HerrMetik | 24.04.2016 14:34 | Schritt 2 Teil 2
Logfile TDSSKiller [Part 2 o2]: Code:
15:29:06.0256 0x1dec [ 96D604A35070360F0DD4A7A8AF410B5E, F94DD1A3566C7C8D0A76D6E1E2530552A9B7F99C5DA0DE11829325EAB9F8B7ED ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys
15:29:06.0266 0x1dec MTConfig - ok
15:29:06.0290 0x1dec [ 619CA29326B82372621DB2C0964D8365, 4091F08E266DB45A6E33A4A8B1CE9FA78BB294B3111526AA9E3868620F30AFDF ] Mup C:\WINDOWS\system32\Drivers\mup.sys
15:29:06.0301 0x1dec Mup - ok
15:29:06.0319 0x1dec [ B8C35C94DCB2DFEAF03BB42131F2F77F, F0FCF367CA8F722D6ABCF7F363CD406D890D71452E91C3FC6677B47AD74D6324 ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys
15:29:06.0331 0x1dec mvumis - ok
15:29:06.0388 0x1dec [ 8DF30698BDD9492A9D45A4B94FB4A82A, 26B1B2D7E785E29B8BCB74C467C66AE4EBDD481ACFF36334F3BDF4506B778244 ] napagent C:\WINDOWS\system32\qagentRT.dll
15:29:06.0411 0x1dec napagent - ok
15:29:06.0475 0x1dec [ 008F7CED69FD5B30CBDE1E03C6F36A27, D4ADA7834C470B17A3CD976012DC5A511B32545B9F91D23D09A85722E0B75320 ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys
15:29:06.0495 0x1dec NativeWifiP - ok
15:29:06.0574 0x1dec [ E0E4A1F81A7D69C595A8A9DDAD084C19, 8F55F3637AE8BFFB0ACE37AFC5122026525137E0B2923899B779C1BD08DF0E22 ] NAUpdate C:\Program Files (x86)\Nero\Update\NASvc.exe
15:29:06.0595 0x1dec NAUpdate - ok
15:29:06.0645 0x1dec [ BFCE1225D10619029E68946929CEB64C, 499F560331FFBA82E3D673B47F027FDAB7BEE4F2CB5B811D69E0218839F6E6A5 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll
15:29:06.0660 0x1dec NcaSvc - ok
15:29:06.0710 0x1dec [ 267C97373110B7AFD3B46DF60B6CBB85, CEBB99F71D47634BB9C04DF2836DF6B47F15B3073FEFC237F85526DF01E4E38B ] NcbService C:\WINDOWS\System32\ncbservice.dll
15:29:06.0726 0x1dec NcbService - ok
15:29:06.0777 0x1dec [ 0813B71EAF097208DC76CE0605B48AF0, A93A2E6A8FB77B58AC4D580E6F8BF307A25BADC9493994F9BE235EBFB0E1DB22 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll
15:29:06.0791 0x1dec NcdAutoSetup - ok
15:29:06.0893 0x1dec [ 97DC5967F65503213FD1F1B3E4A6F983, 3EC515856C7CE9B30032F963DC04190F66EE62402A819781DC45B7D088C84229 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys
15:29:06.0929 0x1dec NDIS - ok
15:29:06.0985 0x1dec [ 8CECC8DA55F3274181FD1EA28AD76664, 188112424CEF97FB926A0FB915260B803555A775DD2E1846725A9C8616300F42 ] NdisCap C:\WINDOWS\system32\DRIVERS\ndiscap.sys
15:29:06.0997 0x1dec NdisCap - ok
15:29:07.0015 0x1dec [ 269882812E9A68FFF1AFE1283D428322, 50B99EBC42DA9B46A8C2C28C9BADCF58AE3079535CDD1227D0F5C86291C715FF ] NdisImPlatform C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
15:29:07.0028 0x1dec NdisImPlatform - ok
15:29:07.0041 0x1dec [ 82821F4EEC776B4CF11695A38F3ABA46, 23184F9D31E662855DC4D23EFE7C2FE00E5487D3762B6024704A5D8C87762E1C ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
15:29:07.0051 0x1dec NdisTapi - ok
15:29:07.0102 0x1dec [ B832B35055BA2B7B4181861FF94D8E59, 2E60E5D503E88D27E35ECFEE265D51328E93A9C7B9B931F86D9CBC947636BB00 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
15:29:07.0114 0x1dec Ndisuio - ok
15:29:07.0125 0x1dec [ 1F58E48EF75F34C35D8E93A0DC535CFE, D65619A6C4B1747F8B05DA08A44EF0E46B5CC384880E04E4755A2BA6CDB3C4EA ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
15:29:07.0137 0x1dec NdisVirtualBus - ok
15:29:07.0153 0x1dec [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
15:29:07.0170 0x1dec NdisWan - ok
15:29:07.0178 0x1dec [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWanLegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys
15:29:07.0195 0x1dec NdisWanLegacy - ok
15:29:07.0245 0x1dec [ DDD7F92A83F74D1476B71FBA9530A8DC, D3F94FC9F48854E09B0B77CE5E1C1DB948D54EAC63C5583437051BB893B5A386 ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
15:29:07.0257 0x1dec NDProxy - ok
15:29:07.0278 0x1dec [ 3083926D1CC5B56EA0786527B557DD1B, 3C3F0CA0D43398576DBE8F677B353ADDA7E8F56829874958CE668E31261C1590 ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys
15:29:07.0291 0x1dec Ndu - ok
15:29:07.0348 0x1dec [ 42FF4975D032CAE558AE4BB8448F6E5A, 0B8FACF3382443DED79A8004A6AA14C32471A6A1C6BAA543AA9F3FEC52620A6D ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
15:29:07.0360 0x1dec NetBIOS - ok
15:29:07.0382 0x1dec [ 0217532E19A748F0E5D569307363D5FD, C40C2E7AFA276057E7327A7BB173122689D6CEC9AE443C3850C3F94AF03DFBF5 ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
15:29:07.0398 0x1dec NetBT - ok
15:29:07.0414 0x1dec [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] Netlogon C:\WINDOWS\system32\lsass.exe
15:29:07.0426 0x1dec Netlogon - ok
15:29:07.0484 0x1dec [ 8F074B62E66B6117D9598C62A12069C5, 5FDB19045D3E2F6D0F0C5158AC2ECB0D5404CD2AF7A319755D7E3753CA3B7CF3 ] Netman C:\WINDOWS\System32\netman.dll
15:29:07.0502 0x1dec Netman - ok
15:29:07.0569 0x1dec [ 4A04B1CD5BFB4A978C5F60E86D6C3E45, A946922C1C38ADD3CF9D3B09DDCC301AE4DAC960A081B2F42B32BE1E7095B3FD ] netprofm C:\WINDOWS\System32\netprofmsvc.dll
15:29:07.0594 0x1dec netprofm - ok
15:29:07.0662 0x1dec [ 1092B3190E69E0C5ECBCE90F171DE047, C16106EEFC324EE80E5F659CB71A5DD69FA800D36D829F5B0E6AD3393BD1BAF7 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:29:07.0673 0x1dec NetTcpPortSharing - ok
15:29:07.0723 0x1dec [ D4DCE03870314D3354F3501F9DDD4123, 5BFE8299B3F72B8C39A4965365CBF5BA151024451F02DD872FAD1CC35CF94CEA ] netvsc C:\WINDOWS\System32\drivers\netvsc63.sys
15:29:07.0735 0x1dec netvsc - ok
15:29:07.0798 0x1dec [ E94EB2A95D7D016E119C4D6868788831, 3E4A925D23262FBA0A6432DD635FBE94B0CEF76BD9BB323254B66977497FEE2A ] NlaSvc C:\WINDOWS\System32\nlasvc.dll
15:29:07.0818 0x1dec NlaSvc - ok
15:29:07.0833 0x1dec [ 1381E95D4E0F94F22DD484B5F8C1D61D, E91C10A62E3B5A610063F48354C6F4A1AAB7300A69EAD59E89ED8EEFDBD99062 ] nmwcd C:\WINDOWS\system32\drivers\ccdcmbx64.sys
15:29:07.0852 0x1dec nmwcd - ok
15:29:07.0878 0x1dec [ 205510CDB7B6084BF31760B5D06F9242, F3EAC6A7127DC5A0FEE7A9AFA561A8CA9B6E83FECCD731C890E85C33514B533B ] nmwcdc C:\WINDOWS\system32\drivers\ccdcmbox64.sys
15:29:07.0898 0x1dec nmwcdc - ok
15:29:08.0036 0x1dec [ FD8082D64C151589F12A4F620DBA3030, 649D61BF958ED50C0B5F7E0D2E633D20C8AAA00706A7AE9528DA78E2B6B3492E ] NOBU C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
15:29:08.0130 0x1dec NOBU - ok
15:29:08.0190 0x1dec [ 8F44A2F57C9F1A19AC9C6288C10FB351, 310274DDBAC0FE4BE54ECD3B90C97D82A0F9F5CFCA7A35711A36164DE4B94074 ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
15:29:08.0202 0x1dec Npfs - ok
15:29:08.0246 0x1dec [ CBDB4F0871C88DF930FC0E8588CA67FC, 7E4AA3EA81A9D532F236FD7896744F07ED07CA9B37A9F18A9778BCCCC67490F2 ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys
15:29:08.0256 0x1dec npsvctrig - ok
15:29:08.0301 0x1dec [ 0F12A72A753CFD7FB0631EE8D08FE983, 860A96471F6CD90DDA9AB3A48E95CEAD826C87D2FA98A00EF91B61C44A4C8B82 ] nsi C:\WINDOWS\system32\nsisvc.dll
15:29:08.0315 0x1dec nsi - ok
15:29:08.0370 0x1dec [ 0E046FF5823B95326D10CF1B4AF23541, 39D22715003746527AB4BFEDED8C34B695DAF589091AE7F3A2A2C4B8A35675A9 ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys
15:29:08.0381 0x1dec nsiproxy - ok
15:29:08.0482 0x1dec [ 9980B262DBE439AE6BDC91AA985F19EE, E998E4CAE9CD103ADA9CA3C737C4DAD017D056828BFA42A41C7B4E4E108FB13C ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
15:29:08.0542 0x1dec Ntfs - ok
15:29:08.0554 0x1dec [ EF1B290FC9F0E47CC0B537292BEE5904, DBC07BBC54EBC2D2E576B23A4CE116B3DA988577AD0D96CB7289A6748A60F9EA ] Null C:\WINDOWS\system32\drivers\Null.sys
15:29:08.0565 0x1dec Null - ok
15:29:08.0585 0x1dec [ BC6B5942AFF25EBAF62DE43C3807EDF8, CB0FA194084B8C309039D571B5760FDA800E9531B8660C499B4F9977BA5C36D5 ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys
15:29:08.0598 0x1dec nvraid - ok
15:29:08.0621 0x1dec [ 1F43ABFFAC3D6CA356851D517392966E, 6FD7621F67BA94B0E1D8F43BEC2951DBCDEEA1E848BB265AC169E27C01DA68F2 ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys
15:29:08.0634 0x1dec nvstor - ok
15:29:08.0653 0x1dec [ 6934A936A7369DFE37B7DBA93F5E5E49, 0900FEEB0CE8D09F0FC60630B5B986034A8BCD3882ED66E47170810C32492892 ] nv_agp C:\WINDOWS\system32\drivers\nv_agp.sys
15:29:08.0666 0x1dec nv_agp - ok
15:29:08.0739 0x1dec [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:29:08.0749 0x1dec ose - ok
15:29:08.0959 0x1dec [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA609268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
15:29:09.0072 0x1dec osppsvc - ok
15:29:09.0140 0x1dec [ 26657F3B4F39A0E64AF859278B599C4E, 3DD65E0BCEF3045DBA29FB8171CA3FCC9781AED3A1C7A160CF26388CE80A3683 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll
15:29:09.0160 0x1dec p2pimsvc - ok
15:29:09.0224 0x1dec [ FD8F61F0D1F64BBB3D835F39A3F979C9, E5C5F86576488EA7F605E26C06EE5AFB36506A446F60C894D55E0A148BF7F02D ] p2psvc C:\WINDOWS\system32\p2psvc.dll
15:29:09.0245 0x1dec p2psvc - ok
15:29:09.0304 0x1dec [ 764B1121867B2D9B31C491668AC72B2B, 32C04B6FCE1DDD09697B81473A23BDCED8BEEFBCD0D2D58DDC9A11A33C756967 ] Parport C:\WINDOWS\System32\drivers\parport.sys
15:29:09.0316 0x1dec Parport - ok
15:29:09.0362 0x1dec [ BAFF6122CFC9F95CA175AD8C348179A4, 079A912D951DF6A57BC1BDB0D182977EE9592751EC9DDCDA2932BDEDB333850C ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys
15:29:09.0373 0x1dec partmgr - ok
15:29:09.0446 0x1dec [ ABE95ABE27A8BD9701782BBCD82C9925, AE3BA1E9ECDE692374D8DAC95A8DAA289DD2470E3D8D58EFAD9F83A37F3AC8E5 ] PcaSvc C:\WINDOWS\System32\pcasvc.dll
15:29:09.0468 0x1dec PcaSvc - ok
15:29:09.0528 0x1dec [ 91ED124E261EA8FAA1C0FFDF2A71B0C4, 20E41A38067395D03184938983A9BE459717A1941352972DBC28D83D542319EC ] pci C:\WINDOWS\system32\drivers\pci.sys
15:29:09.0544 0x1dec pci - ok
15:29:09.0559 0x1dec [ 346E38FCC6859A727DD28AFAD1F0AFF4, FF3DA26F79B3BC3A5B8A8AA0B9139B9EF70297F4EA1203B1E68FB5A212C3AA58 ] pciide C:\WINDOWS\system32\drivers\pciide.sys
15:29:09.0568 0x1dec pciide - ok
15:29:09.0596 0x1dec [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397, 27A7AF2127B699F4579CB77936F38DC102211E26E5E2947DB808756FE06FC98E ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys
15:29:09.0608 0x1dec pcmcia - ok
15:29:09.0620 0x1dec [ BF28771D1436C88BE1D297D3098B0F7D, 5F7630916A76A8CF31289E9C577F522B999C74C39E541CD40E62BD53004BEF74 ] pcw C:\WINDOWS\system32\drivers\pcw.sys
15:29:09.0631 0x1dec pcw - ok
15:29:09.0687 0x1dec [ 24A8DFC07E4BAF29AEA26E383D4CC886, 1B903FE52CD816662D37A8113930B4B7019B6996D49F1982D8F42933A3525A67 ] pdc C:\WINDOWS\system32\drivers\pdc.sys
15:29:09.0698 0x1dec pdc - ok
15:29:09.0790 0x1dec [ 8F98C4BC605261B4B6E568FE791EB67A, 7B0D99D972A60423F7378BEE886061695FDA79B59AFF939744A130721E0174A1 ] PDF Architect 2 C:\Program Files (x86)\PDF Architect 2\ws.exe
15:29:09.0833 0x1dec PDF Architect 2 - ok
15:29:09.0892 0x1dec [ 9077A3059AB47834633AEAAED465F3D9, 9CA662E9CBA30795E4E5DAB3E309D2062FFDC2053C261054E24EF7EE5300F69F ] pdfforge CrashHandler C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe
15:29:09.0915 0x1dec pdfforge CrashHandler - ok
15:29:09.0982 0x1dec [ 0ECEE590F2E2EF969FB74A6FC583A1E6, 1C611D9225C863CF32125F684B324C58BDE1942F4F283F5674133200AC505D44 ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys
15:29:10.0006 0x1dec PEAUTH - ok
15:29:10.0106 0x1dec [ 8E3C640FFF5A963F570233AE99C0FFF3, 3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe
15:29:10.0123 0x1dec PerfHost - ok
15:29:10.0211 0x1dec [ 70B39E7241F750A248798CE82C44596D, 54A72199EB277EE586611DCBC21654786FD2196F91D5884C4F531297893CC3EC ] pla C:\WINDOWS\system32\pla.dll
15:29:10.0257 0x1dec pla - ok
15:29:10.0313 0x1dec [ 2C02AFF8383D893F8DBEB07A84F6E77C, 7CC34BAC67E2988E3D16DD6EB6F6785CD2460E3EF7FBD0BD5F86E49793BD473E ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll
15:29:10.0330 0x1dec PlugPlay - ok
15:29:10.0373 0x1dec [ 4570F8A37D221660F3A09D6F4DD4BA94, 0EA190CFFA53DF9CCA2D53A4EF1BCB837BA3F2489A3AC5BD11F6D6ED811D118E ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll
15:29:10.0385 0x1dec PNRPAutoReg - ok
15:29:10.0406 0x1dec [ 26657F3B4F39A0E64AF859278B599C4E, 3DD65E0BCEF3045DBA29FB8171CA3FCC9781AED3A1C7A160CF26388CE80A3683 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll
15:29:10.0426 0x1dec PNRPsvc - ok
15:29:10.0484 0x1dec [ BDD52AB4AEBB8B1904568DBD0CCB70CB, C3D1DBA349C79B43DCDD9EF5255C5EE973EFB844235B808B5EF9B63A51FF00AA ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll
15:29:10.0504 0x1dec PolicyAgent - ok
15:29:10.0528 0x1dec [ C8DD82C3035E60D671B8CC5DF128D3A9, 6AABF632CBEDA9A7B553BC9134FF100CB6FDC88000D499D2883408FCEDD97576 ] Power C:\WINDOWS\system32\umpo.dll
15:29:10.0542 0x1dec Power - ok
15:29:10.0694 0x1dec [ E3514CE7CB4AF80ECCA383F065BC77C0, 1EA06D358A07EB9DFB703CEFC4EB834B947B899E0ACFE1C494E2DAED63F1D4B5 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll
15:29:10.0767 0x1dec PrintNotify - ok
15:29:10.0820 0x1dec [ ECD373F9571C745894367CC2635EA44F, E08B2A1017DAE1BF10B986DAFAD14BDE20D79703E0EF3A8C700A3753908C1392 ] Processor C:\WINDOWS\System32\drivers\processr.sys
15:29:10.0832 0x1dec Processor - ok
15:29:10.0896 0x1dec [ 6E409D818C6B342544EAE741B1422B85, B4ADFB7809FC42C432C984C3AC13FAFD1B7AD53BCC7FB16E86371DE4C829DD1A ] ProfSvc C:\WINDOWS\system32\profsvc.dll
15:29:10.0914 0x1dec ProfSvc - ok
15:29:10.0965 0x1dec [ FC0141B4A5AD6D637D883C1A89FC45C5, DCE8942C02EEDAE7A57707CA60CAC3A8CD6BA68E6571E405CA882D4DD6D69E43 ] Psched C:\WINDOWS\system32\DRIVERS\pacer.sys
15:29:10.0979 0x1dec Psched - ok
15:29:11.0038 0x1dec [ DAA9DEE0A5D5F238C4EE54C2C7FB67C5, 7EC8C603BD92699AC35BDCD294F13BEE90D5C2C195FD93A3F16928BFCF53CA93 ] QWAVE C:\WINDOWS\system32\qwave.dll
15:29:11.0057 0x1dec QWAVE - ok
15:29:11.0109 0x1dec [ 83868EB2924E6BC21A54337C65D614D1, 8D1BE01EBD190231153B867C32120DC8FBFBD32050448A778134D435D76A0B07 ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys
15:29:11.0120 0x1dec QWAVEdrv - ok
15:29:11.0205 0x1dec [ 16327C2B25A82ABD16F92DD72B26489D, F37F76222993938322FE3BD5494AA3CC9D4678F1E34FE5E0580515AA144048AF ] RadeonPro Support Service C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe
15:29:11.0212 0x1dec RadeonPro Support Service - detected UnsignedFile.Multi.Generic ( 1 )
15:29:13.0682 0x1dec RadeonPro Support Service ( UnsignedFile.Multi.Generic ) - warning
15:29:16.0092 0x1dec [ E94067155C8AA4EF134CB2528E0C9CD7, 6EEF603F64827AB138930DFE379BF8E48E64AE8AA5EE7B9E0CA369022BAAA2EA ] RadioShim C:\WINDOWS\System32\drivers\RadioShim.sys
15:29:16.0099 0x1dec RadioShim - ok
15:29:16.0116 0x1dec [ B337B1F1E82A83E20A1743E008E25C0F, A2E8AF041B4CAB78AEE28A2147A189FF0F9D2FCEFB167D60FBBA0A787A5A5BE7 ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
15:29:16.0128 0x1dec RasAcd - ok
15:29:16.0185 0x1dec [ 044638489B4A5FE5334F46C5314A0826, E06CC2A9EF369794DAD69FBB5AFD1676D4283DDAB2AD5E3EFE454C473F62F955 ] RasAuto C:\WINDOWS\System32\rasauto.dll
15:29:16.0200 0x1dec RasAuto - ok
15:29:16.0266 0x1dec [ F83B38FCD4F69157B3D158433FA149CC, AB103BD3E2B3B134CB355C556DF70BCF0CF4DB11EFF7DB4A9876D5AA43D81293 ] RasMan C:\WINDOWS\System32\rasmans.dll
15:29:16.0291 0x1dec RasMan - ok
15:29:16.0347 0x1dec [ 5247F308C4103CDC4FE12AE1D235800A, E567CD33CA1897D53795E071B7AFBAF98B2C8F725F8BED0BA90F5EF611520E48 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
15:29:16.0361 0x1dec RasPppoe - ok
15:29:16.0419 0x1dec [ A1A5E79C0D1352AFDC08328A623DA051, 01546DDE6F1FF159A7EB7F2BF104910445D3D863F1F37DEA695579BA60D84280 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
15:29:16.0437 0x1dec rdbss - ok
15:29:16.0491 0x1dec [ 6B21EBF892CD8CACB71669B35AB5DE32, 0AD8E14FEF16FB2559F5FC8AFBC9D49E4E24F43CF65F480DBF9FAB593269B419 ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys
15:29:16.0501 0x1dec rdpbus - ok
15:29:16.0511 0x1dec [ 680C1DAE268B6FB67FA21B389A8B79EF, 856911F77BDD8830C3D683EBE8AF399FB3A54C7D8D0B34EA37D903377F0A39BD ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys
15:29:16.0525 0x1dec RDPDR - ok
15:29:16.0584 0x1dec [ BC8A79C625568DDB7DCA49D0C2741A64, AB0A7ED9EC2282EC0356D27EA4F70515943E41C2112428B787636B8BEC278933 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
15:29:16.0594 0x1dec RdpVideoMiniport - ok
15:29:16.0646 0x1dec [ A26AEC49F318FEE141DDDB2C5F99B3E6, 246AD79FF27E79DEDCB0AAA7C22A8EA6349DEDAC863413A1E378E68FD94C9C4F ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys
15:29:16.0662 0x1dec rdyboost - ok
15:29:16.0734 0x1dec [ 615DFD97DEA56CE1C3A52185A3038FF8, 707BF5F9FAE478A12656D15013F507CC1335E7B72BD21CA99BB813CB95E37BC0 ] ReFS C:\WINDOWS\system32\drivers\ReFS.sys
15:29:16.0765 0x1dec ReFS - ok
15:29:16.0814 0x1dec [ 0CF7CB56BF2D5E9DBCEE0185CB626FAD, 2BD2E2FB1D2EADD1F70EF55E8523C353F95D4FEB1BAD5017FA4D94F790F27825 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
15:29:16.0831 0x1dec RemoteAccess - ok
15:29:16.0893 0x1dec [ AC8785B53F8436058C90450DA1840AE7, CC1FFC2713910211F8A6AD532DBB9253ACD188CBD784F1BE6613DF382825A3C1 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
15:29:16.0909 0x1dec RemoteRegistry - ok
15:29:17.0156 0x1dec [ 813B179ABA2E31CA2B146ACFFAB2AF1C, 82CF1E7EC6E62F423CDA4B67F310B7BBBBEEFA9856D31F4BE031FF3455D53A37 ] ReportServer C:\Program Files\Microsoft SQL Server\MSRS12.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
15:29:17.0217 0x1dec ReportServer - ok
15:29:17.0275 0x1dec [ DC66AE45816614D2999DCD3834DCCC4E, 1C26225135E851DDD1307F52401DD7055B26B3F3B8FDD693B21042C2896E235A ] RFCOMM C:\WINDOWS\System32\drivers\rfcomm.sys
15:29:17.0289 0x1dec RFCOMM - ok
15:29:17.0350 0x1dec [ 65B9FDE300A6DECC03BA44C4616DCAD6, CAD992982733DD20282A3453DC4E554AE1FC077C35479C0CA4E8BC3A9DCD3BB0 ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll
15:29:17.0366 0x1dec RpcEptMapper - ok
15:29:17.0383 0x1b8c Object required for P2P: [ C35B91B6777E7C6DB67B8583D2AA66A7 ] c2cpnrsvc
15:29:17.0415 0x1dec [ A737B433ABAF3F2DCB2BD7B4CC582B26, 3B5706B0CF0969A9F82060FD4DCC745F2D83C066B663FE8A4F0F493B64032C9C ] RpcLocator C:\WINDOWS\system32\locator.exe
15:29:17.0427 0x1dec RpcLocator - ok
15:29:17.0466 0x1dec [ E4220FD9C7F1579D9C5F9DFB00427841, 77740122A01A08F18CC82A4BB3F00EC59F29EE10779092F872572C264F6728D0 ] RpcSs C:\WINDOWS\system32\rpcss.dll
15:29:17.0496 0x1dec RpcSs - ok
15:29:17.0548 0x1dec [ E2319BDFF45DC9600E3751BE690F044D, 93F7A1EB1DB5F5CD41846F8D1DD5F08569DDE55AB125A01131B4ED20C322B956 ] RsFx0310 C:\WINDOWS\system32\DRIVERS\RsFx0310.sys
15:29:17.0561 0x1dec RsFx0310 - ok
15:29:17.0582 0x1dec [ 2D05A5508F4685412F2B89E8C2189ABC, 82F12B4E0E73411A121EFD35FBD3B44CBBC0AE96ACFBB45D8C3C3777E2EA320D ] rspndr C:\WINDOWS\system32\DRIVERS\rspndr.sys
15:29:17.0597 0x1dec rspndr - ok
15:29:17.0641 0x1dec [ 1A063730F221B2746FF00457AE17E4F0, 39A3C258CBFE3BC566C63528C9020A3BC9409736AE5289C08A7BA471D8409263 ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys
15:29:17.0651 0x1dec s3cap - ok
15:29:17.0711 0x1dec [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] SamSs C:\WINDOWS\system32\lsass.exe
15:29:17.0724 0x1dec SamSs - ok
15:29:17.0772 0x1dec [ C624A1B32211C3166EDB3F4AB02A30B7, 6B2A4607DB52D74242787ED9DF9067058983D310431D8612D2B0236E6201E681 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys
15:29:17.0784 0x1dec sbp2port - ok
15:29:17.0838 0x1dec [ 74A3B67F03877D06B09B1B40C5ED582E, A8FF9BF416F0BF365BFB4E1796859825C811A74B5E54DDDCE8345193BEEBE206 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll
15:29:17.0856 0x1dec SCardSvr - ok
15:29:17.0914 0x1dec [ 8B9C4D55B4A536FB01C360DDB9533574, 9B939FE68F6F9C171ED0D91E2CE1E67515295D34EC23606BCDFD097DCC8CFD4A ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll
15:29:17.0931 0x1dec ScDeviceEnum - ok
15:29:17.0977 0x1dec [ 13BEA6C882D4D877A5A85CA149C86BC1, 8E9BE5C2A36D5881D9985C3A31309FE03966EA13A3541D3C5B542AB67FA0D55F ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys
15:29:17.0989 0x1dec scfilter - ok
15:29:18.0079 0x1dec [ 3151A020E03DDE31AAC49F35C5EFB4DB, 5ABB1103009979F86C862357E28F37C2744979F2C99F7CF6ABB4EB1B8416B3F6 ] Schedule C:\WINDOWS\system32\schedsvc.dll
15:29:18.0117 0x1dec Schedule - ok
15:29:18.0172 0x1dec [ 41C0D7B1A6D4AD119BA6AC0487EA5C8E, 516C2B34BA7507D0DA4148B4ABC0A8C36286570D4EA5C60B28647B1249C15018 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll
15:29:18.0186 0x1dec SCPolicySvc - ok
15:29:18.0240 0x1dec [ C54B6B2170BF628FD42F799A66956D75, BCF460A124CAA6F1F1A9A7BCBDCC2D5E39B0404D96B7C9FFAC806E041782B91E ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys
15:29:18.0255 0x1dec sdbus - ok
15:29:18.0302 0x1dec [ 0B1E929D11A8E358106955603FAC65E8, A5EC91BFC0873EC6AB1D0DB4E91654BD35339BD680E7E82DA2DC64996B4AE515 ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys
15:29:18.0313 0x1dec sdstor - ok
15:29:18.0364 0x1dec [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\WINDOWS\system32\drivers\secdrv.sys
15:29:18.0374 0x1dec secdrv - ok
15:29:18.0430 0x1dec [ 6627154693B6C2B8A59727F5B38728E8, F08251EE3436400295F120D48F3763E6F11BBF4132D674AD3E8112B6B3538455 ] seclogon C:\WINDOWS\system32\seclogon.dll
15:29:18.0444 0x1dec seclogon - ok
15:29:18.0462 0x1dec [ 81FE9A81EDF8016816C9E91FBFBF7D35, 87FB92A3D15F312F0B9C423EF851061A944B013E5668D8C9A441B4DC0EB690AF ] SENS C:\WINDOWS\System32\sens.dll
15:29:18.0478 0x1dec SENS - ok
15:29:18.0529 0x1dec [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] SensorsSimulatorDriver C:\WINDOWS\system32\DRIVERS\WUDFRd.sys
15:29:18.0544 0x1dec SensorsSimulatorDriver - ok
15:29:18.0599 0x1dec [ 6E4012AE67F09F867EF620C8D5524C0B, 63933E51F8E413E63481369CE2F9FD224560550FBD3BD2B4573E9F4AD88708A2 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll
15:29:18.0617 0x1dec SensrSvc - ok
15:29:18.0658 0x1dec [ DB2FF24CE0BDD15FE75870AFE312BA89, 7DB0D978C92CD0A0A81F7AB46FE323B4929CEA01585B0F330921E6DFA7DE1B85 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys
15:29:18.0668 0x1dec SerCx - ok
15:29:18.0743 0x1dec [ 0044B31F93946D5D41982314381FE431, 95B8A94BA9EF770F29ACD5B23D447EC2B6CF1CB3D0030343BA1550AC31F6E2A5 ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys
15:29:18.0756 0x1dec SerCx2 - ok
15:29:18.0768 0x1dec [ 3CD600C089C1251BEEB4CD4CD5164F9E, D9F81951B4454B24E821E33ACA53A851A61F3135E8EC6FBE6761A1A3E1CDCBE2 ] Serenum C:\WINDOWS\System32\drivers\serenum.sys
15:29:18.0779 0x1dec Serenum - ok
15:29:18.0799 0x1dec [ D864381BC9C725FAB01D94C060660166, 132FED95222BBE3B0B25B3F1F0EFC5903D04564BD047BA4D2042AD51E3FDA724 ] Serial C:\WINDOWS\System32\drivers\serial.sys
15:29:18.0812 0x1dec Serial - ok
15:29:18.0861 0x1dec [ 148195AE95D9BC7375A08846439FDAC1, 3A2F78FD18AA7A6D659921E19335E943894530874AC5AB5E7219CEF28FA54F7A ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys
15:29:18.0872 0x1dec sermouse - ok
15:29:18.0986 0x1dec [ 78F7BB9F4924BE164294C59B8C3FC096, 75051A6A8B0DBB16CD70855A408134270EEAF0C127BAAE5B592DB53BB87C085B ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
15:29:19.0007 0x1dec ServiceLayer - ok
15:29:19.0075 0x1dec [ 3A2F1A7472C3B7CC9B89C8516C726488, 9BCBBAC10C900EA7B30822B463A77EE5067F217C4B490857A09E5277983CB89B ] SessionEnv C:\WINDOWS\system32\sessenv.dll
15:29:19.0095 0x1dec SessionEnv - ok
15:29:19.0109 0x1dec [ 472B7A5AC181C050888DB454663DD764, C950A8615D57BFD455E18880398350642B2E1D6B951EC9754FD8D429F3418835 ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys
15:29:19.0120 0x1dec sfloppy - ok
15:29:19.0187 0x1dec [ 8081FF3DAE8159FE8956B09BC29CE983, AC0F305AEE8B1AB2E1275F1D33EC1D2F3E23F234F831BD9D41F415A94A19D3AB ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
15:29:19.0208 0x1dec SharedAccess - ok
15:29:19.0273 0x1dec [ 7FD9A61A3523A61FC135D61D6E160314, 409E1CF7A62FD90CBC31AEAFBB7230B02DBEC6CFCA2D266D221A7643FAEBA13B ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
15:29:19.0300 0x1dec ShellHWDetection - ok
15:29:19.0348 0x1dec [ 2F518D13DD6F3053837FE606F1A2EA1F, 64109296CE95BD233525688A350D575CF97B9464659AA07CF78B307B6ADBC835 ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys
15:29:19.0359 0x1dec SiSRaid2 - ok
15:29:19.0375 0x1dec [ 1AC9A200A9C49C4508F04AAFFCA34A3F, 972BCB2A39169155F74111FAC74ACCD8F50E34EADCF087833B0980827627BBF4 ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys
15:29:19.0386 0x1dec SiSRaid4 - ok
15:29:19.0438 0x1dec [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
15:29:19.0452 0x1dec SkypeUpdate - ok
15:29:19.0508 0x1dec [ 3C84DCCE5B322F745A75CA8BA3A0F6B3, 1FB94A8A1C63D6FDB82E28ED5B696B3CB1F64183A89A3B5153B266C292CB7815 ] smphost C:\WINDOWS\System32\smphost.dll
15:29:19.0521 0x1dec smphost - ok
15:29:19.0583 0x1dec [ D0EB0DF8C603BBA084351A92732B1CBE, E24ED8F78EF41C1BC17386AE4BBCE0DC892C5B89B12C03FC9FB61D359B13F1B4 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe
15:29:19.0597 0x1dec SNMPTRAP - ok
15:29:19.0670 0x1dec [ B45AE0970B2D66CCE756DE6989E23EEC, 8393CF2DC4F65CD48D4D7B3C8C2D29E26728593B652D6CEAB65B50AEDA0884B7 ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys
15:29:19.0690 0x1dec spaceport - ok
15:29:19.0734 0x1dec [ F337BE11071818FC3F5DC2940B6BDE34, D5CFF00E5DF37045F71AEE101AC9B270EBB29F372F404757B58600E9966C7E4D ] SpbCx C:\WINDOWS\system32\drivers\SpbCx.sys
15:29:19.0745 0x1dec SpbCx - ok
15:29:19.0824 0x1dec [ FCB156A6745631A67DEA61827061D483, 9275ABFA1E1E595969A71C0DA228D18D1B868BF46E097E1276142BD80F8A32C9 ] Spooler C:\WINDOWS\System32\spoolsv.exe
15:29:19.0828 0x1b8c Object send P2P result: true
15:29:19.0843 0x1b8c Object required for P2P: [ 63282F5EB7E5BFB58FD1EC93C6ADB457 ] MozillaMaintenance
15:29:19.0862 0x1dec Spooler - ok
15:29:20.0072 0x1dec [ C993A0B97BECD3AAF5158E3869878465, 8B86F37DEFCBE55DE507D830EC4980EBB39B3CCA30C2B3E76B588AAB282A50FC ] sppsvc C:\WINDOWS\system32\sppsvc.exe
15:29:20.0263 0x1dec sppsvc - ok
15:29:20.0460 0x1dec [ D8DA6E4BAF25A0DD3281EC21364B7E37, 8B74BD8C763A4E2ED99772BB4951BC59B8AF939A74EA4622DC7CEE631E75B05A ] SQL Server Distributed Replay Client C:\Program Files (x86)\Microsoft SQL Server\120\Tools\DReplayClient\DReplayClient.exe
15:29:20.0471 0x1dec SQL Server Distributed Replay Client - ok
15:29:20.0529 0x1dec [ BD5FBB57B66308911B8219437A0436F1, 03A8787E7A00C05484671E90E72393D01B7D04B67070B42527788FC92F0C1FD6 ] SQL Server Distributed Replay Controller C:\Program Files (x86)\Microsoft SQL Server\120\Tools\DReplayController\DReplayController.exe
15:29:20.0544 0x1dec SQL Server Distributed Replay Controller - ok
15:29:20.0587 0x1dec [ 774C1D27B9ED5A420E11C2343B0FFF7B, 6C291CF9C9205D6F9BA43156E1EBB370CA11DD1656694F1B434E2E7F8AFBC6A4 ] SQLBrowser C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
15:29:20.0601 0x1dec SQLBrowser - ok
15:29:20.0707 0x1dec [ D1A4A546ED802E6854B1F1F5DFB58D27, CFA21C67B806176FAC5C9E70B8DB2E1D3E3BC75B0B548D06238CBEFBFEC65A90 ] SQLSERVERAGENT C:\Program Files\Microsoft SQL Server\MSSQL12.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE
15:29:20.0729 0x1dec SQLSERVERAGENT - ok
15:29:20.0796 0x1dec [ FAD8A14CAE92E805E48DA87B9564391A, B4BD026B6C9EE72CDE5E9215D903F16AE15893A1491ECFC346CB030C56D592A5 ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
15:29:20.0806 0x1dec SQLWriter - ok
15:29:20.0863 0x1dec [ 8003E034E3EA0E29DA54215A770FC27C, 28AB1FDEA372D33540A26DAE413A10336409D33B91F51DC0AE144D451022A2A7 ] srv C:\WINDOWS\system32\DRIVERS\srv.sys
15:29:20.0882 0x1dec srv - ok
15:29:20.0960 0x1dec [ 00D8AC8E3053290BDE6EA2FB6810D2FC, 957FEF84CBBAE71829529AE99A1B24F52D7831BD666442D0132FBB825409A75D ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys
15:29:20.0984 0x1dec srv2 - ok
15:29:21.0041 0x1dec [ D047CD668E6277FD80F0C613946F034C, BD0209E7FD89F9295D4DE48C9652DF2A2990277C16AFA473B96704B1CBD2F338 ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys
15:29:21.0056 0x1dec srvnet - ok
15:29:21.0115 0x1dec [ CF6C3037839CF78421A94F9060C2886F, CA98C180AE03F5BE8FEFFBA75BD98DEE2AD4FA975E1EF83215C9CD2476946811 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
15:29:21.0133 0x1dec SSDPSRV - ok
15:29:21.0187 0x1dec [ 198A737DBA666F4808D62E9A8277A6B7, 90B6E5E2ACE95D850C913A3A1DA1F966C44955C530004C228FA93B2A536F5C27 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll
15:29:21.0202 0x1dec SstpSvc - ok
15:29:21.0238 0x1dec [ 91310683D7B6B292B746D60734B59322, 2C56C3E4AA7356FB544B52F80ABDA39A80473390CB2059C69BDCCAD40FE56325 ] ssudmdm C:\WINDOWS\system32\DRIVERS\ssudmdm.sys
15:29:21.0249 0x1dec ssudmdm - ok
15:29:21.0418 0x1dec [ 9DA3B55B17B54789AFB8C657D4ACE4D7, 5E4599E682327E3B8097A88A69ED73F96254A29054744D5DFB782054863F131E ] ss_conn_service C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe
15:29:21.0439 0x1dec ss_conn_service - ok
15:29:21.0443 0x1dec StarOpen - ok
15:29:21.0501 0x1dec [ D27C8C88CEB69075465B41DA6ECF3374, B1A70A30787080474E901E4743996EEE4FCD09BEDBBA89CE57ACAE05A67907AB ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
15:29:21.0525 0x1dec Steam Client Service - ok
15:29:21.0545 0x1dec [ 366DEA74BBA65B362BCCFC6FC2ADFD8B, 4D28122AB9D8DAB724021E6513B4474BD34FCEDF47769B1D27AC7551FCA002F8 ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys
15:29:21.0555 0x1dec stexstor - ok
15:29:21.0620 0x1dec [ 63E9CE568CF1192771A5F0460DE7D2B9, C27B21FD2C14AD41A59EF62EB8AC95C08EB13CCB1CEECD8378B8CDD4DC352E69 ] stisvc C:\WINDOWS\System32\wiaservc.dll
15:29:21.0647 0x1dec stisvc - ok
15:29:21.0706 0x1dec [ 0ED2E318ABB68C1A35A8B8038BDB4C90, 5C3ABC245F4BCFE64E646D9C0E2F5E211244956C84D03084C71FF6A7E0CDED30 ] storahci C:\WINDOWS\system32\drivers\storahci.sys
15:29:21.0718 0x1dec storahci - ok
15:29:21.0765 0x1dec [ 8B9486B64E5FC17FB9CC04CA10B77A34, C1EAC9D27DC83E4C56B890D97988C3CCFAE3877309610601F2E3FFFE97686D43 ] storflt C:\WINDOWS\system32\drivers\vmstorfl.sys
15:29:21.0775 0x1dec storflt - ok
15:29:21.0825 0x1dec [ 6B06E2D11E604BE2B1A406C4CB3B90DE, 2DDEA1568A85AD64FCE5D10D348304FCD9BE6E96C2313353EF70A2933306D188 ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys
15:29:21.0836 0x1dec stornvme - ok
15:29:21.0889 0x1dec [ A45F5AC9D8069D0EC66E3CA73103073B, 996788F1C58E016E8E5CF3FD1D220A3C40AFFD6C21361A34636415DB12E0D381 ] StorSvc C:\WINDOWS\system32\storsvc.dll
15:29:21.0902 0x1dec StorSvc - ok
15:29:21.0914 0x1dec [ 548759755BC73DAD663250239D7E0B9F, D31A05A8CE800B539420B6E545F1F4BF6E4B02EAF8366DE89CAF13A83C6CA48D ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys
15:29:21.0925 0x1dec storvsc - ok
15:29:21.0987 0x1dec [ E395BE02F80A79A6CF973BA38DBB8135, 4C6F85B0EB8E7725BA720F9742561D229726C0D7C17505D1E79F19A5626F6325 ] svsvc C:\WINDOWS\system32\svsvc.dll
15:29:22.0000 0x1dec svsvc - ok
15:29:22.0050 0x1dec [ 65454187E0F8B6C0DCECB0287D06EC43, 87550000CF5B3C1DF3E69633934AFE8554AE40B6638F190D3185AD63F1D7A2EE ] swenum C:\WINDOWS\System32\drivers\swenum.sys
15:29:22.0059 0x1dec swenum - ok
15:29:22.0133 0x1dec [ 1C71D72D4997A284128FBEE770726330, 21682BDE74A1108FED1124FB1EA35A03CBFA94ABE1B89CC0FADB4DD82596C43E ] swprv C:\WINDOWS\System32\swprv.dll
15:29:22.0163 0x1dec swprv - ok
15:29:22.0247 0x1dec [ 7E85DB0463AD2403AE84AD162B162279, 996C42ECAFC6E24C623068AFAFCC0A2612526333AF9315F7536C6D40C2570632 ] SysMain C:\WINDOWS\system32\sysmain.dll
15:29:22.0285 0x1dec SysMain - ok
15:29:22.0340 0x1dec [ D73DBBB96CEE90C2856164AAD8543425, D11ADB5D4C5DD355314CA656D375D0062CAE7462E866F94F1B26D5803F65DCB2 ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
15:29:22.0359 0x1dec SystemEventsBroker - ok
15:29:22.0412 0x1dec [ D6A71B95ACF71ACA63B67232059F1BCD, C5CEC032E7AB507500D1CC7A4E65DA6322412C798201A9D770CBDE892E50DFC8 ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
15:29:22.0429 0x1dec TabletInputService - ok
15:29:22.0485 0x1dec [ 5A5BAB1CA9621E73E25EE4744B67CDA6, 479EBD7BAE1E2AD431153FDC016742F7A8D824716EAB1A4CA87EBBD21D61DECD ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
15:29:22.0505 0x1dec TapiSrv - ok
15:29:22.0593 0x1dec [ 746DDF7D59AB8D721C88D48434597E8D, 78BDBAB8D1E86A11804FEB19B355C0FAD04ACE8DD4BDDFDADCE5461E259BCE82 ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys
15:29:22.0663 0x1dec Tcpip - ok
15:29:22.0737 0x1dec [ 746DDF7D59AB8D721C88D48434597E8D, 78BDBAB8D1E86A11804FEB19B355C0FAD04ACE8DD4BDDFDADCE5461E259BCE82 ] TCPIP6 C:\WINDOWS\system32\DRIVERS\tcpip.sys
15:29:22.0806 0x1dec TCPIP6 - ok
15:29:22.0832 0x1dec [ 41CF802064F72E55F50CA0A221FD36D4, 70ABCDF9E96611E8C83042C581575E26649FE479475E8E118CD3FF6CB1C84C3F ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys
15:29:22.0843 0x1dec tcpipreg - ok
15:29:22.0908 0x1dec [ E0BD2D83875464FEEEB242CBA8B7E073, A3067165128F36035FA9F3CBA55CFED736E180C495497FA7332B3D97908C3D90 ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys
15:29:22.0920 0x1dec tdx - ok
15:29:23.0260 0x1b8c Object send P2P result: true
15:29:23.0261 0x1b8c Object required for P2P: [ 51B3AC0560848CD6D65AC2033E293113 ] MsLldp
15:29:23.0288 0x1dec [ 2E7EFE9F59DA5EF7AAAE5712324FAAFD, 960130B0559F59AF3FF6DA1E6D11CAF663CEA2BCDAC3263699D67D20C1360318 ] TeamViewer C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
15:29:23.0435 0x1dec TeamViewer - ok
15:29:23.0468 0x1dec [ F5520DBB47C60EE83024B38720ABDA24, B8E555D92440BF93E3B55A66E27CEF936477EF7528F870D3B78BD3B294A05CC0 ] teamviewervpn C:\WINDOWS\system32\DRIVERS\teamviewervpn.sys
15:29:23.0476 0x1dec teamviewervpn - ok
15:29:23.0530 0x1dec [ 232D185D2337F141311D0CF1983E1431, 02EB56D3F26174AF1741C1A444CE30DE84D5BAF583C1A52C7A953BCC52445547 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys
15:29:23.0540 0x1dec terminpt - ok
15:29:23.0612 0x1dec [ C50997E282576DA492EBA66B059D4196, EBD793CB396F9503376207FA60353F5672DEDB620C8E01C8D6AE0030B3B03339 ] TermService C:\WINDOWS\System32\termsrv.dll
15:29:23.0648 0x1dec TermService - ok
15:29:23.0706 0x1dec [ 48D9D00C2E0E72C3D4F52772C80355F6, 86F281C7F5FA2FCF1A36C69DD6561531E48483CACB8A873B955F7E93D9A1D259 ] TFsExDisk C:\WINDOWS\System32\Drivers\TFsExDisk.sys
15:29:23.0713 0x1dec TFsExDisk - ok
15:29:23.0769 0x1dec [ 2180DBCE75B914E5E5BBFFFAAE97AA21, 8000AECC8855903DB50ABA7E304396D1FCEAE8DC9ADD4FC50275CF24B4D914DE ] Themes C:\WINDOWS\system32\themeservice.dll
15:29:23.0784 0x1dec Themes - ok
15:29:23.0846 0x1dec [ 4C5179DB61B9E14BEC15CDC4B152B2E9, 9048BEC7AD6A3F4B640E99B1F0365AC9A46740B188758FBB2C160EF30AD6E64B ] THREADORDER C:\WINDOWS\system32\mmcss.dll
15:29:23.0860 0x1dec THREADORDER - ok
15:29:23.0917 0x1dec [ B5ED9CC61798C7D44BD535D40B89EFB5, 1BDCEAA9AF2096381870D92129C748F4EE06A1167ABA9367B9DD43BAF27E3F5B ] TimeBroker C:\WINDOWS\System32\TimeBrokerServer.dll
15:29:23.0935 0x1dec TimeBroker - ok
15:29:23.0992 0x1dec [ 80A2FC1A089A71F2DBE5D8394FFB009F, DEA30E751F6EA42E43E16869713FC7E37832B15DAFA0062B1798DFA476981385 ] TPM C:\WINDOWS\system32\drivers\tpm.sys
15:29:24.0006 0x1dec TPM - ok
15:29:24.0028 0x1dec [ 884113C2BB703FE806C8608B75F34831, 24DE5750CA4363455412BABB0B1FAB08497153E8F158ED44958F100410F93506 ] TrkWks C:\WINDOWS\System32\trkwks.dll
15:29:24.0044 0x1dec TrkWks - ok
15:29:24.0086 0x1dec [ 44A94FB4C76528D2382FFE04B05827C3, B0BCDF7CD1D65E61A9061D539D83527A89B69583958F8A26C6BF9766C1B61E0C ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
15:29:24.0098 0x1dec TrustedInstaller - ok
15:29:24.0117 0x1dec [ BF8F54CA37E9C9D6582C31C5761F8C93, 337C566792F6FB9B7FD5D1D4384B767CFE4CF5DBB2E4688CCC36CBB018A0DD0F ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys
15:29:24.0129 0x1dec TsUsbFlt - ok
15:29:24.0181 0x1dec [ 20185BEB7512EDE4EFECDFA148AC9F99, 6F539478493C0F87F3DDF67A4A6D4D41E9474EEF21434E856350CE149A34EA9F ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys
15:29:24.0192 0x1dec TsUsbGD - ok
15:29:24.0246 0x1dec [ E85916632CD3B9E9B546968DB950BF42, DECE3852C763CC6293C7D1B772296C43A0AE1E47BBCC4979C96B3B2AD70413F3 ] tunnel C:\WINDOWS\system32\DRIVERS\tunnel.sys
15:29:24.0259 0x1dec tunnel - ok
15:29:24.0310 0x1dec [ F6EEAD052943B5A3104C1405BB856C54, FE422813E6C1012E9F392EFF2AE4C6D3A4DBD9CB2BD5E6A5CAB57D4E89A29468 ] uagp35 C:\WINDOWS\system32\drivers\uagp35.sys
15:29:24.0321 0x1dec uagp35 - ok
15:29:24.0335 0x1dec [ FE6067B1FD4E63650C667B33D080565B, 2C330ED00E49BA55E25564230E0DFB8A35F2B5320EB18D4AF7CAACFA9A449044 ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys
15:29:24.0346 0x1dec UASPStor - ok
15:29:24.0402 0x1dec [ 807F8CF3E973305FC435C61CBBEE2A49, 43CDEAC2BFC5091C11DFC0E7F7171AF9A598AE56CB056C3CF382AE7807F79EF0 ] UCX01000 C:\WINDOWS\System32\drivers\ucx01000.sys
15:29:24.0416 0x1dec UCX01000 - ok
15:29:24.0474 0x1dec [ C61EAF8E1E4B2F62BA4FDF457440B2C6, 961F76A789925234AC27F56AAE34556FA06088D71580B42C24B0BC209EAFD67E ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys
15:29:24.0491 0x1dec udfs - ok
15:29:24.0507 0x1dec [ 9578691F297E1B1F519970FE6D47CB21, 080C352AAF22A16A4F3C4AB4DCEA5BFA656457C73F735CEBA30516FDACCF6301 ] UEFI C:\WINDOWS\System32\drivers\UEFI.sys
15:29:24.0517 0x1dec UEFI - ok
15:29:24.0570 0x1dec [ A867F0F978EE64C87FADC3B100869EE4, 2686BE85F963D0D0BB275E92E5B543280D8742CF10772303E3189D0719B6A277 ] UI0Detect C:\WINDOWS\system32\UI0Detect.exe
15:29:24.0585 0x1dec UI0Detect - ok
15:29:24.0605 0x1dec [ 5EAB5117DDB24FC4D39E6FFFCF1837B9, 2BC709240867F161E94BE6625A04F478EAAA3EEE7BC7C37ED0DFA9EEA5928E98 ] uliagpkx C:\WINDOWS\system32\drivers\uliagpkx.sys
15:29:24.0616 0x1dec uliagpkx - ok
15:29:24.0634 0x1dec [ DA34C39A18E60E7C3FA0630566408034, 2F162504214053894C72760D9933D01DBF3578609FE5E2376C3272818599FE32 ] umbus C:\WINDOWS\System32\drivers\umbus.sys
15:29:24.0647 0x1dec umbus - ok
15:29:24.0666 0x1dec [ AE8294875E5446E359B1E8035D40C05E, AE0357BAB47C07C3576BC76951CD258C009BC5A1B93259D2122A841BD9CDA8FA ] UmPass C:\WINDOWS\System32\drivers\umpass.sys
15:29:24.0677 0x1dec UmPass - ok
15:29:24.0700 0x1dec [ A023F267A262D5DA6CE1436D9C5E8FD9, 92AD7AF91184C244A7E392F49663143193A80D5D81114546A00F18227DE31D23 ] UmRdpService C:\WINDOWS\System32\umrdp.dll
15:29:24.0720 0x1dec UmRdpService - ok
15:29:24.0781 0x1dec [ C98493DD8E6A50154FAC75C15E1C36BB, CECD1C826C8F7AF05468871BF6A0ACDBB6B0202F4F87F48C6D367E5BD699E800 ] upnphost C:\WINDOWS\System32\upnphost.dll
15:29:24.0804 0x1dec upnphost - ok
15:29:24.0824 0x1dec [ 311C90F0767A63000AC35DD0A7078A30, DB80E10015DCC595F90C31CE61590DB07E84F8B13DA904B2D59233678C366A2D ] upperdev C:\WINDOWS\system32\DRIVERS\usbser_lowerfltx64.sys
15:29:24.0842 0x1dec upperdev - ok
15:29:24.0893 0x1dec [ DF355EB0199198728027962DCFCDE5FB, 9E158BD07389B4CFF99674716647FA3AABEECBD1A98EDF20E544E099A99A8768 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys
15:29:24.0906 0x1dec usbaudio - ok
15:29:24.0958 0x1dec [ FF78D053A05E5A394F4E3C1816CC65A8, 5DAE02414271231F5FDBB751AFEB99874779B467947020815D4AE54432D4269D ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys
15:29:24.0971 0x1dec usbccgp - ok
15:29:24.0988 0x1dec [ 0139248F6B95CF0D837B5B46A2722D40, 38E3E704E0364F07732DB418AEBD126B040FB3CDB7D78EA36E8605D50D528A80 ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys
15:29:25.0000 0x1dec usbcir - ok
15:29:25.0051 0x1dec [ C996CBEF922B5653A01E3F50DDCE2F86, 231EB5A36E7EE242197E796D3B4AB12F945D2C8570587BC8D57D45530A0C59B4 ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys
15:29:25.0062 0x1dec usbehci - ok
15:29:25.0133 0x1dec [ CD81683F4553677B9BF5163A922153EB, 6B304B0D68B9BFF0245EC755CDAAF9DF59DF3A081727E32CB66672929F0DBC50 ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys
15:29:25.0154 0x1dec usbhub - ok
15:29:25.0222 0x1dec [ 5C90D5379B53590FBB24BBAD4FA682EE, DC036340510C1C0999AB1CB845F8E6EB8B7696BAC9BBE6E936454C0000D1E9D4 ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys
15:29:25.0242 0x1dec USBHUB3 - ok
15:29:25.0293 0x1dec [ A0F0484C97D6441ED6A75D7426ECCC9E, FF928ADE1C5464E581BF929F7383D5762D110EA6C7E31A6F0887EA7357ADBEFE ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys
15:29:25.0305 0x1dec usbohci - ok
15:29:25.0402 0x1dec [ 0A89F75BB756604BBD995F2A0C8144F3, 1F766F6A6482B75749D3BAFCC84484C65076E179AC5E33DB2EF10D575090B81E ] USBPNPA C:\WINDOWS\system32\drivers\CM10864.sys
15:29:25.0450 0x1dec USBPNPA - ok
15:29:25.0508 0x1dec [ 4D655E3B684BE9B0F7FFD8A2935C348C, 3A7FC1748C5AEA8CFE0E7C22ADC77E3DCA475455FC16D9C6A5C16EB5E949A516 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys
15:29:25.0521 0x1dec usbprint - ok
15:29:25.0568 0x1dec [ 9EAA9AEE921DDBC96557BD0ABCA90829, 9263F1855118A9B769E01055B09FC527A18BC6C9A524566B5CE7EEC9A82F749B ] usbrndis6 C:\WINDOWS\system32\DRIVERS\usb80236.sys
15:29:25.0578 0x1dec usbrndis6 - ok
15:29:25.0624 0x1dec [ 0F030491BA4A27BD46F8B8ACEEE83F1A, 7063855611BEF94D4D229BA1BE507ECBDD89F5861641A407EB3E2919A352F9D4 ] usbscan C:\WINDOWS\System32\drivers\usbscan.sys
15:29:25.0636 0x1dec usbscan - ok
15:29:25.0651 0x1dec [ 029DFB6E5B38ADD45561A8CE0F60B331, 09F616C1F17CB8D51D19017D6AD02479B709A713349AC69CFFED695ABFD753D2 ] usbser C:\WINDOWS\system32\DRIVERS\usbser.sys
15:29:25.0663 0x1dec usbser - ok
15:29:25.0680 0x1dec [ C03DA998E412D69D18DD11D835229AF0, DD43E370EF370767588A6D56A51A4ADF99B5E063C7AA0528F91FD431DE7C2932 ] UsbserFilt C:\WINDOWS\system32\DRIVERS\usbser_lowerfltjx64.sys
15:29:25.0699 0x1dec UsbserFilt - ok
15:29:25.0707 0x1b8c Object send P2P result: true
15:29:25.0757 0x1dec [ 9D168BFA334D47BE404367EB58D4E130, 23279CBE6ACBD074E7B268BA2EDA14E2255C41F8117173B2BBE653D8259ECFA2 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS
15:29:25.0771 0x1dec USBSTOR - ok
15:29:25.0818 0x1dec [ FC974B03C8B87455F44F734C8F31A3C8, D69F6EE8030F7DF96FF151D9EAA6AE65417ACAC5A267C7DB96E9611D5BC42D2C ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys
15:29:25.0829 0x1dec usbuhci - ok
15:29:25.0883 0x1dec [ 5C8F604F6DC74177CDD8372D7B1ADFF0, C1DE9A37A7A01CCCBFCE13C1E5B26683F620AB21EDA5A14C82022E2F49C84484 ] usbvideo C:\WINDOWS\System32\Drivers\usbvideo.sys
15:29:25.0898 0x1dec usbvideo - ok
15:29:25.0956 0x1dec [ 44603DA5A87FB491EF59C889EBBB4DDB, 59AA9B6B0B5D66F9312CD3F999D0D9F12F1A2C5D230365AD7287CD71FD86961C ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS
15:29:25.0973 0x1dec USBXHCI - ok
15:29:25.0988 0x1dec [ 382100E75B6F4668AEAEF228C6CEFFAD, 9C7229F10F11D18E1FED6395391A46225A84B421034B9AB6F81AF7430FDC556F ] VaultSvc C:\WINDOWS\system32\lsass.exe
15:29:26.0000 0x1dec VaultSvc - ok
15:29:26.0058 0x1dec VBoxAswDrv - ok
15:29:26.0108 0x1dec [ 3C8E2C591345F38149C69FE8E5DF8C90, 9F4BB9BDA09CB2E99A6A888B288F322AE5C460B5D124CD714C6F00FF5029144B ] VClone C:\WINDOWS\System32\drivers\VClone.sys
15:29:26.0116 0x1dec VClone - ok
15:29:26.0165 0x1dec [ FEB26E3B8345A7E8D62F945C4AE86562, 3AAFE87C402FC8E92542DFE60EC9540559863065F88D429A16D7B1BF829223FF ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys
15:29:26.0176 0x1dec vdrvroot - ok
15:29:26.0262 0x1dec [ 8A4D808D1EC7C1C47B2C8BF488A9A07A, 63C07312ADB6F8A8BDE93361C30AC63DAB4DE1141AF54630EEF11E54B0BF983D ] vds C:\WINDOWS\System32\vds.exe
15:29:26.0304 0x1dec vds - ok
15:29:26.0359 0x1dec [ A026EDEAA5EECAE0B08E2748B616D4BD, 2525A54DC7F49DDFBB999C22BF3FAB6D9E9F70C0806E58D81E90AC59F9F46089 ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys
15:29:26.0373 0x1dec VerifierExt - ok
15:29:26.0437 0x1dec [ 34CAF69BF4166AB40BFF0ED068FF6F91, BF5DA4F85A2C537DD76A3271956EC5BDB9ABC495FAA9371037F608152BE2725D ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys
15:29:26.0459 0x1dec vhdmp - ok
15:29:26.0471 0x1dec [ 06D38968028E9AB19DE9B618C7B6D199, 62022297A47F440D1C82CA0B0E57C0C8E9D5033D83DD3B40492B218DF65EBF68 ] viaide C:\WINDOWS\system32\drivers\viaide.sys
15:29:26.0481 0x1dec viaide - ok
15:29:26.0537 0x1dec [ 511AD3FF957A0127E6BD336FF6F89C38, 55325BFD0857A1204F7F6F8ED8C91C07B0E20A50402105708E7365ECD9E25A21 ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys
15:29:26.0547 0x1dec vmbus - ok
15:29:26.0564 0x1dec [ DA40BEA0A863CE768C940CA9723BF81F, 567C0C3F422325635808B0CF76E05D3B6187F96845C33F85F92F98C9FE53A5B8 ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys
15:29:26.0575 0x1dec VMBusHID - ok
15:29:26.0635 0x1dec [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll
15:29:26.0659 0x1dec vmicguestinterface - ok
15:29:26.0674 0x1dec [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicheartbeat C:\WINDOWS\System32\ICSvc.dll
15:29:26.0699 0x1dec vmicheartbeat - ok
15:29:26.0714 0x1dec [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
15:29:26.0738 0x1dec vmickvpexchange - ok
15:29:26.0753 0x1dec [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicrdv C:\WINDOWS\System32\ICSvc.dll
15:29:26.0776 0x1dec vmicrdv - ok
15:29:26.0791 0x1dec [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicshutdown C:\WINDOWS\System32\ICSvc.dll
15:29:26.0815 0x1dec vmicshutdown - ok
15:29:26.0829 0x1dec [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmictimesync C:\WINDOWS\System32\ICSvc.dll
15:29:26.0851 0x1dec vmictimesync - ok
15:29:26.0866 0x1dec [ C42C38E15C0DC39D4B0BDF34F733E468, 7264680C44FA68BB1FC0A490FE3988AFDE19892295F7458943D8CBEE6C01D4F0 ] vmicvss C:\WINDOWS\System32\ICSvc.dll
15:29:26.0891 0x1dec vmicvss - ok
15:29:26.0908 0x1dec [ 55D7D963DE85162F1C49721E502F9744, 5AD34D6DB707EF3E5242BD8CA67B21D6258EE7E7FC477D5227BD15500AE7F45F ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys
15:29:26.0918 0x1dec volmgr - ok
15:29:26.0935 0x1dec [ CCB9E901F7254BF96D28EB1B0E5329B7, F0E3CA4EFA544CDAEF4092284CF3EC7DF07F806A770285E281816457AD8813F5 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys
15:29:26.0955 0x1dec volmgrx - ok
15:29:26.0970 0x1dec [ D537962695CAFEC1301F3EB7C8C3A1D2, 76FBEE866C4191E43B232B7ED34CB1FC1603C15F930EBBC5EFC6EA4B4500E1E8 ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys
15:29:26.0987 0x1dec volsnap - ok
15:29:27.0011 0x1dec [ DAC438FB5FF85A9E72806E2341D5D732, B1D1EFCA8C588A6BF53CEC941CC59702C366F15C7D5943431736EC857E57C0A2 ] vpci C:\WINDOWS\System32\drivers\vpci.sys
15:29:27.0022 0x1dec vpci - ok
15:29:27.0036 0x1dec [ 4539F45F9F4C9757A86A56C949421E07, DEC362314B2C66414F39354AFE79C02B18BF4EEF90787FB58307F6EB62237E2C ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys
15:29:27.0049 0x1dec vsmraid - ok
15:29:27.0120 0x1dec [ D0CBA7B3531CCF2ADB985856D5F92434, 7FCBBCAF1AA85DCE8D75FB38DC4848AE12E8DD913CEBBC37BCD3D0123F0A3CAB ] VSS C:\WINDOWS\system32\vssvc.exe
15:29:27.0164 0x1dec VSS - ok
15:29:27.0315 0x1dec [ 558B8E6F99E198519FD87F1575F7D92D, B176F51B72D9BCD6472A710D4E0B78A7A7D1C3CAEC12725289C1EBA54E35083D ] VSStandardCollectorService140 C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe
15:29:27.0325 0x1dec VSStandardCollectorService140 - ok
15:29:27.0353 0x1dec [ 0849B7260F26FE05EA56DED0672E2F4B, 7EAC0E7988F45CB4133A15932955B7B03CE715C967A3BAC9999D81543EBCAEC5 ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys
15:29:27.0370 0x1dec VSTXRAID - ok
15:29:27.0447 0x1dec [ BE970C369E43B509C1EDA2B8FA7CECB0, 18951F2AA842A0795AA79A4E164EE925A35E6270EBE4C4CDB19D0A891830E383 ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys
15:29:27.0457 0x1dec vwifibus - ok
15:29:27.0489 0x1dec [ 35BF5C5F5E3C9902C98978C7640574DA, C61E50B04000DCEC72365723F0C0725C2E005529DAF2777A59E624C14DA29E55 ] vwififlt C:\WINDOWS\system32\DRIVERS\vwififlt.sys
15:29:27.0500 0x1dec vwififlt - ok
15:29:27.0511 0x1dec [ 65ED7B9CFEA893DF7748D5FF692690DE, 73AB9D8BB928B3247BDFC7BB47AD7FCA763B375DC250C251DB4E0573531040E8 ] vwifimp C:\WINDOWS\system32\DRIVERS\vwifimp.sys
15:29:27.0522 0x1dec vwifimp - ok
15:29:27.0576 0x1dec [ DC821E811EFBB65CDD77FBB8B6ECA385, B7C8AACDF81DBA298F2F384983D36B269876C31F0398D89BF9070217A069B96F ] W32Time C:\WINDOWS\system32\w32time.dll
15:29:27.0597 0x1dec W32Time - ok
15:29:27.0655 0x1dec [ 0910AB9ED404C1434E2D0376C2AD5D8B, 62585CA5F1375BDA440D28D5DF1ADDC9DE3DDFA196D49BBFF3456A5A09EE1C6B ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys
15:29:27.0666 0x1dec WacomPen - ok
15:29:27.0760 0x1dec [ 139D842E5FB75A1E2F0212FBD7B0E457, F29F73B56865C5EBBE89B8F92AEFE2DB19E5C29A94D2E006A23243C23A41AE79 ] wbengine C:\WINDOWS\system32\wbengine.exe
15:29:27.0806 0x1dec wbengine - ok
15:29:27.0871 0x1dec [ 0F1DFA2FED73FA78B8C3CDE332A870F6, 1089F6F585F5350D349A640EBD3117832DF6B3657EB6667CB00AE217E04ACA17 ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll
15:29:27.0893 0x1dec WbioSrvc - ok
15:29:27.0920 0x1dec [ 0EAEC313B24837613621B4A2536ED382, 61C194ED7FA7D65BBE61A546D5FCA52F52AB08324E084D3EC23C9706E9BF0175 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll
15:29:27.0943 0x1dec Wcmsvc - ok
15:29:28.0005 0x1dec [ F6B4C2280FF7C7156AC8A4687B9DA35E, 1899D584D7469BB49355D84080051E2575B033E6312009D9C6C1DD3F7F9AA4C5 ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll
15:29:28.0027 0x1dec wcncsvc - ok
15:29:28.0073 0x1dec [ B7BF1D783F5B2484E8CE1C0C78257F16, 468601199FCCF63DBAE86EE6B8825EA85B2A1EE177413353FFA2CC9CA5249FCD ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
15:29:28.0088 0x1dec WcsPlugInService - ok
15:29:28.0144 0x1dec [ 81285DDC994F03379DB46419300B2DCB, 98D3622E11F375718AEA1DE3B5F0104DDAB4F96B6D4C19788C14F7B338A6F235 ] WdBoot C:\WINDOWS\system32\drivers\WdBoot.sys
15:29:28.0155 0x1dec WdBoot - ok
15:29:28.0196 0x1dec [ CB6C63FF8342B467E2EF76E98D5B934D, BE017CE91E3BAB293DE6ECF143797CCE3F33CC63024437472B4E38C6961AD884 ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys
15:29:28.0223 0x1dec Wdf01000 - ok
15:29:28.0290 0x1dec [ 26B8FED3F3B85F5F0C4BD03FD00B9941, 7F94FE7954498223B33C025258DB588A3AC9FF25C58EEAD204514FD20652FE40 ] WdFilter C:\WINDOWS\system32\drivers\WdFilter.sys
15:29:28.0305 0x1dec WdFilter - ok
15:29:28.0356 0x1dec [ F581F9C9D6953FABFA24E67105F0B614, 5A7BB72523D1C53BBE68700537D7AE0D150BC7E4B8227A916B2E29EE4CA267A9 ] WdiServiceHost C:\WINDOWS\system32\wdi.dll
15:29:28.0372 0x1dec WdiServiceHost - ok
15:29:28.0376 0x1dec [ F581F9C9D6953FABFA24E67105F0B614, 5A7BB72523D1C53BBE68700537D7AE0D150BC7E4B8227A916B2E29EE4CA267A9 ] WdiSystemHost C:\WINDOWS\system32\wdi.dll
15:29:28.0393 0x1dec WdiSystemHost - ok
15:29:28.0410 0x1dec [ CE67080F00E0AF32755096CEA6430ABA, 0E5D626F9F76C0BC63B2D246AD66D9CBF7D92F34B56398417BCFD0C331DBD282 ] WdNisDrv C:\WINDOWS\system32\Drivers\WdNisDrv.sys
15:29:28.0423 0x1dec WdNisDrv - ok
15:29:28.0445 0x1dec WdNisSvc - ok
15:29:28.0495 0x1dec [ 40F83492DB9ABBA59773A45FB487C8B2, 0D0DE0B0C9B929FEFD2674CCF17F5F2FC4B16EAB8E1981BBCE51B0305FD7D75E ] WebClient C:\WINDOWS\System32\webclnt.dll
15:29:28.0513 0x1dec WebClient - ok
15:29:28.0576 0x1dec [ 384E1D04FE20845B2559D292F17A9FA1, AD3B0B2B2219691AC30FEEC8AFDB3BBB74B51BB7D02038AE2B4DEA514E245315 ] Wecsvc C:\WINDOWS\system32\wecsvc.dll
15:29:28.0594 0x1dec Wecsvc - ok
15:29:28.0642 0x1dec [ 455014F4E48B67EBE0F032E2B0E06BF2, A36435784A034B27056A0E606683A20C69F1B0AB2B6BAEDEAEAA190F6287CAEF ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll
15:29:28.0656 0x1dec WEPHOSTSVC - ok
15:29:28.0709 0x1dec [ F13DBA57CEA9B7074B95EDCA6AD2635E, 1D9BA4841EF1343A5D9096B5FE27FC65DC1901D6683DD13516171638549666B5 ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll
15:29:28.0725 0x1dec wercplsupport - ok
15:29:28.0788 0x1dec [ FD7E58B6AA3EABF2D12B9762A20E11E4, 4C5E2E246C5C70074866BB3DBC2AAF483ECE4345004CCB8D1FE285047268685D ] WerSvc C:\WINDOWS\System32\WerSvc.dll
15:29:28.0806 0x1dec WerSvc - ok
15:29:28.0859 0x1dec [ 715ABA3DD164D06457A2A3C92F6EA9D5, E6F8269D2FFC4A548B65724C0A3F53756ED15E47229861FBD40B656EE40FE166 ] WFPLWFS C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
15:29:28.0871 0x1dec WFPLWFS - ok
15:29:28.0927 0x1dec [ 8C840E1FD7584E74BD0CC1EA581EC187, 148E534A94B4882E7396B13FABE17407802292E7890713540080D03D5629C81D ] WiaRpc C:\WINDOWS\System32\wiarpc.dll
15:29:28.0942 0x1dec WiaRpc - ok
15:29:28.0961 0x1dec [ 5F66B7BB330AA80067FC66149A692620, 92C5D7115A168A23108B65EEEB5FBA8FA43D781855355792596D2419160263C2 ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys
15:29:28.0971 0x1dec WIMMount - ok
15:29:28.0973 0x1dec WinDefend - ok
15:29:29.0042 0x1dec [ 10DAD6A7FC617A221313BD584E3C3A00, F139B878668ECF38FE59831E8595A207D5CEEE76C6FFDA8C9F735435E601A763 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
15:29:29.0072 0x1dec WinHttpAutoProxySvc - ok
15:29:29.0150 0x1dec [ FC8BD690321216C32BB58B035B6D5674, D61698DB19D9DB2593B60B6BA13F7B7735667206F41D751D507135469D6D3CDD ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
15:29:29.0166 0x1dec Winmgmt - ok
15:29:29.0249 0x1dec [ 427873F889F2F508BE8BE982219CE578, CA8DCFB774BF0F747295A7A0CB46A6177DE12AD6BD58266182206C41A3C9001E ] WinRM C:\WINDOWS\system32\WsmSvc.dll
15:29:29.0316 0x1dec WinRM - ok
15:29:29.0346 0x1dec [ 3AF1FA17F1C4ACBDB660D8F98B1A9C13, 99B0851410B462685F6705EBF832D10943FB9634030B02D15BF5D0C66F26F2C2 ] WinUsb C:\WINDOWS\System32\drivers\WinUsb.sys
15:29:29.0358 0x1dec WinUsb - ok
15:29:29.0445 0x1dec [ DC079BA8390089E4EBCA63D27EEA3ECB, 4D549217A68292E2B16C09FD9F84317011EE54A2DAF4E2AB85554267DF0D3249 ] WlanSvc C:\WINDOWS\System32\wlansvc.dll
15:29:29.0491 0x1dec WlanSvc - ok
15:29:29.0586 0x1dec [ 06BF5897949A8F24893F792E876B71F5, 9D3719492A86BF52A56E2EA798FD6FDB5862A03F6D360FCC4B0CEA9BE9792AE4 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll
15:29:29.0633 0x1dec wlidsvc - ok
15:29:29.0688 0x1dec [ 2834D9D3B4F554A39C72F00EA3F0E128, D10124343C67FE9A0B711AD569BB8080495FCEA0ECEF9AC3F3FBD6865F436A44 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys
15:29:29.0698 0x1dec WmiAcpi - ok
15:29:29.0759 0x1dec [ B96F7A1236C3F21212DE2C40A3DDB005, 5A29EBB6DA036E303611EB1304192655021405BB05452FD37886DDE604FF0D9D ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe
15:29:29.0773 0x1dec wmiApSrv - ok
15:29:29.0795 0x1dec WMPNetworkSvc - ok
15:29:29.0821 0x1dec [ 7FC5667DF73D4B04AA457CC3A4180E09, CB7B014945DCA16B6D120DBE0E5876C4C867A4ACD3C3536AEADC14B908613D4E ] Wof C:\WINDOWS\system32\drivers\Wof.sys
15:29:29.0834 0x1dec Wof - ok
15:29:29.0901 0x1dec [ EDFA5CEDBE174FAAA4A09A6B297AEA42, 5998FE15462E4AD9C7B1444E5E2C17BD470DA3A5D474A0A118E02E47DADC678A ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll
15:29:29.0949 0x1dec workfolderssvc - ok
15:29:30.0013 0x1dec [ A2468CC3509394A33C4C32F99563D845, 62690C7D41F382DF74B8F4B942647842858E37DE35FF2DE028192E4D09ABB2C5 ] wpcfltr C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
15:29:30.0024 0x1dec wpcfltr - ok
15:29:30.0076 0x1dec [ 19F4DF69876DA7E9C4965351560FE6B7, 127247A7964F55EE3AF842D25120F5ACD387632BEE2BF3D28FAC05840CEA19BA ] WPCSvc C:\WINDOWS\System32\wpcsvc.dll
15:29:30.0091 0x1dec WPCSvc - ok
15:29:30.0148 0x1dec [ 2ADE11F3D84709C5F6781E4C59F11683, F003C43396CF8FCF44EAB87583650DB4D2A233322D28D6A78D1694945D9073BB ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll
15:29:30.0164 0x1dec WPDBusEnum - ok
15:29:30.0216 0x1dec [ 9F2904B55F6CECCD1A8D986B5CE2609A, E19ED4DD3CEF3A22C058FC324824604FB3FC98A029C94E6C2A3389F938D680B6 ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys
15:29:30.0226 0x1dec WpdUpFltr - ok
15:29:30.0278 0x1dec [ AE072B0339D0A18E455DC21666CAD572, AB1DAEA25E2C7AD610818D4B4783F6D4190D85EBB3963BBAD410E8CEA7899EDB ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys
15:29:30.0292 0x1dec ws2ifsl - ok
15:29:30.0345 0x1dec [ 501D5EFAB9711039479AE48401386D2B, C8C1184DE93E9D2C4E8A60E4E9980745C4E5470E5DA9B59165D18705330ADEFE ] wscsvc C:\WINDOWS\System32\wscsvc.dll
15:29:30.0362 0x1dec wscsvc - ok
15:29:30.0385 0x1dec [ F586F3F1BF962FE9AE4316E0D896B22F, 8D0AD48D79294567123D943D0F5B6D5A32D7A82B129A24DC821D3095AFAA100B ] WSDPrintDevice C:\WINDOWS\System32\drivers\WSDPrint.sys
15:29:30.0396 0x1dec WSDPrintDevice - ok
15:29:30.0449 0x1dec [ 58035FD3369879E02D65989C44D27450, B9245DB5C17F7CE94FAA20AB4B0D06A4DFB6133C6E82343758CDC713EB64DFEF ] WSDScan C:\WINDOWS\system32\DRIVERS\WSDScan.sys
15:29:30.0460 0x1dec WSDScan - ok
15:29:30.0464 0x1dec WSearch - ok
15:29:30.0621 0x1dec [ 6B2D71124C1EA86B74412F414C42431D, 078CC6C9667EF6BDA3E6900BC26A5A5B030CAA66928A6BBB7B7DC43C5C199EDC ] WSService C:\WINDOWS\System32\WSService.dll
15:29:30.0721 0x1dec WSService - ok
15:29:30.0873 0x1dec [ 020F47C655ED1F63BBA834AA53575D5C, 7E36BB83B937CEA8B5D1EAF1DF63D32D64CA8045DA377DF5237D2F4DC16574CC ] wuauserv C:\WINDOWS\system32\wuaueng.dll
15:29:30.0965 0x1dec wuauserv - ok
15:29:31.0025 0x1dec [ 481286719402E4BAEFEA0604AB1B5113, F3CF65DF2AB39F79AE4C1335831408418E40726706E0242677E8B96B0FAD988F ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys
15:29:31.0037 0x1dec WudfPf - ok
15:29:31.0057 0x1dec [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys
15:29:31.0071 0x1dec WUDFRd - ok
15:29:31.0126 0x1dec [ 51D28F7F1F888DDCF2C67DCF3B79A5D3, 74FF2936AFCEB9A36175D5B00EB91A5AD614B52BE3FB3FA9B994A025A484D2B7 ] wudfsvc C:\WINDOWS\System32\WUDFSvc.dll
15:29:31.0142 0x1dec wudfsvc - ok
15:29:31.0150 0x1dec [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFWpdFs C:\WINDOWS\System32\drivers\WUDFRd.sys
15:29:31.0166 0x1dec WUDFWpdFs - ok
15:29:31.0173 0x1dec [ D7B4859227B02BCC1055B279A63C937F, 82C99844CC596C2723523B1B98573488FF23337947B78AA04BA21E58394BB751 ] WUDFWpdMtp C:\WINDOWS\System32\drivers\WUDFRd.sys
15:29:31.0188 0x1dec WUDFWpdMtp - ok
15:29:31.0294 0x1dec [ A0900F8F628B5AF6841414EB3CF11E50, 8A531F2472FF4B4D895D469D28C215C834ECADBEF539894B8F3F606079A86184 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll
15:29:31.0317 0x1dec WwanSvc - ok
15:29:31.0372 0x1dec [ 86B8B1F5C1189D68B07666784BE882FE, 0DD8C627F3DDBDB61B1910540C465C0D62C9F8D84C7CBB6C80782DB02D535AF0 ] ZAtheros Bt and Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
15:29:31.0382 0x1dec ZAtheros Bt and Wlan Coex Agent - detected UnsignedFile.Multi.Generic ( 1 )
15:29:33.0747 0x1dec Detect skipped due to KSN trusted
15:29:33.0747 0x1dec ZAtheros Bt and Wlan Coex Agent - ok
15:29:33.0759 0x1dec ================ Scan global ===============================
15:29:33.0785 0x1dec [ 3500AF0BA2EF095BF313EEB75D2366C6, C755E57B02BFA82151A182DF964349859575570EA5C3FBA81F747B8D2134A4D0 ] C:\WINDOWS\system32\basesrv.dll
15:29:33.0799 0x1dec [ EAB311B0A7A8EA0346F14F08D4BC8F46, 11168E4074679F8A69DA714C0ABD0C68BA49D171B379343F14783C9C563202CA ] C:\WINDOWS\system32\winsrv.dll
15:29:33.0853 0x1dec [ 3600ED7EA8AED849E20700551C0BD63B, 4A8C346C1646E80B58EF93F87F915A41E05CA2E993BB1C96955AE62A0669AF66 ] C:\WINDOWS\system32\sxssrv.dll
15:29:33.0920 0x1dec [ E0C7813A97CA7947FF5C18A8F3B61A45, 083BB4F3B20419C87DB656F1465E5F782ACDE76838CDE6207F26AAD035C69DE0 ] C:\WINDOWS\system32\services.exe
15:29:33.0930 0x1dec [ Global ] - ok
15:29:33.0931 0x1dec ================ Scan MBR ==================================
15:29:33.0939 0x1dec [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
15:29:34.0011 0x1dec \Device\Harddisk0\DR0 - ok
15:29:34.0015 0x1dec [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
15:29:34.0115 0x1dec \Device\Harddisk1\DR1 - ok
15:29:34.0116 0x1dec ================ Scan VBR ==================================
15:29:34.0146 0x1dec [ 6886F75186B233327FF9D62126DA330D ] \Device\Harddisk0\DR0\Partition1
15:29:34.0160 0x1dec \Device\Harddisk0\DR0\Partition1 - ok
15:29:34.0180 0x1dec [ 3C8FE5CDFB76823E49F409B080EE6FCA ] \Device\Harddisk0\DR0\Partition2
15:29:34.0194 0x1dec \Device\Harddisk0\DR0\Partition2 - ok
15:29:34.0203 0x1dec [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
15:29:34.0203 0x1dec \Device\Harddisk0\DR0\Partition3 - ok
15:29:34.0216 0x1dec [ 1392BDD7FE6391DF0D5393312AB523C8 ] \Device\Harddisk0\DR0\Partition4
15:29:34.0225 0x1dec \Device\Harddisk0\DR0\Partition4 - ok
15:29:34.0257 0x1dec [ E95C2D646FADE8536E45339B22BEF977 ] \Device\Harddisk0\DR0\Partition5
15:29:34.0267 0x1dec \Device\Harddisk0\DR0\Partition5 - ok
15:29:34.0283 0x1dec [ 605A458C42365FF268B01D97B7BC660A ] \Device\Harddisk0\DR0\Partition6
15:29:34.0294 0x1dec \Device\Harddisk0\DR0\Partition6 - ok
15:29:34.0297 0x1dec [ A6FE06AC60F7033541A2283EF38581C5 ] \Device\Harddisk1\DR1\Partition1
15:29:34.0302 0x1dec \Device\Harddisk1\DR1\Partition1 - ok
15:29:34.0303 0x1dec ================ Scan generic autorun ======================
15:29:34.0364 0x1dec [ ED77575498921FE61B53A5EBB1F4136B, C52D3451F34E5115A1AAA424DC8F0A7A2AA3468726BA1873F0BCCFE1480FCB57 ] C:\WINDOWS\system32\igfxtray.exe
15:29:34.0380 0x1dec IgfxTray - ok
15:29:34.0398 0x1dec [ F31985811DD87B61708B0E8484E88216, A61C4B48AFF70455FBD989FBAC3C9CF8C4C1425CF1F94296660036CF6E0E2B04 ] C:\WINDOWS\system32\hkcmd.exe
15:29:34.0423 0x1dec HotKeysCmds - ok
15:29:34.0453 0x1dec [ C89C68961854E7A67946BE47D44EFAF4, 954EE4BF56F9602B6275B6F852BBB5F739147B3D1395AC07A02BDE0027828CFF ] C:\WINDOWS\system32\igfxpers.exe
15:29:34.0477 0x1dec Persistence - ok
15:29:34.0861 0x1dec [ 6DDA13FB28B620FEE52E0E616F4E7B70, 8C75E17E2C0C81BA3D1660ACB73591C181C3BD15237DF3A2E9734A7FF365C16A ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
15:29:35.0131 0x1dec RTHDVCPL - ok
15:29:35.0143 0x1dec ETDCtrl - ok
15:29:35.0240 0x1dec [ 8BFE805555CDAF6387912A34D7978DAA, 6F9195D85B386099F9F63E3319F5E9E85E0F3A1F0D48CFC9A37E7EFF65225933 ] C:\WINDOWS\syswow64\RunDll32.exe
15:29:35.0254 0x1dec Cm108Sound - ok
15:29:35.0340 0x1dec [ 7C1ACD465142D7F50E8EE4D140F24A8B, 0F69CCFFCBA0848E886CD897273FF88B0A4D73394F7DDBC688ED4E905170F5AB ] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
15:29:35.0360 0x1dec StartCCC - ok
15:29:35.0405 0x1dec [ 4DAB37E8BEDA1F286F0C40B8AAB0D65C, 8125DC609079FDCFF58431BEB70827C5D29F3730BA76012822162C40EEDBBFF6 ] C:\Program Files (x86)\Everything\Everything.exe
15:29:35.0422 0x1dec Everything - detected UnsignedFile.Multi.Generic ( 1 )
15:29:37.0887 0x1dec Detect skipped due to KSN trusted
15:29:37.0887 0x1dec Everything - ok
15:29:37.0960 0x1dec [ 3BD79A1F6D2EA0FDDEA3F8914B2A6A0C, 332E6806EFF846A2E6D0DC04A70D3503855DABFA83E6EC27F37E2D9103E80E51 ] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
15:29:37.0969 0x1dec VirtualCloneDrive - ok
15:29:38.0232 0x1dec [ 60E6FC4E478A1D65069A1C331603101C, 5DDBBD49D9964BF3715660A3F91FCBB6703F7D6003FCA0D3E1BF9B1395F61394 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
15:29:38.0363 0x1dec AvastUI.exe - ok
15:29:38.0439 0x1dec [ 4DDC9B851FFCA263272B1BFF99B53C82, F2B28072C639A29CB40863EFBD5790422CC1A043E700558E9E6A2302B8A670FB ] C:\Program Files (x86)\PDF24\pdf24.exe
15:29:38.0452 0x1dec PDFPrint - ok
15:29:38.0568 0x1dec [ 53EBC5A93B96B8590BC7F02D7316A9EE, 40E2FF18A57128A197502A2D52808F326C4250B0CE9C310232A92139AF039D89 ] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
15:29:38.0581 0x1dec KiesTrayAgent - ok
15:29:38.0710 0x1dec [ 901AA7A38CE13F14B6BBEC38C0595698, 1E95F2048E2A1782807D52E9816ED267355718E24D01FF07ACE73D965EDE388A ] C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe
15:29:38.0720 0x1dec BCSSync - ok
15:29:38.0888 0x1dec [ 4EAF6F8F0B3BE33A0E3877EB7FFD48D4, CD89A31004E3E5A3253554CABF70B89D4F2FCBC40161FFA9E633CD85261A2769 ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
15:29:38.0917 0x1dec Adobe ARM - ok
15:29:38.0983 0x1dec [ C9B67BCB8E384064A8C2263740B0C437, F2609406A84F3A8E256DD250F84A774EF43F92C9F8B373E297A99ACF95B3CCE4 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
15:29:39.0006 0x1dec SunJavaUpdateSched - ok
15:29:39.0098 0x1dec [ 99C03F5D726A415253DBF09AFDA0A72E, 860DEF308AA90385763AF0F91F9CEFC3AFDB3C7DFB317B4A5C94429FD0F9707E ] C:\Program Files (x86)\Samsung\Kies\Kies.exe
15:29:39.0177 0x1dec KiesPreload - ok
15:29:39.0182 0x1dec Waiting for KSN requests completion. In queue: 211
15:29:40.0182 0x1dec Waiting for KSN requests completion. In queue: 211
15:29:41.0183 0x1dec Waiting for KSN requests completion. In queue: 211
15:29:42.0184 0x1dec Waiting for KSN requests completion. In queue: 211
15:29:42.0925 0x15b4 Object required for P2P: [ FAD8A14CAE92E805E48DA87B9564391A ] SQLWriter
15:29:43.0184 0x1dec Waiting for KSN requests completion. In queue: 153
15:29:44.0185 0x1dec Waiting for KSN requests completion. In queue: 153
15:29:45.0186 0x1dec Waiting for KSN requests completion. In queue: 153
15:29:46.0186 0x1dec Waiting for KSN requests completion. In queue: 153
15:29:46.0342 0x15b4 Object send P2P result: true
15:29:46.0348 0x15b4 Object required for P2P: [ BF8F54CA37E9C9D6582C31C5761F8C93 ] TsUsbFlt
15:29:47.0186 0x1dec Waiting for KSN requests completion. In queue: 116
15:29:48.0187 0x1dec Waiting for KSN requests completion. In queue: 116
15:29:48.0787 0x15b4 Object send P2P result: true
15:29:48.0797 0x15b4 Object required for P2P: [ 4EAF6F8F0B3BE33A0E3877EB7FFD48D4 ] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
15:29:49.0188 0x1dec Waiting for KSN requests completion. In queue: 3
15:29:50.0188 0x1dec Waiting for KSN requests completion. In queue: 3
15:29:51.0188 0x1dec Waiting for KSN requests completion. In queue: 3
15:29:52.0189 0x1dec Waiting for KSN requests completion. In queue: 3
15:29:52.0217 0x15b4 Object send P2P result: true
15:29:53.0201 0x1dec AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.8.207.0 ), 0x60100 ( disabled : updated )
15:29:53.0224 0x1dec AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 10.3.2225.1172 ), 0x41000 ( enabled : updated )
15:29:53.0226 0x1dec Win FW state via NFP2: enabled ( trusted )
15:29:55.0608 0x1dec ============================================================
15:29:55.0608 0x1dec Scan finished
15:29:55.0608 0x1dec ============================================================
15:29:55.0617 0x1df4 Detected object count: 1
15:29:55.0617 0x1df4 Actual detected object count: 1
15:30:12.0537 0x1df4 RadeonPro Support Service ( UnsignedFile.Multi.Generic ) - skipped by user
15:30:12.0537 0x1df4 RadeonPro Support Service ( UnsignedFile.Multi.Generic ) - User select action: Skip |