Scan mit mbar    Danke! 
Ich habe Kaspersky entfernt, und mit mbar gescannt. 
MSE hat am 04.01. einen Fund gemeldet.     Code:  
 Malwarebytes Anti-Rootkit BETA 1.9.3.1001 
www.malwarebytes.org   
Database version: 
  main:    v2016.01.06.04 
  rootkit: v2016.01.05.01   
Windows 7 Service Pack 1 x86 NTFS 
Internet Explorer 11.0.9600.18124 
Admin :: JOLIWA [administrator]   
06.01.2016 19:29:36 
mbar-log-2016-01-06 (19-29-36).txt   
Scan type: Quick scan 
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken 
Scan options disabled:  
Objects scanned: 370218 
Time elapsed: 35 minute(s), 2 second(s)   
Memory Processes Detected: 0 
(No malicious items detected)   
Memory Modules Detected: 0 
(No malicious items detected)   
Registry Keys Detected: 0 
(No malicious items detected)   
Registry Values Detected: 0 
(No malicious items detected)   
Registry Data Items Detected: 0 
(No malicious items detected)   
Folders Detected: 0 
(No malicious items detected)   
Files Detected: 0 
(No malicious items detected)   
Physical Sectors Detected: 0 
(No malicious items detected)   
(end)    Code:  
  
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 12-31-2015 00:18:50 
************************************************************ 
2015-12-30T23:18:50.179Z Trace session started - MpWppTracing-12312015-001850-00000003-ffffffff.binResetting SFCState failed with 0x80070015**********Cache stats************ 
No. Of buckets -> 12800 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 0 
Number of invalid entries is 0 
Number of inserts issued is 0 
Number of replaces issued is 0 
Number of insert failures is 0 
Number of inserts with duplicate entries is 0 
Number of lookups is 0 
Number of lookup misses is 0 
Number of fast lookup misses is 0 
Number of false fast lookups is 0 
Number of invalidations is 0 
Number of maintenance invalidations is 0 
Current File Size is 319488 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2015-12-30T23:18:50.475Z Verifying RTP plugin... 
2015-12-30T23:18:50.625Z verified! 
2015-12-30T23:18:50.821Z Verifying Nis plugin... 
2015-12-30T23:18:50.854Z verified! 
2015-12-30T23:18:50.858Z Initializing Nis plugin state... 
2015-12-30T23:18:50.858Z Nis initialized! 
2015-12-30T23:18:50.858Z Loading engine... 
2015-12-30T23:18:50.865Z CSignatureStatus: changed to DUE_REPORTED 
2015-12-30T23:18:50.866Z loaded! 
2015-12-30T23:18:50.906Z Verifying license file... 
2015-12-30T23:18:50.951Z verified! 
2015-12-30T23:18:50.952Z Product supports installmode: 0 
2015-12-30T23:18:50.957Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.5.216.0 
Service Version: 4.5.216.0 
Engine Version: 0.0.0.0 
AS Signature Version: 0.0.0.0 
AV Signature Version: 0.0.0.0 
************************************************************ 
2015-12-30T23:18:55.685Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(0) 
2015-12-30T23:18:55.737Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(0) 
2015-12-30T23:18:57.762Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(0) 
2015-12-30T23:18:57.779Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(0) 
2015-12-30T23:18:59.819Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(0) 
2015-12-30T23:18:59.837Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(0) 
2015-12-30T23:19:08.244Z Task(SignaturesUpdateService -UnmanagedUpdate) launched 
2015-12-30T23:19:50.958Z Calling MpUpdateStart with update options = 257 
2015-12-30T23:28:50.957Z AutoPurgeWorker triggered with dwWork=0x3 
2015-12-30T23:28:50.958Z Product supports installmode: 0 
2015-12-30T23:28:50.961Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
2015-12-30T23:28:51.324Z Trace buffers written: 12, events lost: 0, buffers lost: 0, days: 0 
2015-12-30T23:28:51.324Z Trusted image bitmap: 0x1 
2015-12-30T23:28:51.324Z Trusted image OEM name: (not found) 
2015-12-30T23:28:51.324Z Start sending one time SQM data points. 
2015-12-30T23:28:51.325Z Finished sending one time SQM data points. 
2015-12-30T23:28:51.397Z Task(-UploadSQM -RestrictPrivileges) launched 
2015-12-30T23:28:51.493Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2015-12-30T23:28:51.495Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 5387107(ms) 
2015-12-30T23:45:04.867Z Verifying engine and signature files (source: 0) ... 
2015-12-30T23:45:06.775Z verified! 
2015-12-30T23:45:26.874Z Initializing SQM in engine... 
2015-12-30T23:45:26.874Z SQM initialized in the engine successfully 
2015-12-30T23:45:27.899Z CSignatureStatus: back to good 
2015-12-30T23:45:27.899Z Initializing RTP plugin state... 
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:N/A 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,1,0 
  SetEngine:1,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:0 
  AsyncQCurrent:0 
  BMFlags:0 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:6 
  TotalStreamCon:936 
  TotalBitmap:113040 
  NTFS Cache Statistics: 
   TotalMisses:10404 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2015-12-30T23:45:27.900Z initialized! 
Signature updated on 12-31-2015 00:45:27 
Product Version: 4.5.216.0 
Service Version: 4.5.216.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1379.0 
AV Signature Version: 1.213.1379.0 
************************************************************ 
2015-12-30T23:45:28.132Z Process scan (postsignatureupdatescan) started. 
2015-12-30T23:45:30.027Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:30.051Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:32.381Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:32.402Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
Signature updated via MicrosoftUpdateServer on 12-31-2015 00:45:33 
************************************************************ 
2015-12-30T23:45:34.480Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:34.500Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:36.553Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:36.577Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:38.631Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:38.654Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:40.709Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:40.757Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:42.934Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:42.956Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:45.029Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-30T23:45:45.073Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1)   
BEGIN BM telemetry 
GUID:{09D9EC19-48D9-C250-A542-90483D28D827} 
TelemetryName:Behavior:Win32/MpTamperIoavClsidDelete.A 
SignatureID:243761822934816 
ProcessID:5156 
ProcessCreationTime:0 
SessionID:4294967295 
CreationTime:12-31-2015 00:45:30 
ImagePath:C:\Windows\System32\svchost.exe 
ImagePathHash:121118A0F5E0E8C933EFD28C9901E54E42792619A8A3A6D11E1F0025A7324BC2 
END BM telemetry   
2015-12-30T23:45:49.040Z Dynamic signature received 
Dynamic Signature has been received 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\8ea90f7a839cdcda0410ed7cb6ea15d5b71c4793 
Dynamic Signature Compilation Timestamp:12-31-2015 00:45:49 
Persistence Type:Duration 
Time remaining:216000000 
DSS Timeout:Received results after timeout 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
2015-12-30T23:50:15.479Z Dynamic signature received 
Dynamic Signature has been received 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\02d3942fefdb6158b94c870c32256580c73bc77a 
Dynamic Signature Compilation Timestamp:12-31-2015 00:50:15 
Persistence Type:Duration 
Time remaining:216000000 
2015-12-30T23:50:15.865Z Process scan (postsignatureupdatescan) completed. 
2015-12-30T23:55:28.111Z Process scan (poststartupscan) started. 
2015-12-30T23:56:11.931Z Process scan (poststartupscan) completed. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\system32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\\?\C:\Windows\system32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\system32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\system32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\system32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\system32\Sens_oal.dll" 
Begin Resource Scan 
Scan ID:{8F093B0F-1896-470D-B8A4-7634B41F51A9} 
Scan Source:7 
Start Time:12-31-2015 01:11:12 
End Time:12-31-2015 01:11:27 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Windows\system32\Sens_oal.dll 
Result Count:1 
Unknown File 
Identifier:18103529816144740350 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Windows\system32\Sens_oal.dll 
Extended Info:65519410711387 
End Scan 
************************************************************   
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=true, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Begin Resource Scan 
Scan ID:{53FA064F-4C68-49F1-8E37-06872723E7C7} 
Scan Source:7 
Start Time:12-31-2015 01:19:26 
End Time:12-31-2015 01:19:31 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Result Count:1 
Unknown File 
Identifier:6723857877691269118 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Extended Info:5863886377321 
End Scan 
************************************************************   
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\Creative\ALchemy\dsound.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
2015-12-31T01:00:17.272Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:00:17.379Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:00:23.931Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:00:23.952Z IWscASStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:00:25.996Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:00:26.028Z IWscASStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:00:28.079Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:00:28.106Z IWscASStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:00:30.146Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:00:30.167Z IWscASStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
Begin Resource Scan 
Scan ID:{F59FA1A8-7151-4BC2-B1E4-E362A641C89C} 
Scan Source:7 
Start Time:12-31-2015 02:00:01 
End Time:12-31-2015 02:00:22 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\ALchemy\ALchemy.exe 
Result Count:1 
Unknown File 
Identifier:3058306356609023998 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\ALchemy\ALchemy.exe 
Extended Info:65519410711387 
End Scan 
************************************************************   
2015-12-31T01:11:50.498Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:11:50.515Z IWscASStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T01:11:50.778Z Reloading engine... 
2015-12-31T01:11:51.068Z Verifying engine and signature files (source: 0) ... 
2015-12-31T01:11:51.071Z verified! 
2015-12-31T01:11:52.584Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:11:52.601Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:12:14.051Z Initializing SQM in engine... 
2015-12-31T01:12:14.051Z SQM initialized in the engine successfully 
2015-12-31T01:12:14.483Z Initializing RTP plugin state... 
2015-12-31T01:12:14.484Z initialized! 
2015-12-31T01:12:14.498Z Engine reloaded 
****************************RTP Perf Log*************************** 
RTP Start:12-31-2015 00:45:27 
Last Perf:12-31-2015 00:45:27 
First RTP Scan:12-31-2015 00:45:28 
Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:3 
System File Cache: 
  Hits:826 
  Misses:4005 
BM Queue:0,97,0 
  Proc:0,90,0 
  File:0,77,0 
Plugin Queue:0,1,0 
  Threat:0,1,0 
  Susp:0,1,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:2,3,0 
  SetEngine:1,1,0 
  SetState:1,2,0 
  SetUser:0,0,0 
  Config:0,1,0 
  ProcExcl:0,2,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:5634 
  Pending:0 
  RegSize:60200 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:545058 
  AsyncQCurrent:0 
  BMFlags:3 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:6 
  TotalStreamCon:3992 
  TotalBitmap:113040 
  NTFS Cache Statistics: 
   TotalMisses:133047 
   TotalHits:51491 
   InstanceCacheHits:327 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2015-12-31T01:12:14.615Z Process scan (poststartupscan) started. 
2015-12-31T01:12:16.541Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:12:16.566Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:12:18.668Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:12:18.688Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:12:20.807Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T01:12:20.841Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 12-31-2015 04:29:35 
************************************************************ 
2015-12-31T03:29:35.500Z Trace session started - MpWppTracing-12312015-042935-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 12800 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 9587 
Number of invalid entries is 0 
Number of inserts issued is 9650 
Number of replaces issued is 0 
Number of insert failures is 0 
Number of inserts with duplicate entries is 8796 
Number of lookups is 42623 
Number of lookup misses is 1974 
Number of fast lookup misses is 33089 
Number of false fast lookups is 1974 
Number of invalidations is 11 
Number of maintenance invalidations is 0 
Current File Size is 319488 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2015-12-31T03:29:35.656Z Verifying RTP plugin... 
2015-12-31T03:29:35.671Z verified! 
2015-12-31T03:29:35.859Z Verifying Nis plugin... 
2015-12-31T03:29:35.859Z verified! 
2015-12-31T03:29:35.906Z Initializing Nis plugin state... 
2015-12-31T03:29:35.906Z Nis initialized! 
2015-12-31T03:29:35.906Z Loading engine... 
2015-12-31T03:29:36.203Z Verifying engine and signature files (source: 1) ... 
2015-12-31T03:29:36.203Z verified! 
2015-12-31T03:29:44.203Z Initializing SQM in engine... 
2015-12-31T03:29:44.250Z SQM initialized in the engine successfully 
2015-12-31T03:29:45.421Z CSignatureStatus: back to good 
2015-12-31T03:29:45.437Z Initializing RTP plugin state... 
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:N/A 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,1,0 
  SetEngine:1,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1144 
  AsyncQCurrent:0 
  BMFlags:0 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:5 
  TotalStreamCon:1352 
  TotalBitmap:113040 
  NTFS Cache Statistics: 
   TotalMisses:3440 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2015-12-31T03:29:45.437Z initialized! 
2015-12-31T03:29:45.437Z loaded! 
2015-12-31T03:29:45.578Z Verifying license file... 
2015-12-31T03:29:45.578Z verified! 
2015-12-31T03:29:45.593Z Product supports installmode: 0 
2015-12-31T03:29:45.656Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.5.216.0 
Service Version: 4.5.216.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1379.0 
AV Signature Version: 1.213.1379.0 
************************************************************ 
2015-12-31T13:58:15.187Z Process scan (poststartupscan) started. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=true, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe"   
Begin Resource Scan 
Scan ID:{71E8FE4D-1B95-4106-9EE5-9B149D9B7043} 
Scan Source:7 
Start Time:12-31-2015 14:58:48 
End Time:12-31-2015 14:58:57 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Extended Info:35872412566804 
End Scan 
************************************************************   
2015-12-31T13:59:02.694Z Process scan (poststartupscan) completed. 
2015-12-31T13:59:41.165Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T13:59:41.226Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1) and up-to-date state(1) 
2015-12-31T14:07:24.546Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 13058946(ms) 
2015-12-31T14:07:24.560Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2015-12-31T14:07:24.561Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 40718304(ms) 
2015-12-31T14:07:24.609Z Timer is triggered for missed daily auto purge tasks 
2015-12-31T14:17:24.613Z AutoPurgeWorker triggered with dwWork=0x100003 
2015-12-31T14:17:24.901Z Product supports installmode: 0 
2015-12-31T14:17:30.323Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
2015-12-31T14:17:31.912Z Trace buffers written: 48, events lost: 0, buffers lost: 0, days: 0 
2015-12-31T14:17:31.913Z Trusted image bitmap: 0x1 
2015-12-31T14:17:31.913Z Trusted image OEM name: (not found) 
2015-12-31T14:17:31.978Z Task(-UploadSQM -RestrictPrivileges) launched 
2015-12-31T14:17:32.287Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 14414241(ms) 
2015-12-31T14:17:32.290Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 39491359(ms) 
2015-12-31T14:53:25.813Z Cache Resizing**********Cache stats************ 
No. Of buckets -> 12800 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 12151 
Number of invalid entries is 0 
Number of inserts issued is 13650 
Number of replaces issued is 0 
Number of insert failures is 1 
Number of inserts with duplicate entries is 11300 
Number of lookups is 67046 
Number of lookup misses is 3482 
Number of fast lookup misses is 43372 
Number of false fast lookups is 3482 
Number of invalidations is 12 
Number of maintenance invalidations is 0 
Current File Size is 319488 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2015-12-31T14:57:47.436Z Cache Resizing**********Cache stats************ 
No. Of buckets -> 16000 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 14721 
Number of invalid entries is 0 
Number of inserts issued is 29327 
Number of replaces issued is 0 
Number of insert failures is 2 
Number of inserts with duplicate entries is 13870 
Number of lookups is 73376 
Number of lookup misses is 4592 
Number of fast lookup misses is 48592 
Number of false fast lookups is 4592 
Number of invalidations is 12 
Number of maintenance invalidations is 0 
Current File Size is 397312 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2015-12-31T15:05:24.554Z Cache Resizing**********Cache stats************ 
No. Of buckets -> 20000 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 19173 
Number of invalid entries is 0 
Number of inserts issued is 51124 
Number of replaces issued is 0 
Number of insert failures is 3 
Number of inserts with duplicate entries is 18322 
Number of lookups is 82282 
Number of lookup misses is 6198 
Number of fast lookup misses is 55892 
Number of false fast lookups is 6198 
Number of invalidations is 12 
Number of maintenance invalidations is 0 
Current File Size is 495616 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Log 
Stopped On 12-31-2015 16:32:37 (Exit Code = 0x0) 
************************************************************ 
2015-12-31T15:32:37.644Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
2015-12-31T15:32:37.707Z IWscASStatus::UpdateStatus() succceeded writing instance with state (0) and up-to-date state(1) 
****************************RTP Perf Log*************************** 
RTP Start:12-31-2015 04:29:45 
Last Perf:12-31-2015 04:29:45 
First RTP Scan:12-31-2015 04:29:45 
Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:1 
System File Cache: 
  Hits:3391 
  Misses:3180 
BM Queue:1,127,0 
  Proc:0,126,0 
  File:1,72,0 
Plugin Queue:0,1,0 
  Threat:0,1,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,3,0 
  SetEngine:1,1,0 
  SetState:0,1,0 
  SetUser:0,0,0 
  Config:0,1,0 
  ProcExcl:0,1,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:7961 
  Pending:0 
  RegSize:60200 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1964626 
  AsyncQCurrent:0 
  BMFlags:3 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:7 
  TotalStreamCon:10246 
  TotalBitmap:113040 
  NTFS Cache Statistics: 
   TotalMisses:125555 
   TotalHits:21664 
   InstanceCacheHits:902 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
****************************RTP Perf Log*************************** 
RTP Start:12-31-2015 16:32:38 
Last Perf:12-31-2015 16:32:37 
First RTP Scan:N/A 
Plugin States:  AV:1  AS:1  RTP:1  OA:1  BM:1 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:1 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:0,1,0 
  SetEngine:0,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:7961 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1964626 
  AsyncQCurrent:0 
  BMFlags:0 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:7 
  TotalStreamCon:10193 
  TotalBitmap:113040 
  NTFS Cache Statistics: 
   TotalMisses:125557 
   TotalHits:21664 
   InstanceCacheHits:902 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 01-01-2016 14:47:09 
************************************************************ 
2016-01-01T13:47:09.640Z Trace session started - MpWppTracing-01012016-144709-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 25000 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 22188 
Number of invalid entries is 0 
Number of inserts issued is 74092 
Number of replaces issued is 0 
Number of insert failures is 3 
Number of inserts with duplicate entries is 21326 
Number of lookups is 91493 
Number of lookup misses is 7251 
Number of fast lookup misses is 62417 
Number of false fast lookups is 7251 
Number of invalidations is 12 
Number of maintenance invalidations is 0 
Current File Size is 618496 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2016-01-01T13:47:09.953Z Verifying RTP plugin... 
2016-01-01T13:47:09.953Z verified! 
2016-01-01T13:47:10.140Z Verifying Nis plugin... 
2016-01-01T13:47:10.156Z verified! 
2016-01-01T13:47:10.203Z Initializing Nis plugin state... 
2016-01-01T13:47:10.203Z Nis initialized! 
2016-01-01T13:47:10.203Z Loading engine... 
2016-01-01T13:47:10.375Z Verifying engine and signature files (source: 1) ... 
2016-01-01T13:47:10.375Z verified! 
2016-01-01T13:47:43.437Z Dynamic signature dropped 
Dynamic Signature has been dropped 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\75712b95e219bf0eee0e63b448e1f0e21a2fc86d 
Dynamic Signature Compilation Timestamp:12-31-2015 19:57:15 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-01T13:47:43.514Z Initializing MPUT in engine... 
2016-01-01T13:47:43.514Z MPUT initialized in the engine successfully 
2016-01-01T13:47:43.745Z CSignatureStatus: back to good 
2016-01-01T13:47:43.746Z Initializing RTP plugin state... 
2016-01-01T13:47:43.747Z  
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:(null) 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,1,0 
  SetEngine:1,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1240 
  AsyncQCurrent:0 
  BMFlags:8 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:5 
  TotalStreamCon:2044 
  TotalBitmap:0 
  NTFS Cache Statistics: 
   TotalMisses:7858 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2016-01-01T13:47:43.747Z initialized! 
2016-01-01T13:47:43.748Z loaded! 
2016-01-01T13:47:43.810Z Verifying license file... 
2016-01-01T13:47:43.811Z verified! 
2016-01-01T13:47:43.811Z Product supports installmode: 0 
2016-01-01T13:47:43.908Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.8.204.0 
Service Version: 4.8.204.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1379.0 
AV Signature Version: 1.213.1379.0 
************************************************************ 
2016-01-01T13:48:10.090Z Task(GetDeviceTicket -AccessKey 30DA7AB1-B716-AA91-A49C-51A3B0874BF1 ) launched as network service 
2016-01-01T13:48:10.417Z Process scan (poststartupscan) started. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
2016-01-01T13:48:32.796Z Task(GetDeviceTicket -AccessKey 60C08B9B-2271-7C2C-7CCA-F8734B3BF582 ) launched as network service 
2016-01-01T13:48:34.046Z Dynamic signature received 
Dynamic Signature has been received 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\f550f9591700a75746eaae2cb1cc70164d801cb6 
Dynamic Signature Compilation Timestamp:01-01-2016 14:48:33 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-01T13:48:34.321Z Process scan (poststartupscan) completed. 
2016-01-01T13:48:50.459Z [Mini-filter] Restricted access to process 4184 from pid: 1812. Original desired access: 0x1fffff. 
2016-01-01T13:48:50.459Z [Mini-filter] Restricted access to process 4184 from pid: 1812. Original desired access: 0x1fffff. 
2016-01-01T13:49:22.555Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-01T13:49:22.594Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-01T13:57:26.304Z [Mini-filter] Restricted access to engine process from pid: 1156. Original desired access: 0x1fffff. 
2016-01-01T13:57:26.511Z [Mini-filter] Restricted access to engine process from pid: 1156. Original desired access: 0x1fffff. 
2016-01-01T13:57:30.175Z [Mini-filter] Restricted access to engine process from pid: 1156. Original desired access: 0x1fffff. 
2016-01-01T13:57:30.338Z [Mini-filter] Restricted access to engine process from pid: 1156. Original desired access: 0x1fffff. 
2016-01-01T13:57:31.261Z [Mini-filter] Restricted access to process 4184 from pid: 1156. Original desired access: 0x1fffff. 
2016-01-01T13:57:43.856Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 14956074(ms) 
2016-01-01T13:57:43.859Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2016-01-01T13:57:43.860Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 40485089(ms) 
2016-01-01T13:57:43.908Z AutoPurgeWorker triggered with dwWork=0x3 
2016-01-01T13:57:43.909Z Product supports installmode: 0 
2016-01-01T13:57:53.021Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 01-01-2016 22:21:24 
************************************************************ 
2016-01-01T21:21:24.781Z Trace session started - MpWppTracing-01012016-222124-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 25000 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 22220 
Number of invalid entries is 0 
Number of inserts issued is 74153 
Number of replaces issued is 0 
Number of insert failures is 3 
Number of inserts with duplicate entries is 21329 
Number of lookups is 104684 
Number of lookup misses is 8333 
Number of fast lookup misses is 68572 
Number of false fast lookups is 8333 
Number of invalidations is 29 
Number of maintenance invalidations is 0 
Current File Size is 618496 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2016-01-01T21:21:25.234Z Verifying RTP plugin... 
2016-01-01T21:21:25.234Z verified! 
2016-01-01T21:21:25.468Z Verifying Nis plugin... 
2016-01-01T21:21:25.484Z verified! 
2016-01-01T21:21:25.484Z Initializing Nis plugin state... 
2016-01-01T21:21:25.484Z Nis initialized! 
2016-01-01T21:21:25.484Z Loading engine... 
2016-01-01T21:21:25.593Z Verifying engine and signature files (source: 1) ... 
2016-01-01T21:21:25.593Z verified! 
2016-01-01T21:21:34.606Z Dynamic signature dropped 
Dynamic Signature has been dropped 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\f550f9591700a75746eaae2cb1cc70164d801cb6 
Dynamic Signature Compilation Timestamp:01-01-2016 14:48:33 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-01T21:21:34.684Z Initializing MPUT in engine... 
2016-01-01T21:21:34.684Z MPUT initialized in the engine successfully 
2016-01-01T21:21:35.356Z CSignatureStatus: back to good 
2016-01-01T21:21:35.356Z Initializing RTP plugin state... 
2016-01-01T21:21:35.356Z initialized! 
2016-01-01T21:21:35.356Z  
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:(null) 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,1,0 
  SetEngine:1,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1240 
  AsyncQCurrent:0 
  BMFlags:8 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:5 
  TotalStreamCon:1160 
  TotalBitmap:0 
  NTFS Cache Statistics: 
   TotalMisses:3219 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2016-01-01T21:21:35.356Z loaded! 
2016-01-01T21:21:35.512Z Verifying license file... 
2016-01-01T21:21:35.512Z verified! 
2016-01-01T21:21:35.512Z Product supports installmode: 0 
2016-01-01T21:21:35.528Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.8.204.0 
Service Version: 4.8.204.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1529.0 
AV Signature Version: 1.213.1529.0 
************************************************************ 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe"   
Begin Resource Scan 
Scan ID:{183EA626-3D94-4C03-8AEE-D6FABB028F81} 
Scan Source:7 
Start Time:01-01-2016 22:21:49 
End Time:01-01-2016 22:21:49 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Extended Info:35872412566804 
End Scan 
************************************************************   
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=true, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Begin Resource Scan 
Scan ID:{689A3CF9-EF1B-49B4-B6C2-9F27D82EA294} 
Scan Source:7 
Start Time:01-01-2016 22:22:07 
End Time:01-01-2016 22:22:19 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Result Count:1 
Unknown File 
Identifier:6723857877691269118 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Extended Info:5863886377321 
End Scan 
************************************************************   
2016-01-01T21:22:19.713Z Task(GetDeviceTicket -AccessKey D11A13A3-1464-54BE-B75C-0AE121A07853 ) launched as network service 
2016-01-01T21:22:25.353Z Task(GetDeviceTicket -AccessKey 075A53CD-233C-8F42-3E73-38283F575333 ) launched as network service 
2016-01-01T21:22:25.413Z Process scan (poststartupscan) started. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
2016-01-01T21:22:46.756Z Task(GetDeviceTicket -AccessKey DF7FC241-BAFA-42B0-6726-9BBE1A7B1045 ) launched as network service 
Dynamic Signature has been received 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\e263c1cb17211e7bb30d43385f53db4389cb4ef8 
Dynamic Signature Compilation Timestamp:01-01-2016 22:22:48 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-01T21:22:48.013Z Dynamic signature received 
2016-01-01T21:22:48.405Z Process scan (poststartupscan) completed. 
2016-01-01T21:23:05.151Z [Mini-filter] Restricted access to process 2820 from pid: 1828. Original desired access: 0x1fffff. 
2016-01-01T21:23:05.152Z [Mini-filter] Restricted access to process 2820 from pid: 1828. Original desired access: 0x1fffff. 
2016-01-01T21:23:54.027Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-01T21:23:54.046Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-01T21:27:13.548Z [Mini-filter] Restricted access to engine process from pid: 1152. Original desired access: 0x1fffff. 
2016-01-01T21:27:13.698Z [Mini-filter] Restricted access to process 2820 from pid: 1152. Original desired access: 0x1fffff. 
2016-01-01T21:27:18.090Z [Mini-filter] Restricted access to engine process from pid: 1152. Original desired access: 0x1fffff. 
2016-01-01T21:27:18.103Z [Mini-filter] Restricted access to process 2820 from pid: 1152. Original desired access: 0x1fffff. 
2016-01-01T21:31:35.512Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 72534355(ms) 
2016-01-01T21:31:35.515Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2016-01-01T21:31:35.516Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 12193720(ms) 
2016-01-01T21:31:35.528Z AutoPurgeWorker triggered with dwWork=0x3 
2016-01-01T21:31:35.528Z Product supports installmode: 0 
2016-01-01T21:31:42.641Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 01-02-2016 23:22:58 
************************************************************ 
2016-01-02T22:22:58.453Z Trace session started - MpWppTracing-01022016-232258-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 25000 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 22221 
Number of invalid entries is 0 
Number of inserts issued is 74156 
Number of replaces issued is 0 
Number of insert failures is 3 
Number of inserts with duplicate entries is 21329 
Number of lookups is 118052 
Number of lookup misses is 9673 
Number of fast lookup misses is 76088 
Number of false fast lookups is 9673 
Number of invalidations is 31 
Number of maintenance invalidations is 0 
Current File Size is 618496 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2016-01-02T22:22:58.515Z Verifying RTP plugin... 
2016-01-02T22:22:58.531Z verified! 
2016-01-02T22:22:58.562Z Verifying Nis plugin... 
2016-01-02T22:22:58.562Z verified! 
2016-01-02T22:22:58.578Z Initializing Nis plugin state... 
2016-01-02T22:22:58.578Z Nis initialized! 
2016-01-02T22:22:58.578Z Loading engine... 
2016-01-02T22:22:58.625Z Verifying engine and signature files (source: 1) ... 
2016-01-02T22:22:58.625Z verified! 
2016-01-02T22:23:04.818Z Dynamic signature dropped 
Dynamic Signature has been dropped 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\69fe6ba3bb1625cacd52c04762aee0d67c8ea6d1 
Dynamic Signature Compilation Timestamp:01-02-2016 13:03:21 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-02T22:23:04.919Z Initializing MPUT in engine... 
2016-01-02T22:23:04.919Z MPUT initialized in the engine successfully 
2016-01-02T22:23:05.099Z CSignatureStatus: back to good 
2016-01-02T22:23:05.099Z Initializing RTP plugin state... 
2016-01-02T22:23:05.099Z initialized! 
2016-01-02T22:23:05.099Z  
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:(null) 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:2,2,0 
  SetEngine:1,1,0 
  SetState:1,1,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1240 
  AsyncQCurrent:0 
  BMFlags:8 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:4 
  TotalStreamCon:958 
  TotalBitmap:0 
  NTFS Cache Statistics: 
   TotalMisses:2685 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2016-01-02T22:23:05.099Z loaded! 
2016-01-02T22:23:05.146Z Verifying license file... 
2016-01-02T22:23:05.154Z verified! 
2016-01-02T22:23:05.154Z Product supports installmode: 0 
2016-01-02T22:23:05.169Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.8.204.0 
Service Version: 4.8.204.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1529.0 
AV Signature Version: 1.213.1529.0 
************************************************************ 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
Begin Resource Scan 
Scan ID:{E7B59B03-CAE3-433A-96A8-56A34E3E9389} 
Scan Source:7 
Start Time:01-02-2016 23:23:26 
End Time:01-02-2016 23:23:26 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Extended Info:35872412566804 
End Scan 
************************************************************   
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe"   
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=true, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Begin Resource Scan 
Scan ID:{6660D123-21F4-4F91-A068-00B38A50A5B6} 
Scan Source:7 
Start Time:01-02-2016 23:23:42 
End Time:01-02-2016 23:23:54 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Result Count:1 
Unknown File 
Identifier:6723857877691269118 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Extended Info:5863886377321 
End Scan 
************************************************************   
2016-01-02T22:23:54.757Z Task(GetDeviceTicket -AccessKey C106FC41-9D3D-4049-DECC-5B4DBEB809B0 ) launched as network service 
2016-01-02T22:23:58.623Z Task(GetDeviceTicket -AccessKey 9BB7B301-7BE8-A5D9-5823-56CC16542DB5 ) launched as network service 
2016-01-02T22:23:58.983Z Process scan (poststartupscan) started. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
2016-01-02T22:24:39.815Z Task(GetDeviceTicket -AccessKey 6F40E7B6-FDBF-F23C-810A-2A62604C7C78 ) launched as network service 
2016-01-02T22:24:40.591Z Dynamic signature received 
Dynamic Signature has been received 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\339d9954d05f16f58eb5675020a24927ba512aa9 
Dynamic Signature Compilation Timestamp:01-02-2016 23:24:41 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-02T22:24:40.965Z Process scan (poststartupscan) completed. 
2016-01-02T22:24:47.127Z [Mini-filter] Restricted access to process 2688 from pid: 1796. Original desired access: 0x1fffff. 
2016-01-02T22:24:47.127Z [Mini-filter] Restricted access to process 2688 from pid: 1796. Original desired access: 0x1fffff. 
2016-01-02T22:25:20.183Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-02T22:25:20.204Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-02T22:33:05.155Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 69306649(ms) 
2016-01-02T22:33:05.158Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2016-01-02T22:33:05.159Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 7644882(ms) 
2016-01-02T22:33:05.169Z AutoPurgeWorker triggered with dwWork=0x3 
2016-01-02T22:33:05.169Z Product supports installmode: 0 
2016-01-02T22:33:12.089Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 01-03-2016 20:27:57 
************************************************************ 
2016-01-03T19:27:57.187Z Trace session started - MpWppTracing-01032016-202757-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 25000 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 22230 
Number of invalid entries is 0 
Number of inserts issued is 74178 
Number of replaces issued is 0 
Number of insert failures is 3 
Number of inserts with duplicate entries is 21332 
Number of lookups is 126135 
Number of lookup misses is 10381 
Number of fast lookup misses is 80145 
Number of false fast lookups is 10381 
Number of invalidations is 41 
Number of maintenance invalidations is 0 
Current File Size is 618496 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2016-01-03T19:27:57.296Z Verifying RTP plugin... 
2016-01-03T19:27:57.312Z verified! 
2016-01-03T19:27:57.343Z Verifying Nis plugin... 
2016-01-03T19:27:57.343Z verified! 
2016-01-03T19:27:57.375Z Initializing Nis plugin state... 
2016-01-03T19:27:57.375Z Nis initialized! 
2016-01-03T19:27:57.375Z Loading engine... 
2016-01-03T19:27:57.500Z Verifying engine and signature files (source: 1) ... 
2016-01-03T19:27:57.515Z verified! 
2016-01-03T19:28:05.472Z Dynamic signature dropped 
Dynamic Signature has been dropped 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\339d9954d05f16f58eb5675020a24927ba512aa9 
Dynamic Signature Compilation Timestamp:01-02-2016 23:24:41 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-03T19:28:05.566Z Initializing MPUT in engine... 
2016-01-03T19:28:05.582Z MPUT initialized in the engine successfully 
2016-01-03T19:28:05.847Z CSignatureStatus: back to good 
2016-01-03T19:28:05.847Z Initializing RTP plugin state... 
2016-01-03T19:28:05.847Z  
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:N/A 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,1,0 
  SetEngine:1,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1240 
  AsyncQCurrent:0 
  BMFlags:8 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:4 
  TotalStreamCon:927 
  TotalBitmap:0 
  NTFS Cache Statistics: 
   TotalMisses:2636 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2016-01-03T19:28:05.847Z initialized! 
2016-01-03T19:28:05.847Z loaded! 
2016-01-03T19:28:05.878Z Verifying license file... 
2016-01-03T19:28:05.878Z verified! 
2016-01-03T19:28:05.878Z Product supports installmode: 0 
2016-01-03T19:28:05.878Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.8.204.0 
Service Version: 4.8.204.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1618.0 
AV Signature Version: 1.213.1618.0 
************************************************************ 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
Begin Resource Scan 
Scan ID:{0490B158-6AF2-4879-AB30-4FEF23DF272C} 
Scan Source:7 
Start Time:01-03-2016 20:28:28 
End Time:01-03-2016 20:28:28 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Extended Info:35872412566804 
End Scan 
************************************************************   
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe"   
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=true, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
2016-01-03T19:28:58.337Z Task(GetDeviceTicket -AccessKey 3B04B1B6-7B9E-E212-4D7A-08CC0D867434 ) launched as network service 
2016-01-03T19:28:58.705Z Process scan (poststartupscan) started. 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Begin Resource Scan 
Scan ID:{92B85ECA-3CB1-484F-936D-617C169EEBD4} 
Scan Source:7 
Start Time:01-03-2016 20:28:51 
End Time:01-03-2016 20:29:10 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Result Count:1 
Unknown File 
Identifier:6723857877691269118 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Extended Info:5863886377321 
End Scan 
************************************************************   
2016-01-03T19:29:23.313Z Task(GetDeviceTicket -AccessKey 256D63D6-14B7-BCC6-60CA-453AF73B5483 ) launched as network service 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
2016-01-03T19:29:48.062Z [Mini-filter] Restricted access to process 2248 from pid: 1804. Original desired access: 0x1fffff. 
2016-01-03T19:29:48.062Z [Mini-filter] Restricted access to process 2248 from pid: 1804. Original desired access: 0x1fffff. 
2016-01-03T19:30:10.616Z Task(GetDeviceTicket -AccessKey CFA6A359-0C57-FB12-5508-777871812C19 ) launched as network service 
2016-01-03T19:30:11.541Z Dynamic signature received 
Dynamic Signature has been received 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\d7e4d615581d3b9d5609d58777be7a6a247ecd0a 
Dynamic Signature Compilation Timestamp:01-03-2016 20:30:11 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-03T19:30:11.812Z Process scan (poststartupscan) completed. 
2016-01-03T19:30:16.099Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-03T19:30:16.118Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-03T19:35:20.623Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T19:35:24.231Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T19:35:40.415Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T19:38:05.877Z AutoPurgeWorker triggered with dwWork=0x3 
2016-01-03T19:38:05.878Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 79434020(ms) 
2016-01-03T19:38:05.880Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2016-01-03T19:38:05.895Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 18127289(ms) 
2016-01-03T19:38:05.999Z Product supports installmode: 0 
2016-01-03T19:38:12.520Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
2016-01-03T19:38:16.278Z Trace buffers written: 39, events lost: 0, buffers lost: 0, days: 0 
2016-01-03T19:38:16.278Z Trusted image bitmap: 0x1 
2016-01-03T19:38:16.279Z Trusted image OEM name: (not found) 
2016-01-03T19:38:16.301Z MOAC capability telemetry: 3,2,CNTFS3DNTFS3ENTFS3F0x155GNTFS3. hr = 0x0 
2016-01-03T19:38:16.330Z Task(-UploadSQM -RestrictPrivileges) launched 
2016-01-03T19:38:16.523Z [Mini-filter] Restricted access to process 5756 from pid: 2492. Original desired access: 0x1fffff. 
2016-01-03T19:38:50.735Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T19:43:39.845Z [Mini-filter] Restricted access to engine process from pid: 1940. Original desired access: 0x1411. 
2016-01-03T19:43:39.856Z [Mini-filter] Restricted access to process 2248 from pid: 1940. Original desired access: 0x1411. 
2016-01-03T19:45:58.161Z [Mini-filter] Restricted access to engine process from pid: 1940. Original desired access: 0x1fffff. 
2016-01-03T19:45:58.243Z [Mini-filter] Restricted access to process 2248 from pid: 1940. Original desired access: 0x1fffff. 
2016-01-03T20:19:25.748Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T20:22:22.376Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T20:22:29.132Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T20:57:35.546Z [Mini-filter] Restricted access to engine process from pid: 1940. Original desired access: 0x1411. 
2016-01-03T20:57:35.565Z [Mini-filter] Restricted access to process 2248 from pid: 1940. Original desired access: 0x1411. 
2016-01-03T21:00:46.257Z [Mini-filter] Restricted access to engine process from pid: 1940. Original desired access: 0x1fffff. 
2016-01-03T21:00:46.355Z [Mini-filter] Restricted access to process 2248 from pid: 1940. Original desired access: 0x1fffff. 
2016-01-03T21:03:56.676Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T21:03:56.804Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T21:04:02.120Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T21:04:02.121Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T21:04:05.414Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T21:07:11.700Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\ProgramData\Creative\MediaSource U\AddOnPack.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\ProgramData\Creative\MediaSource U\AddOnPack.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\ProgramData\Creative\MediaSource U\AddOnPack.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\ProgramData\Creative\MediaSource U\AddOnPack.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\ProgramData\Creative\MediaSource U\AddOnPack.exe" 
Begin Resource Scan 
Scan ID:{2A69BC19-3A46-4A3B-955A-7AB86F5A6CA7} 
Scan Source:7 
Start Time:01-03-2016 22:09:41 
End Time:01-03-2016 22:10:45 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\ProgramData\Creative\MediaSource U\AddOnPack.exe 
Result Count:1 
Unknown File 
Identifier:15559123462655049726 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\ProgramData\Creative\MediaSource U\AddOnPack.exe 
Extended Info:65519410711387 
End Scan 
************************************************************   
2016-01-03T21:10:46.530Z Task(GetDeviceTicket -AccessKey AC95A143-EC49-F8F9-5E4D-193195E9F034 ) launched as network service 
Begin Resource Scan 
Scan ID:{1345F8C9-6D83-4E24-93E7-A36176DE74BC} 
Scan Source:3 
Start Time:01-03-2016 22:11:37 
End Time:01-03-2016 22:12:06 
Explicit resource to scan 
Resource Schema:file 
Resource Path:C:\ProgramData\molecule-9\molecule-5.exe 
Result Count:1 
Threat Name:TrojanDownloader:Win32/Nymaim.I 
ID:2147708375 
Severity:5 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\ProgramData\molecule-9\molecule-5.exe 
Extended Info:252306585499706 
End Scan 
************************************************************   
2016-01-03T21:12:06.837Z DETECTIONEVENT TrojanDownloader:Win32/Nymaim.I file:C:\ProgramData\molecule-9\molecule-5.exe; 
2016-01-03T21:12:06.881Z DETECTION_ADD TrojanDownloader:Win32/Nymaim.I file:C:\ProgramData\molecule-9\molecule-5.exe 
2016-01-03T21:19:26.608Z Cache Resizing**********Cache stats************ 
No. Of buckets -> 25000 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 24167 
Number of invalid entries is 0 
Number of inserts issued is 79192 
Number of replaces issued is 0 
Number of insert failures is 4 
Number of inserts with duplicate entries is 21332 
Number of lookups is 180920 
Number of lookup misses is 19117 
Number of fast lookup misses is 123750 
Number of false fast lookups is 19117 
Number of invalidations is 48 
Number of maintenance invalidations is 0 
Current File Size is 618496 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\Creative\ALchemy\dsound.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\ALchemy\ALchemy.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\Creative\SB X-Fi MB\AudioCS\CTAudCS.exe" 
Begin Resource Scan 
Scan ID:{0F0FCC9A-CCE6-4433-AAB8-6BA20208DF3E} 
Scan Source:7 
Start Time:01-03-2016 22:25:52 
End Time:01-03-2016 22:26:06 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\ALchemy\ALchemy.exe 
Result Count:1 
Unknown File 
Identifier:3058306356609023998 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\ALchemy\ALchemy.exe 
Extended Info:65519410711387 
End Scan 
************************************************************   
2016-01-03T21:26:07.317Z Task(GetDeviceTicket -AccessKey 18E62776-C241-FC75-F9BC-C40701D51478 ) launched as network service 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\Creative\SB X-Fi MB\Console Launcher\ConsoLCu.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\Creative\SB X-Fi MB\Console Launcher\CTAudMon.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\AudioCS\CTAudCS.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\Console Launcher\ConsoLCu.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\AudioCS\CTAudCS.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\Console Launcher\ConsoLCu.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\AudioCS\CTAudCS.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\Console Launcher\ConsoLCu.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\AudioCS\CTAudCS.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\Creative\SB X-Fi MB\Console Launcher\ConsoLCu.exe" 
Begin Resource Scan 
Scan ID:{EE56D8A6-5F97-4DF3-B84C-371E7ACEE485} 
Scan Source:7 
Start Time:01-03-2016 22:26:23 
End Time:01-03-2016 22:27:19 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\SB X-Fi MB\AudioCS\CTAudCS.exe 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\SB X-Fi MB\Console Launcher\ConsoLCu.exe 
Result Count:2 
Unknown File 
Identifier:9476335291930247166 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\SB X-Fi MB\Console Launcher\ConsoLCu.exe 
Extended Info:65519410711387 
Unknown File 
Identifier:11827572875647254526 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Creative\SB X-Fi MB\AudioCS\CTAudCS.exe 
Extended Info:65519410711387 
End Scan 
************************************************************   
2016-01-03T21:27:20.370Z Task(GetDeviceTicket -AccessKey C985B550-4ADC-E735-AE09-C382AF9876B0 ) launched as network service 
Internal signature match:subtype=Lowfi, sigseq=0x800022783EA9DC83, signame=!#Datechk, cached=false, resource="\Device\HarddiskVolume1\Windows\SoftwareDistribution\Download\50c3ba3b5a597cdd29f9d4e053e3c23fc1522acb" 
Begin Resource Scan 
Scan ID:{6E86FDB7-0C6B-4925-AB78-D35293158180} 
Scan Source:7 
Start Time:01-03-2016 22:38:26 
End Time:01-03-2016 22:38:33 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Windows\SoftwareDistribution\Download\50c3ba3b5a597cdd29f9d4e053e3c23fc1522acb 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Windows\SoftwareDistribution\Download\50c3ba3b5a597cdd29f9d4e053e3c23fc1522acb 
Extended Info:481036337152 
End Scan 
************************************************************   
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Windows\System32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\System32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\System32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\System32\Sens_oal.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Windows\System32\Sens_oal.dll" 
Begin Resource Scan 
Scan ID:{C066BF39-99CB-4F8D-93F6-F68F2D68450D} 
Scan Source:7 
Start Time:01-03-2016 22:39:46 
End Time:01-03-2016 22:41:34 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Windows\System32\Sens_oal.dll 
Result Count:1 
Unknown File 
Identifier:18103529816144740350 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Windows\System32\Sens_oal.dll 
Extended Info:65519410711387 
End Scan 
************************************************************   
2016-01-03T21:41:41.902Z Task(GetDeviceTicket -AccessKey 00CAC880-01E7-AF8F-0692-73FE88799292 ) launched as network service 
Internal signature match:subtype=Lowfi, sigseq=0x80004D8FDD5A2B9B, signame=!#HSTR:MacroDownloader, cached=false, resource="\Device\HarddiskVolume2\Programme\Microsoft Office\Templates\1031\Batch Conversion Wizard.Wiz" 
Internal signature match:subtype=Lowfi, sigseq=0x80004D8FDD5A2B9B, signame=!#HSTR:MacroDownloader, cached=false, resource="\\?\D:\Programme\Microsoft Office\Templates\1031\Batch Conversion Wizard.Wiz" 
Begin Resource Scan 
Scan ID:{133B22F6-597A-476F-92CA-FA895BC8350A} 
Scan Source:7 
Start Time:01-03-2016 23:11:39 
End Time:01-03-2016 23:11:44 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:D:\Programme\Microsoft Office\Templates\1031\Batch Conversion Wizard.Wiz 
Result Count:1 
Unknown File 
Identifier:4902323854745010174 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:D:\Programme\Microsoft Office\Templates\1031\Batch Conversion Wizard.Wiz 
Extended Info:9223457317144112027 
End Scan 
************************************************************   
2016-01-03T22:11:50.699Z Task(GetDeviceTicket -AccessKey 18C535BE-5575-52B0-CF24-B1C24ECC7316 ) launched as network service 
2016-01-03T22:35:26.386Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-03T22:37:25.978Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
Internal signature match:subtype=Lowfi, sigseq=0x80004D8FDD5A2B9B, signame=!#HSTR:MacroDownloader, cached=true, resource="\Device\HarddiskVolume3\Daten\Schuldaten alt PC\DATEN\PROGRAMME\MICROSOFT_OFFICE\TEMPLATES\1031\BATCH_CONVERSION_WIZARD.WIZ" 
2016-01-04T00:19:24.617Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:05:13.440Z Timer is triggered for lost scheduled jobs 
2016-01-04T01:05:13.440Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 84899744(ms) 
2016-01-04T01:05:36.036Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:05:42.992Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:05:43.521Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:05:45.368Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:05:46.877Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:05:46.969Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:05:46.973Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:06:00.475Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:06:00.491Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:06:22.409Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:06:35.159Z [Mini-filter] Restricted access to engine process from pid: 1148. Original desired access: 0x1fffff. 
2016-01-04T01:06:35.166Z [Mini-filter] Restricted access to process 2248 from pid: 1148. Original desired access: 0x1fffff. 
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 01-06-2016 00:50:22 
************************************************************ 
2016-01-05T23:50:22.953Z Trace session started - MpWppTracing-01062016-005022-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 31250 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 27824 
Number of invalid entries is 0 
Number of inserts issued is 108135 
Number of replaces issued is 0 
Number of insert failures is 4 
Number of inserts with duplicate entries is 21332 
Number of lookups is 344384 
Number of lookup misses is 40965 
Number of fast lookup misses is 238936 
Number of false fast lookups is 40965 
Number of invalidations is 53 
Number of maintenance invalidations is 0 
Current File Size is 774144 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2016-01-05T23:50:23.062Z Verifying RTP plugin... 
2016-01-05T23:50:23.062Z verified! 
2016-01-05T23:50:23.109Z Verifying Nis plugin... 
2016-01-05T23:50:23.109Z verified! 
2016-01-05T23:50:23.125Z Initializing Nis plugin state... 
2016-01-05T23:50:23.125Z Nis initialized! 
2016-01-05T23:50:23.125Z Loading engine... 
2016-01-05T23:50:23.218Z Verifying engine and signature files (source: 1) ... 
2016-01-05T23:50:23.218Z verified! 
2016-01-05T23:50:29.083Z Dynamic signature dropped 
Dynamic Signature has been dropped 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\24b41a112605f8d887cdf9b58e899332f72526f9 
Dynamic Signature Compilation Timestamp:01-04-2016 23:54:19 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-05T23:50:29.129Z Initializing MPUT in engine... 
2016-01-05T23:50:29.129Z MPUT initialized in the engine successfully 
2016-01-05T23:50:29.453Z CSignatureStatus: back to good 
2016-01-05T23:50:29.458Z Initializing RTP plugin state... 
2016-01-05T23:50:29.458Z  
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:N/A 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,1,0 
  SetEngine:1,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1240 
  AsyncQCurrent:0 
  BMFlags:8 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:4 
  TotalStreamCon:883 
  TotalBitmap:0 
  NTFS Cache Statistics: 
   TotalMisses:2516 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2016-01-05T23:50:29.460Z initialized! 
2016-01-05T23:50:29.469Z loaded! 
2016-01-05T23:50:29.765Z Verifying license file... 
2016-01-05T23:50:29.772Z verified! 
2016-01-05T23:50:29.772Z Product supports installmode: 0 
2016-01-05T23:50:29.807Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.8.204.0 
Service Version: 4.8.204.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1618.0 
AV Signature Version: 1.213.1618.0 
************************************************************ 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
Begin Resource Scan 
Scan ID:{575B2647-CB71-47A3-93E0-E6EA07F570EE} 
Scan Source:7 
Start Time:01-06-2016 00:50:44 
End Time:01-06-2016 00:50:44 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Extended Info:35872412566804 
End Scan 
************************************************************   
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe"   
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=true, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\\?\C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Begin Resource Scan 
Scan ID:{46E3C3B5-E1E1-41CC-B8FD-5FF2FC8A4E7C} 
Scan Source:7 
Start Time:01-06-2016 00:51:11 
End Time:01-06-2016 00:51:19 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Result Count:1 
Unknown File 
Identifier:6723857877691269118 
Number of Resources:1 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll 
Extended Info:5863886377321 
End Scan 
************************************************************   
2016-01-05T23:51:19.969Z Task(GetDeviceTicket -AccessKey E98D5DDA-27D7-6140-3D46-D8234DE487A5 ) launched as network service 
2016-01-05T23:51:23.178Z Task(GetDeviceTicket -AccessKey ABAAC391-6C4F-A880-2D36-09F55C51C305 ) launched as network service 
2016-01-05T23:51:23.255Z Process scan (poststartupscan) started. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\\?\C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
2016-01-05T23:51:41.889Z Task(GetDeviceTicket -AccessKey 8557344F-C841-8982-BE99-426A6D4E8678 ) launched as network service 
2016-01-05T23:51:42.634Z Dynamic signature received 
Dynamic Signature has been received 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\cfd9c510a6e7cfabccb95fa29bc70dbeff8097b3 
Dynamic Signature Compilation Timestamp:01-06-2016 00:51:44 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-05T23:51:42.957Z Process scan (poststartupscan) completed. 
2016-01-05T23:52:07.119Z [Mini-filter] Restricted access to process 2168 from pid: 1844. Original desired access: 0x1fffff. 
2016-01-05T23:52:07.120Z [Mini-filter] Restricted access to process 2168 from pid: 1844. Original desired access: 0x1fffff. 
2016-01-05T23:52:42.630Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-05T23:52:42.649Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-06T00:00:29.791Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 65613747(ms) 
2016-01-06T00:00:29.794Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2016-01-06T00:00:29.807Z AutoPurgeWorker triggered with dwWork=0x3 
2016-01-06T00:00:29.821Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 3060078(ms) 
2016-01-06T00:00:30.148Z Product supports installmode: 0 
2016-01-06T00:01:04.797Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 01-06-2016 17:43:47 
************************************************************ 
2016-01-06T16:43:47.781Z Trace session started - MpWppTracing-01062016-174347-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 31250 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 27830 
Number of invalid entries is 0 
Number of inserts issued is 108179 
Number of replaces issued is 0 
Number of insert failures is 4 
Number of inserts with duplicate entries is 21335 
Number of lookups is 354128 
Number of lookup misses is 42115 
Number of fast lookup misses is 243724 
Number of false fast lookups is 42115 
Number of invalidations is 85 
Number of maintenance invalidations is 0 
Current File Size is 774144 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2016-01-06T16:43:47.875Z Verifying RTP plugin... 
2016-01-06T16:43:47.875Z verified! 
2016-01-06T16:43:47.921Z Verifying Nis plugin... 
2016-01-06T16:43:47.921Z verified! 
2016-01-06T16:43:47.937Z Initializing Nis plugin state... 
2016-01-06T16:43:47.937Z Nis initialized! 
2016-01-06T16:43:47.937Z Loading engine... 
2016-01-06T16:43:48.187Z Verifying engine and signature files (source: 1) ... 
2016-01-06T16:43:48.187Z verified! 
Dynamic Signature has been dropped 
Dynamic Signature Type:Signature Update 
Signature Path:C:\ProgramData\Microsoft\Microsoft Antimalware\Scans\\RtSigs\Data\cfd9c510a6e7cfabccb95fa29bc70dbeff8097b3 
Dynamic Signature Compilation Timestamp:01-06-2016 00:51:44 
Persistence Type:Duration 
Time remaining:216000000 
2016-01-06T16:43:57.221Z Dynamic signature dropped 
2016-01-06T16:43:57.237Z Initializing MPUT in engine... 
2016-01-06T16:43:57.252Z MPUT initialized in the engine successfully 
2016-01-06T16:43:57.502Z CSignatureStatus: back to good 
2016-01-06T16:43:57.502Z Initializing RTP plugin state... 
2016-01-06T16:43:57.502Z  
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:(null) 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:1,1,0 
  SetEngine:1,1,0 
  SetState:0,0,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1240 
  AsyncQCurrent:0 
  BMFlags:8 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:5 
  TotalStreamCon:972 
  TotalBitmap:0 
  NTFS Cache Statistics: 
   TotalMisses:2701 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2016-01-06T16:43:57.502Z initialized! 
2016-01-06T16:43:57.518Z loaded! 
2016-01-06T16:43:57.549Z Verifying license file... 
2016-01-06T16:43:57.549Z verified! 
2016-01-06T16:43:57.549Z Product supports installmode: 0 
2016-01-06T16:43:57.549Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.8.204.0 
Service Version: 4.8.204.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1872.0 
AV Signature Version: 1.213.1872.0 
************************************************************ 
2016-01-06T16:44:48.096Z Task(GetDeviceTicket -AccessKey 0D49B277-C2DA-33B9-47CA-3B3F1D424E7A ) launched as network service 
2016-01-06T16:44:48.174Z Process scan (poststartupscan) started. 
2016-01-06T16:44:54.377Z Process scan (poststartupscan) completed. 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe"   
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=false, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Internal signature match:subtype=Lowfi, sigseq=0x000005554ADD5169, signame=#LowFi:Win32/Generic!SigAttrIdsFastRank, cached=true, resource="\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.0\instrumental_services.dll" 
Begin Resource Scan 
Scan ID:{774006BF-39BC-42E4-B234-F2F04D1331FB} 
Scan Source:7 
Start Time:01-06-2016 17:45:35 
End Time:01-06-2016 17:45:55 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Extended Info:35872412566804 
End Scan 
************************************************************   
2016-01-06T16:46:22.535Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-06T16:46:22.582Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-06T16:46:59.097Z [Mini-filter] Restricted access to process 2284 from pid: 1840. Original desired access: 0x1fffff. 
2016-01-06T16:46:59.098Z [Mini-filter] Restricted access to process 2284 from pid: 1840. Original desired access: 0x1fffff. 
2016-01-06T16:46:59.108Z [Mini-filter] Restricted access to engine process from pid: 1840. Original desired access: 0x1fffff. 
2016-01-06T16:46:59.108Z [Mini-filter] Restricted access to engine process from pid: 1840. Original desired access: 0x1fffff. 
2016-01-06T16:49:36.708Z [Mini-filter] Restricted access to engine process from pid: 1176. Original desired access: 0x1fffff. 
2016-01-06T16:49:36.754Z [Mini-filter] Restricted access to process 2284 from pid: 1176. Original desired access: 0x1fffff. 
2016-01-06T16:49:41.129Z [Mini-filter] Restricted access to engine process from pid: 1176. Original desired access: 0x1fffff. 
2016-01-06T16:49:41.135Z [Mini-filter] Restricted access to process 2284 from pid: 1176. Original desired access: 0x1fffff. 
2016-01-06T16:53:57.550Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 5145294(ms) 
2016-01-06T16:53:57.553Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2016-01-06T16:53:57.554Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 30121750(ms) 
2016-01-06T16:53:57.554Z AutoPurgeWorker triggered with dwWork=0x3 
2016-01-06T16:53:57.555Z Product supports installmode: 0 
2016-01-06T16:54:14.797Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0) 
-------------------------------------------------------------------------------- 
Microsoft Security Essentials (EDB4FA23-53B8-4AFA-8C5D-99752CCA7094) Service Log 
Started On 01-06-2016 18:51:03 
************************************************************ 
2016-01-06T17:51:03.859Z Trace session started - MpWppTracing-01062016-185103-00000003-ffffffff.bin**********Cache stats************ 
No. Of buckets -> 31250 
Each Bucket has max capacity of -> 1 entries 
number of Entries is 27829 
Number of invalid entries is 0 
Number of inserts issued is 108187 
Number of replaces issued is 0 
Number of insert failures is 4 
Number of inserts with duplicate entries is 21335 
Number of lookups is 364410 
Number of lookup misses is 43489 
Number of fast lookup misses is 250261 
Number of false fast lookups is 43489 
Number of invalidations is 94 
Number of maintenance invalidations is 0 
Current File Size is 774144 
Journal ID = 1cf6016361880da 
Trusted image state = 1 USN = 0 
Setup boot count = 0   
2016-01-06T17:51:03.953Z Verifying RTP plugin... 
2016-01-06T17:51:03.953Z verified! 
2016-01-06T17:51:04.000Z Verifying Nis plugin... 
2016-01-06T17:51:04.000Z verified! 
2016-01-06T17:51:04.000Z Initializing Nis plugin state... 
2016-01-06T17:51:04.000Z Nis initialized! 
2016-01-06T17:51:04.000Z Loading engine... 
2016-01-06T17:51:04.421Z Verifying engine and signature files (source: 1) ... 
2016-01-06T17:51:04.421Z verified! 
2016-01-06T17:51:10.898Z Initializing MPUT in engine... 
2016-01-06T17:51:10.914Z MPUT initialized in the engine successfully 
2016-01-06T17:51:11.148Z CSignatureStatus: back to good 
2016-01-06T17:51:11.164Z Initializing RTP plugin state... 
2016-01-06T17:51:11.164Z initialized! 
2016-01-06T17:51:11.164Z loaded! 
2016-01-06T17:51:11.164Z  
****************************RTP Perf Log*************************** 
RTP Start:N/A 
Last Perf:N/A 
First RTP Scan:N/A 
Plugin States:  AV:2  AS:2  RTP:2  OA:2  BM:2 
Process Exclusions: 
Path Exclusions: 
Ext Exclusions: 
Worker Threads: 
  AM:19 
  Async:4 
Cache Flushes: 
  RTP:0 
System File Cache: 
  Hits:0 
  Misses:0 
BM Queue:0,0,0 
  Proc:0,0,0 
  File:0,0,0 
Plugin Queue:0,0,0 
  Threat:0,0,0 
  Susp:0,0,0 
  Unknown:0,0,0 
  Error:0,0,0 
Request Queue:2,2,0 
  SetEngine:1,1,0 
  SetState:1,1,0 
  SetUser:0,0,0 
  Config:0,0,0 
  ProcExcl:0,0,0 
  FilterReload:0,0,0 
  FilterUnload:0,0,0 
MpFilter: 
  Scans:0 
  Pending:0 
  RegSize:0 
  AsyncQNotif:0 
  AsyncQMissed:0 
  AsyncQTotalSent:1240 
  AsyncQCurrent:0 
  BMFlags:8 
  ServiceMaj:0 
  ServiceMin:0 
  ProcBitmap:0 
  NumInstance:5 
  TotalStreamCon:1227 
  TotalBitmap:0 
  NTFS Cache Statistics: 
   TotalMisses:3166 
   TotalHits:0 
   InstanceCacheHits:0 
  CSVFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  REFS Cache Statistics (Type:GenericTable, Policy:WriteBack): 
   TotalMisses:0 
   TotalHits:0 
   InstanceCacheInserts:0 
   InstanceCacheUpdates:0 
   InstanceCacheDeletes:0 
   InstanceCacheHits:0 
   InstanceCacheMisses:0 
   InstanceCacheOverflows:0 
  
**************************END RTP Perf Log*************************   
  
    
2016-01-06T17:51:11.179Z Verifying license file... 
2016-01-06T17:51:11.179Z verified! 
2016-01-06T17:51:11.179Z Product supports installmode: 0 
2016-01-06T17:51:11.201Z Auto purger task is scheduled to run in 600000(ms) from now with period 86400000(ms) 
Product Version: 4.8.204.0 
Service Version: 4.8.204.0 
Engine Version: 1.1.12400.0 
AS Signature Version: 1.213.1872.0 
AV Signature Version: 1.213.1872.0 
************************************************************ 
2016-01-06T17:52:04.094Z Task(GetDeviceTicket -AccessKey 867E86E8-1C49-CB03-060F-5F07EFDF809F ) launched as network service 
2016-01-06T17:52:04.141Z Process scan (poststartupscan) started. 
2016-01-06T17:52:05.235Z Process scan (poststartupscan) completed. 
2016-01-06T17:53:14.438Z IWscAVStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
2016-01-06T17:53:14.454Z IWscASStatus::UpdateStatus() succceeded writing instance with state (1), snoooze state (0), and up-to-date state(1) 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=false, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe" 
Internal signature match:subtype=Lowfi, sigseq=0x00003B96ED338B5B, signame=ALF:PeaDisUnpRdVd, cached=true, resource="\Device\HarddiskVolume1\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe"   
Begin Resource Scan 
Scan ID:{5378F9AF-6A45-442B-A2BA-99CAC325428D} 
Scan Source:7 
Start Time:01-06-2016 18:55:35 
End Time:01-06-2016 18:55:38 
Explicit resource to scan 
Resource Schema:queryfilertsig 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Result Count:1 
Known File 
Number of Resources:1 
Resource Schema:file 
Resource Path:C:\Program Files\InstallShield Installation Information\{F3D9AC82-30F4-4BB9-B9AB-8697637568C1}\AMBSPISyncService.exe 
Extended Info:35872412566804 
End Scan 
************************************************************   
2016-01-06T17:57:02.053Z [Mini-filter] Restricted access to process 2220 from pid: 1664. Original desired access: 0x1fffff. 
2016-01-06T17:57:02.053Z [Mini-filter] Restricted access to process 2220 from pid: 1664. Original desired access: 0x1fffff. 
2016-01-06T17:57:02.060Z [Mini-filter] Restricted access to engine process from pid: 1664. Original desired access: 0x1fffff. 
2016-01-06T17:57:02.060Z [Mini-filter] Restricted access to engine process from pid: 1664. Original desired access: 0x1fffff. 
2016-01-06T18:01:11.179Z Task(Scan -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 116134(ms) 
2016-01-06T18:01:11.182Z Task(SignatureUpdate -ScheduleJob -RestrictPrivileges) is scheduled to run in 86400000(ms) from now with period 86400000(ms) 
2016-01-06T18:01:11.183Z Task(Scan -ScheduleJob -RestrictPrivileges -ScanType 2) is scheduled to run in 86400000(ms) from now with period 26049452(ms) 
2016-01-06T18:01:11.201Z AutoPurgeWorker triggered with dwWork=0x3 
2016-01-06T18:01:11.201Z Product supports installmode: 0 
2016-01-06T18:01:17.370Z Detection State: Finished(0) Failed(0) CriticalFailed(0) Additional Actions(0)      |