Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Flystudio + possible unknown rootkit variant - hidden process


  • This topic is locked This topic is locked
17 replies to this topic

#1 dralon

dralon

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:54 AM

Posted 16 June 2013 - 11:28 PM

Ok here is the situation. I got infected with flystudio plus a couple of generic worms on either a driveby exploit from a website or from Freemake Video Downloader, the only two things I've done lately. I ran Malwarebytes right away and it rebooted and removed them. After that removal process I started scanning with various rootkit detectors to make sure there wasn't something nastier dropped into my system. Nothing was found by a whole host of programs I tried, except for adwcleaner, JRT, aswMBR, combofix, and GMER. Ran sfc scannow in safe mode, because it wouldn't run in WinRE for some reason, and it healed a few files, or so it said. Logs revealed that it healed netbios.sys Anyways, aswMBR detected some hooks which wouldn't go away, and GMER listed even more, a bunch of IRP hooks on atapi.sys. Even after running all the other tools, GMER continued to detected a hidden process and a couple of devices as possible rootkit, namely wdf01000.sys and kbdclass, which combofix did not touch. Well I took care of the wdf01000 and kbdclass, I replaced them with original versions off of the install CD using DOS in WinRE. Now those don't show up anymore in the GMER scan, but the Trace IO hooks continued to show up and that hidden process. THere was no option to restore code, and no services or files to disable or delete. I could kill the process, and it did not impact my system negatively at all. At this point I came to find the bleeping computer forum, ran defogger, and most of the list of rootkit/drivers/trace IO's completely disappeared, except for about 10 registry lines most likely related to alcohol 120% and a bunch of .text lines that show up only when firefox is running. Those all relate to a file named xul.dll.

So, it's down to this hidden process and a bunch of .text reports in firefox, and the million dollar question is, is it a rootkit/malware?
As one of it's threads, it lists Gmer's driver, kgrcrpow.sys located in the appdata\local\temp folder.

And the second question is, could perhaps a rootkit be hiding in one of the cd emulation drivers and is just hiding until defogger re-enables them again?

All logs are attached to this thread, the hidden process and stuff attached to firefox is just bugging me, but I want to know if they are legit or not.

Attached File  logs.zip   16.01KB   3 downloads



BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:54 AM

Posted 21 June 2013 - 11:30 PM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> http://www.bleepingcomputer.com/logreply/498308 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new DDS log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download DDS by sUBs from the following link if you no longer have it available and save it to your destop.

    DDS.com Download Link
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explanation about the tool. No input is needed, the scan is running.
  • Notepad will open with the results.
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.

Information on A/V control can be found HERE.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 22 June 2013 - 11:49 AM

Hello dralon, and welcome to Bleeping Computer!
 
Sorry for the delay!
 
My name is bloopie and I'll be helping you with your problems as best I can! :thumbup2:

A few things to keep in mind while we are working together:
  • If you have since resolved the original problem you were having, I would appreciate it if you let me know.
  • If you are unsure about any of the steps just post what you can and I will guide you!
  • Please tell me if you have your original Windows CD/DVD available.
  • Please copy and paste all logs here unless otherwise instructed!
  • Upon completing the steps below I will review your topic an do my best to resolve your issues.
==========
 
Now after looking at those logs, I see lots of tools run, but you're missing an important one when rootkits are concerned:
  • Please download TDSSKiller from HERE and save it to your Desktop
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters


    tds2.jpg
  • Check Loaded Modules, Verify Driver Digital Signature, and Detect TDLFS file system
  • If you are asked to reboot because an "Extended Monitoring Driver is required" please click Reboot now


    2012081514h0118.png
  • Click Start Scan and allow the scan process to run


    tds4-1.jpg
  • If threats are detected select Skip or Cure (if available) for all of them unless otherwise instructed.
    ***Do NOT select Delete!
  • Click Continue


    tds6.jpg
  • Click Reboot computer
  • Please copy the TDSSKiller.[Version]_[Date]_[Time]_log.txt file found in your root directory (typically c:\) and paste it into your next reply
==========

If this doesn't help, then there are other avenues we can explore.

bloopie

#4 dralon

dralon
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:54 AM

Posted 23 June 2013 - 11:53 PM

Hi bloopie, thankyou for taking the time to help me.

 

The problem has not been resolved.
Original Windows DVD is available.

Further information on the process after much examination it appears to mirror the called threads of the regular system process. So it's a hidden process, with no name, that uses the same PID as the system process (4), and it uses all the threads of the system process. I am prepared to resign myself to living with it as it appears to be a harmless glitch but that's what I'm here for, to find out if it's really harmless or not.

I actually ran TDSSKiller as one of the first things I did, and I just failed to grab the logs for it. It only found unsigned files listed below as far as I can recall. And a systool driver that was actually a remnant of a FSB clock changing program I had installed briefly, which I used it to remove.

Here is the log:

21:42:17.0956 2592  TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:42:19.0414 2592  ============================================================
21:42:19.0414 2592  Current date / time: 2013/06/23 21:42:19.0414
21:42:19.0414 2592  SystemInfo:
21:42:19.0414 2592  
21:42:19.0414 2592  OS Version: 6.0.6000 ServicePack: 0.0
21:42:19.0414 2592  Product type: Workstation
21:42:19.0414 2592  ComputerName: RULER-PC
21:42:19.0420 2592  UserName: Ruler
21:42:19.0420 2592  Windows directory: C:\Windows
21:42:19.0420 2592  System windows directory: C:\Windows
21:42:19.0420 2592  Processor architecture: Intel x86
21:42:19.0420 2592  Number of processors: 2
21:42:19.0420 2592  Page size: 0x1000
21:42:19.0420 2592  Boot type: Normal boot
21:42:19.0420 2592  ============================================================
21:42:20.0863 2592  BG loaded
21:42:21.0191 2592  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
21:42:21.0207 2592  ============================================================
21:42:21.0207 2592  \Device\Harddisk0\DR0:
21:42:21.0207 2592  MBR partitions:
21:42:21.0207 2592  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xFDE8000
21:42:21.0207 2592  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xFDE8800, BlocksNum 0x2A59D000
21:42:21.0207 2592  ============================================================
21:42:21.0238 2592  C: <-> \Device\Harddisk0\DR0\Partition1
21:42:21.0285 2592  D: <-> \Device\Harddisk0\DR0\Partition2
21:42:21.0285 2592  ============================================================
21:42:21.0285 2592  Initialize success
21:42:21.0285 2592  ============================================================
21:42:26.0947 3136  ============================================================
21:42:26.0947 3136  Scan started
21:42:26.0947 3136  Mode: Manual; SigCheck; TDLFS;
21:42:26.0947 3136  ============================================================
21:42:28.0008 3136  ================ Scan system memory ========================
21:42:28.0008 3136  System memory - ok
21:42:28.0008 3136  ================ Scan services =============================
21:42:28.0164 3136  [ 84FC6DF81212D16BE5C4F441682FECCC ] ACPI            C:\Windows\system32\drivers\acpi.sys
21:42:28.0258 3136  ACPI - ok
21:42:28.0289 3136  [ 2EDC5BBAC6C651ECE337BDE8ED97C9FB ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
21:42:28.0320 3136  adp94xx - ok
21:42:28.0351 3136  [ B84088CA3CDCA97DA44A984C6CE1CCAD ] adpahci         C:\Windows\system32\drivers\adpahci.sys
21:42:28.0367 3136  adpahci - ok
21:42:28.0383 3136  [ 7880C67BCCC27C86FD05AA2AFB5EA469 ] adpu160m        C:\Windows\system32\drivers\adpu160m.sys
21:42:28.0398 3136  adpu160m - ok
21:42:28.0414 3136  [ 9AE713F8E30EFC2ABCCD84904333DF4D ] adpu320         C:\Windows\system32\drivers\adpu320.sys
21:42:28.0414 3136  adpu320 - ok
21:42:28.0461 3136  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
21:42:31.0471 3136  AeLookupSvc - ok
21:42:31.0534 3136  [ 5D24CAF8EFD924A875698FF28384DB8B ] AFD             C:\Windows\system32\drivers\afd.sys
21:42:31.0596 3136  AFD - ok
21:42:31.0690 3136  [ 5D97943C128ED756D1B0A08302C1B1F8 ] AgereSoftModem  C:\Windows\system32\DRIVERS\AGRSM.sys
21:42:31.0830 3136  AgereSoftModem - ok
21:42:31.0908 3136  [ EF23439CDD587F64C2C1B8825CEAD7D8 ] agp440          C:\Windows\system32\drivers\agp440.sys
21:42:31.0908 3136  agp440 - ok
21:42:31.0939 3136  [ AE1FDF7BF7BB6C6A70F67699D880592A ] aic78xx         C:\Windows\system32\drivers\djsvs.sys
21:42:31.0939 3136  aic78xx - ok
21:42:31.0971 3136  [ E69FB0E3112C40FDC0EF7D21A52DC951 ] ALG             C:\Windows\System32\alg.exe
21:42:32.0017 3136  ALG - ok
21:42:32.0033 3136  [ 90395B64600EBB4552E26E178C94B2E4 ] aliide          C:\Windows\system32\drivers\aliide.sys
21:42:32.0049 3136  aliide - ok
21:42:32.0095 3136  [ 2B13E304C9DFDFA5EB582F6A149FA2C7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
21:42:32.0095 3136  amdagp - ok
21:42:32.0111 3136  [ 0577DF1D323FE75A739C787893D300EA ] amdide          C:\Windows\system32\drivers\amdide.sys
21:42:32.0127 3136  amdide - ok
21:42:32.0127 3136  [ DC487885BCEF9F28EECE6FAC0E5DDFC5 ] AmdK7           C:\Windows\system32\drivers\amdk7.sys
21:42:32.0189 3136  AmdK7 - ok
21:42:32.0220 3136  [ 0CA0071DA4315B00FC1328CA86B425DA ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
21:42:32.0283 3136  AmdK8 - ok
21:42:32.0329 3136  [ 8D3A55F7B7BE6B374479E5195F477226 ] AnyDVD          C:\Windows\system32\Drivers\AnyDVD.sys
21:42:32.0361 3136  AnyDVD - ok
21:42:32.0392 3136  [ CFA455816879F06F1C4E5BBF9E8AEF7D ] Appinfo         C:\Windows\System32\appinfo.dll
21:42:32.0470 3136  Appinfo - ok
21:42:32.0501 3136  [ 5F673180268BB1FDB69C99B6619FE379 ] arc             C:\Windows\system32\drivers\arc.sys
21:42:32.0501 3136  arc - ok
21:42:32.0532 3136  [ 957F7540B5E7F602E44648C7DE5A1C05 ] arcsas          C:\Windows\system32\drivers\arcsas.sys
21:42:32.0532 3136  arcsas - ok
21:42:32.0641 3136  [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
21:42:32.0673 3136  aspnet_state - ok
21:42:32.0704 3136  [ E86CF7CE67D5DE898F27EF884DC357D8 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
21:42:32.0766 3136  AsyncMac - ok
21:42:32.0797 3136  [ 4F4FCB8B6EA06784FB6D475B7EC7300F ] atapi           C:\Windows\system32\drivers\atapi.sys
21:42:32.0797 3136  atapi - ok
21:42:32.0844 3136  [ E760FC1BD68F7F6F1B17EB4E8D9480B0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:42:32.0891 3136  AudioEndpointBuilder - ok
21:42:32.0907 3136  [ E760FC1BD68F7F6F1B17EB4E8D9480B0 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
21:42:32.0938 3136  Audiosrv - ok
21:42:33.0047 3136  [ 7692F4B242E45870873CAF4CB85CF769 ] AxAutoMntSrv    C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
21:42:33.0063 3136  AxAutoMntSrv - ok
21:42:33.0109 3136  [ AC3DD1708B22761EBD7CBE14DCC3B5D7 ] Beep            C:\Windows\system32\drivers\Beep.sys
21:42:33.0172 3136  Beep - ok
21:42:33.0234 3136  [ 98EBDFFB824A7C265337D68DD480E45C ] BFE             C:\Windows\System32\bfe.dll
21:42:33.0297 3136  BFE - ok
21:42:33.0343 3136  [ DA551697E34D2B9943C8B1C8EAFFE89A ] BITS            C:\Windows\System32\qmgr.dll
21:42:33.0406 3136  BITS - ok
21:42:33.0406 3136  blbdrive - ok
21:42:33.0468 3136  [ 913CD06FBE9105CE6077E90FD4418561 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
21:42:33.0531 3136  bowser - ok
21:42:33.0546 3136  [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo        C:\Windows\system32\drivers\brfiltlo.sys
21:42:33.0609 3136  BrFiltLo - ok
21:42:33.0624 3136  [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp        C:\Windows\system32\drivers\brfiltup.sys
21:42:33.0671 3136  BrFiltUp - ok
21:42:33.0718 3136  [ BEB6470532B7461D7BB426E3FACB424F ] Browser         C:\Windows\System32\browser.dll
21:42:33.0780 3136  Browser - ok
21:42:33.0811 3136  [ B304E75CFF293029EDDF094246747113 ] Brserid         C:\Windows\system32\drivers\brserid.sys
21:42:33.0874 3136  Brserid - ok
21:42:33.0889 3136  [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm        C:\Windows\system32\drivers\brserwdm.sys
21:42:33.0952 3136  BrSerWdm - ok
21:42:33.0967 3136  [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm        C:\Windows\system32\drivers\brusbmdm.sys
21:42:34.0030 3136  BrUsbMdm - ok
21:42:34.0045 3136  [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer        C:\Windows\system32\drivers\brusbser.sys
21:42:34.0108 3136  BrUsbSer - ok
21:42:34.0123 3136  [ AD07C1EC6665B8B35741AB91200C6B68 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
21:42:34.0186 3136  BTHMODEM - ok
21:42:34.0248 3136  catchme - ok
21:42:34.0279 3136  [ 6C3A437FC873C6F6A4FC620B6888CB86 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
21:42:34.0326 3136  cdfs - ok
21:42:34.0357 3136  [ 8D1866E61AF096AE8B582454F5E4D303 ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
21:42:34.0420 3136  cdrom - ok
21:42:34.0467 3136  [ 0600E04315FE543802A379D5D23C8BE0 ] CertPropSvc     C:\Windows\System32\certprop.dll
21:42:34.0513 3136  CertPropSvc - ok
21:42:34.0529 3136  [ DA8E0AFC7BAA226C538EF53AC2F90897 ] circlass        C:\Windows\system32\drivers\circlass.sys
21:42:34.0576 3136  circlass - ok
21:42:34.0638 3136  [ 1B84FD0937D3B99AF9BA38DDFF3DAF54 ] CLFS            C:\Windows\system32\CLFS.sys
21:42:34.0654 3136  CLFS - ok
21:42:34.0685 3136  [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:42:34.0701 3136  clr_optimization_v2.0.50727_32 - ok
21:42:34.0732 3136  [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:42:34.0794 3136  clr_optimization_v4.0.30319_32 - ok
21:42:34.0841 3136  [ ED97AD3DF1B9005989EAF149BF06C821 ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
21:42:34.0872 3136  CmBatt - ok
21:42:34.0903 3136  [ 45201046C776FFDAF3FC8A0029C581C8 ] cmdide          C:\Windows\system32\drivers\cmdide.sys
21:42:34.0903 3136  cmdide - ok
21:42:34.0919 3136  [ 722936AFB75A7F509662B69B5632F48A ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
21:42:34.0935 3136  Compbatt - ok
21:42:34.0935 3136  COMSysApp - ok
21:42:34.0950 3136  [ 2A213AE086BBEC5E937553C7D9A2B22C ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
21:42:34.0950 3136  crcdisk - ok
21:42:34.0966 3136  [ 22A7F883508176489F559EE745B5BF5D ] Crusoe          C:\Windows\system32\drivers\crusoe.sys
21:42:35.0013 3136  Crusoe - ok
21:42:35.0044 3136  [ 1C26FB097170A2A91066D1E3A24366E3 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
21:42:35.0106 3136  CryptSvc - ok
21:42:35.0137 3136  DarkSpy - ok
21:42:35.0184 3136  [ 7B981222A257D076885BFFB66F19B7CE ] DcomLaunch      C:\Windows\system32\rpcss.dll
21:42:35.0215 3136  DcomLaunch - ok
21:42:35.0231 3136  [ A7179DE59AE269AB70345527894CCD7C ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
21:42:35.0262 3136  DfsC - ok
21:42:35.0340 3136  [ E0D584AA76C7D845BA9F3A788260528F ] DFSR            C:\Windows\system32\DFSR.exe
21:42:35.0481 3136  DFSR - ok
21:42:35.0527 3136  [ DC45739BC22D528D2B3E50D3F6761750 ] Dhcp            C:\Windows\System32\dhcpcsvc.dll
21:42:35.0590 3136  Dhcp - ok
21:42:35.0621 3136  [ 841AF4C4D41D3E3B2F244E976B0F7963 ] disk            C:\Windows\system32\drivers\disk.sys
21:42:35.0621 3136  disk - ok
21:42:35.0652 3136  [ EECBA1DD142BF8693C476BE8F32FE253 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
21:42:35.0699 3136  Dnscache - ok
21:42:35.0730 3136  [ 1F795D214820E496BF1124434A6DB546 ] dot3svc         C:\Windows\System32\dot3svc.dll
21:42:35.0793 3136  dot3svc - ok
21:42:35.0824 3136  [ 032C90AD677BF7B7A8013D6087C7A921 ] DPS             C:\Windows\system32\dps.dll
21:42:35.0839 3136  DPS - ok
21:42:35.0902 3136  [ EE472CD2C01F6F8E8AA1FA06FFEF61B6 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
21:42:35.0964 3136  drmkaud - ok
21:42:35.0995 3136  [ 334988883DE69ADB27E2CF9F9715BBDB ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
21:42:36.0027 3136  DXGKrnl - ok
21:42:36.0073 3136  [ F88FB26547FD2CE6D0A5AF2985892C48 ] E1G60           C:\Windows\system32\DRIVERS\E1G60I32.sys
21:42:36.0136 3136  E1G60 - ok
21:42:36.0167 3136  EagleXNt - ok
21:42:36.0198 3136  [ 90A0A875642E18618010645311B4E89E ] EapHost         C:\Windows\System32\eapsvc.dll
21:42:36.0261 3136  EapHost - ok
21:42:36.0292 3136  [ 0EFC7531B936EE57FDB4E837664C509F ] Ecache          C:\Windows\system32\drivers\ecache.sys
21:42:36.0292 3136  Ecache - ok
21:42:36.0354 3136  [ B4580122B0A7B263B6EE9ACBA69C8013 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
21:42:36.0401 3136  ehRecvr - ok
21:42:36.0401 3136  [ AD1870C8E5D6DD340C829E6074BF3C3F ] ehSched         C:\Windows\ehome\ehsched.exe
21:42:36.0432 3136  ehSched - ok
21:42:36.0463 3136  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] ehstart         C:\Windows\ehome\ehstart.dll
21:42:36.0479 3136  ehstart - ok
21:42:36.0495 3136  [ D71233D7CCC2E64F8715A20428D5A33B ] ElbyCDIO        C:\Windows\system32\Drivers\ElbyCDIO.sys
21:42:36.0510 3136  ElbyCDIO - ok
21:42:36.0526 3136  [ E8F3F21A71720C84BCF423B80028359F ] elxstor         C:\Windows\system32\drivers\elxstor.sys
21:42:36.0557 3136  elxstor - ok
21:42:36.0573 3136  [ 3226FDA08988526E819E364E8CCE4CEE ] EMDMgmt         C:\Windows\system32\emdmgmt.dll
21:42:36.0619 3136  EMDMgmt - ok
21:42:36.0682 3136  [ 7B4971C3D43525175A4EA0D143E0412E ] EventSystem     C:\Windows\system32\es.dll
21:42:36.0729 3136  EventSystem - ok
21:42:36.0760 3136  [ 84A317CB0B3954D3768CDCD018DBF670 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
21:42:36.0822 3136  fastfat - ok
21:42:36.0869 3136  [ 63BDADA84951B9C03E641800E176898A ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
21:42:36.0916 3136  fdc - ok
21:42:36.0947 3136  [ E43BCE1A77D6FD4ED5F8E0482B9E7DF1 ] fdPHost         C:\Windows\system32\fdPHost.dll
21:42:36.0994 3136  fdPHost - ok
21:42:37.0009 3136  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] FDResPub        C:\Windows\system32\fdrespub.dll
21:42:37.0056 3136  FDResPub - ok
21:42:37.0087 3136  [ 65773D6115C037FFD7EF8280AE85EB9D ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
21:42:37.0087 3136  FileInfo - ok
21:42:37.0103 3136  [ C226DD0DE060745F3E042F58DCF78402 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
21:42:37.0165 3136  Filetrace - ok
21:42:37.0181 3136  [ 6603957EFF5EC62D25075EA8AC27DE68 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
21:42:37.0212 3136  flpydisk - ok
21:42:37.0243 3136  [ A6A8DA7AE4D53394AB22AC3AB6D3F5D3 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
21:42:37.0243 3136  FltMgr - ok
21:42:37.0306 3136  [ C9BE08664611DDAF98E2331E9288B00B ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
21:42:37.0321 3136  FontCache3.0.0.0 - ok
21:42:37.0399 3136  [ 46532E80E18BB25D3B568DA10A160653 ] FreemakeVideoCapture C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe
21:42:37.0415 3136  FreemakeVideoCapture ( UnsignedFile.Multi.Generic ) - warning
21:42:37.0415 3136  FreemakeVideoCapture - detected UnsignedFile.Multi.Generic (1)
21:42:37.0446 3136  [ 66A078591208BAA210C7634B11EB392C ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
21:42:37.0493 3136  Fs_Rec - ok
21:42:37.0524 3136  [ 4E1CD0A45C50A8882616CAE5BF82F3C5 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
21:42:37.0524 3136  gagp30kx - ok
21:42:37.0571 3136  [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio          C:\Windows\system32\giveio.sys
21:42:37.0587 3136  giveio ( UnsignedFile.Multi.Generic ) - warning
21:42:37.0587 3136  giveio - detected UnsignedFile.Multi.Generic (1)
21:42:37.0633 3136  [ BCF6589C42D8F6A20F33EF133FFE0524 ] gpsvc           C:\Windows\System32\gpsvc.dll
21:42:37.0711 3136  gpsvc - ok
21:42:37.0805 3136  [ F02A533F517EB38333CB12A9E8963773 ] gupdate         C:\Program Files\Google\Update\GoogleUpdate.exe
21:42:37.0805 3136  gupdate - ok
21:42:37.0821 3136  [ F02A533F517EB38333CB12A9E8963773 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
21:42:37.0836 3136  gupdatem - ok
21:42:37.0883 3136  [ CB04C744BE0A61B1D648FAED182C3B59 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
21:42:37.0945 3136  HdAudAddService - ok
21:42:37.0961 3136  [ 0DB613A7E427B5663563677796FD5258 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
21:42:37.0992 3136  HDAudBus - ok
21:42:38.0023 3136  [ 1338520E78D90154ED6BE8F84DE5FCEB ] HidBth          C:\Windows\system32\drivers\hidbth.sys
21:42:38.0070 3136  HidBth - ok
21:42:38.0086 3136  [ FF3160C3A2445128C5A6D9B076DA519E ] HidIr           C:\Windows\system32\drivers\hidir.sys
21:42:38.0133 3136  HidIr - ok
21:42:38.0148 3136  [ 8FA640195279ACE21BEA91396A0054FC ] hidserv         C:\Windows\System32\hidserv.dll
21:42:38.0195 3136  hidserv - ok
21:42:38.0211 3136  [ 3C64042B95E583B366BA4E5D2450235E ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
21:42:38.0257 3136  HidUsb - ok
21:42:38.0320 3136  [ D40AA05E29BF6ED29B139F044B461E9B ] hkmsvc          C:\Windows\system32\kmsvc.dll
21:42:38.0367 3136  hkmsvc - ok
21:42:38.0398 3136  [ DF353B401001246853763C4B7AAA6F50 ] HpCISSs         C:\Windows\system32\drivers\hpcisss.sys
21:42:38.0398 3136  HpCISSs - ok
21:42:38.0429 3136  [ EA24FE637D974A8A31BC650F478E3533 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
21:42:38.0460 3136  HTTP - ok
21:42:38.0507 3136  [ 324C2152FF2C61ABAE92D09F3CCA4D63 ] i2omp           C:\Windows\system32\drivers\i2omp.sys
21:42:38.0507 3136  i2omp - ok
21:42:38.0554 3136  [ 1C9EE072BAA3ABB460B91D7EE9152660 ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
21:42:38.0601 3136  i8042prt - ok
21:42:38.0632 3136  [ C957BF4B5D80B46C5017BF0101E6C906 ] iaStorV         C:\Windows\system32\drivers\iastorv.sys
21:42:38.0647 3136  iaStorV - ok
21:42:38.0710 3136  [ 7B630ACAED64FEF0C3E1CF255CB56686 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
21:42:38.0757 3136  idsvc - ok
21:42:38.0819 3136  [ 6FB1858D1F0923D122B0331865695041 ] igfx            C:\Windows\system32\DRIVERS\igdkmd32.sys
21:42:38.0928 3136  igfx - ok
21:42:38.0944 3136  [ 2D077BF86E843F901D8DB709C95B49A5 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
21:42:38.0959 3136  iirsp - ok
21:42:38.0991 3136  [ 35662FE4D8622F667AA5A5568F7F1B40 ] IKEEXT          C:\Windows\System32\ikeext.dll
21:42:39.0037 3136  IKEEXT - ok
21:42:39.0162 3136  [ B9CBD3DEA7CA02868621173BF7A2AF9F ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
21:42:39.0225 3136  IntcAzAudAddService - ok
21:42:39.0271 3136  [ 97469037714070E45194ED318D636401 ] intelide        C:\Windows\system32\drivers\intelide.sys
21:42:39.0271 3136  intelide - ok
21:42:39.0287 3136  [ CE44CC04262F28216DD4341E9E36A16F ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
21:42:39.0349 3136  intelppm - ok
21:42:39.0381 3136  [ 88CF5281ED9880D74DC9011CF8B5262D ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
21:42:39.0443 3136  IPBusEnum - ok
21:42:39.0459 3136  [ 880C6F86CC3F551B8FEA2C11141268C0 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:42:39.0521 3136  IpFilterDriver - ok
21:42:39.0552 3136  [ ECC9AD72CFC4AB41CF6A9BCC11F9FEF6 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
21:42:39.0583 3136  iphlpsvc - ok
21:42:39.0583 3136  IpInIp - ok
21:42:39.0630 3136  [ 40F34F8ABA2A015D780E4B09138B6C17 ] IPMIDRV         C:\Windows\system32\drivers\ipmidrv.sys
21:42:39.0693 3136  IPMIDRV - ok
21:42:39.0708 3136  [ 10077C35845101548037DF04FD1A420B ] IPNAT           C:\Windows\system32\DRIVERS\ipnat.sys
21:42:39.0771 3136  IPNAT - ok
21:42:39.0802 3136  [ A82F328F4792304184642D6D397BB1E3 ] IRENUM          C:\Windows\system32\drivers\irenum.sys
21:42:39.0849 3136  IRENUM - ok
21:42:39.0880 3136  [ 350FCA7E73CF65BCEF43FAE1E4E91293 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
21:42:39.0880 3136  isapnp - ok
21:42:39.0895 3136  [ 4DCA456D4D5723F8FA9C6760D240B0DF ] iScsiPrt        C:\Windows\system32\DRIVERS\msiscsi.sys
21:42:39.0911 3136  iScsiPrt - ok
21:42:39.0927 3136  [ BCED60D16156E428F8DF8CF27B0DF150 ] iteatapi        C:\Windows\system32\drivers\iteatapi.sys
21:42:39.0927 3136  iteatapi - ok
21:42:39.0942 3136  [ 06FA654504A498C30ADCA8BEC4E87E7E ] iteraid         C:\Windows\system32\drivers\iteraid.sys
21:42:39.0942 3136  iteraid - ok
21:42:39.0973 3136  [ 1A48765F92BA1A88445FC25C9C9D94FC ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
21:42:39.0989 3136  kbdclass - ok
21:42:39.0989 3136  [ ED61DBC6603F612B7338283EDBACBC4B ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
21:42:40.0020 3136  kbdhid - ok
21:42:40.0051 3136  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] KeyIso          C:\Windows\system32\lsass.exe
21:42:40.0098 3136  KeyIso - ok
21:42:40.0114 3136  [ 0A829977B078DEA11641FC2AF87CEADE ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
21:42:40.0145 3136  KSecDD - ok
21:42:40.0192 3136  [ 45C537FE5DDE9A0146AEFF76E615737D ] KtmRm           C:\Windows\system32\msdtckrm.dll
21:42:40.0254 3136  KtmRm - ok
21:42:40.0285 3136  [ 53D1482FC1AA36AC015A85E6CF2146BD ] LanmanServer    C:\Windows\System32\srvsvc.dll
21:42:40.0348 3136  LanmanServer - ok
21:42:40.0379 3136  [ 435F0F6DC87A4B5DA78F1FA309884189 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:42:40.0395 3136  LanmanWorkstation - ok
21:42:40.0426 3136  [ FD015B4F95DAA2B712F0E372A116FBAD ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
21:42:40.0488 3136  lltdio - ok
21:42:40.0519 3136  [ 7450DBCF754391DD6363FFFD5EF0E789 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
21:42:40.0582 3136  lltdsvc - ok
21:42:40.0597 3136  [ 35D40113E4A5B961B6CE5C5857702518 ] lmhosts         C:\Windows\System32\lmhsvc.dll
21:42:40.0629 3136  lmhosts - ok
21:42:40.0644 3136  [ A2262FB9F28935E862B4DB46438C80D2 ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
21:42:40.0660 3136  LSI_FC - ok
21:42:40.0675 3136  [ 30D73327D390F72A62F32C103DAF1D6D ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
21:42:40.0691 3136  LSI_SAS - ok
21:42:40.0722 3136  [ E1E36FEFD45849A95F1AB81DE0159FE3 ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
21:42:40.0722 3136  LSI_SCSI - ok
21:42:40.0738 3136  [ 42885BB44B6E065B8575A8DD6C430C52 ] luafv           C:\Windows\system32\drivers\luafv.sys
21:42:40.0800 3136  luafv - ok
21:42:40.0831 3136  [ E93C1AD58E88A0846EAEE10671C2A8F3 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
21:42:40.0847 3136  Mcx2Svc - ok
21:42:40.0863 3136  [ D153B14FC6598EAE8422A2037553ADCE ] megasas         C:\Windows\system32\drivers\megasas.sys
21:42:40.0878 3136  megasas - ok
21:42:40.0894 3136  [ 9DFA3A459AF0954AA85B4F7622AD87BB ] MMCSS           C:\Windows\system32\mmcss.dll
21:42:40.0956 3136  MMCSS - ok
21:42:40.0972 3136  [ 21755967298A46FB6ADFEC9DB6012211 ] Modem           C:\Windows\system32\drivers\modem.sys
21:42:41.0034 3136  Modem - ok
21:42:41.0065 3136  [ 7446E104A5FE5987CA9E4983FBAC4F97 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
21:42:41.0097 3136  monitor - ok
21:42:41.0128 3136  [ 5FBA13C1A1841B0885D316ED3589489D ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
21:42:41.0143 3136  mouclass - ok
21:42:41.0159 3136  [ B569B5C5D3BDE545DF3A6AF512CCCDBA ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
21:42:41.0159 3136  mouhid - ok
21:42:41.0175 3136  [ 01F1E5A3E4877C931CBB31613FEC16A6 ] MountMgr        C:\Windows\system32\drivers\mountmgr.sys
21:42:41.0175 3136  MountMgr - ok
21:42:41.0237 3136  [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
21:42:41.0253 3136  MozillaMaintenance - ok
21:42:41.0268 3136  [ 583A41F26278D9E0EA548163D6139397 ] mpio            C:\Windows\system32\drivers\mpio.sys
21:42:41.0284 3136  mpio - ok
21:42:41.0299 3136  [ 6E7A7F0C1193EE5648443FE2D4B789EC ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
21:42:41.0346 3136  mpsdrv - ok
21:42:41.0362 3136  [ 563ED845885C6A7C09A7715D8BD0585C ] MpsSvc          C:\Windows\system32\mpssvc.dll
21:42:41.0409 3136  MpsSvc - ok
21:42:41.0440 3136  [ 4FBBB70D30FD20EC51F80061703B001E ] Mraid35x        C:\Windows\system32\drivers\mraid35x.sys
21:42:41.0455 3136  Mraid35x - ok
21:42:41.0487 3136  [ 1D8828B98EE309D65E006F0829E280E5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
21:42:41.0518 3136  MRxDAV - ok
21:42:41.0549 3136  [ 8AF705CE1BB907932157FAB821170F27 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
21:42:41.0580 3136  mrxsmb - ok
21:42:41.0611 3136  [ 47E13AB23371BE3279EEF22BBFA2C1BE ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:42:41.0643 3136  mrxsmb10 - ok
21:42:41.0658 3136  [ 90B3FC7BD6B3D7EE7635DEBBA2187F66 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:42:41.0674 3136  mrxsmb20 - ok
21:42:41.0705 3136  [ B2EFB263600314BABCF9DADB1CBBA994 ] msahci          C:\Windows\system32\drivers\msahci.sys
21:42:41.0721 3136  msahci - ok
21:42:41.0736 3136  [ 3FC82A2AE4CC149165A94699183D3028 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
21:42:41.0752 3136  msdsm - ok
21:42:41.0767 3136  [ BC64A92D821EFEA8BAB8E8CAF1B668BC ] MSDTC           C:\Windows\System32\msdtc.exe
21:42:41.0799 3136  MSDTC - ok
21:42:41.0830 3136  [ 729EAFEFD4E7417165F353A18DBE947D ] Msfs            C:\Windows\system32\drivers\Msfs.sys
21:42:41.0892 3136  Msfs - ok
21:42:41.0923 3136  [ 5F454A16A5146CD91A176D70F0CFA3EC ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
21:42:41.0939 3136  msisadrv - ok
21:42:41.0970 3136  [ 8ACF956D9154E893E789881430C12632 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
21:42:42.0033 3136  MSiSCSI - ok
21:42:42.0048 3136  msiserver - ok
21:42:42.0064 3136  [ 892CEDEFA7E0FFE7BE8DA651B651D047 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
21:42:42.0111 3136  MSKSSRV - ok
21:42:42.0111 3136  [ AE2CB1DA69B2676B4CEE2A501AF5871C ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
21:42:42.0173 3136  MSPCLOCK - ok
21:42:42.0204 3136  [ F910DA84FA90C44A3ADDB7CD874463FD ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
21:42:42.0267 3136  MSPQM - ok
21:42:42.0282 3136  [ 84571C0AE07647BA38D493F5F0015DF7 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
21:42:42.0298 3136  MsRPC - ok
21:42:42.0313 3136  [ 4385C80EDE885E25492D408CAD91BD6F ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
21:42:42.0329 3136  mssmbios - ok
21:42:42.0329 3136  [ C826DD1373F38AFD9CA46EC3C436A14E ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
21:42:42.0391 3136  MSTEE - ok
21:42:42.0407 3136  [ FA7AA70050CF5E2D15DE00941E5665E5 ] Mup             C:\Windows\system32\Drivers\mup.sys
21:42:42.0407 3136  Mup - ok
21:42:42.0454 3136  [ 1CDBB5D002FE2BC5300AA20550D8A52E ] napagent        C:\Windows\system32\qagentRT.dll
21:42:42.0516 3136  napagent - ok
21:42:42.0563 3136  [ 6DA4A0FC7C0E83DF0CB3CFD0A514C3BC ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
21:42:42.0594 3136  NativeWifiP - ok
21:42:42.0641 3136  [ 227C11E1E7CF6EF8AFB2A238D209760C ] NDIS            C:\Windows\system32\drivers\ndis.sys
21:42:42.0657 3136  NDIS - ok
21:42:42.0688 3136  [ 81659CDCBD0F9A9E07E6878AD8C78D3F ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
21:42:42.0735 3136  NdisTapi - ok
21:42:42.0766 3136  [ 5DE5EE546BF40838EBE0E01CB629DF64 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
21:42:42.0828 3136  Ndisuio - ok
21:42:42.0844 3136  [ 397402ADCBB8946223A1950101F6CD94 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
21:42:42.0906 3136  NdisWan - ok
21:42:42.0937 3136  [ 1B24FA907AF283199A81B3BB37E5E526 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
21:42:42.0969 3136  NDProxy - ok
21:42:43.0000 3136  [ 356DBB9F98E8DC1028DD3092FCEEB877 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
21:42:43.0062 3136  NetBIOS - ok
21:42:43.0078 3136  [ E3A168912E7EEFC3BD3B814720D68B41 ] netbt           C:\Windows\system32\DRIVERS\netbt.sys
21:42:43.0125 3136  netbt - ok
21:42:43.0140 3136  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] Netlogon        C:\Windows\system32\lsass.exe
21:42:43.0156 3136  Netlogon - ok
21:42:43.0187 3136  [ 90A4DAE28B94497F83BEA0F2A3B77092 ] Netman          C:\Windows\System32\netman.dll
21:42:43.0249 3136  Netman - ok
21:42:43.0281 3136  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:42:43.0312 3136  NetMsmqActivator - ok
21:42:43.0312 3136  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:42:43.0327 3136  NetPipeActivator - ok
21:42:43.0343 3136  [ 7C5C3D9CEEE838856B828AB6F98A2857 ] netprofm        C:\Windows\System32\netprofm.dll
21:42:43.0405 3136  netprofm - ok
21:42:43.0405 3136  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:42:43.0421 3136  NetTcpActivator - ok
21:42:43.0421 3136  [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:42:43.0437 3136  NetTcpPortSharing - ok
21:42:43.0530 3136  [ 8DE67BD902095A13329FD82C85A1FA09 ] NETw5v32        C:\Windows\system32\DRIVERS\NETw5v32.sys
21:42:45.0262 3136  NETw5v32 - ok
21:42:45.0309 3136  [ 2E7FB731D4790A1BC6270ACCEFACB36E ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
21:42:45.0309 3136  nfrd960 - ok
21:42:45.0340 3136  [ C424117A562F2DE37A42266894C79AEB ] NlaSvc          C:\Windows\System32\nlasvc.dll
21:42:45.0402 3136  NlaSvc - ok
21:42:45.0433 3136  [ B48DC6ABCD3AEFF8618350CCBDC6B09A ] npf             C:\Windows\system32\drivers\npf.sys
21:42:45.0433 3136  npf - ok
21:42:45.0465 3136  [ 4F9832BEB9FAFD8CEB0E541F1323B26E ] Npfs            C:\Windows\system32\drivers\Npfs.sys
21:42:45.0527 3136  Npfs - ok
21:42:45.0543 3136  npggsvc - ok
21:42:45.0574 3136  [ 23B8201A363DE0E649FC75EE9874DEE2 ] nsi             C:\Windows\system32\nsisvc.dll
21:42:45.0621 3136  nsi - ok
21:42:45.0621 3136  [ B488DFEC274DE1FC9D653870EF2587BE ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
21:42:45.0667 3136  nsiproxy - ok
21:42:45.0699 3136  [ 3F379380A4A2637F559444E338CF1B51 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
21:42:45.0761 3136  Ntfs - ok
21:42:45.0792 3136  [ E875C093AEC0C978A90F30C9E0DFBB72 ] ntrigdigi       C:\Windows\system32\drivers\ntrigdigi.sys
21:42:45.0855 3136  ntrigdigi - ok
21:42:45.0870 3136  [ EC5EFB3C60F1B624648344A328BCE596 ] Null            C:\Windows\system32\drivers\Null.sys
21:42:45.0917 3136  Null - ok
21:42:45.0933 3136  [ E69E946F80C1C31C53003BFBF50CBB7C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
21:42:45.0933 3136  nvraid - ok
21:42:45.0948 3136  [ 9E0BA19A28C498A6D323D065DB76DFFC ] nvstor          C:\Windows\system32\drivers\nvstor.sys
21:42:45.0964 3136  nvstor - ok
21:42:45.0979 3136  [ 07C186427EB8FCC3D8D7927187F260F7 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
21:42:45.0995 3136  nv_agp - ok
21:42:45.0995 3136  NwlnkFlt - ok
21:42:45.0995 3136  NwlnkFwd - ok
21:42:46.0026 3136  [ BE32DA025A0BE1878F0EE8D6D9386CD5 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
21:42:46.0073 3136  ohci1394 - ok
21:42:46.0104 3136  [ 016D01D3B8FB976A193C7434BED8DCCF ] p2pimsvc        C:\Windows\system32\p2psvc.dll
21:42:46.0167 3136  p2pimsvc - ok
21:42:46.0182 3136  [ 016D01D3B8FB976A193C7434BED8DCCF ] p2psvc          C:\Windows\system32\p2psvc.dll
21:42:46.0213 3136  p2psvc - ok
21:42:46.0245 3136  [ 0FA9B5055484649D63C303FE404E5F4D ] Parport         C:\Windows\system32\drivers\parport.sys
21:42:46.0307 3136  Parport - ok
21:42:46.0338 3136  [ 555A5B2C8022983BC7467BC925B222EE ] partmgr         C:\Windows\system32\drivers\partmgr.sys
21:42:46.0338 3136  partmgr - ok
21:42:46.0354 3136  [ 4F9A6A8A31413180D0FCB279AD5D8112 ] Parvdm          C:\Windows\system32\drivers\parvdm.sys
21:42:46.0401 3136  Parvdm - ok
21:42:46.0432 3136  [ D8C5C215C932233A4F1D7F368F4E4E65 ] PcaSvc          C:\Windows\System32\pcasvc.dll
21:42:46.0463 3136  PcaSvc - ok
21:42:46.0479 3136  [ 1085D75657807E0E8B32F9E19A1647C3 ] pci             C:\Windows\system32\drivers\pci.sys
21:42:46.0494 3136  pci - ok
21:42:46.0510 3136  [ 3B1901E401473E03EB8C874271E50C26 ] pciide          C:\Windows\system32\drivers\pciide.sys
21:42:46.0510 3136  pciide - ok
21:42:46.0541 3136  [ E6F3FB1B86AA519E7698AD05E58B04E5 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
21:42:46.0541 3136  pcmcia - ok
21:42:46.0588 3136  [ 6349F6ED9C623B44B52EA3C63C831A92 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
21:42:46.0650 3136  PEAUTH - ok
21:42:46.0713 3136  [ CD05A38D166BEADE18030BAFC0C0A939 ] pla             C:\Windows\system32\pla.dll
21:42:46.0775 3136  pla - ok
21:42:46.0806 3136  [ 747BB4C31F3B6E8D1B5ED0AD61518CB5 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
21:42:46.0822 3136  PlugPlay - ok
21:42:46.0869 3136  [ 205E1B699FD3F2F9B036EEA2EC30C620 ] PnkBstrA        C:\Windows\system32\PnkBstrA.exe
21:42:46.0884 3136  PnkBstrA - ok
21:42:46.0900 3136  [ 016D01D3B8FB976A193C7434BED8DCCF ] PNRPAutoReg     C:\Windows\system32\p2psvc.dll
21:42:46.0931 3136  PNRPAutoReg - ok
21:42:46.0947 3136  [ 016D01D3B8FB976A193C7434BED8DCCF ] PNRPsvc         C:\Windows\system32\p2psvc.dll
21:42:46.0962 3136  PNRPsvc - ok
21:42:47.0009 3136  [ 5EBDEC613BD377CE9A85382BE5C6B83B ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
21:42:47.0040 3136  PolicyAgent - ok
21:42:47.0056 3136  [ 6C359AC71D7B550A0D41F9DB4563CE05 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
21:42:47.0118 3136  PptpMiniport - ok
21:42:47.0149 3136  [ 0E3CEF5D28B40CF273281D620C50700A ] Processor       C:\Windows\system32\drivers\processr.sys
21:42:47.0196 3136  Processor - ok
21:42:47.0227 3136  [ 213112E152E68F0E4705E36F052A2880 ] ProfSvc         C:\Windows\system32\profsvc.dll
21:42:47.0274 3136  ProfSvc - ok
21:42:47.0290 3136  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] ProtectedStorage C:\Windows\system32\lsass.exe
21:42:47.0290 3136  ProtectedStorage - ok
21:42:47.0321 3136  [ 2C8BAE55247C4E09352E870292E4D1AB ] PSched          C:\Windows\system32\DRIVERS\pacer.sys
21:42:47.0337 3136  PSched - ok
21:42:47.0368 3136  [ CCDAC889326317792480C0A67156A1EC ] ql2300          C:\Windows\system32\drivers\ql2300.sys
21:42:47.0461 3136  ql2300 - ok
21:42:47.0508 3136  [ 81A7E5C076E59995D54BC1ED3A16E60B ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
21:42:47.0524 3136  ql40xx - ok
21:42:47.0539 3136  [ CA61BDFD3713A7CE75F2812AFC431594 ] QWAVE           C:\Windows\system32\qwave.dll
21:42:47.0555 3136  QWAVE - ok
21:42:47.0571 3136  [ D2B3E2B7426DC23E185FBC73C8936C12 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
21:42:47.0586 3136  QWAVEdrv - ok
21:42:47.0617 3136  [ BD7B30F55B3649506DD8B3D38F571D2A ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
21:42:47.0664 3136  RasAcd - ok
21:42:47.0680 3136  [ F14F4AAB9F54D099FE99192BDB100AC9 ] RasAuto         C:\Windows\System32\rasauto.dll
21:42:47.0727 3136  RasAuto - ok
21:42:47.0758 3136  [ 88587DD843E2059848995B407B67F6CF ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
21:42:47.0805 3136  Rasl2tp - ok
21:42:47.0820 3136  [ 11D65E29BC9D1E4114D18FE68194394C ] RasMan          C:\Windows\System32\rasmans.dll
21:42:47.0883 3136  RasMan - ok
21:42:47.0883 3136  [ CCF4E9C6CBBAC81437F88CB2AE0B6C96 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
21:42:47.0929 3136  RasPppoe - ok
21:42:47.0945 3136  [ 54129C5D9581BBEC8BD1EBD3BA813F47 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
21:42:47.0992 3136  rdbss - ok
21:42:48.0023 3136  [ 794585276B5D7FCA9F3FC15543F9F0B9 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
21:42:48.0070 3136  RDPCDD - ok
21:42:48.0101 3136  [ E8BD98D46F2ED77132BA927FCCB47D8B ] rdpdr           C:\Windows\system32\drivers\rdpdr.sys
21:42:48.0163 3136  rdpdr - ok
21:42:48.0179 3136  [ 980B56E2E273E19D3A9D72D5C420F008 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
21:42:48.0226 3136  RDPENCDD - ok
21:42:48.0241 3136  [ 8830E790A74A96605FABA74F9665BB3C ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
21:42:48.0304 3136  RDPWD - ok
21:42:48.0351 3136  [ 6C1A43C589EE8011A1EBFD51C01B77CE ] RemoteAccess    C:\Windows\System32\mprdim.dll
21:42:48.0397 3136  RemoteAccess - ok
21:42:48.0429 3136  [ 9A043808667C8C1893DA7275AF373F0E ] RemoteRegistry  C:\Windows\system32\regsvc.dll
21:42:48.0491 3136  RemoteRegistry - ok
21:42:48.0522 3136  [ B9BB8E2093C1615AD6EA55AD96214354 ] Revoflt         C:\Windows\system32\DRIVERS\revoflt.sys
21:42:48.0538 3136  Revoflt - ok
21:42:48.0553 3136  rkhdrv40 - ok
21:42:48.0569 3136  [ 5123F83CBC4349D065534EEB6BBDC42B ] RpcLocator      C:\Windows\system32\locator.exe
21:42:48.0600 3136  RpcLocator - ok
21:42:48.0631 3136  [ 7B981222A257D076885BFFB66F19B7CE ] RpcSs           C:\Windows\system32\rpcss.dll
21:42:48.0663 3136  RpcSs - ok
21:42:48.0694 3136  [ 97E939D2128FEC5D5A3E6E79B290A2F4 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
21:42:48.0741 3136  rspndr - ok
21:42:48.0756 3136  [ 2D19A7469EA19993D0C12E627F4530BC ] RTL8169         C:\Windows\system32\DRIVERS\Rtlh86.sys
21:42:48.0772 3136  RTL8169 - ok
21:42:48.0787 3136  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] SamSs           C:\Windows\system32\lsass.exe
21:42:48.0803 3136  SamSs - ok
21:42:48.0819 3136  [ 3CE8F073A557E172B330109436984E30 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
21:42:48.0834 3136  sbp2port - ok
21:42:48.0850 3136  [ 565B4B9E5AD2F2F18A4F8AAFA6C06BBB ] SCardSvr        C:\Windows\System32\SCardSvr.dll
21:42:48.0912 3136  SCardSvr - ok
21:42:48.0943 3136  [ 886CEC884B5BE29AB9828B8AB46B11F7 ] Schedule        C:\Windows\system32\schedsvc.dll
21:42:48.0975 3136  Schedule - ok
21:42:49.0006 3136  [ 0600E04315FE543802A379D5D23C8BE0 ] SCPolicySvc     C:\Windows\System32\certprop.dll
21:42:49.0053 3136  SCPolicySvc - ok
21:42:49.0068 3136  [ F7B6BF02240D0A764ADF8C8966735552 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
21:42:49.0099 3136  SDRSVC - ok
21:42:49.0131 3136  [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
21:42:49.0177 3136  secdrv - ok
21:42:49.0193 3136  [ 8388C4133DDBE62AD7BC3EC9F14271ED ] seclogon        C:\Windows\system32\seclogon.dll
21:42:49.0240 3136  seclogon - ok
21:42:49.0255 3136  [ 34350AE2C1D33D21C7305F861BD8DAD8 ] SENS            C:\Windows\system32\sens.dll
21:42:49.0302 3136  SENS - ok
21:42:49.0318 3136  [ 68E44E331D46F0FB38F0863A84CD1A31 ] Serenum         C:\Windows\system32\drivers\serenum.sys
21:42:49.0380 3136  Serenum - ok
21:42:49.0411 3136  [ C70D69A918B178D3C3B06339B40C2E1B ] Serial          C:\Windows\system32\drivers\serial.sys
21:42:49.0458 3136  Serial - ok
21:42:49.0489 3136  [ 450ACCD77EC5CEA720C1CDB9E26B953B ] sermouse        C:\Windows\system32\drivers\sermouse.sys
21:42:49.0505 3136  sermouse - ok
21:42:49.0536 3136  [ 78878235DA4DF0D116E86837A0A21DF8 ] SessionEnv      C:\Windows\system32\sessenv.dll
21:42:49.0583 3136  SessionEnv - ok
21:42:49.0630 3136  [ 103B79418DA647736EE95645F305F68A ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
21:42:49.0661 3136  sffdisk - ok
21:42:49.0692 3136  [ 8FD08A310645FE872EEEC6E08C6BF3EE ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
21:42:49.0739 3136  sffp_mmc - ok
21:42:49.0755 3136  [ 9CFA05FCFCB7124E69CFC812B72F9614 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
21:42:49.0786 3136  sffp_sd - ok
21:42:49.0817 3136  [ 46ED8E91793B2E6F848015445A0AC188 ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
21:42:49.0879 3136  sfloppy - ok
21:42:49.0926 3136  [ 9A82BF4C90B00A63150A606A1E2FD82B ] SharedAccess    C:\Windows\System32\ipnathlp.dll
21:42:49.0942 3136  SharedAccess - ok
21:42:49.0989 3136  [ B264DFA21677728613267FE63802B332 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:42:50.0020 3136  ShellHWDetection - ok
21:42:50.0067 3136  [ D2A595D6EEBEEAF4334F8E50EFBC9931 ] sisagp          C:\Windows\system32\drivers\sisagp.sys
21:42:50.0067 3136  sisagp - ok
21:42:50.0082 3136  [ CEDD6F4E7D84E9F98B34B3FE988373AA ] SiSRaid2        C:\Windows\system32\drivers\sisraid2.sys
21:42:50.0098 3136  SiSRaid2 - ok
21:42:50.0113 3136  [ DF843C528C4F69D12CE41CE462E973A7 ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
21:42:50.0129 3136  SiSRaid4 - ok
21:42:50.0176 3136  [ 7C15061CD0372487903B07B9BB03AFAD ] SkypeUpdate     C:\Program Files\Skype\Updater\Updater.exe
21:42:50.0191 3136  SkypeUpdate - ok
21:42:50.0675 3136  [ 7610645679BB5994210D21A347E0C479 ] slsvc           C:\Windows\system32\SLsvc.exe
21:42:50.0753 3136  slsvc - ok
21:42:51.0003 3136  [ 49670F3E42A0178A0AB425AE15D88E7C ] SLUINotify      C:\Windows\system32\SLUINotify.dll
21:42:51.0065 3136  SLUINotify - ok
21:42:51.0299 3136  [ 46B40982AF166BF89C3F51FB13E60D6D ] SmartDefragDriver C:\Windows\system32\Drivers\SmartDefragDriver.sys
21:42:51.0299 3136  SmartDefragDriver - ok
21:42:51.0408 3136  [ AC0D90738ADB51A6FD12FF00874A2162 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
21:42:51.0471 3136  Smb - ok
21:42:51.0767 3136  [ 2A146A055B4401C16EE62D18B8E2A032 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
21:42:51.0767 3136  SNMPTRAP - ok
21:42:51.0985 3136  [ DC8D2952FB6FFBAEC67BD1B93A34DF11 ] speedfan        C:\Windows\system32\speedfan.sys
21:42:52.0001 3136  speedfan - ok
21:42:52.0032 3136  [ 426F9B029AA9162CECCF65369457D046 ] spldr           C:\Windows\system32\drivers\spldr.sys
21:42:52.0048 3136  spldr - ok
21:42:52.0063 3136  [ DA612EF2556776DF2630B68BF2D48935 ] Spooler         C:\Windows\System32\spoolsv.exe
21:42:52.0079 3136  Spooler - ok
21:42:52.0095 3136  sptd - ok
21:42:52.0141 3136  [ 038579C35F7CAD4A4BBF735DBF83277D ] srv             C:\Windows\system32\DRIVERS\srv.sys
21:42:52.0173 3136  srv - ok
21:42:52.0204 3136  [ 6971A757AF8CB5E2CBCBB76CC530DB6C ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
21:42:52.0235 3136  srv2 - ok
21:42:52.0251 3136  [ 9E1A4603B874EEBCE0298113951ABEFB ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
21:42:52.0266 3136  srvnet - ok
21:42:52.0313 3136  [ 8D3E4BAFF8B3997138C38EB1B600519A ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
21:42:52.0360 3136  SSDPSRV - ok
21:42:52.0375 3136  Steam Client Service - ok
21:42:52.0407 3136  [ A941E099EF46E3CC12F898CBE1C39910 ] stisvc          C:\Windows\System32\wiaservc.dll
21:42:52.0469 3136  stisvc - ok
21:42:52.0500 3136  [ 1379BDB336F8158C176A465E30759F57 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
21:42:52.0500 3136  swenum - ok
21:42:52.0531 3136  [ 749ADA8D6C18A08ADFEDE69CBF5DB2E0 ] swprv           C:\Windows\System32\swprv.dll
21:42:52.0594 3136  swprv - ok
21:42:52.0625 3136  [ 192AA3AC01DF071B541094F251DEED10 ] Symc8xx         C:\Windows\system32\drivers\symc8xx.sys
21:42:52.0625 3136  Symc8xx - ok
21:42:52.0641 3136  [ 8C8EB8C76736EBAF3B13B633B2E64125 ] Sym_hi          C:\Windows\system32\drivers\sym_hi.sys
21:42:52.0656 3136  Sym_hi - ok
21:42:52.0672 3136  [ 8072AF52B5FD103BBBA387A1E49F62CB ] Sym_u3          C:\Windows\system32\drivers\sym_u3.sys
21:42:52.0672 3136  Sym_u3 - ok
21:42:52.0703 3136  [ 70534D1E4F9AC990536D5FB5B550B3DE ] SynTP           C:\Windows\system32\DRIVERS\SynTP.sys
21:42:52.0703 3136  SynTP - ok
21:42:52.0750 3136  [ 8F2B5FEDE18BD3C4C926CBF88E6F1264 ] SysMain         C:\Windows\system32\sysmain.dll
21:42:52.0781 3136  SysMain - ok
21:42:52.0812 3136  [ 2DCA225EAE15F42C0933E998EE0231C3 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:42:52.0843 3136  TabletInputService - ok
21:42:52.0875 3136  [ EF3DD33C740FC2F82E7E4622F1C49289 ] TapiSrv         C:\Windows\System32\tapisrv.dll
21:42:52.0921 3136  TapiSrv - ok
21:42:52.0937 3136  [ 68FA52794AE9ACC61BDE16FE0956B414 ] TBS             C:\Windows\System32\tbssvc.dll
21:42:52.0999 3136  TBS - ok
21:42:53.0031 3136  [ 4A82FA8F0DF67AA354580C3FAAF8BDE3 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
21:42:53.0077 3136  Tcpip - ok
21:42:53.0109 3136  [ 4A82FA8F0DF67AA354580C3FAAF8BDE3 ] Tcpip6          C:\Windows\system32\DRIVERS\tcpip.sys
21:42:53.0140 3136  Tcpip6 - ok
21:42:53.0187 3136  [ 5CE0C4A7B12D0067DAD527D72B68C726 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
21:42:53.0233 3136  tcpipreg - ok
21:42:53.0249 3136  [ 964248AEF49C31FA6A93201A73FFAF50 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
21:42:53.0296 3136  TDPIPE - ok
21:42:53.0311 3136  [ 7D2C1AE1648A60FCE4AA0F7982E419D3 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
21:42:53.0358 3136  TDTCP - ok
21:42:53.0358 3136  [ AB4FDE8AF4A0270A46A001C08CBCE1C2 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
21:42:53.0405 3136  tdx - ok
21:42:53.0405 3136  [ 2C549BD9DD091FBFAA0A2A48E82EC2FB ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
21:42:53.0421 3136  TermDD - ok
21:42:53.0452 3136  [ FAD71C1E8E4047B154E899AE31EB8CAA ] TermService     C:\Windows\System32\termsrv.dll
21:42:53.0514 3136  TermService - ok
21:42:53.0545 3136  [ B264DFA21677728613267FE63802B332 ] Themes          C:\Windows\system32\shsvcs.dll
21:42:53.0561 3136  Themes - ok
21:42:53.0577 3136  [ 9DFA3A459AF0954AA85B4F7622AD87BB ] THREADORDER     C:\Windows\system32\mmcss.dll
21:42:53.0608 3136  THREADORDER - ok
21:42:53.0623 3136  [ 6BBA0582C0025D43729A1112D3B57897 ] TrkWks          C:\Windows\System32\trkwks.dll
21:42:53.0670 3136  TrkWks - ok
21:42:53.0701 3136  [ 34E388A395FEDBA1D0511ED39BBF4074 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:42:53.0717 3136  TrustedInstaller - ok
21:42:53.0733 3136  [ 29F0ECA726F0D51F7E048BDB0B372F29 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
21:42:53.0764 3136  tssecsrv - ok
21:42:53.0795 3136  [ 65E953BC0084D44498B51F59784D2A82 ] tunmp           C:\Windows\system32\DRIVERS\tunmp.sys
21:42:53.0811 3136  tunmp - ok
21:42:53.0842 3136  [ 4A39BDA5E0FD30BDF4884F9D33AE6105 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
21:42:53.0857 3136  tunnel - ok
21:42:53.0920 3136  [ 792A8B80F8188ABA4B2BE271583F3E46 ] TVALZ           C:\Windows\system32\DRIVERS\TVALZ_O.SYS
21:42:53.0920 3136  TVALZ - ok
21:42:53.0935 3136  [ C3ADE15414120033A36C0F293D4A4121 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
21:42:53.0951 3136  uagp35 - ok
21:42:53.0967 3136  [ 6348DA98707CEDA8A0DFB05820E17732 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
21:42:54.0013 3136  udfs - ok
21:42:54.0076 3136  [ 24A333F4F14DCFB6FF6D5A1B9E5D79DD ] UI0Detect       C:\Windows\system32\UI0Detect.exe
21:42:54.0107 3136  UI0Detect - ok
21:42:54.0123 3136  [ 75E6890EBFCE0841D3291B02E7A8BDB0 ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
21:42:54.0123 3136  uliagpkx - ok
21:42:54.0154 3136  [ 3CD4EA35A6221B85DCC25DAA46313F8D ] uliahci         C:\Windows\system32\drivers\uliahci.sys
21:42:54.0169 3136  uliahci - ok
21:42:54.0185 3136  [ 8514D0E5CD0534467C5FC61BE94A569F ] UlSata          C:\Windows\system32\drivers\ulsata.sys
21:42:54.0185 3136  UlSata - ok
21:42:54.0201 3136  [ 38C3C6E62B157A6BC46594FADA45C62B ] ulsata2         C:\Windows\system32\drivers\ulsata2.sys
21:42:54.0216 3136  ulsata2 - ok
21:42:54.0232 3136  [ 3FB78F1D1DD86D87BECECD9DFFA24DD9 ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
21:42:54.0294 3136  umbus - ok
21:42:54.0325 3136  [ 8EB871A3DEB6B3D5A85EB6DDFC390B59 ] upnphost        C:\Windows\System32\upnphost.dll
21:42:54.0372 3136  upnphost - ok
21:42:54.0403 3136  [ F6BF998AE33E3FB6C7D27F0560F1173F ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
21:42:54.0450 3136  usbaudio - ok
21:42:54.0466 3136  [ 8BD3AE150D97BA4E633C6C5C51B41AE1 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
21:42:54.0528 3136  usbccgp - ok
21:42:54.0559 3136  [ E9476E6C486E76BC4898074768FB7131 ] usbcir          C:\Windows\system32\drivers\usbcir.sys
21:42:54.0591 3136  usbcir - ok
21:42:54.0606 3136  [ 63FE924D8A1113C3BA6750693FBEC7D3 ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
21:42:54.0653 3136  usbehci - ok
21:42:54.0731 3136  [ 5EDEC5510592C905E91817707DCE62A2 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
21:42:54.0778 3136  usbhub - ok
21:42:54.0793 3136  [ 38DBC7DD6CC5A72011F187425384388B ] usbohci         C:\Windows\system32\drivers\usbohci.sys
21:42:54.0856 3136  usbohci - ok
21:42:54.0887 3136  [ B51E52ACF758BE00EF3A58EA452FE360 ] usbprint        C:\Windows\system32\drivers\usbprint.sys
21:42:54.0918 3136  usbprint - ok
21:42:54.0949 3136  [ 7887CE56934E7F104E98C975F47353C5 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:42:54.0996 3136  USBSTOR - ok
21:42:55.0027 3136  [ 325DBBACB8A36AF9988CCF40EAC228CC ] usbuhci         C:\Windows\system32\DRIVERS\usbuhci.sys
21:42:55.0074 3136  usbuhci - ok
21:42:55.0137 3136  [ 0A6B81F01BC86399482E27E6FDA7B33B ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
21:42:55.0183 3136  usbvideo - ok
21:42:55.0246 3136  [ F79D0D7C9004474CB42746D9B2C30A2B ] UxSms           C:\Windows\System32\uxsms.dll
21:42:55.0277 3136  UxSms - ok
21:42:55.0308 3136  [ C9D0BAFEE0D0A2681F048CA61BC0DA96 ] vds             C:\Windows\System32\vds.exe
21:42:55.0339 3136  vds - ok
21:42:55.0371 3136  [ 7D92BE0028ECDEDEC74617009084B5EF ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
21:42:55.0402 3136  vga - ok
21:42:55.0417 3136  [ 17A8F877314E4067F8C8172CC6D9101C ] VgaSave         C:\Windows\System32\drivers\vga.sys
21:42:55.0464 3136  VgaSave - ok
21:42:55.0480 3136  [ 045D9961E591CF0674A920B6BA3BA5CB ] viaagp          C:\Windows\system32\drivers\viaagp.sys
21:42:55.0495 3136  viaagp - ok
21:42:55.0527 3136  [ 56A4DE5F02F2E88182B0981119B4DD98 ] ViaC7           C:\Windows\system32\drivers\viac7.sys
21:42:55.0589 3136  ViaC7 - ok
21:42:55.0605 3136  [ FD2E3175FCADA350C7AB4521DCA187EC ] viaide          C:\Windows\system32\drivers\viaide.sys
21:42:55.0620 3136  viaide - ok
21:42:55.0636 3136  [ 103E84C95832D0ED93507997CC7B54E8 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
21:42:55.0651 3136  volmgr - ok
21:42:55.0651 3136  [ 294DA8D3F965F6A8DB934A83C7B461FF ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
21:42:55.0667 3136  volmgrx - ok
21:42:55.0698 3136  [ 80DC0C9BCB579ED9815001A4D37CBFD5 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
21:42:55.0714 3136  volsnap - ok
21:42:55.0729 3136  [ D984439746D42B30FC65A4C3546C6829 ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
21:42:55.0729 3136  vsmraid - ok
21:42:55.0776 3136  [ E0E29D9EF2524ABD11749C7C2FD7F607 ] VSS             C:\Windows\system32\vssvc.exe
21:42:55.0839 3136  VSS - ok
21:42:55.0870 3136  [ 62B0D0F6F5580D9D0DFA5E0B466FF2ED ] W32Time         C:\Windows\system32\w32time.dll
21:42:55.0917 3136  W32Time - ok
21:42:55.0963 3136  [ 48DFEE8F1AF7C8235D4E626F0C4FE031 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
21:42:55.0995 3136  WacomPen - ok
21:42:56.0041 3136  [ 6798C1209A53B5A0DED8D437C45145FF ] Wanarp          C:\Windows\system32\DRIVERS\wanarp.sys
21:42:56.0057 3136  Wanarp - ok
21:42:56.0057 3136  [ 6798C1209A53B5A0DED8D437C45145FF ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
21:42:56.0057 3136  Wanarpv6 - ok
21:42:56.0104 3136  [ C1B19162E0509CEAB4CDF664E139D956 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
21:42:56.0135 3136  wcncsvc - ok
21:42:56.0151 3136  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:42:56.0213 3136  WcsPlugInService - ok
21:42:56.0244 3136  [ AFC5AD65B991C1E205CF25CFDBF7A6F4 ] Wd              C:\Windows\system32\drivers\wd.sys
21:42:56.0260 3136  Wd - ok
21:42:56.0291 3136  [ 5DFDBD5EF13E4D95BE6FC108E2ED4A67 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
21:42:56.0322 3136  Wdf01000 - ok
21:42:56.0369 3136  [ 2A424B89B14EF17A3D06BCB5A8F79601 ] WdiServiceHost  C:\Windows\system32\wdi.dll
21:42:56.0385 3136  WdiServiceHost - ok
21:42:56.0400 3136  [ 2A424B89B14EF17A3D06BCB5A8F79601 ] WdiSystemHost   C:\Windows\system32\wdi.dll
21:42:56.0416 3136  WdiSystemHost - ok
21:42:56.0431 3136  [ 01E41C264EEDCB827820A1909162579F ] WebClient       C:\Windows\System32\webclnt.dll
21:42:56.0478 3136  WebClient - ok
21:42:56.0494 3136  [ 9CF67FF7F8D34CBF115D0C278B9F74AA ] Wecsvc          C:\Windows\system32\wecsvc.dll
21:42:56.0541 3136  Wecsvc - ok
21:42:56.0556 3136  [ B68CAB45DB1DAB59D92ACADFAD6364A8 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
21:42:56.0603 3136  wercplsupport - ok
21:42:56.0634 3136  [ 36BA0707680EF4236FD752BEE982CC25 ] WerSvc          C:\Windows\System32\WerSvc.dll
21:42:56.0681 3136  WerSvc - ok
21:42:56.0759 3136  [ 0D5AD0E71FF5DDAC5DD2F443B499ABD0 ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
21:42:56.0759 3136  WinDefend - ok
21:42:56.0775 3136  WinHttpAutoProxySvc - ok
21:42:56.0853 3136  [ 38A7B89DE4E3417C122317949667FDD8 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
21:42:56.0899 3136  Winmgmt - ok
21:42:56.0977 3136  [ 3F6823040030C3E4DA1CF11CD40B7534 ] WinRM           C:\Windows\system32\WsmSvc.dll
21:42:57.0087 3136  WinRM - ok
21:42:57.0165 3136  [ 7640ACEA41348BFEF34B76E245501261 ] Wlansvc         C:\Windows\System32\wlansvc.dll
21:42:57.0227 3136  Wlansvc - ok
21:42:57.0243 3136  [ 701A9F884A294327E9141D73746EE279 ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
21:42:57.0289 3136  WmiAcpi - ok
21:42:57.0336 3136  [ A279323BEE5FFFAFDA222910BCE92132 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
21:42:57.0352 3136  wmiApSrv - ok
21:42:57.0477 3136  [ ACB2E63D50157E3EA7140F29D9E76A48 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
21:42:57.0508 3136  WMPNetworkSvc - ok
21:42:57.0539 3136  [ 3D3B3B80C12ABE506F56930C46422C28 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
21:42:57.0586 3136  WPCSvc - ok
21:42:57.0601 3136  [ C24844A1D0D9528B19D5BC266B8CD572 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
21:42:57.0648 3136  WPDBusEnum - ok
21:42:57.0726 3136  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:42:57.0742 3136  WPFFontCache_v0400 - ok
21:42:57.0804 3136  [ 84620AECDCFD2A7A14E6263927D8C0ED ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
21:42:57.0851 3136  ws2ifsl - ok
21:42:57.0882 3136  [ F97CBB919AF6D0A6643D1A59C15014D1 ] wscsvc          C:\Windows\system32\wscsvc.dll
21:42:57.0898 3136  wscsvc - ok
21:42:57.0898 3136  WSearch - ok
21:42:58.0007 3136  [ 6298277B73C77FA99106B271A7525163 ] wuauserv        C:\Windows\system32\wuaueng.dll
21:42:58.0085 3136  wuauserv - ok
21:42:58.0132 3136  [ A2AAFCC8A204736296D937C7C545B53F ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
21:42:58.0194 3136  WUDFRd - ok
21:42:58.0225 3136  [ DB5BF5AAB72B1B99B5331231D09EBB26 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
21:42:58.0257 3136  wudfsvc - ok
21:42:58.0288 3136  ================ Scan global ===============================
21:42:58.0319 3136  [ 8CD98A8EC9CADAF4E051CDCAC15C96C4 ] C:\Windows\system32\basesrv.dll
21:42:58.0366 3136  [ E3F137ADC0A9D7F3A2E4F557272FE6B3 ] C:\Windows\system32\winsrv.dll
21:42:58.0381 3136  [ E3F137ADC0A9D7F3A2E4F557272FE6B3 ] C:\Windows\system32\winsrv.dll
21:42:58.0413 3136  [ 329CF3C97CE4C19375C8ABCABAE258B0 ] C:\Windows\system32\services.exe
21:42:58.0413 3136  [Global] - ok
21:42:58.0413 3136  ================ Scan MBR ==================================
21:42:58.0444 3136  [ 239841E1AE8E4843C0676F3681A7D6BE ] \Device\Harddisk0\DR0
21:42:59.0832 3136  \Device\Harddisk0\DR0 - ok
21:42:59.0832 3136  ================ Scan VBR ==================================
21:42:59.0863 3136  [ 90776F95F68B64B19D0A2C722A85004A ] \Device\Harddisk0\DR0\Partition1
21:42:59.0879 3136  \Device\Harddisk0\DR0\Partition1 - ok
21:42:59.0895 3136  [ D68E06A8B9A802CB0494ECCFFC24D544 ] \Device\Harddisk0\DR0\Partition2
21:42:59.0910 3136  \Device\Harddisk0\DR0\Partition2 - ok
21:42:59.0910 3136  ================ Scan active images ========================
21:42:59.0910 3136  [ 3596CB9EA8A12E6E858107912973EBFB ] C:\Windows\System32\drivers\crashdmp.sys
21:42:59.0910 3136  C:\Windows\System32\drivers\crashdmp.sys - ok
21:42:59.0910 3136  [ 5D975CD05FC673794501E3CE37AEA6E0 ] C:\Windows\System32\drivers\Dumpata.sys
21:42:59.0910 3136  C:\Windows\System32\drivers\Dumpata.sys - ok
21:42:59.0926 3136  [ B2EFB263600314BABCF9DADB1CBBA994 ] C:\Windows\System32\drivers\msahci.sys
21:42:59.0926 3136  C:\Windows\System32\drivers\msahci.sys - ok
21:42:59.0926 3136  [ CE44CC04262F28216DD4341E9E36A16F ] C:\Windows\System32\drivers\intelppm.sys
21:42:59.0926 3136  C:\Windows\System32\drivers\intelppm.sys - ok
21:42:59.0926 3136  [ 65E953BC0084D44498B51F59784D2A82 ] C:\Windows\System32\drivers\TUNMP.SYS
21:42:59.0926 3136  C:\Windows\System32\drivers\TUNMP.SYS - ok
21:42:59.0941 3136  [ 4A39BDA5E0FD30BDF4884F9D33AE6105 ] C:\Windows\System32\drivers\tunnel.sys
21:42:59.0941 3136  C:\Windows\System32\drivers\tunnel.sys - ok
21:42:59.0941 3136  [ ED97AD3DF1B9005989EAF149BF06C821 ] C:\Windows\System32\drivers\CmBatt.sys
21:42:59.0941 3136  C:\Windows\System32\drivers\CmBatt.sys - ok
21:42:59.0957 3136  [ 6FB1858D1F0923D122B0331865695041 ] C:\Windows\System32\drivers\igdkmd32.sys
21:42:59.0957 3136  C:\Windows\System32\drivers\igdkmd32.sys - ok
21:42:59.0957 3136  [ 334988883DE69ADB27E2CF9F9715BBDB ] C:\Windows\System32\drivers\dxgkrnl.sys
21:42:59.0957 3136  C:\Windows\System32\drivers\dxgkrnl.sys - ok
21:42:59.0957 3136  [ 3A1F38A6FB749FC7A57A2826F6F8FB01 ] C:\Windows\System32\drivers\watchdog.sys
21:42:59.0957 3136  C:\Windows\System32\drivers\watchdog.sys - ok
21:42:59.0973 3136  [ 63FE924D8A1113C3BA6750693FBEC7D3 ] C:\Windows\System32\drivers\usbehci.sys
21:42:59.0973 3136  C:\Windows\System32\drivers\usbehci.sys - ok
21:42:59.0973 3136  [ 7F510748487D3D67C70FE5FB061FE55A ] C:\Windows\System32\drivers\usbport.sys
21:42:59.0973 3136  C:\Windows\System32\drivers\usbport.sys - ok
21:42:59.0988 3136  [ 325DBBACB8A36AF9988CCF40EAC228CC ] C:\Windows\System32\drivers\usbuhci.sys
21:42:59.0988 3136  C:\Windows\System32\drivers\usbuhci.sys - ok
21:42:59.0988 3136  [ 0DB613A7E427B5663563677796FD5258 ] C:\Windows\System32\drivers\hdaudbus.sys
21:42:59.0988 3136  C:\Windows\System32\drivers\hdaudbus.sys - ok
21:42:59.0988 3136  [ 2D19A7469EA19993D0C12E627F4530BC ] C:\Windows\System32\drivers\Rtlh86.sys
21:42:59.0988 3136  C:\Windows\System32\drivers\Rtlh86.sys - ok
21:43:00.0004 3136  [ 8DE67BD902095A13329FD82C85A1FA09 ] C:\Windows\System32\drivers\NETw5v32.sys
21:43:00.0004 3136  C:\Windows\System32\drivers\NETw5v32.sys - ok
21:43:00.0004 3136  [ 1C9EE072BAA3ABB460B91D7EE9152660 ] C:\Windows\System32\drivers\i8042prt.sys
21:43:00.0004 3136  C:\Windows\System32\drivers\i8042prt.sys - ok
21:43:00.0019 3136  [ 1A48765F92BA1A88445FC25C9C9D94FC ] C:\Windows\System32\drivers\kbdclass.sys
21:43:00.0019 3136  C:\Windows\System32\drivers\kbdclass.sys - ok
21:43:00.0019 3136  [ 8D3A55F7B7BE6B374479E5195F477226 ] C:\Windows\System32\drivers\AnyDVD.sys
21:43:00.0019 3136  C:\Windows\System32\drivers\AnyDVD.sys - ok
21:43:00.0019 3136  [ 70534D1E4F9AC990536D5FB5B550B3DE ] C:\Windows\System32\drivers\SynTP.sys
21:43:00.0019 3136  C:\Windows\System32\drivers\SynTP.sys - ok
21:43:00.0035 3136  [ E5350A6599D84F73DA3DC87183C40BD7 ] C:\Windows\System32\drivers\usbd.sys
21:43:00.0035 3136  C:\Windows\System32\drivers\usbd.sys - ok
21:43:00.0035 3136  [ 8D1866E61AF096AE8B582454F5E4D303 ] C:\Windows\System32\drivers\cdrom.sys
21:43:00.0035 3136  C:\Windows\System32\drivers\cdrom.sys - ok
21:43:00.0051 3136  [ 4DCA456D4D5723F8FA9C6760D240B0DF ] C:\Windows\System32\drivers\msiscsi.sys
21:43:00.0051 3136  C:\Windows\System32\drivers\msiscsi.sys - ok
21:43:00.0051 3136  [ 81659CDCBD0F9A9E07E6878AD8C78D3F ] C:\Windows\System32\drivers\ndistapi.sys
21:43:00.0051 3136  C:\Windows\System32\drivers\ndistapi.sys - ok
21:43:00.0051 3136  [ 88587DD843E2059848995B407B67F6CF ] C:\Windows\System32\drivers\rasl2tp.sys
21:43:00.0051 3136  C:\Windows\System32\drivers\rasl2tp.sys - ok
21:43:00.0066 3136  [ ED386E31D263448B2ED36D4839F2CA04 ] C:\Windows\System32\drivers\Storport.sys
21:43:00.0066 3136  C:\Windows\System32\drivers\Storport.sys - ok
21:43:00.0066 3136  [ BBE07D2766FB165BDF1F49107DABCE85 ] C:\Windows\System32\drivers\tdi.sys
21:43:00.0066 3136  C:\Windows\System32\drivers\tdi.sys - ok
21:43:00.0066 3136  [ 397402ADCBB8946223A1950101F6CD94 ] C:\Windows\System32\drivers\ndiswan.sys
21:43:00.0066 3136  C:\Windows\System32\drivers\ndiswan.sys - ok
21:43:00.0082 3136  [ CCF4E9C6CBBAC81437F88CB2AE0B6C96 ] C:\Windows\System32\drivers\raspppoe.sys
21:43:00.0082 3136  C:\Windows\System32\drivers\raspppoe.sys - ok
21:43:00.0082 3136  [ 6C359AC71D7B550A0D41F9DB4563CE05 ] C:\Windows\System32\drivers\raspptp.sys
21:43:00.0082 3136  C:\Windows\System32\drivers\raspptp.sys - ok
21:43:00.0097 3136  [ 48314CDD79CE94B8F36BD6243323A310 ] C:\Windows\System32\drivers\ks.sys
21:43:00.0097 3136  C:\Windows\System32\drivers\ks.sys - ok
21:43:00.0097 3136  [ 5FBA13C1A1841B0885D316ED3589489D ] C:\Windows\System32\drivers\mouclass.sys
21:43:00.0097 3136  C:\Windows\System32\drivers\mouclass.sys - ok
21:43:00.0113 3136  [ 2C549BD9DD091FBFAA0A2A48E82EC2FB ] C:\Windows\System32\drivers\termdd.sys
21:43:00.0113 3136  C:\Windows\System32\drivers\termdd.sys - ok
21:43:00.0113 3136  [ 4385C80EDE885E25492D408CAD91BD6F ] C:\Windows\System32\drivers\mssmbios.sys
21:43:00.0113 3136  C:\Windows\System32\drivers\mssmbios.sys - ok
21:43:00.0129 3136  [ 1379BDB336F8158C176A465E30759F57 ] C:\Windows\System32\drivers\swenum.sys
21:43:00.0129 3136  C:\Windows\System32\drivers\swenum.sys - ok
21:43:00.0144 3136  [ 3FB78F1D1DD86D87BECECD9DFFA24DD9 ] C:\Windows\System32\drivers\umbus.sys
21:43:00.0144 3136  C:\Windows\System32\drivers\umbus.sys - ok
21:43:00.0144 3136  [ 5EDEC5510592C905E91817707DCE62A2 ] C:\Windows\System32\drivers\usbhub.sys
21:43:00.0144 3136  C:\Windows\System32\drivers\usbhub.sys - ok
21:43:00.0160 3136  [ 1B24FA907AF283199A81B3BB37E5E526 ] C:\Windows\System32\drivers\ndproxy.sys
21:43:00.0160 3136  C:\Windows\System32\drivers\ndproxy.sys - ok
21:43:00.0160 3136  [ 1660613337E5EBE07B4DD78C1A55C5C0 ] C:\Windows\System32\drivers\drmk.sys
21:43:00.0160 3136  C:\Windows\System32\drivers\drmk.sys - ok
21:43:00.0175 3136  [ 9A23E21ECA1246950E440E158DE50750 ] C:\Windows\System32\drivers\portcls.sys
21:43:00.0175 3136  C:\Windows\System32\drivers\portcls.sys - ok
21:43:00.0175 3136  [ B9CBD3DEA7CA02868621173BF7A2AF9F ] C:\Windows\System32\drivers\RTKVHDA.sys
21:43:00.0175 3136  C:\Windows\System32\drivers\RTKVHDA.sys - ok
21:43:00.0191 3136  [ 5D97943C128ED756D1B0A08302C1B1F8 ] C:\Windows\System32\drivers\AGRSM.sys
21:43:00.0191 3136  C:\Windows\System32\drivers\AGRSM.sys - ok
21:43:00.0207 3136  [ 21755967298A46FB6ADFEC9DB6012211 ] C:\Windows\System32\drivers\modem.sys
21:43:00.0207 3136  C:\Windows\System32\drivers\modem.sys - ok
21:43:00.0207 3136  [ 66A078591208BAA210C7634B11EB392C ] C:\Windows\System32\drivers\fs_rec.sys
21:43:00.0207 3136  C:\Windows\System32\drivers\fs_rec.sys - ok
21:43:00.0222 3136  [ AC3DD1708B22761EBD7CBE14DCC3B5D7 ] C:\Windows\System32\drivers\beep.sys
21:43:00.0222 3136  C:\Windows\System32\drivers\beep.sys - ok
21:43:00.0222 3136  [ 451A4D76448CEE21407FB0A9A362C057 ] C:\Windows\System32\drivers\hidparse.sys
21:43:00.0222 3136  C:\Windows\System32\drivers\hidparse.sys - ok
21:43:00.0238 3136  [ ED61DBC6603F612B7338283EDBACBC4B ] C:\Windows\System32\drivers\kbdhid.sys
21:43:00.0238 3136  C:\Windows\System32\drivers\kbdhid.sys - ok
21:43:00.0253 3136  [ EC5EFB3C60F1B624648344A328BCE596 ] C:\Windows\System32\drivers\null.sys
21:43:00.0253 3136  C:\Windows\System32\drivers\null.sys - ok
21:43:00.0253 3136  [ 17A8F877314E4067F8C8172CC6D9101C ] C:\Windows\System32\drivers\vga.sys
21:43:00.0253 3136  C:\Windows\System32\drivers\vga.sys - ok
21:43:00.0269 3136  [ D1FA901E4878B7011FE8A8C2890E90C7 ] C:\Windows\System32\drivers\videoprt.sys
21:43:00.0269 3136  C:\Windows\System32\drivers\videoprt.sys - ok
21:43:00.0269 3136  [ 794585276B5D7FCA9F3FC15543F9F0B9 ] C:\Windows\System32\drivers\RDPCDD.sys
21:43:00.0269 3136  C:\Windows\System32\drivers\RDPCDD.sys - ok
21:43:00.0269 3136  [ 980B56E2E273E19D3A9D72D5C420F008 ] C:\Windows\System32\drivers\RDPENCDD.sys
21:43:00.0269 3136  C:\Windows\System32\drivers\RDPENCDD.sys - ok
21:43:00.0285 3136  [ 729EAFEFD4E7417165F353A18DBE947D ] C:\Windows\System32\drivers\msfs.sys
21:43:00.0285 3136  C:\Windows\System32\drivers\msfs.sys - ok
21:43:00.0285 3136  [ 4F9832BEB9FAFD8CEB0E541F1323B26E ] C:\Windows\System32\drivers\npfs.sys
21:43:00.0285 3136  C:\Windows\System32\drivers\npfs.sys - ok
21:43:00.0300 3136  [ BD7B30F55B3649506DD8B3D38F571D2A ] C:\Windows\System32\drivers\rasacd.sys
21:43:00.0300 3136  C:\Windows\System32\drivers\rasacd.sys - ok
21:43:00.0300 3136  [ E216CF8C8605E546981098484B78D08B ] C:\Windows\System32\drivers\FWPKCLNT.SYS
21:43:00.0300 3136  C:\Windows\System32\drivers\FWPKCLNT.SYS - ok
21:43:00.0300 3136  [ 4A82FA8F0DF67AA354580C3FAAF8BDE3 ] C:\Windows\System32\drivers\tcpip.sys
21:43:00.0300 3136  C:\Windows\System32\drivers\tcpip.sys - ok
21:43:00.0316 3136  [ AB4FDE8AF4A0270A46A001C08CBCE1C2 ] C:\Windows\System32\drivers\tdx.sys
21:43:00.0316 3136  C:\Windows\System32\drivers\tdx.sys - ok
21:43:00.0316 3136  [ 5D24CAF8EFD924A875698FF28384DB8B ] C:\Windows\System32\drivers\afd.sys
21:43:00.0316 3136  C:\Windows\System32\drivers\afd.sys - ok
21:43:00.0316 3136  [ E3A168912E7EEFC3BD3B814720D68B41 ] C:\Windows\System32\drivers\netbt.sys
21:43:00.0316 3136  C:\Windows\System32\drivers\netbt.sys - ok
21:43:00.0331 3136  [ AC0D90738ADB51A6FD12FF00874A2162 ] C:\Windows\System32\drivers\smb.sys
21:43:00.0331 3136  C:\Windows\System32\drivers\smb.sys - ok
21:43:00.0331 3136  [ 356DBB9F98E8DC1028DD3092FCEEB877 ] C:\Windows\System32\drivers\netbios.sys
21:43:00.0331 3136  C:\Windows\System32\drivers\netbios.sys - ok
21:43:00.0331 3136  [ 2C8BAE55247C4E09352E870292E4D1AB ] C:\Windows\System32\drivers\pacer.sys
21:43:00.0331 3136  C:\Windows\System32\drivers\pacer.sys - ok
21:43:00.0347 3136  [ 84620AECDCFD2A7A14E6263927D8C0ED ] C:\Windows\System32\drivers\ws2ifsl.sys
21:43:00.0347 3136  C:\Windows\System32\drivers\ws2ifsl.sys - ok
21:43:00.0347 3136  [ B488DFEC274DE1FC9D653870EF2587BE ] C:\Windows\System32\drivers\nsiproxy.sys
21:43:00.0347 3136  C:\Windows\System32\drivers\nsiproxy.sys - ok
21:43:00.0347 3136  [ 54129C5D9581BBEC8BD1EBD3BA813F47 ] C:\Windows\System32\drivers\rdbss.sys
21:43:00.0347 3136  C:\Windows\System32\drivers\rdbss.sys - ok
21:43:00.0363 3136  [ 6798C1209A53B5A0DED8D437C45145FF ] C:\Windows\System32\drivers\wanarp.sys
21:43:00.0363 3136  C:\Windows\System32\drivers\wanarp.sys - ok
21:43:00.0363 3136  [ A7179DE59AE269AB70345527894CCD7C ] C:\Windows\System32\drivers\dfsc.sys
21:43:00.0363 3136  C:\Windows\System32\drivers\dfsc.sys - ok
21:43:00.0378 3136  [ D71233D7CCC2E64F8715A20428D5A33B ] C:\Windows\System32\drivers\ElbyCDIO.sys
21:43:00.0378 3136  C:\Windows\System32\drivers\ElbyCDIO.sys - ok
21:43:00.0378 3136  [ 8BD3AE150D97BA4E633C6C5C51B41AE1 ] C:\Windows\System32\drivers\usbccgp.sys
21:43:00.0378 3136  C:\Windows\System32\drivers\usbccgp.sys - ok
21:43:00.0378 3136  [ 0A6B81F01BC86399482E27E6FDA7B33B ] C:\Windows\System32\drivers\usbvideo.sys
21:43:00.0378 3136  C:\Windows\System32\drivers\usbvideo.sys - ok
21:43:00.0394 3136  [ 04E4C2069D7254E3FBB90D5B519AB53C ] C:\Windows\System32\ntdll.dll
21:43:00.0394 3136  C:\Windows\System32\ntdll.dll - ok
21:43:00.0394 3136  [ CAA75757BB3695478C23CB0624342A61 ] C:\Windows\System32\smss.exe
21:43:00.0394 3136  C:\Windows\System32\smss.exe - ok
21:43:00.0394 3136  [ C08D1FE284C3330934E45D6E5F5B768B ] C:\Windows\System32\autochk.exe
21:43:00.0394 3136  C:\Windows\System32\autochk.exe - ok
21:43:00.0409 3136  [ 7887CE56934E7F104E98C975F47353C5 ] C:\Windows\System32\drivers\USBSTOR.SYS
21:43:00.0409 3136  C:\Windows\System32\drivers\USBSTOR.SYS - ok
21:43:00.0409 3136  [ 081655939FA6C09EEC56DA090F461ECC ] C:\Windows\System32\drivers\hidclass.sys
21:43:00.0409 3136  C:\Windows\System32\drivers\hidclass.sys - ok
21:43:00.0425 3136  [ 3C64042B95E583B366BA4E5D2450235E ] C:\Windows\System32\drivers\hidusb.sys
21:43:00.0425 3136  C:\Windows\System32\drivers\hidusb.sys - ok
21:43:00.0425 3136  [ B569B5C5D3BDE545DF3A6AF512CCCDBA ] C:\Windows\System32\drivers\mouhid.sys
21:43:00.0425 3136  C:\Windows\System32\drivers\mouhid.sys - ok
21:43:00.0425 3136  [ 7F3415D246E2AE6E8CFD6A561016A91F ] C:\Windows\System32\comdlg32.dll
21:43:00.0425 3136  C:\Windows\System32\comdlg32.dll - ok
21:43:00.0441 3136  [ 75287677BB8BC9A16C32CE8A72F485A0 ] C:\Windows\System32\msvcrt.dll
21:43:00.0441 3136  C:\Windows\System32\msvcrt.dll - ok
21:43:00.0441 3136  [ C7A318E74FEF945EBFF855C1513CD96C ] C:\Windows\System32\wininet.dll
21:43:00.0441 3136  C:\Windows\System32\wininet.dll - ok
21:43:00.0441 3136  [ 9F5D9DBBC7613712A8778385B6FB12CA ] C:\Windows\System32\rpcrt4.dll
21:43:00.0441 3136  C:\Windows\System32\rpcrt4.dll - ok
21:43:00.0456 3136  [ B82C7AC1D559F0FD088792171D64C7F3 ] C:\Windows\System32\kernel32.dll
21:43:00.0456 3136  C:\Windows\System32\kernel32.dll - ok
21:43:00.0456 3136  [ 3D7FE2E7923EEA92E68062BBA3377067 ] C:\Windows\System32\setupapi.dll
21:43:00.0456 3136  C:\Windows\System32\setupapi.dll - ok
21:43:00.0472 3136  [ EE12864398F1C3BF5BEE91F6AF9842E1 ] C:\Windows\System32\imm32.dll
21:43:00.0472 3136  C:\Windows\System32\imm32.dll - ok
21:43:00.0472 3136  [ F352E76E220EB21A0C29734B66048DDE ] C:\Windows\System32\msctf.dll
21:43:00.0472 3136  C:\Windows\System32\msctf.dll - ok
21:43:00.0472 3136  [ D99A071C1018BB3D4ABAAD4B62048AC2 ] C:\Windows\System32\ws2_32.dll
21:43:00.0472 3136  C:\Windows\System32\ws2_32.dll - ok
21:43:00.0472 3136  [ 6F29236AB5926100972924BD29D9D225 ] C:\Windows\System32\normaliz.dll
21:43:00.0472 3136  C:\Windows\System32\normaliz.dll - ok
21:43:00.0487 3136  [ CF1D75E7B4A7CC6D2A21FE64C9E50A12 ] C:\Windows\System32\shell32.dll
21:43:00.0487 3136  C:\Windows\System32\shell32.dll - ok
21:43:00.0487 3136  [ 7924BCCE665AC92FC04CD45A46FE3E3D ] C:\Windows\System32\oleaut32.dll
21:43:00.0487 3136  C:\Windows\System32\oleaut32.dll - ok
21:43:00.0487 3136  [ 71A0DC633D1D76744441EFD4B7FB230F ] C:\Windows\System32\gdi32.dll
21:43:00.0487 3136  C:\Windows\System32\gdi32.dll - ok
21:43:00.0503 3136  [ CCE6FB960F8985BF500CE9CB0B2EF4CF ] C:\Windows\System32\ole32.dll
21:43:00.0503 3136  C:\Windows\System32\ole32.dll - ok
21:43:00.0503 3136  [ 456FB859236C9074ACF6C3B6243D8B46 ] C:\Windows\System32\usp10.dll
21:43:00.0503 3136  C:\Windows\System32\usp10.dll - ok
21:43:00.0519 3136  [ 5D53724E96F6B907355E616FFE08EB83 ] C:\Windows\System32\imagehlp.dll
21:43:00.0519 3136  C:\Windows\System32\imagehlp.dll - ok
21:43:00.0519 3136  [ 63B4F59D7C89B1BF5277F1FFEFD491CD ] C:\Windows\System32\user32.dll
21:43:00.0519 3136  C:\Windows\System32\user32.dll - ok
21:43:00.0534 3136  [ 438AE83490959C0F5A6BE97DAFEA68D2 ] C:\Windows\System32\shlwapi.dll
21:43:00.0534 3136  C:\Windows\System32\shlwapi.dll - ok
21:43:00.0534 3136  [ 4306242128019B290E1FA7EB998952D7 ] C:\Windows\System32\Wldap32.dll
21:43:00.0534 3136  C:\Windows\System32\Wldap32.dll - ok
21:43:00.0550 3136  [ DF43158D5E043553CAC6BFE28F90E545 ] C:\Windows\System32\clbcatq.dll
21:43:00.0550 3136  C:\Windows\System32\clbcatq.dll - ok
21:43:00.0550 3136  [ 9178B1C1C55DAD01BD65A162A39AE6C3 ] C:\Windows\System32\advapi32.dll
21:43:00.0550 3136  C:\Windows\System32\advapi32.dll - ok
21:43:00.0550 3136  [ 42CFAF7900E04E7041D54152D7B707BC ] C:\Windows\System32\iertutil.dll
21:43:00.0550 3136  C:\Windows\System32\iertutil.dll - ok
21:43:00.0565 3136  [ 5CD3F8485A88CF0F035CFF5576D66029 ] C:\Windows\System32\nsi.dll
21:43:00.0565 3136  C:\Windows\System32\nsi.dll - ok
21:43:00.0565 3136  [ C504C720A5EE8CF112758FEE04D4625B ] C:\Windows\System32\urlmon.dll
21:43:00.0565 3136  C:\Windows\System32\urlmon.dll - ok
21:43:00.0565 3136  [ 7BE32E67440BB5B2205C5402A2FBDE25 ] C:\Windows\System32\lpk.dll
21:43:00.0565 3136  C:\Windows\System32\lpk.dll - ok
21:43:00.0581 3136  [ BB61FB941A382A197AC2989337BF6364 ] C:\Windows\System32\comctl32.dll
21:43:00.0581 3136  C:\Windows\System32\comctl32.dll - ok
21:43:00.0581 3136  [ 93A1732F7F997E36A5C3893539E2FF02 ] C:\Windows\System32\psapi.dll
21:43:00.0581 3136  C:\Windows\System32\psapi.dll - ok
21:43:00.0581 3136  [ A253AA14CA560A4B8BA6E9D1F78EF10E ] C:\Windows\System32\drivers\dxapi.sys
21:43:00.0581 3136  C:\Windows\System32\drivers\dxapi.sys - ok
21:43:00.0597 3136  [ 9352E049F234BFA756C840CD8BDF4FFE ] C:\Windows\System32\win32k.sys
21:43:00.0597 3136  C:\Windows\System32\win32k.sys - ok
21:43:00.0597 3136  [ 8CD98A8EC9CADAF4E051CDCAC15C96C4 ] C:\Windows\System32\basesrv.dll
21:43:00.0597 3136  C:\Windows\System32\basesrv.dll - ok
21:43:00.0597 3136  [ 2F8A776FF2087357DDEB9992E06EECAA ] C:\Windows\System32\csrsrv.dll
21:43:00.0597 3136  C:\Windows\System32\csrsrv.dll - ok
21:43:00.0612 3136  [ 117B7C8A8B026A5DCE5E3180ED05E823 ] C:\Windows\System32\csrss.exe
21:43:00.0612 3136  C:\Windows\System32\csrss.exe - ok
21:43:00.0612 3136  [ E3F137ADC0A9D7F3A2E4F557272FE6B3 ] C:\Windows\System32\winsrv.dll
21:43:00.0612 3136  C:\Windows\System32\winsrv.dll - ok
21:43:00.0628 3136  [ 7446E104A5FE5987CA9E4983FBAC4F97 ] C:\Windows\System32\drivers\monitor.sys
21:43:00.0628 3136  C:\Windows\System32\drivers\monitor.sys - ok
21:43:00.0628 3136  [ D77B3F6785289CEC0F32D5A7B5B1268E ] C:\Windows\System32\tsddd.dll
21:43:00.0628 3136  C:\Windows\System32\tsddd.dll - ok
21:43:00.0628 3136  [ 68410CF6FB13CED160EF0149EABFC35C ] C:\Windows\System32\secur32.dll
21:43:00.0628 3136  C:\Windows\System32\secur32.dll - ok
21:43:00.0643 3136  [ CD5F587157B0150FB6955D939BDAB825 ] C:\Windows\System32\userenv.dll
21:43:00.0643 3136  C:\Windows\System32\userenv.dll - ok
21:43:00.0643 3136  [ D4385B03E8CCCEE6F0EE249F827C1F3E ] C:\Windows\System32\wininit.exe
21:43:00.0643 3136  C:\Windows\System32\wininit.exe - ok
21:43:00.0643 3136  [ 12C8D6C564702B0776512932290A3F6B ] C:\Windows\System32\KBDUS.DLL
21:43:00.0643 3136  C:\Windows\System32\KBDUS.DLL - ok
21:43:00.0659 3136  [ 75EDBAACA7D5F2B3B165B8DAB3E1542E ] C:\Windows\System32\apphelp.dll
21:43:00.0659 3136  C:\Windows\System32\apphelp.dll - ok
21:43:00.0659 3136  [ 92283D9E33EC5F41ECC0B430B7459241 ] C:\Windows\System32\WlS0WndH.dll
21:43:00.0659 3136  C:\Windows\System32\WlS0WndH.dll - ok
21:43:00.0659 3136  [ 329CF3C97CE4C19375C8ABCABAE258B0 ] C:\Windows\System32\services.exe
21:43:00.0659 3136  C:\Windows\System32\services.exe - ok
21:43:00.0675 3136  [ C19BA7DAD3AB3AFE6322248047560122 ] C:\Windows\System32\sxs.dll
21:43:00.0675 3136  C:\Windows\System32\sxs.dll - ok
21:43:00.0675 3136  [ C731B1FE449D4E9CEA358C9D55B69BE9 ] C:\Windows\System32\lsass.exe
21:43:00.0675 3136  C:\Windows\System32\lsass.exe - ok
21:43:00.0690 3136  [ 67FEFD286869A5EC50257AC62DCBA2B7 ] C:\Windows\System32\lsasrv.dll
21:43:00.0690 3136  C:\Windows\System32\lsasrv.dll - ok
21:43:00.0690 3136  [ 77F52395637906269B91264FFE576B51 ] C:\Windows\System32\lsm.exe
21:43:00.0690 3136  C:\Windows\System32\lsm.exe - ok
21:43:00.0690 3136  [ D39DB142B8A0C56616136DD0A1028FC1 ] C:\Windows\System32\scesrv.dll
21:43:00.0690 3136  C:\Windows\System32\scesrv.dll - ok
21:43:00.0706 3136  [ F3AA50FABE35385A7A1613E75B95565D ] C:\Windows\System32\authz.dll
21:43:00.0706 3136  C:\Windows\System32\authz.dll - ok
21:43:00.0706 3136  [ E3AFCA30714898BAAE6F12B52627761C ] C:\Windows\System32\netapi32.dll
21:43:00.0706 3136  C:\Windows\System32\netapi32.dll - ok
21:43:00.0706 3136  [ 71F5A7104FDF16C0AC5283A6CE666553 ] C:\Windows\System32\sysntfy.dll
21:43:00.0706 3136  C:\Windows\System32\sysntfy.dll - ok
21:43:00.0721 3136  [ F0321DA5203F1E71917F3B7A13DC4912 ] C:\Windows\System32\wmsgapi.dll
21:43:00.0721 3136  C:\Windows\System32\wmsgapi.dll - ok
21:43:00.0721 3136  [ 1E4B805A21583C9BAEC3758AA6BCA1CD ] C:\Windows\System32\ncobjapi.dll
21:43:00.0721 3136  C:\Windows\System32\ncobjapi.dll - ok
21:43:00.0721 3136  [ 9D1FDA9E086BA64E3C93C9DE32461BCF ] C:\Windows\System32\aelupsvc.dll
21:43:00.0721 3136  C:\Windows\System32\aelupsvc.dll - ok
21:43:00.0737 3136  [ E69FB0E3112C40FDC0EF7D21A52DC951 ] C:\Windows\System32\alg.exe
21:43:00.0737 3136  C:\Windows\System32\alg.exe - ok
21:43:00.0737 3136  [ 22054E4E3CF6174CFCE6AB2776DA22A0 ] C:\Windows\System32\samsrv.dll
21:43:00.0737 3136  C:\Windows\System32\samsrv.dll - ok
21:43:00.0737 3136  [ CFA455816879F06F1C4E5BBF9E8AEF7D ] C:\Windows\System32\appinfo.dll
21:43:00.0737 3136  C:\Windows\System32\appinfo.dll - ok
21:43:00.0753 3136  [ 2079C0B313846B4564380DBEDAD00E5E ] C:\Windows\System32\cryptdll.dll
21:43:00.0753 3136  C:\Windows\System32\cryptdll.dll - ok
21:43:00.0753 3136  [ 1CF533790D3D883A7AB671040FB18A93 ] C:\Windows\System32\dnsapi.dll
21:43:00.0753 3136  C:\Windows\System32\dnsapi.dll - ok
21:43:00.0753 3136  [ 47D3305C6986EC21A25B023779881015 ] C:\Windows\System32\feclient.dll
21:43:00.0753 3136  C:\Windows\System32\feclient.dll - ok
21:43:00.0768 3136  [ 24D50EA947B40A8C816B9206FBBB8BEE ] C:\Windows\System32\msasn1.dll
21:43:00.0768 3136  C:\Windows\System32\msasn1.dll - ok
21:43:00.0768 3136  [ 83942D329D01B8AA9721FEF668E1E1A6 ] C:\Windows\System32\ntdsapi.dll
21:43:00.0768 3136  C:\Windows\System32\ntdsapi.dll - ok
21:43:00.0768 3136  [ 039E4E0488F4E1A985139A24D0359AC3 ] C:\Windows\System32\samlib.dll
21:43:00.0768 3136  C:\Windows\System32\samlib.dll - ok
21:43:00.0784 3136  [ E760FC1BD68F7F6F1B17EB4E8D9480B0 ] C:\Windows\System32\audiosrv.dll
21:43:00.0784 3136  C:\Windows\System32\audiosrv.dll - ok
21:43:00.0784 3136  [ 360191D2A50180C3E0673BAB7F5529E0 ] C:\Windows\System32\crypt32.dll
21:43:00.0784 3136  C:\Windows\System32\crypt32.dll - ok
21:43:00.0799 3136  [ 75AEB9BA69D36AFF80011B74F27912AF ] C:\Windows\System32\mpr.dll
21:43:00.0799 3136  C:\Windows\System32\mpr.dll - ok
21:43:00.0799 3136  [ 98EBDFFB824A7C265337D68DD480E45C ] C:\Windows\System32\BFE.DLL
21:43:00.0799 3136  C:\Windows\System32\BFE.DLL - ok
21:43:00.0815 3136  [ E8C6F8EC1064EE21704307B2CE72C3FB ] C:\Windows\System32\cdd.dll
21:43:00.0815 3136  C:\Windows\System32\cdd.dll - ok
21:43:00.0815 3136  [ C984BA7C8AAB74D1ED8A38A14B19D8C6 ] C:\Windows\System32\SLC.dll
21:43:00.0815 3136  C:\Windows\System32\SLC.dll - ok
21:43:00.0815 3136  [ BCE6F538105E7713C4A5A0CA683D6795 ] C:\Windows\System32\wevtapi.dll
21:43:00.0815 3136  C:\Windows\System32\wevtapi.dll - ok
21:43:00.0831 3136  [ DC45739BC22D528D2B3E50D3F6761750 ] C:\Windows\System32\dhcpcsvc.dll
21:43:00.0831 3136  C:\Windows\System32\dhcpcsvc.dll - ok
21:43:00.0831 3136  [ B1143BE81DD6AE13943B806261CE91A0 ] C:\Windows\System32\dhcpcsvc6.dll
21:43:00.0831 3136  C:\Windows\System32\dhcpcsvc6.dll - ok
21:43:00.0831 3136  [ 3B7336FC377803D3BDA3139DF1343B2D ] C:\Windows\System32\IPHLPAPI.DLL
21:43:00.0831 3136  C:\Windows\System32\IPHLPAPI.DLL - ok
21:43:00.0846 3136  [ DA551697E34D2B9943C8B1C8EAFFE89A ] C:\Windows\System32\qmgr.dll
21:43:00.0846 3136  C:\Windows\System32\qmgr.dll - ok
21:43:00.0846 3136  [ 86FBD7D3E975464E94F0A270E5E79CEC ] C:\Windows\System32\winnsi.dll
21:43:00.0846 3136  C:\Windows\System32\winnsi.dll - ok
21:43:00.0846 3136  [ BEB6470532B7461D7BB426E3FACB424F ] C:\Windows\System32\browser.dll
21:43:00.0846 3136  C:\Windows\System32\browser.dll - ok
21:43:00.0862 3136  [ 0600E04315FE543802A379D5D23C8BE0 ] C:\Windows\System32\certprop.dll
21:43:00.0862 3136  C:\Windows\System32\certprop.dll - ok
21:43:00.0862 3136  [ 7F15B4953378C8B5161D65C26D5FED4D ] C:\Windows\System32\cngaudit.dll
21:43:00.0862 3136  C:\Windows\System32\cngaudit.dll - ok
21:43:00.0862 3136  [ 4843A1784BA6434DFF80F841DDC592C6 ] C:\Windows\System32\comres.dll
21:43:00.0862 3136  C:\Windows\System32\comres.dll - ok
21:43:00.0877 3136  [ 121AFD967914292D5CBF7BEE9572BE71 ] C:\Windows\System32\ncrypt.dll
21:43:00.0877 3136  C:\Windows\System32\ncrypt.dll - ok
21:43:00.0877 3136  [ 1C90E67A15D7B35909AF8A808A1ECCFF ] C:\Windows\System32\bcrypt.dll
21:43:00.0877 3136  C:\Windows\System32\bcrypt.dll - ok
21:43:00.0877 3136  [ 8C312DE50B90F7C22349E6DB1D9538E3 ] C:\Windows\System32\credssp.dll
21:43:00.0877 3136  C:\Windows\System32\credssp.dll - ok
21:43:00.0893 3136  [ F4AFBEB2BD4972F57C53CB8D54561C4E ] C:\Windows\System32\kerberos.dll
21:43:00.0893 3136  C:\Windows\System32\kerberos.dll - ok
21:43:00.0893 3136  [ ABE9EEA1EABEA0711610A637A7B1C25D ] C:\Windows\System32\msprivs.dll
21:43:00.0893 3136  C:\Windows\System32\msprivs.dll - ok
21:43:00.0893 3136  [ 9F6487E56876511E764DD097AB0CE9A0 ] C:\Windows\System32\wship6.dll
21:43:00.0893 3136  C:\Windows\System32\wship6.dll - ok
21:43:00.0909 3136  [ FB036947195D5FEFBC8083D5DEB024DE ] C:\Windows\System32\wshqos.dll
21:43:00.0909 3136  C:\Windows\System32\wshqos.dll - ok
21:43:00.0909 3136  [ CE0D320700CCF7C78AEF9ED84332CC53 ] C:\Windows\System32\WSHTCPIP.DLL
21:43:00.0909 3136  C:\Windows\System32\WSHTCPIP.DLL - ok
21:43:00.0909 3136  [ 1C26FB097170A2A91066D1E3A24366E3 ] C:\Windows\System32\cryptsvc.dll
21:43:00.0909 3136  C:\Windows\System32\cryptsvc.dll - ok
21:43:00.0924 3136  [ C424117A562F2DE37A42266894C79AEB ] C:\Windows\System32\nlasvc.dll
21:43:00.0924 3136  C:\Windows\System32\nlasvc.dll - ok
21:43:00.0924 3136  [ 74F380C8EC8813626C670D46E8A714D1 ] C:\Windows\System32\dfsrres.dll
21:43:00.0924 3136  C:\Windows\System32\dfsrres.dll - ok
21:43:00.0940 3136  [ 54E9576169A248AD62A1EB9773225826 ] C:\Windows\System32\mswsock.dll
21:43:00.0940 3136  C:\Windows\System32\mswsock.dll - ok
21:43:00.0940 3136  [ 5E72DCFF9FB2374642043899A1C2E446 ] C:\Windows\System32\NapiNSP.dll
21:43:00.0940 3136  C:\Windows\System32\NapiNSP.dll - ok
21:43:00.0940 3136  [ 08D6D1692B62C9EE4062E1FA04D8FE2F ] C:\Windows\System32\oleres.dll
21:43:00.0940 3136  C:\Windows\System32\oleres.dll - ok
21:43:00.0955 3136  [ C0DC476E89558242848572F9ADE1D685 ] C:\Windows\System32\pnrpnsp.dll
21:43:00.0955 3136  C:\Windows\System32\pnrpnsp.dll - ok
21:43:00.0955 3136  [ 1F795D214820E496BF1124434A6DB546 ] C:\Windows\System32\dot3svc.dll
21:43:00.0955 3136  C:\Windows\System32\dot3svc.dll - ok
21:43:00.0955 3136  [ C5213AC0CD7D4A6BE4BBABA0B18B9BE5 ] C:\Windows\System32\msv1_0.dll
21:43:00.0955 3136  C:\Windows\System32\msv1_0.dll - ok
21:43:00.0971 3136  [ 889A2C9F2AACCD8F64EF50AC0B3D553B ] C:\Windows\System32\netlogon.dll
21:43:00.0971 3136  C:\Windows\System32\netlogon.dll - ok
21:43:00.0971 3136  [ 032C90AD677BF7B7A8013D6087C7A921 ] C:\Windows\System32\dps.dll
21:43:00.0971 3136  C:\Windows\System32\dps.dll - ok
21:43:00.0971 3136  [ 9F75392B9128A91ABAFB044EA350BAAD ] C:\Windows\System32\winlogon.exe
21:43:00.0971 3136  C:\Windows\System32\winlogon.exe - ok
21:43:00.0987 3136  [ B4580122B0A7B263B6EE9ACBA69C8013 ] C:\Windows\ehome\ehrecvr.exe
21:43:00.0987 3136  C:\Windows\ehome\ehrecvr.exe - ok
21:43:00.0987 3136  [ 90A0A875642E18618010645311B4E89E ] C:\Windows\System32\eapsvc.dll
21:43:00.0987 3136  C:\Windows\System32\eapsvc.dll - ok
21:43:00.0987 3136  [ 72910BC4A218C49EA8E43D1FAEC403A5 ] C:\Windows\System32\winbrand.dll
21:43:00.0987 3136  C:\Windows\System32\winbrand.dll - ok
21:43:01.0002 3136  [ 9CA8B435FB0B8F7BD25268AE75639107 ] C:\Windows\System32\winsta.dll
21:43:01.0002 3136  C:\Windows\System32\winsta.dll - ok
21:43:01.0002 3136  [ AD1870C8E5D6DD340C829E6074BF3C3F ] C:\Windows\ehome\ehsched.exe
21:43:01.0002 3136  C:\Windows\ehome\ehsched.exe - ok
21:43:01.0002 3136  [ C27C4EE8926E74AA72EFCAB24C5242C3 ] C:\Windows\ehome\ehstart.dll
21:43:01.0002 3136  C:\Windows\ehome\ehstart.dll - ok
21:43:01.0018 3136  [ 3226FDA08988526E819E364E8CCE4CEE ] C:\Windows\System32\emdmgmt.dll
21:43:01.0018 3136  C:\Windows\System32\emdmgmt.dll - ok
21:43:01.0018 3136  [ 37ADD2A134AE436FFF0976D69449F45C ] C:\Windows\System32\wevtsvc.dll
21:43:01.0018 3136  C:\Windows\System32\wevtsvc.dll - ok
21:43:01.0018 3136  [ 4F34903E7989C6EDDAAABDEE6E01D381 ] C:\Windows\System32\schannel.dll
21:43:01.0018 3136  C:\Windows\System32\schannel.dll - ok
21:43:01.0033 3136  [ 8B8DF4AE8B98BB671E1DAB65C72411B4 ] C:\Windows\System32\wdigest.dll
21:43:01.0033 3136  C:\Windows\System32\wdigest.dll - ok
21:43:01.0033 3136  [ A90247CD20C2DB51C264EACC00A3039F ] C:\Windows\System32\rsaenh.dll
21:43:01.0033 3136  C:\Windows\System32\rsaenh.dll - ok
21:43:01.0049 3136  [ E43BCE1A77D6FD4ED5F8E0482B9E7DF1 ] C:\Windows\System32\fdPHost.dll
21:43:01.0049 3136  C:\Windows\System32\fdPHost.dll - ok
21:43:01.0049 3136  [ 89ED56DCE8E47AF40892778A5BD31FD2 ] C:\Windows\System32\FDResPub.dll
21:43:01.0049 3136  C:\Windows\System32\FDResPub.dll - ok
21:43:01.0049 3136  [ 0DFC9EA99681BF966F794AF7C39495F2 ] C:\Windows\System32\gpapi.dll
21:43:01.0049 3136  C:\Windows\System32\gpapi.dll - ok
21:43:01.0065 3136  [ 302964DCAC79D618CC7B72C778DA9FD2 ] C:\Windows\System32\PresentationHost.exe
21:43:01.0065 3136  C:\Windows\System32\PresentationHost.exe - ok
21:43:01.0065 3136  [ 07A6B9B0227E2FAAD4DF420B7230E790 ] C:\Windows\System32\TSpkg.dll
21:43:01.0065 3136  C:\Windows\System32\TSpkg.dll - ok
21:43:01.0065 3136  [ 58236642134BC28334F3209F0130F7A0 ] C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll
21:43:01.0065 3136  C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll - ok
21:43:01.0080 3136  [ 8FA640195279ACE21BEA91396A0054FC ] C:\Windows\System32\hidserv.dll
21:43:01.0080 3136  C:\Windows\System32\hidserv.dll - ok
21:43:01.0080 3136  [ D40AA05E29BF6ED29B139F044B461E9B ] C:\Windows\System32\KMSVC.DLL
21:43:01.0080 3136  C:\Windows\System32\KMSVC.DLL - ok
21:43:01.0080 3136  [ 35662FE4D8622F667AA5A5568F7F1B40 ] C:\Windows\System32\IKEEXT.DLL
21:43:01.0080 3136  C:\Windows\System32\IKEEXT.DLL - ok
21:43:01.0096 3136  [ 88CF5281ED9880D74DC9011CF8B5262D ] C:\Windows\System32\IPBusEnum.dll
21:43:01.0096 3136  C:\Windows\System32\IPBusEnum.dll - ok
21:43:01.0096 3136  [ ECC9AD72CFC4AB41CF6A9BCC11F9FEF6 ] C:\Windows\System32\iphlpsvc.dll
21:43:01.0096 3136  C:\Windows\System32\iphlpsvc.dll - ok
21:43:01.0111 3136  [ 74C2F29CC612B2B34231BEBD824D2FB2 ] C:\Windows\System32\keyiso.dll
21:43:01.0111 3136  C:\Windows\System32\keyiso.dll - ok
21:43:01.0111 3136  [ 53D1482FC1AA36AC015A85E6CF2146BD ] C:\Windows\System32\srvsvc.dll
21:43:01.0111 3136  C:\Windows\System32\srvsvc.dll - ok
21:43:01.0111 3136  [ 435F0F6DC87A4B5DA78F1FA309884189 ] C:\Windows\System32\wkssvc.dll
21:43:01.0111 3136  C:\Windows\System32\wkssvc.dll - ok
21:43:01.0127 3136  [ 1C0A6AF5FA2960CD23F8D849703F685E ] C:\Windows\ehome\ehres.dll
21:43:01.0127 3136  C:\Windows\ehome\ehres.dll - ok
21:43:01.0127 3136  [ FA0593D936C9B95FB6FAA32AD1595D49 ] C:\Windows\System32\lltdres.dll
21:43:01.0127 3136  C:\Windows\System32\lltdres.dll - ok
21:43:01.0127 3136  [ 35D40113E4A5B961B6CE5C5857702518 ] C:\Windows\System32\lmhsvc.dll
21:43:01.0127 3136  C:\Windows\System32\lmhsvc.dll - ok
21:43:01.0143 3136  [ 9DFA3A459AF0954AA85B4F7622AD87BB ] C:\Windows\System32\mmcss.dll
21:43:01.0143 3136  C:\Windows\System32\mmcss.dll - ok
21:43:01.0143 3136  [ 5ED6BB7CB8726BB1E5EE479FB9E61A18 ] C:\Windows\System32\FirewallAPI.dll
21:43:01.0143 3136  C:\Windows\System32\FirewallAPI.dll - ok
21:43:01.0143 3136  [ EA822412BBBA9B7D2B1A3748AD50EFB8 ] C:\Windows\System32\iscsidsc.dll
21:43:01.0143 3136  C:\Windows\System32\iscsidsc.dll - ok
21:43:01.0158 3136  [ E9E753A96E40CFD19D31A6F4C8207D35 ] C:\Windows\System32\msimsg.dll
21:43:01.0158 3136  C:\Windows\System32\msimsg.dll - ok
21:43:01.0158 3136  [ 1CDBB5D002FE2BC5300AA20550D8A52E ] C:\Windows\System32\QAGENTRT.DLL
21:43:01.0158 3136  C:\Windows\System32\QAGENTRT.DLL - ok
21:43:01.0158 3136  [ 90A4DAE28B94497F83BEA0F2A3B77092 ] C:\Windows\System32\netman.dll
21:43:01.0158 3136  C:\Windows\System32\netman.dll - ok
21:43:01.0174 3136  [ 4EF5DF1B011B05737ECB8F0B7B171510 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll
21:43:01.0174 3136  C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelInstallRC.dll - ok
21:43:01.0174 3136  [ 3A500F3E98436E852C25E6206161B0D4 ] C:\Windows\System32\netprof.dll
21:43:01.0174 3136  C:\Windows\System32\netprof.dll - ok
21:43:01.0174 3136  [ 23B8201A363DE0E649FC75EE9874DEE2 ] C:\Windows\System32\nsisvc.dll
21:43:01.0174 3136  C:\Windows\System32\nsisvc.dll - ok
21:43:01.0189 3136  [ 016D01D3B8FB976A193C7434BED8DCCF ] C:\Windows\System32\p2psvc.dll
21:43:01.0189 3136  C:\Windows\System32\p2psvc.dll - ok
21:43:01.0189 3136  [ D8C5C215C932233A4F1D7F368F4E4E65 ] C:\Windows\System32\pcasvc.dll
21:43:01.0189 3136  C:\Windows\System32\pcasvc.dll - ok
21:43:01.0189 3136  [ CD05A38D166BEADE18030BAFC0C0A939 ] C:\Windows\System32\pla.dll
21:43:01.0189 3136  C:\Windows\System32\pla.dll - ok
21:43:01.0205 3136  [ 6B23DBA3732D20A59348B766E1CFBD20 ] C:\Windows\System32\polstore.dll
21:43:01.0205 3136  C:\Windows\System32\polstore.dll - ok
21:43:01.0205 3136  [ 747BB4C31F3B6E8D1B5ED0AD61518CB5 ] C:\Windows\System32\umpnpmgr.dll
21:43:01.0205 3136  C:\Windows\System32\umpnpmgr.dll - ok
21:43:01.0205 3136  [ 213112E152E68F0E4705E36F052A2880 ] C:\Windows\System32\profsvc.dll
21:43:01.0205 3136  C:\Windows\System32\profsvc.dll - ok
21:43:01.0221 3136  [ 740FCD1371B5E2E34072397DBA4BCFB2 ] C:\Windows\System32\psbase.dll
21:43:01.0221 3136  C:\Windows\System32\psbase.dll - ok
21:43:01.0221 3136  [ D2B3E2B7426DC23E185FBC73C8936C12 ] C:\Windows\System32\drivers\qwavedrv.sys
21:43:01.0221 3136  C:\Windows\System32\drivers\qwavedrv.sys - ok
21:43:01.0236 3136  [ CA61BDFD3713A7CE75F2812AFC431594 ] C:\Windows\System32\qwave.dll
21:43:01.0236 3136  C:\Windows\System32\qwave.dll - ok
21:43:01.0236 3136  [ F14F4AAB9F54D099FE99192BDB100AC9 ] C:\Windows\System32\rasauto.dll
21:43:01.0236 3136  C:\Windows\System32\rasauto.dll - ok
21:43:01.0236 3136  [ 11D65E29BC9D1E4114D18FE68194394C ] C:\Windows\System32\rasmans.dll
21:43:01.0236 3136  C:\Windows\System32\rasmans.dll - ok
21:43:01.0252 3136  [ 6C1A43C589EE8011A1EBFD51C01B77CE ] C:\Windows\System32\mprdim.dll
21:43:01.0252 3136  C:\Windows\System32\mprdim.dll - ok
21:43:01.0252 3136  [ 5123F83CBC4349D065534EEB6BBDC42B ] C:\Windows\System32\Locator.exe
21:43:01.0252 3136  C:\Windows\System32\Locator.exe - ok
21:43:01.0252 3136  [ 9A043808667C8C1893DA7275AF373F0E ] C:\Windows\System32\regsvc.dll
21:43:01.0252 3136  C:\Windows\System32\regsvc.dll - ok
21:43:01.0267 3136  [ 565B4B9E5AD2F2F18A4F8AAFA6C06BBB ] C:\Windows\System32\SCardSvr.dll
21:43:01.0267 3136  C:\Windows\System32\SCardSvr.dll - ok
21:43:01.0267 3136  [ 886CEC884B5BE29AB9828B8AB46B11F7 ] C:\Windows\System32\schedsvc.dll
21:43:01.0267 3136  C:\Windows\System32\schedsvc.dll - ok
21:43:01.0283 3136  [ F7B6BF02240D0A764ADF8C8966735552 ] C:\Windows\System32\sdrsvc.dll
21:43:01.0283 3136  C:\Windows\System32\sdrsvc.dll - ok
21:43:01.0283 3136  [ 9A82BF4C90B00A63150A606A1E2FD82B ] C:\Windows\System32\ipnathlp.dll
21:43:01.0283 3136  C:\Windows\System32\ipnathlp.dll - ok
21:43:01.0283 3136  [ 8388C4133DDBE62AD7BC3EC9F14271ED ] C:\Windows\System32\seclogon.dll
21:43:01.0283 3136  C:\Windows\System32\seclogon.dll - ok
21:43:01.0299 3136  [ 34350AE2C1D33D21C7305F861BD8DAD8 ] C:\Windows\System32\Sens.dll
21:43:01.0299 3136  C:\Windows\System32\Sens.dll - ok
21:43:01.0299 3136  [ 78878235DA4DF0D116E86837A0A21DF8 ] C:\Windows\System32\SessEnv.dll
21:43:01.0299 3136  C:\Windows\System32\SessEnv.dll - ok
21:43:01.0299 3136  [ B264DFA21677728613267FE63802B332 ] C:\Windows\System32\shsvcs.dll
21:43:01.0299 3136  C:\Windows\System32\shsvcs.dll - ok
21:43:01.0314 3136  [ 7610645679BB5994210D21A347E0C479 ] C:\Windows\System32\SLsvc.exe
21:43:01.0314 3136  C:\Windows\System32\SLsvc.exe - ok
21:43:01.0314 3136  [ 49670F3E42A0178A0AB425AE15D88E7C ] C:\Windows\System32\SLUINotify.dll
21:43:01.0314 3136  C:\Windows\System32\SLUINotify.dll - ok
21:43:01.0314 3136  [ 925E6EC977B316AB3D3A536E8AD36B5E ] C:\Windows\System32\tcpipcfg.dll
21:43:01.0314 3136  C:\Windows\System32\tcpipcfg.dll - ok
21:43:01.0330 3136  [ 2A146A055B4401C16EE62D18B8E2A032 ] C:\Windows\System32\snmptrap.exe
21:43:01.0330 3136  C:\Windows\System32\snmptrap.exe - ok
21:43:01.0330 3136  [ DA612EF2556776DF2630B68BF2D48935 ] C:\Windows\System32\spoolsv.exe
21:43:01.0330 3136  C:\Windows\System32\spoolsv.exe - ok
21:43:01.0330 3136  [ 8D3E4BAFF8B3997138C38EB1B600519A ] C:\Windows\System32\ssdpsrv.dll
21:43:01.0330 3136  C:\Windows\System32\ssdpsrv.dll - ok
21:43:01.0345 3136  [ A941E099EF46E3CC12F898CBE1C39910 ] C:\Windows\System32\wiaservc.dll
21:43:01.0345 3136  C:\Windows\System32\wiaservc.dll - ok
21:43:01.0345 3136  [ 749ADA8D6C18A08ADFEDE69CBF5DB2E0 ] C:\Windows\System32\swprv.dll
21:43:01.0345 3136  C:\Windows\System32\swprv.dll - ok
21:43:01.0361 3136  [ 8F2B5FEDE18BD3C4C926CBF88E6F1264 ] C:\Windows\System32\sysmain.dll
21:43:01.0361 3136  C:\Windows\System32\sysmain.dll - ok
21:43:01.0361 3136  [ 2DCA225EAE15F42C0933E998EE0231C3 ] C:\Windows\System32\TabSvc.dll
21:43:01.0361 3136  C:\Windows\System32\TabSvc.dll - ok
21:43:01.0361 3136  [ EF3DD33C740FC2F82E7E4622F1C49289 ] C:\Windows\System32\tapisrv.dll
21:43:01.0361 3136  C:\Windows\System32\tapisrv.dll - ok
21:43:01.0377 3136  [ 68FA52794AE9ACC61BDE16FE0956B414 ] C:\Windows\System32\tbssvc.dll
21:43:01.0377 3136  C:\Windows\System32\tbssvc.dll - ok
21:43:01.0377 3136  [ FAD71C1E8E4047B154E899AE31EB8CAA ] C:\Windows\System32\termsrv.dll
21:43:01.0377 3136  C:\Windows\System32\termsrv.dll - ok
21:43:01.0377 3136  [ 34E388A395FEDBA1D0511ED39BBF4074 ] C:\Windows\servicing\TrustedInstaller.exe
21:43:01.0377 3136  C:\Windows\servicing\TrustedInstaller.exe - ok
21:43:01.0392 3136  [ 6BBA0582C0025D43729A1112D3B57897 ] C:\Windows\System32\trkwks.dll
21:43:01.0392 3136  C:\Windows\System32\trkwks.dll - ok
21:43:01.0392 3136  [ 24A333F4F14DCFB6FF6D5A1B9E5D79DD ] C:\Windows\System32\UI0Detect.exe
21:43:01.0392 3136  C:\Windows\System32\UI0Detect.exe - ok
21:43:01.0392 3136  [ 8EB871A3DEB6B3D5A85EB6DDFC390B59 ] C:\Windows\System32\upnphost.dll
21:43:01.0392 3136  C:\Windows\System32\upnphost.dll - ok
21:43:01.0408 3136  [ E87B968F3D49117445893EB0503FE34F ] C:\Windows\System32\dwm.exe
21:43:01.0408 3136  C:\Windows\System32\dwm.exe - ok
21:43:01.0408 3136  [ C9D0BAFEE0D0A2681F048CA61BC0DA96 ] C:\Windows\System32\vds.exe
21:43:01.0408 3136  C:\Windows\System32\vds.exe - ok
21:43:01.0408 3136  [ 62B0D0F6F5580D9D0DFA5E0B466FF2ED ] C:\Windows\System32\w32time.dll
21:43:01.0408 3136  C:\Windows\System32\w32time.dll - ok
21:43:01.0423 3136  [ C1B19162E0509CEAB4CDF664E139D956 ] C:\Windows\System32\wcncsvc.dll
21:43:01.0423 3136  C:\Windows\System32\wcncsvc.dll - ok
21:43:01.0423 3136  [ 11BCB7AFCDD7AADACB5746F544D3A9C7 ] C:\Windows\System32\WcsPlugInService.dll
21:43:01.0423 3136  C:\Windows\System32\WcsPlugInService.dll - ok
21:43:01.0423 3136  [ 2A424B89B14EF17A3D06BCB5A8F79601 ] C:\Windows\System32\wdi.dll
21:43:01.0423 3136  C:\Windows\System32\wdi.dll - ok
21:43:01.0439 3136  [ 01E41C264EEDCB827820A1909162579F ] C:\Windows\System32\WebClnt.dll
21:43:01.0439 3136  C:\Windows\System32\WebClnt.dll - ok
21:43:01.0439 3136  [ 9CF67FF7F8D34CBF115D0C278B9F74AA ] C:\Windows\System32\wecsvc.dll
21:43:01.0439 3136  C:\Windows\System32\wecsvc.dll - ok
21:43:01.0455 3136  [ B68CAB45DB1DAB59D92ACADFAD6364A8 ] C:\Windows\System32\wercplsupport.dll
21:43:01.0455 3136  C:\Windows\System32\wercplsupport.dll - ok
21:43:01.0455 3136  [ 36BA0707680EF4236FD752BEE982CC25 ] C:\Windows\System32\wersvc.dll
21:43:01.0455 3136  C:\Windows\System32\wersvc.dll - ok
21:43:01.0455 3136  [ E762562A8D43BDE3EE11428EB681FF9C ] C:\Windows\System32\winhttp.dll
21:43:01.0455 3136  C:\Windows\System32\winhttp.dll - ok
21:43:01.0470 3136  [ 38A7B89DE4E3417C122317949667FDD8 ] C:\Windows\System32\wbem\WMIsvc.dll
21:43:01.0470 3136  C:\Windows\System32\wbem\WMIsvc.dll - ok
21:43:01.0470 3136  [ 3F6823040030C3E4DA1CF11CD40B7534 ] C:\Windows\System32\WsmSvc.dll
21:43:01.0470 3136  C:\Windows\System32\WsmSvc.dll - ok
21:43:01.0470 3136  [ 7640ACEA41348BFEF34B76E245501261 ] C:\Windows\System32\wlansvc.dll
21:43:01.0470 3136  C:\Windows\System32\wlansvc.dll - ok
21:43:01.0486 3136  [ ACB2E63D50157E3EA7140F29D9E76A48 ] C:\Program Files\Windows Media Player\wmpnetwk.exe
21:43:01.0486 3136  C:\Program Files\Windows Media Player\wmpnetwk.exe - ok
21:43:01.0486 3136  [ A279323BEE5FFFAFDA222910BCE92132 ] C:\Windows\System32\wbem\WmiApSrv.exe
21:43:01.0486 3136  C:\Windows\System32\wbem\WmiApSrv.exe - ok
21:43:01.0486 3136  [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:43:01.0486 3136  C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe - ok
21:43:01.0501 3136  [ 3D3B3B80C12ABE506F56930C46422C28 ] C:\Windows\System32\wpcsvc.dll
21:43:01.0501 3136  C:\Windows\System32\wpcsvc.dll - ok
21:43:01.0501 3136  [ C24844A1D0D9528B19D5BC266B8CD572 ] C:\Windows\System32\wpdbusenum.dll
21:43:01.0501 3136  C:\Windows\System32\wpdbusenum.dll - ok
21:43:01.0517 3136  [ 5DE40982E3AE45DC00586A93637B351B ] C:\Windows\System32\SearchIndexer.exe
21:43:01.0517 3136  C:\Windows\System32\SearchIndexer.exe - ok
21:43:01.0517 3136  [ F97CBB919AF6D0A6643D1A59C15014D1 ] C:\Windows\System32\wscsvc.dll
21:43:01.0517 3136  C:\Windows\System32\wscsvc.dll - ok
21:43:01.0517 3136  [ 6298277B73C77FA99106B271A7525163 ] C:\Windows\System32\wuaueng.dll
21:43:01.0517 3136  C:\Windows\System32\wuaueng.dll - ok
21:43:01.0533 3136  [ DB5BF5AAB72B1B99B5331231D09EBB26 ] C:\Windows\System32\WUDFSvc.dll
21:43:01.0533 3136  C:\Windows\System32\WUDFSvc.dll - ok
21:43:01.0533 3136  [ 80E2839D05CA5970A86D7BE2A08BFF61 ] C:\Windows\System32\scecli.dll
21:43:01.0533 3136  C:\Windows\System32\scecli.dll - ok
21:43:01.0533 3136  [ BBDE9DB609D0657BE77AF63CC392F6B0 ] C:\Windows\System32\ntmarta.dll
21:43:01.0533 3136  C:\Windows\System32\ntmarta.dll - ok
21:43:01.0548 3136  [ 3CDEC51291F735C5C276B957239017A3 ] C:\Windows\System32\powrprof.dll
21:43:01.0548 3136  C:\Windows\System32\powrprof.dll - ok
21:43:01.0548 3136  [ 10DA15933D582D2FEDCF705EFE394B09 ] C:\Windows\System32\svchost.exe
21:43:01.0548 3136  C:\Windows\System32\svchost.exe - ok
21:43:01.0548 3136  [ 42885BB44B6E065B8575A8DD6C430C52 ] C:\Windows\System32\drivers\luafv.sys
21:43:01.0548 3136  C:\Windows\System32\drivers\luafv.sys - ok
21:43:01.0564 3136  [ 7B981222A257D076885BFFB66F19B7CE ] C:\Windows\System32\rpcss.dll
21:43:01.0564 3136  C:\Windows\System32\rpcss.dll - ok
21:43:01.0564 3136  [ D8C819157EBA10401FD25FB48184EF24 ] C:\Windows\System32\version.dll
21:43:01.0564 3136  C:\Windows\System32\version.dll - ok
21:43:01.0564 3136  [ EAB1144395AACB4CBB85AE5F6334CB3F ] C:\Windows\System32\LogonUI.exe
21:43:01.0564 3136  C:\Windows\System32\LogonUI.exe - ok
21:43:01.0579 3136  [ 501956FA7FF3E5277BEB396E4F5C6F23 ] C:\Windows\System32\authui.dll
21:43:01.0579 3136  C:\Windows\System32\authui.dll - ok
21:43:01.0579 3136  [ B28A9B2300A250B703D44C1759AF2605 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll
21:43:01.0579 3136  C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6000.16386_none_5d07289e07e1d100\comctl32.dll - ok
21:43:01.0595 3136  [ B3FF96D8591FF8608BB53214FF0A8B49 ] C:\Windows\System32\avrt.dll
21:43:01.0595 3136  C:\Windows\System32\avrt.dll - ok
21:43:01.0595 3136  [ B55A6BEA7EA9087DC72485D5E028EBCB ] C:\Windows\System32\MMDevAPI.dll
21:43:01.0595 3136  C:\Windows\System32\MMDevAPI.dll - ok
21:43:01.0595 3136  [ 4D14689094BFE7C16CDECF659D8A80F6 ] C:\Windows\System32\wtsapi32.dll
21:43:01.0595 3136  C:\Windows\System32\wtsapi32.dll - ok
21:43:01.0611 3136  [ 6D78A92F2CDB58DA04207AA57C58E87C ] C:\Windows\System32\WUDFPlatform.dll
21:43:01.0611 3136  C:\Windows\System32\WUDFPlatform.dll - ok
21:43:01.0611 3136  [ 2EC53B5A351C4D443896DBAD117F7E82 ] C:\Windows\System32\msimg32.dll
21:43:01.0611 3136  C:\Windows\System32\msimg32.dll - ok
21:43:01.0611 3136  [ E340D47578B8CB8A86D3578EA50A3B83 ] C:\Windows\System32\uxtheme.dll
21:43:01.0611 3136  C:\Windows\System32\uxtheme.dll - ok
21:43:01.0626 3136  [ C6E246BE0C525762C474F7EC758A70A9 ] C:\Windows\System32\wintrust.dll
21:43:01.0626 3136  C:\Windows\System32\wintrust.dll - ok
21:43:01.0626 3136  [ AD5B9D71CCCFB5FA200271537F185544 ] C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\GdiPlus.dll
21:43:01.0626 3136  C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7\GdiPlus.dll - ok
21:43:01.0626 3136  [ 54BF0DCEC92854F8FAEC362AB2BC8600 ] C:\Windows\System32\cabinet.dll
21:43:01.0626 3136  C:\Windows\System32\cabinet.dll - ok
21:43:01.0642 3136  [ 3CC7841F318C99819BE3A9736C9A7BA1 ] C:\Windows\System32\duser.dll
21:43:01.0642 3136  C:\Windows\System32\duser.dll - ok
21:43:01.0642 3136  [ 71A2DCA8F626FCEF8BFF7E2C17C67A7F ] C:\Windows\System32\xmllite.dll
21:43:01.0642 3136  C:\Windows\System32\xmllite.dll - ok
21:43:01.0642 3136  [ EE472CD2C01F6F8E8AA1FA06FFEF61B6 ] C:\Windows\System32\drivers\drmkaud.sys
21:43:01.0642 3136  C:\Windows\System32\drivers\drmkaud.sys - ok
21:43:01.0657 3136  [ B1B7BF8A406A19CC4AD6E45555EA77E5 ] C:\Windows\System32\audiodg.exe
21:43:01.0657 3136  C:\Windows\System32\audiodg.exe - ok
21:43:01.0657 3136  [ 9694942A39AB2A7DF58A1D95EA37AC3D ] C:\Windows\System32\SmartcardCredentialProvider.dll
21:43:01.0657 3136  C:\Windows\System32\SmartcardCredentialProvider.dll - ok
21:43:01.0657 3136  [ BCF6589C42D8F6A20F33EF133FFE0524 ] C:\Windows\System32\gpsvc.dll
21:43:01.0657 3136  C:\Windows\System32\gpsvc.dll - ok
21:43:01.0673 3136  [ 4E579F380701D9BF0669ED61E8EC5951 ] C:\Windows\System32\rasapi32.dll
21:43:01.0673 3136  C:\Windows\System32\rasapi32.dll - ok
21:43:01.0673 3136  [ 2CD4F35B30A5781D0628BEF5BC07CA70 ] C:\Windows\System32\rasplap.dll
21:43:01.0673 3136  C:\Windows\System32\rasplap.dll - ok
21:43:01.0689 3136  [ 9BCBDCA7312A0806CE7D8976C314A988 ] C:\Windows\System32\rasman.dll
21:43:01.0689 3136  C:\Windows\System32\rasman.dll - ok
21:43:01.0689 3136  [ 0F0DA05C44E911301028D9CEC6294EBB ] C:\Windows\System32\nlaapi.dll
21:43:01.0689 3136  C:\Windows\System32\nlaapi.dll - ok
21:43:01.0689 3136  [ 70F08ECE7A30A639D3F0C8C433685C7D ] C:\Windows\System32\tapi32.dll
21:43:01.0689 3136  C:\Windows\System32\tapi32.dll - ok
21:43:01.0704 3136  [ 36C5C3CAB3B467BA68AE345C9B9DADC3 ] C:\Windows\System32\atl.dll
21:43:01.0704 3136  C:\Windows\System32\atl.dll - ok
21:43:01.0704 3136  [ 40AC3601ACA74A015C4E0DB0727929CA ] C:\Windows\System32\oleacc.dll
21:43:01.0704 3136  C:\Windows\System32\oleacc.dll - ok
21:43:01.0704 3136  [ BF832D4C49AAEA869E7D9248D0E73A83 ] C:\Windows\System32\rtutils.dll
21:43:01.0704 3136  C:\Windows\System32\rtutils.dll - ok
21:43:01.0720 3136  [ 3B5E50A380AE03249C9F60E5BB28EFCB ] C:\Windows\System32\winmm.dll
21:43:01.0720 3136  C:\Windows\System32\winmm.dll - ok
21:43:01.0720 3136  [ 35A9D03D0B77E4A35104D851B1095A59 ] C:\Windows\System32\WinSCard.dll
21:43:01.0720 3136  C:\Windows\System32\WinSCard.dll - ok
21:43:01.0720 3136  [ 7B4971C3D43525175A4EA0D143E0412E ] C:\Windows\System32\es.dll
21:43:01.0720 3136  C:\Windows\System32\es.dll - ok
21:43:01.0735 3136  [ 96BC076D1BA9FEE72709FC72DC025270 ] C:\Windows\System32\propsys.dll
21:43:01.0735 3136  C:\Windows\System32\propsys.dll - ok
21:43:01.0735 3136  [ 297ED36343DE583013757975AF58DA84 ] C:\Windows\System32\drivers\spsys.sys
21:43:01.0735 3136  C:\Windows\System32\drivers\spsys.sys - ok
21:43:01.0735 3136  [ 8758474CE387F7F18F2672C89D8AF6E8 ] C:\Windows\System32\shgina.dll
21:43:01.0735 3136  C:\Windows\System32\shgina.dll - ok
21:43:01.0751 3136  [ 0227EDA48B7A2E8751557006D4ABD832 ] C:\Windows\System32\shacct.dll
21:43:01.0751 3136  C:\Windows\System32\shacct.dll - ok
21:43:01.0751 3136  [ 919CC2A0476D5A6A4C935D4B88E29912 ] C:\Windows\System32\ksuser.dll
21:43:01.0751 3136  C:\Windows\System32\ksuser.dll - ok
21:43:01.0751 3136  [ C3A87CA43956F2B8D0C3F567F129ABF3 ] C:\Windows\System32\wdmaud.drv
21:43:01.0751 3136  C:\Windows\System32\wdmaud.drv - ok
21:43:01.0767 3136  [ 663C2340C3061A99D1C58F8094F66CEC ] C:\Windows\System32\AudioSes.dll
21:43:01.0767 3136  C:\Windows\System32\AudioSes.dll - ok
21:43:01.0767 3136  [ 03F14F32FA71F9DA9FA60CC0000EACD4 ] C:\Windows\System32\AudioEng.dll
21:43:01.0767 3136  C:\Windows\System32\AudioEng.dll - ok
21:43:01.0767 3136  [ F79D0D7C9004474CB42746D9B2C30A2B ] C:\Windows\System32\uxsms.dll
21:43:01.0767 3136  C:\Windows\System32\uxsms.dll - ok
21:43:01.0782 3136  [ 8269CC01940A202BBB9FDF26705DBD67 ] C:\Windows\System32\hid.dll
21:43:01.0782 3136  C:\Windows\System32\hid.dll - ok
21:43:01.0782 3136  [ 02BA9C898969CA850C84DDF867378C27 ] C:\Windows\System32\msacm32.dll
21:43:01.0782 3136  C:\Windows\System32\msacm32.dll - ok
21:43:01.0782 3136  [ 49F6BF22FA9DAD48E5E6964B1775EEBF ] C:\Windows\System32\msacm32.drv
21:43:01.0782 3136  C:\Windows\System32\msacm32.drv - ok
21:43:01.0798 3136  [ FD015B4F95DAA2B712F0E372A116FBAD ] C:\Windows\System32\drivers\lltdio.sys
21:43:01.0798 3136  C:\Windows\System32\drivers\lltdio.sys - ok
21:43:01.0798 3136  [ 848E745A842F903FD521DB585AB00D97 ] C:\Windows\System32\midimap.dll
21:43:01.0798 3136  C:\Windows\System32\midimap.dll - ok
21:43:01.0813 3136  [ AD38BD7F36A71D1B0BE965BD3CB376AC ] C:\Windows\System32\WindowsCodecs.dll
21:43:01.0813 3136  C:\Windows\System32\WindowsCodecs.dll - ok
21:43:01.0813 3136  [ 6DA4A0FC7C0E83DF0CB3CFD0A514C3BC ] C:\Windows\System32\drivers\nwifi.sys
21:43:01.0813 3136  C:\Windows\System32\drivers\nwifi.sys - ok
21:43:01.0813 3136  [ 7C0D4B898C24000DBEDFF0BDAFEC2EC4 ] C:\Windows\System32\adtschema.dll
21:43:01.0813 3136  C:\Windows\System32\adtschema.dll - ok
21:43:01.0829 3136  [ A6A8DA7AE4D53394AB22AC3AB6D3F5D3 ] C:\Windows\System32\drivers\fltMgr.sys
21:43:01.0829 3136  C:\Windows\System32\drivers\fltMgr.sys - ok
21:43:01.0829 3136  [ 5DE5EE546BF40838EBE0E01CB629DF64 ] C:\Windows\System32\drivers\ndisuio.sys
21:43:01.0829 3136  C:\Windows\System32\drivers\ndisuio.sys - ok
21:43:01.0829 3136  [ 97E939D2128FEC5D5A3E6E79B290A2F4 ] C:\Windows\System32\drivers\rspndr.sys
21:43:01.0829 3136  C:\Windows\System32\drivers\rspndr.sys - ok
21:43:01.0845 3136  [ 8356A02DD1B2783987134FDF8B71633F ] C:\Windows\System32\ci.dll
21:43:01.0845 3136  C:\Windows\System32\ci.dll - ok
21:43:01.0845 3136  [ EECBA1DD142BF8693C476BE8F32FE253 ] C:\Windows\System32\dnsrslvr.dll
21:43:01.0845 3136  C:\Windows\System32\dnsrslvr.dll - ok
21:43:01.0845 3136  [ B2D633D018D722879B6AAAECE9CBFEE1 ] C:\Windows\System32\AUDIOKSE.dll
21:43:01.0845 3136  C:\Windows\System32\AUDIOKSE.dll - ok
21:43:01.0860 3136  [ F99AD9DC3B8CA26C211D92C030787A5C ] C:\Windows\System32\eapphost.dll
21:43:01.0860 3136  C:\Windows\System32\eapphost.dll - ok
21:43:01.0860 3136  [ ED1CE465D0D897889FABEAE3ED9215CF ] C:\Windows\System32\rastls.dll
21:43:01.0860 3136  C:\Windows\System32\rastls.dll - ok
21:43:01.0860 3136  [ 972A0C4A4CBF7575D5E2CA20229820B9 ] C:\Windows\System32\PSHED.DLL
21:43:01.0860 3136  C:\Windows\System32\PSHED.DLL - ok
21:43:01.0876 3136  [ 8F23A0C652C9205A919476D1E62D3C65 ] C:\Windows\System32\raschap.dll
21:43:01.0876 3136  C:\Windows\System32\raschap.dll - ok
21:43:01.0876 3136  [ E90BB891CE98D647E88C5BBD58A8F4DA ] C:\Windows\System32\RtkAPO.dll
21:43:01.0876 3136  C:\Windows\System32\RtkAPO.dll - ok
21:43:01.0891 3136  [ 8C9513713A1A830EE9A716FB91E08267 ] C:\Windows\System32\wlanmsm.dll
21:43:01.0891 3136  C:\Windows\System32\wlanmsm.dll - ok
21:43:01.0891 3136  [ DA8F5026ABAC8A5F965256AAD5B8B667 ] C:\Windows\System32\wlansec.dll
21:43:01.0891 3136  C:\Windows\System32\wlansec.dll - ok
21:43:01.0891 3136  [ 39C4C7E087DC64C492108CA98936FF30 ] C:\Windows\System32\onex.dll
21:43:01.0891 3136  C:\Windows\System32\onex.dll - ok
21:43:01.0907 3136  [ FC34CA580010DABFEC1EA854BA94AA01 ] C:\Windows\System32\eappcfg.dll
21:43:01.0907 3136  C:\Windows\System32\eappcfg.dll - ok
21:43:01.0907 3136  [ F9FECFEEDCC32E55093FC9F3F5A09739 ] C:\Windows\System32\eappprxy.dll
21:43:01.0907 3136  C:\Windows\System32\eappprxy.dll - ok
21:43:01.0907 3136  [ 2FA7EF1006DC44CB3C86E727D432D827 ] C:\Windows\System32\l2gpstore.dll
21:43:01.0907 3136  C:\Windows\System32\l2gpstore.dll - ok
21:43:01.0923 3136  [ EB2170D0DDF3B2A92506AE16BC524B0B ] C:\Windows\System32\wlanutil.dll
21:43:01.0923 3136  C:\Windows\System32\wlanutil.dll - ok
21:43:01.0923 3136  [ 979B8FD012A35D567A9088A100DC4D78 ] C:\Windows\System32\wlgpclnt.dll
21:43:01.0923 3136  C:\Windows\System32\wlgpclnt.dll - ok
21:43:01.0923 3136  [ D6185339319ADE924A5531196AE4040F ] C:\Windows\System32\WMALFXGFXDSP.dll
21:43:01.0923 3136  C:\Windows\System32\WMALFXGFXDSP.dll - ok
21:43:01.0938 3136  [ 3283DE6F4B572CE2E1710F336489AA28 ] C:\Windows\System32\mfplat.dll
21:43:01.0938 3136  C:\Windows\System32\mfplat.dll - ok
21:43:01.0938 3136  [ 473DF61261C234A4A4C577F3631B9327 ] C:\Windows\System32\msxml6.dll
21:43:01.0938 3136  C:\Windows\System32\msxml6.dll - ok
21:43:01.0938 3136  [ 38D84E4D1F7514B883D2858C54E81441 ] C:\Windows\System32\ktmw32.dll
21:43:01.0938 3136  C:\Windows\System32\ktmw32.dll - ok
21:43:01.0954 3136  [ 4A05089F43041903A3C523A3C16E3350 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\comctl32.dll
21:43:01.0954 3136  C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6000.16386_none_87e0cb09378714f1\comctl32.dll - ok
21:43:01.0954 3136  [ 096B4ACC6E513D400B79BBE986A12AC3 ] C:\Windows\System32\taskcomp.dll
21:43:01.0954 3136  C:\Windows\System32\taskcomp.dll - ok
21:43:01.0954 3136  [ FDE35AE1E3A1F21AE1E31674295F31E9 ] C:\Windows\System32\netcfgx.dll
21:43:01.0954 3136  C:\Windows\System32\netcfgx.dll - ok
21:43:01.0969 3136  [ EA24FE637D974A8A31BC650F478E3533 ] C:\Windows\System32\drivers\http.sys
21:43:01.0969 3136  C:\Windows\System32\drivers\http.sys - ok
21:43:01.0969 3136  [ 976B09666D0A076ECC3F330891DA0DAD ] C:\Windows\System32\spoolss.dll
21:43:01.0969 3136  C:\Windows\System32\spoolss.dll - ok
21:43:01.0969 3136  [ 9E1A4603B874EEBCE0298113951ABEFB ] C:\Windows\System32\drivers\srvnet.sys
21:43:01.0969 3136  C:\Windows\System32\drivers\srvnet.sys - ok
21:43:01.0985 3136  [ BBC285B1A17A0C08FC6A2E1FB3E9D141 ] C:\Windows\System32\FWPUCLNT.DLL
21:43:01.0985 3136  C:\Windows\System32\FWPUCLNT.DLL - ok
21:43:01.0985 3136  [ 913CD06FBE9105CE6077E90FD4418561 ] C:\Windows\System32\drivers\bowser.sys
21:43:01.0985 3136  C:\Windows\System32\drivers\bowser.sys - ok
21:43:02.0001 3136  [ 6E7A7F0C1193EE5648443FE2D4B789EC ] C:\Windows\System32\drivers\mpsdrv.sys
21:43:02.0001 3136  C:\Windows\System32\drivers\mpsdrv.sys - ok
21:43:02.0001 3136  [ 151A9EB1398736668D9E78DECFD013D2 ] C:\Windows\System32\wiarpc.dll
21:43:02.0001 3136  C:\Windows\System32\wiarpc.dll - ok
21:43:02.0001 3136  [ 563ED845885C6A7C09A7715D8BD0585C ] C:\Windows\System32\MPSSVC.dll
21:43:02.0001 3136  C:\Windows\System32\MPSSVC.dll - ok
21:43:02.0016 3136  [ 1D8828B98EE309D65E006F0829E280E5 ] C:\Windows\System32\drivers\mrxdav.sys
21:43:02.0016 3136  C:\Windows\System32\drivers\mrxdav.sys - ok
21:43:02.0016 3136  [ 8AF705CE1BB907932157FAB821170F27 ] C:\Windows\System32\drivers\mrxsmb.sys
21:43:02.0016 3136  C:\Windows\System32\drivers\mrxsmb.sys - ok
21:43:02.0016 3136  [ 47E13AB23371BE3279EEF22BBFA2C1BE ] C:\Windows\System32\drivers\mrxsmb10.sys
21:43:02.0016 3136  C:\Windows\System32\drivers\mrxsmb10.sys - ok
21:43:02.0032 3136  [ 90B3FC7BD6B3D7EE7635DEBBA2187F66 ] C:\Windows\System32\drivers\mrxsmb20.sys
21:43:02.0032 3136  C:\Windows\System32\drivers\mrxsmb20.sys - ok
21:43:02.0032 3136  [ 6971A757AF8CB5E2CBCBB76CC530DB6C ] C:\Windows\System32\drivers\srv2.sys
21:43:02.0032 3136  C:\Windows\System32\drivers\srv2.sys - ok
21:43:02.0032 3136  [ 038579C35F7CAD4A4BBF735DBF83277D ] C:\Windows\System32\drivers\srv.sys
21:43:02.0032 3136  C:\Windows\System32\drivers\srv.sys - ok
21:43:02.0047 3136  [ A324D72A06C110152E7607745F39BFA1 ] C:\Windows\System32\netmsg.dll
21:43:02.0047 3136  C:\Windows\System32\netmsg.dll - ok
21:43:02.0047 3136  [ 452341E471D2D961229DFE0842957272 ] C:\Windows\System32\sscore.dll
21:43:02.0047 3136  C:\Windows\System32\sscore.dll - ok
21:43:02.0047 3136  [ 9FB0C935D2FC55EC1DC648D6A085E66C ] C:\Windows\System32\clusapi.dll
21:43:02.0047 3136  C:\Windows\System32\clusapi.dll - ok
21:43:02.0063 3136  [ A9CB04FABBB885C98EC3620E0540ED47 ] C:\Windows\System32\activeds.dll
21:43:02.0063 3136  C:\Windows\System32\activeds.dll - ok
21:43:02.0063 3136  [ 4A448F53FEA2AF8DC606827BCB2B703A ] C:\Windows\System32\wfapigp.dll
21:43:02.0063 3136  C:\Windows\System32\wfapigp.dll - ok
21:43:02.0079 3136  [ B86BE8E7D6709018C73E4B5E1C070F65 ] C:\Windows\System32\adsldpc.dll
21:43:02.0079 3136  C:\Windows\System32\adsldpc.dll - ok
21:43:02.0079 3136  [ 6CFCA2A5B71C1CB908049DBC6BF6C6D1 ] C:\Windows\System32\mscms.dll
21:43:02.0079 3136  C:\Windows\System32\mscms.dll - ok
21:43:02.0079 3136  [ 6A6E9935532F74A074BDD7C3D84A4376 ] C:\Windows\System32\credui.dll
21:43:02.0079 3136  C:\Windows\System32\credui.dll - ok
21:43:02.0094 3136  [ BA767B42633E32719018F0D02AC01C59 ] C:\Windows\System32\resutils.dll
21:43:02.0094 3136  C:\Windows\System32\resutils.dll - ok
21:43:02.0094 3136  [ E223D2851906B84F52E1B75EA16198F9 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelEvents.dll
21:43:02.0094 3136  C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelEvents.dll - ok
21:43:02.0094 3136  [ E230F3776F373F4C5E788794B53101E4 ] C:\Windows\System32\plasrv.exe
21:43:02.0094 3136  C:\Windows\System32\plasrv.exe - ok
21:43:02.0110 3136  [ BE01E566D1F569AAB32D0335613E1EEA ] C:\Windows\System32\dllhost.exe
21:43:02.0110 3136  C:\Windows\System32\dllhost.exe - ok
21:43:02.0110 3136  [ 1DACD1530C6E58AEAE9F6DE7DA851935 ] C:\Windows\System32\shimeng.dll
21:43:02.0110 3136  C:\Windows\System32\shimeng.dll - ok
21:43:02.0110 3136  [ 5C8D22F3E0B49216C9D2E71BDF202218 ] C:\Windows\System32\dwmapi.dll
21:43:02.0110 3136  C:\Windows\System32\dwmapi.dll - ok
21:43:02.0125 3136  [ 22027835939F86C3E47AD8E3FBDE3D11 ] C:\Windows\System32\userinit.exe
21:43:02.0125 3136  C:\Windows\System32\userinit.exe - ok
21:43:02.0125 3136  [ 8AB84CD4DF5591D7E59667BF90943372 ] C:\Windows\System32\dwmredir.dll
21:43:02.0125 3136  C:\Windows\System32\dwmredir.dll - ok
21:43:02.0125 3136  [ 1226E9FAE5B8508801EC974E3C9D9C14 ] C:\Windows\System32\taskeng.exe
21:43:02.0125 3136  C:\Windows\System32\taskeng.exe - ok
21:43:02.0141 3136  [ B39F1844AD6C656F64ACD32CAEE72CAA ] C:\Windows\System32\slwga.dll
21:43:02.0141 3136  C:\Windows\System32\slwga.dll - ok
21:43:02.0141 3136  [ 77958E07E2A98C7DB5F98C04DE3440B6 ] C:\Windows\System32\milcore.dll
21:43:02.0141 3136  C:\Windows\System32\milcore.dll - ok
21:43:02.0157 3136  [ FF78B8E67EDCE9FEED651D7858D77A04 ] C:\Windows\System32\winrnr.dll
21:43:02.0157 3136  C:\Windows\System32\winrnr.dll - ok
21:43:02.0157 3136  [ A7D525E5C0D91C8C1D84C6BCD25AD77D ] C:\Windows\System32\rasadhlp.dll
21:43:02.0157 3136  C:\Windows\System32\rasadhlp.dll - ok
21:43:02.0157 3136  [ B886D818B9265518A1A6D4AEE43C8159 ] C:\Windows\System32\umb.dll
21:43:02.0157 3136  C:\Windows\System32\umb.dll - ok
21:43:02.0172 3136  [ E37137CB0031440061EB3BF14EC6AC74 ] C:\Windows\System32\localspl.dll
21:43:02.0172 3136  C:\Windows\System32\localspl.dll - ok
21:43:02.0172 3136  [ F4E1AA5D59C849A4AB47E895DC76B9C8 ] C:\Windows\System32\sfc.dll
21:43:02.0172 3136  C:\Windows\System32\sfc.dll - ok
21:43:02.0172 3136  [ E72A22DCF0733AC06695ACD2268F6EB3 ] C:\Windows\System32\d3d9.dll
21:43:02.0172 3136  C:\Windows\System32\d3d9.dll - ok
21:43:02.0188 3136  [ E42320B5A0B23BCB2F324286D0572D68 ] C:\Windows\System32\winspool.drv
21:43:02.0188 3136  C:\Windows\System32\winspool.drv - ok
21:43:02.0188 3136  [ CD6DA5770CAE9D5E6E86722E17B442E0 ] C:\Windows\System32\d3d8thk.dll
21:43:02.0188 3136  C:\Windows\System32\d3d8thk.dll - ok
21:43:02.0188 3136  [ B11FDCA4410D6252964EF97F9A47DE74 ] C:\Windows\System32\TSChannel.dll
21:43:02.0188 3136  C:\Windows\System32\TSChannel.dll - ok
21:43:02.0203 3136  [ 50F69B362FA8C08E7D447842DBEDAD99 ] C:\Windows\System32\HotStartUserAgent.dll
21:43:02.0203 3136  C:\Windows\System32\HotStartUserAgent.dll - ok
21:43:02.0203 3136  [ 27C03E086B8794D1F4032A4F99EE3E22 ] C:\Windows\System32\igdumdx32.dll
21:43:02.0203 3136  C:\Windows\System32\igdumdx32.dll - ok
21:43:02.0203 3136  [ 238C3965DD2E6D2C59D79A3125CE8A0A ] C:\Windows\System32\igdumd32.dll
21:43:02.0203 3136  C:\Windows\System32\igdumd32.dll - ok
21:43:02.0219 3136  [ 5ED1BC5287C8F8A3DA10403152E7BD8B ] C:\Windows\System32\PlaySndSrv.dll
21:43:02.0219 3136  C:\Windows\System32\PlaySndSrv.dll - ok
21:43:02.0219 3136  [ 079FDC65148018E64DFCCEA671E8308C ] C:\Windows\System32\tcpmon.dll
21:43:02.0219 3136  C:\Windows\System32\tcpmon.dll - ok
21:43:02.0219 3136  [ AF24A9DF84637BF9858EC6FB88EBA7B2 ] C:\Windows\System32\snmpapi.dll
21:43:02.0219 3136  C:\Windows\System32\snmpapi.dll - ok
21:43:02.0235 3136  [ F891E412E27C3375257E3D5BD6E17431 ] C:\Windows\System32\wsnmp32.dll
21:43:02.0235 3136  C:\Windows\System32\wsnmp32.dll - ok
21:43:02.0235 3136  [ B4F5DE3DAD8E6B97272F45DB97674878 ] C:\Windows\System32\mgmtapi.dll
21:43:02.0235 3136  C:\Windows\System32\mgmtapi.dll - ok
21:43:02.0235 3136  [ 5091452DC719281CF1DD69367E13B494 ] C:\Windows\System32\tcpmib.dll
21:43:02.0235 3136  C:\Windows\System32\tcpmib.dll - ok
21:43:02.0250 3136  [ 2E3166B370D65D61C05B2E3A662F6EEF ] C:\Windows\System32\usbmon.dll
21:43:02.0250 3136  C:\Windows\System32\usbmon.dll - ok
21:43:02.0250 3136  [ AC5C0C85F248DD2D4BA9805FE2635AEA ] C:\Windows\System32\WSDMon.dll
21:43:02.0250 3136  C:\Windows\System32\WSDMon.dll - ok
21:43:02.0250 3136  [ 0E99592E68DD44610B473B7A024FA32D ] C:\Windows\System32\fundisc.dll
21:43:02.0250 3136  C:\Windows\System32\fundisc.dll - ok
21:43:02.0266 3136  [ 261612679999991EECAEEF98ACE2856C ] C:\Windows\System32\httpapi.dll
21:43:02.0266 3136  C:\Windows\System32\httpapi.dll - ok
21:43:02.0266 3136  [ B25DBC371CDE14C9CBCCB6329C46E7E8 ] C:\Windows\System32\WSDApi.dll
21:43:02.0266 3136  C:\Windows\System32\WSDApi.dll - ok
21:43:02.0281 3136  [ C72DC4848F94A84BDBAE3B1080086316 ] C:\Windows\System32\msxml3.dll
21:43:02.0281 3136  C:\Windows\System32\msxml3.dll - ok
21:43:02.0281 3136  [ 3D16FB7105A4600349E5C6407CBF76CE ] C:\Windows\System32\uDWM.dll
21:43:02.0281 3136  C:\Windows\System32\uDWM.dll - ok
21:43:02.0281 3136  [ 37440D09DEAE0B672A04DCCF7ABF06BE ] C:\Windows\explorer.exe
21:43:02.0281 3136  C:\Windows\explorer.exe - ok
21:43:02.0297 3136  [ 9AD8D54807B34897E41F68C6FF27F3CC ] C:\Windows\System32\win32spl.dll
21:43:02.0297 3136  C:\Windows\System32\win32spl.dll - ok
21:43:02.0297 3136  [ 4BF053944E973C073339BE841C9ECF28 ] C:\Windows\System32\netrap.dll
21:43:02.0297 3136  C:\Windows\System32\netrap.dll - ok
21:43:02.0297 3136  [ D37ED6C2721764E3D08C975DD977A5EE ] C:\Windows\System32\printcom.dll
21:43:02.0297 3136  C:\Windows\System32\printcom.dll - ok
21:43:02.0313 3136  [ EC760B0B76A4353DE49D66520EB2141F ] C:\Windows\System32\SensApi.dll
21:43:02.0313 3136  C:\Windows\System32\SensApi.dll - ok
21:43:02.0313 3136  [ 0F0C15A3D8F98A9CAE53235CDFA9A695 ] C:\Windows\System32\inetpp.dll
21:43:02.0313 3136  C:\Windows\System32\inetpp.dll - ok
21:43:02.0313 3136  [ A4B7D7F3675B7C4490C066A4829CB26D ] C:\Windows\System32\shdocvw.dll
21:43:02.0313 3136  C:\Windows\System32\shdocvw.dll - ok
21:43:02.0328 3136  [ EC4A360BA892320DA05BA504EA7390BC ] C:\Windows\System32\browseui.dll
21:43:02.0328 3136  C:\Windows\System32\browseui.dll - ok
21:43:02.0328 3136  [ 111C47816F39A91EAAA18DA0A54E8E63 ] C:\Windows\System32\imageres.dll
21:43:02.0328 3136  C:\Windows\System32\imageres.dll - ok
21:43:02.0328 3136  [ 08578F3CA5365F896D90CE2BF97FD000 ] C:\Windows\System32\IconCodecService.dll
21:43:02.0328 3136  C:\Windows\System32\IconCodecService.dll - ok
21:43:02.0344 3136  [ 7692F4B242E45870873CAF4CB85CF769 ] C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
21:43:02.0344 3136  C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe - ok
21:43:02.0344 3136  [ B48DC6ABCD3AEFF8618350CCBDC6B09A ] C:\Windows\System32\drivers\npf.sys
21:43:02.0344 3136  C:\Windows\System32\drivers\npf.sys - ok
21:43:02.0344 3136  [ AF5EE37A862936A727A766466A1D4586 ] C:\Windows\System32\taskschd.dll
21:43:02.0344 3136  C:\Windows\System32\taskschd.dll - ok
21:43:02.0359 3136  [ ED627F91528C9829AA1C248ACCD1AC7A ] C:\Windows\System32\wdscore.dll
21:43:02.0359 3136  C:\Windows\System32\wdscore.dll - ok
21:43:02.0359 3136  [ 38CCE934026691EA652C9955BB8AA04A ] C:\Windows\System32\vssapi.dll
21:43:02.0359 3136  C:\Windows\System32\vssapi.dll - ok
21:43:02.0375 3136  [ 6349F6ED9C623B44B52EA3C63C831A92 ] C:\Windows\System32\drivers\PEAuth.sys
21:43:02.0375 3136  C:\Windows\System32\drivers\PEAuth.sys - ok
21:43:02.0375 3136  [ 205E1B699FD3F2F9B036EEA2EC30C620 ] C:\Windows\System32\PnkBstrA.exe
21:43:02.0375 3136  C:\Windows\System32\PnkBstrA.exe - ok
21:43:02.0375 3136  [ 7870FB37A74418E55B0A7DE4776D9E75 ] C:\Windows\System32\wsock32.dll
21:43:02.0375 3136  C:\Windows\System32\wsock32.dll - ok
21:43:02.0391 3136  [ 28B257AE1B63699A3415CBC80E26F7E1 ] C:\Windows\System32\vsstrace.dll
21:43:02.0391 3136  C:\Windows\System32\vsstrace.dll - ok
21:43:02.0391 3136  [ 85508A59E3B0D12D4737184A11C5F8E2 ] C:\Windows\System32\ncsi.dll
21:43:02.0391 3136  C:\Windows\System32\ncsi.dll - ok
21:43:02.0391 3136  [ 90A3935D05B494A5A39D37E71F09A677 ] C:\Windows\System32\drivers\secdrv.sys
21:43:02.0391 3136  C:\Windows\System32\drivers\secdrv.sys - ok
21:43:02.0406 3136  [ 5EBDEC613BD377CE9A85382BE5C6B83B ] C:\Windows\System32\IPSECSVC.DLL
21:43:02.0406 3136  C:\Windows\System32\IPSECSVC.DLL - ok
21:43:02.0406 3136  [ 7C15061CD0372487903B07B9BB03AFAD ] C:\Program Files\Skype\Updater\Updater.exe
21:43:02.0406 3136  C:\Program Files\Skype\Updater\Updater.exe - ok
21:43:02.0406 3136  [ 990B4C7B63E5CCE829F504ADF891103E ] C:\Windows\System32\diagperf.dll
21:43:02.0406 3136  C:\Windows\System32\diagperf.dll - ok
21:43:02.0422 3136  [ A5D1DE63B11448213BF34E14FEA6F117 ] C:\Windows\System32\FwRemoteSvr.dll
21:43:02.0422 3136  C:\Windows\System32\FwRemoteSvr.dll - ok
21:43:02.0422 3136  [ 07472441A6C6F655786A3BCC3EE30F38 ] C:\Windows\System32\pnpts.dll
21:43:02.0422 3136  C:\Windows\System32\pnpts.dll - ok
21:43:02.0422 3136  [ 01BCD91CC2B0EFDA4890F547010750BD ] C:\Windows\System32\ssdpapi.dll
21:43:02.0422 3136  C:\Windows\System32\ssdpapi.dll - ok
21:43:02.0437 3136  [ 5CE0C4A7B12D0067DAD527D72B68C726 ] C:\Windows\System32\drivers\tcpipreg.sys
21:43:02.0437 3136  C:\Windows\System32\drivers\tcpipreg.sys - ok
21:43:02.0453 3136  [ 428FF21418ADCD6FAD6189CD9520A67B ] C:\Windows\System32\wiatrace.dll
21:43:02.0453 3136  C:\Windows\System32\wiatrace.dll - ok
21:43:02.0453 3136  [ 04A677AE406EF88E4AFE0FC0EE3F2908 ] C:\Windows\System32\icaapi.dll
21:43:02.0453 3136  C:\Windows\System32\icaapi.dll - ok
21:43:02.0453 3136  [ D024930AE4DFFCFCE97481A77D485FBB ] C:\Windows\System32\wbem\wbemcomn.dll
21:43:02.0453 3136  C:\Windows\System32\wbem\wbemcomn.dll - ok
21:43:02.0469 3136  [ F806DA1E15896659E3A1E00F3A9FC8BF ] C:\Windows\System32\tquery.dll
21:43:02.0469 3136  C:\Windows\System32\tquery.dll - ok
21:43:02.0469 3136  [ CCAF246004F719F858E841A2BA12C308 ] C:\Windows\System32\wsdchngr.dll
21:43:02.0469 3136  C:\Windows\System32\wsdchngr.dll - ok
21:43:02.0469 3136  [ 1F18B9EA1BBFF033413414C3BEA13AD6 ] C:\Windows\System32\wbem\WinMgmtR.dll
21:43:02.0469 3136  C:\Windows\System32\wbem\WinMgmtR.dll - ok
21:43:02.0484 3136  [ EFF2D358FAD99D865E829C86A72934E3 ] C:\Windows\System32\PortableDeviceApi.dll
21:43:02.0484 3136  C:\Windows\System32\PortableDeviceApi.dll - ok
21:43:02.0484 3136  [ 3D80328AA84D9FE130D869CF83923D74 ] C:\Windows\System32\drivers\WUDFPf.sys
21:43:02.0484 3136  C:\Windows\System32\drivers\WUDFPf.sys - ok
21:43:02.0500 3136  [ A2AAFCC8A204736296D937C7C545B53F ] C:\Windows\System32\drivers\WUDFRd.sys
21:43:02.0500 3136  C:\Windows\System32\drivers\WUDFRd.sys - ok
21:43:02.0500 3136  [ 373BB8D77133CBB854B039F23D474C46 ] C:\Windows\System32\Query.dll
21:43:02.0500 3136  C:\Windows\System32\Query.dll - ok
21:43:02.0500 3136  [ 2F15BE6B5C7F2FF7FE3656F6B1858DE4 ] C:\Windows\System32\msstrc.dll
21:43:02.0500 3136  C:\Windows\System32\msstrc.dll - ok
21:43:02.0515 3136  [ 8D5DE07842A2B50D8B20EA1CD44AC97F ] C:\Windows\System32\WUDFHost.exe
21:43:02.0515 3136  C:\Windows\System32\WUDFHost.exe - ok
21:43:02.0515 3136  [ 43C8CCD4F24A245379116592BEF9E70F ] C:\Windows\System32\mssrch.dll
21:43:02.0515 3136  C:\Windows\System32\mssrch.dll - ok
21:43:02.0515 3136  [ 7C5C3D9CEEE838856B828AB6F98A2857 ] C:\Windows\System32\netprofm.dll
21:43:02.0515 3136  C:\Windows\System32\netprofm.dll - ok
21:43:02.0531 3136  [ 5EB87BA0B93CA7E894FC8002E3CE4C2A ] C:\Windows\System32\sqmapi.dll
21:43:02.0531 3136  C:\Windows\System32\sqmapi.dll - ok
21:43:02.0531 3136  [ 5088C107CEED276FFCE55F8BE549933B ] C:\Windows\System32\rasmontr.dll
21:43:02.0531 3136  C:\Windows\System32\rasmontr.dll - ok
21:43:02.0531 3136  [ DFCAB29E8FD38F95650CC1E203E8D318 ] C:\Windows\System32\npmproxy.dll
21:43:02.0531 3136  C:\Windows\System32\npmproxy.dll - ok
21:43:02.0547 3136  [ 2600A4854B435D3C15A28369CCD0B1F3 ] C:\Windows\System32\mprapi.dll
21:43:02.0547 3136  C:\Windows\System32\mprapi.dll - ok
21:43:02.0547 3136  [ AAA5518DEE99D976A6FE6BE691F64BD0 ] C:\Windows\System32\dbghelp.dll
21:43:02.0547 3136  C:\Windows\System32\dbghelp.dll - ok
21:43:02.0547 3136  [ A1AAC0D6828D2A69A952321AA9950A47 ] C:\Windows\System32\netsh.exe
21:43:02.0547 3136  C:\Windows\System32\netsh.exe - ok
21:43:02.0562 3136  [ 6A82BBD57C2DEDD4FB85DF87C8883243 ] C:\Windows\System32\mfc42u.dll
21:43:02.0562 3136  C:\Windows\System32\mfc42u.dll - ok
21:43:02.0562 3136  [ E28354FEEA5EF4A20A8E4D7FE6EB0297 ] C:\Windows\System32\WUDFx.dll
21:43:02.0562 3136  C:\Windows\System32\WUDFx.dll - ok
21:43:02.0562 3136  [ A5AAD78A599FDD93D87745439FF37DA9 ] C:\Windows\System32\msidle.dll
21:43:02.0562 3136  C:\Windows\System32\msidle.dll - ok
21:43:02.0578 3136  [ 466E13539D9920C5AD84F3132ACF9EF5 ] C:\Windows\System32\drivers\UMDF\WpdFs.dll
21:43:02.0578 3136  C:\Windows\System32\drivers\UMDF\WpdFs.dll - ok
21:43:02.0578 3136  [ 3D9A5347126A306084B858C0C61090F5 ] C:\Windows\System32\odbc32.dll
21:43:02.0578 3136  C:\Windows\System32\odbc32.dll - ok
21:43:02.0593 3136  [ C96A5DBA9FEA24D6C5C4BA77ED851CA7 ] C:\Windows\System32\propdefs.dll
21:43:02.0593 3136  C:\Windows\System32\propdefs.dll - ok
21:43:02.0593 3136  [ 0DAAF8032546D1B4543D7B101B53FD6C ] C:\Windows\System32\odbcint.dll
21:43:02.0593 3136  C:\Windows\System32\odbcint.dll - ok
21:43:02.0593 3136  [ D9AB631DFE5B28815838FC38F632B6C1 ] C:\Windows\System32\WMVCORE.DLL
21:43:02.0593 3136  C:\Windows\System32\WMVCORE.DLL - ok
21:43:02.0609 3136  [ 7818D574CB625D272BABDA8C5338E23A ] C:\Windows\System32\rastapi.dll
21:43:02.0609 3136  C:\Windows\System32\rastapi.dll - ok
21:43:02.0609 3136  [ 254836A3CA138824C1BA0FA544BF2B78 ] C:\Windows\System32\unimdm.tsp
21:43:02.0609 3136  C:\Windows\System32\unimdm.tsp - ok
21:43:02.0609 3136  [ EB6F35234AD9D628184B6AFAD129B23A ] C:\Windows\System32\en-US\tquery.dll.mui
21:43:02.0609 3136  C:\Windows\System32\en-US\tquery.dll.mui - ok
21:43:02.0625 3136  [ 312BA286EB3BE9EAE82DA427ED2C0284 ] C:\Windows\System32\hnetcfg.dll
21:43:02.0625 3136  C:\Windows\System32\hnetcfg.dll - ok
21:43:02.0625 3136  [ DFBAADF1B624DC71E88D34D86B3595BE ] C:\Windows\System32\uniplat.dll
21:43:02.0625 3136  C:\Windows\System32\uniplat.dll - ok
21:43:02.0625 3136  [ B8A559FDF98DD186AB84898E7DD191DC ] C:\Windows\System32\wbem\wbemprox.dll
21:43:02.0625 3136  C:\Windows\System32\wbem\wbemprox.dll - ok
21:43:02.0640 3136  [ 1692212E48CFA7E3B4647ECCE6308B46 ] C:\Windows\System32\esent.dll
21:43:02.0640 3136  C:\Windows\System32\esent.dll - ok
21:43:02.0640 3136  [ 64B7373D5DD4995C57A9AFCE45FE9586 ] C:\Windows\System32\WMASF.DLL
21:43:02.0640 3136  C:\Windows\System32\WMASF.DLL - ok
21:43:02.0640 3136  [ 60C518CC84C7D9887860AAF99C32566D ] C:\Windows\System32\modemui.dll
21:43:02.0640 3136  C:\Windows\System32\modemui.dll - ok
21:43:02.0656 3136  [ 0B71899E60D1265229BF3D080EAB573D ] C:\Windows\System32\unimdmat.dll
21:43:02.0656 3136  C:\Windows\System32\unimdmat.dll - ok
21:43:02.0656 3136  [ 47D89DC720723845900D483C7D80B00F ] C:\Windows\System32\wbem\wbemcore.dll
21:43:02.0656 3136  C:\Windows\System32\wbem\wbemcore.dll - ok
21:43:02.0656 3136  [ 86D4BF98C8F35F45A22723EEB9A05220 ] C:\Windows\System32\PortableDeviceClassExtension.dll
21:43:02.0656 3136  C:\Windows\System32\PortableDeviceClassExtension.dll - ok
21:43:02.0671 3136  [ B4B59AC042EE3733A862F26CBC0B17FC ] C:\Windows\System32\hidphone.tsp
21:43:02.0671 3136  C:\Windows\System32\hidphone.tsp - ok
21:43:02.0671 3136  [ E051555F2157272CDEC7EAE174692770 ] C:\Windows\System32\kmddsp.tsp
21:43:02.0671 3136  C:\Windows\System32\kmddsp.tsp - ok
21:43:02.0687 3136  [ 1FDFC86E6EFFC8CFEE05105A1B757D54 ] C:\Windows\System32\ndptsp.tsp
21:43:02.0687 3136  C:\Windows\System32\ndptsp.tsp - ok
21:43:02.0687 3136  [ C3BAC3F95F2FB22BA903928B68B107CC ] C:\Windows\System32\wbem\esscli.dll
21:43:02.0687 3136  C:\Windows\System32\wbem\esscli.dll - ok
21:43:02.0687 3136  [ 4D767749DD84B170D52D3E15D24BB4E3 ] C:\Windows\System32\PortableDeviceTypes.dll
21:43:02.0687 3136  C:\Windows\System32\PortableDeviceTypes.dll - ok
21:43:02.0703 3136  [ E046D89F1872801602DFE94E97F7409E ] C:\Windows\System32\msscb.dll
21:43:02.0703 3136  C:\Windows\System32\msscb.dll - ok
21:43:02.0703 3136  [ 798FD364677DA5278266102371B96F4B ] C:\Windows\System32\wbem\fastprox.dll
21:43:02.0703 3136  C:\Windows\System32\wbem\fastprox.dll - ok
21:43:02.0703 3136  [ 4297615D968B294D8E95270EA7FC6A65 ] C:\Windows\System32\wbem\wbemsvc.dll
21:43:02.0703 3136  C:\Windows\System32\wbem\wbemsvc.dll - ok
21:43:02.0718 3136  [ 0F751202DD25E725CB9556A8A1257B9B ] C:\Windows\System32\wbem\wmiutils.dll
21:43:02.0718 3136  C:\Windows\System32\wbem\wmiutils.dll - ok
21:43:02.0718 3136  [ 81294812D4D6884CA4E2DEB5E0747D48 ] C:\Windows\System32\rasppp.dll
21:43:02.0718 3136  C:\Windows\System32\rasppp.dll - ok
21:43:02.0718 3136  [ CCA209EB7B096D2BAB66A4DBD500C088 ] C:\Windows\System32\wbem\repdrvfs.dll
21:43:02.0718 3136  C:\Windows\System32\wbem\repdrvfs.dll - ok
21:43:02.0734 3136  [ 7C206778460F2ED59E81474A197458A7 ] C:\Windows\System32\cryptui.dll
21:43:02.0734 3136  C:\Windows\System32\cryptui.dll - ok
21:43:02.0734 3136  [ 409F5D96AD20EFABDFA9C8FA52A2D69B ] C:\Windows\System32\QUTIL.DLL
21:43:02.0734 3136  C:\Windows\System32\QUTIL.DLL - ok
21:43:02.0734 3136  [ 1CA27B5452B59AD895888D51C7C38E59 ] C:\Windows\System32\rasqec.dll
21:43:02.0734 3136  C:\Windows\System32\rasqec.dll - ok
21:43:02.0749 3136  [ E6E2DA076B902C99E40BD202A2936949 ] C:\Windows\System32\wbem\WmiPrvSD.dll
21:43:02.0749 3136  C:\Windows\System32\wbem\WmiPrvSD.dll - ok
21:43:02.0749 3136  [ F4FF57BE16BED8A8BD45D0DB14E6125D ] C:\Windows\System32\netshell.dll
21:43:02.0749 3136  C:\Windows\System32\netshell.dll - ok
21:43:02.0749 3136  [ BD1D1FD2AC8579F94D97D976D498BECA ] C:\Windows\System32\wbem\wbemess.dll
21:43:02.0749 3136  C:\Windows\System32\wbem\wbemess.dll - ok
21:43:02.0765 3136  [ 0C9AA5E9B25C32643565352ABA5F95CF ] C:\Program Files\Alcohol Soft\Alcohol 120\Alcoholx.dll
21:43:02.0765 3136  C:\Program Files\Alcohol Soft\Alcohol 120\Alcoholx.dll - ok
21:43:02.0765 3136  [ 4DE1EBB2314E2F10AC9EC83138193F8B ] C:\Program Files\Alcohol Soft\Alcohol 120\imgengine.dll
21:43:02.0765 3136  C:\Program Files\Alcohol Soft\Alcohol 120\imgengine.dll - ok
21:43:02.0781 3136  [ 930349946FF183F06FC78351E11B7A9A ] C:\Windows\System32\cfgmgr32.dll
21:43:02.0781 3136  C:\Windows\System32\cfgmgr32.dll - ok
21:43:02.0781 3136  [ DF0A32CC2F2AF3C88A5C7FC426FF8FBC ] C:\Windows\System32\lsmproxy.dll
21:43:02.0781 3136  C:\Windows\System32\lsmproxy.dll - ok
21:43:02.0781 3136  [ 4DDF005065B3A1E25C9A69801C306D1E ] C:\Windows\System32\dimsjob.dll
21:43:02.0781 3136  C:\Windows\System32\dimsjob.dll - ok
21:43:02.0796 3136  [ 0066EB51C3E53E026D5CC65422809341 ] C:\Windows\System32\pcadm.dll
21:43:02.0796 3136  C:\Windows\System32\pcadm.dll - ok
21:43:02.0796 3136  [ B08A1FEEEA9BB6475C03203DCF470691 ] C:\Windows\System32\certcli.dll
21:43:02.0796 3136  C:\Windows\System32\certcli.dll - ok
21:43:02.0796 3136  [ 98638A4CA187245C469DA0DEC4F04A45 ] C:\Windows\System32\pautoenr.dll
21:43:02.0796 3136  C:\Windows\System32\pautoenr.dll - ok
21:43:02.0812 3136  [ 2D547CFD0C798EE94AC56300D6176AC1 ] C:\Windows\System32\regapi.dll
21:43:02.0812 3136  C:\Windows\System32\regapi.dll - ok
21:43:02.0812 3136  [ AE0038B9CAF5DF6043C099C7871A0F99 ] C:\Windows\System32\mstlsapi.dll
21:43:02.0812 3136  C:\Windows\System32\mstlsapi.dll - ok
21:43:02.0812 3136  [ 5B5B284354E02E81FFED24FFB0DF3204 ] C:\Windows\System32\rdpwsx.dll
21:43:02.0812 3136  C:\Windows\System32\rdpwsx.dll - ok
21:43:02.0827 3136  [ B1D4F4B30A7C4F32062C957EC3FBED8E ] C:\Windows\System32\CertEnroll.dll
21:43:02.0827 3136  C:\Windows\System32\CertEnroll.dll - ok
21:43:02.0827 3136  [ F41F8B01EEDF74B99C06B0BE2D002AA9 ] C:\Windows\System32\TMM.dll
21:43:02.0827 3136  C:\Windows\System32\TMM.dll - ok
21:43:02.0827 3136  [ 7D2C1AE1648A60FCE4AA0F7982E419D3 ] C:\Windows\System32\drivers\tdtcp.sys
21:43:02.0827 3136  C:\Windows\System32\drivers\tdtcp.sys - ok
21:43:02.0843 3136  [ 29F0ECA726F0D51F7E048BDB0B372F29 ] C:\Windows\System32\drivers\tssecsrv.sys
21:43:02.0843 3136  C:\Windows\System32\drivers\tssecsrv.sys - ok
21:43:02.0843 3136  [ 8830E790A74A96605FABA74F9665BB3C ] C:\Windows\System32\drivers\rdpwd.sys
21:43:02.0843 3136  C:\Windows\System32\drivers\rdpwd.sys - ok
21:43:02.0859 3136  [ 0F04702C1599E632EB9C6E5AA7352F77 ] C:\Windows\System32\MsCtfMonitor.dll
21:43:02.0859 3136  C:\Windows\System32\MsCtfMonitor.dll - ok
21:43:02.0859 3136  [ AD306E253C5593B55564AE4B3BA5FEBA ] C:\Windows\System32\msutb.dll
21:43:02.0859 3136  C:\Windows\System32\msutb.dll - ok
21:43:02.0859 3136  [ D4C7C8129B2EDCF1AF96A643A11ED5EE ] C:\Windows\System32\igfxTMM.dll
21:43:02.0859 3136  C:\Windows\System32\igfxTMM.dll - ok
21:43:02.0859 3136  [ 56DE7AEB7435FEE1EDB8A83030026884 ] C:\Windows\System32\QAGENT.DLL
21:43:02.0859 3136  C:\Windows\System32\QAGENT.DLL - ok
21:43:02.0874 3136  [ D24CEF0216E5AED59AFF4BA11F37274E ] C:\Windows\System32\runonce.exe
21:43:02.0874 3136  C:\Windows\System32\runonce.exe - ok
21:43:02.0874 3136  [ 349CD4318E6E351C9BB72EE13B7CA807 ] C:\Windows\System32\cmd.exe
21:43:02.0874 3136  C:\Windows\System32\cmd.exe - ok
21:43:02.0890 3136  [ 096C5E4BD9AC53EEDE744609ADC8C5B7 ] C:\Windows\System32\ieframe.dll
21:43:02.0890 3136  C:\Windows\System32\ieframe.dll - ok
21:43:02.0890 3136  [ 91B7EC5F0FE04566782075171BF94A86 ] C:\Windows\System32\p2pcollab.dll
21:43:02.0890 3136  C:\Windows\System32\p2pcollab.dll - ok
21:43:02.0890 3136  [ D351DFCAF085B4771580E3F256F8F6E0 ] C:\Windows\System32\cryptnet.dll
21:43:02.0890 3136  C:\Windows\System32\cryptnet.dll - ok
21:43:02.0905 3136  [ 9E816AEEDB04745C3F3D74DDE90BD79A ] C:\Windows\System32\igfxdev.dll
21:43:02.0905 3136  C:\Windows\System32\igfxdev.dll - ok
21:43:02.0905 3136  [ CD4654BA4F1264532033B1E34DDABE14 ] C:\Windows\System32\PresentationSettings.exe
21:43:02.0905 3136  C:\Windows\System32\PresentationSettings.exe - ok
21:43:02.0905 3136  [ 178A34E5554DCE485E1262DDF027960C ] C:\Users\Ruler\AppData\Local\temp\AA09C926-D3D0-4BC6-A21B-6E9E053B390F.exe
21:43:02.0905 3136  C:\Users\Ruler\AppData\Local\temp\AA09C926-D3D0-4BC6-A21B-6E9E053B390F.exe - ok
21:43:02.0921 3136  [ 4DB158BC772FD434036487DCB7825625 ] C:\Windows\System32\sfc_os.dll
21:43:02.0921 3136  C:\Windows\System32\sfc_os.dll - ok
21:43:02.0921 3136  [ BA174723B7998BC2332D657DE720A9D3 ] C:\Windows\System32\timedate.cpl
21:43:02.0921 3136  C:\Windows\System32\timedate.cpl - ok
21:43:02.0921 3136  [ 7812ED1E5F39F057C725ED9EFAE19529 ] C:\Windows\System32\actxprxy.dll
21:43:02.0921 3136  C:\Windows\System32\actxprxy.dll - ok
21:43:02.0937 3136  [ B9D6F987566F13E99E10AE0E0C680A2B ] C:\Windows\System32\msshsq.dll
21:43:02.0937 3136  C:\Windows\System32\msshsq.dll - ok
21:43:02.0937 3136  [ AB26EB32F91D3F04E14101B62EB47589 ] C:\Windows\System32\NaturalLanguage6.dll
21:43:02.0937 3136  C:\Windows\System32\NaturalLanguage6.dll - ok
21:43:02.0937 3136  [ 29ADC97527E30540944F1735B2795C3D ] C:\Windows\System32\NlsData0009.dll
21:43:02.0937 3136  C:\Windows\System32\NlsData0009.dll - ok
21:43:02.0952 3136  [ FD7B6F48B20D9A29D5811BA50051509A ] C:\Windows\System32\NlsLexicons0009.dll
21:43:02.0952 3136  C:\Windows\System32\NlsLexicons0009.dll - ok
21:43:02.0952 3136  [ 24F90AEFEBE601D427CB4511E74CDCB6 ] C:\Windows\System32\linkinfo.dll
21:43:02.0952 3136  C:\Windows\System32\linkinfo.dll - ok
21:43:02.0952 3136  [ 810AE8B27B91240252D7223A536BB95E ] C:\Windows\System32\networkexplorer.dll
21:43:02.0952 3136  C:\Windows\System32\networkexplorer.dll - ok
21:43:02.0968 3136  [ F61200A4B3E6E781DE8B5653517566D7 ] C:\Windows\System32\igfxtray.exe
21:43:02.0968 3136  C:\Windows\System32\igfxtray.exe - ok
21:43:02.0968 3136  [ B669ADB56ABE22BA2B69A96D6CEE8508 ] C:\Windows\System32\hccutils.dll
21:43:02.0968 3136  C:\Windows\System32\hccutils.dll - ok
21:43:02.0968 3136  [ EB7F7F7DBA47FDC1E2FA386B00DA0F90 ] C:\Windows\System32\hkcmd.exe
21:43:02.0968 3136  C:\Windows\System32\hkcmd.exe - ok
21:43:02.0983 3136  [ 8EF0123B03F1DDD8A618EB1D0BA71F54 ] C:\Windows\System32\igfxpers.exe
21:43:02.0983 3136  C:\Windows\System32\igfxpers.exe - ok
21:43:02.0983 3136  [ A702A2ED07645100C2CAD8E0ADB87E9D ] C:\Windows\System32\thumbcache.dll
21:43:02.0983 3136  C:\Windows\System32\thumbcache.dll - ok
21:43:02.0983 3136  [ 6C887E9BA3AE7F62635F098BFC9853CD ] C:\Windows\RtHDVCpl.exe
21:43:02.0983 3136  C:\Windows\RtHDVCpl.exe - ok
21:43:02.0999 3136  [ C8612E58FB7FCFA5EEA4E39F7B8CBC17 ] C:\Windows\SkyTel.exe
21:43:02.0999 3136  C:\Windows\SkyTel.exe - ok
21:43:02.0999 3136  [ 7CE0BEB1DA5628C128EB8782A6FE1747 ] C:\Windows\System32\igfxsrvc.exe
21:43:02.0999 3136  C:\Windows\System32\igfxsrvc.exe - ok
21:43:02.0999 3136  [ 720C8EE22B359ED438BDA19F6F603345 ] C:\Windows\System32\igfxsrvc.dll
21:43:02.0999 3136  C:\Windows\System32\igfxsrvc.dll - ok
21:43:03.0015 3136  [ 13CC964E280C9A15636ACBE5C4E5A575 ] C:\Windows\System32\igfxrenu.lrc
21:43:03.0015 3136  C:\Windows\System32\igfxrenu.lrc - ok
21:43:03.0015 3136  [ D87D76A514D99E70D122CD96EADC5353 ] C:\Windows\System32\igfxress.dll
21:43:03.0015 3136  C:\Windows\System32\igfxress.dll - ok
21:43:03.0015 3136  [ 05145613C47BF084976C2C762CD19A61 ] C:\Windows\System32\ntshrui.dll
21:43:03.0015 3136  C:\Windows\System32\ntshrui.dll - ok
21:43:03.0030 3136  [ 68AC082734363E6BA813E7EAA353DB13 ] C:\Windows\System32\dsound.dll
21:43:03.0030 3136  C:\Windows\System32\dsound.dll - ok
21:43:03.0030 3136  [ 6E240D6C2F0DB74BED13AD723D3AB0A1 ] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
21:43:03.0030 3136  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe - ok
21:43:03.0046 3136  [ D7787D202FB15B2AE6B08A1AF57F91DD ] C:\Windows\System32\cscapi.dll
21:43:03.0046 3136  C:\Windows\System32\cscapi.dll - ok
21:43:03.0046 3136  [ 5607B5FBA62A238D68CD1B5B0383728C ] C:\Windows\System32\oledlg.dll
21:43:03.0046 3136  C:\Windows\System32\oledlg.dll - ok
21:43:03.0046 3136  [ B55E77BB01E85D2CA2C4B8424E1DF345 ] C:\Windows\System32\opengl32.dll
21:43:03.0046 3136  C:\Windows\System32\opengl32.dll - ok
21:43:03.0061 3136  [ 195D45D59E8366E1C3634F67A9E6AAF6 ] C:\Program Files\AGEIA Technologies\TrayIcon.exe
21:43:03.0061 3136  C:\Program Files\AGEIA Technologies\TrayIcon.exe - ok
21:43:03.0061 3136  [ 7A137514F4E48ECDBDD1F29CF7E8D5A4 ] C:\Windows\System32\glu32.dll
21:43:03.0061 3136  C:\Windows\System32\glu32.dll - ok
21:43:03.0061 3136  [ D517ACAF8252713960AA0E0BB41614D1 ] C:\Windows\System32\ExplorerFrame.dll
21:43:03.0061 3136  C:\Windows\System32\ExplorerFrame.dll - ok
21:43:03.0077 3136  [ 561FA2ABB31DFA8FAB762145F81667C2 ] C:\Program Files\AGEIA Technologies\msvcp71.dll
21:43:03.0077 3136  C:\Program Files\AGEIA Technologies\msvcp71.dll - ok
21:43:03.0077 3136  [ 29EF7A2EE634DD701571E781DE5E7E91 ] C:\Windows\System32\ddraw.dll
21:43:03.0077 3136  C:\Windows\System32\ddraw.dll - ok
21:43:03.0077 3136  [ 82ABE656D4CAAB9FA69C601D988D23BE ] C:\Windows\System32\dciman32.dll
21:43:03.0077 3136  C:\Windows\System32\dciman32.dll - ok
21:43:03.0093 3136  [ 390951D528C971215AC220BA12F60DEC ] C:\Windows\System32\SynCOM.dll
21:43:03.0093 3136  C:\Windows\System32\SynCOM.dll - ok
21:43:03.0093 3136  [ 027E5E14C9CFF810377701BDEAD8210F ] C:\Windows\System32\control.exe
21:43:03.0093 3136  C:\Windows\System32\control.exe - ok
21:43:03.0093 3136  [ 86F1895AE8C5E8B17D99ECE768A70732 ] C:\Program Files\AGEIA Technologies\msvcr71.dll
21:43:03.0093 3136  C:\Program Files\AGEIA Technologies\msvcr71.dll - ok
21:43:03.0108 3136  [ 9F8C33181A3A38666C68A1FFC744D8A0 ] C:\Users\Ruler\jagexcache\jagexlauncher\bin\JagexLauncher.exe
21:43:03.0108 3136  C:\Users\Ruler\jagexcache\jagexlauncher\bin\JagexLauncher.exe - ok
21:43:03.0108 3136  [ 1EDEB2982D305451E689755DC4BCB7A2 ] C:\Program Files\Windows Calendar\WinCal.exe
21:43:03.0108 3136  C:\Program Files\Windows Calendar\WinCal.exe - ok
21:43:03.0108 3136  [ 02EA06DD2318BC0EAEAE17206D052A44 ] C:\Program Files\Windows Mail\wab.exe
21:43:03.0108 3136  C:\Program Files\Windows Mail\wab.exe - ok
21:43:03.0124 3136  [ 7E9F9A33C7266E5D28B301ECED6888A2 ] C:\Program Files\Movie Maker\DVDMaker.exe
21:43:03.0124 3136  C:\Program Files\Movie Maker\DVDMaker.exe - ok
21:43:03.0124 3136  [ DE7F813217EC88C0A6D4D8F2F39D7949 ] C:\Windows\System32\msiltcfg.dll
21:43:03.0124 3136  C:\Windows\System32\msiltcfg.dll - ok
21:43:03.0124 3136  [ 29A9F4BED779981EFEF1F0722C78640B ] C:\Windows\System32\msi.dll
21:43:03.0124 3136  C:\Windows\System32\msi.dll - ok
21:43:03.0139 3136  [ 2A8681AEA24003040CA7D677BE9F1702 ] C:\Windows\System32\drivers\81513518.sys
21:43:03.0139 3136  C:\Windows\System32\drivers\81513518.sys - ok
21:43:03.0139 3136  [ B7ED332A57FC78CA29E40D3619550225 ] C:\Windows\ehome\ehshell.exe
21:43:03.0139 3136  C:\Windows\ehome\ehshell.exe - ok
21:43:03.0155 3136  [ 9C2A1150A2902C503D092614E44A202A ] C:\Program Files\Windows Collaboration\WinCollab.exe
21:43:03.0155 3136  C:\Program Files\Windows Collaboration\WinCollab.exe - ok
21:43:03.0155 3136  [ 77CCB4074CC32BF68CED66A90B865C8B ] C:\Program Files\Movie Maker\MOVIEMK.exe
21:43:03.0155 3136  C:\Program Files\Movie Maker\MOVIEMK.exe - ok
21:43:03.0155 3136  [ C03AC1FBCD625F93D2C245D97E06F270 ] C:\Program Files\Windows Photo Gallery\WindowsPhotoGallery.exe
21:43:03.0155 3136  C:\Program Files\Windows Photo Gallery\WindowsPhotoGallery.exe - ok
21:43:03.0171 3136  [ 8870208FCB90E11960D45ECC994D268F ] C:\Windows\System32\wuapp.exe
21:43:03.0171 3136  C:\Windows\System32\wuapp.exe - ok
21:43:03.0171 3136  [ 4FF455520B17D15E9191C5BC7D8148FE ] C:\Windows\System32\riched20.dll
21:43:03.0171 3136  C:\Windows\System32\riched20.dll - ok
21:43:03.0171 3136  [ 9253C752DC9B5CEEAA7747E165B75EEB ] C:\Windows\System32\stobject.dll
21:43:03.0171 3136  C:\Windows\System32\stobject.dll - ok
21:43:03.0186 3136  [ EC69B16644C613F41A57169F8D068F1D ] C:\Windows\System32\batmeter.dll
21:43:03.0186 3136  C:\Windows\System32\batmeter.dll - ok
21:43:03.0186 3136  [ 30F02D9C55053367E26A11482F51E255 ] C:\Windows\System32\SndVolSSO.dll
21:43:03.0186 3136  C:\Windows\System32\SndVolSSO.dll - ok
21:43:03.0186 3136  [ AA83361E1505A5AEC46FA0A2AAF18181 ] C:\Windows\ehome\ehSSO.dll
21:43:03.0186 3136  C:\Windows\ehome\ehSSO.dll - ok
21:43:03.0202 3136  [ BE37415BBEB27A0797088868C498ED54 ] C:\Windows\System32\pnidui.dll
21:43:03.0202 3136  C:\Windows\System32\pnidui.dll - ok
21:43:03.0202 3136  [ DA20A42F514ADDD91F0E4D1533CB6AA0 ] C:\Windows\System32\rasdlg.dll
21:43:03.0202 3136  C:\Windows\System32\rasdlg.dll - ok
21:43:03.0202 3136  [ AB2FDF76CD9D5906710150461967DD3E ] C:\Windows\System32\wlanapi.dll
21:43:03.0202 3136  C:\Windows\System32\wlanapi.dll - ok
21:43:03.0217 3136  [ 4A839160ED1963F9A1526DDA2D1233B2 ] C:\Windows\System32\AltTab.dll
21:43:03.0217 3136  C:\Windows\System32\AltTab.dll - ok
21:43:03.0217 3136  [ DE55F0A8D2F7DF728E796509C846A17E ] C:\Windows\System32\WPDShServiceObj.dll
21:43:03.0217 3136  C:\Windows\System32\WPDShServiceObj.dll - ok
21:43:03.0217 3136  [ EDF5249A8DC8B453D54033E6A98807BF ] C:\Windows\System32\srchadmin.dll
21:43:03.0217 3136  C:\Windows\System32\srchadmin.dll - ok
21:43:03.0233 3136  [ 4FD45F2A2C445359482CA3F34EAB1A4D ] C:\Windows\System32\webcheck.dll
21:43:03.0233 3136  C:\Windows\System32\webcheck.dll - ok
21:43:03.0233 3136  [ 78F9800FA0E89DA51747AEEAC8B422DB ] C:\Windows\System32\SyncCenter.dll
21:43:03.0233 3136  C:\Windows\System32\SyncCenter.dll - ok
21:43:03.0233 3136  [ B3EAFDBF7DECF6BC290F98761D26A366 ] C:\Windows\System32\mssprxy.dll
21:43:03.0233 3136  C:\Windows\System32\mssprxy.dll - ok
21:43:03.0249 3136  [ 57201DFB464DF1E1AB47BAB1B2AE66B7 ] C:\Windows\System32\wscntfy.dll
21:43:03.0249 3136  C:\Windows\System32\wscntfy.dll - ok
21:43:03.0249 3136  [ 8149E826AAFA94823D3EFC0674CF7FA1 ] C:\Windows\System32\wscapi.dll
21:43:03.0249 3136  C:\Windows\System32\wscapi.dll - ok
21:43:03.0249 3136  [ 6C3A437FC873C6F6A4FC620B6888CB86 ] C:\Windows\System32\drivers\cdfs.sys
21:43:03.0249 3136  C:\Windows\System32\drivers\cdfs.sys - ok
21:43:03.0264 3136  [ 6E30D310BC7D1684B1CE7407F9A1638D ] C:\Windows\System32\imapi2.dll
21:43:03.0264 3136  C:\Windows\System32\imapi2.dll - ok
21:43:03.0264 3136  [ B41DD8277022E22CE64BDD97F248D29C ] C:\Windows\System32\upnp.dll
21:43:03.0264 3136  C:\Windows\System32\upnp.dll - ok
21:43:03.0264 3136  ============================================================
21:43:03.0264 3136  Scan finished
21:43:03.0264 3136  ============================================================
21:43:03.0280 3128  Detected object count: 2
21:43:03.0280 3128  Actual detected object count: 2
21:43:19.0379 3128  FreemakeVideoCapture ( UnsignedFile.Multi.Generic ) - skipped by user
21:43:19.0379 3128  FreemakeVideoCapture ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:43:19.0379 3128  giveio ( UnsignedFile.Multi.Generic ) - skipped by user
21:43:19.0379 3128  giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
 



#5 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 24 June 2013 - 06:29 PM

Hello again,
 

Hi bloopie, thankyou for taking the time to help me.

It's my pleasure.
 
Just for kicks, when you're unsure of a file you can always upload it to Virustotal to have many AV programs check it for you and then see the outcome.

  • Go to VirusTotal.com
  • Click the "Choose File" button.
  • Navigate to the file of your choice and click Open.
  • Click the "Scan It" button (***Note: If it says this file has already been scanned, please click "Reanalyze").
  • When it is finished scanning please provide a link to the results page in your next reply.

Feel free to check atapi.sys from Virustotal and let me know the findings.

==========

Now, lets get a log from another tool so we can have another look:

Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

==========

Please post the Virustotal results and the FRST log in your next reply.

bloopie



#6 dralon

dralon
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:54 AM

Posted 25 June 2013 - 12:08 PM

Virustotal, one of my favorite sites when dealing with suspicious files. :)

Here is the reanalyzed file. https://www.virustotal.com/en/file/6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896/analysis/1372178710/

The Synaptics error in Addition.txt was caused by me replacing the kbdclass driver I believe, although I replaced several others at the time. I figured I could just uninstall device and then scan for hardware changes, however I've done that several times and it refuses to install correctly as you will see in the logs. Keyboard and mouse are fine, and I don't use the touchpad anyways so I'm ok for now, but eventually I'll have to fix it.

Here is the log.

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-06-2013 01
Ran by Ruler (administrator) on 25-06-2013 09:49:26
Running from C:\Users\Ruler\Desktop
Microsoft® Windows Vista™ Home Premium  (X86) OS Language: English(US)
Internet Explorer Version 7
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
() C:\Program Files\AGEIA Technologies\TrayIcon.exe
(Intel Corporation) C:\Windows\system32\igfxsrvc.exe
() C:\Windows\system32\PnkBstrA.exe
(Microsoft Corporation) C:\Windows\System32\mobsync.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] RtHDVCpl.exe [x]
HKLM\...\Run: [Skytel] Skytel.exe [x]
HKLM\...\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1348904 2008-08-14] (Synaptics, Inc.)
HKLM\...\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe [331776 2006-03-20] ()
HKCU\...\Policies\system: [disableregistrytools] 0

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO: Freemake.YoutubeButton - {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} - C:\Windows\System32\mscoree.dll (Microsoft Corporation)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: intu-tt2012 - {02F985EF-502B-4597-993F-6BF9E004C138} - C:\Program Files\TurboTax 2012\ic2012pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 64.251.68.9 64.141.73.187

FireFox:
========
FF ProfilePath: C:\Users\Ruler\AppData\Roaming\Mozilla\Firefox\Profiles\8zj0ps33.default
FF Homepage: hxxp://www.google.com/
FF NetworkProxy: "backup.ftp", "42.117.1.77"
FF NetworkProxy: "backup.ftp_port", 3128
FF NetworkProxy: "backup.socks", "42.117.1.77"
FF NetworkProxy: "backup.socks_port", 3128
FF NetworkProxy: "backup.ssl", "42.117.1.77"
FF NetworkProxy: "backup.ssl_port", 3128
FF NetworkProxy: "ftp", "218.108.168.165"
FF NetworkProxy: "ftp_port", 80
FF NetworkProxy: "http", "218.108.168.165"
FF NetworkProxy: "http_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "218.108.168.165"
FF NetworkProxy: "socks_port", 80
FF NetworkProxy: "ssl", "218.108.168.165"
FF NetworkProxy: "ssl_port", 80
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=10.21.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.21.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @nexon.net/NxGame - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF Plugin: @pandonetworks.com/PandoWebPlugin - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Extension: Battlefield Play4Free - C:\Users\Ruler\AppData\Roaming\Mozilla\Firefox\Profiles\8zj0ps33.default\Extensions\battlefieldplay4free@ea.com
FF Extension: No Name - C:\Users\Ruler\AppData\Roaming\Mozilla\Firefox\Profiles\8zj0ps33.default\Extensions\{7CA9CF31-1C73-46CD-8377-85AB71EA771F}.xpi
FF Extension: No Name - C:\Users\Ruler\AppData\Roaming\Mozilla\Firefox\Profiles\8zj0ps33.default\Extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}.xpi
FF Extension: No Name - C:\Users\Ruler\AppData\Roaming\Mozilla\Firefox\Profiles\8zj0ps33.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\24.0.1312.56\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\24.0.1312.56\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java™ Platform SE 7 U11) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (Pando Web Plugin) - C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Nexon Game Controller) - C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
CHR Plugin: (RockMelt Update) - C:\Users\Ruler\AppData\Local\RockMelt\Update\1.2.189.1\npRockMeltOneClick8.dll No File
CHR Plugin: (Windows Presentation Foundation) - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File
CHR Plugin: (Java Deployment Toolkit 7.0.110.21) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
CHR Extension: (YouTube) - C:\Users\Ruler\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_1
CHR Extension: (Freemake Video Downloader) - C:\Users\Ruler\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0
CHR Extension: (Adblock Plus) - C:\Users\Ruler\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0
CHR Extension: (Google Search) - C:\Users\Ruler\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Freemake Youtube Download Button) - C:\Users\Ruler\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0
CHR Extension: (Gmail) - C:\Users\Ruler\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1

========================== Services (Whitelisted) =================

S2 AxAutoMntSrv; C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [75624 2012-01-05] (Alcohol Soft Development Team)
S4 FreemakeVideoCapture; C:\Program Files\Freemake\CaptureLib\CaptureLibService.exe [9216 2013-05-14] (Ellora Assets Corp.)
S3 npggsvc; C:\Windows\system32\GameMon.des [4703728 2012-11-15] (INCA Internet Co., Ltd.)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2013-06-24] ()

==================== Drivers (Whitelisted) ====================

R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [121248 2012-08-26] (SlySoft, Inc.)
R1 ElbyCDIO; C:\Windows\System32\Drivers\ElbyCDIO.sys [31088 2010-12-16] (Elaborate Bytes AG)
R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] ()
R2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.)
R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [15672 2010-11-26] ()
R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software)
S4 sptd; C:\Windows\System32\Drivers\sptd.sys [477240 2013-01-16] (Duplex Secure Ltd.)
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 catchme; \??\C:\Users\Ruler\AppData\Local\Temp\catchme.sys [x]
S3 DarkSpy; \??\C:\Windows\system32\DarkSpyKernel.sys [x]
S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
S3 rkhdrv40; No ImagePath

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-06-25 09:48 - 2013-06-25 09:48 - 01370263 ____A (Farbar) C:\Users\Ruler\Desktop\FRST.exe
2013-06-25 09:48 - 2013-06-25 09:48 - 00000000 ____D C:\FRST
2013-06-24 15:47 - 2013-06-24 20:11 - 00000000 ____D C:\Users\Ruler\AppData\Local\Deployment
2013-06-24 15:47 - 2013-06-24 15:47 - 00000332 ____A C:\Users\Ruler\Desktop\Ghost Recon Online (EU).appref-ms
2013-06-24 15:47 - 2013-06-24 15:47 - 00000000 ____D C:\Users\Ruler\AppData\Local\Apps\2.0
2013-06-20 17:49 - 2013-06-20 17:49 - 00000000 ____D C:\Users\Ruler\Documents\TurboTax
2013-06-20 15:32 - 2013-06-20 15:32 - 00000000 ____D C:\Users\Ruler\AppData\Roaming\Intuit Canada
2013-06-20 15:31 - 2013-06-20 15:32 - 00000000 ____D C:\Program Files\TurboTax 2012
2013-06-20 15:31 - 2013-06-20 15:31 - 00001773 ____A C:\Users\Public\Desktop\TurboTax Canada 2012.lnk
2013-06-20 15:31 - 2013-06-20 15:31 - 00000000 ____D C:\ProgramData\Intuit Canada
2013-06-20 15:31 - 2013-06-20 15:31 - 00000000 ____D C:\Program Files\Common Files\Intuit
2013-06-15 18:25 - 2013-06-15 18:25 - 00000020 ____A C:\Users\Ruler\defogger_reenable
2013-06-14 11:52 - 2013-06-14 11:58 - 00000000 ____D C:\Program Files\Uplink
2013-06-14 11:51 - 2013-06-14 11:51 - 00000000 _RASH C:\MSDOS.SYS
2013-06-14 11:51 - 2013-06-14 11:51 - 00000000 _RASH C:\IO.SYS
2013-06-14 11:51 - 1997-11-19 15:49 - 00303616 ____A (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2013-06-13 22:23 - 2013-06-13 22:23 - 00000297 ____A C:\Windows\System32\userawacs.cfg
2013-06-13 22:21 - 2013-06-13 22:21 - 00000000 ____D C:\Windows\System32\%systemroot%
2013-06-13 22:20 - 2013-06-13 22:20 - 00000000 ____D C:\Program Files\AVG
2013-06-13 21:06 - 2013-06-13 21:07 - 00000000 ___SD C:\32788R22FWJFW
2013-06-13 18:58 - 2013-06-13 18:58 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2013-06-13 18:58 - 2013-06-13 18:58 - 00000000 ____D C:\users\Administrator
2013-06-09 22:14 - 2013-06-09 22:15 - 00138816 ____A C:\Windows\Minidump\Mini060913-03.dmp
2013-06-09 21:56 - 2013-06-09 21:56 - 00138816 ____A C:\Windows\Minidump\Mini060913-02.dmp
2013-06-09 21:51 - 2013-06-09 21:51 - 00000000 ____D C:\RkUnhooker
2013-06-09 21:26 - 2013-06-09 21:49 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-09 20:26 - 2013-06-09 20:26 - 00000000 ____A C:\Windows\System32\settings.dat
2013-06-09 13:37 - 2013-06-09 13:37 - 00008202 ____A C:\ComboFix.txt
2013-06-09 13:26 - 2013-06-13 20:57 - 00000000 ____D C:\Qoobox
2013-06-09 13:26 - 2013-06-09 13:36 - 00000000 ____D C:\Windows\erdnt
2013-06-09 10:57 - 2013-06-09 10:57 - 00000000 ____D C:\ProgramData\Sophos
2013-06-09 10:51 - 2013-06-09 10:51 - 00002038 ____A C:\Users\Ruler\Desktop\Sophos Virus Removal Tool.lnk
2013-06-09 10:51 - 2013-06-09 10:51 - 00000000 ____D C:\Program Files\Sophos
2013-06-09 10:13 - 2013-06-09 10:13 - 00001429 ____A C:\Users\Ruler\Desktop\JRT.txt
2013-06-09 10:10 - 2013-06-09 10:10 - 00000000 ____D C:\Windows\ERUNT
2013-06-09 10:10 - 2013-06-09 10:10 - 00000000 ____D C:\JRT
2013-06-09 10:09 - 2013-06-09 10:09 - 00001140 ____A C:\AdwCleaner[R1].txt
2013-06-09 10:04 - 2013-06-09 10:04 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-06-09 09:46 - 2013-06-09 22:14 - 00000000 ____D C:\Windows\Minidump
2013-06-09 09:46 - 2013-06-09 09:46 - 00138816 ____A C:\Windows\Minidump\Mini060913-01.dmp
2013-06-09 09:45 - 2013-06-09 22:14 - 285317279 ____A C:\Windows\MEMORY.DMP
2013-06-08 19:56 - 2013-06-08 19:56 - 00002157 ____A C:\Users\Ruler\Desktop\RKreport[1]_S_06082013_02d1956.txt
2013-06-08 19:55 - 2013-06-08 19:57 - 00000000 ____D C:\Users\Ruler\Desktop\RK_Quarantine
2013-06-02 21:58 - 2013-06-02 21:58 - 00001843 ____A C:\Users\Public\Desktop\Foxit Reader.lnk
2013-06-02 21:57 - 2013-06-02 21:57 - 00000000 ____D C:\Program Files\Foxit Software
2013-06-02 09:28 - 2013-06-02 09:28 - 00000000 ____D C:\Program Files\WinPcap
2013-06-02 09:26 - 2013-06-02 09:34 - 00000000 ____D C:\Users\Ruler\Documents\Freemake
2013-06-02 09:26 - 2013-06-02 09:32 - 00000000 ____D C:\ProgramData\Freemake
2013-06-02 09:26 - 2013-06-02 09:26 - 00001125 ____A C:\Users\Public\Desktop\Freemake Video Downloader.lnk
2013-06-02 08:03 - 2013-06-02 09:26 - 00000000 ____D C:\Program Files\Freemake
2013-06-01 20:36 - 2013-06-01 20:36 - 00000000 ____D C:\Windows\pss
2013-05-30 18:26 - 2013-05-30 18:26 - 00000690 ____A C:\Users\Ruler\Desktop\DEFIANCE.lnk

==================== One Month Modified Files and Folders ========

2013-06-25 09:48 - 2013-06-25 09:48 - 01370263 ____A (Farbar) C:\Users\Ruler\Desktop\FRST.exe
2013-06-25 09:48 - 2013-06-25 09:48 - 00000000 ____D C:\FRST
2013-06-25 08:52 - 2006-11-02 05:47 - 00004672 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-06-25 08:52 - 2006-11-02 05:47 - 00004672 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-06-25 06:58 - 2006-11-02 03:33 - 00781210 ____A C:\Windows\System32\PerfStringBackup.INI
2013-06-25 06:56 - 2013-01-14 23:23 - 01788656 ____A C:\Windows\WindowsUpdate.log
2013-06-25 06:52 - 2006-11-02 06:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-06-24 21:32 - 2006-11-02 06:01 - 00032606 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-24 20:13 - 2012-01-15 18:18 - 00000000 ____D C:\Users\Ruler\AppData\Local\PunkBuster
2013-06-24 20:11 - 2013-06-24 15:47 - 00000000 ____D C:\Users\Ruler\AppData\Local\Deployment
2013-06-24 20:11 - 2012-01-14 21:26 - 00138904 ____A C:\Windows\System32\Drivers\PnkBstrK.sys
2013-06-24 20:11 - 2012-01-14 21:26 - 00138904 ____A C:\Users\Ruler\AppData\Roaming\PnkBstrK.sys
2013-06-24 20:11 - 2012-01-14 21:25 - 00282512 ____A C:\Windows\System32\PnkBstrB.exe
2013-06-24 20:11 - 2012-01-14 21:25 - 00282512 ____A C:\Windows\System32\PnkBstrB.ex0
2013-06-24 20:11 - 2012-01-14 21:25 - 00076888 ____A C:\Windows\System32\PnkBstrA.exe
2013-06-24 17:49 - 2012-01-15 18:18 - 00282104 ____A C:\Windows\System32\PnkBstrB.xtr
2013-06-24 15:47 - 2013-06-24 15:47 - 00000332 ____A C:\Users\Ruler\Desktop\Ghost Recon Online (EU).appref-ms
2013-06-24 15:47 - 2013-06-24 15:47 - 00000000 ____D C:\Users\Ruler\AppData\Local\Apps\2.0
2013-06-24 15:39 - 2012-01-13 22:54 - 00057032 ____A C:\Users\Ruler\AppData\Local\GDIPFONTCACHEV1.DAT
2013-06-24 11:12 - 2012-05-16 20:07 - 00000024 ____A C:\Users\Ruler\jagexappletviewer.preferences
2013-06-24 11:12 - 2012-01-17 19:13 - 00000024 ____A C:\Users\Ruler\random.dat
2013-06-24 10:11 - 2012-01-17 19:13 - 00000044 ____A C:\Users\Ruler\jagex_cl_runescape_LIVE.dat
2013-06-24 09:49 - 2013-01-13 15:28 - 00000000 ____D C:\Users\Ruler\AppData\Roaming\.minecraft
2013-06-21 05:17 - 2012-05-09 18:12 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe
2013-06-21 05:17 - 2012-01-14 20:05 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl
2013-06-21 05:10 - 2006-11-02 05:47 - 00258608 ____A C:\Windows\System32\FNTCACHE.DAT
2013-06-20 17:49 - 2013-06-20 17:49 - 00000000 ____D C:\Users\Ruler\Documents\TurboTax
2013-06-20 17:02 - 2012-03-24 20:49 - 00000000 ____D C:\Users\Ruler\AppData\Roaming\uTorrent
2013-06-20 15:32 - 2013-06-20 15:32 - 00000000 ____D C:\Users\Ruler\AppData\Roaming\Intuit Canada
2013-06-20 15:32 - 2013-06-20 15:31 - 00000000 ____D C:\Program Files\TurboTax 2012
2013-06-20 15:31 - 2013-06-20 15:31 - 00001773 ____A C:\Users\Public\Desktop\TurboTax Canada 2012.lnk
2013-06-20 15:31 - 2013-06-20 15:31 - 00000000 ____D C:\ProgramData\Intuit Canada
2013-06-20 15:31 - 2013-06-20 15:31 - 00000000 ____D C:\Program Files\Common Files\Intuit
2013-06-18 17:59 - 2012-12-27 22:30 - 00000000 ____D C:\Users\Ruler\AppData\Roaming\Skype
2013-06-17 22:06 - 2013-01-08 17:25 - 00000000 ____D C:\Users\Ruler\AppData\Roaming\vlc
2013-06-15 19:16 - 2013-05-05 20:00 - 00017784 ____A C:\Windows\PFRO.log
2013-06-15 18:25 - 2013-06-15 18:25 - 00000020 ____A C:\Users\Ruler\defogger_reenable
2013-06-15 18:25 - 2012-01-13 22:53 - 00000000 ____D C:\users\Ruler
2013-06-15 18:24 - 2013-01-16 10:17 - 00000308 ____A C:\Users\Ruler\Documents\ax_files.xml
2013-06-14 11:58 - 2013-06-14 11:52 - 00000000 ____D C:\Program Files\Uplink
2013-06-14 11:51 - 2013-06-14 11:51 - 00000000 _RASH C:\MSDOS.SYS
2013-06-14 11:51 - 2013-06-14 11:51 - 00000000 _RASH C:\IO.SYS
2013-06-14 11:29 - 2013-02-16 22:55 - 00006228 ____A C:\Windows\setupact.log
2013-06-13 22:23 - 2013-06-13 22:23 - 00000297 ____A C:\Windows\System32\userawacs.cfg
2013-06-13 22:21 - 2013-06-13 22:21 - 00000000 ____D C:\Windows\System32\%systemroot%
2013-06-13 22:20 - 2013-06-13 22:20 - 00000000 ____D C:\Program Files\AVG
2013-06-13 21:07 - 2013-06-13 21:06 - 00000000 ___SD C:\32788R22FWJFW
2013-06-13 20:57 - 2013-06-09 13:26 - 00000000 ____D C:\Qoobox
2013-06-13 19:29 - 2006-11-02 04:18 - 00000000 ____D C:\Windows\System32\LogFiles
2013-06-13 18:58 - 2013-06-13 18:58 - 00000020 ___SH C:\Users\Administrator\ntuser.ini
2013-06-13 18:58 - 2013-06-13 18:58 - 00000000 ____D C:\users\Administrator
2013-06-12 17:52 - 2013-04-05 20:23 - 00000000 ____D C:\Program Files\SpeedFan
2013-06-09 22:15 - 2013-06-09 22:14 - 00138816 ____A C:\Windows\Minidump\Mini060913-03.dmp
2013-06-09 22:14 - 2013-06-09 09:46 - 00000000 ____D C:\Windows\Minidump
2013-06-09 22:14 - 2013-06-09 09:45 - 285317279 ____A C:\Windows\MEMORY.DMP
2013-06-09 21:56 - 2013-06-09 21:56 - 00138816 ____A C:\Windows\Minidump\Mini060913-02.dmp
2013-06-09 21:51 - 2013-06-09 21:51 - 00000000 ____D C:\RkUnhooker
2013-06-09 21:49 - 2013-06-09 21:26 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2013-06-09 20:26 - 2013-06-09 20:26 - 00000000 ____A C:\Windows\System32\settings.dat
2013-06-09 13:37 - 2013-06-09 13:37 - 00008202 ____A C:\ComboFix.txt
2013-06-09 13:37 - 2006-11-02 04:18 - 00000000 ___RD C:\users\Public
2013-06-09 13:36 - 2013-06-09 13:26 - 00000000 ____D C:\Windows\erdnt
2013-06-09 13:35 - 2006-11-02 03:23 - 00000215 ____A C:\Windows\system.ini
2013-06-09 10:57 - 2013-06-09 10:57 - 00000000 ____D C:\ProgramData\Sophos
2013-06-09 10:51 - 2013-06-09 10:51 - 00002038 ____A C:\Users\Ruler\Desktop\Sophos Virus Removal Tool.lnk
2013-06-09 10:51 - 2013-06-09 10:51 - 00000000 ____D C:\Program Files\Sophos
2013-06-09 10:51 - 2013-04-20 09:37 - 00002170 ____A C:\Users\Ruler\Desktop\Rkill.txt
2013-06-09 10:13 - 2013-06-09 10:13 - 00001429 ____A C:\Users\Ruler\Desktop\JRT.txt
2013-06-09 10:10 - 2013-06-09 10:10 - 00000000 ____D C:\Windows\ERUNT
2013-06-09 10:10 - 2013-06-09 10:10 - 00000000 ____D C:\JRT
2013-06-09 10:09 - 2013-06-09 10:09 - 00001140 ____A C:\AdwCleaner[R1].txt
2013-06-09 10:04 - 2013-06-09 10:04 - 00000000 ____D C:\TDSSKiller_Quarantine
2013-06-09 09:46 - 2013-06-09 09:46 - 00138816 ____A C:\Windows\Minidump\Mini060913-01.dmp
2013-06-08 19:57 - 2013-06-08 19:55 - 00000000 ____D C:\Users\Ruler\Desktop\RK_Quarantine
2013-06-08 19:56 - 2013-06-08 19:56 - 00002157 ____A C:\Users\Ruler\Desktop\RKreport[1]_S_06082013_02d1956.txt
2013-06-02 22:20 - 2012-05-16 17:37 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-06-02 21:58 - 2013-06-02 21:58 - 00001843 ____A C:\Users\Public\Desktop\Foxit Reader.lnk
2013-06-02 21:58 - 2013-02-21 10:02 - 00000000 ____D C:\Users\Ruler\AppData\Roaming\Foxit Software
2013-06-02 21:57 - 2013-06-02 21:57 - 00000000 ____D C:\Program Files\Foxit Software
2013-06-02 13:37 - 2012-12-30 21:10 - 00000000 ____D C:\ProgramData\Skype
2013-06-02 09:34 - 2013-06-02 09:26 - 00000000 ____D C:\Users\Ruler\Documents\Freemake
2013-06-02 09:34 - 2012-06-21 18:16 - 00009216 ____A C:\Users\Ruler\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-06-02 09:32 - 2013-06-02 09:26 - 00000000 ____D C:\ProgramData\Freemake
2013-06-02 09:28 - 2013-06-02 09:28 - 00000000 ____D C:\Program Files\WinPcap
2013-06-02 09:27 - 2012-08-08 20:26 - 00000906 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-06-02 09:26 - 2013-06-02 09:26 - 00001125 ____A C:\Users\Public\Desktop\Freemake Video Downloader.lnk
2013-06-02 09:26 - 2013-06-02 08:03 - 00000000 ____D C:\Program Files\Freemake
2013-06-01 20:36 - 2013-06-01 20:36 - 00000000 ____D C:\Windows\pss
2013-05-30 18:26 - 2013-05-30 18:26 - 00000690 ____A C:\Users\Ruler\Desktop\DEFIANCE.lnk

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-06-25 06:59

==================== End Of Log ============================

Attached Files



#7 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 25 June 2013 - 06:30 PM

Hello again,

 

I'm going to need some time to take a closer look at this. Your logs aren't showing much malware, but your RogueKiller log is what I'm concerned about.

 

Please allow me time for some more research on this, and I'll get back to you as soon as I can. Thank you for your patience!

 

bloopie



#8 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 26 June 2013 - 06:13 PM

Hello again, sorry for the delay, and thanks for waiting!

 

After looking again at your FRST log, I need some input from you (this caused me to abandon your RogueKiller log for the time being):

 

Maybe I've missed this the first time your FRST log was posted, but there are a couple of proxies set in your firefox browser:

 

FF NetworkProxy: "backup.ftp", "42.117.1.77"
FF NetworkProxy: "backup.ftp_port", 3128
FF NetworkProxy: "backup.socks", "42.117.1.77"
FF NetworkProxy: "backup.socks_port", 3128
FF NetworkProxy: "backup.ssl", "42.117.1.77"
FF NetworkProxy: "backup.ssl_port", 3128
FF NetworkProxy: "ftp", "218.108.168.165"
FF NetworkProxy: "ftp_port", 80
FF NetworkProxy: "http", "218.108.168.165"
FF NetworkProxy: "http_port", 80
FF NetworkProxy: "share_proxy_settings", true
FF NetworkProxy: "socks", "218.108.168.165"
FF NetworkProxy: "socks_port", 80
FF NetworkProxy: "ssl", "218.108.168.165"
FF NetworkProxy: "ssl_port", 80
FF NetworkProxy: "type", 0

 

Those IP's, are known spammer IP's and they don't look very good. Please confirm you haven't set those manually. If not, then we'll remove them with a script.

 

If that script fails to resolve the problem, then we'll explore other avenues.

 

bloopie



#9 dralon

dralon
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:54 AM

Posted 26 June 2013 - 10:41 PM

Oh I forgot to tell you about the proxies before I posted. That is something I just recently set up myself. The RogueKiller log provided was from the first time I ran it, no more entries showed up after I cleaned it out and scanned again, it has been clean since. However if you know the identity of the malware shown in the RK log, perhaps that could lead us to a specific location to search for other fragments of the same malware.

I got rid of the IRP hooks listed in the RK log at the time by replacing the MBR. Those were the same hooks as listed in the GMER log of the same time frame.

I suspect one IRP hook on atapi.sys will come back when I defog after this is all over, because there was one that just would not go away. I'm not sure if that is part of my emulation software or what.



#10 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 27 June 2013 - 06:31 PM

Hello again,
 
Thanks for letting me know about the proxies! :)
 

I got rid of the IRP hooks listed in the RK log at the time by replacing the MBR.


Ahh, that changes things. I did not know you replaced the MBR already (although I should have seen it in your CF log you posted). I was about to ask you to dump the MBR for me to have a look at it, but since it's already been rewritten it will come up clean now. Did you make a backup of the MBR before fixing it? If so, I'd like to have a look at it. aswMBR will make a backup to the desktop if you've ran the tool before the change was made.
 
==========
 
I'd like you to run Combofix again and post me the new log. Since it's been a while, please delete the Combofix.exe from your desktop, and download a fresh copy and run the tool again with the below instructions:

Run Combofix

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out here or here

Combofix may need to reboot your computer more than once to do its job...this is normal.

You can download Combofix from one of these links.

  • Close any open browsers or any other programs that are open.
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Double click on combofix.exe & follow the prompts.
  • When finished, it will produce a report for you C:\Combofix.txt. Please include that in your next reply.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

==========

Please copy and paste the new CF log in your next reply! And if you have it, please attach the MBR.dat file from the aswMBR tool if it was run before you fixed the MBR!

bloopie



#11 dralon

dralon
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:54 AM

Posted 28 June 2013 - 10:11 PM

It actually saved MBR.dat to the folder it was run from in D partition. I have it here, however since I actually replaced the MBR a couple times trying to get rid of the persistent IRP MJ CREATE on atapi.sys and all the stuff that you have seen in the aswMBR log that I gave you. That all has continued to persist, although I have not run aswMBR since running Defogger, in compliance with the instructions given in requesting help here that I do not change or run anything on my own. I will attach it anyways so if you want to look at it you can. I will also attach the MBR backup that combofix made, although none of these may be any good to you, they may help you if they are still infected. I have also attached the latest MBR backup that was just made by Combofix.

I believe this hidden process may date back to when I put in a DVD that I think was "protected" by Sony's "copyright protection" rootkit. Although I know they don't use the old system from 2005 anymore, it's possible a new protection tool is at work here. Thus relating to DVD/CD emulation, it's hooks could be hidden by the Defogger while we are searching for the root cause of this.

 

Combofix log:

 

ComboFix 13-06-28.02 - Ruler 06/28/2013  19:55:31.1.2 - x86
Microsoft® Windows Vista™ Home Premium   6.0.6000.0.1252.1.1033.18.2939.2128 [GMT -7:00]
Running from: d:\programs\ComboFix.exe
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\system32\%SYSTE~1
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgadvisor.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgadvisor.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgcfg.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgcfg.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgchjw.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgchjw.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgcore.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgcore.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgcsl.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgcsl.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgdecider.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgdecider.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgexc.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgexc.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgidpagent.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgidpagent.log.1
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgidpagent.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgmsgdisp.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgmsgdisp.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgrkt.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgrkt.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgscan.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgscan.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgsched.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgsched.log.1
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgsched.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgsecapi.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgsecapi.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgsrm.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgsrm.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwd.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwd.log.1
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwd.log.2
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwd.log.3
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwd.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwdsvc.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwdsvc.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwdsvc_idp_SYSTEM.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwdsvc_idp_SYSTEM.log.1
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwdsvc_idp_SYSTEM.log.2
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\avgwdsvc_idp_SYSTEM.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\commonpriv.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\commonpriv.log.lock
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\vault.log
c:\windows\system32\%SYSTE~1\system32\config\systemprofile\AppData\Local\Avg2013\log\vault.log.lock
.
.
(((((((((((((((((((((((((   Files Created from 2013-05-28 to 2013-06-29  )))))))))))))))))))))))))))))))
.
.
2013-06-29 03:01 . 2013-06-29 03:01    --------    d-----w-    c:\users\Ruler\AppData\Local\temp
2013-06-25 16:48 . 2013-06-25 16:48    --------    d-----w-    C:\FRST
2013-06-24 22:47 . 2013-06-25 17:46    --------    d-----w-    c:\users\Ruler\AppData\Local\Deployment
2013-06-24 22:47 . 2013-06-24 22:47    --------    d-----w-    c:\users\Ruler\AppData\Local\Apps
2013-06-20 22:32 . 2013-06-20 22:32    --------    d-----w-    c:\users\Ruler\AppData\Roaming\Intuit Canada
2013-06-20 22:31 . 2013-06-20 22:31    --------    d-----w-    c:\program files\Common Files\Intuit
2013-06-20 22:31 . 2013-06-20 22:32    --------    d-----w-    c:\program files\TurboTax 2012
2013-06-20 22:31 . 2013-06-20 22:31    --------    d-----w-    c:\programdata\Intuit Canada
2013-06-14 18:52 . 2013-06-14 18:58    --------    d-----w-    c:\program files\Uplink
2013-06-14 18:51 . 1997-11-19 22:49    303616    ----a-w-    c:\windows\IsUninst.exe
2013-06-14 05:20 . 2013-06-14 05:20    --------    d-----w-    c:\program files\AVG
2013-06-14 05:19 . 2013-06-14 05:19    --------    d--h--w-    c:\programdata\Common Files
2013-06-14 01:58 . 2013-06-14 01:58    --------    d-----w-    c:\users\Administrator
2013-06-10 04:51 . 2013-06-10 04:51    --------    d-----w-    C:\RkUnhooker
2013-06-10 04:26 . 2013-06-10 04:49    --------    d-----w-    c:\programdata\Malwarebytes' Anti-Malware (portable)
2013-06-09 17:57 . 2013-06-09 17:57    --------    d-----w-    c:\programdata\Sophos
2013-06-09 17:51 . 2013-06-09 17:51    73728    ----a-r-    c:\users\Ruler\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe1_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-06-09 17:51 . 2013-06-09 17:51    73728    ----a-r-    c:\users\Ruler\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\SVRTgui.exe_810EDD9E2F0A4E2BACF86673C38D9F48.exe
2013-06-09 17:51 . 2013-06-09 17:51    73728    ----a-r-    c:\users\Ruler\AppData\Roaming\Microsoft\Installer\{B829E117-D072-41EA-9606-9826A38D34C1}\ARPPRODUCTICON.exe
2013-06-09 17:51 . 2013-06-09 17:51    --------    d-----w-    c:\program files\Sophos
2013-06-09 17:10 . 2013-06-09 17:10    --------    d-----w-    c:\windows\ERUNT
2013-06-09 17:10 . 2013-06-09 17:10    --------    d-----w-    C:\JRT
2013-06-09 17:04 . 2013-06-09 17:04    --------    d-----w-    C:\TDSSKiller_Quarantine
2013-06-09 02:53 . 2013-06-09 02:53    60872    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{DF8B577F-64E5-4935-B45A-B053A12292C1}\offreg.dll
2013-06-06 00:47 . 2013-05-13 06:19    7016152    ----a-w-    c:\programdata\Microsoft\Windows Defender\Definition Updates\{DF8B577F-64E5-4935-B45A-B053A12292C1}\mpengine.dll
2013-06-03 04:57 . 2013-06-03 04:57    --------    d-----w-    c:\program files\Foxit Software
2013-06-02 16:28 . 2013-06-02 16:28    --------    d-----w-    c:\program files\WinPcap
2013-06-02 16:26 . 2013-06-02 16:32    --------    d-----w-    c:\programdata\Freemake
2013-06-02 16:26 . 2013-05-15 06:14    8013376    ----a-w-    c:\program files\Internet Explorer\Microsoft.mshtml.dll
2013-06-02 15:03 . 2013-06-02 16:26    --------    d-----w-    c:\program files\Freemake
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-25 18:47 . 2012-01-15 04:26    139424    ----a-w-    c:\windows\system32\drivers\PnkBstrK.sys
2013-06-25 18:47 . 2012-01-16 01:18    282104    ----a-w-    c:\windows\system32\PnkBstrB.xtr
2013-06-25 18:47 . 2012-01-15 04:25    282104    ----a-w-    c:\windows\system32\PnkBstrB.exe
2013-06-25 03:11 . 2012-01-15 04:26    138904    ----a-w-    c:\users\Ruler\AppData\Roaming\PnkBstrK.sys
2013-06-25 03:11 . 2012-01-15 04:25    282512    ----a-w-    c:\windows\system32\PnkBstrB.ex0
2013-06-25 03:11 . 2012-01-15 04:25    76888    ----a-w-    c:\windows\system32\PnkBstrA.exe
2013-06-21 12:17 . 2012-05-10 01:12    692104    ----a-w-    c:\windows\system32\FlashPlayerApp.exe
2013-06-21 12:17 . 2012-01-15 03:05    71048    ----a-w-    c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-02 09:06 . 2012-01-15 06:14    238872    ------w-    c:\windows\system32\MpSigStub.exe
2013-04-20 03:55 . 2013-04-20 03:55    94112    ----a-w-    c:\windows\system32\WindowsAccessBridge.dll
2013-04-20 03:54 . 2013-01-16 05:42    866720    ----a-w-    c:\windows\system32\npDeployJava1.dll
2013-04-20 03:54 . 2012-01-15 03:09    788896    ----a-w-    c:\windows\system32\deployJava1.dll
2013-04-04 21:50 . 2012-05-17 00:37    22856    ----a-w-    c:\windows\system32\drivers\mbam.sys
.
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\~\Browser Helper Objects\{e9e8eb35-ff77-455d-b677-91e5e4fc06c2}]
2012-01-15 06:49    297808    ----a-w-    c:\windows\System32\mscoree.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-08 6037504]
"Skytel"="Skytel.exe" [2007-11-21 1826816]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
"AGEIA PhysX SysTray"="c:\program files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 331776]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootxrepeal.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootxrexpeal.sys]
@=""
.
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kuma_Tray.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Kuma_Tray.lnk
backup=c:\windows\pss\Kuma_Tray.lnk.CommonStartup
backupExtension=.CommonStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Akamai NetSession Interface]
2013-01-26 14:08    4480768    ----a-w-    c:\users\Ruler\AppData\Local\Akamai\netsession_win.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2013-03-12 14:32    253816    ----a-w-    c:\program files\Common Files\Java\Java Update\jusched.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3508924782-381798385-1543019129-1000]
"EnableNotifications"=dword:00000001
"EnableNotificationsRef"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2013-01-25 08:01    1607120    ----a-w-    c:\program files\Google\Chrome\Application\24.0.1312.56\Installer\chrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2013-01-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-06-29 00:34]
.
2013-01-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-06-29 00:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = <local>
TCP: DhcpNameServer = 64.251.68.9 64.141.73.187
Handler: intu-tt2012 - {02F985EF-502B-4597-993F-6BF9E004C138} - c:\program files\TurboTax 2012\ic2012pp.dll
FF - ProfilePath - c:\users\Ruler\AppData\Roaming\Mozilla\Firefox\Profiles\8zj0ps33.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.ftp - 218.108.168.165
FF - prefs.js: network.proxy.ftp_port - 80
FF - prefs.js: network.proxy.http - 218.108.168.165
FF - prefs.js: network.proxy.http_port - 80
FF - prefs.js: network.proxy.socks - 218.108.168.165
FF - prefs.js: network.proxy.socks_port - 80
FF - prefs.js: network.proxy.ssl - 218.108.168.165
FF - prefs.js: network.proxy.ssl_port - 80
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-06-02 09:26; fmdownloader@gmail.com; c:\program files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\fmdownloader@gmail.com
FF - ExtSQL: 2013-06-02 09:26; ytfmdownloader@gmail.com; c:\program files\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\ytfmdownloader@gmail.com
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-32024050.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-28 20:01
Windows 6.0.6000  NTFS
.
scanning hidden processes ...  
.
scanning hidden autostart entries ...
.
scanning hidden files ...  
.
.
c:\users\Ruler\AppData\Local\Temp\catchme.dll 53248 bytes executable
.
scan completed successfully
hidden files: 1
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
Completion time: 2013-06-28  20:03:26
ComboFix-quarantined-files.txt  2013-06-29 03:03
.
Pre-Run: 63,828,574,208 bytes free
Post-Run: 63,893,180,416 bytes free
.
- - End Of File - - B3CD2F3FC41DC0024863E2C3BBA00518
239841E1AE8E4843C0676F3681A7D6BE
 

 

Attached Files



#12 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 29 June 2013 - 04:29 PM

Hello again and thanks,

 

I'm going to need some further time to look at this, and I will ask about it with some colleagues as well.

 

Thanks for your patience!

 

bloopie



#13 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 30 June 2013 - 12:13 PM

Hello again,

I'm just not seeing any malware in your latest logs, so I'll need to take a step back and find out what is currently wrong.

Could you please let me know your current issues with the machine?

There has been too much done on your own to know exactly what is left to do, and that's why I ask the above again.

bloopie

#14 dralon

dralon
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:54 AM

Posted 01 July 2013 - 11:15 AM

OK it would appear that I have successfully removed Flystudio and associated malware.

The current problem is

 

1. Hidden process listed in GMER.

2. Xul.dll reports in Firefox that's probably nothing but an extension at work.

 

I currently have zero symptoms of malware, whereas during my removal efforts, I had some weird experiences. I disabled the administrator account after working in it in safe mode for a while. It had no password at the time, I did a regular boot and suddenly administrator account was not only active, but password protected. Keep in mind that was after already replacing the MBR and cleaning out the system with all tools including with combofix, but prior to manually replacing wdf01000.sys, kbdclass.sys, netbios.sys, ntfs.sys, atapi.sys, and possibly also msahci.sys. After removal of these, things were normal. Notably during the whole time there was an odd driver named acwz5314.sys, which changed name randomly every time I booted the computer, but always began with the letter a. This disappeared upon defogging as requested prior to posting here.

Prior symptoms experienced:
1. Slight lag in loading facebook, just a split second enough to get me to look, and sure enough, flystudio.

2. While removing malware, weird experience with changed password on administrator account.

Current symptoms experienced:

0.

The only thing that really bugs me is my inability to understand where and how this hidden process is coming from. I may ultimately have to do some packet sniffing to find out what it is up to. I have attached some screenshots so you can see exactly what I'm looking at.





And here is a new GMER scan log, the only tool that reports anything suspicious on my system currently.

GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-07-01 08:43:56
Windows 6.0.6000  \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD5000BEVT-00A0RT0 rev.01.01A01 465.76GB
Running: lclwo35l.exe; Driver: C:\Users\Ruler\AppData\Local\Temp\kgrcrpow.sys


---- User code sections - GMER 2.1 ----

.text    C:\Program Files\Mozilla Firefox\firefox.exe[1908] ntdll.dll!LdrLoadDll                                               77A2EB00 5 Bytes  JMP 69F49CF0 C:\Program Files\Mozilla Firefox\xul.dll
.text    C:\Program Files\Mozilla Firefox\firefox.exe[1908] kernel32.dll!ActivateActCtx + 2C                                   767D7379 7 Bytes  JMP 6A4F5408 C:\Program Files\Mozilla Firefox\xul.dll
.text    C:\Program Files\Mozilla Firefox\firefox.exe[1908] kernel32.dll!VirtualQuery + 24                                     767DD172 7 Bytes  JMP 69F5369E C:\Program Files\Mozilla Firefox\xul.dll
.text    C:\Program Files\Mozilla Firefox\firefox.exe[1908] kernel32.dll!VirtualAllocEx + 54                                   767F9BC5 7 Bytes  JMP 6A4F542B C:\Program Files\Mozilla Firefox\xul.dll
.text    C:\Program Files\Mozilla Firefox\firefox.exe[1908] GDI32.dll!SetTextAlign + E6                                        769D7EEF 7 Bytes  JMP 6A4F5389 C:\Program Files\Mozilla Firefox\xul.dll

---- Processes - GMER 2.1 ----

Process   (*** hidden *** )                                                                                                    [4] 8405E968                                                             

---- Registry - GMER 2.1 ----

Reg      HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Configuration Manager@BackupCount                               2
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04                                      
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                   C:\Program Files\Alcohol Soft\Alcohol 120\
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                   0
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                0x5C 0xF9 0x7D 0x4E ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001                             
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                          0xA0 0x02 0x00 0x00 ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                       0x41 0x95 0x14 0x2B ...
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40                      
Reg      HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                0x97 0xEB 0x8A 0x81 ...
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)                  
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0                                       C:\Program Files\Alcohol Soft\Alcohol 120\
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0                                       0
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew                                    0x5C 0xF9 0x7D 0x4E ...
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)         
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0                              0xA0 0x02 0x00 0x00 ...
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew                           0x41 0x95 0x14 0x2B ...
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)  
Reg      HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew                    0x97 0xEB 0x8A 0x81 ...

---- EOF - GMER 2.1 ----
 

 

Attached Files



#15 bloopie

bloopie

    Bleepin' Sith Turner


  • Malware Response Team
  • 7,927 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New York
  • Local time:04:54 AM

Posted 02 July 2013 - 06:27 PM

Hello again,

I don't think the Xul.dll reports in Firefox are malware related...that seems to be a crash of some sort. You can try to rollback Firefox to an earlier version and see if that persists.

The hidden process in the GMER log may not be malware related either, but there just isn't enough information about the process to be 100% sure.

It seems the only way to tell for sure is to backup your data and reformat/reinstall the Operating System. Then see if it is still there after.

Either way though, the reformat/reinstall should take care of any possible malware related issues.

bloopie




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users