Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Lot of malware detected by Microsoft Security Essentials


  • Please log in to reply
23 replies to this topic

#1 Newbie1011

Newbie1011

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 20 September 2015 - 07:15 PM

Hello

 

The Microsoft Security essentials has detected and quarantined a lot of malware

 

I have deleted them but i am suspecting that there may be some more in the system

 

I am running Windows 7 Ultimate 64 bit updated to latest versions and have MBAM pro and windows security essentials

 

Please advise

 

Thanks for helping

 

Shravan



BC AdBot (Login to Remove)

 


#2 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,569 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:32 AM

Posted 20 September 2015 - 07:42 PM

Hi newbie, let's look a bit farther and see,,

3Al62Pm.pngMiniToolBox
  • Please download MiniToolBox, save it to your desktop and run it.
  • Checkmark the following checkboxes:
    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • Report FF Proxy Settings
    • Reset FF Proxy Settings
    • List content of Hosts
    • List IP configuration
    • List Winsock Entries
    • List last 10 Event Viewer log
    • List Installed Programs
    • List Users, Partitions and Memory size.
  • Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run. Note: When using "Reset FF Proxy Settings" option Firefox should be closed.
SXvL3ZF.pngTDSSKiller
  • Download TDSSKiller and save it to your desktop.
  • Extract (unzip) its contents to your desktop.
  • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
  • If an infected file is detected, the default action will be Cure, click on Continue.
  • If a suspicious file is detected, the default action will be Skip, click on Continue.
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
  • If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
zcMPezJ.pngAdwCleaner
  • Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool. Vista/Windows 7/8 users right-click and select Run As Administrator
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
lv0mVRW.pngJunkware Removal Tool
  • Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
cvMlKv6.pngESET Online Scanner
  • Click here to download the installer for ESET Online Scanner and save it to your Desktop.
  • Disable all your antivirus and antimalware software - see how to do that here.
  • Right click on esetsmartinstaller_enu.exe and select Run as Administrator.
  • Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.
  • Select Enable detection of potentially unwanted applications.
  • Click Advanced Settings, then place a checkmark in the following:
    • Remove found threats
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click Start to begin scanning.
  • ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
  • When the scan is done, click List threats (only available if ESET Online Scanner found something).
  • Click Export, then save the file to your desktop.
  • Click Back, then Finish to exit ESET Online Scanner.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#3 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 20 September 2015 - 08:42 PM

MiniToolBox by Farbar  Version: 25-07-2015 01
Ran by Shravan (administrator) on 21-09-2015 at 06:25:20
Running from "C:\Users\Shravan\Downloads"
Microsoft Windows 7 Ultimate  Service Pack 1 (X64)
Model: System Product Name Manufacturer: System manufacturer
Boot Mode: Normal
***************************************************************************
 
========================= Flush DNS: ===================================
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========================= IE Proxy Settings: ============================== 
 
Proxy is not enabled.
No Proxy Server is set.
 
"Reset IE Proxy Settings": IE Proxy Settings were reset.
 
========================= FF Proxy Settings: ============================== 
 
 
"Reset FF Proxy Settings": Firefox Proxy settings were reset.
 
========================= Hosts content: =================================
 
 
 
========================= IP Configuration: ================================
 
Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller = Local Area Connection (Connected)
 
 
# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4
 
reset
set global icmpredirects=enabled
add route prefix=0.0.0.0/0 interface="Local Area Connection" nexthop=192.168.1.1 publish=Yes
add address name="Local Area Connection" address=192.168.1.100 mask=255.255.255.0
 
 
popd
# End of IPv4 configuration
 
 
 
Windows IP Configuration
 
   Host Name . . . . . . . . . . . . : Shravan-PC
   Primary Dns Suffix  . . . . . . . : 
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
 
Ethernet adapter Local Area Connection:
 
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
   Physical Address. . . . . . . . . : BC-AE-C5-47-59-77
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::a465:9d1c:90b7:30cb%10(Preferred) 
   IPv4 Address. . . . . . . . . . . : 192.168.1.100(Preferred) 
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : fe80::ed2:b5ff:fe04:892c%10
                                       192.168.1.1
   DHCPv6 IAID . . . . . . . . . . . : 180137669
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-18-46-A3-6B-BC-AE-C5-47-59-77
   DNS Servers . . . . . . . . . . . : 125.22.47.125
                                       202.56.250.5
   NetBIOS over Tcpip. . . . . . . . : Enabled
 
Tunnel adapter isatap.{2BE50405-7707-4913-8488-C5774ABE191E}:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
 
Tunnel adapter Teredo Tunneling Pseudo-Interface:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : 
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  aes-static-125.47.22.125.airtel.in
Address:  125.22.47.125
 
Name:    google.com
Addresses:  2404:6800:4007:805::200e
 216.58.220.46
 
 
Pinging google.com [216.58.220.46] with 32 bytes of data:
Reply from 216.58.220.46: bytes=32 time=30ms TTL=56
Reply from 216.58.220.46: bytes=32 time=31ms TTL=56
 
Ping statistics for 216.58.220.46:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 30ms, Maximum = 31ms, Average = 30ms
Server:  aes-static-125.47.22.125.airtel.in
Address:  125.22.47.125
 
Name:    yahoo.com
Addresses:  2001:4998:44:204::a7
 2001:4998:c:a06::2:4008
 2001:4998:58:c02::a9
 98.138.253.109
 206.190.36.45
 98.139.183.24
 
 
Pinging yahoo.com [206.190.36.45] with 32 bytes of data:
Reply from 206.190.36.45: bytes=32 time=288ms TTL=46
Reply from 206.190.36.45: bytes=32 time=287ms TTL=46
 
Ping statistics for 206.190.36.45:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 287ms, Maximum = 288ms, Average = 287ms
 
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
 
Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 10...bc ae c5 47 59 77 ......Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
  1...........................Software Loopback Interface 1
 11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
 12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
===========================================================================
 
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      192.168.1.1    192.168.1.100    276
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link     192.168.1.100    276
    192.168.1.100  255.255.255.255         On-link     192.168.1.100    276
    192.168.1.255  255.255.255.255         On-link     192.168.1.100    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link     192.168.1.100    276
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link     192.168.1.100    276
===========================================================================
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
          0.0.0.0          0.0.0.0      192.168.1.1  Default 
===========================================================================
 
IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 10    276 ::/0                     fe80::ed2:b5ff:fe04:892c
  1    306 ::1/128                  On-link
 10    276 fe80::/64                On-link
 10    276 fe80::a465:9d1c:90b7:30cb/128
                                    On-link
  1    306 ff00::/8                 On-link
 10    276 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================
 
Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648] (Microsoft Corp.)
Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145648] (Microsoft Corp.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760] (Microsoft Corp.)
x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [171760] (Microsoft Corp.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
 
========================= Event log errors: ===============================
 
Application errors:
==================
Error: (09/11/2015 11:22:05 AM) (Source: Application Error) (User: )
Description: Faulting application name: Now.exe, version: 1.13.2.0, time stamp: 0x53058be3
Faulting module name: ntdll.dll, version: 6.1.7601.18939, time stamp: 0x55afd843
Exception code: 0xc0150010
Fault offset: 0x00084a6b
Faulting process id: 0x15f0
Faulting application start time: 0xNow.exe0
Faulting application path: Now.exe1
Faulting module path: Now.exe2
Report Id: Now.exe3
 
Error: (09/11/2015 11:22:03 AM) (Source: Application Error) (User: )
Description: Faulting application name: Now.exe, version: 1.13.2.0, time stamp: 0x53058be3
Faulting module name: Now.exe, version: 1.13.2.0, time stamp: 0x53058be3
Exception code: 0xc0000005
Fault offset: 0x00006abb
Faulting process id: 0x15f0
Faulting application start time: 0xNow.exe0
Faulting application path: Now.exe1
Faulting module path: Now.exe2
Report Id: Now.exe3
 
Error: (09/08/2015 10:07:11 AM) (Source: Application Error) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17923, time stamp: 0x55945dbd
Faulting module name: ntdll.dll, version: 6.1.7601.18939, time stamp: 0x55b02e88
Exception code: 0xc0000005
Fault offset: 0x000000000004ac04
Faulting process id: 0x10dc
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3
 
Error: (09/08/2015 05:40:06 AM) (Source: Application Hang) (User: )
Description: The program IEXPLORE.EXE version 11.0.9600.17937 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1704
 
Start Time: 01d0e9caa4a76a24
 
Termination Time: 0
 
Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Report Id:
 
Error: (09/04/2015 12:56:31 PM) (Source: Application Hang) (User: )
Description: The program chrome.exe version 45.0.2454.85 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1564
 
Start Time: 01d0e6e2bd46a515
 
Termination Time: 4
 
Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
Report Id: 27419a43-52d6-11e5-830e-bcaec5475977
 
Error: (09/03/2015 12:08:26 PM) (Source: Application Error) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17923, time stamp: 0x55945dbd
Faulting module name: ntdll.dll, version: 6.1.7601.18939, time stamp: 0x55b02e88
Exception code: 0xc0000005
Fault offset: 0x000000000004ac04
Faulting process id: 0x16e0
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3
 
Error: (08/28/2015 03:26:07 PM) (Source: Application Error) (User: )
Description: Faulting application name: explorer.exe, version: 6.1.7601.17567, time stamp: 0x4d672ee4
Faulting module name: MSVCR90.dll, version: 9.0.30729.6161, time stamp: 0x4dace4e7
Exception code: 0xc0000005
Fault offset: 0x000000000001e1ac
Faulting process id: 0x1030
Faulting application start time: 0xexplorer.exe0
Faulting application path: explorer.exe1
Faulting module path: explorer.exe2
Report Id: explorer.exe3
 
Error: (08/28/2015 03:25:41 PM) (Source: Application Error) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4
Faulting module name: MSVCR90.dll, version: 9.0.30729.6161, time stamp: 0x4dace4e7
Exception code: 0xc0000005
Fault offset: 0x000000000001e1ac
Faulting process id: 0x4a4
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3
 
Error: (08/21/2015 02:18:51 PM) (Source: Application Hang) (User: )
Description: The program wlmail.exe version 16.4.3528.331 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1a3c
 
Start Time: 01d0dbd7a0cba121
 
Termination Time: 37
 
Application Path: C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
 
Report Id: 6f8b9057-47e1-11e5-8878-bcaec5475977
 
Error: (08/21/2015 11:35:51 AM) (Source: Application Hang) (User: )
Description: The program wlmail.exe version 16.4.3528.331 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 174c
 
Start Time: 01d0dbd7529211e8
 
Termination Time: 24
 
Application Path: C:\Program Files (x86)\Windows Live\Mail\wlmail.exe
 
Report Id: a9452330-47ca-11e5-8878-bcaec5475977
 
 
System errors:
=============
Error: (09/21/2015 05:46:24 AM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureCommand with the following error: 
%%5
 
Error: (09/21/2015 05:46:09 AM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
%%5
 
Error: (09/21/2015 05:39:12 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (09/20/2015 11:52:34 AM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureCommand with the following error: 
%%5
 
Error: (09/20/2015 11:51:52 AM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error: 
%%5
 
Error: (09/20/2015 11:44:46 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (09/20/2015 11:39:50 AM) (Source: Microsoft Antimalware) (User: )
Description: %%860 Real-Time Protection feature has encountered an error and failed.
 
Feature: %%886
 
Error Code: 0x80004004
 
Error description: Operation aborted 
 
Reason: %%892
 
Error: (09/20/2015 11:39:35 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
 
Error: (09/20/2015 11:39:31 AM) (Source: Service Control Manager) (User: )
Description: The Group Policy Client service did not shut down properly after receiving a preshutdown control.
 
Error: (09/20/2015 05:46:22 AM) (Source: Service Control Manager) (User: )
Description: The ScRegSetValueExW call failed for FailureCommand with the following error: 
%%5
 
 
Microsoft Office Sessions:
=========================
Error: (09/11/2015 11:22:05 AM) (Source: Application Error)(User: )
Description: Now.exe1.13.2.053058be3ntdll.dll6.1.7601.1893955afd843c015001000084a6b15f001d0ec411e2e9062C:\Program Files\NOW\Now.exeC:\Windows\SysWOW64\ntdll.dll3ae855b2-5849-11e5-801e-bcaec5475977
 
Error: (09/11/2015 11:22:03 AM) (Source: Application Error)(User: )
Description: Now.exe1.13.2.053058be3Now.exe1.13.2.053058be3c000000500006abb15f001d0ec411e2e9062C:\Program Files\NOW\Now.exeC:\Program Files\NOW\Now.exe395d1c08-5849-11e5-801e-bcaec5475977
 
Error: (09/08/2015 10:07:11 AM) (Source: Application Error)(User: )
Description: GWXUX.exe6.3.9600.1792355945dbdntdll.dll6.1.7601.1893955b02e88c0000005000000000004ac0410dc01d0e9f005ee3471C:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dll44bdcf6d-55e3-11e5-8846-bcaec5475977
 
Error: (09/08/2015 05:40:06 AM) (Source: Application Hang)(User: )
Description: IEXPLORE.EXE11.0.9600.17937170401d0e9caa4a76a240C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
 
Error: (09/04/2015 12:56:31 PM) (Source: Application Hang)(User: )
Description: chrome.exe45.0.2454.85156401d0e6e2bd46a5154C:\Program Files (x86)\Google\Chrome\Application\chrome.exe27419a43-52d6-11e5-830e-bcaec5475977
 
Error: (09/03/2015 12:08:26 PM) (Source: Application Error)(User: )
Description: GWXUX.exe6.3.9600.1792355945dbdntdll.dll6.1.7601.1893955b02e88c0000005000000000004ac0416e001d0e6132242f329C:\Windows\System32\GWX\GWXUX.exeC:\Windows\SYSTEM32\ntdll.dll60f2f7bf-5206-11e5-83fa-bcaec5475977
 
Error: (08/28/2015 03:26:07 PM) (Source: Application Error)(User: )
Description: explorer.exe6.1.7601.175674d672ee4MSVCR90.dll9.0.30729.61614dace4e7c0000005000000000001e1ac103001d0e177b737a6f5C:\Windows\explorer.exeC:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_08e61857a83bc251\MSVCR90.dll002aed13-4d6b-11e5-84ea-bcaec5475977
 
Error: (08/28/2015 03:25:41 PM) (Source: Application Error)(User: )
Description: Explorer.EXE6.1.7601.175674d672ee4MSVCR90.dll9.0.30729.61614dace4e7c0000005000000000001e1ac4a401d0e127d287c807C:\Windows\Explorer.EXEC:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_08e61857a83bc251\MSVCR90.dllf0be5602-4d6a-11e5-84ea-bcaec5475977
 
Error: (08/21/2015 02:18:51 PM) (Source: Application Hang)(User: )
Description: wlmail.exe16.4.3528.3311a3c01d0dbd7a0cba12137C:\Program Files (x86)\Windows Live\Mail\wlmail.exe6f8b9057-47e1-11e5-8878-bcaec5475977
 
Error: (08/21/2015 11:35:51 AM) (Source: Application Hang)(User: )
Description: wlmail.exe16.4.3528.331174c01d0dbd7529211e824C:\Program Files (x86)\Windows Live\Mail\wlmail.exea9452330-47ca-11e5-8878-bcaec5475977
 
 
=========================== Installed Programs ============================
 
AC3Filter 2.6.0b (HKLM-x32\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky)
Adobe Flash Player 18 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{5E03A267-415E-5383-FA8F-3CE4145663B9}) (Version: 8.0.903.0 - Advanced Micro Devices, Inc.)
BOLTPlusOnWeb (HKLM-x32\...\{D45758D3-E62A-42BC-AF9D-EEE4EB23D9DF}) (Version: 4.21.1129 - MarketPlace Technologies Pvt. Ltd.)
Bullzip PDF Printer 10.20.0.2459 (HKLM\...\Bullzip PDF Printer_is1) (Version: 10.20.0.2459 - Bullzip)
Caesar 3 (HKLM-x32\...\Caesar 3) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Cool & Quiet (HKLM-x32\...\{1ADE1AA0-7F82-4BB1-B1BD-727DE438057B}) (Version:  - )
CPUID HWMonitor 1.21 (HKLM\...\CPUID HWMonitor_is1) (Version:  - )
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DivX Setup (HKLM-x32\...\DivX Setup) (Version: 2.7.0.70 - DivX, LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.93 - Google Inc.)
Google Drive (HKLM-x32\...\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.)
Google Earth Pro (HKLM-x32\...\{FBAA5E9E-8614-11E1-B079-B8AC6F97B88E}) (Version: 6.2.2.6613 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.28.15 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
JMicron JMB36X Driver (HKLM-x32\...\{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}) (Version: 1.17.62.0 - JMicron Technology Corp.)
Junk Mail filter update (HKLM-x32\...\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Marvell Miniport Driver (HKLM-x32\...\Marvell Miniport Driver) (Version: 11.24.10.3 - Marvell)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{6965A8D2-465D-4F98-9FAA-0E9E2348F329}) (Version: 3.22.270.0 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM-x32\...\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft OneDrive (HKCU\...\OneDriveSetup.exe) (Version: 17.3.1229.0918 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 40.0.3 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 40.0.3 (x86 en-US)) (Version: 40.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 40.0.3.5716 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NEC Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.19.0 - NEC Electronics Corporation) Hidden
NEC Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.19.0 - NEC Electronics Corporation)
NOW (HKLM-x32\...\{FB99AFEA-0B85-4FDB-8026-3B073033CC6D}) (Version: 1.13.2.0 - Dotex International)
Nymgo (HKCU\...\Nymgo) (Version: 5.3.36 - Nymgo S.A.)
Oracle Database 11g Express Edition (HKLM-x32\...\{05A7B662-80A3-4EB9-AE1D-89A62449431C}) (Version: 11.2.0 - Oracle Corporation) Hidden
Oracle Database 11g Express Edition (HKLM-x32\...\InstallShield_{05A7B662-80A3-4EB9-AE1D-89A62449431C}) (Version: 11.2.0 - Oracle Corporation)
PDFill FREE PDF Tools (HKLM\...\{60724DF0-7436-48B8-BEF9-07BA4C3880EE}) (Version: 9.0 - PlotSoft LLC)
Power Indiabulls (HKLM-x32\...\{5119A2DE-A628-4471-9CF8-50B6F974B315}) (Version: 5.0 - Indiabulls Securities Ltd)
Sierra Utilities (HKLM-x32\...\Sierra Utilities) (Version:  - )
Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.28 - Piriform)
SpywareBlaster 5.2 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.2.0 - BrightFort LLC)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.45862 - TeamViewer)
VC80CRTRedist - 8.0.50727.6195 (HKLM-x32\...\{933B4015-4618-4716-A828-5289FC03165F}) (Version: 1.2.0 - DivX, Inc) Hidden
Viber (HKCU\...\Viber) (Version: 5.1.1.15 - Viber Media Inc)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Phone app for desktop (HKLM-x32\...\{5F71448B-88EB-4357-9A98-8658D4C49C48}) (Version: 1.1.2726.0 - Microsoft Corporation)
Yahoo! Messenger (HKLM-x32\...\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
 
========================= Memory info: ===================================
 
Percentage of memory in use: 32%
Total physical RAM: 8190.18 MB
Available physical RAM: 5535.8 MB
Total Virtual: 16378.55 MB
Available Virtual: 13048.95 MB
 
========================= Partitions: =====================================
 
1 Drive c: (New Volume) (Fixed) (Total:270.45 GB) (Free:150.56 GB) NTFS
2 Drive d: (New Volume) (Fixed) (Total:195.31 GB) (Free:181.19 GB) NTFS
3 Drive f: (New Volume) (Fixed) (Total:232.88 GB) (Free:84.62 GB) NTFS
 
========================= Users: ========================================
 
User accounts for \\SHRAVAN-PC
 
Administrator            Guest                    Shravan                  
 
 
**** End of log ****


#4 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 20 September 2015 - 08:44 PM

06:28:07.0033 0x0fcc  TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57
06:28:11.0947 0x0fcc  ============================================================
06:28:11.0947 0x0fcc  Current date / time: 2015/09/21 06:28:11.0947
06:28:11.0947 0x0fcc  SystemInfo:
06:28:11.0947 0x0fcc  
06:28:11.0947 0x0fcc  OS Version: 6.1.7601 ServicePack: 1.0
06:28:11.0947 0x0fcc  Product type: Workstation
06:28:11.0947 0x0fcc  ComputerName: SHRAVAN-PC
06:28:11.0947 0x0fcc  UserName: Shravan
06:28:11.0947 0x0fcc  Windows directory: C:\Windows
06:28:11.0947 0x0fcc  System windows directory: C:\Windows
06:28:11.0947 0x0fcc  Running under WOW64
06:28:11.0947 0x0fcc  Processor architecture: Intel x64
06:28:11.0947 0x0fcc  Number of processors: 6
06:28:11.0947 0x0fcc  Page size: 0x1000
06:28:11.0947 0x0fcc  Boot type: Normal boot
06:28:11.0947 0x0fcc  ============================================================
06:28:13.0897 0x0fcc  KLMD registered as C:\Windows\system32\drivers\23453336.sys
06:28:14.0724 0x0fcc  System UUID: {E83D9CBF-3169-3904-9626-0D870BDFABFA}
06:28:15.0457 0x0fcc  Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
06:28:18.0531 0x0fcc  Drive \Device\Harddisk1\DR1 - Size: 0x3A38B2E000 ( 232.89 Gb ), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
06:28:18.0531 0x0fcc  ============================================================
06:28:18.0531 0x0fcc  \Device\Harddisk0\DR0:
06:28:18.0546 0x0fcc  MBR partitions:
06:28:18.0546 0x0fcc  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x21CE666A
06:28:18.0546 0x0fcc  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x21CE66A9, BlocksNum 0x1869E598
06:28:18.0546 0x0fcc  \Device\Harddisk1\DR1:
06:28:18.0546 0x0fcc  MBR partitions:
06:28:18.0546 0x0fcc  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1D1C4800
06:28:18.0546 0x0fcc  ============================================================
06:28:18.0562 0x0fcc  C: <-> \Device\Harddisk0\DR0\Partition1
06:28:18.0610 0x0fcc  D: <-> \Device\Harddisk0\DR0\Partition2
06:28:18.0750 0x0fcc  F: <-> \Device\Harddisk1\DR1\Partition1
06:28:18.0750 0x0fcc  ============================================================
06:28:18.0750 0x0fcc  Initialize success
06:28:18.0750 0x0fcc  ============================================================
06:28:20.0294 0x0e54  ============================================================
06:28:20.0294 0x0e54  Scan started
06:28:20.0294 0x0e54  Mode: Manual; 
06:28:20.0294 0x0e54  ============================================================
06:28:20.0294 0x0e54  KSN ping started
06:28:23.0134 0x0e54  KSN ping finished: true
06:28:24.0116 0x0e54  ================ Scan system memory ========================
06:28:24.0116 0x0e54  System memory - ok
06:28:24.0116 0x0e54  ================ Scan services =============================
06:28:24.0319 0x0e54  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
06:28:24.0319 0x0e54  1394ohci - ok
06:28:24.0397 0x0e54  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
06:28:24.0413 0x0e54  ACPI - ok
06:28:24.0444 0x0e54  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
06:28:24.0444 0x0e54  AcpiPmi - ok
06:28:24.0553 0x0e54  [ 013697369EAFFA675D0671607F036020, 65611C775AC4681E46A6565E5A7A4FF3363C66EBDC98C4C58AFB365D40BE23B6 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
06:28:24.0569 0x0e54  AdobeARMservice - ok
06:28:24.0694 0x0e54  [ 368290D0A612D62DA6F3D798B1BB8FE7, D573BF8543F37BC51B88A2473EDFD28AFBCCC446E8CADD54A90FA48D8739D222 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
06:28:24.0694 0x0e54  AdobeFlashPlayerUpdateSvc - ok
06:28:24.0756 0x0e54  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
06:28:24.0772 0x0e54  adp94xx - ok
06:28:24.0787 0x0e54  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
06:28:24.0803 0x0e54  adpahci - ok
06:28:24.0818 0x0e54  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
06:28:24.0818 0x0e54  adpu320 - ok
06:28:24.0850 0x0e54  [ 83BFCCAC53795E8A5055A93672D0C46C, B2B03473D950A5BA9DE59D81E7B14C1FAFF17B2A4D8A5808588F5CC21D63B291 ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
06:28:24.0850 0x0e54  AeLookupSvc - ok
06:28:24.0896 0x0e54  [ FA886682CFC5D36718D3E436AACF10B9, F80AB4F91AA6B5C7ECCB000D8E1BC2CF776DC3D69B3D9EBC2558C19035A6B3AB ] AFD             C:\Windows\system32\drivers\afd.sys
06:28:24.0912 0x0e54  AFD - ok
06:28:24.0959 0x0e54  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
06:28:24.0959 0x0e54  agp440 - ok
06:28:24.0974 0x0e54  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG             C:\Windows\System32\alg.exe
06:28:24.0990 0x0e54  ALG - ok
06:28:25.0006 0x0e54  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
06:28:25.0006 0x0e54  aliide - ok
06:28:25.0037 0x0e54  [ 4EAAAAB8759644D572522FBCDD196A13, EF1ECE8073B048C2286F639BA76C523B6B267B64447358383C042BD593194350 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
06:28:25.0052 0x0e54  AMD External Events Utility - ok
06:28:25.0130 0x0e54  AMD FUEL Service - ok
06:28:25.0146 0x0e54  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
06:28:25.0146 0x0e54  amdide - ok
06:28:25.0193 0x0e54  [ 6A2EEB0C4133B20773BB3DD0B7B377B4, E4CB35C6937C70A145A13E5AE5B34A271B49101DA623171ACBFDA8601E5A70EA ] amdiox64        C:\Windows\system32\DRIVERS\amdiox64.sys
06:28:25.0193 0x0e54  amdiox64 - ok
06:28:25.0240 0x0e54  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
06:28:25.0240 0x0e54  AmdK8 - ok
06:28:25.0505 0x0e54  [ 22A14DF59FB8D0BE918C597988AF4296, 714BD1BB63D732C6D03DFA1C2D81A2E00659C04052E110F0BF1EB74A7CD39B1C ] amdkmdag        C:\Windows\system32\DRIVERS\atikmdag.sys
06:28:25.0754 0x0e54  amdkmdag - ok
06:28:25.0786 0x0e54  [ EE22D3ED6D55A855E709F811CCCA97ED, 179F34CF6E0C2F821EBC0AECF09AAA0867616CCBB5EA6B17891860B27D56AC66 ] amdkmdap        C:\Windows\system32\DRIVERS\atikmpag.sys
06:28:25.0803 0x0e54  amdkmdap - ok
06:28:25.0819 0x0e54  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
06:28:25.0819 0x0e54  AmdPPM - ok
06:28:25.0850 0x0e54  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
06:28:25.0850 0x0e54  amdsata - ok
06:28:25.0866 0x0e54  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
06:28:25.0881 0x0e54  amdsbs - ok
06:28:25.0897 0x0e54  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata         C:\Windows\system32\drivers\amdxata.sys
06:28:25.0897 0x0e54  amdxata - ok
06:28:25.0928 0x0e54  [ 5A528A540B1AEE8B1C77ED65094E8CDF, 6E3DE68E630B81425056AB58E64721DD41F56491DD2D281CBB86AA7EF9CAD0E0 ] AODDriver4.2    C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys
06:28:25.0928 0x0e54  AODDriver4.2 - ok
06:28:25.0975 0x0e54  [ A0711D119BA4B48A1470C768D301013E, 536366F809125D2C2171597C8C2CB3271BE5C6B373152112E0D970749776E00A ] AppID           C:\Windows\system32\drivers\appid.sys
06:28:25.0975 0x0e54  AppID - ok
06:28:26.0006 0x0e54  [ 173C90AF5B243B4DD86F95CA154CB58A, 349F566DADC96B31FDC34C4F26545FB880844DBF84E5821AA0D0CAA91FB837E1 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
06:28:26.0006 0x0e54  AppIDSvc - ok
06:28:26.0037 0x0e54  [ 3EA5DA3F459F6ED19E10166965F6892F, F5618A5FA72C5E57BCFA6F2ECB840B1AEC60C72840AF3C1D94D5FCDB5ED2BF5E ] Appinfo         C:\Windows\System32\appinfo.dll
06:28:26.0037 0x0e54  Appinfo - ok
06:28:26.0068 0x0e54  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt         C:\Windows\System32\appmgmts.dll
06:28:26.0084 0x0e54  AppMgmt - ok
06:28:26.0131 0x0e54  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc             C:\Windows\system32\DRIVERS\arc.sys
06:28:26.0131 0x0e54  arc - ok
06:28:26.0131 0x0e54  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
06:28:26.0146 0x0e54  arcsas - ok
06:28:26.0209 0x0e54  [ 68726474C69B738EAC3A62E06B33ADDC, C470C9DB58840149CE002F3E6003382ECF740884A683BAE8F9D10831BE218FA2 ] AsIO            C:\Windows\syswow64\drivers\AsIO.sys
06:28:26.0240 0x0e54  AsIO - ok
06:28:26.0412 0x0e54  [ F15AB80B867D3332D5DDFB0A05B9CE04, 5A16577106246AB5DCC04FE0A0B00B7C5702557B75F958721E4C00383AB99809 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
06:28:26.0412 0x0e54  aspnet_state - ok
06:28:26.0427 0x0e54  Ast Service - ok
06:28:26.0443 0x0e54  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
06:28:26.0443 0x0e54  AsyncMac - ok
06:28:26.0474 0x0e54  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi           C:\Windows\system32\drivers\atapi.sys
06:28:26.0474 0x0e54  atapi - ok
06:28:26.0490 0x0e54  [ 437F55435623D4D54D36197F5AD8B435, CE004F1E3299E39AFD70C8618253901614C0F3DBD594B6F0E1BA294C7B47FAD6 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
06:28:26.0505 0x0e54  AtiHDAudioService - ok
06:28:26.0552 0x0e54  [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
06:28:26.0552 0x0e54  AudioEndpointBuilder - ok
06:28:26.0599 0x0e54  [ 6968D02DC38757C3FBE7ED7C2F9670AA, C8B3115DDB32EFBE8C56C5AA78EEA05BBB77DF3F75CC2A04532EB32327E4735A ] AudioSrv        C:\Windows\System32\Audiosrv.dll
06:28:26.0614 0x0e54  AudioSrv - ok
06:28:26.0677 0x0e54  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
06:28:26.0677 0x0e54  AxInstSV - ok
06:28:26.0770 0x0e54  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbda.sys
06:28:26.0786 0x0e54  b06bdrv - ok
06:28:26.0817 0x0e54  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
06:28:26.0833 0x0e54  b57nd60a - ok
06:28:26.0864 0x0e54  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
06:28:26.0864 0x0e54  BDESVC - ok
06:28:26.0880 0x0e54  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
06:28:26.0880 0x0e54  Beep - ok
06:28:26.0942 0x0e54  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE             C:\Windows\System32\bfe.dll
06:28:26.0958 0x0e54  BFE - ok
06:28:27.0004 0x0e54  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\System32\qmgr.dll
06:28:27.0020 0x0e54  BITS - ok
06:28:27.0051 0x0e54  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
06:28:27.0051 0x0e54  blbdrive - ok
06:28:27.0082 0x0e54  [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107C2AE2703A2CF28 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
06:28:27.0082 0x0e54  bowser - ok
06:28:27.0098 0x0e54  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
06:28:27.0098 0x0e54  BrFiltLo - ok
06:28:27.0098 0x0e54  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
06:28:27.0098 0x0e54  BrFiltUp - ok
06:28:27.0145 0x0e54  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser         C:\Windows\System32\browser.dll
06:28:27.0145 0x0e54  Browser - ok
06:28:27.0160 0x0e54  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
06:28:27.0160 0x0e54  Brserid - ok
06:28:27.0176 0x0e54  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
06:28:27.0176 0x0e54  BrSerWdm - ok
06:28:27.0192 0x0e54  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
06:28:27.0192 0x0e54  BrUsbMdm - ok
06:28:27.0192 0x0e54  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
06:28:27.0192 0x0e54  BrUsbSer - ok
06:28:27.0207 0x0e54  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
06:28:27.0207 0x0e54  BTHMODEM - ok
06:28:27.0238 0x0e54  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv         C:\Windows\system32\bthserv.dll
06:28:27.0238 0x0e54  bthserv - ok
06:28:27.0254 0x0e54  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
06:28:27.0270 0x0e54  cdfs - ok
06:28:27.0301 0x0e54  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
06:28:27.0316 0x0e54  cdrom - ok
06:28:27.0348 0x0e54  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc     C:\Windows\System32\certprop.dll
06:28:27.0348 0x0e54  CertPropSvc - ok
06:28:27.0379 0x0e54  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
06:28:27.0379 0x0e54  circlass - ok
06:28:27.0426 0x0e54  [ 404B7DF9CA4D1CB675045AF220FF3285, 91FFADE2ABE5C48849E63134D5FFD20671FE0D1720F7D486F904391B3D142C96 ] CLFS            C:\Windows\system32\CLFS.sys
06:28:27.0441 0x0e54  CLFS - ok
06:28:27.0519 0x0e54  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
06:28:27.0519 0x0e54  clr_optimization_v2.0.50727_32 - ok
06:28:27.0566 0x0e54  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
06:28:27.0582 0x0e54  clr_optimization_v2.0.50727_64 - ok
06:28:27.0644 0x0e54  [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
06:28:27.0644 0x0e54  clr_optimization_v4.0.30319_32 - ok
06:28:27.0675 0x0e54  [ 9ACBE5EC13C2CC95833BFB7636CA8B1A, 6224DA9FB335D2A8374C60B8DEA539DD3A0E43230DB888B137B71A56EC57D6AF ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
06:28:27.0675 0x0e54  clr_optimization_v4.0.30319_64 - ok
06:28:27.0691 0x0e54  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
06:28:27.0691 0x0e54  CmBatt - ok
06:28:27.0706 0x0e54  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
06:28:27.0706 0x0e54  cmdide - ok
06:28:27.0784 0x0e54  [ 27667A788130A7F7A5858DE27572E6D7, 5501D80BCCB7A811ECCED3828DFD0A5D948BBED8504E9BCC4A3BFB840DD41CBC ] CNG             C:\Windows\system32\Drivers\cng.sys
06:28:27.0784 0x0e54  CNG - ok
06:28:27.0816 0x0e54  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
06:28:27.0831 0x0e54  Compbatt - ok
06:28:27.0878 0x0e54  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
06:28:27.0878 0x0e54  CompositeBus - ok
06:28:27.0878 0x0e54  COMSysApp - ok
06:28:27.0894 0x0e54  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
06:28:27.0894 0x0e54  crcdisk - ok
06:28:27.0925 0x0e54  [ 7BC3E861F7E8EB543A630090FAE779E0, 52A538F25C853AAC9706CD0D4EBF80B1963391AA175895CFD9D44C8ABBFCFB74 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
06:28:27.0940 0x0e54  CryptSvc - ok
06:28:27.0972 0x0e54  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC             C:\Windows\system32\drivers\csc.sys
06:28:27.0972 0x0e54  CSC - ok
06:28:28.0018 0x0e54  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
06:28:28.0018 0x0e54  CscService - ok
06:28:28.0050 0x0e54  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] DcomLaunch      C:\Windows\system32\rpcss.dll
06:28:28.0050 0x0e54  DcomLaunch - ok
06:28:28.0096 0x0e54  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc       C:\Windows\System32\defragsvc.dll
06:28:28.0096 0x0e54  defragsvc - ok
06:28:28.0143 0x0e54  [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751FB26DFB318636F ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
06:28:28.0143 0x0e54  DfsC - ok
06:28:28.0174 0x0e54  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
06:28:28.0174 0x0e54  Dhcp - ok
06:28:28.0284 0x0e54  [ EC3F433D00365F1A9BC3411BCA7C7140, 0852D747359DE573504EBBDB99DA26D3BFA8B3C7A4836F8E3A5AD94B5571AD5C ] DiagTrack       C:\Windows\system32\diagtrack.dll
06:28:28.0299 0x0e54  DiagTrack - ok
06:28:28.0346 0x0e54  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
06:28:28.0346 0x0e54  discache - ok
06:28:28.0377 0x0e54  [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA91275E26056D427 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
06:28:28.0377 0x0e54  Disk - ok
06:28:28.0408 0x0e54  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
06:28:28.0408 0x0e54  Dnscache - ok
06:28:28.0455 0x0e54  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc         C:\Windows\System32\dot3svc.dll
06:28:28.0455 0x0e54  dot3svc - ok
06:28:28.0486 0x0e54  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS             C:\Windows\system32\dps.dll
06:28:28.0486 0x0e54  DPS - ok
06:28:28.0533 0x0e54  [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45BFC03C5DA7F21A7 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
06:28:28.0533 0x0e54  drmkaud - ok
06:28:28.0580 0x0e54  [ 87CE5C8965E101CCCED1F4675557E868, 077D98F0F130B2FC710208BA34016EF2B2506EE2BD71740B228145E34A3046F1 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
06:28:28.0596 0x0e54  DXGKrnl - ok
06:28:28.0642 0x0e54  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost         C:\Windows\System32\eapsvc.dll
06:28:28.0642 0x0e54  EapHost - ok
06:28:28.0736 0x0e54  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv           C:\Windows\system32\DRIVERS\evbda.sys
06:28:28.0830 0x0e54  ebdrv - ok
06:28:28.0861 0x0e54  [ 3E9BDCA3994E2B6B6AC16BAA76722934, A77FEE9D78C1151B13C9509FA89B64024442D00C3C9EA19954045413D8A69D73 ] EFS             C:\Windows\System32\lsass.exe
06:28:28.0861 0x0e54  EFS - ok
06:28:28.0908 0x0e54  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
06:28:28.0939 0x0e54  ehRecvr - ok
06:28:28.0970 0x0e54  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched         C:\Windows\ehome\ehsched.exe
06:28:28.0970 0x0e54  ehSched - ok
06:28:29.0017 0x0e54  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
06:28:29.0032 0x0e54  elxstor - ok
06:28:29.0048 0x0e54  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
06:28:29.0048 0x0e54  ErrDev - ok
06:28:29.0095 0x0e54  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem     C:\Windows\system32\es.dll
06:28:29.0110 0x0e54  EventSystem - ok
06:28:29.0126 0x0e54  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat           C:\Windows\system32\drivers\exfat.sys
06:28:29.0126 0x0e54  exfat - ok
06:28:29.0173 0x0e54  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
06:28:29.0173 0x0e54  fastfat - ok
06:28:29.0220 0x0e54  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax             C:\Windows\system32\fxssvc.exe
06:28:29.0235 0x0e54  Fax - ok
06:28:29.0251 0x0e54  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
06:28:29.0251 0x0e54  fdc - ok
06:28:29.0266 0x0e54  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost         C:\Windows\system32\fdPHost.dll
06:28:29.0266 0x0e54  fdPHost - ok
06:28:29.0282 0x0e54  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
06:28:29.0282 0x0e54  FDResPub - ok
06:28:29.0298 0x0e54  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
06:28:29.0298 0x0e54  FileInfo - ok
06:28:29.0298 0x0e54  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
06:28:29.0313 0x0e54  Filetrace - ok
06:28:29.0329 0x0e54  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
06:28:29.0329 0x0e54  flpydisk - ok
06:28:29.0376 0x0e54  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
06:28:29.0376 0x0e54  FltMgr - ok
06:28:29.0438 0x0e54  [ D5A775990A7C202A037378FDBCDB6141, 27AD242914FAFB7A27B3045C0F0F6AFE6873FE331A51D8BB29A63B5D84C72EFB ] FontCache       C:\Windows\system32\FntCache.dll
06:28:29.0454 0x0e54  FontCache - ok
06:28:29.0516 0x0e54  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
06:28:29.0516 0x0e54  FontCache3.0.0.0 - ok
06:28:29.0532 0x0e54  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
06:28:29.0532 0x0e54  FsDepends - ok
06:28:29.0563 0x0e54  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
06:28:29.0563 0x0e54  Fs_Rec - ok
06:28:29.0594 0x0e54  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
06:28:29.0610 0x0e54  fvevol - ok
06:28:29.0625 0x0e54  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
06:28:29.0625 0x0e54  gagp30kx - ok
06:28:29.0672 0x0e54  [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC963E18D47B94D24 ] gpsvc           C:\Windows\System32\gpsvc.dll
06:28:29.0688 0x0e54  gpsvc - ok
06:28:29.0859 0x0e54  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
06:28:29.0859 0x0e54  gupdate - ok
06:28:29.0875 0x0e54  [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3418A1CF0BC53E9 ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
06:28:29.0875 0x0e54  gupdatem - ok
06:28:29.0890 0x0e54  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
06:28:29.0890 0x0e54  hcw85cir - ok
06:28:29.0937 0x0e54  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
06:28:29.0937 0x0e54  HdAudAddService - ok
06:28:29.0953 0x0e54  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
06:28:29.0953 0x0e54  HDAudBus - ok
06:28:29.0968 0x0e54  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
06:28:29.0968 0x0e54  HidBatt - ok
06:28:29.0984 0x0e54  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
06:28:29.0984 0x0e54  HidBth - ok
06:28:30.0000 0x0e54  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
06:28:30.0000 0x0e54  HidIr - ok
06:28:30.0031 0x0e54  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv         C:\Windows\system32\hidserv.dll
06:28:30.0031 0x0e54  hidserv - ok
06:28:30.0078 0x0e54  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
06:28:30.0078 0x0e54  HidUsb - ok
06:28:30.0109 0x0e54  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
06:28:30.0109 0x0e54  hkmsvc - ok
06:28:30.0140 0x0e54  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
06:28:30.0140 0x0e54  HomeGroupListener - ok
06:28:30.0171 0x0e54  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
06:28:30.0187 0x0e54  HomeGroupProvider - ok
06:28:30.0202 0x0e54  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
06:28:30.0202 0x0e54  HpSAMD - ok
06:28:30.0265 0x0e54  [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
06:28:30.0280 0x0e54  HTTP - ok
06:28:30.0343 0x0e54  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
06:28:30.0343 0x0e54  hwpolicy - ok
06:28:30.0405 0x0e54  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
06:28:30.0405 0x0e54  i8042prt - ok
06:28:30.0436 0x0e54  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
06:28:30.0452 0x0e54  iaStorV - ok
06:28:30.0530 0x0e54  [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D305F016C4BDAA81 ] IDriverT        C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
06:28:30.0530 0x0e54  IDriverT - ok
06:28:30.0592 0x0e54  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
06:28:30.0624 0x0e54  idsvc - ok
06:28:30.0624 0x0e54  IEEtwCollectorService - ok
06:28:30.0670 0x0e54  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
06:28:30.0670 0x0e54  iirsp - ok
06:28:30.0702 0x0e54  [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT          C:\Windows\System32\ikeext.dll
06:28:30.0717 0x0e54  IKEEXT - ok
06:28:30.0764 0x0e54  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
06:28:30.0764 0x0e54  intelide - ok
06:28:30.0780 0x0e54  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
06:28:30.0780 0x0e54  intelppm - ok
06:28:30.0826 0x0e54  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
06:28:30.0826 0x0e54  IPBusEnum - ok
06:28:30.0873 0x0e54  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
06:28:30.0873 0x0e54  IpFilterDriver - ok
06:28:30.0920 0x0e54  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
06:28:30.0920 0x0e54  iphlpsvc - ok
06:28:30.0967 0x0e54  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
06:28:30.0967 0x0e54  IPMIDRV - ok
06:28:30.0982 0x0e54  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
06:28:30.0982 0x0e54  IPNAT - ok
06:28:31.0014 0x0e54  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
06:28:31.0014 0x0e54  IRENUM - ok
06:28:31.0045 0x0e54  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
06:28:31.0045 0x0e54  isapnp - ok
06:28:31.0076 0x0e54  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
06:28:31.0076 0x0e54  iScsiPrt - ok
06:28:31.0138 0x0e54  [ 79A55E8907F34AB569029505418C35EF, 2B97AD5800AD3F4467D30DC2F3E4A1614570D267231FBBD7C0251A2DC73402EF ] JRAID           C:\Windows\system32\DRIVERS\jraid.sys
06:28:31.0138 0x0e54  JRAID - ok
06:28:31.0154 0x0e54  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\drivers\kbdclass.sys
06:28:31.0154 0x0e54  kbdclass - ok
06:28:31.0201 0x0e54  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\drivers\kbdhid.sys
06:28:31.0201 0x0e54  kbdhid - ok
06:28:31.0216 0x0e54  [ 3E9BDCA3994E2B6B6AC16BAA76722934, A77FEE9D78C1151B13C9509FA89B64024442D00C3C9EA19954045413D8A69D73 ] KeyIso          C:\Windows\system32\lsass.exe
06:28:31.0216 0x0e54  KeyIso - ok
06:28:31.0248 0x0e54  [ 1DAC21EC0705A6AFEFACCE265798F0F9, 16B66AE2578C6744825B0DFBB9CBA35FBDF5C04E8999F7629BA43D566FA9277F ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
06:28:31.0248 0x0e54  KSecDD - ok
06:28:31.0279 0x0e54  [ 2737840E7F6F6FF439966A67A35D59F8, 7442A8864D0A92C3A7EDBF889EC1AA9F743D6B48C4075CA8F3C0F1D836DFB9CE ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
06:28:31.0279 0x0e54  KSecPkg - ok
06:28:31.0294 0x0e54  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
06:28:31.0294 0x0e54  ksthunk - ok
06:28:31.0326 0x0e54  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm           C:\Windows\system32\msdtckrm.dll
06:28:31.0341 0x0e54  KtmRm - ok
06:28:31.0372 0x0e54  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\system32\srvsvc.dll
06:28:31.0372 0x0e54  LanmanServer - ok
06:28:31.0419 0x0e54  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
06:28:31.0419 0x0e54  LanmanWorkstation - ok
06:28:31.0450 0x0e54  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
06:28:31.0450 0x0e54  lltdio - ok
06:28:31.0482 0x0e54  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
06:28:31.0482 0x0e54  lltdsvc - ok
06:28:31.0497 0x0e54  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts         C:\Windows\System32\lmhsvc.dll
06:28:31.0497 0x0e54  lmhosts - ok
06:28:31.0513 0x0e54  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
06:28:31.0513 0x0e54  LSI_FC - ok
06:28:31.0528 0x0e54  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
06:28:31.0544 0x0e54  LSI_SAS - ok
06:28:31.0544 0x0e54  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
06:28:31.0544 0x0e54  LSI_SAS2 - ok
06:28:31.0560 0x0e54  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
06:28:31.0575 0x0e54  LSI_SCSI - ok
06:28:31.0591 0x0e54  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv           C:\Windows\system32\drivers\luafv.sys
06:28:31.0591 0x0e54  luafv - ok
06:28:31.0622 0x0e54  [ DE585D1D266805E5EEDAE911FDD16F38, D954C1795D98653F1FB0AE8650FF0DEDDAA730B98C9449E6F608154D573DAB27 ] ManyCam         C:\Windows\system32\DRIVERS\mcvidrv_x64.sys
06:28:31.0622 0x0e54  ManyCam - ok
06:28:31.0684 0x0e54  [ A8D28D5B3E2A528D1EF0E338E44F2820, 40D1EFDD253BC0A0D984A5AD8A2721C3E83B15F14D538204714E6D5B00D92CEB ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
06:28:31.0684 0x0e54  MBAMProtector - ok
06:28:31.0794 0x0e54  [ 301E3FDFCF33640BB8763BA444BC5093, 362B069BB9A313A06B376CE27E6F7F8D569F6CA39A8ABC96D9DF231EE462C604 ] MBAMScheduler   C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
06:28:31.0825 0x0e54  MBAMScheduler - ok
06:28:31.0872 0x0e54  [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F606A16768A11DB0C ] MBAMService     C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
06:28:31.0903 0x0e54  MBAMService - ok
06:28:31.0950 0x0e54  [ 8F22037D3F5A6BB676525D825A1388B9, 2AAC748D46136DFA1BE45150BF0AB7707D45391CAC1F63B964D341D11B135C91 ] MBAMSwissArmy   C:\Windows\system32\drivers\MBAMSwissArmy.sys
06:28:31.0965 0x0e54  MBAMSwissArmy - ok
06:28:31.0996 0x0e54  [ AE757332EA130E94E646621CC695B52A, E688CF34A4206F32B5C7301119D8459C3456FC178FA1DAA6215CE15F2C824C43 ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
06:28:31.0996 0x0e54  MBAMWebAccessControl - ok
06:28:32.0012 0x0e54  [ 5858C4ABE87D0A842A941D6BD08038F1, FA082135752ECE107AC5E94066541F07FC1D56CE070CE8476A30375308F290A9 ] mcaudrv_simple  C:\Windows\system32\drivers\mcaudrv_x64.sys
06:28:32.0012 0x0e54  mcaudrv_simple - ok
06:28:32.0043 0x0e54  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
06:28:32.0043 0x0e54  Mcx2Svc - ok
06:28:32.0074 0x0e54  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
06:28:32.0090 0x0e54  megasas - ok
06:28:32.0106 0x0e54  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
06:28:32.0106 0x0e54  MegaSR - ok
06:28:32.0137 0x0e54  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS           C:\Windows\system32\mmcss.dll
06:28:32.0137 0x0e54  MMCSS - ok
06:28:32.0152 0x0e54  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem           C:\Windows\system32\drivers\modem.sys
06:28:32.0152 0x0e54  Modem - ok
06:28:32.0199 0x0e54  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
06:28:32.0199 0x0e54  monitor - ok
06:28:32.0246 0x0e54  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
06:28:32.0246 0x0e54  mouclass - ok
06:28:32.0324 0x0e54  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
06:28:32.0324 0x0e54  mouhid - ok
06:28:32.0355 0x0e54  [ 67050452C0118BAF2883928E6FCCFE47, 335FC0AEB7B47DCC7CE0CF3F424EB60ACB1327D2FF6515F04D9AC03A10FF1E31 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
06:28:32.0355 0x0e54  mountmgr - ok
06:28:32.0418 0x0e54  [ CC11EEB7AF4617D65DF0E9A21FC1ABD0, A683A5FB26E1B9FB4EEB40A9C7186F8433E3FB0A45848DF6102EF07B4DC75AC8 ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
06:28:32.0418 0x0e54  MozillaMaintenance - ok
06:28:32.0464 0x0e54  [ 73150F67D20270FF95A021A22E64F28A, A8878DEFBE437FB453F8E9243FB5C787D07AC7415A4475388D479C10417C524F ] MpFilter        C:\Windows\system32\DRIVERS\MpFilter.sys
06:28:32.0480 0x0e54  MpFilter - ok
06:28:32.0511 0x0e54  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
06:28:32.0511 0x0e54  mpio - ok
06:28:32.0542 0x0e54  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
06:28:32.0542 0x0e54  mpsdrv - ok
06:28:32.0605 0x0e54  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
06:28:32.0605 0x0e54  MpsSvc - ok
06:28:32.0652 0x0e54  [ AE3334958D8F631FF14A0AEB3D7EFB3A, F5FD6B61F896104C20DFC43FEE2FCE6930B73F78DF876BD19A333EABB9139C6D ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
06:28:32.0652 0x0e54  MRxDAV - ok
06:28:32.0667 0x0e54  [ DB8E6BA1D110A4E40D48612E9009E366, 678728CC8BBCD0D99E67DA63F53A99AC6D6D12EAE3E26655D372940BE7411098 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
06:28:32.0683 0x0e54  mrxsmb - ok
06:28:32.0714 0x0e54  [ 24432705B02BC1EFC42A83F93BA202A3, 13F2CA069FAEDA9CEAC6E09D10807DBFF729EAF6133DC46DE5A14C5694E9510B ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
06:28:32.0730 0x0e54  mrxsmb10 - ok
06:28:32.0761 0x0e54  [ 5E7E31C6426F000AF29E7C452826AF5E, F66102138458BDBD2CE586C95FF90F9B90F5DC8832EA1ACFAD694F1D0B949B21 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
06:28:32.0776 0x0e54  mrxsmb20 - ok
06:28:32.0823 0x0e54  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
06:28:32.0823 0x0e54  msahci - ok
06:28:32.0917 0x0e54  [ A592A054D78750B4D73ABAA4C94DECDF, 40B135C9F9EE698EC78BD19BD18353AE2CF4D020DDB9CFC37CD2FDBF7602614A ] MSCamSvc        C:\Program Files\Microsoft LifeCam\MSCamS64.exe
06:28:32.0917 0x0e54  MSCamSvc - ok
06:28:32.0932 0x0e54  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
06:28:32.0948 0x0e54  msdsm - ok
06:28:32.0964 0x0e54  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC           C:\Windows\System32\msdtc.exe
06:28:32.0964 0x0e54  MSDTC - ok
06:28:33.0010 0x0e54  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
06:28:33.0010 0x0e54  Msfs - ok
06:28:33.0010 0x0e54  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
06:28:33.0010 0x0e54  mshidkmdf - ok
06:28:33.0010 0x0e54  [ 55218F924E55FD2786ED40EDF4ED79C3, C6000DE3A1FB526ECB77438A03F7212517CCD5E0CC9DDA07826865F8B980BEA0 ] MSHUSBVideo     C:\Windows\system32\Drivers\nx6000.sys
06:28:33.0010 0x0e54  MSHUSBVideo - ok
06:28:33.0042 0x0e54  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
06:28:33.0042 0x0e54  msisadrv - ok
06:28:33.0088 0x0e54  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
06:28:33.0088 0x0e54  MSiSCSI - ok
06:28:33.0104 0x0e54  msiserver - ok
06:28:33.0120 0x0e54  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
06:28:33.0120 0x0e54  MSKSSRV - ok
06:28:33.0198 0x0e54  [ CE996C1821021ADF8E28E80A54E846A8, 99042E895B6C2EA80F3BA65563A12C8EBA882E3AD6A21DD8E799B0112C75DDD2 ] MsMpSvc         c:\Program Files\Microsoft Security Client\MsMpEng.exe
06:28:33.0198 0x0e54  MsMpSvc - ok
06:28:33.0213 0x0e54  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
06:28:33.0213 0x0e54  MSPCLOCK - ok
06:28:33.0229 0x0e54  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
06:28:33.0229 0x0e54  MSPQM - ok
06:28:33.0260 0x0e54  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
06:28:33.0260 0x0e54  MsRPC - ok
06:28:33.0307 0x0e54  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
06:28:33.0307 0x0e54  mssmbios - ok
06:28:33.0307 0x0e54  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
06:28:33.0322 0x0e54  MSTEE - ok
06:28:33.0322 0x0e54  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
06:28:33.0322 0x0e54  MTConfig - ok
06:28:33.0369 0x0e54  [ 2219A3D695405E7BA2186BA6B9EDE14A, 8B99BD22DACB56FF544ED922962FE4EC1172BF90987A46E3A5F62A3B4E720B0C ] MTsensor        C:\Windows\system32\DRIVERS\ASACPI.sys
06:28:33.0369 0x0e54  MTsensor - ok
06:28:33.0385 0x0e54  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup             C:\Windows\system32\Drivers\mup.sys
06:28:33.0385 0x0e54  Mup - ok
06:28:33.0432 0x0e54  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
06:28:33.0432 0x0e54  napagent - ok
06:28:33.0463 0x0e54  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
06:28:33.0463 0x0e54  NativeWifiP - ok
06:28:33.0525 0x0e54  [ 760E38053BF56E501D562B70AD796B88, F856E81A975D44F8684A6F2466549CEEDFAEB3950191698555A93A1206E0A42D ] NDIS            C:\Windows\system32\drivers\ndis.sys
06:28:33.0541 0x0e54  NDIS - ok
06:28:33.0572 0x0e54  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
06:28:33.0572 0x0e54  NdisCap - ok
06:28:33.0588 0x0e54  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
06:28:33.0588 0x0e54  NdisTapi - ok
06:28:33.0619 0x0e54  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
06:28:33.0634 0x0e54  Ndisuio - ok
06:28:33.0681 0x0e54  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
06:28:33.0759 0x0e54  NdisWan - ok
06:28:33.0884 0x0e54  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
06:28:33.0931 0x0e54  NDProxy - ok
06:28:33.0978 0x0e54  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
06:28:33.0993 0x0e54  NetBIOS - ok
06:28:34.0024 0x0e54  [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D12158AC22CCCE37 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
06:28:34.0024 0x0e54  NetBT - ok
06:28:34.0040 0x0e54  [ 3E9BDCA3994E2B6B6AC16BAA76722934, A77FEE9D78C1151B13C9509FA89B64024442D00C3C9EA19954045413D8A69D73 ] Netlogon        C:\Windows\system32\lsass.exe
06:28:34.0040 0x0e54  Netlogon - ok
06:28:34.0102 0x0e54  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
06:28:34.0102 0x0e54  Netman - ok
06:28:34.0149 0x0e54  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
06:28:34.0149 0x0e54  NetMsmqActivator - ok
06:28:34.0149 0x0e54  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
06:28:34.0149 0x0e54  NetPipeActivator - ok
06:28:34.0165 0x0e54  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
06:28:34.0165 0x0e54  netprofm - ok
06:28:34.0180 0x0e54  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
06:28:34.0180 0x0e54  NetTcpActivator - ok
06:28:34.0196 0x0e54  [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
06:28:34.0196 0x0e54  NetTcpPortSharing - ok
06:28:34.0212 0x0e54  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
06:28:34.0212 0x0e54  nfrd960 - ok
06:28:34.0258 0x0e54  [ 4774AD83C650001B337B92E5E5DA337B, 138ECC7F556D8A12AE58B78B68F6515BE4C00F9F062596B48B6CA6C010F13035 ] NisDrv          C:\Windows\system32\DRIVERS\NisDrvWFP.sys
06:28:34.0258 0x0e54  NisDrv - ok
06:28:34.0321 0x0e54  [ 96B7D15161A778B359E707796CCEA646, 9E4A25D9848FAECC517474EAD548E7975CBE3F41AAA964E5245E78F2A723925E ] NisSrv          c:\Program Files\Microsoft Security Client\NisSrv.exe
06:28:34.0321 0x0e54  NisSrv - ok
06:28:34.0368 0x0e54  [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc          C:\Windows\System32\nlasvc.dll
06:28:34.0368 0x0e54  NlaSvc - ok
06:28:34.0383 0x0e54  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
06:28:34.0383 0x0e54  Npfs - ok
06:28:34.0414 0x0e54  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi             C:\Windows\system32\nsisvc.dll
06:28:34.0414 0x0e54  nsi - ok
06:28:34.0430 0x0e54  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
06:28:34.0430 0x0e54  nsiproxy - ok
06:28:34.0508 0x0e54  [ 1A29A59A4C5BA6F8C85062A613B7E2B2, CC137F499A12C724D4166C2D85E9F447413419A0683DAC6F1A802B7F210C77F1 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
06:28:34.0555 0x0e54  Ntfs - ok
06:28:34.0586 0x0e54  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
06:28:34.0586 0x0e54  Null - ok
06:28:34.0633 0x0e54  [ 8EBCB9165EE7F1571842F4D9D624A74C, 115F46B8391866762AD41B299F0670D8735D124BD518A53EC73DCDBFCA9C28F9 ] nusb3hub        C:\Windows\system32\DRIVERS\nusb3hub.sys
06:28:34.0633 0x0e54  nusb3hub - ok
06:28:34.0680 0x0e54  [ 5D54DBB12BBFE07CC283FD39F2CD6D63, 3DC3F9121F8892EDABD07ACDE45DB025BA2FC4245A8D3EE343F1FDF7189B391F ] nusb3xhc        C:\Windows\system32\DRIVERS\nusb3xhc.sys
06:28:34.0680 0x0e54  nusb3xhc - ok
06:28:34.0726 0x0e54  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
06:28:34.0726 0x0e54  nvraid - ok
06:28:34.0742 0x0e54  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
06:28:34.0742 0x0e54  nvstor - ok
06:28:34.0758 0x0e54  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
06:28:34.0758 0x0e54  nv_agp - ok
06:28:34.0789 0x0e54  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
06:28:34.0804 0x0e54  ohci1394 - ok
06:28:34.0882 0x0e54  OracleJobSchedulerXE - ok
06:28:34.0898 0x0e54  OracleMTSRecoveryService - ok
06:28:34.0898 0x0e54  OracleServiceXE - ok
06:28:34.0898 0x0e54  OracleXEClrAgent - ok
06:28:34.0945 0x0e54  [ 788D4CD078E3D55D92C4B986C739DA43, 54531617299D9077BF09A9717F3F1D23D7E8CE2B3A6D189278D7CC103F4ADC3F ] OracleXETNSListener C:\oraclexe\app\oracle\product\11.2.0\server\BIN\tnslsnr.exe
06:28:34.0976 0x0e54  OracleXETNSListener - ok
06:28:35.0023 0x0e54  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
06:28:35.0023 0x0e54  p2pimsvc - ok
06:28:35.0054 0x0e54  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
06:28:35.0070 0x0e54  p2psvc - ok
06:28:35.0101 0x0e54  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport         C:\Windows\system32\DRIVERS\parport.sys
06:28:35.0101 0x0e54  Parport - ok
06:28:35.0148 0x0e54  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
06:28:35.0148 0x0e54  partmgr - ok
06:28:35.0179 0x0e54  [ DB2D62AA2DF6B1F3D690A9EC9701AA2C, BEAC55E1AA0494565F1547DF5E6FE20FCEA66461764C016FCB68D8BFF0F0C375 ] PcaSvc          C:\Windows\System32\pcasvc.dll
06:28:35.0179 0x0e54  PcaSvc - ok
06:28:35.0194 0x0e54  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci             C:\Windows\system32\drivers\pci.sys
06:28:35.0194 0x0e54  pci - ok
06:28:35.0226 0x0e54  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
06:28:35.0226 0x0e54  pciide - ok
06:28:35.0241 0x0e54  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
06:28:35.0241 0x0e54  pcmcia - ok
06:28:35.0257 0x0e54  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw             C:\Windows\system32\drivers\pcw.sys
06:28:35.0257 0x0e54  pcw - ok
06:28:35.0304 0x0e54  [ ED6E75158D28D33A2E2A020AC5B2B59D, 0F364D9A88304C45F31318605C417A70A9D0E4CF087D73E949B42C12CC76CD6C ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
06:28:35.0319 0x0e54  PEAUTH - ok
06:28:35.0382 0x0e54  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
06:28:35.0397 0x0e54  PeerDistSvc - ok
06:28:35.0491 0x0e54  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
06:28:35.0491 0x0e54  PerfHost - ok
06:28:35.0553 0x0e54  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla             C:\Windows\system32\pla.dll
06:28:35.0584 0x0e54  pla - ok
06:28:35.0631 0x0e54  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
06:28:35.0631 0x0e54  PlugPlay - ok
06:28:35.0694 0x0e54  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
06:28:35.0694 0x0e54  PNRPAutoReg - ok
06:28:35.0709 0x0e54  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
06:28:35.0725 0x0e54  PNRPsvc - ok
06:28:35.0740 0x0e54  [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D654D9F7A5C12A044 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
06:28:35.0756 0x0e54  PolicyAgent - ok
06:28:35.0787 0x0e54  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power           C:\Windows\system32\umpo.dll
06:28:35.0787 0x0e54  Power - ok
06:28:35.0834 0x0e54  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
06:28:35.0834 0x0e54  PptpMiniport - ok
06:28:35.0850 0x0e54  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
06:28:35.0850 0x0e54  Processor - ok
06:28:35.0896 0x0e54  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc         C:\Windows\system32\profsvc.dll
06:28:35.0912 0x0e54  ProfSvc - ok
06:28:35.0928 0x0e54  [ 3E9BDCA3994E2B6B6AC16BAA76722934, A77FEE9D78C1151B13C9509FA89B64024442D00C3C9EA19954045413D8A69D73 ] ProtectedStorage C:\Windows\system32\lsass.exe
06:28:35.0928 0x0e54  ProtectedStorage - ok
06:28:36.0006 0x0e54  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
06:28:36.0006 0x0e54  Psched - ok
06:28:36.0068 0x0e54  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
06:28:36.0115 0x0e54  ql2300 - ok
06:28:36.0130 0x0e54  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
06:28:36.0130 0x0e54  ql40xx - ok
06:28:36.0177 0x0e54  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE           C:\Windows\system32\qwave.dll
06:28:36.0177 0x0e54  QWAVE - ok
06:28:36.0193 0x0e54  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
06:28:36.0193 0x0e54  QWAVEdrv - ok
06:28:36.0193 0x0e54  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
06:28:36.0193 0x0e54  RasAcd - ok
06:28:36.0240 0x0e54  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
06:28:36.0240 0x0e54  RasAgileVpn - ok
06:28:36.0255 0x0e54  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto         C:\Windows\System32\rasauto.dll
06:28:36.0255 0x0e54  RasAuto - ok
06:28:36.0286 0x0e54  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
06:28:36.0286 0x0e54  Rasl2tp - ok
06:28:36.0333 0x0e54  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
06:28:36.0333 0x0e54  RasMan - ok
06:28:36.0349 0x0e54  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
06:28:36.0364 0x0e54  RasPppoe - ok
06:28:36.0364 0x0e54  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
06:28:36.0364 0x0e54  RasSstp - ok
06:28:36.0396 0x0e54  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
06:28:36.0411 0x0e54  rdbss - ok
06:28:36.0411 0x0e54  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
06:28:36.0411 0x0e54  rdpbus - ok
06:28:36.0427 0x0e54  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
06:28:36.0427 0x0e54  RDPCDD - ok
06:28:36.0458 0x0e54  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
06:28:36.0458 0x0e54  RDPDR - ok
06:28:36.0489 0x0e54  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
06:28:36.0489 0x0e54  RDPENCDD - ok
06:28:36.0489 0x0e54  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
06:28:36.0489 0x0e54  RDPREFMP - ok
06:28:36.0567 0x0e54  [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
06:28:36.0583 0x0e54  RdpVideoMiniport - ok
06:28:36.0630 0x0e54  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
06:28:36.0645 0x0e54  RDPWD - ok
06:28:36.0692 0x0e54  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
06:28:36.0692 0x0e54  rdyboost - ok
06:28:36.0723 0x0e54  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
06:28:36.0739 0x0e54  RemoteAccess - ok
06:28:36.0770 0x0e54  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
06:28:36.0770 0x0e54  RemoteRegistry - ok
06:28:36.0786 0x0e54  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
06:28:36.0786 0x0e54  RpcEptMapper - ok
06:28:36.0817 0x0e54  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
06:28:36.0817 0x0e54  RpcLocator - ok
06:28:36.0864 0x0e54  [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C4D6400B354B401 ] RpcSs           C:\Windows\system32\rpcss.dll
06:28:36.0879 0x0e54  RpcSs - ok
06:28:36.0926 0x0e54  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
06:28:36.0942 0x0e54  rspndr - ok
06:28:36.0973 0x0e54  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
06:28:36.0973 0x0e54  s3cap - ok
06:28:36.0988 0x0e54  [ 3E9BDCA3994E2B6B6AC16BAA76722934, A77FEE9D78C1151B13C9509FA89B64024442D00C3C9EA19954045413D8A69D73 ] SamSs           C:\Windows\system32\lsass.exe
06:28:36.0988 0x0e54  SamSs - ok
06:28:37.0020 0x0e54  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
06:28:37.0020 0x0e54  sbp2port - ok
06:28:37.0051 0x0e54  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
06:28:37.0051 0x0e54  SCardSvr - ok
06:28:37.0098 0x0e54  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
06:28:37.0098 0x0e54  scfilter - ok
06:28:37.0144 0x0e54  [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule        C:\Windows\system32\schedsvc.dll
06:28:37.0160 0x0e54  Schedule - ok
06:28:37.0191 0x0e54  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc     C:\Windows\System32\certprop.dll
06:28:37.0191 0x0e54  SCPolicySvc - ok
06:28:37.0222 0x0e54  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
06:28:37.0238 0x0e54  SDRSVC - ok
06:28:37.0254 0x0e54  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
06:28:37.0254 0x0e54  secdrv - ok
06:28:37.0285 0x0e54  [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C7060829E8204A2297F9 ] seclogon        C:\Windows\system32\seclogon.dll
06:28:37.0285 0x0e54  seclogon - ok
06:28:37.0300 0x0e54  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\System32\sens.dll
06:28:37.0300 0x0e54  SENS - ok
06:28:37.0300 0x0e54  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
06:28:37.0300 0x0e54  SensrSvc - ok
06:28:37.0316 0x0e54  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
06:28:37.0316 0x0e54  Serenum - ok
06:28:37.0332 0x0e54  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\DRIVERS\serial.sys
06:28:37.0332 0x0e54  Serial - ok
06:28:37.0378 0x0e54  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
06:28:37.0378 0x0e54  sermouse - ok
06:28:37.0410 0x0e54  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
06:28:37.0410 0x0e54  SessionEnv - ok
06:28:37.0456 0x0e54  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
06:28:37.0456 0x0e54  sffdisk - ok
06:28:37.0456 0x0e54  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
06:28:37.0456 0x0e54  sffp_mmc - ok
06:28:37.0456 0x0e54  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
06:28:37.0472 0x0e54  sffp_sd - ok
06:28:37.0472 0x0e54  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
06:28:37.0472 0x0e54  sfloppy - ok
06:28:37.0519 0x0e54  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
06:28:37.0519 0x0e54  SharedAccess - ok
06:28:37.0566 0x0e54  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
06:28:37.0581 0x0e54  ShellHWDetection - ok
06:28:37.0597 0x0e54  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
06:28:37.0597 0x0e54  SiSRaid2 - ok
06:28:37.0612 0x0e54  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
06:28:37.0612 0x0e54  SiSRaid4 - ok
06:28:37.0737 0x0e54  [ 52F7E8603E888E3DB0A8B3D1804098E9, 4E23DC9442C0C14AAE7146DACBB0B39743F1FFAA463EE7069CCDF866AD27BD77 ] SkypeUpdate     C:\Program Files (x86)\Skype\Updater\Updater.exe
06:28:37.0737 0x0e54  SkypeUpdate - ok
06:28:37.0768 0x0e54  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
06:28:37.0768 0x0e54  Smb - ok
06:28:37.0815 0x0e54  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
06:28:37.0815 0x0e54  SNMPTRAP - ok
06:28:37.0831 0x0e54  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr           C:\Windows\system32\drivers\spldr.sys
06:28:37.0831 0x0e54  spldr - ok
06:28:37.0878 0x0e54  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler         C:\Windows\System32\spoolsv.exe
06:28:37.0878 0x0e54  Spooler - ok
06:28:38.0002 0x0e54  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
06:28:38.0049 0x0e54  sppsvc - ok
06:28:38.0065 0x0e54  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
06:28:38.0065 0x0e54  sppuinotify - ok
06:28:38.0112 0x0e54  [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7CD1863FDB8932C0 ] srv             C:\Windows\system32\DRIVERS\srv.sys
06:28:38.0112 0x0e54  srv - ok
06:28:38.0158 0x0e54  [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE4A8C9DB29E87F7 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
06:28:38.0174 0x0e54  srv2 - ok
06:28:38.0205 0x0e54  [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF39FF9AF3646D9E6 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
06:28:38.0205 0x0e54  srvnet - ok
06:28:38.0236 0x0e54  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
06:28:38.0236 0x0e54  SSDPSRV - ok
06:28:38.0268 0x0e54  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc         C:\Windows\system32\sstpsvc.dll
06:28:38.0268 0x0e54  SstpSvc - ok
06:28:38.0299 0x0e54  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
06:28:38.0299 0x0e54  stexstor - ok
06:28:38.0361 0x0e54  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
06:28:38.0377 0x0e54  stisvc - ok
06:28:38.0408 0x0e54  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
06:28:38.0424 0x0e54  storflt - ok
06:28:38.0424 0x0e54  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc         C:\Windows\system32\drivers\storvsc.sys
06:28:38.0424 0x0e54  storvsc - ok
06:28:38.0455 0x0e54  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\drivers\swenum.sys
06:28:38.0455 0x0e54  swenum - ok
06:28:38.0486 0x0e54  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv           C:\Windows\System32\swprv.dll
06:28:38.0502 0x0e54  swprv - ok
06:28:38.0517 0x0e54  Synth3dVsc - ok
06:28:38.0595 0x0e54  [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain         C:\Windows\system32\sysmain.dll
06:28:38.0626 0x0e54  SysMain - ok
06:28:38.0673 0x0e54  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
06:28:38.0673 0x0e54  TabletInputService - ok
06:28:38.0720 0x0e54  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv         C:\Windows\System32\tapisrv.dll
06:28:38.0736 0x0e54  TapiSrv - ok
06:28:38.0767 0x0e54  [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5A92E5E78A952E4 ] TBS             C:\Windows\System32\tbssvc.dll
06:28:38.0767 0x0e54  TBS - ok
06:28:38.0829 0x0e54  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
06:28:38.0892 0x0e54  Tcpip - ok
06:28:38.0938 0x0e54  [ 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E, F05C0C4CA3DD234AD5D60CF1EF763C9A1D9EC3C157E180C2D75CC07E6B02A611 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
06:28:38.0970 0x0e54  TCPIP6 - ok
06:28:39.0016 0x0e54  [ 1B16D0BD9841794A6E0CDE0CEF744ABC, 7EB8BA97339199EEE7F2B09DA2DA6279DA64A510D4598D42CF86415D67CD674C ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
06:28:39.0032 0x0e54  tcpipreg - ok
06:28:39.0063 0x0e54  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
06:28:39.0079 0x0e54  TDPIPE - ok
06:28:39.0126 0x0e54  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
06:28:39.0157 0x0e54  TDTCP - ok
06:28:39.0204 0x0e54  [ 70988118145F5F10EF24720B97F35F65, F80C806417A68047FFB3D63214BC4AE5445315219AC594E043293006B704A63D ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
06:28:39.0204 0x0e54  tdx - ok
06:28:39.0391 0x0e54  [ CFC9B7B465283378D374D5E380D5D244, 5E66A62C6A6272B65181F116031AA80E8DCEDA3B7E2C1130DD631347DF644D79 ] TeamViewer      C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
06:28:39.0484 0x0e54  TeamViewer - ok
06:28:39.0516 0x0e54  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\drivers\termdd.sys
06:28:39.0516 0x0e54  TermDD - ok
06:28:39.0562 0x0e54  [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService     C:\Windows\System32\termsrv.dll
06:28:39.0578 0x0e54  TermService - ok
06:28:39.0609 0x0e54  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
06:28:39.0625 0x0e54  Themes - ok
06:28:39.0640 0x0e54  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER     C:\Windows\system32\mmcss.dll
06:28:39.0640 0x0e54  THREADORDER - ok
06:28:39.0672 0x0e54  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
06:28:39.0672 0x0e54  TrkWks - ok
06:28:39.0734 0x0e54  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
06:28:39.0734 0x0e54  TrustedInstaller - ok
06:28:39.0750 0x0e54  [ 19BEDA57F3E0A06B8D5EB6D619BD5624, 952D5FAFD662C93628C12A6F7EB8E240A44216C0A15CBD2F5016BC357CBFE821 ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
06:28:39.0765 0x0e54  tssecsrv - ok
06:28:39.0796 0x0e54  [ E9981ECE8D894CEF7038FD1D040EB426, DCDDCE933CAECE8180A3447199B07F2F0413704EEC1A09606EE357901A84A7CF ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
06:28:39.0796 0x0e54  TsUsbFlt - ok
06:28:39.0796 0x0e54  tsusbhub - ok
06:28:39.0843 0x0e54  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
06:28:39.0843 0x0e54  tunnel - ok
06:28:39.0874 0x0e54  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
06:28:39.0874 0x0e54  uagp35 - ok
06:28:39.0906 0x0e54  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
06:28:39.0921 0x0e54  udfs - ok
06:28:39.0952 0x0e54  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect       C:\Windows\system32\UI0Detect.exe
06:28:39.0952 0x0e54  UI0Detect - ok
06:28:39.0952 0x0e54  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
06:28:39.0952 0x0e54  uliagpkx - ok
06:28:39.0999 0x0e54  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
06:28:39.0999 0x0e54  umbus - ok
06:28:40.0015 0x0e54  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
06:28:40.0015 0x0e54  UmPass - ok
06:28:40.0046 0x0e54  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
06:28:40.0046 0x0e54  UmRdpService - ok
06:28:40.0077 0x0e54  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
06:28:40.0077 0x0e54  upnphost - ok
06:28:40.0108 0x0e54  [ B0435098C81D04CAFFF80DDB746CD3A2, A17B207740382E38729571F0B0BC98FF874E856A7C7CE9EB930328A2AD88F52A ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
06:28:40.0108 0x0e54  usbaudio - ok
06:28:40.0140 0x0e54  [ DCA68B0943D6FA415F0C56C92158A83A, BEE5A5B33B22D1DF50B884D46D89FC3B8286EB16E38AD5A20F0A49E5C6766C57 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
06:28:40.0140 0x0e54  usbccgp - ok
06:28:40.0171 0x0e54  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\Windows\system32\drivers\usbcir.sys
06:28:40.0171 0x0e54  usbcir - ok
06:28:40.0202 0x0e54  [ 18A85013A3E0F7E1755365D287443965, 811C5EDF38C765BCF71BCE25CB6626FF6988C3699F5EF1846240EA0052F34C33 ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
06:28:40.0202 0x0e54  usbehci - ok
06:28:40.0249 0x0e54  [ 8D1196CFBB223621F2C67D45710F25BA, B5D7AFE51833B24FC9576F3AED3D8A2B290E5846060E73F9FFFAC1890A8B6003 ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
06:28:40.0249 0x0e54  usbhub - ok
06:28:40.0264 0x0e54  [ 765A92D428A8DB88B960DA5A8D6089DC, 56DE8A2ED58E53B202C399CA7BACB1551136303C2EE0AB426BDBBF880E3C542C ] usbohci         C:\Windows\system32\DRIVERS\usbohci.sys
06:28:40.0264 0x0e54  usbohci - ok
06:28:40.0296 0x0e54  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
06:28:40.0296 0x0e54  usbprint - ok
06:28:40.0327 0x0e54  [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D5711D9C19DEB96 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
06:28:40.0342 0x0e54  USBSTOR - ok
06:28:40.0374 0x0e54  [ DD253AFC3BC6CBA412342DE60C3647F3, 146F8613F1057AC054DC3593E84BC52899DA27EA33B0E72ACFB78C3699ADCDE7 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
06:28:40.0374 0x0e54  usbuhci - ok
06:28:40.0405 0x0e54  [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
06:28:40.0405 0x0e54  usbvideo - ok
06:28:40.0436 0x0e54  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms           C:\Windows\System32\uxsms.dll
06:28:40.0436 0x0e54  UxSms - ok
06:28:40.0452 0x0e54  [ 3E9BDCA3994E2B6B6AC16BAA76722934, A77FEE9D78C1151B13C9509FA89B64024442D00C3C9EA19954045413D8A69D73 ] VaultSvc        C:\Windows\system32\lsass.exe
06:28:40.0452 0x0e54  VaultSvc - ok
06:28:40.0467 0x0e54  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
06:28:40.0467 0x0e54  vdrvroot - ok
06:28:40.0514 0x0e54  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds             C:\Windows\System32\vds.exe
06:28:40.0530 0x0e54  vds - ok
06:28:40.0561 0x0e54  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
06:28:40.0561 0x0e54  vga - ok
06:28:40.0576 0x0e54  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave         C:\Windows\System32\drivers\vga.sys
06:28:40.0576 0x0e54  VgaSave - ok
06:28:40.0592 0x0e54  VGPU - ok
06:28:40.0670 0x0e54  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
06:28:40.0670 0x0e54  vhdmp - ok
06:28:40.0686 0x0e54  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
06:28:40.0686 0x0e54  viaide - ok
06:28:40.0701 0x0e54  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
06:28:40.0701 0x0e54  vmbus - ok
06:28:40.0717 0x0e54  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
06:28:40.0717 0x0e54  VMBusHID - ok
06:28:40.0732 0x0e54  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
06:28:40.0732 0x0e54  volmgr - ok
06:28:40.0764 0x0e54  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
06:28:40.0779 0x0e54  volmgrx - ok
06:28:40.0795 0x0e54  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap         C:\Windows\system32\drivers\volsnap.sys
06:28:40.0795 0x0e54  volsnap - ok
06:28:40.0826 0x0e54  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
06:28:40.0826 0x0e54  vsmraid - ok
06:28:40.0888 0x0e54  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS             C:\Windows\system32\vssvc.exe
06:28:40.0951 0x0e54  VSS - ok
06:28:40.0982 0x0e54  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
06:28:40.0982 0x0e54  vwifibus - ok
06:28:41.0029 0x0e54  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time         C:\Windows\system32\w32time.dll
06:28:41.0029 0x0e54  W32Time - ok
06:28:41.0044 0x0e54  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
06:28:41.0044 0x0e54  WacomPen - ok
06:28:41.0091 0x0e54  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
06:28:41.0091 0x0e54  WANARP - ok
06:28:41.0091 0x0e54  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
06:28:41.0091 0x0e54  Wanarpv6 - ok
06:28:41.0169 0x0e54  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
06:28:41.0200 0x0e54  WatAdminSvc - ok
06:28:41.0263 0x0e54  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
06:28:41.0310 0x0e54  wbengine - ok
06:28:41.0325 0x0e54  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
06:28:41.0325 0x0e54  WbioSrvc - ok
06:28:41.0356 0x0e54  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
06:28:41.0372 0x0e54  wcncsvc - ok
06:28:41.0388 0x0e54  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
06:28:41.0388 0x0e54  WcsPlugInService - ok
06:28:41.0419 0x0e54  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
06:28:41.0419 0x0e54  Wd - ok
06:28:41.0450 0x0e54  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
06:28:41.0481 0x0e54  Wdf01000 - ok
06:28:41.0512 0x0e54  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost  C:\Windows\system32\wdi.dll
06:28:41.0528 0x0e54  WdiServiceHost - ok
06:28:41.0528 0x0e54  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost   C:\Windows\system32\wdi.dll
06:28:41.0528 0x0e54  WdiSystemHost - ok
06:28:41.0559 0x0e54  [ 4E89FC53493704BF835F0300DC201C34, FB3080725E144D93512DED81047D21C0582BC3412250EFF37E039108D7351F53 ] WebClient       C:\Windows\System32\webclnt.dll
06:28:41.0575 0x0e54  WebClient - ok
06:28:41.0622 0x0e54  [ D5BA7D43FA2EF656BF7E98A188391E40, 56CF132B7C43A0F9C7C4D070730315FE7AFD2E87E94014DFC3D7107BB52B9C64 ] Wecsvc          C:\Windows\system32\wecsvc.dll
06:28:41.0622 0x0e54  Wecsvc - ok
06:28:41.0637 0x0e54  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
06:28:41.0637 0x0e54  wercplsupport - ok
06:28:41.0653 0x0e54  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
06:28:41.0653 0x0e54  WerSvc - ok
06:28:41.0684 0x0e54  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
06:28:41.0684 0x0e54  WfpLwf - ok
06:28:41.0684 0x0e54  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
06:28:41.0684 0x0e54  WIMMount - ok
06:28:41.0715 0x0e54  WinDefend - ok
06:28:41.0731 0x0e54  WinHttpAutoProxySvc - ok
06:28:41.0793 0x0e54  [ 136760C1E9697BAF4ECDEAE5590A0806, 12E80D0923D794F4C520FEA7CB98EF581231B996FB1876EB20995E6E457EFF56 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
06:28:41.0809 0x0e54  Winmgmt - ok
06:28:41.0887 0x0e54  [ 3BB6B401A780BF434C8F58137DE10BF7, 1A377C39B78B92A1A1FED699EE5E5ED0271A6FFAC143F1D29FC1FDF4D726A522 ] WinRM           C:\Windows\system32\WsmSvc.dll
06:28:41.0980 0x0e54  WinRM - ok
06:28:42.0027 0x0e54  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] winusb          C:\Windows\system32\DRIVERS\WinUsb.sys
06:28:42.0027 0x0e54  winusb - ok
06:28:42.0105 0x0e54  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc         C:\Windows\System32\wlansvc.dll
06:28:42.0121 0x0e54  Wlansvc - ok
06:28:42.0308 0x0e54  [ 357CABBF155AFD1D3926E62539D2A3A7, C43CFF84E7D930B4999DC061AB0766B57AAD7540B3E6EE54605B10ECE90825F5 ] wlidsvc         C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
06:28:42.0339 0x0e54  wlidsvc - ok
06:28:42.0386 0x0e54  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
06:28:42.0386 0x0e54  WmiAcpi - ok
06:28:42.0433 0x0e54  [ 4DF841632B62A7CF19A79A05046A8AB1, D80F28FD7FEB95DB83976EAFECB2E9AE1423DA4D34EC5D820FC39A33444B82DA ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
06:28:42.0433 0x0e54  wmiApSrv - ok
06:28:42.0464 0x0e54  WMPNetworkSvc - ok
06:28:42.0480 0x0e54  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
06:28:42.0480 0x0e54  WPCSvc - ok
06:28:42.0511 0x0e54  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
06:28:42.0511 0x0e54  WPDBusEnum - ok
06:28:42.0542 0x0e54  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
06:28:42.0542 0x0e54  ws2ifsl - ok
06:28:42.0589 0x0e54  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\System32\wscsvc.dll
06:28:42.0589 0x0e54  wscsvc - ok
06:28:42.0589 0x0e54  WSearch - ok
06:28:42.0682 0x0e54  [ 39D604E190DFE2E483B637D6796ABAFF, 52DCCEA0DB59F00C615D94CC2B70FC1C335E553E8FC79AAC8C8C7D9EE1F6111D ] wuauserv        C:\Windows\system32\wuaueng.dll
06:28:42.0729 0x0e54  wuauserv - ok
06:28:42.0760 0x0e54  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
06:28:42.0760 0x0e54  WudfPf - ok
06:28:42.0792 0x0e54  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
06:28:42.0792 0x0e54  WUDFRd - ok
06:28:42.0823 0x0e54  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
06:28:42.0823 0x0e54  wudfsvc - ok
06:28:42.0854 0x0e54  [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc         C:\Windows\System32\wwansvc.dll
06:28:42.0870 0x0e54  WwanSvc - ok
06:28:42.0916 0x0e54  [ B2818BFAB7817F7E7EE886F58B15B35C, 7A82422F9343AF1F4318C6BD5DD63333DD0BF2DFF6778457CA04E1580B0DD7B4 ] yukonw7         C:\Windows\system32\DRIVERS\yk62x64.sys
06:28:42.0932 0x0e54  yukonw7 - ok
06:28:42.0932 0x0e54  ================ Scan global ===============================
06:28:42.0963 0x0e54  [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\Windows\system32\basesrv.dll
06:28:42.0994 0x0e54  [ 8927015C999D55D9B4AC66000EE5343D, 2AC4896880BAD44192822063A31785F4A716D992201B3E6A590A2D75D9729A4A ] C:\Windows\system32\winsrv.dll
06:28:43.0010 0x0e54  [ 8927015C999D55D9B4AC66000EE5343D, 2AC4896880BAD44192822063A31785F4A716D992201B3E6A590A2D75D9729A4A ] C:\Windows\system32\winsrv.dll
06:28:43.0041 0x0e54  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
06:28:43.0072 0x0e54  [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\Windows\system32\services.exe
06:28:43.0088 0x0e54  [ Global ] - ok
06:28:43.0088 0x0e54  ================ Scan MBR ==================================
06:28:43.0088 0x0e54  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
06:28:43.0260 0x0e54  \Device\Harddisk0\DR0 - ok
06:28:43.0275 0x0e54  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
06:28:43.0291 0x0e54  \Device\Harddisk1\DR1 - ok
06:28:43.0291 0x0e54  ================ Scan VBR ==================================
06:28:43.0291 0x0e54  [ 65A5550B86C578B7AF8C3A1D790ABF8C ] \Device\Harddisk0\DR0\Partition1
06:28:43.0338 0x0e54  \Device\Harddisk0\DR0\Partition1 - ok
06:28:43.0338 0x0e54  [ 7DFD00EA7F80EEDFE658BE33F076E762 ] \Device\Harddisk0\DR0\Partition2
06:28:43.0338 0x0e54  \Device\Harddisk0\DR0\Partition2 - ok
06:28:43.0338 0x0e54  [ 4D1DCFBA7E12774E0EEDA92E56F4422F ] \Device\Harddisk1\DR1\Partition1
06:28:43.0338 0x0e54  \Device\Harddisk1\DR1\Partition1 - ok
06:28:43.0338 0x0e54  ================ Scan generic autorun ======================
06:28:43.0416 0x0e54  [ 35BA4E6632BA690EA6421C1E03537D0E, 99D6B4DB12ABE3A7F44AB1B2D626978E85231185AE280D9516986027BC8385CB ] C:\Program Files\Microsoft Security Client\msseces.exe
06:28:43.0431 0x0e54  MSC - ok
06:28:43.0478 0x0e54  [ B01A82A16B0D205DEF42E113FE8B3C4E, E665069EE127D7BA5E9D2B269802DF1C1945FCC83BEADD0B1D2D2DCCE4193340 ] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
06:28:43.0494 0x0e54  DivXMediaServer - ok
06:28:43.0556 0x0e54  [ 4F9DD96AECDC12373D4203253D665C6D, 871FF2367ACD5F9A378FED53574BF28A8129224C4B7C4AF074809ED7CF870904 ] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
06:28:43.0556 0x0e54  SunJavaUpdateSched - ok
06:28:43.0634 0x0e54  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
06:28:43.0696 0x0e54  Sidebar - ok
06:28:43.0728 0x0e54  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
06:28:43.0728 0x0e54  mctadmin - ok
06:28:43.0743 0x0e54  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
06:28:43.0759 0x0e54  Sidebar - ok
06:28:43.0774 0x0e54  [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B725CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
06:28:43.0774 0x0e54  mctadmin - ok
06:28:43.0852 0x0e54  GoogleDriveSync - ok
06:28:43.0962 0x0e54  Viber - ok
06:28:43.0962 0x0e54  Waiting for KSN requests completion. In queue: 341
06:28:44.0976 0x0e54  Waiting for KSN requests completion. In queue: 341
06:28:45.0990 0x0e54  Waiting for KSN requests completion. In queue: 29
06:28:47.0004 0x0e54  Waiting for KSN requests completion. In queue: 29
06:28:48.0018 0x0e54  AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.8.204.0 ), 0x61000 ( enabled : updated )
06:28:48.0033 0x0e54  Win FW state via NFP2: enabled ( trusted )
06:28:50.0919 0x0e54  ============================================================
06:28:50.0919 0x0e54  Scan finished
06:28:50.0919 0x0e54  ============================================================
06:28:50.0919 0x110c  Detected object count: 0
06:28:50.0919 0x110c  Actual detected object count: 0

# AdwCleaner v5.008 - Logfile created 21/09/2015 at 06:31:38
# Updated 18/09/2015 by Xplode
# Database : 2015-09-20.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Shravan - SHRAVAN-PC
# Running from : C:\Users\Shravan\Downloads\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
Folder Found : C:\ProgramData\apn
Folder Found : C:\ProgramData\{3727c30e-4e22-fc11-3727-7c30e4e20c39}
Folder Found : C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
Folder Found : C:\Windows\SysWOW64\C2MP
 
***** [ Files ] *****
 
File Found : C:\Users\Shravan\AppData\Roaming\Mozilla\Firefox\Profiles\d46u3ncj.default-1376014017535\user.js
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
Task Found : DSite
 
***** [ Registry ] *****
 
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
Key Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
Key Found : HKCU\Software\Conduit
Key Found : HKCU\Software\systweak
Key Found : HKCU\Software\PRODUCTSETUP
Key Found : HKCU\Software\WEBAPP
Key Found : [x64] HKCU\Software\Conduit
Key Found : [x64] HKCU\Software\systweak
Key Found : [x64] HKCU\Software\PRODUCTSETUP
Key Found : [x64] HKCU\Software\WEBAPP
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F00E6C48-0924-48ED-80B0-FFEF19EE30A4}
Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {F00E6C48-0924-48ED-80B0-FFEF19EE30A4}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{F00E6C48-0924-48ED-80B0-FFEF19EE30A4}
Data Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {F00E6C48-0924-48ED-80B0-FFEF19EE30A4}
Key Found : HKU\S-1-5-21-950273752-2326613030-74709175-1000\Software\Microsoft\Internet Explorer\SearchScopes\{F00E6C48-0924-48ED-80B0-FFEF19EE30A4}
Data Found : HKU\S-1-5-21-950273752-2326613030-74709175-1000\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {F00E6C48-0924-48ED-80B0-FFEF19EE30A4}
 
***** [ Web browsers ] *****
 
[C:\Users\Shravan\AppData\Roaming\Mozilla\Firefox\Profiles\pjNCDMFd.default\prefs.js] [Preference] Found : user_pref("browser.startup.homepage", "hxxp://in.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_wnzp_15_35&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Din%26pa%3DWincy%26cd[...]
[C:\Users\Shravan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://myhome.vi-view.com/?type=hp&ts=1416185050&from=cor&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUF85580155801
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2996 bytes] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.2 (09.14.2015:1)
OS: Windows 7 Ultimate x64
Ran by Shravan on 21/Sep/2015 at  6:33:54.73
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs
 
 
 
~~~ Registry Keys
 
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{A2B57937-079F-4FD6-9726-D5A23D27B0DD}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{F00E6C48-0924-48ED-80B0-FFEF19EE30A4}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Eventlog\Application\Update EnhanceTronic
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
Successfully deleted: [Empty Folder] C:\Users\Shravan\Appdata\Local\{3536FD64-FCE7-4701-83A9-6D42B4AF18C6}
Successfully deleted: [Empty Folder] C:\Users\Shravan\Appdata\Local\{53EF5737-6853-4DA6-B240-068583DA144E}
Successfully deleted: [Folder] C:\ProgramData\ammyy
Successfully deleted: [Folder] C:\ProgramData\apn
Successfully deleted: [Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mipony
Successfully deleted: [Folder] C:\Users\Shravan\AppData\Roaming\mipony
Successfully deleted: [Folder] C:\Users\Shravan\Documents\add-in express
Successfully deleted: [Folder] C:\Windows\SysWOW64\C2MP
 
 
 
~~~ FireFox
 
Successfully deleted: [File] C:\Users\Shravan\AppData\Roaming\mozilla\firefox\profiles\d46u3ncj.default-1376014017535\user.js
Emptied folder: C:\Users\Shravan\AppData\Roaming\mozilla\firefox\profiles\d46u3ncj.default-1376014017535\minidumps [18 files]
 
 
 
~~~ Chrome
 
 
[C:\Users\Shravan\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Shravan\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\Shravan\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Shravan\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 21/Sep/2015 at  6:36:48.97
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#5 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,569 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:32 AM

Posted 20 September 2015 - 09:10 PM

After ESET completes remove what ADWclener found.

Double click on AdwCleaner.exe to run the tool again. Vista/Windows 7/8 users right-click and select Run As Administrator[/i]
  • The tool will start to update the database, please wait a bit.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
  • <-insert any special instructions here for what to uncheck OR remove this line if there are none->
  • I'll look back tomorrow
  • This time click on the Cleaning button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#6 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 21 September 2015 - 01:41 AM

C:\Users\All Users\IObit\ASCDownloader\ASCSetup.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application
C:\Users\All Users\IObit\ASCDownloader\Smart Defrag.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application
D:\Users\All Users\IObit\ASCDownloader\ASCSetup.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application
D:\Users\All Users\IObit\ASCDownloader\Smart Defrag.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application
C:\ProgramData\IObit\ASCDownloader\ASCSetup.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application deleted - quarantined
C:\ProgramData\IObit\ASCDownloader\Smart Defrag.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application deleted - quarantined
C:\Users\Shravan\AppData\Local\Temp\F52C.exe a variant of Win32/Adware.MultiPlug.JK application cleaned by deleting - quarantined
C:\Users\Shravan\AppData\Local\Temp\uttFFC2.tmp.exe a variant of Win32/Bundled.Toolbar.Ask.E potentially unsafe application cleaned by deleting - quarantined
C:\Users\Shravan\AppData\Local\Temp\3740\temp\Game of Thrones S05E01 1080p HDTV.exe a variant of Win32/Adware.MultiPlug.JK application cleaned by deleting - quarantined
C:\Users\Shravan\AppData\Local\Temp\is360511915\012FB511_stp.MSI a variant of Win32/Systweak.L potentially unwanted application deleted - quarantined
C:\Users\Shravan\AppData\Local\{71D94785-5571-2B3D-38E9-0ED51C81F24D}\uninstall.exe a variant of Win32/DealPly.BB potentially unwanted application cleaned by deleting - quarantined
C:\Users\Shravan\AppData\Roaming\BitTorrent\updates\7.9.2_35144.exe a variant of Win32/OpenCandy.C potentially unsafe application cleaned by deleting - quarantined
C:\Users\Shravan\AppData\Roaming\Indiabulls Securities Ltd\Power Indiabulls\AutoUpgrade.jar a variant of Java/JShrink.A potentially unsafe application deleted - quarantined
C:\Users\Shravan\AppData\Roaming\Indiabulls Securities Ltd\Power Indiabulls\desktrade.jar a variant of Java/JShrink.A potentially unsafe application deleted (after the next restart) - quarantined
C:\Users\Shravan\AppData\Roaming\Indiabulls Securities Ltd\Power Indiabulls\desktrade_old.jar a variant of Java/JShrink.A potentially unsafe application deleted - quarantined
C:\Users\Shravan\Downloads\asc-setup.exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application deleted - quarantined
C:\Users\Shravan\Downloads\Best+Business+Practices+f (1).ace a variant of Win32/Amonetize.HZ potentially unwanted application deleted - quarantined
C:\Users\Shravan\Downloads\Best+Business+Practices+f.ace a variant of Win32/Amonetize.HZ potentially unwanted application deleted - quarantined
C:\Users\Shravan\Downloads\BitTorrent (1).exe a variant of Win32/AdkDLLWrapper.A potentially unwanted application cleaned by deleting - quarantined
C:\Users\Shravan\Downloads\BitTorrent (2).exe a variant of Win32/OpenCandy.C potentially unsafe application cleaned by deleting - quarantined
C:\Users\Shravan\Downloads\BitTorrent.exe.9548.tmp a variant of Win32/AdkDLLWrapper.A potentially unwanted application cleaned by deleting - quarantined
C:\Users\Shravan\Downloads\cbsidlm-cbsi183-Free_MKV_Player-ORG-75978742.exe a variant of Win32/CNETInstaller.B potentially unwanted application cleaned by deleting - quarantined
C:\Users\Shravan\Downloads\defragsetup (1).exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application deleted - quarantined
C:\Users\Shravan\Downloads\defragsetup (2).exe a variant of Win32/Toolbar.Widgi.B potentially unwanted application deleted - quarantined
C:\Users\Shravan\Downloads\H.264 DVR CMS.exe a variant of Win32/4Shared.V potentially unwanted application cleaned by deleting - quarantined
C:\Users\Shravan\Downloads\PIBSetup5.2 (3).msi a variant of Java/JShrink.A potentially unsafe application deleted - quarantined
C:\Users\Shravan\Downloads\PIBSetup5.2.msi a variant of Java/JShrink.A potentially unsafe application deleted - quarantined
C:\Users\Shravan\Downloads\ViberSetup.exe Win32/Toolbar.SearchSuite.P potentially unwanted application cleaned by deleting - quarantined
C:\Windows\Installer\7063c.msi a variant of Java/JShrink.A potentially unsafe application deleted - quarantined
C:\Windows\Installer\MSI2898.tmp a variant of Win32/Bundled.Toolbar.Ask.F potentially unsafe application cleaned by deleting - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-11 042909\Backup Files 2013-03-11 042909\Backup files 1.zip a variant of Win32/AdkDLLWrapper.A potentially unwanted application deleted - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-11 042909\Backup Files 2013-03-11 042909\Backup files 7.zip a variant of Win32/Toolbar.Widgi.B potentially unwanted application deleted - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-11 042909\Backup Files 2013-03-11 042909\Backup files 8.zip a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application deleted - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-11 042909\Backup Files 2013-03-11 042909\Backup files 9.zip a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application deleted - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-17 193422\Backup Files 2013-03-17 193422\Backup files 1.zip a variant of Win32/AdkDLLWrapper.A potentially unwanted application deleted - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-17 193422\Backup Files 2013-03-17 193422\Backup files 7.zip a variant of Win32/Toolbar.Widgi.B potentially unwanted application deleted - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-17 193422\Backup Files 2013-03-17 193422\Backup files 8.zip a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application deleted - quarantined
F:\SHRAVAN-PC\Backup Set 2013-03-17 193422\Backup Files 2013-03-17 193422\Backup files 9.zip a variant of Win32/Bundled.Toolbar.Ask.G potentially unsafe application deleted - quarantined


#7 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 21 September 2015 - 01:49 AM

# AdwCleaner v5.008 - Logfile created 21/09/2015 at 12:14:47
# Updated 18/09/2015 by Xplode
# Database : 2015-09-20.1 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Shravan - SHRAVAN-PC
# Running from : C:\Users\Shravan\Downloads\AdwCleaner.exe
# Option : Cleaning
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\ProgramData\{3727c30e-4e22-fc11-3727-7c30e4e20c39}
[-] Folder Deleted : C:\ProgramData\{CED89F1A-945F-46EC-B23C-5EAF6D2DB12A}
 
***** [ Files ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
[-] Task Deleted : DSite
 
***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A43DE495-3D00-47D4-9D2C-303115707939}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
[-] Key Deleted : HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6}
[-] Key Deleted : HKCU\Software\Conduit
[-] Key Deleted : HKCU\Software\systweak
[-] Key Deleted : HKCU\Software\PRODUCTSETUP
[-] Key Deleted : HKCU\Software\WEBAPP
[!] Key Not Deleted : [x64] HKCU\Software\Conduit
[!] Key Not Deleted : [x64] HKCU\Software\systweak
[!] Key Not Deleted : [x64] HKCU\Software\PRODUCTSETUP
[!] Key Not Deleted : [x64] HKCU\Software\WEBAPP
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Shravan\AppData\Roaming\Mozilla\Firefox\Profiles\pjNCDMFd.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://in.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_wnzp_15_35&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Din%26pa%3DWincy%26cd[...]
[-] [C:\Users\Shravan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://myhome.vi-view.com/?type=hp&ts=1416185050&from=cor&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUF85580155801
 
*************************
 
:: Winsock settings cleared
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [2211 bytes] ##########


#8 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,569 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:32 AM

Posted 22 September 2015 - 09:16 AM

Run TFC and see how it is now.

Empty your temp folders using TFC (Temporary File Cleaner)
  • Please download TFC by Old Timer and save it to your desktop.
    alternate download link
  • Save any unsaved work. (TFC will close ALL open programs including your browser!)
  • Double-click on TFC.exe to run it. (If you are using Vista or above, right-click on the file and choose "Run As Administrator".)
  • Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
  • Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway allowing Windows to load normally (not into Safe Mode) to ensure a complete clean.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#9 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 22 September 2015 - 07:34 PM

Hello

I am running the TFC process as instructed
However, I am finding that the logo of the software keeps flashing and the bar of how much is done keeps flashing random lengths
My desktop has not disappeared which should as per the software

It's running like this for a long time
Is it normal or I am doing something wrong ?

Thanks for advising

#10 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,569 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:32 AM

Posted 22 September 2015 - 08:15 PM

Hi can you stop it?


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#11 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 22 September 2015 - 08:20 PM

Hello

 

Sorry for the alarm

 

The utility has completed its course

About 29 GB of files removed

Although it did not ask me to reboot, i exited and rebooted anyway

 

Please advise next course of action

 

Thanks for advising



#12 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,569 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:32 AM

Posted 22 September 2015 - 08:24 PM

That was good.

Please reboot again..

 

Now run ADWcleaner again and post that log.

 

EDIT: then run MBAM


Edited by boopme, 22 September 2015 - 08:26 PM.

How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook

#13 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 22 September 2015 - 08:36 PM

# AdwCleaner v5.008 - Logfile created 23/09/2015 at 07:04:39
# Updated 18/09/2015 by Xplode
# Database : 2015-09-22.3 [Server]
# Operating system : Windows 7 Ultimate Service Pack 1 (x64)
# Username : Shravan - SHRAVAN-PC
# Running from : C:\Users\Shravan\Downloads\AdwCleaner.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
 
***** [ Files ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
[C:\Users\Shravan\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Shravan\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Shravan\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://myhome.vi-view.com/?type=hp&ts=1416185050&from=cor&uid=WDCXWD5000AAKX-003CA0_WD-WMAYUF85580155801
 
########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [992 bytes] ##########


#14 Newbie1011

Newbie1011
  • Topic Starter

  • Members
  • 121 posts
  • OFFLINE
  •  
  • Local time:06:02 PM

Posted 22 September 2015 - 08:38 PM

Hello

 

Which MBAM Scan should I run ?

Threat , Custom or Hyper  ?

 

Thanks for advising



#15 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 73,569 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:07:32 AM

Posted 22 September 2015 - 08:41 PM

Run threat

 

Remove the ADW items next, seepost 5 if needed.


How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users