AZEdeluxe | 01.05.2017 12:32 | Addition Code:
Zusätzliches Untersuchungsergebnis von Farbar Recovery Scan Tool (x64) Version: 30-04-2017
durchgeführt von Wolf-Rüdiger Kaiser (01-05-2017 13:27:59)
Gestartet von C:\Users\Wolf-Rüdiger Kaiser\Desktop
Windows 10 Pro Version 1607 (X64) (2016-10-14 13:26:24)
Start-Modus: Normal
==========================================================
==================== Konten: =============================
Administrator (S-1-5-21-4246772196-3469511708-1303041041-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4246772196-3469511708-1303041041-503 - Limited - Disabled)
Gast (S-1-5-21-4246772196-3469511708-1303041041-501 - Limited - Disabled)
Wolf-Rüdiger Kaiser (S-1-5-21-4246772196-3469511708-1303041041-1001 - Administrator - Enabled) => C:\Users\Wolf-Rüdiger Kaiser
==================== Sicherheits-Center ========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er entfernt.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee VirusScan (Enabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee VirusScan (Enabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501}
FW: McAfee Firewall (Enabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7}
==================== Installierte Programme ======================
(Nur Adware-Programme mit dem Zusatz "Hidden" können in die Fixlist aufgenommen werden, um sie sichtbar zu machen. Die Adware-Programme sollten manuell deinstalliert werden.)
Adobe Acrobat Reader DC - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
chip 1-click download service (HKLM-x32\...\{503CA94E-0834-4CEE-AD92-BA17AF4E809A}) (Version: 3.6.9.0 - Chip Digital GmbH)
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.6.3.1 - Dolby Laboratories Inc)
FreeOCR v5.4 (HKLM-x32\...\freeocr_is1) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
HP Officejet 5740 series - Grundlegende Software für das Gerät (HKLM\...\{4029319E-A53E-4FAA-A2FA-D0091D85EB17}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
HP Officejet Pro 8100 - Grundlegende Software für das Gerät (HKLM\...\{4D139017-971D-45CF-B94E-26C4DC93A814}) (Version: 28.0.1321.0 - Hewlett-Packard Co.)
HP Officejet Pro 8100 Hilfe (HKLM-x32\...\{73DB9F06-C125-4A1C-A982-5801338EBE84}) (Version: 28.0.0 - Hewlett Packard)
HP Photo Creations (HKU\S-1-5-21-4246772196-3469511708-1303041041-1001\...\HP Photo Creations) (Version: 1.0.0.22032 - HP)
HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.4.14.41 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{B1AD4FFB-DD17-43EC-8C30-B9E71EAD9132}) (Version: 12.6.14.19 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Integrated Camera (HKLM-x32\...\Sunplus SPUVCb) (Version: 3.5.7.17 - SunplusIT)
Intel Security True Key (HKLM\...\TrueKey) (Version: 4.15.132.1 - Intel Security)
Intel(R) Chipset Device Software (x32 Version: 10.1.1.8 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1156 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.15.4256 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{1A51AA9E-D4BC-4318-9419-B55EA4C95B3C}) (Version: 17.1.1525.1443 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{185db067-38cd-4521-a43e-c39b96ee1389}) (Version: 19.50.1 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{475ea806-cb2a-455b-bb1b-9f99342b2fe2}) (Version: 19.40.0 - Intel Corporation)
Lenovo Anzeige am Bildschirm (Version: 8.85.03 - Lenovo) Hidden
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 2.0.9.0 - Lenovo)
Lenovo Mouse Suite (HKLM\...\MouseSuite98) (Version: 6.74 - Lenovo)
Lenovo Power Management Driver (Version: 1.67.12.16 - Lenovo) Hidden
Lenovo QuickOptimizer (HKLM\...\{8D2C871B-1B9F-45AC-9C43-2BB18089CDFA}) (Version: 1.0.016.00 - Lenovo)
Lenovo Settings - Power (x32 Version: 2.00.000 - Lenovo) Hidden
Lenovo Solution Center (HKLM\...\{DB529F41-7844-4FD9-B660-CE829E59A71E}) (Version: 3.1.002.00 - Lenovo)
Lenovo System Interface Foundation (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.0.076.00 - Lenovo)
McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 14.0 R13 - McAfee, Inc.)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.551.2 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.127 - McAfee, Inc.)
Metric Collection SDK (x32 Version: 1.1.0012.00 - Lenovo Group Limited) Hidden
Metric Collection SDK 35 (x32 Version: 1.2.0010.00 - Lenovo Group Limited) Hidden
Microsoft Office Professional 2013 - de-de (HKLM\...\ProfessionalRetail - de-de) (Version: 15.0.4919.1002 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4246772196-3469511708-1303041041-1001\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 53.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 53.0 (x86 de)) (Version: 53.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 53.0.0.6312 - Mozilla)
NVIDIA Graphics Driver 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation)
NVIDIA WMI 2.22.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.22.0 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4919.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4919.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4919.1002 - Microsoft Corporation) Hidden
PC Cleaner v5.0 (HKLM-x32\...\PC Cleaner_is1) (Version: 5.0 - PC HelpSoft)
PowerDVD Create (HKLM-x32\...\InstallShield_{DE485075-8CD3-4A1E-9ABC-6412EBA44872}) (Version: 10.0 - CyberLink Corp.)
PowerDVD Create 10 (x32 Version: 10.0.1.3222 - CyberLink Corp.) Hidden
REACHit (HKLM-x32\...\{4532E4C5-C84D-4040-A044-ECFCC5C6995B}) (Version: 2.5.005.12 - Lenovo)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.21288 - Realtek Semiconduct Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7756 - Realtek Semiconductor Corp.)
SHAREit (HKLM-x32\...\SHAREit_is1) (Version: 2.5.5.0 - Lenovo)
Studie zur Verbesserung von HP Officejet Pro 8100 Produkten (HKLM\...\{B1153774-BFFE-4D42-AC2C-6503DBE96EBA}) (Version: 28.0.1321.0 - Hewlett-Packard Co.)
SuperEasy Driver Updater v.1.1.1 (HKLM-x32\...\{039BC111-D60F-A6FF-85F4-7992EA886B8D}_is1) (Version: 1.1.1 - SuperEasy Software GmbH & Co. KG)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.115 - Synaptics Incorporated)
ThinkPad Settings Dependency (Version: 3.0.0.12 - Lenovo) Hidden
Thinkpad USB Ethernet Adapter Driver (HKLM-x32\...\{D8102684-7BA1-4948-88B9-535F84E6E588}) (Version: 10.1.506.2015 - Lenovo)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
VLC Updater (HKLM-x32\...\VLC Updater) (Version: 1.0 - VLC Updater) <==== ACHTUNG
WaveEditor (HKLM-x32\...\InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}) (Version: 1.0.1.4514 - CyberLink Corp.)
WaveEditor (x32 Version: 1.0.1.4514 - CyberLink Corp.) Hidden
Windows Driver Package - Lenovo 1.67.10.15 (06/22/2015 1.67.10.15) (HKLM\...\116858BC299A848A634E4FC927990093F81F608D) (Version: 06/22/2015 1.67.10.15 - Lenovo)
Windows Driver Package - Realtek Semiconduct Corp. (RTSPER) MTD (05/29/2015 10.0.10125.21277) (HKLM\...\4E55DAEF56C7E4B0BFE2CA2C3C55718B1DB7B3B9) (Version: 05/29/2015 10.0.10125.21277 - Realtek Semiconduct Corp.)
Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (07/29/2015 6.0.1.7572) (HKLM\...\FB7FCBF0F17BC6F027BA3449CC8B02C4445C5565) (Version: 07/29/2015 6.0.1.7572 - Realtek Semiconductor Corp.)
Windows Driver Package - Synaptics (SmbDrv) System (07/24/2015 19.0.17.2) (HKLM\...\D46201570EE858381BA5A517C517317159E0F49A) (Version: 07/24/2015 19.0.17.2 - Synaptics)
Windows Driver Package - Synaptics (SynTP) Mouse (07/24/2015 19.0.17.2) (HKLM\...\BCACBD4A2C3424D2C4AB53EE766C3F38399CEB15) (Version: 07/24/2015 19.0.17.2 - Synaptics)
Windows Driver Package - Synaptics FP Sensors (WUDFRd) Biometric (07/28/2015 4.5.317.0) (HKLM\...\FD3941EBC31C6FC067D7184B5EB55011CBFBB255) (Version: 07/28/2015 4.5.317.0 - Synaptics FP Sensors)
==================== Benutzerdefinierte CLSID (Nicht auf der Ausnahmeliste): ==========================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
CustomCLSID: HKU\S-1-5-21-4246772196-3469511708-1303041041-1001_Classes\CLSID\{cece6816-6107-4dc7-bdbc-20cd5ae1ffed}\localserver32 -> C:\ProgramData\Lenovo\ImController\Plugins\LenovoAppPromotionPlugin\x64\DesktopToastsHelper.exe => K (Der Dateneintrag hat 10 mehr Zeichen).
==================== Geplante Aufgaben (Nicht auf der Ausnahmeliste) =============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
Task: {028926CC-E32D-4E90-B678-6E4938464203} - System32\Tasks\RtHDVBg_Dolby => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2016-03-04] (Realtek Semiconductor)
Task: {0B2CBFBC-9760-45F1-81CA-8C72ED40A105} - System32\Tasks\PC Cleaner Schedule => C:\Program Files (x86)\PC Cleaner\PCCSchedule.exe [2017-03-03] (PCHelp Soft)
Task: {0B689A78-7C07-4BE3-88CE-E9B7250EDCA3} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2016-03-04] (Realtek Semiconductor)
Task: {0BC43B32-D283-4C88-BC22-D545918B3E18} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2017-02-06] (McAfee, Inc.)
Task: {0BC77D93-3558-4C5B-B63E-41B74770186C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {0F3B0329-DBF4-46D7-9B41-EC6130BFBFFB} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2017-02-22] (McAfee, Inc.)
Task: {144FE919-0373-478F-AC4B-CFC9559987F4} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
Task: {2699E22C-0EE9-4190-94DD-44280FF29846} - System32\Tasks\SuperEasyDriverUpdater_UPDATES => C:\Program Files (x86)\SuperEasy Software\Driver Updater\supereasydu.exe [2014-07-17] (SuperEasy Software)
Task: {27C5989A-24A8-420C-ADD0-8218CDE574E0} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\d4acd1ca-6919-401f-914e-51352b10f752 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2017-04-25] (Lenovo Group Limited)
Task: {2DE3565E-359C-49C4-941F-F66C6E969EFC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-04-06] (HP Inc.)
Task: {3C1BDD8C-1BFE-43EA-BC9F-536B1280FB18} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2015-07-08] (Lenovo)
Task: {3CDB3236-8FFA-4191-8FFE-468ECAE4B5FA} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {4019354F-1837-41D7-8520-881E2B6A9806} - System32\Tasks\Lenovo\REACHit Agent Update => C:\Program Files (x86)\Lenovo\REACHit\REACHitAgent.exe [2016-05-18] (Lenovo)
Task: {45AB6103-DC1C-4571-83E4-C2979A22FD24} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => Sc.exe START ImControllerService
Task: {47764D1F-4889-4ADF-AD8D-8841CC266371} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {4F8BFC3F-B939-4DEA-AF5A-EB5544F8E98B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {532A43DE-EC74-4667-B66F-EFC2CAAB7D29} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated)
Task: {556EBB6A-3B54-4781-A37E-886D5A605F24} - System32\Tasks\Lenovo\SHUpdate => C:\Program Files (x86)\Lenovo\SHAREit\ShareitUpdater.exe [2015-07-13] ()
Task: {5C902D20-42CB-48E4-93DF-D2AE9AAD20FF} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {6433F0DC-FEDC-4405-AEB1-55CF98BEC4DB} - System32\Tasks\Lenovo\REACHit Agent Startup => C:\Program Files (x86)\Lenovo\REACHit\REACHitAgent.exe [2016-05-18] (Lenovo)
Task: {71847799-6E31-4EB4-89A2-8216FC9BFD09} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Wolf-Rüdiger Kaiser\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
Task: {7382A6BF-6231-4F2F-8790-D3894F8B908F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-03-14] (Microsoft Corporation)
Task: {8841BA53-ED44-4561-97E3-84E9D2899FEF} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2015-12-12] (Lenovo)
Task: {88A93ABA-4D26-4F26-92A8-3DE528891C6D} - System32\Tasks\CLMLSvc => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [2013-03-06] (CyberLink)
Task: {895C28AC-5202-43A2-BB2D-F26D47425B8B} - System32\Tasks\HP AR Program Upload - 1519524a51754b0ca6862317aac6f33dc9fcbb5ccdd0431cbc623d8730f62132 => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {89C39F4D-78CF-4A9B-987E-4C1F245D35DB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-10] (Google Inc.)
Task: {8BF4B716-1339-4C72-BCEA-C59C0C06AAA4} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-04-01] (HP Inc.)
Task: {91F81EB8-3173-4580-B73E-C4A735D73AEA} - System32\Tasks\HP Photo Creations Communicator => C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe [2011-09-23] ()
Task: {92319297-CDE1-4F46-9682-241C7B00D468} - System32\Tasks\Lenovo\LSC\Lenovo Solution Center Notifications => C:\Program Files\Lenovo\Lenovo Solution Center\LSCNotify.exe [2015-09-05] (Lenovo)
Task: {9F826DC1-C50A-47C6-BA5D-484616E19049} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\9049ac9b-936e-4d7e-aa7a-302ef9c47fa7 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2017-04-25] (Lenovo Group Limited)
Task: {A09126BB-9091-4FF2-9A24-EF0C1E4BFD16} - System32\Tasks\Lenovo\LSC\LSCHardwareScan => C:\Program Files\Lenovo\Lenovo Solution Center\LSC.exe [2015-09-05] ()
Task: {A484AE41-608B-4F43-B925-BD11DE33A10E} - System32\Tasks\Lenovo\Lenovo Settings Power => Rundll32.exe "C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.dll",PwrMgrBkGndMonitor
Task: {AC6989B4-6240-4DC8-B355-5789A02F7E26} - System32\Tasks\RtHDVBg_LENOVO_MICPKEY => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2016-03-04] (Realtek Semiconductor)
Task: {B3953A3B-2857-4F97-A552-294AB4DECB88} - System32\Tasks\Lenovo\Lenovo Solution Center Launcher => C:\Program Files\lenovo\lenovo solution center\App\LSCService.exe [2015-09-05] (Lenovo)
Task: {BB00BBD9-CD60-4BEC-A089-5B9DF779B5EE} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {CB5DD811-584F-4A1C-A153-87A5F825DC90} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2017-02-06] (McAfee, Inc.)
Task: {D77795CE-9876-442F-B012-D36993589AA5} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-03-14] (Microsoft Corporation)
Task: {DAE4DE1D-7C2B-4AB2-B85A-BA5AF454C81C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-10] (Google Inc.)
Task: {E606A7CA-5197-4D7A-825B-9C76B332297E} - System32\Tasks\HPCeeScheduleForWolf-Rüdiger Kaiser => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {ED135A3E-3BD5-48CF-A89D-BD0DA38FFA46} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {F4829AAB-883E-4D06-B708-44E1A9F6AA89} - System32\Tasks\Lenovo\SHPrompt => C:\Program Files (x86)\Lenovo\SHAREit\ShareitPrompt.exe [2015-07-13] ()
Task: {F8834439-7C63-4F46-BA3E-2D0BFDA6C611} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-11] (Adobe Systems Incorporated)
Task: {F91F895D-842B-4F83-90FC-1BF6C940C060} - System32\Tasks\DolbySelectorTask => %ProgramFiles%\Dolby Digital Plus\ddp.exe
Task: {FBE37EDA-0728-48DB-A0BC-B22066AC65D8} - System32\Tasks\Microsoft\Windows\PLA\LSC Memory => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "LSC Memory" "$(Arg0)"
Task: {FC6C60A7-5351-4859-AB9A-0AB23B0BCAD6} - System32\Tasks\HPCustParticipation HP Officejet Pro 8100 => C:\Program Files\HP\HP Officejet Pro 8100\Bin\HPCustPartic.exe [2012-11-01] (Hewlett-Packard Co.)
Task: {FEBE0154-8ABF-4588-97BB-79C02DCA56C8} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-04-13] (Microsoft Corporation)
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird die Aufgabe verschoben. Die Datei, die durch die Aufgabe gestartet wird, wird nicht verschoben.)
Task: C:\WINDOWS\Tasks\HP Photo Creations Communicator.job => C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForWolf-Rüdiger Kaiser.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\SuperEasyDriverUpdater_UPDATES.job => C:\Program Files (x86)\SuperEasy Software\Driver Updater\supereasydu.exe
==================== Verknüpfungen =============================
(Die Einträge können gelistet werden, um sie zurückzusetzen oder zu entfernen.)
==================== Geladene Module (Nicht auf der Ausnahmeliste) ==============
2015-12-03 11:22 - 2015-07-23 06:02 - 03164816 _____ () C:\Windows\system32\nvwmi64.exe
2015-12-12 07:09 - 2017-01-17 04:25 - 00117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-12-12 09:51 - 2015-07-09 12:17 - 00184088 _____ () C:\Program Files\Lenovo\Lenovo Mouse Suite\Service\PelService.exe
2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-04-14 19:55 - 2017-03-28 08:22 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-10-14 15:19 - 2016-08-01 14:54 - 00133056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-12-03 11:22 - 2015-07-23 06:02 - 03164816 _____ () C:\WINDOWS\system32\nvwmi64.exe
2017-04-14 19:55 - 2017-03-28 08:22 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-04-14 19:55 - 2017-03-28 08:22 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-10-14 16:13 - 2016-10-14 16:13 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-15 17:04 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-15 17:05 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-15 17:05 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-15 17:05 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-04-14 19:55 - 2017-03-28 07:07 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-04-14 19:55 - 2017-03-28 07:08 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-04-14 19:55 - 2017-03-28 07:11 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-24 19:34 - 2017-02-20 08:03 - 00213880 _____ () C:\Program Files (x86)\ThinkPad\Utilities\GR\PWMRT64V.DLL
2015-12-12 09:51 - 2015-07-09 12:42 - 00026248 _____ () C:\Program Files\Lenovo\Lenovo Mouse Suite\FSRremoS.EXE
2015-12-12 09:51 - 2015-07-09 12:17 - 00233240 _____ () C:\Program Files\Lenovo\Lenovo Mouse Suite\Service\PelElvDm.exe
2017-04-04 10:38 - 2017-04-04 10:39 - 00019456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2017-04-04 10:38 - 2017-04-04 10:39 - 22723584 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-04-04 10:38 - 2017-04-04 10:39 - 00448512 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll
2017-04-04 10:38 - 2017-04-04 10:39 - 05427200 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2016-06-03 17:40 - 2016-06-03 17:41 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
2017-04-04 10:38 - 2017-04-04 10:39 - 00435712 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2017-04-04 10:38 - 2017-04-04 10:39 - 01062400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll
2016-03-04 11:51 - 2016-03-04 11:52 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.313.10010.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2017-05-01 10:15 - 2017-05-01 10:15 - 00077312 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-05-01 10:15 - 2017-05-01 10:15 - 00190464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-05-01 10:15 - 2017-05-01 10:15 - 43012096 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-05-01 10:15 - 2017-05-01 10:15 - 02451456 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.14.675.0_x64__kzf8qxf38zg5c\skypert.dll
2015-07-07 03:36 - 2015-07-07 03:36 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-12-03 11:22 - 2015-06-24 13:37 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2013-03-06 22:49 - 2013-03-06 22:49 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMediaLibrary.dll
2013-03-06 22:52 - 2013-03-06 22:52 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvcPS.dll
==================== Alternate Data Streams (Nicht auf der Ausnahmeliste) =========
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird nur der ADS entfernt.)
==================== Abgesicherter Modus (Nicht auf der Ausnahmeliste) ===================
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Der Wert "AlternateShell" wird wiederhergestellt.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
==================== Verknüpfungen (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird der Registryeintrag auf den Standardwert zurückgesetzt oder entfernt.)
==================== Internet Explorer Vertrauenswürdig/Eingeschränkt ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt.)
==================== Hosts Inhalt: ===============================
(Wenn benötigt kann der Hosts: Schalter in die Fixlist aufgenommen werden um die Hosts Datei zurückzusetzen.)
2015-07-10 13:04 - 2017-05-01 10:13 - 00000875 _____ C:\WINDOWS\system32\Drivers\etc\hosts
0.0.0.1 mssplus.mcafee.com
==================== Andere Bereiche ============================
(Aktuell gibt es keinen automatisierten Fix für diesen Bereich.)
HKU\S-1-5-21-4246772196-3469511708-1303041041-1001\Control Panel\Desktop\\Wallpaper -> c:\users\wolf-rüdiger kaiser\pictures\saved pictures\amg-gt-r-2016.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall ist aktiviert.
==================== MSCONFIG/TASK MANAGER Deaktivierte Einträge ==
==================== Firewall Regeln (Nicht auf der Ausnahmeliste) ===============
(Wenn ein Eintrag in die Fixlist aufgenommen wird, wird er aus der Registry entfernt. Die Datei wird nicht verschoben solange sie nicht separat aufgelistet wird.)
FirewallRules: [{9FBB39AE-BF3A-4269-BD52-B60C2C3B454C}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{51320BEB-B5E9-42C3-A11A-5FFE7B50E7E6}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{45C88AE5-9C5A-47E1-AD93-C5AA0AE7F010}] => (Allow) LPort=5357
FirewallRules: [{F84EDD41-9A7A-4074-A25C-7812F714CB13}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\Bin\DeviceSetup.exe
FirewallRules: [{FBC5A9BD-1AF4-4E65-9D06-7989366B19AF}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\bin\SendAFax.exe
FirewallRules: [{3C6C58E2-47B0-47A0-A864-60FC4F516D31}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\bin\DigitalWizards.exe
FirewallRules: [{544E7F3B-DDFB-4EF0-86DD-24944D11CA1F}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\bin\FaxApplications.exe
FirewallRules: [{F6B3A693-8755-4B34-BA19-0C3CF00A9650}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{76F158F5-32A8-48D9-8A4D-8407EE077CA8}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{BFEC2B77-FA42-4DA8-B71B-B30C73D851E5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{00F18B3C-1FF5-4B76-B829-70C31011AC3B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D734CB3C-A80D-4579-8C67-6858B87144B8}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{1823F631-9C64-4DEB-B501-DBA5F4074B07}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8100\Bin\DeviceSetup.exe
FirewallRules: [{48A75FEB-005C-4563-8F07-2F886E3397F8}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8100\Bin\HPNetworkCommunicator.exe
FirewallRules: [{C9CD3A2D-A07B-4FAC-ADEF-721799332653}] => (Allow) C:\Program Files\HP\HP Officejet Pro 8100\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{29DA1674-E7CD-4614-88D0-AB83E76E2C2C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2B90772F-ED79-4FF9-BB53-FBDEA448B6FF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E036E14D-8142-4FEB-8B42-886D6D531E82}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{8E29FBCE-76E9-435F-A1F4-54B4B18266F7}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
==================== Wiederherstellungspunkte =========================
13-04-2017 15:06:03 Windows Update
20-04-2017 17:30:25 Geplanter Prüfpunkt
30-04-2017 02:28:45 Geplanter Prüfpunkt
==================== Fehlerhafte Geräte im Gerätemanager =============
==================== Fehlereinträge in der Ereignisanzeige: =========================
Applikationsfehler:
==================
Error: (04/30/2017 08:12:47 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x22c8
Startzeit der fehlerhaften Anwendung: 0x01d2c1dd5df0eef2
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: c0c7829b-ae97-4d2b-9c62-54a81e0abfc6
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 05:41:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x2f04
Startzeit der fehlerhaften Anwendung: 0x01d2c1c84065b7b6
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: 81ef94cc-806c-4d62-82fd-d92ee390f32f
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 04:41:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x3e10
Startzeit der fehlerhaften Anwendung: 0x01d2c1bfdea238f4
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: b11be380-94e1-4842-8184-00fff898a094
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 03:41:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x740
Startzeit der fehlerhaften Anwendung: 0x01d2c1b77cdd92b9
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: 57e80623-9476-465e-8b40-6248ce6f7f54
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 02:41:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x3790
Startzeit der fehlerhaften Anwendung: 0x01d2c1af1b17ec0d
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: 92753d9d-0605-41fc-87b1-4073d9fb599c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 01:41:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x1adc
Startzeit der fehlerhaften Anwendung: 0x01d2c1a6b9543aba
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: e29429f5-4126-4213-83de-7e9d0f9f369c
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 12:41:36 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x14d0
Startzeit der fehlerhaften Anwendung: 0x01d2c19e57915918
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: fd0bb725-bb5c-4b2b-8079-d9cca40a7bee
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 11:41:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x3120
Startzeit der fehlerhaften Anwendung: 0x01d2c195f5cb0d36
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: 708380ea-19f8-4e09-ac55-e5fc2738ccd5
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 10:41:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x2c30
Startzeit der fehlerhaften Anwendung: 0x01d2c18d94067de2
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: d5dbd975-1b13-47ed-aa0b-fed24dd8ae37
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (04/30/2017 09:41:36 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Name des fehlerhaften Moduls: Communicator.exe, Version: 0.0.0.0, Zeitstempel: 0x57e5b552
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000ee4d
ID des fehlerhaften Prozesses: 0x193c
Startzeit der fehlerhaften Anwendung: 0x01d2c18532420d9d
Pfad der fehlerhaften Anwendung: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Pfad des fehlerhaften Moduls: C:\Users\Wolf-Rüdiger Kaiser\AppData\Roaming\HP Photo Creations\Communicator.exe
Berichtskennung: 5c06e446-3c81-4890-ae2a-e948b51081da
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Systemfehler:
=============
Error: (05/01/2017 01:21:04 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Erkennung interaktiver Dienste" wurde mit folgendem Fehler beendet:
Unzulässige Funktion.
Error: (05/01/2017 01:06:36 PM) (Source: NetBT) (EventID: 4319) (User: )
Description: Ein doppelter Name wurde im TCP-Netzwerk entdeckt. Die IP-Adresse des Computers,
der die Meldung gesendet hat, steht in den Daten. Verwenden Sie NBTSTAT -n an
der Eingabeaufforderung, um den doppelten Namen zu bestimmen.
Error: (05/01/2017 10:32:55 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (05/01/2017 10:11:46 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (05/01/2017 10:11:46 AM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\Lokaler Dienst" (SID: S-1-5-19) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
und der APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (05/01/2017 10:11:46 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "CDPUserSvc_60800c1" wurde mit folgendem Fehler beendet:
Unbekannter Fehler
Error: (04/30/2017 09:28:47 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/30/2017 09:11:18 PM) (Source: disk) (EventID: 11) (User: )
Description: Der Treiber hat einen Controllerfehler auf \Device\Harddisk2\DR19 gefunden.
Error: (04/30/2017 06:36:03 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT)
Description: Durch die Berechtigungseinstellungen für "Anwendungsspezifisch" wird dem Benutzer "NT-AUTORITÄT\SYSTEM" (SID: S-1-5-18) unter der Adresse "LocalHost (unter Verwendung von LRPC)" keine Berechtigung vom Typ "Lokal Aktivierung" für die COM-Serveranwendung mit der CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
und der APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
im Anwendungscontainer "Nicht verfügbar" (SID: Nicht verfügbar) gewährt. Die Sicherheitsberechtigung kann mit dem Verwaltungstool für Komponentendienste geändert werden.
Error: (04/30/2017 06:19:49 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Der Dienst "Erkennung interaktiver Dienste" wurde mit folgendem Fehler beendet:
Unzulässige Funktion.
==================== Speicherinformationen ===========================
Prozessor: Intel(R) Core(TM) i7-5500U CPU @ 2.40GHz
Prozentuale Nutzung des RAM: 38%
Installierter physikalischer RAM: 8071 MB
Verfügbarer physikalischer RAM: 4970.28 MB
Summe virtueller Speicher: 9351 MB
Verfügbarer virtueller Speicher: 6153.73 MB
==================== Laufwerke ================================
Drive c: (Windows) (Fixed) (Total:475.69 GB) (Free:335.03 GB) NTFS ==>[System mit Startkomponenten (eingeholt von Laufwerk)]
Drive d: () (Removable) (Total:0.97 GB) (Free:0.21 GB) FAT
Drive e: (INTENSO) (Fixed) (Total:931.28 GB) (Free:797.7 GB) FAT32
==================== MBR & Partitionstabelle ==================
========================================================
Disk: 0 (Size: 476.9 GB) (Disk ID: D0A5E542)
Partition: GPT.
========================================================
Disk: 1 (Size: 931.5 GB) (Disk ID: 96109550)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=0C)
========================================================
Disk: 2 (MBR Code: Windows XP) (Size: 991.5 MB) (Disk ID: C3072E18)
Partition 1: (Not Active) - (Size=991 MB) - (Type=04)
==================== Ende von Addition.txt ============================ TDSSKiller teil 1 Code:
13:29:08.0313 0x2860 TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02
13:29:08.0313 0x2860 UEFI system
13:29:11.0281 0x2860 ============================================================
13:29:11.0281 0x2860 Current date / time: 2017/05/01 13:29:11.0281
13:29:11.0281 0x2860 SystemInfo:
13:29:11.0281 0x2860
13:29:11.0281 0x2860 OS Version: 10.0.14393 ServicePack: 0.0
13:29:11.0281 0x2860 Product type: Workstation
13:29:11.0281 0x2860 ComputerName: THINKPAD-WRK-1
13:29:11.0281 0x2860 UserName: Wolf-Rüdiger Kaiser
13:29:11.0281 0x2860 Windows directory: C:\WINDOWS
13:29:11.0281 0x2860 System windows directory: C:\WINDOWS
13:29:11.0281 0x2860 Running under WOW64
13:29:11.0281 0x2860 Processor architecture: Intel x64
13:29:11.0281 0x2860 Number of processors: 4
13:29:11.0281 0x2860 Page size: 0x1000
13:29:11.0281 0x2860 Boot type: Normal boot
13:29:11.0281 0x2860 CodeIntegrityOptions = 0x00000001
13:29:11.0281 0x2860 ============================================================
13:29:11.0297 0x2860 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.1066, osProperties = 0x19
13:29:12.0563 0x2860 System UUID: {390D711A-A09A-F59D-6D0E-10F97791677C}
13:29:13.0078 0x2860 Drive \Device\Harddisk0\DR0 - Size: 0x773C256000 ( 476.94 Gb ), SectorSize: 0x200, Cylinders: 0xF334, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
13:29:13.0078 0x2860 Drive \Device\Harddisk1\DR20 - Size: 0xE8E0DB5E00 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:29:13.0078 0x2860 Drive \Device\Harddisk2\DR21 - Size: 0x3DF80000 ( 0.97 Gb ), SectorSize: 0x200, Cylinders: 0x7E, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
13:29:13.0078 0x2860 ============================================================
13:29:13.0078 0x2860 \Device\Harddisk0\DR0:
13:29:13.0078 0x2860 GPT partitions:
13:29:13.0078 0x2860 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {BDA7AEA8-61C6-47FF-BA45-2BDF44C7D253}, Name: EFI system partition, StartLBA 0x800, BlocksNum 0x82000
13:29:13.0078 0x2860 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {25AAAA40-7642-4192-A5C9-BF8CE6274558}, Name: Microsoft reserved partition, StartLBA 0x82800, BlocksNum 0x8000
13:29:13.0078 0x2860 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {C2875017-323B-4096-9772-9825AAC65837}, Name: Basic data partition, StartLBA 0x8A800, BlocksNum 0x3B762800
13:29:13.0078 0x2860 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {3AB2DC98-1F17-4EB4-AC76-3CF31A7B3B20}, Name: Basic data partition, StartLBA 0x3B7ED000, BlocksNum 0x1F4000
13:29:13.0078 0x2860 MBR partitions:
13:29:13.0078 0x2860 \Device\Harddisk1\DR20:
13:29:13.0078 0x2860 MBR partitions:
13:29:13.0078 0x2860 \Device\Harddisk1\DR20\Partition1: MBR, Type 0xC, StartLBA 0x800, BlocksNum 0x747051C1
13:29:13.0078 0x2860 \Device\Harddisk2\DR21:
13:29:13.0078 0x2860 MBR partitions:
13:29:13.0078 0x2860 \Device\Harddisk2\DR21\Partition1: MBR, Type 0x4, StartLBA 0x20, BlocksNum 0x1EFBE0
13:29:13.0078 0x2860 ============================================================
13:29:13.0094 0x2860 C: <-> \Device\Harddisk0\DR0\Partition3
13:29:13.0375 0x2860 E: <-> \Device\Harddisk1\DR20\Partition1
13:29:13.0375 0x2860 ============================================================
13:29:13.0375 0x2860 Initialize success
13:29:13.0375 0x2860 ============================================================
13:29:20.0718 0x19f0 ============================================================
13:29:20.0718 0x19f0 Scan started
13:29:20.0718 0x19f0 Mode: Manual; SigCheck; TDLFS;
13:29:20.0718 0x19f0 ============================================================
13:29:20.0718 0x19f0 KSN ping started
13:29:20.0827 0x19f0 KSN ping finished: true
13:29:21.0233 0x19f0 ================ Scan system memory ========================
13:29:21.0233 0x19f0 System memory - ok
13:29:21.0233 0x19f0 ================ Scan services =============================
13:29:21.0249 0x19f0 0216541493019156mcinstcleanup - ok
13:29:21.0280 0x19f0 [ A7901875F89D011C38CF52C98ACF5B29, 782141AB1DD7ACDE6EA08B5BAFDE8BADD05B81D38C18E097D6D9C46102056EB1 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys
13:29:21.0327 0x19f0 1394ohci - ok
13:29:21.0327 0x19f0 [ EE1CCC54F75C24727A218F98FC5349DA, 0B0D26640BFA0F551B7087027E572D0BF2C5EAF50A4187C5A7D839180B7FF589 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys
13:29:21.0343 0x19f0 3ware - ok
13:29:21.0358 0x19f0 [ 73C73E1AA0D4D727A04AAAB120B7F56A, 5D311F11022994410DF5C67914D38B1F0D813EFD181EA234750286A272D67A1A ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys
13:29:21.0390 0x19f0 ACPI - ok
13:29:21.0390 0x19f0 [ 0935496EF9624B46B935CB35ECE1F205, A22A2A29195505A65E8626D60B00C86C23E0CABC1EB8345EA5ED523516CC21C0 ] AcpiDev C:\WINDOWS\System32\drivers\AcpiDev.sys
13:29:21.0405 0x19f0 AcpiDev - ok
13:29:21.0421 0x19f0 [ D6794C31F4077B71433988787BAA926E, F16365C2F195AAE94D4740E6C3DF4C0CECEC6393CAD65425DCCD28CDBA6EC51A ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys
13:29:21.0421 0x19f0 acpiex - ok
13:29:21.0436 0x19f0 [ FE5F656D6B35089DA39112E74EC6A85A, 5D81EE63998232A5B36DE47FE15B9D04D5BD02234CA133A2462AECA8C60A22ED ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys
13:29:21.0436 0x19f0 acpipagr - ok
13:29:21.0452 0x19f0 [ 2F242941E4DFF69B883D77A16F039557, 45C388365317C720654A659A9326B2BC0E9D84929C704654985597D5D620101C ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys
13:29:21.0468 0x19f0 AcpiPmi - ok
13:29:21.0468 0x19f0 [ C247E35A21682DA8D0DC3AF9F025FCC5, 455415EE3166B3043AD8A4DD50B688DB74242267FB555642441251EFA823E971 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys
13:29:21.0483 0x19f0 acpitime - ok
13:29:21.0483 0x19f0 [ 671133C0AC2D8B40B7574F69059653E9, A36CC49A0C829A5C4D6CF273791071213F5FFB57DC7022D523CFB731374FF63C ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
13:29:21.0499 0x19f0 AdobeARMservice - ok
13:29:21.0515 0x19f0 [ BE62B286791F715E430FB022C1707BBA, 7EDFF71EFB65AA895270BD83B16F390F53D98C438ADA23E780CE6200CA0449F1 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
13:29:21.0530 0x19f0 AdobeFlashPlayerUpdateSvc - ok
13:29:21.0561 0x19f0 [ 49B9DB97AFC85DCCBDACDAB2E90085B7, 2A6C2A09F74EA15044F442CCFB54A0F24F105ADB915E5C78F02F59652DC29152 ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS
13:29:21.0593 0x19f0 ADP80XX - ok
13:29:21.0608 0x19f0 [ 323AA1953ED9C01E23F740FA891FE064, 4CED6E3D61749316CDE28965C913E7ED462539DAAD637A29484F62AF47AD650D ] AFD C:\WINDOWS\system32\drivers\afd.sys
13:29:21.0624 0x19f0 AFD - ok
13:29:21.0640 0x19f0 [ 23522E5D581F7722B1B5B86737CAE39C, FB81ABD304376A1E87B65F5E1B34477B628CEDB2091C5D754DE97464B6050C5B ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys
13:29:21.0655 0x19f0 ahcache - ok
13:29:21.0671 0x19f0 [ D0905D4A945D01D4B28DB9E1BD5985F7, CF389CBCD3B99D1BAE34A42F723F1005C32213A394F691978076D3DF1727715C ] AJRouter C:\WINDOWS\System32\AJRouter.dll
13:29:21.0671 0x19f0 AJRouter - ok
13:29:21.0686 0x19f0 [ 8FD51B3B35707A66080D7C8CB05E792D, FE52F3DC280D208FDDC75F6E3294B8D601E0D86F9BD3DB1ACC8FC296AC74C23B ] ALG C:\WINDOWS\System32\alg.exe
13:29:21.0702 0x19f0 ALG - ok
13:29:21.0702 0x19f0 [ DF21E05E41E5AC3F13F304D91457649A, 7F48F2AD1DBE89A261113C76D7C23AD7D87D5599BCC31F8A558A8A10B81BF521 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys
13:29:21.0718 0x19f0 AmdK8 - ok
13:29:21.0733 0x19f0 [ 45D0AA4BB90B821DF92E8F19ABED0C5E, EA87A6E98DB3C5A88A844C04C6934E870B7004E783AA5211722115382A211B90 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys
13:29:21.0749 0x19f0 AmdPPM - ok
13:29:21.0749 0x19f0 [ 74FFBC43B4B899C9A8CA06A892F2CE73, 8D599363C7F3D373F1859BAA4D06DD0F40BE78B56BE52B74DE6EA6EF99452004 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys
13:29:21.0765 0x19f0 amdsata - ok
13:29:21.0780 0x19f0 [ AAB0F1D8D7E54761ABAB13AF161F1680, CF847990EFFA2828F5B1DB1A68F08A6C2C918E9612EDFFCF95C36BCABBBEA272 ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys
13:29:21.0796 0x19f0 amdsbs - ok
13:29:21.0796 0x19f0 [ F91BAAC4237C40352A807000F3B716F9, F7EFA08E5067C3D419C9D21EDB880BA08883A80DDF35F8B42EC3AB293FE5E03E ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys
13:29:21.0811 0x19f0 amdxata - ok
13:29:21.0811 0x19f0 [ BC121C099C6C659126AD2102AFDFF8CF, 42B5EE293BDD7ADCE48173A01B30D8452564B9DA225EAF25E9292FE77C0FCF3E ] AppID C:\WINDOWS\system32\drivers\appid.sys
13:29:21.0827 0x19f0 AppID - ok
13:29:21.0843 0x19f0 [ 74A24CF946279111D7F203B36569EC02, FD67D36804744B4FE3E20BA891852575E6C2DA6515643B2F4B4210118B0FCCDA ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll
13:29:21.0858 0x19f0 AppIDSvc - ok
13:29:21.0858 0x19f0 [ 79A87DD43331290A276C02DC396BF530, D0781DC027EE60C94831A2C9C3DD741F8F2100A253CD847E7FCFA59919014278 ] Appinfo C:\WINDOWS\System32\appinfo.dll
13:29:21.0874 0x19f0 Appinfo - ok
13:29:21.0874 0x19f0 [ 68190E2BADF23BD782344970E5B5DE9E, 95D30EC12C7FDF5822CED8BC2F17669A6687A2FB262B4F0D15C8DCFF4E9AB33D ] applockerfltr C:\WINDOWS\system32\drivers\applockerfltr.sys
13:29:21.0905 0x19f0 applockerfltr - ok
13:29:21.0905 0x19f0 [ 76A12AC673B0F8A607ACDD0583C247D4, CBC6C0EB82C7A8E3998344280BBB5A697AFA7206CA2BADFDA7ED6E7DD20E3DAC ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
13:29:21.0921 0x19f0 AppMgmt - ok
13:29:21.0937 0x19f0 [ 32155E028491267CF2DB6085A0B7E359, 562831841293E4849CD01992DECE39B9B3C0835DCD352994CA2E2FE1C76A7CB3 ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll
13:29:21.0968 0x19f0 AppReadiness - ok
13:29:21.0983 0x19f0 [ 99CA3E622070FDBD7B75EB7E86B2DE40, 12BDD092667250EBC99B4D597897C1B2C83115CD83ECCDEAC36B2D9C9BEA77B6 ] AppVClient C:\WINDOWS\system32\AppVClient.exe
13:29:22.0015 0x19f0 AppVClient - ok
13:29:22.0015 0x19f0 [ B66ED2CB37F7E4696A51612AFBA08834, 70BA67AF7F1290E3145B873B53516F138E50D8AAC80CD00CBA66467ABC6643CB ] AppvStrm C:\WINDOWS\system32\drivers\AppvStrm.sys
13:29:22.0030 0x19f0 AppvStrm - ok
13:29:22.0046 0x19f0 [ 8DC924848E20F890BEFC6B31136D46BE, B7603425B4970F505B5A3EB0F6652A9CDD188059BDC945D6DF2BADC2DF8F4B5D ] AppvVemgr C:\WINDOWS\system32\drivers\AppvVemgr.sys
13:29:22.0062 0x19f0 AppvVemgr - ok
13:29:22.0062 0x19f0 [ 9ADC5A8BEE10E174F95349E9232D8E76, F322991323DCDC51199BB3AB0DA20F6C3CC7EE6E804400B473C610FDB895F0AE ] AppvVfs C:\WINDOWS\system32\drivers\AppvVfs.sys
13:29:22.0077 0x19f0 AppvVfs - ok
13:29:22.0124 0x19f0 [ 95415C7C5C43882F7163CA07D956ADA2, 5A082F36A39BE9ABC47AE8A72972554BA577EB04D8018EC862615EA2130FA0E3 ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll
13:29:22.0187 0x19f0 AppXSvc - ok
13:29:22.0202 0x19f0 [ E6AB1F0B4C3D4E0D2A88332D76FECD03, 0D3003EB979DA4546DCDD055011E24F13E34F683F02C9801CAC564D1809F11D2 ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys
13:29:22.0202 0x19f0 arcsas - ok
13:29:22.0218 0x19f0 [ 61C5A480C43E7E8E49C42869F49D0D3E, E610F0E4315ABA1D90AD4A1D7A68ABA2ACBB7FCA89E9D1798470365D52592D55 ] AsyncMac C:\WINDOWS\System32\drivers\asyncmac.sys
13:29:22.0233 0x19f0 AsyncMac - ok
13:29:22.0233 0x19f0 [ A10F989A812B57B9695F6C305907C9C6, E2B292610079AA1A10696138DE8130905A8A834B75A8DED7EBF8B6732B77A0F4 ] atapi C:\WINDOWS\system32\drivers\atapi.sys
13:29:22.0233 0x19f0 atapi - ok
13:29:22.0249 0x19f0 [ 2DC3D53FFA0D10EB8C911AE2DB7BF4CF, 8E0A4B5D610D487A216E70396A99ACC1BEA12C46A6681B1A39CD0FD01EDD406A ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
13:29:22.0280 0x19f0 AudioEndpointBuilder - ok
13:29:22.0296 0x19f0 [ 7B993290E7691C446C16A56A431669BA, 004551934E27E9FC1A939C9BD1DEB850A216CBED9B18CB3317920F5656D9F6BF ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll
13:29:22.0327 0x19f0 Audiosrv - ok
13:29:22.0343 0x19f0 [ 6D90FDA2DC364B8EA1420F2F81585CC3, 10E6F23A213CFE49BE04BB7D366ADD4028D61D7114FEC67C30B5467DF6B36D4F ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll
13:29:22.0358 0x19f0 AxInstSV - ok
13:29:22.0374 0x19f0 [ 61BAC67048CA5C1D08C48FCC8012B613, 71B2A466FC38DA1029B471FBD2541D8FE359751A7B212AE0F420DB3645916450 ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys
13:29:22.0405 0x19f0 b06bdrv - ok
13:29:22.0405 0x19f0 [ 94D6B95485BFA35D81524B0EBA0F7569, 14A32CD501B1D816526A75A9EB3782E6C4FF78831628F257050AD2BA73733F57 ] BasicDisplay C:\WINDOWS\System32\drivers\BasicDisplay.sys
13:29:22.0421 0x19f0 BasicDisplay - ok
13:29:22.0421 0x19f0 [ 2E78B31C90766FD086D2B766528E9AEA, D0D9ED8AD90E3D400DA4231AB313B4B2869930DADC3034D6FCDEA000E424F843 ] BasicRender C:\WINDOWS\System32\drivers\BasicRender.sys
13:29:22.0437 0x19f0 BasicRender - ok
13:29:22.0437 0x19f0 [ 3F5523DCEFE42B385659C5CB46A6B810, CA24A3DF002B19E7BDEDE9B5EB60623F299D0E78B2E4F58DCFC028D76DEFE52D ] bcmfn C:\WINDOWS\System32\drivers\bcmfn.sys
13:29:22.0452 0x19f0 bcmfn - ok
13:29:22.0468 0x19f0 [ 0B750A6A6D847E73CA48ADD7A0F5A393, 6A43020F23846EFB1AFA3C070465B0059E9DF60DEB16899E09559462DF30939F ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys
13:29:22.0468 0x19f0 bcmfn2 - ok
13:29:22.0483 0x19f0 [ 2B4D3AEAAD02954F8C191BC2D67949AD, 8237C9AD556CFAF7442FF60F78608104BC17CE3134C89D986D49C38CC60B1518 ] BDESVC C:\WINDOWS\System32\bdesvc.dll
13:29:22.0499 0x19f0 BDESVC - ok
13:29:22.0515 0x19f0 [ 0A508274355745EEF01C6BE3198D02C4, E2DB08AEE2368FA95FDB357BB31EA4EBF31679C3E72E109DB3D7CD1B5F7B828E ] Beep C:\WINDOWS\system32\drivers\Beep.sys
13:29:22.0530 0x19f0 Beep - ok
13:29:22.0546 0x19f0 [ 5125CBB61AC81168366BEB290399CB8E, B2A3095D45E2114DE2BD0E5A3AE20B3CE95EE517A35B9E1EAD05E231F38DBDCF ] BFE C:\WINDOWS\System32\bfe.dll
13:29:22.0577 0x19f0 BFE - ok
13:29:22.0608 0x19f0 [ D876C567AB767258036F05E4766189FD, DE8BA67325CB64495BD454B8F9DDCAE82636253844FC68B360C7E1CF5D51DD0E ] BITS C:\WINDOWS\System32\qmgr.dll
13:29:22.0640 0x19f0 BITS - ok
13:29:22.0655 0x19f0 [ 9CD2A4821DE379305CACB2E99AD8953A, 89D700DFC3C59ACBBADB48954A28C0EBF8D6A11A9E63837689DD891868E43188 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys
13:29:22.0671 0x19f0 bowser - ok
13:29:22.0687 0x19f0 [ 6A15C5140B6F7D9479A32276AC2BA108, 0A8C6DB88148C6DB61226DD2FF816BDF3FED9E7A60EF17CCA17FA7D9EEC01C71 ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
13:29:22.0718 0x19f0 BrokerInfrastructure - ok
13:29:22.0718 0x19f0 [ B3F32C630DD3F2F6A6091B89CFF13641, 7A9C53EF9AB9FF1DC392FD711B194A101DB36CA5BC799E817BEB446741089B76 ] Browser C:\WINDOWS\System32\browser.dll
13:29:22.0733 0x19f0 Browser - ok
13:29:22.0749 0x19f0 [ 722036C26D2C4E50EC2A2EC5FD678846, 999468038AE01F0FF6881F4B2A2CB67BC636641188E95F10729E08ADBC3CB3DE ] BthAvrcpTg C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
13:29:22.0765 0x19f0 BthAvrcpTg - ok
13:29:22.0765 0x19f0 [ 77630A51FAF6A07922FEE835F4DED8F6, E096A9DC12885FD19575346A9693A66D0DDFF96C3155AD2040F2BF4249D1D609 ] BthEnum C:\WINDOWS\System32\drivers\BthEnum.sys
13:29:22.0780 0x19f0 BthEnum - ok
13:29:22.0780 0x19f0 [ C2E31BE025D46D189E38DD1EDF07837A, 656528DCAAAF485EC57EE5C3021E96736634DE3B9C39CBCD2728E055ABD4C0A5 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys
13:29:22.0796 0x19f0 BthHFEnum - ok
13:29:22.0812 0x19f0 [ F7CD605FC0B0B22F3F6F247595E3A655, 1CD9140DE5415DDBEACD8667E63E5C95FD64D693B56302A0474E693E578BEAB0 ] bthhfhid C:\WINDOWS\System32\drivers\BthHFHid.sys
13:29:22.0827 0x19f0 bthhfhid - ok
13:29:22.0827 0x19f0 [ B157D72BDA6A6DD6E9DC6BF338CD0CF8, B2AC26AE214151E5AD93DED78256BC0295DBF0133C854E7DEE4CD776D9C9A349 ] BthHFSrv C:\WINDOWS\System32\BthHFSrv.dll
13:29:22.0858 0x19f0 BthHFSrv - ok
13:29:22.0858 0x19f0 [ 0AB691736D4D4029444AF62DE59CFD37, C1C22EFBF67331B87AB261BBF9813009257437BA02F728EC2DFA1A49ECC5FABF ] BthLEEnum C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
13:29:22.0874 0x19f0 BthLEEnum - ok
13:29:22.0890 0x19f0 [ 535DC41A33630AE4C262406F9E981C03, 599332589AA28D04189E19B87A4AE6FEEB60B40A7BC6E3B11240DA363A981C29 ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys
13:29:22.0905 0x19f0 BTHMODEM - ok
13:29:22.0905 0x19f0 [ 224BA1CB1F3C702F0D001D2AFC9793B1, F139F6F78C716E1167E16530AE31E4A26C2A69467BCB08A9A52A101B31DF7771 ] BthPan C:\WINDOWS\System32\drivers\bthpan.sys
13:29:22.0921 0x19f0 BthPan - ok
13:29:22.0952 0x19f0 [ 851ED52AE3E62CD5374BD4BBFF7A9DAB, 381281CB7D8FC4026092330B06E24BC84EEF79EE3C97E21900D950D7D9AB2FC3 ] BTHPORT C:\WINDOWS\System32\drivers\BTHport.sys
13:29:22.0983 0x19f0 BTHPORT - ok
13:29:22.0999 0x19f0 [ 96932F631F5CB9F5D1C8F99A71568EF3, 5E4C8955A2EE9DC76B4EBC383653EB753D76D6B017E1A5DD553AC16094D7F12A ] bthserv C:\WINDOWS\system32\bthserv.dll
13:29:23.0015 0x19f0 bthserv - ok
13:29:23.0015 0x19f0 [ DC5955E589C55E2313D69B64E1A183F3, 06D703246D0813DE53D62885C8B7381135783673FF4BDDD5CC38FEB54901BB76 ] BTHUSB C:\WINDOWS\System32\drivers\BTHUSB.sys
13:29:23.0030 0x19f0 BTHUSB - ok
13:29:23.0046 0x19f0 [ 23F9EF739F685E07482116425E7879AA, 0EBDF96A49A319C0BCF6F51FB6C8C392C017E1738B950C19C91FF43E14D73143 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys
13:29:23.0062 0x19f0 buttonconverter - ok
13:29:23.0062 0x19f0 [ 60EB6A4CE3E21887D302350631C16F26, 4270EFA22285C1A9336CF1220761E416950D2DA9C6A40D1D8452686CD5040DAB ] CapImg C:\WINDOWS\System32\drivers\capimg.sys
13:29:23.0077 0x19f0 CapImg - ok
13:29:23.0077 0x19f0 [ F8FB51B9EF6372610E9B31A1D86B62FC, 7461584A8B39AC549AD7BAFFA509D4CD81EEE542808BC8EFC285863A0AE6432D ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys
13:29:23.0093 0x19f0 cdfs - ok
13:29:23.0108 0x19f0 [ 2E6612376D257F74781F2EF1F869D8C3, 908B0DECB9F098F7F11B029A03C06C67FB52E5E8BEA42033A2B579D3B3686AB8 ] CDPSvc C:\WINDOWS\System32\CDPSvc.dll
13:29:23.0140 0x19f0 CDPSvc - ok
13:29:23.0140 0x19f0 [ A93C9B9EBE2FDE5A536000D72CC17F7F, 9793CFAE8BE8C6B5B39A1D276577965FBB2CE131325A410B7C68BD23492ADAAF ] CDPUserSvc C:\WINDOWS\System32\CDPUserSvc.dll
13:29:23.0155 0x19f0 CDPUserSvc - ok
13:29:23.0171 0x19f0 [ 613D0137C269187FA298A157E3D14A18, 84BC268525F14BB27202CE242BF94D9E83BC91B50A0335908574F31B29A2F04D ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys
13:29:23.0187 0x19f0 cdrom - ok
13:29:23.0202 0x19f0 [ E189727B3C9909A85B33A16B290E192E, 2C273A9F44EDC5E5435904E9681973854B2F3EBB6100021BB139FF0CCCE9BF20 ] CertPropSvc C:\WINDOWS\System32\certprop.dll
13:29:23.0218 0x19f0 CertPropSvc - ok
13:29:23.0218 0x19f0 [ 515FAA4CABCBB83347205119E57868C8, 8E008E87E4DD223E1F4262C08E65439D6C02894F69A1A7DD07530044A0B6CE16 ] cfwids C:\WINDOWS\system32\drivers\cfwids.sys
13:29:23.0233 0x19f0 cfwids - ok
13:29:23.0233 0x19f0 [ 59B4AB79011957DD3B83F0C2E63741BD, 5DE68785D701DBA0F98452B7D5CC407BEECD51685F39516157733CED2EF2FA19 ] chip1click C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe
13:29:23.0249 0x19f0 chip1click - detected UnsignedFile.Multi.Generic ( 1 )
13:29:23.0983 0x19f0 Detect skipped due to KSN trusted
13:29:23.0983 0x19f0 chip1click - ok
13:29:24.0015 0x19f0 [ 0AED948DA8D5F08B3D6F12E4E2089736, 95E538E81DDBC83492C5F3820C82C78F050B4D74ACF12D7970EC84F93581AE29 ] cht4iscsi C:\WINDOWS\system32\drivers\cht4sx64.sys
13:29:24.0046 0x19f0 cht4iscsi - ok
13:29:24.0077 0x19f0 [ 0002A0FDE087C1657AB31CE73077539C, 4DD6210B67E9633AB3240371590869DC833A4C986C74FC12A5D4FFFFD361848A ] cht4vbd C:\WINDOWS\System32\drivers\cht4vx64.sys
13:29:24.0140 0x19f0 cht4vbd - ok
13:29:24.0140 0x19f0 [ 6B4F90A287D75CCD78694F6790C911B2, 73D7C31E9F475FA3FD568FCA9A953F968729AA114F63C06F38BF5198DAD67BD8 ] circlass C:\WINDOWS\System32\drivers\circlass.sys
13:29:24.0155 0x19f0 circlass - ok
13:29:24.0171 0x19f0 [ B72D26074E72A757D788FB1BEF8B2F2E, 36847C5315AFB9A5EC66AD3EF2A09C24C0FAF669FDF0831F78600F4609352CB4 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys
13:29:24.0187 0x19f0 CLFS - ok
13:29:24.0249 0x19f0 [ 209D07A9F54C2211C4C1E387EC971C97, 02112545E31E617602ED527E9191BD819413FB3732EAD16699E0C5795F8C58B2 ] ClickToRunSvc C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
13:29:24.0312 0x19f0 ClickToRunSvc - ok
13:29:24.0343 0x19f0 [ 85F31D4986E81CF3E78A5E2442C8F7AF, B6E6233D63A2C3E7AF0A9BBB62799159BF96C0F0EEBBC9B523BD227CC7A746B3 ] ClientAnalyticsService C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe
13:29:24.0390 0x19f0 ClientAnalyticsService - ok
13:29:24.0405 0x19f0 [ E133CFCBFABB3CB517BE9F42FEA5887C, DA699CDD5F3CC427354540C907BD24CCA7BAC3112C53918EB611CB4EEC7611DA ] ClipSVC C:\WINDOWS\System32\ClipSVC.dll
13:29:24.0437 0x19f0 ClipSVC - ok
13:29:24.0437 0x19f0 [ EEC3A4A98AE1A337E3CD1483AD6F2E15, 764DA329984A95E092F5C15116DA34FA7FC27216C0862365D4BF10ADC97EC5C5 ] clreg C:\WINDOWS\System32\drivers\registry.sys
13:29:24.0452 0x19f0 clreg - ok
13:29:24.0468 0x19f0 [ 429623E266EF067A44E8CF148E9DFB9B, A48AA85ACC52C7AD73DB2D6148B3F9FB5EAC33C8F8C5BB6D7D0A9D84B7C08E11 ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys
13:29:24.0483 0x19f0 CmBatt - ok
13:29:24.0499 0x19f0 [ 4289C913D7E2FE963ABB096AA99CB1F7, 49D9008C5E18F62751D2312CE4F49DFBC04ACBBFDD950F0437F35AC21318041B ] CNG C:\WINDOWS\system32\Drivers\cng.sys
13:29:24.0515 0x19f0 CNG - ok
13:29:24.0530 0x19f0 [ 3DB10C59405931E2C72EFB82C1AF97D1, 100B5450A70988DB1C1F8A5FDBB3553AF1A0D47B42A5AC71460DB92E26010CE6 ] cnghwassist C:\WINDOWS\system32\DRIVERS\cnghwassist.sys
13:29:24.0530 0x19f0 cnghwassist - ok
13:29:24.0546 0x19f0 [ 34C935AF2A414572B412B3556586D783, 912981B88B0796576ECCD5EBE0C4728EC02D5D6A96B039447DCBA59B2583F25E ] CompositeBus C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys
13:29:24.0562 0x19f0 CompositeBus - ok
13:29:24.0562 0x19f0 COMSysApp - ok
13:29:24.0577 0x19f0 [ 44EEEB2382F566999287E13F2067693C, 53A4A0C85EAD38030FF2078C67465E3710ECD03A08FF34E1E67B2E3E1CC70043 ] condrv C:\WINDOWS\system32\drivers\condrv.sys
13:29:24.0577 0x19f0 condrv - ok
13:29:24.0593 0x19f0 [ 9E3B10C490D860F3ED8F61FD0FD5B828, A21CB206A09053C7D9C94F2B71F53A40B3810D02A70C3D6AA0B48676BA5753BD ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll
13:29:24.0624 0x19f0 CoreMessagingRegistrar - ok
13:29:24.0655 0x19f0 [ CFFF490F6615A17E2F73FC830F2B1E13, BCBC19445056E553219414438BA9DE6778E26DD66AA5BAE217474140EEB1DFD0 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
13:29:24.0671 0x19f0 cphs - ok
13:29:24.0671 0x19f0 [ 5F06CAC4B09250CDDDD0180A08162924, A2EB0A57225E65FC264CFC9FAD858D8B54A015CDAE3DC904B1C4E9AAB40B1F06 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll
13:29:24.0687 0x19f0 CryptSvc - ok
13:29:24.0702 0x19f0 [ EC2EA2F6C6D23315C20B4829F00D0440, BF1F47C3485E9112FB64F582DFA4679455203574F82A5ADB222BDA1FED1601E6 ] CSC C:\WINDOWS\system32\drivers\csc.sys
13:29:24.0733 0x19f0 CSC - ok
13:29:24.0749 0x19f0 [ BE35D1BAC3F18C9EB1C1CFBA31ED95E3, 4255475D173868A0E5583E844A1884E819E229838C4DEACAC47F1A4DEF388C9D ] CscService C:\WINDOWS\System32\cscsvc.dll
13:29:24.0780 0x19f0 CscService - ok
13:29:24.0780 0x19f0 [ 3BBD0073265DA6D3EFBA54B26E5D8236, 3C10C8BEC0D8AC41A3FBD589F41A83D6345C1FDD04B8B99063B2F5670CF10B18 ] dam C:\WINDOWS\system32\drivers\dam.sys
13:29:24.0796 0x19f0 dam - ok
13:29:24.0812 0x19f0 [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
13:29:24.0858 0x19f0 DcomLaunch - ok
13:29:24.0874 0x19f0 [ AE9F09F87755C18904656CB4F59F351D, B352A43B3B68B497D87B49C302AF3F37F36D56D49878AE3785C3D43597E5DC57 ] DcpSvc C:\WINDOWS\system32\dcpsvc.dll
13:29:24.0890 0x19f0 DcpSvc - ok
13:29:24.0905 0x19f0 [ ABBD3EE724117242E28D31F19FBCFF03, 68EA91A969DD80A5DE28B0A8EAEB308837183713559C2C2FAEF991858C971393 ] defragsvc C:\WINDOWS\System32\defragsvc.dll
13:29:24.0921 0x19f0 defragsvc - ok
13:29:24.0937 0x19f0 [ DD74F18227ACC837D9856E24282D446D, 6A760E44CD897952538CDFA8895FE11263D51AAA79CFF24C01F3862E919DA478 ] DeviceAssociationService C:\WINDOWS\system32\das.dll
13:29:24.0968 0x19f0 DeviceAssociationService - ok
13:29:24.0968 0x19f0 [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll
13:29:24.0999 0x19f0 DeviceInstall - ok
13:29:24.0999 0x19f0 [ CDF1B1B5C5951111791C236B2696C7F8, BF6C4BA545C8827B40DB69890DB4D2B2F9C583C5E3CFBDFD370B05891141458D ] DevQueryBroker C:\WINDOWS\system32\DevQueryBroker.dll
13:29:25.0015 0x19f0 DevQueryBroker - ok
13:29:25.0015 0x19f0 [ 4BC21E937E9F9F408672D2C2CBE4A153, 2F27560D09D184ABB7B4415146F5B8DE56C84FF74A4042596635EF896E39CBC4 ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys
13:29:25.0046 0x19f0 Dfsc - ok
13:29:25.0046 0x19f0 [ F0D4400BA0F08610D9A551B15BF10B76, 83EB8FB272FC2DD2CC0659C2FB90AD0DAE88A88AB3951E03BCD933A25B601E10 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll
13:29:25.0077 0x19f0 Dhcp - ok
13:29:25.0077 0x19f0 [ CA7FEDDFCF61EF15A09C54DA2C07C49F, 346EF7709BA9E6BD48592B86FA46F9D956C847EF91F4980EEAD98269D0F0EF67 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
13:29:25.0093 0x19f0 diagnosticshub.standardcollector.service - ok
13:29:25.0140 0x19f0 [ EE32B36EA7CBD9BBA26B137C84943E23, BD5DDA2DEAF2D2CF6B24AED81C3EDBFECF6402A7B6A5D49FEDF334FF03CACB86 ] DiagTrack C:\WINDOWS\system32\diagtrack.dll
13:29:25.0202 0x19f0 DiagTrack - ok
13:29:25.0202 0x19f0 [ 35B9D46560339A5A7F0CAC6ED702C817, F70480B01533B7029F90E2DE297E9E829660300DDE7A7D009B0AC2684E7691A7 ] disk C:\WINDOWS\system32\drivers\disk.sys
13:29:25.0218 0x19f0 disk - ok
13:29:25.0233 0x19f0 [ A1D7F926ABE7895D18467FF9A5EE7FC7, 2922C92D31EA50A126594967D325B21936432D1BB9C941416989B6848DF890E2 ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll
13:29:25.0249 0x19f0 DmEnrollmentSvc - ok
13:29:25.0265 0x19f0 [ 815F45161A4571C2C44491564F3D5968, 32E7AE8414A178CE429C0CDFCF718E3C11C705FB3155EA5CA0EAD48AAE507B01 ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys
13:29:25.0280 0x19f0 dmvsc - ok
13:29:25.0280 0x19f0 [ 6E5EE6E420FECD64DE463C5F01CBFE71, F173C56895E80AA03D70CD78B3AB659C2EEAACFF43BE3B6EF3939D6F4AD4F62D ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll
13:29:25.0296 0x19f0 dmwappushservice - ok
13:29:25.0312 0x19f0 [ 86E507EE1457D7FA463BBF05BA76EB1E, 2D2D05CED57C22F41684DC6DD00ACECDF708407493286B2D4007068154E436FF ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
13:29:25.0327 0x19f0 Dnscache - ok
13:29:25.0343 0x19f0 [ 8F46B4C3F9BA19C26A26D0A11137B20B, BA0A66DBA98D77FD85A7CD2D4593F2B2A1A3B4D32BBECBCFFBEB5A54DCB0D8ED ] dot3svc C:\WINDOWS\System32\dot3svc.dll
13:29:25.0358 0x19f0 dot3svc - ok
13:29:25.0358 0x19f0 [ CA09EAEE92C6FDDC6B05057F11A0372D, 14DB5C186B69644AA93C445BF31CC9670204F95A47B77B6EACB19B4A316378AD ] DPS C:\WINDOWS\system32\dps.dll
13:29:25.0374 0x19f0 DPS - ok
13:29:25.0390 0x19f0 [ AE6BD4C879A8C849E53947C92DF3B3A0, 8C29774CB2D30D901C54AAC0C8ACE709351EE40E5C8FB9951B2A18B4A03F28B7 ] drmkaud C:\WINDOWS\system32\DRIVERS\drmkaud.sys
13:29:25.0390 0x19f0 drmkaud - ok
13:29:25.0405 0x19f0 [ 7433474BE77F065D2FA628671FE31A3E, 063ADDC68F48036749E6EC7B2F66284DB29F90F62E9468D16B4EF5A0FDC45E35 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll
13:29:25.0421 0x19f0 DsmSvc - ok
13:29:25.0437 0x19f0 [ 5FCA45C24501DA7390065D3706A9FC3F, 093FD840F1502ECC6F05B9723CA523B3F15CF39A5D2B9106E1267739B3F2C52C ] DsSvc C:\WINDOWS\System32\DsSvc.dll
13:29:25.0452 0x19f0 DsSvc - ok
13:29:25.0483 0x19f0 [ 2DD9CF863320D5EDEA3ED9B8ED280BB0, CC35571FBA2E6E617CF93F778351ED3B3EA16F0B301C5433E94AD328E6EEA0FF ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys
13:29:25.0546 0x19f0 DXGKrnl - ok
13:29:25.0562 0x19f0 [ 43272EB461C0905269520104D6A061BE, 0C756B8873BD7D95DEF7D49330892D31EE73CCB5C3C6DD26F1CBA37D55F4F62B ] e1dexpress C:\WINDOWS\system32\DRIVERS\e1d65x64.sys
13:29:25.0593 0x19f0 e1dexpress - ok
13:29:25.0593 0x19f0 [ 9FCE4EF7D5E274F862D9A2526B5F4779, 81D42D5475C2801C8E0C233A0BA827569D8A70590017C91C665C8B232D9BFAA9 ] EapHost C:\WINDOWS\System32\eapsvc.dll
13:29:25.0624 0x19f0 EapHost - ok
13:29:25.0671 0x19f0 [ 7EC6FC0266D74BD47ABB130A328B70EC, 3856790AF967AB03B1A89F97328DC4D5A6854ACDA6169681A9AFB03D7CF791F9 ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys
13:29:25.0749 0x19f0 ebdrv - ok
13:29:25.0765 0x19f0 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] EFS C:\WINDOWS\System32\lsass.exe
13:29:25.0780 0x19f0 EFS - ok
13:29:25.0780 0x19f0 [ 8D74B8B5D6F7C5BC4C525BAF2B083FF1, DA5656F745B3911F96871887FDFDC40F4D9C820622A0AA27EFE4BA93662833CA ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys
13:29:25.0796 0x19f0 EhStorClass - ok
13:29:25.0796 0x19f0 [ 2A9817B5A9260D8F60D52E36BEF10443, AC1A0203221AFAF584C71317FA07AA1B6E61BE619E918B3B1E4AD57CCED1CF03 ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
13:29:25.0812 0x19f0 EhStorTcgDrv - ok
13:29:25.0827 0x19f0 [ 80A7999DE02CE678B865832E1CE78CD6, 2576EBB6E4D630A906DE724F125099E52A962B5B68B9F9BCA849A7B29D8C8689 ] embeddedmode C:\WINDOWS\System32\embeddedmodesvc.dll
13:29:25.0843 0x19f0 embeddedmode - ok
13:29:25.0843 0x19f0 [ 3CE2B6AECB9AF8BC159299EEC46A35CA, E933B28BB6E4D01FCCDF8FBBB134C244B28DA3ECBDFA13333F0D4C24B2551780 ] EntAppSvc C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
13:29:25.0874 0x19f0 EntAppSvc - ok
13:29:25.0874 0x19f0 [ 77B60DEC7DCB4233E4A69D3F52E5DB24, 3A5C905E37A93899051497C90E5BA8E1D003B56C6906CADFD2F1CDF52052D248 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys
13:29:25.0890 0x19f0 ErrDev - ok
13:29:25.0905 0x19f0 [ F89083AB8B9F51C0031C1CBD0A9A7E35, 9EE973A25134960E62D1A6A1E34AD9B3F7690E71C1AD31A23FA2081A73438754 ] EventSystem C:\WINDOWS\system32\es.dll
13:29:25.0921 0x19f0 EventSystem - ok
13:29:25.0937 0x19f0 [ 30FBA772B6963ADA4DE738FC8977611B, A8D3BFA43CE547765CDB475BC88E7153DA4A4215CC577EDFF8DA0AC1B025F654 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe
13:29:25.0968 0x19f0 EvtEng - ok
13:29:25.0968 0x19f0 [ FCD2C63754C2E739A8EEAD9BC63F9DDC, C57A72ABA4C0BD71F914B9C8FF965DCFF585A205498F19A4584A4BAF7674839D ] exfat C:\WINDOWS\system32\drivers\exfat.sys
13:29:25.0999 0x19f0 exfat - ok
13:29:25.0999 0x19f0 [ FA918EC296EB410FF02867D008D02421, 23D164A24CB0D212778FA9592A046B6BA1F3628003E04181744A1F891B5B3E5A ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys
13:29:26.0015 0x19f0 fastfat - ok
13:29:26.0030 0x19f0 [ 77CE56471AF984800F318F3734D768C7, 72D540072374A56C2C497F0532A50705D3F0637F2C0C96B1D715F2EDFCA3AA2D ] Fax C:\WINDOWS\system32\fxssvc.exe
13:29:26.0062 0x19f0 Fax - ok
13:29:26.0077 0x19f0 [ 99598ECA5E41996E005D5B9D9FF1EFA2, 91345CD50EF02431B69093505C1C5F5DC6A1AA6BF192EE9392ED4D5626B60462 ] fdc C:\WINDOWS\System32\drivers\fdc.sys
13:29:26.0077 0x19f0 fdc - ok
13:29:26.0093 0x19f0 [ EF0DD43A4CBAB367BCA1AFBDC9971E4F, 73E161C45D63FDDE71EE2438137913724DC513860539D1E7F6BD861F5D1B33F3 ] fdPHost C:\WINDOWS\system32\fdPHost.dll
13:29:26.0108 0x19f0 fdPHost - ok
13:29:26.0108 0x19f0 [ 34DAC585994CD3B4E910DE11C584EF3D, A6C6A4CB5413EA61F1A54E2D3AD71A311CEA2C26218544D2D2D4A5CFEC52DE8C ] FDResPub C:\WINDOWS\system32\fdrespub.dll
13:29:26.0124 0x19f0 FDResPub - ok
13:29:26.0140 0x19f0 [ B68DA1FE3CA2311AFD38DD6905CA7F71, 4B395DFB1B47D2507CA4D9DC996A70D0A3BDB1A245CD6DA6C42B2A299AFCCF37 ] fhsvc C:\WINDOWS\system32\fhsvc.dll
13:29:26.0155 0x19f0 fhsvc - ok
13:29:26.0155 0x19f0 [ F44F666B0EACC3181544FFCF8CA0FFC7, 83F771CF9DAE1C504B30731EEC55355EA1253174252DA2192ADF1D228B3735C3 ] FileCrypt C:\WINDOWS\system32\drivers\filecrypt.sys
13:29:26.0171 0x19f0 FileCrypt - ok
13:29:26.0171 0x19f0 [ 78A210DDFDF2C9EC884631D2DAA573F0, 5D39C6EF4AC690A9749EEDBE2478FFF15A22877A2861EDA103C7BF1607B0C1BD ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys
13:29:26.0187 0x19f0 FileInfo - ok
13:29:26.0202 0x19f0 [ 1A97DB5E701A186989F3795223C3BE39, F7982220D4DF7E104955E63CACE352394E2577DEF49506EA126127F820EB62DF ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys
13:29:26.0218 0x19f0 Filetrace - ok
13:29:26.0218 0x19f0 [ 46626665F0E5906E45619B4EFD6186B8, 37FDD3B8AD49FD29E54DA5567EA77F28A53498AE56348F7A2628E5E5549D638B ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys
13:29:26.0233 0x19f0 flpydisk - ok
13:29:26.0249 0x19f0 [ FDA72ACA14D516D18C33AFCD0FD9260F, 6509612DEC82EA74614B5C9A7B432305A1A468C97B88BED9E141DF2929B621B1 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
13:29:26.0265 0x19f0 FltMgr - ok
13:29:26.0296 0x19f0 [ 2E193D24CE8460A9C703D0F193192BEF, CD95928BC240D556DFEA265A09A655FFE157A36D2230CD10BBAD4CA15CB98412 ] FontCache C:\WINDOWS\system32\FntCache.dll
13:29:26.0374 0x19f0 FontCache - ok
13:29:26.0374 0x19f0 [ 59241194DBDF30A2B4029E402F377900, 47A92E9CD8494C403B377799D395670A393766647E24CD83B15338CE2AA50266 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
13:29:26.0390 0x19f0 FontCache3.0.0.0 - ok
13:29:26.0405 0x19f0 [ CD7CD19E72EA2F597D01FC68ECD2F28E, 4E8BAA4AEF28B043780E2FEFFEB5E4DF4E2FB3211CE617D2DBAFB6C7B7DBBDFD ] FrameServer C:\WINDOWS\system32\FrameServer.dll
13:29:26.0437 0x19f0 FrameServer - ok
13:29:26.0452 0x19f0 [ D152CCBFC8251670BF0AAFE00D6BC782, 9DE82D8FC4E1DAF8FF23EE08C0B7CB5051A9224E64544D262CFA4996A41B04E1 ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys
13:29:26.0468 0x19f0 FsDepends - ok
13:29:26.0468 0x19f0 [ 6D6BB5C7363CD35FA715E826F3D029EE, C214F791EB39E8B25CE57ED9D6C1D56EE1AF6021BCB380980BD42A6338A6C9F7 ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
13:29:26.0483 0x19f0 Fs_Rec - ok
13:29:26.0499 0x19f0 [ 8EEC4925C03E375C4EC496E45C44139A, 06C5C7BCC28D3E435675F0759A09CAB726E971DF4BFC1DC3DCF503EABCDCCCC6 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys
13:29:26.0515 0x19f0 fvevol - ok
13:29:26.0530 0x19f0 [ EF78034773CE506323655A868C949144, DF195BEEE6704FBCC6D2D9E1BF6723E52ED502A1459F495B7D18481E6A79B5BC ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys
13:29:26.0530 0x19f0 gencounter - ok
13:29:26.0546 0x19f0 [ B55FEBC6A00DAA1FE074F020B6907516, 67071FBAC2ABA47AB71358A5F08E92E034A55343878F00137E90B3B1F7362976 ] genericusbfn C:\WINDOWS\System32\drivers\genericusbfn.sys
13:29:26.0546 0x19f0 genericusbfn - ok
13:29:26.0562 0x19f0 [ DDD8A8CDDC7F13EF57D1DAAE71865936, 9D472A8689F72F24D40D5B94849690F53C67849FDF6162A94EF4FB330A3DA566 ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys
13:29:26.0577 0x19f0 GPIOClx0101 - ok
13:29:26.0593 0x19f0 [ 8997353398C8466ECD183942D5FCC65B, C73FD5FFD71003F7FDDC17F59812BD6860992FA35EC0ECC8DE37D935606B485B ] gpsvc C:\WINDOWS\System32\gpsvc.dll
13:29:26.0655 0x19f0 gpsvc - ok
13:29:26.0655 0x19f0 [ 7ACD8F69B5D6EC97E6D2C006E19BED88, FC69214C9308EA64B88EF4C3C95800586DDBB44C8540846B79A161BAD8203B6E ] GpuEnergyDrv C:\WINDOWS\system32\drivers\gpuenergydrv.sys
13:29:26.0671 0x19f0 GpuEnergyDrv - ok
13:29:26.0671 0x19f0 [ 750446ED76A5D13E902174DDDDA1A62B, F67355A6659E21D8D97E6982B28F22453F8C298E822E27FADDB440DA4A6DE7C0 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:29:26.0687 0x19f0 gupdate - ok
13:29:26.0687 0x19f0 [ 750446ED76A5D13E902174DDDDA1A62B, F67355A6659E21D8D97E6982B28F22453F8C298E822E27FADDB440DA4A6DE7C0 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
13:29:26.0702 0x19f0 gupdatem - ok
13:29:26.0702 0x19f0 [ 10E3515FE5DBA6656FA62C29342EC4A1, 2051F10F74ED712B1766EB61E87FADE25AB3D0970BABFD320600D1B0D6377F26 ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys
13:29:26.0718 0x19f0 HDAudBus - ok
13:29:26.0733 0x19f0 [ B90D284B97CD4CA9DE7430AAAD887A56, 2F14F985C39B7801ED64590979CF2114924E9547F5B11D2B37A74DBFFDD9E7C5 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys
13:29:26.0749 0x19f0 HidBatt - ok
13:29:26.0749 0x19f0 [ B2FE11643CC6ACDEE6C247DD36018FDB, 5796613C7DBF8B2A9E860E006FF1A245B6BE7D10E3F6685AD142B48E5C237B8C ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys
13:29:26.0765 0x19f0 HidBth - ok
13:29:26.0780 0x19f0 [ D24355488A2D4D2323518EC1AC7A6D9E, ED2176A2093726087EDDA25B86E9CDD4BA35F4E748E3A6DE0B15C4C97646B5C7 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys
13:29:26.0796 0x19f0 hidi2c - ok
13:29:26.0796 0x19f0 [ 0AF9ABBA4F3F55C6C803890D64BC3C29, D3DE6FA308F8E7CD4F16387F46AE4B2F7EC9BBA07BF87652B660A0D645710571 ] hidinterrupt C:\WINDOWS\System32\drivers\hidinterrupt.sys
13:29:26.0812 0x19f0 hidinterrupt - ok
13:29:26.0812 0x19f0 [ CDBCF8E9AB06D88A1E1191D32F320C5D, F76963AB7CF2BAB3A220013879AECD3976BFD851CFB66B5A69A9EA2541048861 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys
13:29:26.0827 0x19f0 HidIr - ok
13:29:26.0843 0x19f0 [ C900FE0DD6A1E2220084B8F1C427790C, 802194EBEDA1A50EDA300078B0888AAC1F17A42E67147B7B3B9C50AD8D4E5C89 ] hidserv C:\WINDOWS\system32\hidserv.dll
13:29:26.0858 0x19f0 hidserv - ok
13:29:26.0858 0x19f0 [ D8536CB438CC4CCDAE047B768EED22B2, 4F666BFA3554F9ACA6B9D436BFA64474D5F30FB3E78F4E66068CCDF283D9867F ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys
13:29:26.0874 0x19f0 HidUsb - ok
13:29:26.0874 0x19f0 [ 7829E439EBDDDB0FEFD6DEBCEE6B09AD, FF6BB82CE0C21513E407FF465C768805CF202A7B4040140A944A0413875BEC37 ] HipShieldK C:\WINDOWS\system32\drivers\HipShieldK.sys
13:29:26.0890 0x19f0 HipShieldK - ok
13:29:26.0890 0x19f0 [ 0AC1BD5A28FAA371EF34859FE703E515, 1DD1C33AF8D6EBE7C36FCD051F066E4039D2B47ABAECF7C68BC3933D567930B2 ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
13:29:26.0921 0x19f0 HomeGroupListener - ok
13:29:26.0937 0x19f0 [ 86161A89F16851728802590EC7C92608, 3A3B05BB4E115410D27063B30C0EF3F18295F542050F329F1E466C81A9E23A46 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
13:29:26.0952 0x19f0 HomeGroupProvider - ok
13:29:26.0968 0x19f0 [ A52ACBECFE7BE36E377A203B969705AE, F42FB19123C5EF404267A911305E3A86411BD22E78944FAF2F189382E364CDF2 ] HomeNetSvc C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
13:29:26.0999 0x19f0 HomeNetSvc - ok
13:29:26.0999 0x19f0 [ F5CA18197B4646E04DB9EB2D6642CC4D, 5BA3342DDF1BCB67E4156169FE9A33E7BC2641C729E9F1A80C0E80953C6AB114 ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys
13:29:27.0015 0x19f0 HpSAMD - ok
13:29:27.0015 0x19f0 [ 91ADA2CF99A0C28A231763E033FD6F98, 80F6ABD22D018EBF5AC3FD5BEE941962B29B1517EACE0C7730C00D7DE17CEFAC ] HPSupportSolutionsFrameworkService C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
13:29:27.0030 0x19f0 HPSupportSolutionsFrameworkService - ok
13:29:27.0062 0x19f0 [ A10C7C1E69FC90620C7BF2E51302A01F, D725AEAE38255CED73F4922A10F226215528706580B06D01C228488F93AC0397 ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys
13:29:27.0093 0x19f0 HTTP - ok
13:29:27.0093 0x19f0 [ 0C84C250F80EAEC2C9768464CC1A9626, 212E1003B78F9B98FEB084FD1FDB59B26A9DE4C9120F24D4361FBBF0F3C035E7 ] HvHost C:\WINDOWS\System32\hvhostsvc.dll
13:29:27.0108 0x19f0 HvHost - ok
13:29:27.0124 0x19f0 [ 74FC79C52395B10FFD0B55CF22CF88FC, 94D977DA2092EE8C2A598AC48758A84BB22CB6378BD114C2D3B4172A07A9CACC ] hvservice C:\WINDOWS\system32\drivers\hvservice.sys
13:29:27.0124 0x19f0 hvservice - ok
13:29:27.0140 0x19f0 [ 771EDDA9830A3079F996F34D681FB6E5, F452AD656872A1C8B2D6DCE232CE01EBD456C46F4934A7601E78470F2A2CBF38 ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys
13:29:27.0140 0x19f0 hwpolicy - ok
13:29:27.0155 0x19f0 [ 3B9F315E7FA72CC25228EB097DD9C694, B26F1E494428EF197A0C97645C05BB3CA093827A005D35C987F1D6778BC4E52C ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys
13:29:27.0155 0x19f0 hyperkbd - ok
13:29:27.0171 0x19f0 [ B54B30992620C97230013A74461C8517, CAF09BDCDD6DE2A39CB8AE2C65E6F8FE12D8E93D84BBEF6C6A98F872BF54A4E3 ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys
13:29:27.0187 0x19f0 i8042prt - ok
13:29:27.0187 0x19f0 [ C6B8743B213F06AA60943D8366FE968F, 758954F70B810063914B243115B2C753B2BCE40190F95C30ACBA0BF04EBD5B33 ] iagpio C:\WINDOWS\System32\drivers\iagpio.sys
13:29:27.0202 0x19f0 iagpio - ok
13:29:27.0202 0x19f0 [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c C:\WINDOWS\System32\drivers\iai2c.sys
13:29:27.0233 0x19f0 iai2c - ok
13:29:27.0233 0x19f0 [ 5A0E850F8CD17791A3E6A3CF81D0CA28, 10A965A49D53360DD250E0758B6BB142872298A21C732EB026ACB93492C5C6CF ] iaLPSS2i_GPIO2 C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys
13:29:27.0249 0x19f0 iaLPSS2i_GPIO2 - ok
13:29:27.0249 0x19f0 [ 7508F1096803385D6376BFD0BD473AC4, 1F32EC23CDC94DCB9710E6663B5C3BD83568545DDC2C741CFC13550A4E4DD2BE ] iaLPSS2i_I2C C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys
13:29:27.0265 0x19f0 iaLPSS2i_I2C - ok
13:29:27.0265 0x19f0 [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
13:29:27.0280 0x19f0 iaLPSSi_GPIO - ok
13:29:27.0280 0x19f0 [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
13:29:27.0296 0x19f0 iaLPSSi_I2C - ok
13:29:27.0327 0x19f0 [ 12859E1215AA083A42E7ADCDE5C061D1, 262F9C65C3FA7EB69C4FA7C6547E1C79DB49697A083309909BC78726A116557F ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys
13:29:27.0374 0x19f0 iaStorA - ok
13:29:27.0390 0x19f0 [ 97E553D03219D3D51705C7235D9EAEBD, 5D4578C8804AF32D1DC0868E34D6538138DC15F9568CA7E21051B1C82C0D8D55 ] iaStorAV C:\WINDOWS\system32\drivers\iaStorAV.sys
13:29:27.0405 0x19f0 iaStorAV - ok
13:29:27.0421 0x19f0 [ 8350FE3BCDE3428BC040877BB7E9EAEB, 77F9456351CA640C6B7862907C0580627E761EC807B551976A95657EB4D6CC20 ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys
13:29:27.0437 0x19f0 iaStorV - ok
13:29:27.0452 0x19f0 [ 3BA03F7C7700DDF4C383DDE9252F5817, 3E90F69D0010E7764349D9AE865D577E431FEBC67DA554B400BC808DD286E203 ] ibbus C:\WINDOWS\System32\drivers\ibbus.sys
13:29:27.0468 0x19f0 ibbus - ok
13:29:27.0483 0x19f0 [ 053DFE4E6324B828C16CB6F5B9F20790, 17347896126DE49C570D2AC025F2A4BB8250B67ECD6A6D31B80EBD9423799F0B ] IBMPMDRV C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
13:29:27.0483 0x19f0 IBMPMDRV - ok
13:29:27.0499 0x19f0 [ D84EF85ED4F2044784A44C211A27D065, FA18EA57507353DC3DB18F840F0499D7874AC055E3190E4D76DB9AA1021FC674 ] IBMPMSVC C:\WINDOWS\system32\ibmpmsvc.exe
13:29:27.0499 0x19f0 IBMPMSVC - ok
13:29:27.0515 0x19f0 ibtsiva - ok
13:29:27.0515 0x19f0 [ 8A89BCB5CEA759E552C6A663E176E2CB, DFDC44AD43C21259AD939D4D1852B9AE57FDC4741E8E64CEB0BD13FA2629C026 ] ibtusb C:\WINDOWS\system32\DRIVERS\ibtusb.sys
13:29:27.0530 0x19f0 ibtusb - ok
13:29:27.0546 0x19f0 [ 937AC47F7356554DA05D9722C356EB55, 9EABC9F19B4E1193B669D2674967F5C6F03FAD348EDF0615E3F78554FF9A83CC ] icssvc C:\WINDOWS\System32\tetheringservice.dll
13:29:27.0562 0x19f0 icssvc - ok
13:29:27.0671 0x19f0 [ 6FFC445E0D38C3C880125F2C201C9BC6, 488A427239B55394359751FCB8CBAEA8E2AE1CB2AE03C04590E7B8C80EF3F709 ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
13:29:27.0796 0x19f0 igfx - ok
13:29:27.0812 0x19f0 [ 5ED1C5B5238B085643D8C4C59E0D3CF1, 3E7580B2A8B47EAC250030420251FE2A34C4B8D2B7C4D0536E64E197CA42F7CB ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe
13:29:27.0827 0x19f0 igfxCUIService2.0.0.0 - ok
13:29:27.0843 0x19f0 [ F2934208C0E50C0B971A7981AB90BED2, B936BFBBD71E731CC2CDB8B47D262F2EF09726FF921C2DA0841910CA2401423D ] IKEEXT C:\WINDOWS\System32\ikeext.dll
13:29:27.0890 0x19f0 IKEEXT - ok
13:29:27.0890 0x19f0 [ FAA36F3AA6737D85636D835273729805, 6CB5877EBC4AF1E44C39028CA6E0D296481221CF1AB3661AB82549BBC0BE22F0 ] ImControllerService C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
13:29:27.0905 0x19f0 ImControllerService - ok
13:29:27.0905 0x19f0 [ 2A01C96DF5802D3434634E55C91232D8, A3ABEF36E2FD2CF5C371ADBF92566A09669A1D990ABE4677370F57F2EEAF8121 ] IndirectKmd C:\WINDOWS\System32\drivers\IndirectKmd.sys
13:29:27.0921 0x19f0 IndirectKmd - ok
13:29:27.0921 0x19f0 InstallerService - ok
13:29:28.0015 0x19f0 [ 7BEEEA8EE522F23365D76C1373DE2279, AF300943982387165EF475DB4950D0DDF50B37FD73B83995783A1A9E751ACF45 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
13:29:28.0108 0x19f0 IntcAzAudAddService - ok
13:29:28.0124 0x19f0 [ 42777B7BE4946135578E5C3BC1D2E4AD, CE4FF334238D0A98139676420E770A42DC0F5567F49D618B56CD55417F556D05 ] IntcDAud C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
13:29:28.0155 0x19f0 IntcDAud - ok
13:29:28.0171 0x19f0 [ B63CF22D1AD2ABDC39D85851B2BEAA6D, 37E9043BABB5895BFD2B59AFB60C438B992C6EAA1B5FDE5B3445314343F4C406 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
13:29:28.0187 0x19f0 Intel(R) Capability Licensing Service TCP IP Interface - ok
13:29:28.0202 0x19f0 [ 72586E6D6DD4144D0C4CBD9D2653BBED, 3EE3CBB98D7A2CEEC92A86D5D2F49733BB1FD42F45CDE8973B71022E57093BBA ] IntelHSWPcc C:\WINDOWS\system32\drivers\IntelPcc.sys
13:29:28.0202 0x19f0 IntelHSWPcc - ok
13:29:28.0218 0x19f0 [ 9F7E87F6595D065A8A200A291043045E, 6944F72F73EADC6C9B7691F2C1C6DF1898F22C88EFA78EC0BA8CB5FFD9CE057B ] intelide C:\WINDOWS\system32\drivers\intelide.sys
13:29:28.0218 0x19f0 intelide - ok
13:29:28.0233 0x19f0 [ A6BD2E20AE1BC5CB2776C87C28E4F4CA, BD8BE67CED9A4982D785CE9ECBEFE868C3A2E37DF7F9592B9F9049B807A1554B ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys
13:29:28.0233 0x19f0 intelpep - ok
13:29:28.0249 0x19f0 [ 2A48DA39542636DB0FA3BA915385D1B3, 6CA0916F5F4B1E81AE6A6233276320599BFA7C129267177703E3BB6468FB4683 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys
13:29:28.0265 0x19f0 intelppm - ok
13:29:28.0265 0x19f0 [ DB32758F3A7F6CCE81A5430080A2EA65, 36A26BAA884E96804F8EA0B12BB3E81BBE6D4EE704809904091445F36CAB5A29 ] iorate C:\WINDOWS\system32\drivers\iorate.sys
13:29:28.0280 0x19f0 iorate - ok
13:29:28.0280 0x19f0 [ FE85D0A86CA7A5A99CF8CD04DE7F80AE, 544C01FC01EE728EB5667158207E5F4418FE77A88BA318192A834722DB766F4E ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
13:29:28.0296 0x19f0 IpFilterDriver - ok
13:29:28.0327 0x19f0 [ 68C50E8E4265698BE6835156F4DD5008, 5B9CBBCE99315E5569E6733F13E91A687A36F536A68A2B670CC24C4BCC4EAFF4 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll
13:29:28.0358 0x19f0 iphlpsvc - ok
13:29:28.0374 0x19f0 [ 10D01A3657AC8E8004C83D613163DE1E, F9389F1BF87A2D28899F50D270DA6F48B0912CFAF06CEE566697B041DBE92F9C ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys
13:29:28.0390 0x19f0 IPMIDRV - ok
13:29:28.0390 0x19f0 [ F1DAECC3B3D6399875D4F10529D6A77C, 6533D2F858816BE6570C998510919FCA2904EC6EF806F61C1FD325E88133111B ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys
13:29:28.0421 0x19f0 IPNAT - ok
13:29:28.0421 0x19f0 [ 7475A2903BB704B446AA6309E34D3362, C94643A1626A9716015EBA7041A1224098501EB7DAA704CBFCAD3DC6F3CFC6AF ] irda C:\WINDOWS\system32\drivers\irda.sys
13:29:28.0437 0x19f0 irda - ok
13:29:28.0437 0x19f0 [ 9725E7F0C64CE9916A5CDABE8D6E13C3, 04AF9E48FEF208A2850DF28352E8FDCBF4018982C72C0F67EE12C048C4070116 ] IRENUM C:\WINDOWS\system32\drivers\irenum.sys
13:29:28.0468 0x19f0 IRENUM - ok
13:29:28.0468 0x19f0 [ 8C604213A2E73088BFFE6CD2E6F1AE53, B4C4FEE4D398A29F72EC27D5668071D7E68CD943FFFC38624DD5DF5BEBDF46D3 ] irmon C:\WINDOWS\System32\irmon.dll
13:29:28.0483 0x19f0 irmon - ok
13:29:28.0483 0x19f0 [ 58040898883A96160D41739C80328BBF, 7F85C91C905811416E266A263DDEFCDCB0B45376AAE51B551AB636C16577DB9F ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys
13:29:28.0499 0x19f0 isapnp - ok
13:29:28.0515 0x19f0 [ CA20F4621AB8CD3F69199DE21B5B41C4, 0AFFC66DD10D4D15139337E5ED343A2ABBB26CC8A83B3BDF6AD10C68B3931A7C ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys
13:29:28.0530 0x19f0 iScsiPrt - ok
13:29:28.0546 0x19f0 [ 832F7C2747F04D1294AEF46A2CE5B63B, ABAECEFCAD9B526C3D98681A874966B924EB99AF61CDFAC6D5E767BE2FAF6CFA ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
13:29:28.0546 0x19f0 jhi_service - ok
13:29:28.0562 0x19f0 [ 210808437570BDDEE71A43535E3A2D30, EF5DE6EE4FF58F44CDE4D4E7F298ABBC9086EC05CC3AE4903060DA878115AC1E ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys
13:29:28.0562 0x19f0 kbdclass - ok
13:29:28.0577 0x19f0 [ 0B779E9FC426CA2268D28181FA6C222F, 83292023A688C3044D096F22242EB954B7F7511BE8341D45FF0AFBD9CB9BCB4E ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys
13:29:28.0593 0x19f0 kbdhid - ok
13:29:28.0593 0x19f0 [ 813BA3EB2CE038F2A5382DDD75CAD60B, 99FA444027CAC247B54317730D54AB0C4C000AE076B97E47470FDA9834594312 ] kdnic C:\WINDOWS\System32\drivers\kdnic.sys
13:29:28.0608 0x19f0 kdnic - ok
13:29:28.0608 0x19f0 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] KeyIso C:\WINDOWS\system32\lsass.exe
13:29:28.0624 0x19f0 KeyIso - ok
13:29:28.0640 0x19f0 [ 705C0F8BCCEF6E7CB704CCB454192D7E, FC608C708E2C3BF7A66E57B95E19E71E5F5C87EF359D8BC1A817500B45DF9338 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys
13:29:28.0655 0x19f0 KSecDD - ok
13:29:28.0655 0x19f0 [ 55AD13E2BAFC5AB53A10F8C271F5D242, 058BEF14DCB95574BCAB985F04737BA89483937E8D8A74F7B4CEAFB7400C2397 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys
13:29:28.0671 0x19f0 KSecPkg - ok
13:29:28.0671 0x19f0 [ 4ED115CD1A1099705F56B5E0FFF97CC6, 9CC49DF2CD6AAAE405BA661D13EFC1E05111D1DE3D1E50C39C425AF1F075610B ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys
13:29:28.0687 0x19f0 ksthunk - ok
13:29:28.0702 0x19f0 [ 8125BDF7ADC261F75EF0CAD92456E350, 184797AA1D58C4FF743BA60D48590B88B781EE7779205E45E0679DEC79F3E185 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll
13:29:28.0733 0x19f0 KtmRm - ok
13:29:28.0733 0x19f0 [ 8CCAB08815B50AD78B823DB3F96C8604, 265E6D582EB7207B5CC577D61CB7BC3646F613047F168CD69BB776C37780EBF5 ] LanmanServer C:\WINDOWS\system32\srvsvc.dll
13:29:28.0765 0x19f0 LanmanServer - ok
13:29:28.0780 0x19f0 [ 33DBBCF71F68EA97D9FD34E4C9AB5AC6, 104F04A1560E75EB224A3825707CE51E8798ABD764F5CC3B854FFFC93A39AF60 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
13:29:28.0796 0x19f0 LanmanWorkstation - ok
13:29:28.0858 0x19f0 [ D33A44F6591075DB9B03807CF7DE9E0A, C14639CE2D7AAD1985F58CFB50C5AA525855CBC8A389D81EE555F5229438C694 ] Lenovo Instant On C:\Program Files\Lenovo\InstantOn\InstantOnSrv.exe
13:29:28.0921 0x19f0 Lenovo Instant On - ok
13:29:28.0921 0x19f0 [ C8A237FF3FD137C30B9B1FF60078A3D2, FBAFA27AC680DAABB5D3A9C1E8CF2E4FFD97020E0848CB8D4D78E8D5CE8F5111 ] LENOVO.MICMUTE C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
13:29:28.0937 0x19f0 LENOVO.MICMUTE - ok
13:29:28.0937 0x19f0 [ F8EBAA1FE6D3BF84752931DE1BFA0E2A, 2F3C512712BA709BBBBD779D9E792DBE324876C402CDCEF0345B8B7ABE1D232A ] lfsvc C:\WINDOWS\System32\lfsvc.dll
13:29:28.0952 0x19f0 lfsvc - ok
13:29:28.0952 0x19f0 [ 5A23E4BE0CCF49663C4CF7EB74C20278, 9DF91014B13B7CED1C3D409F90858FD03EFC5C4347C98901B4DF0AFF2B77845D ] LicenseManager C:\WINDOWS\system32\LicenseManagerSvc.dll
13:29:28.0983 0x19f0 LicenseManager - ok
13:29:28.0983 0x19f0 [ 5933A6673F00D8255C52957E40C2D601, 0AA1281F8B3F97E360592D1B35EE7D3D614F1AB46007F9884CFFB1C5E647575E ] lltdio C:\WINDOWS\system32\drivers\lltdio.sys
13:29:28.0999 0x19f0 lltdio - ok
13:29:29.0015 0x19f0 [ 88A3C935725FA6EA1A228DCC26CF9C6F, 9B1F70644EEFA1EE7CE151A8A970430087339B7A6345F2E0252370929D4AFAC6 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll
13:29:29.0030 0x19f0 lltdsvc - ok
13:29:29.0030 0x19f0 [ 3F858E28AEE6545FA1B64134DFD5C2CE, FFD7B4FB0A7B61BC6B76A172134673842F2CF00E96FA3ED4A8273DC525B6BB92 ] lmhosts C:\WINDOWS\System32\lmhsvc.dll
13:29:29.0046 0x19f0 lmhosts - ok
13:29:29.0062 0x19f0 [ 76BC5705E1F838E32451ECF14518B1C8, 3F664723DCF6C07BDB3287184175F60DD7B4A85B0480800ECBE065730E2DA5F5 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
13:29:29.0077 0x19f0 LMS - ok
13:29:29.0093 0x19f0 [ 67569B50D28182AE1B21C46815CE58D0, 8332604147643BB151DB035F97A611B0D935DA6778266D9913BC945D5789EF87 ] LPlatSvc C:\WINDOWS\system32\LPlatSvc.exe
13:29:29.0108 0x19f0 LPlatSvc - ok
13:29:29.0124 0x19f0 [ 2D2075DDCEA5DFF7F30EB3C1470F84E8, 24E0C7B9A7D85E5A0AE1993973A76920F2363612115E716F5EBF7E83DEBEB79F ] LSCWinService C:\Program Files\Lenovo\Lenovo Solution Center\App\LSCWinService.exe
13:29:29.0140 0x19f0 LSCWinService - ok
13:29:29.0140 0x19f0 [ 8E1B0946948CCC0BC1FA3CB70374A795, 0B894C129A35E223FF9594725AC90916CBD597FAD2211A18FC2AE03EA8679597 ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys
13:29:29.0155 0x19f0 LSI_SAS - ok
13:29:29.0171 0x19f0 [ 4F68163FC04C973500DC4DA0946917B0, DF060C29109EB3978CEDFE781999B0C4C1E8C0FDB133428058D8400C53315EEC ] LSI_SAS2i C:\WINDOWS\system32\drivers\lsi_sas2i.sys
13:29:29.0171 0x19f0 LSI_SAS2i - ok
13:29:29.0187 0x19f0 [ E5AC5F2815938651CDCC27F425474673, 3AF0598982153C36A766506FA088F7B84333CC96FEBB050402547AFC613AF9F7 ] LSI_SAS3i C:\WINDOWS\system32\drivers\lsi_sas3i.sys
13:29:29.0187 0x19f0 LSI_SAS3i - ok
13:29:29.0202 0x19f0 [ CCF6EC9FB9B8F18E05B4253E81013E48, EBE8D77FEE8B99BD8C29702404774D554673C96DF3FDF3DCEA9C99E22C2709FC ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys
13:29:29.0218 0x19f0 LSI_SSS - ok
13:29:29.0233 0x19f0 [ D5EFC0BAEC21EDE6FE03D377D403B421, 41BE71AF7C896FD4C51EF7E3871AAB769164DFB8050DA43E48C7A100711414B4 ] LSM C:\WINDOWS\System32\lsm.dll
13:29:29.0265 0x19f0 LSM - ok
13:29:29.0265 0x19f0 [ C9579D32219E5B936AC3A48D470117EC, E61A77191B6BA25D29B1221FEBBE826BBC11F825C0E35A72B4CEFFF8B7FE59A8 ] luafv C:\WINDOWS\system32\drivers\luafv.sys
13:29:29.0280 0x19f0 luafv - ok
13:29:29.0296 0x19f0 [ 9F699136FA1A8A170C2C05D7790A5FC0, 4363C527BD2FC9FD8937E9866CA200809AC87B64EA57084491BAB6DEB8ED9E87 ] MapsBroker C:\WINDOWS\System32\moshost.dll
13:29:29.0312 0x19f0 MapsBroker - ok
13:29:29.0312 0x19f0 [ BDE2FC7213C0897524C1357BAAE30239, 1E1AB68145107429217E07A662477C86406E0188BE9F01CAC416AC13054D1A5E ] MBAMSwissArmy C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
13:29:29.0327 0x19f0 MBAMSwissArmy - ok
13:29:29.0343 0x19f0 [ D6067E2128F6AE309F9F39EE69DE85A0, 9D172FF4CA5AED9FB7CAE8E75151A25AC34251202C4ECF563535C0DD2500AC3A ] MBAMWebProtection C:\WINDOWS\system32\drivers\mwac.sys
13:29:29.0343 0x19f0 MBAMWebProtection - ok
13:29:29.0358 0x19f0 [ 0382A6E46EA4C79B25005E6597159C27, 0587839138301092C12323A7CF9E3E0A9BB1FBB0AAA97409145D0BCA77F89749 ] McAfee SiteAdvisor Service C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
13:29:29.0374 0x19f0 McAfee SiteAdvisor Service - ok
13:29:29.0390 0x19f0 [ 11D9A803DE0F825C59F3D4F17BD73A6E, FCD675CEE0B0CFFDF1A60251E1D753F7DB08223DCFCC107765EED7163FF2CFBD ] McAPExe C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe
13:29:29.0421 0x19f0 McAPExe - ok
13:29:29.0437 0x19f0 [ A52ACBECFE7BE36E377A203B969705AE, F42FB19123C5EF404267A911305E3A86411BD22E78944FAF2F189382E364CDF2 ] McBootDelayStartSvc C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
13:29:29.0452 0x19f0 McBootDelayStartSvc - ok
13:29:29.0468 0x19f0 [ 9CC3CA0D8C99F88642446ECD563ECCF5, 7EA997737291F69A1F26D1EEAAED107099484246657AB48135C32020DBE6EE12 ] McComponentHostService C:\Program Files\McAfee Security Scan\3.11.551\McCHSvc.exe
13:29:29.0483 0x19f0 McComponentHostService - ok
13:29:29.0515 0x19f0 [ 01B9FF6FA5F8605AE92695C1393CD833, A89709A51FE311CBACE1BFC28492C101E7F2D613481248F815D3FA0DB6900C29 ] mccspsvc C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\\McCSPServiceHost.exe
13:29:29.0562 0x19f0 mccspsvc - ok
13:29:29.0577 0x19f0 [ A52ACBECFE7BE36E377A203B969705AE, F42FB19123C5EF404267A911305E3A86411BD22E78944FAF2F189382E364CDF2 ] McMPFSvc C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
13:29:29.0608 0x19f0 McMPFSvc - ok
13:29:29.0624 0x19f0 [ A52ACBECFE7BE36E377A203B969705AE, F42FB19123C5EF404267A911305E3A86411BD22E78944FAF2F189382E364CDF2 ] McNaiAnn C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
13:29:29.0640 0x19f0 McNaiAnn - ok
13:29:29.0671 0x19f0 [ D4AD64832DF34E2C7916088D75B20152, F74E1049EB9ACD8BFDCB88669781E4655B4555E4F699BA57CD641F9058E6A139 ] McODS C:\Program Files\McAfee\VirusScan\mcods.exe
13:29:29.0702 0x19f0 McODS - ok
13:29:29.0718 0x19f0 [ A52ACBECFE7BE36E377A203B969705AE, F42FB19123C5EF404267A911305E3A86411BD22E78944FAF2F189382E364CDF2 ] mcpltsvc C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
13:29:29.0733 0x19f0 mcpltsvc - ok
13:29:29.0749 0x19f0 [ A52ACBECFE7BE36E377A203B969705AE, F42FB19123C5EF404267A911305E3A86411BD22E78944FAF2F189382E364CDF2 ] McProxy C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
13:29:29.0765 0x19f0 McProxy - ok
13:29:29.0780 0x19f0 [ C3CDCCF07486BD2616A7B82946E07AC0, 1EF95DAB2DA856BC7D7573B2EB2D9006DF337F827F0B56A161D0C97F45DB755E ] megasas C:\WINDOWS\system32\drivers\megasas.sys
13:29:29.0780 0x19f0 megasas - ok
13:29:29.0796 0x19f0 [ 2CF0CB2A0ED68C5455371E84C16F9627, 1C9166B52140145F1968E83E52BFF041250811B23C770FE181A18A4BA060CA81 ] megasas2i C:\WINDOWS\system32\drivers\MegaSas2i.sys
13:29:29.0796 0x19f0 megasas2i - ok
13:29:29.0812 0x19f0 [ FADB2FE017E69EECE0E1BA78661C2E8C, BE99B49031D8B4B670B6F6B6E829E54406779CF6F1D8AFE8AB79A73E6764AB2F ] megasr C:\WINDOWS\system32\drivers\megasr.sys
13:29:29.0843 0x19f0 megasr - ok
13:29:29.0843 0x19f0 [ C0CBCF18B6F105109566E837461333B7, B2B89D57C1373C6EF4E8C7C4B5AE40AA5596C0B672DB753AC42AC87D56433964 ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys
13:29:29.0858 0x19f0 MEIx64 - ok
13:29:29.0874 0x19f0 [ 55A417C3E41F2A98666CF929EC19108E, A38C262B2863C87E4151525BF26D6AC16E7982D370E2C6998EB15C88C4BC8254 ] MessagingService C:\WINDOWS\System32\MessagingService.dll
13:29:29.0890 0x19f0 MessagingService - ok
13:29:29.0905 0x19f0 [ 5FBBB352A34904A4A374C3EB62A09F15, 6EBA43181E8EBAE8A82145CDA17434903B720BA73F9D4297FB28F96C122E40B8 ] mfeaack C:\WINDOWS\system32\drivers\mfeaack.sys
13:29:29.0921 0x19f0 mfeaack - ok
13:29:29.0937 0x19f0 [ D65406A780E64B5E6C48A06C8F2439A6, 3AA3BB5A3EA5798BE2DBDC3B3355F4F9F04CEC565F834DD8FB6A419A2DDAC53A ] mfeavfk C:\WINDOWS\system32\drivers\mfeavfk.sys
13:29:29.0952 0x19f0 mfeavfk - ok
13:29:29.0952 0x19f0 [ F64C5922E34CD0C786F7C8117A023F13, FCB51448366EB9E896205086F04A98479D94D2586D84D680241F123CB2653005 ] mfeelamk C:\WINDOWS\system32\drivers\mfeelamk.sys
13:29:29.0968 0x19f0 mfeelamk - ok
13:29:29.0968 0x19f0 [ 4EAFB984E9533263B7D2F0C20DA822C1, EE60B94B632690FF9CFC423C7F0D28EE2EAB375430F7E59EBDB12D415763F6FB ] mfefire C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
13:29:29.0983 0x19f0 mfefire - ok
13:29:29.0999 0x19f0 [ 6ABC14D586E9DCCFF37988D0EC6B1345, DC40223FEF0CD2D1F5EB1CA6D67E8C889FCDC8AB2EE44508BD2C51070A50CA71 ] mfefirek C:\WINDOWS\system32\drivers\mfefirek.sys
13:29:30.0015 0x19f0 mfefirek - ok
13:29:30.0030 0x19f0 [ 37914975BD1A752161A6A68D6755BD98, A05BC57CD14520862AFE77C79AB6642EA6E442B8DFB8D1626FF238FEF6FFFFA5 ] mfehidk C:\WINDOWS\system32\drivers\mfehidk.sys
13:29:30.0062 0x19f0 mfehidk - ok
13:29:30.0077 0x19f0 [ 39B7315698B6F19BC14F2D538EF72981, E94663052849F0A6593C17F5412F1FC21174C225173866B335E534DB4539A8A2 ] mfemms C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe
13:29:30.0093 0x19f0 mfemms - ok
13:29:30.0093 0x19f0 [ 4306C4FA3551B1E6725B07BD4EF6EC02, 9B3DE12CDFA2FB33D39B08346279052D150B489B2696A9C4A637983A7F45EA11 ] mfencbdc C:\WINDOWS\system32\DRIVERS\mfencbdc.sys
13:29:30.0124 0x19f0 mfencbdc - ok
13:29:30.0124 0x19f0 [ 79404EA7FFB82C9426A06CC97DE8E83B, E1BAA3B92A5C91DA7B6E6BCB02EC8DA23F5AEB52C8BCA9052323B7462B7BD6DB ] mfencrk C:\WINDOWS\system32\DRIVERS\mfencrk.sys
13:29:30.0140 0x19f0 mfencrk - ok
13:29:30.0140 0x19f0 [ 3A2C7251E0F4992AFA2E7636F045B723, 722FE227A18106673FA7E78B1F7B42285F7E016EEBDF75983C842A53DDEF62CC ] mfeplk C:\WINDOWS\system32\drivers\mfeplk.sys
13:29:30.0155 0x19f0 mfeplk - ok
13:29:30.0155 0x19f0 [ DA49A90A69B3284FD11B6F02D0209A99, 759380964E6450FF21FB9A2BD23BA0394B005EC332E714D40D47262FCDC6CFE9 ] mfesapsn C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys
13:29:30.0171 0x19f0 mfesapsn - ok
13:29:30.0171 0x19f0 [ 43DB4E36146D076EBD7B864162C8C242, 3A84F17D3FCC9D3E481032A452D0984668AE286FCD9379A4204C1AD048A4BA6A ] mfevtp C:\WINDOWS\system32\mfevtps.exe
13:29:30.0187 0x19f0 mfevtp - ok
13:29:30.0202 0x19f0 [ 0143C30546864E43EB507AFBF2DC9E58, E09C4CFE0364805C522D355900FF7BDA1A6FFF5EDCAB094DA52AC9D90FB5D826 ] mfewfpk C:\WINDOWS\system32\drivers\mfewfpk.sys
13:29:30.0202 0x19f0 mfewfpk - ok
13:29:30.0233 0x19f0 [ FD60818B66B2E8A5415EA840E99A9D8F, 5D2F22909354534B821D958FBEF6A40EB4F642F53C7B509D00949096EF716F36 ] mlx4_bus C:\WINDOWS\System32\drivers\mlx4_bus.sys
13:29:30.0249 0x19f0 mlx4_bus - ok
13:29:30.0265 0x19f0 [ 68F6977F1CFBAAC770D940A8C0326FA1, 90EE1E7DAC680EAA5AD50E9B0B9FD8FCE8DD6A02D5EF941B5AA5084CBD40BB80 ] MMCSS |