Hallo Schrauber.
Seit meinem letzten Post war ich doch noch einige Zeit am Computer. Der "Virus" wurde je länger je mächtiger. wusste, wenn ich noch lange zusehe, wird er sich irgendwann überall als Besitzer eintragen und mich nichts mehr machen lassen, das ihm schaden könnte. Ich habe deshalb versucht, Treiber neu zu installieren. Angefangen mit der Netzwerkkarte. Und das hat das Geschehen stark abgebremst. Habe dann noch andere Treiber Chipsatz usw. neu installiert. Und dann hab ich einen Scan gemacht mit Emsisoft. Ich werde das Logfile ebenfalls posten. Code:
Malwarebytes Anti-Rootkit BETA 1.9.2.1008
www.malwarebytes.org
Database version:
main: v2015.09.06.02
rootkit: v2015.08.16.01
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
AS :: AS-PC [administrator]
06.09.2015 09:41:28
mbar-log-2015-09-06 (09-41-28).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 359881
Time elapsed: 1 hour(s), 40 minute(s), 26 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) Code:
11:27:53.0303 0x0228 TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57
11:29:16.0468 0x0228 ============================================================
11:29:16.0469 0x0228 Current date / time: 2015/09/06 11:29:16.0468
11:29:16.0469 0x0228 SystemInfo:
11:29:16.0469 0x0228
11:29:16.0469 0x0228 OS Version: 6.1.7601 ServicePack: 1.0
11:29:16.0469 0x0228 Product type: Workstation
11:29:16.0469 0x0228 ComputerName: AS-PC
11:29:16.0470 0x0228 UserName: AS
11:29:16.0470 0x0228 Windows directory: C:\Windows
11:29:16.0470 0x0228 System windows directory: C:\Windows
11:29:16.0470 0x0228 Processor architecture: Intel x86
11:29:16.0470 0x0228 Number of processors: 2
11:29:16.0470 0x0228 Page size: 0x1000
11:29:16.0470 0x0228 Boot type: Normal boot
11:29:16.0470 0x0228 ============================================================
11:29:19.0699 0x0228 KLMD registered as C:\Windows\system32\drivers\75945153.sys
11:29:20.0145 0x0228 System UUID: {3E032D51-BBD0-70B0-51CA-81D15C41CD6E}
11:29:21.0143 0x0228 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:29:21.0160 0x0228 ============================================================
11:29:21.0160 0x0228 \Device\Harddisk0\DR0:
11:29:21.0160 0x0228 MBR partitions:
11:29:21.0160 0x0228 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:29:21.0160 0x0228 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1CD8E800
11:29:21.0160 0x0228 \Device\Harddisk0\DR0\Partition3: MBR, Type 0xC, StartLBA 0x1CDC1000, BlocksNum 0x400000
11:29:21.0160 0x0228 ============================================================
11:29:21.0183 0x0228 C: <-> \Device\Harddisk0\DR0\Partition2
11:29:21.0205 0x0228 E: <-> \Device\Harddisk0\DR0\Partition3
11:29:21.0205 0x0228 ============================================================
11:29:21.0205 0x0228 Initialize success
11:29:21.0206 0x0228 ============================================================
11:29:30.0465 0x12f0 ============================================================
11:29:30.0465 0x12f0 Scan started
11:29:30.0465 0x12f0 Mode: Manual; SigCheck; TDLFS;
11:29:30.0465 0x12f0 ============================================================
11:29:30.0465 0x12f0 KSN ping started
11:29:33.0164 0x12f0 KSN ping finished: true
11:29:35.0245 0x12f0 ================ Scan system memory ========================
11:29:35.0245 0x12f0 System memory - ok
11:29:35.0246 0x12f0 ================ Scan services =============================
11:29:35.0471 0x12f0 [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
11:29:35.0698 0x12f0 1394ohci - ok
11:29:35.0814 0x12f0 [ 00659E56339389469473AEC41587E706, 33CF74B079268D7B1205969212F2F6145095F0A5500C1B96957F0EB08C2D9D4E ] ac.sharedstore C:\Program Files\Common Files\ActivIdentity\ac.sharedstore.exe
11:29:35.0837 0x12f0 ac.sharedstore - ok
11:29:35.0901 0x12f0 [ CC1F1D3D70DC13C2C281488D347D4415, 3AB1495F8982C727D02E9975E2E04203B918AFAA7B05B5E7FEB5142EB30D1998 ] Accelerometer C:\Windows\system32\DRIVERS\Accelerometer.sys
11:29:35.0918 0x12f0 Accelerometer - ok
11:29:35.0980 0x12f0 [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:29:36.0002 0x12f0 ACPI - ok
11:29:36.0072 0x12f0 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:29:36.0161 0x12f0 AcpiPmi - ok
11:29:36.0222 0x12f0 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
11:29:36.0250 0x12f0 adp94xx - ok
11:29:36.0261 0x12f0 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
11:29:36.0276 0x12f0 adpahci - ok
11:29:36.0284 0x12f0 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
11:29:36.0295 0x12f0 adpu320 - ok
11:29:36.0342 0x12f0 [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:29:36.0381 0x12f0 AeLookupSvc - ok
11:29:36.0450 0x12f0 [ 1151FD4FB0216CFED887BFDE29EBD516, 673C2B498744C7EB846F6BD4FDC852B0A9722377D75FD694F7F78E727ADF4563 ] AFD C:\Windows\system32\drivers\afd.sys
11:29:36.0479 0x12f0 AFD - ok
11:29:36.0613 0x12f0 [ 7E10E3BB9B258AD8A9300F91214D67B9, CE5FAD7BF78234B64EAADF64DB23F3C342AADB9C5E3B0168E57863F494F30318 ] AgereSoftModem C:\Windows\system32\DRIVERS\AGRSM.sys
11:29:36.0661 0x12f0 AgereSoftModem - ok
11:29:36.0719 0x12f0 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys
11:29:36.0728 0x12f0 agp440 - ok
11:29:36.0803 0x12f0 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
11:29:36.0824 0x12f0 aic78xx - ok
11:29:36.0888 0x12f0 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe
11:29:36.0958 0x12f0 ALG - ok
11:29:37.0026 0x12f0 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys
11:29:37.0048 0x12f0 aliide - ok
11:29:37.0117 0x12f0 [ 86C472E88FCAE58A5CC9FFE10871B3F8, E6588128D39CFBFD0B86B17D588A5D16BF9E159865C4E71E259DC704D46E9CCF ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
11:29:37.0208 0x12f0 AMD External Events Utility - ok
11:29:37.0231 0x12f0 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
11:29:37.0245 0x12f0 amdagp - ok
11:29:37.0292 0x12f0 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\drivers\amdide.sys
11:29:37.0310 0x12f0 amdide - ok
11:29:37.0351 0x12f0 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
11:29:37.0420 0x12f0 AmdK8 - ok
11:29:37.0775 0x12f0 [ 36CD7F1619EE478A7395963AD6A340F7, 728D823D065772758F0A97D22D48AF04EA568FF2A8F713E8247B2F467454AF64 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:29:38.0145 0x12f0 amdkmdag - ok
11:29:38.0326 0x12f0 [ D03F046CCAC3DDC5DAA9EA4114DDC39D, 81CE30C1F803BFF02045F09A266609064C1FD1B021DC62E5C77D87452FF551FB ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
11:29:38.0362 0x12f0 amdkmdap - ok
11:29:38.0419 0x12f0 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
11:29:38.0453 0x12f0 AmdPPM - ok
11:29:38.0515 0x12f0 [ E7F4D42D8076EC60E21715CD11743A0D, 91AC020A70964F8783C999BDE8AB8391A3FA3AFC1CD4BC52A43625A2010A53E7 ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:29:38.0529 0x12f0 amdsata - ok
11:29:38.0563 0x12f0 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
11:29:38.0580 0x12f0 amdsbs - ok
11:29:38.0637 0x12f0 [ 146459D2B08BFDCBFA856D9947043C81, AC7F2069717601F949B0968EA651899D497170A93B84281B66D3CE5C382DDECB ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:29:38.0661 0x12f0 amdxata - ok
11:29:38.0718 0x12f0 [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID C:\Windows\system32\drivers\appid.sys
11:29:38.0745 0x12f0 AppID - ok
11:29:38.0813 0x12f0 [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:29:38.0863 0x12f0 AppIDSvc - ok
11:29:38.0903 0x12f0 [ FB1959012294D6AD43E5304DF65E3C26, CFE906B07FF71A178CF9C254B056C6F5A303DDC511F0E4E1E75808F1D5326495 ] Appinfo C:\Windows\System32\appinfo.dll
11:29:38.0923 0x12f0 Appinfo - ok
11:29:38.0989 0x12f0 [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt C:\Windows\System32\appmgmts.dll
11:29:39.0049 0x12f0 AppMgmt - ok
11:29:39.0084 0x12f0 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys
11:29:39.0099 0x12f0 arc - ok
11:29:39.0105 0x12f0 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
11:29:39.0120 0x12f0 arcsas - ok
11:29:39.0277 0x12f0 [ ACC23F541E1CC51E4FE9F947AC0F74EC, 094569F1411F664F9B55C68629BFD8C3862CD8BA1D076F55398B8EA351AE9F25 ] ASBroker C:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll
11:29:39.0375 0x12f0 ASBroker - ok
11:29:39.0413 0x12f0 [ A33370AC33281AC2310E1364E20D4887, F88BEAF8AEDCB83A0AEF3E39C6786CCBD6DF2C7829591C86B4DE7637EE80C7F2 ] ASChannel C:\Program Files\Hewlett-Packard\IAM\bin\AsChnl.dll
11:29:39.0436 0x12f0 ASChannel - ok
11:29:39.0495 0x12f0 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:29:39.0653 0x12f0 AsyncMac - ok
11:29:39.0722 0x12f0 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys
11:29:39.0734 0x12f0 atapi - ok
11:29:39.0792 0x12f0 [ 4D201D8B576BE4473405B2A86A2D28B3, 97D14459C5ED6EA67220485CC8828C07E9C39C4D04A371AB86AB6379E664DC7D ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW73.sys
11:29:39.0811 0x12f0 AtiHDAudioService - ok
11:29:40.0133 0x12f0 [ 36CD7F1619EE478A7395963AD6A340F7, 728D823D065772758F0A97D22D48AF04EA568FF2A8F713E8247B2F467454AF64 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:29:40.0363 0x12f0 atikmdag - ok
11:29:40.0597 0x12f0 [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:29:40.0641 0x12f0 AudioEndpointBuilder - ok
11:29:40.0655 0x12f0 [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] Audiosrv C:\Windows\System32\Audiosrv.dll
11:29:40.0685 0x12f0 Audiosrv - ok
11:29:40.0881 0x12f0 [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:29:40.0964 0x12f0 AxInstSV - ok
11:29:41.0041 0x12f0 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
11:29:41.0072 0x12f0 b06bdrv - ok
11:29:41.0108 0x12f0 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
11:29:41.0124 0x12f0 b57nd60x - ok
11:29:41.0158 0x12f0 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll
11:29:41.0173 0x12f0 BDESVC - ok
11:29:41.0203 0x12f0 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys
11:29:41.0224 0x12f0 Beep - ok
11:29:41.0307 0x12f0 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\Windows\System32\bfe.dll
11:29:41.0355 0x12f0 BFE - ok
11:29:41.0387 0x12f0 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\system32\qmgr.dll
11:29:41.0425 0x12f0 BITS - ok
11:29:41.0477 0x12f0 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:29:41.0529 0x12f0 blbdrive - ok
11:29:41.0545 0x12f0 [ FCAFAEF6798D7B51FF029F99A9898961, BFB37686B1386EB883B99DB6AC342C20514939F8B7A5CEC5D63865B3DC2B4D4F ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:29:41.0581 0x12f0 bowser - ok
11:29:41.0598 0x12f0 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:29:41.0696 0x12f0 BrFiltLo - ok
11:29:41.0731 0x12f0 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:29:41.0745 0x12f0 BrFiltUp - ok
11:29:41.0848 0x12f0 [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
11:29:41.0894 0x12f0 BridgeMP - ok
11:29:41.0942 0x12f0 [ 6E11F33D14D020F58D5E02E4D67DFA19, 9563E4E8CE769B7619745F6F6DE618389A1595785023BF1F295AD8301B27F0AF ] Browser C:\Windows\System32\browser.dll
11:29:42.0010 0x12f0 Browser - ok
11:29:42.0034 0x12f0 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:29:42.0061 0x12f0 Brserid - ok
11:29:42.0067 0x12f0 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:29:42.0080 0x12f0 BrSerWdm - ok
11:29:42.0084 0x12f0 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:29:42.0095 0x12f0 BrUsbMdm - ok
11:29:42.0123 0x12f0 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:29:42.0137 0x12f0 BrUsbSer - ok
11:29:42.0141 0x12f0 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
11:29:42.0154 0x12f0 BTHMODEM - ok
11:29:42.0198 0x12f0 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll
11:29:42.0243 0x12f0 bthserv - ok
11:29:42.0372 0x12f0 catchme - ok
11:29:42.0415 0x12f0 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:29:42.0486 0x12f0 cdfs - ok
11:29:42.0544 0x12f0 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\drivers\cdrom.sys
11:29:42.0563 0x12f0 cdrom - ok
11:29:42.0669 0x12f0 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll
11:29:42.0715 0x12f0 CertPropSvc - ok
11:29:42.0760 0x12f0 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
11:29:42.0772 0x12f0 circlass - ok
11:29:42.0798 0x12f0 [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS C:\Windows\system32\CLFS.sys
11:29:42.0812 0x12f0 CLFS - ok
11:29:42.0890 0x12f0 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:29:42.0909 0x12f0 clr_optimization_v2.0.50727_32 - ok
11:29:43.0075 0x12f0 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:29:43.0102 0x12f0 clr_optimization_v4.0.30319_32 - ok
11:29:43.0134 0x12f0 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:29:43.0150 0x12f0 CmBatt - ok
11:29:43.0181 0x12f0 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:29:43.0193 0x12f0 cmdide - ok
11:29:43.0208 0x12f0 [ 1B675691ED940766149C93E8F4488D68, A55C41B2B343B1CF53D737ED1752D0510052094FFC60FDB833279A8A52398132 ] CNG C:\Windows\system32\Drivers\cng.sys
11:29:43.0228 0x12f0 CNG - ok
11:29:43.0370 0x12f0 [ C7A0E61D5714AC20DE52D4F66EC773B8, 53F0C91FD62E6787221EFB4BFDB087C2087CACD6B0C0605F58FC391F546EBA7A ] Com4QLBEx C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
11:29:43.0390 0x12f0 Com4QLBEx - ok
11:29:43.0418 0x12f0 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:29:43.0426 0x12f0 Compbatt - ok
11:29:43.0495 0x12f0 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
11:29:43.0515 0x12f0 CompositeBus - ok
11:29:43.0529 0x12f0 COMSysApp - ok
11:29:43.0552 0x12f0 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
11:29:43.0560 0x12f0 crcdisk - ok
11:29:43.0607 0x12f0 [ A585BEBF7D054BD9618EDA0922D5484A, 340DF730E88F8B6A4EF542F620EBA2A720546AFAB4DFFA00F066B7610A1026C5 ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:29:43.0643 0x12f0 CryptSvc - ok
11:29:43.0671 0x12f0 [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC C:\Windows\system32\drivers\csc.sys
11:29:43.0714 0x12f0 CSC - ok
11:29:43.0781 0x12f0 [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService C:\Windows\System32\cscsvc.dll
11:29:43.0814 0x12f0 CscService - ok
11:29:43.0870 0x12f0 [ A05433F6218DCB8F0DEC232DE65F8B26, CFA2BC253E6B714A177AE8CFD4C24CFE8F5B638D479BFBC6A886A70A3590CC90 ] DAMDrv C:\Windows\system32\DRIVERS\DAMDrv.sys
11:29:43.0886 0x12f0 DAMDrv - ok
11:29:43.0923 0x12f0 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\Windows\system32\rpcss.dll
11:29:43.0955 0x12f0 DcomLaunch - ok
11:29:44.0002 0x12f0 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll
11:29:44.0050 0x12f0 defragsvc - ok
11:29:44.0094 0x12f0 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:29:44.0116 0x12f0 DfsC - ok
11:29:44.0199 0x12f0 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll
11:29:44.0243 0x12f0 Dhcp - ok
11:29:44.0276 0x12f0 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys
11:29:44.0332 0x12f0 discache - ok
11:29:44.0359 0x12f0 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys
11:29:44.0368 0x12f0 Disk - ok
11:29:44.0401 0x12f0 [ 2FE30D71919C51131405797620E0A714, 16060DDC32EF95EB6E37B91D50A96AB53CB0DEBB3DFDCB31975D16361092ABA5 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:29:44.0425 0x12f0 Dnscache - ok
11:29:44.0505 0x12f0 [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\Windows\System32\dot3svc.dll
11:29:44.0556 0x12f0 dot3svc - ok
11:29:44.0586 0x12f0 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll
11:29:44.0630 0x12f0 DPS - ok
11:29:44.0686 0x12f0 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:29:44.0768 0x12f0 drmkaud - ok
11:29:44.0865 0x12f0 [ 23F5D28378A160352BA8F817BD8C71CB, 11BF7B7E6276C28EFF74B8AF89B493CBB89B394D2A091708EDA15DA5C342FF19 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:29:44.0898 0x12f0 DXGKrnl - ok
11:29:44.0966 0x12f0 [ F8261752AB473E3B24376AAB280AD15A, 8E681395EB13A06634034356B7C807028655160EB879EFDECE8DC684F78C7246 ] e1yexpress C:\Windows\system32\DRIVERS\e1y6232.sys
11:29:44.0998 0x12f0 e1yexpress - ok
11:29:45.0049 0x12f0 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll
11:29:45.0095 0x12f0 EapHost - ok
11:29:45.0283 0x12f0 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
11:29:45.0495 0x12f0 ebdrv - ok
11:29:45.0531 0x12f0 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] EFS C:\Windows\System32\lsass.exe
11:29:45.0542 0x12f0 EFS - ok
11:29:45.0671 0x12f0 [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
11:29:45.0900 0x12f0 ehRecvr - ok
11:29:45.0951 0x12f0 [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe
11:29:46.0005 0x12f0 ehSched - ok
11:29:46.0063 0x12f0 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
11:29:46.0090 0x12f0 elxstor - ok
11:29:46.0122 0x12f0 epp32 - ok
11:29:46.0140 0x12f0 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:29:46.0150 0x12f0 ErrDev - ok
11:29:46.0194 0x12f0 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll
11:29:46.0223 0x12f0 EventSystem - ok
11:29:46.0303 0x12f0 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys
11:29:46.0354 0x12f0 exfat - ok
11:29:46.0367 0x12f0 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:29:46.0393 0x12f0 fastfat - ok
11:29:46.0476 0x12f0 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe
11:29:46.0520 0x12f0 Fax - ok
11:29:46.0546 0x12f0 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:29:46.0557 0x12f0 fdc - ok
11:29:46.0573 0x12f0 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll
11:29:46.0596 0x12f0 fdPHost - ok
11:29:46.0622 0x12f0 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll
11:29:46.0647 0x12f0 FDResPub - ok
11:29:46.0664 0x12f0 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:29:46.0674 0x12f0 FileInfo - ok
11:29:46.0678 0x12f0 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:29:46.0701 0x12f0 Filetrace - ok
11:29:46.0776 0x12f0 [ C2F62839BB7ADBEC31F19776504867C4, 88450B4A23142D8EA5C68B16D35054259E48A04C3FC9294DCD390451753D730C ] FLCDLOCK c:\Windows\system32\flcdlock.exe
11:29:46.0792 0x12f0 FLCDLOCK - ok
11:29:46.0826 0x12f0 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:29:46.0836 0x12f0 flpydisk - ok
11:29:46.0869 0x12f0 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:29:46.0882 0x12f0 FltMgr - ok
11:29:46.0964 0x12f0 [ FA6C66E4364D7DA57AADE5DCC03BB999, 9C0D0A04D2558CF60B7F7185CC9B369CDDD3B1C625960910CECF07611F288378 ] FontCache C:\Windows\system32\FntCache.dll
11:29:47.0010 0x12f0 FontCache - ok
11:29:47.0095 0x12f0 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:29:47.0116 0x12f0 FontCache3.0.0.0 - ok
11:29:47.0147 0x12f0 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:29:47.0170 0x12f0 FsDepends - ok
11:29:47.0175 0x12f0 [ A574B4360E438977038AAE4BF60D79A2, 7255CCDDDAC4853FA72E6487408C4B7390CBA37549CE952929B2A9CF3327C616 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:29:47.0188 0x12f0 Fs_Rec - ok
11:29:47.0244 0x12f0 [ 8A73E79089B282100B9393B644CB853B, 844DC5AADFABBD050B967904B796BA06BFD64C9112616EA26229D084F8B3AD41 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:29:47.0273 0x12f0 fvevol - ok
11:29:47.0322 0x12f0 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
11:29:47.0348 0x12f0 gagp30kx - ok
11:29:47.0417 0x12f0 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll
11:29:47.0471 0x12f0 gpsvc - ok
11:29:47.0521 0x12f0 [ C172F0D0329E46513B09E1FC60A27B9D, 05DE0544C8A29B2C6028D2B97F81EACED5B99B571DE507A18CE856BD30DF7D56 ] HBtnKey C:\Windows\system32\DRIVERS\cpqbttn.sys
11:29:47.0527 0x12f0 HBtnKey - ok
11:29:47.0553 0x12f0 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:29:47.0579 0x12f0 hcw85cir - ok
11:29:47.0649 0x12f0 [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:29:47.0687 0x12f0 HdAudAddService - ok
11:29:47.0757 0x12f0 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
11:29:47.0784 0x12f0 HDAudBus - ok
11:29:47.0827 0x12f0 [ 30D57EE84E1E169D41A6E873B549A096, 3473AF4A8B651E27ADC91BEC3AF379196ECB7525D768D7984D1FCF67A322116B ] HECI C:\Windows\system32\DRIVERS\HECI.sys
11:29:47.0844 0x12f0 HECI - ok
11:29:47.0878 0x12f0 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
11:29:47.0889 0x12f0 HidBatt - ok
11:29:47.0894 0x12f0 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
11:29:47.0909 0x12f0 HidBth - ok
11:29:47.0917 0x12f0 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
11:29:47.0929 0x12f0 HidIr - ok
11:29:47.0959 0x12f0 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\System32\hidserv.dll
11:29:47.0984 0x12f0 hidserv - ok
11:29:48.0062 0x12f0 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\drivers\hidusb.sys
11:29:48.0082 0x12f0 HidUsb - ok
11:29:48.0120 0x12f0 [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll
11:29:48.0166 0x12f0 hkmsvc - ok
11:29:48.0409 0x12f0 [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:29:48.0570 0x12f0 HomeGroupListener - ok
11:29:48.0620 0x12f0 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:29:48.0646 0x12f0 HomeGroupProvider - ok
11:29:48.0808 0x12f0 [ 38024D5D5D9CF7C12B74AECDA968C970, 3AB4906D8E34A0797C16E3B8933B72A560711CBB6AFC2D61851B9B12DA49B9C1 ] HP ProtectTools Service C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
11:29:48.0831 0x12f0 HP ProtectTools Service - detected UnsignedFile.Multi.Generic ( 1 )
11:29:51.0488 0x12f0 Detect skipped due to KSN trusted
11:29:51.0488 0x12f0 HP ProtectTools Service - ok
11:29:51.0701 0x12f0 [ C5D2F308E1C12A5C328EF549696DBC05, 4BBDA3E0707854CC80FF8699A478D0D2AF18094B9F7EFB629B0CE4F890C44464 ] hpCMSrv C:\Program Files\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe
11:29:51.0729 0x12f0 hpCMSrv - ok
11:29:51.0881 0x12f0 [ C48B579D5A287AD85BEDEF291E81A3AA, 7A84EF09659A8DE4F121BDE9FCD4BCA9323C114B2F16C21D0B078950086E8E1A ] HPDrvMntSvc.exe C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
11:29:51.0908 0x12f0 HPDrvMntSvc.exe - ok
11:29:51.0949 0x12f0 [ 4EF10B866C62ABBEAF7511CDD05A19BE, B758DCB9CD8C7E6ED4DEFB666A94B0F749CB86964D2CA9004DF94C5E321F5151 ] hpdskflt C:\Windows\system32\DRIVERS\hpdskflt.sys
11:29:51.0954 0x12f0 hpdskflt - ok
11:29:52.0019 0x12f0 [ 81C5E6C3AE27DCF17BE506046F00015F, 3FA23B6B56B2CAD5C1BBB1B9F71B5665A40D0A262E7D67774B19ECA6E20B0F49 ] HpFkCryptService C:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
11:29:52.0039 0x12f0 HpFkCryptService - ok
11:29:52.0121 0x12f0 [ 3918E9D008F200B67C81A450668DADF2, 82AD5D827E3089DB013852E35969270864CEECEF8FB7E3B0A5CDB21A2CB58535 ] HPFSService C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
11:29:52.0150 0x12f0 HPFSService - detected UnsignedFile.Multi.Generic ( 1 )
11:29:55.0140 0x12f0 HPFSService ( UnsignedFile.Multi.Generic ) - warning
11:29:57.0923 0x12f0 [ 1210960FF8928950D2A786895B0C424A, 22C8785E024CFDD3A43FAEAAA96B8332C37E9B6C765AB7AFBCD3DAA2DC9EFFC7 ] HpqKbFiltr C:\Windows\system32\DRIVERS\HpqKbFiltr.sys
11:29:57.0958 0x12f0 HpqKbFiltr - ok
11:29:58.0093 0x12f0 [ 375B287A63F5E27D20EE94B459981CEA, F151F031F2CD9F48AFE0F87E089946623D5EC4AB73E2BFEFEC0F09716E6EF472 ] hpqwmiex C:\Program Files\Hewlett-Packard\Shared\hpqWmiEx.exe
11:29:58.0119 0x12f0 hpqwmiex - ok
11:29:58.0167 0x12f0 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:29:58.0176 0x12f0 HpSAMD - ok
11:29:58.0205 0x12f0 [ C0BEB56ED79B59B7B33D0AA6C38A0BA6, 8A21DB7B51BF533CBA08640498C132560641244B9218C483E2053502DF88313D ] hpsrv C:\Windows\system32\Hpservice.exe
11:29:58.0216 0x12f0 hpsrv - ok
11:29:58.0302 0x12f0 [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:29:58.0353 0x12f0 HTTP - ok
11:29:58.0391 0x12f0 [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:29:58.0415 0x12f0 hwpolicy - ok
11:29:58.0469 0x12f0 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
11:29:58.0487 0x12f0 i8042prt - ok
11:29:58.0636 0x12f0 [ 593EF9F904C8497F6D794DC6FCC59DCA, 13944636B6477C70970B257913E13D03AA94B4E48A45B1D9753F2C04BB9D125E ] IAANTMON C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
11:29:58.0663 0x12f0 IAANTMON - ok
11:29:58.0692 0x12f0 [ 592A0B130FF567A1725F96AD1510D551, AF97DB45EB9C22DA48D925BAD256DE869DF67F16073C506EE5CCC9685F1203A2 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
11:29:58.0704 0x12f0 iaStor - ok
11:29:58.0774 0x12f0 [ A3CAE5D281DB4CFF7CFF8233507EE5AD, 2666107220B9F301193F2CF85A3D6B09E6E42CC150152D10A8886E47A3FD9B0D ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:29:58.0811 0x12f0 iaStorV - ok
11:29:58.0895 0x12f0 [ C521D7EB6497BB1AF6AFA89E322FB43C, BDDCFCBB5B76A9295669B5AC9F732D6127199ED5C300770B554C4E4794F66BB7 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:29:58.0923 0x12f0 idsvc - ok
11:29:59.0023 0x12f0 [ 5BB5332B7A08A7493680B477212753AB, 605CFFA72DA031954FFF86B9F1660EAC877A4DEA74C10A7F181BCD63AFD550F8 ] IFXSpMgtSrv C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxspmgt.exe
11:29:59.0051 0x12f0 IFXSpMgtSrv - ok
11:29:59.0093 0x12f0 [ DD2CA93025BB1174C870F0B0A7B445DE, 64816442BEEE911FC52D95C5235B00D96DE274C17BF09076594C52C31C58C9D3 ] IFXTCS C:\Program Files\Hewlett-Packard\Embedded Security Software\ifxtcs.exe
11:29:59.0118 0x12f0 IFXTCS - ok
11:29:59.0154 0x12f0 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
11:29:59.0163 0x12f0 iirsp - ok
11:29:59.0254 0x12f0 [ F95622F161474511B8D80D6B093AA610, F2320E25EB9B4AA9A8366BD3AA23EABEBE111A5610D3A62EBA47D90427D5BC26 ] IKEEXT C:\Windows\System32\ikeext.dll
11:29:59.0296 0x12f0 IKEEXT - ok
11:29:59.0313 0x12f0 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys
11:29:59.0321 0x12f0 intelide - ok
11:29:59.0366 0x12f0 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:29:59.0377 0x12f0 intelppm - ok
11:29:59.0416 0x12f0 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:29:59.0485 0x12f0 IPBusEnum - ok
11:29:59.0508 0x12f0 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:29:59.0531 0x12f0 IpFilterDriver - ok
11:29:59.0584 0x12f0 [ 4D65A07B795D6674312F879D09AA7663, 8D72FE0B51A6FF71F85D2602DB3AE91C8749F70869B6789552F047BA81411EDA ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:29:59.0617 0x12f0 iphlpsvc - ok
11:29:59.0655 0x12f0 [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:29:59.0683 0x12f0 IPMIDRV - ok
11:29:59.0713 0x12f0 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:29:59.0745 0x12f0 IPNAT - ok
11:29:59.0766 0x12f0 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:29:59.0793 0x12f0 IRENUM - ok
11:29:59.0839 0x12f0 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:29:59.0860 0x12f0 isapnp - ok
11:29:59.0898 0x12f0 [ CB7A9ABB12B8415BCE5D74994C7BA3AE, 464BFF3F5EEE985BE075E23E1813F5CB82A9A0771A92C6D889B13B867BCDF647 ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:29:59.0911 0x12f0 iScsiPrt - ok
11:29:59.0945 0x12f0 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys
11:29:59.0954 0x12f0 kbdclass - ok
11:29:59.0986 0x12f0 [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
11:29:59.0997 0x12f0 kbdhid - ok
11:30:00.0011 0x12f0 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] KeyIso C:\Windows\system32\lsass.exe
11:30:00.0023 0x12f0 KeyIso - ok
11:30:00.0058 0x12f0 [ 412CEA1AA78CC02A447F5C9E62B32FF1, E06859E2CE2AFA3CE521851F8810778ED1748B812E601A58786605096AACEA81 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:30:00.0068 0x12f0 KSecDD - ok
11:30:00.0108 0x12f0 [ 26C046977E85B95036453D7B88BA1820, 375B284AFB407CAE417D2090B112A0ED1CCD516ABFDDBFCD5D6AADE859F14ACD ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:30:00.0119 0x12f0 KSecPkg - ok
11:30:00.0157 0x12f0 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll
11:30:00.0190 0x12f0 KtmRm - ok
11:30:00.0245 0x12f0 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\System32\srvsvc.dll
11:30:00.0273 0x12f0 LanmanServer - ok
11:30:00.0300 0x12f0 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:30:00.0323 0x12f0 LanmanWorkstation - ok
11:30:00.0375 0x12f0 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:30:00.0445 0x12f0 lltdio - ok
11:30:00.0474 0x12f0 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:30:00.0502 0x12f0 lltdsvc - ok
11:30:00.0521 0x12f0 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll
11:30:00.0542 0x12f0 lmhosts - ok
11:30:00.0578 0x12f0 [ 44CBF7F9E2FB9C36ACC892812F8750A0, B97D477494072D456D45046E66F341757A40B92390836D9C4AE24EB5D088D63A ] LMS C:\Program Files\Intel\AMT\LMS.exe
11:30:00.0604 0x12f0 LMS - ok
11:30:00.0642 0x12f0 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
11:30:00.0652 0x12f0 LSI_FC - ok
11:30:00.0671 0x12f0 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
11:30:00.0681 0x12f0 LSI_SAS - ok
11:30:00.0686 0x12f0 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:30:00.0695 0x12f0 LSI_SAS2 - ok
11:30:00.0700 0x12f0 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:30:00.0710 0x12f0 LSI_SCSI - ok
11:30:00.0725 0x12f0 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys
11:30:00.0749 0x12f0 luafv - ok
11:30:00.0784 0x12f0 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
11:30:00.0817 0x12f0 Mcx2Svc - ok
11:30:00.0845 0x12f0 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
11:30:00.0868 0x12f0 megasas - ok
11:30:00.0889 0x12f0 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
11:30:00.0902 0x12f0 MegaSR - ok
11:30:00.0957 0x12f0 [ 64B96DE8C492BD435372D9130A535F1D, B253682F140CD548489AE6CD2EC281C382E8D3C4C3BE9A423DFEB963E37D665C ] MfeAVFK C:\Windows\system32\drivers\MfeAVFK.sys
11:30:00.0979 0x12f0 MfeAVFK - ok
11:30:01.0005 0x12f0 [ 078E87A89D36CC3516F19D5FB518BDDC, 09C80B948D638D67805EA21CFC9C8FE29685BBDE167385248CD763F9E1C9A1F4 ] MfeBOPK C:\Windows\system32\drivers\MfeBOPK.sys
11:30:01.0011 0x12f0 MfeBOPK - ok
11:30:01.0044 0x12f0 [ 168C565101FD5B9DB694EFDEC91FAFA9, 1F7E469BDE079C85EE6CB6F02423E4F93C5FE373BDEA5CCD62173AA31934AFB4 ] mfehidk C:\Windows\system32\drivers\mfehidk.sys
11:30:01.0054 0x12f0 mfehidk - ok
11:30:01.0105 0x12f0 [ E0842F67DC9BC4D21D1E319610EBE9E5, 7FEBA23EDA99D092775AE8F41AE0B5812C6C6CB95DAB387FF5845FE6113B1E40 ] MfeRKDK C:\Windows\system32\drivers\MfeRKDK.sys
11:30:01.0125 0x12f0 MfeRKDK - ok
11:30:01.0162 0x12f0 [ 43A7ACBBD70ECD62F0B63486C72089A3, 2A50971FF6C42A63857B5972E4CF01E9632A5B7E3149A395446F9CB72A19C987 ] mfetdik C:\Windows\system32\drivers\mfetdik.sys
11:30:01.0169 0x12f0 mfetdik - ok
11:30:01.0196 0x12f0 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll
11:30:01.0220 0x12f0 MMCSS - ok
11:30:01.0250 0x12f0 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys
11:30:01.0274 0x12f0 Modem - ok
11:30:01.0449 0x12f0 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:30:01.0485 0x12f0 monitor - ok
11:30:01.0540 0x12f0 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\drivers\mouclass.sys
11:30:01.0567 0x12f0 mouclass - ok
11:30:01.0618 0x12f0 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:30:01.0647 0x12f0 mouhid - ok
11:30:01.0702 0x12f0 [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:30:01.0731 0x12f0 mountmgr - ok
11:30:01.0796 0x12f0 [ CC11EEB7AF4617D65DF0E9A21FC1ABD0, A683A5FB26E1B9FB4EEB40A9C7186F8433E3FB0A45848DF6102EF07B4DC75AC8 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
11:30:01.0813 0x12f0 MozillaMaintenance - ok
11:30:01.0863 0x12f0 [ F112DA773EC3E9D3CDE9221ED300E033, 693C416B281DA3489C096812D0E4E0413C05798D36AF534624C3B29551CE68A4 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
11:30:01.0885 0x12f0 MpFilter - ok
11:30:01.0944 0x12f0 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio C:\Windows\system32\drivers\mpio.sys
11:30:01.0976 0x12f0 mpio - ok
11:30:02.0010 0x12f0 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:30:02.0034 0x12f0 mpsdrv - ok
11:30:02.0081 0x12f0 [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:30:02.0120 0x12f0 MpsSvc - ok
11:30:02.0153 0x12f0 [ CEB46AB7C01C9F825F8CC6BABC18166A, AA98898204FC58878502C170FE6ED8BA681396DDD8BF3689D0C3642DEA87BEF8 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:30:02.0169 0x12f0 MRxDAV - ok
11:30:02.0234 0x12f0 [ B272B4C3E085EA860C12F2E4FAF2FFA2, DA99D8223D9FB7BFA52E66B73D1E1AA47B76B45A649400F7898E8D65D8672E52 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:30:02.0274 0x12f0 mrxsmb - ok
11:30:02.0293 0x12f0 [ 9AC33EF26C8A3AD0F117D00EB7301D03, 403445B07DC55F9DF98CA11AC87D4231187A2472A4E107786A5845B213355F0A ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:30:02.0342 0x12f0 mrxsmb10 - ok
11:30:02.0386 0x12f0 [ E0ABDB5ED7E199E242A7D028E76C1D3A, 4014A1F0720F6D15A2FB0CF4F1F970595BC29929F92F461CDD68E4513F49563E ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:30:02.0431 0x12f0 mrxsmb20 - ok
11:30:02.0450 0x12f0 [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci C:\Windows\system32\drivers\msahci.sys
11:30:02.0458 0x12f0 msahci - ok
11:30:02.0477 0x12f0 [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:30:02.0488 0x12f0 msdsm - ok
11:30:02.0533 0x12f0 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe
11:30:02.0563 0x12f0 MSDTC - ok
11:30:02.0606 0x12f0 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:30:02.0628 0x12f0 Msfs - ok
11:30:02.0632 0x12f0 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:30:02.0654 0x12f0 mshidkmdf - ok
11:30:02.0704 0x12f0 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:30:02.0723 0x12f0 msisadrv - ok
11:30:02.0774 0x12f0 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:30:02.0813 0x12f0 MSiSCSI - ok
11:30:02.0816 0x12f0 msiserver - ok
11:30:02.0851 0x12f0 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:30:02.0875 0x12f0 MSKSSRV - ok
11:30:02.0964 0x12f0 [ CC09BB7FDEFC5763CCB3CF7DAE2D76CF, F8F00900EDBA2F64BF136DD0B6C83CAF07C72F24F3D49C78B7EA24757FDBC6D0 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
11:30:02.0989 0x12f0 MsMpSvc - ok
11:30:03.0020 0x12f0 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:30:03.0062 0x12f0 MSPCLOCK - ok
11:30:03.0081 0x12f0 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:30:03.0102 0x12f0 MSPQM - ok
11:30:03.0122 0x12f0 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:30:03.0134 0x12f0 MsRPC - ok
11:30:03.0176 0x12f0 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
11:30:03.0184 0x12f0 mssmbios - ok
11:30:03.0220 0x12f0 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:30:03.0267 0x12f0 MSTEE - ok
11:30:03.0282 0x12f0 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
11:30:03.0293 0x12f0 MTConfig - ok
11:30:03.0310 0x12f0 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys
11:30:03.0319 0x12f0 Mup - ok
11:30:03.0366 0x12f0 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent C:\Windows\system32\qagentRT.dll
11:30:03.0417 0x12f0 napagent - ok
11:30:03.0488 0x12f0 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:30:03.0526 0x12f0 NativeWifiP - ok
11:30:03.0583 0x12f0 [ E7C54812A2AAF43316EB6930C1FFA108, C8A6FC1957FA29A3B372132FEA9145538BC767044A11D77316D3D1A3EAA60630 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:30:03.0609 0x12f0 NDIS - ok
11:30:03.0645 0x12f0 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:30:03.0667 0x12f0 NdisCap - ok
11:30:03.0686 0x12f0 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:30:03.0706 0x12f0 NdisTapi - ok
11:30:03.0752 0x12f0 [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:30:03.0794 0x12f0 Ndisuio - ok
11:30:03.0830 0x12f0 [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:30:03.0853 0x12f0 NdisWan - ok
11:30:03.0882 0x12f0 [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:30:03.0903 0x12f0 NDProxy - ok
11:30:03.0945 0x12f0 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:30:03.0990 0x12f0 NetBIOS - ok
11:30:04.0038 0x12f0 [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:30:04.0076 0x12f0 NetBT - ok
11:30:04.0100 0x12f0 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] Netlogon C:\Windows\system32\lsass.exe
11:30:04.0111 0x12f0 Netlogon - ok
11:30:04.0174 0x12f0 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll
11:30:04.0206 0x12f0 Netman - ok
11:30:04.0230 0x12f0 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll
11:30:04.0263 0x12f0 netprofm - ok
11:30:04.0310 0x12f0 [ F476EC40033CDB91EFBE73EB99B8362D, B17535037BC070F9AE1F6B381C2DBEE27658A8FDE15FB0E061F485EA7C7CBE59 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:30:04.0331 0x12f0 NetTcpPortSharing - ok
11:30:04.0383 0x12f0 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
11:30:04.0396 0x12f0 nfrd960 - ok
11:30:04.0443 0x12f0 [ 780FF28BCD8470C5FDDEEF69982AA295, 1ED386E87E0AA733F23D554D2BF4EF4168DB9A419B7BA0BA8FBA20F118BE21DF ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
11:30:04.0458 0x12f0 NisDrv - ok
11:30:04.0496 0x12f0 [ 3FF257F54649D4F19E39263C5D581CD1, 1F201EEE770A452AA30C6270AAA456A77F9F3A102F473E12C22D3B8809932C1B ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
11:30:04.0519 0x12f0 NisSrv - ok
11:30:04.0580 0x12f0 [ 912084381D30D8B89EC4E293053F4710, 99B8CD043DF531D4B9725ED167F63CED220608B2FED3EE8250C217D15762DFD7 ] NlaSvc C:\Windows\System32\nlasvc.dll
11:30:04.0618 0x12f0 NlaSvc - ok
11:30:04.0638 0x12f0 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:30:04.0661 0x12f0 Npfs - ok
11:30:04.0690 0x12f0 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll
11:30:04.0712 0x12f0 nsi - ok
11:30:04.0738 0x12f0 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:30:04.0760 0x12f0 nsiproxy - ok
11:30:04.0873 0x12f0 [ 33C3093D09017CFE2E219F2472BFF6EB, DE46C7A53C3606F036DED1EE8A81B79CAF3171A7E97DA2F71712E2DA046A262E ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:30:04.0912 0x12f0 Ntfs - ok
11:30:04.0942 0x12f0 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys
11:30:04.0964 0x12f0 Null - ok
11:30:05.0015 0x12f0 [ AF2EEC9580C1D32FB7EAF105D9784061, 6DAAE3BCA048ACD7FFD26A65C793C461933179070F03855FE3DC3C01F968163A ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:30:05.0044 0x12f0 nvraid - ok
11:30:05.0077 0x12f0 [ 9283C58EBAA2618F93482EB5DABCEC82, 0BC119D4EAFDEA879E4C1CFBA5402499DBD1970EDF963C6D2034D4867C34D15E ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:30:05.0088 0x12f0 nvstor - ok
11:30:05.0134 0x12f0 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:30:05.0160 0x12f0 nv_agp - ok
11:30:05.0180 0x12f0 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:30:05.0191 0x12f0 ohci1394 - ok
11:30:05.0223 0x12f0 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:30:05.0252 0x12f0 p2pimsvc - ok
11:30:05.0329 0x12f0 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll
11:30:05.0378 0x12f0 p2psvc - ok
11:30:05.0428 0x12f0 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:30:05.0447 0x12f0 Parport - ok
11:30:05.0470 0x12f0 [ BF8F6AF06DA75B336F07E23AEF97D93B, 2F2C4314872732550A112BFF2F803484D4A3D697F0D69D352350CE208FD8A1A4 ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:30:05.0484 0x12f0 partmgr - ok
11:30:05.0490 0x12f0 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
11:30:05.0502 0x12f0 Parvdm - ok
11:30:05.0541 0x12f0 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:30:05.0559 0x12f0 PcaSvc - ok
11:30:05.0602 0x12f0 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys
11:30:05.0613 0x12f0 pci - ok
11:30:05.0627 0x12f0 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys
11:30:05.0635 0x12f0 pciide - ok
11:30:05.0669 0x12f0 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:30:05.0681 0x12f0 pcmcia - ok
11:30:05.0686 0x12f0 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
11:30:05.0695 0x12f0 pcw - ok
11:30:05.0732 0x12f0 pdfcDispatcher - ok
11:30:05.0814 0x12f0 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:30:05.0881 0x12f0 PEAUTH - ok
11:30:05.0955 0x12f0 [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
11:30:06.0007 0x12f0 PeerDistSvc - ok
11:30:06.0079 0x12f0 [ B27F1DF5ABC5240480D4D2D9666867A5, CB9FB18F5D8C925750655B6CCCFEF403D02DEAA7ABC2BF6B4B952AB0D3AA2BA7 ] PersonalSecureDrive C:\Windows\System32\drivers\psd.sys
11:30:06.0097 0x12f0 PersonalSecureDrive - ok
11:30:06.0125 0x12f0 [ 0AED704097BA683113CF08E8AD37723B, 23184E1428136536C36395190A8B9C5FAE80CC61375E6E5E3F18C2F4657A7650 ] PersonalSecureDriveService C:\Program Files\Hewlett-Packard\Embedded Security Software\IfxPsdSv.exe
11:30:06.0134 0x12f0 PersonalSecureDriveService - ok
11:30:06.0204 0x12f0 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll
11:30:06.0270 0x12f0 pla - ok
11:30:06.0337 0x12f0 [ 92DC6E68D2C856C5C2F21AE9E22112B8, EFAA27886A05E57E629A9EFC3671D9D64144795EDF55438A676F5B43E59BE3FC ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:30:06.0387 0x12f0 PlugPlay - ok
11:30:06.0475 0x12f0 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:30:06.0600 0x12f0 PNRPAutoReg - ok
11:30:06.0654 0x12f0 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:30:06.0680 0x12f0 PNRPsvc - ok
11:30:06.0719 0x12f0 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:30:06.0749 0x12f0 PolicyAgent - ok
11:30:06.0775 0x12f0 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll
11:30:06.0800 0x12f0 Power - ok
11:30:06.0865 0x12f0 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:30:06.0916 0x12f0 PptpMiniport - ok
11:30:06.0936 0x12f0 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:30:06.0948 0x12f0 Processor - ok
11:30:06.0987 0x12f0 [ 43CA4CCC22D52FB58E8988F0198851D0, DF67BD70D9D82677AE61244B4E54677A5008A7F5EB531DF2A7E7D33F1658EA78 ] ProfSvc C:\Windows\system32\profsvc.dll
11:30:07.0013 0x12f0 ProfSvc - ok
11:30:07.0033 0x12f0 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:30:07.0044 0x12f0 ProtectedStorage - ok
11:30:07.0071 0x12f0 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:30:07.0096 0x12f0 Psched - ok
11:30:07.0190 0x12f0 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:30:07.0234 0x12f0 ql2300 - ok
11:30:07.0260 0x12f0 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:30:07.0271 0x12f0 ql40xx - ok
11:30:07.0299 0x12f0 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
11:30:07.0318 0x12f0 QWAVE - ok
11:30:07.0338 0x12f0 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:30:07.0350 0x12f0 QWAVEdrv - ok
11:30:07.0363 0x12f0 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:30:07.0385 0x12f0 RasAcd - ok
11:30:07.0592 0x12f0 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:30:07.0636 0x12f0 RasAgileVpn - ok
11:30:07.0671 0x12f0 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
11:30:07.0697 0x12f0 RasAuto - ok
11:30:07.0717 0x12f0 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:30:07.0748 0x12f0 Rasl2tp - ok
11:30:07.0797 0x12f0 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll
11:30:07.0843 0x12f0 RasMan - ok
11:30:07.0862 0x12f0 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:30:07.0886 0x12f0 RasPppoe - ok
11:30:07.0905 0x12f0 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:30:07.0927 0x12f0 RasSstp - ok
11:30:07.0970 0x12f0 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:30:08.0008 0x12f0 rdbss - ok
11:30:08.0043 0x12f0 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:30:08.0072 0x12f0 rdpbus - ok
11:30:08.0114 0x12f0 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:30:08.0134 0x12f0 RDPCDD - ok
11:30:08.0177 0x12f0 [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
11:30:08.0228 0x12f0 RDPDR - ok
11:30:08.0248 0x12f0 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:30:08.0279 0x12f0 RDPENCDD - ok
11:30:08.0303 0x12f0 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:30:08.0322 0x12f0 RDPREFMP - ok
11:30:08.0430 0x12f0 [ 68A0387F58E226DEEE23D9715955572A, F95BB1D2BB3E79AF47B1C715BB5E3003EEF888AAA963F46F4A2FE8AFBD4F37A4 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
11:30:08.0478 0x12f0 RdpVideoMiniport - ok
11:30:08.0514 0x12f0 [ 288B06960D78428FF89E811632684E20, 82FB13C2749637E172381C9C205080921A45453191B6246C5D3FE946A06D17F5 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:30:08.0551 0x12f0 RDPWD - ok
11:30:08.0574 0x12f0 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:30:08.0586 0x12f0 rdyboost - ok
11:30:08.0628 0x12f0 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll
11:30:08.0672 0x12f0 RemoteAccess - ok
11:30:08.0703 0x12f0 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:30:08.0729 0x12f0 RemoteRegistry - ok
11:30:08.0794 0x12f0 [ 470FC46E2989F6606043C1C5365B15FD, 6EC46EE251674F22A43D6E3E0C2ECAF6A156386CD7A1C2C6821F4328F8A04826 ] RICOH SmartCard Reader C:\Windows\system32\DRIVERS\rismc32.sys
11:30:08.0827 0x12f0 RICOH SmartCard Reader - ok
11:30:08.0895 0x12f0 [ DF672613FBBCD58C38BB0BC2694BCFB0, 9B574773C7E796B7E30481F7A22D996078D5D3D295270B5BA5931A2D2F03EB4B ] rimmptsk C:\Windows\system32\DRIVERS\rimmptsk.sys
11:30:08.0918 0x12f0 rimmptsk - ok
11:30:08.0964 0x12f0 [ 9BFB54D3559F2FF7301271D29D383564, DA7F9D7432D2DD4B8FCEEB5D995E4E0A2BF6226C3A244BE4EE6BF08EF29C8687 ] rimsptsk C:\Windows\system32\DRIVERS\rimsptsk.sys
11:30:08.0993 0x12f0 rimsptsk - ok
11:30:09.0014 0x12f0 [ 470FC46E2989F6606043C1C5365B15FD, 6EC46EE251674F22A43D6E3E0C2ECAF6A156386CD7A1C2C6821F4328F8A04826 ] rismc32 C:\Windows\system32\DRIVERS\rismc32.sys
11:30:09.0027 0x12f0 rismc32 - ok
11:30:09.0105 0x12f0 [ DCB87DA83CC1010CBC9FC4DC9E395BBC, 2123B7CAD746141C69F7DFCB4C351905C32E5B433F806EDA50074B088DC886DC ] rismxdp C:\Windows\system32\DRIVERS\rixdptsk.sys
11:30:09.0146 0x12f0 rismxdp - ok
11:30:09.0174 0x12f0 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:30:09.0211 0x12f0 RpcEptMapper - ok
11:30:09.0244 0x12f0 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
11:30:09.0273 0x12f0 RpcLocator - ok
11:30:09.0349 0x12f0 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll
11:30:09.0402 0x12f0 RpcSs - ok
11:30:09.0446 0x12f0 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:30:09.0469 0x12f0 rspndr - ok
11:30:09.0512 0x12f0 [ 9BB0009C4822BF6AF4C903EEA1332E2E, DC4D7736463BBF4349CF0E873C84DC4BE2D4D86AF0FE650901F5D1E583DB6D18 ] RsvLock C:\Windows\system32\drivers\RsvLock.sys
11:30:09.0522 0x12f0 RsvLock - ok
11:30:09.0571 0x12f0 [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap C:\Windows\system32\drivers\vms3cap.sys
11:30:09.0613 0x12f0 s3cap - ok
11:30:09.0684 0x12f0 [ C9E02C8CDEA1230729EE0E0F683428C3, EAA630742B0FF68F41BB6726C596C3785652DE618400622B6FDFE77663CAF6C6 ] SafeBoot C:\Windows\system32\drivers\SafeBoot.sys
11:30:09.0685 0x12f0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\SafeBoot.sys. md5: C9E02C8CDEA1230729EE0E0F683428C3, sha256: EAA630742B0FF68F41BB6726C596C3785652DE618400622B6FDFE77663CAF6C6
11:30:09.0686 0x12f0 SafeBoot - detected LockedFile.Multi.Generic ( 1 )
11:30:12.0486 0x12f0 Detect skipped due to KSN trusted
11:30:12.0486 0x12f0 SafeBoot - ok
11:30:12.0546 0x12f0 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] SamSs C:\Windows\system32\lsass.exe
11:30:12.0579 0x12f0 SamSs - ok
11:30:12.0627 0x12f0 [ 227D5EA7301B6286B18660D83AE066A9, 245AE7F75FE94CAC973EBC2747AB434D09AFAF0DFA3A6402461CA2FCE0D18B45 ] SbAlg C:\Windows\system32\drivers\SbAlg.sys
11:30:12.0646 0x12f0 SbAlg - ok
11:30:12.0678 0x12f0 [ 3BE51C4A8F7489B6758033DEBD2BCE6E, 81D6CAA3E70C6AE6186E475F14FAB8703BCB7F22100AA92D7DF14D7CD624D75E ] SbFsLock C:\Windows\system32\drivers\SbFsLock.sys
11:30:12.0694 0x12f0 SbFsLock - ok
11:30:12.0746 0x12f0 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:30:12.0761 0x12f0 sbp2port - ok
11:30:12.0810 0x12f0 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:30:12.0848 0x12f0 SCardSvr - ok
11:30:12.0860 0x12f0 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:30:12.0881 0x12f0 scfilter - ok
11:30:12.0936 0x12f0 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll
11:30:12.0978 0x12f0 Schedule - ok
11:30:12.0992 0x12f0 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll
11:30:13.0013 0x12f0 SCPolicySvc - ok
11:30:13.0063 0x12f0 [ 0328BE1C7F1CBA23848179F8762E391C, EA80853F04BAE6F46F658B3EFED34BFDDE20E6F2BDA349EBC17EC75DFF19855D ] sdbus C:\Windows\system32\drivers\sdbus.sys
11:30:13.0093 0x12f0 sdbus - ok
11:30:13.0124 0x12f0 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:30:13.0161 0x12f0 SDRSVC - ok
11:30:13.0194 0x12f0 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:30:13.0216 0x12f0 secdrv - ok
11:30:13.0250 0x12f0 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
11:30:13.0273 0x12f0 seclogon - ok
11:30:13.0285 0x12f0 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\system32\sens.dll
11:30:13.0315 0x12f0 SENS - ok
11:30:13.0344 0x12f0 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:30:13.0364 0x12f0 SensrSvc - ok
11:30:13.0383 0x12f0 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:30:13.0393 0x12f0 Serenum - ok
11:30:13.0407 0x12f0 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:30:13.0420 0x12f0 Serial - ok
11:30:13.0438 0x12f0 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:30:13.0468 0x12f0 sermouse - ok
11:30:13.0504 0x12f0 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll
11:30:13.0566 0x12f0 SessionEnv - ok
11:30:13.0611 0x12f0 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:30:13.0646 0x12f0 sffdisk - ok
11:30:13.0663 0x12f0 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:30:13.0674 0x12f0 sffp_mmc - ok
11:30:13.0678 0x12f0 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:30:13.0690 0x12f0 sffp_sd - ok
11:30:13.0721 0x12f0 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:30:13.0732 0x12f0 sfloppy - ok
11:30:13.0778 0x12f0 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:30:13.0809 0x12f0 SharedAccess - ok
11:30:13.0838 0x12f0 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:30:13.0869 0x12f0 ShellHWDetection - ok
11:30:13.0890 0x12f0 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys
11:30:13.0898 0x12f0 sisagp - ok
11:30:13.0931 0x12f0 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:30:13.0940 0x12f0 SiSRaid2 - ok
11:30:13.0945 0x12f0 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:30:13.0954 0x12f0 SiSRaid4 - ok
11:30:13.0982 0x12f0 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:30:14.0007 0x12f0 Smb - ok
11:30:14.0040 0x12f0 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:30:14.0052 0x12f0 SNMPTRAP - ok
11:30:14.0200 0x12f0 [ 44EDD50D218EF1CF76FBF9B9FC58F79D, 07780E3D1345C917798499DB2887FA0F4905E0987AF801619F95D396F07A9EDA ] SNP2UVC C:\Windows\system32\DRIVERS\snp2uvc.sys
11:30:14.0253 0x12f0 SNP2UVC - ok
11:30:14.0309 0x12f0 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
11:30:14.0317 0x12f0 spldr - ok
11:30:14.0368 0x12f0 [ 866A43013535DC8587C258E43579C764, B2BE846B5167A2ECD1E30C69A81385FCC6EAE6033394D08458A5583D311C4D82 ] Spooler C:\Windows\System32\spoolsv.exe
11:30:14.0415 0x12f0 Spooler - ok
11:30:14.0626 0x12f0 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe
11:30:14.0910 0x12f0 sppsvc - ok
11:30:14.0939 0x12f0 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:30:14.0962 0x12f0 sppuinotify - ok
11:30:14.0998 0x12f0 [ 112127C3B2E64D7680CC39CD0A39DD7E, ABE8B868CFE0EF4DAF886517047DBFD5A9C964983FAA499AC086CCD45BA46366 ] srv C:\Windows\system32\DRIVERS\srv.sys
11:30:15.0027 0x12f0 srv - ok
11:30:15.0043 0x12f0 [ E5DD784A4EE5EBC72A86C677C988FCDB, 5D54C9AF291F8047DD66C31671F279A5D7EE8BCB5E55640F5F976E16211F59DD ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:30:15.0071 0x12f0 srv2 - ok
11:30:15.0100 0x12f0 [ CDBE627E16CC9E98F343D73F8E81D258, 25A68A6F943FCBA79A0D97ABC5B2EAEEB65C268F1CB2DD445ABF7E2758DF2802 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:30:15.0123 0x12f0 srvnet - ok
11:30:15.0171 0x12f0 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:30:15.0220 0x12f0 SSDPSRV - ok
11:30:15.0226 0x12f0 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:30:15.0250 0x12f0 SstpSvc - ok
11:30:15.0273 0x12f0 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:30:15.0281 0x12f0 stexstor - ok
11:30:15.0366 0x12f0 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll
11:30:15.0406 0x12f0 StiSvc - ok
11:30:15.0438 0x12f0 [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt C:\Windows\system32\drivers\vmstorfl.sys
11:30:15.0447 0x12f0 storflt - ok
11:30:15.0495 0x12f0 [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc C:\Windows\system32\drivers\storvsc.sys
11:30:15.0519 0x12f0 storvsc - ok
11:30:15.0547 0x12f0 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\drivers\swenum.sys
11:30:15.0569 0x12f0 swenum - ok
11:30:15.0626 0x12f0 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
11:30:15.0665 0x12f0 swprv - ok
11:30:15.0702 0x12f0 Synth3dVsc - ok
11:30:15.0854 0x12f0 [ 0E8676FB3BB95AA40FDF7A4A31018C8B, C14931CB26830E2A720C4DA5C16E2CBF1BDDDBD253257491F0D84EF5C94437E4 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys
11:30:15.0892 0x12f0 SynTP - ok
11:30:15.0962 0x12f0 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll
11:30:16.0009 0x12f0 SysMain - ok
11:30:16.0034 0x12f0 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
11:30:16.0080 0x12f0 TabletInputService - ok
11:30:16.0108 0x12f0 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll
11:30:16.0136 0x12f0 TapiSrv - ok
11:30:16.0170 0x12f0 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
11:30:16.0195 0x12f0 TBS - ok
11:30:16.0271 0x12f0 [ 37E8FA3779668837CA9E2C36D2415949, FDDA99B7501CDBC3032AA12FD8E929F5E3B47DA112D0F8A05E2D833E5609EDEA ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:30:16.0311 0x12f0 Tcpip - ok
11:30:16.0368 0x12f0 [ 37E8FA3779668837CA9E2C36D2415949, FDDA99B7501CDBC3032AA12FD8E929F5E3B47DA112D0F8A05E2D833E5609EDEA ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:30:16.0403 0x12f0 TCPIP6 - ok
11:30:16.0444 0x12f0 [ CCA24162E055C3714CE5A88B100C64ED, 9B7712E793B9478BA7A1EF71EA9CC03CCB9C4004C54EAA911F158958519EDCD9 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:30:16.0485 0x12f0 tcpipreg - ok
11:30:16.0511 0x12f0 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:30:16.0539 0x12f0 TDPIPE - ok
11:30:16.0564 0x12f0 [ 2C10395BAA4847F83042813C515CC289, CBC058AE2EB6AA5905F9D2EF52573E1C06330462952E6D6E7083F8DB2C441E3E ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:30:16.0585 0x12f0 TDTCP - ok
11:30:16.0611 0x12f0 [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:30:16.0633 0x12f0 tdx - ok
11:30:16.0663 0x12f0 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:30:16.0672 0x12f0 TermDD - ok
11:30:16.0749 0x12f0 [ 382C804C92811BE57829D8E550A900E2, 5F52C2E7902024CF1C9CC0069F411C3F19CCA3DB209F437FA0F3932D4898EB50 ] TermService C:\Windows\System32\termsrv.dll
11:30:16.0793 0x12f0 TermService - ok
11:30:16.0829 0x12f0 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll
11:30:16.0871 0x12f0 Themes - ok
11:30:16.0887 0x12f0 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
11:30:16.0914 0x12f0 THREADORDER - ok
11:30:16.0953 0x12f0 [ 5AD05191DC8B444A7BA4D79B76C42A30, 6166E939A5A240388EBA5AF7FF335DC413F2BBCF74C2E1D310F4BE2A5454A610 ] TPM C:\Windows\system32\drivers\tpm.sys
11:30:16.0964 0x12f0 TPM - ok
11:30:17.0009 0x12f0 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
11:30:17.0035 0x12f0 TrkWks - ok
11:30:17.0106 0x12f0 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:30:17.0132 0x12f0 TrustedInstaller - ok
11:30:17.0148 0x12f0 [ 254BB140EEE3C59D6114C1A86B636877, EE09D62E90407A40278F2136F640DAB16A4E2BF57D4FB6E05F92CA9CC9CF57C0 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:30:17.0285 0x12f0 tssecsrv - ok
11:30:17.0328 0x12f0 [ FD1D6C73E6333BE727CBCC6054247654, 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:30:17.0362 0x12f0 TsUsbFlt - ok
11:30:17.0366 0x12f0 tsusbhub - ok
11:30:17.0438 0x12f0 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:30:17.0471 0x12f0 tunnel - ok
11:30:17.0504 0x12f0 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:30:17.0513 0x12f0 uagp35 - ok
11:30:17.0542 0x12f0 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:30:17.0569 0x12f0 udfs - ok
11:30:17.0604 0x12f0 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:30:17.0617 0x12f0 UI0Detect - ok
11:30:17.0676 0x12f0 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:30:17.0703 0x12f0 uliagpkx - ok
11:30:17.0762 0x12f0 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\drivers\umbus.sys
11:30:17.0796 0x12f0 umbus - ok
11:30:17.0813 0x12f0 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:30:17.0828 0x12f0 UmPass - ok
11:30:17.0873 0x12f0 [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService C:\Windows\System32\umrdp.dll
11:30:17.0903 0x12f0 UmRdpService - ok
11:30:18.0087 0x12f0 [ C0AD6D5023060BB22CAC042A50B989D7, 828BF49AFF6DBD177E803C448C3C4B050D4BE1399E150830EB22C4EA2A641F5D ] UNS C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe
11:30:18.0141 0x12f0 UNS - ok
11:30:18.0203 0x12f0 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
11:30:18.0254 0x12f0 upnphost - ok
11:30:18.0308 0x12f0 [ 7E72E7D7E0757D59481D530FD2B0BFAE, 288CAC9F4AC09DEB2B30C6E3A6ACF8D62A75576F62F0EC159D5E1B257419E9DC ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
11:30:18.0339 0x12f0 usbccgp - ok
11:30:18.0379 0x12f0 [ 04EC7CEC62EC3B6D9354EEE93327FC82, 6CB41D8644618A5F701F6CA91FB65BB94AA83EA48992133B5262DC539B334B2E ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:30:18.0393 0x12f0 usbcir - ok
11:30:18.0406 0x12f0 [ CFBCE999C057D78979A181C9C60F208E, D60698EAA8A085214D5945818B0863976CF116EBE523046C344AF4E9392FDF80 ] usbehci C:\Windows\system32\drivers\usbehci.sys
11:30:18.0428 0x12f0 usbehci - ok
11:30:18.0481 0x12f0 [ 9D22AAD9AC6A07C691A1113E5F860868, AC34D36DBB5649650FCD873A792CA1387AE841D4C46781C63C0D29834F9B58E9 ] usbhub C:\Windows\system32\drivers\usbhub.sys
11:30:18.0516 0x12f0 usbhub - ok
11:30:18.0529 0x12f0 [ A6FB7957EA7AFB1165991E54CE934B74, 1CE83D9E3276AE380F720C7700A17D58A37A2A77FD72DA69EE0C756B88DB3689 ] usbohci C:\Windows\system32\drivers\usbohci.sys
11:30:18.0554 0x12f0 usbohci - ok
11:30:18.0589 0x12f0 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:30:18.0601 0x12f0 usbprint - ok
11:30:18.0654 0x12f0 [ BF63EBFC6979FEFB2BC03DF7989A0C1A, AFEF764A3E5D52CDBB5074F0E87F2B5EBCDF8D9B6E8F88EE235602B80145BE31 ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
11:30:18.0675 0x12f0 USBSTOR - ok
11:30:18.0688 0x12f0 [ 78780C3EBCE17405B1CCD07A3A8A7D72, FBFF3111E22EE0B4BCAFA81F89AAE985135BFF48EEFD130C09B49CCF8A9946B9 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
11:30:18.0698 0x12f0 usbuhci - ok
11:30:18.0715 0x12f0 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2, F9B72DE82078FDB5551D48988190F46EECA9B99655C591B7865FEA1AFB31F637 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys
11:30:18.0731 0x12f0 usbvideo - ok
11:30:18.0759 0x12f0 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
11:30:18.0781 0x12f0 UxSms - ok
11:30:18.0790 0x12f0 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] VaultSvc C:\Windows\system32\lsass.exe
11:30:18.0801 0x12f0 VaultSvc - ok
11:30:18.0827 0x12f0 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:30:18.0836 0x12f0 vdrvroot - ok
11:30:18.0896 0x12f0 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe
11:30:18.0954 0x12f0 vds - ok
11:30:18.0995 0x12f0 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:30:19.0008 0x12f0 vga - ok
11:30:19.0025 0x12f0 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
11:30:19.0049 0x12f0 VgaSave - ok
11:30:19.0063 0x12f0 VGPU - ok
11:30:19.0124 0x12f0 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:30:19.0152 0x12f0 vhdmp - ok
11:30:19.0193 0x12f0 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys
11:30:19.0202 0x12f0 viaagp - ok
11:30:19.0235 0x12f0 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
11:30:19.0271 0x12f0 ViaC7 - ok
11:30:19.0319 0x12f0 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys
11:30:19.0327 0x12f0 viaide - ok
11:30:19.0386 0x12f0 [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus C:\Windows\system32\drivers\vmbus.sys
11:30:19.0424 0x12f0 vmbus - ok
11:30:19.0448 0x12f0 [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
11:30:19.0463 0x12f0 VMBusHID - ok
11:30:19.0478 0x12f0 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:30:19.0487 0x12f0 volmgr - ok
11:30:19.0526 0x12f0 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:30:19.0541 0x12f0 volmgrx - ok
11:30:19.0573 0x12f0 [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:30:19.0587 0x12f0 volsnap - ok
11:30:19.0627 0x12f0 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:30:19.0639 0x12f0 vsmraid - ok
11:30:19.0732 0x12f0 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe
11:30:19.0787 0x12f0 VSS - ok
11:30:19.0815 0x12f0 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
11:30:19.0826 0x12f0 vwifibus - ok
11:30:19.0853 0x12f0 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
11:30:19.0884 0x12f0 W32Time - ok
11:30:19.0903 0x12f0 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:30:19.0927 0x12f0 WacomPen - ok
11:30:19.0982 0x12f0 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:30:20.0025 0x12f0 WANARP - ok
11:30:20.0029 0x12f0 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:30:20.0050 0x12f0 Wanarpv6 - ok
11:30:20.0116 0x12f0 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe
11:30:20.0179 0x12f0 wbengine - ok
11:30:20.0204 0x12f0 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:30:20.0222 0x12f0 WbioSrvc - ok
11:30:20.0286 0x12f0 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:30:20.0319 0x12f0 wcncsvc - ok
11:30:20.0348 0x12f0 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:30:20.0367 0x12f0 WcsPlugInService - ok
11:30:20.0394 0x12f0 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:30:20.0402 0x12f0 Wd - ok
11:30:20.0448 0x12f0 [ 9950E3D0F08141C7E89E64456AE7DC73, DE4B96812B305A63F5874BBF2DC40354FB45B3D96C1D33436E677099760BA448 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:30:20.0484 0x12f0 Wdf01000 - ok
11:30:20.0498 0x12f0 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:30:20.0533 0x12f0 WdiServiceHost - ok
11:30:20.0538 0x12f0 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:30:20.0552 0x12f0 WdiSystemHost - ok
11:30:20.0612 0x12f0 [ A9D880F97530D5B8FEE278923349929D, 6A293E2DB9B7C434EA8B4CD4861E11905D46BD60E014AE27B74DC8C4B2DDF834 ] WebClient C:\Windows\System32\webclnt.dll
11:30:20.0655 0x12f0 WebClient - ok
11:30:20.0697 0x12f0 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:30:20.0725 0x12f0 Wecsvc - ok
11:30:20.0735 0x12f0 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:30:20.0758 0x12f0 wercplsupport - ok
11:30:20.0785 0x12f0 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
11:30:20.0809 0x12f0 WerSvc - ok
11:30:20.0850 0x12f0 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:30:20.0871 0x12f0 WfpLwf - ok
11:30:20.0891 0x12f0 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:30:20.0899 0x12f0 WIMMount - ok
11:30:21.0009 0x12f0 [ 3FAE8F94296001C32EAB62CD7D82E0FD, 180FAECC426CF8F46700C855022E5865D528B1A20686F96D11080AB2FE2E0430 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
11:30:21.0040 0x12f0 WinDefend - ok
11:30:21.0046 0x12f0 WinHttpAutoProxySvc - ok
11:30:21.0099 0x12f0 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:30:21.0142 0x12f0 Winmgmt - ok
11:30:21.0254 0x12f0 [ 1B91CD34EA3A90AB6A4EF0550174F4CC, 5B6618615EBFBA594C945AD35F5C68DA8C6053892B6D12D626BB6120910D80DC ] WinRM C:\Windows\system32\WsmSvc.dll
11:30:21.0311 0x12f0 WinRM - ok
11:30:21.0401 0x12f0 [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:30:21.0431 0x12f0 WinUsb - ok
11:30:21.0548 0x12f0 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
11:30:21.0586 0x12f0 Wlansvc - ok
11:30:21.0649 0x12f0 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:30:21.0679 0x12f0 WmiAcpi - ok
11:30:21.0724 0x12f0 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:30:21.0759 0x12f0 wmiApSrv - ok
11:30:21.0884 0x12f0 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
11:30:21.0937 0x12f0 WMPNetworkSvc - ok
11:30:21.0980 0x12f0 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:30:22.0018 0x12f0 WPCSvc - ok
11:30:22.0066 0x12f0 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:30:22.0114 0x12f0 WPDBusEnum - ok
11:30:22.0151 0x12f0 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:30:22.0198 0x12f0 ws2ifsl - ok
11:30:22.0334 0x12f0 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\system32\wscsvc.dll
11:30:22.0453 0x12f0 wscsvc - ok
11:30:22.0458 0x12f0 WSearch - ok
11:30:22.0599 0x12f0 [ D9B0134913E5EF007AF82A418C503322, 7418DD28C8E968674382F8352AAFFC4DE77887E2B71B8844D615F19432B4C55A ] wuauserv C:\Windows\system32\wuaueng.dll
11:30:22.0660 0x12f0 wuauserv - ok
11:30:22.0721 0x12f0 [ E714A1C0354636837E20CCBF00888EE7, 0E31F0DB0AA318E3B0DACD26C0D3B11519B42F2A996AE580BE67FA8B3C42C436 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:30:22.0760 0x12f0 WudfPf - ok
11:30:22.0839 0x12f0 [ 1023EE888C9B47178C5293ED5336AB69, 62221C80C3F719A585266247482A64F7CB2F5EF69AFA8FA07D563CA2B0A37561 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:30:22.0888 0x12f0 WUDFRd - ok
11:30:22.0937 0x12f0 [ 8D1E1E529A2C9E9B6A85B55A345F7629, 64B637CFE2AF58A4F7CE6D8C3D603F8EFD527500F7137E0A37840313C712CA93 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:30:22.0983 0x12f0 wudfsvc - ok
11:30:23.0038 0x12f0 [ FF2D745B560F7C71B31F30F4D49F73D2, B2FBF7E5F58E34AC64FE6CF65800F1F07939279203BDE89375FAC92B884A4F37 ] WwanSvc C:\Windows\System32\wwansvc.dll
11:30:23.0071 0x12f0 WwanSvc - ok
11:30:23.0077 0x12f0 ================ Scan global ===============================
11:30:23.0117 0x12f0 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
11:30:23.0148 0x12f0 [ A9F564F254E9DDDE120A7135767EC24B, F255DCB4C7F4F941BA27700D66684AD0BA3DF114D6F298E2A909095B71B11D94 ] C:\Windows\system32\winsrv.dll
11:30:23.0180 0x12f0 [ A9F564F254E9DDDE120A7135767EC24B, F255DCB4C7F4F941BA27700D66684AD0BA3DF114D6F298E2A909095B71B11D94 ] C:\Windows\system32\winsrv.dll
11:30:23.0226 0x12f0 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
11:30:23.0278 0x12f0 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
11:30:23.0293 0x12f0 [ Global ] - ok
11:30:23.0294 0x12f0 ================ Scan MBR ==================================
11:30:23.0304 0x12f0 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:30:24.0015 0x12f0 \Device\Harddisk0\DR0 - ok
11:30:24.0016 0x12f0 ================ Scan VBR ==================================
11:30:24.0028 0x12f0 [ 2BDECE77356BE1042B7A1C3CABA1BF4C ] \Device\Harddisk0\DR0\Partition1
11:30:24.0031 0x12f0 \Device\Harddisk0\DR0\Partition1 - ok
11:30:24.0048 0x12f0 [ DAF1B783CB95A487C64C2343E7912E29 ] \Device\Harddisk0\DR0\Partition2
11:30:24.0051 0x12f0 \Device\Harddisk0\DR0\Partition2 - ok
11:30:24.0100 0x12f0 [ E057F3716B9AC4682967BF9BAE696634 ] \Device\Harddisk0\DR0\Partition3
11:30:24.0102 0x12f0 \Device\Harddisk0\DR0\Partition3 - ok
11:30:24.0103 0x12f0 ================ Scan generic autorun ======================
11:30:24.0193 0x12f0 [ 20DE1CDD37A5D3D4177B8D9FEF907D81, F6CE80984852595A677C92B8C555F9B0D398BAE36768E0D6FC7F8C7211D962D2 ] c:\Program Files\Microsoft Security Client\msseces.exe
11:30:24.0221 0x12f0 MSC - ok
11:30:24.0253 0x12f0 [ 7BD82C5AD184D7AE88CB4DA3EE97DE03, 132A1C3061E5DDEE2E2E46EC345F236F978983CDF728D018C39A0BCBD0BB7C78 ] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
11:30:24.0262 0x12f0 IAAnotif - ok
11:30:24.0337 0x12f0 [ 71FC40DF690F7BF9F657616DEE9B3635, 0718AB8D42E0397CCD6BC612E26EC6AF01F84C6C6C081D429835C216CBBF7E29 ] C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe
11:30:24.0351 0x12f0 picon - ok
11:30:24.0573 0x12f0 [ 20CB286C4591EEA68778CA6626D70D47, 3F8FC588B23128754CCACC2C83BF3265FB81605AED3A613DA34261806CFAEA03 ] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
11:30:24.0615 0x12f0 SynTPEnh - ok
11:30:24.0741 0x12f0 [ FE7CE849DB8C3986B2E721C6A3184FAA, 9879821AF51D13DB22EE2A8B351C5C8BB338408D325D9ACEC95237F3DE502069 ] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
11:30:24.0764 0x12f0 QlbCtrl.exe - ok
11:30:24.0804 0x12f0 [ 21E858BD6B6AC12C669BF94DF159981C, 4947106254C8F5CE04E86101317AD3F515FB956B00F9C4A2F77EB9DE6EE0895A ] C:\Program Files\ActivIdentity\ActivClient\acevents.exe
11:30:24.0815 0x12f0 acevents - ok
11:30:24.0817 0x12f0 Waiting for KSN requests completion. In queue: 139
11:30:25.0817 0x12f0 Waiting for KSN requests completion. In queue: 139
11:30:26.0817 0x12f0 Waiting for KSN requests completion. In queue: 139
11:30:27.0846 0x12f0 AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.8.204.0 ), 0x60000 ( disabled : updated )
11:30:28.0001 0x12f0 Win FW state via NFP2: enabled ( trusted )
11:30:30.0699 0x12f0 ============================================================
11:30:30.0699 0x12f0 Scan finished
11:30:30.0699 0x12f0 ============================================================
11:30:30.0720 0x17c8 Detected object count: 1
11:30:30.0720 0x17c8 Actual detected object count: 1
11:31:09.0683 0x17c8 HPFSService ( UnsignedFile.Multi.Generic ) - skipped by user
11:31:09.0683 0x17c8 HPFSService ( UnsignedFile.Multi.Generic ) - User select action: Skip Code:
Emsisoft Emergency Kit - Version 10.0
Letztes Update: 06.09.2015 04:04:33
Benutzerkonto: AS-PC\AS
Scan-Einstellungen:
Scan-Methode: Eigener Scan
Objekte: Rootkits, Speicher, Traces, C:\, E:\
PUPs-Erkennung: An
Archiv-Scan: An
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: An
Scan-Beginn: 06.09.2015 04:05:05
Value: HKEY_USERS\S-1-5-21-158092205-2151267107-1323972103-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR Gefunden: Setting.DisableTaskMgr (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Gefunden: Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-158092205-2151267107-1323972103-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Gefunden: Setting.DisableRegistryTools (A)
Gescannt: 150923
Gefunden 3
Scan-Ende: 06.09.2015 04:58:13
Scan-Zeit: 0:53:08
Value: HKEY_USERS\S-1-5-21-158092205-2151267107-1323972103-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Quarantäne Setting.DisableRegistryTools (A)
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Quarantäne Setting.DisableRegistryTools (A)
Value: HKEY_USERS\S-1-5-21-158092205-2151267107-1323972103-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLETASKMGR Quarantäne Setting.DisableTaskMgr (A)
Quarantäne 3 |