Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Can't stop IE opening randomly to lpcloudsvr203.com ! >:(


  • Please log in to reply
9 replies to this topic

#1 NSGF

NSGF

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:05 AM

Posted 07 May 2014 - 03:56 AM

Hi all, 

 

Randomly an Internet Explorer Window will pop up with this page : 

 

http://malwaretips.com/blogs/wp-content/uploads/2014/02/lpcloudsvr203-com-virus.jpg

 

The web url is lpcloudsvr203.com...etc..

 

I have not installed any new programs recently, and have no idea what could be causing it. Just got this laptop brand new from Lenovo a week ago.

 

Have tried rkill, adwcleaner, malware bytes, spybot s&d, jrt, hitman pro. Nothing comes up with any.

 

Have reset IE and Chrome just in case.

 

Driving me crazy, and help much appreciated!!

 

It has to be malware right....right?

 

 

 

Thank you so much.


Edited by NSGF, 07 May 2014 - 04:00 AM.


BC AdBot (Login to Remove)

 


#2 RedRay

RedRay

  • Members
  • 41 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:05 PM

Posted 07 May 2014 - 06:13 AM

Try scanning with your anti-virus or if you have no AV i recommend buying one like Norton or Bitfender.  Also you can get a free AV, Avast if the best free one for me.



#3 NSGF

NSGF
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:05 AM

Posted 07 May 2014 - 01:22 PM

Try scanning with your anti-virus or if you have no AV i recommend buying one like Norton or Bitfender.  Also you can get a free AV, Avast if the best free one for me

 

Thank you, I will do a scan with AVG free and Avast.

 

Any other opinions?



#4 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:05 AM

Posted 08 May 2014 - 09:45 PM

Hello NSGF, also do these.

Please download MiniToolBox, save it to your desktop and run it.
Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Users, Partitions and Memory size.
  • Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
    Note: When using "Reset FF Proxy Settings" option Firefox should be closed.



    Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
  • .
    .
    .
    ADW Cleaner

    Please download AdwCleaner by Xplode and save to your Desktop.
  • Double-click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
  • -- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on each one and uncheck any items you want to keep (except you cannot uncheck Chrome and Firefox preferences lines).


    .

    thisisujrt.gif Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
  • .
    .
    .
    .
  • Last run ESET.
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click the esetonlinebtn.png button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the esetsmartinstaller_enu.png icon on your desktop.
  • Check "YES, I accept the Terms of Use."
  • Click the Start button.
  • Accept any security warnings from your browser.
  • Under scan settings, check "Scan Archives" and "Remove found threats"
  • Click Advanced settings and select the following:
  • Scan potentially unwanted applications
  • Scan for potentially unsafe applications
  • Enable Anti-Stealth technology
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Click the Back button.
  • Click the Finish button.
  • NOTE:Sometimes if ESET finds no infections it will not create a log.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#5 NSGF

NSGF
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:05 AM

Posted 09 May 2014 - 12:17 AM

AVG and Avast both found nothing.

 

Thank you so much for replying boopme, I truly appreciate it. Here are my log files.

 

Mini Tool Box:

 

MiniToolBox by Farbar  Version: 23-01-2014
Ran by Neil (administrator) on 08-05-2014 at 21:51:00
Running from "C:\Users\Neil\Downloads"
Microsoft Windows 8.1  (X64)
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= Hosts content: =================================
 
 
 
========================= IP Configuration: ================================
 
DisplayLink Network Adapter NCM = Ethernet 2 (Disconnected)
Intel® Dual Band Wireless-AC 7260 = Wi-Fi (Connected)
TAP-Win32 Adapter V9 = Local Area Connection (Connected)
Intel® Ethernet Connection I218-LM = Ethernet (Media disconnected)
Bluetooth Device (Personal Area Network) = Bluetooth Network Connection (Media disconnected)
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
set interface interface="Local Area Connection* 1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Wi-Fi" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 13" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Local Area Connection* 12" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="ethernet_3" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Ethernet 2" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="other_1" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
set interface interface="Bluetooth Network Connection" forwarding=enabled advertise=enabled nud=enabled ignoredefaultroutes=disabled
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : Nico_Bellic
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
 
Ethernet adapter Bluetooth Network Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Bluetooth Device (Personal Area Network)
   Physical Address. . . . . . . . . : 5C-51-4F-E8-38-15
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Ethernet adapter Local Area Connection:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : TAP-Win32 Adapter V9
   Physical Address. . . . . . . . . : 00-FF-7B-D5-E6-42
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::6087:1b8f:5c16:cc5e%10(Preferred) 
   IPv4 Address. . . . . . . . . . . : 10.30.1.42(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.252
   Lease Obtained. . . . . . . . . . : Thursday, May 8, 2014 7:40:42 PM
   Lease Expires . . . . . . . . . . : Friday, May 8, 2015 7:40:40 PM
   Default Gateway . . . . . . . . . : 
   DHCP Server . . . . . . . . . . . : 10.30.1.41
   DHCPv6 IAID . . . . . . . . . . . : 520159099
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1A-BC-74-4F-28-D2-44-52-0F-CE
   DNS Servers . . . . . . . . . . . : 209.222.18.222
                                       209.222.18.218
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Ethernet adapter Ethernet 2:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Plugable Ethernet
   Physical Address. . . . . . . . . : 00-50-B6-11-17-42
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Local Area Connection* 12:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : 5C-51-4F-E8-38-12
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Local Area Connection* 13:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft Hosted Network Virtual Adapter
   Physical Address. . . . . . . . . : 5E-51-4F-E8-38-11
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Wireless LAN adapter Wi-Fi:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Intel® Dual Band Wireless-AC 7260
   Physical Address. . . . . . . . . : 5C-51-4F-E8-38-11
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : fd7f:7d4c:7b74:0:b8f6:728:a4e1:51d6(Preferred) 
   Temporary IPv6 Address. . . . . . : fd7f:7d4c:7b74:0:fc85:f4cd:82ea:3ccc(Preferred) 
   Link-local IPv6 Address . . . . . : fe80::b8f6:728:a4e1:51d6%4(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.1.126(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Thursday, May 8, 2014 4:38:40 PM
   Lease Expires . . . . . . . . . . : Friday, May 9, 2014 8:24:51 PM
   Default Gateway . . . . . . . . . : 192.168.1.1
   DHCP Server . . . . . . . . . . . : 192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 375148879
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1A-BC-74-4F-28-D2-44-52-0F-CE
   DNS Servers . . . . . . . . . . . : 8.8.8.8
                                       8.8.4.4
                                       192.168.1.1
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Ethernet adapter Ethernet:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Intel® Ethernet Connection I218-LM
   Physical Address. . . . . . . . . : 28-D2-44-52-0F-CE
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.{AC931492-D1D4-4A61-98EB-C8DB78E80DB6}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Local Area Connection* 14:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter isatap.{7BD5E642-9DA3-40EC-B6E6-BEA529840D6C}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  resolver1.privateinternetaccess.com
Address:  209.222.18.222
 
Name:    google.com
Addresses:  74.125.225.4
 74.125.225.6
 74.125.225.1
 74.125.225.8
 74.125.225.0
 74.125.225.9
 74.125.225.2
 74.125.225.5
 74.125.225.3
 74.125.225.14
 74.125.225.7
 
 
Pinging google.com [74.125.225.7] with 32 bytes of data:
Reply from 74.125.225.7: bytes=32 time=4ms TTL=55
Reply from 74.125.225.7: bytes=32 time=6ms TTL=55
 
Ping statistics for 74.125.225.7:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 4ms, Maximum = 6ms, Average = 5ms
Server:  resolver1.privateinternetaccess.com
Address:  209.222.18.222
 
Name:    yahoo.com
Addresses:  98.138.253.109
 206.190.36.45
 98.139.183.24
 
 
Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=1830ms TTL=48
Reply from 98.139.183.24: bytes=32 time=68ms TTL=48
 
Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 68ms, Maximum = 1830ms, Average = 949ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 13...5c 51 4f e8 38 15 ......Bluetooth Device (Personal Area Network)
 10...00 ff 7b d5 e6 42 ......TAP-Win32 Adapter V9
  9...00 50 b6 11 17 42 ......Plugable Ethernet
  8...5c 51 4f e8 38 12 ......Microsoft Wi-Fi Direct Virtual Adapter
  7...5e 51 4f e8 38 11 ......Microsoft Hosted Network Virtual Adapter
  4...5c 51 4f e8 38 11 ......Intel® Dual Band Wireless-AC 7260
  3...28 d2 44 52 0f ce ......Intel® Ethernet Connection I218-LM
  1...........................Software Loopback Interface 1
  5...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
  6...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 12...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.126     25
          0.0.0.0        128.0.0.0       10.30.1.25       10.30.1.42     30
          0.0.0.0        128.0.0.0       10.30.1.37       10.30.1.42     30
          0.0.0.0        128.0.0.0       10.30.1.41       10.30.1.42     30
        10.30.1.1  255.255.255.255       10.30.1.25       10.30.1.42     30
        10.30.1.1  255.255.255.255       10.30.1.37       10.30.1.42     30
        10.30.1.1  255.255.255.255       10.30.1.41       10.30.1.42     30
       10.30.1.40  255.255.255.252         On-link        10.30.1.42    286
       10.30.1.42  255.255.255.255         On-link        10.30.1.42    286
       10.30.1.43  255.255.255.255         On-link        10.30.1.42    286
      66.90.98.34  255.255.255.255      192.168.1.1    192.168.1.126     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
        128.0.0.0        128.0.0.0       10.30.1.25       10.30.1.42     30
        128.0.0.0        128.0.0.0       10.30.1.37       10.30.1.42     30
        128.0.0.0        128.0.0.0       10.30.1.41       10.30.1.42     30
      192.168.1.0    255.255.255.0         On-link     192.168.1.126    281
    192.168.1.126  255.255.255.255         On-link     192.168.1.126    281
    192.168.1.255  255.255.255.255         On-link     192.168.1.126    281
   208.53.158.109  255.255.255.255      192.168.1.1    192.168.1.126     25
    208.53.180.50  255.255.255.255      192.168.1.1    192.168.1.126     25
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link        10.30.1.42    286
        224.0.0.0        240.0.0.0         On-link     192.168.1.126    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link        10.30.1.42    286
  255.255.255.255  255.255.255.255         On-link     192.168.1.126    281
===========================================================================
Persistent Routes:
  None
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
  1    306 ::1/128                  On-link
  4    281 fd7f:7d4c:7b74::/64      On-link
  4    281 fd7f:7d4c:7b74:0:b8f6:728:a4e1:51d6/128
                                    On-link
  4    281 fd7f:7d4c:7b74:0:fc85:f4cd:82ea:3ccc/128
                                    On-link
 10    286 fe80::/64                On-link
  4    281 fe80::/64                On-link
 10    286 fe80::6087:1b8f:5c16:cc5e/128
                                    On-link
  4    281 fe80::b8f6:728:a4e1:51d6/128
                                    On-link
  1    306 ff00::/8                 On-link
 10    286 ff00::/8                 On-link
  4    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\WINDOWS\SysWOW64\napinsp.dll [53760] (Microsoft Corporation)
Catalog5 02 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 03 C:\WINDOWS\SysWOW64\pnrpnsp.dll [68096] (Microsoft Corporation)
Catalog5 04 C:\WINDOWS\SysWOW64\NLAapi.dll [64000] (Microsoft Corporation)
Catalog5 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog5 06 C:\WINDOWS\SysWOW64\winrnr.dll [21504] (Microsoft Corporation)
Catalog5 07 C:\WINDOWS\SysWOW64\wshbth.dll [51200] (Microsoft Corporation)
Catalog9 01 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 02 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 03 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 04 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 05 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 06 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 07 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 08 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 09 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 10 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
Catalog9 11 C:\WINDOWS\SysWOW64\mswsock.dll [270848] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\napinsp.dll [67584] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [87040] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\NLAapi.dll [84480] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [30208] (Microsoft Corporation)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [63488] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [338432] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service) (User: )
Description: The index cannot be initialized.
 
 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
 
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service) (User: )
Description: The application cannot be initialized.
 
Context: Windows Application
 
 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
 
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service) (User: )
Description: The gatherer object cannot be initialized.
 
Context: Windows Application, SystemIndex Catalog
 
 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
 
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.
 
Context: Windows Application, SystemIndex Catalog
 
 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
 
Error: (05/08/2014 04:38:38 PM) (Source: Windows Search Service) (User: )
Description: The plug-in manager <Search.TripoliIndexer> cannot be initialized.
 
Context: Windows Application
 
 
Details:
(HRESULT : 0x8e5e0713) (0x8e5e0713)
 
Error: (05/08/2014 04:38:38 PM) (Source: Windows Search Service) (User: )
Description: The Windows Search Service is being stopped because there is a problem with the indexer: The catalog is corrupt.
 
 
Details:
The content index catalog is corrupt.   0xc0041801 (0xc0041801)
 
Error: (05/08/2014 04:38:38 PM) (Source: Windows Search Service) (User: )
Description: The search service has detected corrupted data files in the index {id=4810 - enduser\mssearch2\search\ytrip\common\util\jetutil.cpp (204)}. The service will attempt to automatically correct this problem by rebuilding the index.
 
 
Details:
0x8e5e0713 (0x8e5e0713)
 
Error: (05/08/2014 03:57:44 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary avast! VM Monitor.
 
System Error:
The system cannot find the file specified.
.
 
Error: (05/08/2014 03:57:44 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswSnx.
 
System Error:
The system cannot find the file specified.
.
 
Error: (05/08/2014 03:57:44 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswMonFlt.
 
System Error:
The system cannot find the file specified.
.
 
 
System errors:
=============
Error: (05/08/2014 04:38:59 PM) (Source: DCOM) (User: NICO_BELLIC)
Description: 1053WSearchUnavailable{9E175B6D-F52A-11D8-B9A5-505054503030}
 
Error: (05/08/2014 04:38:59 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service failed to start due to the following error: 
%%1053
 
Error: (05/08/2014 04:38:59 PM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
 
Error: (05/08/2014 04:38:40 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (05/08/2014 04:38:40 PM) (Source: Service Control Manager) (User: )
Description: The Windows Search service terminated with the following service-specific error: 
%%2147749126
 
Error: (05/08/2014 04:38:16 PM) (Source: volsnap) (User: )
Description: The shadow copies of volume C: were aborted during detection.
 
Error: (05/08/2014 03:06:26 PM) (Source: Service Control Manager) (User: )
Description: The avast! HardwareID service failed to start due to the following error: 
%%127
 
Error: (05/08/2014 01:33:09 PM) (Source: Service Control Manager) (User: )
Description: The avast! HardwareID service failed to start due to the following error: 
%%127
 
Error: (05/08/2014 01:29:55 PM) (Source: Service Control Manager) (User: )
Description: The avast! HardwareID service failed to start due to the following error: 
%%127
 
Error: (05/08/2014 01:29:36 PM) (Source: Service Control Manager) (User: )
Description: The avast! HardwareID service failed to start due to the following error: 
%%127
 
 
Microsoft Office Sessions:
=========================
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service)(User: )
Description: 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
 
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application
 
 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
 
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application, SystemIndex Catalog
 
 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
 
Error: (05/08/2014 04:38:40 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application, SystemIndex Catalog
 
 
Details:
The specified object cannot be found. Specify the name of an existing object.  (HRESULT : 0x80040d06) (0x80040d06)
Search.TripoliIndexer
 
Error: (05/08/2014 04:38:38 PM) (Source: Windows Search Service)(User: )
Description: Context: Windows Application
 
 
Details:
(HRESULT : 0x8e5e0713) (0x8e5e0713)
Search.TripoliIndexer
 
Error: (05/08/2014 04:38:38 PM) (Source: Windows Search Service)(User: )
Description: 
Details:
The content index catalog is corrupt.   0xc0041801 (0xc0041801)
The catalog is corrupt
 
Error: (05/08/2014 04:38:38 PM) (Source: Windows Search Service)(User: )
Description: 
Details:
0x8e5e0713 (0x8e5e0713)
4810 - enduser\mssearch2\search\ytrip\common\util\jetutil.cpp (204)
 
Error: (05/08/2014 03:57:44 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary avast! VM Monitor.
 
System Error:
The system cannot find the file specified.
 
Error: (05/08/2014 03:57:44 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswSnx.
 
System Error:
The system cannot find the file specified.
 
Error: (05/08/2014 03:57:44 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswMonFlt.
 
System Error:
The system cannot find the file specified.
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-05-02 22:31:30.869
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\dsound.dll because the set of per-page image hashes could not be found on the system.
 
 
=========================== Installed Programs ============================
 
Adobe AIR (Version: 3.4.0.2710)
Disable AMT Profile Synchronization Pop-up for Windows XP/Vista/7/8 (Version: 1.00)
DisplayLink Core Software (Version: 7.4.53134.0)
Dolby Digital Plus Advanced Audio (Version: 7.5.1.1)
f.lux
Free YouTube to MP3 Converter version 3.12.34.430 (Version: 3.12.34.430)
Google Chrome (Version: 34.0.1847.131)
Google Update Helper (Version: 1.3.24.7)
Integrated Camera (Version: 3.4.7.31)
Intel Collaborative Processor Performance Control (Version: 1.0.0.1015)
Intel® Management Engine Components (Version: 9.5.10.1652)
Intel® Network Connections Drivers (Version: 19.0)
Intel® PRO/Wireless Driver (Version: 16.11.0000.1384)
Intel® Processor Graphics (Version: 10.18.10.3412)
Intel® PROSet/Wireless Software for Bluetooth® Technology(patch version 3.0.1342.1) (Version: 3.1.1309.0390)
Intel® SDK for OpenCL - CPU Only Runtime Package (Version: 3.0.0.66956)
Intel® Smart Connect Technology 4.1 x64 (Version: 4.1.41.2234)
Intel® Update Manager (Version: 1.6.3.70)
Intel® WiDi (Version: 4.2.19.0)
Intel® PROSet/Wireless Software (Version: 16.11.0)
Intel® PROSet/Wireless WiFi Software (Version: 16.10.0.0307)
Intel® Trusted Connect Service Client (Version: 1.28.487.1)
Java 7 Update 55 (Version: 7.0.550)
Java Auto Updater (Version: 2.1.9.8)
Lenovo Auto Scroll Utility (Version: 2.10)
Lenovo Patch Utility (Version: 1.3.2.6)
Lenovo Patch Utility 64 bit (Version: 1.3.2.6)
Lenovo Power Management Driver (Version: 1.67.04.05)
Lenovo Settings - Camera Audio (Version: 4.2.2.0)
Lenovo Settings - Location Awareness (Version: 1.3.0.10)
Lenovo Settings Dependency Package (Version: 2.0.0.16)
Lenovo Settings UMDF driver (Version: 1.1.0.5)
Lenovo System Update (Version: 5.05.0009)
Malwarebytes Anti-Malware version 2.0.1.1004 (Version: 2.0.1.1004)
Microsoft Office 365 ProPlus - en-us (Version: 15.0.4605.1003)
Microsoft Silverlight (Version: 5.1.30214.0)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (Version: 10.0.40219)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219)
Office 15 Click-to-Run Extensibility Component (Version: 15.0.4605.1003)
Office 15 Click-to-Run Licensing Component (Version: 15.0.4605.1003)
Office 15 Click-to-Run Localization Component (Version: 15.0.4605.1003)
On Screen Display (Version: 7.12.21)
Paragon Backup and Recovery™ 14 Home (Version: 90.00.0003)
Private Internet Access Support Files (Version: 1.0.0.0)
RapidBoot HDD Accelerator (Version: 2.1.1.0)
Realtek Card Reader (Version: 6.2.9200.21236)
Realtek High Definition Audio Driver (Version: 6.0.1.7188)
ShortKeys Lite (Version: 2.3.2.1)
ThinkPad UltraNav Driver (Version: 18.0.7.40)
Visual Studio 2012 x64 Redistributables (Version: 14.0.0.1)
Visual Studio 2012 x86 Redistributables (Version: 14.0.0.1)
VLC media player 2.1.3 (Version: 2.1.3)
Windows Driver Package - Intel (e1dexpress) Net  (05/06/2013 12.6.51.9427) (Version: 05/06/2013 12.6.51.9427)
Windows Driver Package - Intel Corporation (iaStorA) HDC  (08/01/2013 12.8.0.1016) (Version: 08/01/2013 12.8.0.1016)
Windows Driver Package - Intel hdc  (02/25/2013 9.4.0.1017) (Version: 02/25/2013 9.4.0.1017)
Windows Driver Package - Intel System  (02/25/2013 9.4.0.1017) (Version: 02/25/2013 9.4.0.1017)
Windows Driver Package - Intel USB  (02/25/2013 9.4.0.1017) (Version: 02/25/2013 9.4.0.1017)
Windows Driver Package - Lenovo 1.67.00.02 (04/17/2013 1.67.00.02) (Version: 04/17/2013 1.67.00.02)
Windows Driver Package - Synaptics (SmbDrv) System  (12/17/2013 17.0.12.60) (Version: 12/17/2013 17.0.12.60)
Windows Driver Package - Synaptics (SynTP) Mouse  (12/17/2013 17.0.12.60) (Version: 12/17/2013 17.0.12.60)
 
========================= Memory info: ===================================
 
Percentage of memory in use: 63%
Total physical RAM: 3981 MB
Available physical RAM: 1464.69 MB
Total Pagefile: 5133 MB
Available Pagefile: 2000.88 MB
Total Virtual: 4095.88 MB
Available Virtual: 3967.32 MB
 
========================= Partitions: =====================================
 
1 Drive c: (Windows8_OS) (Fixed) (Total:98.18 GB) (Free:73.47 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\NICO_BELLIC
 
Administrator            Guest                    Neil                     
 
 
**** End of log ****
 
 
TDSS Killer
 
21:54:08.0161 0x183c  TDSS rootkit removing tool 3.0.0.34 Apr 29 2014 18:20:10
21:54:08.0161 0x183c  UEFI system
21:54:10.0894 0x183c  ============================================================
21:54:10.0894 0x183c  Current date / time: 2014/05/08 21:54:10.0894
21:54:10.0894 0x183c  SystemInfo:
21:54:10.0894 0x183c  
21:54:10.0894 0x183c  OS Version: 6.3.9600 ServicePack: 0.0
21:54:10.0894 0x183c  Product type: Workstation
21:54:10.0894 0x183c  ComputerName: NICO_BELLIC
21:54:10.0895 0x183c  UserName: Neil
21:54:10.0895 0x183c  Windows directory: C:\WINDOWS
21:54:10.0895 0x183c  System windows directory: C:\WINDOWS
21:54:10.0895 0x183c  Running under WOW64
21:54:10.0895 0x183c  Processor architecture: Intel x64
21:54:10.0895 0x183c  Number of processors: 4
21:54:10.0895 0x183c  Page size: 0x1000
21:54:10.0895 0x183c  Boot type: Normal boot
21:54:10.0895 0x183c  ============================================================
21:54:11.0013 0x183c  System UUID: {4DD6A68D-6B5E-96F1-33C0-8DEAA0F5E654}
21:54:11.0338 0x183c  Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:54:11.0341 0x183c  ============================================================
21:54:11.0341 0x183c  \Device\Harddisk0\DR0:
21:54:11.0341 0x183c  GPT partitions:
21:54:11.0342 0x183c  \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {5DF720CA-9A1D-4E18-E858-AE951A81119A}, Name: , StartLBA 0x800, BlocksNum 0x1F4000
21:54:11.0342 0x183c  \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {1723CE29-36D1-4DDD-980B-FBC1CC170BF6}, Name: , StartLBA 0x1F5000, BlocksNum 0x82000
21:54:11.0342 0x183c  \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {F8B36663-A196-443D-307C-C501BD94BE65}, Name: , StartLBA 0x277000, BlocksNum 0x40000
21:54:11.0342 0x183c  \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {C6FCB543-8DF1-4D77-2868-77DC8365E8A9}, Name: , StartLBA 0x2B7000, BlocksNum 0xC45C000
21:54:11.0342 0x183c  \Device\Harddisk0\DR0\Partition5: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {0032E27D-7009-4708-C485-CBFB8CAEA650}, Name: , StartLBA 0xC713000, BlocksNum 0xE1000
21:54:11.0342 0x183c  \Device\Harddisk0\DR0\Partition6: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {4867D563-6F88-455E-1A71-6C405FB4EA41}, Name: , StartLBA 0xC7F4000, BlocksNum 0x179F800
21:54:11.0342 0x183c  MBR partitions:
21:54:11.0342 0x183c  ============================================================
21:54:11.0343 0x183c  C: <-> \Device\Harddisk0\DR0\Partition4
21:54:11.0343 0x183c  ============================================================
21:54:11.0343 0x183c  Initialize success
21:54:11.0343 0x183c  ============================================================
21:54:12.0183 0x1868  ============================================================
21:54:12.0183 0x1868  Scan started
21:54:12.0183 0x1868  Mode: Manual; 
21:54:12.0183 0x1868  ============================================================
21:54:12.0183 0x1868  KSN ping started
21:54:14.0528 0x1868  KSN ping finished: true
21:54:14.0657 0x1868  ================ Scan system memory ========================
21:54:14.0657 0x1868  System memory - ok
21:54:14.0659 0x1868  ================ Scan services =============================
21:54:14.0763 0x1868  [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1, 41FF7418887AFC8B9C96EF21C5950DD342CC9E3C0D87AFD60A05B988C1D6CC23 ] 1394ohci        C:\WINDOWS\System32\drivers\1394ohci.sys
21:54:14.0775 0x1868  1394ohci - ok
21:54:14.0808 0x1868  [ AD508A1A46EC21B740AB31C28EFDFDB1, 9B1046CF0B80723149BD359B55CC0B8B3ABBEAA9038469F542A4C345C503FB02 ] 3ware           C:\WINDOWS\system32\drivers\3ware.sys
21:54:14.0814 0x1868  3ware - ok
21:54:14.0853 0x1868  [ 9539F7917B4B6D92C90F0FAA6B86C605, B4C284E8EECC2E7025053A3320EFDC9F47BCA9828853AD2A805DB826CA4AC27E ] ACPI            C:\WINDOWS\system32\drivers\ACPI.sys
21:54:14.0866 0x1868  ACPI - ok
21:54:14.0871 0x1868  [ AC8279D229398BCF05C3154ADCA86813, 083E86CBE53244D24C334DB1511C77025133AE7875191845764B890A8CA5AFA9 ] acpiex          C:\WINDOWS\system32\Drivers\acpiex.sys
21:54:14.0873 0x1868  acpiex - ok
21:54:14.0876 0x1868  [ A8970D9BF23CD309E0403978A1B58F3F, 9946C8477104EEC7DB197E2222F9905307F101C398CCED4B5FD0F86A5622C791 ] acpipagr        C:\WINDOWS\System32\drivers\acpipagr.sys
21:54:14.0877 0x1868  acpipagr - ok
21:54:14.0881 0x1868  [ 111A89C99C5B4F1A7BCE5F643DD86F65, 41A2E49FF443927D05F7EF638518108227852984E68D4663C8761178C0B84A45 ] AcpiPmi         C:\WINDOWS\System32\drivers\acpipmi.sys
21:54:14.0882 0x1868  AcpiPmi - ok
21:54:14.0885 0x1868  [ 5758387D68A20AE7D3245011B07E36E7, 77832E200E8B0D259552F6F60FE454A887E3EBBB9EA2F3590E6645289A04E293 ] acpitime        C:\WINDOWS\System32\drivers\acpitime.sys
21:54:14.0886 0x1868  acpitime - ok
21:54:14.0905 0x1868  [ 7C1FDF1B48298CBA7CE4BDD4978951AD, 80F4D536E1231B30E836F72ADC8814AE6AA9FEC573FB5F3F965FAC8ABCCAF0F8 ] ADP80XX         C:\WINDOWS\system32\drivers\ADP80XX.SYS
21:54:14.0917 0x1868  ADP80XX - ok
21:54:14.0927 0x1868  [ 0F17D49BE041B7EFF1D33BF1414E7AC6, F8B536B60903814DF88DAF535753288537EF0993E42AA4E734EDA8D68B24C7AB ] AeLookupSvc     C:\WINDOWS\System32\aelupsvc.dll
21:54:14.0930 0x1868  AeLookupSvc - ok
21:54:14.0945 0x1868  [ 239268BAB58EAE9A3FF4E08334C00451, 13F927730DF9BAEDB3A7AB6F7238270A20E4CDEB3D5324A1C471DF2209F3D239 ] AFD             C:\WINDOWS\system32\drivers\afd.sys
21:54:14.0957 0x1868  AFD - ok
21:54:14.0963 0x1868  [ 7DFAEBA9AD62D20102B576D5CAC45EC8, 9FA5207335303D1E8E9A3C9E1FB82C09AD21B04382F69D777A67E48EE91D2093 ] agp440          C:\WINDOWS\system32\drivers\agp440.sys
21:54:14.0964 0x1868  agp440 - ok
21:54:14.0970 0x1868  [ 8E8E34B7BA059050EED827410D0697A2, 85B6684709F24729A6497563812A90A54068AC2DD9EEA03037CB1EEF5C85AAA9 ] ahcache         C:\WINDOWS\system32\DRIVERS\ahcache.sys
21:54:14.0971 0x1868  ahcache - ok
21:54:14.0978 0x1868  [ A91D8E1E433EFB32551BCE69037E1CE7, 41DFDD5B56918D19D09DFB3E4B07460AA85647A8647ABBBB906158D8D6653290 ] ALG             C:\WINDOWS\System32\alg.exe
21:54:14.0980 0x1868  ALG - ok
21:54:14.0985 0x1868  [ 7589DE749DB6F71A68489DCE04158729, 5F35EDD50737985595C9D6703237CA2ADE49AA5443331020899698EB5114A0FB ] AmdK8           C:\WINDOWS\System32\drivers\amdk8.sys
21:54:14.0987 0x1868  AmdK8 - ok
21:54:14.0992 0x1868  [ B46D2D89AFF8A9490FA8C98C7A5616E3, BE0765B5423B690E0F097FECD9717FAA95BFDFFDC6CF1B93DE5A19A1B7797879 ] AmdPPM          C:\WINDOWS\System32\drivers\amdppm.sys
21:54:14.0995 0x1868  AmdPPM - ok
21:54:15.0001 0x1868  [ D2BF2F94A47D332814910FD47C6BBCD2, FE273D77D119D958676E1197D9EA7B008E3B05C6192B1962A81D4223ED204C35 ] amdsata         C:\WINDOWS\system32\drivers\amdsata.sys
21:54:15.0002 0x1868  amdsata - ok
21:54:15.0011 0x1868  [ A8E04943C7BBA7219AA50400272C3C6E, 794C0BD12DF0392654E9A37AE4A24B5BE2D83F1F24F74DD48A1A0BF3AB8B1FF8 ] amdsbs          C:\WINDOWS\system32\drivers\amdsbs.sys
21:54:15.0017 0x1868  amdsbs - ok
21:54:15.0022 0x1868  [ CEA5F4F27CFC08E3A44D576811B35F50, 89DF64B81BD109BAABAE93A4603C1617241219F38DDAF325EFE6BD35FF6FD717 ] amdxata         C:\WINDOWS\system32\drivers\amdxata.sys
21:54:15.0023 0x1868  amdxata - ok
21:54:15.0028 0x1868  [ 04951A9A937CBE28A2D3FEEA360B6D1F, D8AAF000BE4FE4B203DC2EB2A64F780A542E5238CE3F9952FD03277379B11529 ] AppID           C:\WINDOWS\system32\drivers\appid.sys
21:54:15.0030 0x1868  AppID - ok
21:54:15.0035 0x1868  [ C0DC3F58214A227980AEB091CFD2F973, 0C3E8453C9F65ADA3E74C38C0E3AC3E0CBFD807B827097046265B38839E151E3 ] AppIDSvc        C:\WINDOWS\System32\appidsvc.dll
21:54:15.0036 0x1868  AppIDSvc - ok
21:54:15.0042 0x1868  [ 8D6F535461F6CFF75A8ADDF83024C904, F2A97EC4A6284F28B685A3CE2D450F61E75EE8692D718A6AA352D5734BBBAD7B ] Appinfo         C:\WINDOWS\System32\appinfo.dll
21:54:15.0045 0x1868  Appinfo - ok
21:54:15.0059 0x1868  [ CB12C47647D8BDAFAA94C0856B14128B, 5590C98095357C92563EF94800107D3611AA6ECA1A70BE463C03B279E618A6C4 ] AppReadiness    C:\WINDOWS\system32\AppReadiness.dll
21:54:15.0068 0x1868  AppReadiness - ok
21:54:15.0098 0x1868  [ F7529BD3FFAC9C33D15F6DE3B7353B03, 8EF0A84C9687A246B60939A326E498121039E9CC617A7ABBA933EDD327F3467E ] AppXSvc         C:\WINDOWS\system32\appxdeploymentserver.dll
21:54:15.0118 0x1868  AppXSvc - ok
21:54:15.0127 0x1868  [ 65045784366F7EC5FB4E71BCF923187B, 53C215C64FF12E44B097F7CB88E8482438CE0ACBD3C68D8FD38BA0D0D8747FAA ] arcsas          C:\WINDOWS\system32\drivers\arcsas.sys
21:54:15.0129 0x1868  arcsas - ok
21:54:15.0134 0x1868  [ 74B14192CF79A72F7536B27CB8814FBD, 0CF6BBB63FFE0C12777664D80B2797923844C8392D0FD81D7962EE5EE2C3C3D9 ] atapi           C:\WINDOWS\system32\drivers\atapi.sys
21:54:15.0135 0x1868  atapi - ok
21:54:15.0145 0x1868  [ F83D49F4B10E813A1F9AC8B92F16592D, E7B2F508D33861A9826F2C7B2087F14F6937C9B8F660D6363F737BAC60BD4578 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll
21:54:15.0148 0x1868  AudioEndpointBuilder - ok
21:54:15.0168 0x1868  [ 9A71BD2E4B8EB550D0022AFDF8616014, 34D595684624114F23265CE8031ADC9E03AD374A5AFEEBB794AC57796A3CDA2F ] Audiosrv        C:\WINDOWS\System32\Audiosrv.dll
21:54:15.0183 0x1868  Audiosrv - ok
21:54:15.0199 0x1868  [ 8DDCC2A7AA316354C65D62C64BC508BE, F2EC1E95E8469D1AB679A2B9A3CC4A7614359A47FB06E206E3530CB81E60E6CC ] AVControlCenter C:\Program Files\Lenovo\Communications Utility\AVControlCenter32.exe
21:54:15.0208 0x1868  AVControlCenter - ok
21:54:15.0216 0x1868  [ 96E8CAF20FC4B6C31CAD7816A801EB78, E4870DB8FFBDCFEE98449338D0BDBF2DD0B5FEC75514E41C11A882BE6EB16833 ] AxInstSV        C:\WINDOWS\System32\AxInstSV.dll
21:54:15.0218 0x1868  AxInstSV - ok
21:54:15.0232 0x1868  [ A4A73F631FE2AA2826FBE4A399B04DEF, 973AACE8DC8DA669D0DF20F17EFDEEABB90AA046AC980948D16A62D39A606A79 ] b06bdrv         C:\WINDOWS\system32\drivers\bxvbda.sys
21:54:15.0240 0x1868  b06bdrv - ok
21:54:15.0248 0x1868  [ 8CC7F7E4AFCBA605921B137ED7992C68, 71406E6D6E9964740A6D90B05329D5492BB90AF40E0630CF2FBF4BA4BA14F2DD ] BasicDisplay    C:\WINDOWS\System32\drivers\BasicDisplay.sys
21:54:15.0249 0x1868  BasicDisplay - ok
21:54:15.0255 0x1868  [ 38A82F4EE8C416A6744B6D30381ED768, 9EAAE5F43BA09359130AC04B1DCA0F5D4DF32ED89C02DC5CEB640918948847F7 ] BasicRender     C:\WINDOWS\System32\drivers\BasicRender.sys
21:54:15.0256 0x1868  BasicRender - ok
21:54:15.0263 0x1868  [ C1ABB0F7E3BEA48A0417BDF6FF14AB21, 1CAC63A1A0FB9855A27EE977794576A860F6650C9EF7667FFB27F2A2FF721857 ] bcmfn2          C:\WINDOWS\System32\drivers\bcmfn2.sys
21:54:15.0263 0x1868  bcmfn2 - ok
21:54:15.0276 0x1868  [ 5BD3A2351BEFCAC8757626271F8EFA89, 6508673210129CF7EFCA93EC7874208FAD361E37814EB4FE9E0EC034E73D5F16 ] BDESVC          C:\WINDOWS\System32\bdesvc.dll
21:54:15.0282 0x1868  BDESVC - ok
21:54:15.0288 0x1868  [ EC19013E4CF87609534165DF897274D6, 8ED45537CF2D58D759A587CCBFDADD5580C7447B0C3B172CF19ECC7585E073FC ] Beep            C:\WINDOWS\system32\drivers\Beep.sys
21:54:15.0288 0x1868  Beep - ok
21:54:15.0307 0x1868  [ BBE15881FE11BE37112F8320C41DAFB9, 5CE92563628812FF6E00556D8E2DAD6ADCAAF0F4C3B90123F1D98ED6E3BB6DAD ] BFE             C:\WINDOWS\System32\bfe.dll
21:54:15.0319 0x1868  BFE - ok
21:54:15.0325 0x1868  [ 65406582EE12531AFEA3F7C5941744EA, 1283D3811AB3EB7559D0C5C9C57CCCECFCF7925F0B58C272EA6B12B72D823A3B ] BioNTDrv        C:\Program Files\Paragon Software\Backup and Recovery 14 Home\program\BioNTDrv.SYS
21:54:15.0326 0x1868  BioNTDrv - ok
21:54:15.0350 0x1868  [ 15225081966C785A9192782401643FD4, E2BA0C8D044556FDD9DD7A25F7F71553DE7A2924E78F9284413C2AC46F0BF4EB ] BITS            C:\WINDOWS\System32\qmgr.dll
21:54:15.0367 0x1868  BITS - ok
21:54:15.0393 0x1868  [ 4D87518BA68C308299441337C55F5427, AE46F847EE605213A3AE9BEFE5EB0B7B8D877340EA1A6CF9EF5683A02ECFE399 ] Bluetooth Device Monitor C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
21:54:15.0410 0x1868  Bluetooth Device Monitor - ok
21:54:15.0434 0x1868  [ 19786E2114E2FCB4EAA30808E9D4FB9A, FCBD15EA7CB0B22DA9ABFACF95DE877042201C85EBC219F5204E12F76E8DBC09 ] Bluetooth OBEX Service C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
21:54:15.0453 0x1868  Bluetooth OBEX Service - ok
21:54:15.0461 0x1868  [ 6B4FFFDDC618FCF64473CAA86E305697, 29EA66071D5822920F5C50533673ADAB5204F8B25C11027AD27450D881F1142D ] bowser          C:\WINDOWS\system32\DRIVERS\bowser.sys
21:54:15.0463 0x1868  bowser - ok
21:54:15.0472 0x1868  [ 190E0C4CD4E5B2BA9C39331E548EB9E5, BC2ED68FCF2BE09CB0BD4E05DD197BF3EF6E13B5BDE5EE9574BA27EED1BA1AA1 ] BrcmSetSecurity C:\Program Files\Intel Corporation\Intel WiDi\BrcmSetSecurity.exe
21:54:15.0477 0x1868  BrcmSetSecurity - ok
21:54:15.0500 0x1868  [ F2559A492AF8D653D1F47ADABA4C3E97, 77347915FB433023769699DFC9511F54E69C7FC7AB75F57FDC1A58E64A7126DE ] BrokerInfrastructure C:\WINDOWS\System32\bisrv.dll
21:54:15.0505 0x1868  BrokerInfrastructure - ok
21:54:15.0511 0x1868  [ D528D6A92D187777691993DD757AF19A, 2C79978310193431E5FC462368424A172858D5351C92D4815C2A7E35B5DDE50C ] Browser         C:\WINDOWS\System32\browser.dll
21:54:15.0513 0x1868  Browser - ok
21:54:15.0520 0x1868  [ 8F7A6409A76914E203423A384A4E1C11, 567D1B456F6457C2D2612D048B7E59C41504565E67BB7F349530249274BF3C3B ] BthA2DP         C:\WINDOWS\system32\drivers\BthA2DP.sys
21:54:15.0522 0x1868  BthA2DP - ok
21:54:15.0528 0x1868  [ A8F23D453A424FF4DE04989C4727ECC7, AE4A9081395C7379F1C947EF8243F7609F90C843E086B8E77E1A2C06E36D4381 ] BthAvrcpTg      C:\WINDOWS\System32\drivers\BthAvrcpTg.sys
21:54:15.0529 0x1868  BthAvrcpTg - ok
21:54:15.0535 0x1868  [ 131F1C8573E7BFB41C54FBF5309CCD94, DAFE51E3BADBD82A33B580F212B2D6520A120877C23F6D675521FEA2F4BA5A1F ] BthEnum         C:\WINDOWS\system32\DRIVERS\BthEnum.sys
21:54:15.0536 0x1868  BthEnum - ok
21:54:15.0542 0x1868  [ 746B9F94214915AECDE4B7FEA5FF9664, EA2877D49DB4B7B9CE61653D63E8776DFF1CBCCAB12C14DB1D20DA44B8F06357 ] BthHFEnum       C:\WINDOWS\System32\drivers\bthhfenum.sys
21:54:15.0544 0x1868  BthHFEnum - ok
21:54:15.0548 0x1868  [ 71FE2A48E4C93DDB9798C024880B6C07, 8E93DE29C61A5FA64216231228CB3C4A1A693FE87CAA2C070BCAD7BE2D8ED000 ] bthhfhid        C:\WINDOWS\System32\drivers\BthHFHid.sys
21:54:15.0549 0x1868  bthhfhid - ok
21:54:15.0557 0x1868  [ D30C67473A2E229662D21F27EAA9AAA5, D009C4836B0DFE963D8E3DEEDE611068838F2BBCAB146E6D70692FAB838E11F1 ] BthLEEnum       C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys
21:54:15.0561 0x1868  BthLEEnum - ok
21:54:15.0570 0x1868  [ 66B791F6B11DC4303DD18A224A501542, 502AE4D6FFC6B0FCED081B0E0F61F699F96F20DFEE737B53828F5DEE3BD0FCB1 ] BTHMODEM        C:\WINDOWS\System32\drivers\bthmodem.sys
21:54:15.0571 0x1868  BTHMODEM - ok
21:54:15.0579 0x1868  [ 3AFE71D80EDF5D4DE0C5731352905669, 3E370169B8C5D301954D1F1DA302F7A0DB2A034990E10B3D64458C48E5693205 ] BthPan          C:\WINDOWS\system32\DRIVERS\bthpan.sys
21:54:15.0581 0x1868  BthPan - ok
21:54:15.0611 0x1868  [ AB8CD3914AD779C15B27DDD9F53F7434, 6E9911C146A038192B95916387FA9D94D952BEFE158E6CBA44F1500A304221A3 ] BTHPORT         C:\WINDOWS\System32\Drivers\BTHport.sys
21:54:15.0631 0x1868  BTHPORT - ok
21:54:15.0639 0x1868  [ E5E48FEED73D463175EAB1542495191C, 0A8182F5BA7B694AB1DD3680F1194E4A568FE40DBA4BFDFF2EA09BAD045FFB29 ] bthserv         C:\WINDOWS\system32\bthserv.dll
21:54:15.0641 0x1868  bthserv - ok
21:54:15.0646 0x1868  [ 23E75BED9076F856B36F5F934BBD5795, CCEB72B788522B7D52A6C07646005EBC68F9599D3714ECACF3A194CA47A1BE85 ] BTHUSB          C:\WINDOWS\System32\Drivers\BTHUSB.sys
21:54:15.0647 0x1868  BTHUSB - ok
21:54:15.0655 0x1868  [ 4428C299BE7B9841ECFA82044B69FA6A, F8AB607D6CACBF2DDE3C392F9756B9F32CB99664A75F3140365CB916450660EC ] btmaux          C:\WINDOWS\system32\DRIVERS\btmaux.sys
21:54:15.0659 0x1868  btmaux - ok
21:54:15.0690 0x1868  [ 7B31A8A9DC95B3634D896FD0F2814F19, 8FD5FBC61968F4BB8C2BAD0D432D5B86DCFED38CCF6F559F9EFB71AADD25474F ] btmhsf          C:\WINDOWS\system32\DRIVERS\btmhsf.sys
21:54:15.0714 0x1868  btmhsf - ok
21:54:15.0721 0x1868  [ 2FA6510E33F7DEFEC03658B74101A9B9, 61C8C8E3F09B427711464C974EE22E1E01C48E10DB54A4EC9901F482FC36C978 ] cdfs            C:\WINDOWS\system32\DRIVERS\cdfs.sys
21:54:15.0723 0x1868  cdfs - ok
21:54:15.0729 0x1868  [ C6796EA22B513E3457514D92DCDB1A3D, 2B893F3950C6B913B934C2089B69F3B0B77F229AE1820907E598455CBB78139C ] cdrom           C:\WINDOWS\System32\drivers\cdrom.sys
21:54:15.0732 0x1868  cdrom - ok
21:54:15.0740 0x1868  [ AB285CE3431FF3D2ACE669245874C1C7, 6AF4C3E86EFA51F7FB6F8492CB2CCB807C7775EAE0508B87F07134FDAC679BD7 ] CertPropSvc     C:\WINDOWS\System32\certprop.dll
21:54:15.0742 0x1868  CertPropSvc - ok
21:54:15.0746 0x1868  [ BE9936EDD3267FAAFF94A7835867F00B, 3CEEF2377D45ED38C7CD3CE4C746EC5EA7277EFEC728A5438F0EF5F62FC7C859 ] circlass        C:\WINDOWS\System32\drivers\circlass.sys
21:54:15.0747 0x1868  circlass - ok
21:54:15.0760 0x1868  [ 179A41249055D5F039F1B6703F3B6D2B, 886CF715D9E85DB5C9B991EBCB9B12E27AA0EEE52528E222C80CA5B5B0A7AF52 ] CLFS            C:\WINDOWS\system32\drivers\CLFS.sys
21:54:15.0765 0x1868  CLFS - ok
21:54:15.0814 0x1868  [ 42BFD23D61E78268F33F0B0282B4A01E, 1803BD3C8E87B805620388C630AF099317AA32E284A264E2793383AB3E1237F1 ] ClickToRunSvc   C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe
21:54:15.0846 0x1868  ClickToRunSvc - ok
21:54:15.0861 0x1868  [ EF6EF85DADC3184A10D8F2F7159973CB, 42FCB286CED95A5DEBC5C0C894FCBC4818A2C818BB71087142FB51A08A0BE96B ] CmBatt          C:\WINDOWS\System32\drivers\CmBatt.sys
21:54:15.0862 0x1868  CmBatt - ok
21:54:15.0877 0x1868  [ 4627C1FBF2802425A408A2D2AF28CF85, 8B91C1BE1104BE93C0D689A20315FD106D89A076267493319B104EE73A90CDCB ] CNG             C:\WINDOWS\system32\Drivers\cng.sys
21:54:15.0886 0x1868  CNG - ok
21:54:15.0892 0x1868  [ 03AAED827C36F35D70900558B8274905, 8E44A23C6013FFAE7769F99CAA3B1D6288DE00A38937F9056903AC265B503AFA ] CompositeBus    C:\WINDOWS\System32\drivers\CompositeBus.sys
21:54:15.0893 0x1868  CompositeBus - ok
21:54:15.0899 0x1868  COMSysApp - ok
21:54:15.0905 0x1868  [ A1FF7DFBFBE164CF92603C651D304DD2, 470ACE5A75E64FC62C950037201199857E974803625DC73BEDBCF6FA4DDD496C ] condrv          C:\WINDOWS\system32\drivers\condrv.sys
21:54:15.0906 0x1868  condrv - ok
21:54:15.0928 0x1868  [ 6DB7264A95FE984FFA072BA79FA087C8, CF180663B24B1660CD04CB26D8663FB7F357C9CF5731B315635D63B7DB76BCEC ] cphs            C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
21:54:15.0934 0x1868  cphs - ok
21:54:15.0944 0x1868  [ 0EFE4B5884A8032617826A4D76F80969, 083D296CC623C83D36A97AEE343ADF819B17E490F931DBE4D161BD1E8C289E02 ] CryptSvc        C:\WINDOWS\system32\cryptsvc.dll
21:54:15.0946 0x1868  CryptSvc - ok
21:54:15.0951 0x1868  [ 315BA4BC19316D72B2E037534E048B93, 69613635DB23E6A935673B1025C2010ED3E195473D25368CF74234C4C36910BE ] dam             C:\WINDOWS\system32\drivers\dam.sys
21:54:15.0952 0x1868  dam - ok
21:54:15.0978 0x1868  [ 81979817943D830BF24571B7C1B28A1A, 9584D8F1FB3E6CF17BD465670B208C723A8E8B06775A3DA44F75D7710404EEA6 ] DcomLaunch      C:\WINDOWS\system32\rpcss.dll
21:54:15.0991 0x1868  DcomLaunch - ok
21:54:16.0005 0x1868  [ 78089FCDE082FD4FA471C30A7C2DC736, C4816D7125C39290C3B0B1F580CEE8BB7FFC004F727EA9E9767671D3EDB946AE ] defragsvc       C:\WINDOWS\System32\defragsvc.dll
21:54:16.0012 0x1868  defragsvc - ok
21:54:16.0024 0x1868  [ 8F387C2C99EE09C6E2AC316205F86A17, EC9E8AE72A21992AA118964E17090BA4503EB051273AD18185C95172F57328CE ] DeviceAssociationService C:\WINDOWS\system32\das.dll
21:54:16.0031 0x1868  DeviceAssociationService - ok
21:54:16.0038 0x1868  [ BC6849C62DB407573C6AD8CB1A4D2628, 5BDE0D60F85E4C27CEAD1B301155B54D841FB773BD5BB8AC5DDAEE31F8E94627 ] DeviceInstall   C:\WINDOWS\system32\umpnpmgr.dll
21:54:16.0041 0x1868  DeviceInstall - ok
21:54:16.0048 0x1868  [ A03F362C5557E238CBFA914689C77248, BAD0A1124E6A384C15028FBE121ADF650F7716442555AD3737B9EA1F58A69246 ] Dfsc            C:\WINDOWS\system32\Drivers\dfsc.sys
21:54:16.0051 0x1868  Dfsc - ok
21:54:16.0062 0x1868  [ 8B107F55FD61654A6C9F1B819AEC5FC4, 773B1B9D3583F17B7C89BDE1EC4487ABB0AE039DF4583F8746460425443DA291 ] Dhcp            C:\WINDOWS\system32\dhcpcore.dll
21:54:16.0068 0x1868  Dhcp - ok
21:54:16.0074 0x1868  [ 4D40C9B33F738797CF50E77CB7C53E85, 7BA341342A47DEB15B51971C97A5237ACD8BDAD9033F63DF0000892BE43F8E13 ] disk            C:\WINDOWS\system32\drivers\disk.sys
21:54:16.0076 0x1868  disk - ok
21:54:16.0244 0x1868  [ 1ECB3FA30B5AEADECC124BD479659C11, 0F8DA6BAE472533F7F338C9C71E5B050D85BD52DACA1C9133B9A24E4F4511B23 ] DisplayLinkService C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe
21:54:16.0379 0x1868  DisplayLinkService - ok
21:54:16.0393 0x1868  [ A858D4926CD003DA0FB17446593842AF, D8F8B7C249BDF8A9089D1E9D21D7E5AC9A3EA7F258EDB5E28AC815646D2B5D67 ] DisplayLinkUsbIo_x64 C:\WINDOWS\system32\DRIVERS\DisplayLinkUsbIo_x64_7.4.53134.0.sys
21:54:16.0394 0x1868  DisplayLinkUsbIo_x64 - ok
21:54:16.0399 0x1868  [ E21BDB9558BD7EC4ADA9514E97A0DCEF, FFB8496A031FBC6D8BD4322FF0B41A857ECB87C8DC09C99AAB0B365E6268AD5A ] dlcdcncm6_x64   C:\WINDOWS\system32\DRIVERS\dlcdcncm6_x64.sys
21:54:16.0401 0x1868  dlcdcncm6_x64 - ok
21:54:16.0411 0x1868  [ 8659706D79D2559F5DC1612B292FA4D2, D4C4123B66E81E1A8D292384BB81000377D403071BB46A52D9A54395B3F32C66 ] dlkmd           C:\WINDOWS\system32\drivers\dlkmd.sys
21:54:16.0417 0x1868  dlkmd - ok
21:54:16.0422 0x1868  [ 43AD7C0C07547A0F6FD921F417731ADF, 190EC0F5BC6159BDC4BE5F817A8B10CADFC38B2BEA4D1D18E6F0594939E0090E ] dlkmdldr        C:\WINDOWS\system32\drivers\dlkmdldr.sys
21:54:16.0423 0x1868  dlkmdldr - ok
21:54:16.0432 0x1868  [ 8E126666F8ABDDE0BFBB67D8A48F445D, 3315273B68D7DCA69775051D337F980457DD8F48C5C3E83613C5614DB82C74F6 ] dlusbaudio      C:\WINDOWS\system32\DRIVERS\dlusbaudio_x64.sys
21:54:16.0435 0x1868  dlusbaudio - ok
21:54:16.0440 0x1868  [ EB70A894708D1BC176AFD690FF06085F, 0DD2A97F5E1B38D1F7C0D44E50F09EA222B18B3B074CC9C8CD25A7526CB1A112 ] dmvsc           C:\WINDOWS\System32\drivers\dmvsc.sys
21:54:16.0441 0x1868  dmvsc - ok
21:54:16.0450 0x1868  [ FE7656474448BE6A6C68E5C9BEB7CA94, 8B9F04CAA29A6EEFCA3D1E7BAFE340D5CCA8AF665474E69B1DF7E2A518B83A89 ] Dnscache        C:\WINDOWS\System32\dnsrslvr.dll
21:54:16.0455 0x1868  Dnscache - ok
21:54:16.0466 0x1868  [ 50288EA079BB520C2B8C8A154202D518, 8916A9180CA009D124FFDFB4CCF5FDFEF7FA2FD37CBCD49FAD4C68E051B4734D ] dot3svc         C:\WINDOWS\System32\dot3svc.dll
21:54:16.0470 0x1868  dot3svc - ok
21:54:16.0479 0x1868  [ 281BEE07BA97E3E98D12A822D923D0D8, 6EB482B2D4D6048D145C3738B2B6FA27A90B5EA53E9167447820F9981B004E63 ] DPS             C:\WINDOWS\system32\dps.dll
21:54:16.0482 0x1868  DPS - ok
21:54:16.0485 0x1868  [ DDC11A202207C0400CBE07315B8FDE5E, 3ED0CA3A714582D92001BA3BFF78BE082F4DC8021298D5A2632F3B2B0A1C09DC ] drmkaud         C:\WINDOWS\system32\drivers\drmkaud.sys
21:54:16.0487 0x1868  drmkaud - ok
21:54:16.0495 0x1868  [ 5B074F14F5DD6418F46EE4CA2DEB7EA8, B8223D73C3DE123759101F7D5D45C60BD12B221F09D349575A1044CE3F43CBC5 ] DsmSvc          C:\WINDOWS\System32\DeviceSetupManager.dll
21:54:16.0499 0x1868  DsmSvc - ok
21:54:16.0538 0x1868  [ C7D252742946DD395670649742FBD73D, 333CC984CF318D36EA8C5867077A1732A214445EB6B7CF7AC2E8F1C8259CD9C7 ] DXGKrnl         C:\WINDOWS\System32\drivers\dxgkrnl.sys
21:54:16.0560 0x1868  DXGKrnl - ok
21:54:16.0576 0x1868  [ 4787BD0EED0E035EEA85625FB5F1F77E, B79E998CCC9D0D6D431645C87C7802AE90FE1A2522BD77EB16CDBF65F6F88507 ] e1dexpress      C:\WINDOWS\system32\DRIVERS\e1d64x64.sys
21:54:16.0583 0x1868  e1dexpress - ok
21:54:16.0589 0x1868  [ 6073537F250B45E1CB2A02E97F0FE1B2, 653F3F2F2019168EDF225944A88AFDBF8393B62AA076BD19980691778F3DB67D ] Eaphost         C:\WINDOWS\System32\eapsvc.dll
21:54:16.0591 0x1868  Eaphost - ok
21:54:16.0657 0x1868  [ 114BCFDF367FF37C3F1B0A96AF542E4D, D385BC1D91BC1406091C8C3691C07A90BD60EDE05B1384E5AA3506FCB909C857 ] ebdrv           C:\WINDOWS\system32\drivers\evbda.sys
21:54:16.0706 0x1868  ebdrv - ok
21:54:16.0715 0x1868  [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] EFS             C:\WINDOWS\System32\lsass.exe
21:54:16.0716 0x1868  EFS - ok
21:54:16.0722 0x1868  [ 43531A5993380CC5113242C29D265FD9, EE0076D96F7F3CF29884AC7A67C08A429115A7201354A1FB5DE45FD63ABB4960 ] EhStorClass     C:\WINDOWS\system32\drivers\EhStorClass.sys
21:54:16.0723 0x1868  EhStorClass - ok
21:54:16.0729 0x1868  [ 6F8E738A9505A388B1157FDDE7B3101B, 3696CA634102B41EEA11EB9DCA0B24439D8636AED4A7190C138C5E64A2EFB514 ] EhStorTcgDrv    C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys
21:54:16.0731 0x1868  EhStorTcgDrv - ok
21:54:16.0737 0x1868  [ DFFFAE1442BA4076E18EED5E406FA0D3, 329FC6FB8D14BEACDBE2A5D4C496EDEA485E838B1DF27566E278F8F8E0D8E82E ] ErrDev          C:\WINDOWS\System32\drivers\errdev.sys
21:54:16.0737 0x1868  ErrDev - ok
21:54:16.0753 0x1868  [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3, 5264734F0572FAEDCCB008221C9982CCB7922C4FFC358605424EA413CDCDAE99 ] EventSystem     C:\WINDOWS\system32\es.dll
21:54:16.0760 0x1868  EventSystem - ok
21:54:16.0778 0x1868  [ C8559336BB21FF701CBEF14527D7660F, AE8CD6514C0B121B260D9101D76E6225599B832504EB5719FD110E348C9E6682 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
21:54:16.0788 0x1868  EvtEng - ok
21:54:16.0796 0x1868  [ 7729D294A555C7AEB281ED8E4D0E01E4, 7269E79D72CCE477AC108294D0DDFB59CF533B03C587599C5AB0507C43A0B6D4 ] exfat           C:\WINDOWS\system32\drivers\exfat.sys
21:54:16.0799 0x1868  exfat - ok
21:54:16.0804 0x1868  [ 785DA3D712E5901E5C4BC0A778F212AD, 6C46363DB905B6EB3C6A4E3CBD80C98113ED44115CE6F149243B434CF59135C5 ] Fastboot        C:\WINDOWS\system32\DRIVERS\fastboot.sys
21:54:16.0805 0x1868  Fastboot - ok
21:54:16.0811 0x1868  [ 8863371E7FDDAFDB2E40D4009D00C507, 89125FF0CD6CEC1996BCBD0644B90C451AB43F0D4C45BDB9237C305AA776A6E6 ] FastbootService C:\Program Files (x86)\Lenovo\RapidBoot HDD Accelerator\FBService.exe
21:54:16.0815 0x1868  FastbootService - ok
21:54:16.0824 0x1868  [ 7C4E0D5900B2A1D11EDD626D6DDB937B, 732F310F8F6016C56F432A81636B13CE0124A802FE8DD91287B618EED22C9A1D ] fastfat         C:\WINDOWS\system32\drivers\fastfat.sys
21:54:16.0828 0x1868  fastfat - ok
21:54:16.0844 0x1868  [ 2BC8532ABF2B3756B78FA1DA54147DDE, DF65EE2AB0255A2CF3221085A6BE7C37E3DB6BFEED3BCADCDD69BB1049F6DCB1 ] Fax             C:\WINDOWS\system32\fxssvc.exe
21:54:16.0858 0x1868  Fax - ok
21:54:16.0863 0x1868  [ 5D8402613E778B3BD45E687A8372710B, EE9EA10805168D309A609B9019AEC5961EE46D18207B5E0EA2DE4064A5770AF8 ] fdc             C:\WINDOWS\System32\drivers\fdc.sys
21:54:16.0864 0x1868  fdc - ok
21:54:16.0869 0x1868  [ DC1A78BCCCB7EE53D6FD3BD615A8E222, EE16B6853185AAE779D7135035983938009901658F76A8856AAC12EBA15BB34E ] fdPHost         C:\WINDOWS\system32\fdPHost.dll
21:54:16.0870 0x1868  fdPHost - ok
21:54:16.0874 0x1868  [ E5AD448F2DC84B1CF387FA7F2A3D1936, BBB29C79A085C503F5EFFB5144596D5DEC48A4EB34A049A4E7B38B27F6D92E0A ] FDResPub        C:\WINDOWS\system32\fdrespub.dll
21:54:16.0875 0x1868  FDResPub - ok
21:54:16.0882 0x1868  [ 0046E0BD031213D37123876B0D0FA61C, A4FE17D56F0BAFB70D0D421ED9D1B6E50AF8ADAA4B59328A41AEC5B4C068A3CB ] fhsvc           C:\WINDOWS\system32\fhsvc.dll
21:54:16.0885 0x1868  fhsvc - ok
21:54:16.0890 0x1868  [ BCFD8B149B3ADF92D0DB1E909CAF0265, 002B085C131473642450176B4B8359F3E5B04350AFB659B9C0F9EB587D1181E7 ] FileInfo        C:\WINDOWS\system32\drivers\fileinfo.sys
21:54:16.0892 0x1868  FileInfo - ok
21:54:16.0899 0x1868  [ A1A66C4FDAFD6B0289523232AFB7D8AF, 0F5832F626BB62190D5F3A088CE6E048D8A400CCF9EA527F06973CAD96D3A81C ] Filetrace       C:\WINDOWS\system32\drivers\filetrace.sys
21:54:16.0900 0x1868  Filetrace - ok
21:54:16.0905 0x1868  [ BE743083CF7063C486A4398E3AEFE59A, 85796D89943DD6FE3932C1ED6CF01470C1B4DFD243C390B07055FFDA3C231551 ] flpydisk        C:\WINDOWS\System32\drivers\flpydisk.sys
21:54:16.0906 0x1868  flpydisk - ok
21:54:16.0917 0x1868  [ 46D1DF775FFF14585218BBE16E5B2C9A, F39EF615B18CEC7BA3F68C7639B636C06812AD9DBEDE90EB7B2C04C64396FC9E ] FltMgr          C:\WINDOWS\system32\drivers\fltmgr.sys
21:54:16.0922 0x1868  FltMgr - ok
21:54:16.0952 0x1868  [ 183CA7699474FDE235853967D1DA4D9B, 8FBD5997F1E39AFFD8C4322520DF4D2227279B5149017D825C188D7411BA99AF ] FontCache       C:\WINDOWS\system32\FntCache.dll
21:54:16.0972 0x1868  FontCache - ok
21:54:16.0982 0x1868  [ 1C52387BF5A127F5F3BFB31288F30D93, 90D13F60170CD74304F3036A90D596AA3E1E134455A780310BDF67AC7815F2E7 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:54:16.0983 0x1868  FontCache3.0.0.0 - ok
21:54:16.0988 0x1868  [ 35005534E600E993A90B036E4E599F2B, DA56FA3776FBD3D50276CB7410E0CB6F137DD8FCA84C0F3FEF8B1FEA5F6CA592 ] FsDepends       C:\WINDOWS\system32\drivers\FsDepends.sys
21:54:16.0990 0x1868  FsDepends - ok
21:54:16.0995 0x1868  [ 09F460AFEDCA03F3BF6E07D1CCC9AC42, B832091BC9B2C2FE38A4BCA132ABB58251E851F21EC6F39636E73777AB9A5791 ] Fs_Rec          C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:54:16.0995 0x1868  Fs_Rec - ok
21:54:17.0011 0x1868  [ B2BD017231836DA9F63F41E3A075D73E, 31B1DD677FE8B4F90B8AB5A131DA0105439AC2D91BC0CEDC972D2D87E595A686 ] fvevol          C:\WINDOWS\system32\DRIVERS\fvevol.sys
21:54:17.0021 0x1868  fvevol - ok
21:54:17.0026 0x1868  [ 9591D0B9351ED489EAFD9D1CE52A8015, AC64C236C3AE545FCE8ED44A4A87FB86265A453BA60026EC9A4DE2B631E99996 ] FxPPM           C:\WINDOWS\System32\drivers\fxppm.sys
21:54:17.0027 0x1868  FxPPM - ok
21:54:17.0033 0x1868  [ FC3EF65EE20D39F8749C2218DBA681CA, 12980F1DE99B25E6920A33556F3ABDA5EC9BFE4757BE602130B5E939D8D25CE3 ] gagp30kx        C:\WINDOWS\system32\drivers\gagp30kx.sys
21:54:17.0034 0x1868  gagp30kx - ok
21:54:17.0039 0x1868  [ 0BF5CAD281E25F1418E5B8875DC5ADD1, 0929AD8437DD78234553D8B2CDF0D6838FD54ACDE1918AFEBE48684EB32A07A3 ] gencounter      C:\WINDOWS\System32\drivers\vmgencounter.sys
21:54:17.0040 0x1868  gencounter - ok
21:54:17.0047 0x1868  [ EF3AE7773394DF49CE74AF78A1C8D23D, CB12FF004C460A89F12AFF2467512B479A07CA10D4280CD4E624A5A9CDAB9C1B ] GPIOClx0101     C:\WINDOWS\system32\Drivers\msgpioclx.sys
21:54:17.0050 0x1868  GPIOClx0101 - ok
21:54:17.0079 0x1868  [ 58C11DCCC6241CC13861A559E31A69F0, 78B38BBC362C9209B06849CC79301EC595AFCE3E2BDE402A0B1F2725D3EDEFA3 ] gpsvc           C:\WINDOWS\System32\gpsvc.dll
21:54:17.0100 0x1868  gpsvc - ok
21:54:17.0107 0x1868  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:54:17.0109 0x1868  gupdate - ok
21:54:17.0114 0x1868  [ 506708142BC63DABA64F2D3AD1DCD5BF, 9C36A08D9E7932FF4DA7B5F24E6B42C92F28685B8ABE964C870E8D7670FD531A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:54:17.0115 0x1868  gupdatem - ok
21:54:17.0121 0x1868  [ 03909BDBFF0DCACCABF2B2D4ADEE44DC, 42E631B23BB004F5C2128BAD334C21AB20FAD08AFED9E8191AE9373531BC73DD ] HDAudBus        C:\WINDOWS\System32\drivers\HDAudBus.sys
21:54:17.0124 0x1868  HDAudBus - ok
21:54:17.0128 0x1868  [ 10A70BC1871CD955D85CD88372724906, 2480A74854D0A89FF028EE9BA41224D4B2F9B0863066BFC43097920794FEE08D ] HidBatt         C:\WINDOWS\System32\drivers\HidBatt.sys
21:54:17.0129 0x1868  HidBatt - ok
21:54:17.0134 0x1868  [ 1EA1B4FABB8CC348E73CA90DBA22E104, 5C18C6BD499272F216DD4626B5E8D38181AEAC9AD917FBEB614A75B70467B258 ] HidBth          C:\WINDOWS\System32\drivers\hidbth.sys
21:54:17.0137 0x1868  HidBth - ok
21:54:17.0141 0x1868  [ C241A8BAFBBFC90176EA0F5240EACC17, 571E20B87818618BE9179986177D55739A240F04D1F740B3C1B7809B9427B767 ] hidi2c          C:\WINDOWS\System32\drivers\hidi2c.sys
21:54:17.0142 0x1868  hidi2c - ok
21:54:17.0147 0x1868  [ 9BDDEE26255421017E161CCB9D5EDA95, B766FD5E31708F29384F69418FC33C4BCC6E3064AA553D5B1D30EE0B8B1BFB40 ] HidIr           C:\WINDOWS\System32\drivers\hidir.sys
21:54:17.0148 0x1868  HidIr - ok
21:54:17.0154 0x1868  [ 449A20A674AA3FAA7F0DD4E33EE2DC20, 28B9BDA306456E8640C355718DE3477537B0FAF8C37F633C709129AAB64D9873 ] hidserv         C:\WINDOWS\system32\hidserv.dll
21:54:17.0155 0x1868  hidserv - ok
21:54:17.0160 0x1868  [ 8DB8EAB9D0C6A5DF0BDCADEA239220B4, EDA23E6909EB83E5E148816DFB16CC29EA01BD6BD2F73AA46B3D820B85FB9C83 ] HidUsb          C:\WINDOWS\System32\drivers\hidusb.sys
21:54:17.0161 0x1868  HidUsb - ok
21:54:17.0166 0x1868  [ 7BF3ADCBD021D4F4A84CF40EB49C71B5, 5758A51FD2EBE67E6DBE3A298D714D351910F9E01C428D0C1359457C9242B298 ] hkmsvc          C:\WINDOWS\system32\kmsvc.dll
21:54:17.0170 0x1868  hkmsvc - ok
21:54:17.0180 0x1868  [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18, 46BF4A968E506DE17CA401401D716B444CDC10A5C60EB081890DD4B886AEDF5F ] HomeGroupListener C:\WINDOWS\system32\ListSvc.dll
21:54:17.0185 0x1868  HomeGroupListener - ok
21:54:17.0196 0x1868  [ 1A4DA1D6287B99033D144B436C23B656, D4D1EEB372E61512EA36A33F095E68C225B8E6C72CC57ED8BD00533F88012F40 ] HomeGroupProvider C:\WINDOWS\system32\provsvc.dll
21:54:17.0205 0x1868  HomeGroupProvider - ok
21:54:17.0210 0x1868  [ A6AACEA4C785789BDA5912AD1FEDA80D, D197012A5DA6AB3F76FF298336DF0CF027C07ECC71267BAEF5912DE12893E096 ] HpSAMD          C:\WINDOWS\system32\drivers\HpSAMD.sys
21:54:17.0211 0x1868  HpSAMD - ok
21:54:17.0234 0x1868  [ 9DDCA7F18983C5410DEFF79F819DF93C, CE97B4440377BFC5CA81BB600C3BD1DD9FB3951CA1EB70735F5E2050EBB74223 ] HTTP            C:\WINDOWS\system32\drivers\HTTP.sys
21:54:17.0249 0x1868  HTTP - ok
21:54:17.0254 0x1868  [ 90656C0B3864804B090434EFC582404F, BDB60050B729AACB9E009AC7129BEBD6298BBD8A9DB14B817D02E8E13669BD6E ] hwpolicy        C:\WINDOWS\system32\drivers\hwpolicy.sys
21:54:17.0255 0x1868  hwpolicy - ok
21:54:17.0261 0x1868  [ 6D6F9E3BF0484967E52F7E846BFF1CA1, C982966BDE6A3E6773D9441ADA7A3B08D13511DFC68D04DF303248B942423F38 ] hyperkbd        C:\WINDOWS\System32\drivers\hyperkbd.sys
21:54:17.0262 0x1868  hyperkbd - ok
21:54:17.0267 0x1868  [ 907C870F8C31F8DDD6F090857B46AB25, 308664A31717383D06185875E76C6612407A9F04E7DB28404F574A5706C6715D ] HyperVideo      C:\WINDOWS\system32\DRIVERS\HyperVideo.sys
21:54:17.0268 0x1868  HyperVideo - ok
21:54:17.0273 0x1868  [ 84CFC5EFA97D0C965EDE1D56F116A541, 0155EA62BF07D99D98D1C9B6559C8E3301B016A20D03DF1EF64B2FAB8C37403B ] i8042prt        C:\WINDOWS\System32\drivers\i8042prt.sys
21:54:17.0275 0x1868  i8042prt - ok
21:54:17.0283 0x1868  [ 5D90E32E36CE5D4C535D17CE08AEAF05, 976A463343E8C8308AFBE9E64DF56C430D2241DE002430D00318AB065EB72E4A ] iaLPSSi_GPIO    C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys
21:54:17.0284 0x1868  iaLPSSi_GPIO - ok
21:54:17.0290 0x1868  [ DD05E7E80F52ADE9AEB292819920F32C, E71AB6A50B0F90C8F94569CE89F66F915A0A4A00D4AC091B2E5E750D88CFC334 ] iaLPSSi_I2C     C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys
21:54:17.0292 0x1868  iaLPSSi_I2C - ok
21:54:17.0310 0x1868  [ 8BE099617DA18FE085A40D47FC156B1B, A5F7AB41D32DF8A12F1945C263EE954CE15069C3CFD7131C74A8A3F4EC3AC122 ] iaStorA         C:\WINDOWS\system32\drivers\iaStorA.sys
21:54:17.0321 0x1868  iaStorA - ok
21:54:17.0338 0x1868  [ 08BFE413B0B4AA8DFA4B5684CE06D3DC, 95DEEBB203E12EE6E191F5247A74C04AEC0E16DE981FADDC4D6C42EE41D8D079 ] iaStorAV        C:\WINDOWS\system32\drivers\iaStorAV.sys
21:54:17.0350 0x1868  iaStorAV - ok
21:54:17.0366 0x1868  [ A2200C3033FA4EF249FC096A7A7D02A2, 5819F5C2020DE2EEE339B0C08CD4B1E3490EAFBBEA1277CE649DB5A5150986B0 ] iaStorV         C:\WINDOWS\system32\drivers\iaStorV.sys
21:54:17.0373 0x1868  iaStorV - ok
21:54:17.0381 0x1868  [ 6C7FE2FD06EF34A7972E34C876FC78DF, B545A10DEEF59B8145D3D20361DA7F1C0FD27B6273B126B500594D6456C3FC06 ] IBMPMDRV        C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys
21:54:17.0389 0x1868  IBMPMDRV - ok
21:54:17.0396 0x1868  [ 5A1E3B4BA187327DF5FF122F96FA753A, AED93AA268F75D46752FCE5189392EE41225DA45F7D67C73B77629C8227E5084 ] IBMPMSVC        C:\WINDOWS\system32\ibmpmsvc.exe
21:54:17.0399 0x1868  IBMPMSVC - ok
21:54:17.0406 0x1868  [ 8B8674AEBAB18B2F422C5FDFA3A48E33, 7257B91408F431401FF50D70C5724D3B18AC226AE4B85ADDC04A5357FF67ACBF ] ibtusb          C:\WINDOWS\system32\DRIVERS\ibtusb.sys
21:54:17.0419 0x1868  ibtusb - ok
21:54:17.0422 0x1868  IEEtwCollectorService - ok
21:54:17.0508 0x1868  [ 0AECABC08F9AB4E504935B7662123B6E, 79D1C801A8FB0920469D6088158C518481485A065E8AF2E580FE4FCC1DE8F39B ] igfx            C:\WINDOWS\system32\DRIVERS\igdkmd64.sys
21:54:17.0608 0x1868  igfx - ok
21:54:17.0619 0x1868  [ E18725531054FE222115873AC1CCB02B, 0FC4B9D5DF77E19E4732759B848B4BCBBD44A124304FA8333BB3B7BC37E15FB8 ] ikbevent        C:\WINDOWS\system32\DRIVERS\ikbevent.sys
21:54:17.0626 0x1868  ikbevent - ok
21:54:17.0651 0x1868  [ CFE7F0267B0C3077042FF291949B5546, 7B8C432632D0210119BFF57D4994F2B8F75307A9D6867353AF93BBA3F561595B ] IKEEXT          C:\WINDOWS\System32\ikeext.dll
21:54:17.0685 0x1868  IKEEXT - ok
21:54:17.0689 0x1868  [ 45060257BCA3D60204FEC29F6E6DE458, C9FB92FEEFC0DC5386B545A8E429D60B932360B9044A920F6F2EDD5CF3B7B5A0 ] imsevent        C:\WINDOWS\system32\DRIVERS\imsevent.sys
21:54:17.0700 0x1868  imsevent - ok
21:54:17.0706 0x1868  [ F0F581A2299CB2BAB1DF2597BCDDB80F, EE485AF3049C87666BC6D6BFFC8A0EB4B95831D9061EB81848ECEE29C4232BF4 ] intaud_WaveExtensible C:\WINDOWS\system32\drivers\intelaud.sys
21:54:17.0717 0x1868  intaud_WaveExtensible - ok
21:54:17.0794 0x1868  [ 70DD225646BF84233E18890583E57EFB, 657CFBEBE5C131873BB0B28F6C719772E19D51B48A795E459C388C8EC5EE655B ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTKVHD64.sys
21:54:17.0874 0x1868  IntcAzAudAddService - ok
21:54:17.0891 0x1868  [ EEE7376243CD8A4B49B885EF122D25E5, A3B89E7B513C95558C4DA41D3C136D464381263BA43E00EC136FC776DAA0BA94 ] IntcDAud        C:\WINDOWS\system32\DRIVERS\IntcDAud.sys
21:54:17.0910 0x1868  IntcDAud - ok
21:54:17.0928 0x1868  [ 0DB1E3F6189C628675F855C0EB510419, 989F539E82105019D2D81255369B96DC65826CD2A421DA09809155B26F69C555 ] Intel® Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe
21:54:17.0942 0x1868  Intel® Capability Licensing Service Interface - ok
21:54:17.0965 0x1868  [ 492AAF2FF66F437F0E796574B116EFC3, 6BF21C61ED05705DD58203952A750D1AB4D4B62F3A2B640BBBD9B85D1ECC3E5C ] Intel® Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
21:54:18.0535 0x1868  Intel® Capability Licensing Service TCP IP Interface - ok
21:54:18.0544 0x1868  [ 6D754F5A8608B71DFAF187C1CDAB6BCA, 43C95FB18086BB5922DE37881B8296F5126B7F614EDBEF18A443C9B7DBB0E8D7 ] Intel® Wireless Bluetooth® 4.0 Radio Management C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
21:54:18.0547 0x1868  Intel® Wireless Bluetooth® 4.0 Radio Management - ok
21:54:18.0552 0x1868  [ F50B2E914B62CE536692FEDD7C81B0D1, ECAA415DB861CAED30BC40F8236C7DC13059BD5B8E4D5021887A902F8F8C38E3 ] IntelHSWPcc     C:\WINDOWS\system32\drivers\IntelPcc.sys
21:54:18.0565 0x1868  IntelHSWPcc - ok
21:54:18.0569 0x1868  [ 4E448FCFFD00E8D657CD9E48D3E47157, 4A958CF0BF8DAEAE5E008500BA67CE89B21388592811274331EE39CAC1043A00 ] intelide        C:\WINDOWS\system32\drivers\intelide.sys
21:54:18.0570 0x1868  intelide - ok
21:54:18.0576 0x1868  [ 139CFCDCD36B1B1782FD8C0014AC9B0E, E0D7E0E9B46A8CECE138D689820023BFA650FB689E4FD62855BED37E04F2D9FF ] intelpep        C:\WINDOWS\system32\drivers\intelpep.sys
21:54:18.0578 0x1868  intelpep - ok
21:54:18.0583 0x1868  [ 47E74A8E53C7C24DCE38311E1451C1D9, 79B06E37A552C8A847404D4C572CDB8CF525354D8AE3BEBC06892B7C3B330761 ] intelppm        C:\WINDOWS\System32\drivers\intelppm.sys
21:54:18.0586 0x1868  intelppm - ok
21:54:18.0591 0x1868  [ 9DB76D7F9E4E53EFE5DD8C53DE837514, 07BA4EDA9BE9139A689A2C3EFC1D1A4F3D1216625ED145F313398292A2CD5703 ] IpFilterDriver  C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:54:18.0593 0x1868  IpFilterDriver - ok
21:54:18.0614 0x1868  [ DFC4050D58565ADBEE793A8D4AEBDAE6, 89B900408F030CD45753A11D6AE6CBAB87E8B0E3F8401402D2D8713C045BF488 ] iphlpsvc        C:\WINDOWS\System32\iphlpsvc.dll
21:54:18.0631 0x1868  iphlpsvc - ok
21:54:18.0637 0x1868  [ FD9C9E9E3F0ED51502C7E8C066BE26B9, 290E74380F1543DD22C9F3821513B3E2FB42E995724238D8779CBBCB4FC386C8 ] IPMIDRV         C:\WINDOWS\System32\drivers\IPMIDrv.sys
21:54:18.0645 0x1868  IPMIDRV - ok
21:54:18.0651 0x1868  [ B7342B3C58E91107F6E946A93D9D4EFD, D5DA3C02C5C5A343785745EF6983CC9B5FBD3FB8D49FE9B450523E50212D1A32 ] IPNAT           C:\WINDOWS\system32\drivers\ipnat.sys
21:54:18.0654 0x1868  IPNAT - ok
21:54:18.0659 0x1868  [ AE44C526AB5F8A487D941CEB57B10C97, A783A2EAF7A6FF450FB3F189A5930036FA60D125C42171AC44B6FE2E3DBD6F7A ] IRENUM          C:\WINDOWS\system32\drivers\irenum.sys
21:54:18.0660 0x1868  IRENUM - ok
21:54:18.0663 0x1868  [ 8AFEEA3955AA43616A60F133B1D25F21, E99359A4F1D653790133F145CF7C9F97399FD75C5E135AA7E5F989BB660789AF ] isapnp          C:\WINDOWS\system32\drivers\isapnp.sys
21:54:18.0664 0x1868  isapnp - ok
21:54:18.0675 0x1868  [ 034D4BD9DC67C64F3A4C8A049B5173BF, C68AF5A5AD4092AA1C871BD38473AEF84EC3ECF4D06FBEB5F6C09972EF1B8A81 ] iScsiPrt        C:\WINDOWS\System32\drivers\msiscsi.sys
21:54:18.0681 0x1868  iScsiPrt - ok
21:54:18.0687 0x1868  [ 4EE2423C38F43D37F8497A672FD10BDC, 031C5272DD28809255CF4FA8E6DE45DBFBD9A363BBD5156D0AEE0787C4297980 ] ISCT            C:\WINDOWS\System32\drivers\ISCTD64.sys
21:54:18.0696 0x1868  ISCT - ok
21:54:18.0703 0x1868  [ 6E5767C95F746B6834F412CDBDCFEC48, DE4FC70159D0A4C0B15DE8F69554F8FF6EED9C6480C0CBE33BF74FCB0BD975FE ] ISCTAgent       C:\Program Files\Intel\Intel® Smart Connect Technology Agent\iSCTAgent.exe
21:54:18.0707 0x1868  ISCTAgent - ok
21:54:18.0711 0x1868  [ C2BC9AC9C6514230A481BDCA6A24BEFD, 84E41675D11EF2EEECED23C8469503C8D12810A2C6B6743D7AA322EB6DF7E68D ] iwdbus          C:\WINDOWS\System32\drivers\iwdbus.sys
21:54:18.0719 0x1868  iwdbus - ok
21:54:18.0728 0x1868  [ F1E91B70B6312F97749F0DBECB56E783, 67135609D1B8436E0E470660FBB1D29D9C9D0E0A1DF91FA47021E20C0AEE0EEF ] jhi_service     C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
21:54:18.0732 0x1868  jhi_service - ok
21:54:18.0738 0x1868  [ 8BE92376799B6B44D543E8D07CDCF885, 425B8BB1BAF62F735B3CB5A002E6055879F02E7207E55942BFD37F1784F5F368 ] kbdclass        C:\WINDOWS\System32\drivers\kbdclass.sys
21:54:18.0739 0x1868  kbdclass - ok
21:54:18.0743 0x1868  [ FB6E47E569D4872ABEB506BE03A45FBA, 5C4056CADA8F67587A119D9AE2A0EFAB30387CF6298F4019FF68AC92E2F6F54B ] kbdhid          C:\WINDOWS\System32\drivers\kbdhid.sys
21:54:18.0744 0x1868  kbdhid - ok
21:54:18.0748 0x1868  [ 813871C7D402A05F2E3A7075F9584A05, FF0C2F87EB083F8CE74C679D80C845CDFBFBBC70BE818F899F3336BBB54A3FFB ] kdnic           C:\WINDOWS\system32\DRIVERS\kdnic.sys
21:54:18.0750 0x1868  kdnic - ok
21:54:18.0754 0x1868  [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] KeyIso          C:\WINDOWS\system32\lsass.exe
21:54:18.0755 0x1868  KeyIso - ok
21:54:18.0761 0x1868  [ ADDECBCC777665BD113BED437E602AB0, B6283475A1219CE44E9F683DD3BEB8C42DA0943297E5C4699B22176AD8A6A7ED ] KSecDD          C:\WINDOWS\system32\Drivers\ksecdd.sys
21:54:18.0763 0x1868  KSecDD - ok
21:54:18.0770 0x1868  [ F88CC88F4A6D8476F1664E805CA18CC2, 2C61EE5EEA4FD45AA3FA927CC16E34EF90BD44324EAB14198AF65C3A27617991 ] KSecPkg         C:\WINDOWS\system32\Drivers\ksecpkg.sys
21:54:18.0774 0x1868  KSecPkg - ok
21:54:18.0778 0x1868  [ 11AFB527AA370B1DAFD5C36F35F6D45F, 757AD234284467ADB826F7CA0251F58D48866B91995BC867DEA4BAF676947163 ] ksthunk         C:\WINDOWS\system32\drivers\ksthunk.sys
21:54:18.0780 0x1868  ksthunk - ok
21:54:18.0790 0x1868  [ 32B1A8351160F307A8C66BCB0F94A9C2, 52F1DEC2BBD4D5DDBB85ED20B99D96BBA7EB83304D76F183A11FDAFDA364E873 ] KtmRm           C:\WINDOWS\system32\msdtckrm.dll
21:54:18.0798 0x1868  KtmRm - ok
21:54:18.0808 0x1868  [ 27B58E16CF895AC1F1A97C04814C2239, D4336155331DDBF91952CDC6C446C68FF524F979099BA8D9B3A578758F97B2BE ] LanmanServer    C:\WINDOWS\system32\srvsvc.dll
21:54:18.0816 0x1868  LanmanServer - ok
21:54:18.0828 0x1868  [ D0D9C2ECA4D03A8F06DCD91236B90C98, E2D1144DC8040EA5FEB0602A20BA4CB920B4BC86AD5AD05FC0DF7D74DC95DC66 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll
21:54:18.0835 0x1868  LanmanWorkstation - ok
21:54:18.0877 0x1868  [ 1C506C379D77C9B23F7D898ECBC4EAAE, 4166C1B9890A292853EC6490FB0F97B3F669E7E1E12150FC8C55D1C7700531C0 ] Lenovo Settings Service C:\Program Files\Lenovo\SettingsDependency\SettingsService.exe
21:54:18.0920 0x1868  Lenovo Settings Service - ok
21:54:18.0948 0x1868  [ 623CB981AE1742BB99D934884443C4EF, 6A96F171BAB219A62E65EFB3817901DB254456EDE53C4FF2446877442BC23E25 ] LENOVO.CAMMUTE  C:\Program Files\Lenovo\Communications Utility\cammute.exe
21:54:18.0971 0x1868  LENOVO.CAMMUTE - ok
21:54:18.0983 0x1868  [ F43BD5D437A3F8EA438A23FB04ABBB73, 8EB53DECFFB07C7BBB09E42493ADA63503662E69EF3D19EAAC806D7B29701188 ] LENOVO.MICMUTE  C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
21:54:18.0987 0x1868  LENOVO.MICMUTE - ok
21:54:19.0009 0x1868  [ 09940F4B99FEE60852CDC84BA6C75E6C, 6A1DE349AD54A2C7F105794977DA78B02AE27694D6E62EB3402A337B9FF1D9C3 ] LENOVO.TPKNRSVC C:\Program Files\Lenovo\Communications Utility\tpknrsvc.exe
21:54:19.0028 0x1868  LENOVO.TPKNRSVC - ok
21:54:19.0059 0x1868  [ 038CF67E2743F96C8A85694740B0173C, A0E373DDAD9448413767D2F40F5A4826B811ADC133867AC4AFC831696CDC3BA5 ] LENOVO.TVTVCAM  C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
21:54:19.0073 0x1868  LENOVO.TVTVCAM - ok
21:54:19.0079 0x1868  [ D253E6009F05776F505F96866CCF460F, 8A39E77B4FC780BB9C6C8A892603248D87ED70255BF9BED0218BE2420B5E8C53 ] Lenovo.VIRTSCRLSVC C:\Program Files\LENOVO\VIRTSCRL\lvvsst.exe
21:54:19.0082 0x1868  Lenovo.VIRTSCRLSVC - ok
21:54:19.0094 0x1868  [ EE289BD147FDFF95EF1B9BD65D3B974A, EFD9D0F6C73E7D2D52DBE2E2A8D3009BFB6AB24776A100CA528A8365002C6105 ] lfsvc           C:\WINDOWS\System32\GeofenceMonitorService.dll
21:54:19.0103 0x1868  lfsvc - ok
21:54:19.0108 0x1868  [ C09010B3680860131631F53E8FE7BAD8, 35F2A06D5F29478D22ABDCC20DA893EF9D96504C65594A0CEA674D1C21B04FF8 ] lltdio          C:\WINDOWS\system32\DRIVERS\lltdio.sys
21:54:19.0110 0x1868  lltdio - ok
21:54:19.0119 0x1868  [ 00E070FC0C673311AFD4B068D1242780, 50B0E0E625361145332C849709498FF444E46578DCAD2536E6D0289E0125580F ] lltdsvc         C:\WINDOWS\System32\lltdsvc.dll
21:54:19.0125 0x1868  lltdsvc - ok
21:54:19.0129 0x1868  [ D113FAD71A5E67AA94B32A0F8828D265, 08DDB4BBDB570C59926DBF5E27FCF46DCDF8B8212BB9251E97837E0504516FB3 ] lmhosts         C:\WINDOWS\System32\lmhsvc.dll
21:54:19.0131 0x1868  lmhosts - ok
21:54:19.0141 0x1868  [ FC0BC73DF7430192A753785179C816B5, 7A9A0C8466E89AC0A3ADCD91A3E9ADDA10E8BFD566A318C21573927530EEEA4C ] LMS             C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
21:54:19.0149 0x1868  LMS - ok
21:54:19.0161 0x1868  [ 658BDE9D88FEC3217065C3A90824E192, 941FFCE10B5EFD475F5C12E85EAECB8FDEEBB479432DFAC336DB7DFABCD574C6 ] LocationTaskManager C:\Program Files (x86)\Lenovo\LocationAware\loctaskmgr.exe
21:54:19.0170 0x1868  LocationTaskManager - ok
21:54:19.0179 0x1868  [ C755AE4635457AA2A11F79C0DF857ABC, E03D1ACAC155287291FE1BD0B653953ADC94279A74D0152088D698FAA796460F ] LSI_SAS         C:\WINDOWS\system32\drivers\lsi_sas.sys
21:54:19.0181 0x1868  LSI_SAS - ok
21:54:19.0187 0x1868  [ ADAC09CBE7A2040B7F68B5E5C9A75141, 7865DA7E91404F3642BC444B97F6B7AA42B9523D5EDD7F6365DA236B8EC3410F ] LSI_SAS2        C:\WINDOWS\system32\drivers\lsi_sas2.sys
21:54:19.0190 0x1868  LSI_SAS2 - ok
21:54:19.0195 0x1868  [ 04D1274BB9BBCCF12BD12374002AA191, 4B9618F8D25F2278DE1610A70ACAADB074D171D162C3AF27D464F5DC800A8E60 ] LSI_SAS3        C:\WINDOWS\system32\drivers\lsi_sas3.sys
21:54:19.0197 0x1868  LSI_SAS3 - ok
21:54:19.0203 0x1868  [ 327469EEF3833D0C584B7E88A76AEC0C, 3D88B5A2D68F93F01B39C6E3D8D5C7A2A20686EFC756086E66AFFF1BC3019B85 ] LSI_SSS         C:\WINDOWS\system32\drivers\lsi_sss.sys
21:54:19.0205 0x1868  LSI_SSS - ok
21:54:19.0223 0x1868  [ 8EBB271E4588D835784A3FF7E80076A8, A508BE95F6F5063A76F4C8726D9425BB1F00DE803EFE73A0BE145DD9AB82FF0A ] LSM             C:\WINDOWS\System32\lsm.dll
21:54:19.0237 0x1868  LSM - ok
21:54:19.0243 0x1868  [ DDEE191AB32DFC22C6465002ECDF5EE4, 190C3930A8449118F9FEDF43C482837EF1C255E6D67F9651156E66A1E2BC6553 ] luafv           C:\WINDOWS\system32\drivers\luafv.sys
21:54:19.0247 0x1868  luafv - ok
21:54:19.0251 0x1868  [ EB5C03A070F30D64A6DF80E53B22F53F, 12051B6AEBDEE1E28F24364F25A52BA3A6E282ECF86D6290E34BD38E6D4E066D ] megasas         C:\WINDOWS\system32\drivers\megasas.sys
21:54:19.0253 0x1868  megasas - ok
21:54:19.0268 0x1868  [ F6F13533196DE7A582D422B0241E4363, B3CD9B08937AFFF12141B38634AF3A56F5AC5FF3EF03941802B9841DEC559469 ] megasr          C:\WINDOWS\system32\drivers\megasr.sys
21:54:19.0280 0x1868  megasr - ok
21:54:19.0288 0x1868  [ E0EF6C1399A9B1AAA0B28590411BED04, 10C193D1ED434A6DC2AD8C450012B9AF1C848A0A0B3B775F13495648FB77E009 ] MEIx64          C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
21:54:19.0289 0x1868  MEIx64 - ok
21:54:19.0297 0x1868  [ FD788C2D96EA91469A3C1D13E80D7473, 7B14D4BFDE18CECC19FBFFAA5AFF5FD78BFB7FCDA6613990740A8A7DD9873D26 ] MMCSS           C:\WINDOWS\system32\mmcss.dll
21:54:19.0300 0x1868  MMCSS - ok
21:54:19.0305 0x1868  [ 8B38C44F69259987C95135C9627E2378, E698B82D4EFFF56D66C7FC9866369BA5736FDBDBE2028CC421C51E70DEA74727 ] Modem           C:\WINDOWS\system32\drivers\modem.sys
21:54:19.0306 0x1868  Modem - ok
21:54:19.0310 0x1868  [ 601589000CC90F0DF8DA2CC254A3CCC9, D1238A386C41B6C368D9A44B7C112C943995B5403E2A5B4B7346B266DDB0C5A0 ] monitor         C:\WINDOWS\System32\drivers\monitor.sys
21:54:19.0312 0x1868  monitor - ok
21:54:19.0318 0x1868  [ CEAC6D40FE887CE8406C2393CF97DE06, 34E76908B802764FF0D7AB3AF89BE77BD35B44787983343FAD89891891C0A045 ] mouclass        C:\WINDOWS\System32\drivers\mouclass.sys
21:54:19.0319 0x1868  mouclass - ok
21:54:19.0323 0x1868  [ 02D98BF804084E9A0D69D1C69B02CCA9, EC5BC5D87043DFFD035FD4DD27B3D94E03119063519E4151BCC3522B613E2D7F ] mouhid          C:\WINDOWS\System32\drivers\mouhid.sys
21:54:19.0325 0x1868  mouhid - ok
21:54:19.0333 0x1868  [ 515549560D481138E6E21AF7C6998E56, C7E4B38D8CCAF15B9BDA63C8C8209F6193AD220DA02E1264F1B687AACD8F409F ] mountmgr        C:\WINDOWS\system32\drivers\mountmgr.sys
21:54:19.0336 0x1868  mountmgr - ok
21:54:19.0342 0x1868  [ F170510BE94CF45E3C6274578F6204B2, 344C3DDE1D622607CA2ABECB2C47CB0166D2D258BD94A7960C45A5ADBB640566 ] mpsdrv          C:\WINDOWS\system32\drivers\mpsdrv.sys
21:54:19.0345 0x1868  mpsdrv - ok
21:54:19.0367 0x1868  [ D186C5844393252147BE934F3871DB7A, 30160F8268B9F46E82C5CB536867E0CF280DC98074A481595072E3320200E343 ] MpsSvc          C:\WINDOWS\system32\mpssvc.dll
21:54:19.0385 0x1868  MpsSvc - ok
21:54:19.0392 0x1868  [ 1D55DADC22D21883A2F80297F5A5AE48, B79DF4AFC2A9CBC54E74233596544D6E41C8CAA0516BD57CA695D051EC780265 ] MRxDAV          C:\WINDOWS\system32\drivers\mrxdav.sys
21:54:19.0402 0x1868  MRxDAV - ok
21:54:19.0413 0x1868  [ C997E6A37BA8915224B3FB5024A34F69, 43E1B83072DF9E878151D276DDB6EB7B3801D72494C43E9B9ABECA4B2DCFD606 ] mrxsmb          C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:54:19.0420 0x1868  mrxsmb - ok
21:54:19.0431 0x1868  [ 3E28B99198B514DFEB152EACF913025E, 6C1D8353DCD5F811F39C0C3CB5DF3D2457F0D17EE80FB06196AA169E3D19E9B2 ] mrxsmb10        C:\WINDOWS\system32\DRIVERS\mrxsmb10.sys
21:54:19.0444 0x1868  mrxsmb10 - ok
21:54:19.0451 0x1868  [ AAF56E4E84D35411B4E446C445732DFE, 7AC41CAA0842AE4DA4EEF976202C58D7923DAA367F0D7E800D432323D5E7DE1A ] mrxsmb20        C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys
21:54:19.0456 0x1868  mrxsmb20 - ok
21:54:19.0463 0x1868  [ 4E888019078AC363076A5433E89AA4F8, 3DEBDA290230B3E83F956C902C960E39463B7EFE86439199521356762769FD91 ] MsBridge        C:\WINDOWS\system32\DRIVERS\bridge.sys
21:54:19.0465 0x1868  MsBridge - ok
21:54:19.0472 0x1868  [ A082C17D14D0790E27D064EA4B138AE1, 9A565ED885782D9D5135C8399C11C356DBF9EBF3B8EB4B4504BD2604AD0B45E6 ] MSDTC           C:\WINDOWS\System32\msdtc.exe
21:54:19.0476 0x1868  MSDTC - ok
21:54:19.0481 0x1868  [ D13329FBF8345B28AB30F44CC247DC08, 9C7EC2D4D65E6510EB5B9E61BB0D14F725D7E8FE98D65161C3971E43EF1AB6EB ] Msfs            C:\WINDOWS\system32\drivers\Msfs.sys
21:54:19.0483 0x1868  Msfs - ok
21:54:19.0487 0x1868  [ C6B474E46F9E543B875981ED3FFE6ADD, E16687E52FB649C23D92159A1F036CB662202C1E58D961EECDAA528AA4FA669A ] msgpiowin32     C:\WINDOWS\System32\drivers\msgpiowin32.sys
21:54:19.0489 0x1868  msgpiowin32 - ok
21:54:19.0493 0x1868  [ 65C92EB9D08DB5C69F28C7FFD4E84E31, D709BA4723225321F665B1157A33A4AE230420752308EF535DA9A41CAC164628 ] mshidkmdf       C:\WINDOWS\System32\drivers\mshidkmdf.sys
21:54:19.0494 0x1868  mshidkmdf - ok
21:54:19.0498 0x1868  [ 52299F086AC2DAFD100DD5DC4A8614BA, B36BE0FC96798E5EB8C193C318970E3906961E3ABC3BFAAD73138C76D9A95B0B ] mshidumdf       C:\WINDOWS\System32\drivers\mshidumdf.sys
21:54:19.0500 0x1868  mshidumdf - ok
21:54:19.0505 0x1868  [ 36D92AF3343C3A3E57FEF11C449AEA4C, ECC85AA1E530DF55B4A4545798219F87F0FCA66DDD2E37BCEF0850D3C9129DD2 ] msisadrv        C:\WINDOWS\system32\drivers\msisadrv.sys
21:54:19.0506 0x1868  msisadrv - ok
21:54:19.0513 0x1868  [ 810F8A0A0680662BB0CE44D0E2CEF90C, 5631B07911B7EF378CB1583A480A3C5715E59A5488B33A528F4D7A2F849B9113 ] MSiSCSI         C:\WINDOWS\system32\iscsiexe.dll
21:54:19.0517 0x1868  MSiSCSI - ok
21:54:19.0521 0x1868  msiserver - ok
21:54:19.0524 0x1868  [ A9BBBD2BAE6142253B9195E949AC2E8D, 599D2952D4E0B0B3E02D91E38A30F4900B1ADA330716B887B156A1CB9A3E6EE9 ] MSKSSRV         C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:54:19.0525 0x1868  MSKSSRV - ok
21:54:19.0530 0x1868  [ 375E44168F2DFB91A68B8A3F619C5A7C, AC243E02E9A39D0B4DE9571F196941700EE6EB5E94F5B0BA8994FB551E73A7A8 ] MsLldp          C:\WINDOWS\system32\DRIVERS\mslldp.sys
21:54:19.0532 0x1868  MsLldp - ok
21:54:19.0537 0x1868  [ 7B2128EB875DCBC006E6A913211006D6, 97BBD7FF770741FBFC0F181A609AD0954EA926DA203B742E8F08C89AD8FE476E ] MSPCLOCK        C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:54:19.0538 0x1868  MSPCLOCK - ok
21:54:19.0572 0x1868  [ 1E88171579B218115C7A772F8DE04BD8, B9EAA835D0BF8F9C4DF8403D95EF1400E8AE38F28F9DBA87657DE2129FEF02D2 ] MSPQM           C:\WINDOWS\system32\drivers\MSPQM.sys
21:54:19.0573 0x1868  MSPQM - ok
21:54:19.0594 0x1868  [ BBE2A455053E63BECBF42C2F9B21FAE0, 7C5DF563499DF59DF9895A1581E47ADF5FD54C94ECEF6C886CDB60E5E95A6DAE ] MsRPC           C:\WINDOWS\system32\drivers\MsRPC.sys
21:54:19.0609 0x1868  MsRPC - ok
21:54:19.0622 0x1868  [ 8D6B7D515C5CBCDB75B928A0B73C3C5E, 1EB4DC3DD21D2627C78EC3F9931D9E5D033169087E43B5D7C17BF1FF2A0028CD ] mssmbios        C:\WINDOWS\System32\drivers\mssmbios.sys
21:54:19.0624 0x1868  mssmbios - ok
21:54:19.0630 0x1868  [ 115019AE01E0EB9C048530D2928AB4A2, 6E2275E85EACF2D0FC784792E0D72A165589D33CBAB3BCFA8E271CA09566C925 ] MSTEE           C:\WINDOWS\system32\drivers\MSTEE.sys
21:54:19.0632 0x1868  MSTEE - ok
21:54:19.0638 0x1868  [ 96D604A35070360F0DD4A7A8AF410B5E, F94DD1A3566C7C8D0A76D6E1E2530552A9B7F99C5DA0DE11829325EAB9F8B7ED ] MTConfig        C:\WINDOWS\System32\drivers\MTConfig.sys
21:54:19.0640 0x1868  MTConfig - ok
21:54:19.0648 0x1868  [ 619CA29326B82372621DB2C0964D8365, 4091F08E266DB45A6E33A4A8B1CE9FA78BB294B3111526AA9E3868620F30AFDF ] Mup             C:\WINDOWS\system32\Drivers\mup.sys
21:54:19.0651 0x1868  Mup - ok
21:54:19.0661 0x1868  [ B8C35C94DCB2DFEAF03BB42131F2F77F, F0FCF367CA8F722D6ABCF7F363CD406D890D71452E91C3FC6677B47AD74D6324 ] mvumis          C:\WINDOWS\system32\drivers\mvumis.sys
21:54:19.0664 0x1868  mvumis - ok
21:54:19.0679 0x1868  [ 50E1967C1C2A2BBF4E361DE1A6DD9A5E, 914650EE73313FF15F778F9002D8A1F43D9850D3D1086282B408CD71AC3874D0 ] MyWiFiDHCPDNS   C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
21:54:19.0727 0x1868  MyWiFiDHCPDNS - ok
21:54:19.0748 0x1868  [ 41A45D2A75494EABF2806EA051E00376, EB2497561C8E33A4297C044604C717FF854C7F046882A9E4A400AE7679BF5467 ] napagent        C:\WINDOWS\system32\qagentRT.dll
21:54:19.0757 0x1868  napagent - ok
21:54:19.0770 0x1868  [ 647C7652FA19F98CADF2BFDA2164BFEC, 711A4A06309393922A70D7FBE5684938CD634F5DED158D847BFADDD5ACF9E44C ] NativeWifiP     C:\WINDOWS\system32\DRIVERS\nwifi.sys
21:54:19.0787 0x1868  NativeWifiP - ok
21:54:19.0795 0x1868  [ 71E3C0100AA19D11373CCEB2F51A6008, 58FBF35F5FE19BEABE483C11E9996BE93D76721C8C34465350FA98B465CA3672 ] NcaSvc          C:\WINDOWS\System32\ncasvc.dll
21:54:19.0799 0x1868  NcaSvc - ok
21:54:19.0805 0x1868  [ 51DF09CAB2CAC64FEE3E371D9028ED01, 9B81604D0D0359AF8F54FED6DA7116FFD2F40407895028EAD99FF1D7CFDC2D14 ] NcbService      C:\WINDOWS\System32\ncbservice.dll
21:54:19.0810 0x1868  NcbService - ok
21:54:19.0815 0x1868  [ 2586C4C167499210DCBF3ECFD8CCE210, D8129FEDE9918BF4FB0057CC58700D4E08457060E810B9CC25CA0F598506ADB8 ] NcdAutoSetup    C:\WINDOWS\System32\NcdAutoSetup.dll
21:54:19.0818 0x1868  NcdAutoSetup - ok
21:54:19.0842 0x1868  [ F21B77B4D74092A543807D3CEB711A88, 5C3C17A10E990070FAB317C0C5333DE768E408CAF43EC4FA9D18116C6EE3B3DC ] NDIS            C:\WINDOWS\system32\drivers\ndis.sys
21:54:19.0864 0x1868  NDIS - ok
21:54:19.0870 0x1868  [ C6BB12BC35D1637CA17AE16D3A4725EB, 01C1D9FA738886A195166F88207EEB6715A1DE0608978ED6C5DC738AF5C02513 ] NdisCap         C:\WINDOWS\system32\DRIVERS\ndiscap.sys
21:54:19.0871 0x1868  NdisCap - ok
21:54:19.0877 0x1868  [ 9F1DA20E943BE7AA4ED5F3E1EBA78B37, CCD99962917BBE256F64AE14CCC9FD12433C72B5DB98E0E57CA8F212A11B3C8F ] NdisImPlatform  C:\WINDOWS\system32\DRIVERS\NdisImPlatform.sys
21:54:19.0880 0x1868  NdisImPlatform - ok
21:54:19.0884 0x1868  [ 9423421E735BD5394351E0C47C76BB92, 763E5D06F896C0EF8AD52515464F28BA85DB7A1560E451857AC9AA68FAFCBC66 ] NdisTapi        C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:54:19.0885 0x1868  NdisTapi - ok
21:54:19.0890 0x1868  [ B832B35055BA2B7B4181861FF94D8E59, 2E60E5D503E88D27E35ECFEE265D51328E93A9C7B9B931F86D9CBC947636BB00 ] Ndisuio         C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:54:19.0891 0x1868  Ndisuio - ok
21:54:19.0896 0x1868  [ 1F58E48EF75F34C35D8E93A0DC535CFE, D65619A6C4B1747F8B05DA08A44EF0E46B5CC384880E04E4755A2BA6CDB3C4EA ] NdisVirtualBus  C:\WINDOWS\System32\drivers\NdisVirtualBus.sys
21:54:19.0897 0x1868  NdisVirtualBus - ok
21:54:19.0905 0x1868  [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWan         C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:54:19.0910 0x1868  NdisWan - ok
21:54:19.0917 0x1868  [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWanLegacy   C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:54:19.0921 0x1868  NdisWanLegacy - ok
21:54:19.0926 0x1868  [ A5BD69A8812FA79D1A487691DD3FB244, 67B5EDE101943E0E8B8041DB2353D20C8B9F2D253E77964761CFE8F136C0BBC7 ] NDProxy         C:\WINDOWS\system32\drivers\NDProxy.sys
21:54:19.0928 0x1868  NDProxy - ok
21:54:19.0934 0x1868  [ 5A072F0B90C29C5233D78BE33EF5ED78, B32ED76A674B1FC743361FB7BBD4C915A78B14132AB056AADD445D5995AD4F32 ] Ndu             C:\WINDOWS\system32\drivers\Ndu.sys
21:54:19.0938 0x1868  Ndu - ok
21:54:19.0942 0x1868  [ A83D67D347A684F10B7D3019C8A6380C, 2B86832967981C8C786BF24C1CF8E13E01745ACE3333CF5C821DD93D623B96E4 ] NetBIOS         C:\WINDOWS\system32\DRIVERS\netbios.sys
21:54:19.0944 0x1868  NetBIOS - ok
21:54:19.0953 0x1868  [ 0217532E19A748F0E5D569307363D5FD, C40C2E7AFA276057E7327A7BB173122689D6CEC9AE443C3850C3F94AF03DFBF5 ] NetBT           C:\WINDOWS\system32\DRIVERS\netbt.sys
21:54:19.0959 0x1868  NetBT - ok
21:54:19.0963 0x1868  [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] Netlogon        C:\WINDOWS\system32\lsass.exe
21:54:19.0965 0x1868  Netlogon - ok
21:54:19.0974 0x1868  [ B7AD851A21FEBA3BA214972627614207, 29605320CCC3DAAD062CAECF0009DACBC2F6D28ED4E8AF7CE76132129F5572A0 ] Netman          C:\WINDOWS\System32\netman.dll
21:54:19.0979 0x1868  Netman - ok
21:54:19.0993 0x1868  [ F0F0A372C2EF6358399C4936F91B6131, CE596C71EB4D1A5E104D3148F2D0D8789882C59FD198DCF33CCAC7A08B50E4EE ] netprofm        C:\WINDOWS\System32\netprofmsvc.dll
21:54:20.0004 0x1868  netprofm - ok
21:54:20.0014 0x1868  [ 1092B3190E69E0C5ECBCE90F171DE047, C16106EEFC324EE80E5F659CB71A5DD69FA800D36D829F5B0E6AD3393BD1BAF7 ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:54:20.0017 0x1868  NetTcpPortSharing - ok
21:54:20.0023 0x1868  [ 70414DB660BFBB7BD58FCE8EA4364E1B, 6DFB3897CD55E22BA1EDF0AE672F4D7A6A1F512F8A0A26AF106765E6B1CF65AC ] netvsc          C:\WINDOWS\system32\DRIVERS\netvsc63.sys
21:54:20.0025 0x1868  netvsc - ok
21:54:20.0095 0x1868  [ BBEAD70B866FBA6836FF165A9B8E07E2, FDF4070C0BE604E9082918840F19F70CE87491926096160274BE43D016B3FD15 ] NETwNb64        C:\WINDOWS\system32\DRIVERS\Netwbw02.sys
21:54:20.0171 0x1868  NETwNb64 - ok
21:54:20.0255 0x1868  [ C1A5058712781556E820CA1CE7CB1244, 5EB9934D6A02B19F42C73924066E54F35B98D07F8FA5B1F6AA74DDBAD5C3986D ] NETwNe64        C:\WINDOWS\system32\DRIVERS\NETwew02.sys
21:54:20.0318 0x1868  NETwNe64 - ok
21:54:20.0334 0x1868  [ 3A280F3B3C7A46E29C404ACD46ECBF5E, 81C3367A2A212DBCC65B8A0166FD092E3205AB31A146B4B737061335CEC51F9D ] NlaSvc          C:\WINDOWS\System32\nlasvc.dll
21:54:20.0343 0x1868  NlaSvc - ok
21:54:20.0348 0x1868  [ 8F44A2F57C9F1A19AC9C6288C10FB351, 310274DDBAC0FE4BE54ECD3B90C97D82A0F9F5CFCA7A35711A36164DE4B94074 ] Npfs            C:\WINDOWS\system32\drivers\Npfs.sys
21:54:20.0349 0x1868  Npfs - ok
21:54:20.0353 0x1868  [ CBDB4F0871C88DF930FC0E8588CA67FC, 7E4AA3EA81A9D532F236FD7896744F07ED07CA9B37A9F18A9778BCCCC67490F2 ] npsvctrig       C:\WINDOWS\System32\drivers\npsvctrig.sys
21:54:20.0354 0x1868  npsvctrig - ok
21:54:20.0359 0x1868  [ 6E2271ED0C3E95B8E29F3752B91B9E84, 44026AD9757EA82967D7F7578455802FAD7FE0057EAC088E0AE207C15F594B86 ] nsi             C:\WINDOWS\system32\nsisvc.dll
21:54:20.0361 0x1868  nsi - ok
21:54:20.0365 0x1868  [ E490B459978CB87779E84C761D22B827, 1E5CA38626E41618E4CA16DD0C70EB2FA86E986F0CF21A749BDE2A17015DEEC6 ] nsiproxy        C:\WINDOWS\system32\drivers\nsiproxy.sys
21:54:20.0366 0x1868  nsiproxy - ok
21:54:20.0407 0x1868  [ 1C80517BE6836A812F6A9B99B8321351, 7DBED4633820E201C9C242D961EF6F25BA2B1D5593BA60F707CC71A4014C2D4B ] Ntfs            C:\WINDOWS\system32\drivers\Ntfs.sys
21:54:20.0443 0x1868  Ntfs - ok
21:54:20.0449 0x1868  [ EF1B290FC9F0E47CC0B537292BEE5904, DBC07BBC54EBC2D2E576B23A4CE116B3DA988577AD0D96CB7289A6748A60F9EA ] Null            C:\WINDOWS\system32\drivers\Null.sys
21:54:20.0450 0x1868  Null - ok
21:54:20.0457 0x1868  [ BC6B5942AFF25EBAF62DE43C3807EDF8, CB0FA194084B8C309039D571B5760FDA800E9531B8660C499B4F9977BA5C36D5 ] nvraid          C:\WINDOWS\system32\drivers\nvraid.sys
21:54:20.0461 0x1868  nvraid - ok
21:54:20.0468 0x1868  [ 1F43ABFFAC3D6CA356851D517392966E, 6FD7621F67BA94B0E1D8F43BEC2951DBCDEEA1E848BB265AC169E27C01DA68F2 ] nvstor          C:\WINDOWS\system32\drivers\nvstor.sys
21:54:20.0472 0x1868  nvstor - ok
21:54:20.0478 0x1868  [ 6934A936A7369DFE37B7DBA93F5E5E49, 0900FEEB0CE8D09F0FC60630B5B986034A8BCD3882ED66E47170810C32492892 ] nv_agp          C:\WINDOWS\system32\drivers\nv_agp.sys
21:54:20.0480 0x1868  nv_agp - ok
21:54:20.0487 0x1868  [ 30B5F9FB0C35AE6B4A0851D24CE2EE8B, 0340E77E8EC2ADC21B8DDD9C9CC95B3F4BCAFD54618A333C72D7D9587D593B83 ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:54:20.0491 0x1868  ose - ok
21:54:20.0501 0x1868  [ E287F157F7A0011D93179C64EF8ADCF2, C16FB92C7B18D634BB1344238D35B3111494C243FBD5853F05376F5051480D83 ] p2pimsvc        C:\WINDOWS\system32\pnrpsvc.dll
21:54:20.0509 0x1868  p2pimsvc - ok
21:54:20.0521 0x1868  [ 2A57A937BC5B1B2D6AFE6A8C5925F50B, 00D84EFED5A7129AAD86945940030474795905C32D65CBD5B1A3EBADCED8F873 ] p2psvc          C:\WINDOWS\system32\p2psvc.dll
21:54:20.0531 0x1868  p2psvc - ok
21:54:20.0540 0x1868  [ 764B1121867B2D9B31C491668AC72B2B, 32C04B6FCE1DDD09697B81473A23BDCED8BEEFBCD0D2D58DDC9A11A33C756967 ] Parport         C:\WINDOWS\System32\drivers\parport.sys
21:54:20.0543 0x1868  Parport - ok
21:54:20.0548 0x1868  [ EF0C1749C9A8CEE9A457473D433CC00F, A5FDAB5AD47471640D697C6CFBA6C67730878ABBA47D394EAA47C9733EDCE1F3 ] partmgr         C:\WINDOWS\system32\drivers\partmgr.sys
21:54:20.0550 0x1868  partmgr - ok
21:54:20.0563 0x1868  [ 9A5309EF92F39346CFD5A4C2C3D1BFAD, 5908E0C9562F9CB24784491BD9AE7983A33A6BDF81AFA0A08045518A0C9BB2B1 ] PcaSvc          C:\WINDOWS\System32\pcasvc.dll
21:54:20.0573 0x1868  PcaSvc - ok
21:54:20.0583 0x1868  [ 275AFE3FA35E8D78BE97695DF49817C6, 447CEBB16285AE073B4251D2DA71399306EF2DCB7F56286ABE2F0BD6C83EB489 ] pci             C:\WINDOWS\system32\drivers\pci.sys
21:54:20.0589 0x1868  pci - ok
21:54:20.0592 0x1868  [ 346E38FCC6859A727DD28AFAD1F0AFF4, FF3DA26F79B3BC3A5B8A8AA0B9139B9EF70297F4EA1203B1E68FB5A212C3AA58 ] pciide          C:\WINDOWS\system32\drivers\pciide.sys
21:54:20.0593 0x1868  pciide - ok
21:54:20.0599 0x1868  [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397, 27A7AF2127B699F4579CB77936F38DC102211E26E5E2947DB808756FE06FC98E ] pcmcia          C:\WINDOWS\system32\drivers\pcmcia.sys
21:54:20.0602 0x1868  pcmcia - ok
21:54:20.0607 0x1868  [ BF28771D1436C88BE1D297D3098B0F7D, 5F7630916A76A8CF31289E9C577F522B999C74C39E541CD40E62BD53004BEF74 ] pcw             C:\WINDOWS\system32\drivers\pcw.sys
21:54:20.0608 0x1868  pcw - ok
21:54:20.0613 0x1868  [ B9D968D8E2B0F9C6301CEB39CFC9B9E4, 83F32831B0727F18B56DC3CAF37E45A3523D2BBCD54D1421F0DE5A0179D8A404 ] pdc             C:\WINDOWS\system32\drivers\pdc.sys
21:54:20.0616 0x1868  pdc - ok
21:54:20.0634 0x1868  [ 0ECEE590F2E2EF969FB74A6FC583A1E6, 1C611D9225C863CF32125F684B324C58BDE1942F4F283F5674133200AC505D44 ] PEAUTH          C:\WINDOWS\system32\drivers\peauth.sys
21:54:20.0646 0x1868  PEAUTH - ok
21:54:20.0664 0x1868  [ 8E3C640FFF5A963F570233AE99C0FFF3, 3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A ] PerfHost        C:\WINDOWS\SysWow64\perfhost.exe
21:54:20.0667 0x1868  PerfHost - ok
21:54:20.0701 0x1868  [ 928061178CD9856CA6B67FFFCE6BA766, 71DE3C7CA7F83EAAA550CD8A68FB67DE042B0AE51BFACB1ECB8852D502E11F50 ] pla             C:\WINDOWS\system32\pla.dll
21:54:20.0728 0x1868  pla - ok
21:54:20.0735 0x1868  [ BC6849C62DB407573C6AD8CB1A4D2628, 5BDE0D60F85E4C27CEAD1B301155B54D841FB773BD5BB8AC5DDAEE31F8E94627 ] PlugPlay        C:\WINDOWS\system32\umpnpmgr.dll
21:54:20.0738 0x1868  PlugPlay - ok
21:54:20.0742 0x1868  [ 045EB4F260606A03BE340D09DEAF3BA4, 6F34B8D414F7F69F4388F2F8A86E0F3AD179E423126990AF3E1EC4DCCB8E7693 ] PNRPAutoReg     C:\WINDOWS\system32\pnrpauto.dll
21:54:20.0744 0x1868  PNRPAutoReg - ok
21:54:20.0755 0x1868  [ E287F157F7A0011D93179C64EF8ADCF2, C16FB92C7B18D634BB1344238D35B3111494C243FBD5853F05376F5051480D83 ] PNRPsvc         C:\WINDOWS\system32\pnrpsvc.dll
21:54:20.0762 0x1868  PNRPsvc - ok
21:54:20.0772 0x1868  [ C16097D77A232A288D65F299E2E01105, 5CE4B44B06FD26569C0F92FF1D3991D0128D8444AE7BC9EBEF5A33811D721BE8 ] PolicyAgent     C:\WINDOWS\System32\ipsecsvc.dll
21:54:20.0781 0x1868  PolicyAgent - ok
21:54:20.0788 0x1868  [ 00E08B30E7F7C13ECE2CDF4F46A77311, 1807C0A64C1794E572C86730816C01DCF4D8F773ADE9CAEA3AC0658F7BD71A4E ] Power           C:\WINDOWS\system32\umpo.dll
21:54:20.0791 0x1868  Power - ok
21:54:20.0826 0x1868  [ 56876103384DC93AF71179E0306C1D81, 7BDA75279CB60DB4DF511D66CEA25C3CD62BC385BF714FAF19D33012103E547B ] Power Manager DBC Service C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE
21:54:20.0856 0x1868  Power Manager DBC Service - ok
21:54:20.0912 0x1868  [ B7DB57A000D46D4DE75BC0C563E58072, 8183EB09DC4D44DFF027CA0AAA8C09921A14F088C1BC427B6ACA42340AAF69E6 ] PrintNotify     C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll
21:54:20.0963 0x1868  PrintNotify - ok
21:54:20.0971 0x1868  [ ECD373F9571C745894367CC2635EA44F, E08B2A1017DAE1BF10B986DAFAD14BDE20D79703E0EF3A8C700A3753908C1392 ] Processor       C:\WINDOWS\System32\drivers\processr.sys
21:54:20.0974 0x1868  Processor - ok
21:54:20.0982 0x1868  [ B2A890D96C05E33FDD2BF3F3D4D0DF92, 3A29E17424429A5654D906E420D938148F09F57457356EFA72DA003B73F2D81E ] ProfSvc         C:\WINDOWS\system32\profsvc.dll
21:54:20.0987 0x1868  ProfSvc - ok
21:54:20.0993 0x1868  [ 8528BB05E4D4E25945F78B00B2555FB7, FF8E0D4580F93CD348080967F52FE6C2C68B56DAEACAE2EAEF04E19412A953AE ] Psched          C:\WINDOWS\system32\DRIVERS\pacer.sys
21:54:20.0996 0x1868  Psched - ok
21:54:21.0006 0x1868  [ AF90BB44C99D6820BE52C9BBAA523283, 9772D9CC1666959EC8EE4ED740A5179473CE4F38762109F1123DD68010D20EA1 ] QWAVE           C:\WINDOWS\system32\qwave.dll
21:54:21.0013 0x1868  QWAVE - ok
21:54:21.0018 0x1868  [ 3FB466684609A4329858CF2EBD62E0FD, CFC8FBAB1436948F9D34CE6A2D6DE2F86F3E93E50B86851CED979C8CCE609798 ] QWAVEdrv        C:\WINDOWS\system32\drivers\qwavedrv.sys
21:54:21.0019 0x1868  QWAVEdrv - ok
21:54:21.0023 0x1868  [ 2C56F0EE27E4EF70CA4B4983D3638905, AFFDD686886CE982424B644D9168D61C6F86A5244FF97BC644DF75B321E415E5 ] RasAcd          C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:54:21.0024 0x1868  RasAcd - ok
21:54:21.0030 0x1868  [ 5F061AC45266841A2860C1858ED863B8, 9E0D52BAC8A50225C32D0397C35350601B996443E2481C808CC59D3B0763FEF0 ] RasAuto         C:\WINDOWS\System32\rasauto.dll
21:54:21.0033 0x1868  RasAuto - ok
21:54:21.0047 0x1868  [ 5C7B86EE33505E36026AFAAB62DA6364, 903BB1A355AC746BF09C2A7C87B068168648DB79DEF39AB1DC710B6A7A5F6556 ] RasMan          C:\WINDOWS\System32\rasmans.dll
21:54:21.0057 0x1868  RasMan - ok
21:54:21.0063 0x1868  [ 5247F308C4103CDC4FE12AE1D235800A, E567CD33CA1897D53795E071B7AFBAF98B2C8F725F8BED0BA90F5EF611520E48 ] RasPppoe        C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:54:21.0065 0x1868  RasPppoe - ok
21:54:21.0076 0x1868  [ A1A5E79C0D1352AFDC08328A623DA051, 01546DDE6F1FF159A7EB7F2BF104910445D3D863F1F37DEA695579BA60D84280 ] rdbss           C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:54:21.0085 0x1868  rdbss - ok
21:54:21.0091 0x1868  [ 6B21EBF892CD8CACB71669B35AB5DE32, 0AD8E14FEF16FB2559F5FC8AFBC9D49E4E24F43CF65F480DBF9FAB593269B419 ] rdpbus          C:\WINDOWS\System32\drivers\rdpbus.sys
21:54:21.0092 0x1868  rdpbus - ok
21:54:21.0100 0x1868  [ 680C1DAE268B6FB67FA21B389A8B79EF, 856911F77BDD8830C3D683EBE8AF399FB3A54C7D8D0B34EA37D903377F0A39BD ] RDPDR           C:\WINDOWS\system32\drivers\rdpdr.sys
21:54:21.0104 0x1868  RDPDR - ok
21:54:21.0112 0x1868  [ 858776908AF838E3790F3261B799CDA6, 5BE4658540382D1B2F46E503CE175D74E3870FE492B8B8F37C3CFB34FF8E2DA8 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys
21:54:21.0113 0x1868  RdpVideoMiniport - ok
21:54:21.0121 0x1868  [ A26AEC49F318FEE141DDDB2C5F99B3E6, 246AD79FF27E79DEDCB0AAA7C22A8EA6349DEDAC863413A1E378E68FD94C9C4F ] rdyboost        C:\WINDOWS\system32\drivers\rdyboost.sys
21:54:21.0127 0x1868  rdyboost - ok
21:54:21.0146 0x1868  [ E515A287C8FAE901EB8FB42F168E14F2, 9AE8D608587713FD18BB728BADD402C86FFF06A67359B22ED9431705522BC310 ] ReFS            C:\WINDOWS\system32\drivers\ReFS.sys
21:54:21.0162 0x1868  ReFS - ok
21:54:21.0169 0x1868  [ 7256A19A9397E71FADC46E23E11B1609, AF403728F751C3ECFBA68D05C1E9672CB7B52CB078DE85CB16EAEC5230BBD5BC ] RegSrvc         C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
21:54:21.0173 0x1868  RegSrvc - ok
21:54:21.0182 0x1868  [ BFFB40FBE6D2C3469F8D06EE5E4934AB, 5B6763F973A740DCD53CEA75156926457BED8B075965033C484877DDA8B97F39 ] RemoteAccess    C:\WINDOWS\System32\mprdim.dll
21:54:21.0186 0x1868  RemoteAccess - ok
21:54:21.0193 0x1868  [ 4DCCABE03D06955ED61BABBD8EF9F30F, 531CD60315AAF283B73E0F6CF77D4DE093B809E73C44D2AC43B7247500B3485E ] RemoteRegistry  C:\WINDOWS\system32\regsvc.dll
21:54:21.0198 0x1868  RemoteRegistry - ok
21:54:21.0204 0x1868  [ 0527EF6E23B9FAB37DDCBC479C6CFA28, C004CE600074AC434F8B24A3383F8C0ACFA5476D9E3B1493B40911C78B028D64 ] RFCOMM          C:\WINDOWS\system32\DRIVERS\rfcomm.sys
21:54:21.0209 0x1868  RFCOMM - ok
21:54:21.0215 0x1868  [ D894CBD7DA753C881EE8D5E33B583225, DA4472A85F10A3DF8CE969F731E67FE7C75EE6095908AB8AC2C44851DC5A3F8B ] RpcEptMapper    C:\WINDOWS\System32\RpcEpMap.dll
21:54:21.0218 0x1868  RpcEptMapper - ok
21:54:21.0223 0x1868  [ 5CAE8F47B31D5CFC322B5B898C19E0FE, FDB5F0B6EA36403E031D9147AB0519011FAAD3AC8190DE5B1F17FB5472D79D47 ] RpcLocator      C:\WINDOWS\system32\locator.exe
21:54:21.0224 0x1868  RpcLocator - ok
21:54:21.0241 0x1868  [ 81979817943D830BF24571B7C1B28A1A, 9584D8F1FB3E6CF17BD465670B208C723A8E8B06775A3DA44F75D7710404EEA6 ] RpcSs           C:\WINDOWS\system32\rpcss.dll
21:54:21.0253 0x1868  RpcSs - ok
21:54:21.0259 0x1868  [ 2D05A5508F4685412F2B89E8C2189ABC, 82F12B4E0E73411A121EFD35FBD3B44CBBC0AE96ACFBB45D8C3C3777E2EA320D ] rspndr          C:\WINDOWS\system32\DRIVERS\rspndr.sys
21:54:21.0262 0x1868  rspndr - ok
21:54:21.0274 0x1868  [ D1255851605A6FBFC5D740152D7FEEA3, 3780D3CD521176850E080A0541201C43ED9E84E2EC7D355DA317CCA491913194 ] RTSPER          C:\WINDOWS\system32\DRIVERS\RtsPer.sys
21:54:21.0282 0x1868  RTSPER - ok
21:54:21.0286 0x1868  [ 1A063730F221B2746FF00457AE17E4F0, 39A3C258CBFE3BC566C63528C9020A3BC9409736AE5289C08A7BA471D8409263 ] s3cap           C:\WINDOWS\System32\drivers\vms3cap.sys
21:54:21.0286 0x1868  s3cap - ok
21:54:21.0290 0x1868  [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] SamSs           C:\WINDOWS\system32\lsass.exe
21:54:21.0292 0x1868  SamSs - ok
21:54:21.0298 0x1868  [ C624A1B32211C3166EDB3F4AB02A30B7, 6B2A4607DB52D74242787ED9DF9067058983D310431D8612D2B0236E6201E681 ] sbp2port        C:\WINDOWS\system32\drivers\sbp2port.sys
21:54:21.0301 0x1868  sbp2port - ok
21:54:21.0308 0x1868  [ 47C497FA4DDEA908633CAA60CEBE6805, 4DF5742D4C99D3F7B6A5671AEDB1E5E47D3399D36B28BA19C105FA604D8D5A1C ] SCardSvr        C:\WINDOWS\System32\SCardSvr.dll
21:54:21.0313 0x1868  SCardSvr - ok
21:54:21.0320 0x1868  [ E76C4E98302AE39CC6FA5D20FC8B5438, B6B6B59CF427515087689285797F4A5763103440EBE5D87A61FA74F80F895BD0 ] ScDeviceEnum    C:\WINDOWS\System32\ScDeviceEnum.dll
21:54:21.0324 0x1868  ScDeviceEnum - ok
21:54:21.0328 0x1868  [ ABD0237B15DBD2B4695F4B7D734A58F7, D6831921F0CD3E03CBF1CA3ED5824EE0C75127842D12D4E897E74EC72B0792EB ] scfilter        C:\WINDOWS\system32\DRIVERS\scfilter.sys
21:54:21.0329 0x1868  scfilter - ok
21:54:21.0355 0x1868  [ A95838FFFAEAA7500263D491575F7E0C, FEB79ECAE6D9AB0C29D9AFE12F60502A8357B3A382C0FACF4C6DA4852B6ECFA4 ] Schedule        C:\WINDOWS\system32\schedsvc.dll
21:54:21.0379 0x1868  Schedule - ok
21:54:21.0386 0x1868  [ AB285CE3431FF3D2ACE669245874C1C7, 6AF4C3E86EFA51F7FB6F8492CB2CCB807C7775EAE0508B87F07134FDAC679BD7 ] SCPolicySvc     C:\WINDOWS\System32\certprop.dll
21:54:21.0389 0x1868  SCPolicySvc - ok
21:54:21.0397 0x1868  [ FDEC5799BA499D18AFA3A540538866E7, 551EE0945FE4EC213FFF623E524500B57531EFEA2D76FA7ED1D2D605E7E2168F ] sdbus           C:\WINDOWS\System32\drivers\sdbus.sys
21:54:21.0402 0x1868  sdbus - ok
21:54:21.0407 0x1868  [ 0B1E929D11A8E358106955603FAC65E8, A5EC91BFC0873EC6AB1D0DB4E91654BD35339BD680E7E82DA2DC64996B4AE515 ] sdstor          C:\WINDOWS\System32\drivers\sdstor.sys
21:54:21.0409 0x1868  sdstor - ok
21:54:21.0413 0x1868  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\WINDOWS\system32\drivers\secdrv.sys
21:54:21.0415 0x1868  secdrv - ok
21:54:21.0419 0x1868  [ C49009F897BA4F2F4F31043663AA1485, 48C8BE1E3A4F150662AD012AF4E0357ABA792AD1147AB90EFF6CB2630E2501B6 ] seclogon        C:\WINDOWS\system32\seclogon.dll
21:54:21.0421 0x1868  seclogon - ok
21:54:21.0426 0x1868  [ A88882E64BDC1D8E8D6E727B71CCCC53, 12D2235F54D0CEEED8AA268C17CDE44020269F4FEFC70CE957DBBF99AF7F553D ] SENS            C:\WINDOWS\System32\sens.dll
21:54:21.0429 0x1868  SENS - ok
21:54:21.0437 0x1868  [ E66A7C8CE7ED22DED6DF1CA479FB4790, ADEB076F131E7A8C3AD96022B09BB33EB9AB26C9C831503B8C6960AA763B8975 ] SensrSvc        C:\WINDOWS\system32\sensrsvc.dll
21:54:21.0443 0x1868  SensrSvc - ok
21:54:21.0448 0x1868  [ DB2FF24CE0BDD15FE75870AFE312BA89, 7DB0D978C92CD0A0A81F7AB46FE323B4929CEA01585B0F330921E6DFA7DE1B85 ] SerCx           C:\WINDOWS\system32\drivers\SerCx.sys
21:54:21.0451 0x1868  SerCx - ok
21:54:21.0458 0x1868  [ 0044B31F93946D5D41982314381FE431, 95B8A94BA9EF770F29ACD5B23D447EC2B6CF1CB3D0030343BA1550AC31F6E2A5 ] SerCx2          C:\WINDOWS\system32\drivers\SerCx2.sys
21:54:21.0462 0x1868  SerCx2 - ok
21:54:21.0465 0x1868  [ 3CD600C089C1251BEEB4CD4CD5164F9E, D9F81951B4454B24E821E33ACA53A851A61F3135E8EC6FBE6761A1A3E1CDCBE2 ] Serenum         C:\WINDOWS\System32\drivers\serenum.sys
21:54:21.0467 0x1868  Serenum - ok
21:54:21.0471 0x1868  [ D864381BC9C725FAB01D94C060660166, 132FED95222BBE3B0B25B3F1F0EFC5903D04564BD047BA4D2042AD51E3FDA724 ] Serial          C:\WINDOWS\System32\drivers\serial.sys
21:54:21.0474 0x1868  Serial - ok
21:54:21.0479 0x1868  [ 0BD2B65DCE756FDE95A2E5CCCBF7705D, F13FAFEC8FCF3E796196562717C433CE359A74A3E5876AB070647C717AF74028 ] sermouse        C:\WINDOWS\System32\drivers\sermouse.sys
21:54:21.0480 0x1868  sermouse - ok
21:54:21.0494 0x1868  [ D5C3776CBD8BC307DCCA3FD4CE667A37, 98E4253B770C25914C91A6148E2EA15ED0EF37ADCB042A47252DBA135972BF74 ] SessionEnv      C:\WINDOWS\system32\sessenv.dll
21:54:21.0510 0x1868  SessionEnv - ok
21:54:21.0517 0x1868  [ 472B7A5AC181C050888DB454663DD764, C950A8615D57BFD455E18880398350642B2E1D6B951EC9754FD8D429F3418835 ] sfloppy         C:\WINDOWS\System32\drivers\sfloppy.sys
21:54:21.0518 0x1868  sfloppy - ok
21:54:21.0533 0x1868  [ F4414F57DF2CECB8FC969AA43A6B0D50, AD09A6E1294721507DD6BE82B91F2EEB0FF0151B9BC14A75840CD657DBFDECEC ] SharedAccess    C:\WINDOWS\System32\ipnathlp.dll
21:54:21.0542 0x1868  SharedAccess - ok
21:54:21.0558 0x1868  [ 0D190D8B4B20446BE6299AC734DFADF1, 6551095971F99820BBFC5FED8FAB9591A3F8ABFA0F027887F3B71B79325FF6D9 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
21:54:21.0570 0x1868  ShellHWDetection - ok
21:54:21.0584 0x1868  [ 2F518D13DD6F3053837FE606F1A2EA1F, 64109296CE95BD233525688A350D575CF97B9464659AA07CF78B307B6ADBC835 ] SiSRaid2        C:\WINDOWS\system32\drivers\SiSRaid2.sys
21:54:21.0584 0x1868  SiSRaid2 - ok
21:54:21.0593 0x1868  [ 1AC9A200A9C49C4508F04AAFFCA34A3F, 972BCB2A39169155F74111FAC74ACCD8F50E34EADCF087833B0980827627BBF4 ] SiSRaid4        C:\WINDOWS\system32\drivers\sisraid4.sys
21:54:21.0595 0x1868  SiSRaid4 - ok
21:54:21.0599 0x1868  [ 7C5B431BB6CD52C46295D9752C1C5A45, CBC2A342F019359629B7141ADD1A5AE3E97785D39ADD398EC60F897FABDD5554 ] SmbDrvI         C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys
21:54:21.0609 0x1868  SmbDrvI - ok
21:54:21.0613 0x1868  [ 587ACA15210D1B01FBF272E07A08F91A, 1F3C13C218C5EA329C6E33E4AE7CFE88DAD59DA40F59FDE09D733AFD2E489000 ] smphost         C:\WINDOWS\System32\smphost.dll
21:54:21.0615 0x1868  smphost - ok
21:54:21.0622 0x1868  [ 49EEB92DE930B8566EF615D600781DB4, 0B7C929D24FAFC34F95BB4AA77DCBA29DDD8F1977EB42713B64228677D1FBFD3 ] SNMPTRAP        C:\WINDOWS\System32\snmptrap.exe
21:54:21.0624 0x1868  SNMPTRAP - ok
21:54:21.0634 0x1868  [ 87765EF43C33BE342F4ACB0E3FBF89A6, 3C1DDED7F96F796702F1BC73D5CEE5251DD16011AA349FE4EE1D9C002E0171C6 ] spaceport       C:\WINDOWS\system32\drivers\spaceport.sys
21:54:21.0642 0x1868  spaceport - ok
21:54:21.0648 0x1868  [ F337BE11071818FC3F5DC2940B6BDE34, D5CFF00E5DF37045F71AEE101AC9B270EBB29F372F404757B58600E9966C7E4D ] SpbCx           C:\WINDOWS\system32\drivers\SpbCx.sys
21:54:21.0650 0x1868  SpbCx - ok
21:54:21.0669 0x1868  [ FE0CB40F36D3FCDD3A1B312EF72C38D5, 42EA50869752164764DFE8CE7E1C247BE8342A0C15F39158DC808E8A692C460F ] Spooler         C:\WINDOWS\System32\spoolsv.exe
21:54:21.0685 0x1868  Spooler - ok
21:54:21.0809 0x1868  [ C993A0B97BECD3AAF5158E3869878465, 8B86F37DEFCBE55DE507D830EC4980EBB39B3CCA30C2B3E76B588AAB282A50FC ] sppsvc          C:\WINDOWS\system32\sppsvc.exe
21:54:21.0919 0x1868  sppsvc - ok
21:54:21.0956 0x1868  [ 13F0EB464D44CA0AE87CF16F72BD07AE, 99894854B1E9EA0E40D2204E5B2006039DEE30E5593290C8323D8340DFF7F8B2 ] SPUVCbv         C:\WINDOWS\System32\Drivers\SPUVCbv_x64.sys
21:54:22.0022 0x1868  SPUVCbv - ok
21:54:22.0047 0x1868  [ 2B78788A1485F9B99A578A299DF42C02, A87183A9B13585C9E850437A45237105D39D7F3212ADB079D6AB430B67A59643 ] srv             C:\WINDOWS\system32\DRIVERS\srv.sys
21:54:22.0064 0x1868  srv - ok
21:54:22.0097 0x1868  [ E62EAEF0BAC9DD61BF22D4A7F2F18571, 910D85FDDBAF0E003A0CA0C23D27615F1B7D6145FB9E3A1661E93498196B303A ] srv2            C:\WINDOWS\system32\DRIVERS\srv2.sys
21:54:22.0123 0x1868  srv2 - ok
21:54:22.0141 0x1868  [ 466BDC0006103F2547D308DD3CD64398, 334E0729B369C7F7CBB9878F423B53E05476D1288A8ECEB18240318ABF2370C1 ] srvnet          C:\WINDOWS\system32\DRIVERS\srvnet.sys
21:54:22.0170 0x1868  srvnet - ok
21:54:22.0189 0x1868  [ BB9ED3EDD8E85008215A7250D325A72E, D3404E31B7706B25CDEA7CB4260C343B5F090E8CCB9A5FA203B0F94A9112F1B3 ] SSDPSRV         C:\WINDOWS\System32\ssdpsrv.dll
21:54:22.0204 0x1868  SSDPSRV - ok
21:54:22.0218 0x1868  [ 3911418AFDE10EA6823B7799E4815524, A73517C4C1271E666B2B3A747756070098E923742B41572AA16573170440AA07 ] SstpSvc         C:\WINDOWS\system32\sstpsvc.dll
21:54:22.0229 0x1868  SstpSvc - ok
21:54:22.0240 0x1868  [ 366DEA74BBA65B362BCCFC6FC2ADFD8B, 4D28122AB9D8DAB724021E6513B4474BD34FCEDF47769B1D27AC7551FCA002F8 ] stexstor        C:\WINDOWS\system32\drivers\stexstor.sys
21:54:22.0242 0x1868  stexstor - ok
21:54:22.0276 0x1868  [ D638904FE86A5FE542A1BA13A9D68E5C, 89A956F932316BC50DD99B54BAF4E2809DCAA084DBB04CB84D11E5470BEAF251 ] stisvc          C:\WINDOWS\System32\wiaservc.dll
21:54:22.0304 0x1868  stisvc - ok
21:54:22.0316 0x1868  [ 0ED2E318ABB68C1A35A8B8038BDB4C90, 5C3ABC245F4BCFE64E646D9C0E2F5E211244956C84D03084C71FF6A7E0CDED30 ] storahci        C:\WINDOWS\system32\drivers\storahci.sys
21:54:22.0321 0x1868  storahci - ok
21:54:22.0329 0x1868  [ 7A08CEE1535F5A448215634C5EA74E50, 41529CDC08A3956F8FE9D5759B147E2E56E3305149EA415EB200249F7CD32094 ] storflt         C:\WINDOWS\system32\DRIVERS\vmstorfl.sys
21:54:22.0332 0x1868  storflt - ok
21:54:22.0343 0x1868  [ 6B06E2D11E604BE2B1A406C4CB3B90DE, 2DDEA1568A85AD64FCE5D10D348304FCD9BE6E96C2313353EF70A2933306D188 ] stornvme        C:\WINDOWS\system32\drivers\stornvme.sys
21:54:22.0347 0x1868  stornvme - ok
21:54:22.0359 0x1868  [ 3118058E3D07021A55324A943C6D722B, 0B255DF1977DADD2B9766EEEA814B464F0ABFA34D6439F3C453083850C121F16 ] StorSvc         C:\WINDOWS\system32\storsvc.dll
21:54:22.0364 0x1868  StorSvc - ok
21:54:22.0375 0x1868  [ 548759755BC73DAD663250239D7E0B9F, D31A05A8CE800B539420B6E545F1F4BF6E4B02EAF8366DE89CAF13A83C6CA48D ] storvsc         C:\WINDOWS\system32\drivers\storvsc.sys
21:54:22.0379 0x1868  storvsc - ok
21:54:22.0389 0x1868  [ F07850E89839894F731E4562B64E08A5, BF11E096E1CC57B57FFB4E0528DB43F6B049A7E8A0C00C34E03A00EF2F2092B6 ] SUService       C:\Program Files (x86)\Lenovo\System Update\SUService.exe
21:54:22.0403 0x1868  SUService - ok
21:54:22.0410 0x1868  [ D8E1AE075AB3E8AD56F69C44AA978596, CAFF5116DE7F0EEFFEBE38724BCEE7D11B44153AD35EE43E314C56D5E210758A ] svsvc           C:\WINDOWS\system32\svsvc.dll
21:54:22.0413 0x1868  svsvc - ok
21:54:22.0421 0x1868  [ 84E0F5D41C138C5CC975137A2A98F6D3, 1E36CED05E4F4365C2AB020CAF920E3959995D7F89F3FABD7B2FB05985F85F38 ] swenum          C:\WINDOWS\System32\drivers\swenum.sys
21:54:22.0422 0x1868  swenum - ok
21:54:22.0428 0x1868  [ 894E0F132E448C5448C17D6E5DBF4103, 5D7F2B32273E52556FE958E042C372EE8967413EF87CF487ACCB8ACE19C68FD5 ] SWIX64          C:\Program Files (x86)\Lenovo\System Update\tvsuhd64.sys
21:54:22.0429 0x1868  SWIX64 - ok
21:54:22.0453 0x1868  [ E3C92D60F6AD7763961D1E7628002844, A33EED7CB3EE0EF4890AAD095F989FCA7F44CA1055E03D3892AB543DEE74C9B6 ] swprv           C:\WINDOWS\System32\swprv.dll
21:54:22.0475 0x1868  swprv - ok
21:54:22.0495 0x1868  [ 16021E640CFA11BFA5F4D789322CFC39, E7249AFD865607502A36A6EC931AA9D04185A255B568F9401D45608305DFBF83 ] SynTP           C:\WINDOWS\system32\DRIVERS\SynTP.sys
21:54:22.0523 0x1868  SynTP - ok
21:54:22.0559 0x1868  [ 3DA26652B12E9AB43FD04976AC6DFD33, DEFE220D86197949E97342FE3487CD6A07DD2FFAF6D17A7C65419C2C1B9D1AB5 ] SysMain         C:\WINDOWS\system32\sysmain.dll
21:54:22.0596 0x1868  SysMain - ok
21:54:22.0612 0x1868  [ D65B1C952AEB864C2BAC7A770B17ECCE, 3EFAAFFF73390D9CB660E0F42B305512396CF66ED06E4A20ED67E8722FB4355B ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll
21:54:22.0623 0x1868  SystemEventsBroker - ok
21:54:22.0632 0x1868  [ BA6DD39266A5E15515C8C14DA2DA3E5C, 5BC917BA4E7281A67CC6CEF2F4D1972DF04DECBEFB6DED0B08FFBD06E15D4B4F ] TabletInputService C:\WINDOWS\System32\TabSvc.dll
21:54:22.0638 0x1868  TabletInputService - ok
21:54:22.0643 0x1868  [ F9BE29D5E097F03F81D3CD12B794CB66, 5EC208DEAF7C721F4C36512E7DAD4AC66578AB935B9502A5E1E213BC91BE508C ] tap0901         C:\WINDOWS\system32\DRIVERS\tap0901.sys
21:54:22.0654 0x1868  tap0901 - ok
21:54:22.0665 0x1868  [ B517410F157693043DACA21B19B258A6, 2224EECEB575CEA811036C43BB5B0A408DE5F59BC97235AB948968E4C3E438F2 ] TapiSrv         C:\WINDOWS\System32\tapisrv.dll
21:54:22.0672 0x1868  TapiSrv - ok
21:54:22.0725 0x1868  [ FEEFE783D87C9063CDAC6DBDCF95F533, EBD00EEE90AC657823A88190BBBED6DA47AF597510C201F3392F4325069D2669 ] Tcpip           C:\WINDOWS\system32\drivers\tcpip.sys
21:54:22.0771 0x1868  Tcpip - ok
21:54:22.0827 0x1868  [ FEEFE783D87C9063CDAC6DBDCF95F533, EBD00EEE90AC657823A88190BBBED6DA47AF597510C201F3392F4325069D2669 ] TCPIP6          C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:54:22.0865 0x1868  TCPIP6 - ok
21:54:22.0874 0x1868  [ 41CF802064F72E55F50CA0A221FD36D4, 70ABCDF9E96611E8C83042C581575E26649FE479475E8E118CD3FF6CB1C84C3F ] tcpipreg        C:\WINDOWS\system32\drivers\tcpipreg.sys
21:54:22.0883 0x1868  tcpipreg - ok
21:54:22.0891 0x1868  [ FFF28F9F6823EB1756C60F1649560BBF, 208DFF8BF0329D0D4761C7E31527AEED7FF5F3C36C5005953D01477F35408D5C ] tdx             C:\WINDOWS\system32\DRIVERS\tdx.sys
21:54:22.0894 0x1868  tdx - ok
21:54:22.0898 0x1868  [ 232D185D2337F141311D0CF1983E1431, 02EB56D3F26174AF1741C1A444CE30DE84D5BAF583C1A52C7A953BCC52445547 ] terminpt        C:\WINDOWS\System32\drivers\terminpt.sys
21:54:22.0900 0x1868  terminpt - ok
21:54:22.0922 0x1868  [ 2C77831737491F4D684D315B95C62883, 90A2574A281F19646CFCDA5FDF40063220058290D2D5523AD91B7E709EC36D3D ] TermService     C:\WINDOWS\System32\termsrv.dll
21:54:22.0956 0x1868  TermService - ok
21:54:22.0965 0x1868  [ 05FBE1F7C13E87AF7A414CDF288B1F62, 24079E1A6B2E33A1A8E76A77F73473B93DD6B379E44C982CE50D6CEED9747838 ] Themes          C:\WINDOWS\system32\themeservice.dll
21:54:22.0970 0x1868  Themes - ok
21:54:22.0981 0x1868  [ FD788C2D96EA91469A3C1D13E80D7473, 7B14D4BFDE18CECC19FBFFAA5AFF5FD78BFB7FCDA6613990740A8A7DD9873D26 ] THREADORDER     C:\WINDOWS\system32\mmcss.dll
21:54:22.0985 0x1868  THREADORDER - ok
21:54:23.0000 0x1868  [ 347A3E49CE18402305B8119A6EC7CFEB, 6768B20EE577880B0353FE84B980D4A18D323929A63FAE41F7A55123BBFC8DBA ] TimeBroker      C:\WINDOWS\System32\TimeBrokerServer.dll
21:54:23.0012 0x1868  TimeBroker - ok
21:54:23.0024 0x1868  [ EEE8F526111B627ADF5A9CE0FAC4D383, 8507C326E2B5421FFE728BA39C7B4C851E9F106F391D8106B77728263B61B057 ] TPHKLOAD        C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
21:54:23.0029 0x1868  TPHKLOAD - ok
21:54:23.0041 0x1868  [ 82F909359600D3603FE852DB7F135626, 2EB2BB9D81AC9A2E432B2628E296B7B21F1C82EAE8009300EEF1B8596A9F418D ] TPM             C:\WINDOWS\system32\drivers\tpm.sys
21:54:23.0047 0x1868  TPM - ok
21:54:23.0054 0x1868  [ A9EF6C7E62DC3B01C51CFB92C1596C62, 432335FDA5DF9FF8C9B86767980A07C720E7158D5362E40D3A745817D4275A07 ] TPPWRIF         C:\WINDOWS\system32\drivers\Tppwr64v.sys
21:54:23.0057 0x1868  TPPWRIF - ok
21:54:23.0068 0x1868  [ C97E14BB6A196B0554D6EB67D8818175, C00588C94988F10507F84584DFA4C0A43B8648AD1AD35E9BAE14CDD21FCF7B90 ] TrkWks          C:\WINDOWS\System32\trkwks.dll
21:54:23.0075 0x1868  TrkWks - ok
21:54:23.0083 0x1868  [ 887CC44830D3F367CAD17A0CA7CCA5C8, D4022A76433A11FD66D0F41A1EB4D6893BC5B22317E7E9E021739109EB493B44 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe
21:54:23.0087 0x1868  TrustedInstaller - ok
21:54:23.0098 0x1868  [ BF8F54CA37E9C9D6582C31C5761F8C93, 337C566792F6FB9B7FD5D1D4384B767CFE4CF5DBB2E4688CCC36CBB018A0DD0F ] TsUsbFlt        C:\WINDOWS\system32\drivers\tsusbflt.sys
21:54:23.0101 0x1868  TsUsbFlt - ok
21:54:23.0108 0x1868  [ E0088068DCE2EE82897027DDB8E05254, FA9C201D3C885DAD2ABE6A23343EDCC83CFB342EFF9E3005FA50B1D88B21D203 ] TsUsbGD         C:\WINDOWS\System32\drivers\TsUsbGD.sys
21:54:23.0110 0x1868  TsUsbGD - ok
21:54:23.0124 0x1868  [ C8E0E78B5D284C2FF59BDFFDAF997242, BA1576C491A1246EF9866762426D110F4570F9DB42A68C174943C7D5020FE3E2 ] tunnel          C:\WINDOWS\system32\DRIVERS\tunnel.sys
21:54:23.0131 0x1868  tunnel - ok
21:54:23.0140 0x1868  [ F6EEAD052943B5A3104C1405BB856C54, FE422813E6C1012E9F392EFF2AE4C6D3A4DBD9CB2BD5E6A5CAB57D4E89A29468 ] uagp35          C:\WINDOWS\system32\drivers\uagp35.sys
21:54:23.0143 0x1868  uagp35 - ok
21:54:23.0152 0x1868  [ FE6067B1FD4E63650C667B33D080565B, 2C330ED00E49BA55E25564230E0DFB8A35F2B5320EB18D4AF7CAACFA9A449044 ] UASPStor        C:\WINDOWS\System32\drivers\uaspstor.sys
21:54:23.0156 0x1868  UASPStor - ok
21:54:23.0169 0x1868  [ B034A41891A36457B994307DFA772293, CA5E6500764A9777AE0E15B2AFB6F05982C90F01374E3F6DDC6DF3852282C66B ] UCX01000        C:\WINDOWS\System32\drivers\ucx01000.sys
21:54:23.0177 0x1868  UCX01000 - ok
21:54:23.0193 0x1868  [ 1EC649F112896FAE33250F0B97AC5D0B, 0C0A1C2C7615DEB298AD3073340FD1BF91FEBE611F133E3B48D994A6EAA8369F ] udfs            C:\WINDOWS\system32\DRIVERS\udfs.sys
21:54:23.0204 0x1868  udfs - ok
21:54:23.0211 0x1868  [ 9578691F297E1B1F519970FE6D47CB21, 080C352AAF22A16A4F3C4AB4DCEA5BFA656457C73F735CEBA30516FDACCF6301 ] UEFI            C:\WINDOWS\System32\drivers\UEFI.sys
21:54:23.0214 0x1868  UEFI - ok
21:54:23.0226 0x1868  [ 320878AFECDBBD61BBE98624A6CAAC08, 15C090EA32A24D976B5FCB1373B1281DCC2295C075299C814345D694AEB47CB9 ] UI0Detect       C:\WINDOWS\system32\UI0Detect.exe
21:54:23.0232 0x1868  UI0Detect - ok
21:54:23.0241 0x1868  [ 5B99D25F5CA1F20CCED62381ED41793E, 672B40021E0C623ED8C7E3203261837B43A5EE750E59DAFC4D6EAC4911B12F44 ] UimBus          C:\WINDOWS\System32\drivers\UimBus.sys
21:54:23.0260 0x1868  UimBus - ok
21:54:23.0266 0x1868  [ 67F428FA5F059A974529ECBA6A6C9D71, 912BCAEC818317AFD051351D5EAAF3B5EC8E5AD3CC9C1B8FC17F5DB78829615A ] Uim_DEVIM       C:\WINDOWS\System32\drivers\uim_devim.sys
21:54:23.0282 0x1868  Uim_DEVIM - ok
21:54:23.0314 0x1868  [ 76E93AD89DEC20EE2AF99E17183F85AB, 4ED49ADA41FA2BFDCC11861241428E23E8396E72BE10929FF01F0FE48D3DF2C2 ] Uim_IM          C:\WINDOWS\System32\drivers\uim_im.sys
21:54:23.0359 0x1868  Uim_IM - ok
21:54:23.0368 0x1868  [ 5EAB5117DDB24FC4D39E6FFFCF1837B9, 2BC709240867F161E94BE6625A04F478EAAA3EEE7BC7C37ED0DFA9EEA5928E98 ] uliagpkx        C:\WINDOWS\system32\drivers\uliagpkx.sys
21:54:23.0371 0x1868  uliagpkx - ok
21:54:23.0380 0x1868  [ DA34C39A18E60E7C3FA0630566408034, 2F162504214053894C72760D9933D01DBF3578609FE5E2376C3272818599FE32 ] umbus           C:\WINDOWS\System32\drivers\umbus.sys
21:54:23.0385 0x1868  umbus - ok
21:54:23.0391 0x1868  [ AE8294875E5446E359B1E8035D40C05E, AE0357BAB47C07C3576BC76951CD258C009BC5A1B93259D2122A841BD9CDA8FA ] UmPass          C:\WINDOWS\System32\drivers\umpass.sys
21:54:23.0392 0x1868  UmPass - ok
21:54:23.0408 0x1868  [ E3DDF7D43E05784FAA5E042605EEE528, 8E20E880FAB09AF4FF5C438BF9EAE9970D46C05167870110869B744E498FD761 ] UmRdpService    C:\WINDOWS\System32\umrdp.dll
21:54:23.0422 0x1868  UmRdpService - ok
21:54:23.0443 0x1868  [ 4A2FFDAC45F317E17DF642C7160EB633, F1AB762912FAA5F469F322407DA37C91556086C42D1643AD27516C12A84F74D0 ] upnphost        C:\WINDOWS\System32\upnphost.dll
21:54:23.0461 0x1868  upnphost - ok
21:54:23.0474 0x1868  [ 524BFB402B1AB1007ED91E94D6AB6F72, 5A970292D2E7A580FAD86615BC6E66C2A5C74044EFF6C1543E928773E5B9C0F8 ] usb3Hub         C:\WINDOWS\System32\drivers\usb3Hub.sys
21:54:23.0498 0x1868  usb3Hub - ok
21:54:23.0511 0x1868  [ 433ECDE01A52691FA7ACA51C10C09B70, B896296A3F8EF2AF3AC5F0091B9848156608586F1E10A95D70700BAB51E8062A ] usbccgp         C:\WINDOWS\System32\drivers\usbccgp.sys
21:54:23.0518 0x1868  usbccgp - ok
21:54:23.0529 0x1868  [ B3D6457D841A0CAEF4C52D88621715F2, CBDD76A8A28379B107B1FB530757B477B8AB74CD01F9F3CEDC7B1BA0C6E5A990 ] usbcir          C:\WINDOWS\System32\drivers\usbcir.sys
21:54:23.0535 0x1868  usbcir - ok
21:54:23.0545 0x1868  [ 5477D6E27C7D266EF8C152B9A25ADE5E, FEE81677D284A78A0C0FB60F887A952CFC759AE78B01206D73F59FE33612C519 ] usbehci         C:\WINDOWS\System32\drivers\usbehci.sys
21:54:23.0549 0x1868  usbehci - ok
21:54:23.0569 0x1868  [ DF56C2C04EFA328D7A66B69007130266, 719316EB25A8C7B82C7941D1C5B964CC4EDA4A997732F481526DE7356F6FC0D8 ] usbhub          C:\WINDOWS\System32\drivers\usbhub.sys
21:54:23.0585 0x1868  usbhub - ok
21:54:23.0607 0x1868  [ CFC52C49BEFE4D70D87FFA900EAB9777, 09A2F5D8AB07C3AE3F2B092F4DD7AE5838736CDC263016F188B442B32EC928F8 ] USBHUB3         C:\WINDOWS\System32\drivers\UsbHub3.sys
21:54:23.0625 0x1868  USBHUB3 - ok
21:54:23.0633 0x1868  [ 3019097FB6C985EF24C058090FF3BDBD, 24AC518D34E338D94BF3D5B3F72E53F8A1369BAA7F32FEA3EDBCF928C4FF1D17 ] usbohci         C:\WINDOWS\System32\drivers\usbohci.sys
21:54:23.0635 0x1868  usbohci - ok
21:54:23.0641 0x1868  [ 4D655E3B684BE9B0F7FFD8A2935C348C, 3A7FC1748C5AEA8CFE0E7C22ADC77E3DCA475455FC16D9C6A5C16EB5E949A516 ] usbprint        C:\WINDOWS\System32\drivers\usbprint.sys
21:54:23.0643 0x1868  usbprint - ok
21:54:23.0658 0x1868  [ EA23453240137F6773174E0D93F61A69, 579AD09FB428C2BB8B4055128620A7AADD1B606C1EA44B87A01D69A84232A5D9 ] USBSTOR         C:\WINDOWS\System32\drivers\USBSTOR.SYS
21:54:23.0665 0x1868  USBSTOR - ok
21:54:23.0672 0x1868  [ BA4FA655E0FC577DB7436FC963932CE4, 3336FDECD4AEC6B316D4C0803E22A12719EBEDD1A9427C0DF5D3B263BE600EE6 ] usbuhci         C:\WINDOWS\System32\drivers\usbuhci.sys
21:54:23.0674 0x1868  usbuhci - ok
21:54:23.0693 0x1868  [ 48430B0313FC1CFE3D2400553F1A93CD, 92994DE6B131E904AFF2C9C4FBB4E6B0D58525A1539763327373DA18C9F08193 ] USBXHCI         C:\WINDOWS\System32\drivers\USBXHCI.SYS
21:54:23.0705 0x1868  USBXHCI - ok
21:54:23.0713 0x1868  [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] VaultSvc        C:\WINDOWS\system32\lsass.exe
21:54:23.0716 0x1868  VaultSvc - ok
21:54:23.0722 0x1868  [ FEB26E3B8345A7E8D62F945C4AE86562, 3AAFE87C402FC8E92542DFE60EC9540559863065F88D429A16D7B1BF829223FF ] vdrvroot        C:\WINDOWS\system32\drivers\vdrvroot.sys
21:54:23.0725 0x1868  vdrvroot - ok
21:54:23.0777 0x1868  [ E3EF58D4123B5AA29C8E19825AF84A5E, FB1046722BC643E955DBC3B1459DBF2A6D575EBA2BCF7B20A0FA51E3993835E2 ] vds             C:\WINDOWS\System32\vds.exe
21:54:23.0827 0x1868  vds - ok
21:54:23.0841 0x1868  [ A026EDEAA5EECAE0B08E2748B616D4BD, 2525A54DC7F49DDFBB999C22BF3FAB6D9E9F70C0806E58D81E90AC59F9F46089 ] VerifierExt     C:\WINDOWS\system32\drivers\VerifierExt.sys
21:54:23.0848 0x1868  VerifierExt - ok
21:54:23.0876 0x1868  [ 52E483A3701A5A61A75A06993720347D, 689E812755E485DF6960D1E049740FBAFB812467D23B673DCAA40C03FEBB544F ] vhdmp           C:\WINDOWS\System32\drivers\vhdmp.sys
21:54:23.0897 0x1868  vhdmp - ok
21:54:23.0904 0x1868  [ 06D38968028E9AB19DE9B618C7B6D199, 62022297A47F440D1C82CA0B0E57C0C8E9D5033D83DD3B40492B218DF65EBF68 ] viaide          C:\WINDOWS\system32\drivers\viaide.sys
21:54:23.0906 0x1868  viaide - ok
21:54:23.0916 0x1868  [ C6305BDFC4F7CE51F72BB072C03D4ACE, 73E62869CA3104F48CC3B0C45E69CE9BF4F8D7D06E29C2F049B9347ABB50554D ] vmbus           C:\WINDOWS\system32\drivers\vmbus.sys
21:54:23.0921 0x1868  vmbus - ok
21:54:23.0928 0x1868  [ DA40BEA0A863CE768C940CA9723BF81F, 567C0C3F422325635808B0CF76E05D3B6187F96845C33F85F92F98C9FE53A5B8 ] VMBusHID        C:\WINDOWS\System32\drivers\VMBusHID.sys
21:54:23.0930 0x1868  VMBusHID - ok
21:54:23.0959 0x1868  [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicguestinterface C:\WINDOWS\System32\ICSvc.dll
21:54:23.0982 0x1868  vmicguestinterface - ok
21:54:24.0006 0x1868  [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicheartbeat   C:\WINDOWS\System32\ICSvc.dll
21:54:24.0026 0x1868  vmicheartbeat - ok
21:54:24.0049 0x1868  [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmickvpexchange C:\WINDOWS\System32\ICSvc.dll
21:54:24.0068 0x1868  vmickvpexchange - ok
21:54:24.0093 0x1868  [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicrdv         C:\WINDOWS\System32\ICSvc.dll
21:54:24.0113 0x1868  vmicrdv - ok
21:54:24.0138 0x1868  [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicshutdown    C:\WINDOWS\System32\ICSvc.dll
21:54:24.0156 0x1868  vmicshutdown - ok
21:54:24.0180 0x1868  [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmictimesync    C:\WINDOWS\System32\ICSvc.dll
21:54:24.0199 0x1868  vmictimesync - ok
21:54:24.0223 0x1868  [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicvss         C:\WINDOWS\System32\ICSvc.dll
21:54:24.0243 0x1868  vmicvss - ok
21:54:24.0252 0x1868  [ 55D7D963DE85162F1C49721E502F9744, 5AD34D6DB707EF3E5242BD8CA67B21D6258EE7E7FC477D5227BD15500AE7F45F ] volmgr          C:\WINDOWS\system32\drivers\volmgr.sys
21:54:24.0256 0x1868  volmgr - ok
21:54:24.0277 0x1868  [ CCB9E901F7254BF96D28EB1B0E5329B7, F0E3CA4EFA544CDAEF4092284CF3EC7DF07F806A770285E281816457AD8813F5 ] volmgrx         C:\WINDOWS\system32\drivers\volmgrx.sys
21:54:24.0291 0x1868  volmgrx - ok
21:54:24.0310 0x1868  [ 3595FBDF25F8BA6256072D103937D7D6, 547AA103804790E31F6E5658923627945948B48F36354EEA2FC0FE09098F9FD5 ] volsnap         C:\WINDOWS\system32\drivers\volsnap.sys
21:54:24.0321 0x1868  volsnap - ok
21:54:24.0330 0x1868  [ 01355C98B5C3ED1EC446743CDA848FCE, B9FCF558C20E05DD0F53FFB70BBEF873EA57801E13A16701E636128D625C4B67 ] vpci            C:\WINDOWS\System32\drivers\vpci.sys
21:54:24.0334 0x1868  vpci - ok
21:54:24.0349 0x1868  [ 4539F45F9F4C9757A86A56C949421E07, DEC362314B2C66414F39354AFE79C02B18BF4EEF90787FB58307F6EB62237E2C ] vsmraid         C:\WINDOWS\system32\drivers\vsmraid.sys
21:54:24.0356 0x1868  vsmraid - ok
21:54:24.0415 0x1868  [ 4957B27219515B93A508B91068B87BF5, 5B6B37A57FC8F4FC8B119C013338292550C63AB5295A596D382D8DCF26D751A2 ] VSS             C:\WINDOWS\system32\vssvc.exe
21:54:24.0472 0x1868  VSS - ok
21:54:24.0491 0x1868  [ 0849B7260F26FE05EA56DED0672E2F4B, 7EAC0E7988F45CB4133A15932955B7B03CE715C967A3BAC9999D81543EBCAEC5 ] VSTXRAID        C:\WINDOWS\system32\drivers\vstxraid.sys
21:54:24.0500 0x1868  VSTXRAID - ok
21:54:24.0505 0x1868  [ BE970C369E43B509C1EDA2B8FA7CECB0, 18951F2AA842A0795AA79A4E164EE925A35E6270EBE4C4CDB19D0A891830E383 ] vwifibus        C:\WINDOWS\System32\drivers\vwifibus.sys
21:54:24.0506 0x1868  vwifibus - ok
21:54:24.0512 0x1868  [ 6B26AD573CCDD5209DF4397438B76354, 2C8AC314EC471F6D8B0B12D49D621360A10DCADA7C52E73596730C954FF89FCF ] vwififlt        C:\WINDOWS\system32\DRIVERS\vwififlt.sys
21:54:24.0514 0x1868  vwififlt - ok
21:54:24.0520 0x1868  [ 0B48E0DFB44EE475F4FD8A8EE599AF30, 28271D4CA0C642304CD8826A3D514F44E3391F9D6D07A1595BB30CE65E7E3494 ] vwifimp         C:\WINDOWS\system32\DRIVERS\vwifimp.sys
21:54:24.0522 0x1868  vwifimp - ok
21:54:24.0538 0x1868  [ 7599E582CA3A6AAA95A18FFE1172D339, A0410778FBBC4302EA91CF24B944427410B4706535F1192504D4F34C3ED4503E ] W32Time         C:\WINDOWS\system32\w32time.dll
21:54:24.0549 0x1868  W32Time - ok
21:54:24.0555 0x1868  [ 0910AB9ED404C1434E2D0376C2AD5D8B, 62585CA5F1375BDA440D28D5DF1ADDC9DE3DDFA196D49BBFF3456A5A09EE1C6B ] WacomPen        C:\WINDOWS\System32\drivers\wacompen.sys
21:54:24.0556 0x1868  WacomPen - ok
21:54:24.0600 0x1868  [ 61692DB39AD3DF2F29392D68EAA7BB93, 854D4B9C7DD1676968598ED973500650ECEC02C420E44C0B3957C24F073AA5FB ] wbengine        C:\WINDOWS\system32\wbengine.exe
21:54:24.0640 0x1868  wbengine - ok
21:54:24.0659 0x1868  [ 3BC1D1D56637A32CD91C8AE08E2484AA, 9EE1BD3FB0D289E25F3DDD0D8F67DC1C701A6B1D5418FADF348D0E642B1DEBEB ] WbioSrvc        C:\WINDOWS\System32\wbiosrvc.dll
21:54:24.0671 0x1868  WbioSrvc - ok
21:54:24.0684 0x1868  [ A07CFC4B593D15B6BF06813C3B5B33BF, B57BD918E2AFF9943B51A24B95E0C4D3482B4DF73C0E2421E8CC67C2BC7A4C70 ] Wcmsvc          C:\WINDOWS\System32\wcmsvc.dll
21:54:24.0695 0x1868  Wcmsvc - ok
21:54:24.0712 0x1868  [ D2726823DF7E19F213F4805A9D6D145F, A7F582C99918D204264D3B374F70D75984BDA5805203041E3DECB8153D16E102 ] wcncsvc         C:\WINDOWS\System32\wcncsvc.dll
21:54:24.0725 0x1868  wcncsvc - ok
21:54:24.0730 0x1868  [ 846C02A8B48CBD921A3D6AB521AA0DC4, B07573A774A6C65D24E5718DC25DF378270EB5B40221CA5A53B21D47838381D3 ] WcsPlugInService C:\WINDOWS\System32\WcsPlugInService.dll
21:54:24.0735 0x1868  WcsPlugInService - ok
21:54:24.0741 0x1868  [ 241895E8A9C158DF86E12FDD21033A32, 46D4BF6319271AC33EC1C7283053B91D38A3D5443F3F749E640253FDC2819679 ] WdBoot          C:\WINDOWS\system32\drivers\WdBoot.sys
21:54:24.0743 0x1868  WdBoot - ok
21:54:24.0769 0x1868  [ CB6C63FF8342B467E2EF76E98D5B934D, BE017CE91E3BAB293DE6ECF143797CCE3F33CC63024437472B4E38C6961AD884 ] Wdf01000        C:\WINDOWS\system32\drivers\Wdf01000.sys
21:54:24.0790 0x1868  Wdf01000 - ok
21:54:24.0802 0x1868  [ C52148456E0F6EAD9E903020A79207FC, 7DEB2D7D09FB005A79E88FA8766B7EBE0396F0CA084D72269156874C727FBFF4 ] WdFilter        C:\WINDOWS\system32\drivers\WdFilter.sys
21:54:24.0807 0x1868  WdFilter - ok
21:54:24.0816 0x1868  [ 40C67D1A4891120874767F6E6604D6C5, 4D9DD658566DE711ADF4D6C33FCB31DA351EE050E3ED188664D04526CCAAEEF5 ] WdiServiceHost  C:\WINDOWS\system32\wdi.dll
21:54:24.0820 0x1868  WdiServiceHost - ok
21:54:24.0824 0x1868  [ 40C67D1A4891120874767F6E6604D6C5, 4D9DD658566DE711ADF4D6C33FCB31DA351EE050E3ED188664D04526CCAAEEF5 ] WdiSystemHost   C:\WINDOWS\system32\wdi.dll
21:54:24.0828 0x1868  WdiSystemHost - ok
21:54:24.0838 0x1868  [ 57F22324FAAF92ADF957B281E88F1743, 46CFBA6529E28756D73A00A211C3D72E9854E035EE6F2520066E074697A9745E ] WdNisDrv        C:\WINDOWS\system32\Drivers\WdNisDrv.sys
21:54:24.0841 0x1868  WdNisDrv - ok
21:54:24.0845 0x1868  WdNisSvc - ok
21:54:24.0856 0x1868  [ 6588A957873326361AB1CAC4E76F8394, BE17880CEDCAE5ED3B983443E3777842646A3E48B661422A717656E11F6DBA94 ] WebClient       C:\WINDOWS\System32\webclnt.dll
21:54:24.0864 0x1868  WebClient - ok
21:54:24.0874 0x1868  [ 3274312F263882B51B964329FAF49734, 99A020377ACF0762BE5ECD2D68EB5E1497B9D59963247E725F7F96FB5DF41FAD ] Wecsvc          C:\WINDOWS\system32\wecsvc.dll
21:54:24.0882 0x1868  Wecsvc - ok
21:54:24.0887 0x1868  [ 7CDD84E0023A0C5C230B06A7965EC65E, 6EC7DC18C76D66CF9A893C3DD20F9BE3ADD76546F9A9BA42CE4F24854709F9D9 ] WEPHOSTSVC      C:\WINDOWS\system32\wephostsvc.dll
21:54:24.0889 0x1868  WEPHOSTSVC - ok
21:54:24.0898 0x1868  [ 959534ACF085C137D2D094384EF89C45, D029F440789FE170A1C46217C6DE6D78DC0188A5CF33FCCC17FA65D3BC80C2B7 ] wercplsupport   C:\WINDOWS\System32\wercplsupport.dll
21:54:24.0901 0x1868  wercplsupport - ok
21:54:24.0909 0x1868  [ 82BCCF5FBE47AC9E8CBA2020994DFB3F, EA96C6BD98A701B465D0780EC10BDA92E45FE636D60C1385813AA3B456D8B931 ] WerSvc          C:\WINDOWS\System32\WerSvc.dll
21:54:24.0914 0x1868  WerSvc - ok
21:54:24.0921 0x1868  [ BFBE1C5F57FE7A885673A1962D5532B7, F0BD05B257108699FE6AB32EF11F927C31932F27062A705B3FEFA4F5B4C0D8C3 ] WFPLWFS         C:\WINDOWS\system32\DRIVERS\wfplwfs.sys
21:54:24.0925 0x1868  WFPLWFS - ok
21:54:24.0931 0x1868  [ E06AFE2F94BA7CFA2FE4FD2A449E60E2, 99A81E16366E9E77905D873B0246E4C11B383FE1E99E0E1D9A07FAD4E52EA9E4 ] WiaRpc          C:\WINDOWS\System32\wiarpc.dll
21:54:24.0935 0x1868  WiaRpc - ok
21:54:24.0942 0x1868  [ 867BCC69ED9C31C501465EB0E8BA9DFA, 678B7FF4D4E8624514301956CDA7FB451159BBFC83FF2E4E5E7DADAE3C7AB2EC ] WIMMount        C:\WINDOWS\system32\drivers\wimmount.sys
21:54:24.0944 0x1868  WIMMount - ok
21:54:24.0947 0x1868  WinDefend - ok
21:54:24.0975 0x1868  [ DD079EC8F44DCA3A176B345C6ADEFB66, 6CD9371B83EA23D2181891FAE1DB285BC111A78C35F374E57666ED09860C91A9 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll
21:54:24.0997 0x1868  WinHttpAutoProxySvc - ok
21:54:25.0010 0x1868  [ 9DB490F3E823C5C3C070644B96CB9D59, 81937D0B331E43C7C61514E60B3AD51370C5201F7B4D12F8534840D91EDC32DD ] Winmgmt         C:\WINDOWS\system32\wbem\WMIsvc.dll
21:54:25.0017 0x1868  Winmgmt - ok
21:54:25.0082 0x1868  [ C8D6344BDE2691A196E61C0D3372EAB7, FF8EB79D8A7E298343C22B83276FF68293D08A9DA438BB22600BEFC4CA93A91D ] WinRM           C:\WINDOWS\system32\WsmSvc.dll
21:54:25.0166 0x1868  WinRM - ok
21:54:25.0229 0x1868  [ 5A917027826D759CC3238C7D3CEC3438, A8FFA28B6D8A314692AA08788FC9E2E0F03D8AD1FCD662826ABA71DB39C3605A ] WlanSvc         C:\WINDOWS\System32\wlansvc.dll
21:54:25.0315 0x1868  WlanSvc - ok
21:54:25.0413 0x1868  [ 5F56C0DE776C7AE43AF749845BFAA1EF, 837993C5853B7E682C7FB8401B7F5D951FFD15E5659EBB1B01DC3F5719ACEE19 ] wlidsvc         C:\WINDOWS\system32\wlidsvc.dll
21:54:25.0504 0x1868  wlidsvc - ok
21:54:25.0518 0x1868  [ 2834D9D3B4F554A39C72F00EA3F0E128, D10124343C67FE9A0B711AD569BB8080495FCEA0ECEF9AC3F3FBD6865F436A44 ] WmiAcpi         C:\WINDOWS\System32\drivers\wmiacpi.sys
21:54:25.0521 0x1868  WmiAcpi - ok
21:54:25.0551 0x1868  [ 7AFAC828F52D62F304A911EC32F42EEE, 4EDCF4149069413A166169F2E23F7505F47B39B7EC319E1EF6D2C46CD140AA24 ] wmiApSrv        C:\WINDOWS\system32\wbem\WmiApSrv.exe
21:54:25.0563 0x1868  wmiApSrv - ok
21:54:25.0570 0x1868  WMPNetworkSvc - ok
21:54:25.0592 0x1868  [ 7FC5667DF73D4B04AA457CC3A4180E09, CB7B014945DCA16B6D120DBE0E5876C4C867A4ACD3C3536AEADC14B908613D4E ] Wof             C:\WINDOWS\system32\drivers\Wof.sys
21:54:25.0602 0x1868  Wof - ok
21:54:25.0710 0x1868  [ 65C65F3BD784158C456E721DDC9F0EA2, CBD3ADFD960456BD4B9557BF691E12D31153499549F5D3D08258BD62013952ED ] workfolderssvc  C:\WINDOWS\system32\workfolderssvc.dll
21:54:25.0802 0x1868  workfolderssvc - ok
21:54:25.0819 0x1868  [ C1F564F324685C088ECAB1933576CF91, 022F0EC160352AB73AF7DA557D1A5798964231B82C556F22F4163E8B3E4088B2 ] wpcfltr         C:\WINDOWS\system32\DRIVERS\wpcfltr.sys
21:54:25.0824 0x1868  wpcfltr - ok
21:54:25.0836 0x1868  [ 4E6A0F60DA7EF050D3D26417CD4D24E9, E6B3BFB007B641D41F8532ED086F92CB3D86E210023DBFAA9AD8152A9FD33CCA ] WPCSvc          C:\WINDOWS\System32\wpcsvc.dll
21:54:25.0842 0x1868  WPCSvc - ok
21:54:25.0857 0x1868  [ D27491CFCE452C154CECFA155AD0EBC8, 1F3F74C253E3B07DE7EFE27C34DD9AF08617C7B03BB44C2902F69BA9DA3F21F2 ] WPDBusEnum      C:\WINDOWS\system32\wpdbusenum.dll
21:54:25.0869 0x1868  WPDBusEnum - ok
21:54:25.0881 0x1868  [ 9F2904B55F6CECCD1A8D986B5CE2609A, E19ED4DD3CEF3A22C058FC324824604FB3FC98A029C94E6C2A3389F938D680B6 ] WpdUpFltr       C:\WINDOWS\system32\drivers\WpdUpFltr.sys
21:54:25.0885 0x1868  WpdUpFltr - ok
21:54:25.0900 0x1868  [ 7CA09731EB7FC99B910C7F239E57720F, 502F8917A0811F37C39B2B3F5E9B4F38A0E899C30CB29D3ECD87A50FF228E536 ] WPRO_41_2001    C:\WINDOWS\system32\drivers\WPRO_41_2001.sys
21:54:25.0918 0x1868  WPRO_41_2001 - ok
21:54:25.0925 0x1868  [ AE072B0339D0A18E455DC21666CAD572, AB1DAEA25E2C7AD610818D4B4783F6D4190D85EBB3963BBAD410E8CEA7899EDB ] ws2ifsl         C:\WINDOWS\system32\drivers\ws2ifsl.sys
21:54:25.0926 0x1868  ws2ifsl - ok
21:54:25.0940 0x1868  [ 515583507D3828E827FF6352C9ACCEFA, D0C42020FA787804DA26FE07D67C8880FE027A230BD9EB6A706862D89181F2BE ] wscsvc          C:\WINDOWS\System32\wscsvc.dll
21:54:25.0948 0x1868  wscsvc - ok
21:54:25.0954 0x1868  WSearch - ok
21:54:26.0096 0x1868  [ 95B6670E6933E1DEE19686C55BE709A0, 4B9EB8F1712B7959A71F6DA445D29BD09B25EEFC6B30D736EFE30163D79B233E ] WSService       C:\WINDOWS\System32\WSService.dll
21:54:26.0227 0x1868  WSService - ok
21:54:26.0370 0x1868  [ 779FB2F26E4339A4DD3EEF57E4E593FA, 8B0369FDF52280EE9E03EE9FF9560FD7A404C14A95930C6AB5EC0FAAC3D57924 ] wuauserv        C:\WINDOWS\system32\wuaueng.dll
21:54:26.0503 0x1868  wuauserv - ok
21:54:26.0514 0x1868  [ 2FEAE33E9B2B56104596E1BA444405A9, 0A142F50E06F6224B9CB36B3CE62BE0B36DE8B8DB9F9E05D287DFB884CC7826E ] WudfPf          C:\WINDOWS\system32\drivers\WudfPf.sys
21:54:26.0517 0x1868  WudfPf - ok
21:54:26.0527 0x1868  [ 19240C13F526125554B5370566F21A0A, 1DD88B092451CEC309A390319342BB4D36CE938BBE6D09127BBAA53960DD8E94 ] WUDFRd          C:\WINDOWS\System32\drivers\WUDFRd.sys
21:54:26.0532 0x1868  WUDFRd - ok
21:54:26.0539 0x1868  [ BB73CBC65AABC4EA0A5C6A1474A0A743, D644B3C6A7202CADDADB3B68FE1B2A7C76B023FE58F667EED4D538C1F4A65D64 ] wudfsvc         C:\WINDOWS\System32\WUDFSvc.dll
21:54:26.0543 0x1868  wudfsvc - ok
21:54:26.0557 0x1868  [ 2FA9794CA36147756F3FDFD6CA29B46F, 4B86DC38C2411C281686E9A4E64DA6FB2992E39391371F78E012D6D8BB85123F ] WwanSvc         C:\WINDOWS\System32\wwansvc.dll
21:54:26.0568 0x1868  WwanSvc - ok
21:54:26.0643 0x1868  [ 19137CA32DA7AA6F4936514721AA53BA, E9E5E6F05A1D529D19339F0C71AA5F9D412F6D3AE4BF84CF340C8569BA367D51 ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
21:54:26.0784 0x1868  ZeroConfigService - ok
21:54:26.0822 0x1868  ================ Scan global ===============================
21:54:26.0830 0x1868  [ C89780A6F58D113C28A96D85D1261DC5, 185114F33A60916C7904E4A0F278CA43258454343E614F01F0DAFA98BAC981B1 ] C:\WINDOWS\system32\basesrv.dll
21:54:26.0845 0x1868  [ 00DD4D2ACC2E72155A8AAA82018BEC0D, 9D7CA68B4A81240477FCC85A3CC11EF986093F9D6228A6C5AC608EDAD664068C ] C:\WINDOWS\system32\winsrv.dll
21:54:26.0863 0x1868  [ 9C1833ABD62876856836C5AE55C7CE86, 0A21E2C8B2FF3B0438C86DA7151A548F9C6F5C62CD402CBBEDB435994C8508F1 ] C:\WINDOWS\system32\sxssrv.dll
21:54:26.0885 0x1868  [ B4B610BBCB002EC478C6FD80CF915697, CE22B87A7C7C0D325CE66FB97E7318B4A41EE0BD14D902A410126A1EBBEAA6FB ] C:\WINDOWS\system32\services.exe
21:54:26.0904 0x1868  [ Global ] - ok
21:54:26.0905 0x1868  ================ Scan MBR ==================================
21:54:26.0910 0x1868  [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk0\DR0
21:54:26.0919 0x1868  \Device\Harddisk0\DR0 - ok
21:54:26.0920 0x1868  ================ Scan VBR ==================================
21:54:26.0923 0x1868  [ 454E41ABA194F4DFC64992A064C941D7 ] \Device\Harddisk0\DR0\Partition1
21:54:26.0925 0x1868  \Device\Harddisk0\DR0\Partition1 - ok
21:54:26.0929 0x1868  [ FC3A71A59667CB175E03E8AF50F93CCE ] \Device\Harddisk0\DR0\Partition2
21:54:26.0932 0x1868  \Device\Harddisk0\DR0\Partition2 - ok
21:54:26.0938 0x1868  [ B1E27AA018409DE6BFD73F8AFB883A65 ] \Device\Harddisk0\DR0\Partition3
21:54:26.0938 0x1868  \Device\Harddisk0\DR0\Partition3 - ok
21:54:26.0944 0x1868  [ BBA1E17E67C2AB36F17F0DADDA22C553 ] \Device\Harddisk0\DR0\Partition4
21:54:26.0948 0x1868  \Device\Harddisk0\DR0\Partition4 - ok
21:54:26.0951 0x1868  [ CE058A7D28EDFFA610CF2DD225A0D5CA ] \Device\Harddisk0\DR0\Partition5
21:54:26.0954 0x1868  \Device\Harddisk0\DR0\Partition5 - ok
21:54:26.0958 0x1868  [ C797CF43E4C5FA0C9507E1817D6E7A01 ] \Device\Harddisk0\DR0\Partition6
21:54:26.0960 0x1868  \Device\Harddisk0\DR0\Partition6 - ok
21:54:26.0962 0x1868  Waiting for KSN requests completion. In queue: 338
21:54:27.0963 0x1868  Waiting for KSN requests completion. In queue: 338
21:54:28.0462 0x19f8  Object required for P2P: [ E0EF6C1399A9B1AAA0B28590411BED04 ] C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys
21:54:28.0964 0x1868  Waiting for KSN requests completion. In queue: 272
21:54:29.0964 0x1868  Waiting for KSN requests completion. In queue: 243
21:54:30.0965 0x1868  Waiting for KSN requests completion. In queue: 243
21:54:31.0118 0x19f8  Object send P2P result: true
21:54:31.0988 0x1868  AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.4.304.0 ), 0x61100 ( enabled : updated )
21:54:31.0994 0x1868  Win FW state via NFP2: enabled
21:54:36.0043 0x1868  ============================================================
21:54:36.0043 0x1868  Scan finished
21:54:36.0043 0x1868  ============================================================
21:54:36.0070 0x0b90  Detected object count: 0
21:54:36.0071 0x0b90  Actual detected object count: 0
 
ADWCleaner
 
# AdwCleaner v3.207 - Report created 08/05/2014 at 21:58:08
# Updated 05/05/2014 by Xplode
# Operating System : Windows 8.1  (64 bits)
# Username : Neil - NICO_BELLIC
# Running from : C:\Users\Neil\Downloads\adwcleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Files / Folders ] *****
 
Folder Deleted : C:\Users\Neil\AppData\Roaming\dvdvideosoftiehelpers
 
***** [ Shortcuts ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Browsers ] *****
 
-\\ Internet Explorer v11.0.9600.17037
 
 
-\\ Google Chrome v34.0.1847.131
 
[ File : C:\Users\Neil\AppData\Local\Google\Chrome\User Data\Default\preferences ]
 
 
*************************
 
AdwCleaner[R0].txt - [903 octets] - [07/05/2014 00:59:32]
AdwCleaner[R1].txt - [856 octets] - [07/05/2014 01:41:53]
AdwCleaner[R2].txt - [1042 octets] - [08/05/2014 21:56:38]
AdwCleaner[S0].txt - [969 octets] - [07/05/2014 01:01:22]
AdwCleaner[S1].txt - [916 octets] - [07/05/2014 01:42:50]
AdwCleaner[S2].txt - [967 octets] - [08/05/2014 21:58:08]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1026 octets] ##########
 
 
JRT
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 8.1 x64
Ran by Neil on Thu 05/08/2014 at 22:02:36.67
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Registry Values
 
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-4064413907-563569548-2304998158-1001\Software\Microsoft\Internet Explorer\Main\\Start Page
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Event Viewer Logs were cleared
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 05/08/2014 at 22:07:30.70
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
ESET
 
C:\Users\Neil\Downloads\FreeYouTubeToMP3Converter.exe Win32/OpenCandy potentially unsafe application deleted - quarantined
C:\Users\Neil\OneDrive\Documents\Misc\Software\FreeYouTubeDownload.exe Win32/OpenCandy potentially unsafe application deleted - quarantined
C:\Users\Neil\OneDrive\Documents\Misc\Software\FreeYouTubeToMP3Converter.exe Win32/OpenCandy potentially unsafe application deleted - quarantined
 
 
 
 


#6 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:05 AM

Posted 09 May 2014 - 10:01 AM

Have you removed both Avast and AVG?
 
Download RogueKiller from one of the following links and save it to your desktop:
  • Link 1
  • Link 2
    • Close all programs and disconnect any USB or external drives before running the tool.
    • Double-click RogueKiller.exe to run the tool (Vista or 7 users: Right-click and select Run As Administrator).
    • Once the Prescan has finished, click Scan.
    • Once the Status box shows "Scan Finished", click the Delete button.
    • Copy and paste the report that opens into your next reply.
      • The log can also be found on your desktop labeled (RKreport[X]_D_xxdatexx_xtimex)
      • The highest number of [X], is the most recent Delete
Download 51a5f31352b88-icon_MBAR.pngMalwarebytes Anti-Rootkit to your desktop.
  • Extract the ZIP archive and double-click "mbar.exe" to start the tool.
  • Warning! Malwarebytes Anti-Rootkit needs to be run from an account with administrator rights.
  • Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
  • When the scan is finished and no malware has been found select "Exit".
  • If malware was detected, make sure to check all the items and click "Cleanup". Reboot your computer.
  • Open the MBAR folder and paste the content of the following files in your next reply:
    • "mbar-log-{date} (xx-xx-xx).txt"
    • "system-log.txt"

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#7 NSGF

NSGF
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:05 AM

Posted 09 May 2014 - 01:42 PM

Yes, AVG and Avast were removed immediately after scanning.

 

RogueKiller

 

RogueKiller V8.8.15 [Mar 27 2014] by Adlice Software
 
Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : Neil [Admin rights]
Mode : Remove -- Date : 05/09/2014 13:20:38
| ARK || FAK || MBR |
 
¤¤¤ Bad processes : 2 ¤¤¤
[SUSP PATH] rubyw.exe -- C:\Users\Neil\AppData\Local\Temp\ocr6B0E.tmp\bin\rubyw.exe [-] -> KILLED [TermProc]
[SUSP PATH] rubyw.exe -- C:\Users\Neil\AppData\Local\Temp\ocrB40D.tmp\bin\rubyw.exe [-] -> KILLED [TermProc]
 
¤¤¤ Registry Entries : 4 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\RunOnce : Application Restart #2 (C:\Users\Neil\AppData\Local\Pokki\Engine\HostAppService.exe  --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\Neil\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --enable-touch-events --flag-switches-begin --flag-switches-end --restore-last-session [x][x]) -> DELETED
[RUN][SUSP PATH] HKUS\S-1-5-21-4064413907-563569548-2304998158-1001\[...]\RunOnce : Application Restart #2 (C:\Users\Neil\AppData\Local\Pokki\Engine\HostAppService.exe  --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-client-side-phishing-detection --enable-file-cookies --disable-sync --disable-breakpad --disable-bundled-ppapi-flash --disable-sync-tabs --disable-speech-input --disable-custom-jumplist --process-per-tab --debug-devtools-frontend="C:\Users\Neil\AppData\Local\Pokki\Engine\inspector" --no-first-run --lang=en-US --disable-component-update --disable-prompt-on-repost --no-startup-window --disable-translate --disable-logging --disable-desktop-notifications --disable-gpu-process-prelaunch --enable-touch-events --flag-switches-begin --flag-switches-end --restore-last-session [x][x]) -> [0x2] The system cannot find the file specified. 
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
 
¤¤¤ Scheduled tasks : 0 ¤¤¤
 
¤¤¤ Startup Entries : 0 ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ Browser Addons : 0 ¤¤¤
 
¤¤¤ Particular Files / Folders: ¤¤¤
 
¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤
 
¤¤¤ External Hives: ¤¤¤
 
¤¤¤ Infection :  ¤¤¤
 
¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts
 
 
 
 
¤¤¤ MBR Check: ¤¤¤
 
+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) Samsung SSD 840 EVO 120GB +++++
--- User ---
[MBR] a84dd93b5b19931ceaddbccc47850486
[BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 1 | Size: 2097151 MB
User = LL1 ... OK!
User = LL2 ... OK!
 
Finished : << RKreport[0]_D_05092014_132038.txt >>
RKreport[0]_S_05092014_132011.txt
 
 
MBAR
 
Malwarebytes Anti-Rootkit BETA 1.07.0.1009
www.malwarebytes.org
 
Database version: v2014.05.09.10
 
Windows 8 x64 NTFS
Internet Explorer 11.0.9600.17105
Neil :: NICO_BELLIC [administrator]
 
5/9/2014 1:23:38 PM
mbar-log-2014-05-09 (13-23-38).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 264777
Time elapsed: 6 minute(s), 5 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)
 
 
MBAR System Log
 
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1009
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.2.9200 Windows 8 x64
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.17105
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.494000 GHz
Memory total: 4174385152, free: 2416664576
 
Downloaded database version: v2014.05.09.10
Downloaded database version: v2014.03.27.01
Initializing...
======================
------------ Kernel report ------------
     05/09/2014 13:23:33
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kd.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\System32\drivers\werkernel.sys
\SystemRoot\System32\drivers\CLFS.SYS
\SystemRoot\System32\drivers\tm.sys
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CI.dll
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\System32\Drivers\acpiex.sys
\SystemRoot\System32\Drivers\WppRecorder.sys
\SystemRoot\System32\drivers\ACPI.sys
\SystemRoot\System32\drivers\WMILIB.SYS
\SystemRoot\System32\drivers\msisadrv.sys
\SystemRoot\System32\drivers\pci.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\system32\drivers\tpm.sys
\SystemRoot\System32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\pdc.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\System32\drivers\spaceport.sys
\SystemRoot\System32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\System32\drivers\iaStorA.sys
\SystemRoot\System32\drivers\storport.sys
\SystemRoot\System32\drivers\EhStorClass.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\System32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Wof.sys
\SystemRoot\system32\drivers\WdFilter.sys
\SystemRoot\System32\DRIVERS\fastboot.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\DRIVERS\wfplwfs.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\System32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\intelpep.sys
\SystemRoot\System32\drivers\IntelPcc.sys
\SystemRoot\system32\drivers\dlkmdldr.sys
\SystemRoot\System32\drivers\disk.sys
\SystemRoot\System32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\BasicRender.sys
\SystemRoot\system32\drivers\dlkmd.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\System32\drivers\BasicDisplay.sys
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\System32\drivers\serial.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\System32\drivers\uim_im.sys
\SystemRoot\System32\drivers\UimFIO.SYS
\SystemRoot\System32\drivers\uim_devim.sys
\SystemRoot\System32\drivers\UimBus.sys
\SystemRoot\System32\drivers\Tppwr64v.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\System32\drivers\npsvctrig.sys
\SystemRoot\System32\drivers\mssmbios.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\ahcache.sys
\SystemRoot\system32\DRIVERS\tap0901.sys
\SystemRoot\System32\drivers\CompositeBus.sys
\SystemRoot\System32\drivers\usb3Hub.sys
\SystemRoot\System32\drivers\USBD.SYS
\SystemRoot\system32\DRIVERS\kdnic.sys
\SystemRoot\System32\drivers\umbus.sys
\SystemRoot\System32\drivers\intelppm.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\System32\drivers\HDAudBus.sys
\SystemRoot\System32\drivers\USBXHCI.SYS
\SystemRoot\System32\drivers\ucx01000.sys
\SystemRoot\system32\DRIVERS\TeeDriverx64.sys
\SystemRoot\System32\drivers\serenum.sys
\SystemRoot\system32\DRIVERS\e1d64x64.sys
\SystemRoot\system32\DRIVERS\RtsPer.sys
\SystemRoot\system32\DRIVERS\Netwbw02.sys
\SystemRoot\System32\drivers\vwifibus.sys
\SystemRoot\System32\drivers\usbehci.sys
\SystemRoot\System32\drivers\USBPORT.SYS
\SystemRoot\System32\drivers\i8042prt.sys
\SystemRoot\system32\DRIVERS\ikbevent.sys
\SystemRoot\system32\DRIVERS\SynTP.sys
\SystemRoot\System32\drivers\kbdclass.sys
\SystemRoot\system32\DRIVERS\imsevent.sys
\SystemRoot\System32\drivers\mouclass.sys
\SystemRoot\System32\drivers\CmBatt.sys
\SystemRoot\System32\drivers\BATTC.SYS
\SystemRoot\system32\DRIVERS\ibmpmdrv.sys
\SystemRoot\system32\DRIVERS\Smb_driver_Intel.sys
\SystemRoot\System32\drivers\wmiacpi.sys
\SystemRoot\System32\drivers\ISCTD64.sys
\SystemRoot\System32\drivers\NdisVirtualBus.sys
\SystemRoot\System32\drivers\swenum.sys
\SystemRoot\System32\drivers\ks.sys
\SystemRoot\System32\drivers\iwdbus.sys
\SystemRoot\System32\drivers\rdpbus.sys
\SystemRoot\System32\drivers\usbhub.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\System32\drivers\UsbHub3.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\System32\drivers\usbccgp.sys
\SystemRoot\system32\DRIVERS\ibtusb.sys
\SystemRoot\system32\DRIVERS\btmhsf.sys
\SystemRoot\System32\Drivers\BTHUSB.sys
\SystemRoot\System32\Drivers\bthport.sys
\SystemRoot\System32\Drivers\SPUVCbv_x64.sys
\SystemRoot\system32\DRIVERS\BthLEEnum.sys
\SystemRoot\system32\DRIVERS\rfcomm.sys
\SystemRoot\system32\DRIVERS\BthEnum.sys
\SystemRoot\system32\DRIVERS\bthpan.sys
\SystemRoot\system32\drivers\BthA2DP.sys
\SystemRoot\system32\drivers\btampm.sys
\SystemRoot\System32\drivers\BthAvrcpTg.sys
\SystemRoot\System32\drivers\HIDCLASS.SYS
\SystemRoot\System32\drivers\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\btmaux.sys
\SystemRoot\System32\drivers\hidusb.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_iaStorA.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\drivers\monitor.sys
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\System32\drivers\condrv.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\drivers\Ndu.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\System32\drivers\WUDFRd.sys
\SystemRoot\system32\drivers\WPRO_41_2001.sys
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\system32\Drivers\WdNisDrv.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\System32\drivers\umpass.sys
\??\C:\WINDOWS\system32\drivers\mbamchameleon.sys
\??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffe00046500460
Upper Device Driver Name: \Driver\disk\
Lower Device Name: \Device\00000039\
Lower Device Object: 0xffffe00044795060
Lower Device Driver Name: \Driver\iaStorA\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffe00046500460, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
--------- Disk Stack ------
DevicePointer: 0xffffe000464ffb20, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffe000464ff040, DeviceName: Unknown, DriverName: \Driver\Fastboot\
DevicePointer: 0xffffe00046500460, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\disk\
DevicePointer: 0xffffe000447a74d0, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffe00044795060, DeviceName: \Device\00000039\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: Unknown, DriverName: \Driver\Fastboot\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Done!
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
This drive is a GPT Drive.
MBR Signature: 55AA
Disk Signature: 0
 
GPT Protective MBR Partition information:
 
    Partition 0 type is EFI-GPT (0xee)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 1  Numsec = 4294967295
 
    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
GPT Partition information:
 
    GPT Header Signature 4546492050415254
    GPT Header Revision 65536 Size 92 CRC 2118116034
    GPT Header CurrentLba = 1 BackupLba 234441647
    GPT Header FirstUsableLba 34  LastUsableLba 234441614
    GPT Header Guid 15848c48-5a0e-49fb-b350-7aa18acefd2
    GPT Header Contains 128 partition entries starting at LBA 2
    GPT Header Partition entry size = 128
 
    Backup GPT header Signature 4546492050415254
    Backup GPT header Revision 65536 Size 92 CRC 2118116034
    Backup GPT header CurrentLba = 234441647 BackupLba 1
    Backup GPT header FirstUsableLba 34  LastUsableLba 234441614
    Backup GPT header Guid 15848c48-5a0e-49fb-b350-7aa18acefd2
    Backup GPT header Contains 128 partition entries starting at LBA 234441615
    Backup GPT header Partition entry size = 128
 
    Partition 0 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 5df720ca-9a1d-4e18-e858-ae951a81119a
    FirstLBA 2048  Last LBA 2050047
    Attributes 0
    Partition Name                                     
 
    Partition 1 Type c12a7328-f81f-11d2-ba4b-0a0c93ec93b
    Partition ID 1723ce29-36d1-4ddd-98b-fbc1cc17bf6
    FirstLBA 2052096  Last LBA 2584575
    Attributes 0
    Partition Name                                     
 
    GPT Partition 1 is bootable
    Partition 2 Type e3c9e316-b5c-4db8-817d-f92df0215ae
    Partition ID f8b36663-a196-443d-307c-c51bd94be65
    FirstLBA 2584576  Last LBA 2846719
    Attributes 0
    Partition Name                                     
 
    Partition 3 Type ebd0a0a2-b9e5-4433-87c0-68b6b72699c7
    Partition ID c6fcb543-8df1-4d77-2868-77dc8365e8a9
    FirstLBA 2846720  Last LBA 208744447
    Attributes 0
    Partition Name                                     
 
    Partition 4 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 32e27d-7009-4708-c485-cbfb8caea650
    FirstLBA 208744448  Last LBA 209666047
    Attributes 0
    Partition Name                                     
 
    Partition 5 Type de94bba4-6d1-4d40-a16a-bfd5179d6ac
    Partition ID 4867d563-6f88-455e-1a71-6c405fb4ea41
    FirstLBA 209666048  Last LBA 234436607
    Attributes 0
    Partition Name                                     
 
Disk Size: 120034123776 bytes
Sector size: 512 bytes
 
Done!
Scan finished
=======================================
 
 
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished
 
 
 
Thank you again!!
 


#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:05 AM

Posted 09 May 2014 - 01:48 PM

OK Great!.. Should be running well now.

Now you need to put an Antivirus back on.. Try either free Avira or Avast from here L@@K
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 NSGF

NSGF
  • Topic Starter

  • Members
  • 7 posts
  • OFFLINE
  •  
  • Local time:01:05 AM

Posted 09 May 2014 - 02:00 PM

OK Great!.. Should be running well now.

Now you need to put an Antivirus back on.. Try either free Avira or Avast from here L@@K

 

 

Nothing has popped up all day or yesterday!

 

Thank you so much for what you do here. I truly appreciate it.

 

I am installing Avast now!

 

 

 

If it is not too much trouble..could you tell me in a 'cliffnotes' version of what the issue was so I can avoid it in the future?

 

Thank you!



#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,338 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:02:05 AM

Posted 09 May 2014 - 07:37 PM

The logs you have from your earlier scans show more of what you had.
From what we had here was a Trojan and files we fixed that were probably damaged by the malware.
I don't a lot of games here but I would thin that some apps you installed had bundled adware. For Example... Pokki has been found to be bundled with 3rd party software. If you have not purposefully installed this, you should be safe uninstalling it.

When installing Apps/ seawares etc...
Look to use the Optional not Recommended install .. This way you can UN check the items they are throwing in like Toolbars and browsers you don't want or need.

Now Empty your temp folders using TFC (Temporary File Cleaner)
  • Please download TFC by Old Timer and save it to your desktop.
    alternate download link
  • Save any unsaved work. (TFC will close ALL open programs including your browser!)
  • Double-click on TFC.exe to run it. (If you are using Vista, right-click on the file and choose "Run As Administrator".)
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users