Shepherd | 21.02.2017 17:40 | Scans wie angegeben durchgeführt; anbei die Logs:
MBAR: Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2017.02.21.05
rootkit: v2017.02.15.01
Windows 10 x64 NTFS
Internet Explorer 11.576.14393.0
****** :: ****** [administrator]
21.02.2017 16:40:16
mbar-log-2017-02-21 (16-40-16).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 453459
Time elapsed: 43 minute(s), 17 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) TDSS: Code:
17:31:15.0074 0x1cf4 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
17:31:17.0563 0x1cf4 ============================================================
17:31:17.0563 0x1cf4 Current date / time: 2017/02/21 17:31:17.0563
17:31:17.0563 0x1cf4 SystemInfo:
17:31:17.0564 0x1cf4
17:31:17.0564 0x1cf4 OS Version: 10.0.14393 ServicePack: 0.0
17:31:17.0564 0x1cf4 Product type: Workstation
17:31:17.0564 0x1cf4 ComputerName: *****
17:31:17.0564 0x1cf4 UserName: *****
17:31:17.0564 0x1cf4 Windows directory: C:\WINDOWS
17:31:17.0564 0x1cf4 System windows directory: C:\WINDOWS
17:31:17.0564 0x1cf4 Running under WOW64
17:31:17.0564 0x1cf4 Processor architecture: Intel x64
17:31:17.0564 0x1cf4 Number of processors: 8
17:31:17.0564 0x1cf4 Page size: 0x1000
17:31:17.0564 0x1cf4 Boot type: Normal boot
17:31:17.0564 0x1cf4 CodeIntegrityOptions = 0x00000001
17:31:17.0564 0x1cf4 ============================================================
17:31:17.0623 0x1cf4 KLMD registered as C:\WINDOWS\system32\drivers\35592823.sys
17:31:17.0623 0x1cf4 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.693, osProperties = 0x19
17:31:18.0179 0x1cf4 ============================================================
17:31:18.0411 0x1cf4 Initialize success
17:31:18.0411 0x1cf4 ============================================================
17:31:38.0198 0x15e4 ============================================================
17:31:38.0198 0x15e4 Scan started
17:31:38.0198 0x15e4 Mode: Manual; SigCheck; TDLFS;
17:31:38.0198 0x15e4 ============================================================
17:31:38.0198 0x15e4 KSN ping started
17:31:38.0258 0x15e4 KSN ping finished: true
17:31:40.0049 0x15e4 ================ Scan system memory ========================
17:31:40.0049 0x15e4 System memory - ok
17:31:40.0049 0x15e4 ================ Scan services =============================
17:31:40.0087 0x15e4 1394ohci - ok
17:31:40.0089 0x15e4 3ware - ok
17:31:40.0095 0x15e4 [ A3769020F7E8A70FD3E824C050F33306, BAAB18DD28C753EC90E9552BD5FFC316AD8815505A7998BCE51D21448B373D86 ] acedrv11 C:\Windows\system32\drivers\acedrv11.sys
17:31:40.0139 0x15e4 acedrv11 - ok
17:31:40.0150 0x15e4 ACPI - ok
17:31:40.0152 0x15e4 AcpiDev - ok
17:31:40.0154 0x15e4 acpiex - ok
17:31:40.0156 0x15e4 acpipagr - ok
17:31:40.0158 0x15e4 AcpiPmi - ok
17:31:40.0160 0x15e4 acpitime - ok
17:31:40.0165 0x15e4 [ AAA8E68E685DB1B68747E3DF68F96368, 1A5BE239B2D0C6F727303A98CFFC91070B6A05ECD6B9CD05AB326AC1910ECEBF ] acsock C:\WINDOWS\system32\DRIVERS\acsock64.sys
17:31:40.0177 0x15e4 acsock - ok
17:31:40.0185 0x15e4 [ 68E7DEA59FDEF410BAF29FDB5B7A6EEF, B808FCF0C30B465A1330E47947B84FC722A3B4C46260E261C54B1EED725A288F ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
17:31:40.0194 0x15e4 AdobeARMservice - ok
17:31:40.0198 0x15e4 ADP80XX - ok
17:31:40.0201 0x15e4 AFD - ok
17:31:40.0204 0x15e4 ahcache - ok
17:31:40.0206 0x15e4 AJRouter - ok
17:31:40.0208 0x15e4 ALG - ok
17:31:40.0211 0x15e4 AmdK8 - ok
17:31:40.0213 0x15e4 AmdPPM - ok
17:31:40.0216 0x15e4 amdsata - ok
17:31:40.0218 0x15e4 amdsbs - ok
17:31:40.0221 0x15e4 amdxata - ok
17:31:40.0224 0x15e4 AppHostSvc - ok
17:31:40.0225 0x15e4 AppID - ok
17:31:40.0228 0x15e4 AppIDSvc - ok
17:31:40.0231 0x15e4 Appinfo - ok
17:31:40.0239 0x15e4 [ 3B3774C868868257533EC7E715BB6D53, 4AF1DADCEDBD80BE6EDEC696DF59E65B51D31E33F4C84413CA03C7BD959FF4E5 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
17:31:40.0248 0x15e4 Apple Mobile Device Service - ok
17:31:40.0251 0x15e4 applockerfltr - ok
17:31:40.0253 0x15e4 AppMgmt - ok
17:31:40.0256 0x15e4 AppReadiness - ok
17:31:40.0258 0x15e4 AppVClient - ok
17:31:40.0260 0x15e4 AppvStrm - ok
17:31:40.0263 0x15e4 AppvVemgr - ok
17:31:40.0265 0x15e4 AppvVfs - ok
17:31:40.0268 0x15e4 AppXSvc - ok
17:31:40.0270 0x15e4 arcsas - ok
17:31:40.0292 0x15e4 [ 5A994C4D363F865F7BC1727F93D37E8E, 1C6D7ACF9B4980CC68190FEA54B1C9FC65701AED1F27EFA84402307DC9239968 ] ArgusMonitor C:\WINDOWS\syswow64\drivers\ArgusMonitor.sys
17:31:40.0303 0x15e4 ArgusMonitor - ok
17:31:40.0321 0x15e4 [ FB03A917C1294D3E6D671F24722E1BA3, C4E2C236E5086F0A7D5E20E426EA7A86B4A38797610188C79151201AD27C0DF4 ] asComSvc C:\Program Files (x86)\ASUS\AXSP\1.00.13\atkexComSvc.exe
17:31:40.0342 0x15e4 asComSvc - ok
17:31:40.0359 0x15e4 [ A63173897EA1A73A75D0E65036DE5B15, 07A83172B525DFC895056612F542420F4DF3C6192624C5B3141C726501163912 ] asHmComSvc C:\Program Files (x86)\ASUS\AAHM\1.00.14\aaHMSvc.exe
17:31:40.0380 0x15e4 asHmComSvc - ok
17:31:40.0383 0x15e4 [ FEF9DD9EA587F8886ADE43C1BEFBDAFE, DDE6F28B3F7F2ABBEE59D4864435108791631E9CB4CDFB1F178E5AA9859956D8 ] AsIO C:\WINDOWS\syswow64\drivers\AsIO.sys
17:31:40.0390 0x15e4 AsIO - ok
17:31:40.0401 0x15e4 aspnet_state - ok
17:31:40.0404 0x15e4 AsyncMac - ok
17:31:40.0407 0x15e4 atapi - ok
17:31:40.0411 0x15e4 [ C34B28D6285EAD94B3A2FABA84E90DA5, 82E69CBDEB9B0D6A2056AE6227A21C4CDB3050B384D69FA879607F3363ABBFD1 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
17:31:40.0422 0x15e4 AtherosSvc - detected UnsignedFile.Multi.Generic ( 1 )
17:31:40.0463 0x15e4 Detect skipped due to KSN trusted
17:31:40.0463 0x15e4 AtherosSvc - ok
17:31:40.0471 0x15e4 [ FC0E8778C000291CAF60EB88C011E931, 09BCCA3DE01021AEF76DFB46F01D21BA6FF409E816FA7547E5C3DFBF3A615ED2 ] atksgt C:\WINDOWS\system32\DRIVERS\atksgt.sys
17:31:40.0484 0x15e4 atksgt - ok
17:31:40.0487 0x15e4 AudioEndpointBuilder - ok
17:31:40.0489 0x15e4 Audiosrv - ok
17:31:40.0492 0x15e4 AxInstSV - ok
17:31:40.0494 0x15e4 b06bdrv - ok
17:31:40.0496 0x15e4 BasicDisplay - ok
17:31:40.0499 0x15e4 BasicRender - ok
17:31:40.0502 0x15e4 bcmfn - ok
17:31:40.0506 0x15e4 bcmfn2 - ok
17:31:40.0508 0x15e4 BDESVC - ok
17:31:40.0510 0x15e4 Beep - ok
17:31:40.0512 0x15e4 BFE - ok
17:31:40.0514 0x15e4 BITS - ok
17:31:40.0525 0x15e4 [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
17:31:40.0538 0x15e4 Bonjour Service - ok
17:31:40.0541 0x15e4 bowser - ok
17:31:40.0544 0x15e4 BrokerInfrastructure - ok
17:31:40.0546 0x15e4 Browser - ok
17:31:40.0549 0x15e4 [ 2D0446336D9DB55A742B999EC16ADF15, FBF57CBDCFE4146176ABBD7ACF04240048403143DD380E10AE63B10BA5D4F311 ] BTATH_BUS C:\WINDOWS\System32\drivers\btath_bus.sys
17:31:40.0556 0x15e4 BTATH_BUS - ok
17:31:40.0559 0x15e4 BthAvrcpTg - ok
17:31:40.0561 0x15e4 BthHFEnum - ok
17:31:40.0563 0x15e4 bthhfhid - ok
17:31:40.0565 0x15e4 BthHFSrv - ok
17:31:40.0569 0x15e4 BTHMODEM - ok
17:31:40.0572 0x15e4 bthserv - ok
17:31:40.0575 0x15e4 buttonconverter - ok
17:31:40.0577 0x15e4 CapImg - ok
17:31:40.0579 0x15e4 cdfs - ok
17:31:40.0581 0x15e4 CDPSvc - ok
17:31:40.0585 0x15e4 CDPUserSvc - ok
17:31:40.0589 0x15e4 cdrom - ok
17:31:40.0592 0x15e4 CertPropSvc - ok
17:31:40.0594 0x15e4 cht4iscsi - ok
17:31:40.0596 0x15e4 cht4vbd - ok
17:31:40.0598 0x15e4 circlass - ok
17:31:40.0601 0x15e4 CLFS - ok
17:31:40.0603 0x15e4 ClipSVC - ok
17:31:40.0606 0x15e4 clreg - ok
17:31:40.0612 0x15e4 CmBatt - ok
17:31:40.0705 0x15e4 [ C206F35A1D0B32B6A65BE2B5D7049B84, BAFE47BE23CB99EE93FAA311B57222E0D7A2B086C0941691995AE3100C52ED6E ] cmdAgent C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
17:31:40.0805 0x15e4 cmdAgent - ok
17:31:40.0813 0x15e4 [ AEF3EA5CDE86309C77D76D2B297C5B78, FAF5CD2B6E7C9CBF57C9257A665AA58A77035243DB02F65B14CEB71DA3B386C4 ] cmderd C:\WINDOWS\system32\DRIVERS\cmderd.sys
17:31:40.0822 0x15e4 cmderd - ok
17:31:40.0838 0x15e4 [ 49A1E016F04231C735C5036E6C74952E, 0ABFAC8DC4962F75894B20C1129C84579DF920BE06694D7BD026698F94604F09 ] cmdGuard C:\WINDOWS\system32\DRIVERS\cmdguard.sys
17:31:40.0863 0x15e4 cmdGuard - ok
17:31:40.0866 0x15e4 [ 3F57B85DEBE2DAC2C6F8F8A3F7FDB963, 703DC27AB9C43AC5AC4A4F0A34FE54C85A9181C33CC905479516EF06277DD184 ] cmdHlp C:\WINDOWS\system32\DRIVERS\cmdhlp.sys
17:31:40.0876 0x15e4 cmdHlp - ok
17:31:40.0913 0x15e4 [ BB82B9D06353F78E4F1DDF04A25F1CC7, 55FD0B3C8187B65C75488B8D86A48E5C47B620AA6426786B28DD21BE9728A6AE ] cmdvirth C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
17:31:40.0961 0x15e4 cmdvirth - ok
17:31:40.0964 0x15e4 CNG - ok
17:31:40.0966 0x15e4 cnghwassist - ok
17:31:40.0981 0x15e4 CompositeBus - ok
17:31:40.0983 0x15e4 COMSysApp - ok
17:31:40.0986 0x15e4 condrv - ok
17:31:40.0989 0x15e4 CoreMessagingRegistrar - ok
17:31:40.0993 0x15e4 [ C0EAD9F8AB83D41FF07303C75589C2B8, C89CAC39BCD2FA2DCC56D7EE84FF66127BCECCAE400E119FE41BF4C4D769504B ] Creative Audio Engine Licensing Service C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
17:31:41.0005 0x15e4 Creative Audio Engine Licensing Service - detected UnsignedFile.Multi.Generic ( 1 )
17:31:41.0047 0x15e4 Detect skipped due to KSN trusted
17:31:41.0047 0x15e4 Creative Audio Engine Licensing Service - ok
17:31:41.0050 0x15e4 CryptSvc - ok
17:31:41.0052 0x15e4 CSC - ok
17:31:41.0056 0x15e4 CscService - ok
17:31:41.0062 0x15e4 [ 6D8E4E90585A460EB0115C694BD3BB00, A014D8F4C254B1F7147A27D00A52561F3B7360EBDB4618BECCBCD7CC8649C8F8 ] CT20XUT C:\WINDOWS\system32\drivers\CT20XUT.SYS
17:31:41.0074 0x15e4 CT20XUT - ok
17:31:41.0081 0x15e4 [ 6D8E4E90585A460EB0115C694BD3BB00, A014D8F4C254B1F7147A27D00A52561F3B7360EBDB4618BECCBCD7CC8649C8F8 ] CT20XUT.SYS C:\WINDOWS\System32\drivers\CT20XUT.SYS
17:31:41.0091 0x15e4 CT20XUT.SYS - ok
17:31:41.0103 0x15e4 [ BC4677BC34C62F76FDE3A59141EB0C04, 9E135EC8A274BC5FBA7020F39583E6F47BA0F64D1326C9F8A73D96DAFE550AA8 ] ctac32k C:\WINDOWS\system32\drivers\ctac32k.sys
17:31:41.0122 0x15e4 ctac32k - ok
17:31:41.0135 0x15e4 [ DB679DCEF3D56B9BDF48851E4F8A9F23, 3182721F01A981C3A8EBF297690CB74CF6E3C94206D240E983F9B6317A4143D6 ] ctaud2k C:\WINDOWS\system32\drivers\ctaud2k.sys
17:31:41.0156 0x15e4 ctaud2k - ok
17:31:41.0164 0x15e4 [ 5CE3D0E1D1B3832EE052CFC442EEE0FA, 6B9DB2C350140ED547C7A96DB0EAD812E8987176B312C79AF52FC9B23EEEB8C4 ] CTAudSvcService C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
17:31:41.0177 0x15e4 CTAudSvcService - detected UnsignedFile.Multi.Generic ( 1 )
17:31:41.0219 0x15e4 Detect skipped due to KSN trusted
17:31:41.0219 0x15e4 CTAudSvcService - ok
17:31:41.0244 0x15e4 [ 74970AC366DEB6E1CA4DFB6A47CB8338, 083ACE4B457DCC8E191F430BF98F8D145B5135BB868FBE01644F3A7D5F8E8F1C ] CTEXFIFX C:\WINDOWS\system32\drivers\CTEXFIFX.SYS
17:31:41.0277 0x15e4 CTEXFIFX - ok
17:31:41.0302 0x15e4 [ 74970AC366DEB6E1CA4DFB6A47CB8338, 083ACE4B457DCC8E191F430BF98F8D145B5135BB868FBE01644F3A7D5F8E8F1C ] CTEXFIFX.SYS C:\WINDOWS\System32\drivers\CTEXFIFX.SYS
17:31:41.0331 0x15e4 CTEXFIFX.SYS - ok
17:31:41.0336 0x15e4 [ 3B858FEF65CAAB47E1B0E7457CF04248, C6B1B864F18B5E998470202C824AC534689515F37DDB3DF0CA81DE93DB65A3FA ] CTHWIUT C:\WINDOWS\system32\drivers\CTHWIUT.SYS
17:31:41.0345 0x15e4 CTHWIUT - ok
17:31:41.0349 0x15e4 [ 3B858FEF65CAAB47E1B0E7457CF04248, C6B1B864F18B5E998470202C824AC534689515F37DDB3DF0CA81DE93DB65A3FA ] CTHWIUT.SYS C:\WINDOWS\System32\drivers\CTHWIUT.SYS
17:31:41.0357 0x15e4 CTHWIUT.SYS - ok
17:31:41.0360 0x15e4 [ D77ED4CB7FE2CED09978676BFA17CBEC, B6712DF40BD32B61E3CC172E95DC6DCAB34138B416CE890B73D0F3FA280B8B73 ] ctprxy2k C:\WINDOWS\system32\drivers\ctprxy2k.sys
17:31:41.0368 0x15e4 ctprxy2k - ok
17:31:41.0374 0x15e4 [ 45A3CA3723B370E0B537284DE5550F5C, CBC882E2431E7C315A29BBC13F0C06BAF021C839AEB872144FA69F98F848EADF ] ctsfm2k C:\WINDOWS\system32\drivers\ctsfm2k.sys
17:31:41.0385 0x15e4 ctsfm2k - ok
17:31:41.0388 0x15e4 dam - ok
17:31:41.0392 0x15e4 DcomLaunch - ok
17:31:41.0394 0x15e4 DcpSvc - ok
17:31:41.0396 0x15e4 defragsvc - ok
17:31:41.0398 0x15e4 DeviceAssociationService - ok
17:31:41.0400 0x15e4 DeviceInstall - ok
17:31:41.0403 0x15e4 DevQueryBroker - ok
17:31:41.0406 0x15e4 Dfsc - ok
17:31:41.0409 0x15e4 Dhcp - ok
17:31:41.0412 0x15e4 diagnosticshub.standardcollector.service - ok
17:31:41.0414 0x15e4 DiagTrack - ok
17:31:41.0422 0x15e4 [ 2A312D761AE650B1BF1296733E872AAC, A05BB3B3BF2DA68599E593BB4367774A74141DE327092C77BCDA3C0F36C8D6AD ] DirMngr C:\Program Files (x86)\GNU\GnuPG\dirmngr.exe
17:31:41.0433 0x15e4 DirMngr - detected UnsignedFile.Multi.Generic ( 1 )
17:31:41.0475 0x15e4 Detect skipped due to KSN trusted
17:31:41.0475 0x15e4 DirMngr - ok
17:31:41.0478 0x15e4 disk - ok
17:31:41.0480 0x15e4 DmEnrollmentSvc - ok
17:31:41.0482 0x15e4 dmvsc - ok
17:31:41.0485 0x15e4 dmwappushservice - ok
17:31:41.0488 0x15e4 Dnscache - ok
17:31:41.0491 0x15e4 dot3svc - ok
17:31:41.0493 0x15e4 DPS - ok
17:31:41.0495 0x15e4 drmkaud - ok
17:31:41.0498 0x15e4 DsmSvc - ok
17:31:41.0500 0x15e4 DsSvc - ok
17:31:41.0505 0x15e4 [ 44BB65B1D3827043978FC8E11CA7C0B4, 9198D43F853DE25CB704CC208F41E649727356E122C7451C411DD49542A5A582 ] DTSAudioService C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe
17:31:41.0515 0x15e4 DTSAudioService - ok
17:31:41.0517 0x15e4 DXGKrnl - ok
17:31:41.0520 0x15e4 EapHost - ok
17:31:41.0522 0x15e4 EasyAntiCheat - ok
17:31:41.0524 0x15e4 ebdrv - ok
17:31:41.0526 0x15e4 EFS - ok
17:31:41.0529 0x15e4 EhStorClass - ok
17:31:41.0532 0x15e4 EhStorTcgDrv - ok
17:31:41.0553 0x15e4 [ 903302B9F63CC4AC570329BAB79300FC, 5F8526349063DEA5A4D50284ADB358CFD17A5373148974F6A1E6DC2C305456B4 ] ElfoService C:\Program Files (x86)\ElsterFormular Update Service\bin\ElfoService.exe
17:31:41.0635 0x15e4 ElfoService - ok
17:31:41.0640 0x15e4 embeddedmode - ok
17:31:41.0644 0x15e4 [ C66FE7442B47F933084943BBA16FDB10, DE9BD12A44FD31842303A0D34BC0A300D6C13E523BB4BA23074739AE07E93DCE ] emupia C:\WINDOWS\system32\drivers\emupia2k.sys
17:31:41.0653 0x15e4 emupia - ok
17:31:41.0656 0x15e4 EntAppSvc - ok
17:31:41.0658 0x15e4 ErrDev - ok
17:31:41.0662 0x15e4 EventSystem - ok
17:31:41.0665 0x15e4 exfat - ok
17:31:41.0667 0x15e4 fastfat - ok
17:31:41.0670 0x15e4 Fax - ok
17:31:41.0673 0x15e4 fdc - ok
17:31:41.0675 0x15e4 fdPHost - ok
17:31:41.0677 0x15e4 FDResPub - ok
17:31:41.0679 0x15e4 fhsvc - ok
17:31:41.0682 0x15e4 FileCrypt - ok
17:31:41.0685 0x15e4 FileInfo - ok
17:31:41.0687 0x15e4 Filetrace - ok
17:31:41.0690 0x15e4 flpydisk - ok
17:31:41.0691 0x15e4 FltMgr - ok
17:31:41.0694 0x15e4 FontCache - ok
17:31:41.0697 0x15e4 FontCache3.0.0.0 - ok
17:31:41.0700 0x15e4 FrameServer - ok
17:31:41.0702 0x15e4 FsDepends - ok
17:31:41.0704 0x15e4 Fs_Rec - ok
17:31:41.0709 0x15e4 [ A33BCF3FAB19DB7D0B501036722F311B, F0356BCF6457E04214D9BAF7E77B3D1CDC53DF829FEF36EF59AB47A52E96DFAD ] Futuremark SystemInfo Service C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
17:31:41.0760 0x15e4 Futuremark SystemInfo Service - ok
17:31:41.0763 0x15e4 fvevol - ok
17:31:41.0767 0x15e4 [ FFF0F0492B78CD0607D95E1819D05C4F, 5F6B6EE32BF62F394E02DB4BB00138B57FDCE02E73E63F1F3C623B85CDBE1072 ] GamingApp_Service C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
17:31:41.0774 0x15e4 GamingApp_Service - ok
17:31:41.0808 0x15e4 [ 4716347F3BE7BFE99DF197D1407E8966, 513CBE08992E172D7759442D272B5CF00411589BC601861AE71A9791B3A72EE0 ] GamingHotkey_Service C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
17:31:41.0846 0x15e4 GamingHotkey_Service - ok
17:31:41.0850 0x15e4 [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
17:31:41.0858 0x15e4 GEARAspiWDM - ok
17:31:41.0861 0x15e4 gencounter - ok
17:31:41.0863 0x15e4 genericusbfn - ok
17:31:41.0864 0x15e4 GPCIDrv - ok
17:31:41.0867 0x15e4 GPIOClx0101 - ok
17:31:41.0869 0x15e4 gpsvc - ok
17:31:41.0872 0x15e4 GpuEnergyDrv - ok
17:31:41.0899 0x15e4 [ F48E1E9289B88B9EFA070E9FACFC8D26, AF93DD0A74ED299F849922889A7EC87A9E1E46EACDEE0B5368381667EDEB1181 ] ha20x2k C:\WINDOWS\system32\drivers\ha20x2k.sys
17:31:41.0936 0x15e4 ha20x2k - ok
17:31:41.0941 0x15e4 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B, F9995CFEC7BBFE10B06EEE04CA6B49658275C43096E57747BFF9C2C31A0F9011 ] hamachi C:\WINDOWS\system32\DRIVERS\hamachi.sys
17:31:41.0950 0x15e4 hamachi - ok
17:31:41.0991 0x15e4 [ B1E3F445943F06E36DC079AF28D0F86B, 14A38DD6D46DA62796F08FC5C8D78DE1A9B687A7BC17321544AA090BFCDC2701 ] Hamachi2Svc C:\Program Files (x86)\Hamachi\hamachi-2.exe
17:31:42.0044 0x15e4 Hamachi2Svc - ok
17:31:42.0049 0x15e4 HDAudBus - ok
17:31:42.0052 0x15e4 HidBatt - ok
17:31:42.0056 0x15e4 HidBth - ok
17:31:42.0059 0x15e4 hidi2c - ok
17:31:42.0061 0x15e4 hidinterrupt - ok
17:31:42.0063 0x15e4 HidIr - ok
17:31:42.0066 0x15e4 hidserv - ok
17:31:42.0068 0x15e4 HidUsb - ok
17:31:42.0071 0x15e4 HomeGroupListener - ok
17:31:42.0073 0x15e4 HomeGroupProvider - ok
17:31:42.0076 0x15e4 HpSAMD - ok
17:31:42.0078 0x15e4 HTTP - ok
17:31:42.0080 0x15e4 HvHost - ok
17:31:42.0083 0x15e4 hvservice - ok
17:31:42.0085 0x15e4 hwpolicy - ok
17:31:42.0088 0x15e4 hyperkbd - ok
17:31:42.0091 0x15e4 [ 38C20EBB2621A86A5E9729EDA8F0F126, C362BF6523A16E4C9B040CD87511EF1E72788FB3B58F2FA23CD0A524CBD51140 ] I2cHkBurn C:\WINDOWS\system32\drivers\I2cHkBurn.sys
17:31:42.0099 0x15e4 I2cHkBurn - ok
17:31:42.0102 0x15e4 i8042prt - ok
17:31:42.0106 0x15e4 iagpio - ok
17:31:42.0108 0x15e4 iai2c - ok
17:31:42.0110 0x15e4 iaLPSS2i_GPIO2 - ok
17:31:42.0113 0x15e4 iaLPSS2i_I2C - ok
17:31:42.0115 0x15e4 iaLPSSi_GPIO - ok
17:31:42.0118 0x15e4 iaLPSSi_I2C - ok
17:31:42.0128 0x15e4 [ 2FDAEC4B02729C48C0FD1B0B4695995B, 87331D91FA3A23257B9913067B7B16D08710408070795B638058DBF728BBB288 ] iaStor C:\WINDOWS\system32\drivers\iaStor.sys
17:31:42.0145 0x15e4 iaStor - ok
17:31:42.0148 0x15e4 iaStorAV - ok
17:31:42.0151 0x15e4 [ D41861E56E7552C13674D7F147A02464, A361AE723FEEFD8D34D259F667ED14EEEC3B8ED6458522AC5D50C08E281B298B ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
17:31:42.0158 0x15e4 IAStorDataMgrSvc - ok
17:31:42.0160 0x15e4 iaStorV - ok
17:31:42.0163 0x15e4 ibbus - ok
17:31:42.0165 0x15e4 icssvc - ok
17:31:42.0169 0x15e4 [ DAF66902F08796F9C694901660E5A64A, F4A4764DED05980426BAB54AAF040BC27A39C80315F5161E8D0B4C7F694BD8E6 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
17:31:42.0221 0x15e4 IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
17:31:42.0261 0x15e4 Detect skipped due to KSN trusted
17:31:42.0261 0x15e4 IDriverT - ok
17:31:42.0265 0x15e4 IEEtwCollectorService - ok
17:31:42.0267 0x15e4 IKEEXT - ok
17:31:42.0270 0x15e4 IndirectKmd - ok
17:31:42.0277 0x15e4 [ 5ED55AAAAADA751CD91BA453C1BCC0C5, 0772E0BAD247FC98071C965A954E7707909FDABF5EADA603E27CB1C1FA778A6F ] inspect C:\WINDOWS\system32\DRIVERS\inspect.sys
17:31:42.0288 0x15e4 inspect - ok
17:31:42.0338 0x15e4 [ 028E40182A6F0374978C755F85B9F07C, 747B5B4E56076A77C7936B71CE20FD413A1869ACF9E4218A1B8EF8D4E8C82A3B ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
17:31:42.0400 0x15e4 IntcAzAudAddService - ok
17:31:42.0406 0x15e4 intelide - ok
17:31:42.0409 0x15e4 intelpep - ok
17:31:42.0411 0x15e4 intelppm - ok
17:31:42.0414 0x15e4 iorate - ok
17:31:42.0416 0x15e4 IpFilterDriver - ok
17:31:42.0418 0x15e4 iphlpsvc - ok
17:31:42.0421 0x15e4 IPMIDRV - ok
17:31:42.0423 0x15e4 IPNAT - ok
17:31:42.0435 0x15e4 [ EECB45F889E99174DA56FBDF37962D25, 12B407C45C9D0396FF3B5B118A863CBDEE0867034AE365F4CF5A8F66A4DB2003 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
17:31:42.0456 0x15e4 iPod Service - ok
17:31:42.0460 0x15e4 irda - ok
17:31:42.0462 0x15e4 IRENUM - ok
17:31:42.0465 0x15e4 irmon - ok
17:31:42.0467 0x15e4 isapnp - ok
17:31:42.0469 0x15e4 iScsiPrt - ok
17:31:42.0472 0x15e4 kbdclass - ok
17:31:42.0475 0x15e4 kbdhid - ok
17:31:42.0477 0x15e4 kdnic - ok
17:31:42.0479 0x15e4 KeyIso - ok
17:31:42.0482 0x15e4 KSecDD - ok
17:31:42.0484 0x15e4 KSecPkg - ok
17:31:42.0486 0x15e4 ksthunk - ok
17:31:42.0490 0x15e4 KtmRm - ok
17:31:42.0492 0x15e4 LanmanServer - ok
17:31:42.0495 0x15e4 LanmanWorkstation - ok
17:31:42.0498 0x15e4 lfsvc - ok
17:31:42.0500 0x15e4 LicenseManager - ok
17:31:42.0503 0x15e4 [ 156AB2E56DC3CA0B582E3362E07CDED7, 7B03929273861690DC42E4C686E655BE5A1C60136AE5E739D7E62306AFD4AB9A ] lirsgt C:\WINDOWS\system32\DRIVERS\lirsgt.sys
17:31:42.0512 0x15e4 lirsgt - ok
17:31:42.0514 0x15e4 lltdio - ok
17:31:42.0517 0x15e4 lltdsvc - ok
17:31:42.0519 0x15e4 lmhosts - ok
17:31:42.0523 0x15e4 LSI_SAS - ok
17:31:42.0525 0x15e4 LSI_SAS2i - ok
17:31:42.0528 0x15e4 LSI_SAS3i - ok
17:31:42.0530 0x15e4 LSI_SSS - ok
17:31:42.0532 0x15e4 LSM - ok
17:31:42.0535 0x15e4 luafv - ok
17:31:42.0538 0x15e4 MapsBroker - ok
17:31:42.0541 0x15e4 megasas - ok
17:31:42.0543 0x15e4 megasas2i - ok
17:31:42.0545 0x15e4 megasr - ok
17:31:42.0548 0x15e4 [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\WINDOWS\System32\drivers\HECIx64.sys
17:31:42.0556 0x15e4 MEIx64 - ok
17:31:42.0559 0x15e4 MessagingService - ok
17:31:42.0563 0x15e4 mlx4_bus - ok
17:31:42.0565 0x15e4 MMCSS - ok
17:31:42.0567 0x15e4 Modem - ok
17:31:42.0570 0x15e4 monitor - ok
17:31:42.0572 0x15e4 mouclass - ok
17:31:42.0575 0x15e4 mouhid - ok
17:31:42.0577 0x15e4 mountmgr - ok
17:31:42.0581 0x15e4 [ 17C3D8D5E65AE57B5E94B969433C0F99, 389F235A540CE1D55903F86C9045CAFC95B93E8EF0C3369D048D67B1106DE6E5 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
17:31:42.0596 0x15e4 MozillaMaintenance - ok
17:31:42.0599 0x15e4 mpsdrv - ok
17:31:42.0602 0x15e4 MpsSvc - ok
17:31:42.0604 0x15e4 MQAC - ok
17:31:42.0606 0x15e4 MRxDAV - ok
17:31:42.0609 0x15e4 mrxsmb - ok
17:31:42.0611 0x15e4 mrxsmb10 - ok
17:31:42.0613 0x15e4 mrxsmb20 - ok
17:31:42.0616 0x15e4 MsBridge - ok
17:31:42.0619 0x15e4 MSDTC - ok
17:31:42.0623 0x15e4 Msfs - ok
17:31:42.0626 0x15e4 msgpiowin32 - ok
17:31:42.0628 0x15e4 mshidkmdf - ok
17:31:42.0630 0x15e4 mshidumdf - ok
17:31:42.0632 0x15e4 MSICDSetup - ok
17:31:42.0637 0x15e4 [ 764362D808EC58BF2D072A3863D865EB, 6C3F385C61B3A8A214D13D5EDEAEF92B7A0C24EABA4C00FE5199B77FACE522A3 ] MSIREGISTER_MR C:\MSI\MSIRegister\MSIRegisterService.exe
17:31:42.0646 0x15e4 MSIREGISTER_MR - ok
17:31:42.0648 0x15e4 msisadrv - ok
17:31:42.0651 0x15e4 MSiSCSI - ok
17:31:42.0654 0x15e4 msiserver - ok
17:31:42.0658 0x15e4 [ 73907C500D91BD23651570CBA301CFA7, 853BDF0C79899D861890BF0BB7E445D025CE54963544DD565A18CE3A7AD69381 ] MSI_ActiveX_Service C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
17:31:42.0665 0x15e4 MSI_ActiveX_Service - ok
17:31:42.0701 0x15e4 [ 0F410B80D02BF73AC5EB22D8422B4DE5, 3F2F19F01E5426B00B4E525C37DB69276E984EF5A7D0C116A59DA1498162D786 ] MSI_LiveUpdate_Service C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
17:31:42.0743 0x15e4 MSI_LiveUpdate_Service - ok
17:31:42.0747 0x15e4 MSKSSRV - ok
17:31:42.0750 0x15e4 MsLldp - ok
17:31:42.0752 0x15e4 MSMQ - ok
17:31:42.0754 0x15e4 MSPCLOCK - ok
17:31:42.0756 0x15e4 MSPQM - ok
17:31:42.0758 0x15e4 MsRPC - ok
17:31:42.0762 0x15e4 MsSecFlt - ok
17:31:42.0764 0x15e4 mssmbios - ok
17:31:42.0766 0x15e4 MSTEE - ok
17:31:42.0769 0x15e4 MTConfig - ok
17:31:42.0772 0x15e4 Mup - ok
17:31:42.0780 0x15e4 [ 38B4C95E821528FB91DF16A78E04450F, 8ADDF63088293923B497E1AFF86C189669B973F43153FEE2370EA32860D71AD7 ] mv91xx C:\WINDOWS\system32\drivers\mv91xx.sys
17:31:42.0791 0x15e4 mv91xx - ok
17:31:42.0794 0x15e4 mvumis - ok
17:31:42.0797 0x15e4 NativeWifiP - ok
17:31:42.0800 0x15e4 NcaSvc - ok
17:31:42.0802 0x15e4 NcbService - ok
17:31:42.0804 0x15e4 NcdAutoSetup - ok
17:31:42.0807 0x15e4 ndfltr - ok
17:31:42.0810 0x15e4 NDIS - ok
17:31:42.0812 0x15e4 NdisCap - ok
17:31:42.0815 0x15e4 NdisImPlatform - ok
17:31:42.0817 0x15e4 NdisTapi - ok
17:31:42.0819 0x15e4 Ndisuio - ok
17:31:42.0822 0x15e4 NdisVirtualBus - ok
17:31:42.0824 0x15e4 NdisWan - ok
17:31:42.0826 0x15e4 ndiswanlegacy - ok
17:31:42.0829 0x15e4 ndproxy - ok
17:31:42.0831 0x15e4 Ndu - ok
17:31:42.0834 0x15e4 NetAdapterCx - ok
17:31:42.0836 0x15e4 NetBIOS - ok
17:31:42.0840 0x15e4 NetBT - ok
17:31:42.0842 0x15e4 Netlogon - ok
17:31:42.0845 0x15e4 Netman - ok
17:31:42.0853 0x15e4 NetMsmqActivator - ok
17:31:42.0855 0x15e4 NetPipeActivator - ok
17:31:42.0859 0x15e4 netprofm - ok
17:31:42.0861 0x15e4 NetSetupSvc - ok
17:31:42.0863 0x15e4 NetTcpActivator - ok
17:31:42.0865 0x15e4 NetTcpPortSharing - ok
17:31:42.0870 0x15e4 NgcCtnrSvc - ok
17:31:42.0872 0x15e4 NgcSvc - ok
17:31:42.0875 0x15e4 NlaSvc - ok
17:31:42.0878 0x15e4 [ 351533ACC2A069B94E80BBFC177E8FDF, 54B2749E0496ECC94CE65657627762B485CBC825767BAEDDAD0D2598820FFB9E ] NPF C:\WINDOWS\system32\drivers\npf.sys
17:31:42.0888 0x15e4 NPF - ok
17:31:42.0891 0x15e4 Npfs - ok
17:31:42.0894 0x15e4 npsvctrig - ok
17:31:42.0896 0x15e4 nsi - ok
17:31:42.0898 0x15e4 nsiproxy - ok
17:31:42.0902 0x15e4 NTFS - ok
17:31:42.0903 0x15e4 NTIOLib_1_0_C - ok
17:31:42.0907 0x15e4 Null - ok
17:31:42.0915 0x15e4 [ 302A57479E9A2A95CE723521A7ED1BD0, CEF8E26DBCA2E840ED32378193127FDC321828D28941AE42C5AA800613A85E91 ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
17:31:42.0927 0x15e4 NVHDA - ok
17:31:43.0170 0x15e4 [ E0854DA823FBC14F750BFD46E690F60F, BAACD13006B7EA377BC57CA502D342097E327486957F905DD720C870C1B4C67C ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvlddmkm.sys
17:31:43.0423 0x15e4 nvlddmkm - ok
17:31:43.0436 0x15e4 nvraid - ok
17:31:43.0439 0x15e4 nvstor - ok
17:31:43.0442 0x15e4 [ F37FE6B15A987AEEC08EEF531F2FAED7, CC768E7DE80C7A8CB2392F9BC528212B8A3A35A30A222ED0B0B959051E6F8065 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
17:31:43.0453 0x15e4 nvvad_WaveExtensible - ok
17:31:43.0463 0x15e4 [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
17:31:43.0488 0x15e4 odserv - ok
17:31:43.0491 0x15e4 OneSyncSvc - ok
17:31:43.0528 0x15e4 [ AD851D818F399DD946A9C17AB2156F22, 4A541E7A3A3164581BFB9080DE0976E18F6DD00E39458EBBCBD3B2445708BEB5 ] Origin Client Service C:\Program Files (x86)\Origin\OriginClientService.exe
17:31:43.0636 0x15e4 Origin Client Service - ok
17:31:43.0672 0x15e4 [ 788363C87EBD90AC1EAD2DC5A9A40759, B565663B459414C5C9F81451D9A127D62CDF605BC2A9E686F74A2E4FD44A9B43 ] Origin Web Helper Service C:\Program Files (x86)\Origin\OriginWebHelperService.exe
17:31:43.0713 0x15e4 Origin Web Helper Service - ok
17:31:43.0719 0x15e4 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:31:43.0734 0x15e4 ose - ok
17:31:43.0739 0x15e4 [ 0901EF0F25D269BD7FB18882D3B1AD34, 0719C716882F31D8BECE7CCA1ACDA63D7A989B6D7198E29EFB4D021354B84BD5 ] ossrv C:\WINDOWS\system32\drivers\ctoss2k.sys
17:31:43.0750 0x15e4 ossrv - ok
17:31:43.0754 0x15e4 p2pimsvc - ok
17:31:43.0757 0x15e4 p2psvc - ok
17:31:43.0759 0x15e4 Parport - ok
17:31:43.0762 0x15e4 partmgr - ok
17:31:43.0765 0x15e4 PcaSvc - ok
17:31:43.0767 0x15e4 pci - ok
17:31:43.0770 0x15e4 pciide - ok
17:31:43.0772 0x15e4 pcmcia - ok
17:31:43.0775 0x15e4 pcw - ok
17:31:43.0778 0x15e4 pdc - ok
17:31:43.0801 0x15e4 [ 20372BE109FEE1C37E2D5216680DB9EB, 2C3737FB3C6BCF81D0A7293667412DDEA649A8AEA40B7ADCFCB9893E8B3C4AF3 ] PDF Architect Helper Service C:\Program Files (x86)\PDF Architect\HelperService.exe
17:31:43.0828 0x15e4 PDF Architect Helper Service - ok
17:31:43.0845 0x15e4 [ B90A279073A815A4AA2C45A09EE004FA, 9EA27630C47F5FF99CBBE513C113F3ED01FABA0D59B9D9637764027BCC6EA24A ] PDF Architect Service C:\Program Files (x86)\PDF Architect\ConversionService.exe
17:31:43.0865 0x15e4 PDF Architect Service - ok
17:31:43.0868 0x15e4 PEAUTH - ok
17:31:43.0871 0x15e4 PeerDistSvc - ok
17:31:43.0874 0x15e4 percsas2i - ok
17:31:43.0877 0x15e4 percsas3i - ok
17:31:43.0895 0x15e4 PerfHost - ok
17:31:43.0902 0x15e4 PhoneSvc - ok
17:31:43.0904 0x15e4 PimIndexMaintenanceSvc - ok
17:31:43.0908 0x15e4 pla - ok
17:31:43.0911 0x15e4 PlugPlay - ok
17:31:43.0914 0x15e4 PnkBstrA - ok
17:31:43.0916 0x15e4 PNRPAutoReg - ok
17:31:43.0919 0x15e4 PNRPsvc - ok
17:31:43.0921 0x15e4 PolicyAgent - ok
17:31:43.0925 0x15e4 Power - ok
17:31:43.0928 0x15e4 PptpMiniport - ok
17:31:43.0994 0x15e4 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
17:31:44.0103 0x15e4 PrintNotify - ok
17:31:44.0108 0x15e4 Processor - ok
17:31:44.0112 0x15e4 ProfSvc - ok
17:31:44.0114 0x15e4 Psched - ok
17:31:44.0118 0x15e4 QWAVE - ok
17:31:44.0121 0x15e4 QWAVEdrv - ok
17:31:44.0124 0x15e4 RasAcd - ok
17:31:44.0127 0x15e4 RasAgileVpn - ok
17:31:44.0130 0x15e4 RasAuto - ok
17:31:44.0133 0x15e4 Rasl2tp - ok
17:31:44.0137 0x15e4 RasMan - ok
17:31:44.0140 0x15e4 RasPppoe - ok
17:31:44.0143 0x15e4 RasSstp - ok
17:31:44.0145 0x15e4 rdbss - ok
17:31:44.0150 0x15e4 rdpbus - ok
17:31:44.0153 0x15e4 RDPDR - ok
17:31:44.0159 0x15e4 RdpVideoMiniport - ok
17:31:44.0161 0x15e4 rdyboost - ok
17:31:44.0164 0x15e4 ReFSv1 - ok
17:31:44.0169 0x15e4 RemoteAccess - ok
17:31:44.0172 0x15e4 RemoteRegistry - ok
17:31:44.0176 0x15e4 RetailDemo - ok
17:31:44.0180 0x15e4 RmSvc - ok
17:31:44.0185 0x15e4 [ B60F58F175DE20A6739194E85B035178, 6E66D6041AF0B69896E4556F9FF3A3AA70CF4B09FFBE68E14E60313C5E3FFDDB ] rpcapd C:\Program Files (x86)\WinPcap\rpcapd.exe
17:31:44.0224 0x15e4 rpcapd - ok
17:31:44.0227 0x15e4 RpcEptMapper - ok
17:31:44.0230 0x15e4 RpcLocator - ok
17:31:44.0233 0x15e4 RpcSs - ok
17:31:44.0235 0x15e4 rspndr - ok
17:31:44.0238 0x15e4 rt640x64 - ok
17:31:44.0241 0x15e4 s3cap - ok
17:31:44.0244 0x15e4 SamSs - ok
17:31:44.0250 0x15e4 [ ECADB026023BF6E200A552E4EA700F47, 3BE40D99EF0229EC69E584D2351806F77A523EF362CC5094066DC4B9F7EB002A ] SbieDrv C:\Program Files\Sandboxie\SbieDrv.sys
17:31:44.0262 0x15e4 SbieDrv - ok
17:31:44.0268 0x15e4 [ 6E78D6CA33ECE9C7F0A7B0775198BA4D, 81F07C1D64FD66BFC0DC817045175EBA2096EC38D5D57584D114283DFA5899F4 ] SbieSvc C:\Program Files\Sandboxie\SbieSvc.exe
17:31:44.0278 0x15e4 SbieSvc - ok
17:31:44.0281 0x15e4 sbp2port - ok
17:31:44.0284 0x15e4 SCardSvr - ok
17:31:44.0287 0x15e4 ScDeviceEnum - ok
17:31:44.0290 0x15e4 scfilter - ok
17:31:44.0292 0x15e4 Schedule - ok
17:31:44.0498 0x15e4 scmbus - ok
17:31:44.0501 0x15e4 scmdisk0101 - ok
17:31:44.0504 0x15e4 SCPolicySvc - ok
17:31:44.0507 0x15e4 sdbus - ok
17:31:44.0510 0x15e4 SDRSVC - ok
17:31:44.0512 0x15e4 sdstor - ok
17:31:44.0515 0x15e4 seclogon - ok
17:31:44.0518 0x15e4 SENS - ok
17:31:44.0520 0x15e4 Sense - ok
17:31:44.0524 0x15e4 SensorDataService - ok
17:31:44.0528 0x15e4 SensorService - ok
17:31:44.0530 0x15e4 SensrSvc - ok
17:31:44.0533 0x15e4 SerCx - ok
17:31:44.0535 0x15e4 SerCx2 - ok
17:31:44.0539 0x15e4 Serenum - ok
17:31:44.0541 0x15e4 Serial - ok
17:31:44.0544 0x15e4 sermouse - ok
17:31:44.0551 0x15e4 SessionEnv - ok
17:31:44.0556 0x15e4 sfloppy - ok
17:31:44.0559 0x15e4 SharedAccess - ok
17:31:44.0562 0x15e4 ShellHWDetection - ok
17:31:44.0565 0x15e4 shpamsvc - ok
17:31:44.0568 0x15e4 SiSRaid2 - ok
17:31:44.0572 0x15e4 SiSRaid4 - ok
17:31:44.0808 0x15e4 smphost - ok
17:31:44.0812 0x15e4 SmsRouter - ok
17:31:44.0817 0x15e4 SNMPTRAP - ok
17:31:44.0821 0x15e4 [ 3BB48F7E33C2B76184DDF233000C09CD, D1AAE5B0425047CA0C2D376D3E59324D35A90DF9074CD442DFD0ED6E434D3C84 ] Sony SCSI Helper Service C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
17:31:44.0857 0x15e4 Sony SCSI Helper Service - detected UnsignedFile.Multi.Generic ( 1 )
17:31:44.0898 0x15e4 Detect skipped due to KSN trusted
17:31:44.0898 0x15e4 Sony SCSI Helper Service - ok
17:31:44.0901 0x15e4 spaceport - ok
17:31:44.0904 0x15e4 SpbCx - ok
17:31:44.0907 0x15e4 Spooler - ok
17:31:44.0910 0x15e4 sppsvc - ok
17:31:44.0913 0x15e4 srv - ok
17:31:44.0915 0x15e4 srv2 - ok
17:31:44.0918 0x15e4 srvnet - ok
17:31:44.0920 0x15e4 SSDPSRV - ok
17:31:44.0925 0x15e4 SstpSvc - ok
17:31:44.0928 0x15e4 StateRepository - ok
17:31:44.0955 0x15e4 [ 97CC32B472DC8AADD902DDD121B6E697, AA10E19CD0E3D9F26EEF6BC7D2ED7D8F94B13595495A5B0F277D53E5B26870F2 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
17:31:44.0985 0x15e4 Steam Client Service - ok
17:31:44.0990 0x15e4 stexstor - ok
17:31:44.0992 0x15e4 stisvc - ok
17:31:44.0995 0x15e4 storahci - ok
17:31:44.0997 0x15e4 storflt - ok
17:31:45.0000 0x15e4 stornvme - ok
17:31:45.0003 0x15e4 storqosflt - ok
17:31:45.0006 0x15e4 StorSvc - ok
17:31:45.0009 0x15e4 storufs - ok
17:31:45.0012 0x15e4 storvsc - ok
17:31:45.0014 0x15e4 svsvc - ok
17:31:45.0017 0x15e4 swenum - ok
17:31:45.0029 0x15e4 [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
17:31:45.0062 0x15e4 SwitchBoard - detected UnsignedFile.Multi.Generic ( 1 )
17:31:45.0104 0x15e4 Detect skipped due to KSN trusted
17:31:45.0104 0x15e4 SwitchBoard - ok
17:31:45.0107 0x15e4 swprv - ok
17:31:45.0110 0x15e4 Synth3dVsc - ok
17:31:45.0113 0x15e4 SysMain - ok
17:31:45.0115 0x15e4 SystemEventsBroker - ok
17:31:45.0119 0x15e4 TabletInputService - ok
17:31:45.0123 0x15e4 [ D0B07EED9DDEC5C69521C689B7BF455F, A9F1C76FBF833E25A8470116A9BB7F7121A86138B31B54C098F1E22C11109044 ] tap0901 C:\WINDOWS\system32\DRIVERS\tap0901.sys
17:31:45.0132 0x15e4 tap0901 - detected UnsignedFile.Multi.Generic ( 1 )
17:31:45.0187 0x15e4 Detect skipped due to KSN trusted
17:31:45.0187 0x15e4 tap0901 - ok
17:31:45.0191 0x15e4 [ F33FDC72298DF4BF9813A55D21F4EB31, 34AADF5115CA1B275FEF4238B420FE424F0E1D0FFD1606B24A0D594D7305CF1F ] taphss C:\WINDOWS\system32\DRIVERS\taphss.sys
17:31:45.0201 0x15e4 taphss - ok
17:31:45.0205 0x15e4 TapiSrv - ok
17:31:45.0207 0x15e4 Tcpip - ok
17:31:45.0210 0x15e4 Tcpip6 - ok
17:31:45.0215 0x15e4 tcpipreg - ok
17:31:45.0240 0x15e4 [ 99527D49EE0A96FC25537C61B270A372, 519E23F86EC86349F92C4A88DBD19C097AEE0A6E152776B32B45D293ED14946B ] tdrpman273 C:\WINDOWS\system32\DRIVERS\tdrpm273.sys
17:31:45.0272 0x15e4 tdrpman273 - ok
17:31:45.0276 0x15e4 tdx - ok
17:31:45.0446 0x15e4 [ 44449A0EB8EBD8DCBC3ED4BB62BA3A5F, 168197015D1E5ED71775250084C224A1100E0F989A6D1CC4102004E5AAD74F3A ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
17:31:45.0664 0x15e4 TeamViewer - ok
17:31:45.0674 0x15e4 terminpt - ok
17:31:45.0677 0x15e4 TermService - ok
17:31:45.0680 0x15e4 Themes - ok
17:31:45.0683 0x15e4 TieringEngineService - ok
17:31:45.0686 0x15e4 tiledatamodelsvc - ok
17:31:45.0689 0x15e4 TimeBrokerSvc - ok
17:31:45.0692 0x15e4 TPM - ok
17:31:45.0694 0x15e4 TrkWks - ok
17:31:45.0697 0x15e4 TrustedInstaller - ok
17:31:45.0701 0x15e4 tsusbflt - ok
17:31:45.0704 0x15e4 TsUsbGD - ok
17:31:45.0707 0x15e4 tsusbhub - ok
17:31:45.0710 0x15e4 tunnel - ok
17:31:45.0713 0x15e4 tzautoupdate - ok
17:31:45.0716 0x15e4 UASPStor - ok
17:31:45.0718 0x15e4 UcmCx0101 - ok
17:31:45.0721 0x15e4 UcmTcpciCx0101 - ok
17:31:45.0724 0x15e4 UcmUcsi - ok
17:31:45.0727 0x15e4 Ucx01000 - ok
17:31:45.0730 0x15e4 UdeCx - ok
17:31:45.0733 0x15e4 udfs - ok
17:31:45.0736 0x15e4 UEFI - ok
17:31:45.0738 0x15e4 UevAgentDriver - ok
17:31:45.0741 0x15e4 UevAgentService - ok
17:31:45.0745 0x15e4 Ufx01000 - ok
17:31:45.0748 0x15e4 UfxChipidea - ok
17:31:45.0751 0x15e4 ufxsynopsys - ok
17:31:45.0757 0x15e4 UI0Detect - ok
17:31:45.0760 0x15e4 umbus - ok
17:31:45.0763 0x15e4 UmPass - ok
17:31:45.0767 0x15e4 UmRdpService - ok
17:31:45.0770 0x15e4 UnistoreSvc - ok
17:31:45.0774 0x15e4 upnphost - ok
17:31:45.0777 0x15e4 UrsChipidea - ok
17:31:45.0780 0x15e4 UrsCx01000 - ok
17:31:45.0783 0x15e4 UrsSynopsys - ok
17:31:45.0786 0x15e4 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
17:31:45.0807 0x15e4 USBAAPL64 - ok
17:31:45.0809 0x15e4 usbccgp - ok
17:31:45.0812 0x15e4 usbcir - ok
17:31:45.0815 0x15e4 usbehci - ok
17:31:45.0818 0x15e4 usbhub - ok
17:31:45.0820 0x15e4 USBHUB3 - ok
17:31:45.0823 0x15e4 usbohci - ok
17:31:45.0826 0x15e4 usbprint - ok
17:31:45.0830 0x15e4 [ 2EC7B2C8123236B1233A77281D378DF7, D97DB59C9CAE2B8B33C707E8CEA7A65BF88712842CC715D270F7432A99D21BB6 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
17:31:45.0845 0x15e4 usbscan - ok
17:31:45.0848 0x15e4 usbser - ok
17:31:45.0851 0x15e4 USBSTOR - ok
17:31:45.0853 0x15e4 usbuhci - ok
17:31:45.0856 0x15e4 USBXHCI - ok
17:31:45.0860 0x15e4 UserDataSvc - ok
17:31:45.0864 0x15e4 UserManager - ok
17:31:45.0867 0x15e4 UsoSvc - ok
17:31:45.0869 0x15e4 VaultSvc - ok
17:31:45.0872 0x15e4 vdrvroot - ok
17:31:45.0875 0x15e4 vds - ok
17:31:45.0878 0x15e4 VerifierExt - ok
17:31:45.0881 0x15e4 vhdmp - ok
17:31:45.0883 0x15e4 vhf - ok
17:31:45.0886 0x15e4 vmbus - ok
17:31:45.0889 0x15e4 VMBusHID - ok
17:31:45.0892 0x15e4 vmgid - ok
17:31:45.0895 0x15e4 vmicguestinterface - ok
17:31:45.0897 0x15e4 vmicheartbeat - ok
17:31:45.0900 0x15e4 vmickvpexchange - ok
17:31:45.0903 0x15e4 vmicrdv - ok
17:31:45.0905 0x15e4 vmicshutdown - ok
17:31:45.0908 0x15e4 vmictimesync - ok
17:31:45.0911 0x15e4 vmicvmsession - ok
17:31:45.0914 0x15e4 vmicvss - ok
17:31:45.0917 0x15e4 volmgr - ok
17:31:45.0920 0x15e4 volmgrx - ok
17:31:45.0924 0x15e4 volsnap - ok
17:31:45.0927 0x15e4 volume - ok
17:31:45.0930 0x15e4 vpci - ok
17:31:45.0942 0x15e4 [ F3EC4EC08EC0C3F7023F0C662107CA7B, FC043142B4634E2AEA258690317B9892E8E1FDDF443846D6A2E4F4BDF2AD0056 ] vpnagent C:\Program Files (x86)\Cisco\Cisco AnyConnect Secure Mobility Client\vpnagent.exe
17:31:45.0957 0x15e4 vpnagent - ok
17:31:45.0961 0x15e4 [ 0F42C39016F82F345C0F2DB2D5B90EB4, 2E957E72BB8D0293F61FA7385BA9400DF7759E1E3D35FE24F3877A6460988F4D ] vpnva C:\WINDOWS\System32\drivers\vpnva64-6.sys
17:31:45.0973 0x15e4 vpnva - ok
17:31:45.0976 0x15e4 vsmraid - ok
17:31:45.0979 0x15e4 VSS - ok
17:31:45.0982 0x15e4 VSTXRAID - ok
17:31:45.0985 0x15e4 vwifibus - ok
17:31:45.0988 0x15e4 vwififlt - ok
17:31:45.0991 0x15e4 W32Time - ok
17:31:45.0994 0x15e4 w3logsvc - ok
17:31:45.0996 0x15e4 WacomPen - ok
17:31:45.0999 0x15e4 WalletService - ok
17:31:46.0002 0x15e4 wanarp - ok
17:31:46.0005 0x15e4 wanarpv6 - ok
17:31:46.0008 0x15e4 WAS - ok
17:31:46.0011 0x15e4 wbengine - ok
17:31:46.0014 0x15e4 WbioSrvc - ok
17:31:46.0017 0x15e4 wcifs - ok
17:31:46.0020 0x15e4 Wcmsvc - ok
17:31:46.0025 0x15e4 wcncsvc - ok
17:31:46.0027 0x15e4 wcnfs - ok
17:31:46.0031 0x15e4 WdBoot - ok
17:31:46.0034 0x15e4 Wdf01000 - ok
17:31:46.0037 0x15e4 WdFilter - ok
17:31:46.0040 0x15e4 WdiServiceHost - ok
17:31:46.0043 0x15e4 WdiSystemHost - ok
17:31:46.0045 0x15e4 wdiwifi - ok
17:31:46.0048 0x15e4 WdNisDrv - ok
17:31:46.0050 0x15e4 WdNisSvc - ok
17:31:46.0054 0x15e4 WebClient - ok
17:31:46.0057 0x15e4 Wecsvc - ok
17:31:46.0060 0x15e4 WEPHOSTSVC - ok
17:31:46.0063 0x15e4 wercplsupport - ok
17:31:46.0065 0x15e4 WerSvc - ok
17:31:46.0068 0x15e4 WFPLWFS - ok
17:31:46.0072 0x15e4 WiaRpc - ok
17:31:46.0075 0x15e4 WIMMount - ok
17:31:46.0077 0x15e4 WinDefend - ok
17:31:46.0083 0x15e4 WindowsTrustedRT - ok
17:31:46.0086 0x15e4 WindowsTrustedRTProxy - ok
17:31:46.0089 0x15e4 WinHttpAutoProxySvc - ok
17:31:46.0092 0x15e4 WinMad - ok
17:31:46.0098 0x15e4 Winmgmt - ok
17:31:46.0101 0x15e4 WinRM - ok
17:31:46.0107 0x15e4 WINUSB - ok
17:31:46.0109 0x15e4 WinVerbs - ok
17:31:46.0112 0x15e4 wisvc - ok
17:31:46.0115 0x15e4 WlanSvc - ok
17:31:46.0118 0x15e4 wlidsvc - ok
17:31:46.0121 0x15e4 WmiAcpi - ok
17:31:46.0125 0x15e4 wmiApSrv - ok
17:31:46.0128 0x15e4 WMPNetworkSvc - ok
17:31:46.0131 0x15e4 Wof - ok
17:31:46.0136 0x15e4 workfolderssvc - ok
17:31:46.0141 0x15e4 WPDBusEnum - ok
17:31:46.0144 0x15e4 WpdUpFltr - ok
17:31:46.0147 0x15e4 WpnService - ok
17:31:46.0150 0x15e4 WpnUserService - ok
17:31:46.0155 0x15e4 ws2ifsl - ok
17:31:46.0159 0x15e4 wscsvc - ok
17:31:46.0161 0x15e4 WSearch - ok
17:31:46.0166 0x15e4 wuauserv - ok
17:31:46.0169 0x15e4 WudfPf - ok
17:31:46.0172 0x15e4 WUDFRd - ok
17:31:46.0175 0x15e4 wudfsvc - ok
17:31:46.0178 0x15e4 WUDFWpdFs - ok
17:31:46.0181 0x15e4 WUDFWpdMtp - ok
17:31:46.0185 0x15e4 WwanSvc - ok
17:31:46.0188 0x15e4 XblAuthManager - ok
17:31:46.0191 0x15e4 XblGameSave - ok
17:31:46.0194 0x15e4 xboxgip - ok
17:31:46.0197 0x15e4 XboxNetApiSvc - ok
17:31:46.0200 0x15e4 [ 65343781331B6AE59E01C4C337682DE4, 738D00277B9137BF3D7C427E41B7835AF41388CF6C04D494CA4525F96CF7F0CC ] xhunter1 C:\WINDOWS\xhunter1.sys
17:31:46.0210 0x15e4 xhunter1 - ok
17:31:46.0213 0x15e4 xinputhid - ok
17:31:46.0215 0x15e4 ================ Scan global ===============================
17:31:46.0225 0x15e4 [ Global ] - ok
17:31:46.0226 0x15e4 ================ Scan MBR ==================================
***** (alles ok)
17:31:46.0341 0x15e4 ================ Scan VBR ==================================
***** (alles ok)
17:31:46.0348 0x15e4 ================ Scan generic autorun ======================
17:31:46.0540 0x15e4 [ 8667556E9A094E935212693AD05098E3, 86732B42130EA18D3CA2B38A7120A2EFE7D52689ABD50AE59A6968316450111F ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
17:31:46.0798 0x15e4 RTHDVCPL - ok
17:31:46.0882 0x15e4 [ 0BE126224273ACB0925C07B30A0E4209, CFFFCA6E70B1818438157209A99B573D06F8FC9F773F8EF3DE4A997A1992F25A ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
17:31:46.0934 0x15e4 RtHDVBg_DTS - ok
17:31:46.0954 0x15e4 [ B73E8CF29007982C778D52319006C04F, BF26199F668A61F94EC8E4E5B67F244A40BE8A69FBFB9CF852CFB332EC9D5AAD ] C:\Program Files\Eraser\Eraser.exe
17:31:47.0021 0x15e4 Eraser - ok
17:31:47.0027 0x15e4 [ ADEA393B2B49EB25578702F4F5525E93, 8F0AB94BEA3751C566CBFF2F9A29495CCAC029DE3721107BBA892A418FD70581 ] C:\Program Files\iTunes\iTunesHelper.exe
17:31:47.0039 0x15e4 iTunesHelper - ok
17:31:47.0043 0x15e4 [ EBC0E8C0A4DDA2C32A7D5863462A321A, 2F410138DB66D0219254339F1F098E401CEDAA032596F1F67BC54F394256FC68 ] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
17:31:47.0052 0x15e4 amd_dc_opt - detected UnsignedFile.Multi.Generic ( 1 )
17:31:47.0094 0x15e4 Detect skipped due to KSN trusted
17:31:47.0094 0x15e4 amd_dc_opt - ok
17:31:47.0113 0x15e4 OneDriveSetup - ok
17:31:47.0114 0x15e4 OneDriveSetup - ok
17:31:47.0240 0x15e4 [ 037EC5376C27B7C9EF04329D171CB0FE, 7D58366DD65600331FDD3291313D9FC7D0EDE6CB74C8E4C7A61C0BCFED75343D ] D:\Steam\steam.exe
17:31:47.0292 0x15e4 Steam - ok
17:31:47.0310 0x15e4 [ E97E971FB9FE4C0A72CB89B8063A4468, 5F45822818D90D3CDD97F6E705C309FD9161F7C55AAA6EFC44976F129D6B0D38 ] C:\Program Files\Sandboxie\SbieCtrl.exe
17:31:47.0337 0x15e4 SandboxieControl - ok
17:31:47.0338 0x15e4 Waiting for KSN requests completion. In queue: 80
17:31:48.0353 0x15e4 AV detected via SS2: COMODO Antivirus, C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe ( 8.4.0.5165 ), 0x61000 ( enabled : updated )
17:31:48.0356 0x15e4 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
17:31:48.0357 0x15e4 FW detected via SS2: COMODO Firewall, C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe ( 8.4.0.5165 ), 0x61010 ( enabled )
17:31:48.0428 0x15e4 ============================================================
17:31:48.0428 0x15e4 Scan finished
17:31:48.0428 0x15e4 ============================================================
17:31:48.0434 0x09c4 Detected object count: 1
17:31:48.0434 0x09c4 Actual detected object count: 1
17:32:15.0456 0x09c4 slb ( UnsignedFile.Multi.Generic ) - skipped by user
17:32:15.0456 0x09c4 slb ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:32:17.0555 0x1704 Deinitialize success |