Hallo,
hier der Report: Code:
09:46:33.0328 0x05c8 TDSS rootkit removing tool 3.1.0.11 Aug 5 2016 12:13:31
09:47:00.0339 0x05c8 ============================================================
09:47:00.0340 0x05c8 Current date / time: 2016/09/26 09:47:00.0339
09:47:00.0340 0x05c8 SystemInfo:
09:47:00.0363 0x05c8
09:47:00.0363 0x05c8 OS Version: 10.0.14393 ServicePack: 0.0
09:47:00.0363 0x05c8 Product type: Workstation
09:47:00.0363 0x05c8 ComputerName: LAP-OLI-PB
09:47:00.0363 0x05c8 UserName: Oliver
09:47:00.0363 0x05c8 Windows directory: C:\WINDOWS
09:47:00.0363 0x05c8 System windows directory: C:\WINDOWS
09:47:00.0363 0x05c8 Running under WOW64
09:47:00.0363 0x05c8 Processor architecture: Intel x64
09:47:00.0363 0x05c8 Number of processors: 4
09:47:00.0364 0x05c8 Page size: 0x1000
09:47:00.0364 0x05c8 Boot type: Normal boot
09:47:00.0364 0x05c8 CodeIntegrityOptions = 0x00000001
09:47:00.0364 0x05c8 ============================================================
09:47:00.0903 0x05c8 KLMD registered as C:\WINDOWS\system32\drivers\76015526.sys
09:47:00.0903 0x05c8 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.187, osProperties = 0x19
09:47:01.0351 0x05c8 System UUID: {35BCC849-4E9C-4941-C05A-CF36D75B4AE6}
09:47:02.0395 0x05c8 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 ( 698.64 Gb ), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
09:47:02.0400 0x05c8 ============================================================
09:47:02.0400 0x05c8 \Device\Harddisk0\DR0:
09:47:02.0404 0x05c8 MBR partitions:
09:47:02.0404 0x05c8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1851BC77
09:47:02.0426 0x05c8 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x186D932C, BlocksNum 0x32B1CD09
09:47:02.0459 0x05c8 ============================================================
09:47:03.0467 0x05c8 C: <-> \Device\Harddisk0\DR0\Partition1
09:47:03.0584 0x05c8 D: <-> \Device\Harddisk0\DR0\Partition2
09:47:03.0584 0x05c8 ============================================================
09:47:03.0584 0x05c8 Initialize success
09:47:03.0584 0x05c8 ============================================================
09:47:32.0968 0x1dfc ============================================================
09:47:32.0968 0x1dfc Scan started
09:47:32.0968 0x1dfc Mode: Manual; SigCheck; TDLFS;
09:47:32.0968 0x1dfc ============================================================
09:47:32.0968 0x1dfc KSN ping started
09:47:33.0113 0x1dfc KSN ping finished: true
09:47:36.0701 0x1dfc ================ Scan system memory ========================
09:47:36.0701 0x1dfc System memory - ok
09:47:36.0703 0x1dfc ================ Scan services =============================
09:47:39.0053 0x1dfc 1394ohci - ok
09:47:39.0057 0x1dfc 3ware - ok
09:47:39.0078 0x1dfc ACPI - ok
09:47:39.0082 0x1dfc AcpiDev - ok
09:47:39.0087 0x1dfc acpiex - ok
09:47:39.0111 0x1dfc acpipagr - ok
09:47:39.0178 0x1dfc AcpiPmi - ok
09:47:39.0194 0x1dfc acpitime - ok
09:47:39.0399 0x1dfc [ A0CAC4F3F998173A8DC1E67E7E0345EF, D0C2F504A5059691EDBBA917D0C6260450A554A365C12E7747E48EE1668C51A5 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
09:47:39.0458 0x1dfc AdobeARMservice - ok
09:47:40.0447 0x1dfc [ 8FC33A20D54FB5CC7FBBA814B4E42A22, 707F61F0CEB9467D9BD1782868403BD53DB46EAB0342772661F370E5174AAD8C ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
09:47:40.0479 0x1dfc AdobeFlashPlayerUpdateSvc - ok
09:47:40.0553 0x1dfc ADP80XX - ok
09:47:40.0559 0x1dfc AFD - ok
09:47:40.0991 0x1dfc [ E20C1118524DF19945BCD83A3843E8CF, 90C87096E9E2595DAA503CFD9C24D7D8F9CB2D567ACAB06FBF5527C8A6059409 ] AGSService C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
09:47:41.0139 0x1dfc AGSService - ok
09:47:41.0168 0x1dfc ahcache - ok
09:47:41.0191 0x1dfc AJRouter - ok
09:47:41.0222 0x1dfc ALG - ok
09:47:41.0288 0x1dfc [ D7A72B9BA6AB996DADB37BFCB0363D63, A223684978928B59D39DFB49F6658E0CF04ADD15AD8ACFCEC384DBD4D8C8CBCA ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
09:47:41.0652 0x1dfc AMD External Events Utility - ok
09:47:41.0665 0x1dfc AmdK8 - ok
09:47:41.0684 0x1dfc amdkmdag - ok
09:47:41.0812 0x1dfc [ C14D7E5F24381BC8F333C4EB77892400, 8B8EF49D2398AF39E36EFFE6D1E0489727D5612DEFA43C71E3C7E4C0650010A5 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
09:47:41.0916 0x1dfc amdkmdap - ok
09:47:41.0965 0x1dfc AmdPPM - ok
09:47:41.0973 0x1dfc amdsata - ok
09:47:41.0989 0x1dfc amdsbs - ok
09:47:41.0993 0x1dfc amdxata - ok
09:47:41.0998 0x1dfc AppID - ok
09:47:42.0013 0x1dfc AppIDSvc - ok
09:47:42.0022 0x1dfc Appinfo - ok
09:47:42.0048 0x1dfc applockerfltr - ok
09:47:42.0072 0x1dfc AppReadiness - ok
09:47:42.0119 0x1dfc AppXSvc - ok
09:47:42.0142 0x1dfc arcsas - ok
09:47:42.0458 0x1dfc aspnet_state - ok
09:47:42.0463 0x1dfc AsyncMac - ok
09:47:42.0487 0x1dfc atapi - ok
09:47:42.0566 0x1dfc athr - ok
09:47:42.0629 0x1dfc AudioEndpointBuilder - ok
09:47:42.0662 0x1dfc Audiosrv - ok
09:47:42.0678 0x1dfc AxInstSV - ok
09:47:42.0697 0x1dfc b06bdrv - ok
09:47:42.0720 0x1dfc BasicDisplay - ok
09:47:42.0743 0x1dfc BasicRender - ok
09:47:42.0758 0x1dfc bcmfn - ok
09:47:42.0772 0x1dfc bcmfn2 - ok
09:47:42.0787 0x1dfc BDESVC - ok
09:47:42.0809 0x1dfc Beep - ok
09:47:42.0832 0x1dfc BFE - ok
09:47:42.0884 0x1dfc BITS - ok
09:47:42.0891 0x1dfc bowser - ok
09:47:42.0926 0x1dfc BrokerInfrastructure - ok
09:47:42.0930 0x1dfc Browser - ok
09:47:42.0960 0x1dfc BthAvrcpTg - ok
09:47:42.0974 0x1dfc BthHFEnum - ok
09:47:42.0986 0x1dfc bthhfhid - ok
09:47:43.0020 0x1dfc BthHFSrv - ok
09:47:43.0030 0x1dfc BTHMODEM - ok
09:47:43.0044 0x1dfc bthserv - ok
09:47:43.0087 0x1dfc buttonconverter - ok
09:47:43.0096 0x1dfc CapImg - ok
09:47:43.0100 0x1dfc cdfs - ok
09:47:43.0115 0x1dfc CDPSvc - ok
09:47:43.0141 0x1dfc CDPUserSvc - ok
09:47:43.0185 0x1dfc cdrom - ok
09:47:43.0193 0x1dfc CertPropSvc - ok
09:47:43.0208 0x1dfc cht4iscsi - ok
09:47:43.0212 0x1dfc cht4vbd - ok
09:47:43.0249 0x1dfc circlass - ok
09:47:43.0253 0x1dfc CLFS - ok
09:47:43.0262 0x1dfc ClipSVC - ok
09:47:43.0270 0x1dfc clreg - ok
09:47:43.0289 0x1dfc CmBatt - ok
09:47:43.0904 0x1dfc [ 7DFC16B25788C97F3E9C42B1FCAC0A67, D729D138CAAE8295B750A48F8A9806F4C54224BEF4A5260EDDB5B1D959FC9CFF ] CmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
09:47:44.0156 0x1dfc CmdAgent - ok
09:47:44.0215 0x1dfc [ EAE2829CFBE8A84E3CC2A1451966E74F, 621AEA870D79A99FBA1339AA8C105A65ED3194E082DFFC33EA7513C0E5C453B5 ] cmderd C:\WINDOWS\system32\DRIVERS\cmderd.sys
09:47:44.0226 0x1dfc cmderd - ok
09:47:44.0317 0x1dfc [ 08400F4E1D6F586EE7C4136C4CB4B1D8, 629FED82F975BC18FCAA9E6B19C5A3CA42DAF2C2F9B383590987A62747707D74 ] cmdGuard C:\WINDOWS\system32\DRIVERS\cmdguard.sys
09:47:44.0374 0x1dfc cmdGuard - ok
09:47:44.0394 0x1dfc [ 752041CFBE3C0EEA5BC4E9F0E98F7929, A88C70610E242B0F3E459A0926A44D6F2CB179C741313D9B4602A48559E313ED ] cmdhlp C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
09:47:44.0405 0x1dfc cmdhlp - ok
09:47:44.0799 0x1dfc [ 084A29576C98C45E836CC977C1D311FD, BE01F6A181AB43590C15271E09BEC9B2CF14A011E7A8EE226CA1A2E6C874B39B ] cmdvirth C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
09:47:44.0879 0x1dfc cmdvirth - ok
09:47:44.0931 0x1dfc CNG - ok
09:47:44.0935 0x1dfc cnghwassist - ok
09:47:45.0149 0x1dfc CompositeBus - ok
09:47:45.0153 0x1dfc COMSysApp - ok
09:47:45.0175 0x1dfc condrv - ok
09:47:45.0226 0x1dfc CoreMessagingRegistrar - ok
09:47:45.0715 0x1dfc [ B18D590BC5220FDB4A747BC16D78ABC7, D46F8B43BAC22E55DE9AFC19CF371B1C4E8D3707163598B2F9884BB31D730C09 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
09:47:46.0947 0x1dfc cphs - ok
09:47:46.0967 0x1dfc CryptSvc - ok
09:47:46.0996 0x1dfc dam - ok
09:47:47.0019 0x1dfc DcomLaunch - ok
09:47:47.0044 0x1dfc DcpSvc - ok
09:47:47.0063 0x1dfc defragsvc - ok
09:47:47.0097 0x1dfc DeviceAssociationService - ok
09:47:47.0110 0x1dfc DeviceInstall - ok
09:47:47.0140 0x1dfc DevQueryBroker - ok
09:47:47.0165 0x1dfc Dfsc - ok
09:47:47.0179 0x1dfc Dhcp - ok
09:47:47.0258 0x1dfc diagnosticshub.standardcollector.service - ok
09:47:47.0274 0x1dfc DiagTrack - ok
09:47:47.0298 0x1dfc disk - ok
09:47:47.0333 0x1dfc DmEnrollmentSvc - ok
09:47:47.0341 0x1dfc dmvsc - ok
09:47:47.0398 0x1dfc dmwappushservice - ok
09:47:47.0410 0x1dfc Dnscache - ok
09:47:47.0422 0x1dfc dot3svc - ok
09:47:47.0436 0x1dfc DPS - ok
09:47:47.0459 0x1dfc drmkaud - ok
09:47:47.0495 0x1dfc DsmSvc - ok
09:47:47.0503 0x1dfc DsSvc - ok
09:47:47.0530 0x1dfc DXGKrnl - ok
09:47:47.0558 0x1dfc EapHost - ok
09:47:47.0575 0x1dfc ebdrv - ok
09:47:47.0607 0x1dfc EFS - ok
09:47:47.0632 0x1dfc EhStorClass - ok
09:47:47.0680 0x1dfc EhStorTcgDrv - ok
09:47:47.0714 0x1dfc embeddedmode - ok
09:47:47.0722 0x1dfc EntAppSvc - ok
09:47:47.0730 0x1dfc ErrDev - ok
09:47:47.0823 0x1dfc [ 6BD85B39B7B23F03B24CF641ED29147B, 850F21750BB39E5239B1584E1117844CAAAF6A5C58E79366552309F917675CE5 ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
09:47:47.0846 0x1dfc ETD - ok
09:47:47.0944 0x1dfc [ 8916EACF1256E1C5A3AF81FD39C747E7, FF28FB95E9F9287C1005CF0D9EB84F7CA3D137689862860C9848398504E1EFFF ] ETDService C:\Program Files\Elantech\ETDService.exe
09:47:47.0958 0x1dfc ETDService - ok
09:47:47.0985 0x1dfc EventSystem - ok
09:47:47.0989 0x1dfc exfat - ok
09:47:48.0008 0x1dfc fastfat - ok
09:47:48.0019 0x1dfc Fax - ok
09:47:48.0043 0x1dfc fdc - ok
09:47:48.0052 0x1dfc fdPHost - ok
09:47:48.0061 0x1dfc FDResPub - ok
09:47:48.0079 0x1dfc fhsvc - ok
09:47:48.0138 0x1dfc FileCrypt - ok
09:47:48.0142 0x1dfc FileInfo - ok
09:47:48.0156 0x1dfc Filetrace - ok
09:47:48.0160 0x1dfc flpydisk - ok
09:47:48.0171 0x1dfc FltMgr - ok
09:47:48.0185 0x1dfc FontCache - ok
09:47:48.0330 0x1dfc FontCache3.0.0.0 - ok
09:47:48.0367 0x1dfc FrameServer - ok
09:47:48.0383 0x1dfc FsDepends - ok
09:47:48.0389 0x1dfc Fs_Rec - ok
09:47:48.0394 0x1dfc fvevol - ok
09:47:48.0435 0x1dfc gencounter - ok
09:47:48.0465 0x1dfc genericusbfn - ok
09:47:48.0474 0x1dfc GPIOClx0101 - ok
09:47:48.0494 0x1dfc gpsvc - ok
09:47:48.0527 0x1dfc GpuEnergyDrv - ok
09:47:48.0558 0x1dfc [ 7F79205B4EFA98F0767309479C8C01C6, 4B576903A83F33A8CF31D3887144A3D51C56D1187115C83AC99C0E9F6B4BF128 ] Hamachi C:\WINDOWS\System32\drivers\Hamdrv.sys
09:47:48.0582 0x1dfc Hamachi - ok
09:47:48.0600 0x1dfc HdAudAddService - ok
09:47:48.0610 0x1dfc HDAudBus - ok
09:47:48.0615 0x1dfc HidBatt - ok
09:47:48.0622 0x1dfc HidBth - ok
09:47:48.0641 0x1dfc hidi2c - ok
09:47:48.0661 0x1dfc hidinterrupt - ok
09:47:48.0696 0x1dfc HidIr - ok
09:47:48.0728 0x1dfc hidserv - ok
09:47:48.0767 0x1dfc HidUsb - ok
09:47:48.0789 0x1dfc HomeGroupListener - ok
09:47:48.0817 0x1dfc HomeGroupProvider - ok
09:47:48.0829 0x1dfc HpSAMD - ok
09:47:48.0834 0x1dfc HTTP - ok
09:47:48.0867 0x1dfc HvHost - ok
09:47:48.0910 0x1dfc hvservice - ok
09:47:48.0914 0x1dfc hwpolicy - ok
09:47:48.0920 0x1dfc hyperkbd - ok
09:47:48.0926 0x1dfc i8042prt - ok
09:47:48.0932 0x1dfc iagpio - ok
09:47:48.0942 0x1dfc iai2c - ok
09:47:48.0947 0x1dfc iaLPSS2i_GPIO2 - ok
09:47:48.0954 0x1dfc iaLPSS2i_I2C - ok
09:47:48.0959 0x1dfc iaLPSSi_GPIO - ok
09:47:48.0970 0x1dfc iaLPSSi_I2C - ok
09:47:48.0975 0x1dfc iaStorAV - ok
09:47:48.0980 0x1dfc iaStorV - ok
09:47:48.0994 0x1dfc ibbus - ok
09:47:49.0026 0x1dfc icssvc - ok
09:47:49.0470 0x1dfc [ 79AE3CC82CA1563A4B392207997ACE7C, A1E4A1DA95CA2FA197EF5975657822F0F813F6C33DA38E1FA5A840194034D071 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
09:47:49.0653 0x1dfc igfx - ok
09:47:49.0684 0x1dfc IKEEXT - ok
09:47:49.0749 0x1dfc IndirectKmd - ok
09:47:49.0818 0x1dfc [ 55BB2E54302416B9F7D2489FC16F7333, FD697F033D56DE76718A83514A468267235BE3AE1ECD2B5E7B8BCA1520699E7F ] inspect C:\WINDOWS\system32\DRIVERS\inspect.sys
09:47:49.0831 0x1dfc inspect - ok
09:47:50.0414 0x1dfc [ D172E06EFE08DF148155A59DB716C1B6, F059B0B37C5E944D70626E9F029BC6311029E0A9D778C9C75DDDDC59A5AF1605 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
09:47:50.0746 0x1dfc IntcAzAudAddService - ok
09:47:50.0775 0x1dfc intelide - ok
09:47:50.0780 0x1dfc intelpep - ok
09:47:50.0784 0x1dfc intelppm - ok
09:47:50.0789 0x1dfc iorate - ok
09:47:50.0795 0x1dfc IpFilterDriver - ok
09:47:50.0838 0x1dfc iphlpsvc - ok
09:47:50.0877 0x1dfc IPMIDRV - ok
09:47:50.0909 0x1dfc IPNAT - ok
09:47:51.0368 0x1dfc [ B76542085ABAD1AD4E5684F761DFC2EF, C6699B788D6E81E73519433F12BFD3B12C71A5EE2A12810697FE9C4350A179B3 ] IpOverUsbSvc C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
09:47:51.0382 0x1dfc IpOverUsbSvc - ok
09:47:51.0386 0x1dfc irda - ok
09:47:51.0390 0x1dfc IRENUM - ok
09:47:51.0400 0x1dfc irmon - ok
09:47:51.0413 0x1dfc isapnp - ok
09:47:51.0444 0x1dfc iScsiPrt - ok
09:47:51.0476 0x1dfc kbdclass - ok
09:47:51.0480 0x1dfc kbdhid - ok
09:47:51.0528 0x1dfc kdnic - ok
09:47:51.0534 0x1dfc KeyIso - ok
09:47:51.0612 0x1dfc KSecDD - ok
09:47:51.0631 0x1dfc KSecPkg - ok
09:47:51.0718 0x1dfc ksthunk - ok
09:47:51.0765 0x1dfc KtmRm - ok
09:47:51.0800 0x1dfc L1C - ok
09:47:51.0832 0x1dfc LanmanServer - ok
09:47:51.0868 0x1dfc LanmanWorkstation - ok
09:47:51.0900 0x1dfc lfsvc - ok
09:47:51.0988 0x1dfc LicenseManager - ok
09:47:52.0020 0x1dfc lltdio - ok
09:47:52.0041 0x1dfc lltdsvc - ok
09:47:52.0083 0x1dfc lmhosts - ok
09:47:52.0122 0x1dfc LSI_SAS - ok
09:47:52.0130 0x1dfc LSI_SAS2i - ok
09:47:52.0142 0x1dfc LSI_SAS3i - ok
09:47:52.0151 0x1dfc LSI_SSS - ok
09:47:52.0162 0x1dfc LSM - ok
09:47:52.0171 0x1dfc luafv - ok
09:47:52.0244 0x1dfc MapsBroker - ok
09:47:52.0264 0x1dfc megasas - ok
09:47:52.0287 0x1dfc megasr - ok
09:47:52.0347 0x1dfc [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
09:47:52.0357 0x1dfc MEIx64 - ok
09:47:52.0403 0x1dfc MessagingService - ok
09:47:52.0772 0x1dfc Microsoft SharePoint Workspace Audit Service - ok
09:47:52.0833 0x1dfc mlx4_bus - ok
09:47:52.0864 0x1dfc MMCSS - ok
09:47:52.0869 0x1dfc Modem - ok
09:47:52.0900 0x1dfc monitor - ok
09:47:52.0914 0x1dfc mouclass - ok
09:47:52.0926 0x1dfc mouhid - ok
09:47:52.0932 0x1dfc mountmgr - ok
09:47:52.0938 0x1dfc mpsdrv - ok
09:47:52.0961 0x1dfc MpsSvc - ok
09:47:52.0992 0x1dfc MRxDAV - ok
09:47:53.0004 0x1dfc mrxsmb - ok
09:47:53.0046 0x1dfc mrxsmb10 - ok
09:47:53.0088 0x1dfc mrxsmb20 - ok
09:47:53.0119 0x1dfc MsBridge - ok
09:47:53.0156 0x1dfc MSDTC - ok
09:47:53.0190 0x1dfc Msfs - ok
09:47:53.0208 0x1dfc msgpiowin32 - ok
09:47:53.0212 0x1dfc mshidkmdf - ok
09:47:53.0222 0x1dfc mshidumdf - ok
09:47:53.0226 0x1dfc msisadrv - ok
09:47:53.0261 0x1dfc MSiSCSI - ok
09:47:53.0267 0x1dfc msiserver - ok
09:47:53.0281 0x1dfc MSKSSRV - ok
09:47:53.0292 0x1dfc MsLldp - ok
09:47:53.0296 0x1dfc MSPCLOCK - ok
09:47:53.0301 0x1dfc MSPQM - ok
09:47:53.0305 0x1dfc MsRPC - ok
09:47:53.0355 0x1dfc mssmbios - ok
09:47:53.0360 0x1dfc MSTEE - ok
09:47:53.0377 0x1dfc MTConfig - ok
09:47:53.0390 0x1dfc Mup - ok
09:47:53.0395 0x1dfc mvumis - ok
09:47:53.0417 0x1dfc NativeWifiP - ok
09:47:53.0449 0x1dfc NcaSvc - ok
09:47:53.0502 0x1dfc NcbService - ok
09:47:53.0523 0x1dfc NcdAutoSetup - ok
09:47:53.0543 0x1dfc ndfltr - ok
09:47:53.0550 0x1dfc NDIS - ok
09:47:53.0555 0x1dfc NdisCap - ok
09:47:53.0573 0x1dfc NdisImPlatform - ok
09:47:53.0576 0x1dfc NdisTapi - ok
09:47:53.0582 0x1dfc Ndisuio - ok
09:47:53.0602 0x1dfc NdisVirtualBus - ok
09:47:53.0620 0x1dfc NdisWan - ok
09:47:53.0625 0x1dfc ndiswanlegacy - ok
09:47:53.0628 0x1dfc ndproxy - ok
09:47:53.0636 0x1dfc Ndu - ok
09:47:53.0643 0x1dfc NetAdapterCx - ok
09:47:53.0650 0x1dfc NetBIOS - ok
09:47:53.0659 0x1dfc NetBT - ok
09:47:53.0667 0x1dfc Netlogon - ok
09:47:53.0695 0x1dfc Netman - ok
09:47:53.0744 0x1dfc netprofm - ok
09:47:53.0776 0x1dfc NetSetupSvc - ok
09:47:54.0270 0x1dfc NetTcpPortSharing - ok
09:47:54.0360 0x1dfc NgcCtnrSvc - ok
09:47:54.0397 0x1dfc NgcSvc - ok
09:47:54.0440 0x1dfc NlaSvc - ok
09:47:54.0498 0x1dfc Npfs - ok
09:47:54.0545 0x1dfc npsvctrig - ok
09:47:54.0556 0x1dfc nsi - ok
09:47:54.0571 0x1dfc nsiproxy - ok
09:47:54.0608 0x1dfc NTFS - ok
09:47:54.0633 0x1dfc Null - ok
09:47:54.0667 0x1dfc nvraid - ok
09:47:54.0715 0x1dfc nvstor - ok
09:47:54.0759 0x1dfc OneSyncSvc - ok
09:47:54.0855 0x1dfc [ 4965B005492CBA7719E82B71E3245495, 52AD72C05FACC1E0E416A1FA25F34FDD3CB274FAB973BEAAE911A2FACA42B650 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
09:47:54.0901 0x1dfc ose64 - ok
09:47:56.0031 0x1dfc [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
09:47:56.0252 0x1dfc osppsvc - ok
09:47:56.0303 0x1dfc p2pimsvc - ok
09:47:56.0334 0x1dfc p2psvc - ok
09:47:56.0338 0x1dfc Parport - ok
09:47:56.0399 0x1dfc partmgr - ok
09:47:56.0409 0x1dfc PcaSvc - ok
09:47:56.0433 0x1dfc pci - ok
09:47:56.0437 0x1dfc pciide - ok
09:47:56.0451 0x1dfc pcmcia - ok
09:47:56.0472 0x1dfc pcw - ok
09:47:56.0502 0x1dfc pdc - ok
09:47:56.0554 0x1dfc PEAUTH - ok
09:47:56.0580 0x1dfc percsas2i - ok
09:47:56.0585 0x1dfc percsas3i - ok
09:47:57.0146 0x1dfc PerfHost - ok
09:47:57.0263 0x1dfc PhoneSvc - ok
09:47:57.0331 0x1dfc PimIndexMaintenanceSvc - ok
09:47:57.0393 0x1dfc pla - ok
09:47:57.0411 0x1dfc PlugPlay - ok
09:47:57.0432 0x1dfc PNRPAutoReg - ok
09:47:57.0437 0x1dfc PNRPsvc - ok
09:47:57.0473 0x1dfc PolicyAgent - ok
09:47:57.0480 0x1dfc Power - ok
09:47:57.0509 0x1dfc PptpMiniport - ok
09:47:58.0425 0x1dfc [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
09:47:58.0865 0x1dfc PrintNotify - ok
09:47:58.0898 0x1dfc Processor - ok
09:47:58.0940 0x1dfc ProfSvc - ok
09:47:58.0947 0x1dfc Psched - ok
09:47:58.0995 0x1dfc QWAVE - ok
09:47:59.0031 0x1dfc QWAVEdrv - ok
09:47:59.0049 0x1dfc RasAcd - ok
09:47:59.0085 0x1dfc RasAgileVpn - ok
09:47:59.0113 0x1dfc RasAuto - ok
09:47:59.0118 0x1dfc Rasl2tp - ok
09:47:59.0138 0x1dfc RasMan - ok
09:47:59.0143 0x1dfc RasPppoe - ok
09:47:59.0148 0x1dfc RasSstp - ok
09:47:59.0183 0x1dfc rdbss - ok
09:47:59.0235 0x1dfc rdpbus - ok
09:47:59.0239 0x1dfc RDPDR - ok
09:47:59.0288 0x1dfc RdpVideoMiniport - ok
09:47:59.0305 0x1dfc rdyboost - ok
09:48:00.0151 0x1dfc [ F1D9E7B84A123F8861F63A2AE1E9F144, 7A56188DE148525B23617F8DA4AD49A88FA1BFC48641ED5065896C4408DA44ED ] ReflectService.exe C:\Program Files\Recovery\Macrium\ReflectService.exe
09:48:00.0310 0x1dfc ReflectService.exe - ok
09:48:00.0318 0x1dfc ReFSv1 - ok
09:48:00.0349 0x1dfc RemoteAccess - ok
09:48:00.0407 0x1dfc RemoteRegistry - ok
09:48:00.0482 0x1dfc RetailDemo - ok
09:48:00.0498 0x1dfc RmSvc - ok
09:48:00.0552 0x1dfc RpcEptMapper - ok
09:48:00.0577 0x1dfc RpcLocator - ok
09:48:00.0616 0x1dfc RpcSs - ok
09:48:00.0642 0x1dfc rspndr - ok
09:48:00.0754 0x1dfc [ AB959F26FBB851A9D31E2F229DB3FA1A, 35961B761C83B48DBB9960C6DEC89806F3BC9FA0F450E566333ABE3F22E42AA9 ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
09:48:00.0772 0x1dfc RTSUER - ok
09:48:00.0812 0x1dfc s3cap - ok
09:48:01.0018 0x1dfc SamSs - ok
09:48:01.0125 0x1dfc [ D95D61869CE6A7F916E53F82E4C7917D, 423BCDFBCD5C670D13F1C390DF6CA83C91137C8FCBD2A07BE03DDD823E8CAB4F ] SbieDrv C:\Program Files\Sandboxie\SbieDrv.sys
09:48:01.0141 0x1dfc SbieDrv - ok
09:48:01.0214 0x1dfc [ 8F237507759186A689450BD9B8CAB7AC, C08A26CE02872281E8C186A0824552DB9A3286D041ADAFBF3F977BBE0EBC266B ] SbieSvc C:\Program Files\Sandboxie\SbieSvc.exe
09:48:01.0229 0x1dfc SbieSvc - ok
09:48:01.0300 0x1dfc sbp2port - ok
09:48:01.0366 0x1dfc SCardSvr - ok
09:48:01.0407 0x1dfc ScDeviceEnum - ok
09:48:01.0454 0x1dfc scfilter - ok
09:48:01.0468 0x1dfc Schedule - ok
09:48:01.0473 0x1dfc scmbus - ok
09:48:01.0488 0x1dfc scmdisk0101 - ok
09:48:01.0516 0x1dfc SCPolicySvc - ok
09:48:01.0578 0x1dfc [ AD7189E85A0801DE0507C610963A3CD0, 0AA9F3C9D252624CC62EC95FD910C6911E136DD3E66159CEB9857BC7AB70FAA2 ] ScpVBus C:\WINDOWS\System32\drivers\ScpVBus.sys
09:48:01.0587 0x1dfc ScpVBus - ok
09:48:01.0657 0x1dfc sdbus - ok
09:48:01.0699 0x1dfc SDRSVC - ok
09:48:01.0715 0x1dfc sdstor - ok
09:48:01.0728 0x1dfc seclogon - ok
09:48:01.0746 0x1dfc SENS - ok
09:48:01.0848 0x1dfc SensorDataService - ok
09:48:01.0908 0x1dfc SensorService - ok
09:48:01.0935 0x1dfc SensrSvc - ok
09:48:01.0939 0x1dfc SerCx - ok
09:48:01.0987 0x1dfc SerCx2 - ok
09:48:02.0022 0x1dfc Serenum - ok
09:48:02.0027 0x1dfc Serial - ok
09:48:02.0033 0x1dfc sermouse - ok
09:48:02.0073 0x1dfc SessionEnv - ok
09:48:02.0095 0x1dfc sfloppy - ok
09:48:02.0160 0x1dfc SharedAccess - ok
09:48:02.0173 0x1dfc ShellHWDetection - ok
09:48:02.0201 0x1dfc shpamsvc - ok
09:48:02.0225 0x1dfc SiSRaid2 - ok
09:48:02.0230 0x1dfc SiSRaid4 - ok
09:48:02.0414 0x1dfc [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
09:48:02.0434 0x1dfc SkypeUpdate - ok
09:48:02.0528 0x1dfc [ AF9CA3A881483E6999CB2764BDAD3414, 95D6F7DA34DAD2CC1E4BC0B0867FA7E90293FB082EE0372DF5FE663E2AFD7AA4 ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
09:48:02.0542 0x1dfc SmbDrvI - ok
09:48:02.0599 0x1dfc smphost - ok
09:48:02.0732 0x1dfc SmsRouter - ok
09:48:02.0807 0x1dfc SNMPTRAP - ok
09:48:02.0934 0x1dfc spaceport - ok
09:48:02.0938 0x1dfc SpbCx - ok
09:48:02.0952 0x1dfc Spooler - ok
09:48:03.0058 0x1dfc sppsvc - ok
09:48:03.0116 0x1dfc srv - ok
09:48:03.0157 0x1dfc srv2 - ok
09:48:03.0201 0x1dfc srvnet - ok
09:48:03.0237 0x1dfc SSDPSRV - ok
09:48:03.0299 0x1dfc SstpSvc - ok
09:48:03.0401 0x1dfc StateRepository - ok
09:48:03.0984 0x1dfc [ E06AA279D85877268E34E9A9BC41F560, 6EFE7E3850CD19B919053293B6D8CB61CC638D3B1626BB62594C681625132689 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
09:48:04.0109 0x1dfc Steam Client Service - ok
09:48:04.0168 0x1dfc stexstor - ok
09:48:04.0210 0x1dfc stisvc - ok
09:48:04.0216 0x1dfc storahci - ok
09:48:04.0232 0x1dfc storflt - ok
09:48:04.0275 0x1dfc stornvme - ok
09:48:04.0305 0x1dfc storqosflt - ok
09:48:04.0383 0x1dfc StorSvc - ok
09:48:04.0389 0x1dfc storufs - ok
09:48:04.0395 0x1dfc storvsc - ok
09:48:04.0410 0x1dfc svsvc - ok
09:48:04.0423 0x1dfc swenum - ok
09:48:04.0427 0x1dfc swprv - ok
09:48:04.0489 0x1dfc Synth3dVsc - ok
09:48:04.0526 0x1dfc SysMain - ok
09:48:04.0600 0x1dfc SystemEventsBroker - ok
09:48:04.0637 0x1dfc TabletInputService - ok
09:48:04.0696 0x1dfc [ 876F4A55F3F5319132E3AC8DC7E75EF8, 2A347F168D406700E83F8BE39BB74E656ADD487018A73F0F4316348CD03C9F36 ] tap0901t C:\WINDOWS\System32\drivers\tap0901t.sys
09:48:04.0711 0x1dfc tap0901t - ok
09:48:04.0731 0x1dfc TapiSrv - ok
09:48:04.0766 0x1dfc Tcpip - ok
09:48:04.0771 0x1dfc Tcpip6 - ok
09:48:04.0779 0x1dfc tcpipreg - ok
09:48:04.0821 0x1dfc tdx - ok
09:48:05.0080 0x1dfc [ 1A4B1847BD8C7079C3A6C873342CC84A, E49E60896C6726EB8F8EE3A443B839AA6A6E802919C7D102DD820AD7C3DDA32C ] Te.Service C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe
09:48:05.0171 0x1dfc Te.Service - detected UnsignedFile.Multi.Generic ( 1 )
09:48:05.0253 0x1dfc Detect skipped due to KSN trusted
09:48:05.0253 0x1dfc Te.Service - ok
09:48:05.0298 0x1dfc terminpt - ok
09:48:05.0337 0x1dfc TermService - ok
09:48:05.0381 0x1dfc Themes - ok
09:48:05.0416 0x1dfc TieringEngineService - ok
09:48:05.0448 0x1dfc tiledatamodelsvc - ok
09:48:05.0474 0x1dfc TimeBrokerSvc - ok
09:48:05.0513 0x1dfc TPM - ok
09:48:05.0546 0x1dfc TrkWks - ok
09:48:05.0650 0x1dfc TrustedInstaller - ok
09:48:05.0656 0x1dfc tsusbflt - ok
09:48:05.0678 0x1dfc TsUsbGD - ok
09:48:05.0732 0x1dfc tunnel - ok
09:48:05.0928 0x1dfc [ E775DAF583CFF96F81306A4A93E501FE, C6F54D6D524CA3D3872C7BD53904A203F55C99EF93E08077183192587BE32D86 ] TunngleService C:\Program Files (x86)\Tunngle\TnglCtrl.exe
09:48:05.0962 0x1dfc TunngleService - ok
09:48:06.0318 0x1dfc tzautoupdate - ok
09:48:06.0322 0x1dfc UASPStor - ok
09:48:06.0328 0x1dfc UcmCx0101 - ok
09:48:06.0445 0x1dfc UcmTcpciCx0101 - ok
09:48:06.0453 0x1dfc UcmUcsi - ok
09:48:06.0476 0x1dfc Ucx01000 - ok
09:48:06.0482 0x1dfc UdeCx - ok
09:48:06.0487 0x1dfc udfs - ok
09:48:06.0513 0x1dfc UEFI - ok
09:48:06.0568 0x1dfc Ufx01000 - ok
09:48:06.0587 0x1dfc UfxChipidea - ok
09:48:06.0592 0x1dfc ufxsynopsys - ok
09:48:06.0683 0x1dfc UI0Detect - ok
09:48:06.0702 0x1dfc umbus - ok
09:48:06.0724 0x1dfc UmPass - ok
09:48:06.0761 0x1dfc UmRdpService - ok
09:48:06.0803 0x1dfc UnistoreSvc - ok
09:48:06.0835 0x1dfc upnphost - ok
09:48:06.0839 0x1dfc UrsChipidea - ok
09:48:06.0880 0x1dfc UrsCx01000 - ok
09:48:06.0887 0x1dfc UrsSynopsys - ok
09:48:06.0893 0x1dfc usbccgp - ok
09:48:06.0921 0x1dfc usbcir - ok
09:48:06.0934 0x1dfc usbehci - ok
09:48:06.0938 0x1dfc usbhub - ok
09:48:06.0992 0x1dfc USBHUB3 - ok
09:48:06.0997 0x1dfc usbohci - ok
09:48:07.0003 0x1dfc usbprint - ok
09:48:07.0018 0x1dfc usbser - ok
09:48:07.0030 0x1dfc USBSTOR - ok
09:48:07.0037 0x1dfc usbuhci - ok
09:48:07.0082 0x1dfc usbvideo - ok
09:48:07.0125 0x1dfc USBXHCI - ok
09:48:07.0183 0x1dfc UserDataSvc - ok
09:48:07.0288 0x1dfc UserManager - ok
09:48:07.0333 0x1dfc UsoSvc - ok
09:48:07.0338 0x1dfc VaultSvc - ok
09:48:07.0369 0x1dfc vdrvroot - ok
09:48:07.0405 0x1dfc vds - ok
09:48:07.0410 0x1dfc VerifierExt - ok
09:48:07.0436 0x1dfc vhdmp - ok
09:48:07.0441 0x1dfc vhf - ok
09:48:07.0462 0x1dfc vmbus - ok
09:48:07.0468 0x1dfc VMBusHID - ok
09:48:07.0499 0x1dfc vmgid - ok
09:48:07.0534 0x1dfc vmicguestinterface - ok
09:48:07.0539 0x1dfc vmicheartbeat - ok
09:48:07.0546 0x1dfc vmickvpexchange - ok
09:48:07.0558 0x1dfc vmicrdv - ok
09:48:07.0566 0x1dfc vmicshutdown - ok
09:48:07.0577 0x1dfc vmictimesync - ok
09:48:07.0586 0x1dfc vmicvmsession - ok
09:48:07.0593 0x1dfc vmicvss - ok
09:48:07.0617 0x1dfc volmgr - ok
09:48:07.0623 0x1dfc volmgrx - ok
09:48:07.0639 0x1dfc volsnap - ok
09:48:07.0655 0x1dfc volume - ok
09:48:07.0712 0x1dfc vpci - ok
09:48:07.0717 0x1dfc vsmraid - ok
09:48:07.0750 0x1dfc VSS - ok
09:48:07.0770 0x1dfc VSTXRAID - ok
09:48:07.0793 0x1dfc vwifibus - ok
09:48:07.0799 0x1dfc vwififlt - ok
09:48:07.0809 0x1dfc vwifimp - ok
09:48:07.0894 0x1dfc W32Time - ok
09:48:07.0932 0x1dfc WacomPen - ok
09:48:08.0041 0x1dfc WalletService - ok
09:48:08.0053 0x1dfc wanarp - ok
09:48:08.0059 0x1dfc wanarpv6 - ok
09:48:08.0094 0x1dfc wbengine - ok
09:48:08.0116 0x1dfc WbioSrvc - ok
09:48:08.0187 0x1dfc wcifs - ok
09:48:08.0209 0x1dfc Wcmsvc - ok
09:48:08.0223 0x1dfc wcncsvc - ok
09:48:08.0228 0x1dfc wcnfs - ok
09:48:08.0235 0x1dfc WdBoot - ok
09:48:08.0241 0x1dfc Wdf01000 - ok
09:48:08.0255 0x1dfc WdFilter - ok
09:48:08.0276 0x1dfc WdiServiceHost - ok
09:48:08.0281 0x1dfc WdiSystemHost - ok
09:48:08.0289 0x1dfc wdiwifi - ok
09:48:08.0295 0x1dfc WdNisDrv - ok
09:48:08.0361 0x1dfc WdNisSvc - ok
09:48:08.0389 0x1dfc WebClient - ok
09:48:08.0433 0x1dfc Wecsvc - ok
09:48:08.0463 0x1dfc WEPHOSTSVC - ok
09:48:08.0501 0x1dfc wercplsupport - ok
09:48:08.0519 0x1dfc WerSvc - ok
09:48:08.0528 0x1dfc WFPLWFS - ok
09:48:08.0536 0x1dfc WiaRpc - ok
09:48:08.0565 0x1dfc WIMMount - ok
09:48:08.0570 0x1dfc WinDefend - ok
09:48:08.0623 0x1dfc WindowsTrustedRT - ok
09:48:08.0627 0x1dfc WindowsTrustedRTProxy - ok
09:48:08.0689 0x1dfc WinHttpAutoProxySvc - ok
09:48:08.0758 0x1dfc WinMad - ok
09:48:08.0790 0x1dfc Winmgmt - ok
09:48:08.0803 0x1dfc WinRM - ok
09:48:08.0829 0x1dfc WINUSB - ok
09:48:08.0844 0x1dfc WinVerbs - ok
09:48:08.0930 0x1dfc wisvc - ok
09:48:08.0998 0x1dfc WlanSvc - ok
09:48:09.0054 0x1dfc wlidsvc - ok
09:48:09.0059 0x1dfc WmiAcpi - ok
09:48:09.0094 0x1dfc wmiApSrv - ok
09:48:09.0125 0x1dfc WMPNetworkSvc - ok
09:48:09.0138 0x1dfc Wof - ok
09:48:09.0155 0x1dfc workfolderssvc - ok
09:48:09.0168 0x1dfc WPDBusEnum - ok
09:48:09.0212 0x1dfc WpdUpFltr - ok
09:48:09.0236 0x1dfc WpnService - ok
09:48:09.0243 0x1dfc WpnUserService - ok
09:48:09.0276 0x1dfc ws2ifsl - ok
09:48:09.0297 0x1dfc wscsvc - ok
09:48:09.0329 0x1dfc WSDPrintDevice - ok
09:48:09.0404 0x1dfc WSDScan - ok
09:48:09.0411 0x1dfc WSearch - ok
09:48:09.0471 0x1dfc wuauserv - ok
09:48:09.0476 0x1dfc WudfPf - ok
09:48:09.0482 0x1dfc WUDFRd - ok
09:48:09.0517 0x1dfc wudfsvc - ok
09:48:09.0526 0x1dfc WUDFWpdFs - ok
09:48:09.0604 0x1dfc WwanSvc - ok
09:48:09.0644 0x1dfc XblAuthManager - ok
09:48:09.0680 0x1dfc XblGameSave - ok
09:48:09.0712 0x1dfc xboxgip - ok
09:48:09.0765 0x1dfc XboxNetApiSvc - ok
09:48:09.0845 0x1dfc [ 65343781331B6AE59E01C4C337682DE4, 738D00277B9137BF3D7C427E41B7835AF41388CF6C04D494CA4525F96CF7F0CC ] xhunter1 C:\WINDOWS\xhunter1.sys
09:48:09.0907 0x1dfc xhunter1 - ok
09:48:09.0922 0x1dfc xinputhid - ok
09:48:09.0931 0x1dfc ================ Scan global ===============================
09:48:10.0075 0x1dfc [ Global ] - ok
09:48:10.0075 0x1dfc ================ Scan MBR ==================================
09:48:10.0137 0x1dfc [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
09:48:24.0021 0x1dfc \Device\Harddisk0\DR0 - ok
09:48:24.0022 0x1dfc ================ Scan VBR ==================================
09:48:24.0034 0x1dfc [ D8393C0DAD999B3D1B1E6EB915DF2D89 ] \Device\Harddisk0\DR0\Partition1
09:48:24.0049 0x1dfc \Device\Harddisk0\DR0\Partition1 - ok
09:48:24.0061 0x1dfc [ 05B046D7D4313F6540B14AAA0C888290 ] \Device\Harddisk0\DR0\Partition2
09:48:24.0100 0x1dfc \Device\Harddisk0\DR0\Partition2 - ok
09:48:24.0101 0x1dfc ================ Scan generic autorun ======================
09:48:24.0129 0x1dfc ETDCtrl - ok
09:48:24.0957 0x1dfc [ BF225BCD0EC2D85719C382019B5B4250, 7FE5A85209BD930FC1622600AB74E59854488986AA052A0D03D5FC7B361F247D ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
09:48:25.0347 0x1dfc RTHDVCPL - ok
09:48:25.0437 0x1dfc [ 0C3154D0620F974AD5C4E8D87626C8CF, 4E6B751F9C0D5D4833A12166BC5142E0A7402E98D00F570926ED9CA0936A8007 ] C:\WINDOWS\system32\igfxtray.exe
09:48:27.0275 0x1dfc IgfxTray - ok
09:48:27.0320 0x1dfc [ E4AA3D28753EF9DB333FE40079993B09, ECC60BAA7D21EF97CDA17F45277FBFE52B2169155DDB157E34A7AE2EC1BEC185 ] C:\WINDOWS\system32\hkcmd.exe
09:48:27.0344 0x1dfc HotKeysCmds - ok
09:48:27.0392 0x1dfc [ CF40080765D6F66FA93318C0DB6C7D1F, 015EE5BE439DAC6D3F7C7471EEF554C11F28947492E3F7AA14BB72622C327DCD ] C:\WINDOWS\system32\igfxpers.exe
09:48:27.0420 0x1dfc Persistence - ok
09:48:27.0613 0x1dfc [ 0FCF03482EA4AAA23E663E047CA48D41, 728156EEDAA37F41C11F141571F1136AD1599E151E9E11462568B3A7759DF984 ] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
09:48:27.0674 0x1dfc COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} - ok
09:48:27.0808 0x1dfc [ 1FAD6ACA65366E1AFF10EC6B02F47A84, 2DA16D06F553FC081E374F1699EC240D7FFFDD39D42774F044AE3DE09F2C8619 ] C:\Program Files\Microsoft Office\Office14\BCSSync.exe
09:48:27.0826 0x1dfc BCSSync - ok
09:48:28.0196 0x1dfc [ 739D7E0025F5CE97309695D3081E3823, 46A4B51123992B2FA3DF51F80C3E9E7118C6CCB6A68B6EDA3585BF87208B7DFC ] C:\Program Files\AMD\CNext\CNext\cnext.exe
09:48:28.0337 0x1dfc StartCN - ok
09:48:28.0436 0x1dfc [ 6513807FEE68E6C32E67437EE3FFB6C8, 2AB388BD68E984C38EAAF2D42DE918A64B42DA229627FC0B1A896A8AD60B5F91 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
09:48:28.0468 0x1dfc SunJavaUpdateSched - ok
09:48:28.0722 0x1dfc OneDriveSetup - ok
09:48:28.0725 0x1dfc OneDriveSetup - ok
09:48:28.0966 0x1dfc [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\Oliver\AppData\Local\Microsoft\OneDrive\OneDrive.exe
09:48:28.0992 0x1dfc OneDrive - ok
09:48:29.0237 0x1dfc [ ADF6C78FC95716CA45A68FD3DA1C1A78, 8250D47AC8C25A3A2DB8AB2148350F7086141F91DB317D0431DA545430B843F5 ] C:\Program Files (x86)\Steam\steam.exe
09:48:29.0350 0x1dfc Steam - ok
09:48:29.0572 0x1dfc [ 330049982A6CF1A2A0500E8E620889D3, 81A804621F9FAD520CB47FC084F6BD4EF2697E1FB8AF30596303089597FE7C2C ] C:\Users\Oliver\AppData\Roaming\Spotify\SpotifyWebHelper.exe
09:48:29.0625 0x1dfc Spotify Web Helper - ok
09:48:29.0704 0x1dfc [ F51BB12D8977D26C1A4CDA348770D9F1, DDA35CD8F8A6591B83821B5180D457740E0B820CCE000BC7FB1B78FB4AEAD3BA ] C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe
09:48:29.0852 0x1dfc SpybotPostWindows10UpgradeReInstall - detected UnsignedFile.Multi.Generic ( 1 )
09:48:29.0976 0x1dfc Detect skipped due to KSN trusted
09:48:29.0976 0x1dfc SpybotPostWindows10UpgradeReInstall - ok
09:48:30.0655 0x1dfc [ 8A793A1618B8C37FC70E85DC03E9567D, 568156DB22BB9E3411923BD3417C1E8BAFC641FB82C298FCFAAD8708BE8E7DF3 ] C:\Users\Oliver\AppData\Roaming\Spotify\Spotify.exe
09:48:30.0952 0x1dfc Spotify - ok
09:48:31.0017 0x1dfc Skype - ok
09:48:31.0995 0x1dfc [ 63405C389EB81881D68AEEB0E05F3F7D, BBE8D64C600A6FCA4BF4B89EF39B551DEB8ED826C33FD6FB2C7E2F7D773AB0E2 ] C:\Program Files\CCleaner\CCleaner64.exe
09:48:32.0353 0x1dfc CCleaner Monitoring - ok
09:48:32.0512 0x1dfc [ 1D37F21A8295466B831E446F3C3082B8, 680B2D309DB4318AD1619537233C70869B3C878FF161999838DDC37801BCC77D ] C:\Program Files\Sandboxie\SbieCtrl.exe
09:48:32.0543 0x1dfc SandboxieControl - ok
09:48:35.0647 0x1dfc Uninstall C:\Users\Oliver\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64 - ok
09:48:35.0726 0x1dfc AV detected via SS2: COMODO Antivirus, C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe ( 8.4.0.5076 ), 0x61010 ( enabled : outofdate )
09:48:35.0726 0x1dfc AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
09:48:35.0728 0x1dfc FW detected via SS2: COMODO Firewall, C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe ( 8.4.0.5076 ), 0x61010 ( enabled )
09:48:35.0845 0x1dfc ============================================================
09:48:35.0845 0x1dfc Scan finished
09:48:35.0845 0x1dfc ============================================================
09:48:35.0856 0x0fd4 Detected object count: 0
09:48:35.0856 0x0fd4 Actual detected object count: 0
09:48:43.0536 0x1978 ============================================================
09:48:43.0536 0x1978 Scan started
09:48:43.0536 0x1978 Mode: Manual; SigCheck; TDLFS;
09:48:43.0536 0x1978 ============================================================
09:48:43.0536 0x1978 KSN ping started
09:48:43.0603 0x1978 KSN ping finished: true
09:48:45.0354 0x1978 ================ Scan system memory ========================
09:48:45.0355 0x1978 System memory - ok
09:48:45.0355 0x1978 ================ Scan services =============================
09:48:48.0551 0x1978 1394ohci - ok
09:48:48.0556 0x1978 3ware - ok
09:48:48.0587 0x1978 ACPI - ok
09:48:48.0592 0x1978 AcpiDev - ok
09:48:48.0596 0x1978 acpiex - ok
09:48:48.0607 0x1978 acpipagr - ok
09:48:48.0644 0x1978 AcpiPmi - ok
09:48:48.0659 0x1978 acpitime - ok
09:48:48.0841 0x1978 [ A0CAC4F3F998173A8DC1E67E7E0345EF, D0C2F504A5059691EDBBA917D0C6260450A554A365C12E7747E48EE1668C51A5 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
09:48:48.0855 0x1978 AdobeARMservice - ok
09:48:49.0912 0x1978 [ 8FC33A20D54FB5CC7FBBA814B4E42A22, 707F61F0CEB9467D9BD1782868403BD53DB46EAB0342772661F370E5174AAD8C ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
09:48:49.0937 0x1978 AdobeFlashPlayerUpdateSvc - ok
09:48:49.0973 0x1978 ADP80XX - ok
09:48:49.0981 0x1978 AFD - ok
09:48:50.0211 0x1978 [ E20C1118524DF19945BCD83A3843E8CF, 90C87096E9E2595DAA503CFD9C24D7D8F9CB2D567ACAB06FBF5527C8A6059409 ] AGSService C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
09:48:50.0274 0x1978 AGSService - ok
09:48:50.0296 0x1978 ahcache - ok
09:48:50.0322 0x1978 AJRouter - ok
09:48:50.0353 0x1978 ALG - ok
09:48:50.0397 0x1978 [ D7A72B9BA6AB996DADB37BFCB0363D63, A223684978928B59D39DFB49F6658E0CF04ADD15AD8ACFCEC384DBD4D8C8CBCA ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
09:48:50.0423 0x1978 AMD External Events Utility - ok
09:48:50.0440 0x1978 AmdK8 - ok
09:48:50.0451 0x1978 amdkmdag - ok
09:48:50.0556 0x1978 [ C14D7E5F24381BC8F333C4EB77892400, 8B8EF49D2398AF39E36EFFE6D1E0489727D5612DEFA43C71E3C7E4C0650010A5 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
09:48:50.0596 0x1978 amdkmdap - ok
09:48:50.0624 0x1978 AmdPPM - ok
09:48:50.0628 0x1978 amdsata - ok
09:48:50.0641 0x1978 amdsbs - ok
09:48:50.0646 0x1978 amdxata - ok
09:48:50.0649 0x1978 AppID - ok
09:48:50.0667 0x1978 AppIDSvc - ok
09:48:50.0683 0x1978 Appinfo - ok
09:48:50.0702 0x1978 applockerfltr - ok
09:48:50.0737 0x1978 AppReadiness - ok
09:48:50.0772 0x1978 AppXSvc - ok
09:48:50.0818 0x1978 arcsas - ok
09:48:51.0056 0x1978 aspnet_state - ok
09:48:51.0060 0x1978 AsyncMac - ok
09:48:51.0084 0x1978 atapi - ok
09:48:51.0131 0x1978 athr - ok
09:48:51.0193 0x1978 AudioEndpointBuilder - ok
09:48:51.0227 0x1978 Audiosrv - ok
09:48:51.0233 0x1978 AxInstSV - ok
09:48:51.0250 0x1978 b06bdrv - ok
09:48:51.0259 0x1978 BasicDisplay - ok
09:48:51.0265 0x1978 BasicRender - ok
09:48:51.0274 0x1978 bcmfn - ok
09:48:51.0279 0x1978 bcmfn2 - ok
09:48:51.0306 0x1978 BDESVC - ok
09:48:51.0318 0x1978 Beep - ok
09:48:51.0340 0x1978 BFE - ok
09:48:51.0393 0x1978 BITS - ok
09:48:51.0490 0x1978 bowser - ok
09:48:51.0524 0x1978 BrokerInfrastructure - ok
09:48:51.0537 0x1978 Browser - ok
09:48:51.0579 0x1978 BthAvrcpTg - ok
09:48:51.0604 0x1978 BthHFEnum - ok
09:48:51.0617 0x1978 bthhfhid - ok
09:48:51.0662 0x1978 BthHFSrv - ok
09:48:51.0671 0x1978 BTHMODEM - ok
09:48:51.0682 0x1978 bthserv - ok
09:48:51.0718 0x1978 buttonconverter - ok
09:48:51.0733 0x1978 CapImg - ok
09:48:51.0740 0x1978 cdfs - ok
09:48:51.0759 0x1978 CDPSvc - ok
09:48:51.0782 0x1978 CDPUserSvc - ok
09:48:51.0849 0x1978 cdrom - ok
09:48:51.0868 0x1978 CertPropSvc - ok
09:48:51.0907 0x1978 cht4iscsi - ok
09:48:51.0917 0x1978 cht4vbd - ok
09:48:51.0991 0x1978 circlass - ok
09:48:51.0996 0x1978 CLFS - ok
09:48:52.0003 0x1978 ClipSVC - ok
09:48:52.0008 0x1978 clreg - ok
09:48:52.0023 0x1978 CmBatt - ok
09:48:52.0691 0x1978 [ 7DFC16B25788C97F3E9C42B1FCAC0A67, D729D138CAAE8295B750A48F8A9806F4C54224BEF4A5260EDDB5B1D959FC9CFF ] CmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
09:48:52.0924 0x1978 CmdAgent - ok
09:48:53.0002 0x1978 [ EAE2829CFBE8A84E3CC2A1451966E74F, 621AEA870D79A99FBA1339AA8C105A65ED3194E082DFFC33EA7513C0E5C453B5 ] cmderd C:\WINDOWS\system32\DRIVERS\cmderd.sys
09:48:53.0012 0x1978 cmderd - ok
09:48:53.0098 0x1978 [ 08400F4E1D6F586EE7C4136C4CB4B1D8, 629FED82F975BC18FCAA9E6B19C5A3CA42DAF2C2F9B383590987A62747707D74 ] cmdGuard C:\WINDOWS\system32\DRIVERS\cmdguard.sys
09:48:53.0195 0x1978 cmdGuard - ok
09:48:53.0265 0x1978 [ 752041CFBE3C0EEA5BC4E9F0E98F7929, A88C70610E242B0F3E459A0926A44D6F2CB179C741313D9B4602A48559E313ED ] cmdhlp C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
09:48:53.0284 0x1978 cmdhlp - ok
09:48:53.0650 0x1978 [ 084A29576C98C45E836CC977C1D311FD, BE01F6A181AB43590C15271E09BEC9B2CF14A011E7A8EE226CA1A2E6C874B39B ] cmdvirth C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
09:48:54.0908 0x1978 cmdvirth - ok
09:48:55.0095 0x1978 CNG - ok
09:48:55.0101 0x1978 cnghwassist - ok
09:48:55.0613 0x1978 CompositeBus - ok
09:48:55.0619 0x1978 COMSysApp - ok
09:48:55.0928 0x1978 condrv - ok
09:48:55.0990 0x1978 CoreMessagingRegistrar - ok
09:48:56.0724 0x1978 [ B18D590BC5220FDB4A747BC16D78ABC7, D46F8B43BAC22E55DE9AFC19CF371B1C4E8D3707163598B2F9884BB31D730C09 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
09:48:56.0750 0x1978 cphs - ok
09:48:56.0768 0x1978 CryptSvc - ok
09:48:56.0782 0x1978 dam - ok
09:48:56.0817 0x1978 DcomLaunch - ok
09:48:56.0853 0x1978 DcpSvc - ok
09:48:56.0871 0x1978 defragsvc - ok
09:48:56.0927 0x1978 DeviceAssociationService - ok
09:48:56.0942 0x1978 DeviceInstall - ok
09:48:56.0960 0x1978 DevQueryBroker - ok
09:48:56.0983 0x1978 Dfsc - ok
09:48:56.0988 0x1978 Dhcp - ok
09:48:57.0056 0x1978 diagnosticshub.standardcollector.service - ok
09:48:57.0084 0x1978 DiagTrack - ok
09:48:57.0107 0x1978 disk - ok
09:48:57.0142 0x1978 DmEnrollmentSvc - ok
09:48:57.0177 0x1978 dmvsc - ok
09:48:57.0207 0x1978 dmwappushservice - ok
09:48:57.0212 0x1978 Dnscache - ok
09:48:57.0224 0x1978 dot3svc - ok
09:48:57.0245 0x1978 DPS - ok
09:48:57.0268 0x1978 drmkaud - ok
09:48:57.0315 0x1978 DsmSvc - ok
09:48:57.0331 0x1978 DsSvc - ok
09:48:57.0350 0x1978 DXGKrnl - ok
09:48:57.0363 0x1978 EapHost - ok
09:48:57.0381 0x1978 ebdrv - ok
09:48:57.0416 0x1978 EFS - ok
09:48:57.0440 0x1978 EhStorClass - ok
09:48:57.0489 0x1978 EhStorTcgDrv - ok
09:48:57.0522 0x1978 embeddedmode - ok
09:48:57.0534 0x1978 EntAppSvc - ok
09:48:57.0544 0x1978 ErrDev - ok
09:48:57.0664 0x1978 [ 6BD85B39B7B23F03B24CF641ED29147B, 850F21750BB39E5239B1584E1117844CAAAF6A5C58E79366552309F917675CE5 ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
09:48:57.0700 0x1978 ETD - ok
09:48:57.0753 0x1978 [ 8916EACF1256E1C5A3AF81FD39C747E7, FF28FB95E9F9287C1005CF0D9EB84F7CA3D137689862860C9848398504E1EFFF ] ETDService C:\Program Files\Elantech\ETDService.exe
09:48:57.0769 0x1978 ETDService - ok
09:48:57.0827 0x1978 EventSystem - ok
09:48:57.0832 0x1978 exfat - ok
09:48:57.0850 0x1978 fastfat - ok
09:48:57.0861 0x1978 Fax - ok
09:48:57.0885 0x1978 fdc - ok
09:48:57.0898 0x1978 fdPHost - ok
09:48:57.0909 0x1978 FDResPub - ok
09:48:57.0917 0x1978 fhsvc - ok
09:48:57.0980 0x1978 FileCrypt - ok
09:48:57.0984 0x1978 FileInfo - ok
09:48:57.0992 0x1978 Filetrace - ok
09:48:57.0995 0x1978 flpydisk - ok
09:48:57.0999 0x1978 FltMgr - ok
09:48:58.0016 0x1978 FontCache - ok
09:48:58.0170 0x1978 FontCache3.0.0.0 - ok
09:48:58.0209 0x1978 FrameServer - ok
09:48:58.0227 0x1978 FsDepends - ok
09:48:58.0231 0x1978 Fs_Rec - ok
09:48:58.0236 0x1978 fvevol - ok
09:48:58.0266 0x1978 gencounter - ok
09:48:58.0287 0x1978 genericusbfn - ok
09:48:58.0297 0x1978 GPIOClx0101 - ok
09:48:58.0325 0x1978 gpsvc - ok
09:48:58.0346 0x1978 GpuEnergyDrv - ok
09:48:58.0389 0x1978 [ 7F79205B4EFA98F0767309479C8C01C6, 4B576903A83F33A8CF31D3887144A3D51C56D1187115C83AC99C0E9F6B4BF128 ] Hamachi C:\WINDOWS\System32\drivers\Hamdrv.sys
09:48:58.0418 0x1978 Hamachi - ok
09:48:58.0431 0x1978 HdAudAddService - ok
09:48:58.0463 0x1978 HDAudBus - ok
09:48:58.0467 0x1978 HidBatt - ok
09:48:58.0476 0x1978 HidBth - ok
09:48:58.0500 0x1978 hidi2c - ok
09:48:58.0517 0x1978 hidinterrupt - ok
09:48:58.0564 0x1978 HidIr - ok
09:48:58.0592 0x1978 hidserv - ok
09:48:58.0640 0x1978 HidUsb - ok
09:48:58.0676 0x1978 HomeGroupListener - ok
09:48:58.0703 0x1978 HomeGroupProvider - ok
09:48:58.0717 0x1978 HpSAMD - ok
09:48:58.0723 0x1978 HTTP - ok
09:48:58.0843 0x1978 HvHost - ok
09:48:58.0886 0x1978 hvservice - ok
09:48:58.0890 0x1978 hwpolicy - ok
09:48:58.0919 0x1978 hyperkbd - ok
09:48:58.0932 0x1978 i8042prt - ok
09:48:58.0936 0x1978 iagpio - ok
09:48:58.0942 0x1978 iai2c - ok
09:48:58.0947 0x1978 iaLPSS2i_GPIO2 - ok
09:48:58.0959 0x1978 iaLPSS2i_I2C - ok
09:48:58.0973 0x1978 iaLPSSi_GPIO - ok
09:48:58.0998 0x1978 iaLPSSi_I2C - ok
09:48:59.0016 0x1978 iaStorAV - ok
09:48:59.0020 0x1978 iaStorV - ok
09:48:59.0031 0x1978 ibbus - ok
09:48:59.0057 0x1978 icssvc - ok
09:48:59.0627 0x1978 [ 79AE3CC82CA1563A4B392207997ACE7C, A1E4A1DA95CA2FA197EF5975657822F0F813F6C33DA38E1FA5A840194034D071 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
09:48:59.0826 0x1978 igfx - ok
09:48:59.0859 0x1978 IKEEXT - ok
09:48:59.0902 0x1978 IndirectKmd - ok
09:48:59.0960 0x1978 [ 55BB2E54302416B9F7D2489FC16F7333, FD697F033D56DE76718A83514A468267235BE3AE1ECD2B5E7B8BCA1520699E7F ] inspect C:\WINDOWS\system32\DRIVERS\inspect.sys
09:48:59.0980 0x1978 inspect - ok
09:49:00.0348 0x1978 [ D172E06EFE08DF148155A59DB716C1B6, F059B0B37C5E944D70626E9F029BC6311029E0A9D778C9C75DDDDC59A5AF1605 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
09:49:00.0475 0x1978 IntcAzAudAddService - ok
09:49:00.0506 0x1978 intelide - ok
09:49:00.0510 0x1978 intelpep - ok
09:49:00.0514 0x1978 intelppm - ok
09:49:00.0518 0x1978 iorate - ok
09:49:00.0526 0x1978 IpFilterDriver - ok
09:49:00.0558 0x1978 iphlpsvc - ok
09:49:00.0608 0x1978 IPMIDRV - ok
09:49:00.0629 0x1978 IPNAT - ok
09:49:00.0832 0x1978 [ B76542085ABAD1AD4E5684F761DFC2EF, C6699B788D6E81E73519433F12BFD3B12C71A5EE2A12810697FE9C4350A179B3 ] IpOverUsbSvc C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
09:49:00.0849 0x1978 IpOverUsbSvc - ok
09:49:00.0853 0x1978 irda - ok
09:49:00.0857 0x1978 IRENUM - ok
09:49:00.0881 0x1978 irmon - ok
09:49:00.0919 0x1978 isapnp - ok
09:49:00.0933 0x1978 iScsiPrt - ok
09:49:00.0946 0x1978 kbdclass - ok
09:49:00.0951 0x1978 kbdhid - ok
09:49:00.0979 0x1978 kdnic - ok
09:49:00.0984 0x1978 KeyIso - ok
09:49:01.0009 0x1978 KSecDD - ok
09:49:01.0029 0x1978 KSecPkg - ok
09:49:01.0037 0x1978 ksthunk - ok
09:49:01.0062 0x1978 KtmRm - ok
09:49:01.0087 0x1978 L1C - ok
09:49:01.0107 0x1978 LanmanServer - ok
09:49:01.0128 0x1978 LanmanWorkstation - ok
09:49:01.0153 0x1978 lfsvc - ok
09:49:01.0219 0x1978 LicenseManager - ok
09:49:01.0240 0x1978 lltdio - ok
09:49:01.0267 0x1978 lltdsvc - ok
09:49:01.0291 0x1978 lmhosts - ok
09:49:01.0330 0x1978 LSI_SAS - ok
09:49:01.0334 0x1978 LSI_SAS2i - ok
09:49:01.0359 0x1978 LSI_SAS3i - ok
09:49:01.0371 0x1978 LSI_SSS - ok
09:49:01.0377 0x1978 LSM - ok
09:49:01.0382 0x1978 luafv - ok
09:49:01.0427 0x1978 MapsBroker - ok
09:49:01.0573 0x1978 megasas - ok
09:49:01.0592 0x1978 megasr - ok
09:49:01.0644 0x1978 [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
09:49:01.0654 0x1978 MEIx64 - ok
09:49:01.0679 0x1978 MessagingService - ok
09:49:01.0804 0x1978 Microsoft SharePoint Workspace Audit Service - ok
09:49:01.0830 0x1978 mlx4_bus - ok
09:49:01.0853 0x1978 MMCSS - ok
09:49:01.0861 0x1978 Modem - ok
09:49:01.0898 0x1978 monitor - ok
09:49:01.0909 0x1978 mouclass - ok
09:49:01.0923 0x1978 mouhid - ok
09:49:01.0930 0x1978 mountmgr - ok
09:49:01.0936 0x1978 mpsdrv - ok
09:49:01.0947 0x1978 MpsSvc - ok
09:49:01.0969 0x1978 MRxDAV - ok
09:49:01.0978 0x1978 mrxsmb - ok
09:49:01.0999 0x1978 mrxsmb10 - ok
09:49:02.0019 0x1978 mrxsmb20 - ok
09:49:02.0040 0x1978 MsBridge - ok
09:49:02.0065 0x1978 MSDTC - ok
09:49:02.0095 0x1978 Msfs - ok
09:49:02.0108 0x1978 msgpiowin32 - ok
09:49:02.0112 0x1978 mshidkmdf - ok
09:49:02.0131 0x1978 mshidumdf - ok
09:49:02.0135 0x1978 msisadrv - ok
09:49:02.0159 0x1978 MSiSCSI - ok
09:49:02.0164 0x1978 msiserver - ok
09:49:02.0173 0x1978 MSKSSRV - ok
09:49:02.0191 0x1978 MsLldp - ok
09:49:02.0194 0x1978 MSPCLOCK - ok
09:49:02.0200 0x1978 MSPQM - ok
09:49:02.0209 0x1978 MsRPC - ok
09:49:02.0231 0x1978 mssmbios - ok
09:49:02.0235 0x1978 MSTEE - ok
09:49:02.0245 0x1978 MTConfig - ok
09:49:02.0256 0x1978 Mup - ok
09:49:02.0264 0x1978 mvumis - ok
09:49:02.0285 0x1978 NativeWifiP - ok
09:49:02.0313 0x1978 NcaSvc - ok
09:49:02.0345 0x1978 NcbService - ok
09:49:02.0353 0x1978 NcdAutoSetup - ok
09:49:02.0376 0x1978 ndfltr - ok
09:49:02.0406 0x1978 NDIS - ok
09:49:02.0415 0x1978 NdisCap - ok
09:49:02.0453 0x1978 NdisImPlatform - ok
09:49:02.0457 0x1978 NdisTapi - ok
09:49:02.0464 0x1978 Ndisuio - ok
09:49:02.0487 0x1978 NdisVirtualBus - ok
09:49:02.0497 0x1978 NdisWan - ok
09:49:02.0501 0x1978 ndiswanlegacy - ok
09:49:02.0506 0x1978 ndproxy - ok
09:49:02.0513 0x1978 Ndu - ok
09:49:02.0519 0x1978 NetAdapterCx - ok
09:49:02.0539 0x1978 NetBIOS - ok
09:49:02.0549 0x1978 NetBT - ok
09:49:02.0553 0x1978 Netlogon - ok
09:49:02.0570 0x1978 Netman - ok
09:49:02.0589 0x1978 netprofm - ok
09:49:02.0629 0x1978 NetSetupSvc - ok
09:49:02.0747 0x1978 NetTcpPortSharing - ok
09:49:02.0790 0x1978 NgcCtnrSvc - ok
09:49:02.0806 0x1978 NgcSvc - ok
09:49:02.0826 0x1978 NlaSvc - ok
09:49:02.0840 0x1978 Npfs - ok
09:49:02.0876 0x1978 npsvctrig - ok
09:49:02.0894 0x1978 nsi - ok
09:49:02.0902 0x1978 nsiproxy - ok
09:49:02.0929 0x1978 NTFS - ok
09:49:02.0941 0x1978 Null - ok
09:49:02.0976 0x1978 nvraid - ok
09:49:02.0990 0x1978 nvstor - ok
09:49:03.0023 0x1978 OneSyncSvc - ok
09:49:03.0107 0x1978 [ 4965B005492CBA7719E82B71E3245495, 52AD72C05FACC1E0E416A1FA25F34FDD3CB274FAB973BEAAE911A2FACA42B650 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
09:49:03.0121 0x1978 ose64 - ok
09:49:03.0478 0x1978 [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
09:49:03.0619 0x1978 osppsvc - ok
09:49:03.0667 0x1978 p2pimsvc - ok
09:49:03.0709 0x1978 p2psvc - ok
09:49:03.0712 0x1978 Parport - ok
09:49:03.0730 0x1978 partmgr - ok
09:49:03.0737 0x1978 PcaSvc - ok
09:49:03.0820 0x1978 pci - ok
09:49:03.0824 0x1978 pciide - ok
09:49:03.0837 0x1978 pcmcia - ok
09:49:03.0851 0x1978 pcw - ok
09:49:03.0889 0x1978 pdc - ok
09:49:03.0918 0x1978 PEAUTH - ok
09:49:03.0964 0x1978 percsas2i - ok
09:49:03.0969 0x1978 percsas3i - ok
09:49:05.0523 0x1978 PerfHost - ok
09:49:05.0627 0x1978 PhoneSvc - ok
09:49:05.0684 0x1978 PimIndexMaintenanceSvc - ok
09:49:05.0710 0x1978 pla - ok
09:49:05.0730 0x1978 PlugPlay - ok
09:49:05.0768 0x1978 PNRPAutoReg - ok
09:49:05.0774 0x1978 PNRPsvc - ok
09:49:05.0792 0x1978 PolicyAgent - ok
09:49:05.0799 0x1978 Power - ok
09:49:05.0929 0x1978 PptpMiniport - ok
09:49:06.0750 0x1978 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
09:49:06.0937 0x1978 PrintNotify - ok
09:49:06.0975 0x1978 Processor - ok
09:49:07.0016 0x1978 ProfSvc - ok
09:49:07.0020 0x1978 Psched - ok
09:49:07.0037 0x1978 QWAVE - ok
09:49:07.0062 0x1978 QWAVEdrv - ok
09:49:07.0084 0x1978 RasAcd - ok
09:49:07.0116 0x1978 RasAgileVpn - ok
09:49:07.0130 0x1978 RasAuto - ok
09:49:07.0135 0x1978 Rasl2tp - ok
09:49:07.0146 0x1978 RasMan - ok
09:49:07.0152 0x1978 RasPppoe - ok
09:49:07.0157 0x1978 RasSstp - ok
09:49:07.0181 0x1978 rdbss - ok
09:49:07.0221 0x1978 rdpbus - ok
09:49:07.0226 0x1978 RDPDR - ok
09:49:07.0262 0x1978 RdpVideoMiniport - ok
09:49:07.0295 0x1978 rdyboost - ok
09:49:07.0831 0x1978 [ F1D9E7B84A123F8861F63A2AE1E9F144, 7A56188DE148525B23617F8DA4AD49A88FA1BFC48641ED5065896C4408DA44ED ] ReflectService.exe C:\Program Files\Recovery\Macrium\ReflectService.exe
09:49:07.0936 0x1978 ReflectService.exe - ok
09:49:07.0945 0x1978 ReFSv1 - ok
09:49:07.0970 0x1978 RemoteAccess - ok
09:49:08.0005 0x1978 RemoteRegistry - ok
09:49:08.0050 0x1978 RetailDemo - ok
09:49:08.0063 0x1978 RmSvc - ok
09:49:08.0105 0x1978 RpcEptMapper - ok
09:49:08.0153 0x1978 RpcLocator - ok
09:49:08.0159 0x1978 RpcSs - ok
09:49:08.0208 0x1978 rspndr - ok
09:49:08.0275 0x1978 [ AB959F26FBB851A9D31E2F229DB3FA1A, 35961B761C83B48DBB9960C6DEC89806F3BC9FA0F450E566333ABE3F22E42AA9 ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
09:49:08.0306 0x1978 RTSUER - ok
09:49:08.0354 0x1978 s3cap - ok
09:49:08.0393 0x1978 SamSs - ok
09:49:08.0515 0x1978 [ D95D61869CE6A7F916E53F82E4C7917D, 423BCDFBCD5C670D13F1C390DF6CA83C91137C8FCBD2A07BE03DDD823E8CAB4F ] SbieDrv C:\Program Files\Sandboxie\SbieDrv.sys
09:49:08.0535 0x1978 SbieDrv - ok
09:49:08.0592 0x1978 [ 8F237507759186A689450BD9B8CAB7AC, C08A26CE02872281E8C186A0824552DB9A3286D041ADAFBF3F977BBE0EBC266B ] SbieSvc C:\Program Files\Sandboxie\SbieSvc.exe
09:49:08.0609 0x1978 SbieSvc - ok
09:49:08.0653 0x1978 sbp2port - ok
09:49:08.0664 0x1978 SCardSvr - ok
09:49:08.0705 0x1978 ScDeviceEnum - ok
09:49:08.0729 0x1978 scfilter - ok
09:49:08.0744 0x1978 Schedule - ok
09:49:08.0773 0x1978 scmbus - ok
09:49:08.0809 0x1978 scmdisk0101 - ok
09:49:08.0836 0x1978 SCPolicySvc - ok
09:49:08.0887 0x1978 [ AD7189E85A0801DE0507C610963A3CD0, 0AA9F3C9D252624CC62EC95FD910C6911E136DD3E66159CEB9857BC7AB70FAA2 ] ScpVBus C:\WINDOWS\System32\drivers\ScpVBus.sys
09:49:08.0899 0x1978 ScpVBus - ok
09:49:09.0366 0x1978 sdbus - ok
09:49:09.0386 0x1978 SDRSVC - ok
09:49:09.0431 0x1978 sdstor - ok
09:49:09.0441 0x1978 seclogon - ok
09:49:09.0459 0x1978 SENS - ok
09:49:09.0524 0x1978 SensorDataService - ok
09:49:09.0539 0x1978 SensorService - ok
09:49:09.0549 0x1978 SensrSvc - ok
09:49:09.0553 0x1978 SerCx - ok
09:49:09.0563 0x1978 SerCx2 - ok
09:49:09.0587 0x1978 Serenum - ok
09:49:09.0591 0x1978 Serial - ok
09:49:09.0596 0x1978 sermouse - ok
09:49:09.0614 0x1978 SessionEnv - ok
09:49:09.0654 0x1978 sfloppy - ok
09:49:09.0702 0x1978 SharedAccess - ok
09:49:09.0715 0x1978 ShellHWDetection - ok
09:49:09.0743 0x1978 shpamsvc - ok
09:49:09.0751 0x1978 SiSRaid2 - ok
09:49:09.0756 0x1978 SiSRaid4 - ok
09:49:09.0977 0x1978 [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
09:49:09.0996 0x1978 SkypeUpdate - ok
09:49:10.0070 0x1978 [ AF9CA3A881483E6999CB2764BDAD3414, 95D6F7DA34DAD2CC1E4BC0B0867FA7E90293FB082EE0372DF5FE663E2AFD7AA4 ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
09:49:10.0078 0x1978 SmbDrvI - ok
09:49:10.0141 0x1978 smphost - ok
09:49:10.0163 0x1978 SmsRouter - ok
09:49:10.0227 0x1978 SNMPTRAP - ok
09:49:10.0265 0x1978 spaceport - ok
09:49:10.0269 0x1978 SpbCx - ok
09:49:10.0307 0x1978 Spooler - ok
09:49:10.0345 0x1978 sppsvc - ok
09:49:10.0370 0x1978 srv - ok
09:49:10.0410 0x1978 srv2 - ok
09:49:10.0422 0x1978 srvnet - ok
09:49:10.0455 0x1978 SSDPSRV - ok
09:49:10.0474 0x1978 SstpSvc - ok
09:49:10.0554 0x1978 StateRepository - ok
09:49:10.0858 0x1978 [ E06AA279D85877268E34E9A9BC41F560, 6EFE7E3850CD19B919053293B6D8CB61CC638D3B1626BB62594C681625132689 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
09:49:10.0906 0x1978 Steam Client Service - ok
09:49:10.0944 0x1978 stexstor - ok
09:49:10.0965 0x1978 stisvc - ok
09:49:10.0972 0x1978 storahci - ok
09:49:11.0092 0x1978 storflt - ok
09:49:11.0117 0x1978 stornvme - ok
09:49:11.0124 0x1978 storqosflt - ok
09:49:11.0158 0x1978 StorSvc - ok
09:49:11.0165 0x1978 storufs - ok
09:49:11.0171 0x1978 storvsc - ok
09:49:11.0196 0x1978 svsvc - ok
09:49:11.0206 0x1978 swenum - ok
09:49:11.0212 0x1978 swprv - ok
09:49:11.0243 0x1978 Synth3dVsc - ok
09:49:11.0269 0x1978 SysMain - ok
09:49:11.0286 0x1978 SystemEventsBroker - ok
09:49:11.0312 0x1978 TabletInputService - ok
09:49:11.0360 0x1978 [ 876F4A55F3F5319132E3AC8DC7E75EF8, 2A347F168D406700E83F8BE39BB74E656ADD487018A73F0F4316348CD03C9F36 ] tap0901t C:\WINDOWS\System32\drivers\tap0901t.sys
09:49:11.0375 0x1978 tap0901t - ok
09:49:11.0391 0x1978 TapiSrv - ok
09:49:11.0419 0x1978 Tcpip - ok
09:49:11.0424 0x1978 Tcpip6 - ok
09:49:11.0431 0x1978 tcpipreg - ok
09:49:11.0451 0x1978 tdx - ok
09:49:11.0604 0x1978 [ 1A4B1847BD8C7079C3A6C873342CC84A, E49E60896C6726EB8F8EE3A443B839AA6A6E802919C7D102DD820AD7C3DDA32C ] Te.Service C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe
09:49:11.0615 0x1978 Te.Service - detected UnsignedFile.Multi.Generic ( 1 )
09:49:11.0615 0x1978 Detect skipped due to KSN trusted
09:49:11.0615 0x1978 Te.Service - ok
09:49:11.0629 0x1978 terminpt - ok
09:49:11.0646 0x1978 TermService - ok
09:49:11.0667 0x1978 Themes - ok
09:49:11.0714 0x1978 TieringEngineService - ok
09:49:11.0727 0x1978 tiledatamodelsvc - ok
09:49:11.0739 0x1978 TimeBrokerSvc - ok
09:49:11.0766 0x1978 TPM - ok
09:49:11.0779 0x1978 TrkWks - ok
09:49:11.0869 0x1978 TrustedInstaller - ok
09:49:11.0876 0x1978 tsusbflt - ok
09:49:11.0898 0x1978 TsUsbGD - ok
09:49:11.0929 0x1978 tunnel - ok
09:49:12.0056 0x1978 [ E775DAF583CFF96F81306A4A93E501FE, C6F54D6D524CA3D3872C7BD53904A203F55C99EF93E08077183192587BE32D86 ] TunngleService C:\Program Files (x86)\Tunngle\TnglCtrl.exe
09:49:12.0092 0x1978 TunngleService - ok
09:49:12.0149 0x1978 tzautoupdate - ok
09:49:12.0155 0x1978 UASPStor - ok
09:49:12.0161 0x1978 UcmCx0101 - ok
09:49:12.0187 0x1978 UcmTcpciCx0101 - ok
09:49:12.0207 0x1978 UcmUcsi - ok
09:49:12.0230 0x1978 Ucx01000 - ok
09:49:12.0235 0x1978 UdeCx - ok
09:49:12.0241 0x1978 udfs - ok
09:49:12.0266 0x1978 UEFI - ok
09:49:12.0296 0x1978 Ufx01000 - ok
09:49:12.0310 0x1978 UfxChipidea - ok
09:49:12.0318 0x1978 ufxsynopsys - ok
09:49:12.0381 0x1978 UI0Detect - ok
09:49:12.0388 0x1978 umbus - ok
09:49:12.0408 0x1978 UmPass - ok
09:49:12.0437 0x1978 UmRdpService - ok
09:49:12.0446 0x1978 UnistoreSvc - ok
09:49:12.0467 0x1978 upnphost - ok
09:49:12.0475 0x1978 UrsChipidea - ok
09:49:12.0498 0x1978 UrsCx01000 - ok
09:49:12.0502 0x1978 UrsSynopsys - ok
09:49:12.0529 0x1978 usbccgp - ok
09:49:12.0564 0x1978 usbcir - ok
09:49:12.0575 0x1978 usbehci - ok
09:49:12.0579 0x1978 usbhub - ok
09:49:12.0596 0x1978 USBHUB3 - ok
09:49:12.0609 0x1978 usbohci - ok
09:49:12.0614 0x1978 usbprint - ok
09:49:12.0622 0x1978 usbser - ok
09:49:12.0638 0x1978 USBSTOR - ok
09:49:12.0655 0x1978 usbuhci - ok
09:49:12.0679 0x1978 usbvideo - ok
09:49:12.0687 0x1978 USBXHCI - ok
09:49:12.0714 0x1978 UserDataSvc - ok
09:49:12.0752 0x1978 UserManager - ok
09:49:12.0787 0x1978 UsoSvc - ok
09:49:12.0795 0x1978 VaultSvc - ok
09:49:12.0818 0x1978 vdrvroot - ok
09:49:12.0848 0x1978 vds - ok
09:49:12.0855 0x1978 VerifierExt - ok
09:49:12.0878 0x1978 vhdmp - ok
09:49:12.0884 0x1978 vhf - ok
09:49:12.0891 0x1978 vmbus - ok
09:49:12.0897 0x1978 VMBusHID - ok
09:49:12.0918 0x1978 vmgid - ok
09:49:12.0942 0x1978 vmicguestinterface - ok
09:49:12.0948 0x1978 vmicheartbeat - ok
09:49:12.0963 0x1978 vmickvpexchange - ok
09:49:13.0005 0x1978 vmicrdv - ok
09:49:13.0014 0x1978 vmicshutdown - ok
09:49:13.0022 0x1978 vmictimesync - ok
09:49:13.0036 0x1978 vmicvmsession - ok
09:49:13.0049 0x1978 vmicvss - ok
09:49:13.0056 0x1978 volmgr - ok
09:49:13.0064 0x1978 volmgrx - ok
09:49:13.0076 0x1978 volsnap - ok
09:49:13.0094 0x1978 volume - ok
09:49:13.0121 0x1978 vpci - ok
09:49:13.0129 0x1978 vsmraid - ok
09:49:13.0147 0x1978 VSS - ok
09:49:13.0156 0x1978 VSTXRAID - ok
09:49:13.0185 0x1978 vwifibus - ok
09:49:13.0195 0x1978 vwififlt - ok
09:49:13.0209 0x1978 vwifimp - ok
09:49:13.0259 0x1978 W32Time - ok
09:49:13.0275 0x1978 WacomPen - ok
09:49:13.0316 0x1978 WalletService - ok
09:49:13.0328 0x1978 wanarp - ok
09:49:13.0335 0x1978 wanarpv6 - ok
09:49:13.0341 0x1978 wbengine - ok
09:49:13.0356 0x1978 WbioSrvc - ok
09:49:13.0364 0x1978 wcifs - ok
09:49:13.0383 0x1978 Wcmsvc - ok
09:49:13.0393 0x1978 wcncsvc - ok
09:49:13.0398 0x1978 wcnfs - ok
09:49:13.0404 0x1978 WdBoot - ok
09:49:13.0410 0x1978 Wdf01000 - ok
09:49:13.0420 0x1978 WdFilter - ok
09:49:13.0433 0x1978 WdiServiceHost - ok
09:49:13.0441 0x1978 WdiSystemHost - ok
09:49:13.0452 0x1978 wdiwifi - ok
09:49:13.0459 0x1978 WdNisDrv - ok
09:49:13.0492 0x1978 WdNisSvc - ok
09:49:13.0501 0x1978 WebClient - ok
09:49:13.0508 0x1978 Wecsvc - ok
09:49:13.0529 0x1978 WEPHOSTSVC - ok
09:49:13.0537 0x1978 wercplsupport - ok
09:49:13.0555 0x1978 WerSvc - ok
09:49:13.0564 0x1978 WFPLWFS - ok
09:49:13.0576 0x1978 WiaRpc - ok
09:49:13.0607 0x1978 WIMMount - ok
09:49:13.0611 0x1978 WinDefend - ok
09:49:13.0665 0x1978 WindowsTrustedRT - ok
09:49:13.0670 0x1978 WindowsTrustedRTProxy - ok
09:49:13.0698 0x1978 WinHttpAutoProxySvc - ok
09:49:13.0728 0x1978 WinMad - ok
09:49:14.0019 0x1978 Winmgmt - ok
09:49:14.0045 0x1978 WinRM - ok
09:49:14.0088 0x1978 WINUSB - ok
09:49:14.0104 0x1978 WinVerbs - ok
09:49:14.0150 0x1978 wisvc - ok
09:49:14.0206 0x1978 WlanSvc - ok
09:49:14.0229 0x1978 wlidsvc - ok
09:49:14.0235 0x1978 WmiAcpi - ok
09:49:14.0259 0x1978 wmiApSrv - ok
09:49:14.0289 0x1978 WMPNetworkSvc - ok
09:49:14.0313 0x1978 Wof - ok
09:49:14.0353 0x1978 workfolderssvc - ok
09:49:14.0364 0x1978 WPDBusEnum - ok
09:49:14.0399 0x1978 WpdUpFltr - ok
09:49:14.0434 0x1978 WpnService - ok
09:49:14.0442 0x1978 WpnUserService - ok
09:49:14.0474 0x1978 ws2ifsl - ok
09:49:14.0480 0x1978 wscsvc - ok
09:49:14.0492 0x1978 WSDPrintDevice - ok
09:49:14.0512 0x1978 WSDScan - ok
09:49:14.0517 0x1978 WSearch - ok
09:49:14.0558 0x1978 wuauserv - ok
09:49:14.0568 0x1978 WudfPf - ok
09:49:14.0572 0x1978 WUDFRd - ok
09:49:14.0589 0x1978 wudfsvc - ok
09:49:14.0597 0x1978 WUDFWpdFs - ok
09:49:14.0655 0x1978 WwanSvc - ok
09:49:14.0684 0x1978 XblAuthManager - ok
09:49:14.0700 0x1978 XblGameSave - ok
09:49:14.0721 0x1978 xboxgip - ok
09:49:14.0732 0x1978 XboxNetApiSvc - ok
09:49:14.0777 0x1978 [ 65343781331B6AE59E01C4C337682DE4, 738D00277B9137BF3D7C427E41B7835AF41388CF6C04D494CA4525F96CF7F0CC ] xhunter1 C:\WINDOWS\xhunter1.sys
09:49:14.0785 0x1978 xhunter1 - ok
09:49:14.0809 0x1978 xinputhid - ok
09:49:14.0811 0x1978 ================ Scan global ===============================
09:49:14.0924 0x1978 [ Global ] - ok
09:49:14.0925 0x1978 ================ Scan MBR ==================================
09:49:14.0946 0x1978 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
09:49:24.0111 0x1978 \Device\Harddisk0\DR0 - ok
09:49:24.0111 0x1978 ================ Scan VBR ==================================
09:49:24.0132 0x1978 [ D8393C0DAD999B3D1B1E6EB915DF2D89 ] \Device\Harddisk0\DR0\Partition1
09:49:24.0157 0x1978 \Device\Harddisk0\DR0\Partition1 - ok
09:49:24.0168 0x1978 [ 05B046D7D4313F6540B14AAA0C888290 ] \Device\Harddisk0\DR0\Partition2
09:49:24.0187 0x1978 \Device\Harddisk0\DR0\Partition2 - ok
09:49:24.0187 0x1978 ================ Scan generic autorun ======================
09:49:24.0233 0x1978 ETDCtrl - ok
09:49:25.0732 0x1978 [ BF225BCD0EC2D85719C382019B5B4250, 7FE5A85209BD930FC1622600AB74E59854488986AA052A0D03D5FC7B361F247D ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
09:49:26.0102 0x1978 RTHDVCPL - ok
09:49:26.0347 0x1978 [ 0C3154D0620F974AD5C4E8D87626C8CF, 4E6B751F9C0D5D4833A12166BC5142E0A7402E98D00F570926ED9CA0936A8007 ] C:\WINDOWS\system32\igfxtray.exe
09:49:26.0368 0x1978 IgfxTray - ok
09:49:26.0441 0x1978 [ E4AA3D28753EF9DB333FE40079993B09, ECC60BAA7D21EF97CDA17F45277FBFE52B2169155DDB157E34A7AE2EC1BEC185 ] C:\WINDOWS\system32\hkcmd.exe
09:49:26.0463 0x1978 HotKeysCmds - ok
09:49:26.0541 0x1978 [ CF40080765D6F66FA93318C0DB6C7D1F, 015EE5BE439DAC6D3F7C7471EEF554C11F28947492E3F7AA14BB72622C327DCD ] C:\WINDOWS\system32\igfxpers.exe
09:49:26.0568 0x1978 Persistence - ok
09:49:26.0841 0x1978 [ 0FCF03482EA4AAA23E663E047CA48D41, 728156EEDAA37F41C11F141571F1136AD1599E151E9E11462568B3A7759DF984 ] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
09:49:26.0891 0x1978 COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} - ok
09:49:27.0017 0x1978 [ 1FAD6ACA65366E1AFF10EC6B02F47A84, 2DA16D06F553FC081E374F1699EC240D7FFFDD39D42774F044AE3DE09F2C8619 ] C:\Program Files\Microsoft Office\Office14\BCSSync.exe
09:49:27.0027 0x1978 BCSSync - ok
09:49:27.0637 0x1978 [ 739D7E0025F5CE97309695D3081E3823, 46A4B51123992B2FA3DF51F80C3E9E7118C6CCB6A68B6EDA3585BF87208B7DFC ] C:\Program Files\AMD\CNext\CNext\cnext.exe
09:49:27.0770 0x1978 StartCN - ok
09:49:27.0905 0x1978 [ 6513807FEE68E6C32E67437EE3FFB6C8, 2AB388BD68E984C38EAAF2D42DE918A64B42DA229627FC0B1A896A8AD60B5F91 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
09:49:27.0930 0x1978 SunJavaUpdateSched - ok
09:49:28.0353 0x1978 OneDriveSetup - ok
09:49:28.0355 0x1978 OneDriveSetup - ok
09:49:28.0653 0x1978 [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\Oliver\AppData\Local\Microsoft\OneDrive\OneDrive.exe
09:49:28.0676 0x1978 OneDrive - ok
09:49:29.0355 0x1978 [ ADF6C78FC95716CA45A68FD3DA1C1A78, 8250D47AC8C25A3A2DB8AB2148350F7086141F91DB317D0431DA545430B843F5 ] C:\Program Files (x86)\Steam\steam.exe
09:49:29.0453 0x1978 Steam - ok
09:49:30.0081 0x1978 [ 330049982A6CF1A2A0500E8E620889D3, 81A804621F9FAD520CB47FC084F6BD4EF2697E1FB8AF30596303089597FE7C2C ] C:\Users\Oliver\AppData\Roaming\Spotify\SpotifyWebHelper.exe
09:49:30.0131 0x1978 Spotify Web Helper - ok
09:49:30.0375 0x1978 [ F51BB12D8977D26C1A4CDA348770D9F1, DDA35CD8F8A6591B83821B5180D457740E0B820CCE000BC7FB1B78FB4AEAD3BA ] C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe
09:49:30.0434 0x1978 SpybotPostWindows10UpgradeReInstall - detected UnsignedFile.Multi.Generic ( 1 )
09:49:30.0434 0x1978 Detect skipped due to KSN trusted
09:49:30.0434 0x1978 SpybotPostWindows10UpgradeReInstall - ok
09:49:31.0207 0x1978 [ 8A793A1618B8C37FC70E85DC03E9567D, 568156DB22BB9E3411923BD3417C1E8BAFC641FB82C298FCFAAD8708BE8E7DF3 ] C:\Users\Oliver\AppData\Roaming\Spotify\Spotify.exe
09:49:31.0386 0x1978 Spotify - ok
09:49:31.0459 0x1978 Skype - ok
09:49:33.0181 0x1978 [ 63405C389EB81881D68AEEB0E05F3F7D, BBE8D64C600A6FCA4BF4B89EF39B551DEB8ED826C33FD6FB2C7E2F7D773AB0E2 ] C:\Program Files\CCleaner\CCleaner64.exe
09:49:33.0456 0x1978 CCleaner Monitoring - ok
09:49:33.0690 0x1978 [ 1D37F21A8295466B831E446F3C3082B8, 680B2D309DB4318AD1619537233C70869B3C878FF161999838DDC37801BCC77D ] C:\Program Files\Sandboxie\SbieCtrl.exe
09:49:33.0718 0x1978 SandboxieControl - ok
09:49:34.0329 0x1978 Uninstall C:\Users\Oliver\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64 - ok
09:49:34.0341 0x1978 AV detected via SS2: COMODO Antivirus, C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe ( 8.4.0.5076 ), 0x61010 ( enabled : outofdate )
09:49:34.0341 0x1978 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
09:49:34.0343 0x1978 FW detected via SS2: COMODO Firewall, C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe ( 8.4.0.5076 ), 0x61010 ( enabled )
09:49:34.0457 0x1978 ============================================================
09:49:34.0457 0x1978 Scan finished
09:49:34.0457 0x1978 ============================================================
09:49:34.0466 0x0fbc Detected object count: 0
09:49:34.0466 0x0fbc Actual detected object count: 0 Grüsse! |