LfAnswers | 18.03.2017 03:12 | TDS Killer Code:
02:57:16.0796 0x06b4 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
02:57:16.0796 0x06b4 UEFI system
02:57:20.0571 0x06b4 ============================================================
02:57:20.0571 0x06b4 Current date / time: 2017/03/18 02:57:20.0571
02:57:20.0571 0x06b4 SystemInfo:
02:57:20.0571 0x06b4
02:57:20.0571 0x06b4 OS Version: 10.0.14393 ServicePack: 0.0
02:57:20.0571 0x06b4 Product type: Workstation
02:57:20.0571 0x06b4 ComputerName: XXXX-PC
02:57:20.0571 0x06b4 UserName: XXXX
02:57:20.0571 0x06b4 Windows directory: C:\WINDOWS
02:57:20.0571 0x06b4 System windows directory: C:\WINDOWS
02:57:20.0571 0x06b4 Running under WOW64
02:57:20.0571 0x06b4 Processor architecture: Intel x64
02:57:20.0571 0x06b4 Number of processors: 8
02:57:20.0571 0x06b4 Page size: 0x1000
02:57:20.0571 0x06b4 Boot type: Normal boot
02:57:20.0571 0x06b4 CodeIntegrityOptions = 0x00000001
02:57:20.0571 0x06b4 ============================================================
02:57:20.0770 0x06b4 KLMD registered as C:\WINDOWS\system32\drivers\56959986.sys
02:57:20.0771 0x06b4 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.953, osProperties = 0x19
02:57:20.0974 0x06b4 System UUID: {17E68F95-C40F-2EB6-D1BB-610BBB050363}
02:57:21.0310 0x06b4 Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
02:57:21.0321 0x06b4 ============================================================
02:57:21.0321 0x06b4 \Device\Harddisk0\DR0:
02:57:21.0322 0x06b4 GPT partitions:
02:57:21.0322 0x06b4 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {65AAF8A8-1627-4F5B-AA99-8A43F8FA36CF}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x32000
02:57:21.0322 0x06b4 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {42C692D2-451B-4636-8993-D8E6E6141AA7}, Name: Microsoft reserved partition, StartLBA 0x32800, BlocksNum 0x40000
02:57:21.0322 0x06b4 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {FB1D1AAE-C868-4726-B55A-E3DCA77D212B}, Name: Basic data partition, StartLBA 0x72800, BlocksNum 0x3DE55000
02:57:21.0322 0x06b4 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {31B8AEE0-E25D-4786-8826-6835E2CB83C6}, Name: , StartLBA 0x3DEC7800, BlocksNum 0xE1000
02:57:21.0322 0x06b4 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {66DF142A-43DF-4742-956A-EBA1940BA6DD}, Name: Basic data partition, StartLBA 0x3DFA8800, BlocksNum 0xAAE60000
02:57:21.0322 0x06b4 MBR partitions:
02:57:21.0322 0x06b4 ============================================================
02:57:21.0335 0x06b4 C: <-> \Device\Harddisk0\DR0\Partition3
02:57:21.0358 0x06b4 D: <-> \Device\Harddisk0\DR0\Partition5
02:57:21.0358 0x06b4 ============================================================
02:57:21.0358 0x06b4 Initialize success
02:57:21.0358 0x06b4 ============================================================
02:57:24.0705 0x12d8 ============================================================
02:57:24.0705 0x12d8 Scan started
02:57:24.0705 0x12d8 Mode: Manual;
02:57:24.0705 0x12d8 ============================================================
02:57:24.0705 0x12d8 KSN ping started
02:57:24.0821 0x12d8 KSN ping finished: true
02:57:27.0647 0x12d8 ================ Scan system memory ========================
02:57:27.0647 0x12d8 System memory - ok
02:57:27.0650 0x12d8 ================ Scan services =============================
02:57:27.0749 0x12d8 1394ohci - ok
02:57:27.0752 0x12d8 3ware - ok
02:57:27.0762 0x12d8 ACPI - ok
02:57:27.0764 0x12d8 AcpiDev - ok
02:57:27.0766 0x12d8 acpiex - ok
02:57:27.0769 0x12d8 acpipagr - ok
02:57:27.0783 0x12d8 AcpiPmi - ok
02:57:27.0787 0x12d8 acpitime - ok
02:57:27.0791 0x12d8 ADP80XX - ok
02:57:27.0801 0x12d8 AFD - ok
02:57:27.0812 0x12d8 ahcache - ok
02:57:27.0819 0x12d8 AJRouter - ok
02:57:27.0828 0x12d8 ALG - ok
02:57:27.0831 0x12d8 AmdK8 - ok
02:57:27.0833 0x12d8 AmdPPM - ok
02:57:27.0835 0x12d8 amdsata - ok
02:57:27.0838 0x12d8 amdsbs - ok
02:57:27.0841 0x12d8 amdxata - ok
02:57:27.0905 0x12d8 [ 42A60840C182E9CFCD4E5EF950303512, E7C3D9888529156D9FB03BC51B170AC027ABA6E7B1ED69FA29944546A202907A ] AntiVirMailService C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
02:57:27.0918 0x12d8 AntiVirMailService - ok
02:57:27.0948 0x12d8 [ 58FD213E044D88825E411A1A0A6AEE64, 870591B7995874215C70218F460C1761564533D75BD4855ACB071F9425AAAB77 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\Antivirus\sched.exe
02:57:27.0954 0x12d8 AntiVirSchedulerService - ok
02:57:27.0975 0x12d8 [ 58FD213E044D88825E411A1A0A6AEE64, 870591B7995874215C70218F460C1761564533D75BD4855ACB071F9425AAAB77 ] AntiVirService C:\Program Files (x86)\Avira\Antivirus\avguard.exe
02:57:27.0981 0x12d8 AntiVirService - ok
02:57:28.0013 0x12d8 [ 4C1B4579EF9D12C88132367333F8F794, 2193359E04F5313BFB7E5FE9AF6D7FBCFFF2CEBCC217F29817F9D450C91160DD ] AntiVirWebService C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
02:57:28.0030 0x12d8 AntiVirWebService - ok
02:57:28.0042 0x12d8 AppHostSvc - ok
02:57:28.0045 0x12d8 AppID - ok
02:57:28.0053 0x12d8 AppIDSvc - ok
02:57:28.0065 0x12d8 Appinfo - ok
02:57:28.0083 0x12d8 applockerfltr - ok
02:57:28.0095 0x12d8 AppReadiness - ok
02:57:28.0099 0x12d8 AppXSvc - ok
02:57:28.0107 0x12d8 arcsas - ok
02:57:28.0169 0x12d8 aspnet_state - ok
02:57:28.0171 0x12d8 AsyncMac - ok
02:57:28.0187 0x12d8 atapi - ok
02:57:28.0192 0x12d8 athr - ok
02:57:28.0212 0x12d8 AudioEndpointBuilder - ok
02:57:28.0219 0x12d8 Audiosrv - ok
02:57:28.0240 0x12d8 [ 11F3AAFB5D279AFBCBB0AD9FF76A24F8, 06C5FA1BD64EB54691629363DD0771394F81E4EB216E489D5169395736E80D99 ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys
02:57:28.0242 0x12d8 avgntflt - ok
02:57:28.0262 0x12d8 [ F8520E88246641E51108922944FB34A6, 326DCB8114439FB1F75E9DB6E5F7818654FAAC4CD957B80DEE17B850676A737F ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys
02:57:28.0265 0x12d8 avipbb - ok
02:57:28.0292 0x12d8 [ 2AEE4D1D7E668F1CCF97EDE93509B0EE, B082B3BBB27D3C8B26A754508C3B98BA803FEA707898FF18A120D6A2679098DF ] Avira.ServiceHost C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
02:57:28.0297 0x12d8 Avira.ServiceHost - ok
02:57:28.0301 0x12d8 [ 2CBA09A7983B1D39531B768BCED08C20, B40968DFE1A648CCB9260033E1EA57B5D496274A335B000354156B0DB740EDE0 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys
02:57:28.0302 0x12d8 avkmgr - ok
02:57:28.0324 0x12d8 [ 8D18C6406FF8DC39028177E1E5675182, 44985DEE74F235567FB849350256F342BCE26EF66439D761FA3F6EDA22882092 ] avnetflt C:\WINDOWS\system32\DRIVERS\avnetflt.sys
02:57:28.0325 0x12d8 avnetflt - ok
02:57:28.0337 0x12d8 AxInstSV - ok
02:57:28.0339 0x12d8 b06bdrv - ok
02:57:28.0348 0x12d8 BasicDisplay - ok
02:57:28.0351 0x12d8 BasicRender - ok
02:57:28.0355 0x12d8 bcmfn - ok
02:57:28.0357 0x12d8 bcmfn2 - ok
02:57:28.0367 0x12d8 BDESVC - ok
02:57:28.0377 0x12d8 Beep - ok
02:57:28.0390 0x12d8 BFE - ok
02:57:28.0402 0x12d8 BITS - ok
02:57:28.0417 0x12d8 bowser - ok
02:57:28.0425 0x12d8 BrokerInfrastructure - ok
02:57:28.0427 0x12d8 Browser - ok
02:57:28.0430 0x12d8 BthAvrcpTg - ok
02:57:28.0433 0x12d8 BthHFEnum - ok
02:57:28.0435 0x12d8 bthhfhid - ok
02:57:28.0437 0x12d8 BthHFSrv - ok
02:57:28.0440 0x12d8 BTHMODEM - ok
02:57:28.0443 0x12d8 bthserv - ok
02:57:28.0453 0x12d8 buttonconverter - ok
02:57:28.0456 0x12d8 CapImg - ok
02:57:28.0459 0x12d8 cdfs - ok
02:57:28.0472 0x12d8 CDPSvc - ok
02:57:28.0481 0x12d8 CDPUserSvc - ok
02:57:28.0513 0x12d8 cdrom - ok
02:57:28.0529 0x12d8 CertPropSvc - ok
02:57:28.0532 0x12d8 cht4iscsi - ok
02:57:28.0534 0x12d8 cht4vbd - ok
02:57:28.0537 0x12d8 circlass - ok
02:57:28.0550 0x12d8 CLFS - ok
02:57:28.0552 0x12d8 ClipSVC - ok
02:57:28.0555 0x12d8 clreg - ok
02:57:28.0562 0x12d8 CmBatt - ok
02:57:28.0574 0x12d8 CNG - ok
02:57:28.0576 0x12d8 cnghwassist - ok
02:57:28.0605 0x12d8 CompositeBus - ok
02:57:28.0607 0x12d8 COMSysApp - ok
02:57:28.0610 0x12d8 condrv - ok
02:57:28.0620 0x12d8 CoreMessagingRegistrar - ok
02:57:28.0632 0x12d8 CryptSvc - ok
02:57:28.0637 0x12d8 dam - ok
02:57:28.0641 0x12d8 DcomLaunch - ok
02:57:28.0650 0x12d8 DcpSvc - ok
02:57:28.0662 0x12d8 defragsvc - ok
02:57:28.0675 0x12d8 DeviceAssociationService - ok
02:57:28.0679 0x12d8 DeviceInstall - ok
02:57:28.0690 0x12d8 DevQueryBroker - ok
02:57:28.0701 0x12d8 Dfsc - ok
02:57:28.0723 0x12d8 Dhcp - ok
02:57:28.0755 0x12d8 diagnosticshub.standardcollector.service - ok
02:57:28.0770 0x12d8 DiagTrack - ok
02:57:28.0782 0x12d8 disk - ok
02:57:28.0788 0x12d8 DmEnrollmentSvc - ok
02:57:28.0791 0x12d8 dmvsc - ok
02:57:28.0794 0x12d8 dmwappushservice - ok
02:57:28.0804 0x12d8 Dnscache - ok
02:57:28.0807 0x12d8 dot3svc - ok
02:57:28.0809 0x12d8 DPS - ok
02:57:28.0819 0x12d8 drmkaud - ok
02:57:28.0822 0x12d8 DsmSvc - ok
02:57:28.0824 0x12d8 DsSvc - ok
02:57:28.0826 0x12d8 DXGKrnl - ok
02:57:28.0829 0x12d8 EapHost - ok
02:57:28.0831 0x12d8 ebdrv - ok
02:57:28.0854 0x12d8 EFS - ok
02:57:28.0857 0x12d8 EhStorClass - ok
02:57:28.0871 0x12d8 EhStorTcgDrv - ok
02:57:28.0875 0x12d8 embeddedmode - ok
02:57:28.0887 0x12d8 EntAppSvc - ok
02:57:28.0890 0x12d8 ErrDev - ok
02:57:28.0902 0x12d8 EventSystem - ok
02:57:28.0904 0x12d8 exfat - ok
02:57:28.0915 0x12d8 fastfat - ok
02:57:28.0923 0x12d8 Fax - ok
02:57:28.0925 0x12d8 fdc - ok
02:57:28.0928 0x12d8 fdPHost - ok
02:57:28.0930 0x12d8 FDResPub - ok
02:57:28.0947 0x12d8 fhsvc - ok
02:57:28.0967 0x12d8 FileCrypt - ok
02:57:28.0969 0x12d8 FileInfo - ok
02:57:28.0971 0x12d8 Filetrace - ok
02:57:28.0973 0x12d8 flpydisk - ok
02:57:28.0976 0x12d8 FltMgr - ok
02:57:28.0982 0x12d8 FontCache - ok
02:57:29.0024 0x12d8 FontCache3.0.0.0 - ok
02:57:29.0034 0x12d8 FrameServer - ok
02:57:29.0036 0x12d8 FsDepends - ok
02:57:29.0038 0x12d8 Fs_Rec - ok
02:57:29.0050 0x12d8 fvevol - ok
02:57:29.0053 0x12d8 gencounter - ok
02:57:29.0056 0x12d8 genericusbfn - ok
02:57:29.0140 0x12d8 [ CBD39E74C61C3A3EF695DB25792F32E6, 95454F245DB818227BFE92EBA927A68FA78FB87E7BF5C28761046FF36C56CF32 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
02:57:29.0154 0x12d8 GfExperienceService - ok
02:57:29.0168 0x12d8 GPIOClx0101 - ok
02:57:29.0171 0x12d8 gpsvc - ok
02:57:29.0173 0x12d8 GpuEnergyDrv - ok
02:57:29.0179 0x12d8 HDAudBus - ok
02:57:29.0181 0x12d8 HidBatt - ok
02:57:29.0184 0x12d8 HidBth - ok
02:57:29.0187 0x12d8 hidi2c - ok
02:57:29.0189 0x12d8 hidinterrupt - ok
02:57:29.0192 0x12d8 HidIr - ok
02:57:29.0200 0x12d8 hidserv - ok
02:57:29.0228 0x12d8 HidUsb - ok
02:57:29.0242 0x12d8 HomeGroupListener - ok
02:57:29.0255 0x12d8 HomeGroupProvider - ok
02:57:29.0260 0x12d8 HpSAMD - ok
02:57:29.0271 0x12d8 HTTP - ok
02:57:29.0287 0x12d8 HvHost - ok
02:57:29.0309 0x12d8 hvservice - ok
02:57:29.0312 0x12d8 hwpolicy - ok
02:57:29.0315 0x12d8 hyperkbd - ok
02:57:29.0328 0x12d8 i8042prt - ok
02:57:29.0330 0x12d8 iagpio - ok
02:57:29.0334 0x12d8 iai2c - ok
02:57:29.0336 0x12d8 iaLPSS2i_GPIO2 - ok
02:57:29.0338 0x12d8 iaLPSS2i_I2C - ok
02:57:29.0341 0x12d8 iaLPSSi_GPIO - ok
02:57:29.0343 0x12d8 iaLPSSi_I2C - ok
02:57:29.0372 0x12d8 [ 47813F2DB651B54F1D3B44848E6CB4F9, 85FD9CEE050C5564EA4665B9B99B58E713217D8CBB5B85A075CA8C0C23D50388 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
02:57:29.0381 0x12d8 iaStorA - ok
02:57:29.0384 0x12d8 iaStorAV - ok
02:57:29.0387 0x12d8 iaStorV - ok
02:57:29.0389 0x12d8 ibbus - ok
02:57:29.0399 0x12d8 icssvc - ok
02:57:29.0403 0x12d8 IKEEXT - ok
02:57:29.0406 0x12d8 IndirectKmd - ok
02:57:29.0451 0x12d8 [ DDA8E5AD97231AB50B81FED04C28F64C, 5C9E8F7CC45A9AE7FF12A02641562E271D84894DFA7C50218AC2AAA298251B60 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
02:57:29.0459 0x12d8 Intel(R) Capability Licensing Service Interface - ok
02:57:29.0485 0x12d8 [ 86FE509640D77FB0998FC8B1FF5523C6, 13E895DEB9B84379251699D7E52C5E3FD888994425DE01B6C4634F9E959D5584 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
02:57:29.0495 0x12d8 Intel(R) Capability Licensing Service TCP IP Interface - ok
02:57:29.0537 0x12d8 [ EE65488B7294FBCB113EAC9FD492345C, D1D6B22CD94324387171B188D295AA716900654DA1DC9F3DC18D0CD528F2BBEA ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
02:57:29.0539 0x12d8 Intel(R) ME Service - ok
02:57:29.0558 0x12d8 intelide - ok
02:57:29.0561 0x12d8 intelpep - ok
02:57:29.0563 0x12d8 intelppm - ok
02:57:29.0577 0x12d8 iorate - ok
02:57:29.0586 0x12d8 IpFilterDriver - ok
02:57:29.0606 0x12d8 iphlpsvc - ok
02:57:29.0616 0x12d8 IPMIDRV - ok
02:57:29.0618 0x12d8 IPNAT - ok
02:57:29.0620 0x12d8 irda - ok
02:57:29.0622 0x12d8 IRENUM - ok
02:57:29.0631 0x12d8 irmon - ok
02:57:29.0642 0x12d8 isapnp - ok
02:57:29.0645 0x12d8 iScsiPrt - ok
02:57:29.0666 0x12d8 [ BF5D3A2624177C413680DEF19A465AF8, B9909D3E6CB6F9971293116387865AD15CB9D47513C7FAA9C36BE4D2847A41EB ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
02:57:29.0668 0x12d8 jhi_service - ok
02:57:29.0671 0x12d8 kbdclass - ok
02:57:29.0674 0x12d8 kbdhid - ok
02:57:29.0685 0x12d8 kdnic - ok
02:57:29.0688 0x12d8 KeyIso - ok
02:57:29.0700 0x12d8 KSecDD - ok
02:57:29.0709 0x12d8 KSecPkg - ok
02:57:29.0712 0x12d8 ksthunk - ok
02:57:29.0723 0x12d8 KtmRm - ok
02:57:29.0733 0x12d8 LanmanServer - ok
02:57:29.0747 0x12d8 LanmanWorkstation - ok
02:57:29.0762 0x12d8 lfsvc - ok
02:57:29.0765 0x12d8 LicenseManager - ok
02:57:29.0767 0x12d8 lltdio - ok
02:57:29.0769 0x12d8 lltdsvc - ok
02:57:29.0778 0x12d8 lmhosts - ok
02:57:29.0797 0x12d8 [ 41686112986A43CFF8CE1EC2A575D6F9, 998E0F4809EE6F21A6ECDADA2CC85CB1A78FDF6AFB88F352C06F69A12E059D3C ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
02:57:29.0802 0x12d8 LMS - ok
02:57:29.0806 0x12d8 LSI_SAS - ok
02:57:29.0809 0x12d8 LSI_SAS2i - ok
02:57:29.0812 0x12d8 LSI_SAS3i - ok
02:57:29.0814 0x12d8 LSI_SSS - ok
02:57:29.0821 0x12d8 LSM - ok
02:57:29.0823 0x12d8 luafv - ok
02:57:29.0837 0x12d8 MapsBroker - ok
02:57:29.0855 0x12d8 [ 47701ECA633574E122687693B5C5D35C, 1DB12767462347504956450FAD0D90B6E682E2E8959A6C5DF3792C3C3DA289B1 ] mbamchameleon C:\WINDOWS\system32\drivers\mbamchameleon.sys
02:57:29.0857 0x12d8 mbamchameleon - ok
02:57:29.0860 0x12d8 megasas - ok
02:57:29.0876 0x12d8 megasas2i - ok
02:57:29.0879 0x12d8 megasr - ok
02:57:29.0895 0x12d8 [ 2BB3EAE2EA641515D4B205CAB29E1624, D3F18EE393EB1B0F919484281269A3C55A092D023E62C59D74CB63A55612024B ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
02:57:29.0896 0x12d8 MEIx64 - ok
02:57:29.0899 0x12d8 MessagingService - ok
02:57:29.0903 0x12d8 mlx4_bus - ok
02:57:29.0906 0x12d8 MMCSS - ok
02:57:29.0908 0x12d8 Modem - ok
02:57:29.0917 0x12d8 monitor - ok
02:57:29.0920 0x12d8 mouclass - ok
02:57:29.0922 0x12d8 mouhid - ok
02:57:29.0924 0x12d8 mountmgr - ok
02:57:29.0954 0x12d8 [ 6F607DE20B98EA056E60319915ADD541, 522E326441EBFE726345ACD36E8DA2BB26849B3350A16463345D1E137CBEE3DF ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
02:57:29.0956 0x12d8 MozillaMaintenance - ok
02:57:29.0958 0x12d8 mpsdrv - ok
02:57:29.0965 0x12d8 MpsSvc - ok
02:57:29.0996 0x12d8 MQAC - ok
02:57:29.0999 0x12d8 MRxDAV - ok
02:57:30.0010 0x12d8 mrxsmb - ok
02:57:30.0021 0x12d8 mrxsmb10 - ok
02:57:30.0027 0x12d8 mrxsmb20 - ok
02:57:30.0029 0x12d8 MsBridge - ok
02:57:30.0041 0x12d8 MSDTC - ok
02:57:30.0045 0x12d8 Msfs - ok
02:57:30.0047 0x12d8 msgpiowin32 - ok
02:57:30.0049 0x12d8 mshidkmdf - ok
02:57:30.0052 0x12d8 mshidumdf - ok
02:57:30.0054 0x12d8 msisadrv - ok
02:57:30.0066 0x12d8 MSiSCSI - ok
02:57:30.0068 0x12d8 msiserver - ok
02:57:30.0076 0x12d8 MSKSSRV - ok
02:57:30.0078 0x12d8 MsLldp - ok
02:57:30.0090 0x12d8 MSMQ - ok
02:57:30.0092 0x12d8 MSPCLOCK - ok
02:57:30.0094 0x12d8 MSPQM - ok
02:57:30.0096 0x12d8 MsRPC - ok
02:57:30.0100 0x12d8 mssmbios - ok
02:57:30.0102 0x12d8 MSTEE - ok
02:57:30.0104 0x12d8 MTConfig - ok
02:57:30.0106 0x12d8 Mup - ok
02:57:30.0108 0x12d8 mvumis - ok
02:57:30.0113 0x12d8 NativeWifiP - ok
02:57:30.0115 0x12d8 NcaSvc - ok
02:57:30.0125 0x12d8 NcbService - ok
02:57:30.0127 0x12d8 NcdAutoSetup - ok
02:57:30.0129 0x12d8 ndfltr - ok
02:57:30.0131 0x12d8 NDIS - ok
02:57:30.0133 0x12d8 NdisCap - ok
02:57:30.0143 0x12d8 NdisImPlatform - ok
02:57:30.0146 0x12d8 NdisTapi - ok
02:57:30.0148 0x12d8 Ndisuio - ok
02:57:30.0150 0x12d8 NdisVirtualBus - ok
02:57:30.0152 0x12d8 NdisWan - ok
02:57:30.0154 0x12d8 ndiswanlegacy - ok
02:57:30.0156 0x12d8 ndproxy - ok
02:57:30.0159 0x12d8 Ndu - ok
02:57:30.0161 0x12d8 NetAdapterCx - ok
02:57:30.0163 0x12d8 NetBIOS - ok
02:57:30.0165 0x12d8 NetBT - ok
02:57:30.0167 0x12d8 Netlogon - ok
02:57:30.0179 0x12d8 Netman - ok
02:57:30.0191 0x12d8 NetMsmqActivator - ok
02:57:30.0192 0x12d8 NetPipeActivator - ok
02:57:30.0195 0x12d8 netprofm - ok
02:57:30.0210 0x12d8 NetSetupSvc - ok
02:57:30.0211 0x12d8 NetTcpActivator - ok
02:57:30.0213 0x12d8 NetTcpPortSharing - ok
02:57:30.0226 0x12d8 NgcCtnrSvc - ok
02:57:30.0238 0x12d8 NgcSvc - ok
02:57:30.0240 0x12d8 NlaSvc - ok
02:57:30.0243 0x12d8 Npfs - ok
02:57:30.0245 0x12d8 npsvctrig - ok
02:57:30.0247 0x12d8 nsi - ok
02:57:30.0249 0x12d8 nsiproxy - ok
02:57:30.0258 0x12d8 NTFS - ok
02:57:30.0261 0x12d8 Null - ok
02:57:30.0281 0x12d8 [ 04936C52B2FF72BB777EEE23FFFED7E0, 5431280DB9897E2A7DD5F496BC6EA5A346C520455072F05235455EB14CE040A0 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
02:57:30.0284 0x12d8 NVHDA - ok
02:57:30.0558 0x12d8 [ 4D56E475D32437ECF663CE944D7E0D3F, 22F4E20D066A750ECC1C2566A0D93FE059CA16CF8A0D26002A1B721E26D443D7 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nvhdcwu.inf_amd64_66cd0bfdc007680b\nvlddmkm.sys
02:57:30.0714 0x12d8 nvlddmkm - ok
02:57:30.0866 0x12d8 [ 855093AFA0B795914D6DD5EF4796D38C, A19B94449DBA50BCC2C09D42DEA1BF29CEF3C79B8F7F384904189A579AAA85A0 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
02:57:30.0887 0x12d8 NvNetworkService - ok
02:57:30.0901 0x12d8 nvraid - ok
02:57:30.0903 0x12d8 nvstor - ok
02:57:30.0940 0x12d8 [ BD96CA245DA2933BB68605D0C2075A72, E406CD97FA1A640C1C5FE01B360A0A9DED6E696F2765E395C16AAFF59F24B7B4 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
02:57:30.0941 0x12d8 NvStreamKms - ok
02:57:31.0093 0x12d8 [ CF27CDA72455B4A7853ED98CFC57218A, D66C3AECF8AAE38ED2DAFF9ABB38FE0301A85375250A8CDEF50F68DECE8BBC64 ] NvStreamNetworkSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
02:57:31.0161 0x12d8 NvStreamNetworkSvc - ok
02:57:31.0247 0x12d8 [ 40BA84AD3348573609095D8F3FD2DA9F, FF68F2352AFCB8C278A2E704F3E9DCC4393299DEAECD9ACF96F2D7FD9830EDF1 ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
02:57:31.0299 0x12d8 NvStreamSvc - ok
02:57:31.0312 0x12d8 [ 64E8275CEAD43D3CA8E3A311B2F4B64A, 99E683890B9AF3243100B387317760B5F91745EF9F7FF2ABA2DC7B6551A6EAB6 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
02:57:31.0313 0x12d8 nvvad_WaveExtensible - ok
02:57:31.0326 0x12d8 OneSyncSvc - ok
02:57:31.0442 0x12d8 [ 3E498CE04DD40C60769854DF2CE8D21D, 28B9331787FE598A79E40DA839B022D353280BE0E8F0D20CE4AAB6284866DE48 ] Origin Client Service D:\Spiele\Origin\OriginClientService.exe
02:57:31.0465 0x12d8 Origin Client Service - ok
02:57:31.0518 0x12d8 [ B66980E730FEF1E31BE39B09F55514A1, 756F7695AB112FB2FEBA905F5F9E7C9435823195DE164AF60071457BC047535E ] Origin Web Helper Service D:\Spiele\Origin\OriginWebHelperService.exe
02:57:31.0542 0x12d8 Origin Web Helper Service - ok
02:57:31.0562 0x12d8 p2pimsvc - ok
02:57:31.0570 0x12d8 p2psvc - ok
02:57:31.0575 0x12d8 Parport - ok
02:57:31.0582 0x12d8 partmgr - ok
02:57:31.0599 0x12d8 PcaSvc - ok
02:57:31.0612 0x12d8 pci - ok
02:57:31.0633 0x12d8 pciide - ok
02:57:31.0638 0x12d8 pcmcia - ok
02:57:31.0642 0x12d8 pcw - ok
02:57:31.0647 0x12d8 pdc - ok
02:57:31.0662 0x12d8 PEAUTH - ok
02:57:31.0673 0x12d8 percsas2i - ok
02:57:31.0677 0x12d8 percsas3i - ok
02:57:31.0717 0x12d8 PerfHost - ok
02:57:31.0740 0x12d8 PhoneSvc - ok
02:57:31.0764 0x12d8 PimIndexMaintenanceSvc - ok
02:57:31.0774 0x12d8 pla - ok
02:57:31.0784 0x12d8 PlugPlay - ok
02:57:31.0790 0x12d8 PNRPAutoReg - ok
02:57:31.0795 0x12d8 PNRPsvc - ok
02:57:31.0801 0x12d8 PolicyAgent - ok
02:57:31.0807 0x12d8 Power - ok
02:57:31.0811 0x12d8 PptpMiniport - ok
02:57:32.0132 0x12d8 [ 77ABF70C71922873BC160933571B3F83, 7FCFBB4B42E7A92FCF11388CD5B600EA79A7C134F13A8A88CF8DCD3DB96C3F5A ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
02:57:32.0170 0x12d8 PrintNotify - ok
02:57:32.0193 0x12d8 Processor - ok
02:57:32.0201 0x12d8 ProfSvc - ok
02:57:32.0212 0x12d8 Psched - ok
02:57:32.0222 0x12d8 QWAVE - ok
02:57:32.0225 0x12d8 QWAVEdrv - ok
02:57:32.0228 0x12d8 RasAcd - ok
02:57:32.0249 0x12d8 RasAgileVpn - ok
02:57:32.0256 0x12d8 RasAuto - ok
02:57:32.0259 0x12d8 Rasl2tp - ok
02:57:32.0269 0x12d8 RasMan - ok
02:57:32.0272 0x12d8 RasPppoe - ok
02:57:32.0275 0x12d8 RasSstp - ok
02:57:32.0278 0x12d8 rdbss - ok
02:57:32.0292 0x12d8 rdpbus - ok
02:57:32.0294 0x12d8 RDPDR - ok
02:57:32.0327 0x12d8 RdpVideoMiniport - ok
02:57:32.0330 0x12d8 rdyboost - ok
02:57:32.0332 0x12d8 ReFSv1 - ok
02:57:32.0343 0x12d8 RemoteAccess - ok
02:57:32.0345 0x12d8 RemoteRegistry - ok
02:57:32.0365 0x12d8 RetailDemo - ok
02:57:32.0373 0x12d8 RmSvc - ok
02:57:32.0377 0x12d8 RpcEptMapper - ok
02:57:32.0391 0x12d8 RpcLocator - ok
02:57:32.0393 0x12d8 RpcSs - ok
02:57:32.0395 0x12d8 rspndr - ok
02:57:32.0422 0x12d8 [ 5E0A1D70E4B0EBCFF68DCBBDF0BBBC13, 2DA2979A1AE8D6BA43F3E556C57342CF7D4EAFEC01D12E0D4C32368EBA74B79C ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
02:57:32.0433 0x12d8 rt640x64 - ok
02:57:32.0446 0x12d8 s3cap - ok
02:57:32.0449 0x12d8 SamSs - ok
02:57:32.0452 0x12d8 sbp2port - ok
02:57:32.0474 0x12d8 SCardSvr - ok
02:57:32.0499 0x12d8 ScDeviceEnum - ok
02:57:32.0522 0x12d8 scfilter - ok
02:57:32.0525 0x12d8 Schedule - ok
02:57:32.0527 0x12d8 scmbus - ok
02:57:32.0530 0x12d8 scmdisk0101 - ok
02:57:32.0546 0x12d8 SCPolicySvc - ok
02:57:32.0553 0x12d8 sdbus - ok
02:57:32.0559 0x12d8 SDRSVC - ok
02:57:32.0562 0x12d8 sdstor - ok
02:57:32.0564 0x12d8 seclogon - ok
02:57:32.0571 0x12d8 SENS - ok
02:57:32.0582 0x12d8 SensorDataService - ok
02:57:32.0594 0x12d8 SensorService - ok
02:57:32.0597 0x12d8 SensrSvc - ok
02:57:32.0598 0x12d8 SerCx - ok
02:57:32.0602 0x12d8 SerCx2 - ok
02:57:32.0604 0x12d8 Serenum - ok
02:57:32.0605 0x12d8 Serial - ok
02:57:32.0609 0x12d8 sermouse - ok
02:57:32.0614 0x12d8 SessionEnv - ok
02:57:32.0618 0x12d8 sfloppy - ok
02:57:32.0631 0x12d8 SharedAccess - ok
02:57:32.0645 0x12d8 ShellHWDetection - ok
02:57:32.0664 0x12d8 shpamsvc - ok
02:57:32.0666 0x12d8 SiSRaid2 - ok
02:57:32.0668 0x12d8 SiSRaid4 - ok
02:57:32.0683 0x12d8 smphost - ok
02:57:32.0701 0x12d8 SmsRouter - ok
02:57:32.0708 0x12d8 SNMPTRAP - ok
02:57:32.0728 0x12d8 spaceport - ok
02:57:32.0731 0x12d8 SpbCx - ok
02:57:32.0746 0x12d8 Spooler - ok
02:57:32.0765 0x12d8 sppsvc - ok
02:57:32.0768 0x12d8 srv - ok
02:57:32.0780 0x12d8 srv2 - ok
02:57:32.0783 0x12d8 srvnet - ok
02:57:32.0786 0x12d8 SSDPSRV - ok
02:57:32.0800 0x12d8 SstpSvc - ok
02:57:32.0813 0x12d8 StateRepository - ok
02:57:32.0894 0x12d8 [ 5CBCEB3FF7C232ACC8891C8197BF3353, B1FE57C61E62B1FEC81B219551DAD68DC5DF17FC1603CDC0CBA097A3E687A027 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
02:57:32.0912 0x12d8 Steam Client Service - ok
02:57:32.0926 0x12d8 stexstor - ok
02:57:32.0965 0x12d8 [ A73F13903345464F04D463B84890A271, F22A088D94418420CA3943D34CB233B82B36A6A66BB36000A44726244D794AFF ] STHDA C:\WINDOWS\system32\DRIVERS\stwrt64.sys
02:57:32.0977 0x12d8 STHDA - ok
02:57:33.0002 0x12d8 stisvc - ok
02:57:33.0017 0x12d8 storahci - ok
02:57:33.0021 0x12d8 storflt - ok
02:57:33.0032 0x12d8 stornvme - ok
02:57:33.0036 0x12d8 storqosflt - ok
02:57:33.0048 0x12d8 StorSvc - ok
02:57:33.0051 0x12d8 storufs - ok
02:57:33.0055 0x12d8 storvsc - ok
02:57:33.0067 0x12d8 svsvc - ok
02:57:33.0071 0x12d8 swenum - ok
02:57:33.0076 0x12d8 swprv - ok
02:57:33.0095 0x12d8 Synth3dVsc - ok
02:57:33.0102 0x12d8 SysMain - ok
02:57:33.0107 0x12d8 SystemEventsBroker - ok
02:57:33.0112 0x12d8 TabletInputService - ok
02:57:33.0116 0x12d8 TapiSrv - ok
02:57:33.0130 0x12d8 Tcpip - ok
02:57:33.0133 0x12d8 Tcpip6 - ok
02:57:33.0145 0x12d8 tcpipreg - ok
02:57:33.0151 0x12d8 tdx - ok
02:57:33.0155 0x12d8 terminpt - ok
02:57:33.0159 0x12d8 TermService - ok
02:57:33.0175 0x12d8 Themes - ok
02:57:33.0193 0x12d8 TieringEngineService - ok
02:57:33.0197 0x12d8 tiledatamodelsvc - ok
02:57:33.0201 0x12d8 TimeBrokerSvc - ok
02:57:33.0205 0x12d8 TPM - ok
02:57:33.0209 0x12d8 TrkWks - ok
02:57:33.0229 0x12d8 TrustedInstaller - ok
02:57:33.0234 0x12d8 tsusbflt - ok
02:57:33.0237 0x12d8 TsUsbGD - ok
02:57:33.0239 0x12d8 tunnel - ok
02:57:33.0262 0x12d8 tzautoupdate - ok
02:57:33.0265 0x12d8 UASPStor - ok
02:57:33.0267 0x12d8 UcmCx0101 - ok
02:57:33.0270 0x12d8 UcmTcpciCx0101 - ok
02:57:33.0273 0x12d8 UcmUcsi - ok
02:57:33.0276 0x12d8 Ucx01000 - ok
02:57:33.0278 0x12d8 UdeCx - ok
02:57:33.0282 0x12d8 udfs - ok
02:57:33.0284 0x12d8 UEFI - ok
02:57:33.0286 0x12d8 Ufx01000 - ok
02:57:33.0290 0x12d8 UfxChipidea - ok
02:57:33.0292 0x12d8 ufxsynopsys - ok
02:57:33.0298 0x12d8 UI0Detect - ok
02:57:33.0300 0x12d8 umbus - ok
02:57:33.0302 0x12d8 UmPass - ok
02:57:33.0305 0x12d8 UmRdpService - ok
02:57:33.0315 0x12d8 UnistoreSvc - ok
02:57:33.0318 0x12d8 upnphost - ok
02:57:33.0322 0x12d8 UrsChipidea - ok
02:57:33.0324 0x12d8 UrsCx01000 - ok
02:57:33.0326 0x12d8 UrsSynopsys - ok
02:57:33.0328 0x12d8 usbccgp - ok
02:57:33.0331 0x12d8 usbcir - ok
02:57:33.0333 0x12d8 usbehci - ok
02:57:33.0335 0x12d8 usbhub - ok
02:57:33.0337 0x12d8 USBHUB3 - ok
02:57:33.0339 0x12d8 usbohci - ok
02:57:33.0342 0x12d8 usbprint - ok
02:57:33.0344 0x12d8 usbser - ok
02:57:33.0346 0x12d8 USBSTOR - ok
02:57:33.0348 0x12d8 usbuhci - ok
02:57:33.0350 0x12d8 USBXHCI - ok
02:57:33.0353 0x12d8 UserDataSvc - ok
02:57:33.0373 0x12d8 UserManager - ok
02:57:33.0385 0x12d8 UsoSvc - ok
02:57:33.0387 0x12d8 VaultSvc - ok
02:57:33.0389 0x12d8 vdrvroot - ok
02:57:33.0399 0x12d8 vds - ok
02:57:33.0401 0x12d8 VerifierExt - ok
02:57:33.0413 0x12d8 vhdmp - ok
02:57:33.0415 0x12d8 vhf - ok
02:57:33.0418 0x12d8 vmbus - ok
02:57:33.0420 0x12d8 VMBusHID - ok
02:57:33.0422 0x12d8 vmgid - ok
02:57:33.0433 0x12d8 vmicguestinterface - ok
02:57:33.0436 0x12d8 vmicheartbeat - ok
02:57:33.0438 0x12d8 vmickvpexchange - ok
02:57:33.0454 0x12d8 vmicrdv - ok
02:57:33.0456 0x12d8 vmicshutdown - ok
02:57:33.0459 0x12d8 vmictimesync - ok
02:57:33.0461 0x12d8 vmicvmsession - ok
02:57:33.0463 0x12d8 vmicvss - ok
02:57:33.0465 0x12d8 volmgr - ok
02:57:33.0467 0x12d8 volmgrx - ok
02:57:33.0469 0x12d8 volsnap - ok
02:57:33.0472 0x12d8 volume - ok
02:57:33.0482 0x12d8 vpci - ok
02:57:33.0486 0x12d8 vsmraid - ok
02:57:33.0488 0x12d8 VSS - ok
02:57:33.0491 0x12d8 VSTXRAID - ok
02:57:33.0493 0x12d8 vwifibus - ok
02:57:33.0495 0x12d8 vwififlt - ok
02:57:33.0497 0x12d8 vwifimp - ok
02:57:33.0500 0x12d8 W32Time - ok
02:57:33.0524 0x12d8 w3logsvc - ok
02:57:33.0535 0x12d8 W3SVC - ok
02:57:33.0537 0x12d8 WacomPen - ok
02:57:33.0544 0x12d8 WalletService - ok
02:57:33.0546 0x12d8 wanarp - ok
02:57:33.0548 0x12d8 wanarpv6 - ok
02:57:33.0550 0x12d8 WAS - ok
02:57:33.0563 0x12d8 wbengine - ok
02:57:33.0570 0x12d8 WbioSrvc - ok
02:57:33.0572 0x12d8 wcifs - ok
02:57:33.0575 0x12d8 Wcmsvc - ok
02:57:33.0578 0x12d8 wcncsvc - ok
02:57:33.0581 0x12d8 wcnfs - ok
02:57:33.0583 0x12d8 WdBoot - ok
02:57:33.0585 0x12d8 Wdf01000 - ok
02:57:33.0587 0x12d8 WdFilter - ok
02:57:33.0591 0x12d8 WdiServiceHost - ok
02:57:33.0593 0x12d8 WdiSystemHost - ok
02:57:33.0596 0x12d8 wdiwifi - ok
02:57:33.0598 0x12d8 WdNisDrv - ok
02:57:33.0612 0x12d8 WdNisSvc - ok
02:57:33.0615 0x12d8 WebClient - ok
02:57:33.0617 0x12d8 Wecsvc - ok
02:57:33.0620 0x12d8 WEPHOSTSVC - ok
02:57:33.0626 0x12d8 wercplsupport - ok
02:57:33.0628 0x12d8 WerSvc - ok
02:57:33.0630 0x12d8 WFPLWFS - ok
02:57:33.0633 0x12d8 WiaRpc - ok
02:57:33.0635 0x12d8 WIMMount - ok
02:57:33.0636 0x12d8 WinDefend - ok
02:57:33.0646 0x12d8 WindowsTrustedRT - ok
02:57:33.0649 0x12d8 WindowsTrustedRTProxy - ok
02:57:33.0651 0x12d8 WinHttpAutoProxySvc - ok
02:57:33.0660 0x12d8 WinMad - ok
02:57:33.0677 0x12d8 Winmgmt - ok
02:57:33.0698 0x12d8 WinRM - ok
02:57:33.0704 0x12d8 WINUSB - ok
02:57:33.0706 0x12d8 WinVerbs - ok
02:57:33.0713 0x12d8 wisvc - ok
02:57:33.0716 0x12d8 WlanSvc - ok
02:57:33.0741 0x12d8 wlidsvc - ok
02:57:33.0744 0x12d8 WmiAcpi - ok
02:57:33.0747 0x12d8 wmiApSrv - ok
02:57:33.0764 0x12d8 WMPNetworkSvc - ok
02:57:33.0773 0x12d8 Wof - ok
02:57:33.0783 0x12d8 workfolderssvc - ok
02:57:33.0800 0x12d8 WPDBusEnum - ok
02:57:33.0803 0x12d8 WpdUpFltr - ok
02:57:33.0806 0x12d8 WpnService - ok
02:57:33.0809 0x12d8 WpnUserService - ok
02:57:33.0836 0x12d8 ws2ifsl - ok
02:57:33.0848 0x12d8 wscsvc - ok
02:57:33.0851 0x12d8 WSearch - ok
02:57:33.0855 0x12d8 wuauserv - ok
02:57:33.0857 0x12d8 WudfPf - ok
02:57:33.0860 0x12d8 WUDFRd - ok
02:57:33.0863 0x12d8 wudfsvc - ok
02:57:33.0865 0x12d8 WUDFWpdFs - ok
02:57:33.0867 0x12d8 WUDFWpdMtp - ok
02:57:33.0870 0x12d8 WwanSvc - ok
02:57:33.0873 0x12d8 XblAuthManager - ok
02:57:33.0876 0x12d8 XblGameSave - ok
02:57:33.0879 0x12d8 xboxgip - ok
02:57:33.0883 0x12d8 XboxNetApiSvc - ok
02:57:33.0898 0x12d8 xinputhid - ok
02:57:33.0908 0x12d8 xusb22 - ok
02:57:33.0909 0x12d8 ================ Scan global ===============================
02:57:33.0962 0x12d8 [ Global ] - ok
02:57:33.0963 0x12d8 ================ Scan MBR ==================================
02:57:33.0972 0x12d8 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
02:57:33.0978 0x12d8 \Device\Harddisk0\DR0 - ok
02:57:33.0978 0x12d8 ================ Scan VBR ==================================
02:57:33.0984 0x12d8 [ AD7BD40A4C0D294F01948F6B0F3730EA ] \Device\Harddisk0\DR0\Partition1
02:57:33.0986 0x12d8 \Device\Harddisk0\DR0\Partition1 - ok
02:57:33.0991 0x12d8 [ A1A1CC4BA4AE1C51FC0245E9B1587FFB ] \Device\Harddisk0\DR0\Partition2
02:57:33.0991 0x12d8 \Device\Harddisk0\DR0\Partition2 - ok
02:57:33.0999 0x12d8 [ 333A0D643E7F1D2CD94334BCFC57AE03 ] \Device\Harddisk0\DR0\Partition3
02:57:34.0001 0x12d8 \Device\Harddisk0\DR0\Partition3 - ok
02:57:34.0016 0x12d8 [ 7EC7217F8D6213120A2CDB876F1FDEB3 ] \Device\Harddisk0\DR0\Partition4
02:57:34.0018 0x12d8 \Device\Harddisk0\DR0\Partition4 - ok
02:57:34.0029 0x12d8 [ 8D10DDACB502CFB061ECE031EDA46539 ] \Device\Harddisk0\DR0\Partition5
02:57:34.0032 0x12d8 \Device\Harddisk0\DR0\Partition5 - ok
02:57:34.0032 0x12d8 ================ Scan generic autorun ======================
02:57:34.0150 0x12d8 [ F4CD6DA32F5FA8DF305C22A444DD7B5D, E8978FDB71597A4501429787E4729555C47292BD40AFDA2487C6D88DFDBD806C ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
02:57:34.0199 0x12d8 NvBackend - ok
02:57:34.0244 0x12d8 SysTrayApp - ok
02:57:34.0264 0x12d8 [ 96A1D93D16F959C6F5A63E749A9F2EF7, 9EDD4EEC5C625ECF4A1C82318ED6B74404E63A3D43312B53E4F627D76D47658C ] C:\Program Files\IDT\WDM\beats64.exe
02:57:34.0267 0x12d8 BeatsOSDApp - ok
02:57:34.0298 0x12d8 [ 258E2CD2C4984A977106C9EF7CA8AF69, D8F6409D5F5782CC27D159D18E914A3DB59D8644D7017CA6F84F0CF30E95174C ] C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
02:57:34.0301 0x12d8 Avira SystrayStartTrigger - ok
02:57:34.0369 0x12d8 [ 1E0029B9936F42C86138EADB5C27439E, 0A57C0DF2E2995C45FB92D1229FFAA1493748F39F01FB53F9559C5AFB5C1CA13 ] C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
02:57:34.0384 0x12d8 avgnt - ok
02:57:34.0386 0x12d8 USB3MON - ok
02:57:34.0428 0x12d8 OneDriveSetup - ok
02:57:34.0430 0x12d8 OneDriveSetup - ok
02:57:34.0586 0x12d8 [ F0B461FB820595E8BAF1161F55BE3E74, B8022060E7280DC568BFC230CA99D37C09092152D0CEE91B08401ACD725E82A2 ] C:\Users\XXXX\AppData\Roaming\Spotify\SpotifyWebHelper.exe
02:57:34.0603 0x12d8 Spotify Web Helper - ok
02:57:34.0605 0x12d8 OneDriveSetup - ok
02:57:34.0606 0x12d8 Waiting for KSN requests completion. In queue: 9
02:57:35.0638 0x12d8 AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\Antivirus\WindowsSecurityCenter.exe ( 15.0.25.151 ), 0x41000 ( enabled : updated )
02:57:35.0653 0x12d8 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x62100 ( disabled : updated )
02:57:35.0658 0x12d8 Win FW state via NFP2: enabled ( trusted )
02:57:35.0779 0x12d8 ============================================================
02:57:35.0779 0x12d8 Scan finished
02:57:35.0779 0x12d8 ============================================================
02:57:35.0802 0x2184 Detected object count: 0
02:57:35.0802 0x2184 Actual detected object count: 0
02:58:45.0452 0x1ee8 ============================================================
02:58:45.0453 0x1ee8 Scan started
02:58:45.0453 0x1ee8 Mode: Manual; SigCheck; TDLFS;
02:58:45.0453 0x1ee8 ============================================================
02:58:45.0453 0x1ee8 KSN ping started
02:58:45.0603 0x1ee8 KSN ping finished: true
02:58:46.0303 0x1ee8 ================ Scan system memory ========================
02:58:46.0303 0x1ee8 System memory - ok
02:58:46.0303 0x1ee8 ================ Scan services =============================
02:58:46.0390 0x1ee8 1394ohci - ok
02:58:46.0396 0x1ee8 3ware - ok
02:58:46.0403 0x1ee8 ACPI - ok
02:58:46.0413 0x1ee8 AcpiDev - ok
02:58:46.0421 0x1ee8 acpiex - ok
02:58:46.0434 0x1ee8 acpipagr - ok
02:58:46.0466 0x1ee8 AcpiPmi - ok
02:58:46.0468 0x1ee8 acpitime - ok
02:58:46.0472 0x1ee8 ADP80XX - ok
02:58:46.0483 0x1ee8 AFD - ok
02:58:46.0503 0x1ee8 ahcache - ok
02:58:46.0510 0x1ee8 AJRouter - ok
02:58:46.0519 0x1ee8 ALG - ok
02:58:46.0521 0x1ee8 AmdK8 - ok
02:58:46.0524 0x1ee8 AmdPPM - ok
02:58:46.0526 0x1ee8 amdsata - ok
02:58:46.0529 0x1ee8 amdsbs - ok
02:58:46.0530 0x1ee8 amdxata - ok
02:58:46.0587 0x1ee8 [ 42A60840C182E9CFCD4E5EF950303512, E7C3D9888529156D9FB03BC51B170AC027ABA6E7B1ED69FA29944546A202907A ] AntiVirMailService C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
02:58:46.0628 0x1ee8 AntiVirMailService - ok
02:58:46.0647 0x1ee8 [ 58FD213E044D88825E411A1A0A6AEE64, 870591B7995874215C70218F460C1761564533D75BD4855ACB071F9425AAAB77 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\Antivirus\sched.exe
02:58:46.0659 0x1ee8 AntiVirSchedulerService - ok
02:58:46.0681 0x1ee8 [ 58FD213E044D88825E411A1A0A6AEE64, 870591B7995874215C70218F460C1761564533D75BD4855ACB071F9425AAAB77 ] AntiVirService C:\Program Files (x86)\Avira\Antivirus\avguard.exe
02:58:46.0694 0x1ee8 AntiVirService - ok
02:58:46.0728 0x1ee8 [ 4C1B4579EF9D12C88132367333F8F794, 2193359E04F5313BFB7E5FE9AF6D7FBCFFF2CEBCC217F29817F9D450C91160DD ] AntiVirWebService C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
02:58:46.0754 0x1ee8 AntiVirWebService - ok
02:58:46.0767 0x1ee8 AppHostSvc - ok
02:58:46.0769 0x1ee8 AppID - ok
02:58:46.0771 0x1ee8 AppIDSvc - ok
02:58:46.0781 0x1ee8 Appinfo - ok
02:58:46.0799 0x1ee8 applockerfltr - ok
02:58:46.0811 0x1ee8 AppReadiness - ok
02:58:46.0813 0x1ee8 AppXSvc - ok
02:58:46.0823 0x1ee8 arcsas - ok
02:58:46.0885 0x1ee8 aspnet_state - ok
02:58:46.0888 0x1ee8 AsyncMac - ok
02:58:46.0903 0x1ee8 atapi - ok
02:58:46.0908 0x1ee8 athr - ok
02:58:46.0928 0x1ee8 AudioEndpointBuilder - ok
02:58:46.0935 0x1ee8 Audiosrv - ok
02:58:46.0956 0x1ee8 [ 11F3AAFB5D279AFBCBB0AD9FF76A24F8, 06C5FA1BD64EB54691629363DD0771394F81E4EB216E489D5169395736E80D99 ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys
02:58:46.0963 0x1ee8 avgntflt - ok
02:58:46.0979 0x1ee8 [ F8520E88246641E51108922944FB34A6, 326DCB8114439FB1F75E9DB6E5F7818654FAAC4CD957B80DEE17B850676A737F ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys
02:58:46.0986 0x1ee8 avipbb - ok
02:58:47.0016 0x1ee8 [ 2AEE4D1D7E668F1CCF97EDE93509B0EE, B082B3BBB27D3C8B26A754508C3B98BA803FEA707898FF18A120D6A2679098DF ] Avira.ServiceHost C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
02:58:47.0029 0x1ee8 Avira.ServiceHost - ok
02:58:47.0036 0x1ee8 [ 2CBA09A7983B1D39531B768BCED08C20, B40968DFE1A648CCB9260033E1EA57B5D496274A335B000354156B0DB740EDE0 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys
02:58:47.0042 0x1ee8 avkmgr - ok
02:58:47.0065 0x1ee8 [ 8D18C6406FF8DC39028177E1E5675182, 44985DEE74F235567FB849350256F342BCE26EF66439D761FA3F6EDA22882092 ] avnetflt C:\WINDOWS\system32\DRIVERS\avnetflt.sys
02:58:47.0071 0x1ee8 avnetflt - ok
02:58:47.0078 0x1ee8 AxInstSV - ok
02:58:47.0080 0x1ee8 b06bdrv - ok
02:58:47.0090 0x1ee8 BasicDisplay - ok
02:58:47.0093 0x1ee8 BasicRender - ok
02:58:47.0096 0x1ee8 bcmfn - ok
02:58:47.0098 0x1ee8 bcmfn2 - ok
02:58:47.0108 0x1ee8 BDESVC - ok
02:58:47.0118 0x1ee8 Beep - ok
02:58:47.0131 0x1ee8 BFE - ok
02:58:47.0143 0x1ee8 BITS - ok
02:58:47.0158 0x1ee8 bowser - ok
02:58:47.0166 0x1ee8 BrokerInfrastructure - ok
02:58:47.0168 0x1ee8 Browser - ok
02:58:47.0171 0x1ee8 BthAvrcpTg - ok
02:58:47.0174 0x1ee8 BthHFEnum - ok
02:58:47.0176 0x1ee8 bthhfhid - ok
02:58:47.0178 0x1ee8 BthHFSrv - ok
02:58:47.0181 0x1ee8 BTHMODEM - ok
02:58:47.0184 0x1ee8 bthserv - ok
02:58:47.0194 0x1ee8 buttonconverter - ok
02:58:47.0196 0x1ee8 CapImg - ok
02:58:47.0198 0x1ee8 cdfs - ok
02:58:47.0213 0x1ee8 CDPSvc - ok
02:58:47.0222 0x1ee8 CDPUserSvc - ok
02:58:47.0226 0x1ee8 cdrom - ok
02:58:47.0244 0x1ee8 CertPropSvc - ok
02:58:47.0247 0x1ee8 cht4iscsi - ok
02:58:47.0249 0x1ee8 cht4vbd - ok
02:58:47.0251 0x1ee8 circlass - ok
02:58:47.0266 0x1ee8 CLFS - ok
02:58:47.0268 0x1ee8 ClipSVC - ok
02:58:47.0270 0x1ee8 clreg - ok
02:58:47.0276 0x1ee8 CmBatt - ok
02:58:47.0278 0x1ee8 CNG - ok
02:58:47.0279 0x1ee8 cnghwassist - ok
02:58:47.0313 0x1ee8 CompositeBus - ok
02:58:47.0315 0x1ee8 COMSysApp - ok
02:58:47.0317 0x1ee8 condrv - ok
02:58:47.0336 0x1ee8 CoreMessagingRegistrar - ok
02:58:47.0341 0x1ee8 CryptSvc - ok
02:58:47.0343 0x1ee8 dam - ok
02:58:47.0346 0x1ee8 DcomLaunch - ok
02:58:47.0349 0x1ee8 DcpSvc - ok
02:58:47.0361 0x1ee8 defragsvc - ok
02:58:47.0375 0x1ee8 DeviceAssociationService - ok
02:58:47.0382 0x1ee8 DeviceInstall - ok
02:58:47.0389 0x1ee8 DevQueryBroker - ok
02:58:47.0391 0x1ee8 Dfsc - ok
02:58:47.0414 0x1ee8 Dhcp - ok
02:58:47.0441 0x1ee8 diagnosticshub.standardcollector.service - ok
02:58:47.0453 0x1ee8 DiagTrack - ok
02:58:47.0465 0x1ee8 disk - ok
02:58:47.0473 0x1ee8 DmEnrollmentSvc - ok
02:58:47.0476 0x1ee8 dmvsc - ok
02:58:47.0479 0x1ee8 dmwappushservice - ok
02:58:47.0487 0x1ee8 Dnscache - ok
02:58:47.0490 0x1ee8 dot3svc - ok
02:58:47.0493 0x1ee8 DPS - ok
02:58:47.0502 0x1ee8 drmkaud - ok
02:58:47.0505 0x1ee8 DsmSvc - ok
02:58:47.0508 0x1ee8 DsSvc - ok
02:58:47.0510 0x1ee8 DXGKrnl - ok
02:58:47.0512 0x1ee8 EapHost - ok
02:58:47.0516 0x1ee8 ebdrv - ok
02:58:47.0537 0x1ee8 EFS - ok
02:58:47.0540 0x1ee8 EhStorClass - ok
02:58:47.0562 0x1ee8 EhStorTcgDrv - ok
02:58:47.0566 0x1ee8 embeddedmode - ok
02:58:47.0578 0x1ee8 EntAppSvc - ok
02:58:47.0580 0x1ee8 ErrDev - ok
02:58:47.0584 0x1ee8 EventSystem - ok
02:58:47.0586 0x1ee8 exfat - ok
02:58:47.0588 0x1ee8 fastfat - ok
02:58:47.0597 0x1ee8 Fax - ok
02:58:47.0600 0x1ee8 fdc - ok
02:58:47.0602 0x1ee8 fdPHost - ok
02:58:47.0604 0x1ee8 FDResPub - ok
02:58:47.0622 0x1ee8 fhsvc - ok
02:58:47.0641 0x1ee8 FileCrypt - ok
02:58:47.0644 0x1ee8 FileInfo - ok
02:58:47.0646 0x1ee8 Filetrace - ok
02:58:47.0653 0x1ee8 flpydisk - ok
02:58:47.0655 0x1ee8 FltMgr - ok
02:58:47.0665 0x1ee8 FontCache - ok
02:58:47.0715 0x1ee8 FontCache3.0.0.0 - ok
02:58:47.0718 0x1ee8 FrameServer - ok
02:58:47.0720 0x1ee8 FsDepends - ok
02:58:47.0722 0x1ee8 Fs_Rec - ok
02:58:47.0733 0x1ee8 fvevol - ok
02:58:47.0736 0x1ee8 gencounter - ok
02:58:47.0739 0x1ee8 genericusbfn - ok
02:58:47.0817 0x1ee8 [ CBD39E74C61C3A3EF695DB25792F32E6, 95454F245DB818227BFE92EBA927A68FA78FB87E7BF5C28761046FF36C56CF32 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
02:58:47.0838 0x1ee8 GfExperienceService - ok
02:58:47.0850 0x1ee8 GPIOClx0101 - ok
02:58:47.0864 0x1ee8 gpsvc - ok
02:58:47.0867 0x1ee8 GpuEnergyDrv - ok
02:58:47.0869 0x1ee8 HDAudBus - ok
02:58:47.0871 0x1ee8 HidBatt - ok
02:58:47.0873 0x1ee8 HidBth - ok
02:58:47.0876 0x1ee8 hidi2c - ok
02:58:47.0878 0x1ee8 hidinterrupt - ok
02:58:47.0880 0x1ee8 HidIr - ok
02:58:47.0900 0x1ee8 hidserv - ok
02:58:47.0927 0x1ee8 HidUsb - ok
02:58:47.0941 0x1ee8 HomeGroupListener - ok
02:58:47.0954 0x1ee8 HomeGroupProvider - ok
02:58:47.0958 0x1ee8 HpSAMD - ok
02:58:47.0971 0x1ee8 HTTP - ok
02:58:47.0986 0x1ee8 HvHost - ok
02:58:48.0008 0x1ee8 hvservice - ok
02:58:48.0011 0x1ee8 hwpolicy - ok
02:58:48.0013 0x1ee8 hyperkbd - ok
02:58:48.0027 0x1ee8 i8042prt - ok
02:58:48.0029 0x1ee8 iagpio - ok
02:58:48.0031 0x1ee8 iai2c - ok
02:58:48.0033 0x1ee8 iaLPSS2i_GPIO2 - ok
02:58:48.0035 0x1ee8 iaLPSS2i_I2C - ok
02:58:48.0037 0x1ee8 iaLPSSi_GPIO - ok
02:58:48.0039 0x1ee8 iaLPSSi_I2C - ok
02:58:48.0063 0x1ee8 [ 47813F2DB651B54F1D3B44848E6CB4F9, 85FD9CEE050C5564EA4665B9B99B58E713217D8CBB5B85A075CA8C0C23D50388 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
02:58:48.0077 0x1ee8 iaStorA - ok
02:58:48.0081 0x1ee8 iaStorAV - ok
02:58:48.0083 0x1ee8 iaStorV - ok
02:58:48.0085 0x1ee8 ibbus - ok
02:58:48.0098 0x1ee8 icssvc - ok
02:58:48.0102 0x1ee8 IKEEXT - ok
02:58:48.0108 0x1ee8 IndirectKmd - ok
02:58:48.0161 0x1ee8 [ DDA8E5AD97231AB50B81FED04C28F64C, 5C9E8F7CC45A9AE7FF12A02641562E271D84894DFA7C50218AC2AAA298251B60 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
02:58:48.0189 0x1ee8 Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
02:58:48.0189 0x1ee8 Detect skipped due to KSN trusted
02:58:48.0189 0x1ee8 Intel(R) Capability Licensing Service Interface - ok
02:58:48.0209 0x1ee8 [ 86FE509640D77FB0998FC8B1FF5523C6, 13E895DEB9B84379251699D7E52C5E3FD888994425DE01B6C4634F9E959D5584 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
02:58:48.0225 0x1ee8 Intel(R) Capability Licensing Service TCP IP Interface - ok
02:58:48.0274 0x1ee8 [ EE65488B7294FBCB113EAC9FD492345C, D1D6B22CD94324387171B188D295AA716900654DA1DC9F3DC18D0CD528F2BBEA ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
02:58:48.0297 0x1ee8 Intel(R) ME Service - ok
02:58:48.0315 0x1ee8 intelide - ok
02:58:48.0319 0x1ee8 intelpep - ok
02:58:48.0322 0x1ee8 intelppm - ok
02:58:48.0334 0x1ee8 iorate - ok
02:58:48.0344 0x1ee8 IpFilterDriver - ok
02:58:48.0372 0x1ee8 iphlpsvc - ok
02:58:48.0382 0x1ee8 IPMIDRV - ok
02:58:48.0386 0x1ee8 IPNAT - ok
02:58:48.0389 0x1ee8 irda - ok
02:58:48.0393 0x1ee8 IRENUM - ok
02:58:48.0405 0x1ee8 irmon - ok
02:58:48.0416 0x1ee8 isapnp - ok
02:58:48.0420 0x1ee8 iScsiPrt - ok
02:58:48.0442 0x1ee8 [ BF5D3A2624177C413680DEF19A465AF8, B9909D3E6CB6F9971293116387865AD15CB9D47513C7FAA9C36BE4D2847A41EB ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
02:58:48.0454 0x1ee8 jhi_service - ok
02:58:48.0467 0x1ee8 kbdclass - ok
02:58:48.0471 0x1ee8 kbdhid - ok
02:58:48.0484 0x1ee8 kdnic - ok
02:58:48.0487 0x1ee8 KeyIso - ok
02:58:48.0499 0x1ee8 KSecDD - ok
02:58:48.0508 0x1ee8 KSecPkg - ok
02:58:48.0510 0x1ee8 ksthunk - ok
02:58:48.0522 0x1ee8 KtmRm - ok
02:58:48.0532 0x1ee8 LanmanServer - ok
02:58:48.0546 0x1ee8 LanmanWorkstation - ok
02:58:48.0549 0x1ee8 lfsvc - ok
02:58:48.0552 0x1ee8 LicenseManager - ok
02:58:48.0555 0x1ee8 lltdio - ok
02:58:48.0557 0x1ee8 lltdsvc - ok
02:58:48.0569 0x1ee8 lmhosts - ok
02:58:48.0589 0x1ee8 [ 41686112986A43CFF8CE1EC2A575D6F9, 998E0F4809EE6F21A6ECDADA2CC85CB1A78FDF6AFB88F352C06F69A12E059D3C ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
02:58:48.0600 0x1ee8 LMS - ok
02:58:48.0603 0x1ee8 LSI_SAS - ok
02:58:48.0605 0x1ee8 LSI_SAS2i - ok
02:58:48.0607 0x1ee8 LSI_SAS3i - ok
02:58:48.0610 0x1ee8 LSI_SSS - ok
02:58:48.0621 0x1ee8 LSM - ok
02:58:48.0623 0x1ee8 luafv - ok
02:58:48.0627 0x1ee8 MapsBroker - ok
02:58:48.0646 0x1ee8 [ 47701ECA633574E122687693B5C5D35C, 1DB12767462347504956450FAD0D90B6E682E2E8959A6C5DF3792C3C3DA289B1 ] mbamchameleon C:\WINDOWS\system32\drivers\mbamchameleon.sys
02:58:48.0653 0x1ee8 mbamchameleon - ok
02:58:48.0655 0x1ee8 megasas - ok
02:58:48.0676 0x1ee8 megasas2i - ok
02:58:48.0678 0x1ee8 megasr - ok
02:58:48.0686 0x1ee8 [ 2BB3EAE2EA641515D4B205CAB29E1624, D3F18EE393EB1B0F919484281269A3C55A092D023E62C59D74CB63A55612024B ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
02:58:48.0692 0x1ee8 MEIx64 - ok
02:58:48.0695 0x1ee8 MessagingService - ok
02:58:48.0698 0x1ee8 mlx4_bus - ok
02:58:48.0699 0x1ee8 MMCSS - ok
02:58:48.0701 0x1ee8 Modem - ok
02:58:48.0708 0x1ee8 monitor - ok
02:58:48.0711 0x1ee8 mouclass - ok
02:58:48.0713 0x1ee8 mouhid - ok
02:58:48.0715 0x1ee8 mountmgr - ok
02:58:48.0744 0x1ee8 [ 6F607DE20B98EA056E60319915ADD541, 522E326441EBFE726345ACD36E8DA2BB26849B3350A16463345D1E137CBEE3DF ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
02:58:48.0752 0x1ee8 MozillaMaintenance - ok
02:58:48.0754 0x1ee8 mpsdrv - ok
02:58:48.0765 0x1ee8 MpsSvc - ok
02:58:48.0779 0x1ee8 MQAC - ok
02:58:48.0781 0x1ee8 MRxDAV - ok
02:58:48.0784 0x1ee8 mrxsmb - ok
02:58:48.0795 0x1ee8 mrxsmb10 - ok
02:58:48.0798 0x1ee8 mrxsmb20 - ok
02:58:48.0810 0x1ee8 MsBridge - ok
02:58:48.0823 0x1ee8 MSDTC - ok
02:58:48.0827 0x1ee8 Msfs - ok
02:58:48.0830 0x1ee8 msgpiowin32 - ok
02:58:48.0833 0x1ee8 mshidkmdf - ok
02:58:48.0835 0x1ee8 mshidumdf - ok
02:58:48.0837 0x1ee8 msisadrv - ok
02:58:48.0848 0x1ee8 MSiSCSI - ok
02:58:48.0851 0x1ee8 msiserver - ok
02:58:48.0853 0x1ee8 MSKSSRV - ok
02:58:48.0855 0x1ee8 MsLldp - ok
02:58:48.0864 0x1ee8 MSMQ - ok
02:58:48.0866 0x1ee8 MSPCLOCK - ok
02:58:48.0868 0x1ee8 MSPQM - ok
02:58:48.0869 0x1ee8 MsRPC - ok
02:58:48.0873 0x1ee8 mssmbios - ok
02:58:48.0875 0x1ee8 MSTEE - ok
02:58:48.0877 0x1ee8 MTConfig - ok
02:58:48.0879 0x1ee8 Mup - ok
02:58:48.0881 0x1ee8 mvumis - ok
02:58:48.0894 0x1ee8 NativeWifiP - ok
02:58:48.0897 0x1ee8 NcaSvc - ok
02:58:48.0907 0x1ee8 NcbService - ok
02:58:48.0909 0x1ee8 NcdAutoSetup - ok
02:58:48.0911 0x1ee8 ndfltr - ok
02:58:48.0913 0x1ee8 NDIS - ok
02:58:48.0915 0x1ee8 NdisCap - ok
02:58:48.0926 0x1ee8 NdisImPlatform - ok
02:58:48.0928 0x1ee8 NdisTapi - ok
02:58:48.0929 0x1ee8 Ndisuio - ok
02:58:48.0931 0x1ee8 NdisVirtualBus - ok
02:58:48.0933 0x1ee8 NdisWan - ok
02:58:48.0935 0x1ee8 ndiswanlegacy - ok
02:58:48.0938 0x1ee8 ndproxy - ok
02:58:48.0940 0x1ee8 Ndu - ok
02:58:48.0943 0x1ee8 NetAdapterCx - ok
02:58:48.0944 0x1ee8 NetBIOS - ok
02:58:48.0947 0x1ee8 NetBT - ok
02:58:48.0949 0x1ee8 Netlogon - ok
02:58:48.0953 0x1ee8 Netman - ok
02:58:48.0964 0x1ee8 NetMsmqActivator - ok
02:58:48.0966 0x1ee8 NetPipeActivator - ok
02:58:48.0968 0x1ee8 netprofm - ok
02:58:48.0984 0x1ee8 NetSetupSvc - ok
02:58:48.0985 0x1ee8 NetTcpActivator - ok
02:58:48.0987 0x1ee8 NetTcpPortSharing - ok
02:58:49.0000 0x1ee8 NgcCtnrSvc - ok
02:58:49.0012 0x1ee8 NgcSvc - ok
02:58:49.0014 0x1ee8 NlaSvc - ok
02:58:49.0016 0x1ee8 Npfs - ok
02:58:49.0019 0x1ee8 npsvctrig - ok
02:58:49.0021 0x1ee8 nsi - ok
02:58:49.0023 0x1ee8 nsiproxy - ok
02:58:49.0032 0x1ee8 NTFS - ok
02:58:49.0034 0x1ee8 Null - ok
02:58:49.0055 0x1ee8 [ 04936C52B2FF72BB777EEE23FFFED7E0, 5431280DB9897E2A7DD5F496BC6EA5A346C520455072F05235455EB14CE040A0 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
02:58:49.0064 0x1ee8 NVHDA - ok
02:58:49.0355 0x1ee8 [ 4D56E475D32437ECF663CE944D7E0D3F, 22F4E20D066A750ECC1C2566A0D93FE059CA16CF8A0D26002A1B721E26D443D7 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nvhdcwu.inf_amd64_66cd0bfdc007680b\nvlddmkm.sys
02:58:49.0555 0x1ee8 nvlddmkm - ok
02:58:49.0652 0x1ee8 [ 855093AFA0B795914D6DD5EF4796D38C, A19B94449DBA50BCC2C09D42DEA1BF29CEF3C79B8F7F384904189A579AAA85A0 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
02:58:49.0682 0x1ee8 NvNetworkService - ok
02:58:49.0691 0x1ee8 nvraid - ok
02:58:49.0694 0x1ee8 nvstor - ok
02:58:49.0730 0x1ee8 [ BD96CA245DA2933BB68605D0C2075A72, E406CD97FA1A640C1C5FE01B360A0A9DED6E696F2765E395C16AAFF59F24B7B4 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
02:58:49.0735 0x1ee8 NvStreamKms - ok
02:58:49.0944 0x1ee8 [ CF27CDA72455B4A7853ED98CFC57218A, D66C3AECF8AAE38ED2DAFF9ABB38FE0301A85375250A8CDEF50F68DECE8BBC64 ] NvStreamNetworkSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
02:58:50.0036 0x1ee8 NvStreamNetworkSvc - ok
02:58:50.0145 0x1ee8 [ 40BA84AD3348573609095D8F3FD2DA9F, FF68F2352AFCB8C278A2E704F3E9DCC4393299DEAECD9ACF96F2D7FD9830EDF1 ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
02:58:50.0216 0x1ee8 NvStreamSvc - ok
02:58:50.0236 0x1ee8 [ 64E8275CEAD43D3CA8E3A311B2F4B64A, 99E683890B9AF3243100B387317760B5F91745EF9F7FF2ABA2DC7B6551A6EAB6 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
02:58:50.0241 0x1ee8 nvvad_WaveExtensible - ok
02:58:50.0258 0x1ee8 OneSyncSvc - ok
02:58:50.0392 0x1ee8 [ 3E498CE04DD40C60769854DF2CE8D21D, 28B9331787FE598A79E40DA839B022D353280BE0E8F0D20CE4AAB6284866DE48 ] Origin Client Service D:\Spiele\Origin\OriginClientService.exe
02:58:50.0426 0x1ee8 Origin Client Service - ok
02:58:50.0475 0x1ee8 [ B66980E730FEF1E31BE39B09F55514A1, 756F7695AB112FB2FEBA905F5F9E7C9435823195DE164AF60071457BC047535E ] Origin Web Helper Service D:\Spiele\Origin\OriginWebHelperService.exe
02:58:50.0509 0x1ee8 Origin Web Helper Service - ok
02:58:50.0528 0x1ee8 p2pimsvc - ok
02:58:50.0536 0x1ee8 p2psvc - ok
02:58:50.0542 0x1ee8 Parport - ok
02:58:50.0548 0x1ee8 partmgr - ok
02:58:50.0564 0x1ee8 PcaSvc - ok
02:58:50.0578 0x1ee8 pci - ok
02:58:50.0599 0x1ee8 pciide - ok
02:58:50.0601 0x1ee8 pcmcia - ok
02:58:50.0603 0x1ee8 pcw - ok
02:58:50.0611 0x1ee8 pdc - ok
02:58:50.0619 0x1ee8 PEAUTH - ok
02:58:50.0622 0x1ee8 percsas2i - ok
02:58:50.0624 0x1ee8 percsas3i - ok
02:58:50.0658 0x1ee8 PerfHost - ok
02:58:50.0672 0x1ee8 PhoneSvc - ok
02:58:50.0689 0x1ee8 PimIndexMaintenanceSvc - ok
02:58:50.0692 0x1ee8 pla - ok
02:58:50.0700 0x1ee8 PlugPlay - ok
02:58:50.0702 0x1ee8 PNRPAutoReg - ok
02:58:50.0704 0x1ee8 PNRPsvc - ok
02:58:50.0709 0x1ee8 PolicyAgent - ok
02:58:50.0712 0x1ee8 Power - ok
02:58:50.0714 0x1ee8 PptpMiniport - ok
02:58:51.0090 0x1ee8 [ 77ABF70C71922873BC160933571B3F83, 7FCFBB4B42E7A92FCF11388CD5B600EA79A7C134F13A8A88CF8DCD3DB96C3F5A ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
02:58:51.0194 0x1ee8 PrintNotify - ok
02:58:51.0217 0x1ee8 Processor - ok
02:58:51.0225 0x1ee8 ProfSvc - ok
02:58:51.0236 0x1ee8 Psched - ok
02:58:51.0247 0x1ee8 QWAVE - ok
02:58:51.0249 0x1ee8 QWAVEdrv - ok
02:58:51.0251 0x1ee8 RasAcd - ok
02:58:51.0281 0x1ee8 RasAgileVpn - ok
02:58:51.0289 0x1ee8 RasAuto - ok
02:58:51.0292 0x1ee8 Rasl2tp - ok
02:58:51.0302 0x1ee8 RasMan - ok
02:58:51.0304 0x1ee8 RasPppoe - ok
02:58:51.0306 0x1ee8 RasSstp - ok
02:58:51.0318 0x1ee8 rdbss - ok
02:58:51.0333 0x1ee8 rdpbus - ok
02:58:51.0335 0x1ee8 RDPDR - ok
02:58:51.0368 0x1ee8 RdpVideoMiniport - ok
02:58:51.0370 0x1ee8 rdyboost - ok
02:58:51.0372 0x1ee8 ReFSv1 - ok
02:58:51.0383 0x1ee8 RemoteAccess - ok
02:58:51.0386 0x1ee8 RemoteRegistry - ok
02:58:51.0397 0x1ee8 RetailDemo - ok
02:58:51.0406 0x1ee8 RmSvc - ok
02:58:51.0409 0x1ee8 RpcEptMapper - ok
02:58:51.0415 0x1ee8 RpcLocator - ok
02:58:51.0417 0x1ee8 RpcSs - ok
02:58:51.0419 0x1ee8 rspndr - ok
02:58:51.0446 0x1ee8 [ 5E0A1D70E4B0EBCFF68DCBBDF0BBBC13, 2DA2979A1AE8D6BA43F3E556C57342CF7D4EAFEC01D12E0D4C32368EBA74B79C ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
02:58:51.0464 0x1ee8 rt640x64 - ok
02:58:51.0487 0x1ee8 s3cap - ok
02:58:51.0490 0x1ee8 SamSs - ok
02:58:51.0493 0x1ee8 sbp2port - ok
02:58:51.0515 0x1ee8 SCardSvr - ok
02:58:51.0540 0x1ee8 ScDeviceEnum - ok
02:58:51.0563 0x1ee8 scfilter - ok
02:58:51.0568 0x1ee8 Schedule - ok
02:58:51.0572 0x1ee8 scmbus - ok
02:58:51.0577 0x1ee8 scmdisk0101 - ok
02:58:51.0595 0x1ee8 SCPolicySvc - ok
02:58:51.0611 0x1ee8 sdbus - ok
02:58:51.0616 0x1ee8 SDRSVC - ok
02:58:51.0619 0x1ee8 sdstor - ok
02:58:51.0622 0x1ee8 seclogon - ok
02:58:51.0629 0x1ee8 SENS - ok
02:58:51.0640 0x1ee8 SensorDataService - ok
02:58:51.0652 0x1ee8 SensorService - ok
02:58:51.0656 0x1ee8 SensrSvc - ok
02:58:51.0659 0x1ee8 SerCx - ok
02:58:51.0661 0x1ee8 SerCx2 - ok
02:58:51.0664 0x1ee8 Serenum - ok
02:58:51.0667 0x1ee8 Serial - ok
02:58:51.0669 0x1ee8 sermouse - ok
02:58:51.0677 0x1ee8 SessionEnv - ok
02:58:51.0682 0x1ee8 sfloppy - ok
02:58:51.0697 0x1ee8 SharedAccess - ok
02:58:51.0700 0x1ee8 ShellHWDetection - ok
02:58:51.0721 0x1ee8 shpamsvc - ok
02:58:51.0723 0x1ee8 SiSRaid2 - ok
02:58:51.0726 0x1ee8 SiSRaid4 - ok
02:58:51.0740 0x1ee8 smphost - ok
02:58:51.0751 0x1ee8 SmsRouter - ok
02:58:51.0756 0x1ee8 SNMPTRAP - ok
02:58:51.0777 0x1ee8 spaceport - ok
02:58:51.0779 0x1ee8 SpbCx - ok
02:58:51.0787 0x1ee8 Spooler - ok
02:58:51.0806 0x1ee8 sppsvc - ok
02:58:51.0808 0x1ee8 srv - ok
02:58:51.0821 0x1ee8 srv2 - ok
02:58:51.0824 0x1ee8 srvnet - ok
02:58:51.0827 0x1ee8 SSDPSRV - ok
02:58:51.0841 0x1ee8 SstpSvc - ok
02:58:51.0854 0x1ee8 StateRepository - ok
02:58:51.0934 0x1ee8 [ 5CBCEB3FF7C232ACC8891C8197BF3353, B1FE57C61E62B1FEC81B219551DAD68DC5DF17FC1603CDC0CBA097A3E687A027 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
02:58:51.0960 0x1ee8 Steam Client Service - ok
02:58:51.0964 0x1ee8 stexstor - ok
02:58:51.0996 0x1ee8 [ A73F13903345464F04D463B84890A271, F22A088D94418420CA3943D34CB233B82B36A6A66BB36000A44726244D794AFF ] STHDA C:\WINDOWS\system32\DRIVERS\stwrt64.sys
02:58:52.0017 0x1ee8 STHDA - ok
02:58:52.0026 0x1ee8 stisvc - ok
02:58:52.0041 0x1ee8 storahci - ok
02:58:52.0044 0x1ee8 storflt - ok
02:58:52.0056 0x1ee8 stornvme - ok
02:58:52.0060 0x1ee8 storqosflt - ok
02:58:52.0062 0x1ee8 StorSvc - ok
02:58:52.0064 0x1ee8 storufs - ok
02:58:52.0066 0x1ee8 storvsc - ok
02:58:52.0068 0x1ee8 svsvc - ok
02:58:52.0070 0x1ee8 swenum - ok
02:58:52.0072 0x1ee8 swprv - ok
02:58:52.0095 0x1ee8 Synth3dVsc - ok
02:58:52.0101 0x1ee8 SysMain - ok
02:58:52.0104 0x1ee8 SystemEventsBroker - ok
02:58:52.0107 0x1ee8 TabletInputService - ok
02:58:52.0109 0x1ee8 TapiSrv - ok
02:58:52.0121 0x1ee8 Tcpip - ok
02:58:52.0123 0x1ee8 Tcpip6 - ok
02:58:52.0136 0x1ee8 tcpipreg - ok
02:58:52.0140 0x1ee8 tdx - ok
02:58:52.0142 0x1ee8 terminpt - ok
02:58:52.0146 0x1ee8 TermService - ok
02:58:52.0157 0x1ee8 Themes - ok
02:58:52.0175 0x1ee8 TieringEngineService - ok
02:58:52.0178 0x1ee8 tiledatamodelsvc - ok
02:58:52.0181 0x1ee8 TimeBrokerSvc - ok
02:58:52.0191 0x1ee8 TPM - ok
02:58:52.0194 0x1ee8 TrkWks - ok
02:58:52.0212 0x1ee8 TrustedInstaller - ok
02:58:52.0215 0x1ee8 tsusbflt - ok
02:58:52.0218 0x1ee8 TsUsbGD - ok
02:58:52.0220 0x1ee8 tunnel - ok
02:58:52.0244 0x1ee8 tzautoupdate - ok
02:58:52.0247 0x1ee8 UASPStor - ok
02:58:52.0249 0x1ee8 UcmCx0101 - ok
02:58:52.0252 0x1ee8 UcmTcpciCx0101 - ok
02:58:52.0254 0x1ee8 UcmUcsi - ok
02:58:52.0257 0x1ee8 Ucx01000 - ok
02:58:52.0259 0x1ee8 UdeCx - ok
02:58:52.0261 0x1ee8 udfs - ok
02:58:52.0263 0x1ee8 UEFI - ok
02:58:52.0265 0x1ee8 Ufx01000 - ok
02:58:52.0267 0x1ee8 UfxChipidea - ok
02:58:52.0269 0x1ee8 ufxsynopsys - ok
02:58:52.0274 0x1ee8 UI0Detect - ok
02:58:52.0277 0x1ee8 umbus - ok
02:58:52.0278 0x1ee8 UmPass - ok
02:58:52.0281 0x1ee8 UmRdpService - ok
02:58:52.0289 0x1ee8 UnistoreSvc - ok
02:58:52.0294 0x1ee8 upnphost - ok
02:58:52.0296 0x1ee8 UrsChipidea - ok
02:58:52.0298 0x1ee8 UrsCx01000 - ok
02:58:52.0301 0x1ee8 UrsSynopsys - ok
02:58:52.0303 0x1ee8 usbccgp - ok
02:58:52.0307 0x1ee8 usbcir - ok
02:58:52.0309 0x1ee8 usbehci - ok
02:58:52.0311 0x1ee8 usbhub - ok
02:58:52.0314 0x1ee8 USBHUB3 - ok
02:58:52.0316 0x1ee8 usbohci - ok
02:58:52.0318 0x1ee8 usbprint - ok
02:58:52.0320 0x1ee8 usbser - ok
02:58:52.0322 0x1ee8 USBSTOR - ok
02:58:52.0324 0x1ee8 usbuhci - ok
02:58:52.0326 0x1ee8 USBXHCI - ok
02:58:52.0329 0x1ee8 UserDataSvc - ok
02:58:52.0339 0x1ee8 UserManager - ok
02:58:52.0342 0x1ee8 UsoSvc - ok
02:58:52.0344 0x1ee8 VaultSvc - ok
02:58:52.0346 0x1ee8 vdrvroot - ok
02:58:52.0356 0x1ee8 vds - ok
02:58:52.0358 0x1ee8 VerifierExt - ok
02:58:52.0370 0x1ee8 vhdmp - ok
02:58:52.0372 0x1ee8 vhf - ok
02:58:52.0375 0x1ee8 vmbus - ok
02:58:52.0377 0x1ee8 VMBusHID - ok
02:58:52.0379 0x1ee8 vmgid - ok
02:58:52.0390 0x1ee8 vmicguestinterface - ok
02:58:52.0393 0x1ee8 vmicheartbeat - ok
02:58:52.0395 0x1ee8 vmickvpexchange - ok
02:58:52.0403 0x1ee8 vmicrdv - ok
02:58:52.0405 0x1ee8 vmicshutdown - ok
02:58:52.0407 0x1ee8 vmictimesync - ok
02:58:52.0409 0x1ee8 vmicvmsession - ok
02:58:52.0411 0x1ee8 vmicvss - ok
02:58:52.0414 0x1ee8 volmgr - ok
02:58:52.0416 0x1ee8 volmgrx - ok
02:58:52.0418 0x1ee8 volsnap - ok
02:58:52.0420 0x1ee8 volume - ok
02:58:52.0431 0x1ee8 vpci - ok
02:58:52.0433 0x1ee8 vsmraid - ok
02:58:52.0436 0x1ee8 VSS - ok
02:58:52.0438 0x1ee8 VSTXRAID - ok
02:58:52.0441 0x1ee8 vwifibus - ok
02:58:52.0443 0x1ee8 vwififlt - ok
02:58:52.0445 0x1ee8 vwifimp - ok
02:58:52.0448 0x1ee8 W32Time - ok
02:58:52.0465 0x1ee8 w3logsvc - ok
02:58:52.0467 0x1ee8 W3SVC - ok
02:58:52.0470 0x1ee8 WacomPen - ok
02:58:52.0473 0x1ee8 WalletService - ok
02:58:52.0475 0x1ee8 wanarp - ok
02:58:52.0477 0x1ee8 wanarpv6 - ok
02:58:52.0479 0x1ee8 WAS - ok
02:58:52.0487 0x1ee8 wbengine - ok
02:58:52.0494 0x1ee8 WbioSrvc - ok
02:58:52.0497 0x1ee8 wcifs - ok
02:58:52.0499 0x1ee8 Wcmsvc - ok
02:58:52.0501 0x1ee8 wcncsvc - ok
02:58:52.0504 0x1ee8 wcnfs - ok
02:58:52.0506 0x1ee8 WdBoot - ok
02:58:52.0508 0x1ee8 Wdf01000 - ok
02:58:52.0510 0x1ee8 WdFilter - ok
02:58:52.0513 0x1ee8 WdiServiceHost - ok
02:58:52.0515 0x1ee8 WdiSystemHost - ok
02:58:52.0517 0x1ee8 wdiwifi - ok
02:58:52.0520 0x1ee8 WdNisDrv - ok
02:58:52.0536 0x1ee8 WdNisSvc - ok
02:58:52.0539 0x1ee8 WebClient - ok
02:58:52.0541 0x1ee8 Wecsvc - ok
02:58:52.0543 0x1ee8 WEPHOSTSVC - ok
02:58:52.0551 0x1ee8 wercplsupport - ok
02:58:52.0553 0x1ee8 WerSvc - ok
02:58:52.0555 0x1ee8 WFPLWFS - ok
02:58:52.0558 0x1ee8 WiaRpc - ok
02:58:52.0560 0x1ee8 WIMMount - ok
02:58:52.0562 0x1ee8 WinDefend - ok
02:58:52.0567 0x1ee8 WindowsTrustedRT - ok
02:58:52.0569 0x1ee8 WindowsTrustedRTProxy - ok
02:58:52.0571 0x1ee8 WinHttpAutoProxySvc - ok
02:58:52.0573 0x1ee8 WinMad - ok
02:58:52.0584 0x1ee8 Winmgmt - ok
02:58:52.0623 0x1ee8 WinRM - ok
02:58:52.0628 0x1ee8 WINUSB - ok
02:58:52.0630 0x1ee8 WinVerbs - ok
02:58:52.0638 0x1ee8 wisvc - ok
02:58:52.0641 0x1ee8 WlanSvc - ok
02:58:52.0645 0x1ee8 wlidsvc - ok
02:58:52.0647 0x1ee8 WmiAcpi - ok
02:58:52.0651 0x1ee8 wmiApSrv - ok
02:58:52.0663 0x1ee8 WMPNetworkSvc - ok
02:58:52.0673 0x1ee8 Wof - ok
02:58:52.0682 0x1ee8 workfolderssvc - ok
02:58:52.0691 0x1ee8 WPDBusEnum - ok
02:58:52.0694 0x1ee8 WpdUpFltr - ok
02:58:52.0699 0x1ee8 WpnService - ok
02:58:52.0701 0x1ee8 WpnUserService - ok
02:58:52.0706 0x1ee8 ws2ifsl - ok
02:58:52.0709 0x1ee8 wscsvc - ok
02:58:52.0711 0x1ee8 WSearch - ok
02:58:52.0715 0x1ee8 wuauserv - ok
02:58:52.0717 0x1ee8 WudfPf - ok
02:58:52.0720 0x1ee8 WUDFRd - ok
02:58:52.0722 0x1ee8 wudfsvc - ok
02:58:52.0725 0x1ee8 WUDFWpdFs - ok
02:58:52.0727 0x1ee8 WUDFWpdMtp - ok
02:58:52.0730 0x1ee8 WwanSvc - ok
02:58:52.0733 0x1ee8 XblAuthManager - ok
02:58:52.0737 0x1ee8 XblGameSave - ok
02:58:52.0740 0x1ee8 xboxgip - ok
02:58:52.0743 0x1ee8 XboxNetApiSvc - ok
02:58:52.0763 0x1ee8 xinputhid - ok
02:58:52.0774 0x1ee8 xusb22 - ok
02:58:52.0775 0x1ee8 ================ Scan global ===============================
02:58:52.0803 0x1ee8 [ Global ] - ok
02:58:52.0804 0x1ee8 ================ Scan MBR ==================================
02:58:52.0812 0x1ee8 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
02:58:52.0895 0x1ee8 \Device\Harddisk0\DR0 - ok
02:58:52.0895 0x1ee8 ================ Scan VBR ==================================
02:58:52.0917 0x1ee8 [ CFEDCE7572C244E6EB9B346351E5A4FD ] \Device\Harddisk0\DR0\Partition1
02:58:52.0918 0x1ee8 \Device\Harddisk0\DR0\Partition1 - ok
02:58:52.0923 0x1ee8 [ A1A1CC4BA4AE1C51FC0245E9B1587FFB ] \Device\Harddisk0\DR0\Partition2
02:58:52.0924 0x1ee8 \Device\Harddisk0\DR0\Partition2 - ok
02:58:52.0932 0x1ee8 [ 333A0D643E7F1D2CD94334BCFC57AE03 ] \Device\Harddisk0\DR0\Partition3
02:58:52.0934 0x1ee8 \Device\Harddisk0\DR0\Partition3 - ok
02:58:52.0948 0x1ee8 [ 7EC7217F8D6213120A2CDB876F1FDEB3 ] \Device\Harddisk0\DR0\Partition4
02:58:52.0950 0x1ee8 \Device\Harddisk0\DR0\Partition4 - ok
02:58:52.0962 0x1ee8 [ 8D10DDACB502CFB061ECE031EDA46539 ] \Device\Harddisk0\DR0\Partition5
02:58:52.0964 0x1ee8 \Device\Harddisk0\DR0\Partition5 - ok
02:58:52.0964 0x1ee8 ================ Scan generic autorun ======================
02:58:53.0052 0x1ee8 [ F4CD6DA32F5FA8DF305C22A444DD7B5D, E8978FDB71597A4501429787E4729555C47292BD40AFDA2487C6D88DFDBD806C ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
02:58:53.0103 0x1ee8 NvBackend - ok
02:58:53.0143 0x1ee8 SysTrayApp - ok
02:58:53.0164 0x1ee8 [ 96A1D93D16F959C6F5A63E749A9F2EF7, 9EDD4EEC5C625ECF4A1C82318ED6B74404E63A3D43312B53E4F627D76D47658C ] C:\Program Files\IDT\WDM\beats64.exe
02:58:53.0203 0x1ee8 BeatsOSDApp - detected UnsignedFile.Multi.Generic ( 1 )
02:58:53.0203 0x1ee8 Detect skipped due to KSN trusted
02:58:53.0203 0x1ee8 BeatsOSDApp - ok
02:58:53.0230 0x1ee8 [ 258E2CD2C4984A977106C9EF7CA8AF69, D8F6409D5F5782CC27D159D18E914A3DB59D8644D7017CA6F84F0CF30E95174C ] C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
02:58:53.0244 0x1ee8 Avira SystrayStartTrigger - ok
02:58:53.0286 0x1ee8 [ 1E0029B9936F42C86138EADB5C27439E, 0A57C0DF2E2995C45FB92D1229FFAA1493748F39F01FB53F9559C5AFB5C1CA13 ] C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
02:58:53.0310 0x1ee8 avgnt - ok
02:58:53.0314 0x1ee8 USB3MON - ok
02:58:53.0353 0x1ee8 OneDriveSetup - ok
02:58:53.0354 0x1ee8 OneDriveSetup - ok
02:58:53.0489 0x1ee8 [ F0B461FB820595E8BAF1161F55BE3E74, B8022060E7280DC568BFC230CA99D37C09092152D0CEE91B08401ACD725E82A2 ] C:\Users\XXXX\AppData\Roaming\Spotify\SpotifyWebHelper.exe
02:58:53.0516 0x1ee8 Spotify Web Helper - ok
02:58:53.0519 0x1ee8 OneDriveSetup - ok
02:58:53.0522 0x1ee8 AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\Antivirus\WindowsSecurityCenter.exe ( 15.0.25.151 ), 0x41000 ( enabled : updated )
02:58:53.0523 0x1ee8 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x62100 ( disabled : updated )
02:58:53.0524 0x1ee8 Win FW state via NFP2: enabled ( trusted )
02:58:53.0598 0x1ee8 ============================================================
02:58:53.0598 0x1ee8 Scan finished
02:58:53.0598 0x1ee8 ============================================================
02:58:53.0603 0x1d98 Detected object count: 0
02:58:53.0603 0x1d98 Actual detected object count: 0 |