querotudo | 10.12.2016 16:41 | Hi Cosinus,
natürlich hattest Du wieder Recht. Ich hatte beim ersten Versuch auch die additional Options nicht gesetzt. Der gefundene Threat gehört zu einem medizinischen Blutzuckermessgerät der Firma Abbott mit dem Namen Freestyle Libre.
Hier das Log: Code:
16:28:09.0921 0x13b14 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
16:28:20.0738 0x13b14 ============================================================
16:28:20.0738 0x13b14 Current date / time: 2016/12/10 16:28:20.0738
16:28:20.0738 0x13b14 SystemInfo:
16:28:20.0739 0x13b14
16:28:20.0739 0x13b14 OS Version: 10.0.14393 ServicePack: 0.0
16:28:20.0739 0x13b14 Product type: Workstation
16:28:20.0739 0x13b14 ComputerName: NORMAN-PC
16:28:20.0739 0x13b14 UserName: Norman
16:28:20.0739 0x13b14 Windows directory: C:\WINDOWS
16:28:20.0739 0x13b14 System windows directory: C:\WINDOWS
16:28:20.0739 0x13b14 Running under WOW64
16:28:20.0739 0x13b14 Processor architecture: Intel x64
16:28:20.0739 0x13b14 Number of processors: 8
16:28:20.0739 0x13b14 Page size: 0x1000
16:28:20.0739 0x13b14 Boot type: Normal boot
16:28:20.0739 0x13b14 CodeIntegrityOptions = 0x00000001
16:28:20.0739 0x13b14 ============================================================
16:28:21.0313 0x13b14 KLMD registered as C:\WINDOWS\system32\drivers\63854804.sys
16:28:21.0313 0x13b14 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.447, osProperties = 0x19
16:28:23.0345 0x13b14 System UUID: {06DBFE8A-9413-C582-4869-9E8D551D7782}
16:28:23.0978 0x13b14 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:28:24.0216 0x13b14 Drive \Device\Harddisk1\DR1 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
16:28:25.0406 0x13b14 ============================================================
16:28:25.0406 0x13b14 \Device\Harddisk0\DR0:
16:28:25.0415 0x13b14 MBR partitions:
16:28:25.0416 0x13b14 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x32FCD, BlocksNum 0x1D4C000
16:28:25.0416 0x13b14 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1D7EFCD, BlocksNum 0x3245F536
16:28:25.0458 0x13b14 \Device\Harddisk1\DR1:
16:28:25.0458 0x13b14 GPT partitions:
16:28:25.0458 0x13b14 \Device\Harddisk1\DR1\Partition1: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {57312DE8-56A7-4CAD-B465-E359A89236E2}, Name: Microsoft reserved partition, StartLBA 0x22, BlocksNum 0x40000
16:28:25.0458 0x13b14 \Device\Harddisk1\DR1\Partition2: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {CF4B67B6-8BB9-44C4-982B-81375847DC13}, Name: Basic data partition, StartLBA 0x40800, BlocksNum 0xE8DC8000
16:28:25.0458 0x13b14 MBR partitions:
16:28:25.0458 0x13b14 ============================================================
16:28:25.0525 0x13b14 C: <-> \Device\Harddisk0\DR0\Partition2
16:28:25.0558 0x13b14 D: <-> \Device\Harddisk1\DR1\Partition2
16:28:25.0558 0x13b14 ============================================================
16:28:25.0558 0x13b14 Initialize success
16:28:25.0558 0x13b14 ============================================================
16:29:39.0302 0x13b20 ============================================================
16:29:39.0302 0x13b20 Scan started
16:29:39.0302 0x13b20 Mode: Manual; SigCheck; TDLFS;
16:29:39.0302 0x13b20 ============================================================
16:29:39.0302 0x13b20 KSN ping started
16:29:39.0355 0x13b20 KSN ping finished: true
16:29:42.0104 0x13b20 ================ Scan system memory ========================
16:29:42.0104 0x13b20 System memory - ok
16:29:42.0104 0x13b20 ================ Scan services =============================
16:29:42.0356 0x13b20 1394ohci - ok
16:29:42.0356 0x13b20 3ware - ok
16:29:42.0387 0x13b20 ACPI - ok
16:29:42.0403 0x13b20 AcpiDev - ok
16:29:42.0403 0x13b20 acpiex - ok
16:29:42.0403 0x13b20 acpipagr - ok
16:29:42.0425 0x13b20 AcpiPmi - ok
16:29:42.0441 0x13b20 acpitime - ok
16:29:42.0591 0x13b20 [ C92B0A0957ACAD3CEEF502A2CA10ACB8, 78BF46318B69D9479ECDC83446DD8D454AA2A9A9D94B33C5FC68933DB18AFA3B ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
16:29:42.0678 0x13b20 AdobeARMservice - ok
16:29:42.0858 0x13b20 [ 9BAF21BA600EC4E5FD9A66AD3E4FF5A6, 5E02E5E80557F6EC870EB7CC2DE95169D4225B87A2FE7E796736205F51C15816 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
16:29:42.0890 0x13b20 AdobeFlashPlayerUpdateSvc - ok
16:29:42.0905 0x13b20 ADP80XX - ok
16:29:42.0963 0x13b20 [ 8621B8CDE2A07112CD723F37D669C0BF, 36FC0B125A0576296FA1F99EEB64D87C8D77FA54CF7D92907A6F6B48E0859FD5 ] AERTFilters C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
16:29:43.0009 0x13b20 AERTFilters - ok
16:29:43.0009 0x13b20 AFD - ok
16:29:43.0032 0x13b20 ahcache - ok
16:29:43.0063 0x13b20 AJRouter - ok
16:29:43.0063 0x13b20 ALG - ok
16:29:43.0078 0x13b20 AmdK8 - ok
16:29:43.0078 0x13b20 AmdPPM - ok
16:29:43.0078 0x13b20 amdsata - ok
16:29:43.0078 0x13b20 amdsbs - ok
16:29:43.0078 0x13b20 amdxata - ok
16:29:43.0110 0x13b20 [ 4DE4BE679205B3A712562507AEE75227, 1C40F14A2BFFFB8E9646B57419D9F810A86D0DCD94F9DE9D9851D498F86F343E ] AMPPAL C:\WINDOWS\System32\drivers\AMPPAL.sys
16:29:43.0163 0x13b20 AMPPAL - ok
16:29:43.0179 0x13b20 AppID - ok
16:29:43.0179 0x13b20 AppIDSvc - ok
16:29:43.0210 0x13b20 Appinfo - ok
16:29:43.0229 0x13b20 applockerfltr - ok
16:29:43.0232 0x13b20 AppMgmt - ok
16:29:43.0248 0x13b20 AppReadiness - ok
16:29:43.0263 0x13b20 AppVClient - ok
16:29:43.0279 0x13b20 AppvStrm - ok
16:29:43.0310 0x13b20 AppvVemgr - ok
16:29:43.0332 0x13b20 AppvVfs - ok
16:29:43.0364 0x13b20 AppXSvc - ok
16:29:43.0379 0x13b20 arcsas - ok
16:29:43.0379 0x13b20 AsyncMac - ok
16:29:43.0395 0x13b20 atapi - ok
16:29:43.0411 0x13b20 AudioEndpointBuilder - ok
16:29:43.0433 0x13b20 Audiosrv - ok
16:29:43.0465 0x13b20 Avira.ServiceHost - ok
16:29:43.0497 0x13b20 AxInstSV - ok
16:29:43.0514 0x13b20 b06bdrv - ok
16:29:43.0537 0x13b20 BasicDisplay - ok
16:29:43.0540 0x13b20 BasicRender - ok
16:29:43.0545 0x13b20 bcmfn - ok
16:29:43.0549 0x13b20 bcmfn2 - ok
16:29:43.0563 0x13b20 BDESVC - ok
16:29:43.0566 0x13b20 Beep - ok
16:29:43.0581 0x13b20 BFE - ok
16:29:43.0594 0x13b20 BITS - ok
16:29:43.0607 0x13b20 bowser - ok
16:29:43.0697 0x13b20 [ 91A907624140CB092E95F157540A74C2, A8562D1C065EEF114E8D2736AB4E6A02D3EB76C9F75A7ACD75AC196A75752AAE ] BrcmSetSecurity C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
16:29:43.0722 0x13b20 BrcmSetSecurity - ok
16:29:43.0742 0x13b20 BrokerInfrastructure - ok
16:29:43.0745 0x13b20 Browser - ok
16:29:43.0751 0x13b20 BthA2DP - ok
16:29:43.0766 0x13b20 BthAvrcpTg - ok
16:29:43.0798 0x13b20 BthEnum - ok
16:29:43.0833 0x13b20 BthHFAud - ok
16:29:43.0849 0x13b20 BthHFEnum - ok
16:29:43.0864 0x13b20 bthhfhid - ok
16:29:43.0880 0x13b20 BthHFSrv - ok
16:29:43.0880 0x13b20 BTHMODEM - ok
16:29:43.0911 0x13b20 BthPan - ok
16:29:43.0932 0x13b20 BTHPORT - ok
16:29:43.0932 0x13b20 bthserv - ok
16:29:43.0964 0x13b20 BTHUSB - ok
16:29:44.0049 0x13b20 [ 7B31A8A9DC95B3634D896FD0F2814F19, 8FD5FBC61968F4BB8C2BAD0D432D5B86DCFED38CCF6F559F9EFB71AADD25474F ] btmhsf C:\WINDOWS\system32\DRIVERS\btmhsf.sys
16:29:44.0080 0x13b20 btmhsf - ok
16:29:44.0095 0x13b20 buttonconverter - ok
16:29:44.0111 0x13b20 CapImg - ok
16:29:44.0111 0x13b20 cdfs - ok
16:29:44.0133 0x13b20 CDPSvc - ok
16:29:44.0133 0x13b20 CDPUserSvc - ok
16:29:44.0211 0x13b20 cdrom - ok
16:29:44.0229 0x13b20 CertPropSvc - ok
16:29:44.0233 0x13b20 cht4iscsi - ok
16:29:44.0233 0x13b20 cht4vbd - ok
16:29:44.0249 0x13b20 circlass - ok
16:29:44.0249 0x13b20 CLFS - ok
16:29:44.0249 0x13b20 ClipSVC - ok
16:29:44.0265 0x13b20 clreg - ok
16:29:44.0265 0x13b20 CmBatt - ok
16:29:44.0265 0x13b20 CNG - ok
16:29:44.0280 0x13b20 cnghwassist - ok
16:29:44.0333 0x13b20 CompositeBus - ok
16:29:44.0348 0x13b20 COMSysApp - ok
16:29:44.0348 0x13b20 condrv - ok
16:29:44.0380 0x13b20 CoreMessagingRegistrar - ok
16:29:44.0519 0x13b20 [ B18D590BC5220FDB4A747BC16D78ABC7, D46F8B43BAC22E55DE9AFC19CF371B1C4E8D3707163598B2F9884BB31D730C09 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
16:29:44.0656 0x13b20 cphs - ok
16:29:44.0678 0x13b20 CryptSvc - ok
16:29:44.0682 0x13b20 CSC - ok
16:29:44.0685 0x13b20 CscService - ok
16:29:44.0722 0x13b20 [ FBE228ABEAB2BE13B9C3A3A112D4D8DC, A9FF2DC38CBE00AAD904BB7EC74480953D513E46FDE607A7773FF5A2A25B8C15 ] CtClsFlt C:\WINDOWS\system32\DRIVERS\CtClsFlt.sys
16:29:44.0813 0x13b20 CtClsFlt - ok
16:29:44.0835 0x13b20 dam - ok
16:29:44.0835 0x13b20 DcomLaunch - ok
16:29:44.0835 0x13b20 DcpSvc - ok
16:29:44.0850 0x13b20 defragsvc - ok
16:29:44.0866 0x13b20 DeviceAssociationService - ok
16:29:44.0882 0x13b20 DeviceInstall - ok
16:29:44.0897 0x13b20 DevQueryBroker - ok
16:29:44.0913 0x13b20 Dfsc - ok
16:29:44.0950 0x13b20 [ 73BDD44A6088916964945886F9025409, 8E2ECC9AAEF3C6EBA2E61D25F657FDFCC72AB517CC4FD5FFF992E1F9EB942662 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
16:29:44.0982 0x13b20 dg_ssudbus - ok
16:29:45.0050 0x13b20 Dhcp - ok
16:29:45.0130 0x13b20 diagnosticshub.standardcollector.service - ok
16:29:45.0150 0x13b20 DiagTrack - ok
16:29:45.0181 0x13b20 DIRECTIO - ok
16:29:45.0213 0x13b20 disk - ok
16:29:45.0235 0x13b20 DmEnrollmentSvc - ok
16:29:45.0235 0x13b20 dmvsc - ok
16:29:45.0250 0x13b20 dmwappushservice - ok
16:29:45.0266 0x13b20 Dnscache - ok
16:29:45.0266 0x13b20 dot3svc - ok
16:29:45.0282 0x13b20 DPS - ok
16:29:45.0297 0x13b20 drmkaud - ok
16:29:45.0350 0x13b20 [ 1ED08A6264C5C92099D6D1DAE5E8F530, 4045AE77859B1DBF13972451972EAAF6F3C97BEA423E9E78F1C2F14330CD47CA ] DrvAgent64 C:\WINDOWS\SysWOW64\Drivers\DrvAgent64.SYS
16:29:45.0413 0x13b20 DrvAgent64 - ok
16:29:45.0429 0x13b20 DsmSvc - ok
16:29:45.0433 0x13b20 DsSvc - ok
16:29:45.0435 0x13b20 DXGKrnl - ok
16:29:45.0435 0x13b20 EapHost - ok
16:29:45.0451 0x13b20 ebdrv - ok
16:29:45.0451 0x13b20 EFS - ok
16:29:45.0451 0x13b20 EhStorClass - ok
16:29:45.0467 0x13b20 EhStorTcgDrv - ok
16:29:45.0482 0x13b20 [ BE2902E13CA69383F449B6BF927844FB, F092785E305D8E1FE795AF98A7A7B7B4548A0D6687060568C9E078FFA8D65C1C ] ElbyCDIO C:\WINDOWS\system32\Drivers\ElbyCDIO.sys
16:29:45.0499 0x13b20 ElbyCDIO - ok
16:29:45.0505 0x13b20 embeddedmode - ok
16:29:45.0523 0x13b20 EntAppSvc - ok
16:29:45.0573 0x13b20 [ D315FF43E23DF424ECEC2F6C930203E4, 68940EDA34DC4945CDD0D8018D96A0DA8F99F16A930946D14E4FECEE033FCB80 ] EpsonScanSvc C:\WINDOWS\system32\EscSvc64.exe
16:29:45.0587 0x13b20 EpsonScanSvc - ok
16:29:45.0590 0x13b20 ErrDev - ok
16:29:45.0602 0x13b20 EventSystem - ok
16:29:45.0605 0x13b20 exfat - ok
16:29:45.0607 0x13b20 fastfat - ok
16:29:45.0625 0x13b20 Fax - ok
16:29:45.0629 0x13b20 fdc - ok
16:29:45.0633 0x13b20 fdPHost - ok
16:29:45.0636 0x13b20 FDResPub - ok
16:29:45.0647 0x13b20 fhsvc - ok
16:29:45.0664 0x13b20 FileCrypt - ok
16:29:45.0667 0x13b20 FileInfo - ok
16:29:45.0671 0x13b20 Filetrace - ok
16:29:45.0788 0x13b20 [ F76D04F7413B07DAA029F6520B64B4E8, 3EB13C0EFE737880853FB8952381E7A57723F9472E0E4ED7CDA8A0D7DE8DC90D ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
16:29:45.0836 0x13b20 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic ( 1 )
16:29:45.0899 0x13b20 Detect skipped due to KSN trusted
16:29:45.0915 0x13b20 FLEXnet Licensing Service - ok
16:29:45.0915 0x13b20 flpydisk - ok
16:29:45.0937 0x13b20 FltMgr - ok
16:29:45.0952 0x13b20 FontCache - ok
16:29:46.0052 0x13b20 FontCache3.0.0.0 - ok
16:29:46.0084 0x13b20 FrameServer - ok
16:29:46.0168 0x13b20 [ 566677EC7238F505557F310691CCEDED, 346E01BC92D9B09560CA4FB769E325A33EA549649FD18D639E7C42F225B37235 ] FreeStyleLibre MAS Server C:\Program Files (x86)\FreeStyle Libre\FreeStyle Libre\MAS.FreeStyleLibre.exe
16:29:46.0268 0x13b20 FreeStyleLibre MAS Server - detected UnsignedFile.Multi.Generic ( 1 )
16:29:46.0415 0x13b20 FreeStyleLibre MAS Server ( UnsignedFile.Multi.Generic ) - warning
16:29:46.0537 0x13b20 FsDepends - ok
16:29:46.0537 0x13b20 Fs_Rec - ok
16:29:46.0537 0x13b20 fvevol - ok
16:29:46.0576 0x13b20 [ 8E98D21EE06192492A5671A6144D092F, B8F656B34D361EA5AFB47F3A67AB2221580DADA59C8CD0CB83181E4AD8B562B4 ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
16:29:46.0584 0x13b20 GEARAspiWDM - ok
16:29:46.0606 0x13b20 gencounter - ok
16:29:46.0623 0x13b20 genericusbfn - ok
16:29:46.0745 0x13b20 [ F78BC07DCED5EDDD6D477E923620F8EA, ABE28155100A38A5E1B58FFC8099EF416145278B440A67B8DAFD7715FE412624 ] GfExperienceService C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
16:29:46.0790 0x13b20 GfExperienceService - ok
16:29:46.0820 0x13b20 [ B93252C4C5A3733ECD5522CAF88DE02D, 382450F0FF238B6077A78F75AC5D4E53AD7D884706B90E7AC4D4DF467C9A2162 ] GigasetGenericUSB_x64 C:\WINDOWS\system32\DRIVERS\GigasetGenericUSB_x64.sys
16:29:46.0900 0x13b20 GigasetGenericUSB_x64 - ok
16:29:46.0938 0x13b20 GPIOClx0101 - ok
16:29:46.0953 0x13b20 gpsvc - ok
16:29:46.0953 0x13b20 GpuEnergyDrv - ok
16:29:47.0038 0x13b20 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:29:47.0069 0x13b20 gupdate - ok
16:29:47.0101 0x13b20 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
16:29:47.0137 0x13b20 gupdatem - ok
16:29:47.0200 0x13b20 HDAudBus - ok
16:29:47.0200 0x13b20 HidBatt - ok
16:29:47.0238 0x13b20 HidBth - ok
16:29:47.0254 0x13b20 hidi2c - ok
16:29:47.0254 0x13b20 hidinterrupt - ok
16:29:47.0254 0x13b20 HidIr - ok
16:29:47.0285 0x13b20 hidserv - ok
16:29:47.0300 0x13b20 HidUsb - ok
16:29:47.0334 0x13b20 HomeGroupListener - ok
16:29:47.0338 0x13b20 HomeGroupProvider - ok
16:29:47.0353 0x13b20 HpSAMD - ok
16:29:47.0353 0x13b20 HTTP - ok
16:29:47.0385 0x13b20 HvHost - ok
16:29:47.0400 0x13b20 hvservice - ok
16:29:47.0416 0x13b20 hwpolicy - ok
16:29:47.0416 0x13b20 hyperkbd - ok
16:29:47.0453 0x13b20 [ 45E0F744B0887E2701B1C59DC86147EC, 04EB75A07B2949AB994F355BBEE33DE2069F94504D738DC7E66ABB1C9F1C31C8 ] i8042HDR C:\WINDOWS\system32\DRIVERS\i8042HDR.sys
16:29:47.0485 0x13b20 i8042HDR - ok
16:29:47.0500 0x13b20 i8042prt - ok
16:29:47.0500 0x13b20 iagpio - ok
16:29:47.0500 0x13b20 iai2c - ok
16:29:47.0516 0x13b20 iaLPSS2i_GPIO2 - ok
16:29:47.0516 0x13b20 iaLPSS2i_I2C - ok
16:29:47.0516 0x13b20 iaLPSSi_GPIO - ok
16:29:47.0516 0x13b20 iaLPSSi_I2C - ok
16:29:47.0516 0x13b20 iaStorAV - ok
16:29:47.0534 0x13b20 iaStorV - ok
16:29:47.0537 0x13b20 ibbus - ok
16:29:47.0538 0x13b20 [ 33120C561E918A18DD48DEFEEEC0885D, F9F7E4610717532E25A2FFBFA507E3B7B0608BEC026FEA2EE0B530560F12F538 ] ibtfltcoex C:\WINDOWS\system32\DRIVERS\ibtfltcoex.sys
16:29:47.0556 0x13b20 ibtfltcoex - ok
16:29:47.0629 0x13b20 [ 83FF82FE209E7997067B375DAD6CF23D, E312DD068E51DBF96A8232D7D1C9F158652FDA23649655F1102928B320795091 ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
16:29:47.0650 0x13b20 ICCS - ok
16:29:47.0673 0x13b20 icssvc - ok
16:29:47.0860 0x13b20 [ 79AE3CC82CA1563A4B392207997ACE7C, A1E4A1DA95CA2FA197EF5975657822F0F813F6C33DA38E1FA5A840194034D071 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
16:29:48.0101 0x13b20 igfx - ok
16:29:48.0138 0x13b20 IKEEXT - ok
16:29:48.0170 0x13b20 [ DD587A55390ED2295BCE6D36AD567DA9, AEB7DCB8EF89BEE8D9649A05FC482B1E4E3F44243D57A2577C862EB69166C48E ] Impcd C:\WINDOWS\system32\DRIVERS\Impcd.sys
16:29:48.0239 0x13b20 Impcd - ok
16:29:48.0254 0x13b20 IndirectKmd - ok
16:29:48.0301 0x13b20 [ FD2032D2EAE8D7F3381EBA5FA3E7FEEA, 46D1DC6A44E20339AD9195EE7CC719DC9BC99C78F8C74E730B671F0D78B9C683 ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
16:29:48.0301 0x13b20 intaud_WaveExtensible - ok
16:29:48.0454 0x13b20 [ 622868E4BAE8FBCD22CB1A5901A2C824, C1A2264C0984DD16C83B663C9CE43E049E1356E32C5771C3ACE225F285699138 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
16:29:48.0636 0x13b20 IntcAzAudAddService - ok
16:29:48.0700 0x13b20 [ F5495B38BFB9149925F54F65AB40EFBF, 7CBB72C41E2343DACBFB967A39CA04788561EDECB289C41BC2D6A06B80882AC4 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
16:29:48.0765 0x13b20 IntcDAud - ok
16:29:48.0815 0x13b20 [ 441D5FAF24CC2EC115B654A55C52F0AF, 5BF5299DAD9A7076C43D68C70E02AEC8DBFD89C1AFDF7CD6AB95550EE25EEB36 ] Intel(R) Wireless Bluetooth(R) 4.0 Radio Management C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
16:29:48.0828 0x13b20 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management - ok
16:29:48.0837 0x13b20 intelide - ok
16:29:48.0858 0x13b20 intelpep - ok
16:29:48.0875 0x13b20 intelppm - ok
16:29:48.0875 0x13b20 iorate - ok
16:29:48.0875 0x13b20 IpFilterDriver - ok
16:29:48.0891 0x13b20 iphlpsvc - ok
16:29:48.0907 0x13b20 IPMIDRV - ok
16:29:48.0907 0x13b20 IPNAT - ok
16:29:49.0002 0x13b20 [ 4EFFC8FF6D349E971E94B1C670C0C66A, E92DA19CE9725BB4CC34DF94873C6B441AE61679A8C615780E1A1E9404C8FA26 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
16:29:49.0039 0x13b20 iPod Service - ok
16:29:49.0039 0x13b20 irda - ok
16:29:49.0039 0x13b20 IRENUM - ok
16:29:49.0055 0x13b20 irmon - ok
16:29:49.0055 0x13b20 isapnp - ok
16:29:49.0071 0x13b20 iScsiPrt - ok
16:29:49.0102 0x13b20 [ E56417C56B6A7316B6F527C890A1860D, 906F361967E56D8254A264E5005FA9F9251510311C88BD305BF92E66CA2E33B2 ] JMCR C:\WINDOWS\system32\DRIVERS\jmcr.sys
16:29:49.0155 0x13b20 JMCR - ok
16:29:49.0202 0x13b20 kbdclass - ok
16:29:49.0217 0x13b20 kbdhid - ok
16:29:49.0239 0x13b20 kdnic - ok
16:29:49.0239 0x13b20 KeyIso - ok
16:29:49.0239 0x13b20 KSecDD - ok
16:29:49.0255 0x13b20 KSecPkg - ok
16:29:49.0255 0x13b20 ksthunk - ok
16:29:49.0270 0x13b20 KtmRm - ok
16:29:49.0270 0x13b20 LanmanServer - ok
16:29:49.0286 0x13b20 LanmanWorkstation - ok
16:29:49.0286 0x13b20 lfsvc - ok
16:29:49.0286 0x13b20 LicenseManager - ok
16:29:49.0286 0x13b20 lltdio - ok
16:29:49.0302 0x13b20 lltdsvc - ok
16:29:49.0302 0x13b20 lmhosts - ok
16:29:49.0355 0x13b20 [ 7F32D4C47A50E7223491E8FB9359907D, 6D3F59A8D006BED3234697933D09C8EE8F7A9F4A4196CFA878F8E8A929B24CE5 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
16:29:49.0370 0x13b20 LMS - ok
16:29:49.0386 0x13b20 LSI_SAS - ok
16:29:49.0386 0x13b20 LSI_SAS2i - ok
16:29:49.0386 0x13b20 LSI_SAS3i - ok
16:29:49.0386 0x13b20 LSI_SSS - ok
16:29:49.0401 0x13b20 LSM - ok
16:29:49.0437 0x13b20 luafv - ok
16:29:49.0439 0x13b20 MapsBroker - ok
16:29:49.0455 0x13b20 megasas - ok
16:29:49.0471 0x13b20 megasas2i - ok
16:29:49.0471 0x13b20 megasr - ok
16:29:49.0502 0x13b20 [ E7C9F74D8CAAB1FF7964C27C070FB16C, 76CCD9109E1031A336B7E275368520FFB60D500E24444B04066F205D1ED5BA2B ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
16:29:49.0539 0x13b20 MEIx64 - ok
16:29:49.0570 0x13b20 MessagingService - ok
16:29:49.0667 0x13b20 Microsoft SharePoint Workspace Audit Service - ok
16:29:49.0677 0x13b20 mlx4_bus - ok
16:29:49.0688 0x13b20 MMCSS - ok
16:29:49.0698 0x13b20 Modem - ok
16:29:49.0732 0x13b20 monitor - ok
16:29:49.0746 0x13b20 mouclass - ok
16:29:49.0749 0x13b20 mouhid - ok
16:29:49.0753 0x13b20 mountmgr - ok
16:29:49.0755 0x13b20 mpsdrv - ok
16:29:49.0766 0x13b20 MpsSvc - ok
16:29:49.0808 0x13b20 MRxDAV - ok
16:29:49.0853 0x13b20 mrxsmb - ok
16:29:49.0866 0x13b20 mrxsmb10 - ok
16:29:49.0873 0x13b20 mrxsmb20 - ok
16:29:49.0882 0x13b20 MsBridge - ok
16:29:49.0893 0x13b20 MSDTC - ok
16:29:49.0898 0x13b20 Msfs - ok
16:29:49.0902 0x13b20 msgpiowin32 - ok
16:29:49.0906 0x13b20 mshidkmdf - ok
16:29:49.0908 0x13b20 mshidumdf - ok
16:29:49.0908 0x13b20 msisadrv - ok
16:29:49.0956 0x13b20 MSiSCSI - ok
16:29:49.0956 0x13b20 msiserver - ok
16:29:49.0972 0x13b20 MSKSSRV - ok
16:29:49.0987 0x13b20 MsLldp - ok
16:29:49.0987 0x13b20 MSPCLOCK - ok
16:29:49.0987 0x13b20 MSPQM - ok
16:29:49.0987 0x13b20 MsRPC - ok
16:29:50.0003 0x13b20 MsSecFlt - ok
16:29:50.0003 0x13b20 mssmbios - ok
16:29:50.0003 0x13b20 MSTEE - ok
16:29:50.0003 0x13b20 MTConfig - ok
16:29:50.0019 0x13b20 Mup - ok
16:29:50.0019 0x13b20 mvumis - ok
16:29:50.0118 0x13b20 [ A25648600888D412CCD2637071B08A04, 78FFF7F7F877EC5E4DC84C597E7639EBBCA9AE9F5B2F8C328022CD3E05E5F838 ] MyEpson Portal Service C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe
16:29:50.0203 0x13b20 MyEpson Portal Service - ok
16:29:50.0240 0x13b20 NativeWifiP - ok
16:29:50.0256 0x13b20 NcaSvc - ok
16:29:50.0256 0x13b20 NcbService - ok
16:29:50.0287 0x13b20 NcdAutoSetup - ok
16:29:50.0287 0x13b20 ndfltr - ok
16:29:50.0318 0x13b20 NDIS - ok
16:29:50.0334 0x13b20 NdisCap - ok
16:29:50.0356 0x13b20 NdisImPlatform - ok
16:29:50.0356 0x13b20 NdisTapi - ok
16:29:50.0356 0x13b20 Ndisuio - ok
16:29:50.0356 0x13b20 NdisVirtualBus - ok
16:29:50.0372 0x13b20 NdisWan - ok
16:29:50.0372 0x13b20 ndiswanlegacy - ok
16:29:50.0372 0x13b20 ndproxy - ok
16:29:50.0372 0x13b20 Ndu - ok
16:29:50.0387 0x13b20 NetAdapterCx - ok
16:29:50.0387 0x13b20 NetBIOS - ok
16:29:50.0387 0x13b20 NetBT - ok
16:29:50.0403 0x13b20 Netlogon - ok
16:29:50.0440 0x13b20 Netman - ok
16:29:50.0456 0x13b20 netprofm - ok
16:29:50.0519 0x13b20 NetSetupSvc - ok
16:29:50.0623 0x13b20 NetTcpPortSharing - ok
16:29:51.0004 0x13b20 [ DB8B323B4F2B46B32ECD2BAE7955E4AA, 89BC9F951B08A8566837DF442C95842061B921B79102A8AD2245783717355B34 ] NETwNs64 C:\WINDOWS\System32\drivers\NETwsw00.sys
16:29:51.0542 0x13b20 NETwNs64 - ok
16:29:51.0542 0x13b20 NgcCtnrSvc - ok
16:29:51.0558 0x13b20 NgcSvc - ok
16:29:51.0574 0x13b20 NlaSvc - ok
16:29:51.0574 0x13b20 Npfs - ok
16:29:51.0574 0x13b20 npsvctrig - ok
16:29:51.0589 0x13b20 nsi - ok
16:29:51.0589 0x13b20 nsiproxy - ok
16:29:51.0620 0x13b20 NTFS - ok
16:29:51.0620 0x13b20 Null - ok
16:29:51.0667 0x13b20 [ 708EDBC756B28B77D1F9C8844148125A, BA730BC3A70122CC3AD6CC4B398B747591F34E00ACEC06545C37A3F10FB56F5F ] NVHDA C:\WINDOWS\system32\drivers\nvhda64v.sys
16:29:51.0683 0x13b20 NVHDA - ok
16:29:52.0206 0x13b20 [ 0CD412D41220FEE9DD1166F7CE7B1DAB, 23CAB64C3DB3C90CAF2DE4100E192295B8F603B8347F8AC6FDC36C2C6D2520D2 ] nvlddmkm C:\WINDOWS\System32\DriverStore\FileRepository\nvdmi.inf_amd64_86f2ae812568c59a\nvlddmkm.sys
16:29:52.0661 0x13b20 nvlddmkm - ok
16:29:52.0854 0x13b20 [ 020F45E362D3B57CCC5735582BB1A6EC, E2D953CEF208528382153D06FED8394BEB52657C547E4D2D2954E537C9A382DC ] NvNetworkService C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
16:29:52.0928 0x13b20 NvNetworkService - ok
16:29:52.0944 0x13b20 [ 14632E55F8E76E3CEFFD058EC0A545E6, 563E4EFC171D5BFEC77BA43E0426A38759B13A8BCA9C6E135E9E0356BBE6D897 ] nvpciflt C:\WINDOWS\system32\DRIVERS\nvpciflt.sys
16:29:52.0953 0x13b20 nvpciflt - ok
16:29:52.0969 0x13b20 nvraid - ok
16:29:52.0969 0x13b20 nvstor - ok
16:29:53.0047 0x13b20 [ F82BCEB9F57B2959F6AAE2A3DDA892A8, 5B02C74BAF0E12B84F239B1449DAA955B28BD5BA7D35D315DB57F45E042E0DB3 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
16:29:53.0062 0x13b20 NvStreamKms - ok
16:29:53.0178 0x13b20 [ 9209D57C1AA24841EF8D5DE6A5B2AAEB, C1A53621F5361DCE9C962A9B9B586D1904901C9EC20EFCA76C40ADCD98BEDF3C ] NvStreamNetworkSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
16:29:53.0325 0x13b20 NvStreamNetworkSvc - ok
16:29:53.0447 0x13b20 [ 0EDF9504CA5174075BA5902AFC1F57C8, 8E210E71BA91813D3BB6B59E5F6AD0889711336AD12B1B1C67CCC882A6ED3E53 ] NvStreamSvc C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
16:29:53.0547 0x13b20 NvStreamSvc - ok
16:29:53.0594 0x13b20 [ 9E01B716C8085F7ADB1CDC10103CEEF8, A8ED454B5AEA0D412F561B99D630C16171D99AC1EC67D79CC4126FE8FC97E144 ] NvStUSB C:\WINDOWS\system32\DRIVERS\nvstusb.sys
16:29:53.0626 0x13b20 NvStUSB - ok
16:29:53.0720 0x13b20 [ BF83A0A7BF998693691349175CF8AC7D, 743DB4DED1372DEB48ACD741CCC4DC01A9755A6D3CDF4F3CB8F68AB1F69D2BFF ] nvsvc C:\WINDOWS\system32\nvvsvc.exe
16:29:53.0781 0x13b20 nvsvc - ok
16:29:53.0816 0x13b20 [ 38175904276F86EA4704EC13B77FB4B0, 4965BCF17E3D9EE4CE2E4DC158C5E7179C3ABBAE9D640FBCFFBCA973F21DDDF6 ] nvvad_WaveExtensible C:\WINDOWS\system32\drivers\nvvad64v.sys
16:29:53.0834 0x13b20 nvvad_WaveExtensible - ok
16:29:53.0864 0x13b20 OneSyncSvc - ok
16:29:53.0943 0x13b20 [ 4965B005492CBA7719E82B71E3245495, 52AD72C05FACC1E0E416A1FA25F34FDD3CB274FAB973BEAAE911A2FACA42B650 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:29:53.0986 0x13b20 ose64 - ok
16:29:54.0179 0x13b20 [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
16:29:54.0364 0x13b20 osppsvc - ok
16:29:54.0395 0x13b20 p2pimsvc - ok
16:29:54.0395 0x13b20 p2psvc - ok
16:29:54.0426 0x13b20 Parport - ok
16:29:54.0445 0x13b20 partmgr - ok
16:29:54.0448 0x13b20 PcaSvc - ok
16:29:54.0464 0x13b20 pci - ok
16:29:54.0495 0x13b20 pciide - ok
16:29:54.0495 0x13b20 pcmcia - ok
16:29:54.0511 0x13b20 pcw - ok
16:29:54.0543 0x13b20 pdc - ok
16:29:54.0549 0x13b20 PEAUTH - ok
16:29:54.0549 0x13b20 PeerDistSvc - ok
16:29:54.0564 0x13b20 percsas2i - ok
16:29:54.0580 0x13b20 percsas3i - ok
16:29:54.0649 0x13b20 PerfHost - ok
16:29:54.0703 0x13b20 PhoneSvc - ok
16:29:54.0727 0x13b20 PimIndexMaintenanceSvc - ok
16:29:54.0732 0x13b20 pla - ok
16:29:54.0740 0x13b20 PlugPlay - ok
16:29:54.0743 0x13b20 PNRPAutoReg - ok
16:29:54.0746 0x13b20 PNRPsvc - ok
16:29:54.0755 0x13b20 PolicyAgent - ok
16:29:54.0759 0x13b20 Power - ok
16:29:54.0763 0x13b20 PptpMiniport - ok
16:29:54.0940 0x13b20 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
16:29:55.0266 0x13b20 PrintNotify - ok
16:29:55.0281 0x13b20 Processor - ok
16:29:55.0297 0x13b20 ProfSvc - ok
16:29:55.0297 0x13b20 Psched - ok
16:29:55.0313 0x13b20 [ 87B04878A6D59D6C79251DC960C674C1, 3EB8DB0624E646F0A65D0381408D35CF9FDC5ABFC30DF6431F4070A8EB68447C ] PxHlpa64 C:\WINDOWS\system32\Drivers\PxHlpa64.sys
16:29:55.0328 0x13b20 PxHlpa64 - ok
16:29:55.0350 0x13b20 [ 0928BD20273625622722FE1DE5BBDE57, 5313C222F8810D3A62CCE64482B5E50E58BBE2A2C298A23C84A454C34324AC52 ] qicflt C:\WINDOWS\system32\DRIVERS\qicflt.sys
16:29:55.0382 0x13b20 qicflt - ok
16:29:55.0397 0x13b20 QWAVE - ok
16:29:55.0397 0x13b20 QWAVEdrv - ok
16:29:55.0413 0x13b20 RasAcd - ok
16:29:55.0429 0x13b20 RasAgileVpn - ok
16:29:55.0450 0x13b20 RasAuto - ok
16:29:55.0450 0x13b20 Rasl2tp - ok
16:29:55.0466 0x13b20 RasMan - ok
16:29:55.0466 0x13b20 RasPppoe - ok
16:29:55.0466 0x13b20 RasSstp - ok
16:29:55.0482 0x13b20 rdbss - ok
16:29:55.0497 0x13b20 rdpbus - ok
16:29:55.0497 0x13b20 RDPDR - ok
16:29:55.0529 0x13b20 RdpVideoMiniport - ok
16:29:55.0529 0x13b20 rdyboost - ok
16:29:55.0550 0x13b20 ReFSv1 - ok
16:29:55.0582 0x13b20 RemoteAccess - ok
16:29:55.0582 0x13b20 RemoteRegistry - ok
16:29:55.0613 0x13b20 RetailDemo - ok
16:29:55.0613 0x13b20 RFCOMM - ok
16:29:55.0629 0x13b20 RmSvc - ok
16:29:55.0645 0x13b20 RpcEptMapper - ok
16:29:55.0666 0x13b20 RpcLocator - ok
16:29:55.0682 0x13b20 RpcSs - ok
16:29:55.0698 0x13b20 rspndr - ok
16:29:55.0716 0x13b20 rt640x64 - ok
16:29:55.0806 0x13b20 [ 347E3CE270009E4C71B26E71ACF98106, E20ACC50C2B4B3FDB28A8FA144EBA02E835873123315FDB5A2C87CBAD95218F6 ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
16:29:55.0833 0x13b20 RtkAudioService - ok
16:29:55.0856 0x13b20 s3cap - ok
16:29:55.0870 0x13b20 SamSs - ok
16:29:55.0883 0x13b20 sbp2port - ok
16:29:55.0895 0x13b20 SCardSvr - ok
16:29:55.0907 0x13b20 ScDeviceEnum - ok
16:29:55.0909 0x13b20 scfilter - ok
16:29:55.0913 0x13b20 Schedule - ok
16:29:55.0917 0x13b20 scmbus - ok
16:29:55.0921 0x13b20 scmdisk0101 - ok
16:29:55.0928 0x13b20 SCPolicySvc - ok
16:29:56.0014 0x13b20 [ B60E9769655DDEE8368E3ABB6668E076, EECA05B36C6F837FA6DB2EDD78E17E9EA5F0D793B869CB99A08C61AB485A1E67 ] ScrybeUpdater C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe
16:29:56.0098 0x13b20 ScrybeUpdater - ok
16:29:56.0114 0x13b20 sdbus - ok
16:29:56.0114 0x13b20 SDRSVC - ok
16:29:56.0114 0x13b20 sdstor - ok
16:29:56.0129 0x13b20 seclogon - ok
16:29:56.0145 0x13b20 SENS - ok
16:29:56.0148 0x13b20 Sense - ok
16:29:56.0151 0x13b20 SensorDataService - ok
16:29:56.0151 0x13b20 SensorService - ok
16:29:56.0151 0x13b20 SensrSvc - ok
16:29:56.0167 0x13b20 SerCx - ok
16:29:56.0167 0x13b20 SerCx2 - ok
16:29:56.0167 0x13b20 Serenum - ok
16:29:56.0167 0x13b20 Serial - ok
16:29:56.0167 0x13b20 sermouse - ok
16:29:56.0182 0x13b20 SessionEnv - ok
16:29:56.0182 0x13b20 sfloppy - ok
16:29:56.0229 0x13b20 SharedAccess - ok
16:29:56.0267 0x13b20 ShellHWDetection - ok
16:29:56.0282 0x13b20 shpamsvc - ok
16:29:56.0298 0x13b20 SiSRaid2 - ok
16:29:56.0298 0x13b20 SiSRaid4 - ok
16:29:56.0329 0x13b20 [ FB9F964FFD265262EE8E98E0ED1FB44E, B02B8BCDF91B9FFCA7E2F8F6CAC310E6EEC4BCF8F8C848DCF9EDE33D8940056D ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
16:29:56.0349 0x13b20 SmbDrvI - ok
16:29:56.0367 0x13b20 smphost - ok
16:29:56.0398 0x13b20 SmsRouter - ok
16:29:56.0414 0x13b20 SNMPTRAP - ok
16:29:56.0482 0x13b20 [ 3BB48F7E33C2B76184DDF233000C09CD, D1AAE5B0425047CA0C2D376D3E59324D35A90DF9074CD442DFD0ED6E434D3C84 ] Sony SCSI Helper Service C:\Program Files (x86)\Common Files\Sony Shared\Fsk\SonySCSIHelperService.exe
16:29:56.0548 0x13b20 Sony SCSI Helper Service - detected UnsignedFile.Multi.Generic ( 1 )
16:29:56.0651 0x13b20 Detect skipped due to KSN trusted
16:29:56.0651 0x13b20 Sony SCSI Helper Service - ok
16:29:56.0698 0x13b20 spaceport - ok
16:29:56.0698 0x13b20 SpbCx - ok
16:29:56.0729 0x13b20 Spooler - ok
16:29:56.0747 0x13b20 sppsvc - ok
16:29:56.0799 0x13b20 [ 893C6AEC077665F438C1B570E82655EC, 0417BF6045FCD548003CC227FA176348277386132FC7CED02C0A0E6DBBC26803 ] SRS_HDAL_Service C:\WINDOWS\system32\drivers\SRS_HDAL_amd64.sys
16:29:56.0829 0x13b20 SRS_HDAL_Service - ok
16:29:56.0845 0x13b20 srv - ok
16:29:56.0859 0x13b20 srv2 - ok
16:29:56.0875 0x13b20 srvnet - ok
16:29:56.0890 0x13b20 SSDPSRV - ok
16:29:56.0901 0x13b20 SstpSvc - ok
16:29:56.0932 0x13b20 [ 5252D7BC56E5E0ED715AEA8FE173A455, 1408B3E98B35A449434718777EE70595F0D306197A428279C6281D2F1953F259 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
16:29:56.0945 0x13b20 ssudmdm - ok
16:29:56.0969 0x13b20 StateRepository - ok
16:29:56.0990 0x13b20 [ 92E7F6666633D2DD91D527503DAA7BE0, E97C7FFCAF2C7A83B270B6C797A91C2731FEA26874FE1E59B4CB55D5D98744BB ] stdcfltn C:\WINDOWS\system32\DRIVERS\stdcfltn.sys
16:29:57.0008 0x13b20 stdcfltn - ok
16:29:57.0114 0x13b20 [ 1C11C1E4578CDC4363CB2E911D53E7E2, BD7D453B8F981A717F56D26DFCB54CA1B666672E03B0AAAF1A39D8330BB1638C ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
16:29:57.0152 0x13b20 Stereo Service - ok
16:29:57.0183 0x13b20 stexstor - ok
16:29:57.0214 0x13b20 stisvc - ok
16:29:57.0214 0x13b20 storahci - ok
16:29:57.0230 0x13b20 storflt - ok
16:29:57.0230 0x13b20 stornvme - ok
16:29:57.0230 0x13b20 storqosflt - ok
16:29:57.0250 0x13b20 StorSvc - ok
16:29:57.0252 0x13b20 storufs - ok
16:29:57.0252 0x13b20 storvsc - ok
16:29:57.0252 0x13b20 svsvc - ok
16:29:57.0252 0x13b20 swenum - ok
16:29:57.0252 0x13b20 swprv - ok
16:29:57.0267 0x13b20 Synth3dVsc - ok
16:29:57.0299 0x13b20 [ 8607DA59550BCEC0CEBC7260AF7359C4, E5FBB4E47586426B24B1706E08D9553598A744463A1EAD5122AF08291412C896 ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys
16:29:57.0352 0x13b20 SynTP - ok
16:29:57.0414 0x13b20 [ DFAF068A21F415187F6096DD005A4ECC, 3BE1249166889684534F8C9F230E8456E0A09AF81A9F568AC04D52D3E5A2D797 ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
16:29:57.0448 0x13b20 SynTPEnhService - ok
16:29:57.0468 0x13b20 SysMain - ok
16:29:57.0468 0x13b20 SystemEventsBroker - ok
16:29:57.0484 0x13b20 TabletInputService - ok
16:29:57.0484 0x13b20 TapiSrv - ok
16:29:57.0515 0x13b20 [ D877BA7EAEC246FD5AFCF912A46B2B2D, CCA0E0C6E4FDFE5A707B71CD08C93B84002F5E15B2C4654AE9D90949D8DE35B0 ] tapstrong C:\WINDOWS\system32\DRIVERS\tapstrong.sys
16:29:57.0531 0x13b20 tapstrong - ok
16:29:57.0552 0x13b20 Tcpip - ok
16:29:57.0568 0x13b20 Tcpip6 - ok
16:29:57.0568 0x13b20 tcpipreg - ok
16:29:57.0568 0x13b20 tdx - ok
16:29:57.0584 0x13b20 terminpt - ok
16:29:57.0599 0x13b20 TermService - ok
16:29:57.0631 0x13b20 Themes - ok
16:29:57.0647 0x13b20 TieringEngineService - ok
16:29:57.0653 0x13b20 tiledatamodelsvc - ok
16:29:57.0668 0x13b20 TimeBrokerSvc - ok
16:29:57.0668 0x13b20 TPM - ok
16:29:57.0668 0x13b20 TrkWks - ok
16:29:57.0715 0x13b20 TrustedInstaller - ok
16:29:57.0731 0x13b20 tsusbflt - ok
16:29:57.0753 0x13b20 TsUsbGD - ok
16:29:57.0753 0x13b20 tsusbhub - ok
16:29:57.0772 0x13b20 tunnel - ok
16:29:57.0799 0x13b20 [ FD24F98D2898BE093FE926604BE7DB99, F9851C57A2ED838AC76BB19FE2F62BB81C57DBBE2A2555F738B5D6725D39AD61 ] TurboB C:\WINDOWS\system32\DRIVERS\TurboB.sys
16:29:57.0826 0x13b20 TurboB - ok
16:29:57.0886 0x13b20 [ 600B406A04D90F577FEA8A88D7379F08, 77CC8E8AFB6F571A42D916C0B2FEFFD3A7A32A455C78228B407C6C9B6DED8CAD ] TurboBoost C:\Program Files\Intel\TurboBoost\TurboBoost.exe
16:29:57.0911 0x13b20 TurboBoost - ok
16:29:57.0928 0x13b20 tzautoupdate - ok
16:29:57.0938 0x13b20 UASPStor - ok
16:29:57.0941 0x13b20 UcmCx0101 - ok
16:29:57.0945 0x13b20 UcmTcpciCx0101 - ok
16:29:57.0948 0x13b20 UcmUcsi - ok
16:29:57.0952 0x13b20 Ucx01000 - ok
16:29:57.0955 0x13b20 UdeCx - ok
16:29:57.0958 0x13b20 udfs - ok
16:29:57.0963 0x13b20 UEFI - ok
16:29:57.0966 0x13b20 UevAgentDriver - ok
16:29:57.0978 0x13b20 UevAgentService - ok
16:29:57.0982 0x13b20 Ufx01000 - ok
16:29:57.0998 0x13b20 UfxChipidea - ok
16:29:58.0002 0x13b20 ufxsynopsys - ok
16:29:58.0009 0x13b20 UI0Detect - ok
16:29:58.0013 0x13b20 umbus - ok
16:29:58.0016 0x13b20 UmPass - ok
16:29:58.0020 0x13b20 UmRdpService - ok
16:29:58.0023 0x13b20 UnistoreSvc - ok
16:29:58.0169 0x13b20 [ 2C16648A12999AE69A9EBF41974B0BA2, 06008F61B6EC36CD34CB8C4BA983371DB7A9F4BEE15E5329F5E90FEEE300D258 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
16:29:58.0285 0x13b20 UNS - ok
16:29:58.0285 0x13b20 upnphost - ok
16:29:58.0285 0x13b20 UrsChipidea - ok
16:29:58.0285 0x13b20 UrsCx01000 - ok
16:29:58.0301 0x13b20 UrsSynopsys - ok
16:29:58.0317 0x13b20 usbaudio - ok
16:29:58.0317 0x13b20 usbccgp - ok
16:29:58.0317 0x13b20 usbcir - ok
16:29:58.0317 0x13b20 usbehci - ok
16:29:58.0317 0x13b20 usbhub - ok
16:29:58.0332 0x13b20 USBHUB3 - ok
16:29:58.0332 0x13b20 usbohci - ok
16:29:58.0332 0x13b20 usbprint - ok
16:29:58.0332 0x13b20 usbser - ok
16:29:58.0351 0x13b20 USBSTOR - ok
16:29:58.0354 0x13b20 usbuhci - ok
16:29:58.0354 0x13b20 usbvideo - ok
16:29:58.0354 0x13b20 USBXHCI - ok
16:29:58.0370 0x13b20 UserDataSvc - ok
16:29:58.0385 0x13b20 UserManager - ok
16:29:58.0385 0x13b20 UsoSvc - ok
16:29:58.0401 0x13b20 VaultSvc - ok
16:29:58.0401 0x13b20 vdrvroot - ok
16:29:58.0417 0x13b20 vds - ok
16:29:58.0417 0x13b20 VerifierExt - ok
16:29:58.0454 0x13b20 vhdmp - ok
16:29:58.0454 0x13b20 vhf - ok
16:29:58.0470 0x13b20 vmbus - ok
16:29:58.0470 0x13b20 VMBusHID - ok
16:29:58.0470 0x13b20 vmgid - ok
16:29:58.0486 0x13b20 vmicguestinterface - ok
16:29:58.0486 0x13b20 vmicheartbeat - ok
16:29:58.0486 0x13b20 vmickvpexchange - ok
16:29:58.0517 0x13b20 vmicrdv - ok
16:29:58.0533 0x13b20 vmicshutdown - ok
16:29:58.0533 0x13b20 vmictimesync - ok
16:29:58.0552 0x13b20 vmicvmsession - ok
16:29:58.0554 0x13b20 vmicvss - ok
16:29:58.0554 0x13b20 volmgr - ok
16:29:58.0554 0x13b20 volmgrx - ok
16:29:58.0554 0x13b20 volsnap - ok
16:29:58.0570 0x13b20 volume - ok
16:29:58.0570 0x13b20 vpci - ok
16:29:58.0586 0x13b20 vsmraid - ok
16:29:58.0586 0x13b20 VSS - ok
16:29:58.0586 0x13b20 VSTXRAID - ok
16:29:58.0586 0x13b20 vwifibus - ok
16:29:58.0586 0x13b20 vwififlt - ok
16:29:58.0601 0x13b20 vwifimp - ok
16:29:58.0601 0x13b20 W32Time - ok
16:29:58.0601 0x13b20 WacomPen - ok
16:29:58.0617 0x13b20 WalletService - ok
16:29:58.0617 0x13b20 wanarp - ok
16:29:58.0617 0x13b20 wanarpv6 - ok
16:29:58.0617 0x13b20 wbengine - ok
16:29:58.0651 0x13b20 WbioSrvc - ok
16:29:58.0655 0x13b20 wcifs - ok
16:29:58.0655 0x13b20 Wcmsvc - ok
16:29:58.0670 0x13b20 wcncsvc - ok
16:29:58.0686 0x13b20 wcnfs - ok
16:29:58.0686 0x13b20 WdBoot - ok
16:29:58.0686 0x13b20 Wdf01000 - ok
16:29:58.0686 0x13b20 WdFilter - ok
16:29:58.0701 0x13b20 WdiServiceHost - ok
16:29:58.0701 0x13b20 WdiSystemHost - ok
16:29:58.0701 0x13b20 wdiwifi - ok
16:29:58.0701 0x13b20 WdNisDrv - ok
16:29:58.0733 0x13b20 WdNisSvc - ok
16:29:58.0733 0x13b20 WebClient - ok
16:29:58.0755 0x13b20 Wecsvc - ok
16:29:58.0782 0x13b20 WEPHOSTSVC - ok
16:29:58.0783 0x13b20 wercplsupport - ok
16:29:58.0783 0x13b20 WerSvc - ok
16:29:58.0801 0x13b20 WFPLWFS - ok
16:29:58.0808 0x13b20 WiaRpc - ok
16:29:58.0837 0x13b20 [ B14EF15BD757FA488F9C970EEE9C0D35, F27DF2D47E7076786AE7C396583D7A1C56B93E766711066C900964FC7313E794 ] WimFltr C:\WINDOWS\system32\DRIVERS\wimfltr.sys
16:29:58.0851 0x13b20 WimFltr - ok
16:29:58.0855 0x13b20 WIMMount - ok
16:29:58.0857 0x13b20 WinDefend - ok
16:29:58.0884 0x13b20 WindowsTrustedRT - ok
16:29:58.0887 0x13b20 WindowsTrustedRTProxy - ok
16:29:58.0896 0x13b20 WinHttpAutoProxySvc - ok
16:29:58.0904 0x13b20 WinMad - ok
16:29:58.0950 0x13b20 Winmgmt - ok
16:29:58.0982 0x13b20 WinRM - ok
16:29:59.0008 0x13b20 WINUSB - ok
16:29:59.0013 0x13b20 WinVerbs - ok
16:29:59.0041 0x13b20 wisvc - ok
16:29:59.0074 0x13b20 WlanSvc - ok
16:29:59.0098 0x13b20 wlidsvc - ok
16:29:59.0114 0x13b20 WmiAcpi - ok
16:29:59.0114 0x13b20 wmiApSrv - ok
16:29:59.0151 0x13b20 WMPNetworkSvc - ok
16:29:59.0171 0x13b20 Wof - ok
16:29:59.0186 0x13b20 workfolderssvc - ok
16:29:59.0202 0x13b20 WPDBusEnum - ok
16:29:59.0218 0x13b20 WpdUpFltr - ok
16:29:59.0233 0x13b20 WpnService - ok
16:29:59.0233 0x13b20 WpnUserService - ok
16:29:59.0271 0x13b20 ws2ifsl - ok
16:29:59.0287 0x13b20 wscsvc - ok
16:29:59.0302 0x13b20 WSDPrintDevice - ok
16:29:59.0318 0x13b20 WSDScan - ok
16:29:59.0318 0x13b20 WSearch - ok
16:29:59.0334 0x13b20 wuauserv - ok
16:29:59.0350 0x13b20 WudfPf - ok
16:29:59.0354 0x13b20 WUDFRd - ok
16:29:59.0355 0x13b20 wudfsvc - ok
16:29:59.0355 0x13b20 WUDFWpdFs - ok
16:29:59.0371 0x13b20 WwanSvc - ok
16:29:59.0387 0x13b20 XblAuthManager - ok
16:29:59.0402 0x13b20 XblGameSave - ok
16:29:59.0402 0x13b20 xboxgip - ok
16:29:59.0418 0x13b20 XboxNetApiSvc - ok
16:29:59.0434 0x13b20 xinputhid - ok
16:29:59.0434 0x13b20 ================ Scan global ===============================
16:29:59.0550 0x13b20 [ Global ] - ok
16:29:59.0553 0x13b20 ================ Scan MBR ==================================
16:29:59.0572 0x13b20 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0
16:30:00.0224 0x13b20 \Device\Harddisk0\DR0 - ok
16:30:00.0239 0x13b20 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
16:30:00.0524 0x13b20 \Device\Harddisk1\DR1 - ok
16:30:00.0524 0x13b20 ================ Scan VBR ==================================
16:30:00.0524 0x13b20 [ 7E69289E67491D6266DF173447C3A02E ] \Device\Harddisk0\DR0\Partition1
16:30:00.0524 0x13b20 \Device\Harddisk0\DR0\Partition1 - ok
16:30:00.0540 0x13b20 [ C1C24B9A439B870F18A02948E0F18B68 ] \Device\Harddisk0\DR0\Partition2
16:30:00.0540 0x13b20 \Device\Harddisk0\DR0\Partition2 - ok
16:30:00.0540 0x13b20 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk1\DR1\Partition1
16:30:00.0540 0x13b20 \Device\Harddisk1\DR1\Partition1 - ok
16:30:00.0559 0x13b20 [ EACD3E72CEF5E2A4F545E98520155EC6 ] \Device\Harddisk1\DR1\Partition2
16:30:00.0560 0x13b20 \Device\Harddisk1\DR1\Partition2 - ok
16:30:00.0560 0x13b20 ================ Scan generic autorun ======================
16:30:00.0593 0x13b20 [ 0C3154D0620F974AD5C4E8D87626C8CF, 4E6B751F9C0D5D4833A12166BC5142E0A7402E98D00F570926ED9CA0936A8007 ] C:\WINDOWS\system32\igfxtray.exe
16:30:00.0662 0x13b20 IgfxTray - ok
16:30:00.0938 0x13b20 [ 22EBD5AE3B3220D713E544D1D3AB3FEE, 9EF058B096DAA5C6242FBEB3DF509108180B1EB1EA252E63C437CF6C1B743BE0 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
16:30:01.0105 0x13b20 RTHDVCPL - ok
16:30:01.0162 0x13b20 [ 31821EC63BDEDE18E64C11F7248B32AB, 6982AE866F8EC7943FDB3E4B77B03542A2E3E07F080B8D806C4ED903DE3368CE ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
16:30:01.0194 0x13b20 RtHDVBg - ok
16:30:01.0263 0x13b20 [ 39CF316EB5842AE27CC0D3CC4E2840DE, BC4D4ED926F988B7B70CC87B7EC92D148DA6BC39C5C514751F1B0CA69D0F9081 ] C:\Program Files\Microsoft Office\Office14\BCSSync.exe
16:30:01.0263 0x13b20 BCSSync - ok
16:30:01.0441 0x13b20 [ E7B32C61E8AA6CD40DF6557FEDD2EB77, A062E7C30CE435A47615D8DB6612AAB45DD6DDDCBC0665BBB52FFC9D8670B218 ] C:\Program Files\Dell\QuickSet\QuickSet.exe
16:30:01.0642 0x13b20 QuickSet - detected UnsignedFile.Multi.Generic ( 1 )
16:30:01.0711 0x13b20 Detect skipped due to KSN trusted
16:30:01.0711 0x13b20 QuickSet - ok
16:30:01.0711 0x13b20 SynTPEnh - ok
16:30:01.0711 0x13b20 WindowsDefender - ok
16:30:01.0727 0x13b20 Avira SystrayStartTrigger - ok
16:30:01.0812 0x13b20 [ F17FFAF69E1AF3D0A010FD4749148981, 7486A1EFE378BFCEE30D169BD0189CABD6935EBEE556BF0328330B120975EA03 ] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
16:30:01.0896 0x13b20 EEventManager - ok
16:30:02.0034 0x13b20 [ 8F9B9F6623F888AF8A9FD922985FECE0, C9C9E6DD0525F176D0EAF5D855C724586E2718D9F90EB4AFF8AD1D0A7109D63F ] C:\Program Files (x86)\Sony\ReaderDesktop\appHelper\ReaderAppHelper.exe
16:30:02.0062 0x13b20 Reader Application Helper - ok
16:30:02.0136 0x13b20 [ B7A00AB53A21C92E61191AF026944D52, 3C09EC115C32ABC75F8CFA5DAFB5511161D61B399686D15027E20C9ED09BEAAB ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
16:30:02.0165 0x13b20 SunJavaUpdateSched - ok
16:30:02.0228 0x13b20 [ 138FA0EBAA0204749C496FA92A39D4D5, D57D3465C2ABE6F82FA8E644F3550D21168D01BEDA9F48B589175BBE35A1D31C ] C:\Program Files (x86)\FreeStyle Libre\FreeStyle Libre\MASLaunchClient.FreeStyleLibre.exe
16:30:02.0312 0x13b20 FreeStyleLibreautorunexe - detected UnsignedFile.Multi.Generic ( 1 )
16:30:02.0365 0x13b20 FreeStyleLibreautorunexe ( UnsignedFile.Multi.Generic ) - warning
16:30:02.0565 0x13b20 OneDriveSetup - ok
16:30:02.0565 0x13b20 OneDriveSetup - ok
16:30:02.0761 0x13b20 [ 11B4662A4DD118132E2648837920AF86, 7643E9CF00C0393ED4A1D294DABA84DCEB6BE696E5B520D413284BAB16CE1CD5 ] C:\Users\Norman\AppData\Roaming\Spotify\SpotifyWebHelper.exe
16:30:03.0168 0x13b20 Spotify Web Helper - ok
16:30:03.0400 0x13b20 [ 6F8EDF5A5D23AD1F4FC168047C80ECE4, CAA605301395B70E724688515936A6C84F90D18EFFBF21CEDD336268AACA8D02 ] C:\Users\Norman\AppData\Roaming\Spotify\Spotify.exe
16:30:03.0616 0x13b20 Spotify - ok
16:30:03.0701 0x13b20 [ 527CF721F78B2DF6A1570F93899A0AA8, 1F08074DA90593E7EDC63C072B784BE438C5EC94FE992433053D6B75CDEE78EB ] C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE
16:30:03.0716 0x13b20 OfficeSyncProcess - ok
16:30:03.0938 0x13b20 [ 5451E20D9EFBDC89991C1B86A6306894, E41CD89C1313C8729F53C91250AAD9C5E7A3F612D75F53751F31F790FF991879 ] C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIMSE.EXE
16:30:03.0953 0x13b20 EPLTarget\P0000000000000000 - ok
16:30:03.0956 0x13b20 OneDriveSetup - ok
16:30:04.0017 0x13b20 WAB Migrate - ok
16:30:04.0019 0x13b20 Waiting for KSN requests completion. In queue: 72
16:30:05.0051 0x13b20 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x61100 ( enabled : updated )
16:30:05.0054 0x13b20 Win FW state via NFP2: enabled ( trusted )
16:30:05.0125 0x13b20 ============================================================
16:30:05.0125 0x13b20 Scan finished
16:30:05.0125 0x13b20 ============================================================
16:30:05.0152 0x13b1c Detected object count: 2
16:30:05.0152 0x13b1c Actual detected object count: 2
16:32:31.0802 0x13b1c FreeStyleLibre MAS Server ( UnsignedFile.Multi.Generic ) - skipped by user
16:32:31.0802 0x13b1c FreeStyleLibre MAS Server ( UnsignedFile.Multi.Generic ) - User select action: Skip
16:32:31.0802 0x13b1c FreeStyleLibreautorunexe ( UnsignedFile.Multi.Generic ) - skipped by user
16:32:31.0802 0x13b1c FreeStyleLibreautorunexe ( UnsignedFile.Multi.Generic ) - User select action: Skip |