Code:
15:15:21.0765 0x2a20 NativeWifiP - ok
15:15:21.0784 0x2a20 [ B281FAC1C60FE21ED3F635ECF673A981, 6641CCBD38AEF3FA5D9EDD24F01AAB6509AD6D3927371CD7938C04B3BBC92FD1 ] NaturalAuthentication C:\Windows\System32\NaturalAuth.dll
15:15:21.0822 0x2a20 NaturalAuthentication - ok
15:15:21.0829 0x2a20 [ 6FEC83EDC4A3D1E99039CA1D96AD720D, F6DB011FBED10EAF8CCDC9EDDCB47F728B6B17A6A3CA5D6DB5DE50EEFE7DDD4D ] NcaSvc C:\Windows\System32\ncasvc.dll
15:15:21.0849 0x2a20 NcaSvc - ok
15:15:21.0859 0x2a20 [ C3D3E2DFBD52C48EA787604F49060A5C, 0F5E3C9E63F6421398154EF942182FE67CCCCE6DE25B1EE2A30A8E6E3C17145A ] NcbService C:\Windows\System32\ncbservice.dll
15:15:21.0886 0x2a20 NcbService - ok
15:15:21.0892 0x2a20 [ 9AB04C4C14B32D127DB6E7D3DF79FF26, DAC84CBDF605C43657CDA1B95A86DC0D55E236A75BFDA3041472C5D6222EB025 ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
15:15:21.0910 0x2a20 NcdAutoSetup - ok
15:15:21.0915 0x2a20 [ AB9EB3CADF4D415B598487397476A23A, EA48BC5CCD9814F6CA50485818BA150A1066D462306764C197935A926DF0565E ] ndfltr C:\Windows\System32\drivers\ndfltr.sys
15:15:21.0927 0x2a20 ndfltr - ok
15:15:21.0953 0x2a20 [ E54D9AC4A3315D7E775ECC7B06F373DC, B3F150A0A3D71DA644BE91B17E1260D790926C10D36B83EB9D59F8C088E2D9F0 ] NDIS C:\Windows\system32\drivers\ndis.sys
15:15:21.0991 0x2a20 NDIS - ok
15:15:21.0998 0x2a20 [ AF73B18F3096B165A6F4417C5ED36B01, B0FA9E52D7208F756103E2E853F1D17F594C9FDD2E76304743C581613E612449 ] NdisCap C:\Windows\system32\drivers\ndiscap.sys
15:15:22.0013 0x2a20 NdisCap - ok
15:15:22.0019 0x2a20 [ 1A9B1F5B8B131CE461A01C9424E149D7, 66E3F49308DF111B5D5DBF57F11A05E0B9492530587E37C6729C46AED17647D3 ] NdisImPlatform C:\Windows\system32\drivers\NdisImPlatform.sys
15:15:22.0037 0x2a20 NdisImPlatform - ok
15:15:22.0041 0x2a20 [ 4C8BBD7EE829CE9BFB8E21134AC477E0, ED8E0D603AFFA4BD7C7057B7B10FEB811B89CB8C6D66EC8212AC24062D58CEDB ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
15:15:22.0058 0x2a20 NdisTapi - ok
15:15:22.0063 0x2a20 [ 76DB7B344F90A29A16CB6B7C67B87CF6, 921E6AF5B22CF3A9E153F6A6F5E3FFE64BE49959AD705F865D2734B0F8A07517 ] Ndisuio C:\Windows\system32\drivers\ndisuio.sys
15:15:22.0083 0x2a20 Ndisuio - ok
15:15:22.0087 0x2a20 [ A76D79B71300EB3FEDD3D12D4C6F1D76, 9B20C3716DDD9EECCDDFA2C4F1A9ACA512B612A8CDFC8C22B2F867280AE51A3B ] NdisVirtualBus C:\Windows\System32\drivers\NdisVirtualBus.sys
15:15:22.0102 0x2a20 NdisVirtualBus - ok
15:15:22.0108 0x2a20 [ 407FC276F4E21FC9BF40D8F78E9D96AE, 87AC75F713100C9938FBAE16B0F40A5C77713DA12690AFCF7365F2FCBCCD4472 ] NdisWan C:\Windows\System32\drivers\ndiswan.sys
15:15:22.0127 0x2a20 NdisWan - ok
15:15:22.0134 0x2a20 [ 407FC276F4E21FC9BF40D8F78E9D96AE, 87AC75F713100C9938FBAE16B0F40A5C77713DA12690AFCF7365F2FCBCCD4472 ] ndiswanlegacy C:\Windows\system32\DRIVERS\ndiswan.sys
15:15:22.0152 0x2a20 ndiswanlegacy - ok
15:15:22.0157 0x2a20 [ 934E4A5CFD9CB891CD338052FA3467C6, 0D7C1709E6C818E2DA969220C888BF3A28D0952E73322EDDFF66AFEEB03A3103 ] ndproxy C:\Windows\system32\DRIVERS\NDProxy.sys
15:15:22.0174 0x2a20 ndproxy - ok
15:15:22.0180 0x2a20 [ 0E3B0F3645D1BAE79397C66FE8AF6402, 6568FD9646FE7C7D61D280C26097583EFA2FB9F59D43340A7283BEAD3A5CC206 ] Ndu C:\Windows\system32\drivers\Ndu.sys
15:15:22.0200 0x2a20 Ndu - ok
15:15:22.0207 0x2a20 [ A704515CF3038668E9E2CA66E31A0700, 0F5A75AC5FF8E021D15D89ACE4C4D215825D931097E1BB633F46177E36F40157 ] NetAdapterCx C:\Windows\system32\drivers\NetAdapterCx.sys
15:15:22.0229 0x2a20 NetAdapterCx - ok
15:15:22.0234 0x2a20 [ DD09E3115DF2CDB36FED21E67149EB91, F2FAD5091F456E593FB25843026C5F2440D3605E5355F5FEFBFEF5E9E70DDED6 ] NetBIOS C:\Windows\system32\drivers\netbios.sys
15:15:22.0246 0x2a20 NetBIOS - ok
15:15:22.0256 0x2a20 [ A6C01E478CD9ED26F6FB7ABCF9A2C773, 9524D6BC0F3360311A8C887B7987949BC1B24606BCAB92532C59AA61B364F0D7 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
15:15:22.0280 0x2a20 NetBT - ok
15:15:22.0285 0x2a20 [ 3DF3B76B19DA92A8ADC01FF38560282D, F56DDDF7A8F1AA0F3D9FFE0CD618544CFAF233A33314240ECCBE5F897A91B534 ] Netlogon C:\Windows\system32\lsass.exe
15:15:22.0297 0x2a20 Netlogon - ok
15:15:22.0306 0x2a20 [ C3D07481FDD607F9B66B2CF1D8E26EF0, 5B20EAE39884B103F83A36E9AA55BA8932432344C7BADB11D8B827C07C7999E4 ] Netman C:\Windows\System32\netman.dll
15:15:22.0329 0x2a20 Netman - ok
15:15:22.0341 0x2a20 [ A3425B6F5F038DA2755EE004CDD2D76D, 2C81B42A77AD27CBDAC2AA1737410EDA52DD00A65529640250EF1462BCD65050 ] netprofm C:\Windows\System32\netprofmsvc.dll
15:15:22.0370 0x2a20 netprofm - ok
15:15:22.0380 0x2a20 [ C8B1AF912319FEF251288BDD27E9576D, 0A8C2CDE353C23F076F6ED8609F3074116179B3C8BF7700324250689FDB2331C ] NetSetupSvc C:\Windows\System32\NetSetupSvc.dll
15:15:22.0407 0x2a20 NetSetupSvc - ok
15:15:22.0417 0x2a20 [ 7EC8B56348F9298BCCA7A745C7F70E2C, F677CBD94ABE25AECF08ECFBBDA063A9C032C678327A0D105CB6B3E587C44C19 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
15:15:22.0428 0x2a20 NetTcpPortSharing - ok
15:15:22.0435 0x2a20 [ DA8548D75434CE421BF921BAAC0916D9, 3A7E1D5EC02D6D4FD3321A1B8ADB20E99DD556E2D5FE1C98633F06EE6A023A23 ] netvsc C:\Windows\System32\drivers\netvsc.sys
15:15:22.0454 0x2a20 netvsc - ok
15:15:22.0469 0x2a20 [ 162A571ABAF9546339EE0BB482FF6AE7, E6E590B628AA65D161D7A87C9CF360D905FCC858E73EE1C4723FE217E8A91EA2 ] NgcCtnrSvc C:\Windows\System32\NgcCtnrSvc.dll
15:15:22.0503 0x2a20 NgcCtnrSvc - ok
15:15:22.0521 0x2a20 [ CA8AD24C34F990C93846D4D9DDDC9E58, 8509062782423D978CBF498731043B1464C2A84524025B08AEA2BB0A51400C31 ] NgcSvc C:\Windows\system32\ngcsvc.dll
15:15:22.0557 0x2a20 NgcSvc - ok
15:15:22.0569 0x2a20 [ BF69FF80C3975B1D1E9428A689A16CB1, 670016D59D2169B44E2EF4CBDE281A34C4E868D2465362B09FA2DBFA393A2804 ] NlaSvc C:\Windows\System32\nlasvc.dll
15:15:22.0596 0x2a20 NlaSvc - ok
15:15:22.0601 0x2a20 [ 57C732F21604C5FC74FD1CBCA0C6EAE7, B65EB98012A14523C5CE59859FD973B3ECEAC929DA58B79CB05597C5A75D4858 ] npcap C:\Windows\system32\DRIVERS\npcap.sys
15:15:22.0612 0x2a20 npcap - ok
15:15:22.0616 0x2a20 [ 57C732F21604C5FC74FD1CBCA0C6EAE7, B65EB98012A14523C5CE59859FD973B3ECEAC929DA58B79CB05597C5A75D4858 ] npcap_wifi C:\Windows\system32\DRIVERS\npcap.sys
15:15:22.0625 0x2a20 npcap_wifi - ok
15:15:22.0634 0x2a20 [ 55E728D557F3AE1CBA58B80D7DD59D69, 03EE2DFDD5A06D6BFDF4382A8DBD3E768A48613311A4C29F7626B81E296B7EF1 ] npf C:\Windows\system32\DRIVERS\npf.sys
15:15:22.0658 0x2a20 npf - ok
15:15:22.0663 0x2a20 [ 7190932DB00BE83B57C01B5EAC4D746B, A3C7C87874620E042EFCDF64332450ACEDD4FAB7F6C1B2DE97A1C6EDA2DA3055 ] Npfs C:\Windows\system32\drivers\Npfs.sys
15:15:22.0679 0x2a20 Npfs - ok
15:15:22.0684 0x2a20 [ 55E728D557F3AE1CBA58B80D7DD59D69, 03EE2DFDD5A06D6BFDF4382A8DBD3E768A48613311A4C29F7626B81E296B7EF1 ] npf_wifi C:\Windows\system32\DRIVERS\npf.sys
15:15:22.0695 0x2a20 npf_wifi - ok
15:15:22.0699 0x2a20 [ 218DB396170D77BB94F69B526CC51B8F, 6AACC3C38E22061A210918771D3B087903CB7024AFBD013827864C02CD75A3F9 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
15:15:22.0717 0x2a20 npsvctrig - ok
15:15:22.0722 0x2a20 [ 457DAC0D0978F5391E0742ADCB4C2E28, AD53F2FC597E90AFF0795655A36192BA803AD1E737C86FD216CD39E2EC4F9C36 ] nsi C:\Windows\system32\nsisvc.dll
15:15:22.0739 0x2a20 nsi - ok
15:15:22.0744 0x2a20 [ A4952889D7C5804F17ABB9F454A371C2, 0FCE2AD4F705805D95993337915607F74CE2AA9EC92919DDE3D2569D6B9B5C13 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
15:15:22.0758 0x2a20 nsiproxy - ok
15:15:22.0805 0x2a20 [ 8AA13C67D70E9452B55B7A5C8B96BD36, 01E69E7E0EC4A6C2DC4736A01188348A8C5B17A6D1B443212173AE4A7D93BEDB ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
15:15:22.0865 0x2a20 Ntfs - ok
15:15:22.0871 0x2a20 [ C029E5408EEE26C3B4E5BA5D29738DB8, 8463A19A690304DC757E7698FCB59902B6305A0E9C48BF2FB2DF24C1EFA4A6EC ] Null C:\Windows\system32\drivers\Null.sys
15:15:22.0889 0x2a20 Null - ok
15:15:22.0898 0x2a20 [ 189E5FCB96ABFEA84239A16062256EE4, F3233B1B14363CD4CD032F43368FD10A42C0BE665F4B13A7E253C327C2B832DB ] nvdimm C:\Windows\System32\drivers\nvdimm.sys
15:15:22.0912 0x2a20 nvdimm - ok
15:15:22.0922 0x2a20 [ 0A4C96A706AAD735FFE0F98C408242A8, EF5DE8569A7BEDF5A940A2567FAC8660140ECD6E407938006880DAB5F8C98A13 ] NVHDA C:\Windows\system32\drivers\nvhda64v.sys
15:15:22.0937 0x2a20 NVHDA - ok
15:15:23.0292 0x2a20 [ F5C82A48B7A514B5CB76089C4B4D3A34, 6CE6BF988D0E9FEC778DD66791EA0C59893138D023CCCFF44EE5EA3B1CE8717B ] nvlddmkm C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_e59b844303b9907e\nvlddmkm.sys
15:15:23.0673 0x2a20 nvlddmkm - ok
15:15:23.0698 0x2a20 [ 1F50ED95984009BF3634D6BD1A16FA5B, 650A25B2419331D95B1E4C26DE253AC3500374EDEFC5DB55CD5D5884A26783F0 ] nvraid C:\Windows\system32\drivers\nvraid.sys
15:15:23.0712 0x2a20 nvraid - ok
15:15:23.0718 0x2a20 [ D6C14906B78F235461EEF96A886830D4, 5D0EDE46EB9965C494B994F7071696C91C0C01352D1B000501E7B55F54F11952 ] nvstor C:\Windows\system32\drivers\nvstor.sys
15:15:23.0732 0x2a20 nvstor - ok
15:15:23.0737 0x2a20 [ 23423E859CA253382D80D0321522A171, 79C914C0A421E0BE566B5FCD5868B1248D4F397C24F8C5E70A8EA6E260617845 ] NvStreamKms C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys
15:15:23.0746 0x2a20 NvStreamKms - ok
15:15:23.0758 0x2a20 [ 4BE0930A6E5FC5FB5C91473A3E89FB7B, 41987260F74651C9BAC97BBB31BAA991C5F86C96E5DAB1F1F7AEBC9BD4BEB502 ] NvStUSB C:\Windows\System32\drivers\nvstusb.sys
15:15:23.0776 0x2a20 NvStUSB - ok
15:15:23.0780 0x2a20 [ F12864A2CCC899FE8E87463C967A9916, 08C2FD2E23EEFAA43904CBE46BBE1D073DE400E4DA005B8B5325BE2C6A29BA9D ] NVSWCFilter C:\Windows\System32\drivers\nvswcfilter.sys
15:15:23.0790 0x2a20 NVSWCFilter - ok
15:15:23.0802 0x2a20 [ 9DF8BBA81D0A44AA9D14B7ADE47D2200, 3F50BE14892D168032DA9AF22259A986F024E6AD43DAEEC3C1E777BFA9E5A157 ] NvTelemetryContainer C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
15:15:23.0818 0x2a20 NvTelemetryContainer - ok
15:15:23.0823 0x2a20 [ E502016A185B5BB9DC341873F82CD49C, A1F7D3E4FA5B4C81966F0E1DE8039CDD0374A9FF86AB252483FC9D98360089A1 ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
15:15:23.0832 0x2a20 nvvad_WaveExtensible - ok
15:15:23.0837 0x2a20 [ F438902185093A11F1BEC238B6B5862A, 18E1CFF7899B0A5D4DBA1633FF0D46ECE47AD0828CEA8D8A3A8B3549BFD1C9E6 ] nvvhci C:\Windows\System32\drivers\nvvhci.sys
15:15:23.0848 0x2a20 nvvhci - ok
15:15:23.0858 0x2a20 [ 9DBC464AB85AA48C9760C6C2E591E2D3, C9D718F8BE838E13F7488F1E8DAA79809340235A5BA5BF206C1C3DBF0A5DDB48 ] OneSyncSvc C:\Windows\System32\APHostService.dll
15:15:23.0882 0x2a20 OneSyncSvc - ok
15:15:24.0021 0x2a20 [ 85E841798B0669F260BAD9D778F8146F, F37CDBC3F875DE1A0104B117D6E8D7DC4C5C1D8196986C08C6A090C1C236970B ] Origin Client Service D:\Games\Origin\OriginClientService.exe
15:15:24.0092 0x2a20 Origin Client Service - detected UnsignedFile.Multi.Generic ( 1 )
15:15:24.0159 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:24.0160 0x2a20 Origin Client Service ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:24.0160 0x2a20 Force sending object to P2P due to detect: Origin Client Service
15:15:24.0327 0x2a20 Object send P2P result: true
15:15:24.0602 0x2a20 [ 23F31E9A56527C63FE34E9C742B27DB8, 2F7279DC19D0BECAB9A282EDFF8A0955A5A2419FBA608D86345C9B21BDB2638D ] Origin Web Helper Service D:\Games\Origin\OriginWebHelperService.exe
15:15:24.0664 0x2a20 Origin Web Helper Service - ok
15:15:24.0675 0x2a20 [ D73A677A040EFEB9645EF25615EE7D5B, 6B88E17E7CF273BF7AB4AFA53D33AFB11CF48D4FE1FB3D20AB122C5369C12415 ] ose64 c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:15:24.0689 0x2a20 ose64 - ok
15:15:24.0699 0x2a20 [ CD5ECD6470B6B235B73569A091150299, FAAE20B0F2F15ADA5B3F5F2BBBFEA000A95EC8A64B37C9364145CE04EE204352 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
15:15:24.0723 0x2a20 p2pimsvc - ok
15:15:24.0735 0x2a20 [ CCD10679BA0D9EF549F80C458C2AD1C4, 7B433FEE4BEA69C28A98F4BFBE5FA603DB2CE1DFCF229EBB4D9B7A0FD159FF04 ] p2psvc C:\Windows\system32\p2psvc.dll
15:15:24.0760 0x2a20 p2psvc - ok
15:15:24.0765 0x2a20 [ 13B175715A4391E4E5D2AB2EBC8CDBB5, 12BA91A586C5A31FBECEB2D4842E52F79EDD3E2AD4DB169C902B9A120AEC0201 ] Parport C:\Windows\System32\drivers\parport.sys
15:15:24.0781 0x2a20 Parport - ok
15:15:24.0788 0x2a20 [ 428B9FAFB0EE6EF66EAAB7B49A96487A, 90892AC924B529B86B42D011B2B2F0556E204650C890FDACABD8051AD6EDB631 ] partmgr C:\Windows\system32\drivers\partmgr.sys
15:15:24.0801 0x2a20 partmgr - ok
15:15:24.0815 0x2a20 [ D0D8F07883CE4C96B41469071DA4E58B, 237B128D8B20101A6AE0BAD2689FEF58A14807A2DB87AEBB21E2F8375F082BB1 ] PcaSvc C:\Windows\System32\pcasvc.dll
15:15:24.0837 0x2a20 PcaSvc - ok
15:15:24.0848 0x2a20 [ 171FEE651F837DE6BC0831EB2EE6E667, 3DA84AE42D5D05405143B76B0DE0D21E46052AF124EBE2E639349250382711E0 ] pci C:\Windows\system32\drivers\pci.sys
15:15:24.0865 0x2a20 pci - ok
15:15:24.0870 0x2a20 [ C447CDA030A3415711E4E940D2E9B399, 292888AE9D44013D8B12BB1D8803988EFF64957DE682B64FDC82E100646390DA ] pciide C:\Windows\system32\drivers\pciide.sys
15:15:24.0880 0x2a20 pciide - ok
15:15:24.0886 0x2a20 [ 753174DF234EA8BBF732986D5F78FCE7, 6BE93B24DA2161DAE5ECBE393729BD4661F04CD0CDEBEBF6D92E9E212FA89D71 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
15:15:24.0897 0x2a20 pcmcia - ok
15:15:24.0902 0x2a20 [ 1D05B6DE437515281CD91A16C16529E6, 0FC581E40AF55D916CF428ECF4387C1E909C3361426F1D9F723F9497C9B025D8 ] pcw C:\Windows\system32\drivers\pcw.sys
15:15:24.0914 0x2a20 pcw - ok
15:15:24.0921 0x2a20 [ F5F1A092463D6E46E71CC709A65403D1, 9EEB499D54842667B4ECF1036E28926C8AD20515333373D2965C57BC2C7EAD4C ] pdc C:\Windows\system32\drivers\pdc.sys
15:15:24.0933 0x2a20 pdc - ok
15:15:24.0950 0x2a20 [ 42B12A76D3C98AE69C97727E3BEC7D8A, C878A05A9817F62514432685FAA795737F628EF7258EC5C7846045E1CAB2DF6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
15:15:24.0994 0x2a20 PEAUTH - ok
15:15:25.0033 0x2a20 [ 05A0A1AC00A8653B49F94381872D47E7, 75B7E616D08D6D8BD964953B5CC342E72E35D8C660E2F97BD36ADA59130169F6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
15:15:25.0102 0x2a20 PeerDistSvc - ok
15:15:25.0109 0x2a20 [ CD9BA1C279BE0E92E971C2B45A7F3D9B, EC6546868718771EE45D07E9E856E5F33DD4339C1115E4479D7DEF4394D141D0 ] percsas2i C:\Windows\system32\drivers\percsas2i.sys
15:15:25.0121 0x2a20 percsas2i - ok
15:15:25.0126 0x2a20 [ 6D5EA79E82A48B181E18C2C39416E8C8, 4F5EF24FFFABB82B1E9D98DE3275508D458589F729C4976FDB3C2EC51549D414 ] percsas3i C:\Windows\system32\drivers\percsas3i.sys
15:15:25.0138 0x2a20 percsas3i - ok
15:15:25.0161 0x2a20 [ 185100798FBD23C849DC1C00ED43D99D, 10895ADE339744BBABDFB50BE6025217C02C76B1911C2C8740A57912385B38DE ] PerfHost C:\Windows\SysWow64\perfhost.exe
15:15:25.0185 0x2a20 PerfHost - ok
15:15:25.0227 0x2a20 [ 7ECA879200FAB0A7EAA2E4F17239666D, 7D9177274055A5DC30C1925F4AB0C79756F4D8BB40440BF1C5C906492343041D ] PhoneSvc C:\Windows\System32\PhoneService.dll
15:15:25.0264 0x2a20 PhoneSvc - ok
15:15:25.0272 0x2a20 [ 807ED476A62E79935315342BD3FAA046, FF56FC79C6B6043A10C123CF85A8DDA0B8564E03D49AD5811DDCBB99823C4836 ] PimIndexMaintenanceSvc C:\Windows\System32\PimIndexMaintenance.dll
15:15:25.0294 0x2a20 PimIndexMaintenanceSvc - ok
15:15:25.0325 0x2a20 [ 4E614DBE28B5857F70DEBCC804629E67, B93C42FB96BBA0577CB892274905352AE4A6DE257F676D6A23CE0297F945D7E7 ] pla C:\Windows\system32\pla.dll
15:15:25.0388 0x2a20 pla - ok
15:15:25.0395 0x2a20 [ DBD6E8A5C358AAA3B4900EFD5CF94CC8, C8261CBE358562B3F31ADA0567723E0118A8687DFC8939FABC65E61C38BFE20B ] PlugPlay C:\Windows\system32\umpnpmgr.dll
15:15:25.0413 0x2a20 PlugPlay - ok
15:15:25.0422 0x2a20 [ E8BE4041A69023B6A4D1096EE8436347, 133BAA21852D077EA600F0A09C112F6511ACB792757472891E71185E94135D5B ] pmem C:\Windows\System32\drivers\pmem.sys
15:15:25.0438 0x2a20 pmem - ok
15:15:25.0443 0x2a20 [ 99ECEDA6B2E1FDB6892FBD5AED1E5D99, C970DDDBDB4AF8C6A1AA92D780B82920B4922304649509075CF14A2AB86C3CCF ] PNPMEM C:\Windows\System32\drivers\pnpmem.sys
15:15:25.0456 0x2a20 PNPMEM - ok
15:15:25.0460 0x2a20 [ 75690F495CEDBEF3D5989828AEEAE832, 3257E7261DF8F39CA4988BBED3060B9E8A5988978F66A4B1409E08F65B262FED ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
15:15:25.0475 0x2a20 PNRPAutoReg - ok
15:15:25.0485 0x2a20 [ CD5ECD6470B6B235B73569A091150299, FAAE20B0F2F15ADA5B3F5F2BBBFEA000A95EC8A64B37C9364145CE04EE204352 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
15:15:25.0508 0x2a20 PNRPsvc - ok
15:15:25.0519 0x2a20 [ 9744ADAF8DD679D64A33D828FABA39E1, AE820E529697A2F308E6A24127B3D4A7F02C406DA46A6CB65243EC3F6B400950 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
15:15:25.0546 0x2a20 PolicyAgent - ok
15:15:25.0555 0x2a20 [ F39D3876C731BB01BFE8F574188837C8, 51CB5E89397D6A150A05BDD53CC9B90B419A040BE1828C2E7BBD6684FE371588 ] Power C:\Windows\system32\umpo.dll
15:15:25.0578 0x2a20 Power - ok
15:15:25.0583 0x2a20 [ 1FB09FD846D5030B82EB345E9970A105, 871D38DD966EDD919B2E0C51125E1834A15A0222E2452605988BFD7E7B37C5C1 ] PptpMiniport C:\Windows\System32\drivers\raspptp.sys
15:15:25.0602 0x2a20 PptpMiniport - ok
15:15:25.0665 0x2a20 [ AD62FCEC1CB8ECD7C0E3DFD2FA79FDE4, 6372FC5E78A2DDB8AE6EB73BEB5C0D4056FB6BE9F231A36BAC37AE970F5EB247 ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
15:15:25.0770 0x2a20 PrintNotify - ok
15:15:25.0783 0x2a20 [ A60202AE474E2173ED91118DD73ADAAD, 6AE315E1DD9E3B03E48B8848FCB0CDD506080F0012DE478BA99D102F91E968E6 ] PrintWorkflowUserSvc C:\Windows\System32\PrintWorkflowService.dll
15:15:25.0802 0x2a20 PrintWorkflowUserSvc - ok
15:15:25.0811 0x2a20 [ E0E55CDA29C80A9520FCFC78D7F8A73D, 9DE15A73643D71183E568F8F4DD8776D935786BE46F15BFE2DFD607378FC9E58 ] Processor C:\Windows\System32\drivers\processr.sys
15:15:25.0828 0x2a20 Processor - ok
15:15:25.0840 0x2a20 [ F96AA93B40D4670016DAF8C8F0D1BCB5, E8B77B271FDD6036F44EB9F7B7D270E754E69914F91E19512BF038FC3EDAC04F ] ProfSvc C:\Windows\system32\profsvc.dll
15:15:25.0867 0x2a20 ProfSvc - ok
15:15:25.0874 0x2a20 [ 9E73997C6710ED6078C814B8708A3ABA, 124649F43C41FCFEC8DC4121716B37ACD559172A3B65FD287A17ADD03C015EE5 ] ProtonVPN Service C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe
15:15:25.0884 0x2a20 ProtonVPN Service - ok
15:15:25.0891 0x2a20 [ E4BF8BE7B3711BCBBC95EE983C0236F4, A71C09D83034C96F7ED4DB58F7388F8A13C7FD1A3F41FE8EEC553C42B65DFFC6 ] Psched C:\Windows\system32\drivers\pacer.sys
15:15:25.0904 0x2a20 Psched - ok
15:15:25.0912 0x2a20 [ 114C1662EBF3C52B0FF52EAB1D9787BB, 6EB1871F69EF4CB1A8FBFA9D73050E5253861D4BF8DC8999B652EAAFB04DD10D ] PushToInstall C:\Windows\system32\PushToInstall.dll
15:15:25.0940 0x2a20 PushToInstall - ok
15:15:25.0949 0x2a20 [ 8AB5F41584C98047ABEF490FC1E31F7E, F8480F9D9C1A60901975C529CC0911ED592834AB1068FADD88B15E6497A59221 ] QWAVE C:\Windows\system32\qwave.dll
15:15:25.0972 0x2a20 QWAVE - ok
15:15:25.0977 0x2a20 [ 00F72861538B6C4E925A21BAE397A49D, 6847E2332CC8573850428CC7E3A73B2DA0274977F53BDDF7DBA68D223A501CC4 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
15:15:25.0993 0x2a20 QWAVEdrv - ok
15:15:25.0997 0x2a20 [ 0FFABEB2D06CD74DDE0BCA510EEAEEBC, 8598F39D312754C92A3776104D596F0C0312712D934B9994B2711F95FA6FE0AE ] Ramdisk C:\Windows\system32\DRIVERS\ramdisk.sys
15:15:26.0009 0x2a20 Ramdisk - ok
15:15:26.0013 0x2a20 [ B834761352403111D0113284D8736025, 444D05D5F4CED956AFE48CA29CD59420BDB2B14336D19BE2A28612A851EACF4E ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
15:15:26.0028 0x2a20 RasAcd - ok
15:15:26.0034 0x2a20 [ FA99CE309B66586A0AA6EF9CFF7BC467, 4684EB05828C2153FE94468E7A9A75D8C81F90E700B437C5990BC9451AD39AC7 ] RasAgileVpn C:\Windows\System32\drivers\AgileVpn.sys
15:15:26.0052 0x2a20 RasAgileVpn - ok
15:15:26.0060 0x2a20 [ C7CCE345D0010B3B9AC5067578436BFE, 4473E7D0492B7F0214576861A6AD90363D7F826B5E0DE15A56E93DA94BBF19E7 ] RasAuto C:\Windows\System32\rasauto.dll
15:15:26.0078 0x2a20 RasAuto - ok
15:15:26.0083 0x2a20 [ 775ED7E51B58CF9EB415A1DBA540DACF, A3035A8A299D35B7A24A347FB8A2DB6B5892FD2A181D90F64CCD4806EA154395 ] Rasl2tp C:\Windows\System32\drivers\rasl2tp.sys
15:15:26.0101 0x2a20 Rasl2tp - ok
15:15:26.0122 0x2a20 [ 6208EAF6A9D17E867401D08BAB2FE47D, 55512CC174029D4168351B8C9584EF730AD25B4197EDED78CE3FD9AC47D761E0 ] RasMan C:\Windows\System32\rasmans.dll
15:15:26.0160 0x2a20 RasMan - ok
15:15:26.0165 0x2a20 [ E2433A620ABF4083157944E4692C500D, 126CA9F9D38FB4FA312A82FEA24C13D0693407384B1BCD55A0CBEFA8E52E1D8A ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
15:15:26.0181 0x2a20 RasPppoe - ok
15:15:26.0186 0x2a20 [ EE5D1D51FA74ECCE57CF2DB8F6A417D8, CC295366C60CAECA7CC32903E3A983635B55A5F5FD6E6BC4FEFE997B8154345C ] RasSstp C:\Windows\System32\drivers\rassstp.sys
15:15:26.0204 0x2a20 RasSstp - ok
15:15:26.0212 0x2a20 [ D7574D53A3D663B1DBBFCDC8223F8961, 711C92FDCA9724E193FE4D510E31C7A037DEF889DE007FC7A24D5941B0A9458D ] Razer Game Manager Service C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
15:15:26.0224 0x2a20 Razer Game Manager Service - ok
15:15:26.0233 0x2a20 [ DDEA05522E182C1B62522663DE3BF750, 047BEDEA92F536F77527BAA2D37C1EAC6F1B4194243084B8EF4268E193600B8E ] Razer Synapse Service C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
15:15:26.0246 0x2a20 Razer Synapse Service - ok
15:15:26.0258 0x2a20 [ 8CBCB14A22D48DE6EADFAED372AF870D, 61AE92836FFB40BC818D713C2E9F8838B4D7AE1327C2720B59CBAF2B101AAA73 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
15:15:26.0278 0x2a20 rdbss - ok
15:15:26.0284 0x2a20 [ 206AB796793FDBD518B82E2F308A7176, ED0DBDE7106970F217F4FB1FB184B6795A16356C879C17E0910840F64F292809 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
15:15:26.0298 0x2a20 rdpbus - ok
15:15:26.0305 0x2a20 [ 3DE4216324BE32FC3AF7667AE2406EE5, B2E3C47983C58B32E07E251FF729670B5D481249EEDFD3A3EFB0F8734673F1F6 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
15:15:26.0331 0x2a20 RDPDR - ok
15:15:26.0340 0x2a20 [ 0600DF60EF88FD10663EC84709E5E245, 48572DC0C644E13BD1713E29E522763EB4E00337ACA64D1392960D17EAF8923A ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
15:15:26.0350 0x2a20 RdpVideoMiniport - ok
15:15:26.0359 0x2a20 [ 65652EFAAF4A8A59E60A2D7BE15317E8, 83A9A8506EF4769625EF0EF43B93906A6FBD9133E52C12B17A68B89DAC68D026 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
15:15:26.0375 0x2a20 rdyboost - ok
15:15:26.0412 0x2a20 [ 3DCB3FAFE46B9FE41C9065EBBED97724, AEB08C8C1E6AB6181A5F2B540F913B59A1256AF0E6D5355C4AC7DDBA0BF0F20B ] ReFS C:\Windows\system32\drivers\ReFS.sys
15:15:26.0462 0x2a20 ReFS - ok
15:15:26.0484 0x2a20 [ B76350D40A46DBA17205F8373528FD83, A599A9B1297B5D70632A9EF23E9771BA646672A1B0E323144EDE906CCA172EB7 ] ReFSv1 C:\Windows\system32\drivers\ReFSv1.sys
15:15:26.0512 0x2a20 ReFSv1 - ok
15:15:26.0526 0x2a20 [ 980F60634FAF9C58FC468AF9AA609D68, 7BA03FE851F78D5DC9062ACEADF194ACB4F8F56C9D496B17D846CE1E4373B404 ] RemoteAccess C:\Windows\System32\mprdim.dll
15:15:26.0554 0x2a20 RemoteAccess - ok
15:15:26.0561 0x2a20 [ 106E630F1B2A8BF2BBD4508D9B166406, FAFBE21EC61B97B4B825285EBA0F661382A95119E1740EE4FB9A1F6FB3C0F5F7 ] RemoteRegistry C:\Windows\system32\regsvc.dll
15:15:26.0581 0x2a20 RemoteRegistry - ok
15:15:26.0597 0x2a20 [ 53BE6D9C36A9CB95A1568C24D44A8A34, DD8245F87B9D4203F56595D6ABF9F1E74EA071D4B7BB0469A293CA9E20BDA246 ] RetailDemo C:\Windows\system32\RDXService.dll
15:15:26.0637 0x2a20 RetailDemo - ok
15:15:26.0645 0x2a20 [ 3D4F4CCE0364CD3F1B539D2630686F24, 620EFC53D6F5279AEF4748FAE22F7239E7855D1F5C79B85F6CB54EF51C516408 ] rhproxy C:\Windows\System32\drivers\rhproxy.sys
15:15:26.0661 0x2a20 rhproxy - ok
15:15:26.0668 0x2a20 [ 7414B6F0E0B9BD9A215F93A385BFEBF1, 17903ABF595411694BC9951785668421FEC439EF346A65C8854D4FA663F185A2 ] RmSvc C:\Windows\System32\RMapi.dll
15:15:26.0686 0x2a20 RmSvc - ok
15:15:26.0692 0x2a20 [ 3CD63AE6A9A1DE4CD5831AE15221C861, CB8B5FDA48D9D4E5A9F26F67859105E2769AF82B2CA1B0B35D9BFBA611445CC0 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
15:15:26.0712 0x2a20 RpcEptMapper - ok
15:15:26.0717 0x2a20 [ 19EC4D05E01FE350B3494CEA122D64EB, 09FF60A8F22D66796257E33F4CFD6059D4A11A3173A7691718E9FE841E15ABA2 ] RpcLocator C:\Windows\system32\locator.exe
15:15:26.0732 0x2a20 RpcLocator - ok
15:15:26.0756 0x2a20 [ E0D1E2A22B39782081D3FC64AB8ABA35, 338B6C7C3E63B783820F159DA502642F88B07F8DE6A6090DF54DAC6BE0400DB0 ] RpcSs C:\Windows\system32\rpcss.dll
15:15:26.0801 0x2a20 RpcSs - ok
15:15:26.0807 0x2a20 [ FFFB16EF6E0B8B5F7F19B425923E7D12, 27C2882AC7B27BAC5A4051C2C9326A6D289F297158DE7A3A93E8B09378DC91AA ] rspndr C:\Windows\system32\drivers\rspndr.sys
15:15:26.0824 0x2a20 rspndr - ok
15:15:26.0839 0x2a20 [ AB7C0639DF052528C2CB06D0EAE115EC, 5D709DE453FBC3DD880859D2B11BCB780FEA8C0618AA47622C85BD414EC540BE ] rt640x64 C:\Windows\System32\drivers\rt640x64.sys
15:15:26.0868 0x2a20 rt640x64 - ok
15:15:26.0990 0x2a20 [ E0FB1CB021E0C1E1BA390EC18B32C022, 0B78AA81E4EAEA00527DCBC1C4A0239D844811E2D537F2BB41E4FEF1C43CE433 ] RtlWlanu C:\Windows\System32\drivers\rtwlanu.sys
15:15:27.0119 0x2a20 RtlWlanu - ok
15:15:27.0130 0x2a20 [ AC8474C1E816A3447E4EA661E18810CC, 3A617E31B9CBFB0A4C25166990E6C04215932E3642535CCC858AA4650408983F ] RunSwUSB C:\Windows\runSW.exe
15:15:27.0140 0x2a20 RunSwUSB - ok
15:15:27.0153 0x2a20 [ 2CDD66018B7B9BD5C148DCC06B1ED5EE, 1832853E77C9D6B363C8EBE06CDEA7C5E2116BBBB7FBE5FAFCED93004E40B23A ] RzActionSvc C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
15:15:27.0172 0x2a20 RzActionSvc - ok
15:15:27.0176 0x2a20 [ A2939E69027B97105014434BFBFF7195, 9DC09BE94415564D0E80431223BDA1C59E3555AB5267DD3F64E71D4A18C8553A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
15:15:27.0190 0x2a20 s3cap - ok
15:15:27.0195 0x2a20 [ 3DF3B76B19DA92A8ADC01FF38560282D, F56DDDF7A8F1AA0F3D9FFE0CD618544CFAF233A33314240ECCBE5F897A91B534 ] SamSs C:\Windows\system32\lsass.exe
15:15:27.0208 0x2a20 SamSs - ok
15:15:27.0214 0x2a20 [ 04C51BBD8C9F54E5F2C5D831B03B11E3, 15AD9F224CBBCAFB117574F03C6F1C02639928A95BC4533453EBAFB20F7AE671 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
15:15:27.0227 0x2a20 sbp2port - ok
15:15:27.0235 0x2a20 [ 2BB468B175EAC4B566954B79142CC73B, 3BD169B0F044F1E53CA4A14021CEA755D29D3F8407300B4AF4F6514DC516FB0D ] SCardSvr C:\Windows\System32\SCardSvr.dll
15:15:27.0256 0x2a20 SCardSvr - ok
15:15:27.0264 0x2a20 [ 1B1FB3D8403E621F2B9201EF414E21D9, 5EFBEA5DC09CD5F151EF224BE2FF2C985D19301B17E5C16F5D00CB2852DAF8BF ] ScDeviceEnum C:\Windows\System32\ScDeviceEnum.dll
15:15:27.0283 0x2a20 ScDeviceEnum - ok
15:15:27.0288 0x2a20 [ 0070C2DC6563C48EDA63A282748F3FCD, 12C8505DDD05994641B2B19666D7A54E12A21F6894913342A9BA5D148F193BE0 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
15:15:27.0302 0x2a20 scfilter - ok
15:15:27.0322 0x2a20 [ 0C333E26CFF25C53FCBAB58F4ED74685, CB3046ECE1D50EC8F4F524615047442DB3A75DD5A171C57980EDC6C91EF87B4A ] Schedule C:\Windows\system32\schedsvc.dll
15:15:27.0362 0x2a20 Schedule - ok
15:15:27.0369 0x2a20 [ A61C34A8B6BA61E61C612CAD636C369F, 9966C5D2B4B60555BE9B9533DA62E0806767226B55EEC31030FB230DEBEC2650 ] scmbus C:\Windows\system32\drivers\scmbus.sys
15:15:27.0382 0x2a20 scmbus - ok
15:15:27.0389 0x2a20 [ 6C6FAAB1BC8D63BF8CB6B5EFCEF4E351, D2AF0A5B3C4BBC4FD19D96D111FB1A694483E91B926C9BC093C114B94BE42CBC ] SCPolicySvc C:\Windows\System32\certprop.dll
15:15:27.0407 0x2a20 SCPolicySvc - ok
15:15:27.0417 0x2a20 [ 495273177E87B0C34D7E431E9254FA23, 61116DA77622F5A0E931F5033C1B870A22AD3438C056FD1F320F857908E4124B ] sdbus C:\Windows\System32\drivers\sdbus.sys
15:15:27.0433 0x2a20 sdbus - ok
15:15:27.0438 0x2a20 [ 9EF09DE84CE20B787C02395394AC2A7E, 17019B74506D26707EBC342365008A9BB5AACA381FB60ABA85F34D153FB0682C ] SDFRd C:\Windows\System32\drivers\SDFRd.sys
15:15:27.0448 0x2a20 SDFRd - ok
15:15:27.0454 0x2a20 [ 01607A2FAB0068450A06C90AF755D57E, 9615261063475045CBC99F17BD3A4919198D0F77CA9E4EC7B13826E514BC8543 ] SDRSVC C:\Windows\System32\SDRSVC.dll
15:15:27.0474 0x2a20 SDRSVC - ok
15:15:27.0479 0x2a20 [ F80D6C03FEA2F7DEE14023B7229DA8C2, B62AFCFCDE9C1BA0A5D80BAAC3D3D95546DB2E532C04C765FF85B27D1CBD5B8D ] sdstor C:\Windows\System32\drivers\sdstor.sys
15:15:27.0490 0x2a20 sdstor - ok
15:15:27.0495 0x2a20 [ 5514DB4DAC7A99CA9F9EF697951BF2F0, 92EB28F543D0A5BF3F53C2638C12B25EA35A3B7329AD87E19A49612333262002 ] seclogon C:\Windows\system32\seclogon.dll
15:15:27.0513 0x2a20 seclogon - ok
15:15:27.0530 0x2a20 [ 0F67F777705C6DC33FFE0FF459762957, 16BE999DCEC6C2C4F799025ACBFDE04CCE66B39160B6186A00F4BCFA2A1E41AA ] SecurityHealthService C:\Windows\system32\SecurityHealthService.exe
15:15:27.0559 0x2a20 SecurityHealthService - ok
15:15:27.0569 0x2a20 [ 271E64A1E7FFFEC74DEB31BA99842A25, B4300129F80FA484BB83181F1B970143D167DA528849BBC0FD02EF0F0E103CD7 ] sedsvc C:\Program Files\rempl\sedsvc.exe
15:15:27.0588 0x2a20 sedsvc - ok
15:15:27.0614 0x2a20 [ 7D7ED932B6417D8687D1D972989B310B, A5DF3B6CEE97DD110FD1BC542CC5A5313B2F447E5FCC40DF6EFB9D7D49CD792C ] SEMgrSvc C:\Windows\system32\SEMgrSvc.dll
15:15:27.0676 0x2a20 SEMgrSvc - ok
15:15:27.0683 0x2a20 [ CA614C9FBC8307AB1DC937F3393899E2, 4833CC631FA30E4D4B45BBC2CE41DE72B332B6A1FFD23B7DBFD6EDD6BC1A2ED8 ] SENS C:\Windows\System32\sens.dll
15:15:27.0702 0x2a20 SENS - ok
15:15:27.0705 0x2a20 Sense - ok
15:15:27.0732 0x2a20 [ 46AEFFC68BEAF89805B95CC6F9529C2E, 7A6A38A329E82F684191561479604142BBB35121822A5CDD828819C606F2A60A ] SensorDataService C:\Windows\System32\SensorDataService.exe
15:15:27.0785 0x2a20 SensorDataService - ok
15:15:27.0802 0x2a20 [ 2B81117E9C3E20BBAA2CB5467D000F77, AC0DF8E635908026EE43EE0444DEF61481E211737A85A473D64EC8BB214D1135 ] SensorService C:\Windows\system32\SensorService.dll
15:15:27.0838 0x2a20 SensorService - ok
15:15:27.0846 0x2a20 [ D093B7A8E73850F0D5FDA3AB37D7A267, 0B7E2DF6C6746856701812E5D010EDB2B82166A3F3561405F547B58F442C6837 ] SensrSvc C:\Windows\system32\sensrsvc.dll
15:15:27.0868 0x2a20 SensrSvc - ok
15:15:27.0873 0x2a20 [ C5CF2941AA9E417B3A224601255C002E, 31E2988E13D9BB3630980E8B71AE5FB244EFB15970623C1FE76B7ACA25A4A2F2 ] SerCx C:\Windows\system32\drivers\SerCx.sys
15:15:27.0886 0x2a20 SerCx - ok
15:15:27.0893 0x2a20 [ B9C113BD9FCA4F3E23F03708A7DA07CC, 0A070BDDA956B1869D58A173B56ABA011E1F7A3C5D258343D0AEDC1EC87F4B53 ] SerCx2 C:\Windows\system32\drivers\SerCx2.sys
15:15:27.0908 0x2a20 SerCx2 - ok
15:15:27.0912 0x2a20 [ 1845736FA47A1DFBBB642FE21095B4E0, 057E8750E8695F6B72A33BBF1C5CFCCD6BFC992E6B99A487A07F5A4921004791 ] Serenum C:\Windows\System32\drivers\serenum.sys
15:15:27.0927 0x2a20 Serenum - ok
15:15:27.0933 0x2a20 [ F1BABF50469041797ED9928C31318832, 1A8C75F4696D4D2AA47EA33BC96069A394466953EBC3CFB2B3D6B961B8B5875A ] Serial C:\Windows\System32\drivers\serial.sys
15:15:27.0950 0x2a20 Serial - ok
15:15:27.0954 0x2a20 [ 340116988930B07629A2D0C2B380A365, EBAAC3DF2E8DABFB477340E79FC8E3A8B74340C389D73E51D64A97A332664113 ] sermouse C:\Windows\System32\drivers\sermouse.sys
15:15:27.0971 0x2a20 sermouse - ok
15:15:27.0987 0x2a20 [ 87340BC77470B34F11A9E558B591DB08, FD91561FE5951B4F59FEE23707E1ACE31293E508EF734A5CDB0F34D332EFDDF7 ] SessionEnv C:\Windows\system32\sessenv.dll
15:15:28.0018 0x2a20 SessionEnv - ok
15:15:28.0023 0x2a20 [ 77FF0A5BA023D8E8C82EACCD54EA5C78, A4A88A550419C347E369DDD29D4EB5C1BC4D980FBA9C655DF787A166FCA2497D ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
15:15:28.0036 0x2a20 sfloppy - ok
15:15:28.0041 0x2a20 [ 1941F5CA54C469E16957587FD56ED842, D356547A9702A50AEB5F7765AC44668EEA913563A422ABBD0427EC22833A5B78 ] SgrmAgent C:\Windows\system32\drivers\SgrmAgent.sys
15:15:28.0053 0x2a20 SgrmAgent - ok
15:15:28.0060 0x2a20 [ D3170A3F3A9626597EEE1888686E3EA6, 9321991C441B095DF15D24C8AE58F87EE5A3242532E8C023D0F78B2F96FEE6B7 ] SgrmBroker C:\Windows\system32\SgrmBroker.exe
15:15:28.0076 0x2a20 SgrmBroker - ok
15:15:28.0090 0x2a20 [ AC1D97F89F2EC7E334A406603A686973, D230059C1CB400CCA62438603356F058B40E17DE4C7BD4DADDBB981E4F5E4C9C ] SharedAccess C:\Windows\System32\ipnathlp.dll
15:15:28.0122 0x2a20 SharedAccess - ok
15:15:28.0139 0x2a20 [ 7C5348D398340B5C2A77543FA966C0D3, E111E2AB4DA47C7A15797DDA2499EF93D26BB0D9103EAAF81A244C9545FC10B4 ] SharedRealitySvc C:\Windows\System32\SharedRealitySvc.dll
15:15:28.0175 0x2a20 SharedRealitySvc - ok
15:15:28.0191 0x2a20 [ 63B104867F70F0D81125C37989146960, 468431098DD9B91F1C58551CEB4DBE6E1C456FFE845E302571B970EF05AE03A8 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
15:15:28.0236 0x2a20 ShellHWDetection - ok
15:15:28.0244 0x2a20 [ F6D90D09D2BCFA2B5E492BFECA40EDE4, 7B427335943C1EFDE482D59F3A23149FCD45BB014643BEF620A708720383C4A8 ] shpamsvc C:\Windows\system32\Windows.SharedPC.AccountManager.dll
15:15:28.0265 0x2a20 shpamsvc - ok
15:15:28.0270 0x2a20 [ 1443CF919C2A3207CE7724E0A31686A2, 3F0ECC565F67638A57A23BF69C399AD638DA9F81F1660CF3E027DC057E990EA4 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
15:15:28.0281 0x2a20 SiSRaid2 - ok
15:15:28.0287 0x2a20 [ C0B1EAD6CC127CAE4E84EBF54105B3B8, 86F5C937D9DC61F262FF00B45249162F4087B6A1CA0FC24EF7950E4E77FEF26B ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
15:15:28.0299 0x2a20 SiSRaid4 - ok
15:15:28.0306 0x2a20 [ 7DDE76ABF8C7E92252343340FFC9C0D8, D0862F24B81904D15D96A403877192042771E113971102BE6B6747A5B80AB141 ] smbdirect C:\Windows\system32\DRIVERS\smbdirect.sys
15:15:28.0324 0x2a20 smbdirect - ok
15:15:28.0330 0x2a20 [ B7C6144293CFAD2DEDCD022C44735DC2, 75F26A8F43EED45764D50B2CCE44C453BFBBD0FA56B6AF1F2B4B8B3665C3961E ] smphost C:\Windows\System32\smphost.dll
15:15:28.0346 0x2a20 smphost - ok
15:15:28.0360 0x2a20 [ A3BEF2736E902B9DCA68554F4E10E08C, 5C7590D8F2D637B6D4A5F68945D8350B1C3D48EBE1B2C36658361900C9425611 ] SmsRouter C:\Windows\system32\SmsRouterSvc.dll
15:15:28.0392 0x2a20 SmsRouter - ok
15:15:28.0401 0x2a20 [ 577EC13EB5215325E9B9FC51FB56A974, 1D7A0245A3C474BCD4EC69704040FB50C0E086DB1711C5B7FC4D9C4A7909DAB9 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
15:15:28.0419 0x2a20 SNMPTRAP - ok
15:15:28.0434 0x2a20 [ FF44BF888D6F8046FD4FCBF96A5FCE65, D79A33B45D8926415E614D2B2709360B9749086FC3C7D9E29E15E4BB0235550E ] spaceport C:\Windows\system32\drivers\spaceport.sys
15:15:28.0457 0x2a20 spaceport - ok
15:15:28.0463 0x2a20 [ FE1776E587227120DC04EAEC45473245, 9DEBD997D275065481EEEDD2310479F2021D53B64AA6D5CEEA70E9BB8C9856C7 ] SpatialGraphFilter C:\Windows\system32\drivers\SpatialGraphFilter.sys
15:15:28.0474 0x2a20 SpatialGraphFilter - ok
15:15:28.0480 0x2a20 [ D05EB2BB52EC6B665D1631EC33241B80, 29598FC180020515254A9FAE7BE8077549C656EDB425059691007EEC0F9346F9 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
15:15:28.0492 0x2a20 SpbCx - ok
15:15:28.0516 0x2a20 [ 52A4B8C04C345434C974B9A949521BAE, 5FAA7E1BECD6FA28E4BA53E9B3301328B6E8516867BD7D76202A73B8CD530BC5 ] spectrum C:\Windows\system32\spectrum.exe
15:15:28.0558 0x2a20 spectrum - ok
15:15:28.0575 0x2a20 [ C05A19A38D7D203B738771FD1854656F, 3A832F3CBA33682EAA18ABB721BF2D5A6FE9AC853038C684C264700DEB52AA65 ] Spooler C:\Windows\System32\spoolsv.exe
15:15:28.0613 0x2a20 Spooler - ok
15:15:28.0691 0x2a20 [ 2D089EFC02200382A6A0597801FF3B37, 0170CFD41CE0DA2589B504C69C898140BB75B7E68CBE67867B787B8097EDCF99 ] sppsvc C:\Windows\system32\sppsvc.exe
15:15:28.0794 0x2a20 sppsvc - ok
15:15:28.0804 0x2a20 [ E8276BE984738AA44070CFDE6EFC9300, F0B09D3E08BDB1B8AEBA97A700271E97AB2506793B42D96415B23DB68DA99FA8 ] SQLWriter C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
15:15:28.0816 0x2a20 SQLWriter - ok
15:15:28.0833 0x2a20 [ D9EFD1D7829994F16141DA4FB6ACAABC, 513C5446DAEA4797049E052E95CBB798DCD8D457A8D8F4999741261150BCDE3B ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
15:15:28.0867 0x2a20 srv2 - ok
15:15:28.0876 0x2a20 [ 93DF24D0C33F2894429D4180145CBDA7, 763F05818AD5F348887C297FA14FB77B6F54B9A5C3C1D70CF2B7B0692961950C ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
15:15:28.0897 0x2a20 srvnet - ok
15:15:28.0906 0x2a20 [ 1AEA66706573E8CCD6038369FE37F237, A62CAFE205D5B4C9F8528EDDA4E20BA4E2D1E231F2B183FE70EFE6458B2D5460 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
15:15:28.0927 0x2a20 SSDPSRV - ok
15:15:28.0940 0x2a20 [ 5EE518DFADC18573E681BB78833E93FA, E98CCD3E2ADA265D6E3CF48CDBFE5C3067E0546F179F23B77C267F65CEB978EE ] ssh-agent C:\Windows\System32\OpenSSH\ssh-agent.exe
15:15:28.0970 0x2a20 ssh-agent - ok
15:15:28.0978 0x2a20 [ C7DF51E24DD853E7E2D3C0BCDCE57D6C, D1BFDC89F00C5B8388EB233290B6D540C246D0267B1C192C51645004A8CD8C62 ] SstpSvc C:\Windows\system32\sstpsvc.dll
15:15:28.0999 0x2a20 SstpSvc - ok
15:15:29.0088 0x2a20 [ B9E4174DFBDCA9979A92D17C2E67890E, 1717A6B7CADDDFCA8879B293C29617E194437E049308BCEDF3D07007C41FE39F ] StateRepository C:\Windows\system32\windows.staterepository.dll
15:15:29.0203 0x2a20 StateRepository - ok
15:15:29.0240 0x2a20 [ E4724564ABC4D34E2FD85907781BF95B, E3C440B87825E4F3E6F8812C6202D1B9EBD453DF97269911AC94B0EFD38CC116 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
15:15:29.0293 0x2a20 Steam Client Service - detected UnsignedFile.Multi.Generic ( 1 )
15:15:29.0359 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:29.0360 0x2a20 Steam Client Service ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:29.0360 0x2a20 Force sending object to P2P due to detect: Steam Client Service
15:15:29.0528 0x2a20 Object send P2P result: true
15:15:29.0671 0x2a20 [ DA82903F26AE12034CC5229F61098948, E7B5CA27C864BE95EC109D0692F44BE9F5F56AB6173AB1811F4E83A3EB5F26CA ] stexstor C:\Windows\system32\drivers\stexstor.sys
15:15:29.0695 0x2a20 stexstor - ok
15:15:29.0715 0x2a20 [ EB2C25A3700309F3F67D9334CF33A36C, 9262778566EEEA810AD32CD660DEA841797BD9F874252CC5445D917FF159280B ] stisvc C:\Windows\System32\wiaservc.dll
15:15:29.0749 0x2a20 stisvc - ok
15:15:29.0757 0x2a20 [ F2D1983C7BEF5E3AB8978A7796C59A75, 39B2005F7CCEC95D2F67AE5F69C3768FEFA04AABC0723BAD8A986A036AF0629B ] storahci C:\Windows\system32\drivers\storahci.sys
15:15:29.0771 0x2a20 storahci - ok
15:15:29.0776 0x2a20 [ 76C9E2AA3400C22FC7091AD2F2999F95, 0015CF42CBA603448DFD85909D5047D5F9BE9153972C3832B1CF4B92A6BF0D01 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
15:15:29.0788 0x2a20 storflt - ok
15:15:29.0794 0x2a20 [ 701078F20919BD635EA25F691880F651, 6D56027007EF92A72C20B9B8024FDD96E03E2B8746F39D57BD1F7CAD2FC80DB2 ] stornvme C:\Windows\system32\drivers\stornvme.sys
15:15:29.0807 0x2a20 stornvme - ok
15:15:29.0812 0x2a20 [ 16CEC85543981EE1D01978C210462993, 7627CDD01ECEEA378A88C73F0ABD49AE559B365B8D8D69A75CA8D6EC3F54A249 ] storqosflt C:\Windows\system32\drivers\storqosflt.sys
15:15:29.0827 0x2a20 storqosflt - ok
15:15:29.0848 0x2a20 [ DEA7BB6D3724F2FD9E61ED085E69DFA7, 5047F184894E79C31739D3C9632E43E8D2ABD70AA674DE82D6D2D0FDA137BF3F ] StorSvc C:\Windows\system32\storsvc.dll
15:15:29.0892 0x2a20 StorSvc - ok
15:15:29.0898 0x2a20 [ 25D7B79F80F3C2CD97D797C14D470165, 5425F98A66741BB2BC7BDC8B21C3AF859A503596D983010883BF5BE4FD999D9D ] storufs C:\Windows\system32\drivers\storufs.sys
15:15:29.0910 0x2a20 storufs - ok
15:15:29.0915 0x2a20 [ 1FC7B7BE58A29DF27F5E6F6C2F061FA3, D8CD6D1BD0ACA4B851DBC85F898CB5DA8715C5AB3D62D7B0D6BBFEADC0382A8E ] storvsc C:\Windows\system32\drivers\storvsc.sys
15:15:29.0926 0x2a20 storvsc - ok
15:15:29.0931 0x2a20 [ 0B154B033AD7F9215DED11E0CFC80A25, 383D7BF361D75A3B78E4C8E3F616E487FA6172F860AE364B1AC73F75BE38944F ] svsvc C:\Windows\system32\svsvc.dll
15:15:29.0949 0x2a20 svsvc - ok
15:15:29.0962 0x2a20 [ 54255DF324C621A97220EBFA832237D2, 27BAB2018BE66C67D6C2BBAA8E849E89B4150B8C81E7350DB0A1D14BEEB965D9 ] swenum C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_ea7b19c04e7a8136\swenum.sys
15:15:29.0972 0x2a20 swenum - ok
15:15:29.0984 0x2a20 [ B3C113C9B784A4D296C7A7BA515F74BF, 0D20281B8AA9ED6C89E10122F3A153C2E21464686E5A3D2F907224584E6B5BCF ] swprv C:\Windows\System32\swprv.dll
15:15:30.0014 0x2a20 swprv - ok
15:15:30.0020 0x2a20 [ A2A42A570524C975259E3B81C4D80DCA, 4B2A6295E46DD2042B3C741D9519A0376687B30711F2DA8B9B81A039E46229F9 ] Synth3dVsc C:\Windows\System32\drivers\Synth3dVsc.sys
15:15:30.0035 0x2a20 Synth3dVsc - ok
15:15:30.0056 0x2a20 [ A8D839012996A00F3071116C529FF5D5, 9C2828C8F645F9F44B65FAC50CACD7D2699634059585DDE84D11C7F06F244060 ] SysMain C:\Windows\system32\sysmain.dll
15:15:30.0098 0x2a20 SysMain - ok
15:15:30.0108 0x2a20 [ 93851A044CE51AB4D6A92ED783B3DDE7, 5E4BB31C5A15C3E6E31C64AD65B513D8A92475393F62EED76056EDC805E8F283 ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
15:15:30.0131 0x2a20 SystemEventsBroker - ok
15:15:30.0139 0x2a20 [ CE9975A9E0DFBEFECECE218D2674C1CD, 20ABA9B78FF40C89A757ED2B4AE2F8BE5F4C6C257AA00A324849D68ACA59A264 ] TabletInputService C:\Windows\System32\TabSvc.dll
15:15:30.0163 0x2a20 TabletInputService - ok
15:15:30.0168 0x2a20 [ 877F60F3BCF2E40D8D65E8616EAD7217, F8FD628CE0F2EB7D2245F2EDEFE1889F61912826EAE1A35089C1C31ECC5806E2 ] tapexpressvpn C:\Windows\System32\drivers\tapexpressvpn.sys
15:15:30.0179 0x2a20 tapexpressvpn - ok
15:15:30.0189 0x2a20 [ E38C7C4D57B1438F70A1B913870E8665, EEBE640E31F3D9126FD2F58EB93051FE4EEA591223DFAB9E918DEBE879718B95 ] TapiSrv C:\Windows\System32\tapisrv.dll
15:15:30.0215 0x2a20 TapiSrv - ok
15:15:30.0220 0x2a20 [ 1960E9FD4082A0170FBA0231FD709113, D5854811787EBC979E9FAB02847F1E662F430A06AB2D3CB9F0EE4BB3A9EC56FE ] tapprotonvpn C:\Windows\System32\drivers\tapprotonvpn.sys
15:15:30.0234 0x2a20 tapprotonvpn - ok
15:15:30.0284 0x2a20 [ B8BED15865E17E73CF19A23CD6EB9FB7, A5CA2B4E00F8F681C7FD9BA5BA3DB3A95E9E4CD785C0FC85A24E9C481EBE08E6 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
15:15:30.0349 0x2a20 Tcpip - ok
15:15:30.0401 0x2a20 [ B8BED15865E17E73CF19A23CD6EB9FB7, A5CA2B4E00F8F681C7FD9BA5BA3DB3A95E9E4CD785C0FC85A24E9C481EBE08E6 ] Tcpip6 C:\Windows\system32\drivers\tcpip.sys
15:15:30.0467 0x2a20 Tcpip6 - ok
15:15:30.0477 0x2a20 [ 085F8A5F09E64CC27309AF160EF4F9BA, DB3DFD3059836A9FB26FE924E9F2B960E454F4B20D8862266DFDA3168D610FD8 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
15:15:30.0493 0x2a20 tcpipreg - ok
15:15:30.0501 0x2a20 [ 16071C42E21CE3378FA449322FB9AB1D, 44CA7FD91275546492EEF0A59261E2B1C924613515D45EFD2EF0442023B2CBE5 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
15:15:30.0514 0x2a20 tdx - ok
15:15:30.0520 0x2a20 [ B2C4D7CB291293CAC636748E695D111E, 5E0AA8147EFDA5D21CEE8AE254F74A974B0ADAF298F569CAA73AC4E3B758438A ] terminpt C:\Windows\System32\drivers\terminpt.sys
15:15:30.0531 0x2a20 terminpt - ok
15:15:30.0554 0x2a20 [ 10ADC3589E50B1ED8452C86E0CBE8248, BE82341A12EA83D9EFADC9AC35CF16D327F8499C99107DCDE88DD0F5DF84523C ] TermService C:\Windows\System32\termsrv.dll
15:15:30.0597 0x2a20 TermService - ok
15:15:30.0603 0x2a20 [ 1A0A0F6A139148AFDC4622046D4B3CBD, 8FC2FB99B70A3A5B2F1D757A2F0E3085B1D242B792A35070E1DB3871A275329E ] Themes C:\Windows\system32\themeservice.dll
15:15:30.0623 0x2a20 Themes - ok
15:15:30.0632 0x2a20 [ 811910E891A6DB4A864AE119EB71218C, 2CBB6159E2ACAE4BA73892A4F7F8A3981C159083C29F1A1D548C59FB713B9D74 ] TieringEngineService C:\Windows\system32\TieringEngineService.exe
15:15:30.0659 0x2a20 TieringEngineService - ok
15:15:30.0667 0x2a20 [ 8BF5E2FD72E939CF68D617E273034793, EE27D070E1C4EFE902BE173C5561F5601499F835762278CC1E5987886BD8A4D1 ] TimeBrokerSvc C:\Windows\System32\TimeBrokerServer.dll
15:15:30.0689 0x2a20 TimeBrokerSvc - ok
15:15:30.0717 0x2a20 [ 5431EB746C6D993C3758389EF297CB01, 36F60AF80379B3F0DDDBBB6A20F45712502BDDF1192F792C78733F6AF465371A ] TokenBroker C:\Windows\System32\TokenBroker.dll
15:15:30.0770 0x2a20 TokenBroker - ok
15:15:30.0780 0x2a20 [ 330F5AA122A302F0244D918B9C92C9D1, 62D513B7357AC8CFC649BCEB4EB682B7493219957A1264BAD4E5C26086BD8F3D ] TPM C:\Windows\System32\drivers\tpm.sys
15:15:30.0796 0x2a20 TPM - ok
15:15:30.0802 0x2a20 [ A5C0F857C38278A90E953A24E1701196, 1A646E47013946CCE41C798A494C6D266AEFC8A8D6EB65CD8848E72106687E38 ] TrkWks C:\Windows\System32\trkwks.dll
15:15:30.0820 0x2a20 TrkWks - ok
15:15:30.0826 0x2a20 [ 4578046C54A954C917BB393B70BA0AEB, 2DFE9DE656B415CF7D81F583F33A20A74CD54C07DB8C3196AA2102431F42F74F ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
15:15:30.0845 0x2a20 TrustedInstaller - ok
15:15:30.0853 0x2a20 [ 0D721F40C179EC5737C15E551F22C69B, BBA04E11C3D9150C60F74D8B1A3F444BDE0C19857BB7C45D58448F641082DE1A ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
15:15:30.0868 0x2a20 TsUsbFlt - ok
15:15:30.0873 0x2a20 [ DE1296871208D1F13B7AC57C4B1FA46C, D18709F65E372A47AE114ECFD6A45E6736089B4A8E719E2FB5D831D9415E995D ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
15:15:30.0886 0x2a20 TsUsbGD - ok
15:15:30.0892 0x2a20 [ 3A84A09CBC42148A0C7D00B3E82517F1, 75E609AC991C96E31F55E723925EAF9A363DC5B3324FFD4CFCB701189369D701 ] tsusbhub C:\Windows\system32\drivers\tsusbhub.sys
15:15:30.0909 0x2a20 tsusbhub - ok
15:15:30.0916 0x2a20 [ BC938ABBF586272BD4063CA51F09149F, 06EB662948D212ACDF930C3CD01C6381A6FB152AC0F1628C86764F0973ABA1CB ] tunnel C:\Windows\system32\drivers\tunnel.sys
15:15:30.0933 0x2a20 tunnel - ok
15:15:30.0939 0x2a20 [ 7F7686C491FD783D42BF70DF8FCC4461, 18C6BE5AD93A8A46862A0AC5E0FD2301178E41CC581926BD9B77D1EBC8A0985C ] tzautoupdate C:\Windows\system32\tzautoupdate.dll
15:15:30.0956 0x2a20 tzautoupdate - ok
15:15:30.0962 0x2a20 [ BDFACE024EFF2398214797143AD76C87, EF9B6CB1F6EAE4786BBDE1E0946BECC5BD2AA493FC32A8F779A757BA57238EC9 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
15:15:30.0975 0x2a20 UASPStor - ok
15:15:30.0982 0x2a20 [ 00C4396DE1CD3502884BB2E2B6D6861C, 39F6BF25096ACE29CAF964DCA15078F47986F645DF49FB502A2CDF2C05C89AAB ] UcmCx0101 C:\Windows\system32\Drivers\UcmCx.sys
15:15:31.0000 0x2a20 UcmCx0101 - ok
15:15:31.0007 0x2a20 [ ED9CBD1541C8AFDAA9B8255A384E2B53, D970F5E976CEBE0BCDF07B9E155EDB5B3C225812991779748CD04A9C4852DF3D ] UcmTcpciCx0101 C:\Windows\system32\Drivers\UcmTcpciCx.sys
15:15:31.0027 0x2a20 UcmTcpciCx0101 - ok
15:15:31.0033 0x2a20 [ F58F1BC6A6972437CE18516F8ACCEB9F, 2C619D1E2E80662FA463EE48E3D41C8437A81B0F68EE67A0839A93DEDCD2E0B2 ] UcmUcsi C:\Windows\System32\drivers\UcmUcsi.sys
15:15:31.0049 0x2a20 UcmUcsi - ok
15:15:31.0057 0x2a20 [ 017FB9532F54B28EFC1E37A91DB9ECC5, B753A114C644E57E3A4754836F29A6974BAADE547D3114D783070E7CDAA7CE1D ] Ucx01000 C:\Windows\system32\drivers\ucx01000.sys
15:15:31.0073 0x2a20 Ucx01000 - ok
15:15:31.0078 0x2a20 [ 12E2B6B642360E66396502B62B048694, C9AC86BF767ED4ACE0F58BA3720369A2758BA154AFFE10CAAD5A2C4C259BA50A ] UdeCx C:\Windows\system32\drivers\udecx.sys
15:15:31.0093 0x2a20 UdeCx - ok
15:15:31.0103 0x2a20 [ 6A442723D4D05D9F15D24C9942CDA00D, 4A60D6CF7214A3891877AC6E5A49AE49D056567162D6355C0D893510F0241DA7 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
15:15:31.0126 0x2a20 udfs - ok
15:15:31.0132 0x2a20 [ D30AF38971B6670C222250AC2CBB6227, 52C1C7AC29D06C701DA0E2772294CED0C1790EC7FCBD5074238B54BEB951E9D0 ] UEFI C:\Windows\System32\drivers\UEFI.sys
15:15:31.0143 0x2a20 UEFI - ok
15:15:31.0149 0x2a20 [ AD58EA78772B8163CFDE9BF671B6F8F1, E8304179B6B52B143846AEF80C7B2D577125742EA2DFF09F8AC5F37F4E28793E ] UevAgentDriver C:\Windows\system32\drivers\UevAgentDriver.sys
15:15:31.0160 0x2a20 UevAgentDriver - ok
15:15:31.0184 0x2a20 [ F7E36C20DB953DFF4FDDB817904C0E48, 2C5EDE0807D8A5EC4B6E0FE0C308B37DBBDE12714FD9ADC4CE3EF4E0A5692207 ] UevAgentService C:\Windows\system32\AgentService.exe
15:15:31.0231 0x2a20 UevAgentService - ok
15:15:31.0242 0x2a20 [ 588B9212DEE84F5192C09A147AA5C316, 80C70FD489D72015FCF8AFBE649F6C77F40B613882A1F031A2DAE088B9B4F67B ] Ufx01000 C:\Windows\system32\drivers\ufx01000.sys
15:15:31.0258 0x2a20 Ufx01000 - ok
15:15:31.0265 0x2a20 [ 78B5C069C9AA1463ACC833FD7E2A3BD5, A44BAB6AB5E071537BD37A26DAF6D0D69BBFFFF686C183BFAAB04286DD3B81BB ] UfxChipidea C:\Windows\System32\drivers\UfxChipidea.sys
15:15:31.0277 0x2a20 UfxChipidea - ok
15:15:31.0285 0x2a20 [ 533BF4F456A1C6E7581E8C0A4EC59300, E5AE7EB4A8E6CE410F465C48F102797806172B5881C2CF570A9851CCDFE656FD ] ufxsynopsys C:\Windows\System32\drivers\ufxsynopsys.sys
15:15:31.0298 0x2a20 ufxsynopsys - ok
15:15:31.0308 0x2a20 [ 360FEE6F687D98EFFE46A5433FE6182E, 1A35569DC29F45F78D705BCEDE850CAF86FD27D6253977497EB3B000CAAE0B27 ] umbus C:\Windows\System32\drivers\umbus.sys
15:15:31.0323 0x2a20 umbus - ok
15:15:31.0328 0x2a20 [ F6F1A9D91F684AA02951B96EE8127DAE, 351139331041BC123C9FEE3A5CE4965AFC4CDCA488080338D98C5EB85D5843D4 ] UmPass C:\Windows\System32\drivers\umpass.sys
15:15:31.0343 0x2a20 UmPass - ok
15:15:31.0354 0x2a20 [ 0D806415E1F86E7C1C192261C247EF0D, 640CB73D9ACC3B6E0F2A2A5A4587375F05A7519081BEC510B926A8A4A496C3B9 ] UmRdpService C:\Windows\System32\umrdp.dll
15:15:31.0379 0x2a20 UmRdpService - ok
15:15:31.0404 0x2a20 [ EAEC69961D9D8B39FEA44D56F7FB259D, 43FEB15A32B353B6F3C8E5F1072FF9507F2FA7799A414F30FEA0B8C47999D969 ] UnistoreSvc C:\Windows\System32\unistore.dll
15:15:31.0455 0x2a20 UnistoreSvc - ok
15:15:31.0471 0x2a20 [ 2362D5C18120FAB9CE5BD1F73EE33758, D9AB5D5BEAF95F62A204CE8A3B8B3B6C9C1E85FB5425CA2AADCBB4770EDCDF30 ] upnphost C:\Windows\System32\upnphost.dll
15:15:31.0499 0x2a20 upnphost - ok
15:15:31.0505 0x2a20 [ 49A5E1B43C59DC0E363AD9C2D7D10BE4, B903C1C24DAF316AF9D8C1770687DE0A24ACDA4EFE47845E13BE99985609B7CE ] UrsChipidea C:\Windows\System32\drivers\urschipidea.sys
15:15:31.0516 0x2a20 UrsChipidea - ok
15:15:31.0521 0x2a20 [ 53F1DA2D92D1D8CE4BB9D33E58D7DF01, CD3F4B92EDA042FE696C59D67BEB711C7AF0EB5979AD5F4110297C47454EBBFA ] UrsCx01000 C:\Windows\system32\drivers\urscx01000.sys
15:15:31.0532 0x2a20 UrsCx01000 - ok
15:15:31.0537 0x2a20 [ 09518A324B95BBC0B472BD5A472CB916, B3C6BF8C84268C02CC43E5C6B37648F9691B6038D275F4BEBA7B5E9ECA046181 ] UrsSynopsys C:\Windows\System32\drivers\urssynopsys.sys
15:15:31.0547 0x2a20 UrsSynopsys - ok
15:15:31.0554 0x2a20 [ C7AD46F101A681B0F4D7F15534A5FF04, 20380A613A3E476A6282BC642534328AC35E24A03D34D6A2DF1C5468912C72D7 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
15:15:31.0572 0x2a20 usbaudio - ok
15:15:31.0579 0x2a20 [ B7211393225AB05324C52BA47B31FEB4, 3FFB7F1C1CA5001B95026D30ECD1991747DDAFFBE3B4929CAEDFA90E169A28AE ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
15:15:31.0593 0x2a20 usbccgp - ok
15:15:31.0600 0x2a20 [ 250D21958EE5F45CD13FE6BE3788EE70, C0EF097EE2ED91950BD3A6881AB08698E85C4ABABC4F7520F7E92E70CA454D4E ] usbcir C:\Windows\System32\drivers\usbcir.sys
15:15:31.0615 0x2a20 usbcir - ok
15:15:31.0621 0x2a20 [ 4269DE1EB8029D55B3BB3A8A330FCF90, 5D9081A07F91AF704D27EEE60516D6E1E0A106D1656CEF0C5C50E51C23E17F61 ] usbehci C:\Windows\System32\drivers\usbehci.sys
15:15:31.0634 0x2a20 usbehci - ok
15:15:31.0648 0x2a20 [ D67AABAE0C9EBAC9BBA2E20E0AF52EF1, FE51895BB81E5320F66C433378469092D39F325D310543AFE28A5603FA9B4F08 ] usbhub C:\Windows\System32\drivers\usbhub.sys
15:15:31.0669 0x2a20 usbhub - ok
15:15:31.0684 0x2a20 [ 95A5A70091854B99C09A4231E5050C65, 4313CD94624A9F81B1C4334F37792A9FD35718143EB0CACE0969E02BB858D452 ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
15:15:31.0706 0x2a20 USBHUB3 - ok
15:15:31.0712 0x2a20 [ A547E7B1B3FB2228259AA85AC7E82698, AB18BBE30A2D149A0E10621DC8497A72DFB841B09F4E4B47FED21843C0F88D92 ] usbohci C:\Windows\System32\drivers\usbohci.sys
15:15:31.0728 0x2a20 usbohci - ok
15:15:31.0733 0x2a20 [ 692C0BA4109C8F78392A299369F51129, A675E11CD4794693D0B65A06E85F264199506A4C6EDBB68503163EED389B8D1F ] usbprint C:\Windows\System32\drivers\usbprint.sys
15:15:31.0746 0x2a20 usbprint - ok
15:15:31.0752 0x2a20 [ 555DE99E30E6A6EF37137F8325B30068, B78B44883A3E524DFEC13B72AFFDF06FD446EFB12061593D8247C0B92D558B8A ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
15:15:31.0767 0x2a20 usbscan - ok
15:15:31.0773 0x2a20 [ 45A9E57185B79420EFEA5A4AED655809, 91D4BDBBAF1D06C404AC926357C3F20D780CF5C858B223930D69CFB17D81F3D3 ] usbser C:\Windows\System32\drivers\usbser.sys
15:15:31.0788 0x2a20 usbser - ok
15:15:31.0795 0x2a20 [ CEF7527514EC49EBE0C760D784643EF0, 2A4E49C5C906339C31F0A646E53773297F4B4CEAFD94CE653C37556AE243E104 ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
15:15:31.0808 0x2a20 USBSTOR - ok
15:15:31.0813 0x2a20 [ A4124036C4FD2B94C6157C4588EEB4E3, 595C8BFB5E63AEA2F7DF2745F7C7CE45938B091470C921E3064E766A0E12851F ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
15:15:31.0829 0x2a20 usbuhci - ok
15:15:31.0841 0x2a20 [ 9F4CCFCD4B4C6008C940510E43D54AEC, CD6082E95EBA618490A2A97E258875440B3440E721B21E81608804B90DEF0D20 ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
15:15:31.0861 0x2a20 USBXHCI - ok
15:15:31.0890 0x2a20 [ CE0E3BA8FC974BEE5BE20E4F43A1C583, E19DE81559FD92D1F7B0ADB4297926E6971F7FCB642E11758D361FC2A22C33BB ] UserDataSvc C:\Windows\System32\userdataservice.dll
15:15:31.0948 0x2a20 UserDataSvc - ok
15:15:31.0974 0x2a20 [ B8D1D74FEF1F190BA4DA7E7A72D5D9CE, F467F39EE09DDC7750BF42C3FF317E0DC324897589268B4C7B63F8E176445820 ] UserManager C:\Windows\System32\usermgr.dll
15:15:32.0019 0x2a20 UserManager - ok
15:15:32.0048 0x2a20 [ C07A5BC1CD6C8C2ED474B9DCED6E785C, 4D723B16C2B450D042E0C0FB1864385AB04D4F15BEDC7C90F360A3C79ADE6548 ] UsoSvc C:\Windows\system32\usocore.dll
15:15:32.0103 0x2a20 UsoSvc - ok
15:15:32.0116 0x2a20 [ 3E283D06357616CD4117CC15BDB7C4C3, ACE50702EE61C9F93855720037898F19E509D45982F9173643EDA455F54FB9E7 ] VacSvc C:\Windows\System32\vac.dll
15:15:32.0136 0x2a20 VacSvc - ok
15:15:32.0142 0x2a20 [ 3DF3B76B19DA92A8ADC01FF38560282D, F56DDDF7A8F1AA0F3D9FFE0CD618544CFAF233A33314240ECCBE5F897A91B534 ] VaultSvc C:\Windows\system32\lsass.exe
15:15:32.0155 0x2a20 VaultSvc - ok
15:15:32.0159 0x2a20 [ F257A2737280F0076EAE3AB489C06474, A02E37292D86E675D55C13097E9F107C73DDFD8AAC69310F7D9910A811A541D8 ] VClone C:\Windows\System32\drivers\VClone.sys
15:15:32.0173 0x2a20 VClone - ok
15:15:32.0179 0x2a20 [ 8DCB7E5A9497C030484E5AD9E541B85C, 1170E5C190E2B6F2966076EFF11B8476CC03D924F43144C2936E11314A89ACA6 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
15:15:32.0190 0x2a20 vdrvroot - ok
15:15:32.0205 0x2a20 [ 4940B49502323905B66039D0D1AB4613, 963BFD563B5A79F0AE81EB9708E85901A545545D4F25FCF37A17295EE9EDA514 ] vds C:\Windows\System32\vds.exe
15:15:32.0240 0x2a20 vds - ok
15:15:32.0259 0x2a20 [ 065E87298A14E08900A8B2369BB4F078, A9DD128B3F0B59930C07F5136376902266F4FDEB745FC0018899A5294E7AA862 ] veracrypt C:\Windows\system32\drivers\veracrypt.sys
15:15:32.0283 0x2a20 veracrypt - ok
15:15:32.0292 0x2a20 [ 5C25C1A89650C95D15F7988D71487B08, EC42E586309B46CF51EC5DC00362ABA82A503545292CACE7B3D23BB0F5E687B9 ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
15:15:32.0306 0x2a20 VerifierExt - ok
15:15:32.0323 0x2a20 [ 621BC9225307C834A0DCE2842052A6B8, 8ED9B414F9C02C7D8C25BB85BA3F47D420C64385702C7D70A7102A2D468E0530 ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
15:15:32.0348 0x2a20 vhdmp - ok
15:15:32.0355 0x2a20 [ EDCD732D7845A2B21B91C7D0CE96DA10, 5C132F33E0FE42A366200BCCFE98D0A55586E9D817B7DF9BA70E2E1736B62E5F ] vhf C:\Windows\System32\drivers\vhf.sys
15:15:32.0370 0x2a20 vhf - ok
15:15:32.0406 0x2a20 [ 90F354410D8CFEB9F908885F6DB84260, 74F9F14A36CBAFFC2118A7F43A1DC80CC5730EB027D141472EEB229C7EFE705E ] VMAuthdService D:\VMware Workstation\Workstation\vmware-authd.exe
15:15:32.0416 0x2a20 VMAuthdService - ok
15:15:32.0423 0x2a20 [ AD63BC4A11A4FD436ED23208BB8D1A9C, 079718B9B2F57716FC50119E9893AABF2AAC6223764E8C2ACAE1016A53E069E5 ] vmbus C:\Windows\system32\drivers\vmbus.sys
15:15:32.0434 0x2a20 vmbus - ok
15:15:32.0439 0x2a20 [ E2D57FB1A62F0BB7F70570806A09CE2B, DCF1699488D913C9E94E2C74CD8606BDAFF69B995B2E3B7DE7F2E9C4D2E6ECF2 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
15:15:32.0452 0x2a20 VMBusHID - ok
15:15:32.0458 0x2a20 [ 9C3FD3B0B9376537181067A28F2A5290, CFD39EBCA8B07C876BBB8469B145AAE95838C4445F946DFF19EB226581DACCEA ] vmci C:\Windows\system32\drivers\vmci.sys
15:15:32.0469 0x2a20 vmci - ok
15:15:32.0473 0x2a20 [ 7D778F1E82EBA9F5A4DD392CFD3C4224, E81D71E88C472B1631758E3C5D22A214450480C2E2DA010FDE21EC1B129C5FAD ] vmgid C:\Windows\System32\drivers\vmgid.sys
15:15:32.0488 0x2a20 vmgid - ok
15:15:32.0498 0x2a20 [ E4F5E83951810583FE8C2423772171DF, B2C7D44AA3F578C8E5B0A6FD8002BA554BAA4492FDFCFAED9D581C3ACD05D620 ] vmicguestinterface C:\Windows\System32\icsvc.dll
15:15:32.0521 0x2a20 vmicguestinterface - ok
15:15:32.0530 0x2a20 [ E4F5E83951810583FE8C2423772171DF, B2C7D44AA3F578C8E5B0A6FD8002BA554BAA4492FDFCFAED9D581C3ACD05D620 ] vmicheartbeat C:\Windows\System32\icsvc.dll
15:15:32.0552 0x2a20 vmicheartbeat - ok
15:15:32.0562 0x2a20 [ E4F5E83951810583FE8C2423772171DF, B2C7D44AA3F578C8E5B0A6FD8002BA554BAA4492FDFCFAED9D581C3ACD05D620 ] vmickvpexchange C:\Windows\System32\icsvc.dll
15:15:32.0591 0x2a20 vmickvpexchange - ok
15:15:32.0601 0x2a20 [ DB7FB1DA7E1564EACBADD436191309C5, B567DFB5828D64A2A199C16538F3557696C3381B858420F23EABC757FDC341C2 ] vmicrdv C:\Windows\System32\icsvcext.dll
15:15:32.0623 0x2a20 vmicrdv - ok
15:15:32.0633 0x2a20 [ E4F5E83951810583FE8C2423772171DF, B2C7D44AA3F578C8E5B0A6FD8002BA554BAA4492FDFCFAED9D581C3ACD05D620 ] vmicshutdown C:\Windows\System32\icsvc.dll
15:15:32.0654 0x2a20 vmicshutdown - ok
15:15:32.0663 0x2a20 [ E4F5E83951810583FE8C2423772171DF, B2C7D44AA3F578C8E5B0A6FD8002BA554BAA4492FDFCFAED9D581C3ACD05D620 ] vmictimesync C:\Windows\System32\icsvc.dll
15:15:32.0684 0x2a20 vmictimesync - ok
15:15:32.0693 0x2a20 [ E4F5E83951810583FE8C2423772171DF, B2C7D44AA3F578C8E5B0A6FD8002BA554BAA4492FDFCFAED9D581C3ACD05D620 ] vmicvmsession C:\Windows\System32\icsvc.dll
15:15:32.0714 0x2a20 vmicvmsession - ok
15:15:32.0724 0x2a20 [ DB7FB1DA7E1564EACBADD436191309C5, B567DFB5828D64A2A199C16538F3557696C3381B858420F23EABC757FDC341C2 ] vmicvss C:\Windows\System32\icsvcext.dll
15:15:32.0746 0x2a20 vmicvss - ok
15:15:32.0752 0x2a20 [ 57F53D802486F346BF0110F56B4B07D1, 7B31CE1010ED51350D5C69D5D4C93A1E55053887AEBCF7C3899901139BD67C8D ] vmkbd3 C:\Windows\system32\DRIVERS\vmkbd.sys
15:15:32.0760 0x2a20 vmkbd3 - ok
15:15:32.0766 0x2a20 [ B3C2E4DE5B1A39B16D43310085E2DEAA, F67D02E8F6FD6C49336B696409DFDF89B0229120D529709DB512F67348E8FE9A ] VMnetAdapter C:\Windows\system32\DRIVERS\vmnetadapter.sys
15:15:32.0776 0x2a20 VMnetAdapter - ok
15:15:32.0781 0x2a20 [ 508BD3B4EF66B4D01A3C848EED4DAB15, D995B802934B5A78019D10A1AB04615D5FBA8DD90270B5EFE9BD559DDC27C3DE ] VMnetBridge C:\Windows\system32\DRIVERS\vmnetbridge.sys
15:15:32.0791 0x2a20 VMnetBridge - ok
15:15:32.0811 0x2a20 [ 7A6AE9A60EA5408EF92F778CFD94D713, 14F441895BF339C7F1786A2A2F6B39458D8284695E39939B706A0EC29D0E9CAC ] VMnetDHCP C:\Windows\SysWOW64\vmnetdhcp.exe
15:15:32.0827 0x2a20 VMnetDHCP - ok
15:15:32.0850 0x2a20 [ 75CACACDA46FD9CB802E9FFB7B5C44DC, 4FD2D97DD70FFD2AEAD76E09DBCF00B06CD309EA6C36427AF392A9D0D45DE925 ] VMnetuserif C:\Windows\system32\DRIVERS\vmnetuserif.sys
15:15:32.0859 0x2a20 VMnetuserif - ok
15:15:32.0865 0x2a20 [ F235ABE47DFEFAC7D1078099F212B68B, A3475FA90D052DE6A09CBA2B5E1A174AC85C46C641963E4E9BECAA2A6448CF2B ] vmusb C:\Windows\System32\drivers\vmusb.sys
15:15:32.0875 0x2a20 vmusb - ok
15:15:32.0896 0x2a20 [ F31CE96F77EAB9A60B42D64DF7C43D89, 210199C260DB853CBD664EB2F3B3A19EAB1FB41EA1EF68D8809684315E427661 ] VMUSBArbService C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
15:15:32.0920 0x2a20 VMUSBArbService - ok
15:15:32.0945 0x2a20 [ 2315ED34AC56039BE948C8704C0DE88E, 0B2316A4C226C03545F6B71F87709E825909E1ED6D101AF0D8FCF473162B0C82 ] VMware NAT Service C:\Windows\SysWOW64\vmnat.exe
15:15:32.0961 0x2a20 VMware NAT Service - ok
15:15:33.0318 0x2a20 [ B72AC58260F05D3EB1F29EFC08BADDF3, 4FBE50305D60DA01334D47AF8E44A7A062FB31AC59CDD13DFE47733AD371E9AA ] VMwareHostd D:\VMware Workstation\Workstation\vmware-hostd.exe
15:15:33.0591 0x2a20 VMwareHostd - ok
15:15:33.0631 0x2a20 [ B13E3C8819736F80D44C26982F32CA08, 9CD54E8D3718B9358A085EDC584D20CC3F54DD852461B7D65F30ACA141FCAEA7 ] vmx86 C:\Windows\system32\DRIVERS\vmx86.sys
15:15:33.0641 0x2a20 vmx86 - ok
15:15:33.0647 0x2a20 [ 708410755721F94FC8939673893C2E2B, C8516DDE667614545DA076A9D034A7941D3E03953CB41576A979199363AB7A99 ] volmgr C:\Windows\system32\drivers\volmgr.sys
15:15:33.0660 0x2a20 volmgr - ok
15:15:33.0671 0x2a20 [ 1514506CA7462A64DC38C48108DDBB45, DEE5D7B79962D9EB6D92FCF870CA1B06FE68CE6AE25F82A5B449445C99E76D2A ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
15:15:33.0689 0x2a20 volmgrx - ok
15:15:33.0700 0x2a20 [ F0EE4E6028CCA58BEA9A04E7BEAB7DB4, 628D0E3D60256B914E46C26BCE8F512DFE0409C34EA603EB0A20C80EB469A4D2 ] volsnap C:\Windows\system32\drivers\volsnap.sys
15:15:33.0719 0x2a20 volsnap - ok
15:15:33.0725 0x2a20 [ 77FD1607F2C371ABD241EC7699C58884, A6FE00D76C615DC641A667EB9B6824C992ED752A31A89AE3FE43BAE5462F3EB7 ] volume C:\Windows\system32\drivers\volume.sys
15:15:33.0735 0x2a20 volume - ok
15:15:33.0741 0x2a20 [ A8E3A6BA6A1B4D1DFEC5E8D5CFF786DF, DEAE1C20AF6BBE419FDE432288C7A45B29AADA8D9E416BC428A4C2BF428D2861 ] vpci C:\Windows\System32\drivers\vpci.sys
15:15:33.0753 0x2a20 vpci - ok
15:15:33.0761 0x2a20 [ ED0B3436E1DE601C6C8EB86789AC8BAB, 0CD186B09903A1D3748A3258D8B84557F3674DA04FEB8EFA24AE81FFE376265C ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
15:15:33.0774 0x2a20 vsmraid - ok
15:15:33.0780 0x2a20 [ A394233BCBAF2D7DEF632EF6BD2D8D6A, DCF8A2D05459351A59C9F666C2E658E453142C7FEBC978F4AE1D1E9D8BC4D782 ] vsock C:\Windows\system32\DRIVERS\vsock.sys
15:15:33.0790 0x2a20 vsock - ok
15:15:33.0826 0x2a20 [ C7053D974A35EAB81F153FF33C883613, 9D89DC644971F93931D0E59D42ADE0A4AB49A5490709B46FCBBC309041C5432D ] VSS C:\Windows\system32\vssvc.exe
15:15:33.0886 0x2a20 VSS - ok
15:15:33.0964 0x2a20 [ AC5D1FB64A169D972AD52897BDC53305, 118F2A49B1C166F9A139A8DF8961790EC0B4B4B181E7903D962BD7C1B46F9287 ] VSStandardCollectorService150 D:\Program Files (x86)\Microsoft Visual Studio\Shared\Common\DiagnosticsHub.Collection.Service\StandardCollector.Service.exe
15:15:33.0977 0x2a20 VSStandardCollectorService150 - detected UnsignedFile.Multi.Generic ( 1 )
15:15:34.0041 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:34.0041 0x2a20 VSStandardCollectorService150 ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:34.0041 0x2a20 Force sending object to P2P due to detect: VSStandardCollectorService150
15:15:34.0176 0x2a20 Object send P2P result: true
15:15:34.0315 0x2a20 [ 23A0B9F051625718C2A0EC9E28D384E8, F146FB6E882B809D913854D4926C8231065024DD7463832B868CC8F4606FA183 ] vstor2-mntapi20-shared C:\Windows\syswow64\drivers\vstor2-x64.sys
15:15:34.0325 0x2a20 vstor2-mntapi20-shared - ok
15:15:34.0354 0x2a20 [ 3D706FBED35DF3B17809C6714F31F9B0, BBC337479DEB628721E651FC165EA01D986E31950189F1A81534922667101487 ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
15:15:34.0371 0x2a20 VSTXRAID - ok
15:15:34.0377 0x2a20 [ 0B11DBB8173AD374D67893D54EBEE9F3, AB8B6FC81244729157E59D062FCC234FD7E818804D94AA6B7BF81E01B7922395 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
15:15:34.0391 0x2a20 vwifibus - ok
15:15:34.0398 0x2a20 [ 95540F74893235C189409C98643D7A77, 4F041301C95F55C8448C3CC5825ED9E631E770BA35BEC8498A0ABB3563584AAE ] vwififlt C:\Windows\system32\drivers\vwififlt.sys
15:15:34.0414 0x2a20 vwififlt - ok
15:15:34.0421 0x2a20 [ 60A14582772A4DF0D0BE27B3F873BE6B, 93DB43D2F4B985A3FF1A152ADEDBB52567CCC29B899F96F8BA0FA9558EF2DF6D ] vwifimp C:\Windows\System32\drivers\vwifimp.sys
15:15:34.0437 0x2a20 vwifimp - ok
15:15:34.0453 0x2a20 [ 4F904ADE8BECDFB48CBA3F44FC0676A1, 2C3D619E9AD0D0DAEC0D170795FD6E5B7FE3FC667C947660320A9BC671B55736 ] W32Time C:\Windows\system32\w32time.dll
15:15:34.0486 0x2a20 W32Time - ok
15:15:34.0498 0x2a20 [ A513D44421D6556FF08CF791FDAF11FC, 0D29306CEF2AEA216088BFDA350F859317F40DF053C657F289A153F035749664 ] WaaSMedicSvc C:\Windows\System32\WaaSMedicSvc.dll
15:15:34.0525 0x2a20 WaaSMedicSvc - ok
15:15:34.0530 0x2a20 [ 87A01F65BD16C9FCCDD1B65F56CB93B0, E84B46DB67F2FCB22DB7130570FE7211FC96A806AC9D1D69D187899C93785CB2 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
15:15:34.0545 0x2a20 WacomPen - ok
15:15:34.0557 0x2a20 [ 25FAB8A2CFFA21FDB472AB3AE6C17A57, C97E651111643F32FD5B94BEDA31D62E6FF83CA0644FFE8BA98463EC9EA6EF9B ] WalletService C:\Windows\system32\WalletService.dll
15:15:34.0588 0x2a20 WalletService - ok
15:15:34.0595 0x2a20 [ 85E187443F68F285DB78BD2279AE3701, FAC03A162CF07FCC6BDB4E45F5EDF16D48BE10D95F73A74E9BADA62EC7F24B53 ] wanarp C:\Windows\system32\DRIVERS\wanarp.sys
15:15:34.0613 0x2a20 wanarp - ok
15:15:34.0618 0x2a20 [ 85E187443F68F285DB78BD2279AE3701, FAC03A162CF07FCC6BDB4E45F5EDF16D48BE10D95F73A74E9BADA62EC7F24B53 ] wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
15:15:34.0636 0x2a20 wanarpv6 - ok
15:15:34.0642 0x2a20 [ 395447583F42FD840520EE87AE439D74, 984AE1EE8BA3B8926C6FC94BC22DE9061C90C15135EA56D0F16C1D3C4EF8DAF8 ] WarpJITSvc C:\Windows\System32\Windows.WARP.JITService.dll
15:15:34.0660 0x2a20 WarpJITSvc - ok
15:15:34.0690 0x2a20 [ 7FDA8043417BF4C30E12BD2704565DA6, ADD2A36164D650A510F85D083EA97B1BE2F26721FD870C9EFACCFBE94A4866E5 ] wbengine C:\Windows\system32\wbengine.exe
15:15:34.0749 0x2a20 wbengine - ok
15:15:34.0772 0x2a20 [ 960FA25C6CAA9082A4DE0A2C81628287, 3DE39C2E28038F9B900319EAF2BC0E2EA5E7415E89AB6FB03E22354AB07A06DD ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
15:15:34.0816 0x2a20 WbioSrvc - ok
15:15:34.0824 0x2a20 [ 8A304D6CDC067922448CBA1EBB9FFCA8, DE40DD3A32DFF22C477F38B5E2224D55B8CCF2499EFFE0A8E9923728295BAEC1 ] wcifs C:\Windows\system32\drivers\wcifs.sys
15:15:34.0838 0x2a20 wcifs - ok
15:15:34.0860 0x2a20 [ E5822CB7C69F41B1B321F2583A85A268, 430AFC79C343951CE2B84ECA1C4951BCCD5473FFBA0AC6FA5031FF4045A6EB68 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
15:15:34.0903 0x2a20 Wcmsvc - ok
15:15:34.0917 0x2a20 [ B797B163EDCA46B5244F4E083BE7A7E7, 18D977A8015380A87EC9962273B90806145186A69F3455B3445A0FE1FE431219 ] wcncsvc C:\Windows\System32\wcncsvc.dll
15:15:34.0945 0x2a20 wcncsvc - ok
15:15:34.0952 0x2a20 [ 8E899F2D39BBE4BD49A1E36C3E8A1E5F, 37FB8860A0FCD5753EA486A735EFD5A92ED87069141F31CBB6587DA195877410 ] wcnfs C:\Windows\system32\drivers\wcnfs.sys
15:15:34.0968 0x2a20 wcnfs - ok
15:15:34.0974 0x2a20 [ E7E16778C8440BB459C94B5AD8282491, 728B2208884B4244E3481DDD82F9B353FC27DAC77488DBC8224AB1630616676A ] WdBoot C:\Windows\system32\drivers\wd\WdBoot.sys
15:15:34.0984 0x2a20 WdBoot - ok
15:15:35.0004 0x2a20 [ 152926023B401D1F5F8852929572F5C3, 61D0FDB0E3A4D16FFA6852174B3824F6294502E331BB0831BCF99F049B09C328 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
15:15:35.0031 0x2a20 Wdf01000 - ok
15:15:35.0042 0x2a20 [ 421A69C03BEB260A1CCAFFD3435AD587, 821FE66B3BB102BF7FDAF2F9A53ADEF89D677FEB4564C6E6EBE08FADF354ED36 ] WdFilter C:\Windows\system32\drivers\wd\WdFilter.sys
15:15:35.0059 0x2a20 WdFilter - ok
15:15:35.0065 0x2a20 [ 067D1A81B4708CA97523709FDF57B728, CA331223250B37E7D2D8B04640EDF279F7FD7336017181ECF2D3E4F82E370F97 ] WdiServiceHost C:\Windows\system32\wdi.dll
15:15:35.0085 0x2a20 WdiServiceHost - ok
15:15:35.0091 0x2a20 [ 067D1A81B4708CA97523709FDF57B728, CA331223250B37E7D2D8B04640EDF279F7FD7336017181ECF2D3E4F82E370F97 ] WdiSystemHost C:\Windows\system32\wdi.dll
15:15:35.0110 0x2a20 WdiSystemHost - ok
15:15:35.0129 0x2a20 [ 7CF63F36E6271E9647CE3C44F95DD613, 54DD9AA9569D7FBAF50E10453C001DF9A384599208BD04CE8818E4573B120C15 ] wdiwifi C:\Windows\system32\DRIVERS\wdiwifi.sys
15:15:35.0164 0x2a20 wdiwifi - ok
15:15:35.0170 0x2a20 [ EAF4FB729E94561EE31BDE5BEF869C65, 73290250B565E0A3F453BC45E69FF16A1D964E372A15401A2D3E2CDEB4670B38 ] WdmCompanionFilter C:\Windows\system32\drivers\WdmCompanionFilter.sys
15:15:35.0181 0x2a20 WdmCompanionFilter - ok
15:15:35.0187 0x2a20 [ E385410A4C16A62E9B6CC2DFF3C7C921, AAE3270025C7A0EC0490504B51C2FBF6C24AA44415DD836B9F49BE5614E20FA6 ] WdNisDrv C:\Windows\system32\drivers\wd\WdNisDrv.sys
15:15:35.0196 0x2a20 WdNisDrv - ok
15:15:35.0266 0x2a20 [ A14F36BF245442B88B1C0109C16C48ED, AE6E300E11B0CC725F444EDA22FC324FB27002CC5FD0F4216F3B6E8004E73302 ] WdNisSvc C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\NisSrv.exe
15:15:35.0380 0x2a20 WdNisSvc - detected UnsignedFile.Multi.Generic ( 1 )
15:15:35.0436 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:35.0438 0x2a20 WdNisSvc ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:35.0438 0x2a20 Force sending object to P2P due to detect: WdNisSvc
15:15:35.0600 0x2a20 Object send P2P result: true
15:15:35.0728 0x2a20 [ BDCC510E85F7AF152E2DFF030A526EA2, 67830B42DE20EBB30DD33093F30FBA166B27D3C1F25B52DABE1BC436671A1882 ] WebClient C:\Windows\System32\webclnt.dll
15:15:35.0751 0x2a20 WebClient - ok
15:15:35.0759 0x2a20 [ 506F0A1CCABF4428733CF854BCBB6832, 859A7E21ABB93A0AD538AAF93D32E31B961EA6012C24567B4C76A9ED8FD4AD46 ] Wecsvc C:\Windows\system32\wecsvc.dll
15:15:35.0782 0x2a20 Wecsvc - ok
15:15:35.0788 0x2a20 [ D8D727E8311C86B2A993A9006A453BAC, AD6C93F5ED51C621841DF68A25D5932578FADB83689FB668D056F316A8AA749D ] WEPHOSTSVC C:\Windows\system32\wephostsvc.dll
15:15:35.0805 0x2a20 WEPHOSTSVC - ok
15:15:35.0812 0x2a20 [ 30B4568D058E17500E7BF88AECEDF3F1, 612597DFAF63E55ACB80789483CBCF0E5AC5FF7607C478C61E5A86D77B169E9E ] wercplsupport C:\Windows\System32\wercplsupport.dll
15:15:35.0832 0x2a20 wercplsupport - ok
15:15:35.0841 0x2a20 [ 5DDB06B07A60E7AEA69837931373C159, 4E0A3260058B19F414B5053701C4723C27735818212AB3D297F896BF4C39E536 ] WerSvc C:\Windows\System32\WerSvc.dll
15:15:35.0865 0x2a20 WerSvc - ok
15:15:35.0882 0x2a20 [ 690537B9569F770ED81CE9C19FD7358A, FF780EBCD8C0B91E99BB2451F08D7826130781136E08FCB4571C3DD0C01B616F ] WFDSConMgrSvc C:\Windows\System32\wfdsconmgrsvc.dll
15:15:35.0915 0x2a20 WFDSConMgrSvc - ok
15:15:35.0924 0x2a20 [ EB0B154F12F78DE232F38EF61BCDEEA2, D4BC28969C94F9A3906339B42FC3638E8BFF575C28C709461D48A84821A89A21 ] WFPLWFS C:\Windows\system32\drivers\wfplwfs.sys
15:15:35.0938 0x2a20 WFPLWFS - ok
15:15:35.0944 0x2a20 [ 752F5931696914DF2EC0B27275C38458, 83415E7BE50D9548785FBF6550FA679E425B5990F303E2D74513275A5E1DC828 ] WiaRpc C:\Windows\System32\wiarpc.dll
15:15:35.0963 0x2a20 WiaRpc - ok
15:15:35.0969 0x2a20 [ 3AE28A996C9EB8A6F2AC12BC55035126, E54227B97F42800D445241EA638EFE86A7FEC664E96A0FA38BC48DDF7DA182AD ] WIMMount C:\Windows\system32\drivers\wimmount.sys
15:15:35.0979 0x2a20 WIMMount - ok
15:15:35.0986 0x2a20 [ AEBF97B10B719B94738F76C5389D1B49, AAB6434F9DA27C01E2B7B5E57310CA0AB9D9169BEF0870165AF418540C59B4BC ] WinDefend C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MsMpEng.exe
15:15:35.0997 0x2a20 WinDefend - detected UnsignedFile.Multi.Generic ( 1 )
15:15:36.0056 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:36.0056 0x2a20 WinDefend ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:36.0056 0x2a20 Force sending object to P2P due to detect: WinDefend
15:15:36.0208 0x2a20 Object send P2P result: true
15:15:36.0362 0x2a20 [ 2BB82BABE32D41F430D290239ABC0E87, 2D519F0B86F7B87B7028E404821EDE8B7BDA18288EF32CF81C25B9C1E629FFB1 ] WindowsTrustedRT C:\Windows\system32\drivers\WindowsTrustedRT.sys
15:15:36.0377 0x2a20 WindowsTrustedRT - ok
15:15:36.0383 0x2a20 [ 5F0EDDA201630E132C2251BC9DA85023, 842B5CBA8C33616345EDC2F91B560416AAEAAB15A8CE1F36978B251CE4CBDA16 ] WindowsTrustedRTProxy C:\Windows\system32\drivers\WindowsTrustedRTProxy.sys
15:15:36.0394 0x2a20 WindowsTrustedRTProxy - ok
15:15:36.0414 0x2a20 [ AABFB1421D248D086519F43BAF839A87, D51F22DE26E053EDD0A4B2D2FD4DBDD5BC5B63F4D6482E26AC4D24C96F3347A8 ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
15:15:36.0446 0x2a20 WinHttpAutoProxySvc - ok
15:15:36.0452 0x2a20 [ 762D8D839C44C5A0BE0449AA84034522, E6602D0FDB501081DF165CE904DA0FEC75F3FE29C3B07B44DED6268612742F9C ] WinMad C:\Windows\System32\drivers\winmad.sys
15:15:36.0464 0x2a20 WinMad - ok
15:15:36.0475 0x2a20 [ 72D83880FEF0C788C5F305F330744208, 3126C2907170BBA47421D61CD6ED04DA3A3FCC66B4DBFCB4E3B56001B3BF6045 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
15:15:36.0497 0x2a20 Winmgmt - ok
15:15:36.0506 0x2a20 [ C5AE3E1B653FD1F8072BE67D2BA28160, A126B9F7C54E978BF1DA74BFB8042357630AB326E82D20D5E2A9645ADB5B3B43 ] WinNat C:\Windows\system32\drivers\winnat.sys
15:15:36.0526 0x2a20 WinNat - ok
15:15:36.0576 0x2a20 [ C57185CC62AA13E4F5A989D904CC9A16, 993F27F710148335C4244AB74D4B1D232DEDB0E3D82E39093A1E422C72283D31 ] WinRM C:\Windows\system32\WsmSvc.dll
15:15:36.0667 0x2a20 WinRM - ok
15:15:36.0681 0x2a20 [ 6FA3D810FE082001B16ADE19829F1E8E, 64B420FC14AB3194D4D2907EA5BE741456928E7E3CB9CBA50FEB8677A43B1971 ] WINUSB C:\Windows\System32\drivers\WinUSB.SYS
15:15:36.0698 0x2a20 WINUSB - ok
15:15:36.0705 0x2a20 [ D2D6DB37E06608A5AF5B68D8E677B219, C7AAFEE7AAF76A4DCFF4FD2EE7232501832A57E3EE92CE20FA4A5D22F03FBE45 ] WinVerbs C:\Windows\System32\drivers\winverbs.sys
15:15:36.0718 0x2a20 WinVerbs - ok
15:15:36.0738 0x2a20 [ 08BEB7851B4B8AA07325C23A657233F1, 6D7A4D194D342A5BC3EE9738765B2F5D6B75165954CA6B0D9CD4B40B262C300E ] wisvc C:\Windows\system32\flightsettings.dll
15:15:36.0775 0x2a20 wisvc - ok
15:15:36.0824 0x2a20 [ 0C700D63A0321073C30D2BED9FDB0F27, 409A5110D442B9FB16E4430AD1756105F81EE30CFAB0D054D787C6A06FEB3FF9 ] WlanSvc C:\Windows\System32\wlansvc.dll
15:15:36.0910 0x2a20 WlanSvc - ok
15:15:36.0955 0x2a20 [ B33CA3C4BA1807B126CE44D98CC20366, 19CE56C9099E0DF249B69CF80F79CDD73EF77B421E7D5769E913E6BCE2A801D6 ] wlidsvc C:\Windows\system32\wlidsvc.dll
15:15:37.0031 0x2a20 wlidsvc - ok
15:15:37.0062 0x2a20 [ 1E2CBF80A663B6A662F68460DD4A5AC1, 4AAEECE3B849D2431F67593C4BA834920E31C1121F0E9802608583ED6B220027 ] wlpasvc C:\Windows\System32\lpasvc.dll
15:15:37.0113 0x2a20 wlpasvc - ok
15:15:37.0119 0x2a20 [ EAEF2A087812BB7110C744446AB731D5, F5571D3C47564DFB6182DC43CC28124892323B60C3F389599DFEC94D227B4A86 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
15:15:37.0133 0x2a20 WmiAcpi - ok
15:15:37.0144 0x2a20 [ ABAC310F5E01CBA9B33AE694F99D0977, 700CDC85479CDBF765FB1A6A389DC991FC4D2A77851A81FF80BEED921250DBF6 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
15:15:37.0165 0x2a20 wmiApSrv - ok
15:15:37.0170 0x2a20 WMPNetworkSvc - ok
15:15:37.0178 0x2a20 [ E122AD60BF4D7E4B28CCBABF33B28C1F, 1ABABE62FCC1B1A837540EE66F3EB0CE062962F05247002D61CFDE6ABB8E7E87 ] Wof C:\Windows\system32\drivers\Wof.sys
15:15:37.0191 0x2a20 Wof - ok
15:15:37.0237 0x2a20 [ 0D3303BDBC591ECF113601D7853A1AA7, 437CF89541696E0B1A8056F4A5189642FC76D762113ED4F71458AF4D72FC3E9A ] workfolderssvc C:\Windows\system32\workfolderssvc.dll
15:15:37.0295 0x2a20 workfolderssvc - ok
15:15:37.0327 0x2a20 [ 58DA02D34C964C00AF9140C07CCFF8F0, 6A02F326251A790F76E59737E20CB6C38190F671766E56CE6C7FB33D1A4588B9 ] WpcMonSvc C:\Windows\System32\WpcDesktopMonSvc.dll
15:15:37.0382 0x2a20 WpcMonSvc - ok
15:15:37.0390 0x2a20 [ 7412ECE8BD5590881FA9780B68BD70C5, 52329B5BF78E2F5792369FE5A72CF4E3E216D4F0670507D10F3DB8383FA5E0BC ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
15:15:37.0412 0x2a20 WPDBusEnum - ok
15:15:37.0418 0x2a20 [ 15C1131EA0216F799C86B03EDAE0BE45, 39F50C084407BC3B498714B74DDA5D63E0539681F324A18ABBED3CD0DE5D52AA ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
15:15:37.0429 0x2a20 WpdUpFltr - ok
15:15:37.0439 0x2a20 [ 096969606BB5C4822AB020081EA07FC5, 522F372834B0497215F45ACBC417DA10DCE45C6D3C7099E47BBA18700C294B22 ] WpnService C:\Windows\system32\WpnService.dll
15:15:37.0463 0x2a20 WpnService - ok
15:15:37.0470 0x2a20 [ 8B694BC50D2D2B98311283CFE5B40EE6, 734F8985CAD99E8635ACF09309D958D2B7FB05C6FF54DBE3623DC071BECE3413 ] WpnUserService C:\Windows\System32\WpnUserService.dll
15:15:37.0491 0x2a20 WpnUserService - ok
15:15:37.0502 0x2a20 [ C1C2E769FCD3B00A59FF876FB2AD4336, B4D9065268A8B3C509E9160E6F30C20F80D14876C9F6C1057245F09CEB6B0F36 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
15:15:37.0518 0x2a20 ws2ifsl - ok
15:15:37.0527 0x2a20 [ DCB549367EB94CD8AFAA28E3F77F6493, 9FD2C6E03F398E76403502CFC94EB8EBD2F90ED5E95ABA5E86C1B7F63601C43C ] wscsvc C:\Windows\System32\wscsvc.dll
15:15:37.0551 0x2a20 wscsvc - ok
15:15:37.0556 0x2a20 WSearch - ok
15:15:37.0612 0x2a20 [ F097CE3EAEF42CCBC9A4FEA9B17BD4A6, 04BEC83B08DADA8896EAFEC3B0004767F9C057D94F7B1A97345E1C0D2C91BD43 ] wuauserv C:\Windows\system32\wuaueng.dll
15:15:37.0705 0x2a20 wuauserv - ok
15:15:37.0714 0x2a20 [ 813DC18CC654CFB1875074139B0FEFD3, 87901841AFD9224BFEC06A712BE3C2371E16D3571210D4792F91034A2B926A06 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
15:15:37.0732 0x2a20 WudfPf - ok
15:15:37.0741 0x2a20 [ FB64BAD6DEDB27EA39B03685AC0A8EB4, CEDCB71F5FC8BAFF69948960F69A46E3A41CDF81304495AFF41088E5B4E9EB1D ] WUDFRd C:\Windows\system32\drivers\WudfRd.sys
15:15:37.0764 0x2a20 WUDFRd - ok
15:15:37.0773 0x2a20 [ FB64BAD6DEDB27EA39B03685AC0A8EB4, CEDCB71F5FC8BAFF69948960F69A46E3A41CDF81304495AFF41088E5B4E9EB1D ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
15:15:37.0794 0x2a20 WUDFWpdFs - ok
15:15:37.0803 0x2a20 [ FB64BAD6DEDB27EA39B03685AC0A8EB4, CEDCB71F5FC8BAFF69948960F69A46E3A41CDF81304495AFF41088E5B4E9EB1D ] WUDFWpdMtp C:\Windows\system32\DRIVERS\WUDFRd.sys
15:15:37.0824 0x2a20 WUDFWpdMtp - ok
15:15:37.0857 0x2a20 [ 5F2074E76546A85B0D6D79CA7024AA3E, D75DCD4C6F1CFB439B5EF0A7CFDDC40B2FCDB466C2574FE2E0FFA08BF216CCA3 ] WwanSvc C:\Windows\System32\wwansvc.dll
15:15:37.0925 0x2a20 WwanSvc - ok
15:15:37.0933 0x2a20 [ 51D3A1E2285E2E931A553281BBA10E81, 8B371AF5E7717C53780A5C2F68400412C4DB0F01AC6551476FF062B83A7D0AC8 ] xbgm C:\Windows\system32\xbgmsvc.exe
15:15:37.0947 0x2a20 xbgm - ok
15:15:37.0971 0x2a20 [ DB952AD196A9548CF5235A71E5197F3F, 6C51EB14B2808665FCB999F376A97018F6B0A91EE6E63A25C044EA59A5713EE1 ] XblAuthManager C:\Windows\System32\XblAuthManager.dll
15:15:38.0020 0x2a20 XblAuthManager - ok
15:15:38.0048 0x2a20 [ 8C0DD7BFFF5A81AEC26AD720057F5451, 4503D4DD540DB9977BBFF3BF7E92BE9778578B769972CF8A54AF0F1FF5C79BF5 ] XblGameSave C:\Windows\System32\XblGameSave.dll
15:15:38.0101 0x2a20 XblGameSave - ok
15:15:38.0112 0x2a20 [ 93352403D9E6B71C275996690672488F, A012D907679B29988D18C71928BDF528506DC05A2DEF01F472B7F0CC043A0340 ] xboxgip C:\Windows\System32\drivers\xboxgip.sys
15:15:38.0141 0x2a20 xboxgip - ok
15:15:38.0148 0x2a20 [ C7FEC5C0377E5598BA919B29731CA45F, C153C62742B6F981905AEF7C464761E5894260F26EE164968B21D93979376378 ] XboxGipSvc C:\Windows\System32\XboxGipSvc.dll
15:15:38.0167 0x2a20 XboxGipSvc - ok
15:15:38.0192 0x2a20 [ 3A94BD93CD2D9C34725D924230B502A5, 87AF2061D348FFFA190D0E50E6860903BED46968CF64B7765D8D80127C702E6A ] XboxNetApiSvc C:\Windows\system32\XboxNetApiSvc.dll
15:15:38.0250 0x2a20 XboxNetApiSvc - ok
15:15:38.0258 0x2a20 [ CE1F78B5C1F14F74242008B2B3153FA2, 682D1F32DD1BBEB031D5129CE40D9C77D3C6CF4FB5979F1918B2482AF617B5BE ] xinputhid C:\Windows\System32\drivers\xinputhid.sys
15:15:38.0274 0x2a20 xinputhid - ok
15:15:38.0285 0x2a20 [ F8EAA1E498EF356906B3509948CF482E, 036785C3B89C50AD262DFF794F606CCDB28D297E64660D585DF18C6F8A8E0D1D ] ysusb_w10_64 C:\Windows\system32\drivers\ysusb_w10_64.sys
15:15:38.0298 0x2a20 ysusb_w10_64 - ok
15:15:38.0298 0x2a20 ================ Scan global ===============================
15:15:38.0303 0x2a20 [ 44D259E3B8F950D123CBE21893CEF1AB, 94FEA350B54D1581FF07D078D25A27FE3C9F815E24D299A0504FB1153E68A903 ] C:\Windows\system32\basesrv.dll
15:15:38.0309 0x2a20 [ 1C346B5D7E5336246604A9FCFCB092BC, BD0C56C943A8F23CA9CD1CE1FE4F9D2183F752B469A72D14B713301A867AE776 ] C:\Windows\system32\winsrv.dll
15:15:38.0315 0x2a20 [ FE8D1AB6D6711BE791A01C17EDEBD0D6, EECE3A16DFA0BE1BB1E7B882D33FB926C90A1DCA89805DD3514FABF7C9F05253 ] C:\Windows\system32\sxssrv.dll
15:15:38.0330 0x2a20 [ 2FC61B2CF84792516D543CA94139A92C, BE42E4A901D6AC8885882D2CD9372A64023794428E0AC8CC87EE3121DD5DC402 ] C:\Windows\system32\services.exe
15:15:38.0340 0x2a20 [ Global ] - ok
15:15:38.0341 0x2a20 ================ Scan MBR ==================================
15:15:38.0342 0x2a20 [ 1F998BE06DC960CE70B919FFF503E98C ] \Device\Harddisk0\DR0
15:15:38.0428 0x2a20 \Device\Harddisk0\DR0 - ok
15:15:38.0450 0x2a20 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk1\DR1
15:15:38.0550 0x2a20 \Device\Harddisk1\DR1 - ok
15:15:38.0551 0x2a20 ================ Scan VBR ==================================
15:15:38.0554 0x2a20 [ 831F7CD8FC9F2758E614FB623826019E ] \Device\Harddisk0\DR0\Partition1
15:15:38.0556 0x2a20 \Device\Harddisk0\DR0\Partition1 - ok
15:15:38.0558 0x2a20 [ AB956D2B21D619B7953AB2E48F0A3948 ] \Device\Harddisk0\DR0\Partition2
15:15:38.0560 0x2a20 \Device\Harddisk0\DR0\Partition2 - ok
15:15:38.0589 0x2a20 [ 8C4292C70B855FD22AB86D4CB4729945 ] \Device\Harddisk1\DR1\Partition1
15:15:38.0592 0x2a20 \Device\Harddisk1\DR1\Partition1 - ok
15:15:38.0593 0x2a20 ================ Scan generic autorun ======================
15:15:38.0594 0x2a20 SecurityHealth - ok
15:15:38.0659 0x2a20 [ 14EFA69C5065CF7A7DA3CD5EACA1AC10, CABC3B4B3C6D435A02DB6C3CA639D2136945CB8460A657C299893B6363E8FA34 ] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe
15:15:38.0723 0x2a20 KeePass 2 PreLoad - ok
15:15:38.0758 0x2a20 [ 9BFBB718830C85F296F9FB87C977232B, BEE40CDE1B9AD704D8B1708A9B3847AF390AAAFAC5F5E7E96A500C892D1474B2 ] D:\VMware Workstation\Workstation\vmware-tray.exe
15:15:38.0770 0x2a20 vmware-tray.exe - detected UnsignedFile.Multi.Generic ( 1 )
15:15:38.0831 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:38.0831 0x2a20 vmware-tray.exe ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:38.0831 0x2a20 Force sending object to P2P due to detect: D:\VMware Workstation\Workstation\vmware-tray.exe
15:15:38.0982 0x2a20 Object send P2P result: true
15:15:39.0168 0x2a20 [ A70070CF2470EEB4544DA7D1BBEE7089, E5B7ADDB00462D72FBE7219C9266FBEC1B016DBBFCEBC6AB7A0375DB068A0B4A ] C:\Program Files (x86)\TP-Link\TP-Link Wireless Adapter WPS Tool\TWCU.exe
15:15:39.0225 0x2a20 WPSTool - detected UnsignedFile.Multi.Generic ( 1 )
15:15:39.0293 0x2a20 Detect skipped due to KSN trusted
15:15:39.0293 0x2a20 WPSTool - ok
15:15:39.0333 0x2a20 [ 993C7977DEE1E4951E11336110218A9C, 75E1F865FD86E5ADE965E764FB52740649B896AB9FB06ADB22A49C4496787986 ] C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
15:15:39.0400 0x2a20 Wondershare Helper Compact.exe - detected UnsignedFile.Multi.Generic ( 1 )
15:15:39.0458 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:39.0458 0x2a20 Wondershare Helper Compact.exe ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:39.0458 0x2a20 Force sending object to P2P due to detect: C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
15:15:39.0599 0x2a20 Object send P2P result: true
15:15:39.0757 0x2a20 [ 6AF81399C8D74051A74D73BE84B6F3A7, B0BB69D690A5CB556D56FCAB0D891BA1A76280907BD9DDEA7505AF8F302007A0 ] C:\Program Files (x86)\CCEnhancer\CCEnhancer.exe
15:15:39.0791 0x2a20 CCEnhancer - detected UnsignedFile.Multi.Generic ( 1 )
15:15:39.0860 0x2a20 Object required for P2P: [ 6AF81399C8D74051A74D73BE84B6F3A7 ] C:\Program Files (x86)\CCEnhancer\CCEnhancer.exe
15:15:40.0018 0x2a20 Object send P2P result: true
15:15:40.0019 0x2a20 CCEnhancer ( UnsignedFile.Multi.Generic ) - warning
15:15:40.0178 0x2a20 [ E358A20B5008FE3AC3CC90B81024B817, 1F5FAE5BD358CBBFF79E4922BEBBA16984782B78FC50EF445027F9B6AA73EA5B ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
15:15:40.0213 0x2a20 SunJavaUpdateSched - ok
15:15:40.0600 0x2a20 [ 450FDD861FD582026BDCE55FCB2162C4, 91166DBAEE6A0D97ABA5EED352D06078870A265E736ED491C666CB6A8559BEB2 ] C:\Windows\SysWOW64\OneDriveSetup.exe
15:15:40.0995 0x2a20 OneDriveSetup - ok
15:15:41.0355 0x2a20 [ 450FDD861FD582026BDCE55FCB2162C4, 91166DBAEE6A0D97ABA5EED352D06078870A265E736ED491C666CB6A8559BEB2 ] C:\Windows\SysWOW64\OneDriveSetup.exe
15:15:41.0738 0x2a20 OneDriveSetup - ok
15:15:42.0101 0x2a20 [ 91D01D7B0835671BF21873C87222C8D7, 18685B196733DFE6FAFCC888940361B35E12B428B8843B53C32CC043F7537753 ] C:\Program Files\CCleaner\CCleaner64.exe
15:15:42.0486 0x2a20 CCleaner Smart Cleaning - ok
15:15:42.0556 0x2a20 [ 14EFA69C5065CF7A7DA3CD5EACA1AC10, CABC3B4B3C6D435A02DB6C3CA639D2136945CB8460A657C299893B6363E8FA34 ] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe
15:15:42.0620 0x2a20 KeePass Password Safe 2 - ok
15:15:42.0727 0x2a20 [ EF5D4F2BC8731C744006E13CAF3F6AC0, 89209688D7436153E780C772CF5A2EFF3AC3E092EA12232CA543C658661FF884 ] C:\Program Files\VeraCrypt\VeraCrypt.exe
15:15:42.0835 0x2a20 VeraCrypt - ok
15:15:42.0876 0x2a20 [ 2526B94482C1F25F000A5835F28FFB39, E4DBA0A971A6397070E7F63315A68C345DD4076B07CB79FE904D5F26A158260D ] C:\Program Files (x86)\Thunder Master\THPanel.exe
15:15:42.0918 0x2a20 THPanel - ok
15:15:42.0979 0x2a20 EpicGamesLauncher - ok
15:15:43.0112 0x2a20 [ C8B0E47E25B727CDDDE7457589B35AFF, EC72E53698072214B4A3035F5CA2F6B4961D58DEC189F1134C254B4BC7AB1336 ] D:\Games\Steam\steam.exe
15:15:43.0206 0x2a20 Steam - detected UnsignedFile.Multi.Generic ( 1 )
15:15:43.0264 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:43.0264 0x2a20 Steam ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:43.0264 0x2a20 Force sending object to P2P due to detect: D:\Games\Steam\steam.exe
15:15:43.0488 0x2a20 Object send P2P result: true
15:15:43.0715 0x2a20 [ A34781E9A2A6CC393B8CA6ED0CFEDDD1, 851D8924D39912879C54BC45CC896AAAC418695CBC2C3A6A4F1EA5894C4F0083 ] C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
15:15:43.0815 0x2a20 Synapse3 - detected UnsignedFile.Multi.Generic ( 1 )
15:15:43.0868 0x2a20 Synapse3 ( UnsignedFile.Multi.Generic ) - warning
15:15:44.0127 0x2a20 [ 3EBB1F423EF0C5BA02E1C216052BE308, 6AD47FED409B7D2F307110AAA70A593BB35D3BFEA954C94D630CA206819C44D6 ] D:\Games\Origin\Origin.exe
15:15:44.0217 0x2a20 EADM - detected UnsignedFile.Multi.Generic ( 1 )
15:15:44.0281 0x2a20 Detect turned to UDS exact due to KSN untrusted
15:15:44.0281 0x2a20 EADM ( UDS:DangerousObject.Multi.Generic ) - infected
15:15:44.0281 0x2a20 Force sending object to P2P due to detect: D:\Games\Origin\Origin.exe
15:15:44.0474 0x2a20 Object send P2P result: true
15:15:44.0971 0x2a20 [ 91D01D7B0835671BF21873C87222C8D7, 18685B196733DFE6FAFCC888940361B35E12B428B8843B53C32CC043F7537753 ] C:\Program Files\CCleaner\CCleaner64.exe
15:15:45.0338 0x2a20 CCleaner - ok
15:15:45.0352 0x2a20 Waiting for KSN requests completion. In queue: 297
15:15:46.0388 0x2a20 AV detected via SS2: Windows Defender, windowsdefender:// ( ), 0x60100 ( disabled : updated )
15:15:46.0388 0x2a20 AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.181 ), 0x61000 ( enabled : updated )
15:15:46.0402 0x2a20 Win FW state via NFP2: enabled ( trusted )
15:15:46.0531 0x2a20 ============================================================
15:15:46.0531 0x2a20 Scan finished
15:15:46.0531 0x2a20 ============================================================
15:15:46.0546 0x23d0 Detected object count: 16
15:15:46.0546 0x23d0 Actual detected object count: 16
15:20:20.0213 0x23d0 BEService ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0213 0x23d0 BEService ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0250 0x23d0 C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe - copied to quarantine
15:20:20.0254 0x23d0 HKLM\SYSTEM\ControlSet001\services\EasyAntiCheat - will be deleted on reboot
15:20:20.0265 0x23d0 C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe - will be deleted on reboot
15:20:20.0265 0x23d0 EasyAntiCheat ( UDS:DangerousObject.Multi.Generic ) - User select action: Delete
15:20:20.0267 0x23d0 gupdate ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0267 0x23d0 gupdate ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0268 0x23d0 gupdatem ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0268 0x23d0 gupdatem ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0269 0x23d0 MozillaMaintenance ( UnsignedFile.Multi.Generic ) - skipped by user
15:20:20.0269 0x23d0 MozillaMaintenance ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:20:20.0270 0x23d0 Origin Client Service ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0270 0x23d0 Origin Client Service ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0272 0x23d0 Steam Client Service ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0272 0x23d0 Steam Client Service ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0273 0x23d0 VSStandardCollectorService150 ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0273 0x23d0 VSStandardCollectorService150 ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0274 0x23d0 WdNisSvc ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0274 0x23d0 WdNisSvc ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0275 0x23d0 WinDefend ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0275 0x23d0 WinDefend ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0276 0x23d0 vmware-tray.exe ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0276 0x23d0 vmware-tray.exe ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0277 0x23d0 Wondershare Helper Compact.exe ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0277 0x23d0 Wondershare Helper Compact.exe ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0279 0x23d0 CCEnhancer ( UnsignedFile.Multi.Generic ) - skipped by user
15:20:20.0279 0x23d0 CCEnhancer ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:20:20.0280 0x23d0 Steam ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0280 0x23d0 Steam ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0281 0x23d0 Synapse3 ( UnsignedFile.Multi.Generic ) - skipped by user
15:20:20.0281 0x23d0 Synapse3 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:20:20.0282 0x23d0 EADM ( UDS:DangerousObject.Multi.Generic ) - skipped by user
15:20:20.0282 0x23d0 EADM ( UDS:DangerousObject.Multi.Generic ) - User select action: Skip
15:20:20.0306 0x23d0 KLMD registered as C:\Windows\system32\drivers\18084314.sys |