Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Cant update avg, malewarebytes or windows update. [Closed]

avg; malewarebytes

  • This topic is locked This topic is locked

#1
stealthhawk

stealthhawk

    New Member

  • Member
  • Pip
  • 8 posts

Hi.  

 

I have been reading fix's on the forums but I am totally lost.

 

About a week ago I was looking at my resource monitor and my win7 laptop had started to upload/download in alot of different areas. (processes/ network and Tcp) svchost (no impersonation) mostly.  I tried to shut down any processes that may have been at fault but...

 

Long story short... I ended up doing a full sys factory reset.

 

Now my system is still running some tcp connections etc. I re-downloaded Avg and malwarebytes but neither of them are able to update... also windows update cant even update.

But even when they could none of them found any problem.

 

So i dont know where to start now....

 

Im typing this on the infected computer...watching the resource manager chew my internet data :(

 

Is there anything I can do to secure my laptop?

 

 

 

Thanks


  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi first thing to do is look at the system

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select additions at the bottom
  • Press Scan button.
    frst.JPG
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please attach both logs generated.

  • 0

#3
stealthhawk

stealthhawk

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Thanks for the reply :)

 

Here are the logs.

Attached Files


  • 0

#4
stealthhawk

stealthhawk

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

should I apply the fix?


  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
What errors do you get when you try to update ?

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
Toolbar: HKU\S-1-5-21-1799504929-2277344849-154051625-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Download the latest version of TDSSKiller from here and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application
    tdss%20start.JPG
  • Then click on Change parameters.

    tdss%20Change%20param.JPG
  • Check the boxes beside Verify Driver Digital Signature, Detect TDLFS file system and Use KSN to scan objects , then click OK.
  • Click the Start Scan button.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.

    tdss%20threat.JPG
  • If malicious objects are found, they will show in the Scan results and offer three (3) options.
  • Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
  • Get the report by selecting Reports

    tdss%20report.JPG
  • Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.
  • 0

#6
stealthhawk

stealthhawk

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Thanks

 

Here is the fixlog... Im about to run tdsskiller.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by hawk at 2015-04-10 06:41:35 Run:1
Running from C:\Users\hawk\Desktop
Loaded Profiles: hawk (Available profiles: hawk)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
CreateRestorePoint:
Toolbar: HKU\S-1-5-21-1799504929-2277344849-154051625-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers

*****************

Restore point was successfully created.
HKU\S-1-5-21-1799504929-2277344849-154051625-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.

========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

 

========= End of Reg: =========

========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

 

========= End of Reg: =========

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.
HKU\S-1-5-21-1799504929-2277344849-154051625-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value deleted successfully.
HKU\S-1-5-21-1799504929-2277344849-154051625-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value deleted successfully.

========= End of RemoveProxy: =========

=========  netsh advfirewall reset =========

Ok.

========= End of CMD: =========

=========  netsh advfirewall set allprofiles state ON =========

Ok.

========= End of CMD: =========

=========  ipconfig /flushdns =========

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

=========  netsh winsock reset catalog =========

Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.

========= End of CMD: =========

=========  netsh int ip reset c:\resetlog.txt =========

Reseting Global, OK!
Reseting Interface, OK!
Reseting Subinterface, OK!
Restart the computer to complete this action.

========= End of CMD: =========

=========  ipconfig /release =========

Windows IP Configuration

No operation can be performed on Local Area Connection while it has its media disconnected.

Wireless LAN adapter Wireless Network Connection:

   Connection-specific DNS Suffix  . :
   Link-local IPv6 Address . . . . . : fe80::6d12:b13b:6156:8215%13
   Default Gateway . . . . . . . . . :

Ethernet adapter Local Area Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : C1-LINE.COM

Tunnel adapter isatap.slingshot.DSL:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Tunnel adapter Local Area Connection* 12:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Tunnel adapter isatap.C1-LINE.COM:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Connection-specific DNS Suffix  . :
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6abd:180f:3af0:3f57:fef4
   Link-local IPv6 Address . . . . . : fe80::180f:3af0:3f57:fef4%17
   Default Gateway . . . . . . . . . : ::

========= End of CMD: =========

=========  ipconfig /renew =========

Windows IP Configuration

No operation can be performed on Local Area Connection while it has its media disconnected.

Wireless LAN adapter Wireless Network Connection:

   Connection-specific DNS Suffix  . : slingshot.DSL
   Link-local IPv6 Address . . . . . : fe80::6d12:b13b:6156:8215%13
   IPv4 Address. . . . . . . . . . . : 192.168.1.11
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1

Ethernet adapter Local Area Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : C1-LINE.COM

Tunnel adapter isatap.slingshot.DSL:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Tunnel adapter Local Area Connection* 12:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Tunnel adapter isatap.C1-LINE.COM:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Connection-specific DNS Suffix  . :
   IPv6 Address. . . . . . . . . . . : 2001:0:9d38:6abd:180f:3af0:3f57:fef4
   Link-local IPv6 Address . . . . . : fe80::180f:3af0:3f57:fef4%17
   Default Gateway . . . . . . . . . : ::

========= End of CMD: =========

=========  netsh int ipv4 reset =========

Reseting Interface, OK!
Restart the computer to complete this action.

========= End of CMD: =========

=========  netsh int ipv6 reset =========

Reseting Interface, OK!
Reseting Subinterface, OK!
Restart the computer to complete this action.

========= End of CMD: =========

=========  bitsadmin /reset /allusers =========

BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

Unable to cancel {FC5B03C8-47D0-4439-B522-7195D868959C}.
Unable to cancel {9A2236CB-63CD-47F5-8793-64E2A296D45A}.
Unable to cancel {3B7AB6FC-41AB-43B2-AE1E-EFEDCDB3CDB1}.
Unable to cancel {07F5176D-28FF-47BE-98EE-CC375EED5B32}.
Unable to cancel {AEF1DC90-CBED-49BE-80FC-ECDD77BB886D}.
Unable to cancel {8969C78B-419F-400A-87F2-890645A494F3}.
Unable to cancel {4768A266-E39D-4F84-B5EC-5A62CCF250FB}.
Unable to cancel {100EF316-C3EE-4C5D-8C32-0B310D5E933D}.
Unable to cancel {8BD4D87C-EB16-480E-9515-AF198B9A39E7}.
Unable to cancel {E40B3B0B-AB7B-45D1-BF0F-55153F6DBE07}.
Unable to cancel {FA76AE35-0F55-4A99-B871-001C3387B9A3}.
Unable to cancel {497699DE-382B-433D-81C4-17A7396C985C}.
Unable to cancel {4126FF82-7FBB-476F-B5C0-DEA07A075DF2}.
Unable to cancel {A04D9051-62E9-4C70-A594-8AAEFE0324A3}.
Unable to cancel {0918AC63-F0C5-4EFB-A86B-8244AEADC2BA}.
Unable to cancel {324101CC-52C7-43B2-B0D1-569D42067B2B}.
Unable to cancel {EEC61525-CF1A-49D3-B6E8-A07400FA6297}.
Unable to cancel {1D260011-41FA-49AF-A4FC-021C4B2A2FE7}.
Unable to cancel {180BCC76-17DD-40A3-AEA3-A02B7FCF522A}.
Unable to cancel {EA7D0072-564F-4530-937E-BF8DB1A32978}.
Unable to cancel {73447AF7-17A0-4D6B-BD77-E492462799B1}.
Unable to cancel {C4003FF5-744C-4D33-AEC2-50BB2A0AFD9B}.
Unable to cancel {D909DA43-45A3-4C7F-8A7C-0781AF61B336}.
Unable to cancel {73466817-5A31-458B-A5A5-31A47111BB97}.
Unable to cancel {A18203A0-EFB4-40AB-9E62-90D0D5A54E75}.
Unable to cancel {071660DC-A318-4B5F-84A7-4139FEB9BBA5}.
Unable to cancel {C8FADDAA-9B74-40E0-AD4D-76CB1436ADB0}.
Unable to cancel {5FB4CF0A-0070-4863-BEC4-8295F9EE5A43}.
Unable to cancel {FB80C087-CE04-47E5-936E-AD2BBDD7824C}.
Unable to cancel {E10C6A31-A159-4396-8E5C-D859F6432B50}.
Unable to cancel {E7656CC7-3D9E-4745-965C-DAF9327AB426}.
Unable to cancel {6B4D2A76-5869-4F0A-8A2B-8204130E3E70}.
Unable to cancel {B4FFA0C5-7AA9-45D6-9BC8-A0648EE32A42}.
Unable to cancel {32D4788D-756A-4A62-A88B-121340236C99}.
Unable to cancel {DDEDF317-B65A-4018-A6F9-2629DE885FD4}.
Unable to cancel {08D095AC-79B0-4FB8-B49B-B5C210E78836}.
Unable to cancel {7753118F-2F63-4003-B3E5-DA4C5A87B574}.
Unable to cancel {7CA018D3-265F-4F2C-8B6F-7ACAC837781D}.
Unable to cancel {F727D526-C30F-4931-B74A-E61C748CF8D3}.
Unable to cancel {8CDFBE09-71BF-4C4B-86BD-D7704A9B6739}.
Unable to cancel {464F8B11-5419-4066-B350-9C2C97BDE702}.
Unable to cancel {02FCBCC3-8C58-4617-9598-37A5C88ED9D8}.
Unable to cancel {D77F6B94-7BC3-4B08-A85E-E2AFB6412310}.
Unable to cancel {C7D65D1C-259C-4315-92CF-DCA203E89D8D}.
Unable to cancel {D96CD2D5-3501-49EA-8053-9A8990ADE1A2}.
Unable to cancel {09A78F59-3E3F-46D6-AF85-2BD923FB2DE7}.
Unable to cancel {0C6DA6C0-75BD-45D1-957B-16CBDD022D23}.
Unable to cancel {36CFEE09-3A2E-46FF-8987-C403797F1E97}.
Unable to cancel {0ED6D374-9628-452E-BA24-8C6C606E67A3}.
Unable to cancel {CFB1CD35-A19C-4322-BAA5-CBF7F4A54BF9}.
Unable to cancel {D19BE510-8970-42FC-90F1-918E42BAAD0D}.
Unable to cancel {854A60B3-88DA-4ADD-A1F8-52C65876B3E5}.
Unable to cancel {983A6EF9-D8E8-42A5-973D-4C23EFBCBE40}.
Unable to cancel {C28A2093-7BD6-4C8D-8D9B-57FCEE1903B3}.
Unable to cancel {45690EA2-FDD5-45EE-80E7-58C420C32DFA}.
Unable to cancel {578D5C83-C5A4-42AE-B0A3-44B897119CC1}.
Unable to cancel {1AA3D4B6-4A5B-471A-9431-83E8404DB73F}.
Unable to cancel {5C677221-E3FA-4546-AD83-9A3F385BBF52}.
Unable to cancel {7BA237E6-8161-4F4A-A495-55D7F447AD51}.
Unable to cancel {CED723BD-BE09-45E7-8739-719E3D51CDBB}.
Unable to cancel {F99E0066-96FE-4067-BC86-99A362C6B30F}.
Unable to cancel {635F0CED-FC4B-4431-BF4D-E7963235776E}.
Unable to cancel {A621F267-6DCB-49AB-99E5-D9D2071F106A}.
Unable to cancel {026D471B-7859-4395-88F2-F4C79BC1B390}.
Unable to cancel {56FB455D-FCEF-460B-BB34-6DED6F477895}.
Unable to cancel {D07CBDA7-9B40-4D76-AD73-B6161EABDA00}.
Unable to cancel {878E1A4D-CF7C-4A0C-8CC3-A2BF1F746ED4}.
Unable to cancel {C519DEEE-4F28-4EE5-AD60-E07D9DDB2743}.
Unable to cancel {4FA84043-1DFF-4D71-B90D-4736DD440AA5}.
Unable to cancel {A9D933FD-FA8E-4F5B-B025-11F4D937897E}.
Unable to cancel {14DAC077-C4AD-4424-9C16-91C3B7583A9D}.
Unable to cancel {E968B8A0-7044-4E53-9618-1B402993AFA3}.
Unable to cancel {42F04361-29BD-4D3F-96FD-00B008AC8FD7}.
Unable to cancel {30E98D44-EE8F-4783-91E9-B99319561935}.
Unable to cancel {BB2A7E62-1FBB-48C2-B175-1A4661E25099}.
Unable to cancel {206F60FB-C39C-4C19-8FAE-93A77CA6A0E3}.
Unable to cancel {5146C968-B4DC-4F58-9785-831F7E561418}.
Unable to cancel {E9A25190-2EB3-4027-B617-FF6071962603}.
Unable to cancel {FECCD488-4B70-4644-A719-7FD7438881A7}.
Unable to cancel {BED01F31-5298-41C5-9C8E-9F6B25908817}.
Unable to cancel {E118AE30-C04C-4B89-9402-E44307F98BDE}.
Unable to cancel {19B3FA42-62C7-485F-9A37-59F3A6E06928}.
Unable to cancel {9F3F2D54-C022-4B24-A0BF-A47623885875}.
Unable to cancel {A265FFD6-A701-418A-9F47-A88290030B97}.
Unable to cancel {F182FAAB-F48C-43A1-8D10-7CA13D1B5BBA}.
Unable to cancel {A96C9A2A-C610-483F-ABF6-C54B6173A649}.
Unable to cancel {A0F50BDD-887E-4E4D-821A-ADD7BE0F9636}.
Unable to cancel {38F5E482-D683-434C-967E-E65DB5A65BDA}.
Unable to cancel {2041B86A-A294-428B-950F-A818FF94096F}.
Unable to cancel {20B72CFA-653A-47AE-8FD8-1CC783A59F6D}.
Unable to cancel {B1D9F988-DB6E-4823-9FB0-B4E4F9782CBC}.
Unable to cancel {F3689EF7-6FA5-44FF-A996-6AA1716D1906}.
Unable to cancel {F58279A6-7049-47AD-8EA6-4340BD3EEA2C}.
Unable to cancel {60D802DF-0B02-4A89-915D-BEFCA75DAD48}.
Unable to cancel {E15BF71F-ABCC-46D0-B990-F9A6FB7499E2}.
Unable to cancel {CBC79849-C652-43B9-849B-26018BB1FB17}.
Unable to cancel {CC788EFB-4073-4BB9-98AC-14097D8448AA}.
Unable to cancel {BC58D09A-46F0-4D14-A82F-12559633FEEB}.
Unable to cancel {E838B515-7AE2-4C1C-B339-4C3C840CF823}.
Unable to cancel {348CE007-DFF0-4C07-B3BD-F33E0C57DEC3}.
Unable to cancel {DB52D853-F6AF-42AD-9AD1-E6F1A909AA9F}.
Unable to cancel {049606D7-E3F9-42CD-BD62-9BB0CC32D9D2}.
Unable to cancel {029A93CF-DCF9-4CDE-8ABC-2372F663C32C}.
Unable to cancel {2F27C0FF-2F20-4742-B84A-E2F928CBCA1C}.
Unable to cancel {34F7A9C1-4195-4E3C-9736-18657E86C01C}.
Unable to cancel {ECC698B5-9802-4EEF-8A3E-130C760307D4}.
Unable to cancel {F14C4A1A-30D6-45D8-B6AF-E45FF8AD17EC}.
Unable to cancel {43C01444-468D-4588-9D60-D4785BEEFE11}.
Unable to cancel {74C84C23-1D51-4091-A272-C6C7BCBF44C2}.
Unable to cancel {40B710E7-3035-46C7-9851-D16AFE0777E5}.
Unable to cancel {FC1F47AE-7F6D-4F3C-84F1-57EEFF8CA338}.
Unable to cancel {FD68E1BA-4A63-4E84-B8C3-D6B65CA3D981}.
Unable to cancel {6252D704-A1D5-471B-9415-743BA6845D5E}.
Unable to cancel {33E6BEC5-FF51-44E5-B3B0-CDE3F9435632}.
Unable to cancel {585D71F3-A20D-4F2D-9CDE-AE749F2B90E5}.
Unable to cancel {E6AB1A5E-43C3-4404-8077-A816CC5258D0}.
Unable to cancel {666B25DD-C362-4F46-A308-F7F85810A3E5}.
Unable to cancel {0542CAD0-7D0F-4D19-82A6-6584D02831AA}.
Unable to cancel {36D29F0C-29DD-4AF9-99CD-75139E5024F6}.
Unable to cancel {284EBD68-0ADC-41AB-9B01-5D64A1BF81E4}.
Unable to cancel {35D64A08-497E-4EF4-8802-3E7CA7809E5C}.
Unable to cancel {043126E2-53F5-4B67-9876-D2C65EF44406}.
Unable to cancel {88A0FB9B-921F-4F3A-8C61-F660C9A179A1}.
Unable to cancel {FC32E919-AE5D-4F5F-971D-1A1BAB82C876}.
Unable to cancel {D4DE7838-C95B-476A-910A-1E5B817B8D1C}.
Unable to cancel {FC876E4B-45ED-42A1-833B-D1EA0EB9EC7A}.
Unable to cancel {CD2C9FAE-6EB4-4FD3-B019-F67699D16BC2}.
Unable to cancel {F6245188-5FBF-4A2A-A431-2BBD37D4250A}.
Unable to cancel {74795D76-CCFC-482C-A0DB-7EADD9694ABC}.
Unable to cancel {629D6A41-65C5-4A6F-97FC-680BF0EB70CD}.
Unable to cancel {DBB013EF-C290-492D-9559-D4D6C6B7B9E2}.
Unable to cancel {F739AF8A-A975-41BB-8F0C-0F7C7331D9A7}.
Unable to cancel {5F265932-0DD7-41EA-B870-6E265A7513D8}.
Unable to cancel {F60FB842-2300-41F1-8286-143E69993E7D}.
Unable to cancel {7ECF3E5C-F2B0-4170-9EEB-3E98605A3F57}.
Unable to cancel {BBBFF54E-6C20-47EA-9F7E-66470FD44B40}.
Unable to cancel {421E2C40-8975-45F0-A9B3-C19A4B481BA2}.
Unable to cancel {D15C0C77-9659-4343-9990-AFD01AD32ECB}.
Unable to cancel {5AA7BC05-F5FE-46D6-9741-DE2D1B3A9DF4}.
0 out of 139 jobs canceled.

========= End of CMD: =========

EmptyTemp: => Removed 8.1 MB temporary data.

The system needed a reboot.

==== End of Fixlog 06:42:05 ====


  • 0

#7
stealthhawk

stealthhawk

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

07:05:24.0791 0x083c TDSS rootkit removing tool 3.0.0.44 Jan 22 2015 08:27:04

07:05:34.0013 0x083c ============================================================

07:05:34.0013 0x083c Current date / time: 2015/04/10 07:05:34.0013

07:05:34.0013 0x083c SystemInfo:

07:05:34.0013 0x083c

07:05:34.0013 0x083c OS Version: 6.1.7601 ServicePack: 1.0

07:05:34.0013 0x083c Product type: Workstation

07:05:34.0013 0x083c ComputerName: HAWK-HP

07:05:34.0013 0x083c UserName: hawk

07:05:34.0013 0x083c Windows directory: C:\Windows

07:05:34.0013 0x083c System windows directory: C:\Windows

07:05:34.0013 0x083c Running under WOW64

07:05:34.0013 0x083c Processor architecture: Intel x64

07:05:34.0013 0x083c Number of processors: 4

07:05:34.0013 0x083c Page size: 0x1000

07:05:34.0013 0x083c Boot type: Normal boot

07:05:34.0013 0x083c ============================================================

07:05:34.0574 0x083c KLMD registered as C:\Windows\system32\drivers\43410320.sys

07:05:35.0089 0x083c System UUID: {5FA10F63-6171-EF04-C74D-E1E6275B6A25}

07:05:35.0588 0x083c Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040

07:05:35.0588 0x083c ============================================================

07:05:35.0588 0x083c \Device\Harddisk0\DR0:

07:05:35.0588 0x083c MBR partitions:

07:05:35.0588 0x083c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x63800

07:05:35.0588 0x083c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64000, BlocksNum 0x37C80000

07:05:35.0588 0x083c \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x37CE4000, BlocksNum 0x1EB2000

07:05:35.0588 0x083c \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x39B96000, BlocksNum 0x7EF830

07:05:35.0588 0x083c ============================================================

07:05:35.0640 0x083c C: <-> \Device\Harddisk0\DR0\Partition2

07:05:35.0687 0x083c D: <-> \Device\Harddisk0\DR0\Partition3

07:05:35.0687 0x083c E: <-> \Device\Harddisk0\DR0\Partition4

07:05:35.0687 0x083c ============================================================

07:05:35.0687 0x083c Initialize success

07:05:35.0687 0x083c ============================================================

07:06:20.0454 0x02fc ============================================================

07:06:20.0454 0x02fc Scan started

07:06:20.0454 0x02fc Mode: Manual; SigCheck; TDLFS;

07:06:20.0454 0x02fc ============================================================

07:06:20.0454 0x02fc KSN ping started

07:06:23.0615 0x02fc KSN ping finished: true

07:06:24.0832 0x02fc ================ Scan system memory ========================

07:06:24.0832 0x02fc System memory - ok

07:06:24.0832 0x02fc ================ Scan services =============================

07:06:25.0222 0x02fc [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys

07:06:25.0331 0x02fc 1394ohci - ok

07:06:25.0383 0x02fc [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI C:\Windows\system32\drivers\ACPI.sys

07:06:25.0398 0x02fc ACPI - ok

07:06:25.0414 0x02fc [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys

07:06:25.0430 0x02fc AcpiPmi - ok

07:06:25.0476 0x02fc [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys

07:06:25.0492 0x02fc adp94xx - ok

07:06:25.0539 0x02fc [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci C:\Windows\system32\drivers\adpahci.sys

07:06:25.0554 0x02fc adpahci - ok

07:06:25.0586 0x02fc [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320 C:\Windows\system32\drivers\adpu320.sys

07:06:25.0601 0x02fc adpu320 - ok

07:06:25.0617 0x02fc [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B253C7329949156 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll

07:06:25.0726 0x02fc AeLookupSvc - ok

07:06:25.0820 0x02fc [ D5B031C308A409A0A576BFF4CF083D30, 081FCB53C65BC48093AEA5B067757F04C5C92F920D32A4DF01DD1DFF6B2FB20D ] AFD C:\Windows\system32\drivers\afd.sys

07:06:25.0898 0x02fc AFD - ok

07:06:25.0929 0x02fc [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440 C:\Windows\system32\drivers\agp440.sys

07:06:25.0944 0x02fc agp440 - ok

07:06:25.0976 0x02fc [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG C:\Windows\System32\alg.exe

07:06:26.0007 0x02fc ALG - ok

07:06:26.0038 0x02fc [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide C:\Windows\system32\drivers\aliide.sys

07:06:26.0054 0x02fc aliide - ok

07:06:26.0100 0x02fc [ 46052887A640397A834CFA61D607BFC5, 64977D48662AD3EBC89C3079AEB0ED79FAE3846AF3C42577E24FD4EF8B3CEECD ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe

07:06:26.0178 0x02fc AMD External Events Utility - ok

07:06:26.0210 0x02fc [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide C:\Windows\system32\drivers\amdide.sys

07:06:26.0225 0x02fc amdide - ok

07:06:26.0241 0x02fc [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys

07:06:26.0272 0x02fc AmdK8 - ok

07:06:26.0600 0x02fc [ F419E5CC07DECDAB85E4E6ADAB1DBB49, 205AD5717D0FBA5F6C91B299CEF40BBA9E31394CDEEFB945433B09DF0AB16CAA ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys

07:06:26.0990 0x02fc amdkmdag - ok

07:06:27.0021 0x02fc [ A2F3F99349169D53E91A953A6F539635, B5E50060D264EAC20143A5A57BF6A7074636C4412137B9954982122F24B04CED ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys

07:06:27.0052 0x02fc amdkmdap - ok

07:06:27.0083 0x02fc [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys

07:06:27.0099 0x02fc AmdPPM - ok

07:06:27.0130 0x02fc [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata C:\Windows\system32\drivers\amdsata.sys

07:06:27.0130 0x02fc amdsata - ok

07:06:27.0161 0x02fc [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys

07:06:27.0161 0x02fc amdsbs - ok

07:06:27.0208 0x02fc [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata C:\Windows\system32\drivers\amdxata.sys

07:06:27.0208 0x02fc amdxata - ok

07:06:27.0239 0x02fc [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644ED2E50CF9BB491A ] AppID C:\Windows\system32\drivers\appid.sys

07:06:27.0369 0x02fc AppID - ok

07:06:27.0400 0x02fc [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF99229794FEF07C4BBE725 ] AppIDSvc C:\Windows\System32\appidsvc.dll

07:06:27.0447 0x02fc AppIDSvc - ok

07:06:27.0463 0x02fc [ 3977D4A871CA0D4F2ED1E7DB46829731, 2AF1C3225994769C3FD25CD7E9603964B035576F25B0B6D91545566E0722FFAA ] Appinfo C:\Windows\System32\appinfo.dll

07:06:27.0509 0x02fc Appinfo - ok

07:06:27.0556 0x02fc [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc C:\Windows\system32\drivers\arc.sys

07:06:27.0587 0x02fc arc - ok

07:06:27.0587 0x02fc [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas C:\Windows\system32\drivers\arcsas.sys

07:06:27.0603 0x02fc arcsas - ok

07:06:27.0619 0x02fc [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys

07:06:27.0665 0x02fc AsyncMac - ok

07:06:27.0681 0x02fc [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi C:\Windows\system32\drivers\atapi.sys

07:06:27.0681 0x02fc atapi - ok

07:06:27.0759 0x02fc [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll

07:06:27.0790 0x02fc AudioEndpointBuilder - ok

07:06:27.0821 0x02fc [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235313A37FCE8F0F6 ] AudioSrv C:\Windows\System32\Audiosrv.dll

07:06:27.0853 0x02fc AudioSrv - ok

07:06:27.0899 0x02fc [ 54FE1CAFA3B3029B282E6A05EA672031, E972B8A22322FF06903A1E3AB20585E02A21C3A6EA9A75C172231494A08D14D1 ] Avgdiska C:\Windows\system32\DRIVERS\avgdiska.sys

07:06:27.0915 0x02fc Avgdiska - ok

07:06:28.0149 0x02fc [ E2FDE8691C03525F095C8D01F005FA97, B234D8642F528550FB246127CBA24A2A115F8EAF8ED1BC8FD37562AFEBEF4978 ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe

07:06:28.0211 0x02fc AVGIDSAgent - ok

07:06:28.0243 0x02fc [ 079F75EE36CD275620298DA7D7636006, 323BA7B327BBE1FBEED3D16D83C2CF0DE5D0D0B9F38A86E3B93E40547FA742B7 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdrivera.sys

07:06:28.0258 0x02fc AVGIDSDriver - ok

07:06:28.0289 0x02fc [ 68070AEEE757ACC6EC5BC291B1E8EA1A, 8A4902CE6F4696F33CD6CF98F96FDA7895B99A676916F3137CF34192AF3C25A4 ] AVGIDSHA C:\Windows\system32\DRIVERS\avgidsha.sys

07:06:28.0305 0x02fc AVGIDSHA - ok

07:06:28.0321 0x02fc [ 7C9E8FD2BFCE60BDF9B5944C0BE47C87, 0F51507BAECDEF7B6F553066621A03832FF070EC6837A8E304AABA1227F779BF ] Avgldx64 C:\Windows\system32\DRIVERS\avgldx64.sys

07:06:28.0321 0x02fc Avgldx64 - ok

07:06:28.0352 0x02fc [ 179835151F9B3FCC2FCB5E633D4F1A2B, 0520CF4C897BD74601CB887E583A7F45AC78B8420293CDE0F8107FB05CD2AA70 ] Avgloga C:\Windows\system32\DRIVERS\avgloga.sys

07:06:28.0367 0x02fc Avgloga - ok

07:06:28.0399 0x02fc [ 66B7273493BF49EE6BDECB574BC5B877, 59779808E57DCC3DF70DEC9779D09B7D62137DBBE2B535C51A08BD7A5DF8EA99 ] Avgmfx64 C:\Windows\system32\DRIVERS\avgmfx64.sys

07:06:28.0399 0x02fc Avgmfx64 - ok

07:06:28.0430 0x02fc [ 3CE824D46BA1871713ABF147E6BAD556, B4D8AFC388BE06D6E3C5CDC865F80FF101E731E1D2B221FFC6C1E28487E1B3CD ] Avgrkx64 C:\Windows\system32\DRIVERS\avgrkx64.sys

07:06:28.0430 0x02fc Avgrkx64 - ok

07:06:28.0445 0x02fc [ C76F53C265E79A2DEFF020E78AF4B6BA, 663A7F8FADB4E5669AD70763CE643AB47D001C7613F2E0F1D611A6E8447CD7B0 ] Avgtdia C:\Windows\system32\DRIVERS\avgtdia.sys

07:06:28.0445 0x02fc Avgtdia - ok

07:06:28.0477 0x02fc [ DCF350D917112A03D3CDC33C8ADEA87A, 78E7B8E6575EEB07C993EA71D699443C428B3258A748236264F75571FE23D796 ] avgwd C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe

07:06:28.0492 0x02fc avgwd - ok

07:06:28.0539 0x02fc [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV C:\Windows\System32\AxInstSV.dll

07:06:28.0570 0x02fc AxInstSV - ok

07:06:28.0617 0x02fc [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys

07:06:28.0664 0x02fc b06bdrv - ok

07:06:28.0711 0x02fc [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys

07:06:28.0726 0x02fc b57nd60a - ok

07:06:28.0789 0x02fc [ 7F46A03C1890D47EF594995DD374C637, EBD8202A40191EC43CB56BCFDE0CAB3B57C26A4278989016C3A9BD3A1C400DB6 ] bcbtums C:\Windows\system32\drivers\bcbtums.sys

07:06:28.0789 0x02fc bcbtums - ok

07:06:28.0991 0x02fc [ 461E574D7967E895640109A371A912A5, 910C7063E9370FC1968E8F75E5350915ED1AFF54B265A86A28A77EE27529E8C3 ] BCM43XX C:\Windows\system32\DRIVERS\bcmwl664.sys

07:06:29.0101 0x02fc BCM43XX - ok

07:06:29.0132 0x02fc [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC C:\Windows\System32\bdesvc.dll

07:06:29.0147 0x02fc BDESVC - ok

07:06:29.0194 0x02fc [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep C:\Windows\system32\drivers\Beep.sys

07:06:29.0241 0x02fc Beep - ok

07:06:29.0303 0x02fc [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE C:\Windows\System32\bfe.dll

07:06:29.0355 0x02fc BFE - ok

07:06:29.0386 0x02fc [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS C:\Windows\System32\qmgr.dll

07:06:29.0449 0x02fc BITS - ok

07:06:29.0480 0x02fc [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys

07:06:29.0496 0x02fc blbdrive - ok

07:06:29.0527 0x02fc [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser C:\Windows\system32\DRIVERS\bowser.sys

07:06:29.0558 0x02fc bowser - ok

07:06:29.0589 0x02fc [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys

07:06:29.0620 0x02fc BrFiltLo - ok

07:06:29.0636 0x02fc [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys

07:06:29.0667 0x02fc BrFiltUp - ok

07:06:29.0698 0x02fc [ 8EF0D5C41EC907751B8429162B1239ED, 9CC25F1F93FACA6F6CE23F78EB58590C39A2E3C8A3ACDF400E8A9DE0757EADAE ] Browser C:\Windows\System32\browser.dll

07:06:29.0730 0x02fc Browser - ok

07:06:29.0776 0x02fc [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid C:\Windows\System32\Drivers\Brserid.sys

07:06:29.0792 0x02fc Brserid - ok

07:06:29.0808 0x02fc [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys

07:06:29.0823 0x02fc BrSerWdm - ok

07:06:29.0854 0x02fc [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys

07:06:29.0886 0x02fc BrUsbMdm - ok

07:06:29.0901 0x02fc [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys

07:06:29.0901 0x02fc BrUsbSer - ok

07:06:29.0932 0x02fc [ CF98190A94F62E405C8CB255018B2315, E1B2540023C4FE9FD588E4B6AE6347DFA565EB3898F21E5360882BF3E8B5E781 ] BthEnum C:\Windows\system32\DRIVERS\BthEnum.sys

07:06:29.0964 0x02fc BthEnum - ok

07:06:29.0979 0x02fc [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys

07:06:30.0010 0x02fc BTHMODEM - ok

07:06:30.0026 0x02fc [ 02DD601B708DD0667E1331FA8518E9FF, 7DE6CC4DBB621CD03B01D9CE6CF66EAFE31D39030A391562CD0E278E1D70ADE1 ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys

07:06:30.0057 0x02fc BthPan - ok

07:06:30.0088 0x02fc [ 0D25B6D300BA26A5F2C3B2A8E96B158B, 45C4D18367BDBD85D442221286FE4E9EBC053F1927A32403B2DEBF95AD4E6676 ] BTHPORT C:\Windows\system32\Drivers\BTHport.sys

07:06:30.0120 0x02fc BTHPORT - ok

07:06:30.0135 0x02fc [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv C:\Windows\system32\bthserv.dll

07:06:30.0182 0x02fc bthserv - ok

07:06:30.0213 0x02fc [ 1F9912F8EC5BFA53432E71E150636A8A, D8DE353FA5A6B95EA1CBC79731657044C09BED38B831B8365DCCA8A6DEA67111 ] BTHUSB C:\Windows\system32\Drivers\BTHUSB.sys

07:06:30.0244 0x02fc BTHUSB - ok

07:06:30.0276 0x02fc [ 0D9F24D24FE52D16F97E758F36FA54BB, BCEE3DDCDAA6FB66E411A306016EA53C2243D44A262B5132C95CCBA994C11B6A ] btwampfl C:\Windows\system32\DRIVERS\btwampfl.sys

07:06:30.0307 0x02fc btwampfl - ok

07:06:30.0307 0x02fc [ 1D007889460CEE1BDF1009E054379706, 6B39DF442C418E45333EC04FDC97B78D8BBDE5331482CC31DC963C195FE6D99A ] btwaudio C:\Windows\system32\drivers\btwaudio.sys

07:06:30.0322 0x02fc btwaudio - ok

07:06:30.0338 0x02fc [ 3DF5971BE52709618FD3959033E654F7, 7B7A9DDF55BF1B382AC0763BFAAFCAC54D182D75D1190DD66F5AEDD85DC05CF3 ] btwavdt C:\Windows\system32\drivers\btwavdt.sys

07:06:30.0338 0x02fc btwavdt - ok

07:06:30.0510 0x02fc [ EB3C8EB163E437CEAE2B738ED99F35C5, B6CB50BF6F79F8C8C040E32F3E610AF7CB7139C9BA2229EC7BEE5EB7F4CA0E29 ] btwdins C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe

07:06:30.0541 0x02fc btwdins - ok

07:06:30.0572 0x02fc [ 41933521A618475644B6E8D8487AF326, A50D6CF096E45E4EA2491D61CFE165C8C8A8956E699519C4314918DE1FD31056 ] BTWDPAN C:\Windows\system32\DRIVERS\btwdpan.sys

07:06:30.0588 0x02fc BTWDPAN - ok

07:06:30.0588 0x02fc [ B9354F9F111C64F2495B60F1E24CB453, 67B3F5867B00F84832EF5AD649D817D27B3F200351C7C53579A63D30F8E2BFDD ] btwl2cap C:\Windows\system32\DRIVERS\btwl2cap.sys

07:06:30.0588 0x02fc btwl2cap - ok

07:06:30.0603 0x02fc [ 745D388376D354B806102B78CE1DE611, 0740C3EF90F66187914F23DC68A1BB1C4ADEC35663471765D3DCD372ED653C7E ] btwrchid C:\Windows\system32\DRIVERS\btwrchid.sys

07:06:30.0619 0x02fc btwrchid - ok

07:06:30.0650 0x02fc [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys

07:06:30.0681 0x02fc cdfs - ok

07:06:30.0712 0x02fc [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys

07:06:30.0744 0x02fc cdrom - ok

07:06:30.0759 0x02fc [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc C:\Windows\System32\certprop.dll

07:06:30.0806 0x02fc CertPropSvc - ok

07:06:30.0853 0x02fc [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass C:\Windows\system32\drivers\circlass.sys

07:06:30.0868 0x02fc circlass - ok

07:06:30.0915 0x02fc [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5C1924C87FE70CE ] CLFS C:\Windows\system32\CLFS.sys

07:06:30.0931 0x02fc CLFS - ok

07:06:31.0056 0x02fc [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe

07:06:31.0056 0x02fc clr_optimization_v2.0.50727_32 - ok

07:06:31.0212 0x02fc [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe

07:06:31.0243 0x02fc clr_optimization_v2.0.50727_64 - ok

07:06:31.0274 0x02fc [ 50F92C943F18B070F166D019DFAB3D9A, A997EAFFC1598B1D0A9E1A4475F25418CA8AA6B703B53A71B1AF028E247C9950 ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys

07:06:31.0292 0x02fc clwvd - ok

07:06:31.0310 0x02fc [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt C:\Windows\system32\drivers\CmBatt.sys

07:06:31.0341 0x02fc CmBatt - ok

07:06:31.0357 0x02fc [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide C:\Windows\system32\drivers\cmdide.sys

07:06:31.0357 0x02fc cmdide - ok

07:06:31.0388 0x02fc [ D5FEA92400F12412B3922087C09DA6A5, C8CD9215D26D3295FE487C96A4FC3F4C8AFED764AE9445D9858D7489823A8A2B ] CNG C:\Windows\system32\Drivers\cng.sys

07:06:31.0419 0x02fc CNG - ok

07:06:31.0435 0x02fc [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt C:\Windows\system32\drivers\compbatt.sys

07:06:31.0435 0x02fc Compbatt - ok

07:06:31.0482 0x02fc [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys

07:06:31.0497 0x02fc CompositeBus - ok

07:06:31.0513 0x02fc COMSysApp - ok

07:06:31.0513 0x02fc [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys

07:06:31.0529 0x02fc crcdisk - ok

07:06:31.0560 0x02fc [ 15597883FBE9B056F276ADA3AD87D9AF, B347E0B11228E38313C59C8ED984253A8A1FF482ED137CF5F488C4AFD6B08857 ] CryptSvc C:\Windows\system32\cryptsvc.dll

07:06:31.0607 0x02fc CryptSvc - ok

07:06:31.0669 0x02fc [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch C:\Windows\system32\rpcss.dll

07:06:31.0716 0x02fc DcomLaunch - ok

07:06:31.0747 0x02fc [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc C:\Windows\System32\defragsvc.dll

07:06:31.0794 0x02fc defragsvc - ok

07:06:31.0825 0x02fc [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC C:\Windows\system32\Drivers\dfsc.sys

07:06:31.0872 0x02fc DfsC - ok

07:06:31.0903 0x02fc [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp C:\Windows\system32\dhcpcore.dll

07:06:31.0950 0x02fc Dhcp - ok

07:06:31.0950 0x02fc [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache C:\Windows\system32\drivers\discache.sys

07:06:31.0997 0x02fc discache - ok

07:06:32.0043 0x02fc [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk C:\Windows\system32\drivers\disk.sys

07:06:32.0043 0x02fc Disk - ok

07:06:32.0090 0x02fc [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache C:\Windows\System32\dnsrslvr.dll

07:06:32.0121 0x02fc Dnscache - ok

07:06:32.0137 0x02fc [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc C:\Windows\System32\dot3svc.dll

07:06:32.0184 0x02fc dot3svc - ok

07:06:32.0215 0x02fc [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS C:\Windows\system32\dps.dll

07:06:32.0262 0x02fc DPS - ok

07:06:32.0277 0x02fc [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys

07:06:32.0309 0x02fc drmkaud - ok

07:06:32.0355 0x02fc [ F5BEE30450E18E6B83A5012C100616FD, 44D0577D159FC2BDF4EAD1DC2C7FD14925D075225EF97608CAC52DEE405B08FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys

07:06:32.0371 0x02fc DXGKrnl - ok

07:06:32.0402 0x02fc [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost C:\Windows\System32\eapsvc.dll

07:06:32.0449 0x02fc EapHost - ok

07:06:32.0605 0x02fc [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv C:\Windows\system32\drivers\evbda.sys

07:06:32.0792 0x02fc ebdrv - ok

07:06:32.0823 0x02fc [ 0793F40B9B8A1BDD266296409DBD91EA, 8A383FC9A66A327905C340D06138980F9E489479535A2C2AAE5E8BB14A74826E ] EFS C:\Windows\System32\lsass.exe

07:06:32.0839 0x02fc EFS - ok

07:06:32.0964 0x02fc [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr C:\Windows\ehome\ehRecvr.exe

07:06:33.0011 0x02fc ehRecvr - ok

07:06:33.0042 0x02fc [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched C:\Windows\ehome\ehsched.exe

07:06:33.0057 0x02fc ehSched - ok

07:06:33.0104 0x02fc [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor C:\Windows\system32\drivers\elxstor.sys

07:06:33.0120 0x02fc elxstor - ok

07:06:33.0135 0x02fc [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev C:\Windows\system32\drivers\errdev.sys

07:06:33.0151 0x02fc ErrDev - ok

07:06:33.0198 0x02fc [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem C:\Windows\system32\es.dll

07:06:33.0260 0x02fc EventSystem - ok

07:06:33.0296 0x02fc [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat C:\Windows\system32\drivers\exfat.sys

07:06:33.0328 0x02fc exfat - ok

07:06:33.0359 0x02fc [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat C:\Windows\system32\drivers\fastfat.sys

07:06:33.0406 0x02fc fastfat - ok

07:06:33.0452 0x02fc [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax C:\Windows\system32\fxssvc.exe

07:06:33.0499 0x02fc Fax - ok

07:06:33.0515 0x02fc [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc C:\Windows\system32\drivers\fdc.sys

07:06:33.0546 0x02fc fdc - ok

07:06:33.0562 0x02fc [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost C:\Windows\system32\fdPHost.dll

07:06:33.0593 0x02fc fdPHost - ok

07:06:33.0593 0x02fc [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub C:\Windows\system32\fdrespub.dll

07:06:33.0624 0x02fc FDResPub - ok

07:06:33.0640 0x02fc [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo C:\Windows\system32\drivers\fileinfo.sys

07:06:33.0655 0x02fc FileInfo - ok

07:06:33.0655 0x02fc [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace C:\Windows\system32\drivers\filetrace.sys

07:06:33.0702 0x02fc Filetrace - ok

07:06:33.0702 0x02fc [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys

07:06:33.0718 0x02fc flpydisk - ok

07:06:33.0718 0x02fc [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys

07:06:33.0733 0x02fc FltMgr - ok

07:06:33.0780 0x02fc [ 5C4CB4086FB83115B153E47ADD961A0C, 0C3AB7D04BEB3A8FDE00B0C86E6FE064B1CEBB3E4DE1A29CD27830806FA300B3 ] FontCache C:\Windows\system32\FntCache.dll

07:06:33.0842 0x02fc FontCache - ok

07:06:33.0874 0x02fc [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe

07:06:33.0889 0x02fc FontCache3.0.0.0 - ok

07:06:33.0952 0x02fc [ 26065327BB2AA358140381FC76520908, FFD3DB199C656B8AE09F4C487C120641567D9A112C6D3C6CFF2711CF45EAFD33 ] FPLService C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe

07:06:33.0983 0x02fc FPLService - ok

07:06:33.0998 0x02fc [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys

07:06:34.0014 0x02fc FsDepends - ok

07:06:34.0045 0x02fc [ E95EF8547DE20CF0603557C0CF7A9462, 55540B06B7B380CA2DA6EEE2D76C6CD6131ADB02B2D0B172A36536863A0C57B6 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys

07:06:34.0061 0x02fc Fs_Rec - ok

07:06:34.0092 0x02fc [ 1F7B25B858FA27015169FE95E54108ED, 72DD12E924AA7273B3E4BDD2A2C581DECE304C8EF3D44EA79ABB032F3F95DCE5 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys

07:06:34.0108 0x02fc fvevol - ok

07:06:34.0139 0x02fc [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys

07:06:34.0139 0x02fc gagp30kx - ok

07:06:34.0232 0x02fc [ C403C5DB49A0F9AAF4F2128EDC0106D8, 3C6948B63278022D8182F773C5FA15784514F76C1546118DDBADBA322B962D12 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe

07:06:34.0248 0x02fc GamesAppService - ok

07:06:34.0310 0x02fc [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc C:\Windows\System32\gpsvc.dll

07:06:34.0357 0x02fc gpsvc - ok

07:06:34.0388 0x02fc [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys

07:06:34.0404 0x02fc hcw85cir - ok

07:06:34.0451 0x02fc [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys

07:06:34.0498 0x02fc HdAudAddService - ok

07:06:34.0513 0x02fc [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys

07:06:34.0544 0x02fc HDAudBus - ok

07:06:34.0560 0x02fc [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys

07:06:34.0591 0x02fc HidBatt - ok

07:06:34.0607 0x02fc [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth C:\Windows\system32\drivers\hidbth.sys

07:06:34.0638 0x02fc HidBth - ok

07:06:34.0638 0x02fc [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr C:\Windows\system32\drivers\hidir.sys

07:06:34.0669 0x02fc HidIr - ok

07:06:34.0700 0x02fc [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv C:\Windows\system32\hidserv.dll

07:06:34.0732 0x02fc hidserv - ok

07:06:34.0778 0x02fc [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys

07:06:34.0794 0x02fc HidUsb - ok

07:06:34.0810 0x02fc [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc C:\Windows\system32\kmsvc.dll

07:06:34.0856 0x02fc hkmsvc - ok

07:06:34.0888 0x02fc [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll

07:06:34.0903 0x02fc HomeGroupListener - ok

07:06:34.0934 0x02fc [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll

07:06:34.0966 0x02fc HomeGroupProvider - ok

07:06:35.0044 0x02fc [ 170233B8D743EFE35F462A5D516B93E3, 469CD3A5DE0CB6E7068F3670DA95FCF46544546AB72B1A508B3A3CA3B8598802 ] HP Support Assistant Service C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe

07:06:35.0059 0x02fc HP Support Assistant Service - ok

07:06:35.0168 0x02fc [ 7B8C1B09C11E8DB7C4480ABD7D17E821, 0E35FD439B24CEAD623A5D7319B865A6BCE6F1F3057671F62B4F844D8EC3D206 ] HPAuto C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe

07:06:35.0184 0x02fc HPAuto - ok

07:06:35.0200 0x02fc [ 6A181452D4E240B8ECC7614B9A19BDE9, 3E458A737DA597DF007D278E9D81F2BF259AB4B97A4C188CEDAEA1F144B1074F ] HPClientSvc C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe

07:06:35.0215 0x02fc HPClientSvc - ok

07:06:35.0314 0x02fc [ C958976C7DAAF47084A33EBBC6E28B84, AAC98901E25911EA6FF65E95007CE2F75B31145ACFADF92CBA48BCAE54CD96EE ] HPDrvMntSvc.exe C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe

07:06:35.0329 0x02fc HPDrvMntSvc.exe - ok

07:06:35.0376 0x02fc [ 09FBD4C4DB2FD84B9AB1C5BFDCC95559, FCC28D44C1E3F6FF65C596CDA9BF09C03D4EF3EEFCDB628954A07B0D3E182F3B ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe

07:06:35.0407 0x02fc hpqwmiex - ok

07:06:35.0439 0x02fc [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys

07:06:35.0454 0x02fc HpSAMD - ok

07:06:35.0532 0x02fc [ 28E15C3D39DCD27A79251BA0BF216A11, DF6CEA842B84148CCB90CA5DB02265BE71BA95CCDE0E186DD72191E0EFA14C11 ] HPWMISVC C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe

07:06:35.0548 0x02fc HPWMISVC - ok

07:06:35.0610 0x02fc [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F730954F0784DDE9779 ] HTTP C:\Windows\system32\drivers\HTTP.sys

07:06:35.0688 0x02fc HTTP - ok

07:06:35.0719 0x02fc [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys

07:06:35.0735 0x02fc hwpolicy - ok

07:06:35.0751 0x02fc [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys

07:06:35.0751 0x02fc i8042prt - ok

07:06:35.0782 0x02fc [ 26CF4275034214ECEDD8EC17B0A18A99, 95A08C63971C28F1BC97040C0ADA247E3B43DE7D937B14E33A394B955D0AC8B7 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys

07:06:35.0797 0x02fc iaStor - ok

07:06:35.0875 0x02fc [ E79A8E33BD136D14BAE1FA20EB2EF124, 54AD784570282FEF21021BE76C57EE878EC6FF6423CE2FFC3A4372AF6C3112D4 ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe

07:06:35.0875 0x02fc IAStorDataMgrSvc - ok

07:06:35.0938 0x02fc [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys

07:06:35.0953 0x02fc iaStorV - ok

07:06:36.0109 0x02fc [ D22D82D74FD1B6C77E7556DBDC3EA9D2, D18B461034A2ECF76E87D13EADA8F9292E44D441B99519D382B29CF99875E5AD ] IconMan_R C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe

07:06:36.0172 0x02fc IconMan_R - detected UnsignedFile.Multi.Generic ( 1 )

07:06:39.0333 0x02fc Detect skipped due to KSN trusted

07:06:39.0333 0x02fc IconMan_R - ok

07:06:39.0458 0x02fc [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209AFC22A34D2BE99 ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe

07:06:39.0489 0x02fc idsvc - ok

07:06:39.0520 0x02fc [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp C:\Windows\system32\drivers\iirsp.sys

07:06:39.0536 0x02fc iirsp - ok

07:06:39.0567 0x02fc [ FCD84C381E0140AF901E58D48882D26B, 76955FFC230C801E8ED890E32076075F04CD6E5EC79E594FDE6D23797A36B406 ] IKEEXT C:\Windows\System32\ikeext.dll

07:06:39.0629 0x02fc IKEEXT - ok

07:06:39.0692 0x02fc [ FC727061C0F47C8059E88E05D5C8E381, C7A3782F5D86C7FDE57AA1F2EE81638C5FC3072ACC6E572BA2EC7B3CFF389800 ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys

07:06:39.0739 0x02fc IntcDAud - ok

07:06:39.0754 0x02fc [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide C:\Windows\system32\drivers\intelide.sys

07:06:39.0770 0x02fc intelide - ok

07:06:40.0160 0x02fc [ 6383899C5F964D71B0F96B81FBE59BB8, 780B2B5945CF266CD0807B6F91177A558EC1E568F9D7D850C172A137414394E6 ] intelkmd C:\Windows\system32\DRIVERS\igdpmd64.sys

07:06:40.0659 0x02fc intelkmd - ok

07:06:40.0737 0x02fc [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys

07:06:40.0753 0x02fc intelppm - ok

07:06:40.0784 0x02fc [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum C:\Windows\system32\ipbusenum.dll

07:06:40.0815 0x02fc IPBusEnum - ok

07:06:40.0831 0x02fc [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys

07:06:40.0862 0x02fc IpFilterDriver - ok

07:06:40.0909 0x02fc [ A34A587FFFD45FA649FBA6D03784D257, C9A2BCD4E2A5EB6E320092A3AFD5737ECDCDA0B83EE42314A23C4978F2974767 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll

07:06:40.0955 0x02fc iphlpsvc - ok

07:06:40.0987 0x02fc [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys

07:06:41.0002 0x02fc IPMIDRV - ok

07:06:41.0018 0x02fc [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT C:\Windows\system32\drivers\ipnat.sys

07:06:41.0049 0x02fc IPNAT - ok

07:06:41.0080 0x02fc [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM C:\Windows\system32\drivers\irenum.sys

07:06:41.0096 0x02fc IRENUM - ok

07:06:41.0096 0x02fc [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp C:\Windows\system32\drivers\isapnp.sys

07:06:41.0096 0x02fc isapnp - ok

07:06:41.0127 0x02fc [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D099508E38D409913ED3 ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys

07:06:41.0143 0x02fc iScsiPrt - ok

07:06:41.0210 0x02fc [ 6C85719A21B3F62C2C76280F4BD36C7B, 471E333467937720EF9369419EEDE5C2246C976123B437E0AC66F394CF1C056A ] jhi_service C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe

07:06:41.0210 0x02fc jhi_service - ok

07:06:41.0241 0x02fc [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass C:\Windows\system32\drivers\kbdclass.sys

07:06:41.0257 0x02fc kbdclass - ok

07:06:41.0272 0x02fc [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys

07:06:41.0304 0x02fc kbdhid - ok

07:06:41.0335 0x02fc [ 0793F40B9B8A1BDD266296409DBD91EA, 8A383FC9A66A327905C340D06138980F9E489479535A2C2AAE5E8BB14A74826E ] KeyIso C:\Windows\system32\lsass.exe

07:06:41.0350 0x02fc KeyIso - ok

07:06:41.0366 0x02fc [ CCD53B5BD33CE0C889E830D839C8B66E, 51B7556DA7DAA0BC75E00E53099776016A55FAA115D5A4E6830E12A0A0869C10 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys

07:06:41.0382 0x02fc KSecDD - ok

07:06:41.0382 0x02fc [ 9FF918A261752C12639E8AD4208D2C2F, B60F7A730C92F2BF7E85A6CA14DD7671AEECEE154CEC83B1E23EF268C25C9E5E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys

07:06:41.0397 0x02fc KSecPkg - ok

07:06:41.0397 0x02fc [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys

07:06:41.0444 0x02fc ksthunk - ok

07:06:41.0475 0x02fc [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm C:\Windows\system32\msdtckrm.dll

07:06:41.0522 0x02fc KtmRm - ok

07:06:41.0694 0x02fc [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer C:\Windows\system32\srvsvc.dll

07:06:41.0756 0x02fc LanmanServer - ok

07:06:41.0787 0x02fc [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll

07:06:41.0818 0x02fc LanmanWorkstation - ok

07:06:41.0865 0x02fc [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys

07:06:41.0896 0x02fc lltdio - ok

07:06:41.0928 0x02fc [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc C:\Windows\System32\lltdsvc.dll

07:06:41.0959 0x02fc lltdsvc - ok

07:06:41.0990 0x02fc [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts C:\Windows\System32\lmhsvc.dll

07:06:42.0006 0x02fc lmhosts - ok

07:06:42.0084 0x02fc [ D75C4B4A8FE6D7FD74A7EECDBAEC729F, 9BB0A3BE7CCDF62CF0A67CB67019364965F6567BE29BA6D153B8E36F88058302 ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe

07:06:42.0099 0x02fc LMS - ok

07:06:42.0146 0x02fc [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys

07:06:42.0162 0x02fc LSI_FC - ok

07:06:42.0162 0x02fc [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys

07:06:42.0162 0x02fc LSI_SAS - ok

07:06:42.0177 0x02fc [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys

07:06:42.0177 0x02fc LSI_SAS2 - ok

07:06:42.0193 0x02fc [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys

07:06:42.0193 0x02fc LSI_SCSI - ok

07:06:42.0208 0x02fc [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv C:\Windows\system32\drivers\luafv.sys

07:06:42.0240 0x02fc luafv - ok

07:06:42.0271 0x02fc [ CF12E148C6FC151335B7D7FE03F1C7A2, 7087DF6D884AF0A57AC22D7AE9C2903913AAB4CE52D19666B6513C3D5706E43C ] MBAMProtector C:\Windows\system32\drivers\mbam.sys

07:06:42.0271 0x02fc MBAMProtector - ok

07:06:42.0349 0x02fc [ E27891A49DF92004041FEC5C3A2D4230, A4679A1F10F84935875E35A83FC7075499B8F4CBB543209A38C0D946347CD264 ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

07:06:42.0380 0x02fc MBAMService - ok

07:06:42.0427 0x02fc [ 0CE2F3E26C770CBAEB50787A2C1FD09E, 2DDB1827027D2CC8E78FE737B5DA21783EFCD13430DBB140C34DAACACD6EF492 ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys

07:06:42.0427 0x02fc MBAMWebAccessControl - ok

07:06:42.0458 0x02fc [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll

07:06:42.0474 0x02fc Mcx2Svc - ok

07:06:42.0489 0x02fc [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas C:\Windows\system32\drivers\megasas.sys

07:06:42.0489 0x02fc megasas - ok

07:06:42.0505 0x02fc [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys

07:06:42.0520 0x02fc MegaSR - ok

07:06:42.0552 0x02fc [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17324474FC96B9BC ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys

07:06:42.0552 0x02fc MEIx64 - ok

07:06:42.0583 0x02fc [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS C:\Windows\system32\mmcss.dll

07:06:42.0630 0x02fc MMCSS - ok

07:06:42.0661 0x02fc [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem C:\Windows\system32\drivers\modem.sys

07:06:42.0708 0x02fc Modem - ok

07:06:42.0708 0x02fc [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor C:\Windows\system32\DRIVERS\monitor.sys

07:06:42.0723 0x02fc monitor - ok

07:06:42.0739 0x02fc [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys

07:06:42.0739 0x02fc mouclass - ok

07:06:42.0754 0x02fc [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys

07:06:42.0770 0x02fc mouhid - ok

07:06:42.0801 0x02fc [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7BFBC12BB9A69E63 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys

07:06:42.0801 0x02fc mountmgr - ok

07:06:42.0817 0x02fc [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio C:\Windows\system32\drivers\mpio.sys

07:06:42.0832 0x02fc mpio - ok

07:06:42.0832 0x02fc [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys

07:06:42.0864 0x02fc mpsdrv - ok

07:06:42.0910 0x02fc [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc C:\Windows\system32\mpssvc.dll

07:06:42.0957 0x02fc MpsSvc - ok

07:06:42.0988 0x02fc [ DC722758B8261E1ABAFD31A3C0A66380, 88BBE073E2CCD1DAB4656DDC53D5161E8A91D035ADAC1465D0CEBA86F1BB6D9A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys

07:06:43.0020 0x02fc MRxDAV - ok

07:06:43.0035 0x02fc [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE35020785387F307E231FBE4 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys

07:06:43.0066 0x02fc mrxsmb - ok

07:06:43.0098 0x02fc [ 2086D463BD371D8A37D153897430916D, A90ABA27FCE94EEF5CF6381D7DB61762752398E4BCC241645965F6BB9CFEFEE5 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys

07:06:43.0113 0x02fc mrxsmb10 - ok

07:06:43.0113 0x02fc [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B7720888F67B9644CC ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys

07:06:43.0129 0x02fc mrxsmb20 - ok

07:06:43.0144 0x02fc [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci C:\Windows\system32\drivers\msahci.sys

07:06:43.0162 0x02fc msahci - ok

07:06:43.0165 0x02fc [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm C:\Windows\system32\drivers\msdsm.sys

07:06:43.0181 0x02fc msdsm - ok

07:06:43.0181 0x02fc [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC C:\Windows\System32\msdtc.exe

07:06:43.0212 0x02fc MSDTC - ok

07:06:43.0227 0x02fc [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs C:\Windows\system32\drivers\Msfs.sys

07:06:43.0259 0x02fc Msfs - ok

07:06:43.0290 0x02fc [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys

07:06:43.0305 0x02fc mshidkmdf - ok

07:06:43.0321 0x02fc [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys

07:06:43.0321 0x02fc msisadrv - ok

07:06:43.0352 0x02fc [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI C:\Windows\system32\iscsiexe.dll

07:06:43.0383 0x02fc MSiSCSI - ok

07:06:43.0383 0x02fc msiserver - ok

07:06:43.0399 0x02fc [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys

07:06:43.0430 0x02fc MSKSSRV - ok

07:06:43.0446 0x02fc [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys

07:06:43.0493 0x02fc MSPCLOCK - ok

07:06:43.0493 0x02fc [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM C:\Windows\system32\drivers\MSPQM.sys

07:06:43.0524 0x02fc MSPQM - ok

07:06:43.0555 0x02fc [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys

07:06:43.0571 0x02fc MsRPC - ok

07:06:43.0571 0x02fc [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys

07:06:43.0586 0x02fc mssmbios - ok

07:06:43.0602 0x02fc [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE C:\Windows\system32\drivers\MSTEE.sys

07:06:43.0649 0x02fc MSTEE - ok

07:06:43.0649 0x02fc [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys

07:06:43.0649 0x02fc MTConfig - ok

07:06:43.0664 0x02fc [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup C:\Windows\system32\Drivers\mup.sys

07:06:43.0664 0x02fc Mup - ok

07:06:43.0711 0x02fc [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent C:\Windows\system32\qagentRT.dll

07:06:43.0758 0x02fc napagent - ok

07:06:43.0805 0x02fc [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys

07:06:43.0836 0x02fc NativeWifiP - ok

07:06:43.0929 0x02fc [ C38B8AE57F78915905064A9A24DC1586, 5A24A490AC5DB4FCC745182BDBAEA8836E8FBEC635609AE4CF51DAC3A30A8221 ] NDIS C:\Windows\system32\drivers\ndis.sys

07:06:43.0961 0x02fc NDIS - ok

07:06:43.0992 0x02fc [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys

07:06:44.0039 0x02fc NdisCap - ok

07:06:44.0070 0x02fc [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys

07:06:44.0085 0x02fc NdisTapi - ok

07:06:44.0101 0x02fc [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys

07:06:44.0117 0x02fc Ndisuio - ok

07:06:44.0132 0x02fc [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys

07:06:44.0179 0x02fc NdisWan - ok

07:06:44.0179 0x02fc [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys

07:06:44.0210 0x02fc NDProxy - ok

07:06:44.0210 0x02fc [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys

07:06:44.0241 0x02fc NetBIOS - ok

07:06:44.0288 0x02fc [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys

07:06:44.0319 0x02fc NetBT - ok

07:06:44.0351 0x02fc [ 0793F40B9B8A1BDD266296409DBD91EA, 8A383FC9A66A327905C340D06138980F9E489479535A2C2AAE5E8BB14A74826E ] Netlogon C:\Windows\system32\lsass.exe

07:06:44.0351 0x02fc Netlogon - ok

07:06:44.0382 0x02fc [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman C:\Windows\System32\netman.dll

07:06:44.0429 0x02fc Netman - ok

07:06:44.0460 0x02fc [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm C:\Windows\System32\netprofm.dll

07:06:44.0507 0x02fc netprofm - ok

07:06:44.0538 0x02fc [ 3E5A36127E201DDF663176B66828FAFE, 5A08BA9EFB1A72DF1DD839BA5FA2B8994012BA62A515588FF62333B33B60045B ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe

07:06:44.0538 0x02fc NetTcpPortSharing - ok

07:06:44.0569 0x02fc [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys

07:06:44.0569 0x02fc nfrd960 - ok

07:06:44.0600 0x02fc [ 1EE99A89CC788ADA662441D1E9830529, 6B4FDD74BB81E12BD4B25A3E8AECB0FA77FA0075D454DD1D6DC1790ADF1F2AA8 ] NlaSvc C:\Windows\System32\nlasvc.dll

07:06:44.0647 0x02fc NlaSvc - ok

07:06:44.0663 0x02fc [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs C:\Windows\system32\drivers\Npfs.sys

07:06:44.0694 0x02fc Npfs - ok

07:06:44.0709 0x02fc [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi C:\Windows\system32\nsisvc.dll

07:06:44.0741 0x02fc nsi - ok

07:06:44.0772 0x02fc [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys

07:06:44.0819 0x02fc nsiproxy - ok

07:06:44.0881 0x02fc [ A2F74975097F52A00745F9637451FDD8, C681DDBD3382C477C2A030E828B5CFB529CB57C7847BD9AFF25E2A5E58B2DAF3 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys

07:06:44.0928 0x02fc Ntfs - ok

07:06:44.0943 0x02fc [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null C:\Windows\system32\drivers\Null.sys

07:06:44.0975 0x02fc Null - ok

07:06:44.0990 0x02fc [ A85B4F2EF3A7304A5399EF0526423040, E45854691BA6AE36E53C2922CC93FF13DC2D84CBE7FE13A2F0B1CE1C16D1D158 ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x64.sys

07:06:45.0037 0x02fc NVENETFD - ok

07:06:45.0053 0x02fc [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid C:\Windows\system32\drivers\nvraid.sys

07:06:45.0068 0x02fc nvraid - ok

07:06:45.0084 0x02fc [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor C:\Windows\system32\drivers\nvstor.sys

07:06:45.0084 0x02fc nvstor - ok

07:06:45.0115 0x02fc [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys

07:06:45.0115 0x02fc nv_agp - ok

07:06:45.0131 0x02fc [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys

07:06:45.0151 0x02fc ohci1394 - ok

07:06:45.0182 0x02fc [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll

07:06:45.0214 0x02fc p2pimsvc - ok

07:06:45.0245 0x02fc [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc C:\Windows\system32\p2psvc.dll

07:06:45.0260 0x02fc p2psvc - ok

07:06:45.0292 0x02fc [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport C:\Windows\system32\drivers\parport.sys

07:06:45.0307 0x02fc Parport - ok

07:06:45.0307 0x02fc [ 871EADAC56B0A4C6512BBE32753CCF79, F9FD9DBA55274BB72B897550988DCDFD0F2D9367BE641DFDE07D240052DDC180 ] partmgr C:\Windows\system32\drivers\partmgr.sys

07:06:45.0307 0x02fc partmgr - ok

07:06:45.0338 0x02fc [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F93925EF2C9FC32D ] PcaSvc C:\Windows\System32\pcasvc.dll

07:06:45.0385 0x02fc PcaSvc - ok

07:06:45.0401 0x02fc [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci C:\Windows\system32\drivers\pci.sys

07:06:45.0416 0x02fc pci - ok

07:06:45.0416 0x02fc [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide C:\Windows\system32\drivers\pciide.sys

07:06:45.0432 0x02fc pciide - ok

07:06:45.0432 0x02fc [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys

07:06:45.0448 0x02fc pcmcia - ok

07:06:45.0448 0x02fc [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw C:\Windows\system32\drivers\pcw.sys

07:06:45.0463 0x02fc pcw - ok

07:06:45.0479 0x02fc [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A76CCD39E00029C ] PEAUTH C:\Windows\system32\drivers\peauth.sys

07:06:45.0541 0x02fc PEAUTH - ok

07:06:45.0744 0x02fc [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost C:\Windows\SysWow64\perfhost.exe

07:06:45.0791 0x02fc PerfHost - ok

07:06:45.0884 0x02fc [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla C:\Windows\system32\pla.dll

07:06:45.0962 0x02fc pla - ok

07:06:46.0009 0x02fc [ B806E50427511BCF4AD8E8239C3E25FA, AB89B48ECCF90F701B314D18BE531CDA5ABE1636C17B994A5E4BE5AAC136B4E3 ] PlugPlay C:\Windows\system32\umpnpmgr.dll

07:06:46.0040 0x02fc PlugPlay - ok

07:06:46.0072 0x02fc [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll

07:06:46.0087 0x02fc PNRPAutoReg - ok

07:06:46.0103 0x02fc [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll

07:06:46.0118 0x02fc PNRPsvc - ok

07:06:46.0150 0x02fc [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll

07:06:46.0196 0x02fc PolicyAgent - ok

07:06:46.0228 0x02fc [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power C:\Windows\system32\umpo.dll

07:06:46.0274 0x02fc Power - ok

07:06:46.0306 0x02fc [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys

07:06:46.0337 0x02fc PptpMiniport - ok

07:06:46.0368 0x02fc [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor C:\Windows\system32\drivers\processr.sys

07:06:46.0384 0x02fc Processor - ok

07:06:46.0415 0x02fc [ 5C78838B4D166D1A27DB3A8A820C799A, BBF7E1D0B6754CF06BF3936671FDF5BF6E845CA5678D0940EA54E9212B539B7F ] ProfSvc C:\Windows\system32\profsvc.dll

07:06:46.0446 0x02fc ProfSvc - ok

07:06:46.0462 0x02fc [ 0793F40B9B8A1BDD266296409DBD91EA, 8A383FC9A66A327905C340D06138980F9E489479535A2C2AAE5E8BB14A74826E ] ProtectedStorage C:\Windows\system32\lsass.exe

07:06:46.0462 0x02fc ProtectedStorage - ok

07:06:46.0493 0x02fc [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched C:\Windows\system32\DRIVERS\pacer.sys

07:06:46.0540 0x02fc Psched - ok

07:06:46.0618 0x02fc [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300 C:\Windows\system32\drivers\ql2300.sys

07:06:46.0649 0x02fc ql2300 - ok

07:06:46.0680 0x02fc [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx C:\Windows\system32\drivers\ql40xx.sys

07:06:46.0680 0x02fc ql40xx - ok

07:06:46.0711 0x02fc [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE C:\Windows\system32\qwave.dll

07:06:46.0742 0x02fc QWAVE - ok

07:06:46.0742 0x02fc [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys

07:06:46.0774 0x02fc QWAVEdrv - ok

07:06:46.0805 0x02fc [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys

07:06:46.0836 0x02fc RasAcd - ok

07:06:46.0867 0x02fc [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys

07:06:46.0914 0x02fc RasAgileVpn - ok

07:06:46.0930 0x02fc [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto C:\Windows\System32\rasauto.dll

07:06:46.0976 0x02fc RasAuto - ok

07:06:47.0008 0x02fc [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys

07:06:47.0039 0x02fc Rasl2tp - ok

07:06:47.0070 0x02fc [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan C:\Windows\System32\rasmans.dll

07:06:47.0122 0x02fc RasMan - ok

07:06:47.0137 0x02fc [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys

07:06:47.0184 0x02fc RasPppoe - ok

07:06:47.0215 0x02fc [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys

07:06:47.0247 0x02fc RasSstp - ok

07:06:47.0278 0x02fc [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys

07:06:47.0325 0x02fc rdbss - ok

07:06:47.0340 0x02fc [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus C:\Windows\system32\drivers\rdpbus.sys

07:06:47.0356 0x02fc rdpbus - ok

07:06:47.0371 0x02fc [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys

07:06:47.0403 0x02fc RDPCDD - ok

07:06:47.0434 0x02fc [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys

07:06:47.0481 0x02fc RDPENCDD - ok

07:06:47.0481 0x02fc [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys

07:06:47.0512 0x02fc RDPREFMP - ok

07:06:47.0543 0x02fc [ 6D76E6433574B058ADCB0C50DF834492, A063D9F3771CBA3C2CA85B3D267C267C310698DEB2818E9C524B55CD74F921DB ] RDPWD C:\Windows\system32\drivers\RDPWD.sys

07:06:47.0574 0x02fc RDPWD - ok

07:06:47.0605 0x02fc [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys

07:06:47.0621 0x02fc rdyboost - ok

07:06:47.0637 0x02fc [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess C:\Windows\System32\mprdim.dll

07:06:47.0683 0x02fc RemoteAccess - ok

07:06:47.0715 0x02fc [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry C:\Windows\system32\regsvc.dll

07:06:47.0761 0x02fc RemoteRegistry - ok

07:06:47.0793 0x02fc [ 3DD798846E2C28102B922C56E71B7932, 30B111615D74CB2213997A5C08DD9C8613ADE441D9423CC1C49A753D13CE524D ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys

07:06:47.0824 0x02fc RFCOMM - ok

07:06:47.0855 0x02fc [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll

07:06:47.0902 0x02fc RpcEptMapper - ok

07:06:47.0917 0x02fc [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator C:\Windows\system32\locator.exe

07:06:47.0933 0x02fc RpcLocator - ok

07:06:47.0964 0x02fc [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs C:\Windows\system32\rpcss.dll

07:06:47.0995 0x02fc RpcSs - ok

07:06:48.0042 0x02fc [ 546D7F426776090B90EF5F195B6AE662, E67598E1CA5F98184DD7380E7AFD65C18C99EDC3326909EBFF2A61F95C3A027D ] RSPCIESTOR C:\Windows\system32\DRIVERS\RtsPStor.sys

07:06:48.0058 0x02fc RSPCIESTOR - ok

07:06:48.0073 0x02fc [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys

07:06:48.0089 0x02fc rspndr - ok

07:06:48.0151 0x02fc [ EA5532868BA76923D75BCB2A1448D810, C1489714C9BC95BB76134E6B8F28C5A3D044E9B2857F01BFEEEE7C8A25C74E7D ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys

07:06:48.0167 0x02fc RTL8167 - ok

07:06:48.0183 0x02fc [ 0793F40B9B8A1BDD266296409DBD91EA, 8A383FC9A66A327905C340D06138980F9E489479535A2C2AAE5E8BB14A74826E ] SamSs C:\Windows\system32\lsass.exe

07:06:48.0183 0x02fc SamSs - ok

07:06:48.0198 0x02fc [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys

07:06:48.0214 0x02fc sbp2port - ok

07:06:48.0245 0x02fc [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr C:\Windows\System32\SCardSvr.dll

07:06:48.0276 0x02fc SCardSvr - ok

07:06:48.0292 0x02fc [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys

07:06:48.0339 0x02fc scfilter - ok

07:06:48.0385 0x02fc [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063AA7F342A60C4A7 ] Schedule C:\Windows\system32\schedsvc.dll

07:06:48.0463 0x02fc Schedule - ok

07:06:48.0495 0x02fc [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc C:\Windows\System32\certprop.dll

07:06:48.0510 0x02fc SCPolicySvc - ok

07:06:48.0541 0x02fc [ 111E0EBC0AD79CB0FA014B907B231CF0, B7D43D156C2524938503CF8E99C4D1F7A5C55E16C0368F57F4CD23C6D833B38F ] sdbus C:\Windows\system32\DRIVERS\sdbus.sys

07:06:48.0557 0x02fc sdbus - ok

07:06:48.0588 0x02fc [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC C:\Windows\System32\SDRSVC.dll

07:06:48.0619 0x02fc SDRSVC - ok

07:06:48.0651 0x02fc [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys

07:06:48.0682 0x02fc secdrv - ok

07:06:48.0713 0x02fc [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon C:\Windows\system32\seclogon.dll

07:06:48.0729 0x02fc seclogon - ok

07:06:48.0744 0x02fc [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS C:\Windows\System32\sens.dll

07:06:48.0791 0x02fc SENS - ok

07:06:48.0822 0x02fc [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc C:\Windows\system32\sensrsvc.dll

07:06:48.0853 0x02fc SensrSvc - ok

07:06:48.0869 0x02fc [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum C:\Windows\system32\drivers\serenum.sys

07:06:48.0885 0x02fc Serenum - ok

07:06:48.0916 0x02fc [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial C:\Windows\system32\drivers\serial.sys

07:06:48.0947 0x02fc Serial - ok

07:06:48.0947 0x02fc [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse C:\Windows\system32\drivers\sermouse.sys

07:06:48.0963 0x02fc sermouse - ok

07:06:48.0994 0x02fc [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv C:\Windows\system32\sessenv.dll

07:06:49.0056 0x02fc SessionEnv - ok

07:06:49.0072 0x02fc [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys

07:06:49.0090 0x02fc sffdisk - ok

07:06:49.0092 0x02fc [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys

07:06:49.0108 0x02fc sffp_mmc - ok

07:06:49.0108 0x02fc [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys

07:06:49.0124 0x02fc sffp_sd - ok

07:06:49.0155 0x02fc [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys

07:06:49.0170 0x02fc sfloppy - ok

07:06:49.0217 0x02fc [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess C:\Windows\System32\ipnathlp.dll

07:06:49.0248 0x02fc SharedAccess - ok

07:06:49.0280 0x02fc [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll

07:06:49.0326 0x02fc ShellHWDetection - ok

07:06:49.0358 0x02fc [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys

07:06:49.0373 0x02fc SiSRaid2 - ok

07:06:49.0373 0x02fc [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys

07:06:49.0389 0x02fc SiSRaid4 - ok

07:06:49.0404 0x02fc [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb C:\Windows\system32\DRIVERS\smb.sys

07:06:49.0451 0x02fc Smb - ok

07:06:49.0482 0x02fc [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP C:\Windows\System32\snmptrap.exe

07:06:49.0514 0x02fc SNMPTRAP - ok

07:06:49.0529 0x02fc [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr C:\Windows\system32\drivers\spldr.sys

07:06:49.0545 0x02fc spldr - ok

07:06:49.0576 0x02fc [ B96C17B5DC1424D56EEA3A99E97428CD, AF0A85066A7983878DC1C663811CE61C6CA1912DC956184F878B7B82DB93C651 ] Spooler C:\Windows\System32\spoolsv.exe

07:06:49.0623 0x02fc Spooler - ok

07:06:49.0732 0x02fc [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc C:\Windows\system32\sppsvc.exe

07:06:49.0935 0x02fc sppsvc - ok

07:06:49.0966 0x02fc [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify C:\Windows\system32\sppuinotify.dll

07:06:49.0982 0x02fc sppuinotify - ok

07:06:50.0028 0x02fc [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv C:\Windows\system32\DRIVERS\srv.sys

07:06:50.0044 0x02fc srv - ok

07:06:50.0060 0x02fc [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys

07:06:50.0091 0x02fc srv2 - ok

07:06:50.0122 0x02fc [ 0C4540311E11664B245A263E1154CEF8, 63376322BFFAFF2F166AF3FDD3F1A346C21FAE21F406F659F8630779D1D6525D ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL6.SYS

07:06:50.0138 0x02fc SrvHsfHDA - ok

07:06:50.0184 0x02fc [ 02071D207A9858FBE3A48CBFD59C4A04, FEA4DEBAEC3465E0C7C1E8B721805922F6BBCB96A60A193B11688F4252F4B89E ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV6.SYS

07:06:50.0247 0x02fc SrvHsfV92 - ok

07:06:50.0294 0x02fc [ 18E40C245DBFAF36FD0134A7EF2DF396, 0138A68958112101A5D3BD94114F320CE80B0C9A93E009AC78DE7415FCCC7DE7 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT6.SYS

07:06:50.0325 0x02fc SrvHsfWinac - ok

07:06:50.0356 0x02fc [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys

07:06:50.0387 0x02fc srvnet - ok

07:06:50.0418 0x02fc [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll

07:06:50.0465 0x02fc SSDPSRV - ok

07:06:50.0465 0x02fc [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc C:\Windows\system32\sstpsvc.dll

07:06:50.0496 0x02fc SstpSvc - ok

07:06:50.0637 0x02fc [ A6B2EC3A2B6AD7C3F7B2F3495CADE4C0, AD540FB4F300731DE403FB95F110A0F3DBA25917A91EAB23966286DD88C98D17 ] STacSV C:\Program Files\IDT\WDM\STacSV64.exe

07:06:50.0684 0x02fc STacSV - ok

07:06:50.0715 0x02fc [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor C:\Windows\system32\drivers\stexstor.sys

07:06:50.0730 0x02fc stexstor - ok

07:06:50.0808 0x02fc [ EBA98394A7D58F7552C52192BD8FA7E6, 4238870E50132E87772300058B37E36973695CC1A5E62117EEF4B424C6A137E4 ] STHDA C:\Windows\system32\DRIVERS\stwrt64.sys

07:06:50.0855 0x02fc STHDA - ok

07:06:50.0902 0x02fc [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc C:\Windows\System32\wiaservc.dll

07:06:50.0933 0x02fc stisvc - ok

07:06:50.0949 0x02fc [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum C:\Windows\system32\drivers\swenum.sys

07:06:50.0964 0x02fc swenum - ok

07:06:51.0011 0x02fc [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv C:\Windows\System32\swprv.dll

07:06:51.0058 0x02fc swprv - ok

07:06:51.0157 0x02fc [ C447977ED2A4AE9346FE3A0579A34D7C, 35A8F13AAB57549BBC1457AD86F44FEF2394E55841A1D6D6C5E029310E02F377 ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys

07:06:51.0188 0x02fc SynTP - ok

07:06:51.0250 0x02fc [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C335B9807EB3DBB8 ] SysMain C:\Windows\system32\sysmain.dll

07:06:51.0313 0x02fc SysMain - ok

07:06:51.0344 0x02fc [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll

07:06:51.0359 0x02fc TabletInputService - ok

07:06:51.0375 0x02fc [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv C:\Windows\System32\tapisrv.dll

07:06:51.0437 0x02fc TapiSrv - ok

07:06:51.0453 0x02fc [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS C:\Windows\System32\tbssvc.dll

07:06:51.0484 0x02fc TBS - ok

07:06:51.0609 0x02fc [ 92CE29D95AC9DD2D0EE9061D551BA250, 47396E19141F72759519F83F5CBBCB8CDB3F8153898879BFE2D9A754EC4E6C47 ] Tcpip C:\Windows\system32\drivers\tcpip.sys

07:06:51.0671 0x02fc Tcpip - ok

07:06:51.0734 0x02fc [ 92CE29D95AC9DD2D0EE9061D551BA250, 47396E19141F72759519F83F5CBBCB8CDB3F8153898879BFE2D9A754EC4E6C47 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys

07:06:51.0781 0x02fc TCPIP6 - ok

07:06:51.0812 0x02fc [ DF687E3D8836BFB04FCC0615BF15A519, 7C5B1E72673B4299DFC21E869F0FBB28198CA54DF4F4AF7080005F2D82467784 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys

07:06:51.0843 0x02fc tcpipreg - ok

07:06:51.0859 0x02fc [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys

07:06:51.0859 0x02fc TDPIPE - ok

07:06:51.0874 0x02fc [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys

07:06:51.0905 0x02fc TDTCP - ok

07:06:51.0937 0x02fc [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719C48B08FAFA9661 ] tdx C:\Windows\system32\DRIVERS\tdx.sys

07:06:51.0968 0x02fc tdx - ok

07:06:51.0968 0x02fc [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD C:\Windows\system32\drivers\termdd.sys

07:06:51.0983 0x02fc TermDD - ok

07:06:52.0015 0x02fc [ 2E648163254233755035B46DD7B89123, 6FA0D07CE18A3A69D82EE49D875F141E39406E92C34EAC76AC4EB052E6EBCBCD ] TermService C:\Windows\System32\termsrv.dll

07:06:52.0061 0x02fc TermService - ok

07:06:52.0077 0x02fc [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes C:\Windows\system32\themeservice.dll

07:06:52.0093 0x02fc Themes - ok

07:06:52.0108 0x02fc [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER C:\Windows\system32\mmcss.dll

07:06:52.0139 0x02fc THREADORDER - ok

07:06:52.0171 0x02fc [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks C:\Windows\System32\trkwks.dll

07:06:52.0202 0x02fc TrkWks - ok

07:06:52.0249 0x02fc [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe

07:06:52.0327 0x02fc TrustedInstaller - ok

07:06:52.0358 0x02fc [ CE18B2CDFC837C99E5FAE9CA6CBA5D30, CA302C2ED6A6BF4670BAAA4F5C14C0238CF0C80316856AA0DB053F4D593033AC ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys

07:06:52.0373 0x02fc tssecsrv - ok

07:06:52.0389 0x02fc [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C85BA45BB71A74EB ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys

07:06:52.0405 0x02fc TsUsbFlt - ok

07:06:52.0420 0x02fc [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B984EEFA337B804 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys

07:06:52.0436 0x02fc TsUsbGD - ok

07:06:52.0451 0x02fc [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys

07:06:52.0498 0x02fc tunnel - ok

07:06:52.0514 0x02fc [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35 C:\Windows\system32\drivers\uagp35.sys

07:06:52.0514 0x02fc uagp35 - ok

07:06:52.0529 0x02fc [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs C:\Windows\system32\DRIVERS\udfs.sys

07:06:52.0576 0x02fc udfs - ok

07:06:52.0592 0x02fc [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect C:\Windows\system32\UI0Detect.exe

07:06:52.0607 0x02fc UI0Detect - ok

07:06:52.0623 0x02fc [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys

07:06:52.0623 0x02fc uliagpkx - ok

07:06:52.0639 0x02fc [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus C:\Windows\system32\DRIVERS\umbus.sys

07:06:52.0670 0x02fc umbus - ok

07:06:52.0685 0x02fc [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass C:\Windows\system32\drivers\umpass.sys

07:06:52.0701 0x02fc UmPass - ok

07:06:52.0826 0x02fc [ 758C2CE427C343F780A205E28555C98D, E3413BA433CD26DD61D3257B08B8354478A049A972EFAC53C303690BC71DD7E1 ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe

07:06:52.0904 0x02fc UNS - ok

07:06:52.0935 0x02fc [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost C:\Windows\System32\upnphost.dll

07:06:52.0997 0x02fc upnphost - ok

07:06:53.0013 0x02fc [ 6F1A3157A1C89435352CEB543CDB359C, 325B46220779C5FE3B6F19FF794474837FAB9675D9C98ACB68CCE47B1CFE5F12 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys

07:06:53.0029 0x02fc usbccgp - ok

07:06:53.0065 0x02fc [ AF0892A803FDDA7492F595368E3B68E7, F263346DEB4D742EB436CF578F187AC8521D84CED52E98475E6198EC52244F07 ] usbcir C:\Windows\system32\drivers\usbcir.sys

07:06:53.0080 0x02fc usbcir - ok

07:06:53.0112 0x02fc [ C025055FE7B87701EB042095DF1A2D7B, D7B34B6C2C5BD3C8141895AC21BB637EA5E3C4F7A85EEF4C4C36E6BB2045A3D9 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys

07:06:53.0127 0x02fc usbehci - ok

07:06:53.0158 0x02fc [ 287C6C9410B111B68B52CA298F7B8C24, 98900C08FE662A00DF8B37837B2BEBF9ACB7989C387AF36B2109B05A4F462D4E ] usbhub C:\Windows\system32\drivers\usbhub.sys

07:06:53.0190 0x02fc usbhub - ok

07:06:53.0190 0x02fc [ 9840FC418B4CBD632D3D0A667A725C31, 776D86A032DCA2842EF7AADB35473193CA80547223EFAA7F110F296C377077B0 ] usbohci C:\Windows\system32\drivers\usbohci.sys

07:06:53.0221 0x02fc usbohci - ok

07:06:53.0236 0x02fc [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint C:\Windows\system32\drivers\usbprint.sys

07:06:53.0268 0x02fc usbprint - ok

07:06:53.0299 0x02fc [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS

07:06:53.0330 0x02fc USBSTOR - ok

07:06:53.0330 0x02fc [ 62069A34518BCF9C1FD9E74B3F6DB7CD, C58E21424718729324B285BEE1C96551540FCC3FD650B2D10895EBA48D981E25 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys

07:06:53.0346 0x02fc usbuhci - ok

07:06:53.0377 0x02fc [ 454800C2BC7F3927CE030141EE4F4C50, 10901E62DAA70657C499AD590DECCCA6E46FDDF4A193B2F19279E1B8ED7B1E44 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys

07:06:53.0392 0x02fc usbvideo - ok

07:06:53.0424 0x02fc [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms C:\Windows\System32\uxsms.dll

07:06:53.0455 0x02fc UxSms - ok

07:06:53.0470 0x02fc [ 0793F40B9B8A1BDD266296409DBD91EA, 8A383FC9A66A327905C340D06138980F9E489479535A2C2AAE5E8BB14A74826E ] VaultSvc C:\Windows\system32\lsass.exe

07:06:53.0486 0x02fc VaultSvc - ok

07:06:53.0502 0x02fc [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys

07:06:53.0517 0x02fc vdrvroot - ok

07:06:53.0548 0x02fc [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds C:\Windows\System32\vds.exe

07:06:53.0595 0x02fc vds - ok

07:06:53.0626 0x02fc [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys

07:06:53.0642 0x02fc vga - ok

07:06:53.0642 0x02fc [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave C:\Windows\System32\drivers\vga.sys

07:06:53.0689 0x02fc VgaSave - ok

07:06:53.0689 0x02fc [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp C:\Windows\system32\drivers\vhdmp.sys

07:06:53.0704 0x02fc vhdmp - ok

07:06:53.0720 0x02fc [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide C:\Windows\system32\drivers\viaide.sys

07:06:53.0720 0x02fc viaide - ok

07:06:53.0720 0x02fc [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr C:\Windows\system32\drivers\volmgr.sys

07:06:53.0736 0x02fc volmgr - ok

07:06:53.0751 0x02fc [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx C:\Windows\system32\drivers\volmgrx.sys

07:06:53.0767 0x02fc volmgrx - ok

07:06:53.0782 0x02fc [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap C:\Windows\system32\drivers\volsnap.sys

07:06:53.0782 0x02fc volsnap - ok

07:06:53.0814 0x02fc [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid C:\Windows\system32\drivers\vsmraid.sys

07:06:53.0829 0x02fc vsmraid - ok

07:06:53.0892 0x02fc [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS C:\Windows\system32\vssvc.exe

07:06:53.0970 0x02fc VSS - ok

07:06:54.0001 0x02fc [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys

07:06:54.0032 0x02fc vwifibus - ok

07:06:54.0032 0x02fc [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys

07:06:54.0063 0x02fc vwififlt - ok

07:06:54.0094 0x02fc [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time C:\Windows\system32\w32time.dll

07:06:54.0126 0x02fc W32Time - ok

07:06:54.0157 0x02fc [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen C:\Windows\system32\drivers\wacompen.sys

07:06:54.0172 0x02fc WacomPen - ok

07:06:54.0188 0x02fc [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys

07:06:54.0235 0x02fc WANARP - ok

07:06:54.0250 0x02fc [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys

07:06:54.0282 0x02fc Wanarpv6 - ok

07:06:54.0344 0x02fc [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine C:\Windows\system32\wbengine.exe

07:06:54.0406 0x02fc wbengine - ok

07:06:54.0422 0x02fc [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc C:\Windows\System32\wbiosrvc.dll

07:06:54.0438 0x02fc WbioSrvc - ok

07:06:54.0469 0x02fc [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc C:\Windows\System32\wcncsvc.dll

07:06:54.0500 0x02fc wcncsvc - ok

07:06:54.0516 0x02fc [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll

07:06:54.0516 0x02fc WcsPlugInService - ok

07:06:54.0547 0x02fc [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd C:\Windows\system32\drivers\wd.sys

07:06:54.0562 0x02fc Wd - ok

07:06:54.0578 0x02fc [ 441BD2D7B4F98134C3A4F9FA570FD250, FF20815273014C5A27C2B75E2C70FE674809293627056199F502DFDF4CECFCA1 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys

07:06:54.0594 0x02fc Wdf01000 - ok

07:06:54.0625 0x02fc [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiServiceHost C:\Windows\system32\wdi.dll

07:06:54.0703 0x02fc WdiServiceHost - ok

07:06:54.0718 0x02fc [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793A3E219EB961209 ] WdiSystemHost C:\Windows\system32\wdi.dll

07:06:54.0734 0x02fc WdiSystemHost - ok

07:06:54.0750 0x02fc [ 3DB6D04E1C64272F8B14EB8BC4616280, 9138642B1C19F895D4ECFD930160C80FBF15813CE63BBF4C899842C300FD3026 ] WebClient C:\Windows\System32\webclnt.dll

07:06:54.0796 0x02fc WebClient - ok

07:06:54.0812 0x02fc [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90640E6EE8EB55C1 ] Wecsvc C:\Windows\system32\wecsvc.dll

07:06:54.0859 0x02fc Wecsvc - ok

07:06:54.0890 0x02fc [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport C:\Windows\System32\wercplsupport.dll

07:06:54.0921 0x02fc wercplsupport - ok

07:06:54.0937 0x02fc [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc C:\Windows\System32\WerSvc.dll

07:06:54.0984 0x02fc WerSvc - ok

07:06:54.0999 0x02fc [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys

07:06:55.0030 0x02fc WfpLwf - ok

07:06:55.0035 0x02fc [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount C:\Windows\system32\drivers\wimmount.sys

07:06:55.0035 0x02fc WIMMount - ok

07:06:55.0035 0x02fc WinDefend - ok

07:06:55.0051 0x02fc WinHttpAutoProxySvc - ok

07:06:55.0176 0x02fc [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll

07:06:55.0223 0x02fc Winmgmt - ok

07:06:55.0301 0x02fc [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B186E1CAD2AC70565 ] WinRM C:\Windows\system32\WsmSvc.dll

07:06:55.0379 0x02fc WinRM - ok

07:06:55.0457 0x02fc [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc C:\Windows\System32\wlansvc.dll

07:06:55.0503 0x02fc Wlansvc - ok

07:06:55.0550 0x02fc [ 06C8FA1CF39DE6A735B54D906BA791C6, D8FEC7DE227781CDA876904701B2AA995268F74DCD6CB34AA0296C557FC283B6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe

07:06:55.0566 0x02fc wlcrasvc - ok

07:06:55.0706 0x02fc [ 7E47C328FC4768CB8BEAFBCFAFA70362, C98BD6A0C2F70E069D5FD3BAB31BD028DFEAC0490D180BBC28A14BE375897D8C ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

07:06:55.0769 0x02fc wlidsvc - ok

07:06:55.0784 0x02fc [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys

07:06:55.0800 0x02fc WmiAcpi - ok

07:06:55.0847 0x02fc [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe

07:06:55.0862 0x02fc wmiApSrv - ok

07:06:55.0878 0x02fc WMPNetworkSvc - ok

07:06:55.0925 0x02fc [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc C:\Windows\System32\wpcsvc.dll

07:06:55.0925 0x02fc WPCSvc - ok

07:06:55.0940 0x02fc [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll

07:06:55.0940 0x02fc WPDBusEnum - ok

07:06:55.0971 0x02fc [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys

07:06:56.0003 0x02fc ws2ifsl - ok

07:06:56.0018 0x02fc [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc C:\Windows\System32\wscsvc.dll

07:06:56.0049 0x02fc wscsvc - ok

07:06:56.0049 0x02fc WSearch - ok

07:06:56.0190 0x02fc [ 61FF576450CCC80564B850BC3FB6713A, B2843BC9E2F62D27DCF6787D063378926748CE75002BADA1873DCB5039883705 ] wuauserv C:\Windows\system32\wuaueng.dll

07:06:56.0268 0x02fc wuauserv - ok

07:06:56.0299 0x02fc [ D3381DC54C34D79B22CEE0D65BA91B7C, 70DC4ADCA4C0C28BB133287511E329D1B6B9B97F96CDE5B1D2F1F59FE1A965D9 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys

07:06:56.0346 0x02fc WudfPf - ok

07:06:56.0361 0x02fc [ 7A95C95B6C4CF292D689106BCAE49543, 9029F489E1E817CE12839B8C6656E46190497D445DC3F43C20CF96E5E6BD0691 ] wudfsvc C:\Windows\System32\WUDFSvc.dll

07:06:56.0393 0x02fc wudfsvc - ok

07:06:56.0439 0x02fc [ CE8CF9DE9CBFDAA318BD04D8BE3FCADA, D0438DFD8A196BD55140D89AACF74E47893AF42771CDCC93970E7CF6E9E9C232 ] WwanSvc C:\Windows\System32\wwansvc.dll

07:06:56.0455 0x02fc WwanSvc - ok

07:06:56.0486 0x02fc ================ Scan global ===============================

07:06:56.0517 0x02fc [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618DD5859E8ADBF1A8 ] C:\Windows\system32\basesrv.dll

07:06:56.0533 0x02fc [ 15822E7206C7A0A893395CB07A63C7E1, 05276307E6FAB03AC5FBED137427AC3AED42FECBF7549B4F2A1D6FA18000F09B ] C:\Windows\system32\winsrv.dll

07:06:56.0549 0x02fc [ 15822E7206C7A0A893395CB07A63C7E1, 05276307E6FAB03AC5FBED137427AC3AED42FECBF7549B4F2A1D6FA18000F09B ] C:\Windows\system32\winsrv.dll

07:06:56.0564 0x02fc [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll

07:06:56.0580 0x02fc [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885F668CF42C5E7E2 ] C:\Windows\system32\services.exe

07:06:56.0595 0x02fc [ Global ] - ok

07:06:56.0595 0x02fc ================ Scan MBR ==================================

07:06:56.0611 0x02fc [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0

07:06:57.0001 0x02fc \Device\Harddisk0\DR0 - ok

07:06:57.0017 0x02fc ================ Scan VBR ==================================

07:06:57.0022 0x02fc [ 4CE6881AC68EB139B60977DA56B73DE3 ] \Device\Harddisk0\DR0\Partition1

07:06:57.0024 0x02fc \Device\Harddisk0\DR0\Partition1 - ok

07:06:57.0027 0x02fc [ A253F03458C8F037934942B448FB7424 ] \Device\Harddisk0\DR0\Partition2

07:06:57.0027 0x02fc \Device\Harddisk0\DR0\Partition2 - ok

07:06:57.0058 0x02fc [ 77D9F988832C84C9E8685E2ADC7A4D53 ] \Device\Harddisk0\DR0\Partition3

07:06:57.0058 0x02fc \Device\Harddisk0\DR0\Partition3 - ok

07:06:57.0073 0x02fc [ 2F2C117FA1F47E6353234DA13FB7AEF3 ] \Device\Harddisk0\DR0\Partition4

07:06:57.0073 0x02fc \Device\Harddisk0\DR0\Partition4 - ok

07:06:57.0073 0x02fc ================ Scan generic autorun ======================

07:06:57.0120 0x02fc [ 6852EFF21A2B89776D184252602EDB16, FE69D5EB3520716310E9908C3A440825BDB939C7521C9978702F1B9C9902E5AE ] C:\Windows\system32\igfxtray.exe

07:06:57.0136 0x02fc IgfxTray - ok

07:06:57.0151 0x02fc [ F80FED5F125F8FD4FD62E5663422FA6C, 033648652D112F2E4D03FDD2C0326ED7A2B2F0555CF828B9152B9FB21771AF9D ] C:\Windows\system32\hkcmd.exe

07:06:57.0167 0x02fc HotKeysCmds - ok

07:06:57.0183 0x02fc [ B870C339B3871BEDCCDA11FACA63A20C, EC11FE4EE0B8CFEE53F354B496689C4261E4BDE3C1513686EC8241723CF0293E ] C:\Windows\system32\igfxpers.exe

07:06:57.0198 0x02fc Persistence - ok

07:06:57.0198 0x02fc SynTPEnh - ok

07:06:57.0245 0x02fc [ D5A3EB5ED95E36B643E55F9F489FC8FC, 9DAE0075888E540659E6FC3FAB433108BF296CDF52DA11ECA4440E06E5187ED1 ] C:\Program Files\IDT\WDM\sttray64.exe

07:06:57.0292 0x02fc SysTrayApp - ok

07:06:57.0339 0x02fc [ 1562933015CD8A731986E5EBBF7CF6B1, 4E446AF7801B9A13EB41A1934CD5A59B7E886C81FF893E03C8E206284FB9E580 ] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe

07:06:57.0339 0x02fc SetDefault - ok

07:06:57.0495 0x02fc [ 92B79A04E8D0A09107E63E4974330FE9, 70569453CC0082D0D0569799DEB4F92EF314689740B5072C73500D4E24869A93 ] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

07:06:57.0541 0x02fc StartCCC - detected UnsignedFile.Multi.Generic ( 1 )

07:07:00.0711 0x02fc Detect skipped due to KSN trusted

07:07:00.0711 0x02fc StartCCC - ok

07:07:00.0820 0x02fc [ F96C73D7D525174B80CFD865A5D7E083, 06E7ACA4B9496CF0505F623DC4516A893E7A70EA37EAB27EA943C8831D221F40 ] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe

07:07:00.0851 0x02fc IAStorIcon - ok

07:07:00.0945 0x02fc [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe

07:07:00.0992 0x02fc Sidebar - ok

07:07:01.0012 0x02fc [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe

07:07:01.0043 0x02fc mctadmin - ok

07:07:01.0090 0x02fc [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe

07:07:01.0121 0x02fc Sidebar - ok

07:07:01.0137 0x02fc [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe

07:07:01.0153 0x02fc mctadmin - ok

07:07:01.0153 0x02fc Waiting for KSN requests completion. In queue: 277

07:07:02.0167 0x02fc Waiting for KSN requests completion. In queue: 277

07:07:03.0170 0x02fc Waiting for KSN requests completion. In queue: 5

07:07:04.0184 0x02fc Waiting for KSN requests completion. In queue: 5

07:07:05.0250 0x02fc AV detected via SS2: AVG AntiVirus Free Edition 2015, C:\Program Files (x86)\AVG\AVG2015\avgwsc.exe ( 15.0.0.5863 ), 0x41000 ( enabled : updated )

07:07:05.0281 0x02fc Win FW state via NFP2: enabled

07:07:08.0468 0x02fc ============================================================

07:07:08.0468 0x02fc Scan finished

07:07:08.0468 0x02fc ============================================================

07:07:08.0484 0x1448 Detected object count: 0

07:07:08.0484 0x1448 Actual detected object count: 0


  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Are you able to update AVG now ? If not what error do you get
  • 0

#9
stealthhawk

stealthhawk

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

yes. Thank you!   :)  AVG downloaded

 

windows update is 42% but slow...

 

I'll try malwarebytes next

 

Do you know what the cause is?  Was it something I did to the firewall?


  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
I could see no malware as such but, I did reset all your network, proxy and DNS connections..

The other issue now is are you still getting the high traffic as before ? A bit difficult at the moment to judge I know due to the updates coming down. However, once they are complete could you let me know how that is running
  • 0

#11
stealthhawk

stealthhawk

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Your awesome man :)

Malwarebytes updated and windows update has downloaded and is still installing...

Sorry if I have dumb questions.

Before I ran sys reset, I was watching resource manager, it had lots (30+) of svchost (no impersonation) all connected to random ip's.  Also alot of no image tcp connections.

My network was constantly recieving and sending way more data than I was use to seeing.  Anti Virus and malware didn't find anything.

 

Its seems alot better now (thanks again) 

There is only a little net movement now... is any of that normal?  What was the cause?  Did I mess up my pc or my modem or both?


Edited by stealthhawk, 09 April 2015 - 03:20 PM.

  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
From what I have seen and done I would suspect that some malware had changed either the DNS or winsock settings, the reset cleared them all away :)

Svchost is the workhorse of windows so multiple copies are not unusual

This is a screen shot of my current network traffic where my AV is checking for updates along with windows plus a few packets to my ISP, so if yours is like this then it is normal



As you have run malwarebytes could you post the log if it showed anything .. Also how is the computer now ?
  • 0

#13
stealthhawk

stealthhawk

    New Member

  • Topic Starter
  • Member
  • Pip
  • 8 posts

Thanks again man :spoton:

 

I cant see the screen shot mentioned but my net activity has stabilised  :D

I still don't trust my sys though because it never found a virus or malware, and the ordeal was draining :smashcomp:

 

Malwarebytes hasn't found anything, neither has avg or adwcleaner.  But all are updating.

 

Before You close this thread for "solved"...CCleaner found some registry entries for invalid firewall rules with netpress.  Do you know if I should I fix them or leave them active?

Im not sure it's related to the issue I was even having.  Google has mixed answers.

 

 

Invalid firewall rule NetPres-Out-TCP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-In-TCP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-WSD-Out-UDP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-WSD-In-UDP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-Out-TCP-NoScope - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-In-TCP-NoScope - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet001\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-Out-TCP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-In-TCP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-WSD-Out-UDP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-WSD-In-UDP - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-Out-TCP-NoScope - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Invalid firewall rule NetPres-In-TCP-NoScope - %SystemRoot%\system32\netproj.exe HKLM\SYSTEM\ControlSet002\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
 


  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hmm I cannot see my screenshot either

Capture.JPG

It may have been a corrupt install in the network area, as I can see no indicators of malware, if the firewall rules are not causing a problem then I would leave them

Before I tidy up are you totally happy now or would you like me to check deeper ?
  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP