Hakan-TR | 20.07.2017 22:27 | TDSS-Killer Code:
23:23:20.0196 0x2584 TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02
23:23:20.0197 0x2584 UEFI system
23:23:26.0720 0x2584 ============================================================
23:23:26.0720 0x2584 Current date / time: 2017/07/20 23:23:26.0720
23:23:26.0721 0x2584 SystemInfo:
23:23:26.0721 0x2584
23:23:26.0721 0x2584 OS Version: 10.0.14393 ServicePack: 0.0
23:23:26.0721 0x2584 Product type: Workstation
23:23:26.0721 0x2584 ComputerName: LAPTOP-9AQNOV5G
23:23:26.0721 0x2584 UserName: durma
23:23:26.0721 0x2584 Windows directory: C:\WINDOWS
23:23:26.0721 0x2584 System windows directory: C:\WINDOWS
23:23:26.0721 0x2584 Running under WOW64
23:23:26.0721 0x2584 Processor architecture: Intel x64
23:23:26.0721 0x2584 Number of processors: 4
23:23:26.0721 0x2584 Page size: 0x1000
23:23:26.0721 0x2584 Boot type: Normal boot
23:23:26.0721 0x2584 CodeIntegrityOptions = 0x00000001
23:23:26.0721 0x2584 ============================================================
23:23:27.0545 0x2584 KLMD registered as C:\WINDOWS\system32\drivers\70707811.sys
23:23:27.0545 0x2584 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.1480, osProperties = 0x19
23:23:27.0735 0x2584 System UUID: {D11415EB-4B5B-B767-61E2-E65E366651C1}
23:23:28.0172 0x2584 Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
23:23:28.0189 0x2584 ============================================================
23:23:28.0189 0x2584 \Device\Harddisk0\DR0:
23:23:28.0189 0x2584 GPT partitions:
23:23:28.0190 0x2584 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {67A56520-D485-4AE1-B3A3-D80789A36FD1}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x82000
23:23:28.0190 0x2584 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {CABFCC5F-FDA4-4519-9D59-CF0C5BC1901C}, Name: Microsoft reserved partition, StartLBA 0x82800, BlocksNum 0x8000
23:23:28.0190 0x2584 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {485E1334-DD94-42C1-AAE2-B366D8671341}, Name: Basic data partition, StartLBA 0x8A800, BlocksNum 0xE6C8B8BD
23:23:28.0190 0x2584 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {B7ECEDE1-D79D-4942-9D1A-25AE37537B0D}, Name: , StartLBA 0xE6D16800, BlocksNum 0x1A1000
23:23:28.0190 0x2584 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {4C1D65D0-D022-4EE7-B319-C401773D18B9}, Name: Basic data partition, StartLBA 0xE6EB7800, BlocksNum 0x1F4E800
23:23:28.0190 0x2584 MBR partitions:
23:23:28.0190 0x2584 ============================================================
23:23:28.0224 0x2584 C: <-> \Device\Harddisk0\DR0\Partition3
23:23:28.0290 0x2584 D: <-> \Device\Harddisk0\DR0\Partition5
23:23:28.0290 0x2584 ============================================================
23:23:28.0290 0x2584 Initialize success
23:23:28.0290 0x2584 ============================================================
23:24:24.0357 0x1498 ============================================================
23:24:24.0357 0x1498 Scan started
23:24:24.0357 0x1498 Mode: Manual; SigCheck; TDLFS;
23:24:24.0357 0x1498 ============================================================
23:24:24.0357 0x1498 KSN ping started
23:24:24.0423 0x1498 KSN ping finished: true
23:24:27.0172 0x1498 ================ Scan system memory ========================
23:24:27.0172 0x1498 System memory - ok
23:24:27.0172 0x1498 ================ Scan services =============================
23:24:27.0367 0x1498 1394ohci - ok
23:24:27.0371 0x1498 3ware - ok
23:24:27.0394 0x1498 ACPI - ok
23:24:27.0397 0x1498 AcpiDev - ok
23:24:27.0401 0x1498 acpiex - ok
23:24:27.0404 0x1498 acpipagr - ok
23:24:27.0426 0x1498 AcpiPmi - ok
23:24:27.0428 0x1498 acpitime - ok
23:24:27.0530 0x1498 [ 8D6BA8E7676038A27FD4ECF12CC744B0, F5D59B764DCB4A06A51939533DC7B2391FD68E3979C48939C023A60DCE0D2101 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
23:24:27.0575 0x1498 AdobeARMservice - ok
23:24:27.0614 0x1498 ADP80XX - ok
23:24:27.0637 0x1498 AFD - ok
23:24:27.0648 0x1498 ahcache - ok
23:24:27.0662 0x1498 AJRouter - ok
23:24:27.0677 0x1498 ALG - ok
23:24:27.0716 0x1498 [ 1E108A1759AAFA8624A85A663F529965, 2470E95DE0C0826E8D7626D71BB9B34D3802535D74CE5D13B103785894766F87 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
23:24:27.0745 0x1498 AMD External Events Utility - ok
23:24:27.0749 0x1498 AmdK8 - ok
23:24:27.0760 0x1498 amdkmdag - ok
23:24:27.0821 0x1498 [ 9EA22FCFEB3A8616CBAF48E62446DED8, A0FBC020058602092C3545675E58FB98645A862269DF7D8697802DA5D79B4056 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
23:24:27.0846 0x1498 amdkmdap - ok
23:24:27.0849 0x1498 AmdPPM - ok
23:24:27.0853 0x1498 amdsata - ok
23:24:27.0855 0x1498 amdsbs - ok
23:24:27.0859 0x1498 amdxata - ok
23:24:27.0902 0x1498 AppHostSvc - ok
23:24:27.0905 0x1498 AppID - ok
23:24:27.0933 0x1498 AppIDSvc - ok
23:24:27.0947 0x1498 Appinfo - ok
23:24:27.0968 0x1498 applockerfltr - ok
23:24:28.0005 0x1498 AppReadiness - ok
23:24:28.0023 0x1498 AppXSvc - ok
23:24:28.0045 0x1498 arcsas - ok
23:24:28.0171 0x1498 aspnet_state - ok
23:24:28.0442 0x1498 [ 29D245C8AE41A5733838B7FE32B6C9FE, 9FB660553704B8A73D88C968ABA328C9097AD97AA2B1921AC5E125C9C65B0C1F ] aswbIDSAgent C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
23:24:28.0608 0x1498 aswbIDSAgent - ok
23:24:28.0671 0x1498 [ 18DDC06277F4C29A8A19A8E5A61530E1, D61FD0B1A1DAF66CADB19849E6090DE23C72DEDD447D6B56FF7106D35AF10F24 ] aswbidsdriver C:\WINDOWS\system32\drivers\aswbidsdrivera.sys
23:24:28.0709 0x1498 aswbidsdriver - ok
23:24:28.0734 0x1498 [ AE4CC3E6F7CA57B38FF42DB7C3182618, 7656D4558ADC78E8BD0FE633DB7A11A414AFF728249F753993C07D0FD84E56BD ] aswbidsh C:\WINDOWS\system32\drivers\aswbidsha.sys
23:24:28.0754 0x1498 aswbidsh - ok
23:24:28.0782 0x1498 [ 10F4D87864D4336A17C39A60512EC494, EF34ECF073B438B661E57863904A1567DC25DA491A0BE736441E46A7D9484251 ] aswblog C:\WINDOWS\system32\drivers\aswbloga.sys
23:24:28.0804 0x1498 aswblog - ok
23:24:28.0834 0x1498 [ FE617BF58A51BBFD819F06965EA9E759, 3A5E53D783B40BBAD27BA40894A1555CB6777D20BB13CEA2C80E72898DCC9948 ] aswbuniv C:\WINDOWS\system32\drivers\aswbuniva.sys
23:24:28.0850 0x1498 aswbuniv - ok
23:24:28.0890 0x1498 [ A332C57F39A94F888A5BAA991ABBB395, 78D55F9ABBC8EB565BA2E8DB881F0F4241FECA06DB46D5F453780252ECF7DE1F ] aswHwid C:\WINDOWS\system32\drivers\aswHwid.sys
23:24:28.0974 0x1498 aswHwid - ok
23:24:29.0003 0x1498 [ 07E8B72CEA29F31AB1975C15AA72A2B0, B8672298D3A5F6C599147F50933D0239C8C68BD583DCA1C11405195E6389E824 ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
23:24:29.0057 0x1498 aswKbd - ok
23:24:29.0088 0x1498 [ 404ABD6F9D057FB054D8DDB602F60444, C3D78EF41E5E0CFE6A6E360395A4803B910C14D33782FF1466208B334E96F76A ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys
23:24:29.0169 0x1498 aswMonFlt - ok
23:24:29.0205 0x1498 [ 92576512177C98D1F48F11322DA717B9, B2724080A9DBC11A3E1363C2EB2E935A324A82D17AFA3631CFE410071E474A10 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr2.sys
23:24:29.0254 0x1498 aswRdr - ok
23:24:29.0269 0x1498 [ 663ABA1DDF8182D1416F5BF066EAED35, 8D9C2DBD803711D9DD01F2E8CE4CB3F8B676A8B373DEDC5310F289D6CC0282DD ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
23:24:29.0311 0x1498 aswRvrt - ok
23:24:29.0354 0x1498 [ 7851937E78E1B6361A8EDA4A6AAEBFE8, 07BFA43DCE570BBA03CB8C2DDC3A5F145EB2EBCB591EDD94D143995A82E306A4 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
23:24:29.0437 0x1498 aswSnx - ok
23:24:29.0465 0x1498 [ FB13D6EB42896ADDA1A8395E1298AC25, C16C51E75D2FFEB37E91289B92FA9B48A1BAD1FFCBCA18790C55B101BE375C2B ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
23:24:29.0531 0x1498 aswSP - ok
23:24:29.0567 0x1498 [ 774696CAAAAD5F63E80472370295DC83, AC6D4A50E5A64D986995B568CE65FFA2802983DE063071818ECE34C72050770E ] aswStm C:\WINDOWS\system32\drivers\aswStm.sys
23:24:29.0592 0x1498 aswStm - ok
23:24:29.0614 0x1498 [ 318CD52B4066304CD5D82B46504CA62F, A613743E2FE9EE1F3D64A3F3CFCB8F8E2E4E2F3F43422DDB604EC6002F35ECB2 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
23:24:29.0657 0x1498 aswVmm - ok
23:24:29.0683 0x1498 AsyncMac - ok
23:24:29.0709 0x1498 atapi - ok
23:24:29.0748 0x1498 AudioEndpointBuilder - ok
23:24:29.0785 0x1498 Audiosrv - ok
23:24:29.0818 0x1498 [ 9037E3CDBADF7AAF14BF0091CCCB6783, 890A4A6D280586F6296E76A9F143E1BDEC187F68B26CB740E04890942F77084D ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
23:24:29.0842 0x1498 avast! Antivirus - ok
23:24:29.0872 0x1498 AxInstSV - ok
23:24:29.0875 0x1498 b06bdrv - ok
23:24:29.0900 0x1498 BasicDisplay - ok
23:24:29.0940 0x1498 BasicRender - ok
23:24:29.0965 0x1498 bcmfn - ok
23:24:29.0973 0x1498 bcmfn2 - ok
23:24:29.0988 0x1498 BDESVC - ok
23:24:30.0008 0x1498 Beep - ok
23:24:30.0015 0x1498 BFE - ok
23:24:30.0054 0x1498 BITS - ok
23:24:30.0095 0x1498 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD, 17BFFC5DF609CE3B2F0CAB4BD6C118608C66A3AD86116A47E90B2BB7D8954122 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
23:24:30.0118 0x1498 Bonjour Service - ok
23:24:30.0142 0x1498 bowser - ok
23:24:30.0155 0x1498 BrokerInfrastructure - ok
23:24:30.0158 0x1498 Browser - ok
23:24:30.0250 0x1498 [ 0958E70CD38E2020B767DC5237E041BE, F6CB7FC7331D0224591C46F4752207EA5B13E30737D410E39A1B4F19FC9EF9C2 ] BTDevManager C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
23:24:30.0262 0x1498 BTDevManager - ok
23:24:30.0287 0x1498 BthAvrcpTg - ok
23:24:30.0290 0x1498 BthHFEnum - ok
23:24:30.0293 0x1498 bthhfhid - ok
23:24:30.0308 0x1498 BthHFSrv - ok
23:24:30.0311 0x1498 BTHMODEM - ok
23:24:30.0327 0x1498 BTHPORT - ok
23:24:30.0342 0x1498 bthserv - ok
23:24:30.0395 0x1498 BTHUSB - ok
23:24:30.0400 0x1498 buttonconverter - ok
23:24:30.0440 0x1498 [ 60EB6A4CE3E21887D302350631C16F26, 4270EFA22285C1A9336CF1220761E416950D2DA9C6A40D1D8452686CD5040DAB ] CapImg C:\WINDOWS\System32\drivers\capimg.sys
23:24:30.0550 0x1498 CapImg - ok
23:24:30.0556 0x1498 cdfs - ok
23:24:30.0578 0x1498 CDPSvc - ok
23:24:30.0590 0x1498 CDPUserSvc - ok
23:24:30.0705 0x1498 cdrom - ok
23:24:30.0732 0x1498 CertPropSvc - ok
23:24:30.0752 0x1498 cht4iscsi - ok
23:24:30.0754 0x1498 cht4vbd - ok
23:24:30.0757 0x1498 circlass - ok
23:24:30.0782 0x1498 CLFS - ok
23:24:30.0995 0x1498 [ DB7156423DF0B216FD8E8C3DE25DB2C7, D2BEE2AD7CD7F36EEB4154A59E86707D62A57F926D1A3B02C15F4DF15F260D5B ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
23:24:31.0101 0x1498 ClickToRunSvc - ok
23:24:31.0128 0x1498 ClipSVC - ok
23:24:31.0140 0x1498 clreg - ok
23:24:31.0177 0x1498 [ 228CB7727EC19833A74DAA5BE8627114, 7ABDEABF648C0CF04C736D9F1056CD54D5913837E1543CC358FDDFA9389934EC ] clwvd6 C:\WINDOWS\system32\DRIVERS\clwvd6.sys
23:24:31.0207 0x1498 clwvd6 - ok
23:24:31.0211 0x1498 CmBatt - ok
23:24:31.0228 0x1498 CNG - ok
23:24:31.0236 0x1498 cnghwassist - ok
23:24:31.0290 0x1498 CompositeBus - ok
23:24:31.0292 0x1498 COMSysApp - ok
23:24:31.0297 0x1498 condrv - ok
23:24:31.0321 0x1498 CoreMessagingRegistrar - ok
23:24:31.0387 0x1498 [ 98B3066540C43BF5349BDB4B5C4CE04F, 97DA0394C77E41360D7F6A4F998D00642DF665384C20E0029D63C99922E9906D ] cphs C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHeciSvc.exe
23:24:31.0406 0x1498 cphs - ok
23:24:31.0436 0x1498 [ 943D29E61044350319CCC5BE0E1A9329, 7269A08BAB6B790A717790118C0CD1EC51DC994CBEFA49AE036477651C83E79B ] cplspcon C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHDCPSvc.exe
23:24:31.0454 0x1498 cplspcon - ok
23:24:31.0480 0x1498 CryptSvc - ok
23:24:31.0508 0x1498 dam - ok
23:24:31.0618 0x1498 [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdate C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
23:24:31.0633 0x1498 dbupdate - ok
23:24:31.0637 0x1498 [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdatem C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
23:24:31.0649 0x1498 dbupdatem - ok
23:24:31.0652 0x1498 dbx - ok
23:24:31.0684 0x1498 [ F0A3CA65871C39CB5BE6475A139536DD, 4715426A4F5AAA27BBC359D8F810005613A26A31439CC4C59C98E7220308238D ] DbxSvc C:\WINDOWS\system32\DbxSvc.exe
23:24:31.0697 0x1498 DbxSvc - ok
23:24:31.0719 0x1498 DcomLaunch - ok
23:24:31.0721 0x1498 DcpSvc - ok
23:24:31.0732 0x1498 defragsvc - ok
23:24:31.0749 0x1498 DeviceAssociationService - ok
23:24:31.0769 0x1498 DeviceInstall - ok
23:24:31.0791 0x1498 DevQueryBroker - ok
23:24:31.0817 0x1498 Dfsc - ok
23:24:31.0854 0x1498 [ 5F78930AAB3900102EA8ACDD38F97324, 49CAE29CC7B1B846BDE603B1A411833162ACC1A9D1608BFDF67C2EA3A0EE0F85 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
23:24:31.0912 0x1498 dg_ssudbus - ok
23:24:31.0952 0x1498 Dhcp - ok
23:24:32.0020 0x1498 diagnosticshub.standardcollector.service - ok
23:24:32.0062 0x1498 DiagTrack - ok
23:24:32.0083 0x1498 disk - ok
23:24:32.0111 0x1498 DmEnrollmentSvc - ok
23:24:32.0114 0x1498 dmvsc - ok
23:24:32.0150 0x1498 dmwappushservice - ok
23:24:32.0178 0x1498 Dnscache - ok
23:24:32.0182 0x1498 dot3svc - ok
23:24:32.0186 0x1498 DPS - ok
23:24:32.0230 0x1498 [ C1283B0BEE35F9AF3511E0EBA71F311C, 542D560B654EA4E4708837231A4A967FB4DF5CDB190B7D763E92B1F6FCB255B4 ] dptf_cpu C:\WINDOWS\System32\drivers\dptf_cpu.sys
23:24:32.0281 0x1498 dptf_cpu - ok
23:24:32.0309 0x1498 drmkaud - ok
23:24:32.0323 0x1498 DsmSvc - ok
23:24:32.0326 0x1498 DsSvc - ok
23:24:32.0335 0x1498 DXGKrnl - ok
23:24:32.0345 0x1498 EapHost - ok
23:24:32.0348 0x1498 ebdrv - ok
23:24:32.0371 0x1498 EFS - ok
23:24:32.0375 0x1498 EhStorClass - ok
23:24:32.0408 0x1498 EhStorTcgDrv - ok
23:24:32.0423 0x1498 embeddedmode - ok
23:24:32.0456 0x1498 EntAppSvc - ok
23:24:32.0485 0x1498 [ D315FF43E23DF424ECEC2F6C930203E4, 68940EDA34DC4945CDD0D8018D96A0DA8F99F16A930946D14E4FECEE033FCB80 ] EpsonScanSvc C:\WINDOWS\system32\EscSvc64.exe
23:24:32.0498 0x1498 EpsonScanSvc - ok
23:24:32.0502 0x1498 ErrDev - ok
23:24:32.0606 0x1498 [ 8A00CC653B8F02503C250FC1B9475807, 496517DD9E0BFFE03701E813EB7732578482ABA808771BE7889A27E1E2FEB647 ] esifsvc C:\WINDOWS\SysWoW64\esif_uf.exe
23:24:32.0645 0x1498 esifsvc - ok
23:24:32.0692 0x1498 [ 99984B5D3378F8236F3A85E51ACEDD16, 73EE5B93C27C09F15BBAEADC8A293CB14FDD1E3DC65DDC0C665549D71F307D33 ] esif_lf C:\WINDOWS\system32\DRIVERS\esif_lf.sys
23:24:32.0713 0x1498 esif_lf - ok
23:24:32.0734 0x1498 EventSystem - ok
23:24:32.0737 0x1498 exfat - ok
23:24:32.0740 0x1498 fastfat - ok
23:24:32.0764 0x1498 Fax - ok
23:24:32.0766 0x1498 fdc - ok
23:24:32.0769 0x1498 fdPHost - ok
23:24:32.0772 0x1498 FDResPub - ok
23:24:32.0823 0x1498 fhsvc - ok
23:24:32.0850 0x1498 FileCrypt - ok
23:24:32.0853 0x1498 FileInfo - ok
23:24:32.0871 0x1498 Filetrace - ok
23:24:32.0874 0x1498 flpydisk - ok
23:24:32.0876 0x1498 FltMgr - ok
23:24:32.0902 0x1498 FontCache - ok
23:24:33.0020 0x1498 FontCache3.0.0.0 - ok
23:24:33.0096 0x1498 FrameServer - ok
23:24:33.0115 0x1498 FsDepends - ok
23:24:33.0123 0x1498 Fs_Rec - ok
23:24:33.0131 0x1498 fvevol - ok
23:24:33.0215 0x1498 [ 714CC2E431883AF55A9686FF637ED2D2, 7944ECC2401E808D74D238F11DF0A2759BC99984284CD75D95D9792EA8EECD28 ] GamesAppIntegrationService C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
23:24:33.0233 0x1498 GamesAppIntegrationService - ok
23:24:33.0256 0x1498 [ E3E4F1CEF352E2AA9DB1EDAF5063313E, 705B0E1ECE7CF1A0E68ECF83F3A6F62A6A17EC40B8E146AE3966F26D8CF244BB ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
23:24:33.0270 0x1498 GamesAppService - ok
23:24:33.0293 0x1498 gencounter - ok
23:24:33.0296 0x1498 genericusbfn - ok
23:24:33.0299 0x1498 GPIOClx0101 - ok
23:24:33.0339 0x1498 gpsvc - ok
23:24:33.0342 0x1498 GpuEnergyDrv - ok
23:24:33.0391 0x1498 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:24:33.0406 0x1498 gupdate - ok
23:24:33.0410 0x1498 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
23:24:33.0420 0x1498 gupdatem - ok
23:24:33.0452 0x1498 [ 7F79205B4EFA98F0767309479C8C01C6, 4B576903A83F33A8CF31D3887144A3D51C56D1187115C83AC99C0E9F6B4BF128 ] Hamachi C:\WINDOWS\system32\DRIVERS\Hamdrv.sys
23:24:33.0510 0x1498 Hamachi - ok
23:24:33.0513 0x1498 HDAudBus - ok
23:24:33.0516 0x1498 HidBatt - ok
23:24:33.0519 0x1498 HidBth - ok
23:24:33.0523 0x1498 hidi2c - ok
23:24:33.0525 0x1498 hidinterrupt - ok
23:24:33.0529 0x1498 HidIr - ok
23:24:33.0555 0x1498 hidserv - ok
23:24:33.0613 0x1498 HidUsb - ok
23:24:33.0624 0x1498 HomeGroupListener - ok
23:24:33.0641 0x1498 HomeGroupProvider - ok
23:24:33.0726 0x1498 [ 7B7DE6B3DC30F3246958F42C67A6F7BB, 4B66B90CFEC2231B905B21DECC4EC7C6500E546F080A452EF67E724EDF37ADD9 ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
23:24:33.0752 0x1498 hpqwmiex - ok
23:24:33.0756 0x1498 HpSAMD - ok
23:24:33.0816 0x1498 [ E34BA2A12721E2B656719CD7F3835F6B, A0502D39BF9182F73CB95CC3AF6B9C4D970188461317FB7A5485221F57906A55 ] HPSupportSolutionsFrameworkService c:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
23:24:33.0835 0x1498 HPSupportSolutionsFrameworkService - ok
23:24:33.0867 0x1498 [ E7F6B3C8F78B4A49E283DB4619B26841, 1653F2CE201A8794D64A5E60B257CB6691D9C4B61CCDA415E0355E56506DFA47 ] HPWMISVC c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
23:24:33.0886 0x1498 HPWMISVC - ok
23:24:33.0898 0x1498 HTTP - ok
23:24:33.0921 0x1498 HvHost - ok
23:24:33.0941 0x1498 hvservice - ok
23:24:33.0957 0x1498 hwpolicy - ok
23:24:33.0969 0x1498 hyperkbd - ok
23:24:33.0990 0x1498 i8042prt - ok
23:24:33.0994 0x1498 iagpio - ok
23:24:33.0997 0x1498 iai2c - ok
23:24:34.0002 0x1498 iaLPSS2i_GPIO2 - ok
23:24:34.0005 0x1498 iaLPSS2i_I2C - ok
23:24:34.0008 0x1498 iaLPSSi_GPIO - ok
23:24:34.0012 0x1498 iaLPSSi_I2C - ok
23:24:34.0075 0x1498 [ 827933B762F90EB4E7690D4484190D77, 7400FA7CB1FDCC3142D9F56156C41427FB394CA32BC8887D17B1FB2DFC962C34 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
23:24:34.0174 0x1498 iaStorA - ok
23:24:34.0178 0x1498 iaStorAV - ok
23:24:34.0181 0x1498 iaStorV - ok
23:24:34.0184 0x1498 ibbus - ok
23:24:34.0214 0x1498 icssvc - ok
23:24:34.0566 0x1498 [ 0A136D4B31D5B6CCA29B913BE080B73F, 5795BC0B93927E1004BA46C105C3E8412DB80B505958E36DF86EC4570C1EA0E6 ] igfx C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igdkmd64.sys
23:24:34.0755 0x1498 igfx - ok
23:24:34.0786 0x1498 [ 936B5DBBC861245A6319F18EA64A99F9, FC1EF74E77D99714AE563A3CF585C9D09F50A664181E99BD2E972C51CC7D3F63 ] igfxCUIService2.0.0.0 C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxCUIService.exe
23:24:34.0803 0x1498 igfxCUIService2.0.0.0 - ok
23:24:34.0831 0x1498 IKEEXT - ok
23:24:34.0847 0x1498 IndirectKmd - ok
23:24:35.0039 0x1498 [ 69D1CE9AF11152D578CFE7C56A53FC8D, 321FB6E4741EA4730A04EC8772E61A068754CBC3F0C51CF62ED485D823C1740C ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
23:24:35.0210 0x1498 IntcAzAudAddService - ok
23:24:35.0261 0x1498 [ A6087A824507CAB1ED568895F8081950, 53ADFCC6E795D47A7197AC372DB53E4F95B10409E5AFA7A40CC252ADBE84E8F4 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
23:24:35.0301 0x1498 IntcDAud - ok
23:24:35.0449 0x1498 [ B63CF22D1AD2ABDC39D85851B2BEAA6D, 37E9043BABB5895BFD2B59AFB60C438B992C6EAA1B5FDE5B3445314343F4C406 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
23:24:35.0473 0x1498 Intel(R) Capability Licensing Service TCP IP Interface - ok
23:24:35.0497 0x1498 intelide - ok
23:24:35.0521 0x1498 intelpep - ok
23:24:35.0525 0x1498 intelppm - ok
23:24:35.0539 0x1498 iorate - ok
23:24:35.0542 0x1498 IpFilterDriver - ok
23:24:35.0581 0x1498 iphlpsvc - ok
23:24:35.0600 0x1498 IPMIDRV - ok
23:24:35.0603 0x1498 IPNAT - ok
23:24:35.0607 0x1498 irda - ok
23:24:35.0610 0x1498 IRENUM - ok
23:24:35.0639 0x1498 irmon - ok
23:24:35.0656 0x1498 isapnp - ok
23:24:35.0680 0x1498 iScsiPrt - ok
23:24:35.0747 0x1498 [ DE70C5C10803C700DC1CFDE2D5CF207A, 4D11DE8B986C6966B66E1D6E931A72A1E9FA8D0B5B9EF57EF3EEDD09D0BE0B4E ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
23:24:35.0763 0x1498 jhi_service - ok
23:24:35.0801 0x1498 kbdclass - ok
23:24:35.0808 0x1498 kbdhid - ok
23:24:35.0816 0x1498 kdnic - ok
23:24:35.0858 0x1498 KeyIso - ok
23:24:35.0883 0x1498 KSecDD - ok
23:24:35.0892 0x1498 KSecPkg - ok
23:24:35.0895 0x1498 ksthunk - ok
23:24:35.0903 0x1498 KtmRm - ok
23:24:35.0917 0x1498 LanmanServer - ok
23:24:35.0935 0x1498 LanmanWorkstation - ok
23:24:35.0939 0x1498 lfsvc - ok
23:24:35.0962 0x1498 LicenseManager - ok
23:24:35.0965 0x1498 lltdio - ok
23:24:35.0968 0x1498 lltdsvc - ok
23:24:35.0978 0x1498 lmhosts - ok
23:24:35.0983 0x1498 LSI_SAS - ok
23:24:35.0985 0x1498 LSI_SAS2i - ok
23:24:35.0989 0x1498 LSI_SAS3i - ok
23:24:35.0993 0x1498 LSI_SSS - ok
23:24:36.0027 0x1498 LSM - ok
23:24:36.0030 0x1498 luafv - ok
23:24:36.0058 0x1498 MapsBroker - ok
23:24:36.0086 0x1498 [ 913F4230E29E312D1B4B02E2BAC67C87, 5C772DA7F2454CAFEA981E18ABCE717FE0D065EE996FB758817F3EF775B0AC14 ] MBAMSwissArmy C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
23:24:36.0101 0x1498 MBAMSwissArmy - ok
23:24:36.0104 0x1498 megasas - ok
23:24:36.0155 0x1498 [ 2CF0CB2A0ED68C5455371E84C16F9627, 1C9166B52140145F1968E83E52BFF041250811B23C770FE181A18A4BA060CA81 ] megasas2i C:\WINDOWS\system32\drivers\MegaSas2i.sys
23:24:36.0232 0x1498 megasas2i - ok
23:24:36.0235 0x1498 megasr - ok
23:24:36.0292 0x1498 [ 48F64A35BA9F2E4AC0587DDA555FF951, 77FE2BE86ADCE103F4220A641139C42B1407CF8EFFEB66F841ABF9CFC3621558 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
23:24:36.0334 0x1498 MEIx64 - ok
23:24:36.0356 0x1498 MessagingService - ok
23:24:36.0440 0x1498 mlx4_bus - ok
23:24:36.0443 0x1498 MMCSS - ok
23:24:36.0447 0x1498 Modem - ok
23:24:36.0467 0x1498 monitor - ok
23:24:36.0470 0x1498 mouclass - ok
23:24:36.0472 0x1498 mouhid - ok
23:24:36.0476 0x1498 mountmgr - ok
23:24:36.0479 0x1498 mpsdrv - ok
23:24:36.0499 0x1498 MpsSvc - ok
23:24:36.0525 0x1498 MRxDAV - ok
23:24:36.0543 0x1498 mrxsmb - ok
23:24:36.0559 0x1498 mrxsmb10 - ok
23:24:36.0561 0x1498 mrxsmb20 - ok
23:24:36.0573 0x1498 MsBridge - ok
23:24:36.0593 0x1498 MSDTC - ok
23:24:36.0598 0x1498 Msfs - ok
23:24:36.0601 0x1498 msgpiowin32 - ok
23:24:36.0604 0x1498 mshidkmdf - ok
23:24:36.0608 0x1498 mshidumdf - ok
23:24:36.0611 0x1498 msisadrv - ok
23:24:36.0640 0x1498 MSiSCSI - ok
23:24:36.0643 0x1498 msiserver - ok
23:24:36.0670 0x1498 MSKSSRV - ok
23:24:36.0697 0x1498 MsLldp - ok
23:24:36.0701 0x1498 MSPCLOCK - ok
23:24:36.0704 0x1498 MSPQM - ok
23:24:36.0706 0x1498 MsRPC - ok
23:24:36.0723 0x1498 mssmbios - ok
23:24:36.0727 0x1498 MSTEE - ok
23:24:36.0730 0x1498 MTConfig - ok
23:24:36.0752 0x1498 Mup - ok
23:24:36.0755 0x1498 mvumis - ok
23:24:36.0767 0x1498 NativeWifiP - ok
23:24:36.0794 0x1498 NcaSvc - ok
23:24:36.0809 0x1498 NcbService - ok
23:24:36.0812 0x1498 NcdAutoSetup - ok
23:24:36.0815 0x1498 ndfltr - ok
23:24:36.0831 0x1498 NDIS - ok
23:24:36.0834 0x1498 NdisCap - ok
23:24:36.0863 0x1498 NdisImPlatform - ok
23:24:36.0866 0x1498 NdisTapi - ok
23:24:36.0869 0x1498 Ndisuio - ok
23:24:36.0896 0x1498 NdisVirtualBus - ok
23:24:36.0899 0x1498 NdisWan - ok
23:24:36.0902 0x1498 ndiswanlegacy - ok
23:24:36.0905 0x1498 ndproxy - ok
23:24:36.0909 0x1498 Ndu - ok
23:24:36.0912 0x1498 NetAdapterCx - ok
23:24:36.0915 0x1498 NetBIOS - ok
23:24:36.0919 0x1498 NetBT - ok
23:24:36.0923 0x1498 Netlogon - ok
23:24:36.0933 0x1498 Netman - ok
23:24:36.0937 0x1498 netprofm - ok
23:24:36.0959 0x1498 NetSetupSvc - ok
23:24:37.0045 0x1498 NetTcpPortSharing - ok
23:24:37.0079 0x1498 NgcCtnrSvc - ok
23:24:37.0084 0x1498 NgcSvc - ok
23:24:37.0115 0x1498 [ 1EC76B65E0FD8F06D9F6D46FE4822D85, 22EE7AFC3B42D2A34D4BC501633E18CCD26A4917DAC379FD9C5263D540DF3B7C ] NgFilter C:\WINDOWS\System32\drivers\ngfilter.sys
23:24:37.0162 0x1498 NgFilter - ok
23:24:37.0180 0x1498 [ B6B688EE7CE921F245D98717CB78C0B8, 4174FBF952C6F1B33267DA032105F335B3413507C65ACCF2C4CA3449779A82CC ] NgLog C:\WINDOWS\System32\drivers\nglog.sys
23:24:37.0235 0x1498 NgLog - ok
23:24:37.0249 0x1498 [ 3F25096134B2D082D189F175AF648413, 33FC71B9BC0F1F277704D66A9FAA5F1CCA1C8A1D10ADB0E7223A8ACFCAB618DF ] NgVpn C:\WINDOWS\System32\drivers\ngvpn.sys
23:24:37.0296 0x1498 NgVpn - ok
23:24:37.0326 0x1498 [ F08CDE876642348F3B9F8C792065777B, A286C91BD4141B31743F1ECC39E5BF241CB94F264058F714EAF58D6AAFAAFDA6 ] NgVpnMgr C:\WINDOWS\system32\ngvpnmgr.exe
23:24:37.0351 0x1498 NgVpnMgr - ok
23:24:37.0371 0x1498 [ 48EA6EF1832244B324E5EA84F2BA9300, ADFB8CFB691BEE738B5ECC648426A5B83104E268ECC9DCEA034D5AE6F7EA9E4D ] NgWfp C:\WINDOWS\System32\drivers\ngwfp.sys
23:24:37.0420 0x1498 NgWfp - ok
23:24:37.0444 0x1498 NlaSvc - ok
23:24:37.0447 0x1498 Npfs - ok
23:24:37.0465 0x1498 npsvctrig - ok
23:24:37.0468 0x1498 nsi - ok
23:24:37.0471 0x1498 nsiproxy - ok
23:24:37.0494 0x1498 NTFS - ok
23:24:37.0498 0x1498 Null - ok
23:24:37.0533 0x1498 nvraid - ok
23:24:37.0555 0x1498 nvstor - ok
23:24:37.0591 0x1498 OneSyncSvc - ok
23:24:37.0677 0x1498 [ 471E40F7D0041E88ED8A423615B6CB58, AC96B19D2F0F56AB7280DD8CA9B34A1D32FDD0D8863E2DC6CA5B1F4A4C7D8EE8 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
23:24:37.0691 0x1498 ose - ok
23:24:37.0711 0x1498 p2pimsvc - ok
23:24:37.0718 0x1498 p2psvc - ok
23:24:37.0721 0x1498 Parport - ok
23:24:37.0742 0x1498 partmgr - ok
23:24:37.0770 0x1498 PcaSvc - ok
23:24:37.0792 0x1498 pci - ok
23:24:37.0807 0x1498 pciide - ok
23:24:37.0810 0x1498 pcmcia - ok
23:24:37.0813 0x1498 pcw - ok
23:24:37.0817 0x1498 pdc - ok
23:24:37.0820 0x1498 PEAUTH - ok
23:24:37.0824 0x1498 percsas2i - ok
23:24:37.0827 0x1498 percsas3i - ok
23:24:37.0892 0x1498 PerfHost - ok
23:24:37.0908 0x1498 PhoneSvc - ok
23:24:37.0942 0x1498 PimIndexMaintenanceSvc - ok
23:24:37.0962 0x1498 pla - ok
23:24:37.0992 0x1498 PlugPlay - ok
23:24:37.0996 0x1498 PNRPAutoReg - ok
23:24:37.0999 0x1498 PNRPsvc - ok
23:24:38.0015 0x1498 PolicyAgent - ok
23:24:38.0020 0x1498 Power - ok
23:24:38.0028 0x1498 PptpMiniport - ok
23:24:38.0195 0x1498 [ 30AA256A85C1A7B17A590B1C5244D28E, 2C1FB30DEF53C37CA0D0CA54B65CB8572C53DDFB430DE57F964253F1082ACEA0 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
23:24:38.0291 0x1498 PrintNotify - ok
23:24:38.0332 0x1498 Processor - ok
23:24:38.0346 0x1498 ProfSvc - ok
23:24:38.0349 0x1498 Psched - ok
23:24:38.0353 0x1498 QWAVE - ok
23:24:38.0357 0x1498 QWAVEdrv - ok
23:24:38.0360 0x1498 RasAcd - ok
23:24:38.0403 0x1498 RasAgileVpn - ok
23:24:38.0408 0x1498 RasAuto - ok
23:24:38.0428 0x1498 Rasl2tp - ok
23:24:38.0456 0x1498 RasMan - ok
23:24:38.0471 0x1498 RasPppoe - ok
23:24:38.0474 0x1498 RasSstp - ok
23:24:38.0478 0x1498 rdbss - ok
23:24:38.0503 0x1498 rdpbus - ok
23:24:38.0506 0x1498 RDPDR - ok
23:24:38.0576 0x1498 RdpVideoMiniport - ok
23:24:38.0579 0x1498 rdyboost - ok
23:24:38.0584 0x1498 ReFSv1 - ok
23:24:38.0600 0x1498 RemoteAccess - ok
23:24:38.0624 0x1498 RemoteRegistry - ok
23:24:38.0659 0x1498 RetailDemo - ok
23:24:38.0791 0x1498 [ 9E18DF158751CF968E7DF83256D70233, 89385DA5ABD283F289E37D7D9E33358B06216E9B3659B2E70F19FD5BA49C7F90 ] RichVideo64 C:\Program Files\CyberLink\Shared files\RichVideo64.exe
23:24:38.0806 0x1498 RichVideo64 - ok
23:24:38.0809 0x1498 RmSvc - ok
23:24:38.0860 0x1498 RpcEptMapper - ok
23:24:38.0888 0x1498 RpcLocator - ok
23:24:38.0896 0x1498 RpcSs - ok
23:24:38.0905 0x1498 rspndr - ok
23:24:38.0955 0x1498 [ 909BEFE0B82DD2CDBAFD2A0C98E8E227, FCF0B863FF21B88F0F678455E3DCB3AC1DB4CF6D51FEE93B5752F72C6B1409EC ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
23:24:39.0027 0x1498 rt640x64 - ok
23:24:39.0155 0x1498 [ 7615992F35982471546A3DE5B7587250, C8703D4A836C543A7AE6E7B980D83712DC456C351FFFAF76987A3B4B50F610F8 ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
23:24:39.0174 0x1498 RtkAudioService - ok
23:24:39.0221 0x1498 [ 4CEC3CEDFFDE813E7E0D057AABD36E1E, 37D37135A8856F81CD6A459627D7D4990C010992CA6BD710D4C9396220742FF0 ] RtkBtFilter C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys
23:24:39.0243 0x1498 RtkBtFilter - ok
23:24:39.0298 0x1498 [ 03E76CF0657BCABA2D7F7EE4384E6562, DCCAA648A34358B3DDBF908E2136C4A3460A297AC9E001B6709C65A9F320EB07 ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
23:24:39.0332 0x1498 RTSUER - ok
23:24:39.0505 0x1498 [ 8245240721FE1614ADA6E4A22CD2FFCD, D18AA3260B54C8727A577702898D86987E15003B130909A70E8A8880D67ECB8D ] RTWlanE C:\WINDOWS\System32\drivers\rtwlane.sys
23:24:39.0624 0x1498 RTWlanE - ok
23:24:39.0662 0x1498 s3cap - ok
23:24:39.0708 0x1498 SamSs - ok
23:24:39.0741 0x1498 sbp2port - ok
23:24:39.0793 0x1498 SCardSvr - ok
23:24:39.0819 0x1498 ScDeviceEnum - ok
23:24:39.0871 0x1498 scfilter - ok
23:24:39.0876 0x1498 Schedule - ok
23:24:39.0896 0x1498 scmbus - ok
23:24:39.0906 0x1498 scmdisk0101 - ok
23:24:39.0910 0x1498 SCPolicySvc - ok
23:24:39.0938 0x1498 sdbus - ok
23:24:39.0965 0x1498 SDRSVC - ok
23:24:39.0968 0x1498 sdstor - ok
23:24:39.0972 0x1498 seclogon - ok
23:24:40.0046 0x1498 [ EA160DB2589350DFF52C7ACCD7763187, 1EA4C33AE67EE0EC0748D892D402AD49832FE752F6864AF99AFCA52873D6F4A4 ] SecureLine C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
23:24:40.0065 0x1498 SecureLine - ok
23:24:40.0085 0x1498 SENS - ok
23:24:40.0118 0x1498 SensorDataService - ok
23:24:40.0157 0x1498 SensorService - ok
23:24:40.0168 0x1498 SensrSvc - ok
23:24:40.0172 0x1498 SerCx - ok
23:24:40.0176 0x1498 SerCx2 - ok
23:24:40.0179 0x1498 Serenum - ok
23:24:40.0183 0x1498 Serial - ok
23:24:40.0187 0x1498 sermouse - ok
23:24:40.0197 0x1498 SessionEnv - ok
23:24:40.0201 0x1498 sfloppy - ok
23:24:40.0249 0x1498 SharedAccess - ok
23:24:40.0268 0x1498 ShellHWDetection - ok
23:24:40.0293 0x1498 shpamsvc - ok
23:24:40.0296 0x1498 SiSRaid2 - ok
23:24:40.0300 0x1498 SiSRaid4 - ok
23:24:40.0390 0x1498 [ FBEB3BE7765B6C27891E9D1D8CE7F626, BC116E67268C8AA37C1EFA04C796A184C9292DBA771004FFA12F26D6C9619AF1 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
23:24:40.0410 0x1498 SkypeUpdate - ok
23:24:40.0439 0x1498 [ AE73570A0AF0FB1BF84B7CD815772409, 2E00FADEA5054E5E8A1BA964FA0F6C787320662C7AECBE0DC923698AB9252300 ] SmbDrv C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys
23:24:40.0450 0x1498 SmbDrv - ok
23:24:40.0487 0x1498 [ 5ABAB1FF9E0174C96AE711803D0B49A1, C037D7C5EBDD3276A689EE81EA8E5881624D20DC3751DE6FBB2870198F502D8A ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
23:24:40.0543 0x1498 SmbDrvI - ok
23:24:40.0555 0x1498 smphost - ok
23:24:40.0558 0x1498 SmsRouter - ok
23:24:40.0585 0x1498 SNMPTRAP - ok
23:24:40.0616 0x1498 spaceport - ok
23:24:40.0619 0x1498 SpbCx - ok
23:24:40.0628 0x1498 Spooler - ok
23:24:40.0655 0x1498 sppsvc - ok
23:24:40.0672 0x1498 srv - ok
23:24:40.0684 0x1498 srv2 - ok
23:24:40.0695 0x1498 srvnet - ok
23:24:40.0698 0x1498 SSDPSRV - ok
23:24:40.0709 0x1498 SstpSvc - ok
23:24:40.0753 0x1498 [ F0B59ADCD06BCEB9D47311B7041CA2C9, 6299AB514CBE153C875F083ED789F6205C1781C0178759521F5A6D8007F5257C ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
23:24:40.0792 0x1498 ssudmdm - ok
23:24:40.0827 0x1498 StateRepository - ok
23:24:40.0930 0x1498 [ C8DC0C34715627ABF7A265ED27D1F75A, 5B8B9AC65D7458A8C6C868107E0BE3F9B1A1A5117FC69FDC260BAA9F1BDD0008 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
23:24:40.0964 0x1498 Steam Client Service - ok
23:24:40.0995 0x1498 stexstor - ok
23:24:41.0034 0x1498 stisvc - ok
23:24:41.0047 0x1498 storahci - ok
23:24:41.0071 0x1498 storflt - ok
23:24:41.0095 0x1498 stornvme - ok
23:24:41.0099 0x1498 storqosflt - ok
23:24:41.0116 0x1498 StorSvc - ok
23:24:41.0121 0x1498 storufs - ok
23:24:41.0130 0x1498 storvsc - ok
23:24:41.0134 0x1498 svsvc - ok
23:24:41.0140 0x1498 swenum - ok
23:24:41.0148 0x1498 swprv - ok
23:24:41.0168 0x1498 Synth3dVsc - ok
23:24:41.0215 0x1498 [ FFFCCD161BBCFDFD89E6D531AB904EFB, D442D0F44FFF555FEDCF004E723A1CBD4F80F2F0E0A127A104FB4778C8738864 ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys
23:24:41.0240 0x1498 SynTP - ok
23:24:41.0292 0x1498 [ FDC86D27886D4F6FC860C2FB7AE1FC52, 52E676495C6C115D356AF4613D779C982E24B770695413F7E46E1BD8F14A977A ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
23:24:41.0308 0x1498 SynTPEnhService - ok
23:24:41.0337 0x1498 SysMain - ok
23:24:41.0357 0x1498 SystemEventsBroker - ok
23:24:41.0370 0x1498 TabletInputService - ok
23:24:41.0373 0x1498 TapiSrv - ok
23:24:41.0399 0x1498 Tcpip - ok
23:24:41.0402 0x1498 Tcpip6 - ok
23:24:41.0415 0x1498 tcpipreg - ok
23:24:41.0421 0x1498 tdx - ok
23:24:41.0424 0x1498 terminpt - ok
23:24:41.0435 0x1498 TermService - ok
23:24:41.0457 0x1498 Themes - ok
23:24:41.0472 0x1498 TieringEngineService - ok
23:24:41.0516 0x1498 tiledatamodelsvc - ok
23:24:41.0521 0x1498 TimeBrokerSvc - ok
23:24:41.0538 0x1498 [ 46171262D0E806779DEEDFCAB2F830CC, 7F4A4658B8BA217D99E5B5C0E01600C20DC96ECBCA32A5BA7FBE17D2A7B8BFD8 ] TPM C:\WINDOWS\System32\drivers\tpm.sys
23:24:41.0620 0x1498 TPM - ok
23:24:41.0625 0x1498 TrkWks - ok
23:24:41.0670 0x1498 TrustedInstaller - ok
23:24:41.0675 0x1498 tsusbflt - ok
23:24:41.0703 0x1498 TsUsbGD - ok
23:24:41.0706 0x1498 tunnel - ok
23:24:41.0749 0x1498 tzautoupdate - ok
23:24:41.0772 0x1498 UASPStor - ok
23:24:41.0775 0x1498 UcmCx0101 - ok
23:24:41.0778 0x1498 UcmTcpciCx0101 - ok
23:24:41.0782 0x1498 UcmUcsi - ok
23:24:41.0786 0x1498 Ucx01000 - ok
23:24:41.0790 0x1498 UdeCx - ok
23:24:41.0793 0x1498 udfs - ok
23:24:41.0797 0x1498 UEFI - ok
23:24:41.0801 0x1498 Ufx01000 - ok
23:24:41.0805 0x1498 UfxChipidea - ok
23:24:41.0808 0x1498 ufxsynopsys - ok
23:24:41.0816 0x1498 UI0Detect - ok
23:24:41.0821 0x1498 umbus - ok
23:24:41.0825 0x1498 UmPass - ok
23:24:41.0828 0x1498 UmRdpService - ok
23:24:41.0876 0x1498 UnistoreSvc - ok
23:24:41.0892 0x1498 upnphost - ok
23:24:41.0896 0x1498 UrsChipidea - ok
23:24:41.0900 0x1498 UrsCx01000 - ok
23:24:41.0904 0x1498 UrsSynopsys - ok
23:24:41.0940 0x1498 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
23:24:41.0994 0x1498 USBAAPL64 - detected UnsignedFile.Multi.Generic ( 1 )
23:24:42.0048 0x1498 Detect skipped due to KSN trusted
23:24:42.0048 0x1498 USBAAPL64 - ok
23:24:42.0061 0x1498 usbaudio - ok
23:24:42.0065 0x1498 usbccgp - ok
23:24:42.0070 0x1498 usbcir - ok
23:24:42.0074 0x1498 usbehci - ok
23:24:42.0077 0x1498 usbhub - ok
23:24:42.0081 0x1498 USBHUB3 - ok
23:24:42.0085 0x1498 usbohci - ok
23:24:42.0089 0x1498 usbprint - ok
23:24:42.0128 0x1498 [ 2EC7B2C8123236B1233A77281D378DF7, D97DB59C9CAE2B8B33C707E8CEA7A65BF88712842CC715D270F7432A99D21BB6 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
23:24:42.0183 0x1498 usbscan - ok
23:24:42.0187 0x1498 usbser - ok
23:24:42.0201 0x1498 USBSTOR - ok
23:24:42.0204 0x1498 usbuhci - ok
23:24:42.0225 0x1498 usbvideo - ok
23:24:42.0234 0x1498 USBXHCI - ok
23:24:42.0270 0x1498 UserDataSvc - ok
23:24:42.0284 0x1498 UserManager - ok
23:24:42.0314 0x1498 UsoSvc - ok
23:24:42.0319 0x1498 VaultSvc - ok
23:24:42.0323 0x1498 vdrvroot - ok
23:24:42.0330 0x1498 vds - ok
23:24:42.0334 0x1498 VerifierExt - ok
23:24:42.0352 0x1498 vhdmp - ok
23:24:42.0355 0x1498 vhf - ok
23:24:42.0359 0x1498 vmbus - ok
23:24:42.0362 0x1498 VMBusHID - ok
23:24:42.0367 0x1498 vmgid - ok
23:24:42.0379 0x1498 vmicguestinterface - ok
23:24:42.0383 0x1498 vmicheartbeat - ok
23:24:42.0387 0x1498 vmickvpexchange - ok
23:24:42.0428 0x1498 vmicrdv - ok
23:24:42.0432 0x1498 vmicshutdown - ok
23:24:42.0435 0x1498 vmictimesync - ok
23:24:42.0439 0x1498 vmicvmsession - ok
23:24:42.0442 0x1498 vmicvss - ok
23:24:42.0471 0x1498 volmgr - ok
23:24:42.0474 0x1498 volmgrx - ok
23:24:42.0479 0x1498 volsnap - ok
23:24:42.0482 0x1498 volume - ok
23:24:42.0519 0x1498 [ 92F6E3E6D3F1795263EB34B37F74AEF7, 33AB1ECCA1216AF1995E1DB4F11E48156FF62391D7C176C8A4CC1037B9CB3A27 ] vpci C:\WINDOWS\System32\drivers\vpci.sys
23:24:42.0568 0x1498 vpci - ok
23:24:42.0577 0x1498 vsmraid - ok
23:24:42.0581 0x1498 VSS - ok
23:24:42.0612 0x1498 VSTXRAID - ok
23:24:42.0641 0x1498 vwifibus - ok
23:24:42.0648 0x1498 vwififlt - ok
23:24:42.0667 0x1498 vwifimp - ok
23:24:42.0677 0x1498 W32Time - ok
23:24:42.0720 0x1498 w3logsvc - ok
23:24:42.0724 0x1498 WacomPen - ok
23:24:42.0760 0x1498 WalletService - ok
23:24:42.0764 0x1498 wanarp - ok
23:24:42.0769 0x1498 wanarpv6 - ok
23:24:42.0774 0x1498 WAS - ok
23:24:42.0802 0x1498 wbengine - ok
23:24:42.0822 0x1498 WbioSrvc - ok
23:24:42.0851 0x1498 wcifs - ok
23:24:42.0883 0x1498 Wcmsvc - ok
23:24:42.0887 0x1498 wcncsvc - ok
23:24:42.0891 0x1498 wcnfs - ok
23:24:42.0895 0x1498 WdBoot - ok
23:24:42.0899 0x1498 Wdf01000 - ok
23:24:42.0904 0x1498 WdFilter - ok
23:24:42.0907 0x1498 WdiServiceHost - ok
23:24:42.0921 0x1498 WdiSystemHost - ok
23:24:42.0937 0x1498 wdiwifi - ok
23:24:42.0940 0x1498 WdNisDrv - ok
23:24:42.0972 0x1498 WdNisSvc - ok
23:24:42.0975 0x1498 WebClient - ok
23:24:42.0979 0x1498 Wecsvc - ok
23:24:42.0983 0x1498 WEPHOSTSVC - ok
23:24:43.0000 0x1498 wercplsupport - ok
23:24:43.0004 0x1498 WerSvc - ok
23:24:43.0007 0x1498 WFPLWFS - ok
23:24:43.0020 0x1498 WiaRpc - ok
23:24:43.0032 0x1498 WIMMount - ok
23:24:43.0035 0x1498 WinDefend - ok
23:24:43.0068 0x1498 WindowsTrustedRT - ok
23:24:43.0071 0x1498 WindowsTrustedRTProxy - ok
23:24:43.0101 0x1498 WinHttpAutoProxySvc - ok
23:24:43.0134 0x1498 WinMad - ok
23:24:43.0196 0x1498 Winmgmt - ok
23:24:43.0233 0x1498 WinRM - ok
23:24:43.0243 0x1498 WINUSB - ok
23:24:43.0247 0x1498 WinVerbs - ok
23:24:43.0298 0x1498 [ 9ABB443957FF46631CD25A2CD5ACD4A1, 7540C01A4B1CF1A74548658D180F517B33A0B2D0CD1A9DBF796AB38F7C2D787A ] WirelessButtonDriver64 C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys
23:24:43.0328 0x1498 WirelessButtonDriver64 - ok
23:24:43.0372 0x1498 wisvc - ok
23:24:43.0394 0x1498 WlanSvc - ok
23:24:43.0412 0x1498 wlidsvc - ok
23:24:43.0415 0x1498 WmiAcpi - ok
23:24:43.0422 0x1498 wmiApSrv - ok
23:24:43.0433 0x1498 WMPNetworkSvc - ok
23:24:43.0448 0x1498 Wof - ok
23:24:43.0473 0x1498 workfolderssvc - ok
23:24:43.0485 0x1498 WPDBusEnum - ok
23:24:43.0510 0x1498 WpdUpFltr - ok
23:24:43.0526 0x1498 WpnService - ok
23:24:43.0529 0x1498 WpnUserService - ok
23:24:43.0536 0x1498 ws2ifsl - ok
23:24:43.0564 0x1498 wscsvc - ok
23:24:43.0594 0x1498 WSDPrintDevice - ok
23:24:43.0598 0x1498 WSDScan - ok
23:24:43.0603 0x1498 WSearch - ok
23:24:43.0642 0x1498 wuauserv - ok
23:24:43.0646 0x1498 WudfPf - ok
23:24:43.0651 0x1498 WUDFRd - ok
23:24:43.0655 0x1498 wudfsvc - ok
23:24:43.0659 0x1498 WUDFWpdFs - ok
23:24:43.0663 0x1498 WUDFWpdMtp - ok
23:24:43.0680 0x1498 WwanSvc - ok
23:24:43.0685 0x1498 XblAuthManager - ok
23:24:43.0698 0x1498 XblGameSave - ok
23:24:43.0712 0x1498 xboxgip - ok
23:24:43.0715 0x1498 XboxNetApiSvc - ok
23:24:43.0756 0x1498 xinputhid - ok
23:24:43.0759 0x1498 ================ Scan global ===============================
23:24:43.0899 0x1498 [ Global ] - ok
23:24:43.0900 0x1498 ================ Scan MBR ==================================
23:24:43.0914 0x1498 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
23:24:43.0987 0x1498 \Device\Harddisk0\DR0 - ok
23:24:43.0987 0x1498 ================ Scan VBR ==================================
23:24:43.0989 0x1498 [ 41BA44D15A2475E4BE8297BA28D12AEB ] \Device\Harddisk0\DR0\Partition1
23:24:43.0990 0x1498 \Device\Harddisk0\DR0\Partition1 - ok
23:24:44.0022 0x1498 [ 6940213001A358836EE8E183F24D8A91 ] \Device\Harddisk0\DR0\Partition2
23:24:44.0022 0x1498 \Device\Harddisk0\DR0\Partition2 - ok
23:24:44.0029 0x1498 [ 2F4E827DB55B25DEBDA3212AFAB243B7 ] \Device\Harddisk0\DR0\Partition3
23:24:44.0031 0x1498 \Device\Harddisk0\DR0\Partition3 - ok
23:24:44.0058 0x1498 [ 24C05B2D896F067EEFD7CCAD3EDA39EB ] \Device\Harddisk0\DR0\Partition4
23:24:44.0060 0x1498 \Device\Harddisk0\DR0\Partition4 - ok
23:24:44.0072 0x1498 [ C861EC1515C9C814A5FD7E65B1F0D72B ] \Device\Harddisk0\DR0\Partition5
23:24:44.0074 0x1498 \Device\Harddisk0\DR0\Partition5 - ok
23:24:44.0074 0x1498 ================ Scan generic autorun ======================
23:24:44.0379 0x1498 [ ADDD0817493A4A7556E89FEF9586CED3, C99E49451D2798420B72C9B9A0EE5FBFE9EA6BAB682C89DB65ED6D9C8F9934D7 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
23:24:44.0549 0x1498 RTHDVCPL - ok
23:24:44.0640 0x1498 [ 1ACD6F295A09260BE8E2D4DE99C79338, 6C62C69C243667D813ACDEDA7B192C0370E97472C48E2AD4D00A7DC329554063 ] C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe
23:24:44.0657 0x1498 BtServer - ok
23:24:44.0738 0x1498 [ D1BD2B7EDD5D5C0CB3DEABDE0F44E11D, 722F5FE8882C7388672FE4F1F2150E09DC169EA2244FC80D01A016C4FAC91C5A ] C:\Program Files\HP\HP ePrint\HP.DeliveryAndStatus.Desktop.App.exe
23:24:44.0755 0x1498 DeliveryAndStatusCheck - ok
23:24:44.0923 0x1498 [ 14200012DD34CC97FF3B92DBEF449457, 6A87AA0792258C4DF4396B0F08A1B59716B88FA158DADAA4EFB4A1CAD46C1E43 ] C:\Program Files\AVAST Software\Avast\AvLaunch.exe
23:24:44.0938 0x1498 AvastUI.exe - ok
23:24:45.0076 0x1498 [ 5602FF42444B4991E69C62E493BDAEC4, 7AE46CA0CD1E1C091B31EE4A691C26823E0F1AB1CA6B1C29E6C662BF7E28A996 ] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
23:24:45.0142 0x1498 Malwarebytes TrayApp - ok
23:24:45.0218 0x1498 [ 90D6A3B9DD3F54A2ACEF8DF2AB001F0D, A7F411C6D0C1B00E9C462ABA13BB765FD2D3C3D49FE0663AABDC32A69835AC2F ] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
23:24:45.0239 0x1498 HPMessageService - ok
23:24:45.0302 0x1498 [ 65C1180F28E870892469340E50CB720D, 7521220A960ADD30A0939B36DD5F09241A5E40D273DA817F1C0FC48A0F9AB7AD ] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe
23:24:45.0324 0x1498 StartCCC - ok
23:24:45.0413 0x1498 [ 995846BC134F8792AF4D3342522A7E33, 652A4B69FD55F97118F282E0615A6EF99BB59753D5B3012D169A6E166922CBCC ] C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe
23:24:45.0436 0x1498 PowerDVD14Agent - ok
23:24:45.0615 0x1498 [ D5EB6E4154952E64C215B5D8BCE06432, 7F0B94ED4AA314274EDFEFAA384DA54BAC8A78B832808F3EF03308F78404FFE0 ] C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
23:24:45.0697 0x1498 Dropbox - ok
23:24:45.0793 0x1498 [ 9872F2B6BD47098092E0C8E2E0B6A21F, 23DECCF3755B4220A13D925D0295D02C60D5DCE354E1659AACEE91DC5FBBE669 ] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe
23:24:45.0815 0x1498 FUFAXRCV - ok
23:24:45.0867 0x1498 [ 0FDE360CDD65A72F50977AA9EADE5D61, D259954CD15AB0358A03EDA6CE64043544D2F76B7FB31A3963BE3CF509D60AE9 ] C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe
23:24:45.0898 0x1498 FUFAXSTM - ok
23:24:45.0994 0x1498 OneDriveSetup - ok
23:24:45.0995 0x1498 OneDriveSetup - ok
23:24:46.0124 0x1498 [ 3F218819210022E0D585957FB155D4A3, A2F27FCB349BAE82B4A4475F3C26E5D57D0EC07C22228F35CFFE3ABBFBA2EEF8 ] C:\Program Files (x86)\Steam\steam.exe
23:24:46.0188 0x1498 Steam - ok
23:24:46.0311 0x1498 [ 88DBF6DF632CAD6B22186DA206829639, CB7FA8F321EDDFAA897E15C5ED212AFAD6469CAD88F966771FF2F824FDE50423 ] C:\Users\durma\AppData\Roaming\OpenOffice Updater\Updater.exe
23:24:46.0331 0x1498 OpenOffice Updater - ok
23:24:46.0458 0x1498 [ 054C5313C15AEBFD031FC4723C08CE14, AE3B67A1863704E0D97321266C3664A4A2AF4C05BB56A4843630F3B6F3DA9305 ] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKEE.EXE
23:24:46.0473 0x1498 EPLTarget\P0000000000000000 - ok
23:24:46.0484 0x1498 [ 054C5313C15AEBFD031FC4723C08CE14, AE3B67A1863704E0D97321266C3664A4A2AF4C05BB56A4843630F3B6F3DA9305 ] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKEE.EXE
23:24:46.0496 0x1498 EPLTarget\P0000000000000001 - ok
23:24:46.0506 0x1498 [ 054C5313C15AEBFD031FC4723C08CE14, AE3B67A1863704E0D97321266C3664A4A2AF4C05BB56A4843630F3B6F3DA9305 ] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKEE.EXE
23:24:46.0520 0x1498 EPLTarget\P0000000000000002 - ok
23:24:46.0524 0x1498 Waiting for KSN requests completion. In queue: 64
23:24:47.0557 0x1498 AV detected via SS2: Avast Antivirus, C:\Program Files\AVAST Software\Avast\wsc_proxy.exe ( 17.5.3559.0 ), 0x41000 ( enabled : updated )
23:24:47.0558 0x1498 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.1198 ), 0x60100 ( disabled : updated )
23:24:47.0561 0x1498 Win FW state via NFP2: enabled ( trusted )
23:24:47.0675 0x1498 ============================================================
23:24:47.0675 0x1498 Scan finished
23:24:47.0675 0x1498 ============================================================
23:24:47.0688 0x2488 Detected object count: 0
23:24:47.0688 0x2488 Actual detected object count: 0 |