regime55 | 20.11.2016 12:45 | 6. mbar-log vom 20.11.2016 Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2016.11.20.03
rootkit: v2016.10.31.01
Windows 10 x64 NTFS
Internet Explorer 11.447.14393.0
User :: BERND [administrator]
20.11.2016 12:04:00
mbar-log-2016-11-20 (12-04-00).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 352065
Time elapsed: 16 minute(s), 53 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end)
7. TDSSKiller Code:
12:40:18.0672 0x0918 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
12:40:25.0305 0x0918 ============================================================
12:40:25.0305 0x0918 Current date / time: 2016/11/20 12:40:25.0305
12:40:25.0305 0x0918 SystemInfo:
12:40:25.0305 0x0918
12:40:25.0305 0x0918 OS Version: 10.0.14393 ServicePack: 0.0
12:40:25.0305 0x0918 Product type: Workstation
12:40:25.0305 0x0918 ComputerName: BERND
12:40:25.0305 0x0918 UserName: User
12:40:25.0305 0x0918 Windows directory: C:\WINDOWS
12:40:25.0305 0x0918 System windows directory: C:\WINDOWS
12:40:25.0305 0x0918 Running under WOW64
12:40:25.0305 0x0918 Processor architecture: Intel x64
12:40:25.0305 0x0918 Number of processors: 4
12:40:25.0305 0x0918 Page size: 0x1000
12:40:25.0305 0x0918 Boot type: Normal boot
12:40:25.0305 0x0918 CodeIntegrityOptions = 0x00000001
12:40:25.0305 0x0918 ============================================================
12:40:25.0539 0x0918 KLMD registered as C:\WINDOWS\system32\drivers\96510266.sys
12:40:25.0539 0x0918 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.447, osProperties = 0x19
12:40:25.0805 0x0918 System UUID: {FE57EF47-BA9A-8745-7445-3F5720120C2F}
12:40:26.0430 0x0918 Drive \Device\Harddisk0\DR0 - Size: 0x15D50F66000 ( 1397.27 Gb ), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:40:26.0445 0x0918 ============================================================
12:40:26.0445 0x0918 \Device\Harddisk0\DR0:
12:40:26.0445 0x0918 MBR partitions:
12:40:26.0445 0x0918 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
12:40:26.0445 0x0918 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x33000, BlocksNum 0xAE972330
12:40:26.0445 0x0918 ============================================================
12:40:26.0477 0x0918 C: <-> \Device\Harddisk0\DR0\Partition2
12:40:26.0492 0x0918 ============================================================
12:40:26.0492 0x0918 Initialize success
12:40:26.0492 0x0918 ============================================================
12:40:28.0941 0x08dc ============================================================
12:40:28.0941 0x08dc Scan started
12:40:28.0941 0x08dc Mode: Manual;
12:40:28.0941 0x08dc ============================================================
12:40:28.0941 0x08dc KSN ping started
12:40:29.0066 0x08dc KSN ping finished: true
12:40:30.0958 0x08dc ================ Scan system memory ========================
12:40:30.0958 0x08dc System memory - ok
12:40:30.0958 0x08dc ================ Scan services =============================
12:40:31.0137 0x08dc 1394ohci - ok
12:40:31.0147 0x08dc 3ware - ok
12:40:31.0256 0x08dc [ 05936579605018BD2BC528FF2C1AD95F, 763C2E76F9078F6A74D5BCCB4DD8A10C82AEB9C9F5A45C3706A587FA2D03E7D3 ] a2injectiondriver C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2dix64.sys
12:40:31.0272 0x08dc a2injectiondriver - ok
12:40:31.0319 0x08dc [ B1AB7116D14667A2238DAEFE20B7F4D0, DC8A9093A6F759657C3354931A462FCCAF3533A907FB7152380EB2E9B4AD3BF8 ] a2util C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\a2util64.sys
12:40:31.0334 0x08dc a2util - ok
12:40:31.0350 0x08dc [ 1FAA46933398A33ABFCDB74824007F22, C38CDD39871E2AE4438B87C790C67A6F13CF60FE84540BAB5F012A93649D7636 ] AAVScan C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\AAV_IFS64.sys
12:40:31.0350 0x08dc AAVScan - ok
12:40:31.0381 0x08dc [ B4DCC8EB6FE251F7DEF297026862ACCE, EA20E783557BEB452331CF37D7189016BF3EC0EB3BDCBE8685D7DA1140CA03EC ] AAVService C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\AAV_Service_VISTA.exe
12:40:31.0412 0x08dc AAVService - ok
12:40:31.0428 0x08dc ACPI - ok
12:40:31.0428 0x08dc AcpiDev - ok
12:40:31.0444 0x08dc acpiex - ok
12:40:31.0444 0x08dc acpipagr - ok
12:40:31.0459 0x08dc AcpiPmi - ok
12:40:31.0475 0x08dc acpitime - ok
12:40:31.0553 0x08dc [ C92B0A0957ACAD3CEEF502A2CA10ACB8, 78BF46318B69D9479ECDC83446DD8D454AA2A9A9D94B33C5FC68933DB18AFA3B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
12:40:31.0584 0x08dc AdobeARMservice - ok
12:40:31.0725 0x08dc [ 8FC33A20D54FB5CC7FBBA814B4E42A22, 707F61F0CEB9467D9BD1782868403BD53DB46EAB0342772661F370E5174AAD8C ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
12:40:31.0772 0x08dc AdobeFlashPlayerUpdateSvc - ok
12:40:31.0772 0x08dc ADP80XX - ok
12:40:31.0787 0x08dc AFD - ok
12:40:31.0803 0x08dc ahcache - ok
12:40:31.0819 0x08dc AJRouter - ok
12:40:31.0834 0x08dc ALG - ok
12:40:31.0850 0x08dc [ BBADD85854BFB5D43C60B7AC8EEA3DBA, 968C043ABEA46F5C79525863B3FE2681AC0FA4202036C9EFD20B408DECF407E2 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe
12:40:31.0866 0x08dc AMD External Events Utility - ok
12:40:31.0928 0x08dc [ DE51F5BB5C05D4C831ECB6E1A70E1B5E, 465834210ACE469481F75EDBB8532386029BD5277C41D084134E9E71B9BD8371 ] AMD FUEL Service C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
12:40:31.0944 0x08dc AMD FUEL Service - ok
12:40:31.0959 0x08dc AmdK8 - ok
12:40:31.0975 0x08dc amdkmdag - ok
12:40:32.0022 0x08dc [ 17BA5C907E14947574CBB788F4CEB85F, EAA3DBF436637C58666A91905E388287FC54334EBB2589A00727EB09AC4870E3 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys
12:40:32.0037 0x08dc amdkmdap - ok
12:40:32.0037 0x08dc AmdPPM - ok
12:40:32.0053 0x08dc amdsata - ok
12:40:32.0053 0x08dc amdsbs - ok
12:40:32.0053 0x08dc amdxata - ok
12:40:32.0084 0x08dc [ C3D487827E48CC5EC17994FEC5BDFF87, 5FCEA3EEA583755D0C9F6005ED3032E9DFECB57F504DC67701AE7D2D2631C30E ] AODDriver4.3 C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
12:40:32.0084 0x08dc AODDriver4.3 - ok
12:40:32.0100 0x08dc AppHostSvc - ok
12:40:32.0116 0x08dc AppID - ok
12:40:32.0116 0x08dc AppIDSvc - ok
12:40:32.0131 0x08dc Appinfo - ok
12:40:32.0131 0x08dc applockerfltr - ok
12:40:32.0131 0x08dc AppMgmt - ok
12:40:32.0147 0x08dc AppReadiness - ok
12:40:32.0162 0x08dc AppVClient - ok
12:40:32.0162 0x08dc AppvStrm - ok
12:40:32.0178 0x08dc AppvVemgr - ok
12:40:32.0178 0x08dc AppvVfs - ok
12:40:32.0209 0x08dc AppXSvc - ok
12:40:32.0209 0x08dc arcsas - ok
12:40:32.0303 0x08dc aspnet_state - ok
12:40:32.0319 0x08dc AsyncMac - ok
12:40:32.0319 0x08dc atapi - ok
12:40:32.0352 0x08dc [ 0966FD5BAB1F9BE200875E9EED0A0A13, F4BE70C0581B51ED6DAE6412A5FF74AE310BF88DE89C5A5E5880BEED543B01D7 ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdWT6.sys
12:40:32.0367 0x08dc AtiHDAudioService - ok
12:40:32.0383 0x08dc AudioEndpointBuilder - ok
12:40:32.0399 0x08dc Audiosrv - ok
12:40:32.0399 0x08dc AxInstSV - ok
12:40:32.0414 0x08dc b06bdrv - ok
12:40:32.0414 0x08dc BasicDisplay - ok
12:40:32.0430 0x08dc BasicRender - ok
12:40:32.0446 0x08dc bcmfn - ok
12:40:32.0446 0x08dc bcmfn2 - ok
12:40:32.0446 0x08dc BDESVC - ok
12:40:32.0461 0x08dc Beep - ok
12:40:32.0477 0x08dc BFE - ok
12:40:32.0477 0x08dc BITS - ok
12:40:32.0492 0x08dc bowser - ok
12:40:32.0492 0x08dc BrokerInfrastructure - ok
12:40:32.0492 0x08dc Browser - ok
12:40:32.0524 0x08dc [ 2D0446336D9DB55A742B999EC16ADF15, FBF57CBDCFE4146176ABBD7ACF04240048403143DD380E10AE63B10BA5D4F311 ] BTATH_BUS C:\WINDOWS\System32\drivers\btath_bus.sys
12:40:32.0539 0x08dc BTATH_BUS - ok
12:40:32.0539 0x08dc BthAvrcpTg - ok
12:40:32.0539 0x08dc BthHFEnum - ok
12:40:32.0555 0x08dc bthhfhid - ok
12:40:32.0571 0x08dc BthHFSrv - ok
12:40:32.0586 0x08dc BTHMODEM - ok
12:40:32.0586 0x08dc bthserv - ok
12:40:32.0602 0x08dc buttonconverter - ok
12:40:32.0602 0x08dc CapImg - ok
12:40:32.0617 0x08dc cdfs - ok
12:40:32.0617 0x08dc CDPSvc - ok
12:40:32.0633 0x08dc CDPUserSvc - ok
12:40:32.0680 0x08dc cdrom - ok
12:40:32.0680 0x08dc CertPropSvc - ok
12:40:32.0696 0x08dc cht4iscsi - ok
12:40:32.0696 0x08dc cht4vbd - ok
12:40:32.0711 0x08dc circlass - ok
12:40:32.0807 0x08dc [ E264626EEA468F0325C244CB9ECDDEB4, 0E10A17E2BEB4C91D3D527AF1C550FDF0132ECF79737514890D79BC00AE553F1 ] cleanhlp C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\cleanhlp64.sys
12:40:32.0807 0x08dc cleanhlp - ok
12:40:32.0823 0x08dc CLFS - ok
12:40:32.0839 0x08dc ClipSVC - ok
12:40:32.0839 0x08dc clreg - ok
12:40:32.0870 0x08dc CmBatt - ok
12:40:32.0870 0x08dc CNG - ok
12:40:32.0885 0x08dc cnghwassist - ok
12:40:32.0948 0x08dc CompositeBus - ok
12:40:32.0964 0x08dc COMSysApp - ok
12:40:32.0964 0x08dc condrv - ok
12:40:32.0995 0x08dc CoreMessagingRegistrar - ok
12:40:33.0026 0x08dc CryptSvc - ok
12:40:33.0026 0x08dc CSC - ok
12:40:33.0047 0x08dc CscService - ok
12:40:33.0141 0x08dc [ B4D1D62A09F09CB2DFD55628350CDAFB, 7DD3CE77D88B5AFAC4B6187F4CA6D50B7BD3398207163B2A1E4C76467801FF28 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
12:40:33.0172 0x08dc cvhsvc - ok
12:40:33.0172 0x08dc dam - ok
12:40:33.0188 0x08dc DcomLaunch - ok
12:40:33.0188 0x08dc DcpSvc - ok
12:40:33.0219 0x08dc defragsvc - ok
12:40:33.0219 0x08dc DeviceAssociationService - ok
12:40:33.0235 0x08dc DeviceInstall - ok
12:40:33.0235 0x08dc DevQueryBroker - ok
12:40:33.0250 0x08dc Dfsc - ok
12:40:33.0282 0x08dc Dhcp - ok
12:40:33.0313 0x08dc diagnosticshub.standardcollector.service - ok
12:40:33.0329 0x08dc DiagTrack - ok
12:40:33.0344 0x08dc disk - ok
12:40:33.0344 0x08dc DmEnrollmentSvc - ok
12:40:33.0344 0x08dc dmvsc - ok
12:40:33.0360 0x08dc dmwappushservice - ok
12:40:33.0375 0x08dc Dnscache - ok
12:40:33.0391 0x08dc dot3svc - ok
12:40:33.0407 0x08dc DPS - ok
12:40:33.0422 0x08dc drmkaud - ok
12:40:33.0422 0x08dc DsmSvc - ok
12:40:33.0422 0x08dc DsSvc - ok
12:40:33.0438 0x08dc DXGKrnl - ok
12:40:33.0438 0x08dc EapHost - ok
12:40:33.0454 0x08dc ebdrv - ok
12:40:33.0454 0x08dc EFS - ok
12:40:33.0469 0x08dc EhStorClass - ok
12:40:33.0485 0x08dc EhStorTcgDrv - ok
12:40:33.0485 0x08dc embeddedmode - ok
12:40:33.0500 0x08dc EntAppSvc - ok
12:40:33.0563 0x08dc [ 8783EDE26F315555EFE697239D337910, 344232F0018A942B57AF40FBE00AEB89F55A8F412CD20A2174024117F95B2BE9 ] epp C:\Emisoft Emergency Kit\bin64\epp.sys
12:40:33.0563 0x08dc epp - ok
12:40:33.0610 0x08dc [ D315FF43E23DF424ECEC2F6C930203E4, 68940EDA34DC4945CDD0D8018D96A0DA8F99F16A930946D14E4FECEE033FCB80 ] EpsonScanSvc C:\WINDOWS\system32\EscSvc64.exe
12:40:33.0610 0x08dc EpsonScanSvc - ok
12:40:33.0688 0x08dc [ 86032A47AD0105130FE7808C903E2086, ACCCA35483B7E8F9FC72A65031E024C469DF94FCCF2C5CC37C9B3BED4F1C676E ] EPSON_PM_RPCV4_06 C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S60RPB.EXE
12:40:33.0688 0x08dc EPSON_PM_RPCV4_06 - ok
12:40:33.0704 0x08dc ErrDev - ok
12:40:33.0719 0x08dc EventSystem - ok
12:40:33.0719 0x08dc exfat - ok
12:40:33.0735 0x08dc fastfat - ok
12:40:33.0751 0x08dc Fax - ok
12:40:33.0766 0x08dc fdc - ok
12:40:33.0766 0x08dc fdPHost - ok
12:40:33.0782 0x08dc FDResPub - ok
12:40:33.0782 0x08dc fhsvc - ok
12:40:33.0797 0x08dc FileCrypt - ok
12:40:33.0797 0x08dc FileInfo - ok
12:40:33.0813 0x08dc Filetrace - ok
12:40:33.0813 0x08dc flpydisk - ok
12:40:33.0829 0x08dc FltMgr - ok
12:40:33.0844 0x08dc FontCache - ok
12:40:33.0922 0x08dc FontCache3.0.0.0 - ok
12:40:33.0954 0x08dc FrameServer - ok
12:40:33.0969 0x08dc FsDepends - ok
12:40:33.0985 0x08dc Fs_Rec - ok
12:40:34.0000 0x08dc fvevol - ok
12:40:34.0000 0x08dc gencounter - ok
12:40:34.0016 0x08dc genericusbfn - ok
12:40:34.0016 0x08dc GPIOClx0101 - ok
12:40:34.0032 0x08dc gpsvc - ok
12:40:34.0032 0x08dc GpuEnergyDrv - ok
12:40:34.0047 0x08dc HdAudAddService - ok
12:40:34.0047 0x08dc HDAudBus - ok
12:40:34.0063 0x08dc HidBatt - ok
12:40:34.0063 0x08dc HidBth - ok
12:40:34.0079 0x08dc hidi2c - ok
12:40:34.0079 0x08dc hidinterrupt - ok
12:40:34.0094 0x08dc HidIr - ok
12:40:34.0094 0x08dc hidserv - ok
12:40:34.0126 0x08dc HidUsb - ok
12:40:34.0141 0x08dc HomeGroupListener - ok
12:40:34.0157 0x08dc HomeGroupProvider - ok
12:40:34.0157 0x08dc HpSAMD - ok
12:40:34.0172 0x08dc HTTP - ok
12:40:34.0188 0x08dc HvHost - ok
12:40:34.0204 0x08dc hvservice - ok
12:40:34.0219 0x08dc hwpolicy - ok
12:40:34.0219 0x08dc hyperkbd - ok
12:40:34.0250 0x08dc i8042prt - ok
12:40:34.0250 0x08dc iagpio - ok
12:40:34.0266 0x08dc iai2c - ok
12:40:34.0266 0x08dc iaLPSS2i_GPIO2 - ok
12:40:34.0282 0x08dc iaLPSS2i_I2C - ok
12:40:34.0282 0x08dc iaLPSSi_GPIO - ok
12:40:34.0297 0x08dc iaLPSSi_I2C - ok
12:40:34.0297 0x08dc iaStorAV - ok
12:40:34.0313 0x08dc iaStorV - ok
12:40:34.0313 0x08dc ibbus - ok
12:40:34.0344 0x08dc icssvc - ok
12:40:34.0407 0x08dc [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
12:40:34.0500 0x08dc IDriverT - ok
12:40:34.0516 0x08dc IKEEXT - ok
12:40:34.0516 0x08dc IndirectKmd - ok
12:40:34.0547 0x08dc intelide - ok
12:40:34.0547 0x08dc intelpep - ok
12:40:34.0563 0x08dc intelppm - ok
12:40:34.0594 0x08dc iorate - ok
12:40:34.0594 0x08dc IpFilterDriver - ok
12:40:34.0626 0x08dc iphlpsvc - ok
12:40:34.0626 0x08dc IPMIDRV - ok
12:40:34.0641 0x08dc IPNAT - ok
12:40:34.0641 0x08dc irda - ok
12:40:34.0657 0x08dc IRENUM - ok
12:40:34.0672 0x08dc irmon - ok
12:40:34.0672 0x08dc isapnp - ok
12:40:34.0688 0x08dc iScsiPrt - ok
12:40:34.0704 0x08dc kbdclass - ok
12:40:34.0704 0x08dc kbdhid - ok
12:40:34.0719 0x08dc kdnic - ok
12:40:34.0735 0x08dc KeyIso - ok
12:40:34.0735 0x08dc KSecDD - ok
12:40:34.0750 0x08dc KSecPkg - ok
12:40:34.0750 0x08dc ksthunk - ok
12:40:34.0782 0x08dc KtmRm - ok
12:40:34.0782 0x08dc LanmanServer - ok
12:40:34.0797 0x08dc LanmanWorkstation - ok
12:40:34.0813 0x08dc lfsvc - ok
12:40:34.0813 0x08dc LicenseManager - ok
12:40:34.0829 0x08dc lltdio - ok
12:40:34.0829 0x08dc lltdsvc - ok
12:40:34.0844 0x08dc lmhosts - ok
12:40:34.0860 0x08dc LSI_SAS - ok
12:40:34.0860 0x08dc LSI_SAS2i - ok
12:40:34.0875 0x08dc LSI_SAS3i - ok
12:40:34.0875 0x08dc LSI_SSS - ok
12:40:34.0891 0x08dc LSM - ok
12:40:34.0891 0x08dc luafv - ok
12:40:34.0907 0x08dc MapsBroker - ok
12:40:34.0938 0x08dc [ 78BFF5425E044086E74E78650A359FBB, 294738C10F3ED933D4EC40EA0659372FCF19A3C6D45D356917438CA495F2CB45 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
12:40:34.0938 0x08dc MBAMProtector - ok
12:40:35.0016 0x08dc [ 9611577752E293259C7DCE19E9026362, 8CB5DFD63FA15603BB6FA6B501E09ED7F4DE0E8F68CB28B78CECAC3711BEFD24 ] MBAMScheduler C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
12:40:35.0047 0x08dc MBAMScheduler - ok
12:40:35.0126 0x08dc [ F1A89A34388B5626F1548D393B23ECB1, EA00AC76C4C8C9340753B58A3313C9177A9B98F9F1BDE08F184CD0F53D0C186F ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
12:40:35.0157 0x08dc MBAMService - ok
12:40:35.0204 0x08dc [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
12:40:35.0204 0x08dc MBAMSwissArmy - ok
12:40:35.0219 0x08dc [ 452ACB7A9914398D9E18CCCFFCF92208, 754AF45C19731C356E7E84497B04E0333759AC86DC553BA275EFC09845E43E4D ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
12:40:35.0235 0x08dc MBAMWebAccessControl - ok
12:40:35.0235 0x08dc megasas - ok
12:40:35.0266 0x08dc megasas2i - ok
12:40:35.0282 0x08dc megasr - ok
12:40:35.0282 0x08dc MessagingService - ok
12:40:35.0391 0x08dc [ 123271BD5237AB991DC5C21FDF8835EB, 004F8F9228EE291A0E36CE33078D572D61733516F9AA5CFC832AF204C6869E89 ] Microsoft Office Groove Audit Service C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe
12:40:35.0391 0x08dc Microsoft Office Groove Audit Service - ok
12:40:35.0407 0x08dc mlx4_bus - ok
12:40:35.0438 0x08dc MMCSS - ok
12:40:35.0438 0x08dc Modem - ok
12:40:35.0454 0x08dc monitor - ok
12:40:35.0454 0x08dc mouclass - ok
12:40:35.0469 0x08dc mouhid - ok
12:40:35.0469 0x08dc mountmgr - ok
12:40:35.0485 0x08dc mpsdrv - ok
12:40:35.0501 0x08dc MpsSvc - ok
12:40:35.0516 0x08dc MQAC - ok
12:40:35.0547 0x08dc MRxDAV - ok
12:40:35.0547 0x08dc mrxsmb - ok
12:40:35.0563 0x08dc mrxsmb10 - ok
12:40:35.0563 0x08dc mrxsmb20 - ok
12:40:35.0579 0x08dc MsBridge - ok
12:40:35.0594 0x08dc MSDTC - ok
12:40:35.0610 0x08dc Msfs - ok
12:40:35.0625 0x08dc msgpiowin32 - ok
12:40:35.0641 0x08dc mshidkmdf - ok
12:40:35.0641 0x08dc mshidumdf - ok
12:40:35.0657 0x08dc msisadrv - ok
12:40:35.0672 0x08dc MSiSCSI - ok
12:40:35.0688 0x08dc msiserver - ok
12:40:35.0704 0x08dc MSKSSRV - ok
12:40:35.0704 0x08dc MsLldp - ok
12:40:35.0719 0x08dc MSMQ - ok
12:40:35.0735 0x08dc MSPCLOCK - ok
12:40:35.0751 0x08dc MSPQM - ok
12:40:35.0751 0x08dc MsRPC - ok
12:40:35.0766 0x08dc MsSecFlt - ok
12:40:35.0782 0x08dc mssmbios - ok
12:40:35.0797 0x08dc MSTEE - ok
12:40:35.0797 0x08dc MTConfig - ok
12:40:35.0813 0x08dc Mup - ok
12:40:35.0829 0x08dc mvumis - ok
12:40:35.0891 0x08dc [ A25648600888D412CCD2637071B08A04, 78FFF7F7F877EC5E4DC84C597E7639EBBCA9AE9F5B2F8C328022CD3E05E5F838 ] MyEpson Portal Service C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
12:40:35.0922 0x08dc MyEpson Portal Service - ok
12:40:35.0954 0x08dc NativeWifiP - ok
12:40:35.0969 0x08dc NcaSvc - ok
12:40:35.0985 0x08dc NcbService - ok
12:40:36.0001 0x08dc NcdAutoSetup - ok
12:40:36.0001 0x08dc ndfltr - ok
12:40:36.0032 0x08dc NDIS - ok
12:40:36.0032 0x08dc NdisCap - ok
12:40:36.0047 0x08dc NdisImPlatform - ok
12:40:36.0063 0x08dc NdisTapi - ok
12:40:36.0063 0x08dc Ndisuio - ok
12:40:36.0079 0x08dc NdisVirtualBus - ok
12:40:36.0094 0x08dc NdisWan - ok
12:40:36.0094 0x08dc ndiswanlegacy - ok
12:40:36.0110 0x08dc ndproxy - ok
12:40:36.0126 0x08dc Ndu - ok
12:40:36.0126 0x08dc NetAdapterCx - ok
12:40:36.0141 0x08dc NetBIOS - ok
12:40:36.0157 0x08dc NetBT - ok
12:40:36.0172 0x08dc Netlogon - ok
12:40:36.0172 0x08dc Netman - ok
12:40:36.0219 0x08dc NetMsmqActivator - ok
12:40:36.0219 0x08dc NetPipeActivator - ok
12:40:36.0235 0x08dc netprofm - ok
12:40:36.0266 0x08dc NetSetupSvc - ok
12:40:36.0266 0x08dc NetTcpActivator - ok
12:40:36.0282 0x08dc NetTcpPortSharing - ok
12:40:36.0297 0x08dc NgcCtnrSvc - ok
12:40:36.0313 0x08dc NgcSvc - ok
12:40:36.0329 0x08dc NlaSvc - ok
12:40:36.0344 0x08dc Npfs - ok
12:40:36.0344 0x08dc npsvctrig - ok
12:40:36.0360 0x08dc nsi - ok
12:40:36.0376 0x08dc nsiproxy - ok
12:40:36.0407 0x08dc NTFS - ok
12:40:36.0422 0x08dc Null - ok
12:40:36.0422 0x08dc nvraid - ok
12:40:36.0438 0x08dc nvstor - ok
12:40:36.0501 0x08dc [ 415695F5A54E91E869EEBFEA261361A6, 1829C15E07D902686171C8A66EB03040A037CAC1E00E24BF598030D9DA795CEC ] nvsvc C:\Windows\system32\nvvsvc.exe
12:40:36.0516 0x08dc nvsvc - ok
12:40:36.0610 0x08dc [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
12:40:36.0657 0x08dc odserv - ok
12:40:36.0704 0x08dc OneSyncSvc - ok
12:40:36.0766 0x08dc [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
12:40:36.0782 0x08dc ose - ok
12:40:36.0985 0x08dc [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
12:40:37.0063 0x08dc osppsvc - ok
12:40:37.0079 0x08dc p2pimsvc - ok
12:40:37.0094 0x08dc p2psvc - ok
12:40:37.0110 0x08dc Parport - ok
12:40:37.0126 0x08dc partmgr - ok
12:40:37.0141 0x08dc PcaSvc - ok
12:40:37.0204 0x08dc pci - ok
12:40:37.0219 0x08dc pciide - ok
12:40:37.0235 0x08dc pcmcia - ok
12:40:37.0251 0x08dc pcw - ok
12:40:37.0266 0x08dc pdc - ok
12:40:37.0282 0x08dc PEAUTH - ok
12:40:37.0282 0x08dc PeerDistSvc - ok
12:40:37.0297 0x08dc percsas2i - ok
12:40:37.0313 0x08dc percsas3i - ok
12:40:37.0391 0x08dc PerfHost - ok
12:40:37.0438 0x08dc PhoneSvc - ok
12:40:37.0469 0x08dc PimIndexMaintenanceSvc - ok
12:40:37.0485 0x08dc pla - ok
12:40:37.0485 0x08dc PlugPlay - ok
12:40:37.0501 0x08dc PNRPAutoReg - ok
12:40:37.0516 0x08dc PNRPsvc - ok
12:40:37.0532 0x08dc PolicyAgent - ok
12:40:37.0547 0x08dc Power - ok
12:40:37.0563 0x08dc PptpMiniport - ok
12:40:37.0735 0x08dc [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
12:40:37.0844 0x08dc PrintNotify - ok
12:40:37.0860 0x08dc Processor - ok
12:40:37.0891 0x08dc ProfSvc - ok
12:40:37.0907 0x08dc Psched - ok
12:40:37.0922 0x08dc QWAVE - ok
12:40:37.0938 0x08dc QWAVEdrv - ok
12:40:37.0954 0x08dc RasAcd - ok
12:40:37.0963 0x08dc RasAgileVpn - ok
12:40:37.0979 0x08dc RasAuto - ok
12:40:37.0994 0x08dc Rasl2tp - ok
12:40:38.0010 0x08dc RasMan - ok
12:40:38.0010 0x08dc RasPppoe - ok
12:40:38.0025 0x08dc RasSstp - ok
12:40:38.0041 0x08dc rdbss - ok
12:40:38.0072 0x08dc rdpbus - ok
12:40:38.0072 0x08dc RDPDR - ok
12:40:38.0135 0x08dc RdpVideoMiniport - ok
12:40:38.0135 0x08dc rdyboost - ok
12:40:38.0150 0x08dc ReFSv1 - ok
12:40:38.0166 0x08dc RemoteAccess - ok
12:40:38.0182 0x08dc RemoteRegistry - ok
12:40:38.0197 0x08dc RetailDemo - ok
12:40:38.0213 0x08dc RmSvc - ok
12:40:38.0229 0x08dc RpcEptMapper - ok
12:40:38.0244 0x08dc RpcLocator - ok
12:40:38.0260 0x08dc RpcSs - ok
12:40:38.0260 0x08dc rspndr - ok
12:40:38.0275 0x08dc rt640x64 - ok
12:40:38.0291 0x08dc RTL8192su - ok
12:40:38.0307 0x08dc s3cap - ok
12:40:38.0322 0x08dc SamSs - ok
12:40:38.0338 0x08dc sbp2port - ok
12:40:38.0338 0x08dc SCardSvr - ok
12:40:38.0354 0x08dc ScDeviceEnum - ok
12:40:38.0369 0x08dc scfilter - ok
12:40:38.0385 0x08dc Schedule - ok
12:40:38.0400 0x08dc scmbus - ok
12:40:38.0416 0x08dc scmdisk0101 - ok
12:40:38.0432 0x08dc SCPolicySvc - ok
12:40:38.0447 0x08dc sdbus - ok
12:40:38.0463 0x08dc SDRSVC - ok
12:40:38.0479 0x08dc sdstor - ok
12:40:38.0494 0x08dc seclogon - ok
12:40:38.0494 0x08dc SENS - ok
12:40:38.0557 0x08dc Sense - ok
12:40:38.0572 0x08dc SensorDataService - ok
12:40:38.0588 0x08dc SensorService - ok
12:40:38.0604 0x08dc SensrSvc - ok
12:40:38.0619 0x08dc SerCx - ok
12:40:38.0635 0x08dc SerCx2 - ok
12:40:38.0635 0x08dc Serenum - ok
12:40:38.0650 0x08dc Serial - ok
12:40:38.0666 0x08dc sermouse - ok
12:40:38.0713 0x08dc SessionEnv - ok
12:40:38.0744 0x08dc sfloppy - ok
12:40:38.0791 0x08dc [ 9242988D74674C2819D454F001457BAD, D353A30D224940B0C7750161782CE98D4C47ABC5C4E04B100F8ABB6A3402B5AD ] Sftfs C:\WINDOWS\system32\DRIVERS\Sftfswin7.sys
12:40:38.0807 0x08dc Sftfs - ok
12:40:38.0885 0x08dc [ 4E1BB8A9CCDB4BAF41F7F9A930EB121D, D994B20DACEB187BEB6530309E2185040B58105E4FD5AC1DA435712F9DE027D0 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
12:40:38.0916 0x08dc sftlist - ok
12:40:38.0932 0x08dc [ 44391FA910901E2B8A2F831340FD707A, 9ACAD655DCCCAF562CEDE9180B187C229FFCAF97BA87D78225253C7868698CB8 ] Sftplay C:\WINDOWS\system32\DRIVERS\Sftplaywin7.sys
12:40:38.0947 0x08dc Sftplay - ok
12:40:38.0963 0x08dc [ 8654DBDC8ED8ED7257618D11B6C590BE, 1A410CCB7CDE99C607662E21054E959D3349647C5BD810CE744DA59EEB9C3FA2 ] Sftredir C:\WINDOWS\system32\DRIVERS\Sftredirwin7.sys
12:40:38.0963 0x08dc Sftredir - ok
12:40:38.0979 0x08dc [ 648F0152A7BAE175905C22E8BD839760, 6E3FC032212FD1F39FEE96D230F47BB25355587E8A73E34776CAEA8C0C1FB58E ] Sftvol C:\WINDOWS\system32\DRIVERS\Sftvolwin7.sys
12:40:38.0979 0x08dc Sftvol - ok
12:40:39.0010 0x08dc [ CECFDE5D3701B2D914862F5E6C3DFE18, E7627F90630C306324A39DC3C652B37D255F90636AC19D3302EE5B85BD504BD5 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
12:40:39.0025 0x08dc sftvsa - ok
12:40:39.0072 0x08dc SharedAccess - ok
12:40:39.0150 0x08dc ShellHWDetection - ok
12:40:39.0213 0x08dc shpamsvc - ok
12:40:39.0229 0x08dc SiSRaid2 - ok
12:40:39.0244 0x08dc SiSRaid4 - ok
12:40:39.0260 0x08dc smphost - ok
12:40:39.0275 0x08dc SmsRouter - ok
12:40:39.0322 0x08dc SNMPTRAP - ok
12:40:39.0354 0x08dc spaceport - ok
12:40:39.0369 0x08dc SpbCx - ok
12:40:39.0385 0x08dc Spooler - ok
12:40:39.0432 0x08dc sppsvc - ok
12:40:39.0432 0x08dc srv - ok
12:40:39.0447 0x08dc srv2 - ok
12:40:39.0463 0x08dc srvnet - ok
12:40:39.0479 0x08dc SSDPSRV - ok
12:40:39.0494 0x08dc SstpSvc - ok
12:40:39.0525 0x08dc StateRepository - ok
12:40:39.0525 0x08dc stexstor - ok
12:40:39.0558 0x08dc stisvc - ok
12:40:39.0574 0x08dc storahci - ok
12:40:39.0589 0x08dc storflt - ok
12:40:39.0605 0x08dc stornvme - ok
12:40:39.0621 0x08dc storqosflt - ok
12:40:39.0636 0x08dc StorSvc - ok
12:40:39.0636 0x08dc storufs - ok
12:40:39.0652 0x08dc storvsc - ok
12:40:39.0668 0x08dc svsvc - ok
12:40:39.0683 0x08dc swenum - ok
12:40:39.0699 0x08dc swprv - ok
12:40:39.0714 0x08dc Synth3dVsc - ok
12:40:39.0714 0x08dc SysMain - ok
12:40:39.0746 0x08dc SystemEventsBroker - ok
12:40:39.0777 0x08dc TabletInputService - ok
12:40:39.0793 0x08dc TapiSrv - ok
12:40:39.0793 0x08dc Tcpip - ok
12:40:39.0808 0x08dc Tcpip6 - ok
12:40:39.0839 0x08dc tcpipreg - ok
12:40:39.0855 0x08dc tdx - ok
12:40:39.0871 0x08dc terminpt - ok
12:40:39.0886 0x08dc TermService - ok
12:40:39.0902 0x08dc Themes - ok
12:40:39.0933 0x08dc TieringEngineService - ok
12:40:39.0949 0x08dc tiledatamodelsvc - ok
12:40:39.0964 0x08dc TimeBrokerSvc - ok
12:40:39.0980 0x08dc TPM - ok
12:40:39.0996 0x08dc TrkWks - ok
12:40:40.0027 0x08dc TrustedInstaller - ok
12:40:40.0058 0x08dc tsusbflt - ok
12:40:40.0074 0x08dc TsUsbGD - ok
12:40:40.0089 0x08dc tsusbhub - ok
12:40:40.0089 0x08dc tunnel - ok
12:40:40.0105 0x08dc tzautoupdate - ok
12:40:40.0121 0x08dc UASPStor - ok
12:40:40.0136 0x08dc UcmCx0101 - ok
12:40:40.0152 0x08dc UcmTcpciCx0101 - ok
12:40:40.0168 0x08dc UcmUcsi - ok
12:40:40.0183 0x08dc Ucx01000 - ok
12:40:40.0199 0x08dc UdeCx - ok
12:40:40.0199 0x08dc udfs - ok
12:40:40.0214 0x08dc UEFI - ok
12:40:40.0230 0x08dc UevAgentDriver - ok
12:40:40.0246 0x08dc UevAgentService - ok
12:40:40.0261 0x08dc Ufx01000 - ok
12:40:40.0277 0x08dc UfxChipidea - ok
12:40:40.0293 0x08dc ufxsynopsys - ok
12:40:40.0324 0x08dc UI0Detect - ok
12:40:40.0339 0x08dc umbus - ok
12:40:40.0355 0x08dc UmPass - ok
12:40:40.0371 0x08dc UmRdpService - ok
12:40:40.0386 0x08dc UnistoreSvc - ok
12:40:40.0402 0x08dc upnphost - ok
12:40:40.0418 0x08dc UrsChipidea - ok
12:40:40.0433 0x08dc UrsCx01000 - ok
12:40:40.0449 0x08dc UrsSynopsys - ok
12:40:40.0464 0x08dc usbccgp - ok
12:40:40.0480 0x08dc usbcir - ok
12:40:40.0496 0x08dc usbehci - ok
12:40:40.0543 0x08dc [ 504901430B6E03B99EBB6BF26E0868C6, D00C0904B7008305DCA5D1E6FED153DD8875CAD14D80348E59F42A182FA7E832 ] usbfilter C:\WINDOWS\system32\DRIVERS\usbfilter.sys
12:40:40.0543 0x08dc usbfilter - ok
12:40:40.0558 0x08dc usbhub - ok
12:40:40.0574 0x08dc USBHUB3 - ok
12:40:40.0574 0x08dc usbohci - ok
12:40:40.0589 0x08dc usbprint - ok
12:40:40.0652 0x08dc [ 2EC7B2C8123236B1233A77281D378DF7, D97DB59C9CAE2B8B33C707E8CEA7A65BF88712842CC715D270F7432A99D21BB6 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
12:40:40.0652 0x08dc usbscan - ok
12:40:40.0683 0x08dc usbser - ok
12:40:40.0699 0x08dc USBSTOR - ok
12:40:40.0714 0x08dc usbuhci - ok
12:40:40.0730 0x08dc USBXHCI - ok
12:40:40.0746 0x08dc UserDataSvc - ok
12:40:40.0777 0x08dc UserManager - ok
12:40:40.0793 0x08dc UsoSvc - ok
12:40:40.0808 0x08dc VaultSvc - ok
12:40:40.0808 0x08dc vdrvroot - ok
12:40:40.0824 0x08dc vds - ok
12:40:40.0839 0x08dc VerifierExt - ok
12:40:40.0855 0x08dc vhdmp - ok
12:40:40.0871 0x08dc vhf - ok
12:40:40.0886 0x08dc vmbus - ok
12:40:40.0902 0x08dc VMBusHID - ok
12:40:40.0918 0x08dc vmgid - ok
12:40:40.0933 0x08dc vmicguestinterface - ok
12:40:40.0949 0x08dc vmicheartbeat - ok
12:40:40.0964 0x08dc vmickvpexchange - ok
12:40:40.0980 0x08dc vmicrdv - ok
12:40:40.0996 0x08dc vmicshutdown - ok
12:40:41.0011 0x08dc vmictimesync - ok
12:40:41.0027 0x08dc vmicvmsession - ok
12:40:41.0043 0x08dc vmicvss - ok
12:40:41.0043 0x08dc volmgr - ok
12:40:41.0058 0x08dc volmgrx - ok
12:40:41.0074 0x08dc volsnap - ok
12:40:41.0089 0x08dc volume - ok
12:40:41.0105 0x08dc vpci - ok
12:40:41.0121 0x08dc vsmraid - ok
12:40:41.0136 0x08dc VSS - ok
12:40:41.0152 0x08dc VSTXRAID - ok
12:40:41.0168 0x08dc vwifibus - ok
12:40:41.0183 0x08dc vwififlt - ok
12:40:41.0199 0x08dc vwifimp - ok
12:40:41.0214 0x08dc W32Time - ok
12:40:41.0246 0x08dc w3logsvc - ok
12:40:41.0261 0x08dc W3SVC - ok
12:40:41.0277 0x08dc WacomPen - ok
12:40:41.0293 0x08dc WalletService - ok
12:40:41.0308 0x08dc wanarp - ok
12:40:41.0324 0x08dc wanarpv6 - ok
12:40:41.0339 0x08dc WAS - ok
12:40:41.0355 0x08dc wbengine - ok
12:40:41.0371 0x08dc WbioSrvc - ok
12:40:41.0386 0x08dc wcifs - ok
12:40:41.0402 0x08dc Wcmsvc - ok
12:40:41.0418 0x08dc wcncsvc - ok
12:40:41.0433 0x08dc wcnfs - ok
12:40:41.0449 0x08dc WdBoot - ok
12:40:41.0464 0x08dc Wdf01000 - ok
12:40:41.0480 0x08dc WdFilter - ok
12:40:41.0496 0x08dc WdiServiceHost - ok
12:40:41.0511 0x08dc WdiSystemHost - ok
12:40:41.0527 0x08dc wdiwifi - ok
12:40:41.0543 0x08dc WdNisDrv - ok
12:40:41.0589 0x08dc WdNisSvc - ok
12:40:41.0605 0x08dc WebClient - ok
12:40:41.0621 0x08dc Wecsvc - ok
12:40:41.0636 0x08dc WEPHOSTSVC - ok
12:40:41.0652 0x08dc wercplsupport - ok
12:40:41.0668 0x08dc WerSvc - ok
12:40:41.0683 0x08dc WFPLWFS - ok
12:40:41.0699 0x08dc WiaRpc - ok
12:40:41.0714 0x08dc WIMMount - ok
12:40:41.0730 0x08dc WinDefend - ok
12:40:41.0777 0x08dc WindowsTrustedRT - ok
12:40:41.0793 0x08dc WindowsTrustedRTProxy - ok
12:40:41.0808 0x08dc WinHttpAutoProxySvc - ok
12:40:41.0824 0x08dc WinMad - ok
12:40:41.0871 0x08dc Winmgmt - ok
12:40:41.0902 0x08dc WinRM - ok
12:40:41.0933 0x08dc WINUSB - ok
12:40:41.0949 0x08dc WinVerbs - ok
12:40:41.0996 0x08dc wisvc - ok
12:40:42.0011 0x08dc WlanSvc - ok
12:40:42.0027 0x08dc wlidsvc - ok
12:40:42.0043 0x08dc WmiAcpi - ok
12:40:42.0074 0x08dc wmiApSrv - ok
12:40:42.0089 0x08dc WMPNetworkSvc - ok
12:40:42.0105 0x08dc Wof - ok
12:40:42.0152 0x08dc workfolderssvc - ok
12:40:42.0168 0x08dc WPDBusEnum - ok
12:40:42.0183 0x08dc WpdUpFltr - ok
12:40:42.0199 0x08dc WpnService - ok
12:40:42.0230 0x08dc WpnUserService - ok
12:40:42.0261 0x08dc ws2ifsl - ok
12:40:42.0277 0x08dc wscsvc - ok
12:40:42.0293 0x08dc WSDPrintDevice - ok
12:40:42.0324 0x08dc WSDScan - ok
12:40:42.0339 0x08dc WSearch - ok
12:40:42.0371 0x08dc wuauserv - ok
12:40:42.0386 0x08dc WudfPf - ok
12:40:42.0402 0x08dc WUDFRd - ok
12:40:42.0418 0x08dc wudfsvc - ok
12:40:42.0433 0x08dc WUDFWpdFs - ok
12:40:42.0449 0x08dc WwanSvc - ok
12:40:42.0464 0x08dc XblAuthManager - ok
12:40:42.0511 0x08dc XblGameSave - ok
12:40:42.0527 0x08dc xboxgip - ok
12:40:42.0543 0x08dc XboxNetApiSvc - ok
12:40:42.0574 0x08dc xinputhid - ok
12:40:42.0574 0x08dc ================ Scan global ===============================
12:40:42.0621 0x08dc [ Global ] - ok
12:40:42.0621 0x08dc ================ Scan MBR ==================================
12:40:42.0636 0x08dc [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:40:42.0902 0x08dc \Device\Harddisk0\DR0 - ok
12:40:42.0902 0x08dc ================ Scan VBR ==================================
12:40:42.0902 0x08dc [ FD1661D6FD0C1EC9F5E07690FC6169AC ] \Device\Harddisk0\DR0\Partition1
12:40:42.0902 0x08dc \Device\Harddisk0\DR0\Partition1 - ok
12:40:42.0902 0x08dc [ 7A005585AE923AD605CC4CA880B78B6B ] \Device\Harddisk0\DR0\Partition2
12:40:42.0918 0x08dc \Device\Harddisk0\DR0\Partition2 - ok
12:40:42.0918 0x08dc ================ Scan generic autorun ======================
12:40:43.0074 0x08dc [ CC80E38697767130DE26E57AAB0264B1, 1487B0818B921057DCEB03EE40F0102900DC65CA7C25E2B94D9292EE06F48EBF ] C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\AAV_Guard.exe
12:40:43.0168 0x08dc Ashampoo Anti-Virus Guard - ok
12:40:43.0277 0x08dc [ 4C6AAABB264526A9C845A39AEBB79B69, B27F869E8B44CC5F1F9ADCA53AA848C16D706587ED9C7F995AE59BF9B0426523 ] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe
12:40:43.0308 0x08dc StartCCC - ok
12:40:43.0402 0x08dc [ F17FFAF69E1AF3D0A010FD4749148981, 7486A1EFE378BFCEE30D169BD0189CABD6935EBEE556BF0328330B120975EA03 ] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
12:40:43.0464 0x08dc EEventManager - ok
12:40:43.0543 0x08dc OneDriveSetup - ok
12:40:43.0543 0x08dc OneDriveSetup - ok
12:40:43.0683 0x08dc [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] C:\Users\User\AppData\Local\Google\Update\GoogleUpdate.exe
12:40:43.0699 0x08dc Google Update - ok
12:40:43.0761 0x08dc [ 8F2EA5EE0695CCE2285D92C44108375C, 2C96A8E7E41E87C27B6A3325526F99A03333357EF2682C17A4892BE4A58D157E ] C:\Users\User\AppData\Local\Microsoft\OneDrive\OneDrive.exe
12:40:43.0808 0x08dc OneDrive - ok
12:40:44.0058 0x08dc [ E93D62A6DB736AA82A3EEDDFDFE73311, 96EC57F66EE1A36580536518A814299DE6D5DACC0026F5A659B41918434ED8FA ] C:\Program Files\CCleaner\CCleaner64.exe
12:40:44.0199 0x08dc CCleaner Monitoring - ok
12:40:44.0308 0x08dc [ 29F2EB3936BD71EC68B87330E3286E2C, 7CEAFDF28F34ED91DA061DD1FC5AC2C9BC019FDA7B65D68B1EA47FAED21D3BE1 ] C:\Program Files (x86)\COMPUTER BILD Account-Alarm\COMPUTER BILD Account-Alarm.exe
12:40:44.0386 0x08dc COMPUTER BILD Account-Alarm - ok
12:40:44.0496 0x08dc [ 716F5828497A7739B1BCCEE4D0E8A80F, D9D3BB3910AD9A5B43E3AFAEBABB474975F30F0C7B82B035B82F39D4B54F7C33 ] C:\Program Files\Zoner\Photo Studio 16\Program32\ZPSTRAY.EXE
12:40:44.0511 0x08dc Zoner Photo Studio Autoupdate - ok
12:40:44.0683 0x08dc [ EFC73875D6A2DECAD030633A9A75F00A, AA7B65649B37FFC68A6FFB23CBBE73E1BB873C840B9EA0049421D2B4C0EC364F ] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILHE.EXE
12:40:44.0683 0x08dc EPLTarget\P0000000000000000 - ok
12:40:44.0761 0x08dc [ EFC73875D6A2DECAD030633A9A75F00A, AA7B65649B37FFC68A6FFB23CBBE73E1BB873C840B9EA0049421D2B4C0EC364F ] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_IATILGE.EXE
12:40:44.0761 0x08dc EPLTarget\P0000000000000001 - ok
12:40:44.0761 0x08dc OneDriveSetup - ok
12:40:44.0793 0x08dc WAB Migrate - ok
12:40:44.0793 0x08dc Waiting for KSN requests completion. In queue: 21
12:40:45.0908 0x08dc AV detected via SS2: Ashampoo Anti-Virus, C:\Program Files (x86)\Ashampoo\Ashampoo Anti-Virus\AAV_WSC_Control.exe ( 1.10.0.0 ), 0x41000 ( enabled : updated )
12:40:45.0939 0x08dc AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
12:40:45.0970 0x08dc Win FW state via NFP2: enabled ( trusted )
12:40:46.0174 0x08dc ============================================================
12:40:46.0174 0x08dc Scan finished
12:40:46.0174 0x08dc ============================================================
12:40:46.0189 0x0704 Detected object count: 0
12:40:46.0189 0x0704 Actual detected object count: 0
12:40:56.0743 0x1ba8 Deinitialize success
LG regime55 |