Teil 3 Code:
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\traydlg.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloaty2.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloatypop2.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayfloatypop2_bottom.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayTaskbar.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\layout\trayTaskbar_wifi.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\style --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Floaty\style\style.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\app.ico --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\file.ico --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\folder.ico --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\foldericon\picture.ico --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\idesk_icon.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\resource.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\traymenu_iconlist.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\app.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_cancel.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_close.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\btn_green_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\file.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\folder.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\logo_small.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\main_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\picture.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\image\arrangedesktop\yac_logo.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout\arrange_desktop.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\layout\traydlg.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\style --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\iDesk\style\style.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\layout --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\layout\default --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\layout\default\MsgCenterDlg.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\close.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\logo.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\Msg_BG.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\resouce\default\Resource.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\style --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\MsgCenter\style\Style.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\pop_startup_slow_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\pop_startup_warning_button.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\resource.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_iconlist.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_pop_cancel_btn2.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\traymenu_pop_ico_query.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\tray_radio_checked.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\image\tray_radio_unchecked.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout\traydlg.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\layout\traymenupop.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\style --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Nodisturb\style\style.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\bing_16_16.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\chrome_ico.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_browser2.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_browser_dropdown_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify2.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_pop_modify_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\combo_skin4.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\firefix_ico.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\google_16_16.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\ie_16_16.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\ie_ico.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\isafe_16.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\pop_startup_slow_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\pop_startup_warning_button.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\resource.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_iconlist.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_pop_cancel_btn2.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\traymenu_pop_ico_query.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\tray_radio_checked.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\tray_radio_unchecked.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\image\yahoo_16_16.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\accesslink.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\blockblacklist.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\lock_guide.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\querymodify.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\querymodify2.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\traydlg.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\layout\traymenupop.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\style --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\Protect\style\style.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\close.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\Location_ico.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\new_left.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\new_right.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_assistant_blue_number.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_assistant_yellow_number.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startupass_comb_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startupass_vscoll.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_fast_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_slow_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_warning_button.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_close.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_Setting.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_sys_star.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\resource.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_anim_expand_bk_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_anim_expand_bk_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_m.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_percent.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_char_s.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_close_btn_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_close_btn_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_drop_bk_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_drop_bk_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_skin_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_combo_skin_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_itemhover_bk_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_itemhover_bk_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_location_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_location_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_news_line_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_news_line_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_number.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_number_fuzzy.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_optimize_btn.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_large.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_middle.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_redpoint_small.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_late_night_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_late_night_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_morning_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_morning_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_nightfall_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_nightfall_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_noon_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_vscoll_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_vscoll_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_cloudy_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_cloudy_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_icon_large.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_icon_small.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_line_blue.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_line_yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_rain_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\pop_startup_nomall_button.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_time_noon_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_rain_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_snow_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_snow_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_thunder_blue.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_weather_thunder_yellow.jpg --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\sa_yac_logo.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\weather_icon.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\image\yellow.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\daily_news.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_2.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_3.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\layout\startup_assist_weather.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\style --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\trayplugin\StartupAssist\style\style.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\exam_tip_wnd_arrow_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\inst_cover_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func_up.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\av_authority_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\combo_list.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\custom_check.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\custom_uncheck.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_antymal_icon.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_clean_icon.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_optimize_icon.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\dl_inst_protect_icon.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\exam_tip_wnd_bk2.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\ico_app.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\ico_face.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\ico_upgrade.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_combo_skin.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_logo.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_prog_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\install_prog_meter.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\open_dir.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\popup_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\resource.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\soft_cof_button_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\soft_remove_button_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_1.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_2.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_3.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_4.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_5.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_6.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninstall_pic_7.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_acc.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_btn_bg1.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_btn_bg2.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_clean.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_complete.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_cry.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func1.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func3.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_func_intr.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_input.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_progress.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_prog_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_protect.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\uninst_spliter.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\upgrade_bg.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\upgrade_prog_bk.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\upgrade_prog_meter.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\vscroll.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\image\yac_side_ico.png --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\cover.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\install.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\uninstallpro.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\uninstall_logo_fade.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\layout\upgrade.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\style --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\skin2\uninstall\style\style.xml --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\update --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\update\0 --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\update\1 --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\update\temp --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\update\temp\dlcfg.ini --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\update\temp\upcfg.ini --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\user --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\user\sie.dat --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\user\softcache2.dat --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\user\svc2.dat --> [FraudTool.YAC]
Infected: C:\Program Files (x86)\Elex-tech\YAC\user\svc2_com.dat --> [FraudTool.YAC]
Scan finished
Creating System Restore point...
Cleaning up...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Removal scheduling successful. System shutdown needed.
System shutdown occurred
=======================================
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.3.1001
(c) Malwarebytes Corporation 2011-2012
OS version: 10.0.14393 Windows 10 x64
Account is Administrative
Internet Explorer version: 11.447.14393.0
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, G:\ DRIVE_FIXED
CPU speed: 4.008000 GHz
Memory total: 17107206144, free: 14521020416
=======================================
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.3.1001
(c) Malwarebytes Corporation 2011-2012
OS version: 10.0.9200 Windows 10 x64
Account is Administrative
Internet Explorer version: 11.447.14393.0
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED, G:\ DRIVE_FIXED
CPU speed: 4.008000 GHz
Memory total: 17107206144, free: 15317635072
=======================================
Initializing...
Driver version: 0.3.0.4
------------ Kernel report ------------
11/17/2016 15:03:00
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\System32\drivers\werkernel.sys
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\System32\drivers\FLTMGR.SYS
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\System32\drivers\ksecdd.sys
\SystemRoot\System32\drivers\clipsp.sys
\SystemRoot\System32\drivers\cmimcext.sys
\SystemRoot\System32\drivers\ntosext.sys
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\cng.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\drivers\intelpep.sys
\SystemRoot\system32\drivers\WindowsTrustedRT.sys
\SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\System32\drivers\imofugc.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\system32\drivers\CEA.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\storahci.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Wof.sys
\SystemRoot\System32\Drivers\NTFS.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\System32\drivers\wfplwfs.sys
\SystemRoot\System32\Drivers\aswVmm.sys
\SystemRoot\System32\Drivers\aswRvrt.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\volume.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\drivers\iorate.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\system32\drivers\aswSP.sys
\SystemRoot\system32\drivers\aswSnx.sys
\SystemRoot\system32\drivers\filecrypt.sys
\SystemRoot\system32\drivers\tbs.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\system32\drivers\aswKbd.sys
\SystemRoot\System32\drivers\BasicDisplay.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\BasicRender.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\ws2ifsl.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\aswRdr2.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\drivers\vwififlt.sys
\SystemRoot\System32\drivers\pacer.sys
\SystemRoot\system32\drivers\aswNetSec.sys
\SystemRoot\system32\drivers\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\drivers\gpuenergydrv.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\SysWow64\drivers\AsUpIO.sys
\SystemRoot\SysWow64\drivers\AsIO.sys
\SystemRoot\system32\DRIVERS\ahcache.sys
\SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys
\SystemRoot\System32\drivers\kdnic.sys
\SystemRoot\System32\drivers\umbus.sys
\SystemRoot\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_848dea456d3c865e\nvlddmkm.sys
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\System32\drivers\portcls.sys
\SystemRoot\System32\drivers\drmk.sys
\SystemRoot\System32\drivers\ks.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\system32\drivers\ucx01000.sys
\SystemRoot\System32\drivers\TeeDriverW8x64.sys
\SystemRoot\System32\drivers\asmtxhci.sys
\SystemRoot\System32\drivers\serial.sys
\SystemRoot\System32\drivers\serenum.sys
\SystemRoot\system32\DRIVERS\e1d65x64.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\intelppm.sys
\SystemRoot\System32\drivers\acpipagr.sys
\SystemRoot\system32\drivers\nvvad64v.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\drivers\NdisVirtualBus.sys
\SystemRoot\System32\drivers\swenum.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\system32\drivers\nvhda64v.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\System32\drivers\USBD.SYS
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_storahci.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\drivers\asmthub3.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\win32kfull.sys
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\System32\win32kbase.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\System32\drivers\USBSTOR.SYS
\SystemRoot\System32\drivers\mouhid.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\drivers\kbdhid.sys
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\system32\DRIVERS\SaiK0728.sys
\SystemRoot\System32\drivers\dxgmms2.sys
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\wcifs.sys
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\drivers\storqosflt.sys
\SystemRoot\system32\drivers\aswMonFlt.sys
\SystemRoot\system32\drivers\wcnfs.sys
\SystemRoot\System32\drivers\registry.sys
\SystemRoot\system32\DRIVERS\WUDFRd.sys
\SystemRoot\System32\drivers\WpdUpFltr.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\rspndr.sys
\SystemRoot\system32\drivers\lltdio.sys
\SystemRoot\system32\drivers\mslldp.sys
\SystemRoot\system32\drivers\aswStm.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\system32\drivers\mmcss.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\Windows\SysWoW64\speedfan.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\drivers\WSDPrint.sys
\SystemRoot\system32\DRIVERS\WSDScan.sys
\SystemRoot\System32\drivers\umpass.sys
\SystemRoot\System32\drivers\condrv.sys
\??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
----------- End -----------
Done!
Scan started
Database versions:
main: v2016.11.17.08
rootkit: v2016.10.31.01
<<<2>>>
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xffffcf084d749060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffcf084d60dae0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffcf084d749060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
DevicePointer: 0xffffcf084d51f590, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffcf084d519e40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffcf084d51e060, DeviceName: \Device\00000039\, DriverName: \Driver\storahci\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffcf084d74a060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffcf084d60fae0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffcf084d74a060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xffffcf084d51f790, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffcf084d51ae40, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffcf084d521060, DeviceName: \Device\00000038\, DriverName: \Driver\storahci\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 66984B4A
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2048 Numsec = 1024000
Partition is bootable
Partition file system is NTFS
Partition 1 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 1026048 Numsec = 975742976
Partition is not bootable
Partition file system is NTFS
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 500107862016 bytes
Sector size: 512 bytes
Done!
Drive 1
This is a System drive
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 7224777E
Partition information:
Partition 0 type is Primary (0x7)
Partition is ACTIVE.
Partition starts at LBA: 2 Numsec = 488397166
Partition is bootable
Partition file system is NTFS
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 250059350016 bytes
Sector size: 512 bytes
Done!
Physical Sector Size: 512
Drive: 2, DevicePointer: 0xffffcf084edaf060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffcf084edb6040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffcf084edaf060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\disk\
DevicePointer: 0xffffcf084edb5060, DeviceName: \Device\0000004d\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 2
Scanning MBR on drive 2...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 0
Partition information:
Partition 0 type is Other (0xc)
Partition is NOT ACTIVE.
Partition starts at LBA: 32 Numsec = 121307104
Partition is not bootable
Partition file system is FAT32
Partition 1 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 2 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0 Numsec = 0
Partition is not bootable
Disk Size: 62109253632 bytes
Sector size: 512 bytes
Done!
File "C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat" is sparse (flags = 32768)
Scan finished
=======================================
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-1-1026048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-0-2-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-2-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-2-0-32-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-2-r.mbam...
Removal finished TDSSKiller Teil1 Code:
15:15:15.0832 0x21b8 TDSS rootkit removing tool 3.1.0.12 Nov 7 2016 07:10:01
15:15:23.0479 0x21b8 ============================================================
15:15:23.0479 0x21b8 Current date / time: 2016/11/17 15:15:23.0479
15:15:23.0479 0x21b8 SystemInfo:
15:15:23.0479 0x21b8
15:15:23.0479 0x21b8 OS Version: 10.0.14393 ServicePack: 0.0
15:15:23.0479 0x21b8 Product type: Workstation
15:15:23.0479 0x21b8 ComputerName: DESKTOP-L90M10J
15:15:23.0479 0x21b8 UserName: Marko
15:15:23.0479 0x21b8 Windows directory: C:\Windows
15:15:23.0479 0x21b8 System windows directory: C:\Windows
15:15:23.0479 0x21b8 Running under WOW64
15:15:23.0479 0x21b8 Processor architecture: Intel x64
15:15:23.0479 0x21b8 Number of processors: 8
15:15:23.0479 0x21b8 Page size: 0x1000
15:15:23.0479 0x21b8 Boot type: Normal boot
15:15:23.0479 0x21b8 CodeIntegrityOptions = 0x00000001
15:15:23.0479 0x21b8 ============================================================
15:15:23.0603 0x21b8 KLMD registered as C:\Windows\system32\drivers\56091211.sys
15:15:23.0603 0x21b8 KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 14393.447, osProperties = 0x19
15:15:23.0688 0x21b8 System UUID: {6B149E7E-B37E-5F59-4987-4C62B73D5173}
15:15:23.0862 0x21b8 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:15:23.0863 0x21b8 Drive \Device\Harddisk1\DR1 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
15:15:23.0866 0x21b8 Drive \Device\Harddisk2\DR2 - Size: 0xE76000000 ( 57.84 Gb ), SectorSize: 0x200, Cylinders: 0x1D7F, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
15:15:23.0867 0x21b8 ============================================================
15:15:23.0867 0x21b8 \Device\Harddisk0\DR0:
15:15:23.0867 0x21b8 MBR partitions:
15:15:23.0867 0x21b8 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xFA000
15:15:23.0867 0x21b8 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xFA800, BlocksNum 0x3A28A800
15:15:23.0867 0x21b8 \Device\Harddisk1\DR1:
15:15:23.0867 0x21b8 MBR partitions:
15:15:23.0867 0x21b8 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x2, BlocksNum 0x1D1C596E
15:15:23.0867 0x21b8 \Device\Harddisk2\DR2:
15:15:23.0868 0x21b8 MBR partitions:
15:15:23.0868 0x21b8 \Device\Harddisk2\DR2\Partition1: MBR, Type 0xC, StartLBA 0x20, BlocksNum 0x73AFFE0
15:15:23.0868 0x21b8 ============================================================
15:15:23.0869 0x21b8 C: <-> \Device\Harddisk1\DR1\Partition1
15:15:23.0869 0x21b8 D: <-> \Device\Harddisk0\DR0\Partition1
15:15:23.0870 0x21b8 G: <-> \Device\Harddisk0\DR0\Partition2
15:15:23.0870 0x21b8 ============================================================
15:15:23.0870 0x21b8 Initialize success
15:15:23.0870 0x21b8 ============================================================
15:15:55.0054 0x1c08 ============================================================
15:15:55.0054 0x1c08 Scan started
15:15:55.0054 0x1c08 Mode: Manual; SigCheck; TDLFS;
15:15:55.0054 0x1c08 ============================================================
15:15:55.0054 0x1c08 KSN ping started
15:15:55.0238 0x1c08 KSN ping finished: true
15:15:56.0422 0x1c08 ================ Scan system memory ========================
15:15:56.0422 0x1c08 System memory - ok
15:15:56.0422 0x1c08 ================ Scan services =============================
15:15:56.0441 0x1c08 [ A7901875F89D011C38CF52C98ACF5B29, 782141AB1DD7ACDE6EA08B5BAFDE8BADD05B81D38C18E097D6D9C46102056EB1 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
15:15:56.0468 0x1c08 1394ohci - ok
15:15:56.0473 0x1c08 [ EE1CCC54F75C24727A218F98FC5349DA, 0B0D26640BFA0F551B7087027E572D0BF2C5EAF50A4187C5A7D839180B7FF589 ] 3ware C:\Windows\system32\drivers\3ware.sys
15:15:56.0480 0x1c08 3ware - ok
15:15:56.0491 0x1c08 [ 73C73E1AA0D4D727A04AAAB120B7F56A, 5D311F11022994410DF5C67914D38B1F0D813EFD181EA234750286A272D67A1A ] ACPI C:\Windows\system32\drivers\ACPI.sys
15:15:56.0506 0x1c08 ACPI - ok
15:15:56.0508 0x1c08 [ 0935496EF9624B46B935CB35ECE1F205, A22A2A29195505A65E8626D60B00C86C23E0CABC1EB8345EA5ED523516CC21C0 ] AcpiDev C:\Windows\System32\drivers\AcpiDev.sys
15:15:56.0515 0x1c08 AcpiDev - ok
15:15:56.0519 0x1c08 [ D6794C31F4077B71433988787BAA926E, F16365C2F195AAE94D4740E6C3DF4C0CECEC6393CAD65425DCCD28CDBA6EC51A ] acpiex C:\Windows\system32\Drivers\acpiex.sys
15:15:56.0526 0x1c08 acpiex - ok
15:15:56.0528 0x1c08 [ FE5F656D6B35089DA39112E74EC6A85A, 5D81EE63998232A5B36DE47FE15B9D04D5BD02234CA133A2462AECA8C60A22ED ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
15:15:56.0534 0x1c08 acpipagr - ok
15:15:56.0537 0x1c08 [ 2F242941E4DFF69B883D77A16F039557, 45C388365317C720654A659A9326B2BC0E9D84929C704654985597D5D620101C ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
15:15:56.0543 0x1c08 AcpiPmi - ok
15:15:56.0545 0x1c08 [ C247E35A21682DA8D0DC3AF9F025FCC5, 455415EE3166B3043AD8A4DD50B688DB74242267FB555642441251EFA823E971 ] acpitime C:\Windows\System32\drivers\acpitime.sys
15:15:56.0551 0x1c08 acpitime - ok
15:15:56.0565 0x1c08 [ 8532B30A054D83614A90D24AD61A29DF, 959C74C63AF7F4E5588C705FBF08EA7A8749268BC28819879ED53AB7A3410B74 ] AdobeUpdateService C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
15:15:56.0577 0x1c08 AdobeUpdateService - ok
15:15:56.0594 0x1c08 [ 49B9DB97AFC85DCCBDACDAB2E90085B7, 2A6C2A09F74EA15044F442CCFB54A0F24F105ADB915E5C78F02F59652DC29152 ] ADP80XX C:\Windows\system32\drivers\ADP80XX.SYS
15:15:56.0614 0x1c08 ADP80XX - ok
15:15:56.0624 0x1c08 [ 323AA1953ED9C01E23F740FA891FE064, 4CED6E3D61749316CDE28965C913E7ED462539DAAD637A29484F62AF47AD650D ] AFD C:\Windows\system32\drivers\afd.sys
15:15:56.0638 0x1c08 AFD - ok
15:15:56.0666 0x1c08 [ 021D06851E7AFF5C314039DF813608F3, 081B14840F4AD428B4407AA2E639369A45D174D9507BD107F33FE3A94FB8F8EC ] AGSService C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
15:15:56.0694 0x1c08 AGSService - ok
15:15:56.0700 0x1c08 [ 23522E5D581F7722B1B5B86737CAE39C, FB81ABD304376A1E87B65F5E1B34477B628CEDB2091C5D754DE97464B6050C5B ] ahcache C:\Windows\system32\DRIVERS\ahcache.sys
15:15:56.0711 0x1c08 ahcache - ok
15:15:56.0719 0x1c08 [ 4BFB41025FA1C37205EDEEFDE36F7771, EA171520C0C8DAFA3D656EC4815393F77096C1E22EC9F39756B52D1565483102 ] AiChargerPlus C:\Windows\syswow64\drivers\AiChargerPlus.sys
15:15:56.0724 0x1c08 AiChargerPlus - ok
15:15:56.0727 0x1c08 [ D0905D4A945D01D4B28DB9E1BD5985F7, CF389CBCD3B99D1BAE34A42F723F1005C32213A394F691978076D3DF1727715C ] AJRouter C:\Windows\System32\AJRouter.dll
15:15:56.0734 0x1c08 AJRouter - ok
15:15:56.0736 0x1c08 [ 8FD51B3B35707A66080D7C8CB05E792D, FE52F3DC280D208FDDC75F6E3294B8D601E0D86F9BD3DB1ACC8FC296AC74C23B ] ALG C:\Windows\System32\alg.exe
15:15:56.0745 0x1c08 ALG - ok
15:15:56.0753 0x1c08 [ 23CB92EE5654BA92619D796E3AC7DB86, DD4536B55F021990DDAD8864F9BAECCDE40B2B532F6FB0D6CF9EB1A6B112A983 ] ALSysIO C:\Users\Marko\AppData\Local\Temp\ALSysIO64.sys
15:15:56.0759 0x1c08 ALSysIO - ok
15:15:56.0765 0x1c08 [ DF21E05E41E5AC3F13F304D91457649A, 7F48F2AD1DBE89A261113C76D7C23AD7D87D5599BCC31F8A558A8A10B81BF521 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
15:15:56.0774 0x1c08 AmdK8 - ok
15:15:56.0777 0x1c08 [ 45D0AA4BB90B821DF92E8F19ABED0C5E, EA87A6E98DB3C5A88A844C04C6934E870B7004E783AA5211722115382A211B90 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
15:15:56.0786 0x1c08 AmdPPM - ok
15:15:56.0789 0x1c08 [ 74FFBC43B4B899C9A8CA06A892F2CE73, 8D599363C7F3D373F1859BAA4D06DD0F40BE78B56BE52B74DE6EA6EF99452004 ] amdsata C:\Windows\system32\drivers\amdsata.sys
15:15:56.0795 0x1c08 amdsata - ok
15:15:56.0800 0x1c08 [ AAB0F1D8D7E54761ABAB13AF161F1680, CF847990EFFA2828F5B1DB1A68F08A6C2C918E9612EDFFCF95C36BCABBBEA272 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
15:15:56.0809 0x1c08 amdsbs - ok
15:15:56.0811 0x1c08 [ F91BAAC4237C40352A807000F3B716F9, F7EFA08E5067C3D419C9D21EDB880BA08883A80DDF35F8B42EC3AB293FE5E03E ] amdxata C:\Windows\system32\drivers\amdxata.sys
15:15:56.0817 0x1c08 amdxata - ok
15:15:56.0821 0x1c08 [ BC121C099C6C659126AD2102AFDFF8CF, 42B5EE293BDD7ADCE48173A01B30D8452564B9DA225EAF25E9292FE77C0FCF3E ] AppID C:\Windows\system32\drivers\appid.sys
15:15:56.0829 0x1c08 AppID - ok
15:15:56.0832 0x1c08 [ 74A24CF946279111D7F203B36569EC02, FD67D36804744B4FE3E20BA891852575E6C2DA6515643B2F4B4210118B0FCCDA ] AppIDSvc C:\Windows\System32\appidsvc.dll
15:15:56.0846 0x1c08 AppIDSvc - ok
15:15:56.0849 0x1c08 [ 73FAA5517CCD1332F00192A303CF2026, 75636222BFF381A3EECA010752DF7DC1603A395B91FF7FBF92127B5CA8EFFEE5 ] Appinfo C:\Windows\System32\appinfo.dll
15:15:56.0859 0x1c08 Appinfo - ok
15:15:56.0863 0x1c08 [ 885888F8AAD89108A5EE2D0174690220, 9B148C117EBE400F40BF7F32B66B20AA4628BA9E233D707DFA2EB4A8A65E7C52 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:15:56.0867 0x1c08 Apple Mobile Device Service - ok
15:15:56.0869 0x1c08 [ 68190E2BADF23BD782344970E5B5DE9E, 95D30EC12C7FDF5822CED8BC2F17669A6687A2FB262B4F0D15C8DCFF4E9AB33D ] applockerfltr C:\Windows\system32\drivers\applockerfltr.sys
15:15:56.0879 0x1c08 applockerfltr - ok
15:15:56.0883 0x1c08 [ 76A12AC673B0F8A607ACDD0583C247D4, CBC6C0EB82C7A8E3998344280BBB5A697AFA7206CA2BADFDA7ED6E7DD20E3DAC ] AppMgmt C:\Windows\System32\appmgmts.dll
15:15:56.0893 0x1c08 AppMgmt - ok
15:15:56.0902 0x1c08 [ 21DC11DA29484AE026E536F2EA7E79E5, 6E17B679494CB293DE13DFA18F79A9DFAFEEBAAE41943F95B5E1AE0720A5CA26 ] AppReadiness C:\Windows\system32\AppReadiness.dll
15:15:56.0919 0x1c08 AppReadiness - ok
15:15:56.0931 0x1c08 [ 6010A920FDE5BFE4EA056F9736FBDC06, F55F68D5AD1F272BC285E716E02090C62FC87476DD6CE7ABA6BE7EF8EF6178DE ] AppVClient C:\Windows\system32\AppVClient.exe
15:15:56.0949 0x1c08 AppVClient - ok
15:15:56.0953 0x1c08 [ B66ED2CB37F7E4696A51612AFBA08834, 70BA67AF7F1290E3145B873B53516F138E50D8AAC80CD00CBA66467ABC6643CB ] AppvStrm C:\Windows\system32\drivers\AppvStrm.sys
15:15:56.0960 0x1c08 AppvStrm - ok
15:15:56.0965 0x1c08 [ 8DC924848E20F890BEFC6B31136D46BE, B7603425B4970F505B5A3EB0F6652A9CDD188059BDC945D6DF2BADC2DF8F4B5D ] AppvVemgr C:\Windows\system32\drivers\AppvVemgr.sys
15:15:56.0973 0x1c08 AppvVemgr - ok
15:15:56.0977 0x1c08 [ 9ADC5A8BEE10E174F95349E9232D8E76, F322991323DCDC51199BB3AB0DA20F6C3CC7EE6E804400B473C610FDB895F0AE ] AppvVfs C:\Windows\system32\drivers\AppvVfs.sys
15:15:56.0984 0x1c08 AppvVfs - ok
15:15:57.0012 0x1c08 [ F9F4CFCB3845EABF81A654001C80854C, 2CB7BED0A838585903056E41D46C2604B5EECA3B6C673497A22BFFCAE7986C5F ] AppXSvc C:\Windows\system32\appxdeploymentserver.dll
15:15:57.0059 0x1c08 AppXSvc - ok
15:15:57.0067 0x1c08 Archer - ok
15:15:57.0070 0x1c08 [ E6AB1F0B4C3D4E0D2A88332D76FECD03, 0D3003EB979DA4546DCDD055011E24F13E34F683F02C9801CAC564D1809F11D2 ] arcsas C:\Windows\system32\drivers\arcsas.sys
15:15:57.0077 0x1c08 arcsas - ok
15:15:57.0090 0x1c08 [ BBF8F831C7720DD5135D8C4C8325187A, 2630C68200D7BD49A5772830D6B369C0EC337C2558A9562DD564DF042249ECC0 ] asComSvc C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
15:15:57.0105 0x1c08 asComSvc - ok
15:15:57.0118 0x1c08 [ 43A8C7A3FBDF14D36CC4A604C43139BC, 3445119038E5A1E2B107A941F8EA52B0D6CE91F6AF2A2F4128BA386BF3DF11D3 ] asHmComSvc C:\Program Files (x86)\ASUS\AAHM\1.00.23\aaHMSvc.exe
15:15:57.0133 0x1c08 asHmComSvc - ok
15:15:57.0135 0x1c08 [ 798DE15F187C1F013095BBBEB6FB6197, 436CCAB6F62FA2D29827916E054ADE7ACAE485B3DE1D3E5C6C62D3DEBF1480E7 ] AsIO C:\Windows\syswow64\drivers\AsIO.sys
15:15:57.0139 0x1c08 AsIO - ok
15:15:57.0143 0x1c08 [ A750BB0FA32D1CC1E0FC740F09BBA3FD, B068F97AD7B47FD224946B98E0F067217A7D8BB8107160EB671F323CFFB3EF06 ] asmthub3 C:\Windows\System32\drivers\asmthub3.sys
15:15:57.0148 0x1c08 asmthub3 - ok
15:15:57.0155 0x1c08 [ 3054586B131D04D2E8796806CA581361, C650A4D93A79FB6F389D727E55CB0A8784600AFA8AE46E47998B4ED244B8F09A ] asmtxhci C:\Windows\System32\drivers\asmtxhci.sys
15:15:57.0163 0x1c08 asmtxhci - ok
15:15:57.0181 0x1c08 [ 37F7DD839A711B5706B1264F4D8D4BDC, C949A7BB236C6C03E197EF7F9A6DF53E34EC35D925034351B5FD5D7DB62A770E ] AsSysCtrlService C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
15:15:57.0213 0x1c08 AsSysCtrlService - detected UnsignedFile.Multi.Generic ( 1 )
15:15:57.0247 0x1c08 Detect skipped due to KSN trusted
15:15:57.0247 0x1c08 AsSysCtrlService - ok
15:15:57.0250 0x1c08 [ 1392B92179B07B672720763D9B1028A5, B4D47EA790920A4531E3DF5A4B4B0721B7FEA6B49A35679F0652F1E590422602 ] AsUpIO C:\Windows\syswow64\drivers\AsUpIO.sys
15:15:57.0257 0x1c08 AsUpIO - ok
15:15:57.0271 0x1c08 [ 8B18DE4E8D649CFBFBFBC67C1AA13C57, E6FACE3BF363AE82105B63771DCA502DB82B188EC090086C7F960CE37A28E9E1 ] AsusFanControlService C:\Program Files (x86)\ASUS\AsusFanControlService\1.08.15\AsusFanControlService.exe
15:15:57.0286 0x1c08 AsusFanControlService - ok
15:15:57.0290 0x1c08 [ A5E4CDB420540095D1293C874B5F89AA, EBC082FF94872537649F00D91AF22E0AFB4D538ACDB4731C9A95D209C7B144FD ] ASUSFILTER C:\Windows\syswow64\drivers\ASUSFILTER.sys
15:15:57.0295 0x1c08 ASUSFILTER - ok
15:15:57.0299 0x1c08 [ 9B480B472D6826E7257C90E2D0EE2954, C52C198602D180011A9345AE6F108EC4B1FD91234AF2E6296B2E39C1888B0D4D ] aswHwid C:\Windows\system32\drivers\aswHwid.sys
15:15:57.0306 0x1c08 aswHwid - ok
15:15:57.0309 0x1c08 [ 06362BBA1347CBA0996F4B39BB1D8353, 0C6B7B085F13FB7C71E2AF481CD216C6ACB63577DC7E2793182F734378C141DA ] aswKbd C:\Windows\system32\drivers\aswKbd.sys
15:15:57.0314 0x1c08 aswKbd - ok
15:15:57.0317 0x1c08 [ 1BB00571CC2C78463ABD7E9C32970758, BF523468754CB1628D66F28B06FAF7C545C5724801B04888517A2FB4BF9582BF ] aswMonFlt C:\Windows\system32\drivers\aswMonFlt.sys
15:15:57.0322 0x1c08 aswMonFlt - ok
15:15:57.0329 0x1c08 [ 75325BC6BE15471331FFCEEC14E1DA03, 68A9DC2C4518DBAD54E60B7C89F713DD9FD287D42CFC75700D44A5B8CA4AED0F ] aswNetSec C:\Windows\system32\drivers\aswNetSec.sys
15:15:57.0337 0x1c08 aswNetSec - ok
15:15:57.0341 0x1c08 [ 7010B57D708DA5C9686A5923EE621776, 5A554B8941C156EC341C602F34679A7475802B19EE6A99AA29AE2628A123ECB1 ] aswRdr C:\Windows\system32\drivers\aswRdr2.sys
15:15:57.0345 0x1c08 aswRdr - ok
15:15:57.0348 0x1c08 [ 937885085BFE5BD08EC1BC0245DD203B, 6DDD89245EEA3B8106C5F2EB6FA8CF525F3B42AA7032276DE78953E06FE7F4B4 ] aswRvrt C:\Windows\system32\drivers\aswRvrt.sys
15:15:57.0352 0x1c08 aswRvrt - ok
15:15:57.0366 0x1c08 [ 0B6352251C5D84130DF4252D33D266C2, C6A2E0074A7FCFB5799949431F5660B9AF6441001EA9B609F7B3900F4007EBD0 ] aswSnx C:\Windows\system32\drivers\aswSnx.sys
15:15:57.0381 0x1c08 aswSnx - ok
15:15:57.0390 0x1c08 [ 28213B34725B18387CC1B8C3D73858A1, D86113D89C62F090B393B68B522581248AEF3568F8FD0FF86B3625F2E6DD4DB8 ] aswSP C:\Windows\system32\drivers\aswSP.sys
15:15:57.0400 0x1c08 aswSP - ok
15:15:57.0404 0x1c08 [ 9C58B6E9663D0A76D00D83E43C765BDF, 3F474932E77318CD450A3A9C89667D2B26A7E3FAB9AA95D97FF3B1979623A7F2 ] aswStm C:\Windows\system32\drivers\aswStm.sys
15:15:57.0409 0x1c08 aswStm - ok
15:15:57.0414 0x1c08 [ D60D9201739400F0FBDB9E36A3212D91, 01A17516AB7F4D2C72E2DC51F7B49D1C4F50F564992F78A71E73821D7F8220E7 ] aswVmm C:\Windows\system32\drivers\aswVmm.sys
15:15:57.0422 0x1c08 aswVmm - ok
15:15:57.0424 0x1c08 [ 61C5A480C43E7E8E49C42869F49D0D3E, E610F0E4315ABA1D90AD4A1D7A68ABA2ACBB7FCA89E9D1798470365D52592D55 ] AsyncMac C:\Windows\System32\drivers\asyncmac.sys
15:15:57.0431 0x1c08 AsyncMac - ok
15:15:57.0433 0x1c08 [ A10F989A812B57B9695F6C305907C9C6, E2B292610079AA1A10696138DE8130905A8A834B75A8DED7EBF8B6732B77A0F4 ] atapi C:\Windows\system32\drivers\atapi.sys
15:15:57.0439 0x1c08 atapi - ok
15:15:57.0444 0x1c08 [ 2DC3D53FFA0D10EB8C911AE2DB7BF4CF, 8E0A4B5D610D487A216E70396A99ACC1BEA12C46A6681B1A39CD0FD01EDD406A ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
15:15:57.0457 0x1c08 AudioEndpointBuilder - ok
15:15:57.0470 0x1c08 [ 7B993290E7691C446C16A56A431669BA, 004551934E27E9FC1A939C9BD1DEB850A216CBED9B18CB3317920F5656D9F6BF ] Audiosrv C:\Windows\System32\Audiosrv.dll
15:15:57.0494 0x1c08 Audiosrv - ok
15:15:57.0500 0x1c08 [ F4E0580B5789474385E7ACB189C4AF2C, DB5BE2C852AC102AB8EB186362E582E250B843BA52B3B71AF08A5FDA8A6F91AF ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
15:15:57.0506 0x1c08 avast! Antivirus - ok
15:15:57.0510 0x1c08 [ CAA9BB913356E9FD56761C9352B7054B, E810C6EE0673BEBCF9C74223D120589E8441CB1B74D25A7E10554B6EA96D6909 ] avast! Firewall C:\Program Files\AVAST Software\Avast\afwServ.exe
15:15:57.0516 0x1c08 avast! Firewall - ok
15:15:57.0520 0x1c08 [ 6D90FDA2DC364B8EA1420F2F81585CC3, 10E6F23A213CFE49BE04BB7D366ADD4028D61D7114FEC67C30B5467DF6B36D4F ] AxInstSV C:\Windows\System32\AxInstSV.dll
15:15:57.0529 0x1c08 AxInstSV - ok
15:15:57.0538 0x1c08 [ 61BAC67048CA5C1D08C48FCC8012B613, 71B2A466FC38DA1029B471FBD2541D8FE359751A7B212AE0F420DB3645916450 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
15:15:57.0551 0x1c08 b06bdrv - ok
15:15:57.0554 0x1c08 [ 68F72B05EBC6D1779C0D60A147C7CA0B, AA1C857BEE34865C6B901157FC22570D4CF45D950708BAD7AA333F120F2B474C ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
15:15:57.0561 0x1c08 BasicDisplay - ok
15:15:57.0564 0x1c08 [ 23156E7EDAF613D839E2839746B168D3, CAEF8F9C7D3A338BD747AC9D5BFBE730D77B911E87BCF532EBB75E1F80916AFA ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
15:15:57.0570 0x1c08 BasicRender - ok
15:15:57.0573 0x1c08 [ 3F5523DCEFE42B385659C5CB46A6B810, CA24A3DF002B19E7BDEDE9B5EB60623F299D0E78B2E4F58DCFC028D76DEFE52D ] bcmfn C:\Windows\System32\drivers\bcmfn.sys
15:15:57.0580 0x1c08 bcmfn - ok
15:15:57.0582 0x1c08 [ 0B750A6A6D847E73CA48ADD7A0F5A393, 6A43020F23846EFB1AFA3C070465B0059E9DF60DEB16899E09559462DF30939F ] bcmfn2 C:\Windows\System32\drivers\bcmfn2.sys
15:15:57.0588 0x1c08 bcmfn2 - ok
15:15:57.0594 0x1c08 [ 2B4D3AEAAD02954F8C191BC2D67949AD, 8237C9AD556CFAF7442FF60F78608104BC17CE3134C89D986D49C38CC60B1518 ] BDESVC C:\Windows\System32\bdesvc.dll
15:15:57.0608 0x1c08 BDESVC - ok
15:15:57.0610 0x1c08 [ 0A508274355745EEF01C6BE3198D02C4, E2DB08AEE2368FA95FDB357BB31EA4EBF31679C3E72E109DB3D7CD1B5F7B828E ] Beep C:\Windows\system32\drivers\Beep.sys
15:15:57.0616 0x1c08 Beep - ok
15:15:57.0628 0x1c08 [ 5125CBB61AC81168366BEB290399CB8E, B2A3095D45E2114DE2BD0E5A3AE20B3CE95EE517A35B9E1EAD05E231F38DBDCF ] BFE C:\Windows\System32\bfe.dll
15:15:57.0649 0x1c08 BFE - ok
15:15:57.0665 0x1c08 [ D876C567AB767258036F05E4766189FD, DE8BA67325CB64495BD454B8F9DDCAE82636253844FC68B360C7E1CF5D51DD0E ] BITS C:\Windows\System32\qmgr.dll
15:15:57.0692 0x1c08 BITS - ok
15:15:57.0700 0x1c08 [ B5C2F92EE1106DFE7BB1CCE4D35B6037, E399C390687589194D8AAD385055F0CFA7D52AD9E837D8FF95008B8EB2B34E50 ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
15:15:57.0708 0x1c08 Bonjour Service - ok
15:15:57.0711 0x1c08 [ 9CD2A4821DE379305CACB2E99AD8953A, 89D700DFC3C59ACBBADB48954A28C0EBF8D6A11A9E63837689DD891868E43188 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
15:15:57.0720 0x1c08 bowser - ok
15:15:57.0730 0x1c08 [ 2447BD15B41298622CC662249CD0F496, 013A326D2E3BF68D654BBABE2F1E5DF0FF0A153A4B95D570EE28F9BC0F5A78C3 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
15:15:57.0751 0x1c08 BrokerInfrastructure - ok
15:15:57.0755 0x1c08 [ B3F32C630DD3F2F6A6091B89CFF13641, 7A9C53EF9AB9FF1DC392FD711B194A101DB36CA5BC799E817BEB446741089B76 ] Browser C:\Windows\System32\browser.dll
15:15:57.0763 0x1c08 Browser - ok
15:15:57.0766 0x1c08 [ 722036C26D2C4E50EC2A2EC5FD678846, 999468038AE01F0FF6881F4B2A2CB67BC636641188E95F10729E08ADBC3CB3DE ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
15:15:57.0773 0x1c08 BthAvrcpTg - ok
15:15:57.0775 0x1c08 [ C2E31BE025D46D189E38DD1EDF07837A, 656528DCAAAF485EC57EE5C3021E96736634DE3B9C39CBCD2728E055ABD4C0A5 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
15:15:57.0783 0x1c08 BthHFEnum - ok
15:15:57.0785 0x1c08 [ F7CD605FC0B0B22F3F6F247595E3A655, 1CD9140DE5415DDBEACD8667E63E5C95FD64D693B56302A0474E693E578BEAB0 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
15:15:57.0792 0x1c08 bthhfhid - ok
15:15:57.0798 0x1c08 [ B157D72BDA6A6DD6E9DC6BF338CD0CF8, B2AC26AE214151E5AD93DED78256BC0295DBF0133C854E7DEE4CD776D9C9A349 ] BthHFSrv C:\Windows\System32\BthHFSrv.dll
15:15:57.0810 0x1c08 BthHFSrv - ok
15:15:57.0813 0x1c08 [ 535DC41A33630AE4C262406F9E981C03, 599332589AA28D04189E19B87A4AE6FEEB60B40A7BC6E3B11240DA363A981C29 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
15:15:57.0821 0x1c08 BTHMODEM - ok
15:15:57.0825 0x1c08 [ 96932F631F5CB9F5D1C8F99A71568EF3, 5E4C8955A2EE9DC76B4EBC383653EB753D76D6B017E1A5DD553AC16094D7F12A ] bthserv C:\Windows\system32\bthserv.dll
15:15:57.0834 0x1c08 bthserv - ok
15:15:57.0836 0x1c08 [ 23F9EF739F685E07482116425E7879AA, 0EBDF96A49A319C0BCF6F51FB6C8C392C017E1738B950C19C91FF43E14D73143 ] buttonconverter C:\Windows\System32\drivers\buttonconverter.sys
15:15:57.0843 0x1c08 buttonconverter - ok
15:15:57.0846 0x1c08 [ 60EB6A4CE3E21887D302350631C16F26, 4270EFA22285C1A9336CF1220761E416950D2DA9C6A40D1D8452686CD5040DAB ] CapImg C:\Windows\System32\drivers\capimg.sys
15:15:57.0855 0x1c08 CapImg - ok
15:15:57.0858 0x1c08 [ F8FB51B9EF6372610E9B31A1D86B62FC, 7461584A8B39AC549AD7BAFFA509D4CD81EEE542808BC8EFC285863A0AE6432D ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
15:15:57.0866 0x1c08 cdfs - ok
15:15:57.0873 0x1c08 [ B737F6FB33A6F79BCBC293A5B32C1C4E, B2EAF621052A4CBEE78208ECF1AC9286BD1EB431019372254E442319308112F8 ] CDPSvc C:\Windows\System32\CDPSvc.dll
15:15:57.0887 0x1c08 CDPSvc - ok
15:15:57.0894 0x1c08 [ 2531EF3423A9FE1692005A41907E3BE3, 4E7D3E216937305B73CBCC5031F513CEC38F4FEFE3F2291DED5F37641221CCA0 ] CDPUserSvc C:\Windows\System32\CDPUserSvc.dll
15:15:57.0906 0x1c08 CDPUserSvc - ok
15:15:57.0912 0x1c08 [ 613D0137C269187FA298A157E3D14A18, 84BC268525F14BB27202CE242BF94D9E83BC91B50A0335908574F31B29A2F04D ] cdrom C:\Windows\System32\drivers\cdrom.sys
15:15:57.0921 0x1c08 cdrom - ok
15:15:57.0925 0x1c08 [ 9450FA11E9DE6715FCB71A519A8FF90B, B7E341C6E4CE967FCDD0D17A497C07E8A1C6B0AACE8A6E8E5D6C21EF73F13E16 ] CertPropSvc C:\Windows\System32\certprop.dll
15:15:57.0936 0x1c08 CertPropSvc - ok
15:15:57.0942 0x1c08 [ 0AED948DA8D5F08B3D6F12E4E2089736, 95E538E81DDBC83492C5F3820C82C78F050B4D74ACF12D7970EC84F93581AE29 ] cht4iscsi C:\Windows\system32\drivers\cht4sx64.sys
15:15:57.0952 0x1c08 cht4iscsi - ok
15:15:57.0978 0x1c08 [ 0002A0FDE087C1657AB31CE73077539C, 4DD6210B67E9633AB3240371590869DC833A4C986C74FC12A5D4FFFFD361848A ] cht4vbd C:\Windows\System32\drivers\cht4vx64.sys
15:15:58.0011 0x1c08 cht4vbd - ok
15:15:58.0015 0x1c08 [ 6B4F90A287D75CCD78694F6790C911B2, 73D7C31E9F475FA3FD568FCA9A953F968729AA114F63C06F38BF5198DAD67BD8 ] circlass C:\Windows\System32\drivers\circlass.sys
15:15:58.0022 0x1c08 circlass - ok
15:15:58.0028 0x1c08 [ 39591D8510CEC3BA6ED4330EE689B791, E827DEA20AB338308D6E4EEFEF551088088B77CD10BF08C8BE568090E04172E2 ] CLFS C:\Windows\system32\drivers\CLFS.sys
15:15:58.0038 0x1c08 CLFS - ok
15:15:58.0082 0x1c08 [ 2FFC3A679CF4FF05AA762E2B8D095574, 5CA2B9898E7493AF71B7D3A35FFB5D9F072DD0381AF89B0F47158895FBF58772 ] ClickToRunSvc C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
15:15:58.0125 0x1c08 ClickToRunSvc - ok
15:15:58.0138 0x1c08 [ E133CFCBFABB3CB517BE9F42FEA5887C, DA699CDD5F3CC427354540C907BD24CCA7BAC3112C53918EB611CB4EEC7611DA ] ClipSVC C:\Windows\System32\ClipSVC.dll
15:15:58.0153 0x1c08 ClipSVC - ok
15:15:58.0156 0x1c08 [ EEC3A4A98AE1A337E3CD1483AD6F2E15, 764DA329984A95E092F5C15116DA34FA7FC27216C0862365D4BF10ADC97EC5C5 ] clreg C:\Windows\System32\drivers\registry.sys
15:15:58.0163 0x1c08 clreg - ok
15:15:58.0168 0x1c08 [ 429623E266EF067A44E8CF148E9DFB9B, A48AA85ACC52C7AD73DB2D6148B3F9FB5EAC33C8F8C5BB6D7D0A9D84B7C08E11 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
15:15:58.0175 0x1c08 CmBatt - ok
15:15:58.0184 0x1c08 [ 3E502EB1701CF54CF237B6250FBE38EA, E63F6F45D3990ACBCA96003F67C83697BA5B74B89F972C5E9CC45F90D05519FF ] CNG C:\Windows\system32\Drivers\cng.sys
15:15:58.0198 0x1c08 CNG - ok
15:15:58.0200 0x1c08 [ 3DB10C59405931E2C72EFB82C1AF97D1, 100B5450A70988DB1C1F8A5FDBB3553AF1A0D47B42A5AC71460DB92E26010CE6 ] cnghwassist C:\Windows\system32\DRIVERS\cnghwassist.sys
15:15:58.0206 0x1c08 cnghwassist - ok
15:15:58.0213 0x1c08 [ 34C935AF2A414572B412B3556586D783, 912981B88B0796576ECCD5EBE0C4728EC02D5D6A96B039447DCBA59B2583F25E ] CompositeBus C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_a140581a8f8b58b7\CompositeBus.sys
15:15:58.0220 0x1c08 CompositeBus - ok
15:15:58.0222 0x1c08 COMSysApp - ok
15:15:58.0224 0x1c08 [ 44EEEB2382F566999287E13F2067693C, 53A4A0C85EAD38030FF2078C67465E3710ECD03A08FF34E1E67B2E3E1CC70043 ] condrv C:\Windows\system32\drivers\condrv.sys
15:15:58.0230 0x1c08 condrv - ok
15:15:58.0241 0x1c08 [ 03DCC01047713690E312B013C60881AE, B98174222DDFDA2A31BAC4795D99FA07D1D03107ABDB27BF5069FAFBBF00D278 ] CoreMessagingRegistrar C:\Windows\system32\coremessaging.dll
15:15:58.0257 0x1c08 CoreMessagingRegistrar - ok
15:15:58.0261 0x1c08 [ 5F06CAC4B09250CDDDD0180A08162924, A2EB0A57225E65FC264CFC9FAD858D8B54A015CDAE3DC904B1C4E9AAB40B1F06 ] CryptSvc C:\Windows\system32\cryptsvc.dll
15:15:58.0270 0x1c08 CryptSvc - ok
15:15:58.0278 0x1c08 [ 03214883D52FAD46573233852344C72C, 63DCCDD895EB804D205ABB8EA381B34FB0879D09E4D0EB0B28F9B2BB1024BAB7 ] CSC C:\Windows\system32\drivers\csc.sys
15:15:58.0294 0x1c08 CSC - ok
15:15:58.0305 0x1c08 [ BE35D1BAC3F18C9EB1C1CFBA31ED95E3, 4255475D173868A0E5583E844A1884E819E229838C4DEACAC47F1A4DEF388C9D ] CscService C:\Windows\System32\cscsvc.dll
15:15:58.0324 0x1c08 CscService - ok
15:15:58.0327 0x1c08 [ 039B5A8CBD5C75D1C46DF15F7C74D136, A5C8A41F2D406D37E147939F2058373ED091BFCC00CA7E829F887638CD3A2F64 ] dam C:\Windows\system32\drivers\dam.sys
15:15:58.0333 0x1c08 dam - ok
15:15:58.0337 0x1c08 [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdate C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
15:15:58.0342 0x1c08 dbupdate - ok
15:15:58.0345 0x1c08 [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdatem C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
15:15:58.0349 0x1c08 dbupdatem - ok
15:15:58.0351 0x1c08 dbx - ok
15:15:58.0354 0x1c08 [ 62C2617E1927776851B108717166BBA4, 5ED905AD21D2BA4308561BDFD2868A15A1F2062DFE1D28689D4082700C85500A ] DbxSvc C:\Windows\system32\DbxSvc.exe
15:15:58.0365 0x1c08 DbxSvc - ok
15:15:58.0393 0x1c08 [ 7BD259FC59CF9C2AE1B979564B374CC6, 299832FCE304A85080C80ABFE820A6093AC15A7C1E7C89D8C946708E955A2909 ] DcomLaunch C:\Windows\system32\rpcss.dll
15:15:58.0427 0x1c08 DcomLaunch - ok
15:15:58.0431 0x1c08 [ AE9F09F87755C18904656CB4F59F351D, B352A43B3B68B497D87B49C302AF3F37F36D56D49878AE3785C3D43597E5DC57 ] DcpSvc C:\Windows\system32\dcpsvc.dll
15:15:58.0445 0x1c08 DcpSvc - ok
15:15:58.0453 0x1c08 [ ABBD3EE724117242E28D31F19FBCFF03, 68EA91A969DD80A5DE28B0A8EAEB308837183713559C2C2FAEF991858C971393 ] defragsvc C:\Windows\System32\defragsvc.dll
15:15:58.0471 0x1c08 defragsvc - ok
15:15:58.0479 0x1c08 [ DD74F18227ACC837D9856E24282D446D, 6A760E44CD897952538CDFA8895FE11263D51AAA79CFF24C01F3862E919DA478 ] DeviceAssociationService C:\Windows\system32\das.dll
15:15:58.0493 0x1c08 DeviceAssociationService - ok
15:15:58.0496 0x1c08 [ FEA494AC3A1BAE63C1F2AF267D49F1DB, 0722FEA2481740B53EF26B1CA59166C63C157A5C708AC93DF3FBB74A27266C9C ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
15:15:58.0509 0x1c08 DeviceInstall - ok
15:15:58.0511 0x1c08 [ CDF1B1B5C5951111791C236B2696C7F8, BF6C4BA545C8827B40DB69890DB4D2B2F9C583C5E3CFBDFD370B05891141458D ] DevQueryBroker C:\Windows\system32\DevQueryBroker.dll
15:15:58.0519 0x1c08 DevQueryBroker - ok
15:15:58.0522 0x1c08 [ 0D1D392ED2597F295956D058D33BD7C3, 2F7FE5A06D880F9E2A46C9803DD249DC40C2898C04E946D14E7EECCCC9F2B24F ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
15:15:58.0531 0x1c08 Dfsc - ok
15:15:58.0537 0x1c08 [ F0D4400BA0F08610D9A551B15BF10B76, 83EB8FB272FC2DD2CC0659C2FB90AD0DAE88A88AB3951E03BCD933A25B601E10 ] Dhcp C:\Windows\system32\dhcpcore.dll
15:15:58.0550 0x1c08 Dhcp - ok
15:15:58.0554 0x1c08 [ CA7FEDDFCF61EF15A09C54DA2C07C49F, 346EF7709BA9E6BD48592B86FA46F9D956C847EF91F4980EEAD98269D0F0EF67 ] diagnosticshub.standardcollector.service C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
15:15:58.0562 0x1c08 diagnosticshub.standardcollector.service - ok
15:15:58.0587 0x1c08 [ CAD14E0AD1F03397E9B1C8733D76BEF4, 0035EF35F6520B1DF0E599C8A06D4163C52576BCE0976BF729B44DECDC506627 ] DiagTrack C:\Windows\system32\diagtrack.dll
15:15:58.0629 0x1c08 DiagTrack - ok
15:15:58.0633 0x1c08 [ 35B9D46560339A5A7F0CAC6ED702C817, F70480B01533B7029F90E2DE297E9E829660300DDE7A7D009B0AC2684E7691A7 ] disk C:\Windows\system32\drivers\disk.sys
15:15:58.0639 0x1c08 disk - ok
15:15:58.0646 0x1c08 [ 44A5CAF4E736BCD4360015BB3B841179, 8CD74620C3E163FF998CA8C09A999FED5C9EFDC88D07493192A57032D18CA973 ] DmEnrollmentSvc C:\Windows\system32\Windows.Internal.Management.dll
15:15:58.0661 0x1c08 DmEnrollmentSvc - ok
15:15:58.0664 0x1c08 [ 815F45161A4571C2C44491564F3D5968, 32E7AE8414A178CE429C0CDFCF718E3C11C705FB3155EA5CA0EAD48AAE507B01 ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
15:15:58.0671 0x1c08 dmvsc - ok
15:15:58.0673 0x1c08 [ 6E5EE6E420FECD64DE463C5F01CBFE71, F173C56895E80AA03D70CD78B3AB659C2EEAACFF43BE3B6EF3939D6F4AD4F62D ] dmwappushservice C:\Windows\system32\dmwappushsvc.dll
15:15:58.0684 0x1c08 dmwappushservice - ok
15:15:58.0689 0x1c08 [ 7F8A3ABF7750326E18CE953CCE262670, 5DBD159E8A455A42764FC73CF7DCAC849B5896848C5589B00BD36697804C0A3B ] Dnscache C:\Windows\System32\dnsrslvr.dll
15:15:58.0701 0x1c08 Dnscache - ok
15:15:58.0706 0x1c08 [ 8F46B4C3F9BA19C26A26D0A11137B20B, BA0A66DBA98D77FD85A7CD2D4593F2B2A1A3B4D32BBECBCFFBEB5A54DCB0D8ED ] dot3svc C:\Windows\System32\dot3svc.dll
15:15:58.0718 0x1c08 dot3svc - ok
15:15:58.0722 0x1c08 [ CA09EAEE92C6FDDC6B05057F11A0372D, 14DB5C186B69644AA93C445BF31CC9670204F95A47B77B6EACB19B4A316378AD ] DPS C:\Windows\system32\dps.dll
15:15:58.0732 0x1c08 DPS - ok
15:15:58.0734 0x1c08 [ AE6BD4C879A8C849E53947C92DF3B3A0, 8C29774CB2D30D901C54AAC0C8ACE709351EE40E5C8FB9951B2A18B4A03F28B7 ] drmkaud C:\Windows\system32\DRIVERS\drmkaud.sys
15:15:58.0739 0x1c08 drmkaud - ok
15:15:58.0744 0x1c08 [ 7433474BE77F065D2FA628671FE31A3E, 063ADDC68F48036749E6EC7B2F66284DB29F90F62E9468D16B4EF5A0FDC45E35 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
15:15:58.0758 0x1c08 DsmSvc - ok
15:15:58.0761 0x1c08 [ 5FCA45C24501DA7390065D3706A9FC3F, 093FD840F1502ECC6F05B9723CA523B3F15CF39A5D2B9106E1267739B3F2C52C ] DsSvc C:\Windows\System32\DsSvc.dll
15:15:58.0772 0x1c08 DsSvc - ok
15:15:58.0799 0x1c08 [ 125C83C44EEE61E2ED5893F23AEF0FC9, D6599AFFA1A554124AEF6862C69027F9FF9B343362091439866641A1CFB0E76A ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
15:15:58.0835 0x1c08 DXGKrnl - ok
15:15:58.0845 0x1c08 [ E063D7568233B6B007A6B18BE3751861, A0352D03B5B73EB219E57B9550D3D7CE41D07A70D8ED43E3AC2BBCE1E6684CE2 ] e1dexpress C:\Windows\system32\DRIVERS\e1d65x64.sys
15:15:58.0858 0x1c08 e1dexpress - ok
15:15:58.0867 0x1c08 [ 83E4A14F851341C933C3235BFB882ECA, 152EDEF6B566D010FE519FE4B046050A5281069B48AFF8A2395D7D2BD0519701 ] e1iexpress C:\Windows\System32\drivers\e1i63x64.sys
15:15:58.0882 0x1c08 e1iexpress - ok
15:15:58.0886 0x1c08 [ 9FCE4EF7D5E274F862D9A2526B5F4779, 81D42D5475C2801C8E0C233A0BA827569D8A70590017C91C665C8B232D9BFAA9 ] EapHost C:\Windows\System32\eapsvc.dll
15:15:58.0898 0x1c08 EapHost - ok
15:15:58.0939 0x1c08 [ 7EC6FC0266D74BD47ABB130A328B70EC, 3856790AF967AB03B1A89F97328DC4D5A6854ACDA6169681A9AFB03D7CF791F9 ] ebdrv C:\Windows\system32\drivers\evbda.sys
15:15:58.0990 0x1c08 ebdrv - ok
15:15:58.0993 0x1c08 ed2kidle - ok
15:15:58.0996 0x1c08 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] EFS C:\Windows\System32\lsass.exe
15:15:59.0003 0x1c08 EFS - ok
15:15:59.0006 0x1c08 [ 8D74B8B5D6F7C5BC4C525BAF2B083FF1, DA5656F745B3911F96871887FDFDC40F4D9C820622A0AA27EFE4BA93662833CA ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
15:15:59.0012 0x1c08 EhStorClass - ok
15:15:59.0015 0x1c08 [ 2A9817B5A9260D8F60D52E36BEF10443, AC1A0203221AFAF584C71317FA07AA1B6E61BE619E918B3B1E4AD57CCED1CF03 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
15:15:59.0022 0x1c08 EhStorTcgDrv - ok
15:15:59.0026 0x1c08 [ 80A7999DE02CE678B865832E1CE78CD6, 2576EBB6E4D630A906DE724F125099E52A962B5B68B9F9BCA849A7B29D8C8689 ] embeddedmode C:\Windows\System32\embeddedmodesvc.dll
15:15:59.0036 0x1c08 embeddedmode - ok
15:15:59.0042 0x1c08 [ B4264DEF962801CDB83C008DE30758D1, 57886688102BE727450BA45932044A5A389B5822A0C1C08C2AFFBA380F70C3F3 ] EntAppSvc C:\Windows\system32\EnterpriseAppMgmtSvc.dll
15:15:59.0057 0x1c08 EntAppSvc - ok
15:15:59.0059 0x1c08 [ 77B60DEC7DCB4233E4A69D3F52E5DB24, 3A5C905E37A93899051497C90E5BA8E1D003B56C6906CADFD2F1CDF52052D248 ] ErrDev C:\Windows\System32\drivers\errdev.sys
15:15:59.0065 0x1c08 ErrDev - ok
15:15:59.0074 0x1c08 [ F89083AB8B9F51C0031C1CBD0A9A7E35, 9EE973A25134960E62D1A6A1E34AD9B3F7690E71C1AD31A23FA2081A73438754 ] EventSystem C:\Windows\system32\es.dll
15:15:59.0089 0x1c08 EventSystem - ok
15:15:59.0095 0x1c08 [ FCD2C63754C2E739A8EEAD9BC63F9DDC, C57A72ABA4C0BD71F914B9C8FF965DCFF585A205498F19A4584A4BAF7674839D ] exfat C:\Windows\system32\drivers\exfat.sys
15:15:59.0108 0x1c08 exfat - ok
15:15:59.0114 0x1c08 [ C077AA74EDDAF69985EB27597BCB342A, 8CE48D37E39A6DFA3C8E959CA92A49029100446DC40044EE009D55FB9CDE378A ] fastfat C:\Windows\system32\drivers\fastfat.sys
15:15:59.0124 0x1c08 fastfat - ok
15:15:59.0135 0x1c08 [ 77CE56471AF984800F318F3734D768C7, 72D540072374A56C2C497F0532A50705D3F0637F2C0C96B1D715F2EDFCA3AA2D ] Fax C:\Windows\system32\fxssvc.exe
15:15:59.0153 0x1c08 Fax - ok
15:15:59.0156 0x1c08 [ 99598ECA5E41996E005D5B9D9FF1EFA2, 91345CD50EF02431B69093505C1C5F5DC6A1AA6BF192EE9392ED4D5626B60462 ] fdc C:\Windows\System32\drivers\fdc.sys
15:15:59.0163 0x1c08 fdc - ok
15:15:59.0165 0x1c08 [ EF0DD43A4CBAB367BCA1AFBDC9971E4F, 73E161C45D63FDDE71EE2438137913724DC513860539D1E7F6BD861F5D1B33F3 ] fdPHost C:\Windows\system32\fdPHost.dll
15:15:59.0174 0x1c08 fdPHost - ok
15:15:59.0176 0x1c08 [ 34DAC585994CD3B4E910DE11C584EF3D, A6C6A4CB5413EA61F1A54E2D3AD71A311CEA2C26218544D2D2D4A5CFEC52DE8C ] FDResPub C:\Windows\system32\fdrespub.dll
15:15:59.0185 0x1c08 FDResPub - ok
15:15:59.0190 0x1c08 [ CC3AFB5FC34E5533C6A3A261EA46B45D, 99BE380E09BA1C85BBB895B5D0855C592FAD7EDE0835F6F083704F88616D6363 ] Ferbayrepecult C:\Program Files (x86)\Themuckthegerch\Ferferrypekerkhlp.dll
15:15:59.0198 0x1c08 Ferbayrepecult - detected UnsignedFile.Multi.Generic ( 1 )
15:15:59.0339 0x1c08 Ferbayrepecult ( UnsignedFile.Multi.Generic ) - warning
15:15:59.0429 0x1c08 [ B68DA1FE3CA2311AFD38DD6905CA7F71, 4B395DFB1B47D2507CA4D9DC996A70D0A3BDB1A245CD6DA6C42B2A299AFCCF37 ] fhsvc C:\Windows\system32\fhsvc.dll
15:15:59.0471 0x1c08 fhsvc - ok
15:15:59.0477 0x1c08 [ F44F666B0EACC3181544FFCF8CA0FFC7, 83F771CF9DAE1C504B30731EEC55355EA1253174252DA2192ADF1D228B3735C3 ] FileCrypt C:\Windows\system32\drivers\filecrypt.sys
15:15:59.0493 0x1c08 FileCrypt - ok
15:15:59.0498 0x1c08 [ 78A210DDFDF2C9EC884631D2DAA573F0, 5D39C6EF4AC690A9749EEDBE2478FFF15A22877A2861EDA103C7BF1607B0C1BD ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
15:15:59.0507 0x1c08 FileInfo - ok
15:15:59.0510 0x1c08 [ 1A97DB5E701A186989F3795223C3BE39, F7982220D4DF7E104955E63CACE352394E2577DEF49506EA126127F820EB62DF ] Filetrace C:\Windows\system32\drivers\filetrace.sys
15:15:59.0522 0x1c08 Filetrace - ok
15:15:59.0524 0x1c08 [ 46626665F0E5906E45619B4EFD6186B8, 37FDD3B8AD49FD29E54DA5567EA77F28A53498AE56348F7A2628E5E5549D638B ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
15:15:59.0532 0x1c08 flpydisk - ok
15:15:59.0538 0x1c08 [ FDA72ACA14D516D18C33AFCD0FD9260F, 6509612DEC82EA74614B5C9A7B432305A1A468C97B88BED9E141DF2929B621B1 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
15:15:59.0549 0x1c08 FltMgr - ok
15:15:59.0598 0x1c08 [ 49BF5C8182C3D2D6CD9F7EEDF1CFDB66, 0977EBE86B57FC370D27CA69D58122397D5D5369AF0C8DBCC492AE7AD55CBA2B ] FontCache C:\Windows\system32\FntCache.dll
15:15:59.0638 0x1c08 FontCache - ok
15:15:59.0641 0x1c08 [ 59241194DBDF30A2B4029E402F377900, 47A92E9CD8494C403B377799D395670A393766647E24CD83B15338CE2AA50266 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
15:15:59.0646 0x1c08 FontCache3.0.0.0 - ok
15:15:59.0658 0x1c08 [ 8B52024D3A5C3A12F1C4D75D30A976C5, 982F1C783966C9A6D255AA7DBAB6D225EBE0050A36176B8DE85E8ADBFE17FDF1 ] FrameServer C:\Windows\system32\FrameServer.dll
15:15:59.0680 0x1c08 FrameServer - ok
15:15:59.0683 0x1c08 [ D152CCBFC8251670BF0AAFE00D6BC782, 9DE82D8FC4E1DAF8FF23EE08C0B7CB5051A9224E64544D262CFA4996A41B04E1 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
15:15:59.0689 0x1c08 FsDepends - ok
15:15:59.0691 0x1c08 [ 6D6BB5C7363CD35FA715E826F3D029EE, C214F791EB39E8B25CE57ED9D6C1D56EE1AF6021BCB380980BD42A6338A6C9F7 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
15:15:59.0696 0x1c08 Fs_Rec - ok
15:15:59.0706 0x1c08 [ 8EEC4925C03E375C4EC496E45C44139A, 06C5C7BCC28D3E435675F0759A09CAB726E971DF4BFC1DC3DCF503EABCDCCCC6 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
15:15:59.0720 0x1c08 fvevol - ok
15:15:59.0722 0x1c08 [ EF78034773CE506323655A868C949144, DF195BEEE6704FBCC6D2D9E1BF6723E52ED502A1459F495B7D18481E6A79B5BC ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
15:15:59.0729 0x1c08 gencounter - ok
15:15:59.0731 0x1c08 [ B55FEBC6A00DAA1FE074F020B6907516, 67071FBAC2ABA47AB71358A5F08E92E034A55343878F00137E90B3B1F7362976 ] genericusbfn C:\Windows\System32\drivers\genericusbfn.sys
15:15:59.0738 0x1c08 genericusbfn - ok
15:15:59.0742 0x1c08 [ DDD8A8CDDC7F13EF57D1DAAE71865936, 9D472A8689F72F24D40D5B94849690F53C67849FDF6162A94EF4FB330A3DA566 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
15:15:59.0749 0x1c08 GPIOClx0101 - ok
15:15:59.0766 0x1c08 [ 713A176494CEC107E663CAD6C2B27F77, 76871D8CFBA8FCD8CFF96208AE84C658EBEC60270D978898B90EE9451AA1BCE1 ] gpsvc C:\Windows\System32\gpsvc.dll
15:15:59.0795 0x1c08 gpsvc - ok
15:15:59.0797 0x1c08 [ 7ACD8F69B5D6EC97E6D2C006E19BED88, FC69214C9308EA64B88EF4C3C95800586DDBB44C8540846B79A161BAD8203B6E ] GpuEnergyDrv C:\Windows\system32\drivers\gpuenergydrv.sys
15:15:59.0804 0x1c08 GpuEnergyDrv - ok
15:15:59.0807 0x1c08 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:15:59.0812 0x1c08 gupdate - ok
15:15:59.0815 0x1c08 [ A8FD9222E4D72596BB37DA8BE95C0BA4, 52FC3AA9F704300041E486E57FE863218E4CDF4C8EEE05CA6B99A296EFEE5737 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
15:15:59.0820 0x1c08 gupdatem - ok
15:15:59.0827 0x1c08 [ 217230B984AB2954E2FA5E36578D7B08, BB7B79EA7501A28EB2A0303FDF66FB9D59D567994C25A1523CD6D2081C403AF6 ] HdAudAddService C:\Windows\system32\DRIVERS\HdAudio.sys
15:15:59.0841 0x1c08 HdAudAddService - ok
15:15:59.0844 0x1c08 [ 10E3515FE5DBA6656FA62C29342EC4A1, 2051F10F74ED712B1766EB61E87FADE25AB3D0970BABFD320600D1B0D6377F26 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
15:15:59.0851 0x1c08 HDAudBus - ok
15:15:59.0853 0x1c08 [ B90D284B97CD4CA9DE7430AAAD887A56, 2F14F985C39B7801ED64590979CF2114924E9547F5B11D2B37A74DBFFDD9E7C5 ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
15:15:59.0859 0x1c08 HidBatt - ok
15:15:59.0862 0x1c08 [ B2FE11643CC6ACDEE6C247DD36018FDB, 5796613C7DBF8B2A9E860E006FF1A245B6BE7D10E3F6685AD142B48E5C237B8C ] HidBth C:\Windows\System32\drivers\hidbth.sys
15:15:59.0870 0x1c08 HidBth - ok
15:15:59.0872 0x1c08 [ D24355488A2D4D2323518EC1AC7A6D9E, ED2176A2093726087EDDA25B86E9CDD4BA35F4E748E3A6DE0B15C4C97646B5C7 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
15:15:59.0879 0x1c08 hidi2c - ok
15:15:59.0882 0x1c08 [ 0AF9ABBA4F3F55C6C803890D64BC3C29, D3DE6FA308F8E7CD4F16387F46AE4B2F7EC9BBA07BF87652B660A0D645710571 ] hidinterrupt C:\Windows\System32\drivers\hidinterrupt.sys
15:15:59.0887 0x1c08 hidinterrupt - ok
15:15:59.0890 0x1c08 [ CDBCF8E9AB06D88A1E1191D32F320C5D, F76963AB7CF2BAB3A220013879AECD3976BFD851CFB66B5A69A9EA2541048861 ] HidIr C:\Windows\System32\drivers\hidir.sys
15:15:59.0897 0x1c08 HidIr - ok
15:15:59.0899 0x1c08 [ C900FE0DD6A1E2220084B8F1C427790C, 802194EBEDA1A50EDA300078B0888AAC1F17A42E67147B7B3B9C50AD8D4E5C89 ] hidserv C:\Windows\system32\hidserv.dll
15:15:59.0907 0x1c08 hidserv - ok
15:15:59.0909 0x1c08 [ D8536CB438CC4CCDAE047B768EED22B2, 4F666BFA3554F9ACA6B9D436BFA64474D5F30FB3E78F4E66068CCDF283D9867F ] HidUsb C:\Windows\System32\drivers\hidusb.sys
15:15:59.0916 0x1c08 HidUsb - ok
15:15:59.0922 0x1c08 [ 0AC1BD5A28FAA371EF34859FE703E515, 1DD1C33AF8D6EBE7C36FCD051F066E4039D2B47ABAECF7C68BC3933D567930B2 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
15:15:59.0934 0x1c08 HomeGroupListener - ok
15:15:59.0942 0x1c08 [ 86161A89F16851728802590EC7C92608, 3A3B05BB4E115410D27063B30C0EF3F18295F542050F329F1E466C81A9E23A46 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
15:15:59.0959 0x1c08 HomeGroupProvider - ok
15:15:59.0961 0x1c08 [ F5CA18197B4646E04DB9EB2D6642CC4D, 5BA3342DDF1BCB67E4156169FE9A33E7BC2641C729E9F1A80C0E80953C6AB114 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
15:15:59.0967 0x1c08 HpSAMD - ok
15:15:59.0982 0x1c08 [ A10C7C1E69FC90620C7BF2E51302A01F, D725AEAE38255CED73F4922A10F226215528706580B06D01C228488F93AC0397 ] HTTP C:\Windows\system32\drivers\HTTP.sys
15:16:00.0002 0x1c08 HTTP - ok
15:16:00.0006 0x1c08 [ 0C84C250F80EAEC2C9768464CC1A9626, 212E1003B78F9B98FEB084FD1FDB59B26A9DE4C9120F24D4361FBBF0F3C035E7 ] HvHost C:\Windows\System32\hvhostsvc.dll
15:16:00.0014 0x1c08 HvHost - ok
15:16:00.0017 0x1c08 [ 74FC79C52395B10FFD0B55CF22CF88FC, 94D977DA2092EE8C2A598AC48758A84BB22CB6378BD114C2D3B4172A07A9CACC ] hvservice C:\Windows\system32\drivers\hvservice.sys
15:16:00.0023 0x1c08 hvservice - ok
15:16:00.0025 0x1c08 [ 771EDDA9830A3079F996F34D681FB6E5, F452AD656872A1C8B2D6DCE232CE01EBD456C46F4934A7601E78470F2A2CBF38 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
15:16:00.0030 0x1c08 hwpolicy - ok
15:16:00.0032 0x1c08 [ 3B9F315E7FA72CC25228EB097DD9C694, B26F1E494428EF197A0C97645C05BB3CA093827A005D35C987F1D6778BC4E52C ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
15:16:00.0038 0x1c08 hyperkbd - ok
15:16:00.0042 0x1c08 [ B54B30992620C97230013A74461C8517, CAF09BDCDD6DE2A39CB8AE2C65E6F8FE12D8E93D84BBEF6C6A98F872BF54A4E3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
15:16:00.0050 0x1c08 i8042prt - ok
15:16:00.0052 0x1c08 [ C6B8743B213F06AA60943D8366FE968F, 758954F70B810063914B243115B2C753B2BCE40190F95C30ACBA0BF04EBD5B33 ] iagpio C:\Windows\System32\drivers\iagpio.sys
15:16:00.0059 0x1c08 iagpio - ok
15:16:00.0062 0x1c08 [ 9A2A2F3C69B9A30B6E78536F6D258BAD, 5E28E132A7300E6F5E0C6439D6BA00F1AEF66D729FF671FDA91274A25A921463 ] iai2c C:\Windows\System32\drivers\iai2c.sys
15:16:00.0070 0x1c08 iai2c - ok
15:16:00.0072 0x1c08 [ 5A0E850F8CD17791A3E6A3CF81D0CA28, 10A965A49D53360DD250E0758B6BB142872298A21C732EB026ACB93492C5C6CF ] iaLPSS2i_GPIO2 C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys
15:16:00.0080 0x1c08 iaLPSS2i_GPIO2 - ok
15:16:00.0084 0x1c08 [ 7508F1096803385D6376BFD0BD473AC4, 1F32EC23CDC94DCB9710E6663B5C3BD83568545DDC2C741CFC13550A4E4DD2BE ] iaLPSS2i_I2C C:\Windows\System32\drivers\iaLPSS2i_I2C.sys
15:16:00.0089 0x1c08 iaLPSS2i_I2C - ok
15:16:00.0092 0x1c08 [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO C:\Windows\System32\drivers\iaLPSSi_GPIO.sys
15:16:00.0096 0x1c08 iaLPSSi_GPIO - ok
15:16:00.0099 0x1c08 [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C C:\Windows\System32\drivers\iaLPSSi_I2C.sys
15:16:00.0107 0x1c08 iaLPSSi_I2C - ok
15:16:00.0118 0x1c08 [ 97E553D03219D3D51705C7235D9EAEBD, 5D4578C8804AF32D1DC0868E34D6538138DC15F9568CA7E21051B1C82C0D8D55 ] iaStorAV C:\Windows\system32\drivers\iaStorAV.sys
15:16:00.0132 0x1c08 iaStorAV - ok
15:16:00.0139 0x1c08 [ 8350FE3BCDE3428BC040877BB7E9EAEB, 77F9456351CA640C6B7862907C0580627E761EC807B551976A95657EB4D6CC20 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
15:16:00.0150 0x1c08 iaStorV - ok
15:16:00.0158 0x1c08 [ 3BA03F7C7700DDF4C383DDE9252F5817, 3E90F69D0010E7764349D9AE865D577E431FEBC67DA554B400BC808DD286E203 ] ibbus C:\Windows\System32\drivers\ibbus.sys
15:16:00.0170 0x1c08 ibbus - ok
15:16:00.0174 0x1c08 [ E54BFAB1679CCFBE2C28AD18BE9D0E5F, DAFFCFEBDADEE43FE657FFFFCFADA2F7AE62FCB29915540F620FDC0041A99CD1 ] ICCS C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
15:16:00.0181 0x1c08 ICCS - ok
15:16:00.0183 0x1c08 [ 3B529CA6E6537E89547B4815FCE95A76, 5FCC3D3EFFA50EEEFA38B6137580AFEDC7C3D56BA1BB44658D9CD6AA60A1B4FF ] ICCWDT C:\Windows\System32\drivers\ICCWDT.sys
15:16:00.0187 0x1c08 ICCWDT - ok
15:16:00.0192 0x1c08 [ 937AC47F7356554DA05D9722C356EB55, 9EABC9F19B4E1193B669D2674967F5C6F03FAD348EDF0615E3F78554FF9A83CC ] icssvc C:\Windows\System32\tetheringservice.dll
15:16:00.0203 0x1c08 icssvc - ok
15:16:00.0217 0x1c08 [ F2934208C0E50C0B971A7981AB90BED2, B936BFBBD71E731CC2CDB8B47D262F2EF09726FF921C2DA0841910CA2401423D ] IKEEXT C:\Windows\System32\ikeext.dll
15:16:00.0240 0x1c08 IKEEXT - ok
15:16:00.0243 0x1c08 [ 2A01C96DF5802D3434634E55C91232D8, A3ABEF36E2FD2CF5C371ADBF92566A09669A1D990ABE4677370F57F2EEAF8121 ] IndirectKmd C:\Windows\System32\drivers\IndirectKmd.sys
15:16:00.0250 0x1c08 IndirectKmd - ok
15:16:00.0311 0x1c08 [ 08A2E765F066DA6957D8CA66C6CBFD1B, 9B3DCAF78BF53B60FB8F92B2E5C994FBC4006082FE114A26009F7CEB10735EE2 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
15:16:00.0374 0x1c08 IntcAzAudAddService - ok
15:16:00.0378 0x1c08 [ 9F7E87F6595D065A8A200A291043045E, 6944F72F73EADC6C9B7691F2C1C6DF1898F22C88EFA78EC0BA8CB5FFD9CE057B ] intelide C:\Windows\system32\drivers\intelide.sys
15:16:00.0384 0x1c08 intelide - ok
15:16:00.0386 0x1c08 [ A6BD2E20AE1BC5CB2776C87C28E4F4CA, BD8BE67CED9A4982D785CE9ECBEFE868C3A2E37DF7F9592B9F9049B807A1554B ] intelpep C:\Windows\system32\drivers\intelpep.sys
15:16:00.0392 0x1c08 intelpep - ok
15:16:00.0395 0x1c08 [ 2A48DA39542636DB0FA3BA915385D1B3, 6CA0916F5F4B1E81AE6A6233276320599BFA7C129267177703E3BB6468FB4683 ] intelppm C:\Windows\System32\drivers\intelppm.sys
15:16:00.0404 0x1c08 intelppm - ok
15:16:00.0406 0x1c08 [ DB32758F3A7F6CCE81A5430080A2EA65, 36A26BAA884E96804F8EA0B12BB3E81BBE6D4EE704809904091445F36CAB5A29 ] iorate C:\Windows\system32\drivers\iorate.sys
15:16:00.0412 0x1c08 iorate - ok
15:16:00.0414 0x1c08 [ FE85D0A86CA7A5A99CF8CD04DE7F80AE, 544C01FC01EE728EB5667158207E5F4418FE77A88BA318192A834722DB766F4E ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
15:16:00.0422 0x1c08 IpFilterDriver - ok
15:16:00.0436 0x1c08 [ EF1BB0EF8A12C32DD88C409706B8145E, 7AEDE717C258C29592CC8AEC40F61617E5382646E5141E1C0941882ACE5C5758 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
15:16:00.0460 0x1c08 iphlpsvc - ok
15:16:00.0463 0x1c08 [ 450DBDD716C7911F83E05F78EE18BFA2, 43C0DA172F632131898F315A53DEDD1AE99FB0620AB32B3A5B99FEC498C9AAE5 ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
15:16:00.0470 0x1c08 IPMIDRV - ok
15:16:00.0474 0x1c08 [ F1DAECC3B3D6399875D4F10529D6A77C, 6533D2F858816BE6570C998510919FCA2904EC6EF806F61C1FD325E88133111B ] IPNAT C:\Windows\system32\drivers\ipnat.sys
15:16:00.0484 0x1c08 IPNAT - ok
15:16:00.0494 0x1c08 [ 16A6D49E7698FC6F1730D3FF9F5561A8, 860D2601BA3A71C81A6B21F4D92A5E9C47772C9DE0F047D49000FA4A484D7932 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
15:16:00.0505 0x1c08 iPod Service - ok
15:16:00.0508 0x1c08 [ 7475A2903BB704B446AA6309E34D3362, C94643A1626A9716015EBA7041A1224098501EB7DAA704CBFCAD3DC6F3CFC6AF ] irda C:\Windows\system32\drivers\irda.sys
15:16:00.0517 0x1c08 irda - ok
15:16:00.0519 0x1c08 [ 9725E7F0C64CE9916A5CDABE8D6E13C3, 04AF9E48FEF208A2850DF28352E8FDCBF4018982C72C0F67EE12C048C4070116 ] IRENUM C:\Windows\system32\drivers\irenum.sys
15:16:00.0526 0x1c08 IRENUM - ok
15:16:00.0528 0x1c08 [ 8C604213A2E73088BFFE6CD2E6F1AE53, B4C4FEE4D398A29F72EC27D5668071D7E68CD943FFFC38624DD5DF5BEBDF46D3 ] irmon C:\Windows\System32\irmon.dll
15:16:00.0536 0x1c08 irmon - ok
15:16:00.0538 0x1c08 [ 58040898883A96160D41739C80328BBF, 7F85C91C905811416E266A263DDEFCDCB0B45376AAE51B551AB636C16577DB9F ] isapnp C:\Windows\system32\drivers\isapnp.sys
15:16:00.0544 0x1c08 isapnp - ok
15:16:00.0549 0x1c08 [ C9FD02D62E09337B67B0C61EC8CA38CC, DC77E935ECC8474BE9018F0937CB11C137073582B20A0EE107CE247FD9E1F9C1 ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
15:16:00.0558 0x1c08 iScsiPrt - ok
15:16:00.0561 0x1c08 [ 210808437570BDDEE71A43535E3A2D30, EF5DE6EE4FF58F44CDE4D4E7F298ABBC9086EC05CC3AE4903060DA878115AC1E ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
15:16:00.0566 0x1c08 kbdclass - ok
15:16:00.0569 0x1c08 [ 0B779E9FC426CA2268D28181FA6C222F, 83292023A688C3044D096F22242EB954B7F7511BE8341D45FF0AFBD9CB9BCB4E ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
15:16:00.0576 0x1c08 kbdhid - ok
15:16:00.0578 0x1c08 [ 813BA3EB2CE038F2A5382DDD75CAD60B, 99FA444027CAC247B54317730D54AB0C4C000AE076B97E47470FDA9834594312 ] kdnic C:\Windows\System32\drivers\kdnic.sys
15:16:00.0585 0x1c08 kdnic - ok
15:16:00.0588 0x1c08 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] KeyIso C:\Windows\system32\lsass.exe
15:16:00.0594 0x1c08 KeyIso - ok
15:16:00.0598 0x1c08 [ 705C0F8BCCEF6E7CB704CCB454192D7E, FC608C708E2C3BF7A66E57B95E19E71E5F5C87EF359D8BC1A817500B45DF9338 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
15:16:00.0605 0x1c08 KSecDD - ok
15:16:00.0608 0x1c08 [ 55AD13E2BAFC5AB53A10F8C271F5D242, 058BEF14DCB95574BCAB985F04737BA89483937E8D8A74F7B4CEAFB7400C2397 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
15:16:00.0616 0x1c08 KSecPkg - ok
15:16:00.0618 0x1c08 [ 4ED115CD1A1099705F56B5E0FFF97CC6, 9CC49DF2CD6AAAE405BA661D13EFC1E05111D1DE3D1E50C39C425AF1F075610B ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
15:16:00.0628 0x1c08 ksthunk - ok
15:16:00.0634 0x1c08 [ 8125BDF7ADC261F75EF0CAD92456E350, 184797AA1D58C4FF743BA60D48590B88B781EE7779205E45E0679DEC79F3E185 ] KtmRm C:\Windows\system32\msdtckrm.dll
15:16:00.0649 0x1c08 KtmRm - ok
15:16:00.0654 0x1c08 [ 8CCAB08815B50AD78B823DB3F96C8604, 265E6D582EB7207B5CC577D61CB7BC3646F613047F168CD69BB776C37780EBF5 ] LanmanServer C:\Windows\system32\srvsvc.dll
15:16:00.0668 0x1c08 LanmanServer - ok
15:16:00.0674 0x1c08 [ B581907FD94F1FF148BF695331F67612, 05D1FFA456557A291566D788B8DE2485552E361EC3C0F63EA1A710BE940A5398 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
15:16:00.0687 0x1c08 LanmanWorkstation - ok
15:16:00.0690 0x1c08 [ F8EBAA1FE6D3BF84752931DE1BFA0E2A, 2F3C512712BA709BBBBD779D9E792DBE324876C402CDCEF0345B8B7ABE1D232A ] lfsvc C:\Windows\System32\lfsvc.dll
15:16:00.0699 0x1c08 lfsvc - ok
15:16:00.0701 0x1c08 [ 5A23E4BE0CCF49663C4CF7EB74C20278, 9DF91014B13B7CED1C3D409F90858FD03EFC5C4347C98901B4DF0AFF2B77845D ] LicenseManager C:\Windows\system32\LicenseManagerSvc.dll
15:16:00.0709 0x1c08 LicenseManager - ok
15:16:00.0712 0x1c08 [ 5933A6673F00D8255C52957E40C2D601, 0AA1281F8B3F97E360592D1B35EE7D3D614F1AB46007F9884CFFB1C5E647575E ] lltdio C:\Windows\system32\drivers\lltdio.sys
15:16:00.0719 0x1c08 lltdio - ok
15:16:00.0724 0x1c08 [ 88A3C935725FA6EA1A228DCC26CF9C6F, 9B1F70644EEFA1EE7CE151A8A970430087339B7A6345F2E0252370929D4AFAC6 ] lltdsvc C:\Windows\System32\lltdsvc.dll
15:16:00.0736 0x1c08 lltdsvc - ok
15:16:00.0739 0x1c08 [ 3F858E28AEE6545FA1B64134DFD5C2CE, FFD7B4FB0A7B61BC6B76A172134673842F2CF00E96FA3ED4A8273DC525B6BB92 ] lmhosts C:\Windows\System32\lmhsvc.dll
15:16:00.0747 0x1c08 lmhosts - ok
15:16:00.0751 0x1c08 [ 8E1B0946948CCC0BC1FA3CB70374A795, 0B894C129A35E223FF9594725AC90916CBD597FAD2211A18FC2AE03EA8679597 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
15:16:00.0758 0x1c08 LSI_SAS - ok
15:16:00.0761 0x1c08 [ 4F68163FC04C973500DC4DA0946917B0, DF060C29109EB3978CEDFE781999B0C4C1E8C0FDB133428058D8400C53315EEC ] LSI_SAS2i C:\Windows\system32\drivers\lsi_sas2i.sys
15:16:00.0767 0x1c08 LSI_SAS2i - ok
15:16:00.0771 0x1c08 [ E5AC5F2815938651CDCC27F425474673, 3AF0598982153C36A766506FA088F7B84333CC96FEBB050402547AFC613AF9F7 ] LSI_SAS3i C:\Windows\system32\drivers\lsi_sas3i.sys
15:16:00.0777 0x1c08 LSI_SAS3i - ok
15:16:00.0780 0x1c08 [ CCF6EC9FB9B8F18E05B4253E81013E48, EBE8D77FEE8B99BD8C29702404774D554673C96DF3FDF3DCEA9C99E22C2709FC ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
15:16:00.0786 0x1c08 LSI_SSS - ok
15:16:00.0796 0x1c08 [ 06276381A0797FD417E7068C1210FA06, 204144E9792216F952CED869ECB6B26FB466BF730B8A73FA4799B1EBC1A630AB ] LSM C:\Windows\System32\lsm.dll
15:16:00.0815 0x1c08 LSM - ok
15:16:00.0819 0x1c08 [ C9579D32219E5B936AC3A48D470117EC, E61A77191B6BA25D29B1221FEBBE826BBC11F825C0E35A72B4CEFFF8B7FE59A8 ] luafv C:\Windows\system32\drivers\luafv.sys
15:16:00.0829 0x1c08 luafv - ok
15:16:00.0832 0x1c08 [ ED5B42D75F3DEE93040B3930DA9F3009, E919DA20E46FE1C81CB76090B799DD858DD4771DB0EBDE4545DB4681A0AFFE8E ] MapsBroker C:\Windows\System32\moshost.dll
15:16:00.0841 0x1c08 MapsBroker - ok
15:16:00.0848 0x1c08 [ 489AD4F59217EBA859EB7129874DC8E3, 7E36CA117F09771018E2BBF657CE15E6C1AB6ACDC531732D313F40B36D9C7CD9 ] MCSvc C:\ProgramData\Microsoft\Blend\14.0\1033\ResourceCacher.dll
15:16:00.0856 0x1c08 MCSvc - detected UnsignedFile.Multi.Generic ( 1 )
15:16:00.0927 0x1c08 MCSvc ( UnsignedFile.Multi.Generic ) - warning
15:16:01.0014 0x1c08 [ C3CDCCF07486BD2616A7B82946E07AC0, 1EF95DAB2DA856BC7D7573B2EB2D9006DF337F827F0B56A161D0C97F45DB755E ] megasas C:\Windows\system32\drivers\megasas.sys
15:16:01.0037 0x1c08 megasas - ok
15:16:01.0043 0x1c08 [ 2CF0CB2A0ED68C5455371E84C16F9627, 1C9166B52140145F1968E83E52BFF041250811B23C770FE181A18A4BA060CA81 ] megasas2i C:\Windows\system32\drivers\MegaSas2i.sys
15:16:01.0058 0x1c08 megasas2i - ok
15:16:01.0069 0x1c08 [ FADB2FE017E69EECE0E1BA78661C2E8C, BE99B49031D8B4B670B6F6B6E829E54406779CF6F1D8AFE8AB79A73E6764AB2F ] megasr C:\Windows\system32\drivers\megasr.sys
15:16:01.0085 0x1c08 megasr - ok
15:16:01.0090 0x1c08 [ 8EC6459491D8508BBA5E3CEC5C930914, E01AEE2E6F569429BC5582AEB63A2CB288499A878B0806D21CC9D78F00E0B284 ] MEIx64 C:\Windows\System32\drivers\TeeDriverW8x64.sys
15:16:01.0099 0x1c08 MEIx64 - ok
15:16:01.0102 0x1c08 [ 55A417C3E41F2A98666CF929EC19108E, A38C262B2863C87E4151525BF26D6AC16E7982D370E2C6998EB15C88C4BC8254 ] MessagingService C:\Windows\System32\MessagingService.dll
15:16:01.0110 0x1c08 MessagingService - ok
15:16:01.0124 0x1c08 [ FD60818B66B2E8A5415EA840E99A9D8F, 5D2F22909354534B821D958FBEF6A40EB4F642F53C7B509D00949096EF716F36 ] mlx4_bus C:\Windows\System32\drivers\mlx4_bus.sys
15:16:01.0141 0x1c08 mlx4_bus - ok
15:16:01.0144 0x1c08 [ 68F6977F1CFBAAC770D940A8C0326FA1, 90EE1E7DAC680EAA5AD50E9B0B9FD8FCE8DD6A02D5EF941B5AA5084CBD40BB80 ] MMCSS C:\Windows\system32\drivers\mmcss.sys
15:16:01.0151 0x1c08 MMCSS - ok
15:16:01.0153 0x1c08 [ D842ADDB5911945D51F61A0B1C8F36E3, 5EB93A1FD2D2D9FAB6121356E1AB18F2ADE9550D3033274AF7CA8F7FD51E59ED ] Modem C:\Windows\system32\drivers\modem.sys
15:16:01.0161 0x1c08 Modem - ok
15:16:01.0163 0x1c08 [ 9CCCB7FC3EDADEBA461D78615A6011A6, C120B58F25E8CCFD971EB78645C0682F367AD56DC15F2D8C1980CE75B04719DF ] monitor C:\Windows\System32\drivers\monitor.sys
15:16:01.0170 0x1c08 monitor - ok
15:16:01.0172 0x1c08 [ 27A07B2FB2E3057DA8DAEA4F25D843C7, 09D2B39E6B9AAEC879E5871DD6BCFF2AEF0B894F3B44649665A685F8B3CA6F27 ] mouclass C:\Windows\System32\drivers\mouclass.sys
15:16:01.0178 0x1c08 mouclass - ok
15:16:01.0180 0x1c08 [ 7BD6E7F7C9001AB21B8362CFFEE80B25, C470C3363EEF3A60409A5934988BFB9B72AE7C2BB63CC2C2D006D7EB1C797F6A ] mouhid C:\Windows\System32\drivers\mouhid.sys
15:16:01.0187 0x1c08 mouhid - ok
15:16:01.0190 0x1c08 [ F5BDAEE4B7D369D4C74668DCFBA3FF10, 100F39288E56AFE0D39D1CC235BDC9F3727C873CD3114E092DA7A08810BD3EB2 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
15:16:01.0196 0x1c08 mountmgr - ok
15:16:01.0199 0x1c08 [ 30844BD376F9D01E62C820BEF446F1F8, 910D672EDB544A20AEB4450B4D89830F46EDD28CE0021156176315C5D068A1B4 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
15:16:01.0207 0x1c08 mpsdrv - ok
15:16:01.0220 0x1c08 [ 779CFDB17EA07A6D26FEBBAC95B65772, 74D9542E8DCCD07396A45A45D2F500AA6F9DCC1DB785A6153EB3067E42F576A4 ] MpsSvc C:\Windows\system32\mpssvc.dll
15:16:01.0243 0x1c08 MpsSvc - ok
15:16:01.0247 0x1c08 [ 25D32BE04FE0A23FDF57FD5382757672, 64E39E3E21D9173FB1116B989D80C244C49DA827698A05AF5CC5CD1C6AE155DE ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
15:16:01.0256 0x1c08 MRxDAV - ok
15:16:01.0264 0x1c08 [ E671EDAB0726E05ECEF4058B4CD73C4D, 9F4C50E635CE2204E3291C8D3D7F658A969E80722B8B6F0304228D9B434C20EA ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
15:16:01.0275 0x1c08 mrxsmb - ok
15:16:01.0280 0x1c08 [ 200E4A385F5F370D8866BAE25B0D9D32, 114AD45000A0C74EAE26C3075BBFEF80B9386C69D58CE4436CAFCF13613EAEFA ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
15:16:01.0292 0x1c08 mrxsmb10 - ok
15:16:01.0296 0x1c08 [ F7C22604CD8AFB9AF1C1E3CE39A5A09F, 3F7B39336F8A72525C667D45C9300CA6D017BDE17A6E23EF794BA59D2F3C78F3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
15:16:01.0304 0x1c08 mrxsmb20 - ok
15:16:01.0308 0x1c08 [ 74C9D21523DAE0C18F413C196DF0058A, 3DB4B8CA368D9DD82FAE2C2BC828A21142C8D29780A7C8667188C447519FF702 ] MsBridge C:\Windows\system32\drivers\bridge.sys
15:16:01.0316 0x1c08 MsBridge - ok
15:16:01.0320 0x1c08 [ 308F08347923DEEDE7BC03EC7D485841, 72DB45CA11FE635DF9F8273C38CBEFB8DF5362ADA0CBF6D2B1E570365DC700C0 ] MSDTC C:\Windows\System32\msdtc.exe
15:16:01.0330 0x1c08 MSDTC - ok
15:16:01.0333 0x1c08 [ F01B849D9D4A8CEAF32D4FDBD0B83C92, D2473AC4C6E6C03DEF13EA73EC78FB878BDC95C047651BF79A16C9DEA82AD046 ] Msfs C:\Windows\system32\drivers\Msfs.sys
15:16:01.0341 0x1c08 Msfs - ok
15:16:01.0343 0x1c08 [ 22ECD8F5D1DFADF2011BBB1700CB871D, 8F9EFF51137394EFA5471B8A29C541710063B65806B075B4925A84D5B6BC3BBB ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
15:16:01.0349 0x1c08 msgpiowin32 - ok
15:16:01.0351 0x1c08 [ FD870F6968A145E4D2BA8A8842686B03, 34B8F601F3B5E42B4D0A41E2AF7DB4EB4E5B627DA8DA9A2A2D46B153AF23AEB1 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
15:16:01.0357 0x1c08 mshidkmdf - ok
15:16:01.0359 0x1c08 [ 30364757963A028CE5DF0FBAAC270173, C72588A6A52FF8E418A15D2C407A4DB7EA768585423720145F8253D5CA519DC2 ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
15:16:01.0366 0x1c08 mshidumdf - ok
15:16:01.0368 0x1c08 [ 6BB0FEDDAE7135FA37FFAFF4D9E0E876, B41A3C0FFDFC493D6325ED493445AFCED04EC9DFF2B38125616FC5419AD1ACC4 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
15:16:01.0373 0x1c08 msisadrv - ok
15:16:01.0377 0x1c08 [ 07E3E54734B14F43A4A95A849C0A0DE2, 314AA02EA84D267B32DBAEBEA6C1AC1A266DED1E8D35A17B41D1D2AC75E8049E ] MSiSCSI C:\Windows\system32\iscsiexe.dll
15:16:01.0387 0x1c08 MSiSCSI - ok
15:16:01.0388 0x1c08 msiserver - ok
15:16:01.0390 0x1c08 [ 13D614E6B51ECF36746C48CE829FA7F6, CAD63C0A4F7110093F84C58252C5803F14E3FC46584B79DA17EC86D49FEAEA64 ] MSKSSRV C:\Windows\system32\DRIVERS\MSKSSRV.sys
15:16:01.0400 0x1c08 MSKSSRV - ok
15:16:01.0403 0x1c08 [ 642CDE46351D5D2D90311E77072AB46D, B2D3033E607BA2F6E6B9CFB1CBF154CD0CE910EA473C56343EC81B9B94044CCA ] MsLldp C:\Windows\system32\drivers\mslldp.sys
15:16:01.0410 0x1c08 MsLldp - ok
15:16:01.0412 0x1c08 [ F2302A5CE63CA7673200FAFCEEEDB6AF, B8C44FC2DC0332183DE325CDBF511101F3307225295EDD428CE575A8DE15C223 ] MSPCLOCK C:\Windows\system32\DRIVERS\MSPCLOCK.sys
15:16:01.0422 0x1c08 MSPCLOCK - ok
15:16:01.0424 0x1c08 [ 6114512EA26E835BA522C63635429DB5, 0F91CE41B4555316A79AEF3047C152D538CC9C7C329987C9FD0E3D961AFC87C8 ] MSPQM C:\Windows\system32\DRIVERS\MSPQM.sys
15:16:01.0433 0x1c08 MSPQM - ok
15:16:01.0440 0x1c08 [ AA538E16E644D00E3BA5349BBA9598EC, 64A68B06883FE7ED34E04AB119BA819753F1222923EDD4E802C35D402B89D075 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
15:16:01.0451 0x1c08 MsRPC - ok
15:16:01.0455 0x1c08 [ 7ACFE7435317E791FF9EED2F49B402F2, EAF2CE12403A9D975112A22EDBC313EE63B926C070B35E62D515403DD34BD88D ] MsSecFlt C:\Windows\system32\drivers\mssecflt.sys
15:16:01.0463 0x1c08 MsSecFlt - ok
15:16:01.0465 0x1c08 [ 0543BEFD41EC4D25C7F7CF36409CEC7D, 631622CFEC49952C0470531B23FFFFF483DC0EFFEF7A97B1179A600392C05DDD ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
15:16:01.0471 0x1c08 mssmbios - ok
15:16:01.0473 0x1c08 [ C1569E4DB8EFE3617847BF041A3C842F, 99ADE5E7F50E04CAEC737F7F90741CCA8EE628996BA5EB6C6BC62184884429B6 ] MSTEE C:\Windows\system32\DRIVERS\MSTEE.sys
15:16:01.0482 0x1c08 MSTEE - ok
15:16:01.0484 0x1c08 [ 130B16970154BA9876B09E5C4BAC63BE, BE3AF8FC5A26AB9C9DBA9C015C2E1FD3C4CD9CB423A2BBDABA91428BF8620553 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
15:16:01.0491 0x1c08 MTConfig - ok
15:16:01.0494 0x1c08 [ 15D987C8F6CCD4AC94E070C5986762CB, 452FB0C48B86C7F8F53794CC2DDBF2B900B03A0383B2DE8F6A830F8CB0AFBAD8 ] Mup C:\Windows\system32\Drivers\mup.sys
15:16:01.0501 0x1c08 Mup - ok
15:16:01.0504 0x1c08 [ 3D2C5B4995CA0751D32DEA0DE9FDFE44, A26958785FD9E05E2CA97078C9BB277CD44222BF5F7D9E8DC2F3F6AAAFFC6483 ] mvumis C:\Windows\system32\drivers\mvumis.sys
15:16:01.0509 0x1c08 mvumis - ok
15:16:01.0519 0x1c08 [ DB31EBB04C871F422C36A0962DA7D38B, B1BC2344744F537FB2C7D07B415F860195B7795E185253F05C0817A3764FEC10 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
15:16:01.0534 0x1c08 NativeWifiP - ok
15:16:01.0539 0x1c08 [ C3D9870E680D9D843B18F4626C3858FE, 43596CAC9FB488F810FBA954C52BC4D13F7D32028C40ACFE33DFD7EE36A65C17 ] NcaSvc C:\Windows\System32\ncasvc.dll
15:16:01.0550 0x1c08 NcaSvc - ok
15:16:01.0555 0x1c08 [ 04CE2C0F0759EACD886BA4B658B60D5D, E34D0976FC5936C8629800D826DB127072D1DFC3D350EFACA3AA1B8119551762 ] NcbService C:\Windows\System32\ncbservice.dll
15:16:01.0569 0x1c08 NcbService - ok
15:16:01.0572 0x1c08 [ E6094065008FE423377294050E7CEA2D, 86E200227256407530E2C28243DEFBC3CB6E9497644404D9AD79DA242286DF7B ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
15:16:01.0585 0x1c08 NcdAutoSetup - ok
15:16:01.0593 0x1c08 [ 629CB21AC49C8867E0F29DF1C16DB7B4, 20663E68C69D0A1A2FE99A0C2A9DEFABF49786A1DC8F7F4E1699458AF57D7E79 ] ndfltr C:\Windows\System32\drivers\ndfltr.sys
15:16:01.0600 0x1c08 ndfltr - ok
15:16:01.0619 0x1c08 [ D5564FC81350458ED570528C4E3B1CCF, DD3C5012492EF9BCE3BE635BBB3AA40B3C5F5FDBD795A76B327D9C994102AC2B ] NDIS C:\Windows\system32\drivers\ndis.sys
15:16:01.0640 0x1c08 NDIS - ok
15:16:01.0643 0x1c08 [ 6DD605338FAAF6BA17662AA874E0D162, 636607829F5D7C3B7A4683C0A2DD594360D72F2AA3F8710153BE32575AE34A15 ] NdisCap C:\Windows\system32\drivers\ndiscap.sys
15:16:01.0650 0x1c08 NdisCap - ok
15:16:01.0653 0x1c08 [ E34196F285F8B8879E1FF36C31F7179E, 77A4F24F995D4C0689C43F9956E08DCEC62517E4F8B1B9EAA1852B5293DB5B9A ] NdisImPlatform C:\Windows\system32\drivers\NdisImPlatform.sys
15:16:01.0664 0x1c08 NdisImPlatform - ok
15:16:01.0666 0x1c08 [ 1FAD2398673F30CEC616B89C46B7DCBA, 70302049E6AE2BC6B3A7A9DE54D3F940AD6A9771CC2EBCCEC65994E67A25ECB5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
15:16:01.0676 0x1c08 NdisTapi - ok
15:16:01.0679 0x1c08 [ AEB8ECBE66CC46854066CB1F5623E179, 2F650A85A9DAE38887610C0B876621035616CEDB65D4BBBD7F1405616D218AAF ] Ndisuio C:\Windows\system32\drivers\ndisuio.sys
15:16:01.0686 0x1c08 Ndisuio - ok
15:16:01.0688 0x1c08 [ 7340104C2BF2F126714F7CDE85E63610, 45B64EC6F3A4C43F7D74806789067658C6EF0D44D36B841F4D26E1EBC95AF66C ] NdisVirtualBus C:\Windows\System32\drivers\NdisVirtualBus.sys
15:16:01.0695 0x1c08 NdisVirtualBus - ok
15:16:01.0699 0x1c08 [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] NdisWan C:\Windows\System32\drivers\ndiswan.sys
15:16:01.0712 0x1c08 NdisWan - ok
15:16:01.0716 0x1c08 [ 07ADC1F8DCBEB8104D75129B11584B8C, CB51A294D9FD4E210DBEEF05A1E60A96CE52D6D138EF62A54E1F608F90FED300 ] ndiswanlegacy C:\Windows\system32\DRIVERS\ndiswan.sys
15:16:01.0728 0x1c08 ndiswanlegacy - ok
15:16:01.0731 0x1c08 [ 78A12E3DF035B5D054986949B19BE43C, AD9B34F89B9F27D473BD5FCE6694A40FCCB808B61ABEDD6F70F1AF6C7E73ABF8 ] ndproxy C:\Windows\system32\DRIVERS\NDProxy.sys
15:16:01.0741 0x1c08 ndproxy - ok
15:16:01.0744 0x1c08 [ 04C8859355C1DC9C0FA198D1894D71C2, E7C67E73009341B5D402470C686781B3C7BBE2531CE26665E08E711B990B1A77 ] Ndu C:\Windows\system32\drivers\Ndu.sys
15:16:01.0756 0x1c08 Ndu - ok
15:16:01.0759 0x1c08 [ 6C76780A01FC2B885BD6E957B5C36B02, DB7834F03A765F65C773E772D8051AFADB22CA4B5074180AA397857A0C47A068 ] NetAdapterCx C:\Windows\system32\drivers\NetAdapterCx.sys
15:16:01.0766 0x1c08 NetAdapterCx - ok
15:16:01.0769 0x1c08 [ 5D1513BD6430307C9DB86C6E351372ED, D2AB709CF7CFA5B857B084AFC821914A975B7DDDCE154229981F19448973BD6D ] NetBIOS C:\Windows\system32\drivers\netbios.sys
15:16:01.0775 0x1c08 NetBIOS - ok
15:16:01.0780 0x1c08 [ 6FEBB0A847FFD5F057B9AC8889F1B9A7, 558BCC64C59079E6569F61CCE1219A124B3313FC4E6CB5CBCC94124D202FF19D ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
15:16:01.0792 0x1c08 NetBT - ok
15:16:01.0794 0x1c08 [ 6F8E95716C1A27FF2FE96D30B147F1C1, 9403E9FE8B13EE294CFBBD96649BBD54CF723CF5872E3E03DA4380379D677983 ] Netlogon C:\Windows\system32\lsass.exe
15:16:01.0801 0x1c08 Netlogon - ok
15:16:01.0806 0x1c08 [ D3BF2DA9216A4CF22A97820A50A67EFF, D00CBE0A7ECFB449D9B48967A01EE56141404EBE229893D5A1710781AD5F2551 ] Netman C:\Windows\System32\netman.dll
15:16:01.0818 0x1c08 Netman - ok
15:16:01.0827 0x1c08 [ F2645D51DD8AABC8BC72358409410437, 8CB97628923D6CEA6EFAD7E666BE92C154060BD108C28D46287A520A14B18ADA ] netprofm C:\Windows\System32\netprofmsvc.dll
15:16:01.0844 0x1c08 netprofm - ok
15:16:01.0849 0x1c08 [ D65F295A049473E6A39EA9A0EA76CA32, 274FC0BA044EB2D14093AB0E561F7FACEE06A3F433C81343C8B926FA2F9BD251 ] NetSetupSvc C:\Windows\System32\NetSetupSvc.dll
15:16:01.0861 0x1c08 NetSetupSvc - ok
15:16:01.0866 0x1c08 [ EFA857E2B0CC7C9DFEF48A2187B910F7, 424475568CD70237F056838388A5F7BDCD1B09349085498644C75940B12E8EAF ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe |