Hallo Matthias,
Vielen Dank für deine schnelle Antwort!
Hier die Logdatei von TDSS-Killer: Code:
22:53:58.0667 0x0e7c TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02
22:53:58.0667 0x0e7c UEFI system
22:54:20.0689 0x0e7c ============================================================
22:54:20.0689 0x0e7c Current date / time: 2017/05/15 22:54:20.0689
22:54:20.0692 0x0e7c SystemInfo:
22:54:20.0692 0x0e7c
22:54:20.0692 0x0e7c OS Version: 10.0.14393 ServicePack: 0.0
22:54:20.0692 0x0e7c Product type: Workstation
22:54:20.0692 0x0e7c ComputerName: TISCHDECKE
22:54:20.0692 0x0e7c UserName: Mara
22:54:20.0692 0x0e7c Windows directory: C:\WINDOWS
22:54:20.0692 0x0e7c System windows directory: C:\WINDOWS
22:54:20.0692 0x0e7c Running under WOW64
22:54:20.0692 0x0e7c Processor architecture: Intel x64
22:54:20.0692 0x0e7c Number of processors: 4
22:54:20.0692 0x0e7c Page size: 0x1000
22:54:20.0692 0x0e7c Boot type: Normal boot
22:54:20.0692 0x0e7c CodeIntegrityOptions = 0x00000001
22:54:20.0692 0x0e7c ============================================================
22:54:20.0766 0x0e7c KLMD registered as C:\WINDOWS\system32\drivers\22816441.sys
22:54:20.0766 0x0e7c KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.1198, osProperties = 0x19
22:54:21.0275 0x0e7c System UUID: {4A8C7568-CCBF-1B0E-71A5-D49B197F7271}
22:54:21.0978 0x0e7c Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:54:21.0981 0x0e7c Drive \Device\Harddisk1\DR1 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:54:21.0988 0x0e7c ============================================================
22:54:21.0988 0x0e7c \Device\Harddisk0\DR0:
22:54:21.0988 0x0e7c MBR partitions:
22:54:21.0988 0x0e7c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x6CE00000
22:54:21.0988 0x0e7c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x6CE00800, BlocksNum 0x7906000
22:54:21.0988 0x0e7c \Device\Harddisk1\DR1:
22:54:21.0988 0x0e7c GPT partitions:
22:54:21.0988 0x0e7c \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {73E6DCE4-0944-11E4-9A60-A82925405469}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xF9800
22:54:21.0988 0x0e7c \Device\Harddisk1\DR1\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {73E6DCE5-0944-11E4-9A60-A82925405469}, Name: EFI system partition, StartLBA 0xFA000, BlocksNum 0x32000
22:54:21.0988 0x0e7c \Device\Harddisk1\DR1\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {73E6DCE6-0944-11E4-9A60-A82925405469}, Name: Microsoft reserved partition, StartLBA 0x12C000, BlocksNum 0x40000
22:54:21.0988 0x0e7c \Device\Harddisk1\DR1\Partition4: GPT, TypeGUID: {8D7F0CC6-879E-47F6-A767-0ED8FD3B0659}, UniqueGUID: {73E6DCE7-0944-11E4-9A60-A82925405469}, Name: Basic data partition, StartLBA 0x16C000, BlocksNum 0x200000
22:54:21.0988 0x0e7c \Device\Harddisk1\DR1\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {73E6DCE8-0944-11E4-9A60-A82925405469}, Name: Basic data partition, StartLBA 0x36C000, BlocksNum 0xEA2E800
22:54:21.0988 0x0e7c \Device\Harddisk1\DR1\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {6D5E1163-5E97-402D-9F62-7256CCB4CA82}, Name: , StartLBA 0xED9A800, BlocksNum 0xE1000
22:54:21.0989 0x0e7c MBR partitions:
22:54:21.0989 0x0e7c ============================================================
22:54:21.0990 0x0e7c C: <-> \Device\Harddisk1\DR1\Partition5
22:54:22.0012 0x0e7c D: <-> \Device\Harddisk0\DR0\Partition1
22:54:22.0052 0x0e7c E: <-> \Device\Harddisk0\DR0\Partition2
22:54:22.0052 0x0e7c ============================================================
22:54:22.0052 0x0e7c Initialize success
22:54:22.0052 0x0e7c ============================================================
22:55:59.0941 0x0020 ============================================================
22:55:59.0941 0x0020 Scan started
22:55:59.0941 0x0020 Mode: Manual; SigCheck; TDLFS;
22:55:59.0941 0x0020 ============================================================
22:55:59.0941 0x0020 KSN ping started
22:56:00.0124 0x0020 KSN ping finished: true
22:56:01.0514 0x0020 ================ Scan system memory ========================
22:56:01.0514 0x0020 System memory - ok
22:56:01.0514 0x0020 ================ Scan services =============================
22:56:01.0558 0x0020 1394ohci - ok
22:56:01.0561 0x0020 3ware - ok
22:56:01.0564 0x0020 ACPI - ok
22:56:01.0567 0x0020 AcpiDev - ok
22:56:01.0571 0x0020 acpiex - ok
22:56:01.0573 0x0020 acpipagr - ok
22:56:01.0578 0x0020 AcpiPmi - ok
22:56:01.0581 0x0020 acpitime - ok
22:56:01.0588 0x0020 [ 8D6BA8E7676038A27FD4ECF12CC744B0, F5D59B764DCB4A06A51939533DC7B2391FD68E3979C48939C023A60DCE0D2101 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
22:56:01.0615 0x0020 AdobeARMservice - ok
22:56:01.0652 0x0020 [ E6A1D864EC90F4397DF5AB2633B34DD4, 05F1B7291EBDD9CA1D74649C0DAFCBE5F2CF93E92C5CA16A8AC10B6DF83101A0 ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
22:56:01.0668 0x0020 AdobeFlashPlayerUpdateSvc - ok
22:56:01.0673 0x0020 ADP80XX - ok
22:56:01.0680 0x0020 AFD - ok
22:56:01.0686 0x0020 ahcache - ok
22:56:01.0716 0x0020 [ 1CC3E547FE3DEC8272780F24F3059519, 72400F60D41239E9F2493DF71472704ECB006F5871E3CBB125DE2D0303051617 ] AHDDC2 C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
22:56:01.0755 0x0020 AHDDC2 - ok
22:56:01.0762 0x0020 AJRouter - ok
22:56:01.0766 0x0020 ALG - ok
22:56:01.0769 0x0020 AmdK8 - ok
22:56:01.0771 0x0020 AmdPPM - ok
22:56:01.0775 0x0020 amdsata - ok
22:56:01.0778 0x0020 amdsbs - ok
22:56:01.0782 0x0020 amdxata - ok
22:56:01.0789 0x0020 [ 4DE4BE679205B3A712562507AEE75227, 1C40F14A2BFFFB8E9646B57419D9F810A86D0DCD94F9DE9D9851D498F86F343E ] AMPPAL C:\WINDOWS\System32\drivers\AMPPAL.sys
22:56:01.0799 0x0020 AMPPAL - ok
22:56:01.0805 0x0020 [ 4DE4BE679205B3A712562507AEE75227, 1C40F14A2BFFFB8E9646B57419D9F810A86D0DCD94F9DE9D9851D498F86F343E ] AMPPALP C:\WINDOWS\system32\DRIVERS\amppal.sys
22:56:01.0815 0x0020 AMPPALP - ok
22:56:01.0819 0x0020 AppID - ok
22:56:01.0822 0x0020 AppIDSvc - ok
22:56:01.0825 0x0020 Appinfo - ok
22:56:01.0829 0x0020 applockerfltr - ok
22:56:01.0833 0x0020 AppReadiness - ok
22:56:01.0836 0x0020 AppXSvc - ok
22:56:01.0838 0x0020 arcsas - ok
22:56:01.0841 0x0020 AsyncMac - ok
22:56:01.0846 0x0020 atapi - ok
22:56:01.0849 0x0020 AudioEndpointBuilder - ok
22:56:01.0852 0x0020 Audiosrv - ok
22:56:01.0855 0x0020 AxInstSV - ok
22:56:01.0859 0x0020 b06bdrv - ok
22:56:01.0863 0x0020 BasicDisplay - ok
22:56:01.0866 0x0020 BasicRender - ok
22:56:01.0870 0x0020 bcmfn - ok
22:56:01.0874 0x0020 bcmfn2 - ok
22:56:01.0879 0x0020 BDESVC - ok
22:56:01.0882 0x0020 Beep - ok
22:56:01.0885 0x0020 BFE - ok
22:56:01.0888 0x0020 BITS - ok
22:56:01.0892 0x0020 bowser - ok
22:56:01.0896 0x0020 BrokerInfrastructure - ok
22:56:01.0899 0x0020 Browser - ok
22:56:01.0903 0x0020 BthA2DP - ok
22:56:01.0907 0x0020 BthAvrcpTg - ok
22:56:01.0912 0x0020 BthEnum - ok
22:56:01.0915 0x0020 BthHFEnum - ok
22:56:01.0919 0x0020 bthhfhid - ok
22:56:01.0921 0x0020 BthHFSrv - ok
22:56:01.0925 0x0020 BthLEEnum - ok
22:56:01.0929 0x0020 BTHMODEM - ok
22:56:01.0932 0x0020 BthPan - ok
22:56:01.0935 0x0020 BTHPORT - ok
22:56:01.0939 0x0020 bthserv - ok
22:56:01.0942 0x0020 BTHUSB - ok
22:56:01.0947 0x0020 buttonconverter - ok
22:56:01.0950 0x0020 CapImg - ok
22:56:01.0953 0x0020 cdfs - ok
22:56:01.0956 0x0020 CDPSvc - ok
22:56:01.0959 0x0020 CDPUserSvc - ok
22:56:01.0967 0x0020 cdrom - ok
22:56:01.0970 0x0020 CertPropSvc - ok
22:56:01.0973 0x0020 cht4iscsi - ok
22:56:01.0977 0x0020 cht4vbd - ok
22:56:01.0981 0x0020 circlass - ok
22:56:01.0984 0x0020 CLFS - ok
22:56:02.0052 0x0020 [ 6BB60E02F8017B55EF9B78E8802A0389, D854B240DB78558A8FD9F2A2D085224AB50B7C66163B03C55E0BF3EE2E16D4A1 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
22:56:02.0120 0x0020 ClickToRunSvc - ok
22:56:02.0130 0x0020 ClipSVC - ok
22:56:02.0133 0x0020 clreg - ok
22:56:02.0142 0x0020 CmBatt - ok
22:56:02.0147 0x0020 CNG - ok
22:56:02.0151 0x0020 cnghwassist - ok
22:56:02.0173 0x0020 CompositeBus - ok
22:56:02.0177 0x0020 COMSysApp - ok
22:56:02.0181 0x0020 condrv - ok
22:56:02.0184 0x0020 CoreMessagingRegistrar - ok
22:56:02.0221 0x0020 [ 75C568E62A2BD89A869C34119A66D19B, 2954F25E511947728FE50AA76ACECE0B6952D1984301027F499E2F3DAAEB65D3 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
22:56:02.0241 0x0020 cphs - ok
22:56:02.0246 0x0020 CryptSvc - ok
22:56:02.0257 0x0020 [ 67A51FEC3B0698D7CF029E9194FBDE0C, F09A6C484E3CAD59BCE20FFE207A647315F82D17A5450BCF9C86E854DE831DF2 ] CTService C:\Program Files (x86)\Cold Turkey\\CTService.exe
22:56:02.0273 0x0020 CTService - detected UnsignedFile.Multi.Generic ( 1 )
22:56:02.0423 0x0020 Detect skipped due to KSN trusted
22:56:02.0423 0x0020 CTService - ok
22:56:02.0429 0x0020 dam - ok
22:56:02.0438 0x0020 DcomLaunch - ok
22:56:02.0446 0x0020 DcpSvc - ok
22:56:02.0454 0x0020 defragsvc - ok
22:56:02.0460 0x0020 DeviceAssociationService - ok
22:56:02.0467 0x0020 DeviceInstall - ok
22:56:02.0472 0x0020 DevQueryBroker - ok
22:56:02.0475 0x0020 Dfsc - ok
22:56:02.0484 0x0020 [ 0F4A5D01156B948B54550375498B08A2, 1CAE3D744429A06E9C9EC46AC6B216AB68154EF8FACDD0721C47902B83820F56 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
22:56:02.0499 0x0020 dg_ssudbus - ok
22:56:02.0504 0x0020 Dhcp - ok
22:56:02.0508 0x0020 diagnosticshub.standardcollector.service - ok
22:56:02.0514 0x0020 DiagTrack - ok
22:56:02.0518 0x0020 disk - ok
22:56:02.0522 0x0020 DmEnrollmentSvc - ok
22:56:02.0527 0x0020 dmvsc - ok
22:56:02.0532 0x0020 dmwappushservice - ok
22:56:02.0535 0x0020 Dnscache - ok
22:56:02.0541 0x0020 dot3svc - ok
22:56:02.0545 0x0020 DPS - ok
22:56:02.0552 0x0020 drmkaud - ok
22:56:02.0555 0x0020 DsmSvc - ok
22:56:02.0559 0x0020 DsSvc - ok
22:56:02.0563 0x0020 DXGKrnl - ok
22:56:02.0566 0x0020 EapHost - ok
22:56:02.0569 0x0020 ebdrv - ok
22:56:02.0573 0x0020 EFS - ok
22:56:02.0576 0x0020 EhStorClass - ok
22:56:02.0581 0x0020 EhStorTcgDrv - ok
22:56:02.0583 0x0020 embeddedmode - ok
22:56:02.0587 0x0020 EntAppSvc - ok
22:56:02.0589 0x0020 ErrDev - ok
22:56:02.0606 0x0020 [ BF8362193CB83B5283BC5D24AA3D8DF3, 9A45520D624B101D18A434E63DB7EA6CC44F598EDA36B8A916BB76C1DBB0955C ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
22:56:02.0624 0x0020 ETD - ok
22:56:02.0634 0x0020 [ 06C67EE6E9E5DF0692BBE14437E56F3F, 9569B03031AE0CAC51AEF8B8CB8F8F2E717478B482AB4760711E1427C33A396D ] ETDService C:\Program Files\Elantech\ETDService.exe
22:56:02.0643 0x0020 ETDService - ok
22:56:02.0648 0x0020 [ C75C4769BBAE1397E1333D895C2DAE63, A066F6D6BCF25976EA16EC2077A0656C44952A3CB49C6A1A857482C8346E9D2D ] ETDSMBus C:\WINDOWS\System32\drivers\ETDSMBus.sys
22:56:02.0655 0x0020 ETDSMBus - ok
22:56:02.0661 0x0020 EventSystem - ok
22:56:02.0665 0x0020 exfat - ok
22:56:02.0668 0x0020 fastfat - ok
22:56:02.0671 0x0020 Fax - ok
22:56:02.0674 0x0020 fdc - ok
22:56:02.0678 0x0020 fdPHost - ok
22:56:02.0682 0x0020 FDResPub - ok
22:56:02.0684 0x0020 fhsvc - ok
22:56:02.0688 0x0020 FileCrypt - ok
22:56:02.0690 0x0020 FileInfo - ok
22:56:02.0694 0x0020 Filetrace - ok
22:56:02.0697 0x0020 flpydisk - ok
22:56:02.0700 0x0020 FltMgr - ok
22:56:02.0703 0x0020 FontCache - ok
22:56:02.0709 0x0020 FontCache3.0.0.0 - ok
22:56:02.0713 0x0020 FrameServer - ok
22:56:02.0716 0x0020 FsDepends - ok
22:56:02.0718 0x0020 Fs_Rec - ok
22:56:02.0722 0x0020 fvevol - ok
22:56:02.0725 0x0020 gencounter - ok
22:56:02.0729 0x0020 genericusbfn - ok
22:56:02.0732 0x0020 GPIOClx0101 - ok
22:56:02.0735 0x0020 gpsvc - ok
22:56:02.0738 0x0020 GpuEnergyDrv - ok
22:56:02.0742 0x0020 HDAudBus - ok
22:56:02.0746 0x0020 HidBatt - ok
22:56:02.0750 0x0020 HidBth - ok
22:56:02.0753 0x0020 hidi2c - ok
22:56:02.0756 0x0020 hidinterrupt - ok
22:56:02.0759 0x0020 HidIr - ok
22:56:02.0763 0x0020 hidserv - ok
22:56:02.0767 0x0020 HidUsb - ok
22:56:02.0770 0x0020 HomeGroupListener - ok
22:56:02.0773 0x0020 HomeGroupProvider - ok
22:56:02.0777 0x0020 HpSAMD - ok
22:56:02.0781 0x0020 HTTP - ok
22:56:02.0785 0x0020 HvHost - ok
22:56:02.0788 0x0020 hvservice - ok
22:56:02.0791 0x0020 hwpolicy - ok
22:56:02.0796 0x0020 hyperkbd - ok
22:56:02.0799 0x0020 i8042prt - ok
22:56:02.0802 0x0020 iagpio - ok
22:56:02.0805 0x0020 iai2c - ok
22:56:02.0808 0x0020 iaLPSS2i_GPIO2 - ok
22:56:02.0813 0x0020 iaLPSS2i_I2C - ok
22:56:02.0815 0x0020 iaLPSSi_GPIO - ok
22:56:02.0818 0x0020 iaLPSSi_I2C - ok
22:56:02.0833 0x0020 [ 9863EC0FB887C0AD0C3A20AC3BF91629, B695048C370CB91BB0CFF2E29641636225B23347B08F7E451FB91CF8B1A0120A ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
22:56:02.0853 0x0020 iaStorA - ok
22:56:02.0856 0x0020 iaStorAV - ok
22:56:02.0861 0x0020 [ E4B16F9770B0F04A1841C74368896870, 55A07A24686DEFB53158992F4490371D7BC6378692F353124599C9E653134236 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
22:56:02.0867 0x0020 IAStorDataMgrSvc - ok
22:56:02.0871 0x0020 iaStorV - ok
22:56:02.0873 0x0020 ibbus - ok
22:56:02.0877 0x0020 ibtsiva - ok
22:56:02.0887 0x0020 [ 17CF9460BCF23BB4F96EAE3E160D7DB9, 68ABB485CBFCC22B9A5A5847557424937E5001086AB30EE5A717B18EDB81DE18 ] ibtusb C:\WINDOWS\system32\DRIVERS\ibtusb.sys
22:56:02.0903 0x0020 ibtusb - ok
22:56:02.0910 0x0020 [ 83FF82FE209E7997067B375DAD6CF23D, E312DD068E51DBF96A8232D7D1C9F158652FDA23649655F1102928B320795091 ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
22:56:02.0919 0x0020 ICCS - ok
22:56:02.0923 0x0020 icssvc - ok
22:56:03.0053 0x0020 [ 658287D76E8D77C08AE98989F99B8948, DBA67B5772E1FE43ABDB3908A1CF86D76F2774BABC20359D2511F06A2A8CAC57 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
22:56:03.0199 0x0020 igfx - ok
22:56:03.0220 0x0020 [ A105AD05696D55E6E4F078ED850F6305, 8121A4226D2941EDD4809D516E7684E5C7164ADCF5AA4C8BC6620110625D3E8D ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
22:56:03.0238 0x0020 igfxCUIService2.0.0.0 - ok
22:56:03.0241 0x0020 IKEEXT - ok
22:56:03.0245 0x0020 IndirectKmd - ok
22:56:03.0250 0x0020 [ CF25067821BB89E87021E9493C178863, 1AA25378EFD977BC6CD9405A395FA2962770385FAB5A9A55FC95B5F6DFD8D1AE ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
22:56:03.0257 0x0020 intaud_WaveExtensible - ok
22:56:03.0334 0x0020 [ 07598029B8B7A18A49095010319E7056, A38FCAC718A11DF92C79E867934CB35825D67942A32C190F6A67230EB20B5878 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
22:56:03.0413 0x0020 IntcAzAudAddService - ok
22:56:03.0431 0x0020 [ E300D1E37B737ED14F7A08CD5604E5D9, 5C1135081E29D7F4A97D5CAA2C8FBE1DD04EC7A3D8E648E69F2AA9EBDD88EBBB ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
22:56:03.0448 0x0020 IntcDAud - ok
22:56:03.0469 0x0020 [ 9A6DEB5DDF7E29728F6FEA5092AFA3F2, 21C47A0490EBA302657EF30C560E4AF83777685FFE126DCCAC310163C47401D1 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
22:56:03.0491 0x0020 Intel(R) Capability Licensing Service TCP IP Interface - ok
22:56:03.0498 0x0020 [ A7AED4514E3E309AABF8237A8DD341A9, 59DC19773C0AA28B08FBB954B4F737EE5EE4D833D6EE12F7E3D901B244C5B1F9 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
22:56:03.0507 0x0020 Intel(R) ME Service - ok
22:56:03.0561 0x0020 [ D578C6D8C13E8107394A7CE89A433B6D, 5742000801697BEF0367896D328E14F13FD21E76D448E5551FDAAA1428E07EF3 ] IntelBCAsvc C:\Program Files\Intel\BCA\pabeSvc64.exe
22:56:03.0620 0x0020 IntelBCAsvc - ok
22:56:03.0628 0x0020 intelide - ok
22:56:03.0631 0x0020 intelpep - ok
22:56:03.0634 0x0020 intelppm - ok
22:56:03.0637 0x0020 iorate - ok
22:56:03.0640 0x0020 IpFilterDriver - ok
22:56:03.0644 0x0020 iphlpsvc - ok
22:56:03.0647 0x0020 IPMIDRV - ok
22:56:03.0650 0x0020 IPNAT - ok
22:56:03.0653 0x0020 irda - ok
22:56:03.0656 0x0020 IRENUM - ok
22:56:03.0660 0x0020 irmon - ok
22:56:03.0664 0x0020 isapnp - ok
22:56:03.0667 0x0020 iScsiPrt - ok
22:56:03.0673 0x0020 [ 622BF9C46A47CF17608C501320E8EFBD, 059F99D4306216324E100FCDAF02093B2CD662F2C6BE8565A4281E7760F8B575 ] iumsvc C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
22:56:03.0689 0x0020 iumsvc - ok
22:56:03.0694 0x0020 [ 2749D828991C160D1D8E7A06A0A95D93, 6F590E3A8F295D367A23938E062AEB0D904CDD8B8262B1EBB1208369587EA186 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
22:56:03.0703 0x0020 jhi_service - ok
22:56:03.0707 0x0020 kbdclass - ok
22:56:03.0710 0x0020 kbdhid - ok
22:56:03.0714 0x0020 kdnic - ok
22:56:03.0717 0x0020 KeyIso - ok
22:56:03.0720 0x0020 KSecDD - ok
22:56:03.0723 0x0020 KSecPkg - ok
22:56:03.0725 0x0020 ksthunk - ok
22:56:03.0730 0x0020 KtmRm - ok
22:56:03.0733 0x0020 LanmanServer - ok
22:56:03.0737 0x0020 LanmanWorkstation - ok
22:56:03.0741 0x0020 lfsvc - ok
22:56:03.0744 0x0020 LicenseManager - ok
22:56:03.0747 0x0020 lltdio - ok
22:56:03.0751 0x0020 lltdsvc - ok
22:56:03.0755 0x0020 lmhosts - ok
22:56:03.0765 0x0020 [ 9C30978597D52AD8EA319BABE6112AAE, 50A63FB33797D79D688CA86600693FA4BD668588FAE0F67D9725ACDD20445D2E ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:56:03.0779 0x0020 LMS - ok
22:56:03.0784 0x0020 LSI_SAS - ok
22:56:03.0787 0x0020 LSI_SAS2i - ok
22:56:03.0790 0x0020 LSI_SAS3i - ok
22:56:03.0794 0x0020 LSI_SSS - ok
22:56:03.0797 0x0020 LSM - ok
22:56:03.0800 0x0020 luafv - ok
22:56:03.0804 0x0020 MapsBroker - ok
22:56:03.0807 0x0020 megasas - ok
22:56:03.0811 0x0020 megasas2i - ok
22:56:03.0814 0x0020 megasr - ok
22:56:03.0819 0x0020 [ 1BC9159CF58BABD89419072EA180A8F6, 6C9AB779C2355A341800A8F93AAAF9B19FAFF444CD6A7BD27C63D53F379A75EF ] MEIx64 C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
22:56:03.0832 0x0020 MEIx64 - ok
22:56:03.0835 0x0020 MessagingService - ok
22:56:03.0841 0x0020 [ 5F4CABAFF1858C54DD5AFB33BD76926E, 06BDEE2B5325E605774C095D9DADFF5E6E124259482C4B7D9E74F1CEDC5A194E ] mfeelamk C:\WINDOWS\system32\drivers\mfeelamk.sys
22:56:03.0856 0x0020 mfeelamk - ok
22:56:03.0860 0x0020 mlx4_bus - ok
22:56:03.0865 0x0020 MMCSS - ok
22:56:03.0868 0x0020 Modem - ok
22:56:03.0872 0x0020 monitor - ok
22:56:03.0875 0x0020 mouclass - ok
22:56:03.0879 0x0020 mouhid - ok
22:56:03.0882 0x0020 mountmgr - ok
22:56:03.0888 0x0020 [ E96D4881189E3241A80EE54EFAB02E00, 13DC3174A2A5CF20C63C3EA5E2FF4060B15B40B02CCB29B41EC7A53047B69D9F ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:56:03.0898 0x0020 MozillaMaintenance - ok
22:56:03.0901 0x0020 mpsdrv - ok
22:56:03.0904 0x0020 MpsSvc - ok
22:56:03.0908 0x0020 MRxDAV - ok
22:56:03.0911 0x0020 mrxsmb - ok
22:56:03.0915 0x0020 mrxsmb10 - ok
22:56:03.0918 0x0020 mrxsmb20 - ok
22:56:03.0921 0x0020 MsBridge - ok
22:56:03.0924 0x0020 MSDTC - ok
22:56:03.0930 0x0020 Msfs - ok
22:56:03.0934 0x0020 msgpiowin32 - ok
22:56:03.0936 0x0020 mshidkmdf - ok
22:56:03.0939 0x0020 mshidumdf - ok
22:56:03.0942 0x0020 msisadrv - ok
22:56:03.0946 0x0020 MSiSCSI - ok
22:56:03.0949 0x0020 msiserver - ok
22:56:03.0952 0x0020 MSKSSRV - ok
22:56:03.0955 0x0020 MsLldp - ok
22:56:03.0959 0x0020 MSPCLOCK - ok
22:56:03.0962 0x0020 MSPQM - ok
22:56:03.0965 0x0020 MsRPC - ok
22:56:03.0970 0x0020 mssmbios - ok
22:56:03.0973 0x0020 MSTEE - ok
22:56:03.0977 0x0020 MTConfig - ok
22:56:03.0980 0x0020 Mup - ok
22:56:03.0983 0x0020 mvumis - ok
22:56:03.0987 0x0020 NativeWifiP - ok
22:56:03.0990 0x0020 NcaSvc - ok
22:56:03.0994 0x0020 NcbService - ok
22:56:03.0997 0x0020 NcdAutoSetup - ok
22:56:04.0001 0x0020 ndfltr - ok
22:56:04.0004 0x0020 NDIS - ok
22:56:04.0007 0x0020 NdisCap - ok
22:56:04.0011 0x0020 NdisImPlatform - ok
22:56:04.0014 0x0020 NdisTapi - ok
22:56:04.0017 0x0020 Ndisuio - ok
22:56:04.0019 0x0020 NdisVirtualBus - ok
22:56:04.0022 0x0020 NdisWan - ok
22:56:04.0025 0x0020 ndiswanlegacy - ok
22:56:04.0029 0x0020 ndproxy - ok
22:56:04.0031 0x0020 Ndu - ok
22:56:04.0034 0x0020 NetAdapterCx - ok
22:56:04.0037 0x0020 NetBIOS - ok
22:56:04.0041 0x0020 NetBT - ok
22:56:04.0045 0x0020 Netlogon - ok
22:56:04.0048 0x0020 Netman - ok
22:56:04.0051 0x0020 netprofm - ok
22:56:04.0054 0x0020 NetSetupSvc - ok
22:56:04.0062 0x0020 NetTcpPortSharing - ok
22:56:04.0066 0x0020 NETwNb64 - ok
22:56:04.0070 0x0020 NgcCtnrSvc - ok
22:56:04.0072 0x0020 NgcSvc - ok
22:56:04.0075 0x0020 NlaSvc - ok
22:56:04.0081 0x0020 [ DE7FCC77F4A503AF4CA6A47D49B3713D, 4BFAA99393F635CD05D91A64DE73EDB5639412C129E049F0FE34F88517A10FC6 ] npf C:\WINDOWS\system32\drivers\npf.sys
22:56:04.0088 0x0020 npf - ok
22:56:04.0092 0x0020 Npfs - ok
22:56:04.0096 0x0020 npsvctrig - ok
22:56:04.0099 0x0020 nsi - ok
22:56:04.0101 0x0020 nsiproxy - ok
22:56:04.0106 0x0020 NTFS - ok
22:56:04.0108 0x0020 Null - ok
22:56:04.0113 0x0020 nvraid - ok
22:56:04.0115 0x0020 nvstor - ok
22:56:04.0119 0x0020 OneSyncSvc - ok
22:56:04.0128 0x0020 [ 0282482270F0D0C6E6E2C483B1A35C16, 030E659B4D5DAFFCBE029B2BD94508437EC0B0AFB4EC026EFA586C2C04F023D6 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:56:04.0139 0x0020 ose - ok
22:56:04.0145 0x0020 p2pimsvc - ok
22:56:04.0149 0x0020 p2psvc - ok
22:56:04.0153 0x0020 Parport - ok
22:56:04.0157 0x0020 partmgr - ok
22:56:04.0161 0x0020 PcaSvc - ok
22:56:04.0164 0x0020 pci - ok
22:56:04.0167 0x0020 pciide - ok
22:56:04.0170 0x0020 pcmcia - ok
22:56:04.0173 0x0020 pcw - ok
22:56:04.0177 0x0020 pdc - ok
22:56:04.0180 0x0020 PEAUTH - ok
22:56:04.0184 0x0020 [ EE926C59CBD4DC4DC9FBB85014A2F1A5, 777459BD30A480E03EA5D0BBA431C2CD573403687FAA0B29F172086A0304E230 ] PEGAGFN C:\Program Files (x86)\PHotkey\PEGAGFN.sys
22:56:04.0190 0x0020 PEGAGFN - ok
22:56:04.0195 0x0020 [ 7BB4BD4E20221B6BFC0038851CF3A4F0, 29EECB0C2A8BFC315C5212AD26B871B02DF7B76B5097FF45BA5E5C78891F357C ] PegaRadioSwitch C:\WINDOWS\System32\drivers\PegaRadioSwitch.sys
22:56:04.0208 0x0020 PegaRadioSwitch - ok
22:56:04.0212 0x0020 percsas2i - ok
22:56:04.0215 0x0020 percsas3i - ok
22:56:04.0243 0x0020 PerfHost - ok
22:56:04.0252 0x0020 [ 81BDFDAE4FA5E1A4F767B332CACB1292, 19C468B1D43ADB93A3BBE03B83137A2720C01F4F63A929D059FA784572F4C97A ] PGFNEXSrv C:\Program Files (x86)\PHotkey\PGFNEXSrv.exe
22:56:04.0260 0x0020 PGFNEXSrv - detected UnsignedFile.Multi.Generic ( 1 )
22:56:04.0584 0x0020 PGFNEXSrv ( UnsignedFile.Multi.Generic ) - warning
22:56:04.0713 0x0020 PhoneSvc - ok
22:56:04.0722 0x0020 PimIndexMaintenanceSvc - ok
22:56:04.0735 0x0020 pla - ok
22:56:04.0745 0x0020 PlugPlay - ok
22:56:04.0750 0x0020 PNRPAutoReg - ok
22:56:04.0754 0x0020 PNRPsvc - ok
22:56:04.0758 0x0020 PolicyAgent - ok
22:56:04.0764 0x0020 Power - ok
22:56:04.0768 0x0020 PptpMiniport - ok
22:56:04.0863 0x0020 [ 30AA256A85C1A7B17A590B1C5244D28E, 2C1FB30DEF53C37CA0D0CA54B65CB8572C53DDFB430DE57F964253F1082ACEA0 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
22:56:04.0960 0x0020 PrintNotify - ok
22:56:04.0969 0x0020 Processor - ok
22:56:04.0973 0x0020 ProfSvc - ok
22:56:04.0975 0x0020 Psched - ok
22:56:04.0979 0x0020 QWAVE - ok
22:56:04.0982 0x0020 QWAVEdrv - ok
22:56:04.0985 0x0020 RasAcd - ok
22:56:04.0989 0x0020 RasAgileVpn - ok
22:56:04.0992 0x0020 RasAuto - ok
22:56:04.0995 0x0020 Rasl2tp - ok
22:56:04.0999 0x0020 RasMan - ok
22:56:05.0002 0x0020 RasPppoe - ok
22:56:05.0005 0x0020 RasSstp - ok
22:56:05.0008 0x0020 rdbss - ok
22:56:05.0013 0x0020 rdpbus - ok
22:56:05.0016 0x0020 RDPDR - ok
22:56:05.0023 0x0020 RdpVideoMiniport - ok
22:56:05.0025 0x0020 rdyboost - ok
22:56:05.0029 0x0020 ReFSv1 - ok
22:56:05.0033 0x0020 RemoteAccess - ok
22:56:05.0036 0x0020 RemoteRegistry - ok
22:56:05.0039 0x0020 RetailDemo - ok
22:56:05.0041 0x0020 RFCOMM - ok
22:56:05.0045 0x0020 RmSvc - ok
22:56:05.0048 0x0020 RpcEptMapper - ok
22:56:05.0052 0x0020 RpcLocator - ok
22:56:05.0055 0x0020 RpcSs - ok
22:56:05.0058 0x0020 rspndr - ok
22:56:05.0069 0x0020 [ 99E927EA78E4B20F02B4B900F6FAB569, C4F6EC9B3BA4FA39926673F39BA3A183CDB7FFC04404F115779C7397C482A795 ] RSUSBVSTOR C:\WINDOWS\System32\Drivers\RtsUVStor.sys
22:56:05.0082 0x0020 RSUSBVSTOR - ok
22:56:05.0101 0x0020 [ 9F2A38C1170594CF493283CE0B987B70, 1CE15815DD54227C3C8ED4B2E4FA09EB3EB91D55379DC286AAC7A6001850CA98 ] RTL8168 C:\WINDOWS\System32\drivers\Rt630x64.sys
22:56:05.0122 0x0020 RTL8168 - ok
22:56:05.0127 0x0020 s3cap - ok
22:56:05.0130 0x0020 SamSs - ok
22:56:05.0133 0x0020 sbp2port - ok
22:56:05.0136 0x0020 SCardSvr - ok
22:56:05.0141 0x0020 ScDeviceEnum - ok
22:56:05.0146 0x0020 scfilter - ok
22:56:05.0150 0x0020 Schedule - ok
22:56:05.0155 0x0020 scmbus - ok
22:56:05.0157 0x0020 scmdisk0101 - ok
22:56:05.0162 0x0020 SCPolicySvc - ok
22:56:05.0165 0x0020 sdbus - ok
22:56:05.0168 0x0020 SDRSVC - ok
22:56:05.0171 0x0020 sdstor - ok
22:56:05.0174 0x0020 seclogon - ok
22:56:05.0178 0x0020 SENS - ok
22:56:05.0181 0x0020 SensorDataService - ok
22:56:05.0184 0x0020 SensorService - ok
22:56:05.0187 0x0020 SensrSvc - ok
22:56:05.0189 0x0020 SerCx - ok
22:56:05.0193 0x0020 SerCx2 - ok
22:56:05.0197 0x0020 Serenum - ok
22:56:05.0200 0x0020 Serial - ok
22:56:05.0203 0x0020 sermouse - ok
22:56:05.0211 0x0020 SessionEnv - ok
22:56:05.0214 0x0020 sfloppy - ok
22:56:05.0217 0x0020 SharedAccess - ok
22:56:05.0221 0x0020 ShellHWDetection - ok
22:56:05.0225 0x0020 shpamsvc - ok
22:56:05.0229 0x0020 SiSRaid2 - ok
22:56:05.0232 0x0020 SiSRaid4 - ok
22:56:05.0556 0x0020 [ B72B80E6FF423C5011E745CB76DA9A08, 18A6B9D46E91AD4D463EB5CB832702392D2E162577F90C328B515FCE69FABD15 ] SkypeUpdate D:\Programme\Skype\Updater\Updater.exe
22:56:05.0599 0x0020 SkypeUpdate - ok
22:56:05.0603 0x0020 smphost - ok
22:56:05.0608 0x0020 SmsRouter - ok
22:56:05.0614 0x0020 SNMPTRAP - ok
22:56:05.0618 0x0020 spaceport - ok
22:56:05.0621 0x0020 SpbCx - ok
22:56:05.0625 0x0020 Spooler - ok
22:56:05.0630 0x0020 sppsvc - ok
22:56:05.0633 0x0020 srv - ok
22:56:05.0635 0x0020 srv2 - ok
22:56:05.0639 0x0020 srvnet - ok
22:56:05.0643 0x0020 SSDPSRV - ok
22:56:05.0647 0x0020 SstpSvc - ok
22:56:05.0654 0x0020 [ D08FFE34AF5B7AC5F69EEA1E0E8C6ECE, CC43752CE5C879E24229C84443DBEE667CE629ECF992AD0D42F0F77FE04F6751 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
22:56:05.0664 0x0020 ssudmdm - ok
22:56:05.0668 0x0020 StateRepository - ok
22:56:05.0672 0x0020 stexstor - ok
22:56:05.0675 0x0020 stisvc - ok
22:56:05.0679 0x0020 storahci - ok
22:56:05.0683 0x0020 storflt - ok
22:56:05.0685 0x0020 stornvme - ok
22:56:05.0689 0x0020 storqosflt - ok
22:56:05.0693 0x0020 StorSvc - ok
22:56:05.0696 0x0020 storufs - ok
22:56:05.0699 0x0020 storvsc - ok
22:56:05.0703 0x0020 svsvc - ok
22:56:05.0706 0x0020 swenum - ok
22:56:05.0710 0x0020 swprv - ok
22:56:05.0714 0x0020 Synth3dVsc - ok
22:56:05.0717 0x0020 SysMain - ok
22:56:05.0722 0x0020 SystemEventsBroker - ok
22:56:05.0727 0x0020 TabletInputService - ok
22:56:05.0730 0x0020 TapiSrv - ok
22:56:05.0733 0x0020 Tcpip - ok
22:56:05.0736 0x0020 Tcpip6 - ok
22:56:05.0740 0x0020 tcpipreg - ok
22:56:05.0747 0x0020 tdx - ok
22:56:05.0750 0x0020 terminpt - ok
22:56:05.0753 0x0020 TermService - ok
22:56:05.0757 0x0020 Themes - ok
22:56:05.0762 0x0020 TieringEngineService - ok
22:56:05.0765 0x0020 tiledatamodelsvc - ok
22:56:05.0768 0x0020 TimeBrokerSvc - ok
22:56:05.0771 0x0020 TPM - ok
22:56:05.0775 0x0020 TrkWks - ok
22:56:05.0800 0x0020 [ 807BFBADD4E45F651D577B16AAA7606D, A73ED96756D1E3BCA63E7EC3499E5D0BD5FE13575DB27B18107E9CB262F9749B ] TrueKey C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
22:56:05.0822 0x0020 TrueKey - ok
22:56:05.0826 0x0020 [ 433D821973B948BF2940B81ACF2A87DB, 2506C296B4FE46CF21C9CDC835ABAB249970BA6F7009313E66DEC005244652C1 ] TrueKeyScheduler C:\Program Files\TrueKey\McTkSchedulerService.exe
22:56:05.0833 0x0020 TrueKeyScheduler - ok
22:56:05.0838 0x0020 [ 9FB477FB7A25E2A1C38D014E5766B0A4, A2036042ED8BC0B2D83A78B2D9FF80D3BC270D3757D3511FC9FBC7FD3512CFE8 ] TrueKeyServiceHelper C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
22:56:05.0846 0x0020 TrueKeyServiceHelper - ok
22:56:05.0850 0x0020 TrustedInstaller - ok
22:56:05.0854 0x0020 tsusbflt - ok
22:56:05.0857 0x0020 TsUsbGD - ok
22:56:05.0861 0x0020 tunnel - ok
22:56:05.0864 0x0020 tzautoupdate - ok
22:56:05.0867 0x0020 UASPStor - ok
22:56:05.0870 0x0020 UcmCx0101 - ok
22:56:05.0873 0x0020 UcmTcpciCx0101 - ok
22:56:05.0877 0x0020 UcmUcsi - ok
22:56:05.0880 0x0020 Ucx01000 - ok
22:56:05.0883 0x0020 UdeCx - ok
22:56:05.0886 0x0020 udfs - ok
22:56:05.0889 0x0020 UEFI - ok
22:56:05.0893 0x0020 Ufx01000 - ok
22:56:05.0896 0x0020 UfxChipidea - ok
22:56:05.0900 0x0020 ufxsynopsys - ok
22:56:05.0906 0x0020 UI0Detect - ok
22:56:05.0910 0x0020 umbus - ok
22:56:05.0913 0x0020 UmPass - ok
22:56:05.0916 0x0020 UmRdpService - ok
22:56:05.0920 0x0020 UnistoreSvc - ok
22:56:05.0924 0x0020 upnphost - ok
22:56:05.0929 0x0020 UrsChipidea - ok
22:56:05.0932 0x0020 UrsCx01000 - ok
22:56:05.0935 0x0020 UrsSynopsys - ok
22:56:05.0939 0x0020 usbaudio - ok
22:56:05.0942 0x0020 usbccgp - ok
22:56:05.0947 0x0020 usbcir - ok
22:56:05.0950 0x0020 usbehci - ok
22:56:05.0953 0x0020 usbhub - ok
22:56:05.0957 0x0020 USBHUB3 - ok
22:56:05.0961 0x0020 usbohci - ok
22:56:05.0964 0x0020 usbprint - ok
22:56:05.0967 0x0020 usbser - ok
22:56:05.0971 0x0020 USBSTOR - ok
22:56:05.0973 0x0020 usbuhci - ok
22:56:05.0977 0x0020 usbvideo - ok
22:56:05.0980 0x0020 USBXHCI - ok
22:56:05.0984 0x0020 UserDataSvc - ok
22:56:05.0988 0x0020 UserManager - ok
22:56:05.0991 0x0020 UsoSvc - ok
22:56:05.0996 0x0020 VaultSvc - ok
22:56:05.0999 0x0020 vdrvroot - ok
22:56:06.0002 0x0020 vds - ok
22:56:06.0005 0x0020 VerifierExt - ok
22:56:06.0009 0x0020 vhdmp - ok
22:56:06.0012 0x0020 vhf - ok
22:56:06.0016 0x0020 vmbus - ok
22:56:06.0019 0x0020 VMBusHID - ok
22:56:06.0022 0x0020 vmgid - ok
22:56:06.0025 0x0020 vmicguestinterface - ok
22:56:06.0030 0x0020 vmicheartbeat - ok
22:56:06.0033 0x0020 vmickvpexchange - ok
22:56:06.0037 0x0020 vmicrdv - ok
22:56:06.0040 0x0020 vmicshutdown - ok
22:56:06.0045 0x0020 vmictimesync - ok
22:56:06.0050 0x0020 vmicvmsession - ok
22:56:06.0053 0x0020 vmicvss - ok
22:56:06.0056 0x0020 volmgr - ok
22:56:06.0060 0x0020 volmgrx - ok
22:56:06.0063 0x0020 volsnap - ok
22:56:06.0067 0x0020 volume - ok
22:56:06.0070 0x0020 vpci - ok
22:56:06.0073 0x0020 vsmraid - ok
22:56:06.0077 0x0020 VSS - ok
22:56:06.0081 0x0020 VSTXRAID - ok
22:56:06.0084 0x0020 vwifibus - ok
22:56:06.0087 0x0020 vwififlt - ok
22:56:06.0090 0x0020 vwifimp - ok
22:56:06.0094 0x0020 W32Time - ok
22:56:06.0097 0x0020 WacomPen - ok
22:56:06.0101 0x0020 WalletService - ok
22:56:06.0104 0x0020 wanarp - ok
22:56:06.0107 0x0020 wanarpv6 - ok
22:56:06.0111 0x0020 wbengine - ok
22:56:06.0114 0x0020 WbioSrvc - ok
22:56:06.0117 0x0020 wcifs - ok
22:56:06.0121 0x0020 Wcmsvc - ok
22:56:06.0124 0x0020 wcncsvc - ok
22:56:06.0129 0x0020 wcnfs - ok
22:56:06.0132 0x0020 WdBoot - ok
22:56:06.0135 0x0020 Wdf01000 - ok
22:56:06.0138 0x0020 WdFilter - ok
22:56:06.0145 0x0020 WdiServiceHost - ok
22:56:06.0149 0x0020 WdiSystemHost - ok
22:56:06.0153 0x0020 wdiwifi - ok
22:56:06.0156 0x0020 WdNisDrv - ok
22:56:06.0160 0x0020 WdNisSvc - ok
22:56:06.0164 0x0020 WebClient - ok
22:56:06.0168 0x0020 Wecsvc - ok
22:56:06.0171 0x0020 WEPHOSTSVC - ok
22:56:06.0176 0x0020 wercplsupport - ok
22:56:06.0179 0x0020 WerSvc - ok
22:56:06.0182 0x0020 WFPLWFS - ok
22:56:06.0186 0x0020 WiaRpc - ok
22:56:06.0189 0x0020 WIMMount - ok
22:56:06.0192 0x0020 WinDefend - ok
22:56:06.0199 0x0020 WindowsTrustedRT - ok
22:56:06.0202 0x0020 WindowsTrustedRTProxy - ok
22:56:06.0206 0x0020 WinHttpAutoProxySvc - ok
22:56:06.0210 0x0020 WinMad - ok
22:56:06.0218 0x0020 Winmgmt - ok
22:56:06.0222 0x0020 WinRM - ok
22:56:06.0229 0x0020 WINUSB - ok
22:56:06.0232 0x0020 WinVerbs - ok
22:56:06.0236 0x0020 wisvc - ok
22:56:06.0239 0x0020 WlanSvc - ok
22:56:06.0243 0x0020 wlidsvc - ok
22:56:06.0247 0x0020 WmiAcpi - ok
22:56:06.0252 0x0020 wmiApSrv - ok
22:56:06.0254 0x0020 WMPNetworkSvc - ok
22:56:06.0259 0x0020 Wof - ok
22:56:06.0264 0x0020 workfolderssvc - ok
22:56:06.0267 0x0020 WPDBusEnum - ok
22:56:06.0270 0x0020 WpdUpFltr - ok
22:56:06.0274 0x0020 WpnService - ok
22:56:06.0278 0x0020 WpnUserService - ok
22:56:06.0283 0x0020 ws2ifsl - ok
22:56:06.0287 0x0020 wscsvc - ok
22:56:06.0290 0x0020 WSDPrintDevice - ok
22:56:06.0294 0x0020 WSearch - ok
22:56:06.0299 0x0020 wuauserv - ok
22:56:06.0302 0x0020 WudfPf - ok
22:56:06.0305 0x0020 WUDFRd - ok
22:56:06.0310 0x0020 wudfsvc - ok
22:56:06.0313 0x0020 WUDFWpdFs - ok
22:56:06.0316 0x0020 WUDFWpdMtp - ok
22:56:06.0319 0x0020 WwanSvc - ok
22:56:06.0323 0x0020 XblAuthManager - ok
22:56:06.0327 0x0020 XblGameSave - ok
22:56:06.0330 0x0020 xboxgip - ok
22:56:06.0334 0x0020 XboxNetApiSvc - ok
22:56:06.0337 0x0020 xinputhid - ok
22:56:06.0339 0x0020 ================ Scan global ===============================
22:56:06.0350 0x0020 [ Global ] - ok
22:56:06.0350 0x0020 ================ Scan MBR ==================================
22:56:06.0392 0x0020 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
22:56:06.0471 0x0020 \Device\Harddisk0\DR0 - ok
22:56:06.0479 0x0020 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
22:56:06.0530 0x0020 \Device\Harddisk1\DR1 - ok
22:56:06.0530 0x0020 ================ Scan VBR ==================================
22:56:06.0532 0x0020 [ B9443415DB74FC870CA37B8440844E8E ] \Device\Harddisk0\DR0\Partition1
22:56:06.0533 0x0020 \Device\Harddisk0\DR0\Partition1 - ok
22:56:06.0535 0x0020 [ A4C9E7CDDE470B2A72B4A0DD70FB4879 ] \Device\Harddisk0\DR0\Partition2
22:56:06.0536 0x0020 \Device\Harddisk0\DR0\Partition2 - ok
22:56:06.0538 0x0020 [ EECBA16893206B7C22D33FD381B9ECBB ] \Device\Harddisk1\DR1\Partition1
22:56:06.0540 0x0020 \Device\Harddisk1\DR1\Partition1 - ok
22:56:06.0542 0x0020 [ 4F07F70F88FEE089DE9086A6E2F7701E ] \Device\Harddisk1\DR1\Partition2
22:56:06.0543 0x0020 \Device\Harddisk1\DR1\Partition2 - ok
22:56:06.0546 0x0020 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk1\DR1\Partition3
22:56:06.0546 0x0020 \Device\Harddisk1\DR1\Partition3 - ok
22:56:06.0549 0x0020 [ 0858BE71E0AF6264240CC0B0A0BB1742 ] \Device\Harddisk1\DR1\Partition4
22:56:06.0550 0x0020 \Device\Harddisk1\DR1\Partition4 - ok
22:56:06.0552 0x0020 [ B5D7D38648BA47102D08ECDA81AFAA20 ] \Device\Harddisk1\DR1\Partition5
22:56:06.0554 0x0020 \Device\Harddisk1\DR1\Partition5 - ok
22:56:06.0556 0x0020 [ 5A3CCDDE847F76045AE94757D66B53F9 ] \Device\Harddisk1\DR1\Partition6
22:56:06.0558 0x0020 \Device\Harddisk1\DR1\Partition6 - ok
22:56:06.0559 0x0020 ================ Scan generic autorun ======================
22:56:06.0559 0x0020 ETDCtrl - ok
22:56:06.0788 0x0020 [ 6BCE148DE6670CFB44828B8497E089F6, 150899C8FCBF57BD61794638149D8C14738AB915CA4470E2B65E766BBE4CF171 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
22:56:07.0023 0x0020 RtHDVCpl - ok
22:56:07.0062 0x0020 [ EC7059FE43C74A6281ECC08253B6D5DB, AE14E00733C0AC394457BFCD4A5ECD884286038BE2C7AAE34E3D32F3F992F29F ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
22:56:07.0092 0x0020 RtHDVBg_Dolby - ok
22:56:07.0098 0x0020 [ 7C17C957880958754F70963E3C8EABBD, F933F2AD913811DE5C1340CB7E76E53F6F3A2AE27943B6AAE0A1A250DA70B439 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
22:56:07.0103 0x0020 IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
22:56:07.0235 0x0020 Detect skipped due to KSN trusted
22:56:07.0235 0x0020 IAStorIcon - ok
22:56:07.0237 0x0020 WindowsDefender - ok
22:56:07.0273 0x0020 [ 8EAC7354D4F6169B47D0970C8D9C4360, 7114FCE62757D5F6CDD171834A8381A1B640DDCF898C780F70BCF80EFC98244D ] C:\Program Files (x86)\Avid\Application Manager\AvidAppManHelper.exe
22:56:07.0305 0x0020 AppManHelper - detected UnsignedFile.Multi.Generic ( 1 )
22:56:07.0447 0x0020 AppManHelper ( UnsignedFile.Multi.Generic ) - warning
22:56:07.0599 0x0020 [ 27B736DF17A786B222F4E8B149AE9B64, D00800CD7DEB98AD61A58D43093551552F1CD0C46EA9E38E638211EC60C662FB ] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
22:56:07.0621 0x0020 IJNetworkScannerSelectorEX - ok
22:56:07.0651 0x0020 [ 0BA2D83CC927053D6EBE5EB78E87E809, 86585BFC7B2C3E1D4A725B93C7CE105DDEC585725602814E8A586444B564927F ] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
22:56:07.0680 0x0020 CanonQuickMenu - ok
22:56:07.0709 0x0020 OneDriveSetup - ok
22:56:07.0711 0x0020 OneDriveSetup - ok
22:56:07.0749 0x0020 [ 6320CA4A7C486D412D01391E202745F6, D694D6A6C696AF16F14A000E0DD09D7BD6F177CEDAF6BD20012AEED4CB531EE4 ] C:\windows\system32\spool\DRIVERS\x64\3\E_YATIHTU.EXE
22:56:07.0766 0x0020 EPLTarget\P0000000000000000 - ok
22:56:07.0806 0x0020 Skype - ok
22:56:07.0810 0x0020 Waiting for KSN requests completion. In queue: 46
22:56:08.0838 0x0020 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.1198 ), 0x61100 ( enabled : updated )
22:56:08.0851 0x0020 Win FW state via NFP2: enabled ( trusted )
22:56:08.0939 0x0020 ============================================================
22:56:08.0939 0x0020 Scan finished
22:56:08.0939 0x0020 ============================================================
22:56:08.0960 0x085c Detected object count: 2
22:56:08.0960 0x085c Actual detected object count: 2
22:56:17.0466 0x085c PGFNEXSrv ( UnsignedFile.Multi.Generic ) - skipped by user
22:56:17.0466 0x085c PGFNEXSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
22:56:17.0466 0x085c AppManHelper ( UnsignedFile.Multi.Generic ) - skipped by user
22:56:17.0467 0x085c AppManHelper ( UnsignedFile.Multi.Generic ) - User select action: Skip |