RoRo1405 | 10.05.2016 22:14 | Code:
23:11:49.0532 0x10c4 TDSS rootkit removing tool 3.1.0.9 Dec 11 2015 22:49:12
23:11:49.0532 0x10c4 UEFI system
23:11:55.0163 0x10c4 ============================================================
23:11:55.0163 0x10c4 Current date / time: 2016/05/10 23:11:55.0163
23:11:55.0163 0x10c4 SystemInfo:
23:11:55.0163 0x10c4
23:11:55.0163 0x10c4 OS Version: 10.0.10586 ServicePack: 0.0
23:11:55.0163 0x10c4 Product type: Workstation
23:11:55.0163 0x10c4 ComputerName: LAPTOP-S87BIA2R
23:11:55.0164 0x10c4 UserName: Robert
23:11:55.0164 0x10c4 Windows directory: C:\WINDOWS
23:11:55.0164 0x10c4 System windows directory: C:\WINDOWS
23:11:55.0164 0x10c4 Running under WOW64
23:11:55.0164 0x10c4 Processor architecture: Intel x64
23:11:55.0164 0x10c4 Number of processors: 4
23:11:55.0164 0x10c4 Page size: 0x1000
23:11:55.0164 0x10c4 Boot type: Normal boot
23:11:55.0164 0x10c4 ============================================================
23:11:55.0471 0x10c4 KLMD registered as C:\WINDOWS\system32\drivers\17563101.sys
23:11:55.0799 0x10c4 System UUID: {56976E3D-A306-6152-D65A-FE092CD6C095}
23:11:56.0282 0x10c4 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:11:57.0493 0x10c4 Drive \Device\Harddisk1\DR1 - Size: 0x3C5C00000 ( 15.09 Gb ), SectorSize: 0x200, Cylinders: 0x7B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
23:11:57.0497 0x10c4 ============================================================
23:11:57.0497 0x10c4 \Device\Harddisk0\DR0:
23:11:57.0497 0x10c4 GPT partitions:
23:11:57.0498 0x10c4 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {779C4D0D-5F6D-4B83-8397-4F1EBAF9090C}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x32000
23:11:57.0498 0x10c4 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {53B4C174-9BCE-4155-B961-9686E6E5B674}, Name: Microsoft reserved partition, StartLBA 0x32800, BlocksNum 0x8000
23:11:57.0498 0x10c4 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {E9A60CB4-32F5-4D17-A33D-504BB9273A2A}, Name: Basic data partition, StartLBA 0x3A800, BlocksNum 0x3BF79800
23:11:57.0498 0x10c4 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {2ADE2068-B4B2-4EDB-9EA5-D838DEDC30D5}, Name: Basic data partition, StartLBA 0x3BFB4000, BlocksNum 0x1F5F4000
23:11:57.0498 0x10c4 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {C345F56F-730C-47E6-B27E-D24A3F25122E}, Name: Basic data partition, StartLBA 0x5B5A8000, BlocksNum 0x19064000
23:11:57.0498 0x10c4 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {051411D2-B082-4244-9E4D-0D6A0C7B9C14}, Name: Basic data partition, StartLBA 0x7460C800, BlocksNum 0xFA000
23:11:57.0498 0x10c4 MBR partitions:
23:11:57.0498 0x10c4 \Device\Harddisk1\DR1:
23:11:57.0499 0x10c4 MBR partitions:
23:11:57.0499 0x10c4 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x2000, BlocksNum 0x1E2C000
23:11:57.0499 0x10c4 ============================================================
23:11:57.0514 0x10c4 C: <-> \Device\Harddisk0\DR0\Partition3
23:11:57.0533 0x10c4 E: <-> \Device\Harddisk0\DR0\Partition4
23:11:57.0587 0x10c4 F: <-> \Device\Harddisk0\DR0\Partition5
23:11:57.0587 0x10c4 ============================================================
23:11:57.0587 0x10c4 Initialize success
23:11:57.0587 0x10c4 ============================================================
23:12:47.0383 0x1f94 ============================================================
23:12:47.0383 0x1f94 Scan started
23:12:47.0383 0x1f94 Mode: Manual; SigCheck; TDLFS;
23:12:47.0383 0x1f94 ============================================================
23:12:47.0383 0x1f94 KSN ping started
23:12:49.0760 0x1f94 KSN ping finished: true
23:12:54.0228 0x1f94 ================ Scan system memory ========================
23:12:54.0228 0x1f94 System memory - ok
23:12:54.0229 0x1f94 ================ Scan services =============================
23:12:54.0370 0x1f94 1394ohci - ok
23:12:54.0376 0x1f94 3ware - ok
23:12:54.0396 0x1f94 ACPI - ok
23:12:54.0403 0x1f94 acpiex - ok
23:12:54.0408 0x1f94 acpipagr - ok
23:12:54.0420 0x1f94 AcpiPmi - ok
23:12:54.0426 0x1f94 acpitime - ok
23:12:54.0435 0x1f94 ADP80XX - ok
23:12:54.0452 0x1f94 AFD - ok
23:12:54.0457 0x1f94 agp440 - ok
23:12:54.0463 0x1f94 ahcache - ok
23:12:54.0498 0x1f94 AJRouter - ok
23:12:54.0515 0x1f94 ALG - ok
23:12:54.0521 0x1f94 AmdK8 - ok
23:12:54.0528 0x1f94 AmdPPM - ok
23:12:54.0538 0x1f94 amdsata - ok
23:12:54.0545 0x1f94 amdsbs - ok
23:12:54.0552 0x1f94 amdxata - ok
23:12:54.0564 0x1f94 AppID - ok
23:12:54.0570 0x1f94 AppIDSvc - ok
23:12:54.0574 0x1f94 Appinfo - ok
23:12:54.0659 0x1f94 [ 3B3774C868868257533EC7E715BB6D53, 4AF1DADCEDBD80BE6EDEC696DF59E65B51D31E33F4C84413CA03C7BD959FF4E5 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
23:12:54.0696 0x1f94 Apple Mobile Device Service - ok
23:12:54.0784 0x1f94 [ A45BBDFE644D9A9EBC79FF05C71BEF4D, E7576C109B8254BAE4028F7AFE58223BEFD8028A5F8D79E9CF36345245931BB1 ] applebmt C:\WINDOWS\system32\DRIVERS\applebmt.sys
23:12:54.0797 0x1f94 applebmt - ok
23:12:54.0808 0x1f94 AppReadiness - ok
23:12:54.0822 0x1f94 AppXSvc - ok
23:12:54.0826 0x1f94 arcsas - ok
23:12:54.0855 0x1f94 [ E4ABC023E251D2BB6B98C9FCAF5CF16D, 2A94320A3EF16E641B693BF6EABABB57C891B914B00F73ACD7ADB8CA5089EC40 ] aswTap C:\WINDOWS\System32\drivers\aswTap.sys
23:12:54.0875 0x1f94 aswTap - ok
23:12:54.0878 0x1f94 AsyncMac - ok
23:12:54.0881 0x1f94 atapi - ok
23:12:54.0942 0x1f94 [ F37EA5056B351F37CE6AB284DCF5AEDF, 2F2D8F27FBD0D1377D058CCE1405CD99F2E2CB73E5AF64193D1EFD707681792F ] AtherosSvc C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
23:12:54.0954 0x1f94 AtherosSvc - ok
23:12:55.0002 0x1f94 AudioEndpointBuilder - ok
23:12:55.0020 0x1f94 Audiosrv - ok
23:12:55.0064 0x1f94 [ 50C3C62FFE6337E6E4F2F01CB07DF63C, CC9C7D2827E872F22A2A79D42195530F61DF6EA6A1C8F520E25DB35537574FAB ] AVP16.0.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\avp.exe
23:12:55.0076 0x1f94 AVP16.0.0 - ok
23:12:55.0086 0x1f94 AxInstSV - ok
23:12:55.0101 0x1f94 b06bdrv - ok
23:12:55.0114 0x1f94 BasicDisplay - ok
23:12:55.0119 0x1f94 BasicRender - ok
23:12:55.0125 0x1f94 bcmfn - ok
23:12:55.0129 0x1f94 bcmfn2 - ok
23:12:55.0147 0x1f94 BDESVC - ok
23:12:55.0162 0x1f94 Beep - ok
23:12:55.0174 0x1f94 BFE - ok
23:12:55.0185 0x1f94 BITS - ok
23:12:55.0237 0x1f94 [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
23:12:55.0256 0x1f94 Bonjour Service - ok
23:12:55.0259 0x1f94 bowser - ok
23:12:55.0273 0x1f94 BrokerInfrastructure - ok
23:12:55.0276 0x1f94 Browser - ok
23:12:55.0318 0x1f94 [ 37213981212FE1EC4C7B0FBA3753B97A, E74C729764D32C21286D3698AFD01AC65B6CC08DC5E0BC7F7B67E0B2ADDEE27C ] BtFilter C:\WINDOWS\system32\DRIVERS\btfilter.sys
23:12:55.0337 0x1f94 BtFilter - ok
23:12:55.0353 0x1f94 BthAvrcpTg - ok
23:12:55.0355 0x1f94 BthEnum - ok
23:12:55.0359 0x1f94 BthHFEnum - ok
23:12:55.0363 0x1f94 bthhfhid - ok
23:12:55.0374 0x1f94 BthHFSrv - ok
23:12:55.0385 0x1f94 BthLEEnum - ok
23:12:55.0387 0x1f94 BTHMODEM - ok
23:12:55.0391 0x1f94 BthPan - ok
23:12:55.0408 0x1f94 BTHPORT - ok
23:12:55.0410 0x1f94 bthserv - ok
23:12:55.0429 0x1f94 BTHUSB - ok
23:12:55.0446 0x1f94 buttonconverter - ok
23:12:55.0456 0x1f94 CapImg - ok
23:12:55.0586 0x1f94 [ 41D709EB4211F6F6411F6105FA39518F, C8C95242BDD88B3FA5CBD1F235A80083B025B59FDAF2BA9040E21A8377BA6FA3 ] CCDMonitorService C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
23:12:55.0661 0x1f94 CCDMonitorService - ok
23:12:55.0667 0x1f94 cdfs - ok
23:12:55.0685 0x1f94 CDPSvc - ok
23:12:55.0688 0x1f94 cdrom - ok
23:12:55.0691 0x1f94 CertPropSvc - ok
23:12:55.0705 0x1f94 circlass - ok
23:12:55.0709 0x1f94 CLFS - ok
23:12:55.0863 0x1f94 [ 2B95B68B712ACEF2D14A3C25D0204635, 857A9EDEE32540DFD0FEB718EB0EB9DCFC9269A1A248D586B9D83A818B9485E6 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
23:12:55.0929 0x1f94 ClickToRunSvc - ok
23:12:55.0945 0x1f94 ClipSVC - ok
23:12:55.0954 0x1f94 CmBatt - ok
23:12:55.0972 0x1f94 [ B2A6D2A30E93B6F215F74AC7E1733C9C, 960299F7BF2501B46296EDEA050BF30313C17A9B785574B56B79C070BD1B6E1A ] cm_km C:\WINDOWS\system32\DRIVERS\cm_km.sys
23:12:55.0986 0x1f94 cm_km - ok
23:12:55.0993 0x1f94 CNG - ok
23:12:55.0997 0x1f94 cnghwassist - ok
23:12:56.0048 0x1f94 CompositeBus - ok
23:12:56.0051 0x1f94 COMSysApp - ok
23:12:56.0057 0x1f94 condrv - ok
23:12:56.0064 0x1f94 CoreMessagingRegistrar - ok
23:12:56.0116 0x1f94 [ 9A54DA0F7DC7203894023964D74DD8FE, DAF69668347BE05E4BCAB1443D66A05C751B6B8F261BAA78D6AE8CF17A08F57C ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
23:12:56.0132 0x1f94 cphs - ok
23:12:56.0148 0x1f94 CryptSvc - ok
23:12:56.0154 0x1f94 dam - ok
23:12:56.0159 0x1f94 DcomLaunch - ok
23:12:56.0173 0x1f94 DcpSvc - ok
23:12:56.0176 0x1f94 defragsvc - ok
23:12:56.0180 0x1f94 DeviceAssociationService - ok
23:12:56.0184 0x1f94 DeviceInstall - ok
23:12:56.0194 0x1f94 DevQueryBroker - ok
23:12:56.0206 0x1f94 Dfsc - ok
23:12:56.0208 0x1f94 Dhcp - ok
23:12:56.0241 0x1f94 diagnosticshub.standardcollector.service - ok
23:12:56.0270 0x1f94 DiagTrack - ok
23:12:56.0286 0x1f94 disk - ok
23:12:56.0299 0x1f94 DmEnrollmentSvc - ok
23:12:56.0305 0x1f94 dmvsc - ok
23:12:56.0322 0x1f94 dmwappushservice - ok
23:12:56.0338 0x1f94 Dnscache - ok
23:12:56.0342 0x1f94 dot3svc - ok
23:12:56.0345 0x1f94 DPS - ok
23:12:56.0367 0x1f94 drmkaud - ok
23:12:56.0387 0x1f94 DsmSvc - ok
23:12:56.0401 0x1f94 DsSvc - ok
23:12:56.0417 0x1f94 DXGKrnl - ok
23:12:56.0437 0x1f94 Eaphost - ok
23:12:56.0452 0x1f94 ebdrv - ok
23:12:56.0470 0x1f94 EFS - ok
23:12:56.0473 0x1f94 EhStorClass - ok
23:12:56.0487 0x1f94 EhStorTcgDrv - ok
23:12:56.0492 0x1f94 embeddedmode - ok
23:12:56.0494 0x1f94 EntAppSvc - ok
23:12:56.0675 0x1f94 [ B17FB7318D7CB8E315309F7484461369, 5D9E6464EDF3D8DA6D9CB2649E923B9DB1B0AA4EBF48A7E9CD64F8C9EAF9E56F ] ePowerSvc C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
23:12:56.0731 0x1f94 ePowerSvc - ok
23:12:56.0736 0x1f94 ErrDev - ok
23:12:56.0771 0x1f94 [ 3B32CAA07D672F8A2E0DF5CB3A873F45, 09687E30FA5779C3593769D66CAEBED95C932746EDD6E83DABE3DCFD126AB5EC ] EsgScanner C:\WINDOWS\system32\DRIVERS\EsgScanner.sys
23:12:56.0778 0x1f94 EsgScanner - ok
23:12:56.0805 0x1f94 [ DE746B8A003484E68ACF0F0FD9E177A1, 2FF895EF39FD923A390E851E4C34D10A4C067318C2D67CDA253C8BD440DCA0C8 ] ETDI2C C:\WINDOWS\system32\DRIVERS\ETDI2C.sys
23:12:56.0815 0x1f94 ETDI2C - ok
23:12:56.0835 0x1f94 EventSystem - ok
23:12:56.0850 0x1f94 exfat - ok
23:12:56.0854 0x1f94 fastfat - ok
23:12:56.0867 0x1f94 Fax - ok
23:12:56.0870 0x1f94 fdc - ok
23:12:56.0873 0x1f94 fdPHost - ok
23:12:56.0876 0x1f94 FDResPub - ok
23:12:56.0879 0x1f94 fhsvc - ok
23:12:56.0890 0x1f94 FileCrypt - ok
23:12:56.0892 0x1f94 FileInfo - ok
23:12:56.0895 0x1f94 Filetrace - ok
23:12:56.0899 0x1f94 flpydisk - ok
23:12:56.0902 0x1f94 FltMgr - ok
23:12:56.0906 0x1f94 FontCache - ok
23:12:56.0974 0x1f94 FontCache3.0.0.0 - ok
23:12:56.0984 0x1f94 FsDepends - ok
23:12:56.0996 0x1f94 Fs_Rec - ok
23:12:57.0003 0x1f94 fvevol - ok
23:12:57.0009 0x1f94 gagp30kx - ok
23:12:57.0026 0x1f94 gencounter - ok
23:12:57.0041 0x1f94 genericusbfn - ok
23:12:57.0117 0x1f94 [ 55FC14B287C6FF306C32B42628CE0D8C, F22D7BA248D616A76AFAC5DA21A419FF13BC4346F402685F6FC6671B04528110 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
23:12:57.0147 0x1f94 GfExperienceService - ok
23:12:57.0161 0x1f94 GPIOClx0101 - ok
23:12:57.0168 0x1f94 gpsvc - ok
23:12:57.0170 0x1f94 GpuEnergyDrv - ok
23:12:57.0183 0x1f94 HDAudBus - ok
23:12:57.0186 0x1f94 HidBatt - ok
23:12:57.0200 0x1f94 HidBth - ok
23:12:57.0203 0x1f94 hidi2c - ok
23:12:57.0207 0x1f94 hidinterrupt - ok
23:12:57.0211 0x1f94 HidIr - ok
23:12:57.0221 0x1f94 hidserv - ok
23:12:57.0224 0x1f94 HidUsb - ok
23:12:57.0243 0x1f94 HomeGroupListener - ok
23:12:57.0255 0x1f94 HomeGroupProvider - ok
23:12:57.0258 0x1f94 HpSAMD - ok
23:12:57.0275 0x1f94 HTTP - ok
23:12:57.0288 0x1f94 hwpolicy - ok
23:12:57.0291 0x1f94 hyperkbd - ok
23:12:57.0295 0x1f94 i8042prt - ok
23:12:57.0300 0x1f94 iai2c - ok
23:12:57.0307 0x1f94 iaLPSS2i_I2C - ok
23:12:57.0312 0x1f94 iaLPSSi_GPIO - ok
23:12:57.0316 0x1f94 iaLPSSi_I2C - ok
23:12:57.0375 0x1f94 [ 12859E1215AA083A42E7ADCDE5C061D1, 262F9C65C3FA7EB69C4FA7C6547E1C79DB49697A083309909BC78726A116557F ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
23:12:57.0410 0x1f94 iaStorA - ok
23:12:57.0415 0x1f94 iaStorAV - ok
23:12:57.0420 0x1f94 iaStorV - ok
23:12:57.0425 0x1f94 ibbus - ok
23:12:57.0459 0x1f94 icssvc - ok
23:12:57.0462 0x1f94 IEEtwCollectorService - ok
23:12:57.0684 0x1f94 [ 765C558B70E6838C040EFE008C5564C3, D9216F4D7AA1B22E5CD784A699596D3CAF85272898B597F4804F0CEE1B699327 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
23:12:57.0842 0x1f94 igfx - ok
23:12:57.0884 0x1f94 [ A87D71C508CDC0AFCEDD42E99CAEEAB3, 54666D1428C6FFAA2539506D2B38B1B4468EA208CAA61D3275EE39C3EDD6424A ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
23:12:57.0903 0x1f94 igfxCUIService2.0.0.0 - ok
23:12:57.0910 0x1f94 IKEEXT - ok
23:12:58.0062 0x1f94 [ D172E06EFE08DF148155A59DB716C1B6, F059B0B37C5E944D70626E9F029BC6311029E0A9D778C9C75DDDDC59A5AF1605 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
23:12:58.0156 0x1f94 IntcAzAudAddService - ok
23:12:58.0204 0x1f94 [ 42777B7BE4946135578E5C3BC1D2E4AD, CE4FF334238D0A98139676420E770A42DC0F5567F49D618B56CD55417F556D05 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
23:12:58.0220 0x1f94 IntcDAud - ok
23:12:58.0319 0x1f94 [ B63CF22D1AD2ABDC39D85851B2BEAA6D, 37E9043BABB5895BFD2B59AFB60C438B992C6EAA1B5FDE5B3445314343F4C406 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
23:12:58.0348 0x1f94 Intel(R) Capability Licensing Service TCP IP Interface - ok
23:12:58.0396 0x1f94 [ 8213094EA736A9C575AB0E22AD09B0BA, 12670A466B5AA37283BD4CB481D000DE3AE2A8D1BD159F67A41703A6FE5675EC ] Intel(R) Security Assist C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
23:12:58.0419 0x1f94 Intel(R) Security Assist - detected UnsignedFile.Multi.Generic ( 1 )
23:13:00.0864 0x1f94 Detect skipped due to KSN trusted
23:13:00.0864 0x1f94 Intel(R) Security Assist - ok
23:13:00.0875 0x1f94 intelide - ok
23:13:00.0888 0x1f94 intelpep - ok
23:13:00.0897 0x1f94 intelppm - ok
23:13:00.0906 0x1f94 IoQos - ok
23:13:00.0919 0x1f94 IpFilterDriver - ok
23:13:00.0937 0x1f94 iphlpsvc - ok
23:13:00.0947 0x1f94 IPMIDRV - ok
23:13:00.0952 0x1f94 IPNAT - ok
23:13:00.0988 0x1f94 [ F96B9EDC032E61EB87652896E92ED526, F9E3CD2FA2D963C56034A4F606869467FDC6647B916CF457249270E6C337A8A5 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
23:13:01.0010 0x1f94 iPod Service - ok
23:13:01.0014 0x1f94 IRENUM - ok
23:13:01.0024 0x1f94 [ 1DFC3CCA51785254C5604238BB1A5467, 31451A90A91AEE14C6B24F84CB9816E5C77179D411B8B3E8547F538235BEEFB0 ] isaHelperSvc C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
23:13:01.0028 0x1f94 isaHelperSvc - detected UnsignedFile.Multi.Generic ( 1 )
23:13:03.0166 0x0568 Object required for P2P: [ 41D709EB4211F6F6411F6105FA39518F ] CCDMonitorService
23:13:03.0457 0x1f94 Detect skipped due to KSN trusted
23:13:03.0457 0x1f94 isaHelperSvc - ok
23:13:03.0464 0x1f94 isapnp - ok
23:13:03.0474 0x1f94 iScsiPrt - ok
23:13:03.0514 0x1f94 [ 51054A35D0303B0466F2031DAFDCE302, C02CB422BA3451C89D9524068D4F6B72073337035EC08C11397931A16E11590A ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
23:13:03.0533 0x1f94 jhi_service - ok
23:13:03.0537 0x1f94 kbdclass - ok
23:13:03.0541 0x1f94 kbdhid - ok
23:13:03.0544 0x1f94 kdnic - ok
23:13:03.0549 0x1f94 KeyIso - ok
23:13:03.0586 0x1f94 [ BEE1682DA217A4AD46C36896769AA580, 4D853D78E459F7BFE4F4217FCAD47CDACFAC19C2F6CF8261FBAA46BDB387FFDC ] kl1 C:\WINDOWS\system32\DRIVERS\kl1.sys
23:13:03.0604 0x1f94 kl1 - ok
23:13:03.0610 0x1f94 [ 86F40D79CE80ACBE6BEBAC8CE89D75A0, 8B800425160D1AF3C32EF7B5CA794658EE09CD3EE782473D8D38E1C7706076B3 ] klbackupdisk C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys
23:13:03.0618 0x1f94 klbackupdisk - ok
23:13:03.0623 0x1f94 [ 2B4BC41223326FF440E2DB32B9239138, E95D5BB3388D6B219A4C175D5DA77CEB620A27A13F5AA4E7E2C05694B6E26947 ] klbackupflt C:\WINDOWS\system32\DRIVERS\klbackupflt.sys
23:13:03.0634 0x1f94 klbackupflt - ok
23:13:03.0663 0x1f94 [ 80D7529E1CF09261FADF55E69EFDA90B, 2FE5EC38866E12D78AE3F4AD8CF647BDED616E8A36D9D737F9B6564DDA4685E7 ] kldisk C:\WINDOWS\system32\DRIVERS\kldisk.sys
23:13:03.0671 0x1f94 kldisk - ok
23:13:03.0696 0x1f94 [ E2097C8F18F1E8E3B7D09F12B51843A3, 0506A99BD0962AAE64692BD7F080DB080F8B678DC59685CF22830A47B486430C ] klelam C:\WINDOWS\system32\DRIVERS\klelam.sys
23:13:03.0709 0x1f94 klelam - ok
23:13:03.0730 0x1f94 [ BACE50477C184A3AA0755702C23B8B27, 5708A1B7C22702AD2E5DD4491A911A51D2FB768E46857639C0C5D8736E487D0F ] klflt C:\WINDOWS\system32\DRIVERS\klflt.sys
23:13:03.0740 0x1f94 klflt - ok
23:13:03.0768 0x1f94 [ 0698A6918DAF5B1710F5A5170C34FC03, 15CBA4089950812A5815D7517B6C25959A793A55A66F8AA6746618D42A849351 ] klhk C:\WINDOWS\system32\DRIVERS\klhk.sys
23:13:03.0778 0x1f94 klhk - ok
23:13:03.0828 0x1f94 [ 3DC953B77F13031C7763464FC0AD1E71, B0142B8A9FB5889D7F76E16EA26F1EA9BC7F1770226CD139B3C932671EBD802B ] KLIF C:\WINDOWS\system32\DRIVERS\klif.sys
23:13:03.0852 0x1f94 KLIF - ok
23:13:03.0886 0x1f94 [ E62321376344231F5F488758ACC6D553, 1155C1FDD5C95B05EABBD4268A7D3FFF050D0C0921B61226179C312605AB46C3 ] KLIM6 C:\WINDOWS\system32\DRIVERS\klim6.sys
23:13:03.0892 0x1f94 KLIM6 - ok
23:13:03.0907 0x1f94 [ DAE5768E6FD34A36E3B9D1AF1FCA682B, 24DA0B71E3B4AC0FABEE0BF687DF8D35283DBF808CA3AB6F86E72B37471F6B33 ] klkbdflt C:\WINDOWS\system32\DRIVERS\klkbdflt.sys
23:13:03.0914 0x1f94 klkbdflt - ok
23:13:03.0920 0x1f94 klkbdflt2 - ok
23:13:03.0939 0x1f94 [ FD47C92A63B6EADEA830BFA96C06EAEE, C15C39B6FA53CBD01A2F95243845C4B706B4229F8FFB75C7128819B9CEE5B2CB ] klmouflt C:\WINDOWS\system32\DRIVERS\klmouflt.sys
23:13:03.0945 0x1f94 klmouflt - ok
23:13:03.0972 0x1f94 [ F610F5F17BC87D61EF8954CCD793BAE4, A77FE26B4A474FE799C3D569BDD7858319C57FC14C1BB43ECFAB1FDB19AF5DC6 ] klpd C:\WINDOWS\system32\DRIVERS\klpd.sys
23:13:03.0980 0x1f94 klpd - ok
23:13:03.0987 0x1f94 [ 26D3895A519220E94D241A8858D40CD9, CBDE2B937D2897FC2F356F73D983023F7CBE3C9E8A2873877E5CAF40F3D9A680 ] klwfp C:\WINDOWS\system32\DRIVERS\klwfp.sys
23:13:03.0996 0x1f94 klwfp - ok
23:13:04.0020 0x1f94 [ 91234D71CEED29F2DBA16942CABDCA4F, 5D71BAC86C33BC77EEBF1ECB8F372DFE631991E4C5F36EAF0C8C957150BD6D52 ] Klwtp C:\WINDOWS\system32\DRIVERS\klwtp.sys
23:13:04.0028 0x1f94 Klwtp - ok
23:13:04.0036 0x1f94 [ 1686DE8288052316EFDD49EEA8929065, AD43D6ACCD8693BD76F218E1A4EE088BA061C1309A3E7DAA7EC94D875985D895 ] kneps C:\WINDOWS\system32\DRIVERS\kneps.sys
23:13:04.0046 0x1f94 kneps - ok
23:13:04.0057 0x1f94 KSecDD - ok
23:13:04.0068 0x1f94 KSecPkg - ok
23:13:04.0071 0x1f94 ksthunk - ok
23:13:04.0096 0x1f94 KtmRm - ok
23:13:04.0105 0x1f94 LanmanServer - ok
23:13:04.0109 0x1f94 LanmanWorkstation - ok
23:13:04.0118 0x1f94 lfsvc - ok
23:13:04.0122 0x1f94 LicenseManager - ok
23:13:04.0129 0x1f94 lltdio - ok
23:13:04.0142 0x1f94 lltdsvc - ok
23:13:04.0175 0x1f94 [ 595FBB84D5E62AE8629ED0F6179818A7, 6BF747A759425BDC1080888B6D9C4611B55020A64B67AC1486DB8C4E70B16A9D ] LMDriver C:\WINDOWS\System32\drivers\LMDriver.sys
23:13:04.0181 0x1f94 LMDriver - ok
23:13:04.0199 0x1f94 lmhosts - ok
23:13:04.0249 0x1f94 [ 36E02306E8697940D42C1DDA1CD1CE2A, BF98F2978FCFD13D8A7CC16AA0F8015DBDF14C92206C55FAF1EDB89728F5DC81 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
23:13:04.0266 0x1f94 LMS - ok
23:13:04.0279 0x1f94 LSI_SAS - ok
23:13:04.0292 0x1f94 LSI_SAS2i - ok
23:13:04.0296 0x1f94 LSI_SAS3i - ok
23:13:04.0300 0x1f94 LSI_SSS - ok
23:13:04.0303 0x1f94 LSM - ok
23:13:04.0307 0x1f94 luafv - ok
23:13:04.0318 0x1f94 MapsBroker - ok
23:13:04.0320 0x1f94 megasas - ok
23:13:04.0323 0x1f94 megasr - ok
23:13:04.0356 0x1f94 [ 5AC258A5845A72B91C675F44050058B2, 69D298B5774F299DE2EECF7B9238BFD36CDC0BAFB167FD0927398E4A89A5D63B ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
23:13:04.0366 0x1f94 MEIx64 - ok
23:13:04.0386 0x1f94 MessagingService - ok
23:13:04.0467 0x1f94 mlx4_bus - ok
23:13:04.0484 0x1f94 MMCSS - ok
23:13:04.0493 0x1f94 Modem - ok
23:13:04.0497 0x1f94 monitor - ok
23:13:04.0504 0x1f94 mouclass - ok
23:13:04.0508 0x1f94 mouhid - ok
23:13:04.0512 0x1f94 mountmgr - ok
23:13:04.0518 0x1f94 mpsdrv - ok
23:13:04.0547 0x1f94 MpsSvc - ok
23:13:04.0556 0x1f94 MRxDAV - ok
23:13:04.0571 0x1f94 mrxsmb - ok
23:13:04.0578 0x1f94 mrxsmb10 - ok
23:13:04.0580 0x1f94 mrxsmb20 - ok
23:13:04.0592 0x1f94 MsBridge - ok
23:13:04.0607 0x1f94 MSDTC - ok
23:13:04.0612 0x1f94 Msfs - ok
23:13:04.0629 0x1f94 msgpiowin32 - ok
23:13:04.0636 0x1f94 mshidkmdf - ok
23:13:04.0641 0x1f94 mshidumdf - ok
23:13:04.0646 0x1f94 msisadrv - ok
23:13:04.0668 0x1f94 MSiSCSI - ok
23:13:04.0673 0x1f94 msiserver - ok
23:13:04.0677 0x1f94 MSKSSRV - ok
23:13:04.0681 0x1f94 MsLldp - ok
23:13:04.0700 0x1f94 MSPCLOCK - ok
23:13:04.0705 0x1f94 MSPQM - ok
23:13:04.0708 0x1f94 MsRPC - ok
23:13:04.0713 0x1f94 mssmbios - ok
23:13:04.0719 0x1f94 MSTEE - ok
23:13:04.0723 0x1f94 MTConfig - ok
23:13:04.0726 0x1f94 Mup - ok
23:13:04.0730 0x1f94 mvumis - ok
23:13:04.0751 0x1f94 NativeWifiP - ok
23:13:04.0775 0x1f94 NcaSvc - ok
23:13:04.0786 0x1f94 NcbService - ok
23:13:04.0790 0x1f94 NcdAutoSetup - ok
23:13:04.0794 0x1f94 ndfltr - ok
23:13:04.0798 0x1f94 NDIS - ok
23:13:04.0804 0x1f94 NdisCap - ok
23:13:04.0808 0x1f94 NdisImPlatform - ok
23:13:04.0812 0x1f94 NdisTapi - ok
23:13:04.0817 0x1f94 Ndisuio - ok
23:13:04.0821 0x1f94 NdisVirtualBus - ok
23:13:04.0825 0x1f94 NdisWan - ok
23:13:04.0828 0x1f94 ndiswanlegacy - ok
23:13:04.0831 0x1f94 ndproxy - ok
23:13:04.0836 0x1f94 Ndu - ok
23:13:04.0839 0x1f94 NetBIOS - ok
23:13:04.0844 0x1f94 NetBT - ok
23:13:04.0847 0x1f94 Netlogon - ok
23:13:04.0866 0x1f94 Netman - ok
23:13:04.0869 0x1f94 netprofm - ok
23:13:04.0884 0x1f94 NetSetupSvc - ok
23:13:04.0907 0x1f94 NetTcpPortSharing - ok
23:13:04.0912 0x1f94 NgcCtnrSvc - ok
23:13:04.0934 0x1f94 NgcSvc - ok
23:13:04.0941 0x1f94 NlaSvc - ok
23:13:04.0947 0x1f94 Npfs - ok
23:13:04.0962 0x1f94 npsvctrig - ok
23:13:04.0967 0x1f94 nsi - ok
23:13:04.0974 0x1f94 nsiproxy - ok
23:13:04.0995 0x1f94 NTFS - ok
23:13:04.0999 0x1f94 Null - ok
23:13:05.0316 0x1f94 [ AEEA2EC9CEEB8ADE8284583BBB98AB0D, AB629C047EFB8F5CF13FF923C332A05CD3F510A8C07D2EA6D3C493E2533DB1E0 ] nvlddmkm C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys
23:13:05.0537 0x1f94 nvlddmkm - ok
23:13:05.0639 0x1f94 [ DCAA93D28D6FC75A4D80AE410008BA90, 7EDB69747C95FB68A4DF1932CF45E078DE94364D7A37D83A29952977A41D1FD7 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
23:13:05.0646 0x0568 Object send P2P result: true
23:13:05.0682 0x1f94 NvNetworkService - ok
23:13:05.0687 0x1f94 nvraid - ok
23:13:05.0692 0x1f94 nvstor - ok
23:13:05.0751 0x1f94 [ 9408391358F3B9FD0F59E27151383C51, 777A41DE1D8D71833369D1335A083BA8F197317CB62D0E65EFFCC9760D84F2AB ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
23:13:05.0763 0x1f94 NvStreamKms - ok
23:13:05.0770 0x1f94 NvStreamSvc - ok
23:13:05.0849 0x1f94 [ 1B44B5244EAF26BEC315AE84B0AFFC66, 760F376FFF7665E32718E890387CA2404D70DED2D2694A1647483722287D01B8 ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
23:13:05.0882 0x1f94 nvsvc - ok
23:13:05.0914 0x1f94 [ 6AC68DDFCAC19A300D738AF3493E46AA, 4E92215B6E3ED263E89489851C6FEAD08D3155C82A74E880DA460DED0021DF42 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
23:13:05.0921 0x1f94 nvvad_WaveExtensible - ok
23:13:05.0924 0x1f94 nv_agp - ok
23:13:05.0944 0x1f94 OneSyncSvc - ok
23:13:06.0052 0x1f94 [ 133447A27BFA334B0EFE25359D3DF580, C97C18A3EEB6489CAA240E00211905B423DF4F17F075A7160F6534BDC4888900 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:13:06.0082 0x1f94 ose - detected UnsignedFile.Multi.Generic ( 1 )
23:13:08.0620 0x1f94 ose ( UnsignedFile.Multi.Generic ) - warning
23:13:08.0620 0x1f94 Force sending object to P2P due to detect: ose
23:13:11.0055 0x1f94 Object send P2P result: true
23:13:13.0471 0x1f94 p2pimsvc - ok
23:13:13.0480 0x1f94 p2psvc - ok
23:13:13.0518 0x1f94 Parport - ok
23:13:13.0534 0x1f94 partmgr - ok
23:13:13.0537 0x1f94 PcaSvc - ok
23:13:13.0543 0x1f94 pci - ok
23:13:13.0547 0x1f94 pciide - ok
23:13:13.0552 0x1f94 pcmcia - ok
23:13:13.0557 0x1f94 pcw - ok
23:13:13.0561 0x1f94 pdc - ok
23:13:13.0572 0x1f94 PEAUTH - ok
23:13:13.0580 0x1f94 percsas2i - ok
23:13:13.0584 0x1f94 percsas3i - ok
23:13:13.0629 0x1f94 PerfHost - ok
23:13:13.0659 0x1f94 PhoneSvc - ok
23:13:13.0674 0x1f94 PimIndexMaintenanceSvc - ok
23:13:13.0714 0x1f94 pla - ok
23:13:13.0726 0x1f94 PlugPlay - ok
23:13:13.0729 0x1f94 PNRPAutoReg - ok
23:13:13.0733 0x1f94 PNRPsvc - ok
23:13:13.0740 0x1f94 PolicyAgent - ok
23:13:13.0744 0x1f94 Power - ok
23:13:13.0756 0x1f94 PptpMiniport - ok
23:13:13.0936 0x1f94 [ 959F94AD1255BC749884EDDD14EC29C4, 2CD6DA9778EA36FA0B4080F6DB1C634712238E014E47546403CD3CDB35A1DCA8 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
23:13:14.0042 0x1f94 PrintNotify - ok
23:13:14.0049 0x1f94 Processor - ok
23:13:14.0086 0x1f94 ProfSvc - ok
23:13:14.0104 0x1f94 Psched - ok
23:13:14.0207 0x1f94 [ D76F885983B04E8BE2D1BDEF118A097E, 34D293F7E9D2E4BF43B2BB575D77E6A8D45D54C22F8F0214EA26712BE6CE9A49 ] Qcamain C:\WINDOWS\System32\drivers\Qcamainx64.sys
23:13:14.0278 0x1f94 Qcamain - detected UnsignedFile.Multi.Generic ( 1 )
23:13:16.0728 0x1f94 Detect skipped due to KSN trusted
23:13:16.0728 0x1f94 Qcamain - ok
23:13:16.0745 0x1f94 Qcamain10x64 - ok
23:13:16.0772 0x1f94 QWAVE - ok
23:13:16.0774 0x1f94 QWAVEdrv - ok
23:13:16.0805 0x1f94 [ 29EF474475CA406FF5B14D6B434F1ECE, A09ABDCE77FF45E0FEB826E96C9F54A5BC6699BF644C8816BAF4CA5630C9D44E ] RadioShim C:\WINDOWS\System32\drivers\RadioShim.sys
23:13:16.0811 0x1f94 RadioShim - ok
23:13:16.0828 0x1f94 RasAcd - ok
23:13:16.0842 0x1f94 RasAgileVpn - ok
23:13:16.0855 0x1f94 RasAuto - ok
23:13:16.0863 0x1f94 Rasl2tp - ok
23:13:16.0878 0x1f94 RasMan - ok
23:13:16.0882 0x1f94 RasPppoe - ok
23:13:16.0886 0x1f94 RasSstp - ok
23:13:16.0889 0x1f94 rdbss - ok
23:13:16.0894 0x1f94 rdpbus - ok
23:13:16.0899 0x1f94 RDPDR - ok
23:13:16.0905 0x1f94 RdpVideoMiniport - ok
23:13:16.0909 0x1f94 rdyboost - ok
23:13:16.0923 0x1f94 ReFSv1 - ok
23:13:16.0935 0x1f94 RemoteAccess - ok
23:13:16.0938 0x1f94 RemoteRegistry - ok
23:13:16.0960 0x1f94 RetailDemo - ok
23:13:16.0967 0x1f94 RFCOMM - ok
23:13:16.0971 0x1f94 RpcEptMapper - ok
23:13:16.0982 0x1f94 RpcLocator - ok
23:13:16.0986 0x1f94 RpcSs - ok
23:13:16.0990 0x1f94 rspndr - ok
23:13:17.0038 0x1f94 [ 12A3D1530E3F67B8664EBA923A3981E4, 8670C39EB0A7C37C17D014A8917493B776DE0829B55EFED13D91B6FA7B81CA11 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
23:13:17.0062 0x1f94 rt640x64 - ok
23:13:17.0081 0x1f94 [ 87CCF37EC2858FCF7689F8FC0B72F39A, 60B71BDC7388887AC7EB2C869DEAF86DD06B7EB9DEE3CF4F4DFE2D1BCE3BDAA8 ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
23:13:17.0095 0x1f94 RTSUER - ok
23:13:17.0098 0x1f94 s3cap - ok
23:13:17.0103 0x1f94 SamSs - ok
23:13:17.0136 0x1f94 [ 328100AF2EFD951EAB657384EC361B6F, 2DECBF74E13511395AA13F931F06F4D557E67654DA3314D0095C332FB758B4D9 ] SamsungAllShareV2.0 C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe
23:13:17.0142 0x1f94 SamsungAllShareV2.0 - ok
23:13:17.0153 0x1f94 sbp2port - ok
23:13:17.0196 0x1f94 SCardSvr - ok
23:13:17.0199 0x1f94 ScDeviceEnum - ok
23:13:17.0204 0x1f94 scfilter - ok
23:13:17.0222 0x1f94 Schedule - ok
23:13:17.0239 0x1f94 SCPolicySvc - ok
23:13:17.0249 0x1f94 sdbus - ok
23:13:17.0251 0x1f94 SDRSVC - ok
23:13:17.0264 0x1f94 sdstor - ok
23:13:17.0276 0x1f94 seclogon - ok
23:13:17.0280 0x1f94 SENS - ok
23:13:17.0295 0x1f94 SensorDataService - ok
23:13:17.0320 0x1f94 SensorService - ok
23:13:17.0324 0x1f94 SensrSvc - ok
23:13:17.0343 0x1f94 SerCx - ok
23:13:17.0359 0x1f94 SerCx2 - ok
23:13:17.0380 0x1f94 Serenum - ok
23:13:17.0392 0x1f94 Serial - ok
23:13:17.0403 0x1f94 sermouse - ok
23:13:17.0425 0x1f94 SessionEnv - ok
23:13:17.0429 0x1f94 sfloppy - ok
23:13:17.0443 0x1f94 SharedAccess - ok
23:13:17.0448 0x1f94 ShellHWDetection - ok
23:13:17.0466 0x1f94 [ 1980FE1F5A32067DAD1D8776B63C2669, 26B53EAF89CDBBA8FFA154DBB1F1DA348F894FE1F1D0CA4060E32496464DD5D2 ] SimpleSlideShowServer C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe
23:13:17.0471 0x1f94 SimpleSlideShowServer - ok
23:13:17.0474 0x1f94 SiSRaid2 - ok
23:13:17.0479 0x1f94 SiSRaid4 - ok
23:13:17.0505 0x1f94 [ 3E98CE04689597C76B3EF4D3D0323836, F7FFF675066281190C236F2995EB003A1779231E5164EEE6BEE334A4240B1DF9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
23:13:17.0531 0x1f94 SkypeUpdate - ok
23:13:17.0543 0x1f94 smphost - ok
23:13:17.0574 0x1f94 SmsRouter - ok
23:13:17.0594 0x1f94 SNMPTRAP - ok
23:13:17.0610 0x1f94 spaceport - ok
23:13:17.0616 0x1f94 SpbCx - ok
23:13:17.0642 0x1f94 Spooler - ok
23:13:17.0646 0x1f94 sppsvc - ok
23:13:17.0651 0x1f94 srv - ok
23:13:17.0655 0x1f94 srv2 - ok
23:13:17.0659 0x1f94 srvnet - ok
23:13:17.0675 0x1f94 SSDPSRV - ok
23:13:17.0699 0x1f94 SstpSvc - ok
23:13:17.0715 0x1f94 StateRepository - ok
23:13:17.0717 0x1f94 stexstor - ok
23:13:17.0723 0x1f94 stisvc - ok
23:13:17.0726 0x1f94 storahci - ok
23:13:17.0742 0x1f94 storflt - ok
23:13:17.0745 0x1f94 stornvme - ok
23:13:17.0749 0x1f94 storqosflt - ok
23:13:17.0765 0x1f94 StorSvc - ok
23:13:17.0768 0x1f94 storufs - ok
23:13:17.0771 0x1f94 storvsc - ok
23:13:17.0786 0x1f94 svsvc - ok
23:13:17.0789 0x1f94 swenum - ok
23:13:17.0794 0x1f94 swprv - ok
23:13:17.0815 0x1f94 Synth3dVsc - ok
23:13:17.0831 0x1f94 SysMain - ok
23:13:17.0836 0x1f94 SystemEventsBroker - ok
23:13:17.0851 0x1f94 TabletInputService - ok
23:13:17.0853 0x1f94 TapiSrv - ok
23:13:17.0862 0x1f94 Tcpip - ok
23:13:17.0864 0x1f94 Tcpip6 - ok
23:13:17.0870 0x1f94 tcpipreg - ok
23:13:17.0887 0x1f94 tdx - ok
23:13:17.0890 0x1f94 terminpt - ok
23:13:17.0901 0x1f94 TermService - ok
23:13:17.0904 0x1f94 Themes - ok
23:13:17.0916 0x1f94 TieringEngineService - ok
23:13:17.0924 0x1f94 tiledatamodelsvc - ok
23:13:17.0947 0x1f94 TimeBroker - ok
23:13:18.0006 0x1f94 TPM - ok
23:13:18.0010 0x1f94 TrkWks - ok
23:13:18.0036 0x1f94 TrustedInstaller - ok
23:13:18.0041 0x1f94 tsusbflt - ok
23:13:18.0045 0x1f94 TsUsbGD - ok
23:13:18.0056 0x1f94 tunnel - ok
23:13:18.0079 0x1f94 tzautoupdate - ok
23:13:18.0082 0x1f94 uagp35 - ok
23:13:18.0085 0x1f94 UASPStor - ok
23:13:18.0089 0x1f94 UcmCx0101 - ok
23:13:18.0094 0x1f94 UcmUcsi - ok
23:13:18.0098 0x1f94 Ucx01000 - ok
23:13:18.0101 0x1f94 UdeCx - ok
23:13:18.0104 0x1f94 udfs - ok
23:13:18.0108 0x1f94 UEFI - ok
23:13:18.0179 0x1f94 [ AD53262AFF486D28190439D3A59C80F7, 9A57AA4BD93392894110B344CAB884476A2F107442FAB6E840178BE544B5CC6E ] UEIPSvc C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
23:13:18.0206 0x1f94 UEIPSvc - ok
23:13:18.0228 0x1f94 Ufx01000 - ok
23:13:18.0241 0x1f94 UfxChipidea - ok
23:13:18.0244 0x1f94 ufxsynopsys - ok
23:13:18.0259 0x1f94 UI0Detect - ok
23:13:18.0263 0x1f94 uliagpkx - ok
23:13:18.0268 0x1f94 umbus - ok
23:13:18.0271 0x1f94 UmPass - ok
23:13:18.0284 0x1f94 UmRdpService - ok
23:13:18.0294 0x1f94 UnistoreSvc - ok
23:13:18.0339 0x1f94 upnphost - ok
23:13:18.0357 0x1f94 UrsChipidea - ok
23:13:18.0360 0x1f94 UrsCx01000 - ok
23:13:18.0364 0x1f94 UrsSynopsys - ok
23:13:18.0386 0x1f94 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
23:13:18.0398 0x1f94 USBAAPL64 - ok
23:13:18.0406 0x1f94 usbccgp - ok
23:13:18.0409 0x1f94 usbcir - ok
23:13:18.0412 0x1f94 usbehci - ok
23:13:18.0416 0x1f94 usbhub - ok
23:13:18.0431 0x1f94 USBHUB3 - ok
23:13:18.0433 0x1f94 usbohci - ok
23:13:18.0436 0x1f94 usbprint - ok
23:13:18.0449 0x1f94 usbser - ok
23:13:18.0452 0x1f94 USBSTOR - ok
23:13:18.0457 0x1f94 usbuhci - ok
23:13:18.0461 0x1f94 usbvideo - ok
23:13:18.0469 0x1f94 USBXHCI - ok
23:13:18.0495 0x1f94 UserDataSvc - ok
23:13:18.0508 0x1f94 UserManager - ok
23:13:18.0518 0x1f94 UsoSvc - ok
23:13:18.0520 0x1f94 VaultSvc - ok
23:13:18.0523 0x1f94 vdrvroot - ok
23:13:18.0534 0x1f94 vds - ok
23:13:18.0537 0x1f94 VerifierExt - ok
23:13:18.0540 0x1f94 vhdmp - ok
23:13:18.0543 0x1f94 vhf - ok
23:13:18.0547 0x1f94 vmbus - ok
23:13:18.0552 0x1f94 VMBusHID - ok
23:13:18.0580 0x1f94 vmicguestinterface - ok
23:13:18.0598 0x1f94 vmicheartbeat - ok
23:13:18.0601 0x1f94 vmickvpexchange - ok
23:13:18.0604 0x1f94 vmicrdv - ok
23:13:18.0608 0x1f94 vmicshutdown - ok
23:13:18.0611 0x1f94 vmictimesync - ok
23:13:18.0614 0x1f94 vmicvmsession - ok
23:13:18.0617 0x1f94 vmicvss - ok
23:13:18.0622 0x1f94 volmgr - ok
23:13:18.0626 0x1f94 volmgrx - ok
23:13:18.0631 0x1f94 volsnap - ok
23:13:18.0634 0x1f94 vpci - ok
23:13:18.0638 0x1f94 vsmraid - ok
23:13:18.0642 0x1f94 VSS - ok
23:13:18.0686 0x1f94 [ 79F4D90FAA0ACC1866F2F3E03E39CA89, EE08BCBF29A7E4AFFF520B8DF067281425F433EC275F8C86CE8F20F000E92E3D ] vssbrigde64 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\x64\vssbridge64.exe
23:13:18.0695 0x1f94 vssbrigde64 - ok
23:13:18.0699 0x1f94 VSTXRAID - ok
23:13:18.0710 0x1f94 vwifibus - ok
23:13:18.0713 0x1f94 vwififlt - ok
23:13:18.0716 0x1f94 vwifimp - ok
23:13:18.0741 0x1f94 W32Time - ok
23:13:18.0744 0x1f94 WacomPen - ok
23:13:18.0774 0x1f94 WalletService - ok
23:13:18.0782 0x1f94 wanarp - ok
23:13:18.0785 0x1f94 wanarpv6 - ok
23:13:18.0789 0x1f94 wbengine - ok
23:13:18.0805 0x1f94 WbioSrvc - ok
23:13:18.0827 0x1f94 Wcmsvc - ok
23:13:18.0831 0x1f94 wcncsvc - ok
23:13:18.0834 0x1f94 WcsPlugInService - ok
23:13:18.0838 0x1f94 WdBoot - ok
23:13:18.0841 0x1f94 Wdf01000 - ok
23:13:18.0844 0x1f94 WdFilter - ok
23:13:18.0849 0x1f94 WdiServiceHost - ok
23:13:18.0852 0x1f94 WdiSystemHost - ok
23:13:18.0865 0x1f94 wdiwifi - ok
23:13:18.0868 0x1f94 WdNisDrv - ok
23:13:18.0888 0x1f94 WdNisSvc - ok
23:13:18.0891 0x1f94 WebClient - ok
23:13:18.0895 0x1f94 Wecsvc - ok
23:13:18.0898 0x1f94 WEPHOSTSVC - ok
23:13:18.0907 0x1f94 wercplsupport - ok
23:13:18.0910 0x1f94 WerSvc - ok
23:13:18.0927 0x1f94 WFPLWFS - ok
23:13:18.0930 0x1f94 WiaRpc - ok
23:13:18.0946 0x1f94 WIMMount - ok
23:13:18.0949 0x1f94 WinDefend - ok
23:13:18.0957 0x1f94 WindowsTrustedRT - ok
23:13:18.0966 0x1f94 WindowsTrustedRTProxy - ok
23:13:18.0982 0x1f94 WinHttpAutoProxySvc - ok
23:13:18.0992 0x1f94 WinMad - ok
23:13:19.0030 0x1f94 Winmgmt - ok
23:13:19.0040 0x1f94 WinRM - ok
23:13:19.0047 0x1f94 WINUSB - ok
23:13:19.0052 0x1f94 WinVerbs - ok
23:13:19.0071 0x1f94 WlanSvc - ok
23:13:19.0074 0x1f94 wlidsvc - ok
23:13:19.0077 0x1f94 WmiAcpi - ok
23:13:19.0083 0x1f94 wmiApSrv - ok
23:13:19.0105 0x1f94 WMPNetworkSvc - ok
23:13:19.0119 0x1f94 [ 2A9650FCC696DB28E45EA8B33B99B8E6, FBEBC6C05D50F578C6EEE0A7285EBE1DEADB08DD21FA3232630FD8D5A68FC3FB ] Wof C:\WINDOWS\system32\drivers\Wof.sys
23:13:19.0133 0x1f94 Wof - ok
23:13:19.0160 0x1f94 workfolderssvc - ok
23:13:19.0175 0x1f94 wpcfltr - ok
23:13:19.0178 0x1f94 WPDBusEnum - ok
23:13:19.0182 0x1f94 WpdUpFltr - ok
23:13:19.0185 0x1f94 WpnService - ok
23:13:19.0189 0x1f94 ws2ifsl - ok
23:13:19.0203 0x1f94 wscsvc - ok
23:13:19.0206 0x1f94 WSearch - ok
23:13:19.0229 0x1f94 WSService - ok
23:13:19.0242 0x1f94 wuauserv - ok
23:13:19.0244 0x1f94 WudfPf - ok
23:13:19.0248 0x1f94 WUDFRd - ok
23:13:19.0261 0x1f94 wudfsvc - ok
23:13:19.0265 0x1f94 WUDFWpdFs - ok
23:13:19.0272 0x1f94 WUDFWpdMtp - ok
23:13:19.0276 0x1f94 WwanSvc - ok
23:13:19.0298 0x1f94 XblAuthManager - ok
23:13:19.0317 0x1f94 XblGameSave - ok
23:13:19.0320 0x1f94 xboxgip - ok
23:13:19.0348 0x1f94 XboxNetApiSvc - ok
23:13:19.0364 0x1f94 xinputhid - ok
23:13:19.0365 0x1f94 ================ Scan global ===============================
23:13:19.0424 0x1f94 [ Global ] - ok
23:13:19.0425 0x1f94 ================ Scan MBR ==================================
23:13:19.0440 0x1f94 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
23:13:19.0537 0x1f94 \Device\Harddisk0\DR0 - ok
23:13:20.0756 0x1f94 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
23:13:20.0866 0x1f94 \Device\Harddisk1\DR1 - ok
23:13:20.0867 0x1f94 ================ Scan VBR ==================================
23:13:20.0873 0x1f94 [ 630E9DB7DE7A18EDFBBD46721400C056 ] \Device\Harddisk0\DR0\Partition1
23:13:20.0920 0x1f94 \Device\Harddisk0\DR0\Partition1 - ok
23:13:20.0935 0x1f94 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition2
23:13:20.0935 0x1f94 \Device\Harddisk0\DR0\Partition2 - ok
23:13:20.0944 0x1f94 [ B6A284E46352D2540C33909198A062FE ] \Device\Harddisk0\DR0\Partition3
23:13:21.0007 0x1f94 \Device\Harddisk0\DR0\Partition3 - ok
23:13:21.0028 0x1f94 [ 41A4C7A60E3CE9536913A133491BD64E ] \Device\Harddisk0\DR0\Partition4
23:13:21.0039 0x1f94 \Device\Harddisk0\DR0\Partition4 - ok
23:13:21.0063 0x1f94 [ 5580FB705EFF4AED3CC5CC6C548AD98A ] \Device\Harddisk0\DR0\Partition5
23:13:21.0077 0x1f94 \Device\Harddisk0\DR0\Partition5 - ok
23:13:21.0092 0x1f94 [ 2DAEDD4FAD1DB0F2DF89ED3163D6C264 ] \Device\Harddisk0\DR0\Partition6
23:13:21.0094 0x1f94 \Device\Harddisk0\DR0\Partition6 - ok
23:13:21.0099 0x1f94 [ 80D96175BAE000A12EE74EC272BC98CE ] \Device\Harddisk1\DR1\Partition1
23:13:21.0101 0x1f94 \Device\Harddisk1\DR1\Partition1 - ok
23:13:21.0102 0x1f94 ================ Scan generic autorun ======================
23:13:21.0509 0x1f94 [ BF225BCD0EC2D85719C382019B5B4250, 7FE5A85209BD930FC1622600AB74E59854488986AA052A0D03D5FC7B361F247D ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
23:13:21.0840 0x1f94 RTHDVCPL - ok
23:13:21.0958 0x1f94 [ D9133D4157664B1E2ACFC2CD56CCB599, 0B2B8EE7D45962026A30833D3D7F59FB1FB07085904C2E77A10714F38910E462 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
23:13:22.0041 0x1f94 NvBackend - ok
23:13:22.0065 0x1f94 ShadowPlay - ok
23:13:22.0098 0x1f94 [ CC9823AA6E3F6229CD6DA193551314A5, 76BCD2BCA391C2114BF9D28FA290D9B39D16379C410070E0E3A6376FDEE51CE1 ] C:\Program Files\iTunes\iTunesHelper.exe
23:13:22.0113 0x1f94 iTunesHelper - ok
23:13:22.0145 0x1f94 [ C91635CC2BF215F9D7A5A7FC2E385D1D, A77AC38D3ACF7C199C0C8A3DB5EF9610FF0E8ED68D6F5E08C75771D5A3659EEB ] C:\Program Files (x86)\Acer\abDocs\abDocsDllLoader.exe
23:13:22.0155 0x1f94 abDocsDllLoader - ok
23:13:22.0303 0x1f94 [ DC34357661A698DED4B4C8C8BF526779, A35358976B18039E0BD2624C08CC865BAE5B490C853E2A233B011E4CEC7158EC ] C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe
23:13:22.0403 0x1f94 GoPro Studio Importer - ok
23:13:22.0455 0x1f94 [ 06E19A109543DDF347762108F08FCFA6, BFAC3DB4276E803C12311585AB01C3792E52EAC3FBA60A24CBDD738D97C3D59A ] C:\Program Files (x86)\Syncios\SynciosDeviceService.exe
23:13:22.0466 0x1f94 Syncios device service - detected UnsignedFile.Multi.Generic ( 1 )
23:13:24.0899 0x1f94 Detect skipped due to KSN trusted
23:13:24.0899 0x1f94 Syncios device service - ok
23:13:24.0988 0x1f94 [ 6513807FEE68E6C32E67437EE3FFB6C8, 2AB388BD68E984C38EAAF2D42DE918A64B42DA229627FC0B1A896A8AD60B5F91 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
23:13:25.0011 0x1f94 SunJavaUpdateSched - ok
23:13:25.0064 0x1f94 OneDriveSetup - ok
23:13:25.0068 0x1f94 OneDriveSetup - ok
23:13:25.0182 0x1f94 [ F9387D080BF8566354CDB0445AB8F87B, 4EE5D4A15E2D3DF578FA0370449C0894166B1B2998B63D9F02A994845350B86A ] C:\Users\Robert\AppData\Local\Microsoft\OneDrive\OneDrive.exe
23:13:25.0232 0x1f94 OneDrive - ok
23:13:25.0289 0x1f94 [ F7BF95877017F53DDAEBC4E87A309168, F7849DBC61E5E7C42B97D011364ADC7C20257994FECBFA988C8CB2E779392F80 ] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
23:13:25.0296 0x1f94 iCloudServices - ok
23:13:25.0314 0x1f94 [ 3558EC1B95ACC52F77BC401D08B47D84, 6BAD7D79003414DCADE127FD2CFE4E3019D4D3CD26083BA45562B39C97AEB9C5 ] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
23:13:25.0322 0x1f94 iCloudDrive - ok
23:13:25.0347 0x1f94 [ 054EBE0E187606965B43AA7C7DCF77F2, B65F1EB130E677E05EEE1BAFDE0D0F85B288A6A826878BF3C8787EA79C0BD609 ] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe
23:13:25.0359 0x1f94 iCloudPhotos - ok
23:13:25.0384 0x1f94 [ 1EE1F7986C80F524AFF4ACE4F637D769, 7667892D6C66C2E17F3FA99F8A12AA25F4968BFBF2B04C2D91A778535F49B840 ] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
23:13:25.0390 0x1f94 ApplePhotoStreams - ok
23:13:25.0415 0x1f94 Skype - ok
23:13:25.0429 0x1f94 Uninstall C:\Users\Robert\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64 - ok
23:13:25.0430 0x1f94 Waiting for KSN requests completion. In queue: 21
23:13:26.0431 0x1f94 Waiting for KSN requests completion. In queue: 21
23:13:27.0431 0x1f94 Waiting for KSN requests completion. In queue: 21
23:13:27.0865 0x09e8 Object required for P2P: [ 3E98CE04689597C76B3EF4D3D0323836 ] SkypeUpdate
23:13:28.0432 0x1f94 Waiting for KSN requests completion. In queue: 16
23:13:29.0432 0x1f94 Waiting for KSN requests completion. In queue: 16
23:13:30.0312 0x09e8 Object send P2P result: true
23:13:30.0313 0x09e8 Object required for P2P: [ DC34357661A698DED4B4C8C8BF526779 ] C:\Program Files (x86)\GoPro\Tools\Importer\GoPro Importer.exe
23:13:30.0432 0x1f94 Waiting for KSN requests completion. In queue: 7
23:13:31.0432 0x1f94 Waiting for KSN requests completion. In queue: 7
23:13:32.0433 0x1f94 Waiting for KSN requests completion. In queue: 7
23:13:32.0785 0x09e8 Object send P2P result: true
23:13:33.0455 0x1f94 AV detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\wmiav.exe ( 16.0.0.614 ), 0x41000 ( enabled : updated )
23:13:33.0501 0x1f94 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.9.10586.0 ), 0x60100 ( disabled : updated )
23:13:33.0502 0x1f94 FW detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\wmiav.exe ( 16.0.0.614 ), 0x41010 ( enabled )
23:13:35.0856 0x1f94 ============================================================
23:13:35.0856 0x1f94 Scan finished
23:13:35.0856 0x1f94 ============================================================
23:13:35.0880 0x1320 Detected object count: 1
23:13:35.0880 0x1320 Actual detected object count: 1
23:14:20.0905 0x1320 ose ( UnsignedFile.Multi.Generic ) - skipped by user
23:14:20.0905 0x1320 ose ( UnsignedFile.Multi.Generic ) - User select action: Skip |