krautsand | 30.10.2016 18:29 | Code:
18:20:35.0658 0x0344 TDSS rootkit removing tool 3.1.0.11 Aug 5 2016 12:13:31
18:20:35.0658 0x0344 UEFI system
18:20:39.0752 0x0344 ============================================================
18:20:39.0752 0x0344 Current date / time: 2016/10/30 18:20:39.0752
18:20:39.0752 0x0344 SystemInfo:
18:20:39.0752 0x0344
18:20:39.0752 0x0344 OS Version: 10.0.14393 ServicePack: 0.0
18:20:39.0752 0x0344 Product type: Workstation
18:20:39.0752 0x0344 ComputerName: WO
18:20:39.0752 0x0344 UserName: hannibla34
18:20:39.0752 0x0344 Windows directory: C:\WINDOWS
18:20:39.0752 0x0344 System windows directory: C:\WINDOWS
18:20:39.0752 0x0344 Running under WOW64
18:20:39.0752 0x0344 Processor architecture: Intel x64
18:20:39.0752 0x0344 Number of processors: 8
18:20:39.0752 0x0344 Page size: 0x1000
18:20:39.0752 0x0344 Boot type: Normal boot
18:20:39.0752 0x0344 CodeIntegrityOptions = 0x00000001
18:20:39.0752 0x0344 ============================================================
18:20:40.0174 0x0344 KLMD registered as C:\WINDOWS\system32\drivers\42561351.sys
18:20:40.0174 0x0344 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.351, osProperties = 0x19
18:20:40.0518 0x0344 System UUID: {3F8E22D3-6932-8A58-EF4E-56EC65BDDB2D}
18:20:41.0112 0x0344 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
18:20:41.0127 0x0344 Drive \Device\Harddisk1\DR1 - Size: 0x950B056000 ( 596.17 Gb ), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
18:20:46.0284 0x0344 ============================================================
18:20:46.0284 0x0344 \Device\Harddisk0\DR0:
18:20:46.0284 0x0344 GPT partitions:
18:20:46.0315 0x0344 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {A87557AB-C51B-4C81-A8FC-3238F1BE4911}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x190000
18:20:46.0315 0x0344 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {442E0D00-58E8-4B54-BEC3-3295F0F195A3}, Name: EFI system partition, StartLBA 0x190800, BlocksNum 0x82000
18:20:46.0315 0x0344 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {4B05466C-2242-4D97-AAC9-A12E5E0953B1}, Name: Microsoft reserved partition, StartLBA 0x212800, BlocksNum 0x40000
18:20:46.0315 0x0344 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {854EB602-EB6C-4F29-8747-355D62CA0D02}, Name: Basic data partition, StartLBA 0x252800, BlocksNum 0x12C00000
18:20:46.0315 0x0344 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {3E25A1E3-9C34-4CFB-866B-31769D6D5425}, Name: Basic data partition, StartLBA 0x12E52800, BlocksNum 0x5F96D800
18:20:46.0315 0x0344 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {6A62A54D-E3A4-441B-8B72-187100569643}, Name: Basic data partition, StartLBA 0x727C0000, BlocksNum 0x1F46800
18:20:46.0315 0x0344 MBR partitions:
18:20:46.0315 0x0344 \Device\Harddisk1\DR1:
18:20:46.0315 0x0344 MBR partitions:
18:20:46.0315 0x0344 \Device\Harddisk1\DR1\Partition1: MBR, Type 0xC, StartLBA 0x40, BlocksNum 0x4A856E81
18:20:46.0315 0x0344 ============================================================
18:20:46.0330 0x0344 C: <-> \Device\Harddisk0\DR0\Partition4
18:20:46.0346 0x0344 D: <-> \Device\Harddisk0\DR0\Partition5
18:20:46.0346 0x0344 M: <-> \Device\Harddisk1\DR1\Partition1
18:20:46.0346 0x0344 ============================================================
18:20:46.0346 0x0344 Initialize success
18:20:46.0346 0x0344 ============================================================
18:24:20.0739 0x23d8 ============================================================
18:24:20.0739 0x23d8 Scan started
18:24:20.0739 0x23d8 Mode: Manual; SigCheck; TDLFS;
18:24:20.0739 0x23d8 ============================================================
18:24:20.0739 0x23d8 KSN ping started
18:24:20.0864 0x23d8 KSN ping finished: true
18:24:22.0739 0x23d8 ================ Scan system memory ========================
18:24:22.0739 0x23d8 System memory - ok
18:24:22.0739 0x23d8 ================ Scan services =============================
18:24:22.0864 0x23d8 1394ohci - ok
18:24:22.0880 0x23d8 3ware - ok
18:24:22.0895 0x23d8 ACPI - ok
18:24:22.0911 0x23d8 AcpiDev - ok
18:24:22.0911 0x23d8 acpiex - ok
18:24:22.0927 0x23d8 acpipagr - ok
18:24:22.0958 0x23d8 AcpiPmi - ok
18:24:22.0958 0x23d8 acpitime - ok
18:24:23.0005 0x23d8 [ DC00FD73505DAEDD99CAF4533B0C05BD, 2863D1F0587B79254FBE093C191C73892768CF2AC59BEF97745EE66CEE3473AF ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
18:24:23.0067 0x23d8 AdobeARMservice - ok
18:24:23.0161 0x23d8 [ 16D11D2CA3F2078F553E0C3A70A4F050, 51EEA7EFBE122D3FEB2F8487F5A45166A0C4963314B28840C3C404479B4E1849 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
18:24:23.0208 0x23d8 AdobeFlashPlayerUpdateSvc - ok
18:24:23.0208 0x23d8 ADP80XX - ok
18:24:23.0208 0x23d8 AFD - ok
18:24:23.0223 0x23d8 ahcache - ok
18:24:23.0255 0x23d8 [ 2C37AD878725987DF1A31B3899CB7FD7, B9161DCD5374FA546C4E1D5FBD69788028BC60BA84E67DE7F49B0B7CDD12B097 ] AiChargerDT C:\WINDOWS\syswow64\drivers\AiChargerDT.sys
18:24:23.0302 0x23d8 AiChargerDT - ok
18:24:23.0317 0x23d8 AJRouter - ok
18:24:23.0333 0x23d8 ALG - ok
18:24:23.0333 0x23d8 AmdK8 - ok
18:24:23.0348 0x23d8 AmdPPM - ok
18:24:23.0348 0x23d8 amdsata - ok
18:24:23.0348 0x23d8 amdsbs - ok
18:24:23.0348 0x23d8 amdxata - ok
18:24:23.0380 0x23d8 [ 809D92855656EFC1D71C980582F7FF8B, 01B551CEC0CFD50CA88EB49AA3F68EEEAE34DFE31E6CA37DA106B3C49CF7FA81 ] AmUStor C:\WINDOWS\system32\drivers\AmUStor.SYS
18:24:23.0442 0x23d8 AmUStor - ok
18:24:23.0458 0x23d8 AppID - ok
18:24:23.0458 0x23d8 AppIDSvc - ok
18:24:23.0473 0x23d8 Appinfo - ok
18:24:23.0505 0x23d8 applockerfltr - ok
18:24:23.0520 0x23d8 AppReadiness - ok
18:24:23.0536 0x23d8 AppXSvc - ok
18:24:23.0552 0x23d8 arcsas - ok
18:24:23.0552 0x23d8 [ 798DE15F187C1F013095BBBEB6FB6197, 436CCAB6F62FA2D29827916E054ADE7ACAE485B3DE1D3E5C6C62D3DEBF1480E7 ] AsIO C:\WINDOWS\syswow64\drivers\AsIO.sys
18:24:23.0598 0x23d8 AsIO - ok
18:24:23.0630 0x23d8 [ 1392B92179B07B672720763D9B1028A5, B4D47EA790920A4531E3DF5A4B4B0721B7FEA6B49A35679F0652F1E590422602 ] AsUpIO C:\WINDOWS\syswow64\drivers\AsUpIO.sys
18:24:23.0661 0x23d8 AsUpIO - ok
18:24:23.0692 0x23d8 [ 9B480B472D6826E7257C90E2D0EE2954, C52C198602D180011A9345AE6F108EC4B1FD91234AF2E6296B2E39C1888B0D4D ] aswHwid C:\WINDOWS\system32\drivers\aswHwid.sys
18:24:23.0755 0x23d8 aswHwid - ok
18:24:23.0770 0x23d8 [ 06362BBA1347CBA0996F4B39BB1D8353, 0C6B7B085F13FB7C71E2AF481CD216C6ACB63577DC7E2793182F734378C141DA ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
18:24:23.0802 0x23d8 aswKbd - ok
18:24:23.0817 0x23d8 [ 1BB00571CC2C78463ABD7E9C32970758, BF523468754CB1628D66F28B06FAF7C545C5724801B04888517A2FB4BF9582BF ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys
18:24:23.0864 0x23d8 aswMonFlt - ok
18:24:23.0880 0x23d8 [ 7010B57D708DA5C9686A5923EE621776, 5A554B8941C156EC341C602F34679A7475802B19EE6A99AA29AE2628A123ECB1 ] aswRdr C:\WINDOWS\system32\drivers\aswRdr2.sys
18:24:23.0942 0x23d8 aswRdr - ok
18:24:23.0958 0x23d8 [ 937885085BFE5BD08EC1BC0245DD203B, 6DDD89245EEA3B8106C5F2EB6FA8CF525F3B42AA7032276DE78953E06FE7F4B4 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
18:24:24.0005 0x23d8 aswRvrt - ok
18:24:24.0067 0x23d8 [ 0B6352251C5D84130DF4252D33D266C2, C6A2E0074A7FCFB5799949431F5660B9AF6441001EA9B609F7B3900F4007EBD0 ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
18:24:24.0161 0x23d8 aswSnx - ok
18:24:24.0208 0x23d8 [ 28213B34725B18387CC1B8C3D73858A1, D86113D89C62F090B393B68B522581248AEF3568F8FD0FF86B3625F2E6DD4DB8 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
18:24:24.0255 0x23d8 aswSP - ok
18:24:24.0302 0x23d8 [ 9C58B6E9663D0A76D00D83E43C765BDF, 3F474932E77318CD450A3A9C89667D2B26A7E3FAB9AA95D97FF3B1979623A7F2 ] aswStm C:\WINDOWS\system32\drivers\aswStm.sys
18:24:24.0333 0x23d8 aswStm - ok
18:24:24.0364 0x23d8 [ E4ABC023E251D2BB6B98C9FCAF5CF16D, 2A94320A3EF16E641B693BF6EABABB57C891B914B00F73ACD7ADB8CA5089EC40 ] aswTap C:\WINDOWS\System32\drivers\aswTap.sys
18:24:24.0395 0x23d8 aswTap - ok
18:24:24.0442 0x23d8 [ D60D9201739400F0FBDB9E36A3212D91, 01A17516AB7F4D2C72E2DC51F7B49D1C4F50F564992F78A71E73821D7F8220E7 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
18:24:24.0505 0x23d8 aswVmm - ok
18:24:24.0520 0x23d8 AsyncMac - ok
18:24:24.0520 0x23d8 atapi - ok
18:24:24.0536 0x23d8 AudioEndpointBuilder - ok
18:24:24.0552 0x23d8 Audiosrv - ok
18:24:24.0630 0x23d8 [ F4E0580B5789474385E7ACB189C4AF2C, DB5BE2C852AC102AB8EB186362E582E250B843BA52B3B71AF08A5FDA8A6F91AF ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:24:24.0661 0x23d8 avast! Antivirus - ok
18:24:24.0692 0x23d8 [ 1B87A1F2FA5B91AC1A7D171B8D952441, 4CB21F6567021DAE6B2E35B9BA84D015580E2DDFEBEB1AA9637BD93F42883DD2 ] avgntflt C:\WINDOWS\system32\DRIVERS\avgntflt.sys
18:24:24.0739 0x23d8 avgntflt - ok
18:24:24.0755 0x23d8 [ AF61774060F277FE45CBD3A9A8E7D45A, 2F96DC9735BAF017603D72A258BF7A772BF8C4AFECB5AA0CAD8F8E3CCAA0F2B5 ] avipbb C:\WINDOWS\system32\DRIVERS\avipbb.sys
18:24:24.0786 0x23d8 avipbb - ok
18:24:24.0786 0x23d8 [ 390184FAD8FCC1B6DA25AEBAE928C3B6, 537B0E0FAE080B55D70E990BBA0F7F22903CA340F6A42039BAD617A8ECF59119 ] avkmgr C:\WINDOWS\system32\DRIVERS\avkmgr.sys
18:24:24.0802 0x23d8 avkmgr - ok
18:24:24.0802 0x23d8 AxInstSV - ok
18:24:24.0817 0x23d8 b06bdrv - ok
18:24:24.0817 0x23d8 BasicDisplay - ok
18:24:24.0817 0x23d8 BasicRender - ok
18:24:24.0833 0x23d8 bcmfn - ok
18:24:24.0833 0x23d8 bcmfn2 - ok
18:24:24.0833 0x23d8 BDESVC - ok
18:24:24.0848 0x23d8 Beep - ok
18:24:24.0848 0x23d8 BFE - ok
18:24:24.0864 0x23d8 BITS - ok
18:24:24.0864 0x23d8 bowser - ok
18:24:24.0880 0x23d8 BrokerInfrastructure - ok
18:24:24.0880 0x23d8 Browser - ok
18:24:24.0895 0x23d8 BthAvrcpTg - ok
18:24:24.0895 0x23d8 BthHFEnum - ok
18:24:24.0895 0x23d8 bthhfhid - ok
18:24:24.0911 0x23d8 BthHFSrv - ok
18:24:24.0911 0x23d8 BTHMODEM - ok
18:24:24.0911 0x23d8 bthserv - ok
18:24:24.0911 0x23d8 buttonconverter - ok
18:24:24.0927 0x23d8 [ 60EB6A4CE3E21887D302350631C16F26, 4270EFA22285C1A9336CF1220761E416950D2DA9C6A40D1D8452686CD5040DAB ] CapImg C:\WINDOWS\System32\drivers\capimg.sys
18:24:25.0083 0x23d8 CapImg - ok
18:24:25.0083 0x23d8 cdfs - ok
18:24:25.0083 0x23d8 CDPSvc - ok
18:24:25.0099 0x23d8 CDPUserSvc - ok
18:24:25.0145 0x23d8 cdrom - ok
18:24:25.0145 0x23d8 CertPropSvc - ok
18:24:25.0161 0x23d8 cht4iscsi - ok
18:24:25.0161 0x23d8 cht4vbd - ok
18:24:25.0177 0x23d8 circlass - ok
18:24:25.0177 0x23d8 CLFS - ok
18:24:25.0177 0x23d8 ClipSVC - ok
18:24:25.0177 0x23d8 clreg - ok
18:24:25.0192 0x23d8 CmBatt - ok
18:24:25.0192 0x23d8 CNG - ok
18:24:25.0192 0x23d8 cnghwassist - ok
18:24:25.0224 0x23d8 CompositeBus - ok
18:24:25.0224 0x23d8 COMSysApp - ok
18:24:25.0224 0x23d8 condrv - ok
18:24:25.0255 0x23d8 CoreMessagingRegistrar - ok
18:24:25.0255 0x23d8 CryptSvc - ok
18:24:25.0255 0x23d8 dam - ok
18:24:25.0270 0x23d8 DcomLaunch - ok
18:24:25.0286 0x23d8 DcpSvc - ok
18:24:25.0286 0x23d8 defragsvc - ok
18:24:25.0302 0x23d8 DeviceAssociationService - ok
18:24:25.0302 0x23d8 DeviceInstall - ok
18:24:25.0302 0x23d8 DevQueryBroker - ok
18:24:25.0317 0x23d8 Dfsc - ok
18:24:25.0333 0x23d8 [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
18:24:25.0380 0x23d8 dg_ssudbus - ok
18:24:25.0411 0x23d8 Dhcp - ok
18:24:25.0442 0x23d8 diagnosticshub.standardcollector.service - ok
18:24:25.0458 0x23d8 DiagTrack - ok
18:24:25.0474 0x23d8 disk - ok
18:24:25.0489 0x23d8 DmEnrollmentSvc - ok
18:24:25.0505 0x23d8 dmvsc - ok
18:24:25.0520 0x23d8 dmwappushservice - ok
18:24:25.0520 0x23d8 Dnscache - ok
18:24:25.0536 0x23d8 dot3svc - ok
18:24:25.0536 0x23d8 DPS - ok
18:24:25.0552 0x23d8 drmkaud - ok
18:24:25.0567 0x23d8 DsmSvc - ok
18:24:25.0567 0x23d8 DsSvc - ok
18:24:25.0583 0x23d8 DXGKrnl - ok
18:24:25.0614 0x23d8 [ 160044DF3554871C42F25DA6EC9017F2, 2E135BB1922C033FBA389635EAEC84E698736096FE93438EF005CD5DD23F7793 ] e1dexpress C:\WINDOWS\system32\DRIVERS\e1d65x64.sys
18:24:25.0708 0x23d8 e1dexpress - ok
18:24:25.0724 0x23d8 e1iexpress - ok
18:24:25.0739 0x23d8 EapHost - ok
18:24:25.0739 0x23d8 ebdrv - ok
18:24:25.0770 0x23d8 EFS - ok
18:24:25.0770 0x23d8 EhStorClass - ok
18:24:25.0786 0x23d8 EhStorTcgDrv - ok
18:24:25.0786 0x23d8 embeddedmode - ok
18:24:25.0802 0x23d8 EntAppSvc - ok
18:24:25.0802 0x23d8 ErrDev - ok
18:24:25.0817 0x23d8 EventSystem - ok
18:24:25.0817 0x23d8 exfat - ok
18:24:25.0817 0x23d8 fastfat - ok
18:24:25.0833 0x23d8 Fax - ok
18:24:25.0833 0x23d8 fdc - ok
18:24:25.0833 0x23d8 fdPHost - ok
18:24:25.0833 0x23d8 FDResPub - ok
18:24:25.0849 0x23d8 fhsvc - ok
18:24:25.0849 0x23d8 FileCrypt - ok
18:24:25.0864 0x23d8 FileInfo - ok
18:24:25.0864 0x23d8 Filetrace - ok
18:24:25.0864 0x23d8 flpydisk - ok
18:24:25.0864 0x23d8 FltMgr - ok
18:24:25.0880 0x23d8 FontCache - ok
18:24:25.0942 0x23d8 FontCache3.0.0.0 - ok
18:24:26.0083 0x23d8 FrameServer - ok
18:24:26.0099 0x23d8 FsDepends - ok
18:24:26.0114 0x23d8 Fs_Rec - ok
18:24:26.0130 0x23d8 fvevol - ok
18:24:26.0145 0x23d8 gencounter - ok
18:24:26.0145 0x23d8 genericusbfn - ok
18:24:26.0255 0x23d8 [ F78BC07DCED5EDDD6D477E923620F8EA, ABE28155100A38A5E1B58FFC8099EF416145278B440A67B8DAFD7715FE412624 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
18:24:26.0302 0x23d8 GfExperienceService - ok
18:24:26.0317 0x23d8 GPIOClx0101 - ok
18:24:26.0317 0x23d8 gpsvc - ok
18:24:26.0333 0x23d8 GpuEnergyDrv - ok
18:24:26.0395 0x23d8 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:24:26.0427 0x23d8 gupdate - ok
18:24:26.0427 0x23d8 [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
18:24:26.0442 0x23d8 gupdatem - ok
18:24:26.0442 0x23d8 HDAudBus - ok
18:24:26.0458 0x23d8 HidBatt - ok
18:24:26.0458 0x23d8 HidBth - ok
18:24:26.0458 0x23d8 hidi2c - ok
18:24:26.0458 0x23d8 hidinterrupt - ok
18:24:26.0458 0x23d8 HidIr - ok
18:24:26.0474 0x23d8 hidserv - ok
18:24:26.0505 0x23d8 HidUsb - ok
18:24:26.0520 0x23d8 HomeGroupListener - ok
18:24:26.0520 0x23d8 HomeGroupProvider - ok
18:24:26.0536 0x23d8 HpSAMD - ok
18:24:26.0552 0x23d8 HTTP - ok
18:24:26.0567 0x23d8 [ 5004E766075BADA25608489A7C649698, 685D6F5B99C06EF091BB126CA3FEADCA3ED3C05DD78B6709AF04A1DD0A030BAE ] huawei_cdcacm C:\WINDOWS\system32\DRIVERS\ew_jucdcacm.sys
18:24:26.0724 0x23d8 huawei_cdcacm - ok
18:24:26.0755 0x23d8 [ D49D4E7B70AD6B1D04771AC1F7DB79C7, 093D8343CF769FC805308ED357EEF30E3D78569B817A20FE9884863A1FDBC028 ] huawei_enumerator C:\WINDOWS\System32\drivers\ew_jubusenum.sys
18:24:26.0833 0x23d8 huawei_enumerator - ok
18:24:26.0864 0x23d8 [ 25002C5DF71CF206569A408B3E0E523C, 49E0938FAFBA828D70DA183B96D2F52A2330A0E59510FC282821C3AD2A42EE46 ] huawei_wwanecm C:\WINDOWS\system32\DRIVERS\ew_juwwanecm.sys
18:24:26.0942 0x23d8 huawei_wwanecm - ok
18:24:26.0958 0x23d8 HvHost - ok
18:24:26.0958 0x23d8 hvservice - ok
18:24:27.0020 0x23d8 [ C08814014290BF3AD581C0E9C5919269, 9C16822AC6B8977AAEFDB54C2B4295546461DD888060B62223EF20151790C934 ] HWDeviceService64.exe C:\ProgramData\DatacardService\HWDeviceService64.exe
18:24:27.0083 0x23d8 HWDeviceService64.exe - ok
18:24:27.0161 0x23d8 [ EF558A02D734A1403583E95CCEEC2487, F0D052DAF48A62E4A90D067BFCB5EE9563804DE68D0EA82E0E11C8D16AD19D29 ] HWiNFO32 C:\WINDOWS\SysWoW64\drivers\HWiNFO64A.SYS
18:24:27.0192 0x23d8 HWiNFO32 - ok
18:24:27.0208 0x23d8 hwpolicy - ok
18:24:27.0208 0x23d8 hyperkbd - ok
18:24:27.0224 0x23d8 i8042prt - ok
18:24:27.0224 0x23d8 iagpio - ok
18:24:27.0224 0x23d8 iai2c - ok
18:24:27.0224 0x23d8 iaLPSS2i_GPIO2 - ok
18:24:27.0239 0x23d8 iaLPSS2i_I2C - ok
18:24:27.0239 0x23d8 iaLPSSi_GPIO - ok
18:24:27.0239 0x23d8 iaLPSSi_I2C - ok
18:24:27.0317 0x23d8 [ 0609694A9C4D6C71319732FA82C6E5C5, 5507D20AB9C86B11564C953C6F535976A0D201295C642EA0CABF435DAD908251 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
18:24:27.0364 0x23d8 iaStorA - ok
18:24:27.0364 0x23d8 iaStorAV - ok
18:24:27.0411 0x23d8 [ 20E83F4632E15A5E9E716FF2E8AC7FAE, 7CA1A4924F432AD30ED7FA6247C6513DA173EE31132AE115E85C0ED7E5971029 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
18:24:27.0427 0x23d8 IAStorDataMgrSvc - ok
18:24:27.0427 0x23d8 iaStorV - ok
18:24:27.0442 0x23d8 ibbus - ok
18:24:27.0458 0x23d8 icssvc - ok
18:24:27.0458 0x23d8 IKEEXT - ok
18:24:27.0458 0x23d8 IndirectKmd - ok
18:24:27.0614 0x23d8 [ 3691A0F19490641A5250919420BF88E9, 70CCE10AB4CEF700292D0F85029FCD2C5D1B0E9010A4CF318F40D763BF3BF36A ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
18:24:27.0770 0x23d8 IntcAzAudAddService - ok
18:24:27.0849 0x23d8 [ 0DB1E3F6189C628675F855C0EB510419, 989F539E82105019D2D81255369B96DC65826CD2A421DA09809155B26F69C555 ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
18:24:27.0927 0x23d8 Intel(R) Capability Licensing Service Interface - detected UnsignedFile.Multi.Generic ( 1 )
18:24:28.0052 0x23d8 Detect skipped due to KSN trusted
18:24:28.0052 0x23d8 Intel(R) Capability Licensing Service Interface - ok
18:24:28.0114 0x23d8 [ 492AAF2FF66F437F0E796574B116EFC3, 6BF21C61ED05705DD58203952A750D1AB4D4B62F3A2B640BBBD9B85D1ECC3E5C ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
18:24:28.0145 0x23d8 Intel(R) Capability Licensing Service TCP IP Interface - ok
18:24:28.0161 0x23d8 [ CBF7341E55A8348C7AB01A9870C7D948, A5084DF3C6321788C88A9E6B5F43FE5BCFDBB579BDE3A4D5F55558C6D13035A5 ] Intel(R) PROSet Monitoring Service C:\Windows\system32\IProsetMonitor.exe
18:24:28.0677 0x23d8 Intel(R) PROSet Monitoring Service - ok
18:24:28.0708 0x23d8 intelide - ok
18:24:28.0708 0x23d8 intelpep - ok
18:24:28.0708 0x23d8 intelppm - ok
18:24:28.0802 0x23d8 [ 477BE2027FB0E5F50A6CD424BFDB3BAA, B9311F9F9685D13FA83B1E168EB6D3555ABAA8C402B4C47EB2629BA6F11444E8 ] Internet Manager. RunOuc C:\Program Files (x86)\T-Mobile\InternetManager_H\UpdateDog\ouc.exe
18:24:28.0849 0x23d8 Internet Manager. RunOuc - ok
18:24:28.0849 0x23d8 iorate - ok
18:24:28.0864 0x23d8 IpFilterDriver - ok
18:24:28.0880 0x23d8 iphlpsvc - ok
18:24:28.0880 0x23d8 IPMIDRV - ok
18:24:28.0880 0x23d8 IPNAT - ok
18:24:28.0880 0x23d8 irda - ok
18:24:28.0880 0x23d8 IRENUM - ok
18:24:28.0880 0x23d8 irmon - ok
18:24:28.0880 0x23d8 isapnp - ok
18:24:28.0895 0x23d8 iScsiPrt - ok
18:24:28.0895 0x23d8 kbdclass - ok
18:24:28.0895 0x23d8 kbdhid - ok
18:24:28.0895 0x23d8 kdnic - ok
18:24:28.0927 0x23d8 KeyIso - ok
18:24:28.0942 0x23d8 KSecDD - ok
18:24:28.0942 0x23d8 KSecPkg - ok
18:24:28.0942 0x23d8 ksthunk - ok
18:24:28.0942 0x23d8 KtmRm - ok
18:24:28.0958 0x23d8 LanmanServer - ok
18:24:28.0958 0x23d8 LanmanWorkstation - ok
18:24:28.0958 0x23d8 lfsvc - ok
18:24:28.0958 0x23d8 LicenseManager - ok
18:24:28.0974 0x23d8 lltdio - ok
18:24:28.0974 0x23d8 lltdsvc - ok
18:24:28.0974 0x23d8 lmhosts - ok
18:24:28.0974 0x23d8 LSI_SAS - ok
18:24:28.0989 0x23d8 LSI_SAS2i - ok
18:24:28.0989 0x23d8 LSI_SAS3i - ok
18:24:29.0005 0x23d8 LSI_SSS - ok
18:24:29.0005 0x23d8 LSM - ok
18:24:29.0005 0x23d8 luafv - ok
18:24:29.0021 0x23d8 MapsBroker - ok
18:24:29.0021 0x23d8 megasas - ok
18:24:29.0036 0x23d8 megasas2i - ok
18:24:29.0036 0x23d8 megasr - ok
18:24:29.0052 0x23d8 [ 1039E2C190060B1A51289B47493DA456, 96B67CD5341F6118063F1C318DDAC86089966E274FEB4EC46F934BBE98C01032 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
18:24:29.0067 0x23d8 MEIx64 - ok
18:24:29.0083 0x23d8 [ 1595FECFFBE9EA2417E06D5FD0BFA4C4, 96006C7F19FDC1700EEBA870F96433D3260DEA06AD7215EAD8F1D74C953E1B50 ] MEMSWEEP2 C:\Windows\system32\2284.tmp
18:24:29.0114 0x23d8 MEMSWEEP2 - detected UnsignedFile.Multi.Generic ( 1 )
18:24:29.0239 0x23d8 Detect skipped due to KSN trusted
18:24:29.0239 0x23d8 MEMSWEEP2 - ok
18:24:29.0255 0x23d8 MessagingService - ok
18:24:29.0286 0x23d8 mlx4_bus - ok
18:24:29.0286 0x23d8 MMCSS - ok
18:24:29.0302 0x23d8 Modem - ok
18:24:29.0317 0x23d8 monitor - ok
18:24:29.0317 0x23d8 mouclass - ok
18:24:29.0317 0x23d8 mouhid - ok
18:24:29.0317 0x23d8 mountmgr - ok
18:24:29.0333 0x23d8 [ 572BD5A99648652147A5D3C6DA946C99, FFDAD4A5682864977C926A5DDDB632CDB2A166BF025757801CC56F2828720023 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
18:24:29.0349 0x23d8 MozillaMaintenance - ok
18:24:29.0349 0x23d8 mpsdrv - ok
18:24:29.0349 0x23d8 MpsSvc - ok
18:24:29.0364 0x23d8 MRxDAV - ok
18:24:29.0364 0x23d8 mrxsmb - ok
18:24:29.0380 0x23d8 mrxsmb10 - ok
18:24:29.0380 0x23d8 mrxsmb20 - ok
18:24:29.0396 0x23d8 MsBridge - ok
18:24:29.0411 0x23d8 MSDTC - ok
18:24:29.0427 0x23d8 Msfs - ok
18:24:29.0427 0x23d8 msgpiowin32 - ok
18:24:29.0427 0x23d8 mshidkmdf - ok
18:24:29.0427 0x23d8 mshidumdf - ok
18:24:29.0427 0x23d8 msisadrv - ok
18:24:29.0442 0x23d8 MSiSCSI - ok
18:24:29.0442 0x23d8 msiserver - ok
18:24:29.0458 0x23d8 MSKSSRV - ok
18:24:29.0458 0x23d8 MsLldp - ok
18:24:29.0458 0x23d8 MSPCLOCK - ok
18:24:29.0458 0x23d8 MSPQM - ok
18:24:29.0458 0x23d8 MsRPC - ok
18:24:29.0474 0x23d8 mssmbios - ok
18:24:29.0474 0x23d8 MSTEE - ok
18:24:29.0474 0x23d8 MTConfig - ok
18:24:29.0489 0x23d8 Mup - ok
18:24:29.0489 0x23d8 mvumis - ok
18:24:29.0489 0x23d8 NativeWifiP - ok
18:24:29.0489 0x23d8 NcaSvc - ok
18:24:29.0489 0x23d8 NcbService - ok
18:24:29.0489 0x23d8 NcdAutoSetup - ok
18:24:29.0489 0x23d8 ndfltr - ok
18:24:29.0505 0x23d8 NDIS - ok
18:24:29.0521 0x23d8 NdisCap - ok
18:24:29.0521 0x23d8 NdisImPlatform - ok
18:24:29.0521 0x23d8 NdisTapi - ok
18:24:29.0521 0x23d8 Ndisuio - ok
18:24:29.0521 0x23d8 NdisVirtualBus - ok
18:24:29.0521 0x23d8 NdisWan - ok
18:24:29.0521 0x23d8 ndiswanlegacy - ok
18:24:29.0521 0x23d8 ndproxy - ok
18:24:29.0536 0x23d8 Ndu - ok
18:24:29.0536 0x23d8 NetAdapterCx - ok
18:24:29.0536 0x23d8 NetBIOS - ok
18:24:29.0536 0x23d8 NetBT - ok
18:24:29.0536 0x23d8 Netlogon - ok
18:24:29.0536 0x23d8 Netman - ok
18:24:29.0552 0x23d8 netprofm - ok
18:24:29.0552 0x23d8 NetSetupSvc - ok
18:24:29.0599 0x23d8 NetTcpPortSharing - ok
18:24:29.0614 0x23d8 NgcCtnrSvc - ok
18:24:29.0630 0x23d8 NgcSvc - ok
18:24:29.0646 0x23d8 NlaSvc - ok
18:24:29.0646 0x23d8 Npfs - ok
18:24:29.0646 0x23d8 npsvctrig - ok
18:24:29.0661 0x23d8 nsi - ok
18:24:29.0661 0x23d8 nsiproxy - ok
18:24:29.0661 0x23d8 NTFS - ok
18:24:29.0677 0x23d8 Null - ok
18:24:29.0692 0x23d8 [ 417F5789073BE7B3DE45C308F3C527DF, 5137D7451D8D58BF5D7FFDF83F8C72CAAB05AFE237318FC4E1AE06F4FFE5CBFD ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
18:24:29.0708 0x23d8 NVHDA - ok
18:24:30.0083 0x23d8 [ DB3FFDB8FB4D08E834B54B858D50DDBE, 3D6437E72FF96BACE0EC1C19C227800E3A6A89239630D71E1D46E0B3AA6CE40C ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d3851cb7c8216f9e\nvlddmkm.sys
18:24:30.0380 0x23d8 nvlddmkm - ok
18:24:30.0505 0x23d8 [ 020F45E362D3B57CCC5735582BB1A6EC, E2D953CEF208528382153D06FED8394BEB52657C547E4D2D2954E537C9A382DC ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
18:24:30.0599 0x23d8 NvNetworkService - ok
18:24:30.0599 0x23d8 nvraid - ok
18:24:30.0599 0x23d8 nvstor - ok
18:24:30.0661 0x23d8 [ F82BCEB9F57B2959F6AAE2A3DDA892A8, 5B02C74BAF0E12B84F239B1449DAA955B28BD5BA7D35D315DB57F45E042E0DB3 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
18:24:30.0708 0x23d8 NvStreamKms - ok
18:24:30.0849 0x23d8 [ 9209D57C1AA24841EF8D5DE6A5B2AAEB, C1A53621F5361DCE9C962A9B9B586D1904901C9EC20EFCA76C40ADCD98BEDF3C ] NvStreamNetworkSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
18:24:30.0927 0x23d8 NvStreamNetworkSvc - ok
18:24:31.0005 0x23d8 [ 0EDF9504CA5174075BA5902AFC1F57C8, 8E210E71BA91813D3BB6B59E5F6AD0889711336AD12B1B1C67CCC882A6ED3E53 ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
18:24:31.0083 0x23d8 NvStreamSvc - ok
18:24:31.0114 0x23d8 [ 403522070F1C1020B9EB862ED989CD87, 01A63D0DA8B47DDE9D2FCF5923529FCA5ABF4154CFFA6D0E10087E3CA5477436 ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
18:24:31.0442 0x23d8 nvsvc - ok
18:24:31.0474 0x23d8 [ 38175904276F86EA4704EC13B77FB4B0, 4965BCF17E3D9EE4CE2E4DC158C5E7179C3ABBAE9D640FBCFFBCA973F21DDDF6 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
18:24:31.0521 0x23d8 nvvad_WaveExtensible - ok
18:24:31.0536 0x23d8 OneSyncSvc - ok
18:24:31.0567 0x23d8 p2pimsvc - ok
18:24:31.0583 0x23d8 p2psvc - ok
18:24:31.0583 0x23d8 Parport - ok
18:24:31.0599 0x23d8 partmgr - ok
18:24:31.0614 0x23d8 PcaSvc - ok
18:24:31.0661 0x23d8 [ 101CC1FD8D48ED1EF71F0840158D0E6D, A944D70DE230E3FBD8B371EF3BED1FCD12AAFD56945A8F5C44994AF13283FCCD ] pci C:\WINDOWS\system32\drivers\pci.sys
18:24:31.0739 0x23d8 pci - ok
18:24:31.0755 0x23d8 pciide - ok
18:24:31.0771 0x23d8 pcmcia - ok
18:24:31.0771 0x23d8 pcw - ok
18:24:31.0786 0x23d8 pdc - ok
18:24:31.0786 0x23d8 PEAUTH - ok
18:24:31.0786 0x23d8 percsas2i - ok
18:24:31.0802 0x23d8 percsas3i - ok
18:24:31.0833 0x23d8 PerfHost - ok
18:24:31.0864 0x23d8 PhoneSvc - ok
18:24:31.0880 0x23d8 PimIndexMaintenanceSvc - ok
18:24:31.0911 0x23d8 pla - ok
18:24:31.0911 0x23d8 PlugPlay - ok
18:24:31.0911 0x23d8 PNRPAutoReg - ok
18:24:31.0911 0x23d8 PNRPsvc - ok
18:24:31.0927 0x23d8 PolicyAgent - ok
18:24:31.0927 0x23d8 Power - ok
18:24:31.0927 0x23d8 PptpMiniport - ok
18:24:32.0052 0x23d8 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
18:24:32.0317 0x23d8 PrintNotify - ok
18:24:32.0317 0x23d8 Processor - ok
18:24:32.0333 0x23d8 ProfSvc - ok
18:24:32.0333 0x23d8 Psched - ok
18:24:32.0349 0x23d8 QWAVE - ok
18:24:32.0349 0x23d8 QWAVEdrv - ok
18:24:32.0364 0x23d8 RasAcd - ok
18:24:32.0364 0x23d8 RasAgileVpn - ok
18:24:32.0364 0x23d8 RasAuto - ok
18:24:32.0364 0x23d8 Rasl2tp - ok
18:24:32.0364 0x23d8 RasMan - ok
18:24:32.0380 0x23d8 RasPppoe - ok
18:24:32.0380 0x23d8 RasSstp - ok
18:24:32.0380 0x23d8 rdbss - ok
18:24:32.0396 0x23d8 rdpbus - ok
18:24:32.0396 0x23d8 RDPDR - ok
18:24:32.0411 0x23d8 RdpVideoMiniport - ok
18:24:32.0411 0x23d8 rdyboost - ok
18:24:32.0411 0x23d8 ReFSv1 - ok
18:24:32.0427 0x23d8 RemoteAccess - ok
18:24:32.0427 0x23d8 RemoteRegistry - ok
18:24:32.0442 0x23d8 RetailDemo - ok
18:24:32.0442 0x23d8 RmSvc - ok
18:24:32.0442 0x23d8 RpcEptMapper - ok
18:24:32.0442 0x23d8 RpcLocator - ok
18:24:32.0442 0x23d8 RpcSs - ok
18:24:32.0442 0x23d8 rspndr - ok
18:24:32.0458 0x23d8 s3cap - ok
18:24:32.0474 0x23d8 SamSs - ok
18:24:32.0536 0x23d8 [ 6D6E490C65D2E222BF51B02D45C1C26A, 2780D239823C14BC42965E8E0034E98F300AEF222B09F02BC00DDA527A86E666 ] Samsung Network Fax Server C:\WINDOWS\system32\spool\drivers\x64\3\NetFaxServer64.exe
18:24:32.0599 0x23d8 Samsung Network Fax Server - ok
18:24:32.0599 0x23d8 Samsung Printer Dianostics Service - ok
18:24:32.0614 0x23d8 [ CCFCF96CB350DA48AFDCB221CA999ADA, 7E5490652E367D1EA0400ED95788AFB4E067373E5F8BF73165B7F7FDE20D1B27 ] SamsungUPDUtilSvc C:\WINDOWS\SysWoW64\SecUPDUtilSvc.exe
18:24:33.0333 0x23d8 SamsungUPDUtilSvc - ok
18:24:33.0364 0x23d8 sbp2port - ok
18:24:33.0380 0x23d8 SCardSvr - ok
18:24:33.0396 0x23d8 ScDeviceEnum - ok
18:24:33.0411 0x23d8 scfilter - ok
18:24:33.0411 0x23d8 Schedule - ok
18:24:33.0427 0x23d8 scmbus - ok
18:24:33.0427 0x23d8 scmdisk0101 - ok
18:24:33.0442 0x23d8 SCPolicySvc - ok
18:24:33.0458 0x23d8 sdbus - ok
18:24:33.0458 0x23d8 SDRSVC - ok
18:24:33.0458 0x23d8 sdstor - ok
18:24:33.0458 0x23d8 seclogon - ok
18:24:33.0489 0x23d8 [ 07F83829E7429E60298440CD1E601A6A, 9F1229CD8DD9092C27A01F5D56E3C0D59C2BB9F0139ABF042E56F343637FDA33 ] semav6msr64 C:\WINDOWS\system32\drivers\semav6msr64.sys
18:24:33.0521 0x23d8 semav6msr64 - ok
18:24:33.0521 0x23d8 SENS - ok
18:24:33.0552 0x23d8 SensorDataService - ok
18:24:33.0567 0x23d8 SensorService - ok
18:24:33.0583 0x23d8 SensrSvc - ok
18:24:33.0583 0x23d8 SerCx - ok
18:24:33.0583 0x23d8 SerCx2 - ok
18:24:33.0599 0x23d8 Serenum - ok
18:24:33.0599 0x23d8 Serial - ok
18:24:33.0614 0x23d8 sermouse - ok
18:24:33.0614 0x23d8 SessionEnv - ok
18:24:33.0630 0x23d8 sfloppy - ok
18:24:33.0630 0x23d8 SharedAccess - ok
18:24:33.0646 0x23d8 ShellHWDetection - ok
18:24:33.0646 0x23d8 shpamsvc - ok
18:24:33.0661 0x23d8 SiSRaid2 - ok
18:24:33.0661 0x23d8 SiSRaid4 - ok
18:24:33.0677 0x23d8 [ 4C51055DA5FF23500EA6FE587EBE26E6, AD2B90FBE4B7989E7715BC566DDE012DE65C1173392232E039A4AAD368AF5075 ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
18:24:33.0708 0x23d8 SmbDrvI - ok
18:24:33.0739 0x23d8 smphost - ok
18:24:33.0739 0x23d8 SmsRouter - ok
18:24:33.0771 0x23d8 SNMPTRAP - ok
18:24:33.0802 0x23d8 [ C994DF90427103CCB80F893FFD2B1CE8, 7E4B08095C77E68D337A3425EEA38F8FEC4D103CA7661E34FD96BF518DFB4BCB ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
18:24:33.0880 0x23d8 spaceport - ok
18:24:33.0880 0x23d8 SpbCx - ok
18:24:33.0927 0x23d8 Spooler - ok
18:24:33.0942 0x23d8 sppsvc - ok
18:24:33.0958 0x23d8 srv - ok
18:24:33.0974 0x23d8 srv2 - ok
18:24:33.0974 0x23d8 srvnet - ok
18:24:33.0989 0x23d8 SSDPSRV - ok
18:24:34.0021 0x23d8 [ 0211AB46B73A2623B86C1CFCB30579AB, 7CC9BA2DF7B9EA6BB17EE342898EDD7F54703B93B6DED6A819E83A7EE9F938B4 ] SSPORT C:\Windows\system32\Drivers\SSPORT.sys
18:24:34.0067 0x23d8 SSPORT - ok
18:24:34.0083 0x23d8 SstpSvc - ok
18:24:34.0099 0x23d8 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
18:24:34.0161 0x23d8 ssudmdm - ok
18:24:34.0192 0x23d8 StateRepository - ok
18:24:34.0286 0x23d8 [ 8AD39F3C6C0ACD29D875905C5F20E6DA, 414053EFA8F4730F5ABB25C5ECA10695A04087471754A22F6B25EED9955A3B09 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
18:24:34.0333 0x23d8 Stereo Service - ok
18:24:34.0333 0x23d8 stexstor - ok
18:24:34.0333 0x23d8 stisvc - ok
18:24:34.0364 0x23d8 [ 53EB8CE34B55A1EE63424C8DB7388BFC, 5AB59117BA8A2844EB8693CCC19B217AE039B28C87519F96E1C845FE9BF456C2 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
18:24:34.0411 0x23d8 storahci - ok
18:24:34.0427 0x23d8 storflt - ok
18:24:34.0442 0x23d8 [ B66D8C75C9BC59D637177AB3B1C569A6, 76252A631F03EEBF5FDC7693F6B0A5E73838CDBE3157114CC96B8BBE88B476BF ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys
18:24:34.0489 0x23d8 stornvme - ok
18:24:34.0489 0x23d8 storqosflt - ok
18:24:34.0521 0x23d8 StorSvc - ok
18:24:34.0521 0x23d8 storufs - ok
18:24:34.0521 0x23d8 storvsc - ok
18:24:34.0521 0x23d8 svsvc - ok
18:24:34.0536 0x23d8 swenum - ok
18:24:34.0536 0x23d8 swprv - ok
18:24:34.0552 0x23d8 Synth3dVsc - ok
18:24:34.0567 0x23d8 SysMain - ok
18:24:34.0583 0x23d8 SystemEventsBroker - ok
18:24:34.0599 0x23d8 [ 2BE3A44B764D6C43CBF4650E862CB807, 78920DA47F3A0C26503FB62EF159455A860E57A9A39C72AEE23A9324168EC1D2 ] SystemUsageReportSvc_WILLAMETTE C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe
18:24:34.0614 0x23d8 SystemUsageReportSvc_WILLAMETTE - ok
18:24:34.0614 0x23d8 TabletInputService - ok
18:24:34.0630 0x23d8 TapiSrv - ok
18:24:34.0630 0x23d8 Tcpip - ok
18:24:34.0630 0x23d8 Tcpip6 - ok
18:24:34.0646 0x23d8 tcpipreg - ok
18:24:34.0661 0x23d8 tdx - ok
18:24:34.0661 0x23d8 terminpt - ok
18:24:34.0661 0x23d8 TermService - ok
18:24:34.0661 0x23d8 Themes - ok
18:24:34.0677 0x23d8 TieringEngineService - ok
18:24:34.0677 0x23d8 tiledatamodelsvc - ok
18:24:34.0677 0x23d8 TimeBrokerSvc - ok
18:24:34.0708 0x23d8 [ 3D04046C468AD2868A093925B5E2AA0A, 44696259BEF49AC200DEE146DE0E4375B0CD09F9356CCFA22BD7AD8B53E48658 ] TPM C:\WINDOWS\System32\drivers\tpm.sys
18:24:34.0771 0x23d8 TPM - ok
18:24:34.0771 0x23d8 TrkWks - ok
18:24:34.0786 0x23d8 TrustedInstaller - ok
18:24:34.0786 0x23d8 tsusbflt - ok
18:24:34.0802 0x23d8 TsUsbGD - ok
18:24:34.0802 0x23d8 tunnel - ok
18:24:34.0833 0x23d8 tzautoupdate - ok
18:24:34.0833 0x23d8 UASPStor - ok
18:24:34.0833 0x23d8 UcmCx0101 - ok
18:24:34.0833 0x23d8 UcmTcpciCx0101 - ok
18:24:34.0833 0x23d8 UcmUcsi - ok
18:24:34.0849 0x23d8 Ucx01000 - ok
18:24:34.0849 0x23d8 UdeCx - ok
18:24:34.0849 0x23d8 udfs - ok
18:24:34.0849 0x23d8 UEFI - ok
18:24:34.0849 0x23d8 Ufx01000 - ok
18:24:34.0864 0x23d8 UfxChipidea - ok
18:24:34.0864 0x23d8 ufxsynopsys - ok
18:24:34.0864 0x23d8 UI0Detect - ok
18:24:34.0864 0x23d8 umbus - ok
18:24:34.0864 0x23d8 UmPass - ok
18:24:34.0880 0x23d8 UmRdpService - ok
18:24:34.0880 0x23d8 UnistoreSvc - ok
18:24:34.0880 0x23d8 upnphost - ok
18:24:34.0880 0x23d8 UrsChipidea - ok
18:24:34.0880 0x23d8 UrsCx01000 - ok
18:24:34.0896 0x23d8 UrsSynopsys - ok
18:24:34.0896 0x23d8 usbaudio - ok
18:24:34.0911 0x23d8 usbccgp - ok
18:24:34.0911 0x23d8 usbcir - ok
18:24:34.0911 0x23d8 usbehci - ok
18:24:34.0911 0x23d8 usbhub - ok
18:24:34.0911 0x23d8 USBHUB3 - ok
18:24:34.0911 0x23d8 usbohci - ok
18:24:34.0927 0x23d8 usbprint - ok
18:24:34.0927 0x23d8 [ 2EC7B2C8123236B1233A77281D378DF7, D97DB59C9CAE2B8B33C707E8CEA7A65BF88712842CC715D270F7432A99D21BB6 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:24:34.0958 0x23d8 usbscan - ok
18:24:34.0958 0x23d8 usbser - ok
18:24:34.0974 0x23d8 USBSTOR - ok
18:24:34.0974 0x23d8 usbuhci - ok
18:24:34.0974 0x23d8 USBXHCI - ok
18:24:34.0989 0x23d8 UserDataSvc - ok
18:24:35.0021 0x23d8 UserManager - ok
18:24:35.0114 0x23d8 [ F4D8F67474DDA4FEF3935393AAA0173F, 5EB1700895E33972816DE4C2B920769CCE5580B83CAB8B2D7A8A6264F3A42B80 ] USER_ESRV_SVC_WILLAMETTE C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
18:24:35.0161 0x23d8 USER_ESRV_SVC_WILLAMETTE - ok
18:24:35.0161 0x23d8 UsoSvc - ok
18:24:35.0192 0x23d8 VaultSvc - ok
18:24:35.0239 0x23d8 [ 0EB68D00C7D3825EBCB8C47018FE2A93, 6A5E675A76AA86ED3C21247D54D4B767BA44D6785DE83FB7946EAD893A9FD5DF ] VBoxDrv C:\WINDOWS\system32\DRIVERS\VBoxDrv.sys
18:24:35.0333 0x23d8 VBoxDrv - ok
18:24:35.0364 0x23d8 [ 82902F80FADDC9BE4AFDAE63430827EE, DEED31F02F68B3E3A9414147F71373F73B195205FAEC3606B5540AE29762A3D1 ] VBoxUSBMon C:\WINDOWS\system32\DRIVERS\VBoxUSBMon.sys
18:24:35.0411 0x23d8 VBoxUSBMon - ok
18:24:35.0411 0x23d8 vdrvroot - ok
18:24:35.0427 0x23d8 vds - ok
18:24:35.0442 0x23d8 VerifierExt - ok
18:24:35.0442 0x23d8 vhdmp - ok
18:24:35.0442 0x23d8 vhf - ok
18:24:35.0442 0x23d8 vmbus - ok
18:24:35.0458 0x23d8 VMBusHID - ok
18:24:35.0458 0x23d8 vmgid - ok
18:24:35.0474 0x23d8 vmicguestinterface - ok
18:24:35.0474 0x23d8 vmicheartbeat - ok
18:24:35.0474 0x23d8 vmickvpexchange - ok
18:24:35.0505 0x23d8 vmicrdv - ok
18:24:35.0505 0x23d8 vmicshutdown - ok
18:24:35.0505 0x23d8 vmictimesync - ok
18:24:35.0505 0x23d8 vmicvmsession - ok
18:24:35.0505 0x23d8 vmicvss - ok
18:24:35.0521 0x23d8 volmgr - ok
18:24:35.0521 0x23d8 volmgrx - ok
18:24:35.0521 0x23d8 volsnap - ok
18:24:35.0521 0x23d8 volume - ok
18:24:35.0536 0x23d8 [ 92F6E3E6D3F1795263EB34B37F74AEF7, 33AB1ECCA1216AF1995E1DB4F11E48156FF62391D7C176C8A4CC1037B9CB3A27 ] vpci C:\WINDOWS\System32\drivers\vpci.sys
18:24:35.0567 0x23d8 vpci - ok
18:24:35.0567 0x23d8 vsmraid - ok
18:24:35.0583 0x23d8 VSS - ok
18:24:35.0583 0x23d8 VSTXRAID - ok
18:24:35.0583 0x23d8 vwifibus - ok
18:24:35.0599 0x23d8 vwififlt - ok
18:24:35.0599 0x23d8 W32Time - ok
18:24:35.0614 0x23d8 WacomPen - ok
18:24:35.0630 0x23d8 WalletService - ok
18:24:35.0630 0x23d8 wanarp - ok
18:24:35.0630 0x23d8 wanarpv6 - ok
18:24:35.0630 0x23d8 wbengine - ok
18:24:35.0661 0x23d8 WbioSrvc - ok
18:24:35.0661 0x23d8 wcifs - ok
18:24:35.0661 0x23d8 Wcmsvc - ok
18:24:35.0661 0x23d8 wcncsvc - ok
18:24:35.0677 0x23d8 wcnfs - ok
18:24:35.0677 0x23d8 WdBoot - ok
18:24:35.0677 0x23d8 Wdf01000 - ok
18:24:35.0677 0x23d8 WdFilter - ok
18:24:35.0677 0x23d8 WdiServiceHost - ok
18:24:35.0677 0x23d8 WdiSystemHost - ok
18:24:35.0692 0x23d8 wdiwifi - ok
18:24:35.0692 0x23d8 WdNisDrv - ok
18:24:35.0708 0x23d8 WdNisSvc - ok
18:24:35.0708 0x23d8 WebClient - ok
18:24:35.0724 0x23d8 Wecsvc - ok
18:24:35.0724 0x23d8 WEPHOSTSVC - ok
18:24:35.0724 0x23d8 wercplsupport - ok
18:24:35.0724 0x23d8 WerSvc - ok
18:24:35.0724 0x23d8 WFPLWFS - ok
18:24:35.0724 0x23d8 WiaRpc - ok
18:24:35.0739 0x23d8 WIMMount - ok
18:24:35.0739 0x23d8 WinDefend - ok
18:24:35.0739 0x23d8 WindowsTrustedRT - ok
18:24:35.0739 0x23d8 WindowsTrustedRTProxy - ok
18:24:35.0739 0x23d8 WinHttpAutoProxySvc - ok
18:24:35.0755 0x23d8 WinMad - ok
18:24:35.0771 0x23d8 Winmgmt - ok
18:24:35.0771 0x23d8 WinRM - ok
18:24:35.0771 0x23d8 WINUSB - ok
18:24:35.0771 0x23d8 WinVerbs - ok
18:24:35.0786 0x23d8 wisvc - ok
18:24:35.0786 0x23d8 WlanSvc - ok
18:24:35.0802 0x23d8 wlidsvc - ok
18:24:35.0802 0x23d8 WmiAcpi - ok
18:24:35.0802 0x23d8 wmiApSrv - ok
18:24:35.0817 0x23d8 Wof - ok
18:24:35.0817 0x23d8 workfolderssvc - ok
18:24:35.0817 0x23d8 WPDBusEnum - ok
18:24:35.0833 0x23d8 WpdUpFltr - ok
18:24:35.0833 0x23d8 WpnService - ok
18:24:35.0833 0x23d8 WpnUserService - ok
18:24:35.0833 0x23d8 ws2ifsl - ok
18:24:35.0849 0x23d8 wscsvc - ok
18:24:35.0849 0x23d8 WSearch - ok
18:24:35.0849 0x23d8 wuauserv - ok
18:24:35.0849 0x23d8 WudfPf - ok
18:24:35.0849 0x23d8 WUDFRd - ok
18:24:35.0864 0x23d8 wudfsvc - ok
18:24:35.0864 0x23d8 WUDFWpdFs - ok
18:24:35.0864 0x23d8 WUDFWpdMtp - ok
18:24:35.0880 0x23d8 WwanSvc - ok
18:24:35.0896 0x23d8 XblAuthManager - ok
18:24:35.0911 0x23d8 XblGameSave - ok
18:24:35.0927 0x23d8 [ C1E85B4FB08B4CCF16841B165910148B, AB33A6630BFC0E230BA464F721DD4ABB7DF79DF2D81C9C7366CC0BA2251F09F3 ] xboxgip C:\WINDOWS\System32\drivers\xboxgip.sys
18:24:35.0989 0x23d8 xboxgip - ok
18:24:35.0989 0x23d8 XboxNetApiSvc - ok
18:24:36.0005 0x23d8 xinputhid - ok
18:24:36.0005 0x23d8 ================ Scan global ===============================
18:24:36.0052 0x23d8 [ Global ] - ok
18:24:36.0052 0x23d8 ================ Scan MBR ==================================
18:24:36.0083 0x23d8 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
18:24:36.0177 0x23d8 \Device\Harddisk0\DR0 - ok
18:24:36.0193 0x23d8 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
18:24:37.0724 0x23d8 \Device\Harddisk1\DR1 - ok
18:24:37.0724 0x23d8 ================ Scan VBR ==================================
18:24:37.0724 0x23d8 [ 587AF438E07D18A66A9D67581F1981EB ] \Device\Harddisk0\DR0\Partition1
18:24:37.0724 0x23d8 \Device\Harddisk0\DR0\Partition1 - ok
18:24:37.0739 0x23d8 [ F0A90E9E1E864AEFDA1825C06612C4D3 ] \Device\Harddisk0\DR0\Partition2
18:24:37.0739 0x23d8 \Device\Harddisk0\DR0\Partition2 - ok
18:24:37.0755 0x23d8 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
18:24:37.0755 0x23d8 \Device\Harddisk0\DR0\Partition3 - ok
18:24:37.0771 0x23d8 [ A7CF1CA9CA68F8942F604E2D195C4202 ] \Device\Harddisk0\DR0\Partition4
18:24:37.0771 0x23d8 \Device\Harddisk0\DR0\Partition4 - ok
18:24:37.0771 0x23d8 [ EBA3075488927C8178708E4E210BFE37 ] \Device\Harddisk0\DR0\Partition5
18:24:37.0786 0x23d8 \Device\Harddisk0\DR0\Partition5 - ok
18:24:37.0802 0x23d8 [ F7E3ECACEDF1938DFBA4EBBA4AED0F37 ] \Device\Harddisk0\DR0\Partition6
18:24:37.0802 0x23d8 \Device\Harddisk0\DR0\Partition6 - ok
18:24:37.0818 0x23d8 [ E9E358FBB58B9D989CD4A842C6C95109 ] \Device\Harddisk1\DR1\Partition1
18:24:37.0818 0x23d8 \Device\Harddisk1\DR1\Partition1 - ok
18:24:37.0818 0x23d8 ================ Scan generic autorun ======================
18:24:38.0068 0x23d8 [ 4DA10F5BB9CBB4BDC4B757BB89E4EBC3, 2E41F18658576E4F62E203BD782EDB99C145B8716874AEDA95807389F59BBFFA ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
18:24:38.0286 0x23d8 RTHDVCPL - ok
18:24:38.0333 0x23d8 [ DD07D37B9A811764313FADE6C87F731F, 0D6CC5A0B0895528170C5FE9C2DA648D97A35C485D8F1FD98042058EA51CE440 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
18:24:38.0396 0x23d8 RtHDVBg - ok
18:24:38.0458 0x23d8 [ 4A0477ADCD07EC9D21257A2E456B16C5, CEF9C81730C12283A7600C3D921D89A62B14D1C46544B493F3AF7520DD2D1F79 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
18:24:38.0489 0x23d8 IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
18:24:38.0614 0x23d8 Detect skipped due to KSN trusted
18:24:38.0614 0x23d8 IAStorIcon - ok
18:24:38.0724 0x23d8 [ 94A8196066774252DF015EEDF02CCA44, AD2DFDA427E3CCB5C8404F0AFAFE71C64B862D2E26A67E1BFC2B40738FD0B873 ] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
18:24:38.0771 0x23d8 NvBackend - ok
18:24:38.0771 0x23d8 ShadowPlay - ok
18:24:38.0833 0x23d8 [ 8CC5E4DB25E4C22A308E2820E69D4950, A53BBE06FF226DA7E37C3ADA881AF4F856E439553DFA7D10DDECB07196545B39 ] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
18:24:38.0864 0x23d8 CDAServer - ok
18:24:38.0927 0x23d8 [ FE18DDEA98D90DBF850AFCA0158ABEC8, 8EC0099B560CC23DA6D26A71A202667D1A7C4BC37CE0F9F3458EA40440541D06 ] C:\Program Files\Everything\Everything.exe
18:24:39.0021 0x23d8 Everything - detected UnsignedFile.Multi.Generic ( 1 )
18:24:39.0130 0x23d8 Detect skipped due to KSN trusted
18:24:39.0130 0x23d8 Everything - ok
18:24:39.0380 0x23d8 [ 56CD0FF9F67B8A3CE0C0FD53B1FC5FC1, D169B7A80117CEC4EA245F8EA9F3B6A280A50AAFE7E9AC4EB8DA285F79821256 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
18:24:39.0521 0x23d8 AvastUI.exe - ok
18:24:39.0568 0x23d8 [ 5153C06FC9D4D094D1A785545928B134, 0037C935722663F9EF028F841DE222FC6418E9D60939AB60C965807E67A458DC ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
18:24:39.0568 0x23d8 SunJavaUpdateSched - ok
18:24:39.0614 0x23d8 OneDriveSetup - ok
18:24:39.0614 0x23d8 OneDriveSetup - ok
18:24:39.0818 0x23d8 [ A70E699E0B0DD9C2B3B35E9A8167F903, 6CC7AFFEED646AA9C46C709C8B36751CA9EBCDDC70438ECE1D1328E6C1A02421 ] C:\Program Files\CCleaner\CCleaner64.exe
18:24:39.0943 0x23d8 CCleaner Monitoring - ok
18:24:40.0052 0x23d8 [ 1D7DD340E13DF9585EABB849CFC3E11B, 31CCD9753402DC030C641214B4ECB48A757BCD9F427A143A88745C62EFF87766 ] C:\Users\hannibla34\AppData\Local\Microsoft\OneDrive\OneDrive.exe
18:24:40.0099 0x23d8 OneDrive - ok
18:24:40.0146 0x23d8 [ DC3DB64A7F934F7941484FEB19380226, 8C00CAC91099B69ACE0F44894D8705CE8C3F0B4362E844A92566FD8902978333 ] C:\Program Files\Samsung\Stylish UI Pack\TouchBasedUI.exe
18:24:40.0177 0x23d8 STUISpeedLauncher - detected UnsignedFile.Multi.Generic ( 1 )
18:24:40.0302 0x23d8 Detect skipped due to KSN trusted
18:24:40.0302 0x23d8 STUISpeedLauncher - ok
18:24:40.0318 0x23d8 Uninstall C:\Users\hannibla34\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64 - ok
18:24:40.0318 0x23d8 Waiting for KSN requests completion. In queue: 47
18:24:40.0443 0x1884 Object required for P2P: [ 56CD0FF9F67B8A3CE0C0FD53B1FC5FC1 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
18:24:40.0677 0x1884 Object send P2P result: true
18:24:41.0364 0x23d8 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
18:24:41.0364 0x23d8 AV detected via SS2: Avast Antivirus, C:\Program Files\AVAST Software\Avast\wsc_proxy.exe ( 12.3.3154.0 ), 0x41000 ( enabled : updated )
18:24:41.0396 0x23d8 Win FW state via NFP2: enabled ( trusted )
18:24:41.0521 0x23d8 ============================================================
18:24:41.0521 0x23d8 Scan finished
18:24:41.0521 0x23d8 ============================================================
18:24:41.0536 0x2034 Detected object count: 0
18:24:41.0536 0x2034 Actual detected object count: 0 |