heldenfels | 07.05.2018 14:04 | Hallo, Code:
15:02:53.0363 0x267c TDSS rootkit removing tool 3.1.0.17 Apr 20 2018 12:12:17
15:02:58.0035 0x267c ============================================================
15:02:58.0035 0x267c Current date / time: 2018/05/07 15:02:58.0035
15:02:58.0035 0x267c SystemInfo:
15:02:58.0035 0x267c
15:02:58.0035 0x267c OS Version: 10.0.16299 ServicePack: 0.0
15:02:58.0035 0x267c Product type: Workstation
15:02:58.0035 0x267c ComputerName: DANIEL-PC
15:02:58.0035 0x267c UserName: daniel
15:02:58.0035 0x267c Windows directory: C:\WINDOWS
15:02:58.0035 0x267c System windows directory: C:\WINDOWS
15:02:58.0035 0x267c Running under WOW64
15:02:58.0035 0x267c Processor architecture: Intel x64
15:02:58.0035 0x267c Number of processors: 4
15:02:58.0035 0x267c Page size: 0x1000
15:02:58.0035 0x267c Boot type: Normal boot
15:02:58.0035 0x267c CodeIntegrityOptions = 0x00000001
15:02:58.0035 0x267c ============================================================
15:02:58.0394 0x267c KLMD registered as C:\WINDOWS\system32\drivers\39350471.sys
15:02:58.0394 0x267c KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 16299.402, osProperties = 0x19
15:02:58.0581 0x267c System UUID: {8F56CC50-72FF-717A-C43D-55206A1651FB}
15:02:59.0191 0x267c Drive \Device\Harddisk0\DR0 - Size: 0x2BAA1476000 ( 2794.52 Gb ), SectorSize: 0x200, Cylinders: 0x59101, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:02:59.0410 0x267c Drive \Device\Harddisk1\DR1 - Size: 0x2BAA1476000 ( 2794.52 Gb ), SectorSize: 0x200, Cylinders: 0x59101, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:02:59.0472 0x267c ============================================================
15:02:59.0472 0x267c \Device\Harddisk0\DR0:
15:02:59.0472 0x267c MBR partitions:
15:02:59.0472 0x267c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
15:02:59.0472 0x267c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x6823000
15:02:59.0472 0x267c \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x6936800, BlocksNum 0xF96C9000
15:02:59.0472 0x267c \Device\Harddisk1\DR1:
15:02:59.0472 0x267c GPT partitions:
15:02:59.0472 0x267c \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {B0C464E9-9063-46A7-A0C2-CE9E732BAC7C}, Name: Microsoft reserved partition, StartLBA 0x22, BlocksNum 0x40000
15:02:59.0472 0x267c \Device\Harddisk1\DR1\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {24540C85-64BF-4D52-8E0F-3FDB4407F9E1}, Name: Basic data partition, StartLBA 0x40800, BlocksNum 0xE33A9800
15:02:59.0472 0x267c \Device\Harddisk1\DR1\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {3870E190-12FF-40F1-919A-43224FBE8A1A}, Name: Basic data partition, StartLBA 0xE33EA000, BlocksNum 0x7A11F800
15:02:59.0472 0x267c MBR partitions:
15:02:59.0472 0x267c ============================================================
15:02:59.0488 0x267c C: <-> \Device\Harddisk0\DR0\Partition2
15:02:59.0535 0x267c D: <-> \Device\Harddisk1\DR1\Partition3
15:02:59.0550 0x267c F: <-> \Device\Harddisk0\DR0\Partition3
15:02:59.0597 0x267c G: <-> \Device\Harddisk1\DR1\Partition2
15:02:59.0597 0x267c ============================================================
15:02:59.0597 0x267c Initialize success
15:02:59.0597 0x267c ============================================================
15:03:42.0858 0x2fb0 ============================================================
15:03:42.0858 0x2fb0 Scan started
15:03:42.0858 0x2fb0 Mode: Manual; SigCheck; TDLFS;
15:03:42.0858 0x2fb0 ============================================================
15:03:42.0858 0x2fb0 KSN ping started
15:03:43.0010 0x2fb0 KSN ping finished: true
15:03:45.0262 0x2fb0 ================ Scan system memory ========================
15:03:45.0262 0x2fb0 System memory - ok
15:03:45.0262 0x2fb0 ================ Scan services =============================
15:03:45.0370 0x2fb0 1394ohci - ok
15:03:45.0378 0x2fb0 3ware - ok
15:03:45.0398 0x2fb0 ACPI - ok
15:03:45.0402 0x2fb0 AcpiDev - ok
15:03:45.0414 0x2fb0 acpiex - ok
15:03:45.0422 0x2fb0 acpipagr - ok
15:03:45.0438 0x2fb0 AcpiPmi - ok
15:03:45.0446 0x2fb0 acpitime - ok
15:03:45.0458 0x2fb0 ADP80XX - ok
15:03:45.0482 0x2fb0 AFD - ok
15:03:45.0490 0x2fb0 ahcache - ok
15:03:45.0502 0x2fb0 AJRouter - ok
15:03:45.0518 0x2fb0 ALG - ok
15:03:45.0526 0x2fb0 AmdK8 - ok
15:03:45.0538 0x2fb0 AmdPPM - ok
15:03:45.0546 0x2fb0 amdsata - ok
15:03:45.0558 0x2fb0 amdsbs - ok
15:03:45.0566 0x2fb0 amdxata - ok
15:03:45.0590 0x2fb0 AppID - ok
15:03:45.0598 0x2fb0 AppIDSvc - ok
15:03:45.0614 0x2fb0 Appinfo - ok
15:03:45.0634 0x2fb0 applockerfltr - ok
15:03:45.0642 0x2fb0 AppMgmt - ok
15:03:45.0650 0x2fb0 AppReadiness - ok
15:03:45.0678 0x2fb0 AppVClient - ok
15:03:45.0698 0x2fb0 AppvStrm - ok
15:03:45.0726 0x2fb0 AppvVemgr - ok
15:03:45.0742 0x2fb0 AppvVfs - ok
15:03:45.0762 0x2fb0 AppXSvc - ok
15:03:45.0766 0x2fb0 arcsas - ok
15:03:45.0810 0x2fb0 AssignedAccessManagerSvc - ok
15:03:45.0814 0x2fb0 AsyncMac - ok
15:03:45.0834 0x2fb0 atapi - ok
15:03:45.0850 0x2fb0 AudioEndpointBuilder - ok
15:03:45.0866 0x2fb0 Audiosrv - ok
15:03:45.0870 0x2fb0 AxInstSV - ok
15:03:45.0878 0x2fb0 b06bdrv - ok
15:03:45.0898 0x2fb0 bam - ok
15:03:45.0914 0x2fb0 BasicDisplay - ok
15:03:45.0934 0x2fb0 BasicRender - ok
15:03:45.0942 0x2fb0 bcmfn2 - ok
15:03:45.0950 0x2fb0 BDESVC - ok
15:03:45.0962 0x2fb0 Beep - ok
15:03:45.0974 0x2fb0 BFE - ok
15:03:45.0982 0x2fb0 BITS - ok
15:03:45.0998 0x2fb0 bowser - ok
15:03:46.0006 0x2fb0 BrokerInfrastructure - ok
15:03:46.0026 0x2fb0 Browser - ok
15:03:46.0054 0x2fb0 BthAvrcpTg - ok
15:03:46.0062 0x2fb0 BthHFEnum - ok
15:03:46.0070 0x2fb0 bthhfhid - ok
15:03:46.0078 0x2fb0 BthHFSrv - ok
15:03:46.0082 0x2fb0 BTHMODEM - ok
15:03:46.0094 0x2fb0 bthserv - ok
15:03:46.0098 0x2fb0 bttflt - ok
15:03:46.0122 0x2fb0 [ 5A458422B4312BAEEFA3E64D321596E6, 1213D86B9B6FBB1414D1D3E5F4B0ED0C68D05EB98C902395AB0F0FC3D8A29AD5 ] busenum C:\WINDOWS\System32\drivers\busenum.sys
15:03:46.0306 0x2fb0 busenum - ok
15:03:46.0330 0x2fb0 buttonconverter - ok
15:03:46.0334 0x2fb0 CAD - ok
15:03:46.0350 0x2fb0 camsvc - ok
15:03:46.0358 0x2fb0 CapImg - ok
15:03:46.0366 0x2fb0 cdfs - ok
15:03:46.0374 0x2fb0 CDPSvc - ok
15:03:46.0390 0x2fb0 CDPUserSvc - ok
15:03:46.0442 0x2fb0 cdrom - ok
15:03:46.0458 0x2fb0 CertPropSvc - ok
15:03:46.0466 0x2fb0 cht4iscsi - ok
15:03:46.0474 0x2fb0 cht4vbd - ok
15:03:46.0482 0x2fb0 circlass - ok
15:03:46.0498 0x2fb0 CldFlt - ok
15:03:46.0522 0x2fb0 CLFS - ok
15:03:46.0546 0x2fb0 ClipSVC - ok
15:03:46.0562 0x2fb0 CmBatt - ok
15:03:46.0578 0x2fb0 CNG - ok
15:03:46.0586 0x2fb0 cnghwassist - ok
15:03:46.0646 0x2fb0 CompositeBus - ok
15:03:46.0654 0x2fb0 COMSysApp - ok
15:03:46.0662 0x2fb0 condrv - ok
15:03:46.0678 0x2fb0 CoreMessagingRegistrar - ok
15:03:46.0706 0x2fb0 CryptSvc - ok
15:03:46.0714 0x2fb0 CSC - ok
15:03:46.0730 0x2fb0 CscService - ok
15:03:46.0734 0x2fb0 dam - ok
15:03:46.0758 0x2fb0 [ 7AF9DAC504FBD047CBC3E64AE52C92BF, CA8F9564733DED4C3895CF7150BB254995D66889E6BE08D6654E4F897E4FF7A4 ] dc3d C:\WINDOWS\System32\drivers\dc3d.sys
15:03:46.0990 0x2fb0 dc3d - ok
15:03:46.0998 0x2fb0 DcomLaunch - ok
15:03:47.0002 0x2fb0 defragsvc - ok
15:03:47.0010 0x2fb0 DeviceAssociationService - ok
15:03:47.0018 0x2fb0 DeviceInstall - ok
15:03:47.0022 0x2fb0 DevicesFlowUserSvc - ok
15:03:47.0054 0x2fb0 DevQueryBroker - ok
15:03:47.0450 0x2fb0 Dfsc - ok
15:03:47.0486 0x2fb0 Dhcp - ok
15:03:47.0518 0x2fb0 diagnosticshub.standardcollector.service - ok
15:03:47.0530 0x2fb0 diagsvc - ok
15:03:47.0546 0x2fb0 DiagTrack - ok
15:03:47.0550 0x2fb0 Disk - ok
15:03:47.0578 0x2fb0 DmEnrollmentSvc - ok
15:03:47.0586 0x2fb0 dmvsc - ok
15:03:47.0594 0x2fb0 dmwappushservice - ok
15:03:47.0614 0x2fb0 Dnscache - ok
15:03:47.0622 0x2fb0 dot3svc - ok
15:03:47.0630 0x2fb0 DPS - ok
15:03:47.0638 0x2fb0 drmkaud - ok
15:03:47.0654 0x2fb0 DsmSvc - ok
15:03:47.0662 0x2fb0 DsSvc - ok
15:03:47.0678 0x2fb0 DusmSvc - ok
15:03:47.0698 0x2fb0 DXGKrnl - ok
15:03:47.0706 0x2fb0 Eaphost - ok
15:03:47.0714 0x2fb0 ebdrv - ok
15:03:47.0746 0x2fb0 EFS - ok
15:03:47.0754 0x2fb0 EhStorClass - ok
15:03:47.0778 0x2fb0 EhStorTcgDrv - ok
15:03:47.0786 0x2fb0 embeddedmode - ok
15:03:47.0810 0x2fb0 EntAppSvc - ok
15:03:47.0814 0x2fb0 ErrDev - ok
15:03:47.0834 0x2fb0 EventSystem - ok
15:03:47.0842 0x2fb0 exfat - ok
15:03:47.0850 0x2fb0 fastfat - ok
15:03:47.0870 0x2fb0 Fax - ok
15:03:47.0878 0x2fb0 fdc - ok
15:03:47.0882 0x2fb0 fdPHost - ok
15:03:47.0890 0x2fb0 FDResPub - ok
15:03:47.0898 0x2fb0 fhsvc - ok
15:03:47.0926 0x2fb0 FileCrypt - ok
15:03:47.0934 0x2fb0 FileInfo - ok
15:03:47.0938 0x2fb0 Filetrace - ok
15:03:47.0946 0x2fb0 flpydisk - ok
15:03:47.0970 0x2fb0 FltMgr - ok
15:03:47.0994 0x2fb0 FontCache - ok
15:03:48.0034 0x2fb0 FontCache3.0.0.0 - ok
15:03:48.0054 0x2fb0 FrameServer - ok
15:03:48.0066 0x2fb0 FsDepends - ok
15:03:48.0074 0x2fb0 Fs_Rec - ok
15:03:48.0082 0x2fb0 fvevol - ok
15:03:48.0106 0x2fb0 gencounter - ok
15:03:48.0118 0x2fb0 genericusbfn - ok
15:03:48.0130 0x2fb0 GPIOClx0101 - ok
15:03:48.0142 0x2fb0 gpsvc - ok
15:03:48.0146 0x2fb0 GpuEnergyDrv - ok
15:03:48.0162 0x2fb0 GraphicsPerfSvc - ok
15:03:48.0174 0x2fb0 HDAudBus - ok
15:03:48.0178 0x2fb0 HidBatt - ok
15:03:48.0186 0x2fb0 HidBth - ok
15:03:48.0194 0x2fb0 hidi2c - ok
15:03:48.0202 0x2fb0 hidinterrupt - ok
15:03:48.0206 0x2fb0 HidIr - ok
15:03:48.0218 0x2fb0 hidserv - ok
15:03:48.0246 0x2fb0 HidUsb - ok
15:03:48.0254 0x2fb0 HomeGroupListener - ok
15:03:48.0278 0x2fb0 HomeGroupProvider - ok
15:03:48.0286 0x2fb0 HpSAMD - ok
15:03:48.0298 0x2fb0 HTTP - ok
15:03:48.0310 0x2fb0 HvHost - ok
15:03:48.0330 0x2fb0 hvservice - ok
15:03:48.0334 0x2fb0 HwNClx0101 - ok
15:03:48.0342 0x2fb0 hwpolicy - ok
15:03:48.0350 0x2fb0 hyperkbd - ok
15:03:48.0370 0x2fb0 HyperVideo - ok
15:03:48.0378 0x2fb0 i8042prt - ok
15:03:48.0382 0x2fb0 iagpio - ok
15:03:48.0390 0x2fb0 iai2c - ok
15:03:48.0394 0x2fb0 iaLPSS2i_GPIO2 - ok
15:03:48.0394 0x2fb0 iaLPSS2i_GPIO2_BXT_P - ok
15:03:48.0410 0x2fb0 iaLPSS2i_I2C - ok
15:03:48.0410 0x2fb0 iaLPSS2i_I2C_BXT_P - ok
15:03:48.0410 0x2fb0 iaLPSSi_GPIO - ok
15:03:48.0425 0x2fb0 iaLPSSi_I2C - ok
15:03:48.0425 0x2fb0 iaStorAV - ok
15:03:48.0441 0x2fb0 iaStorV - ok
15:03:48.0441 0x2fb0 ibbus - ok
15:03:48.0472 0x2fb0 icssvc - ok
15:03:48.0488 0x2fb0 IKEEXT - ok
15:03:48.0488 0x2fb0 IndirectKmd - ok
15:03:48.0519 0x2fb0 InstallService - ok
15:03:48.0644 0x2fb0 [ 622868E4BAE8FBCD22CB1A5901A2C824, C1A2264C0984DD16C83B663C9CE43E049E1356E32C5771C3ACE225F285699138 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
15:03:49.0050 0x2fb0 IntcAzAudAddService - ok
15:03:49.0066 0x2fb0 intelide - ok
15:03:49.0082 0x2fb0 intelpep - ok
15:03:49.0082 0x2fb0 intelppm - ok
15:03:49.0097 0x2fb0 invdimm - ok
15:03:49.0113 0x2fb0 iorate - ok
15:03:49.0113 0x2fb0 IpFilterDriver - ok
15:03:49.0144 0x2fb0 iphlpsvc - ok
15:03:49.0144 0x2fb0 IPMIDRV - ok
15:03:49.0160 0x2fb0 IPNAT - ok
15:03:49.0160 0x2fb0 IPT - ok
15:03:49.0175 0x2fb0 IpxlatCfgSvc - ok
15:03:49.0175 0x2fb0 irda - ok
15:03:49.0191 0x2fb0 IRENUM - ok
15:03:49.0191 0x2fb0 irmon - ok
15:03:49.0207 0x2fb0 isapnp - ok
15:03:49.0207 0x2fb0 iScsiPrt - ok
15:03:49.0238 0x2fb0 kbdclass - ok
15:03:49.0238 0x2fb0 kbdhid - ok
15:03:49.0254 0x2fb0 kdnic - ok
15:03:49.0269 0x2fb0 KeyIso - ok
15:03:49.0269 0x2fb0 KSecDD - ok
15:03:49.0269 0x2fb0 KSecPkg - ok
15:03:49.0285 0x2fb0 ksthunk - ok
15:03:49.0300 0x2fb0 KtmRm - ok
15:03:49.0316 0x2fb0 LanmanServer - ok
15:03:49.0316 0x2fb0 LanmanWorkstation - ok
15:03:49.0332 0x2fb0 lfsvc - ok
15:03:49.0347 0x2fb0 LicenseManager - ok
15:03:49.0363 0x2fb0 lltdio - ok
15:03:49.0363 0x2fb0 lltdsvc - ok
15:03:49.0379 0x2fb0 lmhosts - ok
15:03:49.0394 0x2fb0 LSI_SAS - ok
15:03:49.0410 0x2fb0 LSI_SAS2i - ok
15:03:49.0410 0x2fb0 LSI_SAS3i - ok
15:03:49.0410 0x2fb0 LSI_SSS - ok
15:03:49.0425 0x2fb0 LSM - ok
15:03:49.0441 0x2fb0 luafv - ok
15:03:49.0457 0x2fb0 MapsBroker - ok
15:03:49.0457 0x2fb0 mausbhost - ok
15:03:49.0472 0x2fb0 mausbip - ok
15:03:49.0488 0x2fb0 [ 3BEC6134F1E45AEF5E971F69F0D38510, 245D7CEEB6561166EE0472551D39A9D3CFDDA52A6BF2E924AB243CCA7FBC9009 ] MBAMChameleon C:\WINDOWS\system32\drivers\MBAMChameleon.sys
15:03:49.0519 0x2fb0 MBAMChameleon - ok
15:03:49.0535 0x2fb0 [ 205C2D377E1CA85A4465491DB8064DA9, 0C69C6C958D8E26A6C6CCF2254E8B531BE718AD7FCFEB970F6F09426CA6C8C26 ] MBAMWebProtection C:\WINDOWS\system32\drivers\mwac.sys
15:03:49.0597 0x2fb0 MBAMWebProtection - ok
15:03:49.0691 0x2fb0 [ 11F714F85530A2BD134074DC30E99FCA, BDB5FD3B2DF4ADD19B31965B3E789768B59E872B3EA85912B1FFB32B2AF9D5D8 ] MDM C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
15:03:49.0722 0x2fb0 MDM - ok
15:03:49.0722 0x2fb0 megasas - ok
15:03:49.0738 0x2fb0 megasas2i - ok
15:03:49.0738 0x2fb0 megasr - ok
15:03:49.0769 0x2fb0 MessagingService - ok
15:03:49.0785 0x2fb0 mlx4_bus - ok
15:03:49.0800 0x2fb0 MMCSS - ok
15:03:49.0800 0x2fb0 Modem - ok
15:03:49.0832 0x2fb0 monitor - ok
15:03:49.0832 0x2fb0 mouclass - ok
15:03:49.0847 0x2fb0 mouhid - ok
15:03:49.0863 0x2fb0 mountmgr - ok
15:03:49.0894 0x2fb0 [ 8DD008A80942B478D8D792646BDAB723, 782F7841AD1401933021CB180CBF1B4B06D2839695E1A2B9452EEFC090BCCB46 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
15:03:50.0019 0x2fb0 MozillaMaintenance - ok
15:03:50.0035 0x2fb0 mpsdrv - ok
15:03:50.0050 0x2fb0 MpsSvc - ok
15:03:50.0050 0x2fb0 MRxDAV - ok
15:03:50.0066 0x2fb0 mrxsmb - ok
15:03:50.0066 0x2fb0 mrxsmb10 - ok
15:03:50.0082 0x2fb0 mrxsmb20 - ok
15:03:50.0097 0x2fb0 MsBridge - ok
15:03:50.0113 0x2fb0 MSDTC - ok
15:03:50.0129 0x2fb0 Msfs - ok
15:03:50.0144 0x2fb0 msgpiowin32 - ok
15:03:50.0160 0x2fb0 mshidkmdf - ok
15:03:50.0160 0x2fb0 mshidumdf - ok
15:03:50.0191 0x2fb0 msisadrv - ok
15:03:50.0207 0x2fb0 MSiSCSI - ok
15:03:50.0207 0x2fb0 msiserver - ok
15:03:50.0222 0x2fb0 MSKSSRV - ok
15:03:50.0222 0x2fb0 MsLldp - ok
15:03:50.0238 0x2fb0 MSPCLOCK - ok
15:03:50.0238 0x2fb0 MSPQM - ok
15:03:50.0254 0x2fb0 MsRPC - ok
15:03:50.0254 0x2fb0 MsSecFlt - ok
15:03:50.0269 0x2fb0 mssmbios - ok
15:03:50.0269 0x2fb0 MSTEE - ok
15:03:50.0285 0x2fb0 MTConfig - ok
15:03:50.0285 0x2fb0 Mup - ok
15:03:50.0285 0x2fb0 mvumis - ok
15:03:50.0316 0x2fb0 NativeWifiP - ok
15:03:50.0332 0x2fb0 NaturalAuthentication - ok
15:03:50.0347 0x2fb0 NcaSvc - ok
15:03:50.0363 0x2fb0 NcbService - ok
15:03:50.0379 0x2fb0 NcdAutoSetup - ok
15:03:50.0379 0x2fb0 ndfltr - ok
15:03:50.0379 0x2fb0 NDIS - ok
15:03:50.0394 0x2fb0 NdisCap - ok
15:03:50.0394 0x2fb0 NdisImPlatform - ok
15:03:50.0441 0x2fb0 NdisTapi - ok
15:03:50.0441 0x2fb0 Ndisuio - ok
15:03:50.0457 0x2fb0 NdisVirtualBus - ok
15:03:50.0472 0x2fb0 NdisWan - ok
15:03:50.0472 0x2fb0 ndiswanlegacy - ok
15:03:50.0488 0x2fb0 ndproxy - ok
15:03:50.0504 0x2fb0 Ndu - ok
15:03:50.0504 0x2fb0 NetAdapterCx - ok
15:03:50.0519 0x2fb0 NetBIOS - ok
15:03:50.0519 0x2fb0 NetBT - ok
15:03:50.0535 0x2fb0 Netlogon - ok
15:03:50.0535 0x2fb0 Netman - ok
15:03:50.0550 0x2fb0 netprofm - ok
15:03:50.0566 0x2fb0 NetSetupSvc - ok
15:03:50.0597 0x2fb0 NetTcpPortSharing - ok
15:03:50.0629 0x2fb0 netvsc - ok
15:03:50.0660 0x2fb0 NgcCtnrSvc - ok
15:03:50.0660 0x2fb0 NgcSvc - ok
15:03:50.0660 0x2fb0 NlaSvc - ok
15:03:50.0675 0x2fb0 Npfs - ok
15:03:50.0707 0x2fb0 npsvctrig - ok
15:03:50.0707 0x2fb0 nsi - ok
15:03:50.0722 0x2fb0 nsiproxy - ok
15:03:50.0722 0x2fb0 NTFS - ok
15:03:50.0738 0x2fb0 Null - ok
15:03:50.0754 0x2fb0 nvdimmn - ok
15:03:50.0785 0x2fb0 [ BF58D8D2DA50AF7A8E55567B7C73661A, 8E6436235E8EBCD20E121BBE8136563B918C127A509192C355F0FCDC6A993ABB ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
15:03:50.0879 0x2fb0 NVHDA - ok
15:03:51.0472 0x2fb0 [ B7CDB3C5EEB48C892D94759D99B19D09, C7A13578AE15ABE6A0053C6B0B45CE17216CFD0E080CCF5AEED79D6C7CB22756 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_c1a085cc86772d3f\nvlddmkm.sys
15:03:52.0675 0x2fb0 nvlddmkm - ok
15:03:52.0738 0x2fb0 nvraid - ok
15:03:52.0754 0x2fb0 nvstor - ok
15:03:52.0816 0x2fb0 [ C460BF2A612CDC75FEA0C8B571912773, DC05370D81948CDA867859E7ACB7E83EF366A752E63547FAB8BEE39C818B73EA ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
15:03:52.0910 0x2fb0 NvStreamKms - ok
15:03:52.0988 0x2fb0 [ 4DFCEB68ADDF290C541D4BD36BBB1AB5, 93918E766DC4898543CE7730782B6C4454D48B08A2F1B4C68F3C9C85E0B9CFB3 ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
15:03:53.0019 0x2fb0 NvTelemetryContainer - ok
15:03:53.0035 0x2fb0 [ 036A8C30C662397A2D882D9AFF99089F, C7AC0E6F7E3275890E36CA052C9DFF1D6D16D9F6102856D51AF088641C7B5709 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
15:03:53.0097 0x2fb0 nvvad_WaveExtensible - ok
15:03:53.0129 0x2fb0 [ 6F34CDC03E80AB53383527072833A731, 5126DCA262F6F74E1EF090EBDE3F50F316A39E368BD59AB675AFD41A1B30FF8D ] nvvhci C:\WINDOWS\System32\drivers\nvvhci.sys
15:03:53.0144 0x2fb0 nvvhci - ok
15:03:53.0175 0x2fb0 OneSyncSvc - ok
15:03:53.0175 0x2fb0 p2pimsvc - ok
15:03:53.0191 0x2fb0 p2psvc - ok
15:03:53.0207 0x2fb0 Parport - ok
15:03:53.0207 0x2fb0 partmgr - ok
15:03:53.0222 0x2fb0 PcaSvc - ok
15:03:53.0238 0x2fb0 pci - ok
15:03:53.0254 0x2fb0 pciide - ok
15:03:53.0254 0x2fb0 pcmcia - ok
15:03:53.0269 0x2fb0 pcw - ok
15:03:53.0269 0x2fb0 pdc - ok
15:03:53.0285 0x2fb0 PEAUTH - ok
15:03:53.0285 0x2fb0 PeerDistSvc - ok
15:03:53.0300 0x2fb0 percsas2i - ok
15:03:53.0316 0x2fb0 percsas3i - ok
15:03:53.0363 0x2fb0 PerfHost - ok
15:03:53.0394 0x2fb0 PhoneSvc - ok
15:03:53.0410 0x2fb0 PimIndexMaintenanceSvc - ok
15:03:53.0457 0x2fb0 pla - ok
15:03:53.0472 0x2fb0 PlugPlay - ok
15:03:53.0472 0x2fb0 pmem - ok
15:03:53.0488 0x2fb0 PNPMEM - ok
15:03:53.0504 0x2fb0 PNRPAutoReg - ok
15:03:53.0504 0x2fb0 PNRPsvc - ok
15:03:53.0519 0x2fb0 PolicyAgent - ok
15:03:53.0535 0x2fb0 Power - ok
15:03:53.0566 0x2fb0 PptpMiniport - ok
15:03:53.0691 0x2fb0 [ FAA5FBD37C00DE72573F9BF6B6E64BAD, AEF599C9D47ED197FAC54326E99114AD7EAA107A0248C77997D353A7B5C06FBB ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
15:03:54.0050 0x2fb0 PrintNotify - ok
15:03:54.0066 0x2fb0 PrintWorkflowUserSvc - ok
15:03:54.0097 0x2fb0 Processor - ok
15:03:54.0129 0x2fb0 ProfSvc - ok
15:03:54.0160 0x2fb0 Psched - ok
15:03:54.0191 0x2fb0 PushToInstall - ok
15:03:54.0191 0x2fb0 QWAVE - ok
15:03:54.0207 0x2fb0 QWAVEdrv - ok
15:03:54.0222 0x2fb0 Ramdisk - ok
15:03:54.0238 0x2fb0 RasAcd - ok
15:03:54.0254 0x2fb0 RasAgileVpn - ok
15:03:54.0269 0x2fb0 RasAuto - ok
15:03:54.0285 0x2fb0 Rasl2tp - ok
15:03:54.0285 0x2fb0 RasMan - ok
15:03:54.0300 0x2fb0 RasPppoe - ok
15:03:54.0300 0x2fb0 RasSstp - ok
15:03:54.0316 0x2fb0 rdbss - ok
15:03:54.0332 0x2fb0 rdpbus - ok
15:03:54.0332 0x2fb0 RDPDR - ok
15:03:54.0363 0x2fb0 RdpVideoMiniport - ok
15:03:54.0363 0x2fb0 rdyboost - ok
15:03:54.0379 0x2fb0 ReFS - ok
15:03:54.0379 0x2fb0 ReFSv1 - ok
15:03:54.0410 0x2fb0 RemoteAccess - ok
15:03:54.0425 0x2fb0 RemoteRegistry - ok
15:03:54.0457 0x2fb0 RetailDemo - ok
15:03:54.0457 0x2fb0 rhproxy - ok
15:03:54.0472 0x2fb0 RmSvc - ok
15:03:54.0472 0x2fb0 RpcEptMapper - ok
15:03:54.0488 0x2fb0 RpcLocator - ok
15:03:54.0488 0x2fb0 RpcSs - ok
15:03:54.0519 0x2fb0 rspndr - ok
15:03:54.0519 0x2fb0 rt640x64 - ok
15:03:54.0535 0x2fb0 s3cap - ok
15:03:54.0582 0x2fb0 SamSs - ok
15:03:54.0582 0x2fb0 sbp2port - ok
15:03:54.0613 0x2fb0 SCardSvr - ok
15:03:54.0629 0x2fb0 ScDeviceEnum - ok
15:03:54.0629 0x2fb0 scfilter - ok
15:03:54.0660 0x2fb0 Schedule - ok
15:03:54.0675 0x2fb0 scmbus - ok
15:03:54.0675 0x2fb0 SCPolicySvc - ok
15:03:54.0691 0x2fb0 sdbus - ok
15:03:54.0691 0x2fb0 SDFRd - ok
15:03:54.0707 0x2fb0 SDRSVC - ok
15:03:54.0738 0x2fb0 sdstor - ok
15:03:54.0738 0x2fb0 seclogon - ok
15:03:54.0769 0x2fb0 SecurityHealthService - ok
15:03:54.0785 0x2fb0 SEMgrSvc - ok
15:03:54.0785 0x2fb0 SENS - ok
15:03:54.0800 0x2fb0 Sense - ok
15:03:54.0816 0x2fb0 SensorDataService - ok
15:03:54.0847 0x2fb0 SensorService - ok
15:03:54.0863 0x2fb0 SensrSvc - ok
15:03:54.0863 0x2fb0 SerCx - ok
15:03:54.0863 0x2fb0 SerCx2 - ok
15:03:54.0879 0x2fb0 Serenum - ok
15:03:54.0894 0x2fb0 Serial - ok
15:03:54.0910 0x2fb0 sermouse - ok
15:03:54.0925 0x2fb0 SessionEnv - ok
15:03:54.0941 0x2fb0 sfloppy - ok
15:03:54.0957 0x2fb0 SharedAccess - ok
15:03:54.0988 0x2fb0 SharedRealitySvc - ok
15:03:54.0988 0x2fb0 ShellHWDetection - ok
15:03:55.0019 0x2fb0 shpamsvc - ok
15:03:55.0019 0x2fb0 SiSRaid2 - ok
15:03:55.0019 0x2fb0 SiSRaid4 - ok
15:03:55.0050 0x2fb0 smphost - ok
15:03:55.0066 0x2fb0 SmsRouter - ok
15:03:55.0082 0x2fb0 SNMPTRAP - ok
15:03:55.0097 0x2fb0 spaceport - ok
15:03:55.0129 0x2fb0 SpatialGraphFilter - ok
15:03:55.0129 0x2fb0 SpbCx - ok
15:03:55.0144 0x2fb0 spectrum - ok
15:03:55.0160 0x2fb0 Spooler - ok
15:03:55.0175 0x2fb0 sppsvc - ok
15:03:55.0191 0x2fb0 srv - ok
15:03:55.0207 0x2fb0 srv2 - ok
15:03:55.0222 0x2fb0 srvnet - ok
15:03:55.0238 0x2fb0 SSDPSRV - ok
15:03:55.0254 0x2fb0 [ 0211AB46B73A2623B86C1CFCB30579AB, 7CC9BA2DF7B9EA6BB17EE342898EDD7F54703B93B6DED6A819E83A7EE9F938B4 ] SSPORT C:\WINDOWS\system32\Drivers\SSPORT.sys
15:03:55.0300 0x2fb0 SSPORT - ok
15:03:55.0316 0x2fb0 SstpSvc - ok
15:03:55.0332 0x2fb0 StateRepository - ok
15:03:55.0347 0x2fb0 stexstor - ok
15:03:55.0363 0x2fb0 stisvc - ok
15:03:55.0363 0x2fb0 storahci - ok
15:03:55.0379 0x2fb0 storflt - ok
15:03:55.0379 0x2fb0 stornvme - ok
15:03:55.0394 0x2fb0 storqosflt - ok
15:03:55.0410 0x2fb0 StorSvc - ok
15:03:55.0410 0x2fb0 storufs - ok
15:03:55.0410 0x2fb0 storvsc - ok
15:03:55.0425 0x2fb0 svsvc - ok
15:03:55.0425 0x2fb0 swenum - ok
15:03:55.0441 0x2fb0 swprv - ok
15:03:55.0472 0x2fb0 Synth3dVsc - ok
15:03:55.0488 0x2fb0 SysMain - ok
15:03:55.0519 0x2fb0 SystemEventsBroker - ok
15:03:55.0519 0x2fb0 TabletInputService - ok
15:03:55.0535 0x2fb0 TapiSrv - ok
15:03:55.0535 0x2fb0 Tcpip - ok
15:03:55.0550 0x2fb0 Tcpip6 - ok
15:03:55.0566 0x2fb0 tcpipreg - ok
15:03:55.0566 0x2fb0 tdx - ok
15:03:55.0879 0x2fb0 [ 70695B67EE8E743125FEBE689BDF9F0E, 6D61BA67A2125F9F2DF81307868CC5BAEE3990F3E6D89D1F2C405A99CB0B7B34 ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
15:03:58.0910 0x2fb0 TeamViewer - ok
15:03:58.0941 0x2fb0 terminpt - ok
15:03:58.0957 0x2fb0 TermService - ok
15:03:58.0957 0x2fb0 Themes - ok
15:03:58.0972 0x2fb0 TieringEngineService - ok
15:03:58.0972 0x2fb0 tiledatamodelsvc - ok
15:03:59.0004 0x2fb0 TimeBrokerSvc - ok
15:03:59.0019 0x2fb0 TokenBroker - ok
15:03:59.0050 0x2fb0 TPM - ok
15:03:59.0050 0x2fb0 TrkWks - ok
15:03:59.0097 0x2fb0 TrustedInstaller - ok
15:03:59.0113 0x2fb0 tsusbflt - ok
15:03:59.0113 0x2fb0 TsUsbGD - ok
15:03:59.0129 0x2fb0 tsusbhub - ok
15:03:59.0129 0x2fb0 tunnel - ok
15:03:59.0144 0x2fb0 tzautoupdate - ok
15:03:59.0144 0x2fb0 UASPStor - ok
15:03:59.0160 0x2fb0 UcmCx0101 - ok
15:03:59.0160 0x2fb0 UcmTcpciCx0101 - ok
15:03:59.0175 0x2fb0 UcmUcsi - ok
15:03:59.0191 0x2fb0 Ucx01000 - ok
15:03:59.0191 0x2fb0 UdeCx - ok
15:03:59.0191 0x2fb0 udfs - ok
15:03:59.0207 0x2fb0 UEFI - ok
15:03:59.0207 0x2fb0 UevAgentDriver - ok
15:03:59.0238 0x2fb0 UevAgentService - ok
15:03:59.0238 0x2fb0 Ufx01000 - ok
15:03:59.0254 0x2fb0 UfxChipidea - ok
15:03:59.0254 0x2fb0 ufxsynopsys - ok
15:03:59.0269 0x2fb0 UI0Detect - ok
15:03:59.0285 0x2fb0 umbus - ok
15:03:59.0300 0x2fb0 UmPass - ok
15:03:59.0316 0x2fb0 UmRdpService - ok
15:03:59.0332 0x2fb0 UnistoreSvc - ok
15:03:59.0347 0x2fb0 upnphost - ok
15:03:59.0363 0x2fb0 UrsChipidea - ok
15:03:59.0379 0x2fb0 UrsCx01000 - ok
15:03:59.0379 0x2fb0 UrsSynopsys - ok
15:03:59.0394 0x2fb0 usbccgp - ok
15:03:59.0394 0x2fb0 usbcir - ok
15:03:59.0472 0x2fb0 [ 29F92C6FFF8D8B661742CB67595BB279, 4460872F57C0CF7B20E44A538360B3B6F7FAB9117EC9C821A79B5ED22B214AAC ] UsbClientService C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
15:03:59.0504 0x2fb0 UsbClientService - ok
15:03:59.0519 0x2fb0 usbehci - ok
15:03:59.0519 0x2fb0 usbhub - ok
15:03:59.0519 0x2fb0 USBHUB3 - ok
15:03:59.0535 0x2fb0 usbohci - ok
15:03:59.0535 0x2fb0 usbprint - ok
15:03:59.0550 0x2fb0 usbser - ok
15:03:59.0566 0x2fb0 USBSTOR - ok
15:03:59.0582 0x2fb0 usbuhci - ok
15:03:59.0597 0x2fb0 USBXHCI - ok
15:03:59.0613 0x2fb0 UserDataSvc - ok
15:03:59.0629 0x2fb0 UserManager - ok
15:03:59.0644 0x2fb0 UsoSvc - ok
15:03:59.0644 0x2fb0 VaultSvc - ok
15:03:59.0660 0x2fb0 vdrvroot - ok
15:03:59.0675 0x2fb0 vds - ok
15:03:59.0675 0x2fb0 VerifierExt - ok
15:03:59.0691 0x2fb0 vhdmp - ok
15:03:59.0691 0x2fb0 vhf - ok
15:03:59.0691 0x2fb0 vmbus - ok
15:03:59.0722 0x2fb0 VMBusHID - ok
15:03:59.0722 0x2fb0 vmgid - ok
15:03:59.0738 0x2fb0 vmicguestinterface - ok
15:03:59.0738 0x2fb0 vmicheartbeat - ok
15:03:59.0754 0x2fb0 vmickvpexchange - ok
15:03:59.0769 0x2fb0 vmicrdv - ok
15:03:59.0769 0x2fb0 vmicshutdown - ok
15:03:59.0785 0x2fb0 vmictimesync - ok
15:03:59.0785 0x2fb0 vmicvmsession - ok
15:03:59.0800 0x2fb0 vmicvss - ok
15:03:59.0816 0x2fb0 vnvdimm - ok
15:03:59.0816 0x2fb0 volmgr - ok
15:03:59.0832 0x2fb0 volmgrx - ok
15:03:59.0847 0x2fb0 volsnap - ok
15:03:59.0863 0x2fb0 volume - ok
15:03:59.0863 0x2fb0 vpci - ok
15:03:59.0879 0x2fb0 vsmraid - ok
15:03:59.0879 0x2fb0 VSS - ok
15:03:59.0894 0x2fb0 VSTXRAID - ok
15:03:59.0925 0x2fb0 vwifibus - ok
15:03:59.0941 0x2fb0 vwififlt - ok
15:03:59.0957 0x2fb0 W32Time - ok
15:03:59.0972 0x2fb0 WacomPen - ok
15:03:59.0988 0x2fb0 WalletService - ok
15:03:59.0988 0x2fb0 wanarp - ok
15:04:00.0004 0x2fb0 wanarpv6 - ok
15:04:00.0004 0x2fb0 WarpJITSvc - ok
15:04:00.0019 0x2fb0 wbengine - ok
15:04:00.0035 0x2fb0 WbioSrvc - ok
15:04:00.0050 0x2fb0 wcifs - ok
15:04:00.0050 0x2fb0 Wcmsvc - ok
15:04:00.0066 0x2fb0 wcncsvc - ok
15:04:00.0066 0x2fb0 wcnfs - ok
15:04:00.0097 0x2fb0 [ 45545A0E3ECDC23C4E2C104674885F51, DC6042F4A10AA564461623440A6F5A63931D28643131047CF23E4CE1A9461893 ] WdBoot C:\WINDOWS\system32\drivers\wd\WdBoot.sys
15:04:00.0144 0x2fb0 WdBoot - ok
15:04:00.0144 0x2fb0 Wdf01000 - ok
15:04:00.0160 0x2fb0 [ 9A3299DA5B85B13C38C3DAB8F80B608D, E39361AEB53A5E6C5C21A3E708088870B7080EA0CC822E8518DCB579A729FDAA ] WdFilter C:\WINDOWS\system32\drivers\wd\WdFilter.sys
15:04:00.0238 0x2fb0 WdFilter - ok
15:04:00.0254 0x2fb0 WdiServiceHost - ok
15:04:00.0254 0x2fb0 WdiSystemHost - ok
15:04:00.0269 0x2fb0 wdiwifi - ok
15:04:00.0285 0x2fb0 [ BB1DD5254A7BBFE88F85B7EDCA3BE92A, 7B5721AAF9B8D96A2E73C50F873ACD95C0ED8F6915A16D258BDE199CC6FC9851 ] WdNisDrv C:\WINDOWS\system32\drivers\wd\WdNisDrv.sys
15:04:00.0316 0x2fb0 WdNisDrv - ok
15:04:00.0488 0x2fb0 [ 3769FB7454F9BFD2860D6E1CA0D3DD24, 2E0E9650F1BE1F20D106EC38ACA36B35658F161E1901E412E5AE535F72F5B5DB ] WdNisSvc C:\ProgramData\Microsoft\Windows Defender\platform\4.14.17639.18041-0\NisSrv.exe
15:04:00.0644 0x2fb0 WdNisSvc - ok
15:04:00.0691 0x2fb0 wdnsfltr - ok
15:04:00.0707 0x2fb0 WebClient - ok
15:04:00.0707 0x2fb0 Wecsvc - ok
15:04:00.0722 0x2fb0 WEPHOSTSVC - ok
15:04:00.0722 0x2fb0 wercplsupport - ok
15:04:00.0738 0x2fb0 WerSvc - ok
15:04:00.0738 0x2fb0 WFDSConMgrSvc - ok
15:04:00.0769 0x2fb0 WFPLWFS - ok
15:04:00.0769 0x2fb0 WiaRpc - ok
15:04:00.0800 0x2fb0 WIMMount - ok
15:04:00.0816 0x2fb0 [ B9AD53D60DA72C194F0AA2C89136FA35, DE0DC4F2E623A2F3AB5F57010765954A77E52D995AF74F6D8A52841C941C041B ] WinDefend C:\ProgramData\Microsoft\Windows Defender\platform\4.14.17639.18041-0\MsMpEng.exe
15:04:00.0832 0x2fb0 WinDefend - ok
15:04:00.0863 0x2fb0 WindowsTrustedRT - ok
15:04:00.0894 0x2fb0 WindowsTrustedRTProxy - ok
15:04:00.0910 0x2fb0 WinHttpAutoProxySvc - ok
15:04:00.0925 0x2fb0 WinMad - ok
15:04:00.0941 0x2fb0 Winmgmt - ok
15:04:00.0941 0x2fb0 WinNat - ok
15:04:00.0957 0x2fb0 WinRM - ok
15:04:00.0988 0x2fb0 WINUSB - ok
15:04:00.0988 0x2fb0 WinVerbs - ok
15:04:01.0004 0x2fb0 [ 3A627A24EAC6CEC3BA59548AA70BAD6E, C4B908CEB2D6F7F14C635AE02E20B16DAF795073975AE3967627D27E8ABAB015 ] WirelessKeyboardFilter C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys
15:04:01.0175 0x2fb0 WirelessKeyboardFilter - ok
15:04:01.0191 0x2fb0 wisvc - ok
15:04:01.0191 0x2fb0 WlanSvc - ok
15:04:01.0222 0x2fb0 wlidsvc - ok
15:04:01.0254 0x2fb0 wlpasvc - ok
15:04:01.0254 0x2fb0 WmiAcpi - ok
15:04:01.0285 0x2fb0 wmiApSrv - ok
15:04:01.0300 0x2fb0 WMPNetworkSvc - ok
15:04:01.0316 0x2fb0 [ 8D6E6F6C233AF450C50FA615530B44D2, 1BF6CD93B97920500F5FD0E9D8395ACCAAA2D126FD9C256148797B292D5F9A6C ] Wof C:\WINDOWS\system32\drivers\Wof.sys
15:04:01.0347 0x2fb0 Wof - ok
15:04:01.0363 0x2fb0 workfolderssvc - ok
15:04:01.0363 0x2fb0 WPDBusEnum - ok
15:04:01.0379 0x2fb0 WpdUpFltr - ok
15:04:01.0379 0x2fb0 WpnService - ok
15:04:01.0394 0x2fb0 WpnUserService - ok
15:04:01.0410 0x2fb0 ws2ifsl - ok
15:04:01.0410 0x2fb0 wscsvc - ok
15:04:01.0410 0x2fb0 WSDPrintDevice - ok
15:04:01.0425 0x2fb0 WSearch - ok
15:04:01.0441 0x2fb0 wuauserv - ok
15:04:01.0457 0x2fb0 WudfPf - ok
15:04:01.0457 0x2fb0 WUDFRd - ok
15:04:01.0472 0x2fb0 WUDFWpdFs - ok
15:04:01.0472 0x2fb0 WUDFWpdMtp - ok
15:04:01.0488 0x2fb0 WwanSvc - ok
15:04:01.0504 0x2fb0 xbgm - ok
15:04:01.0504 0x2fb0 XblAuthManager - ok
15:04:01.0519 0x2fb0 XblGameSave - ok
15:04:01.0519 0x2fb0 xboxgip - ok
15:04:01.0535 0x2fb0 XboxGipSvc - ok
15:04:01.0535 0x2fb0 XboxNetApiSvc - ok
15:04:01.0550 0x2fb0 xinputhid - ok
15:04:01.0550 0x2fb0 ================ Scan global ===============================
15:04:01.0629 0x2fb0 [ Global ] - ok
15:04:01.0629 0x2fb0 ================ Scan MBR ==================================
15:04:01.0644 0x2fb0 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
15:04:01.0894 0x2fb0 \Device\Harddisk0\DR0 - ok
15:04:01.0894 0x2fb0 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
15:04:01.0988 0x2fb0 \Device\Harddisk1\DR1 - ok
15:04:01.0988 0x2fb0 ================ Scan VBR ==================================
15:04:01.0988 0x2fb0 [ 1E5F014C57A0963D335C3350B1F5F863 ] \Device\Harddisk0\DR0\Partition1
15:04:01.0988 0x2fb0 \Device\Harddisk0\DR0\Partition1 - ok
15:04:01.0988 0x2fb0 [ 9423100D845A96F04C744B6038050D89 ] \Device\Harddisk0\DR0\Partition2
15:04:01.0988 0x2fb0 \Device\Harddisk0\DR0\Partition2 - ok
15:04:02.0004 0x2fb0 [ 07D8EEA610FFDFA425F3198ACF1F0363 ] \Device\Harddisk0\DR0\Partition3
15:04:02.0004 0x2fb0 \Device\Harddisk0\DR0\Partition3 - ok
15:04:02.0004 0x2fb0 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk1\DR1\Partition1
15:04:02.0004 0x2fb0 \Device\Harddisk1\DR1\Partition1 - ok
15:04:02.0019 0x2fb0 [ 62AD5CF25B2FC5631D9299C050EC3245 ] \Device\Harddisk1\DR1\Partition2
15:04:02.0019 0x2fb0 \Device\Harddisk1\DR1\Partition2 - ok
15:04:02.0035 0x2fb0 [ B57735446C15356DF119C660F5651EF8 ] \Device\Harddisk1\DR1\Partition3
15:04:02.0035 0x2fb0 \Device\Harddisk1\DR1\Partition3 - ok
15:04:02.0035 0x2fb0 ================ Scan generic autorun ======================
15:04:02.0082 0x2fb0 SecurityHealth - ok
15:04:02.0441 0x2fb0 [ 65E8545F1297CD83534C354A7BED1848, 19B3F3C17A335837454DC1851C6436D0BB2D8B1595AEB4DC71265FB20868B48F ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
15:04:02.0800 0x2fb0 RtHDVCpl - ok
15:04:02.0863 0x2fb0 OneDriveSetup - ok
15:04:02.0863 0x2fb0 OneDriveSetup - ok
15:04:02.0988 0x2fb0 [ A9620DF3B8AE68B0DD2881BF1805B86B, 1895C0A5B049CC2C9C9AC92AF103E1703379AD84766352E83F98A088B5A6612E ] C:\Users\daniel\AppData\Local\Microsoft\OneDrive\OneDrive.exe
15:04:03.0066 0x2fb0 OneDrive - ok
15:04:03.0066 0x2fb0 Waiting for KSN requests completion. In queue: 11
15:04:04.0113 0x2fb0 AV detected via SS2: Windows Defender, windowsdefender:// ( ), 0x61100 ( enabled : updated )
15:04:04.0207 0x2fb0 Win FW state via NFP2: enabled ( trusted )
15:04:04.0363 0x2fb0 ============================================================
15:04:04.0363 0x2fb0 Scan finished
15:04:04.0363 0x2fb0 ============================================================
15:04:04.0379 0x2fa0 Detected object count: 0
15:04:04.0379 0x2fa0 Actual detected object count: 0 |