Beide Programme haben wohl nichts gefunden. Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2015.10.01.04
rootkit: v2015.09.22.01
Windows 10 x64 NTFS
Internet Explorer 11.0.10240.16431
Sven :: SVEN-PC [administrator]
01.10.2015 15:26:26
mbar-log-2015-10-01 (15-26-26).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 531195
Time elapsed: 16 minute(s), 40 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) Code:
15:53:48.0818 0x1abc TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57
15:53:56.0812 0x1abc ============================================================
15:53:56.0812 0x1abc Current date / time: 2015/10/01 15:53:56.0812
15:53:56.0812 0x1abc SystemInfo:
15:53:56.0812 0x1abc
15:53:56.0812 0x1abc OS Version: 10.0.10240 ServicePack: 0.0
15:53:56.0812 0x1abc Product type: Workstation
15:53:56.0812 0x1abc ComputerName: SVEN-PC
15:53:56.0812 0x1abc UserName: Sven
15:53:56.0812 0x1abc Windows directory: C:\WINDOWS
15:53:56.0812 0x1abc System windows directory: C:\WINDOWS
15:53:56.0812 0x1abc Running under WOW64
15:53:56.0812 0x1abc Processor architecture: Intel x64
15:53:56.0812 0x1abc Number of processors: 8
15:53:56.0812 0x1abc Page size: 0x1000
15:53:56.0812 0x1abc Boot type: Normal boot
15:53:56.0812 0x1abc ============================================================
15:53:56.0943 0x1abc KLMD registered as C:\WINDOWS\system32\drivers\63154018.sys
15:53:56.0996 0x1abc System UUID: {F3B6507A-62D0-D0FB-2B1F-B48191D43F72}
15:53:57.0191 0x1abc Drive \Device\Harddisk1\DR1 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:53:57.0211 0x1abc Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:53:57.0213 0x1abc ============================================================
15:53:57.0213 0x1abc \Device\Harddisk1\DR1:
15:53:57.0213 0x1abc MBR partitions:
15:53:57.0213 0x1abc \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
15:53:57.0213 0x1abc \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xEE49000
15:53:57.0213 0x1abc \Device\Harddisk0\DR0:
15:53:57.0213 0x1abc MBR partitions:
15:53:57.0213 0x1abc \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
15:53:57.0213 0x1abc ============================================================
15:53:57.0214 0x1abc C: <-> \Device\Harddisk1\DR1\Partition2
15:53:57.0239 0x1abc E: <-> \Device\Harddisk0\DR0\Partition1
15:53:57.0239 0x1abc ============================================================
15:53:57.0239 0x1abc Initialize success
15:53:57.0239 0x1abc ============================================================
15:54:24.0027 0x0810 ============================================================
15:54:24.0027 0x0810 Scan started
15:54:24.0027 0x0810 Mode: Manual; SigCheck; TDLFS;
15:54:24.0027 0x0810 ============================================================
15:54:24.0027 0x0810 KSN ping started
15:54:26.0367 0x0810 KSN ping finished: true
15:54:27.0963 0x0810 ================ Scan system memory ========================
15:54:27.0963 0x0810 System memory - ok
15:54:27.0963 0x0810 ================ Scan services =============================
15:54:28.0015 0x0810 1394ohci - ok
15:54:28.0020 0x0810 3ware - ok
15:54:28.0026 0x0810 ACPI - ok
15:54:28.0031 0x0810 acpiex - ok
15:54:28.0038 0x0810 acpipagr - ok
15:54:28.0043 0x0810 AcpiPmi - ok
15:54:28.0047 0x0810 acpitime - ok
15:54:28.0053 0x0810 [ 013697369EAFFA675D0671607F036020, 65611C775AC4681E46A6565E5A7A4FF3363C66EBDC98C4C58AFB365D40BE23B6 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
15:54:28.0070 0x0810 AdobeARMservice - ok
15:54:28.0099 0x0810 [ C6D147C12C424373B016C0AB0A6C61EB, 043D44F3C942CFC3558E782938C26849BF648A58A7AA62C4A526E37DE4136C27 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
15:54:28.0107 0x0810 AdobeFlashPlayerUpdateSvc - ok
15:54:28.0110 0x0810 ADP80XX - ok
15:54:28.0113 0x0810 AFD - ok
15:54:28.0115 0x0810 agp440 - ok
15:54:28.0117 0x0810 ahcache - ok
15:54:28.0118 0x0810 AJRouter - ok
15:54:28.0120 0x0810 ALG - ok
15:54:28.0122 0x0810 AmdK8 - ok
15:54:28.0124 0x0810 AmdPPM - ok
15:54:28.0125 0x0810 amdsata - ok
15:54:28.0127 0x0810 amdsbs - ok
15:54:28.0129 0x0810 amdxata - ok
15:54:28.0148 0x0810 [ 6B31C215750CD41567E962D22839EE44, FF0B92807296B88DE37F9F2EB27FF7B73AA998B98074AA54A949A2B79690AFE5 ] AntiVirMailService C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
15:54:28.0166 0x0810 AntiVirMailService - ok
15:54:28.0175 0x0810 [ 18B0643B3B504E0FDCFCE0C8743B29C7, 1D4C004AD5066F52A4AA039F5364814F8F6B04EC1F704A5A3110172AD465661C ] AntiVirSchedulerService C:\Program Files (x86)\Avira\Antivirus\sched.exe
15:54:28.0184 0x0810 AntiVirSchedulerService - ok
15:54:28.0193 0x0810 [ 18B0643B3B504E0FDCFCE0C8743B29C7, 1D4C004AD5066F52A4AA039F5364814F8F6B04EC1F704A5A3110172AD465661C ] AntiVirService C:\Program Files (x86)\Avira\Antivirus\avguard.exe
15:54:28.0202 0x0810 AntiVirService - ok
15:54:28.0220 0x0810 [ 9A12F8E472FE05EF653CA152050405D4, 569EA8FFDE827F850CA8E3CB747A8552FD9981E61C48C7EA55E550A6C07F770E ] AntiVirWebService C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
15:54:28.0238 0x0810 AntiVirWebService - ok
15:54:28.0241 0x0810 AppHostSvc - ok
15:54:28.0243 0x0810 AppID - ok
15:54:28.0245 0x0810 AppIDSvc - ok
15:54:28.0248 0x0810 Appinfo - ok
15:54:28.0259 0x0810 [ 3E7C6639E424FD28952C29D66B7E5277, B10AD3FA5CB36328C5DF33AF58F76770E2B54CFBCB70BD84934F925B8E19FA1F ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:54:28.0263 0x0810 Apple Mobile Device Service - ok
15:54:28.0265 0x0810 AppReadiness - ok
15:54:28.0267 0x0810 AppXSvc - ok
15:54:28.0268 0x0810 arcsas - ok
15:54:28.0271 0x0810 [ 4DFF4312661F54EE87DC9A13CAEE60E0, 8821D2CA4036E764EFF71108735148FF54D3275DDCE1860EC7D67B2355E8DF82 ] asahci64 C:\WINDOWS\system32\drivers\asahci64.sys
15:54:28.0275 0x0810 asahci64 - ok
15:54:28.0296 0x0810 [ E536856E96A7605EBF580D62A868E5FE, 70D0F6ECB05E923C1B274605CB3320091D35D7622003FF7E4806645519C70F01 ] ASGT C:\Windows\SysWOW64\ASGT.exe
15:54:28.0303 0x0810 ASGT - detected UnsignedFile.Multi.Generic ( 1 )
15:54:30.0621 0x0810 Detect skipped due to KSN trusted
15:54:30.0621 0x0810 ASGT - ok
15:54:30.0645 0x0810 aspnet_state - ok
15:54:30.0650 0x0810 AsyncMac - ok
15:54:30.0656 0x0810 atapi - ok
15:54:30.0674 0x0810 [ 4AEF9EC86818375495FB78CA58DF4E18, 0565888F798FAB86091E7A7D8E1D583DF3CC5756A12ACF04987C67C14E360DFB ] atksgt C:\WINDOWS\system32\DRIVERS\atksgt.sys
15:54:30.0693 0x0810 atksgt - detected UnsignedFile.Multi.Generic ( 1 )
15:54:33.0019 0x0810 Detect skipped due to KSN trusted
15:54:33.0019 0x0810 atksgt - ok
15:54:33.0025 0x0810 AudioEndpointBuilder - ok
15:54:33.0029 0x0810 Audiosrv - ok
15:54:33.0036 0x0810 [ AC82CC4F2A41E098EB34C0A9F8125DDC, CC416DD5FC8E14A1F99F8DF52D795CA6E16EDBF8FD7C9624B10BA83D9D954BF2 ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys
15:54:33.0044 0x0810 avgntflt - ok
15:54:33.0052 0x0810 [ 45061BD6F11B80BF1C07A9253A659BF1, 9A1AFE963672E23F3C19FACE2CEB64766C964B165ECB26F36B6FB5730CEAFD2D ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys
15:54:33.0059 0x0810 avipbb - ok
15:54:33.0062 0x0810 [ 390184FAD8FCC1B6DA25AEBAE928C3B6, 537B0E0FAE080B55D70E990BBA0F7F22903CA340F6A42039BAD617A8ECF59119 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys
15:54:33.0067 0x0810 avkmgr - ok
15:54:33.0070 0x0810 [ 74179E7C103F3A44B33D7D982E21E35D, 7F2384B065EA9959734D65426781D901CDB0DA8DFCAD13BF05044DDF33CA5688 ] avnetflt C:\WINDOWS\system32\DRIVERS\avnetflt.sys
15:54:33.0074 0x0810 avnetflt - ok
15:54:33.0077 0x0810 AxInstSV - ok
15:54:33.0078 0x0810 b06bdrv - ok
15:54:33.0081 0x0810 BasicDisplay - ok
15:54:33.0083 0x0810 BasicRender - ok
15:54:33.0086 0x0810 bcmfn2 - ok
15:54:33.0088 0x0810 BDESVC - ok
15:54:33.0090 0x0810 Beep - ok
15:54:33.0107 0x0810 [ 2EE42E7539BBF4252F7F47B288E61CEA, 2113A7C825AE2D222FD80D092BAA254AB3EFA8A2F58EC8325837A6BC611BC715 ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
15:54:33.0129 0x0810 BEService - ok
15:54:33.0133 0x0810 BFE - ok
15:54:33.0135 0x0810 BITS - ok
15:54:33.0143 0x0810 [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
15:54:33.0152 0x0810 Bonjour Service - ok
15:54:33.0154 0x0810 bowser - ok
15:54:33.0156 0x0810 BrokerInfrastructure - ok
15:54:33.0158 0x0810 Browser - ok
15:54:33.0160 0x0810 BthAvrcpTg - ok
15:54:33.0162 0x0810 BthHFEnum - ok
15:54:33.0164 0x0810 bthhfhid - ok
15:54:33.0166 0x0810 BthHFSrv - ok
15:54:33.0168 0x0810 BTHMODEM - ok
15:54:33.0171 0x0810 bthserv - ok
15:54:33.0173 0x0810 buttonconverter - ok
15:54:33.0175 0x0810 CapImg - ok
15:54:33.0177 0x0810 cdfs - ok
15:54:33.0179 0x0810 CDPSvc - ok
15:54:33.0181 0x0810 cdrom - ok
15:54:33.0183 0x0810 CertPropSvc - ok
15:54:33.0185 0x0810 circlass - ok
15:54:33.0187 0x0810 CLFS - ok
15:54:33.0189 0x0810 ClipSVC - ok
15:54:33.0194 0x0810 CmBatt - ok
15:54:33.0195 0x0810 CNG - ok
15:54:33.0197 0x0810 cnghwassist - ok
15:54:33.0212 0x0810 CompositeBus - ok
15:54:33.0216 0x0810 COMSysApp - ok
15:54:33.0224 0x0810 condrv - ok
15:54:33.0226 0x0810 CoreMessagingRegistrar - ok
15:54:33.0231 0x0810 CryptSvc - ok
15:54:33.0233 0x0810 dam - ok
15:54:33.0236 0x0810 DcomLaunch - ok
15:54:33.0237 0x0810 DcpSvc - ok
15:54:33.0239 0x0810 defragsvc - ok
15:54:33.0241 0x0810 DeviceAssociationService - ok
15:54:33.0243 0x0810 DeviceInstall - ok
15:54:33.0245 0x0810 DevQueryBroker - ok
15:54:33.0246 0x0810 Dfsc - ok
15:54:33.0249 0x0810 Dhcp - ok
15:54:33.0251 0x0810 diagnosticshub.standardcollector.service - ok
15:54:33.0253 0x0810 DiagTrack - ok
15:54:33.0255 0x0810 disk - ok
15:54:33.0256 0x0810 DmEnrollmentSvc - ok
15:54:33.0258 0x0810 dmvsc - ok
15:54:33.0260 0x0810 dmwappushservice - ok
15:54:33.0262 0x0810 Dnscache - ok
15:54:33.0267 0x0810 dot3svc - ok
15:54:33.0269 0x0810 DPS - ok
15:54:33.0270 0x0810 drmkaud - ok
15:54:33.0272 0x0810 DsmSvc - ok
15:54:33.0274 0x0810 DsSvc - ok
15:54:33.0276 0x0810 DXGKrnl - ok
15:54:33.0278 0x0810 e1iexpress - ok
15:54:33.0280 0x0810 Eaphost - ok
15:54:33.0289 0x0810 [ B6572CC49E8D0DBCCAB230B4DAB06FB1, 8DEABC39E09ABBA51BA1739A34E77F955E0D9D77094575EBB927CA320D874B25 ] EaseUS Agent C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
15:54:33.0294 0x0810 EaseUS Agent - detected UnsignedFile.Multi.Generic ( 1 )
15:54:35.0619 0x0810 Detect skipped due to KSN trusted
15:54:35.0619 0x0810 EaseUS Agent - ok
15:54:35.0624 0x0810 ebdrv - ok
15:54:35.0629 0x0810 EFS - ok
15:54:35.0634 0x0810 EhStorClass - ok
15:54:35.0639 0x0810 EhStorTcgDrv - ok
15:54:35.0644 0x0810 embeddedmode - ok
15:54:35.0650 0x0810 EntAppSvc - ok
15:54:35.0654 0x0810 ErrDev - ok
15:54:35.0665 0x0810 [ A40A3A4653A18A0DA6522CEC69547B9F, ABB8D6C5A890D15DE9B96768BC91F48D7223C514C480706884D3C96FF539DC0D ] EUBAKUP C:\WINDOWS\system32\drivers\eubakup.sys
15:54:35.0675 0x0810 EUBAKUP - detected UnsignedFile.Multi.Generic ( 1 )
15:54:37.0999 0x0810 Detect skipped due to KSN trusted
15:54:37.0999 0x0810 EUBAKUP - ok
15:54:38.0009 0x0810 [ 23A4CFFF224CD9FA2226B64F1DCC4B4A, 67FD0393C592591CE9B87C21C78651CB73C1FB67C125B5B04D56F64C241F4F24 ] EUBKMON C:\WINDOWS\system32\drivers\EUBKMON.sys
15:54:38.0016 0x0810 EUBKMON - detected UnsignedFile.Multi.Generic ( 1 )
15:54:40.0342 0x0810 Detect skipped due to KSN trusted
15:54:40.0342 0x0810 EUBKMON - ok
15:54:40.0347 0x0810 [ 38A68D8706F79429ACAD043BE3533B97, 19879137A938A77DB0DD68A15BEFB2908F4D592510EBA7B676BBB43CE93E2745 ] EUDSKACS C:\Windows\system32\drivers\eudskacs.sys
15:54:40.0358 0x0810 EUDSKACS - detected UnsignedFile.Multi.Generic ( 1 )
15:54:42.0675 0x0810 Detect skipped due to KSN trusted
15:54:42.0675 0x0810 EUDSKACS - ok
15:54:42.0686 0x0810 [ 06BB97B21EF082703B7F3AE97F2DFFD8, E40C844E476B8500760549CF5A615A7EE094F18FA14F1C1DF08292B1B73EF804 ] EUFDDISK C:\Windows\system32\drivers\EuFdDisk.sys
15:54:42.0709 0x0810 EUFDDISK - detected UnsignedFile.Multi.Generic ( 1 )
15:54:45.0030 0x0810 Detect skipped due to KSN trusted
15:54:45.0030 0x0810 EUFDDISK - ok
15:54:45.0037 0x0810 EventSystem - ok
15:54:45.0042 0x0810 exfat - ok
15:54:45.0047 0x0810 fastfat - ok
15:54:45.0052 0x0810 Fax - ok
15:54:45.0057 0x0810 fcvsc - ok
15:54:45.0060 0x0810 fdc - ok
15:54:45.0063 0x0810 fdPHost - ok
15:54:45.0066 0x0810 FDResPub - ok
15:54:45.0068 0x0810 fhsvc - ok
15:54:45.0071 0x0810 FileCrypt - ok
15:54:45.0074 0x0810 FileInfo - ok
15:54:45.0078 0x0810 Filetrace - ok
15:54:45.0080 0x0810 flpydisk - ok
15:54:45.0083 0x0810 FltMgr - ok
15:54:45.0086 0x0810 FontCache - ok
15:54:45.0089 0x0810 FontCache3.0.0.0 - ok
15:54:45.0090 0x0810 FsDepends - ok
15:54:45.0092 0x0810 Fs_Rec - ok
15:54:45.0094 0x0810 fvevol - ok
15:54:45.0096 0x0810 gagp30kx - ok
15:54:45.0098 0x0810 [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
15:54:45.0101 0x0810 GEARAspiWDM - ok
15:54:45.0103 0x0810 gencounter - ok
15:54:45.0105 0x0810 genericusbfn - ok
15:54:45.0123 0x0810 [ 5031F3E650D242EEECEB92EB9900FB93, FB51ADB81AC3E0097362BAECEC4F0C83C46E5505277B7F35FDCE9BF88B72C963 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
15:54:45.0141 0x0810 GfExperienceService - ok
15:54:45.0144 0x0810 GPIOClx0101 - ok
15:54:45.0145 0x0810 gpsvc - ok
15:54:45.0147 0x0810 GpuEnergyDrv - ok
15:54:45.0151 0x0810 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:54:45.0156 0x0810 gupdate - ok
15:54:45.0159 0x0810 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:54:45.0164 0x0810 gupdatem - ok
15:54:45.0166 0x0810 HDAudBus - ok
15:54:45.0167 0x0810 HidBatt - ok
15:54:45.0169 0x0810 HidBth - ok
15:54:45.0171 0x0810 hidi2c - ok
15:54:45.0173 0x0810 hidinterrupt - ok
15:54:45.0174 0x0810 HidIr - ok
15:54:45.0176 0x0810 hidserv - ok
15:54:45.0177 0x0810 HidUsb - ok
15:54:45.0179 0x0810 HomeGroupListener - ok
15:54:45.0182 0x0810 HomeGroupProvider - ok
15:54:45.0183 0x0810 HpSAMD - ok
15:54:45.0185 0x0810 HTTP - ok
15:54:45.0186 0x0810 hwpolicy - ok
15:54:45.0188 0x0810 hyperkbd - ok
15:54:45.0190 0x0810 HyperVideo - ok
15:54:45.0192 0x0810 i8042prt - ok
15:54:45.0193 0x0810 iaLPSSi_GPIO - ok
15:54:45.0195 0x0810 iaLPSSi_I2C - ok
15:54:45.0206 0x0810 [ BC14E2C46AECD17D22D3356CA0A2DD4B, B325BC739019AEE9BA787BD936A660439CA861F84A3289788ADB2DD7756F632B ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
15:54:45.0217 0x0810 iaStorA - ok
15:54:45.0219 0x0810 iaStorAV - ok
15:54:45.0221 0x0810 [ 10F228CC634E74B47FD48FDBFE0126D9, 1A761E43C4ABFCBDBD4CC1CA5630408DBFF470208E09D4A388B3B5B16CE677D1 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorDataMgrSvc.exe
15:54:45.0224 0x0810 IAStorDataMgrSvc - detected UnsignedFile.Multi.Generic ( 1 )
15:54:48.0537 0x0810 Detect skipped due to KSN trusted
15:54:48.0537 0x0810 IAStorDataMgrSvc - ok
15:54:48.0543 0x0810 [ 0475F003D7F3A949CA5BFC56C6B1DF43, 45A586407FF543DC4135E9601D647287A0355E0D0AF9E244C6B23CE7729EF6BD ] iaStorF C:\WINDOWS\system32\drivers\iaStorF.sys
15:54:48.0553 0x0810 iaStorF - ok
15:54:48.0557 0x0810 iaStorV - ok
15:54:48.0567 0x0810 ibbus - ok
15:54:48.0575 0x0810 [ 86B750CC384F3A8B8C1D12F3188307AE, 222B271B1E958715FF54B63B4533FA24DF13191B99D1A406BF2E9A532E31FF30 ] ICQ Service C:\Program Files (x86)\ICQ6Toolbar\ICQ Service.exe
15:54:48.0586 0x0810 ICQ Service - ok
15:54:48.0590 0x0810 icssvc - ok
15:54:48.0595 0x0810 [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
15:54:48.0600 0x0810 IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
15:54:50.0920 0x0810 Detect skipped due to KSN trusted
15:54:50.0920 0x0810 IDriverT - ok
15:54:50.0927 0x0810 IEEtwCollectorService - ok
15:54:50.0933 0x0810 IKEEXT - ok
15:54:51.0035 0x0810 [ 622868E4BAE8FBCD22CB1A5901A2C824, C1A2264C0984DD16C83B663C9CE43E049E1356E32C5771C3ACE225F285699138 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
15:54:51.0134 0x0810 IntcAzAudAddService - ok
15:54:51.0140 0x0810 intelide - ok
15:54:51.0141 0x0810 intelpep - ok
15:54:51.0143 0x0810 intelppm - ok
15:54:51.0145 0x0810 IoQos - ok
15:54:51.0147 0x0810 IpFilterDriver - ok
15:54:51.0149 0x0810 iphlpsvc - ok
15:54:51.0150 0x0810 IPMIDRV - ok
15:54:51.0152 0x0810 IPNAT - ok
15:54:51.0162 0x0810 [ 57A85230DA22ABCFD9AF2E5A3D946F41, 9E9217FF5AB64D06D79632B9F9CEDABA10F744C40896D7622D0FD397FD0E99BF ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
15:54:51.0173 0x0810 iPod Service - ok
15:54:51.0176 0x0810 IRENUM - ok
15:54:51.0177 0x0810 isapnp - ok
15:54:51.0179 0x0810 iScsiPrt - ok
15:54:51.0181 0x0810 kbdclass - ok
15:54:51.0183 0x0810 kbdhid - ok
15:54:51.0184 0x0810 kdnic - ok
15:54:51.0186 0x0810 KeyIso - ok
15:54:51.0187 0x0810 KSecDD - ok
15:54:51.0189 0x0810 KSecPkg - ok
15:54:51.0191 0x0810 ksthunk - ok
15:54:51.0193 0x0810 KtmRm - ok
15:54:51.0200 0x0810 [ 305BB2AC00D46542E0A653AB63F4ABB1, E3BE57A0EBB1194656D20C11688863A7864B06223419F688D82881F9F49604B6 ] LADF_CaptureOnly C:\WINDOWS\system32\DRIVERS\ladfGSCamd64.sys
15:54:51.0210 0x0810 LADF_CaptureOnly - ok
15:54:51.0214 0x0810 [ 28CDDC7D478A6313F55077416DCBD0DE, EE4174FC9444856DF0693D1A5F16EB88352A3B012AA82D49C462980703981A7A ] LADF_RenderOnly C:\WINDOWS\system32\DRIVERS\ladfGSRamd64.sys
15:54:51.0219 0x0810 LADF_RenderOnly - ok
15:54:51.0221 0x0810 LanmanServer - ok
15:54:51.0222 0x0810 LanmanWorkstation - ok
15:54:51.0225 0x0810 lfsvc - ok
15:54:51.0227 0x0810 [ 17325C9B9ADB2BB99049936D0C9812C8, 70ADDC85FD5757BC9C4B97F382B25A19851FF8275021FFC04A81E208A604F83E ] LGBusEnum C:\WINDOWS\system32\drivers\LGBusEnum.sys
15:54:51.0237 0x0810 LGBusEnum - ok
15:54:51.0239 0x0810 [ 2D7F1C02B94D6F0F3E10107E5EA8E141, 93B266F38C3C3EAAB475D81597ABBD7CC07943035068BB6FD670DBBE15DE0131 ] LGCoreTemp C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys
15:54:51.0243 0x0810 LGCoreTemp - ok
15:54:51.0246 0x0810 [ C7AF05942E041D4B1F345ACF79993BB3, E8FAAE356C99A11F6CF17640FD9C67F87AFBFEFB70C458CB85178F2AD94DF848 ] LGJoyXlCore C:\WINDOWS\system32\drivers\LGJoyXlCore.sys
15:54:51.0253 0x0810 LGJoyXlCore - ok
15:54:51.0256 0x0810 [ 94AF1384A67B9FCF5651E70BC9D4C526, 9C025F7BBB5BBE9DAF3DEF2F6385CE77C8F413912C4D16930814F6D19B62B367 ] LGSHidFilt C:\WINDOWS\system32\DRIVERS\LGSHidFilt.Sys
15:54:51.0260 0x0810 LGSHidFilt - ok
15:54:51.0263 0x0810 [ 1DDB8DE3D6EEF31EDCF4977B2D2FAACC, 24291B522A596E2D9A1CDAC192DB1C7422D5DD0E87E5C8A5F5E2CAA90296BF23 ] LGVirHid C:\WINDOWS\system32\drivers\LGVirHid.sys
15:54:51.0270 0x0810 LGVirHid - ok
15:54:51.0272 0x0810 [ B6552D382FF070B4ED34CBD6737277C0, 7C2C24454037170311B0267DEFB797E8DF8D157D62157D271BF7F5F74B2A12F3 ] LHidFilt C:\WINDOWS\system32\DRIVERS\LHidFilt.Sys
15:54:51.0276 0x0810 LHidFilt - ok
15:54:51.0278 0x0810 LicenseManager - ok
15:54:51.0282 0x0810 [ B658B7076B1ACAA5876524595630F183, 3B800B81D0966C2B988857847F35FCA5BB446B368063B10094FB4483A1508B8E ] lirsgt C:\WINDOWS\system32\DRIVERS\lirsgt.sys
15:54:51.0285 0x0810 lirsgt - detected UnsignedFile.Multi.Generic ( 1 )
15:54:53.0614 0x0810 Detect skipped due to KSN trusted
15:54:53.0614 0x0810 lirsgt - ok
15:54:53.0618 0x0810 lltdio - ok
15:54:53.0624 0x0810 lltdsvc - ok
15:54:53.0629 0x0810 lmhosts - ok
15:54:53.0636 0x0810 [ 73C1F563AB73D459DFFE682D66476558, 9B8BEE384C968DC6C37DD54B9128D9C2BA92EDBF7BDF49D753AA7DB165F18D00 ] LMouFilt C:\WINDOWS\system32\DRIVERS\LMouFilt.Sys
15:54:53.0647 0x0810 LMouFilt - ok
15:54:53.0654 0x0810 LSI_SAS - ok
15:54:53.0659 0x0810 LSI_SAS2i - ok
15:54:53.0664 0x0810 LSI_SAS3i - ok
15:54:53.0668 0x0810 LSI_SSS - ok
15:54:53.0671 0x0810 LSM - ok
15:54:53.0673 0x0810 luafv - ok
15:54:53.0676 0x0810 MapsBroker - ok
15:54:53.0678 0x0810 megasas - ok
15:54:53.0681 0x0810 megasr - ok
15:54:53.0685 0x0810 [ E4DD818EF22BBBF4274AF767A96D34C8, 4796F543091E2FC2F143296C71CC13BE18646261E5E293A07C5872A544933826 ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
15:54:53.0691 0x0810 MEIx64 - ok
15:54:53.0696 0x0810 [ 123271BD5237AB991DC5C21FDF8835EB, 004F8F9228EE291A0E36CE33078D572D61733516F9AA5CFC832AF204C6869E89 ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
15:54:53.0702 0x0810 Microsoft Office Groove Audit Service - ok
15:54:53.0704 0x0810 mlx4_bus - ok
15:54:53.0705 0x0810 MMCSS - ok
15:54:53.0707 0x0810 Modem - ok
15:54:53.0709 0x0810 monitor - ok
15:54:53.0710 0x0810 mouclass - ok
15:54:53.0712 0x0810 mouhid - ok
15:54:53.0716 0x0810 mountmgr - ok
15:54:53.0719 0x0810 [ 8C7336950F1E69CDFD811CBBD9CF00A2, 6A85107B66936B3AAB10A4209F17A72BA86923B95A334B12F48D8512EB93CBAA ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
15:54:53.0724 0x0810 MozillaMaintenance - ok
15:54:53.0725 0x0810 mpsdrv - ok
15:54:53.0727 0x0810 MpsSvc - ok
15:54:53.0729 0x0810 MQAC - ok
15:54:53.0732 0x0810 MRxDAV - ok
15:54:53.0734 0x0810 mrxsmb - ok
15:54:53.0735 0x0810 mrxsmb10 - ok
15:54:53.0737 0x0810 mrxsmb20 - ok
15:54:53.0739 0x0810 MsBridge - ok
15:54:53.0741 0x0810 MSDTC - ok
15:54:53.0744 0x0810 Msfs - ok
15:54:53.0746 0x0810 msgpiowin32 - ok
15:54:53.0747 0x0810 mshidkmdf - ok
15:54:53.0749 0x0810 mshidumdf - ok
15:54:53.0751 0x0810 msisadrv - ok
15:54:53.0753 0x0810 MSiSCSI - ok
15:54:53.0754 0x0810 msiserver - ok
15:54:53.0756 0x0810 MSKSSRV - ok
15:54:53.0758 0x0810 MsLldp - ok
15:54:53.0759 0x0810 MSMQ - ok
15:54:53.0761 0x0810 MSPCLOCK - ok
15:54:53.0763 0x0810 MSPQM - ok
15:54:53.0765 0x0810 MsRPC - ok
15:54:53.0767 0x0810 mssmbios - ok
15:54:53.0769 0x0810 MSTEE - ok
15:54:53.0771 0x0810 MTConfig - ok
15:54:53.0772 0x0810 Mup - ok
15:54:53.0775 0x0810 [ A56731462518CCE74EB0DB38C2A04986, 0E38662CC1D90E1A2DBE0835B0C23ED81CC48868104CBF637DB1C9881821A9B9 ] mv91cons C:\WINDOWS\system32\drivers\mv91cons.sys
15:54:53.0779 0x0810 mv91cons - ok
15:54:53.0784 0x0810 [ 232DE45537AE5652C64F0B8669081D02, 5382E94E1A61C78D36C77B4ABEA62F345C715FC60D8F3D35F29363BAB1DE10CC ] mvs91xx C:\WINDOWS\system32\drivers\mvs91xx.sys
15:54:53.0792 0x0810 mvs91xx - ok
15:54:53.0794 0x0810 mvumis - ok
15:54:53.0796 0x0810 NativeWifiP - ok
15:54:53.0798 0x0810 NcaSvc - ok
15:54:53.0800 0x0810 NcbService - ok
15:54:53.0801 0x0810 NcdAutoSetup - ok
15:54:53.0803 0x0810 ndfltr - ok
15:54:53.0805 0x0810 NDIS - ok
15:54:53.0806 0x0810 NdisCap - ok
15:54:53.0808 0x0810 NdisImPlatform - ok
15:54:53.0810 0x0810 NdisTapi - ok
15:54:53.0812 0x0810 Ndisuio - ok
15:54:53.0813 0x0810 NdisVirtualBus - ok
15:54:53.0815 0x0810 NdisWan - ok
15:54:53.0817 0x0810 ndiswanlegacy - ok
15:54:53.0819 0x0810 ndproxy - ok
15:54:53.0820 0x0810 Ndu - ok
15:54:53.0823 0x0810 [ EE00C544C025958AF50C7B199F3C8595, D774DB020D9C46D1AA0B2DB9FA2C36C4A9C38D904CC6929695321D32ACA0D4D1 ] Netaapl C:\WINDOWS\System32\drivers\netaapl64.sys
15:54:53.0832 0x0810 Netaapl - ok
15:54:53.0834 0x0810 NetBIOS - ok
15:54:53.0836 0x0810 NetBT - ok
15:54:53.0838 0x0810 Netlogon - ok
15:54:53.0840 0x0810 Netman - ok
15:54:53.0844 0x0810 NetMsmqActivator - ok
15:54:53.0845 0x0810 NetPipeActivator - ok
15:54:53.0847 0x0810 netprofm - ok
15:54:53.0849 0x0810 NetSetupSvc - ok
15:54:53.0850 0x0810 NetTcpActivator - ok
15:54:53.0852 0x0810 NetTcpPortSharing - ok
15:54:53.0854 0x0810 netvsc - ok
15:54:53.0857 0x0810 NgcCtnrSvc - ok
15:54:53.0858 0x0810 NgcSvc - ok
15:54:53.0860 0x0810 NlaSvc - ok
15:54:53.0862 0x0810 Npfs - ok
15:54:53.0864 0x0810 npsvctrig - ok
15:54:53.0866 0x0810 nsi - ok
15:54:53.0867 0x0810 nsiproxy - ok
15:54:53.0870 0x0810 NTFS - ok
15:54:53.0871 0x0810 Null - ok
15:54:53.0876 0x0810 [ B9E5A80F646DDFEF158773722A466EA3, 028979FE600D17DA70445F44D81FAE4EDA3478FCC81FA5506133CCAC37C4E2BF ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
15:54:53.0884 0x0810 NVHDA - ok
15:54:54.0033 0x0810 [ 5FB73F2354F2993136567EB209F4835A, 40EA334DEDEB76C101CC432D1D07E59F1CD123D01778BE80193F821FC211512B ] nvlddmkm C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys
15:54:54.0234 0x0810 nvlddmkm - ok
15:54:54.0268 0x0810 [ 4EBEE69A8FE7DC85FD3C122821C617A0, 7193C14DEB4C5B0D86C5C6841C80879C28E1FDA8F77879EB18A3D2685C67B986 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
15:54:54.0295 0x0810 NvNetworkService - ok
15:54:54.0298 0x0810 nvraid - ok
15:54:54.0299 0x0810 nvstor - ok
15:54:54.0301 0x0810 [ 0EF30778078D7B5877F8F57151699798, B0409C79143BDBB774C3C740CCA8EB77CF67915E59EC6050DB993ED0575EC077 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
15:54:54.0305 0x0810 NvStreamKms - ok
15:54:54.0380 0x0810 [ D23A07D549243F5B77780BAA4FBF5BC3, 5BC5161CAE6BE6382BDCDE9B1CDD5F4DEBC3EA18D01B0E261AF716FDB04154BC ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
15:54:54.0454 0x0810 NvStreamSvc - ok
15:54:54.0473 0x0810 [ AE16891F2D960D9B312D704A8122AB29, DD9767637CC34C3D0EED6243FAD3D3D321873A5B72688CAD31895655A933055F ] nvsvc C:\Windows\system32\nvvsvc.exe
15:54:54.0493 0x0810 nvsvc - ok
15:54:54.0496 0x0810 [ 4F00008B513F4019623ED61159363888, A1047FF1FCF3ED405C3426C8959AD10426F30E3F58E95BFD6ADF1DBC947AB379 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
15:54:54.0501 0x0810 nvvad_WaveExtensible - ok
15:54:54.0502 0x0810 nv_agp - ok
15:54:54.0511 0x0810 [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
15:54:54.0520 0x0810 odserv - ok
15:54:54.0522 0x0810 OneSyncSvc - ok
15:54:54.0639 0x0810 [ 4F9FFCF12B6ED0B4DAC95427772C226E, 4A79AEC410ED1034366FAC1388FB29381EE6541AA17E3652BE86265D09541C56 ] Origin Client Service E:\Program Files (x86)\Origin\OriginClientService.exe
15:54:54.0695 0x0810 Origin Client Service - ok
15:54:54.0700 0x0810 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:54:54.0705 0x0810 ose - ok
15:54:54.0708 0x0810 p2pimsvc - ok
15:54:54.0710 0x0810 p2psvc - ok
15:54:54.0711 0x0810 Parport - ok
15:54:54.0713 0x0810 partmgr - ok
15:54:54.0715 0x0810 PcaSvc - ok
15:54:54.0717 0x0810 pci - ok
15:54:54.0718 0x0810 pciide - ok
15:54:54.0720 0x0810 pcmcia - ok
15:54:54.0722 0x0810 pcw - ok
15:54:54.0723 0x0810 pdc - ok
15:54:54.0725 0x0810 PEAUTH - ok
15:54:54.0727 0x0810 percsas2i - ok
15:54:54.0729 0x0810 percsas3i - ok
15:54:54.0750 0x0810 PerfHost - ok
15:54:54.0754 0x0810 PimIndexMaintenanceSvc - ok
15:54:54.0756 0x0810 pla - ok
15:54:54.0758 0x0810 PlugPlay - ok
15:54:54.0761 0x0810 [ CD421DDB5C6E5458CE52EDC36DE7DC5B, 7B9C0A8B2B86BBF5D7E02F2620B0015A2530CBBC99724BE20313DE53EB31D62E ] PnkBstrA C:\Windows\system32\PnkBstrA.exe
15:54:54.0769 0x0810 PnkBstrA - ok
15:54:54.0771 0x0810 PNRPAutoReg - ok
15:54:54.0772 0x0810 PNRPsvc - ok
15:54:54.0774 0x0810 PolicyAgent - ok
15:54:54.0776 0x0810 Power - ok
15:54:54.0778 0x0810 PptpMiniport - ok
15:54:54.0833 0x0810 [ 12E2582F69ACA40A6BAE91DA578CBF34, 648C6394763906AA4163976DA2C3308F8B706486D9D8F16258CB1D61C2929930 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
15:54:54.0917 0x0810 PrintNotify - ok
15:54:54.0921 0x0810 Processor - ok
15:54:54.0922 0x0810 ProfSvc - ok
15:54:54.0924 0x0810 Psched - ok
15:54:54.0926 0x0810 [ C32ECB99AD25E9A04F01C8665DF29EF8, 0489B3DEC6A33E50D8A48A8DAD3F5B923A81F7300E4A71358D90D2879BAC9AA2 ] pwdrvio C:\Windows\system32\pwdrvio.sys
15:54:54.0935 0x0810 pwdrvio - ok
15:54:54.0937 0x0810 [ D619356B955EEFA642F5FF72755E8B3C, 1FD54978A77ACD6FBF1236E177ED074894743A9141E4169FE9AFE28680FC93C5 ] pwdspio C:\Windows\system32\pwdspio.sys
15:54:54.0944 0x0810 pwdspio - ok
15:54:54.0946 0x0810 QWAVE - ok
15:54:54.0948 0x0810 QWAVEdrv - ok
15:54:54.0949 0x0810 RasAcd - ok
15:54:54.0951 0x0810 RasAgileVpn - ok
15:54:54.0953 0x0810 RasAuto - ok
15:54:54.0954 0x0810 Rasl2tp - ok
15:54:54.0956 0x0810 RasMan - ok
15:54:54.0958 0x0810 RasPppoe - ok
15:54:54.0959 0x0810 RasSstp - ok
15:54:54.0961 0x0810 rdbss - ok
15:54:54.0964 0x0810 rdpbus - ok
15:54:54.0966 0x0810 RDPDR - ok
15:54:54.0969 0x0810 RdpVideoMiniport - ok
15:54:54.0971 0x0810 rdyboost - ok
15:54:54.0973 0x0810 ReFSv1 - ok
15:54:54.0975 0x0810 RemoteAccess - ok
15:54:54.0976 0x0810 RemoteRegistry - ok
15:54:54.0978 0x0810 RetailDemo - ok
15:54:54.0980 0x0810 RpcEptMapper - ok
15:54:54.0982 0x0810 RpcLocator - ok
15:54:54.0983 0x0810 RpcSs - ok
15:54:54.0985 0x0810 rspndr - ok
15:54:54.0987 0x0810 s3cap - ok
15:54:54.0988 0x0810 SamSs - ok
15:54:54.0990 0x0810 sbp2port - ok
15:54:54.0992 0x0810 SCardSvr - ok
15:54:54.0993 0x0810 ScDeviceEnum - ok
15:54:54.0995 0x0810 scfilter - ok
15:54:54.0997 0x0810 Schedule - ok
15:54:54.0999 0x0810 SCPolicySvc - ok
15:54:55.0000 0x0810 sdbus - ok
15:54:55.0002 0x0810 SDRSVC - ok
15:54:55.0004 0x0810 sdstor - ok
15:54:55.0005 0x0810 SecDrv - ok
15:54:55.0007 0x0810 seclogon - ok
15:54:55.0009 0x0810 SENS - ok
15:54:55.0011 0x0810 SensorDataService - ok
15:54:55.0012 0x0810 SensorService - ok
15:54:55.0014 0x0810 SensrSvc - ok
15:54:55.0016 0x0810 SerCx - ok
15:54:55.0017 0x0810 SerCx2 - ok
15:54:55.0019 0x0810 Serenum - ok
15:54:55.0021 0x0810 Serial - ok
15:54:55.0022 0x0810 sermouse - ok
15:54:55.0027 0x0810 SessionEnv - ok
15:54:55.0032 0x0810 sfloppy - ok
15:54:55.0034 0x0810 SharedAccess - ok
15:54:55.0036 0x0810 ShellHWDetection - ok
15:54:55.0037 0x0810 SiSRaid2 - ok
15:54:55.0039 0x0810 SiSRaid4 - ok
15:54:55.0046 0x0810 [ F6EF225A23D336CA30001E5007644C24, B0A4B1256C1074F1B4F73E3BBA16FD4683D6EEA583DEEF8E11EFD29BA7541F2A ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
15:54:55.0055 0x0810 SkypeUpdate - ok
15:54:55.0057 0x0810 smphost - ok
15:54:55.0059 0x0810 SmsRouter - ok
15:54:55.0063 0x0810 SNMPTRAP - ok
15:54:55.0065 0x0810 spaceport - ok
15:54:55.0066 0x0810 SpbCx - ok
15:54:55.0069 0x0810 Spooler - ok
15:54:55.0070 0x0810 sppsvc - ok
15:54:55.0072 0x0810 srv - ok
15:54:55.0074 0x0810 srv2 - ok
15:54:55.0075 0x0810 srvnet - ok
15:54:55.0077 0x0810 SSDPSRV - ok
15:54:55.0079 0x0810 SstpSvc - ok
15:54:55.0082 0x0810 StateRepository - ok
15:54:55.0095 0x0810 [ 2A6EDC2FBB4B9C11BB21BE3881C7A692, 74482CA4EC2B98C069A32C224BA5449AE10A8B41BFC053A4C23B6F65113A97A4 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
15:54:55.0109 0x0810 Steam Client Service - ok
15:54:55.0117 0x0810 [ 7477A8BD87856CBDF92BBD72692649A8, D13D117506D350AAC555C2ACB1DABDFAB199A954E1220940C91F2551BEF9D2E4 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
15:54:55.0126 0x0810 Stereo Service - ok
15:54:55.0128 0x0810 stexstor - ok
15:54:55.0130 0x0810 [ 7C4D2F167FA6153B4FE7145FE6D3DF15, F39ED9CDF323DDC57D0F64F9CC121E911EA53819A3A941A2F6EA557C35FCB372 ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
15:54:55.0137 0x0810 StillCam - ok
15:54:55.0139 0x0810 stisvc - ok
15:54:55.0140 0x0810 storahci - ok
15:54:55.0142 0x0810 storflt - ok
15:54:55.0144 0x0810 stornvme - ok
15:54:55.0148 0x0810 storqosflt - ok
15:54:55.0150 0x0810 StorSvc - ok
15:54:55.0152 0x0810 storufs - ok
15:54:55.0153 0x0810 storvsc - ok
15:54:55.0156 0x0810 svsvc - ok
15:54:55.0171 0x0810 swenum - ok
15:54:55.0172 0x0810 swprv - ok
15:54:55.0174 0x0810 Synth3dVsc - ok
15:54:55.0176 0x0810 SysMain - ok
15:54:55.0177 0x0810 SystemEventsBroker - ok
15:54:55.0179 0x0810 TabletInputService - ok
15:54:55.0181 0x0810 TapiSrv - ok
15:54:55.0182 0x0810 Tcpip - ok
15:54:55.0184 0x0810 Tcpip6 - ok
15:54:55.0186 0x0810 tcpipreg - ok
15:54:55.0189 0x0810 tdx - ok
15:54:55.0268 0x0810 [ 8305FB462C325A67628E0556DF244B8B, 4ABD5D14E64BE07DD9332E39C3B902A40BD1E763A075F68F0048A7FAEB3019D5 ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
15:54:55.0343 0x0810 TeamViewer - ok
15:54:55.0349 0x0810 terminpt - ok
15:54:55.0351 0x0810 TermService - ok
15:54:55.0352 0x0810 Themes - ok
15:54:55.0354 0x0810 tiledatamodelsvc - ok
15:54:55.0356 0x0810 TimeBroker - ok
15:54:55.0357 0x0810 TPM - ok
15:54:55.0359 0x0810 TrkWks - ok
15:54:55.0361 0x0810 TrustedInstaller - ok
15:54:55.0365 0x0810 TsUsbFlt - ok
15:54:55.0367 0x0810 TsUsbGD - ok
15:54:55.0369 0x0810 tunnel - ok
15:54:55.0370 0x0810 uagp35 - ok
15:54:55.0372 0x0810 UASPStor - ok
15:54:55.0374 0x0810 UcmCx0101 - ok
15:54:55.0376 0x0810 UcmUcsi - ok
15:54:55.0377 0x0810 Ucx01000 - ok
15:54:55.0379 0x0810 UdeCx - ok
15:54:55.0381 0x0810 udfs - ok
15:54:55.0382 0x0810 UEFI - ok
15:54:55.0384 0x0810 Ufx01000 - ok
15:54:55.0386 0x0810 UfxChipidea - ok
15:54:55.0388 0x0810 ufxsynopsys - ok
15:54:55.0391 0x0810 UI0Detect - ok
15:54:55.0393 0x0810 uliagpkx - ok
15:54:55.0394 0x0810 umbus - ok
15:54:55.0396 0x0810 UmPass - ok
15:54:55.0398 0x0810 UmRdpService - ok
15:54:55.0400 0x0810 UnistoreSvc - ok
15:54:55.0402 0x0810 upnphost - ok
15:54:55.0404 0x0810 UrsChipidea - ok
15:54:55.0406 0x0810 UrsCx01000 - ok
15:54:55.0407 0x0810 UrsSynopsys - ok
15:54:55.0410 0x0810 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
15:54:55.0419 0x0810 USBAAPL64 - ok
15:54:55.0421 0x0810 usbaudio - ok
15:54:55.0423 0x0810 usbccgp - ok
15:54:55.0424 0x0810 usbcir - ok
15:54:55.0427 0x0810 usbehci - ok
15:54:55.0428 0x0810 usbhub - ok
15:54:55.0430 0x0810 USBHUB3 - ok
15:54:55.0432 0x0810 usbohci - ok
15:54:55.0434 0x0810 usbprint - ok
15:54:55.0436 0x0810 usbser - ok
15:54:55.0437 0x0810 USBSTOR - ok
15:54:55.0439 0x0810 usbuhci - ok
15:54:55.0441 0x0810 USBXHCI - ok
15:54:55.0443 0x0810 UserDataSvc - ok
15:54:55.0445 0x0810 UserManager - ok
15:54:55.0447 0x0810 UsoSvc - ok
15:54:55.0448 0x0810 VaultSvc - ok
15:54:55.0450 0x0810 vdrvroot - ok
15:54:55.0452 0x0810 vds - ok
15:54:55.0453 0x0810 VerifierExt - ok
15:54:55.0455 0x0810 vhdmp - ok
15:54:55.0457 0x0810 vhf - ok
15:54:55.0459 0x0810 vmbus - ok
15:54:55.0460 0x0810 VMBusHID - ok
15:54:55.0462 0x0810 vmicguestinterface - ok
15:54:55.0464 0x0810 vmicheartbeat - ok
15:54:55.0466 0x0810 vmickvpexchange - ok
15:54:55.0467 0x0810 vmicrdv - ok
15:54:55.0469 0x0810 vmicshutdown - ok
15:54:55.0470 0x0810 vmictimesync - ok
15:54:55.0472 0x0810 vmicvmsession - ok
15:54:55.0473 0x0810 vmicvss - ok
15:54:55.0475 0x0810 volmgr - ok
15:54:55.0477 0x0810 volmgrx - ok
15:54:55.0479 0x0810 volsnap - ok
15:54:55.0480 0x0810 vpci - ok
15:54:55.0482 0x0810 vsmraid - ok
15:54:55.0484 0x0810 VSS - ok
15:54:55.0485 0x0810 VSTXRAID - ok
15:54:55.0487 0x0810 vwifibus - ok
15:54:55.0489 0x0810 vwififlt - ok
15:54:55.0491 0x0810 W32Time - ok
15:54:55.0493 0x0810 w3logsvc - ok
15:54:55.0494 0x0810 W3SVC - ok
15:54:55.0496 0x0810 WacomPen - ok
15:54:55.0498 0x0810 WalletService - ok
15:54:55.0499 0x0810 wanarp - ok
15:54:55.0501 0x0810 wanarpv6 - ok
15:54:55.0503 0x0810 WAS - ok
15:54:55.0504 0x0810 wbengine - ok
15:54:55.0506 0x0810 WbioSrvc - ok
15:54:55.0508 0x0810 Wcmsvc - ok
15:54:55.0510 0x0810 wcncsvc - ok
15:54:55.0511 0x0810 WcsPlugInService - ok
15:54:55.0513 0x0810 WdBoot - ok
15:54:55.0515 0x0810 Wdf01000 - ok
15:54:55.0516 0x0810 WdFilter - ok
15:54:55.0518 0x0810 WdiServiceHost - ok
15:54:55.0520 0x0810 WdiSystemHost - ok
15:54:55.0521 0x0810 wdiwifi - ok
15:54:55.0523 0x0810 WdNisDrv - ok
15:54:55.0525 0x0810 WdNisSvc - ok
15:54:55.0527 0x0810 WebClient - ok
15:54:55.0528 0x0810 Wecsvc - ok
15:54:55.0530 0x0810 WEPHOSTSVC - ok
15:54:55.0532 0x0810 wercplsupport - ok
15:54:55.0533 0x0810 WerSvc - ok
15:54:55.0535 0x0810 wfpcapture - ok
15:54:55.0537 0x0810 WFPLWFS - ok
15:54:55.0538 0x0810 WiaRpc - ok
15:54:55.0540 0x0810 WIMMount - ok
15:54:55.0541 0x0810 WinDefend - ok
15:54:55.0545 0x0810 WindowsTrustedRT - ok
15:54:55.0547 0x0810 WindowsTrustedRTProxy - ok
15:54:55.0549 0x0810 WinHttpAutoProxySvc - ok
15:54:55.0551 0x0810 WinMad - ok
15:54:55.0555 0x0810 Winmgmt - ok
15:54:55.0556 0x0810 WinRM - ok
15:54:55.0559 0x0810 WINUSB - ok
15:54:55.0561 0x0810 WinVerbs - ok
15:54:55.0563 0x0810 WlanSvc - ok
15:54:55.0565 0x0810 wlidsvc - ok
15:54:55.0566 0x0810 WmiAcpi - ok
15:54:55.0569 0x0810 wmiApSrv - ok
15:54:55.0571 0x0810 WMPNetworkSvc - ok
15:54:55.0573 0x0810 Wof - ok
15:54:55.0575 0x0810 workfolderssvc - ok
15:54:55.0577 0x0810 wpcfltr - ok
15:54:55.0580 0x0810 WPDBusEnum - ok
15:54:55.0582 0x0810 WpdUpFltr - ok
15:54:55.0583 0x0810 WpnService - ok
15:54:55.0585 0x0810 ws2ifsl - ok
15:54:55.0587 0x0810 wscsvc - ok
15:54:55.0588 0x0810 WSDPrintDevice - ok
15:54:55.0590 0x0810 WSDScan - ok
15:54:55.0592 0x0810 WSearch - ok
15:54:55.0596 0x0810 WSService - ok
15:54:55.0597 0x0810 wuauserv - ok
15:54:55.0599 0x0810 WudfPf - ok
15:54:55.0601 0x0810 WUDFRd - ok
15:54:55.0603 0x0810 wudfsvc - ok
15:54:55.0604 0x0810 WUDFWpdFs - ok
15:54:55.0606 0x0810 WUDFWpdMtp - ok
15:54:55.0608 0x0810 WwanSvc - ok
15:54:55.0609 0x0810 XblAuthManager - ok
15:54:55.0611 0x0810 XblGameSave - ok
15:54:55.0614 0x0810 xboxgip - ok
15:54:55.0616 0x0810 XboxNetApiSvc - ok
15:54:55.0618 0x0810 xinputhid - ok
15:54:55.0619 0x0810 ================ Scan global ===============================
15:54:55.0626 0x0810 [ Global ] - ok
15:54:55.0626 0x0810 ================ Scan MBR ==================================
15:54:55.0627 0x0810 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
15:54:55.0652 0x0810 \Device\Harddisk1\DR1 - ok
15:54:55.0653 0x0810 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
15:54:55.0697 0x0810 \Device\Harddisk0\DR0 - ok
15:54:55.0697 0x0810 ================ Scan VBR ==================================
15:54:55.0698 0x0810 [ A3231EAAA0E80DEFC8DB538E8B06DF0B ] \Device\Harddisk1\DR1\Partition1
15:54:55.0699 0x0810 \Device\Harddisk1\DR1\Partition1 - ok
15:54:55.0700 0x0810 [ 8DE403B6B6D0A6C4A0B18AAF4A49487B ] \Device\Harddisk1\DR1\Partition2
15:54:55.0701 0x0810 \Device\Harddisk1\DR1\Partition2 - ok
15:54:55.0702 0x0810 [ F3C37D13917630C1CDB12EF7C57CB9A9 ] \Device\Harddisk0\DR0\Partition1
15:54:55.0743 0x0810 \Device\Harddisk0\DR0\Partition1 - ok
15:54:55.0744 0x0810 ================ Scan generic autorun ======================
15:54:55.0968 0x0810 [ 65E8545F1297CD83534C354A7BED1848, 19B3F3C17A335837454DC1851C6436D0BB2D8B1595AEB4DC71265FB20868B48F ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
15:54:56.0146 0x0810 RTHDVCPL - ok
15:54:56.0189 0x0810 [ 8F82FFC6CD0F4C83F4565E1A40332CCD, 45D17603664CBE2C4236AEDB3C21D585C8225A3D3B1118365EE2C6BFDB8A7890 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
15:54:56.0225 0x0810 NvBackend - ok
15:54:56.0227 0x0810 ShadowPlay - ok
15:54:56.0431 0x0810 [ 4914D5FCBE8C478DCCDCB58945EEFAFC, A59B49114429A4DB8789AD7DE35C44B8EED0BF5B39A1814512DD91DB2F94FCCB ] C:\Program Files\Logitech Gaming Software\LCore.exe
15:54:56.0617 0x0810 Launch LCore - ok
15:54:56.0696 0x0810 [ 6D44DE61A0BC7EE359D65992665C6432, 5A3C2D57A293B9BDD7CB1A4AA0ACF19374866F8A88EF132E350E5973CB4F7662 ] E:\Program Files\iTunes\iTunesHelper.exe
15:54:56.0710 0x0810 iTunesHelper - ok
15:54:56.0723 0x0810 [ 994B8BF5CA5FD971647DD9E41630973E, 062A8F2D3E40BC0D8B53030507AA04C348AB52843EF78ED63BDE5233C607BECA ] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology enterprise\IAStorIcon.exe
15:54:56.0736 0x0810 IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
15:54:59.0061 0x0810 Detect skipped due to KSN trusted
15:54:59.0061 0x0810 IAStorIcon - ok
15:54:59.0067 0x0810 [ 0E34B7BB1FCF22BCC1E394D16F9E992B, 382CA8E6BAC301E2F277F8EDA03D263FF71272796A8EED582C36294EEE9191F9 ] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe
15:54:59.0079 0x0810 GrooveMonitor - ok
15:54:59.0106 0x0810 [ C1A86A6D6847DEFF009EAE85BA0C1F20, 7DC2A823FA281117B335B74876469C788A5C81534251179BE86F3FB35F1B6D67 ] C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
15:54:59.0127 0x0810 avgnt - ok
15:54:59.0137 0x0810 [ F916BA0DA28A4B4F7B1ADE76EB42F088, FB3C91D44709D039E959B275F6ECE26AF9307D272FE3E25CC41EAC259AA3B596 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
15:54:59.0148 0x0810 SunJavaUpdateSched - ok
15:54:59.0168 0x0810 OneDriveSetup - ok
15:54:59.0169 0x0810 OneDriveSetup - ok
15:54:59.0200 0x0810 [ F34001FB7E4EA94D404339CD8B15D84C, 7E76FD43729CE6B6F29C2ED4F6B41BE3232390D9E6224F65AB506C0846BB557D ] C:\Users\Sven\AppData\Roaming\Spotify\SpotifyWebHelper.exe
15:54:59.0230 0x0810 Spotify Web Helper - ok
15:54:59.0356 0x0810 [ 86BF17A265E1B4BA41325623EC132E66, 4414B5F01A78B76BFC1A7C39F595645A09E674FA6DE7991F31BA6673EEB23F9E ] E:\Program Files (x86)\Steam\steam.exe
15:54:59.0397 0x0810 Steam - ok
15:54:59.0399 0x0810 OneDriveSetup - ok
15:54:59.0400 0x0810 Waiting for KSN requests completion. In queue: 48
15:55:00.0400 0x0810 Waiting for KSN requests completion. In queue: 48
15:55:01.0401 0x0810 Waiting for KSN requests completion. In queue: 48
15:55:01.0753 0x1098 Object required for P2P: [ 8305FB462C325A67628E0556DF244B8B ] TeamViewer
15:55:02.0401 0x0810 Waiting for KSN requests completion. In queue: 11
15:55:03.0401 0x0810 Waiting for KSN requests completion. In queue: 11
15:55:04.0345 0x1098 Object send P2P result: true
15:55:04.0417 0x0810 AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\Antivirus\wsctool.exe ( 15.0.13.202 ), 0x41000 ( enabled : updated )
15:55:04.0421 0x0810 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.8.10240.16384 ), 0x60100 ( disabled : updated )
15:55:04.0453 0x0810 Win FW state via NFP2: enabled ( trusted )
15:55:06.0868 0x0810 ============================================================
15:55:06.0868 0x0810 Scan finished
15:55:06.0868 0x0810 ============================================================
15:55:06.0881 0x05b0 Detected object count: 0
15:55:06.0881 0x05b0 Actual detected object count: 0 PS: Habe anhand des Email-Quellcodes herausgefunden dass meine Mails aus Ungarn und über eine weitere IP verschickt werden die ich nach mehreren Stationen in den USA nicht nachverfolgen kann. (Windows tracert CMD)
Gruß |