haakenson | 15.11.2016 14:59 | Beide negativ. Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2016.11.15.08
rootkit: v2016.10.31.01
Windows 10 x64 NTFS
Internet Explorer 11.447.14393.0
plani :: PXT02 [administrator]
15.11.2016 14:46:54
mbar-log-2016-11-15 (14-46-54).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 301068
Time elapsed: 6 minute(s), 55 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) Code:
14:57:01.0932 0x2bf0 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
14:57:01.0932 0x2bf0 UEFI system
14:57:05.0873 0x2bf0 ============================================================
14:57:05.0873 0x2bf0 Current date / time: 2016/11/15 14:57:05.0873
14:57:05.0906 0x2bf0 SystemInfo:
14:57:05.0906 0x2bf0
14:57:05.0906 0x2bf0 OS Version: 10.0.14393 ServicePack: 0.0
14:57:05.0906 0x2bf0 Product type: Workstation
14:57:05.0906 0x2bf0 ComputerName: PXT02
14:57:05.0906 0x2bf0 UserName: plani
14:57:05.0906 0x2bf0 Windows directory: C:\WINDOWS
14:57:05.0906 0x2bf0 System windows directory: C:\WINDOWS
14:57:05.0906 0x2bf0 Running under WOW64
14:57:05.0906 0x2bf0 Processor architecture: Intel x64
14:57:05.0906 0x2bf0 Number of processors: 8
14:57:05.0906 0x2bf0 Page size: 0x1000
14:57:05.0906 0x2bf0 Boot type: Normal boot
14:57:05.0906 0x2bf0 CodeIntegrityOptions = 0x00000001
14:57:05.0906 0x2bf0 ============================================================
14:57:05.0973 0x2bf0 KLMD registered as C:\WINDOWS\system32\drivers\39990946.sys
14:57:05.0973 0x2bf0 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.447, osProperties = 0x19
14:57:06.0424 0x2bf0 System UUID: {7CC6C2EC-1DB3-AFFA-0AFC-13A2DE2A117E}
14:57:08.0840 0x2bf0 Drive \Device\Harddisk1\DR1 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
14:57:08.0840 0x2bf0 Drive \Device\Harddisk0\DR0 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
14:57:08.0840 0x2bf0 ============================================================
14:57:08.0840 0x2bf0 \Device\Harddisk1\DR1:
14:57:08.0840 0x2bf0 GPT partitions:
14:57:08.0840 0x2bf0 \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {68DB67E3-86B7-47F5-B2B9-A9424ADDB79B}, Name: Microsoft reserved partition, StartLBA 0x22, BlocksNum 0x40000
14:57:08.0840 0x2bf0 \Device\Harddisk1\DR1\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {79F23EF4-8F93-49F1-AFD7-261A7C556973}, Name: Basic data partition, StartLBA 0x40800, BlocksNum 0x3D7DE000
14:57:08.0840 0x2bf0 \Device\Harddisk1\DR1\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {82BA5E9B-0F9A-4F13-AB00-1487531AE3CE}, Name: Basic data partition, StartLBA 0x3D81E800, BlocksNum 0x36EE7800
14:57:08.0840 0x2bf0 MBR partitions:
14:57:08.0840 0x2bf0 \Device\Harddisk0\DR0:
14:57:08.0840 0x2bf0 GPT partitions:
14:57:08.0856 0x2bf0 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {3792F0D7-8C70-444C-8D45-FE3B85C8B970}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x82000
14:57:08.0856 0x2bf0 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {883D10F1-AD25-464E-8D0F-AA625CB6A724}, Name: Microsoft reserved partition, StartLBA 0x82800, BlocksNum 0x8000
14:57:08.0856 0x2bf0 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {50168199-FE22-40C8-AE0A-7E557037B375}, Name: Basic data partition, StartLBA 0x8A800, BlocksNum 0xBF15800
14:57:08.0856 0x2bf0 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {05FC3100-AC41-4933-B7A7-3BF753630AD6}, Name: Basic data partition, StartLBA 0xBFA0000, BlocksNum 0x1F4000
14:57:08.0856 0x2bf0 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {3F0A3103-E16D-4AF8-B58D-CA8780BD3AA5}, Name: Basic data partition, StartLBA 0xC194000, BlocksNum 0x2AF4000
14:57:08.0856 0x2bf0 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {F7422F52-D14B-4A1D-83A3-13BB522BA5A7}, Name: Basic data partition, StartLBA 0xEC88000, BlocksNum 0x1F4000
14:57:08.0856 0x2bf0 MBR partitions:
14:57:08.0856 0x2bf0 ============================================================
14:57:08.0856 0x2bf0 C: <-> \Device\Harddisk0\DR0\Partition3
14:57:08.0907 0x2bf0 D: <-> \Device\Harddisk1\DR1\Partition2
14:57:08.0962 0x2bf0 G: <-> \Device\Harddisk1\DR1\Partition3
14:57:08.0962 0x2bf0 ============================================================
14:57:08.0962 0x2bf0 Initialize success
14:57:08.0962 0x2bf0 ============================================================
14:58:01.0707 0x2c68 ============================================================
14:58:01.0707 0x2c68 Scan started
14:58:01.0707 0x2c68 Mode: Manual; SigCheck; TDLFS;
14:58:01.0707 0x2c68 ============================================================
14:58:01.0707 0x2c68 KSN ping started
14:58:01.0806 0x2c68 KSN ping finished: true
14:58:04.0494 0x2c68 ================ Scan system memory ========================
14:58:04.0494 0x2c68 System memory - ok
14:58:04.0495 0x2c68 ================ Scan services =============================
14:58:04.0523 0x2c68 1394ohci - ok
14:58:04.0523 0x2c68 3ware - ok
14:58:04.0523 0x2c68 ACPI - ok
14:58:04.0523 0x2c68 AcpiDev - ok
14:58:04.0523 0x2c68 acpiex - ok
14:58:04.0523 0x2c68 acpipagr - ok
14:58:04.0523 0x2c68 AcpiPmi - ok
14:58:04.0540 0x2c68 acpitime - ok
14:58:04.0540 0x2c68 [ E13DE7CD2B62254DD4FF658B7798A37D, 9FCCC90DEF6BE83F8C41D4552D235A7BB5534954D2E7CB7B1C336A31FCCAB3AD ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
14:58:04.0574 0x2c68 ACPIVPC - ok
14:58:04.0574 0x2c68 [ C92B0A0957ACAD3CEEF502A2CA10ACB8, 78BF46318B69D9479ECDC83446DD8D454AA2A9A9D94B33C5FC68933DB18AFA3B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
14:58:04.0574 0x2c68 AdobeARMservice - ok
14:58:04.0603 0x2c68 [ 8532B30A054D83614A90D24AD61A29DF, 959C74C63AF7F4E5588C705FBF08EA7A8749268BC28819879ED53AB7A3410B74 ] AdobeUpdateService C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
14:58:04.0607 0x2c68 AdobeUpdateService - ok
14:58:04.0624 0x2c68 ADP80XX - ok
14:58:04.0624 0x2c68 AFD - ok
14:58:04.0657 0x2c68 [ 021D06851E7AFF5C314039DF813608F3, 081B14840F4AD428B4407AA2E639369A45D174D9507BD107F33FE3A94FB8F8EC ] AGSService C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
14:58:04.0707 0x2c68 AGSService - ok
14:58:04.0707 0x2c68 ahcache - ok
14:58:04.0707 0x2c68 AJRouter - ok
14:58:04.0707 0x2c68 ALG - ok
14:58:04.0707 0x2c68 AmdK8 - ok
14:58:04.0723 0x2c68 AmdPPM - ok
14:58:04.0723 0x2c68 amdsata - ok
14:58:04.0723 0x2c68 amdsbs - ok
14:58:04.0723 0x2c68 amdxata - ok
14:58:04.0723 0x2c68 AppID - ok
14:58:04.0740 0x2c68 AppIDSvc - ok
14:58:04.0740 0x2c68 Appinfo - ok
14:58:04.0740 0x2c68 applockerfltr - ok
14:58:04.0740 0x2c68 AppReadiness - ok
14:58:04.0740 0x2c68 AppXSvc - ok
14:58:04.0756 0x2c68 arcsas - ok
14:58:04.0757 0x2c68 AsyncMac - ok
14:58:04.0757 0x2c68 atapi - ok
14:58:04.0757 0x2c68 AudioEndpointBuilder - ok
14:58:04.0757 0x2c68 Audiosrv - ok
14:58:04.0757 0x2c68 AxInstSV - ok
14:58:04.0757 0x2c68 b06bdrv - ok
14:58:04.0774 0x2c68 BasicDisplay - ok
14:58:04.0774 0x2c68 BasicRender - ok
14:58:04.0774 0x2c68 bcmfn - ok
14:58:04.0774 0x2c68 bcmfn2 - ok
14:58:04.0774 0x2c68 BDESVC - ok
14:58:04.0774 0x2c68 Beep - ok
14:58:04.0790 0x2c68 BFE - ok
14:58:04.0792 0x2c68 BITS - ok
14:58:04.0796 0x2c68 bowser - ok
14:58:04.0798 0x2c68 BrokerInfrastructure - ok
14:58:04.0800 0x2c68 Browser - ok
14:58:04.0802 0x2c68 BthAvrcpTg - ok
14:58:04.0804 0x2c68 BthEnum - ok
14:58:04.0806 0x2c68 BthHFEnum - ok
14:58:04.0807 0x2c68 bthhfhid - ok
14:58:04.0807 0x2c68 BthHFSrv - ok
14:58:04.0807 0x2c68 BthLEEnum - ok
14:58:04.0807 0x2c68 BTHMODEM - ok
14:58:04.0807 0x2c68 BthPan - ok
14:58:04.0807 0x2c68 BTHPORT - ok
14:58:04.0807 0x2c68 bthserv - ok
14:58:04.0823 0x2c68 BTHUSB - ok
14:58:04.0823 0x2c68 buttonconverter - ok
14:58:04.0823 0x2c68 CapImg - ok
14:58:04.0840 0x2c68 [ 8189001F994864B4C4CAE344494749E3, 19CF815639588CAA5A85FCE76E3780A004350654B7917E9F0DB7B5245E4CF9B7 ] CCSDK C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
14:58:04.0857 0x2c68 CCSDK - ok
14:58:04.0857 0x2c68 cdfs - ok
14:58:04.0857 0x2c68 CDPSvc - ok
14:58:04.0857 0x2c68 CDPUserSvc - ok
14:58:04.0873 0x2c68 cdrom - ok
14:58:04.0873 0x2c68 CertPropSvc - ok
14:58:04.0873 0x2c68 cht4iscsi - ok
14:58:04.0873 0x2c68 cht4vbd - ok
14:58:04.0873 0x2c68 circlass - ok
14:58:04.0890 0x2c68 CLFS - ok
14:58:04.0940 0x2c68 [ 99C73D65BF6E6AE66D1B4337D8260C97, D13E9861125ABFA892F7FCED1E007FD5FBEE27954C9084286FFD186193157D3A ] ClickToRunSvc C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
14:58:05.0007 0x2c68 ClickToRunSvc - ok
14:58:05.0007 0x2c68 ClipSVC - ok
14:58:05.0007 0x2c68 clreg - ok
14:58:05.0007 0x2c68 CmBatt - ok
14:58:05.0023 0x2c68 CNG - ok
14:58:05.0023 0x2c68 cnghwassist - ok
14:58:05.0040 0x2c68 CompositeBus - ok
14:58:05.0040 0x2c68 COMSysApp - ok
14:58:05.0040 0x2c68 condrv - ok
14:58:05.0040 0x2c68 CoreMessagingRegistrar - ok
14:58:05.0073 0x2c68 [ D981A3E57ADD7D6A42AFFB3ED7C28B41, 1285518373DBEBE7876B8A20B73C1EB57A397832C8F1FE7211F01F47B7119E5E ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
14:58:05.0091 0x2c68 cphs - ok
14:58:05.0106 0x2c68 [ 24DA245050CA0F4A1A15C95F82D9A73A, FD6A2363BBE80921FC1A0F9FB4F16F53C6171891E40C5294EDB674E2DCEDB3D5 ] cplspcon C:\WINDOWS\system32\IntelCpHDCPSvc.exe
14:58:05.0123 0x2c68 cplspcon - ok
14:58:05.0123 0x2c68 CryptSvc - ok
14:58:05.0123 0x2c68 dam - ok
14:58:05.0123 0x2c68 [ 6854D12B9E943A6A1C8FCD846A6A09C8, AD94FEAEDE7E8DE912BBBEE4F069ED092DE7A209769389E985AE7A68085434FF ] DAX2API C:\Program Files\Dolby\Dolby DAX2\DAX2_API\DolbyDAX2API.exe
14:58:05.0140 0x2c68 DAX2API - detected UnsignedFile.Multi.Generic ( 1 )
14:58:05.0204 0x2c68 Detect skipped due to KSN trusted
14:58:05.0204 0x2c68 DAX2API - ok
14:58:05.0207 0x2c68 DcomLaunch - ok
14:58:05.0207 0x2c68 DcpSvc - ok
14:58:05.0207 0x2c68 defragsvc - ok
14:58:05.0207 0x2c68 DeviceAssociationService - ok
14:58:05.0207 0x2c68 DeviceInstall - ok
14:58:05.0207 0x2c68 DevQueryBroker - ok
14:58:05.0223 0x2c68 Dfsc - ok
14:58:05.0223 0x2c68 Dhcp - ok
14:58:05.0223 0x2c68 diagnosticshub.standardcollector.service - ok
14:58:05.0223 0x2c68 DiagTrack - ok
14:58:05.0223 0x2c68 disk - ok
14:58:05.0223 0x2c68 DisplayLinkUsbIo_x64 - ok
14:58:05.0241 0x2c68 [ 9512FBA26244E75B422301E879B0D381, CF8211FC224F9DBCDA6B32E82DFD43292CB148D271E45A57081EBACAC970D103 ] dlcdcncm C:\WINDOWS\System32\drivers\dlcdcncm62_x64.sys
14:58:05.0241 0x2c68 dlcdcncm - ok
14:58:05.0256 0x2c68 [ 3B4FBF05A191D844FA59F22DF69346F7, 34DC686A49A9D31E4837B8B281C0AAF8D86BC57AEF31E0E826DCC2CF5C15993C ] dlusbaudio C:\WINDOWS\system32\DRIVERS\dlusbaudio_x64.sys
14:58:05.0257 0x2c68 dlusbaudio - ok
14:58:05.0257 0x2c68 DmEnrollmentSvc - ok
14:58:05.0257 0x2c68 dmvsc - ok
14:58:05.0257 0x2c68 dmwappushservice - ok
14:58:05.0273 0x2c68 Dnscache - ok
14:58:05.0273 0x2c68 dot3svc - ok
14:58:05.0273 0x2c68 DPS - ok
14:58:05.0273 0x2c68 drmkaud - ok
14:58:05.0273 0x2c68 DsmSvc - ok
14:58:05.0273 0x2c68 DsSvc - ok
14:58:05.0273 0x2c68 DXGKrnl - ok
14:58:05.0289 0x2c68 EapHost - ok
14:58:05.0292 0x2c68 ebdrv - ok
14:58:05.0296 0x2c68 EFS - ok
14:58:05.0298 0x2c68 EhStorClass - ok
14:58:05.0300 0x2c68 EhStorTcgDrv - ok
14:58:05.0304 0x2c68 embeddedmode - ok
14:58:05.0306 0x2c68 EntAppSvc - ok
14:58:05.0307 0x2c68 ErrDev - ok
14:58:05.0323 0x2c68 [ 81B95401325461B14942845C56047990, C2F6074D8AC5E7A8CECB35E5699493881865DEEEC186866FDE1B4BDB30331752 ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
14:58:05.0324 0x2c68 ETD - ok
14:58:05.0340 0x2c68 [ C57A527D108B721E9AE6D25166BE470D, 8B7BB93523A3BBFA00001A1B809BC67008D0E8A0F9C33181632D00695E858A62 ] ETDService C:\Program Files\Elantech\ETDService.exe
14:58:05.0340 0x2c68 ETDService - ok
14:58:05.0357 0x2c68 [ C11EA1618BC4FDAB718B93DE6D3696B3, 30DD6911A6705863F76D40A78FFBDED2109E637DC50AC47382802143A3BD8C31 ] ETDSMBus C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys
14:58:05.0357 0x2c68 ETDSMBus - ok
14:58:05.0357 0x2c68 EventSystem - ok
14:58:05.0373 0x2c68 [ A3037B7A05E7F90373323B7B5B0C2E16, 4AA0ED6A3E30C69224B22B98211BDC51BF36A0BFF55461EF1BA0E33287B88B8F ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
14:58:05.0399 0x2c68 EvtEng - ok
14:58:05.0402 0x2c68 exfat - ok
14:58:05.0404 0x2c68 fastfat - ok
14:58:05.0407 0x2c68 Fax - ok
14:58:05.0407 0x2c68 fdc - ok
14:58:05.0407 0x2c68 fdPHost - ok
14:58:05.0407 0x2c68 FDResPub - ok
14:58:05.0407 0x2c68 fhsvc - ok
14:58:05.0407 0x2c68 FileCrypt - ok
14:58:05.0407 0x2c68 FileInfo - ok
14:58:05.0424 0x2c68 Filetrace - ok
14:58:05.0424 0x2c68 flpydisk - ok
14:58:05.0424 0x2c68 FltMgr - ok
14:58:05.0424 0x2c68 FontCache - ok
14:58:05.0424 0x2c68 FontCache3.0.0.0 - ok
14:58:05.0424 0x2c68 FrameServer - ok
14:58:05.0440 0x2c68 FsDepends - ok
14:58:05.0440 0x2c68 Fs_Rec - ok
14:58:05.0440 0x2c68 fvevol - ok
14:58:05.0474 0x2c68 [ D56EE61F9B62AD677395BF003A49B4A7, A4B657AF38253F4BAE2A8BE7E9453E662BC378773A93631C0445C96267296B53 ] GDCAgent C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
14:58:05.0497 0x2c68 GDCAgent - ok
14:58:05.0500 0x2c68 gencounter - ok
14:58:05.0502 0x2c68 genericusbfn - ok
14:58:05.0506 0x2c68 [ 27C992DA9AC769D1826D897766D7A246, 29525D01D2452B193B012F1AA2C474E8DE372009224C66DB5E70643FD57CFFC7 ] GeneStor C:\WINDOWS\system32\DRIVERS\GeneStor.sys
14:58:05.0506 0x2c68 GeneStor - ok
14:58:05.0506 0x2c68 GPIOClx0101 - ok
14:58:05.0506 0x2c68 gpsvc - ok
14:58:05.0523 0x2c68 GpuEnergyDrv - ok
14:58:05.0523 0x2c68 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
14:58:05.0523 0x2c68 gupdate - ok
14:58:05.0539 0x2c68 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
14:58:05.0540 0x2c68 gupdatem - ok
14:58:05.0540 0x2c68 HDAudBus - ok
14:58:05.0540 0x2c68 HidBatt - ok
14:58:05.0540 0x2c68 HidBth - ok
14:58:05.0540 0x2c68 hidi2c - ok
14:58:05.0557 0x2c68 hidinterrupt - ok
14:58:05.0557 0x2c68 HidIr - ok
14:58:05.0557 0x2c68 hidserv - ok
14:58:05.0557 0x2c68 HidUsb - ok
14:58:05.0557 0x2c68 HomeGroupListener - ok
14:58:05.0557 0x2c68 HomeGroupProvider - ok
14:58:05.0557 0x2c68 HpSAMD - ok
14:58:05.0574 0x2c68 HTTP - ok
14:58:05.0574 0x2c68 HvHost - ok
14:58:05.0574 0x2c68 hvservice - ok
14:58:05.0574 0x2c68 hwpolicy - ok
14:58:05.0574 0x2c68 hyperkbd - ok
14:58:05.0574 0x2c68 i8042prt - ok
14:58:05.0590 0x2c68 iagpio - ok
14:58:05.0592 0x2c68 iai2c - ok
14:58:05.0595 0x2c68 iaLPSS2i_GPIO2 - ok
14:58:05.0598 0x2c68 iaLPSS2i_I2C - ok
14:58:05.0605 0x2c68 [ FF8E14813E3A77DE0DAE0719D5F59428, 9D1EA4963C1CBF8610FB5D6BC868C48C3985D2678F7BDD0E77B3E45A7C13457F ] iaLPSS2_UART2 C:\WINDOWS\System32\drivers\iaLPSS2_UART2.sys
14:58:05.0607 0x2c68 iaLPSS2_UART2 - ok
14:58:05.0607 0x2c68 iaLPSSi_GPIO - ok
14:58:05.0607 0x2c68 iaLPSSi_I2C - ok
14:58:05.0640 0x2c68 [ 5F6CA62BE8ECC4D0E1F5D4D4A02B456B, F720A1F14C9053D24C5B42827E5F9578A27F3E62A6C65A3CFA068E580F02F072 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
14:58:05.0673 0x2c68 iaStorA - ok
14:58:05.0673 0x2c68 iaStorAV - ok
14:58:05.0689 0x2c68 [ D90885430767C6152AF908D57A5159AC, A3C25AA5CDDFBBA91199F673471C64A8A4792A0F2D642F46AD54B18879A464B1 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
14:58:05.0695 0x2c68 IAStorDataMgrSvc - ok
14:58:05.0697 0x2c68 iaStorV - ok
14:58:05.0700 0x2c68 ibbus - ok
14:58:05.0706 0x2c68 [ 606148419C4F99C3102E1EF5E3AFC72A, 63DB5D2ABFB3A0F048B87FCF4B32C4B862F396DDBD3AC5E52951648C99BEC3DD ] ibtusb C:\WINDOWS\system32\DRIVERS\ibtusb.sys
14:58:05.0706 0x2c68 ibtusb - ok
14:58:05.0706 0x2c68 icssvc - ok
14:58:05.0840 0x2c68 [ 43662F2C671B63F4C082F4A573F8A7E1, E83434D1914044B4CDF395E49E42C2A0B57CA34679A6EF54264A5A96BB4417AA ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
14:58:05.0972 0x2c68 igfx - ok
14:58:05.0989 0x2c68 [ 7376BD8A6E189F98969A63482CF23884, 4CF1745C422B819F408B23B67AC2445F5D5DEBB02F76F33A4A416C80EEDB33AA ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
14:58:06.0003 0x2c68 igfxCUIService2.0.0.0 - ok
14:58:06.0005 0x2c68 IKEEXT - ok
14:58:06.0009 0x2c68 [ D10CAFE291F7440D29A6F25343F8B5F3, ECEA095FE6A28BE1198AA258CB22CFBFC40FB5B053D76CDF130717249B12608B ] ImControllerService C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
14:58:06.0016 0x2c68 ImControllerService - ok
14:58:06.0018 0x2c68 IndirectKmd - ok
14:58:06.0089 0x2c68 [ 39200ECEFB50612B13B5D16545BEB201, B093B3A2E2B26ACA64B5DB526C492DFB73AB2F03321E1A3D3CE0EE88920DEAF6 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
14:58:06.0157 0x2c68 IntcAzAudAddService - ok
14:58:06.0174 0x2c68 [ 6A0C4532E05CEAC587531AF318BDDCBC, 70F7C0D617E962801DF09BB2FE45E2F2EF5E9D92632A659F0485A16DF03E6882 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
14:58:06.0190 0x2c68 IntcDAud - ok
14:58:06.0223 0x2c68 [ B63CF22D1AD2ABDC39D85851B2BEAA6D, 37E9043BABB5895BFD2B59AFB60C438B992C6EAA1B5FDE5B3445314343F4C406 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
14:58:06.0241 0x2c68 Intel(R) Capability Licensing Service TCP IP Interface - ok
14:58:06.0257 0x2c68 [ 8213094EA736A9C575AB0E22AD09B0BA, 12670A466B5AA37283BD4CB481D000DE3AE2A8D1BD159F67A41703A6FE5675EC ] Intel(R) Security Assist C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
14:58:06.0273 0x2c68 Intel(R) Security Assist - detected UnsignedFile.Multi.Generic ( 1 )
14:58:06.0321 0x2c68 Detect skipped due to KSN trusted
14:58:06.0321 0x2c68 Intel(R) Security Assist - ok
14:58:06.0324 0x2c68 intelide - ok
14:58:06.0324 0x2c68 intelpep - ok
14:58:06.0324 0x2c68 intelppm - ok
14:58:06.0324 0x2c68 iorate - ok
14:58:06.0324 0x2c68 IpFilterDriver - ok
14:58:06.0324 0x2c68 iphlpsvc - ok
14:58:06.0324 0x2c68 IPMIDRV - ok
14:58:06.0324 0x2c68 IPNAT - ok
14:58:06.0340 0x2c68 irda - ok
14:58:06.0340 0x2c68 IRENUM - ok
14:58:06.0340 0x2c68 irmon - ok
14:58:06.0340 0x2c68 [ 1DFC3CCA51785254C5604238BB1A5467, 31451A90A91AEE14C6B24F84CB9816E5C77179D411B8B3E8547F538235BEEFB0 ] isaHelperSvc C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
14:58:06.0340 0x2c68 isaHelperSvc - detected UnsignedFile.Multi.Generic ( 1 )
14:58:06.0490 0x2c68 Detect skipped due to KSN trusted
14:58:06.0490 0x2c68 isaHelperSvc - ok
14:58:06.0490 0x2c68 isapnp - ok
14:58:06.0490 0x2c68 iScsiPrt - ok
14:58:06.0514 0x2c68 [ DE70C5C10803C700DC1CFDE2D5CF207A, 4D11DE8B986C6966B66E1D6E931A72A1E9FA8D0B5B9EF57EF3EEDD09D0BE0B4E ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
14:58:06.0522 0x2c68 jhi_service - ok
14:58:06.0524 0x2c68 kbdclass - ok
14:58:06.0524 0x2c68 kbdhid - ok
14:58:06.0524 0x2c68 kdnic - ok
14:58:06.0524 0x2c68 KeyIso - ok
14:58:06.0524 0x2c68 KSecDD - ok
14:58:06.0524 0x2c68 KSecPkg - ok
14:58:06.0524 0x2c68 ksthunk - ok
14:58:06.0539 0x2c68 KtmRm - ok
14:58:06.0540 0x2c68 LanmanServer - ok
14:58:06.0540 0x2c68 LanmanWorkstation - ok
14:58:06.0540 0x2c68 lfsvc - ok
14:58:06.0540 0x2c68 LicenseManager - ok
14:58:06.0540 0x2c68 lltdio - ok
14:58:06.0540 0x2c68 lltdsvc - ok
14:58:06.0557 0x2c68 lmhosts - ok
14:58:06.0573 0x2c68 [ 1CE3A27B6B0658F4242AB2DECE69704E, FB705D43554478FA438CE600DAD65C5885858ABF9FCB5D9CC6E5F7C87FD6A853 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
14:58:06.0573 0x2c68 LMS - ok
14:58:06.0590 0x2c68 [ 4799AAD825F79C187FBA948D299386E7, 4E3618CF59B81825CF3E2AEC070CC57E3869BFF7543BB151530F02A3947A22F8 ] LSC.Services.SystemService C:\Program Files\Lenovo\Lenovo Solution Center\App\LSC.Services.SystemService.exe
14:58:06.0590 0x2c68 LSC.Services.SystemService - ok
14:58:06.0610 0x2c68 LSI_SAS - ok
14:58:06.0615 0x2c68 LSI_SAS2i - ok
14:58:06.0617 0x2c68 LSI_SAS3i - ok
14:58:06.0620 0x2c68 LSI_SSS - ok
14:58:06.0621 0x2c68 LSM - ok
14:58:06.0623 0x2c68 luafv - ok
14:58:06.0624 0x2c68 MapsBroker - ok
14:58:06.0624 0x2c68 megasas - ok
14:58:06.0624 0x2c68 megasas2i - ok
14:58:06.0624 0x2c68 megasr - ok
14:58:06.0624 0x2c68 [ 48F64A35BA9F2E4AC0587DDA555FF951, 77FE2BE86ADCE103F4220A641139C42B1407CF8EFFEB66F841ABF9CFC3621558 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
14:58:06.0640 0x2c68 MEIx64 - ok
14:58:06.0640 0x2c68 MessagingService - ok
14:58:06.0640 0x2c68 mlx4_bus - ok
14:58:06.0640 0x2c68 MMCSS - ok
14:58:06.0657 0x2c68 Modem - ok
14:58:06.0657 0x2c68 monitor - ok
14:58:06.0657 0x2c68 mouclass - ok
14:58:06.0657 0x2c68 mouhid - ok
14:58:06.0657 0x2c68 mountmgr - ok
14:58:06.0657 0x2c68 mpsdrv - ok
14:58:06.0657 0x2c68 MpsSvc - ok
14:58:06.0673 0x2c68 MRxDAV - ok
14:58:06.0674 0x2c68 mrxsmb - ok
14:58:06.0674 0x2c68 mrxsmb10 - ok
14:58:06.0674 0x2c68 mrxsmb20 - ok
14:58:06.0674 0x2c68 MsBridge - ok
14:58:06.0674 0x2c68 MSDTC - ok
14:58:06.0674 0x2c68 Msfs - ok
14:58:06.0690 0x2c68 msgpiowin32 - ok
14:58:06.0690 0x2c68 mshidkmdf - ok
14:58:06.0690 0x2c68 mshidumdf - ok
14:58:06.0690 0x2c68 msisadrv - ok
14:58:06.0690 0x2c68 MSiSCSI - ok
14:58:06.0690 0x2c68 msiserver - ok
14:58:06.0690 0x2c68 MSKSSRV - ok
14:58:06.0706 0x2c68 MsLldp - ok
14:58:06.0710 0x2c68 MSPCLOCK - ok
14:58:06.0714 0x2c68 MSPQM - ok
14:58:06.0715 0x2c68 MsRPC - ok
14:58:06.0719 0x2c68 mssmbios - ok
14:58:06.0721 0x2c68 MSTEE - ok
14:58:06.0723 0x2c68 MTConfig - ok
14:58:06.0723 0x2c68 Mup - ok
14:58:06.0723 0x2c68 mvumis - ok
14:58:06.0723 0x2c68 [ 0358DFD6B383CB917FF9B8061FDC8C5E, 18176FA40E376972A858275303EAABD5B4004CE741B35AAC2BCF89F5BB045FB3 ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
14:58:06.0741 0x2c68 MyWiFiDHCPDNS - ok
14:58:06.0741 0x2c68 NativeWifiP - ok
14:58:06.0741 0x2c68 NcaSvc - ok
14:58:06.0741 0x2c68 NcbService - ok
14:58:06.0757 0x2c68 NcdAutoSetup - ok
14:58:06.0757 0x2c68 ndfltr - ok
14:58:06.0757 0x2c68 NDIS - ok
14:58:06.0757 0x2c68 NdisCap - ok
14:58:06.0757 0x2c68 NdisImPlatform - ok
14:58:06.0757 0x2c68 NdisTapi - ok
14:58:06.0757 0x2c68 Ndisuio - ok
14:58:06.0773 0x2c68 NdisVirtualBus - ok
14:58:06.0774 0x2c68 NdisWan - ok
14:58:06.0774 0x2c68 ndiswanlegacy - ok
14:58:06.0774 0x2c68 ndproxy - ok
14:58:06.0774 0x2c68 Ndu - ok
14:58:06.0774 0x2c68 NetAdapterCx - ok
14:58:06.0774 0x2c68 NetBIOS - ok
14:58:06.0789 0x2c68 NetBT - ok
14:58:06.0790 0x2c68 Netlogon - ok
14:58:06.0790 0x2c68 Netman - ok
14:58:06.0790 0x2c68 netprofm - ok
14:58:06.0790 0x2c68 NetSetupSvc - ok
14:58:06.0790 0x2c68 NetTcpPortSharing - ok
14:58:06.0807 0x2c68 NETwNe64 - ok
14:58:06.0912 0x2c68 [ 446E90BF5209CE2D6C641F0670DA0023, 683EAD3618D2DE343D5AF686EDD59ED07BB25134E666F0D37BE756EBC7D64D68 ] Netwtw04 C:\WINDOWS\System32\drivers\Netwtw04.sys
14:58:07.0023 0x2c68 Netwtw04 - ok
14:58:07.0023 0x2c68 NgcCtnrSvc - ok
14:58:07.0023 0x2c68 NgcSvc - ok
14:58:07.0023 0x2c68 NlaSvc - ok
14:58:07.0040 0x2c68 Npfs - ok
14:58:07.0041 0x2c68 npsvctrig - ok
14:58:07.0041 0x2c68 nsi - ok
14:58:07.0041 0x2c68 nsiproxy - ok
14:58:07.0041 0x2c68 NTFS - ok
14:58:07.0041 0x2c68 Null - ok
14:58:07.0057 0x2c68 [ CE299A069E9003596C69DDB838A2A8D7, D015D7FAC1736C976005152B2C6F338452384491B4293E20E14547390130DC78 ] NvContainerLocalSystem C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
14:58:07.0074 0x2c68 NvContainerLocalSystem - ok
14:58:07.0074 0x2c68 [ CE299A069E9003596C69DDB838A2A8D7, D015D7FAC1736C976005152B2C6F338452384491B4293E20E14547390130DC78 ] NvContainerNetworkService C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
14:58:07.0090 0x2c68 NvContainerNetworkService - ok
14:58:07.0116 0x2c68 [ 3A66606F30142D882750FB5FA56F4C5A, 9B84199008220EF2B6B8A0236D6D5EC42D85FFD1054969ED757A09E26B25502B ] NVIDIA Wireless Controller Service C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
14:58:07.0140 0x2c68 NVIDIA Wireless Controller Service - ok
14:58:07.0360 0x2c68 [ 4311C3082527FCC8C464893ECFBF5652, D75F532A31587E15B521FCF053D940BD4CF6EF91E248EEF57A1895D60671B860 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_0326b872c1b453bb\nvlddmkm.sys
14:58:07.0603 0x2c68 nvlddmkm - ok
14:58:07.0620 0x2c68 nvraid - ok
14:58:07.0622 0x2c68 nvstor - ok
14:58:07.0625 0x2c68 [ 7A1728F6C6D19CEF1B1DD1EF2BF88FDB, 6FCB0E1D3926BE0A29D10F458294F0D38FF735E57CD2CD5BF17A7D76DD3D433A ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
14:58:07.0631 0x2c68 NvStreamKms - ok
14:58:07.0657 0x2c68 [ DEFADC7096D8DD06E1675D80B7DAD51E, AD39D17296E5801BF7955693774D6786F11C84A94C1C31EF88AD829A869AB783 ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
14:58:07.0690 0x2c68 nvsvc - ok
14:58:07.0690 0x2c68 [ EDD60410F12366570FD1A5DDBA925EC3, 73CE206C45887CD714F8A4E801B75C6E38AC9DA105F36656FBC6E235C7FC8290 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
14:58:07.0690 0x2c68 nvvad_WaveExtensible - ok
14:58:07.0707 0x2c68 OneSyncSvc - ok
14:58:07.0707 0x2c68 [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:58:07.0722 0x2c68 ose - ok
14:58:07.0729 0x2c68 p2pimsvc - ok
14:58:07.0734 0x2c68 p2psvc - ok
14:58:07.0737 0x2c68 Parport - ok
14:58:07.0739 0x2c68 partmgr - ok
14:58:07.0741 0x2c68 PcaSvc - ok
14:58:07.0744 0x2c68 pci - ok
14:58:07.0747 0x2c68 pciide - ok
14:58:07.0749 0x2c68 pcmcia - ok
14:58:07.0752 0x2c68 pcw - ok
14:58:07.0754 0x2c68 pdc - ok
14:58:07.0756 0x2c68 PEAUTH - ok
14:58:07.0759 0x2c68 percsas2i - ok
14:58:07.0761 0x2c68 percsas3i - ok
14:58:07.0773 0x2c68 PerfHost - ok
14:58:07.0790 0x2c68 PhoneSvc - ok
14:58:07.0790 0x2c68 PimIndexMaintenanceSvc - ok
14:58:07.0790 0x2c68 pla - ok
14:58:07.0790 0x2c68 PlugPlay - ok
14:58:07.0790 0x2c68 PNRPAutoReg - ok
14:58:07.0790 0x2c68 PNRPsvc - ok
14:58:07.0807 0x2c68 PolicyAgent - ok
14:58:07.0807 0x2c68 Power - ok
14:58:07.0807 0x2c68 PptpMiniport - ok
14:58:07.0890 0x2c68 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
14:58:07.0990 0x2c68 PrintNotify - ok
14:58:07.0990 0x2c68 Processor - ok
14:58:07.0990 0x2c68 ProfSvc - ok
14:58:08.0007 0x2c68 Psched - ok
14:58:08.0007 0x2c68 QWAVE - ok
14:58:08.0007 0x2c68 QWAVEdrv - ok
14:58:08.0007 0x2c68 RasAcd - ok
14:58:08.0007 0x2c68 RasAgileVpn - ok
14:58:08.0007 0x2c68 RasAuto - ok
14:58:08.0024 0x2c68 Rasl2tp - ok
14:58:08.0027 0x2c68 RasMan - ok
14:58:08.0030 0x2c68 RasPppoe - ok
14:58:08.0034 0x2c68 RasSstp - ok
14:58:08.0036 0x2c68 rdbss - ok
14:58:08.0039 0x2c68 rdpbus - ok
14:58:08.0040 0x2c68 RDPDR - ok
14:58:08.0040 0x2c68 RdpVideoMiniport - ok
14:58:08.0040 0x2c68 rdyboost - ok
14:58:08.0040 0x2c68 ReFSv1 - ok
14:58:08.0056 0x2c68 [ 89253C7F17EF15F627CDE2DB104E6BF8, 80F3EF26D3EFE2BFD82AC1DAC83439A03133477409D5594683CAB92C8F9CB7E7 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
14:58:08.0056 0x2c68 RegSrvc - ok
14:58:08.0056 0x2c68 RemoteAccess - ok
14:58:08.0056 0x2c68 RemoteRegistry - ok
14:58:08.0056 0x2c68 RetailDemo - ok
14:58:08.0073 0x2c68 RFCOMM - ok
14:58:08.0073 0x2c68 RmSvc - ok
14:58:08.0073 0x2c68 RpcEptMapper - ok
14:58:08.0073 0x2c68 RpcLocator - ok
14:58:08.0073 0x2c68 RpcSs - ok
14:58:08.0089 0x2c68 rspndr - ok
14:58:08.0107 0x2c68 [ 952209B8749D7AB91D5BB95665C5D13E, B7E6D7293A2D2B7492FD240E52E041E0BA4818F99FEBB3C6B718C1871D190E26 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
14:58:08.0128 0x2c68 rt640x64 - ok
14:58:08.0174 0x2c68 [ DB49507BAFF78DA30CCCD4BAFC49FA1C, 7AC4B3419686969E81ECBBC8EFCAA2C3560D50055F3C39BFE419FC360A027970 ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
14:58:08.0240 0x2c68 rtsuvc - ok
14:58:08.0240 0x2c68 s3cap - ok
14:58:08.0240 0x2c68 SamSs - ok
14:58:08.0240 0x2c68 sbp2port - ok
14:58:08.0240 0x2c68 SCardSvr - ok
14:58:08.0256 0x2c68 ScDeviceEnum - ok
14:58:08.0257 0x2c68 scfilter - ok
14:58:08.0257 0x2c68 Schedule - ok
14:58:08.0257 0x2c68 scmbus - ok
14:58:08.0257 0x2c68 scmdisk0101 - ok
14:58:08.0257 0x2c68 SCPolicySvc - ok
14:58:08.0273 0x2c68 sdbus - ok
14:58:08.0273 0x2c68 SDRSVC - ok
14:58:08.0273 0x2c68 sdstor - ok
14:58:08.0273 0x2c68 seclogon - ok
14:58:08.0273 0x2c68 [ 07F83829E7429E60298440CD1E601A6A, 9F1229CD8DD9092C27A01F5D56E3C0D59C2BB9F0139ABF042E56F343637FDA33 ] semav6msr64 C:\Windows\system32\drivers\semav6msr64.sys
14:58:08.0290 0x2c68 semav6msr64 - ok
14:58:08.0290 0x2c68 SENS - ok
14:58:08.0290 0x2c68 SensorDataService - ok
14:58:08.0290 0x2c68 SensorService - ok
14:58:08.0290 0x2c68 SensrSvc - ok
14:58:08.0290 0x2c68 SerCx - ok
14:58:08.0306 0x2c68 SerCx2 - ok
14:58:08.0306 0x2c68 Serenum - ok
14:58:08.0306 0x2c68 Serial - ok
14:58:08.0306 0x2c68 sermouse - ok
14:58:08.0325 0x2c68 SessionEnv - ok
14:58:08.0328 0x2c68 sfloppy - ok
14:58:08.0332 0x2c68 SharedAccess - ok
14:58:08.0334 0x2c68 ShellHWDetection - ok
14:58:08.0336 0x2c68 shpamsvc - ok
14:58:08.0340 0x2c68 SiSRaid2 - ok
14:58:08.0340 0x2c68 SiSRaid4 - ok
14:58:08.0340 0x2c68 smphost - ok
14:58:08.0340 0x2c68 SmsRouter - ok
14:58:08.0340 0x2c68 SNMPTRAP - ok
14:58:08.0357 0x2c68 spaceport - ok
14:58:08.0357 0x2c68 SpbCx - ok
14:58:08.0357 0x2c68 Spooler - ok
14:58:08.0357 0x2c68 sppsvc - ok
14:58:08.0357 0x2c68 srv - ok
14:58:08.0357 0x2c68 srv2 - ok
14:58:08.0373 0x2c68 srvnet - ok
14:58:08.0373 0x2c68 SSDPSRV - ok
14:58:08.0373 0x2c68 SstpSvc - ok
14:58:08.0390 0x2c68 StateRepository - ok
14:58:08.0390 0x2c68 [ F92C4729D4E4282DF6196AEFE4AC51AB, 546E4067D06E93DDF36315C46B5699DF13095000EEC186011346133DEAC67928 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
14:58:08.0407 0x2c68 Stereo Service - ok
14:58:08.0407 0x2c68 stexstor - ok
14:58:08.0407 0x2c68 stisvc - ok
14:58:08.0407 0x2c68 storahci - ok
14:58:08.0425 0x2c68 storflt - ok
14:58:08.0429 0x2c68 stornvme - ok
14:58:08.0432 0x2c68 storqosflt - ok
14:58:08.0436 0x2c68 StorSvc - ok
14:58:08.0438 0x2c68 storufs - ok
14:58:08.0440 0x2c68 storvsc - ok
14:58:08.0440 0x2c68 svsvc - ok
14:58:08.0440 0x2c68 swenum - ok
14:58:08.0440 0x2c68 swprv - ok
14:58:08.0440 0x2c68 Synth3dVsc - ok
14:58:08.0440 0x2c68 SysMain - ok
14:58:08.0457 0x2c68 SystemEventsBroker - ok
14:58:08.0457 0x2c68 [ 2BE3A44B764D6C43CBF4650E862CB807, 78920DA47F3A0C26503FB62EF159455A860E57A9A39C72AEE23A9324168EC1D2 ] SystemUsageReportSvc_WILLAMETTE C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
14:58:08.0457 0x2c68 SystemUsageReportSvc_WILLAMETTE - ok
14:58:08.0457 0x2c68 TabletInputService - ok
14:58:08.0474 0x2c68 TapiSrv - ok
14:58:08.0474 0x2c68 Tcpip - ok
14:58:08.0483 0x2c68 Tcpip6 - ok
14:58:08.0489 0x2c68 tcpipreg - ok
14:58:08.0494 0x2c68 tdx - ok
14:58:08.0497 0x2c68 terminpt - ok
14:58:08.0500 0x2c68 TermService - ok
14:58:08.0503 0x2c68 Themes - ok
14:58:08.0506 0x2c68 TieringEngineService - ok
14:58:08.0513 0x2c68 tiledatamodelsvc - ok
14:58:08.0518 0x2c68 TimeBrokerSvc - ok
14:58:08.0520 0x2c68 TPM - ok
14:58:08.0523 0x2c68 TrkWks - ok
14:58:08.0526 0x2c68 TrustedInstaller - ok
14:58:08.0530 0x2c68 tsusbflt - ok
14:58:08.0532 0x2c68 TsUsbGD - ok
14:58:08.0535 0x2c68 tunnel - ok
14:58:08.0538 0x2c68 tzautoupdate - ok
14:58:08.0540 0x2c68 UASPStor - ok
14:58:08.0540 0x2c68 UcmCx0101 - ok
14:58:08.0546 0x2c68 UcmTcpciCx0101 - ok
14:58:08.0549 0x2c68 UcmUcsi - ok
14:58:08.0551 0x2c68 Ucx01000 - ok
14:58:08.0554 0x2c68 UdeCx - ok
14:58:08.0556 0x2c68 udfs - ok
14:58:08.0557 0x2c68 UEFI - ok
14:58:08.0563 0x2c68 Ufx01000 - ok
14:58:08.0566 0x2c68 UfxChipidea - ok
14:58:08.0568 0x2c68 ufxsynopsys - ok
14:58:08.0574 0x2c68 UI0Detect - ok
14:58:08.0577 0x2c68 umbus - ok
14:58:08.0580 0x2c68 UmPass - ok
14:58:08.0583 0x2c68 UmRdpService - ok
14:58:08.0587 0x2c68 UnistoreSvc - ok
14:58:08.0591 0x2c68 upnphost - ok
14:58:08.0594 0x2c68 UrsChipidea - ok
14:58:08.0597 0x2c68 UrsCx01000 - ok
14:58:08.0600 0x2c68 UrsSynopsys - ok
14:58:08.0603 0x2c68 usbccgp - ok
14:58:08.0606 0x2c68 usbcir - ok
14:58:08.0609 0x2c68 usbehci - ok
14:58:08.0612 0x2c68 usbhub - ok
14:58:08.0615 0x2c68 USBHUB3 - ok
14:58:08.0618 0x2c68 usbohci - ok
14:58:08.0621 0x2c68 usbprint - ok
14:58:08.0624 0x2c68 usbser - ok
14:58:08.0627 0x2c68 USBSTOR - ok
14:58:08.0630 0x2c68 usbuhci - ok
14:58:08.0633 0x2c68 USBXHCI - ok
14:58:08.0635 0x2c68 UserDataSvc - ok
14:58:08.0639 0x2c68 UserManager - ok
14:58:08.0640 0x2c68 [ F4D8F67474DDA4FEF3935393AAA0173F, 5EB1700895E33972816DE4C2B920769CCE5580B83CAB8B2D7A8A6264F3A42B80 ] USER_ESRV_SVC_WILLAMETTE C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
14:58:08.0657 0x2c68 USER_ESRV_SVC_WILLAMETTE - ok
14:58:08.0657 0x2c68 UsoSvc - ok
14:58:08.0657 0x2c68 VaultSvc - ok
14:58:08.0657 0x2c68 vdrvroot - ok
14:58:08.0657 0x2c68 vds - ok
14:58:08.0673 0x2c68 VerifierExt - ok
14:58:08.0673 0x2c68 vhdmp - ok
14:58:08.0673 0x2c68 vhf - ok
14:58:08.0673 0x2c68 vmbus - ok
14:58:08.0673 0x2c68 VMBusHID - ok
14:58:08.0673 0x2c68 vmgid - ok
14:58:08.0689 0x2c68 vmicguestinterface - ok
14:58:08.0690 0x2c68 vmicheartbeat - ok
14:58:08.0690 0x2c68 vmickvpexchange - ok
14:58:08.0690 0x2c68 vmicrdv - ok
14:58:08.0690 0x2c68 vmicshutdown - ok
14:58:08.0690 0x2c68 vmictimesync - ok
14:58:08.0706 0x2c68 vmicvmsession - ok
14:58:08.0706 0x2c68 vmicvss - ok
14:58:08.0706 0x2c68 volmgr - ok
14:58:08.0706 0x2c68 volmgrx - ok
14:58:08.0706 0x2c68 volsnap - ok
14:58:08.0706 0x2c68 volume - ok
14:58:08.0722 0x2c68 vpci - ok
14:58:08.0726 0x2c68 vsmraid - ok
14:58:08.0729 0x2c68 VSS - ok
14:58:08.0732 0x2c68 VSTXRAID - ok
14:58:08.0734 0x2c68 vwifibus - ok
14:58:08.0737 0x2c68 vwififlt - ok
14:58:08.0739 0x2c68 vwifimp - ok
14:58:08.0740 0x2c68 W32Time - ok
14:58:08.0740 0x2c68 WacomPen - ok
14:58:08.0740 0x2c68 WalletService - ok
14:58:08.0740 0x2c68 wanarp - ok
14:58:08.0740 0x2c68 wanarpv6 - ok
14:58:08.0757 0x2c68 wbengine - ok
14:58:08.0757 0x2c68 WbioSrvc - ok
14:58:08.0757 0x2c68 wcifs - ok
14:58:08.0757 0x2c68 Wcmsvc - ok
14:58:08.0757 0x2c68 wcncsvc - ok
14:58:08.0757 0x2c68 wcnfs - ok
14:58:08.0773 0x2c68 WdBoot - ok
14:58:08.0774 0x2c68 Wdf01000 - ok
14:58:08.0774 0x2c68 WdFilter - ok
14:58:08.0774 0x2c68 WdiServiceHost - ok
14:58:08.0774 0x2c68 WdiSystemHost - ok
14:58:08.0774 0x2c68 wdiwifi - ok
14:58:08.0774 0x2c68 WdNisDrv - ok
14:58:08.0790 0x2c68 WdNisSvc - ok
14:58:08.0790 0x2c68 WebClient - ok
14:58:08.0790 0x2c68 Wecsvc - ok
14:58:08.0790 0x2c68 WEPHOSTSVC - ok
14:58:08.0790 0x2c68 wercplsupport - ok
14:58:08.0790 0x2c68 WerSvc - ok
14:58:08.0806 0x2c68 WFPLWFS - ok
14:58:08.0807 0x2c68 WiaRpc - ok
14:58:08.0807 0x2c68 WIMMount - ok
14:58:08.0807 0x2c68 WinDefend - ok
14:58:08.0807 0x2c68 WindowsTrustedRT - ok
14:58:08.0807 0x2c68 WindowsTrustedRTProxy - ok
14:58:08.0825 0x2c68 WinHttpAutoProxySvc - ok
14:58:08.0828 0x2c68 WinMad - ok
14:58:08.0834 0x2c68 Winmgmt - ok
14:58:08.0836 0x2c68 WinRM - ok
14:58:08.0840 0x2c68 WINUSB - ok
14:58:08.0840 0x2c68 WinVerbs - ok
14:58:08.0840 0x2c68 wisvc - ok
14:58:08.0840 0x2c68 WlanSvc - ok
14:58:08.0840 0x2c68 wlidsvc - ok
14:58:08.0855 0x2c68 WmiAcpi - ok
14:58:08.0857 0x2c68 wmiApSrv - ok
14:58:08.0857 0x2c68 WMPNetworkSvc - ok
14:58:08.0857 0x2c68 Wof - ok
14:58:08.0857 0x2c68 workfolderssvc - ok
14:58:08.0857 0x2c68 WPDBusEnum - ok
14:58:08.0873 0x2c68 WpdUpFltr - ok
14:58:08.0873 0x2c68 WpnService - ok
14:58:08.0873 0x2c68 WpnUserService - ok
14:58:08.0873 0x2c68 ws2ifsl - ok
14:58:08.0873 0x2c68 wscsvc - ok
14:58:08.0890 0x2c68 WSDPrintDevice - ok
14:58:08.0891 0x2c68 WSDScan - ok
14:58:08.0891 0x2c68 WSearch - ok
14:58:08.0891 0x2c68 [ 72B4E9DF6456C43C42A1419B09486045, 536BA7377B5BEA7EA46864453933111DB88DB8FB689C68915ACD7261A996E61D ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
14:58:08.0907 0x2c68 wsvd - ok
14:58:08.0907 0x2c68 wuauserv - ok
14:58:08.0907 0x2c68 WudfPf - ok
14:58:08.0907 0x2c68 WUDFRd - ok
14:58:08.0907 0x2c68 wudfsvc - ok
14:58:08.0923 0x2c68 WUDFWpdFs - ok
14:58:08.0926 0x2c68 WwanSvc - ok
14:58:08.0929 0x2c68 XblAuthManager - ok
14:58:08.0933 0x2c68 XblGameSave - ok
14:58:08.0935 0x2c68 xboxgip - ok
14:58:08.0938 0x2c68 XboxNetApiSvc - ok
14:58:08.0940 0x2c68 xinputhid - ok
14:58:08.0990 0x2c68 [ F01B10760ED962879BCAA456AD39A898, EF384EB9C8E170C0394BB5C78721DFAA190698CD38C56736D0120754D50047EC ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
14:58:09.0056 0x2c68 ZeroConfigService - ok
14:58:09.0056 0x2c68 ================ Scan global ===============================
14:58:09.0073 0x2c68 [ Global ] - ok
14:58:09.0073 0x2c68 ================ Scan MBR ==================================
14:58:09.0073 0x2c68 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
14:58:09.0257 0x2c68 \Device\Harddisk1\DR1 - ok
14:58:09.0257 0x2c68 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
14:58:09.0290 0x2c68 \Device\Harddisk0\DR0 - ok
14:58:09.0290 0x2c68 ================ Scan VBR ==================================
14:58:09.0290 0x2c68 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk1\DR1\Partition1
14:58:09.0290 0x2c68 \Device\Harddisk1\DR1\Partition1 - ok
14:58:09.0290 0x2c68 [ C1490FFC3E30999FA3BBDA6C8CD217A5 ] \Device\Harddisk1\DR1\Partition2
14:58:09.0290 0x2c68 \Device\Harddisk1\DR1\Partition2 - ok
14:58:09.0290 0x2c68 [ C861789EA59D708FA2DD777D885AE028 ] \Device\Harddisk1\DR1\Partition3
14:58:09.0290 0x2c68 \Device\Harddisk1\DR1\Partition3 - ok
14:58:09.0306 0x2c68 [ 4DEBFF9B2136F084E91530637095B30D ] \Device\Harddisk0\DR0\Partition1
14:58:09.0306 0x2c68 \Device\Harddisk0\DR0\Partition1 - ok
14:58:09.0306 0x2c68 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition2
14:58:09.0306 0x2c68 \Device\Harddisk0\DR0\Partition2 - ok
14:58:09.0306 0x2c68 [ 4B10A999A2B896A58D301E650DEDAD7D ] \Device\Harddisk0\DR0\Partition3
14:58:09.0306 0x2c68 \Device\Harddisk0\DR0\Partition3 - ok
14:58:09.0306 0x2c68 [ 435534EB7756CD49722ADF0CA0005CC7 ] \Device\Harddisk0\DR0\Partition4
14:58:09.0306 0x2c68 \Device\Harddisk0\DR0\Partition4 - ok
14:58:09.0306 0x2c68 [ 8F89D2F01730CC811A7DC1D374F15462 ] \Device\Harddisk0\DR0\Partition5
14:58:09.0306 0x2c68 \Device\Harddisk0\DR0\Partition5 - ok
14:58:09.0306 0x2c68 [ 2A265B11E1F504DAD1F45F9D7570C8A4 ] \Device\Harddisk0\DR0\Partition6
14:58:09.0306 0x2c68 \Device\Harddisk0\DR0\Partition6 - ok
14:58:09.0306 0x2c68 ================ Scan generic autorun ======================
14:58:09.0571 0x2c68 [ BA3AB83C9D468655F81FE607A796CD0C, DDADA5A229A0B2566C27D484479D9AED3DCD09FD8F701A0FD839CB63326A5ABE ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
14:58:09.0800 0x2c68 RTHDVCPL - ok
14:58:09.0824 0x2c68 [ F7A9CF17145A32910F996BE63781BE27, 48CACE27A93ABF37944331E9237A5C860DA22C5A87EDD3B2922E26149E2400AE ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
14:58:09.0857 0x2c68 RtHDVBg_Dolby - ok
14:58:09.0873 0x2c68 [ F7A9CF17145A32910F996BE63781BE27, 48CACE27A93ABF37944331E9237A5C860DA22C5A87EDD3B2922E26149E2400AE ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
14:58:09.0913 0x2c68 RtHDVBg_LENOVO_DOLBYDRAGON - ok
14:58:09.0940 0x2c68 [ F7A9CF17145A32910F996BE63781BE27, 48CACE27A93ABF37944331E9237A5C860DA22C5A87EDD3B2922E26149E2400AE ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
14:58:09.0957 0x2c68 RtHDVBg_LENOVO_MICPKEY - ok
14:58:09.0973 0x2c68 [ 772123B2276B94C797659AEDC0D49943, 6ADD29D91EE5C510B2C7F788FBA034A45400EA25449C1826ABE1296553EF1CBD ] C:\Program Files\Lenovo\LenovoUtility\utility.exe
14:58:09.0991 0x2c68 LenovoUtility - ok
14:58:10.0024 0x2c68 [ 5DAF33FC6EC8591F723B525FC3E451DD, 1E86BE5A7CE9C56A5DA465030D173B6CD208AC932E1DA893A94B751D59AE28F6 ] C:\Program Files\Dolby\Dolby DAX2\DAX2_APP\DolbyDAX2TrayIcon.exe
14:58:10.0041 0x2c68 DAX2_APP - detected UnsignedFile.Multi.Generic ( 1 )
14:58:10.0074 0x2c68 Detect skipped due to KSN trusted
14:58:10.0074 0x2c68 DAX2_APP - ok
14:58:10.0090 0x2c68 [ 03AE229AD0EC7BFDA3D2B37BA9E5799E, E22C1C0F78515595A27812459810774175100D4096D0F0E15812AD3761D1DCC9 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
14:58:10.0090 0x2c68 IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
14:58:10.0140 0x2c68 Detect skipped due to KSN trusted
14:58:10.0140 0x2c68 IAStorIcon - ok
14:58:10.0157 0x2c68 [ 48515EEA1608ECD83FE26C7490460F59, C7C552D13ED12B4165FDE45F69E170D4F18B746D84B3B08E7254AAF8D9671D0C ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
14:58:10.0174 0x2c68 AdobeAAMUpdater-1.0 - ok
14:58:10.0190 0x2c68 [ EDBD0648A97D4485E24F21C50F9FCB49, 4B63E79C44E08DA92E4DA3D98CDC6F7B11FC20E8B315FC580488B52C08074EC2 ] C:\WINDOWS\SysWOW64\UMonit64.exe
14:58:10.0220 0x2c68 UMonit - ok
14:58:10.0220 0x2c68 WindowsDefender - ok
14:58:10.0257 0x2c68 [ 7D5E8D5BDF324718BBC91DF02D830317, AA6A8B0536C14A7D11FDFFA5F980E90059F6C3BE99DE57503EC58DEA022C5398 ] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
14:58:10.0290 0x2c68 Adobe Creative Cloud - ok
14:58:10.0323 0x2c68 [ 18A7D576C182E67F73DB5E0E7AD284EC, 311C46B24603D425F7E2791D286E07E1DE9562374B337D47778403A9B31B642C ] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe
14:58:10.0367 0x2c68 Acrobat Assistant 8.0 - ok
14:58:10.0369 0x2c68 OneDriveSetup - ok
14:58:10.0372 0x2c68 OneDriveSetup - ok
14:58:10.0372 0x2c68 VLC Updater - ok
14:58:10.0389 0x2c68 [ B6EF01B68C33060134D1D3C2EC947D48, 8A29B1C5FD570E31B8DC7178965D3107D70BF1860A1D1F0B62D0C3487D6AFF9B ] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe
14:58:10.0407 0x2c68 Adobe Acrobat Synchronizer - ok
14:58:10.0408 0x2c68 Waiting for KSN requests completion. In queue: 62
14:58:11.0433 0x2c68 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x61100 ( enabled : updated )
14:58:11.0440 0x2c68 Win FW state via NFP2: enabled ( trusted )
14:58:11.0672 0x2c68 ============================================================
14:58:11.0672 0x2c68 Scan finished
14:58:11.0672 0x2c68 ============================================================
14:58:11.0673 0x2b04 Detected object count: 0
14:58:11.0673 0x2b04 Actual detected object count: 0 |