Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

I need help with an Alureon Virus


  • Please log in to reply

#16
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

I got the did not find any integrity violations message. I meant to ask you if it was okay to use Teamviewer now? I traveled to her apartment since you said the host files were manipulated and that is reason I didn't respond yet. 

 

Vino's Event Viewer v01c run on Windows 7 in English
Report run at 04/12/2017 10:45:46 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 04/12/2017 3:42:27 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x80070103: Advanced Micro Devices, Inc driver update for AMD SMBus.

Log: 'System' Date/Time: 02/12/2017 1:35:28 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

Log: 'System' Date/Time: 02/12/2017 1:35:28 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

Log: 'System' Date/Time: 02/12/2017 1:35:28 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 02/12/2017 4:28:29 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device SWD\WPDBUSENUM\_??_USBSTOR#Disk&Ven_SanDisk&Prod_U3_Cruzer_Micro&Rev_3.27#000016151173DCE0&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}.

Log: 'System' Date/Time: 02/12/2017 1:37:05 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device SWD\WPDBUSENUM\_??_USBSTOR#Disk&Ven_SanDisk&Prod_U3_Cruzer_Micro&Rev_3.27#000016151173DCE0&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}.

 

Vino's Event Viewer v01c run on Windows 7 in English
Report run at 04/12/2017 10:48:45 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


  • 0

Advertisements


#17
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

You can use Teamviewer.  Sorry if I wasn't clear. 


  • 0

#18
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

You're good man. No  worries. The second log after I checked application seemed really small. Standing by!


  • 0

#19
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Log: 'System' Date/Time: 02/12/2017 4:28:29 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device

 

This error is trivial but annoying.  Usually you can fix it by searching for services.msc and hitting Enter to bring up the service menu ( or Control Panel, Administrative Tools, Services)

 

Find:

 

Windows Driver Foundation - User-mode Driver Framework

 

right click on it and Properties then change Startup Type from Manual to Automatic.

 

These errors:

 

Log: 'System' Date/Time: 02/12/2017 1:35:28 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server {9BA05972-F6A8-11CF-A442-00A0C90A8F39} did not register with DCOM within the required timeout.

 

are common on Win 8 & 10 systems and probably not that important.  9BA05972-F6A8-11CF-A442-00A0C90A8F39 refers to something called ShellWindows which seems to be related to Internet Explorer which I never use so may be why I don't have it.  Usually it's a permission problem.  You have to go in to regedit and change ownership of the

HKEY_CLASSES_ROOT\AppID\{9BA05972-F6A8-11CF-A442-00A0C90A8F39} key to Administrators then give System & Administrators Full COntrol then Search

for DCOMCNFG and right click and Run As Admin when it finds it then

  1. Navigate to Component Services >> Computers >> My Computer >> DCOM Config
  2. Find ShellWindows >> Right Click >> Properties >> Security Tab
  3. Launch and Activation Permissions  (click Customize) >> Edit >> Add System and give it full control

A lot of work and probably not worth the effort to get rid of the errors.

 

I reread your posts and noticed you are using a very old version of TDSS Killer.  Get the latest from:

https://usa.kaspersk...oads/tdsskiller

and run it.  Let's see what it says.

 

Also did you run MBAR? 


  • 0

#20
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

I found the old version using the search feature. Here's the latest scan with the updated version:

 

12:48:09.0615 0x1ad8  TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02
12:48:09.0615 0x1ad8  UEFI system
12:48:14.0899 0x1ad8  ============================================================
12:48:14.0899 0x1ad8  Current date / time: 2017/12/05 12:48:14.0899
12:48:14.0899 0x1ad8  SystemInfo:
12:48:14.0899 0x1ad8  
12:48:14.0899 0x1ad8  OS Version: 6.3.9600 ServicePack: 0.0
12:48:14.0899 0x1ad8  Product type: Workstation
12:48:14.0899 0x1ad8  ComputerName: HP-DESKTOP
12:48:14.0899 0x1ad8  UserName: Owner
12:48:14.0899 0x1ad8  Windows directory: C:\Windows
12:48:14.0899 0x1ad8  System windows directory: C:\Windows
12:48:14.0899 0x1ad8  Running under WOW64
12:48:14.0899 0x1ad8  Processor architecture: Intel x64
12:48:14.0899 0x1ad8  Number of processors: 4
12:48:14.0899 0x1ad8  Page size: 0x1000
12:48:14.0899 0x1ad8  Boot type: Normal boot
12:48:14.0899 0x1ad8  CodeIntegrityOptions = 0x00000001
12:48:14.0899 0x1ad8  ============================================================
12:48:15.0775 0x1ad8  KLMD registered as C:\Windows\system32\drivers\61219944.sys
12:48:15.0775 0x1ad8  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 9600.18821, osProperties = 0x19
12:48:18.0182 0x1ad8  System UUID: {8F04FE06-DF58-C067-1E31-DEAE2A40F1CB}
12:48:19.0385 0x1ad8  Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
12:48:19.0401 0x1ad8  ============================================================
12:48:19.0401 0x1ad8  \Device\Harddisk0\DR0:
12:48:19.0417 0x1ad8  GPT partitions:
12:48:19.0417 0x1ad8  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {D247555E-D39B-464F-A1A6-73D996B00567}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x96000
12:48:19.0417 0x1ad8  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {76457BAD-1730-4F8E-A20E-8F4A7D9F447B}, Name: EFI system partition, StartLBA 0x96800, BlocksNum 0x32000
12:48:19.0417 0x1ad8  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {4F195DDA-4FA4-42B0-92A4-E9039210EB80}, Name: Microsoft reserved partition, StartLBA 0xC8800, BlocksNum 0x40000
12:48:19.0417 0x1ad8  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {9B4C8972-8B43-485B-94C6-1B4881B9DE50}, Name: Basic data partition, StartLBA 0x108800, BlocksNum 0xE8D00000
12:48:19.0417 0x1ad8  MBR partitions:
12:48:19.0417 0x1ad8  ============================================================
12:48:19.0448 0x1ad8  C: <-> \Device\Harddisk0\DR0\Partition4
12:48:19.0448 0x1ad8  ============================================================
12:48:19.0448 0x1ad8  Initialize success
12:48:19.0448 0x1ad8  ============================================================
12:48:20.0979 0x195c  ============================================================
12:48:20.0979 0x195c  Scan started
12:48:20.0979 0x195c  Mode: Manual;
12:48:20.0979 0x195c  ============================================================
12:48:20.0979 0x195c  KSN ping started
12:48:21.0151 0x195c  KSN ping finished: true
12:48:23.0887 0x195c  ================ Scan system memory ========================
12:48:23.0887 0x195c  System memory - ok
12:48:23.0887 0x195c  ================ Scan services =============================
12:48:24.0077 0x195c  [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1, 41FF7418887AFC8B9C96EF21C5950DD342CC9E3C0D87AFD60A05B988C1D6CC23 ] 1394ohci        C:\Windows\System32\drivers\1394ohci.sys
12:48:24.0077 0x195c  1394ohci - ok
12:48:24.0109 0x195c  [ AD508A1A46EC21B740AB31C28EFDFDB1, 9B1046CF0B80723149BD359B55CC0B8B3ABBEAA9038469F542A4C345C503FB02 ] 3ware           C:\Windows\system32\drivers\3ware.sys
12:48:24.0124 0x195c  3ware - ok
12:48:24.0155 0x195c  [ E796AE43DDD1844281DB4D57294D17C0, 21AE69615044A96041E46476BE814B52C22624B6C7EA6BFC77BB64F69C3C21F5 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
12:48:24.0155 0x195c  ACPI - ok
12:48:24.0186 0x195c  [ AC8279D229398BCF05C3154ADCA86813, 083E86CBE53244D24C334DB1511C77025133AE7875191845764B890A8CA5AFA9 ] acpiex          C:\Windows\system32\Drivers\acpiex.sys
12:48:24.0186 0x195c  acpiex - ok
12:48:24.0203 0x195c  [ A8970D9BF23CD309E0403978A1B58F3F, 9946C8477104EEC7DB197E2222F9905307F101C398CCED4B5FD0F86A5622C791 ] acpipagr        C:\Windows\System32\drivers\acpipagr.sys
12:48:24.0203 0x195c  acpipagr - ok
12:48:24.0233 0x195c  [ 111A89C99C5B4F1A7BCE5F643DD86F65, 41A2E49FF443927D05F7EF638518108227852984E68D4663C8761178C0B84A45 ] AcpiPmi         C:\Windows\System32\drivers\acpipmi.sys
12:48:24.0233 0x195c  AcpiPmi - ok
12:48:24.0233 0x195c  [ 5758387D68A20AE7D3245011B07E36E7, 77832E200E8B0D259552F6F60FE454A887E3EBBB9EA2F3590E6645289A04E293 ] acpitime        C:\Windows\System32\drivers\acpitime.sys
12:48:24.0249 0x195c  acpitime - ok
12:48:24.0282 0x195c  [ 7C1FDF1B48298CBA7CE4BDD4978951AD, 80F4D536E1231B30E836F72ADC8814AE6AA9FEC573FB5F3F965FAC8ABCCAF0F8 ] ADP80XX         C:\Windows\system32\drivers\ADP80XX.SYS
12:48:24.0298 0x195c  ADP80XX - ok
12:48:24.0343 0x195c  [ BCD58DACAA1EAAADC115EDD940478F6D, F31613F583C302F62A00E6766B031531C9E193CAED563689B178BA257715B992 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
12:48:24.0343 0x195c  AeLookupSvc - ok
12:48:24.0390 0x195c  [ A460C3AF3755A2A79A3C8EFE72E147B5, 62CEA85DA53D86D3E7B5D79F94095C6126FFF3DEE1427BBF3DEF5EA366B4513B ] AFD             C:\Windows\system32\drivers\afd.sys
12:48:24.0407 0x195c  AFD - ok
12:48:24.0421 0x195c  [ 7DFAEBA9AD62D20102B576D5CAC45EC8, 9FA5207335303D1E8E9A3C9E1FB82C09AD21B04382F69D777A67E48EE91D2093 ] agp440          C:\Windows\system32\drivers\agp440.sys
12:48:24.0421 0x195c  agp440 - ok
12:48:24.0455 0x195c  [ FE14D249D39368CA62D8DA6BC94AC694, E1036E22BFBD3750FD2D3DA6AB939B2DD54E824F4BD3E6539EF0E45AB5453DD1 ] ahcache         C:\Windows\system32\DRIVERS\ahcache.sys
12:48:24.0455 0x195c  ahcache - ok
12:48:24.0484 0x195c  [ 14A45BE6F5678339F0EC5752D9849410, DD0F60E96FAC68FBD5B86382E541408C613BD0F871D0E0A1EF9AB6E7B26E545C ] ALG             C:\Windows\System32\alg.exe
12:48:24.0499 0x195c  ALG - ok
12:48:24.0531 0x195c  [ BC54D9830300C8B4F2B483CD6E0FC4CB, 0081541C35FC74BC3926468A34ED5BA2AD055D5AEAC7F43753F9A9FD4F6029FD ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
12:48:24.0531 0x195c  AMD External Events Utility - ok
12:48:24.0563 0x195c  [ 7589DE749DB6F71A68489DCE04158729, 5F35EDD50737985595C9D6703237CA2ADE49AA5443331020899698EB5114A0FB ] AmdK8           C:\Windows\System32\drivers\amdk8.sys
12:48:24.0563 0x195c  AmdK8 - ok
12:48:25.0218 0x195c  [ 6398021B262BD1531E8523CF5DEFD600, 26F331F008E8D2A0D224DB176A7B4F13C0291EEAB4B3FF435F7B8644D4EF48A9 ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
12:48:25.0452 0x195c  amdkmdag - ok
12:48:25.0562 0x195c  [ BB4A8E585178DDAE35875D670C41C981, 9678B8F3E4F2D0C5D38B15EAFED9A437AF2877D464E7B0A6C36C8443D19F9BE2 ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
12:48:25.0577 0x195c  amdkmdap - ok
12:48:25.0609 0x195c  [ B46D2D89AFF8A9490FA8C98C7A5616E3, BE0765B5423B690E0F097FECD9717FAA95BFDFFDC6CF1B93DE5A19A1B7797879 ] AmdPPM          C:\Windows\System32\drivers\amdppm.sys
12:48:25.0609 0x195c  AmdPPM - ok
12:48:25.0640 0x195c  [ D2BF2F94A47D332814910FD47C6BBCD2, FE273D77D119D958676E1197D9EA7B008E3B05C6192B1962A81D4223ED204C35 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
12:48:25.0640 0x195c  amdsata - ok
12:48:25.0672 0x195c  [ A8E04943C7BBA7219AA50400272C3C6E, 794C0BD12DF0392654E9A37AE4A24B5BE2D83F1F24F74DD48A1A0BF3AB8B1FF8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
12:48:25.0688 0x195c  amdsbs - ok
12:48:25.0719 0x195c  [ CEA5F4F27CFC08E3A44D576811B35F50, 89DF64B81BD109BAABAE93A4603C1617241219F38DDAF325EFE6BD35FF6FD717 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
12:48:25.0719 0x195c  amdxata - ok
12:48:25.0751 0x195c  [ 415DD71628795197F7AFC176CBADC74E, 5F0359053A6CD6EE239139E0E6F46E1FA9A73F017C0CE9B7BC052216B2C846EC ] AppID           C:\Windows\system32\drivers\appid.sys
12:48:25.0765 0x195c  AppID - ok
12:48:25.0812 0x195c  [ 942C8297400FCFB13CEE3F3CD89C5CE5, AFD9EC35F6C44D86DD5943A2AB0B99B0C1B1783D70FD966F6467F97F0831403F ] AppIDSvc        C:\Windows\System32\appidsvc.dll
12:48:25.0812 0x195c  AppIDSvc - ok
12:48:25.0858 0x195c  [ 734622FBA766DBD65B1803549B24A04A, 3B6872B87A60D4DA265D3B8AB0561A929CFE2C097419183E93D3843422363C89 ] Appinfo         C:\Windows\System32\appinfo.dll
12:48:25.0858 0x195c  Appinfo - ok
12:48:25.0969 0x195c  [ 7D811EA7A2AAA49B0446D42CBC1CD338, AFECE5E44E48F756C7EB81D95C9237552AF8A9C02CBE756E0F3D3C6524DE49AD ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:48:25.0969 0x195c  Apple Mobile Device Service - ok
12:48:26.0046 0x195c  [ 35E28923A23ADABAA5A1B43256D0AB58, A5F3AF8BBEE58B2165BAFACC5FF8B167B55B020998D3D1565C2229ED8753B269 ] AppReadiness    C:\Windows\system32\AppReadiness.dll
12:48:26.0046 0x195c  AppReadiness - ok
12:48:26.0155 0x195c  [ E0F846ADE7DED88981D0908DE56FF160, D8F536438091878724A5004849306ADFB96A2778A9D958ED3DCC0CD9E35160BB ] AppXSvc         C:\Windows\system32\appxdeploymentserver.dll
12:48:26.0171 0x195c  AppXSvc - ok
12:48:26.0204 0x195c  [ 65045784366F7EC5FB4E71BCF923187B, 53C215C64FF12E44B097F7CB88E8482438CE0ACBD3C68D8FD38BA0D0D8747FAA ] arcsas          C:\Windows\system32\drivers\arcsas.sys
12:48:26.0218 0x195c  arcsas - ok
12:48:26.0235 0x195c  [ 74B14192CF79A72F7536B27CB8814FBD, 0CF6BBB63FFE0C12777664D80B2797923844C8392D0FD81D7962EE5EE2C3C3D9 ] atapi           C:\Windows\system32\drivers\atapi.sys
12:48:26.0235 0x195c  atapi - ok
12:48:26.0468 0x195c  [ 2C7676F892E88FD190F08D98048C7C6C, 44C13C103F61DA4D1A3823D37344F8C9465A611A9560808CE928925FB69604F7 ] athr            C:\Windows\system32\DRIVERS\athw8x.sys
12:48:26.0530 0x195c  athr - ok
12:48:26.0562 0x195c  [ 431FE56F5A2F5937994CB2DA330B47DB, E5AED551529A21494114959251FDF566802DD6D9B9D86A937A0EECE53338CAC7 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
12:48:26.0577 0x195c  AudioEndpointBuilder - ok
12:48:26.0610 0x195c  [ 0F03CC00645D7F841879A048787D6AC7, 3ECD2486157469F2EDB63D4868338D1445F2909153DF0AFFE432083730EEE3F5 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
12:48:26.0624 0x195c  Audiosrv - ok
12:48:26.0655 0x195c  [ 3C6ED74AF41DD1A5585CE5EF3D00915F, A742F576407776634E5A8E49C60023FFDF395DE0B2DE36662A23F85B79405ED2 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
12:48:26.0673 0x195c  AxInstSV - ok
12:48:26.0718 0x195c  [ A4A73F631FE2AA2826FBE4A399B04DEF, 973AACE8DC8DA669D0DF20F17EFDEEABB90AA046AC980948D16A62D39A606A79 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
12:48:26.0733 0x195c  b06bdrv - ok
12:48:26.0749 0x195c  [ 8CC7F7E4AFCBA605921B137ED7992C68, 71406E6D6E9964740A6D90B05329D5492BB90AF40E0630CF2FBF4BA4BA14F2DD ] BasicDisplay    C:\Windows\System32\drivers\BasicDisplay.sys
12:48:26.0749 0x195c  BasicDisplay - ok
12:48:26.0813 0x195c  [ 195BD339B4B782B42C19489DCFB4D110, E63CC0AEF1875D5D127E341CF65117DABC9E376A83E615EC8D01F6AB705DABAD ] BasicRender     C:\Windows\System32\drivers\BasicRender.sys
12:48:26.0813 0x195c  BasicRender - ok
12:48:26.0828 0x195c  [ C1ABB0F7E3BEA48A0417BDF6FF14AB21, 1CAC63A1A0FB9855A27EE977794576A860F6650C9EF7667FFB27F2A2FF721857 ] bcmfn2          C:\Windows\System32\drivers\bcmfn2.sys
12:48:26.0846 0x195c  bcmfn2 - ok
12:48:26.0874 0x195c  [ 174394F4EF93C117BF7BE3878046A1B1, D58E868342D1DAFC4B04384A3713F729DF07F408AA6AE4762E6A4244F976526A ] BDESVC          C:\Windows\System32\bdesvc.dll
12:48:26.0874 0x195c  BDESVC - ok
12:48:26.0890 0x195c  [ EC19013E4CF87609534165DF897274D6, 8ED45537CF2D58D759A587CCBFDADD5580C7447B0C3B172CF19ECC7585E073FC ] Beep            C:\Windows\system32\drivers\Beep.sys
12:48:26.0890 0x195c  Beep - ok
12:48:26.0936 0x195c  [ 5059D93764340D4EAEDF49C47133118F, 26C5779469E04BEAFD290B619CA355648F3911C66D41B22D2C3DCA909FCA0F6E ] BFE             C:\Windows\System32\bfe.dll
12:48:26.0952 0x195c  BFE - ok
12:48:27.0030 0x195c  [ 48554994279BFE17A3D2B00076D0CB1A, 6521B1EC0BC6B01F63976370D89FE7DC2E7404899F68B6FAC37A9173B9C5D489 ] BITS            C:\Windows\System32\qmgr.dll
12:48:27.0046 0x195c  BITS - ok
12:48:27.0077 0x195c  [ 4938A9236300A356F97E378491EE4844, 60D892960D48EEF48F8EC4DE4F174EBD0BC0E7B28B6D8723D554CD1979EB55B4 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
12:48:27.0077 0x195c  bowser - ok
12:48:27.0125 0x195c  [ FA601515FF2B59F25FDD8EDB1D2A1104, 21DFB53241F8E880F7546B9ADF38F47D6AD0782EC7F8F0284ED69DE7CEF7DCB9 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
12:48:27.0125 0x195c  BrokerInfrastructure - ok
12:48:27.0156 0x195c  [ BC111AADACD0BF59D56547461D13AB6E, 91E3619930C29EE4B2683683888BA7EE3CF6B1DDB0C19A14E0880470CBE40EF4 ] Browser         C:\Windows\System32\browser.dll
12:48:27.0156 0x195c  Browser - ok
12:48:27.0187 0x195c  [ A8F23D453A424FF4DE04989C4727ECC7, AE4A9081395C7379F1C947EF8243F7609F90C843E086B8E77E1A2C06E36D4381 ] BthAvrcpTg      C:\Windows\System32\drivers\BthAvrcpTg.sys
12:48:27.0187 0x195c  BthAvrcpTg - ok
12:48:27.0233 0x195c  [ 272A62B660A48AEF366F8A1836CED19F, 78EFAC6B1B2313482329BBFFBF0DDA6462BD88E5BE3C817C5E8E0EAF3074C925 ] BthHFEnum       C:\Windows\System32\drivers\bthhfenum.sys
12:48:27.0233 0x195c  BthHFEnum - ok
12:48:27.0249 0x195c  [ 71FE2A48E4C93DDB9798C024880B6C07, 8E93DE29C61A5FA64216231228CB3C4A1A693FE87CAA2C070BCAD7BE2D8ED000 ] bthhfhid        C:\Windows\System32\drivers\BthHFHid.sys
12:48:27.0249 0x195c  bthhfhid - ok
12:48:27.0296 0x195c  [ 9307A4B743D277C499CDA8E19E5687AC, 7A01989EC3D54581F292BDEDC9B9445F2ABD50165102617E3089BDD061C63A19 ] BthHFSrv        C:\Windows\System32\BthHFSrv.dll
12:48:27.0296 0x195c  BthHFSrv - ok
12:48:27.0330 0x195c  [ EF4B9E7C9AD88C00C18A12B0D22D1894, 672537E75201E690D86CD65252B8AEF887C76EBD37AB0C419462D69164B350CC ] BTHMODEM        C:\Windows\System32\drivers\bthmodem.sys
12:48:27.0330 0x195c  BTHMODEM - ok
12:48:27.0343 0x195c  [ 043A0F37631BF453F16D478B71320F46, C368296B802984F438852927B8A40EA3F4205724A05828F3173F08EC17228356 ] bthserv         C:\Windows\system32\bthserv.dll
12:48:27.0343 0x195c  bthserv - ok
12:48:27.0359 0x195c  [ 2FA6510E33F7DEFEC03658B74101A9B9, 61C8C8E3F09B427711464C974EE22E1E01C48E10DB54A4EC9901F482FC36C978 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
12:48:27.0359 0x195c  cdfs - ok
12:48:27.0407 0x195c  [ C6796EA22B513E3457514D92DCDB1A3D, 2B893F3950C6B913B934C2089B69F3B0B77F229AE1820907E598455CBB78139C ] cdrom           C:\Windows\System32\drivers\cdrom.sys
12:48:27.0407 0x195c  cdrom - ok
12:48:27.0452 0x195c  [ ACFDC4EE40EC6E4A0AB91D923B8288C8, D31555AB31F504C247049219BE0ECDF26BB18E210BE7C45E8575FD166FD7EE23 ] CertPropSvc     C:\Windows\System32\certprop.dll
12:48:27.0452 0x195c  CertPropSvc - ok
12:48:27.0468 0x195c  [ BE9936EDD3267FAAFF94A7835867F00B, 3CEEF2377D45ED38C7CD3CE4C746EC5EA7277EFEC728A5438F0EF5F62FC7C859 ] circlass        C:\Windows\System32\drivers\circlass.sys
12:48:27.0468 0x195c  circlass - ok
12:48:27.0515 0x195c  [ 39D72BA91AFE3C81C1AB0DE41AA07EF3, E5FCE197700E68D48A1701030AAF33E41C44A929B47D79B5C91C68B86684FFB0 ] CLFS            C:\Windows\system32\drivers\CLFS.sys
12:48:27.0530 0x195c  CLFS - ok
12:48:27.0593 0x195c  [ EF6EF85DADC3184A10D8F2F7159973CB, 42FCB286CED95A5DEBC5C0C894FCBC4818A2C818BB71087142FB51A08A0BE96B ] CmBatt          C:\Windows\System32\drivers\CmBatt.sys
12:48:27.0593 0x195c  CmBatt - ok
12:48:27.0671 0x195c  [ C8823A6ECE66B997C8E9F413D1D671E7, D739A194BCA4C1979C5B2A71F4B8DAB0BCC1524808C50BA302847B6C82D77250 ] CNG             C:\Windows\system32\Drivers\cng.sys
12:48:27.0687 0x195c  CNG - ok
12:48:27.0702 0x195c  [ 03AAED827C36F35D70900558B8274905, 8E44A23C6013FFAE7769F99CAA3B1D6288DE00A38937F9056903AC265B503AFA ] CompositeBus    C:\Windows\System32\drivers\CompositeBus.sys
12:48:27.0702 0x195c  CompositeBus - ok
12:48:27.0718 0x195c  COMSysApp - ok
12:48:27.0765 0x195c  [ A1FF7DFBFBE164CF92603C651D304DD2, 470ACE5A75E64FC62C950037201199857E974803625DC73BEDBCF6FA4DDD496C ] condrv          C:\Windows\system32\drivers\condrv.sys
12:48:27.0765 0x195c  condrv - ok
12:48:27.0812 0x195c  [ 6324F0D18FB52833BA64BC828E29054C, 04118FA1BDFC512F76E4A81FEF34C78B6BD98429DB1D65123B6802B4A1E30584 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
12:48:27.0827 0x195c  CryptSvc - ok
12:48:27.0860 0x195c  [ 315BA4BC19316D72B2E037534E048B93, 69613635DB23E6A935673B1025C2010ED3E195473D25368CF74234C4C36910BE ] dam             C:\Windows\system32\drivers\dam.sys
12:48:27.0860 0x195c  dam - ok
12:48:27.0952 0x195c  [ 20CC6E9FE25ACD34BE4FCDDB7B08364D, 295B2BBDC860A4CD65CD09C975D08CA1B8E4FE60AD0CA084CAB149A3E9D64B40 ] DcomLaunch      C:\Windows\system32\rpcss.dll
12:48:27.0968 0x195c  DcomLaunch - ok
12:48:28.0015 0x195c  [ 95E1ABFB27F8A62ED764805775F0D2F3, 692865DA60C93481E01592883678B2C51FD9AC9A835DFB00A8E3F2DFEE7AB0ED ] defragsvc       C:\Windows\System32\defragsvc.dll
12:48:28.0015 0x195c  defragsvc - ok
12:48:28.0078 0x195c  [ FF086DEF5995558CCB1B5AAC2110195D, CED52FF01F9247BFDAFC5C7EFC538F8638146ED715574A422496EE0F846CB079 ] DeviceAssociationService C:\Windows\system32\das.dll
12:48:28.0078 0x195c  DeviceAssociationService - ok
12:48:28.0109 0x195c  [ 2C02AFF8383D893F8DBEB07A84F6E77C, 7CC34BAC67E2988E3D16DD6EB6F6785CD2460E3EF7FBD0BD5F86E49793BD473E ] DeviceInstall   C:\Windows\system32\umpnpmgr.dll
12:48:28.0109 0x195c  DeviceInstall - ok
12:48:28.0172 0x195c  [ 4FED6AD69C9EE1EE7FD3C88437138855, 71E0863898F2E3B1F9769C8A9980E2063042961D417FE0C969B2E5B7A0013978 ] Dfsc            C:\Windows\system32\Drivers\dfsc.sys
12:48:28.0172 0x195c  Dfsc - ok
12:48:28.0219 0x195c  [ 3EEAADA3125431980E5804ED7143458A, 381E12C83E3211C255B321D35536F4049D67E31061F8D82155E4D4509E97F43D ] Dhcp            C:\Windows\system32\dhcpcore.dll
12:48:28.0219 0x195c  Dhcp - ok
12:48:28.0328 0x195c  [ 0AC9F83A5508935DE89C447473085EEA, 223782B17BACEFB0A663EB13514B68B919C95EF641CDDA7AC30CB239BC4307EC ] DiagTrack       C:\Windows\system32\diagtrack.dll
12:48:28.0361 0x195c  DiagTrack - ok
12:48:28.0407 0x195c  [ BF6D8575DDF30384939B2D5251F27C1F, 1605530BC61FB726F1095C5B5C8E27B18C06BCE01948550988E9EDCEBBCC0B3D ] disk            C:\Windows\system32\drivers\disk.sys
12:48:28.0407 0x195c  disk - ok
12:48:28.0906 0x195c  [ CAF3719E7EBB5CAC650F72330D9C5BBE, DF3E5FFC10C409D80F35BFD0CD80E17E0980F1A0ED54959A526764E5553979D5 ] dKeySync        C:\dKEYUSBCradle\SyncService.exe
12:48:28.0953 0x195c  dKeySync - ok
12:48:28.0969 0x195c  [ EB70A894708D1BC176AFD690FF06085F, 0DD2A97F5E1B38D1F7C0D44E50F09EA222B18B3B074CC9C8CD25A7526CB1A112 ] dmvsc           C:\Windows\System32\drivers\dmvsc.sys
12:48:28.0969 0x195c  dmvsc - ok
12:48:29.0018 0x195c  [ D9F407D006C916B7EC167858F88F13EB, 0D0FF69F9C695A2371DF798429EA2AA7B96F1C552EDC70DA4DD61EC8BD5563A3 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
12:48:29.0031 0x195c  Dnscache - ok
12:48:29.0064 0x195c  [ 811EACBCC7C51A03AE11F13CC27B2AB6, FAB94F84950FFB7D3649BAFB8D96D43B880D7FDE8D5B879472AE26C4BC4203B0 ] dot3svc         C:\Windows\System32\dot3svc.dll
12:48:29.0064 0x195c  dot3svc - ok
12:48:29.0094 0x195c  [ B99CB575986789A93A683DCF292A43A1, 6ACEA31C723B74003E106FC8303542FCC6DBC4952B6B523F6590D006BE57238D ] DPS             C:\Windows\system32\dps.dll
12:48:29.0094 0x195c  DPS - ok
12:48:29.0111 0x195c  [ 00C594D5A1DBD22AD8B2902B9F6EFF94, 2920D62B5F7C49A8AFA80FCAD1E834BBAA670AEBDD7E6F21F0496D1D3CCB4E90 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
12:48:29.0111 0x195c  drmkaud - ok
12:48:29.0140 0x195c  [ 263625A4F616538EB867B6306A6590DB, 2A064720C247EAA3446EFDCC9E01D84CBA875905D78DFED0FBD62D1EE422D416 ] DsmSvc          C:\Windows\System32\DeviceSetupManager.dll
12:48:29.0156 0x195c  DsmSvc - ok
12:48:29.0219 0x195c  [ 670E7F15CEEA22C34CED8F4D0EC161BF, CB3922F9B63C1C92798326C12FA5586081C3ED9EC87EA31BA992360773BA871D ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
12:48:29.0250 0x195c  DXGKrnl - ok
12:48:29.0298 0x195c  [ E253530BD5EDE28F1FF6AF93C4D8034D, 787A70C3E946348F066FB8EB81FCE60157217D93FD78ADC631B5835E8D76A253 ] Eaphost         C:\Windows\System32\eapsvc.dll
12:48:29.0298 0x195c  Eaphost - ok
12:48:29.0406 0x195c  [ 114BCFDF367FF37C3F1B0A96AF542E4D, D385BC1D91BC1406091C8C3691C07A90BD60EDE05B1384E5AA3506FCB909C857 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
12:48:29.0469 0x195c  ebdrv - ok
12:48:29.0844 0x195c  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] EFS             C:\Windows\System32\lsass.exe
12:48:29.0844 0x195c  EFS - ok
12:48:29.0875 0x195c  [ 43531A5993380CC5113242C29D265FD9, EE0076D96F7F3CF29884AC7A67C08A429115A7201354A1FB5DE45FD63ABB4960 ] EhStorClass     C:\Windows\system32\drivers\EhStorClass.sys
12:48:29.0875 0x195c  EhStorClass - ok
12:48:29.0922 0x195c  [ 6F8E738A9505A388B1157FDDE7B3101B, 3696CA634102B41EEA11EB9DCA0B24439D8636AED4A7190C138C5E64A2EFB514 ] EhStorTcgDrv    C:\Windows\system32\drivers\EhStorTcgDrv.sys
12:48:29.0922 0x195c  EhStorTcgDrv - ok
12:48:29.0938 0x195c  [ DFFFAE1442BA4076E18EED5E406FA0D3, 329FC6FB8D14BEACDBE2A5D4C496EDEA485E838B1DF27566E278F8F8E0D8E82E ] ErrDev          C:\Windows\System32\drivers\errdev.sys
12:48:29.0938 0x195c  ErrDev - ok
12:48:29.0970 0x195c  [ F00C593994D57C75273F820653440536, 2DC986D9890EC907405FB2045E6F55ACC384169B45F0B56CCB1A953CF71D9A5D ] EventSystem     C:\Windows\system32\es.dll
12:48:29.0984 0x195c  EventSystem - ok
12:48:30.0016 0x195c  [ 7729D294A555C7AEB281ED8E4D0E01E4, 7269E79D72CCE477AC108294D0DDFB59CF533B03C587599C5AB0507C43A0B6D4 ] exfat           C:\Windows\system32\drivers\exfat.sys
12:48:30.0016 0x195c  exfat - ok
12:48:30.0031 0x195c  [ 7C4E0D5900B2A1D11EDD626D6DDB937B, 732F310F8F6016C56F432A81636B13CE0124A802FE8DD91287B618EED22C9A1D ] fastfat         C:\Windows\system32\drivers\fastfat.sys
12:48:30.0031 0x195c  fastfat - ok
12:48:30.0079 0x195c  [ 304B6AEC4639A7CCCCF544C6BA6177B2, B75CDD52FD3890B3008E06C503945D1E36478F0EC5E067C8DBC2822D7935D24B ] Fax             C:\Windows\system32\fxssvc.exe
12:48:30.0094 0x195c  Fax - ok
12:48:30.0110 0x195c  [ 5D8402613E778B3BD45E687A8372710B, EE9EA10805168D309A609B9019AEC5961EE46D18207B5E0EA2DE4064A5770AF8 ] fdc             C:\Windows\System32\drivers\fdc.sys
12:48:30.0110 0x195c  fdc - ok
12:48:30.0125 0x195c  [ 020D2F29009F893ADEFF4405B4B44565, 9F8501064C72933D1442DA00E70392B30D0207EB7D60F50E6648FF363799E6F1 ] fdPHost         C:\Windows\system32\fdPHost.dll
12:48:30.0141 0x195c  fdPHost - ok
12:48:30.0156 0x195c  [ E80D2EDD2F88B6E20076A0A4F5A5A245, E3CD6E0BE152B22E8A7340EFFD10CCDB1B632CD3EDF487E83F697D2E22A7D594 ] FDResPub        C:\Windows\system32\fdrespub.dll
12:48:30.0156 0x195c  FDResPub - ok
12:48:30.0174 0x195c  [ 47AB7D16EDE434B934AA4D661456C2D5, D375A92FB3E4BB0A8DA5270DACC888E53FB9F514516039FE6DAE4D4EF6B9A970 ] fhsvc           C:\Windows\system32\fhsvc.dll
12:48:30.0174 0x195c  fhsvc - ok
12:48:30.0188 0x195c  [ BCFD8B149B3ADF92D0DB1E909CAF0265, 002B085C131473642450176B4B8359F3E5B04350AFB659B9C0F9EB587D1181E7 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
12:48:30.0188 0x195c  FileInfo - ok
12:48:30.0203 0x195c  [ A1A66C4FDAFD6B0289523232AFB7D8AF, 0F5832F626BB62190D5F3A088CE6E048D8A400CCF9EA527F06973CAD96D3A81C ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
12:48:30.0203 0x195c  Filetrace - ok
12:48:30.0203 0x195c  [ BE743083CF7063C486A4398E3AEFE59A, 85796D89943DD6FE3932C1ED6CF01470C1B4DFD243C390B07055FFDA3C231551 ] flpydisk        C:\Windows\System32\drivers\flpydisk.sys
12:48:30.0219 0x195c  flpydisk - ok
12:48:30.0235 0x195c  [ C1FB505A73FA2E9019D32444AB33B75A, 765F0635C18295855CA4C0394192E8B94BA2EA1C4D74F86B720358ABA019FFAA ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
12:48:30.0250 0x195c  FltMgr - ok
12:48:30.0328 0x195c  [ 223CD19D2F84B7B42081F4FB530B658F, 4A9D1A6688C3C8F0B866B0FE2715C9FBA62BE66D4ADCC327A8CABF9EA876A664 ] FontCache       C:\Windows\system32\FntCache.dll
12:48:30.0344 0x195c  FontCache - ok
12:48:30.0438 0x195c  [ 1C52387BF5A127F5F3BFB31288F30D93, 90D13F60170CD74304F3036A90D596AA3E1E134455A780310BDF67AC7815F2E7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
12:48:30.0438 0x195c  FontCache3.0.0.0 - ok
12:48:30.0454 0x195c  [ A7C31B168F371E8E6796219F23E354DB, C51C9BF568F1E96CBBE57D2432B38F93F40520086DDB6AAAAC48CBCD1691B441 ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
12:48:30.0454 0x195c  FsDepends - ok
12:48:30.0469 0x195c  [ 09F460AFEDCA03F3BF6E07D1CCC9AC42, B832091BC9B2C2FE38A4BCA132ABB58251E851F21EC6F39636E73777AB9A5791 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
12:48:30.0469 0x195c  Fs_Rec - ok
12:48:30.0516 0x195c  [ 9540C57068902DAA6F272D70E922C090, D02FF8E9CF717291B1A6744A563822E4A1D8C9E0FB65CF5C986EE46F73DD9B2B ] ftnlsv3hv       C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnlsv.exe
12:48:30.0516 0x195c  ftnlsv3hv - ok
12:48:30.0734 0x195c  [ AFC4552FB7F8A1C04FA0EE57A78933FC, D503C34B56247A42AD4A12F730358F770437C2594B3BBC1EC7EB4B0E1576E4BF ] ftscanmgr       C:\Program Files (x86)\VMware\ScannerRedirection\ftscanmgr.exe
12:48:30.0844 0x195c  ftscanmgr - ok
12:48:31.0313 0x195c  [ D4AB6EE3D715BC44C00277FD934FAACF, DE8A8B14D7BA73BA1B5A833DE193CA65EDFE512A57D84F4F2CE19D9646D97F4E ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
12:48:31.0328 0x195c  fvevol - ok
12:48:31.0344 0x195c  [ 9591D0B9351ED489EAFD9D1CE52A8015, AC64C236C3AE545FCE8ED44A4A87FB86265A453BA60026EC9A4DE2B631E99996 ] FxPPM           C:\Windows\System32\drivers\fxppm.sys
12:48:31.0344 0x195c  FxPPM - ok
12:48:31.0391 0x195c  [ FC3EF65EE20D39F8749C2218DBA681CA, 12980F1DE99B25E6920A33556F3ABDA5EC9BFE4757BE602130B5E939D8D25CE3 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
12:48:31.0391 0x195c  gagp30kx - ok
12:48:31.0422 0x195c  [ 0BF5CAD281E25F1418E5B8875DC5ADD1, 0929AD8437DD78234553D8B2CDF0D6838FD54ACDE1918AFEBE48684EB32A07A3 ] gencounter      C:\Windows\System32\drivers\vmgencounter.sys
12:48:31.0422 0x195c  gencounter - ok
12:48:31.0438 0x195c  [ 8DF1254093B5C354CE725EB6B9B0DE19, DE6C5661CC076DA44B8A5D044FDB7280EDCF38D322A98C14FDC82E25586B3014 ] GPIOClx0101     C:\Windows\system32\Drivers\msgpioclx.sys
12:48:31.0438 0x195c  GPIOClx0101 - ok
12:48:31.0516 0x195c  [ 2DAFF4F76A90E3C523C2FE50338537E9, 625745E538208B50E8F5A9A2C09C6CD03D51E424BB16BC6C5B156CBC25373B6D ] gpsvc           C:\Windows\System32\gpsvc.dll
12:48:31.0547 0x195c  gpsvc - ok
12:48:31.0611 0x195c  [ 0545A3EB959CFA4790D267BFB8C1ACA4, 69061E33ACB7587D773D05000390F9101F71DFD6EED7973B551594EAF3F04193 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:48:31.0611 0x195c  gupdate - ok
12:48:31.0627 0x195c  [ 0545A3EB959CFA4790D267BFB8C1ACA4, 69061E33ACB7587D773D05000390F9101F71DFD6EED7973B551594EAF3F04193 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
12:48:31.0627 0x195c  gupdatem - ok
12:48:31.0656 0x195c  [ FA4AC219AA758EA46D7148059BB9D36E, 120066DB008F6258BE314C9CBBA8A4D18E21FA35B83FC5428E9BE7BE5A6C3FA2 ] hcmon           C:\Windows\system32\drivers\hcmon.sys
12:48:31.0656 0x195c  hcmon - ok
12:48:31.0703 0x195c  [ 56F69F7C25FB67C970997D7066DBC593, 83E03A82237DCC5BCB3E722ACECACEF3510CAA619F33E0D7C4D902A482E90418 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:48:31.0703 0x195c  HdAudAddService - ok
12:48:31.0734 0x195c  [ D4B7ED39C7900384D9E5C1283F1E7926, F93F98858067B40F1C071EAD0F8E85442A78B95342BC692AF4D726540634923F ] HDAudBus        C:\Windows\System32\drivers\HDAudBus.sys
12:48:31.0734 0x195c  HDAudBus - ok
12:48:31.0750 0x195c  [ 10A70BC1871CD955D85CD88372724906, 2480A74854D0A89FF028EE9BA41224D4B2F9B0863066BFC43097920794FEE08D ] HidBatt         C:\Windows\System32\drivers\HidBatt.sys
12:48:31.0750 0x195c  HidBatt - ok
12:48:31.0781 0x195c  [ 42F88B57CAE42FC10059C887B3FCFCEA, 9363AA2B8E839A6935A7C6A36C491938DF78024886DCCE6D29CB18E1D6A6D806 ] HidBth          C:\Windows\System32\drivers\hidbth.sys
12:48:31.0781 0x195c  HidBth - ok
12:48:31.0781 0x195c  [ C241A8BAFBBFC90176EA0F5240EACC17, 571E20B87818618BE9179986177D55739A240F04D1F740B3C1B7809B9427B767 ] hidi2c          C:\Windows\System32\drivers\hidi2c.sys
12:48:31.0781 0x195c  hidi2c - ok
12:48:31.0813 0x195c  [ 9BDDEE26255421017E161CCB9D5EDA95, B766FD5E31708F29384F69418FC33C4BCC6E3064AA553D5B1D30EE0B8B1BFB40 ] HidIr           C:\Windows\System32\drivers\hidir.sys
12:48:31.0813 0x195c  HidIr - ok
12:48:31.0845 0x195c  [ EA85B5093DF7B5C3E80362B053740AE2, 1D4251385402A2ADEE8FA1642F54180304F88337DA74989BDE44025ABB145FE5 ] hidserv         C:\Windows\system32\hidserv.dll
12:48:31.0845 0x195c  hidserv - ok
12:48:31.0876 0x195c  [ 49676FEC898AB2A11B157F848269A56E, 011E6DDEF9570212520F92FEFD205E1F8104F198B57C40D11BE857FCBCC5F68D ] HidUsb          C:\Windows\System32\drivers\hidusb.sys
12:48:31.0876 0x195c  HidUsb - ok
12:48:31.0891 0x195c  [ 93C4315F47F8D635C6DB0DF49FCE10EE, 70C52B8927D54ACD23F27948780B522974250FD5CD81AA9801C3F158C402889F ] hkmsvc          C:\Windows\system32\kmsvc.dll
12:48:31.0891 0x195c  hkmsvc - ok
12:48:32.0297 0x195c  [ AC49522ED106BD4B545D6614D71C2445, 40BD738A301170378ECFC031635EB04E2F812B676376CADDD6607ECABEC9255F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:48:32.0297 0x195c  HomeGroupListener - ok
12:48:32.0344 0x195c  [ 99932E30CE0283B73BB6E5019E150394, 1F88C2F56A7B8E1F75E6359281F418F9661DA4FB7B7D7B14FA7F718B15D4DCE0 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:48:32.0360 0x195c  HomeGroupProvider - ok
12:48:32.0360 0x195c  [ A6AACEA4C785789BDA5912AD1FEDA80D, D197012A5DA6AB3F76FF298336DF0CF027C07ECC71267BAEF5912DE12893E096 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
12:48:32.0375 0x195c  HpSAMD - ok
12:48:32.0407 0x195c  [ 0821D9404151398E43B794828DFBFB07, 43845FBB96D839BE26196DD49644BA8CF1C111365022EB55CD34F57DE6030E74 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
12:48:32.0438 0x195c  HTTP - ok
12:48:32.0485 0x195c  [ 90656C0B3864804B090434EFC582404F, BDB60050B729AACB9E009AC7129BEBD6298BBD8A9DB14B817D02E8E13669BD6E ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
12:48:32.0485 0x195c  hwpolicy - ok
12:48:32.0500 0x195c  [ 6D6F9E3BF0484967E52F7E846BFF1CA1, C982966BDE6A3E6773D9441ADA7A3B08D13511DFC68D04DF303248B942423F38 ] hyperkbd        C:\Windows\System32\drivers\hyperkbd.sys
12:48:32.0500 0x195c  hyperkbd - ok
12:48:32.0500 0x195c  [ 907C870F8C31F8DDD6F090857B46AB25, 308664A31717383D06185875E76C6612407A9F04E7DB28404F574A5706C6715D ] HyperVideo      C:\Windows\system32\DRIVERS\HyperVideo.sys
12:48:32.0516 0x195c  HyperVideo - ok
12:48:32.0532 0x195c  [ 49EE0AE9E5B64FFBBD06D55C4984B598, 8866627F9241B24A59C81D8BCC67A4DCA87576F589599BA291D0E323F679EB4D ] i8042prt        C:\Windows\System32\drivers\i8042prt.sys
12:48:32.0532 0x195c  i8042prt - ok
12:48:32.0563 0x195c  [ 5D90E32E36CE5D4C535D17CE08AEAF05, 976A463343E8C8308AFBE9E64DF56C430D2241DE002430D00318AB065EB72E4A ] iaLPSSi_GPIO    C:\Windows\System32\drivers\iaLPSSi_GPIO.sys
12:48:32.0563 0x195c  iaLPSSi_GPIO - ok
12:48:32.0580 0x195c  [ DD05E7E80F52ADE9AEB292819920F32C, E71AB6A50B0F90C8F94569CE89F66F915A0A4A00D4AC091B2E5E750D88CFC334 ] iaLPSSi_I2C     C:\Windows\System32\drivers\iaLPSSi_I2C.sys
12:48:32.0580 0x195c  iaLPSSi_I2C - ok
12:48:32.0610 0x195c  [ 08BFE413B0B4AA8DFA4B5684CE06D3DC, 95DEEBB203E12EE6E191F5247A74C04AEC0E16DE981FADDC4D6C42EE41D8D079 ] iaStorAV        C:\Windows\system32\drivers\iaStorAV.sys
12:48:32.0627 0x195c  iaStorAV - ok
12:48:32.0799 0x195c  [ A2200C3033FA4EF249FC096A7A7D02A2, 5819F5C2020DE2EEE339B0C08CD4B1E3490EAFBBEA1277CE649DB5A5150986B0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
12:48:32.0813 0x195c  iaStorV - ok
12:48:32.0813 0x195c  IEEtwCollectorService - ok
12:48:32.0875 0x195c  [ 02211401EFFC4965C014C8F9696539A2, 4C58DA5FF219B25B84A0C351436F07F13FCACEDFECDD7BCC91DE129F11FE36A8 ] IKEEXT          C:\Windows\System32\ikeext.dll
12:48:32.0891 0x195c  IKEEXT - ok
12:48:32.0908 0x195c  [ 4E448FCFFD00E8D657CD9E48D3E47157, 4A958CF0BF8DAEAE5E008500BA67CE89B21388592811274331EE39CAC1043A00 ] intelide        C:\Windows\system32\drivers\intelide.sys
12:48:32.0908 0x195c  intelide - ok
12:48:32.0923 0x195c  [ A770340FC02B999EF0DE6C2A6BC8437C, 214567BE706B21BEA7EC13AF6B10FBFF658000511DBBA79BAA28D1D4EFD029A7 ] intelpep        C:\Windows\system32\drivers\intelpep.sys
12:48:32.0923 0x195c  intelpep - ok
12:48:32.0938 0x195c  [ 47E74A8E53C7C24DCE38311E1451C1D9, 79B06E37A552C8A847404D4C572CDB8CF525354D8AE3BEBC06892B7C3B330761 ] intelppm        C:\Windows\System32\drivers\intelppm.sys
12:48:32.0938 0x195c  intelppm - ok
12:48:32.0954 0x195c  [ 9DB76D7F9E4E53EFE5DD8C53DE837514, 07BA4EDA9BE9139A689A2C3EFC1D1A4F3D1216625ED145F313398292A2CD5703 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:48:32.0969 0x195c  IpFilterDriver - ok
12:48:33.0036 0x195c  [ B452623C1DE60544054E784D94A7AA47, 57AECDEE0AB2B80DFFE11E43608988D46E9169288CB56D644DDE2CAFED6AFD40 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
12:48:33.0052 0x195c  iphlpsvc - ok
12:48:33.0084 0x195c  [ C800DCD904016B2BF6AB541083770A3A, 95A8FB9AB2818A4F44AFCBF2715B0B3024DCE38E1406EA639F2A5ECA105D2290 ] IPMIDRV         C:\Windows\System32\drivers\IPMIDrv.sys
12:48:33.0084 0x195c  IPMIDRV - ok
12:48:33.0116 0x195c  [ B7342B3C58E91107F6E946A93D9D4EFD, D5DA3C02C5C5A343785745EF6983CC9B5FBD3FB8D49FE9B450523E50212D1A32 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
12:48:33.0116 0x195c  IPNAT - ok
12:48:33.0208 0x195c  [ 97C9EBB84A761D48DC17E0E6B913C164, D195A8410E1FEED1A0EE9C5F5AF6F5FC861284765A38D460D496CE1048501905 ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
12:48:33.0208 0x195c  iPod Service - ok
12:48:33.0225 0x195c  [ AE44C526AB5F8A487D941CEB57B10C97, A783A2EAF7A6FF450FB3F189A5930036FA60D125C42171AC44B6FE2E3DBD6F7A ] IRENUM          C:\Windows\system32\drivers\irenum.sys
12:48:33.0225 0x195c  IRENUM - ok
12:48:33.0255 0x195c  [ 8AFEEA3955AA43616A60F133B1D25F21, E99359A4F1D653790133F145CF7C9F97399FD75C5E135AA7E5F989BB660789AF ] isapnp          C:\Windows\system32\drivers\isapnp.sys
12:48:33.0255 0x195c  isapnp - ok
12:48:33.0303 0x195c  [ C378ED678D1316721A40E1F60FB76184, 972900D99BBC02BA3FD664DAE36EFF7D25286912C7DDFD443C8CB37D997D304F ] iScsiPrt        C:\Windows\System32\drivers\msiscsi.sys
12:48:33.0303 0x195c  iScsiPrt - ok
12:48:33.0335 0x195c  [ 5917AFE4A3F695A54B99C1849C8207FE, DD57638966F2F0387DCF9DA4BBAEE3CDD8CC6F1A2D49581A0374D46A565BED4F ] kbdclass        C:\Windows\System32\drivers\kbdclass.sys
12:48:33.0335 0x195c  kbdclass - ok
12:48:33.0349 0x195c  [ 8CD840A062F6BDF41DDE3ACB96164B72, AEAE867F3557C1CE6B931E19D7144A3BD3CBABD81B1542667680D54FC24DEBE1 ] kbdhid          C:\Windows\System32\drivers\kbdhid.sys
12:48:33.0349 0x195c  kbdhid - ok
12:48:33.0364 0x195c  [ 813871C7D402A05F2E3A7075F9584A05, FF0C2F87EB083F8CE74C679D80C845CDFBFBBC70BE818F899F3336BBB54A3FFB ] kdnic           C:\Windows\system32\DRIVERS\kdnic.sys
12:48:33.0380 0x195c  kdnic - ok
12:48:33.0397 0x195c  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] KeyIso          C:\Windows\system32\lsass.exe
12:48:33.0397 0x195c  KeyIso - ok
12:48:33.0427 0x195c  [ 304DA394D958BC3B62AF6DF514005B01, 8D17777C82F034E800181E82D30FCED800CBC46CD659AE2E0D972CA1381BD4C2 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
12:48:33.0427 0x195c  KSecDD - ok
12:48:33.0458 0x195c  [ 3D4AE520CD6F6FFE549DD195C1F515BE, 2AD3E07F504CE50956C391FD4633D20B354A854C940B3563A67B79BB6E40218F ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
12:48:33.0474 0x195c  KSecPkg - ok
12:48:33.0489 0x195c  [ 11AFB527AA370B1DAFD5C36F35F6D45F, 757AD234284467ADB826F7CA0251F58D48866B91995BC867DEA4BAF676947163 ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
12:48:33.0489 0x195c  ksthunk - ok
12:48:33.0521 0x195c  [ C1591A66028C71147A3E2EAB0B1CCB7E, 82F3D5DCC1614398A144D9791E4BAA814DBA9112677341FD57D5E9834CEDEB41 ] KtmRm           C:\Windows\system32\msdtckrm.dll
12:48:33.0521 0x195c  KtmRm - ok
12:48:33.0553 0x195c  [ B75ADC97905F43C7C946F1465A8697BD, AF50E3F5DBF222DB095B40FD4896650B5F8DD47153CB9A1ADE54D17FCE85C529 ] LanmanServer    C:\Windows\system32\srvsvc.dll
12:48:33.0567 0x195c  LanmanServer - ok
12:48:33.0614 0x195c  [ 3DBD9100745F9B8506B8FEC6FE6CCDE3, C3EF2856A1680AFDE133887E48946CF9CAB6755C3BDC07F0326965DCD4096F62 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:48:33.0631 0x195c  LanmanWorkstation - ok
12:48:33.0677 0x195c  [ 8B9F3796EC1762CF255BDB324E5529C8, F73D6BEF19BE20AEB18DA82CB63E9D8B50ACBBE4ED9B646EF0C9F598F6B81F94 ] lfsvc           C:\Windows\System32\GeofenceMonitorService.dll
12:48:33.0692 0x195c  lfsvc - ok
12:48:33.0724 0x195c  [ C09010B3680860131631F53E8FE7BAD8, 35F2A06D5F29478D22ABDCC20DA893EF9D96504C65594A0CEA674D1C21B04FF8 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
12:48:33.0724 0x195c  lltdio - ok
12:48:33.0739 0x195c  [ DAE98CC96C5EE308BF4EA7B18F226CB8, 7A6CC56BF075010707715AB6608764291E358EDF27C806A025532869004C686B ] lltdsvc         C:\Windows\System32\lltdsvc.dll
12:48:33.0755 0x195c  lltdsvc - ok
12:48:33.0771 0x195c  [ 1E2662D847B7D9995C65D90D254A7E0F, AFD4063D2071FFCB6B0EAC0715276D986F42326919C86E525DCE12E1109A93E2 ] lmhosts         C:\Windows\System32\lmhsvc.dll
12:48:33.0786 0x195c  lmhosts - ok
12:48:33.0817 0x195c  [ C755AE4635457AA2A11F79C0DF857ABC, E03D1ACAC155287291FE1BD0B653953ADC94279A74D0152088D698FAA796460F ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
12:48:33.0817 0x195c  LSI_SAS - ok
12:48:33.0833 0x195c  [ ADAC09CBE7A2040B7F68B5E5C9A75141, 7865DA7E91404F3642BC444B97F6B7AA42B9523D5EDD7F6365DA236B8EC3410F ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
12:48:33.0833 0x195c  LSI_SAS2 - ok
12:48:33.0849 0x195c  [ 04D1274BB9BBCCF12BD12374002AA191, 4B9618F8D25F2278DE1610A70ACAADB074D171D162C3AF27D464F5DC800A8E60 ] LSI_SAS3        C:\Windows\system32\drivers\lsi_sas3.sys
12:48:33.0849 0x195c  LSI_SAS3 - ok
12:48:33.0880 0x195c  [ 327469EEF3833D0C584B7E88A76AEC0C, 3D88B5A2D68F93F01B39C6E3D8D5C7A2A20686EFC756086E66AFFF1BC3019B85 ] LSI_SSS         C:\Windows\system32\drivers\lsi_sss.sys
12:48:33.0880 0x195c  LSI_SSS - ok
12:48:33.0942 0x195c  [ 9A7A7E45DAED2E8C2816716D8D28236A, C94787988826E546A8DC752BD6BE4EA7423DC3762B2D371DB297A63F865A95FF ] LSM             C:\Windows\System32\lsm.dll
12:48:33.0958 0x195c  LSM - ok
12:48:33.0991 0x195c  [ B0AF753AF28303BB69C67BD85F06FFC9, 6B6805C17BC39F972BB7FF52BDF798B0B57EC5D5F3CE1C97415E86110235C603 ] luafv           C:\Windows\system32\drivers\luafv.sys
12:48:34.0021 0x195c  luafv - ok
12:48:34.0052 0x195c  [ EB5C03A070F30D64A6DF80E53B22F53F, 12051B6AEBDEE1E28F24364F25A52BA3A6E282ECF86D6290E34BD38E6D4E066D ] megasas         C:\Windows\system32\drivers\megasas.sys
12:48:34.0052 0x195c  megasas - ok
12:48:34.0099 0x195c  [ F6F13533196DE7A582D422B0241E4363, B3CD9B08937AFFF12141B38634AF3A56F5AC5FF3EF03941802B9841DEC559469 ] megasr          C:\Windows\system32\drivers\megasr.sys
12:48:34.0114 0x195c  megasr - ok
12:48:34.0146 0x195c  [ 4C5179DB61B9E14BEC15CDC4B152B2E9, 9048BEC7AD6A3F4B640E99B1F0365AC9A46740B188758FBB2C160EF30AD6E64B ] MMCSS           C:\Windows\system32\mmcss.dll
12:48:34.0146 0x195c  MMCSS - ok
12:48:34.0180 0x195c  [ 8B38C44F69259987C95135C9627E2378, E698B82D4EFFF56D66C7FC9866369BA5736FDBDBE2028CC421C51E70DEA74727 ] Modem           C:\Windows\system32\drivers\modem.sys
12:48:34.0180 0x195c  Modem - ok
12:48:34.0192 0x195c  [ 601589000CC90F0DF8DA2CC254A3CCC9, D1238A386C41B6C368D9A44B7C112C943995B5403E2A5B4B7346B266DDB0C5A0 ] monitor         C:\Windows\System32\drivers\monitor.sys
12:48:34.0192 0x195c  monitor - ok
12:48:34.0209 0x195c  [ 08374E4E5B8914DE6067CBA99F61E930, CBB1390D6523FC968BEDF78FD13699488621ACB2CD1DF55D1606316090548661 ] mouclass        C:\Windows\System32\drivers\mouclass.sys
12:48:34.0209 0x195c  mouclass - ok
12:48:34.0239 0x195c  [ 5FCBAB60598AE119E02B4C27DE6B99EA, 36F30094F700DE41C293047ACB49ED1961DD927BEDAD8DFDAB7023D4D24CB0DE ] mouhid          C:\Windows\System32\drivers\mouhid.sys
12:48:34.0239 0x195c  mouhid - ok
12:48:34.0271 0x195c  [ E5E8665272EBCD87A0A632314F0D221D, 37FDC4CEB8E5FC39C10DE875676863D090CFEA708AC3A8415114DCDD94BD7A1D ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
12:48:34.0287 0x195c  mountmgr - ok
12:48:34.0317 0x195c  [ 30813D30C0F03BB6D2B584C665C83F25, F341D30E503F18CA36041F05C8613AB88FF84CD0710CB5AF081F2F07F76FE8F5 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
12:48:34.0317 0x195c  MozillaMaintenance - ok
12:48:34.0444 0x195c  [ BF2513029E231BE96D82F7C3ABFF87F4, F6DB64112CC50EEE495E2D7C61B8BDBE757A31B03144B0396615FD38C312824E ] MpKsl7c336dd6   C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{C1DA5E0C-8913-470D-AB12-BE37D6456C7B}\MpKsl7c336dd6.sys
12:48:34.0444 0x195c  MpKsl7c336dd6 - ok
12:48:34.0474 0x195c  [ 6FC047578785B0435F4E2660946D1ADC, 8AEA5659F01FC2F75160922C69622502DABA39F33CB90D5178DD679A1CDE617D ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
12:48:34.0474 0x195c  mpsdrv - ok
12:48:34.0505 0x195c  [ D1418745A5472F3930A288E05B9E2C05, 95785F0FA7EE239459C0288DB37E9E54648029FD6FE45A61E6343526D67FFA32 ] MpsSvc          C:\Windows\system32\mpssvc.dll
12:48:34.0521 0x195c  MpsSvc - ok
12:48:34.0567 0x195c  [ 3F818C1518DA702C8F10259095C9BDE0, B98C1A6F9A3C01A10503B2B2C45CC89AFF17B346B15990F4DB4820F68BDC62C8 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
12:48:34.0567 0x195c  MRxDAV - ok
12:48:34.0599 0x195c  [ E2FC654EC895E92A022794329BFC53EC, BDEFF410B8A1D213B652A86DBF53774A3EBD58C32CCB9180712F9F3777307688 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
12:48:34.0614 0x195c  mrxsmb - ok
12:48:34.0646 0x195c  [ AFE6DC2E57E876175BA074AD2CB5594F, 004873302BA0BF1B1359A90A5399915BE00A9ED800F60E477A5AE4682C70A708 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:48:34.0678 0x195c  mrxsmb10 - ok
12:48:34.0724 0x195c  [ B37B58F9F80A51098C42663D5FA5F2BA, 996E2D8344F0095C136D1670D63A476E6B6F6BBA9DD773EEE5F0FD580562B000 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:48:34.0739 0x195c  mrxsmb20 - ok
12:48:34.0739 0x195c  [ F3C060444777A59FC63D920719E43CCD, 8766A2746E3DFB0749E902F458141269335CA6F0CEDCA3D5F8C204637C19E783 ] MsBridge        C:\Windows\system32\DRIVERS\bridge.sys
12:48:34.0755 0x195c  MsBridge - ok
12:48:34.0771 0x195c  [ 915747E010A9414B069173284A9B93F4, 8A335C28FE1EF96DD71485877F2E86155D24B5614ACE05468F4B07E2ACD56331 ] MSDTC           C:\Windows\System32\msdtc.exe
12:48:34.0786 0x195c  MSDTC - ok
12:48:34.0817 0x195c  [ D13329FBF8345B28AB30F44CC247DC08, 9C7EC2D4D65E6510EB5B9E61BB0D14F725D7E8FE98D65161C3971E43EF1AB6EB ] Msfs            C:\Windows\system32\drivers\Msfs.sys
12:48:34.0817 0x195c  Msfs - ok
12:48:34.0849 0x195c  [ C6B474E46F9E543B875981ED3FFE6ADD, E16687E52FB649C23D92159A1F036CB662202C1E58D961EECDAA528AA4FA669A ] msgpiowin32     C:\Windows\System32\drivers\msgpiowin32.sys
12:48:34.0849 0x195c  msgpiowin32 - ok
12:48:34.0866 0x195c  [ 65C92EB9D08DB5C69F28C7FFD4E84E31, D709BA4723225321F665B1157A33A4AE230420752308EF535DA9A41CAC164628 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
12:48:34.0866 0x195c  mshidkmdf - ok
12:48:34.0880 0x195c  [ 52299F086AC2DAFD100DD5DC4A8614BA, B36BE0FC96798E5EB8C193C318970E3906961E3ABC3BFAAD73138C76D9A95B0B ] mshidumdf       C:\Windows\System32\drivers\mshidumdf.sys
12:48:34.0880 0x195c  mshidumdf - ok
12:48:34.0896 0x195c  [ 36D92AF3343C3A3E57FEF11C449AEA4C, ECC85AA1E530DF55B4A4545798219F87F0FCA66DDD2E37BCEF0850D3C9129DD2 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
12:48:34.0896 0x195c  msisadrv - ok
12:48:34.0929 0x195c  [ A06142B3850B06972F1C89748FAA2C02, B1CCC5C8D100FEB384FCC85FED2A77F47DA4C9BA5F6889A130F4D73E30ACAA78 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
12:48:34.0942 0x195c  MSiSCSI - ok
12:48:34.0942 0x195c  msiserver - ok
12:48:34.0959 0x195c  [ A9BBBD2BAE6142253B9195E949AC2E8D, 599D2952D4E0B0B3E02D91E38A30F4900B1ADA330716B887B156A1CB9A3E6EE9 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
12:48:34.0959 0x195c  MSKSSRV - ok
12:48:34.0974 0x195c  [ 51B3AC0560848CD6D65AC2033E293113, 73A27E88774C6929328E6C9FC9C389F4DF76D4D4D5CBFC4F51651CC308829628 ] MsLldp          C:\Windows\system32\DRIVERS\mslldp.sys
12:48:34.0974 0x195c  MsLldp - ok
12:48:34.0989 0x195c  [ 7B2128EB875DCBC006E6A913211006D6, 97BBD7FF770741FBFC0F181A609AD0954EA926DA203B742E8F08C89AD8FE476E ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
12:48:34.0989 0x195c  MSPCLOCK - ok
12:48:35.0005 0x195c  [ 1E88171579B218115C7A772F8DE04BD8, B9EAA835D0BF8F9C4DF8403D95EF1400E8AE38F28F9DBA87657DE2129FEF02D2 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
12:48:35.0005 0x195c  MSPQM - ok
12:48:35.0039 0x195c  [ BBE2A455053E63BECBF42C2F9B21FAE0, 7C5DF563499DF59DF9895A1581E47ADF5FD54C94ECEF6C886CDB60E5E95A6DAE ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
12:48:35.0053 0x195c  MsRPC - ok
12:48:35.0068 0x195c  [ 8D6B7D515C5CBCDB75B928A0B73C3C5E, 1EB4DC3DD21D2627C78EC3F9931D9E5D033169087E43B5D7C17BF1FF2A0028CD ] mssmbios        C:\Windows\System32\drivers\mssmbios.sys
12:48:35.0083 0x195c  mssmbios - ok
12:48:35.0083 0x195c  [ 115019AE01E0EB9C048530D2928AB4A2, 6E2275E85EACF2D0FC784792E0D72A165589D33CBAB3BCFA8E271CA09566C925 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
12:48:35.0083 0x195c  MSTEE - ok
12:48:35.0099 0x195c  [ 96D604A35070360F0DD4A7A8AF410B5E, F94DD1A3566C7C8D0A76D6E1E2530552A9B7F99C5DA0DE11829325EAB9F8B7ED ] MTConfig        C:\Windows\System32\drivers\MTConfig.sys
12:48:35.0099 0x195c  MTConfig - ok
12:48:35.0132 0x195c  [ 438EA7A2D8D4F9B8AFB64748ACA70BA8, AEEB7B657B645C4006C6D5E8D07ECE581DEE7AD22EA1A587C552574990CF091B ] Mup             C:\Windows\system32\Drivers\mup.sys
12:48:35.0132 0x195c  Mup - ok
12:48:35.0161 0x195c  [ B8C35C94DCB2DFEAF03BB42131F2F77F, F0FCF367CA8F722D6ABCF7F363CD406D890D71452E91C3FC6677B47AD74D6324 ] mvumis          C:\Windows\system32\drivers\mvumis.sys
12:48:35.0161 0x195c  mvumis - ok
12:48:35.0194 0x195c  [ 8DF30698BDD9492A9D45A4B94FB4A82A, 26B1B2D7E785E29B8BCB74C467C66AE4EBDD481ACFF36334F3BDF4506B778244 ] napagent        C:\Windows\system32\qagentRT.dll
12:48:35.0210 0x195c  napagent - ok
12:48:35.0239 0x195c  [ BB78990894F14D725EBD301E1945BF0F, 88B2A23F65E6C3A97B5D00E20D5A64C227BB50063C23561713C2AF9525DC3E44 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
12:48:35.0271 0x195c  NativeWifiP - ok
12:48:35.0333 0x195c  [ BFCE1225D10619029E68946929CEB64C, 499F560331FFBA82E3D673B47F027FDAB7BEE4F2CB5B811D69E0218839F6E6A5 ] NcaSvc          C:\Windows\System32\ncasvc.dll
12:48:35.0333 0x195c  NcaSvc - ok
12:48:35.0364 0x195c  [ 267C97373110B7AFD3B46DF60B6CBB85, CEBB99F71D47634BB9C04DF2836DF6B47F15B3073FEFC237F85526DF01E4E38B ] NcbService      C:\Windows\System32\ncbservice.dll
12:48:35.0364 0x195c  NcbService - ok
12:48:35.0380 0x195c  [ 0813B71EAF097208DC76CE0605B48AF0, A93A2E6A8FB77B58AC4D580E6F8BF307A25BADC9493994F9BE235EBFB0E1DB22 ] NcdAutoSetup    C:\Windows\System32\NcdAutoSetup.dll
12:48:35.0396 0x195c  NcdAutoSetup - ok
12:48:35.0444 0x195c  [ FFAA6C6E798FBA448FA7628A1B277F5C, 9E1F2C848A019CE6397F652A21AE43B76149EF95452BB8353249BD9E28D98083 ] NDIS            C:\Windows\system32\drivers\ndis.sys
12:48:35.0474 0x195c  NDIS - ok
12:48:35.0489 0x195c  [ 8CECC8DA55F3274181FD1EA28AD76664, 188112424CEF97FB926A0FB915260B803555A775DD2E1846725A9C8616300F42 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
12:48:35.0489 0x195c  NdisCap - ok
12:48:35.0505 0x195c  [ 269882812E9A68FFF1AFE1283D428322, 50B99EBC42DA9B46A8C2C28C9BADCF58AE3079535CDD1227D0F5C86291C715FF ] NdisImPlatform  C:\Windows\system32\DRIVERS\NdisImPlatform.sys
12:48:35.0505 0x195c  NdisImPlatform - ok
12:48:35.0552 0x195c  [ 82821F4EEC776B4CF11695A38F3ABA46, 23184F9D31E662855DC4D23EFE7C2FE00E5487D3762B6024704A5D8C87762E1C ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
12:48:35.0552 0x195c  NdisTapi - ok
12:48:35.0569 0x195c  [ B832B35055BA2B7B4181861FF94D8E59, 2E60E5D503E88D27E35ECFEE265D51328E93A9C7B9B931F86D9CBC947636BB00 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
12:48:35.0569 0x195c  Ndisuio - ok
12:48:35.0583 0x195c  [ 1F58E48EF75F34C35D8E93A0DC535CFE, D65619A6C4B1747F8B05DA08A44EF0E46B5CC384880E04E4755A2BA6CDB3C4EA ] NdisVirtualBus  C:\Windows\System32\drivers\NdisVirtualBus.sys
12:48:35.0583 0x195c  NdisVirtualBus - ok
12:48:35.0630 0x195c  [ C3755FCF9A0B5C6FE8ED9E873B85D3CE, 4D3DAFAFA5FB2930522D6DA536E3A731BABE0C24613C190D2330DB415D1A6515 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
12:48:35.0630 0x195c  NdisWan - ok
12:48:35.0646 0x195c  [ C3755FCF9A0B5C6FE8ED9E873B85D3CE, 4D3DAFAFA5FB2930522D6DA536E3A731BABE0C24613C190D2330DB415D1A6515 ] NdisWanLegacy   C:\Windows\system32\DRIVERS\ndiswan.sys
12:48:35.0646 0x195c  NdisWanLegacy - ok
12:48:35.0693 0x195c  [ DDD7F92A83F74D1476B71FBA9530A8DC, D3F94FC9F48854E09B0B77CE5E1C1DB948D54EAC63C5583437051BB893B5A386 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
12:48:35.0708 0x195c  NDProxy - ok
12:48:35.0740 0x195c  [ 3083926D1CC5B56EA0786527B557DD1B, 3C3F0CA0D43398576DBE8F677B353ADDA7E8F56829874958CE668E31261C1590 ] Ndu             C:\Windows\system32\drivers\Ndu.sys
12:48:35.0740 0x195c  Ndu - ok
12:48:35.0755 0x195c  [ 42FF4975D032CAE558AE4BB8448F6E5A, 0B8FACF3382443DED79A8004A6AA14C32471A6A1C6BAA543AA9F3FEC52620A6D ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
12:48:35.0771 0x195c  NetBIOS - ok
12:48:35.0802 0x195c  [ 0FE750800DEEE91D22399D081371BA79, 7E1E01A5D5BAE68F975070D1676BD830ADF010E42A8046D4074D17B710230CD9 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
12:48:35.0849 0x195c  NetBT - ok
12:48:35.0898 0x195c  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] Netlogon        C:\Windows\system32\lsass.exe
12:48:35.0898 0x195c  Netlogon - ok
12:48:35.0927 0x195c  [ 8F074B62E66B6117D9598C62A12069C5, 5FDB19045D3E2F6D0F0C5158AC2ECB0D5404CD2AF7A319755D7E3753CA3B7CF3 ] Netman          C:\Windows\System32\netman.dll
12:48:35.0942 0x195c  Netman - ok
12:48:35.0975 0x195c  [ 4A04B1CD5BFB4A978C5F60E86D6C3E45, A946922C1C38ADD3CF9D3B09DDCC301AE4DAC960A081B2F42B32BE1E7095B3FD ] netprofm        C:\Windows\System32\netprofmsvc.dll
12:48:35.0989 0x195c  netprofm - ok
12:48:36.0021 0x195c  [ 10D5997E2F5F16FE3BC3BD1A4BF31EA8, 0DDC4855C00A581A35AB2A11D2AAACC844C460F13F524DD9B92B8F00C31173A7 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
12:48:36.0037 0x195c  NetTcpPortSharing - ok
12:48:36.0052 0x195c  [ D4DCE03870314D3354F3501F9DDD4123, 5BFE8299B3F72B8C39A4965365CBF5BA151024451F02DD872FAD1CC35CF94CEA ] netvsc          C:\Windows\System32\drivers\netvsc63.sys
12:48:36.0068 0x195c  netvsc - ok
12:48:36.0083 0x195c  [ E94EB2A95D7D016E119C4D6868788831, 3E4A925D23262FBA0A6432DD635FBE94B0CEF76BD9BB323254B66977497FEE2A ] NlaSvc          C:\Windows\System32\nlasvc.dll
12:48:36.0099 0x195c  NlaSvc - ok
12:48:36.0115 0x195c  [ 8F44A2F57C9F1A19AC9C6288C10FB351, 310274DDBAC0FE4BE54ECD3B90C97D82A0F9F5CFCA7A35711A36164DE4B94074 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
12:48:36.0115 0x195c  Npfs - ok
12:48:36.0130 0x195c  [ CBDB4F0871C88DF930FC0E8588CA67FC, 7E4AA3EA81A9D532F236FD7896744F07ED07CA9B37A9F18A9778BCCCC67490F2 ] npsvctrig       C:\Windows\System32\drivers\npsvctrig.sys
12:48:36.0146 0x195c  npsvctrig - ok
12:48:36.0162 0x195c  [ 0F12A72A753CFD7FB0631EE8D08FE983, 860A96471F6CD90DDA9AB3A48E95CEAD826C87D2FA98A00EF91B61C44A4C8B82 ] nsi             C:\Windows\system32\nsisvc.dll
12:48:36.0162 0x195c  nsi - ok
12:48:36.0179 0x195c  [ 018510D88536798852DAE12F9BA6E138, C0D89C36F8737FD139CEA80BED65D1DB4248E667804645FF71C39BA92FEC4109 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
12:48:36.0224 0x195c  nsiproxy - ok
12:48:36.0287 0x195c  [ 9907FCC207E470F94B9DB6BD037E79C4, 03ACD858BB8388D263E99EE5ECC53D9FC9747869E01E821AB36AE53FDEFAC8F5 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
12:48:36.0318 0x195c  Ntfs - ok
12:48:36.0381 0x195c  [ EF1B290FC9F0E47CC0B537292BEE5904, DBC07BBC54EBC2D2E576B23A4CE116B3DA988577AD0D96CB7289A6748A60F9EA ] Null            C:\Windows\system32\drivers\Null.sys
12:48:36.0381 0x195c  Null - ok
12:48:36.0396 0x195c  [ BC6B5942AFF25EBAF62DE43C3807EDF8, CB0FA194084B8C309039D571B5760FDA800E9531B8660C499B4F9977BA5C36D5 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
12:48:36.0396 0x195c  nvraid - ok
12:48:36.0434 0x195c  [ 1F43ABFFAC3D6CA356851D517392966E, 6FD7621F67BA94B0E1D8F43BEC2951DBCDEEA1E848BB265AC169E27C01DA68F2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
12:48:36.0443 0x195c  nvstor - ok
12:48:36.0443 0x195c  [ 6934A936A7369DFE37B7DBA93F5E5E49, 0900FEEB0CE8D09F0FC60630B5B986034A8BCD3882ED66E47170810C32492892 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
12:48:36.0458 0x195c  nv_agp - ok
12:48:36.0490 0x195c  [ 26657F3B4F39A0E64AF859278B599C4E, 3DD65E0BCEF3045DBA29FB8171CA3FCC9781AED3A1C7A160CF26388CE80A3683 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
12:48:36.0490 0x195c  p2pimsvc - ok
12:48:36.0521 0x195c  [ FD8F61F0D1F64BBB3D835F39A3F979C9, E5C5F86576488EA7F605E26C06EE5AFB36506A446F60C894D55E0A148BF7F02D ] p2psvc          C:\Windows\system32\p2psvc.dll
12:48:36.0537 0x195c  p2psvc - ok
12:48:36.0569 0x195c  [ 57DCE4FB0467986AE78E1C6FC5240D32, F7F3ADD1B48E4D6BB0A664A2FE556F71ED7453054B4FB667A29BE050C845045B ] Parport         C:\Windows\System32\drivers\parport.sys
12:48:36.0583 0x195c  Parport - ok
12:48:36.0583 0x195c  [ BAFF6122CFC9F95CA175AD8C348179A4, 079A912D951DF6A57BC1BDB0D182977EE9592751EC9DDCDA2932BDEDB333850C ] partmgr         C:\Windows\system32\drivers\partmgr.sys
12:48:36.0583 0x195c  partmgr - ok
12:48:36.0630 0x195c  [ C37AFACC6F809061A9CB5A8A863894F2, FA3E219AB631C2E9BD1E3E68E3D4F96768D1503951542D268DF66590BAC089AF ] PcaSvc          C:\Windows\System32\pcasvc.dll
12:48:36.0647 0x195c  PcaSvc - ok
12:48:36.0678 0x195c  [ 91ED124E261EA8FAA1C0FFDF2A71B0C4, 20E41A38067395D03184938983A9BE459717A1941352972DBC28D83D542319EC ] pci             C:\Windows\system32\drivers\pci.sys
12:48:36.0693 0x195c  pci - ok
12:48:36.0711 0x195c  [ 346E38FCC6859A727DD28AFAD1F0AFF4, FF3DA26F79B3BC3A5B8A8AA0B9139B9EF70297F4EA1203B1E68FB5A212C3AA58 ] pciide          C:\Windows\system32\drivers\pciide.sys
12:48:36.0711 0x195c  pciide - ok
12:48:36.0740 0x195c  [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397, 27A7AF2127B699F4579CB77936F38DC102211E26E5E2947DB808756FE06FC98E ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
12:48:36.0740 0x195c  pcmcia - ok
12:48:36.0755 0x195c  [ BF28771D1436C88BE1D297D3098B0F7D, 5F7630916A76A8CF31289E9C577F522B999C74C39E541CD40E62BD53004BEF74 ] pcw             C:\Windows\system32\drivers\pcw.sys
12:48:36.0755 0x195c  pcw - ok
12:48:36.0787 0x195c  [ E6B3ACBA06BAF48594557FCCBFA66FD2, 44A0FAC6169D9130870456DEFBFFE563FCCC4AD7A9754B455D5A1C1A77F0699D ] pdc             C:\Windows\system32\drivers\pdc.sys
12:48:36.0818 0x195c  pdc - ok
12:48:36.0849 0x195c  [ 0ECEE590F2E2EF969FB74A6FC583A1E6, 1C611D9225C863CF32125F684B324C58BDE1942F4F283F5674133200AC505D44 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
12:48:36.0865 0x195c  PEAUTH - ok
12:48:36.0928 0x195c  [ 8E3C640FFF5A963F570233AE99C0FFF3, 3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A ] PerfHost        C:\Windows\SysWow64\perfhost.exe
12:48:36.0928 0x195c  PerfHost - ok
12:48:36.0991 0x195c  [ 70B39E7241F750A248798CE82C44596D, 54A72199EB277EE586611DCBC21654786FD2196F91D5884C4F531297893CC3EC ] pla             C:\Windows\system32\pla.dll
12:48:37.0021 0x195c  pla - ok
12:48:37.0052 0x195c  [ 2C02AFF8383D893F8DBEB07A84F6E77C, 7CC34BAC67E2988E3D16DD6EB6F6785CD2460E3EF7FBD0BD5F86E49793BD473E ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
12:48:37.0052 0x195c  PlugPlay - ok
12:48:37.0068 0x195c  [ 4570F8A37D221660F3A09D6F4DD4BA94, 0EA190CFFA53DF9CCA2D53A4EF1BCB837BA3F2489A3AC5BD11F6D6ED811D118E ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
12:48:37.0068 0x195c  PNRPAutoReg - ok
12:48:37.0099 0x195c  [ 26657F3B4F39A0E64AF859278B599C4E, 3DD65E0BCEF3045DBA29FB8171CA3FCC9781AED3A1C7A160CF26388CE80A3683 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
12:48:37.0099 0x195c  PNRPsvc - ok
12:48:37.0132 0x195c  [ 0FF8507A8B901B904E98EB36B9E347EE, FE4A9A6159A8490F3155D166656748722EFDEDCDC447C09155A5AD6D9F5D294D ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
12:48:37.0146 0x195c  PolicyAgent - ok
12:48:37.0177 0x195c  [ C8DD82C3035E60D671B8CC5DF128D3A9, 6AABF632CBEDA9A7B553BC9134FF100CB6FDC88000D499D2883408FCEDD97576 ] Power           C:\Windows\system32\umpo.dll
12:48:37.0177 0x195c  Power - ok
12:48:37.0318 0x195c  [ F6EA63145C20A23732AD2CA1EBA65FA1, 0DD1164D37C1500258E9CCCE458778A3DA196D9A65919B2672E3C88383068F52 ] PrintNotify     C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
12:48:37.0521 0x195c  PrintNotify - ok
12:48:37.0552 0x195c  [ ECD373F9571C745894367CC2635EA44F, E08B2A1017DAE1BF10B986DAFAD14BDE20D79703E0EF3A8C700A3753908C1392 ] Processor       C:\Windows\System32\drivers\processr.sys
12:48:37.0568 0x195c  Processor - ok
12:48:37.0601 0x195c  [ 6E409D818C6B342544EAE741B1422B85, B4ADFB7809FC42C432C984C3AC13FAFD1B7AD53BCC7FB16E86371DE4C829DD1A ] ProfSvc         C:\Windows\system32\profsvc.dll
12:48:37.0615 0x195c  ProfSvc - ok
12:48:37.0630 0x195c  [ FC0141B4A5AD6D637D883C1A89FC45C5, DCE8942C02EEDAE7A57707CA60CAC3A8CD6BA68E6571E405CA882D4DD6D69E43 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
12:48:37.0630 0x195c  Psched - ok
12:48:37.0661 0x195c  [ DAA9DEE0A5D5F238C4EE54C2C7FB67C5, 7EC8C603BD92699AC35BDCD294F13BEE90D5C2C195FD93A3F16928BFCF53CA93 ] QWAVE           C:\Windows\system32\qwave.dll
12:48:37.0678 0x195c  QWAVE - ok
12:48:37.0694 0x195c  [ 83868EB2924E6BC21A54337C65D614D1, 8D1BE01EBD190231153B867C32120DC8FBFBD32050448A778134D435D76A0B07 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
12:48:37.0694 0x195c  QWAVEdrv - ok
12:48:37.0708 0x195c  [ B337B1F1E82A83E20A1743E008E25C0F, A2E8AF041B4CAB78AEE28A2147A189FF0F9D2FCEFB167D60FBBA0A787A5A5BE7 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
12:48:37.0725 0x195c  RasAcd - ok
12:48:37.0756 0x195c  [ 044638489B4A5FE5334F46C5314A0826, E06CC2A9EF369794DAD69FBB5AFD1676D4283DDAB2AD5E3EFE454C473F62F955 ] RasAuto         C:\Windows\System32\rasauto.dll
12:48:37.0756 0x195c  RasAuto - ok
12:48:37.0833 0x195c  [ 0A655DD285E4E1E2975CEAB8FDE75295, 023B73A71CB48578702548F8F1096BDF72BE09D836F2D324DDA869E4F0354133 ] RasMan          C:\Windows\System32\rasmans.dll
12:48:37.0833 0x195c  RasMan - ok
12:48:37.0882 0x195c  [ 5247F308C4103CDC4FE12AE1D235800A, E567CD33CA1897D53795E071B7AFBAF98B2C8F725F8BED0BA90F5EF611520E48 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
12:48:37.0882 0x195c  RasPppoe - ok
12:48:37.0913 0x195c  [ D67ED4AB59D1EF66B05AD1A81AC28B26, 72E750A9A6B484D8BEDE52FA6DABEF4D95765DE491152E1F6C856D0590B50C28 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
12:48:37.0927 0x195c  rdbss - ok
12:48:37.0943 0x195c  [ 6B21EBF892CD8CACB71669B35AB5DE32, 0AD8E14FEF16FB2559F5FC8AFBC9D49E4E24F43CF65F480DBF9FAB593269B419 ] rdpbus          C:\Windows\System32\drivers\rdpbus.sys
12:48:37.0958 0x195c  rdpbus - ok
12:48:37.0958 0x195c  [ 680C1DAE268B6FB67FA21B389A8B79EF, 856911F77BDD8830C3D683EBE8AF399FB3A54C7D8D0B34EA37D903377F0A39BD ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
12:48:37.0974 0x195c  RDPDR - ok
12:48:38.0022 0x195c  [ BC8A79C625568DDB7DCA49D0C2741A64, AB0A7ED9EC2282EC0356D27EA4F70515943E41C2112428B787636B8BEC278933 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
12:48:38.0022 0x195c  RdpVideoMiniport - ok
12:48:38.0038 0x195c  [ A26AEC49F318FEE141DDDB2C5F99B3E6, 246AD79FF27E79DEDCB0AAA7C22A8EA6349DEDAC863413A1E378E68FD94C9C4F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
12:48:38.0052 0x195c  rdyboost - ok
12:48:38.0083 0x195c  [ 2D39BCFA4DD1081B8F282B623456B858, DD8C433B66B6661F4DBD1784CBD334441B508BE84932DD443F7AD51CEA192BA9 ] ReFS            C:\Windows\system32\drivers\ReFS.sys
12:48:38.0099 0x195c  ReFS - ok
12:48:38.0132 0x195c  [ DF78648AC3C8DC9D70E6714AF785382F, 56E104939ED0AB5B26AE07BAB1BBB7D15828DBD3A2AD35361423D7ADDA4BA551 ] RemoteAccess    C:\Windows\System32\mprdim.dll
12:48:38.0147 0x195c  RemoteAccess - ok
12:48:38.0177 0x195c  [ 7594FEFBAD6BA4645CE7AA175C19BAD0, 32625BA39B905576F0465E261F15D222ED228A19071E3A1BC4286B5FECA0F948 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
12:48:38.0193 0x195c  RemoteRegistry - ok
12:48:38.0226 0x195c  [ 65B9FDE300A6DECC03BA44C4616DCAD6, CAD992982733DD20282A3453DC4E554AE1FC077C35479C0CA4E8BC3A9DCD3BB0 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
12:48:38.0226 0x195c  RpcEptMapper - ok
12:48:38.0255 0x195c  [ A737B433ABAF3F2DCB2BD7B4CC582B26, 3B5706B0CF0969A9F82060FD4DCC745F2D83C066B663FE8A4F0F493B64032C9C ] RpcLocator      C:\Windows\system32\locator.exe
12:48:38.0255 0x195c  RpcLocator - ok
12:48:38.0287 0x195c  [ 20CC6E9FE25ACD34BE4FCDDB7B08364D, 295B2BBDC860A4CD65CD09C975D08CA1B8E4FE60AD0CA084CAB149A3E9D64B40 ] RpcSs           C:\Windows\system32\rpcss.dll
12:48:38.0302 0x195c  RpcSs - ok
12:48:38.0318 0x195c  [ 2D05A5508F4685412F2B89E8C2189ABC, 82F12B4E0E73411A121EFD35FBD3B44CBBC0AE96ACFBB45D8C3C3777E2EA320D ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
12:48:38.0318 0x195c  rspndr - ok
12:48:38.0365 0x195c  [ 3AB1AA5155684F40E2F5215A258D2471, 3D6A5F603FA6809651A006EA31F57920A45642B6B9E8EC80E5399D1301F635E4 ] RTL8168         C:\Windows\system32\DRIVERS\Rt630x64.sys
12:48:38.0380 0x195c  RTL8168 - ok
12:48:38.0396 0x195c  [ AAC76DA735718DB96E95509BCFCD75CB, A025881110479EE1150FBBA339CA71CF50E2B1568B9933DECE9D7CB5B5BD8666 ] RTLU3E8023-W8-64 C:\Windows\system32\DRIVERS\rtu30x64w8.sys
12:48:38.0396 0x195c  RTLU3E8023-W8-64 - ok
12:48:38.0411 0x195c  [ 1A063730F221B2746FF00457AE17E4F0, 39A3C258CBFE3BC566C63528C9020A3BC9409736AE5289C08A7BA471D8409263 ] s3cap           C:\Windows\System32\drivers\vms3cap.sys
12:48:38.0411 0x195c  s3cap - ok
12:48:38.0427 0x195c  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] SamSs           C:\Windows\system32\lsass.exe
12:48:38.0427 0x195c  SamSs - ok
12:48:38.0458 0x195c  [ C624A1B32211C3166EDB3F4AB02A30B7, 6B2A4607DB52D74242787ED9DF9067058983D310431D8612D2B0236E6201E681 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
12:48:38.0475 0x195c  sbp2port - ok
12:48:38.0490 0x195c  [ 74A3B67F03877D06B09B1B40C5ED582E, A8FF9BF416F0BF365BFB4E1796859825C811A74B5E54DDDCE8345193BEEBE206 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
12:48:38.0505 0x195c  SCardSvr - ok
12:48:38.0538 0x195c  [ 92D2FA1870F4EB4A9BA767DB6E0DEF6F, AB019E17D5F330CBB7F7CAF8CEB01F3F3DBBB181CDE19E4C2354AF51E66C8291 ] ScDeviceEnum    C:\Windows\System32\ScDeviceEnum.dll
12:48:38.0538 0x195c  ScDeviceEnum - ok
12:48:38.0568 0x195c  [ FA7ABD857DEB0FE3C94CC39A4C845E66, ACD551F75E00C4EB9CFDA73B04051D0BF5FF0BA67C716E1989A21683D8777A41 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
12:48:38.0584 0x195c  scfilter - ok
12:48:38.0630 0x195c  [ 3151A020E03DDE31AAC49F35C5EFB4DB, 5ABB1103009979F86C862357E28F37C2744979F2C99F7CF6ABB4EB1B8416B3F6 ] Schedule        C:\Windows\system32\schedsvc.dll
12:48:38.0646 0x195c  Schedule - ok
12:48:38.0693 0x195c  [ ACFDC4EE40EC6E4A0AB91D923B8288C8, D31555AB31F504C247049219BE0ECDF26BB18E210BE7C45E8575FD166FD7EE23 ] SCPolicySvc     C:\Windows\System32\certprop.dll
12:48:38.0693 0x195c  SCPolicySvc - ok
12:48:38.0724 0x195c  [ C54B6B2170BF628FD42F799A66956D75, BCF460A124CAA6F1F1A9A7BCBDCC2D5E39B0404D96B7C9FFAC806E041782B91E ] sdbus           C:\Windows\System32\drivers\sdbus.sys
12:48:38.0740 0x195c  sdbus - ok
12:48:38.0755 0x195c  [ 0B1E929D11A8E358106955603FAC65E8, A5EC91BFC0873EC6AB1D0DB4E91654BD35339BD680E7E82DA2DC64996B4AE515 ] sdstor          C:\Windows\System32\drivers\sdstor.sys
12:48:38.0755 0x195c  sdstor - ok
12:48:38.0787 0x195c  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
12:48:38.0787 0x195c  secdrv - ok
12:48:38.0819 0x195c  [ 6627154693B6C2B8A59727F5B38728E8, F08251EE3436400295F120D48F3763E6F11BBF4132D674AD3E8112B6B3538455 ] seclogon        C:\Windows\system32\seclogon.dll
12:48:38.0819 0x195c  seclogon - ok
12:48:38.0850 0x195c  [ 81FE9A81EDF8016816C9E91FBFBF7D35, 87FB92A3D15F312F0B9C423EF851061A944B013E5668D8C9A441B4DC0EB690AF ] SENS            C:\Windows\System32\sens.dll
12:48:38.0865 0x195c  SENS - ok
12:48:38.0880 0x195c  [ 6E4012AE67F09F867EF620C8D5524C0B, 63933E51F8E413E63481369CE2F9FD224560550FBD3BD2B4573E9F4AD88708A2 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
12:48:38.0880 0x195c  SensrSvc - ok
12:48:38.0896 0x195c  [ DB2FF24CE0BDD15FE75870AFE312BA89, 7DB0D978C92CD0A0A81F7AB46FE323B4929CEA01585B0F330921E6DFA7DE1B85 ] SerCx           C:\Windows\system32\drivers\SerCx.sys
12:48:38.0896 0x195c  SerCx - ok
12:48:38.0911 0x195c  [ 0044B31F93946D5D41982314381FE431, 95B8A94BA9EF770F29ACD5B23D447EC2B6CF1CB3D0030343BA1550AC31F6E2A5 ] SerCx2          C:\Windows\system32\drivers\SerCx2.sys
12:48:38.0911 0x195c  SerCx2 - ok
12:48:38.0946 0x195c  [ 1F0135949A6AD6025F363F80FE268251, DB2D503863143F2251E589F7B0B3E9FBF997D7333D54C55856590B5080B5513D ] Serenum         C:\Windows\System32\drivers\serenum.sys
12:48:38.0946 0x195c  Serenum - ok
12:48:38.0958 0x195c  [ 81633C87B42B63BA484A6177179AC750, A22BA40E9EC74E88D8098CBDC954E1D63B832FCB789E3C7B731DE5DA39BEE2CA ] Serial          C:\Windows\System32\drivers\serial.sys
12:48:38.0958 0x195c  Serial - ok
12:48:38.0990 0x195c  [ 148195AE95D9BC7375A08846439FDAC1, 3A2F78FD18AA7A6D659921E19335E943894530874AC5AB5E7219CEF28FA54F7A ] sermouse        C:\Windows\System32\drivers\sermouse.sys
12:48:38.0990 0x195c  sermouse - ok
12:48:39.0054 0x195c  [ 624BB76941938B9F5776DEA56004D33E, D4EE7A23665D71646622D477CA962335B4C17BAC931A728122DF8C112CD5A560 ] SessionEnv      C:\Windows\system32\sessenv.dll
12:48:39.0068 0x195c  SessionEnv - ok
12:48:39.0085 0x195c  [ 472B7A5AC181C050888DB454663DD764, C950A8615D57BFD455E18880398350642B2E1D6B951EC9754FD8D429F3418835 ] sfloppy         C:\Windows\System32\drivers\sfloppy.sys
12:48:39.0085 0x195c  sfloppy - ok
12:48:39.0115 0x195c  [ 8081FF3DAE8159FE8956B09BC29CE983, AC0F305AEE8B1AB2E1275F1D33EC1D2F3E23F234F831BD9D41F415A94A19D3AB ] SharedAccess    C:\Windows\System32\ipnathlp.dll
12:48:39.0130 0x195c  SharedAccess - ok
12:48:39.0161 0x195c  [ 7FD9A61A3523A61FC135D61D6E160314, 409E1CF7A62FD90CBC31AEAFBB7230B02DBEC6CFCA2D266D221A7643FAEBA13B ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:48:39.0177 0x195c  ShellHWDetection - ok
12:48:39.0208 0x195c  [ 693C0C1A4F89BED4CEA1FA291638C02B, 5DCDFB81F07DADDC941B9BD0F49D078A8F27F8D9B57DE503AF1ACDC55A41B744 ] silabenm        C:\Windows\system32\DRIVERS\silabenm.sys
12:48:39.0240 0x195c  silabenm - ok
12:48:39.0258 0x195c  [ CD54DDA4898439ADB7A2E26EB9133028, 94154F24CC74E956B7C7D90D61631AA03F4EB9B3BB491E758FEC152B6C1606A7 ] silabser        C:\Windows\system32\DRIVERS\silabser.sys
12:48:39.0382 0x195c  silabser - ok
12:48:39.0396 0x195c  [ 2F518D13DD6F3053837FE606F1A2EA1F, 64109296CE95BD233525688A350D575CF97B9464659AA07CF78B307B6ADBC835 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
12:48:39.0396 0x195c  SiSRaid2 - ok
12:48:39.0416 0x195c  [ 1AC9A200A9C49C4508F04AAFFCA34A3F, 972BCB2A39169155F74111FAC74ACCD8F50E34EADCF087833B0980827627BBF4 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
12:48:39.0416 0x195c  SiSRaid4 - ok
12:48:39.0445 0x195c  [ 3C84DCCE5B322F745A75CA8BA3A0F6B3, 1FB94A8A1C63D6FDB82E28ED5B696B3CB1F64183A89A3B5153B266C292CB7815 ] smphost         C:\Windows\System32\smphost.dll
12:48:39.0445 0x195c  smphost - ok
12:48:39.0474 0x195c  [ 961507DB02D7AC0B7A7828D457143B8E, F423BE6287C65960A955EBB3BFBAC047313BEB2F54920A6E57E51FCCE855F5E0 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
12:48:39.0474 0x195c  SNMPTRAP - ok
12:48:39.0507 0x195c  [ F6AF6499C3788105EA7AF1DA27769A77, F847789B0AD498CC9C985F334F7BA0906ACB41FB356CC2EF2A00C62C75D94A79 ] spaceport       C:\Windows\system32\drivers\spaceport.sys
12:48:39.0521 0x195c  spaceport - ok
12:48:39.0538 0x195c  [ F337BE11071818FC3F5DC2940B6BDE34, D5CFF00E5DF37045F71AEE101AC9B270EBB29F372F404757B58600E9966C7E4D ] SpbCx           C:\Windows\system32\drivers\SpbCx.sys
12:48:39.0538 0x195c  SpbCx - ok
12:48:39.0583 0x195c  [ FCB156A6745631A67DEA61827061D483, 9275ABFA1E1E595969A71C0DA228D18D1B868BF46E097E1276142BD80F8A32C9 ] Spooler         C:\Windows\System32\spoolsv.exe
12:48:39.0599 0x195c  Spooler - ok
12:48:39.0802 0x195c  [ F264662C057A54AA2DE41B3C7551712F, 2C123C6ACD967CDF1AD2855187CF3D8357B16A4FD9C2F18AE54CFA384165FA11 ] sppsvc          C:\Windows\system32\sppsvc.exe
12:48:39.0975 0x195c  sppsvc - ok
12:48:40.0115 0x195c  [ 3D0CA97EA01210E0BC032EB6FDCCF03D, 2FA90A54B77E7F6C08873CB72E20AFED30862270D7DA23D0480E72AC1077CD7E ] srv             C:\Windows\system32\DRIVERS\srv.sys
12:48:40.0195 0x195c  srv - ok
12:48:40.0240 0x195c  [ FD4A645C5BA587257A97D7AC46212F4A, 93D028A6917D8E02EDEEF63DCAC4137DCC0AD27586A478656174ECBF03127120 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
12:48:40.0257 0x195c  srv2 - ok
12:48:40.0287 0x195c  [ D3EAE998706531157CBEA3F5218435BC, F5BA622BDAE25E0060007A27C9708A6F082AAAD4745852B1197C7A29B1BD286F ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
12:48:40.0333 0x195c  srvnet - ok
12:48:40.0382 0x195c  [ CF6C3037839CF78421A94F9060C2886F, CA98C180AE03F5BE8FEFFBA75BD98DEE2AD4FA975E1EF83215C9CD2476946811 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
12:48:40.0413 0x195c  SSDPSRV - ok
12:48:40.0474 0x195c  [ 198A737DBA666F4808D62E9A8277A6B7, 90B6E5E2ACE95D850C913A3A1DA1F966C44955C530004C228FA93B2A536F5C27 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
12:48:40.0474 0x195c  SstpSvc - ok
12:48:40.0662 0x195c  [ 857693A4DA826BCD422C48114AA72B10, E6614B190004B17FDF9ED9FEFC8965B819D4D65CC6480BB5557317A6DDBC4B09 ] STacSV          C:\Program Files\IDT\WDM\STacSV64.exe
12:48:41.0068 0x195c  STacSV - ok
12:48:41.0084 0x195c  [ 366DEA74BBA65B362BCCFC6FC2ADFD8B, 4D28122AB9D8DAB724021E6513B4474BD34FCEDF47769B1D27AC7551FCA002F8 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
12:48:41.0084 0x195c  stexstor - ok
12:48:41.0177 0x195c  [ A73F13903345464F04D463B84890A271, F22A088D94418420CA3943D34CB233B82B36A6A66BB36000A44726244D794AFF ] STHDA           C:\Windows\system32\DRIVERS\stwrt64.sys
12:48:41.0177 0x195c  STHDA - ok
12:48:41.0302 0x195c  [ 63E9CE568CF1192771A5F0460DE7D2B9, C27B21FD2C14AD41A59EF62EB8AC95C08EB13CCB1CEECD8378B8CDD4DC352E69 ] stisvc          C:\Windows\System32\wiaservc.dll
12:48:41.0333 0x195c  stisvc - ok
12:48:41.0349 0x195c  [ 0ED2E318ABB68C1A35A8B8038BDB4C90, 5C3ABC245F4BCFE64E646D9C0E2F5E211244956C84D03084C71FF6A7E0CDED30 ] storahci        C:\Windows\system32\drivers\storahci.sys
12:48:41.0349 0x195c  storahci - ok
12:48:41.0365 0x195c  [ 8B9486B64E5FC17FB9CC04CA10B77A34, C1EAC9D27DC83E4C56B890D97988C3CCFAE3877309610601F2E3FFFE97686D43 ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
12:48:41.0381 0x195c  storflt - ok
12:48:41.0411 0x195c  [ 1D5A045F59D216448FCDE3A8D69970E2, CEDEB0843D93339D10FE4BC209CCFCB6E12C6064FD62694DA7675082E8B8C915 ] stornvme        C:\Windows\system32\drivers\stornvme.sys
12:48:41.0411 0x195c  stornvme - ok
12:48:41.0458 0x195c  [ A45F5AC9D8069D0EC66E3CA73103073B, 996788F1C58E016E8E5CF3FD1D220A3C40AFFD6C21361A34636415DB12E0D381 ] StorSvc         C:\Windows\system32\storsvc.dll
12:48:41.0458 0x195c  StorSvc - ok
12:48:41.0474 0x195c  [ 548759755BC73DAD663250239D7E0B9F, D31A05A8CE800B539420B6E545F1F4BF6E4B02EAF8366DE89CAF13A83C6CA48D ] storvsc         C:\Windows\system32\drivers\storvsc.sys
12:48:41.0474 0x195c  storvsc - ok
12:48:41.0505 0x195c  [ E395BE02F80A79A6CF973BA38DBB8135, 4C6F85B0EB8E7725BA720F9742561D229726C0D7C17505D1E79F19A5626F6325 ] svsvc           C:\Windows\system32\svsvc.dll
12:48:41.0521 0x195c  svsvc - ok
12:48:41.0537 0x195c  [ 65454187E0F8B6C0DCECB0287D06EC43, 87550000CF5B3C1DF3E69633934AFE8554AE40B6638F190D3185AD63F1D7A2EE ] swenum          C:\Windows\System32\drivers\swenum.sys
12:48:41.0537 0x195c  swenum - ok
12:48:41.0615 0x195c  [ 1C71D72D4997A284128FBEE770726330, 21682BDE74A1108FED1124FB1EA35A03CBFA94ABE1B89CC0FADB4DD82596C43E ] swprv           C:\Windows\System32\swprv.dll
12:48:41.0662 0x195c  swprv - ok
12:48:41.0927 0x195c  [ 7E85DB0463AD2403AE84AD162B162279, 996C42ECAFC6E24C623068AFAFCC0A2612526333AF9315F7536C6D40C2570632 ] SysMain         C:\Windows\system32\sysmain.dll
12:48:42.0037 0x195c  SysMain - ok
12:48:42.0130 0x195c  [ D73DBBB96CEE90C2856164AAD8543425, D11ADB5D4C5DD355314CA656D375D0062CAE7462E866F94F1B26D5803F65DCB2 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
12:48:42.0130 0x195c  SystemEventsBroker - ok
12:48:42.0177 0x195c  [ 54A1F83B166F1062000A0D816CB3B43A, 8A104B2141546984CFB988CC178EB1910F6B42A19CB75A30F4E74D5EE67901EB ] TabletInputService C:\Windows\System32\TabSvc.dll
12:48:42.0193 0x195c  TabletInputService - ok
12:48:42.0240 0x195c  [ 5A5BAB1CA9621E73E25EE4744B67CDA6, 479EBD7BAE1E2AD431153FDC016742F7A8D824716EAB1A4CA87EBBD21D61DECD ] TapiSrv         C:\Windows\System32\tapisrv.dll
12:48:42.0240 0x195c  TapiSrv - ok
12:48:42.0443 0x195c  [ 4C58B60C1E6A2946D6E3D67A36E5E03E, 30952D48B96BB5B858B48194B6C6D1BB64880D3801D46F8CB5CD81CC77B63EDD ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
12:48:42.0505 0x195c  Tcpip - ok
12:48:42.0583 0x195c  [ 4C58B60C1E6A2946D6E3D67A36E5E03E, 30952D48B96BB5B858B48194B6C6D1BB64880D3801D46F8CB5CD81CC77B63EDD ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
12:48:42.0630 0x195c  TCPIP6 - ok
12:48:42.0662 0x195c  [ 41CF802064F72E55F50CA0A221FD36D4, 70ABCDF9E96611E8C83042C581575E26649FE479475E8E118CD3FF6CB1C84C3F ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
12:48:42.0662 0x195c  tcpipreg - ok
12:48:42.0711 0x195c  [ 576FA545FAB846B06E79B324160DE25C, 14F1FD2769E7F5362E6452CA061564EF3DEBFDF6BC8EFF0CD4E22068A460A727 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
12:48:42.0724 0x195c  tdx - ok
12:48:43.0443 0x195c  [ F38A3CBCB78CBEF1E986A626D3F46943, FFB62FD1756FB2D261F8B8C01DA5BCB720C4D05742F7DF92E18C8990121699DD ] TeamViewer      C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
12:48:43.0787 0x195c  TeamViewer - ok
12:48:43.0833 0x195c  [ 232D185D2337F141311D0CF1983E1431, 02EB56D3F26174AF1741C1A444CE30DE84D5BAF583C1A52C7A953BCC52445547 ] terminpt        C:\Windows\System32\drivers\terminpt.sys
12:48:43.0833 0x195c  terminpt - ok
12:48:44.0115 0x195c  [ 76938862B2674EFED79E814CD36E6A08, 911C0B419AC68EC535E0BEFAD1612A840AA22745215834DF421F10041B4ADA27 ] TermService     C:\Windows\System32\termsrv.dll
12:48:44.0193 0x195c  TermService - ok
12:48:44.0225 0x195c  [ 2180DBCE75B914E5E5BBFFFAAE97AA21, 8000AECC8855903DB50ABA7E304396D1FCEAE8DC9ADD4FC50275CF24B4D914DE ] Themes          C:\Windows\system32\themeservice.dll
12:48:44.0225 0x195c  Themes - ok
12:48:44.0256 0x195c  [ 4C5179DB61B9E14BEC15CDC4B152B2E9, 9048BEC7AD6A3F4B640E99B1F0365AC9A46740B188758FBB2C160EF30AD6E64B ] THREADORDER     C:\Windows\system32\mmcss.dll
12:48:44.0256 0x195c  THREADORDER - ok
12:48:44.0271 0x195c  [ B5ED9CC61798C7D44BD535D40B89EFB5, 1BDCEAA9AF2096381870D92129C748F4EE06A1167ABA9367B9DD43BAF27E3F5B ] TimeBroker      C:\Windows\System32\TimeBrokerServer.dll
12:48:44.0287 0x195c  TimeBroker - ok
12:48:44.0318 0x195c  [ 80A2FC1A089A71F2DBE5D8394FFB009F, DEA30E751F6EA42E43E16869713FC7E37832B15DAFA0062B1798DFA476981385 ] TPM             C:\Windows\system32\drivers\tpm.sys
12:48:44.0318 0x195c  TPM - ok
12:48:44.0334 0x195c  [ 884113C2BB703FE806C8608B75F34831, 24DE5750CA4363455412BABB0B1FAB08497153E8F158ED44958F100410F93506 ] TrkWks          C:\Windows\System32\trkwks.dll
12:48:44.0349 0x195c  TrkWks - ok
12:48:44.0382 0x195c  [ 44A94FB4C76528D2382FFE04B05827C3, B0BCDF7CD1D65E61A9061D539D83527A89B69583958F8A26C6BF9766C1B61E0C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:48:44.0382 0x195c  TrustedInstaller - ok
12:48:44.0396 0x195c  [ BF8F54CA37E9C9D6582C31C5761F8C93, 337C566792F6FB9B7FD5D1D4384B767CFE4CF5DBB2E4688CCC36CBB018A0DD0F ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
12:48:44.0412 0x195c  TsUsbFlt - ok
12:48:44.0412 0x195c  [ 20185BEB7512EDE4EFECDFA148AC9F99, 6F539478493C0F87F3DDF67A4A6D4D41E9474EEF21434E856350CE149A34EA9F ] TsUsbGD         C:\Windows\System32\drivers\TsUsbGD.sys
12:48:44.0412 0x195c  TsUsbGD - ok
12:48:44.0444 0x195c  [ E85916632CD3B9E9B546968DB950BF42, DECE3852C763CC6293C7D1B772296C43A0AE1E47BBCC4979C96B3B2AD70413F3 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
12:48:44.0444 0x195c  tunnel - ok
12:48:44.0459 0x195c  [ F6EEAD052943B5A3104C1405BB856C54, FE422813E6C1012E9F392EFF2AE4C6D3A4DBD9CB2BD5E6A5CAB57D4E89A29468 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
12:48:44.0459 0x195c  uagp35 - ok
12:48:44.0491 0x195c  [ FE6067B1FD4E63650C667B33D080565B, 2C330ED00E49BA55E25564230E0DFB8A35F2B5320EB18D4AF7CAACFA9A449044 ] UASPStor        C:\Windows\System32\drivers\uaspstor.sys
12:48:44.0491 0x195c  UASPStor - ok
12:48:44.0506 0x195c  [ 807F8CF3E973305FC435C61CBBEE2A49, 43CDEAC2BFC5091C11DFC0E7F7171AF9A598AE56CB056C3CF382AE7807F79EF0 ] UCX01000        C:\Windows\System32\drivers\ucx01000.sys
12:48:44.0506 0x195c  UCX01000 - ok
12:48:44.0537 0x195c  [ C61EAF8E1E4B2F62BA4FDF457440B2C6, 961F76A789925234AC27F56AAE34556FA06088D71580B42C24B0BC209EAFD67E ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
12:48:44.0552 0x195c  udfs - ok
12:48:44.0568 0x195c  [ 9578691F297E1B1F519970FE6D47CB21, 080C352AAF22A16A4F3C4AB4DCEA5BFA656457C73F735CEBA30516FDACCF6301 ] UEFI            C:\Windows\System32\drivers\UEFI.sys
12:48:44.0568 0x195c  UEFI - ok
12:48:44.0599 0x195c  [ A867F0F978EE64C87FADC3B100869EE4, 2686BE85F963D0D0BB275E92E5B543280D8742CF10772303E3189D0719B6A277 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
12:48:44.0599 0x195c  UI0Detect - ok
12:48:44.0615 0x195c  [ 5EAB5117DDB24FC4D39E6FFFCF1837B9, 2BC709240867F161E94BE6625A04F478EAAA3EEE7BC7C37ED0DFA9EEA5928E98 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
12:48:44.0615 0x195c  uliagpkx - ok
12:48:44.0648 0x195c  [ DA34C39A18E60E7C3FA0630566408034, 2F162504214053894C72760D9933D01DBF3578609FE5E2376C3272818599FE32 ] umbus           C:\Windows\System32\drivers\umbus.sys
12:48:44.0648 0x195c  umbus - ok
12:48:44.0662 0x195c  [ AE8294875E5446E359B1E8035D40C05E, AE0357BAB47C07C3576BC76951CD258C009BC5A1B93259D2122A841BD9CDA8FA ] UmPass          C:\Windows\System32\drivers\umpass.sys
12:48:44.0662 0x195c  UmPass - ok
12:48:44.0694 0x195c  [ 87743CF5FF2FB3F2B424F0D8DFF8FD8C, C14C979612426D4449274C109FCF25D3BE170DC5CD7EF8E230C7E8D5681904D3 ] UmRdpService    C:\Windows\System32\umrdp.dll
12:48:44.0709 0x195c  UmRdpService - ok
12:48:44.0756 0x195c  [ C98493DD8E6A50154FAC75C15E1C36BB, CECD1C826C8F7AF05468871BF6A0ACDBB6B0202F4F87F48C6D367E5BD699E800 ] upnphost        C:\Windows\System32\upnphost.dll
12:48:44.0771 0x195c  upnphost - ok
12:48:44.0787 0x195c  [ F957092C63CD71D85903CA0D8370F473, 4DEC2FC20329F248135DA24CB6694FD972DCCE8B1BBEA8D872FDE41939E96AAF ] USBAAPL64       C:\Windows\System32\Drivers\usbaapl64.sys
12:48:44.0802 0x195c  USBAAPL64 - ok
12:48:44.0834 0x195c  [ 621317D14B93CBFBD5694767EFB6B40A, 84D3F4AA2CAFA11DF5EAD178889ACCAA2FF50D48AFE9518F63FBB862928630FB ] usbccgp         C:\Windows\System32\drivers\usbccgp.sys
12:48:44.0881 0x195c  usbccgp - ok
12:48:44.0898 0x195c  [ 0139248F6B95CF0D837B5B46A2722D40, 38E3E704E0364F07732DB418AEBD126B040FB3CDB7D78EA36E8605D50D528A80 ] usbcir          C:\Windows\System32\drivers\usbcir.sys
12:48:44.0898 0x195c  usbcir - ok
12:48:44.0927 0x195c  [ C996CBEF922B5653A01E3F50DDCE2F86, 231EB5A36E7EE242197E796D3B4AB12F945D2C8570587BC8D57D45530A0C59B4 ] usbehci         C:\Windows\System32\drivers\usbehci.sys
12:48:44.0927 0x195c  usbehci - ok
12:48:44.0959 0x195c  [ E30B159760053C5A1297D2CD08046CD7, E45472CEEC31616DBE2B38C4FD9B90179ED7FF29041F21FB124334B4A53AE48C ] usbhub          C:\Windows\System32\drivers\usbhub.sys
12:48:44.0974 0x195c  usbhub - ok
12:48:45.0006 0x195c  [ 5C90D5379B53590FBB24BBAD4FA682EE, DC036340510C1C0999AB1CB845F8E6EB8B7696BAC9BBE6E936454C0000D1E9D4 ] USBHUB3         C:\Windows\System32\drivers\UsbHub3.sys
12:48:45.0021 0x195c  USBHUB3 - ok
12:48:45.0070 0x195c  [ A0F0484C97D6441ED6A75D7426ECCC9E, FF928ADE1C5464E581BF929F7383D5762D110EA6C7E31A6F0887EA7357ADBEFE ] usbohci         C:\Windows\System32\drivers\usbohci.sys
12:48:45.0084 0x195c  usbohci - ok
12:48:45.0099 0x195c  [ 4D655E3B684BE9B0F7FFD8A2935C348C, 3A7FC1748C5AEA8CFE0E7C22ADC77E3DCA475455FC16D9C6A5C16EB5E949A516 ] usbprint        C:\Windows\System32\drivers\usbprint.sys
12:48:45.0099 0x195c  usbprint - ok
12:48:45.0131 0x195c  [ 0F030491BA4A27BD46F8B8ACEEE83F1A, 7063855611BEF94D4D229BA1BE507ECBDD89F5861641A407EB3E2919A352F9D4 ] usbscan         C:\Windows\system32\DRIVERS\usbscan.sys
12:48:45.0131 0x195c  usbscan - ok
12:48:45.0162 0x195c  [ 9D168BFA334D47BE404367EB58D4E130, 23279CBE6ACBD074E7B268BA2EDA14E2255C41F8117173B2BBE653D8259ECFA2 ] USBSTOR         C:\Windows\System32\drivers\USBSTOR.SYS
12:48:45.0177 0x195c  USBSTOR - ok
12:48:45.0177 0x195c  [ FC974B03C8B87455F44F734C8F31A3C8, D69F6EE8030F7DF96FF151D9EAA6AE65417ACAC5A267C7DB96E9611D5BC42D2C ] usbuhci         C:\Windows\System32\drivers\usbuhci.sys
12:48:45.0193 0x195c  usbuhci - ok
12:48:45.0225 0x195c  [ 44603DA5A87FB491EF59C889EBBB4DDB, 59AA9B6B0B5D66F9312CD3F999D0D9F12F1A2C5D230365AD7287CD71FD86961C ] USBXHCI         C:\Windows\System32\drivers\USBXHCI.SYS
12:48:45.0240 0x195c  USBXHCI - ok
12:48:45.0256 0x195c  [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] VaultSvc        C:\Windows\system32\lsass.exe
12:48:45.0256 0x195c  VaultSvc - ok
12:48:45.0287 0x195c  [ FEB26E3B8345A7E8D62F945C4AE86562, 3AAFE87C402FC8E92542DFE60EC9540559863065F88D429A16D7B1BF829223FF ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
12:48:45.0287 0x195c  vdrvroot - ok
12:48:45.0349 0x195c  [ 8A4D808D1EC7C1C47B2C8BF488A9A07A, 63C07312ADB6F8A8BDE93361C30AC63DAB4DE1141AF54630EEF11E54B0BF983D ] vds             C:\Windows\System32\vds.exe
12:48:45.0381 0x195c  vds - ok
12:48:45.0396 0x195c  [ A026EDEAA5EECAE0B08E2748B616D4BD, 2525A54DC7F49DDFBB999C22BF3FAB6D9E9F70C0806E58D81E90AC59F9F46089 ] VerifierExt     C:\Windows\system32\drivers\VerifierExt.sys
12:48:45.0412 0x195c  VerifierExt - ok
12:48:45.0443 0x195c  [ 8ABB4BABF59F092DF0B43778D8FD1884, 94C2100CE86448543A8DD586AD4A128AB9EB37959238D70F33EF59202270AC6C ] vhdmp           C:\Windows\System32\drivers\vhdmp.sys
12:48:45.0459 0x195c  vhdmp - ok
12:48:45.0506 0x195c  [ 06D38968028E9AB19DE9B618C7B6D199, 62022297A47F440D1C82CA0B0E57C0C8E9D5033D83DD3B40492B218DF65EBF68 ] viaide          C:\Windows\system32\drivers\viaide.sys
12:48:45.0506 0x195c  viaide - ok
12:48:45.0537 0x195c  [ 511AD3FF957A0127E6BD336FF6F89C38, 55325BFD0857A1204F7F6F8ED8C91C07B0E20A50402105708E7365ECD9E25A21 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
12:48:45.0537 0x195c  vmbus - ok
12:48:45.0552 0x195c  [ DA40BEA0A863CE768C940CA9723BF81F, 567C0C3F422325635808B0CF76E05D3B6187F96845C33F85F92F98C9FE53A5B8 ] VMBusHID        C:\Windows\System32\drivers\VMBusHID.sys
12:48:45.0552 0x195c  VMBusHID - ok
12:48:45.0601 0x195c  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicguestinterface C:\Windows\System32\ICSvc.dll
12:48:45.0616 0x195c  vmicguestinterface - ok
12:48:45.0631 0x195c  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicheartbeat   C:\Windows\System32\ICSvc.dll
12:48:45.0646 0x195c  vmicheartbeat - ok
12:48:45.0663 0x195c  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
12:48:45.0678 0x195c  vmickvpexchange - ok
12:48:45.0693 0x195c  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicrdv         C:\Windows\System32\ICSvc.dll
12:48:45.0709 0x195c  vmicrdv - ok
12:48:45.0740 0x195c  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicshutdown    C:\Windows\System32\ICSvc.dll
12:48:45.0756 0x195c  vmicshutdown - ok
12:48:45.0771 0x195c  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmictimesync    C:\Windows\System32\ICSvc.dll
12:48:45.0787 0x195c  vmictimesync - ok
12:48:45.0818 0x195c  [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicvss         C:\Windows\System32\ICSvc.dll
12:48:45.0834 0x195c  vmicvss - ok
12:48:45.0927 0x195c  [ 0E068DF0796A33D2922EC69652A2C043, 487250C6424C0CD4F794DCD34533F00FDCE12BCEFB36C742189978D10A2EBB63 ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
12:48:45.0943 0x195c  VMUSBArbService - ok
12:48:46.0021 0x195c  [ 6DBA40D936A02CDE219D43FD47C845F8, 8E0D1EE3F31E29B3581EF702877F6FB5A00F5F2961DB26788412F9F44018D05F ] vmware-view-usbd C:\Program Files (x86)\VMware\VMware Horizon View Client\bin\vmware-view-usbd.exe
12:48:46.0052 0x195c  vmware-view-usbd - ok
12:48:46.0084 0x195c  [ 771D3F512B2738338E321556D9D4690F, 7A6C37729B6FFEF38FEFA7082F89F2B071FF44D7C86254DA20C23999CADBDD23 ] vmwsprrdpwks    C:\Program Files (x86)\Common Files\VMware\SerialPortRedirection\Client\vmwsprrdpwks.exe
12:48:46.0084 0x195c  vmwsprrdpwks - ok
12:48:46.0115 0x195c  [ 436E1A724E7E683F6B612D3D58F04241, 939B5EF0090DF3759295F88402FD0EA33F499DDA9F89E5D0E90D1F9AED65D491 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
12:48:46.0115 0x195c  volmgr - ok
12:48:46.0146 0x195c  [ 7DD4EAE2E680948D9AFF3E1B5234C1D3, 7B893CEF2B72458F5C716C811A24E4A8856E12E2AC9F551606A64B59C9DCF272 ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
12:48:46.0162 0x195c  volmgrx - ok
12:48:46.0194 0x195c  [ 17F7B0F2298D97F4B6C7A69511033D3D, 5BDFC225F31553786726808FB7952940FC05CA72B3977D684056F42AFAA59565 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
12:48:46.0194 0x195c  volsnap - ok
12:48:46.0224 0x195c  [ DAC438FB5FF85A9E72806E2341D5D732, B1D1EFCA8C588A6BF53CEC941CC59702C366F15C7D5943431736EC857E57C0A2 ] vpci            C:\Windows\System32\drivers\vpci.sys
12:48:46.0224 0x195c  vpci - ok
12:48:46.0256 0x195c  [ 4539F45F9F4C9757A86A56C949421E07, DEC362314B2C66414F39354AFE79C02B18BF4EEF90787FB58307F6EB62237E2C ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
12:48:46.0256 0x195c  vsmraid - ok
12:48:46.0302 0x195c  [ D0CBA7B3531CCF2ADB985856D5F92434, 7FCBBCAF1AA85DCE8D75FB38DC4848AE12E8DD913CEBBC37BCD3D0123F0A3CAB ] VSS             C:\Windows\system32\vssvc.exe
12:48:46.0349 0x195c  VSS - ok
12:48:46.0365 0x195c  [ 0849B7260F26FE05EA56DED0672E2F4B, 7EAC0E7988F45CB4133A15932955B7B03CE715C967A3BAC9999D81543EBCAEC5 ] VSTXRAID        C:\Windows\system32\drivers\vstxraid.sys
12:48:46.0381 0x195c  VSTXRAID - ok
12:48:46.0413 0x195c  [ 71066FF95C487327E44C8AF1B72EBE8B, EA2729126B452CAE0C80D07501779D804B08E47F1217B61D53277B40869FEC25 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
12:48:46.0413 0x195c  vwifibus - ok
12:48:46.0427 0x195c  [ 29AB43937FFDA0B0FB56984226E698C6, 6A1A559964FE5D594E54988C46149969E6FFD5A8D5A6862E14648B608794CC29 ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
12:48:46.0427 0x195c  vwififlt - ok
12:48:46.0443 0x195c  [ 8B8624A93E3F88CB923AEB05B6313227, 2856B63CD376BF2B1A9129581E7B9207588D4EAFD29A2C8D98F176FEAFDE26A9 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
12:48:46.0443 0x195c  vwifimp - ok
12:48:46.0475 0x195c  [ DC821E811EFBB65CDD77FBB8B6ECA385, B7C8AACDF81DBA298F2F384983D36B269876C31F0398D89BF9070217A069B96F ] W32Time         C:\Windows\system32\w32time.dll
12:48:46.0490 0x195c  W32Time - ok
12:48:46.0522 0x195c  [ 0910AB9ED404C1434E2D0376C2AD5D8B, 62585CA5F1375BDA440D28D5DF1ADDC9DE3DDFA196D49BBFF3456A5A09EE1C6B ] WacomPen        C:\Windows\System32\drivers\wacompen.sys
12:48:46.0522 0x195c  WacomPen - ok
12:48:46.0568 0x195c  [ 841345442390953CBC8801B95D3D0540, FD4F9FD2C4C60A1A580177FFF2E9035009AC6A38E78D4236B0ED4773E3B263EE ] wbengine        C:\Windows\system32\wbengine.exe
12:48:46.0599 0x195c  wbengine - ok
12:48:46.0662 0x195c  [ 0F1DFA2FED73FA78B8C3CDE332A870F6, 1089F6F585F5350D349A640EBD3117832DF6B3657EB6667CB00AE217E04ACA17 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
12:48:46.0677 0x195c  WbioSrvc - ok
12:48:46.0693 0x195c  [ 0EAEC313B24837613621B4A2536ED382, 61C194ED7FA7D65BBE61A546D5FCA52F52AB08324E084D3EC23C9706E9BF0175 ] Wcmsvc          C:\Windows\System32\wcmsvc.dll
12:48:46.0709 0x195c  Wcmsvc - ok
12:48:46.0724 0x195c  [ F6B4C2280FF7C7156AC8A4687B9DA35E, 1899D584D7469BB49355D84080051E2575B033E6312009D9C6C1DD3F7F9AA4C5 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
12:48:46.0741 0x195c  wcncsvc - ok
12:48:46.0756 0x195c  [ B7BF1D783F5B2484E8CE1C0C78257F16, 468601199FCCF63DBAE86EE6B8825EA85B2A1EE177413353FFA2CC9CA5249FCD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:48:46.0771 0x195c  WcsPlugInService - ok
12:48:46.0787 0x195c  [ F2E08D1C067FEFC3A42D21FD4810F1D3, A8AD114094D9AE3BC6F76940EF873FD21CCF130DE7F8712950F1962DCE25F1B3 ] WdBoot          C:\Windows\system32\drivers\WdBoot.sys
12:48:46.0787 0x195c  WdBoot - ok
12:48:46.0834 0x195c  [ CB6C63FF8342B467E2EF76E98D5B934D, BE017CE91E3BAB293DE6ECF143797CCE3F33CC63024437472B4E38C6961AD884 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
12:48:46.0849 0x195c  Wdf01000 - ok
12:48:46.0867 0x195c  [ E234820E6B84ABA5E84E00227F505AE8, 645B809B883D8F678F2535B575AA1D595F27EBFCE0A16433E9A54CC266BD74F2 ] WdFilter        C:\Windows\system32\drivers\WdFilter.sys
12:48:46.0881 0x195c  WdFilter - ok
12:48:46.0881 0x195c  [ F581F9C9D6953FABFA24E67105F0B614, 5A7BB72523D1C53BBE68700537D7AE0D150BC7E4B8227A916B2E29EE4CA267A9 ] WdiServiceHost  C:\Windows\system32\wdi.dll
12:48:46.0896 0x195c  WdiServiceHost - ok
12:48:46.0896 0x195c  [ F581F9C9D6953FABFA24E67105F0B614, 5A7BB72523D1C53BBE68700537D7AE0D150BC7E4B8227A916B2E29EE4CA267A9 ] WdiSystemHost   C:\Windows\system32\wdi.dll
12:48:46.0896 0x195c  WdiSystemHost - ok
12:48:46.0927 0x195c  [ A74AD6D80AC26E1B5DD276FC927F2BAC, F73F090D46BB2AAA6A8D148C658B2EA8C07B16201BB800A9283F4017DC249809 ] WdNisDrv        C:\Windows\system32\Drivers\WdNisDrv.sys
12:48:46.0927 0x195c  WdNisDrv - ok
12:48:46.0943 0x195c  WdNisSvc - ok
12:48:46.0974 0x195c  [ A70CAF5EA36CBA5FCA24244306D4D5C6, 76C3E20B62B89D9699A1E817377FAD70B144B877BCC5C850A5B64CC68184D8DA ] WebClient       C:\Windows\System32\webclnt.dll
12:48:46.0990 0x195c  WebClient - ok
12:48:47.0008 0x195c  [ 384E1D04FE20845B2559D292F17A9FA1, AD3B0B2B2219691AC30FEEC8AFDB3BBB74B51BB7D02038AE2B4DEA514E245315 ] Wecsvc          C:\Windows\system32\wecsvc.dll
12:48:47.0021 0x195c  Wecsvc - ok
12:48:47.0021 0x195c  [ 455014F4E48B67EBE0F032E2B0E06BF2, A36435784A034B27056A0E606683A20C69F1B0AB2B6BAEDEAEAA190F6287CAEF ] WEPHOSTSVC      C:\Windows\system32\wephostsvc.dll
12:48:47.0037 0x195c  WEPHOSTSVC - ok
12:48:47.0052 0x195c  [ F13DBA57CEA9B7074B95EDCA6AD2635E, 1D9BA4841EF1343A5D9096B5FE27FC65DC1901D6683DD13516171638549666B5 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
12:48:47.0052 0x195c  wercplsupport - ok
12:48:47.0068 0x195c  [ FD7E58B6AA3EABF2D12B9762A20E11E4, 4C5E2E246C5C70074866BB3DBC2AAF483ECE4345004CCB8D1FE285047268685D ] WerSvc          C:\Windows\System32\WerSvc.dll
12:48:47.0068 0x195c  WerSvc - ok
12:48:47.0099 0x195c  [ 715ABA3DD164D06457A2A3C92F6EA9D5, E6F8269D2FFC4A548B65724C0A3F53756ED15E47229861FBD40B656EE40FE166 ] WFPLWFS         C:\Windows\system32\DRIVERS\wfplwfs.sys
12:48:47.0115 0x195c  WFPLWFS - ok
12:48:47.0131 0x195c  [ 8C840E1FD7584E74BD0CC1EA581EC187, 148E534A94B4882E7396B13FABE17407802292E7890713540080D03D5629C81D ] WiaRpc          C:\Windows\System32\wiarpc.dll
12:48:47.0131 0x195c  WiaRpc - ok
12:48:47.0162 0x195c  [ 5F66B7BB330AA80067FC66149A692620, 92C5D7115A168A23108B65EEEB5FBA8FA43D781855355792596D2419160263C2 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
12:48:47.0162 0x195c  WIMMount - ok
12:48:47.0162 0x195c  WinDefend - ok
12:48:47.0210 0x195c  [ 0E70990EC2E5D2331AA5E88DB0CFB826, 79DFF565C3FCBC691E8FEB669CEC00E340FD2A2AFA4488D23A7CC63A2A98A5C1 ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
12:48:47.0225 0x195c  WinHttpAutoProxySvc - ok
12:48:47.0273 0x195c  [ FC8BD690321216C32BB58B035B6D5674, D61698DB19D9DB2593B60B6BA13F7B7735667206F41D751D507135469D6D3CDD ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
12:48:47.0287 0x195c  Winmgmt - ok
12:48:47.0365 0x195c  [ B56BFFFB740D76E634DB7B4802E36E4E, 2AA84756DE882463AE4C7BA0DCDEE3E5501DDF673ADD3F37B2B814FB0342E61F ] WinRM           C:\Windows\system32\WsmSvc.dll
12:48:47.0444 0x195c  WinRM - ok
12:48:47.0506 0x195c  [ 3AF1FA17F1C4ACBDB660D8F98B1A9C13, 99B0851410B462685F6705EBF832D10943FB9634030B02D15BF5D0C66F26F2C2 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
12:48:47.0506 0x195c  WinUsb - ok
12:48:47.0552 0x195c  [ F6F13FB009D43CE75FDBC35A5A46F9BB, 8F993BB0579129373F9B1A1EEAC1DA18A22B4E6089CAFA7BCAE4D12D1C2A9A03 ] WlanSvc         C:\Windows\System32\wlansvc.dll
12:48:47.0599 0x195c  WlanSvc - ok
12:48:47.0662 0x195c  [ 06BF5897949A8F24893F792E876B71F5, 9D3719492A86BF52A56E2EA798FD6FDB5862A03F6D360FCC4B0CEA9BE9792AE4 ] wlidsvc         C:\Windows\system32\wlidsvc.dll
12:48:47.0693 0x195c  wlidsvc - ok
12:48:47.0740 0x195c  [ 2834D9D3B4F554A39C72F00EA3F0E128, D10124343C67FE9A0B711AD569BB8080495FCEA0ECEF9AC3F3FBD6865F436A44 ] WmiAcpi         C:\Windows\System32\drivers\wmiacpi.sys
12:48:47.0740 0x195c  WmiAcpi - ok
12:48:47.0756 0x195c  [ B96F7A1236C3F21212DE2C40A3DDB005, 5A29EBB6DA036E303611EB1304192655021405BB05452FD37886DDE604FF0D9D ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
12:48:47.0756 0x195c  wmiApSrv - ok
12:48:47.0771 0x195c  WMPNetworkSvc - ok
12:48:47.0802 0x195c  [ 7FC5667DF73D4B04AA457CC3A4180E09, CB7B014945DCA16B6D120DBE0E5876C4C867A4ACD3C3536AEADC14B908613D4E ] Wof             C:\Windows\system32\drivers\Wof.sys
12:48:47.0802 0x195c  Wof - ok
12:48:47.0865 0x195c  [ EDFA5CEDBE174FAAA4A09A6B297AEA42, 5998FE15462E4AD9C7B1444E5E2C17BD470DA3A5D474A0A118E02E47DADC678A ] workfolderssvc  C:\Windows\system32\workfolderssvc.dll
12:48:47.0912 0x195c  workfolderssvc - ok
12:48:47.0959 0x195c  [ A2468CC3509394A33C4C32F99563D845, 62690C7D41F382DF74B8F4B942647842858E37DE35FF2DE028192E4D09ABB2C5 ] wpcfltr         C:\Windows\system32\DRIVERS\wpcfltr.sys
12:48:47.0959 0x195c  wpcfltr - ok
12:48:47.0975 0x195c  [ 19F4DF69876DA7E9C4965351560FE6B7, 127247A7964F55EE3AF842D25120F5ACD387632BEE2BF3D28FAC05840CEA19BA ] WPCSvc          C:\Windows\System32\wpcsvc.dll
12:48:47.0990 0x195c  WPCSvc - ok
12:48:48.0021 0x195c  [ 25BE82B325AC22FE563A58A1AC29F4C1, 4247BAA9A44C964446F81ED44F18B28F1F730F46851EC2B756BAC57FB9D86700 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
12:48:48.0021 0x195c  WPDBusEnum - ok
12:48:48.0037 0x195c  [ 9F2904B55F6CECCD1A8D986B5CE2609A, E19ED4DD3CEF3A22C058FC324824604FB3FC98A029C94E6C2A3389F938D680B6 ] WpdUpFltr       C:\Windows\system32\drivers\WpdUpFltr.sys
12:48:48.0037 0x195c  WpdUpFltr - ok
12:48:48.0054 0x195c  [ AE072B0339D0A18E455DC21666CAD572, AB1DAEA25E2C7AD610818D4B4783F6D4190D85EBB3963BBAD410E8CEA7899EDB ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
12:48:48.0054 0x195c  ws2ifsl - ok
12:48:48.0086 0x195c  [ 501D5EFAB9711039479AE48401386D2B, C8C1184DE93E9D2C4E8A60E4E9980745C4E5470E5DA9B59165D18705330ADEFE ] wscsvc          C:\Windows\System32\wscsvc.dll
12:48:48.0086 0x195c  wscsvc - ok
12:48:48.0102 0x195c  WSearch - ok
12:48:48.0133 0x195c  [ 552BD369EF502489AF40899BDBFF35C6, 000ED5C07308C80358DE61B7E416AE87603A294DA377100F353DC6FD4657D032 ] wsnm            C:\Program Files (x86)\VMware\VMware Horizon View Client\wsnm\wsnm.exe
12:48:48.0148 0x195c  wsnm - ok
12:48:48.0273 0x195c  [ 6B2D71124C1EA86B74412F414C42431D, 078CC6C9667EF6BDA3E6900BC26A5A5B030CAA66928A6BBB7B7DC43C5C199EDC ] WSService       C:\Windows\System32\WSService.dll
12:48:48.0352 0x195c  WSService - ok
12:48:48.0461 0x195c  [ F8AAE8C41092D195C470EE7EF2D0BB01, D02B608244D084669632F60CC977BA10A9A5F7CEA73F15A8ADE6BF9EFE8C4052 ] wuauserv        C:\Windows\system32\wuaueng.dll
12:48:48.0571 0x195c  wuauserv - ok
12:48:48.0602 0x195c  [ 481286719402E4BAEFEA0604AB1B5113, F3CF65DF2AB39F79AE4C1335831408418E40726706E0242677E8B96B0FAD988F ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
12:48:48.0602 0x195c  WudfPf - ok
12:48:48.0633 0x195c  [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFRd          C:\Windows\System32\drivers\WUDFRd.sys
12:48:48.0633 0x195c  WUDFRd - ok
12:48:48.0649 0x195c  [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFSensorLP    C:\Windows\system32\DRIVERS\WUDFRd.sys
12:48:48.0649 0x195c  WUDFSensorLP - ok
12:48:48.0665 0x195c  [ 51D28F7F1F888DDCF2C67DCF3B79A5D3, 74FF2936AFCEB9A36175D5B00EB91A5AD614B52BE3FB3FA9B994A025A484D2B7 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
12:48:48.0665 0x195c  wudfsvc - ok
12:48:48.0681 0x195c  [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFWpdFs       C:\Windows\system32\DRIVERS\WUDFRd.sys
12:48:48.0695 0x195c  WUDFWpdFs - ok
12:48:48.0711 0x195c  [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFWpdMtp      C:\Windows\system32\DRIVERS\WUDFRd.sys
12:48:48.0711 0x195c  WUDFWpdMtp - ok
12:48:48.0728 0x195c  [ A0900F8F628B5AF6841414EB3CF11E50, 8A531F2472FF4B4D895D469D28C215C834ECADBEF539894B8F3F606079A86184 ] WwanSvc         C:\Windows\System32\wwansvc.dll
12:48:48.0758 0x195c  WwanSvc - ok
12:48:48.0773 0x195c  ================ Scan global ===============================
12:48:48.0789 0x195c  [ 3500AF0BA2EF095BF313EEB75D2366C6, C755E57B02BFA82151A182DF964349859575570EA5C3FBA81F747B8D2134A4D0 ] C:\Windows\system32\basesrv.dll
12:48:48.0820 0x195c  [ EAB311B0A7A8EA0346F14F08D4BC8F46, 11168E4074679F8A69DA714C0ABD0C68BA49D171B379343F14783C9C563202CA ] C:\Windows\system32\winsrv.dll
12:48:48.0836 0x195c  [ 3600ED7EA8AED849E20700551C0BD63B, 4A8C346C1646E80B58EF93F87F915A41E05CA2E993BB1C96955AE62A0669AF66 ] C:\Windows\system32\sxssrv.dll
12:48:48.0867 0x195c  [ E0C7813A97CA7947FF5C18A8F3B61A45, 083BB4F3B20419C87DB656F1465E5F782ACDE76838CDE6207F26AAD035C69DE0 ] C:\Windows\system32\services.exe
12:48:48.0883 0x195c  [ Global ] - ok
12:48:48.0883 0x195c  ================ Scan MBR ==================================
12:48:48.0899 0x195c  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
12:48:48.0914 0x195c  \Device\Harddisk0\DR0 - ok
12:48:48.0914 0x195c  ================ Scan VBR ==================================
12:48:48.0930 0x195c  [ 7B6E0BBDB7BB60CBDAC4EA9DBBCFB1D1 ] \Device\Harddisk0\DR0\Partition1
12:48:48.0930 0x195c  \Device\Harddisk0\DR0\Partition1 - ok
12:48:48.0945 0x195c  [ 725FF3117B2345BE9DDD1B451FCC0501 ] \Device\Harddisk0\DR0\Partition2
12:48:48.0945 0x195c  \Device\Harddisk0\DR0\Partition2 - ok
12:48:48.0962 0x195c  [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
12:48:48.0962 0x195c  \Device\Harddisk0\DR0\Partition3 - ok
12:48:48.0977 0x195c  [ 9A46419798180A728FEAE1618C879082 ] \Device\Harddisk0\DR0\Partition4
12:48:48.0977 0x195c  \Device\Harddisk0\DR0\Partition4 - ok
12:48:48.0977 0x195c  ================ Scan generic autorun ======================
12:48:49.0039 0x195c  [ 1F918DDAE59E246B8F48CE5AA400B3AA, 8896809E855AE08B43E41B25A6BDCA8ED1905BBFC59E7B779070EAA0BBC1B319 ] C:\Program Files\IDT\WDM\sttray64.exe
12:48:49.0117 0x195c  SysTrayApp - ok
12:48:49.0133 0x195c  [ 96A1D93D16F959C6F5A63E749A9F2EF7, 9EDD4EEC5C625ECF4A1C82318ED6B74404E63A3D43312B53E4F627D76D47658C ] C:\Program Files\IDT\WDM\beats64.exe
12:48:49.0133 0x195c  BeatsOSDApp - ok
12:48:49.0164 0x195c  [ A8E816B1969A6287C77FFA7F6A4B0AFA, 1B29779F287D28A5F89A64AEDDF3F3BE5E14CFEAFAB0A7C574A5012F9070A4C8 ] C:\Program Files\Common Files\VMware\DeviceRedirectionCommon\ftnliu.exe
12:48:49.0164 0x195c  VMware Netlink 3 HV Install Utility - ok
12:48:49.0211 0x195c  [ 64D89BDA981ECD2BC9B547E4210CA6E0, 403F685FBC8A71896F550476C3E3CAAC0D593F7CF25D4A2F61ED62D576E62F12 ] C:\Program Files\iTunes\iTunesHelper.exe
12:48:49.0211 0x195c  iTunesHelper - ok
12:48:49.0211 0x195c  WindowsDefender - ok
12:48:49.0289 0x195c  Skype for Desktop - ok
12:48:49.0305 0x195c  Waiting for KSN requests completion. In queue: 106
12:48:50.0461 0x195c  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.10.209.0 ), 0x61100 ( enabled : updated )
12:48:50.0493 0x195c  Win FW state via NFP2: enabled ( trusted )
12:48:50.0743 0x195c  ============================================================
12:48:50.0743 0x195c  Scan finished
12:48:50.0743 0x195c  ============================================================
12:48:50.0743 0x1948  Detected object count: 0
12:48:50.0743 0x1948  Actual detected object count: 0
 

 

 

Currently running MBAR. Also, searching for services.msc, where do I search? Elevated command prompt? I tried going through control panel and didn't find Administrative tools or  Services.

 

*Edit* MBAR found no malware. 


Edited by Himynameiskyle, 05 December 2017 - 01:04 PM.

  • 0

#21
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

I also tried to change the permissions for the reg entry. I got access denied. I found it in the registry, but I right clicked and went to permissions. Was that right?


  • 0

#22
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

TDSSKiller seems happy.

 

You have to go in to regedit and change ownership of the

HKEY_CLASSES_ROOT\AppID\{9BA05972-F6A8-11CF-A442-00A0C90A8F39} key

https://www.howtogee...y-in-windows-7/

 

Once you are the owner then you can change to Full Control.


  • 0

#23
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

So instead of access denied it now says unable to save. I clicked on each System and then Administrator and tried it for both and got the same thing. Do I need to uncheck read on those or does that not even matter? *Edit* I guess the error message was the same as before. I just didn't realize that it said unable to save. I'm doing everything right. Any ideas? I see that the only thing that has full control is "Trusted Installer", do I need to uncheck that first before applying the new permissions?

 

Okay so I clicked advanced like the instructions in the link you provided and her dialogue box is slightly different. "Owner" is not a tab like it is in the instructions. I looked them up for Windows 8 and other instructions show screenshots that show "Owner" as a tab. Hers has owner at the top and then says trusted installer with "change" as a option to press. When I go there that is where I get confused. It's a bunch of other options that I don't see in other instructions.


Edited by Himynameiskyle, 08 December 2017 - 11:53 AM.

  • 0

#24
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Make sure that after you take ownership that you close the key then reopen it by clicking on some other key then coming back to this key before trying to make changes to the permissions.

 

This is what mine looks like now:

[attachment=86348:regown.JPG]

 

You see the owner line at the top?  To the right is a Change button.  Click it and it should let you change the owner.

 

(Make sure you check the bottom box then Apply so that all of the sub stuff gets changed)

 

[attachment=86349:regperm.JPG]


  • 0

#25
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

Okay so I do that and it opens another box that says object types. Then I can enter names below, I type SYSTEM and Administrators there?

 

*Edit* She might have Windows 8.1 and I noticed that bit at the bottom. Ever hear of the freeware RegOwnit?

 

https://www.maketech...-registry-keys/
 


Edited by Himynameiskyle, 08 December 2017 - 12:20 PM.

  • 0

Advertisements


#26
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

You can only have one owner so make it Administrators.

 

Once you type in administrators there is a box that says Check Names.  You can click on that and it will make sure you typed it right and change it to your PC name\Administrators. Then OK out of it.

 

Go back into Permissions and then you should be able to check Full Control for System & Administrator and when you Apply it should take them.


  • 0

#27
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

Okay so I got the ownership changed, that worked. I also went into Launch and Activate, I added SYSTEM, but it already had full control. I didn't have to check those boxes for it.  Standing by.


  • 0

#28
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Copy the next line:

for /F "tokens=*" %1 in ('wevtutil.exe el') DO wevtutil.exe cl "%1"

Open an elevated command prompt:

Win 10: http://www.howtogeek...-in-windows-10/
Win 8: http://www.eightforu...indows-8-a.html

If you open an elevated command prompt it will by default open in c:\Windows\system32

Once you have an elevated command prompt:
 

right click and paste or edit then paste and hit enter.

 

You will get a few errors. Ignore them.  Reboot.

 

run vew as before:

 

2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.  (Each time you run VEW it overwrites the log so copy the first one to a Reply or rename it before running it a second time.)



 


  • 0

#29
Himynameiskyle

Himynameiskyle

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts

Vino's Event Viewer v01c run on Windows 7 in English
Report run at 09/12/2017 5:43:11 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

Vino's Event Viewer v01c run on Windows 7 in English
Report run at 09/12/2017 5:44:48 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


  • 0

#30
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Did you reboot before running VEW?

 

How is it running now?


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP