13:55:03.0330 0x015c TDSS rootkit removing tool 3.0.0.25 Feb 27 2014 15:23:02 13:55:03.0845 0x015c ============================================================ 13:55:03.0845 0x015c Current date / time: 2014/03/13 13:55:03.0845 13:55:03.0845 0x015c SystemInfo: 13:55:03.0845 0x015c 13:55:03.0845 0x015c OS Version: 6.1.7601 ServicePack: 1.0 13:55:03.0845 0x015c Product type: Workstation 13:55:03.0845 0x015c ComputerName: SANEX-KOMPUTER 13:55:03.0845 0x015c UserName: SANEX 13:55:03.0845 0x015c Windows directory: C:\Windows 13:55:03.0845 0x015c System windows directory: C:\Windows 13:55:03.0845 0x015c Processor architecture: Intel x86 13:55:03.0845 0x015c Number of processors: 2 13:55:03.0845 0x015c Page size: 0x1000 13:55:03.0845 0x015c Boot type: Normal boot 13:55:03.0845 0x015c ============================================================ 13:55:03.0845 0x015c BG loaded 13:55:04.0640 0x015c System UUID: {D3AE0D40-ACED-BD37-4D78-6CE02DF98F79} 13:55:06.0564 0x015c Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050 13:55:06.0584 0x015c ============================================================ 13:55:06.0584 0x015c \Device\Harddisk0\DR0: 13:55:06.0604 0x015c MBR partitions: 13:55:06.0604 0x015c \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x7C1000, BlocksNum 0x97B5800 13:55:06.0604 0x015c \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x9F76800, BlocksNum 0x8AA2000 13:55:06.0604 0x015c ============================================================ 13:55:06.0754 0x015c C: <-> \Device\Harddisk0\DR0\Partition1 13:55:06.0914 0x015c D: <-> \Device\Harddisk0\DR0\Partition2 13:55:06.0914 0x015c ============================================================ 13:55:06.0914 0x015c Initialize success 13:55:06.0914 0x015c ============================================================ 13:55:22.0970 0x0a48 ============================================================ 13:55:22.0970 0x0a48 Scan started 13:55:22.0970 0x0a48 Mode: Manual; SigCheck; TDLFS; 13:55:22.0970 0x0a48 ============================================================ 13:55:22.0970 0x0a48 KSN ping started 13:55:26.0074 0x0a48 KSN ping finished: true 13:55:36.0261 0x0a48 ================ Scan system memory ======================== 13:55:36.0261 0x0a48 System memory - ok 13:55:36.0261 0x0a48 ================ Scan services ============================= 13:55:38.0258 0x0a48 [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys 13:55:38.0913 0x0a48 1394ohci - ok 13:55:38.0944 0x0a48 Suspicious service (NoAccess): 28925ee982f322e5 13:55:38.0991 0x0a48 [ 50F9D0C60BBA75C4D100F29CDA78FF9A, 6EC82FFF7EA28331557417E84A49B0B59C6B69353EEFBD76FE1CEEEA80E5D184 ] 28925ee982f322e5 C:\Windows\System32\Drivers\28925ee982f322e5.sys 13:55:39.0022 0x0a48 Suspicious file ( NoAccess ): C:\Windows\System32\Drivers\28925ee982f322e5.sys. md5: 50F9D0C60BBA75C4D100F29CDA78FF9A, sha256: 6EC82FFF7EA28331557417E84A49B0B59C6B69353EEFBD76FE1CEEEA80E5D184 13:55:39.0054 0x0a48 28925ee982f322e5 - detected Rootkit.Win32.Necurs.gen ( 0 ) 13:55:41.0503 0x0a48 28925ee982f322e5 ( Rootkit.Win32.Necurs.gen ) - infected 13:55:41.0503 0x0a48 Force sending object to P2P due to detect: C:\Windows\System32\Drivers\28925ee982f322e5.sys 13:55:45.0263 0x0a48 Object send P2P result: true 13:55:48.0492 0x0a48 [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\Windows\system32\drivers\ACPI.sys 13:55:48.0523 0x0a48 ACPI - ok 13:55:48.0554 0x0a48 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys 13:55:48.0617 0x0a48 AcpiPmi - ok 13:55:48.0710 0x0a48 [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 13:55:48.0726 0x0a48 AdobeARMservice - ok 13:55:48.0804 0x0a48 [ 9D96B0D5855FD1B98023B3EEC9F06786, E4C79233158BE8AA4E9C6DD71585E5D2703A5156531EB3D692D7D81BC443E844 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe 13:55:48.0819 0x0a48 AdobeFlashPlayerUpdateSvc - ok 13:55:48.0882 0x0a48 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 13:55:48.0913 0x0a48 adp94xx - ok 13:55:48.0944 0x0a48 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\drivers\adpahci.sys 13:55:48.0975 0x0a48 adpahci - ok 13:55:48.0991 0x0a48 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\drivers\adpu320.sys 13:55:49.0007 0x0a48 adpu320 - ok 13:55:49.0038 0x0a48 [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 13:55:49.0147 0x0a48 AeLookupSvc - ok 13:55:49.0178 0x0a48 [ F81BB7E487EDCEAB630A7EE66CF23913, 7D1638FD7E388EF670FA0A421762E0413351058A20DDF0F9988A383F05395A68 ] AFD C:\Windows\system32\drivers\afd.sys 13:55:49.0241 0x0a48 AFD - ok 13:55:49.0256 0x0a48 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys 13:55:49.0272 0x0a48 agp440 - ok 13:55:49.0319 0x0a48 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\drivers\djsvs.sys 13:55:49.0334 0x0a48 aic78xx - ok 13:55:49.0381 0x0a48 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe 13:55:49.0428 0x0a48 ALG - ok 13:55:49.0475 0x0a48 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys 13:55:49.0490 0x0a48 aliide - ok 13:55:49.0490 0x0a48 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys 13:55:49.0506 0x0a48 amdagp - ok 13:55:49.0521 0x0a48 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\drivers\amdide.sys 13:55:49.0537 0x0a48 amdide - ok 13:55:49.0553 0x0a48 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 13:55:49.0584 0x0a48 AmdK8 - ok 13:55:49.0584 0x0a48 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\drivers\amdppm.sys 13:55:49.0631 0x0a48 AmdPPM - ok 13:55:49.0677 0x0a48 [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\Windows\system32\drivers\amdsata.sys 13:55:49.0709 0x0a48 amdsata - ok 13:55:49.0724 0x0a48 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 13:55:49.0740 0x0a48 amdsbs - ok 13:55:49.0787 0x0a48 [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\Windows\system32\drivers\amdxata.sys 13:55:49.0802 0x0a48 amdxata - ok 13:55:49.0833 0x0a48 [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID C:\Windows\system32\drivers\appid.sys 13:55:49.0880 0x0a48 AppID - ok 13:55:49.0896 0x0a48 [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc C:\Windows\System32\appidsvc.dll 13:55:49.0943 0x0a48 AppIDSvc - ok 13:55:50.0005 0x0a48 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\Windows\System32\appinfo.dll 13:55:50.0052 0x0a48 Appinfo - ok 13:55:50.0099 0x0a48 [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt C:\Windows\System32\appmgmts.dll 13:55:50.0145 0x0a48 AppMgmt - ok 13:55:50.0177 0x0a48 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\drivers\arc.sys 13:55:50.0192 0x0a48 arc - ok 13:55:50.0239 0x0a48 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\drivers\arcsas.sys 13:55:50.0255 0x0a48 arcsas - ok 13:55:50.0364 0x0a48 [ 9D768C43FEF254DD50B1DBF8AD5C4C0B, A50854EA5C08605133B8BB4DFDC6090357C5665314AA72E0BFA1E07D4E451F09 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe 13:55:50.0473 0x0a48 aspnet_state - ok 13:55:50.0489 0x0a48 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 13:55:50.0582 0x0a48 AsyncMac - ok 13:55:50.0629 0x0a48 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys 13:55:50.0629 0x0a48 atapi - ok 13:55:50.0723 0x0a48 [ 14F8D278988BC02B9B4BF202B5BB1115, 6453BADFBCBCA7A7618C75C66A4E9130102885466C7195F34E57CAA6517F7D21 ] athur C:\Windows\system32\DRIVERS\athur.sys 13:55:50.0785 0x0a48 athur - ok 13:55:50.0832 0x0a48 [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 13:55:50.0863 0x0a48 AudioEndpointBuilder - ok 13:55:50.0894 0x0a48 [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] Audiosrv C:\Windows\System32\Audiosrv.dll 13:55:50.0910 0x0a48 Audiosrv - ok 13:55:50.0941 0x0a48 [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\Windows\System32\AxInstSV.dll 13:55:51.0003 0x0a48 AxInstSV - ok 13:55:51.0050 0x0a48 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\drivers\bxvbdx.sys 13:55:51.0097 0x0a48 b06bdrv - ok 13:55:51.0144 0x0a48 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys 13:55:51.0175 0x0a48 b57nd60x - ok 13:55:51.0222 0x0a48 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll 13:55:51.0269 0x0a48 BDESVC - ok 13:55:51.0284 0x0a48 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys 13:55:51.0331 0x0a48 Beep - ok 13:55:51.0378 0x0a48 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\Windows\System32\bfe.dll 13:55:51.0425 0x0a48 BFE - ok 13:55:51.0471 0x0a48 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\System32\qmgr.dll 13:55:51.0518 0x0a48 BITS - ok 13:55:51.0534 0x0a48 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys 13:55:51.0549 0x0a48 blbdrive - ok 13:55:51.0596 0x0a48 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 13:55:51.0643 0x0a48 bowser - ok 13:55:51.0674 0x0a48 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys 13:55:51.0705 0x0a48 BrFiltLo - ok 13:55:51.0752 0x0a48 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys 13:55:51.0971 0x0a48 BrFiltUp - ok 13:55:52.0080 0x0a48 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\Windows\System32\browser.dll 13:55:52.0158 0x0a48 Browser - ok 13:55:52.0283 0x0a48 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys 13:55:52.0470 0x0a48 Brserid - ok 13:55:52.0532 0x0a48 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys 13:55:52.0641 0x0a48 BrSerWdm - ok 13:55:52.0688 0x0a48 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys 13:55:52.0766 0x0a48 BrUsbMdm - ok 13:55:52.0797 0x0a48 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys 13:55:52.0860 0x0a48 BrUsbSer - ok 13:55:52.0891 0x0a48 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 13:55:52.0922 0x0a48 BTHMODEM - ok 13:55:52.0985 0x0a48 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll 13:55:53.0016 0x0a48 bthserv - ok 13:55:53.0047 0x0a48 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 13:55:53.0078 0x0a48 cdfs - ok 13:55:53.0141 0x0a48 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 13:55:53.0172 0x0a48 cdrom - ok 13:55:53.0219 0x0a48 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll 13:55:53.0250 0x0a48 CertPropSvc - ok 13:55:53.0281 0x0a48 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\drivers\circlass.sys 13:55:53.0312 0x0a48 circlass - ok 13:55:53.0359 0x0a48 [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS C:\Windows\system32\CLFS.sys 13:55:53.0375 0x0a48 CLFS - ok 13:55:53.0437 0x0a48 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 13:55:53.0453 0x0a48 clr_optimization_v2.0.50727_32 - ok 13:55:53.0499 0x0a48 [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 13:55:53.0562 0x0a48 clr_optimization_v4.0.30319_32 - ok 13:55:53.0577 0x0a48 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\drivers\CmBatt.sys 13:55:53.0609 0x0a48 CmBatt - ok 13:55:53.0640 0x0a48 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys 13:55:53.0655 0x0a48 cmdide - ok 13:55:53.0702 0x0a48 [ 85449EEBE8F8EBD6481EFBF0F352B4EB, E6FF04970C5A5BFDE7297A86C1C7B9BFE2E0F976A1A1AFB874CEB488DC6151CC ] CNG C:\Windows\system32\Drivers\cng.sys 13:55:53.0733 0x0a48 CNG - ok 13:55:53.0733 0x0a48 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\drivers\compbatt.sys 13:55:53.0733 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\compbatt.sys. md5: A6023D3823C37043986713F118A89BEE, sha256: FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B 13:55:53.0733 0x0a48 Compbatt - detected LockedFile.Multi.Generic ( 1 ) 13:55:56.0183 0x0a48 Detect skipped due to KSN trusted 13:55:56.0183 0x0a48 Compbatt - ok 13:55:56.0214 0x0a48 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys 13:55:56.0245 0x0a48 CompositeBus - ok 13:55:56.0261 0x0a48 COMSysApp - ok 13:55:56.0276 0x0a48 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 13:55:56.0292 0x0a48 crcdisk - ok 13:55:56.0323 0x0a48 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162ED8C76A036CD71549ED64E7797 ] CryptSvc C:\Windows\system32\cryptsvc.dll 13:55:56.0385 0x0a48 CryptSvc - ok 13:55:56.0401 0x0a48 [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] CSC C:\Windows\system32\drivers\csc.sys 13:55:56.0463 0x0a48 CSC - ok 13:55:56.0510 0x0a48 [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] CscService C:\Windows\System32\cscsvc.dll 13:55:56.0541 0x0a48 CscService - ok 13:55:56.0573 0x0a48 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\Windows\system32\rpcss.dll 13:55:56.0619 0x0a48 DcomLaunch - ok 13:55:56.0651 0x0a48 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll 13:55:56.0697 0x0a48 defragsvc - ok 13:55:56.0744 0x0a48 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 13:55:56.0791 0x0a48 DfsC - ok 13:55:56.0822 0x0a48 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll 13:55:56.0885 0x0a48 Dhcp - ok 13:55:56.0900 0x0a48 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys 13:55:56.0947 0x0a48 discache - ok 13:55:56.0994 0x0a48 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\drivers\disk.sys 13:55:56.0994 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\disk.sys. md5: 565003F326F99802E68CA78F2A68E9FF, sha256: ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 13:55:56.0994 0x0a48 Disk - detected LockedFile.Multi.Generic ( 1 ) 13:55:59.0833 0x0a48 Detect skipped due to KSN trusted 13:55:59.0833 0x0a48 Disk - ok 13:55:59.0849 0x0a48 [ 2A958EF85DB1B61FFCA65044FA4BCE9E, C83511685EE1CE85A5ADF9B5BE96C375A521601F66024BDC3EE044C0B6E85D69 ] dmvsc C:\Windows\system32\drivers\dmvsc.sys 13:55:59.0895 0x0a48 dmvsc - ok 13:55:59.0942 0x0a48 [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\Windows\System32\dnsrslvr.dll 13:56:00.0005 0x0a48 Dnscache - ok 13:56:00.0036 0x0a48 [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\Windows\System32\dot3svc.dll 13:56:00.0083 0x0a48 dot3svc - ok 13:56:00.0129 0x0a48 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll 13:56:00.0176 0x0a48 DPS - ok 13:56:00.0223 0x0a48 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 13:56:00.0270 0x0a48 drmkaud - ok 13:56:00.0301 0x0a48 [ E6B7D1B24E16FB24CE1FEA964E144EBC, 30F81E0A017163A1AB463FE3A13B5CC2905B973E782AEBC1EB63759BF2470658 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys 13:56:00.0301 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\dtsoftbus01.sys. md5: E6B7D1B24E16FB24CE1FEA964E144EBC, sha256: 30F81E0A017163A1AB463FE3A13B5CC2905B973E782AEBC1EB63759BF2470658 13:56:00.0317 0x0a48 dtsoftbus01 - detected LockedFile.Multi.Generic ( 1 ) 13:56:02.0781 0x0a48 Detect skipped due to KSN trusted 13:56:02.0781 0x0a48 dtsoftbus01 - ok 13:56:02.0844 0x0a48 [ 71BC35067CABC02C9453AEAA42B2E43E, 713B19F2C08EA5E4C087F7A74A8856932CF33E19D63384823DD4E02ED8798619 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 13:56:02.0844 0x0a48 Suspicious file ( NoAccess ): C:\Windows\System32\drivers\dxgkrnl.sys. md5: 71BC35067CABC02C9453AEAA42B2E43E, sha256: 713B19F2C08EA5E4C087F7A74A8856932CF33E19D63384823DD4E02ED8798619 13:56:02.0844 0x0a48 DXGKrnl - detected LockedFile.Multi.Generic ( 1 ) 13:56:05.0355 0x0a48 Detect skipped due to KSN trusted 13:56:05.0355 0x0a48 DXGKrnl - ok 13:56:05.0387 0x0a48 [ CF0A6015F437161698C5B2A0A12CF052, C23A777CF5D34C96B16A4A6197DA3F14CC2F8C56421E422BBD46617C941DBBCE ] e1express C:\Windows\system32\DRIVERS\e1e6032.sys 13:56:05.0387 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\e1e6032.sys. md5: CF0A6015F437161698C5B2A0A12CF052, sha256: C23A777CF5D34C96B16A4A6197DA3F14CC2F8C56421E422BBD46617C941DBBCE 13:56:05.0387 0x0a48 e1express - detected LockedFile.Multi.Generic ( 1 ) 13:56:07.0805 0x0a48 Detect skipped due to KSN trusted 13:56:07.0805 0x0a48 e1express - ok 13:56:07.0836 0x0a48 [ 3EA531906572FFD549B72A10F828E58C, 179D40413E5CB1E46F9486F80D56C8DE5CDE0C309BC65E0508D98C3E6A00BBEB ] e1kexpress C:\Windows\system32\DRIVERS\e1k6032.sys 13:56:07.0836 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\e1k6032.sys. md5: 3EA531906572FFD549B72A10F828E58C, sha256: 179D40413E5CB1E46F9486F80D56C8DE5CDE0C309BC65E0508D98C3E6A00BBEB 13:56:07.0836 0x0a48 e1kexpress - detected LockedFile.Multi.Generic ( 1 ) 13:56:11.0330 0x0a48 Detect skipped due to KSN trusted 13:56:11.0330 0x0a48 e1kexpress - ok 13:56:11.0377 0x0a48 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll 13:56:11.0439 0x0a48 EapHost - ok 13:56:11.0564 0x0a48 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\drivers\evbdx.sys 13:56:11.0564 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\evbdx.sys. md5: 024E1B5CAC09731E4D868E64DBFB4AB0, sha256: AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 13:56:11.0564 0x0a48 ebdrv - detected LockedFile.Multi.Generic ( 1 ) 13:56:14.0060 0x0a48 Detect skipped due to KSN trusted 13:56:14.0060 0x0a48 ebdrv - ok 13:56:14.0123 0x0a48 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] EFS C:\Windows\System32\lsass.exe 13:56:14.0185 0x0a48 EFS - ok 13:56:14.0357 0x0a48 [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe 13:56:14.0419 0x0a48 ehRecvr - ok 13:56:14.0435 0x0a48 [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe 13:56:14.0467 0x0a48 ehSched - ok 13:56:14.0529 0x0a48 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\drivers\elxstor.sys 13:56:14.0529 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\elxstor.sys. md5: 0ED67910C8C326796FAA00B2BF6D9D3C, sha256: 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 13:56:14.0545 0x0a48 elxstor - detected LockedFile.Multi.Generic ( 1 ) 13:56:16.0932 0x0a48 Detect skipped due to KSN trusted 13:56:16.0932 0x0a48 elxstor - ok 13:56:16.0947 0x0a48 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys 13:56:16.0947 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\errdev.sys. md5: 8FC3208352DD3912C94367A206AB3F11, sha256: 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 13:56:16.0947 0x0a48 ErrDev - detected LockedFile.Multi.Generic ( 1 ) 13:56:19.0334 0x0a48 Detect skipped due to KSN trusted 13:56:19.0334 0x0a48 ErrDev - ok 13:56:19.0381 0x0a48 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll 13:56:19.0443 0x0a48 EventSystem - ok 13:56:19.0459 0x0a48 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys 13:56:19.0459 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\exfat.sys. md5: 2DC9108D74081149CC8B651D3A26207F, sha256: 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 13:56:19.0459 0x0a48 exfat - detected LockedFile.Multi.Generic ( 1 ) 13:56:22.0532 0x0a48 Detect skipped due to KSN trusted 13:56:22.0532 0x0a48 exfat - ok 13:56:22.0548 0x0a48 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys 13:56:22.0548 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\fastfat.sys. md5: 7E0AB74553476622FB6AE36F73D97D35, sha256: 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 13:56:22.0548 0x0a48 fastfat - detected LockedFile.Multi.Generic ( 1 ) 13:56:25.0028 0x0a48 Detect skipped due to KSN trusted 13:56:25.0028 0x0a48 fastfat - ok 13:56:25.0075 0x0a48 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe 13:56:25.0137 0x0a48 Fax - ok 13:56:25.0168 0x0a48 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 13:56:25.0168 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\fdc.sys. md5: E817A017F82DF2A1F8CFDBDA29388B29, sha256: 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 13:56:25.0168 0x0a48 fdc - detected LockedFile.Multi.Generic ( 1 ) 13:56:27.0649 0x0a48 Detect skipped due to KSN trusted 13:56:27.0649 0x0a48 fdc - ok 13:56:27.0680 0x0a48 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll 13:56:27.0727 0x0a48 fdPHost - ok 13:56:27.0758 0x0a48 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll 13:56:27.0774 0x0a48 FDResPub - ok 13:56:27.0789 0x0a48 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 13:56:27.0789 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\fileinfo.sys. md5: 6CF00369C97F3CF563BE99BE983D13D8, sha256: F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 13:56:27.0789 0x0a48 FileInfo - detected LockedFile.Multi.Generic ( 1 ) 13:56:30.0223 0x0a48 Detect skipped due to KSN trusted 13:56:30.0223 0x0a48 FileInfo - ok 13:56:30.0238 0x0a48 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys 13:56:30.0238 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\filetrace.sys. md5: 42C51DC94C91DA21CB9196EB64C45DB9, sha256: 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 13:56:30.0238 0x0a48 Filetrace - detected LockedFile.Multi.Generic ( 1 ) 13:56:33.0702 0x0a48 Detect skipped due to KSN trusted 13:56:33.0702 0x0a48 Filetrace - ok 13:56:33.0717 0x0a48 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\drivers\flpydisk.sys 13:56:33.0717 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\flpydisk.sys. md5: 87907AA70CB3C56600F1C2FB8841579B, sha256: CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 13:56:33.0717 0x0a48 flpydisk - detected LockedFile.Multi.Generic ( 1 ) 13:56:36.0151 0x0a48 Detect skipped due to KSN trusted 13:56:36.0151 0x0a48 flpydisk - ok 13:56:36.0182 0x0a48 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 13:56:36.0182 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\fltmgr.sys. md5: 7520EC808E0C35E0EE6F841294316653, sha256: 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 13:56:36.0182 0x0a48 FltMgr - detected LockedFile.Multi.Generic ( 1 ) 13:56:40.0034 0x0a48 Detect skipped due to KSN trusted 13:56:40.0034 0x0a48 FltMgr - ok 13:56:40.0114 0x0a48 [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache C:\Windows\system32\FntCache.dll 13:56:40.0174 0x0a48 FontCache - ok 13:56:40.0234 0x0a48 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe 13:56:40.0264 0x0a48 FontCache3.0.0.0 - ok 13:56:40.0314 0x0a48 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 13:56:40.0314 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\FsDepends.sys. md5: 1A16B57943853E598CFF37FE2B8CBF1D, sha256: 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E 13:56:40.0314 0x0a48 FsDepends - detected LockedFile.Multi.Generic ( 1 ) 13:56:44.0134 0x0a48 Detect skipped due to KSN trusted 13:56:44.0134 0x0a48 FsDepends - ok 13:56:44.0174 0x0a48 [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 13:56:44.0174 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Fs_Rec.sys. md5: 7DAE5EBCC80E45D3253F4923DC424D05, sha256: 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A 13:56:44.0174 0x0a48 Fs_Rec - detected LockedFile.Multi.Generic ( 1 ) 13:56:46.0576 0x0a48 Detect skipped due to KSN trusted 13:56:46.0576 0x0a48 Fs_Rec - ok 13:56:46.0626 0x0a48 [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 13:56:46.0626 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\fvevol.sys. md5: E306A24D9694C724FA2491278BF50FDB, sha256: 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 13:56:46.0626 0x0a48 fvevol - detected LockedFile.Multi.Generic ( 1 ) 13:56:48.0986 0x0a48 Detect skipped due to KSN trusted 13:56:48.0986 0x0a48 fvevol - ok 13:56:49.0016 0x0a48 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 13:56:49.0016 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\gagp30kx.sys. md5: 65EE0C7A58B65E74AE05637418153938, sha256: 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF 13:56:49.0016 0x0a48 gagp30kx - detected LockedFile.Multi.Generic ( 1 ) 13:56:51.0496 0x0a48 Detect skipped due to KSN trusted 13:56:51.0496 0x0a48 gagp30kx - ok 13:56:51.0546 0x0a48 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll 13:56:51.0586 0x0a48 gpsvc - ok 13:56:51.0606 0x0a48 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys 13:56:51.0606 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\hcw85cir.sys. md5: C44E3C2BAB6837DB337DDEE7544736DB, sha256: 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D 13:56:51.0606 0x0a48 hcw85cir - detected LockedFile.Multi.Generic ( 1 ) 13:56:54.0046 0x0a48 Detect skipped due to KSN trusted 13:56:54.0046 0x0a48 hcw85cir - ok 13:56:54.0066 0x0a48 [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 13:56:54.0066 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\HdAudio.sys. md5: A5EF29D5315111C80A5C1ABAD14C8972, sha256: A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A 13:56:54.0066 0x0a48 HdAudAddService - detected LockedFile.Multi.Generic ( 1 ) 13:56:56.0466 0x0a48 Detect skipped due to KSN trusted 13:56:56.0466 0x0a48 HdAudAddService - ok 13:56:56.0486 0x0a48 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 13:56:56.0486 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\HDAudBus.sys. md5: 9036377B8A6C15DC2EEC53E489D159B5, sha256: 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B 13:56:56.0486 0x0a48 HDAudBus - detected LockedFile.Multi.Generic ( 1 ) 13:57:00.0306 0x0a48 Detect skipped due to KSN trusted 13:57:00.0306 0x0a48 HDAudBus - ok 13:57:00.0336 0x0a48 [ 88A67C34E37186665E916FD347B50D19, 23C4F11E421DE7D8330418118524D345A905300816E3D7D486DB18C670226EE1 ] HECI C:\Windows\system32\DRIVERS\HECI.sys 13:57:00.0336 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\HECI.sys. md5: 88A67C34E37186665E916FD347B50D19, sha256: 23C4F11E421DE7D8330418118524D345A905300816E3D7D486DB18C670226EE1 13:57:00.0336 0x0a48 HECI - detected LockedFile.Multi.Generic ( 1 ) 13:57:02.0736 0x0a48 Detect skipped due to KSN trusted 13:57:02.0736 0x0a48 HECI - ok 13:57:02.0756 0x0a48 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys 13:57:02.0756 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\HidBatt.sys. md5: 1D58A7F3E11A9731D0EAAAA8405ACC36, sha256: 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 13:57:02.0756 0x0a48 HidBatt - detected LockedFile.Multi.Generic ( 1 ) 13:57:05.0186 0x0a48 Detect skipped due to KSN trusted 13:57:05.0196 0x0a48 HidBatt - ok 13:57:05.0216 0x0a48 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\drivers\hidbth.sys 13:57:05.0216 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\hidbth.sys. md5: 89448F40E6DF260C206A193A4683BA78, sha256: 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C 13:57:05.0216 0x0a48 HidBth - detected LockedFile.Multi.Generic ( 1 ) 13:57:07.0576 0x0a48 Detect skipped due to KSN trusted 13:57:07.0576 0x0a48 HidBth - ok 13:57:07.0606 0x0a48 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\drivers\hidir.sys 13:57:07.0606 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\hidir.sys. md5: CF50B4CF4A4F229B9F3C08351F99CA5E, sha256: B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F 13:57:07.0606 0x0a48 HidIr - detected LockedFile.Multi.Generic ( 1 ) 13:57:09.0996 0x0a48 Detect skipped due to KSN trusted 13:57:09.0996 0x0a48 HidIr - ok 13:57:10.0016 0x0a48 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\system32\hidserv.dll 13:57:10.0056 0x0a48 hidserv - ok 13:57:10.0136 0x0a48 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 13:57:10.0136 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\hidusb.sys. md5: 10C19F8290891AF023EAEC0832E1EB4D, sha256: E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 13:57:10.0136 0x0a48 HidUsb - detected LockedFile.Multi.Generic ( 1 ) 13:57:12.0566 0x0a48 Detect skipped due to KSN trusted 13:57:12.0566 0x0a48 HidUsb - ok 13:57:12.0596 0x0a48 [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll 13:57:12.0626 0x0a48 hkmsvc - ok 13:57:12.0646 0x0a48 [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll 13:57:12.0696 0x0a48 HomeGroupListener - ok 13:57:12.0716 0x0a48 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 13:57:12.0746 0x0a48 HomeGroupProvider - ok 13:57:12.0766 0x0a48 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 13:57:12.0766 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\HpSAMD.sys. md5: 295FDC419039090EB8B49FFDBB374549, sha256: 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 13:57:12.0776 0x0a48 HpSAMD - detected LockedFile.Multi.Generic ( 1 ) 13:57:15.0246 0x0a48 Detect skipped due to KSN trusted 13:57:15.0246 0x0a48 HpSAMD - ok 13:57:15.0286 0x0a48 [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP C:\Windows\system32\drivers\HTTP.sys 13:57:15.0286 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\HTTP.sys. md5: 871917B07A141BFF43D76D8844D48106, sha256: 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 13:57:15.0286 0x0a48 HTTP - detected LockedFile.Multi.Generic ( 1 ) 13:57:18.0656 0x0a48 Detect skipped due to KSN trusted 13:57:18.0656 0x0a48 HTTP - ok 13:57:18.0676 0x0a48 [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 13:57:18.0676 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\hwpolicy.sys. md5: 0C4E035C7F105F1299258C90886C64C5, sha256: CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 13:57:18.0676 0x0a48 hwpolicy - detected LockedFile.Multi.Generic ( 1 ) 13:57:21.0067 0x0a48 Detect skipped due to KSN trusted 13:57:21.0067 0x0a48 hwpolicy - ok 13:57:21.0097 0x0a48 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys 13:57:21.0097 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\i8042prt.sys. md5: F151F0BDC47F4A28B1B20A0818EA36D6, sha256: 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 13:57:21.0107 0x0a48 i8042prt - detected LockedFile.Multi.Generic ( 1 ) 13:57:23.0447 0x0a48 Detect skipped due to KSN trusted 13:57:23.0447 0x0a48 i8042prt - ok 13:57:23.0507 0x0a48 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 13:57:23.0507 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\iaStorV.sys. md5: 5CD5F9A5444E6CDCB0AC89BD62D8B76E, sha256: 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 13:57:23.0507 0x0a48 iaStorV - detected LockedFile.Multi.Generic ( 1 ) 13:57:25.0897 0x0a48 Detect skipped due to KSN trusted 13:57:25.0897 0x0a48 iaStorV - ok 13:57:25.0967 0x0a48 [ C521D7EB6497BB1AF6AFA89E322FB43C, BDDCFCBB5B76A9295669B5AC9F732D6127199ED5C300770B554C4E4794F66BB7 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe 13:57:26.0027 0x0a48 idsvc - ok 13:57:26.0047 0x0a48 IEEtwCollectorService - ok 13:57:26.0367 0x0a48 [ DCE0B53570703CCE580D066F89EF58CD, C5C2C4F51F2DB2BB6E7F1218472AEAAD996514AB99EA84946A473CB7A64D9E15 ] igfx C:\Windows\system32\DRIVERS\igdkmd32.sys 13:57:26.0367 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\igdkmd32.sys. md5: DCE0B53570703CCE580D066F89EF58CD, sha256: C5C2C4F51F2DB2BB6E7F1218472AEAAD996514AB99EA84946A473CB7A64D9E15 13:57:26.0387 0x0a48 igfx - detected LockedFile.Multi.Generic ( 1 ) 13:57:30.0279 0x0a48 Detect skipped due to KSN trusted 13:57:30.0279 0x0a48 igfx - ok 13:57:30.0339 0x0a48 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\drivers\iirsp.sys 13:57:30.0339 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\iirsp.sys. md5: 4173FF5708F3236CF25195FECD742915, sha256: 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D 13:57:30.0339 0x0a48 iirsp - detected LockedFile.Multi.Generic ( 1 ) 13:57:32.0729 0x0a48 Detect skipped due to KSN trusted 13:57:32.0729 0x0a48 iirsp - ok 13:57:32.0809 0x0a48 [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT C:\Windows\System32\ikeext.dll 13:57:32.0859 0x0a48 IKEEXT - ok 13:57:32.0869 0x0a48 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys 13:57:32.0869 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\intelide.sys. md5: A0F12F2C9BA6C72F3987CE780E77C130, sha256: 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 13:57:32.0869 0x0a48 intelide - detected LockedFile.Multi.Generic ( 1 ) 13:57:35.0359 0x0a48 Detect skipped due to KSN trusted 13:57:35.0359 0x0a48 intelide - ok 13:57:35.0399 0x0a48 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 13:57:35.0399 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\intelppm.sys. md5: 3B514D27BFC4ACCB4037BC6685F766E0, sha256: F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A 13:57:35.0399 0x0a48 intelppm - detected LockedFile.Multi.Generic ( 1 ) 13:57:37.0759 0x0a48 Detect skipped due to KSN trusted 13:57:37.0759 0x0a48 intelppm - ok 13:57:37.0789 0x0a48 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 13:57:37.0819 0x0a48 IPBusEnum - ok 13:57:37.0829 0x0a48 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 13:57:37.0829 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ipfltdrv.sys. md5: 709D1761D3B19A932FF0238EA6D50200, sha256: 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 13:57:37.0829 0x0a48 IpFilterDriver - detected LockedFile.Multi.Generic ( 1 ) 13:57:41.0439 0x0a48 Detect skipped due to KSN trusted 13:57:41.0439 0x0a48 IpFilterDriver - ok 13:57:41.0509 0x0a48 [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 13:57:41.0549 0x0a48 iphlpsvc - ok 13:57:41.0579 0x0a48 [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys 13:57:41.0579 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\IPMIDrv.sys. md5: 4BD7134618C1D2A27466A099062547BF, sha256: 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 13:57:41.0579 0x0a48 IPMIDRV - detected LockedFile.Multi.Generic ( 1 ) 13:57:43.0989 0x0a48 Detect skipped due to KSN trusted 13:57:43.0989 0x0a48 IPMIDRV - ok 13:57:43.0999 0x0a48 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 13:57:43.0999 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ipnat.sys. md5: A5FA468D67ABCDAA36264E463A7BB0CD, sha256: EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 13:57:43.0999 0x0a48 IPNAT - detected LockedFile.Multi.Generic ( 1 ) 13:57:46.0489 0x0a48 Detect skipped due to KSN trusted 13:57:46.0489 0x0a48 IPNAT - ok 13:57:46.0519 0x0a48 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys 13:57:46.0519 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\irenum.sys. md5: 42996CFF20A3084A56017B7902307E9F, sha256: 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D 13:57:46.0529 0x0a48 IRENUM - detected LockedFile.Multi.Generic ( 1 ) 13:57:48.0999 0x0a48 Detect skipped due to KSN trusted 13:57:48.0999 0x0a48 IRENUM - ok 13:57:48.0999 0x0a48 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys 13:57:48.0999 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\isapnp.sys. md5: 1F32BB6B38F62F7DF1A7AB7292638A35, sha256: 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F 13:57:48.0999 0x0a48 isapnp - detected LockedFile.Multi.Generic ( 1 ) 13:57:52.0539 0x0a48 Detect skipped due to KSN trusted 13:57:52.0539 0x0a48 isapnp - ok 13:57:52.0579 0x0a48 [ CB7A9ABB12B8415BCE5D74994C7BA3AE, 464BFF3F5EEE985BE075E23E1813F5CB82A9A0771A92C6D889B13B867BCDF647 ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys 13:57:52.0579 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msiscsi.sys. md5: CB7A9ABB12B8415BCE5D74994C7BA3AE, sha256: 464BFF3F5EEE985BE075E23E1813F5CB82A9A0771A92C6D889B13B867BCDF647 13:57:52.0579 0x0a48 iScsiPrt - detected LockedFile.Multi.Generic ( 1 ) 13:57:54.0969 0x0a48 Detect skipped due to KSN trusted 13:57:54.0969 0x0a48 iScsiPrt - ok 13:57:54.0999 0x0a48 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 13:57:54.0999 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\kbdclass.sys. md5: ADEF52CA1AEAE82B50DF86B56413107E, sha256: A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 13:57:54.0999 0x0a48 kbdclass - detected LockedFile.Multi.Generic ( 1 ) 13:57:58.0839 0x0a48 Detect skipped due to KSN trusted 13:57:58.0839 0x0a48 kbdclass - ok 13:57:58.0859 0x0a48 [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 13:57:58.0859 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\kbdhid.sys. md5: 9E3CED91863E6EE98C24794D05E27A71, sha256: 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F 13:57:58.0859 0x0a48 kbdhid - detected LockedFile.Multi.Generic ( 1 ) 13:58:01.0289 0x0a48 Detect skipped due to KSN trusted 13:58:01.0289 0x0a48 kbdhid - ok 13:58:01.0299 0x0a48 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] KeyIso C:\Windows\system32\lsass.exe 13:58:01.0309 0x0a48 KeyIso - ok 13:58:01.0359 0x0a48 [ F286830298323272260332D6ABC905C1, FF4CD182A95CA53119B228690D682EE9214BE131A0DBCB09B6189FBEBBFF902C ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 13:58:01.0359 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\ksecdd.sys. md5: F286830298323272260332D6ABC905C1, sha256: FF4CD182A95CA53119B228690D682EE9214BE131A0DBCB09B6189FBEBBFF902C 13:58:01.0359 0x0a48 KSecDD - detected LockedFile.Multi.Generic ( 1 ) 13:58:04.0099 0x0a48 Detect skipped due to KSN trusted 13:58:04.0099 0x0a48 KSecDD - ok 13:58:04.0119 0x0a48 [ D7C760D57B1656DD748B9E4AB6CB5A51, F8AE4185A6A9F7005DEFF1FDC03F395C6189825B482B8C650637FD29DE93AB68 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 13:58:04.0119 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\ksecpkg.sys. md5: D7C760D57B1656DD748B9E4AB6CB5A51, sha256: F8AE4185A6A9F7005DEFF1FDC03F395C6189825B482B8C650637FD29DE93AB68 13:58:04.0119 0x0a48 KSecPkg - detected LockedFile.Multi.Generic ( 1 ) 13:58:06.0469 0x0a48 Detect skipped due to KSN trusted 13:58:06.0469 0x0a48 KSecPkg - ok 13:58:06.0499 0x0a48 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll 13:58:06.0539 0x0a48 KtmRm - ok 13:58:06.0569 0x0a48 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\system32\srvsvc.dll 13:58:06.0609 0x0a48 LanmanServer - ok 13:58:06.0639 0x0a48 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 13:58:06.0659 0x0a48 LanmanWorkstation - ok 13:58:06.0709 0x0a48 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 13:58:06.0709 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\lltdio.sys. md5: F7611EC07349979DA9B0AE1F18CCC7A6, sha256: 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E 13:58:06.0709 0x0a48 lltdio - detected LockedFile.Multi.Generic ( 1 ) 13:58:09.0189 0x0a48 Detect skipped due to KSN trusted 13:58:09.0189 0x0a48 lltdio - ok 13:58:09.0229 0x0a48 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll 13:58:09.0279 0x0a48 lltdsvc - ok 13:58:09.0299 0x0a48 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll 13:58:09.0339 0x0a48 lmhosts - ok 13:58:09.0389 0x0a48 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 13:58:09.0389 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_fc.sys. md5: EB119A53CCF2ACC000AC71B065B78FEF, sha256: 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 13:58:09.0389 0x0a48 LSI_FC - detected LockedFile.Multi.Generic ( 1 ) 13:58:11.0879 0x0a48 Detect skipped due to KSN trusted 13:58:11.0879 0x0a48 LSI_FC - ok 13:58:11.0889 0x0a48 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 13:58:11.0889 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_sas.sys. md5: 8ADE1C877256A22E49B75D1CC9161F9C, sha256: 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 13:58:11.0889 0x0a48 LSI_SAS - detected LockedFile.Multi.Generic ( 1 ) 13:58:15.0329 0x0a48 Detect skipped due to KSN trusted 13:58:15.0329 0x0a48 LSI_SAS - ok 13:58:15.0339 0x0a48 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 13:58:15.0339 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_sas2.sys. md5: DC9DC3D3DAA0E276FD2EC262E38B11E9, sha256: A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC 13:58:15.0339 0x0a48 LSI_SAS2 - detected LockedFile.Multi.Generic ( 1 ) 13:58:17.0819 0x0a48 Detect skipped due to KSN trusted 13:58:17.0819 0x0a48 LSI_SAS2 - ok 13:58:17.0829 0x0a48 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 13:58:17.0829 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\lsi_scsi.sys. md5: 0A036C7D7CAB643A7F07135AC47E0524, sha256: 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 13:58:17.0829 0x0a48 LSI_SCSI - detected LockedFile.Multi.Generic ( 1 ) 13:58:20.0229 0x0a48 Detect skipped due to KSN trusted 13:58:20.0229 0x0a48 LSI_SCSI - ok 13:58:20.0249 0x0a48 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys 13:58:20.0249 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\luafv.sys. md5: 6703E366CC18D3B6E534F5CF7DF39CEE, sha256: 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 13:58:20.0249 0x0a48 luafv - detected LockedFile.Multi.Generic ( 1 ) 13:58:22.0609 0x0a48 Detect skipped due to KSN trusted 13:58:22.0609 0x0a48 luafv - ok 13:58:22.0669 0x0a48 [ 3B4C137E2CA87CF773204653A80B5BE9, D774945037F7A39EB23392DCCF4B52BDE03134C8D457EB9DDFE761B3B8C3D0D9 ] mbamchameleon C:\Windows\system32\drivers\mbamchameleon.sys 13:58:22.0689 0x0a48 mbamchameleon - ok 13:58:22.0699 0x0a48 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 13:58:22.0719 0x0a48 Mcx2Svc - ok 13:58:22.0749 0x0a48 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\drivers\megasas.sys 13:58:22.0749 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\megasas.sys. md5: 0FFF5B045293002AB38EB1FD1FC2FB74, sha256: 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 13:58:22.0749 0x0a48 megasas - detected LockedFile.Multi.Generic ( 1 ) 13:58:25.0219 0x0a48 Detect skipped due to KSN trusted 13:58:25.0219 0x0a48 megasas - ok 13:58:25.0249 0x0a48 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\drivers\MegaSR.sys 13:58:25.0249 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MegaSR.sys. md5: DCBAB2920C75F390CAF1D29F675D03D6, sha256: 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB 13:58:25.0259 0x0a48 MegaSR - detected LockedFile.Multi.Generic ( 1 ) 13:58:27.0699 0x0a48 Detect skipped due to KSN trusted 13:58:27.0699 0x0a48 MegaSR - ok 13:58:27.0719 0x0a48 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll 13:58:27.0759 0x0a48 MMCSS - ok 13:58:27.0779 0x0a48 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys 13:58:27.0779 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\modem.sys. md5: F001861E5700EE84E2D4E52C712F4964, sha256: F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE 13:58:27.0779 0x0a48 Modem - detected LockedFile.Multi.Generic ( 1 ) 13:58:30.0229 0x0a48 Detect skipped due to KSN trusted 13:58:30.0229 0x0a48 Modem - ok 13:58:30.0259 0x0a48 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 13:58:30.0259 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\monitor.sys. md5: 79D10964DE86B292320E9DFE02282A23, sha256: 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 13:58:30.0269 0x0a48 monitor - detected LockedFile.Multi.Generic ( 1 ) 13:58:32.0649 0x0a48 Detect skipped due to KSN trusted 13:58:32.0649 0x0a48 monitor - ok 13:58:32.0669 0x0a48 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 13:58:32.0669 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mouclass.sys. md5: FB18CC1D4C2E716B6B903B0AC0CC0609, sha256: F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E 13:58:32.0669 0x0a48 mouclass - detected LockedFile.Multi.Generic ( 1 ) 13:58:35.0319 0x0a48 Detect skipped due to KSN trusted 13:58:35.0319 0x0a48 mouclass - ok 13:58:35.0399 0x0a48 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 13:58:35.0399 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mouhid.sys. md5: 2C388D2CD01C9042596CF3C8F3C7B24D, sha256: B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 13:58:35.0399 0x0a48 mouhid - detected LockedFile.Multi.Generic ( 1 ) 13:58:39.0316 0x0a48 Detect skipped due to KSN trusted 13:58:39.0316 0x0a48 mouhid - ok 13:58:39.0334 0x0a48 [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 13:58:39.0334 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mountmgr.sys. md5: FC8771F45ECCCFD89684E38842539B9B, sha256: 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A 13:58:39.0334 0x0a48 mountmgr - detected LockedFile.Multi.Generic ( 1 ) 13:58:41.0773 0x0a48 Detect skipped due to KSN trusted 13:58:41.0773 0x0a48 mountmgr - ok 13:58:41.0841 0x0a48 [ 338037EFA0E8E8699B2667D57B751574, 59E0D39806D0C4EB57913AA013242837FD39AD378726AEE42D250CBA87C1C3BF ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe 13:58:41.0864 0x0a48 MozillaMaintenance - ok 13:58:41.0888 0x0a48 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio C:\Windows\system32\drivers\mpio.sys 13:58:41.0889 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mpio.sys. md5: 2D699FB6E89CE0D8DA14ECC03B3EDFE0, sha256: D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 13:58:41.0889 0x0a48 mpio - detected LockedFile.Multi.Generic ( 1 ) 13:58:44.0279 0x0a48 Detect skipped due to KSN trusted 13:58:44.0279 0x0a48 mpio - ok 13:58:44.0300 0x0a48 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 13:58:44.0300 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mpsdrv.sys. md5: AD2723A7B53DD1AACAE6AD8C0BFBF4D0, sha256: 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 13:58:44.0301 0x0a48 mpsdrv - detected LockedFile.Multi.Generic ( 1 ) 13:58:48.0141 0x0a48 Detect skipped due to KSN trusted 13:58:48.0141 0x0a48 mpsdrv - ok 13:58:48.0195 0x0a48 [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc C:\Windows\system32\mpssvc.dll 13:58:48.0250 0x0a48 MpsSvc - ok 13:58:48.0288 0x0a48 [ 21F4B24ACFC79A483515BD986DD9043F, 22681907E02E0B723ABE2CEF0602D36C8EF862E7E2B62A9B40A5EF582E58D7BA ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 13:58:48.0288 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\mrxdav.sys. md5: 21F4B24ACFC79A483515BD986DD9043F, sha256: 22681907E02E0B723ABE2CEF0602D36C8EF862E7E2B62A9B40A5EF582E58D7BA 13:58:48.0289 0x0a48 MRxDAV - detected LockedFile.Multi.Generic ( 1 ) 13:58:50.0648 0x0a48 Detect skipped due to KSN trusted 13:58:50.0648 0x0a48 MRxDAV - ok 13:58:50.0693 0x0a48 [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 13:58:50.0693 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mrxsmb.sys. md5: 5D16C921E3671636C0EBA3BBAAC5FD25, sha256: 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C 13:58:50.0694 0x0a48 mrxsmb - detected LockedFile.Multi.Generic ( 1 ) 13:58:53.0052 0x0a48 Detect skipped due to KSN trusted 13:58:53.0052 0x0a48 mrxsmb - ok 13:58:53.0095 0x0a48 [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 13:58:53.0096 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mrxsmb10.sys. md5: 6D17A4791ACA19328C685D256349FEFC, sha256: 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 13:58:53.0096 0x0a48 mrxsmb10 - detected LockedFile.Multi.Generic ( 1 ) 13:58:55.0529 0x0a48 Detect skipped due to KSN trusted 13:58:55.0529 0x0a48 mrxsmb10 - ok 13:58:55.0575 0x0a48 [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 13:58:55.0575 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mrxsmb20.sys. md5: B81F204D146000BE76651A50670A5E9E, sha256: 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 13:58:55.0575 0x0a48 mrxsmb20 - detected LockedFile.Multi.Generic ( 1 ) 13:58:57.0963 0x0a48 Detect skipped due to KSN trusted 13:58:57.0963 0x0a48 mrxsmb20 - ok 13:58:57.0979 0x0a48 [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci C:\Windows\system32\drivers\msahci.sys 13:58:57.0980 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msahci.sys. md5: 012C5F4E9349E711E11E0F19A8589F0A, sha256: 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 13:58:57.0980 0x0a48 msahci - detected LockedFile.Multi.Generic ( 1 ) 13:59:00.0883 0x0a48 Detect skipped due to KSN trusted 13:59:00.0883 0x0a48 msahci - ok 13:59:00.0914 0x0a48 [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm C:\Windows\system32\drivers\msdsm.sys 13:59:00.0915 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msdsm.sys. md5: 55055F8AD8BE27A64C831322A780A228, sha256: C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 13:59:00.0915 0x0a48 msdsm - detected LockedFile.Multi.Generic ( 1 ) 13:59:03.0303 0x0a48 Detect skipped due to KSN trusted 13:59:03.0303 0x0a48 msdsm - ok 13:59:03.0325 0x0a48 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe 13:59:03.0345 0x0a48 MSDTC - ok 13:59:03.0359 0x0a48 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys 13:59:03.0359 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Msfs.sys. md5: DAEFB28E3AF5A76ABCC2C3078C07327F, sha256: 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF 13:59:03.0359 0x0a48 Msfs - detected LockedFile.Multi.Generic ( 1 ) 13:59:05.0790 0x0a48 Detect skipped due to KSN trusted 13:59:05.0790 0x0a48 Msfs - ok 13:59:05.0815 0x0a48 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 13:59:05.0815 0x0a48 Suspicious file ( NoAccess ): C:\Windows\System32\drivers\mshidkmdf.sys. md5: 3E1E5767043C5AF9367F0056295E9F84, sha256: B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 13:59:05.0816 0x0a48 mshidkmdf - detected LockedFile.Multi.Generic ( 1 ) 13:59:08.0209 0x0a48 Detect skipped due to KSN trusted 13:59:08.0209 0x0a48 mshidkmdf - ok 13:59:08.0307 0x0a48 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 13:59:08.0307 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\msisadrv.sys. md5: 0A4E5757AE09FA9622E3158CC1AEF114, sha256: ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 13:59:08.0307 0x0a48 msisadrv - detected LockedFile.Multi.Generic ( 1 ) 13:59:10.0785 0x0a48 Detect skipped due to KSN trusted 13:59:10.0785 0x0a48 msisadrv - ok 13:59:10.0815 0x0a48 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll 13:59:10.0866 0x0a48 MSiSCSI - ok 13:59:10.0869 0x0a48 msiserver - ok 13:59:10.0890 0x0a48 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 13:59:10.0890 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSKSSRV.sys. md5: 8C0860D6366AAFFB6C5BB9DF9448E631, sha256: 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 13:59:10.0890 0x0a48 MSKSSRV - detected LockedFile.Multi.Generic ( 1 ) 13:59:13.0321 0x0a48 Detect skipped due to KSN trusted 13:59:13.0322 0x0a48 MSKSSRV - ok 13:59:13.0325 0x0a48 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 13:59:13.0325 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSPCLOCK.sys. md5: 3EA8B949F963562CEDBB549EAC0C11CE, sha256: 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D 13:59:13.0326 0x0a48 MSPCLOCK - detected LockedFile.Multi.Generic ( 1 ) 13:59:15.0794 0x0a48 Detect skipped due to KSN trusted 13:59:15.0794 0x0a48 MSPCLOCK - ok 13:59:15.0814 0x0a48 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 13:59:15.0814 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSPQM.sys. md5: F456E973590D663B1073E9C463B40932, sha256: 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 13:59:15.0814 0x0a48 MSPQM - detected LockedFile.Multi.Generic ( 1 ) 13:59:18.0166 0x0a48 Detect skipped due to KSN trusted 13:59:18.0166 0x0a48 MSPQM - ok 13:59:18.0180 0x0a48 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 13:59:18.0180 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MsRPC.sys. md5: 0E008FC4819D238C51D7C93E7B41E560, sha256: 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 13:59:18.0180 0x0a48 MsRPC - detected LockedFile.Multi.Generic ( 1 ) 13:59:20.0614 0x0a48 Detect skipped due to KSN trusted 13:59:20.0614 0x0a48 MsRPC - ok 13:59:20.0633 0x0a48 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 13:59:20.0633 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\mssmbios.sys. md5: FC6B9FF600CC585EA38B12589BD4E246, sha256: F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A 13:59:20.0633 0x0a48 mssmbios - detected LockedFile.Multi.Generic ( 1 ) 13:59:23.0320 0x0a48 Detect skipped due to KSN trusted 13:59:23.0320 0x0a48 mssmbios - ok 13:59:23.0331 0x0a48 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 13:59:23.0332 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MSTEE.sys. md5: B42C6B921F61A6E55159B8BE6CD54A36, sha256: 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C 13:59:23.0332 0x0a48 MSTEE - detected LockedFile.Multi.Generic ( 1 ) 13:59:25.0718 0x0a48 Detect skipped due to KSN trusted 13:59:25.0718 0x0a48 MSTEE - ok 13:59:25.0739 0x0a48 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\drivers\MTConfig.sys 13:59:25.0739 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\MTConfig.sys. md5: 33599130F44E1F34631CEA241DE8AC84, sha256: E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B 13:59:25.0739 0x0a48 MTConfig - detected LockedFile.Multi.Generic ( 1 ) 13:59:28.0175 0x0a48 Detect skipped due to KSN trusted 13:59:28.0176 0x0a48 MTConfig - ok 13:59:28.0197 0x0a48 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys 13:59:28.0197 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\Drivers\mup.sys. md5: 159FAD02F64E6381758C990F753BCC80, sha256: E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 13:59:28.0197 0x0a48 Mup - detected LockedFile.Multi.Generic ( 1 ) 13:59:30.0641 0x0a48 Detect skipped due to KSN trusted 13:59:30.0641 0x0a48 Mup - ok 13:59:30.0683 0x0a48 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent C:\Windows\system32\qagentRT.dll 13:59:30.0733 0x0a48 napagent - ok 13:59:30.0799 0x0a48 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 13:59:30.0799 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\nwifi.sys. md5: 26384429FCD85D83746F63E798AB1480, sha256: 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB 13:59:30.0809 0x0a48 NativeWifiP - detected LockedFile.Multi.Generic ( 1 ) 13:59:33.0194 0x0a48 Detect skipped due to KSN trusted 13:59:33.0194 0x0a48 NativeWifiP - ok 13:59:33.0254 0x0a48 [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS C:\Windows\system32\drivers\ndis.sys 13:59:33.0255 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ndis.sys. md5: 8C9C922D71F1CD4DEF73F186416B7896, sha256: 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 13:59:33.0256 0x0a48 NDIS - detected LockedFile.Multi.Generic ( 1 ) 13:59:35.0784 0x0a48 Detect skipped due to KSN trusted 13:59:35.0784 0x0a48 NDIS - ok 13:59:35.0814 0x0a48 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 13:59:35.0814 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ndiscap.sys. md5: 0E1787AA6C9191D3D319E8BAFE86F80C, sha256: F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 13:59:35.0814 0x0a48 NdisCap - detected LockedFile.Multi.Generic ( 1 ) 13:59:38.0274 0x0a48 Detect skipped due to KSN trusted 13:59:38.0274 0x0a48 NdisCap - ok 13:59:38.0307 0x0a48 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 13:59:38.0307 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ndistapi.sys. md5: E4A8AEC125A2E43A9E32AFEEA7C9C888, sha256: 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 13:59:38.0307 0x0a48 NdisTapi - detected LockedFile.Multi.Generic ( 1 ) 13:59:40.0654 0x0a48 Detect skipped due to KSN trusted 13:59:40.0654 0x0a48 NdisTapi - ok 13:59:40.0688 0x0a48 [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 13:59:40.0688 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ndisuio.sys. md5: D8A65DAFB3EB41CBB622745676FCD072, sha256: 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 13:59:40.0689 0x0a48 Ndisuio - detected LockedFile.Multi.Generic ( 1 ) 13:59:43.0071 0x0a48 Detect skipped due to KSN trusted 13:59:43.0071 0x0a48 Ndisuio - ok 13:59:43.0084 0x0a48 [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 13:59:43.0084 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\ndiswan.sys. md5: 38FBE267E7E6983311179230FACB1017, sha256: CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 13:59:43.0089 0x0a48 NdisWan - detected LockedFile.Multi.Generic ( 1 ) 13:59:45.0944 0x0a48 Detect skipped due to KSN trusted 13:59:45.0944 0x0a48 NdisWan - ok 13:59:45.0969 0x0a48 [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 13:59:45.0970 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\NDProxy.sys. md5: A4BDC541E69674FBFF1A8FF00BE913F2, sha256: 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA 13:59:45.0970 0x0a48 NDProxy - detected LockedFile.Multi.Generic ( 1 ) 13:59:48.0394 0x0a48 Detect skipped due to KSN trusted 13:59:48.0394 0x0a48 NDProxy - ok 13:59:48.0424 0x0a48 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 13:59:48.0424 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\netbios.sys. md5: 80B275B1CE3B0E79909DB7B39AF74D51, sha256: 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 13:59:48.0424 0x0a48 NetBIOS - detected LockedFile.Multi.Generic ( 1 ) 13:59:50.0812 0x0a48 Detect skipped due to KSN trusted 13:59:50.0813 0x0a48 NetBIOS - ok 13:59:50.0836 0x0a48 [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 13:59:50.0836 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\netbt.sys. md5: 280122DDCF04B378EDD1AD54D71C1E54, sha256: F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 13:59:50.0837 0x0a48 NetBT - detected LockedFile.Multi.Generic ( 1 ) 13:59:53.0292 0x0a48 Detect skipped due to KSN trusted 13:59:53.0292 0x0a48 NetBT - ok 13:59:53.0307 0x0a48 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] Netlogon C:\Windows\system32\lsass.exe 13:59:53.0322 0x0a48 Netlogon - ok 13:59:53.0354 0x0a48 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll 13:59:53.0390 0x0a48 Netman - ok 13:59:53.0444 0x0a48 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 13:59:53.0525 0x0a48 NetMsmqActivator - ok 13:59:53.0536 0x0a48 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 13:59:53.0548 0x0a48 NetPipeActivator - ok 13:59:53.0578 0x0a48 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll 13:59:53.0622 0x0a48 netprofm - ok 13:59:53.0644 0x0a48 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 13:59:53.0656 0x0a48 NetTcpActivator - ok 13:59:53.0669 0x0a48 [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe 13:59:53.0681 0x0a48 NetTcpPortSharing - ok 13:59:53.0708 0x0a48 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 13:59:53.0708 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nfrd960.sys. md5: 1D85C4B390B0EE09C7A46B91EFB2C097, sha256: 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 13:59:53.0709 0x0a48 nfrd960 - detected LockedFile.Multi.Generic ( 1 ) 13:59:57.0117 0x0a48 Detect skipped due to KSN trusted 13:59:57.0117 0x0a48 nfrd960 - ok 13:59:57.0163 0x0a48 [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC9F9B3FF45FCA7F5CF242C9E92 ] NlaSvc C:\Windows\System32\nlasvc.dll 13:59:57.0184 0x0a48 NlaSvc - ok 13:59:57.0196 0x0a48 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys 13:59:57.0196 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Npfs.sys. md5: 1DB262A9F8C087E8153D89BEF3D2235F, sha256: A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 13:59:57.0196 0x0a48 Npfs - detected LockedFile.Multi.Generic ( 1 ) 13:59:59.0654 0x0a48 Detect skipped due to KSN trusted 13:59:59.0654 0x0a48 Npfs - ok 13:59:59.0686 0x0a48 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll 13:59:59.0728 0x0a48 nsi - ok 13:59:59.0751 0x0a48 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 13:59:59.0751 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nsiproxy.sys. md5: E9A0A4D07E53D8FEA2BB8387A3293C58, sha256: 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A 13:59:59.0752 0x0a48 nsiproxy - detected LockedFile.Multi.Generic ( 1 ) 14:00:02.0100 0x0a48 Detect skipped due to KSN trusted 14:00:02.0100 0x0a48 nsiproxy - ok 14:00:02.0459 0x0a48 [ 5E43D2B0EE64123D4880DFA6626DEFDE, 164413A22DE58B19EA2B4120034B46D6BE1F424B80C3421E10BE5C81153D049F ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 14:00:02.0460 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Ntfs.sys. md5: 5E43D2B0EE64123D4880DFA6626DEFDE, sha256: 164413A22DE58B19EA2B4120034B46D6BE1F424B80C3421E10BE5C81153D049F 14:00:02.0462 0x0a48 Ntfs - detected LockedFile.Multi.Generic ( 1 ) 14:00:05.0298 0x0a48 Detect skipped due to KSN trusted 14:00:05.0299 0x0a48 Ntfs - ok 14:00:05.0319 0x0a48 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys 14:00:05.0320 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Null.sys. md5: F9756A98D69098DCA8945D62858A812C, sha256: 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 14:00:05.0320 0x0a48 Null - detected LockedFile.Multi.Generic ( 1 ) 14:00:08.0833 0x0a48 Detect skipped due to KSN trusted 14:00:08.0833 0x0a48 Null - ok 14:00:08.0873 0x0a48 [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid C:\Windows\system32\drivers\nvraid.sys 14:00:08.0873 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nvraid.sys. md5: B3E25EE28883877076E0E1FF877D02E0, sha256: 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C 14:00:08.0873 0x0a48 nvraid - detected LockedFile.Multi.Generic ( 1 ) 14:00:11.0343 0x0a48 Detect skipped due to KSN trusted 14:00:11.0343 0x0a48 nvraid - ok 14:00:11.0383 0x0a48 [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor C:\Windows\system32\drivers\nvstor.sys 14:00:11.0383 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nvstor.sys. md5: 4380E59A170D88C4F1022EFF6719A8A4, sha256: 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 14:00:11.0383 0x0a48 nvstor - detected LockedFile.Multi.Generic ( 1 ) 14:00:15.0213 0x0a48 Detect skipped due to KSN trusted 14:00:15.0213 0x0a48 nvstor - ok 14:00:15.0233 0x0a48 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 14:00:15.0233 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\nv_agp.sys. md5: 5A0983915F02BAE73267CC2A041F717D, sha256: D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 14:00:15.0233 0x0a48 nv_agp - detected LockedFile.Multi.Generic ( 1 ) 14:00:17.0583 0x0a48 Detect skipped due to KSN trusted 14:00:17.0583 0x0a48 nv_agp - ok 14:00:17.0603 0x0a48 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys 14:00:17.0603 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ohci1394.sys. md5: 08A70A1F2CDDE9BB49B885CB817A66EB, sha256: 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 14:00:17.0603 0x0a48 ohci1394 - detected LockedFile.Multi.Generic ( 1 ) 14:00:20.0043 0x0a48 Detect skipped due to KSN trusted 14:00:20.0043 0x0a48 ohci1394 - ok 14:00:20.0123 0x0a48 [ 7A56CF3E3F12E8AF599963B16F50FB6A, 882C82BAE96D263138D4C0D6C425458B770B7B9C8E9C1D28AC918BF6BE94A5C2 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 14:00:20.0133 0x0a48 ose - ok 14:00:20.0163 0x0a48 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 14:00:20.0203 0x0a48 p2pimsvc - ok 14:00:20.0233 0x0a48 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll 14:00:20.0263 0x0a48 p2psvc - ok 14:00:20.0303 0x0a48 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\drivers\parport.sys 14:00:20.0303 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\parport.sys. md5: 2EA877ED5DD9713C5AC74E8EA7348D14, sha256: 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE 14:00:20.0303 0x0a48 Parport - detected LockedFile.Multi.Generic ( 1 ) 14:00:26.0003 0x0a48 Detect skipped due to KSN trusted 14:00:26.0003 0x0a48 Parport - ok 14:00:26.0033 0x0a48 [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\Windows\system32\drivers\partmgr.sys 14:00:26.0033 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\partmgr.sys. md5: 3F34A1B4C5F6475F320C275E63AFCE9B, sha256: 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B 14:00:26.0033 0x0a48 partmgr - detected LockedFile.Multi.Generic ( 1 ) 14:00:28.0423 0x0a48 Detect skipped due to KSN trusted 14:00:28.0423 0x0a48 partmgr - ok 14:00:28.0443 0x0a48 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\drivers\parvdm.sys 14:00:28.0443 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\parvdm.sys. md5: EB0A59F29C19B86479D36B35983DAADC, sha256: AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 14:00:28.0443 0x0a48 Parvdm - detected LockedFile.Multi.Generic ( 1 ) 14:00:31.0533 0x0a48 Detect skipped due to KSN trusted 14:00:31.0533 0x0a48 Parvdm - ok 14:00:31.0563 0x0a48 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll 14:00:31.0603 0x0a48 PcaSvc - ok 14:00:31.0623 0x0a48 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys 14:00:31.0623 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pci.sys. md5: 673E55C3498EB970088E812EA820AA8F, sha256: 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 14:00:31.0623 0x0a48 pci - detected LockedFile.Multi.Generic ( 1 ) 14:00:33.0983 0x0a48 Detect skipped due to KSN trusted 14:00:33.0983 0x0a48 pci - ok 14:00:34.0013 0x0a48 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys 14:00:34.0013 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pciide.sys. md5: AFE86F419014DB4E5593F69FFE26CE0A, sha256: CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 14:00:34.0013 0x0a48 pciide - detected LockedFile.Multi.Generic ( 1 ) 14:00:36.0403 0x0a48 Detect skipped due to KSN trusted 14:00:36.0403 0x0a48 pciide - ok 14:00:36.0433 0x0a48 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 14:00:36.0433 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pcmcia.sys. md5: F396431B31693E71E8A80687EF523506, sha256: BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B 14:00:36.0433 0x0a48 pcmcia - detected LockedFile.Multi.Generic ( 1 ) 14:00:42.0593 0x0a48 Detect skipped due to KSN trusted 14:00:42.0593 0x0a48 pcmcia - ok 14:00:42.0603 0x0a48 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys 14:00:42.0603 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\pcw.sys. md5: 250F6B43D2B613172035C6747AEEB19F, sha256: A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 14:00:42.0603 0x0a48 pcw - detected LockedFile.Multi.Generic ( 1 ) 14:00:45.0083 0x0a48 Detect skipped due to KSN trusted 14:00:45.0083 0x0a48 pcw - ok 14:00:45.0113 0x0a48 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 14:00:45.0113 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\peauth.sys. md5: 9E0104BA49F4E6973749A02BF41344ED, sha256: B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 14:00:45.0123 0x0a48 PEAUTH - detected LockedFile.Multi.Generic ( 1 ) 14:00:47.0473 0x0a48 Detect skipped due to KSN trusted 14:00:47.0473 0x0a48 PEAUTH - ok 14:00:47.0543 0x0a48 [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll 14:00:47.0643 0x0a48 PeerDistSvc - ok 14:00:47.0703 0x0a48 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll 14:00:47.0793 0x0a48 pla - ok 14:00:47.0863 0x0a48 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll 14:00:47.0923 0x0a48 PlugPlay - ok 14:00:47.0943 0x0a48 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 14:00:47.0983 0x0a48 PNRPAutoReg - ok 14:00:48.0013 0x0a48 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 14:00:48.0033 0x0a48 PNRPsvc - ok 14:00:48.0083 0x0a48 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 14:00:48.0143 0x0a48 PolicyAgent - ok 14:00:48.0173 0x0a48 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll 14:00:48.0223 0x0a48 Power - ok 14:00:48.0273 0x0a48 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 14:00:48.0273 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\raspptp.sys. md5: 631E3E205AD6D86F2AED6A4A8E69F2DB, sha256: 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 14:00:48.0273 0x0a48 PptpMiniport - detected LockedFile.Multi.Generic ( 1 ) 14:00:50.0743 0x0a48 Detect skipped due to KSN trusted 14:00:50.0743 0x0a48 PptpMiniport - ok 14:00:50.0753 0x0a48 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\drivers\processr.sys 14:00:50.0753 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\processr.sys. md5: 85B1E3A0C7585BC4AAE6899EC6FCF011, sha256: 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 14:00:50.0753 0x0a48 Processor - detected LockedFile.Multi.Generic ( 1 ) 14:00:53.0653 0x0a48 Detect skipped due to KSN trusted 14:00:53.0653 0x0a48 Processor - ok 14:00:53.0703 0x0a48 [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] ProfSvc C:\Windows\system32\profsvc.dll 14:00:53.0753 0x0a48 ProfSvc - ok 14:00:53.0773 0x0a48 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] ProtectedStorage C:\Windows\system32\lsass.exe 14:00:53.0793 0x0a48 ProtectedStorage - ok 14:00:53.0813 0x0a48 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys 14:00:53.0813 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\pacer.sys. md5: 6270CCAE2A86DE6D146529FE55B3246A, sha256: 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 14:00:53.0813 0x0a48 Psched - detected LockedFile.Multi.Generic ( 1 ) 14:00:56.0283 0x0a48 Detect skipped due to KSN trusted 14:00:56.0283 0x0a48 Psched - ok 14:00:56.0343 0x0a48 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\drivers\ql2300.sys 14:00:56.0343 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ql2300.sys. md5: AB95ECF1F6659A60DDC166D8315B0751, sha256: 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D 14:00:56.0343 0x0a48 ql2300 - detected LockedFile.Multi.Generic ( 1 ) 14:00:58.0693 0x0a48 Detect skipped due to KSN trusted 14:00:58.0693 0x0a48 ql2300 - ok 14:00:58.0693 0x0a48 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 14:00:58.0693 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ql40xx.sys. md5: B4DD51DD25182244B86737DC51AF2270, sha256: 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B 14:00:58.0693 0x0a48 ql40xx - detected LockedFile.Multi.Generic ( 1 ) 14:01:01.0123 0x0a48 Detect skipped due to KSN trusted 14:01:01.0123 0x0a48 ql40xx - ok 14:01:01.0143 0x0a48 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll 14:01:01.0193 0x0a48 QWAVE - ok 14:01:01.0213 0x0a48 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 14:01:01.0213 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\qwavedrv.sys. md5: 584078CA1B95CA72DF2A27C336F9719D, sha256: 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 14:01:01.0213 0x0a48 QWAVEdrv - detected LockedFile.Multi.Generic ( 1 ) 14:01:05.0033 0x0a48 Detect skipped due to KSN trusted 14:01:05.0033 0x0a48 QWAVEdrv - ok 14:01:05.0063 0x0a48 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 14:01:05.0063 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rasacd.sys. md5: 30A81B53C766D0133BB86D234E5556AB, sha256: 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 14:01:05.0063 0x0a48 RasAcd - detected LockedFile.Multi.Generic ( 1 ) 14:01:07.0443 0x0a48 Detect skipped due to KSN trusted 14:01:07.0443 0x0a48 RasAcd - ok 14:01:07.0473 0x0a48 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 14:01:07.0473 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\AgileVpn.sys. md5: 57EC4AEF73660166074D8F7F31C0D4FD, sha256: C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF 14:01:07.0473 0x0a48 RasAgileVpn - detected LockedFile.Multi.Generic ( 1 ) 14:01:09.0823 0x0a48 Detect skipped due to KSN trusted 14:01:09.0823 0x0a48 RasAgileVpn - ok 14:01:09.0843 0x0a48 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll 14:01:09.0893 0x0a48 RasAuto - ok 14:01:09.0923 0x0a48 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 14:01:09.0923 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rasl2tp.sys. md5: D9F91EAFEC2815365CBE6D167E4E332A, sha256: 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C 14:01:09.0923 0x0a48 Rasl2tp - detected LockedFile.Multi.Generic ( 1 ) 14:01:12.0393 0x0a48 Detect skipped due to KSN trusted 14:01:12.0393 0x0a48 Rasl2tp - ok 14:01:12.0443 0x0a48 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll 14:01:12.0573 0x0a48 RasMan - ok 14:01:12.0613 0x0a48 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 14:01:12.0613 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\raspppoe.sys. md5: 0FE8B15916307A6AC12BFB6A63E45507, sha256: 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E 14:01:12.0613 0x0a48 RasPppoe - detected LockedFile.Multi.Generic ( 1 ) 14:01:15.0003 0x0a48 Detect skipped due to KSN trusted 14:01:15.0003 0x0a48 RasPppoe - ok 14:01:15.0023 0x0a48 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 14:01:15.0023 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rassstp.sys. md5: 44101F495A83EA6401D886E7FD70096B, sha256: 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A 14:01:15.0023 0x0a48 RasSstp - detected LockedFile.Multi.Generic ( 1 ) 14:01:18.0427 0x0a48 Detect skipped due to KSN trusted 14:01:18.0427 0x0a48 RasSstp - ok 14:01:18.0437 0x0a48 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 14:01:18.0437 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rdbss.sys. md5: D528BC58A489409BA40334EBF96A311B, sha256: C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 14:01:18.0437 0x0a48 rdbss - detected LockedFile.Multi.Generic ( 1 ) 14:01:24.0107 0x0a48 Detect skipped due to KSN trusted 14:01:24.0107 0x0a48 rdbss - ok 14:01:24.0127 0x0a48 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys 14:01:24.0127 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rdpbus.sys. md5: 0D8F05481CB76E70E1DA06EE9F0DA9DF, sha256: 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB 14:01:24.0127 0x0a48 rdpbus - detected LockedFile.Multi.Generic ( 1 ) 14:01:26.0669 0x0a48 Detect skipped due to KSN trusted 14:01:26.0669 0x0a48 rdpbus - ok 14:01:26.0679 0x0a48 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 14:01:26.0679 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\RDPCDD.sys. md5: 23DAE03F29D253AE74C44F99E515F9A1, sha256: 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 14:01:26.0679 0x0a48 RDPCDD - detected LockedFile.Multi.Generic ( 1 ) 14:01:29.0041 0x0a48 Detect skipped due to KSN trusted 14:01:29.0041 0x0a48 RDPCDD - ok 14:01:29.0071 0x0a48 [ B973FCFC50DC1434E1970A146F7E3885, BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 14:01:29.0071 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdpdr.sys. md5: B973FCFC50DC1434E1970A146F7E3885, sha256: BE797E5F5AE34D37F8DA1134CE94DD14DBE36D2BC405B97E992E2257848B7CA9 14:01:29.0071 0x0a48 RDPDR - detected LockedFile.Multi.Generic ( 1 ) 14:01:31.0461 0x0a48 Detect skipped due to KSN trusted 14:01:31.0461 0x0a48 RDPDR - ok 14:01:31.0491 0x0a48 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 14:01:31.0491 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdpencdd.sys. md5: 5A53CA1598DD4156D44196D200C94B8A, sha256: 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 14:01:31.0491 0x0a48 RDPENCDD - detected LockedFile.Multi.Generic ( 1 ) 14:01:33.0882 0x0a48 Detect skipped due to KSN trusted 14:01:33.0882 0x0a48 RDPENCDD - ok 14:01:33.0912 0x0a48 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys 14:01:33.0912 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdprefmp.sys. md5: 44B0A53CD4F27D50ED461DAE0C0B4E1F, sha256: CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 14:01:33.0912 0x0a48 RDPREFMP - detected LockedFile.Multi.Generic ( 1 ) 14:01:36.0354 0x0a48 Detect skipped due to KSN trusted 14:01:36.0354 0x0a48 RDPREFMP - ok 14:01:36.0374 0x0a48 [ F031683E6D1FEA157ABB2FF260B51E61, 83B552819A5964152882C527E1421DBCEAACC74DEB897E3C4B53F52F1467FED3 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 14:01:36.0374 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\RDPWD.sys. md5: F031683E6D1FEA157ABB2FF260B51E61, sha256: 83B552819A5964152882C527E1421DBCEAACC74DEB897E3C4B53F52F1467FED3 14:01:36.0374 0x0a48 RDPWD - detected LockedFile.Multi.Generic ( 1 ) 14:01:43.0164 0x0a48 Detect skipped due to KSN trusted 14:01:43.0164 0x0a48 RDPWD - ok 14:01:43.0184 0x0a48 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 14:01:43.0184 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\rdyboost.sys. md5: 518395321DC96FE2C9F0E96AC743B656, sha256: 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 14:01:43.0204 0x0a48 rdyboost - detected LockedFile.Multi.Generic ( 1 ) 14:01:45.0664 0x0a48 Detect skipped due to KSN trusted 14:01:45.0664 0x0a48 rdyboost - ok 14:01:45.0704 0x0a48 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll 14:01:45.0734 0x0a48 RemoteAccess - ok 14:01:45.0754 0x0a48 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll 14:01:45.0784 0x0a48 RemoteRegistry - ok 14:01:45.0794 0x0a48 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 14:01:45.0834 0x0a48 RpcEptMapper - ok 14:01:45.0864 0x0a48 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe 14:01:45.0894 0x0a48 RpcLocator - ok 14:01:45.0924 0x0a48 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll 14:01:45.0964 0x0a48 RpcSs - ok 14:01:46.0004 0x0a48 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 14:01:46.0004 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\rspndr.sys. md5: 032B0D36AD92B582D869879F5AF5B928, sha256: 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 14:01:46.0004 0x0a48 rspndr - detected LockedFile.Multi.Generic ( 1 ) 14:01:48.0344 0x0a48 Detect skipped due to KSN trusted 14:01:48.0344 0x0a48 rspndr - ok 14:01:48.0354 0x0a48 [ 7FA7F2E249A5DCBB7970630E15E1F482, 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF ] s3cap C:\Windows\system32\drivers\vms3cap.sys 14:01:48.0354 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vms3cap.sys. md5: 7FA7F2E249A5DCBB7970630E15E1F482, sha256: 9633B193F3FDA67BC551C6DCA4788AB83E9F45F77763EE579D02FE5D6B80DEDF 14:01:48.0354 0x0a48 s3cap - detected LockedFile.Multi.Generic ( 1 ) 14:01:51.0306 0x0a48 Detect skipped due to KSN trusted 14:01:51.0306 0x0a48 s3cap - ok 14:01:51.0316 0x0a48 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] SamSs C:\Windows\system32\lsass.exe 14:01:51.0326 0x0a48 SamSs - ok 14:01:51.0356 0x0a48 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 14:01:51.0356 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sbp2port.sys. md5: 05D860DA1040F111503AC416CCEF2BCA, sha256: DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E 14:01:51.0356 0x0a48 sbp2port - detected LockedFile.Multi.Generic ( 1 ) 14:01:53.0706 0x0a48 Detect skipped due to KSN trusted 14:01:53.0706 0x0a48 sbp2port - ok 14:01:53.0736 0x0a48 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll 14:01:53.0786 0x0a48 SCardSvr - ok 14:01:53.0806 0x0a48 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 14:01:53.0806 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\scfilter.sys. md5: 0693B5EC673E34DC147E195779A4DCF6, sha256: AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 14:01:53.0806 0x0a48 scfilter - detected LockedFile.Multi.Generic ( 1 ) 14:01:56.0276 0x0a48 Detect skipped due to KSN trusted 14:01:56.0276 0x0a48 scfilter - ok 14:01:56.0336 0x0a48 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll 14:01:56.0396 0x0a48 Schedule - ok 14:01:56.0416 0x0a48 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll 14:01:56.0436 0x0a48 SCPolicySvc - ok 14:01:56.0446 0x0a48 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll 14:01:56.0496 0x0a48 SDRSVC - ok 14:01:56.0526 0x0a48 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys 14:01:56.0526 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\secdrv.sys. md5: 90A3935D05B494A5A39D37E71F09A677, sha256: F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 14:01:56.0526 0x0a48 secdrv - detected LockedFile.Multi.Generic ( 1 ) 14:02:02.0586 0x0a48 Detect skipped due to KSN trusted 14:02:02.0586 0x0a48 secdrv - ok 14:02:02.0596 0x0a48 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll 14:02:02.0646 0x0a48 seclogon - ok 14:02:02.0666 0x0a48 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll 14:02:02.0706 0x0a48 SENS - ok 14:02:02.0736 0x0a48 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll 14:02:02.0786 0x0a48 SensrSvc - ok 14:02:02.0826 0x0a48 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 14:02:02.0826 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\serenum.sys. md5: 9AD8B8B515E3DF6ACD4212EF465DE2D1, sha256: E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 14:02:02.0826 0x0a48 Serenum - detected LockedFile.Multi.Generic ( 1 ) 14:02:08.0726 0x0a48 Detect skipped due to KSN trusted 14:02:08.0726 0x0a48 Serenum - ok 14:02:08.0756 0x0a48 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys 14:02:08.0756 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\serial.sys. md5: 5FB7FCEA0490D821F26F39CC5EA3D1E2, sha256: A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F 14:02:08.0766 0x0a48 Serial - detected LockedFile.Multi.Generic ( 1 ) 14:02:11.0226 0x0a48 Detect skipped due to KSN trusted 14:02:11.0226 0x0a48 Serial - ok 14:02:11.0246 0x0a48 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\drivers\sermouse.sys 14:02:11.0246 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sermouse.sys. md5: 79BFFB520327FF916A582DFEA17AA813, sha256: 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C 14:02:11.0246 0x0a48 sermouse - detected LockedFile.Multi.Generic ( 1 ) 14:02:18.0466 0x0a48 Detect skipped due to KSN trusted 14:02:18.0466 0x0a48 sermouse - ok 14:02:18.0496 0x0a48 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll 14:02:18.0546 0x0a48 SessionEnv - ok 14:02:18.0576 0x0a48 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 14:02:18.0576 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffdisk.sys. md5: 9F976E1EB233DF46FCE808D9DEA3EB9C, sha256: 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 14:02:18.0576 0x0a48 sffdisk - detected LockedFile.Multi.Generic ( 1 ) 14:02:20.0926 0x0a48 Detect skipped due to KSN trusted 14:02:20.0926 0x0a48 sffdisk - ok 14:02:20.0926 0x0a48 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 14:02:20.0926 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffp_mmc.sys. md5: 932A68EE27833CFD57C1639D375F2731, sha256: 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 14:02:20.0926 0x0a48 sffp_mmc - detected LockedFile.Multi.Generic ( 1 ) 14:02:23.0316 0x0a48 Detect skipped due to KSN trusted 14:02:23.0316 0x0a48 sffp_mmc - ok 14:02:23.0316 0x0a48 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 14:02:23.0316 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sffp_sd.sys. md5: 6D4CCAEDC018F1CF52866BBBAA235982, sha256: AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 14:02:23.0326 0x0a48 sffp_sd - detected LockedFile.Multi.Generic ( 1 ) 14:02:25.0706 0x0a48 Detect skipped due to KSN trusted 14:02:25.0706 0x0a48 sffp_sd - ok 14:02:25.0706 0x0a48 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 14:02:25.0706 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sfloppy.sys. md5: DB96666CC8312EBC45032F30B007A547, sha256: C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 14:02:25.0706 0x0a48 sfloppy - detected LockedFile.Multi.Generic ( 1 ) 14:02:28.0056 0x0a48 Detect skipped due to KSN trusted 14:02:28.0056 0x0a48 sfloppy - ok 14:02:28.0086 0x0a48 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll 14:02:28.0136 0x0a48 SharedAccess - ok 14:02:28.0186 0x0a48 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 14:02:28.0236 0x0a48 ShellHWDetection - ok 14:02:28.0266 0x0a48 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys 14:02:28.0266 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sisagp.sys. md5: 2565CAC0DC9FE0371BDCE60832582B2E, sha256: 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D 14:02:28.0266 0x0a48 sisagp - detected LockedFile.Multi.Generic ( 1 ) 14:02:31.0136 0x0a48 Detect skipped due to KSN trusted 14:02:31.0136 0x0a48 sisagp - ok 14:02:31.0146 0x0a48 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 14:02:31.0146 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\SiSRaid2.sys. md5: A9F0486851BECB6DDA1D89D381E71055, sha256: 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 14:02:31.0156 0x0a48 SiSRaid2 - detected LockedFile.Multi.Generic ( 1 ) 14:02:34.0976 0x0a48 Detect skipped due to KSN trusted 14:02:34.0976 0x0a48 SiSRaid2 - ok 14:02:35.0116 0x0a48 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 14:02:35.0116 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\sisraid4.sys. md5: 3727097B55738E2F554972C3BE5BC1AA, sha256: 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 14:02:35.0116 0x0a48 SiSRaid4 - detected LockedFile.Multi.Generic ( 1 ) 14:02:40.0866 0x0a48 Detect skipped due to KSN trusted 14:02:40.0866 0x0a48 SiSRaid4 - ok 14:02:40.0896 0x0a48 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys 14:02:40.0896 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\smb.sys. md5: 3E21C083B8A01CB70BA1F09303010FCE, sha256: 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 14:02:40.0896 0x0a48 Smb - detected LockedFile.Multi.Generic ( 1 ) 14:02:43.0366 0x0a48 Detect skipped due to KSN trusted 14:02:43.0366 0x0a48 Smb - ok 14:02:43.0396 0x0a48 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 14:02:43.0406 0x0a48 SNMPTRAP - ok 14:02:43.0416 0x0a48 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys 14:02:43.0426 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\spldr.sys. md5: 95CF1AE7527FB70F7816563CBC09D942, sha256: CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 14:02:43.0426 0x0a48 spldr - detected LockedFile.Multi.Generic ( 1 ) 14:02:49.0146 0x0a48 Detect skipped due to KSN trusted 14:02:49.0146 0x0a48 spldr - ok 14:02:49.0216 0x0a48 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\Windows\System32\spoolsv.exe 14:02:49.0276 0x0a48 Spooler - ok 14:02:49.0406 0x0a48 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe 14:02:49.0496 0x0a48 sppsvc - ok 14:02:49.0526 0x0a48 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll 14:02:49.0566 0x0a48 sppuinotify - ok 14:02:49.0606 0x0a48 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\Windows\system32\DRIVERS\srv.sys 14:02:49.0606 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\srv.sys. md5: E4C2764065D66EA1D2D3EBC28FE99C46, sha256: 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 14:02:49.0616 0x0a48 srv - detected LockedFile.Multi.Generic ( 1 ) 14:02:52.0036 0x0a48 Detect skipped due to KSN trusted 14:02:52.0036 0x0a48 srv - ok 14:02:52.0066 0x0a48 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 14:02:52.0066 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\srv2.sys. md5: 03F0545BD8D4C77FA0AE1CEEDFCC71AB, sha256: 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 14:02:52.0066 0x0a48 srv2 - detected LockedFile.Multi.Generic ( 1 ) 14:02:54.0736 0x0a48 Detect skipped due to KSN trusted 14:02:54.0736 0x0a48 srv2 - ok 14:02:54.0766 0x0a48 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 14:02:54.0766 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\srvnet.sys. md5: BE6BD660CAA6F291AE06A718A4FA8ABC, sha256: CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 14:02:54.0766 0x0a48 srvnet - detected LockedFile.Multi.Generic ( 1 ) 14:02:57.0226 0x0a48 Detect skipped due to KSN trusted 14:02:57.0226 0x0a48 srvnet - ok 14:02:57.0256 0x0a48 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 14:02:57.0296 0x0a48 SSDPSRV - ok 14:02:57.0306 0x0a48 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll 14:02:57.0356 0x0a48 SstpSvc - ok 14:02:57.0396 0x0a48 Steam Client Service - ok 14:02:57.0426 0x0a48 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\drivers\stexstor.sys 14:02:57.0426 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\stexstor.sys. md5: DB32D325C192B801DF274BFD12A7E72B, sha256: F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA 14:02:57.0426 0x0a48 stexstor - detected LockedFile.Multi.Generic ( 1 ) 14:03:03.0176 0x0a48 Detect skipped due to KSN trusted 14:03:03.0176 0x0a48 stexstor - ok 14:03:03.0216 0x0a48 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll 14:03:03.0286 0x0a48 StiSvc - ok 14:03:03.0316 0x0a48 [ 472AF0311073DCECEAA8FA18BA2BDF89, 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC ] storflt C:\Windows\system32\drivers\vmstorfl.sys 14:03:03.0316 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vmstorfl.sys. md5: 472AF0311073DCECEAA8FA18BA2BDF89, sha256: 089414057EB2047E42C96C1ACE79D509967461DC5A4D2836F63C04268637A3FC 14:03:03.0326 0x0a48 storflt - detected LockedFile.Multi.Generic ( 1 ) 14:03:05.0676 0x0a48 Detect skipped due to KSN trusted 14:03:05.0676 0x0a48 storflt - ok 14:03:05.0706 0x0a48 [ 0BF669F0A910BEDA4A32258D363AF2A5, 83EEBACDE4F69A2866B69CAA633F5C8B3CB01D88CEDB01B6EA5988E0A25CEE47 ] StorSvc C:\Windows\system32\storsvc.dll 14:03:05.0726 0x0a48 StorSvc - ok 14:03:05.0756 0x0a48 [ DCAFFD62259E0BDB433DD67B5BB37619, CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 ] storvsc C:\Windows\system32\drivers\storvsc.sys 14:03:05.0756 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\storvsc.sys. md5: DCAFFD62259E0BDB433DD67B5BB37619, sha256: CBD12FF9BBF33D18B0F3D322B12EC62E7DF3BF45C6AD43D2E91FF4C4762E05D0 14:03:05.0756 0x0a48 storvsc - detected LockedFile.Multi.Generic ( 1 ) 14:03:08.0156 0x0a48 Detect skipped due to KSN trusted 14:03:08.0156 0x0a48 storvsc - ok 14:03:08.0176 0x0a48 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\DRIVERS\swenum.sys 14:03:08.0176 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\swenum.sys. md5: E58C78A848ADD9610A4DB6D214AF5224, sha256: 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 14:03:08.0176 0x0a48 swenum - detected LockedFile.Multi.Generic ( 1 ) 14:03:10.0546 0x0a48 Detect skipped due to KSN trusted 14:03:10.0546 0x0a48 swenum - ok 14:03:10.0576 0x0a48 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll 14:03:10.0626 0x0a48 swprv - ok 14:03:10.0676 0x0a48 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll 14:03:10.0716 0x0a48 SysMain - ok 14:03:10.0736 0x0a48 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll 14:03:10.0766 0x0a48 TabletInputService - ok 14:03:10.0786 0x0a48 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll 14:03:10.0816 0x0a48 TapiSrv - ok 14:03:10.0836 0x0a48 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll 14:03:10.0886 0x0a48 TBS - ok 14:03:10.0956 0x0a48 [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] Tcpip C:\Windows\system32\drivers\tcpip.sys 14:03:10.0956 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tcpip.sys. md5: CA59F7C570AF70BC174F477CFE2D9EE3, sha256: F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD 14:03:10.0986 0x0a48 Tcpip - detected LockedFile.Multi.Generic ( 1 ) 14:03:16.0918 0x0a48 Detect skipped due to KSN trusted 14:03:16.0918 0x0a48 Tcpip - ok 14:03:16.0978 0x0a48 [ CA59F7C570AF70BC174F477CFE2D9EE3, F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 14:03:16.0978 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tcpip.sys. md5: CA59F7C570AF70BC174F477CFE2D9EE3, sha256: F09E4E14207A2AC6957D2C0AC8707D0E356A9087FA6DC703373242D8EEB026BD 14:03:16.0978 0x0a48 TCPIP6 - detected LockedFile.Multi.Generic ( 1 ) 14:03:16.0978 0x0a48 Detect skipped due to KSN trusted 14:03:16.0978 0x0a48 TCPIP6 - ok 14:03:17.0018 0x0a48 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 14:03:17.0018 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tcpipreg.sys. md5: 3EEBD3BD93DA46A26E89893C7AB2FF3B, sha256: 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E 14:03:17.0018 0x0a48 tcpipreg - detected LockedFile.Multi.Generic ( 1 ) 14:03:19.0718 0x0a48 Detect skipped due to KSN trusted 14:03:19.0718 0x0a48 tcpipreg - ok 14:03:19.0738 0x0a48 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 14:03:19.0738 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tdpipe.sys. md5: 1CB91B2BD8F6DD367DFC2EF26FD751B2, sha256: 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 14:03:19.0738 0x0a48 TDPIPE - detected LockedFile.Multi.Generic ( 1 ) 14:03:22.0208 0x0a48 Detect skipped due to KSN trusted 14:03:22.0208 0x0a48 TDPIPE - ok 14:03:22.0258 0x0a48 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 14:03:22.0258 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tdtcp.sys. md5: 2C2C5AFE7EE4F620D69C23C0617651A8, sha256: E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 14:03:22.0258 0x0a48 TDTCP - detected LockedFile.Multi.Generic ( 1 ) 14:03:24.0610 0x0a48 Detect skipped due to KSN trusted 14:03:24.0610 0x0a48 TDTCP - ok 14:03:24.0640 0x0a48 [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 14:03:24.0640 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tdx.sys. md5: B459575348C20E8121D6039DA063C704, sha256: 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 14:03:24.0640 0x0a48 tdx - detected LockedFile.Multi.Generic ( 1 ) 14:03:27.0600 0x0a48 Detect skipped due to KSN trusted 14:03:27.0600 0x0a48 tdx - ok 14:03:27.0620 0x0a48 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 14:03:27.0620 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\termdd.sys. md5: 04DBF4B01EA4BF25A9A3E84AFFAC9B20, sha256: 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 14:03:27.0630 0x0a48 TermDD - detected LockedFile.Multi.Generic ( 1 ) 14:03:30.0050 0x0a48 Detect skipped due to KSN trusted 14:03:30.0050 0x0a48 TermDD - ok 14:03:30.0090 0x0a48 [ 382C804C92811BE57829D8E550A900E2, 5F52C2E7902024CF1C9CC0069F411C3F19CCA3DB209F437FA0F3932D4898EB50 ] TermService C:\Windows\System32\termsrv.dll 14:03:30.0130 0x0a48 TermService - ok 14:03:30.0150 0x0a48 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll 14:03:30.0180 0x0a48 Themes - ok 14:03:30.0200 0x0a48 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll 14:03:30.0220 0x0a48 THREADORDER - ok 14:03:30.0250 0x0a48 [ 5AD05191DC8B444A7BA4D79B76C42A30, 6166E939A5A240388EBA5AF7FF335DC413F2BBCF74C2E1D310F4BE2A5454A610 ] TPM C:\Windows\system32\drivers\tpm.sys 14:03:30.0250 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tpm.sys. md5: 5AD05191DC8B444A7BA4D79B76C42A30, sha256: 6166E939A5A240388EBA5AF7FF335DC413F2BBCF74C2E1D310F4BE2A5454A610 14:03:30.0250 0x0a48 TPM - detected LockedFile.Multi.Generic ( 1 ) 14:03:35.0900 0x0a48 Detect skipped due to KSN trusted 14:03:35.0900 0x0a48 TPM - ok 14:03:35.0990 0x0a48 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll 14:03:36.0040 0x0a48 TrkWks - ok 14:03:36.0210 0x0a48 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 14:03:36.0270 0x0a48 TrustedInstaller - ok 14:03:36.0300 0x0a48 [ B37B08F2E5EEB1A37E448E09BACE1101, 32CC9E06B88BAB6FAB4696B744548DFCE9199A7FD2BA8B019F269CA75895852C ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 14:03:36.0300 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tssecsrv.sys. md5: B37B08F2E5EEB1A37E448E09BACE1101, sha256: 32CC9E06B88BAB6FAB4696B744548DFCE9199A7FD2BA8B019F269CA75895852C 14:03:36.0300 0x0a48 tssecsrv - detected LockedFile.Multi.Generic ( 1 ) 14:03:38.0690 0x0a48 Detect skipped due to KSN trusted 14:03:38.0690 0x0a48 tssecsrv - ok 14:03:38.0700 0x0a48 [ FD1D6C73E6333BE727CBCC6054247654, 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 14:03:38.0700 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\tsusbflt.sys. md5: FD1D6C73E6333BE727CBCC6054247654, sha256: 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E 14:03:38.0700 0x0a48 TsUsbFlt - detected LockedFile.Multi.Generic ( 1 ) 14:03:41.0160 0x0a48 Detect skipped due to KSN trusted 14:03:41.0170 0x0a48 TsUsbFlt - ok 14:03:41.0190 0x0a48 [ 01246F0BAAD7B68EC0F472AA41E33282, 51F975AF029AD015576FFFA3E88F5DBB8B40C7CD30ECDEDE8AFABCB08C954199 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys 14:03:41.0190 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\TsUsbGD.sys. md5: 01246F0BAAD7B68EC0F472AA41E33282, sha256: 51F975AF029AD015576FFFA3E88F5DBB8B40C7CD30ECDEDE8AFABCB08C954199 14:03:41.0190 0x0a48 TsUsbGD - detected LockedFile.Multi.Generic ( 1 ) 14:03:45.0030 0x0a48 Detect skipped due to KSN trusted 14:03:45.0030 0x0a48 TsUsbGD - ok 14:03:45.0050 0x0a48 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 14:03:45.0050 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\tunnel.sys. md5: B2FA25D9B17A68BB93D58B0556E8C90D, sha256: 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE 14:03:45.0050 0x0a48 tunnel - detected LockedFile.Multi.Generic ( 1 ) 14:03:48.0890 0x0a48 Detect skipped due to KSN trusted 14:03:48.0890 0x0a48 tunnel - ok 14:03:48.0920 0x0a48 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 14:03:48.0920 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\uagp35.sys. md5: 750FBCB269F4D7DD2E420C56B795DB6D, sha256: E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 14:03:48.0920 0x0a48 uagp35 - detected LockedFile.Multi.Generic ( 1 ) 14:03:51.0382 0x0a48 Detect skipped due to KSN trusted 14:03:51.0382 0x0a48 uagp35 - ok 14:03:51.0402 0x0a48 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 14:03:51.0402 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\udfs.sys. md5: EE43346C7E4B5E63E54F927BABBB32FF, sha256: BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 14:03:51.0402 0x0a48 udfs - detected LockedFile.Multi.Generic ( 1 ) 14:03:57.0062 0x0a48 Detect skipped due to KSN trusted 14:03:57.0062 0x0a48 udfs - ok 14:03:57.0092 0x0a48 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe 14:03:57.0122 0x0a48 UI0Detect - ok 14:03:57.0152 0x0a48 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 14:03:57.0162 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\uliagpkx.sys. md5: 44E8048ACE47BEFBFDC2E9BE4CBC8880, sha256: 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C 14:03:57.0162 0x0a48 uliagpkx - detected LockedFile.Multi.Generic ( 1 ) 14:03:59.0582 0x0a48 Detect skipped due to KSN trusted 14:03:59.0582 0x0a48 uliagpkx - ok 14:03:59.0612 0x0a48 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 14:03:59.0612 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\umbus.sys. md5: D295BED4B898F0FD999FCFA9B32B071B, sha256: D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 14:03:59.0612 0x0a48 umbus - detected LockedFile.Multi.Generic ( 1 ) 14:04:02.0022 0x0a48 Detect skipped due to KSN trusted 14:04:02.0022 0x0a48 umbus - ok 14:04:02.0042 0x0a48 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\drivers\umpass.sys 14:04:02.0042 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\umpass.sys. md5: 7550AD0C6998BA1CB4843E920EE0FEAC, sha256: 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D 14:04:02.0052 0x0a48 UmPass - detected LockedFile.Multi.Generic ( 1 ) 14:04:04.0532 0x0a48 Detect skipped due to KSN trusted 14:04:04.0532 0x0a48 UmPass - ok 14:04:04.0552 0x0a48 [ 409994A8EACEEE4E328749C0353527A0, FFC57B647147DE2957A7DE4B330CC534DE7AC892A2FCE3BB164F7A516CAB1B56 ] UmRdpService C:\Windows\System32\umrdp.dll 14:04:04.0612 0x0a48 UmRdpService - ok 14:04:04.0652 0x0a48 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll 14:04:04.0692 0x0a48 upnphost - ok 14:04:04.0732 0x0a48 [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 14:04:04.0732 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbccgp.sys. md5: 0803FBA9FE829D61AE26EC0BCC910C46, sha256: 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B 14:04:04.0732 0x0a48 usbccgp - detected LockedFile.Multi.Generic ( 1 ) 14:04:07.0112 0x0a48 Detect skipped due to KSN trusted 14:04:07.0112 0x0a48 usbccgp - ok 14:04:07.0162 0x0a48 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys 14:04:07.0162 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\usbcir.sys. md5: 2352AB5F9F8F097BF9D41D5A4718A041, sha256: 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C 14:04:07.0162 0x0a48 usbcir - detected LockedFile.Multi.Generic ( 1 ) 14:04:09.0602 0x0a48 Detect skipped due to KSN trusted 14:04:09.0602 0x0a48 usbcir - ok 14:04:09.0622 0x0a48 [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 14:04:09.0622 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbehci.sys. md5: D40855F89B69305140BBD7E9A3BA2DA6, sha256: 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C 14:04:09.0622 0x0a48 usbehci - detected LockedFile.Multi.Generic ( 1 ) 14:04:13.0452 0x0a48 Detect skipped due to KSN trusted 14:04:13.0452 0x0a48 usbehci - ok 14:04:13.0502 0x0a48 [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 14:04:13.0502 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbhub.sys. md5: EDF2DF71C4F1E13A6AC75F5224DE655A, sha256: 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C 14:04:13.0502 0x0a48 usbhub - detected LockedFile.Multi.Generic ( 1 ) 14:04:16.0042 0x0a48 Detect skipped due to KSN trusted 14:04:16.0042 0x0a48 usbhub - ok 14:04:16.0062 0x0a48 [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci C:\Windows\system32\drivers\usbohci.sys 14:04:16.0062 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\usbohci.sys. md5: 9828C8D14CC2676421778F0DE638CF97, sha256: 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 14:04:16.0062 0x0a48 usbohci - detected LockedFile.Multi.Generic ( 1 ) 14:04:18.0442 0x0a48 Detect skipped due to KSN trusted 14:04:18.0442 0x0a48 usbohci - ok 14:04:18.0482 0x0a48 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 14:04:18.0482 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbprint.sys. md5: 797D862FE0875E75C7CC4C1AD7B30252, sha256: 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 14:04:18.0482 0x0a48 usbprint - detected LockedFile.Multi.Generic ( 1 ) 14:04:20.0922 0x0a48 Detect skipped due to KSN trusted 14:04:20.0922 0x0a48 usbprint - ok 14:04:20.0942 0x0a48 [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 14:04:20.0942 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\USBSTOR.SYS. md5: F991AB9CC6B908DB552166768176896A, sha256: AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 14:04:20.0952 0x0a48 USBSTOR - detected LockedFile.Multi.Generic ( 1 ) 14:04:23.0302 0x0a48 Detect skipped due to KSN trusted 14:04:23.0302 0x0a48 USBSTOR - ok 14:04:23.0322 0x0a48 [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 14:04:23.0322 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\usbuhci.sys. md5: 800AABFD625EEFF899F7E5496BDE37AB, sha256: 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 14:04:23.0322 0x0a48 usbuhci - detected LockedFile.Multi.Generic ( 1 ) 14:04:25.0704 0x0a48 Detect skipped due to KSN trusted 14:04:25.0704 0x0a48 usbuhci - ok 14:04:25.0744 0x0a48 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll 14:04:25.0784 0x0a48 UxSms - ok 14:04:25.0804 0x0a48 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] VaultSvc C:\Windows\system32\lsass.exe 14:04:25.0814 0x0a48 VaultSvc - ok 14:04:25.0844 0x0a48 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 14:04:25.0844 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vdrvroot.sys. md5: A059C4C3EDB09E07D21A8E5C0AABD3CB, sha256: BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 14:04:25.0844 0x0a48 vdrvroot - detected LockedFile.Multi.Generic ( 1 ) 14:04:28.0264 0x0a48 Detect skipped due to KSN trusted 14:04:28.0264 0x0a48 vdrvroot - ok 14:04:28.0304 0x0a48 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe 14:04:28.0404 0x0a48 vds - ok 14:04:28.0434 0x0a48 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 14:04:28.0434 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\vgapnp.sys. md5: 17C408214EA61696CEC9C66E388B14F3, sha256: 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 14:04:28.0434 0x0a48 vga - detected LockedFile.Multi.Generic ( 1 ) 14:04:30.0784 0x0a48 Detect skipped due to KSN trusted 14:04:30.0784 0x0a48 vga - ok 14:04:30.0794 0x0a48 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys 14:04:30.0794 0x0a48 Suspicious file ( NoAccess ): C:\Windows\System32\drivers\vga.sys. md5: 8E38096AD5C8570A6F1570A61E251561, sha256: 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 14:04:30.0794 0x0a48 VgaSave - detected LockedFile.Multi.Generic ( 1 ) 14:04:33.0234 0x0a48 Detect skipped due to KSN trusted 14:04:33.0234 0x0a48 VgaSave - ok 14:04:33.0264 0x0a48 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys 14:04:33.0264 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vhdmp.sys. md5: 5461686CCA2FDA57B024547733AB42E3, sha256: 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 14:04:33.0264 0x0a48 vhdmp - detected LockedFile.Multi.Generic ( 1 ) 14:04:35.0654 0x0a48 Detect skipped due to KSN trusted 14:04:35.0654 0x0a48 vhdmp - ok 14:04:35.0674 0x0a48 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys 14:04:35.0674 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viaagp.sys. md5: C829317A37B4BEA8F39735D4B076E923, sha256: 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 14:04:35.0674 0x0a48 viaagp - detected LockedFile.Multi.Generic ( 1 ) 14:04:38.0434 0x0a48 Detect skipped due to KSN trusted 14:04:38.0434 0x0a48 viaagp - ok 14:04:38.0474 0x0a48 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\drivers\viac7.sys 14:04:38.0474 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viac7.sys. md5: E02F079A6AA107F06B16549C6E5C7B74, sha256: B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 14:04:38.0474 0x0a48 ViaC7 - detected LockedFile.Multi.Generic ( 1 ) 14:04:40.0944 0x0a48 Detect skipped due to KSN trusted 14:04:40.0944 0x0a48 ViaC7 - ok 14:04:40.0974 0x0a48 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys 14:04:40.0974 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\viaide.sys. md5: E43574F6A56A0EE11809B48C09E4FD3C, sha256: 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 14:04:40.0974 0x0a48 viaide - detected LockedFile.Multi.Generic ( 1 ) 14:04:46.0584 0x0a48 Detect skipped due to KSN trusted 14:04:46.0584 0x0a48 viaide - ok 14:04:46.0614 0x0a48 [ C2F2911156FDC7817C52829C86DA494E, FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC ] vmbus C:\Windows\system32\drivers\vmbus.sys 14:04:46.0614 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vmbus.sys. md5: C2F2911156FDC7817C52829C86DA494E, sha256: FE499F189B5016FCE0018AA3DE3970B72275B7B15F3D4D608117F6DDEC6B90DC 14:04:46.0614 0x0a48 vmbus - detected LockedFile.Multi.Generic ( 1 ) 14:04:49.0874 0x0a48 Detect skipped due to KSN trusted 14:04:49.0874 0x0a48 vmbus - ok 14:04:49.0904 0x0a48 [ D4D77455211E204F370D08F4963063CE, 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys 14:04:49.0904 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\VMBusHID.sys. md5: D4D77455211E204F370D08F4963063CE, sha256: 2018B2A84C73E0834200A594C02A9D28C74906F126DAD3CCDDFC9CD9A61669E2 14:04:49.0904 0x0a48 VMBusHID - detected LockedFile.Multi.Generic ( 1 ) 14:04:52.0294 0x0a48 Detect skipped due to KSN trusted 14:04:52.0294 0x0a48 VMBusHID - ok 14:04:52.0304 0x0a48 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys 14:04:52.0304 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volmgr.sys. md5: 4C63E00F2F4B5F86AB48A58CD990F212, sha256: 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 14:04:52.0304 0x0a48 volmgr - detected LockedFile.Multi.Generic ( 1 ) 14:04:54.0794 0x0a48 Detect skipped due to KSN trusted 14:04:54.0794 0x0a48 volmgr - ok 14:04:54.0834 0x0a48 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 14:04:54.0834 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volmgrx.sys. md5: B5BB72067DDDDBBFB04B2F89FF8C3C87, sha256: 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC 14:04:54.0834 0x0a48 volmgrx - detected LockedFile.Multi.Generic ( 1 ) 14:04:58.0654 0x0a48 Detect skipped due to KSN trusted 14:04:58.0654 0x0a48 volmgrx - ok 14:04:58.0664 0x0a48 [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys 14:04:58.0664 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\volsnap.sys. md5: F497F67932C6FA693D7DE2780631CFE7, sha256: DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 14:04:58.0664 0x0a48 volsnap - detected LockedFile.Multi.Generic ( 1 ) 14:05:02.0498 0x0a48 Detect skipped due to KSN trusted 14:05:02.0498 0x0a48 volsnap - ok 14:05:02.0531 0x0a48 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 14:05:02.0532 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\vsmraid.sys. md5: 9DFA0CC2F8855A04816729651175B631, sha256: 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 14:05:02.0532 0x0a48 vsmraid - detected LockedFile.Multi.Generic ( 1 ) 14:05:04.0921 0x0a48 Detect skipped due to KSN trusted 14:05:04.0921 0x0a48 vsmraid - ok 14:05:04.0986 0x0a48 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe 14:05:05.0070 0x0a48 VSS - ok 14:05:05.0092 0x0a48 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 14:05:05.0093 0x0a48 Suspicious file ( NoAccess ): C:\Windows\System32\drivers\vwifibus.sys. md5: 90567B1E658001E79D7C8BBD3DDE5AA6, sha256: EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 14:05:05.0093 0x0a48 vwifibus - detected LockedFile.Multi.Generic ( 1 ) 14:05:07.0439 0x0a48 Detect skipped due to KSN trusted 14:05:07.0439 0x0a48 vwifibus - ok 14:05:07.0465 0x0a48 [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 14:05:07.0465 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\vwififlt.sys. md5: 7090D3436EEB4E7DA3373090A23448F7, sha256: 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 14:05:07.0466 0x0a48 vwififlt - detected LockedFile.Multi.Generic ( 1 ) 14:05:09.0935 0x0a48 Detect skipped due to KSN trusted 14:05:09.0935 0x0a48 vwififlt - ok 14:05:09.0957 0x0a48 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll 14:05:10.0008 0x0a48 W32Time - ok 14:05:10.0038 0x0a48 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 14:05:10.0038 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wacompen.sys. md5: DE3721E89C653AA281428C8A69745D90, sha256: 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 14:05:10.0038 0x0a48 WacomPen - detected LockedFile.Multi.Generic ( 1 ) 14:05:12.0815 0x0a48 Detect skipped due to KSN trusted 14:05:12.0815 0x0a48 WacomPen - ok 14:05:12.0841 0x0a48 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys 14:05:12.0841 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wanarp.sys. md5: 3C3C78515F5AB448B022BDF5B8FFDD2E, sha256: 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 14:05:12.0842 0x0a48 WANARP - detected LockedFile.Multi.Generic ( 1 ) 14:05:15.0244 0x0a48 Detect skipped due to KSN trusted 14:05:15.0245 0x0a48 WANARP - ok 14:05:15.0265 0x0a48 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 14:05:15.0265 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wanarp.sys. md5: 3C3C78515F5AB448B022BDF5B8FFDD2E, sha256: 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 14:05:15.0266 0x0a48 Wanarpv6 - detected LockedFile.Multi.Generic ( 1 ) 14:05:15.0266 0x0a48 Detect skipped due to KSN trusted 14:05:15.0266 0x0a48 Wanarpv6 - ok 14:05:15.0349 0x0a48 [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe 14:05:15.0407 0x0a48 WatAdminSvc - ok 14:05:15.0468 0x0a48 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe 14:05:15.0540 0x0a48 wbengine - ok 14:05:15.0556 0x0a48 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 14:05:15.0588 0x0a48 WbioSrvc - ok 14:05:15.0612 0x0a48 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll 14:05:15.0652 0x0a48 wcncsvc - ok 14:05:15.0669 0x0a48 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 14:05:15.0715 0x0a48 WcsPlugInService - ok 14:05:15.0737 0x0a48 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\drivers\wd.sys 14:05:15.0738 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wd.sys. md5: 1112A9BADACB47B7C0BB0392E3158DFF, sha256: 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 14:05:15.0738 0x0a48 Wd - detected LockedFile.Multi.Generic ( 1 ) 14:05:18.0095 0x0a48 Detect skipped due to KSN trusted 14:05:18.0095 0x0a48 Wd - ok 14:05:18.0164 0x0a48 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 14:05:18.0165 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\Wdf01000.sys. md5: 25944D2CC49E0A6C581D02A74B7D6645, sha256: AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE 14:05:18.0166 0x0a48 Wdf01000 - detected LockedFile.Multi.Generic ( 1 ) 14:05:20.0639 0x0a48 Detect skipped due to KSN trusted 14:05:20.0640 0x0a48 Wdf01000 - ok 14:05:20.0656 0x0a48 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll 14:05:20.0730 0x0a48 WdiServiceHost - ok 14:05:20.0735 0x0a48 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\system32\wdi.dll 14:05:20.0751 0x0a48 WdiSystemHost - ok 14:05:20.0787 0x0a48 [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\Windows\System32\webclnt.dll 14:05:20.0846 0x0a48 WebClient - ok 14:05:20.0879 0x0a48 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll 14:05:20.0910 0x0a48 Wecsvc - ok 14:05:20.0923 0x0a48 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll 14:05:20.0956 0x0a48 wercplsupport - ok 14:05:20.0987 0x0a48 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll 14:05:21.0023 0x0a48 WerSvc - ok 14:05:21.0044 0x0a48 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys 14:05:21.0044 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wfplwf.sys. md5: 8B9A943F3B53861F2BFAF6C186168F79, sha256: 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 14:05:21.0045 0x0a48 WfpLwf - detected LockedFile.Multi.Generic ( 1 ) 14:05:27.0621 0x0a48 Detect skipped due to KSN trusted 14:05:27.0621 0x0a48 WfpLwf - ok 14:05:27.0639 0x0a48 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys 14:05:27.0639 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\wimmount.sys. md5: 5CF95B35E59E2A38023836FFF31BE64C, sha256: CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D 14:05:27.0639 0x0a48 WIMMount - detected LockedFile.Multi.Generic ( 1 ) 14:05:31.0688 0x0a48 Detect skipped due to KSN trusted 14:05:31.0688 0x0a48 WIMMount - ok 14:05:31.0767 0x0a48 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll 14:05:31.0844 0x0a48 WinDefend - ok 14:05:31.0862 0x0a48 WinHttpAutoProxySvc - ok 14:05:31.0901 0x0a48 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 14:05:31.0924 0x0a48 Winmgmt - ok 14:05:31.0979 0x0a48 [ 1B91CD34EA3A90AB6A4EF0550174F4CC, 5B6618615EBFBA594C945AD35F5C68DA8C6053892B6D12D626BB6120910D80DC ] WinRM C:\Windows\system32\WsmSvc.dll 14:05:32.0107 0x0a48 WinRM - ok 14:05:32.0165 0x0a48 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll 14:05:32.0215 0x0a48 Wlansvc - ok 14:05:32.0249 0x0a48 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 14:05:32.0249 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\wmiacpi.sys. md5: 0217679B8FCA58714C3BF2726D2CA84E, sha256: 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A 14:05:32.0250 0x0a48 WmiAcpi - detected LockedFile.Multi.Generic ( 1 ) 14:05:35.0370 0x0a48 Detect skipped due to KSN trusted 14:05:35.0370 0x0a48 WmiAcpi - ok 14:05:35.0414 0x0a48 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 14:05:35.0449 0x0a48 wmiApSrv - ok 14:05:35.0530 0x0a48 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe 14:05:35.0610 0x0a48 WMPNetworkSvc - ok 14:05:35.0638 0x0a48 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll 14:05:35.0686 0x0a48 WPCSvc - ok 14:05:35.0713 0x0a48 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 14:05:35.0742 0x0a48 WPDBusEnum - ok 14:05:35.0766 0x0a48 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 14:05:35.0766 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\ws2ifsl.sys. md5: 6DB3276587B853BF886B69528FDB048C, sha256: 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C 14:05:35.0767 0x0a48 ws2ifsl - detected LockedFile.Multi.Generic ( 1 ) 14:05:38.0150 0x0a48 Detect skipped due to KSN trusted 14:05:38.0150 0x0a48 ws2ifsl - ok 14:05:38.0176 0x0a48 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\System32\wscsvc.dll 14:05:38.0208 0x0a48 wscsvc - ok 14:05:38.0213 0x0a48 WSearch - ok 14:05:38.0309 0x0a48 [ FC3EC24FCE372C89423E015A2AC1A31E, 8D028182CF83667D3E4D148979972D208FA6D9B8540EE47A0A7831B770ECD257 ] wuauserv C:\Windows\system32\wuaueng.dll 14:05:38.0391 0x0a48 wuauserv - ok 14:05:38.0429 0x0a48 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 14:05:38.0429 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\drivers\WudfPf.sys. md5: 06E6F32C8D0A3F66D956F57B43A2E070, sha256: 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 14:05:38.0429 0x0a48 WudfPf - detected LockedFile.Multi.Generic ( 1 ) 14:05:40.0904 0x0a48 Detect skipped due to KSN trusted 14:05:40.0904 0x0a48 WudfPf - ok 14:05:40.0935 0x0a48 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 14:05:40.0935 0x0a48 Suspicious file ( NoAccess ): C:\Windows\system32\DRIVERS\WUDFRd.sys. md5: 867C301E8B790040AE9CF6486E8041DF, sha256: D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 14:05:40.0935 0x0a48 WUDFRd - detected LockedFile.Multi.Generic ( 1 ) 14:05:48.0111 0x0a48 Detect skipped due to KSN trusted 14:05:48.0111 0x0a48 WUDFRd - ok 14:05:48.0178 0x0a48 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll 14:05:48.0208 0x0a48 wudfsvc - ok 14:05:48.0254 0x0a48 [ 3C5E51C05BE9B56EAFF4E388C3AB25E4, 10D9FDEDAB1FB2E76D54661AFA5C1A6B1B0980525F38F5D061537077841C6AEE ] WwanSvc C:\Windows\System32\wwansvc.dll 14:05:48.0285 0x0a48 WwanSvc - ok 14:05:48.0299 0x0a48 ================ Scan global =============================== 14:05:48.0330 0x0a48 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll 14:05:48.0372 0x0a48 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll 14:05:48.0388 0x0a48 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll 14:05:48.0414 0x0a48 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll 14:05:48.0433 0x0a48 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe 14:05:48.0439 0x0a48 [ Global ] - ok 14:05:48.0439 0x0a48 ================ Scan MBR ================================== 14:05:48.0451 0x0a48 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0 14:05:48.0953 0x0a48 \Device\Harddisk0\DR0 - ok 14:05:48.0956 0x0a48 ================ Scan VBR ================================== 14:05:48.0984 0x0a48 [ 57A3169F8DEE214ED99DDDA540A8F62F ] \Device\Harddisk0\DR0\Partition1 14:05:49.0003 0x0a48 \Device\Harddisk0\DR0\Partition1 - ok 14:05:49.0037 0x0a48 [ 0E70EA370ADDBC3B807180F3EA1BB489 ] \Device\Harddisk0\DR0\Partition2 14:05:49.0056 0x0a48 \Device\Harddisk0\DR0\Partition2 - ok 14:05:49.0058 0x0a48 ================ Scan active images ======================== 14:05:49.0060 0x0a48 [ B7EFEF22FF426EC4158A177CB3B558D3, 87D8F07E23B928B9D71B13B0F43A6235BAFC48879CFCF5920889849D09FFCD6C ] C:\Windows\System32\drivers\crashdmp.sys 14:05:49.0060 0x0a48 C:\Windows\System32\drivers\crashdmp.sys - ok 14:05:49.0065 0x0a48 [ 5428227D4730EBDFC842E9FB593F8C8A, C62A122FC8A04B63A94F337699A70901ED04B0F20AEC9538EC6E83ED2D18F1E3 ] C:\Windows\System32\drivers\Dumpata.sys 14:05:49.0065 0x0a48 C:\Windows\System32\drivers\Dumpata.sys - ok 14:05:49.0069 0x0a48 [ 62A63EF2F3053B461CB327E4D69AAA74, 26CC8BBC9BB6C53B46C837FA75C5449508989C26949BD19EB8E03E37F7928456 ] C:\Windows\System32\drivers\dumpfve.sys 14:05:49.0069 0x0a48 C:\Windows\System32\drivers\dumpfve.sys - ok 14:05:49.0074 0x0a48 [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] C:\Windows\System32\drivers\msahci.sys 14:05:49.0074 0x0a48 C:\Windows\System32\drivers\msahci.sys - ok 14:05:49.0076 0x0a48 [ 3B4C137E2CA87CF773204653A80B5BE9, D774945037F7A39EB23392DCCF4B52BDE03134C8D457EB9DDFE761B3B8C3D0D9 ] C:\Windows\System32\drivers\mbamchameleon.sys 14:05:49.0076 0x0a48 C:\Windows\System32\drivers\mbamchameleon.sys - ok 14:05:49.0080 0x0a48 [ E6B7D1B24E16FB24CE1FEA964E144EBC, 30F81E0A017163A1AB463FE3A13B5CC2905B973E782AEBC1EB63759BF2470658 ] C:\Windows\System32\drivers\dtsoftbus01.sys 14:05:49.0080 0x0a48 C:\Windows\System32\drivers\dtsoftbus01.sys - ok 14:05:49.0084 0x0a48 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] C:\Windows\System32\drivers\beep.sys 14:05:49.0084 0x0a48 C:\Windows\System32\drivers\beep.sys - ok 14:05:49.0089 0x0a48 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] C:\Windows\System32\drivers\cdrom.sys 14:05:49.0090 0x0a48 C:\Windows\System32\drivers\cdrom.sys - ok 14:05:49.0093 0x0a48 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] C:\Windows\System32\drivers\null.sys 14:05:49.0093 0x0a48 C:\Windows\System32\drivers\null.sys - ok 14:05:49.0096 0x0a48 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] C:\Windows\System32\drivers\RDPCDD.sys 14:05:49.0096 0x0a48 C:\Windows\System32\drivers\RDPCDD.sys - ok 14:05:49.0098 0x0a48 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] C:\Windows\System32\drivers\vga.sys 14:05:49.0098 0x0a48 C:\Windows\System32\drivers\vga.sys - ok 14:05:49.0102 0x0a48 [ 15C126D1B55814B9E5CAB10A9C1F4C67, CD118B6508355037294AE940E039C095BA9E4A96AA129D38DB0AEC0C393D0F00 ] C:\Windows\System32\drivers\videoprt.sys 14:05:49.0102 0x0a48 C:\Windows\System32\drivers\videoprt.sys - ok 14:05:49.0107 0x0a48 [ CB45A417C8EF7BA6BAC67EDCDDED8700, 0D9AD2498A7D3B7C3E485A5803D2BDF781B38E07E3C2B5980859073EF6FD9B8A ] C:\Windows\System32\drivers\watchdog.sys 14:05:49.0107 0x0a48 C:\Windows\System32\drivers\watchdog.sys - ok 14:05:49.0110 0x0a48 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] C:\Windows\System32\drivers\RDPENCDD.sys 14:05:49.0110 0x0a48 C:\Windows\System32\drivers\RDPENCDD.sys - ok 14:05:49.0113 0x0a48 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] C:\Windows\System32\drivers\RDPREFMP.sys 14:05:49.0113 0x0a48 C:\Windows\System32\drivers\RDPREFMP.sys - ok 14:05:49.0116 0x0a48 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] C:\Windows\System32\drivers\msfs.sys 14:05:49.0116 0x0a48 C:\Windows\System32\drivers\msfs.sys - ok 14:05:49.0119 0x0a48 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] C:\Windows\System32\drivers\npfs.sys 14:05:49.0119 0x0a48 C:\Windows\System32\drivers\npfs.sys - ok 14:05:49.0123 0x0a48 [ 2F885864D5BC8A16C86BEE595969A48A, 279E176CDEF9148A4A07F7D37172A2C2BDC89E47021EEB76F1BCDF789B76D95A ] C:\Windows\System32\drivers\tdi.sys 14:05:49.0123 0x0a48 C:\Windows\System32\drivers\tdi.sys - ok 14:05:49.0126 0x0a48 [ B459575348C20E8121D6039DA063C704, 1B4328A9EA39FF5A57F258E02254D04B73455F1DF7C997C13702A8B2F12D0347 ] C:\Windows\System32\drivers\tdx.sys 14:05:49.0126 0x0a48 C:\Windows\System32\drivers\tdx.sys - ok 14:05:49.0130 0x0a48 [ F81BB7E487EDCEAB630A7EE66CF23913, 7D1638FD7E388EF670FA0A421762E0413351058A20DDF0F9988A383F05395A68 ] C:\Windows\System32\drivers\afd.sys 14:05:49.0130 0x0a48 C:\Windows\System32\drivers\afd.sys - ok 14:05:49.0133 0x0a48 [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] C:\Windows\System32\drivers\netbt.sys 14:05:49.0133 0x0a48 C:\Windows\System32\drivers\netbt.sys - ok 14:05:49.0136 0x0a48 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] C:\Windows\System32\drivers\pacer.sys 14:05:49.0136 0x0a48 C:\Windows\System32\drivers\pacer.sys - ok 14:05:49.0140 0x0a48 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] C:\Windows\System32\drivers\wfplwf.sys 14:05:49.0140 0x0a48 C:\Windows\System32\drivers\wfplwf.sys - ok 14:05:49.0141 0x0a48 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] C:\Windows\System32\drivers\netbios.sys 14:05:49.0141 0x0a48 C:\Windows\System32\drivers\netbios.sys - ok 14:05:49.0146 0x0a48 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] C:\Windows\System32\drivers\serial.sys 14:05:49.0146 0x0a48 C:\Windows\System32\drivers\serial.sys - ok 14:05:49.0148 0x0a48 [ 7090D3436EEB4E7DA3373090A23448F7, 3A130B28F2BFA7DCEC8596C4CE4E187B019F5ECF1AAC8DD1BBDE9CBD2428FEC2 ] C:\Windows\System32\drivers\vwififlt.sys 14:05:49.0148 0x0a48 C:\Windows\System32\drivers\vwififlt.sys - ok 14:05:49.0151 0x0a48 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] C:\Windows\System32\drivers\wanarp.sys 14:05:49.0151 0x0a48 C:\Windows\System32\drivers\wanarp.sys - ok 14:05:49.0153 0x0a48 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] C:\Windows\System32\drivers\nsiproxy.sys 14:05:49.0153 0x0a48 C:\Windows\System32\drivers\nsiproxy.sys - ok 14:05:49.0155 0x0a48 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] C:\Windows\System32\drivers\rdbss.sys 14:05:49.0155 0x0a48 C:\Windows\System32\drivers\rdbss.sys - ok 14:05:49.0157 0x0a48 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] C:\Windows\System32\drivers\termdd.sys 14:05:49.0157 0x0a48 C:\Windows\System32\drivers\termdd.sys - ok 14:05:49.0162 0x0a48 [ 3C2177A897B4CA2788C6FB0C3FD81D4B, 98575CBD0664586E6211D02E71BDD52CBAA149A1658573550E29E74E5F7B1553 ] C:\Windows\System32\drivers\csc.sys 14:05:49.0162 0x0a48 C:\Windows\System32\drivers\csc.sys - ok 14:05:49.0164 0x0a48 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] C:\Windows\System32\drivers\discache.sys 14:05:49.0164 0x0a48 C:\Windows\System32\drivers\discache.sys - ok 14:05:49.0168 0x0a48 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] C:\Windows\System32\drivers\mssmbios.sys 14:05:49.0168 0x0a48 C:\Windows\System32\drivers\mssmbios.sys - ok 14:05:49.0174 0x0a48 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] C:\Windows\System32\drivers\blbdrive.sys 14:05:49.0174 0x0a48 C:\Windows\System32\drivers\blbdrive.sys - ok 14:05:49.0176 0x0a48 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] C:\Windows\System32\drivers\dfsc.sys 14:05:49.0176 0x0a48 C:\Windows\System32\drivers\dfsc.sys - ok 14:05:49.0179 0x0a48 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] C:\Windows\System32\drivers\intelppm.sys 14:05:49.0179 0x0a48 C:\Windows\System32\drivers\intelppm.sys - ok 14:05:49.0184 0x0a48 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] C:\Windows\System32\drivers\tunnel.sys 14:05:49.0184 0x0a48 C:\Windows\System32\drivers\tunnel.sys - ok 14:05:49.0187 0x0a48 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] C:\Windows\System32\drivers\wmiacpi.sys 14:05:49.0187 0x0a48 C:\Windows\System32\drivers\wmiacpi.sys - ok 14:05:49.0190 0x0a48 [ E0B8C6B1EA1EF94747E966E9093FB968, 364539AE2AD49870DAF2773B6BD6306764D936F5EE1C2929B2B5A47EEC3409A7 ] C:\Windows\System32\ntdll.dll 14:05:49.0190 0x0a48 C:\Windows\System32\ntdll.dll - ok 14:05:49.0191 0x0a48 [ DE91DCC7BC55E940979097E98F743205, 77CBB42FA1648CF03F21709738F7F91513385F82B544981741F7BD8D65FB7786 ] C:\Windows\System32\smss.exe 14:05:49.0191 0x0a48 C:\Windows\System32\smss.exe - ok 14:05:49.0194 0x0a48 [ F88A52EB62019D6A62FDD9E08034DBD8, 2E035366E9A1A26FB15F1E4857056E6AD7932BCE8CC68BB4B655609F424D2756 ] C:\Windows\System32\autochk.exe 14:05:49.0194 0x0a48 C:\Windows\System32\autochk.exe - ok 14:05:49.0197 0x0a48 [ DCE0B53570703CCE580D066F89EF58CD, C5C2C4F51F2DB2BB6E7F1218472AEAAD996514AB99EA84946A473CB7A64D9E15 ] C:\Windows\System32\drivers\igdkmd32.sys 14:05:49.0197 0x0a48 C:\Windows\System32\drivers\igdkmd32.sys - ok 14:05:49.0200 0x0a48 [ 71BC35067CABC02C9453AEAA42B2E43E, 713B19F2C08EA5E4C087F7A74A8856932CF33E19D63384823DD4E02ED8798619 ] C:\Windows\System32\drivers\dxgkrnl.sys 14:05:49.0200 0x0a48 C:\Windows\System32\drivers\dxgkrnl.sys - ok 14:05:49.0202 0x0a48 [ E405328A0E38BF823E2361C413283F6D, 7637EA2F14216F0469CC309C0ABBFB70213721B0BADD6C36522F6789CC0F361E ] C:\Windows\System32\drivers\dxgmms1.sys 14:05:49.0202 0x0a48 C:\Windows\System32\drivers\dxgmms1.sys - ok 14:05:49.0205 0x0a48 [ 3EA531906572FFD549B72A10F828E58C, 179D40413E5CB1E46F9486F80D56C8DE5CDE0C309BC65E0508D98C3E6A00BBEB ] C:\Windows\System32\drivers\e1k6032.sys 14:05:49.0205 0x0a48 C:\Windows\System32\drivers\e1k6032.sys - ok 14:05:49.0206 0x0a48 [ 88A67C34E37186665E916FD347B50D19, 23C4F11E421DE7D8330418118524D345A905300816E3D7D486DB18C670226EE1 ] C:\Windows\System32\drivers\HECI.sys 14:05:49.0206 0x0a48 C:\Windows\System32\drivers\HECI.sys - ok 14:05:49.0208 0x0a48 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] C:\Windows\System32\drivers\serenum.sys 14:05:49.0208 0x0a48 C:\Windows\System32\drivers\serenum.sys - ok 14:05:49.0211 0x0a48 [ EC2C5AF37B76D7B58C642CB74423DB7A, BE1F6F2CE3B1539DAC23B73EA655B77E6E628E5E55BD16091E76934723BE77B1 ] C:\Windows\System32\drivers\usbport.sys 14:05:49.0211 0x0a48 C:\Windows\System32\drivers\usbport.sys - ok 14:05:49.0213 0x0a48 [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] C:\Windows\System32\drivers\usbuhci.sys 14:05:49.0213 0x0a48 C:\Windows\System32\drivers\usbuhci.sys - ok 14:05:49.0215 0x0a48 [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] C:\Windows\System32\drivers\usbehci.sys 14:05:49.0215 0x0a48 C:\Windows\System32\drivers\usbehci.sys - ok 14:05:49.0218 0x0a48 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] C:\Windows\System32\drivers\hdaudbus.sys 14:05:49.0218 0x0a48 C:\Windows\System32\drivers\hdaudbus.sys - ok 14:05:49.0223 0x0a48 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] C:\Windows\System32\drivers\fdc.sys 14:05:49.0223 0x0a48 C:\Windows\System32\drivers\fdc.sys - ok 14:05:49.0225 0x0a48 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] C:\Windows\System32\drivers\agilevpn.sys 14:05:49.0225 0x0a48 C:\Windows\System32\drivers\agilevpn.sys - ok 14:05:49.0230 0x0a48 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] C:\Windows\System32\drivers\CompositeBus.sys 14:05:49.0230 0x0a48 C:\Windows\System32\drivers\CompositeBus.sys - ok 14:05:49.0233 0x0a48 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] C:\Windows\System32\drivers\ndistapi.sys 14:05:49.0233 0x0a48 C:\Windows\System32\drivers\ndistapi.sys - ok 14:05:49.0238 0x0a48 [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] C:\Windows\System32\drivers\ndiswan.sys 14:05:49.0238 0x0a48 C:\Windows\System32\drivers\ndiswan.sys - ok 14:05:49.0241 0x0a48 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] C:\Windows\System32\drivers\rasl2tp.sys 14:05:49.0241 0x0a48 C:\Windows\System32\drivers\rasl2tp.sys - ok 14:05:49.0243 0x0a48 [ 5AD05191DC8B444A7BA4D79B76C42A30, 6166E939A5A240388EBA5AF7FF335DC413F2BBCF74C2E1D310F4BE2A5454A610 ] C:\Windows\System32\drivers\tpm.sys 14:05:49.0243 0x0a48 C:\Windows\System32\drivers\tpm.sys - ok 14:05:49.0246 0x0a48 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] C:\Windows\System32\drivers\raspppoe.sys 14:05:49.0246 0x0a48 C:\Windows\System32\drivers\raspppoe.sys - ok 14:05:49.0248 0x0a48 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] C:\Windows\System32\drivers\raspptp.sys 14:05:49.0248 0x0a48 C:\Windows\System32\drivers\raspptp.sys - ok 14:05:49.0250 0x0a48 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] C:\Windows\System32\drivers\rassstp.sys 14:05:49.0250 0x0a48 C:\Windows\System32\drivers\rassstp.sys - ok 14:05:49.0254 0x0a48 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] C:\Windows\System32\drivers\rdpbus.sys 14:05:49.0254 0x0a48 C:\Windows\System32\drivers\rdpbus.sys - ok 14:05:49.0258 0x0a48 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] C:\Windows\System32\drivers\kbdclass.sys 14:05:49.0258 0x0a48 C:\Windows\System32\drivers\kbdclass.sys - ok 14:05:49.0262 0x0a48 [ 5DCEF0C32BE0F33277326586FA503689, B6AEB5DE8F2430D2032DAF5B58DBB4E192F6113DB5379F5AD8189A7AC2560EEA ] C:\Windows\System32\drivers\ks.sys 14:05:49.0262 0x0a48 C:\Windows\System32\drivers\ks.sys - ok 14:05:49.0266 0x0a48 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] C:\Windows\System32\drivers\mouclass.sys 14:05:49.0266 0x0a48 C:\Windows\System32\drivers\mouclass.sys - ok 14:05:49.0269 0x0a48 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] C:\Windows\System32\drivers\swenum.sys 14:05:49.0269 0x0a48 C:\Windows\System32\drivers\swenum.sys - ok 14:05:49.0273 0x0a48 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] C:\Windows\System32\drivers\umbus.sys 14:05:49.0273 0x0a48 C:\Windows\System32\drivers\umbus.sys - ok 14:05:49.0278 0x0a48 [ E7B9D5FF20FFDD4AAE2EF1D1B8C27A37, 689D126B1B42140D5049015E3E324268E6542D4BC6CC14E31D8B89A25B94BAA5 ] C:\Windows\System32\imagehlp.dll 14:05:49.0278 0x0a48 C:\Windows\System32\imagehlp.dll - ok 14:05:49.0280 0x0a48 [ CFC97F07904067A1E5FAE195D534DA3A, EB4D2D127312EB09E2ACCA3276779E80F90FAF77322684BABF72B8EC6E1F906C ] C:\Windows\System32\sechost.dll 14:05:49.0280 0x0a48 C:\Windows\System32\sechost.dll - ok 14:05:49.0282 0x0a48 [ 10FB16B50AFFDA6D44588F3C445DC273, 6CDA17DA9B44D11E69F7C6682FA633EA75731623BB21B429A0FE2086ED4495A7 ] C:\Windows\System32\setupapi.dll 14:05:49.0282 0x0a48 C:\Windows\System32\setupapi.dll - ok 14:05:49.0284 0x0a48 [ 6377051C63D5552A311935C67E9FDFDC, 3FB82988AAB66813567E8DB951D4EE87F156201070F005FDBF52EF998A323E65 ] C:\Windows\System32\nsi.dll 14:05:49.0284 0x0a48 C:\Windows\System32\nsi.dll - ok 14:05:49.0286 0x0a48 [ 6933E2AFF444A7A95D5C67E98449163E, 4E745B89D319FF997F7DFD288E9D02143CEF5474D2B8814803504A6570A146DE ] C:\Windows\System32\kernel32.dll 14:05:49.0287 0x0a48 C:\Windows\System32\kernel32.dll - ok 14:05:49.0289 0x0a48 [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] C:\Windows\System32\drivers\usbhub.sys 14:05:49.0289 0x0a48 C:\Windows\System32\drivers\usbhub.sys - ok 14:05:49.0291 0x0a48 [ F1DD3ACAEE5E6B4BBC69BC6DF75CEF66, 6CCAD926934EACBE92FDFA1AE46DA6101D78A0B44AE38594E3A88FEBB35D230F ] C:\Windows\System32\user32.dll 14:05:49.0291 0x0a48 C:\Windows\System32\user32.dll - ok 14:05:49.0293 0x0a48 [ 9C278785347BCC991F8EA2999D90F58D, EA680C3642A6ABF627415AEE019956FAC702DC6A8F4B4D0FC8A4FB21EADD3896 ] C:\Windows\System32\normaliz.dll 14:05:49.0293 0x0a48 C:\Windows\System32\normaliz.dll - ok 14:05:49.0297 0x0a48 [ 5D9DC6332A4FC66388B09BBE7CF53750, 497961D2ED6C83E1198C3706E4A6CB8B01FE55FCD96E19EEB279352CF56679C1 ] C:\Windows\System32\urlmon.dll 14:05:49.0297 0x0a48 C:\Windows\System32\urlmon.dll - ok 14:05:49.0301 0x0a48 [ C9618BC9B2B0FD7C1138D8774795A79B, 0AC170669C2626519FA7A745C56BFBA6B83B8537488F5B9EB7BA72448E5E7A43 ] C:\Windows\System32\msctf.dll 14:05:49.0301 0x0a48 C:\Windows\System32\msctf.dll - ok 14:05:49.0317 0x0a48 [ 5A775CAE7CCCAC581C05B8D2C92C0DF1, 0BD75912F3BDCF79B6C3CCEBCF3242725A17F73D6F6772C2C145F8157628B2E9 ] C:\Windows\System32\gdi32.dll 14:05:49.0317 0x0a48 C:\Windows\System32\gdi32.dll - ok 14:05:49.0321 0x0a48 [ 4A8E2F20809CC161107FAA94F6CF2685, 561DCE9E49696288A9EE802C0BEF424EB34A1C29B6D8931CCD5C7E26CB4F88EA ] C:\Windows\System32\imm32.dll 14:05:49.0322 0x0a48 C:\Windows\System32\imm32.dll - ok 14:05:49.0324 0x0a48 [ 928CF7268086631F54C3D8E17238C6DD, F058FAFB04E7EBD5CADE9B48195B7AA7C3508F332A89F5E6E5F3F071E8CADD4A ] C:\Windows\System32\ole32.dll 14:05:49.0324 0x0a48 C:\Windows\System32\ole32.dll - ok 14:05:49.0329 0x0a48 [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] C:\Windows\System32\drivers\ndproxy.sys 14:05:49.0329 0x0a48 C:\Windows\System32\drivers\ndproxy.sys - ok 14:05:49.0332 0x0a48 [ 9842041E2F5ACE1E2F5FB4EF02053DC8, 8260D3DDCC92987CA3A456ABD0982A7C81DBBEDB87DE781039F2E4BCCF27DB6D ] C:\Windows\System32\drivers\drmk.sys 14:05:49.0332 0x0a48 C:\Windows\System32\drivers\drmk.sys - ok 14:05:49.0337 0x0a48 [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] C:\Windows\System32\drivers\HdAudio.sys 14:05:49.0337 0x0a48 C:\Windows\System32\drivers\HdAudio.sys - ok 14:05:49.0341 0x0a48 [ EB6137D696A9B4E9718AC6F8641CB4C9, 438B6177F8BF50E17226D9C4E5FAE42D82178CCDD79979C78B15261B459E153E ] C:\Windows\System32\drivers\portcls.sys 14:05:49.0341 0x0a48 C:\Windows\System32\drivers\portcls.sys - ok 14:05:49.0346 0x0a48 [ 50ABE682EBE752EAF62B18790D6D491C, E01499C4F81CC49A89590A07CB814D21126CE52DCD3FACADB6D1E243940C69FA ] C:\Windows\System32\drivers\hidclass.sys 14:05:49.0346 0x0a48 C:\Windows\System32\drivers\hidclass.sys - ok 14:05:49.0349 0x0a48 [ F1B27299F547D452EDAEF01FC187CB91, 574FC8ACB349244122E6D76333E2BB72680639EEF61C0B679F8485023B619263 ] C:\Windows\System32\drivers\hidparse.sys 14:05:49.0349 0x0a48 C:\Windows\System32\drivers\hidparse.sys - ok 14:05:49.0352 0x0a48 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] C:\Windows\System32\drivers\hidusb.sys 14:05:49.0352 0x0a48 C:\Windows\System32\drivers\hidusb.sys - ok 14:05:49.0355 0x0a48 [ 74F805AB12EB0E3E49E469F19FF02640, 23A845F9162ECE37B6CF5B2537562C69705A4192D19438109B5212E111A49004 ] C:\Windows\System32\drivers\usbd.sys 14:05:49.0355 0x0a48 C:\Windows\System32\drivers\usbd.sys - ok 14:05:49.0357 0x0a48 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] C:\Windows\System32\drivers\mouhid.sys 14:05:49.0357 0x0a48 C:\Windows\System32\drivers\mouhid.sys - ok 14:05:49.0361 0x0a48 [ 8CC3C111D653E96F3EA1590891491D71, 1D326D7D116D76876EE2B14A5BFB7B4328E21DB9B5AAAB9CB67F8EFB93924230 ] C:\Windows\System32\shlwapi.dll 14:05:49.0361 0x0a48 C:\Windows\System32\shlwapi.dll - ok 14:05:49.0363 0x0a48 [ 5A043BDA3BFADD5B4C16F3BDE5EC4312, 70E4D7EB03AE69D51EFCFBF227D3C06CD378806B1D0FB6993D6022379FC0B9F9 ] C:\Windows\System32\rpcrt4.dll 14:05:49.0363 0x0a48 C:\Windows\System32\rpcrt4.dll - ok 14:05:49.0365 0x0a48 [ 6C765E82B57F2E66CE9C54AC238471D9, 97F410023F5C08B4BC5DBF89A642200E76F4025ADD9707C24FD89D673675BB43 ] C:\Windows\System32\oleaut32.dll 14:05:49.0365 0x0a48 C:\Windows\System32\oleaut32.dll - ok 14:05:49.0367 0x0a48 [ A8BB45F9ECAD993461E0FEF8E2A99152, ACB756EA54E71F124D928829666B5B439785593877FF7C0C76ADCF954F4E6C94 ] C:\Windows\System32\Wldap32.dll 14:05:49.0367 0x0a48 C:\Windows\System32\Wldap32.dll - ok 14:05:49.0369 0x0a48 [ A543AC1F7138376D778D630A35FCBC4C, 2D824C66A97FC8C39DAFA397CC47495B712D175EEF393486946DA8936BDD466A ] C:\Windows\System32\psapi.dll 14:05:49.0369 0x0a48 C:\Windows\System32\psapi.dll - ok 14:05:49.0371 0x0a48 [ FF5688D309347F2720911D8796912834, 3B0D73C50D40A6F42629B7750F99F656BF5C1C50237D5F98B6C0F2CE5E2DA359 ] C:\Windows\System32\clbcatq.dll 14:05:49.0371 0x0a48 C:\Windows\System32\clbcatq.dll - ok 14:05:49.0374 0x0a48 [ 34CBED7698D557DDB43F8732FBC2ACB9, 2406E009E037F0C577984792FD41CECD96078AA8B6EAC9207051CDE8DBED89CD ] C:\Windows\System32\iertutil.dll 14:05:49.0374 0x0a48 C:\Windows\System32\iertutil.dll - ok 14:05:49.0375 0x0a48 [ F632602316001D517F4EF3B53B9A6C33, 1492B82B12AA8B69C5111D5E61997D41AEC9E454BE76E8024B18E28B145E9FFD ] C:\Windows\System32\lpk.dll 14:05:49.0375 0x0a48 C:\Windows\System32\lpk.dll - ok 14:05:49.0377 0x0a48 [ E02781D4871844DCD30DF1D69A650F78, DC77302F06CD6CF7FC2C3B0F433A4AE41DF869B9F342C0656CCD8A125B3D3318 ] C:\Windows\System32\shell32.dll 14:05:49.0377 0x0a48 C:\Windows\System32\shell32.dll - ok 14:05:49.0380 0x0a48 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] C:\Windows\System32\drivers\usbprint.sys 14:05:49.0380 0x0a48 C:\Windows\System32\drivers\usbprint.sys - ok 14:05:49.0382 0x0a48 [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] C:\Windows\System32\drivers\usbccgp.sys 14:05:49.0382 0x0a48 C:\Windows\System32\drivers\usbccgp.sys - ok 14:05:49.0385 0x0a48 [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] C:\Windows\System32\drivers\kbdhid.sys 14:05:49.0385 0x0a48 C:\Windows\System32\drivers\kbdhid.sys - ok 14:05:49.0389 0x0a48 [ 070C5B9D3006602A07757179D9B56F5D, 7B24E38ADDEEDD9168D0C87275AC0936D0A4F1195810F9736118076589BC18BA ] C:\Windows\System32\difxapi.dll 14:05:49.0389 0x0a48 C:\Windows\System32\difxapi.dll - ok 14:05:49.0392 0x0a48 [ 7FF15A4F092CD4A96055BA69F903E3E9, 1B594E6D057C632ABB3A8CF838157369024BD6B9F515CA8E774B22FE71A11627 ] C:\Windows\System32\ws2_32.dll 14:05:49.0392 0x0a48 C:\Windows\System32\ws2_32.dll - ok 14:05:49.0400 0x0a48 [ 9C89246184979A070B0C6CCF61C68136, 409D5CB32E803B623F79A0CBAB094D33B078ED164002687B1CEA236E2B77C7D8 ] C:\Windows\System32\wininet.dll 14:05:49.0400 0x0a48 C:\Windows\System32\wininet.dll - ok 14:05:49.0405 0x0a48 [ 9DC80A8AAAAAC397BDAB3C67165A824E, 051636BFDFF7AB0E4191354E846BD0DACCA1A01FCC13C1AFED91D8DBFE17127A ] C:\Windows\System32\msvcrt.dll 14:05:49.0405 0x0a48 C:\Windows\System32\msvcrt.dll - ok 14:05:49.0408 0x0a48 [ D1DE1EAFDE97BE41CF6585027FF3E732, 76F17D4DF440D6734DC8157092D94EB18C2A73A0A49BEEA289E7B3EDE30E86A2 ] C:\Windows\System32\comdlg32.dll 14:05:49.0408 0x0a48 C:\Windows\System32\comdlg32.dll - ok 14:05:49.0411 0x0a48 [ B7230010D97787AF3D25E4C82F2B06B9, C795E9811CD461F8E98D1738667EB0C265A57065EA3420CE596D5038E7430C1E ] C:\Windows\System32\usp10.dll 14:05:49.0411 0x0a48 C:\Windows\System32\usp10.dll - ok 14:05:49.0414 0x0a48 [ D67472125471784DE7147946EDA25FEB, F41960118F412B6CA5E80AE5E8DB9AECDD043A7DB34388FF57C6F9C5A0056F91 ] C:\Windows\System32\advapi32.dll 14:05:49.0414 0x0a48 C:\Windows\System32\advapi32.dll - ok 14:05:49.0417 0x0a48 [ 2E33DFD10F28F86C3FC40EE123CC3904, 57C65671A04EFCA437A69E8E97B2FCA17897EE4608C7DB69F77D44FBD3490B50 ] C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll 14:05:49.0417 0x0a48 C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll - ok 14:05:49.0420 0x0a48 [ CC09E0C9A2D89C6E71D093DC8BD121B7, 5F92457E27D817541EBA92FED984D2E6C1E35AD4E4E4CAE0F0778B795C260FAA ] C:\Windows\System32\crypt32.dll 14:05:49.0420 0x0a48 C:\Windows\System32\crypt32.dll - ok 14:05:49.0422 0x0a48 [ 68EAAEDF0365168B804E8728368FA946, 1FA25087E8B247B099B729F780DBF24F77FD34F58186A1C94329261CF3D18B8E ] C:\Windows\System32\wintrust.dll 14:05:49.0422 0x0a48 C:\Windows\System32\wintrust.dll - ok 14:05:49.0424 0x0a48 [ 6A13B4F3B3F575F1E24B877B9359AABA, 676AD5F8F709D4A9DCE9938D82DEEE329C9A385A6969C169B3DF37AA75F1E4C7 ] C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll 14:05:49.0424 0x0a48 C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll - ok 14:05:49.0428 0x0a48 [ 6951562DC4625EEFC6EACD52AD165866, 44A0B3EA0232D613A5B4115492DF2A7CEF25B35300E6A3E3E50C9544C5D1049E ] C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 14:05:49.0428 0x0a48 C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll - ok 14:05:49.0430 0x0a48 [ 3BE0D923AA45A4DBE091C2D84F0B4FE7, 603EEC55D6F646150FC3F0F2C939CFE434C02FC7A7AB23B1FEC8B5C77E4C8381 ] C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll 14:05:49.0430 0x0a48 C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll - ok 14:05:49.0433 0x0a48 [ 3FFAEA12666E565FF51BF2FCA674F543, 95BA8DBDA495C170E075F48627D7DD89C6B29BE0CE0D0D8316B0236692675060 ] C:\Windows\System32\cfgmgr32.dll 14:05:49.0433 0x0a48 C:\Windows\System32\cfgmgr32.dll - ok 14:05:49.0435 0x0a48 [ CC4ED8BEA78B0DCA6F217E014C3291A7, 01104182E4E6FB3CF6397936D30B2CE3486967586D1B94187B59A8232DAE39FF ] C:\Windows\System32\devobj.dll 14:05:49.0435 0x0a48 C:\Windows\System32\devobj.dll - ok 14:05:49.0437 0x0a48 [ 1E65CF7B26D02750544EFDD73C8118FA, EAE54B09FCA7D9A7F26BF3CC30ECDF0E58555F21DEA1A6A3F1D58554DBE86598 ] C:\Windows\System32\KernelBase.dll 14:05:49.0437 0x0a48 C:\Windows\System32\KernelBase.dll - ok 14:05:49.0439 0x0a48 [ 1C60E09CA1C3A045BC4D367F67C915B7, DF1ED88CB57DA1AB1A4245AE0D5B42AFA3396EBF67B99411FFFB0DD06DE1AEAF ] C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll 14:05:49.0439 0x0a48 C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll - ok 14:05:49.0442 0x0a48 [ 75F5E1FE8D55CF8E577E0EC5F2290D3F, F4E2C81F0834018052A481AE8D7DF4780302A6844160CCDC09F7D82D3B992BDE ] C:\Windows\System32\comctl32.dll 14:05:49.0442 0x0a48 C:\Windows\System32\comctl32.dll - ok 14:05:49.0445 0x0a48 [ 589CBC4989F750E1DA35625AB481CF43, B93E1B8C3775F9C995FD5451C685A06DEFD24AE1DF0DD99D19D5E4B9AC0010F9 ] C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll 14:05:49.0445 0x0a48 C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll - ok 14:05:49.0447 0x0a48 [ 938F39B50BAFE13D6F58C7790682C010, 902000EE51EFEABAF6A4B30F880AA37083D2232C6FC622CA513C4A823390FEDA ] C:\Windows\System32\msasn1.dll 14:05:49.0447 0x0a48 C:\Windows\System32\msasn1.dll - ok 14:05:49.0451 0x0a48 [ 5FCD3320AAE71506B43F9E12E4E72172, 067531833F90241A181EF082D85CFF74336D68DAB0AADE4393C1F35CD662DAAE ] C:\Windows\System32\drivers\dxapi.sys 14:05:49.0451 0x0a48 C:\Windows\System32\drivers\dxapi.sys - ok 14:05:49.0452 0x0a48 [ 1E882889A4314D6DF5DED4F6EC994E72, 4D8736BC20540A24D073D629ED8B1F089F4994195F737342C763DD5D532B2F74 ] C:\Windows\System32\win32k.sys 14:05:49.0452 0x0a48 C:\Windows\System32\win32k.sys - ok 14:05:49.0455 0x0a48 [ 23AB7E36551C6BA5370EF7F05142F0EB, F190F2DCB416D109DFCA167628824CE053774FB708AA494450AD6313EF6BE654 ] C:\Windows\System32\csrsrv.dll 14:05:49.0455 0x0a48 C:\Windows\System32\csrsrv.dll - ok 14:05:49.0458 0x0a48 [ 342271F6142E7C70805B8A81E1BA5F5C, F9112B88FEC5EF10A7AEDF88DCEE61956D1FCDE7CB42197216E8265578713786 ] C:\Windows\System32\csrss.exe 14:05:49.0458 0x0a48 C:\Windows\System32\csrss.exe - ok 14:05:49.0460 0x0a48 [ 14F8D278988BC02B9B4BF202B5BB1115, 6453BADFBCBCA7A7618C75C66A4E9130102885466C7195F34E57CAA6517F7D21 ] C:\Windows\System32\drivers\athur.sys 14:05:49.0460 0x0a48 C:\Windows\System32\drivers\athur.sys - ok 14:05:49.0464 0x0a48 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\System32\basesrv.dll 14:05:49.0464 0x0a48 C:\Windows\System32\basesrv.dll - ok 14:05:49.0466 0x0a48 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\System32\winsrv.dll 14:05:49.0466 0x0a48 C:\Windows\System32\winsrv.dll - ok 14:05:49.0468 0x0a48 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] C:\Windows\System32\drivers\vwifibus.sys 14:05:49.0468 0x0a48 C:\Windows\System32\drivers\vwifibus.sys - ok 14:05:49.0470 0x0a48 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] C:\Windows\System32\drivers\monitor.sys 14:05:49.0470 0x0a48 C:\Windows\System32\drivers\monitor.sys - ok 14:05:49.0472 0x0a48 [ C733D233B623B7FFCE5031E4B756EE26, 33CC8B140B0E4A9B702E3468BE2646AEE4273F20C6EA5BAC6C3D8FC8EDEF0881 ] C:\Windows\System32\profapi.dll 14:05:49.0472 0x0a48 C:\Windows\System32\profapi.dll - ok 14:05:49.0474 0x0a48 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\System32\sxssrv.dll 14:05:49.0474 0x0a48 C:\Windows\System32\sxssrv.dll - ok 14:05:49.0476 0x0a48 [ 7C76B61A5E1EF5D1FA554CF134100F18, 2B07C27A2C9A5D939CE9255C67E87B4EF8BFD3B011A592CC0E6994E660483648 ] C:\Windows\System32\tsddd.dll 14:05:49.0476 0x0a48 C:\Windows\System32\tsddd.dll - ok 14:05:49.0479 0x0a48 [ B5C5DCAD3899512020D135600129D665, F6B4D18FA0D3C4958711AC0D476C21A6FDF2897F989A0AD290B43F463DD8B5B0 ] C:\Windows\System32\wininit.exe 14:05:49.0479 0x0a48 C:\Windows\System32\wininit.exe - ok 14:05:49.0481 0x0a48 [ CAEF9CD6C10B1017E2C298D849CD31DB, 62C6638D34CC554D952A09CDBABF29AA1487EED90578C48E3D01C519A4CC6FB8 ] C:\Windows\System32\cdd.dll 14:05:49.0481 0x0a48 C:\Windows\System32\cdd.dll - ok 14:05:49.0482 0x0a48 [ C857C08D2C94B5E3E801895A37B91981, 3D82AF42DF292A75B707F8F4E196DAC8184CD6D3038ACC610495DD0152F7A750 ] C:\Windows\System32\KBDPL1.DLL 14:05:49.0482 0x0a48 C:\Windows\System32\KBDPL1.DLL - ok 14:05:49.0484 0x0a48 [ 5997D769CDB108390DCFAEBF442BF816, 0E25CA984C0EEB629184423FAA9BC6D4356DF9A93F281E06DC83B4AC638AEC4A ] C:\Windows\System32\RpcRtRemote.dll 14:05:49.0484 0x0a48 C:\Windows\System32\RpcRtRemote.dll - ok 14:05:49.0487 0x0a48 [ A32DFD02B72403CE0F9A7BB3CF7CB8AA, 76B2825EFB11455DECD7F97AB8F5324DCA0E12E3099820C2474FD77F88BF0699 ] C:\Windows\System32\KBDPL.DLL 14:05:49.0487 0x0a48 C:\Windows\System32\KBDPL.DLL - ok 14:05:49.0489 0x0a48 [ C25F054900BD3CC5C333E7B0FA75DA91, D2BE71A629BFEFE92F03CCC4766E335768474CF44FF584759875E45A67676940 ] C:\Windows\System32\KBDUSX.DLL 14:05:49.0489 0x0a48 C:\Windows\System32\KBDUSX.DLL - ok 14:05:49.0491 0x0a48 [ 919001D2BB17DF06CA3F8AC16AD039F6, 5169ACFBE9E9D4C4012773ECDD28231C952675EF0C272A40F226E7B5D671B18B ] C:\Windows\System32\sxs.dll 14:05:49.0491 0x0a48 C:\Windows\System32\sxs.dll - ok 14:05:49.0493 0x0a48 [ 633C2C060CF857099F6C4F8D75C952B1, 95E14B5212301900BC9DDB6B42735B114D364188E9B312C786511258106398C8 ] C:\Windows\System32\WlS0WndH.dll 14:05:49.0493 0x0a48 C:\Windows\System32\WlS0WndH.dll - ok 14:05:49.0495 0x0a48 [ F08F6FCD09F9BE94C37ACC1B344685FF, DE48D766258B46EFEAB16579421C4BD97ACC6883F782D00E9857F4A0CE7E8A34 ] C:\Windows\System32\cryptbase.dll 14:05:49.0495 0x0a48 C:\Windows\System32\cryptbase.dll - ok 14:05:49.0497 0x0a48 [ 863F793D15B4026B1A5FDECA873D4D84, AF7ABD95BB5467551562F129F03C7AC9D52A021F7E547609F40A80E66932C942 ] C:\Windows\System32\apphelp.dll 14:05:49.0497 0x0a48 C:\Windows\System32\apphelp.dll - ok 14:05:49.0499 0x0a48 [ 6D13E1406F50C66E2A95D97F22C47560, BE40E84A824CB201F9C54DB4F860F3937630FDA3423940D44FCF4AC5DFF44271 ] C:\Windows\System32\winlogon.exe 14:05:49.0499 0x0a48 C:\Windows\System32\winlogon.exe - ok 14:05:49.0501 0x0a48 [ 418E881201583A3039D81F43E39E6C78, C96AAC161E09BE12815A4E931E65F66DB1A456C03253EF1111AE66F44B1515FF ] C:\Windows\System32\winsta.dll 14:05:49.0501 0x0a48 C:\Windows\System32\winsta.dll - ok 14:05:49.0504 0x0a48 [ EF6950D7B24AAF4E477065F5455DD4F8, D02D02528EB103808BAD71FBE0271D5D3C101A53ACFB0B2B3835CFE6C7A2BE03 ] C:\Windows\System32\lsasrv.dll 14:05:49.0504 0x0a48 C:\Windows\System32\lsasrv.dll - ok 14:05:49.0507 0x0a48 [ 803B370865D907EA21DC0C2B6A8936B5, E98F0BA1D94786E061A3EA2CC76041FF6BE0ADF47C6205D5572C03BF0E29CA78 ] C:\Windows\System32\lsass.exe 14:05:49.0507 0x0a48 C:\Windows\System32\lsass.exe - ok 14:05:49.0508 0x0a48 [ 8AEA9A37C1A3565A204D37C5E72AB791, 939903F93FF37525A6C4B5CBA29CDEEE6D6055C42D605E80AE787F2A76F9870E ] C:\Windows\System32\lsm.exe 14:05:49.0508 0x0a48 C:\Windows\System32\lsm.exe - ok 14:05:49.0510 0x0a48 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\System32\services.exe 14:05:49.0510 0x0a48 C:\Windows\System32\services.exe - ok 14:05:49.0512 0x0a48 [ BD6B9BC84D004C6BEE89CF7BDB95E1FC, 142BCB6F616A34679FDFB5285E0C8CED110501518BA4B4E2DF3B4F691E28DE72 ] C:\Windows\System32\sspicli.dll 14:05:49.0512 0x0a48 C:\Windows\System32\sspicli.dll - ok 14:05:49.0514 0x0a48 [ D89077E2E1C88A29C57F21FAD28DAC45, 39B760D9976B9FF61046303B9FA29C2A0483D1CCC9617822810F46F288710627 ] C:\Windows\System32\sspisrv.dll 14:05:49.0514 0x0a48 C:\Windows\System32\sspisrv.dll - ok 14:05:49.0516 0x0a48 [ 250AA41DE690561AF1282D598914564C, 0F16F50EC74CAC8879F8D88AF4FB656E06D19819E96BC3D71BCDDBF400C78F60 ] C:\Windows\System32\scesrv.dll 14:05:49.0516 0x0a48 C:\Windows\System32\scesrv.dll - ok 14:05:49.0518 0x0a48 [ 3369D021265E369D57317D61FA86DD79, 25A3BE3619324578C5B7CCB4585D89131DC60A969D35F9573FF20CCD67809BA3 ] C:\Windows\System32\scext.dll 14:05:49.0518 0x0a48 C:\Windows\System32\scext.dll - ok 14:05:49.0520 0x0a48 [ 372948BB5E41CE42341C4398DE572E56, A12A3CB0C04FD02A17E202FEE79EA1B4009DAE4B5DB8B9B9D4919D1FFB270CF3 ] C:\Windows\System32\secur32.dll 14:05:49.0520 0x0a48 C:\Windows\System32\secur32.dll - ok 14:05:49.0522 0x0a48 [ BA51FFE170C5B3AE8EC4F5BD2581A29E, CF734875C91B6C547A5F0BA68FB10ECDFD5FF24166A0D69309C27DC712C22F4B ] C:\Windows\System32\sysntfy.dll 14:05:49.0522 0x0a48 C:\Windows\System32\sysntfy.dll - ok 14:05:49.0524 0x0a48 [ D412B1B72C5AB020218E9A047D90CA05, A9CF8134DB968D259DF4DCC736159841BCB8DF309BEED4FB44F99033B8D31B39 ] C:\Windows\System32\wmsgapi.dll 14:05:49.0524 0x0a48 C:\Windows\System32\wmsgapi.dll - ok 14:05:49.0526 0x0a48 [ 5CCDCD40E732D54E0F7451AC66AC1C87, 66F4DA105BD72E41250CD59E2B3CD931B47AC9FDB6C784B9E33C5EE1AC29841F ] C:\Windows\System32\srvcli.dll 14:05:49.0526 0x0a48 C:\Windows\System32\srvcli.dll - ok 14:05:49.0528 0x0a48 [ 245F4691314F42D4D1BC06442F0B2086, 281DD81E06547BEB0DDB1FBB68B149961F1DEE268C9E9648DE662900ECB40FE0 ] C:\Windows\System32\samsrv.dll 14:05:49.0528 0x0a48 C:\Windows\System32\samsrv.dll - ok 14:05:49.0530 0x0a48 [ 1128637CAD49A8E3C8B5FA5D0A061525, 6B80E50D8296F9E2C978CC6BC002B964ACFD8F4BCF623F4770513792845B5278 ] C:\Windows\System32\cryptdll.dll 14:05:49.0530 0x0a48 C:\Windows\System32\cryptdll.dll - ok 14:05:49.0533 0x0a48 [ FD1D6C73E6333BE727CBCC6054247654, 6F7B9AE1A5986204DB3348D13B303F30FC17624939DA74D6BD114FAEED0FB30E ] C:\Windows\System32\drivers\TsUsbFlt.sys 14:05:49.0533 0x0a48 C:\Windows\System32\drivers\TsUsbFlt.sys - ok 14:05:49.0536 0x0a48 [ 82C089EA2A3EEFADF3588EA71E8BDADA, 2F3BB32EE2C0673058A74DEEB2D405E5E79F833F33C4D289A93EB3C618A86E75 ] C:\Windows\System32\wevtapi.dll 14:05:49.0536 0x0a48 C:\Windows\System32\wevtapi.dll - ok 14:05:49.0538 0x0a48 [ FB4EB9352B7D698E6B3C2AA2ED724DAD, 534AB280ACD29E88FD1BD8838E1231D9364E649C917547A838F51EC8AB941EE2 ] C:\Windows\System32\authz.dll 14:05:49.0538 0x0a48 C:\Windows\System32\authz.dll - ok 14:05:49.0540 0x0a48 [ 50BA656134F78AF64E4DD3C8B6FEFD7E, F7AB96E0C9658B0444FD473E87165199FA90AE5CE434B40FBA1DB324925DF886 ] C:\Windows\System32\cngaudit.dll 14:05:49.0540 0x0a48 C:\Windows\System32\cngaudit.dll - ok 14:05:49.0542 0x0a48 [ AD7FB087A238883D1618F29F7BBBD584, D9541CA4D2AADFEEEC195863133B16C2EC94CA63F842F5646F7834F2D0E85FF3 ] C:\Windows\System32\ncrypt.dll 14:05:49.0542 0x0a48 C:\Windows\System32\ncrypt.dll - ok 14:05:49.0544 0x0a48 [ FC7650224790CAE75A5E9231961FDEC5, D634FC1F43AAC41D8B440BD4C1E7576886CDE683EDE4CAF06C43163B5E176CBB ] C:\Windows\System32\bcrypt.dll 14:05:49.0544 0x0a48 C:\Windows\System32\bcrypt.dll - ok 14:05:49.0546 0x0a48 [ C90878913DF3DC504790282043DB5F4C, 5DC30020A523B5B219A219D74208A1249A43510D70723985817A021249D97036 ] C:\Windows\System32\msprivs.dll 14:05:49.0546 0x0a48 C:\Windows\System32\msprivs.dll - ok 14:05:49.0550 0x0a48 [ E343CABBD8D600ABAF3F11625D33B3D0, AA73D0F205749C291BF5EF179BDF3BF30977E36C87F4FF5361942EE024E848F9 ] C:\Windows\System32\netjoin.dll 14:05:49.0550 0x0a48 C:\Windows\System32\netjoin.dll - ok 14:05:49.0553 0x0a48 [ BDA0B954A30498B5A7EDC6204CBA07ED, B14AC33E649F02AEC7ED9237DF6EB1801506C3066B0DACC8EBC4660D408AF614 ] C:\Windows\System32\kerberos.dll 14:05:49.0553 0x0a48 C:\Windows\System32\kerberos.dll - ok 14:05:49.0556 0x0a48 [ 6DCFAEC6D1334AA6CDF8961DB4633CBF, DA7A26935691379DA0DBA829DEDE82401BCA7D35E28BFBFE3F9CE38AFF344737 ] C:\Windows\System32\negoexts.dll 14:05:49.0556 0x0a48 C:\Windows\System32\negoexts.dll - ok 14:05:49.0560 0x0a48 [ 7321F18D1F820612ED0E9F2D4B578A7E, 612BD7DE1DFBD100BD6ACB37A38565D88C39842D990D296B9B8E1FB75C3A94E7 ] C:\Windows\System32\cryptsp.dll 14:05:49.0560 0x0a48 C:\Windows\System32\cryptsp.dll - ok 14:05:49.0561 0x0a48 [ E94C583CDE2348950155F2AF2876F34D, D00C7E0D665E467B712C68A446CC5BE14FDA743A2301878B3CEB72CDD0A8B8E7 ] C:\Windows\System32\mswsock.dll 14:05:49.0561 0x0a48 C:\Windows\System32\mswsock.dll - ok 14:05:49.0564 0x0a48 [ 4C1E16B9A53102C8D6FBA587CBCB95DE, F982ABB2353E45E3E09B30EA99EFDC2A905AD75B43CDB0A34DB33D91AADDAB17 ] C:\Windows\System32\msv1_0.dll 14:05:49.0564 0x0a48 C:\Windows\System32\msv1_0.dll - ok 14:05:49.0566 0x0a48 [ C1809B9907ADEDAF16F50C894100883B, 464CF897CB376DCDC9A584A2A470B5B82D99C595DC55930778B162E605CDFBA8 ] C:\Windows\System32\netlogon.dll 14:05:49.0566 0x0a48 C:\Windows\System32\netlogon.dll - ok 14:05:49.0568 0x0a48 [ 73E8667A19FEEDD856DF2695E9E511D4, 68D66C36D1F293D10ADCC6A33C870F989A29743537592CF172F02E794BEAFD1C ] C:\Windows\System32\wship6.dll 14:05:49.0569 0x0a48 C:\Windows\System32\wship6.dll - ok 14:05:49.0570 0x0a48 [ B40420876B9288E0A1C8CCA8A84E5DC9, 0D3C73B45BC708D7B1E26DFB6D4F64031A998548FEA0FB5CE198ED716F7DC9A0 ] C:\Windows\System32\dnsapi.dll 14:05:49.0570 0x0a48 C:\Windows\System32\dnsapi.dll - ok 14:05:49.0572 0x0a48 [ 8EA53101FF2B15BDFF934B62A8FB326D, E28536A4AC6764C2480EF047AF2312AE2600819899C3E33B486CFE19F25AC464 ] C:\Windows\System32\logoncli.dll 14:05:49.0572 0x0a48 C:\Windows\System32\logoncli.dll - ok 14:05:49.0574 0x0a48 [ AA6F6457116B559B76BC6A012CB4C293, 87888451759EECCEA178BDB23AE48EEA534202AC40ED0DD83474ED7CE557C9F1 ] C:\Windows\System32\schannel.dll 14:05:49.0574 0x0a48 C:\Windows\System32\schannel.dll - ok 14:05:49.0576 0x0a48 [ 0450CF487ECD8A67B56F59F9A96D024D, 7B19CD3B3A98384844E3F4D04C505B8D17B2D5AABE184E265E85A17D0DDBC25B ] C:\Windows\System32\wdigest.dll 14:05:49.0576 0x0a48 C:\Windows\System32\wdigest.dll - ok 14:05:49.0578 0x0a48 [ 37CC990D4E2CDFAE12AC47F6B620FC13, D07E6EF4EED10ACA21A41A739147E54CC435EAF952CD0CA1F2E3CB2D83CEC831 ] C:\Windows\System32\pku2u.dll 14:05:49.0578 0x0a48 C:\Windows\System32\pku2u.dll - ok 14:05:49.0581 0x0a48 [ ED8EC63F7522DF4852147C84EC62C36A, 75633011CD28DCBD4834211A9D415F17DE15BFCD80FB9FF6CE25CBBD4E9899AF ] C:\Windows\System32\rsaenh.dll 14:05:49.0581 0x0a48 C:\Windows\System32\rsaenh.dll - ok 14:05:49.0583 0x0a48 [ D29E45078CF4020CE0AAC82EC652D1EA, 3CB552744C9D02A488ABCF171E29872156BA6B57C73EC45D708C72D541BE8365 ] C:\Windows\System32\TSpkg.dll 14:05:49.0583 0x0a48 C:\Windows\System32\TSpkg.dll - ok 14:05:49.0586 0x0a48 [ E8449FE262D7406BCB2AC2A45C53EC5F, 6C118C9FB26404D1943824CF3990F36E12986547FFACB7CC0DF975A913065D78 ] C:\Windows\System32\bcryptprimitives.dll 14:05:49.0586 0x0a48 C:\Windows\System32\bcryptprimitives.dll - ok 14:05:49.0588 0x0a48 [ 4E5FE39C1076D115EC8BFCFE14D75B80, F1D02BCA6F664DCDD0CCDE269D31787C7553CD38C7208A8DD8B80B9EA09FEB1C ] C:\Windows\System32\credssp.dll 14:05:49.0588 0x0a48 C:\Windows\System32\credssp.dll - ok 14:05:49.0590 0x0a48 [ 91F434FF6606ED9BDC6A05D651B69553, F2CF43DDDE2241E8A25F710A516371E0C56D99195022D9715A98379C753929B3 ] C:\Windows\System32\efslsaext.dll 14:05:49.0590 0x0a48 C:\Windows\System32\efslsaext.dll - ok 14:05:49.0592 0x0a48 [ 8124944EC89D6A1815E4E53F5B96AAF4, A6766BD0F62A381C9899F66E5C32731BD91600363F4CFBE560BC8AA2B111C790 ] C:\Windows\System32\scecli.dll 14:05:49.0592 0x0a48 C:\Windows\System32\scecli.dll - ok 14:05:49.0594 0x0a48 [ 7222995615BF93B628DCEA4BD6CCACF7, 306A3220868AC38AC796027F0D75052B596F55B9CAE87A9B8863515995BFC2F2 ] C:\Windows\System32\ubpm.dll 14:05:49.0594 0x0a48 C:\Windows\System32\ubpm.dll - ok 14:05:49.0596 0x0a48 [ 4BDBBE5E4208022DD794F7EEEB0F7366, 4F69BA2EDABFA63A300B9F1880349EFAE185B899DD5C561E7B3BA6AAA4B22D6A ] C:\Windows\System32\SPInf.dll 14:05:49.0596 0x0a48 C:\Windows\System32\SPInf.dll - ok 14:05:49.0598 0x0a48 [ 54A47F6B5E09A77E61649109C6A08866, 121118A0F5E0E8C933EFD28C9901E54E42792619A8A3A6D11E1F0025A7324BC2 ] C:\Windows\System32\svchost.exe 14:05:49.0598 0x0a48 C:\Windows\System32\svchost.exe - ok 14:05:49.0600 0x0a48 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] C:\Windows\System32\umpnpmgr.dll 14:05:49.0600 0x0a48 C:\Windows\System32\umpnpmgr.dll - ok 14:05:49.0602 0x0a48 [ FD07F21E0A19C27ED4E1EEC2B07452B3, DF54C00B021AF64BB04EDEBCA6F41CCF48F1959DD53ADE545FAFC565F1243392 ] C:\Windows\System32\devrtl.dll 14:05:49.0602 0x0a48 C:\Windows\System32\devrtl.dll - ok 14:05:49.0604 0x0a48 [ D15618A0FF8DBC2C5BF3726BACC75A0B, ADD81EA1D208907D67802F0E96EC0327BA89021F870BA22B9C7E3A19013A6AE7 ] C:\Windows\System32\userenv.dll 14:05:49.0604 0x0a48 C:\Windows\System32\userenv.dll - ok 14:05:49.0606 0x0a48 [ 1097F3035BAF46CED8B332B3564C5108, C69781683CA963A1335780DABBBC60E2C3CEF0888738D3425D358D12E8D0AF58 ] C:\Windows\System32\gpapi.dll 14:05:49.0606 0x0a48 C:\Windows\System32\gpapi.dll - ok 14:05:49.0608 0x0a48 [ 5893EBDCE371174AC89ECD7731DD6D77, 31CC55F4724CFD95E48954B38C0A04D674399FD243083A816893ED5E5A770086 ] C:\Windows\System32\pcwum.dll 14:05:49.0608 0x0a48 C:\Windows\System32\pcwum.dll - ok 14:05:49.0610 0x0a48 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] C:\Windows\System32\umpo.dll 14:05:49.0610 0x0a48 C:\Windows\System32\umpo.dll - ok 14:05:49.0612 0x0a48 [ 08DFDBD2FD4EA951DC46B1C7661ED35A, D926530C659DDAF80770663F46F1EFD94FFB4AAB475C4E3367CB531AF4A734E1 ] C:\Windows\System32\powrprof.dll 14:05:49.0612 0x0a48 C:\Windows\System32\powrprof.dll - ok 14:05:49.0614 0x0a48 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] C:\Windows\System32\drivers\luafv.sys 14:05:49.0614 0x0a48 C:\Windows\System32\drivers\luafv.sys - ok 14:05:49.0616 0x0a48 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] C:\Windows\System32\RpcEpMap.dll 14:05:49.0616 0x0a48 C:\Windows\System32\RpcEpMap.dll - ok 14:05:49.0619 0x0a48 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] C:\Windows\System32\rpcss.dll 14:05:49.0619 0x0a48 C:\Windows\System32\rpcss.dll - ok 14:05:49.0620 0x0a48 [ 3F50200237961034FACE602373838980, F97D72CC75D921CF8F8E0544614407358AEFF97A8F48E4A89F82689EE8F2FC86 ] C:\Windows\System32\FirewallAPI.dll 14:05:49.0620 0x0a48 C:\Windows\System32\FirewallAPI.dll - ok 14:05:49.0622 0x0a48 [ 81F08948A0F1475894C99D4D19A158A8, 93334DA369BF976E498265E432CAF63D898D378C6B32947DF355366ABE2A0FAC ] C:\Windows\System32\wshqos.dll 14:05:49.0622 0x0a48 C:\Windows\System32\wshqos.dll - ok 14:05:49.0624 0x0a48 [ EE5C8E27C37B79CB54A2FCEEED2DC262, 0A5E200FD65A491756B951A4A0ED39B88B7B313E97C2BBF3C91AC4C290772BB7 ] C:\Windows\System32\WSHTCPIP.DLL 14:05:49.0624 0x0a48 C:\Windows\System32\WSHTCPIP.DLL - ok 14:05:49.0626 0x0a48 [ 702254574E7E52052DE39408457B7149, 645CA9E88DA21C63710A04A0F54421018DF415A3D612112C71A255C49325C082 ] C:\Windows\System32\version.dll 14:05:49.0626 0x0a48 C:\Windows\System32\version.dll - ok 14:05:49.0628 0x0a48 [ EE7CB55F77465CDAC4C80F587FF7C278, 9DB3FC61275BA78A0A4E66440024341F0C6863659937A78E6224D3C42D7E57E7 ] C:\Windows\System32\authui.dll 14:05:49.0628 0x0a48 C:\Windows\System32\authui.dll - ok 14:05:49.0630 0x0a48 [ 3EF0D8AB08385AAB5802E773511A2E6A, 1A7EE4BC646767004372EAEA9BC0A2071790E739101F7D25ECD9C95D3F29AFD6 ] C:\Windows\System32\LogonUI.exe 14:05:49.0630 0x0a48 C:\Windows\System32\LogonUI.exe - ok 14:05:49.0632 0x0a48 [ 241E015DD809CFB23242F890B1FC575B, 763381DCBACF06FD8D043B14D383B6F4D5295B8E665796C59603F15F3E3E36FC ] C:\Windows\System32\wevtsvc.dll 14:05:49.0632 0x0a48 C:\Windows\System32\wevtsvc.dll - ok 14:05:49.0634 0x0a48 [ CE3B4E731638D2EF62FCB419BE0D39F0, 3B98179CB0101778D9E7810D2CD46D9C0D7120E141BA11471666E7D9EB3C93CC ] C:\Windows\System32\audiosrv.dll 14:05:49.0634 0x0a48 C:\Windows\System32\audiosrv.dll - ok 14:05:49.0637 0x0a48 [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] C:\Windows\System32\profsvc.dll 14:05:49.0637 0x0a48 C:\Windows\System32\profsvc.dll - ok 14:05:49.0640 0x0a48 [ 139D3AB6AA920C34C50CBFFB9EB7D222, 5A5D205E16E6AFDCC965E4144FE6E104157DE7541D31727520363F2670513940 ] C:\Windows\System32\avrt.dll 14:05:49.0640 0x0a48 C:\Windows\System32\avrt.dll - ok 14:05:49.0642 0x0a48 [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] C:\Windows\System32\FntCache.dll 14:05:49.0642 0x0a48 C:\Windows\System32\FntCache.dll - ok 14:05:49.0644 0x0a48 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] C:\Windows\System32\mmcss.dll 14:05:49.0644 0x0a48 C:\Windows\System32\mmcss.dll - ok 14:05:49.0646 0x0a48 [ 243974EC02F7AE49E4179C54624143AB, 755FA67F7BF10E3C6336788D297FBAA70F28F630852A43A78D3F7D7E3A7ECED0 ] C:\Windows\System32\MMDevAPI.dll 14:05:49.0646 0x0a48 C:\Windows\System32\MMDevAPI.dll - ok 14:05:49.0648 0x0a48 [ 12C45E3CB6D65F73209549E2D02ECA7A, 9DFD9C58B90257C34D52B7156C1D2566BE32EE7BD4699DDE164A5F190EC4D44A ] C:\Windows\System32\propsys.dll 14:05:49.0648 0x0a48 C:\Windows\System32\propsys.dll - ok 14:05:49.0650 0x0a48 [ F68194F74350D4A2ADE98961E33F884C, 75DE3554409C42CA3B6FC1503BCB8CAFF85D5D7703F7E68C38A69AA8EF3FDA81 ] C:\Windows\System32\audiodg.exe 14:05:49.0650 0x0a48 C:\Windows\System32\audiodg.exe - ok 14:05:49.0652 0x0a48 [ 3FD15B4611D9BDA3F8013548C0ECAECA, B47A8D9985D9B71EB870816A0AB2B6403D394CCBDF7DE5378D5721D58D68D28D ] C:\Windows\System32\ntmarta.dll 14:05:49.0652 0x0a48 C:\Windows\System32\ntmarta.dll - ok 14:05:49.0654 0x0a48 [ F10E5311E5093FA3C00FF88C54C32FCA, B557F5B00D77F030850D9AAC0FFEFC4C2A759EC4081C8459C9DEAE51BAAACC65 ] C:\Windows\System32\atl.dll 14:05:49.0654 0x0a48 C:\Windows\System32\atl.dll - ok 14:05:49.0656 0x0a48 [ 15F93B37F6801943360D9EB42485D5D3, DD6838C6496CB15F8BB57A6596F6A64ADD9C36B09F062295699131232712B558 ] C:\Windows\System32\cscsvc.dll 14:05:49.0656 0x0a48 C:\Windows\System32\cscsvc.dll - ok 14:05:49.0658 0x0a48 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] C:\Windows\System32\gpsvc.dll 14:05:49.0658 0x0a48 C:\Windows\System32\gpsvc.dll - ok 14:05:49.0660 0x0a48 [ 2F040CF0613A6D64DCBBA9EE81F5A5AE, DA16117429AF47230CD7C136407C81951B8D2E45A8B7A9DC6948407AA2EC4ADD ] C:\Windows\System32\dsrole.dll 14:05:49.0660 0x0a48 C:\Windows\System32\dsrole.dll - ok 14:05:49.0662 0x0a48 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] C:\Windows\System32\es.dll 14:05:49.0662 0x0a48 C:\Windows\System32\es.dll - ok 14:05:49.0664 0x0a48 [ 50E0DD0A5B8D8BC353578F2F73926697, 9A453F60FC0149417105BB5B4CB910D614A3D832D98313A58D0EA36BABED4460 ] C:\Windows\System32\nlaapi.dll 14:05:49.0664 0x0a48 C:\Windows\System32\nlaapi.dll - ok 14:05:49.0666 0x0a48 [ 772F44012DBE49DE894976AE2259A659, 34C7E200D075087A4084EF8947D5FC5A2511CC02A8A34AF8CFEEB5691364E522 ] C:\Windows\System32\PeerDist.dll 14:05:49.0666 0x0a48 C:\Windows\System32\PeerDist.dll - ok 14:05:49.0668 0x0a48 [ 8B74CEC6980D4816B0037AE9A27E538F, 8721EDB4C51BF6020002FA5DDB1987C68590F9F433A2F18D9756B2DAC7542CB6 ] C:\Windows\System32\slc.dll 14:05:49.0668 0x0a48 C:\Windows\System32\slc.dll - ok 14:05:49.0670 0x0a48 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] C:\Windows\System32\themeservice.dll 14:05:49.0671 0x0a48 C:\Windows\System32\themeservice.dll - ok 14:05:49.0672 0x0a48 [ 544EFF88AC6C85DF5A4D6F18DFE08CFC, D688381F42062FD5D868E7770857C5951C41BA20A1B6E6F60B5D9536C02CD293 ] C:\Windows\System32\taskschd.dll 14:05:49.0672 0x0a48 C:\Windows\System32\taskschd.dll - ok 14:05:49.0674 0x0a48 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] C:\Windows\System32\Sens.dll 14:05:49.0674 0x0a48 C:\Windows\System32\Sens.dll - ok 14:05:49.0676 0x0a48 [ C5A99A4C0DC9F0F5A95BA0C83D30A549, F99CCCE303F0FC07D82D3BBA223E8CCE41FB7FA8FB5C2A9214C161826537C7C9 ] C:\Windows\System32\mstask.dll 14:05:49.0676 0x0a48 C:\Windows\System32\mstask.dll - ok 14:05:49.0678 0x0a48 [ 352B3DC62A0D259A82A052238425C872, 393B24E0D6007C74AEE2FB2EE2C18623D37DF64E279B6767952DCFEE0EACBB10 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll 14:05:49.0678 0x0a48 C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - ok 14:05:49.0681 0x0a48 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] C:\Windows\System32\drivers\lltdio.sys 14:05:49.0681 0x0a48 C:\Windows\System32\drivers\lltdio.sys - ok 14:05:49.0683 0x0a48 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] C:\Windows\System32\drivers\nwifi.sys 14:05:49.0683 0x0a48 C:\Windows\System32\drivers\nwifi.sys - ok 14:05:49.0685 0x0a48 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] C:\Windows\System32\uxsms.dll 14:05:49.0685 0x0a48 C:\Windows\System32\uxsms.dll - ok 14:05:49.0687 0x0a48 [ 6A6B2EE4565A178035BE2A4FF6F2C968, E2E231F1C2E2CE19583483ACC53318651FA7CA2DE46BCB89B4CBF97CA0525122 ] C:\Windows\System32\wtsapi32.dll 14:05:49.0687 0x0a48 C:\Windows\System32\wtsapi32.dll - ok 14:05:49.0689 0x0a48 [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] C:\Windows\System32\drivers\ndisuio.sys 14:05:49.0689 0x0a48 C:\Windows\System32\drivers\ndisuio.sys - ok 14:05:49.0691 0x0a48 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] C:\Windows\System32\dhcpcore.dll 14:05:49.0691 0x0a48 C:\Windows\System32\dhcpcore.dll - ok 14:05:49.0693 0x0a48 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] C:\Windows\System32\drivers\rspndr.sys 14:05:49.0693 0x0a48 C:\Windows\System32\drivers\rspndr.sys - ok 14:05:49.0695 0x0a48 [ A90DC9ABD65DB1A8902F361103029952, 26798758976CE53251AC342B966BE0363AE1794BD965C452F5DEBC33E18969F0 ] C:\Windows\System32\IPHLPAPI.DLL 14:05:49.0695 0x0a48 C:\Windows\System32\IPHLPAPI.DLL - ok 14:05:49.0697 0x0a48 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] C:\Windows\System32\lmhsvc.dll 14:05:49.0697 0x0a48 C:\Windows\System32\lmhsvc.dll - ok 14:05:49.0701 0x0a48 [ D2A937964199F647B1C3BC435712E5D9, 03029296547750229C0C484CD09D67286096B92661C41DF67C60019DEF75A2F7 ] C:\Windows\System32\nrpsrv.dll 14:05:49.0701 0x0a48 C:\Windows\System32\nrpsrv.dll - ok 14:05:49.0704 0x0a48 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] C:\Windows\System32\nsisvc.dll 14:05:49.0704 0x0a48 C:\Windows\System32\nsisvc.dll - ok 14:05:49.0707 0x0a48 [ CFF35B879D1618D42C86644C717BA947, 1837275202628D3320867A3BF8CFDA15491730C4B74215F7C0D7E140BF01AC3C ] C:\Windows\System32\winnsi.dll 14:05:49.0707 0x0a48 C:\Windows\System32\winnsi.dll - ok 14:05:49.0709 0x0a48 [ EF71BA5DF59034962B0C62314A71351A, BB31EDFCCFF1CE984CDE0E1D8996BF70DC28F97B6685AE54172F2F4BAFA56A0F ] C:\Windows\System32\dhcpcore6.dll 14:05:49.0709 0x0a48 C:\Windows\System32\dhcpcore6.dll - ok 14:05:49.0712 0x0a48 [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] C:\Windows\System32\dnsrslvr.dll 14:05:49.0712 0x0a48 C:\Windows\System32\dnsrslvr.dll - ok 14:05:49.0713 0x0a48 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] C:\Windows\System32\eapsvc.dll 14:05:49.0713 0x0a48 C:\Windows\System32\eapsvc.dll - ok 14:05:49.0717 0x0a48 [ F0D0E883EBBDC7615DC9EDEA0FFB2817, 58F1395445018CB16ED4D3710443FB5B0E087043F6A69F7B10D72D0455958954 ] C:\Windows\System32\FWPUCLNT.DLL 14:05:49.0717 0x0a48 C:\Windows\System32\FWPUCLNT.DLL - ok 14:05:49.0721 0x0a48 [ AF75DBA674E55221B7A055B0A4345F16, 50F1B550F4EBFA946564EB66BBD17C308DCB08055017E010095A94C2EBCE208D ] C:\Windows\System32\keyiso.dll 14:05:49.0721 0x0a48 C:\Windows\System32\keyiso.dll - ok 14:05:49.0724 0x0a48 [ 9A85ABCE0FDD1AF8E79E731EB0B679F3, 2A610BEB16610FE2F2E9A50477A62A05481E8A5843A814955A0EDFF45D0304B3 ] C:\Windows\System32\dhcpcsvc.dll 14:05:49.0724 0x0a48 C:\Windows\System32\dhcpcsvc.dll - ok 14:05:49.0729 0x0a48 [ 81F6C1AE23B1C493D9E996C3103915D7, E22408B4D2EDE2F89E686A4FDCD4057BE27B86D050E9CB489F0FFB39C72AEC1D ] C:\Windows\System32\dhcpcsvc6.dll 14:05:49.0729 0x0a48 C:\Windows\System32\dhcpcsvc6.dll - ok 14:05:49.0732 0x0a48 [ 100103C6535C66265267F5EEA5F5846E, DC5972BC1FCABDC51E4DF4D5124D408BB03F2EFAF25AB70C921DD7A03A12DFD4 ] C:\Windows\System32\dnsext.dll 14:05:49.0732 0x0a48 C:\Windows\System32\dnsext.dll - ok 14:05:49.0736 0x0a48 [ 9A892B3439884C62B04718F0303A49E9, E3A772832BE440B074628FCAE06FACA451E2329BAEDD62CAB54310B44AF6BA4A ] C:\Windows\System32\eapphost.dll 14:05:49.0736 0x0a48 C:\Windows\System32\eapphost.dll - ok 14:05:49.0739 0x0a48 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] C:\Windows\System32\wlansvc.dll 14:05:49.0739 0x0a48 C:\Windows\System32\wlansvc.dll - ok 14:05:49.0742 0x0a48 [ 28CA821606669BB9215CE010767720FA, C8A1F0D6704F8F37CF8AADDFAD511FF27E56E8BCFFD4AC948DFA0329DB1F3A1E ] C:\Windows\System32\cryptui.dll 14:05:49.0742 0x0a48 C:\Windows\System32\cryptui.dll - ok 14:05:49.0744 0x0a48 [ F14A9B1778376D0B1788E402AC1F831A, 6110F29669E03F8163B5CD7124BE0FF329F36C18529FA3B8FF70FC00B2D8AA02 ] C:\Windows\System32\shacct.dll 14:05:49.0744 0x0a48 C:\Windows\System32\shacct.dll - ok 14:05:49.0747 0x0a48 [ C30A3E5DEEEBA22E782AC54C5AF5F352, 80939A7B5354032256706C6CA0C3CCC7E67CD1C1C81EAEA2CBC74997C0863662 ] C:\Windows\System32\samlib.dll 14:05:49.0747 0x0a48 C:\Windows\System32\samlib.dll - ok 14:05:49.0750 0x0a48 [ 63BFDF555DA2075A77D677829C3CCCD0, 13B0C0576A0158FBEE6C216136F8C66373C8E6592895D3D824EC67147B9190E9 ] C:\Windows\System32\uxtheme.dll 14:05:49.0750 0x0a48 C:\Windows\System32\uxtheme.dll - ok 14:05:49.0753 0x0a48 [ 84174CA0E190BB9D1EFD0F005FE13B35, B0146E651DAD4A8050FAF70026F1B7CE16EF454EB6E31088CDEBE3CD57E6591C ] C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\GdiPlus.dll 14:05:49.0753 0x0a48 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.18120_none_72d2e82386681b36\GdiPlus.dll - ok 14:05:49.0755 0x0a48 [ EE06B85BC69F18826302348A2AD089E0, 417205797CC9F6C986A863A61179784D9ADCAF1961EF8A4D9042D73C5A86509A ] C:\Windows\System32\dui70.dll 14:05:49.0755 0x0a48 C:\Windows\System32\dui70.dll - ok 14:05:49.0758 0x0a48 [ 6E1F8165C365D35C8E3C045AF0CDD481, B861360D0A014265A0BEB4CC2FE31EA05AE95120E8B07820C13A044D64C00E2B ] C:\Windows\System32\duser.dll 14:05:49.0758 0x0a48 C:\Windows\System32\duser.dll - ok 14:05:49.0760 0x0a48 [ 2CFA4569350B7F84F815E9EC34E85766, 8DE5F880F23435256E697C24BDDFA9B8994ACC3FAA063AF274BEC918FE012788 ] C:\Windows\System32\SndVolSSO.dll 14:05:49.0760 0x0a48 C:\Windows\System32\SndVolSSO.dll - ok 14:05:49.0763 0x0a48 [ 63DF770DF74ACB370EF5A16727069AAF, B8F96336BF87F1153C245D19606CBD10FBE7CF2795BCC762F2A1B57CB7C39116 ] C:\Windows\System32\hid.dll 14:05:49.0764 0x0a48 C:\Windows\System32\hid.dll - ok 14:05:49.0767 0x0a48 [ 39C5F32747B3414D1BB216FDB1DEFC58, 6FAE64CB9748304090113903A5AE9E7154BE16BA2EEA7AB3EF04AB9D79B81380 ] C:\Windows\System32\dwmapi.dll 14:05:49.0767 0x0a48 C:\Windows\System32\dwmapi.dll - ok 14:05:49.0769 0x0a48 [ EDF2A5E96BEC469DA3F64E9BDD386111, 63C91BBDFA2E087293B010A4E45625FBD1BFCAF655BFADE2F8B1C36CF804B118 ] C:\Windows\System32\xmllite.dll 14:05:49.0769 0x0a48 C:\Windows\System32\xmllite.dll - ok 14:05:49.0772 0x0a48 [ 5B2E4E90C04FB9AE9F2C5E99FF59B283, 69DC06F246C3983934CA92149B4010A51868667D6E9A54A36338B1953B4CB21E ] C:\Windows\System32\WindowsCodecs.dll 14:05:49.0772 0x0a48 C:\Windows\System32\WindowsCodecs.dll - ok 14:05:49.0774 0x0a48 [ 326C7F76A29897A892AA7726E91C1C67, 64305346B06EC14976130B0B80F14B4D5AB63E5B2A6A7B872EC9CE2BF8FADCD2 ] C:\Windows\System32\winbrand.dll 14:05:49.0774 0x0a48 C:\Windows\System32\winbrand.dll - ok 14:05:49.0776 0x0a48 [ D33E95C0A2754061233B58DC41F8094C, C957FD018DCCC8EA4BFD0EBB16A8A65B5F8AD543929EE92251C8718872BBA628 ] C:\Windows\System32\umb.dll 14:05:49.0776 0x0a48 C:\Windows\System32\umb.dll - ok 14:05:49.0777 0x0a48 [ 3C9035085141162416A0DD34DBF3F3C1, 31856241BBCC5AEC32C36BD073667001ECBA3A65C1D55B26A9CEE186CE1C03E6 ] C:\Windows\System32\wlanmsm.dll 14:05:49.0777 0x0a48 C:\Windows\System32\wlanmsm.dll - ok 14:05:49.0781 0x0a48 [ 20C06A50DFC097E134BC6FA8444CA9BC, 7739CF0ABCA918C9A49D655FB4E032163BBFB7064844F0C8EBDA282CB0225DFC ] C:\Windows\System32\wlansec.dll 14:05:49.0781 0x0a48 C:\Windows\System32\wlansec.dll - ok 14:05:49.0784 0x0a48 [ F748F53FE09D21D8ECBB6421E6792024, 38F737673F8B089B2540CE7015A4DF7081754F7CC83BFF85199B70555AF32ED0 ] C:\Windows\System32\onex.dll 14:05:49.0784 0x0a48 C:\Windows\System32\onex.dll - ok 14:05:49.0786 0x0a48 [ 5A5FEDDF02588B8F9FE4A95E5E7EAE97, 364A2DC446E9AB091A216D0EED559CEA334AA46EC0BC693CBD6CE1DE0F89317B ] C:\Windows\System32\eappcfg.dll 14:05:49.0786 0x0a48 C:\Windows\System32\eappcfg.dll - ok 14:05:49.0789 0x0a48 [ 666E57B6B51824D1D235F80A3DD70A13, B2ACCABDD5D8B23E502FE691C1DEE4A2C0EA20EDCDE5B4000557579D56D411EC ] C:\Windows\System32\eappprxy.dll 14:05:49.0789 0x0a48 C:\Windows\System32\eappprxy.dll - ok 14:05:49.0791 0x0a48 [ C1585EAA67C37A05BF6F93726FAFC069, 50401A628053871D5B864E2493018236A117F177AD1E466EDE6FB3CACBD6C5BD ] C:\Windows\System32\l2gpstore.dll 14:05:49.0791 0x0a48 C:\Windows\System32\l2gpstore.dll - ok 14:05:49.0794 0x0a48 [ 9419ABF3163B6F0E3AD3DD2B381C879F, 75029AFDB5F8A8F74A63B6C8165E77110E2FBAEC0021A9613035BFFEC646A54E ] C:\Windows\System32\WinSCard.dll 14:05:49.0794 0x0a48 C:\Windows\System32\WinSCard.dll - ok 14:05:49.0797 0x0a48 [ 1D6A771D1D702AE07919DB52C889A249, E5F3378AC40AEE6114EEAF3BF11DC1059466891CAE353E80C08622A60485C954 ] C:\Windows\System32\wlanutil.dll 14:05:49.0797 0x0a48 C:\Windows\System32\wlanutil.dll - ok 14:05:49.0800 0x0a48 [ 749F9795F01C35EEBE100A87D82B9681, 03A636328D3D97AFA6B5D6B3085EA8D27C3DBCAEA5986FD74904FC754378CD64 ] C:\Windows\System32\wlgpclnt.dll 14:05:49.0800 0x0a48 C:\Windows\System32\wlgpclnt.dll - ok 14:05:49.0802 0x0a48 [ EAADD6E47ED2A7003ACE1793B98CF63F, EE090284CA4595B6A140949A41025926CEC3CCACCD2931B6AC77A1E14D20E5B4 ] C:\Windows\System32\msxml6.dll 14:05:49.0802 0x0a48 C:\Windows\System32\msxml6.dll - ok 14:05:49.0806 0x0a48 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] C:\Windows\System32\shsvcs.dll 14:05:49.0806 0x0a48 C:\Windows\System32\shsvcs.dll - ok 14:05:49.0810 0x0a48 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] C:\Windows\System32\schedsvc.dll 14:05:49.0810 0x0a48 C:\Windows\System32\schedsvc.dll - ok 14:05:49.0812 0x0a48 [ 38B13C0DF479DBA23ECFA815159BA86E, C289C65AF3FB689AD6B770AB0E815860D9EA36FB2A8DE9F1818C63AD0FE47CBD ] C:\Windows\System32\ktmw32.dll 14:05:49.0812 0x0a48 C:\Windows\System32\ktmw32.dll - ok 14:05:49.0816 0x0a48 [ 2FCA0D2C59A855C54BAFA22AA329DF0F, ED9D26F539065D62FCCEDEEC8E509B30F4D15F8DA586C1F657ACEFE9DABAACD0 ] C:\Windows\System32\netapi32.dll 14:05:49.0816 0x0a48 C:\Windows\System32\netapi32.dll - ok 14:05:49.0818 0x0a48 [ 20B3934DB73EABA2B49B7177873CB81F, 492EAC5C51472B43DE11825358AEC4B9E3A081DACFD7513C696D6FE40F302EE5 ] C:\Windows\System32\netutils.dll 14:05:49.0818 0x0a48 C:\Windows\System32\netutils.dll - ok 14:05:49.0820 0x0a48 [ E5A4A1326A02F8E7B59E6C3270CE7202, DCB76016F9AC47E631540874DA208A089F9D529DA9628705A2869B954526BFE0 ] C:\Windows\System32\wkscli.dll 14:05:49.0820 0x0a48 C:\Windows\System32\wkscli.dll - ok 14:05:49.0822 0x0a48 [ 65BF13016A3C22775F3E17591AE5268A, 7DFE2F99D33D47E4A55ACBE83FE5B536A2983742522629414D5F941043C591D3 ] C:\Windows\System32\VaultCredProvider.dll 14:05:49.0822 0x0a48 C:\Windows\System32\VaultCredProvider.dll - ok 14:05:49.0826 0x0a48 [ E59F08ED9D2A128CE436BBFC232247F6, 9CD690C1B7CB6CA59F6AB2752A5AF2FC5A057CCBDA4166900F0AC68296972060 ] C:\Windows\System32\BioCredProv.dll 14:05:49.0826 0x0a48 C:\Windows\System32\BioCredProv.dll - ok 14:05:49.0828 0x0a48 [ 4BCC63ED1C3D15B2635A8AE2B854B3EB, 4CF29B4E896996145D54263FD06358E16C3FE2CD39C3AF6BCCE607590C637555 ] C:\Windows\System32\SmartcardCredentialProvider.dll 14:05:49.0828 0x0a48 C:\Windows\System32\SmartcardCredentialProvider.dll - ok 14:05:49.0830 0x0a48 [ E9BB0CD09DA17C71FD1B9954D75AEEF7, FF5E2F04F1FD56FDD19368150B5750275F0A44E9EA9820C8087E84ECBBF45286 ] C:\Windows\System32\credui.dll 14:05:49.0831 0x0a48 C:\Windows\System32\credui.dll - ok 14:05:49.0833 0x0a48 [ 3FAD263CE1E2A6FFF40D00043B2275E3, 0063D7DAD57CA78C3DCE6A2E7D4FF7A47DBBBBAA33F92AEF747D8102E055D1AA ] C:\Windows\System32\winbio.dll 14:05:49.0833 0x0a48 C:\Windows\System32\winbio.dll - ok 14:05:49.0835 0x0a48 [ 68ECCA523ED760AAFC03C5D587569859, CDD734279C8F9F24EA2538BAD8E91EB8C3DD74C33032DB6B2D85C19576B42707 ] C:\Windows\System32\samcli.dll 14:05:49.0835 0x0a48 C:\Windows\System32\samcli.dll - ok 14:05:49.0837 0x0a48 [ 36B8D5903CEEF0AA42A1EE002BD27FF1, CBD5C4D0E05B9A2657D816B655FFFC386807061594DEAABA754658D3152F7403 ] C:\Windows\System32\vaultcli.dll 14:05:49.0837 0x0a48 C:\Windows\System32\vaultcli.dll - ok 14:05:49.0840 0x0a48 [ 6D8CACF3B1B54943EFCF420C2D667B37, 64EB621EC68077761A0662BE78D2D17ADA982FCFE4D3BBD3A96D0D990BD8541A ] C:\Windows\System32\certCredProvider.dll 14:05:49.0840 0x0a48 C:\Windows\System32\certCredProvider.dll - ok 14:05:49.0842 0x0a48 [ FFE4BEC5C187C426A17AE76A773063A6, 0003F7DBCE52F3E7B467FBB6522623E7318E22BC2E1BB5890AFAE29682543F99 ] C:\Windows\System32\rasplap.dll 14:05:49.0842 0x0a48 C:\Windows\System32\rasplap.dll - ok 14:05:49.0844 0x0a48 [ 839F96DBAAFD3353E0B248A5E0BD2A51, 11DA5AD3EA5FF4766C12B99FB520B3CBE08581ECAF1A2FD1DC5AC835CA78FAC2 ] C:\Windows\System32\rasapi32.dll 14:05:49.0844 0x0a48 C:\Windows\System32\rasapi32.dll - ok 14:05:49.0847 0x0a48 [ FFA7172354B9256DBB2CDD75F16F33FE, 85B2F014C67C2E52540F17D561793C6633C9E98F12639CCD3854EB1EC34DD035 ] C:\Windows\System32\rasman.dll 14:05:49.0847 0x0a48 C:\Windows\System32\rasman.dll - ok 14:05:49.0850 0x0a48 [ 0915C4DB6DBC3BB9E11B7ECBBE4B7159, ACE7F85685EB92FC3AB4215122B0469E32F23B196C49F08CDA7791D3122C45DC ] C:\Windows\System32\rtutils.dll 14:05:49.0850 0x0a48 C:\Windows\System32\rtutils.dll - ok 14:05:49.0854 0x0a48 [ AC8C80DC4F1A6E60C9A762C1799F0B39, 9FD3A62B4E476CBE6D94D587826B5D8C6EB8208035A20B8E17749312C251FD6A ] C:\Windows\System32\adtschema.dll 14:05:49.0854 0x0a48 C:\Windows\System32\adtschema.dll - ok 14:05:49.0860 0x0a48 [ 808D8A8B2A3074002852BC856D419576, 1AFDEAAD071D398F4663E82D58510ABC0A30048018866C59AB53D3ECB6E6D349 ] C:\Windows\System32\comres.dll 14:05:49.0860 0x0a48 C:\Windows\System32\comres.dll - ok 14:05:49.0862 0x0a48 [ 8B0B4C5927A333A05513791758350DC4, 52FF08569678F3DA6D52FAE200E4C8C85E986805987EF1CDC0616C29664E7D64 ] C:\Windows\System32\microsoft-windows-kernel-power-events.dll 14:05:49.0862 0x0a48 C:\Windows\System32\microsoft-windows-kernel-power-events.dll - ok 14:05:49.0865 0x0a48 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] C:\Windows\System32\drivers\fltMgr.sys 14:05:49.0865 0x0a48 C:\Windows\System32\drivers\fltMgr.sys - ok 14:05:49.0867 0x0a48 [ 8E01332CC4B68BC6B5B7EFFE374442AA, A4AD1D2FD3EC2F26949DBBC388F9FFF3713AD7EB4E9220AF817EBB5223E467C6 ] C:\Windows\System32\oleacc.dll 14:05:49.0867 0x0a48 C:\Windows\System32\oleacc.dll - ok 14:05:49.0870 0x0a48 [ E6D90DC604F407B3B5E0FD285E46B2A0, 41C0E25E93E6985445410B23058B8972E7720464ABDB41D84FF10CCAC204921A ] C:\Windows\System32\fveapi.dll 14:05:49.0870 0x0a48 C:\Windows\System32\fveapi.dll - ok 14:05:49.0873 0x0a48 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] C:\Windows\System32\netprofm.dll 14:05:49.0873 0x0a48 C:\Windows\System32\netprofm.dll - ok 14:05:49.0876 0x0a48 [ 1FF7E4F548C7C372C804938F0D5B36AE, F20409733F67853CBF51FD83E4DB73260FED7B7A4F361C6B3482D78C990E16FC ] C:\Windows\System32\netcfgx.dll 14:05:49.0876 0x0a48 C:\Windows\System32\netcfgx.dll - ok 14:05:49.0879 0x0a48 [ FD049C25A168D3DE310D9207B7B6367B, 48966605E7CF87996068AC1A2E563F90F6F152E710323792C633E10BCBA480E4 ] C:\Windows\System32\UIAutomationCore.dll 14:05:49.0879 0x0a48 C:\Windows\System32\UIAutomationCore.dll - ok 14:05:49.0881 0x0a48 [ C87F28A34B3840F4B40011D170B1A159, 4FB94B9197C5FA73E1A74BA8DCD4ACE830C927FD67B117426714CCD7396E3CB9 ] C:\Windows\System32\fvecerts.dll 14:05:49.0881 0x0a48 C:\Windows\System32\fvecerts.dll - ok 14:05:49.0883 0x0a48 [ 1C3E8371377E988B683797A132EFFE1B, CC4A9B9084F163428973A04D77CADDAA838C5761BF9E55971FAD7275BB9D2194 ] C:\Windows\System32\taskcomp.dll 14:05:49.0883 0x0a48 C:\Windows\System32\taskcomp.dll - ok 14:05:49.0888 0x0a48 [ EAFC149CD3BD78C443E31BB157841197, 9045425B0C7A23D5A96D1084FB3B1DED35852B3FB1DCB942DEB4A5B906126CA4 ] C:\Windows\System32\tbs.dll 14:05:49.0888 0x0a48 C:\Windows\System32\tbs.dll - ok 14:05:49.0891 0x0a48 [ A12829E9974F57E9B5DBFEA7C93190F6, 1EC2A36CAF30A706B6082C5CA79B6A33FA99342E144508DB1415D1611E631EBC ] C:\Windows\System32\UXInit.dll 14:05:49.0891 0x0a48 C:\Windows\System32\UXInit.dll - ok 14:05:49.0895 0x0a48 [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] C:\Windows\System32\drivers\http.sys 14:05:49.0895 0x0a48 C:\Windows\System32\drivers\http.sys - ok 14:05:49.0898 0x0a48 [ 18AB2E5A40064ED5F7791AC5946A90F3, B7536CE56702C23B1CEC3E1B6C78866E0A76808B85A92AF3733D9ED9429E004C ] C:\Windows\System32\msimg32.dll 14:05:49.0898 0x0a48 C:\Windows\System32\msimg32.dll - ok 14:05:49.0901 0x0a48 [ E2D56AE1D40E3725084054CD8E9CFBB1, 7548C22DE09DCCC9BA41BA1DE331CFD0B18DDA00A40E27DFB8EA551CDF7050BC ] C:\Windows\System32\wiarpc.dll 14:05:49.0901 0x0a48 C:\Windows\System32\wiarpc.dll - ok 14:05:49.0904 0x0a48 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] C:\Windows\System32\spoolsv.exe 14:05:49.0904 0x0a48 C:\Windows\System32\spoolsv.exe - ok 14:05:49.0907 0x0a48 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] C:\Windows\System32\BFE.DLL 14:05:49.0907 0x0a48 C:\Windows\System32\BFE.DLL - ok 14:05:49.0909 0x0a48 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] C:\Windows\System32\drivers\bowser.sys 14:05:49.0909 0x0a48 C:\Windows\System32\drivers\bowser.sys - ok 14:05:49.0913 0x0a48 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] C:\Windows\System32\drivers\mpsdrv.sys 14:05:49.0913 0x0a48 C:\Windows\System32\drivers\mpsdrv.sys - ok 14:05:49.0916 0x0a48 [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] C:\Windows\System32\MPSSVC.dll 14:05:49.0916 0x0a48 C:\Windows\System32\MPSSVC.dll - ok 14:05:49.0917 0x0a48 [ D93A937A2A9D2CBC06B3A615A197011F, E55028F641512EC22CEC4674F7E380FE71059A21E51ECB345DDB769A276F30D1 ] C:\Windows\System32\PSHED.DLL 14:05:49.0917 0x0a48 C:\Windows\System32\PSHED.DLL - ok 14:05:49.0920 0x0a48 [ 1F5497D7D3D79C7BF0AB0C8B4C5BFE6E, 27848861F25C00168A1A0FE0722D8E327D2251C4FB69A7968EE5722ECCD129E3 ] C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll 14:05:49.0920 0x0a48 C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll - ok 14:05:49.0924 0x0a48 [ 019C372B1A9DA73A22D0D35A4D40F5C9, 6DDAF455D528FDC2F8271E5909289E76E54D81AC5563433653FC7E0C6EA5BB70 ] C:\Windows\System32\wfapigp.dll 14:05:49.0924 0x0a48 C:\Windows\System32\wfapigp.dll - ok 14:05:49.0935 0x0a48 [ 7F8678C59F188528D60104E697C2361E, 9B4D262B10CB09543ACA9A78482F4EDD905791D2C8C518B574EBA440A71A85B7 ] C:\Windows\System32\mscms.dll 14:05:49.0935 0x0a48 C:\Windows\System32\mscms.dll - ok 14:05:49.0937 0x0a48 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] C:\Windows\System32\pcasvc.dll 14:05:49.0937 0x0a48 C:\Windows\System32\pcasvc.dll - ok 14:05:49.0948 0x0a48 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] C:\Windows\System32\snmptrap.exe 14:05:49.0948 0x0a48 C:\Windows\System32\snmptrap.exe - ok 14:05:49.0955 0x0a48 [ 4A1E806032413883BAF1E9A6047BC668, 4D8EA2B36B57C7ABF131193B9C23B1A7209A3464C2716C471C7F8C11E0FA9E62 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelEvents.dll 14:05:49.0955 0x0a48 C:\Windows\Microsoft.NET\Framework\v4.0.30319\ServiceModelEvents.dll - ok 14:05:49.0959 0x0a48 [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] C:\Windows\System32\drivers\mrxsmb.sys 14:05:49.0959 0x0a48 C:\Windows\System32\drivers\mrxsmb.sys - ok 14:05:49.0963 0x0a48 [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] C:\Windows\System32\drivers\mrxsmb10.sys 14:05:49.0964 0x0a48 C:\Windows\System32\drivers\mrxsmb10.sys - ok 14:05:49.0966 0x0a48 [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] C:\Windows\System32\drivers\mrxsmb20.sys 14:05:49.0966 0x0a48 C:\Windows\System32\drivers\mrxsmb20.sys - ok 14:05:49.0977 0x0a48 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] C:\Windows\System32\wkssvc.dll 14:05:49.0977 0x0a48 C:\Windows\System32\wkssvc.dll - ok 14:05:49.0987 0x0a48 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] C:\Windows\System32\drivers\parport.sys 14:05:49.0987 0x0a48 C:\Windows\System32\drivers\parport.sys - ok 14:05:49.0991 0x0a48 [ B362181ED3771DC03B4141927C80F801, 69514E5177A0AEA89C27C2234712F9F82E8D8F99E1FD4273898C9324C6FF7472 ] C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe 14:05:49.0991 0x0a48 C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe - ok 14:05:49.0994 0x0a48 [ B3892E6DA8E2C8CE4B0A9D3EB9A185E5, AE163388201EF2F119E11265586E7DA32C6E5B348E0CC32E3F72E21EBFD0843B ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_50916076bcb9a742\msvcr90.dll 14:05:49.0994 0x0a48 C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_50916076bcb9a742\msvcr90.dll - ok 14:05:49.0997 0x0a48 [ 7B851A8018B1EA00A69707A390004884, DAE654713EF1DC66C8C2D27752B659081794063A7D522D1F680AA9A6E7FBA9FD ] C:\Windows\System32\cryptnet.dll 14:05:49.0997 0x0a48 C:\Windows\System32\cryptnet.dll - ok 14:05:50.0000 0x0a48 [ 7CA1BECEA5DE2643ADDAD32670E7A4C9, E3AB4CC52A97E3855D7EAB87363F807FDD2162ED8C76A036CD71549ED64E7797 ] C:\Windows\System32\cryptsvc.dll 14:05:50.0000 0x0a48 C:\Windows\System32\cryptsvc.dll - ok 14:05:50.0003 0x0a48 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] C:\Windows\System32\dps.dll 14:05:50.0003 0x0a48 C:\Windows\System32\dps.dll - ok 14:05:50.0006 0x0a48 [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] C:\Windows\System32\IKEEXT.DLL 14:05:50.0006 0x0a48 C:\Windows\System32\IKEEXT.DLL - ok 14:05:50.0011 0x0a48 [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC9F9B3FF45FCA7F5CF242C9E92 ] C:\Windows\System32\nlasvc.dll 14:05:50.0011 0x0a48 C:\Windows\System32\nlasvc.dll - ok 14:05:50.0015 0x0a48 [ 5845B1C54380FB980F68024B3A8B1E66, A7215D59B5C452F1494CFEC0DFC1E4ABE2D17EA0E1D07FBA062901BC3DED21AF ] C:\Windows\System32\vpnikeapi.dll 14:05:50.0015 0x0a48 C:\Windows\System32\vpnikeapi.dll - ok 14:05:50.0019 0x0a48 [ 140D9F911182357626165EA0BEB98C4F, 9B24047BF104895FCFDB68694934BDDD92DE98A0E6334A62E987C6DCBFFB9C5B ] C:\Windows\System32\ncsi.dll 14:05:50.0019 0x0a48 C:\Windows\System32\ncsi.dll - ok 14:05:50.0022 0x0a48 [ A2F17346CC5C502D4E29EF986BD17D34, 786E1DA5DBE8B56A8708F361425059EC6DB89C43FD4A136090BAB44B084CC204 ] C:\Windows\System32\PeerDistSh.dll 14:05:50.0022 0x0a48 C:\Windows\System32\PeerDistSh.dll - ok 14:05:50.0023 0x0a48 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] C:\Windows\System32\sstpsvc.dll 14:05:50.0023 0x0a48 C:\Windows\System32\sstpsvc.dll - ok 14:05:50.0025 0x0a48 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] C:\Windows\System32\provsvc.dll 14:05:50.0025 0x0a48 C:\Windows\System32\provsvc.dll - ok 14:05:50.0028 0x0a48 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] C:\Windows\System32\drivers\PEAuth.sys 14:05:50.0028 0x0a48 C:\Windows\System32\drivers\PEAuth.sys - ok 14:05:50.0030 0x0a48 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] C:\Windows\System32\drivers\secdrv.sys 14:05:50.0030 0x0a48 C:\Windows\System32\drivers\secdrv.sys - ok 14:05:50.0032 0x0a48 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] C:\Windows\System32\drivers\srvnet.sys 14:05:50.0032 0x0a48 C:\Windows\System32\drivers\srvnet.sys - ok 14:05:50.0034 0x0a48 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] C:\Windows\System32\drivers\tcpipreg.sys 14:05:50.0034 0x0a48 C:\Windows\System32\drivers\tcpipreg.sys - ok 14:05:50.0036 0x0a48 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] C:\Windows\System32\sysmain.dll 14:05:50.0036 0x0a48 C:\Windows\System32\sysmain.dll - ok 14:05:50.0038 0x0a48 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] C:\Windows\System32\wbem\WMIsvc.dll 14:05:50.0038 0x0a48 C:\Windows\System32\wbem\WMIsvc.dll - ok 14:05:50.0041 0x0a48 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] C:\Windows\System32\trkwks.dll 14:05:50.0041 0x0a48 C:\Windows\System32\trkwks.dll - ok 14:05:50.0045 0x0a48 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] C:\Windows\System32\drivers\srv2.sys 14:05:50.0045 0x0a48 C:\Windows\System32\drivers\srv2.sys - ok 14:05:50.0047 0x0a48 [ 704314FD398C81D5F342CAA5DF7B7F21, CDA660E1E8AAE0789780B6B9604B138E67B2BDD1404A5E4C2354B35879D43085 ] C:\Windows\System32\wbemcomn.dll 14:05:50.0047 0x0a48 C:\Windows\System32\wbemcomn.dll - ok 14:05:50.0050 0x0a48 [ 881D9F2D6E04E1C323050CF1574870F7, DA02C415977A2E50C3D1E96E227234E7195BD33903C446A17FBE0FA8D14A164F ] C:\Windows\System32\wbem\WinMgmtR.dll 14:05:50.0050 0x0a48 C:\Windows\System32\wbem\WinMgmtR.dll - ok 14:05:50.0052 0x0a48 [ 701C9EB15E1E23D22F7C7184C0506673, 1CD59E8B8889C93B55F600DA1A7246810E8EAB725EFEF80327AC96344AC596A6 ] C:\Windows\System32\wbem\WmiDcPrv.dll 14:05:50.0052 0x0a48 C:\Windows\System32\wbem\WmiDcPrv.dll - ok 14:05:50.0056 0x0a48 [ CA9F7888B524D8100B977C81F44C3234, 57F3353F89724147D8AC8B69B12C1303DF26978309776F5F8CCF074526A915D3 ] C:\Windows\System32\winhttp.dll 14:05:50.0057 0x0a48 C:\Windows\System32\winhttp.dll - ok 14:05:50.0065 0x0a48 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] C:\Windows\System32\drivers\srv.sys 14:05:50.0065 0x0a48 C:\Windows\System32\drivers\srv.sys - ok 14:05:50.0069 0x0a48 [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] C:\Windows\System32\iphlpsvc.dll 14:05:50.0069 0x0a48 C:\Windows\System32\iphlpsvc.dll - ok 14:05:50.0073 0x0a48 [ CE292C4C10B8DB6070F262EA2733F0DC, 0A685263DA0277F2D215C4C22BF39E2F869B632B42B8C992E068129F57177BE1 ] C:\Windows\System32\sqmapi.dll 14:05:50.0073 0x0a48 C:\Windows\System32\sqmapi.dll - ok 14:05:50.0078 0x0a48 [ CFC7D8289D2B5F3CF8D16E2DB7F93D4A, 61B4D669C692775EF361445293163E84FAD8636AC49C8047BE806DB4E4093291 ] C:\Windows\System32\wbem\fastprox.dll 14:05:50.0078 0x0a48 C:\Windows\System32\wbem\fastprox.dll - ok 14:05:50.0080 0x0a48 [ E3E811471DE781900FF21C1FD84E941E, 2A47FF52D1D6480AAD1919382E783EA184BF926311F8C7E466FEBE9F6FB88FD6 ] C:\Windows\System32\ntdsapi.dll 14:05:50.0080 0x0a48 C:\Windows\System32\ntdsapi.dll - ok 14:05:50.0091 0x0a48 [ FB19FC5951A88F3C523E35C2C98D23C0, FF0DB8BF0C68DA0D09272E8181D2B5409C8850BB2F31AEA3AC4CD14C5A420A59 ] C:\Windows\System32\webio.dll 14:05:50.0091 0x0a48 C:\Windows\System32\webio.dll - ok 14:05:50.0094 0x0a48 [ 827CB0D6C3F8057EA037FF271F8E9795, 82760DBDDD38D2A31CAAF51D065DF4E7E1D0F0C22733A0AF653776EBF7B79470 ] C:\Windows\System32\imageres.dll 14:05:50.0094 0x0a48 C:\Windows\System32\imageres.dll - ok 14:05:50.0096 0x0a48 [ 13337A3FB17F2242487FD45488ED0485, C174F8652118876494336AB88A65D594E0E6CCBAB20CC6BA08E6B253855A01CA ] C:\Windows\System32\vssapi.dll 14:05:50.0096 0x0a48 C:\Windows\System32\vssapi.dll - ok 14:05:50.0098 0x0a48 [ 28E2231BD34A39C854BDF3923AB2FF86, A95179068F7B86E04F976B724F155DA86253B7F4414F43DBD95F2058282B99E4 ] C:\Windows\System32\ssdpapi.dll 14:05:50.0098 0x0a48 C:\Windows\System32\ssdpapi.dll - ok 14:05:50.0100 0x0a48 [ B940289C83121046BD6A60ACC6028593, EBD1C2C0A8EBB201924536AB5C6E032C12B9E081A153CC079748E1D6D625F0DF ] C:\Windows\System32\vsstrace.dll 14:05:50.0100 0x0a48 C:\Windows\System32\vsstrace.dll - ok 14:05:50.0102 0x0a48 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] C:\Windows\System32\browser.dll 14:05:50.0102 0x0a48 C:\Windows\System32\browser.dll - ok 14:05:50.0105 0x0a48 [ E4B72E71EC37A59FE574A998A0C0EB9B, C17B06C936FC47B6AA5221ABF1DDE283F59E5751BEE9CDBCCBAF25CD4E7232AD ] C:\Windows\System32\netmsg.dll 14:05:50.0105 0x0a48 C:\Windows\System32\netmsg.dll - ok 14:05:50.0107 0x0a48 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] C:\Windows\System32\srvsvc.dll 14:05:50.0107 0x0a48 C:\Windows\System32\srvsvc.dll - ok 14:05:50.0110 0x0a48 [ A399514D3B28C9A3453A486BBAAFF1C7, 487CAA68CF4EE0C9DC26975C694A2780ADEFB687D1EDF929CE6E1C7E3722FFE9 ] C:\Windows\System32\wdscore.dll 14:05:50.0110 0x0a48 C:\Windows\System32\wdscore.dll - ok 14:05:50.0112 0x0a48 [ 89E783711AF91AF09E1EF30EF3107446, CA91DABED7508A86A4AFA5F99A4A78D0BA3577168B04C8E3462FC4D55FA33FFD ] C:\Windows\System32\sscore.dll 14:05:50.0112 0x0a48 C:\Windows\System32\sscore.dll - ok 14:05:50.0114 0x0a48 [ C5B0324DB461559ADD070E632A6919FA, AB09CACB5B7DD372B27921A5E01220552A611CECA27EF87961001FA467FDED45 ] C:\Windows\System32\wbem\wbemprox.dll 14:05:50.0114 0x0a48 C:\Windows\System32\wbem\wbemprox.dll - ok 14:05:50.0117 0x0a48 [ AE9898D5600A232CD8AE3298692162E5, 8B94BA9C404B8A21CE023335960E77C73245FB30015161EEFF48573DDB7E6922 ] C:\Windows\System32\clusapi.dll 14:05:50.0117 0x0a48 C:\Windows\System32\clusapi.dll - ok 14:05:50.0122 0x0a48 [ 2AF094C822BD6094F14A8E85FB51D52A, F70A4FEC66E64245237D9D1A4C2C87168A26F224FCE648A3D7065E95259887D2 ] C:\Windows\System32\resutils.dll 14:05:50.0122 0x0a48 C:\Windows\System32\resutils.dll - ok 14:05:50.0124 0x0a48 [ 6383C60EC0133B14F5705F96369421B2, EAB3FA2344B853148F199F744E716FBB8E9331B9DB588F784274599B6BCE2335 ] C:\Windows\System32\hnetcfg.dll 14:05:50.0124 0x0a48 C:\Windows\System32\hnetcfg.dll - ok 14:05:50.0129 0x0a48 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] C:\Windows\System32\wdi.dll 14:05:50.0129 0x0a48 C:\Windows\System32\wdi.dll - ok 14:05:50.0131 0x0a48 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] C:\Windows\System32\wpdbusenum.dll 14:05:50.0131 0x0a48 C:\Windows\System32\wpdbusenum.dll - ok 14:05:50.0134 0x0a48 [ ECF036299AA554B5E0455262857B39D0, E7A08E4AA1677291FB55E1B43511B912D45676652E35C6BA75D1604A8BE5B1D0 ] C:\Windows\System32\diagperf.dll 14:05:50.0134 0x0a48 C:\Windows\System32\diagperf.dll - ok 14:05:50.0138 0x0a48 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] C:\Windows\System32\hidserv.dll 14:05:50.0138 0x0a48 C:\Windows\System32\hidserv.dll - ok 14:05:50.0147 0x0a48 [ 585EB475E7AF55C9065256E8FFB751A1, 5AE557013435DF993F0E872B90A94CBB9E80FA8A080469C300EBCEE62CABA92F ] C:\Windows\System32\wbem\wbemcore.dll 14:05:50.0147 0x0a48 C:\Windows\System32\wbem\wbemcore.dll - ok 14:05:50.0149 0x0a48 [ F8E882C10AF4C29E378D1E28D4817CB1, 1164096E044FA9B38CCC462315B9A2F7C43C472091F539F6A4BF7B5EAA389410 ] C:\Windows\System32\pnpts.dll 14:05:50.0149 0x0a48 C:\Windows\System32\pnpts.dll - ok 14:05:50.0155 0x0a48 [ 7FFD52D73352806969D424EF327D10A7, DD44B084F052EF798997D7A8578E98DD4EF3F0E2A0C522DA2CC169D362C7B900 ] C:\Windows\System32\radardt.dll 14:05:50.0155 0x0a48 C:\Windows\System32\radardt.dll - ok 14:05:50.0157 0x0a48 [ F0016853FA3F38F55FD868FF74C0359B, 49A6A6D610591D0F2FF8A88C8E72D6DCABB8C5FE5D3E995F0CE0E8FC073BA289 ] C:\Windows\System32\wdiasqmmodule.dll 14:05:50.0157 0x0a48 C:\Windows\System32\wdiasqmmodule.dll - ok 14:05:50.0160 0x0a48 [ 5AE88135C6A86FCD67BA16AFBB1C8389, 0FC750B5C84F1AFBE93E8A23410360F4B068D367A9AF6FF2E3F6160DA5005DE5 ] C:\Windows\System32\wbem\esscli.dll 14:05:50.0160 0x0a48 C:\Windows\System32\wbem\esscli.dll - ok 14:05:50.0163 0x0a48 [ 7E82616BEE76BF5EAA5B30F681414E21, 2138D743C4C09ECD829E194CA42934CB044BFF400921DA9B5FA50371E191656E ] C:\Windows\System32\perftrack.dll 14:05:50.0163 0x0a48 C:\Windows\System32\perftrack.dll - ok 14:05:50.0167 0x0a48 [ 590D5C506044FE02FF7643E32FF9BDAC, B8178A45E1DB6A39501E95CE4A2B2A1A88119367EC8DA7877120575A3EA47D16 ] C:\Windows\System32\wer.dll 14:05:50.0167 0x0a48 C:\Windows\System32\wer.dll - ok 14:05:50.0171 0x0a48 [ 8B794AE6D5C7D42092804BC39A2EB8F6, 0C8078442EABA31D48019F1A3B7941CC19D9B3AA571FFA5DCD4E19F67DEBF723 ] C:\Windows\System32\aepic.dll 14:05:50.0171 0x0a48 C:\Windows\System32\aepic.dll - ok 14:05:50.0175 0x0a48 [ 15E298B5EC5B89C5994A59863969D9FF, 8D38B2E023462D0804F72E907D11FF72CE84540EA3B8D83F411C602C3F6A1177 ] C:\Windows\System32\npmproxy.dll 14:05:50.0175 0x0a48 C:\Windows\System32\npmproxy.dll - ok 14:05:50.0178 0x0a48 [ 40CAEEE0EAF1B8569F7C8DF6420F2CB9, E18D66455D00A6D2A2D7CC0833C233FE8A6DD910B59D6B5B5F82EF91450858DF ] C:\Windows\System32\sfc.dll 14:05:50.0178 0x0a48 C:\Windows\System32\sfc.dll - ok 14:05:50.0182 0x0a48 [ 84799328D87B3091A3BDD251E1AD31F9, F85521215924388830DBB13580688DB70B46AF4C7D82D549D09086438F8D237B ] C:\Windows\System32\sfc_os.dll 14:05:50.0182 0x0a48 C:\Windows\System32\sfc_os.dll - ok 14:05:50.0184 0x0a48 [ 0B7E85364CB878E2AD531DB7B601A9E5, F5AD3018427F1CD68450EE5CB55AA9572546322580E0FB1E7888702A291C2380 ] C:\Windows\System32\NapiNSP.dll 14:05:50.0184 0x0a48 C:\Windows\System32\NapiNSP.dll - ok 14:05:50.0187 0x0a48 [ E98278865E8DABA21CFE5FE4BE34210A, 3BB431A9F6476EA98C17DF46BA5DFA265E74328D84875E402236ED12E50B6330 ] C:\Windows\System32\PortableDeviceApi.dll 14:05:50.0187 0x0a48 C:\Windows\System32\PortableDeviceApi.dll - ok 14:05:50.0190 0x0a48 [ 5CF640EDDB1E40A5AB1BB743BCDEC610, 0313AA3F713C9F5B84DBB0B4DE78A96B173E9F7B4CF61C10FDC7DAE952DB04E5 ] C:\Windows\System32\pnrpnsp.dll 14:05:50.0190 0x0a48 C:\Windows\System32\pnrpnsp.dll - ok 14:05:50.0192 0x0a48 [ 5DF5D8CFD9B9573FA3B2C89D9061A240, 990EA273B640DF2D7E800C0CFF18550259C605A4951CD82CD9F1E7B6FF0C9533 ] C:\Windows\System32\winrnr.dll 14:05:50.0192 0x0a48 C:\Windows\System32\winrnr.dll - ok 14:05:50.0194 0x0a48 [ D99621C0735B21DCC8BC4FEF02F379EF, C9FAD74DD80B6CCA95B83B767BB55644E775E8DC3FFC05CD89AEF16686F902FD ] C:\Windows\System32\Apphlpdm.dll 14:05:50.0194 0x0a48 C:\Windows\System32\Apphlpdm.dll - ok 14:05:50.0196 0x0a48 [ C693E642ACFBDD76433AF6BE3C3EEE6F, 5241C30CCB095B10B10AD11F42F57B2DEA362C7F6DA36A9A5B23E4DFF113CFD7 ] C:\Windows\System32\PortableDeviceConnectApi.dll 14:05:50.0196 0x0a48 C:\Windows\System32\PortableDeviceConnectApi.dll - ok 14:05:50.0198 0x0a48 [ A63DC5C2EA944E6657203E0C8EDEAF61, F7AD4B09AFB301CE46DF695B22114331A57D52E6D4163FF74787BF68CCF44C78 ] C:\Windows\System32\dllhost.exe 14:05:50.0198 0x0a48 C:\Windows\System32\dllhost.exe - ok 14:05:50.0201 0x0a48 [ ED6EE83D61EBC683C2CD8E899EA6FEBE, F82592908D038C44D9F2E5C5B7BC663A2D370FC565F40420E1138A9E55F0E7EB ] C:\Windows\System32\rasadhlp.dll 14:05:50.0201 0x0a48 C:\Windows\System32\rasadhlp.dll - ok 14:05:50.0202 0x0a48 [ 371E3B05894549113D07CD3081ED55EF, 9973678AC0F50B1F02B379B1D4A7DDF317B724D65BE3FF635FD751EDD1D96B5A ] C:\Windows\System32\wbem\repdrvfs.dll 14:05:50.0202 0x0a48 C:\Windows\System32\wbem\repdrvfs.dll - ok 14:05:50.0205 0x0a48 [ 776AE0564F8B1C282E331FD95A1BDC5F, 601CFCA3922FFEA46A54AD323845A76A12FC6AF9FF64E9B0AE294FBB1AFCF4CB ] C:\Windows\System32\wbem\wbemsvc.dll 14:05:50.0205 0x0a48 C:\Windows\System32\wbem\wbemsvc.dll - ok 14:05:50.0207 0x0a48 [ 5610B0425518D185331CB8E968D060E6, E235186C3BF266EE9EC733D2CFF35E3A65DE039C19B14260F4054F34B5E8AD41 ] C:\Windows\System32\wbem\wmiutils.dll 14:05:50.0207 0x0a48 C:\Windows\System32\wbem\wmiutils.dll - ok 14:05:50.0209 0x0a48 [ 75F5E1FE8D55CF8E577E0EC5F2290D3F, F4E2C81F0834018052A481AE8D7DF4780302A6844160CCDC09F7D82D3B992BDE ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll 14:05:50.0209 0x0a48 C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll - ok 14:05:50.0212 0x0a48 [ 0B31464B7B2D616BD5F7036673588EC1, AAC717D7FB02D5F7CC11AECC5C87FE6B7224340C569EBF7B77BD8C9F79FAA190 ] C:\Windows\System32\IDStore.dll 14:05:50.0212 0x0a48 C:\Windows\System32\IDStore.dll - ok 14:05:50.0214 0x0a48 [ 72E953215CADE1A726C04AAFDF6B463D, 473866333D2241BAD6918D21EBCBE8F8EEA9344D816788300BCA290A89FBD3DD ] C:\Windows\System32\taskhost.exe 14:05:50.0214 0x0a48 C:\Windows\System32\taskhost.exe - ok 14:05:50.0216 0x0a48 [ B9A8CBCFCD3EC9D2EA4740AF347BF108, 97FA304E3880BC863D999F441AE47CB8ADF00D2DEC2A52ACD8FBD02CC096786A ] C:\Windows\System32\mpr.dll 14:05:50.0216 0x0a48 C:\Windows\System32\mpr.dll - ok 14:05:50.0219 0x0a48 [ 61AC3EFDFACFDD3F0F11DD4FD4044223, 538FE1012FEDC72727A8DE0C2C01944B3D35C29812ECEF88E95AAC07235E0B0B ] C:\Windows\System32\userinit.exe 14:05:50.0219 0x0a48 C:\Windows\System32\userinit.exe - ok 14:05:50.0221 0x0a48 [ 505BF4D1CADEB8D4F8BCD08D944DE25D, 526F07768471F4457CBEAB7093AF0B0242044C89A80A347DB47F44EBADEEA68D ] C:\Windows\System32\dwm.exe 14:05:50.0221 0x0a48 C:\Windows\System32\dwm.exe - ok 14:05:50.0223 0x0a48 [ 754AFC50022C95DA7C86B7020DB78136, 81C58F303DA2E0EC066261890C1D638EE02D2B579BBCB1BB398EDF6A0EBA671E ] C:\Windows\System32\dwmredir.dll 14:05:50.0223 0x0a48 C:\Windows\System32\dwmredir.dll - ok 14:05:50.0225 0x0a48 [ 497E59D9F01C6F247E72222A61835119, 4C31900BA2F911B2A5AE8F7FCE267DCE17655B20A6B71CD4E38FE1B1692142D1 ] C:\Windows\System32\dwmcore.dll 14:05:50.0225 0x0a48 C:\Windows\System32\dwmcore.dll - ok 14:05:50.0228 0x0a48 [ 3C1936A12C62254F914A01BBC6A8DC69, 0068F7A8B0D9E9776B44EAD99007B0CE5A5600633F2B477E9EFAAC644408C70E ] C:\Windows\System32\d3d10_1.dll 14:05:50.0228 0x0a48 C:\Windows\System32\d3d10_1.dll - ok 14:05:50.0230 0x0a48 [ D4212AB475A3B25EC4DF574536C3EDC5, F8BBEECB66BA6DDE5A64ED41D8BF95A1C81470552B4BFD5B11D888156289CCDD ] C:\Windows\System32\d3d10_1core.dll 14:05:50.0230 0x0a48 C:\Windows\System32\d3d10_1core.dll - ok 14:05:50.0232 0x0a48 [ D4F264FE23F8953D840904418220C15E, 72EAF30265A0CC88DEC0FCA7869734D8C93572457C61A2BF1BDFFB20C061DBCD ] C:\Windows\System32\dxgi.dll 14:05:50.0232 0x0a48 C:\Windows\System32\dxgi.dll - ok 14:05:50.0234 0x0a48 [ 74AF6AA2E8B3180AADAE5FE8813CB1CD, FB1C334A76B4E51B1C91141CB7E8B435FE4A8403072112B5F1BAC917649FFC22 ] C:\Windows\System32\localspl.dll 14:05:50.0234 0x0a48 C:\Windows\System32\localspl.dll - ok 14:05:50.0236 0x0a48 [ 629181C26A78EB66B0B4E774E5AC2882, DE39D01ADC4123C81EF77B24D7FC2F66C27CC2D31248EF53C52CD31AC90A95CE ] C:\Windows\System32\spoolss.dll 14:05:50.0236 0x0a48 C:\Windows\System32\spoolss.dll - ok 14:05:50.0238 0x0a48 [ 9E4B0E7472B4CEBA9E17F440B8CB0AB8, B1A9B2EF000917214C0198958CBD239D1D91B1720EC40DF041262A34D302AD74 ] C:\Windows\System32\winspool.drv 14:05:50.0238 0x0a48 C:\Windows\System32\winspool.drv - ok 14:05:50.0240 0x0a48 [ 63D1535235FDD0E80C76EBF0FE6AA392, B40829A705BAAD9B71A8E08BE2871BDB43469F8B97708469DF4F08F94195E28A ] C:\Windows\System32\HP1006LM.DLL 14:05:50.0240 0x0a48 C:\Windows\System32\HP1006LM.DLL - ok 14:05:50.0242 0x0a48 [ 03CF941D031F30272D3063E5A4D686F5, 641189DA98156FC8DFABF766EB34726F64E5901AF5F74B42C392C218C892F179 ] C:\Windows\System32\PrintIsolationProxy.dll 14:05:50.0242 0x0a48 C:\Windows\System32\PrintIsolationProxy.dll - ok 14:05:50.0244 0x0a48 [ 322FD75A97DBA67FC8F97A9957F857F1, 52CC0FBBE9769C0C751F886E0ED58ED263FB9175F323C603E7BAB876AE60D196 ] C:\Windows\System32\mdimon.dll 14:05:50.0244 0x0a48 C:\Windows\System32\mdimon.dll - ok 14:05:50.0246 0x0a48 [ A6C29DB53ECA94FA8591C5388D604B82, F25E95BA669422286A8FA3A68E0C639A2F06319B6DC8FA641C965CFB27A50BD6 ] C:\Windows\System32\msi.dll 14:05:50.0246 0x0a48 C:\Windows\System32\msi.dll - ok 14:05:50.0248 0x0a48 [ 126F8331BD023178C7F0EF2F5EDE16B3, F56DDCC9F282274F2EB073CE33B0CAB7EFC759B9C39B19909FE901E89DA0307F ] C:\Windows\System32\FXSMON.dll 14:05:50.0248 0x0a48 C:\Windows\System32\FXSMON.dll - ok 14:05:50.0250 0x0a48 [ A5030E7E41E6F6346EFC42ACDFDE5546, FDA054B011BBD189198EB83BE62143A10045E8BFF430985A3D46554876B24215 ] C:\Windows\System32\hpf3l70w.dll 14:05:50.0250 0x0a48 C:\Windows\System32\hpf3l70w.dll - ok 14:05:50.0253 0x0a48 [ 1220595CABA75AB91A6B3FA3B89483CC, 313DFE385336D00DAFBC8DF30F001859C77DEB214BB3F874CE42F22734FFAE4E ] C:\Windows\System32\snmpapi.dll 14:05:50.0253 0x0a48 C:\Windows\System32\snmpapi.dll - ok 14:05:50.0256 0x0a48 [ B390C1D825C7687493BEDE237C6C2F25, 969C456E52695E8AECDDF80995F05D18F6F686AA1AE58A9A661C3069CDF5B1BD ] C:\Windows\System32\tcpmon.dll 14:05:50.0256 0x0a48 C:\Windows\System32\tcpmon.dll - ok 14:05:50.0258 0x0a48 [ 6357E2B68753A1F5CF4A68A25C4FD14A, F56BFEEACBB9DAE084F4C275DF0086091F5B83DE7183FA33F4445CD31FBB44E3 ] C:\Windows\System32\wsnmp32.dll 14:05:50.0258 0x0a48 C:\Windows\System32\wsnmp32.dll - ok 14:05:50.0260 0x0a48 [ 923CDD30092DB73EC4A0EBCDDD16C686, 83F94BE7C324FFADCA13780C617A8CAA1C7CD80F205EACA8FBADA83865D1E0D3 ] C:\Windows\System32\usbmon.dll 14:05:50.0260 0x0a48 C:\Windows\System32\usbmon.dll - ok 14:05:50.0262 0x0a48 [ A8EB761DE499242BECF153B2B34F020E, 3C6F477B5143FCE607FDB088AE471C7037E2BAC01D8CE8C57B5CF1BE57E78D46 ] C:\Windows\System32\WSDMon.dll 14:05:50.0262 0x0a48 C:\Windows\System32\WSDMon.dll - ok 14:05:50.0263 0x0a48 [ 73F6C5223F7E9B5780DD4A6C30FCF569, 121A361A572EFC6AC964300DA93BF28DC11E55DDCA29A7C6E6FD12955FBA68B8 ] C:\Windows\System32\WSDApi.dll 14:05:50.0263 0x0a48 C:\Windows\System32\WSDApi.dll - ok 14:05:50.0265 0x0a48 [ DB846EECA70EE9D2E2FF31147C57B0F4, 1086310477697F43EB156314804B7E9100E04966EF3934F9F5E37112C5129954 ] C:\Windows\System32\webservices.dll 14:05:50.0265 0x0a48 C:\Windows\System32\webservices.dll - ok 14:05:50.0267 0x0a48 [ 89D90579E5FB1469CB0464F6512E42B7, 0E85C6935FEAA219C923FF63D17F7C3AF72FF5028E0FF95B66092C6DF64C665C ] C:\Windows\System32\fundisc.dll 14:05:50.0267 0x0a48 C:\Windows\System32\fundisc.dll - ok 14:05:50.0271 0x0a48 [ F34CFADA6C48DAA41B996D24C7D8D3CA, D294DECC607A6ED7264BEC41FDA3BF12D3F2B3FAFAF55F0C5F2235A9066C97EC ] C:\Windows\System32\fdPnp.dll 14:05:50.0271 0x0a48 C:\Windows\System32\fdPnp.dll - ok 14:05:50.0273 0x0a48 [ 6BE0F22408603F825E64D5876DE5C306, BD2AD72FAC97496E18C032843CCA7F90CFD372F5247F4CA4E1D564828BA1346A ] C:\Windows\System32\spool\prtprocs\w32x86\HP1006PP.DLL 14:05:50.0273 0x0a48 C:\Windows\System32\spool\prtprocs\w32x86\HP1006PP.DLL - ok 14:05:50.0276 0x0a48 [ CD72C6406BA561BED6D42CB145E55307, F5DD79FCE5CAA5049C74462B366509356B8B5CCB68E14586ED95CDF98F307787 ] C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll 14:05:50.0276 0x0a48 C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll - ok 14:05:50.0278 0x0a48 [ 04B5BCB246DAEDF5CED6D16315113AF6, 598C1253539CA575248000684664C3A71A85CAA941F255051BE182D5EB8549D0 ] C:\Windows\System32\spool\prtprocs\w32x86\hpfpp70w.dll 14:05:50.0278 0x0a48 C:\Windows\System32\spool\prtprocs\w32x86\hpfpp70w.dll - ok 14:05:50.0280 0x0a48 [ EA8647A21BCB56C5F15712D4B7407501, E6479992B84BD336E672B0A724A3C9FB90AC28CEFD186FCC628006061C9927C0 ] C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll 14:05:50.0280 0x0a48 C:\Windows\System32\spool\prtprocs\w32x86\mdippr.dll - ok 14:05:50.0282 0x0a48 [ FC415B303B1ECF80B5F130A1F7203D02, ACC51D8CCF02E5EFB495BF66538B5F42CFFE5A186BC5762CC286E98509FC5DC4 ] C:\Windows\System32\win32spl.dll 14:05:50.0282 0x0a48 C:\Windows\System32\win32spl.dll - ok 14:05:50.0284 0x0a48 [ D27DDE7E0444C7F1819F958469EB7D93, EA13616D78F17CCFD77603F7EE2DDDD159100AA3DF78C1FAAEB4695D5AC7218A ] C:\Windows\System32\inetpp.dll 14:05:50.0284 0x0a48 C:\Windows\System32\inetpp.dll - ok 14:05:50.0287 0x0a48 [ 8B88EBBB05A0E56B7DCC708498C02B3E, 9E1EC8B43A88E68767FD8FED2F38E7984357B3F4186D0F907E62F8B6C9FF56AD ] C:\Windows\explorer.exe 14:05:50.0287 0x0a48 C:\Windows\explorer.exe - ok 14:05:50.0290 0x0a48 [ 6DE66FE7C526637E74CD066461C7C871, 7E8980A3751762180D795EAC38458303BEAF8D1F85AB5F2D10D9CE7013090CBE ] C:\Windows\System32\d3d11.dll 14:05:50.0290 0x0a48 C:\Windows\System32\d3d11.dll - ok 14:05:50.0292 0x0a48 [ 3CDE2911462FEC80064A409C07710C06, DBEC8669B1B8FA68750B17008C4328B223F8263EBE02C550780926C23D38D7D3 ] C:\Windows\System32\wbem\WmiPrvSD.dll 14:05:50.0292 0x0a48 C:\Windows\System32\wbem\WmiPrvSD.dll - ok 14:05:50.0294 0x0a48 [ A4CC7227A452C4909F9499D91B184364, 56111E57D17553BE3EAB8DA2DC42C7132E4458549AFFC08975B7A7204D8F5E76 ] C:\Windows\System32\ncobjapi.dll 14:05:50.0294 0x0a48 C:\Windows\System32\ncobjapi.dll - ok 14:05:50.0296 0x0a48 [ B350509B6C9296529BC464C60FEEAEF1, CC653ED001FE6A2BE5A9687572A70CEF9FAB258A57896643379E5D6C1D8E4F1F ] C:\Windows\System32\wbem\wbemess.dll 14:05:50.0296 0x0a48 C:\Windows\System32\wbem\wbemess.dll - ok 14:05:50.0298 0x0a48 [ F58516E2DC0D963EF70D6BFC21FD82C4, 5689BF12B43BE0D6BFBD6B9122A2FF53FCEC766A58A0F3C6B88AE504ACB10E04 ] C:\Windows\System32\PlaySndSrv.dll 14:05:50.0298 0x0a48 C:\Windows\System32\PlaySndSrv.dll - ok 14:05:50.0300 0x0a48 [ B43687C534A49700BF4B3C9898763752, B4C371CB2C0EAC1803E6C845F629814B2CE4C568022EB6A1C9AC1F293BF74F40 ] C:\Windows\System32\MsCtfMonitor.dll 14:05:50.0300 0x0a48 C:\Windows\System32\MsCtfMonitor.dll - ok 14:05:50.0304 0x0a48 [ 7319102526BD11B45FD66335CF90CA12, F2C7484AE33BEDE8586FB09273665B25DA7E8FEEACF9FEF43EB0B902CE4A0BD9 ] C:\Windows\System32\HotStartUserAgent.dll 14:05:50.0304 0x0a48 C:\Windows\System32\HotStartUserAgent.dll - ok 14:05:50.0306 0x0a48 [ 56CEED370508F69A1BA04939BD1BADDA, C84F383F2B3C9581F635E51DA39567F0B5ED2D847B18CCE51022BA4B2FA7EA8D ] C:\Windows\System32\msutb.dll 14:05:50.0306 0x0a48 C:\Windows\System32\msutb.dll - ok 14:05:50.0308 0x0a48 [ 49ACA548B2423F1C67898E6AC719A9A6, 23D84137EAB9AFDD31CBB6776B6B25AD135A120AF7F7885EB5BBF9E0A2CCC4C1 ] C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll 14:05:50.0308 0x0a48 C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll - ok 14:05:50.0310 0x0a48 [ C5C867CD7EFAC60D5021223E374DEEC5, 197FEE8F02DE348E75771AC9AD748EFB29939F1AAF02DA6555181EEF787FD099 ] C:\Windows\System32\dimsjob.dll 14:05:50.0310 0x0a48 C:\Windows\System32\dimsjob.dll - ok 14:05:50.0312 0x0a48 [ 5C3F9DBA818CD93379D1A0F215270374, 6A4D96AC83989D47D80332E41E627F2607A3B2167E1A5D8E21361136C4424633 ] C:\Windows\System32\esent.dll 14:05:50.0312 0x0a48 C:\Windows\System32\esent.dll - ok 14:05:50.0313 0x0a48 [ E2A17BCC08D92F42E08AF6BA2F93ABA7, 5FC9D47BF4B1094BECC0C0DDCD5CD4318DD3E4495D982F8785331616D5B82599 ] C:\Windows\System32\ExplorerFrame.dll 14:05:50.0313 0x0a48 C:\Windows\System32\ExplorerFrame.dll - ok 14:05:50.0316 0x0a48 [ 14486EB6AF542F2BD3239F7FC3E713F7, C084C653CF6C63D7B4DB08CBDE2CAF059019D276BCACD923A29D22E69055012C ] C:\Windows\System32\pautoenr.dll 14:05:50.0316 0x0a48 C:\Windows\System32\pautoenr.dll - ok 14:05:50.0319 0x0a48 [ 846D0E4DB261CFAF363902E41498E961, D7E5591B7604FD583AF7FDA19E30928B24A6145318A3944E7D207F0CCEEB30D0 ] C:\Windows\System32\EhStorShell.dll 14:05:50.0319 0x0a48 C:\Windows\System32\EhStorShell.dll - ok 14:05:50.0322 0x0a48 [ 3EC541C196DE18ED9A0D0AC82A694D4C, 51BCBDDFF113A02EF85E09BE6B2727EDB505EBFE355A8E163A7F4C82EBFBBCC4 ] C:\Windows\System32\cscui.dll 14:05:50.0322 0x0a48 C:\Windows\System32\cscui.dll - ok 14:05:50.0323 0x0a48 [ 465BEA35F7ED4A4A57686DEA7EA10F47, 7F1B3CA09AB045F805DA5765BE7DD270F5DDACE3073017F7386FF1E2FA82D6FB ] C:\Windows\System32\cscapi.dll 14:05:50.0323 0x0a48 C:\Windows\System32\cscapi.dll - ok 14:05:50.0325 0x0a48 [ 57A51217581614DE07F30E34D6BB4993, 19D06DCCF1B39DFE4FF269C5C4001E60837296411EB8E169CE142DEFAA3D94FA ] C:\Windows\System32\cscdll.dll 14:05:50.0325 0x0a48 C:\Windows\System32\cscdll.dll - ok 14:05:50.0327 0x0a48 [ 03F3B770DFBED6131653CEDA8CA780F0, 77373919DCA647F09851E7E460AE78FBD89F21516B961F84AC4446304E51E09C ] C:\Windows\System32\ntshrui.dll 14:05:50.0327 0x0a48 C:\Windows\System32\ntshrui.dll - ok 14:05:50.0329 0x0a48 [ 523CF74A52C9A1762DA8B83AEE734498, 5A739182B916738B611E1BBA9098F8BCC8C4E2CC2CFEFD1BC5CE7941D11CEDFD ] C:\Windows\System32\IconCodecService.dll 14:05:50.0329 0x0a48 C:\Windows\System32\IconCodecService.dll - ok 14:05:50.0331 0x0a48 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] C:\Windows\System32\appinfo.dll 14:05:50.0331 0x0a48 C:\Windows\System32\appinfo.dll - ok 14:05:50.0333 0x0a48 [ A648AB50A6FE18002C762674F4E0F41C, 7D5230AE3346277896E13D5B40FFDB91ED3ECE655F0643BBEEFDA78B26488301 ] C:\Windows\System32\igd10umd32.dll 14:05:50.0333 0x0a48 C:\Windows\System32\igd10umd32.dll - ok 14:05:50.0337 0x0a48 [ D44741F65A1D71F65814A12CF6E2400A, C6721F830675ADC7E7FDE2B5E822E56F6A063146F5066F1E25EBFE86F0A87136 ] C:\Windows\System32\runonce.exe 14:05:50.0337 0x0a48 C:\Windows\System32\runonce.exe - ok 14:05:50.0339 0x0a48 [ AD7B9C14083B52BC532FBA5948342B98, 17F746D82695FA9B35493B41859D39D786D32B23A9D2E00F4011DEC7A02402AE ] C:\Windows\System32\cmd.exe 14:05:50.0339 0x0a48 C:\Windows\System32\cmd.exe - ok 14:05:50.0341 0x0a48 [ 2DE16A63F71D10B42ACE01E759078600, D52FAE32C1BBF982C9222FBF275FF53D5F6F77B7747AFBF641937DFDC8D70487 ] C:\Windows\System32\conhost.exe 14:05:50.0341 0x0a48 C:\Windows\System32\conhost.exe - ok 14:05:50.0346 0x0a48 [ 79FA7D8B488F90EDE325963379A6F738, 90E0F2022D1697D5FEBE00AAB7D7E232AE42EA2AB243CD132B3BB739A6987CDD ] C:\Windows\System32\ieframe.dll 14:05:50.0346 0x0a48 C:\Windows\System32\ieframe.dll - ok 14:05:50.0349 0x0a48 [ 60F4AEFA103D421EA4A40E31409B4756, 037A8605CA504A4FF43E9D4DE9017CEA1E26D3556C975872C747E24D8B0835EF ] C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll 14:05:50.0349 0x0a48 C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll - ok 14:05:50.0352 0x0a48 [ 32F4D839CA942236F933A78C3DC404F9, EF925A407D2FC4C8806A6F3EA85BA5C2BC6651EDAADBA29F306034AA9EBC2A54 ] C:\Windows\System32\spool\drivers\w32x86\3\unidrvui.dll 14:05:50.0352 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\unidrvui.dll - ok 14:05:50.0355 0x0a48 [ BA54A966F873B043FDFCDA0B77937855, D410F6919D7A6E11615EEE2D20267F258B5A9B934E255D9B9CAF20CC77B1EDB5 ] C:\Windows\System32\mgmtapi.dll 14:05:50.0355 0x0a48 C:\Windows\System32\mgmtapi.dll - ok 14:05:50.0359 0x0a48 [ 03F364F70669D6CCDFBB648C735A1CC1, 6D9DAE8350FB2C8B5FB4F2E11896CF7B49FB9CC297178B7C0C6E1D0D2838DF46 ] C:\Windows\System32\tcpmib.dll 14:05:50.0359 0x0a48 C:\Windows\System32\tcpmib.dll - ok 14:05:50.0361 0x0a48 [ 61B1ED5F429EFAC7E2036769870AB93E, 628CF28434C5DFB81B76B90BEA4CDD9EB1E4B0971BEE24136A09490F9439E00E ] C:\Windows\System32\certcli.dll 14:05:50.0361 0x0a48 C:\Windows\System32\certcli.dll - ok 14:05:50.0362 0x0a48 [ 2C4A87CA8C00E98EFDCFA2E8EC9A3503, DA59CE662E98E56D89E2894D2AC8B9F324C16DA23C860640EDC2C82E0AD06097 ] C:\Windows\System32\shdocvw.dll 14:05:50.0362 0x0a48 C:\Windows\System32\shdocvw.dll - ok 14:05:50.0364 0x0a48 [ F672155776ABADF6A23C59E74491C9F2, B623F7901B85BA72808EC4AF9A195236C601A6B965F9202DB557746AE3FFC327 ] C:\Users\SANEX\AppData\Local\Temp\{3822B738-416C-4EE6-AEAF-CC04A4A2B16A}.exe 14:05:50.0364 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{3822B738-416C-4EE6-AEAF-CC04A4A2B16A}.exe - ok 14:05:50.0367 0x0a48 [ 29BC473072568C072EC8B176498DE996, D3A4DB88BECA8AB3F8722E499548EFEC63022C1CE38F526AFBDA76DDBA8E9064 ] C:\Windows\System32\CertEnroll.dll 14:05:50.0367 0x0a48 C:\Windows\System32\CertEnroll.dll - ok 14:05:50.0369 0x0a48 [ D5AEFAD57C08349A4393D987DF7C715D, C36A45BC2448DF30CD17BD2F8A17FC196FAFB685612CACCEB22DC7B58515C201 ] C:\Windows\System32\winmm.dll 14:05:50.0369 0x0a48 C:\Windows\System32\winmm.dll - ok 14:05:50.0371 0x0a48 [ 6F8E3B7B70E1BBA871212940C1FBDF60, 3F9D4EE64E4210340C6FEE0DE81BFE3C613DDBE608EC09D63817D24CE24BFC5E ] C:\Windows\System32\SensApi.dll 14:05:50.0371 0x0a48 C:\Windows\System32\SensApi.dll - ok 14:05:50.0373 0x0a48 [ D4191EFAB91E00FC09257AA5EBAF503B, 161B572CF4C65984EAFDBA95357373BC712AA414B52DDA23523F84151240E337 ] C:\Windows\System32\mprapi.dll 14:05:50.0373 0x0a48 C:\Windows\System32\mprapi.dll - ok 14:05:50.0375 0x0a48 [ F7FE730CE31B54145DEE1F1482BCCDD7, E7F0F59AB2B0D5EC5FE9B966006D06FE0FCEDBA99E2A4A8A6D410A0490F1F017 ] C:\Windows\System32\ndiscapCfg.dll 14:05:50.0375 0x0a48 C:\Windows\System32\ndiscapCfg.dll - ok 14:05:50.0377 0x0a48 [ 761A3A4038C1FD4F5795427907C28484, B9338BC022DC5B8C0502E6A88E7D76E03C19A828861A922360B147441FB09285 ] C:\Windows\System32\rascfg.dll 14:05:50.0377 0x0a48 C:\Windows\System32\rascfg.dll - ok 14:05:50.0379 0x0a48 [ 9A7B54D57594233EEB17892BAD309970, 64EF2A51BFA13455038DCB6773F9DEF6FD46FAA1F1CF47E7B61D3E64466DA5AA ] C:\Windows\System32\mprmsg.dll 14:05:50.0379 0x0a48 C:\Windows\System32\mprmsg.dll - ok 14:05:50.0382 0x0a48 [ CAFC0B884E5590B5E80D84F592388B3D, FFCA66AEB6869BCC7A469C5E968B20A2DFA49D97E4E598CC36E839047FF7AB2B ] C:\Windows\System32\tcpipcfg.dll 14:05:50.0382 0x0a48 C:\Windows\System32\tcpipcfg.dll - ok 14:05:50.0385 0x0a48 [ FC70115B86B7BC41467BE7A5696C44C5, 8ED2828F49F679D58B97F17865823C1349993CFC6B9FB7E0BF06F88B3EDD04C6 ] C:\Windows\System32\spool\drivers\w32x86\3\UNIDRV.DLL 14:05:50.0385 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\UNIDRV.DLL - ok 14:05:50.0389 0x0a48 [ 78DE417B7921DACA072059E6BF410FC7, 8A32772A5500F6076D207EA7194C67B4147BCE28DEA4B582C2129BEC4A42D7CD ] C:\Windows\System32\wshnetbs.dll 14:05:50.0389 0x0a48 C:\Windows\System32\wshnetbs.dll - ok 14:05:50.0392 0x0a48 [ 45D9F6CD2469CDB6A640DD4BD2B01471, 21704ADB83B26DD9C2D4D248FE61F3FEC2003D6748BB6A830334F0FDA9610362 ] C:\Windows\System32\nci.dll 14:05:50.0392 0x0a48 C:\Windows\System32\nci.dll - ok 14:05:50.0395 0x0a48 [ 9E6AF823733C70E207D9FB6731A63B3D, 2E10E0CD623243A465315985630C25906B700F1F2DA52BC641F4900615B4F28E ] C:\Windows\System32\wlaninst.dll 14:05:50.0395 0x0a48 C:\Windows\System32\wlaninst.dll - ok 14:05:50.0397 0x0a48 [ 5B6EF0861BB5AC0EC347548E85C24A1D, 790EAEF1025293E45436654AD04C6D4E1A366879C0DA176AF157B0465E3A9A21 ] C:\Windows\System32\wwaninst.dll 14:05:50.0397 0x0a48 C:\Windows\System32\wwaninst.dll - ok 14:05:50.0399 0x0a48 [ 96C70BD48D49B87475F4572DEDC62EB9, DA841CEBDFF2C5821D4D3396BD9299940A4A2927C161554B66AB8F58CBF04467 ] C:\Windows\AppPatch\AcLayers.dll 14:05:50.0399 0x0a48 C:\Windows\AppPatch\AcLayers.dll - ok 14:05:50.0401 0x0a48 [ 51138BEEA3E2C21EC44D0932C71762A8, 5AD3C37E6F2B9DB3EE8B5AEEDC474645DE90C66E3D95F8620C48102F1EBA4124 ] C:\Windows\System32\rundll32.exe 14:05:50.0401 0x0a48 C:\Windows\System32\rundll32.exe - ok 14:05:50.0405 0x0a48 [ FD0195ECD48ED3A70D4FA439E30C36F2, 28ADD70CEFD5435256B7EE9C9517C84B3F67DFB36A009AC31559F0BE081B8825 ] C:\Windows\System32\spool\drivers\w32x86\3\hpfui70w.dll 14:05:50.0405 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfui70w.dll - ok 14:05:50.0406 0x0a48 [ D2958325C1AE1AE37A83334C6229E3BC, D8263CB39A25447442B75A8D8E8111DF671D645DA90A33865C089DEDA9706904 ] C:\Windows\System32\actxprxy.dll 14:05:50.0406 0x0a48 C:\Windows\System32\actxprxy.dll - ok 14:05:50.0409 0x0a48 [ 63FC6B04A81CC5324429107DD5C405DA, FC6D4237D7E84DA20F52CE2C801EB8343910B81AC071B4A3F21503A3369C4B51 ] C:\Windows\System32\spool\drivers\w32x86\3\hpfst70w.dll 14:05:50.0409 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfst70w.dll - ok 14:05:50.0411 0x0a48 [ 4B9E4CE667DF26ADA061AA81E9AA841D, F6C151A14ADF4229AC8192EE9B7C3C5445619EECCCCEB647F3674360D65284B9 ] C:\Windows\System32\spfileq.dll 14:05:50.0411 0x0a48 C:\Windows\System32\spfileq.dll - ok 14:05:50.0413 0x0a48 [ 15A9B01686075F7524D91BB479926F87, F699CCFA426E3FE618203A02632422BB2C6E079E1AD820FA63D0AAF217111AC3 ] C:\Windows\System32\spool\drivers\w32x86\3\UNIRES.DLL 14:05:50.0413 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\UNIRES.DLL - ok 14:05:50.0415 0x0a48 [ F93C4372E5450243D076BB7E1138952E, 40AA86B029DFD5C35063E166DCACE27978D1D675F32918800E9EFF3E4BE7633C ] C:\Windows\System32\spool\drivers\w32x86\3\hpfvu70w.dll 14:05:50.0415 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfvu70w.dll - ok 14:05:50.0417 0x0a48 [ 91893BBC140F86CFC4343F434A6B2E3B, FF1FA02DC0D51032FC4458A839BC00752899446401C54B5C701623530611881A ] C:\Windows\System32\spool\drivers\w32x86\3\hpw450g3.dll 14:05:50.0417 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpw450g3.dll - ok 14:05:50.0422 0x0a48 [ 613582378EFEE1122AC70FE0C61DB0DB, 8ACD1C5BF47AC476C1D7C6EC82EC7452FDDC7E635E004D40B6FF7B9706C1FA5E ] C:\Windows\System32\spool\drivers\w32x86\3\hpfev70w.dll 14:05:50.0422 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfev70w.dll - ok 14:05:50.0424 0x0a48 [ 492E444CDB0AA5322F67621C3CA11852, 2BBDA3103547E96BBC646811F1C00084268001D7278D458FE7EF009F2B381FE7 ] C:\Windows\System32\spool\drivers\w32x86\3\hpf3r70w.dll 14:05:50.0424 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpf3r70w.dll - ok 14:05:50.0426 0x0a48 [ 80FC06A0EB5F034BAC900E21F3A0D5E7, F3B41366FC9460C8B987E67DFAA52297AB3697A0372F1CBD18431C78910FAEC5 ] C:\Windows\System32\spool\drivers\w32x86\3\hpfrs70w.dll 14:05:50.0426 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfrs70w.dll - ok 14:05:50.0428 0x0a48 [ F8F11C44C3C72DB4E768233DD50A2658, C300F6353F82F0720DE0AC62A242346389E0F4F0F1D00F5668740EBB35CAF8F4 ] C:\Windows\System32\spool\drivers\w32x86\3\hpfie70w.dll 14:05:50.0428 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfie70w.dll - ok 14:05:50.0430 0x0a48 [ 66DC7D3DA7D4C877D7024DDFD0C2A339, 0E02510EC6A4B1F0BCE72066A87074709F7DBB0A3867D7EA62A8B31D83668D79 ] C:\Windows\System32\spool\drivers\w32x86\3\hpfpr70w.dll 14:05:50.0430 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfpr70w.dll - ok 14:05:50.0432 0x0a48 [ 7AAD682FD87A5136C7C5ECDD4A365463, B64B43FF3724F81D815F0E9ABE4F4BDE6FEC29582BA53BECD500813CDA854F4A ] C:\Windows\System32\spool\drivers\w32x86\3\hpfpa70w.dll 14:05:50.0432 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\hpfpa70w.dll - ok 14:05:50.0435 0x0a48 [ B2BCD4B0352B069F160C4DB82334768B, 81F5C962DD18FF3EB802DFB06683962473CCE9C0518484C9BC21220640F2BF74 ] C:\Windows\System32\spool\drivers\w32x86\3\HPCDMC32.dll 14:05:50.0435 0x0a48 C:\Windows\System32\spool\drivers\w32x86\3\HPCDMC32.dll - ok 14:05:50.0439 0x0a48 [ 7E9917D5309A90E7576653BFE39F80D8, 3525795CA69EF165AAAA20C878A20DF5A5F183CF6F8358A0132A88153E6459C6 ] C:\Windows\System32\timedate.cpl 14:05:50.0439 0x0a48 C:\Windows\System32\timedate.cpl - ok 14:05:50.0443 0x0a48 [ 5987EA8A82C53359BCD2C29D6588583E, 59E2DF91F8DA9E33DE65FA67A6A49A7C3F524618A87EAEFC8A28C5304E7FAB85 ] C:\Windows\System32\linkinfo.dll 14:05:50.0443 0x0a48 C:\Windows\System32\linkinfo.dll - ok 14:05:50.0446 0x0a48 [ 64E211E0FDFCE4D186DF58BB7D0503BC, 6B9E12979119BAD721D493A9CEFDC7B4150121D5590222069FD1B8D80F9AC5C0 ] C:\Windows\System32\gameux.dll 14:05:50.0446 0x0a48 C:\Windows\System32\gameux.dll - ok 14:05:50.0448 0x0a48 [ F1278B3514EA6FA9BC39B20D26139AAC, 7FA1B8CCBB4771F3105EEACE2C13F949FA65C7F53817C783BDF9770F94FF12B5 ] C:\Windows\System32\msiltcfg.dll 14:05:50.0448 0x0a48 C:\Windows\System32\msiltcfg.dll - ok 14:05:50.0450 0x0a48 [ 3A16EA01FCFAAB40882DB5BFEE632322, 04ED66BEFDB822181EBD1D84CBF0B17AAADF8455AE742F44D7ADCB26AB07BDAD ] C:\Windows\System32\msftedit.dll 14:05:50.0450 0x0a48 C:\Windows\System32\msftedit.dll - ok 14:05:50.0452 0x0a48 [ 298FDE634538B62CEEEC266D8773B21A, E6E445282D17CEAFEAB66A5A1E0124DD50F2438205BCE5649DB998BDAED06CB7 ] C:\Windows\System32\msls31.dll 14:05:50.0452 0x0a48 C:\Windows\System32\msls31.dll - ok 14:05:50.0454 0x0a48 [ 7896EFFDEE215C172BE724A64931EF1C, 10F9D73B85853FD6D7B54DCB9BC0FA5EC9FAECFB01E3AD4DAE4CC2FE2E68EE6D ] C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll 14:05:50.0454 0x0a48 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll - ok 14:05:50.0457 0x0a48 [ 87D78CF6365BDDACBE9D34B60FE0E23B, 4561DE7171FD9035FEDF7EEA059859732996A5E72364D0D9F230563A1A6AE3D4 ] C:\Windows\System32\hkcmd.exe 14:05:50.0457 0x0a48 C:\Windows\System32\hkcmd.exe - ok 14:05:50.0459 0x0a48 [ 2C1B1E9174D94E9F6EE3CF373ABAB7DD, 729D283DF70F727824EBCA223D5E5B27D16E3E2B5312B1B34CAE1E763192D7B5 ] C:\Windows\System32\igfxtray.exe 14:05:50.0459 0x0a48 C:\Windows\System32\igfxtray.exe - ok 14:05:50.0461 0x0a48 [ 007863E45F25AA47A4C30D0930BBFD85, 60F2ABA40D520FCA2C57FA2DB72E111C14F21821DA17F662837506B80C269634 ] C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 14:05:50.0461 0x0a48 C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll - ok 14:05:50.0463 0x0a48 [ 2A39F32E0067CBF221611FE1FA8C6D8F, C6D1CAB7BC87F8EB7D801BE3E3DA9B631932A94468E7A6F46D60A43C9AB08EE7 ] C:\Windows\System32\DeviceCenter.dll 14:05:50.0463 0x0a48 C:\Windows\System32\DeviceCenter.dll - ok 14:05:50.0465 0x0a48 [ 5F12DCBECEE0ADE819E3F710F5508B31, 150C423D0C922B4EBB1A2E4B30920E10127169F2E83447B9CA257FE7D3FC06D3 ] C:\Windows\System32\hccutils.dll 14:05:50.0465 0x0a48 C:\Windows\System32\hccutils.dll - ok 14:05:50.0467 0x0a48 [ 89D3DE5E2C77DCD99C56F0E46310AEA0, 02E1B2353E5D5F65D7968698AFE079A4DF11C230F6213C07D128F47147BACA29 ] C:\Windows\System32\igfxpers.exe 14:05:50.0468 0x0a48 C:\Windows\System32\igfxpers.exe - ok 14:05:50.0471 0x0a48 [ 5E350C463EE596321C79CF23ADA56E7A, BE71E7A301BD12653FA49EF7AD7E6669D9151030D0C26A818DEBCADA8C89FD62 ] C:\Windows\System32\igfxsrvc.exe 14:05:50.0471 0x0a48 C:\Windows\System32\igfxsrvc.exe - ok 14:05:50.0472 0x0a48 [ 3D57FFBAD3ED16B63DE3879BAB0FB56F, 6BEAF5AFC98961190B004E8DE57CD5F9F39117287AE18D59DDB2EC5C0A0C6622 ] C:\Windows\System32\networkexplorer.dll 14:05:50.0472 0x0a48 C:\Windows\System32\networkexplorer.dll - ok 14:05:50.0475 0x0a48 [ 672D7C5080ACB003343006405DA2E621, 5F28C83A20ECB1F20894B60725477BEF0D672817DFDB9822FB345A3270A0C095 ] C:\Windows\System32\thumbcache.dll 14:05:50.0475 0x0a48 C:\Windows\System32\thumbcache.dll - ok 14:05:50.0477 0x0a48 [ 53EE5AF5320FEA562A7A7BE6F71A534A, C0BEF7D3797BA037806B81A11038675C2A816217A614BC647BB430567604BE94 ] C:\Windows\System32\igfxsrvc.dll 14:05:50.0477 0x0a48 C:\Windows\System32\igfxsrvc.dll - ok 14:05:50.0479 0x0a48 [ 7B2E20CAE7730B2ADD47E09FD14F18C3, BB15923E533CF522CD040C977EC2104EA3FA15FA9191F4BCAC3839169C1CE664 ] C:\Windows\System32\igfxdev.dll 14:05:50.0479 0x0a48 C:\Windows\System32\igfxdev.dll - ok 14:05:50.0481 0x0a48 [ EB151D6761A5F3AA393E3408430F5BF7, 2D442D6384A9D6B44426DD93B5217E41BB31B5D90E168F5E3B4079E7D2C5FE3F ] C:\Windows\System32\igfxrplk.lrc 14:05:50.0481 0x0a48 C:\Windows\System32\igfxrplk.lrc - ok 14:05:50.0483 0x0a48 [ 048EA4B978851788E9F5E8E4F081DF7A, EB62719AC0DCC18FF056F2CD84438BF14B61E38F0619617C81961C6257BDFCEC ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe 14:05:50.0483 0x0a48 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe - ok 14:05:50.0488 0x0a48 [ 9A69089E04F060CB25657EA0EA2ED503, E9DE97A56BBF2EF7007240B787502377EA7B5FA166908D2B66AF6A9134D89777 ] C:\Windows\System32\GfxUI.exe 14:05:50.0488 0x0a48 C:\Windows\System32\GfxUI.exe - ok 14:05:50.0494 0x0a48 [ 683C9DF0582D8EEFAA90CE1514019BC1, 62C875888029BF32C19656B13C5504016209E4553B0B93FAE21F3930149EE9CA ] C:\Program Files\DAEMON Tools Lite\DTLite.exe 14:05:50.0495 0x0a48 C:\Program Files\DAEMON Tools Lite\DTLite.exe - ok 14:05:50.0499 0x0a48 [ 2B8064BFF1C61C7E61232D2652894CD4, EDAA935B35392AD17DC953CE4341674AF0687322B35956962A8BFF8AE3F793B7 ] C:\Windows\System32\igfxress.dll 14:05:50.0499 0x0a48 C:\Windows\System32\igfxress.dll - ok 14:05:50.0502 0x0a48 [ D205C24A9D069049FE2DF2A1B38726A7, B98F420B57A34FDA24F9A655319245EEF86EF4A952014FFA018070A01D5CBC4C ] C:\Windows\System32\wdmaud.drv 14:05:50.0502 0x0a48 C:\Windows\System32\wdmaud.drv - ok 14:05:50.0504 0x0a48 [ 9C67F6BBDA3881CFD02095160CF91576, 6CE97C6F0AD8BE183DE935A7AAB7D46821E8DE9E55A4BFF54ACB49D056826A94 ] C:\Windows\System32\ksuser.dll 14:05:50.0504 0x0a48 C:\Windows\System32\ksuser.dll - ok 14:05:50.0507 0x0a48 [ C940F2F5C60B3727C5F18840735B229C, EFC3F465FD6C570505C214A92644357ACD01B1843ED25B5FCCCE10533403485C ] C:\Windows\System32\AudioSes.dll 14:05:50.0507 0x0a48 C:\Windows\System32\AudioSes.dll - ok 14:05:50.0510 0x0a48 [ CCDA8E6A2AC68FD417A8BB8D88CBFDAC, EA9226AB7559B9D136566FDF7FCEDA34D0956E8065C6A3B692C88E2A945136E0 ] C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe 14:05:50.0510 0x0a48 C:\Program Files\Adobe\Reader 11.0\Reader\AcroRd32.exe - ok 14:05:50.0512 0x0a48 [ 175383778EB24D98C84E624021E3AA0B, FE831AC7C5375FE0F0D2A56F1546F968B2595503CC63FE9A8F819F7910A1604A ] C:\Windows\System32\aeevts.dll 14:05:50.0512 0x0a48 C:\Windows\System32\aeevts.dll - ok 14:05:50.0514 0x0a48 [ 5A12C364AD1D4FCC0AD0E56DBBC34462, 5FDF434BE4E15311AC83754CF85B5451F5A219D768A5DE3DC4FD9AE0B57B0AD9 ] C:\Windows\System32\midimap.dll 14:05:50.0514 0x0a48 C:\Windows\System32\midimap.dll - ok 14:05:50.0517 0x0a48 [ 85683DF1F917E4D7F6BE1A04986BF1C8, D68D9F525D31C1843B6EC8FA950166FA1F34DB71222716E7B22DD33981C152B6 ] C:\Windows\System32\msacm32.dll 14:05:50.0517 0x0a48 C:\Windows\System32\msacm32.dll - ok 14:05:50.0519 0x0a48 [ 07393A09C46083588E751B63B03C8301, 36E2351CF5FA05FEAAEB340B5E04B107B53C8174F8333559D8AEA40BEB94F678 ] C:\Windows\System32\msacm32.drv 14:05:50.0519 0x0a48 C:\Windows\System32\msacm32.drv - ok 14:05:50.0521 0x0a48 [ BBA9D5A730D5E304117AD26923EBD8AA, 62DD6CEA9B3819DEC704BFBDCFF771903A2E2E8668EB9D5AD32210EEDB359132 ] C:\Windows\System32\AudioEng.dll 14:05:50.0521 0x0a48 C:\Windows\System32\AudioEng.dll - ok 14:05:50.0524 0x0a48 [ 96F0F8F4DEE598C8D12AD9633E0CFE2A, 56EA483444BB6CCD6B9BE8030BB0FBB60EEE34A96731AB50CDC7DBA56BF2CB7C ] C:\Windows\System32\AUDIOKSE.dll 14:05:50.0524 0x0a48 C:\Windows\System32\AUDIOKSE.dll - ok 14:05:50.0527 0x0a48 [ 4E30ED3E551E867ADD1C8D58F5EDD9DF, C933ABF1069128F4AB73DA47B2E7C029249804D65F50720897ECCAB3F4A07C27 ] C:\Windows\System32\WMALFXGFXDSP.dll 14:05:50.0527 0x0a48 C:\Windows\System32\WMALFXGFXDSP.dll - ok 14:05:50.0529 0x0a48 [ 7D6F3E59417CAA671D73FAA2D665CCC4, 5366685316DB6EFE640B09B2AA07E85B041FC3DBF7D032EF18337B18ACB6346B ] C:\Program Files\Steam\Steam.exe 14:05:50.0529 0x0a48 C:\Program Files\Steam\Steam.exe - ok 14:05:50.0531 0x0a48 [ 40B82688907A7DBA4DB3B5ADDE3EAB3B, 7A8A051F414A0A11252A361461A086890BCE9F49CE1AF794061184AE16517EF1 ] C:\Windows\System32\mfplat.dll 14:05:50.0531 0x0a48 C:\Windows\System32\mfplat.dll - ok 14:05:50.0533 0x0a48 [ 9DD06F00898AA5CA7E24186EFC8E5E25, 51141D0D07DBC955B63281351D3F17163ACE9A5B08628EA1C82F33FD2913970E ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{794789CA-FB43-4990-A5FD-BED2A4048C7A}.tmp 14:05:50.0533 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{794789CA-FB43-4990-A5FD-BED2A4048C7A}.tmp - ok 14:05:50.0537 0x0a48 [ 91A7771934C0D9D2DA7699D25BB5B348, 154A6EB866AF22B38AEE8DB5A864653FEB15DED69DE26E5B602B7C5056CDDF72 ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{35F14E4B-E709-4AC7-9E1B-BEC4299BDEB0}.tmp 14:05:50.0537 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{35F14E4B-E709-4AC7-9E1B-BEC4299BDEB0}.tmp - ok 14:05:50.0539 0x0a48 [ 80808656078CFCC32CF8BFEB0DD66279, 383F37599ABF16EEDEB2A60242DB7EDCC3D210A2A59DD61169047059F7041C5C ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{16265E4B-5B2D-4278-AE58-18C3D14548C3}.tmp 14:05:50.0539 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{16265E4B-5B2D-4278-AE58-18C3D14548C3}.tmp - ok 14:05:50.0541 0x0a48 [ DF471F11CC78BE02FE6BA15F2D94F65B, 9AC230DE58CE40E78AE6872BCF4778B69EEBF17E0E41B1301FF364ABD4737A78 ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{99CE96B1-1FB7-4B70-AE26-17A1BA778151}.tmp 14:05:50.0541 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{99CE96B1-1FB7-4B70-AE26-17A1BA778151}.tmp - ok 14:05:50.0544 0x0a48 [ 0FD19BDDD2513874FF6903F717367795, DFAF9C33F993BA26FC84EF66ABC7C483E62762F7E1FC763605A75ACC2E8AA4EE ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{A149050C-CDF6-4543-B30F-C8CE9AD77591}.tmp 14:05:50.0544 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{A149050C-CDF6-4543-B30F-C8CE9AD77591}.tmp - ok 14:05:50.0546 0x0a48 [ DD88BBF87A43331A4E99E37F7BF59FDB, 872190F559FA0DD1F711E9FA101BA1AB6E6DE5ED0CCCE1AB7AFE45BC3B78A0F1 ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{0794C079-3B3F-4B6F-A514-33A204000CEE}.tmp 14:05:50.0546 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{0794C079-3B3F-4B6F-A514-33A204000CEE}.tmp - ok 14:05:50.0549 0x0a48 [ 4261449C1CADA6B007E5C27522946D2B, 11E79D1C529E816CCCAC9266089C77A4DB44676CAEEE25C66D6DB420B18D3ACB ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{3AE9E6B3-68BA-45A5-9BA7-F7B4DD7B14D4}.tmp 14:05:50.0549 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{3AE9E6B3-68BA-45A5-9BA7-F7B4DD7B14D4}.tmp - ok 14:05:50.0551 0x0a48 [ 58B8702C20DE211D1FCB248D2FDD71D1, B2F6E3BA6FB5250F0E70555B39D34F19ADA760BDDA7E1A44113B97C3A1FD3F8B ] C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe 14:05:50.0551 0x0a48 C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe - ok 14:05:50.0555 0x0a48 [ 6627AA675A5C1B0330487A02E23F0560, 256AE9BA4273D4247FFAD6099D5A4FC8E98EDB27293AC8CAF7A571EB3890FAA7 ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{2B164A2B-2E6C-47FF-8CB4-0CA86290D196}.tmp 14:05:50.0555 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{2B164A2B-2E6C-47FF-8CB4-0CA86290D196}.tmp - ok 14:05:50.0557 0x0a48 [ E3C817F7FE44CC870ECDBCBC3EA36132, D769FAFA2B3232DE9FA7153212BA287F68E745257F1C00FAFB511E7A02DE7ADF ] C:\Windows\System32\msvcp100.dll 14:05:50.0557 0x0a48 C:\Windows\System32\msvcp100.dll - ok 14:05:50.0559 0x0a48 [ D83947A58613E9091B4C9CC0F1546A8D, C71DF6E18E2099FC462717B8658D39C607A62C7E7A1E5CD0E258C17434535AD0 ] C:\Windows\System32\mscoree.dll 14:05:50.0559 0x0a48 C:\Windows\System32\mscoree.dll - ok 14:05:50.0561 0x0a48 [ 723B834A07F7DF7DE4CEB637D57ACEA3, B42867045DD3FB7682CDBD133970421010F0F14125E4992C73657CABA4659250 ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{B85EBD06-821F-4378-8A17-870C4265FC44}.tmp 14:05:50.0561 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{B85EBD06-821F-4378-8A17-870C4265FC44}.tmp - ok 14:05:50.0564 0x0a48 [ 2F106DEDFF07C7DA2E3F246D8DF9EF21, E3D9839C79F22B831978B2142F79E0EB6F0FD2D56FF387BB74B2EE74CA8ADE7B ] C:\Program Files\Steam\crashhandler.dll 14:05:50.0564 0x0a48 C:\Program Files\Steam\crashhandler.dll - ok 14:05:50.0566 0x0a48 [ C1DE893FAF6D7F6CFB479A1F61835482, AD5FA3CE73777704C67C933691F1F068E1A7FF545F728B97574F9C33AC4BBC01 ] C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{54BF0584-9414-4064-BEDA-E19615C1AD41}.tmp 14:05:50.0566 0x0a48 C:\Users\SANEX\AppData\Local\Temp\{BCEA63B0-7A7D-450F-875F-30DE99B37AB9}\{54BF0584-9414-4064-BEDA-E19615C1AD41}.tmp - ok 14:05:50.0569 0x0a48 [ 5E3C0E5FFDA48C5DA35BBFB8EFFF8066, E2BBCC111DB1CE6072CB796F21677E4529029CE66DDC471EC793278F81F1FCF6 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll 14:05:50.0569 0x0a48 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll - ok 14:05:50.0572 0x0a48 [ CE38536E05E23FE796C11AFFAB6FA842, C513ECE5B70D433C7D97009307C3CCFDD0E5ED77423AD57319EC8390DAEFD0BC ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll 14:05:50.0572 0x0a48 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - ok 14:05:50.0574 0x0a48 [ BF38660A9125935658CFA3E53FDC7D65, 60C06E0FA4449314DA3A0A87C1A9D9577DF99226F943637E06F61188E5862EFA ] C:\Windows\System32\msvcr100.dll 14:05:50.0574 0x0a48 C:\Windows\System32\msvcr100.dll - ok 14:05:50.0576 0x0a48 [ BC53B2CBDCE615BF695A2799F0A705E8, C8E5531E3B14C13FB641D2ED735D9E55B6F0BFAE2962075DDC2CEDFC199479DE ] C:\Program Files\DAEMON Tools Lite\DTCommonRes.dll 14:05:50.0576 0x0a48 C:\Program Files\DAEMON Tools Lite\DTCommonRes.dll - ok 14:05:50.0578 0x0a48 [ 53223B673A3FA2F9A4D1C31C8D3F6CD8, B07A12E3ECD5E418A3F99F00C56E7F482F68CADE330E7C079DCCDFFAD2E21299 ] C:\Windows\System32\dbghelp.dll 14:05:50.0578 0x0a48 C:\Windows\System32\dbghelp.dll - ok 14:05:50.0580 0x0a48 [ 8B285BDAB7735FDFB18E6F7122923B77, DE3DBDDBF0E999CDE4A53B194128094671684708CDBED2C4D5362316CAA3A8CD ] C:\Windows\System32\UIAnimation.dll 14:05:50.0580 0x0a48 C:\Windows\System32\UIAnimation.dll - ok 14:05:50.0582 0x0a48 [ 5FF5E12F28725D14CAA3B408848ADFFC, 32C38FEC25F193EAB1C7EB567666D4F7E46117AC3C1F341C14C1DD5C926BFAAC ] C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll 14:05:50.0582 0x0a48 C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll - ok 14:05:50.0584 0x0a48 [ 102CF6879887BBE846A00C459E6D4ABC, A4C51C79CF95D5C79DCEFB02946A09A987FEAF83CE2EE1BA7677EBA90869AC80 ] C:\Windows\System32\riched20.dll 14:05:50.0584 0x0a48 C:\Windows\System32\riched20.dll - ok 14:05:50.0588 0x0a48 [ 93C2D166F5C3C14B32B15184254049C3, 397879F4974CD03FBEE3DC3EA859F1BE3B9E3269603F053CE17DCBC384B83B34 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll 14:05:50.0589 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll - ok 14:05:50.0591 0x0a48 [ 936F728E04ACCF3F38801CFFCF1E3F40, 59CA86096F4B928E364B6A3C0408615F068BB8BC02DCFC5EAF4873EC6D6E0797 ] C:\Windows\System32\oledlg.dll 14:05:50.0591 0x0a48 C:\Windows\System32\oledlg.dll - ok 14:05:50.0593 0x0a48 [ 968FFCFA1B5CA1633382A0B06228AF34, 3512DAB9A48BBBDD2C45A33F077AB59758B571FCA6FC233D02F490BD96EFAAF2 ] C:\Program Files\DAEMON Tools Lite\Engine.dll 14:05:50.0593 0x0a48 C:\Program Files\DAEMON Tools Lite\Engine.dll - ok 14:05:50.0595 0x0a48 [ 0F42F3605AB5C3679765FF1081275EF3, 50BD23EC2590C1083EA33E3D1E3448244A3D8995672DFB4DBC409E20FA9BF2FF ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll 14:05:50.0595 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll - ok 14:05:50.0597 0x0a48 [ 56F80C7292E97CF71A669E121FAE821A, 4382427F1C0C10459443E675389B9320A091DBDDE08F91A567E3BFC272B39B79 ] C:\Program Files\DAEMON Tools Lite\imgengine.dll 14:05:50.0597 0x0a48 C:\Program Files\DAEMON Tools Lite\imgengine.dll - ok 14:05:50.0601 0x0a48 [ 912649A1B3F9E6ACB3899FBDABA2ED5F, 049DFA9EA45A888B984E459B927A0F8AA4C10B9D36C6C0A0FE57F6329BEAF555 ] C:\Windows\System32\stobject.dll 14:05:50.0601 0x0a48 C:\Windows\System32\stobject.dll - ok 14:05:50.0604 0x0a48 [ 67C1B58706B47EEBA4E117AC197289E6, 9213E55DA854563E3A99369A4FAD853C0A97241A4F6D93F98444C57ADEEF89C1 ] C:\Windows\System32\batmeter.dll 14:05:50.0604 0x0a48 C:\Windows\System32\batmeter.dll - ok 14:05:50.0608 0x0a48 [ 8CC33F757E817C7C03C6A5F7FDF85F09, C120CA09A37CAD9DD39B59B9C99476B38E666B32A907D68495F9E568DA5CE694 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1d696b2d3de530f7ee971070263667ff\WindowsBase.ni.dll 14:05:50.0608 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1d696b2d3de530f7ee971070263667ff\WindowsBase.ni.dll - ok 14:05:50.0612 0x0a48 [ C8333F1F77A1B2E25F2202E892CAF634, 7A614AA4353ECE8175B6AB7B25EE26FAB22DF2A53C9A5A694B3A3B56F6C783A7 ] C:\Windows\System32\prnfldr.dll 14:05:50.0613 0x0a48 C:\Windows\System32\prnfldr.dll - ok 14:05:50.0616 0x0a48 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] C:\Windows\System32\drivers\cdfs.sys 14:05:50.0616 0x0a48 C:\Windows\System32\drivers\cdfs.sys - ok 14:05:50.0620 0x0a48 [ ADDB05C93272A62606599B24730BD645, 38E2E2979C48549A3B72807B33254DB3AC106DB1FD2790C8AC1B27CDE86EC38F ] C:\Windows\System32\DXP.dll 14:05:50.0620 0x0a48 C:\Windows\System32\DXP.dll - ok 14:05:50.0623 0x0a48 [ 856CFFCD835528136367BB1A8FE1DB87, 97EE0B243F460BE737D18B634559BC6389064BA013890E69B650E5152AB873C8 ] C:\Windows\System32\Syncreg.dll 14:05:50.0623 0x0a48 C:\Windows\System32\Syncreg.dll - ok 14:05:50.0627 0x0a48 [ 739AFF76CF8D1280EB3E10DD02748DDF, 6917FDD9C3CB48F550550A1BC4670C919FCD05D55AB91DE8A4BB025BFCAB918C ] C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\660ac5d6da77df8e86fb26f05c6a9816\PresentationCore.ni.dll 14:05:50.0627 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\660ac5d6da77df8e86fb26f05c6a9816\PresentationCore.ni.dll - ok 14:05:50.0630 0x0a48 [ F8F03D206F7D5811D630349A23E9B9B9, D8F63A2DF5E79103BC3DD36BF09E60D095577BCB30BADA8763168E0199ED4CD8 ] C:\Windows\ehome\ehSSO.dll 14:05:50.0630 0x0a48 C:\Windows\ehome\ehSSO.dll - ok 14:05:50.0632 0x0a48 [ EAB975DB4C2805927FE5BD047D05C9AA, 8F5497B1A2652B5EAA5D35BD314B5F90C5140207427DAE6068D665FA44D3FD56 ] C:\Windows\System32\netshell.dll 14:05:50.0632 0x0a48 C:\Windows\System32\netshell.dll - ok 14:05:50.0636 0x0a48 [ B2B3DAE040F6B5AE1DF52B0CD7631A18, 062680EFF24EB83FF34DDD76043DB9ABB476C8FEE7BBE869A1E7F7FC8891314F ] C:\Windows\System32\AltTab.dll 14:05:50.0637 0x0a48 C:\Windows\System32\AltTab.dll - ok 14:05:50.0639 0x0a48 [ 735263DA17BF5BAF9CCD483843BF9D5A, A493F9191EA3F37A53474E94B3917EA038B29545FC62B1634CE47F05EA2FF5C6 ] C:\Windows\System32\WPDShServiceObj.dll 14:05:50.0639 0x0a48 C:\Windows\System32\WPDShServiceObj.dll - ok 14:05:50.0642 0x0a48 [ ADB45A977BD9E45790CA496DB84BA148, BB251C9A5D2F5C6BDFB22C6BA235748472FC28AF2ADAF1CE7948352301DDE3C1 ] C:\Windows\System32\PortableDeviceTypes.dll 14:05:50.0642 0x0a48 C:\Windows\System32\PortableDeviceTypes.dll - ok 14:05:50.0645 0x0a48 [ 3D6F22551D422F97AACB0BB927E4C846, 9AB7C9F2E7F3D1CEC4553D0DF57E074121957055A9A4349946D354ACB6FC4579 ] C:\Windows\System32\pnidui.dll 14:05:50.0645 0x0a48 C:\Windows\System32\pnidui.dll - ok 14:05:50.0651 0x0a48 [ B6D3C63C07085941446AA90BD77AC07F, F4E1144DFC8A6A5F81F7326BA3E6E1A6A6CE419C3FAA9513835FB17BFEE73842 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f703846404bb66a4ae03ef8133755007\PresentationFramework.ni.dll 14:05:50.0652 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f703846404bb66a4ae03ef8133755007\PresentationFramework.ni.dll - ok 14:05:50.0655 0x0a48 [ BD626EF05967D14C772B8096292731A3, FE3838B41DCAFC52089D909E7F411186D993C08AC149E093352D691D57C9BE71 ] C:\Windows\System32\QUTIL.DLL 14:05:50.0655 0x0a48 C:\Windows\System32\QUTIL.DLL - ok 14:05:50.0659 0x0a48 [ CF4274CEEA9F7791FB7FC40A066BC2C7, C153EC0D420261185001B354955DF85C6E842334D34E70BB69CECC3AFC8CE36C ] C:\Windows\System32\cscobj.dll 14:05:50.0659 0x0a48 C:\Windows\System32\cscobj.dll - ok 14:05:50.0663 0x0a48 [ 236F286E103FD44BD85FDD93097FD5DD, C369C98E76FEFBB05A12ABEECCF89C75132419B56866ED9AB77F61F84BA62785 ] C:\Windows\System32\SearchIndexer.exe 14:05:50.0663 0x0a48 C:\Windows\System32\SearchIndexer.exe - ok 14:05:50.0664 0x0a48 [ 674B0C0F6A448EB185CAAB9C51D44032, 6722351F46BF70BA967844D3239CD801DFC4538A4EB6C478D8497F27F7FD9F1D ] C:\Windows\System32\srchadmin.dll 14:05:50.0664 0x0a48 C:\Windows\System32\srchadmin.dll - ok 14:05:50.0668 0x0a48 [ 465DBF63A5049E4DB4BC5C12FFE781CB, D12F6A9FB92144B2CFFD28BD72C234BA42F882EF22122DB83CE5EB1B8EBE9017 ] C:\Windows\System32\tquery.dll 14:05:50.0668 0x0a48 C:\Windows\System32\tquery.dll - ok 14:05:50.0672 0x0a48 [ 9A39A2A5F443A756C568C6ED5748AFE4, 13C2790985CBA9CD325BA20364A665DB50B769B7DDE93E6BE20F25427BDB34F8 ] C:\Windows\System32\ActionCenter.dll 14:05:50.0672 0x0a48 C:\Windows\System32\ActionCenter.dll - ok 14:05:50.0675 0x0a48 [ 0241CB16136B9A4939CA0395768AE286, E7A3A0BDB4AC4BD718C93BE650541F96603739BDB3DB6860665DCC073DA8007D ] C:\Windows\System32\mssrch.dll 14:05:50.0675 0x0a48 C:\Windows\System32\mssrch.dll - ok 14:05:50.0678 0x0a48 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] C:\Windows\System32\netman.dll 14:05:50.0678 0x0a48 C:\Windows\System32\netman.dll - ok 14:05:50.0681 0x0a48 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] C:\Windows\System32\wersvc.dll 14:05:50.0681 0x0a48 C:\Windows\System32\wersvc.dll - ok 14:05:50.0684 0x0a48 [ 81600E2E27ED61427AAD865B9BCDDB9D, 0D7D39C0A5A2C24FAADCA41658A1C62D13180B462C78103BDF6DBD76B64DD79A ] C:\Windows\System32\msidle.dll 14:05:50.0684 0x0a48 C:\Windows\System32\msidle.dll - ok 14:05:50.0688 0x0a48 [ 1E8D06AAE74FED674C1156B3FEA911C2, C1999BA9E436F9E0B9302DC82DF8B214E66372899FD4C0C60C56EE5340BADB9F ] C:\Windows\System32\Faultrep.dll 14:05:50.0688 0x0a48 C:\Windows\System32\Faultrep.dll - ok 14:05:50.0693 0x0a48 [ 1CBF15FDB0310345A68972EB5C5B948F, E1EDCE6216B24037B243AC68CEEBD510646B2EFD70BC118E68303F9ED85D1973 ] C:\Windows\System32\mssprxy.dll 14:05:50.0693 0x0a48 C:\Windows\System32\mssprxy.dll - ok 14:05:50.0695 0x0a48 [ C2D6A4475B87651D5909E364439FDA52, BE9B898A8396F977E05A22D6EDF7B6B4EF4C16E159806453D03C2A918D24C19F ] C:\Windows\System32\FXSST.dll 14:05:50.0695 0x0a48 C:\Windows\System32\FXSST.dll - ok 14:05:50.0699 0x0a48 [ 5FEAB868CAEDBBD1B7A145CA8261E4AA, 08BACE187A0225E10677DE9AA6738A7118BE3E5CAD6DC45FB8D3366A61BB343C ] C:\Windows\System32\WerFault.exe 14:05:50.0699 0x0a48 C:\Windows\System32\WerFault.exe - ok 14:05:50.0703 0x0a48 [ 942E57152F1CD0533644AB30EF1A4728, 4F72510BECFAFDBB06C9CAAC66BA9E95225DE1EA12B4D2FD5B67492A2E628ABD ] C:\Windows\System32\FXSAPI.dll 14:05:50.0703 0x0a48 C:\Windows\System32\FXSAPI.dll - ok 14:05:50.0709 0x0a48 [ C4096CA42199428B3D63DC206C197F0E, 76336CD81608650E5AAD02D59D2AC752E7BDD057314BBC7334CECF74D1EAB587 ] C:\Windows\System32\FXSRESM.dll 14:05:50.0711 0x0a48 C:\Windows\System32\FXSRESM.dll - ok 14:05:50.0714 0x0a48 [ 8E8C92DD50F6B34907813AFDC0C8F7DD, EF7FF7CFAEB5D930EB96B5F81BD60EE23692E24A31650CA72B25164D20F2DAE4 ] C:\Windows\System32\dbgeng.dll 14:05:50.0714 0x0a48 C:\Windows\System32\dbgeng.dll - ok 14:05:50.0717 0x0a48 [ D39DA70FEA6BD713682F70635587DA9E, FF18C97642F48C711D75F32115B1260FE0BDF6072403E5A9226E9BE780AF1969 ] C:\Windows\System32\rasdlg.dll 14:05:50.0718 0x0a48 C:\Windows\System32\rasdlg.dll - ok 14:05:50.0721 0x0a48 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] C:\Windows\System32\FXSSVC.exe 14:05:50.0721 0x0a48 C:\Windows\System32\FXSSVC.exe - ok 14:05:50.0724 0x0a48 [ 47BB23927747B934C6690F86C33E3C16, 28009E9966CDA25DA61A3B25DB8B2A84FE765932D568D5DB335C0A955D834782 ] C:\Windows\System32\fthsvc.dll 14:05:50.0724 0x0a48 C:\Windows\System32\fthsvc.dll - ok 14:05:50.0727 0x0a48 [ 04B88428A872390D235BE52D38A9D4EF, F6954D514B67547738EB012456342D65289B0B18A0304BBAD5BDAA3436181C77 ] C:\Windows\System32\dot3api.dll 14:05:50.0727 0x0a48 C:\Windows\System32\dot3api.dll - ok 14:05:50.0730 0x0a48 [ 8063046AA70B97CA9985672B8848FB2E, C7A7F2D216D1F0D7F28A22E4933DB3D821AC52CC2EF7AE8BA08D18104FCF8B81 ] C:\Windows\System32\wlanhlp.dll 14:05:50.0730 0x0a48 C:\Windows\System32\wlanhlp.dll - ok 14:05:50.0738 0x0a48 [ B010CF886420EE29C2C276646721D255, CBCD032D679ADE3A9942A1D116648D6A9ECC71F66F8630629E724E5EE23F9F73 ] C:\Windows\System32\wlanapi.dll 14:05:50.0738 0x0a48 C:\Windows\System32\wlanapi.dll - ok 14:05:50.0740 0x0a48 [ 53683A331F8A1BB20ADD0330F1DE6388, 5525766F740268FF5287F927CD784B885F5B8523374AC2858256E6757CDED9F4 ] C:\Program Files\Windows Media Player\wmpnscfg.exe 14:05:50.0740 0x0a48 C:\Program Files\Windows Media Player\wmpnscfg.exe - ok 14:05:50.0742 0x0a48 [ C02AA67276FEE0C15CC4D6D616BDE95E, 24B0FFA2903CC77FEDE6B491647BB759C4AE054E38A19EFA0D2662AC2959570B ] C:\Windows\System32\WWanAPI.dll 14:05:50.0742 0x0a48 C:\Windows\System32\WWanAPI.dll - ok 14:05:50.0744 0x0a48 [ 8DFB5078508924FA725C203CE179B10C, A26A42B331C75D455074B597B982D4CB734B57F1F527C7B2EDBCD0746C38CD52 ] C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll 14:05:50.0744 0x0a48 C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll - ok 14:05:50.0753 0x0a48 [ 8F8AB20AA863EA95A421B9D54C74F20C, BA71E3EED39E78EC554049464D4112EB3A15419F0C5809D9C7CB7F1746BDEBD3 ] C:\Program Files\Windows Media Player\wmpnssci.dll 14:05:50.0753 0x0a48 C:\Program Files\Windows Media Player\wmpnssci.dll - ok 14:05:50.0760 0x0a48 [ F2ED6D00921CA138289E5E0CCB9ABF87, 528F249CE0835CA4D8B7C4940F5132DF1155EB344177BEA4CD7FCF9B8DCCCA4B ] C:\Windows\System32\wwapi.dll 14:05:50.0760 0x0a48 C:\Windows\System32\wwapi.dll - ok 14:05:50.0765 0x0a48 [ BB3C7E48088D37417EB37F1A9E3D2449, EA1AA2D208472790FCA1ACFC8A6DB9EAF0CDDE4E0B54B0B8631B3F6EC0FD56FF ] C:\Windows\System32\werui.dll 14:05:50.0765 0x0a48 C:\Windows\System32\werui.dll - ok 14:05:50.0770 0x0a48 [ 02530B0B7E048DD5AC8D52DAEACAEB2B, 2DEB454F8B71EC54C59185E2F1D679F7EC1C7AEFCD1D59761FDD3D70CABE0254 ] C:\Windows\System32\QAGENT.DLL 14:05:50.0770 0x0a48 C:\Windows\System32\QAGENT.DLL - ok 14:05:50.0774 0x0a48 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] C:\Program Files\Windows Media Player\wmpnetwk.exe 14:05:50.0774 0x0a48 C:\Program Files\Windows Media Player\wmpnetwk.exe - ok 14:05:50.0777 0x0a48 [ E3D5E244807AD655787FCD25477CC1BC, 8A378249C936914DBFEDAE310D6ACB93D488C8F490EC4AAB435861C413A5BB0F ] C:\Windows\System32\bthprops.cpl 14:05:50.0777 0x0a48 C:\Windows\System32\bthprops.cpl - ok 14:05:50.0779 0x0a48 [ DF13A51A5C591887D2EC6AE64CEED0FA, DFD503AEBCAA056B2B0E669ACA52F6D26F4E6892F2DCFCCD902752C23A621653 ] C:\Windows\System32\wsock32.dll 14:05:50.0779 0x0a48 C:\Windows\System32\wsock32.dll - ok 14:05:50.0782 0x0a48 [ 5CF15474FFDB5005E54958DF6EDD97AB, D4DBB3AACBB7679948258FFC53472FE8B5D0B3EC06D572EE2BDBF45CE608D86D ] C:\Windows\System32\wmdrmdev.dll 14:05:50.0782 0x0a48 C:\Windows\System32\wmdrmdev.dll - ok 14:05:50.0785 0x0a48 [ 47D052D9EE1FD3BA2A55D13F61E3EF24, 8DB44BA6FC0C49039F3E95D6137CFFF9EE0E0B24CA4E25342B7EFA897737DFAC ] C:\Windows\System32\drmv2clt.dll 14:05:50.0785 0x0a48 C:\Windows\System32\drmv2clt.dll - ok 14:05:50.0792 0x0a48 [ E0E5BB58A4C43F7DBB83352785F32DEF, 03000DF8B9C6D1E13F85730643797413EEE8221653A761FFBECB0AE64457F9E4 ] C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll 14:05:50.0792 0x0a48 C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll - ok 14:05:50.0797 0x0a48 [ 6C4B2E1A25841077084EB9F76FF6FFA7, 777D9E5D81409A54BF387BDDF4E471932FFB636406E390EC29EDF1FFFE3D8880 ] C:\Windows\System32\wmp.dll 14:05:50.0798 0x0a48 C:\Windows\System32\wmp.dll - ok 14:05:50.0800 0x0a48 [ 09A116FB06C5E362EF8938D29CDAB27B, 887B39388C39FF262FBBE3047FA1F5F47EB649AF3D760865AFE614DE64160D33 ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll 14:05:50.0800 0x0a48 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll - ok 14:05:50.0808 0x0a48 [ A0617B5753E31126AD29C03154F4F329, 3BC10C0A54D1D60B0C670D901944D3F115E2EBB406C989409145E7151AA55EFE ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll 14:05:50.0808 0x0a48 C:\Windows\Microsoft.NET\Framework\v2.0.50727\Culture.dll - ok 14:05:50.0816 0x0a48 [ 8050B4440BA297EFAE6616C4FF0EAD27, 0DEEA6A65AA0E2C516C76AF28C54CF88C78AE90187ADDCD066F1ABC8BD02C114 ] C:\Windows\System32\gfxSrvc.dll 14:05:50.0816 0x0a48 C:\Windows\System32\gfxSrvc.dll - ok 14:05:50.0818 0x0a48 [ 028B2DCFC468CF98B5428AF8AEF2C849, B161C28843A5F40406F7619DE182B2F3152B05B6C0B682B971A0C942D9317DFC ] C:\Windows\System32\IGFXDEVLib.dll 14:05:50.0818 0x0a48 C:\Windows\System32\IGFXDEVLib.dll - ok 14:05:50.0821 0x0a48 [ 9D99FBB1A50E798158726F5E0793A705, AE52E9BFEFDCB530D1711DBABCD2596D990E9E8A585930A9C962E0EBE297D3D8 ] C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll 14:05:50.0822 0x0a48 C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_pl_b77a5c561934e089\mscorlib.resources.dll - ok 14:05:50.0828 0x0a48 [ 6EF5F3F18413C367195F06E503AB86A6, 6F8B87FB4D67F9E76A51EF759B58A95D903C4AAC9C789A65A3FA1FC4F253D978 ] C:\Windows\System32\d3d9.dll 14:05:50.0828 0x0a48 C:\Windows\System32\d3d9.dll - ok 14:05:50.0832 0x0a48 [ 77B1471A490B53B24EFE136F09F76550, A650C3A244306F8E605BDA8E74BFE438356BA4403B0CB61E980D3183E3F0A7C7 ] C:\Windows\System32\d3d8thk.dll 14:05:50.0832 0x0a48 C:\Windows\System32\d3d8thk.dll - ok 14:05:50.0833 0x0a48 [ F5ECEAF5132D00B3DA565DBDD14E430F, 210689FA1967B007B9884D275100AA366F9197CF8EA3EE07BC3F75F48DE994FD ] C:\Windows\System32\igdumdx32.dll 14:05:50.0833 0x0a48 C:\Windows\System32\igdumdx32.dll - ok 14:05:50.0837 0x0a48 [ F58E87DE0F2855BAE62EED30D306358D, F26AF292B035EF3939D583FA38FB60C0A95C5E052245FB93B5066873A4C0A28F ] C:\Windows\System32\igdumd32.dll 14:05:50.0837 0x0a48 C:\Windows\System32\igdumd32.dll - ok 14:05:50.0846 0x0a48 [ 02DF0628BE8B64B84D50FBE53549AA3B, AED50B07451F14D0C0682EDDC11ED5BBAD63D6DB11A91826B0ADBDBE411F0084 ] C:\Windows\System32\wmploc.DLL 14:05:50.0846 0x0a48 C:\Windows\System32\wmploc.DLL - ok 14:05:50.0851 0x0a48 [ 3D232BA8915FEA0694B07E535FC8D03A, 7995028113425BC802A77F5529D49E9EBC3012117585AE079F694D969AA05EEF ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\System.Xml.ni.dll 14:05:50.0851 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\System.Xml.ni.dll - ok 14:05:50.0855 0x0a48 [ 0EF6ADCF0AEC1EB8B758A72FBA757A95, D374559A2F0CA85AD5CC2562A4EA9F2FAF7B29185E817E8AF0B671B7D0939D3B ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll 14:05:50.0855 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll - ok 14:05:50.0860 0x0a48 [ 03B3541AE6986602CF9CB5B3AD169C33, FC4B0ABA53EDB19DCBA00B8FEBE807643A4AB2D6B8337EE05CE2D0283BEF0F4E ] C:\Windows\System32\webcheck.dll 14:05:50.0860 0x0a48 C:\Windows\System32\webcheck.dll - ok 14:05:50.0867 0x0a48 [ 2DDEA2C345DA5BC589EFD398F220DB0E, B515B15BE7CB66F94B7A9B802719DAF7D50E1FE2832B66B6883AC0023060800D ] C:\Windows\System32\SyncCenter.dll 14:05:50.0867 0x0a48 C:\Windows\System32\SyncCenter.dll - ok 14:05:50.0870 0x0a48 [ 62A6EB5771580CAE445804389F3F7432, CC529625540204E82794E5494C063371BF7A5164823E6C3B2CCAAC030AE4D5AE ] C:\Windows\System32\WindowsCodecsExt.dll 14:05:50.0871 0x0a48 C:\Windows\System32\WindowsCodecsExt.dll - ok 14:05:50.0874 0x0a48 [ 816B681CC308FAA128EDCB90643DCED7, C2C6295F59F00F4D47673C361F1965BA62F9ADF6897A6A0BE224509628A27D7E ] C:\Windows\System32\icm32.dll 14:05:50.0874 0x0a48 C:\Windows\System32\icm32.dll - ok 14:05:50.0878 0x0a48 [ CB13488CD185012377DECBE0845567E8, 066FD57B3179F617171D55A701BE369BAA4756977706CA80817618F14A189341 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\8f2441d71e42bd17d5afd83524c67c57\WindowsFormsIntegration.ni.dll 14:05:50.0878 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\8f2441d71e42bd17d5afd83524c67c57\WindowsFormsIntegration.ni.dll - ok 14:05:50.0881 0x0a48 [ 2D11BC8B460957E62E4420373A0D8BDA, 56105E84333998D43DFCDA9E8A4D70EAC43076CFF8389B2E525EC5C3017DC5FD ] C:\Windows\System32\imapi2.dll 14:05:50.0881 0x0a48 C:\Windows\System32\imapi2.dll - ok 14:05:50.0885 0x0a48 [ C277FAB73175C5D37D35DE0DEB05D213, AB0DE2DCCA2133C2AF8C7F1154B4A7DE5FE3E20B3088084205CE1FA24777CD97 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\72284863df9bea3f081ae98996400619\PresentationFramework.Aero.ni.dll 14:05:50.0885 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\72284863df9bea3f081ae98996400619\PresentationFramework.Aero.ni.dll - ok 14:05:50.0888 0x0a48 [ C7952D0A4C43A965A1741916BB134751, 84EF222159E8C444A1D9D2E6509245716E4106C8032861DBFF399001A529BF94 ] C:\Windows\System32\hgcpl.dll 14:05:50.0888 0x0a48 C:\Windows\System32\hgcpl.dll - ok 14:05:50.0893 0x0a48 [ 65BFE7B5BE7F2F2ED4DD66830AB94019, AB473F650736204341F4B5C21B3C047FA2087B3EDBFDE9ED4CB863E83F3B659B ] C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_pl_31bf3856ad364e35\PresentationFramework.resources.dll 14:05:50.0893 0x0a48 C:\Windows\assembly\GAC_MSIL\PresentationFramework.resources\3.0.0.0_pl_31bf3856ad364e35\PresentationFramework.resources.dll - ok 14:05:50.0897 0x0a48 [ 12DDA8027618DE959EB6FD0A4FAB2DE8, 9566E57D0DC73E2B5F4432EC96196DCEE8B392DFBB2C529B1192CCCD4F1DAA1D ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll 14:05:50.0897 0x0a48 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll - ok 14:05:50.0900 0x0a48 Waiting for KSN requests completion. In queue: 2 14:05:51.0900 0x0a48 Waiting for KSN requests completion. In queue: 2 14:05:52.0900 0x0a48 Waiting for KSN requests completion. In queue: 2 14:05:53.0911 0x0a48 Win FW state via NFP2: enabled 14:05:56.0310 0x0a48 ============================================================ 14:05:56.0310 0x0a48 Scan finished 14:05:56.0310 0x0a48 ============================================================ 14:05:56.0318 0x0a40 Detected object count: 1 14:05:56.0318 0x0a40 Actual detected object count: 1 14:06:05.0707 0x0a40 C:\Windows\System32\Drivers\28925ee982f322e5.sys - copied to quarantine 14:06:05.0708 0x0a40 HKLM\SYSTEM\ControlSet001\services\28925ee982f322e5 - will be deleted on reboot 14:06:05.0731 0x0a40 HKLM\SYSTEM\ControlSet002\services\28925ee982f322e5 - will be deleted on reboot 14:06:05.0840 0x0a40 C:\Windows\System32\Drivers\28925ee982f322e5.sys - will be deleted on reboot 14:06:05.0840 0x0a40 28925ee982f322e5 ( Rootkit.Win32.Necurs.gen ) - User select action: Delete 14:06:06.0486 0x0a40 KLMD registered as C:\Windows\system32\drivers\06981823.sys 14:06:23.0521 0x00f0 Deinitialize success