Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Urgent: Exploit:JS/Blacole.GP


  • Please log in to reply
12 replies to this topic

#1 Corradio

Corradio

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 07:16 PM

Hi,
I just ran Microsoft Security Essentials and it found Exploit:JS/Blacole.GP on my pc.
Now I googled it and I read a lot of scary things about it.
Hence I am not sure how to proceed. Simply removing it with Security Essentials will probably not solve the problem, right?

I hope there are some people here who have experience with this virus or exploit.

N.b. the threat was found in the folder
file:C:\Users\****\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ME0WIMYV\word_arrangements[1].htm

I am not going to shut down my pc now because I am scared that it won't start again.

I really hope someone can help me to safely remove this virus.

Thanks a lot in advance.

Corradio

Edited by Corradio, 30 January 2013 - 07:16 PM.


BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:54 AM

Posted 30 January 2013 - 08:32 PM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here.If you get crashes in normal mode,run it in safemode with networking

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 Corradio

Corradio
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 08:38 PM

Hi, I put the file in Quarantine with Microsoft Security Essentials while i was waiting for a reply. What should I do now?

#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:05:54 AM

Posted 30 January 2013 - 08:43 PM

I already gave you the instructions.

#5 Corradio

Corradio
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 08:45 PM

Yes indeed, but will these logs still be useful with the file in quarantine?

#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:54 AM

Posted 30 January 2013 - 09:28 PM

Yes, the newlogs are needed.


I also moved this to the Am I Infected forum.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 Corradio

Corradio
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 09:33 PM

But I moved the Exploit:JS/Blacole.GP- file to quarantine with Microsoft Security Essentials. Should I remove it as well? I am running the third program you listed (ESET Online Scanner) now, but they all come back clean (since the file is in quarantine).

I'm not sure what to do but Ill post the 3 logs in a few minutes.

#8 Corradio

Corradio
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 09:37 PM

02:40:40.0930 4856 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
02:40:41.0185 4856 ============================================================
02:40:41.0185 4856 Current date / time: 2013/01/31 02:40:41.0185
02:40:41.0185 4856 SystemInfo:
02:40:41.0185 4856
02:40:41.0185 4856 OS Version: 6.1.7601 ServicePack: 1.0
02:40:41.0185 4856 Product type: Workstation
02:40:41.0185 4856 ComputerName: ***
02:40:41.0185 4856 UserName: ***
02:40:41.0185 4856 Windows directory: C:\Windows
02:40:41.0185 4856 System windows directory: C:\Windows
02:40:41.0185 4856 Running under WOW64
02:40:41.0185 4856 Processor architecture: Intel x64
02:40:41.0185 4856 Number of processors: 4
02:40:41.0185 4856 Page size: 0x1000
02:40:41.0185 4856 Boot type: Normal boot
02:40:41.0185 4856 ============================================================
02:40:43.0281 4856 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
02:40:43.0301 4856 ============================================================
02:40:43.0301 4856 \Device\Harddisk0\DR0:
02:40:43.0321 4856 MBR partitions:
02:40:43.0321 4856 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x64000
02:40:43.0321 4856 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x6ECA1800
02:40:43.0321 4856 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x6ED06000, BlocksNum 0x32F0000
02:40:43.0321 4856 ============================================================
02:40:43.0406 4856 C: <-> \Device\Harddisk0\DR0\Partition2
02:40:43.0541 4856 D: <-> \Device\Harddisk0\DR0\Partition3
02:40:43.0541 4856 ============================================================
02:40:43.0541 4856 Initialize success
02:40:43.0541 4856 ============================================================
02:41:13.0385 3040 ============================================================
02:41:13.0385 3040 Scan started
02:41:13.0385 3040 Mode: Manual; TDLFS;
02:41:13.0385 3040 ============================================================
02:41:14.0041 3040 ================ Scan system memory ========================
02:41:14.0041 3040 System memory - ok
02:41:14.0041 3040 ================ Scan services =============================
02:41:18.0926 3040 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
02:41:18.0936 3040 1394ohci - ok
02:41:18.0966 3040 Scan interrupted by user!
02:41:18.0966 3040 ================ Scan global ===============================
02:41:18.0966 3040 Scan interrupted by user!
02:41:18.0966 3040 ================ Scan MBR ==================================
02:41:18.0966 3040 Scan interrupted by user!
02:41:18.0966 3040 ================ Scan VBR ==================================
02:41:18.0966 3040 Scan interrupted by user!
02:41:18.0966 3040 ============================================================
02:41:18.0966 3040 Scan finished
02:41:18.0966 3040 ============================================================
02:41:18.0976 5520 Detected object count: 0
02:41:18.0976 5520 Actual detected object count: 0
02:44:50.0082 5288 ============================================================
02:44:50.0082 5288 Scan started
02:44:50.0082 5288 Mode: Manual; TDLFS;
02:44:50.0082 5288 ============================================================
02:44:50.0347 5288 ================ Scan system memory ========================
02:44:50.0347 5288 System memory - ok
02:44:50.0352 5288 ================ Scan services =============================
02:44:50.0487 5288 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
02:44:50.0487 5288 1394ohci - ok
02:44:50.0507 5288 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
02:44:50.0507 5288 ACPI - ok
02:44:50.0537 5288 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
02:44:50.0537 5288 AcpiPmi - ok
02:44:50.0557 5288 [ 5E813B11629007309E4FC0F0FD2B7C30 ] ACPIVPC C:\Windows\system32\DRIVERS\AcpiVpc.sys
02:44:50.0562 5288 ACPIVPC - ok
02:44:50.0662 5288 [ 3927397AC60D943DAF8808AFFED582B7 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
02:44:50.0682 5288 AdobeARMservice - ok
02:44:50.0712 5288 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
02:44:50.0717 5288 adp94xx - ok
02:44:50.0742 5288 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\drivers\adpahci.sys
02:44:50.0747 5288 adpahci - ok
02:44:50.0747 5288 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
02:44:50.0752 5288 adpu320 - ok
02:44:50.0782 5288 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
02:44:50.0782 5288 AeLookupSvc - ok
02:44:50.0827 5288 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
02:44:50.0837 5288 AFD - ok
02:44:50.0867 5288 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
02:44:50.0867 5288 agp440 - ok
02:44:50.0882 5288 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
02:44:50.0882 5288 ALG - ok
02:44:50.0892 5288 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
02:44:50.0897 5288 aliide - ok
02:44:50.0897 5288 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
02:44:50.0902 5288 amdide - ok
02:44:50.0902 5288 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
02:44:50.0907 5288 AmdK8 - ok
02:44:50.0912 5288 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\drivers\amdppm.sys
02:44:50.0912 5288 AmdPPM - ok
02:44:50.0937 5288 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
02:44:50.0937 5288 amdsata - ok
02:44:50.0962 5288 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
02:44:50.0967 5288 amdsbs - ok
02:44:50.0987 5288 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
02:44:50.0987 5288 amdxata - ok
02:44:51.0012 5288 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
02:44:51.0017 5288 AppID - ok
02:44:51.0047 5288 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
02:44:51.0047 5288 AppIDSvc - ok
02:44:51.0067 5288 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
02:44:51.0067 5288 Appinfo - ok
02:44:51.0132 5288 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
02:44:51.0132 5288 Apple Mobile Device - ok
02:44:51.0147 5288 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\drivers\arc.sys
02:44:51.0147 5288 arc - ok
02:44:51.0167 5288 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\drivers\arcsas.sys
02:44:51.0167 5288 arcsas - ok
02:44:51.0187 5288 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
02:44:51.0192 5288 AsyncMac - ok
02:44:51.0212 5288 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
02:44:51.0212 5288 atapi - ok
02:44:51.0237 5288 [ 78B183A794A08978EA0A8D017054352B ] AthBTPort C:\Windows\system32\DRIVERS\btath_flt.sys
02:44:51.0242 5288 AthBTPort - ok
02:44:51.0298 5288 [ 42EF52D591A53CBE43D82C6C96F50A59 ] AtherosSvc C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
02:44:51.0313 5288 AtherosSvc - ok
02:44:51.0378 5288 [ 6C496450404ABDC887E56DF462B34255 ] athr C:\Windows\system32\DRIVERS\athrx.sys
02:44:51.0398 5288 athr - ok
02:44:51.0443 5288 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
02:44:51.0448 5288 AudioEndpointBuilder - ok
02:44:51.0458 5288 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
02:44:51.0458 5288 AudioSrv - ok
02:44:51.0483 5288 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
02:44:51.0483 5288 AxInstSV - ok
02:44:51.0518 5288 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
02:44:51.0523 5288 b06bdrv - ok
02:44:51.0563 5288 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
02:44:51.0568 5288 b57nd60a - ok
02:44:51.0618 5288 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
02:44:51.0623 5288 BDESVC - ok
02:44:51.0648 5288 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
02:44:51.0648 5288 Beep - ok
02:44:51.0713 5288 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
02:44:51.0723 5288 BFE - ok
02:44:51.0763 5288 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
02:44:51.0768 5288 BITS - ok
02:44:51.0793 5288 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
02:44:51.0793 5288 blbdrive - ok
02:44:51.0823 5288 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
02:44:51.0823 5288 bowser - ok
02:44:51.0853 5288 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
02:44:51.0853 5288 BrFiltLo - ok
02:44:51.0858 5288 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
02:44:51.0858 5288 BrFiltUp - ok
02:44:51.0893 5288 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
02:44:51.0893 5288 Browser - ok
02:44:51.0908 5288 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
02:44:51.0908 5288 Brserid - ok
02:44:51.0913 5288 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
02:44:51.0913 5288 BrSerWdm - ok
02:44:51.0918 5288 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
02:44:51.0918 5288 BrUsbMdm - ok
02:44:51.0938 5288 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
02:44:51.0938 5288 BrUsbSer - ok
02:44:51.0973 5288 [ EDEBD26DF631A78483707C3F7429027F ] BTATH_A2DP C:\Windows\system32\drivers\btath_a2dp.sys
02:44:51.0978 5288 BTATH_A2DP - ok
02:44:51.0998 5288 [ 2F22177BFEA75326DC0C535D71985A4E ] btath_avdt C:\Windows\system32\drivers\btath_avdt.sys
02:44:51.0998 5288 btath_avdt - ok
02:44:52.0038 5288 [ D438A33D568C76C24E8D7394981F42DC ] BTATH_BUS C:\Windows\system32\DRIVERS\btath_bus.sys
02:44:52.0038 5288 BTATH_BUS - ok
02:44:52.0048 5288 [ 6EFA8C93009E0BE0886C2422C7D20BC5 ] BTATH_HCRP C:\Windows\system32\DRIVERS\btath_hcrp.sys
02:44:52.0053 5288 BTATH_HCRP - ok
02:44:52.0078 5288 [ 168506D0F0C8DF588F8A7E25C58A2DE6 ] BTATH_LWFLT C:\Windows\system32\DRIVERS\btath_lwflt.sys
02:44:52.0078 5288 BTATH_LWFLT - ok
02:44:52.0098 5288 [ 7C8FB1D73BD279DD914CCA6ED0F4F62B ] BTATH_RCP C:\Windows\system32\DRIVERS\btath_rcp.sys
02:44:52.0098 5288 BTATH_RCP - ok
02:44:52.0143 5288 [ 58D67C18894F96E89C076150BB76AD40 ] BtFilter C:\Windows\system32\DRIVERS\btfilter.sys
02:44:52.0148 5288 BtFilter - ok
02:44:52.0198 5288 [ CF98190A94F62E405C8CB255018B2315 ] BthEnum C:\Windows\system32\drivers\BthEnum.sys
02:44:52.0198 5288 BthEnum - ok
02:44:52.0213 5288 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
02:44:52.0218 5288 BTHMODEM - ok
02:44:52.0243 5288 [ 02DD601B708DD0667E1331FA8518E9FF ] BthPan C:\Windows\system32\DRIVERS\bthpan.sys
02:44:52.0243 5288 BthPan - ok
02:44:52.0263 5288 [ 738D0E9272F59EB7A1449C3EC118E6C4 ] BTHPORT C:\Windows\System32\Drivers\BTHport.sys
02:44:52.0269 5288 BTHPORT - ok
02:44:52.0314 5288 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
02:44:52.0314 5288 bthserv - ok
02:44:52.0334 5288 [ F188B7394D81010767B6DF3178519A37 ] BTHUSB C:\Windows\System32\Drivers\BTHUSB.sys
02:44:52.0339 5288 BTHUSB - ok
02:44:52.0384 5288 [ DD9BBFE0AD2A271A438333CC611EB904 ] camfilt2 C:\Windows\system32\DRIVERS\camfilt2.sys
02:44:52.0399 5288 camfilt2 - ok
02:44:52.0419 5288 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
02:44:52.0419 5288 cdfs - ok
02:44:52.0484 5288 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
02:44:52.0494 5288 cdrom - ok
02:44:52.0519 5288 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
02:44:52.0519 5288 CertPropSvc - ok
02:44:52.0549 5288 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\drivers\circlass.sys
02:44:52.0549 5288 circlass - ok
02:44:52.0584 5288 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
02:44:52.0589 5288 CLFS - ok
02:44:52.0689 5288 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
02:44:52.0689 5288 clr_optimization_v2.0.50727_32 - ok
02:44:52.0749 5288 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
02:44:52.0754 5288 clr_optimization_v2.0.50727_64 - ok
02:44:52.0804 5288 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
02:44:52.0809 5288 clr_optimization_v4.0.30319_32 - ok
02:44:52.0844 5288 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
02:44:52.0844 5288 clr_optimization_v4.0.30319_64 - ok
02:44:52.0874 5288 [ 50F92C943F18B070F166D019DFAB3D9A ] clwvd C:\Windows\system32\DRIVERS\clwvd.sys
02:44:52.0879 5288 clwvd - ok
02:44:52.0914 5288 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
02:44:52.0914 5288 CmBatt - ok
02:44:52.0924 5288 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
02:44:52.0924 5288 cmdide - ok
02:44:52.0974 5288 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
02:44:52.0984 5288 CNG - ok
02:44:53.0049 5288 [ 9F6DE1995A188615CEEE908E750A34ED ] CnxtHdAudService C:\Windows\system32\drivers\CHDRT64.sys
02:44:53.0064 5288 CnxtHdAudService - ok
02:44:53.0114 5288 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
02:44:53.0114 5288 Compbatt - ok
02:44:53.0129 5288 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
02:44:53.0134 5288 CompositeBus - ok
02:44:53.0139 5288 COMSysApp - ok
02:44:53.0204 5288 [ 78AF1C499BF02F9814DF959A04A4F9C9 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe
02:44:53.0209 5288 cphs - ok
02:44:53.0234 5288 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
02:44:53.0239 5288 crcdisk - ok
02:44:53.0289 5288 [ 9C01375BE382E834CC26D1B7EAF2C4FE ] CryptSvc C:\Windows\system32\cryptsvc.dll
02:44:53.0289 5288 CryptSvc - ok
02:44:53.0349 5288 [ F160B26B26BA4AFE8CECC12ED5AC231E ] CxAudMsg C:\Windows\system32\CxAudMsg64.exe
02:44:53.0589 5288 CxAudMsg - ok
02:44:53.0644 5288 [ 56F4750B7F0CE969E43DE2A76DDA5A5F ] DamageGuard C:\Windows\system32\DRIVERS\DamageGuardX64.sys
02:44:53.0649 5288 DamageGuard - ok
02:44:53.0739 5288 [ 75974DA59BA3D2E3DCE9386493A31F54 ] DamageGuardSvc C:\Program Files\Lenovo\Instant Reset\DamageGuardSvc.exe
02:44:53.0749 5288 DamageGuardSvc - ok
02:44:53.0809 5288 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
02:44:53.0814 5288 DcomLaunch - ok
02:44:53.0844 5288 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
02:44:53.0849 5288 defragsvc - ok
02:44:53.0869 5288 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
02:44:53.0869 5288 DfsC - ok
02:44:53.0894 5288 [ 5014042B07FE6CBE0E6C737AA3F1EBFC ] dgFltr C:\Windows\system32\drivers\dgFltrX64.sys
02:44:53.0894 5288 dgFltr - ok
02:44:53.0924 5288 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
02:44:53.0929 5288 Dhcp - ok
02:44:53.0969 5288 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
02:44:53.0969 5288 discache - ok
02:44:53.0999 5288 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\drivers\disk.sys
02:44:53.0999 5288 Disk - ok
02:44:54.0029 5288 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
02:44:54.0034 5288 Dnscache - ok
02:44:54.0044 5288 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
02:44:54.0049 5288 dot3svc - ok
02:44:54.0069 5288 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
02:44:54.0069 5288 DPS - ok
02:44:54.0094 5288 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
02:44:54.0094 5288 drmkaud - ok
02:44:54.0119 5288 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
02:44:54.0129 5288 DXGKrnl - ok
02:44:54.0164 5288 [ A0D5450B3D4689DCE4CBBC8268141C37 ] e.dentifier2 C:\Windows\system32\DRIVERS\aabed2.sys
02:44:54.0164 5288 e.dentifier2 - ok
02:44:54.0184 5288 EagleX64 - ok
02:44:54.0209 5288 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
02:44:54.0209 5288 EapHost - ok
02:44:54.0294 5288 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\drivers\evbda.sys
02:44:54.0344 5288 ebdrv - ok
02:44:54.0364 5288 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
02:44:54.0364 5288 EFS - ok
02:44:54.0409 5288 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
02:44:54.0414 5288 ehRecvr - ok
02:44:54.0429 5288 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
02:44:54.0429 5288 ehSched - ok
02:44:54.0479 5288 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\drivers\elxstor.sys
02:44:54.0484 5288 elxstor - ok
02:44:54.0504 5288 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
02:44:54.0504 5288 ErrDev - ok
02:44:54.0569 5288 [ 4B18C33EEDD15BD2AAF99807D36555B3 ] ETD C:\Windows\system32\DRIVERS\ETD.sys
02:44:54.0569 5288 ETD - ok
02:44:54.0599 5288 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
02:44:54.0604 5288 EventSystem - ok
02:44:54.0629 5288 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
02:44:54.0629 5288 exfat - ok
02:44:54.0649 5288 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
02:44:54.0649 5288 fastfat - ok
02:44:54.0709 5288 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
02:44:54.0719 5288 Fax - ok
02:44:54.0734 5288 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\drivers\fdc.sys
02:44:54.0734 5288 fdc - ok
02:44:54.0754 5288 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
02:44:54.0754 5288 fdPHost - ok
02:44:54.0779 5288 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
02:44:54.0779 5288 FDResPub - ok
02:44:54.0789 5288 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
02:44:54.0789 5288 FileInfo - ok
02:44:54.0799 5288 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
02:44:54.0799 5288 Filetrace - ok
02:44:54.0874 5288 [ BB0667B0171B632B97EA759515476F07 ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
02:44:54.0884 5288 FLEXnet Licensing Service - ok
02:44:54.0924 5288 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
02:44:54.0924 5288 flpydisk - ok
02:44:54.0934 5288 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
02:44:54.0939 5288 FltMgr - ok
02:44:54.0979 5288 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
02:44:54.0999 5288 FontCache - ok
02:44:55.0034 5288 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
02:44:55.0034 5288 FontCache3.0.0.0 - ok
02:44:55.0049 5288 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
02:44:55.0054 5288 FsDepends - ok
02:44:55.0074 5288 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
02:44:55.0074 5288 Fs_Rec - ok
02:44:55.0104 5288 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
02:44:55.0104 5288 fvevol - ok
02:44:55.0114 5288 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
02:44:55.0119 5288 gagp30kx - ok
02:44:55.0174 5288 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
02:44:55.0189 5288 gpsvc - ok
02:44:55.0254 5288 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
02:44:55.0259 5288 gupdate - ok
02:44:55.0289 5288 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
02:44:55.0289 5288 gupdatem - ok
02:44:55.0309 5288 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
02:44:55.0309 5288 hcw85cir - ok
02:44:55.0339 5288 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
02:44:55.0344 5288 HdAudAddService - ok
02:44:55.0364 5288 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
02:44:55.0364 5288 HDAudBus - ok
02:44:55.0364 5288 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
02:44:55.0369 5288 HidBatt - ok
02:44:55.0369 5288 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\drivers\hidbth.sys
02:44:55.0369 5288 HidBth - ok
02:44:55.0384 5288 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\drivers\hidir.sys
02:44:55.0389 5288 HidIr - ok
02:44:55.0399 5288 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\system32\hidserv.dll
02:44:55.0399 5288 hidserv - ok
02:44:55.0429 5288 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
02:44:55.0429 5288 HidUsb - ok
02:44:55.0454 5288 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
02:44:55.0454 5288 hkmsvc - ok
02:44:55.0474 5288 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
02:44:55.0479 5288 HomeGroupListener - ok
02:44:55.0499 5288 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
02:44:55.0504 5288 HomeGroupProvider - ok
02:44:55.0524 5288 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
02:44:55.0524 5288 HpSAMD - ok
02:44:55.0554 5288 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
02:44:55.0559 5288 HTTP - ok
02:44:55.0569 5288 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
02:44:55.0569 5288 hwpolicy - ok
02:44:55.0599 5288 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
02:44:55.0599 5288 i8042prt - ok
02:44:55.0629 5288 [ C224331A54571C8C9162F7714400BBBD ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys
02:44:55.0634 5288 iaStor - ok
02:44:55.0694 5288 [ 7D4B9A48430ED57ACA6373B71D5904CA ] IAStorDataMgrSvc C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
02:44:55.0699 5288 IAStorDataMgrSvc - ok
02:44:55.0719 5288 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
02:44:55.0724 5288 iaStorV - ok
02:44:55.0799 5288 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
02:44:55.0809 5288 idsvc - ok
02:44:55.0914 5288 [ A1CF07D24EDCDC6870535471654D957C ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
02:44:55.0994 5288 igfx - ok
02:44:56.0019 5288 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\drivers\iirsp.sys
02:44:56.0019 5288 iirsp - ok
02:44:56.0049 5288 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
02:44:56.0059 5288 IKEEXT - ok
02:44:56.0104 5288 [ 6C9FFFECA9FED31347D211C5D1FFBD2D ] IntcDAud C:\Windows\system32\DRIVERS\IntcDAud.sys
02:44:56.0104 5288 IntcDAud - ok
02:44:56.0159 5288 [ 832CE330DD987227B7DEA8C03F22AEFA ] Intel® Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
02:44:56.0865 5288 Intel® Capability Licensing Service Interface - ok
02:44:56.0885 5288 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
02:44:56.0885 5288 intelide - ok
02:44:56.0915 5288 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
02:44:56.0920 5288 intelppm - ok
02:44:56.0950 5288 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
02:44:56.0950 5288 IPBusEnum - ok
02:44:56.0955 5288 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
02:44:56.0955 5288 IpFilterDriver - ok
02:44:56.0995 5288 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
02:44:57.0000 5288 iphlpsvc - ok
02:44:57.0010 5288 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
02:44:57.0010 5288 IPMIDRV - ok
02:44:57.0015 5288 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
02:44:57.0015 5288 IPNAT - ok
02:44:57.0065 5288 [ 0F261EC4F514926177C70C1832374231 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
02:44:57.0070 5288 iPod Service - ok
02:44:57.0100 5288 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
02:44:57.0100 5288 IRENUM - ok
02:44:57.0105 5288 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
02:44:57.0110 5288 isapnp - ok
02:44:57.0140 5288 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
02:44:57.0145 5288 iScsiPrt - ok
02:44:57.0185 5288 [ 846354992EBB373F452EB9182D501B08 ] iusb3hcs C:\Windows\system32\DRIVERS\iusb3hcs.sys
02:44:57.0185 5288 iusb3hcs - ok
02:44:57.0205 5288 [ 1D88A23853387D34D52CC8F9DDBFC56C ] iusb3hub C:\Windows\system32\DRIVERS\iusb3hub.sys
02:44:57.0210 5288 iusb3hub - ok
02:44:57.0230 5288 [ FC5EFD7C797DF19DFB999F0605A7924E ] iusb3xhc C:\Windows\system32\DRIVERS\iusb3xhc.sys
02:44:57.0235 5288 iusb3xhc - ok
02:44:57.0310 5288 [ 09CA717536671E0896E07D239EE6740F ] jhi_service C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
02:44:57.0310 5288 jhi_service - ok
02:44:57.0345 5288 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
02:44:57.0345 5288 kbdclass - ok
02:44:57.0380 5288 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
02:44:57.0380 5288 kbdhid - ok
02:44:57.0390 5288 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
02:44:57.0395 5288 KeyIso - ok
02:44:57.0420 5288 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
02:44:57.0420 5288 KSecDD - ok
02:44:57.0450 5288 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
02:44:57.0450 5288 KSecPkg - ok
02:44:57.0470 5288 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
02:44:57.0470 5288 ksthunk - ok
02:44:57.0500 5288 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
02:44:57.0505 5288 KtmRm - ok
02:44:57.0535 5288 [ FC741259B7C22379EE83257D7CF91151 ] L1C C:\Windows\system32\DRIVERS\L1C62x64.sys
02:44:57.0535 5288 L1C - ok
02:44:57.0570 5288 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\system32\srvsvc.dll
02:44:57.0575 5288 LanmanServer - ok
02:44:57.0600 5288 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
02:44:57.0605 5288 LanmanWorkstation - ok
02:44:57.0630 5288 [ BE166935083F9C38EDFDC21B9A7A679B ] LHDmgr C:\Windows\system32\DRIVERS\LhdX64.sys
02:44:57.0635 5288 LHDmgr - ok
02:44:57.0670 5288 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
02:44:57.0670 5288 lltdio - ok
02:44:57.0695 5288 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
02:44:57.0695 5288 lltdsvc - ok
02:44:57.0710 5288 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
02:44:57.0710 5288 lmhosts - ok
02:44:57.0740 5288 [ A60D56228FF3EE7EC1A56A908924680E ] LMS C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
02:44:57.0745 5288 LMS - ok
02:44:57.0780 5288 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
02:44:57.0780 5288 LSI_FC - ok
02:44:57.0785 5288 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
02:44:57.0785 5288 LSI_SAS - ok
02:44:57.0790 5288 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
02:44:57.0790 5288 LSI_SAS2 - ok
02:44:57.0795 5288 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
02:44:57.0795 5288 LSI_SCSI - ok
02:44:57.0830 5288 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
02:44:57.0830 5288 luafv - ok
02:44:57.0855 5288 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
02:44:57.0860 5288 Mcx2Svc - ok
02:44:57.0885 5288 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\drivers\megasas.sys
02:44:57.0885 5288 megasas - ok
02:44:57.0915 5288 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
02:44:57.0915 5288 MegaSR - ok
02:44:57.0950 5288 [ 6B01B7414A105B9E51652089A03027CF ] MEIx64 C:\Windows\system32\DRIVERS\HECIx64.sys
02:44:57.0950 5288 MEIx64 - ok
02:44:57.0985 5288 Microsoft SharePoint Workspace Audit Service - ok
02:44:58.0020 5288 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
02:44:58.0020 5288 MMCSS - ok
02:44:58.0020 5288 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
02:44:58.0025 5288 Modem - ok
02:44:58.0055 5288 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
02:44:58.0055 5288 monitor - ok
02:44:58.0075 5288 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
02:44:58.0075 5288 mouclass - ok
02:44:58.0100 5288 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
02:44:58.0100 5288 mouhid - ok
02:44:58.0125 5288 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
02:44:58.0125 5288 mountmgr - ok
02:44:58.0165 5288 [ 9C3758018DED02F4AE53CCA1C5F084A2 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
02:44:58.0170 5288 MozillaMaintenance - ok
02:44:58.0205 5288 [ 05BF204EC0E82CC4A054DB189C8A3D84 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
02:44:58.0210 5288 MpFilter - ok
02:44:58.0245 5288 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
02:44:58.0245 5288 mpio - ok
02:44:58.0265 5288 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
02:44:58.0265 5288 mpsdrv - ok
02:44:58.0300 5288 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
02:44:58.0305 5288 MpsSvc - ok
02:44:58.0310 5288 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
02:44:58.0315 5288 MRxDAV - ok
02:44:58.0325 5288 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
02:44:58.0325 5288 mrxsmb - ok
02:44:58.0335 5288 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
02:44:58.0340 5288 mrxsmb10 - ok
02:44:58.0355 5288 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
02:44:58.0355 5288 mrxsmb20 - ok
02:44:58.0365 5288 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
02:44:58.0370 5288 msahci - ok
02:44:58.0390 5288 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
02:44:58.0390 5288 msdsm - ok
02:44:58.0410 5288 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
02:44:58.0410 5288 MSDTC - ok
02:44:58.0440 5288 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
02:44:58.0440 5288 Msfs - ok
02:44:58.0445 5288 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
02:44:58.0450 5288 mshidkmdf - ok
02:44:58.0455 5288 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
02:44:58.0455 5288 msisadrv - ok
02:44:58.0490 5288 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
02:44:58.0490 5288 MSiSCSI - ok
02:44:58.0495 5288 msiserver - ok
02:44:58.0530 5288 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
02:44:58.0530 5288 MSKSSRV - ok
02:44:58.0600 5288 [ CC8E4F72F21340A4D3A3D4DB50313EF5 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
02:44:58.0600 5288 MsMpSvc - ok
02:44:58.0625 5288 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
02:44:58.0630 5288 MSPCLOCK - ok
02:44:58.0630 5288 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
02:44:58.0630 5288 MSPQM - ok
02:44:58.0650 5288 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
02:44:58.0655 5288 MsRPC - ok
02:44:58.0665 5288 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
02:44:58.0665 5288 mssmbios - ok
02:44:58.0690 5288 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
02:44:58.0690 5288 MSTEE - ok
02:44:58.0695 5288 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
02:44:58.0695 5288 MTConfig - ok
02:44:58.0710 5288 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
02:44:58.0715 5288 Mup - ok
02:44:58.0740 5288 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
02:44:58.0750 5288 napagent - ok
02:44:58.0785 5288 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
02:44:58.0790 5288 NativeWifiP - ok
02:44:58.0830 5288 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
02:44:58.0835 5288 NDIS - ok
02:44:58.0850 5288 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
02:44:58.0850 5288 NdisCap - ok
02:44:58.0880 5288 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
02:44:58.0880 5288 NdisTapi - ok
02:44:58.0895 5288 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
02:44:58.0895 5288 Ndisuio - ok
02:44:58.0915 5288 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
02:44:58.0915 5288 NdisWan - ok
02:44:58.0930 5288 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
02:44:58.0935 5288 NDProxy - ok
02:44:58.0960 5288 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
02:44:58.0960 5288 NetBIOS - ok
02:44:58.0975 5288 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
02:44:58.0980 5288 NetBT - ok
02:44:59.0000 5288 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
02:44:59.0000 5288 Netlogon - ok
02:44:59.0045 5288 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
02:44:59.0045 5288 Netman - ok
02:44:59.0065 5288 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
02:44:59.0070 5288 netprofm - ok
02:44:59.0090 5288 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
02:44:59.0090 5288 NetTcpPortSharing - ok
02:44:59.0105 5288 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
02:44:59.0105 5288 nfrd960 - ok
02:44:59.0130 5288 [ 5FF89F20317309D28AC1EDEB0CD1BA72 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
02:44:59.0130 5288 NisDrv - ok
02:44:59.0150 5288 [ 79E80B10FE8F6662E0C9162A68C43444 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
02:44:59.0155 5288 NisSrv - ok
02:44:59.0190 5288 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
02:44:59.0190 5288 NlaSvc - ok
02:44:59.0225 5288 [ 907B5E1E4A592E5EDC5E4CCBDE4863C2 ] nmwcd C:\Windows\system32\drivers\ccdcmbx64.sys
02:44:59.0225 5288 nmwcd - ok
02:44:59.0240 5288 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
02:44:59.0240 5288 Npfs - ok
02:44:59.0265 5288 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
02:44:59.0265 5288 nsi - ok
02:44:59.0281 5288 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
02:44:59.0281 5288 nsiproxy - ok
02:44:59.0326 5288 [ E453ACF4E7D44E5530B5D5F2B9CA8563 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
02:44:59.0341 5288 Ntfs - ok
02:44:59.0366 5288 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
02:44:59.0371 5288 Null - ok
02:44:59.0631 5288 [ 5104BAC2DA2A5BDD86AC6B0708B00F06 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
02:44:59.0836 5288 nvlddmkm - ok
02:44:59.0876 5288 [ 918841B2454F4F2BD94479692079490B ] nvpciflt C:\Windows\system32\DRIVERS\nvpciflt.sys
02:44:59.0876 5288 nvpciflt - ok
02:44:59.0911 5288 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
02:44:59.0916 5288 nvraid - ok
02:44:59.0916 5288 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
02:44:59.0921 5288 nvstor - ok
02:44:59.0951 5288 [ DDFAFCE89A5C93D04712B86F94E9FCBA ] nvsvc C:\Windows\system32\nvvsvc.exe
02:44:59.0956 5288 nvsvc - ok
02:45:00.0016 5288 [ 84E035225474E48CD3A6A3CE52332095 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
02:45:00.0026 5288 nvUpdatusService - ok
02:45:00.0051 5288 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
02:45:00.0051 5288 nv_agp - ok
02:45:00.0066 5288 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
02:45:00.0066 5288 ohci1394 - ok
02:45:00.0126 5288 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
02:45:00.0126 5288 ose64 - ok
02:45:00.0271 5288 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
02:45:00.0356 5288 osppsvc - ok
02:45:00.0386 5288 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
02:45:00.0391 5288 p2pimsvc - ok
02:45:00.0406 5288 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
02:45:00.0411 5288 p2psvc - ok
02:45:00.0436 5288 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\drivers\parport.sys
02:45:00.0436 5288 Parport - ok
02:45:00.0481 5288 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
02:45:00.0481 5288 partmgr - ok
02:45:00.0516 5288 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
02:45:00.0521 5288 PcaSvc - ok
02:45:00.0531 5288 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
02:45:00.0536 5288 pci - ok
02:45:00.0551 5288 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
02:45:00.0556 5288 pciide - ok
02:45:00.0566 5288 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
02:45:00.0571 5288 pcmcia - ok
02:45:00.0591 5288 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
02:45:00.0591 5288 pcw - ok
02:45:00.0616 5288 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
02:45:00.0621 5288 PEAUTH - ok
02:45:00.0681 5288 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
02:45:00.0681 5288 PerfHost - ok
02:45:00.0731 5288 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
02:45:00.0751 5288 pla - ok
02:45:00.0791 5288 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
02:45:00.0796 5288 PlugPlay - ok
02:45:00.0806 5288 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
02:45:00.0806 5288 PNRPAutoReg - ok
02:45:00.0816 5288 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
02:45:00.0821 5288 PNRPsvc - ok
02:45:00.0846 5288 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
02:45:00.0851 5288 PolicyAgent - ok
02:45:00.0861 5288 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
02:45:00.0866 5288 Power - ok
02:45:00.0891 5288 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
02:45:00.0896 5288 PptpMiniport - ok
02:45:00.0921 5288 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\drivers\processr.sys
02:45:00.0926 5288 Processor - ok
02:45:00.0951 5288 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
02:45:00.0951 5288 ProfSvc - ok
02:45:00.0966 5288 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
02:45:00.0966 5288 ProtectedStorage - ok
02:45:00.0991 5288 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
02:45:00.0991 5288 Psched - ok
02:45:01.0021 5288 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
02:45:01.0036 5288 ql2300 - ok
02:45:01.0046 5288 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
02:45:01.0046 5288 ql40xx - ok
02:45:01.0071 5288 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
02:45:01.0076 5288 QWAVE - ok
02:45:01.0081 5288 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
02:45:01.0086 5288 QWAVEdrv - ok
02:45:01.0086 5288 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
02:45:01.0091 5288 RasAcd - ok
02:45:01.0131 5288 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
02:45:01.0131 5288 RasAgileVpn - ok
02:45:01.0146 5288 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
02:45:01.0146 5288 RasAuto - ok
02:45:01.0161 5288 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
02:45:01.0161 5288 Rasl2tp - ok
02:45:01.0201 5288 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
02:45:01.0206 5288 RasMan - ok
02:45:01.0221 5288 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
02:45:01.0221 5288 RasPppoe - ok
02:45:01.0226 5288 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
02:45:01.0226 5288 RasSstp - ok
02:45:01.0236 5288 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
02:45:01.0241 5288 rdbss - ok
02:45:01.0266 5288 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\drivers\rdpbus.sys
02:45:01.0266 5288 rdpbus - ok
02:45:01.0276 5288 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
02:45:01.0276 5288 RDPCDD - ok
02:45:01.0296 5288 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
02:45:01.0296 5288 RDPENCDD - ok
02:45:01.0306 5288 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
02:45:01.0306 5288 RDPREFMP - ok
02:45:01.0351 5288 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
02:45:01.0351 5288 RdpVideoMiniport - ok
02:45:01.0386 5288 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
02:45:01.0386 5288 RDPWD - ok
02:45:01.0416 5288 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
02:45:01.0416 5288 rdyboost - ok
02:45:01.0451 5288 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
02:45:01.0456 5288 RemoteAccess - ok
02:45:01.0486 5288 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
02:45:01.0496 5288 RemoteRegistry - ok
02:45:01.0521 5288 [ 3DD798846E2C28102B922C56E71B7932 ] RFCOMM C:\Windows\system32\DRIVERS\rfcomm.sys
02:45:01.0526 5288 RFCOMM - ok
02:45:01.0551 5288 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
02:45:01.0556 5288 RpcEptMapper - ok
02:45:01.0571 5288 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
02:45:01.0576 5288 RpcLocator - ok
02:45:01.0596 5288 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
02:45:01.0601 5288 RpcSs - ok
02:45:01.0631 5288 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
02:45:01.0636 5288 rspndr - ok
02:45:01.0666 5288 [ 88AB579F407A3D02918B8DCC4E6E34B3 ] RSUSBVSTOR C:\Windows\system32\Drivers\RtsUVStor.sys
02:45:01.0666 5288 RSUSBVSTOR - ok
02:45:01.0686 5288 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
02:45:01.0686 5288 SamSs - ok
02:45:01.0706 5288 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
02:45:01.0711 5288 sbp2port - ok
02:45:01.0731 5288 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
02:45:01.0736 5288 SCardSvr - ok
02:45:01.0761 5288 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
02:45:01.0761 5288 scfilter - ok
02:45:01.0791 5288 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
02:45:01.0801 5288 Schedule - ok
02:45:01.0826 5288 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
02:45:01.0826 5288 SCPolicySvc - ok
02:45:01.0846 5288 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
02:45:01.0846 5288 SDRSVC - ok
02:45:01.0891 5288 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
02:45:01.0891 5288 secdrv - ok
02:45:01.0901 5288 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
02:45:01.0901 5288 seclogon - ok
02:45:01.0941 5288 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\System32\sens.dll
02:45:01.0946 5288 SENS - ok
02:45:01.0971 5288 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
02:45:01.0976 5288 SensrSvc - ok
02:45:02.0011 5288 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\drivers\serenum.sys
02:45:02.0011 5288 Serenum - ok
02:45:02.0026 5288 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\drivers\serial.sys
02:45:02.0031 5288 Serial - ok
02:45:02.0051 5288 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\drivers\sermouse.sys
02:45:02.0051 5288 sermouse - ok
02:45:02.0076 5288 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
02:45:02.0081 5288 SessionEnv - ok
02:45:02.0086 5288 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
02:45:02.0086 5288 sffdisk - ok
02:45:02.0111 5288 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
02:45:02.0116 5288 sffp_mmc - ok
02:45:02.0116 5288 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
02:45:02.0116 5288 sffp_sd - ok
02:45:02.0121 5288 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
02:45:02.0126 5288 sfloppy - ok
02:45:02.0156 5288 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
02:45:02.0161 5288 SharedAccess - ok
02:45:02.0191 5288 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
02:45:02.0196 5288 ShellHWDetection - ok
02:45:02.0201 5288 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
02:45:02.0201 5288 SiSRaid2 - ok
02:45:02.0206 5288 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
02:45:02.0206 5288 SiSRaid4 - ok
02:45:02.0256 5288 [ 8C4F0DCC6A5100D48F9B2F950CDD220F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
02:45:02.0256 5288 SkypeUpdate - ok
02:45:02.0276 5288 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
02:45:02.0276 5288 Smb - ok
02:45:02.0306 5288 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
02:45:02.0311 5288 SNMPTRAP - ok
02:45:02.0466 5288 [ 56B69DE178E12F4C2A25AC18E1D0BFB0 ] SNPSTD3 C:\Windows\system32\DRIVERS\snpstd3.sys
02:45:02.0881 5288 SNPSTD3 - ok
02:45:02.0921 5288 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
02:45:02.0921 5288 spldr - ok
02:45:02.0961 5288 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
02:45:02.0971 5288 Spooler - ok
02:45:03.0066 5288 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
02:45:03.0101 5288 sppsvc - ok
02:45:03.0116 5288 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
02:45:03.0116 5288 sppuinotify - ok
02:45:03.0141 5288 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
02:45:03.0146 5288 srv - ok
02:45:03.0176 5288 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
02:45:03.0181 5288 srv2 - ok
02:45:03.0196 5288 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
02:45:03.0201 5288 srvnet - ok
02:45:03.0231 5288 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
02:45:03.0236 5288 SSDPSRV - ok
02:45:03.0256 5288 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
02:45:03.0256 5288 SstpSvc - ok
02:45:03.0266 5288 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\drivers\stexstor.sys
02:45:03.0266 5288 stexstor - ok
02:45:03.0306 5288 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
02:45:03.0311 5288 stisvc - ok
02:45:03.0331 5288 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
02:45:03.0331 5288 swenum - ok
02:45:03.0341 5288 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
02:45:03.0351 5288 swprv - ok
02:45:03.0396 5288 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
02:45:03.0416 5288 SysMain - ok
02:45:03.0441 5288 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
02:45:03.0446 5288 TabletInputService - ok
02:45:03.0461 5288 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
02:45:03.0466 5288 TapiSrv - ok
02:45:03.0476 5288 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
02:45:03.0481 5288 TBS - ok
02:45:03.0531 5288 [ 37608401DFDB388CAF66917F6B2D6FB0 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
02:45:03.0551 5288 Tcpip - ok
02:45:03.0581 5288 [ 37608401DFDB388CAF66917F6B2D6FB0 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
02:45:03.0591 5288 TCPIP6 - ok
02:45:03.0621 5288 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
02:45:03.0621 5288 tcpipreg - ok
02:45:03.0651 5288 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
02:45:03.0651 5288 TDPIPE - ok
02:45:03.0676 5288 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
02:45:03.0676 5288 TDTCP - ok
02:45:03.0691 5288 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
02:45:03.0691 5288 tdx - ok
02:45:03.0706 5288 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
02:45:03.0711 5288 TermDD - ok
02:45:03.0751 5288 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
02:45:03.0756 5288 TermService - ok
02:45:03.0771 5288 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
02:45:03.0771 5288 Themes - ok
02:45:03.0786 5288 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
02:45:03.0786 5288 THREADORDER - ok
02:45:03.0806 5288 [ DBCC20C02E8A3E43B03C304A4E40A84F ] TPM C:\Windows\system32\drivers\tpm.sys
02:45:03.0811 5288 TPM - ok
02:45:03.0826 5288 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
02:45:03.0826 5288 TrkWks - ok
02:45:03.0876 5288 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
02:45:03.0876 5288 TrustedInstaller - ok
02:45:03.0901 5288 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
02:45:03.0901 5288 tssecsrv - ok
02:45:03.0931 5288 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
02:45:03.0931 5288 TsUsbFlt - ok
02:45:03.0961 5288 [ AD64450A4ABE076F5CB34CC08EEACB07 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
02:45:03.0961 5288 TsUsbGD - ok
02:45:04.0006 5288 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
02:45:04.0011 5288 tunnel - ok
02:45:04.0036 5288 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
02:45:04.0036 5288 uagp35 - ok
02:45:04.0061 5288 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
02:45:04.0066 5288 udfs - ok
02:45:04.0091 5288 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
02:45:04.0091 5288 UI0Detect - ok
02:45:04.0121 5288 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
02:45:04.0121 5288 uliagpkx - ok
02:45:04.0141 5288 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
02:45:04.0146 5288 umbus - ok
02:45:04.0146 5288 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\drivers\umpass.sys
02:45:04.0151 5288 UmPass - ok
02:45:04.0236 5288 [ A0153CC9D28568A10BDAEE5EC612CFC8 ] UNS C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
02:45:04.0241 5288 UNS - ok
02:45:04.0281 5288 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
02:45:04.0286 5288 upnphost - ok
02:45:04.0331 5288 [ 43228F8EDD1B0BCDD3145AD246E63D39 ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
02:45:04.0331 5288 USBAAPL64 - ok
02:45:04.0361 5288 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
02:45:04.0366 5288 usbaudio - ok
02:45:04.0401 5288 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
02:45:04.0406 5288 usbccgp - ok
02:45:04.0426 5288 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
02:45:04.0426 5288 usbcir - ok
02:45:04.0446 5288 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
02:45:04.0446 5288 usbehci - ok
02:45:04.0481 5288 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
02:45:04.0486 5288 usbhub - ok
02:45:04.0501 5288 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\drivers\usbohci.sys
02:45:04.0501 5288 usbohci - ok
02:45:04.0531 5288 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
02:45:04.0531 5288 usbprint - ok
02:45:04.0561 5288 [ AAA2513C8AED8B54B189FD0C6B1634C0 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
02:45:04.0561 5288 usbscan - ok
02:45:04.0576 5288 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
02:45:04.0576 5288 USBSTOR - ok
02:45:04.0581 5288 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
02:45:04.0586 5288 usbuhci - ok
02:45:04.0611 5288 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
02:45:04.0616 5288 usbvideo - ok
02:45:04.0636 5288 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
02:45:04.0641 5288 UxSms - ok
02:45:04.0646 5288 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
02:45:04.0646 5288 VaultSvc - ok
02:45:04.0666 5288 [ FD911873C0BB6945FA38C16E9A2B58F9 ] VClone C:\Windows\system32\DRIVERS\VClone.sys
02:45:04.0666 5288 VClone - ok
02:45:04.0691 5288 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
02:45:04.0696 5288 vdrvroot - ok
02:45:04.0716 5288 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
02:45:04.0721 5288 vds - ok
02:45:04.0741 5288 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
02:45:04.0741 5288 vga - ok
02:45:04.0746 5288 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
02:45:04.0746 5288 VgaSave - ok
02:45:04.0766 5288 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
02:45:04.0766 5288 vhdmp - ok
02:45:04.0771 5288 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
02:45:04.0771 5288 viaide - ok
02:45:04.0821 5288 [ BEEC7DB99737B083C62A84D1328571D2 ] vm332avs C:\Windows\system32\Drivers\vm332avs.sys
02:45:04.0826 5288 vm332avs - ok
02:45:04.0836 5288 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
02:45:04.0841 5288 volmgr - ok
02:45:04.0851 5288 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
02:45:04.0856 5288 volmgrx - ok
02:45:04.0871 5288 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
02:45:04.0876 5288 volsnap - ok
02:45:04.0901 5288 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
02:45:04.0906 5288 vsmraid - ok
02:45:04.0946 5288 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
02:45:04.0961 5288 VSS - ok
02:45:04.0976 5288 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
02:45:04.0976 5288 vwifibus - ok
02:45:05.0001 5288 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
02:45:05.0006 5288 vwififlt - ok
02:45:05.0031 5288 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
02:45:05.0031 5288 vwifimp - ok
02:45:05.0071 5288 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
02:45:05.0076 5288 W32Time - ok
02:45:05.0116 5288 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\drivers\wacompen.sys
02:45:05.0116 5288 WacomPen - ok
02:45:05.0161 5288 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
02:45:05.0161 5288 WANARP - ok
02:45:05.0171 5288 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
02:45:05.0171 5288 Wanarpv6 - ok
02:45:05.0226 5288 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
02:45:05.0236 5288 WatAdminSvc - ok
02:45:05.0276 5288 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
02:45:05.0291 5288 wbengine - ok
02:45:05.0306 5288 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
02:45:05.0311 5288 WbioSrvc - ok
02:45:05.0326 5288 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
02:45:05.0331 5288 wcncsvc - ok
02:45:05.0351 5288 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
02:45:05.0351 5288 WcsPlugInService - ok
02:45:05.0376 5288 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\drivers\wd.sys
02:45:05.0376 5288 Wd - ok
02:45:05.0401 5288 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
02:45:05.0411 5288 Wdf01000 - ok
02:45:05.0421 5288 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
02:45:05.0426 5288 WdiServiceHost - ok
02:45:05.0426 5288 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
02:45:05.0431 5288 WdiSystemHost - ok
02:45:05.0446 5288 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
02:45:05.0451 5288 WebClient - ok
02:45:05.0486 5288 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
02:45:05.0491 5288 Wecsvc - ok
02:45:05.0511 5288 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
02:45:05.0511 5288 wercplsupport - ok
02:45:05.0531 5288 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
02:45:05.0536 5288 WerSvc - ok
02:45:05.0571 5288 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
02:45:05.0571 5288 WfpLwf - ok
02:45:05.0581 5288 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
02:45:05.0581 5288 WIMMount - ok
02:45:05.0606 5288 WinDefend - ok
02:45:05.0611 5288 WinHttpAutoProxySvc - ok
02:45:05.0671 5288 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
02:45:05.0676 5288 Winmgmt - ok
02:45:05.0746 5288 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
02:45:05.0776 5288 WinRM - ok
02:45:05.0866 5288 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
02:45:05.0866 5288 WinUsb - ok
02:45:05.0901 5288 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
02:45:05.0911 5288 Wlansvc - ok
02:45:06.0046 5288 [ 357CABBF155AFD1D3926E62539D2A3A7 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
02:45:06.0071 5288 wlidsvc - ok
02:45:06.0111 5288 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
02:45:06.0111 5288 WmiAcpi - ok
02:45:06.0146 5288 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
02:45:06.0151 5288 wmiApSrv - ok
02:45:06.0196 5288 WMPNetworkSvc - ok
02:45:06.0221 5288 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
02:45:06.0226 5288 WPCSvc - ok
02:45:06.0256 5288 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
02:45:06.0261 5288 WPDBusEnum - ok
02:45:06.0286 5288 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
02:45:06.0286 5288 ws2ifsl - ok
02:45:06.0296 5288 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\System32\wscsvc.dll
02:45:06.0301 5288 wscsvc - ok
02:45:06.0306 5288 WSearch - ok
02:45:06.0331 5288 [ 83575C43B2BFE9AB0661A7F957E843C0 ] wsvd C:\Windows\system32\DRIVERS\wsvd.sys
02:45:06.0336 5288 wsvd - ok
02:45:06.0391 5288 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
02:45:06.0411 5288 wuauserv - ok
02:45:06.0436 5288 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
02:45:06.0436 5288 WudfPf - ok
02:45:06.0466 5288 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
02:45:06.0466 5288 WUDFRd - ok
02:45:06.0496 5288 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
02:45:06.0496 5288 wudfsvc - ok
02:45:06.0526 5288 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
02:45:06.0531 5288 WwanSvc - ok
02:45:06.0576 5288 [ D65B42FBF19C676AA01AE95EC62F7764 ] ZAtheros Bt&Wlan Coex Agent C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
02:45:06.0601 5288 ZAtheros Bt&Wlan Coex Agent - ok
02:45:06.0631 5288 ================ Scan global ===============================
02:45:06.0666 5288 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
02:45:06.0691 5288 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
02:45:06.0696 5288 [ 9E479C2B605C25DA4971ABA36250FAEF ] C:\Windows\system32\winsrv.dll
02:45:06.0716 5288 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
02:45:06.0741 5288 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
02:45:06.0746 5288 [Global] - ok
02:45:06.0746 5288 ================ Scan MBR ==================================
02:45:06.0761 5288 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
02:45:06.0926 5288 \Device\Harddisk0\DR0 - ok
02:45:06.0926 5288 ================ Scan VBR ==================================
02:45:06.0931 5288 [ 701C158016624478CAC86C979929B7AE ] \Device\Harddisk0\DR0\Partition1
02:45:06.0931 5288 \Device\Harddisk0\DR0\Partition1 - ok
02:45:06.0961 5288 [ 1C115F7A07A81D097C07A7016198979B ] \Device\Harddisk0\DR0\Partition2
02:45:06.0961 5288 \Device\Harddisk0\DR0\Partition2 - ok
02:45:06.0996 5288 [ 1D8C1FE2F820BA7A81B829DE287E9EF8 ] \Device\Harddisk0\DR0\Partition3
02:45:06.0996 5288 \Device\Harddisk0\DR0\Partition3 - ok
02:45:06.0996 5288 ============================================================
02:45:06.0996 5288 Scan finished
02:45:06.0996 5288 ============================================================
02:45:07.0011 7036 Detected object count: 0
02:45:07.0011 7036 Actual detected object count: 0

aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-01-31 02:49:12
-----------------------------
02:49:12.901 OS Version: Windows x64 6.1.7601 Service Pack 1
02:49:12.901 Number of processors: 4 586 0x3A09
02:49:12.901 ComputerName: *** UserName:
02:49:14.797 Initialize success
02:50:18.830 AVAST engine defs: 13013000
02:51:15.258 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
02:51:15.263 Disk 0 Vendor: ST1000LM 2AR1 Size: 953869MB BusType: 3
02:51:15.273 Disk 0 MBR read successfully
02:51:15.278 Disk 0 MBR scan
02:51:15.283 Disk 0 Windows 7 default MBR code
02:51:15.293 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 200 MB offset 2048
02:51:15.328 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 907587 MB offset 411648
02:51:15.373 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 26080 MB offset 1859149824
02:51:15.403 Disk 0 Partition 4 00 12 Compaq diag NTFS 20001 MB offset 1912561664
02:51:15.518 Disk 0 scanning C:\Windows\system32\drivers
02:51:28.659 Service scanning
02:51:59.803 Modules scanning
02:51:59.808 Disk 0 trace - called modules:
02:52:00.143 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
02:52:00.153 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800a011060]
02:52:00.158 3 CLASSPNP.SYS[fffff88001d9c43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8007774050]
02:52:01.833 AVAST engine scan C:\Windows
02:52:06.033 AVAST engine scan C:\Windows\system32
02:55:29.051 AVAST engine scan C:\Windows\system32\drivers
02:55:44.848 AVAST engine scan C:\Users\***
03:03:48.938 AVAST engine scan C:\ProgramData
03:24:33.072 Scan finished successfully
03:26:37.930 Disk 0 MBR has been saved successfully to "C:\Users\***\Desktop\MBR.dat"
03:26:37.970 The log file has been saved successfully to "C:\Users\***\Desktop\aswMBR.txt"

#9 Corradio

Corradio
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 09:56 PM

what can i do next? should i delete the Exploit:JS/Blacole.GP-file from Microsoft Security Essentials - quarantine??

#10 Corradio

Corradio
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 10:25 PM

the scan from ESET scanner came back clean as well

#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:54 AM

Posted 30 January 2013 - 10:28 PM

You can delete it. A file in quaratine can no longer harm your machine. see Clean, Quarantine, or Delete?


JS/Blacole is a detection for a component of the Blackhole exploit kit - a kit used by attackers to distribute malware. Attackers install the kit onto a server, and then when you visit the compromised server, the kit attempts to exploit various, multiple vulnerabilities on your computer in order to install malware. For example, if you browsed a compromised website containing the exploit pack using a vulnerable computer, malware could be downloaded and installed onto your computer.

Typically, the Blackhole exploit kit attempts to exploit vulnerabilities in applications such as Oracle Java, Sun Java, Adobe Acrobat and Adobe Reader.


So wait for naren's next reply.
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#12 Corradio

Corradio
  • Topic Starter

  • Members
  • 8 posts
  • OFFLINE
  •  
  • Local time:11:54 AM

Posted 30 January 2013 - 10:44 PM

Alright I deleted it with Microsoft Security Essentials, rebooted and ran another scan. Everything seems fine. Is there any other way to be sure that my PC is safe?
Thanks for your help

#13 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:06:54 AM

Posted 31 January 2013 - 09:48 AM

OK, Lets see if we can see any exploits.


MiniToolBox
Please download MiniToolBox, save it to your desktop and run it.Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.

Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
>>>

ADW Cleaner

Please download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • You will be prompted to restart your computer. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users