nekropolit | 25.02.2017 11:34 | Habe alle logs aufbewahrt und stelle die dann hier rein. Brauche ne pause von rechnern. Danke für die weitere Hilfestellung!
Edit:
Einen schönen guten Morgen. Folgend das letzte mbar - log.
Aktuell sind sämtliche ungewöhnlichen Effekte nicht aufgetaucht. Code:
Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
Database version:
main: v2017.02.24.04
rootkit: v2017.02.15.01
Windows 10 x64 NTFS (Safe Mode/Networking)
Internet Explorer 11.576.14393.0
Martin Zenker :: MZ_YOGA_1 [administrator]
24.02.2017 10:37:34
mbar-log-2017-02-24 (10-37-34).txt
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 775171
Time elapsed: 23 minute(s), 20 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 1
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IPHLPSVC\PARAMETERS\PROXYMGR\{A19842D9-66F2-4325-874C-FAE83313D956}|AutoConfigUrl (Hijack.AutoConfigURL.PrxySvrRST) -> Data: hxxp://nonestops.net/wpad.dat?89e382b56eda289e10ebbc854016a45018971410 -> Delete on reboot. [556f55517038fc3ae293d06d4eb21fe1]
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
Physical Sectors Detected: 0
(No malicious items detected)
(end) ich verfahre nun weiter mit Kaspersky Code:
10:31:27.0858 0x2fb8 PMBDeviceInfoProvider - ok
10:31:27.0874 0x2fb8 [ 56D7A89423325121C4A9BD5C326414F3, 649048C23D1973C3504E26B35362AC99DFE9BF31FFE73F45B43306A212AEA34C ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
10:31:27.0874 0x2fb8 PNRPAutoReg - ok
10:31:27.0890 0x2fb8 [ 4578ECA1FCEF4E7C787D84F78625143B, F5FE84D6D7412A4C037772593C434253D590E476B0B7498987A1697BED86A510 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
10:31:27.0905 0x2fb8 PNRPsvc - ok
10:31:27.0921 0x2fb8 [ F70CAC34B455D05EAA04B2F8FB58E1CB, 295BFFB3DA03C5CE5462C11D3240024B68AC06E8DEA9062A739BE2CCEE19EB5D ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll
10:31:27.0943 0x2fb8 PolicyAgent - ok
10:31:27.0943 0x2fb8 [ 60C8376B48BA96F07AEA536527433D44, EB988C119C3E71169B91ED2A744C71933DD35447DC4A8249E80EC24E9E7077D4 ] Power C:\WINDOWS\system32\umpo.dll
10:31:27.0974 0x2fb8 Power - ok
10:31:27.0974 0x2fb8 [ 5645B9D9788CCA2C88B9534996ED2D6D, 4988942DF163DB5B9B1A08CE6B628D2C47C2E2EAA30AEAE4EFE21C8CF4C8DC5D ] PptpMiniport C:\WINDOWS\System32\drivers\raspptp.sys
10:31:27.0990 0x2fb8 PptpMiniport - ok
10:31:28.0059 0x2fb8 [ 7196D3C2E2E3129814C8DAB91F9A7D1E, 6763E4BF8E846B597E78778E520F5BADC95608BAA4EA0AC84971384B5D976DD7 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
10:31:28.0159 0x2fb8 PrintNotify - ok
10:31:28.0175 0x2fb8 [ 372913E12677A8CBBBABDD8311894F9D, A5233D95A0D22D2A9DB214E7CB79A99D389B67189FF6A87D0AD4610A333A637F ] Processor C:\WINDOWS\System32\drivers\processr.sys
10:31:28.0191 0x2fb8 Processor - ok
10:31:28.0206 0x2fb8 [ 1F115AF75EFBAC28479B4F94A3F8D4A3, BE8D8C50D985F6AF9DDC0F13BDBE2D55D600E1F5E344982536538B14EC484AA6 ] ProfSvc C:\WINDOWS\system32\profsvc.dll
10:31:28.0222 0x2fb8 ProfSvc - ok
10:31:28.0222 0x2fb8 [ 577C79B8F5C6A6925F6EF0AE1B0D4051, B9C1F62310B26C1009A55261667CA04349B1A89F96AD1DCFFE8348289668E579 ] prwntdrv C:\WINDOWS\system32\prwntdrv.sys
10:31:28.0242 0x2fb8 prwntdrv - detected UnsignedFile.Multi.Generic ( 1 )
10:31:28.0544 0x2fb8 Detect skipped due to KSN trusted
10:31:28.0544 0x2fb8 prwntdrv - ok
10:31:28.0544 0x2fb8 [ FC98407B85A31161851FDE245517574F, 2CCD706CF243934FCDA32B24CE0C385EA2E67F206E0306FA584496F583A20CD1 ] Psched C:\WINDOWS\system32\drivers\pacer.sys
10:31:28.0559 0x2fb8 Psched - ok
10:31:28.0559 0x2fb8 [ C32ECB99AD25E9A04F01C8665DF29EF8, 0489B3DEC6A33E50D8A48A8DAD3F5B923A81F7300E4A71358D90D2879BAC9AA2 ] pwdrvio C:\windows\system32\pwdrvio.sys
10:31:28.0575 0x2fb8 pwdrvio - ok
10:31:28.0575 0x2fb8 [ D619356B955EEFA642F5FF72755E8B3C, 1FD54978A77ACD6FBF1236E177ED074894743A9141E4169FE9AFE28680FC93C5 ] pwdspio C:\windows\system32\pwdspio.sys
10:31:28.0591 0x2fb8 pwdspio - ok
10:31:28.0591 0x2fb8 [ 7A68710BAC9B6809314B86C0CB1CBC4A, C02D97993D1F6FE6EFBA5B1366B3A4FE8CE1136A95F3A2DA07BA59554C163501 ] QWAVE C:\WINDOWS\system32\qwave.dll
10:31:28.0606 0x2fb8 QWAVE - ok
10:31:28.0622 0x2fb8 [ 819602BBBFDB0BD46DEA3715BF0DD452, D4007FF1E5296316B53436CA3598D6B1CF4F60AB77D5B02F3E595081EDD5D879 ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
10:31:28.0622 0x2fb8 QWAVEdrv - ok
10:31:28.0643 0x2fb8 [ CDF47037A0939F56D11F699629C276AD, A63F2A3FE80FB8084E3870E907505694B79EE1D9E56E292C01D481FEFD2534B0 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:31:28.0644 0x2fb8 RasAcd - ok
10:31:28.0644 0x2fb8 [ 28C2EA278070EE12701D0EDF8CB0EC36, F10288C1C6835840026DB30285345EF892DE989F43C948E7F4760B8895FF675F ] RasAgileVpn C:\WINDOWS\System32\drivers\AgileVpn.sys
10:31:28.0660 0x2fb8 RasAgileVpn - ok
10:31:28.0675 0x2fb8 [ 7B82197BF35CC3BE59AEF8B706AB8A16, AB0216164A548A48CD21F5F035E57E867584A96890B9887EC08F8DABDD89F990 ] RasAuto C:\WINDOWS\System32\rasauto.dll
10:31:28.0691 0x2fb8 RasAuto - ok
10:31:28.0691 0x2fb8 [ 17E565710172ED71B8531D8822E1C5D1, 0CA39ABD9E544DDAD9D9D7D1FC50444274C31E18F9BF73069051D9F62833698F ] Rasl2tp C:\WINDOWS\System32\drivers\rasl2tp.sys
10:31:28.0707 0x2fb8 Rasl2tp - ok
10:31:28.0722 0x2fb8 [ F79BFB5588B777C71734C1D1EC129D07, 9B9D70EC8978AAC19B2B94694EE1B9957C13DFDDFCBE8AA82C5F0D0EA04CDBDF ] RasMan C:\WINDOWS\System32\rasmans.dll
10:31:28.0760 0x2fb8 RasMan - ok
10:31:28.0760 0x2fb8 [ 9387DF155233D45D4E010F4F2FB52A57, CABC25DA4E512809AED0085767BDD94BF3C1DA792BFF8A009B5465D9110E7060 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:31:28.0776 0x2fb8 RasPppoe - ok
10:31:28.0776 0x2fb8 [ F0F4EEDEEBEE7A4244FAFB96A16B5712, F64717E601BD5EB674003009507B8CDD6F69F00E8670D6895EC64786166A0E8D ] RasSstp C:\WINDOWS\System32\drivers\rassstp.sys
10:31:28.0791 0x2fb8 RasSstp - ok
10:31:28.0807 0x2fb8 [ AF6963414B820B7C45578ED3300438A7, C00F60FD72608E6983D32642768AECE891DD816FADFA7B872BA88091C16B95D7 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
10:31:28.0823 0x2fb8 rdbss - ok
10:31:28.0843 0x2fb8 [ 79A415E6FA915EFC00297DAB16EC2635, 47BB49F6D756214193D38A4AB182B541AAC180381C3111FF7F9B0AD4C44D8733 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
10:31:28.0845 0x2fb8 rdpbus - ok
10:31:28.0860 0x2fb8 [ 7135785C21CA79D270D11037C43D3F19, 654A3C65CF891ED8C82A740D10CF607FC7D709185E664DE03288CEB5B25F03A6 ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
10:31:28.0860 0x2fb8 RDPDR - ok
10:31:28.0876 0x2fb8 [ 97A61A3CB2B5CB4FC32B3224EF333448, E4F2E8BCEE3639BE57BBC8A8E67FDE42C3A5158F1204684B0ECD216F4AA044A3 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
10:31:28.0892 0x2fb8 RdpVideoMiniport - ok
10:31:28.0892 0x2fb8 [ 69BB204AE07EE84ECFAB1BF13C4BD04B, 1CA832CBF4AE4821EEA2A19F9519C2D1D00406B8CCE2A86FE3B33A5F293DB218 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
10:31:28.0907 0x2fb8 rdyboost - ok
10:31:28.0940 0x2fb8 [ 940D6F5A2B0A61EE4170DF84F6C95C20, F8EE846DC8015EDFE7CB5BEEDC977EAA9C586BAC2216DE69D8ECCBDBC7408649 ] ReFSv1 C:\WINDOWS\system32\drivers\ReFSv1.sys
10:31:28.0961 0x2fb8 ReFSv1 - ok
10:31:28.0976 0x2fb8 [ 13F6B64235C60167052364BF7D99E4CA, BC12EE00775F7456FB922FBD684BF3F0CFABA5BEBB6E162C23B41DED5C20A978 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
10:31:29.0007 0x2fb8 RemoteAccess - ok
10:31:29.0007 0x2fb8 [ 3183B161B1F05333F6C325577FEF3596, D6A89B2A021377B6F371E5B9EFC36FF018822B28F0ED41F8CD2F00C5C8605707 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
10:31:29.0023 0x2fb8 RemoteRegistry - ok
10:31:29.0045 0x2fb8 [ 0660F4A14F9D2A2F59B26B1D74F1A6D0, A9443B6B7ED1ECA22AC960A2C6A2BE18C0BA58CD7BCF60E7AA617CD3662D122D ] RetailDemo C:\WINDOWS\system32\RDXService.dll
10:31:29.0076 0x2fb8 RetailDemo - ok
10:31:29.0076 0x2fb8 [ E82F3B1918C6A5FE6EB761CDF1E772AF, 0C993FCB7BFD6E01B70A1821E0DEAFA2CB241AF8C2E6D4CC120F59C1B5F6FF5F ] RFCOMM C:\WINDOWS\System32\drivers\rfcomm.sys
10:31:29.0092 0x2fb8 RFCOMM - ok
10:31:29.0107 0x2fb8 [ 5DAA644F17780FC4E3F4820A46D38FEC, 32C27FFA0A4608B164F4E709CD0D998AB73CA9713BE3E47F9DBC7B3D1B6C7453 ] RmSvc C:\WINDOWS\System32\RMapi.dll
10:31:29.0123 0x2fb8 RmSvc - ok
10:31:29.0123 0x2fb8 [ 672724C8B21B7DC56646045DE4D5B860, 79986E80A92C949C543959F1E35647A9788DAB2892AC20B6DEA5C0BBC0CEDE9E ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll
10:31:29.0146 0x2fb8 RpcEptMapper - ok
10:31:29.0146 0x2fb8 [ 109C1D609951E886D3643B15C1EDD1C2, 347D8E7C50EC7F96217C7421D9BC8A42C9DF50B94169CB58DCF857A63C33C2EA ] RpcLocator C:\WINDOWS\system32\locator.exe
10:31:29.0161 0x2fb8 RpcLocator - ok
10:31:29.0177 0x2fb8 [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] RpcSs C:\WINDOWS\system32\rpcss.dll
10:31:29.0224 0x2fb8 RpcSs - ok
10:31:29.0242 0x2fb8 [ 0F44FEA610B74258762F925C61A8D9CC, ADB1B7F55FFC02687614CA7459F22AEBA0A3156CD95FBC470648AC3DC1E4A205 ] rscp C:\Program Files\Reason\Security\Protection\rscp\bin\rscp_svc.exe
10:31:29.0246 0x2fb8 rscp - ok
10:31:29.0246 0x2fb8 [ DCAA9E6A211B0928FA9AE4BD57377EB6, 99BCF5E48D3D343156302CD290FB8F7E8DDF02426EBF13A2B50EEE727F4ABA76 ] rsEngineSvc C:\Program Files\Reason\Security\rsEngineSvc.exe
10:31:29.0261 0x2fb8 rsEngineSvc - ok
10:31:29.0261 0x2fb8 [ 5FF28F097C9699097B473F8FC7C1AA7D, 695560F1DBD85073F3D6CB1FF16F16504CA044EA62E940E463A16BBA8B86E2FA ] rspndr C:\WINDOWS\system32\drivers\rspndr.sys
10:31:29.0277 0x2fb8 rspndr - ok
10:31:29.0293 0x2fb8 [ 8EB6DCEB7473C232D8BC9A886E3183AC, D81B089443306AD9D89F59DBC5F9C2F5B6A86112B4AB59316B97EE7D8B97D2FA ] RSUSBVSTOR C:\WINDOWS\System32\Drivers\RtsUVStor.sys
10:31:29.0293 0x2fb8 RSUSBVSTOR - ok
10:31:29.0308 0x2fb8 [ 7876D414526C82EFAC5DF3FF00A680BD, EF1A26CA4212311CE9993BF851D473FCC4A1DACCCD830DCAF551583881EF00AC ] RtkBtFilter C:\WINDOWS\system32\DRIVERS\RtkBtfilter.sys
10:31:29.0340 0x2fb8 RtkBtFilter - ok
10:31:29.0409 0x2fb8 [ 301FEB2D456DE694F5B505399520488B, BC3915336E7AA0A308D485C8437CBB747B3D1647BAE23133AFC5C7BDC79E32B2 ] RtlWlanu_OldIC C:\WINDOWS\System32\drivers\rtwlanu_oldIC.sys
10:31:29.0525 0x2fb8 RtlWlanu_OldIC - ok
10:31:29.0547 0x2fb8 [ 4DBBD2B451A2C45536F14FA972DD3E83, 22B47D79452593E57640B70F3A2EAA9D448046BD1BACBFD2851366DD6FC6DCAE ] RTSUER C:\WINDOWS\system32\Drivers\RtsUer.sys
10:31:29.0547 0x2fb8 RTSUER - ok
10:31:29.0562 0x2fb8 [ 6106526CA0AB6DFE788BDB29C98B5004, B4E6BD6C79E513600DBEA4CDAAAE27D1A95A51ECD565BCC2DADF7EEB546B4962 ] RunSwUSB C:\Windows\runSW.exe
10:31:29.0562 0x2fb8 RunSwUSB - ok
10:31:29.0562 0x2fb8 [ B5DAEE69BACA64D2BB004568E22D8756, C0072CF6B438ED756435A182D55AC55F3AD356ACBD483DE06A94893D3CA8CCC5 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
10:31:29.0578 0x2fb8 s3cap - ok
10:31:29.0578 0x2fb8 [ B3A62D2AEED3DE93239252A2DFFA9728, 7CDE07B59B5BEFD4A9FB295D14AABC95A8EDA807A4F357817824723C26A5C6AD ] SaiK1705 C:\WINDOWS\system32\DRIVERS\SaiK1705.sys
10:31:29.0594 0x2fb8 SaiK1705 - ok
10:31:29.0594 0x2fb8 [ B08581EDF3290210D3366CD2D992F6C2, FF1BE97B8F37FF39B784CAB254F2460B7F7A84C45BAD5CDB06FE5C29CF293BE5 ] SaiMini C:\WINDOWS\System32\drivers\SaiMini.sys
10:31:29.0609 0x2fb8 SaiMini - ok
10:31:29.0609 0x2fb8 [ D086C2F45D328C2F63FC6B4CD79FCB66, BF3D27D95C83D2454AE62BAFE9297E08BB58EA4C7FBFBDEE075A4FFC6085735C ] SaiNtBus C:\WINDOWS\system32\drivers\SaiBus.sys
10:31:29.0609 0x2fb8 SaiNtBus - ok
10:31:29.0625 0x2fb8 [ 338F85CC164C90F46B5580D94F1E740E, B677E79F41D5027769E75488B2B91C88E9D76CA51FA85BF0E6AA66013D047E04 ] SaiU1705 C:\WINDOWS\System32\drivers\SaiU1705.sys
10:31:29.0625 0x2fb8 SaiU1705 - ok
10:31:29.0625 0x2fb8 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] SamSs C:\WINDOWS\system32\lsass.exe
10:31:29.0647 0x2fb8 SamSs - ok
10:31:29.0647 0x2fb8 SAService - ok
10:31:29.0647 0x2fb8 [ 5E73FB63E2DBC75FE0C17DEB0010CE0E, 9DAC47486262397D03BC01F7438CAB62CF33BD7B5283F5B9548C770A3D6D0ADC ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys
10:31:29.0663 0x2fb8 sbp2port - ok
10:31:29.0678 0x2fb8 [ 3CD0130FFDEAEACF0905B482F3934EA3, 1EC355B63135FD2563093EBB206741C0C4CCE0551A662F6DC86C875146A88B06 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
10:31:29.0694 0x2fb8 SCardSvr - ok
10:31:29.0694 0x2fb8 [ 5E8ECCE130A72107B6DFDBE26185A7FB, 811E2CE485BC14161FF629069BCCF53B2B8C6F8B1E1A6B3A3C86DBE4F85A5577 ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll
10:31:29.0709 0x2fb8 ScDeviceEnum - ok
10:31:29.0725 0x2fb8 [ 3D9A82B03C92D1FEC42CB171D6F57778, DC027F02F5EB5F1D10DB6F405FB0C15D4D5C922445F5F3C916624113278AF072 ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
10:31:29.0741 0x2fb8 scfilter - ok
10:31:29.0763 0x2fb8 [ D4DB6B318A0A0C74A90260725A228C0B, 57BA2EF9D880488C785C806ABF9EE753A48E589129442D72F815CD6EFFA07B22 ] Schedule C:\WINDOWS\system32\schedsvc.dll
10:31:29.0794 0x2fb8 Schedule - ok
10:31:29.0810 0x2fb8 [ 9055ADDFBA4C8B914C914CE693B55C0A, DB213AC36E14D856B81D2AFE46815402537A2ABEEA15032A9FF436F953129441 ] scmbus C:\WINDOWS\system32\drivers\scmbus.sys
10:31:29.0825 0x2fb8 scmbus - ok
10:31:29.0825 0x2fb8 [ B6F2363584E62960846F7C3F00124A4F, 252189FF9D623CF69BF415FF7C7FE74B0BBF756B632420578BFAFF6595616CF7 ] scmdisk0101 C:\WINDOWS\System32\drivers\scmdisk0101.sys
10:31:29.0845 0x2fb8 scmdisk0101 - ok
10:31:29.0847 0x2fb8 [ C1B5EE58E759C53F9939581709DC70BB, 85095ABC9459A766832373BC3839E573E9A73C967F8427D6B7CAB972551C3191 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
10:31:29.0863 0x2fb8 SCPolicySvc - ok
10:31:29.0879 0x2fb8 [ 7C3D10BEC8B0DBA00A78C78EB10B3AE2, A671C9CB97977613576D70607E106C7A29B9EA9E875C7C5AF293EE5903D7AD0A ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys
10:31:29.0879 0x2fb8 sdbus - ok
10:31:29.0894 0x2fb8 [ F3714DBAA42C15F78FFCDFE4273214EB, 2D018970B92C5F0744FAE10A2FC298F3DCEA5C2EDEB760F4F0651337B9878ABF ] SDRSVC C:\WINDOWS\System32\SDRSVC.dll
10:31:29.0910 0x2fb8 SDRSVC - ok
10:31:29.0951 0x2fb8 [ D777F1417D9BB9F66CD9D9C3B61F730F, 0CBD830EB9D2B0F1946131F20907793B2D68A3BCEEC3EA5416972149F73DC815 ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
10:31:29.0979 0x2fb8 SDScannerService - ok
10:31:29.0995 0x2fb8 [ 120DFCB71D6C502613A9E2D50E16850C, 2C294010AD1C9C380CD5221A37720544178B7358C8C8553AF44055E4CEE5DAF5 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys
10:31:29.0995 0x2fb8 sdstor - ok
10:31:30.0048 0x2fb8 [ 68D6C7F99BC73B88954D844FCCBEB2A0, F746861B103C8BE8EA234B9FCFBBDD2412C79FB65F2F1E0F5E6EBC0B34905FF1 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
10:31:30.0079 0x2fb8 SDUpdateService - ok
10:31:30.0095 0x2fb8 [ 9B9B368A8FF5CAF91D7A333CF62CD2CC, A4AE7FFBBAF983BFDE15B521ED162CBC4E6FC85BCDB200C75D45878B3FFDFA68 ] SDWSCService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
10:31:30.0095 0x2fb8 SDWSCService - ok
10:31:30.0110 0x2fb8 [ EFD644DD091E1D94555FC3BBC95EA66D, FBDDA6680BEC378CCF12A32D9186020E884DA15A1E789D1531B1E687FC7B54B1 ] seclogon C:\WINDOWS\system32\seclogon.dll
10:31:30.0126 0x2fb8 seclogon - ok
10:31:30.0126 0x2fb8 [ F48535714BED7DD784853889B4594B26, 9B4AB7E7293E79A8F6CC46C84F23E62AD3BD6E958FCE078CDBB125A69FAC7E50 ] SENS C:\WINDOWS\System32\sens.dll
10:31:30.0147 0x2fb8 SENS - ok
10:31:30.0148 0x2fb8 Sense - ok
10:31:30.0179 0x2fb8 [ 2B4E090D06C60853C5C00CF255F9E02A, 4D4DBA7B04519622612BD4A4F28318CA2F5646C84CAFF8C5ACC9BF4C6031894E ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe
10:31:30.0226 0x2fb8 SensorDataService - ok
10:31:30.0241 0x2fb8 [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] SensorsAlsDriver C:\WINDOWS\System32\drivers\WUDFRd.sys
10:31:30.0248 0x2fb8 SensorsAlsDriver - ok
10:31:30.0263 0x2fb8 [ C09A42163878A082C3F0D0A3DFE95714, 8033DC38D0EDED3758DA6BF8C1955BE5FFE48863C079C589660B37D0E461300F ] SensorService C:\WINDOWS\system32\SensorService.dll
10:31:30.0279 0x2fb8 SensorService - ok
10:31:30.0295 0x2fb8 [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] SensorsSimulatorDriver C:\WINDOWS\System32\drivers\WUDFRd.sys
10:31:30.0310 0x2fb8 SensorsSimulatorDriver - ok
10:31:30.0326 0x2fb8 [ E6F00415DADCEEC860E7AB42BFD19A65, 274CAF22F93D43B6DB6953730E3DF8DA94776B24EEE74B80AB4CD780BC1366A9 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
10:31:30.0342 0x2fb8 SensrSvc - ok
10:31:30.0348 0x2fb8 [ 401D706DDC0A7AF18C3DD228ADF74551, 27C0B38D7C2E3F6FF06201124E63483931F6071954B2B99EC0143C464238C0B7 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys
10:31:30.0348 0x2fb8 SerCx - ok
10:31:30.0364 0x2fb8 [ 7084D11083F0CDCA8B5C76F9846ABF5D, F639920882B0E784D8CFAF0D4C0F0C411937B6831E5DD99B0ABFBFE06BA4742F ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys
10:31:30.0364 0x2fb8 SerCx2 - ok
10:31:30.0379 0x2fb8 [ 3FF478A8ED32A83C36581425F6282B6C, 787646A17098EA7CF36064D0A950C1D470D4A280C8C5AC40023D566E53860EAE ] Serenum C:\WINDOWS\System32\drivers\serenum.sys
10:31:30.0379 0x2fb8 Serenum - ok
10:31:30.0395 0x2fb8 [ 92509187AA171A80521528B36F753E1D, FE0DA272B8A155ECC161E99586C4AE7EE17B1C84BC330DA1566C83B8E03FA825 ] Serial C:\WINDOWS\System32\drivers\serial.sys
10:31:30.0395 0x2fb8 Serial - ok
10:31:30.0411 0x2fb8 [ 433D38FF6D08B993847EA2A10EB8CB52, 29BA75DB6D1AC761BBDFB5AC8874FC7D763E1CD10D290E369063B34CE951270F ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys
10:31:30.0426 0x2fb8 sermouse - ok
10:31:30.0443 0x2fb8 [ 82CF273F0E8F243789683DEB40757569, 5433D93A41C4BF04494E6158931C6AC3154888F7CD3A417253EC02FF7EA6D00E ] SessionEnv C:\WINDOWS\system32\sessenv.dll
10:31:30.0464 0x2fb8 SessionEnv - ok
10:31:30.0464 0x2fb8 [ 697D3EE0740AEAB62B66ABCA1C83D13B, FCF54A0071ED04AD3FC8551C67FE5FD49089DC0510F753052CAC5972A65C9E3D ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys
10:31:30.0480 0x2fb8 sfloppy - ok
10:31:30.0495 0x2fb8 [ 832E933AA8DB9FD4733B96D8B6484D3F, 3A8E3D7ECA192EEE154CB568073B7211FDA06078EFC3BC7E961563A1BFDD0CAA ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
10:31:30.0511 0x2fb8 SharedAccess - ok
10:31:30.0527 0x2fb8 [ 482E6BE8A07832E824080D352075ACA1, 4123A76C8E805AF4FE229C53E9C174095C0937913BA81A63FE9B45C44AA5B15F ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
10:31:30.0564 0x2fb8 ShellHWDetection - ok
10:31:30.0580 0x2fb8 [ CF3BDF9EAD8D3EF671E9339B44B185BA, C17EC6D5B00F49D9C8B5B6C262A85F34ED71C58450659F006B3632AA84F68E23 ] shpamsvc C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
10:31:30.0596 0x2fb8 shpamsvc - ok
10:31:30.0596 0x2fb8 [ 7799106FEE728B907A86D9C9751E02D5, EE85E8D3CF3819DB28221BFC103DE8DF0E14E1878CECF54E8CD8C161B0E0AF3C ] silabenm C:\WINDOWS\system32\DRIVERS\silabenm.sys
10:31:30.0596 0x2fb8 silabenm - detected UnsignedFile.Multi.Generic ( 1 )
10:31:30.0927 0x2fb8 Detect skipped due to KSN trusted
10:31:30.0927 0x2fb8 silabenm - ok
10:31:30.0948 0x2fb8 [ 447209C314E6E0D26E01962075802B18, AB1AC5854EB0EDF66025609CF9CB5639014C264327F4DEE1223BF7F6E1BD2D15 ] silabser C:\WINDOWS\system32\DRIVERS\silabser.sys
10:31:30.0949 0x2fb8 silabser - detected UnsignedFile.Multi.Generic ( 1 )
10:31:31.0265 0x2fb8 Detect skipped due to KSN trusted
10:31:31.0265 0x2fb8 silabser - ok
10:31:31.0265 0x2fb8 [ A34CE1830E45DA98932295FDE4B7908A, FC553ECF4D64B4B10B7FDE5352707785517A18D487A80665BAFC7261E3F35CDC ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys
10:31:31.0280 0x2fb8 SiSRaid2 - ok
10:31:31.0280 0x2fb8 [ A7B5C670770E908DA5FEF5BF1136E933, 8D3BB6FF65E631C34BE8EA766481B2FDB2E1E916A4FD67F86705A8975A136E6C ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys
10:31:31.0296 0x2fb8 SiSRaid4 - ok
10:31:31.0311 0x2fb8 [ F3AAB7DF6408431C762D8721B68F46E4, 56ED764AA660955B8B06322703D086B3A52106625A83CCAF195B08BCBDEDA88F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
10:31:31.0327 0x2fb8 SkypeUpdate - ok
10:31:31.0327 0x2fb8 [ 8A6571231D93C08434A56E19E33A35CB, 78A12B58D129D5B2017C9A94734656B9F1ED41345DF1D01F82702D4D95C1BE3F ] SmbDrvI C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
10:31:31.0327 0x2fb8 SmbDrvI - ok
10:31:31.0344 0x2fb8 [ D233EAE2A9D48485321816486ED635EF, 03AB49BE9CF15EB7EDC50C400E673B4DF0E5BFDA9A7811E157F2AF2F3CF38D49 ] smphost C:\WINDOWS\System32\smphost.dll
10:31:31.0349 0x2fb8 smphost - ok
10:31:31.0364 0x2fb8 [ 0B217141AC1283655402CDB356577735, 6EFA4CA46CFC8B7156CE7E5CA89B7F7073E16D66C2FC13F4DB95FEB78CCF698F ] SmsRouter C:\WINDOWS\system32\SmsRouterSvc.dll
10:31:31.0396 0x2fb8 SmsRouter - ok
10:31:31.0411 0x2fb8 [ 6F4CE07D420FB657B5936F71101ABD41, CEC52984C56E578E0FFE12BE1B8148335F788B7D1751F2D0E79B944A41113C20 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
10:31:31.0411 0x2fb8 SNMPTRAP - ok
10:31:31.0427 0x2fb8 [ C994DF90427103CCB80F893FFD2B1CE8, 7E4B08095C77E68D337A3425EEA38F8FEC4D103CA7661E34FD96BF518DFB4BCB ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
10:31:31.0450 0x2fb8 spaceport - ok
10:31:31.0465 0x2fb8 [ E03264C4C25B568F92ED1656AD541E64, D42942BFFBC7213D204FAF84F4FE015FC23A6ACB29B5E752834EDBC17A3AC20D ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys
10:31:31.0465 0x2fb8 SpbCx - ok
10:31:31.0496 0x2fb8 [ 79DCE27E8C4CF6701BFE49EC2446BBF6, F51CBB7A45C3C878F41653FD5FBDC93CC302712B7725DAAB4D3475A1F4771E3D ] Spooler C:\WINDOWS\System32\spoolsv.exe
10:31:31.0528 0x2fb8 Spooler - ok
10:31:31.0628 0x2fb8 [ 23529A00195CE71252FEBF647E56E27D, 8ADF7A1C96DAE005E9A974D90BE8954F88D49B6848252B88513C49E0A3BD9774 ] sppsvc C:\WINDOWS\system32\sppsvc.exe
10:31:31.0765 0x2fb8 sppsvc - ok
10:31:31.0790 0x2fb8 [ 3FE2F3796B4C62D0155C0C91C8975C89, 7D0B6C2D4D89BB98104BD6C403AC626285A3B977DB148461C28D0913FD736BDD ] SPUVCbv C:\WINDOWS\System32\Drivers\SPUVCbv64.sys
10:31:31.0821 0x2fb8 SPUVCbv - ok
10:31:31.0821 0x2fb8 [ FAD8A14CAE92E805E48DA87B9564391A, B4BD026B6C9EE72CDE5E9215D903F16AE15893A1491ECFC346CB030C56D592A5 ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
10:31:31.0837 0x2fb8 SQLWriter - ok
10:31:31.0853 0x2fb8 [ E83830BB74AE8CBECEA0ECD94DE436F9, 4A34569A34260324EBD629039E1BF45A3527FC75B22D9A3DB6360A6EB365483A ] srv C:\WINDOWS\system32\DRIVERS\srv.sys
10:31:31.0868 0x2fb8 srv - ok
10:31:31.0890 0x2fb8 [ 55CA5329D1ADEB8F8034045930147AE4, D4F31BC82700D166564C7F9CDCEA3ABAB4A37B55137C34572768DF46FDA9320A ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys
10:31:31.0921 0x2fb8 srv2 - ok
10:31:31.0921 0x2fb8 [ F13EE0DB1FB1D6946AC3228D7EFCFC8F, 109A809F0338FAB0F4045FA5EE33C6F0A994A9F586B2FBD8920A6AABA0E0EF66 ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys
10:31:31.0937 0x2fb8 srvnet - ok
10:31:31.0953 0x2fb8 [ 44758105AB3EA34E815D4B6CA1153311, 7F223A20D2538C123BAC6F75BE0E126876A116F09502FD980C05B8916E26E1B7 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
10:31:31.0968 0x2fb8 SSDPSRV - ok
10:31:31.0988 0x2fb8 [ BE9AD856DC28955E5933553421F99DFD, F60B5429B50CFAA6D336D8384BCD16FF262ADBCD997A5CB9CD9BCC06B67C96F8 ] SshBroker C:\WINDOWS\System32\SshBroker.dll
10:31:32.0006 0x2fb8 SshBroker - ok
10:31:32.0006 0x2fb8 [ 284FB23A402836877FBCD735E0C07A7E, EA47FD98220DFA80B78D4E747602FD6D39DCAD54030EB8E478DA4EA6C9B1DC68 ] SshProxy C:\WINDOWS\System32\SshProxy.dll
10:31:32.0037 0x2fb8 SshProxy - ok
10:31:32.0037 0x2fb8 [ B97C7EC07218A8002323718202BF5E77, 39D3254383E3F49FD3E2DFF8212F4B5744D8D5E0A6BB320516C5EE525AD211EB ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll
10:31:32.0053 0x2fb8 SstpSvc - ok
10:31:32.0069 0x2fb8 [ 592FF34A2FD6C6351B8A3AA76B2C0A9E, 152B7472DE531AC45492F562DD470B2CE33F1EEF13BC78F26046AE5ABF54E32F ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
10:31:32.0069 0x2fb8 ssudmdm - ok
10:31:32.0090 0x2fb8 [ 7DB9E612A2742ACEAB080B882E83141C, FFD1FA36E732F55223F3F4B5F845331DBB3073B023C2C5BF51A0E7680DEE7FA7 ] ss_conn_service C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
10:31:32.0122 0x2fb8 ss_conn_service - ok
10:31:32.0191 0x2fb8 [ 4E330AD1EED4A5D582EE415FD55953A2, 2C02E1F45F74D250110BA5117AA942495CB2EBAC7F2CCECC284B4FB8F47B13E1 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll
10:31:32.0339 0x2fb8 StateRepository - ok
10:31:32.0351 0x2fb8 [ 29D26E1347AE1BBD4201014E19880B2C, 9E2153AD96CE4F189EEE43BB02515532C619FB1CA02D8F6DEF517AC3347AAA14 ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys
10:31:32.0359 0x2fb8 stexstor - ok
10:31:32.0368 0x2fb8 [ 91CB95B35481155BFE29C217CD237F27, CA66957DF1441D991453BEF02D768D44E5D9A484BC23C8874E8A7AC20904CB06 ] stisvc C:\WINDOWS\System32\wiaservc.dll
10:31:32.0407 0x2fb8 stisvc - ok
10:31:32.0407 0x2fb8 [ 53EB8CE34B55A1EE63424C8DB7388BFC, 5AB59117BA8A2844EB8693CCC19B217AE039B28C87519F96E1C845FE9BF456C2 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
10:31:32.0423 0x2fb8 storahci - ok
10:31:32.0423 0x2fb8 [ C5E0ACE4771F5575D9D5B457ABF3AD03, 365880BC5AC313F25C313EFB7758301F98D9B2BF4C5FC9499F98C2B7F8407D96 ] storflt C:\WINDOWS\system32\drivers\vmstorfl.sys
10:31:32.0438 0x2fb8 storflt - ok
10:31:32.0438 0x2fb8 [ B66D8C75C9BC59D637177AB3B1C569A6, 76252A631F03EEBF5FDC7693F6B0A5E73838CDBE3157114CC96B8BBE88B476BF ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys
10:31:32.0454 0x2fb8 stornvme - ok
10:31:32.0470 0x2fb8 [ BEBF85EB4D90E6996047DA027D0ED26E, DF109CF0F07CDD1B9B702C2A076D4DD5366DAAD971CC9359AF0358E79981706F ] storqosflt C:\WINDOWS\system32\drivers\storqosflt.sys
10:31:32.0470 0x2fb8 storqosflt - ok
10:31:32.0492 0x2fb8 [ B91FBE7CB4633FEB32AFBD0B48576396, 9EFDD92E8096CE5555F8DC3C870864E5515469603C2373B99B3607234633CA66 ] StorSvc C:\WINDOWS\system32\storsvc.dll
10:31:32.0507 0x2fb8 StorSvc - ok
10:31:32.0507 0x2fb8 [ 8E73037A6F8938475692FFCC26EBF385, F78C5CD1A3CD17AA831EEC82426B14006B4DDBC9085A4814E04E8C37FD6B05F7 ] storufs C:\WINDOWS\system32\drivers\storufs.sys
10:31:32.0523 0x2fb8 storufs - ok
10:31:32.0523 0x2fb8 [ 9D9DED47DA10E845EFF2DD57C94C809B, 520D0CE7A867051B80C8141E351FE5A5BCE3C99776093F234DB77D3407B1F104 ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys
10:31:32.0539 0x2fb8 storvsc - ok
10:31:32.0539 0x2fb8 [ 224C92E442B1B8C20C274332F1ACF00D, CDE5DCFB7A21089464A6E2ABB29BBE08B184C3433C218756AA5902A8F67C0B2C ] svsvc C:\WINDOWS\system32\svsvc.dll
10:31:32.0554 0x2fb8 svsvc - ok
10:31:32.0554 0x2fb8 [ 505E0C40B5D0ADDCBB414640F59BD2E0, DF4B5E65FE6FF2224F298A2A2FAC9B648C082DFF8463148633647580A9FAD34D ] swenum C:\WINDOWS\System32\drivers\swenum.sys
10:31:32.0570 0x2fb8 swenum - ok
10:31:32.0591 0x2fb8 [ 2EE27411B5904C63D723BEA391819F58, C88C11D460E90398E16011B8A2CED5EE5626084F24790EA6115532F8F70060C6 ] swprv C:\WINDOWS\System32\swprv.dll
10:31:32.0608 0x2fb8 swprv - ok
10:31:32.0623 0x2fb8 [ 7D33F42955235182C234A1D7B1AFDF4A, E73067BEE7E12A7C68F79AAEF6A2EB04C69468A6DDFC636500C2A00C60660708 ] sxuptp C:\WINDOWS\System32\drivers\sxuptp.sys
10:31:32.0639 0x2fb8 sxuptp - ok
10:31:32.0639 0x2fb8 [ 32F46FB0F290D16DAA452B289C985795, 73F88AAAA6026DB4C27F1D054145216DCC3F1960946FB2A7A90518DD1D5737CB ] Synth3dVsc C:\WINDOWS\System32\drivers\Synth3dVsc.sys
10:31:32.0654 0x2fb8 Synth3dVsc - ok
10:31:32.0670 0x2fb8 [ 7DC2B34FB6F1798F2D13453E0321D025, 60EF12A8824384DD88D9C5D188E8FB137F0F85A63C06AAF720CB2D616EB847F4 ] SynTP C:\WINDOWS\system32\DRIVERS\SynTP.sys
10:31:32.0691 0x2fb8 SynTP - ok
10:31:32.0692 0x2fb8 [ 6FBDBC24B1642868E041463795CBFA44, E9FA0DB094E7B2129ABD325BC91A48D6646380D6AA97BE6233C220E0C98637AF ] SynTPEnhService C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
10:31:32.0712 0x2fb8 SynTPEnhService - ok
10:31:32.0732 0x2fb8 [ FED48B19D6F55D7A3AB498D85729D1BA, FA5E0E02BC2E2DE108C55991E3B063CC947072228B53539F42F922661510DE7C ] SysMain C:\WINDOWS\system32\sysmain.dll
10:31:32.0779 0x2fb8 SysMain - ok
10:31:32.0793 0x2fb8 [ D9FEA79BF6AF136F8E656AE045C2FEC8, E6F08A93348E035185F0F1C6B6277E636F4F25D1136E3ACCA63488DAEEC7114B ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
10:31:32.0808 0x2fb8 SystemEventsBroker - ok
10:31:32.0824 0x2fb8 [ 86E7FD5C8DBEC1EB51C4368561402B75, 86EE61414CD5854E39E33F67BF5DA4377B569B3ED4D18882C470BC6784891DA1 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
10:31:32.0839 0x2fb8 TabletInputService - ok
10:31:32.0839 0x2fb8 [ 7F5BFF7A547AE4BBF9CB8A80F844206C, B4D7DBDDECF5C8E632B1207311BC7899A0E0CD1020A46ECB59955C6B9361CF7A ] tap0901 C:\WINDOWS\System32\drivers\tap0901.sys
10:31:32.0855 0x2fb8 tap0901 - ok
10:31:32.0855 0x2fb8 [ 3929C8FC134AC672C4F3F85160956257, CD3195CA58BA6F55EA0DDA2BE6AB58280AD1CA488D7AAA1539DD05FB99374F36 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
10:31:32.0889 0x2fb8 TapiSrv - ok
10:31:32.0924 0x2fb8 [ 4F25E481124059CC593B4C68BC485640, 2814D2BA4E83D3B0F7569E6C6EE0C763D9801BC505D8ED84675D19C8573834DB ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys
10:31:32.0993 0x2fb8 Tcpip - ok
10:31:33.0040 0x2fb8 [ 4F25E481124059CC593B4C68BC485640, 2814D2BA4E83D3B0F7569E6C6EE0C763D9801BC505D8ED84675D19C8573834DB ] Tcpip6 C:\WINDOWS\system32\drivers\tcpip.sys
10:31:33.0109 0x2fb8 Tcpip6 - ok
10:31:33.0125 0x2fb8 [ 8DBB1BE20C36E6D19BCC89EEA00B953C, 8B97A7E53E1D77363AFF6A5AAEAD89EBAE28DCB8D82753C804FD7CD5646500AF ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
10:31:33.0125 0x2fb8 tcpipreg - ok
10:31:33.0140 0x2fb8 [ 9D2DD64A0B51C56285512DC9454340F6, ABB90CE6A55269F71AFB08E04969CF9A4EFD93F7A7189AF920EEE3E005214DDD ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys
10:31:33.0156 0x2fb8 tdx - ok
10:31:33.0156 0x2fb8 [ 950AD1AE7498A492126FB9F9B2E27DB5, C4C9A972015F567FC87A4094C86835B2DD3476426AB8B40CD4872A725CA89CFC ] Te.Service C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe
10:31:33.0171 0x2fb8 Te.Service - detected UnsignedFile.Multi.Generic ( 1 )
10:31:33.0493 0x2fb8 Detect skipped due to KSN trusted
10:31:33.0493 0x2fb8 Te.Service - ok
10:31:33.0493 0x2fb8 [ 06130AFFECEB94525FC2352936576B70, 10EBE2C8FDC087D29E2FFB328F0F7905A5374AB8CC9FAE8699E7676DBC8CBF91 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
10:31:33.0509 0x2fb8 terminpt - ok
10:31:33.0524 0x2fb8 [ FB68E5F02316C42BE7282DA492351C6F, AC31D841FEA58B776127E138DB20F8D48E26FD8C00CE2FA9695EA14EBF159A0A ] TermService C:\WINDOWS\System32\termsrv.dll
10:31:33.0571 0x2fb8 TermService - ok
10:31:33.0571 0x2fb8 [ 2AF438EC0D361A7BBB70E604A686602C, 4BE6A0461EB2CB94288614434A1CEC81C2ED46241721FD5BBD8ABE0680F7C804 ] Themes C:\WINDOWS\system32\themeservice.dll
10:31:33.0593 0x2fb8 Themes - ok
10:31:33.0609 0x2fb8 [ 1482B8ED5CACA87992A882B853B83CEE, 613247F0E362A109090E8563D977DECC50C64D45D6962905FA84A2D59329045C ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe
10:31:33.0625 0x2fb8 TieringEngineService - ok
10:31:33.0640 0x2fb8 [ 3B3C607C3C62DFBEF61938DA2CAB94DF, E5EEA7F45A7BBFDF6F0003CD77E39958C451DD1B4B401876B5619A3C20F5C370 ] tiledatamodelsvc C:\WINDOWS\system32\tileobjserver.dll
10:31:33.0671 0x2fb8 tiledatamodelsvc - ok
10:31:33.0691 0x2fb8 [ C1F8CBE2D4843E0CCC3EFEA2EC60D4AB, 9D07527D982066922318C77AECE99280DE55034C375ACE145E827A6BEB5C3B70 ] TimeBrokerSvc C:\WINDOWS\System32\TimeBrokerServer.dll
10:31:33.0694 0x2fb8 TimeBrokerSvc - ok
10:31:33.0709 0x2fb8 [ 46171262D0E806779DEEDFCAB2F830CC, 7F4A4658B8BA217D99E5B5C0E01600C20DC96ECBCA32A5BA7FBE17D2A7B8BFD8 ] TPM C:\WINDOWS\System32\drivers\tpm.sys
10:31:33.0725 0x2fb8 TPM - ok
10:31:33.0725 0x2fb8 [ 3B91F35089240F6187AD681A5EC28BDE, 3D035CB73BC8E7831DCD0FB7D9DAD91CE51D3D0F9D9C8B866A0009BD508B6702 ] TrkWks C:\WINDOWS\System32\trkwks.dll
10:31:33.0741 0x2fb8 TrkWks - ok
10:31:33.0756 0x2fb8 [ 09440FA30C020B4443391FAFCF4876E3, 208C7725F70C75D8C96CCAF5B22F83B8B1C66D8C9FFF48465B1C9F4A77425569 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
10:31:33.0756 0x2fb8 TrustedInstaller - ok
10:31:33.0772 0x2fb8 [ A6F4025664C9D4BC2A9EDAB4092706D7, 89808A1679C0E716F86F06EE7701DCC289200894F0FA1F120DA2AC3A45FDB312 ] tsusbflt C:\WINDOWS\system32\drivers\TsUsbFlt.sys
10:31:33.0789 0x2fb8 tsusbflt - ok
10:31:33.0793 0x2fb8 [ 37A96AD493E110C0BF1EE0AC0F9E7DBD, F2A6894A4AEE18DF2B92222CDB0801A13AEEB7212071F0431430788339B30E23 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
10:31:33.0794 0x2fb8 TsUsbGD - ok
10:31:33.0810 0x2fb8 [ 5A91FDBA4D3FCB56DAEB8C091B3EB8E1, 8AB91F4423125267FA8509A1C3A9AD1CBD642FA6A96D8789F9AB8CB75ABAD58C ] tsusbhub C:\WINDOWS\system32\drivers\tsusbhub.sys
10:31:33.0825 0x2fb8 tsusbhub - ok
10:31:33.0825 0x2fb8 [ 79E264287F17D56D768440B0270466DE, ABF9DC95C5E939B30BFD9BF9EDFDB3BD78A9DFCB055B945965303B6A60E6D7A7 ] tunnel C:\WINDOWS\System32\drivers\tunnel.sys
10:31:33.0849 0x2fb8 tunnel - ok
10:31:33.0857 0x2fb8 [ F723552F65D44FE693DB1A383825B3A8, EF8C343C4EB5EEA4EC830378EF576CCD6CD4EEDEDD486C0F29697044E8C71F45 ] tzautoupdate C:\WINDOWS\system32\tzautoupdate.dll
10:31:33.0869 0x2fb8 tzautoupdate - ok
10:31:33.0869 0x2fb8 [ AA65954F512BA097DD190790876DD991, C1BB2B8F54F064D01190327B5E7949EBBDA21D6FC6F94D9FCD20F685C2F855FA ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys
10:31:33.0888 0x2fb8 UASPStor - ok
10:31:33.0894 0x2fb8 [ AB6268022C3A5B529075A39C33904DA6, 2717F1704640201F2681711543EA39A74C3E89C7DB232EC5DD89FD8AA6F07846 ] UcmCx0101 C:\WINDOWS\system32\Drivers\UcmCx.sys
10:31:33.0894 0x2fb8 UcmCx0101 - ok
10:31:33.0909 0x2fb8 [ 7ED2EDA43D21C7A5F589A7960E265C52, 7DB8A595236FBB8A264D7AB155201357212855050ABB5B1036EF32F1223FDCC2 ] UcmTcpciCx0101 C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys
10:31:33.0925 0x2fb8 UcmTcpciCx0101 - ok
10:31:33.0925 0x2fb8 [ 169351463039B45F5CDED9768879F712, 990C8C4AEF9ED7FF6BCEAE67F7BDAA037777B142B8D96A74F8715C941A5C63C6 ] UcmUcsi C:\WINDOWS\System32\drivers\UcmUcsi.sys
10:31:33.0941 0x2fb8 UcmUcsi - ok
10:31:33.0941 0x2fb8 [ 08A9E3AD29B215484FBB68CDC175DF3A, 3EFFF99C3BC4A1454E3D2B5177AE587ED3041AB4CE2A95BA7E28A2124E38E1E5 ] Ucx01000 C:\WINDOWS\system32\drivers\ucx01000.sys
10:31:33.0956 0x2fb8 Ucx01000 - ok
10:31:33.0956 0x2fb8 [ DA70AEE267491AA56BC63AA0C0C96CA2, 0A0AADB27607F9292BB3CE000CFDDB19BD4CA09EAAD926C4925CB43B17817AD9 ] UdeCx C:\WINDOWS\system32\drivers\udecx.sys
10:31:33.0972 0x2fb8 UdeCx - ok
10:31:33.0993 0x2fb8 [ FBC5ECF6D5A868D0B116C2DBB02B8168, 945AA76C60ABAD6075B5C8F9172C018F75BCF393A1CB8B329F5E68E664627775 ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys
10:31:34.0010 0x2fb8 udfs - ok
10:31:34.0010 0x2fb8 [ B918E40FAA9CD118CCA4AD388B748C98, 4B539B7B656F02C5E5BAEE52A677757B05CC11C5500D619850A564C28FAB8115 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys
10:31:34.0025 0x2fb8 UEFI - ok
10:31:34.0025 0x2fb8 [ 166B17AE1DD24D8BA8CA474C7C31148F, D34E786277093278F58EFAC957279DC4ED43A190538C875B80F5B1E0A0C30381 ] UevAgentDriver C:\WINDOWS\system32\drivers\UevAgentDriver.sys
10:31:34.0041 0x2fb8 UevAgentDriver - ok
10:31:34.0072 0x2fb8 [ FCA4D901FB9934DAB82ED31C4EE89A11, 8EDF8DD71C13DE77AC83D1086670E9E90C69DE379F1CF768C8B9C789254C04AA ] UevAgentService C:\WINDOWS\system32\AgentService.exe
10:31:34.0110 0x2fb8 UevAgentService - ok
10:31:34.0126 0x2fb8 [ 0FD75222C1AD2687AB365BEBEA400DD4, AD10DBCA59EB7D34FD8F963CE267F36774A9BC613F8D637903B12AC88C328E8A ] Ufx01000 C:\WINDOWS\system32\drivers\ufx01000.sys
10:31:34.0141 0x2fb8 Ufx01000 - ok
10:31:34.0141 0x2fb8 [ C1A78C53E01C641AE41BFA65797819F5, 0B9FE1BD724B3315199A1B1DA2F03255E4FE744DA3CE6CD0F77699A8E42E9359 ] UfxChipidea C:\WINDOWS\System32\drivers\UfxChipidea.sys
10:31:34.0157 0x2fb8 UfxChipidea - ok
10:31:34.0157 0x2fb8 [ 767307212110EBEFB93EC9A5BE9E85B9, 368797400FE54802CE74F34B773CE2AF09EB8DEA6C035B55419A52F0B5A6FAD0 ] ufxsynopsys C:\WINDOWS\System32\drivers\ufxsynopsys.sys
10:31:34.0172 0x2fb8 ufxsynopsys - ok
10:31:34.0172 0x2fb8 [ 8578F83EC5175920F2D8586FFF9DCE47, 049A16AC87F93E761150C8286633FFCA62EE85F5645DDE77D36BD0EB6481FF83 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
10:31:34.0195 0x2fb8 UI0Detect - ok
10:31:34.0195 0x2fb8 [ DC460AAA18CA2342FBBFB2DF9B044472, 14D45E059C596AE97506D26705F248CA1C2269160B31A60341060E8A93146CBD ] umbus C:\WINDOWS\System32\drivers\umbus.sys
10:31:34.0210 0x2fb8 umbus - ok
10:31:34.0210 0x2fb8 [ C3CF0377917ECE6D65D7623E1E61568F, 4909695E04CBC86BFCFFBC15F332C367521054B7B4D3C141C7CA6B2E40E090B9 ] UmPass C:\WINDOWS\System32\drivers\umpass.sys
10:31:34.0226 0x2fb8 UmPass - ok
10:31:34.0241 0x2fb8 [ 640CF093C1CF16D5FD317616CA348F31, BEC34D1AACA83BF5A84CE01F6A668E3CA5A33C56A446DC42EFFF7C43D22E1AE6 ] UmRdpService C:\WINDOWS\System32\umrdp.dll
10:31:34.0257 0x2fb8 UmRdpService - ok
10:31:34.0293 0x2fb8 [ B8272BB8D4982C496FDC704809C38E02, F93855D932FB1DBBCC86E82C0FE0DC9ECF93BBD629D2CA9D0BE7E075E114B7FF ] UnistoreSvc C:\WINDOWS\System32\unistore.dll
10:31:34.0326 0x2fb8 UnistoreSvc - ok
10:31:34.0357 0x2fb8 [ DBE2E6388379D5CC78099650541E9566, 1914BC929F109A49FB18ED31F239A9813A010B0A3914BC8CD0D6A94A67A072D7 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
10:31:34.0357 0x2fb8 UNS - ok
10:31:34.0391 0x2fb8 [ 6CDA3536F6BAB7896A57EAB7DC07F379, 8FBE6457ECD1ABB518D9800EBA8A017774FFAA8EABD2EDC0825181A12FE9AEF6 ] upnphost C:\WINDOWS\System32\upnphost.dll
10:31:34.0410 0x2fb8 upnphost - ok
10:31:34.0426 0x2fb8 [ 6B46FC140C9AF68E6E7697D66D59CB4D, F018B4784D65F1A8140A6EA69C35D6A7ECE01738694052FD54AFD2B81A8F2FF8 ] UrsChipidea C:\WINDOWS\System32\drivers\urschipidea.sys
10:31:34.0441 0x2fb8 UrsChipidea - ok
10:31:34.0457 0x2fb8 [ B4402E7F0923F660270442CE76877ABE, 1C2DD26EAB71F75EA576E8DAABAF71FD7DC3DF807CF025617C774CEF33C0B718 ] UrsCx01000 C:\WINDOWS\system32\drivers\urscx01000.sys
10:31:34.0457 0x2fb8 UrsCx01000 - ok
10:31:34.0473 0x2fb8 [ 9DD431F1B94789CFB527E5D19261F124, 8F5A249A97C5B14B282E3147DD21951D2AD34B651E762814C12F4C26D74EC70C ] UrsSynopsys C:\WINDOWS\System32\drivers\urssynopsys.sys
10:31:34.0473 0x2fb8 UrsSynopsys - ok
10:31:34.0494 0x2fb8 [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64 C:\WINDOWS\System32\Drivers\usbaapl64.sys
10:31:34.0495 0x2fb8 USBAAPL64 - detected UnsignedFile.Multi.Generic ( 1 )
10:31:34.0826 0x2fb8 Detect skipped due to KSN trusted
10:31:34.0826 0x2fb8 USBAAPL64 - ok
10:31:34.0826 0x2fb8 [ C87E32B90F085970D9637FBAD45EF6FE, C180EACD2EE479277DA5DBF39E43B428BD7945141B2451CB3946B0C1E495E76F ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys
10:31:34.0842 0x2fb8 usbccgp - ok
10:31:34.0842 0x2fb8 [ 0B663856474AC41924D9E9112203858F, 9E09F2A6279B48CAC09F8C7AA1F1BE02864D540C2ED1460CBA9FABCF0A546A1E ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys
10:31:34.0858 0x2fb8 usbcir - ok
10:31:34.0873 0x2fb8 [ 635686E528F2C9CB916EC1BB04EE6AD1, 080A0F209773232860F510F17005EF92650BA831F69BB0006AEF11A2BB0A4906 ] UsbClientService C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
10:31:34.0889 0x2fb8 UsbClientService - detected UnsignedFile.Multi.Generic ( 1 )
10:31:35.0195 0x2fb8 Detect skipped due to KSN trusted
10:31:35.0195 0x2fb8 UsbClientService - ok
10:31:35.0211 0x2fb8 [ F83D2250256203AC5DA5E8601C1AFDD7, AC0D90E2DB3051798B9D287CF3D0E92FED4000822E65A82775A29CF896B76F04 ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys
10:31:35.0227 0x2fb8 usbehci - ok
10:31:35.0242 0x2fb8 [ 7FFD26742321919590ED77FCA556D65F, F7FAB63C36F8519F5A7B9091C507F3CB580C390322FAF9155CCE7F66C965B968 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys
10:31:35.0258 0x2fb8 usbhub - ok
10:31:35.0274 0x2fb8 [ 7A749B2863B5561BE34B39E8E249AD8F, E5B67DFAF5407007FD0CC408D6B4BA19DF59584819FC715E9F9E0FBF3EA00AAB ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys
10:31:35.0296 0x2fb8 USBHUB3 - ok
10:31:35.0296 0x2fb8 [ D2109F1F4FEBF1DAC415CDC5DE876479, C8A871EBD0E5EF004BA622A73DAC36C03608CD317FDCD0A6A98608DF4CC10D55 ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys
10:31:35.0311 0x2fb8 usbohci - ok
10:31:35.0311 0x2fb8 [ 29C9572F2D061CFC3C0BD48A3163E343, 2527DCC9E6D421F5DC40051C787A5270EB077746785465C9AA2A2AEEF47307D5 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys
10:31:35.0327 0x2fb8 usbprint - ok
10:31:35.0343 0x2fb8 [ 429477D6DEF3321FF7D3EF23CAAADA00, BB7D2AFE99736AAFFA8B0B2DABF7D6A6D5CB9563B1DE6A7E86CE7DC9D27F31C0 ] usbser C:\WINDOWS\System32\drivers\usbser.sys
10:31:35.0343 0x2fb8 usbser - ok
10:31:35.0358 0x2fb8 [ 0CC16F7B91C57AE9A4E44425A295FDAA, 7CEE11955E5742DA390601F565412C14A7481B8747C495CCD246696C56B426DC ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS
10:31:35.0358 0x2fb8 USBSTOR - ok
10:31:35.0374 0x2fb8 [ C917D09064CDBD18F75ADC9B2C48F847, A7F6223346CCD7E84186CD0C0715014F8E3A4398298925A43290224678620D23 ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys
10:31:35.0390 0x2fb8 usbuhci - ok
10:31:35.0396 0x2fb8 [ 95BCCEFBC40D06484CF16144FE79B8A5, 8ABA73C5FFEDD319FB96B807AD08716698E557522478DF1A2C5D662675636AE0 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS
10:31:35.0412 0x2fb8 USBXHCI - ok
10:31:35.0443 0x2fb8 [ 4CC81AB9D380A6264FF4C0C1512CF965, 76C33053D1C9155B0F3F8392FF982AD4EABEE2BBBEE89EA41DBFE8E436973EB0 ] UserDataSvc C:\WINDOWS\System32\userdataservice.dll
10:31:35.0496 0x2fb8 UserDataSvc - ok
10:31:35.0528 0x2fb8 [ AA24C61D88E36BA1144072227922173D, 2EBBC827E740F72EA2E75745E585378189BC0DEE91CACD7FA31BDBC5EFCF8733 ] UserManager C:\WINDOWS\System32\usermgr.dll
10:31:35.0559 0x2fb8 UserManager - ok
10:31:35.0591 0x2fb8 [ EBF9E40845362DBE2AD0DB3077269488, A6363006350D097F95B03A2F44E1D3FBD3BC40048BE57C715CD7CBC22D1EE70B ] UsoSvc C:\WINDOWS\system32\usocore.dll
10:31:35.0612 0x2fb8 UsoSvc - ok
10:31:35.0612 0x2fb8 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] VaultSvc C:\WINDOWS\system32\lsass.exe
10:31:35.0628 0x2fb8 VaultSvc - ok
10:31:35.0628 0x2fb8 [ 3C8E2C591345F38149C69FE8E5DF8C90, 9F4BB9BDA09CB2E99A6A888B288F322AE5C460B5D124CD714C6F00FF5029144B ] VClone C:\WINDOWS\System32\drivers\VClone.sys
10:31:35.0644 0x2fb8 VClone - ok
10:31:35.0644 0x2fb8 [ 0CBDE344FB48E42D78E29469F202ADBC, A1C3FBA5409DD3BBEAF1D3CE2583D6C8A621C0E4F534155EC540AFD67BC9E8CA ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys
10:31:35.0659 0x2fb8 vdrvroot - ok
10:31:35.0675 0x2fb8 [ 0783EDE1FA94649ED7F3CEF6A734041A, 1A13A613EF6B67459031C7994FFC6F32F73E02E0F123A171618E4F011C635684 ] vds C:\WINDOWS\System32\vds.exe
10:31:35.0713 0x2fb8 vds - ok
10:31:35.0713 0x2fb8 [ 723195568C8755CAD57F7933C5F2C5C2, 5C403799F67223605F825BC16D217C1EF5E1A0DDF00AC6380FE8976339B67D9B ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys
10:31:35.0728 0x2fb8 VerifierExt - ok
10:31:35.0744 0x2fb8 [ 3BB8D153A9A514EC9FFCB586251A1925, 5E4B46511F9791699826DC63B35528544347166BDE9981FB93F1F7F2A09599C7 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys
10:31:35.0775 0x2fb8 vhdmp - ok
10:31:35.0775 0x2fb8 [ 7929228F0E8B0C2FA0495A17A4FC27F6, 1F1667B10A96B1D85ED165F62A5C0EF28C37F828B8280EA08BFCC1BAC03F2C90 ] vhf C:\WINDOWS\System32\drivers\vhf.sys
10:31:35.0797 0x2fb8 vhf - ok
10:31:35.0797 0x2fb8 [ AEE432ED868831B1F068E373598F6D93, BAE91F47B0CB94B826CA010B490AD924D7B715911DF3FCE62F9165F3B571105C ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys
10:31:35.0813 0x2fb8 vmbus - ok
10:31:35.0813 0x2fb8 [ 9444B23FC694B5F90F21B0FC7F10D8DD, 86F92856F5C985DD8E5993B51E85E1F47EF8C9B2FB37468998C94266963BB4BD ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys
10:31:35.0828 0x2fb8 VMBusHID - ok
10:31:35.0828 0x2fb8 [ 4D0287F566B36536DD812A54C015FC4A, 01D6508CA59CF04A47902B1F7C202FD14A81240E0B447588D919DD1072B040CF ] vmgid C:\WINDOWS\System32\drivers\vmgid.sys
10:31:35.0844 0x2fb8 vmgid - ok
10:31:35.0844 0x2fb8 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll
10:31:35.0875 0x2fb8 vmicguestinterface - ok
10:31:35.0875 0x2fb8 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicheartbeat C:\WINDOWS\System32\icsvc.dll
10:31:35.0897 0x2fb8 vmicheartbeat - ok
10:31:35.0897 0x2fb8 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll
10:31:35.0929 0x2fb8 vmickvpexchange - ok
10:31:35.0944 0x2fb8 [ 0F621B52259D88A719AA20C6D04E3D72, 80B0528CCDE6E1B6F092787E1C0769C649698B196602859A5855134F0ECCBAE5 ] vmicrdv C:\WINDOWS\System32\icsvcext.dll
10:31:35.0960 0x2fb8 vmicrdv - ok
10:31:35.0976 0x2fb8 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicshutdown C:\WINDOWS\System32\icsvc.dll
10:31:35.0997 0x2fb8 vmicshutdown - ok
10:31:35.0997 0x2fb8 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmictimesync C:\WINDOWS\System32\icsvc.dll
10:31:36.0013 0x2fb8 vmictimesync - ok
10:31:36.0029 0x2fb8 [ 704609D80666FCB1DAE91260CF2CBB20, 0764DA123DA3FE8543B9205DDF17B0621E6A0F0DF95E8C3D177FD3FAED516119 ] vmicvmsession C:\WINDOWS\System32\icsvc.dll
10:31:36.0044 0x2fb8 vmicvmsession - ok
10:31:36.0060 0x2fb8 [ 0F621B52259D88A719AA20C6D04E3D72, 80B0528CCDE6E1B6F092787E1C0769C649698B196602859A5855134F0ECCBAE5 ] vmicvss C:\WINDOWS\System32\icsvcext.dll
10:31:36.0075 0x2fb8 vmicvss - ok
10:31:36.0092 0x2fb8 [ 29075915F9BDC3437F8BED71C067D399, 2C7718080C11DFDD4C9A2085537F78F5633369B4A27D9C64168F0249594A4AA2 ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys
10:31:36.0098 0x2fb8 volmgr - ok
10:31:36.0114 0x2fb8 [ 6BDB6CE6D2D9E3D3F28F1C97E12B62E2, 5E77D7AF858D7B90FF395F39B86D6F96413D1DDEA28BC9FB40C5524A4DF6DAD0 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys
10:31:36.0129 0x2fb8 volmgrx - ok
10:31:36.0129 0x2fb8 [ BF2546583BB75F01DDA60A7921DFB230, 579BD0BC55F4F03CD8D1FCDAC3975A1649C688820F2F7FC1AD354132D9E3BEE9 ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys
10:31:36.0145 0x2fb8 volsnap - ok
10:31:36.0161 0x2fb8 [ AC2E20A74D09D24485BE8396CE04F07B, 23FCE8BEE01B89E5CDCA536D75DBA6DCE3E92E13178A66836CEB7829310A89D1 ] volume C:\WINDOWS\system32\drivers\volume.sys
10:31:36.0161 0x2fb8 volume - ok
10:31:36.0176 0x2fb8 [ 92F6E3E6D3F1795263EB34B37F74AEF7, 33AB1ECCA1216AF1995E1DB4F11E48156FF62391D7C176C8A4CC1037B9CB3A27 ] vpci C:\WINDOWS\System32\drivers\vpci.sys
10:31:36.0176 0x2fb8 vpci - ok
10:31:36.0195 0x2fb8 [ 6814DDD37C300F845C4FFE4D4CC9A8C7, 206D5D0A803B8EC26A190C5BF72FF12137C1B8D76A674B6C7C16C8C9BBE44C29 ] VsEtwService120 C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe
10:31:36.0198 0x2fb8 VsEtwService120 - ok
10:31:36.0198 0x2fb8 [ FD9BCB8920973CEAD4D49DC7A6D8A618, 34AB4A485FB40DF737600006D8323BE927FB0BDA2BC170F4C123BE775EAE7CC8 ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys
10:31:36.0214 0x2fb8 vsmraid - ok
10:31:36.0245 0x2fb8 [ 01FFD5AF533F2CFDF26DDDC9313731C1, BFF0F2E57CD2358AC8F519F6F5692A46D97EC4E9B763D47101CEF31712FD4738 ] VSS C:\WINDOWS\system32\vssvc.exe
10:31:36.0314 0x2fb8 VSS - ok
10:31:36.0314 0x2fb8 [ 558B8E6F99E198519FD87F1575F7D92D, B176F51B72D9BCD6472A710D4E0B78A7A7D1C3CAEC12725289C1EBA54E35083D ] VSStandardCollectorService140 C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe
10:31:36.0330 0x2fb8 VSStandardCollectorService140 - ok
10:31:36.0330 0x2fb8 [ 0C111F220798CCE80484026E06822379, B98A5E44D3ABA67E6DE99E18BF3C2C606923E6269E262665C721F672ACBBED2A ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys
10:31:36.0345 0x2fb8 VSTXRAID - ok
10:31:36.0361 0x2fb8 [ 607639716E9DB1CEF4E18B5B229293B4, 1D997177093F907EFE8A04AD10443BB9C355C0D7657DBD449E7EE7FCABC3ECBC ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys
10:31:36.0361 0x2fb8 vwifibus - ok
10:31:36.0377 0x2fb8 [ B1ED64E628763148BF84FBE23F2AD711, 6182A39675E6049BC3DD353694720795A8E3D0331509AA8ABA4883D5C569AD5E ] vwififlt C:\WINDOWS\system32\drivers\vwififlt.sys
10:31:36.0377 0x2fb8 vwififlt - ok
10:31:36.0395 0x2fb8 [ 59920894C38A827091A06AF559834E47, 8B40FE0B1BA3B2A79BFF70803D039DB921F85C978724722E5E5AFF188FA75471 ] vwifimp C:\WINDOWS\System32\drivers\vwifimp.sys
10:31:36.0399 0x2fb8 vwifimp - ok
10:31:36.0414 0x2fb8 [ 76C1CC611352499326001F25A3ED15F8, 228BFA8A01BB1B3868576D509A2EA6F3D37FEDC8F12D4DC4E0A84CE926C6D1B1 ] W32Time C:\WINDOWS\system32\w32time.dll
10:31:36.0446 0x2fb8 W32Time - ok
10:31:36.0446 0x2fb8 [ 4053FB949F48647A327BC18DFEEA4374, 52511C35854A673ADCD9084FEF9BC6A339BCA0290374B81140A371D67B13A8FB ] w3logsvc C:\WINDOWS\system32\inetsrv\w3logsvc.dll
10:31:36.0461 0x2fb8 w3logsvc - ok
10:31:36.0477 0x2fb8 [ 85461F6AD65CCE84A7BC6D9F2A5861B3, 0C9A662F1BADF429B1DF62E91F4626DE996F84945D3A42D26A0FA09EC15CC9D7 ] W3SVC C:\WINDOWS\system32\inetsrv\iisw3adm.dll
10:31:36.0499 0x2fb8 W3SVC - ok
10:31:36.0499 0x2fb8 [ 55D00B785A7587F4263D125817871283, B92400B229099C1E243F2B149881A1423A2E9C8CA2D77D868B9B923BFDEC7FF2 ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys
10:31:36.0515 0x2fb8 WacomPen - ok
10:31:36.0530 0x2fb8 [ 1483BE4D0135C378CB61D3CD73AB3E03, B7309C9E4F370860C507BF52D17234CDF4A7FAE95D2D822714E07EF5DEC0249B ] WalletService C:\WINDOWS\system32\WalletService.dll
10:31:36.0546 0x2fb8 WalletService - ok
10:31:36.0562 0x2fb8 [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:31:36.0577 0x2fb8 wanarp - ok
10:31:36.0577 0x2fb8 [ CEF3D306C09BEC1A800E9B4A06F859F6, 75D21F97E9F94FA97024F945AF512FEC94F88DD8073F3FAD92A6E0A9FDC586DB ] wanarpv6 C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:31:36.0599 0x2fb8 wanarpv6 - ok
10:31:36.0615 0x2fb8 [ 85461F6AD65CCE84A7BC6D9F2A5861B3, 0C9A662F1BADF429B1DF62E91F4626DE996F84945D3A42D26A0FA09EC15CC9D7 ] WAS C:\WINDOWS\system32\inetsrv\iisw3adm.dll
10:31:36.0647 0x2fb8 WAS - ok
10:31:36.0675 0x2fb8 [ 30B8286F8FE1AE90A583100D45E02247, 3C86A4A5E21F9A1267EA231B20914E0A162BA4C25FE8917AD3AB6D504DA5BE0C ] wbengine C:\WINDOWS\system32\wbengine.exe
10:31:36.0731 0x2fb8 wbengine - ok
10:31:36.0746 0x2fb8 [ 8C521D161445C3E1F38A494E7649E70D, F00990B2FE1FB52C74A2057E6480C5EBF2BDBC32955CC03C6B63360F20A49A18 ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll
10:31:36.0794 0x2fb8 WbioSrvc - ok
10:31:36.0799 0x2fb8 [ E330144B97D493AA886000DCAAA8DAF5, ED86F46F5A76FD8F06CA98BD61B174ADB9AD4B065394356872708DF8B614E4F9 ] wcifs C:\WINDOWS\system32\drivers\wcifs.sys
10:31:36.0799 0x2fb8 wcifs - ok
10:31:36.0830 0x2fb8 [ 32960EA9CF836D7DD77767DCB68CE230, 679446A4FAB0331C181D2716CAEA225267C6164BB9867E360C5B3D6AB1083195 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll
10:31:36.0862 0x2fb8 Wcmsvc - ok
10:31:36.0877 0x2fb8 [ D50645235A507B0546B1B5CF7D0B8849, 19F5FE10C953B8EE8EEDA9A9F7F2E97AA193BB085E7FC364066686089ADD1C9F ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll
10:31:36.0900 0x2fb8 wcncsvc - ok
10:31:36.0900 0x2fb8 [ AEA1093B751339267D8C8C1EF3D669CF, 8F3325E7FB16BD856A0593C36F2E3E018909038C52CD5F92E116E0C1366F31CB ] wcnfs C:\WINDOWS\system32\drivers\wcnfs.sys
10:31:36.0916 0x2fb8 wcnfs - ok
10:31:36.0916 0x2fb8 [ D520B1B849B6D4D707AB31722B952C2D, 149BABB7BD63C1F212ADD9306C84FFB2A5CE6DC435BD3213EAB787E9B222C61F ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys
10:31:36.0931 0x2fb8 WdBoot - ok
10:31:36.0947 0x2fb8 [ 5030C76047D756263093A47B82970868, E772F15973F6DE36851DD230F1F4190746CD81CA1E7284DC074711C4BF45CAF0 ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys
10:31:36.0978 0x2fb8 Wdf01000 - ok
10:31:36.0997 0x2fb8 [ 29FF9199EDEB4F5470BB134D1A2563D2, 94713F98A6EA6042203D5DD0DE6758F5F0F331F7D4BB05E91EF20CEEEBD6780F ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys
10:31:37.0000 0x2fb8 WdFilter - ok
10:31:37.0016 0x2fb8 [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll
10:31:37.0032 0x2fb8 WdiServiceHost - ok
10:31:37.0032 0x2fb8 [ E7A7E8803E66B7CCED95D327A4DBC135, 401ECD953D4014A95C9022822D9ACEC1A68C917281DBA2365503A473FC6D9507 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll
10:31:37.0047 0x2fb8 WdiSystemHost - ok
10:31:37.0063 0x2fb8 [ 8CB606A3057355FD5A9DBDD1A0AC94EF, 6DD0B4A2270633086EBB569A00B87430EE6EF173525E341404B15845B57BE86D ] wdiwifi C:\WINDOWS\system32\DRIVERS\wdiwifi.sys
10:31:37.0101 0x2fb8 wdiwifi - ok
10:31:37.0101 0x2fb8 [ 17CF416CFF408190F5A4CBD79AB12E55, E376C8865C7EA633AE20D2CF940E4C7584AC783BAAF7941780FB6C4C84802F33 ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys
10:31:37.0116 0x2fb8 WdNisDrv - ok
10:31:37.0116 0x2fb8 WdNisSvc - ok
10:31:37.0132 0x2fb8 [ 3570C4E14F85CE0B537D126727ACA91C, A474C9E6B6E4E5945C63367C1D3D24D4782C4A4FEB00FAE15DFED099D8283078 ] WebClient C:\WINDOWS\System32\webclnt.dll
10:31:37.0147 0x2fb8 WebClient - ok
10:31:37.0179 0x2fb8 [ 2D1C892A586B9EF5B9DB2E26D744AB0E, B61173946A3784A503940FD8F231CFEA4D47ADE3E28E6F2853D5A5473EB775F8 ] WebManagement C:\WINDOWS\system32\WebManagement.exe
10:31:37.0216 0x2fb8 WebManagement - ok
10:31:37.0216 0x2fb8 [ 1785F9C96A0BDEC1F6E0C79EF412F342, D6D4EDA69457BEDDA69C2F60FC4C2FAC97D46CD8E9C1804CCD68F169383583E3 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll
10:31:37.0248 0x2fb8 Wecsvc - ok
10:31:37.0248 0x2fb8 [ B9175D63527B05131F2FA504CF0265F2, 1E43A17788F1B6A29E2889C81E0BE100D64BD3A9DEE7C154D9581F01D2D7D05F ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll
10:31:37.0263 0x2fb8 WEPHOSTSVC - ok
10:31:37.0263 0x2fb8 [ 5C58EC0C9D4DE04DCDE56F6DCEA62080, 8ED386EDF4C39C339CE0BB2AC7E199C38705E5A6B3F56A4987B9A8ABD19BB59F ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll
10:31:37.0279 0x2fb8 wercplsupport - ok
10:31:37.0300 0x2fb8 [ F899B355CC95AF26AB36E84E8A0DD685, C400F2F80FFF6473FEF066943C4A2AFF0FFE988A4F755757A2E5005C2A10DAD8 ] WerSvc C:\WINDOWS\System32\WerSvc.dll
10:31:37.0301 0x2fb8 WerSvc - ok
10:31:37.0317 0x2fb8 [ E1785942AC51FEE6826CDF02075C5AA9, 56FE7017684086F4F9C3A2C0D3AC00369BA0938BA3987EEBEE9A75B8E3CA0AE1 ] WFPLWFS C:\WINDOWS\system32\drivers\wfplwfs.sys
10:31:37.0332 0x2fb8 WFPLWFS - ok
10:31:37.0332 0x2fb8 [ B154618505A6A9026EFA6AB8C4123BF1, 713648D71AA027B4472E7E75B942630DBE7383687984B02A5E99C9E4192C95EB ] WiaRpc C:\WINDOWS\System32\wiarpc.dll
10:31:37.0348 0x2fb8 WiaRpc - ok
10:31:37.0364 0x2fb8 [ 0CF79A0EACFFBB75A50A469A27696D02, E112BF7B5A8D0B0AD2EA0E7B9FD4E8CFEC9371C8E94A60248292D688AFE715C4 ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys
10:31:37.0364 0x2fb8 WIMMount - ok
10:31:37.0364 0x2fb8 WinDefend - ok
10:31:37.0379 0x2fb8 [ 0DE131733317EB4BE67028366B0CAAC6, AC7DADBF03A3752B4D33CA19F03DBCEDD6F56893C2DA25C98B0AB07063D990E3 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys
10:31:37.0399 0x2fb8 WindowsTrustedRT - ok
10:31:37.0401 0x2fb8 [ 92EB5D38BDF10C790450F3E46BF93A0E, 0FC027398DBD43EDC1F7D703C0B6DB20294DF34E67C9288442039B1A5663CE1B ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys
10:31:37.0401 0x2fb8 WindowsTrustedRTProxy - ok
10:31:37.0432 0x2fb8 [ C2A3B07F0118D61086C99BDCBAB6A6A3, 04D646BEF1C6F427503C594F0ECBB33140C3991A3A7AFB66B2C9581E358F9FD2 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
10:31:37.0464 0x2fb8 WinHttpAutoProxySvc - ok
10:31:37.0464 0x2fb8 [ F95DE20312ACCA7761446DE152BD1F7C, F6C5ACA500C2182437F4A7402BD81C3A2B77C0BBD78BA31FB574DC1997FCBFE6 ] WinMad C:\WINDOWS\System32\drivers\winmad.sys
10:31:37.0479 0x2fb8 WinMad - ok
10:31:37.0479 0x2fb8 [ CD49CA8E3280ACEEC5ECF431A59F5EFD, 75F48EFC6DEE9E06B490703EE47602AFDEA51505285B02D2CF884601E71857CC ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
10:31:37.0501 0x2fb8 Winmgmt - ok
10:31:37.0564 0x2fb8 [ B8C0D620219ECAA23A2AC841EAF454D1, FB527C4D36929D7FAE2A837727C557B7823A72069EBCAB7D16C49E8B21E8D952 ] WinRM C:\WINDOWS\system32\WsmSvc.dll
10:31:37.0649 0x2fb8 WinRM - ok
10:31:37.0664 0x2fb8 [ 4EFB346BFDAEEB29316AA52BBB9852B1, 4BC5554F44BD9549D0A929D77BD410FA3EB502A7D0170303D369268672505494 ] WINUSB C:\WINDOWS\System32\drivers\WinUSB.SYS
10:31:37.0680 0x2fb8 WINUSB - ok
10:31:37.0680 0x2fb8 [ 8B9AFF5F08E66A6F1F1063DEC9457FB6, 98F2AF6988D125521FD34CAA48B9652922F0C8ECFAE9B0C1DF4B3CE6B9CF500F ] WinVerbs C:\WINDOWS\System32\drivers\winverbs.sys
10:31:37.0701 0x2fb8 WinVerbs - ok
10:31:37.0718 0x2fb8 [ ECD999D8412A3473C26B118F89DB9908, 5FB9B93E4B5482CCFF01D805DFA386FD8D3441BC81E7BD5DF89EE3078FD724F3 ] wisvc C:\WINDOWS\system32\flightsettings.dll
10:31:37.0733 0x2fb8 wisvc - ok
10:31:37.0780 0x2fb8 [ 7671078AEF4C0203B053A9642C401FF7, BBFADA89CD31F20ADDBFAFAD2E492C72D82BF2F8B823BB6773F04D229B62534C ] WlanSvc C:\WINDOWS\System32\wlansvc.dll
10:31:37.0877 0x2fb8 WlanSvc - ok
10:31:37.0918 0x2fb8 [ E15711970C5BE05E8D70B294D0AFF621, 30670CFC4DA57B4A3E0E895E4111100D847BB8041A258A303524CD96DC566482 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll
10:31:38.0002 0x2fb8 wlidsvc - ok
10:31:38.0002 0x2fb8 [ 89F278FBC9FCDD63BDC0E7A27E6C8DA9, F0AE847C58BF380E9CB235D7EB56C1E2DA714F756E5E2EE5D718A147B14D73DE ] WLNdis50 C:\WINDOWS\system32\DRIVERS\wlndis50.sys
10:31:38.0018 0x2fb8 WLNdis50 - ok
10:31:38.0018 0x2fb8 [ 6F4F4F5A007D1710BD76FB311DA97C07, FC0FEA4364F6BA4E31DBC82735D09D429CA3BE9AFCFF5D5E1263D8B27FC2CE3E ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys
10:31:38.0034 0x2fb8 WmiAcpi - ok
10:31:38.0049 0x2fb8 [ 3CDDFF6CAD962C5EF1C52FD667C358B6, F6F09145E9461EB17172988D26749FCF36920A1A683459334D04A6D072B31A92 ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe
10:31:38.0065 0x2fb8 wmiApSrv - ok
10:31:38.0065 0x2fb8 WMPNetworkSvc - ok
10:31:38.0081 0x2fb8 [ 43C8D087B31C592163B33A4BDA540E40, 3A6C4E5E56931B29321DCC723585F2F0E804EF4DCDEAB2A8687F30FC3AE70E43 ] Wof C:\WINDOWS\system32\drivers\Wof.sys
10:31:38.0102 0x2fb8 Wof - ok
10:31:38.0134 0x2fb8 [ 909CB4BBF7B08E78C363000E09E79A6F, 217205D1B5EE03274AFF9405AED6D2A5665CBA4C3876E84B53DA44920CDF9CB1 ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll
10:31:38.0203 0x2fb8 workfolderssvc - ok
10:31:38.0218 0x2fb8 [ F02930EB91596042F2221397D60AFCE5, 10E2AB0993B67CBAA9E11C68280608965064EC9F7E0C570F5B453FACADB8AB5D ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll
10:31:38.0234 0x2fb8 WPDBusEnum - ok
10:31:38.0250 0x2fb8 [ 75A9284F01FE7CB1A7D5EAE5C1EB4F33, 390EF23AEA06D8711555F7979FF8BE0620B53C1A551638C4EC6FB7C6678965B3 ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys
10:31:38.0250 0x2fb8 WpdUpFltr - ok
10:31:38.0265 0x2fb8 [ 60E2EB3E7B7F15C25E02462159F90707, D8344B529EEC0D4922CAC3E6897CC9F191ACF1376017BE38ED6BF6019F1ED181 ] WpnService C:\WINDOWS\system32\WpnService.dll
10:31:38.0297 0x2fb8 WpnService - ok
10:31:38.0302 0x2fb8 [ C7C91FB86A3C6CD7619725A88ED1884C, 132C43C518F37BF303D768BD5FB0AB835F693C43FE693937D804A34E940D770F ] WpnUserService C:\WINDOWS\System32\WpnUserService.dll
10:31:38.0302 0x2fb8 WpnUserService - ok
10:31:38.0318 0x2fb8 [ 36D7B73ADC3E10607ED6EC874AFB5D1E, 1737B3E4D2CA76BB27903BF460E4960E6A0BC32D35069AC7C5E4B07F625F3282 ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys
10:31:38.0334 0x2fb8 ws2ifsl - ok
10:31:38.0334 0x2fb8 [ 9A0E0B836413EB0BC885532D2A5389D6, AFEE4A0578D5581E4D72999A33C0DEA6253BD891F611AFF9AFDE4160A60105F3 ] wscsvc C:\WINDOWS\System32\wscsvc.dll
10:31:38.0349 0x2fb8 wscsvc - ok
10:31:38.0365 0x2fb8 [ 696EC2EAA2A42A137CCBB9A84D6917C0, 424089F4F373962AF8357C5D4D43F35948989BE3F58EAD3690F565F4C1BBC66F ] WSDPrintDevice C:\WINDOWS\System32\drivers\WSDPrint.sys
10:31:38.0365 0x2fb8 WSDPrintDevice - ok
10:31:38.0381 0x2fb8 [ 46E4A69825A7554A5DB784A55F8AD203, 7F347054FCDD5DEF93083D420E56EBE5EEBBAE2BD2FED9B2E75E85149DE52780 ] WSDScan C:\WINDOWS\system32\DRIVERS\WSDScan.sys
10:31:38.0381 0x2fb8 WSDScan - ok
10:31:38.0399 0x2fb8 WSearch - ok
10:31:38.0402 0x2fb8 [ 72B4E9DF6456C43C42A1419B09486045, 536BA7377B5BEA7EA46864453933111DB88DB8FB689C68915ACD7261A996E61D ] wsvd C:\WINDOWS\system32\DRIVERS\wsvd.sys
10:31:38.0402 0x2fb8 wsvd - ok
10:31:38.0449 0x2fb8 [ DDB7E452A99E0E5244105C6D2CF4BC9E, 1364B03AFFD20D339A2EBA303575BCCBC2D122D89810B1E3593CC55F93F9B79A ] wuauserv C:\WINDOWS\system32\wuaueng.dll
10:31:38.0534 0x2fb8 wuauserv - ok
10:31:38.0534 0x2fb8 [ AED7FE551E8672B824A56324076183EB, FFE543AAEFDEFFE6B20C244DB141A9425BDA88ED36F4870F0B70FEC433BDF0C1 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys
10:31:38.0550 0x2fb8 WudfPf - ok
10:31:38.0565 0x2fb8 [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys
10:31:38.0581 0x2fb8 WUDFRd - ok
10:31:38.0581 0x2fb8 [ 47F6450F28BAA32B2AB0D6BE00996249, C8A47D6ADF89AD613AB685C6224B9099DCEFDCD8ABCF703542AFDC356404116E ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll
10:31:38.0603 0x2fb8 wudfsvc - ok
10:31:38.0619 0x2fb8 [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFWpdFs C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
10:31:38.0634 0x2fb8 WUDFWpdFs - ok
10:31:38.0634 0x2fb8 [ CEFAB17FD7DFCFA515626C306262E89D, 9D2B728DDD478580987E2DB7AA4DA81D77F3362F536AC1CADED20EB6ECEBB55D ] WUDFWpdMtp C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
10:31:38.0650 0x2fb8 WUDFWpdMtp - ok
10:31:38.0681 0x2fb8 [ E231728BC515A4B85543AF74A1FEDFCB, 5D250D7D789B5BB56BFA2E7A109BCEB3686B7636C54D89F4E9804101D145C955 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll
10:31:38.0734 0x2fb8 WwanSvc - ok
10:31:38.0750 0x2fb8 [ F39D6915451D9226AC9A5E7AE70E2ABA, E05D678DC0423A4D0EB8B3BB5A942721BB4F3B0BED22748252DBD6053FE956F1 ] XblAuthManager C:\WINDOWS\System32\XblAuthManager.dll
10:31:38.0800 0x2fb8 XblAuthManager - ok
10:31:38.0819 0x2fb8 [ 765FF96467A26C4C03281ECA426EC2D9, 2526B03C518D72F429C29BA4D4F11707AF277BF71520A1A92238A932950AE161 ] XblGameSave C:\WINDOWS\System32\XblGameSave.dll
10:31:38.0866 0x2fb8 XblGameSave - ok
10:31:38.0882 0x2fb8 [ 9627BBAA50878F6833A6A7843EE3B1D9, 637566BB56501C4D11E3B6E6AC1C602D880C9D357CCE3DF1DF74EE672744F2B7 ] xboxgip C:\WINDOWS\System32\drivers\xboxgip.sys
10:31:38.0902 0x2fb8 xboxgip - ok
10:31:38.0919 0x2fb8 [ 335E6F2BE58523B295945C840C185B00, 94ED7E2CB212A3D55B8A2CB90CD1D02A6AF92DC0DDD487CB5B7CAC9883343460 ] XboxNetApiSvc C:\WINDOWS\system32\XboxNetApiSvc.dll
10:31:38.0966 0x2fb8 XboxNetApiSvc - ok
10:31:38.0966 0x2fb8 [ 63088A3361D9A308F328F11E9099DD87, E03FDB932FC57F199C8F8A8EADA338BDF7D2F9C6CB8FAB679A92B48B1E5AFE8A ] xinputhid C:\WINDOWS\System32\drivers\xinputhid.sys
10:31:38.0982 0x2fb8 xinputhid - ok
10:31:39.0000 0x2fb8 [ 21E13F2CB269DEFEAE5E1D09887D47BB, 543991CA8D1C65113DFF039B85AE3F9A87F503DAEC30F46929FD454BC57E5A91 ] ZAM C:\WINDOWS\System32\drivers\zam64.sys
10:31:39.0003 0x2fb8 ZAM - ok
10:31:39.0003 0x2fb8 [ 21E13F2CB269DEFEAE5E1D09887D47BB, 543991CA8D1C65113DFF039B85AE3F9A87F503DAEC30F46929FD454BC57E5A91 ] ZAM_Guard C:\WINDOWS\System32\drivers\zamguard64.sys
10:31:39.0019 0x2fb8 ZAM_Guard - ok
10:31:39.0051 0x2fb8 ================ Scan global ===============================
10:31:39.0051 0x2fb8 [ 0C710DB449712EE13ACE733695DB7780, BBC7875B38D318CE4E88979D083AC72E8993254A466A8A6882DDE9E0C3B687A3 ] C:\WINDOWS\system32\basesrv.dll
10:31:39.0066 0x2fb8 [ 4C08BF958476A137C78B62B22B5F90A4, 11DDD033896C96F8F7F1A1EDD0F4E0F07AFBB3202DC8A2E5E3ADB51C4D0700D4 ] C:\WINDOWS\system32\winsrv.dll
10:31:39.0066 0x2fb8 [ 1EE06E957B0B2CA52D26DA7861E160EF, 4B743A1C7010138F5F6684BBCF7CAD6FD05F49920BDD3FDB776347AA6B44AB94 ] C:\WINDOWS\system32\sxssrv.dll
10:31:39.0082 0x2fb8 [ 3C69CC28665854F1AAB4B4005005FA31, 2750F5ECCD448C07E3402AA64EA625D27C6BC1D000A3FFE57C03D62428BB46C4 ] C:\WINDOWS\system32\services.exe
10:31:39.0082 0x2fb8 [ Global ] - ok
10:31:39.0082 0x2fb8 ================ Scan MBR ==================================
10:31:39.0100 0x2fb8 [ 0792F22BCC85CFD3B28324561FFFCABB ] \Device\Harddisk1\DR1
10:31:40.0506 0x2fb8 \Device\Harddisk1\DR1 - ok
10:31:40.0522 0x2fb8 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
10:31:40.0569 0x2fb8 \Device\Harddisk0\DR0 - ok
10:31:40.0569 0x2fb8 [ 0792F22BCC85CFD3B28324561FFFCABB ] \Device\Harddisk1\DR1
10:31:41.0989 0x2fb8 \Device\Harddisk1\DR1 - ok
10:31:42.0004 0x2fb8 ================ Scan VBR ==================================
10:31:42.0007 0x2fb8 [ F68E68F0890DC2414FD86BEDA8A0F7D1 ] \Device\Harddisk1\DR1\Partition1
10:31:42.0008 0x2fb8 \Device\Harddisk1\DR1\Partition1 - ok
10:31:42.0010 0x2fb8 [ 26BD3D425C2B773547904565F23579AF ] \Device\Harddisk0\DR0\Partition1
10:31:42.0010 0x2fb8 \Device\Harddisk0\DR0\Partition1 - ok
10:31:42.0010 0x2fb8 [ 17BE8265382E56DE6499C13860C246BC ] \Device\Harddisk0\DR0\Partition2
10:31:42.0010 0x2fb8 \Device\Harddisk0\DR0\Partition2 - ok
10:31:42.0010 0x2fb8 [ 58A1B73E15ECB3CCA4420D90BB1C9CE7 ] \Device\Harddisk0\DR0\Partition3
10:31:42.0010 0x2fb8 \Device\Harddisk0\DR0\Partition3 - ok
10:31:42.0010 0x2fb8 [ EBE53444C41E5298BADB1D83D301163B ] \Device\Harddisk0\DR0\Partition4
10:31:42.0010 0x2fb8 \Device\Harddisk0\DR0\Partition4 - ok
10:31:42.0026 0x2fb8 [ 168C882C8848521892794A26CCB15497 ] \Device\Harddisk0\DR0\Partition5
10:31:42.0026 0x2fb8 \Device\Harddisk0\DR0\Partition5 - ok
10:31:42.0026 0x2fb8 [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition6
10:31:42.0026 0x2fb8 \Device\Harddisk0\DR0\Partition6 - ok
10:31:42.0026 0x2fb8 [ 787ADDBF8CF3799F354919F442041831 ] \Device\Harddisk0\DR0\Partition7
10:31:42.0026 0x2fb8 \Device\Harddisk0\DR0\Partition7 - ok
10:31:42.0026 0x2fb8 [ F68E68F0890DC2414FD86BEDA8A0F7D1 ] \Device\Harddisk1\DR1\Partition1
10:31:42.0026 0x2fb8 \Device\Harddisk1\DR1\Partition1 - ok
10:31:42.0026 0x2fb8 ================ Scan generic autorun ======================
10:31:42.0042 0x2fb8 [ 09B7C685A35DFB954BD2C7FE30268C0A, 2657727699AF7B8F8D6F3DD4B86300091817FF314555C2471A8CBC04D95F7A73 ] C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe
10:31:42.0042 0x2fb8 DptfPolicyLpmServiceHelper - ok
10:31:42.0042 0x2fb8 [ 42361B4BD80768E82B80285851037665, A555A6BF8016645B838FEA993AD273D1F472586F3600619DC243B1C33438FA07 ] C:\Program Files\Conexant\ForteConfig\fmapp.exe
10:31:42.0057 0x2fb8 ForteConfig - ok
10:31:42.0073 0x2fb8 [ FFBFE1175531CD582D89796835CBB598, 7DC1FEB90AFC08C829001849985C7B20CB782F05CD9C000C6C9D42D3FDB1DDF4 ] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe
10:31:42.0089 0x2fb8 cAudioFilterAgent - ok
10:31:42.0142 0x2fb8 [ 4F8B94EC4D4FFA0712CCADF8145F28D1, 6CED9332100CA71FB17930AAC4ED1798E6F3A83CEBEE0A3412EFA01F6F1A6F22 ] C:\Program Files\CONEXANT\SAII\SACpl.exe
10:31:42.0173 0x2fb8 SmartAudio - ok
10:31:42.0173 0x2fb8 [ E71D67CC5FF2DB3D44B717EC259DB83A, 13A90DF0B7224FC26D179F2DCF588628D380A5CCA32EDF4B0B0FB1D29B672C52 ] C:\ProgramData\YogaSmartSwicth\yogaserver.exe
10:31:42.0188 0x2fb8 yogaserver - ok
10:31:42.0490 0x2fb8 [ DF99547E3CD8C828202546ED9C4D7D25, 83013EEE760004E812CD63662843D1F3972AFBF83B4739935FC746F470FA7188 ] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
10:31:42.0807 0x2fb8 Energy Management - ok
10:31:42.0828 0x2fb8 [ D41309D7717CC5D62C2E0C5EB6B127B3, 50F46F762320C9B2560AA356B31EB564651F92BDA2DBCE34E3E349A65E347FAC ] C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe
10:31:42.0828 0x2fb8 EnergyUtility - ok
10:31:42.0844 0x2fb8 [ 48515EEA1608ECD83FE26C7490460F59, C7C552D13ED12B4165FDE45F69E170D4F18B746D84B3B08E7254AAF8D9671D0C ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
10:31:42.0860 0x2fb8 AdobeAAMUpdater-1.0 - ok
10:31:42.0860 0x2fb8 [ 4A0477ADCD07EC9D21257A2E456B16C5, CEF9C81730C12283A7600C3D921D89A62B14D1C46544B493F3AF7520DD2D1F79 ] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
10:31:42.0860 0x2fb8 IAStorIcon - detected UnsignedFile.Multi.Generic ( 1 )
10:31:43.0191 0x2fb8 Detect skipped due to KSN trusted
10:31:43.0191 0x2fb8 IAStorIcon - ok
10:31:43.0191 0x2fb8 SynTPEnh - ok
10:31:43.0191 0x2fb8 [ 3BD79A1F6D2EA0FDDEA3F8914B2A6A0C, 332E6806EFF846A2E6D0DC04A70D3503855DABFA83E6EC27F37E2D9103E80E51 ] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
10:31:43.0211 0x2fb8 VirtualCloneDrive - ok
10:31:43.0212 0x2fb8 [ 0080EB1CDD83F14C01534B1DC754234D, D0FC9B95A12D0C92730F8031B3DB287D1309008CF15EA0C02FC14B56FAE8C320 ] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
10:31:43.0212 0x2fb8 APSDaemon - ok
10:31:43.0260 0x2fb8 [ 7D5E8D5BDF324718BBC91DF02D830317, AA6A8B0536C14A7D11FDFFA5F980E90059F6C3BE99DE57503EC58DEA022C5398 ] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
10:31:43.0313 0x2fb8 Adobe Creative Cloud - ok
10:31:43.0313 0x2fb8 Lenovo App Shop - ok
10:31:43.0313 0x2fb8 EaseUS EPM tray - ok
10:31:43.0329 0x2fb8 [ C2CE42005E3381A95460876020518440, 562EB30DA9A1DB58DB221423177C0680E69A4C38EEE2D5FD936633B2EB8A616E ] C:\Program Files (x86)\QuickTime\QTTask.exe
10:31:43.0344 0x2fb8 QuickTime Task - detected UnsignedFile.Multi.Generic ( 1 )
10:31:43.0675 0x2fb8 Detect skipped due to KSN trusted
10:31:43.0675 0x2fb8 QuickTime Task - ok
10:31:43.0729 0x2fb8 [ DC87E00FD7B2E6CBA4997A9CB2914B59, 05BF560B2303B5E33CBCAFA82C351375CDD7E7B72DD9EAB8886463D3744FCB98 ] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
10:31:43.0776 0x2fb8 PMBVolumeWatcher - ok
10:31:43.0860 0x2fb8 [ 7EE68A122ED08E4AAD8DA551E34D2515, B3C9AB270AF595D3DBAFBF4A312B96CBF00C16F0A03CCC86BE56825CD1EB7143 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
10:31:43.0934 0x2fb8 SDTray - ok
10:31:43.0949 0x2fb8 [ A8AD6D36CA5A1D7E280621BB7E8117CA, 5E6A5589D72E8FF7A739D14739D06FBE218C4132943E643BD0317EDC8FD8952E ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
10:31:43.0965 0x2fb8 SunJavaUpdateSched - ok
10:31:44.0161 0x2fb8 [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
10:31:44.0315 0x2fb8 OneDriveSetup - ok
10:31:44.0478 0x2fb8 [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
10:31:44.0647 0x2fb8 OneDriveSetup - ok
10:31:44.0763 0x2fb8 [ 6CE0A962E0AF81BD2EE8FE6B37A1FEE1, 987545ED7F4B10212393CD62DE4C36E307E92C08ADA741571029DC8091CBB30C ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe
10:31:44.0879 0x2fb8 Spybot-S&D Cleaning - ok
10:31:45.0063 0x2fb8 [ 4BEC28F2CB50F1AEF969351CB0520B56, C8A1DD8254622E4C80EC1096CE7D2D1D9253E2623BFDDF5B23E58031BDB29D30 ] C:\Program Files (x86)\GlassWire\glasswire.exe
10:31:45.0280 0x2fb8 GlassWire - ok
10:31:45.0348 0x2fb8 [ F4F684066175B77E0C3A000549D2922C, 935C1861DF1F4018D698E8B65ABFA02D7E9037D8F68CA3C2065B6CA165D44AD2 ] C:\WINDOWS\system32\cmd.exe
10:31:45.0364 0x2fb8 Uninstall C:\Users\mzenk_000\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64 - ok
10:31:45.0517 0x2fb8 [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
10:31:45.0680 0x2fb8 OneDriveSetup - ok
10:31:45.0696 0x2fb8 Skype - ok
10:31:45.0718 0x2fb8 [ 2781E6EF593909A8B73FE1AD397F778A, E892D6C57F8903E20129E75A9B877690229280FD8106B5C7F96173175EA1AC4E ] C:\Program Files (x86)\Windows Mail\wab.exe
10:31:45.0734 0x2fb8 WAB Migrate - ok
10:31:45.0896 0x2fb8 [ 1496120E3867FD75AE5D4EAD6E618E7A, 8D8A2FD43D33A3F7A177783921BB7E50FECBAEF1E09CD42BCDC851375F3294D1 ] C:\Windows\SysWOW64\OneDriveSetup.exe
10:31:46.0073 0x2fb8 OneDriveSetup - ok
10:31:46.0095 0x2fb8 [ 2781E6EF593909A8B73FE1AD397F778A, E892D6C57F8903E20129E75A9B877690229280FD8106B5C7F96173175EA1AC4E ] C:\Program Files (x86)\Windows Mail\wab.exe
10:31:46.0119 0x2fb8 WAB Migrate - ok
10:31:46.0120 0x2fb8 Waiting for KSN requests completion. In queue: 23
10:31:47.0141 0x2fb8 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.14393.187 ), 0x60100 ( disabled : updated )
10:31:47.0141 0x2fb8 Win FW state via NFP2: enabled ( trusted )
10:31:47.0234 0x2fb8 ============================================================
10:31:47.0235 0x2fb8 Scan finished
10:31:47.0235 0x2fb8 ============================================================
10:31:47.0240 0x2fb0 Detected object count: 1
10:31:47.0240 0x2fb0 Actual detected object count: 1
10:31:52.0589 0x2fb0 OpenVPNService ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:52.0589 0x2fb0 OpenVPNService ( UnsignedFile.Multi.Generic ) - User select action: Skip Edit 1:
2x durchlaufen lassen.
rkill Auszug: Code:
Rkill 2.8.4 by Lawrence Abrams (Grinler)
hxxp://www.bleepingcomputer.com/
Copyright 2008-2017 BleepingComputer.com
More Information about Rkill can be found at this link:
hxxp://www.bleepingcomputer.com/forums/topic308364.html
Program started at: 02/25/2017 11:11:44 AM in x64 mode.
Windows Version: Windows 10 Pro
Checking for Windows services to stop:
* No malware services found to stop.
Checking for processes to terminate:
* C:\Windows\SwUSB.exe (PID: 8540) [WD-HEUR]
* C:\Windows\STK03N\STK03NM.exe (PID: 2816) [WD-HEUR]
2 proccesses terminated!
Checking Registry for malware related settings:
* No issues found in the Registry.
Resetting .EXE, .COM, & .BAT associations in the Windows Registry.
Performing miscellaneous checks:
* No issues found.
Checking Windows Service Integrity:
* gagp30kx [Missing Service]
* IEEtwCollectorService [Missing Service]
* IoQos [Missing Service]
* nv_agp [Missing Service]
* TimeBroker [Missing Service]
* uagp35 [Missing Service]
* uliagpkx [Missing Service]
* WcsPlugInService [Missing Service]
* wpcfltr [Missing Service]
* WSService [Missing Service]
* agp440 [Missing ImagePath]
* AJRouter => %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted [Incorrect ImagePath]
* WpnService => %systemroot%\system32\svchost.exe -k netsvcs [Incorrect ImagePath]
* vmicrdv => %SystemRoot%\System32\icsvcext.dll [Incorrect ServiceDLL]
* vmicvss => %SystemRoot%\System32\icsvcext.dll [Incorrect ServiceDLL]
Searching for Missing Digital Signatures:
* No issues found.
Checking HOSTS File:
* Cannot edit the HOSTS file.
* Permissions could not be fixed. Use Hosts-perm.bat to fix permissions: hxxp://www.bleepingcomputer.com/download/hosts-permbat/
* HOSTS file entries found:
0.0.0.0 0.0.0.0
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
20 out of 15654 HOSTS entries shown.
Please review HOSTS file for further entries.
Program finished at: 02/25/2017 11:12:26 AM
Execution time: 0 hours(s), 0 minute(s), and 42 seconds(s) |