Code:
15:38:22.0904 0x23e8 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
15:38:22.0904 0x23e8 UEFI system
15:38:26.0490 0x23e8 ============================================================
15:38:26.0490 0x23e8 Current date / time: 2016/11/08 15:38:26.0490
15:38:26.0490 0x23e8 SystemInfo:
15:38:26.0490 0x23e8
15:38:26.0490 0x23e8 OS Version: 10.0.14393 ServicePack: 0.0
15:38:26.0490 0x23e8 Product type: Workstation
15:38:26.0490 0x23e8 ComputerName: COMEBACK
15:38:26.0490 0x23e8 UserName: Aleksandar
15:38:26.0490 0x23e8 Windows directory: C:\WINDOWS
15:38:26.0490 0x23e8 System windows directory: C:\WINDOWS
15:38:26.0490 0x23e8 Running under WOW64
15:38:26.0490 0x23e8 Processor architecture: Intel x64
15:38:26.0490 0x23e8 Number of processors: 4
15:38:26.0490 0x23e8 Page size: 0x1000
15:38:26.0490 0x23e8 Boot type: Normal boot
15:38:26.0490 0x23e8 CodeIntegrityOptions = 0x00000001
15:38:26.0490 0x23e8 ============================================================
15:38:26.0741 0x23e8 KLMD registered as C:\WINDOWS\system32\drivers\27969094.sys
15:38:26.0741 0x23e8 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.351, osProperties = 0x19
15:38:27.0488 0x23e8 System UUID: {2E6A0DDA-3572-B788-1EF0-67A2BD79C72A}
15:38:27.0953 0x23e8 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:38:27.0986 0x23e8 ============================================================
15:38:27.0986 0x23e8 \Device\Harddisk0\DR0:
15:38:27.0994 0x23e8 GPT partitions:
15:38:27.0994 0x23e8 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {C1C6EC63-DBE1-48E3-8003-C0402DFC79D2}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0xF9800
15:38:27.0994 0x23e8 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {99C904D8-D49A-416F-9C34-FC8B2C21C15F}, Name: EFI system partition, StartLBA 0xFA000, BlocksNum 0x32000
15:38:27.0994 0x23e8 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {001B3BAD-F362-48D6-AE5F-15EF2BDB23FF}, Name: Microsoft reserved partition, StartLBA 0x12C000, BlocksNum 0x40000
15:38:27.0994 0x23e8 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {8D7F0CC6-879E-47F6-A767-0ED8FD3B0659}, UniqueGUID: {75FF9B77-0140-43E8-9A08-D17994DFDE1C}, Name: Basic data partition, StartLBA 0x16C000, BlocksNum 0x200000
15:38:27.0994 0x23e8 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {C32F3F10-0099-4F33-896E-A164539C2BC6}, Name: Basic data partition, StartLBA 0x36C000, BlocksNum 0x6CAB9000
15:38:27.0994 0x23e8 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {F9C92E28-0B46-4FAC-8F74-6A998D57251F}, Name: , StartLBA 0x6CE25000, BlocksNum 0xE1000
15:38:27.0994 0x23e8 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {452E6CB4-9755-4903-8BD5-BC6AFBA554AD}, Name: Basic data partition, StartLBA 0x6CF06000, BlocksNum 0x7800000
15:38:27.0994 0x23e8 MBR partitions:
15:38:27.0994 0x23e8 ============================================================
15:38:28.0016 0x23e8 C: <-> \Device\Harddisk0\DR0\Partition5
15:38:28.0058 0x23e8 D: <-> \Device\Harddisk0\DR0\Partition7
15:38:28.0058 0x23e8 ============================================================
15:38:28.0058 0x23e8 Initialize success
15:38:28.0058 0x23e8 ============================================================
15:39:22.0014 0x0894 ============================================================
15:39:22.0014 0x0894 Scan started
15:39:22.0014 0x0894 Mode: Manual; SigCheck; TDLFS;
15:39:22.0014 0x0894 ============================================================
15:39:22.0014 0x0894 KSN ping started
15:39:22.0130 0x0894 KSN ping finished: true
15:39:25.0415 0x0894 ================ Scan system memory ========================
15:39:25.0415 0x0894 System memory - ok
15:39:25.0416 0x0894 ================ Scan services =============================
15:39:25.0557 0x0894 1394ohci - ok
15:39:25.0566 0x0894 3ware - ok
15:39:25.0590 0x0894 ACPI - ok
15:39:25.0598 0x0894 AcpiDev - ok
15:39:25.0606 0x0894 acpiex - ok
15:39:25.0615 0x0894 acpipagr - ok
15:39:25.0649 0x0894 AcpiPmi - ok
15:39:25.0653 0x0894 acpitime - ok
15:39:25.0717 0x0894 [ 2D766591E87FFFF237C0C9C16CDDECAB, AF04A4C029FD34A5F16B689A4F7F328FCEE11B0033E077FF5FC154C6021B2986 ] ACT2PM C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2ProcessMonitor64.sys
15:39:25.0762 0x0894 ACT2PM - ok
15:39:25.0799 0x0894 [ C47D15FC2CA269DD2EC5946953C5BF03, 20C9CEDECE45E24AA9C78A1FFE4BE6D150B10B726F6F576889971E40CDA267C4 ] ACT2_Service C:\Program Files (x86)\Ashampoo\Ashampoo Core Tuner 2\ACT2Service.exe
15:39:25.0828 0x0894 ACT2_Service - ok
15:39:25.0927 0x0894 [ 16D11D2CA3F2078F553E0C3A70A4F050, 51EEA7EFBE122D3FEB2F8487F5A45166A0C4963314B28840C3C404479B4E1849 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
15:39:25.0946 0x0894 AdobeFlashPlayerUpdateSvc - ok
15:39:25.0952 0x0894 ADP80XX - ok
15:39:25.0966 0x0894 AFD - ok
15:39:25.0975 0x0894 ahcache - ok
15:39:26.0016 0x0894 [ 1CC3E547FE3DEC8272780F24F3059519, 72400F60D41239E9F2493DF71472704ECB006F5871E3CBB125DE2D0303051617 ] AHDDC2 C:\Program Files (x86)\Ashampoo\Ashampoo HDD Control 2\AHDDC2_Service.exe
15:39:26.0050 0x0894 AHDDC2 - ok
15:39:26.0070 0x0894 AJRouter - ok
15:39:26.0078 0x0894 ALG - ok
15:39:26.0081 0x0894 AmdK8 - ok
15:39:26.0083 0x0894 AmdPPM - ok
15:39:26.0086 0x0894 amdsata - ok
15:39:26.0088 0x0894 amdsbs - ok
15:39:26.0089 0x0894 amdxata - ok
15:39:26.0092 0x0894 AppID - ok
15:39:26.0095 0x0894 AppIDSvc - ok
15:39:26.0116 0x0894 Appinfo - ok
15:39:26.0118 0x0894 applockerfltr - ok
15:39:26.0146 0x0894 AppReadiness - ok
15:39:26.0179 0x0894 AppXSvc - ok
15:39:26.0185 0x0894 arcsas - ok
15:39:26.0190 0x0894 AsyncMac - ok
15:39:26.0206 0x0894 atapi - ok
15:39:26.0213 0x0894 AudioEndpointBuilder - ok
15:39:26.0227 0x0894 Audiosrv - ok
15:39:26.0232 0x0894 AxInstSV - ok
15:39:26.0236 0x0894 b06bdrv - ok
15:39:26.0241 0x0894 BasicDisplay - ok
15:39:26.0245 0x0894 BasicRender - ok
15:39:26.0249 0x0894 bcmfn - ok
15:39:26.0252 0x0894 bcmfn2 - ok
15:39:26.0255 0x0894 BDESVC - ok
15:39:26.0258 0x0894 Beep - ok
15:39:26.0277 0x0894 BFE - ok
15:39:26.0298 0x0894 BITS - ok
15:39:26.0301 0x0894 bowser - ok
15:39:26.0324 0x0894 BrokerInfrastructure - ok
15:39:26.0328 0x0894 Browser - ok
15:39:26.0331 0x0894 BthAvrcpTg - ok
15:39:26.0335 0x0894 BthHFEnum - ok
15:39:26.0338 0x0894 bthhfhid - ok
15:39:26.0360 0x0894 BthHFSrv - ok
15:39:26.0364 0x0894 BTHMODEM - ok
15:39:26.0368 0x0894 bthserv - ok
15:39:26.0388 0x0894 buttonconverter - ok
15:39:26.0391 0x0894 CapImg - ok
15:39:26.0394 0x0894 cdfs - ok
15:39:26.0397 0x0894 CDPSvc - ok
15:39:26.0400 0x0894 CDPUserSvc - ok
15:39:26.0419 0x0894 cdrom - ok
15:39:26.0422 0x0894 CertPropSvc - ok
15:39:26.0455 0x0894 [ CF3FFDA7B06A62DC018AFF75B4749FF4, B9ECE0A37CA4A389114737EADF68334DBF6A77214E8794ADFC6F83AD42F90D56 ] chip1click C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe
15:39:26.0530 0x0894 chip1click - detected UnsignedFile.Multi.Generic ( 1 )
15:39:26.0710 0x0894 chip1click ( UnsignedFile.Multi.Generic ) - warning
15:39:26.0849 0x0894 cht4iscsi - ok
15:39:26.0857 0x0894 cht4vbd - ok
15:39:26.0866 0x0894 circlass - ok
15:39:26.0871 0x0894 CLFS - ok
15:39:27.0059 0x0894 [ 2FFC3A679CF4FF05AA762E2B8D095574, 5CA2B9898E7493AF71B7D3A35FFB5D9F072DD0381AF89B0F47158895FBF58772 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
15:39:27.0123 0x0894 ClickToRunSvc - ok
15:39:27.0130 0x0894 ClipSVC - ok
15:39:27.0132 0x0894 clreg - ok
15:39:27.0155 0x0894 [ 3E76A1547F2448BCEE3D2F4AE3931AB5, 31B41723FAA4210A86B1AE02D6C052BD8B738C4B89FB0177C1AE997D24BA5B8C ] CLVirtualDrive C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys
15:39:27.0162 0x0894 CLVirtualDrive - ok
15:39:27.0165 0x0894 CmBatt - ok
15:39:27.0177 0x0894 CNG - ok
15:39:27.0179 0x0894 cnghwassist - ok
15:39:27.0232 0x0894 CompositeBus - ok
15:39:27.0235 0x0894 COMSysApp - ok
15:39:27.0240 0x0894 condrv - ok
15:39:27.0280 0x0894 CoreMessagingRegistrar - ok
15:39:27.0294 0x0894 CryptSvc - ok
15:39:27.0345 0x0894 [ 9FF6436D65CD8C798691373E28FBFB3B, 7A9ACD14679FB82E71EF4C47E43DAD931EC4FD727A5656AF8A3CC3B95D67EB5B ] CyberLink PowerDVD 10 MS Monitor Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSMonitorService.exe
15:39:27.0351 0x0894 CyberLink PowerDVD 10 MS Monitor Service - ok
15:39:27.0369 0x0894 [ 06B5C625CB915E9A7A1F08A43E332FA1, 66F0BFE088B44ED3D36E62DC05200CD09F135FF63C447846C603D6246FABB9BE ] CyberLink PowerDVD 10 MS Service C:\Program Files (x86)\CyberLink\PowerDVD10\Device\MediaServer\CLMSServer.exe
15:39:27.0379 0x0894 CyberLink PowerDVD 10 MS Service - ok
15:39:27.0383 0x0894 dam - ok
15:39:27.0401 0x0894 DcomLaunch - ok
15:39:27.0403 0x0894 DcpSvc - ok
15:39:27.0406 0x0894 defragsvc - ok
15:39:27.0412 0x0894 DeviceAssociationService - ok
15:39:27.0414 0x0894 DeviceInstall - ok
15:39:27.0423 0x0894 DevQueryBroker - ok
15:39:27.0442 0x0894 Dfsc - ok
15:39:27.0469 0x0894 Dhcp - ok
15:39:27.0513 0x0894 diagnosticshub.standardcollector.service - ok
15:39:27.0535 0x0894 DiagTrack - ok
15:39:27.0557 0x0894 disk - ok
15:39:27.0584 0x0894 DmEnrollmentSvc - ok
15:39:27.0590 0x0894 dmvsc - ok
15:39:27.0597 0x0894 dmwappushservice - ok
15:39:27.0609 0x0894 Dnscache - ok
15:39:27.0638 0x0894 dot3svc - ok
15:39:27.0646 0x0894 DPS - ok
15:39:27.0668 0x0894 drmkaud - ok
15:39:27.0674 0x0894 DsmSvc - ok
15:39:27.0684 0x0894 DsSvc - ok
15:39:27.0701 0x0894 DXGKrnl - ok
15:39:27.0707 0x0894 EapHost - ok
15:39:27.0713 0x0894 ebdrv - ok
15:39:27.0719 0x0894 EFS - ok
15:39:27.0725 0x0894 EhStorClass - ok
15:39:27.0744 0x0894 EhStorTcgDrv - ok
15:39:27.0747 0x0894 embeddedmode - ok
15:39:27.0751 0x0894 EntAppSvc - ok
15:39:27.0754 0x0894 ErrDev - ok
15:39:27.0761 0x0894 EventSystem - ok
15:39:27.0764 0x0894 exfat - ok
15:39:27.0820 0x0894 Fabs - ok
15:39:27.0823 0x0894 fastfat - ok
15:39:27.0826 0x0894 Fax - ok
15:39:27.0829 0x0894 fdc - ok
15:39:27.0841 0x0894 fdPHost - ok
15:39:27.0912 0x0894 FDResPub - ok
15:39:27.0930 0x0894 fhsvc - ok
15:39:27.0958 0x0894 FileCrypt - ok
15:39:27.0964 0x0894 FileInfo - ok
15:39:27.0970 0x0894 Filetrace - ok
15:39:28.0074 0x0894 [ 5BD96D8C5411ACE71A7EAACAF0EF2903, 2AF58E6060C7DEC44B4CA30E14E164473CD4089AE475DAFFC61DFE56990C1147 ] FirebirdServerMAGIXInstance C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
15:39:28.0167 0x0894 FirebirdServerMAGIXInstance - detected UnsignedFile.Multi.Generic ( 1 )
15:39:28.0256 0x0894 Detect skipped due to KSN trusted
15:39:28.0257 0x0894 FirebirdServerMAGIXInstance - ok
15:39:28.0263 0x0894 flpydisk - ok
15:39:28.0268 0x0894 FltMgr - ok
15:39:28.0301 0x0894 FontCache - ok
15:39:28.0388 0x0894 FontCache3.0.0.0 - ok
15:39:28.0397 0x0894 FrameServer - ok
15:39:28.0404 0x0894 FsDepends - ok
15:39:28.0413 0x0894 Fs_Rec - ok
15:39:28.0443 0x0894 fvevol - ok
15:39:28.0520 0x0894 [ 9ACFC1E97F789D3C2E6E44431C9FB47B, BE5787A7B9F96BE384FF9EE4962766E7A83C60E74613557FE5274E3900889B6B ] GamesAppIntegrationService C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
15:39:28.0554 0x0894 GamesAppIntegrationService - ok
15:39:28.0586 0x0894 [ C23410A44ADDF0E1A9B4BA42A5DD5EA7, 384382D16D09A17E29D8348E1CF8DD7E377607DB3472AB8888EF8E83671B772C ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
15:39:28.0612 0x0894 GamesAppService - ok
15:39:28.0740 0x0894 [ 13B46C5D8AC698E7E5C46620516F03AC, D9756699B7F9701F2EF70E3DB2C3DED25D12478C4831F9F0621C542998CBD03D ] Garmin Device Interaction Service C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
15:39:28.0770 0x0894 Garmin Device Interaction Service - ok
15:39:28.0791 0x0894 gencounter - ok
15:39:28.0799 0x0894 genericusbfn - ok
15:39:28.0940 0x0894 [ C2730FE9713C1C474257A7085386B11E, 7D35D00D2B455841C8C9A87CE92885CD22F4B8B6690CB21443ED1B515117EF95 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
15:39:28.0964 0x0894 GfExperienceService - ok
15:39:28.0967 0x0894 GPIOClx0101 - ok
15:39:28.0970 0x0894 gpsvc - ok
15:39:28.0972 0x0894 GpuEnergyDrv - ok
15:39:28.0992 0x0894 [ B9893A68032A6D9ADDB5B98287C630F7, F0280764D7B31F1EA634E91397229B1C064A7C1B3A77A6BBD123CEA74180789F ] grmnusb C:\WINDOWS\system32\drivers\grmnusb.sys
15:39:28.0997 0x0894 grmnusb - ok
15:39:29.0059 0x0894 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:39:29.0086 0x0894 gupdate - ok
15:39:29.0095 0x0894 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:39:29.0110 0x0894 gupdatem - ok
15:39:29.0116 0x0894 HDAudBus - ok
15:39:29.0120 0x0894 HidBatt - ok
15:39:29.0134 0x0894 HidBth - ok
15:39:29.0137 0x0894 hidi2c - ok
15:39:29.0140 0x0894 hidinterrupt - ok
15:39:29.0144 0x0894 HidIr - ok
15:39:29.0153 0x0894 hidserv - ok
15:39:29.0171 0x0894 HidUsb - ok
15:39:29.0184 0x0894 HomeGroupListener - ok
15:39:29.0203 0x0894 HomeGroupProvider - ok
15:39:29.0206 0x0894 HpSAMD - ok
15:39:29.0226 0x0894 HTTP - ok
15:39:29.0252 0x0894 HvHost - ok
15:39:29.0276 0x0894 hvservice - ok
15:39:29.0279 0x0894 hwpolicy - ok
15:39:29.0282 0x0894 hyperkbd - ok
15:39:29.0308 0x0894 i8042prt - ok
15:39:29.0311 0x0894 iagpio - ok
15:39:29.0314 0x0894 iai2c - ok
15:39:29.0317 0x0894 iaLPSS2i_GPIO2 - ok
15:39:29.0320 0x0894 iaLPSS2i_I2C - ok
15:39:29.0323 0x0894 iaLPSSi_GPIO - ok
15:39:29.0326 0x0894 iaLPSSi_I2C - ok
15:39:29.0361 0x0894 [ 57CD95DEB3529181BCC931DD2DFB2341, 03ACF906E4C3CF954F503900F42C7A60FCD5624772B90A956F032484146E42B7 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
15:39:29.0402 0x0894 iaStorA - ok
15:39:29.0407 0x0894 iaStorAV - ok
15:39:29.0443 0x0894 [ 20E83F4632E15A5E9E716FF2E8AC7FAE, 7CA1A4924F432AD30ED7FA6247C6513DA173EE31132AE115E85C0ED7E5971029 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
15:39:29.0450 0x0894 IAStorDataMgrSvc - ok
15:39:29.0454 0x0894 iaStorV - ok
15:39:29.0458 0x0894 ibbus - ok
15:39:29.0482 0x0894 icssvc - ok
15:39:29.0534 0x0894 [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
15:39:29.0562 0x0894 IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
15:39:29.0649 0x0894 Detect skipped due to KSN trusted
15:39:29.0649 0x0894 IDriverT - ok
15:39:29.0670 0x0894 IKEEXT - ok
15:39:29.0673 0x0894 IndirectKmd - ok
15:39:29.0788 0x0894 [ 8EB4D1D7806D05E5AB39D96464D801CA, 73853F56CD05243B1CABED2CA2420DFC8BA53F951030EECCD0D2A0E26D8A0D1B ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
15:39:29.0888 0x0894 IntcAzAudAddService - ok
15:39:29.0919 0x0894 [ 0DB1E3F6189C628675F855C0EB510419, 989F539E82105019D2D81255369B96DC65826CD2A421DA09809155B26F69C555 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
15:39:29.0959 0x0894 Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
15:39:31.0044 0x0894 Detect skipped due to KSN trusted
15:39:31.0044 0x0894 Intel(R) Capability Licensing Service Interface - ok
15:39:31.0108 0x0894 [ 492AAF2FF66F437F0E796574B116EFC3, 6BF21C61ED05705DD58203952A750D1AB4D4B62F3A2B640BBBD9B85D1ECC3E5C ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
15:39:31.0138 0x0894 Intel(R) Capability Licensing Service TCP IP Interface - ok
15:39:31.0182 0x0894 [ 57739E742ABC085C2A4340D4404B4A8B, B4B85C35AC96D11F5940AFCB15A2B2A41D70E3C392E1D4D9353899FA140FF281 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
15:39:31.0189 0x0894 Intel(R) ME Service - ok
15:39:31.0221 0x0894 [ B3FF41FCB17206ABFC9B7DCC5E8E0777, 9C4BFC63A2DECBBD380FCCEEFCC8B04BFC4C76F26D4AEEAC5EE8D9D8ED68A493 ] IntelHaxm C:\WINDOWS\system32\DRIVERS\IntelHaxm.sys
15:39:31.0247 0x0894 IntelHaxm - ok
15:39:31.0266 0x0894 intelide - ok
15:39:31.0274 0x0894 intelpep - ok
15:39:31.0277 0x0894 intelppm - ok
15:39:31.0280 0x0894 iorate - ok
15:39:31.0293 0x0894 IpFilterDriver - ok
15:39:31.0318 0x0894 iphlpsvc - ok
15:39:31.0321 0x0894 IPMIDRV - ok
15:39:31.0323 0x0894 IPNAT - ok
15:39:31.0326 0x0894 irda - ok
15:39:31.0329 0x0894 IRENUM - ok
15:39:31.0348 0x0894 irmon - ok
15:39:31.0352 0x0894 isapnp - ok
15:39:31.0356 0x0894 iScsiPrt - ok
15:39:31.0377 0x0894 [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
15:39:31.0385 0x0894 jhi_service - ok
15:39:31.0391 0x0894 kbdclass - ok
15:39:31.0415 0x0894 kbdhid - ok
15:39:31.0434 0x0894 kdnic - ok
15:39:31.0436 0x0894 KeyIso - ok
15:39:31.0439 0x0894 KSecDD - ok
15:39:31.0445 0x0894 KSecPkg - ok
15:39:31.0447 0x0894 ksthunk - ok
15:39:31.0456 0x0894 KtmRm - ok
15:39:31.0460 0x0894 LanmanServer - ok
15:39:31.0463 0x0894 LanmanWorkstation - ok
15:39:31.0539 0x0894 [ 8FB6D64CB42E660C4534D38013D64A03, 11A6A914E8588DDFDE32D12A858BA8A31783B5DDB42C9E7FD0F237D57A437976 ] LavasoftTcpService C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe
15:39:31.0588 0x0894 LavasoftTcpService - ok
15:39:31.0596 0x0894 lfsvc - ok
15:39:31.0604 0x0894 LicenseManager - ok
15:39:31.0607 0x0894 lltdio - ok
15:39:31.0609 0x0894 lltdsvc - ok
15:39:31.0629 0x0894 lmhosts - ok
15:39:31.0650 0x0894 [ 6A35B295812CE7064CFBCD9F254169CF, 561DD131FED6F90686D8C031B45B87B6D065C7E0C8804AEFCDE239725AAEE43E ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
15:39:31.0662 0x0894 LMS - ok
15:39:31.0667 0x0894 LSI_SAS - ok
15:39:31.0669 0x0894 LSI_SAS2i - ok
15:39:31.0672 0x0894 LSI_SAS3i - ok
15:39:31.0675 0x0894 LSI_SSS - ok
15:39:31.0698 0x0894 LSM - ok
15:39:31.0700 0x0894 luafv - ok
15:39:31.0740 0x0894 [ A0A527569856B9814E8920F52EBB67F5, 4347277C84B47E4CC048850BDEFB258CFB3B476AA99FD503FD71FBB70FFF5ACF ] lvrs64 C:\WINDOWS\system32\DRIVERS\lvrs64.sys
15:39:31.0752 0x0894 lvrs64 - ok
15:39:31.0863 0x0894 [ 415E344294D1C0D04627B29146F68481, B4A1A05BDF07E8F226A98E51F62BE18BE2C046A084C495BD8A95CABC79FD0614 ] LVUVC64 C:\WINDOWS\system32\DRIVERS\lvuvc64.sys
15:39:31.0979 0x0894 LVUVC64 - ok
15:39:31.0987 0x0894 MapsBroker - ok
15:39:32.0000 0x0894 megasas - ok
15:39:32.0041 0x0894 megasas2i - ok
15:39:32.0050 0x0894 megasr - ok
15:39:32.0092 0x0894 [ 926C135CFB0C75B32FB714B5C0C58FAA, AF627CD125794B69D450D298D5608D357F2C91FB89EBFAA0DA2A0F07C6A304A8 ] MEIx64 C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
15:39:32.0118 0x0894 MEIx64 - ok
15:39:32.0132 0x0894 MessagingService - ok
15:39:32.0154 0x0894 mlx4_bus - ok
15:39:32.0157 0x0894 MMCSS - ok
15:39:32.0161 0x0894 Modem - ok
15:39:32.0175 0x0894 monitor - ok
15:39:32.0179 0x0894 mouclass - ok
15:39:32.0182 0x0894 mouhid - ok
15:39:32.0184 0x0894 mountmgr - ok
15:39:32.0213 0x0894 [ 572BD5A99648652147A5D3C6DA946C99, FFDAD4A5682864977C926A5DDDB632CDB2A166BF025757801CC56F2828720023 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
15:39:32.0222 0x0894 MozillaMaintenance - ok
15:39:32.0225 0x0894 mpsdrv - ok
15:39:32.0227 0x0894 MpsSvc - ok
15:39:32.0239 0x0894 MRxDAV - ok
15:39:32.0248 0x0894 mrxsmb - ok
15:39:32.0262 0x0894 mrxsmb10 - ok
15:39:32.0282 0x0894 mrxsmb20 - ok
15:39:32.0285 0x0894 MsBridge - ok
15:39:32.0308 0x0894 MSDTC - ok
15:39:32.0312 0x0894 Msfs - ok
15:39:32.0315 0x0894 msgpiowin32 - ok
15:39:32.0317 0x0894 mshidkmdf - ok
15:39:32.0320 0x0894 mshidumdf - ok
15:39:32.0322 0x0894 msisadrv - ok
15:39:32.0341 0x0894 MSiSCSI - ok
15:39:32.0344 0x0894 msiserver - ok
15:39:32.0346 0x0894 MSKSSRV - ok
15:39:32.0350 0x0894 MsLldp - ok
15:39:32.0352 0x0894 MSPCLOCK - ok
15:39:32.0355 0x0894 MSPQM - ok
15:39:32.0357 0x0894 MsRPC - ok
15:39:32.0361 0x0894 mssmbios - ok
15:39:32.0363 0x0894 MSTEE - ok
15:39:32.0366 0x0894 MTConfig - ok
15:39:32.0369 0x0894 Mup - ok
15:39:32.0371 0x0894 mvumis - ok
15:39:32.0394 0x0894 NativeWifiP - ok
15:39:32.0397 0x0894 NcaSvc - ok
15:39:32.0414 0x0894 NcbService - ok
15:39:32.0417 0x0894 NcdAutoSetup - ok
15:39:32.0420 0x0894 ndfltr - ok
15:39:32.0442 0x0894 NDIS - ok
15:39:32.0445 0x0894 NdisCap - ok
15:39:32.0447 0x0894 NdisImPlatform - ok
15:39:32.0449 0x0894 NdisTapi - ok
15:39:32.0452 0x0894 Ndisuio - ok
15:39:32.0455 0x0894 NdisVirtualBus - ok
15:39:32.0457 0x0894 NdisWan - ok
15:39:32.0461 0x0894 ndiswanlegacy - ok
15:39:32.0463 0x0894 ndproxy - ok
15:39:32.0465 0x0894 Ndu - ok
15:39:32.0468 0x0894 NetAdapterCx - ok
15:39:32.0471 0x0894 NetBIOS - ok
15:39:32.0474 0x0894 NetBT - ok
15:39:32.0478 0x0894 Netlogon - ok
15:39:32.0481 0x0894 Netman - ok
15:39:32.0483 0x0894 netprofm - ok
15:39:32.0507 0x0894 netr28ux - ok
15:39:32.0511 0x0894 NetSetupSvc - ok
15:39:32.0541 0x0894 NetTcpPortSharing - ok
15:39:32.0545 0x0894 NgcCtnrSvc - ok
15:39:32.0548 0x0894 NgcSvc - ok
15:39:32.0551 0x0894 NlaSvc - ok
15:39:32.0553 0x0894 Npfs - ok
15:39:32.0556 0x0894 npsvctrig - ok
15:39:32.0558 0x0894 nsi - ok
15:39:32.0561 0x0894 nsiproxy - ok
15:39:32.0578 0x0894 NTFS - ok
15:39:32.0581 0x0894 Null - ok
15:39:32.0598 0x0894 [ 04AFA4A13AB62E3FC46C327E294B2A34, 8537F79C976C6AEA23BDB71444ADFC1DFAB0CB7470C114AFD7E4D8E6397F8F8C ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
15:39:32.0610 0x0894 NVHDA - ok
15:39:33.0031 0x0894 [ 95F5990A2395CB4095E7628A49C741FC, D263767B80BF30686E6B6ED1F68AE32619BE2CA5E058BAD8B8B7A1824EBC48B0 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nvmowu.inf_amd64_a9c3add7483ca8dd\nvlddmkm.sys
15:39:33.0363 0x0894 nvlddmkm - ok
15:39:33.0517 0x0894 [ F9CF3FB8DD81B390783532B3C98D6976, 8C94638136CFAEB3ED6DD7CE2059E98B64B15918DDB0796CC0B88474EE99F5BF ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
15:39:33.0556 0x0894 NvNetworkService - ok
15:39:33.0576 0x0894 nvraid - ok
15:39:33.0579 0x0894 nvstor - ok
15:39:33.0657 0x0894 [ 3A7B0570D896602E37EAF80EC3D1615A, 1F5A71432F96731115ADA2A50E605923666188D08F9FD748424AB6588D0E1482 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
15:39:33.0668 0x0894 NvStreamKms - ok
15:39:33.0682 0x0894 NvStreamSvc - ok
15:39:33.0751 0x0894 [ 85397430F424516BF8300FAAEF929366, 2EDF41407C7483AC8E4703BC0A13F764563E4B00D6923FD4678E6E361AC14D6B ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
15:39:33.0790 0x0894 nvsvc - ok
15:39:33.0834 0x0894 [ DBFE7B2DF103F74AE51840B3C5F25FE9, 436CAA417FD24BA870F117FA4BABA2AB694825795508BCFCC8C927CC2D5BBC5E ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
15:39:33.0847 0x0894 nvvad_WaveExtensible - ok
15:39:33.0868 0x0894 OneSyncSvc - ok
15:39:33.0978 0x0894 [ 880CD3C9ACE342F29AB2F90C751B91A4, 7882ED604EE443E182B323D9A38E35B49FD8C28EDC1196B65EDFABB22CBF6161 ] Origin Client Service C:\Program Files (x86)\Origin\OriginClientService.exe
15:39:34.0020 0x0894 Origin Client Service - ok
15:39:34.0084 0x0894 [ 63511820A101C1C5DB95B9ECFFEDA089, AD517FFE1FFD103FF1F371A0406CA8CDCAD762CE4DDC829759BE1914F4DF0675 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:39:34.0102 0x0894 ose - ok
15:39:34.0119 0x0894 p2pimsvc - ok
15:39:34.0126 0x0894 p2psvc - ok
15:39:34.0130 0x0894 Parport - ok
15:39:34.0149 0x0894 partmgr - ok
15:39:34.0179 0x0894 PcaSvc - ok
15:39:34.0185 0x0894 pci - ok
15:39:34.0215 0x0894 pciide - ok
15:39:34.0220 0x0894 pcmcia - ok
15:39:34.0224 0x0894 pcw - ok
15:39:34.0245 0x0894 pdc - ok
15:39:34.0259 0x0894 PEAUTH - ok
15:39:34.0265 0x0894 percsas2i - ok
15:39:34.0269 0x0894 percsas3i - ok
15:39:34.0317 0x0894 PerfHost - ok
15:39:34.0327 0x0894 PhoneSvc - ok
15:39:34.0365 0x0894 PimIndexMaintenanceSvc - ok
15:39:34.0398 0x0894 pla - ok
15:39:34.0419 0x0894 PlugPlay - ok
15:39:34.0422 0x0894 PNRPAutoReg - ok
15:39:34.0425 0x0894 PNRPsvc - ok
15:39:34.0437 0x0894 PolicyAgent - ok
15:39:34.0511 0x0894 [ 4671F353D0DF74C3B0D2D00DE676F56C, 0F75009DD36B2E18212CE855FB7CA7D273E5749D8F2F451655ED81AA5E86BA9F ] postgresql-8.4 c:\postgreSQL\bin\pg_ctl.exe
15:39:34.0554 0x0894 postgresql-8.4 - detected UnsignedFile.Multi.Generic ( 1 )
15:39:34.0645 0x0894 Detect skipped due to KSN trusted
15:39:34.0645 0x0894 postgresql-8.4 - ok
15:39:34.0653 0x0894 Power - ok
15:39:34.0662 0x0894 PptpMiniport - ok
15:39:34.0807 0x0894 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
15:39:34.0976 0x0894 PrintNotify - ok
15:39:34.0983 0x0894 Processor - ok
15:39:35.0008 0x0894 ProfSvc - ok
15:39:35.0026 0x0894 Psched - ok
15:39:35.0029 0x0894 QWAVE - ok
15:39:35.0032 0x0894 QWAVEdrv - ok
15:39:35.0034 0x0894 RasAcd - ok
15:39:35.0043 0x0894 RasAgileVpn - ok
15:39:35.0050 0x0894 RasAuto - ok
15:39:35.0052 0x0894 Rasl2tp - ok
15:39:35.0076 0x0894 RasMan - ok
15:39:35.0079 0x0894 RasPppoe - ok
15:39:35.0081 0x0894 RasSstp - ok
15:39:35.0091 0x0894 rdbss - ok
15:39:35.0114 0x0894 rdpbus - ok
15:39:35.0118 0x0894 RDPDR - ok
15:39:35.0151 0x0894 RdpVideoMiniport - ok
15:39:35.0153 0x0894 rdyboost - ok
15:39:35.0157 0x0894 ReFSv1 - ok
15:39:35.0175 0x0894 RemoteAccess - ok
15:39:35.0178 0x0894 RemoteRegistry - ok
15:39:35.0196 0x0894 RetailDemo - ok
15:39:35.0199 0x0894 RmSvc - ok
15:39:35.0202 0x0894 RpcEptMapper - ok
15:39:35.0208 0x0894 RpcLocator - ok
15:39:35.0211 0x0894 RpcSs - ok
15:39:35.0213 0x0894 rspndr - ok
15:39:35.0254 0x0894 [ 948D5E71CF9DB59961353A355EA45139, A23D012B07A92CC217C67C904CDFBA2BCCDCC2BD49B24FB694BD230D000F2B7B ] RTL8168 C:\WINDOWS\System32\drivers\Rt630x64.sys
15:39:35.0274 0x0894 RTL8168 - ok
15:39:35.0279 0x0894 s3cap - ok
15:39:35.0295 0x0894 SamSs - ok
15:39:35.0298 0x0894 sbp2port - ok
15:39:35.0301 0x0894 SCardSvr - ok
15:39:35.0305 0x0894 ScDeviceEnum - ok
15:39:35.0307 0x0894 scfilter - ok
15:39:35.0310 0x0894 Schedule - ok
15:39:35.0313 0x0894 scmbus - ok
15:39:35.0315 0x0894 scmdisk0101 - ok
15:39:35.0323 0x0894 SCPolicySvc - ok
15:39:35.0341 0x0894 sdbus - ok
15:39:35.0344 0x0894 SDRSVC - ok
15:39:35.0347 0x0894 sdstor - ok
15:39:35.0349 0x0894 seclogon - ok
15:39:35.0352 0x0894 SENS - ok
15:39:35.0354 0x0894 SensorDataService - ok
15:39:35.0374 0x0894 SensorService - ok
15:39:35.0376 0x0894 SensrSvc - ok
15:39:35.0380 0x0894 SerCx - ok
15:39:35.0382 0x0894 SerCx2 - ok
15:39:35.0386 0x0894 Serenum - ok
15:39:35.0388 0x0894 Serial - ok
15:39:35.0390 0x0894 sermouse - ok
15:39:35.0397 0x0894 SessionEnv - ok
15:39:35.0399 0x0894 sfloppy - ok
15:39:35.0407 0x0894 SharedAccess - ok
15:39:35.0421 0x0894 ShellHWDetection - ok
15:39:35.0438 0x0894 shpamsvc - ok
15:39:35.0441 0x0894 SiSRaid2 - ok
15:39:35.0444 0x0894 SiSRaid4 - ok
15:39:35.0486 0x0894 [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
15:39:35.0499 0x0894 SkypeUpdate - ok
15:39:35.0510 0x0894 smphost - ok
15:39:35.0514 0x0894 SmsRouter - ok
15:39:35.0519 0x0894 SNMPTRAP - ok
15:39:35.0550 0x0894 [ 21FF393512F51F5A98620C794B4488A3, 8A35923D3D6993FC014D86F0F7BD5C106586824DB8D26C04DC2AD0B8ED13ED20 ] Sony PC Companion C:\Program Files (x86)\Sony\Sony PC Companion\PCCService.exe
15:39:35.0557 0x0894 Sony PC Companion - ok
15:39:35.0572 0x0894 spaceport - ok
15:39:35.0575 0x0894 SpbCx - ok
15:39:35.0581 0x0894 Spooler - ok
15:39:35.0593 0x0894 sppsvc - ok
15:39:35.0613 0x0894 srv - ok
15:39:35.0616 0x0894 srv2 - ok
15:39:35.0619 0x0894 srvnet - ok
15:39:35.0635 0x0894 SSDPSRV - ok
15:39:35.0653 0x0894 SstpSvc - ok
15:39:35.0692 0x0894 StateRepository - ok
15:39:35.0795 0x0894 [ F82B2FC221CA0E408874884787491667, A9C7FB9C4719484BDA4FB69A8F948DC556CFEA19DFE89D2E63536F2C42725E66 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
15:39:35.0824 0x0894 Stereo Service - ok
15:39:35.0843 0x0894 stexstor - ok
15:39:35.0847 0x0894 stisvc - ok
15:39:35.0850 0x0894 storahci - ok
15:39:35.0854 0x0894 storflt - ok
15:39:35.0857 0x0894 stornvme - ok
15:39:35.0862 0x0894 storqosflt - ok
15:39:35.0868 0x0894 StorSvc - ok
15:39:35.0870 0x0894 storufs - ok
15:39:35.0873 0x0894 storvsc - ok
15:39:35.0876 0x0894 svsvc - ok
15:39:35.0879 0x0894 swenum - ok
15:39:35.0881 0x0894 swprv - ok
15:39:35.0901 0x0894 Synth3dVsc - ok
15:39:35.0904 0x0894 SysMain - ok
15:39:35.0913 0x0894 SystemEventsBroker - ok
15:39:35.0921 0x0894 TabletInputService - ok
15:39:35.0952 0x0894 [ DA0780D55E8CF724CF3EF7CCF0F0DB67, 47CD0FC1CAD0603674EC06C469F7C92518C8668DF6DA56DF5E3DD7640E287203 ] taphss6 C:\WINDOWS\system32\DRIVERS\taphss6.sys
15:39:35.0960 0x0894 taphss6 - ok
15:39:35.0963 0x0894 TapiSrv - ok
15:39:35.0965 0x0894 Tcpip - ok
15:39:35.0968 0x0894 Tcpip6 - ok
15:39:35.0972 0x0894 tcpipreg - ok
15:39:35.0975 0x0894 tdx - ok
15:39:35.0978 0x0894 terminpt - ok
15:39:35.0981 0x0894 TermService - ok
15:39:35.0984 0x0894 Themes - ok
15:39:36.0011 0x0894 TieringEngineService - ok
15:39:36.0014 0x0894 tiledatamodelsvc - ok
15:39:36.0017 0x0894 TimeBrokerSvc - ok
15:39:36.0019 0x0894 TPM - ok
15:39:36.0022 0x0894 TrkWks - ok
15:39:36.0044 0x0894 TrustedInstaller - ok
15:39:36.0048 0x0894 tsusbflt - ok
15:39:36.0051 0x0894 TsUsbGD - ok
15:39:36.0054 0x0894 tunnel - ok
15:39:36.0070 0x0894 tzautoupdate - ok
15:39:36.0074 0x0894 UASPStor - ok
15:39:36.0076 0x0894 UcmCx0101 - ok
15:39:36.0079 0x0894 UcmTcpciCx0101 - ok
15:39:36.0082 0x0894 UcmUcsi - ok
15:39:36.0084 0x0894 Ucx01000 - ok
15:39:36.0087 0x0894 UdeCx - ok
15:39:36.0090 0x0894 udfs - ok
15:39:36.0093 0x0894 UEFI - ok
15:39:36.0095 0x0894 Ufx01000 - ok
15:39:36.0098 0x0894 UfxChipidea - ok
15:39:36.0100 0x0894 ufxsynopsys - ok
15:39:36.0106 0x0894 UI0Detect - ok
15:39:36.0108 0x0894 umbus - ok
15:39:36.0111 0x0894 UmPass - ok
15:39:36.0114 0x0894 UmRdpService - ok
15:39:36.0117 0x0894 UnistoreSvc - ok
15:39:36.0121 0x0894 upnphost - ok
15:39:36.0123 0x0894 UrsChipidea - ok
15:39:36.0126 0x0894 UrsCx01000 - ok
15:39:36.0129 0x0894 UrsSynopsys - ok
15:39:36.0131 0x0894 usbccgp - ok
15:39:36.0134 0x0894 usbcir - ok
15:39:36.0137 0x0894 usbehci - ok
15:39:36.0139 0x0894 usbhub - ok
15:39:36.0143 0x0894 USBHUB3 - ok
15:39:36.0145 0x0894 usbohci - ok
15:39:36.0148 0x0894 usbprint - ok
15:39:36.0151 0x0894 usbser - ok
15:39:36.0153 0x0894 USBSTOR - ok
15:39:36.0156 0x0894 usbuhci - ok
15:39:36.0159 0x0894 USBXHCI - ok
15:39:36.0163 0x0894 UserDataSvc - ok
15:39:36.0179 0x0894 UserManager - ok
15:39:36.0193 0x0894 UsoSvc - ok
15:39:36.0195 0x0894 VaultSvc - ok
15:39:36.0198 0x0894 vdrvroot - ok
15:39:36.0200 0x0894 vds - ok
15:39:36.0203 0x0894 VerifierExt - ok
15:39:36.0205 0x0894 vhdmp - ok
15:39:36.0208 0x0894 vhf - ok
15:39:36.0212 0x0894 vmbus - ok
15:39:36.0214 0x0894 VMBusHID - ok
15:39:36.0217 0x0894 vmgid - ok
15:39:36.0220 0x0894 vmicguestinterface - ok
15:39:36.0223 0x0894 vmicheartbeat - ok
15:39:36.0225 0x0894 vmickvpexchange - ok
15:39:36.0244 0x0894 vmicrdv - ok
15:39:36.0246 0x0894 vmicshutdown - ok
15:39:36.0249 0x0894 vmictimesync - ok
15:39:36.0251 0x0894 vmicvmsession - ok
15:39:36.0254 0x0894 vmicvss - ok
15:39:36.0257 0x0894 volmgr - ok
15:39:36.0259 0x0894 volmgrx - ok
15:39:36.0262 0x0894 volsnap - ok
15:39:36.0265 0x0894 volume - ok
15:39:36.0267 0x0894 vpci - ok
15:39:36.0270 0x0894 vsmraid - ok
15:39:36.0273 0x0894 VSS - ok
15:39:36.0275 0x0894 VSTXRAID - ok
15:39:36.0278 0x0894 vwifibus - ok
15:39:36.0281 0x0894 vwififlt - ok
15:39:36.0283 0x0894 vwifimp - ok
15:39:36.0286 0x0894 W32Time - ok
15:39:36.0289 0x0894 WacomPen - ok
15:39:36.0301 0x0894 WalletService - ok
15:39:36.0303 0x0894 wanarp - ok
15:39:36.0306 0x0894 wanarpv6 - ok
15:39:36.0310 0x0894 wbengine - ok
15:39:36.0344 0x0894 WbioSrvc - ok
15:39:36.0366 0x0894 wcifs - ok
15:39:36.0399 0x0894 Wcmsvc - ok
15:39:36.0402 0x0894 wcncsvc - ok
15:39:36.0404 0x0894 wcnfs - ok
15:39:36.0407 0x0894 WdBoot - ok
15:39:36.0411 0x0894 Wdf01000 - ok
15:39:36.0414 0x0894 WdFilter - ok
15:39:36.0416 0x0894 WdiServiceHost - ok
15:39:36.0419 0x0894 WdiSystemHost - ok
15:39:36.0422 0x0894 wdiwifi - ok
15:39:36.0424 0x0894 WdNisDrv - ok
15:39:36.0458 0x0894 WdNisSvc - ok
15:39:36.0462 0x0894 WebClient - ok
15:39:36.0465 0x0894 Wecsvc - ok
15:39:36.0469 0x0894 WEPHOSTSVC - ok
15:39:36.0473 0x0894 wercplsupport - ok
15:39:36.0477 0x0894 WerSvc - ok
15:39:36.0481 0x0894 WFPLWFS - ok
15:39:36.0484 0x0894 WiaRpc - ok
15:39:36.0487 0x0894 WIMMount - ok
15:39:36.0489 0x0894 WinDefend - ok
15:39:36.0496 0x0894 WindowsTrustedRT - ok
15:39:36.0500 0x0894 WindowsTrustedRTProxy - ok
15:39:36.0511 0x0894 WinHttpAutoProxySvc - ok
15:39:36.0514 0x0894 WinMad - ok
15:39:36.0542 0x0894 Winmgmt - ok
15:39:36.0548 0x0894 WinRM - ok
15:39:36.0553 0x0894 WINUSB - ok
15:39:36.0556 0x0894 WinVerbs - ok
15:39:36.0564 0x0894 wisvc - ok
15:39:36.0568 0x0894 WlanSvc - ok
15:39:36.0572 0x0894 wlidsvc - ok
15:39:36.0575 0x0894 WmiAcpi - ok
15:39:36.0579 0x0894 wmiApSrv - ok
15:39:36.0587 0x0894 WMPNetworkSvc - ok
15:39:36.0598 0x0894 Wof - ok
15:39:36.0603 0x0894 workfolderssvc - ok
15:39:36.0606 0x0894 WPDBusEnum - ok
15:39:36.0609 0x0894 WpdUpFltr - ok
15:39:36.0612 0x0894 WpnService - ok
15:39:36.0615 0x0894 WpnUserService - ok
15:39:36.0625 0x0894 ws2ifsl - ok
15:39:36.0629 0x0894 wscsvc - ok
15:39:36.0632 0x0894 WSearch - ok
15:39:36.0645 0x0894 wuauserv - ok
15:39:36.0648 0x0894 WudfPf - ok
15:39:36.0651 0x0894 WUDFRd - ok
15:39:36.0654 0x0894 wudfsvc - ok
15:39:36.0656 0x0894 WUDFWpdFs - ok
15:39:36.0660 0x0894 WwanSvc - ok
15:39:36.0700 0x0894 XblAuthManager - ok
15:39:36.0714 0x0894 XblGameSave - ok
15:39:36.0717 0x0894 xboxgip - ok
15:39:36.0721 0x0894 XboxNetApiSvc - ok
15:39:36.0745 0x0894 xinputhid - ok
15:39:36.0747 0x0894 ================ Scan global ===============================
15:39:36.0799 0x0894 [ Global ] - ok
15:39:36.0800 0x0894 ================ Scan MBR ==================================
15:39:36.0811 0x0894 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
15:39:36.0903 0x0894 \Device\Harddisk0\DR0 - ok
15:39:36.0904 0x0894 ================ Scan VBR ==================================
15:39:36.0933 0x0894 [ 2AF275F0948CBB32F0C49D947F94EC14 ] \Device\Harddisk0\DR0\Partition1
15:39:36.0937 0x0894 \Device\Harddisk0\DR0\Partition1 - ok
15:39:36.0950 0x0894 [ 8954B01B0064FFC47111B0F929A03C08 ] \Device\Harddisk0\DR0\Partition2
15:39:36.0952 0x0894 \Device\Harddisk0\DR0\Partition2 - ok
15:39:36.0960 0x0894 [ 9D327BA77F9A4BB193707A464C3EE21D ] \Device\Harddisk0\DR0\Partition3
15:39:36.0961 0x0894 \Device\Harddisk0\DR0\Partition3 - ok
15:39:36.0970 0x0894 [ 408AA2997C6CA02CBD378462C994127A ] \Device\Harddisk0\DR0\Partition4
15:39:36.0972 0x0894 \Device\Harddisk0\DR0\Partition4 - ok
15:39:36.0981 0x0894 [ 17F746D272DF57AFB6C0EF5A1FBC29A5 ] \Device\Harddisk0\DR0\Partition5
15:39:36.0982 0x0894 \Device\Harddisk0\DR0\Partition5 - ok
15:39:37.0006 0x0894 [ 9FDEE4B282DCC3D4FD979D503FA62B24 ] \Device\Harddisk0\DR0\Partition6
15:39:37.0007 0x0894 \Device\Harddisk0\DR0\Partition6 - ok
15:39:37.0015 0x0894 [ E1E14EBF4C1367A2C78A8A71C4CA7AB2 ] \Device\Harddisk0\DR0\Partition7
15:39:37.0017 0x0894 \Device\Harddisk0\DR0\Partition7 - ok
15:39:37.0018 0x0894 ================ Scan generic autorun ======================
15:39:37.0352 0x0894 [ 0011163AC036C71E03883DD10C626F81, CD1F55C6BC20817F69E76A2B2AB4BA30D175821A3A4EA5A34E285182584518B7 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
15:39:37.0571 0x0894 RTHDVCPL - ok
15:39:37.0638 0x0894 [ 4A0477ADCD07EC9D21257A2E456B16C5, CEF9C81730C12283A7600C3D921D89A62B14D1C46544B493F3AF7520DD2D1F79 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
15:39:37.0667 0x0894 IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
15:39:37.0819 0x0894 Detect skipped due to KSN trusted
15:39:37.0819 0x0894 IAStorIcon - ok
15:39:37.0923 0x0894 [ 046DDF9B31BEC14D03CCC97DD728A4D1, D29F49F870B27553E13F9C1486D9B27A27C41FBEC7ACEC77EDFD5552C941E710 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
15:39:37.0968 0x0894 NvBackend - ok
15:39:37.0971 0x0894 WindowsDefender - ok
15:39:38.0069 0x0894 [ 4E9AF25BA5E8219310E384AEA5B0EED8, 743062F755E7A88BA394E96CA26A988CCFDF73B441B779B3149D54A769CBC411 ] C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
15:39:38.0090 0x0894 CLMLServer_For_P2G8 - ok
15:39:38.0114 0x0894 [ 806222C9B0B8606061830527296328ED, 93E241CA93177D63120A97BF72B91A1EA3D14BE4ADB210181AF975074268183F ] C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe
15:39:38.0130 0x0894 CLVirtualDrive - ok
15:39:38.0156 0x0894 [ 0966408A384E8B0FE57B0008E18D561C, 045AB5798CAFA7D27E7D02F780B3508EBF34C0991C8EF166A61CF869D9399B70 ] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
15:39:38.0164 0x0894 RemoteControl10 - ok
15:39:38.0225 0x0894 OneDriveSetup - ok
15:39:38.0226 0x0894 OneDriveSetup - ok
15:39:38.0361 0x0894 [ 49610A409DFAE252AE6A07E400013178, 4191C5BF1BF0E029F58F71BC9B06C1A817FA6250EC6F33C6C680EDE4A2B47F19 ] C:\Users\Aleksandar\AppData\Roaming\Spotify\SpotifyWebHelper.exe
15:39:38.0390 0x0894 Spotify Web Helper - ok
15:39:38.0530 0x0894 [ F38F205DB8CD54351735E3FECBB78788, 1E3577CD1D12B9AD44D2675267D6322114B4FBD06754BA1C80908E3C74BBCCAA ] C:\Users\Aleksandar\AppData\Roaming\Spotify\Spotify.exe
15:39:38.0682 0x0894 Spotify - ok
15:39:38.0769 0x0894 [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\Aleksandar\AppData\Local\Microsoft\OneDrive\OneDrive.exe
15:39:38.0796 0x0894 OneDrive - ok
15:39:38.0824 0x0894 [ 89CACBC5A5D9F14AD11F09D1DE49294E, 5D9F810E57527ED9E95BB208DBA13D25AF64346B298C1C793335775F9AED21C7 ] C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe
15:39:38.0834 0x0894 Sony PC Companion - ok
15:39:38.0881 0x0894 [ 1505DEDB7382A40238C4AF4AB1C39019, A5935610510E8CC271B0C48782F1FECD9B2B8CE4E9BC51359DDE5B3A5F1916F7 ] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe
15:39:38.0912 0x0894 Web Companion - ok
15:39:39.0023 0x0894 [ D7B1603DB2DA16CC64FF4B6FEC5CD793, 71455625DB7D488712CE5D16FA7BBE982AB626118A40F98560A1D99B2DF464A6 ] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
15:39:39.0052 0x0894 GarminExpressTrayApp - ok
15:39:39.0143 0x0894 [ 4B4F81C294B9A07479F4F4F8FF20E58C, 2D034E1E75E8A425E620A3920E28F49CB0721129E37E7764B0FA7FA960A0F253 ] C:\Program Files (x86)\Garmin\Training Center\gStart.exe
15:39:39.0226 0x0894 gStart - detected UnsignedFile.Multi.Generic ( 1 )
15:39:39.0553 0x0894 Detect skipped due to KSN trusted
15:39:39.0553 0x0894 gStart - ok
15:39:39.0624 0x0894 [ 5B922D366915A45EAE53570590E175B9, 61E466990CB4435AF89AAEA81A69E86CC31A6873FDBEC747B04353F950A723CA ] C:\ProgramData\benefit-41\benefit-4.exe
15:39:39.0667 0x0894 benefit-8 - detected UnsignedFile.Multi.Generic ( 1 )
15:39:39.0762 0x0894 benefit-8 ( UnsignedFile.Multi.Generic ) - warning
15:39:39.0943 0x0894 [ B1B2604ADE84A1C8C1B2438B07F43342, 63C6EAC0EFC3BF05A178175C20EB1D953268C54E907DD5D17468039EA407660B ] C:\Users\Aleksandar\AppData\Roaming\computer-13\computer-68.exe
15:39:39.0995 0x0894 computer-52 - detected UnsignedFile.Multi.Generic ( 1 )
15:39:40.0071 0x0894 Detect turned to UDS exact due to KSN untrusted
15:39:40.0071 0x0894 computer-52 ( UDS:DangerousObject.Multi.Generic ) - infected
15:39:40.0071 0x0894 Force sending object to P2P due to detect: C:\Users\Aleksandar\AppData\Roaming\computer-13\computer-68.exe
15:39:40.0280 0x0894 Object send P2P result: true
15:39:40.0387 0x0894 OneDriveSetup - ok
15:39:40.0429 0x0894 WAB Migrate - ok
15:39:40.0433 0x0894 OneDriveSetup - ok
15:39:40.0434 0x0894 WAB Migrate - ok
15:39:40.0441 0x0894 OneDriveSetup - ok
15:39:40.0554 0x0894 [ 2010CA459E5EC8F9D5FC8B000D130294, 058FF215A3AAD04F2A4CF23B2CC62A5EA28F5A705EFA689DCE9126720CF33229 ] C:\Users\mirko\AppData\Local\Microsoft\OneDrive\OneDrive.exe
15:39:40.0584 0x0894 OneDrive - ok
15:39:40.0585 0x0894 WAB Migrate - ok
15:39:40.0586 0x0894 Waiting for KSN requests completion. In queue: 54
15:39:41.0613 0x0894 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x61100 ( enabled : updated )
15:39:41.0681 0x0894 Win FW state via NFP2: enabled ( trusted )
15:39:41.0778 0x0894 ============================================================
15:39:41.0778 0x0894 Scan finished
15:39:41.0778 0x0894 ============================================================
15:39:41.0799 0x0874 Detected object count: 3
15:39:41.0799 0x0874 Actual detected object count: 3
15:41:55.0998 0x0874 chip1click ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:55.0998 0x0874 chip1click ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:55.0998 0x0874 benefit-8 ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:55.0998 0x0874 benefit-8 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:55.0999 0x0874 computer-52 ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:41:55.0999 0x0874 computer-52 ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:42:03.0005 0x32bc Deinitialize success Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2016.11.08.09
rootkit: v2016.10.31.01
Windows 10 x64 NTFS
Internet Explorer 11.321.14393.0
Aleksandar :: COMEBACK [administrator]
08.11.2016 15:05:44
mbar-log-2016-11-08 (15-05-44).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 537061
Time elapsed: 26 minute(s), 42 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) |