Spheenix | 15.01.2017 14:59 | Malwarebytes Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2017.01.15.03
rootkit: v2016.11.20.01
Windows 10 x64 NTFS
Internet Explorer 11.576.14393.0
Sebastian :: MICASA [administrator]
15.01.2017 14:30:49
mbar-log-2017-01-15 (14-30-49).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 359519
Time elapsed: 22 minute(s), 33 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) TDSSKiller Code:
14:56:03.0689 0x32c0 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
14:56:03.0689 0x32c0 UEFI system
14:56:07.0796 0x32c0 ============================================================
14:56:07.0796 0x32c0 Current date / time: 2017/01/15 14:56:07.0796
14:56:07.0798 0x32c0 SystemInfo:
14:56:07.0798 0x32c0
14:56:07.0798 0x32c0 OS Version: 10.0.14393 ServicePack: 0.0
14:56:07.0798 0x32c0 Product type: Workstation
14:56:07.0798 0x32c0 ComputerName: MICASA
14:56:07.0799 0x32c0 UserName: Sebastian
14:56:07.0799 0x32c0 Windows directory: C:\WINDOWS
14:56:07.0799 0x32c0 System windows directory: C:\WINDOWS
14:56:07.0799 0x32c0 Running under WOW64
14:56:07.0799 0x32c0 Processor architecture: Intel x64
14:56:07.0799 0x32c0 Number of processors: 4
14:56:07.0799 0x32c0 Page size: 0x1000
14:56:07.0799 0x32c0 Boot type: Normal boot
14:56:07.0799 0x32c0 CodeIntegrityOptions = 0x00000001
14:56:07.0799 0x32c0 ============================================================
14:56:08.0816 0x32c0 KLMD registered as C:\WINDOWS\system32\drivers\73121870.sys
14:56:08.0816 0x32c0 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.693, osProperties = 0x19
14:56:09.0286 0x32c0 System UUID: {331859AA-1F7A-2436-C6F5-4682B1DA5DBB}
14:56:10.0080 0x32c0 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
14:56:10.0088 0x32c0 ============================================================
14:56:10.0088 0x32c0 \Device\Harddisk0\DR0:
14:56:10.0100 0x32c0 GPT partitions:
14:56:10.0130 0x32c0 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {810FC053-D3E1-4372-B567-5BBB3A6B8343}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x12C000
14:56:10.0130 0x32c0 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {EACFC1CF-161D-4FFC-96E6-6E3A267662E6}, Name: EFI system partition, StartLBA 0x12C800, BlocksNum 0x96000
14:56:10.0130 0x32c0 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {50677074-B3B7-4EF5-BF58-2A0B334B1279}, Name: Microsoft reserved partition, StartLBA 0x1C2800, BlocksNum 0x40000
14:56:10.0130 0x32c0 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {03B848BA-65FC-4BC2-B0BF-BC8D62CDB0EA}, Name: Basic data partition, StartLBA 0x202800, BlocksNum 0x38EFF000
14:56:10.0130 0x32c0 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {72AEAE8A-1F55-4F7F-B23B-28F3F667F176}, Name: Basic data partition, StartLBA 0x39101800, BlocksNum 0x39005000
14:56:10.0130 0x32c0 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {34A3AC33-CEA4-4964-A9BF-6A3AB06257D8}, Name: Basic data partition, StartLBA 0x72106800, BlocksNum 0x2600000
14:56:10.0130 0x32c0 MBR partitions:
14:56:10.0130 0x32c0 ============================================================
14:56:10.0162 0x32c0 C: <-> \Device\Harddisk0\DR0\Partition4
14:56:10.0199 0x32c0 D: <-> \Device\Harddisk0\DR0\Partition5
14:56:10.0199 0x32c0 ============================================================
14:56:10.0199 0x32c0 Initialize success
14:56:10.0199 0x32c0 ============================================================
14:57:08.0099 0x2ab8 ============================================================
14:57:08.0099 0x2ab8 Scan started
14:57:08.0099 0x2ab8 Mode: Manual; SigCheck; TDLFS;
14:57:08.0099 0x2ab8 ============================================================
14:57:08.0099 0x2ab8 KSN ping started
14:57:08.0184 0x2ab8 KSN ping finished: true
14:57:11.0755 0x2ab8 ================ Scan system memory ========================
14:57:11.0755 0x2ab8 System memory - ok
14:57:11.0755 0x2ab8 ================ Scan services =============================
14:57:11.0863 0x2ab8 1394ohci - ok
14:57:11.0866 0x2ab8 3ware - ok
14:57:11.0874 0x2ab8 ACPI - ok
14:57:11.0877 0x2ab8 AcpiDev - ok
14:57:11.0889 0x2ab8 acpiex - ok
14:57:11.0892 0x2ab8 acpipagr - ok
14:57:11.0933 0x2ab8 AcpiPmi - ok
14:57:11.0935 0x2ab8 acpitime - ok
14:57:11.0979 0x2ab8 [ A4E1EA8C252B0974EE0810580E53047F, 3C9203F0276678001D1B7B0866D327F32A308B7123688A469FA69FBF4F48039A ] acsock C:\WINDOWS\system32\DRIVERS\acsock64.sys
14:57:12.0040 0x2ab8 acsock - ok
14:57:12.0120 0x2ab8 [ B932E0EE190778D840F1442DFC0F9612, 8780963F14D57279FDD585BE945ED40F24590D32676C7A9EF94002D38B8BA643 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
14:57:12.0145 0x2ab8 AdobeARMservice - ok
14:57:12.0148 0x2ab8 ADP80XX - ok
14:57:12.0161 0x2ab8 AFD - ok
14:57:12.0168 0x2ab8 ahcache - ok
14:57:12.0184 0x2ab8 AJRouter - ok
14:57:12.0198 0x2ab8 ALG - ok
14:57:12.0200 0x2ab8 AmdK8 - ok
14:57:12.0202 0x2ab8 AmdPPM - ok
14:57:12.0204 0x2ab8 amdsata - ok
14:57:12.0206 0x2ab8 amdsbs - ok
14:57:12.0210 0x2ab8 amdxata - ok
14:57:12.0212 0x2ab8 AppID - ok
14:57:12.0214 0x2ab8 AppIDSvc - ok
14:57:12.0219 0x2ab8 Appinfo - ok
14:57:12.0223 0x2ab8 applockerfltr - ok
14:57:12.0238 0x2ab8 AppReadiness - ok
14:57:12.0265 0x2ab8 AppXSvc - ok
14:57:12.0267 0x2ab8 arcsas - ok
14:57:12.0318 0x2ab8 [ 1A234F4643F5658BAB07BFA611282267, F40435488389B4FB3B945CA21A8325A51E1B5F80F045AB019748D0EC66056A8B ] AsrDrv101 C:\Windows\SysWOW64\Drivers\AsrDrv101.sys
14:57:12.0328 0x2ab8 AsrDrv101 - ok
14:57:12.0362 0x2ab8 [ A16DACE95B82683C852CD18578162735, 6E3663B43FB18BFD3B47A63297FA251C467D7B3C7B70020FC87DEAD8F0882B37 ] ASRockIOMon C:\Program Files (x86)\ASRock Utility\A-Tuning\Bin\IOMonitorSrv.exe
14:57:12.0522 0x2ab8 ASRockIOMon - ok
14:57:12.0545 0x2ab8 [ A149C93231945A5118C63AEACA6D1E72, 60B28184585B389751FCF71651A139D74018DE04AEBF4A497835AF727B64BD53 ] AsrRamDisk C:\WINDOWS\system32\drivers\AsrRamDisk.sys
14:57:12.0555 0x2ab8 AsrRamDisk - ok
14:57:12.0557 0x2ab8 AsyncMac - ok
14:57:12.0561 0x2ab8 atapi - ok
14:57:12.0571 0x2ab8 AudioEndpointBuilder - ok
14:57:12.0592 0x2ab8 Audiosrv - ok
14:57:12.0594 0x2ab8 AxInstSV - ok
14:57:12.0597 0x2ab8 b06bdrv - ok
14:57:12.0599 0x2ab8 BasicDisplay - ok
14:57:12.0601 0x2ab8 BasicRender - ok
14:57:12.0604 0x2ab8 bcmfn - ok
14:57:12.0606 0x2ab8 bcmfn2 - ok
14:57:12.0624 0x2ab8 BDESVC - ok
14:57:12.0627 0x2ab8 Beep - ok
14:57:12.0695 0x2ab8 [ CE4DEB0464915A50371D1FCDD22BE6D0, 8CFDC981605DE5ED22DC07E892108445BDAE84FCACFAF2EB5E4417E0757B623D ] BEService C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
14:57:12.0861 0x2ab8 BEService - ok
14:57:12.0872 0x2ab8 BFE - ok
14:57:12.0874 0x2ab8 BITS - ok
14:57:12.0910 0x2ab8 [ 3F56903E124E820AEECE6D471583C6C1, B3C045AFACC8A8F5DC289ADE9ACFB2FE7F9CA24A900BBAED47E2A63837208CB3 ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
14:57:12.0974 0x2ab8 Bonjour Service - ok
14:57:12.0985 0x2ab8 bowser - ok
14:57:13.0051 0x2ab8 [ 7487B46E104303E247F68D485C12326F, BAC6A4FFD5B4009B4B673479630FAA2784618438925DFB6489F07BF163188114 ] BRDriver64_1_3_3_E02B25FC C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys
14:57:13.0063 0x2ab8 BRDriver64_1_3_3_E02B25FC - ok
14:57:13.0081 0x2ab8 BrokerInfrastructure - ok
14:57:13.0096 0x2ab8 Browser - ok
14:57:13.0124 0x2ab8 [ 448917845F097FCE9D4554C3D2001EF3, BDCBEC01579D7CF28963E4E13CDC5B26E4B69CA24FA2CC4D6E24CAE0DDBCB3FE ] BRSptStub C:\ProgramData\BitRaider\BRSptStub.exe
14:57:13.0170 0x2ab8 BRSptStub - ok
14:57:13.0182 0x2ab8 BthAvrcpTg - ok
14:57:13.0208 0x2ab8 BthEnum - ok
14:57:13.0211 0x2ab8 BthHFEnum - ok
14:57:13.0213 0x2ab8 bthhfhid - ok
14:57:13.0227 0x2ab8 BthHFSrv - ok
14:57:13.0230 0x2ab8 BTHMODEM - ok
14:57:13.0235 0x2ab8 BthPan - ok
14:57:13.0243 0x2ab8 BTHPORT - ok
14:57:13.0245 0x2ab8 bthserv - ok
14:57:13.0264 0x2ab8 BTHUSB - ok
14:57:13.0267 0x2ab8 buttonconverter - ok
14:57:13.0269 0x2ab8 CapImg - ok
14:57:13.0271 0x2ab8 cdfs - ok
14:57:13.0285 0x2ab8 CDPSvc - ok
14:57:13.0300 0x2ab8 CDPUserSvc - ok
14:57:13.0322 0x2ab8 cdrom - ok
14:57:13.0334 0x2ab8 CertPropSvc - ok
14:57:13.0337 0x2ab8 cht4iscsi - ok
14:57:13.0339 0x2ab8 cht4vbd - ok
14:57:13.0342 0x2ab8 circlass - ok
14:57:13.0359 0x2ab8 CLFS - ok
14:57:13.0483 0x2ab8 [ ACFB2A62301C6A903FA6A97DB84E9C31, 7A3089812330B605D2F545374A1A916B6DBA188186EC88DA3348814A95C791F0 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
14:57:13.0565 0x2ab8 ClickToRunSvc - ok
14:57:13.0575 0x2ab8 ClipSVC - ok
14:57:13.0592 0x2ab8 clreg - ok
14:57:13.0598 0x2ab8 CmBatt - ok
14:57:13.0600 0x2ab8 CNG - ok
14:57:13.0602 0x2ab8 cnghwassist - ok
14:57:13.0657 0x2ab8 CompositeBus - ok
14:57:13.0659 0x2ab8 COMSysApp - ok
14:57:13.0662 0x2ab8 condrv - ok
14:57:13.0677 0x2ab8 CoreMessagingRegistrar - ok
14:57:13.0681 0x2ab8 CryptSvc - ok
14:57:13.0683 0x2ab8 dam - ok
14:57:13.0693 0x2ab8 DcomLaunch - ok
14:57:13.0705 0x2ab8 DcpSvc - ok
14:57:13.0719 0x2ab8 defragsvc - ok
14:57:13.0732 0x2ab8 DeviceAssociationService - ok
14:57:13.0734 0x2ab8 DeviceInstall - ok
14:57:13.0742 0x2ab8 DevQueryBroker - ok
14:57:13.0745 0x2ab8 Dfsc - ok
14:57:13.0762 0x2ab8 [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
14:57:13.0777 0x2ab8 dg_ssudbus - ok
14:57:13.0793 0x2ab8 Dhcp - ok
14:57:13.0830 0x2ab8 diagnosticshub.standardcollector.service - ok
14:57:13.0832 0x2ab8 disk - ok
14:57:13.0840 0x2ab8 DmEnrollmentSvc - ok
14:57:13.0844 0x2ab8 dmvsc - ok
14:57:13.0846 0x2ab8 dmwappushservice - ok
14:57:13.0859 0x2ab8 Dnscache - ok
14:57:13.0862 0x2ab8 dot3svc - ok
14:57:13.0864 0x2ab8 DPS - ok
14:57:13.0874 0x2ab8 drmkaud - ok
14:57:13.0877 0x2ab8 DsmSvc - ok
14:57:13.0878 0x2ab8 DsSvc - ok
14:57:13.0892 0x2ab8 DXGKrnl - ok
14:57:13.0895 0x2ab8 e1iexpress - ok
14:57:13.0897 0x2ab8 EapHost - ok
14:57:13.0899 0x2ab8 ebdrv - ok
14:57:13.0913 0x2ab8 EFS - ok
14:57:13.0915 0x2ab8 EhStorClass - ok
14:57:13.0923 0x2ab8 EhStorTcgDrv - ok
14:57:13.0933 0x2ab8 embeddedmode - ok
14:57:13.0943 0x2ab8 EntAppSvc - ok
14:57:13.0944 0x2ab8 ErrDev - ok
14:57:13.0948 0x2ab8 EventSystem - ok
14:57:13.0950 0x2ab8 exfat - ok
14:57:13.0953 0x2ab8 fastfat - ok
14:57:13.0965 0x2ab8 Fax - ok
14:57:13.0967 0x2ab8 fdc - ok
14:57:13.0969 0x2ab8 fdPHost - ok
14:57:13.0971 0x2ab8 FDResPub - ok
14:57:13.0985 0x2ab8 fhsvc - ok
14:57:13.0987 0x2ab8 FileCrypt - ok
14:57:13.0989 0x2ab8 FileInfo - ok
14:57:13.0991 0x2ab8 Filetrace - ok
14:57:13.0993 0x2ab8 flpydisk - ok
14:57:13.0996 0x2ab8 FltMgr - ok
14:57:14.0006 0x2ab8 FontCache - ok
14:57:14.0082 0x2ab8 FontCache3.0.0.0 - ok
14:57:14.0102 0x2ab8 FrameServer - ok
14:57:14.0104 0x2ab8 FsDepends - ok
14:57:14.0106 0x2ab8 Fs_Rec - ok
14:57:14.0109 0x2ab8 fvevol - ok
14:57:14.0157 0x2ab8 [ 11DD69E94F3B3F2614E88C5657011583, C87D588C3F6517F5ED42BB2512653E0D9860D98E043161686F3A4750F6ECBD40 ] GalaxyClientService D:\GalaxyClient\GalaxyClientService.exe
14:57:14.0207 0x2ab8 GalaxyClientService - ok
14:57:14.0394 0x2ab8 [ CB8157B535DA674CA6CBEBE7E3BD5268, 1028FDA5207E9CF412BB0B1F0B984FEFEE511EBF8BD353F392F7052B0021F531 ] GalaxyCommunication C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
14:57:14.0709 0x2ab8 GalaxyCommunication - ok
14:57:14.0733 0x2ab8 gencounter - ok
14:57:14.0736 0x2ab8 genericusbfn - ok
14:57:14.0738 0x2ab8 GPIOClx0101 - ok
14:57:14.0744 0x2ab8 gpsvc - ok
14:57:14.0746 0x2ab8 GpuEnergyDrv - ok
14:57:14.0784 0x2ab8 [ E1B44A75947137F4143308D566889837, EC7E883E7AF38BF3AC0AC513CFDE0186038443E9ACC7AD616EE6BD0EC09AACB9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
14:57:14.0819 0x2ab8 gupdate - ok
14:57:14.0822 0x2ab8 [ E1B44A75947137F4143308D566889837, EC7E883E7AF38BF3AC0AC513CFDE0186038443E9ACC7AD616EE6BD0EC09AACB9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
14:57:14.0855 0x2ab8 gupdatem - ok
14:57:14.0858 0x2ab8 HDAudBus - ok
14:57:14.0860 0x2ab8 HidBatt - ok
14:57:14.0862 0x2ab8 HidBth - ok
14:57:14.0865 0x2ab8 hidi2c - ok
14:57:14.0867 0x2ab8 hidinterrupt - ok
14:57:14.0870 0x2ab8 HidIr - ok
14:57:14.0872 0x2ab8 hidserv - ok
14:57:14.0874 0x2ab8 HidUsb - ok
14:57:14.0884 0x2ab8 HomeGroupListener - ok
14:57:14.0889 0x2ab8 HomeGroupProvider - ok
14:57:14.0891 0x2ab8 HpSAMD - ok
14:57:14.0893 0x2ab8 HTTP - ok
14:57:14.0919 0x2ab8 HvHost - ok
14:57:14.0926 0x2ab8 hvservice - ok
14:57:14.0928 0x2ab8 hwpolicy - ok
14:57:14.0930 0x2ab8 hyperkbd - ok
14:57:14.0947 0x2ab8 i8042prt - ok
14:57:14.0949 0x2ab8 iagpio - ok
14:57:14.0951 0x2ab8 iai2c - ok
14:57:14.0953 0x2ab8 iaLPSS2i_GPIO2 - ok
14:57:14.0955 0x2ab8 iaLPSS2i_I2C - ok
14:57:14.0957 0x2ab8 iaLPSSi_GPIO - ok
14:57:14.0960 0x2ab8 iaLPSSi_I2C - ok
14:57:14.0962 0x2ab8 iaStorAV - ok
14:57:14.0964 0x2ab8 iaStorV - ok
14:57:14.0967 0x2ab8 ibbus - ok
14:57:15.0002 0x2ab8 [ E199288F016C354255C39A84378A48F6, 881B41D64D73F7A3A1680EDD68201E14AC5C60B848374EEAE44CCDDE46010E81 ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
14:57:15.0028 0x2ab8 ICCS - ok
14:57:15.0051 0x2ab8 icssvc - ok
14:57:15.0053 0x2ab8 IKEEXT - ok
14:57:15.0055 0x2ab8 IndirectKmd - ok
14:57:15.0157 0x2ab8 [ 7F08B78B1516626869FB44A61EFDF566, C585902D4F6E36A44097C192CCF19F1947F99C86A7BB77E83C0BE475F0151161 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
14:57:15.0281 0x2ab8 IntcAzAudAddService - ok
14:57:15.0379 0x2ab8 [ DAE6C3099D291EED8922A65C29ABCF52, AD0A932345382824122F84AF97A8609BAE1B916A3B9FD608779A1411E37D3643 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
14:57:15.0453 0x2ab8 Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
14:57:16.0709 0x2ab8 Detect skipped due to KSN trusted
14:57:16.0709 0x2ab8 Intel(R) Capability Licensing Service Interface - ok
14:57:16.0732 0x2ab8 [ D45226E3E7A25F1E7CE8DF8FD0A2A098, 7BD74E9E3CB0A83D26BA3FD8177C6B9BA46A8695B6569CF7887FDC87947DA2D6 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
14:57:16.0764 0x2ab8 Intel(R) Capability Licensing Service TCP IP Interface - ok
14:57:16.0795 0x2ab8 [ DD73746062EAF2767EC84D995B50C977, FC06F843A400CDBC64ED2DC73A15DF4348D52D8D058A490E07363A8F4E9F6F7C ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
14:57:16.0814 0x2ab8 Intel(R) PROSet Monitoring Service - ok
14:57:16.0826 0x2ab8 intelide - ok
14:57:16.0829 0x2ab8 intelpep - ok
14:57:16.0831 0x2ab8 intelppm - ok
14:57:16.0844 0x2ab8 iorate - ok
14:57:16.0846 0x2ab8 IpFilterDriver - ok
14:57:16.0864 0x2ab8 iphlpsvc - ok
14:57:16.0867 0x2ab8 IPMIDRV - ok
14:57:16.0869 0x2ab8 IPNAT - ok
14:57:16.0871 0x2ab8 irda - ok
14:57:16.0873 0x2ab8 IRENUM - ok
14:57:16.0892 0x2ab8 irmon - ok
14:57:16.0894 0x2ab8 isapnp - ok
14:57:16.0896 0x2ab8 iScsiPrt - ok
14:57:16.0923 0x2ab8 [ 52069AEB42D3D0F97CBCA1085EBF55E6, ADB2EFFF563B3FE113FCD156FD1E469BC24FC1D68AFEDCA21306F76592C9FF88 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
14:57:16.0955 0x2ab8 jhi_service - ok
14:57:16.0962 0x2ab8 kbdclass - ok
14:57:16.0964 0x2ab8 kbdhid - ok
14:57:16.0981 0x2ab8 kdnic - ok
14:57:16.0983 0x2ab8 KeyIso - ok
14:57:16.0985 0x2ab8 KSecDD - ok
14:57:16.0987 0x2ab8 KSecPkg - ok
14:57:16.0989 0x2ab8 ksthunk - ok
14:57:17.0006 0x2ab8 KtmRm - ok
14:57:17.0018 0x2ab8 LanmanServer - ok
14:57:17.0034 0x2ab8 LanmanWorkstation - ok
14:57:17.0037 0x2ab8 lfsvc - ok
14:57:17.0041 0x2ab8 LicenseManager - ok
14:57:17.0044 0x2ab8 lltdio - ok
14:57:17.0046 0x2ab8 lltdsvc - ok
14:57:17.0048 0x2ab8 lmhosts - ok
14:57:17.0089 0x2ab8 [ 3DE66F47365AA8CEB18B1EE272F4FEBA, 8DDD6AB4AEDE3B2FEA0D3B63DD24E3F3422D6ADE067756A3919FCED53C349167 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
14:57:17.0183 0x2ab8 LMS - ok
14:57:17.0186 0x2ab8 LSI_SAS - ok
14:57:17.0188 0x2ab8 LSI_SAS2i - ok
14:57:17.0191 0x2ab8 LSI_SAS3i - ok
14:57:17.0193 0x2ab8 LSI_SSS - ok
14:57:17.0208 0x2ab8 LSM - ok
14:57:17.0211 0x2ab8 luafv - ok
14:57:17.0214 0x2ab8 MapsBroker - ok
14:57:17.0216 0x2ab8 megasas - ok
14:57:17.0230 0x2ab8 megasas2i - ok
14:57:17.0232 0x2ab8 megasr - ok
14:57:17.0251 0x2ab8 [ 1BC9159CF58BABD89419072EA180A8F6, 6C9AB779C2355A341800A8F93AAAF9B19FAFF444CD6A7BD27C63D53F379A75EF ] MEIx64 C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
14:57:17.0275 0x2ab8 MEIx64 - ok
14:57:17.0278 0x2ab8 MessagingService - ok
14:57:17.0298 0x2ab8 mlx4_bus - ok
14:57:17.0300 0x2ab8 MMCSS - ok
14:57:17.0302 0x2ab8 Modem - ok
14:57:17.0316 0x2ab8 monitor - ok
14:57:17.0318 0x2ab8 mouclass - ok
14:57:17.0320 0x2ab8 mouhid - ok
14:57:17.0322 0x2ab8 mountmgr - ok
14:57:17.0325 0x2ab8 mpsdrv - ok
14:57:17.0327 0x2ab8 MpsSvc - ok
14:57:17.0352 0x2ab8 MRxDAV - ok
14:57:17.0354 0x2ab8 mrxsmb - ok
14:57:17.0356 0x2ab8 mrxsmb10 - ok
14:57:17.0359 0x2ab8 mrxsmb20 - ok
14:57:17.0374 0x2ab8 MsBridge - ok
14:57:17.0384 0x2ab8 MSDTC - ok
14:57:17.0388 0x2ab8 Msfs - ok
14:57:17.0399 0x2ab8 msgpiowin32 - ok
14:57:17.0402 0x2ab8 mshidkmdf - ok
14:57:17.0404 0x2ab8 mshidumdf - ok
14:57:17.0406 0x2ab8 msisadrv - ok
14:57:17.0420 0x2ab8 MSiSCSI - ok
14:57:17.0422 0x2ab8 msiserver - ok
14:57:17.0424 0x2ab8 MSKSSRV - ok
14:57:17.0427 0x2ab8 MsLldp - ok
14:57:17.0429 0x2ab8 MSPCLOCK - ok
14:57:17.0431 0x2ab8 MSPQM - ok
14:57:17.0433 0x2ab8 MsRPC - ok
14:57:17.0436 0x2ab8 mssmbios - ok
14:57:17.0438 0x2ab8 MSTEE - ok
14:57:17.0440 0x2ab8 MTConfig - ok
14:57:17.0442 0x2ab8 Mup - ok
14:57:17.0445 0x2ab8 mvumis - ok
14:57:17.0457 0x2ab8 NativeWifiP - ok
14:57:17.0460 0x2ab8 NcaSvc - ok
14:57:17.0467 0x2ab8 NcbService - ok
14:57:17.0469 0x2ab8 NcdAutoSetup - ok
14:57:17.0472 0x2ab8 ndfltr - ok
14:57:17.0476 0x2ab8 NDIS - ok
14:57:17.0478 0x2ab8 NdisCap - ok
14:57:17.0496 0x2ab8 NdisImPlatform - ok
14:57:17.0498 0x2ab8 NdisTapi - ok
14:57:17.0500 0x2ab8 Ndisuio - ok
14:57:17.0502 0x2ab8 NdisVirtualBus - ok
14:57:17.0504 0x2ab8 NdisWan - ok
14:57:17.0507 0x2ab8 ndiswanlegacy - ok
14:57:17.0509 0x2ab8 ndproxy - ok
14:57:17.0511 0x2ab8 Ndu - ok
14:57:17.0588 0x2ab8 [ B90E093E7A7250906F1054418B5339C0, F9A0BAC5B4B29F14B5CACA1047F8928A495EFD56E485492BF71C856B296476D6 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
14:57:17.0636 0x2ab8 Nero BackItUp Scheduler 4.0 - ok
14:57:17.0639 0x2ab8 NetAdapterCx - ok
14:57:17.0641 0x2ab8 NetBIOS - ok
14:57:17.0645 0x2ab8 NetBT - ok
14:57:17.0647 0x2ab8 Netlogon - ok
14:57:17.0657 0x2ab8 Netman - ok
14:57:17.0660 0x2ab8 netprofm - ok
14:57:17.0667 0x2ab8 netr28ux - ok
14:57:17.0673 0x2ab8 NetSetupSvc - ok
14:57:17.0691 0x2ab8 NetTcpPortSharing - ok
14:57:17.0701 0x2ab8 NgcCtnrSvc - ok
14:57:17.0703 0x2ab8 NgcSvc - ok
14:57:17.0712 0x2ab8 NlaSvc - ok
14:57:17.0714 0x2ab8 Npfs - ok
14:57:17.0716 0x2ab8 npsvctrig - ok
14:57:17.0718 0x2ab8 nsi - ok
14:57:17.0720 0x2ab8 nsiproxy - ok
14:57:17.0732 0x2ab8 NTFS - ok
14:57:17.0734 0x2ab8 Null - ok
14:57:17.0768 0x2ab8 [ C93013BBB38330C73285547174F8FEE1, 2CCC8B1A868098EBEACF4D4E178002D382E9BB28CC0D57D76E0813C56DB1BC98 ] NvContainerLocalSystem C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
14:57:17.0787 0x2ab8 NvContainerLocalSystem - ok
14:57:17.0818 0x2ab8 [ C93013BBB38330C73285547174F8FEE1, 2CCC8B1A868098EBEACF4D4E178002D382E9BB28CC0D57D76E0813C56DB1BC98 ] NvContainerNetworkService C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
14:57:17.0837 0x2ab8 NvContainerNetworkService - ok
14:57:17.0852 0x2ab8 [ 64DA1993B1973F049C1347DA1B05185E, 2A04E263DB13751D033E2F9B9518820CF4942EEAFA5A32488570EEB699EE2A96 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
14:57:17.0866 0x2ab8 NVHDA - ok
14:57:17.0891 0x2ab8 NVIDIA Wireless Controller Service - ok
14:57:18.0239 0x2ab8 [ 557A0393BDFED327968A9E695FB4CEBA, 76D39F74439205B5B614B0D99E9E10629738E00250A5E7FFEE50815F69EE70D0 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_3f929cc119e3b994\nvlddmkm.sys
14:57:18.0674 0x2ab8 nvlddmkm - ok
14:57:18.0688 0x2ab8 nvraid - ok
14:57:18.0690 0x2ab8 nvstor - ok
14:57:18.0723 0x2ab8 [ 4F75E1292E95EBFAD3A0CABB0972F7B8, E4E3AC25AFA4949765F75777769310CB6200A5F537F56205960B40775282FEC0 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
14:57:18.0733 0x2ab8 NvStreamKms - ok
14:57:18.0795 0x2ab8 [ 4D205C0A3C0118D41361F945F337977E, DBEF90119B68EEC7FECBF73D64A0AD63401237048B104B4570E7CEC5D2F38E3A ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
14:57:18.0899 0x2ab8 NvTelemetryContainer - ok
14:57:18.0921 0x2ab8 [ 54ABC4EA39DDE92977DCE644D325213A, D754E5D0418B3C48AD9988D1A2705975C78C8B87990E211651C388A76FB17E51 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
14:57:18.0932 0x2ab8 nvvad_WaveExtensible - ok
14:57:18.0938 0x2ab8 [ B6704EE5A17116F0723014F0C3DA1954, 2319837173981DCC818E433AAE87A2BA7C90EAE43C6C218C18AD8353C4162114 ] nvvhci C:\WINDOWS\System32\drivers\nvvhci.sys
14:57:18.0949 0x2ab8 nvvhci - ok
14:57:18.0974 0x2ab8 OneSyncSvc - ok
14:57:19.0053 0x2ab8 [ AD851D818F399DD946A9C17AB2156F22, 4A541E7A3A3164581BFB9080DE0976E18F6DD00E39458EBBCBD3B2445708BEB5 ] Origin Client Service D:\Origin\OriginClientService.exe
14:57:19.0176 0x2ab8 Origin Client Service - ok
14:57:19.0227 0x2ab8 [ 788363C87EBD90AC1EAD2DC5A9A40759, B565663B459414C5C9F81451D9A127D62CDF605BC2A9E686F74A2E4FD44A9B43 ] Origin Web Helper Service D:\Origin\OriginWebHelperService.exe
14:57:19.0341 0x2ab8 Origin Web Helper Service - ok
14:57:19.0394 0x2ab8 [ AC0F1B7B71D9D435EC33456F7EDF6FF1, 8FEFF5F99F1AFF21CF9415D4BF26936EF3A7347DA06F30ADD1DD1B14916F2585 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
14:57:19.0445 0x2ab8 ose - ok
14:57:19.0461 0x2ab8 p2pimsvc - ok
14:57:19.0468 0x2ab8 p2psvc - ok
14:57:19.0470 0x2ab8 Parport - ok
14:57:19.0478 0x2ab8 partmgr - ok
14:57:19.0500 0x2ab8 PcaSvc - ok
14:57:19.0512 0x2ab8 pci - ok
14:57:19.0515 0x2ab8 pciide - ok
14:57:19.0517 0x2ab8 pcmcia - ok
14:57:19.0519 0x2ab8 pcw - ok
14:57:19.0524 0x2ab8 pdc - ok
14:57:19.0533 0x2ab8 PEAUTH - ok
14:57:19.0535 0x2ab8 percsas2i - ok
14:57:19.0537 0x2ab8 percsas3i - ok
14:57:19.0584 0x2ab8 PerfHost - ok
14:57:19.0629 0x2ab8 PhoneSvc - ok
14:57:19.0634 0x2ab8 PimIndexMaintenanceSvc - ok
14:57:19.0645 0x2ab8 pla - ok
14:57:19.0652 0x2ab8 PlugPlay - ok
14:57:19.0654 0x2ab8 PnkBstrA - ok
14:57:19.0657 0x2ab8 PNRPAutoReg - ok
14:57:19.0659 0x2ab8 PNRPsvc - ok
14:57:19.0665 0x2ab8 PolicyAgent - ok
14:57:19.0668 0x2ab8 Power - ok
14:57:19.0670 0x2ab8 PptpMiniport - ok
14:57:19.0771 0x2ab8 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
14:57:19.0947 0x2ab8 PrintNotify - ok
14:57:19.0952 0x2ab8 Processor - ok
14:57:19.0964 0x2ab8 ProfSvc - ok
14:57:19.0966 0x2ab8 Psched - ok
14:57:19.0969 0x2ab8 QWAVE - ok
14:57:19.0971 0x2ab8 QWAVEdrv - ok
14:57:19.0973 0x2ab8 RasAcd - ok
14:57:20.0004 0x2ab8 RasAgileVpn - ok
14:57:20.0017 0x2ab8 RasAuto - ok
14:57:20.0019 0x2ab8 Rasl2tp - ok
14:57:20.0031 0x2ab8 RasMan - ok
14:57:20.0034 0x2ab8 RasPppoe - ok
14:57:20.0036 0x2ab8 RasSstp - ok
14:57:20.0038 0x2ab8 rdbss - ok
14:57:20.0056 0x2ab8 rdpbus - ok
14:57:20.0059 0x2ab8 RDPDR - ok
14:57:20.0082 0x2ab8 RdpVideoMiniport - ok
14:57:20.0085 0x2ab8 rdyboost - ok
14:57:20.0087 0x2ab8 ReFSv1 - ok
14:57:20.0089 0x2ab8 RemoteAccess - ok
14:57:20.0116 0x2ab8 [ 10E4D1F67A369A3F6E9CE00AC4A43BE0, D41D7DD9CBFB718AFE94883AE8E79832D4DA3321878BEAB81F4382DC1DFAB8A7 ] RemoteMouseService C:\Program Files (x86)\Remote Mouse\RemoteMouseService.exe
14:57:20.0166 0x2ab8 RemoteMouseService - detected UnsignedFile.Multi.Generic ( 1 )
14:57:20.0429 0x2ab8 Detect skipped due to KSN trusted
14:57:20.0429 0x2ab8 RemoteMouseService - ok
14:57:20.0432 0x2ab8 RemoteRegistry - ok
14:57:20.0452 0x2ab8 RetailDemo - ok
14:57:20.0458 0x2ab8 RFCOMM - ok
14:57:20.0460 0x2ab8 RmSvc - ok
14:57:20.0463 0x2ab8 RpcEptMapper - ok
14:57:20.0474 0x2ab8 RpcLocator - ok
14:57:20.0477 0x2ab8 RpcSs - ok
14:57:20.0479 0x2ab8 rspndr - ok
14:57:20.0483 0x2ab8 s3cap - ok
14:57:20.0489 0x2ab8 SamSs - ok
14:57:20.0557 0x2ab8 [ D324EC7BE1510CE7171B06B8FA7FEDE1, 6C85F8F18C68ADA7C4A55E31F6FE66DF47B7E77B1D2AC7197938B8706FB914D2 ] SAVAdminService C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
14:57:20.0595 0x2ab8 SAVAdminService - ok
14:57:20.0614 0x2ab8 [ 3B3437CBEADB5950665A037E9EE7AAF6, FFC568472B688EE6A3C40ED3EF40F100ECA76667D67A4E94D004888485CDFCE9 ] SAVOnAccess C:\WINDOWS\system32\DRIVERS\savonaccess.sys
14:57:20.0629 0x2ab8 SAVOnAccess - ok
14:57:20.0639 0x2ab8 [ CBD4FC747036459BA52C67BC0EFF92C2, C412999413AC096B7FE48C08FC3E1EE76CE00742B98AFB98EF7E1626889E560F ] SAVService C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
14:57:20.0668 0x2ab8 SAVService - ok
14:57:20.0671 0x2ab8 sbp2port - ok
14:57:20.0678 0x2ab8 SCardSvr - ok
14:57:20.0698 0x2ab8 ScDeviceEnum - ok
14:57:20.0700 0x2ab8 scfilter - ok
14:57:20.0703 0x2ab8 Schedule - ok
14:57:20.0705 0x2ab8 scmbus - ok
14:57:20.0707 0x2ab8 scmdisk0101 - ok
14:57:20.0718 0x2ab8 SCPolicySvc - ok
14:57:20.0734 0x2ab8 sdbus - ok
14:57:20.0748 0x2ab8 [ 75B98959013B22F8F40C08095B8AB73C, EF608EFBF72AF48EFC9352FCEDF0523BDBA6055612FFD22654E3B241AA9C8033 ] sdcfilter C:\WINDOWS\system32\DRIVERS\sdcfilter.sys
14:57:20.0759 0x2ab8 sdcfilter - ok
14:57:20.0762 0x2ab8 SDRSVC - ok
14:57:20.0765 0x2ab8 sdstor - ok
14:57:20.0767 0x2ab8 seclogon - ok
14:57:20.0785 0x2ab8 SENS - ok
14:57:20.0788 0x2ab8 SensorDataService - ok
14:57:20.0791 0x2ab8 SensorService - ok
14:57:20.0794 0x2ab8 SensrSvc - ok
14:57:20.0796 0x2ab8 SerCx - ok
14:57:20.0798 0x2ab8 SerCx2 - ok
14:57:20.0801 0x2ab8 Serenum - ok
14:57:20.0804 0x2ab8 Serial - ok
14:57:20.0807 0x2ab8 sermouse - ok
14:57:20.0815 0x2ab8 SessionEnv - ok
14:57:20.0817 0x2ab8 sfloppy - ok
14:57:20.0834 0x2ab8 SharedAccess - ok
14:57:20.0844 0x2ab8 ShellHWDetection - ok
14:57:20.0866 0x2ab8 shpamsvc - ok
14:57:20.0869 0x2ab8 SiSRaid2 - ok
14:57:20.0871 0x2ab8 SiSRaid4 - ok
14:57:20.0895 0x2ab8 [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
14:57:20.0931 0x2ab8 SkypeUpdate - ok
14:57:20.0934 0x2ab8 smphost - ok
14:57:20.0953 0x2ab8 SmsRouter - ok
14:57:20.0958 0x2ab8 SNMPTRAP - ok
14:57:20.0995 0x2ab8 [ C051B67548BBAFA9101B695C8C1F2F08, FFDE14BC6A7116A93CC2FACBC1BDE42CEE44CD0630BCB1AA856C22134DCBCB9F ] Sophos AutoUpdate Service C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
14:57:21.0063 0x2ab8 Sophos AutoUpdate Service - ok
14:57:21.0124 0x2ab8 [ 91C1C6631962C8D3A6CABFB901BFB607, C69053A07164C936C1FA30E17025AEE43F0CB0CC2ED0954CECB6E81C84F9669D ] Sophos MCS Agent C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe
14:57:21.0292 0x2ab8 Sophos MCS Agent - ok
14:57:21.0327 0x2ab8 [ 7A9AF7DE7A3C9A12B7A0129B9CD00523, 76863318F6D9BFBD8DD7E59F341F9D961C4715B83C325D8E6E098527767F337F ] Sophos MCS Client C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe
14:57:21.0527 0x2ab8 Sophos MCS Client - ok
14:57:21.0549 0x2ab8 [ 5861A2F04500F404AAC57CF323E3090C, 912FA7663573D044F57CDA29A122393E6E7BD6B90C8CBD2642DD6C6E105D34F9 ] Sophos Web Control Service C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
14:57:21.0602 0x2ab8 Sophos Web Control Service - ok
14:57:21.0615 0x2ab8 [ FFD056D55C46946ACA218F0A61DA2743, A9E3910EBEFC8674704F42C6D43A12A521C212B911D46FCD669D8AAFA8381C55 ] SophosBootDriver C:\WINDOWS\system32\DRIVERS\SophosBootDriver.sys
14:57:21.0626 0x2ab8 SophosBootDriver - ok
14:57:21.0682 0x2ab8 [ 410506D87F07AF40880BE50262C2D6C4, 7E8195A2028AD577C4E934AEDC1C296EAE06EDEB904EFA00A83B7E7D4D2F9361 ] SophosDataRecorderService C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe
14:57:21.0712 0x2ab8 SophosDataRecorderService - ok
14:57:21.0816 0x2ab8 [ C07BB5FFB85E64DF1AB67E17188DF22F, 322FD46C8694BA5DE88CCACFD8364F8A3397AA02C9FD5644333AE3D3BECA4ABB ] sophossps C:\Program Files\Sophos\Sophos System Protection\ssp.exe
14:57:21.0939 0x2ab8 sophossps - ok
14:57:21.0960 0x2ab8 spaceport - ok
14:57:21.0963 0x2ab8 SpbCx - ok
14:57:21.0965 0x2ab8 Spooler - ok
14:57:21.0967 0x2ab8 sppsvc - ok
14:57:21.0984 0x2ab8 srv - ok
14:57:21.0992 0x2ab8 srv2 - ok
14:57:21.0994 0x2ab8 srvnet - ok
14:57:22.0001 0x2ab8 SSDPSRV - ok
14:57:22.0003 0x2ab8 SstpSvc - ok
14:57:22.0035 0x2ab8 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
14:57:22.0049 0x2ab8 ssudmdm - ok
14:57:22.0058 0x2ab8 StateRepository - ok
14:57:22.0137 0x2ab8 [ 9867A86327E8AE3806305F1BCF01211A, CCDDB2560B30D27CE662F1B02710E1FAA9331E6A27D9A6629EEDED2CBA822062 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
14:57:22.0204 0x2ab8 Steam Client Service - ok
14:57:22.0208 0x2ab8 stexstor - ok
14:57:22.0230 0x2ab8 [ B11724BFE7DA1BA55903B4D849415F1A, ED09B6AD68C87FED34FC66CB6C7A74DFC3AF524E3BE89EDD18A5B6685F656ACA ] StillCam C:\WINDOWS\system32\DRIVERS\serscan.sys
14:57:22.0320 0x2ab8 StillCam - ok
14:57:22.0336 0x2ab8 stisvc - ok
14:57:22.0345 0x2ab8 storahci - ok
14:57:22.0347 0x2ab8 storflt - ok
14:57:22.0351 0x2ab8 stornvme - ok
14:57:22.0353 0x2ab8 storqosflt - ok
14:57:22.0356 0x2ab8 StorSvc - ok
14:57:22.0359 0x2ab8 storufs - ok
14:57:22.0362 0x2ab8 storvsc - ok
14:57:22.0365 0x2ab8 svsvc - ok
14:57:22.0367 0x2ab8 swenum - ok
14:57:22.0396 0x2ab8 [ C60F83AC3A812324892B4E740F8C6E68, 5E54B92CE641458F649E8EB29752C38760CB2BAE7FBFBE921403CD31D81F9CDB ] swi_callout C:\WINDOWS\system32\DRIVERS\swi_callout.sys
14:57:22.0407 0x2ab8 swi_callout - ok
14:57:22.0423 0x2ab8 [ BE992FA01303BF02506D65511D308FC2, 5B37DEE85A6A4C1EFCC1CDBDFDE3366DDEF0D40B70105FCCBA816AE64377F73D ] swi_filter C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_filter.exe
14:57:22.0585 0x2ab8 swi_filter - ok
14:57:22.0655 0x2ab8 [ DD8D59364AF34D7CDD562D5EA92DCF4D, 8C252E59D8ECF395807A9E801CF4393C70DE25BEF9CE80FDF4CE000C94852CFF ] swi_service C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
14:57:22.0761 0x2ab8 swi_service - ok
14:57:22.0767 0x2ab8 swprv - ok
14:57:22.0791 0x2ab8 Synth3dVsc - ok
14:57:22.0793 0x2ab8 SysMain - ok
14:57:22.0811 0x2ab8 SystemEventsBroker - ok
14:57:22.0833 0x2ab8 TabletInputService - ok
14:57:22.0836 0x2ab8 TapiSrv - ok
14:57:22.0838 0x2ab8 Tcpip - ok
14:57:22.0841 0x2ab8 Tcpip6 - ok
14:57:22.0850 0x2ab8 tcpipreg - ok
14:57:22.0854 0x2ab8 tdx - ok
14:57:22.0979 0x2ab8 [ 2AA61246A5B813C1B12BCCFAA6F23DD8, 74EE3DB839A0F4BC781294803281DB2248D013B8808FF05F2EE9597C14C6FEED ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
14:57:23.0448 0x2ab8 TeamViewer - ok
14:57:23.0455 0x2ab8 terminpt - ok
14:57:23.0458 0x2ab8 TermService - ok
14:57:23.0476 0x2ab8 Themes - ok
14:57:23.0484 0x2ab8 TieringEngineService - ok
14:57:23.0486 0x2ab8 tiledatamodelsvc - ok
14:57:23.0489 0x2ab8 TimeBrokerSvc - ok
14:57:23.0492 0x2ab8 TPM - ok
14:57:23.0495 0x2ab8 TrkWks - ok
14:57:23.0522 0x2ab8 TrustedInstaller - ok
14:57:23.0526 0x2ab8 tsusbflt - ok
14:57:23.0530 0x2ab8 TsUsbGD - ok
14:57:23.0532 0x2ab8 tunnel - ok
14:57:23.0535 0x2ab8 tzautoupdate - ok
14:57:23.0538 0x2ab8 UASPStor - ok
14:57:23.0541 0x2ab8 UcmCx0101 - ok
14:57:23.0544 0x2ab8 UcmTcpciCx0101 - ok
14:57:23.0546 0x2ab8 UcmUcsi - ok
14:57:23.0549 0x2ab8 Ucx01000 - ok
14:57:23.0552 0x2ab8 UdeCx - ok
14:57:23.0554 0x2ab8 udfs - ok
14:57:23.0557 0x2ab8 UEFI - ok
14:57:23.0560 0x2ab8 Ufx01000 - ok
14:57:23.0562 0x2ab8 UfxChipidea - ok
14:57:23.0565 0x2ab8 ufxsynopsys - ok
14:57:23.0570 0x2ab8 UI0Detect - ok
14:57:23.0572 0x2ab8 umbus - ok
14:57:23.0575 0x2ab8 UmPass - ok
14:57:23.0578 0x2ab8 UmRdpService - ok
14:57:23.0581 0x2ab8 UnistoreSvc - ok
14:57:23.0591 0x2ab8 upnphost - ok
14:57:23.0593 0x2ab8 UrsChipidea - ok
14:57:23.0596 0x2ab8 UrsCx01000 - ok
14:57:23.0598 0x2ab8 UrsSynopsys - ok
14:57:23.0684 0x2ab8 [ 2F8AB74A6BB3040F4972F77F4B4EF623, 3EE892530419759B6A9A0A27B6EE9771820941B5B0C2A78A6E2606F6C8779ED4 ] USBADVAU C:\WINDOWS\system32\drivers\cm11264.sys
14:57:23.0877 0x2ab8 USBADVAU - ok
14:57:23.0883 0x2ab8 usbccgp - ok
14:57:23.0886 0x2ab8 usbcir - ok
14:57:23.0888 0x2ab8 usbehci - ok
14:57:23.0891 0x2ab8 usbhub - ok
14:57:23.0895 0x2ab8 USBHUB3 - ok
14:57:23.0897 0x2ab8 usbohci - ok
14:57:23.0900 0x2ab8 usbprint - ok
14:57:23.0902 0x2ab8 usbser - ok
14:57:23.0905 0x2ab8 USBSTOR - ok
14:57:23.0908 0x2ab8 usbuhci - ok
14:57:23.0911 0x2ab8 USBXHCI - ok
14:57:23.0914 0x2ab8 UserDataSvc - ok
14:57:23.0928 0x2ab8 UserManager - ok
14:57:23.0938 0x2ab8 UsoSvc - ok
14:57:23.0947 0x2ab8 VaultSvc - ok
14:57:23.0950 0x2ab8 vdrvroot - ok
14:57:23.0964 0x2ab8 vds - ok
14:57:23.0966 0x2ab8 VerifierExt - ok
14:57:23.0981 0x2ab8 [ E4DA1D85CCCB610DFF0C0E116900E17F, 874EB88B9E2743654094F04AB04C254BBDFBCDECBB200514E73F696098B847F3 ] vflt C:\WINDOWS\system32\DRIVERS\vfilter.sys
14:57:24.0022 0x2ab8 vflt - detected UnsignedFile.Multi.Generic ( 1 )
14:57:24.0182 0x2ab8 Detect skipped due to KSN trusted
14:57:24.0182 0x2ab8 vflt - ok
14:57:24.0185 0x2ab8 vhdmp - ok
14:57:24.0187 0x2ab8 vhf - ok
14:57:24.0190 0x2ab8 vmbus - ok
14:57:24.0193 0x2ab8 VMBusHID - ok
14:57:24.0196 0x2ab8 vmgid - ok
14:57:24.0199 0x2ab8 vmicguestinterface - ok
14:57:24.0202 0x2ab8 vmicheartbeat - ok
14:57:24.0205 0x2ab8 vmickvpexchange - ok
14:57:24.0207 0x2ab8 vmicrdv - ok
14:57:24.0210 0x2ab8 vmicshutdown - ok
14:57:24.0213 0x2ab8 vmictimesync - ok
14:57:24.0215 0x2ab8 vmicvmsession - ok
14:57:24.0218 0x2ab8 vmicvss - ok
14:57:24.0235 0x2ab8 [ A99CA064AD11266FE7067A79BF78BBB5, B5AFFBA1A9A6E51639A89B9F6C0678E70F73D2BF37D5F88F4AD45DFC6798597D ] vnet C:\WINDOWS\System32\drivers\virtualnet.sys
14:57:24.0265 0x2ab8 vnet - detected UnsignedFile.Multi.Generic ( 1 )
14:57:24.0796 0x2ab8 Detect skipped due to KSN trusted
14:57:24.0796 0x2ab8 vnet - ok
14:57:24.0799 0x2ab8 volmgr - ok
14:57:24.0801 0x2ab8 volmgrx - ok
14:57:24.0804 0x2ab8 volsnap - ok
14:57:24.0806 0x2ab8 volume - ok
14:57:24.0809 0x2ab8 vpci - ok
14:57:24.0849 0x2ab8 [ 0AC0A4E541EFB67A3D9FDEDEC54481E8, 959F42383AFCED701692AA47478EBF3ECF9E01C733D0442A4D6718FEC98E2E78 ] vpnagent C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
14:57:24.0886 0x2ab8 vpnagent - ok
14:57:24.0910 0x2ab8 [ 0F42C39016F82F345C0F2DB2D5B90EB4, 2E957E72BB8D0293F61FA7385BA9400DF7759E1E3D35FE24F3877A6460988F4D ] vpnva C:\WINDOWS\System32\drivers\vpnva64-6.sys
14:57:24.0930 0x2ab8 vpnva - ok
14:57:24.0932 0x2ab8 vsmraid - ok
14:57:24.0935 0x2ab8 VSS - ok
14:57:24.0938 0x2ab8 VSTXRAID - ok
14:57:24.0940 0x2ab8 vwifibus - ok
14:57:24.0943 0x2ab8 vwififlt - ok
14:57:24.0946 0x2ab8 vwifimp - ok
14:57:24.0962 0x2ab8 W32Time - ok
14:57:24.0964 0x2ab8 WacomPen - ok
14:57:24.0967 0x2ab8 WalletService - ok
14:57:24.0970 0x2ab8 wanarp - ok
14:57:24.0972 0x2ab8 wanarpv6 - ok
14:57:24.0975 0x2ab8 wbengine - ok
14:57:24.0990 0x2ab8 WbioSrvc - ok
14:57:24.0994 0x2ab8 wcifs - ok
14:57:24.0996 0x2ab8 Wcmsvc - ok
14:57:24.0999 0x2ab8 wcncsvc - ok
14:57:25.0001 0x2ab8 wcnfs - ok
14:57:25.0004 0x2ab8 WdBoot - ok
14:57:25.0007 0x2ab8 Wdf01000 - ok
14:57:25.0010 0x2ab8 WdFilter - ok
14:57:25.0013 0x2ab8 WdiServiceHost - ok
14:57:25.0016 0x2ab8 WdiSystemHost - ok
14:57:25.0019 0x2ab8 wdiwifi - ok
14:57:25.0021 0x2ab8 WdNisDrv - ok
14:57:25.0029 0x2ab8 WdNisSvc - ok
14:57:25.0032 0x2ab8 WebClient - ok
14:57:25.0035 0x2ab8 Wecsvc - ok
14:57:25.0053 0x2ab8 WEPHOSTSVC - ok
14:57:25.0056 0x2ab8 wercplsupport - ok
14:57:25.0059 0x2ab8 WerSvc - ok
14:57:25.0062 0x2ab8 WFPLWFS - ok
14:57:25.0065 0x2ab8 WiaRpc - ok
14:57:25.0068 0x2ab8 WIMMount - ok
14:57:25.0070 0x2ab8 WinDefend - ok
14:57:25.0077 0x2ab8 WindowsTrustedRT - ok
14:57:25.0080 0x2ab8 WindowsTrustedRTProxy - ok
14:57:25.0095 0x2ab8 WinHttpAutoProxySvc - ok
14:57:25.0098 0x2ab8 WinMad - ok
14:57:25.0128 0x2ab8 Winmgmt - ok
14:57:25.0157 0x2ab8 WinRM - ok
14:57:25.0163 0x2ab8 WINUSB - ok
14:57:25.0166 0x2ab8 WinVerbs - ok
14:57:25.0201 0x2ab8 wisvc - ok
14:57:25.0204 0x2ab8 WlanSvc - ok
14:57:25.0231 0x2ab8 wlidsvc - ok
14:57:25.0234 0x2ab8 WmiAcpi - ok
14:57:25.0239 0x2ab8 wmiApSrv - ok
14:57:25.0250 0x2ab8 WMPNetworkSvc - ok
14:57:25.0258 0x2ab8 Wof - ok
14:57:25.0283 0x2ab8 workfolderssvc - ok
14:57:25.0286 0x2ab8 WPDBusEnum - ok
14:57:25.0289 0x2ab8 WpdUpFltr - ok
14:57:25.0292 0x2ab8 WpnService - ok
14:57:25.0295 0x2ab8 WpnUserService - ok
14:57:25.0312 0x2ab8 ws2ifsl - ok
14:57:25.0327 0x2ab8 wscsvc - ok
14:57:25.0330 0x2ab8 WSDPrintDevice - ok
14:57:25.0334 0x2ab8 WSDScan - ok
14:57:25.0337 0x2ab8 WSearch - ok
14:57:25.0351 0x2ab8 wuauserv - ok
14:57:25.0353 0x2ab8 WudfPf - ok
14:57:25.0357 0x2ab8 WUDFRd - ok
14:57:25.0360 0x2ab8 wudfsvc - ok
14:57:25.0363 0x2ab8 WUDFWpdFs - ok
14:57:25.0366 0x2ab8 WUDFWpdMtp - ok
14:57:25.0384 0x2ab8 WwanSvc - ok
14:57:25.0387 0x2ab8 XblAuthManager - ok
14:57:25.0399 0x2ab8 XblGameSave - ok
14:57:25.0402 0x2ab8 xboxgip - ok
14:57:25.0406 0x2ab8 XboxNetApiSvc - ok
14:57:25.0423 0x2ab8 xinputhid - ok
14:57:25.0438 0x2ab8 xusb22 - ok
14:57:25.0439 0x2ab8 ================ Scan global ===============================
14:57:25.0478 0x2ab8 [ Global ] - ok
14:57:25.0478 0x2ab8 ================ Scan MBR ==================================
14:57:25.0511 0x2ab8 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
14:57:25.0586 0x2ab8 \Device\Harddisk0\DR0 - ok
14:57:25.0586 0x2ab8 ================ Scan VBR ==================================
14:57:25.0588 0x2ab8 [ E53244C8EE35D6DDE71F4F149BE02A30 ] \Device\Harddisk0\DR0\Partition1
14:57:25.0589 0x2ab8 \Device\Harddisk0\DR0\Partition1 - ok
14:57:25.0614 0x2ab8 [ 487927010857CE87D8C677812E73775B ] \Device\Harddisk0\DR0\Partition2
14:57:25.0615 0x2ab8 \Device\Harddisk0\DR0\Partition2 - ok
14:57:25.0626 0x2ab8 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
14:57:25.0626 0x2ab8 \Device\Harddisk0\DR0\Partition3 - ok
14:57:25.0637 0x2ab8 [ A2E1B881262A7E742A93F8B8C6EA524C ] \Device\Harddisk0\DR0\Partition4
14:57:25.0639 0x2ab8 \Device\Harddisk0\DR0\Partition4 - ok
14:57:25.0657 0x2ab8 [ DC90FFAE35040E47C043D2F2017C5BC7 ] \Device\Harddisk0\DR0\Partition5
14:57:25.0658 0x2ab8 \Device\Harddisk0\DR0\Partition5 - ok
14:57:25.0685 0x2ab8 [ 927FAED4DE249BB2F06C294F6C65477C ] \Device\Harddisk0\DR0\Partition6
14:57:25.0686 0x2ab8 \Device\Harddisk0\DR0\Partition6 - ok
14:57:25.0686 0x2ab8 ================ Scan generic autorun ======================
14:57:25.0996 0x2ab8 [ 4878D4D36D683EBE2F1E5F83C6A3BDB3, 82DA7BFED5F61DF4B679B06339E4065CCE0DA0D6741287F93A2EF1BCC85AB1E1 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
14:57:26.0268 0x2ab8 RTHDVCPL - ok
14:57:26.0305 0x2ab8 [ F7ED64C9765A92B65F2E1868CFF7431A, 5EEFDB3B2C8CEF2C96BF39DE3E527D7D59845250B3861F6D42D7CC3CDA7C6769 ] C:\WINDOWS\System\3DG4me.exe
14:57:26.0473 0x2ab8 3DG4me - detected UnsignedFile.Multi.Generic ( 1 )
14:57:26.0682 0x2ab8 3DG4me ( UnsignedFile.Multi.Generic ) - warning
14:57:26.0789 0x2ab8 ShadowPlay - ok
14:57:26.0847 0x2ab8 [ 793D7221E5EC69EA615349A13B702B8C, 1545C9634A6599FE4B35419B1B40932797FE2E7DF0B5F27D6698810CC075CF86 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
14:57:27.0049 0x2ab8 SunJavaUpdateSched - ok
14:57:27.0082 0x2ab8 [ CD0362AEE36CFE1EF5DF973230742E67, 9F1D8AD4E09D16C39CD6A35CB298456468C1808226FFA8AD65BF9562A6ECC07D ] C:\Program Files (x86)\PDF24\pdf24.exe
14:57:27.0124 0x2ab8 PDFPrint - ok
14:57:27.0201 0x2ab8 [ D1AC7398ACC4B9EEA26758124ABB1C43, 4CA3C434A985450C9D2628ECE033734323431996CA0C483955FE44B596A1FE0D ] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
14:57:27.0249 0x2ab8 Sophos AutoUpdate Monitor - ok
14:57:27.0288 0x2ab8 [ 75A272C58A549AB33B5960B729C2BCF6, 089C5912B75747128E1C0D03AD91D2BC4A9E08745AFB0E5852F4792765D4C259 ] C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnui.exe
14:57:27.0326 0x2ab8 Cisco AnyConnect Secure Mobility Agent for Windows - ok
14:57:27.0381 0x2ab8 OneDriveSetup - ok
14:57:27.0382 0x2ab8 OneDriveSetup - ok
14:57:27.0431 0x2ab8 [ 92B29E6BE97F5B2C5894904D1447BBFE, C8BF1ABDC9EDE0264ED7A818F61BB84BA2D42F160FDEA45DE6ED6EF816A6425E ] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
14:57:27.0480 0x2ab8 GoogleChromeAutoLaunch_678E52C622D3FEC81C940F43ECEEEB26 - ok
14:57:27.0574 0x2ab8 [ FF206944E3A8590FABE10FB2C321AA6D, 77C555667674C9E4473C64921C5F2A7D723FBE28A73EB5EBAA777CD04D11C06B ] D:\Steam\steam.exe
14:57:27.0707 0x2ab8 Steam - ok
14:57:27.0789 0x2ab8 [ C55C8610720CC75EE8358AF58BA520F1, 6B4A01AAB5C9340121A82A95AEAF92DA162C61013EE1684839A7AC22EAE435D0 ] D:\GalaxyClient\GalaxyClient.exe
14:57:27.0884 0x2ab8 GalaxyClient - ok
14:57:28.0000 0x2ab8 [ 67E3BD0F8FB0F39C241A2D60CC7D98EF, 09586F6A11AB10BBD38E8C44A88AFA9AD915981B908EEDA20B9AD2C34BFF7543 ] C:\Users\Sebastian\AppData\Roaming\Spotify\SpotifyWebHelper.exe
14:57:28.0139 0x2ab8 Spotify Web Helper - ok
14:57:28.0188 0x2ab8 [ 2287DAEA100837E40232FD9053F635D8, 8E905B8BC72F8DD6C7C71A7E04CD8D8EC1E9AD2B77EF5A48E089E439A75043D6 ] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIIJE.EXE
14:57:28.0204 0x2ab8 EPLTarget\P0000000000000000 - ok
14:57:28.0273 0x2ab8 [ 309A0390822194B835DBBF1374718354, BE1021B9D5EA4C4180E752F21191BD21010298BB2545F3D725E71E913DB14808 ] C:\Users\Sebastian\AppData\Roaming\uTorrent\uTorrent.exe
14:57:29.0622 0x2ab8 uTorrent - ok
14:57:29.0663 0x2ab8 Skype - ok
14:57:29.0693 0x2ab8 icq.desktop - ok
14:57:29.0863 0x2ab8 [ ABD86DD5E75DC483D4A153B2CB506C4C, 6D20F343BBA0D0CD9D3B0B2BE2A2F18E4EA3E028E48B382B162BD0CDDD06E3AA ] C:\Program Files (x86)\AirDroid\AirDroid.exe
14:57:30.0170 0x2ab8 AirDroid 3 - ok
14:57:30.0361 0x2ab8 [ C4668A2D015BFC941394010662CC21CC, 971712B7C2B12C2931A26B39D7FEB8D1AE0FDF2CEE33A6DE28232DA669CADB16 ] C:\Program Files\CCleaner\CCleaner64.exe
14:57:30.0584 0x2ab8 CCleaner Monitoring - ok
14:57:30.0662 0x2ab8 [ 44348495F9D6ED21F4EFB3FF80677D99, 05B76248764B2BF7F9229626D7EFAFF96B724D38A82969EBE376CBE879E30450 ] C:\Users\Sebastian\AppData\Local\Microsoft\OneDrive\OneDrive.exe
14:57:30.0756 0x2ab8 OneDrive - ok
14:57:30.0838 0x2ab8 [ 22F7B9670AD770C7ED7F4738204C8E5C, 7B793AC094CB1B073419B5DAE09DFBB8EBED03D29301F490AA76EA0667613438 ] C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe
14:57:30.0929 0x2ab8 HP Deskjet 3520 series (NET) - ok
14:57:30.0931 0x2ab8 Waiting for KSN requests completion. In queue: 72
14:57:31.0999 0x2ab8 AV detected via SS2: Sophos Home, C:\Program Files (x86)\Sophos\Sophos Anti-Virus\WSCClient.exe ( 10.7.0.0 ), 0x51000 ( enabled : updated )
14:57:32.0017 0x2ab8 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
14:57:32.0032 0x2ab8 Win FW state via NFP2: enabled ( trusted )
14:57:32.0132 0x2ab8 ============================================================
14:57:32.0132 0x2ab8 Scan finished
14:57:32.0132 0x2ab8 ============================================================
14:57:32.0137 0x2bdc Detected object count: 1
14:57:32.0137 0x2bdc Actual detected object count: 1
14:57:50.0261 0x2bdc 3DG4me ( UnsignedFile.Multi.Generic ) - skipped by user
14:57:50.0261 0x2bdc 3DG4me ( UnsignedFile.Multi.Generic ) - User select action: Skip |