Vielen Dank!
Hier TDSS-Killer: Code:
22:00:13.0481 0x29d8 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
22:00:13.0481 0x29d8 UEFI system
22:00:16.0997 0x29d8 ============================================================
22:00:16.0997 0x29d8 Current date / time: 2017/03/03 22:00:16.0997
22:00:16.0997 0x29d8 SystemInfo:
22:00:16.0997 0x29d8
22:00:16.0997 0x29d8 OS Version: 10.0.14393 ServicePack: 0.0
22:00:16.0997 0x29d8 Product type: Workstation
22:00:16.0997 0x29d8 ComputerName: DESKTOP-A10S929
22:00:16.0997 0x29d8 UserName: Baby
22:00:16.0997 0x29d8 Windows directory: C:\WINDOWS
22:00:16.0997 0x29d8 System windows directory: C:\WINDOWS
22:00:16.0997 0x29d8 Running under WOW64
22:00:16.0997 0x29d8 Processor architecture: Intel x64
22:00:16.0997 0x29d8 Number of processors: 4
22:00:16.0997 0x29d8 Page size: 0x1000
22:00:16.0997 0x29d8 Boot type: Normal boot
22:00:16.0997 0x29d8 CodeIntegrityOptions = 0x00000001
22:00:16.0997 0x29d8 ============================================================
22:00:17.0309 0x29d8 KLMD registered as C:\WINDOWS\system32\drivers\56145642.sys
22:00:17.0309 0x29d8 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.693, osProperties = 0x19
22:00:18.0137 0x29d8 System UUID: {DC30BCFC-A93E-F47D-9442-E72F04A99A9B}
22:00:20.0997 0x29d8 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
22:00:21.0012 0x29d8 ============================================================
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0:
22:00:21.0012 0x29d8 GPT partitions:
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {9E1C85E6-2EDD-4BFC-902D-3BCCA502EDBA}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x82000
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {6E7470DD-3887-4817-A1E3-E530E565EA89}, Name: Microsoft reserved partition, StartLBA 0x82800, BlocksNum 0x8000
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {C00315AD-91CA-4933-8C82-EB6D9D2B0C5A}, Name: Basic data partition, StartLBA 0x8A800, BlocksNum 0x3543C800
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {14D36E42-9256-4AF9-908B-AEDD97483DD9}, Name: Basic data partition, StartLBA 0x354C7000, BlocksNum 0x3200000
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {C6018A70-B47F-488E-AA70-EF06BB5A7D63}, Name: Basic data partition, StartLBA 0x386C7000, BlocksNum 0x1F4000
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {98E3C13B-FA5E-4ECD-BA7F-2FEC526715E2}, Name: Basic data partition, StartLBA 0x388BB000, BlocksNum 0x18D7000
22:00:21.0012 0x29d8 \Device\Harddisk0\DR0\Partition7: GPT, TypeGUID: {BFBFAFE7-A34F-448A-9A5B-6213EB736C22}, UniqueGUID: {6954EAEC-6A48-4090-84B2-43FD22522BAC}, Name: Basic data partition, StartLBA 0x3A192000, BlocksNum 0x1F4000
22:00:21.0012 0x29d8 MBR partitions:
22:00:21.0012 0x29d8 ============================================================
22:00:21.0012 0x29d8 C: <-> \Device\Harddisk0\DR0\Partition3
22:00:21.0028 0x29d8 D: <-> \Device\Harddisk0\DR0\Partition4
22:00:21.0028 0x29d8 ============================================================
22:00:21.0028 0x29d8 Initialize success
22:00:21.0028 0x29d8 ============================================================
22:00:22.0794 0x1884 ============================================================
22:00:22.0794 0x1884 Scan started
22:00:22.0794 0x1884 Mode: Manual;
22:00:22.0794 0x1884 ============================================================
22:00:22.0794 0x1884 KSN ping started
22:00:22.0997 0x1884 KSN ping finished: true
22:00:24.0544 0x1884 ================ Scan system memory ========================
22:00:24.0544 0x1884 System memory - ok
22:00:24.0544 0x1884 ================ Scan services =============================
22:00:24.0731 0x1884 1394ohci - ok
22:00:24.0747 0x1884 3ware - ok
22:00:24.0778 0x1884 ACPI - ok
22:00:24.0794 0x1884 AcpiDev - ok
22:00:24.0825 0x1884 acpiex - ok
22:00:24.0841 0x1884 acpipagr - ok
22:00:24.0872 0x1884 AcpiPmi - ok
22:00:24.0888 0x1884 acpitime - ok
22:00:24.0919 0x1884 [ E13DE7CD2B62254DD4FF658B7798A37D, 9FCCC90DEF6BE83F8C41D4552D235A7BB5534954D2E7CB7B1C336A31FCCAB3AD ] ACPIVPC C:\WINDOWS\System32\drivers\AcpiVpc.sys
22:00:24.0919 0x1884 ACPIVPC - ok
22:00:24.0981 0x1884 ADP80XX - ok
22:00:25.0013 0x1884 AFD - ok
22:00:25.0059 0x1884 ahcache - ok
22:00:25.0075 0x1884 AJRouter - ok
22:00:25.0106 0x1884 ALG - ok
22:00:25.0138 0x1884 AmdK8 - ok
22:00:25.0153 0x1884 AmdPPM - ok
22:00:25.0185 0x1884 amdsata - ok
22:00:25.0216 0x1884 amdsbs - ok
22:00:25.0231 0x1884 amdxata - ok
22:00:25.0247 0x1884 AppID - ok
22:00:25.0278 0x1884 AppIDSvc - ok
22:00:25.0294 0x1884 Appinfo - ok
22:00:25.0325 0x1884 applockerfltr - ok
22:00:25.0356 0x1884 AppReadiness - ok
22:00:25.0388 0x1884 AppXSvc - ok
22:00:25.0419 0x1884 arcsas - ok
22:00:25.0434 0x1884 AsyncMac - ok
22:00:25.0466 0x1884 atapi - ok
22:00:25.0497 0x1884 AudioEndpointBuilder - ok
22:00:25.0513 0x1884 Audiosrv - ok
22:00:25.0575 0x1884 [ 03B45C52179E8DAE51A0F685C30D06D6, E06F066B4BFE5344BBF5749B9B8B8CFBA0C02920FD2B9C73BDDA7E34F1785DA7 ] AVP17.0.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\avp.exe
22:00:25.0591 0x1884 AVP17.0.0 - ok
22:00:25.0622 0x1884 AxInstSV - ok
22:00:25.0638 0x1884 b06bdrv - ok
22:00:25.0669 0x1884 BasicDisplay - ok
22:00:25.0684 0x1884 BasicRender - ok
22:00:25.0731 0x1884 bcmfn - ok
22:00:25.0763 0x1884 bcmfn2 - ok
22:00:25.0778 0x1884 BDESVC - ok
22:00:25.0809 0x1884 Beep - ok
22:00:25.0825 0x1884 BFE - ok
22:00:25.0856 0x1884 BITS - ok
22:00:25.0888 0x1884 bowser - ok
22:00:25.0919 0x1884 BrokerInfrastructure - ok
22:00:25.0950 0x1884 Browser - ok
22:00:25.0966 0x1884 BthAvrcpTg - ok
22:00:25.0997 0x1884 BthEnum - ok
22:00:26.0013 0x1884 BthHFEnum - ok
22:00:26.0044 0x1884 bthhfhid - ok
22:00:26.0059 0x1884 BthHFSrv - ok
22:00:26.0091 0x1884 BthLEEnum - ok
22:00:26.0122 0x1884 BTHMODEM - ok
22:00:26.0138 0x1884 BthPan - ok
22:00:26.0169 0x1884 BTHPORT - ok
22:00:26.0184 0x1884 bthserv - ok
22:00:26.0216 0x1884 BTHUSB - ok
22:00:26.0247 0x1884 buttonconverter - ok
22:00:26.0263 0x1884 CapImg - ok
22:00:26.0356 0x1884 [ C267A09490883B77E7678DCF38E3B723, 8FD7858B5BA84CF3640E250DE2448E383E6233BE6F3E92FDB702DB82111A9AF0 ] CCSDK C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
22:00:26.0434 0x1884 CCSDK - ok
22:00:26.0450 0x1884 cdfs - ok
22:00:26.0481 0x1884 CDPSvc - ok
22:00:26.0497 0x1884 CDPUserSvc - ok
22:00:26.0559 0x1884 cdrom - ok
22:00:26.0575 0x1884 CertPropSvc - ok
22:00:26.0622 0x1884 [ 3CA560EE2846FCC7A212ECC0A30AA24B, AF23987DA4F9EC2BC524C787F30BE49C34A3F9716E32046F510766E1F3A08A9A ] cfwids C:\WINDOWS\system32\drivers\cfwids.sys
22:00:26.0622 0x1884 cfwids - ok
22:00:26.0653 0x1884 cht4iscsi - ok
22:00:26.0684 0x1884 cht4vbd - ok
22:00:26.0700 0x1884 circlass - ok
22:00:26.0731 0x1884 CLFS - ok
22:00:27.0122 0x1884 [ CB6AC02C92BBA30187EA4591D771660E, B3BB15DC814F131672D864CAAD1537933EE83C9029DF143E5E105077EA4D7F30 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
22:00:27.0466 0x1884 ClickToRunSvc - ok
22:00:27.0513 0x1884 ClipSVC - ok
22:00:27.0544 0x1884 clreg - ok
22:00:27.0622 0x1884 CmBatt - ok
22:00:27.0669 0x1884 [ B29A764A1E76473CD9D64C9438705C19, CD0497EB84DE60E1E491CA495AF981A8DFC4949BB373C1978CAF1BCF4321D30E ] cm_km C:\WINDOWS\system32\DRIVERS\cm_km.sys
22:00:27.0700 0x1884 cm_km - ok
22:00:27.0731 0x1884 CNG - ok
22:00:27.0747 0x1884 cnghwassist - ok
22:00:27.0856 0x1884 CompositeBus - ok
22:00:27.0888 0x1884 COMSysApp - ok
22:00:27.0919 0x1884 condrv - ok
22:00:27.0950 0x1884 CoreMessagingRegistrar - ok
22:00:28.0060 0x1884 [ AA4C3229C6C1765D996F43F43FE4FBED, E0D341E63DB6F3E7F8BFB09D3D643009F345380BF94736576595A6DDD37A5E03 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
22:00:28.0106 0x1884 cphs - ok
22:00:28.0138 0x1884 CryptSvc - ok
22:00:28.0169 0x1884 dam - ok
22:00:28.0216 0x1884 DcomLaunch - ok
22:00:28.0247 0x1884 DcpSvc - ok
22:00:28.0294 0x1884 defragsvc - ok
22:00:28.0310 0x1884 DeviceAssociationService - ok
22:00:28.0341 0x1884 DeviceInstall - ok
22:00:28.0372 0x1884 DevQueryBroker - ok
22:00:28.0403 0x1884 Dfsc - ok
22:00:28.0435 0x1884 [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\WINDOWS\system32\DRIVERS\ssudbus.sys
22:00:28.0466 0x1884 dg_ssudbus - ok
22:00:28.0481 0x1884 Dhcp - ok
22:00:28.0513 0x1884 diagnosticshub.standardcollector.service - ok
22:00:28.0528 0x1884 DiagTrack - ok
22:00:28.0560 0x1884 disk - ok
22:00:28.0591 0x1884 DmEnrollmentSvc - ok
22:00:28.0606 0x1884 dmvsc - ok
22:00:28.0638 0x1884 dmwappushservice - ok
22:00:28.0669 0x1884 Dnscache - ok
22:00:28.0700 0x1884 dot3svc - ok
22:00:28.0731 0x1884 DPS - ok
22:00:28.0763 0x1884 drmkaud - ok
22:00:28.0778 0x1884 DsmSvc - ok
22:00:28.0810 0x1884 DsSvc - ok
22:00:28.0841 0x1884 DXGKrnl - ok
22:00:28.0872 0x1884 EapHost - ok
22:00:28.0903 0x1884 ebdrv - ok
22:00:28.0935 0x1884 EFS - ok
22:00:28.0950 0x1884 EhStorClass - ok
22:00:28.0981 0x1884 EhStorTcgDrv - ok
22:00:29.0185 0x1884 [ 9DF468D8CCE3B3BD200CFB31E9EA17BB, D2700E2ACB034E8698E81526E7470E265E1F791503ED528E66ED0BB574CA6FFA ] ElfoService C:\Program Files (x86)\ElsterFormular Update Service\bin\ElfoService.exe
22:00:29.0310 0x1884 ElfoService - ok
22:00:29.0325 0x1884 embeddedmode - ok
22:00:29.0356 0x1884 EntAppSvc - ok
22:00:29.0388 0x1884 ErrDev - ok
22:00:29.0481 0x1884 [ 4F1F28FD1E5618444B7F529C27E063C7, 1964B4B45F9FDCFE0F7F3C7121D96081A13EAA6E6DFE39FA9CD2D7B06091B6A6 ] ETD C:\WINDOWS\system32\DRIVERS\ETD.sys
22:00:29.0528 0x1884 ETD - ok
22:00:29.0560 0x1884 [ CD7256F391779D5473BDED03C1537AF7, EFC5FA3AF9BE390FC5BD25D9A2969E12D5A9FF60D07C8B25C53278E16925A08D ] ETDService C:\Program Files\Elantech\ETDService.exe
22:00:29.0575 0x1884 ETDService - ok
22:00:29.0606 0x1884 [ 7A6A9202245A8D93B771734C543FBB2D, A1B452E2F97988F128B4A6FFFC89C6F8F9FE39DD0D0C574EC3C3ACA7C4DCBE27 ] ETDSMBus C:\WINDOWS\system32\DRIVERS\ETDSMBus.sys
22:00:29.0606 0x1884 ETDSMBus - ok
22:00:29.0638 0x1884 EventSystem - ok
22:00:29.0747 0x1884 [ 6DCB7233AAD29E43331B3ECFCC8FB8D1, A8E203BB774A4E055C871E9A28F958287A75E8BEA42496E6BA9983063CF6C539 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
22:00:29.0810 0x1884 EvtEng - ok
22:00:29.0841 0x1884 exfat - ok
22:00:29.0856 0x1884 fastfat - ok
22:00:29.0888 0x1884 Fax - ok
22:00:29.0919 0x1884 fdc - ok
22:00:29.0950 0x1884 fdPHost - ok
22:00:29.0966 0x1884 FDResPub - ok
22:00:29.0997 0x1884 fhsvc - ok
22:00:30.0013 0x1884 FileCrypt - ok
22:00:30.0044 0x1884 FileInfo - ok
22:00:30.0075 0x1884 Filetrace - ok
22:00:30.0106 0x1884 flpydisk - ok
22:00:30.0122 0x1884 FltMgr - ok
22:00:30.0153 0x1884 FontCache - ok
22:00:30.0185 0x1884 FontCache3.0.0.0 - ok
22:00:30.0200 0x1884 FrameServer - ok
22:00:30.0247 0x1884 FsDepends - ok
22:00:30.0278 0x1884 Fs_Rec - ok
22:00:30.0310 0x1884 fvevol - ok
22:00:30.0481 0x1884 [ D56EE61F9B62AD677395BF003A49B4A7, A4B657AF38253F4BAE2A8BE7E9453E662BC378773A93631C0445C96267296B53 ] GDCAgent C:\Program Files (x86)\Lenovo\GDCAgentSetupRed\GDCAgent.exe
22:00:30.0606 0x1884 GDCAgent - ok
22:00:30.0638 0x1884 gencounter - ok
22:00:30.0653 0x1884 genericusbfn - ok
22:00:30.0685 0x1884 GPIOClx0101 - ok
22:00:30.0716 0x1884 gpsvc - ok
22:00:30.0731 0x1884 GpuEnergyDrv - ok
22:00:30.0763 0x1884 HDAudBus - ok
22:00:30.0778 0x1884 HidBatt - ok
22:00:30.0810 0x1884 HidBth - ok
22:00:30.0841 0x1884 hidi2c - ok
22:00:30.0856 0x1884 hidinterrupt - ok
22:00:30.0888 0x1884 HidIr - ok
22:00:30.0919 0x1884 hidserv - ok
22:00:30.0950 0x1884 HidUsb - ok
22:00:30.0997 0x1884 [ F60E629BADC03B5BCCF8AAE022651A64, 08D3BA75F3A43843F8F13D7EEA263E46A9452FAB3B30BFD389E4B0477675CB3B ] HipShieldK C:\WINDOWS\system32\drivers\HipShieldK.sys
22:00:31.0028 0x1884 HipShieldK - ok
22:00:31.0060 0x1884 HomeGroupListener - ok
22:00:31.0075 0x1884 HomeGroupProvider - ok
22:00:31.0106 0x1884 HpSAMD - ok
22:00:31.0138 0x1884 HTTP - ok
22:00:31.0153 0x1884 HvHost - ok
22:00:31.0185 0x1884 hvservice - ok
22:00:31.0216 0x1884 hwpolicy - ok
22:00:31.0231 0x1884 hyperkbd - ok
22:00:31.0263 0x1884 HyperVideo - ok
22:00:31.0294 0x1884 i8042prt - ok
22:00:31.0310 0x1884 iagpio - ok
22:00:31.0341 0x1884 iai2c - ok
22:00:31.0372 0x1884 iaLPSS2i_GPIO2 - ok
22:00:31.0403 0x1884 iaLPSS2i_I2C - ok
22:00:31.0419 0x1884 iaLPSSi_GPIO - ok
22:00:31.0450 0x1884 iaLPSSi_I2C - ok
22:00:31.0481 0x1884 [ 8FD3487A6AE70321404C34AC278840D8, 2BD7720A7D907F5D036982D4DA32128D427CE5110544F51F003C7693A51A29EE ] iaLPSS_GPIO C:\WINDOWS\System32\drivers\iaLPSS_GPIO.sys
22:00:31.0497 0x1884 iaLPSS_GPIO - ok
22:00:31.0685 0x1884 [ 5F6CA62BE8ECC4D0E1F5D4D4A02B456B, F720A1F14C9053D24C5B42827E5F9578A27F3E62A6C65A3CFA068E580F02F072 ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
22:00:31.0825 0x1884 iaStorA - ok
22:00:31.0841 0x1884 iaStorAV - ok
22:00:31.0872 0x1884 [ D90885430767C6152AF908D57A5159AC, A3C25AA5CDDFBBA91199F673471C64A8A4792A0F2D642F46AD54B18879A464B1 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
22:00:31.0888 0x1884 IAStorDataMgrSvc - ok
22:00:31.0903 0x1884 iaStorV - ok
22:00:31.0935 0x1884 ibbus - ok
22:00:31.0966 0x1884 ibtsiva - ok
22:00:32.0028 0x1884 [ C5547F54E191D36AFD3A3654CBA65806, FC4EA1FFE2077FE17C536C0674CBC61EFDA138BC145346DA67742C15A93D9C1A ] ibtusb C:\WINDOWS\system32\DRIVERS\ibtusb.sys
22:00:32.0044 0x1884 ibtusb - ok
22:00:32.0075 0x1884 icssvc - ok
22:00:32.0856 0x1884 [ 1E64B1ACBA54360B4BA2D6DB3C4F482E, D25B2DBBA6C82D29B080960961775726A16CB24426BFEEF18F966AD7C54801F3 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
22:00:33.0544 0x1884 igfx - ok
22:00:33.0638 0x1884 [ 7075C9341BBB75F7E54AAB291AB82223, 16779559625C78C0C15A030FB5EB03D18D163CD71FB703B003A25DA0E0F50BCA ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
22:00:33.0716 0x1884 igfxCUIService2.0.0.0 - ok
22:00:33.0731 0x1884 IKEEXT - ok
22:00:33.0763 0x1884 [ CDA315AF0F1DAA6925AA5442FA2412F4, 82E00696C65FAA715066096751560803ADFAD1765086D7806F11D6F64FAC03BB ] ImControllerService C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
22:00:33.0778 0x1884 ImControllerService - ok
22:00:33.0794 0x1884 IndirectKmd - ok
22:00:34.0356 0x1884 [ 73D45AF87AD38A24CD9EA7834324D41C, 893BE814F4EE53CFC47AD783D88BC457CA4F23AE37BF3FAE8ED51DB815260259 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
22:00:34.0825 0x1884 IntcAzAudAddService - ok
22:00:34.0935 0x1884 [ C8D2B9B619E5A1E33C0A5CA8F0870298, F61941F2B6C65BDEF17514F0D991EA11D8F3D4B959DAA47C483277C63E910733 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
22:00:34.0997 0x1884 IntcDAud - ok
22:00:35.0138 0x1884 [ B63CF22D1AD2ABDC39D85851B2BEAA6D, 37E9043BABB5895BFD2B59AFB60C438B992C6EAA1B5FDE5B3445314343F4C406 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
22:00:35.0216 0x1884 Intel(R) Capability Licensing Service TCP IP Interface - ok
22:00:35.0278 0x1884 [ 8213094EA736A9C575AB0E22AD09B0BA, 12670A466B5AA37283BD4CB481D000DE3AE2A8D1BD159F67A41703A6FE5675EC ] Intel(R) Security Assist C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
22:00:35.0310 0x1884 Intel(R) Security Assist - ok
22:00:35.0325 0x1884 intelide - ok
22:00:35.0341 0x1884 intelpep - ok
22:00:35.0372 0x1884 intelppm - ok
22:00:35.0403 0x1884 iorate - ok
22:00:35.0435 0x1884 IpFilterDriver - ok
22:00:35.0466 0x1884 iphlpsvc - ok
22:00:35.0481 0x1884 IPMIDRV - ok
22:00:35.0513 0x1884 IPNAT - ok
22:00:35.0528 0x1884 irda - ok
22:00:35.0560 0x1884 IRENUM - ok
22:00:35.0591 0x1884 irmon - ok
22:00:35.0606 0x1884 [ 1DFC3CCA51785254C5604238BB1A5467, 31451A90A91AEE14C6B24F84CB9816E5C77179D411B8B3E8547F538235BEEFB0 ] isaHelperSvc C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
22:00:35.0622 0x1884 isaHelperSvc - ok
22:00:35.0638 0x1884 isapnp - ok
22:00:35.0669 0x1884 iScsiPrt - ok
22:00:35.0700 0x1884 [ DE70C5C10803C700DC1CFDE2D5CF207A, 4D11DE8B986C6966B66E1D6E931A72A1E9FA8D0B5B9EF57EF3EEDD09D0BE0B4E ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
22:00:35.0731 0x1884 jhi_service - ok
22:00:35.0763 0x1884 kbdclass - ok
22:00:35.0794 0x1884 kbdhid - ok
22:00:35.0825 0x1884 kdnic - ok
22:00:35.0841 0x1884 KeyIso - ok
22:00:35.0919 0x1884 [ 97E3E8F35632EECD0ABD2DE6519A9666, ABE96FDEB1076E380D7FB4975C020B43ED4E821097EFC6AFE8C75D764167D6E8 ] kl1 C:\WINDOWS\system32\DRIVERS\kl1.sys
22:00:35.0982 0x1884 kl1 - ok
22:00:36.0013 0x1884 [ B01AD8DA034EE42D4C2282F77FDB03AE, 3FF55F3CEE4A0E5D559F04F5A639297EA0F36580720E94CF9DD56DEBF2E98F39 ] klbackupdisk C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys
22:00:36.0028 0x1884 klbackupdisk - ok
22:00:36.0060 0x1884 [ 10549B5BFD9A3DCF4FFA6287236FA959, 6BDFA335A8E3A69425CB23230660D3168CB82911ACB3AAAF85C19263511EAF51 ] klbackupflt C:\WINDOWS\system32\DRIVERS\klbackupflt.sys
22:00:36.0075 0x1884 klbackupflt - ok
22:00:36.0091 0x1884 [ 7DAA9047F50BF5A3F8C147719FC520AF, 0740387075AF46DB1E9AEE3B12C65A06EDFE58EADB8B562C36CB1FEFF9905C26 ] kldisk C:\WINDOWS\system32\DRIVERS\kldisk.sys
22:00:36.0107 0x1884 kldisk - ok
22:00:36.0153 0x1884 [ 5766A27C85EE813029831D125D2EFB45, BB5BAFD5A58E80C7F0B8D24121352E0386B3422FFC16B56F1D1B1C6A482AC9F0 ] klelam C:\WINDOWS\system32\DRIVERS\klelam.sys
22:00:36.0169 0x1884 klelam - ok
22:00:36.0232 0x1884 [ 63FD545876EF4248BE3C8788D8270758, 5FF6529F8D7F94848E68142D8B2CAA446342AF95644C9223E689E303E8AB7336 ] klflt C:\WINDOWS\system32\DRIVERS\klflt.sys
22:00:36.0247 0x1884 klflt - ok
22:00:36.0310 0x1884 [ 3524D3B8F5BEF8C01EAF7EEFFA5EAB3F, 0908A6E3E62017F7099900850D58A1B775D808F7DC0951B09781689DF3994DA2 ] klhk C:\WINDOWS\System32\drivers\klhk.sys
22:00:36.0357 0x1884 klhk - ok
22:00:36.0435 0x1884 [ 7796EAD58D8C1A42AAB6B6CA9A3F106C, 7DA8A05A0210F63C7D120DCF0101AD895D53368C0DED23E275F2BA79239FCE28 ] klids C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys
22:00:36.0450 0x1884 klids - ok
22:00:36.0575 0x1884 [ 2CE22F21119A089277B067A1B1BDC592, 7CDE229899B6344967098FB03C7C1C360CC3DC2DCC096F8AAC6CC96536FF1AE9 ] KLIF C:\WINDOWS\system32\DRIVERS\klif.sys
22:00:36.0685 0x1884 KLIF - ok
22:00:36.0716 0x1884 [ 6357C533C30650361110DBAF59A25DF8, FA8CF6292CCBC7E23527D968E54CD773706CF091E35563B0CF9F8A1DF0B724B9 ] KLIM6 C:\WINDOWS\system32\DRIVERS\klim6.sys
22:00:36.0716 0x1884 KLIM6 - ok
22:00:36.0747 0x1884 [ 5480CC93737F48282552C84FA7EBA59B, B7D92424399B647132F6B9409FE75EAA310C984F796FC0B65BBE2EA180110968 ] klkbdflt C:\WINDOWS\system32\DRIVERS\klkbdflt.sys
22:00:36.0763 0x1884 klkbdflt - ok
22:00:36.0778 0x1884 [ FD47C92A63B6EADEA830BFA96C06EAEE, C15C39B6FA53CBD01A2F95243845C4B706B4229F8FFB75C7128819B9CEE5B2CB ] klmouflt C:\WINDOWS\system32\DRIVERS\klmouflt.sys
22:00:36.0794 0x1884 klmouflt - ok
22:00:36.0825 0x1884 [ 6B0C605591C892CBB683F63EA47822DC, E74C0A0501A1B4B56B417402108521F34DA6A23FCD1C05E4E524E41EBA0906FF ] klpd C:\WINDOWS\system32\DRIVERS\klpd.sys
22:00:36.0825 0x1884 klpd - ok
22:00:36.0857 0x1884 [ 828B042A95F055648DA190DF6C7AB1B6, 0457B0EF03BCB4CC1297EB25A25C162937F456BF406EC7B1A5E9A0AA13A9BCD7 ] kltap C:\WINDOWS\System32\drivers\kltap.sys
22:00:36.0857 0x1884 kltap - ok
22:00:36.0935 0x1884 [ 66516A704F1D378E58B85D79633C103D, 54E3EB342D2FD17CF742A8ACADCA81A553216AA289955DD176A54D6414727DA5 ] klupd_klif_arkmon C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
22:00:36.0950 0x1884 klupd_klif_arkmon - ok
22:00:36.0982 0x1884 [ 941727CDC11A0E1A407B602D88CD58CB, 8E290245A42E75FC532A72A850BAF5516BA7488BEF015F46CA9D215BCA0D7CE0 ] klupd_klif_kimul C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
22:00:36.0997 0x1884 klupd_klif_kimul - ok
22:00:37.0044 0x1884 [ 55FC7F42A5AA55A265CE466227ABD0DE, AB72152F39460327D74DB693BFB36A93BC2D752653D3633BB7F439DC4B9AB081 ] klupd_klif_klark C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
22:00:37.0075 0x1884 klupd_klif_klark - ok
22:00:37.0107 0x1884 [ D7709E365C10F99DE58BB688C45358B7, C028FB885B7A4AFB98FD2B8EABF99E913F480891A9ED859FE5B4E077BDE8ACB5 ] klupd_klif_klbg C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
22:00:37.0122 0x1884 klupd_klif_klbg - ok
22:00:37.0153 0x1884 [ 8D7E0B5D4F843D39AA1F644B2578B0EE, C4A8E569A253738AA7B7CDE8D0E987954D1DA6BE6F32D962BD458CA5275A5D76 ] klupd_klif_mark C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
22:00:37.0169 0x1884 klupd_klif_mark - ok
22:00:37.0216 0x1884 [ D7F0B46844565E2ED68AC99AF0F4263F, AB419CBC29F96703237127AC4178A5365D4CCA010BAB1BD66D100D635E6E89B8 ] klvssbrigde64 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\x64\vssbridge64.exe
22:00:37.0216 0x1884 klvssbrigde64 - ok
22:00:37.0247 0x1884 [ 4C5305295B51BA72FC9C8CDAB32F95C3, 0E5850AC4CA14D971E7B04FED23CB2F6CEEE2796E905AADA0104677982ECD58A ] klwfp C:\WINDOWS\system32\DRIVERS\klwfp.sys
22:00:37.0263 0x1884 klwfp - ok
22:00:37.0294 0x1884 [ EF1AFCADCA485B3846D7A8B71F87509B, C27B579742389ACD8804EC372CBA3C4FDFFB1A8AA6280AE1353BC089E8E34C76 ] Klwtp C:\WINDOWS\system32\DRIVERS\klwtp.sys
22:00:37.0310 0x1884 Klwtp - ok
22:00:37.0357 0x1884 [ 67EFD862ACEFCB9687523832C62FA584, B3C9A36C535B706EB19E5C5437705E8C5EC71F45115A2C97E1348462EC2A3922 ] kneps C:\WINDOWS\system32\DRIVERS\kneps.sys
22:00:37.0388 0x1884 kneps - ok
22:00:37.0450 0x1884 [ EFF5EA6088DB81C6EF6EDCDA5EE79909, 4D364B0BF012C335FA3B25BDF042D4AF672D961B9B48CB7C5BE34FCFD1D64979 ] KSDE1.0.0 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe
22:00:37.0466 0x1884 KSDE1.0.0 - ok
22:00:37.0482 0x1884 KSecDD - ok
22:00:37.0528 0x1884 KSecPkg - ok
22:00:37.0544 0x1884 ksthunk - ok
22:00:37.0575 0x1884 KtmRm - ok
22:00:37.0591 0x1884 LanmanServer - ok
22:00:37.0622 0x1884 LanmanWorkstation - ok
22:00:37.0653 0x1884 lfsvc - ok
22:00:37.0685 0x1884 LicenseManager - ok
22:00:37.0716 0x1884 lltdio - ok
22:00:37.0732 0x1884 lltdsvc - ok
22:00:37.0763 0x1884 lmhosts - ok
22:00:37.0841 0x1884 [ 1CE3A27B6B0658F4242AB2DECE69704E, FB705D43554478FA438CE600DAD65C5885858ABF9FCB5D9CC6E5F7C87FD6A853 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
22:00:37.0872 0x1884 LMS - ok
22:00:37.0919 0x1884 LSI_SAS - ok
22:00:37.0935 0x1884 LSI_SAS2i - ok
22:00:37.0966 0x1884 LSI_SAS3i - ok
22:00:37.0982 0x1884 LSI_SSS - ok
22:00:38.0013 0x1884 LSM - ok
22:00:38.0044 0x1884 luafv - ok
22:00:38.0060 0x1884 MapsBroker - ok
22:00:38.0278 0x1884 [ 40B02F6D4B331443CC7E879BCD87100F, ACF976DC9565A905F71EFE9A25516A0F1B128E70B961B8D8256F51474B1F78D7 ] mccspsvc C:\Program Files\Common Files\McAfee\CSP\1.9.829.0\\McCSPServiceHost.exe
22:00:38.0450 0x1884 mccspsvc - ok
22:00:38.0482 0x1884 megasas - ok
22:00:38.0497 0x1884 megasas2i - ok
22:00:38.0528 0x1884 megasr - ok
22:00:38.0575 0x1884 [ 48F64A35BA9F2E4AC0587DDA555FF951, 77FE2BE86ADCE103F4220A641139C42B1407CF8EFFEB66F841ABF9CFC3621558 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
22:00:38.0591 0x1884 MEIx64 - ok
22:00:38.0622 0x1884 MessagingService - ok
22:00:38.0732 0x1884 [ 22CE39824DECE03C8DEF8832F029E3ED, C036E7E28BD4B90B29AF5B389486836137DCF9AB371D9D98CB12AD06F4107015 ] mfeaack C:\WINDOWS\system32\drivers\mfeaack.sys
22:00:38.0763 0x1884 mfeaack - ok
22:00:38.0825 0x1884 [ FB9188B17958E6DFE959D23281547605, A595D8D9A34BF390AA648883FCBAF38E96B896FAD43D97EA4F4DA791812626F2 ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys
22:00:38.0872 0x1884 mfeavfk - ok
22:00:38.0903 0x1884 [ 7257ECF649C19DCBEB3B5CFF5B9323EC, 1A0D0B2DDFD00628E891B5667143C8AFB698F21242574457E5222D7F6ACD5A61 ] mfeelamk C:\WINDOWS\system32\drivers\mfeelamk.sys
22:00:38.0919 0x1884 mfeelamk - ok
22:00:38.0966 0x1884 [ 95A4DC60385F57418BD3361262D5F7C8, 5FAAE03B306710509E36A7B77DE9D36E4A1A38832403C29247E1A8B8C1D918B3 ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
22:00:38.0982 0x1884 mfefire - ok
22:00:39.0060 0x1884 [ A2163D325F01DA86E140C91D3560C95E, 49D94BA855746591E545A6C82690E5F0B228E43FDD5AE3940F2D62835BFD7A96 ] mfefirek C:\WINDOWS\system32\drivers\mfefirek.sys
22:00:39.0107 0x1884 mfefirek - ok
22:00:39.0216 0x1884 [ C30A6CB5A1B908643EEE9651E94BFE92, 394CDE243A10E5AB91FF27E722E4E8E23B5AC50EEB2A8D6A7BDB37DB0A0E23FB ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys
22:00:39.0294 0x1884 mfehidk - ok
22:00:39.0372 0x1884 [ 8703CE0AF859D00B37254E1858E68B40, 09D27BEDA8290DB3C2FBC4CCD8AA86AA8761E9975EBEF0260CA9BB57468F4025 ] mfemms C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe
22:00:39.0403 0x1884 mfemms - ok
22:00:39.0482 0x1884 [ 34812CE00FAE95A6275D6B58072457F5, 23118A5E58F88AF5B8C5D4C15AEFA99C47D37A8E8C8FBF840DEEECC3C483AD8B ] mfencbdc C:\WINDOWS\system32\DRIVERS\mfencbdc.sys
22:00:39.0528 0x1884 mfencbdc - ok
22:00:39.0560 0x1884 [ CF9D4FCA3A5C737DCF72B9F94BB0AC62, 8534DADB74EF745F50A1A148DE5CBAD573B890C604CDA08276CDE3D5C2E8788F ] mfencrk C:\WINDOWS\system32\DRIVERS\mfencrk.sys
22:00:39.0575 0x1884 mfencrk - ok
22:00:39.0622 0x1884 [ 8DFE9C58B1509E3BBC6FD92B954204D9, 72D519AB2F5E3A335C61C1B632BB846FCD6406194EC36E965D52C1028E68FB33 ] mfevtp C:\Windows\system32\mfevtps.exe
22:00:39.0669 0x1884 mfevtp - ok
22:00:39.0716 0x1884 [ ECDFB70AB9C0DC93E0A7AE4B0893E39F, 5021C95E01870C35A3B6A5423E8BA432B4CC2014B8C6B5FD766393A963C59C35 ] mfewfpk C:\WINDOWS\system32\drivers\mfewfpk.sys
22:00:39.0747 0x1884 mfewfpk - ok
22:00:39.0763 0x1884 mlx4_bus - ok
22:00:39.0778 0x1884 MMCSS - ok
22:00:39.0810 0x1884 Modem - ok
22:00:39.0966 0x1884 [ DFB4BC8B5CD8C85D0BD9E608898901FB, AB3BB7FA2D23A5B7815E85F7A73E3F36E95D8FD895F76FA9936AD4C1DA1849EF ] ModuleCoreService C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
22:00:40.0107 0x1884 ModuleCoreService - ok
22:00:40.0138 0x1884 monitor - ok
22:00:40.0153 0x1884 mouclass - ok
22:00:40.0185 0x1884 mouhid - ok
22:00:40.0200 0x1884 mountmgr - ok
22:00:40.0247 0x1884 [ ADF79A49E942C91D1FC9863CBFDD6B58, C2B2A792C4717133DCAE6297EE3F5D985B11D3C1E68A8DC23985AC6B78ACDE98 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
22:00:40.0278 0x1884 MozillaMaintenance - ok
22:00:40.0294 0x1884 mpsdrv - ok
22:00:40.0325 0x1884 MpsSvc - ok
22:00:40.0357 0x1884 MRxDAV - ok
22:00:40.0372 0x1884 mrxsmb - ok
22:00:40.0403 0x1884 mrxsmb10 - ok
22:00:40.0435 0x1884 mrxsmb20 - ok
22:00:40.0466 0x1884 MsBridge - ok
22:00:40.0497 0x1884 MSDTC - ok
22:00:40.0544 0x1884 Msfs - ok
22:00:40.0575 0x1884 msgpiowin32 - ok
22:00:40.0591 0x1884 mshidkmdf - ok
22:00:40.0622 0x1884 mshidumdf - ok
22:00:40.0638 0x1884 msisadrv - ok
22:00:40.0669 0x1884 MSiSCSI - ok
22:00:40.0700 0x1884 msiserver - ok
22:00:40.0732 0x1884 MSKSSRV - ok
22:00:40.0747 0x1884 MsLldp - ok
22:00:40.0778 0x1884 MSPCLOCK - ok
22:00:40.0810 0x1884 MSPQM - ok
22:00:40.0841 0x1884 MsRPC - ok
22:00:40.0857 0x1884 mssmbios - ok
22:00:40.0888 0x1884 MSTEE - ok
22:00:40.0903 0x1884 MTConfig - ok
22:00:40.0935 0x1884 Mup - ok
22:00:40.0966 0x1884 mvumis - ok
22:00:41.0013 0x1884 [ F1F6EE6C068CBDB80BAC43A79591F1F2, 39387A25ECFBFDD5B6A43A9A2CA2EC5703D0CCCFFE36C989B0E461B72C242D1C ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
22:00:41.0028 0x1884 MyWiFiDHCPDNS - ok
22:00:41.0060 0x1884 NativeWifiP - ok
22:00:41.0091 0x1884 NcaSvc - ok
22:00:41.0122 0x1884 NcbService - ok
22:00:41.0138 0x1884 NcdAutoSetup - ok
22:00:41.0153 0x1884 ndfltr - ok
22:00:41.0185 0x1884 NDIS - ok
22:00:41.0216 0x1884 NdisCap - ok
22:00:41.0232 0x1884 NdisImPlatform - ok
22:00:41.0263 0x1884 NdisTapi - ok
22:00:41.0278 0x1884 Ndisuio - ok
22:00:41.0294 0x1884 NdisVirtualBus - ok
22:00:41.0325 0x1884 NdisWan - ok
22:00:41.0357 0x1884 ndiswanlegacy - ok
22:00:41.0372 0x1884 ndproxy - ok
22:00:41.0403 0x1884 Ndu - ok
22:00:41.0419 0x1884 NetAdapterCx - ok
22:00:41.0450 0x1884 NetBIOS - ok
22:00:41.0497 0x1884 NetBT - ok
22:00:41.0513 0x1884 Netlogon - ok
22:00:41.0560 0x1884 Netman - ok
22:00:41.0575 0x1884 netprofm - ok
22:00:41.0607 0x1884 NetSetupSvc - ok
22:00:41.0638 0x1884 NetTcpPortSharing - ok
22:00:41.0763 0x1884 [ 9EE21F7D46BD2B0F128E0907BABC7D28, 158CE7A2D8FD23CDAB6DF8EF35F624DF85435D2DF273EABF128D46354E12238B ] NetUtils2016 C:\Windows\system32\drivers\NetUtils2016.sys
22:00:41.0857 0x1884 NetUtils2016 - ok
22:00:41.0888 0x1884 netvsc - ok
22:00:42.0341 0x1884 [ 93F9E44D6AA0FFDE901D53CEF389AADD, 6DBF20DD61F6BF478D3099343B23DC4F45D836192B4E3E95EF0CEAFD63799128 ] NETwNb64 C:\WINDOWS\System32\drivers\Netwbw02.sys
22:00:42.0732 0x1884 NETwNb64 - ok
22:00:43.0107 0x1884 [ 99C24A7DC1F3D4845553B4BD189274A0, 801C2A1F12E6F0D646E92C98477FCDB84C6743803CD7365B774B0F88EB650584 ] NETwNe64 C:\WINDOWS\System32\drivers\NETwew01.sys
22:00:43.0419 0x1884 NETwNe64 - ok
22:00:43.0450 0x1884 NgcCtnrSvc - ok
22:00:43.0482 0x1884 NgcSvc - ok
22:00:43.0513 0x1884 NlaSvc - ok
22:00:43.0544 0x1884 Npfs - ok
22:00:43.0560 0x1884 npsvctrig - ok
22:00:43.0591 0x1884 nsi - ok
22:00:43.0622 0x1884 nsiproxy - ok
22:00:43.0653 0x1884 NTFS - ok
22:00:43.0685 0x1884 Null - ok
22:00:43.0716 0x1884 nvraid - ok
22:00:43.0747 0x1884 nvstor - ok
22:00:43.0841 0x1884 [ 6EECE59EA8BF0FDA859E8D5962081EF2, 8F5A6F648269DBA616DAB1E34940CCE6BE25D0B8EB4C0BFB380FA626EF13A11F ] ogmservice C:\Program Files (x86)\Online Games Manager\ogmservice.exe
22:00:43.0888 0x1884 ogmservice - ok
22:00:43.0919 0x1884 OneSyncSvc - ok
22:00:43.0982 0x1884 [ 5C12E1436BD6CC9ED022CA5335D4F1A0, CE323DE98A4328B348193B10867E16C840224559F391213590629360EFB5F33D ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:00:43.0997 0x1884 ose - ok
22:00:44.0028 0x1884 p2pimsvc - ok
22:00:44.0044 0x1884 p2psvc - ok
22:00:44.0076 0x1884 Parport - ok
22:00:44.0107 0x1884 partmgr - ok
22:00:44.0138 0x1884 PcaSvc - ok
22:00:44.0154 0x1884 pci - ok
22:00:44.0185 0x1884 pciide - ok
22:00:44.0216 0x1884 pcmcia - ok
22:00:44.0247 0x1884 pcw - ok
22:00:44.0279 0x1884 pdc - ok
22:00:44.0310 0x1884 PEAUTH - ok
22:00:44.0435 0x1884 [ EDD4C63050ED1821B4C92D06FFD7180B, 33C6B54147771C813CD78CEF66C0A76CA50D9F1D13D41E6764310BF8C0D8D89D ] PEFService C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
22:00:44.0513 0x1884 PEFService - ok
22:00:44.0544 0x1884 percsas2i - ok
22:00:44.0575 0x1884 percsas3i - ok
22:00:44.0685 0x1884 PerfHost - ok
22:00:44.0747 0x1884 PhoneSvc - ok
22:00:44.0779 0x1884 PimIndexMaintenanceSvc - ok
22:00:44.0825 0x1884 pla - ok
22:00:44.0841 0x1884 PlugPlay - ok
22:00:44.0872 0x1884 PNRPAutoReg - ok
22:00:44.0904 0x1884 PNRPsvc - ok
22:00:44.0935 0x1884 PolicyAgent - ok
22:00:44.0982 0x1884 Power - ok
22:00:45.0013 0x1884 PptpMiniport - ok
22:00:45.0044 0x1884 PrintNotify - ok
22:00:45.0075 0x1884 Processor - ok
22:00:45.0107 0x1884 ProfSvc - ok
22:00:45.0138 0x1884 Psched - ok
22:00:45.0169 0x1884 QWAVE - ok
22:00:45.0200 0x1884 QWAVEdrv - ok
22:00:45.0232 0x1884 RasAcd - ok
22:00:45.0263 0x1884 RasAgileVpn - ok
22:00:45.0294 0x1884 RasAuto - ok
22:00:45.0325 0x1884 Rasl2tp - ok
22:00:45.0357 0x1884 RasMan - ok
22:00:45.0388 0x1884 RasPppoe - ok
22:00:45.0419 0x1884 RasSstp - ok
22:00:45.0450 0x1884 rdbss - ok
22:00:45.0497 0x1884 rdpbus - ok
22:00:45.0529 0x1884 RDPDR - ok
22:00:45.0575 0x1884 RdpVideoMiniport - ok
22:00:45.0607 0x1884 rdyboost - ok
22:00:45.0638 0x1884 ReFSv1 - ok
22:00:45.0685 0x1884 [ B91EE7363FDC2B0CB1C5E6190B46F7DC, 650EE0262F2EE242D99A5BE013A64F76CA3537274C0B9313F9BD7741ACF38017 ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
22:00:45.0700 0x1884 RegSrvc - ok
22:00:45.0747 0x1884 RemoteAccess - ok
22:00:45.0779 0x1884 RemoteRegistry - ok
22:00:45.0810 0x1884 RetailDemo - ok
22:00:45.0841 0x1884 RFCOMM - ok
22:00:45.0857 0x1884 RmSvc - ok
22:00:45.0888 0x1884 RpcEptMapper - ok
22:00:45.0919 0x1884 RpcLocator - ok
22:00:45.0950 0x1884 RpcSs - ok
22:00:45.0966 0x1884 rspndr - ok
22:00:46.0075 0x1884 [ 12A3D1530E3F67B8664EBA923A3981E4, 8670C39EB0A7C37C17D014A8917493B776DE0829B55EFED13D91B6FA7B81CA11 ] rt640x64 C:\WINDOWS\System32\drivers\rt640x64.sys
22:00:46.0169 0x1884 rt640x64 - ok
22:00:46.0482 0x1884 [ 924449B5A5A6AC96BBBED49915E40719, A72CBE9A23919911874CA66CA1B18B77F0B4BDA1C3592B60DB338F23A8FD83D6 ] rtsuvc C:\WINDOWS\system32\DRIVERS\rtsuvc.sys
22:00:46.0763 0x1884 rtsuvc - ok
22:00:46.0794 0x1884 s3cap - ok
22:00:46.0825 0x1884 SamSs - ok
22:00:46.0857 0x1884 sbp2port - ok
22:00:46.0888 0x1884 SCardSvr - ok
22:00:46.0919 0x1884 ScDeviceEnum - ok
22:00:46.0950 0x1884 scfilter - ok
22:00:46.0966 0x1884 Schedule - ok
22:00:46.0997 0x1884 scmbus - ok
22:00:47.0029 0x1884 scmdisk0101 - ok
22:00:47.0060 0x1884 SCPolicySvc - ok
22:00:47.0075 0x1884 sdbus - ok
22:00:47.0107 0x1884 SDRSVC - ok
22:00:47.0138 0x1884 sdstor - ok
22:00:47.0169 0x1884 seclogon - ok
22:00:47.0200 0x1884 SENS - ok
22:00:47.0216 0x1884 SensorDataService - ok
22:00:47.0247 0x1884 SensorService - ok
22:00:47.0279 0x1884 SensorsHIDClassDriver - ok
22:00:47.0310 0x1884 SensrSvc - ok
22:00:47.0325 0x1884 SerCx - ok
22:00:47.0357 0x1884 SerCx2 - ok
22:00:47.0388 0x1884 Serenum - ok
22:00:47.0404 0x1884 Serial - ok
22:00:47.0435 0x1884 sermouse - ok
22:00:47.0513 0x1884 SessionEnv - ok
22:00:47.0544 0x1884 sfloppy - ok
22:00:47.0575 0x1884 SharedAccess - ok
22:00:47.0591 0x1884 ShellHWDetection - ok
22:00:47.0622 0x1884 shpamsvc - ok
22:00:47.0638 0x1884 SiSRaid2 - ok
22:00:47.0669 0x1884 SiSRaid4 - ok
22:00:47.0700 0x1884 smphost - ok
22:00:47.0732 0x1884 SmsRouter - ok
22:00:47.0779 0x1884 SNMPTRAP - ok
22:00:47.0794 0x1884 spaceport - ok
22:00:47.0825 0x1884 SpbCx - ok
22:00:47.0857 0x1884 Spooler - ok
22:00:47.0888 0x1884 sppsvc - ok
22:00:47.0919 0x1884 srv - ok
22:00:47.0950 0x1884 srv2 - ok
22:00:47.0966 0x1884 srvnet - ok
22:00:47.0997 0x1884 SSDPSRV - ok
22:00:48.0029 0x1884 SstpSvc - ok
22:00:48.0075 0x1884 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
22:00:48.0091 0x1884 ssudmdm - ok
22:00:48.0122 0x1884 StateRepository - ok
22:00:48.0138 0x1884 stexstor - ok
22:00:48.0169 0x1884 stisvc - ok
22:00:48.0200 0x1884 storahci - ok
22:00:48.0232 0x1884 storflt - ok
22:00:48.0263 0x1884 stornvme - ok
22:00:48.0294 0x1884 storqosflt - ok
22:00:48.0310 0x1884 StorSvc - ok
22:00:48.0341 0x1884 storufs - ok
22:00:48.0372 0x1884 storvsc - ok
22:00:48.0404 0x1884 svsvc - ok
22:00:48.0419 0x1884 swenum - ok
22:00:48.0450 0x1884 swprv - ok
22:00:48.0482 0x1884 Synth3dVsc - ok
22:00:48.0513 0x1884 SysMain - ok
22:00:48.0544 0x1884 SystemEventsBroker - ok
22:00:48.0575 0x1884 TabletInputService - ok
22:00:48.0607 0x1884 TapiSrv - ok
22:00:48.0622 0x1884 Tcpip - ok
22:00:48.0654 0x1884 Tcpip6 - ok
22:00:48.0700 0x1884 tcpipreg - ok
22:00:48.0747 0x1884 tdx - ok
22:00:48.0763 0x1884 terminpt - ok
22:00:48.0794 0x1884 TermService - ok
22:00:48.0825 0x1884 Themes - ok
22:00:48.0857 0x1884 TieringEngineService - ok
22:00:48.0888 0x1884 tiledatamodelsvc - ok
22:00:48.0919 0x1884 TimeBrokerSvc - ok
22:00:48.0935 0x1884 TPM - ok
22:00:48.0966 0x1884 TrkWks - ok
22:00:48.0997 0x1884 TrustedInstaller - ok
22:00:49.0044 0x1884 tsusbflt - ok
22:00:49.0075 0x1884 TsUsbGD - ok
22:00:49.0107 0x1884 tunnel - ok
22:00:49.0122 0x1884 tzautoupdate - ok
22:00:49.0154 0x1884 UASPStor - ok
22:00:49.0185 0x1884 UcmCx0101 - ok
22:00:49.0216 0x1884 UcmTcpciCx0101 - ok
22:00:49.0247 0x1884 UcmUcsi - ok
22:00:49.0263 0x1884 Ucx01000 - ok
22:00:49.0294 0x1884 UdeCx - ok
22:00:49.0310 0x1884 udfs - ok
22:00:49.0341 0x1884 UEFI - ok
22:00:49.0372 0x1884 Ufx01000 - ok
22:00:49.0404 0x1884 UfxChipidea - ok
22:00:49.0435 0x1884 ufxsynopsys - ok
22:00:49.0482 0x1884 UI0Detect - ok
22:00:49.0513 0x1884 umbus - ok
22:00:49.0529 0x1884 UmPass - ok
22:00:49.0560 0x1884 UmRdpService - ok
22:00:49.0591 0x1884 UnistoreSvc - ok
22:00:49.0638 0x1884 upnphost - ok
22:00:49.0654 0x1884 UrsChipidea - ok
22:00:49.0685 0x1884 UrsCx01000 - ok
22:00:49.0716 0x1884 UrsSynopsys - ok
22:00:49.0747 0x1884 usbccgp - ok
22:00:49.0779 0x1884 usbcir - ok
22:00:49.0810 0x1884 usbehci - ok
22:00:49.0841 0x1884 usbhub - ok
22:00:49.0857 0x1884 USBHUB3 - ok
22:00:49.0888 0x1884 usbohci - ok
22:00:49.0919 0x1884 usbprint - ok
22:00:49.0950 0x1884 usbscan - ok
22:00:49.0966 0x1884 usbser - ok
22:00:49.0997 0x1884 USBSTOR - ok
22:00:50.0013 0x1884 usbuhci - ok
22:00:50.0044 0x1884 USBXHCI - ok
22:00:50.0075 0x1884 UserDataSvc - ok
22:00:50.0122 0x1884 UserManager - ok
22:00:50.0154 0x1884 UsoSvc - ok
22:00:50.0185 0x1884 VaultSvc - ok
22:00:50.0216 0x1884 vdrvroot - ok
22:00:50.0232 0x1884 vds - ok
22:00:50.0263 0x1884 VerifierExt - ok
22:00:50.0294 0x1884 vhdmp - ok
22:00:50.0325 0x1884 vhf - ok
22:00:50.0341 0x1884 vmbus - ok
22:00:50.0372 0x1884 VMBusHID - ok
22:00:50.0404 0x1884 vmgid - ok
22:00:50.0435 0x1884 vmicguestinterface - ok
22:00:50.0450 0x1884 vmicheartbeat - ok
22:00:50.0482 0x1884 vmickvpexchange - ok
22:00:50.0513 0x1884 vmicrdv - ok
22:00:50.0544 0x1884 vmicshutdown - ok
22:00:50.0575 0x1884 vmictimesync - ok
22:00:50.0607 0x1884 vmicvmsession - ok
22:00:50.0622 0x1884 vmicvss - ok
22:00:50.0654 0x1884 volmgr - ok
22:00:50.0685 0x1884 volmgrx - ok
22:00:50.0716 0x1884 volsnap - ok
22:00:50.0747 0x1884 volume - ok
22:00:50.0763 0x1884 vpci - ok
22:00:50.0794 0x1884 vsmraid - ok
22:00:50.0825 0x1884 VSS - ok
22:00:50.0857 0x1884 VSTXRAID - ok
22:00:50.0888 0x1884 vwifibus - ok
22:00:50.0919 0x1884 vwififlt - ok
22:00:50.0951 0x1884 vwifimp - ok
22:00:50.0966 0x1884 W32Time - ok
22:00:50.0997 0x1884 WacomPen - ok
22:00:51.0029 0x1884 WalletService - ok
22:00:51.0075 0x1884 wanarp - ok
22:00:51.0107 0x1884 wanarpv6 - ok
22:00:51.0138 0x1884 wbengine - ok
22:00:51.0169 0x1884 WbioSrvc - ok
22:00:51.0201 0x1884 wcifs - ok
22:00:51.0263 0x1884 Wcmsvc - ok
22:00:51.0279 0x1884 wcncsvc - ok
22:00:51.0310 0x1884 wcnfs - ok
22:00:51.0341 0x1884 WdBoot - ok
22:00:51.0357 0x1884 Wdf01000 - ok
22:00:51.0388 0x1884 WdFilter - ok
22:00:51.0419 0x1884 WdiServiceHost - ok
22:00:51.0482 0x1884 WdiSystemHost - ok
22:00:51.0529 0x1884 wdiwifi - ok
22:00:51.0560 0x1884 WdNisDrv - ok
22:00:51.0575 0x1884 WdNisSvc - ok
22:00:51.0607 0x1884 WebClient - ok
22:00:51.0638 0x1884 Wecsvc - ok
22:00:51.0669 0x1884 WEPHOSTSVC - ok
22:00:51.0700 0x1884 wercplsupport - ok
22:00:51.0747 0x1884 WerSvc - ok
22:00:51.0763 0x1884 WFPLWFS - ok
22:00:51.0794 0x1884 WiaRpc - ok
22:00:51.0825 0x1884 WIMMount - ok
22:00:51.0857 0x1884 WinDefend - ok
22:00:51.0935 0x1884 WindowsTrustedRT - ok
22:00:51.0966 0x1884 WindowsTrustedRTProxy - ok
22:00:51.0997 0x1884 WinHttpAutoProxySvc - ok
22:00:52.0029 0x1884 WinMad - ok
22:00:52.0060 0x1884 Winmgmt - ok
22:00:52.0091 0x1884 WinRM - ok
22:00:52.0154 0x1884 WINUSB - ok
22:00:52.0169 0x1884 WinVerbs - ok
22:00:52.0200 0x1884 wisvc - ok
22:00:52.0232 0x1884 WlanSvc - ok
22:00:52.0263 0x1884 wlidsvc - ok
22:00:52.0294 0x1884 WmiAcpi - ok
22:00:52.0341 0x1884 wmiApSrv - ok
22:00:52.0372 0x1884 WMPNetworkSvc - ok
22:00:52.0419 0x1884 [ 43C8D087B31C592163B33A4BDA540E40, 3A6C4E5E56931B29321DCC723585F2F0E804EF4DCDEAB2A8687F30FC3AE70E43 ] Wof C:\WINDOWS\system32\drivers\Wof.sys
22:00:52.0451 0x1884 Wof - ok
22:00:52.0482 0x1884 workfolderssvc - ok
22:00:52.0513 0x1884 WPDBusEnum - ok
22:00:52.0544 0x1884 WpdUpFltr - ok
22:00:52.0560 0x1884 WpnService - ok
22:00:52.0591 0x1884 WpnUserService - ok
22:00:52.0638 0x1884 ws2ifsl - ok
22:00:52.0669 0x1884 wscsvc - ok
22:00:52.0700 0x1884 WSearch - ok
22:00:52.0747 0x1884 [ 72B4E9DF6456C43C42A1419B09486045, 536BA7377B5BEA7EA46864453933111DB88DB8FB689C68915ACD7261A996E61D ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
22:00:52.0763 0x1884 wsvd - ok
22:00:52.0794 0x1884 wuauserv - ok
22:00:52.0825 0x1884 WudfPf - ok
22:00:52.0857 0x1884 WUDFRd - ok
22:00:52.0888 0x1884 wudfsvc - ok
22:00:52.0904 0x1884 WUDFWpdFs - ok
22:00:52.0935 0x1884 WUDFWpdMtp - ok
22:00:52.0966 0x1884 WwanSvc - ok
22:00:53.0013 0x1884 XblAuthManager - ok
22:00:53.0044 0x1884 XblGameSave - ok
22:00:53.0076 0x1884 xboxgip - ok
22:00:53.0107 0x1884 XboxNetApiSvc - ok
22:00:53.0138 0x1884 xinputhid - ok
22:00:53.0185 0x1884 [ 1C051499D9D8952A1A2DB43A27550D0F, 330C6F21D928633424B1587BF2FFA8E418592836F6C286887745D6C851A15D51 ] ymc C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
22:00:53.0201 0x1884 ymc - ok
22:00:53.0607 0x1884 [ 65308E8DDBCA0A3D7A72E3404E194319, 93D51235D4CB50F3C73DE006843CB98B8940F92BBB84365443C9A31DEB2426A6 ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
22:00:53.0951 0x1884 ZeroConfigService - ok
22:00:53.0982 0x1884 ================ Scan global ===============================
22:00:54.0044 0x1884 [ Global ] - ok
22:00:54.0044 0x1884 ================ Scan MBR ==================================
22:00:54.0060 0x1884 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
22:00:54.0107 0x1884 \Device\Harddisk0\DR0 - ok
22:00:54.0107 0x1884 ================ Scan VBR ==================================
22:00:54.0107 0x1884 [ FDD6257C6F01DC99E967D3AC83279FF9 ] \Device\Harddisk0\DR0\Partition1
22:00:54.0122 0x1884 \Device\Harddisk0\DR0\Partition1 - ok
22:00:54.0138 0x1884 [ 2A8D6B5E0E19D4ED5FDC24E53B4097E2 ] \Device\Harddisk0\DR0\Partition2
22:00:54.0138 0x1884 \Device\Harddisk0\DR0\Partition2 - ok
22:00:54.0154 0x1884 [ 12857D2196A20555591A3449D7583301 ] \Device\Harddisk0\DR0\Partition3
22:00:54.0169 0x1884 \Device\Harddisk0\DR0\Partition3 - ok
22:00:54.0169 0x1884 [ FCB43097861724941B019B69B3C462D4 ] \Device\Harddisk0\DR0\Partition4
22:00:54.0185 0x1884 \Device\Harddisk0\DR0\Partition4 - ok
22:00:54.0201 0x1884 [ 2F9C5DDD29EC85C8B5F73ED574143481 ] \Device\Harddisk0\DR0\Partition5
22:00:54.0216 0x1884 \Device\Harddisk0\DR0\Partition5 - ok
22:00:54.0232 0x1884 [ 488DDECCCC652DC7F4B0CF59FF7270A2 ] \Device\Harddisk0\DR0\Partition6
22:00:54.0232 0x1884 \Device\Harddisk0\DR0\Partition6 - ok
22:00:54.0247 0x1884 [ AF8FE7C55BF252B05E239D87FA128CDB ] \Device\Harddisk0\DR0\Partition7
22:00:54.0247 0x1884 \Device\Harddisk0\DR0\Partition7 - ok
22:00:54.0263 0x1884 ================ Scan generic autorun ======================
22:00:55.0951 0x1884 [ 27D32ED77BC7ABD9E87F0C3CFE99D84A, 2FF9C213022545A58EC0237E9EA234CC7B9B5347C88B42F94AD2EC08EBE6661B ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
22:00:57.0388 0x1884 RtHDVCpl - ok
22:00:57.0622 0x1884 [ 78C48AD707AADA8E7692A5D58E7D6753, ECB5C795A637433ADD0851589B76807F2EB8E4C22392F7312F693A8806AB2782 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
22:00:57.0732 0x1884 RtHDVBg_Dolby - ok
22:00:57.0888 0x1884 [ 78C48AD707AADA8E7692A5D58E7D6753, ECB5C795A637433ADD0851589B76807F2EB8E4C22392F7312F693A8806AB2782 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
22:00:58.0013 0x1884 RtHDVBg_LENOVO_DOLBYDRAGON - ok
22:00:58.0169 0x1884 [ 78C48AD707AADA8E7692A5D58E7D6753, ECB5C795A637433ADD0851589B76807F2EB8E4C22392F7312F693A8806AB2782 ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
22:00:58.0279 0x1884 RtHDVBg_LENOVO_MICPKEY - ok
22:00:58.0388 0x1884 [ 772123B2276B94C797659AEDC0D49943, 6ADD29D91EE5C510B2C7F788FBA034A45400EA25449C1826ABE1296553EF1CBD ] C:\Program Files\Lenovo\LenovoUtility\utility.exe
22:00:58.0451 0x1884 LenovoUtility - ok
22:00:58.0529 0x1884 [ 079511E999ACAB4B8CC08432F0363368, 05A2707AE075206E8913FE6249C0474FE350DCF61F4E8569904D7A8247F012BF ] c:\Program Files\Dolby\DDP_F3\ddpf3.exe
22:00:58.0607 0x1884 DDPF3 - ok
22:00:58.0638 0x1884 [ 03AE229AD0EC7BFDA3D2B37BA9E5799E, E22C1C0F78515595A27812459810774175100D4096D0F0E15812AD3761D1DCC9 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
22:00:58.0638 0x1884 IAStorIcon - ok
22:00:58.0747 0x1884 OneDriveSetup - ok
22:00:58.0763 0x1884 OneDriveSetup - ok
22:00:58.0935 0x1884 [ AAE92457F50F4DD74E2D502ADB9549EE, 70C8FBE410FE388D6B85334215EBE3393C16E8F8B19F5A8BA50DB6DF23196D50 ] C:\Users\Baby\AppData\Local\Microsoft\OneDrive\OneDrive.exe
22:00:59.0060 0x1884 OneDrive - ok
22:00:59.0122 0x1884 [ 88DBF6DF632CAD6B22186DA206829639, CB7FA8F321EDDFAA897E15C5ED212AFAD6469CAD88F966771FF2F824FDE50423 ] C:\Users\Baby\AppData\Roaming\OpenOffice Updater\Updater.exe
22:00:59.0154 0x1884 OpenOffice Updater - ok
22:00:59.0154 0x1884 Waiting for KSN requests completion. In queue: 9
22:01:00.0216 0x1884 AV detected via SS2: Kaspersky Total Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\wmiav.exe ( 17.0.0.611 ), 0x41000 ( enabled : updated )
22:01:00.0216 0x1884 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
22:01:00.0232 0x1884 FW detected via SS2: Kaspersky Total Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 17.0.0\wmiav.exe ( 17.0.0.611 ), 0x41010 ( enabled )
22:01:00.0451 0x1884 ============================================================
22:01:00.0451 0x1884 Scan finished
22:01:00.0451 0x1884 ============================================================
22:01:00.0482 0x2b68 Detected object count: 0
22:01:00.0482 0x2b68 Actual detected object count: 0
22:01:03.0966 0x2364 Deinitialize success |