Code: 
Alles auswählen Aufklappen  ATTFilter
 
10:02:16.0822 0x2300  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
10:02:16.0822 0x2300  UEFI system
10:02:22.0008 0x2300  ============================================================
10:02:22.0008 0x2300  Current date / time: 2017/01/01 10:02:22.0008
10:02:22.0008 0x2300  SystemInfo:
10:02:22.0008 0x2300  
10:02:22.0008 0x2300  OS Version: 10.0.14393 ServicePack: 0.0
10:02:22.0008 0x2300  Product type: Workstation
10:02:22.0008 0x2300  ComputerName: BÜRO-PC
10:02:22.0009 0x2300  UserName: Michael
10:02:22.0009 0x2300  Windows directory: C:\WINDOWS
10:02:22.0009 0x2300  System windows directory: C:\WINDOWS
10:02:22.0009 0x2300  Running under WOW64
10:02:22.0009 0x2300  Processor architecture: Intel x64
10:02:22.0009 0x2300  Number of processors: 4
10:02:22.0009 0x2300  Page size: 0x1000
10:02:22.0009 0x2300  Boot type: Normal boot
10:02:22.0009 0x2300  CodeIntegrityOptions = 0x00000001
10:02:22.0009 0x2300  ============================================================
10:02:22.0651 0x2300  KLMD registered as C:\WINDOWS\system32\drivers\56605955.sys
10:02:22.0651 0x2300  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.576, osProperties = 0x19
10:02:22.0939 0x2300  System UUID: {DBB9EEE9-BD9E-126F-6569-E96BC2D268B8}
10:02:23.0654 0x2300  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:02:23.0679 0x2300  ============================================================
10:02:23.0679 0x2300  \Device\Harddisk0\DR0:
10:02:23.0679 0x2300  GPT partitions:
10:02:23.0679 0x2300  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {6C492D71-1A31-4E8F-9656-F831768BEBF8}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x96000
10:02:23.0680 0x2300  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {CF71B53D-6B1C-4C0C-8CA9-99528CFB3A84}, Name: EFI system partition, StartLBA 0x96800, BlocksNum 0x82000
10:02:23.0680 0x2300  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {88729A5F-6B01-48F6-8FD2-FF81C2669D0B}, Name: Microsoft reserved partition, StartLBA 0x118800, BlocksNum 0x40000
10:02:23.0680 0x2300  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {691C0A2D-F07E-4236-85C4-958E390DA549}, Name: Basic data partition, StartLBA 0x158800, BlocksNum 0x38BD0000
10:02:23.0680 0x2300  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {FDC94643-DD41-4F42-B33A-CC628DFD3722}, Name: , StartLBA 0x38D28800, BlocksNum 0xE1000
10:02:23.0680 0x2300  \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {A6156BA3-AA32-4C69-B044-DED7B1A6A6A8}, Name: Basic data partition, StartLBA 0x38E0A000, BlocksNum 0x157C000
10:02:23.0680 0x2300  MBR partitions:
10:02:23.0680 0x2300  ============================================================
10:02:23.0709 0x2300  C: <-> \Device\Harddisk0\DR0\Partition4
10:02:23.0709 0x2300  ============================================================
10:02:23.0709 0x2300  Initialize success
10:02:23.0709 0x2300  ============================================================
10:03:13.0462 0x0ccc  ============================================================
10:03:13.0462 0x0ccc  Scan started
10:03:13.0462 0x0ccc  Mode: Manual; SigCheck; TDLFS; 
10:03:13.0462 0x0ccc  ============================================================
10:03:13.0462 0x0ccc  KSN ping started
10:03:13.0678 0x0ccc  KSN ping finished: true
10:03:17.0920 0x0ccc  ================ Scan system memory ========================
10:03:17.0920 0x0ccc  System memory - ok
10:03:17.0921 0x0ccc  ================ Scan services =============================
10:03:18.0046 0x0ccc  1394ohci - ok
10:03:18.0052 0x0ccc  3ware - ok
10:03:18.0079 0x0ccc  ACPI - ok
10:03:18.0085 0x0ccc  AcpiDev - ok
10:03:18.0093 0x0ccc  acpiex - ok
10:03:18.0101 0x0ccc  acpipagr - ok
10:03:18.0129 0x0ccc  AcpiPmi - ok
10:03:18.0133 0x0ccc  acpitime - ok
10:03:18.0237 0x0ccc  [ B79750091FC0842182FE49D263791294, 32FC260A74C9C45CD1E8998523642C285866378FCD9478FEFD15A0CC42EC0E0B ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
10:03:18.0300 0x0ccc  AdobeFlashPlayerUpdateSvc - ok
10:03:18.0337 0x0ccc  ADP80XX - ok
10:03:18.0358 0x0ccc  AFD - ok
10:03:18.0371 0x0ccc  ahcache - ok
10:03:18.0389 0x0ccc  AJRouter - ok
10:03:18.0403 0x0ccc  ALG - ok
10:03:18.0431 0x0ccc  [ BBADD85854BFB5D43C60B7AC8EEA3DBA, 968C043ABEA46F5C79525863B3FE2681AC0FA4202036C9EFD20B408DECF407E2 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
10:03:18.0489 0x0ccc  AMD External Events Utility - ok
10:03:18.0552 0x0ccc  [ DE51F5BB5C05D4C831ECB6E1A70E1B5E, 465834210ACE469481F75EDBB8532386029BD5277C41D084134E9E71B9BD8371 ] AMD FUEL Service C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
10:03:18.0587 0x0ccc  AMD FUEL Service - ok
10:03:18.0613 0x0ccc  AmdK8 - ok
10:03:18.0617 0x0ccc  amdkmdag - ok
10:03:18.0658 0x0ccc  [ 17BA5C907E14947574CBB788F4CEB85F, EAA3DBF436637C58666A91905E388287FC54334EBB2589A00727EB09AC4870E3 ] amdkmdap        C:\WINDOWS\system32\DRIVERS\atikmpag.sys
10:03:18.0689 0x0ccc  amdkmdap - ok
10:03:18.0695 0x0ccc  AmdPPM - ok
10:03:18.0700 0x0ccc  amdsata - ok
10:03:18.0704 0x0ccc  amdsbs - ok
10:03:18.0710 0x0ccc  amdxata - ok
10:03:18.0718 0x0ccc  [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.2.0  C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
10:03:18.0728 0x0ccc  AODDriver4.2.0 - ok
10:03:18.0733 0x0ccc  [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.3    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
10:03:18.0742 0x0ccc  AODDriver4.3 - ok
10:03:18.0763 0x0ccc  AppID - ok
10:03:18.0790 0x0ccc  AppIDSvc - ok
10:03:18.0806 0x0ccc  Appinfo - ok
10:03:18.0820 0x0ccc  applockerfltr - ok
10:03:18.0846 0x0ccc  AppReadiness - ok
10:03:18.0866 0x0ccc  AppXSvc - ok
10:03:18.0895 0x0ccc  arcsas - ok
10:03:18.0901 0x0ccc  AsyncMac - ok
10:03:18.0930 0x0ccc  atapi - ok
10:03:18.0960 0x0ccc  [ 5903F7756DE3D71DF5094262B4FAAB3C, 78832A7438BCC910FC571CCC62EC03F5F54A6238544F3305CCB1295006F35859 ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdWT6.sys
10:03:18.0987 0x0ccc  AtiHDAudioService - ok
10:03:19.0014 0x0ccc  AudioEndpointBuilder - ok
10:03:19.0248 0x0ccc  Audiosrv - ok
10:03:19.0300 0x0ccc  [ 03B45C52179E8DAE51A0F685C30D06D6, E06F066B4BFE5344BBF5749B9B8B8CFBA0C02920FD2B9C73BDDA7E34F1785DA7 ] AVP17.0.0       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe
10:03:19.0321 0x0ccc  AVP17.0.0 - ok
10:03:19.0342 0x0ccc  AxInstSV - ok
10:03:19.0354 0x0ccc  b06bdrv - ok
10:03:19.0363 0x0ccc  BasicDisplay - ok
10:03:19.0367 0x0ccc  BasicRender - ok
10:03:19.0374 0x0ccc  bcmfn - ok
10:03:19.0380 0x0ccc  bcmfn2 - ok
10:03:19.0386 0x0ccc  BDESVC - ok
10:03:19.0396 0x0ccc  Beep - ok
10:03:19.0410 0x0ccc  BFE - ok
10:03:19.0430 0x0ccc  BITS - ok
10:03:19.0443 0x0ccc  bowser - ok
10:03:19.0462 0x0ccc  BrokerInfrastructure - ok
10:03:19.0468 0x0ccc  Browser - ok
10:03:19.0487 0x0ccc  BthAvrcpTg - ok
10:03:19.0493 0x0ccc  BthHFEnum - ok
10:03:19.0498 0x0ccc  bthhfhid - ok
10:03:19.0511 0x0ccc  BthHFSrv - ok
10:03:19.0516 0x0ccc  BTHMODEM - ok
10:03:19.0537 0x0ccc  bthserv - ok
10:03:19.0563 0x0ccc  buttonconverter - ok
10:03:19.0580 0x0ccc  CapImg - ok
10:03:19.0595 0x0ccc  cdfs - ok
10:03:19.0609 0x0ccc  CDPSvc - ok
10:03:19.0630 0x0ccc  CDPUserSvc - ok
10:03:19.0653 0x0ccc  cdrom - ok
10:03:19.0669 0x0ccc  CertPropSvc - ok
10:03:19.0673 0x0ccc  cht4iscsi - ok
10:03:19.0679 0x0ccc  cht4vbd - ok
10:03:19.0689 0x0ccc  circlass - ok
10:03:19.0709 0x0ccc  CLFS - ok
10:03:19.0713 0x0ccc  ClipSVC - ok
10:03:19.0718 0x0ccc  clreg - ok
10:03:19.0731 0x0ccc  CmBatt - ok
10:03:19.0756 0x0ccc  [ B29A764A1E76473CD9D64C9438705C19, CD0497EB84DE60E1E491CA495AF981A8DFC4949BB373C1978CAF1BCF4321D30E ] cm_km           C:\WINDOWS\system32\DRIVERS\cm_km.sys
10:03:19.0783 0x0ccc  cm_km - ok
10:03:19.0803 0x0ccc  CNG - ok
10:03:19.0807 0x0ccc  cnghwassist - ok
10:03:19.0842 0x0ccc  CompositeBus - ok
10:03:19.0847 0x0ccc  COMSysApp - ok
10:03:19.0852 0x0ccc  condrv - ok
10:03:19.0876 0x0ccc  CoreMessagingRegistrar - ok
10:03:19.0903 0x0ccc  CryptSvc - ok
10:03:19.0920 0x0ccc  dam - ok
10:03:19.0946 0x0ccc  DcomLaunch - ok
10:03:20.0007 0x0ccc  DcpSvc - ok
10:03:20.0014 0x0ccc  defragsvc - ok
10:03:20.0046 0x0ccc  DeviceAssociationService - ok
10:03:20.0052 0x0ccc  DeviceInstall - ok
10:03:20.0067 0x0ccc  DevQueryBroker - ok
10:03:20.0087 0x0ccc  Dfsc - ok
10:03:20.0097 0x0ccc  Dhcp - ok
10:03:20.0139 0x0ccc  diagnosticshub.standardcollector.service - ok
10:03:20.0164 0x0ccc  DiagTrack - ok
10:03:20.0188 0x0ccc  disk - ok
10:03:20.0215 0x0ccc  DmEnrollmentSvc - ok
10:03:20.0223 0x0ccc  dmvsc - ok
10:03:20.0231 0x0ccc  dmwappushservice - ok
10:03:20.0262 0x0ccc  Dnscache - ok
10:03:20.0271 0x0ccc  dot3svc - ok
10:03:20.0277 0x0ccc  DPS - ok
10:03:20.0295 0x0ccc  drmkaud - ok
10:03:20.0307 0x0ccc  DsmSvc - ok
10:03:20.0316 0x0ccc  DsSvc - ok
10:03:20.0333 0x0ccc  DXGKrnl - ok
10:03:20.0347 0x0ccc  EapHost - ok
10:03:20.0353 0x0ccc  ebdrv - ok
10:03:20.0377 0x0ccc  EFS - ok
10:03:20.0384 0x0ccc  EhStorClass - ok
10:03:20.0396 0x0ccc  EhStorTcgDrv - ok
10:03:20.0412 0x0ccc  embeddedmode - ok
10:03:20.0438 0x0ccc  EntAppSvc - ok
10:03:20.0443 0x0ccc  ErrDev - ok
10:03:20.0462 0x0ccc  EventSystem - ok
10:03:20.0470 0x0ccc  exfat - ok
10:03:20.0488 0x0ccc  fastfat - ok
10:03:20.0498 0x0ccc  Fax - ok
10:03:20.0503 0x0ccc  fdc - ok
10:03:20.0508 0x0ccc  fdPHost - ok
10:03:20.0514 0x0ccc  FDResPub - ok
10:03:20.0534 0x0ccc  fhsvc - ok
10:03:20.0554 0x0ccc  FileCrypt - ok
10:03:20.0558 0x0ccc  FileInfo - ok
10:03:20.0573 0x0ccc  Filetrace - ok
10:03:20.0577 0x0ccc  flpydisk - ok
10:03:20.0585 0x0ccc  FltMgr - ok
10:03:20.0613 0x0ccc  FontCache - ok
10:03:20.0698 0x0ccc  FontCache3.0.0.0 - ok
10:03:20.0788 0x0ccc  [ 59F5C34DFBDB3DE37F321258FAD21BA2, 54C0A1BCAC3C10FBB3259EB0A4830ED9C8BA3C079F237D4CE5B34AA2C5F68411 ] FoxitReaderService C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe
10:03:20.0854 0x0ccc  FoxitReaderService - ok
10:03:20.0878 0x0ccc  FrameServer - ok
10:03:20.0883 0x0ccc  FsDepends - ok
10:03:20.0887 0x0ccc  Fs_Rec - ok
10:03:20.0903 0x0ccc  fvevol - ok
10:03:20.0922 0x0ccc  gencounter - ok
10:03:20.0931 0x0ccc  genericusbfn - ok
10:03:20.0938 0x0ccc  GPIOClx0101 - ok
10:03:20.0946 0x0ccc  gpsvc - ok
10:03:20.0955 0x0ccc  GpuEnergyDrv - ok
10:03:20.0969 0x0ccc  HdAudAddService - ok
10:03:20.0973 0x0ccc  HDAudBus - ok
10:03:20.0978 0x0ccc  HidBatt - ok
10:03:20.0983 0x0ccc  HidBth - ok
10:03:20.0988 0x0ccc  hidi2c - ok
10:03:20.0994 0x0ccc  hidinterrupt - ok
10:03:20.0999 0x0ccc  HidIr - ok
10:03:21.0013 0x0ccc  hidserv - ok
10:03:21.0045 0x0ccc  HidUsb - ok
10:03:21.0065 0x0ccc  HomeGroupListener - ok
10:03:21.0093 0x0ccc  HomeGroupProvider - ok
10:03:21.0100 0x0ccc  HpSAMD - ok
10:03:21.0125 0x0ccc  HTTP - ok
10:03:21.0156 0x0ccc  HvHost - ok
10:03:21.0179 0x0ccc  hvservice - ok
10:03:21.0185 0x0ccc  hwpolicy - ok
10:03:21.0193 0x0ccc  hyperkbd - ok
10:03:21.0217 0x0ccc  i8042prt - ok
10:03:21.0221 0x0ccc  iagpio - ok
10:03:21.0225 0x0ccc  iai2c - ok
10:03:21.0232 0x0ccc  iaLPSS2i_GPIO2 - ok
10:03:21.0236 0x0ccc  iaLPSS2i_I2C - ok
10:03:21.0242 0x0ccc  iaLPSSi_GPIO - ok
10:03:21.0248 0x0ccc  iaLPSSi_I2C - ok
10:03:21.0252 0x0ccc  iaStorAV - ok
10:03:21.0257 0x0ccc  iaStorV - ok
10:03:21.0263 0x0ccc  ibbus - ok
10:03:21.0282 0x0ccc  icssvc - ok
10:03:21.0286 0x0ccc  IKEEXT - ok
10:03:21.0296 0x0ccc  IndirectKmd - ok
10:03:21.0318 0x0ccc  intelide - ok
10:03:21.0322 0x0ccc  intelpep - ok
10:03:21.0340 0x0ccc  intelppm - ok
10:03:21.0358 0x0ccc  iorate - ok
10:03:21.0371 0x0ccc  IpFilterDriver - ok
10:03:21.0388 0x0ccc  iphlpsvc - ok
10:03:21.0392 0x0ccc  IPMIDRV - ok
10:03:21.0397 0x0ccc  IPNAT - ok
10:03:21.0401 0x0ccc  irda - ok
10:03:21.0406 0x0ccc  IRENUM - ok
10:03:21.0425 0x0ccc  irmon - ok
10:03:21.0430 0x0ccc  isapnp - ok
10:03:21.0435 0x0ccc  iScsiPrt - ok
10:03:21.0451 0x0ccc  kbdclass - ok
10:03:21.0471 0x0ccc  kbdhid - ok
10:03:21.0484 0x0ccc  kdnic - ok
10:03:21.0488 0x0ccc  KeyIso - ok
10:03:21.0528 0x0ccc  [ 97E3E8F35632EECD0ABD2DE6519A9666, ABE96FDEB1076E380D7FB4975C020B43ED4E821097EFC6AFE8C75D764167D6E8 ] kl1             C:\WINDOWS\system32\DRIVERS\kl1.sys
10:03:21.0566 0x0ccc  kl1 - ok
10:03:21.0579 0x0ccc  [ B01AD8DA034EE42D4C2282F77FDB03AE, 3FF55F3CEE4A0E5D559F04F5A639297EA0F36580720E94CF9DD56DEBF2E98F39 ] klbackupdisk    C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys
10:03:21.0591 0x0ccc  klbackupdisk - ok
10:03:21.0604 0x0ccc  [ 10549B5BFD9A3DCF4FFA6287236FA959, 6BDFA335A8E3A69425CB23230660D3168CB82911ACB3AAAF85C19263511EAF51 ] klbackupflt     C:\WINDOWS\system32\DRIVERS\klbackupflt.sys
10:03:21.0616 0x0ccc  klbackupflt - ok
10:03:21.0626 0x0ccc  [ 7DAA9047F50BF5A3F8C147719FC520AF, 0740387075AF46DB1E9AEE3B12C65A06EDFE58EADB8B562C36CB1FEFF9905C26 ] kldisk          C:\WINDOWS\system32\DRIVERS\kldisk.sys
10:03:21.0638 0x0ccc  kldisk - ok
10:03:21.0659 0x0ccc  [ 5766A27C85EE813029831D125D2EFB45, BB5BAFD5A58E80C7F0B8D24121352E0386B3422FFC16B56F1D1B1C6A482AC9F0 ] klelam          C:\WINDOWS\system32\DRIVERS\klelam.sys
10:03:21.0685 0x0ccc  klelam - ok
10:03:21.0712 0x0ccc  [ 63FD545876EF4248BE3C8788D8270758, 5FF6529F8D7F94848E68142D8B2CAA446342AF95644C9223E689E303E8AB7336 ] klflt           C:\WINDOWS\system32\DRIVERS\klflt.sys
10:03:21.0726 0x0ccc  klflt - ok
10:03:21.0766 0x0ccc  [ 3524D3B8F5BEF8C01EAF7EEFFA5EAB3F, 0908A6E3E62017F7099900850D58A1B775D808F7DC0951B09781689DF3994DA2 ] klhk            C:\WINDOWS\System32\drivers\klhk.sys
10:03:21.0787 0x0ccc  klhk - ok
10:03:21.0865 0x0ccc  [ 7796EAD58D8C1A42AAB6B6CA9A3F106C, 7DA8A05A0210F63C7D120DCF0101AD895D53368C0DED23E275F2BA79239FCE28 ] klids           C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys
10:03:21.0893 0x0ccc  klids - ok
10:03:21.0942 0x0ccc  [ 2CE22F21119A089277B067A1B1BDC592, 7CDE229899B6344967098FB03C7C1C360CC3DC2DCC096F8AAC6CC96536FF1AE9 ] KLIF            C:\WINDOWS\system32\DRIVERS\klif.sys
10:03:21.0978 0x0ccc  KLIF - ok
10:03:21.0992 0x0ccc  [ 6357C533C30650361110DBAF59A25DF8, FA8CF6292CCBC7E23527D968E54CD773706CF091E35563B0CF9F8A1DF0B724B9 ] KLIM6           C:\WINDOWS\system32\DRIVERS\klim6.sys
10:03:22.0004 0x0ccc  KLIM6 - ok
10:03:22.0024 0x0ccc  [ 5480CC93737F48282552C84FA7EBA59B, B7D92424399B647132F6B9409FE75EAA310C984F796FC0B65BBE2EA180110968 ] klkbdflt        C:\WINDOWS\system32\DRIVERS\klkbdflt.sys
10:03:22.0036 0x0ccc  klkbdflt - ok
10:03:22.0041 0x0ccc  [ FD47C92A63B6EADEA830BFA96C06EAEE, C15C39B6FA53CBD01A2F95243845C4B706B4229F8FFB75C7128819B9CEE5B2CB ] klmouflt        C:\WINDOWS\system32\DRIVERS\klmouflt.sys
10:03:22.0053 0x0ccc  klmouflt - ok
10:03:22.0076 0x0ccc  [ 6B0C605591C892CBB683F63EA47822DC, E74C0A0501A1B4B56B417402108521F34DA6A23FCD1C05E4E524E41EBA0906FF ] klpd            C:\WINDOWS\system32\DRIVERS\klpd.sys
10:03:22.0088 0x0ccc  klpd - ok
10:03:22.0126 0x0ccc  [ 828B042A95F055648DA190DF6C7AB1B6, 0457B0EF03BCB4CC1297EB25A25C162937F456BF406EC7B1A5E9A0AA13A9BCD7 ] kltap           C:\WINDOWS\System32\drivers\kltap.sys
10:03:22.0137 0x0ccc  kltap - ok
10:03:22.0168 0x0ccc  [ 66516A704F1D378E58B85D79633C103D, 54E3EB342D2FD17CF742A8ACADCA81A553216AA289955DD176A54D6414727DA5 ] klupd_klif_arkmon C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
10:03:22.0183 0x0ccc  klupd_klif_arkmon - ok
10:03:22.0213 0x0ccc  [ 941727CDC11A0E1A407B602D88CD58CB, 8E290245A42E75FC532A72A850BAF5516BA7488BEF015F46CA9D215BCA0D7CE0 ] klupd_klif_kimul C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
10:03:22.0225 0x0ccc  klupd_klif_kimul - ok
10:03:22.0248 0x0ccc  [ 55FC7F42A5AA55A265CE466227ABD0DE, AB72152F39460327D74DB693BFB36A93BC2D752653D3633BB7F439DC4B9AB081 ] klupd_klif_klark C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
10:03:22.0263 0x0ccc  klupd_klif_klark - ok
10:03:22.0277 0x0ccc  [ D7709E365C10F99DE58BB688C45358B7, C028FB885B7A4AFB98FD2B8EABF99E913F480891A9ED859FE5B4E077BDE8ACB5 ] klupd_klif_klbg C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
10:03:22.0290 0x0ccc  klupd_klif_klbg - ok
10:03:22.0302 0x0ccc  [ 8D7E0B5D4F843D39AA1F644B2578B0EE, C4A8E569A253738AA7B7CDE8D0E987954D1DA6BE6F32D962BD458CA5275A5D76 ] klupd_klif_mark C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
10:03:22.0315 0x0ccc  klupd_klif_mark - ok
10:03:22.0390 0x0ccc  [ D7F0B46844565E2ED68AC99AF0F4263F, AB419CBC29F96703237127AC4178A5365D4CCA010BAB1BD66D100D635E6E89B8 ] klvssbrigde64   C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe
10:03:22.0411 0x0ccc  klvssbrigde64 - ok
10:03:22.0429 0x0ccc  [ 4C5305295B51BA72FC9C8CDAB32F95C3, 0E5850AC4CA14D971E7B04FED23CB2F6CEEE2796E905AADA0104677982ECD58A ] klwfp           C:\WINDOWS\system32\DRIVERS\klwfp.sys
10:03:22.0442 0x0ccc  klwfp - ok
10:03:22.0462 0x0ccc  [ EF1AFCADCA485B3846D7A8B71F87509B, C27B579742389ACD8804EC372CBA3C4FDFFB1A8AA6280AE1353BC089E8E34C76 ] Klwtp           C:\WINDOWS\system32\DRIVERS\klwtp.sys
10:03:22.0476 0x0ccc  Klwtp - ok
10:03:22.0493 0x0ccc  [ 67EFD862ACEFCB9687523832C62FA584, B3C9A36C535B706EB19E5C5437705E8C5EC71F45115A2C97E1348462EC2A3922 ] kneps           C:\WINDOWS\system32\DRIVERS\kneps.sys
10:03:22.0507 0x0ccc  kneps - ok
10:03:22.0535 0x0ccc  [ EFF5EA6088DB81C6EF6EDCDA5EE79909, 4D364B0BF012C335FA3B25BDF042D4AF672D961B9B48CB7C5BE34FCFD1D64979 ] KSDE1.0.0       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
10:03:22.0549 0x0ccc  KSDE1.0.0 - ok
10:03:22.0563 0x0ccc  KSecDD - ok
10:03:22.0570 0x0ccc  KSecPkg - ok
10:03:22.0580 0x0ccc  ksthunk - ok
10:03:22.0606 0x0ccc  KtmRm - ok
10:03:22.0613 0x0ccc  LanmanServer - ok
10:03:22.0624 0x0ccc  LanmanWorkstation - ok
10:03:22.0636 0x0ccc  lfsvc - ok
10:03:22.0648 0x0ccc  LicenseManager - ok
10:03:22.0655 0x0ccc  lltdio - ok
10:03:22.0659 0x0ccc  lltdsvc - ok
10:03:22.0677 0x0ccc  lmhosts - ok
10:03:22.0690 0x0ccc  LSI_SAS - ok
10:03:22.0694 0x0ccc  LSI_SAS2i - ok
10:03:22.0700 0x0ccc  LSI_SAS3i - ok
10:03:22.0704 0x0ccc  LSI_SSS - ok
10:03:22.0709 0x0ccc  LSM - ok
10:03:22.0715 0x0ccc  luafv - ok
10:03:22.0728 0x0ccc  MapsBroker - ok
10:03:22.0752 0x0ccc  [ 78BFF5425E044086E74E78650A359FBB, 294738C10F3ED933D4EC40EA0659372FCF19A3C6D45D356917438CA495F2CB45 ] MBAMProtector   C:\WINDOWS\system32\drivers\mbam.sys
10:03:22.0762 0x0ccc  MBAMProtector - ok
10:03:22.0818 0x0ccc  [ F1A89A34388B5626F1548D393B23ECB1, EA00AC76C4C8C9340753B58A3313C9177A9B98F9F1BDE08F184CD0F53D0C186F ] MBAMService     C:\Program Files (x86)\ Malwarebytes Anti-Malware  \mbamservice.exe
10:03:22.0854 0x0ccc  MBAMService - ok
10:03:22.0903 0x0ccc  [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy   C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
10:03:22.0916 0x0ccc  MBAMSwissArmy - ok
10:03:22.0939 0x0ccc  [ 898415AC0B5F1D2A9A48ABCB68A6DC4B, E1FD9AE5E22E3E5A18288E66A6184E92A4B63A1274DCE147A7728BB09C6A225E ] MBAMWebAccessControl C:\WINDOWS\system32\drivers\mwac.sys
10:03:22.0951 0x0ccc  MBAMWebAccessControl - ok
10:03:22.0981 0x0ccc  megasas - ok
10:03:23.0006 0x0ccc  megasas2i - ok
10:03:23.0014 0x0ccc  megasr - ok
10:03:23.0051 0x0ccc  MessagingService - ok
10:03:23.0077 0x0ccc  mlx4_bus - ok
10:03:23.0097 0x0ccc  MMCSS - ok
10:03:23.0108 0x0ccc  Modem - ok
10:03:23.0121 0x0ccc  monitor - ok
10:03:23.0126 0x0ccc  mouclass - ok
10:03:23.0132 0x0ccc  mouhid - ok
10:03:23.0138 0x0ccc  mountmgr - ok
10:03:23.0175 0x0ccc  [ E464A0A92E2E354D07DDA713D3E10DE4, D5CF213F03DF54EF9933027A7A7D4413371C1ECBFF61E4DE818D50FA72C8C5FC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
10:03:23.0198 0x0ccc  MozillaMaintenance - ok
10:03:23.0205 0x0ccc  mpsdrv - ok
10:03:23.0228 0x0ccc  MpsSvc - ok
10:03:23.0245 0x0ccc  MRxDAV - ok
10:03:23.0263 0x0ccc  mrxsmb - ok
10:03:23.0273 0x0ccc  mrxsmb10 - ok
10:03:23.0279 0x0ccc  mrxsmb20 - ok
10:03:23.0284 0x0ccc  MsBridge - ok
10:03:23.0299 0x0ccc  MSDTC - ok
10:03:23.0313 0x0ccc  Msfs - ok
10:03:23.0317 0x0ccc  msgpiowin32 - ok
10:03:23.0323 0x0ccc  mshidkmdf - ok
10:03:23.0331 0x0ccc  mshidumdf - ok
10:03:23.0336 0x0ccc  msisadrv - ok
10:03:23.0364 0x0ccc  MSiSCSI - ok
10:03:23.0368 0x0ccc  msiserver - ok
10:03:23.0372 0x0ccc  MSKSSRV - ok
10:03:23.0377 0x0ccc  MsLldp - ok
10:03:23.0382 0x0ccc  MSPCLOCK - ok
10:03:23.0388 0x0ccc  MSPQM - ok
10:03:23.0392 0x0ccc  MsRPC - ok
10:03:23.0400 0x0ccc  mssmbios - ok
10:03:23.0404 0x0ccc  MSTEE - ok
10:03:23.0410 0x0ccc  MTConfig - ok
10:03:23.0415 0x0ccc  Mup - ok
10:03:23.0420 0x0ccc  mvumis - ok
10:03:23.0436 0x0ccc  NativeWifiP - ok
10:03:23.0443 0x0ccc  NcaSvc - ok
10:03:23.0457 0x0ccc  NcbService - ok
10:03:23.0461 0x0ccc  NcdAutoSetup - ok
10:03:23.0467 0x0ccc  ndfltr - ok
10:03:23.0486 0x0ccc  NDIS - ok
10:03:23.0490 0x0ccc  NdisCap - ok
10:03:23.0504 0x0ccc  NdisImPlatform - ok
10:03:23.0508 0x0ccc  NdisTapi - ok
10:03:23.0514 0x0ccc  Ndisuio - ok
10:03:23.0519 0x0ccc  NdisVirtualBus - ok
10:03:23.0524 0x0ccc  NdisWan - ok
10:03:23.0529 0x0ccc  ndiswanlegacy - ok
10:03:23.0534 0x0ccc  ndproxy - ok
10:03:23.0539 0x0ccc  Ndu - ok
10:03:23.0544 0x0ccc  NetAdapterCx - ok
10:03:23.0550 0x0ccc  NetBIOS - ok
10:03:23.0558 0x0ccc  NetBT - ok
10:03:23.0564 0x0ccc  Netlogon - ok
10:03:23.0579 0x0ccc  Netman - ok
10:03:23.0584 0x0ccc  netprofm - ok
10:03:23.0610 0x0ccc  NetSetupSvc - ok
10:03:23.0684 0x0ccc  NetTcpPortSharing - ok
10:03:23.0694 0x0ccc  NgcCtnrSvc - ok
10:03:23.0711 0x0ccc  NgcSvc - ok
10:03:23.0718 0x0ccc  NlaSvc - ok
10:03:23.0724 0x0ccc  Npfs - ok
10:03:23.0729 0x0ccc  npsvctrig - ok
10:03:23.0745 0x0ccc  nsi - ok
10:03:23.0749 0x0ccc  nsiproxy - ok
10:03:23.0772 0x0ccc  NTFS - ok
10:03:23.0789 0x0ccc  Null - ok
10:03:23.0799 0x0ccc  nvraid - ok
10:03:23.0803 0x0ccc  nvstor - ok
10:03:23.0816 0x0ccc  OneSyncSvc - ok
10:03:23.0884 0x0ccc  [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:03:23.0905 0x0ccc  ose - ok
10:03:24.0075 0x0ccc  [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc         C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
10:03:24.0204 0x0ccc  osppsvc - ok
10:03:24.0233 0x0ccc  p2pimsvc - ok
10:03:24.0239 0x0ccc  p2psvc - ok
10:03:24.0248 0x0ccc  Parport - ok
10:03:24.0262 0x0ccc  partmgr - ok
10:03:24.0289 0x0ccc  PcaSvc - ok
10:03:24.0307 0x0ccc  pci - ok
10:03:24.0331 0x0ccc  pciide - ok
10:03:24.0335 0x0ccc  pcmcia - ok
10:03:24.0339 0x0ccc  pcw - ok
10:03:24.0354 0x0ccc  pdc - ok
10:03:24.0365 0x0ccc  PEAUTH - ok
10:03:24.0369 0x0ccc  percsas2i - ok
10:03:24.0374 0x0ccc  percsas3i - ok
10:03:24.0432 0x0ccc  PerfHost - ok
10:03:24.0473 0x0ccc  PhoneSvc - ok
10:03:24.0494 0x0ccc  PimIndexMaintenanceSvc - ok
10:03:24.0533 0x0ccc  pla - ok
10:03:24.0547 0x0ccc  PlugPlay - ok
10:03:24.0554 0x0ccc  PNRPAutoReg - ok
10:03:24.0563 0x0ccc  PNRPsvc - ok
10:03:24.0580 0x0ccc  PolicyAgent - ok
10:03:24.0590 0x0ccc  Power - ok
10:03:24.0597 0x0ccc  PptpMiniport - ok
10:03:24.0743 0x0ccc  [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify     C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
10:03:24.0898 0x0ccc  PrintNotify - ok
10:03:24.0923 0x0ccc  Processor - ok
10:03:24.0933 0x0ccc  ProfSvc - ok
10:03:24.0948 0x0ccc  Psched - ok
10:03:24.0977 0x0ccc  QWAVE - ok
10:03:24.0982 0x0ccc  QWAVEdrv - ok
10:03:24.0988 0x0ccc  RasAcd - ok
10:03:25.0027 0x0ccc  RasAgileVpn - ok
10:03:25.0046 0x0ccc  RasAuto - ok
10:03:25.0050 0x0ccc  Rasl2tp - ok
10:03:25.0087 0x0ccc  RasMan - ok
10:03:25.0093 0x0ccc  RasPppoe - ok
10:03:25.0101 0x0ccc  RasSstp - ok
10:03:25.0108 0x0ccc  rdbss - ok
10:03:25.0129 0x0ccc  rdpbus - ok
10:03:25.0138 0x0ccc  RDPDR - ok
10:03:25.0177 0x0ccc  RdpVideoMiniport - ok
10:03:25.0184 0x0ccc  rdyboost - ok
10:03:25.0191 0x0ccc  ReFSv1 - ok
10:03:25.0199 0x0ccc  RemoteAccess - ok
10:03:25.0207 0x0ccc  RemoteRegistry - ok
10:03:25.0235 0x0ccc  RetailDemo - ok
10:03:25.0251 0x0ccc  RmSvc - ok
10:03:25.0256 0x0ccc  RpcEptMapper - ok
10:03:25.0265 0x0ccc  RpcLocator - ok
10:03:25.0269 0x0ccc  RpcSs - ok
10:03:25.0281 0x0ccc  rspndr - ok
10:03:25.0292 0x0ccc  rt640x64 - ok
10:03:25.0304 0x0ccc  RTL8192su - ok
10:03:25.0308 0x0ccc  s3cap - ok
10:03:25.0326 0x0ccc  SamSs - ok
10:03:25.0341 0x0ccc  sbp2port - ok
10:03:25.0353 0x0ccc  SCardSvr - ok
10:03:25.0361 0x0ccc  ScDeviceEnum - ok
10:03:25.0365 0x0ccc  scfilter - ok
10:03:25.0370 0x0ccc  Schedule - ok
10:03:25.0374 0x0ccc  scmbus - ok
10:03:25.0381 0x0ccc  scmdisk0101 - ok
10:03:25.0393 0x0ccc  SCPolicySvc - ok
10:03:25.0409 0x0ccc  sdbus - ok
10:03:25.0420 0x0ccc  SDRSVC - ok
10:03:25.0425 0x0ccc  sdstor - ok
10:03:25.0431 0x0ccc  seclogon - ok
10:03:25.0436 0x0ccc  SENS - ok
10:03:25.0456 0x0ccc  SensorDataService - ok
10:03:25.0460 0x0ccc  SensorService - ok
10:03:25.0465 0x0ccc  SensrSvc - ok
10:03:25.0470 0x0ccc  SerCx - ok
10:03:25.0474 0x0ccc  SerCx2 - ok
10:03:25.0480 0x0ccc  Serenum - ok
10:03:25.0484 0x0ccc  Serial - ok
10:03:25.0489 0x0ccc  sermouse - ok
10:03:25.0501 0x0ccc  SessionEnv - ok
10:03:25.0505 0x0ccc  sfloppy - ok
10:03:25.0537 0x0ccc  SharedAccess - ok
10:03:25.0556 0x0ccc  ShellHWDetection - ok
10:03:25.0570 0x0ccc  shpamsvc - ok
10:03:25.0574 0x0ccc  SiSRaid2 - ok
10:03:25.0579 0x0ccc  SiSRaid4 - ok
10:03:25.0628 0x0ccc  smphost - ok
10:03:25.0633 0x0ccc  SmsRouter - ok
10:03:25.0641 0x0ccc  SNMPTRAP - ok
10:03:25.0662 0x0ccc  spaceport - ok
10:03:25.0666 0x0ccc  SpbCx - ok
10:03:25.0679 0x0ccc  Spooler - ok
10:03:25.0695 0x0ccc  sppsvc - ok
10:03:25.0699 0x0ccc  srv - ok
10:03:25.0715 0x0ccc  srv2 - ok
10:03:25.0719 0x0ccc  srvnet - ok
10:03:25.0723 0x0ccc  SSDPSRV - ok
10:03:25.0738 0x0ccc  SstpSvc - ok
10:03:25.0757 0x0ccc  StateRepository - ok
10:03:25.0774 0x0ccc  stexstor - ok
10:03:25.0781 0x0ccc  stisvc - ok
10:03:25.0785 0x0ccc  storahci - ok
10:03:25.0790 0x0ccc  storflt - ok
10:03:25.0795 0x0ccc  stornvme - ok
10:03:25.0800 0x0ccc  storqosflt - ok
10:03:25.0804 0x0ccc  StorSvc - ok
10:03:25.0809 0x0ccc  storufs - ok
10:03:25.0815 0x0ccc  storvsc - ok
10:03:25.0820 0x0ccc  svsvc - ok
10:03:25.0824 0x0ccc  swenum - ok
10:03:25.0830 0x0ccc  swprv - ok
10:03:25.0846 0x0ccc  Synth3dVsc - ok
10:03:25.0875 0x0ccc  SysMain - ok
10:03:25.0908 0x0ccc  SystemEventsBroker - ok
10:03:25.0942 0x0ccc  TabletInputService - ok
10:03:25.0949 0x0ccc  TapiSrv - ok
10:03:25.0969 0x0ccc  Tcpip - ok
10:03:25.0974 0x0ccc  Tcpip6 - ok
10:03:25.0982 0x0ccc  tcpipreg - ok
10:03:25.0989 0x0ccc  tdx - ok
10:03:25.0993 0x0ccc  terminpt - ok
10:03:25.0999 0x0ccc  TermService - ok
10:03:26.0014 0x0ccc  Themes - ok
10:03:26.0035 0x0ccc  TieringEngineService - ok
10:03:26.0039 0x0ccc  tiledatamodelsvc - ok
10:03:26.0059 0x0ccc  TimeBrokerSvc - ok
10:03:26.0076 0x0ccc  TPM - ok
10:03:26.0081 0x0ccc  TrkWks - ok
10:03:26.0112 0x0ccc  TrustedInstaller - ok
10:03:26.0118 0x0ccc  tsusbflt - ok
10:03:26.0123 0x0ccc  TsUsbGD - ok
10:03:26.0127 0x0ccc  tunnel - ok
10:03:26.0156 0x0ccc  tzautoupdate - ok
10:03:26.0160 0x0ccc  UASPStor - ok
10:03:26.0166 0x0ccc  UcmCx0101 - ok
10:03:26.0171 0x0ccc  UcmTcpciCx0101 - ok
10:03:26.0176 0x0ccc  UcmUcsi - ok
10:03:26.0181 0x0ccc  Ucx01000 - ok
10:03:26.0187 0x0ccc  UdeCx - ok
10:03:26.0192 0x0ccc  udfs - ok
10:03:26.0197 0x0ccc  UEFI - ok
10:03:26.0202 0x0ccc  Ufx01000 - ok
10:03:26.0207 0x0ccc  UfxChipidea - ok
10:03:26.0211 0x0ccc  ufxsynopsys - ok
10:03:26.0221 0x0ccc  UI0Detect - ok
10:03:26.0226 0x0ccc  umbus - ok
10:03:26.0231 0x0ccc  UmPass - ok
10:03:26.0236 0x0ccc  UmRdpService - ok
10:03:26.0241 0x0ccc  UnistoreSvc - ok
10:03:26.0249 0x0ccc  upnphost - ok
10:03:26.0254 0x0ccc  UrsChipidea - ok
10:03:26.0258 0x0ccc  UrsCx01000 - ok
10:03:26.0264 0x0ccc  UrsSynopsys - ok
10:03:26.0269 0x0ccc  usbccgp - ok
10:03:26.0274 0x0ccc  usbcir - ok
10:03:26.0279 0x0ccc  usbehci - ok
10:03:26.0284 0x0ccc  usbhub - ok
10:03:26.0289 0x0ccc  USBHUB3 - ok
10:03:26.0295 0x0ccc  usbohci - ok
10:03:26.0300 0x0ccc  usbprint - ok
10:03:26.0305 0x0ccc  usbser - ok
10:03:26.0310 0x0ccc  USBSTOR - ok
10:03:26.0315 0x0ccc  usbuhci - ok
10:03:26.0320 0x0ccc  USBXHCI - ok
10:03:26.0329 0x0ccc  UserDataSvc - ok
10:03:26.0369 0x0ccc  UserManager - ok
10:03:26.0390 0x0ccc  UsoSvc - ok
10:03:26.0394 0x0ccc  VaultSvc - ok
10:03:26.0419 0x0ccc  vdrvroot - ok
10:03:26.0427 0x0ccc  vds - ok
10:03:26.0432 0x0ccc  VerifierExt - ok
10:03:26.0447 0x0ccc  vhdmp - ok
10:03:26.0451 0x0ccc  vhf - ok
10:03:26.0455 0x0ccc  vmbus - ok
10:03:26.0460 0x0ccc  VMBusHID - ok
10:03:26.0481 0x0ccc  vmgid - ok
10:03:26.0501 0x0ccc  vmicguestinterface - ok
10:03:26.0506 0x0ccc  vmicheartbeat - ok
10:03:26.0512 0x0ccc  vmickvpexchange - ok
10:03:26.0530 0x0ccc  vmicrdv - ok
10:03:26.0535 0x0ccc  vmicshutdown - ok
10:03:26.0540 0x0ccc  vmictimesync - ok
10:03:26.0546 0x0ccc  vmicvmsession - ok
10:03:26.0551 0x0ccc  vmicvss - ok
10:03:26.0557 0x0ccc  volmgr - ok
10:03:26.0562 0x0ccc  volmgrx - ok
10:03:26.0568 0x0ccc  volsnap - ok
10:03:26.0572 0x0ccc  volume - ok
10:03:26.0584 0x0ccc  vpci - ok
10:03:26.0588 0x0ccc  vsmraid - ok
10:03:26.0593 0x0ccc  VSS - ok
10:03:26.0598 0x0ccc  VSTXRAID - ok
10:03:26.0603 0x0ccc  vwifibus - ok
10:03:26.0608 0x0ccc  vwififlt - ok
10:03:26.0613 0x0ccc  vwifimp - ok
10:03:26.0618 0x0ccc  W32Time - ok
10:03:26.0623 0x0ccc  WacomPen - ok
10:03:26.0634 0x0ccc  WalletService - ok
10:03:26.0638 0x0ccc  wanarp - ok
10:03:26.0642 0x0ccc  wanarpv6 - ok
10:03:26.0648 0x0ccc  wbengine - ok
10:03:26.0669 0x0ccc  WbioSrvc - ok
10:03:26.0684 0x0ccc  wcifs - ok
10:03:26.0688 0x0ccc  Wcmsvc - ok
10:03:26.0704 0x0ccc  wcncsvc - ok
10:03:26.0708 0x0ccc  wcnfs - ok
10:03:26.0714 0x0ccc  WdBoot - ok
10:03:26.0718 0x0ccc  Wdf01000 - ok
10:03:26.0723 0x0ccc  WdFilter - ok
10:03:26.0729 0x0ccc  WdiServiceHost - ok
10:03:26.0734 0x0ccc  WdiSystemHost - ok
10:03:26.0749 0x0ccc  wdiwifi - ok
10:03:26.0753 0x0ccc  WdNisDrv - ok
10:03:26.0784 0x0ccc  WdNisSvc - ok
10:03:26.0790 0x0ccc  WebClient - ok
10:03:26.0795 0x0ccc  Wecsvc - ok
10:03:26.0800 0x0ccc  WEPHOSTSVC - ok
10:03:26.0805 0x0ccc  wercplsupport - ok
10:03:26.0810 0x0ccc  WerSvc - ok
10:03:26.0816 0x0ccc  WFPLWFS - ok
10:03:26.0820 0x0ccc  WiaRpc - ok
10:03:26.0825 0x0ccc  WIMMount - ok
10:03:26.0830 0x0ccc  WinDefend - ok
10:03:26.0855 0x0ccc  WindowsTrustedRT - ok
10:03:26.0859 0x0ccc  WindowsTrustedRTProxy - ok
10:03:26.0876 0x0ccc  WinHttpAutoProxySvc - ok
10:03:26.0881 0x0ccc  WinMad - ok
10:03:26.0916 0x0ccc  Winmgmt - ok
10:03:26.0946 0x0ccc  WinRM - ok
10:03:26.0956 0x0ccc  WINUSB - ok
10:03:26.0971 0x0ccc  WinVerbs - ok
10:03:26.0997 0x0ccc  wisvc - ok
10:03:27.0018 0x0ccc  WlanSvc - ok
10:03:27.0041 0x0ccc  wlidsvc - ok
10:03:27.0046 0x0ccc  WmiAcpi - ok
10:03:27.0053 0x0ccc  wmiApSrv - ok
10:03:27.0065 0x0ccc  WMPNetworkSvc - ok
10:03:27.0079 0x0ccc  Wof - ok
10:03:27.0123 0x0ccc  workfolderssvc - ok
10:03:27.0127 0x0ccc  WPDBusEnum - ok
10:03:27.0141 0x0ccc  WpdUpFltr - ok
10:03:27.0146 0x0ccc  WpnService - ok
10:03:27.0151 0x0ccc  WpnUserService - ok
10:03:27.0191 0x0ccc  ws2ifsl - ok
10:03:27.0196 0x0ccc  wscsvc - ok
10:03:27.0201 0x0ccc  WSearch - ok
10:03:27.0208 0x0ccc  wuauserv - ok
10:03:27.0214 0x0ccc  WudfPf - ok
10:03:27.0218 0x0ccc  WUDFRd - ok
10:03:27.0232 0x0ccc  wudfsvc - ok
10:03:27.0236 0x0ccc  WUDFWpdFs - ok
10:03:27.0255 0x0ccc  WwanSvc - ok
10:03:27.0275 0x0ccc  XblAuthManager - ok
10:03:27.0295 0x0ccc  XblGameSave - ok
10:03:27.0300 0x0ccc  xboxgip - ok
10:03:27.0305 0x0ccc  XboxNetApiSvc - ok
10:03:27.0328 0x0ccc  xinputhid - ok
10:03:27.0331 0x0ccc  ================ Scan global ===============================
10:03:27.0408 0x0ccc  [ Global ] - ok
10:03:27.0409 0x0ccc  ================ Scan MBR ==================================
10:03:27.0417 0x0ccc  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
10:03:27.0494 0x0ccc  \Device\Harddisk0\DR0 - ok
10:03:27.0495 0x0ccc  ================ Scan VBR ==================================
10:03:27.0530 0x0ccc  [ D545FDFC6FA3C1EA0A19553A0A116B83 ] \Device\Harddisk0\DR0\Partition1
10:03:27.0532 0x0ccc  \Device\Harddisk0\DR0\Partition1 - ok
10:03:27.0543 0x0ccc  [ 819F9AAD2A99FA29B91FDCC268036B52 ] \Device\Harddisk0\DR0\Partition2
10:03:27.0545 0x0ccc  \Device\Harddisk0\DR0\Partition2 - ok
10:03:27.0554 0x0ccc  [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
10:03:27.0554 0x0ccc  \Device\Harddisk0\DR0\Partition3 - ok
10:03:27.0563 0x0ccc  [ 85D3D3C3287C1776EDD7E0E319620A5F ] \Device\Harddisk0\DR0\Partition4
10:03:27.0563 0x0ccc  \Device\Harddisk0\DR0\Partition4 - ok
10:03:27.0598 0x0ccc  [ 2C1079B25328462261E1C6098363D2F0 ] \Device\Harddisk0\DR0\Partition5
10:03:27.0600 0x0ccc  \Device\Harddisk0\DR0\Partition5 - ok
10:03:27.0616 0x0ccc  [ 9FA6006FFB3B0176B9BE3583EE76CFCA ] \Device\Harddisk0\DR0\Partition6
10:03:27.0618 0x0ccc  \Device\Harddisk0\DR0\Partition6 - ok
10:03:27.0618 0x0ccc  ================ Scan generic autorun ======================
10:03:27.0729 0x0ccc  [ 4C6AAABB264526A9C845A39AEBB79B69, B27F869E8B44CC5F1F9ADCA53AA848C16D706587ED9C7F995AE59BF9B0426523 ] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe
10:03:27.0762 0x0ccc  StartCCC - ok
10:03:27.0816 0x0ccc  [ F8A8125BF28F03D79CDEA5B0B69FF60B, 13E5DE36EB61384B0726447442F0CE4838C20E4F3F730B9B9BB84A2020A68A82 ] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
10:03:27.0843 0x0ccc  IJNetworkScannerSelectorEX - ok
10:03:27.0904 0x0ccc  [ CD0362AEE36CFE1EF5DF973230742E67, 9F1D8AD4E09D16C39CD6A35CB298456468C1808226FFA8AD65BF9562A6ECC07D ] C:\Program Files (x86)\PDF24\pdf24.exe
10:03:27.0929 0x0ccc  PDFPrint - ok
10:03:27.0999 0x0ccc  OneDriveSetup - ok
10:03:28.0002 0x0ccc  OneDriveSetup - ok
10:03:28.0075 0x0ccc  [ 06F6DB72ADABC5E858F38EF69014CE52, B4AEABF3EA6FCABBED879D642BA070DF9C244E28DB5BDC3211205C7B8DB97BFB ] C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
10:03:28.0103 0x0ccc  OfficeSyncProcess - ok
10:03:28.0109 0x0ccc  Waiting for KSN requests completion. In queue: 18
10:03:29.0144 0x0ccc  AV detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\wmiav.exe ( 17.0.0.611 ), 0x41000 ( enabled : updated )
10:03:29.0197 0x0ccc  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
10:03:29.0200 0x0ccc  FW detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\wmiav.exe ( 17.0.0.611 ), 0x41010 ( enabled )
10:03:29.0337 0x0ccc  ============================================================
10:03:29.0337 0x0ccc  Scan finished
10:03:29.0337 0x0ccc  ============================================================
10:03:29.0354 0x2b04  Detected object count: 0
10:03:29.0354 0x2b04  Actual detected object count: 0