Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Readme.hta Ransomware

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 15.10.2016, 08:05   #1
andre_schmid
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Hallo zusammen,

leider hab ich mir am 12.10.2016 einen Trojaner geholt.
Es werden auf allen Laufwerken die Textdokumente verschlüsselt zu Dateien mit der Endung *.8684
In jedem Ordner, wo so eine Verschlüsselung vorgenommen wurde, wird außerdem eine Datei mit dem Namen "Readme.hta" erstellt.

Nun hab ich gestern mit Adwarecleaner eine Datei gefunden und gelöscht. Seither lief das System stabil. Habe alle "Readme.hta" Dateien gelöscht. Dann war ich mit Datensichern beschäftigt, um nicht noch mehr Dateien zu verlieren.

Leider begannen die Troubles heute erneut. Mein PC wurde langsam. Im Taskmanager sah ich, dass immer wieder ein neuer "Internet Explorer" Prozess gestartet wurde. Es lief dann Werbung auf meinen Boxen, ohne, dass ich den Internet Explorer selber sah. Die vielen Internet Explorer Prozesse ließen sich nicht so schnell beenden, wie neue gestartet wurden. Ich musse den PC schnell herunterfahren.
Nun im abgesicherten Modus läuft er stabil.

Gerade lasse ich "Maleware-bytes" über meinen Rechner laufen. Was kann ich sonst machen. Hat jemand Erfahrung mit dem Trojaner und/oder Tipps für mich?

Bei Google findet man jede Menge Seiten, die angeben, eine Lösung für den Trojaner parat zu haben - dies sind jedoch so ziemlich alles gefakte Seiten, die selbst weitere Gefahren bereit halten...

Bitte um Hilfe - danke!!

André

Alt 15.10.2016, 13:43   #2
M-K-D-B
/// TB-Ausbilder
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware






Mein Name ist Matthias und ich werde dir bei der Bereinigung deines Computers helfen.


Bitte beachte folgende Hinweise:
  • Falls wir Hinweise auf illegal erworbene Software finden, werden wir den Support unterbrechen bis jegliche Art von illegaler Software vom Rechner entfernt wurde.
  • Lies dir die Anleitungen sorgfältig durch. Solltest du Probleme haben, stoppe mit deiner Bearbeitung und beschreibe mir dein Problem so gut es geht.
  • Solltest du mir nicht innerhalb von 3 Tagen antworten, gehe ich davon aus, dass du keine Hilfe mehr benötigst. Dann lösche ich dein Thema aus meinem Abo. Solltest du einmal länger abwesend sein, so gib mir bitte Bescheid!
  • Während der Bereinigung bitte nichts installieren oder deinstallieren, außer ich bitte dich darum!
  • Bitte beachten: Download bei filepony.de: So ladet Ihr unsere Tools richtig!
  • Alle zu verwendenen Programme sind auf dem Desktop abzuspeichern und von dort als Administrator zu starten!
  • Einige Programme, die wir hier verwenden, können unter Umständen von deinem Antiviren- oder Anti-Malwareprogramm fälschlicherweise als Bedrohung eingestuft werden. Die Sicherheitsprogramme können aufgrund eines bestimmten Programmverhaltens nicht zwischen "gut" oder "böse" unterscheiden und schlagen Alarm. Dabei handelt es sich um Fehlalarme, welche du getrost ignorieren kannst. Gegebenenfalls musst du deine Sicherheitssoftware vor der Ausführung eines Programms deaktivieren, damit unsere Bereinigungsvorgänge nicht beeinträchtigt werden.



Bitte arbeite alle Schritte in der vorgegebenen Reihefolge nacheinander ab und poste alle Logdateien in CODE-Tags:
So funktioniert es:
Posten in CODE-Tags
Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert deinem Helfer massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu groß für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
  • Markiere das gesamte Logfile (geht meist mit STRG+A) und kopiere es in die Zwischenablage mit STRG+C.
  • Klicke im Editor auf das #-Symbol. Es erscheinen zwei Klammerausdrücke [CODE] [/CODE].
  • Setze den Curser zwischen die CODE-Tags und drücke STRG+V.
  • Klicke aauf Erweitert/Vorschau, um so prüfen, ob du es richtig gemacht hast. Wenn alles stimmt ... auf Antworten.

Danke für deine Mitarbeit!




Sieht nach Cerber Ransomware aus.

Zur ersten Analyse bitte FRST und TDSS-Killer bitte im normalen Modus (wenn möglich) ausführen. Sollte der normale Modus gar nicht gehen, dann bitte im abgesicherten Modus mit Netzwerkunterstützung.

Außerdem bitte die Logdateien von AdwCleaner und MBAM mit den Funden nachreichen.




Schritt 1
  • Besuche diese Seite.
  • Unter "Sample Encrypted File" klicke auf Durchsuchen.
  • Wähle eine verschlüsselte Datei aus und lade diese hoch.
  • Nach der Analyse sollte dort stehen, um welchen Verschlüsselungstrojaner es sich handelt und ob es einen sog. Decrypter gibt oder nicht.
    Poste mir das Ergebnis der Analyse mit deiner nächsten Antwort.





Schritt 2
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)






Schritt 3
Downloade dir bitte TDSSKiller TDSSKiller.exe und speichere diese Datei auf dem Desktop
  • Starte die TDSSKiller.exe - Einstellen wie in der Anleitung zu TDSSKiller beschrieben.
  • Drücke Start Scan
  • Sollten infizierte Objekte gefunden werden, wähle keinesfalls Cure. Wähle Skip und klicke auf Continue.
    TDSSKiller wird eine Logfile auf deinem Systemlaufwerk speichern (Meistens C:\)
    Als Beispiel: C:\TDSSKiller.<Version_Datum_Uhrzeit>log.txt
Poste den Inhalt bitte in jedem Fall hier in deinen Thread.







Bitte poste mit deiner nächsten Antwort
  • die Info von id-ransomware,
  • die Logdatei von TDSS-Killer,
  • die beiden neuen Logdateien von FRST,
  • die Logdateien von AdwCleaner und MBAM mit den Funden, die bereits entfernt wurden.
__________________


Alt 17.10.2016, 10:32   #3
andre_schmid
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Ergebnis Schritt 1:

1 Result
Cerber 4.0
This ransomware has no known way of decrypting data at this time.

It is recommended to backup your encrypted files, and hope for a solution in the future.

Identified by

sample_extension: .<random 4 characters>

Click here for more information about Cerber 4.0
__________________

Alt 17.10.2016, 10:40   #4
andre_schmid
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Ergebnis Schritt 2:

siehe die beiden TXT Dateien anbei

Alt 17.10.2016, 10:45   #5
andre_schmid
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Ergebnis Schirtt 3:

(Datei ist zu groß, darum hier der Text aus der txt-Datei kopiert):

11:41:26.0706 0x091c TDSS rootkit removing tool 3.1.0.11 Aug 5 2016 12:13:31
11:41:29.0998 0x091c ============================================================
11:41:29.0998 0x091c Current date / time: 2016/10/17 11:41:29.0998
11:41:29.0998 0x091c SystemInfo:
11:41:29.0998 0x091c
11:41:29.0998 0x091c OS Version: 6.1.7601 ServicePack: 1.0
11:41:29.0998 0x091c Product type: Workstation
11:41:29.0998 0x091c ComputerName: ANDRE_PC
11:41:29.0998 0x091c UserName: Andre
11:41:29.0998 0x091c Windows directory: C:\Windows
11:41:29.0998 0x091c System windows directory: C:\Windows
11:41:29.0998 0x091c Running under WOW64
11:41:29.0998 0x091c Processor architecture: Intel x64
11:41:29.0998 0x091c Number of processors: 8
11:41:29.0998 0x091c Page size: 0x1000
11:41:29.0998 0x091c Boot type: Safe boot with network
11:41:29.0998 0x091c CodeIntegrityOptions = 0x00000001
11:41:29.0998 0x091c ============================================================
11:41:31.0529 0x091c KLMD registered as C:\Windows\system32\drivers\99801771.sys
11:41:31.0529 0x091c KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.23418, osProperties = 0x1
11:41:31.0673 0x091c System UUID: {DDEA225C-708C-D089-DF71-F1AFA495CB2E}
11:41:31.0957 0x091c Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:41:31.0963 0x091c Drive \Device\Harddisk1\DR1 - Size: 0x15D50F66000 ( 1397.27 Gb ), SectorSize: 0x200, Cylinders: 0x2F509, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
11:41:31.0965 0x091c Drive \Device\Harddisk2\DR2 - Size: 0x1D1C0F00000 ( 1863.01 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
11:41:32.0037 0x091c ============================================================
11:41:32.0037 0x091c \Device\Harddisk0\DR0:
11:41:32.0037 0x091c MBR partitions:
11:41:32.0037 0x091c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
11:41:32.0037 0x091c \Device\Harddisk1\DR1:
11:41:32.0037 0x091c MBR partitions:
11:41:32.0037 0x091c \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:41:32.0037 0x091c \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x61A4D800
11:41:32.0037 0x091c \Device\Harddisk1\DR1\Partition3: MBR, Type 0x7, StartLBA 0x61A80000, BlocksNum 0x4D007000
11:41:32.0037 0x091c \Device\Harddisk2\DR2:
11:41:32.0037 0x091c MBR partitions:
11:41:32.0037 0x091c \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07000
11:41:32.0037 0x091c ============================================================
11:41:32.0052 0x091c C: <-> \Device\Harddisk1\DR1\Partition2
11:41:32.0057 0x091c D: <-> \Device\Harddisk1\DR1\Partition1
11:41:32.0084 0x091c E: <-> \Device\Harddisk1\DR1\Partition3
11:41:32.0984 0x091c G: <-> \Device\Harddisk2\DR2\Partition1
11:41:33.0024 0x091c H: <-> \Device\Harddisk0\DR0\Partition1
11:41:33.0024 0x091c ============================================================
11:41:33.0024 0x091c Initialize success
11:41:33.0024 0x091c ============================================================
11:42:18.0509 0x0c3c ============================================================
11:42:18.0509 0x0c3c Scan started
11:42:18.0509 0x0c3c Mode: Manual; SigCheck; TDLFS;
11:42:18.0509 0x0c3c ============================================================
11:42:18.0509 0x0c3c KSN ping started
11:42:29.0649 0x0c3c KSN ping finished: true
11:42:31.0819 0x0c3c ================ Scan system memory ========================
11:42:31.0819 0x0c3c System memory - ok
11:42:31.0819 0x0c3c ================ Scan services =============================
11:42:31.0909 0x0c3c [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
11:42:31.0948 0x0c3c 1394ohci - ok
11:42:31.0962 0x0c3c [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:42:31.0973 0x0c3c ACPI - ok
11:42:31.0986 0x0c3c [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:42:31.0993 0x0c3c AcpiPmi - ok
11:42:32.0107 0x0c3c [ DC00FD73505DAEDD99CAF4533B0C05BD, 2863D1F0587B79254FBE093C191C73892768CF2AC59BEF97745EE66CEE3473AF ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:42:32.0126 0x0c3c AdobeARMservice - ok
11:42:32.0191 0x0c3c [ 1E30AB3A4D3EB916FF6C1B71B9F2331A, 4D1D703CD16FAE5096A8897DDC69C925FA3BFF1F45E1EA55898BF251AF0D3E9A ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
11:42:32.0199 0x0c3c AdobeFlashPlayerUpdateSvc - ok
11:42:32.0225 0x0c3c [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
11:42:32.0238 0x0c3c adp94xx - ok
11:42:32.0252 0x0c3c [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\drivers\adpahci.sys
11:42:32.0262 0x0c3c adpahci - ok
11:42:32.0283 0x0c3c [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
11:42:32.0291 0x0c3c adpu320 - ok
11:42:32.0316 0x0c3c [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:42:32.0323 0x0c3c AeLookupSvc - ok
11:42:32.0352 0x0c3c [ 9A4A1EEE802BF2F878EE8EAB407B21B7, 177EB7DF4B35FE4C0E45E775A0FD5D48D39B410052E3EE18BDEEC809E152D9D8 ] AFD C:\Windows\system32\drivers\afd.sys
11:42:32.0365 0x0c3c AFD - ok
11:42:32.0376 0x0c3c [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys
11:42:32.0382 0x0c3c agp440 - ok
11:42:32.0400 0x0c3c [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe
11:42:32.0407 0x0c3c ALG - ok
11:42:32.0430 0x0c3c [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys
11:42:32.0434 0x0c3c aliide - ok
11:42:32.0445 0x0c3c [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys
11:42:32.0450 0x0c3c amdide - ok
11:42:32.0465 0x0c3c [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
11:42:32.0471 0x0c3c AmdK8 - ok
11:42:32.0481 0x0c3c [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
11:42:32.0487 0x0c3c AmdPPM - ok
11:42:32.0530 0x0c3c [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:42:32.0537 0x0c3c amdsata - ok
11:42:32.0562 0x0c3c [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
11:42:32.0570 0x0c3c amdsbs - ok
11:42:32.0572 0x0c3c [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:42:32.0577 0x0c3c amdxata - ok
11:42:32.0651 0x0c3c [ 1B534F5AE93CA21DBA5FF502F5353B66, DCA07FD29FEF0FD3025DD12E3B047B99D4FAD387E37A84C3859D12C1ECD1080B ] AntiVirMailService C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
11:42:32.0693 0x0c3c AntiVirMailService - ok
11:42:32.0721 0x0c3c [ 0511A349A99745B0811B94A008C639BE, E0FA78704957562C66C83E730882560F71C92E297B67DB6A9D2954DA23154826 ] AntiVirSchedulerService C:\Program Files (x86)\Avira\Antivirus\sched.exe
11:42:32.0734 0x0c3c AntiVirSchedulerService - ok
11:42:32.0748 0x0c3c [ 0511A349A99745B0811B94A008C639BE, E0FA78704957562C66C83E730882560F71C92E297B67DB6A9D2954DA23154826 ] AntiVirService C:\Program Files (x86)\Avira\Antivirus\avguard.exe
11:42:32.0760 0x0c3c AntiVirService - ok
11:42:32.0799 0x0c3c [ AAD3327DE3F2C90421E5BBFA4E63B6BA, 25E6BEAD80898F7422973EABAB2AAADE0A760F7B5CFCC3714966B464135640CB ] AntiVirWebService C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
11:42:32.0830 0x0c3c AntiVirWebService - ok
11:42:32.0855 0x0c3c [ 6474F8823C7188D2DA579F01FB6CED6B, 81D4E9D026CA60FB8840D520D151B8C2F4745A75DF90A4D6C80641F1A23AB605 ] AppID C:\Windows\system32\drivers\appid.sys
11:42:32.0861 0x0c3c AppID - ok
11:42:32.0872 0x0c3c [ 8F58BA1F7772D6D7CE45F03309608001, CDB109E0DD241042C058F7D81A1BDEBC34435CB2DC4A7A7A3692193DD5806097 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:42:32.0877 0x0c3c AppIDSvc - ok
11:42:32.0908 0x0c3c [ B62867835B41BCD839D9896AB4D7DF09, 98036D0202DB6171E90485898175833AC44873A85E6453EBE928E433B364CE07 ] Appinfo C:\Windows\System32\appinfo.dll
11:42:32.0914 0x0c3c Appinfo - ok
11:42:32.0931 0x0c3c [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt C:\Windows\System32\appmgmts.dll
11:42:32.0939 0x0c3c AppMgmt - ok
11:42:32.0955 0x0c3c [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\drivers\arc.sys
11:42:32.0961 0x0c3c arc - ok
11:42:32.0967 0x0c3c [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\drivers\arcsas.sys
11:42:32.0973 0x0c3c arcsas - ok
11:42:33.0043 0x0c3c [ F15AB80B867D3332D5DDFB0A05B9CE04, 5A16577106246AB5DCC04FE0A0B00B7C5702557B75F958721E4C00383AB99809 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
11:42:33.0058 0x0c3c aspnet_state - ok
11:42:33.0060 0x0c3c [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:42:33.0079 0x0c3c AsyncMac - ok
11:42:33.0104 0x0c3c [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys
11:42:33.0109 0x0c3c atapi - ok
11:42:33.0155 0x0c3c [ 7D89B0C443F6068E5B27AA3B972069FF, 34CBB7D44D060F1D614BCA1357C8A260A002C21E67D33E819F57815AC400CCBD ] athr C:\Windows\system32\DRIVERS\athrx.sys
11:42:33.0185 0x0c3c athr - ok
11:42:33.0228 0x0c3c [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:42:33.0245 0x0c3c AudioEndpointBuilder - ok
11:42:33.0258 0x0c3c [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioSrv C:\Windows\System32\Audiosrv.dll
11:42:33.0274 0x0c3c AudioSrv - ok
11:42:33.0309 0x0c3c [ C7255291C3FDA7EC6FB4F928C442E0D4, DFA0CDB1E6DC981A4A7C81098B0A26571C6BFE3A4E186BD592E285C3927E2823 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys
11:42:33.0317 0x0c3c avgntflt - ok
11:42:33.0336 0x0c3c [ E745629CBC104D2B446CFB859084BEB5, 3FC86742A44D9867F7CE7FD28DB4591B745495AF6A96E057A5F62ACD87E9E5B5 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys
11:42:33.0343 0x0c3c avipbb - ok
11:42:33.0400 0x0c3c [ A177265C1777ABE56B22D921F91DDC38, D4E9C5BFC65063EDA015723058805B03C51F5B7456B404A4548CEC8DF6A3F7B7 ] Avira.ServiceHost C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
11:42:33.0409 0x0c3c Avira.ServiceHost - ok
11:42:33.0439 0x0c3c [ 390184FAD8FCC1B6DA25AEBAE928C3B6, 537B0E0FAE080B55D70E990BBA0F7F22903CA340F6A42039BAD617A8ECF59119 ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys
11:42:33.0444 0x0c3c avkmgr - ok
11:42:33.0470 0x0c3c [ 138A53D17B040F5A3A307D44A89D0905, AD212E430F2DE43F037BECF6A46FCD53270A5EE11427030C7D5CBC3EAAAAA029 ] avnetflt C:\Windows\system32\DRIVERS\avnetflt.sys
11:42:33.0476 0x0c3c avnetflt - ok
11:42:33.0500 0x0c3c [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:42:33.0510 0x0c3c AxInstSV - ok
11:42:33.0529 0x0c3c [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
11:42:33.0542 0x0c3c b06bdrv - ok
11:42:33.0551 0x0c3c [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
11:42:33.0561 0x0c3c b57nd60a - ok
11:42:33.0568 0x0c3c [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll
11:42:33.0574 0x0c3c BDESVC - ok
11:42:33.0592 0x0c3c [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys
11:42:33.0611 0x0c3c Beep - ok
11:42:33.0633 0x0c3c [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll
11:42:33.0650 0x0c3c BFE - ok
11:42:33.0683 0x0c3c [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll
11:42:33.0716 0x0c3c BITS - ok
11:42:33.0727 0x0c3c [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:42:33.0733 0x0c3c blbdrive - ok
11:42:33.0766 0x0c3c [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:42:33.0773 0x0c3c bowser - ok
11:42:33.0778 0x0c3c [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
11:42:33.0785 0x0c3c BrFiltLo - ok
11:42:33.0787 0x0c3c [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
11:42:33.0794 0x0c3c BrFiltUp - ok
11:42:33.0821 0x0c3c [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser C:\Windows\System32\browser.dll
11:42:33.0829 0x0c3c Browser - ok
11:42:33.0839 0x0c3c [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:42:33.0848 0x0c3c Brserid - ok
11:42:33.0858 0x0c3c [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:42:33.0866 0x0c3c BrSerWdm - ok
11:42:33.0873 0x0c3c [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:42:33.0880 0x0c3c BrUsbMdm - ok
11:42:33.0882 0x0c3c [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:42:33.0887 0x0c3c BrUsbSer - ok
11:42:33.0896 0x0c3c [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
11:42:33.0904 0x0c3c BTHMODEM - ok
11:42:33.0910 0x0c3c [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll
11:42:33.0930 0x0c3c bthserv - ok
11:42:33.0934 0x0c3c [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:42:33.0955 0x0c3c cdfs - ok
11:42:33.0960 0x0c3c [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
11:42:33.0967 0x0c3c cdrom - ok
11:42:33.0973 0x0c3c [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll
11:42:33.0993 0x0c3c CertPropSvc - ok
11:42:33.0996 0x0c3c [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\drivers\circlass.sys
11:42:34.0004 0x0c3c circlass - ok
11:42:34.0019 0x0c3c [ 404B7DF9CA4D1CB675045AF220FF3285, 91FFADE2ABE5C48849E63134D5FFD20671FE0D1720F7D486F904391B3D142C96 ] CLFS C:\Windows\system32\CLFS.sys
11:42:34.0031 0x0c3c CLFS - ok
11:42:34.0067 0x0c3c [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:42:34.0074 0x0c3c clr_optimization_v2.0.50727_32 - ok
11:42:34.0091 0x0c3c [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
11:42:34.0098 0x0c3c clr_optimization_v2.0.50727_64 - ok
11:42:34.0167 0x0c3c [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:42:34.0217 0x0c3c clr_optimization_v4.0.30319_32 - ok
11:42:34.0233 0x0c3c [ 9ACBE5EC13C2CC95833BFB7636CA8B1A, 6224DA9FB335D2A8374C60B8DEA539DD3A0E43230DB888B137B71A56EC57D6AF ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
11:42:34.0255 0x0c3c clr_optimization_v4.0.30319_64 - ok
11:42:34.0265 0x0c3c [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\drivers\CmBatt.sys
11:42:34.0271 0x0c3c CmBatt - ok
11:42:34.0282 0x0c3c [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:42:34.0287 0x0c3c cmdide - ok
11:42:34.0320 0x0c3c [ 3323F76352B0AF14B2CDC4DFBF3E980A, F8E3C3508C37E647497B6889F26819B1DB30275F48A994D1BBFBAA9454E5FD70 ] CNG C:\Windows\system32\Drivers\cng.sys
11:42:34.0337 0x0c3c CNG - ok
11:42:34.0354 0x0c3c [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
11:42:34.0359 0x0c3c Compbatt - ok
11:42:34.0370 0x0c3c [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
11:42:34.0377 0x0c3c CompositeBus - ok
11:42:34.0379 0x0c3c COMSysApp - ok
11:42:34.0385 0x0c3c [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
11:42:34.0390 0x0c3c crcdisk - ok
11:42:34.0412 0x0c3c [ 7BC3E861F7E8EB543A630090FAE779E0, 52A538F25C853AAC9706CD0D4EBF80B1963391AA175895CFD9D44C8ABBFCFB74 ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:42:34.0420 0x0c3c CryptSvc - ok
11:42:34.0443 0x0c3c [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC C:\Windows\system32\drivers\csc.sys
11:42:34.0457 0x0c3c CSC - ok
11:42:34.0474 0x0c3c [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService C:\Windows\System32\cscsvc.dll
11:42:34.0490 0x0c3c CscService - ok
11:42:34.0580 0x0c3c [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdate C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
11:42:34.0587 0x0c3c dbupdate - ok
11:42:34.0605 0x0c3c [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdatem C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
11:42:34.0611 0x0c3c dbupdatem - ok
11:42:34.0614 0x0c3c dbx - ok
11:42:34.0658 0x0c3c [ A8352D11F8E2F7E8FA0BD6F8EF599C61, 72B9F8B96433CCFE5CC9FB786BF976068BDDC04D39F9F3BCFA5132E61A97C3FD ] DbxSvc C:\Windows\system32\DbxSvc.exe
11:42:34.0667 0x0c3c DbxSvc - ok
11:42:34.0707 0x0c3c [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] DcomLaunch C:\Windows\system32\rpcss.dll
11:42:34.0721 0x0c3c DcomLaunch - ok
11:42:34.0739 0x0c3c [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll
11:42:34.0762 0x0c3c defragsvc - ok
11:42:34.0769 0x0c3c [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:42:34.0789 0x0c3c DfsC - ok
11:42:34.0805 0x0c3c [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll
11:42:34.0815 0x0c3c Dhcp - ok
11:42:34.0881 0x0c3c [ EC3F433D00365F1A9BC3411BCA7C7140, 0852D747359DE573504EBBDB99DA26D3BFA8B3C7A4836F8E3A5AD94B5571AD5C ] DiagTrack C:\Windows\system32\diagtrack.dll
11:42:34.0909 0x0c3c DiagTrack - ok
11:42:34.0982 0x0c3c [ BB5B80616BD01A9C59BF1D52BA238EDA, 8168F38127EC955B25AD4EF61081D86473E4959F797F68055E6210080EFEFF9F ] DigitalWave.Update.Service C:\Program Files (x86)\Common Files\DVDVideoSoft\lib\app_updater.exe
11:42:34.0995 0x0c3c DigitalWave.Update.Service - ok
11:42:35.0003 0x0c3c [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys
11:42:35.0022 0x0c3c discache - ok
11:42:35.0046 0x0c3c [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk C:\Windows\system32\drivers\disk.sys
11:42:35.0052 0x0c3c Disk - ok
11:42:35.0067 0x0c3c [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys
11:42:35.0073 0x0c3c dmvsc - ok
11:42:35.0105 0x0c3c [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:42:35.0112 0x0c3c Dnscache - ok
11:42:35.0124 0x0c3c [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll
11:42:35.0146 0x0c3c dot3svc - ok
11:42:35.0153 0x0c3c [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll
11:42:35.0174 0x0c3c DPS - ok
11:42:35.0193 0x0c3c [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:42:35.0198 0x0c3c drmkaud - ok
11:42:35.0240 0x0c3c [ 3A9D7D464BDB3B70D7ECF689ADABBD4D, B4F5B23705EA1BA453FE30791CA245E1A5F7FBEABAD026E4A8A15A9FC44E8C9C ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:42:35.0261 0x0c3c DXGKrnl - ok
11:42:35.0282 0x0c3c [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll
11:42:35.0303 0x0c3c EapHost - ok
11:42:35.0383 0x0c3c [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\drivers\evbda.sys
11:42:35.0441 0x0c3c ebdrv - ok
11:42:35.0471 0x0c3c [ 13FE29C1C8E782829C7FAA3B14F4A666, C53F7F9039E79AC6D5BDA94981A187570D6C7828930B6064CEFC17DC172EA20E ] EFS C:\Windows\System32\lsass.exe
11:42:35.0477 0x0c3c EFS - ok
11:42:35.0527 0x0c3c [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:42:35.0544 0x0c3c ehRecvr - ok
11:42:35.0558 0x0c3c [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe
11:42:35.0566 0x0c3c ehSched - ok
11:42:35.0594 0x0c3c [ BDD265EEB37DF5953A547FE412E2472F, 17EB4FD54D62207937F8CA7454837DBF1EEC867AEDAF201FC2E839A3ED357F4F ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys
11:42:35.0599 0x0c3c ElbyCDIO - ok
11:42:35.0617 0x0c3c [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\drivers\elxstor.sys
11:42:35.0631 0x0c3c elxstor - ok
11:42:35.0638 0x0c3c [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:42:35.0643 0x0c3c ErrDev - ok
11:42:35.0668 0x0c3c [ 84486624268E078255BC7AA47F0960BC, EC2540698B974572F0AC4A93D57C63295BAF66BF50F7416B9DFF5DE790EBDBE7 ] etdrv C:\Windows\etdrv.sys
11:42:35.0673 0x0c3c etdrv - ok
11:42:35.0687 0x0c3c [ 6C17A702399B0205AB7836C2B45CD806, 54BACC652D905A31959031DE1F6116187D6E7961D05DBC2211904CB7EE7E9CFC ] EtronHub3 C:\Windows\system32\Drivers\EtronHub3.sys
11:42:35.0691 0x0c3c EtronHub3 - ok
11:42:35.0705 0x0c3c [ B5348A55CC9541FFA930E30BB0CC8EF6, D20DC1B5BD6DB6AF621611ADE9CDA413587C58515B84814423339AC7BD89F775 ] EtronXHCI C:\Windows\system32\Drivers\EtronXHCI.sys
11:42:35.0709 0x0c3c EtronXHCI - ok
11:42:35.0761 0x0c3c [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll
11:42:35.0787 0x0c3c EventSystem - ok
11:42:35.0805 0x0c3c [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys
11:42:35.0828 0x0c3c exfat - ok
11:42:35.0837 0x0c3c [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:42:35.0859 0x0c3c fastfat - ok
11:42:35.0885 0x0c3c [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe
11:42:35.0901 0x0c3c Fax - ok
11:42:35.0915 0x0c3c [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\drivers\fdc.sys
11:42:35.0921 0x0c3c fdc - ok
11:42:35.0933 0x0c3c [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll
11:42:35.0952 0x0c3c fdPHost - ok
11:42:35.0961 0x0c3c [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll
11:42:35.0981 0x0c3c FDResPub - ok
11:42:35.0992 0x0c3c [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:42:35.0998 0x0c3c FileInfo - ok
11:42:36.0003 0x0c3c [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:42:36.0023 0x0c3c Filetrace - ok
11:42:36.0036 0x0c3c [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
11:42:36.0042 0x0c3c flpydisk - ok
11:42:36.0054 0x0c3c [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:42:36.0064 0x0c3c FltMgr - ok
11:42:36.0124 0x0c3c [ BCB16AE33AA58E0042F3EF34CFB6396A, E8ADA10DE60A94E4BABE9FCA6D0AA83B11520C092D49057E17F6C6059D35A323 ] FontCache C:\Windows\system32\FntCache.dll
11:42:36.0148 0x0c3c FontCache - ok
11:42:36.0175 0x0c3c [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:42:36.0180 0x0c3c FontCache3.0.0.0 - ok
11:42:36.0182 0x0c3c [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:42:36.0188 0x0c3c FsDepends - ok
11:42:36.0202 0x0c3c [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:42:36.0207 0x0c3c Fs_Rec - ok
11:42:36.0234 0x0c3c [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:42:36.0245 0x0c3c fvevol - ok
11:42:36.0253 0x0c3c [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
11:42:36.0259 0x0c3c gagp30kx - ok
11:42:36.0277 0x0c3c [ 7907E14F9BCF3A4689C9A74A1A873CB6, 17927B93B2D6AB4271C158F039CAE2D60591D6A14458F5A5690AEC86F5D54229 ] gdrv C:\Windows\gdrv.sys
11:42:36.0281 0x0c3c gdrv - ok
11:42:36.0306 0x0c3c [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc C:\Windows\System32\gpsvc.dll
11:42:36.0325 0x0c3c gpsvc - ok
11:42:36.0354 0x0c3c [ 8126331FBD4ED29EB3B356F9C905064D, A58BCE904591DD762410E99960FD956FB579C2CE78FA7BF1406075D29537EF82 ] GVTDrv64 C:\Windows\GVTDrv64.sys
11:42:36.0358 0x0c3c GVTDrv64 - ok
11:42:36.0377 0x0c3c [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:42:36.0382 0x0c3c hcw85cir - ok
11:42:36.0403 0x0c3c [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:42:36.0415 0x0c3c HdAudAddService - ok
11:42:36.0430 0x0c3c [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
11:42:36.0439 0x0c3c HDAudBus - ok
11:42:36.0444 0x0c3c [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
11:42:36.0450 0x0c3c HidBatt - ok
11:42:36.0464 0x0c3c [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\drivers\hidbth.sys
11:42:36.0472 0x0c3c HidBth - ok
11:42:36.0479 0x0c3c [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\drivers\hidir.sys
11:42:36.0487 0x0c3c HidIr - ok
11:42:36.0510 0x0c3c [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll
11:42:36.0530 0x0c3c hidserv - ok
11:42:36.0561 0x0c3c [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
11:42:36.0566 0x0c3c HidUsb - ok
11:42:36.0601 0x0c3c [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:42:36.0621 0x0c3c hkmsvc - ok
11:42:36.0635 0x0c3c [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:42:36.0645 0x0c3c HomeGroupListener - ok
11:42:36.0653 0x0c3c [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:42:36.0661 0x0c3c HomeGroupProvider - ok
11:42:36.0664 0x0c3c [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:42:36.0670 0x0c3c HpSAMD - ok
11:42:36.0712 0x0c3c [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:42:36.0729 0x0c3c HTTP - ok
11:42:36.0831 0x0c3c [ E5805896A55D4166C20F216249F40FA3, F426BF60D5B916E7A778EF24C49FE1FFE1B2977C2ABD2977FD5C38C6E6CB139F ] HWiNFO32 C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS
11:42:36.0835 0x0c3c HWiNFO32 - ok
11:42:36.0843 0x0c3c [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:42:36.0848 0x0c3c hwpolicy - ok
11:42:36.0851 0x0c3c [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
11:42:36.0858 0x0c3c i8042prt - ok
11:42:36.0902 0x0c3c [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:42:36.0914 0x0c3c iaStorV - ok
11:42:36.0950 0x0c3c [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
11:42:36.0952 0x0c3c IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
11:42:37.0083 0x0c3c Detect skipped due to KSN trusted
11:42:37.0083 0x0c3c IDriverT - ok
11:42:37.0134 0x0c3c [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
11:42:37.0153 0x0c3c idsvc - ok
11:42:37.0156 0x0c3c IEEtwCollectorService - ok
11:42:37.0173 0x0c3c [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\drivers\iirsp.sys
11:42:37.0179 0x0c3c iirsp - ok
11:42:37.0220 0x0c3c [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT C:\Windows\System32\ikeext.dll
11:42:37.0240 0x0c3c IKEEXT - ok
11:42:37.0261 0x0c3c [ BEF622DCE5FC16655100B9C6ABAA4C9C, E81440B179F4D5BCF965BA73F050EB7766D8C7AF8B924D231FEAAA2DD6E1ECDA ] iLokDrvr C:\Windows\system32\DRIVERS\iLokDrvr.sys
11:42:37.0265 0x0c3c iLokDrvr - ok
11:42:37.0326 0x0c3c [ 03076F51AF9F78A272CCCDE03E9340CE, 60B6B236618FD8A0ACCC17EB086F0573A5CC4FFE78CE26702981580D5F68FB0D ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
11:42:37.0373 0x0c3c IntcAzAudAddService - ok
11:42:37.0408 0x0c3c [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys
11:42:37.0413 0x0c3c intelide - ok
11:42:37.0423 0x0c3c [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:42:37.0430 0x0c3c intelppm - ok
11:42:37.0449 0x0c3c [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:42:37.0470 0x0c3c IPBusEnum - ok
11:42:37.0478 0x0c3c [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:42:37.0498 0x0c3c IpFilterDriver - ok
11:42:37.0529 0x0c3c [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:42:37.0544 0x0c3c iphlpsvc - ok
11:42:37.0559 0x0c3c [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:42:37.0566 0x0c3c IPMIDRV - ok
11:42:37.0582 0x0c3c [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:42:37.0603 0x0c3c IPNAT - ok
11:42:37.0610 0x0c3c [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:42:37.0619 0x0c3c IRENUM - ok
11:42:37.0636 0x0c3c [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:42:37.0641 0x0c3c isapnp - ok
11:42:37.0676 0x0c3c [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:42:37.0685 0x0c3c iScsiPrt - ok
11:42:37.0693 0x0c3c [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
11:42:37.0699 0x0c3c kbdclass - ok
11:42:37.0704 0x0c3c [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
11:42:37.0713 0x0c3c kbdhid - ok
11:42:37.0722 0x0c3c [ 13FE29C1C8E782829C7FAA3B14F4A666, C53F7F9039E79AC6D5BDA94981A187570D6C7828930B6064CEFC17DC172EA20E ] KeyIso C:\Windows\system32\lsass.exe
11:42:37.0727 0x0c3c KeyIso - ok
11:42:37.0752 0x0c3c [ CFBA6BCBBDC7E33813D92FFB3460FA07, 4BE0DF9AC976A991731C784CD3F32C4CED67AD58267658F046798E84BA1BF78C ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:42:37.0759 0x0c3c KSecDD - ok
11:42:37.0772 0x0c3c [ CE66825289EE8326CB52C4E9E785ACB0, 41113B55F891A300C7967F585F59921917EC0718C26798946056B1DE534EE0E3 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:42:37.0780 0x0c3c KSecPkg - ok
11:42:37.0784 0x0c3c [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
11:42:37.0803 0x0c3c ksthunk - ok
11:42:37.0825 0x0c3c [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll
11:42:37.0851 0x0c3c KtmRm - ok
11:42:37.0863 0x0c3c [ 32980B4E711D2EF7128C44DC2CF85706, 1468C4497FA888A9A3415F0CB1D18FF2603DFFEF66515E0863C6342ED71214DA ] L1C C:\Windows\system32\DRIVERS\L1C62x64.sys
11:42:37.0868 0x0c3c L1C - ok
11:42:37.0884 0x0c3c [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll
11:42:37.0907 0x0c3c LanmanServer - ok
11:42:37.0918 0x0c3c [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:42:37.0939 0x0c3c LanmanWorkstation - ok
11:42:37.0950 0x0c3c [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:42:37.0970 0x0c3c lltdio - ok
11:42:37.0989 0x0c3c [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:42:38.0013 0x0c3c lltdsvc - ok
11:42:38.0028 0x0c3c [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll
11:42:38.0047 0x0c3c lmhosts - ok
11:42:38.0078 0x0c3c [ 0803906D607A9B83184447B75B60ECC2, A7A599C4CEDD4AC4196A558442E80B4F852AF6C6104A53C8819A79AA5D388DE8 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
11:42:38.0087 0x0c3c LMS - ok
11:42:38.0102 0x0c3c [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
11:42:38.0109 0x0c3c LSI_FC - ok
11:42:38.0112 0x0c3c [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
11:42:38.0119 0x0c3c LSI_SAS - ok
11:42:38.0121 0x0c3c [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
11:42:38.0127 0x0c3c LSI_SAS2 - ok
11:42:38.0131 0x0c3c [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
11:42:38.0137 0x0c3c LSI_SCSI - ok
11:42:38.0146 0x0c3c [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys
11:42:38.0167 0x0c3c luafv - ok
11:42:38.0207 0x0c3c [ 78488AF2AB2111D67B3C4044707A519B, 7AA71B9C4C7949A1A21F60EF7CCEDE0079794990696B60557B5DC86F4D47223A ] MBAMSwissArmy C:\Windows\system32\drivers\MBAMSwissArmy.sys
11:42:38.0214 0x0c3c MBAMSwissArmy - ok
11:42:38.0243 0x0c3c [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:42:38.0250 0x0c3c Mcx2Svc - ok
11:42:38.0260 0x0c3c [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\drivers\megasas.sys
11:42:38.0266 0x0c3c megasas - ok
11:42:38.0272 0x0c3c [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
11:42:38.0282 0x0c3c MegaSR - ok
11:42:38.0293 0x0c3c [ 1C6E73FC46B509EFF9D0086AA37132DF, B4FB5512D75112C553FC22593F6123A7C9B9B7825D40148F604CCEFEB149FD97 ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
11:42:38.0297 0x0c3c MEIx64 - ok
11:42:38.0320 0x0c3c [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll
11:42:38.0340 0x0c3c MMCSS - ok
11:42:38.0342 0x0c3c [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys
11:42:38.0362 0x0c3c Modem - ok
11:42:38.0364 0x0c3c [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:42:38.0371 0x0c3c monitor - ok
11:42:38.0377 0x0c3c [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
11:42:38.0382 0x0c3c mouclass - ok
11:42:38.0387 0x0c3c [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:42:38.0393 0x0c3c mouhid - ok
11:42:38.0415 0x0c3c [ 67050452C0118BAF2883928E6FCCFE47, 335FC0AEB7B47DCC7CE0CF3F424EB60ACB1327D2FF6515F04D9AC03A10FF1E31 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:42:38.0422 0x0c3c mountmgr - ok
11:42:38.0438 0x0c3c [ A82AA5481A845F4AC0E5EE83904FBFED, 2E1640BCA51B1957815465E4DEE895FCD87C93EA80DDD3A80B5647B23D16FB67 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:42:38.0445 0x0c3c MozillaMaintenance - ok
11:42:38.0449 0x0c3c [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys
11:42:38.0456 0x0c3c mpio - ok
11:42:38.0459 0x0c3c [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:42:38.0479 0x0c3c mpsdrv - ok
11:42:38.0504 0x0c3c [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:42:38.0536 0x0c3c MpsSvc - ok
11:42:38.0566 0x0c3c [ D7ADC2B83CA0B0381F75A98351F72CEE, 05476B7CA0486DF770AE492B5A90C85E3D3E7485152EB2FA30A19EC9BE44ED81 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:42:38.0574 0x0c3c MRxDAV - ok
11:42:38.0595 0x0c3c [ B7FADA5E1E55BB63F90EB9F8F016113B, 33C2C898E4AD0CBD34D9A6CF51987A4703009E23CD9D4F4294BF444C4D3D5A60 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:42:38.0602 0x0c3c mrxsmb - ok
11:42:38.0618 0x0c3c [ 34AFF1849B3EC042C40C5EEC9D78562A, E3378A9977B429812C38529C562FE27945706ADB5E9E877C4A90B0285631A501 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:42:38.0627 0x0c3c mrxsmb10 - ok
11:42:38.0637 0x0c3c [ 058CE7A55E140EB0C72FBA6FD2FA72DE, B1D89E524A621BDCC464882EF621BDC7779BFCBCC9FD923D70DE130C41D0DB4C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:42:38.0644 0x0c3c mrxsmb20 - ok
11:42:38.0669 0x0c3c [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys
11:42:38.0675 0x0c3c msahci - ok
11:42:38.0679 0x0c3c [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:42:38.0686 0x0c3c msdsm - ok
11:42:38.0701 0x0c3c [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe
11:42:38.0710 0x0c3c MSDTC - ok
11:42:38.0729 0x0c3c [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:42:38.0748 0x0c3c Msfs - ok
11:42:38.0750 0x0c3c [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:42:38.0769 0x0c3c mshidkmdf - ok
11:42:38.0774 0x0c3c [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:42:38.0779 0x0c3c msisadrv - ok
11:42:38.0800 0x0c3c [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:42:38.0822 0x0c3c MSiSCSI - ok
11:42:38.0824 0x0c3c msiserver - ok
11:42:38.0830 0x0c3c [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:42:38.0849 0x0c3c MSKSSRV - ok
11:42:38.0851 0x0c3c [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:42:38.0870 0x0c3c MSPCLOCK - ok
11:42:38.0872 0x0c3c [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:42:38.0890 0x0c3c MSPQM - ok
11:42:38.0908 0x0c3c [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:42:38.0919 0x0c3c MsRPC - ok
11:42:38.0934 0x0c3c [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
11:42:38.0939 0x0c3c mssmbios - ok
11:42:38.0952 0x0c3c [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:42:38.0971 0x0c3c MSTEE - ok
11:42:38.0973 0x0c3c [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
11:42:38.0978 0x0c3c MTConfig - ok
11:42:38.0987 0x0c3c [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys
11:42:38.0993 0x0c3c Mup - ok
11:42:39.0022 0x0c3c [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll
11:42:39.0049 0x0c3c napagent - ok
11:42:39.0058 0x0c3c [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:42:39.0072 0x0c3c NativeWifiP - ok
11:42:39.0113 0x0c3c [ F7309F42555F8AAB7144A51A1F2585B0, 065277A8AFAEE3888C997A76D2F751070F92DF4C3354D16B194860B4BDAFF937 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:42:39.0134 0x0c3c NDIS - ok
11:42:39.0142 0x0c3c [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:42:39.0161 0x0c3c NdisCap - ok
11:42:39.0171 0x0c3c [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:42:39.0190 0x0c3c NdisTapi - ok
11:42:39.0199 0x0c3c [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:42:39.0218 0x0c3c Ndisuio - ok
11:42:39.0232 0x0c3c [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:42:39.0253 0x0c3c NdisWan - ok
11:42:39.0266 0x0c3c [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:42:39.0285 0x0c3c NDProxy - ok
11:42:39.0292 0x0c3c [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:42:39.0312 0x0c3c NetBIOS - ok
11:42:39.0345 0x0c3c [ E47D571FEC2C76E867935109AB2A770C, F349D25890B6F476B106FD75BFB081DB737CA9B224D95E44927942FFF2DF82CD ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:42:39.0354 0x0c3c NetBT - ok
11:42:39.0363 0x0c3c [ 13FE29C1C8E782829C7FAA3B14F4A666, C53F7F9039E79AC6D5BDA94981A187570D6C7828930B6064CEFC17DC172EA20E ] Netlogon C:\Windows\system32\lsass.exe
11:42:39.0369 0x0c3c Netlogon - ok
11:42:39.0387 0x0c3c [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll
11:42:39.0413 0x0c3c Netman - ok
11:42:39.0463 0x0c3c [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:42:39.0477 0x0c3c NetMsmqActivator - ok
11:42:39.0480 0x0c3c [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:42:39.0488 0x0c3c NetPipeActivator - ok
11:42:39.0498 0x0c3c [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll
11:42:39.0525 0x0c3c netprofm - ok
11:42:39.0529 0x0c3c [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:42:39.0536 0x0c3c NetTcpActivator - ok
11:42:39.0540 0x0c3c [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:42:39.0548 0x0c3c NetTcpPortSharing - ok
11:42:39.0553 0x0c3c [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
11:42:39.0558 0x0c3c nfrd960 - ok
11:42:39.0758 0x0c3c [ 93F304DEB07095BCF33BD1C17C2DB2A7, DCD4A810512BE0D86E019DB19C4317AB3FD2FEEE1166162155F6B5BA7D0EFF4F ] NIHardwareService C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
11:42:39.0867 0x0c3c NIHardwareService - ok
11:42:39.0907 0x0c3c [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc C:\Windows\System32\nlasvc.dll
11:42:39.0917 0x0c3c NlaSvc - ok
11:42:39.0921 0x0c3c [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:42:39.0941 0x0c3c Npfs - ok
11:42:39.0960 0x0c3c [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll
11:42:39.0980 0x0c3c nsi - ok
11:42:39.0987 0x0c3c [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:42:40.0006 0x0c3c nsiproxy - ok
11:42:40.0065 0x0c3c [ 47B2D0B31BDC3EBE6090228E2BA3764D, 984A4B38300954164BCBF57EC1A09C18B53779E60A26E9618B50E26016735787 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:42:40.0104 0x0c3c Ntfs - ok
11:42:40.0110 0x0c3c [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys
11:42:40.0129 0x0c3c Null - ok
11:42:40.0148 0x0c3c [ E366A5681C50785D4ED04FCFD65C3415, 7FF7B4B8F09E773401AE879897E60BF494B57B9ACEE990204A4C98A3FB183A33 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
11:42:40.0155 0x0c3c NVHDA - ok
11:42:40.0435 0x0c3c [ 0218E1CE8F7B5D404980192B9112D03A, 30BFBDC8F4BFF9DCAE71940AFD3F3E8CCC71C950F3B4A9717A70FF667F6DDC9E ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
11:42:40.0649 0x0c3c nvlddmkm - ok
11:42:40.0683 0x0c3c [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:42:40.0691 0x0c3c nvraid - ok
11:42:40.0702 0x0c3c [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:42:40.0709 0x0c3c nvstor - ok
11:42:40.0738 0x0c3c [ B7973C405247C5A44BA46B12A4B7AEEA, DF25E4CB7093EFF528C47A51C68CD1B0A93AE273D078804B7E09E74163753AA8 ] NVSvc C:\Windows\system32\nvvsvc.exe
11:42:40.0757 0x0c3c NVSvc - ok
11:42:40.0777 0x0c3c [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:42:40.0784 0x0c3c nv_agp - ok
11:42:40.0787 0x0c3c [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:42:40.0793 0x0c3c ohci1394 - ok
11:42:40.0851 0x0c3c [ 1C28B83FF75CE3B43D932162FC40DC2E, B17778948C529CED898EE4669D778868B98D7984E712C51C052B76867D9522A9 ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:42:40.0860 0x0c3c ose - ok
11:42:40.0891 0x0c3c [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:42:40.0902 0x0c3c p2pimsvc - ok
11:42:40.0918 0x0c3c [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll
11:42:40.0931 0x0c3c p2psvc - ok
11:42:41.0333 0x0c3c [ CF68416210A56B51C64BCA85AC63A503, 0E6AC89FD28603D917439FE1AC180E303443C4A0B7070328024FB52A1533E99D ] PaceLicenseDServices C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
11:42:41.0640 0x0c3c PaceLicenseDServices - ok
11:42:41.0679 0x0c3c [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:42:41.0686 0x0c3c Parport - ok
11:42:41.0716 0x0c3c [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:42:41.0722 0x0c3c partmgr - ok
11:42:41.0748 0x0c3c [ DB2D62AA2DF6B1F3D690A9EC9701AA2C, BEAC55E1AA0494565F1547DF5E6FE20FCEA66461764C016FCB68D8BFF0F0C375 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:42:41.0757 0x0c3c PcaSvc - ok
11:42:41.0763 0x0c3c [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\Windows\system32\drivers\pci.sys
11:42:41.0771 0x0c3c pci - ok
11:42:41.0796 0x0c3c [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys
11:42:41.0801 0x0c3c pciide - ok
11:42:41.0814 0x0c3c [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
11:42:41.0823 0x0c3c pcmcia - ok
11:42:41.0825 0x0c3c [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys
11:42:41.0830 0x0c3c pcw - ok
11:42:41.0932 0x0c3c [ A279FC9BE4D1DA5DA3E79B5EAE0FDCF4, 0CC9A413E2BFE30421A74610300F6AD29769EF45557137F6FD7B7FAF0E0A241C ] PDF Architect 3 C:\Program Files (x86)\PDF Architect 3\ws.exe
11:42:41.0973 0x0c3c PDF Architect 3 - ok
11:42:42.0011 0x0c3c [ 29D993E6AABC958032ED9620D232C521, 68F6581BB8A856561BAD22B5EB5CAB25B3F9473228B553D133ECFB4BDCEB2A3F ] PDF Architect 3 CrashHandler C:\Program Files (x86)\PDF Architect 3\crash-handler-ws.exe
11:42:42.0031 0x0c3c PDF Architect 3 CrashHandler - ok
11:42:42.0076 0x0c3c [ 9EC3A20048C2E53B98E3617B7D6EB1DE, 8C2A11FFE65C062E8091135ECE4E392C2F18BB48C565E47DA08BF344B2587061 ] PDF Architect 3 Creator C:\Program Files (x86)\PDF Architect 3\creator-ws.exe
11:42:42.0092 0x0c3c PDF Architect 3 Creator - ok
11:42:42.0129 0x0c3c [ ED6E75158D28D33A2E2A020AC5B2B59D, 0F364D9A88304C45F31318605C417A70A9D0E4CF087D73E949B42C12CC76CD6C ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:42:42.0145 0x0c3c PEAUTH - ok
11:42:42.0186 0x0c3c [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
11:42:42.0214 0x0c3c PeerDistSvc - ok
11:42:42.0265 0x0c3c [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe
11:42:42.0272 0x0c3c PerfHost - ok
11:42:42.0324 0x0c3c [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll
11:42:42.0365 0x0c3c pla - ok
11:42:42.0406 0x0c3c [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:42:42.0418 0x0c3c PlugPlay - ok
11:42:42.0427 0x0c3c [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:42:42.0433 0x0c3c PNRPAutoReg - ok
11:42:42.0449 0x0c3c [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:42:42.0460 0x0c3c PNRPsvc - ok
11:42:42.0494 0x0c3c [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:42:42.0507 0x0c3c PolicyAgent - ok
11:42:42.0529 0x0c3c [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\Windows\system32\umpo.dll
11:42:42.0551 0x0c3c Power - ok
11:42:42.0570 0x0c3c [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:42:42.0590 0x0c3c PptpMiniport - ok
11:42:42.0604 0x0c3c [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\drivers\processr.sys
11:42:42.0611 0x0c3c Processor - ok
11:42:42.0626 0x0c3c [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc C:\Windows\system32\profsvc.dll
11:42:42.0634 0x0c3c ProfSvc - ok
11:42:42.0646 0x0c3c [ 13FE29C1C8E782829C7FAA3B14F4A666, C53F7F9039E79AC6D5BDA94981A187570D6C7828930B6064CEFC17DC172EA20E ] ProtectedStorage C:\Windows\system32\lsass.exe
11:42:42.0651 0x0c3c ProtectedStorage - ok
11:42:42.0663 0x0c3c [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:42:42.0683 0x0c3c Psched - ok
11:42:42.0722 0x0c3c [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
11:42:42.0751 0x0c3c ql2300 - ok
11:42:42.0761 0x0c3c [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
11:42:42.0768 0x0c3c ql40xx - ok
11:42:42.0786 0x0c3c [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll
11:42:42.0798 0x0c3c QWAVE - ok
11:42:42.0804 0x0c3c [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:42:42.0812 0x0c3c QWAVEdrv - ok
11:42:42.0822 0x0c3c [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:42:42.0841 0x0c3c RasAcd - ok
11:42:42.0854 0x0c3c [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:42:42.0874 0x0c3c RasAgileVpn - ok
11:42:42.0885 0x0c3c [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll
11:42:42.0906 0x0c3c RasAuto - ok
11:42:42.0914 0x0c3c [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:42:42.0934 0x0c3c Rasl2tp - ok
11:42:42.0948 0x0c3c [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll
11:42:42.0972 0x0c3c RasMan - ok
11:42:42.0980 0x0c3c [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:42:43.0000 0x0c3c RasPppoe - ok
11:42:43.0006 0x0c3c [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:42:43.0026 0x0c3c RasSstp - ok
11:42:43.0050 0x0c3c [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:42:43.0074 0x0c3c rdbss - ok
11:42:43.0084 0x0c3c [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:42:43.0091 0x0c3c rdpbus - ok
11:42:43.0099 0x0c3c [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:42:43.0118 0x0c3c RDPCDD - ok
11:42:43.0133 0x0c3c [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
11:42:43.0141 0x0c3c RDPDR - ok
11:42:43.0151 0x0c3c [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:42:43.0170 0x0c3c RDPENCDD - ok
11:42:43.0174 0x0c3c [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:42:43.0192 0x0c3c RDPREFMP - ok
11:42:43.0218 0x0c3c [ 065F79543D7999EC28B687F87E96B803, 6B235C422DCA79ABF0D051C066B2866643333F7ADB7AF914F6EEAC448AA59AAF ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
11:42:43.0223 0x0c3c RdpVideoMiniport - ok
11:42:43.0253 0x0c3c [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:42:43.0261 0x0c3c RDPWD - ok
11:42:43.0277 0x0c3c [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:42:43.0285 0x0c3c rdyboost - ok
11:42:43.0309 0x0c3c [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll
11:42:43.0330 0x0c3c RemoteAccess - ok
11:42:43.0346 0x0c3c [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:42:43.0367 0x0c3c RemoteRegistry - ok
11:42:43.0378 0x0c3c [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:42:43.0398 0x0c3c RpcEptMapper - ok
11:42:43.0400 0x0c3c [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe
11:42:43.0406 0x0c3c RpcLocator - ok
11:42:43.0440 0x0c3c [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] RpcSs C:\Windows\system32\rpcss.dll
11:42:43.0454 0x0c3c RpcSs - ok
11:42:43.0466 0x0c3c [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:42:43.0486 0x0c3c rspndr - ok
11:42:43.0502 0x0c3c [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap C:\Windows\system32\drivers\vms3cap.sys
11:42:43.0507 0x0c3c s3cap - ok
11:42:43.0568 0x0c3c [ D174C61D55A64EE909720C0B15A7BF7B, 6294B66D8097864A8223FD055B04890AF916A10898237059B6088E12743EB851 ] Saffire C:\Windows\system32\Drivers\Saffire.sys
11:42:43.0576 0x0c3c Saffire - ok
11:42:43.0585 0x0c3c [ D7FBE1F0FF621F41C1DB16722F14250A, C41575B509E4FC757CF236AB8C2499941282B9A02F9C4D9408AFCF9A2929A19F ] SaffireAudio C:\Windows\system32\drivers\SaffireAudio.sys
11:42:43.0590 0x0c3c SaffireAudio - ok
11:42:43.0600 0x0c3c [ C8A462C4136EA82F539344619A8DD749, BE1767FCD0B855C5E13D0855F5F412954BE90584E423A36F759A1653BBECA119 ] SaffireMidi C:\Windows\system32\drivers\SaffireMidi.sys
11:42:43.0604 0x0c3c SaffireMidi - ok
11:42:43.0613 0x0c3c [ 13FE29C1C8E782829C7FAA3B14F4A666, C53F7F9039E79AC6D5BDA94981A187570D6C7828930B6064CEFC17DC172EA20E ] SamSs C:\Windows\system32\lsass.exe
11:42:43.0618 0x0c3c SamSs - ok
11:42:43.0646 0x0c3c [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:42:43.0652 0x0c3c sbp2port - ok
11:42:43.0665 0x0c3c [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:42:43.0688 0x0c3c SCardSvr - ok
11:42:43.0690 0x0c3c [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:42:43.0709 0x0c3c scfilter - ok
11:42:43.0762 0x0c3c [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule C:\Windows\system32\schedsvc.dll
11:42:43.0786 0x0c3c Schedule - ok
11:42:43.0807 0x0c3c [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll
11:42:43.0826 0x0c3c SCPolicySvc - ok
11:42:43.0837 0x0c3c [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:42:43.0845 0x0c3c SDRSVC - ok
11:42:43.0850 0x0c3c [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:42:43.0855 0x0c3c secdrv - ok
11:42:43.0885 0x0c3c [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon C:\Windows\system32\seclogon.dll
11:42:43.0890 0x0c3c seclogon - ok
11:42:43.0895 0x0c3c [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\System32\sens.dll
11:42:43.0915 0x0c3c SENS - ok
11:42:43.0917 0x0c3c [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:42:43.0923 0x0c3c SensrSvc - ok
11:42:43.0927 0x0c3c [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:42:43.0933 0x0c3c Serenum - ok
11:42:43.0944 0x0c3c [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:42:43.0950 0x0c3c Serial - ok
11:42:43.0959 0x0c3c [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\drivers\sermouse.sys
11:42:43.0965 0x0c3c sermouse - ok
11:42:43.0981 0x0c3c [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll
11:42:44.0001 0x0c3c SessionEnv - ok
11:42:44.0010 0x0c3c [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:42:44.0017 0x0c3c sffdisk - ok
11:42:44.0019 0x0c3c [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:42:44.0026 0x0c3c sffp_mmc - ok
11:42:44.0027 0x0c3c [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:42:44.0034 0x0c3c sffp_sd - ok
11:42:44.0036 0x0c3c [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
11:42:44.0041 0x0c3c sfloppy - ok
11:42:44.0073 0x0c3c [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:42:44.0098 0x0c3c SharedAccess - ok
11:42:44.0122 0x0c3c [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:42:44.0146 0x0c3c ShellHWDetection - ok
11:42:44.0149 0x0c3c [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
11:42:44.0154 0x0c3c SiSRaid2 - ok
11:42:44.0157 0x0c3c [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
11:42:44.0163 0x0c3c SiSRaid4 - ok
11:42:44.0166 0x0c3c [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:42:44.0186 0x0c3c Smb - ok
11:42:44.0206 0x0c3c [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:42:44.0213 0x0c3c SNMPTRAP - ok
11:42:44.0223 0x0c3c [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys
11:42:44.0228 0x0c3c spldr - ok
11:42:44.0265 0x0c3c [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler C:\Windows\System32\spoolsv.exe
11:42:44.0279 0x0c3c Spooler - ok
11:42:44.0357 0x0c3c [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe
11:42:44.0433 0x0c3c sppsvc - ok
11:42:44.0448 0x0c3c [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:42:44.0469 0x0c3c sppuinotify - ok
11:42:44.0534 0x0c3c [ F2F4B895296EE3ECCE781CC2A296A5D1, 126321EDDA8141A42DBE7C90675948433063E6D5B6DEFD805AA0797C95A461EE ] srv C:\Windows\system32\DRIVERS\srv.sys
11:42:44.0547 0x0c3c srv - ok
11:42:44.0561 0x0c3c [ FD0008BEDD2723170CCA7D61837DFD52, F9F576FA7B84CAB5180B9080D62B8A00B3E5D5BC73199B11C63193742529227D ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:42:44.0572 0x0c3c srv2 - ok
11:42:44.0587 0x0c3c [ 63B5845D9379262083655D5C6AB8DFC5, 1813D2FC41ADCDAC6E3A522373B9DB934CC27B89E7185E0E4FC26E30CDAF1523 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:42:44.0594 0x0c3c srvnet - ok
11:42:44.0622 0x0c3c [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:42:44.0645 0x0c3c SSDPSRV - ok
11:42:44.0655 0x0c3c [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:42:44.0676 0x0c3c SstpSvc - ok
11:42:44.0728 0x0c3c [ EACEC497A6496E2A280348AD67ACF280, DAC7141A072FC83274612BC228DA6E014C371707FC76832470604ACDD5BF4BE3 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
11:42:44.0738 0x0c3c Stereo Service - ok
11:42:44.0754 0x0c3c [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\drivers\stexstor.sys
11:42:44.0759 0x0c3c stexstor - ok
11:42:44.0795 0x0c3c [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll
11:42:44.0813 0x0c3c stisvc - ok
11:42:44.0824 0x0c3c [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt C:\Windows\system32\drivers\vmstorfl.sys
11:42:44.0830 0x0c3c storflt - ok
11:42:44.0836 0x0c3c [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc C:\Windows\system32\drivers\storvsc.sys
11:42:44.0841 0x0c3c storvsc - ok
11:42:44.0851 0x0c3c [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
11:42:44.0856 0x0c3c swenum - ok
11:42:44.0937 0x0c3c [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
11:42:44.0950 0x0c3c SwitchBoard - detected UnsignedFile.Multi.Generic ( 1 )
11:42:45.0077 0x0c3c Detect skipped due to KSN trusted
11:42:45.0077 0x0c3c SwitchBoard - ok
11:42:45.0094 0x0c3c [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll
11:42:45.0122 0x0c3c swprv - ok
11:42:45.0134 0x0c3c [ C3A39C4079305480972D29C44B868C78, 8F1BB75C743256F905EAEDE744B6082C53774C49126875FB4E4FBA30F5478B17 ] Synth3dVsc C:\Windows\system32\drivers\synth3dvsc.sys
11:42:45.0140 0x0c3c Synth3dVsc - ok
11:42:45.0199 0x0c3c [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain C:\Windows\system32\sysmain.dll
11:42:45.0233 0x0c3c SysMain - ok
11:42:45.0255 0x0c3c [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:42:45.0265 0x0c3c TabletInputService - ok
11:42:45.0275 0x0c3c [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll
11:42:45.0299 0x0c3c TapiSrv - ok
11:42:45.0300 0x0c3c TBPanel - ok
11:42:45.0368 0x0c3c [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:42:45.0404 0x0c3c Tcpip - ok
11:42:45.0440 0x0c3c [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:42:45.0476 0x0c3c TCPIP6 - ok
11:42:45.0505 0x0c3c [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:42:45.0511 0x0c3c tcpipreg - ok
11:42:45.0529 0x0c3c [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:42:45.0534 0x0c3c TDPIPE - ok
11:42:45.0546 0x0c3c [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:42:45.0551 0x0c3c TDTCP - ok
11:42:45.0582 0x0c3c [ AA77EB517D2F07A947294F260E3ACA83, B7A5DF3066830C0C2302B059778A67419792058A0D300C471DE40AB245EA7E58 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:42:45.0589 0x0c3c tdx - ok
11:42:45.0596 0x0c3c [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
11:42:45.0602 0x0c3c TermDD - ok
11:42:45.0620 0x0c3c [ 2B5BDFF688EC9871D7EC5837833374E9, BD6C629FA2938987ABF95B790B20F0B7D4D023D5013E575F343A802D6213074E ] terminpt C:\Windows\system32\drivers\terminpt.sys
11:42:45.0625 0x0c3c terminpt - ok
11:42:45.0657 0x0c3c [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService C:\Windows\System32\termsrv.dll
11:42:45.0674 0x0c3c TermService - ok
11:42:45.0686 0x0c3c [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll
11:42:45.0695 0x0c3c Themes - ok
11:42:45.0711 0x0c3c [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll
11:42:45.0731 0x0c3c THREADORDER - ok
11:42:45.0759 0x0c3c [ D154DD00C8F12D94C9CC94027356B6E4, 501026564147DC43D0764521816B8D20576DA8F5D9DB0D2D8D3A16AA48A534A3 ] Tpkd C:\Windows\system32\drivers\Tpkd.sys
11:42:45.0765 0x0c3c Tpkd - ok
11:42:45.0784 0x0c3c [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll
11:42:45.0805 0x0c3c TrkWks - ok
11:42:45.0842 0x0c3c [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:42:45.0864 0x0c3c TrustedInstaller - ok
11:42:45.0888 0x0c3c [ E232A3B43A894BB327FC161529BD9ED1, F2673DA8C920F21ACCECC25F7C59A05822E5E577D47F126EDF9C94FEB4B30C5F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:42:45.0893 0x0c3c tssecsrv - ok
11:42:45.0905 0x0c3c [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C85BA45BB71A74EB ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:42:45.0911 0x0c3c TsUsbFlt - ok
11:42:45.0919 0x0c3c [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B984EEFA337B804 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
11:42:45.0924 0x0c3c TsUsbGD - ok
11:42:45.0938 0x0c3c [ E1748D04AE40118B62BC18AC86032192, A954B141D1B27272C771D14F3B40C7CC1F572DD72559F2C96182EFBE2B095FDE ] tsusbhub C:\Windows\system32\drivers\tsusbhub.sys
11:42:45.0944 0x0c3c tsusbhub - ok
11:42:45.0954 0x0c3c [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:42:45.0975 0x0c3c tunnel - ok
11:42:45.0982 0x0c3c [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
11:42:45.0988 0x0c3c uagp35 - ok
11:42:46.0041 0x0c3c [ 5B6F1A788D8353D4C38BA2861704D961, F27D8D207B4E3A50C0D4C5A79A356E3DAC03B297100E3E3206847895C4D8FDE1 ] ubohci C:\Windows\system32\DRIVERS\ubohci.sys
11:42:46.0047 0x0c3c ubohci - ok
11:42:46.0072 0x0c3c [ 850920DCB6E3D306EB6B431D4A89BA00, 4D6AAF201C918193FE050A4B7D1E248E179B90B31DAEDA1F49A90607D4506374 ] ubsbm C:\Windows\system32\DRIVERS\ubsbm.sys
11:42:46.0076 0x0c3c ubsbm - ok
11:42:46.0083 0x0c3c [ 3977ADE1C3B4845E81E3A039A520405D, 3DE8E27EDD0B61C3FF6FBE765A3CE5BE2BA6051AD10C1FF4BE1512CEF68B6F6E ] ubumapi C:\Windows\system32\DRIVERS\ubumapi.sys
11:42:46.0087 0x0c3c ubumapi - ok
11:42:46.0102 0x0c3c [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:42:46.0125 0x0c3c udfs - ok
11:42:46.0139 0x0c3c [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:42:46.0146 0x0c3c UI0Detect - ok
11:42:46.0159 0x0c3c [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:42:46.0164 0x0c3c uliagpkx - ok
11:42:46.0177 0x0c3c [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\DRIVERS\umbus.sys
11:42:46.0183 0x0c3c umbus - ok
11:42:46.0191 0x0c3c [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\drivers\umpass.sys
11:42:46.0196 0x0c3c UmPass - ok
11:42:46.0221 0x0c3c [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService C:\Windows\System32\umrdp.dll
11:42:46.0229 0x0c3c UmRdpService - ok
11:42:46.0309 0x0c3c [ EB79C6C91A99930015EF29AE7FA802D1, 96D00BA330854C7763BF385D84D47C3D1B87C4085A91D73B558C86829930DC4B ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
11:42:46.0356 0x0c3c UNS - ok
11:42:46.0381 0x0c3c [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll
11:42:46.0406 0x0c3c upnphost - ok
11:42:46.0451 0x0c3c [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
11:42:46.0457 0x0c3c usbaudio - ok
11:42:46.0477 0x0c3c [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:42:46.0483 0x0c3c usbccgp - ok
11:42:46.0519 0x0c3c [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:42:46.0526 0x0c3c usbcir - ok
11:42:46.0588 0x0c3c [ 18A85013A3E0F7E1755365D287443965, 811C5EDF38C765BCF71BCE25CB6626FF6988C3699F5EF1846240EA0052F34C33 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
11:42:46.0594 0x0c3c usbehci - ok
11:42:46.0629 0x0c3c [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:42:46.0639 0x0c3c usbhub - ok
11:42:46.0677 0x0c3c [ 58E546BBAF87664FC57E0F6081E4F609, 1DD99D57369A0069654432AB5325AFD8F7D422D531E053EA05FF664BA6BDAEF9 ] usbohci C:\Windows\system32\drivers\usbohci.sys
11:42:46.0683 0x0c3c usbohci - ok
11:42:46.0725 0x0c3c [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:42:46.0733 0x0c3c usbprint - ok
11:42:46.0764 0x0c3c [ 9661DA76B4531B2DA272ECCE25A8AF24, FEA93254A21E71A7EB8AD35FCCAD2C1E41F7329EC33B1734F5B41307A34D8637 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
11:42:46.0769 0x0c3c usbscan - ok
11:42:46.0798 0x0c3c [ D029DD09E22EB24318A8FC3D8138BA43, C95805E8BF75ECB939520AE86420B16467B0771C161C51C9F1A37649ADFADCD0 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:42:46.0804 0x0c3c USBSTOR - ok
11:42:46.0816 0x0c3c [ 81FB2216D3A60D1284455D511797DB3D, 121E52B18A1832E775EA0AE2E053BAA53E5A70E9754724B1449AE5992D63B13E ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
11:42:46.0822 0x0c3c usbuhci - ok
11:42:46.0824 0x0c3c [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll
11:42:46.0844 0x0c3c UxSms - ok
11:42:46.0854 0x0c3c [ 13FE29C1C8E782829C7FAA3B14F4A666, C53F7F9039E79AC6D5BDA94981A187570D6C7828930B6064CEFC17DC172EA20E ] VaultSvc C:\Windows\system32\lsass.exe
11:42:46.0859 0x0c3c VaultSvc - ok
11:42:46.0901 0x0c3c [ F257A2737280F0076EAE3AB489C06474, A02E37292D86E675D55C13097E9F107C73DDFD8AAC69310F7D9910A811A541D8 ] VClone C:\Windows\system32\DRIVERS\VClone.sys
11:42:46.0905 0x0c3c VClone - ok
11:42:46.0915 0x0c3c [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:42:46.0921 0x0c3c vdrvroot - ok
11:42:46.0936 0x0c3c [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe
11:42:46.0963 0x0c3c vds - ok
11:42:46.0979 0x0c3c [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:42:46.0986 0x0c3c vga - ok
11:42:46.0994 0x0c3c [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:42:47.0013 0x0c3c VgaSave - ok
11:42:47.0014 0x0c3c VGPU - ok
11:42:47.0030 0x0c3c [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:42:47.0038 0x0c3c vhdmp - ok
11:42:47.0048 0x0c3c [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys
11:42:47.0054 0x0c3c viaide - ok
11:42:47.0075 0x0c3c [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus C:\Windows\system32\drivers\vmbus.sys
11:42:47.0083 0x0c3c vmbus - ok
11:42:47.0088 0x0c3c [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
11:42:47.0094 0x0c3c VMBusHID - ok
11:42:47.0104 0x0c3c [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:42:47.0110 0x0c3c volmgr - ok
11:42:47.0127 0x0c3c [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:42:47.0137 0x0c3c volmgrx - ok
11:42:47.0150 0x0c3c [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:42:47.0160 0x0c3c volsnap - ok
11:42:47.0164 0x0c3c [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
11:42:47.0172 0x0c3c vsmraid - ok
11:42:47.0208 0x0c3c [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe
11:42:47.0253 0x0c3c VSS - ok
11:42:47.0261 0x0c3c [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
11:42:47.0268 0x0c3c vwifibus - ok
11:42:47.0281 0x0c3c [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
11:42:47.0290 0x0c3c vwififlt - ok
11:42:47.0310 0x0c3c [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
11:42:47.0318 0x0c3c vwifimp - ok
11:42:47.0334 0x0c3c [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll
11:42:47.0359 0x0c3c W32Time - ok
11:42:47.0367 0x0c3c [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
11:42:47.0372 0x0c3c WacomPen - ok
11:42:47.0384 0x0c3c [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:42:47.0404 0x0c3c WANARP - ok
11:42:47.0406 0x0c3c [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:42:47.0426 0x0c3c Wanarpv6 - ok
11:42:47.0488 0x0c3c [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:42:47.0514 0x0c3c WatAdminSvc - ok
11:42:47.0542 0x0c3c [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe
11:42:47.0573 0x0c3c wbengine - ok
11:42:47.0587 0x0c3c [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:42:47.0599 0x0c3c WbioSrvc - ok
11:42:47.0617 0x0c3c [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:42:47.0632 0x0c3c wcncsvc - ok
11:42:47.0636 0x0c3c [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:42:47.0642 0x0c3c WcsPlugInService - ok
11:42:47.0660 0x0c3c [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\drivers\wd.sys
11:42:47.0665 0x0c3c Wd - ok
11:42:47.0706 0x0c3c [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:42:47.0724 0x0c3c Wdf01000 - ok
11:42:47.0754 0x0c3c [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:42:47.0761 0x0c3c WdiServiceHost - ok
11:42:47.0763 0x0c3c [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:42:47.0770 0x0c3c WdiSystemHost - ok
11:42:47.0794 0x0c3c [ 4E89FC53493704BF835F0300DC201C34, FB3080725E144D93512DED81047D21C0582BC3412250EFF37E039108D7351F53 ] WebClient C:\Windows\System32\webclnt.dll
11:42:47.0803 0x0c3c WebClient - ok
11:42:47.0828 0x0c3c [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:42:47.0851 0x0c3c Wecsvc - ok
11:42:47.0863 0x0c3c [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:42:47.0884 0x0c3c wercplsupport - ok
11:42:47.0892 0x0c3c [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll
11:42:47.0912 0x0c3c WerSvc - ok
11:42:47.0916 0x0c3c [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:42:47.0935 0x0c3c WfpLwf - ok
11:42:47.0941 0x0c3c [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:42:47.0946 0x0c3c WIMMount - ok
11:42:47.0962 0x0c3c WinDefend - ok
11:42:47.0964 0x0c3c WinHttpAutoProxySvc - ok
11:42:48.0006 0x0c3c [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:42:48.0029 0x0c3c Winmgmt - ok
11:42:48.0093 0x0c3c [ D929ABD465A2DED963DA8B30946A8D5C, DE8DBFB01C11D2AE903CBD6A974D6F995E9813CE2D6484B7DA06EAE4C545842A ] WinRM C:\Windows\system32\WsmSvc.dll
11:42:48.0131 0x0c3c WinRM - ok
11:42:48.0155 0x0c3c [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:42:48.0163 0x0c3c WinUsb - ok
11:42:48.0189 0x0c3c [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:42:48.0213 0x0c3c Wlansvc - ok
11:42:48.0225 0x0c3c [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:42:48.0231 0x0c3c WmiAcpi - ok
11:42:48.0243 0x0c3c [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:42:48.0252 0x0c3c wmiApSrv - ok
11:42:48.0262 0x0c3c WMPNetworkSvc - ok
11:42:48.0274 0x0c3c [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:42:48.0280 0x0c3c WPCSvc - ok
11:42:48.0295 0x0c3c [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:42:48.0303 0x0c3c WPDBusEnum - ok
11:42:48.0318 0x0c3c [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:42:48.0337 0x0c3c ws2ifsl - ok
11:42:48.0345 0x0c3c [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\System32\wscsvc.dll
11:42:48.0355 0x0c3c wscsvc - ok
11:42:48.0357 0x0c3c WSearch - ok
11:42:48.0432 0x0c3c [ 86F11B85102AFA6A1A6101DCE2F09386, 68A0F0E628C8F33FDAC114876DA8ED14776DD74E80AC5A6A52257E19DE011091 ] wuauserv C:\Windows\system32\wuaueng.dll
11:42:48.0481 0x0c3c wuauserv - ok
11:42:48.0508 0x0c3c [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:42:48.0514 0x0c3c WudfPf - ok
11:42:48.0540 0x0c3c [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:42:48.0548 0x0c3c WUDFRd - ok
11:42:48.0577 0x0c3c [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:42:48.0586 0x0c3c wudfsvc - ok
11:42:48.0622 0x0c3c [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc C:\Windows\System32\wwansvc.dll
11:42:48.0631 0x0c3c WwanSvc - ok
11:42:48.0634 0x0c3c ================ Scan global ===============================
11:42:48.0675 0x0c3c [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\Windows\system32\basesrv.dll
11:42:48.0706 0x0c3c [ E0E4D286839FC27F56A85B4710E16B6B, 6BBBADB8904D6159E6171A339E0BF30A41D14E885D560BFB8BB73B1FF7239E1A ] C:\Windows\system32\winsrv.dll
11:42:48.0715 0x0c3c [ E0E4D286839FC27F56A85B4710E16B6B, 6BBBADB8904D6159E6171A339E0BF30A41D14E885D560BFB8BB73B1FF7239E1A ] C:\Windows\system32\winsrv.dll
11:42:48.0734 0x0c3c [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
11:42:48.0768 0x0c3c [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\Windows\system32\services.exe
11:42:48.0772 0x0c3c [ Global ] - ok
11:42:48.0773 0x0c3c ================ Scan MBR ==================================
11:42:48.0774 0x0c3c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:42:48.0944 0x0c3c \Device\Harddisk0\DR0 - ok
11:42:48.0950 0x0c3c [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
11:42:49.0302 0x0c3c \Device\Harddisk1\DR1 - ok
11:42:49.0612 0x0c3c [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk2\DR2
11:42:49.0705 0x0c3c \Device\Harddisk2\DR2 - ok
11:42:49.0706 0x0c3c ================ Scan VBR ==================================
11:42:49.0707 0x0c3c [ 21F4866AD9B302CBC6C37CC6BCFFCC91 ] \Device\Harddisk0\DR0\Partition1
11:42:49.0708 0x0c3c \Device\Harddisk0\DR0\Partition1 - ok
11:42:49.0709 0x0c3c [ BCEF6BA11F1B35A4600059C7BE1E3A6E ] \Device\Harddisk1\DR1\Partition1
11:42:49.0710 0x0c3c \Device\Harddisk1\DR1\Partition1 - ok
11:42:49.0711 0x0c3c [ BA64B44835DD3984C344582673544BAE ] \Device\Harddisk1\DR1\Partition2
11:42:49.0711 0x0c3c \Device\Harddisk1\DR1\Partition2 - ok
11:42:49.0712 0x0c3c [ BB0CBD289C18042CD35D5AE3D7FB9BBB ] \Device\Harddisk1\DR1\Partition3
11:42:49.0713 0x0c3c \Device\Harddisk1\DR1\Partition3 - ok
11:42:49.0714 0x0c3c [ 7E7BA06923BDB7DABA4BE73B92AD0B7F ] \Device\Harddisk2\DR2\Partition1
11:42:49.0715 0x0c3c \Device\Harddisk2\DR2\Partition1 - ok
11:42:49.0715 0x0c3c ================ Scan generic autorun ======================
11:42:49.0999 0x0c3c [ 02D4B89754302FC728FF8549ED259B84, 8F7E12C788D229790696DBE01B77FEE4AEF436B220CB5355DE296BFAC33E5BD6 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
11:42:50.0240 0x0c3c RtHDVCpl - ok
11:42:50.0311 0x0c3c [ DB282FA0CBA880D36BA5FBE748BD6F4F, C3A6AB6A2D084048F8C622B9B4CF138CE577B7B4CBC0BF00E5CB2A18918070DC ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
11:42:50.0325 0x0c3c AdobeAAMUpdater-1.0 - ok
11:42:50.0357 0x0c3c [ E127B5D81CE968CD3858AF6BDCADEC7C, AF426B8259E2801679A8E3FAE42B617D0DA1D4E834DF0F7B1FD93AB5E64CBE34 ] C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe
11:42:50.0363 0x0c3c Avira SystrayStartTrigger - ok
11:42:50.0411 0x0c3c [ E49A23D41A1F29D67EE24F1E3C29B8D0, D1CAD57BBA9361DCC537E3627EE1D30C83F017BA04D8A6A2A0D8B1D81D7800FD ] C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
11:42:50.0435 0x0c3c avgnt - ok
11:42:50.0469 0x0c3c [ 3BD79A1F6D2EA0FDDEA3F8914B2A6A0C, 332E6806EFF846A2E6D0DC04A70D3503855DABFA83E6EC27F37E2D9103E80E51 ] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
11:42:50.0475 0x0c3c VirtualCloneDrive - ok
11:42:50.0495 0x0c3c [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
11:42:50.0507 0x0c3c SwitchBoard - detected UnsignedFile.Multi.Generic ( 1 )
11:42:50.0507 0x0c3c Detect skipped due to KSN trusted
11:42:50.0507 0x0c3c SwitchBoard - ok
11:42:50.0550 0x0c3c [ 8FE651ACBA3344E645CFEB6286FFF6B8, ECE4DFFEB7EB0B19B6790FD0F619A5C4B23CA0BA9CC3F25924925F8EA07264B6 ] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
11:42:50.0575 0x0c3c AdobeCS6ServiceManager - ok
11:42:50.0630 0x0c3c [ 635F9280C61F3A67D920061E382A7717, D29A0616C821525977B0B3A80B81EC2403E36D238D89F5E742F9B9BE69F03543 ] C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe
11:42:50.0655 0x0c3c AdobeCEPServiceManager - ok
11:42:50.0697 0x0c3c Dropbox - ok
11:42:50.0709 0x0c3c [ 95828D670CFD3B16EE188168E083C3C5, 8C10AE4BE93834A4C744F27CA79736D9123ED9B0D180DB28556D2D002545BAF2 ] C:\Windows\system32\mshta.exe
11:42:50.0716 0x0c3c - ok
11:42:50.0775 0x0c3c [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
11:42:50.0811 0x0c3c Sidebar - ok
11:42:50.0833 0x0c3c [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
11:42:50.0851 0x0c3c mctadmin - ok
11:42:50.0873 0x0c3c [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
11:42:50.0897 0x0c3c Sidebar - ok
11:42:50.0900 0x0c3c [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
11:42:50.0910 0x0c3c mctadmin - ok
11:42:50.0991 0x0c3c [ 91227FE053DD660A8B5C35C61E04CBF5, BC14EEEBB7A08B81B6D14BBC64A9B41BEB5A7954AA2731864940273B09D73372 ] C:\Program Files (x86)\Vtune\TBPanel.exe
11:42:51.0039 0x0c3c TBPanel - detected UnsignedFile.Multi.Generic ( 1 )
11:42:51.0176 0x0c3c Detect skipped due to KSN trusted
11:42:51.0176 0x0c3c TBPanel - ok
11:42:51.0227 0x0c3c [ 8B4593392FADED550786D52510A05102, F42980BE0E1C3BD23F84A35AB75D30CFA4036F393BCACC93CAEF9E3E78DAF6BA ] C:\Users\Andre\AppData\Local\78c21744\2e736586.lnk
11:42:51.0257 0x0c3c - detected UnsignedFile.Multi.Generic ( 1 )
11:42:51.0436 0x0c3c ( UnsignedFile.Multi.Generic ) - warning
11:42:51.0456 0x0c3c BrowserUpdate - ok
11:42:51.0458 0x0c3c BrowserMe - ok
11:42:51.0682 0x0c3c [ 8AA4A3119B2DF4FFAAD39A98F4764E47, 412192A2261ED0BD82EE2418DF94A8B3BC41D2D40F5AB8DA0F99FB9F0525910E ] C:\Program Files\CCleaner\CCleaner64.exe
11:42:51.0866 0x0c3c CCleaner Monitoring - ok
11:42:51.0884 0x0c3c [ 95828D670CFD3B16EE188168E083C3C5, 8C10AE4BE93834A4C744F27CA79736D9123ED9B0D180DB28556D2D002545BAF2 ] C:\Windows\system32\mshta.exe
11:42:51.0891 0x0c3c - ok
11:42:51.0892 0x0c3c Waiting for KSN requests completion. In queue: 112
11:42:53.0002 0x0c3c AV detected via SS2: Avira Antivirus, C:\Program Files (x86)\Avira\Antivirus\wsctool.exe ( 15.0.22.49 ), 0x41000 ( enabled : updated )
11:42:53.0020 0x0c3c Win FW state via NFP2: enabled ( trusted )
11:42:53.0170 0x0c3c ============================================================
11:42:53.0170 0x0c3c Scan finished
11:42:53.0170 0x0c3c ============================================================
11:42:53.0173 0x08b8 Detected object count: 1
11:42:53.0173 0x08b8 Actual detected object count: 1
11:43:09.0617 0x08b8 ( UnsignedFile.Multi.Generic ) - skipped by user
11:43:09.0617 0x08b8 ( UnsignedFile.Multi.Generic ) - User select action: Skip


Alt 17.10.2016, 10:49   #6
andre_schmid
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Anbei noch die LOG Datei von ADWCleaner.

Mailware-Bytes ließ ich über Nacht laufen, jedoch kam das Programm nicht einmal bis zum Punkt Suchlauf... blieb irgendwie bei "Vorgänge vor dem Suchlauf" hängen... Also keine Log-Datei dazu.

Alt 17.10.2016, 17:40   #7
andre_schmid
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Anbei jetzt auch ein Malewarebytes-Log - hat einiges gefunden.
Mache grade noch einen Suchlauf über die anderen Laufwerke.

Alt 17.10.2016, 18:12   #8
M-K-D-B
/// TB-Ausbilder
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Servus,


also, so sieht es aus:
Die verschlüsselten Daten können (aktuell) nicht wiederhergestellt werden.




Option 1
Du hast deine privaten Daten vor der Infektion gesichert gehabt.
In dem Fall empfehle ich Windows neu zu installieren. Damit wären wir hier fertig.



Option 2
Du hast kein Backup deiner Daten vor der Infektion gemacht und hast daher nur die verschlüsselten Dateien.
Wir sollten dann zuerst den Rechner bereinigen und anschließend kannst du die verschlüsselten Dateien auf einen externen Datenträger kopieren. Evtl. gibt es ja in Zukunft mal einen sog. Decrypter, mit dem man diese Daten wieder entschlüsseln kann.



Bitte gib mir Bescheid, für welche Option du dich entschieden hast.
Bitte keine "Tools" mehr selber ausführen.

Geändert von M-K-D-B (17.10.2016 um 18:19 Uhr)

Alt 21.10.2016, 13:34   #9
M-K-D-B
/// TB-Ausbilder
 
Readme.hta Ransomware - Standard

Readme.hta Ransomware



Fehlende Rückmeldung
Dieses Thema wurde aus den Abos gelöscht. Somit bekomme ich keine Benachrichtigung über neue Antworten.
PM an mich falls Du denoch weiter machen willst.

Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist.

Jeder andere bitte hier klicken und einen eigenen Thread erstellen!

Antwort

Themen zu Readme.hta Ransomware
beenden, boxen, dateien, explorer, google, hallo zusammen, internet, internet explorer, laufwerke, lösung, namen, neuer, ordner, prozess, prozesse, rechner, schnell, seite, seiten, system, taskmanager, tipps, trojaner, verschlüsselung, werbung




Ähnliche Themen: Readme.hta Ransomware


  1. Readme.hta Ransomware
    Alles rund um Windows - 14.10.2016 (1)
  2. CrypMIC Ransomware (README Files Encrypted Malware) entfernen
    Anleitungen, FAQs & Links - 22.07.2016 (2)
  3. XIPR Ransomware Encryption
    Diskussionsforum - 01.07.2016 (10)
  4. Cerber Ransomware
    Plagegeister aller Art und deren Bekämpfung - 08.06.2016 (10)
  5. DMA Locker 4.0 ransomware entfernen
    Anleitungen, FAQs & Links - 20.05.2016 (2)
  6. BadBlock ransomware entfernen
    Anleitungen, FAQs & Links - 20.05.2016 (2)
  7. Cerber ransomware entfernen
    Anleitungen, FAQs & Links - 10.04.2016 (2)
  8. Win7 64, Crypto-Ransomware
    Log-Analyse und Auswertung - 10.02.2016 (6)
  9. Chimera Ransomware
    Log-Analyse und Auswertung - 14.11.2015 (3)
  10. Chimera Ransomware
    Plagegeister aller Art und deren Bekämpfung - 30.10.2015 (4)
  11. Chimera Ransomware in Firmennetzwerk
    Plagegeister aller Art und deren Bekämpfung - 07.10.2015 (10)
  12. Ransomware Virus
    Log-Analyse und Auswertung - 09.06.2015 (5)
  13. avast! Ransomware Removal
    Smartphone, Tablet & Handy Security - 19.09.2014 (0)
  14. *.LOCKED - README TO UNLOCK.txt - Verschlüsselungs - Virus
    Plagegeister aller Art und deren Bekämpfung - 17.04.2014 (7)
  15. GVU-Ransomware / Bin ich sie schon los?
    Log-Analyse und Auswertung - 27.06.2013 (13)
  16. Ransomware auf meinem PC :(
    Plagegeister aller Art und deren Bekämpfung - 02.10.2012 (10)
  17. BKA-Trojaner Windows XP readme[1].exe
    Log-Analyse und Auswertung - 29.04.2011 (6)

Zum Thema Readme.hta Ransomware - Hallo zusammen, leider hab ich mir am 12.10.2016 einen Trojaner geholt. Es werden auf allen Laufwerken die Textdokumente verschlüsselt zu Dateien mit der Endung *.8684 In jedem Ordner, wo so - Readme.hta Ransomware...
Archiv
Du betrachtest: Readme.hta Ransomware auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.