Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Need help with persistent rootkit removal please!!!


  • This topic is locked This topic is locked
9 replies to this topic

#1 nimble

nimble

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 19 May 2013 - 03:20 PM

Hello forum...I have an interesting challenge for someone. My gateway netbook has been infected with some sort of super rootkit. It returns after a Dban wipe and just about any other format program. I even tried linux dd wipe commands and still same result. On a clean install my o/s operating logs show errors and tampering even before I go online to update. I also have a desktop with the same issue but i would like to get this netbook clean first. This is a very stealth virus and hides from my main antivirus programs. The only one program that detects it was Hitmanpro for a split second as a Volume boot sector virus but the virus quickly erases the finding so i recieve a clean scan (wth)! This virus really doesn't lockup my pc or give blod's. I know it's doing background duties and prolly hogging bandwith and cpu power. Gmer also shows bad registry keys in red but can't remove them. It appears this rootkit has some sort of encrypt hidden volumes on the harddrive. Ok right now this netbook has a clean 1 day old reinstall of windows 7 home 32bit genuine with just windows defender and no other antivirus that would just be modified not to work anyway. This pc is wireless to my modem/router. For now i can see setup logs of the privilege escalation and other stuff and some encypted mess. Also seems like some dude in witchita kansas is one of the hackers because his ip is always in my logs. Even changes his mac to bypass my firewall. Like i said i have tried live linux cd's, wipe's and rootkit scanners and nothing seems to work. Even replaced the whole dang hard drive for it to only return again. Help is needed!



BC AdBot (Login to Remove)

 


#2 nimble

nimble
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 21 May 2013 - 01:20 PM

Title was: rootkit/hacker controlling pc...logs included ~ OB
 
 
Hello everyone. This is my second time trying to post logs because my ie keeps shuting down. Apparently someone does not want this virus removed! I already described some problems in a previous post. I believe it is some sort of rootkit with backdoor ability. Here is a log and screen shot.
 
DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16576
Run by OFFICE at 12:43:17 on 2013-05-21
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.1979.1258 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{A7D230A1-4993-414D-8290-59CEBB4A7DAF} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{A7D230A1-4993-414D-8290-59CEBB4A7DAF}\14E64627F696461405 : DHCPNameServer = 192.168.43.1
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-6-10 50688]
R3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\drivers\NETw5s32.sys [2010-1-13 6755840]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-5-19 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2013-5-18 1343400]
.
=============== Created Last 30 ================
.
2013-05-21 19:00:50 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-05-21 17:31:52 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-05-21 17:30:56 1796096 ----a-w- c:\windows\system32\authui.dll
2013-05-21 17:30:56 101720 ----a-w- c:\windows\system32\consent.exe
2013-05-21 17:30:55 47104 ----a-w- c:\windows\system32\appinfo.dll
2013-05-21 17:28:45 7016152 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-05-21 17:28:34 7016152 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{9b75946d-c0da-4f1c-b7c8-d1e202eb0ae4}\mpengine.dll
2013-05-19 23:05:45 -------- d-----w- c:\windows\system32\SPReview
2013-05-19 23:05:20 -------- d-----w- c:\windows\system32\EventProviders
2013-05-19 21:44:59 2522624 ----a-w- c:\windows\system32\dbgeng.dll
2013-05-19 21:43:56 189952 ----a-w- c:\windows\system32\wdscore.dll
2013-05-19 21:43:46 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2013-05-19 21:43:46 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2013-05-19 21:43:46 189952 ----a-w- c:\program files\windows portable devices\sqmapi.dll
2013-05-19 21:43:43 189952 ----a-w- c:\windows\system32\sqmapi.dll
2013-05-19 04:57:44 -------- d-sh--w- c:\windows\Installer
2013-05-19 04:48:42 -------- d-----w- c:\windows\system32\Wat
2013-05-19 03:01:36 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-05-19 03:01:36 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-05-19 03:01:36 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-05-19 02:22:29 -------- d-----w- C:\Intel
2013-05-19 02:17:54 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-05-19 02:13:32 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-05-19 02:13:32 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-05-19 02:13:32 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-05-19 02:12:21 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-05-19 02:12:21 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-05-19 02:12:21 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-05-19 02:12:21 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-05-19 02:12:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-05-19 02:12:21 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-05-19 02:12:21 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-05-19 02:10:25 5120 ----a-w- c:\windows\system32\wmi.dll
2013-05-19 02:10:25 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-05-19 02:10:25 159232 ----a-w- c:\windows\system32\imagehlp.dll
2013-05-19 01:59:11 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-05-19 01:59:11 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-05-19 01:59:10 36864 ----a-w- c:\windows\system32\tsgqec.dll
2013-05-19 01:59:02 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-05-19 01:59:02 1159680 ----a-w- c:\windows\system32\crypt32.dll
2013-05-19 01:59:02 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-05-19 01:57:29 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-19 01:56:53 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2013-05-19 01:55:59 642048 ----a-w- c:\windows\system32\CPFilters.dll
2013-05-19 01:49:34 123904 ----a-w- c:\windows\system32\poqexec.exe
2013-05-19 01:49:07 107520 ----a-w- c:\windows\system32\cdd.dll
2013-05-19 01:49:03 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2013-05-19 01:49:03 1137664 ----a-w- c:\windows\system32\mfc42.dll
2013-05-19 01:47:56 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2013-05-19 01:45:08 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2013-05-19 01:45:04 2048 ----a-w- c:\windows\system32\tzres.dll
2013-05-19 01:44:06 163504 ----a-w- c:\programdata\microsoft\windows\sqm\manifest\Sqm10144.bin
2013-05-19 01:41:14 826880 ----a-w- c:\windows\system32\rdpcore.dll
2013-05-19 01:41:14 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-05-19 01:41:14 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys
2013-05-18 23:02:58 -------- d-----w- c:\users\office\appdata\local\Diagnostics
2013-05-18 22:50:57 -------- d-----w- c:\windows\Panther
2013-05-18 22:45:35 -------- d-----w- c:\users\office\appdata\local\ElevatedDiagnostics
2013-05-18 22:35:54 -------- d-sh--w- C:\Recovery
2013-05-18 22:28:36 -------- d-----w- c:\windows\system32\wbem\Performance
.
==================== Find3M  ====================
.
2013-05-21 19:00:27 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-21 04:46:50 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-04-13 04:45:16 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 13:45:29 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 05:18:40 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 05:18:40 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 03:14:06 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-03-19 05:04:10 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 04:53:27 186368 ----a-w- c:\windows\system32\wwansvc.dll
2013-03-19 04:48:45 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 03:33:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-03-19 02:49:16 69632 ----a-w- c:\windows\system32\smss.exe
.
============= FINISH: 12:44:22.75 ===============

Attached Files


Edited by Orange Blossom, 23 May 2013 - 09:59 AM.
Merged topics. ~ OB


#3 nimble

nimble
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 23 May 2013 - 12:43 PM

Should I include a gmer log with more details guys? That's about the only scanner that really showed the rootkit/virus activity.



#4 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:05:49 PM

Posted 23 May 2013 - 07:57 PM

Hello nimble, and  :welcome: to the Virus/Trojan/Spyware/Malware Removal forum.

I am oneof4, and I am here to help you!

  • I ask that you refrain from running tools other than those I suggest to you while I am cleaning up your computer. The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.

 

  • Please perform all steps in the order received and do not proceed if you need clarification.

 

  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems please stop and tell me about it. When your computer is clean I will alert you of such. I will also provide you with detailed suggestions for prevention.

 

  • At the top right-center  of the topic you will see a button called Watch Topic. If you click on this, another page will open. Please choose Immediate Notification and then clicking on Proceed you will be advised when we respond to your topic and facilitate the cleaning of your machine.

 

  • If after 5 days you have not replied to this topic, I will assume it has been abandoned, and I will close it.

 

  • I would also like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. :heart: Please be courteous and appreciative for the assistance provided!

 

  • Again I would like to remind you to make no further changes to your computer unless I direct you to do so. Your computer fix will be based on the current condition of your computer! Any changes might delay my ability to help you.

==========

We need to see some information about what is happening in your machine.  Please perform the following scans:

Download Security Check by screen317 from http://screen317.spywareinfoforum.org/SecurityCheck.exe or http://screen317.changelog.fr/SecurityCheck.exe.

 

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

==========

 

  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool.  No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.

Please note:  You may have to disable any script protection running if the scan fails to run.  After downloading the tool, disconnect from the internet and disable all antivirus protection.  Run the scan, enable your A/V and reconnect to the internet.  

Information on A/V control http://www.bleepingcomputer.com/forums/topic114351.html

==========


Please download aswMBR ( 511KB ) from here: http://public.avast.com/~gmerek/aswMBR.exe to your desktop.

  • Double click the aswMBR.exe icon to run it
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

Things I need to see in your next reply:

  • checkup.txt
  • DDS.txt
  • Attach.txt
  • aswMBR.txt
     

 


Best Regards,
oneof4.


#5 nimble

nimble
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 25 May 2013 - 09:46 PM

I was unable to post a log from aswMBR due to program crashing near the end of scan. I posted a screen capture of the error

 

 

DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 10.0.9200.16576
Run by OFFICE at 19:09:30 on 2013-05-25
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.1979.1309 [GMT -7:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ================
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\sppsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\System32\svchost.exe -k secsvcs
.
============== Pseudo HJT Report ===============
.
uSearch Bar = Preserve
uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
dRunOnce: [SPReview] "c:\windows\system32\spreview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
TCP: NameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{A7D230A1-4993-414D-8290-59CEBB4A7DAF} : DHCPNameServer = 75.75.75.75 75.75.76.76
TCP: Interfaces\{A7D230A1-4993-414D-8290-59CEBB4A7DAF}\14E64627F696461405 : DHCPNameServer = 192.168.43.1
Notify: igfxcui - igfxdev.dll
SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\drivers\L1C62x86.sys [2009-6-10 50688]
R3 NETw5s32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 32 Bit;c:\windows\system32\drivers\NETw5s32.sys [2010-1-13 6755840]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 netw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\drivers\netw5v32.sys [2009-6-10 4231168]
S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2013-5-19 52224]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2013-5-18 1343400]
.
=============== Created Last 30 ================
.
2013-05-26 02:07:28 60872 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{9a9dccbd-9e14-4350-ac95-2a66137a400b}\offreg.dll
2013-05-26 01:57:11 7016152 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{9a9dccbd-9e14-4350-ac95-2a66137a400b}\mpengine.dll
2013-05-21 19:00:50 49152 ----a-w- c:\windows\system32\taskhost.exe
2013-05-21 17:31:52 712048 ----a-w- c:\windows\system32\drivers\ndis.sys
2013-05-21 17:30:56 1796096 ----a-w- c:\windows\system32\authui.dll
2013-05-21 17:30:56 101720 ----a-w- c:\windows\system32\consent.exe
2013-05-21 17:30:55 47104 ----a-w- c:\windows\system32\appinfo.dll
2013-05-21 17:28:45 7016152 ----a-w- c:\programdata\microsoft\windows defender\definition updates\backup\mpengine.dll
2013-05-19 23:05:45 -------- d-----w- c:\windows\system32\SPReview
2013-05-19 23:05:20 -------- d-----w- c:\windows\system32\EventProviders
2013-05-19 21:44:59 2522624 ----a-w- c:\windows\system32\dbgeng.dll
2013-05-19 21:43:56 189952 ----a-w- c:\windows\system32\wdscore.dll
2013-05-19 21:43:46 606208 ----a-w- c:\windows\system32\wbem\fastprox.dll
2013-05-19 21:43:46 363008 ----a-w- c:\windows\system32\wbemcomn.dll
2013-05-19 21:43:46 189952 ----a-w- c:\program files\windows portable devices\sqmapi.dll
2013-05-19 21:43:43 189952 ----a-w- c:\windows\system32\sqmapi.dll
2013-05-19 04:57:44 -------- d-sh--w- c:\windows\Installer
2013-05-19 04:48:42 -------- d-----w- c:\windows\system32\Wat
2013-05-19 03:01:36 70656 ----a-w- c:\windows\system32\fontsub.dll
2013-05-19 03:01:36 34304 ----a-w- c:\windows\system32\atmlib.dll
2013-05-19 03:01:36 295424 ----a-w- c:\windows\system32\atmfd.dll
2013-05-19 02:22:29 -------- d-----w- C:\Intel
2013-05-19 02:17:54 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-05-19 02:13:32 9728 ----a-w- c:\windows\system32\Wdfres.dll
2013-05-19 02:13:32 526952 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2013-05-19 02:13:32 47720 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2013-05-19 02:12:21 73216 ----a-w- c:\windows\system32\WUDFSvc.dll
2013-05-19 02:12:21 66560 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2013-05-19 02:12:21 613888 ----a-w- c:\windows\system32\WUDFx.dll
2013-05-19 02:12:21 38912 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2013-05-19 02:12:21 196608 ----a-w- c:\windows\system32\WUDFHost.exe
2013-05-19 02:12:21 172032 ----a-w- c:\windows\system32\WUDFPlatform.dll
2013-05-19 02:12:21 155136 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2013-05-19 02:10:25 5120 ----a-w- c:\windows\system32\wmi.dll
2013-05-19 02:10:25 19824 ----a-w- c:\windows\system32\drivers\fs_rec.sys
2013-05-19 02:10:25 159232 ----a-w- c:\windows\system32\imagehlp.dll
2013-05-19 01:59:11 3217408 ----a-w- c:\windows\system32\mstscax.dll
2013-05-19 01:59:11 131584 ----a-w- c:\windows\system32\aaclient.dll
2013-05-19 01:59:10 36864 ----a-w- c:\windows\system32\tsgqec.dll
2013-05-19 01:59:02 140288 ----a-w- c:\windows\system32\cryptsvc.dll
2013-05-19 01:59:02 1159680 ----a-w- c:\windows\system32\crypt32.dll
2013-05-19 01:59:02 103936 ----a-w- c:\windows\system32\cryptnet.dll
2013-05-19 01:57:29 3968856 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-19 01:56:53 96768 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2013-05-19 01:55:59 642048 ----a-w- c:\windows\system32\CPFilters.dll
2013-05-19 01:49:34 123904 ----a-w- c:\windows\system32\poqexec.exe
2013-05-19 01:49:07 107520 ----a-w- c:\windows\system32\cdd.dll
2013-05-19 01:49:03 1164288 ----a-w- c:\windows\system32\mfc42u.dll
2013-05-19 01:49:03 1137664 ----a-w- c:\windows\system32\mfc42.dll
2013-05-19 01:47:56 69632 ----a-w- c:\windows\system32\drivers\bowser.sys
2013-05-19 01:45:08 27008 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2013-05-19 01:45:04 2048 ----a-w- c:\windows\system32\tzres.dll
2013-05-19 01:44:06 163504 ----a-w- c:\programdata\microsoft\windows\sqm\manifest\Sqm10144.bin
2013-05-19 01:41:14 826880 ----a-w- c:\windows\system32\rdpcore.dll
2013-05-19 01:41:14 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-05-19 01:41:14 18432 ----a-w- c:\windows\system32\drivers\tdpipe.sys
2013-05-18 23:02:58 -------- d-----w- c:\users\office\appdata\local\Diagnostics
2013-05-18 22:50:57 -------- d-----w- c:\windows\Panther
2013-05-18 22:45:35 -------- d-----w- c:\users\office\appdata\local\ElevatedDiagnostics
2013-05-18 22:35:54 -------- d-sh--w- C:\Recovery
2013-05-18 22:28:36 -------- d-----w- c:\windows\system32\wbem\Performance
.
==================== Find3M  ====================
.
2013-05-21 19:00:27 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-21 04:46:50 152576 ----a-w- c:\windows\system32\msclmd.dll
2013-04-13 04:45:16 474624 ----a-w- c:\windows\apppatch\AcSpecfc.dll
2013-04-13 04:45:15 2176512 ----a-w- c:\windows\apppatch\AcGenral.dll
2013-04-12 13:45:29 1211752 ----a-w- c:\windows\system32\drivers\ntfs.sys
2013-04-10 05:18:40 728424 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2013-04-10 05:18:40 218984 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2013-04-10 03:14:06 2347520 ----a-w- c:\windows\system32\win32k.sys
2013-03-19 05:04:10 3913560 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-03-19 04:53:27 186368 ----a-w- c:\windows\system32\wwansvc.dll
2013-03-19 04:48:45 38912 ----a-w- c:\windows\system32\csrsrv.dll
2013-03-19 03:33:33 40960 ----a-w- c:\windows\system32\wwanprotdim.dll
2013-03-19 02:49:16 69632 ----a-w- c:\windows\system32\smss.exe
.
============= FINISH: 19:10:10.29 ===============
 

 

Attached Files



#6 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:05:49 PM

Posted 26 May 2013 - 01:09 PM

Hi nimble, :)

 

Your DDS is clean.  You mentioned earlier that a GMER scan revealed "something."  Do you still have the log from that scan?  If so, could you post it in your next reply.

 

Also, let's run the following:

 

Please download the TDSS Rootkit Removing Tool (TDSSKiller.exe) and save it to your Desktop. <-Important!!!

  • Double-click on TDSSKiller.exe to run the tool for known TDSS variants.
    Vista/Windows 7 users right-click and select Run As Administrator.
  • If TDSSKiller does not run, try renaming it.
  • To do this, right-click on TDSSKiller.exe, select Rename and give it a random name with the .com file extension (i.e. 123abc.com). If you do not see the file extension, please refer to How to change the file extension.
  • Click the Start Scan button.
  • Do not use the computer during the scan
  • If the scan completes with nothing found, click Close to exit.
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not an option, Skip instead, do not choose Delete unless instructed.
  • A log file named TDSSKiller_version_date_time_log.txt (i.e. TDSSKiller.2.4.0.0_27.07.2010_09.o7.26_log.txt) will be created and saved to the root directory (usually Local Disk C:).
  • Copy and paste the contents of that file in your next reply.

 


Best Regards,
oneof4.


#7 nimble

nimble
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:02:49 PM

Posted 27 May 2013 - 07:38 PM

11:41:03.0033 1864  TDSS rootkit removing tool 2.8.17.0 Apr 11 2013 11:56:34
11:41:04.0157 1864  ============================================================
11:41:04.0157 1864  Current date / time: 2013/05/26 11:41:04.0157
11:41:04.0157 1864  SystemInfo:
11:41:04.0157 1864 
11:41:04.0157 1864  OS Version: 6.1.7601 ServicePack: 1.0
11:41:04.0157 1864  Product type: Workstation
11:41:04.0172 1864  ComputerName: OFFICE-PC
11:41:04.0172 1864  UserName: OFFICE
11:41:04.0172 1864  Windows directory: C:\Windows
11:41:04.0172 1864  System windows directory: C:\Windows
11:41:04.0172 1864  Processor architecture: Intel x86
11:41:04.0172 1864  Number of processors: 1
11:41:04.0172 1864  Page size: 0x1000
11:41:04.0172 1864  Boot type: Normal boot
11:41:04.0172 1864  ============================================================
11:41:04.0188 1864  BG loaded
11:41:05.0483 1864  Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
11:41:05.0521 1864  ============================================================
11:41:05.0521 1864  \Device\Harddisk0\DR0:
11:41:05.0584 1864  MBR partitions:
11:41:05.0584 1864  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
11:41:05.0584 1864  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x1D192800
11:41:05.0584 1864  ============================================================
11:41:05.0647 1864  C: <-> \Device\Harddisk0\DR0\Partition2
11:41:05.0647 1864  ============================================================
11:41:05.0648 1864  Initialize success
11:41:05.0648 1864  ============================================================
11:41:10.0821 0228  ============================================================
11:41:10.0821 0228  Scan started
11:41:10.0821 0228  Mode: Manual;
11:41:10.0821 0228  ============================================================
11:41:12.0037 0228  ================ Scan system memory ========================
11:41:12.0037 0228  System memory - ok
11:41:12.0053 0228  ================ Scan services =============================
11:41:13.0457 0228  [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
11:41:13.0473 0228  1394ohci - ok
11:41:13.0582 0228  [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
11:41:13.0582 0228  ACPI - ok
11:41:13.0691 0228  [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
11:41:13.0691 0228  AcpiPmi - ok
11:41:13.0800 0228  [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
11:41:13.0816 0228  adp94xx - ok
11:41:13.0925 0228  [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
11:41:13.0941 0228  adpahci - ok
11:41:14.0019 0228  [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
11:41:14.0050 0228  adpu320 - ok
11:41:14.0097 0228  [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
11:41:14.0097 0228  AeLookupSvc - ok
11:41:14.0206 0228  [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD             C:\Windows\system32\drivers\afd.sys
11:41:14.0206 0228  AFD - ok
11:41:14.0299 0228  [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440          C:\Windows\system32\drivers\agp440.sys
11:41:14.0299 0228  agp440 - ok
11:41:14.0674 0228  [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx         C:\Windows\system32\DRIVERS\djsvs.sys
11:41:14.0674 0228  aic78xx - ok
11:41:14.0736 0228  [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG             C:\Windows\System32\alg.exe
11:41:14.0736 0228  ALG - ok
11:41:14.0799 0228  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide          C:\Windows\system32\drivers\aliide.sys
11:41:14.0799 0228  aliide - ok
11:41:14.0845 0228  [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
11:41:14.0845 0228  amdagp - ok
11:41:14.0908 0228  [ CD5914170297126B6266860198D1D4F0 ] amdide          C:\Windows\system32\drivers\amdide.sys
11:41:14.0923 0228  amdide - ok
11:41:14.0955 0228  [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
11:41:14.0955 0228  AmdK8 - ok
11:41:14.0970 0228  [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
11:41:14.0970 0228  AmdPPM - ok
11:41:15.0064 0228  [ D320BF87125326F996D4904FE24300FC ] amdsata         C:\Windows\system32\drivers\amdsata.sys
11:41:15.0095 0228  amdsata - ok
11:41:15.0173 0228  [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
11:41:15.0173 0228  amdsbs - ok
11:41:15.0220 0228  [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
11:41:15.0251 0228  amdxata - ok
11:41:15.0313 0228  [ AEA177F783E20150ACE5383EE368DA19 ] AppID           C:\Windows\system32\drivers\appid.sys
11:41:15.0313 0228  AppID - ok
11:41:15.0391 0228  [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
11:41:15.0391 0228  AppIDSvc - ok
11:41:15.0454 0228  [ EACFDF31921F51C097629F1F3C9129B4 ] Appinfo         C:\Windows\System32\appinfo.dll
11:41:15.0454 0228  Appinfo - ok
11:41:15.0516 0228  [ 2932004F49677BD84DBC72EDB754FFB3 ] arc             C:\Windows\system32\DRIVERS\arc.sys
11:41:15.0532 0228  arc - ok
11:41:15.0579 0228  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
11:41:15.0594 0228  arcsas - ok
11:41:15.0625 0228  [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
11:41:15.0641 0228  AsyncMac - ok
11:41:15.0719 0228  [ 338C86357871C167A96AB976519BF59E ] atapi           C:\Windows\system32\drivers\atapi.sys
11:41:15.0719 0228  atapi - ok
11:41:15.0906 0228  [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:41:15.0906 0228  AudioEndpointBuilder - ok
11:41:15.0937 0228  [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
11:41:15.0937 0228  Audiosrv - ok
11:41:16.0031 0228  [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
11:41:16.0047 0228  AxInstSV - ok
11:41:16.0140 0228  [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbdx.sys
11:41:16.0156 0228  b06bdrv - ok
11:41:16.0203 0228  [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
11:41:16.0218 0228  b57nd60x - ok
11:41:16.0343 0228  [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC          C:\Windows\System32\bdesvc.dll
11:41:16.0343 0228  BDESVC - ok
11:41:16.0374 0228  [ 505506526A9D467307B3C393DEDAF858 ] Beep            C:\Windows\system32\drivers\Beep.sys
11:41:16.0374 0228  Beep - ok
11:41:16.0515 0228  [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE             C:\Windows\System32\bfe.dll
11:41:16.0515 0228  BFE - ok
11:41:16.0546 0228  [ E585445D5021971FAE10393F0F1C3961 ] BITS            C:\Windows\System32\qmgr.dll
11:41:16.0561 0228  BITS - ok
11:41:16.0577 0228  [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
11:41:16.0577 0228  blbdrive - ok
11:41:16.0639 0228  [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
11:41:16.0639 0228  bowser - ok
11:41:16.0686 0228  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:41:16.0686 0228  BrFiltLo - ok
11:41:16.0702 0228  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:41:16.0702 0228  BrFiltUp - ok
11:41:16.0764 0228  [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser         C:\Windows\System32\browser.dll
11:41:16.0764 0228  Browser - ok
11:41:16.0842 0228  [ 845B8CE732E67F3B4133164868C666EA ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
11:41:16.0873 0228  Brserid - ok
11:41:16.0905 0228  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
11:41:16.0905 0228  BrSerWdm - ok
11:41:16.0920 0228  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
11:41:16.0920 0228  BrUsbMdm - ok
11:41:16.0936 0228  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
11:41:16.0936 0228  BrUsbSer - ok
11:41:16.0951 0228  [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
11:41:16.0951 0228  BTHMODEM - ok
11:41:16.0998 0228  [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv         C:\Windows\system32\bthserv.dll
11:41:16.0998 0228  bthserv - ok
11:41:17.0029 0228  [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
11:41:17.0045 0228  cdfs - ok
11:41:17.0107 0228  [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom           C:\Windows\system32\drivers\cdrom.sys
11:41:17.0107 0228  cdrom - ok
11:41:17.0170 0228  [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc     C:\Windows\System32\certprop.dll
11:41:17.0170 0228  CertPropSvc - ok
11:41:17.0201 0228  [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
11:41:17.0201 0228  circlass - ok
11:41:17.0248 0228  [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS            C:\Windows\system32\CLFS.sys
11:41:17.0248 0228  CLFS - ok
11:41:17.0357 0228  [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:41:17.0373 0228  clr_optimization_v2.0.50727_32 - ok
11:41:17.0497 0228  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:41:17.0544 0228  clr_optimization_v4.0.30319_32 - ok
11:41:17.0591 0228  [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
11:41:17.0591 0228  CmBatt - ok
11:41:17.0607 0228  [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
11:41:17.0607 0228  cmdide - ok
11:41:17.0685 0228  [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG             C:\Windows\system32\Drivers\cng.sys
11:41:17.0685 0228  CNG - ok
11:41:17.0731 0228  [ A6023D3823C37043986713F118A89BEE ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
11:41:17.0731 0228  Compbatt - ok
11:41:17.0778 0228  [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
11:41:17.0778 0228  CompositeBus - ok
11:41:17.0809 0228  COMSysApp - ok
11:41:17.0841 0228  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
11:41:17.0841 0228  crcdisk - ok
11:41:17.0903 0228  [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc        C:\Windows\system32\cryptsvc.dll
11:41:17.0903 0228  CryptSvc - ok
11:41:17.0997 0228  [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch      C:\Windows\system32\rpcss.dll
11:41:17.0997 0228  DcomLaunch - ok
11:41:18.0075 0228  [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc       C:\Windows\System32\defragsvc.dll
11:41:18.0075 0228  defragsvc - ok
11:41:18.0137 0228  [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
11:41:18.0137 0228  DfsC - ok
11:41:18.0246 0228  [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp            C:\Windows\system32\dhcpcore.dll
11:41:18.0246 0228  Dhcp - ok
11:41:18.0262 0228  [ 1A050B0274BFB3890703D490F330C0DA ] discache        C:\Windows\system32\drivers\discache.sys
11:41:18.0262 0228  discache - ok
11:41:18.0324 0228  [ 565003F326F99802E68CA78F2A68E9FF ] Disk            C:\Windows\system32\DRIVERS\disk.sys
11:41:18.0324 0228  Disk - ok
11:41:18.0387 0228  [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
11:41:18.0387 0228  Dnscache - ok
11:41:18.0449 0228  [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc         C:\Windows\System32\dot3svc.dll
11:41:18.0465 0228  dot3svc - ok
11:41:18.0527 0228  [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS             C:\Windows\system32\dps.dll
11:41:18.0527 0228  DPS - ok
11:41:18.0574 0228  [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
11:41:18.0574 0228  drmkaud - ok
11:41:18.0636 0228  [ 16498EBC04AE9DD07049A8884B205C05 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
11:41:18.0636 0228  DXGKrnl - ok
11:41:18.0699 0228  [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost         C:\Windows\System32\eapsvc.dll
11:41:18.0699 0228  EapHost - ok
11:41:18.0855 0228  [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv           C:\Windows\system32\DRIVERS\evbdx.sys
11:41:18.0964 0228  ebdrv - ok
11:41:19.0011 0228  [ 81951F51E318AECC2D68559E47485CC4 ] EFS             C:\Windows\System32\lsass.exe
11:41:19.0011 0228  EFS - ok
11:41:19.0167 0228  [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
11:41:19.0167 0228  ehRecvr - ok
11:41:19.0198 0228  [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched         C:\Windows\ehome\ehsched.exe
11:41:19.0198 0228  ehSched - ok
11:41:19.0260 0228  [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
11:41:19.0260 0228  elxstor - ok
11:41:19.0307 0228  [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
11:41:19.0307 0228  ErrDev - ok
11:41:19.0369 0228  [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem     C:\Windows\system32\es.dll
11:41:19.0385 0228  EventSystem - ok
11:41:19.0416 0228  [ 2DC9108D74081149CC8B651D3A26207F ] exfat           C:\Windows\system32\drivers\exfat.sys
11:41:19.0416 0228  exfat - ok
11:41:19.0447 0228  [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
11:41:19.0447 0228  fastfat - ok
11:41:19.0541 0228  [ 967EA5B213E9984CBE270205DF37755B ] Fax             C:\Windows\system32\fxssvc.exe
11:41:19.0541 0228  Fax - ok
11:41:19.0572 0228  [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
11:41:19.0572 0228  fdc - ok
11:41:19.0619 0228  [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost         C:\Windows\system32\fdPHost.dll
11:41:19.0619 0228  fdPHost - ok
11:41:19.0635 0228  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub        C:\Windows\system32\fdrespub.dll
11:41:19.0635 0228  FDResPub - ok
11:41:19.0666 0228  [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
11:41:19.0681 0228  FileInfo - ok
11:41:19.0713 0228  [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
11:41:19.0713 0228  Filetrace - ok
11:41:19.0728 0228  [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
11:41:19.0728 0228  flpydisk - ok
11:41:19.0775 0228  [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
11:41:19.0775 0228  FltMgr - ok
11:41:19.0947 0228  [ E12C4928B32ACE04610259647F072635 ] FontCache       C:\Windows\system32\FntCache.dll
11:41:19.0947 0228  FontCache - ok
11:41:20.0009 0228  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
11:41:20.0009 0228  FontCache3.0.0.0 - ok
11:41:20.0040 0228  [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
11:41:20.0040 0228  FsDepends - ok
11:41:20.0087 0228  [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
11:41:20.0103 0228  Fs_Rec - ok
11:41:20.0165 0228  [ E306A24D9694C724FA2491278BF50FDB ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
11:41:20.0165 0228  fvevol - ok
11:41:20.0196 0228  [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
11:41:20.0196 0228  gagp30kx - ok
11:41:20.0368 0228  [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc           C:\Windows\System32\gpsvc.dll
11:41:20.0368 0228  gpsvc - ok
11:41:20.0399 0228  [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
11:41:20.0399 0228  hcw85cir - ok
11:41:20.0461 0228  [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:41:20.0461 0228  HdAudAddService - ok
11:41:20.0508 0228  [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
11:41:20.0508 0228  HDAudBus - ok
11:41:20.0524 0228  [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
11:41:20.0524 0228  HidBatt - ok
11:41:20.0539 0228  [ 89448F40E6DF260C206A193A4683BA78 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
11:41:20.0555 0228  HidBth - ok
11:41:20.0586 0228  [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
11:41:20.0586 0228  HidIr - ok
11:41:20.0617 0228  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv         C:\Windows\system32\hidserv.dll
11:41:20.0617 0228  hidserv - ok
11:41:20.0695 0228  [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb          C:\Windows\system32\drivers\hidusb.sys
11:41:20.0695 0228  HidUsb - ok
11:41:20.0758 0228  [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc          C:\Windows\system32\kmsvc.dll
11:41:20.0758 0228  hkmsvc - ok
11:41:20.0820 0228  [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:41:20.0836 0228  HomeGroupListener - ok
11:41:20.0867 0228  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:41:20.0867 0228  HomeGroupProvider - ok
11:41:20.0929 0228  [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
11:41:20.0945 0228  HpSAMD - ok
11:41:21.0023 0228  [ 871917B07A141BFF43D76D8844D48106 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
11:41:21.0039 0228  HTTP - ok
11:41:21.0085 0228  [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
11:41:21.0085 0228  hwpolicy - ok
11:41:21.0148 0228  [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
11:41:21.0148 0228  i8042prt - ok
11:41:21.0195 0228  [ D483687EACE0C065EE772481A96E05F5 ] iaStor          C:\Windows\system32\DRIVERS\iaStor.sys
11:41:21.0195 0228  iaStor - ok
11:41:21.0241 0228  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
11:41:21.0257 0228  iaStorV - ok
11:41:21.0382 0228  [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
11:41:21.0397 0228  idsvc - ok
11:41:22.0302 0228  [ 8266AE06DF974E5BA047B3E9E9E70B3F ] igfx            C:\Windows\system32\DRIVERS\igdkmd32.sys
11:41:22.0380 0228  igfx - ok
11:41:22.0427 0228  [ 4173FF5708F3236CF25195FECD742915 ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
11:41:22.0427 0228  iirsp - ok
11:41:22.0489 0228  [ F95622F161474511B8D80D6B093AA610 ] IKEEXT          C:\Windows\System32\ikeext.dll
11:41:22.0505 0228  IKEEXT - ok
11:41:22.0567 0228  [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide        C:\Windows\system32\drivers\intelide.sys
11:41:22.0583 0228  intelide - ok
11:41:22.0614 0228  [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
11:41:22.0630 0228  intelppm - ok
11:41:22.0677 0228  [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
11:41:22.0677 0228  IPBusEnum - ok
11:41:22.0708 0228  [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:41:22.0708 0228  IpFilterDriver - ok
11:41:22.0848 0228  [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
11:41:22.0864 0228  iphlpsvc - ok
11:41:22.0911 0228  [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
11:41:22.0911 0228  IPMIDRV - ok
11:41:22.0957 0228  [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
11:41:22.0957 0228  IPNAT - ok
11:41:22.0973 0228  [ 42996CFF20A3084A56017B7902307E9F ] IRENUM          C:\Windows\system32\drivers\irenum.sys
11:41:22.0973 0228  IRENUM - ok
11:41:23.0004 0228  [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
11:41:23.0004 0228  isapnp - ok
11:41:23.0035 0228  [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
11:41:23.0035 0228  iScsiPrt - ok
11:41:23.0082 0228  [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass        C:\Windows\system32\drivers\kbdclass.sys
11:41:23.0082 0228  kbdclass - ok
11:41:23.0145 0228  [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
11:41:23.0160 0228  kbdhid - ok
11:41:23.0191 0228  [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso          C:\Windows\system32\lsass.exe
11:41:23.0191 0228  KeyIso - ok
11:41:23.0269 0228  [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
11:41:23.0269 0228  KSecDD - ok
11:41:23.0301 0228  [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
11:41:23.0301 0228  KSecPkg - ok
11:41:23.0332 0228  [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm           C:\Windows\system32\msdtckrm.dll
11:41:23.0347 0228  KtmRm - ok
11:41:23.0379 0228  [ 6C32BFEAB708915D6BBF4B20D4F3EF7B ] L1C             C:\Windows\system32\DRIVERS\L1C62x86.sys
11:41:23.0379 0228  L1C - ok
11:41:23.0425 0228  [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer    C:\Windows\system32\srvsvc.dll
11:41:23.0441 0228  LanmanServer - ok
11:41:23.0488 0228  [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:41:23.0503 0228  LanmanWorkstation - ok
11:41:23.0566 0228  [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
11:41:23.0566 0228  lltdio - ok
11:41:23.0613 0228  [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
11:41:23.0613 0228  lltdsvc - ok
11:41:23.0628 0228  [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts         C:\Windows\System32\lmhsvc.dll
11:41:23.0628 0228  lmhosts - ok
11:41:23.0675 0228  [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
11:41:23.0675 0228  LSI_FC - ok
11:41:23.0675 0228  [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
11:41:23.0691 0228  LSI_SAS - ok
11:41:23.0706 0228  [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:41:23.0706 0228  LSI_SAS2 - ok
11:41:23.0706 0228  [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:41:23.0722 0228  LSI_SCSI - ok
11:41:23.0722 0228  [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv           C:\Windows\system32\drivers\luafv.sys
11:41:23.0722 0228  luafv - ok
11:41:23.0769 0228  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
11:41:23.0800 0228  Mcx2Svc - ok
11:41:23.0847 0228  [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
11:41:23.0847 0228  megasas - ok
11:41:23.0878 0228  [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
11:41:23.0878 0228  MegaSR - ok
11:41:23.0909 0228  [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS           C:\Windows\system32\mmcss.dll
11:41:23.0909 0228  MMCSS - ok
11:41:23.0940 0228  [ F001861E5700EE84E2D4E52C712F4964 ] Modem           C:\Windows\system32\drivers\modem.sys
11:41:23.0940 0228  Modem - ok
11:41:23.0971 0228  [ 79D10964DE86B292320E9DFE02282A23 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
11:41:23.0971 0228  monitor - ok
11:41:24.0018 0228  [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass        C:\Windows\system32\drivers\mouclass.sys
11:41:24.0018 0228  mouclass - ok
11:41:24.0049 0228  [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
11:41:24.0049 0228  mouhid - ok
11:41:24.0112 0228  [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
11:41:24.0127 0228  mountmgr - ok
11:41:24.0174 0228  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio            C:\Windows\system32\drivers\mpio.sys
11:41:24.0174 0228  mpio - ok
11:41:24.0205 0228  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
11:41:24.0205 0228  mpsdrv - ok
11:41:24.0283 0228  [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc          C:\Windows\system32\mpssvc.dll
11:41:24.0283 0228  MpsSvc - ok
11:41:24.0361 0228  [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
11:41:24.0361 0228  MRxDAV - ok
11:41:24.0424 0228  [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
11:41:24.0424 0228  mrxsmb - ok
11:41:24.0471 0228  [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:41:24.0471 0228  mrxsmb10 - ok
11:41:24.0502 0228  [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:41:24.0502 0228  mrxsmb20 - ok
11:41:24.0517 0228  [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci          C:\Windows\system32\drivers\msahci.sys
11:41:24.0517 0228  msahci - ok
11:41:24.0580 0228  [ 55055F8AD8BE27A64C831322A780A228 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
11:41:24.0580 0228  msdsm - ok
11:41:24.0595 0228  [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC           C:\Windows\System32\msdtc.exe
11:41:24.0611 0228  MSDTC - ok
11:41:24.0658 0228  [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs            C:\Windows\system32\drivers\Msfs.sys
11:41:24.0658 0228  Msfs - ok
11:41:24.0689 0228  [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
11:41:24.0705 0228  mshidkmdf - ok
11:41:24.0736 0228  [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
11:41:24.0751 0228  msisadrv - ok
11:41:24.0798 0228  [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
11:41:24.0798 0228  MSiSCSI - ok
11:41:24.0814 0228  msiserver - ok
11:41:24.0861 0228  [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
11:41:24.0861 0228  MSKSSRV - ok
11:41:24.0861 0228  [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
11:41:24.0876 0228  MSPCLOCK - ok
11:41:24.0876 0228  [ F456E973590D663B1073E9C463B40932 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
11:41:24.0876 0228  MSPQM - ok
11:41:24.0907 0228  [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
11:41:24.0923 0228  MsRPC - ok
11:41:24.0970 0228  [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
11:41:24.0970 0228  mssmbios - ok
11:41:24.0985 0228  [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
11:41:24.0985 0228  MSTEE - ok
11:41:25.0001 0228  [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
11:41:25.0001 0228  MTConfig - ok
11:41:25.0032 0228  [ 159FAD02F64E6381758C990F753BCC80 ] Mup             C:\Windows\system32\Drivers\mup.sys
11:41:25.0032 0228  Mup - ok
11:41:25.0095 0228  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent        C:\Windows\system32\qagentRT.dll
11:41:25.0095 0228  napagent - ok
11:41:25.0141 0228  [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
11:41:25.0141 0228  NativeWifiP - ok
11:41:25.0235 0228  [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS            C:\Windows\system32\drivers\ndis.sys
11:41:25.0235 0228  NDIS - ok
11:41:25.0282 0228  [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
11:41:25.0282 0228  NdisCap - ok
11:41:25.0313 0228  [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
11:41:25.0313 0228  NdisTapi - ok
11:41:25.0375 0228  [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
11:41:25.0375 0228  Ndisuio - ok
11:41:25.0438 0228  [ 38FBE267E7E6983311179230FACB1017 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
11:41:25.0438 0228  NdisWan - ok
11:41:25.0516 0228  [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
11:41:25.0516 0228  NDProxy - ok
11:41:25.0563 0228  [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
11:41:25.0563 0228  NetBIOS - ok
11:41:25.0641 0228  [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
11:41:25.0641 0228  NetBT - ok
11:41:25.0672 0228  [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon        C:\Windows\system32\lsass.exe
11:41:25.0672 0228  Netlogon - ok
11:41:25.0719 0228  [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman          C:\Windows\System32\netman.dll
11:41:25.0719 0228  Netman - ok
11:41:25.0765 0228  [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm        C:\Windows\System32\netprofm.dll
11:41:25.0781 0228  netprofm - ok
11:41:25.0797 0228  [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
11:41:25.0828 0228  NetTcpPortSharing - ok
11:41:26.0405 0228  [ 5B2DFA9C5C02DDF2A113CC0F551B59DF ] NETw5s32        C:\Windows\system32\DRIVERS\NETw5s32.sys
11:41:26.0452 0228  NETw5s32 - ok
11:41:26.0779 0228  [ 58218EC6B61B1169CF54AAB0D00F5FE2 ] netw5v32        C:\Windows\system32\DRIVERS\netw5v32.sys
11:41:26.0935 0228  netw5v32 - ok
11:41:26.0998 0228  [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
11:41:26.0998 0228  nfrd960 - ok
11:41:27.0076 0228  [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc          C:\Windows\System32\nlasvc.dll
11:41:27.0076 0228  NlaSvc - ok
11:41:27.0107 0228  [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
11:41:27.0107 0228  Npfs - ok
11:41:27.0169 0228  [ BA387E955E890C8A88306D9B8D06BF17 ] nsi             C:\Windows\system32\nsisvc.dll
11:41:27.0169 0228  nsi - ok
11:41:27.0201 0228  [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
11:41:27.0201 0228  nsiproxy - ok
11:41:27.0294 0228  [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
11:41:27.0310 0228  Ntfs - ok
11:41:27.0372 0228  [ F9756A98D69098DCA8945D62858A812C ] Null            C:\Windows\system32\drivers\Null.sys
11:41:27.0372 0228  Null - ok
11:41:27.0388 0228  [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
11:41:27.0388 0228  nvraid - ok
11:41:27.0481 0228  [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
11:41:27.0481 0228  nvstor - ok
11:41:27.0513 0228  [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
11:41:27.0513 0228  nv_agp - ok
11:41:27.0544 0228  [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
11:41:27.0559 0228  ohci1394 - ok
11:41:27.0591 0228  [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
11:41:27.0606 0228  p2pimsvc - ok
11:41:27.0653 0228  [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc          C:\Windows\system32\p2psvc.dll
11:41:27.0653 0228  p2psvc - ok
11:41:27.0700 0228  [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
11:41:27.0700 0228  Parport - ok
11:41:27.0762 0228  [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
11:41:27.0762 0228  partmgr - ok
11:41:27.0778 0228  [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
11:41:27.0778 0228  Parvdm - ok
11:41:27.0809 0228  [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc          C:\Windows\System32\pcasvc.dll
11:41:27.0809 0228  PcaSvc - ok
11:41:27.0887 0228  [ 673E55C3498EB970088E812EA820AA8F ] pci             C:\Windows\system32\drivers\pci.sys
11:41:27.0887 0228  pci - ok
11:41:27.0918 0228  [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide          C:\Windows\system32\drivers\pciide.sys
11:41:27.0918 0228  pciide - ok
11:41:27.0965 0228  [ F396431B31693E71E8A80687EF523506 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
11:41:27.0965 0228  pcmcia - ok
11:41:27.0981 0228  [ 250F6B43D2B613172035C6747AEEB19F ] pcw             C:\Windows\system32\drivers\pcw.sys
11:41:27.0981 0228  pcw - ok
11:41:28.0027 0228  [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
11:41:28.0027 0228  PEAUTH - ok
11:41:28.0215 0228  [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla             C:\Windows\system32\pla.dll
11:41:28.0277 0228  pla - ok
11:41:28.0417 0228  [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
11:41:28.0417 0228  PlugPlay - ok
11:41:28.0495 0228  [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
11:41:28.0495 0228  PNRPAutoReg - ok
11:41:28.0558 0228  [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
11:41:28.0558 0228  PNRPsvc - ok
11:41:28.0651 0228  [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
11:41:28.0683 0228  PolicyAgent - ok
11:41:28.0714 0228  [ F87D30E72E03D579A5199CCB3831D6EA ] Power           C:\Windows\system32\umpo.dll
11:41:28.0714 0228  Power - ok
11:41:28.0761 0228  [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
11:41:28.0761 0228  PptpMiniport - ok
11:41:28.0792 0228  [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
11:41:28.0823 0228  Processor - ok
11:41:28.0901 0228  [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc         C:\Windows\system32\profsvc.dll
11:41:28.0917 0228  ProfSvc - ok
11:41:28.0932 0228  [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:41:28.0948 0228  ProtectedStorage - ok
11:41:28.0979 0228  [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
11:41:28.0979 0228  Psched - ok
11:41:29.0026 0228  [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
11:41:29.0057 0228  ql2300 - ok
11:41:29.0088 0228  [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
11:41:29.0119 0228  ql40xx - ok
11:41:29.0197 0228  [ 31AC809E7707EB580B2BDB760390765A ] QWAVE           C:\Windows\system32\qwave.dll
11:41:29.0213 0228  QWAVE - ok
11:41:29.0244 0228  [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
11:41:29.0244 0228  QWAVEdrv - ok
11:41:29.0260 0228  [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
11:41:29.0260 0228  RasAcd - ok
11:41:29.0307 0228  [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
11:41:29.0307 0228  RasAgileVpn - ok
11:41:29.0322 0228  [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto         C:\Windows\System32\rasauto.dll
11:41:29.0338 0228  RasAuto - ok
11:41:29.0369 0228  [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
11:41:29.0369 0228  Rasl2tp - ok
11:41:29.0431 0228  [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan          C:\Windows\System32\rasmans.dll
11:41:29.0447 0228  RasMan - ok
11:41:29.0463 0228  [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
11:41:29.0463 0228  RasPppoe - ok
11:41:29.0494 0228  [ 44101F495A83EA6401D886E7FD70096B ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
11:41:29.0494 0228  RasSstp - ok
11:41:29.0556 0228  [ D528BC58A489409BA40334EBF96A311B ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
11:41:29.0556 0228  rdbss - ok
11:41:29.0572 0228  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
11:41:29.0587 0228  rdpbus - ok
11:41:29.0634 0228  [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
11:41:29.0634 0228  RDPCDD - ok
11:41:29.0681 0228  [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
11:41:29.0697 0228  RDPENCDD - ok
11:41:29.0712 0228  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
11:41:29.0712 0228  RDPREFMP - ok
11:41:29.0775 0228  [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
11:41:29.0790 0228  RDPWD - ok
11:41:29.0884 0228  [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
11:41:29.0884 0228  rdyboost - ok
11:41:29.0931 0228  [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess    C:\Windows\System32\mprdim.dll
11:41:29.0931 0228  RemoteAccess - ok
11:41:29.0962 0228  [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
11:41:29.0993 0228  RemoteRegistry - ok
11:41:30.0024 0228  [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
11:41:30.0024 0228  RpcEptMapper - ok
11:41:30.0055 0228  [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator      C:\Windows\system32\locator.exe
11:41:30.0055 0228  RpcLocator - ok
11:41:30.0087 0228  [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs           C:\Windows\system32\rpcss.dll
11:41:30.0102 0228  RpcSs - ok
11:41:30.0149 0228  [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
11:41:30.0149 0228  rspndr - ok
11:41:30.0180 0228  [ 81951F51E318AECC2D68559E47485CC4 ] SamSs           C:\Windows\system32\lsass.exe
11:41:30.0180 0228  SamSs - ok
11:41:30.0211 0228  [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
11:41:30.0211 0228  sbp2port - ok
11:41:30.0243 0228  [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
11:41:30.0258 0228  SCardSvr - ok
11:41:30.0274 0228  [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
11:41:30.0274 0228  scfilter - ok
11:41:30.0383 0228  [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule        C:\Windows\system32\schedsvc.dll
11:41:30.0399 0228  Schedule - ok
11:41:30.0430 0228  [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc     C:\Windows\System32\certprop.dll
11:41:30.0430 0228  SCPolicySvc - ok
11:41:30.0492 0228  [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
11:41:30.0523 0228  SDRSVC - ok
11:41:30.0570 0228  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
11:41:30.0570 0228  secdrv - ok
11:41:30.0617 0228  [ A59B3A4442C52060CC7A85293AA3546F ] seclogon        C:\Windows\system32\seclogon.dll
11:41:30.0617 0228  seclogon - ok
11:41:30.0648 0228  [ DCB7FCDCC97F87360F75D77425B81737 ] SENS            C:\Windows\System32\sens.dll
11:41:30.0648 0228  SENS - ok
11:41:30.0679 0228  [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc        C:\Windows\system32\sensrsvc.dll
11:41:30.0695 0228  SensrSvc - ok
11:41:30.0711 0228  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
11:41:30.0711 0228  Serenum - ok
11:41:30.0726 0228  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial          C:\Windows\system32\DRIVERS\serial.sys
11:41:30.0726 0228  Serial - ok
11:41:30.0773 0228  [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
11:41:30.0773 0228  sermouse - ok
11:41:30.0835 0228  [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv      C:\Windows\system32\sessenv.dll
11:41:30.0851 0228  SessionEnv - ok
11:41:30.0867 0228  [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
11:41:30.0867 0228  sffdisk - ok
11:41:30.0898 0228  [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
11:41:30.0898 0228  sffp_mmc - ok
11:41:30.0898 0228  [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
11:41:30.0898 0228  sffp_sd - ok
11:41:30.0929 0228  [ DB96666CC8312EBC45032F30B007A547 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
11:41:30.0945 0228  sfloppy - ok
11:41:30.0976 0228  [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
11:41:30.0976 0228  SharedAccess - ok
11:41:31.0007 0228  [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:41:31.0007 0228  ShellHWDetection - ok
11:41:31.0054 0228  [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp          C:\Windows\system32\drivers\sisagp.sys
11:41:31.0054 0228  sisagp - ok
11:41:31.0116 0228  [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:41:31.0116 0228  SiSRaid2 - ok
11:41:31.0132 0228  [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
11:41:31.0132 0228  SiSRaid4 - ok
11:41:31.0163 0228  [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb             C:\Windows\system32\DRIVERS\smb.sys
11:41:31.0163 0228  Smb - ok
11:41:31.0225 0228  [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
11:41:31.0241 0228  SNMPTRAP - ok
11:41:31.0272 0228  [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr           C:\Windows\system32\drivers\spldr.sys
11:41:31.0288 0228  spldr - ok
11:41:31.0428 0228  [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler         C:\Windows\System32\spoolsv.exe
11:41:31.0428 0228  Spooler - ok
11:41:31.0771 0228  [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc          C:\Windows\system32\sppsvc.exe
11:41:31.0912 0228  sppsvc - ok
11:41:31.0959 0228  [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
11:41:31.0959 0228  sppuinotify - ok
11:41:32.0083 0228  [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv             C:\Windows\system32\DRIVERS\srv.sys
11:41:32.0083 0228  srv - ok
11:41:32.0177 0228  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
11:41:32.0193 0228  srv2 - ok
11:41:32.0239 0228  [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
11:41:32.0239 0228  srvnet - ok
11:41:32.0302 0228  [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
11:41:32.0317 0228  SSDPSRV - ok
11:41:32.0349 0228  [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
11:41:32.0349 0228  SstpSvc - ok
11:41:32.0395 0228  [ DB32D325C192B801DF274BFD12A7E72B ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
11:41:32.0411 0228  stexstor - ok
11:41:32.0520 0228  [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc          C:\Windows\System32\wiaservc.dll
11:41:32.0536 0228  StiSvc - ok
11:41:32.0598 0228  [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum          C:\Windows\system32\drivers\swenum.sys
11:41:32.0598 0228  swenum - ok
11:41:32.0629 0228  [ A28BD92DF340E57B024BA433165D34D7 ] swprv           C:\Windows\System32\swprv.dll
11:41:32.0645 0228  swprv - ok
11:41:32.0817 0228  [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain         C:\Windows\system32\sysmain.dll
11:41:32.0848 0228  SysMain - ok
11:41:32.0895 0228  [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:41:32.0895 0228  TabletInputService - ok
11:41:32.0941 0228  [ 613BF4820361543956909043A265C6AC ] TapiSrv         C:\Windows\System32\tapisrv.dll
11:41:32.0957 0228  TapiSrv - ok
11:41:32.0988 0228  [ B799D9FDB26111737F58288D8DC172D9 ] TBS             C:\Windows\System32\tbssvc.dll
11:41:33.0004 0228  TBS - ok
11:41:33.0113 0228  [ 7C0507D2391AF5933600CBCED799F277 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
11:41:33.0144 0228  Tcpip - ok
11:41:33.0222 0228  [ 7C0507D2391AF5933600CBCED799F277 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
11:41:33.0238 0228  TCPIP6 - ok
11:41:33.0300 0228  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
11:41:33.0300 0228  tcpipreg - ok
11:41:33.0363 0228  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
11:41:33.0363 0228  TDPIPE - ok
11:41:33.0394 0228  [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
11:41:33.0394 0228  TDTCP - ok
11:41:33.0472 0228  [ B459575348C20E8121D6039DA063C704 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
11:41:33.0472 0228  tdx - ok
11:41:33.0519 0228  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD          C:\Windows\system32\drivers\termdd.sys
11:41:33.0534 0228  TermDD - ok
11:41:33.0643 0228  [ 382C804C92811BE57829D8E550A900E2 ] TermService     C:\Windows\System32\termsrv.dll
11:41:33.0659 0228  TermService - ok
11:41:33.0706 0228  [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes          C:\Windows\system32\themeservice.dll
11:41:33.0721 0228  Themes - ok
11:41:33.0737 0228  [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER     C:\Windows\system32\mmcss.dll
11:41:33.0753 0228  THREADORDER - ok
11:41:33.0799 0228  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks          C:\Windows\System32\trkwks.dll
11:41:33.0799 0228  TrkWks - ok
11:41:33.0893 0228  [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:41:33.0924 0228  TrustedInstaller - ok
11:41:33.0971 0228  [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
11:41:33.0971 0228  tssecsrv - ok
11:41:34.0049 0228  [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
11:41:34.0049 0228  TsUsbFlt - ok
11:41:34.0158 0228  [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
11:41:34.0158 0228  tunnel - ok
11:41:34.0221 0228  [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
11:41:34.0236 0228  uagp35 - ok
11:41:34.0267 0228  [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
11:41:34.0283 0228  udfs - ok
11:41:34.0361 0228  [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect       C:\Windows\system32\UI0Detect.exe
11:41:34.0377 0228  UI0Detect - ok
11:41:34.0408 0228  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
11:41:34.0408 0228  uliagpkx - ok
11:41:34.0439 0228  [ D295BED4B898F0FD999FCFA9B32B071B ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
11:41:34.0439 0228  umbus - ok
11:41:34.0470 0228  [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
11:41:34.0470 0228  UmPass - ok
11:41:34.0501 0228  [ 833FBB672460EFCE8011D262175FAD33 ] upnphost        C:\Windows\System32\upnphost.dll
11:41:34.0564 0228  upnphost - ok
11:41:34.0611 0228  [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
11:41:34.0611 0228  usbccgp - ok
11:41:34.0657 0228  [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
11:41:34.0657 0228  usbcir - ok
11:41:34.0673 0228  [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
11:41:34.0673 0228  usbehci - ok
11:41:34.0720 0228  [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
11:41:34.0720 0228  usbhub - ok
11:41:34.0751 0228  [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci         C:\Windows\system32\drivers\usbohci.sys
11:41:34.0751 0228  usbohci - ok
11:41:34.0782 0228  [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
11:41:34.0782 0228  usbprint - ok
11:41:34.0798 0228  [ F991AB9CC6B908DB552166768176896A ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:41:34.0813 0228  USBSTOR - ok
11:41:34.0860 0228  [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci         C:\Windows\system32\DRIVERS\usbuhci.sys
11:41:34.0860 0228  usbuhci - ok
11:41:34.0907 0228  [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo        C:\Windows\System32\Drivers\usbvideo.sys
11:41:34.0907 0228  usbvideo - ok
11:41:34.0969 0228  [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms           C:\Windows\System32\uxsms.dll
11:41:34.0969 0228  UxSms - ok
11:41:35.0001 0228  [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc        C:\Windows\system32\lsass.exe
11:41:35.0001 0228  VaultSvc - ok
11:41:35.0032 0228  [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
11:41:35.0032 0228  vdrvroot - ok
11:41:35.0110 0228  [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds             C:\Windows\System32\vds.exe
11:41:35.0125 0228  vds - ok
11:41:35.0188 0228  [ 17C408214EA61696CEC9C66E388B14F3 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
11:41:35.0188 0228  vga - ok
11:41:35.0235 0228  [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave         C:\Windows\System32\drivers\vga.sys
11:41:35.0235 0228  VgaSave - ok
11:41:35.0266 0228  [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
11:41:35.0281 0228  vhdmp - ok
11:41:35.0313 0228  [ C829317A37B4BEA8F39735D4B076E923 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
11:41:35.0313 0228  viaagp - ok
11:41:35.0328 0228  [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7           C:\Windows\system32\DRIVERS\viac7.sys
11:41:35.0328 0228  ViaC7 - ok
11:41:35.0359 0228  [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide          C:\Windows\system32\drivers\viaide.sys
11:41:35.0359 0228  viaide - ok
11:41:35.0375 0228  [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
11:41:35.0391 0228  volmgr - ok
11:41:35.0437 0228  [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
11:41:35.0437 0228  volmgrx - ok
11:41:35.0469 0228  [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
11:41:35.0484 0228  volsnap - ok
11:41:35.0531 0228  [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
11:41:35.0531 0228  vsmraid - ok
11:41:35.0625 0228  [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS             C:\Windows\system32\vssvc.exe
11:41:35.0687 0228  VSS - ok
11:41:35.0749 0228  [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
11:41:35.0749 0228  vwifibus - ok
11:41:35.0765 0228  [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
11:41:35.0765 0228  vwififlt - ok
11:41:35.0859 0228  [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time         C:\Windows\system32\w32time.dll
11:41:35.0874 0228  W32Time - ok
11:41:35.0905 0228  [ DE3721E89C653AA281428C8A69745D90 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
11:41:35.0905 0228  WacomPen - ok
11:41:35.0968 0228  [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
11:41:35.0968 0228  WANARP - ok
11:41:35.0983 0228  [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
11:41:35.0983 0228  Wanarpv6 - ok
11:41:36.0155 0228  [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
11:41:36.0186 0228  WatAdminSvc - ok
11:41:36.0264 0228  [ 691E3285E53DCA558E1A84667F13E15A ] wbengine        C:\Windows\system32\wbengine.exe
11:41:36.0295 0228  wbengine - ok
11:41:36.0342 0228  [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
11:41:36.0342 0228  WbioSrvc - ok
11:41:36.0420 0228  [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc         C:\Windows\System32\wcncsvc.dll
11:41:36.0436 0228  wcncsvc - ok
11:41:36.0467 0228  [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:41:36.0467 0228  WcsPlugInService - ok
11:41:36.0514 0228  [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd              C:\Windows\system32\DRIVERS\wd.sys
11:41:36.0514 0228  Wd - ok
11:41:36.0623 0228  [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
11:41:36.0623 0228  Wdf01000 - ok
11:41:36.0670 0228  [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost  C:\Windows\system32\wdi.dll
11:41:36.0670 0228  WdiServiceHost - ok
11:41:36.0685 0228  [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost   C:\Windows\system32\wdi.dll
11:41:36.0685 0228  WdiSystemHost - ok
11:41:36.0763 0228  [ A9D880F97530D5B8FEE278923349929D ] WebClient       C:\Windows\System32\webclnt.dll
11:41:36.0763 0228  WebClient - ok
11:41:36.0795 0228  [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc          C:\Windows\system32\wecsvc.dll
11:41:36.0795 0228  Wecsvc - ok
11:41:36.0810 0228  [ AC804569BB2364FB6017370258A4091B ] wercplsupport   C:\Windows\System32\wercplsupport.dll
11:41:36.0810 0228  wercplsupport - ok
11:41:36.0841 0228  [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc          C:\Windows\System32\WerSvc.dll
11:41:36.0841 0228  WerSvc - ok
11:41:36.0873 0228  [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
11:41:36.0873 0228  WfpLwf - ok
11:41:36.0904 0228  [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
11:41:36.0919 0228  WIMMount - ok
11:41:37.0060 0228  [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
11:41:37.0075 0228  WinDefend - ok
11:41:37.0107 0228  WinHttpAutoProxySvc - ok
11:41:37.0169 0228  [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
11:41:37.0185 0228  Winmgmt - ok
11:41:37.0278 0228  [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM           C:\Windows\system32\WsmSvc.dll
11:41:37.0325 0228  WinRM - ok
11:41:37.0497 0228  [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc         C:\Windows\System32\wlansvc.dll
11:41:37.0512 0228  Wlansvc - ok
11:41:37.0543 0228  [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
11:41:37.0543 0228  WmiAcpi - ok
11:41:37.0590 0228  [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
11:41:37.0590 0228  wmiApSrv - ok
11:41:37.0793 0228  [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
11:41:37.0824 0228  WMPNetworkSvc - ok
11:41:37.0855 0228  [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc          C:\Windows\System32\wpcsvc.dll
11:41:37.0871 0228  WPCSvc - ok
11:41:37.0918 0228  [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
11:41:37.0918 0228  WPDBusEnum - ok
11:41:37.0980 0228  [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
11:41:37.0980 0228  ws2ifsl - ok
11:41:38.0011 0228  [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc          C:\Windows\System32\wscsvc.dll
11:41:38.0011 0228  wscsvc - ok
11:41:38.0027 0228  WSearch - ok
11:41:38.0230 0228  [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv        C:\Windows\system32\wuaueng.dll
11:41:38.0261 0228  wuauserv - ok
11:41:38.0339 0228  [ 06E6F32C8D0A3F66D956F57B43A2E070 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
11:41:38.0355 0228  WudfPf - ok
11:41:38.0417 0228  [ 867C301E8B790040AE9CF6486E8041DF ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
11:41:38.0433 0228  WUDFRd - ok
11:41:38.0479 0228  [ FE47B7BC8EA320C2D9B5E5BF6E303765 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
11:41:38.0495 0228  wudfsvc - ok
11:41:38.0589 0228  [ 3C5E51C05BE9B56EAFF4E388C3AB25E4 ] WwanSvc         C:\Windows\System32\wwansvc.dll
11:41:38.0604 0228  WwanSvc - ok
11:41:38.0651 0228  ================ Scan global ===============================
11:41:38.0698 0228  [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
11:41:38.0760 0228  [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:41:38.0776 0228  [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\system32\winsrv.dll
11:41:38.0838 0228  [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
11:41:38.0885 0228  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
11:41:38.0885 0228  [Global] - ok
11:41:38.0901 0228  ================ Scan MBR ==================================
11:41:38.0916 0228  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:41:39.0259 0228  \Device\Harddisk0\DR0 - ok
11:41:39.0275 0228  ================ Scan VBR ==================================
11:41:39.0275 0228  [ 090D9A1D6668CD9BAA79EEC875F403B7 ] \Device\Harddisk0\DR0\Partition1
11:41:39.0275 0228  \Device\Harddisk0\DR0\Partition1 - ok
11:41:39.0306 0228  [ 8B43FD62261AD21A9E02F8A887350299 ] \Device\Harddisk0\DR0\Partition2
11:41:39.0306 0228  \Device\Harddisk0\DR0\Partition2 - ok
11:41:39.0306 0228  ================ Scan active images ========================
11:41:39.0306 0228  [ B7EFEF22FF426EC4158A177CB3B558D3 ] C:\Windows\System32\drivers\crashdmp.sys
11:41:39.0306 0228  C:\Windows\System32\drivers\crashdmp.sys - ok
11:41:39.0322 0228  [ 62A63EF2F3053B461CB327E4D69AAA74 ] C:\Windows\System32\drivers\dumpfve.sys
11:41:39.0322 0228  C:\Windows\System32\drivers\dumpfve.sys - ok
11:41:39.0322 0228  [ D483687EACE0C065EE772481A96E05F5 ] C:\Windows\System32\drivers\iaStor.sys
11:41:39.0322 0228  C:\Windows\System32\drivers\iaStor.sys - ok
11:41:39.0337 0228  [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] C:\Windows\System32\drivers\cdrom.sys
11:41:39.0337 0228  C:\Windows\System32\drivers\cdrom.sys - ok
11:41:39.0337 0228  [ 505506526A9D467307B3C393DEDAF858 ] C:\Windows\System32\drivers\beep.sys
11:41:39.0337 0228  C:\Windows\System32\drivers\beep.sys - ok
11:41:39.0353 0228  [ F9756A98D69098DCA8945D62858A812C ] C:\Windows\System32\drivers\null.sys
11:41:39.0353 0228  C:\Windows\System32\drivers\null.sys - ok
11:41:39.0353 0228  [ 8E38096AD5C8570A6F1570A61E251561 ] C:\Windows\System32\drivers\vga.sys
11:41:39.0353 0228  C:\Windows\System32\drivers\vga.sys - ok
11:41:39.0369 0228  [ 15C126D1B55814B9E5CAB10A9C1F4C67 ] C:\Windows\System32\drivers\videoprt.sys
11:41:39.0369 0228  C:\Windows\System32\drivers\videoprt.sys - ok
11:41:39.0369 0228  [ CB45A417C8EF7BA6BAC67EDCDDED8700 ] C:\Windows\System32\drivers\watchdog.sys
11:41:39.0369 0228  C:\Windows\System32\drivers\watchdog.sys - ok
11:41:39.0384 0228  [ DAEFB28E3AF5A76ABCC2C3078C07327F ] C:\Windows\System32\drivers\msfs.sys
11:41:39.0384 0228  C:\Windows\System32\drivers\msfs.sys - ok
11:41:39.0384 0228  [ 1DB262A9F8C087E8153D89BEF3D2235F ] C:\Windows\System32\drivers\npfs.sys
11:41:39.0384 0228  C:\Windows\System32\drivers\npfs.sys - ok
11:41:39.0400 0228  [ 23DAE03F29D253AE74C44F99E515F9A1 ] C:\Windows\System32\drivers\RDPCDD.sys
11:41:39.0400 0228  C:\Windows\System32\drivers\RDPCDD.sys - ok
11:41:39.0400 0228  [ 5A53CA1598DD4156D44196D200C94B8A ] C:\Windows\System32\drivers\RDPENCDD.sys
11:41:39.0400 0228  C:\Windows\System32\drivers\RDPENCDD.sys - ok
11:41:39.0415 0228  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] C:\Windows\System32\drivers\RDPREFMP.sys
11:41:39.0415 0228  C:\Windows\System32\drivers\RDPREFMP.sys - ok
11:41:39.0415 0228  [ 2F885864D5BC8A16C86BEE595969A48A ] C:\Windows\System32\drivers\tdi.sys
11:41:39.0415 0228  C:\Windows\System32\drivers\tdi.sys - ok
11:41:39.0431 0228  [ B459575348C20E8121D6039DA063C704 ] C:\Windows\System32\drivers\tdx.sys
11:41:39.0431 0228  C:\Windows\System32\drivers\tdx.sys - ok
11:41:39.0431 0228  [ 9EBBBA55060F786F0FCAA3893BFA2806 ] C:\Windows\System32\drivers\afd.sys
11:41:39.0431 0228  C:\Windows\System32\drivers\afd.sys - ok
11:41:39.0447 0228  [ 280122DDCF04B378EDD1AD54D71C1E54 ] C:\Windows\System32\drivers\netbt.sys
11:41:39.0447 0228  C:\Windows\System32\drivers\netbt.sys - ok
11:41:39.0462 0228  [ 6270CCAE2A86DE6D146529FE55B3246A ] C:\Windows\System32\drivers\pacer.sys
11:41:39.0462 0228  C:\Windows\System32\drivers\pacer.sys - ok
11:41:39.0462 0228  [ 7090D3436EEB4E7DA3373090A23448F7 ] C:\Windows\System32\drivers\vwififlt.sys
11:41:39.0462 0228  C:\Windows\System32\drivers\vwififlt.sys - ok
11:41:39.0478 0228  [ 8B9A943F3B53861F2BFAF6C186168F79 ] C:\Windows\System32\drivers\wfplwf.sys
11:41:39.0478 0228  C:\Windows\System32\drivers\wfplwf.sys - ok
11:41:39.0478 0228  [ 80B275B1CE3B0E79909DB7B39AF74D51 ] C:\Windows\System32\drivers\netbios.sys
11:41:39.0478 0228  C:\Windows\System32\drivers\netbios.sys - ok
11:41:39.0493 0228  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] C:\Windows\System32\drivers\termdd.sys
11:41:39.0493 0228  C:\Windows\System32\drivers\termdd.sys - ok
11:41:39.0493 0228  [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] C:\Windows\System32\drivers\wanarp.sys
11:41:39.0493 0228  C:\Windows\System32\drivers\wanarp.sys - ok
11:41:39.0509 0228  [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] C:\Windows\System32\drivers\nsiproxy.sys
11:41:39.0509 0228  C:\Windows\System32\drivers\nsiproxy.sys - ok
11:41:39.0509 0228  [ D528BC58A489409BA40334EBF96A311B ] C:\Windows\System32\drivers\rdbss.sys
11:41:39.0509 0228  C:\Windows\System32\drivers\rdbss.sys - ok
11:41:39.0525 0228  [ 1A050B0274BFB3890703D490F330C0DA ] C:\Windows\System32\drivers\discache.sys
11:41:39.0525 0228  C:\Windows\System32\drivers\discache.sys - ok
11:41:39.0525 0228  [ FC6B9FF600CC585EA38B12589BD4E246 ] C:\Windows\System32\drivers\mssmbios.sys
11:41:39.0525 0228  C:\Windows\System32\drivers\mssmbios.sys - ok
11:41:39.0540 0228  [ 2287078ED48FCFC477B05B20CF38F36F ] C:\Windows\System32\drivers\blbdrive.sys
11:41:39.0540 0228  C:\Windows\System32\drivers\blbdrive.sys - ok
11:41:39.0540 0228  [ F024449C97EC1E464AAFFDA18593DB88 ] C:\Windows\System32\drivers\dfsc.sys
11:41:39.0540 0228  C:\Windows\System32\drivers\dfsc.sys - ok
11:41:39.0556 0228  [ DEA805815E587DAD1DD2C502220B5616 ] C:\Windows\System32\drivers\CmBatt.sys
11:41:39.0556 0228  C:\Windows\System32\drivers\CmBatt.sys - ok
11:41:39.0556 0228  [ 3B514D27BFC4ACCB4037BC6685F766E0 ] C:\Windows\System32\drivers\intelppm.sys
11:41:39.0556 0228  C:\Windows\System32\drivers\intelppm.sys - ok
11:41:39.0571 0228  [ B2FA25D9B17A68BB93D58B0556E8C90D ] C:\Windows\System32\drivers\tunnel.sys
11:41:39.0571 0228  C:\Windows\System32\drivers\tunnel.sys - ok
11:41:39.0571 0228  [ 8266AE06DF974E5BA047B3E9E9E70B3F ] C:\Windows\System32\drivers\igdkmd32.sys
11:41:39.0571 0228  C:\Windows\System32\drivers\igdkmd32.sys - ok
11:41:39.0587 0228  [ C30A91ADE8C9CB91E4281EC83C4500C6 ] C:\Windows\System32\ntdll.dll
11:41:39.0587 0228  C:\Windows\System32\ntdll.dll - ok
11:41:39.0587 0228  [ DE91DCC7BC55E940979097E98F743205 ] C:\Windows\System32\smss.exe
11:41:39.0587 0228  C:\Windows\System32\smss.exe - ok
11:41:39.0603 0228  [ F88A52EB62019D6A62FDD9E08034DBD8 ] C:\Windows\System32\autochk.exe
11:41:39.0603 0228  C:\Windows\System32\autochk.exe - ok
11:41:39.0603 0228  [ 16498EBC04AE9DD07049A8884B205C05 ] C:\Windows\System32\drivers\dxgkrnl.sys
11:41:39.0603 0228  C:\Windows\System32\drivers\dxgkrnl.sys - ok
11:41:39.0618 0228  [ E405328A0E38BF823E2361C413283F6D ] C:\Windows\System32\drivers\dxgmms1.sys
11:41:39.0618 0228  C:\Windows\System32\drivers\dxgmms1.sys - ok
11:41:39.0618 0228  [ 3AA940AA9AC3055FE32FF2D3D20CCD28 ] C:\Windows\System32\drivers\usbport.sys
11:41:39.0618 0228  C:\Windows\System32\drivers\usbport.sys - ok
11:41:39.0634 0228  [ 68DF884CF41CDADA664BEB01DAF67E3D ] C:\Windows\System32\drivers\usbuhci.sys
11:41:39.0634 0228  C:\Windows\System32\drivers\usbuhci.sys - ok
11:41:39.0634 0228  [ 9036377B8A6C15DC2EEC53E489D159B5 ] C:\Windows\System32\drivers\hdaudbus.sys
11:41:39.0634 0228  C:\Windows\System32\drivers\hdaudbus.sys - ok
11:41:39.0649 0228  [ F92DE757E4B7CE9C07C5E65423F3AE3B ] C:\Windows\System32\drivers\usbehci.sys
11:41:39.0649 0228  C:\Windows\System32\drivers\usbehci.sys - ok
11:41:39.0649 0228  [ 6C32BFEAB708915D6BBF4B20D4F3EF7B ] C:\Windows\System32\drivers\L1C62x86.sys
11:41:39.0649 0228  C:\Windows\System32\drivers\L1C62x86.sys - ok
11:41:39.0665 0228  [ D1DE1EAFDE97BE41CF6585027FF3E732 ] C:\Windows\System32\comdlg32.dll
11:41:39.0665 0228  C:\Windows\System32\comdlg32.dll - ok
11:41:39.0681 0228  [ 5B2DFA9C5C02DDF2A113CC0F551B59DF ] C:\Windows\System32\drivers\NETw5s32.sys
11:41:39.0681 0228  C:\Windows\System32\drivers\NETw5s32.sys - ok
11:41:39.0681 0228  [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] C:\Windows\System32\drivers\vwifibus.sys
11:41:39.0681 0228  C:\Windows\System32\drivers\vwifibus.sys - ok
11:41:39.0696 0228  [ F151F0BDC47F4A28B1B20A0818EA36D6 ] C:\Windows\System32\drivers\i8042prt.sys
11:41:39.0696 0228  C:\Windows\System32\drivers\i8042prt.sys - ok
11:41:39.0696 0228  [ ADEF52CA1AEAE82B50DF86B56413107E ] C:\Windows\System32\drivers\kbdclass.sys
11:41:39.0696 0228  C:\Windows\System32\drivers\kbdclass.sys - ok
11:41:39.0712 0228  [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] C:\Windows\System32\drivers\mouclass.sys
11:41:39.0712 0228  C:\Windows\System32\drivers\mouclass.sys - ok
11:41:39.0712 0228  [ 0217679B8FCA58714C3BF2726D2CA84E ] C:\Windows\System32\drivers\wmiacpi.sys
11:41:39.0712 0228  C:\Windows\System32\drivers\wmiacpi.sys - ok
11:41:39.0727 0228  [ CBE8C58A8579CFE5FCCF809E6F114E89 ] C:\Windows\System32\drivers\CompositeBus.sys
11:41:39.0727 0228  C:\Windows\System32\drivers\CompositeBus.sys - ok
11:41:39.0727 0228  [ 57EC4AEF73660166074D8F7F31C0D4FD ] C:\Windows\System32\drivers\agilevpn.sys
11:41:39.0727 0228  C:\Windows\System32\drivers\agilevpn.sys - ok
11:41:39.0743 0228  [ D9F91EAFEC2815365CBE6D167E4E332A ] C:\Windows\System32\drivers\rasl2tp.sys
11:41:39.0743 0228  C:\Windows\System32\drivers\rasl2tp.sys - ok
11:41:39.0743 0228  [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] C:\Windows\System32\drivers\ndistapi.sys
11:41:39.0743 0228  C:\Windows\System32\drivers\ndistapi.sys - ok
11:41:39.0759 0228  [ 38FBE267E7E6983311179230FACB1017 ] C:\Windows\System32\drivers\ndiswan.sys
11:41:39.0759 0228  C:\Windows\System32\drivers\ndiswan.sys - ok
11:41:39.0759 0228  [ 0FE8B15916307A6AC12BFB6A63E45507 ] C:\Windows\System32\drivers\raspppoe.sys
11:41:39.0759 0228  C:\Windows\System32\drivers\raspppoe.sys - ok
11:41:39.0774 0228  [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] C:\Windows\System32\drivers\raspptp.sys
11:41:39.0774 0228  C:\Windows\System32\drivers\raspptp.sys - ok
11:41:39.0774 0228  [ 44101F495A83EA6401D886E7FD70096B ] C:\Windows\System32\drivers\rassstp.sys
11:41:39.0774 0228  C:\Windows\System32\drivers\rassstp.sys - ok
11:41:39.0790 0228  [ 5DCEF0C32BE0F33277326586FA503689 ] C:\Windows\System32\drivers\ks.sys
11:41:39.0790 0228  C:\Windows\System32\drivers\ks.sys - ok
11:41:39.0790 0228  [ E58C78A848ADD9610A4DB6D214AF5224 ] C:\Windows\System32\drivers\swenum.sys
11:41:39.0790 0228  C:\Windows\System32\drivers\swenum.sys - ok
11:41:39.0805 0228  [ D295BED4B898F0FD999FCFA9B32B071B ] C:\Windows\System32\drivers\umbus.sys
11:41:39.0805 0228  C:\Windows\System32\drivers\umbus.sys - ok
11:41:39.0805 0228  [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] C:\Windows\System32\drivers\usbhub.sys
11:41:39.0805 0228  C:\Windows\System32\drivers\usbhub.sys - ok
11:41:39.0821 0228  [ A4BDC541E69674FBFF1A8FF00BE913F2 ] C:\Windows\System32\drivers\ndproxy.sys
11:41:39.0821 0228  C:\Windows\System32\drivers\ndproxy.sys - ok
11:41:39.0821 0228  [ 27F9288AF019E6DACA281EDE51FF5928 ] C:\Windows\System32\drivers\drmk.sys
11:41:39.0821 0228  C:\Windows\System32\drivers\drmk.sys - ok
11:41:39.0837 0228  [ A5EF29D5315111C80A5C1ABAD14C8972 ] C:\Windows\System32\drivers\HdAudio.sys
11:41:39.0837 0228  C:\Windows\System32\drivers\HdAudio.sys - ok
11:41:39.0837 0228  [ D72708C9F49500C13D7D067E169B7715 ] C:\Windows\System32\drivers\portcls.sys
11:41:39.0837 0228  C:\Windows\System32\drivers\portcls.sys - ok
11:41:39.0852 0228  [ 4A8E2F20809CC161107FAA94F6CF2685 ] C:\Windows\System32\imm32.dll
11:41:39.0852 0228  C:\Windows\System32\imm32.dll - ok
11:41:39.0852 0228  [ 5ABB3F36AF17007F33FA275E96A2C95E ] C:\Windows\System32\wininet.dll
11:41:39.0852 0228  C:\Windows\System32\wininet.dll - ok
11:41:39.0868 0228  [ C9618BC9B2B0FD7C1138D8774795A79B ] C:\Windows\System32\msctf.dll
11:41:39.0868 0228  C:\Windows\System32\msctf.dll - ok
11:41:39.0868 0228  [ B2DB6ABA2E292235749B80A9C3DFA867 ] C:\Windows\System32\imagehlp.dll
11:41:39.0868 0228  C:\Windows\System32\imagehlp.dll - ok
11:41:39.0883 0228  [ F59A16A9418044C1D505C53DA370B099 ] C:\Windows\System32\iertutil.dll
11:41:39.0883 0228  C:\Windows\System32\iertutil.dll - ok
11:41:39.0883 0228  [ 7FF15A4F092CD4A96055BA69F903E3E9 ] C:\Windows\System32\ws2_32.dll
11:41:39.0883 0228  C:\Windows\System32\ws2_32.dll - ok
11:41:39.0899 0228  [ FF5688D309347F2720911D8796912834 ] C:\Windows\System32\clbcatq.dll
11:41:39.0899 0228  C:\Windows\System32\clbcatq.dll - ok
11:41:39.0899 0228  [ 9DC80A8AAAAAC397BDAB3C67165A824E ] C:\Windows\System32\msvcrt.dll
11:41:39.0899 0228  C:\Windows\System32\msvcrt.dll - ok
11:41:39.0915 0228  [ B7230010D97787AF3D25E4C82F2B06B9 ] C:\Windows\System32\usp10.dll
11:41:39.0915 0228  C:\Windows\System32\usp10.dll - ok
11:41:39.0915 0228  [ AE09B85158C66E2C154C5C9B3C0027B3 ] C:\Windows\System32\kernel32.dll
11:41:39.0915 0228  C:\Windows\System32\kernel32.dll - ok
11:41:39.0930 0228  [ 070C5B9D3006602A07757179D9B56F5D ] C:\Windows\System32\difxapi.dll
11:41:39.0930 0228  C:\Windows\System32\difxapi.dll - ok
11:41:39.0930 0228  [ A543AC1F7138376D778D630A35FCBC4C ] C:\Windows\System32\psapi.dll
11:41:39.0930 0228  C:\Windows\System32\psapi.dll - ok
11:41:39.0946 0228  [ A8BB45F9ECAD993461E0FEF8E2A99152 ] C:\Windows\System32\Wldap32.dll
11:41:39.0946 0228  C:\Windows\System32\Wldap32.dll - ok
11:41:39.0946 0228  [ 6400774E903729ADD0A62A24A334EE56 ] C:\Windows\System32\rpcrt4.dll
11:41:39.0946 0228  C:\Windows\System32\rpcrt4.dll - ok
11:41:39.0961 0228  [ 928CF7268086631F54C3D8E17238C6DD ] C:\Windows\System32\ole32.dll
11:41:39.0961 0228  C:\Windows\System32\ole32.dll - ok
11:41:39.0961 0228  [ 6C765E82B57F2E66CE9C54AC238471D9 ] C:\Windows\System32\oleaut32.dll
11:41:39.0961 0228  C:\Windows\System32\oleaut32.dll - ok
11:41:39.0977 0228  [ 95E2376B3323F062EB562B8586D0F14A ] C:\Windows\System32\advapi32.dll
11:41:39.0977 0228  C:\Windows\System32\advapi32.dll - ok
11:41:39.0977 0228  [ 565D78187494FB5F08B5A52DEB2AEA7A ] C:\Windows\System32\shell32.dll
11:41:39.0977 0228  C:\Windows\System32\shell32.dll - ok
11:41:39.0993 0228  [ 6377051C63D5552A311935C67E9FDFDC ] C:\Windows\System32\nsi.dll
11:41:39.0993 0228  C:\Windows\System32\nsi.dll - ok
11:41:39.0993 0228  [ CFC97F07904067A1E5FAE195D534DA3A ] C:\Windows\System32\sechost.dll
11:41:39.0993 0228  C:\Windows\System32\sechost.dll - ok
11:41:40.0008 0228  [ E87F5393F7D8CE2FACC4DFF703531392 ] C:\Windows\System32\gdi32.dll
11:41:40.0008 0228  C:\Windows\System32\gdi32.dll - ok
11:41:40.0008 0228  [ 65C95886E1B17001ADDF163AC18C5525 ] C:\Windows\System32\urlmon.dll
11:41:40.0008 0228  C:\Windows\System32\urlmon.dll - ok
11:41:40.0024 0228  [ 9C278785347BCC991F8EA2999D90F58D ] C:\Windows\System32\normaliz.dll
11:41:40.0024 0228  C:\Windows\System32\normaliz.dll - ok
11:41:40.0024 0228  [ 10FB16B50AFFDA6D44588F3C445DC273 ] C:\Windows\System32\setupapi.dll
11:41:40.0024 0228  C:\Windows\System32\setupapi.dll - ok
11:41:40.0039 0228  [ 8CC3C111D653E96F3EA1590891491D71 ] C:\Windows\System32\shlwapi.dll
11:41:40.0039 0228  C:\Windows\System32\shlwapi.dll - ok
11:41:40.0039 0228  [ 4F154D2C9C6DF951FD6E5AABBAE6B5EE ] C:\Windows\System32\lpk.dll
11:41:40.0039 0228  C:\Windows\System32\lpk.dll - ok
11:41:40.0055 0228  [ F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 ] C:\Windows\System32\user32.dll
11:41:40.0055 0228  C:\Windows\System32\user32.dll - ok
11:41:40.0055 0228  [ 1C60E09CA1C3A045BC4D367F67C915B7 ] C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
11:41:40.0055 0228  C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll - ok
11:41:40.0071 0228  [ 60D21799A4AF4EDCE65FB98830E4B0C8 ] C:\Windows\System32\crypt32.dll
11:41:40.0071 0228  C:\Windows\System32\crypt32.dll - ok
11:41:40.0086 0228  [ BDAC1AA64495D0F7E1FF810EBBF1F018 ] C:\Windows\System32\comctl32.dll
11:41:40.0086 0228  C:\Windows\System32\comctl32.dll - ok
11:41:40.0086 0228  [ 3BE0D923AA45A4DBE091C2D84F0B4FE7 ] C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
11:41:40.0086 0228  C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll - ok
11:41:40.0102 0228  [ 3FFAEA12666E565FF51BF2FCA674F543 ] C:\Windows\System32\cfgmgr32.dll
11:41:40.0102 0228  C:\Windows\System32\cfgmgr32.dll - ok
11:41:40.0102 0228  [ 6A13B4F3B3F575F1E24B877B9359AABA ] C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
11:41:40.0102 0228  C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll - ok
11:41:40.0117 0228  [ 6951562DC4625EEFC6EACD52AD165866 ] C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
11:41:40.0117 0228  C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll - ok
11:41:40.0117 0228  [ 589CBC4989F750E1DA35625AB481CF43 ] C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
11:41:40.0117 0228  C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll - ok
11:41:40.0133 0228  [ 2E33DFD10F28F86C3FC40EE123CC3904 ] C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
11:41:40.0133 0228  C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll - ok
11:41:40.0133 0228  [ 17448AF0BBA9E7AB5EC955AF93F271BD ] C:\Windows\System32\wintrust.dll
11:41:40.0133 0228  C:\Windows\System32\wintrust.dll - ok
11:41:40.0149 0228  [ CC4ED8BEA78B0DCA6F217E014C3291A7 ] C:\Windows\System32\devobj.dll
11:41:40.0149 0228  C:\Windows\System32\devobj.dll - ok
11:41:40.0149 0228  [ AD88D390C9417C959E08F8BF6F2B8154 ] C:\Windows\System32\KernelBase.dll
11:41:40.0149 0228  C:\Windows\System32\KernelBase.dll - ok
11:41:40.0164 0228  [ 938F39B50BAFE13D6F58C7790682C010 ] C:\Windows\System32\msasn1.dll
11:41:40.0164 0228  C:\Windows\System32\msasn1.dll - ok
11:41:40.0164 0228  [ 5FCD3320AAE71506B43F9E12E4E72172 ] C:\Windows\System32\drivers\dxapi.sys
11:41:40.0164 0228  C:\Windows\System32\drivers\dxapi.sys - ok
11:41:40.0180 0228  [ 52948A58E4E64427DC399A409EF1CAB5 ] C:\Windows\System32\win32k.sys
11:41:40.0180 0228  C:\Windows\System32\win32k.sys - ok
11:41:40.0195 0228  [ 342271F6142E7C70805B8A81E1BA5F5C ] C:\Windows\System32\csrss.exe
11:41:40.0195 0228  C:\Windows\System32\csrss.exe - ok
11:41:40.0195 0228  [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\System32\basesrv.dll
11:41:40.0195 0228  C:\Windows\System32\basesrv.dll - ok
11:41:40.0211 0228  [ 23AB7E36551C6BA5370EF7F05142F0EB ] C:\Windows\System32\csrsrv.dll
11:41:40.0211 0228  C:\Windows\System32\csrsrv.dll - ok
11:41:40.0211 0228  [ 1F5F07091D50244F17DD8D5147A628CC ] C:\Windows\System32\winsrv.dll
11:41:40.0211 0228  C:\Windows\System32\winsrv.dll - ok
11:41:40.0227 0228  [ 5787196F32D043572EC6565C0EF1B8E0 ] C:\Windows\System32\drivers\usbd.sys
11:41:40.0227 0228  C:\Windows\System32\drivers\usbd.sys - ok
11:41:40.0227 0228  [ BD9C55D7023C5DE374507ACC7A14E2AC ] C:\Windows\System32\drivers\usbccgp.sys
11:41:40.0227 0228  C:\Windows\System32\drivers\usbccgp.sys - ok
11:41:40.0242 0228  [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] C:\Windows\System32\drivers\usbvideo.sys
11:41:40.0242 0228  C:\Windows\System32\drivers\usbvideo.sys - ok
11:41:40.0242 0228  [ 79D10964DE86B292320E9DFE02282A23 ] C:\Windows\System32\drivers\monitor.sys
11:41:40.0242 0228  C:\Windows\System32\drivers\monitor.sys - ok
11:41:40.0258 0228  [ 7C76B61A5E1EF5D1FA554CF134100F18 ] C:\Windows\System32\tsddd.dll
11:41:40.0258 0228  C:\Windows\System32\tsddd.dll - ok
11:41:40.0258 0228  [ 364455805E64882844EE9ACB72522830 ] C:\Windows\System32\sxssrv.dll
11:41:40.0258 0228  C:\Windows\System32\sxssrv.dll - ok
11:41:40.0273 0228  [ CAEF9CD6C10B1017E2C298D849CD31DB ] C:\Windows\System32\cdd.dll
11:41:40.0273 0228  C:\Windows\System32\cdd.dll - ok
11:41:40.0273 0228  [ B5C5DCAD3899512020D135600129D665 ] C:\Windows\System32\wininit.exe
11:41:40.0273 0228  C:\Windows\System32\wininit.exe - ok
11:41:40.0289 0228  [ C733D233B623B7FFCE5031E4B756EE26 ] C:\Windows\System32\profapi.dll
11:41:40.0289 0228  C:\Windows\System32\profapi.dll - ok
11:41:40.0289 0228  [ 6D13E1406F50C66E2A95D97F22C47560 ] C:\Windows\System32\winlogon.exe
11:41:40.0289 0228  C:\Windows\System32\winlogon.exe - ok
11:41:40.0305 0228  [ 357B990A4249D7F7485B230C0CC8825A ] C:\Windows\System32\KBDUS.DLL
11:41:40.0305 0228  C:\Windows\System32\KBDUS.DLL - ok
11:41:40.0305 0228  [ 5997D769CDB108390DCFAEBF442BF816 ] C:\Windows\System32\RpcRtRemote.dll
11:41:40.0305 0228  C:\Windows\System32\RpcRtRemote.dll - ok
11:41:40.0320 0228  [ 418E881201583A3039D81F43E39E6C78 ] C:\Windows\System32\winsta.dll
11:41:40.0320 0228  C:\Windows\System32\winsta.dll - ok
11:41:40.0320 0228  [ 633C2C060CF857099F6C4F8D75C952B1 ] C:\Windows\System32\WlS0WndH.dll
11:41:40.0320 0228  C:\Windows\System32\WlS0WndH.dll - ok
11:41:40.0336 0228  [ 919001D2BB17DF06CA3F8AC16AD039F6 ] C:\Windows\System32\sxs.dll
11:41:40.0336 0228  C:\Windows\System32\sxs.dll - ok
11:41:40.0336 0228  [ F08F6FCD09F9BE94C37ACC1B344685FF ] C:\Windows\System32\cryptbase.dll
11:41:40.0336 0228  C:\Windows\System32\cryptbase.dll - ok
11:41:40.0351 0228  [ 863F793D15B4026B1A5FDECA873D4D84 ] C:\Windows\System32\apphelp.dll
11:41:40.0351 0228  C:\Windows\System32\apphelp.dll - ok
11:41:40.0351 0228  [ 3369D021265E369D57317D61FA86DD79 ] C:\Windows\System32\scext.dll
11:41:40.0351 0228  C:\Windows\System32\scext.dll - ok
11:41:40.0367 0228  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\System32\services.exe
11:41:40.0367 0228  C:\Windows\System32\services.exe - ok
11:41:40.0367 0228  [ 4A054C853031616D161A84BECF281F47 ] C:\Windows\System32\sspicli.dll
11:41:40.0367 0228  C:\Windows\System32\sspicli.dll - ok
11:41:40.0383 0228  [ 81951F51E318AECC2D68559E47485CC4 ] C:\Windows\System32\lsass.exe
11:41:40.0383 0228  C:\Windows\System32\lsass.exe - ok
11:41:40.0383 0228  [ 250AA41DE690561AF1282D598914564C ] C:\Windows\System32\scesrv.dll
11:41:40.0383 0228  C:\Windows\System32\scesrv.dll - ok
11:41:40.0398 0228  [ 69678722290C78D5D7198C60B5A4E3E8 ] C:\Windows\System32\secur32.dll
11:41:40.0398 0228  C:\Windows\System32\secur32.dll - ok
11:41:40.0398 0228  [ 5CCDCD40E732D54E0F7451AC66AC1C87 ] C:\Windows\System32\srvcli.dll
11:41:40.0398 0228  C:\Windows\System32\srvcli.dll - ok
11:41:40.0414 0228  [ E361AE3010EA4B3123DAB5BDAE21798F ] C:\Windows\System32\sspisrv.dll
11:41:40.0414 0228  C:\Windows\System32\sspisrv.dll - ok
11:41:40.0414 0228  [ C95CA687D32DDAB1C91E1122E80D5E16 ] C:\Windows\System32\lsasrv.dll
11:41:40.0414 0228  C:\Windows\System32\lsasrv.dll - ok
11:41:40.0429 0228  [ 8AEA9A37C1A3565A204D37C5E72AB791 ] C:\Windows\System32\lsm.exe
11:41:40.0429 0228  C:\Windows\System32\lsm.exe - ok
11:41:40.0429 0228  [ BA51FFE170C5B3AE8EC4F5BD2581A29E ] C:\Windows\System32\sysntfy.dll
11:41:40.0429 0228  C:\Windows\System32\sysntfy.dll - ok
11:41:40.0445 0228  [ D412B1B72C5AB020218E9A047D90CA05 ] C:\Windows\System32\wmsgapi.dll
11:41:40.0445 0228  C:\Windows\System32\wmsgapi.dll - ok
11:41:40.0445 0228  [ 245F4691314F42D4D1BC06442F0B2086 ] C:\Windows\System32\samsrv.dll
11:41:40.0445 0228  C:\Windows\System32\samsrv.dll - ok
11:41:40.0461 0228  [ FB4EB9352B7D698E6B3C2AA2ED724DAD ] C:\Windows\System32\authz.dll
11:41:40.0461 0228  C:\Windows\System32\authz.dll - ok
11:41:40.0461 0228  [ 50BA656134F78AF64E4DD3C8B6FEFD7E ] C:\Windows\System32\cngaudit.dll
11:41:40.0461 0228  C:\Windows\System32\cngaudit.dll - ok
11:41:40.0476 0228  [ 1128637CAD49A8E3C8B5FA5D0A061525 ] C:\Windows\System32\cryptdll.dll
11:41:40.0476 0228  C:\Windows\System32\cryptdll.dll - ok
11:41:40.0476 0228  [ 82C089EA2A3EEFADF3588EA71E8BDADA ] C:\Windows\System32\wevtapi.dll
11:41:40.0476 0228  C:\Windows\System32\wevtapi.dll - ok
11:41:40.0492 0228  [ FC7650224790CAE75A5E9231961FDEC5 ] C:\Windows\System32\bcrypt.dll
11:41:40.0492 0228  C:\Windows\System32\bcrypt.dll - ok
11:41:40.0492 0228  [ BF6D6ED5FADCEEE885BD0144ECF1BA27 ] C:\Windows\System32\ncrypt.dll
11:41:40.0492 0228  C:\Windows\System32\ncrypt.dll - ok
11:41:40.0507 0228  [ C90878913DF3DC504790282043DB5F4C ] C:\Windows\System32\msprivs.dll
11:41:40.0507 0228  C:\Windows\System32\msprivs.dll - ok
11:41:40.0507 0228  [ E343CABBD8D600ABAF3F11625D33B3D0 ] C:\Windows\System32\netjoin.dll
11:41:40.0507 0228  C:\Windows\System32\netjoin.dll - ok
11:41:40.0523 0228  [ BDA0B954A30498B5A7EDC6204CBA07ED ] C:\Windows\System32\kerberos.dll
11:41:40.0523 0228  C:\Windows\System32\kerberos.dll - ok
11:41:40.0523 0228  [ 6DCFAEC6D1334AA6CDF8961DB4633CBF ] C:\Windows\System32\negoexts.dll
11:41:40.0523 0228  C:\Windows\System32\negoexts.dll - ok
11:41:40.0539 0228  [ 7321F18D1F820612ED0E9F2D4B578A7E ] C:\Windows\System32\cryptsp.dll
11:41:40.0539 0228  C:\Windows\System32\cryptsp.dll - ok
11:41:40.0539 0228  [ FD1D6C73E6333BE727CBCC6054247654 ] C:\Windows\System32\drivers\TsUsbFlt.sys
11:41:40.0539 0228  C:\Windows\System32\drivers\TsUsbFlt.sys - ok
11:41:40.0554 0228  [ 702254574E7E52052DE39408457B7149 ] C:\Windows\System32\version.dll
11:41:40.0554 0228  C:\Windows\System32\version.dll - ok
11:41:40.0554 0228  [ 8999B8631C7FD9F7F9EC3CAFD953BA24 ] C:\Windows\System32\mswsock.dll
11:41:40.0554 0228  C:\Windows\System32\mswsock.dll - ok
11:41:40.0570 0228  [ 73E8667A19FEEDD856DF2695E9E511D4 ] C:\Windows\System32\wship6.dll
11:41:40.0570 0228  C:\Windows\System32\wship6.dll - ok
11:41:40.0570 0228  [ 4C1E16B9A53102C8D6FBA587CBCB95DE ] C:\Windows\System32\msv1_0.dll
11:41:40.0570 0228  C:\Windows\System32\msv1_0.dll - ok
11:41:40.0585 0228  [ C1809B9907ADEDAF16F50C894100883B ] C:\Windows\System32\netlogon.dll
11:41:40.0585 0228  C:\Windows\System32\netlogon.dll - ok
11:41:40.0585 0228  [ B40420876B9288E0A1C8CCA8A84E5DC9 ] C:\Windows\System32\dnsapi.dll
11:41:40.0585 0228  C:\Windows\System32\dnsapi.dll - ok
11:41:40.0601 0228  [ 8EA53101FF2B15BDFF934B62A8FB326D ] C:\Windows\System32\logoncli.dll
11:41:40.0601 0228  C:\Windows\System32\logoncli.dll - ok
11:41:40.0601 0228  [ 3D3CBD1847F980FB03343A63671E7886 ] C:\Windows\System32\schannel.dll
11:41:40.0601 0228  C:\Windows\System32\schannel.dll - ok
11:41:40.0617 0228  [ 0450CF487ECD8A67B56F59F9A96D024D ] C:\Windows\System32\wdigest.dll
11:41:40.0617 0228  C:\Windows\System32\wdigest.dll - ok
11:41:40.0617 0228  [ ED8EC63F7522DF4852147C84EC62C36A ] C:\Windows\System32\rsaenh.dll
11:41:40.0617 0228  C:\Windows\System32\rsaenh.dll - ok
11:41:40.0632 0228  [ 37CC990D4E2CDFAE12AC47F6B620FC13 ] C:\Windows\System32\pku2u.dll
11:41:40.0632 0228  C:\Windows\System32\pku2u.dll - ok
11:41:40.0632 0228  [ D29E45078CF4020CE0AAC82EC652D1EA ] C:\Windows\System32\TSpkg.dll
11:41:40.0632 0228  C:\Windows\System32\TSpkg.dll - ok
11:41:40.0648 0228  [ E8449FE262D7406BCB2AC2A45C53EC5F ] C:\Windows\System32\bcryptprimitives.dll
11:41:40.0648 0228  C:\Windows\System32\bcryptprimitives.dll - ok
11:41:40.0663 0228  [ 91F434FF6606ED9BDC6A05D651B69553 ] C:\Windows\System32\efslsaext.dll
11:41:40.0663 0228  C:\Windows\System32\efslsaext.dll - ok
11:41:40.0663 0228  [ 4E5FE39C1076D115EC8BFCFE14D75B80 ] C:\Windows\System32\credssp.dll
11:41:40.0663 0228  C:\Windows\System32\credssp.dll - ok
11:41:40.0679 0228  [ 7222995615BF93B628DCEA4BD6CCACF7 ] C:\Windows\System32\ubpm.dll
11:41:40.0679 0228  C:\Windows\System32\ubpm.dll - ok
11:41:40.0679 0228  [ 8124944EC89D6A1815E4E53F5B96AAF4 ] C:\Windows\System32\scecli.dll
11:41:40.0679 0228  C:\Windows\System32\scecli.dll - ok
11:41:40.0695 0228  [ 4BDBBE5E4208022DD794F7EEEB0F7366 ] C:\Windows\System32\SPInf.dll
11:41:40.0695 0228  C:\Windows\System32\SPInf.dll - ok
11:41:40.0695 0228  [ 54A47F6B5E09A77E61649109C6A08866 ] C:\Windows\System32\svchost.exe
11:41:40.0695 0228  C:\Windows\System32\svchost.exe - ok
11:41:40.0710 0228  [ EC7BC28D207DA09E79B3E9FAF8B232CA ] C:\Windows\System32\umpnpmgr.dll
11:41:40.0710 0228  C:\Windows\System32\umpnpmgr.dll - ok
11:41:40.0710 0228  [ FD07F21E0A19C27ED4E1EEC2B07452B3 ] C:\Windows\System32\devrtl.dll
11:41:40.0710 0228  C:\Windows\System32\devrtl.dll - ok
11:41:40.0726 0228  [ 1097F3035BAF46CED8B332B3564C5108 ] C:\Windows\System32\gpapi.dll
11:41:40.0726 0228  C:\Windows\System32\gpapi.dll - ok
11:41:40.0726 0228  [ D15618A0FF8DBC2C5BF3726BACC75A0B ] C:\Windows\System32\userenv.dll
11:41:40.0726 0228  C:\Windows\System32\userenv.dll - ok
11:41:40.0741 0228  [ 5893EBDCE371174AC89ECD7731DD6D77 ] C:\Windows\System32\pcwum.dll
11:41:40.0741 0228  C:\Windows\System32\pcwum.dll - ok
11:41:40.0741 0228  [ F87D30E72E03D579A5199CCB3831D6EA ] C:\Windows\System32\umpo.dll
11:41:40.0741 0228  C:\Windows\System32\umpo.dll - ok
11:41:40.0757 0228  [ 08DFDBD2FD4EA951DC46B1C7661ED35A ] C:\Windows\System32\powrprof.dll
11:41:40.0757 0228  C:\Windows\System32\powrprof.dll - ok
11:41:40.0757 0228  [ 6703E366CC18D3B6E534F5CF7DF39CEE ] C:\Windows\System32\drivers\luafv.sys
11:41:40.0757 0228  C:\Windows\System32\drivers\luafv.sys - ok
11:41:40.0773 0228  [ 7660F01D3B38ACA1747E397D21D790AF ] C:\Windows\System32\rpcss.dll
11:41:40.0773 0228  C:\Windows\System32\rpcss.dll - ok
11:41:40.0773 0228  [ 78D072F35BC45D9E4E1B61895C152234 ] C:\Windows\System32\RpcEpMap.dll
11:41:40.0773 0228  C:\Windows\System32\RpcEpMap.dll - ok
11:41:40.0788 0228  [ 81F08948A0F1475894C99D4D19A158A8 ] C:\Windows\System32\wshqos.dll
11:41:40.0788 0228  C:\Windows\System32\wshqos.dll - ok
11:41:40.0788 0228  [ EE5C8E27C37B79CB54A2FCEEED2DC262 ] C:\Windows\System32\WSHTCPIP.DLL
11:41:40.0788 0228  C:\Windows\System32\WSHTCPIP.DLL - ok
11:41:40.0804 0228  [ 3F50200237961034FACE602373838980 ] C:\Windows\System32\FirewallAPI.dll
11:41:40.0804 0228  C:\Windows\System32\FirewallAPI.dll - ok
11:41:40.0804 0228  [ 3EF0D8AB08385AAB5802E773511A2E6A ] C:\Windows\System32\LogonUI.exe
11:41:40.0804 0228  C:\Windows\System32\LogonUI.exe - ok
11:41:40.0819 0228  [ 241E015DD809CFB23242F890B1FC575B ] C:\Windows\System32\wevtsvc.dll
11:41:40.0819 0228  C:\Windows\System32\wevtsvc.dll - ok
11:41:40.0819 0228  [ E904178851A6A44BFA97E064EF779E9D ] C:\Windows\System32\authui.dll
11:41:40.0819 0228  C:\Windows\System32\authui.dll - ok
11:41:40.0835 0228  [ 139D3AB6AA920C34C50CBFFB9EB7D222 ] C:\Windows\System32\avrt.dll
11:41:40.0835 0228  C:\Windows\System32\avrt.dll - ok
11:41:40.0835 0228  [ 146B6F43A673379A3C670E86D89BE5EA ] C:\Windows\System32\mmcss.dll
11:41:40.0835 0228  C:\Windows\System32\mmcss.dll - ok
11:41:40.0851 0228  [ CE3B4E731638D2EF62FCB419BE0D39F0 ] C:\Windows\System32\audiosrv.dll
11:41:40.0851 0228  C:\Windows\System32\audiosrv.dll - ok
11:41:40.0851 0228  [ E12C4928B32ACE04610259647F072635 ] C:\Windows\System32\FntCache.dll
11:41:40.0851 0228  C:\Windows\System32\FntCache.dll - ok
11:41:40.0866 0228  [ CADEFAC453040E370A1BDFF3973BE00D ] C:\Windows\System32\profsvc.dll
11:41:40.0866 0228  C:\Windows\System32\profsvc.dll - ok
11:41:40.0866 0228  [ 243974EC02F7AE49E4179C54624143AB ] C:\Windows\System32\MMDevAPI.dll
11:41:40.0866 0228  C:\Windows\System32\MMDevAPI.dll - ok
11:41:40.0882 0228  [ 12C45E3CB6D65F73209549E2D02ECA7A ] C:\Windows\System32\propsys.dll
11:41:40.0882 0228  C:\Windows\System32\propsys.dll - ok
11:41:40.0882 0228  [ F68194F74350D4A2ADE98961E33F884C ] C:\Windows\System32\audiodg.exe
11:41:40.0882 0228  C:\Windows\System32\audiodg.exe - ok
11:41:40.0897 0228  [ 28CA821606669BB9215CE010767720FA ] C:\Windows\System32\cryptui.dll
11:41:40.0897 0228  C:\Windows\System32\cryptui.dll - ok
11:41:40.0897 0228  [ 352B3DC62A0D259A82A052238425C872 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
11:41:40.0897 0228  C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - ok
11:41:40.0913 0228  [ 3FD15B4611D9BDA3F8013548C0ECAECA ] C:\Windows\System32\ntmarta.dll
11:41:40.0913 0228  C:\Windows\System32\ntmarta.dll - ok
11:41:40.0913 0228  [ E897EAF5ED6BA41E081060C9B447A673 ] C:\Windows\System32\gpsvc.dll
11:41:40.0913 0228  C:\Windows\System32\gpsvc.dll - ok
11:41:40.0929 0228  [ 50E0DD0A5B8D8BC353578F2F73926697 ] C:\Windows\System32\nlaapi.dll
11:41:40.0929 0228  C:\Windows\System32\nlaapi.dll - ok
11:41:40.0929 0228  [ F10E5311E5093FA3C00FF88C54C32FCA ] C:\Windows\System32\atl.dll
11:41:40.0929 0228  C:\Windows\System32\atl.dll - ok
11:41:40.0944 0228  [ 42FB6AFD6B79D9FE07381609172E7CA4 ] C:\Windows\System32\themeservice.dll
11:41:40.0944 0228  C:\Windows\System32\themeservice.dll - ok
11:41:40.0944 0228  [ AC8C80DC4F1A6E60C9A762C1799F0B39 ] C:\Windows\System32\adtschema.dll
11:41:40.0944 0228  C:\Windows\System32\adtschema.dll - ok
11:41:40.0960 0228  [ 2F040CF0613A6D64DCBBA9EE81F5A5AE ] C:\Windows\System32\dsrole.dll
11:41:40.0960 0228  C:\Windows\System32\dsrole.dll - ok
11:41:40.0960 0228  [ 5826854E4E420E29F59C2865F0FA562F ] C:\Program Files\Windows Defender\MpEvMsg.dll
11:41:40.0960 0228  C:\Program Files\Windows Defender\MpEvMsg.dll - ok
11:41:40.0975 0228  [ 8B74CEC6980D4816B0037AE9A27E538F ] C:\Windows\System32\slc.dll
11:41:40.0975 0228  C:\Windows\System32\slc.dll - ok
11:41:40.0975 0228  [ F6916EFC29D9953D5D0DF06882AE8E16 ] C:\Windows\System32\es.dll
11:41:40.0975 0228  C:\Windows\System32\es.dll - ok
11:41:40.0991 0228  [ DCB7FCDCC97F87360F75D77425B81737 ] C:\Windows\System32\Sens.dll
11:41:40.0991 0228  C:\Windows\System32\Sens.dll - ok
11:41:40.0991 0228  [ 808D8A8B2A3074002852BC856D419576 ] C:\Windows\System32\comres.dll
11:41:40.0991 0228  C:\Windows\System32\comres.dll - ok
11:41:41.0007 0228  [ 081E6E1C91AEC36758902A9F727CD23C ] C:\Windows\System32\uxsms.dll
11:41:41.0007 0228  C:\Windows\System32\uxsms.dll - ok
11:41:41.0007 0228  [ 6A6B2EE4565A178035BE2A4FF6F2C968 ] C:\Windows\System32\wtsapi32.dll
11:41:41.0007 0228  C:\Windows\System32\wtsapi32.dll - ok
11:41:41.0022 0228  [ F7611EC07349979DA9B0AE1F18CCC7A6 ] C:\Windows\System32\drivers\lltdio.sys
11:41:41.0022 0228  C:\Windows\System32\drivers\lltdio.sys - ok
11:41:41.0022 0228  [ 26384429FCD85D83746F63E798AB1480 ] C:\Windows\System32\drivers\nwifi.sys
11:41:41.0022 0228  C:\Windows\System32\drivers\nwifi.sys - ok
11:41:41.0038 0228  [ D8A65DAFB3EB41CBB622745676FCD072 ] C:\Windows\System32\drivers\ndisuio.sys
11:41:41.0038 0228  C:\Windows\System32\drivers\ndisuio.sys - ok
11:41:41.0038 0228  [ 032B0D36AD92B582D869879F5AF5B928 ] C:\Windows\System32\drivers\rspndr.sys
11:41:41.0038 0228  C:\Windows\System32\drivers\rspndr.sys - ok
11:41:41.0053 0228  [ BA387E955E890C8A88306D9B8D06BF17 ] C:\Windows\System32\nsisvc.dll
11:41:41.0053 0228  C:\Windows\System32\nsisvc.dll - ok
11:41:41.0069 0228  [ E9E01EB683C132F7FA27CD607B8A2B63 ] C:\Windows\System32\dhcpcore.dll
11:41:41.0069 0228  C:\Windows\System32\dhcpcore.dll - ok
11:41:41.0069 0228  [ CFF35B879D1618D42C86644C717BA947 ] C:\Windows\System32\winnsi.dll
11:41:41.0069 0228  C:\Windows\System32\winnsi.dll - ok
11:41:41.0085 0228  [ EF71BA5DF59034962B0C62314A71351A ] C:\Windows\System32\dhcpcore6.dll
11:41:41.0085 0228  C:\Windows\System32\dhcpcore6.dll - ok
11:41:41.0085 0228  [ 8600142FA91C1B96367D3300AD0F3F3A ] C:\Windows\System32\eapsvc.dll
11:41:41.0085 0228  C:\Windows\System32\eapsvc.dll - ok
11:41:41.0100 0228  [ A90DC9ABD65DB1A8902F361103029952 ] C:\Windows\System32\IPHLPAPI.DLL
11:41:41.0100 0228  C:\Windows\System32\IPHLPAPI.DLL - ok
11:41:41.0100 0228  [ AF75DBA674E55221B7A055B0A4345F16 ] C:\Windows\System32\keyiso.dll
11:41:41.0100 0228  C:\Windows\System32\keyiso.dll - ok
11:41:41.0116 0228  [ 9A892B3439884C62B04718F0303A49E9 ] C:\Windows\System32\eapphost.dll
11:41:41.0116 0228  C:\Windows\System32\eapphost.dll - ok
11:41:41.0116 0228  [ 33EF4861F19A0736B11314AAD9AE28D0 ] C:\Windows\System32\dnsrslvr.dll
11:41:41.0116 0228  C:\Windows\System32\dnsrslvr.dll - ok
11:41:41.0131 0228  [ 03A03A453F1AAAE0C73AAAF895321C7A ] C:\Windows\System32\FWPUCLNT.DLL
11:41:41.0131 0228  C:\Windows\System32\FWPUCLNT.DLL - ok
11:41:41.0131 0228  [ 100103C6535C66265267F5EEA5F5846E ] C:\Windows\System32\dnsext.dll
11:41:41.0131 0228  C:\Windows\System32\dnsext.dll - ok
11:41:41.0147 0228  [ 9A85ABCE0FDD1AF8E79E731EB0B679F3 ] C:\Windows\System32\dhcpcsvc.dll
11:41:41.0147 0228  C:\Windows\System32\dhcpcsvc.dll - ok
11:41:41.0147 0228  [ 81F6C1AE23B1C493D9E996C3103915D7 ] C:\Windows\System32\dhcpcsvc6.dll
11:41:41.0147 0228  C:\Windows\System32\dhcpcsvc6.dll - ok
11:41:41.0163 0228  [ D33E95C0A2754061233B58DC41F8094C ] C:\Windows\System32\umb.dll
11:41:41.0163 0228  C:\Windows\System32\umb.dll - ok
11:41:41.0163 0228  [ 16935C98FF639D185086A3529B1F2067 ] C:\Windows\System32\wlansvc.dll
11:41:41.0163 0228  C:\Windows\System32\wlansvc.dll - ok
11:41:41.0178 0228  [ 3C9035085141162416A0DD34DBF3F3C1 ] C:\Windows\System32\wlanmsm.dll
11:41:41.0178 0228  C:\Windows\System32\wlanmsm.dll - ok
11:41:41.0178 0228  [ 20C06A50DFC097E134BC6FA8444CA9BC ] C:\Windows\System32\wlansec.dll
11:41:41.0178 0228  C:\Windows\System32\wlansec.dll - ok
11:41:41.0194 0228  [ 5A5FEDDF02588B8F9FE4A95E5E7EAE97 ] C:\Windows\System32\eappcfg.dll
11:41:41.0194 0228  C:\Windows\System32\eappcfg.dll - ok
11:41:41.0194 0228  [ 666E57B6B51824D1D235F80A3DD70A13 ] C:\Windows\System32\eappprxy.dll
11:41:41.0194 0228  C:\Windows\System32\eappprxy.dll - ok
11:41:41.0209 0228  [ F748F53FE09D21D8ECBB6421E6792024 ] C:\Windows\System32\onex.dll
11:41:41.0209 0228  C:\Windows\System32\onex.dll - ok
11:41:41.0209 0228  [ 749F9795F01C35EEBE100A87D82B9681 ] C:\Windows\System32\wlgpclnt.dll
11:41:41.0209 0228  C:\Windows\System32\wlgpclnt.dll - ok
11:41:41.0225 0228  [ C1585EAA67C37A05BF6F93726FAFC069 ] C:\Windows\System32\l2gpstore.dll
11:41:41.0225 0228  C:\Windows\System32\l2gpstore.dll - ok
11:41:41.0225 0228  [ 9419ABF3163B6F0E3AD3DD2B381C879F ] C:\Windows\System32\WinSCard.dll
11:41:41.0225 0228  C:\Windows\System32\WinSCard.dll - ok
11:41:41.0241 0228  [ 1D6A771D1D702AE07919DB52C889A249 ] C:\Windows\System32\wlanutil.dll
11:41:41.0241 0228  C:\Windows\System32\wlanutil.dll - ok
11:41:41.0241 0228  [ 8C338238C16777A802D6A9211EB2BA50 ] C:\Windows\System32\netprofm.dll
11:41:41.0241 0228  C:\Windows\System32\netprofm.dll - ok
11:41:41.0256 0228  [ EAADD6E47ED2A7003ACE1793B98CF63F ] C:\Windows\System32\msxml6.dll
11:41:41.0256 0228  C:\Windows\System32\msxml6.dll - ok
11:41:41.0256 0228  [ 8B0B4C5927A333A05513791758350DC4 ] C:\Windows\System32\microsoft-windows-kernel-power-events.dll
11:41:41.0256 0228  C:\Windows\System32\microsoft-windows-kernel-power-events.dll - ok
11:41:41.0272 0228  [ F14A9B1778376D0B1788E402AC1F831A ] C:\Windows\System32\shacct.dll
11:41:41.0272 0228  C:\Windows\System32\shacct.dll - ok
11:41:41.0272 0228  [ C30A3E5DEEEBA22E782AC54C5AF5F352 ] C:\Windows\System32\samlib.dll
11:41:41.0272 0228  C:\Windows\System32\samlib.dll - ok
11:41:41.0287 0228  [ 63BFDF555DA2075A77D677829C3CCCD0 ] C:\Windows\System32\uxtheme.dll
11:41:41.0287 0228  C:\Windows\System32\uxtheme.dll - ok
11:41:41.0287 0228  [ 7717F84F483002815490033BF069DABD ] C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\GdiPlus.dll
11:41:41.0287 0228  C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\GdiPlus.dll - ok
11:41:41.0303 0228  [ EE06B85BC69F18826302348A2AD089E0 ] C:\Windows\System32\dui70.dll
11:41:41.0303 0228  C:\Windows\System32\dui70.dll - ok
11:41:41.0303 0228  [ 6E1F8165C365D35C8E3C045AF0CDD481 ] C:\Windows\System32\duser.dll
11:41:41.0303 0228  C:\Windows\System32\duser.dll - ok
11:41:41.0319 0228  [ 2CFA4569350B7F84F815E9EC34E85766 ] C:\Windows\System32\SndVolSSO.dll
11:41:41.0319 0228  C:\Windows\System32\SndVolSSO.dll - ok
11:41:41.0319 0228  [ 63DF770DF74ACB370EF5A16727069AAF ] C:\Windows\System32\hid.dll
11:41:41.0319 0228  C:\Windows\System32\hid.dll - ok
11:41:41.0334 0228  [ D5AEFAD57C08349A4393D987DF7C715D ] C:\Windows\System32\winmm.dll
11:41:41.0334 0228  C:\Windows\System32\winmm.dll - ok
11:41:41.0334 0228  [ 39C5F32747B3414D1BB216FDB1DEFC58 ] C:\Windows\System32\dwmapi.dll
11:41:41.0334 0228  C:\Windows\System32\dwmapi.dll - ok
11:41:41.0350 0228  [ EDF2A5E96BEC469DA3F64E9BDD386111 ] C:\Windows\System32\xmllite.dll
11:41:41.0350 0228  C:\Windows\System32\xmllite.dll - ok
11:41:41.0350 0228  [ 3BCECD87AB4E6743BFB45B352AD1A529 ] C:\Windows\System32\WindowsCodecs.dll
11:41:41.0350 0228  C:\Windows\System32\WindowsCodecs.dll - ok
11:41:41.0365 0228  [ 326C7F76A29897A892AA7726E91C1C67 ] C:\Windows\System32\winbrand.dll
11:41:41.0365 0228  C:\Windows\System32\winbrand.dll - ok
11:41:41.0365 0228  [ 65BF13016A3C22775F3E17591AE5268A ] C:\Windows\System32\VaultCredProvider.dll
11:41:41.0365 0228  C:\Windows\System32\VaultCredProvider.dll - ok
11:41:41.0381 0228  [ 05BF975CA428E04B462FB90841B37C95 ] C:\Windows\System32\SmartcardCredentialProvider.dll
11:41:41.0381 0228  C:\Windows\System32\SmartcardCredentialProvider.dll - ok
11:41:41.0397 0228  [ E59F08ED9D2A128CE436BBFC232247F6 ] C:\Windows\System32\BioCredProv.dll
11:41:41.0397 0228  C:\Windows\System32\BioCredProv.dll - ok
11:41:41.0397 0228  [ 108C2CFA5527458C096A699929ECBD80 ] C:\Windows\System32\credui.dll
11:41:41.0397 0228  C:\Windows\System32\credui.dll - ok
11:41:41.0412 0228  [ 3FAD263CE1E2A6FFF40D00043B2275E3 ] C:\Windows\System32\winbio.dll
11:41:41.0412 0228  C:\Windows\System32\winbio.dll - ok
11:41:41.0412 0228  [ 2FCA0D2C59A855C54BAFA22AA329DF0F ] C:\Windows\System32\netapi32.dll
11:41:41.0412 0228  C:\Windows\System32\netapi32.dll - ok
11:41:41.0428 0228  [ 20B3934DB73EABA2B49B7177873CB81F ] C:\Windows\System32\netutils.dll
11:41:41.0428 0228  C:\Windows\System32\netutils.dll - ok
11:41:41.0428 0228  [ 68ECCA523ED760AAFC03C5D587569859 ] C:\Windows\System32\samcli.dll
11:41:41.0428 0228  C:\Windows\System32\samcli.dll - ok
11:41:41.0443 0228  [ 36B8D5903CEEF0AA42A1EE002BD27FF1 ] C:\Windows\System32\vaultcli.dll
11:41:41.0443 0228  C:\Windows\System32\vaultcli.dll - ok
11:41:41.0443 0228  [ E5A4A1326A02F8E7B59E6C3270CE7202 ] C:\Windows\System32\wkscli.dll
11:41:41.0443 0228  C:\Windows\System32\wkscli.dll - ok
11:41:41.0459 0228  [ 6D8CACF3B1B54943EFCF420C2D667B37 ] C:\Windows\System32\certCredProvider.dll
11:41:41.0459 0228  C:\Windows\System32\certCredProvider.dll - ok
11:41:41.0459 0228  [ FFE4BEC5C187C426A17AE76A773063A6 ] C:\Windows\System32\rasplap.dll
11:41:41.0459 0228  C:\Windows\System32\rasplap.dll - ok
11:41:41.0475 0228  [ 839F96DBAAFD3353E0B248A5E0BD2A51 ] C:\Windows\System32\rasapi32.dll
11:41:41.0475 0228  C:\Windows\System32\rasapi32.dll - ok
11:41:41.0475 0228  [ FFA7172354B9256DBB2CDD75F16F33FE ] C:\Windows\System32\rasman.dll
11:41:41.0475 0228  C:\Windows\System32\rasman.dll - ok
11:41:41.0490 0228  [ 0915C4DB6DBC3BB9E11B7ECBBE4B7159 ] C:\Windows\System32\rtutils.dll
11:41:41.0490 0228  C:\Windows\System32\rtutils.dll - ok
11:41:41.0490 0228  [ 9C67F6BBDA3881CFD02095160CF91576 ] C:\Windows\System32\ksuser.dll
11:41:41.0490 0228  C:\Windows\System32\ksuser.dll - ok
11:41:41.0506 0228  [ D205C24A9D069049FE2DF2A1B38726A7 ] C:\Windows\System32\wdmaud.drv
11:41:41.0506 0228  C:\Windows\System32\wdmaud.drv - ok
11:41:41.0506 0228  [ C940F2F5C60B3727C5F18840735B229C ] C:\Windows\System32\AudioSes.dll
11:41:41.0506 0228  C:\Windows\System32\AudioSes.dll - ok
11:41:41.0521 0228  [ 1FF7E4F548C7C372C804938F0D5B36AE ] C:\Windows\System32\netcfgx.dll
11:41:41.0521 0228  C:\Windows\System32\netcfgx.dll - ok
11:41:41.0521 0228  [ 414DA952A35BF5D50192E28263B40577 ] C:\Windows\System32\shsvcs.dll
11:41:41.0521 0228  C:\Windows\System32\shsvcs.dll - ok
11:41:41.0537 0228  [ A12829E9974F57E9B5DBFEA7C93190F6 ] C:\Windows\System32\UXInit.dll
11:41:41.0537 0228  C:\Windows\System32\UXInit.dll - ok
11:41:41.0537 0228  [ 85683DF1F917E4D7F6BE1A04986BF1C8 ] C:\Windows\System32\msacm32.dll
11:41:41.0537 0228  C:\Windows\System32\msacm32.dll - ok
11:41:41.0553 0228  [ 07393A09C46083588E751B63B03C8301 ] C:\Windows\System32\msacm32.drv
11:41:41.0553 0228  C:\Windows\System32\msacm32.drv - ok
11:41:41.0553 0228  [ 5A12C364AD1D4FCC0AD0E56DBBC34462 ] C:\Windows\System32\midimap.dll
11:41:41.0553 0228  C:\Windows\System32\midimap.dll - ok
11:41:41.0568 0228  [ E6D90DC604F407B3B5E0FD285E46B2A0 ] C:\Windows\System32\fveapi.dll
11:41:41.0568 0228  C:\Windows\System32\fveapi.dll - ok
11:41:41.0568 0228  [ 827CB0D6C3F8057EA037FF271F8E9795 ] C:\Windows\System32\imageres.dll
11:41:41.0568 0228  C:\Windows\System32\imageres.dll - ok
11:41:41.0584 0228  [ EAFC149CD3BD78C443E31BB157841197 ] C:\Windows\System32\tbs.dll
11:41:41.0584 0228  C:\Windows\System32\tbs.dll - ok
11:41:41.0584 0228  [ C87F28A34B3840F4B40011D170B1A159 ] C:\Windows\System32\fvecerts.dll
11:41:41.0584 0228  C:\Windows\System32\fvecerts.dll - ok
11:41:41.0599 0228  [ A04BB13F8A72F8B6E8B4071723E4E336 ] C:\Windows\System32\schedsvc.dll
11:41:41.0599 0228  C:\Windows\System32\schedsvc.dll - ok
11:41:41.0599 0228  [ 38B13C0DF479DBA23ECFA815159BA86E ] C:\Windows\System32\ktmw32.dll
11:41:41.0599 0228  C:\Windows\System32\ktmw32.dll - ok
11:41:41.0615 0228  [ E2D56AE1D40E3725084054CD8E9CFBB1 ] C:\Windows\System32\wiarpc.dll
11:41:41.0615 0228  C:\Windows\System32\wiarpc.dll - ok
11:41:41.0615 0228  [ 1C3E8371377E988B683797A132EFFE1B ] C:\Windows\System32\taskcomp.dll
11:41:41.0615 0228  C:\Windows\System32\taskcomp.dll - ok
11:41:41.0631 0228  [ 871917B07A141BFF43D76D8844D48106 ] C:\Windows\System32\drivers\http.sys
11:41:41.0631 0228  C:\Windows\System32\drivers\http.sys - ok
11:41:41.0631 0228  [ 9AEA093B8F9C37CF45538382CABA2475 ] C:\Windows\System32\spoolsv.exe
11:41:41.0631 0228  C:\Windows\System32\spoolsv.exe - ok
11:41:41.0646 0228  [ 1E2BAC209D184BB851E1A187D8A29136 ] C:\Windows\System32\BFE.DLL
11:41:41.0646 0228  C:\Windows\System32\BFE.DLL - ok
11:41:41.0646 0228  [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] C:\Windows\System32\drivers\bowser.sys
11:41:41.0646 0228  C:\Windows\System32\drivers\bowser.sys - ok
11:41:41.0662 0228  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] C:\Windows\System32\drivers\mpsdrv.sys
11:41:41.0662 0228  C:\Windows\System32\drivers\mpsdrv.sys - ok
11:41:41.0662 0228  [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] C:\Windows\System32\drivers\mrxsmb.sys
11:41:41.0662 0228  C:\Windows\System32\drivers\mrxsmb.sys - ok
11:41:41.0677 0228  [ 6D17A4791ACA19328C685D256349FEFC ] C:\Windows\System32\drivers\mrxsmb10.sys
11:41:41.0677 0228  C:\Windows\System32\drivers\mrxsmb10.sys - ok
11:41:41.0677 0228  [ B81F204D146000BE76651A50670A5E9E ] C:\Windows\System32\drivers\mrxsmb20.sys
11:41:41.0677 0228  C:\Windows\System32\drivers\mrxsmb20.sys - ok
11:41:41.0693 0228  [ 9835584E999D25004E1EE8E5F3E3B881 ] C:\Windows\System32\MPSSVC.dll
11:41:41.0693 0228  C:\Windows\System32\MPSSVC.dll - ok
11:41:41.0693 0228  [ 7520EC808E0C35E0EE6F841294316653 ] C:\Windows\System32\drivers\fltMgr.sys
11:41:41.0693 0228  C:\Windows\System32\drivers\fltMgr.sys - ok
11:41:41.0709 0228  [ D93A937A2A9D2CBC06B3A615A197011F ] C:\Windows\System32\PSHED.DLL
11:41:41.0709 0228  C:\Windows\System32\PSHED.DLL - ok
11:41:41.0709 0228  [ BBA9D5A730D5E304117AD26923EBD8AA ] C:\Windows\System32\AudioEng.dll
11:41:41.0709 0228  C:\Windows\System32\AudioEng.dll - ok
11:41:41.0724 0228  [ 58405E4F68BA8E4057C6E914F326ABA2 ] C:\Windows\System32\wkssvc.dll
11:41:41.0724 0228  C:\Windows\System32\wkssvc.dll - ok
11:41:41.0724 0228  [ 96C0E38905CFD788313BE8E11DAE3F2F ] C:\Windows\System32\cryptsvc.dll
11:41:41.0724 0228  C:\Windows\System32\cryptsvc.dll - ok
11:41:41.0740 0228  [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] C:\Windows\System32\drivers\parport.sys
11:41:41.0740 0228  C:\Windows\System32\drivers\parport.sys - ok
11:41:41.0740 0228  [ 1F5497D7D3D79C7BF0AB0C8B4C5BFE6E ] C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll
11:41:41.0740 0228  C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll - ok
11:41:41.0755 0228  [ 96F0F8F4DEE598C8D12AD9633E0CFE2A ] C:\Windows\System32\AUDIOKSE.dll
11:41:41.0755 0228  C:\Windows\System32\AUDIOKSE.dll - ok
11:41:41.0755 0228  [ CA79539D3D4C0BA66F0F051A5EE5E923 ] C:\Windows\System32\cryptnet.dll
11:41:41.0755 0228  C:\Windows\System32\cryptnet.dll - ok
11:41:41.0771 0228  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] C:\Windows\System32\FDResPub.dll
11:41:41.0771 0228  C:\Windows\System32\FDResPub.dll - ok
11:41:41.0771 0228  [ 4E30ED3E551E867ADD1C8D58F5EDD9DF ] C:\Windows\System32\WMALFXGFXDSP.dll
11:41:41.0771 0228  C:\Windows\System32\WMALFXGFXDSP.dll - ok
11:41:41.0787 0228  [ 40B82688907A7DBA4DB3B5ADDE3EAB3B ] C:\Windows\System32\mfplat.dll
11:41:41.0787 0228  C:\Windows\System32\mfplat.dll - ok
11:41:41.0787 0228  [ 8EC04CA86F1D68DA9E11952EB85973D6 ] C:\Windows\System32\dps.dll
11:41:41.0787 0228  C:\Windows\System32\dps.dll - ok
11:41:41.0802 0228  [ 544EFF88AC6C85DF5A4D6F18DFE08CFC ] C:\Windows\System32\taskschd.dll
11:41:41.0802 0228  C:\Windows\System32\taskschd.dll - ok
11:41:41.0802 0228  [ 13337A3FB17F2242487FD45488ED0485 ] C:\Windows\System32\vssapi.dll
11:41:41.0802 0228  C:\Windows\System32\vssapi.dll - ok
11:41:41.0818 0228  [ 019C372B1A9DA73A22D0D35A4D40F5C9 ] C:\Windows\System32\wfapigp.dll
11:41:41.0818 0228  C:\Windows\System32\wfapigp.dll - ok
11:41:41.0833 0228  [ B940289C83121046BD6A60ACC6028593 ] C:\Windows\System32\vsstrace.dll
11:41:41.0833 0228  C:\Windows\System32\vsstrace.dll - ok
11:41:41.0833 0228  [ 7F8678C59F188528D60104E697C2361E ] C:\Windows\System32\mscms.dll
11:41:41.0833 0228  C:\Windows\System32\mscms.dll - ok
11:41:41.0833 0228  [ 358AB7956D3160000726574083DFC8A6 ] C:\Windows\System32\pcasvc.dll
11:41:41.0833 0228  C:\Windows\System32\pcasvc.dll - ok
11:41:41.0849 0228  [ 6A984831644ECA1A33FFEAE4126F4F37 ] C:\Windows\System32\snmptrap.exe
11:41:41.0849 0228  C:\Windows\System32\snmptrap.exe - ok
11:41:41.0849 0228  [ 55CA01BA19D0006C8F2639B6C045E08B ] C:\Windows\System32\lmhsvc.dll
11:41:41.0849 0228  C:\Windows\System32\lmhsvc.dll - ok
11:41:41.0865 0228  [ 73F6C5223F7E9B5780DD4A6C30FCF569 ] C:\Windows\System32\WSDApi.dll
11:41:41.0865 0228  C:\Windows\System32\WSDApi.dll - ok
11:41:41.0880 0228  [ DB846EECA70EE9D2E2FF31147C57B0F4 ] C:\Windows\System32\webservices.dll
11:41:41.0880 0228  C:\Windows\System32\webservices.dll - ok
11:41:41.0880 0228  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] C:\Windows\System32\provsvc.dll
11:41:41.0880 0228  C:\Windows\System32\provsvc.dll - ok
11:41:41.0896 0228  [ D318F23BE45D5E3A107469EB64815B50 ] C:\Windows\System32\sstpsvc.dll
11:41:41.0896 0228  C:\Windows\System32\sstpsvc.dll - ok
11:41:41.0896 0228  [ 9E0104BA49F4E6973749A02BF41344ED ] C:\Windows\System32\drivers\PEAuth.sys
11:41:41.0896 0228  C:\Windows\System32\drivers\PEAuth.sys - ok
11:41:41.0911 0228  [ 374071043F9E4231EE43BE2BB48DD36D ] C:\Windows\System32\nlasvc.dll
11:41:41.0911 0228  C:\Windows\System32\nlasvc.dll - ok
11:41:41.0911 0228  [ 90A3935D05B494A5A39D37E71F09A677 ] C:\Windows\System32\drivers\secdrv.sys
11:41:41.0911 0228  C:\Windows\System32\drivers\secdrv.sys - ok
11:41:41.0927 0228  [ BE6BD660CAA6F291AE06A718A4FA8ABC ] C:\Windows\System32\drivers\srvnet.sys
11:41:41.0927 0228  C:\Windows\System32\drivers\srvnet.sys - ok
11:41:41.0927 0228  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] C:\Windows\System32\drivers\tcpipreg.sys
11:41:41.0927 0228  C:\Windows\System32\drivers\tcpipreg.sys - ok
11:41:41.0943 0228  [ 36650D618CA34C9D357DFD3D89B2C56F ] C:\Windows\System32\sysmain.dll
11:41:41.0943 0228  C:\Windows\System32\sysmain.dll - ok
11:41:41.0943 0228  [ 140D9F911182357626165EA0BEB98C4F ] C:\Windows\System32\ncsi.dll
11:41:41.0943 0228  C:\Windows\System32\ncsi.dll - ok
11:41:41.0958 0228  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] C:\Windows\System32\trkwks.dll
11:41:41.0958 0228  C:\Windows\System32\trkwks.dll - ok
11:41:41.0958 0228  [ F62E510B6AD4C21EB9FE8668ED251826 ] C:\Windows\System32\wbem\WMIsvc.dll
11:41:41.0958 0228  C:\Windows\System32\wbem\WMIsvc.dll - ok
11:41:41.0974 0228  [ 704314FD398C81D5F342CAA5DF7B7F21 ] C:\Windows\System32\wbemcomn.dll
11:41:41.0974 0228  C:\Windows\System32\wbemcomn.dll - ok
11:41:41.0974 0228  [ 881D9F2D6E04E1C323050CF1574870F7 ] C:\Windows\System32\wbem\WinMgmtR.dll
11:41:41.0974 0228  C:\Windows\System32\wbem\WinMgmtR.dll - ok
11:41:41.0989 0228  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] C:\Windows\System32\drivers\srv2.sys
11:41:41.0989 0228  C:\Windows\System32\drivers\srv2.sys - ok
11:41:41.0989 0228  [ CA9F7888B524D8100B977C81F44C3234 ] C:\Windows\System32\winhttp.dll
11:41:41.0989 0228  C:\Windows\System32\winhttp.dll - ok
11:41:42.0005 0228  [ FB19FC5951A88F3C523E35C2C98D23C0 ] C:\Windows\System32\webio.dll
11:41:42.0005 0228  C:\Windows\System32\webio.dll - ok
11:41:42.0005 0228  [ E4C2764065D66EA1D2D3EBC28FE99C46 ] C:\Windows\System32\drivers\srv.sys
11:41:42.0005 0228  C:\Windows\System32\drivers\srv.sys - ok
11:41:42.0021 0228  [ 28E2231BD34A39C854BDF3923AB2FF86 ] C:\Windows\System32\ssdpapi.dll
11:41:42.0021 0228  C:\Windows\System32\ssdpapi.dll - ok
11:41:42.0021 0228  [ 58F67245D041FBE7AF88F4EAF79DF0FA ] C:\Windows\System32\iphlpsvc.dll
11:41:42.0021 0228  C:\Windows\System32\iphlpsvc.dll - ok
11:41:42.0036 0228  [ CE292C4C10B8DB6070F262EA2733F0DC ] C:\Windows\System32\sqmapi.dll
11:41:42.0036 0228  C:\Windows\System32\sqmapi.dll - ok
11:41:42.0036 0228  [ A399514D3B28C9A3453A486BBAAFF1C7 ] C:\Windows\System32\wdscore.dll
11:41:42.0036 0228  C:\Windows\System32\wdscore.dll - ok
11:41:42.0052 0228  [ 3DAA727B5B0A45039B0E1C9A211B8400 ] C:\Windows\System32\browser.dll
11:41:42.0052 0228  C:\Windows\System32\browser.dll - ok
11:41:42.0052 0228  [ D64AF876D53ECA3668BB97B51B4E70AB ] C:\Windows\System32\srvsvc.dll
11:41:42.0052 0228  C:\Windows\System32\srvsvc.dll - ok
11:41:42.0067 0228  [ E4B72E71EC37A59FE574A998A0C0EB9B ] C:\Windows\System32\netmsg.dll
11:41:42.0067 0228  C:\Windows\System32\netmsg.dll - ok
11:41:42.0067 0228  [ 89E783711AF91AF09E1EF30EF3107446 ] C:\Windows\System32\sscore.dll
11:41:42.0067 0228  C:\Windows\System32\sscore.dll - ok
11:41:42.0083 0228  [ 701C9EB15E1E23D22F7C7184C0506673 ] C:\Windows\System32\wbem\WmiDcPrv.dll
11:41:42.0083 0228  C:\Windows\System32\wbem\WmiDcPrv.dll - ok
11:41:42.0083 0228  [ CFC7D8289D2B5F3CF8D16E2DB7F93D4A ] C:\Windows\System32\wbem\fastprox.dll
11:41:42.0083 0228  C:\Windows\System32\wbem\fastprox.dll - ok
11:41:42.0099 0228  [ E3E811471DE781900FF21C1FD84E941E ] C:\Windows\System32\ntdsapi.dll
11:41:42.0099 0228  C:\Windows\System32\ntdsapi.dll - ok
11:41:42.0099 0228  [ C5B0324DB461559ADD070E632A6919FA ] C:\Windows\System32\wbem\wbemprox.dll
11:41:42.0099 0228  C:\Windows\System32\wbem\wbemprox.dll - ok
11:41:42.0114 0228  [ AE9898D5600A232CD8AE3298692162E5 ] C:\Windows\System32\clusapi.dll
11:41:42.0114 0228  C:\Windows\System32\clusapi.dll - ok
11:41:42.0114 0228  [ 2AF094C822BD6094F14A8E85FB51D52A ] C:\Windows\System32\resutils.dll
11:41:42.0114 0228  C:\Windows\System32\resutils.dll - ok
11:41:42.0130 0228  [ 585EB475E7AF55C9065256E8FFB751A1 ] C:\Windows\System32\wbem\wbemcore.dll
11:41:42.0130 0228  C:\Windows\System32\wbem\wbemcore.dll - ok
11:41:42.0130 0228  [ 5AE88135C6A86FCD67BA16AFBB1C8389 ] C:\Windows\System32\wbem\esscli.dll
11:41:42.0130 0228  C:\Windows\System32\wbem\esscli.dll - ok
11:41:42.0145 0228  [ 776AE0564F8B1C282E331FD95A1BDC5F ] C:\Windows\System32\wbem\wbemsvc.dll
11:41:42.0145 0228  C:\Windows\System32\wbem\wbemsvc.dll - ok
11:41:42.0145 0228  [ 6383C60EC0133B14F5705F96369421B2 ] C:\Windows\System32\hnetcfg.dll
11:41:42.0145 0228  C:\Windows\System32\hnetcfg.dll - ok
11:41:42.0161 0228  [ 371E3B05894549113D07CD3081ED55EF ] C:\Windows\System32\wbem\repdrvfs.dll
11:41:42.0161 0228  C:\Windows\System32\wbem\repdrvfs.dll - ok
11:41:42.0161 0228  [ 5610B0425518D185331CB8E968D060E6 ] C:\Windows\System32\wbem\wmiutils.dll
11:41:42.0161 0228  C:\Windows\System32\wbem\wmiutils.dll - ok
11:41:42.0177 0228  [ ED6EE83D61EBC683C2CD8E899EA6FEBE ] C:\Windows\System32\rasadhlp.dll
11:41:42.0177 0228  C:\Windows\System32\rasadhlp.dll - ok
11:41:42.0177 0228  [ 89D90579E5FB1469CB0464F6512E42B7 ] C:\Windows\System32\fundisc.dll
11:41:42.0177 0228  C:\Windows\System32\fundisc.dll - ok
11:41:42.0192 0228  [ 8CD1DEE212E52B9C22E66DBA44991D32 ] C:\Windows\System32\httpapi.dll
11:41:42.0192 0228  C:\Windows\System32\httpapi.dll - ok
11:41:42.0192 0228  [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] C:\Windows\System32\wdi.dll
11:41:42.0192 0228  C:\Windows\System32\wdi.dll - ok
11:41:42.0208 0228  [ AA53356D60AF47EACC85BC617A4F3F66 ] C:\Windows\System32\wpdbusenum.dll
11:41:42.0208 0228  C:\Windows\System32\wpdbusenum.dll - ok
11:41:42.0208 0228  [ 15E298B5EC5B89C5994A59863969D9FF ] C:\Windows\System32\npmproxy.dll
11:41:42.0208 0228  C:\Windows\System32\npmproxy.dll - ok
11:41:42.0223 0228  [ D99621C0735B21DCC8BC4FEF02F379EF ] C:\Windows\System32\Apphlpdm.dll
11:41:42.0223 0228  C:\Windows\System32\Apphlpdm.dll - ok
11:41:42.0223 0228  [ F7FE730CE31B54145DEE1F1482BCCDD7 ] C:\Windows\System32\ndiscapCfg.dll
11:41:42.0223 0228  C:\Windows\System32\ndiscapCfg.dll - ok
11:41:42.0239 0228  [ D4191EFAB91E00FC09257AA5EBAF503B ] C:\Windows\System32\mprapi.dll
11:41:42.0239 0228  C:\Windows\System32\mprapi.dll - ok
11:41:42.0239 0228  [ 9A7B54D57594233EEB17892BAD309970 ] C:\Windows\System32\mprmsg.dll
11:41:42.0239 0228  C:\Windows\System32\mprmsg.dll - ok
11:41:42.0255 0228  [ 761A3A4038C1FD4F5795427907C28484 ] C:\Windows\System32\rascfg.dll
11:41:42.0255 0228  C:\Windows\System32\rascfg.dll - ok
11:41:42.0270 0228  [ CAFC0B884E5590B5E80D84F592388B3D ] C:\Windows\System32\tcpipcfg.dll
11:41:42.0270 0228  C:\Windows\System32\tcpipcfg.dll - ok
11:41:42.0270 0228  [ 590D5C506044FE02FF7643E32FF9BDAC ] C:\Windows\System32\wer.dll
11:41:42.0270 0228  C:\Windows\System32\wer.dll - ok
11:41:42.0286 0228  [ ECF036299AA554B5E0455262857B39D0 ] C:\Windows\System32\diagperf.dll
11:41:42.0286 0228  C:\Windows\System32\diagperf.dll - ok
11:41:42.0286 0228  [ 7E82616BEE76BF5EAA5B30F681414E21 ] C:\Windows\System32\perftrack.dll
11:41:42.0286 0228  C:\Windows\System32\perftrack.dll - ok
11:41:42.0301 0228  [ 8B794AE6D5C7D42092804BC39A2EB8F6 ] C:\Windows\System32\aepic.dll
11:41:42.0301 0228  C:\Windows\System32\aepic.dll - ok
11:41:42.0301 0228  [ 40CAEEE0EAF1B8569F7C8DF6420F2CB9 ] C:\Windows\System32\sfc.dll
11:41:42.0301 0228  C:\Windows\System32\sfc.dll - ok
11:41:42.0317 0228  [ 84799328D87B3091A3BDD251E1AD31F9 ] C:\Windows\System32\sfc_os.dll
11:41:42.0317 0228  C:\Windows\System32\sfc_os.dll - ok
11:41:42.0317 0228  [ F8E882C10AF4C29E378D1E28D4817CB1 ] C:\Windows\System32\pnpts.dll
11:41:42.0317 0228  C:\Windows\System32\pnpts.dll - ok
11:41:42.0333 0228  [ E98278865E8DABA21CFE5FE4BE34210A ] C:\Windows\System32\PortableDeviceApi.dll
11:41:42.0333 0228  C:\Windows\System32\PortableDeviceApi.dll - ok
11:41:42.0333 0228  [ C693E642ACFBDD76433AF6BE3C3EEE6F ] C:\Windows\System32\PortableDeviceConnectApi.dll
11:41:42.0333 0228  C:\Windows\System32\PortableDeviceConnectApi.dll - ok
11:41:42.0348 0228  [ 3CDE2911462FEC80064A409C07710C06 ] C:\Windows\System32\wbem\WmiPrvSD.dll
11:41:42.0348 0228  C:\Windows\System32\wbem\WmiPrvSD.dll - ok
11:41:42.0348 0228  [ A4CC7227A452C4909F9499D91B184364 ] C:\Windows\System32\ncobjapi.dll
11:41:42.0348 0228  C:\Windows\System32\ncobjapi.dll - ok
11:41:42.0364 0228  [ B350509B6C9296529BC464C60FEEAEF1 ] C:\Windows\System32\wbem\wbemess.dll
11:41:42.0364 0228  C:\Windows\System32\wbem\wbemess.dll - ok
11:41:42.0364 0228  [ F0016853FA3F38F55FD868FF74C0359B ] C:\Windows\System32\wdiasqmmodule.dll
11:41:42.0364 0228  C:\Windows\System32\wdiasqmmodule.dll - ok
11:41:42.0379 0228  [ 1B0EC94520CAB89A9CE1B2DA405166AF ] C:\Windows\System32\p2pcollab.dll
11:41:42.0379 0228  C:\Windows\System32\p2pcollab.dll - ok
11:41:42.0379 0228  [ 78DE417B7921DACA072059E6BF410FC7 ] C:\Windows\System32\wshnetbs.dll
11:41:42.0379 0228  C:\Windows\System32\wshnetbs.dll - ok
11:41:42.0395 0228  [ 45D9F6CD2469CDB6A640DD4BD2B01471 ] C:\Windows\System32\nci.dll
11:41:42.0395 0228  C:\Windows\System32\nci.dll - ok
11:41:42.0395 0228  [ 9E6AF823733C70E207D9FB6731A63B3D ] C:\Windows\System32\wlaninst.dll
11:41:42.0395 0228  C:\Windows\System32\wlaninst.dll - ok
11:41:42.0411 0228  [ 5B6EF0861BB5AC0EC347548E85C24A1D ] C:\Windows\System32\wwaninst.dll
11:41:42.0411 0228  C:\Windows\System32\wwaninst.dll - ok
11:41:42.0411 0228  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] C:\Windows\System32\QAGENTRT.DLL
11:41:42.0411 0228  C:\Windows\System32\QAGENTRT.DLL - ok
11:41:42.0426 0228  [ 9FD6496B6D91C8BE2A10BD55EAE2D5F2 ] C:\Windows\System32\fveui.dll
11:41:42.0426 0228  C:\Windows\System32\fveui.dll - ok
11:41:42.0426 0228  [ 6F8E3B7B70E1BBA871212940C1FBDF60 ] C:\Windows\System32\SensApi.dll
11:41:42.0426 0228  C:\Windows\System32\SensApi.dll - ok
11:41:42.0442 0228  [ 8D47D01378347889A662D54037A988CC ] C:\Windows\System32\tdh.dll
11:41:42.0442 0228  C:\Windows\System32\tdh.dll - ok
11:41:42.0442 0228  [ 3D6F22551D422F97AACB0BB927E4C846 ] C:\Windows\System32\pnidui.dll
11:41:42.0442 0228  C:\Windows\System32\pnidui.dll - ok
11:41:42.0457 0228  [ 1957D49A9613FAAD1C73B508CCE02AA5 ] C:\Windows\System32\wmp.dll
11:41:42.0457 0228  C:\Windows\System32\wmp.dll - ok
11:41:42.0457 0228  [ 4B9E4CE667DF26ADA061AA81E9AA841D ] C:\Windows\System32\spfileq.dll
11:41:42.0457 0228  C:\Windows\System32\spfileq.dll - ok
11:41:42.0473 0228  [ 0B7E85364CB878E2AD531DB7B601A9E5 ] C:\Windows\System32\NapiNSP.dll
11:41:42.0473 0228  C:\Windows\System32\NapiNSP.dll - ok
11:41:42.0473 0228  [ 5CF640EDDB1E40A5AB1BB743BCDEC610 ] C:\Windows\System32\pnrpnsp.dll
11:41:42.0473 0228  C:\Windows\System32\pnrpnsp.dll - ok
11:41:42.0489 0228  [ 5DF5D8CFD9B9573FA3B2C89D9061A240 ] C:\Windows\System32\winrnr.dll
11:41:42.0489 0228  C:\Windows\System32\winrnr.dll - ok
11:41:42.0489 0228  [ 72E953215CADE1A726C04AAFDF6B463D ] C:\Windows\System32\taskhost.exe
11:41:42.0489 0228  C:\Windows\System32\taskhost.exe - ok
11:41:42.0504 0228  [ C5C867CD7EFAC60D5021223E374DEEC5 ] C:\Windows\System32\dimsjob.dll
11:41:42.0504 0228  C:\Windows\System32\dimsjob.dll - ok
11:41:42.0504 0228  [ 14486EB6AF542F2BD3239F7FC3E713F7 ] C:\Windows\System32\pautoenr.dll
11:41:42.0504 0228  C:\Windows\System32\pautoenr.dll - ok
11:41:42.0520 0228  [ 61B1ED5F429EFAC7E2036769870AB93E ] C:\Windows\System32\certcli.dll
11:41:42.0520 0228  C:\Windows\System32\certcli.dll - ok
11:41:42.0520 0228  [ 29BC473072568C072EC8B176498DE996 ] C:\Windows\System32\CertEnroll.dll
11:41:42.0520 0228  C:\Windows\System32\CertEnroll.dll - ok
11:41:42.0535 0228  [ A63DC5C2EA944E6657203E0C8EDEAF61 ] C:\Windows\System32\dllhost.exe
11:41:42.0535 0228  C:\Windows\System32\dllhost.exe - ok
11:41:42.0535 0228  [ BDAC1AA64495D0F7E1FF810EBBF1F018 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
11:41:42.0535 0228  C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll - ok
11:41:42.0551 0228  [ 0B31464B7B2D616BD5F7036673588EC1 ] C:\Windows\System32\IDStore.dll
11:41:42.0551 0228  C:\Windows\System32\IDStore.dll - ok
11:41:42.0551 0228  [ B9A8CBCFCD3EC9D2EA4740AF347BF108 ] C:\Windows\System32\mpr.dll
11:41:42.0551 0228  C:\Windows\System32\mpr.dll - ok
11:41:42.0567 0228  [ 7319102526BD11B45FD66335CF90CA12 ] C:\Windows\System32\HotStartUserAgent.dll
11:41:42.0567 0228  C:\Windows\System32\HotStartUserAgent.dll - ok
11:41:42.0567 0228  [ 61AC3EFDFACFDD3F0F11DD4FD4044223 ] C:\Windows\System32\userinit.exe
11:41:42.0567 0228  C:\Windows\System32\userinit.exe - ok
11:41:42.0582 0228  [ 505BF4D1CADEB8D4F8BCD08D944DE25D ] C:\Windows\System32\dwm.exe
11:41:42.0582 0228  C:\Windows\System32\dwm.exe - ok
11:41:42.0582 0228  [ 497E59D9F01C6F247E72222A61835119 ] C:\Windows\System32\dwmcore.dll
11:41:42.0582 0228  C:\Windows\System32\dwmcore.dll - ok
11:41:42.0598 0228  [ 754AFC50022C95DA7C86B7020DB78136 ] C:\Windows\System32\dwmredir.dll
11:41:42.0598 0228  C:\Windows\System32\dwmredir.dll - ok
11:41:42.0598 0228  [ B43687C534A49700BF4B3C9898763752 ] C:\Windows\System32\MsCtfMonitor.dll
11:41:42.0598 0228  C:\Windows\System32\MsCtfMonitor.dll - ok
11:41:42.0613 0228  [ 56CEED370508F69A1BA04939BD1BADDA ] C:\Windows\System32\msutb.dll
11:41:42.0613 0228  C:\Windows\System32\msutb.dll - ok
11:41:42.0613 0228  [ 3C1936A12C62254F914A01BBC6A8DC69 ] C:\Windows\System32\d3d10_1.dll
11:41:42.0613 0228  C:\Windows\System32\d3d10_1.dll - ok
11:41:42.0629 0228  [ F58516E2DC0D963EF70D6BFC21FD82C4 ] C:\Windows\System32\PlaySndSrv.dll
11:41:42.0629 0228  C:\Windows\System32\PlaySndSrv.dll - ok
11:41:42.0629 0228  [ 74AF6AA2E8B3180AADAE5FE8813CB1CD ] C:\Windows\System32\localspl.dll
11:41:42.0629 0228  C:\Windows\System32\localspl.dll - ok
11:41:42.0645 0228  [ 7FFD52D73352806969D424EF327D10A7 ] C:\Windows\System32\radardt.dll
11:41:42.0645 0228  C:\Windows\System32\radardt.dll - ok
11:41:42.0660 0228  [ 49ACA548B2423F1C67898E6AC719A9A6 ] C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
11:41:42.0660 0228  C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll - ok
11:41:42.0660 0228  [ D4212AB475A3B25EC4DF574536C3EDC5 ] C:\Windows\System32\d3d10_1core.dll
11:41:42.0660 0228  C:\Windows\System32\d3d10_1core.dll - ok
11:41:42.0676 0228  [ 629181C26A78EB66B0B4E774E5AC2882 ] C:\Windows\System32\spoolss.dll
11:41:42.0676 0228  C:\Windows\System32\spoolss.dll - ok
11:41:42.0676 0228  [ 9E4B0E7472B4CEBA9E17F440B8CB0AB8 ] C:\Windows\System32\winspool.drv
11:41:42.0676 0228  C:\Windows\System32\winspool.drv - ok
11:41:42.0691 0228  [ D4F264FE23F8953D840904418220C15E ] C:\Windows\System32\dxgi.dll
11:41:42.0691 0228  C:\Windows\System32\dxgi.dll - ok
11:41:42.0691 0228  [ 126F8331BD023178C7F0EF2F5EDE16B3 ] C:\Windows\System32\FXSMON.dll
11:41:42.0691 0228  C:\Windows\System32\FXSMON.dll - ok
11:41:42.0707 0228  [ 03CF941D031F30272D3063E5A4D686F5 ] C:\Windows\System32\PrintIsolationProxy.dll
11:41:42.0707 0228  C:\Windows\System32\PrintIsolationProxy.dll - ok
11:41:42.0707 0228  [ 8B88EBBB05A0E56B7DCC708498C02B3E ] C:\Windows\explorer.exe
11:41:42.0707 0228  C:\Windows\explorer.exe - ok
11:41:42.0723 0228  [ 5C3F9DBA818CD93379D1A0F215270374 ] C:\Windows\System32\esent.dll
11:41:42.0723 0228  C:\Windows\System32\esent.dll - ok
11:41:42.0723 0228  [ B390C1D825C7687493BEDE237C6C2F25 ] C:\Windows\System32\tcpmon.dll
11:41:42.0723 0228  C:\Windows\System32\tcpmon.dll - ok
11:41:42.0738 0228  [ 1220595CABA75AB91A6B3FA3B89483CC ] C:\Windows\System32\snmpapi.dll
11:41:42.0738 0228  C:\Windows\System32\snmpapi.dll - ok
11:41:42.0738 0228  [ 923CDD30092DB73EC4A0EBCDDD16C686 ] C:\Windows\System32\usbmon.dll
11:41:42.0738 0228  C:\Windows\System32\usbmon.dll - ok
11:41:42.0754 0228  [ 6357E2B68753A1F5CF4A68A25C4FD14A ] C:\Windows\System32\wsnmp32.dll
11:41:42.0754 0228  C:\Windows\System32\wsnmp32.dll - ok
11:41:42.0754 0228  [ A8EB761DE499242BECF153B2B34F020E ] C:\Windows\System32\WSDMon.dll
11:41:42.0754 0228  C:\Windows\System32\WSDMon.dll - ok
11:41:42.0769 0228  [ 7ACDFB4CC67F4993DF0E0731576309B2 ] C:\Windows\System32\d3d11.dll
11:41:42.0769 0228  C:\Windows\System32\d3d11.dll - ok
11:41:42.0769 0228  [ F34CFADA6C48DAA41B996D24C7D8D3CA ] C:\Windows\System32\fdPnp.dll
11:41:42.0769 0228  C:\Windows\System32\fdPnp.dll - ok
11:41:42.0785 0228  [ CD72C6406BA561BED6D42CB145E55307 ] C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
11:41:42.0785 0228  C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll - ok
11:41:42.0785 0228  [ 52CCA2E9FFD0653CACED1E808AADE4B6 ] C:\Windows\System32\win32spl.dll
11:41:42.0785 0228  C:\Windows\System32\win32spl.dll - ok
11:41:42.0801 0228  [ D27DDE7E0444C7F1819F958469EB7D93 ] C:\Windows\System32\inetpp.dll
11:41:42.0801 0228  C:\Windows\System32\inetpp.dll - ok
11:41:42.0801 0228  [ 465BEA35F7ED4A4A57686DEA7EA10F47 ] C:\Windows\System32\cscapi.dll
11:41:42.0801 0228  C:\Windows\System32\cscapi.dll - ok
11:41:42.0816 0228  [ B0335E0E041106E15ACC6D36D6D75BF5 ] C:\Windows\System32\igd10umd32.dll
11:41:42.0816 0228  C:\Windows\System32\igd10umd32.dll - ok
11:41:42.0816 0228  [ E2A17BCC08D92F42E08AF6BA2F93ABA7 ] C:\Windows\System32\ExplorerFrame.dll
11:41:42.0816 0228  C:\Windows\System32\ExplorerFrame.dll - ok
11:41:42.0832 0228  [ 2100560AF3F7F2948F2676E44DFB4ECF ] C:\Windows\System32\uDWM.dll
11:41:42.0832 0228  C:\Windows\System32\uDWM.dll - ok
11:41:42.0832 0228  [ 846D0E4DB261CFAF363902E41498E961 ] C:\Windows\System32\EhStorShell.dll
11:41:42.0832 0228  C:\Windows\System32\EhStorShell.dll - ok
11:41:42.0847 0228  [ 03F3B770DFBED6131653CEDA8CA780F0 ] C:\Windows\System32\ntshrui.dll
11:41:42.0847 0228  C:\Windows\System32\ntshrui.dll - ok
11:41:42.0847 0228  [ 523CF74A52C9A1762DA8B83AEE734498 ] C:\Windows\System32\IconCodecService.dll
11:41:42.0847 0228  C:\Windows\System32\IconCodecService.dll - ok
11:41:42.0863 0228  [ EACFDF31921F51C097629F1F3C9129B4 ] C:\Windows\System32\appinfo.dll
11:41:42.0863 0228  C:\Windows\System32\appinfo.dll - ok
11:41:42.0863 0228  [ D44741F65A1D71F65814A12CF6E2400A ] C:\Windows\System32\runonce.exe
11:41:42.0863 0228  C:\Windows\System32\runonce.exe - ok
11:41:42.0879 0228  [ AD7B9C14083B52BC532FBA5948342B98 ] C:\Windows\System32\cmd.exe
11:41:42.0879 0228  C:\Windows\System32\cmd.exe - ok
11:41:42.0879 0228  [ 3FA214B377B8711D859F950FDFEFF739 ] C:\Windows\System32\conhost.exe
11:41:42.0879 0228  C:\Windows\System32\conhost.exe - ok
11:41:42.0894 0228  [ D5E5A86F49ACC11768D8339094C3AFD8 ] C:\Windows\System32\ieframe.dll
11:41:42.0894 0228  C:\Windows\System32\ieframe.dll - ok
11:41:42.0894 0228  [ 007863E45F25AA47A4C30D0930BBFD85 ] C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
11:41:42.0894 0228  C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll - ok
11:41:42.0910 0228  [ 60F4AEFA103D421EA4A40E31409B4756 ] C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
11:41:42.0910 0228  C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll - ok
11:41:42.0910 0228  [ 1F05F5A16881CD928C82D53CEFCF4477 ] C:\Windows\System32\shdocvw.dll
11:41:42.0910 0228  C:\Windows\System32\shdocvw.dll - ok
11:41:42.0925 0228  [ 5F69D5310C01C7488828F4FC5479BAE5 ] C:\Users\OFFICE\AppData\Local\Temp\9368D51D-D3CC-4C80-B7EB-558E4FDC1DCD.exe
11:41:42.0925 0228  C:\Users\OFFICE\AppData\Local\Temp\9368D51D-D3CC-4C80-B7EB-558E4FDC1DCD.exe - ok
11:41:42.0925 0228  [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] C:\Windows\System32\aelupsvc.dll
11:41:42.0925 0228  C:\Windows\System32\aelupsvc.dll - ok
11:41:42.0941 0228  [ 5992A9DF57FD5E6960FDCC2DB69867F7 ] C:\Windows\System32\themeui.dll
11:41:42.0941 0228  C:\Windows\System32\themeui.dll - ok
11:41:42.0941 0228  [ 7E9917D5309A90E7576653BFE39F80D8 ] C:\Windows\System32\timedate.cpl
11:41:42.0941 0228  C:\Windows\System32\timedate.cpl - ok
11:41:42.0957 0228  [ D2958325C1AE1AE37A83334C6229E3BC ] C:\Windows\System32\actxprxy.dll
11:41:42.0957 0228  C:\Windows\System32\actxprxy.dll - ok
11:41:42.0957 0228  [ 5987EA8A82C53359BCD2C29D6588583E ] C:\Windows\System32\linkinfo.dll
11:41:42.0957 0228  C:\Windows\System32\linkinfo.dll - ok
11:41:42.0972 0228  [ 64E211E0FDFCE4D186DF58BB7D0503BC ] C:\Windows\System32\gameux.dll
11:41:42.0972 0228  C:\Windows\System32\gameux.dll - ok
11:41:42.0972 0228  [ 3A16EA01FCFAAB40882DB5BFEE632322 ] C:\Windows\System32\msftedit.dll
11:41:42.0972 0228  C:\Windows\System32\msftedit.dll - ok
11:41:42.0988 0228  [ 175383778EB24D98C84E624021E3AA0B ] C:\Windows\System32\aeevts.dll
11:41:42.0988 0228  C:\Windows\System32\aeevts.dll - ok
11:41:42.0988 0228  [ 7896EFFDEE215C172BE724A64931EF1C ] C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
11:41:42.0988 0228  C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll - ok
11:41:43.0003 0228  [ C225E5307D8D4982A1687F2702C37C78 ] C:\Windows\System32\msls31.dll
11:41:43.0003 0228  C:\Windows\System32\msls31.dll - ok
11:41:43.0003 0228  [ 2A39F32E0067CBF221611FE1FA8C6D8F ] C:\Windows\System32\DeviceCenter.dll
11:41:43.0003 0228  C:\Windows\System32\DeviceCenter.dll - ok
11:41:43.0019 0228  [ 1029B84ECBE4B95ACB8491A3FE63D70F ] C:\Windows\System32\igfxtray.exe
11:41:43.0019 0228  C:\Windows\System32\igfxtray.exe - ok
11:41:43.0019 0228  [ 6B0450136DBCA36C6722C21A746D96CB ] C:\Windows\System32\hccutils.dll
11:41:43.0019 0228  C:\Windows\System32\hccutils.dll - ok
11:41:43.0035 0228  [ 3CD5BBDA19A1AB4EBA359E0A14FDF0F0 ] C:\Windows\System32\hkcmd.exe
11:41:43.0035 0228  C:\Windows\System32\hkcmd.exe - ok
11:41:43.0035 0228  [ DCCA4B04AF87E52EF9EAA2190E06CBAC ] C:\Program Files\Windows Sidebar\sidebar.exe
11:41:43.0035 0228  C:\Program Files\Windows Sidebar\sidebar.exe - ok
11:41:43.0050 0228  [ 3142195521FEE436088EE8A5748DE1B1 ] C:\Windows\System32\igfxpers.exe
11:41:43.0050 0228  C:\Windows\System32\igfxpers.exe - ok
11:41:43.0050 0228  [ 672D7C5080ACB003343006405DA2E621 ] C:\Windows\System32\thumbcache.dll
11:41:43.0050 0228  C:\Windows\System32\thumbcache.dll - ok
11:41:43.0066 0228  [ 3D57FFBAD3ED16B63DE3879BAB0FB56F ] C:\Windows\System32\networkexplorer.dll
11:41:43.0066 0228  C:\Windows\System32\networkexplorer.dll - ok
11:41:43.0081 0228  [ B9AA850CDA55097EB13E03698C8F5828 ] C:\Windows\System32\igfxsrvc.exe
11:41:43.0081 0228  C:\Windows\System32\igfxsrvc.exe - ok
11:41:43.0081 0228  [ 1CDEA9188899E76D4FFD54C9D512CCDB ] C:\Windows\System32\msxml3.dll
11:41:43.0081 0228  C:\Windows\System32\msxml3.dll - ok
11:41:43.0097 0228  [ 493164122DC72E1BF6D12F575604FBDA ] C:\Windows\System32\igfxsrvc.dll
11:41:43.0097 0228  C:\Windows\System32\igfxsrvc.dll - ok
11:41:43.0097 0228  [ FDC6BD427E353D205C1AFB6065FA8175 ] C:\Windows\System32\igfxdev.dll
11:41:43.0097 0228  C:\Windows\System32\igfxdev.dll - ok
11:41:43.0113 0228  [ 7A468BC721C1D34E60389D3F2F87BBEA ] C:\Windows\System32\mshtml.dll
11:41:43.0113 0228  C:\Windows\System32\mshtml.dll - ok
11:41:43.0113 0228  [ 1D1EAA16D193C6A2D45981ED3914D22A ] C:\Windows\System32\msimtf.dll
11:41:43.0113 0228  C:\Windows\System32\msimtf.dll - ok
11:41:43.0128 0228  [ C9A062F32FF600C96795B43CD9A53151 ] C:\Windows\System32\jscript9.dll
11:41:43.0128 0228  C:\Windows\System32\jscript9.dll - ok
11:41:43.0128 0228  [ D9A3009A2AB658DDE1D20358176CE546 ] C:\Windows\System32\GfxUI.exe
11:41:43.0128 0228  C:\Windows\System32\GfxUI.exe - ok
11:41:43.0144 0228  [ A6C29DB53ECA94FA8591C5388D604B82 ] C:\Windows\System32\msi.dll
11:41:43.0144 0228  C:\Windows\System32\msi.dll - ok
11:41:43.0144 0228  [ 9FF8F684BACF326082E5562F7C104A79 ] C:\Windows\System32\d2d1.dll
11:41:43.0144 0228  C:\Windows\System32\d2d1.dll - ok
11:41:43.0159 0228  [ D83947A58613E9091B4C9CC0F1546A8D ] C:\Windows\System32\mscoree.dll
11:41:43.0159 0228  C:\Windows\System32\mscoree.dll - ok
11:41:43.0159 0228  [ 4277F5164DE9B7C665BB928B9145BEE0 ] C:\Windows\System32\DWrite.dll
11:41:43.0159 0228  C:\Windows\System32\DWrite.dll - ok
11:41:43.0175 0228  [ 5BC881B4BEFCD1F005A7C1845AC63AD7 ] C:\Windows\System32\igfxrenu.lrc
11:41:43.0175 0228  C:\Windows\System32\igfxrenu.lrc - ok
11:41:43.0175 0228  [ F5DF6846F30E9F54EA60CCAEB3FB2055 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
11:41:43.0175 0228  C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll - ok
11:41:43.0191 0228  [ BA38C50F523DC053488AC3F9EF99AA0B ] C:\Windows\System32\igdumdx32.dll
11:41:43.0191 0228  C:\Windows\System32\igdumdx32.dll - ok
11:41:43.0191 0228  [ 102CF6879887BBE846A00C459E6D4ABC ] C:\Windows\System32\riched20.dll
11:41:43.0191 0228  C:\Windows\System32\riched20.dll - ok
11:41:43.0206 0228  [ B3170CCC779B682C3341873EA60CF084 ] C:\Windows\System32\d3d10warp.dll
11:41:43.0206 0228  C:\Windows\System32\d3d10warp.dll - ok
11:41:43.0206 0228  [ 8B92BED5B8D4A8480E7AA631F35A6F35 ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
11:41:43.0206 0228  C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - ok
11:41:43.0222 0228  [ 8B285BDAB7735FDFB18E6F7122923B77 ] C:\Windows\System32\UIAnimation.dll
11:41:43.0222 0228  C:\Windows\System32\UIAnimation.dll - ok
11:41:43.0222 0228  [ B39B8CC163C41B12FE83E777199F3378 ] C:\Windows\System32\tzres.dll
11:41:43.0222 0228  C:\Windows\System32\tzres.dll - ok
11:41:43.0237 0228  [ 5FF5E12F28725D14CAA3B408848ADFFC ] C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
11:41:43.0237 0228  C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll - ok
11:41:43.0237 0228  [ 198552AEFECA69D646867EC8D792DE95 ] C:\Windows\System32\ddraw.dll
11:41:43.0237 0228  C:\Windows\System32\ddraw.dll - ok
11:41:43.0253 0228  [ 55E5B32AE8D1F51A63C82919656FD275 ] C:\Windows\System32\dciman32.dll
11:41:43.0253 0228  C:\Windows\System32\dciman32.dll - ok
11:41:43.0253 0228  [ 10AB9C9ADB89816BEFB077E72659D029 ] C:\Windows\System32\igdumd32.dll
11:41:43.0253 0228  C:\Windows\System32\igdumd32.dll - ok
11:41:43.0269 0228  [ 523214677C1D31D7991632C6D11E6B42 ] C:\Windows\System32\d3dim700.dll
11:41:43.0269 0228  C:\Windows\System32\d3dim700.dll - ok
11:41:43.0269 0228  [ C3E39FB1398EEE8E612C2FE53A9192EF ] C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
11:41:43.0269 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll - ok
11:41:43.0284 0228  [ 3518CB4E2D896CAB53D5386F15AC0566 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
11:41:43.0284 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll - ok
11:41:43.0300 0228  [ 7F683A346C425ACD4F098BAA7C5792FC ] C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll
11:41:43.0300 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\716959df79685a1eae0fc14275a32b0f\WindowsBase.ni.dll - ok
11:41:43.0300 0228  [ B7A68C8F0EA038CB13E7B99AF9CDE513 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7eac0dbe9aa20b55e37235f8ee030e6b\PresentationCore.ni.dll
11:41:43.0300 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7eac0dbe9aa20b55e37235f8ee030e6b\PresentationCore.ni.dll - ok
11:41:43.0315 0228  [ 88DC26C8BC98DFF1B55985E25DF53262 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\af525b4bec3b9941b7be8ffbf813da80\PresentationFramework.ni.dll
11:41:43.0315 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\af525b4bec3b9941b7be8ffbf813da80\PresentationFramework.ni.dll - ok
11:41:43.0315 0228  [ AEDDFD540E3E6BECDB14C30D1F12B78A ] C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
11:41:43.0315 0228  C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll - ok
11:41:43.0331 0228  [ 912649A1B3F9E6ACB3899FBDABA2ED5F ] C:\Windows\System32\stobject.dll
11:41:43.0331 0228  C:\Windows\System32\stobject.dll - ok
11:41:43.0331 0228  [ 67C1B58706B47EEBA4E117AC197289E6 ] C:\Windows\System32\batmeter.dll
11:41:43.0331 0228  C:\Windows\System32\batmeter.dll - ok
11:41:43.0347 0228  [ C8333F1F77A1B2E25F2202E892CAF634 ] C:\Windows\System32\prnfldr.dll
11:41:43.0347 0228  C:\Windows\System32\prnfldr.dll - ok
11:41:43.0347 0228  [ DDFBFD8959F32AC0CF3947F36BAC3081 ] C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
11:41:43.0347 0228  C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll - ok
11:41:43.0362 0228  [ 09A116FB06C5E362EF8938D29CDAB27B ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
11:41:43.0362 0228  C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll - ok
11:41:43.0362 0228  [ ADDB05C93272A62606599B24730BD645 ] C:\Windows\System32\DXP.dll
11:41:43.0362 0228  C:\Windows\System32\DXP.dll - ok
11:41:43.0378 0228  [ A0617B5753E31126AD29C03154F4F329 ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll
11:41:43.0378 0228  C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll - ok
11:41:43.0378 0228  [ 856CFFCD835528136367BB1A8FE1DB87 ] C:\Windows\System32\Syncreg.dll
11:41:43.0378 0228  C:\Windows\System32\Syncreg.dll - ok
11:41:43.0393 0228  [ 754BD8D28C6E605A6383D96718083EAE ] C:\Windows\System32\gfxSrvc.dll
11:41:43.0393 0228  C:\Windows\System32\gfxSrvc.dll - ok
11:41:43.0393 0228  [ F8F03D206F7D5811D630349A23E9B9B9 ] C:\Windows\ehome\ehSSO.dll
11:41:43.0393 0228  C:\Windows\ehome\ehSSO.dll - ok
11:41:43.0409 0228  [ BF0E656D728C2F13616B4E1AFB7AE7CC ] C:\Windows\System32\IGFXDEVLib.dll
11:41:43.0409 0228  C:\Windows\System32\IGFXDEVLib.dll - ok
11:41:43.0409 0228  [ EAB975DB4C2805927FE5BD047D05C9AA ] C:\Windows\System32\netshell.dll
11:41:43.0409 0228  C:\Windows\System32\netshell.dll - ok
11:41:43.0425 0228  [ 6EF5F3F18413C367195F06E503AB86A6 ] C:\Windows\System32\d3d9.dll
11:41:43.0425 0228  C:\Windows\System32\d3d9.dll - ok
11:41:43.0425 0228  [ 77B1471A490B53B24EFE136F09F76550 ] C:\Windows\System32\d3d8thk.dll
11:41:43.0425 0228  C:\Windows\System32\d3d8thk.dll - ok
11:41:43.0440 0228  [ B2B3DAE040F6B5AE1DF52B0CD7631A18 ] C:\Windows\System32\AltTab.dll
11:41:43.0440 0228  C:\Windows\System32\AltTab.dll - ok
11:41:43.0440 0228  [ 871F7F32E3441580138E61A4AA072DF6 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
11:41:43.0440 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll - ok
11:41:43.0456 0228  [ 735263DA17BF5BAF9CCD483843BF9D5A ] C:\Windows\System32\WPDShServiceObj.dll
11:41:43.0456 0228  C:\Windows\System32\WPDShServiceObj.dll - ok
11:41:43.0471 0228  [ ADB45A977BD9E45790CA496DB84BA148 ] C:\Windows\System32\PortableDeviceTypes.dll
11:41:43.0471 0228  C:\Windows\System32\PortableDeviceTypes.dll - ok
11:41:43.0471 0228  [ BD626EF05967D14C772B8096292731A3 ] C:\Windows\System32\QUTIL.DLL
11:41:43.0471 0228  C:\Windows\System32\QUTIL.DLL - ok
11:41:43.0487 0228  [ 236F286E103FD44BD85FDD93097FD5DD ] C:\Windows\System32\SearchIndexer.exe
11:41:43.0487 0228  C:\Windows\System32\SearchIndexer.exe - ok
11:41:43.0487 0228  [ 674B0C0F6A448EB185CAAB9C51D44032 ] C:\Windows\System32\srchadmin.dll
11:41:43.0487 0228  C:\Windows\System32\srchadmin.dll - ok
11:41:43.0503 0228  [ 465DBF63A5049E4DB4BC5C12FFE781CB ] C:\Windows\System32\tquery.dll
11:41:43.0503 0228  C:\Windows\System32\tquery.dll - ok
11:41:43.0503 0228  [ C6458BF42FD8A9194EA4B2C81AA3B157 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll
11:41:43.0503 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\764f15e86c82662e977bd418bd6318c1\System.Configuration.ni.dll - ok
11:41:43.0518 0228  [ 0241CB16136B9A4939CA0395768AE286 ] C:\Windows\System32\mssrch.dll
11:41:43.0518 0228  C:\Windows\System32\mssrch.dll - ok
11:41:43.0518 0228  [ 62A6EB5771580CAE445804389F3F7432 ] C:\Windows\System32\WindowsCodecsExt.dll
11:41:43.0518 0228  C:\Windows\System32\WindowsCodecsExt.dll - ok
11:41:43.0534 0228  [ 816B681CC308FAA128EDCB90643DCED7 ] C:\Windows\System32\icm32.dll
11:41:43.0534 0228  C:\Windows\System32\icm32.dll - ok
11:41:43.0534 0228  [ 9A39A2A5F443A756C568C6ED5748AFE4 ] C:\Windows\System32\ActionCenter.dll
11:41:43.0534 0228  C:\Windows\System32\ActionCenter.dll - ok
11:41:43.0549 0228  [ CF4B9326EA3AF8D69EB743FB34AC8BF5 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\78967b28f748b8807eaa97c1cb454adc\WindowsFormsIntegration.ni.dll
11:41:43.0549 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\78967b28f748b8807eaa97c1cb454adc\WindowsFormsIntegration.ni.dll - ok
11:41:43.0549 0228  [ BE39E22059A3082D5289739299C33C01 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll
11:41:43.0549 0228  C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll - ok
11:41:43.0565 0228  [ 81600E2E27ED61427AAD865B9BCDDB9D ] C:\Windows\System32\msidle.dll
11:41:43.0565 0228  C:\Windows\System32\msidle.dll - ok
11:41:43.0565 0228  [ 7CCCFCA7510684768DA22092D1FA4DB2 ] C:\Windows\System32\netman.dll
11:41:43.0565 0228  C:\Windows\System32\netman.dll - ok
11:41:43.0581 0228  [ 1CBF15FDB0310345A68972EB5C5B948F ] C:\Windows\System32\mssprxy.dll
11:41:43.0581 0228  C:\Windows\System32\mssprxy.dll - ok
11:41:43.0581 0228  ============================================================
11:41:43.0581 0228  Scan finished
11:41:43.0581 0228  ============================================================
11:41:43.0596 0232  Detected object count: 0
11:41:43.0596 0232  Actual detected object count: 0
11:41:54.0969 1460  Deinitialize success

 

 

Hello 1of4...thanks for your help so far.d Here is the Tdss log. Scan came out clean. I included some gmer log and screen shots. The stuff in red is good or bad???
 

 

Attached Files



#8 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:05:49 PM

Posted 29 May 2013 - 06:00 AM

Hey nimble, :)

 

Well, your machine actually appears to be clean.  The red colored folders from the GMER scan are normal and necessary for Windows to function properly.  So far, all of the scan logs you've submitted have come back clean so I do not believe you are infected with malware.  At this point, how is your machine running?  Are you experiencing lock-ups?  Is your internet browser being redirected to sites other than what you are requesting?

 

Just as one final clean up and left-over check, let's run these two scans:

 

Please download and scan with SUPERAntiSpyware Free

  • Double-click SUPERAntiSypware.exe and use the default settings for installation.
  • An icon will be created on your desktop. Double-click that icon to launch the program.
  • If it will not start, go to Start > All Prgrams > SUPERAntiSpyware and click on Alternate Start.
  • If asked to update the program definitions, click "Yes". If not, update the definitions before scanning by selecting "Check for Updates". (If you encounter any problems while downloading the updates, manually download them from here. Double-click on the hyperlink for Download Installer and save SASDEFINITIONS.EXE to your desktop. Then double-click on SASDEFINITIONS.EXE to install the definitions.)
  • In the Main Menu, click the Preferences... button.
  • Click the "General and Startup" tab, and under Start-up Options, make sure "Start SUPERAntiSpyware when Windows starts" box is unchecked.
  • Click the "Scanning Control" tab, and under Scanner Options, make sure the following are checked (leave all other options as they are set):
    • Close browsers before scanning.
    • Scan for tracking cookies.
    • Terminate memory threats before quarantining.
  • Click the "Close" button to leave the Control Center screen.
  • Back on the main screen, under "Select Scan Type" check the box for Complete Scan.
  • If your computer is badly infected, be sure to check the box next to Enable Rescue Scan (Highly Infected Systems ONLY).
  • Click the Scan your computer... button.
  • After the scan is complete, a Scan Summary box will appear with potentially harmful items that were detected. Click "OK".
  • Make sure everything has a checkmark next to it and click "Next".
  • A notification will appear that "Quarantine and Removal is Complete". Click "OK" and then click the "Finish" button to return to the main menu.
  • If asked if you want to reboot, click "Yes" and reboot normally.

To retrieve the scan log after reboot, launch SUPERAntiSpyware again.

  • Click the View Scan Logs button at the bottom.
  • This will open the Scanner Logs Window.
  • Click on the log to highlight it and then click on View Selected Log to open it.
  • Copy and paste the scan log results in your next reply.

-- Some types of malware will disable security tools. If SUPERAntiSpyware will not install, please refer to these instructions for using the SUPERAntiSpyware Installer. If SUPERAntiSpyware is already installed but will not run, then follow the instructions for using RUNSAS.EXE to launch the program.

 

==========

 

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista/Windows 7 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here to run the scan.

    Quote

     

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: EOLS2.gif
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: EOLS3.gif
  • The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: EOLS4.gif
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

 

 

Post the logs from the two scans, along with a description of how your machine is running.

 


Best Regards,
oneof4.


#9 oneof4

oneof4

  • Malware Response Team
  • 3,779 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:The Collective
  • Local time:05:49 PM

Posted 04 June 2013 - 05:44 AM

Are you still with us?


Best Regards,
oneof4.


#10 Elise

Elise

    Bleepin' Blonde


  • Malware Study Hall Admin
  • 60,933 posts
  • ONLINE
  •  
  • Gender:Female
  • Location:Romania
  • Local time:12:49 AM

Posted 10 June 2013 - 11:24 AM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

regards, Elise


"Now faith is the substance of things hoped for, the evidence of things not seen."

 

Follow BleepingComputer on: Facebook | Twitter | Google+ | lockerdome

 

Malware analyst @ Emsisoft





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users