Steffen 70 | 31.03.2015 11:54 | Code:
2:38:18.0514 0x0dd0 Parvdm - ok
12:38:18.0560 0x0dd0 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll
12:38:18.0654 0x0dd0 PcaSvc - ok
12:38:18.0685 0x0dd0 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys
12:38:18.0685 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pci.sys. md5: 673E55C3498EB970088E812EA820AA8F, sha256: 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5
12:38:18.0685 0x0dd0 pci - detected LockedFile.Multi.Generic ( 1 )
12:38:28.0529 0x0dd0 Object is SCO, delete is not allowed
12:38:28.0529 0x0dd0 pci ( LockedFile.Multi.Generic ) - warning
12:38:28.0560 0x0dd0 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys
12:38:28.0560 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pciide.sys. md5: AFE86F419014DB4E5593F69FFE26CE0A, sha256: CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00
12:38:28.0560 0x0dd0 pciide - detected LockedFile.Multi.Generic ( 1 )
12:38:28.0560 0x0dd0 Object is SCO, delete is not allowed
12:38:28.0560 0x0dd0 pciide ( LockedFile.Multi.Generic ) - warning
12:38:28.0591 0x0dd0 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
12:38:28.0591 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\pcmcia.sys. md5: F396431B31693E71E8A80687EF523506, sha256: BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B
12:38:28.0591 0x0dd0 pcmcia - detected LockedFile.Multi.Generic ( 1 )
12:38:28.0591 0x0dd0 Object is SCO, delete is not allowed
12:38:28.0591 0x0dd0 pcmcia ( LockedFile.Multi.Generic ) - warning
12:38:28.0607 0x0dd0 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
12:38:28.0622 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pcw.sys. md5: 250F6B43D2B613172035C6747AEEB19F, sha256: A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9
12:38:28.0622 0x0dd0 pcw - detected LockedFile.Multi.Generic ( 1 )
12:38:28.0622 0x0dd0 pcw ( LockedFile.Multi.Generic ) - warning
12:38:28.0685 0x0dd0 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
12:38:28.0685 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\peauth.sys. md5: 9E0104BA49F4E6973749A02BF41344ED, sha256: B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116
12:38:28.0700 0x0dd0 PEAUTH - detected LockedFile.Multi.Generic ( 1 )
12:38:28.0700 0x0dd0 Object is SCO, delete is not allowed
12:38:28.0700 0x0dd0 PEAUTH ( LockedFile.Multi.Generic ) - warning
12:38:28.0700 0x0dd0 Force sending object to P2P due to detect: PEAUTH
12:38:28.0700 0x0dd0 Object send P2P result: false
12:38:28.0825 0x0dd0 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll
12:38:28.0919 0x0dd0 pla - ok
12:38:28.0981 0x0dd0 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
12:38:29.0028 0x0dd0 PlugPlay - ok
12:38:29.0044 0x0dd0 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
12:38:29.0075 0x0dd0 PNRPAutoReg - ok
12:38:29.0106 0x0dd0 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
12:38:29.0137 0x0dd0 PNRPsvc - ok
12:38:29.0184 0x0dd0 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
12:38:29.0231 0x0dd0 PolicyAgent - ok
12:38:29.0278 0x0dd0 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll
12:38:29.0309 0x0dd0 Power - ok
12:38:29.0356 0x0dd0 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
12:38:29.0356 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\raspptp.sys. md5: 631E3E205AD6D86F2AED6A4A8E69F2DB, sha256: 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065
12:38:29.0356 0x0dd0 PptpMiniport - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0356 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0356 0x0dd0 PptpMiniport ( LockedFile.Multi.Generic ) - warning
12:38:29.0387 0x0dd0 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys
12:38:29.0387 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\processr.sys. md5: 85B1E3A0C7585BC4AAE6899EC6FCF011, sha256: 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3
12:38:29.0387 0x0dd0 Processor - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0387 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0387 0x0dd0 Processor ( LockedFile.Multi.Generic ) - warning
12:38:29.0387 0x0dd0 Force sending object to P2P due to detect: Processor
12:38:29.0387 0x0dd0 Object send P2P result: false
12:38:29.0449 0x0dd0 [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc C:\Windows\system32\profsvc.dll
12:38:29.0512 0x0dd0 ProfSvc - ok
12:38:29.0527 0x0dd0 [ BF08DE8E4FA1F143D41B3241F7FCE5F6, 4140BE0ECE0D4B8FDD413DBA120F5D7EF6F94628224320EDA2A85E50BEFDA638 ] ProtectedStorage C:\Windows\system32\lsass.exe
12:38:29.0543 0x0dd0 ProtectedStorage - ok
12:38:29.0558 0x0dd0 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
12:38:29.0558 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\pacer.sys. md5: 6270CCAE2A86DE6D146529FE55B3246A, sha256: 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883
12:38:29.0558 0x0dd0 Psched - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0558 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0558 0x0dd0 Psched ( LockedFile.Multi.Generic ) - warning
12:38:29.0668 0x0dd0 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
12:38:29.0668 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ql2300.sys. md5: AB95ECF1F6659A60DDC166D8315B0751, sha256: 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D
12:38:29.0668 0x0dd0 ql2300 - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0668 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0668 0x0dd0 ql2300 ( LockedFile.Multi.Generic ) - warning
12:38:29.0683 0x0dd0 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
12:38:29.0683 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ql40xx.sys. md5: B4DD51DD25182244B86737DC51AF2270, sha256: 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B
12:38:29.0699 0x0dd0 ql40xx - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0699 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0699 0x0dd0 ql40xx ( LockedFile.Multi.Generic ) - warning
12:38:29.0699 0x0dd0 Force sending object to P2P due to detect: ql40xx
12:38:29.0699 0x0dd0 Object send P2P result: false
12:38:29.0730 0x0dd0 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
12:38:29.0761 0x0dd0 QWAVE - ok
12:38:29.0792 0x0dd0 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
12:38:29.0792 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\qwavedrv.sys. md5: 584078CA1B95CA72DF2A27C336F9719D, sha256: 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121
12:38:29.0792 0x0dd0 QWAVEdrv - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0792 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0792 0x0dd0 QWAVEdrv ( LockedFile.Multi.Generic ) - warning
12:38:29.0792 0x0dd0 Force sending object to P2P due to detect: QWAVEdrv
12:38:29.0792 0x0dd0 Object send P2P result: false
12:38:29.0808 0x0dd0 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
12:38:29.0824 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rasacd.sys. md5: 30A81B53C766D0133BB86D234E5556AB, sha256: 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090
12:38:29.0824 0x0dd0 RasAcd - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0824 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0824 0x0dd0 RasAcd ( LockedFile.Multi.Generic ) - warning
12:38:29.0839 0x0dd0 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
12:38:29.0839 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\AgileVpn.sys. md5: 57EC4AEF73660166074D8F7F31C0D4FD, sha256: C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF
12:38:29.0839 0x0dd0 RasAgileVpn - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0839 0x0dd0 RasAgileVpn ( LockedFile.Multi.Generic ) - warning
12:38:29.0870 0x0dd0 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
12:38:29.0917 0x0dd0 RasAuto - ok
12:38:29.0933 0x0dd0 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
12:38:29.0933 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rasl2tp.sys. md5: D9F91EAFEC2815365CBE6D167E4E332A, sha256: 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C
12:38:29.0933 0x0dd0 Rasl2tp - detected LockedFile.Multi.Generic ( 1 )
12:38:29.0933 0x0dd0 Object is SCO, delete is not allowed
12:38:29.0933 0x0dd0 Rasl2tp ( LockedFile.Multi.Generic ) - warning
12:38:29.0933 0x0dd0 Force sending object to P2P due to detect: Rasl2tp
12:38:29.0933 0x0dd0 Object send P2P result: false
12:38:29.0980 0x0dd0 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll
12:38:30.0058 0x0dd0 RasMan - ok
12:38:30.0073 0x0dd0 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
12:38:30.0073 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\raspppoe.sys. md5: 0FE8B15916307A6AC12BFB6A63E45507, sha256: 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E
12:38:30.0073 0x0dd0 RasPppoe - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0073 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0073 0x0dd0 RasPppoe ( LockedFile.Multi.Generic ) - warning
12:38:30.0104 0x0dd0 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
12:38:30.0104 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rassstp.sys. md5: 44101F495A83EA6401D886E7FD70096B, sha256: 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A
12:38:30.0120 0x0dd0 RasSstp - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0120 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0120 0x0dd0 RasSstp ( LockedFile.Multi.Generic ) - warning
12:38:30.0120 0x0dd0 Force sending object to P2P due to detect: RasSstp
12:38:30.0120 0x0dd0 Object send P2P result: false
12:38:30.0151 0x0dd0 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
12:38:30.0151 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rdbss.sys. md5: D528BC58A489409BA40334EBF96A311B, sha256: C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61
12:38:30.0151 0x0dd0 rdbss - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0167 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0167 0x0dd0 rdbss ( LockedFile.Multi.Generic ) - warning
12:38:30.0182 0x0dd0 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
12:38:30.0182 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rdpbus.sys. md5: 0D8F05481CB76E70E1DA06EE9F0DA9DF, sha256: 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB
12:38:30.0182 0x0dd0 rdpbus - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0182 0x0dd0 rdpbus ( LockedFile.Multi.Generic ) - warning
12:38:30.0214 0x0dd0 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
12:38:30.0214 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\RDPCDD.sys. md5: 23DAE03F29D253AE74C44F99E515F9A1, sha256: 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430
12:38:30.0214 0x0dd0 RDPCDD - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0214 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0214 0x0dd0 RDPCDD ( LockedFile.Multi.Generic ) - warning
12:38:30.0214 0x0dd0 Force sending object to P2P due to detect: RDPCDD
12:38:30.0214 0x0dd0 Object send P2P result: false
12:38:30.0245 0x0dd0 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
12:38:30.0245 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdpencdd.sys. md5: 5A53CA1598DD4156D44196D200C94B8A, sha256: 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4
12:38:30.0245 0x0dd0 RDPENCDD - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0245 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0245 0x0dd0 RDPENCDD ( LockedFile.Multi.Generic ) - warning
12:38:30.0245 0x0dd0 Force sending object to P2P due to detect: RDPENCDD
12:38:30.0245 0x0dd0 Object send P2P result: false
12:38:30.0260 0x0dd0 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
12:38:30.0260 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdprefmp.sys. md5: 44B0A53CD4F27D50ED461DAE0C0B4E1F, sha256: CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91
12:38:30.0260 0x0dd0 RDPREFMP - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0260 0x0dd0 RDPREFMP ( LockedFile.Multi.Generic ) - warning
12:38:30.0260 0x0dd0 Force sending object to P2P due to detect: RDPREFMP
12:38:30.0260 0x0dd0 Object send P2P result: false
12:38:30.0307 0x0dd0 [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
12:38:30.0307 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\RDPWD.sys. md5: CD9214A6AE17D188D17C3CF8CB9CC693, sha256: 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60
12:38:30.0307 0x0dd0 RDPWD - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0307 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0307 0x0dd0 RDPWD ( LockedFile.Multi.Generic ) - warning
12:38:30.0354 0x0dd0 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
12:38:30.0354 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdyboost.sys. md5: 518395321DC96FE2C9F0E96AC743B656, sha256: 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776
12:38:30.0385 0x0dd0 rdyboost - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0385 0x0dd0 rdyboost ( LockedFile.Multi.Generic ) - warning
12:38:30.0385 0x0dd0 Force sending object to P2P due to detect: rdyboost
12:38:30.0385 0x0dd0 Object send P2P result: false
12:38:30.0416 0x0dd0 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll
12:38:30.0463 0x0dd0 RemoteAccess - ok
12:38:30.0494 0x0dd0 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
12:38:30.0541 0x0dd0 RemoteRegistry - ok
12:38:30.0572 0x0dd0 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
12:38:30.0604 0x0dd0 RpcEptMapper - ok
12:38:30.0635 0x0dd0 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
12:38:30.0682 0x0dd0 RpcLocator - ok
12:38:30.0728 0x0dd0 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll
12:38:30.0760 0x0dd0 RpcSs - ok
12:38:30.0806 0x0dd0 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
12:38:30.0806 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rspndr.sys. md5: 032B0D36AD92B582D869879F5AF5B928, sha256: 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184
12:38:30.0806 0x0dd0 rspndr - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0806 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0806 0x0dd0 rspndr ( LockedFile.Multi.Generic ) - warning
12:38:30.0822 0x0dd0 [ BF08DE8E4FA1F143D41B3241F7FCE5F6, 4140BE0ECE0D4B8FDD413DBA120F5D7EF6F94628224320EDA2A85E50BEFDA638 ] SamSs C:\Windows\system32\lsass.exe
12:38:30.0853 0x0dd0 SamSs - ok
12:38:30.0884 0x0dd0 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
12:38:30.0884 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sbp2port.sys. md5: 05D860DA1040F111503AC416CCEF2BCA, sha256: DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E
12:38:30.0884 0x0dd0 sbp2port - detected LockedFile.Multi.Generic ( 1 )
12:38:30.0884 0x0dd0 Object is SCO, delete is not allowed
12:38:30.0884 0x0dd0 sbp2port ( LockedFile.Multi.Generic ) - warning
12:38:30.0916 0x0dd0 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll
12:38:30.0978 0x0dd0 SCardSvr - ok
12:38:31.0009 0x0dd0 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
12:38:31.0009 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\scfilter.sys. md5: 0693B5EC673E34DC147E195779A4DCF6, sha256: AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670
12:38:31.0009 0x0dd0 scfilter - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0009 0x0dd0 scfilter ( LockedFile.Multi.Generic ) - warning
12:38:31.0009 0x0dd0 Force sending object to P2P due to detect: scfilter
12:38:31.0009 0x0dd0 Object send P2P result: false
12:38:31.0087 0x0dd0 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll
12:38:31.0165 0x0dd0 Schedule - ok
12:38:31.0181 0x0dd0 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll
12:38:31.0212 0x0dd0 SCPolicySvc - ok
12:38:31.0243 0x0dd0 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll
12:38:31.0290 0x0dd0 SDRSVC - ok
12:38:31.0321 0x0dd0 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
12:38:31.0321 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\secdrv.sys. md5: 90A3935D05B494A5A39D37E71F09A677, sha256: F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952
12:38:31.0321 0x0dd0 secdrv - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0321 0x0dd0 secdrv ( LockedFile.Multi.Generic ) - warning
12:38:31.0368 0x0dd0 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
12:38:31.0415 0x0dd0 seclogon - ok
12:38:31.0446 0x0dd0 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll
12:38:31.0477 0x0dd0 SENS - ok
12:38:31.0508 0x0dd0 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
12:38:31.0571 0x0dd0 SensrSvc - ok
12:38:31.0586 0x0dd0 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
12:38:31.0586 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\serenum.sys. md5: 9AD8B8B515E3DF6ACD4212EF465DE2D1, sha256: E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86
12:38:31.0586 0x0dd0 Serenum - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0586 0x0dd0 Object is SCO, delete is not allowed
12:38:31.0586 0x0dd0 Serenum ( LockedFile.Multi.Generic ) - warning
12:38:31.0618 0x0dd0 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
12:38:31.0618 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\serial.sys. md5: 5FB7FCEA0490D821F26F39CC5EA3D1E2, sha256: A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F
12:38:31.0618 0x0dd0 Serial - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0618 0x0dd0 Object is SCO, delete is not allowed
12:38:31.0618 0x0dd0 Serial ( LockedFile.Multi.Generic ) - warning
12:38:31.0618 0x0dd0 Force sending object to P2P due to detect: Serial
12:38:31.0618 0x0dd0 Object send P2P result: false
12:38:31.0649 0x0dd0 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
12:38:31.0649 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\sermouse.sys. md5: 79BFFB520327FF916A582DFEA17AA813, sha256: 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C
12:38:31.0649 0x0dd0 sermouse - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0649 0x0dd0 Object is SCO, delete is not allowed
12:38:31.0649 0x0dd0 sermouse ( LockedFile.Multi.Generic ) - warning
12:38:31.0696 0x0dd0 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll
12:38:31.0742 0x0dd0 SessionEnv - ok
12:38:31.0774 0x0dd0 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
12:38:31.0774 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffdisk.sys. md5: 9F976E1EB233DF46FCE808D9DEA3EB9C, sha256: 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75
12:38:31.0774 0x0dd0 sffdisk - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0774 0x0dd0 Object is SCO, delete is not allowed
12:38:31.0774 0x0dd0 sffdisk ( LockedFile.Multi.Generic ) - warning
12:38:31.0789 0x0dd0 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
12:38:31.0789 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffp_mmc.sys. md5: 932A68EE27833CFD57C1639D375F2731, sha256: 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3
12:38:31.0789 0x0dd0 sffp_mmc - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0789 0x0dd0 Object is SCO, delete is not allowed
12:38:31.0789 0x0dd0 sffp_mmc ( LockedFile.Multi.Generic ) - warning
12:38:31.0789 0x0dd0 Force sending object to P2P due to detect: sffp_mmc
12:38:31.0789 0x0dd0 Object send P2P result: false
12:38:31.0789 0x0dd0 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
12:38:31.0805 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffp_sd.sys. md5: 6D4CCAEDC018F1CF52866BBBAA235982, sha256: AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131
12:38:31.0805 0x0dd0 sffp_sd - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0805 0x0dd0 Object is SCO, delete is not allowed
12:38:31.0805 0x0dd0 sffp_sd ( LockedFile.Multi.Generic ) - warning
12:38:31.0805 0x0dd0 Force sending object to P2P due to detect: sffp_sd
12:38:31.0805 0x0dd0 Object send P2P result: false
12:38:31.0820 0x0dd0 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
12:38:31.0820 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\sfloppy.sys. md5: DB96666CC8312EBC45032F30B007A547, sha256: C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7
12:38:31.0820 0x0dd0 sfloppy - detected LockedFile.Multi.Generic ( 1 )
12:38:31.0820 0x0dd0 Object is SCO, delete is not allowed
12:38:31.0820 0x0dd0 sfloppy ( LockedFile.Multi.Generic ) - warning
12:38:31.0820 0x0dd0 Force sending object to P2P due to detect: sfloppy
12:38:31.0836 0x0dd0 Object send P2P result: false
12:38:31.0883 0x0dd0 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
12:38:31.0961 0x0dd0 SharedAccess - ok
12:38:32.0023 0x0dd0 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:38:32.0086 0x0dd0 ShellHWDetection - ok
12:38:32.0086 0x0dd0 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys
12:38:32.0086 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sisagp.sys. md5: 2565CAC0DC9FE0371BDCE60832582B2E, sha256: 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D
12:38:32.0086 0x0dd0 sisagp - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0086 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0086 0x0dd0 sisagp ( LockedFile.Multi.Generic ) - warning
12:38:32.0086 0x0dd0 Force sending object to P2P due to detect: sisagp
12:38:32.0086 0x0dd0 Object send P2P result: false
12:38:32.0132 0x0dd0 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:38:32.0132 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\SiSRaid2.sys. md5: A9F0486851BECB6DDA1D89D381E71055, sha256: 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35
12:38:32.0132 0x0dd0 SiSRaid2 - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0132 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0132 0x0dd0 SiSRaid2 ( LockedFile.Multi.Generic ) - warning
12:38:32.0148 0x0dd0 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
12:38:32.0148 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\sisraid4.sys. md5: 3727097B55738E2F554972C3BE5BC1AA, sha256: 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566
12:38:32.0148 0x0dd0 SiSRaid4 - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0148 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0148 0x0dd0 SiSRaid4 ( LockedFile.Multi.Generic ) - warning
12:38:32.0148 0x0dd0 Force sending object to P2P due to detect: SiSRaid4
12:38:32.0148 0x0dd0 Object send P2P result: false
12:38:32.0179 0x0dd0 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
12:38:32.0179 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\smb.sys. md5: 3E21C083B8A01CB70BA1F09303010FCE, sha256: 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197
12:38:32.0179 0x0dd0 Smb - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0179 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0179 0x0dd0 Smb ( LockedFile.Multi.Generic ) - warning
12:38:32.0179 0x0dd0 Force sending object to P2P due to detect: Smb
12:38:32.0179 0x0dd0 Object send P2P result: false
12:38:32.0210 0x0dd0 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
12:38:32.0257 0x0dd0 SNMPTRAP - ok
12:38:32.0273 0x0dd0 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
12:38:32.0273 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\spldr.sys. md5: 95CF1AE7527FB70F7816563CBC09D942, sha256: CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65
12:38:32.0273 0x0dd0 spldr - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0273 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0273 0x0dd0 spldr ( LockedFile.Multi.Generic ) - warning
12:38:32.0273 0x0dd0 Force sending object to P2P due to detect: spldr
12:38:32.0273 0x0dd0 Object send P2P result: false
12:38:32.0320 0x0dd0 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\Windows\System32\spoolsv.exe
12:38:32.0382 0x0dd0 Spooler - ok
12:38:32.0554 0x0dd0 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe
12:38:32.0678 0x0dd0 sppsvc - ok
12:38:32.0725 0x0dd0 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll
12:38:32.0772 0x0dd0 sppuinotify - ok
12:38:32.0819 0x0dd0 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\Windows\system32\DRIVERS\srv.sys
12:38:32.0819 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\srv.sys. md5: E4C2764065D66EA1D2D3EBC28FE99C46, sha256: 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5
12:38:32.0819 0x0dd0 srv - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0819 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0819 0x0dd0 srv ( LockedFile.Multi.Generic ) - warning
12:38:32.0850 0x0dd0 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
12:38:32.0850 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\srv2.sys. md5: 03F0545BD8D4C77FA0AE1CEEDFCC71AB, sha256: 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0
12:38:32.0850 0x0dd0 srv2 - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0850 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0850 0x0dd0 srv2 ( LockedFile.Multi.Generic ) - warning
12:38:32.0866 0x0dd0 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
12:38:32.0866 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\srvnet.sys. md5: BE6BD660CAA6F291AE06A718A4FA8ABC, sha256: CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59
12:38:32.0866 0x0dd0 srvnet - detected LockedFile.Multi.Generic ( 1 )
12:38:32.0866 0x0dd0 Object is SCO, delete is not allowed
12:38:32.0866 0x0dd0 srvnet ( LockedFile.Multi.Generic ) - warning
12:38:32.0897 0x0dd0 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
12:38:32.0944 0x0dd0 SSDPSRV - ok
12:38:32.0975 0x0dd0 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
12:38:32.0990 0x0dd0 SstpSvc - ok
12:38:33.0084 0x0dd0 [ 5A19667A580B1CE886EAF968B9743F45, 0A9EBE4057A0A6EF4732623794C2416A6BD8B87356DA46652BD92762505F57C7 ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
12:38:33.0100 0x0dd0 Stereo Service - ok
12:38:33.0131 0x0dd0 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
12:38:33.0131 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\stexstor.sys. md5: DB32D325C192B801DF274BFD12A7E72B, sha256: F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA
12:38:33.0146 0x0dd0 stexstor - detected LockedFile.Multi.Generic ( 1 )
12:38:33.0146 0x0dd0 stexstor ( LockedFile.Multi.Generic ) - warning
12:38:33.0146 0x0dd0 Force sending object to P2P due to detect: stexstor
12:38:33.0146 0x0dd0 Object send P2P result: false
12:38:33.0209 0x0dd0 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll
12:38:33.0271 0x0dd0 StiSvc - ok
12:38:33.0302 0x0dd0 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\drivers\swenum.sys
12:38:33.0318 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\swenum.sys. md5: E58C78A848ADD9610A4DB6D214AF5224, sha256: 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426
12:38:33.0318 0x0dd0 swenum - detected LockedFile.Multi.Generic ( 1 )
12:38:33.0318 0x0dd0 Object is SCO, delete is not allowed
12:38:33.0318 0x0dd0 swenum ( LockedFile.Multi.Generic ) - warning
12:38:33.0318 0x0dd0 Force sending object to P2P due to detect: swenum
12:38:33.0334 0x0dd0 Object send P2P result: false
12:38:33.0365 0x0dd0 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
12:38:33.0412 0x0dd0 swprv - ok
12:38:33.0505 0x0dd0 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll
12:38:33.0583 0x0dd0 SysMain - ok
12:38:33.0630 0x0dd0 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
12:38:33.0661 0x0dd0 TabletInputService - ok
12:38:33.0692 0x0dd0 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll
12:38:33.0739 0x0dd0 TapiSrv - ok
12:38:33.0770 0x0dd0 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
12:38:33.0802 0x0dd0 TBS - ok
12:38:33.0926 0x0dd0 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
12:38:33.0926 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tcpip.sys. md5: 5579DD18546999F5D0EC39D018726C6B, sha256: 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3
12:38:33.0942 0x0dd0 Tcpip - detected LockedFile.Multi.Generic ( 1 )
12:38:33.0942 0x0dd0 Object is SCO, delete is not allowed
12:38:33.0942 0x0dd0 Tcpip ( LockedFile.Multi.Generic ) - warning
12:38:33.0942 0x0dd0 Force sending object to P2P due to detect: Tcpip
12:38:33.0942 0x0dd0 Object send P2P result: false
12:38:34.0020 0x0dd0 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
12:38:34.0020 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tcpip.sys. md5: 5579DD18546999F5D0EC39D018726C6B, sha256: 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3
12:38:34.0020 0x0dd0 TCPIP6 - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0020 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0020 0x0dd0 TCPIP6 ( LockedFile.Multi.Generic ) - warning
12:38:34.0051 0x0dd0 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
12:38:34.0051 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tcpipreg.sys. md5: 3EEBD3BD93DA46A26E89893C7AB2FF3B, sha256: 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E
12:38:34.0067 0x0dd0 tcpipreg - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0067 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0067 0x0dd0 tcpipreg ( LockedFile.Multi.Generic ) - warning
12:38:34.0082 0x0dd0 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
12:38:34.0082 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tdpipe.sys. md5: 1CB91B2BD8F6DD367DFC2EF26FD751B2, sha256: 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954
12:38:34.0082 0x0dd0 TDPIPE - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0082 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0082 0x0dd0 TDPIPE ( LockedFile.Multi.Generic ) - warning
12:38:34.0114 0x0dd0 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
12:38:34.0114 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tdtcp.sys. md5: 2C2C5AFE7EE4F620D69C23C0617651A8, sha256: E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103
12:38:34.0114 0x0dd0 TDTCP - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0114 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0114 0x0dd0 TDTCP ( LockedFile.Multi.Generic ) - warning
12:38:34.0114 0x0dd0 Force sending object to P2P due to detect: TDTCP
12:38:34.0114 0x0dd0 Object send P2P result: false
12:38:34.0145 0x0dd0 [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx C:\Windows\system32\DRIVERS\tdx.sys
12:38:34.0145 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tdx.sys. md5: 7FE680A3DFA421C4A8E4879AE4C5AAB0, sha256: A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD
12:38:34.0145 0x0dd0 tdx - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0145 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0145 0x0dd0 tdx ( LockedFile.Multi.Generic ) - warning
12:38:34.0160 0x0dd0 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\drivers\termdd.sys
12:38:34.0160 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\termdd.sys. md5: 04DBF4B01EA4BF25A9A3E84AFFAC9B20, sha256: 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663
12:38:34.0160 0x0dd0 TermDD - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0160 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0160 0x0dd0 TermDD ( LockedFile.Multi.Generic ) - warning
12:38:34.0238 0x0dd0 [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService C:\Windows\System32\termsrv.dll
12:38:34.0316 0x0dd0 TermService - ok
12:38:34.0348 0x0dd0 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll
12:38:34.0379 0x0dd0 Themes - ok
12:38:34.0410 0x0dd0 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
12:38:34.0426 0x0dd0 THREADORDER - ok
12:38:34.0457 0x0dd0 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
12:38:34.0504 0x0dd0 TrkWks - ok
12:38:34.0566 0x0dd0 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:38:34.0613 0x0dd0 TrustedInstaller - ok
12:38:34.0660 0x0dd0 [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
12:38:34.0660 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tssecsrv.sys. md5: 6C5139E4283249518F7743D7043775B3, sha256: 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F
12:38:34.0660 0x0dd0 tssecsrv - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0660 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0660 0x0dd0 tssecsrv ( LockedFile.Multi.Generic ) - warning
12:38:34.0660 0x0dd0 Force sending object to P2P due to detect: tssecsrv
12:38:34.0660 0x0dd0 Object send P2P result: false
12:38:34.0706 0x0dd0 [ FD1D6C73E6333BE727CBCC6054247654, 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
12:38:34.0706 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tsusbflt.sys. md5: FD1D6C73E6333BE727CBCC6054247654, sha256: 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E
12:38:34.0706 0x0dd0 TsUsbFlt - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0706 0x0dd0 TsUsbFlt ( LockedFile.Multi.Generic ) - warning
12:38:34.0769 0x0dd0 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
12:38:34.0769 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tunnel.sys. md5: B2FA25D9B17A68BB93D58B0556E8C90D, sha256: 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE
12:38:34.0769 0x0dd0 tunnel - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0769 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0769 0x0dd0 tunnel ( LockedFile.Multi.Generic ) - warning
12:38:34.0769 0x0dd0 Force sending object to P2P due to detect: tunnel
12:38:34.0769 0x0dd0 Object send P2P result: false
12:38:34.0800 0x0dd0 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
12:38:34.0800 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\uagp35.sys. md5: 750FBCB269F4D7DD2E420C56B795DB6D, sha256: E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7
12:38:34.0800 0x0dd0 uagp35 - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0800 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0800 0x0dd0 uagp35 ( LockedFile.Multi.Generic ) - warning
12:38:34.0831 0x0dd0 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
12:38:34.0831 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\udfs.sys. md5: EE43346C7E4B5E63E54F927BABBB32FF, sha256: BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9
12:38:34.0831 0x0dd0 udfs - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0831 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0831 0x0dd0 udfs ( LockedFile.Multi.Generic ) - warning
12:38:34.0862 0x0dd0 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
12:38:34.0878 0x0dd0 UI0Detect - ok
12:38:34.0925 0x0dd0 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
12:38:34.0925 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\uliagpkx.sys. md5: 44E8048ACE47BEFBFDC2E9BE4CBC8880, sha256: 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C
12:38:34.0925 0x0dd0 uliagpkx - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0925 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0925 0x0dd0 uliagpkx ( LockedFile.Multi.Generic ) - warning
12:38:34.0956 0x0dd0 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\drivers\umbus.sys
12:38:34.0956 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\umbus.sys. md5: D295BED4B898F0FD999FCFA9B32B071B, sha256: D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2
12:38:34.0972 0x0dd0 umbus - detected LockedFile.Multi.Generic ( 1 )
12:38:34.0972 0x0dd0 Object is SCO, delete is not allowed
12:38:34.0972 0x0dd0 umbus ( LockedFile.Multi.Generic ) - warning
12:38:34.0972 0x0dd0 Force sending object to P2P due to detect: umbus
12:38:34.0972 0x0dd0 Object send P2P result: false
12:38:35.0003 0x0dd0 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
12:38:35.0003 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\umpass.sys. md5: 7550AD0C6998BA1CB4843E920EE0FEAC, sha256: 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D
12:38:35.0003 0x0dd0 UmPass - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0003 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0003 0x0dd0 UmPass ( LockedFile.Multi.Generic ) - warning
12:38:35.0003 0x0dd0 Force sending object to P2P due to detect: UmPass
12:38:35.0003 0x0dd0 Object send P2P result: false
12:38:35.0050 0x0dd0 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
12:38:35.0128 0x0dd0 upnphost - ok
12:38:35.0159 0x0dd0 [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
12:38:35.0159 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbccgp.sys. md5: 0803FBA9FE829D61AE26EC0BCC910C46, sha256: 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B
12:38:35.0159 0x0dd0 usbccgp - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0159 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0159 0x0dd0 usbccgp ( LockedFile.Multi.Generic ) - warning
12:38:35.0190 0x0dd0 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys
12:38:35.0190 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\usbcir.sys. md5: 2352AB5F9F8F097BF9D41D5A4718A041, sha256: 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C
12:38:35.0190 0x0dd0 usbcir - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0190 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0190 0x0dd0 usbcir ( LockedFile.Multi.Generic ) - warning
12:38:35.0221 0x0dd0 [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
12:38:35.0221 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbehci.sys. md5: D40855F89B69305140BBD7E9A3BA2DA6, sha256: 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C
12:38:35.0221 0x0dd0 usbehci - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0221 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0221 0x0dd0 usbehci ( LockedFile.Multi.Generic ) - warning
12:38:35.0221 0x0dd0 Force sending object to P2P due to detect: usbehci
12:38:35.0221 0x0dd0 Object send P2P result: false
12:38:35.0284 0x0dd0 [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
12:38:35.0284 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbhub.sys. md5: EDF2DF71C4F1E13A6AC75F5224DE655A, sha256: 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C
12:38:35.0284 0x0dd0 usbhub - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0284 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0284 0x0dd0 usbhub ( LockedFile.Multi.Generic ) - warning
12:38:35.0284 0x0dd0 Force sending object to P2P due to detect: usbhub
12:38:35.0284 0x0dd0 Object send P2P result: false
12:38:35.0330 0x0dd0 [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
12:38:35.0330 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbohci.sys. md5: 9828C8D14CC2676421778F0DE638CF97, sha256: 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453
12:38:35.0330 0x0dd0 usbohci - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0330 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0330 0x0dd0 usbohci ( LockedFile.Multi.Generic ) - warning
12:38:35.0330 0x0dd0 Force sending object to P2P due to detect: usbohci
12:38:35.0330 0x0dd0 Object send P2P result: false
12:38:35.0362 0x0dd0 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
12:38:35.0362 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbprint.sys. md5: 797D862FE0875E75C7CC4C1AD7B30252, sha256: 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069
12:38:35.0362 0x0dd0 usbprint - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0362 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0362 0x0dd0 usbprint ( LockedFile.Multi.Generic ) - warning
12:38:35.0393 0x0dd0 [ 576096CCBC07E7C4EA4F5E6686D6888F, 8C643F43BD0017979548389C4DB36A1EE872CCF19C86FAE3752A4989173E28ED ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
12:38:35.0393 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbscan.sys. md5: 576096CCBC07E7C4EA4F5E6686D6888F, sha256: 8C643F43BD0017979548389C4DB36A1EE872CCF19C86FAE3752A4989173E28ED
12:38:35.0393 0x0dd0 usbscan - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0393 0x0dd0 usbscan ( LockedFile.Multi.Generic ) - warning
12:38:35.0393 0x0dd0 Force sending object to P2P due to detect: usbscan
12:38:35.0408 0x0dd0 Object send P2P result: false
12:38:35.0440 0x0dd0 [ 007C0C8D5B01D82ACEB70431D15083F6, 7EAF68CD3C38D3CD2CDFEE9ECE1DFB38E274F1F9E6F70B73BCE1336E87D5496C ] usbser C:\Windows\system32\DRIVERS\usbser.sys
12:38:35.0440 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbser.sys. md5: 007C0C8D5B01D82ACEB70431D15083F6, sha256: 7EAF68CD3C38D3CD2CDFEE9ECE1DFB38E274F1F9E6F70B73BCE1336E87D5496C
12:38:35.0440 0x0dd0 usbser - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0440 0x0dd0 usbser ( LockedFile.Multi.Generic ) - warning
12:38:35.0471 0x0dd0 [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\Windows\system32\drivers\USBSTOR.SYS
12:38:35.0471 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\USBSTOR.SYS. md5: F991AB9CC6B908DB552166768176896A, sha256: AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026
12:38:35.0471 0x0dd0 USBSTOR - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0471 0x0dd0 USBSTOR ( LockedFile.Multi.Generic ) - warning
12:38:35.0502 0x0dd0 [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
12:38:35.0502 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\usbuhci.sys. md5: 800AABFD625EEFF899F7E5496BDE37AB, sha256: 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2
12:38:35.0502 0x0dd0 usbuhci - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0502 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0502 0x0dd0 usbuhci ( LockedFile.Multi.Generic ) - warning
12:38:35.0533 0x0dd0 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
12:38:35.0596 0x0dd0 UxSms - ok
12:38:35.0611 0x0dd0 [ BF08DE8E4FA1F143D41B3241F7FCE5F6, 4140BE0ECE0D4B8FDD413DBA120F5D7EF6F94628224320EDA2A85E50BEFDA638 ] VaultSvc C:\Windows\system32\lsass.exe
12:38:35.0627 0x0dd0 VaultSvc - ok
12:38:35.0658 0x0dd0 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
12:38:35.0658 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vdrvroot.sys. md5: A059C4C3EDB09E07D21A8E5C0AABD3CB, sha256: BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07
12:38:35.0658 0x0dd0 vdrvroot - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0658 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0658 0x0dd0 vdrvroot ( LockedFile.Multi.Generic ) - warning
12:38:35.0720 0x0dd0 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe
12:38:35.0783 0x0dd0 vds - ok
12:38:35.0814 0x0dd0 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
12:38:35.0814 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\vgapnp.sys. md5: 17C408214EA61696CEC9C66E388B14F3, sha256: 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97
12:38:35.0814 0x0dd0 vga - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0814 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0814 0x0dd0 vga ( LockedFile.Multi.Generic ) - warning
12:38:35.0830 0x0dd0 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
12:38:35.0830 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\System32\drivers\vga.sys. md5: 8E38096AD5C8570A6F1570A61E251561, sha256: 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39
12:38:35.0830 0x0dd0 VgaSave - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0830 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0830 0x0dd0 VgaSave ( LockedFile.Multi.Generic ) - warning
12:38:35.0876 0x0dd0 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
12:38:35.0876 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vhdmp.sys. md5: 5461686CCA2FDA57B024547733AB42E3, sha256: 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84
12:38:35.0876 0x0dd0 vhdmp - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0876 0x0dd0 vhdmp ( LockedFile.Multi.Generic ) - warning
12:38:35.0876 0x0dd0 Force sending object to P2P due to detect: vhdmp
12:38:35.0876 0x0dd0 Object send P2P result: false
12:38:35.0923 0x0dd0 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys
12:38:35.0923 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viaagp.sys. md5: C829317A37B4BEA8F39735D4B076E923, sha256: 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497
12:38:35.0923 0x0dd0 viaagp - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0923 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0923 0x0dd0 viaagp ( LockedFile.Multi.Generic ) - warning
12:38:35.0954 0x0dd0 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
12:38:35.0954 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\viac7.sys. md5: E02F079A6AA107F06B16549C6E5C7B74, sha256: B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788
12:38:35.0954 0x0dd0 ViaC7 - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0954 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0954 0x0dd0 ViaC7 ( LockedFile.Multi.Generic ) - warning
12:38:35.0986 0x0dd0 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys
12:38:35.0986 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viaide.sys. md5: E43574F6A56A0EE11809B48C09E4FD3C, sha256: 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9
12:38:35.0986 0x0dd0 viaide - detected LockedFile.Multi.Generic ( 1 )
12:38:35.0986 0x0dd0 Object is SCO, delete is not allowed
12:38:35.0986 0x0dd0 viaide ( LockedFile.Multi.Generic ) - warning
12:38:35.0986 0x0dd0 Force sending object to P2P due to detect: viaide
12:38:35.0986 0x0dd0 Object send P2P result: false
12:38:36.0017 0x0dd0 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys
12:38:36.0017 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volmgr.sys. md5: 4C63E00F2F4B5F86AB48A58CD990F212, sha256: 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035
12:38:36.0017 0x0dd0 volmgr - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0017 0x0dd0 Object is SCO, delete is not allowed
12:38:36.0017 0x0dd0 volmgr ( LockedFile.Multi.Generic ) - warning
12:38:36.0017 0x0dd0 Force sending object to P2P due to detect: volmgr
12:38:36.0017 0x0dd0 Object send P2P result: false
12:38:36.0048 0x0dd0 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
12:38:36.0048 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volmgrx.sys. md5: B5BB72067DDDDBBFB04B2F89FF8C3C87, sha256: 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC
12:38:36.0048 0x0dd0 volmgrx - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0048 0x0dd0 Object is SCO, delete is not allowed
12:38:36.0048 0x0dd0 volmgrx ( LockedFile.Multi.Generic ) - warning
12:38:36.0048 0x0dd0 Force sending object to P2P due to detect: volmgrx
12:38:36.0048 0x0dd0 Object send P2P result: false
12:38:36.0095 0x0dd0 [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys
12:38:36.0095 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volsnap.sys. md5: F497F67932C6FA693D7DE2780631CFE7, sha256: DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6
12:38:36.0095 0x0dd0 volsnap - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0095 0x0dd0 Object is SCO, delete is not allowed
12:38:36.0095 0x0dd0 volsnap ( LockedFile.Multi.Generic ) - warning
12:38:36.0095 0x0dd0 Force sending object to P2P due to detect: volsnap
12:38:36.0095 0x0dd0 Object send P2P result: false
12:38:36.0126 0x0dd0 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
12:38:36.0126 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\vsmraid.sys. md5: 9DFA0CC2F8855A04816729651175B631, sha256: 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3
12:38:36.0126 0x0dd0 vsmraid - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0126 0x0dd0 Object is SCO, delete is not allowed
12:38:36.0126 0x0dd0 vsmraid ( LockedFile.Multi.Generic ) - warning
12:38:36.0220 0x0dd0 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe
12:38:36.0329 0x0dd0 VSS - ok
12:38:36.0360 0x0dd0 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
12:38:36.0360 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\System32\drivers\vwifibus.sys. md5: 90567B1E658001E79D7C8BBD3DDE5AA6, sha256: EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557
12:38:36.0360 0x0dd0 vwifibus - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0360 0x0dd0 vwifibus ( LockedFile.Multi.Generic ) - warning
12:38:36.0360 0x0dd0 Force sending object to P2P due to detect: vwifibus
12:38:36.0360 0x0dd0 Object send P2P result: false
12:38:36.0422 0x0dd0 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
12:38:36.0485 0x0dd0 W32Time - ok
12:38:36.0516 0x0dd0 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
12:38:36.0516 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wacompen.sys. md5: DE3721E89C653AA281428C8A69745D90, sha256: 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516
12:38:36.0516 0x0dd0 WacomPen - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0516 0x0dd0 Object is SCO, delete is not allowed
12:38:36.0516 0x0dd0 WacomPen ( LockedFile.Multi.Generic ) - warning
12:38:36.0516 0x0dd0 Force sending object to P2P due to detect: WacomPen
12:38:36.0516 0x0dd0 Object send P2P result: false
12:38:36.0563 0x0dd0 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
12:38:36.0563 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wanarp.sys. md5: 3C3C78515F5AB448B022BDF5B8FFDD2E, sha256: 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7
12:38:36.0563 0x0dd0 WANARP - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0563 0x0dd0 Object is SCO, delete is not allowed
12:38:36.0563 0x0dd0 WANARP ( LockedFile.Multi.Generic ) - warning
12:38:36.0563 0x0dd0 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
12:38:36.0563 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wanarp.sys. md5: 3C3C78515F5AB448B022BDF5B8FFDD2E, sha256: 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7
12:38:36.0563 0x0dd0 Wanarpv6 - detected LockedFile.Multi.Generic ( 1 )
12:38:36.0563 0x0dd0 Object is SCO, delete is not allowed
12:38:36.0563 0x0dd0 Wanarpv6 ( LockedFile.Multi.Generic ) - warning
12:38:36.0563 0x0dd0 Force sending object to P2P due to detect: Wanarpv6
12:38:36.0563 0x0dd0 Object send P2P result: false
12:38:36.0672 0x0dd0 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe
12:38:36.0781 0x0dd0 wbengine - ok
12:38:36.0828 0x0dd0 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
12:38:36.0859 0x0dd0 WbioSrvc - ok
12:38:36.0890 0x0dd0 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll
12:38:36.0922 0x0dd0 wcncsvc - ok
12:38:36.0937 0x0dd0 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:38:36.0953 0x0dd0 WcsPlugInService - ok
12:38:37.0000 0x0dd0 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys
12:38:37.0000 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wd.sys. md5: 1112A9BADACB47B7C0BB0392E3158DFF, sha256: 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4
12:38:37.0000 0x0dd0 Wd - detected LockedFile.Multi.Generic ( 1 )
12:38:37.0000 0x0dd0 Object is SCO, delete is not allowed
12:38:37.0000 0x0dd0 Wd ( LockedFile.Multi.Generic ) - warning
12:38:37.0062 0x0dd0 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
12:38:37.0062 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Wdf01000.sys. md5: 25944D2CC49E0A6C581D02A74B7D6645, sha256: AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE
12:38:37.0062 0x0dd0 Wdf01000 - detected LockedFile.Multi.Generic ( 1 )
12:38:37.0062 0x0dd0 Object is SCO, delete is not allowed
12:38:37.0062 0x0dd0 Wdf01000 ( LockedFile.Multi.Generic ) - warning
12:38:37.0062 0x0dd0 Force sending object to P2P due to detect: Wdf01000
12:38:37.0078 0x0dd0 Object send P2P result: false
12:38:37.0093 0x0dd0 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll
12:38:37.0187 0x0dd0 WdiServiceHost - ok
12:38:37.0187 0x0dd0 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\system32\wdi.dll
12:38:37.0202 0x0dd0 WdiSystemHost - ok
12:38:37.0234 0x0dd0 [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\Windows\System32\webclnt.dll
12:38:37.0265 0x0dd0 WebClient - ok
12:38:37.0312 0x0dd0 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
12:38:37.0358 0x0dd0 Wecsvc - ok
12:38:37.0374 0x0dd0 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
12:38:37.0421 0x0dd0 wercplsupport - ok
12:38:37.0452 0x0dd0 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
12:38:37.0483 0x0dd0 WerSvc - ok
12:38:37.0530 0x0dd0 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
12:38:37.0530 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wfplwf.sys. md5: 8B9A943F3B53861F2BFAF6C186168F79, sha256: 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713
12:38:37.0530 0x0dd0 WfpLwf - detected LockedFile.Multi.Generic ( 1 )
12:38:37.0530 0x0dd0 WfpLwf ( LockedFile.Multi.Generic ) - warning
12:38:37.0530 0x0dd0 Force sending object to P2P due to detect: WfpLwf
12:38:37.0530 0x0dd0 Object send P2P result: false
12:38:37.0546 0x0dd0 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
12:38:37.0546 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wimmount.sys. md5: 5CF95B35E59E2A38023836FFF31BE64C, sha256: CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D
12:38:37.0546 0x0dd0 WIMMount - detected LockedFile.Multi.Generic ( 1 )
12:38:37.0546 0x0dd0 WIMMount ( LockedFile.Multi.Generic ) - warning
12:38:37.0639 0x0dd0 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
12:38:37.0733 0x0dd0 WinDefend - ok
12:38:37.0764 0x0dd0 WinHttpAutoProxySvc - ok
12:38:37.0826 0x0dd0 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
12:38:37.0889 0x0dd0 Winmgmt - ok
12:38:37.0998 0x0dd0 [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM C:\Windows\system32\WsmSvc.dll
12:38:38.0107 0x0dd0 WinRM - ok
12:38:38.0154 0x0dd0 [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
12:38:38.0154 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\WinUsb.sys. md5: A67E5F9A400F3BD1BE3D80613B45F708, sha256: E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367
12:38:38.0154 0x0dd0 WinUsb - detected LockedFile.Multi.Generic ( 1 )
12:38:38.0154 0x0dd0 WinUsb ( LockedFile.Multi.Generic ) - warning
12:38:38.0154 0x0dd0 Force sending object to P2P due to detect: WinUsb
12:38:38.0154 0x0dd0 Object send P2P result: false
12:38:38.0232 0x0dd0 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
12:38:38.0263 0x0dd0 Wlansvc - ok
12:38:38.0310 0x0dd0 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
12:38:38.0310 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wmiacpi.sys. md5: 0217679B8FCA58714C3BF2726D2CA84E, sha256: 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A
12:38:38.0310 0x0dd0 WmiAcpi - detected LockedFile.Multi.Generic ( 1 )
12:38:38.0310 0x0dd0 Object is SCO, delete is not allowed
12:38:38.0310 0x0dd0 WmiAcpi ( LockedFile.Multi.Generic ) - warning
12:38:38.0341 0x0dd0 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
12:38:38.0388 0x0dd0 wmiApSrv - ok
12:38:38.0513 0x0dd0 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
12:38:38.0575 0x0dd0 WMPNetworkSvc - ok
12:38:38.0606 0x0dd0 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
12:38:38.0653 0x0dd0 WPCSvc - ok
12:38:38.0684 0x0dd0 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
12:38:38.0731 0x0dd0 WPDBusEnum - ok
12:38:38.0762 0x0dd0 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
12:38:38.0762 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ws2ifsl.sys. md5: 6DB3276587B853BF886B69528FDB048C, sha256: 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C
12:38:38.0762 0x0dd0 ws2ifsl - detected LockedFile.Multi.Generic ( 1 )
12:38:38.0762 0x0dd0 Object is SCO, delete is not allowed
12:38:38.0762 0x0dd0 ws2ifsl ( LockedFile.Multi.Generic ) - warning
12:38:38.0762 0x0dd0 Force sending object to P2P due to detect: ws2ifsl
12:38:38.0778 0x0dd0 Object send P2P result: false
12:38:38.0794 0x0dd0 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\System32\wscsvc.dll
12:38:38.0825 0x0dd0 wscsvc - ok
12:38:38.0825 0x0dd0 WSearch - ok
12:38:38.0981 0x0dd0 [ D9B0134913E5EF007AF82A418C503322, 7418DD28C8E968674382F8352AAFFC4DE77887E2B71B8844D615F19432B4C55A ] wuauserv C:\Windows\system32\wuaueng.dll
12:38:39.0043 0x0dd0 wuauserv - ok
12:38:39.0090 0x0dd0 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
12:38:39.0090 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\WudfPf.sys. md5: 06E6F32C8D0A3F66D956F57B43A2E070, sha256: 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943
12:38:39.0090 0x0dd0 WudfPf - detected LockedFile.Multi.Generic ( 1 )
12:38:39.0090 0x0dd0 Object is SCO, delete is not allowed
12:38:39.0090 0x0dd0 WudfPf ( LockedFile.Multi.Generic ) - warning
12:38:39.0090 0x0dd0 Force sending object to P2P due to detect: WudfPf
12:38:39.0090 0x0dd0 Object send P2P result: false
12:38:39.0106 0x0dd0 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
12:38:39.0106 0x0dd0 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\WUDFRd.sys. md5: 867C301E8B790040AE9CF6486E8041DF, sha256: D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855
12:38:39.0106 0x0dd0 WUDFRd - detected LockedFile.Multi.Generic ( 1 )
12:38:39.0106 0x0dd0 Object is SCO, delete is not allowed
12:38:39.0106 0x0dd0 WUDFRd ( LockedFile.Multi.Generic ) - warning
12:38:39.0106 0x0dd0 Force sending object to P2P due to detect: WUDFRd
12:38:39.0121 0x0dd0 Object send P2P result: false
12:38:39.0152 0x0dd0 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
12:38:39.0199 0x0dd0 wudfsvc - ok
12:38:39.0230 0x0dd0 [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc C:\Windows\System32\wwansvc.dll
12:38:39.0293 0x0dd0 WwanSvc - ok
12:38:39.0324 0x0dd0 ================ Scan global ===============================
12:38:39.0355 0x0dd0 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
12:38:39.0386 0x0dd0 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
12:38:39.0418 0x0dd0 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
12:38:39.0449 0x0dd0 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
12:38:39.0480 0x0dd0 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
12:38:39.0496 0x0dd0 [ Global ] - ok
12:38:39.0496 0x0dd0 ================ Scan MBR ==================================
12:38:39.0511 0x0dd0 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
12:38:39.0683 0x0dd0 \Device\Harddisk0\DR0 - ok
12:38:39.0683 0x0dd0 ================ Scan VBR ==================================
12:38:39.0683 0x0dd0 [ FA6446873707FE19EAA751E6F3BFA568 ] \Device\Harddisk0\DR0\Partition1
12:38:39.0683 0x0dd0 \Device\Harddisk0\DR0\Partition1 - ok
12:38:39.0714 0x0dd0 [ 086FB0FB9F4BA3DD31E6CF289DC97C22 ] \Device\Harddisk0\DR0\Partition2
12:38:39.0714 0x0dd0 \Device\Harddisk0\DR0\Partition2 - ok
12:38:39.0714 0x0dd0 ================ Scan generic autorun ======================
12:38:39.0761 0x0dd0 [ C26DC901D106AB96F405A35069B8E8EB, F245F715BFFCC5C535AA43ED630CE146794BCA56D9EBA46E6778450D06232731 ] C:\Program Files\avmwlanstick\FRITZWLANMini.exe
12:38:39.0792 0x0dd0 AVMWlanClient - detected UnsignedFile.Multi.Generic ( 1 )
12:38:39.0792 0x0dd0 AVMWlanClient ( UnsignedFile.Multi.Generic ) - warning
12:38:39.0917 0x0dd0 [ A9F3C6135C9756E21A331F20437BC83E, 2576B4DD5D8374FF3042704DC885B4674ABF3E239BD7697785680C1D705901BA ] C:\Program Files\G Data\InternetSecurity\DelayLoader\AutorunDelayLoader.exe
12:38:39.0932 0x0dd0 G Data ASM - ok
12:38:40.0010 0x0dd0 [ E66532FD491AD5604C36916715FBA092, 43FA8EF2025E7F1281CA024CB2EB2A433310E1515DCA9359035B3FB4BAE1FA8C ] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
12:38:40.0026 0x0dd0 Adobe Reader Speed Launcher - ok
12:38:40.0151 0x0dd0 [ 3CB07566302BCEEB898DE270A0BEC175, B234D1044D8702A0929BB48F729EB5078B44AA7CD574B6482633B51289E70200 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
12:38:40.0213 0x0dd0 Adobe ARM - ok
12:38:40.0260 0x0dd0 [ 13E7CFE8E269ED15E7FC9C3EBBCB7E2B, 3B64263BA305F094B09B1961621C50CA6F9771F80CAC9F916B18BB0C7753A662 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
12:38:40.0291 0x0dd0 SunJavaUpdateSched - ok
12:38:40.0556 0x0dd0 [ 2A06A880B6AECB9B1F384B60F35D5831, A5FF754AFBC6F818F470F50253A9E88BA24C5AA3E056D28AAF32ABBF1202C81B ] C:\Program Files\G Data\InternetSecurity\Firewall\GDFirewallTray.exe
12:38:40.0619 0x0dd0 GDFirewallTray - ok
12:38:40.0728 0x0dd0 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
12:38:40.0853 0x0dd0 Sidebar - ok
12:38:40.0884 0x0dd0 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
12:38:40.0915 0x0dd0 mctadmin - ok
12:38:41.0009 0x0dd0 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
12:38:41.0071 0x0dd0 Sidebar - ok
12:38:41.0087 0x0dd0 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
12:38:41.0087 0x0dd0 mctadmin - ok
12:38:41.0414 0x0dd0 [ D6E2ED7F1F7BE7CCB8676491BF950B57, CBF07EE746F2C27ACC532E83ADC43FBE954DC3C598C4333F13B1A7615AEA9AD5 ] C:\Users\Steffen\AppData\Local\Akamai\netsession_win.exe
12:38:41.0555 0x0dd0 Akamai NetSession Interface - ok
12:38:41.0648 0x0dd0 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
12:38:41.0695 0x0dd0 Sidebar - ok
12:38:41.0726 0x0dd0 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
12:38:41.0742 0x0dd0 mctadmin - ok
12:38:41.0820 0x0dd0 AV detected via SS2: G Data InternetSecurity CBE, C:\Program Files\G Data\InternetSecurity\AVK\avkwscpe.exe ( 25.0.0.0 ), 0x41010 ( enabled : outofdate )
12:38:41.0820 0x0dd0 FW detected via SS2: G Data Personal Firewall, C:\Program Files\G Data\InternetSecurity\Firewall\GDFwSvc.exe ( 22.0.0.1 ), 0x41010 ( enabled )
12:38:41.0820 0x0dd0 ============================================================
12:38:41.0820 0x0dd0 Scan finished
12:38:41.0820 0x0dd0 ============================================================
12:38:41.0836 0x0dc4 Detected object count: 99
12:38:41.0836 0x0dc4 Actual detected object count: 99
12:40:29.0008 0x0dc4 98730404f2d3d842 ( Rootkit.Win32.Necurs.gen ) - skipped by user
12:40:29.0008 0x0dc4 98730404f2d3d842 ( Rootkit.Win32.Necurs.gen ) - User select action: Skip
12:40:29.0008 0x0dc4 HidUsb ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0008 0x0dc4 HidUsb ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0008 0x0dc4 LSI_SAS2 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0008 0x0dc4 LSI_SAS2 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0008 0x0dc4 mshidkmdf ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0008 0x0dc4 mshidkmdf ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0008 0x0dc4 Ntfs ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0008 0x0dc4 Ntfs ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 pci ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 pci ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 pciide ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 pciide ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 pcmcia ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 pcmcia ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 pcw ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 pcw ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 PEAUTH ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 PEAUTH ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 PptpMiniport ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 PptpMiniport ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 Processor ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 Processor ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 Psched ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 Psched ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 ql2300 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 ql2300 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0023 0x0dc4 ql40xx ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0023 0x0dc4 ql40xx ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 QWAVEdrv ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 QWAVEdrv ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 RasAcd ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 RasAcd ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 RasAgileVpn ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 RasAgileVpn ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 Rasl2tp ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 Rasl2tp ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 RasPppoe ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 RasPppoe ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 RasSstp ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 RasSstp ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 rdbss ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 rdbss ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 rdpbus ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 rdpbus ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0039 0x0dc4 RDPCDD ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0039 0x0dc4 RDPCDD ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 RDPENCDD ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 RDPENCDD ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 RDPREFMP ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 RDPREFMP ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 RDPWD ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 RDPWD ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 rdyboost ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 rdyboost ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 rspndr ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 rspndr ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 sbp2port ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 sbp2port ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 scfilter ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 scfilter ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 secdrv ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 secdrv ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0054 0x0dc4 Serenum ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0054 0x0dc4 Serenum ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 Serial ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 Serial ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 sermouse ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 sermouse ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 sffdisk ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 sffdisk ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 sffp_mmc ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 sffp_mmc ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 sffp_sd ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 sffp_sd ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 sfloppy ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 sfloppy ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 sisagp ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 sisagp ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 SiSRaid2 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 SiSRaid2 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 SiSRaid4 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 SiSRaid4 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0070 0x0dc4 Smb ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0070 0x0dc4 Smb ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 spldr ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 spldr ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 srv ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 srv ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 srv2 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 srv2 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 srvnet ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 srvnet ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 stexstor ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 stexstor ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 swenum ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 swenum ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 Tcpip ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 Tcpip ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 TCPIP6 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 TCPIP6 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0086 0x0dc4 tcpipreg ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0086 0x0dc4 tcpipreg ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0101 0x0dc4 TDPIPE ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0101 0x0dc4 TDPIPE ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0101 0x0dc4 TDTCP ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0101 0x0dc4 TDTCP ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0101 0x0dc4 tdx ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0101 0x0dc4 tdx ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0101 0x0dc4 TermDD ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0101 0x0dc4 TermDD ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0101 0x0dc4 tssecsrv ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0101 0x0dc4 tssecsrv ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0101 0x0dc4 TsUsbFlt ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0101 0x0dc4 TsUsbFlt ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0117 0x0dc4 tunnel ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0117 0x0dc4 tunnel ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0117 0x0dc4 uagp35 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0117 0x0dc4 uagp35 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0117 0x0dc4 udfs ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0117 0x0dc4 udfs ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0117 0x0dc4 uliagpkx ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0117 0x0dc4 uliagpkx ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0117 0x0dc4 umbus ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0117 0x0dc4 umbus ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0117 0x0dc4 UmPass ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0117 0x0dc4 UmPass ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0132 0x0dc4 usbccgp ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0132 0x0dc4 usbccgp ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0132 0x0dc4 usbcir ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0132 0x0dc4 usbcir ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0132 0x0dc4 usbehci ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0132 0x0dc4 usbehci ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0132 0x0dc4 usbhub ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0132 0x0dc4 usbhub ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0132 0x0dc4 usbohci ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0132 0x0dc4 usbohci ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0132 0x0dc4 usbprint ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0132 0x0dc4 usbprint ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0132 0x0dc4 usbscan ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0132 0x0dc4 usbscan ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 usbser ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 usbser ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 USBSTOR ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 USBSTOR ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 usbuhci ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 usbuhci ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 vdrvroot ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 vdrvroot ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 vga ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 vga ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 VgaSave ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 VgaSave ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 vhdmp ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 vhdmp ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 viaagp ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 viaagp ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0148 0x0dc4 ViaC7 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0148 0x0dc4 ViaC7 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0164 0x0dc4 viaide ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0164 0x0dc4 viaide ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0164 0x0dc4 volmgr ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0164 0x0dc4 volmgr ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0164 0x0dc4 volmgrx ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0164 0x0dc4 volmgrx ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0164 0x0dc4 volsnap ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0164 0x0dc4 volsnap ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0164 0x0dc4 vsmraid ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0164 0x0dc4 vsmraid ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0164 0x0dc4 vwifibus ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0164 0x0dc4 vwifibus ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0164 0x0dc4 WacomPen ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0164 0x0dc4 WacomPen ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 WANARP ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 WANARP ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 Wanarpv6 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 Wanarpv6 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 Wd ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 Wd ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 Wdf01000 ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 Wdf01000 ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 WfpLwf ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 WfpLwf ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 WIMMount ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 WIMMount ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 WinUsb ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 WinUsb ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 WmiAcpi ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 WmiAcpi ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0179 0x0dc4 ws2ifsl ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0179 0x0dc4 ws2ifsl ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0195 0x0dc4 WudfPf ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0195 0x0dc4 WudfPf ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0195 0x0dc4 WUDFRd ( LockedFile.Multi.Generic ) - skipped by user
12:40:29.0195 0x0dc4 WUDFRd ( LockedFile.Multi.Generic ) - User select action: Skip
12:40:29.0195 0x0dc4 AVMWlanClient ( UnsignedFile.Multi.Generic ) - skipped by user
12:40:29.0195 0x0dc4 AVMWlanClient ( UnsignedFile.Multi.Generic ) - User select action: Skip |