OhSchreck! | 21.02.2017 06:26 | Code:
06:01:19.0207 0x261c TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
06:01:28.0645 0x261c ============================================================
06:01:28.0645 0x261c Current date / time: 2017/02/21 06:01:28.0645
06:01:28.0645 0x261c SystemInfo:
06:01:28.0645 0x261c
06:01:28.0645 0x261c OS Version: 10.0.14393 ServicePack: 0.0
06:01:28.0645 0x261c Product type: Workstation
06:01:28.0645 0x261c ComputerName: THOMASKEUNE-PC
06:01:28.0645 0x261c UserName: Thomas Keune
06:01:28.0645 0x261c Windows directory: C:\Windows
06:01:28.0645 0x261c System windows directory: C:\Windows
06:01:28.0645 0x261c Running under WOW64
06:01:28.0645 0x261c Processor architecture: Intel x64
06:01:28.0645 0x261c Number of processors: 4
06:01:28.0645 0x261c Page size: 0x1000
06:01:28.0645 0x261c Boot type: Normal boot
06:01:28.0645 0x261c CodeIntegrityOptions = 0x00000001
06:01:28.0645 0x261c ============================================================
06:01:30.0286 0x261c KLMD registered as C:\Windows\system32\drivers\83354219.sys
06:01:30.0286 0x261c KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.693, osProperties = 0x19
06:01:31.0552 0x261c System UUID: {BD170EF7-5A84-14D8-289F-811BC3028570}
06:01:33.0317 0x261c Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
06:01:33.0380 0x261c Drive \Device\Harddisk1\DR1 - Size: 0x15D50F66000 ( 1397.27 Gb ), SectorSize: 0x200, Cylinders: 0x15D50F, SectorsPerTrack: 0x20, TracksPerCylinder: 0x40, Type 'W'
06:01:33.0411 0x261c ============================================================
06:01:33.0411 0x261c \Device\Harddisk0\DR0:
06:01:33.0427 0x261c MBR partitions:
06:01:33.0427 0x261c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
06:01:33.0427 0x261c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xE4FD5800
06:01:33.0427 0x261c \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xE5008000, BlocksNum 0x3C00000
06:01:33.0427 0x261c \Device\Harddisk1\DR1:
06:01:33.0427 0x261c MBR partitions:
06:01:33.0427 0x261c \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x81F, BlocksNum 0x249EF8A1
06:01:33.0427 0x261c \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x249F00FF, BlocksNum 0x249EFC91
06:01:33.0427 0x261c \Device\Harddisk1\DR1\Partition3: MBR, Type 0x7, StartLBA 0x493DFDCF, BlocksNum 0x249EFC91
06:01:33.0427 0x261c \Device\Harddisk1\DR1\Partition4: MBR, Type 0x7, StartLBA 0x6DDCFA9F, BlocksNum 0x249EFC91
06:01:33.0442 0x261c \Device\Harddisk1\DR1\Partition5: MBR, Type 0x7, StartLBA 0x927BF76F, BlocksNum 0x1C2C83C1
06:01:33.0442 0x261c ============================================================
06:01:33.0536 0x261c C: <-> \Device\Harddisk0\DR0\Partition2
06:01:34.0052 0x261c D: <-> \Device\Harddisk0\DR0\Partition3
06:01:34.0067 0x261c K: <-> \Device\Harddisk1\DR1\Partition1
06:01:34.0067 0x261c L: <-> \Device\Harddisk1\DR1\Partition2
06:01:34.0114 0x261c M: <-> \Device\Harddisk1\DR1\Partition3
06:01:34.0114 0x261c N: <-> \Device\Harddisk1\DR1\Partition4
06:01:34.0161 0x261c O: <-> \Device\Harddisk0\DR0\Partition1
06:01:34.0192 0x261c P: <-> \Device\Harddisk1\DR1\Partition5
06:01:34.0192 0x261c ============================================================
06:01:34.0192 0x261c Initialize success
06:01:34.0192 0x261c ============================================================
06:02:19.0038 0x252c ============================================================
06:02:19.0038 0x252c Scan started
06:02:19.0038 0x252c Mode: Manual; SigCheck; TDLFS;
06:02:19.0038 0x252c ============================================================
06:02:19.0038 0x252c KSN ping started
06:02:20.0179 0x252c KSN ping finished: false
06:02:27.0820 0x252c ================ Scan system memory ========================
06:02:27.0820 0x252c System memory - ok
06:02:27.0820 0x252c ================ Scan services =============================
06:02:28.0242 0x252c 1394ohci - ok
06:02:28.0257 0x252c 3ware - ok
06:02:29.0367 0x252c [ 78F0179B6C4C93119432C3A2C511EB44, 746A48F8D9C4004E7FB8BD72DA40DBBD207A882ED33B4A844F2F017521403D85 ] a2AntiMalware C:\Program Files\Emsisoft Anti-Malware\a2service.exe
06:02:30.0242 0x252c a2AntiMalware - ok
06:02:30.0367 0x252c ACPI - ok
06:02:30.0383 0x252c AcpiDev - ok
06:02:30.0445 0x252c acpiex - ok
06:02:30.0445 0x252c acpipagr - ok
06:02:30.0508 0x252c AcpiPmi - ok
06:02:30.0523 0x252c acpitime - ok
06:02:30.0992 0x252c [ B932E0EE190778D840F1442DFC0F9612, 8780963F14D57279FDD585BE945ED40F24590D32676C7A9EF94002D38B8BA643 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
06:02:31.0070 0x252c AdobeARMservice - ok
06:02:32.0430 0x252c [ 32B31B696CB8E8F380831DFEB80A67E4, 8C8F6E16F2FB3E8F10569261B7712BBC931A2924B6C27D561E7F828041C4F3E6 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
06:02:32.0508 0x252c AdobeFlashPlayerUpdateSvc - ok
06:02:32.0570 0x252c ADP80XX - ok
06:02:32.0601 0x252c AFD - ok
06:02:32.0664 0x252c ahcache - ok
06:02:32.0680 0x252c AJRouter - ok
06:02:32.0726 0x252c ALG - ok
06:02:32.0742 0x252c AmdK8 - ok
06:02:32.0758 0x252c AmdPPM - ok
06:02:32.0773 0x252c amdsata - ok
06:02:32.0773 0x252c amdsbs - ok
06:02:32.0773 0x252c amdxata - ok
06:02:32.0805 0x252c AppID - ok
06:02:32.0836 0x252c AppIDSvc - ok
06:02:32.0867 0x252c Appinfo - ok
06:02:32.0883 0x252c applockerfltr - ok
06:02:32.0992 0x252c AppReadiness - ok
06:02:33.0055 0x252c AppXSvc - ok
06:02:33.0070 0x252c arcsas - ok
06:02:33.0086 0x252c AsyncMac - ok
06:02:33.0086 0x252c atapi - ok
06:02:33.0148 0x252c AudioEndpointBuilder - ok
06:02:33.0226 0x252c Audiosrv - ok
06:02:33.0258 0x252c AxInstSV - ok
06:02:33.0305 0x252c b06bdrv - ok
06:02:33.0367 0x252c BasicDisplay - ok
06:02:33.0367 0x252c BasicRender - ok
06:02:33.0383 0x252c bcmfn - ok
06:02:33.0398 0x252c bcmfn2 - ok
06:02:33.0414 0x252c BDESVC - ok
06:02:33.0461 0x252c Beep - ok
06:02:33.0523 0x252c BFE - ok
06:02:33.0539 0x252c BITS - ok
06:02:33.0617 0x252c bowser - ok
06:02:33.0664 0x252c BrokerInfrastructure - ok
06:02:33.0742 0x252c Browser - ok
06:02:33.0758 0x252c BthAvrcpTg - ok
06:02:33.0836 0x252c BthHFEnum - ok
06:02:33.0836 0x252c bthhfhid - ok
06:02:33.0883 0x252c BthHFSrv - ok
06:02:33.0930 0x252c BTHMODEM - ok
06:02:33.0945 0x252c bthserv - ok
06:02:34.0008 0x252c buttonconverter - ok
06:02:34.0055 0x252c CapImg - ok
06:02:34.0070 0x252c cdfs - ok
06:02:34.0102 0x252c CDPSvc - ok
06:02:34.0180 0x252c CDPUserSvc - ok
06:02:34.0258 0x252c cdrom - ok
06:02:34.0289 0x252c CertPropSvc - ok
06:02:34.0430 0x252c [ 59B4AB79011957DD3B83F0C2E63741BD, 5DE68785D701DBA0F98452B7D5CC407BEECD51685F39516157733CED2EF2FA19 ] chip1click C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe
06:02:34.0477 0x252c chip1click - detected UnsignedFile.Multi.Generic ( 1 )
06:02:37.0633 0x252c chip1click ( UnsignedFile.Multi.Generic ) - warning
06:02:37.0680 0x252c cht4iscsi - ok
06:02:37.0680 0x252c cht4vbd - ok
06:02:37.0711 0x252c circlass - ok
06:02:38.0070 0x252c [ ED81E81752CA817AFA740C14AD05BC6C, 9E4B04D4604B96866B3ED18433914BF7ECF3F746CDB34ED856FFC418AAB3C04F ] cjpcsc C:\Windows\SysWOW64\cjpcsc.exe
06:02:38.0586 0x252c cjpcsc - ok
06:02:38.0602 0x252c [ 06E1F5228399FC49A8D026DA38DB6784, 5554071E5C55FC7EF3C7C95F0BC565509C3F0C03E0814C98376932A9D1C32AA6 ] cjusb C:\Windows\system32\DRIVERS\cjusb.sys
06:02:38.0695 0x252c cjusb - ok
06:02:38.0727 0x252c CLFS - ok
06:02:38.0742 0x252c ClipSVC - ok
06:02:38.0742 0x252c clreg - ok
06:02:38.0758 0x252c CmBatt - ok
06:02:38.0789 0x252c CNG - ok
06:02:38.0789 0x252c cnghwassist - ok
06:02:39.0477 0x252c CompositeBus - ok
06:02:39.0477 0x252c COMSysApp - ok
06:02:39.0508 0x252c condrv - ok
06:02:39.0539 0x252c CoreMessagingRegistrar - ok
06:02:40.0008 0x252c cpuz139 - ok
06:02:40.0071 0x252c CryptSvc - ok
06:02:40.0133 0x252c dam - ok
06:02:40.0133 0x252c dbx - ok
06:02:40.0242 0x252c [ 566BD6ED419F7FBC88EDD579044AD5C9, EC66C10DAC23ED149545305EA25F60888C5D3675BD850C7C12275B8666D18FEF ] DbxSvc C:\Windows\system32\DbxSvc.exe
06:02:41.0102 0x252c DbxSvc - ok
06:02:41.0117 0x252c DcomLaunch - ok
06:02:41.0133 0x252c DcpSvc - ok
06:02:41.0180 0x252c defragsvc - ok
06:02:41.0196 0x252c DeviceAssociationService - ok
06:02:41.0227 0x252c DeviceInstall - ok
06:02:41.0242 0x252c DevQueryBroker - ok
06:02:41.0289 0x252c Dfsc - ok
06:02:41.0352 0x252c Dhcp - ok
06:02:41.0414 0x252c diagnosticshub.standardcollector.service - ok
06:02:41.0461 0x252c DiagTrack - ok
06:02:41.0664 0x252c DigitalWave.Update.Service - ok
06:02:41.0680 0x252c disk - ok
06:02:41.0774 0x252c DmEnrollmentSvc - ok
06:02:41.0789 0x252c dmvsc - ok
06:02:41.0789 0x252c dmwappushservice - ok
06:02:41.0805 0x252c Dnscache - ok
06:02:41.0836 0x252c dot3svc - ok
06:02:41.0867 0x252c DPS - ok
06:02:41.0914 0x252c drmkaud - ok
06:02:41.0946 0x252c DsmSvc - ok
06:02:41.0961 0x252c DsSvc - ok
06:02:42.0024 0x252c DXGKrnl - ok
06:02:42.0086 0x252c e1iexpress - ok
06:02:42.0133 0x252c EapHost - ok
06:02:42.0164 0x252c ebdrv - ok
06:02:42.0258 0x252c EFS - ok
06:02:42.0274 0x252c EhStorClass - ok
06:02:42.0336 0x252c EhStorTcgDrv - ok
06:02:42.0383 0x252c embeddedmode - ok
06:02:42.0414 0x252c EntAppSvc - ok
06:02:42.0571 0x252c [ 0E840AA66CAB02CBA9730C772BBE305B, 8862583E653D13D1D10A1A4A33704E4F70576E80370943AAFD1EAED6657A0104 ] epp C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys
06:02:42.0586 0x252c epp - ok
06:02:42.0633 0x252c ErrDev - ok
06:02:42.0649 0x252c EventSystem - ok
06:02:42.0664 0x252c exfat - ok
06:02:42.0664 0x252c fastfat - ok
06:02:42.0696 0x252c Fax - ok
06:02:42.0696 0x252c fdc - ok
06:02:42.0727 0x252c fdPHost - ok
06:02:42.0727 0x252c FDResPub - ok
06:02:42.0789 0x252c fhsvc - ok
06:02:42.0852 0x252c FileCrypt - ok
06:02:42.0868 0x252c FileInfo - ok
06:02:42.0914 0x252c Filetrace - ok
06:02:42.0946 0x252c flpydisk - ok
06:02:42.0977 0x252c FltMgr - ok
06:02:43.0039 0x252c FontCache - ok
06:02:43.0102 0x252c FrameServer - ok
06:02:43.0274 0x252c [ 93B5CD0AC126BE95F65B28AF3D9542DC, BFDAFE9B7A150056C1E6C683197CA7F9E86FF6EBD27178A70BE1FC9BF381D8AA ] FreemakeVideoCapture C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
06:02:43.0414 0x252c FreemakeVideoCapture - detected UnsignedFile.Multi.Generic ( 1 )
06:02:43.0414 0x252c FreemakeVideoCapture ( UnsignedFile.Multi.Generic ) - warning
06:02:43.0414 0x252c FsDepends - ok
06:02:43.0414 0x252c Fs_Rec - ok
06:02:43.0446 0x252c fvevol - ok
06:02:43.0508 0x252c [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
06:02:43.0571 0x252c GEARAspiWDM - ok
06:02:43.0602 0x252c gencounter - ok
06:02:43.0618 0x252c genericusbfn - ok
06:02:43.0680 0x252c GPIOClx0101 - ok
06:02:43.0711 0x252c gpsvc - ok
06:02:43.0727 0x252c GpuEnergyDrv - ok
06:02:43.0930 0x252c [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
06:02:43.0946 0x252c gupdate - ok
06:02:44.0039 0x252c [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
06:02:44.0055 0x252c gupdatem - ok
06:02:44.0118 0x252c HDAudBus - ok
06:02:44.0133 0x252c HidBatt - ok
06:02:44.0133 0x252c HidBth - ok
06:02:44.0149 0x252c hidi2c - ok
06:02:44.0164 0x252c hidinterrupt - ok
06:02:44.0180 0x252c HidIr - ok
06:02:44.0227 0x252c hidserv - ok
06:02:44.0289 0x252c HidUsb - ok
06:02:44.0321 0x252c HomeGroupListener - ok
06:02:44.0368 0x252c HomeGroupProvider - ok
06:02:44.0446 0x252c [ 987CE6F69764B66D8026518AEFEDB508, 37AD86BD716588678EC9B825D87BA2AF157BE0A619F7A012EFE26F378A523E5B ] hotcore3 C:\Windows\system32\DRIVERS\hotcore3.sys
06:02:44.0555 0x252c hotcore3 - ok
06:02:44.0711 0x252c [ 97AAC45A375168C6A2297BEEB9692E31, 9C7285988D0C5DE8E3608F4E9F50A5C9398FFD0DA0F4C965C953859001FC76C8 ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll
06:02:44.0743 0x252c hpqcxs08 - ok
06:02:44.0774 0x252c [ 19A4FB67B1C97EA18EDFF44340973CD9, F1B6A7C1E450FF9A1D10F315F17D42DFE8390E88FF1AED4DE35237C4B81FC81D ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll
06:02:44.0805 0x252c hpqddsvc - ok
06:02:44.0805 0x252c HpSAMD - ok
06:02:44.0993 0x252c [ F37882F128EFACEFE353E0BAE2766909, 2F9D21613500F092DFC0DB879180B549EE615D9B07408A5CC1A7F84663B2F47A ] HPSLPSVC C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
06:02:45.0102 0x252c HPSLPSVC - detected UnsignedFile.Multi.Generic ( 1 )
06:02:45.0102 0x252c HPSLPSVC ( UnsignedFile.Multi.Generic ) - warning
06:02:45.0211 0x252c [ 1878A79551F2EDAE7EBD110AAE6D33AD, 1F409360B44AEB3A6023E953EAB350FFB3EB8322F589E2422AB312288B33A2DA ] HPSupportSolutionsFrameworkService C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe
06:02:45.0227 0x252c HPSupportSolutionsFrameworkService - ok
06:02:45.0305 0x252c [ CA53DA4C3EAD4C86918E7F80CD281ABB, E894D6807103194CC3C8F232C0310016EE2CD396C37565BEFDDB52E1A1B1CA26 ] HssDRV6 C:\Windows\system32\DRIVERS\hssdrv6.sys
06:02:45.0336 0x252c HssDRV6 - ok
06:02:45.0368 0x252c HTTP - ok
06:02:45.0430 0x252c HvHost - ok
06:02:45.0477 0x252c hvservice - ok
06:02:45.0477 0x252c hwpolicy - ok
06:02:45.0493 0x252c hyperkbd - ok
06:02:45.0524 0x252c i8042prt - ok
06:02:45.0540 0x252c iagpio - ok
06:02:45.0540 0x252c iai2c - ok
06:02:45.0540 0x252c iaLPSS2i_GPIO2 - ok
06:02:45.0555 0x252c iaLPSS2i_I2C - ok
06:02:45.0555 0x252c iaLPSSi_GPIO - ok
06:02:45.0555 0x252c iaLPSSi_I2C - ok
06:02:45.0618 0x252c [ 87A72502C8AC5E89B5A46FF6E874F5C5, A72C8C96BA29B5894A3085CA2ADB6343FEFA79534B334416F8D4751CF8A30008 ] IAMTVE C:\Windows\system32\drivers\IAMTVE.sys
06:02:45.0743 0x252c IAMTVE - ok
06:02:45.0868 0x252c [ 26CF4275034214ECEDD8EC17B0A18A99, 95A08C63971C28F1BC97040C0ADA247E3B43DE7D937B14E33A394B955D0AC8B7 ] iaStor C:\Windows\system32\drivers\iaStor.sys
06:02:45.0930 0x252c iaStor - ok
06:02:46.0071 0x252c [ 25555186E4FBDF0E30A5DBFC9B9A73F9, 4A9DAC2B56389C5955C343E202C6E81CD3A608E78A4BB7E6ED560719DF02C955 ] iaStorA C:\Windows\system32\drivers\iaStorA.sys
06:02:46.0118 0x252c iaStorA - ok
06:02:46.0149 0x252c iaStorAV - ok
06:02:46.0149 0x252c iaStorV - ok
06:02:46.0149 0x252c ibbus - ok
06:02:46.0165 0x252c icssvc - ok
06:02:46.0180 0x252c IKEEXT - ok
06:02:46.0211 0x252c IndirectKmd - ok
06:02:46.0711 0x252c [ ECA5E9DA350D2D21376260CD3602449A, B027FE77062488B8FC0EEE2113341DD922CE1BD741DF4F5D92DCCDC2E2C18BB2 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
06:02:46.0930 0x252c IntcAzAudAddService - ok
06:02:46.0977 0x252c [ 8C90FA99363E2BC4938CCA3A487100E9, E16285D52B070466C2E1556D74A1F577F92E20AD66B9F8708957F25EB8DDB56F ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
06:02:47.0930 0x252c Intel(R) PROSet Monitoring Service - ok
06:02:47.0993 0x252c intelide - ok
06:02:48.0055 0x252c intelpep - ok
06:02:48.0071 0x252c intelppm - ok
06:02:48.0149 0x252c [ E45575812630B049CE0F679D87561A4D, 2645B87960DAA51295530ECF5518E5872B17520293068E7DEA064FEAE3884E87 ] ioatdma1 C:\Windows\System32\Drivers\qd162x64.sys
06:02:48.0227 0x252c ioatdma1 - ok
06:02:48.0337 0x252c [ 2C23820DD9E81199E60F553EB50BC449, AF3847AD90A79E9D22DC67F4ED52B1D3FAF7C6420D60F2044C1FB49FD338BB70 ] ioatdma2 C:\Windows\System32\Drivers\qd262x64.sys
06:02:48.0368 0x252c ioatdma2 - ok
06:02:48.0383 0x252c iorate - ok
06:02:48.0383 0x252c IpFilterDriver - ok
06:02:48.0399 0x252c iphlpsvc - ok
06:02:48.0399 0x252c IPMIDRV - ok
06:02:48.0415 0x252c IPNAT - ok
06:02:48.0415 0x252c irda - ok
06:02:48.0430 0x252c IRENUM - ok
06:02:48.0446 0x252c irmon - ok
06:02:48.0462 0x252c isapnp - ok
06:02:48.0508 0x252c iScsiPrt - ok
06:02:48.0618 0x252c kbdclass - ok
06:02:48.0665 0x252c kbdhid - ok
06:02:48.0696 0x252c kdnic - ok
06:02:48.0712 0x252c KeyIso - ok
06:02:48.0712 0x252c KSecDD - ok
06:02:48.0727 0x252c KSecPkg - ok
06:02:48.0743 0x252c ksthunk - ok
06:02:48.0774 0x252c KtmRm - ok
06:02:48.0837 0x252c LanmanServer - ok
06:02:48.0883 0x252c LanmanWorkstation - ok
06:02:48.0930 0x252c lfsvc - ok
06:02:48.0962 0x252c LicenseManager - ok
06:02:48.0993 0x252c lltdio - ok
06:02:49.0040 0x252c lltdsvc - ok
06:02:49.0118 0x252c lmhosts - ok
06:02:49.0133 0x252c LSI_SAS - ok
06:02:49.0133 0x252c LSI_SAS2i - ok
06:02:49.0149 0x252c LSI_SAS3i - ok
06:02:49.0196 0x252c LSI_SSS - ok
06:02:49.0258 0x252c LSM - ok
06:02:49.0258 0x252c luafv - ok
06:02:49.0305 0x252c MapsBroker - ok
06:02:49.0383 0x252c [ 024DA28053D57E9E32BEE52600576BBB, 8EC636DAB90A835DEBA2EC6176F4547EEF557415FF77C6378EF423569702731E ] MarvinBus C:\Windows\System32\drivers\MarvinBus64.sys
06:02:49.0602 0x252c MarvinBus - ok
06:02:49.0649 0x252c [ 42B3F5C9FBC9B3F0E0BA6B5D7FC8E849, 80E571FEE4373E4AF487176C9265FB89912739E961C47880A60115BD50638AEA ] mbamchameleon C:\Windows\system32\drivers\mbamchameleon.sys
06:02:49.0665 0x252c mbamchameleon - ok
06:02:49.0712 0x252c [ 78BFF5425E044086E74E78650A359FBB, 294738C10F3ED933D4EC40EA0659372FCF19A3C6D45D356917438CA495F2CB45 ] MBAMProtector C:\WINDOWS\system32\drivers\mbam.sys
06:02:49.0743 0x252c MBAMProtector - ok
06:02:50.0071 0x252c [ 9611577752E293259C7DCE19E9026362, 8CB5DFD63FA15603BB6FA6B501E09ED7F4DE0E8F68CB28B78CECAC3711BEFD24 ] MBAMScheduler C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
06:02:50.0149 0x252c MBAMScheduler - ok
06:02:50.0305 0x252c [ F1A89A34388B5626F1548D393B23ECB1, EA00AC76C4C8C9340753B58A3313C9177A9B98F9F1BDE08F184CD0F53D0C186F ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
06:02:50.0399 0x252c MBAMService - ok
06:02:50.0540 0x252c [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy C:\Windows\system32\drivers\MBAMSwissArmy.sys
06:02:50.0571 0x252c MBAMSwissArmy - ok
06:02:50.0634 0x252c [ 898415AC0B5F1D2A9A48ABCB68A6DC4B, E1FD9AE5E22E3E5A18288E66A6184E92A4B63A1274DCE147A7728BB09C6A225E ] MBAMWebAccessControl C:\WINDOWS\system32\drivers\mwac.sys
06:02:50.0665 0x252c MBAMWebAccessControl - ok
06:02:50.0727 0x252c megasas - ok
06:02:50.0790 0x252c megasas2i - ok
06:02:50.0805 0x252c megasr - ok
06:02:50.0884 0x252c [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys
06:02:50.0915 0x252c MEIx64 - ok
06:02:50.0946 0x252c MessagingService - ok
06:02:50.0962 0x252c mlx4_bus - ok
06:02:51.0024 0x252c MMCSS - ok
06:02:51.0055 0x252c Modem - ok
06:02:51.0102 0x252c monitor - ok
06:02:51.0134 0x252c mouclass - ok
06:02:51.0134 0x252c mouhid - ok
06:02:51.0134 0x252c mountmgr - ok
06:02:51.0290 0x252c [ ADF79A49E942C91D1FC9863CBFDD6B58, C2B2A792C4717133DCAE6297EE3F5D985B11D3C1E68A8DC23985AC6B78ACDE98 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
06:02:51.0321 0x252c MozillaMaintenance - ok
06:02:51.0337 0x252c mpsdrv - ok
06:02:51.0399 0x252c MpsSvc - ok
06:02:51.0430 0x252c MRxDAV - ok
06:02:51.0462 0x252c mrxsmb - ok
06:02:51.0477 0x252c mrxsmb10 - ok
06:02:51.0509 0x252c mrxsmb20 - ok
06:02:51.0524 0x252c MsBridge - ok
06:02:51.0555 0x252c MSDTC - ok
06:02:51.0555 0x252c Msfs - ok
06:02:51.0587 0x252c msgpiowin32 - ok
06:02:51.0587 0x252c mshidkmdf - ok
06:02:51.0634 0x252c mshidumdf - ok
06:02:51.0634 0x252c msisadrv - ok
06:02:51.0696 0x252c MSiSCSI - ok
06:02:51.0696 0x252c msiserver - ok
06:02:51.0712 0x252c MSKSSRV - ok
06:02:51.0727 0x252c MsLldp - ok
06:02:51.0727 0x252c MSPCLOCK - ok
06:02:51.0743 0x252c MSPQM - ok
06:02:51.0774 0x252c MsRPC - ok
06:02:51.0805 0x252c mssmbios - ok
06:02:51.0821 0x252c MSTEE - ok
06:02:51.0837 0x252c MTConfig - ok
06:02:51.0837 0x252c Mup - ok
06:02:51.0852 0x252c mvumis - ok
06:02:51.0899 0x252c NativeWifiP - ok
06:02:52.0087 0x252c [ 003DDE9E91D324DDD86F11BF580FD627, 733674D5A6246BA2B4DE420AD89FE171ACCEA9EB5FC20F13F688A3910C1AA74C ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
06:02:52.0134 0x252c NAUpdate - ok
06:02:52.0196 0x252c NcaSvc - ok
06:02:52.0212 0x252c NcbService - ok
06:02:52.0212 0x252c NcdAutoSetup - ok
06:02:52.0243 0x252c ndfltr - ok
06:02:52.0290 0x252c NDIS - ok
06:02:52.0290 0x252c NdisCap - ok
06:02:52.0305 0x252c NdisImPlatform - ok
06:02:52.0321 0x252c NdisTapi - ok
06:02:52.0321 0x252c Ndisuio - ok
06:02:52.0337 0x252c NdisVirtualBus - ok
06:02:52.0337 0x252c NdisWan - ok
06:02:52.0352 0x252c ndiswanlegacy - ok
06:02:52.0352 0x252c ndproxy - ok
06:02:52.0368 0x252c Ndu - ok
06:02:52.0431 0x252c [ 76C4D5C98A808D8C8E0C46280036FAF8, A808DFA8B6949D44698122CDA43CD01B3B1CD14029B368F1686D023426239B87 ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
06:02:52.0477 0x252c Net Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
06:02:52.0477 0x252c Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
06:02:52.0477 0x252c Force sending object to P2P due to detect: Net Driver HPZ12
06:02:52.0493 0x252c Object send P2P result: false
06:02:52.0509 0x252c NetAdapterCx - ok
06:02:52.0509 0x252c NetBIOS - ok
06:02:52.0509 0x252c NetBT - ok
06:02:52.0524 0x252c Netlogon - ok
06:02:52.0540 0x252c Netman - ok
06:02:52.0602 0x252c netprofm - ok
06:02:52.0680 0x252c NetSetupSvc - ok
06:02:52.0993 0x252c NetTcpPortSharing - ok
06:02:53.0024 0x252c NgcCtnrSvc - ok
06:02:53.0071 0x252c NgcSvc - ok
06:02:53.0071 0x252c NlaSvc - ok
06:02:53.0087 0x252c Npfs - ok
06:02:53.0087 0x252c npsvctrig - ok
06:02:53.0118 0x252c nsi - ok
06:02:53.0118 0x252c nsiproxy - ok
06:02:53.0134 0x252c NTFS - ok
06:02:53.0149 0x252c Null - ok
06:02:53.0399 0x252c [ 62D705A1C4F8FBDD2941CCD2E9DEC206, 2E1F6127737D764AE6A35655C54ADE554333C3156CAA322C0FE5704A693A1BD7 ] NvContainerLocalSystem C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
06:02:53.0431 0x252c NvContainerLocalSystem - ok
06:02:53.0477 0x252c [ 62D705A1C4F8FBDD2941CCD2E9DEC206, 2E1F6127737D764AE6A35655C54ADE554333C3156CAA322C0FE5704A693A1BD7 ] NvContainerNetworkService C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
06:02:53.0493 0x252c NvContainerNetworkService - ok
06:02:53.0540 0x252c [ 207A78939B7BBA0EFE8BFA947A35E71C, BB7DDFED575F81CAB958DDC7CFF2D798EB14DAE633F49FA2229D98BDC489C0EE ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
06:02:53.0556 0x252c NVHDA - ok
06:02:54.0977 0x252c [ B360CFC497FF8070E37AEEA92CEF14BC, 3172A296192640474E9B78A83C66079D916523F04D950AA56B65D570BED633FA ] nvlddmkm C:\Windows\System32\DriverStore\FileRepository\nvmoi.inf_amd64_bab0214c8bd45ad2\nvlddmkm.sys
06:02:55.0446 0x252c nvlddmkm - ok
06:02:55.0681 0x252c [ 1E3277F1C9F62F90488D02869A9522B7, 464870ACE9BDF7A6A9C46701209BEED5C33454CFF44CDABEAF871E06F23FEF17 ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
06:02:55.0790 0x252c NvNetworkService - ok
06:02:55.0821 0x252c nvraid - ok
06:02:55.0821 0x252c nvstor - ok
06:02:55.0962 0x252c [ 6C672A80B4FBF160E2814EAE0AB3020B, FD5BDE067D29AA9FC20D7C571607D3AC351BFD65EF6E0C75374A2D9C0B17FED3 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
06:02:55.0993 0x252c NvStreamKms - ok
06:02:56.0056 0x252c [ 282423AA3B0648082647103A5C42B66C, 5C8DBE5A95C1232E7D0F84E6A8749550C0026F2139D136E94347C2FB2E772950 ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
06:02:56.0071 0x252c NvTelemetryContainer - ok
06:02:56.0087 0x252c [ 47E9348591CAACC64E41C9FD88D17A5B, 5B7AECFD5D35F55BDA8E6137D80B72166EA7AA0DF075BF4615D8EE50656CDDAF ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
06:02:56.0103 0x252c nvvad_WaveExtensible - ok
06:02:56.0134 0x252c [ 61BD2E2560FD1C5E0A8B8738816A0B93, 1057A6C4F7D04E81BFFD5B806295B3A5D12DE4D13F66E8542426D83D97E68C97 ] nvvhci C:\Windows\System32\drivers\nvvhci.sys
06:02:56.0149 0x252c nvvhci - ok
06:02:56.0181 0x252c OneSyncSvc - ok
06:02:56.0290 0x252c [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
06:02:56.0353 0x252c ose - ok
06:02:56.0696 0x252c [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
06:02:56.0915 0x252c osppsvc - ok
06:02:56.0931 0x252c p2pimsvc - ok
06:02:56.0931 0x252c p2psvc - ok
06:02:56.0946 0x252c Parport - ok
06:02:56.0962 0x252c partmgr - ok
06:02:56.0993 0x252c PcaSvc - ok
06:02:56.0993 0x252c pci - ok
06:02:57.0009 0x252c pciide - ok
06:02:57.0009 0x252c pcmcia - ok
06:02:57.0009 0x252c pcw - ok
06:02:57.0024 0x252c pdc - ok
06:02:57.0212 0x252c [ 8764DACFEF5E0973A16E93892957CDA8, 10C78A63AA21A2AD2596A3A416AA254EB0C596559ED83C7C30C6259D6FCA2867 ] PDF Architect 2 C:\Program Files (x86)\PDF Architect 2\ws.exe
06:02:57.0306 0x252c PDF Architect 2 - ok
06:02:57.0384 0x252c [ 6B808A3C06470B50D42817D9D7C2F28B, 0AAFACB08D035862E9E213B35081E7174E064F61D03B047AB5F87B92E6923C68 ] pdfforge CrashHandler C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
06:02:57.0712 0x252c pdfforge CrashHandler - ok
06:02:57.0728 0x252c PEAUTH - ok
06:02:57.0743 0x252c percsas2i - ok
06:02:57.0743 0x252c percsas3i - ok
06:02:57.0821 0x252c PerfHost - ok
06:02:57.0853 0x252c PhoneSvc - ok
06:02:57.0868 0x252c PimIndexMaintenanceSvc - ok
06:02:57.0962 0x252c pla - ok
06:02:57.0978 0x252c PlugPlay - ok
06:02:58.0009 0x252c [ D1A4DBB8A29F7FFC78378F47F9EA6B91, 782C7C6AA7A4A772C5E7392EA6D849BBCD159C30DF30918941C0BE058226D765 ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
06:02:58.0087 0x252c Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic ( 1 )
06:02:58.0087 0x252c Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
06:02:58.0103 0x252c PNRPAutoReg - ok
06:02:58.0103 0x252c PNRPsvc - ok
06:02:58.0118 0x252c PolicyAgent - ok
06:02:58.0134 0x252c Power - ok
06:02:58.0134 0x252c PptpMiniport - ok
06:02:58.0353 0x252c [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
06:02:58.0978 0x252c PrintNotify - ok
06:02:59.0025 0x252c Processor - ok
06:02:59.0056 0x252c ProfSvc - ok
06:02:59.0103 0x252c Psched - ok
06:02:59.0165 0x252c QWAVE - ok
06:02:59.0165 0x252c QWAVEdrv - ok
06:02:59.0181 0x252c RasAcd - ok
06:02:59.0275 0x252c RasAgileVpn - ok
06:02:59.0321 0x252c RasAuto - ok
06:02:59.0337 0x252c Rasl2tp - ok
06:02:59.0384 0x252c RasMan - ok
06:02:59.0384 0x252c RasPppoe - ok
06:02:59.0400 0x252c RasSstp - ok
06:02:59.0400 0x252c rdbss - ok
06:02:59.0431 0x252c rdpbus - ok
06:02:59.0431 0x252c RDPDR - ok
06:02:59.0571 0x252c RdpVideoMiniport - ok
06:02:59.0587 0x252c rdyboost - ok
06:02:59.0681 0x252c [ EA569D48B2E755AF6D96F03F3335D98A, EED2DCDF187A69F36A38129C8A1E0D6FE0EBF9232DEAF68A116E9A26E40AB636 ] Realtek11nSU C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
06:02:59.0728 0x252c Realtek11nSU - detected UnsignedFile.Multi.Generic ( 1 )
06:02:59.0728 0x252c Realtek11nSU ( UnsignedFile.Multi.Generic ) - warning
06:02:59.0743 0x252c ReFSv1 - ok
06:02:59.0775 0x252c RemoteAccess - ok
06:02:59.0775 0x252c RemoteRegistry - ok
06:02:59.0790 0x252c RetailDemo - ok
06:02:59.0821 0x252c RmSvc - ok
06:02:59.0821 0x252c RpcEptMapper - ok
06:02:59.0821 0x252c RpcLocator - ok
06:02:59.0837 0x252c RpcSs - ok
06:02:59.0837 0x252c rspndr - ok
06:02:59.0884 0x252c RTL8192su - ok
06:02:59.0884 0x252c s3cap - ok
06:02:59.0931 0x252c SamSs - ok
06:02:59.0946 0x252c sbp2port - ok
06:02:59.0962 0x252c SCardSvr - ok
06:03:00.0009 0x252c ScDeviceEnum - ok
06:03:00.0009 0x252c scfilter - ok
06:03:00.0025 0x252c Schedule - ok
06:03:00.0025 0x252c scmbus - ok
06:03:00.0025 0x252c scmdisk0101 - ok
06:03:00.0071 0x252c SCPolicySvc - ok
06:03:00.0087 0x252c sdbus - ok
06:03:00.0103 0x252c SDRSVC - ok
06:03:00.0103 0x252c sdstor - ok
06:03:00.0118 0x252c seclogon - ok
06:03:00.0134 0x252c SENS - ok
06:03:00.0150 0x252c SensorDataService - ok
06:03:00.0165 0x252c SensorService - ok
06:03:00.0181 0x252c SensrSvc - ok
06:03:00.0181 0x252c SerCx - ok
06:03:00.0196 0x252c SerCx2 - ok
06:03:00.0196 0x252c Serenum - ok
06:03:00.0212 0x252c Serial - ok
06:03:00.0212 0x252c sermouse - ok
06:03:00.0228 0x252c SessionEnv - ok
06:03:00.0228 0x252c sfloppy - ok
06:03:00.0259 0x252c SharedAccess - ok
06:03:00.0290 0x252c ShellHWDetection - ok
06:03:00.0353 0x252c shpamsvc - ok
06:03:00.0353 0x252c SiSRaid2 - ok
06:03:00.0368 0x252c SiSRaid4 - ok
06:03:00.0431 0x252c smphost - ok
06:03:00.0540 0x252c SmsRouter - ok
06:03:00.0556 0x252c SNMPTRAP - ok
06:03:00.0650 0x252c spaceport - ok
06:03:00.0681 0x252c SpbCx - ok
06:03:00.0712 0x252c Spooler - ok
06:03:00.0759 0x252c sppsvc - ok
06:03:00.0806 0x252c srv - ok
06:03:00.0837 0x252c srv2 - ok
06:03:00.0853 0x252c srvnet - ok
06:03:00.0884 0x252c SSDPSRV - ok
06:03:00.0900 0x252c SstpSvc - ok
06:03:00.0962 0x252c StateRepository - ok
06:03:00.0993 0x252c stexstor - ok
06:03:01.0009 0x252c stisvc - ok
06:03:01.0040 0x252c storahci - ok
06:03:01.0087 0x252c storflt - ok
06:03:01.0103 0x252c stornvme - ok
06:03:01.0212 0x252c storqosflt - ok
06:03:01.0228 0x252c StorSvc - ok
06:03:01.0243 0x252c storufs - ok
06:03:01.0243 0x252c storvsc - ok
06:03:01.0259 0x252c svsvc - ok
06:03:01.0275 0x252c swenum - ok
06:03:01.0275 0x252c swprv - ok
06:03:01.0337 0x252c Synth3dVsc - ok
06:03:01.0353 0x252c SysMain - ok
06:03:01.0368 0x252c SystemEventsBroker - ok
06:03:01.0400 0x252c TabletInputService - ok
06:03:01.0447 0x252c [ BB3F041ACE6FF23FD8F51B4CDDAB111B, A74544001291AB5E03E4B728CE7A336B17AA351C5E57C48536F62EAA756DFF7B ] tap0901 C:\Windows\System32\drivers\tap0901.sys
06:03:01.0493 0x252c tap0901 - ok
06:03:01.0525 0x252c [ F33FDC72298DF4BF9813A55D21F4EB31, 34AADF5115CA1B275FEF4238B420FE424F0E1D0FFD1606B24A0D594D7305CF1F ] taphss C:\Windows\system32\DRIVERS\taphss.sys
06:03:01.0556 0x252c taphss - ok
06:03:01.0618 0x252c [ FCEC2C65B9AF8B43C23F4765D17F4574, 71B501CFB0597D15897B7223AEA3C663F15EB1984A02511A6578520B67C6B18A ] taphss6 C:\Windows\System32\drivers\taphss6.sys
06:03:01.0634 0x252c taphss6 - ok
06:03:01.0665 0x252c TapiSrv - ok
06:03:01.0665 0x252c Tcpip - ok
06:03:01.0681 0x252c Tcpip6 - ok
06:03:01.0681 0x252c tcpipreg - ok
06:03:01.0697 0x252c tdx - ok
06:03:01.0728 0x252c terminpt - ok
06:03:01.0775 0x252c TermService - ok
06:03:01.0790 0x252c Themes - ok
06:03:01.0900 0x252c TieringEngineService - ok
06:03:01.0900 0x252c tiledatamodelsvc - ok
06:03:01.0915 0x252c TimeBrokerSvc - ok
06:03:01.0931 0x252c TPM - ok
06:03:01.0962 0x252c TrkWks - ok
06:03:02.0072 0x252c TrustedInstaller - ok
06:03:02.0072 0x252c tsusbflt - ok
06:03:02.0134 0x252c TsUsbGD - ok
06:03:02.0134 0x252c tunnel - ok
06:03:02.0259 0x252c [ AFDF84A53D56468AAE01090E62572810, 97098C7A054AA6AAA7BF2B101B8B2F4FD219D1518230F776A2821CE3A5C5A3A4 ] TVGOnlineUpdateSvc C:\Program Files (x86)\TVG\OnlineUpdate\OnlineUpdateSvc.exe
06:03:02.0322 0x252c TVGOnlineUpdateSvc - ok
06:03:02.0384 0x252c tzautoupdate - ok
06:03:02.0400 0x252c UASPStor - ok
06:03:02.0415 0x252c UcmCx0101 - ok
06:03:02.0415 0x252c UcmTcpciCx0101 - ok
06:03:02.0431 0x252c UcmUcsi - ok
06:03:02.0447 0x252c Ucx01000 - ok
06:03:02.0462 0x252c UdeCx - ok
06:03:02.0462 0x252c udfs - ok
06:03:02.0493 0x252c UEFI - ok
06:03:02.0509 0x252c Ufx01000 - ok
06:03:02.0525 0x252c UfxChipidea - ok
06:03:02.0540 0x252c ufxsynopsys - ok
06:03:02.0556 0x252c UI0Detect - ok
06:03:02.0634 0x252c [ 5357F9507B59C831C5CD79F1F6374A5E, 37013E7B442D532CC702F994FDA25860996E02B741E2D844DAD82FC49AED29C6 ] UimBus C:\Windows\System32\drivers\uimx64.sys
06:03:02.0697 0x252c UimBus - ok
06:03:02.0806 0x252c [ 001402EA0FB543F77F91090130FD029D, 4CCFC07F06AD9DC85BE732A00A7C9759DEA849054FB10A2598E1958A927B28DD ] Uim_IM C:\Windows\System32\Drivers\Uim_IMx64.sys
06:03:02.0915 0x252c Uim_IM - ok
06:03:02.0962 0x252c [ E75B35EEBC923B6DB2DBEA52E71A7892, 9ED7EB2EFA3F09FC4E123E23876C923045F94C169387E74EDAAFDA0980AAD00C ] Uim_VIM C:\Windows\System32\Drivers\uim_vimx64.sys
06:03:03.0087 0x252c Uim_VIM - ok
06:03:03.0103 0x252c umbus - ok
06:03:03.0118 0x252c UmPass - ok
06:03:03.0165 0x252c UmRdpService - ok
06:03:03.0181 0x252c UnistoreSvc - ok
06:03:03.0197 0x252c upnphost - ok
06:03:03.0212 0x252c UrsChipidea - ok
06:03:03.0212 0x252c UrsCx01000 - ok
06:03:03.0212 0x252c UrsSynopsys - ok
06:03:03.0275 0x252c usbccgp - ok
06:03:03.0275 0x252c usbcir - ok
06:03:03.0290 0x252c usbehci - ok
06:03:03.0290 0x252c usbhub - ok
06:03:03.0306 0x252c USBHUB3 - ok
06:03:03.0322 0x252c usbohci - ok
06:03:03.0337 0x252c usbprint - ok
06:03:03.0384 0x252c [ 2EC7B2C8123236B1233A77281D378DF7, D97DB59C9CAE2B8B33C707E8CEA7A65BF88712842CC715D270F7432A99D21BB6 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
06:03:03.0431 0x252c usbscan - ok
06:03:03.0431 0x252c usbser - ok
06:03:03.0447 0x252c USBSTOR - ok
06:03:03.0478 0x252c usbuhci - ok
06:03:03.0478 0x252c USBXHCI - ok
06:03:03.0509 0x252c UserDataSvc - ok
06:03:03.0603 0x252c UserManager - ok
06:03:03.0650 0x252c UsoSvc - ok
06:03:03.0650 0x252c VaultSvc - ok
06:03:03.0681 0x252c vdrvroot - ok
06:03:03.0712 0x252c vds - ok
06:03:03.0728 0x252c VerifierExt - ok
06:03:03.0790 0x252c vhdmp - ok
06:03:03.0806 0x252c vhf - ok
06:03:03.0822 0x252c vmbus - ok
06:03:03.0853 0x252c VMBusHID - ok
06:03:03.0853 0x252c vmgid - ok
06:03:03.0900 0x252c vmicguestinterface - ok
06:03:03.0915 0x252c vmicheartbeat - ok
06:03:03.0915 0x252c vmickvpexchange - ok
06:03:03.0915 0x252c vmicrdv - ok
06:03:03.0931 0x252c vmicshutdown - ok
06:03:03.0931 0x252c vmictimesync - ok
06:03:03.0947 0x252c vmicvmsession - ok
06:03:03.0947 0x252c vmicvss - ok
06:03:03.0978 0x252c volmgr - ok
06:03:04.0009 0x252c volmgrx - ok
06:03:04.0009 0x252c volsnap - ok
06:03:04.0009 0x252c volume - ok
06:03:04.0025 0x252c vpci - ok
06:03:04.0040 0x252c vsmraid - ok
06:03:04.0040 0x252c VSS - ok
06:03:04.0056 0x252c VSTXRAID - ok
06:03:04.0072 0x252c vwifibus - ok
06:03:04.0072 0x252c vwififlt - ok
06:03:04.0087 0x252c vwifimp - ok
06:03:04.0103 0x252c W32Time - ok
06:03:04.0119 0x252c WacomPen - ok
06:03:04.0181 0x252c WalletService - ok
06:03:04.0181 0x252c wanarp - ok
06:03:04.0197 0x252c wanarpv6 - ok
06:03:04.0228 0x252c wbengine - ok
06:03:04.0290 0x252c WbioSrvc - ok
06:03:04.0322 0x252c wcifs - ok
06:03:04.0337 0x252c Wcmsvc - ok
06:03:04.0353 0x252c wcncsvc - ok
06:03:04.0369 0x252c wcnfs - ok
06:03:04.0369 0x252c WdBoot - ok
06:03:04.0384 0x252c Wdf01000 - ok
06:03:04.0400 0x252c WdFilter - ok
06:03:04.0415 0x252c WdiServiceHost - ok
06:03:04.0415 0x252c WdiSystemHost - ok
06:03:04.0447 0x252c wdiwifi - ok
06:03:04.0447 0x252c WdNisDrv - ok
06:03:04.0540 0x252c WdNisSvc - ok
06:03:04.0603 0x252c WebClient - ok
06:03:04.0603 0x252c Wecsvc - ok
06:03:04.0619 0x252c WEPHOSTSVC - ok
06:03:04.0619 0x252c wercplsupport - ok
06:03:04.0650 0x252c WerSvc - ok
06:03:04.0665 0x252c WFPLWFS - ok
06:03:04.0681 0x252c WiaRpc - ok
06:03:04.0697 0x252c WIMMount - ok
06:03:04.0697 0x252c WinDefend - ok
06:03:04.0728 0x252c WindowsTrustedRT - ok
06:03:04.0744 0x252c WindowsTrustedRTProxy - ok
06:03:04.0790 0x252c WinHttpAutoProxySvc - ok
06:03:04.0822 0x252c WinMad - ok
06:03:05.0056 0x252c Winmgmt - ok
06:03:05.0119 0x252c WinRM - ok
06:03:05.0150 0x252c WINUSB - ok
06:03:05.0165 0x252c WinVerbs - ok
06:03:05.0244 0x252c wisvc - ok
06:03:05.0259 0x252c WlanSvc - ok
06:03:05.0290 0x252c wlidsvc - ok
06:03:05.0322 0x252c WmiAcpi - ok
06:03:05.0369 0x252c wmiApSrv - ok
06:03:05.0431 0x252c WMPNetworkSvc - ok
06:03:05.0447 0x252c Wof - ok
06:03:05.0478 0x252c workfolderssvc - ok
06:03:05.0525 0x252c WPDBusEnum - ok
06:03:05.0540 0x252c WpdUpFltr - ok
06:03:05.0556 0x252c WpnService - ok
06:03:05.0572 0x252c WpnUserService - ok
06:03:05.0572 0x252c ws2ifsl - ok
06:03:05.0603 0x252c wscsvc - ok
06:03:05.0650 0x252c WSDPrintDevice - ok
06:03:05.0650 0x252c WSearch - ok
06:03:05.0712 0x252c [ 82E8F5AA03DF7DBDB8A33F700D5D8CDA, 7EEB1B8F1430AFB06A18DC6107DBDD57EBBF473FF96F3578481EB89724823393 ] wsvd C:\Windows\system32\DRIVERS\wsvd.sys
06:03:05.0759 0x252c wsvd - ok
06:03:05.0775 0x252c wuauserv - ok
06:03:05.0790 0x252c WudfPf - ok
06:03:05.0790 0x252c WUDFRd - ok
06:03:05.0790 0x252c wudfsvc - ok
06:03:05.0806 0x252c WUDFWpdFs - ok
06:03:05.0822 0x252c WwanSvc - ok
06:03:05.0869 0x252c XblAuthManager - ok
06:03:05.0900 0x252c XblGameSave - ok
06:03:05.0947 0x252c xboxgip - ok
06:03:05.0994 0x252c XboxNetApiSvc - ok
06:03:06.0056 0x252c xinputhid - ok
06:03:06.0072 0x252c ================ Scan global ===============================
06:03:06.0275 0x252c [ Global ] - ok
06:03:06.0275 0x252c ================ Scan MBR ==================================
06:03:06.0337 0x252c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
06:03:11.0322 0x252c \Device\Harddisk0\DR0 - ok
06:03:11.0322 0x252c [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
06:03:11.0431 0x252c \Device\Harddisk1\DR1 - ok
06:03:11.0447 0x252c ================ Scan VBR ==================================
06:03:11.0478 0x252c [ 9A68B682D125BECBD31BF8C5BCE94578 ] \Device\Harddisk0\DR0\Partition1
06:03:11.0525 0x252c \Device\Harddisk0\DR0\Partition1 - ok
06:03:11.0556 0x252c [ 00B20D56693D368EA34A381CF4C8A2D7 ] \Device\Harddisk0\DR0\Partition2
06:03:11.0572 0x252c \Device\Harddisk0\DR0\Partition2 - ok
06:03:11.0619 0x252c [ 5AE8FF71A6831C08C2BB67D4E13F8B95 ] \Device\Harddisk0\DR0\Partition3
06:03:11.0666 0x252c \Device\Harddisk0\DR0\Partition3 - ok
06:03:11.0666 0x252c [ E3953DB350D378058EEB17757A3D9C7E ] \Device\Harddisk1\DR1\Partition1
06:03:11.0681 0x252c \Device\Harddisk1\DR1\Partition1 - ok
06:03:11.0681 0x252c [ 93EB66A986852B96F5D8770AF0931A1A ] \Device\Harddisk1\DR1\Partition2
06:03:11.0681 0x252c \Device\Harddisk1\DR1\Partition2 - ok
06:03:11.0681 0x252c [ F8D0336518C74735702E4FAF88981EF1 ] \Device\Harddisk1\DR1\Partition3
06:03:11.0697 0x252c \Device\Harddisk1\DR1\Partition3 - ok
06:03:11.0697 0x252c [ 256D099ED0C5E92D902C83B7E60EC8E7 ] \Device\Harddisk1\DR1\Partition4
06:03:11.0697 0x252c \Device\Harddisk1\DR1\Partition4 - ok
06:03:11.0697 0x252c [ 7C565020E6D5D889D902D6EEDFB01878 ] \Device\Harddisk1\DR1\Partition5
06:03:11.0713 0x252c \Device\Harddisk1\DR1\Partition5 - ok
06:03:11.0713 0x252c ================ Scan generic autorun ======================
06:03:11.0775 0x252c Logitech Download Assistant - ok
06:03:11.0775 0x252c ShadowPlay - ok
06:03:12.0900 0x252c [ 88F4C0223A76F670C68440CCFE9CECB3, 3A9C6EA49D9A72EFE4D794A1463F1626C1E608E43256627E21D51A9C3B78D618 ] c:\program files\emsisoft anti-malware\a2guard.exe
06:03:13.0088 0x252c emsisoft anti-malware - ok
06:03:13.0088 0x252c WindowsDefender - ok
06:03:13.0775 0x252c OneDriveSetup - ok
06:03:13.0791 0x252c OneDriveSetup - ok
06:03:14.0306 0x252c [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\Thomas Keune\AppData\Local\Microsoft\OneDrive\OneDrive.exe
06:03:14.0353 0x252c OneDrive - ok
06:03:14.0853 0x252c [ 55770AF6D09328F6580054B998A293F5, 8F557E7906257C43125AB02B3D41D9733D92106ABFDD4961E8A793D6D314F61A ] C:\Program Files (x86)\Music Recorder\Music Recorder 2016\AudialsNotifier.exe
06:03:14.0994 0x252c AudialsNotifier - ok
06:03:15.0885 0x252c [ A95474B14C558CF85A79C18C9356CBCA, 16CCDEE1A2A0930A1EACF1D5E81955CB66DDB872DD2F5602058D6392B80EB56C ] C:\Program Files\CCleaner\CCleaner64.exe
06:03:16.0182 0x252c CCleaner Monitoring - ok
06:03:16.0275 0x252c Uninstall C:\Users\Thomas Keune\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64 - ok
06:03:16.0275 0x252c OneDriveSetup - ok
06:03:16.0353 0x252c WAB Migrate - ok
06:03:16.0432 0x252c AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x61100 ( enabled : updated )
06:03:16.0432 0x252c AV detected via SS2: Emsisoft Anti-Malware, C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2start.exe ( 2017.1.1.7166 ), 0x41000 ( enabled : updated )
06:03:16.0650 0x252c Win FW state via NFP2: enabled ( trusted )
06:03:16.0650 0x252c ============================================================
06:03:16.0650 0x252c Scan finished
06:03:16.0650 0x252c ============================================================
06:03:16.0650 0x1f24 Detected object count: 6
06:03:16.0650 0x1f24 Actual detected object count: 6
06:03:32.0495 0x1f24 chip1click ( UnsignedFile.Multi.Generic ) - skipped by user
06:03:32.0495 0x1f24 chip1click ( UnsignedFile.Multi.Generic ) - User select action: Skip
06:03:32.0495 0x1f24 FreemakeVideoCapture ( UnsignedFile.Multi.Generic ) - skipped by user
06:03:32.0495 0x1f24 FreemakeVideoCapture ( UnsignedFile.Multi.Generic ) - User select action: Skip
06:03:32.0495 0x1f24 HPSLPSVC ( UnsignedFile.Multi.Generic ) - skipped by user
06:03:32.0495 0x1f24 HPSLPSVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
06:03:32.0495 0x1f24 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
06:03:32.0495 0x1f24 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
06:03:32.0495 0x1f24 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
06:03:32.0495 0x1f24 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
06:03:32.0495 0x1f24 Realtek11nSU ( UnsignedFile.Multi.Generic ) - skipped by user
06:03:32.0495 0x1f24 Realtek11nSU ( UnsignedFile.Multi.Generic ) - User select action: Skip Und das sagt mein Defender der sich gemeldet hat:
TrojanDownloader: Win32/Dofoil.T
Trojan: Win32/Matsnu.Q
TrojanDownloader: Win32/Dofoil.T |