23:28:10.0032 0x0598 TDSS rootkit removing tool 3.0.0.40 Jul 10 2014 12:37:58 23:28:10.0032 0x0598 UEFI system 23:28:13.0726 0x0598 ============================================================ 23:28:13.0726 0x0598 Current date / time: 2014/10/14 23:28:13.0726 23:28:13.0726 0x0598 SystemInfo: 23:28:13.0726 0x0598 23:28:13.0726 0x0598 OS Version: 6.3.9600 ServicePack: 0.0 23:28:13.0726 0x0598 Product type: Workstation 23:28:13.0726 0x0598 ComputerName: HP 23:28:13.0727 0x0598 UserName: hp_home 23:28:13.0727 0x0598 Windows directory: C:\Windows 23:28:13.0727 0x0598 System windows directory: C:\Windows 23:28:13.0727 0x0598 Running under WOW64 23:28:13.0727 0x0598 Processor architecture: Intel x64 23:28:13.0727 0x0598 Number of processors: 2 23:28:13.0727 0x0598 Page size: 0x1000 23:28:13.0727 0x0598 Boot type: Normal boot 23:28:13.0727 0x0598 ============================================================ 23:28:14.0430 0x0598 KLMD registered as C:\Windows\system32\drivers\03840874.sys 23:28:15.0335 0x0598 System UUID: {6A812116-38DD-42E6-FA55-440E94FC64ED} 23:28:16.0351 0x0598 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 23:28:16.0351 0x0598 ============================================================ 23:28:16.0351 0x0598 \Device\Harddisk0\DR0: 23:28:16.0351 0x0598 GPT partitions: 23:28:16.0351 0x0598 \Device\Harddisk0\DR0\Partition1: GPT, TypeGUID: {DE94BBA4-06D1-4D40-A16A-BFD50179D6AC}, UniqueGUID: {05DBFD75-2DAB-44BD-9D75-B3E53D236DF9}, Name: Basic data partition, StartLBA 0x800, BlocksNum 0x96000 23:28:16.0351 0x0598 \Device\Harddisk0\DR0\Partition2: GPT, TypeGUID: {C12A7328-F81F-11D2-BA4B-00A0C93EC93B}, UniqueGUID: {08CE76E6-05DD-4D44-87D6-AFAEF5A008D8}, Name: EFI system partition, StartLBA 0x96800, BlocksNum 0x32000 23:28:16.0351 0x0598 \Device\Harddisk0\DR0\Partition3: GPT, TypeGUID: {E3C9E316-0B5C-4DB8-817D-F92DF00215AE}, UniqueGUID: {FA0F05CE-8EFF-40CC-9459-6021F98DC423}, Name: Microsoft reserved partition, StartLBA 0xC8800, BlocksNum 0x40000 23:28:16.0351 0x0598 \Device\Harddisk0\DR0\Partition4: GPT, TypeGUID: {EBD0A0A2-B9E5-4433-87C0-68B6B72699C7}, UniqueGUID: {F8CE6274-F11B-4071-8BED-44610AD01B7B}, Name: Basic data partition, StartLBA 0x108800, BlocksNum 0x3A27D800 23:28:16.0351 0x0598 MBR partitions: 23:28:16.0351 0x0598 ============================================================ 23:28:16.0366 0x0598 C: <-> \Device\Harddisk0\DR0\Partition4 23:28:16.0366 0x0598 ============================================================ 23:28:16.0366 0x0598 Initialize success 23:28:16.0366 0x0598 ============================================================ 23:28:26.0335 0x0e30 ============================================================ 23:28:26.0335 0x0e30 Scan started 23:28:26.0335 0x0e30 Mode: Manual; SigCheck; 23:28:26.0335 0x0e30 ============================================================ 23:28:26.0335 0x0e30 KSN ping started 23:28:26.0398 0x0e30 KSN ping finished: false 23:28:28.0023 0x0e30 ================ Scan system memory ======================== 23:28:28.0023 0x0e30 System memory - ok 23:28:28.0023 0x0e30 ================ Scan services ============================= 23:28:28.0242 0x0e30 [ E1832BD9FD7E0FC2DC9FA5935DE3E8C1, 41FF7418887AFC8B9C96EF21C5950DD342CC9E3C0D87AFD60A05B988C1D6CC23 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys 23:28:28.0445 0x0e30 1394ohci - ok 23:28:28.0476 0x0e30 [ AD508A1A46EC21B740AB31C28EFDFDB1, 9B1046CF0B80723149BD359B55CC0B8B3ABBEAA9038469F542A4C345C503FB02 ] 3ware C:\Windows\system32\drivers\3ware.sys 23:28:28.0523 0x0e30 3ware - ok 23:28:28.0601 0x0e30 [ 9539F7917B4B6D92C90F0FAA6B86C605, B4C284E8EECC2E7025053A3320EFDC9F47BCA9828853AD2A805DB826CA4AC27E ] ACPI C:\Windows\system32\drivers\ACPI.sys 23:28:28.0664 0x0e30 ACPI - ok 23:28:28.0695 0x0e30 [ AC8279D229398BCF05C3154ADCA86813, 083E86CBE53244D24C334DB1511C77025133AE7875191845764B890A8CA5AFA9 ] acpiex C:\Windows\system32\Drivers\acpiex.sys 23:28:28.0726 0x0e30 acpiex - ok 23:28:28.0742 0x0e30 [ A8970D9BF23CD309E0403978A1B58F3F, 9946C8477104EEC7DB197E2222F9905307F101C398CCED4B5FD0F86A5622C791 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys 23:28:28.0835 0x0e30 acpipagr - ok 23:28:28.0867 0x0e30 [ 111A89C99C5B4F1A7BCE5F643DD86F65, 41A2E49FF443927D05F7EF638518108227852984E68D4663C8761178C0B84A45 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys 23:28:28.0976 0x0e30 AcpiPmi - ok 23:28:29.0007 0x0e30 [ 5758387D68A20AE7D3245011B07E36E7, 77832E200E8B0D259552F6F60FE454A887E3EBBB9EA2F3590E6645289A04E293 ] acpitime C:\Windows\System32\drivers\acpitime.sys 23:28:29.0085 0x0e30 acpitime - ok 23:28:29.0179 0x0e30 [ 7C1FDF1B48298CBA7CE4BDD4978951AD, 80F4D536E1231B30E836F72ADC8814AE6AA9FEC573FB5F3F965FAC8ABCCAF0F8 ] ADP80XX C:\Windows\system32\drivers\ADP80XX.SYS 23:28:29.0242 0x0e30 ADP80XX - ok 23:28:29.0289 0x0e30 [ 0F17D49BE041B7EFF1D33BF1414E7AC6, F8B536B60903814DF88DAF535753288537EF0993E42AA4E734EDA8D68B24C7AB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 23:28:29.0445 0x0e30 AeLookupSvc - ok 23:28:29.0507 0x0e30 [ 374E27295F0A9DCAA8FC96370F9BEEA5, 51C394E0C2322D7D093941A1B8766171B5D1F47DF2FE0834209492891EA7D999 ] AFD C:\Windows\system32\drivers\afd.sys 23:28:29.0601 0x0e30 AFD - ok 23:28:29.0617 0x0e30 [ 7DFAEBA9AD62D20102B576D5CAC45EC8, 9FA5207335303D1E8E9A3C9E1FB82C09AD21B04382F69D777A67E48EE91D2093 ] agp440 C:\Windows\system32\drivers\agp440.sys 23:28:29.0648 0x0e30 agp440 - ok 23:28:29.0679 0x0e30 [ 8E8E34B7BA059050EED827410D0697A2, 85B6684709F24729A6497563812A90A54068AC2DD9EEA03037CB1EEF5C85AAA9 ] ahcache C:\Windows\system32\DRIVERS\ahcache.sys 23:28:29.0789 0x0e30 ahcache - ok 23:28:29.0820 0x0e30 [ A91D8E1E433EFB32551BCE69037E1CE7, 41DFDD5B56918D19D09DFB3E4B07460AA85647A8647ABBBB906158D8D6653290 ] ALG C:\Windows\System32\alg.exe 23:28:29.0929 0x0e30 ALG - ok 23:28:29.0961 0x0e30 [ 6CF81DD5083D7F94A7E76E50429A949C, 19240502A6406924F889D1AFA975B975A300776D8B2D0557181DF13649622E2B ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe 23:28:30.0132 0x0e30 AMD External Events Utility - ok 23:28:30.0148 0x0e30 [ 7589DE749DB6F71A68489DCE04158729, 5F35EDD50737985595C9D6703237CA2ADE49AA5443331020899698EB5114A0FB ] AmdK8 C:\Windows\System32\drivers\amdk8.sys 23:28:30.0257 0x0e30 AmdK8 - ok 23:28:30.0695 0x0e30 [ 71F8D8B977ACC5973FA042BF906E709F, 8106C5F5C8E40344CCCDB912845786DF287BDF068D7A6EF9D26B00FA1754C1BC ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys 23:28:31.0289 0x0e30 amdkmdag - ok 23:28:31.0367 0x0e30 [ 4AA027F91A8093B1CDF453B5394F6715, E6D15E959637C102A34F73F66BFDC38436575A2FEFFC3976ACF399A472F126A5 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys 23:28:31.0570 0x0e30 amdkmdap - ok 23:28:31.0617 0x0e30 [ 8A375CB3B6D1A56A2AEEE72A5F1D0926, 03D6EA77B141675B719E66DA09D1DACC7137B19F9918C303DD6870B3F36ADEBB ] amdkmpfd C:\Windows\system32\drivers\amdkmpfd.sys 23:28:31.0664 0x0e30 amdkmpfd - ok 23:28:31.0711 0x0e30 [ B46D2D89AFF8A9490FA8C98C7A5616E3, BE0765B5423B690E0F097FECD9717FAA95BFDFFDC6CF1B93DE5A19A1B7797879 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys 23:28:31.0867 0x0e30 AmdPPM - ok 23:28:31.0914 0x0e30 [ D2BF2F94A47D332814910FD47C6BBCD2, FE273D77D119D958676E1197D9EA7B008E3B05C6192B1962A81D4223ED204C35 ] amdsata C:\Windows\system32\drivers\amdsata.sys 23:28:31.0961 0x0e30 amdsata - ok 23:28:32.0008 0x0e30 [ A8E04943C7BBA7219AA50400272C3C6E, 794C0BD12DF0392654E9A37AE4A24B5BE2D83F1F24F74DD48A1A0BF3AB8B1FF8 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys 23:28:32.0054 0x0e30 amdsbs - ok 23:28:32.0070 0x0e30 [ CEA5F4F27CFC08E3A44D576811B35F50, 89DF64B81BD109BAABAE93A4603C1617241219F38DDAF325EFE6BD35FF6FD717 ] amdxata C:\Windows\system32\drivers\amdxata.sys 23:28:32.0086 0x0e30 amdxata - ok 23:28:32.0101 0x0e30 [ 04951A9A937CBE28A2D3FEEA360B6D1F, D8AAF000BE4FE4B203DC2EB2A64F780A542E5238CE3F9952FD03277379B11529 ] AppID C:\Windows\system32\drivers\appid.sys 23:28:32.0273 0x0e30 AppID - ok 23:28:32.0304 0x0e30 [ C0DC3F58214A227980AEB091CFD2F973, 0C3E8453C9F65ADA3E74C38C0E3AC3E0CBFD807B827097046265B38839E151E3 ] AppIDSvc C:\Windows\System32\appidsvc.dll 23:28:32.0398 0x0e30 AppIDSvc - ok 23:28:32.0414 0x0e30 [ 8D6F535461F6CFF75A8ADDF83024C904, F2A97EC4A6284F28B685A3CE2D450F61E75EE8692D718A6AA352D5734BBBAD7B ] Appinfo C:\Windows\System32\appinfo.dll 23:28:32.0445 0x0e30 Suspicious file ( Forged ): C:\Windows\System32\appinfo.dll. Real md5: 8D6F535461F6CFF75A8ADDF83024C904, sha256: F2A97EC4A6284F28B685A3CE2D450F61E75EE8692D718A6AA352D5734BBBAD7B, fake md5: 7667B9D81EA8FD6540E6CF72F92161A6, fake sha256: 98F3D0E376F715EBE083FE112CAA640BCE0F13DCE0F244D059D7FA019EA3D24C 23:28:32.0445 0x0e30 Appinfo - detected ForgedFile.Multi.Generic ( 1 ) 23:28:32.0554 0x0e30 Object is SCO, delete is not allowed 23:28:32.0554 0x0e30 Appinfo ( ForgedFile.Multi.Generic ) - warning 23:28:32.0601 0x0e30 [ CB12C47647D8BDAFAA94C0856B14128B, 5590C98095357C92563EF94800107D3611AA6ECA1A70BE463C03B279E618A6C4 ] AppReadiness C:\Windows\system32\AppReadiness.dll 23:28:32.0679 0x0e30 AppReadiness - ok 23:28:32.0773 0x0e30 [ F7529BD3FFAC9C33D15F6DE3B7353B03, 8EF0A84C9687A246B60939A326E498121039E9CC617A7ABBA933EDD327F3467E ] AppXSvc C:\Windows\system32\appxdeploymentserver.dll 23:28:32.0883 0x0e30 AppXSvc - ok 23:28:32.0945 0x0e30 [ 65045784366F7EC5FB4E71BCF923187B, 53C215C64FF12E44B097F7CB88E8482438CE0ACBD3C68D8FD38BA0D0D8747FAA ] arcsas C:\Windows\system32\drivers\arcsas.sys 23:28:32.0976 0x0e30 arcsas - ok 23:28:32.0992 0x0e30 [ 3DB7721F06BC2FEDB25029EA23AB27DA, 221861148C66FE53E4D6EE49C6E656479AB5804A2D348A280A1CD8093E8AB788 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 23:28:33.0054 0x0e30 AsyncMac - ok 23:28:33.0086 0x0e30 [ 74B14192CF79A72F7536B27CB8814FBD, 0CF6BBB63FFE0C12777664D80B2797923844C8392D0FD81D7962EE5EE2C3C3D9 ] atapi C:\Windows\system32\drivers\atapi.sys 23:28:33.0101 0x0e30 atapi - ok 23:28:33.0133 0x0e30 [ 886767FD022213F7885416134E9082E5, E248D82210FBEBF62C23EBEC74A976B2D1A4E62D3B7638D95B2574B77BA05DD0 ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll 23:28:33.0211 0x0e30 AudioEndpointBuilder - ok 23:28:33.0258 0x0e30 [ 79B134ECE836B406B212E28C24011538, 1B875DD23CCAD8A2759DCDBCDCF3DE14231B9DB5EEC8E84FE081E41A52A047A1 ] Audiosrv C:\Windows\System32\Audiosrv.dll 23:28:33.0414 0x0e30 Audiosrv - ok 23:28:33.0492 0x0e30 [ 636B15879AE62E47444F99C60C900AA6, 335B1378037B2CFEBDAA95B1ABB619A4C18C5CD37A12688E606E7A12BE31735C ] avc3 C:\Windows\system32\DRIVERS\avc3.sys 23:28:33.0554 0x0e30 avc3 - ok 23:28:33.0648 0x0e30 [ 3B9549FEF98AB1768A1D6A919F355B70, 0014914051CB54CD7CC25561D29099A19DCFB2E1810FF635F9B6AD3D9C6FBC4B ] avchv C:\Windows\system32\DRIVERS\avchv.sys 23:28:33.0711 0x0e30 avchv - ok 23:28:33.0742 0x0e30 [ 14023A39BC91AC5A2077766D28EBA7C5, 855FEE69105438ADE79C9389E0581C62FE1D134863F8D6FA27DE83737E4B4213 ] avckf C:\Windows\system32\DRIVERS\avckf.sys 23:28:33.0820 0x0e30 avckf - ok 23:28:33.0851 0x0e30 [ 96E8CAF20FC4B6C31CAD7816A801EB78, E4870DB8FFBDCFEE98449338D0BDBF2DD0B5FEC75514E41C11A882BE6EB16833 ] AxInstSV C:\Windows\System32\AxInstSV.dll 23:28:34.0039 0x0e30 AxInstSV - ok 23:28:34.0117 0x0e30 [ A4A73F631FE2AA2826FBE4A399B04DEF, 973AACE8DC8DA669D0DF20F17EFDEEABB90AA046AC980948D16A62D39A606A79 ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys 23:28:34.0164 0x0e30 b06bdrv - ok 23:28:34.0180 0x0e30 [ 8CC7F7E4AFCBA605921B137ED7992C68, 71406E6D6E9964740A6D90B05329D5492BB90AF40E0630CF2FBF4BA4BA14F2DD ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys 23:28:34.0289 0x0e30 BasicDisplay - ok 23:28:34.0320 0x0e30 [ 38A82F4EE8C416A6744B6D30381ED768, 9EAAE5F43BA09359130AC04B1DCA0F5D4DF32ED89C02DC5CEB640918948847F7 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys 23:28:34.0508 0x0e30 BasicRender - ok 23:28:34.0555 0x0e30 [ C1ABB0F7E3BEA48A0417BDF6FF14AB21, 1CAC63A1A0FB9855A27EE977794576A860F6650C9EF7667FFB27F2A2FF721857 ] bcmfn2 C:\Windows\System32\drivers\bcmfn2.sys 23:28:34.0586 0x0e30 bcmfn2 - ok 23:28:34.0680 0x0e30 [ B56C89AC51CDE54CBDC5E49B94ED54BF, 7EA4C4F838B498944F21E91640535B5507C00A71F2FBEA3A5E9E25900EE3C95D ] BdDesktopParental C:\Program Files\Bitdefender\Bitdefender\bdparentalservice.exe 23:28:34.0726 0x0e30 BdDesktopParental - ok 23:28:34.0758 0x0e30 [ 3701D3BF4AC12EAACB1F58847C1D32FC, 29F3DA7E4C1706934BE92D03CB6F633C47D0251E5580958E823B6148DA5E5E73 ] bdelam C:\Windows\system32\drivers\bdelam.sys 23:28:34.0789 0x0e30 bdelam - ok 23:28:34.0820 0x0e30 [ E07C80468D0C599BFF01D9D4EC7AEDC3, F675F455924DEC3FF69AD816DFEB6E74C804AEC3D3BFF7515953DB9D79C9B2D0 ] BDESVC C:\Windows\System32\bdesvc.dll 23:28:34.0914 0x0e30 BDESVC - ok 23:28:34.0976 0x0e30 [ 78612E1E8D62AA1FDD56FAAE6A7C1BD6, E014BF19D38BA2C8C23E9B866DA36EBE92CA8D3F95D6CDD10F90B909F85B513C ] BdfNdisf C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys 23:28:35.0039 0x0e30 BdfNdisf - ok 23:28:35.0070 0x0e30 [ 923E8216382E2F64EC8AADBA3C2CFFEE, 3811C5B18CEDCA3E7951950605B4A59301D5E2188E0752E26F1A1F8B868B8E13 ] bdfwfpf C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys 23:28:35.0101 0x0e30 bdfwfpf - ok 23:28:35.0133 0x0e30 [ C0247341C1BCD7FF2742821D0AD7AFBC, EC2B246F3233302DB540394AC0F11F294CA16FB9E44110126CC9807BAC20EA35 ] bdfwfpf_pc C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf_pc.sys 23:28:35.0148 0x0e30 bdfwfpf_pc - ok 23:28:35.0148 0x0e30 [ B9ECE7FD9F58DAF19450C88338DC5267, 9857DFE0BDDEA791F2DDA99C24A064D488B52E4AC1402A37EF22C244C9283681 ] BDSandBox C:\Windows\system32\drivers\bdsandbox.sys 23:28:35.0195 0x0e30 BDSandBox - ok 23:28:35.0211 0x0e30 [ EC19013E4CF87609534165DF897274D6, 8ED45537CF2D58D759A587CCBFDADD5580C7447B0C3B172CF19ECC7585E073FC ] Beep C:\Windows\system32\drivers\Beep.sys 23:28:35.0320 0x0e30 Beep - ok 23:28:35.0414 0x0e30 [ 20FB137ADDE1255F15F265A7BD9579BE, 87B4D5C91EFEAD987AAC3491A4360F82824C46AFF958B6F4CAED7C12224EF159 ] BFE C:\Windows\System32\bfe.dll 23:28:35.0539 0x0e30 BFE - ok 23:28:35.0633 0x0e30 [ 15225081966C785A9192782401643FD4, E2BA0C8D044556FDD9DD7A25F7F71553DE7A2924E78F9284413C2AC46F0BF4EB ] BITS C:\Windows\System32\qmgr.dll 23:28:35.0758 0x0e30 BITS - ok 23:28:35.0789 0x0e30 [ 6B4FFFDDC618FCF64473CAA86E305697, 29EA66071D5822920F5C50533673ADAB5204F8B25C11027AD27450D881F1142D ] bowser C:\Windows\system32\DRIVERS\bowser.sys 23:28:35.0867 0x0e30 bowser - ok 23:28:35.0914 0x0e30 [ F2559A492AF8D653D1F47ADABA4C3E97, 77347915FB433023769699DFC9511F54E69C7FC7AB75F57FDC1A58E64A7126DE ] BrokerInfrastructure C:\Windows\System32\bisrv.dll 23:28:35.0976 0x0e30 Suspicious file ( Forged ): C:\Windows\System32\bisrv.dll. Real md5: F2559A492AF8D653D1F47ADABA4C3E97, sha256: 77347915FB433023769699DFC9511F54E69C7FC7AB75F57FDC1A58E64A7126DE, fake md5: E325BCD68EC0CF2E2EDD0AB7CC17C698, fake sha256: 4DEDEF91F6BD1CC8DBE118AC28CA6BD874449A053B9CDE9FFEB1C7B98501D938 23:28:35.0976 0x0e30 BrokerInfrastructure - detected ForgedFile.Multi.Generic ( 1 ) 23:28:35.0976 0x0e30 BrokerInfrastructure ( ForgedFile.Multi.Generic ) - warning 23:28:36.0008 0x0e30 [ 041A999E4FF9A7CDBE67357751881FB8, 356C52637EA715D6FA2B65BD311C9BF1635A582023434902EC2DE4A2448961F8 ] Browser C:\Windows\System32\browser.dll 23:28:36.0148 0x0e30 Browser - ok 23:28:36.0164 0x0e30 [ A8F23D453A424FF4DE04989C4727ECC7, AE4A9081395C7379F1C947EF8243F7609F90C843E086B8E77E1A2C06E36D4381 ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys 23:28:36.0258 0x0e30 BthAvrcpTg - ok 23:28:36.0320 0x0e30 [ 746B9F94214915AECDE4B7FEA5FF9664, EA2877D49DB4B7B9CE61653D63E8776DFF1CBCCAB12C14DB1D20DA44B8F06357 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys 23:28:36.0398 0x0e30 BthHFEnum - ok 23:28:36.0445 0x0e30 [ 71FE2A48E4C93DDB9798C024880B6C07, 8E93DE29C61A5FA64216231228CB3C4A1A693FE87CAA2C070BCAD7BE2D8ED000 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys 23:28:36.0523 0x0e30 bthhfhid - ok 23:28:36.0539 0x0e30 [ 66B791F6B11DC4303DD18A224A501542, 502AE4D6FFC6B0FCED081B0E0F61F699F96F20DFEE737B53828F5DEE3BD0FCB1 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys 23:28:36.0601 0x0e30 BTHMODEM - ok 23:28:36.0633 0x0e30 [ E5E48FEED73D463175EAB1542495191C, 0A8182F5BA7B694AB1DD3680F1194E4A568FE40DBA4BFDFF2EA09BAD045FFB29 ] bthserv C:\Windows\system32\bthserv.dll 23:28:36.0680 0x0e30 bthserv - ok 23:28:36.0711 0x0e30 [ 2FA6510E33F7DEFEC03658B74101A9B9, 61C8C8E3F09B427711464C974EE22E1E01C48E10DB54A4EC9901F482FC36C978 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 23:28:36.0758 0x0e30 cdfs - ok 23:28:36.0773 0x0e30 [ C6796EA22B513E3457514D92DCDB1A3D, 2B893F3950C6B913B934C2089B69F3B0B77F229AE1820907E598455CBB78139C ] cdrom C:\Windows\System32\drivers\cdrom.sys 23:28:36.0867 0x0e30 cdrom - ok 23:28:36.0898 0x0e30 [ AB285CE3431FF3D2ACE669245874C1C7, 6AF4C3E86EFA51F7FB6F8492CB2CCB807C7775EAE0508B87F07134FDAC679BD7 ] CertPropSvc C:\Windows\System32\certprop.dll 23:28:37.0117 0x0e30 CertPropSvc - ok 23:28:37.0133 0x0e30 [ BE9936EDD3267FAAFF94A7835867F00B, 3CEEF2377D45ED38C7CD3CE4C746EC5EA7277EFEC728A5438F0EF5F62FC7C859 ] circlass C:\Windows\System32\drivers\circlass.sys 23:28:37.0242 0x0e30 circlass - ok 23:28:37.0289 0x0e30 [ 179A41249055D5F039F1B6703F3B6D2B, 886CF715D9E85DB5C9B991EBCB9B12E27AA0EEE52528E222C80CA5B5B0A7AF52 ] CLFS C:\Windows\system32\drivers\CLFS.sys 23:28:37.0367 0x0e30 CLFS - ok 23:28:37.0430 0x0e30 [ EF6EF85DADC3184A10D8F2F7159973CB, 42FCB286CED95A5DEBC5C0C894FCBC4818A2C818BB71087142FB51A08A0BE96B ] CmBatt C:\Windows\System32\drivers\CmBatt.sys 23:28:37.0523 0x0e30 CmBatt - ok 23:28:37.0570 0x0e30 [ 1CD3A907D64D08F49208DA00B69BF35E, ABBD70FFCA0DE2274D855AFC08BF7BC0AA6D44EFC9FDBF7DF44B73CD5C210E28 ] CNG C:\Windows\system32\Drivers\cng.sys 23:28:37.0586 0x0e30 Suspicious file ( Forged ): C:\Windows\system32\Drivers\cng.sys. Real md5: 1CD3A907D64D08F49208DA00B69BF35E, sha256: ABBD70FFCA0DE2274D855AFC08BF7BC0AA6D44EFC9FDBF7DF44B73CD5C210E28, fake md5: 593CA2F3E870D586C20A332171988AFF, fake sha256: A811C1ED00E616D0F752EB35D03DD4CA852503D4B8553B99EBE1212D915E7448 23:28:37.0586 0x0e30 CNG - detected ForgedFile.Multi.Generic ( 1 ) 23:28:37.0586 0x0e30 CNG ( ForgedFile.Multi.Generic ) - warning 23:28:37.0586 0x0e30 Force sending object to P2P due to detect: CNG 23:28:37.0633 0x0e30 Object send P2P result: false 23:28:37.0695 0x0e30 [ 03AAED827C36F35D70900558B8274905, 8E44A23C6013FFAE7769F99CAA3B1D6288DE00A38937F9056903AC265B503AFA ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys 23:28:37.0773 0x0e30 CompositeBus - ok 23:28:37.0789 0x0e30 COMSysApp - ok 23:28:37.0805 0x0e30 [ A1FF7DFBFBE164CF92603C651D304DD2, 470ACE5A75E64FC62C950037201199857E974803625DC73BEDBCF6FA4DDD496C ] condrv C:\Windows\system32\drivers\condrv.sys 23:28:37.0898 0x0e30 condrv - ok 23:28:37.0977 0x0e30 [ 08F934092E0429BADF88E9F91DB0F61E, 6E9091C006FFFF261DC61C8E9A45219E47C351296E5355FC4B7242F30E1DDFE3 ] cphs C:\Windows\SysWow64\IntelCpHeciSvc.exe 23:28:38.0086 0x0e30 cphs - ok 23:28:38.0148 0x0e30 [ 3CA734CE373E5675FBC15CA2C45228E5, A6C6E9FABDE5EA18D266DB71C0CC6B51D682116D1898CCB4E9BA730F15C44B32 ] cpudrv64 C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys 23:28:38.0211 0x0e30 cpudrv64 - ok 23:28:38.0273 0x0e30 [ 0EFE4B5884A8032617826A4D76F80969, 083D296CC623C83D36A97AEE343ADF819B17E490F931DBE4D161BD1E8C289E02 ] CryptSvc C:\Windows\system32\cryptsvc.dll 23:28:38.0352 0x0e30 CryptSvc - ok 23:28:38.0398 0x0e30 [ 315BA4BC19316D72B2E037534E048B93, 69613635DB23E6A935673B1025C2010ED3E195473D25368CF74234C4C36910BE ] dam C:\Windows\system32\drivers\dam.sys 23:28:38.0430 0x0e30 dam - ok 23:28:38.0492 0x0e30 [ 81979817943D830BF24571B7C1B28A1A, 9584D8F1FB3E6CF17BD465670B208C723A8E8B06775A3DA44F75D7710404EEA6 ] DcomLaunch C:\Windows\system32\rpcss.dll 23:28:38.0633 0x0e30 DcomLaunch - ok 23:28:38.0695 0x0e30 [ D249C3A58A4FCF755EF4C94F7047E015, 68C044CE2DB93FB502F85F6E081EA164F6E6DCBA6B3EE2A5CBDA122065E522F8 ] defragsvc C:\Windows\System32\defragsvc.dll 23:28:38.0758 0x0e30 defragsvc - ok 23:28:38.0805 0x0e30 [ 8F387C2C99EE09C6E2AC316205F86A17, EC9E8AE72A21992AA118964E17090BA4503EB051273AD18185C95172F57328CE ] DeviceAssociationService C:\Windows\system32\das.dll 23:28:38.0914 0x0e30 DeviceAssociationService - ok 23:28:38.0961 0x0e30 [ BC6849C62DB407573C6AD8CB1A4D2628, 5BDE0D60F85E4C27CEAD1B301155B54D841FB773BD5BB8AC5DDAEE31F8E94627 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll 23:28:39.0023 0x0e30 DeviceInstall - ok 23:28:39.0070 0x0e30 [ A03F362C5557E238CBFA914689C77248, BAD0A1124E6A384C15028FBE121ADF650F7716442555AD3737B9EA1F58A69246 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys 23:28:39.0195 0x0e30 Dfsc - ok 23:28:39.0242 0x0e30 [ 05DE04005CE0D84D0E6AD21CAEB369C6, E6704A2A685BCFD560796D7C328F8E53DF0793DBDA590598A492D9070D109298 ] Dhcp C:\Windows\system32\dhcpcore.dll 23:28:39.0383 0x0e30 Dhcp - ok 23:28:39.0414 0x0e30 [ 4D40C9B33F738797CF50E77CB7C53E85, 7BA341342A47DEB15B51971C97A5237ACD8BDAD9033F63DF0000892BE43F8E13 ] disk C:\Windows\system32\drivers\disk.sys 23:28:39.0477 0x0e30 disk - ok 23:28:39.0524 0x0e30 [ EB70A894708D1BC176AFD690FF06085F, 0DD2A97F5E1B38D1F7C0D44E50F09EA222B18B3B074CC9C8CD25A7526CB1A112 ] dmvsc C:\Windows\System32\drivers\dmvsc.sys 23:28:39.0602 0x0e30 dmvsc - ok 23:28:39.0648 0x0e30 [ A1C0A8CFE138A617565523CAD717EF81, C1C449F2F601F0777EBE576CDBDE598F1717E2A98982F14A6E558E44EA6D1BC9 ] Dnscache C:\Windows\System32\dnsrslvr.dll 23:28:39.0758 0x0e30 Dnscache - ok 23:28:39.0805 0x0e30 [ 50288EA079BB520C2B8C8A154202D518, 8916A9180CA009D124FFDFB4CCF5FDFEF7FA2FD37CBCD49FAD4C68E051B4734D ] dot3svc C:\Windows\System32\dot3svc.dll 23:28:39.0899 0x0e30 dot3svc - ok 23:28:39.0945 0x0e30 [ 281BEE07BA97E3E98D12A822D923D0D8, 6EB482B2D4D6048D145C3738B2B6FA27A90B5EA53E9167447820F9981B004E63 ] DPS C:\Windows\system32\dps.dll 23:28:40.0102 0x0e30 DPS - ok 23:28:40.0133 0x0e30 [ DDC11A202207C0400CBE07315B8FDE5E, 3ED0CA3A714582D92001BA3BFF78BE082F4DC8021298D5A2632F3B2B0A1C09DC ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 23:28:40.0164 0x0e30 drmkaud - ok 23:28:40.0211 0x0e30 [ 5B074F14F5DD6418F46EE4CA2DEB7EA8, B8223D73C3DE123759101F7D5D45C60BD12B221F09D349575A1044CE3F43CBC5 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll 23:28:40.0305 0x0e30 DsmSvc - ok 23:28:40.0367 0x0e30 [ 0359D701C5ADE2F11D758BA2C5CDBD69, 9F6D64C4999AC944D0F6A68ED683F73410CB217732ABAEB4CE95E1638386BCCA ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 23:28:40.0461 0x0e30 DXGKrnl - ok 23:28:40.0477 0x0e30 [ 6073537F250B45E1CB2A02E97F0FE1B2, 653F3F2F2019168EDF225944A88AFDBF8393B62AA076BD19980691778F3DB67D ] Eaphost C:\Windows\System32\eapsvc.dll 23:28:40.0539 0x0e30 Eaphost - ok 23:28:40.0711 0x0e30 [ 114BCFDF367FF37C3F1B0A96AF542E4D, D385BC1D91BC1406091C8C3691C07A90BD60EDE05B1384E5AA3506FCB909C857 ] ebdrv C:\Windows\system32\drivers\evbda.sys 23:28:40.0867 0x0e30 ebdrv - ok 23:28:40.0899 0x0e30 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] EFS C:\Windows\System32\lsass.exe 23:28:40.0945 0x0e30 EFS - ok 23:28:40.0992 0x0e30 [ 43531A5993380CC5113242C29D265FD9, EE0076D96F7F3CF29884AC7A67C08A429115A7201354A1FB5DE45FD63ABB4960 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys 23:28:41.0070 0x0e30 EhStorClass - ok 23:28:41.0102 0x0e30 [ 6F8E738A9505A388B1157FDDE7B3101B, 3696CA634102B41EEA11EB9DCA0B24439D8636AED4A7190C138C5E64A2EFB514 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys 23:28:41.0164 0x0e30 EhStorTcgDrv - ok 23:28:41.0195 0x0e30 [ DFFFAE1442BA4076E18EED5E406FA0D3, 329FC6FB8D14BEACDBE2A5D4C496EDEA485E838B1DF27566E278F8F8E0D8E82E ] ErrDev C:\Windows\System32\drivers\errdev.sys 23:28:41.0274 0x0e30 ErrDev - ok 23:28:41.0430 0x0e30 [ 030CE75B7D8F75FAA7BA1EC6FD0EB5A3, 5264734F0572FAEDCCB008221C9982CCB7922C4FFC358605424EA413CDCDAE99 ] EventSystem C:\Windows\system32\es.dll 23:28:41.0508 0x0e30 EventSystem - ok 23:28:41.0539 0x0e30 [ 7729D294A555C7AEB281ED8E4D0E01E4, 7269E79D72CCE477AC108294D0DDFB59CF533B03C587599C5AB0507C43A0B6D4 ] exfat C:\Windows\system32\drivers\exfat.sys 23:28:41.0680 0x0e30 exfat - ok 23:28:41.0711 0x0e30 [ 7C4E0D5900B2A1D11EDD626D6DDB937B, 732F310F8F6016C56F432A81636B13CE0124A802FE8DD91287B618EED22C9A1D ] fastfat C:\Windows\system32\drivers\fastfat.sys 23:28:41.0774 0x0e30 fastfat - ok 23:28:41.0820 0x0e30 [ 2BC8532ABF2B3756B78FA1DA54147DDE, DF65EE2AB0255A2CF3221085A6BE7C37E3DB6BFEED3BCADCDD69BB1049F6DCB1 ] Fax C:\Windows\system32\fxssvc.exe 23:28:41.0914 0x0e30 Fax - ok 23:28:41.0930 0x0e30 [ 5D8402613E778B3BD45E687A8372710B, EE9EA10805168D309A609B9019AEC5961EE46D18207B5E0EA2DE4064A5770AF8 ] fdc C:\Windows\System32\drivers\fdc.sys 23:28:41.0992 0x0e30 fdc - ok 23:28:42.0024 0x0e30 [ DC1A78BCCCB7EE53D6FD3BD615A8E222, EE16B6853185AAE779D7135035983938009901658F76A8856AAC12EBA15BB34E ] fdPHost C:\Windows\system32\fdPHost.dll 23:28:42.0086 0x0e30 fdPHost - ok 23:28:42.0117 0x0e30 [ E5AD448F2DC84B1CF387FA7F2A3D1936, BBB29C79A085C503F5EFFB5144596D5DEC48A4EB34A049A4E7B38B27F6D92E0A ] FDResPub C:\Windows\system32\fdrespub.dll 23:28:42.0164 0x0e30 FDResPub - ok 23:28:42.0211 0x0e30 [ 0046E0BD031213D37123876B0D0FA61C, A4FE17D56F0BAFB70D0D421ED9D1B6E50AF8ADAA4B59328A41AEC5B4C068A3CB ] fhsvc C:\Windows\system32\fhsvc.dll 23:28:42.0305 0x0e30 fhsvc - ok 23:28:42.0321 0x0e30 [ BCFD8B149B3ADF92D0DB1E909CAF0265, 002B085C131473642450176B4B8359F3E5B04350AFB659B9C0F9EB587D1181E7 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 23:28:42.0367 0x0e30 FileInfo - ok 23:28:42.0399 0x0e30 [ A1A66C4FDAFD6B0289523232AFB7D8AF, 0F5832F626BB62190D5F3A088CE6E048D8A400CCF9EA527F06973CAD96D3A81C ] Filetrace C:\Windows\system32\drivers\filetrace.sys 23:28:42.0508 0x0e30 Filetrace - ok 23:28:42.0524 0x0e30 [ BE743083CF7063C486A4398E3AEFE59A, 85796D89943DD6FE3932C1ED6CF01470C1B4DFD243C390B07055FFDA3C231551 ] flpydisk C:\Windows\System32\drivers\flpydisk.sys 23:28:42.0586 0x0e30 flpydisk - ok 23:28:42.0633 0x0e30 [ 6592D192E2823C043EDBC010E7774053, C025A0EC5517DC3BD5D6656DC0F0F19021FB3D2EE90EC6194E1BD74E638EBBDC ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 23:28:42.0680 0x0e30 FltMgr - ok 23:28:42.0774 0x0e30 [ 3FA6DC6B29717E32E211C1FD821F2C75, E467F3775427C93CC2B87327B0A45669631A5FC460C558F6796BA26002A8BBFC ] FontCache C:\Windows\system32\FntCache.dll 23:28:42.0852 0x0e30 FontCache - ok 23:28:42.0914 0x0e30 [ 1C52387BF5A127F5F3BFB31288F30D93, 90D13F60170CD74304F3036A90D596AA3E1E134455A780310BDF67AC7815F2E7 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 23:28:42.0961 0x0e30 FontCache3.0.0.0 - ok 23:28:42.0977 0x0e30 [ 35005534E600E993A90B036E4E599F2B, DA56FA3776FBD3D50276CB7410E0CB6F137DD8FCA84C0F3FEF8B1FEA5F6CA592 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys 23:28:43.0008 0x0e30 FsDepends - ok 23:28:43.0039 0x0e30 [ 09F460AFEDCA03F3BF6E07D1CCC9AC42, B832091BC9B2C2FE38A4BCA132ABB58251E851F21EC6F39636E73777AB9A5791 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 23:28:43.0071 0x0e30 Fs_Rec - ok 23:28:43.0133 0x0e30 [ F152D55E497E12256290C43B31C7D0CE, FFC54B14CCFBC1548948C07FB3866E40A11D0C05AC352BD000E71CEF053F6A6E ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys 23:28:43.0196 0x0e30 fvevol - ok 23:28:43.0227 0x0e30 [ 9591D0B9351ED489EAFD9D1CE52A8015, AC64C236C3AE545FCE8ED44A4A87FB86265A453BA60026EC9A4DE2B631E99996 ] FxPPM C:\Windows\System32\drivers\fxppm.sys 23:28:43.0289 0x0e30 FxPPM - ok 23:28:43.0321 0x0e30 [ FC3EF65EE20D39F8749C2218DBA681CA, 12980F1DE99B25E6920A33556F3ABDA5EC9BFE4757BE602130B5E939D8D25CE3 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 23:28:43.0352 0x0e30 gagp30kx - ok 23:28:43.0367 0x0e30 [ 0BF5CAD281E25F1418E5B8875DC5ADD1, 0929AD8437DD78234553D8B2CDF0D6838FD54ACDE1918AFEBE48684EB32A07A3 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys 23:28:43.0399 0x0e30 gencounter - ok 23:28:43.0446 0x0e30 [ 8DF1254093B5C354CE725EB6B9B0DE19, DE6C5661CC076DA44B8A5D044FDB7280EDCF38D322A98C14FDC82E25586B3014 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys 23:28:43.0492 0x0e30 GPIOClx0101 - ok 23:28:43.0571 0x0e30 [ 69DB09F0263C637DA8568D404842466A, D042194266978AAD31E04DAF7018CD50754077212DC74A4D8AFF6BFEE80CDD20 ] gpsvc C:\Windows\System32\gpsvc.dll 23:28:43.0696 0x0e30 gpsvc - ok 23:28:43.0742 0x0e30 [ 0A9D58AABD01DA97B1D101473EFA7659, C18EA4F5BF569C230AD682A418F69B6E4209AD467BCCBDABD0515DBB582BF04B ] gzflt C:\Windows\system32\DRIVERS\gzflt.sys 23:28:43.0789 0x0e30 gzflt - ok 23:28:43.0836 0x0e30 [ 56F69F7C25FB67C970997D7066DBC593, 83E03A82237DCC5BCB3E722ACECACEF3510CAA619F33E0D7C4D902A482E90418 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 23:28:43.0961 0x0e30 HdAudAddService - ok 23:28:43.0977 0x0e30 [ D4B7ED39C7900384D9E5C1283F1E7926, F93F98858067B40F1C071EAD0F8E85442A78B95342BC692AF4D726540634923F ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys 23:28:44.0086 0x0e30 HDAudBus - ok 23:28:44.0117 0x0e30 [ 10A70BC1871CD955D85CD88372724906, 2480A74854D0A89FF028EE9BA41224D4B2F9B0863066BFC43097920794FEE08D ] HidBatt C:\Windows\System32\drivers\HidBatt.sys 23:28:44.0164 0x0e30 HidBatt - ok 23:28:44.0196 0x0e30 [ 1EA1B4FABB8CC348E73CA90DBA22E104, 5C18C6BD499272F216DD4626B5E8D38181AEAC9AD917FBEB614A75B70467B258 ] HidBth C:\Windows\System32\drivers\hidbth.sys 23:28:44.0211 0x0e30 HidBth - ok 23:28:44.0242 0x0e30 [ C241A8BAFBBFC90176EA0F5240EACC17, 571E20B87818618BE9179986177D55739A240F04D1F740B3C1B7809B9427B767 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys 23:28:44.0289 0x0e30 hidi2c - ok 23:28:44.0321 0x0e30 [ 9BDDEE26255421017E161CCB9D5EDA95, B766FD5E31708F29384F69418FC33C4BCC6E3064AA553D5B1D30EE0B8B1BFB40 ] HidIr C:\Windows\System32\drivers\hidir.sys 23:28:44.0383 0x0e30 HidIr - ok 23:28:44.0430 0x0e30 [ 449A20A674AA3FAA7F0DD4E33EE2DC20, 28B9BDA306456E8640C355718DE3477537B0FAF8C37F633C709129AAB64D9873 ] hidserv C:\Windows\system32\hidserv.dll 23:28:44.0508 0x0e30 hidserv - ok 23:28:44.0555 0x0e30 [ 8DB8EAB9D0C6A5DF0BDCADEA239220B4, EDA23E6909EB83E5E148816DFB16CC29EA01BD6BD2F73AA46B3D820B85FB9C83 ] HidUsb C:\Windows\System32\drivers\hidusb.sys 23:28:44.0664 0x0e30 HidUsb - ok 23:28:44.0680 0x0e30 [ 7BF3ADCBD021D4F4A84CF40EB49C71B5, 5758A51FD2EBE67E6DBE3A298D714D351910F9E01C428D0C1359457C9242B298 ] hkmsvc C:\Windows\system32\kmsvc.dll 23:28:44.0711 0x0e30 hkmsvc - ok 23:28:44.0758 0x0e30 [ 6CD9C3819BE8C0A3DACC82AE5D3C4F18, 46BF4A968E506DE17CA401401D716B444CDC10A5C60EB081890DD4B886AEDF5F ] HomeGroupListener C:\Windows\system32\ListSvc.dll 23:28:44.0852 0x0e30 HomeGroupListener - ok 23:28:44.0930 0x0e30 [ 1A4DA1D6287B99033D144B436C23B656, D4D1EEB372E61512EA36A33F095E68C225B8E6C72CC57ED8BD00533F88012F40 ] HomeGroupProvider C:\Windows\system32\provsvc.dll 23:28:44.0993 0x0e30 HomeGroupProvider - ok 23:28:45.0071 0x0e30 [ D2946D9F020AE76E9CEF9B4A6DF838C0, C29CE594879385DA12B8EAA90B258905827B613839CCD820DE49215B68676995 ] hpqwmiex C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe 23:28:45.0164 0x0e30 hpqwmiex - ok 23:28:45.0211 0x0e30 [ A6AACEA4C785789BDA5912AD1FEDA80D, D197012A5DA6AB3F76FF298336DF0CF027C07ECC71267BAEF5912DE12893E096 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys 23:28:45.0227 0x0e30 HpSAMD - ok 23:28:45.0258 0x0e30 [ 82C47A85494249623F40E43C7B04051C, 97EF087B49219B68686914B250634FF67D13B7D3F81562614F108D2A40BEBA54 ] HPSupportSolutionsFrameworkService C:\Program Files (x86)\Hp\Common\HPSupportSolutionsFrameworkService.exe 23:28:45.0305 0x0e30 HPSupportSolutionsFrameworkService - ok 23:28:45.0352 0x0e30 [ 9DDCA7F18983C5410DEFF79F819DF93C, CE97B4440377BFC5CA81BB600C3BD1DD9FB3951CA1EB70735F5E2050EBB74223 ] HTTP C:\Windows\system32\drivers\HTTP.sys 23:28:45.0399 0x0e30 HTTP - ok 23:28:45.0430 0x0e30 [ 90656C0B3864804B090434EFC582404F, BDB60050B729AACB9E009AC7129BEBD6298BBD8A9DB14B817D02E8E13669BD6E ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys 23:28:45.0461 0x0e30 hwpolicy - ok 23:28:45.0493 0x0e30 [ 6D6F9E3BF0484967E52F7E846BFF1CA1, C982966BDE6A3E6773D9441ADA7A3B08D13511DFC68D04DF303248B942423F38 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys 23:28:45.0571 0x0e30 hyperkbd - ok 23:28:45.0586 0x0e30 [ 907C870F8C31F8DDD6F090857B46AB25, 308664A31717383D06185875E76C6612407A9F04E7DB28404F574A5706C6715D ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys 23:28:45.0711 0x0e30 HyperVideo - ok 23:28:45.0774 0x0e30 [ 84CFC5EFA97D0C965EDE1D56F116A541, 0155EA62BF07D99D98D1C9B6559C8E3301B016A20D03DF1EF64B2FAB8C37403B ] i8042prt C:\Windows\System32\drivers\i8042prt.sys 23:28:45.0899 0x0e30 i8042prt - ok 23:28:45.0930 0x0e30 [ 5D90E32E36CE5D4C535D17CE08AEAF05, 976A463343E8C8308AFBE9E64DF56C430D2241DE002430D00318AB065EB72E4A ] iaLPSSi_GPIO C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 23:28:45.0930 0x0e30 iaLPSSi_GPIO - ok 23:28:45.0946 0x0e30 [ DD05E7E80F52ADE9AEB292819920F32C, E71AB6A50B0F90C8F94569CE89F66F915A0A4A00D4AC091B2E5E750D88CFC334 ] iaLPSSi_I2C C:\Windows\System32\drivers\iaLPSSi_I2C.sys 23:28:45.0977 0x0e30 iaLPSSi_I2C - ok 23:28:46.0039 0x0e30 [ 08BFE413B0B4AA8DFA4B5684CE06D3DC, 95DEEBB203E12EE6E191F5247A74C04AEC0E16DE981FADDC4D6C42EE41D8D079 ] iaStorAV C:\Windows\system32\drivers\iaStorAV.sys 23:28:46.0071 0x0e30 iaStorAV - ok 23:28:46.0133 0x0e30 [ A2200C3033FA4EF249FC096A7A7D02A2, 5819F5C2020DE2EEE339B0C08CD4B1E3490EAFBBEA1277CE649DB5A5150986B0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys 23:28:46.0196 0x0e30 iaStorV - ok 23:28:46.0196 0x0e30 IEEtwCollectorService - ok 23:28:46.0414 0x0e30 [ 8C44E6B688790E2AD3846C97661C54F1, CB487D167EDA3C1E30BD5FB8F98C15EB9E75A6FB793009C2F1BBCAAB4285F772 ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 23:28:46.0649 0x0e30 igfx - ok 23:28:46.0774 0x0e30 [ DEA76F90F9777E3427D70E380222B23B, B917BA423896A12E45623E3D494CA03317A6FC612CA433C62C897524DC3E756B ] IKEEXT C:\Windows\System32\ikeext.dll 23:28:46.0930 0x0e30 IKEEXT - ok 23:28:46.0993 0x0e30 [ C99F8E90DE4B8F0C7FE15BB1CBCD29DC, F791EE101EEF8B9F48102B6C63A89B78F7C0041C750C4F4C0D16D54B583B7B5C ] Intel(R) Capability Licensing Service Interface C:\Program Files\Intel\iCLS Client\HeciServer.exe 23:28:47.0055 0x0e30 Intel(R) Capability Licensing Service Interface - ok 23:28:47.0133 0x0e30 [ 30E9FAC23E2537D82F2836CB81AEE186, 03E5072D43ECED70EF004D2E6E654B4CCCE059825CC3C641C0534E4C0BC0C7E8 ] Intel(R) ME Service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 23:28:47.0196 0x0e30 Intel(R) ME Service - ok 23:28:47.0243 0x0e30 [ 4E448FCFFD00E8D657CD9E48D3E47157, 4A958CF0BF8DAEAE5E008500BA67CE89B21388592811274331EE39CAC1043A00 ] intelide C:\Windows\system32\drivers\intelide.sys 23:28:47.0274 0x0e30 intelide - ok 23:28:47.0305 0x0e30 [ 139CFCDCD36B1B1782FD8C0014AC9B0E, E0D7E0E9B46A8CECE138D689820023BFA650FB689E4FD62855BED37E04F2D9FF ] intelpep C:\Windows\system32\drivers\intelpep.sys 23:28:47.0321 0x0e30 intelpep - ok 23:28:47.0352 0x0e30 [ 47E74A8E53C7C24DCE38311E1451C1D9, 79B06E37A552C8A847404D4C572CDB8CF525354D8AE3BEBC06892B7C3B330761 ] intelppm C:\Windows\System32\drivers\intelppm.sys 23:28:47.0430 0x0e30 intelppm - ok 23:28:47.0461 0x0e30 [ 9DB76D7F9E4E53EFE5DD8C53DE837514, 07BA4EDA9BE9139A689A2C3EFC1D1A4F3D1216625ED145F313398292A2CD5703 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 23:28:47.0524 0x0e30 IpFilterDriver - ok 23:28:47.0602 0x0e30 [ 1670A274ED1A815311BA33CD27B0D0E8, 28378D3908DCFA2C0E8FCF83E5AFEF643C89BBB285FA0F1692FE576AEA2F4E45 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 23:28:47.0680 0x0e30 Suspicious file ( Forged ): C:\Windows\System32\iphlpsvc.dll. Real md5: 1670A274ED1A815311BA33CD27B0D0E8, sha256: 28378D3908DCFA2C0E8FCF83E5AFEF643C89BBB285FA0F1692FE576AEA2F4E45, fake md5: ACFEE9487693C2BD573DFCA71D98E17C, fake sha256: A347FD476147CD3568EEE6993B46AFC05A66A4269094CA51572D0FD013FCB535 23:28:47.0680 0x0e30 iphlpsvc - detected ForgedFile.Multi.Generic ( 1 ) 23:28:47.0680 0x0e30 Object is SCO, delete is not allowed 23:28:47.0680 0x0e30 iphlpsvc ( ForgedFile.Multi.Generic ) - warning 23:28:47.0711 0x0e30 [ 9C096BF5E10CA8BFA56F32522A89FAF1, 6C1151160799338DA351C7237AB049926C6C15F24F5E154BBF5929B4A96C0B8D ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys 23:28:47.0789 0x0e30 IPMIDRV - ok 23:28:47.0821 0x0e30 [ B7342B3C58E91107F6E946A93D9D4EFD, D5DA3C02C5C5A343785745EF6983CC9B5FBD3FB8D49FE9B450523E50212D1A32 ] IPNAT C:\Windows\system32\drivers\ipnat.sys 23:28:47.0914 0x0e30 IPNAT - ok 23:28:47.0930 0x0e30 [ AE44C526AB5F8A487D941CEB57B10C97, A783A2EAF7A6FF450FB3F189A5930036FA60D125C42171AC44B6FE2E3DBD6F7A ] IRENUM C:\Windows\system32\drivers\irenum.sys 23:28:47.0993 0x0e30 IRENUM - ok 23:28:48.0024 0x0e30 [ 8AFEEA3955AA43616A60F133B1D25F21, E99359A4F1D653790133F145CF7C9F97399FD75C5E135AA7E5F989BB660789AF ] isapnp C:\Windows\system32\drivers\isapnp.sys 23:28:48.0024 0x0e30 isapnp - ok 23:28:48.0102 0x0e30 [ D90AB68D0FAC9F357F663670FDBB511E, A82AAA5DF1B38EFBDCF834535A0C520D1BB2D7A4A906C18CFDD22BCF16BDB97D ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys 23:28:48.0149 0x0e30 iScsiPrt - ok 23:28:48.0196 0x0e30 [ 3C4002D339491AF73D663FFC7F6E5ECB, 0B53047989BDB781572253BC3AA757912FE54366870C1955E687972CE210C285 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe 23:28:48.0227 0x0e30 jhi_service - ok 23:28:48.0243 0x0e30 [ 8BE92376799B6B44D543E8D07CDCF885, 425B8BB1BAF62F735B3CB5A002E6055879F02E7207E55942BFD37F1784F5F368 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys 23:28:48.0258 0x0e30 kbdclass - ok 23:28:48.0290 0x0e30 [ FB6E47E569D4872ABEB506BE03A45FBA, 5C4056CADA8F67587A119D9AE2A0EFAB30387CF6298F4019FF68AC92E2F6F54B ] kbdhid C:\Windows\System32\drivers\kbdhid.sys 23:28:48.0336 0x0e30 kbdhid - ok 23:28:48.0352 0x0e30 [ 813871C7D402A05F2E3A7075F9584A05, FF0C2F87EB083F8CE74C679D80C845CDFBFBBC70BE818F899F3336BBB54A3FFB ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys 23:28:48.0461 0x0e30 kdnic - ok 23:28:48.0493 0x0e30 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] KeyIso C:\Windows\system32\lsass.exe 23:28:48.0508 0x0e30 KeyIso - ok 23:28:48.0524 0x0e30 [ ADDECBCC777665BD113BED437E602AB0, B6283475A1219CE44E9F683DD3BEB8C42DA0943297E5C4699B22176AD8A6A7ED ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 23:28:48.0555 0x0e30 KSecDD - ok 23:28:48.0602 0x0e30 [ F88CC88F4A6D8476F1664E805CA18CC2, 2C61EE5EEA4FD45AA3FA927CC16E34EF90BD44324EAB14198AF65C3A27617991 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys 23:28:48.0602 0x0e30 Suspicious file ( Forged ): C:\Windows\system32\Drivers\ksecpkg.sys. Real md5: F88CC88F4A6D8476F1664E805CA18CC2, sha256: 2C61EE5EEA4FD45AA3FA927CC16E34EF90BD44324EAB14198AF65C3A27617991, fake md5: 24F7908334185E342729B883DA5DFA84, fake sha256: D80AED7B43971BF9B53C4128D602DA1B39BC55666D4FCB2FDF40732358A837C2 23:28:48.0602 0x0e30 KSecPkg - detected ForgedFile.Multi.Generic ( 1 ) 23:28:48.0602 0x0e30 KSecPkg ( ForgedFile.Multi.Generic ) - warning 23:28:48.0618 0x0e30 [ 11AFB527AA370B1DAFD5C36F35F6D45F, 757AD234284467ADB826F7CA0251F58D48866B91995BC867DEA4BAF676947163 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 23:28:48.0696 0x0e30 ksthunk - ok 23:28:48.0758 0x0e30 [ 32B1A8351160F307A8C66BCB0F94A9C2, 52F1DEC2BBD4D5DDBB85ED20B99D96BBA7EB83304D76F183A11FDAFDA364E873 ] KtmRm C:\Windows\system32\msdtckrm.dll 23:28:48.0868 0x0e30 KtmRm - ok 23:28:48.0930 0x0e30 [ 793EACA6BAE9F481C2059BCB3743EB4A, 2624905C6B6A1227BD1CAC7D4FE55A5F6543E1278DAB31EC553748472D180D1D ] LanmanServer C:\Windows\system32\srvsvc.dll 23:28:49.0040 0x0e30 LanmanServer - ok 23:28:49.0102 0x0e30 [ D0D9C2ECA4D03A8F06DCD91236B90C98, E2D1144DC8040EA5FEB0602A20BA4CB920B4BC86AD5AD05FC0DF7D74DC95DC66 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 23:28:49.0165 0x0e30 LanmanWorkstation - ok 23:28:49.0211 0x0e30 [ 626D19F1771E1AE72208AE9A8F3082F7, 78FDB64545ED2EAE9F51C08120E21D2C3285208F6846BD8BBA08CAA839E7A0C4 ] lfsvc C:\Windows\System32\GeofenceMonitorService.dll 23:28:49.0290 0x0e30 lfsvc - ok 23:28:49.0321 0x0e30 [ C09010B3680860131631F53E8FE7BAD8, 35F2A06D5F29478D22ABDCC20DA893EF9D96504C65594A0CEA674D1C21B04FF8 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 23:28:49.0383 0x0e30 lltdio - ok 23:28:49.0446 0x0e30 [ 00E070FC0C673311AFD4B068D1242780, 50B0E0E625361145332C849709498FF444E46578DCAD2536E6D0289E0125580F ] lltdsvc C:\Windows\System32\lltdsvc.dll 23:28:49.0586 0x0e30 lltdsvc - ok 23:28:49.0602 0x0e30 [ D113FAD71A5E67AA94B32A0F8828D265, 08DDB4BBDB570C59926DBF5E27FCF46DCDF8B8212BB9251E97837E0504516FB3 ] lmhosts C:\Windows\System32\lmhsvc.dll 23:28:49.0680 0x0e30 lmhosts - ok 23:28:49.0743 0x0e30 [ 4269D44BB47A6DA5D80B11F4C8536458, 7A8FFC8F851DD9E5C43986BE0888831CB71D188138DF3CF7F787DADDA70915B0 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 23:28:49.0774 0x0e30 LMS - ok 23:28:49.0821 0x0e30 [ C755AE4635457AA2A11F79C0DF857ABC, E03D1ACAC155287291FE1BD0B653953ADC94279A74D0152088D698FAA796460F ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 23:28:49.0836 0x0e30 LSI_SAS - ok 23:28:49.0852 0x0e30 [ ADAC09CBE7A2040B7F68B5E5C9A75141, 7865DA7E91404F3642BC444B97F6B7AA42B9523D5EDD7F6365DA236B8EC3410F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys 23:28:49.0883 0x0e30 LSI_SAS2 - ok 23:28:49.0899 0x0e30 [ 04D1274BB9BBCCF12BD12374002AA191, 4B9618F8D25F2278DE1610A70ACAADB074D171D162C3AF27D464F5DC800A8E60 ] LSI_SAS3 C:\Windows\system32\drivers\lsi_sas3.sys 23:28:49.0915 0x0e30 LSI_SAS3 - ok 23:28:49.0930 0x0e30 [ 327469EEF3833D0C584B7E88A76AEC0C, 3D88B5A2D68F93F01B39C6E3D8D5C7A2A20686EFC756086E66AFFF1BC3019B85 ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys 23:28:49.0961 0x0e30 LSI_SSS - ok 23:28:50.0008 0x0e30 [ 8EBB271E4588D835784A3FF7E80076A8, A508BE95F6F5063A76F4C8726D9425BB1F00DE803EFE73A0BE145DD9AB82FF0A ] LSM C:\Windows\System32\lsm.dll 23:28:50.0055 0x0e30 LSM - ok 23:28:50.0086 0x0e30 [ DDEE191AB32DFC22C6465002ECDF5EE4, 190C3930A8449118F9FEDF43C482837EF1C255E6D67F9651156E66A1E2BC6553 ] luafv C:\Windows\system32\drivers\luafv.sys 23:28:50.0180 0x0e30 luafv - ok 23:28:50.0211 0x0e30 [ EB5C03A070F30D64A6DF80E53B22F53F, 12051B6AEBDEE1E28F24364F25A52BA3A6E282ECF86D6290E34BD38E6D4E066D ] megasas C:\Windows\system32\drivers\megasas.sys 23:28:50.0227 0x0e30 megasas - ok 23:28:50.0274 0x0e30 [ F6F13533196DE7A582D422B0241E4363, B3CD9B08937AFFF12141B38634AF3A56F5AC5FF3EF03941802B9841DEC559469 ] megasr C:\Windows\system32\drivers\megasr.sys 23:28:50.0321 0x0e30 megasr - ok 23:28:50.0352 0x0e30 [ 772A1DEEDFDBC244183B5C805D1B7D85, 7D821B8DF1F174E5414FFDEAB5207DB687740E9842F7203600AEBA086945AFC9 ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys 23:28:50.0399 0x0e30 MEIx64 - ok 23:28:50.0430 0x0e30 [ FD788C2D96EA91469A3C1D13E80D7473, 7B14D4BFDE18CECC19FBFFAA5AFF5FD78BFB7FCDA6613990740A8A7DD9873D26 ] MMCSS C:\Windows\system32\mmcss.dll 23:28:50.0524 0x0e30 MMCSS - ok 23:28:50.0555 0x0e30 [ 8B38C44F69259987C95135C9627E2378, E698B82D4EFFF56D66C7FC9866369BA5736FDBDBE2028CC421C51E70DEA74727 ] Modem C:\Windows\system32\drivers\modem.sys 23:28:50.0586 0x0e30 Modem - ok 23:28:50.0586 0x0e30 [ 601589000CC90F0DF8DA2CC254A3CCC9, D1238A386C41B6C368D9A44B7C112C943995B5403E2A5B4B7346B266DDB0C5A0 ] monitor C:\Windows\System32\drivers\monitor.sys 23:28:50.0680 0x0e30 monitor - ok 23:28:50.0712 0x0e30 [ CEAC6D40FE887CE8406C2393CF97DE06, 34E76908B802764FF0D7AB3AF89BE77BD35B44787983343FAD89891891C0A045 ] mouclass C:\Windows\System32\drivers\mouclass.sys 23:28:50.0727 0x0e30 mouclass - ok 23:28:50.0743 0x0e30 [ 02D98BF804084E9A0D69D1C69B02CCA9, EC5BC5D87043DFFD035FD4DD27B3D94E03119063519E4151BCC3522B613E2D7F ] mouhid C:\Windows\System32\drivers\mouhid.sys 23:28:50.0821 0x0e30 mouhid - ok 23:28:50.0837 0x0e30 [ 515549560D481138E6E21AF7C6998E56, C7E4B38D8CCAF15B9BDA63C8C8209F6193AD220DA02E1264F1B687AACD8F409F ] mountmgr C:\Windows\system32\drivers\mountmgr.sys 23:28:50.0915 0x0e30 mountmgr - ok 23:28:50.0930 0x0e30 [ F170510BE94CF45E3C6274578F6204B2, 344C3DDE1D622607CA2ABECB2C47CB0166D2D258BD94A7960C45A5ADBB640566 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 23:28:50.0993 0x0e30 mpsdrv - ok 23:28:51.0118 0x0e30 [ D186C5844393252147BE934F3871DB7A, 30160F8268B9F46E82C5CB536867E0CF280DC98074A481595072E3320200E343 ] MpsSvc C:\Windows\system32\mpssvc.dll 23:28:51.0321 0x0e30 MpsSvc - ok 23:28:51.0430 0x0e30 [ 1D55DADC22D21883A2F80297F5A5AE48, B79DF4AFC2A9CBC54E74233596544D6E41C8CAA0516BD57CA695D051EC780265 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 23:28:51.0477 0x0e30 MRxDAV - ok 23:28:51.0493 0x0e30 [ 7A1A3F213CDB3363D179D5014272025D, 6756F5B7D9FBF6839DB1FF4E94EA45B5499D7DF925E75581C96FBBA4BE131542 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 23:28:51.0602 0x0e30 mrxsmb - ok 23:28:51.0665 0x0e30 [ 3E28B99198B514DFEB152EACF913025E, 6C1D8353DCD5F811F39C0C3CB5DF3D2457F0D17EE80FB06196AA169E3D19E9B2 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 23:28:51.0727 0x0e30 mrxsmb10 - ok 23:28:51.0758 0x0e30 [ C910E5D18958914A66F0E45689D0B40A, AD7C91DD8A60A511E580DD56BACC97F85075A539E7C5D95040A8F870A621DAF4 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 23:28:51.0805 0x0e30 mrxsmb20 - ok 23:28:51.0837 0x0e30 [ E0927EFA25D473367C3341B9F5969779, B77A162BD3334557623674373D8EC2BE7CC0B359DF06304E467ABFFEE0530271 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys 23:28:51.0930 0x0e30 MsBridge - ok 23:28:51.0977 0x0e30 [ A082C17D14D0790E27D064EA4B138AE1, 9A565ED885782D9D5135C8399C11C356DBF9EBF3B8EB4B4504BD2604AD0B45E6 ] MSDTC C:\Windows\System32\msdtc.exe 23:28:52.0071 0x0e30 MSDTC - ok 23:28:52.0133 0x0e30 [ D13329FBF8345B28AB30F44CC247DC08, 9C7EC2D4D65E6510EB5B9E61BB0D14F725D7E8FE98D65161C3971E43EF1AB6EB ] Msfs C:\Windows\system32\drivers\Msfs.sys 23:28:52.0212 0x0e30 Msfs - ok 23:28:52.0227 0x0e30 [ C6B474E46F9E543B875981ED3FFE6ADD, E16687E52FB649C23D92159A1F036CB662202C1E58D961EECDAA528AA4FA669A ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys 23:28:52.0274 0x0e30 msgpiowin32 - ok 23:28:52.0290 0x0e30 [ 65C92EB9D08DB5C69F28C7FFD4E84E31, D709BA4723225321F665B1157A33A4AE230420752308EF535DA9A41CAC164628 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys 23:28:52.0352 0x0e30 mshidkmdf - ok 23:28:52.0383 0x0e30 [ 52299F086AC2DAFD100DD5DC4A8614BA, B36BE0FC96798E5EB8C193C318970E3906961E3ABC3BFAAD73138C76D9A95B0B ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys 23:28:52.0399 0x0e30 mshidumdf - ok 23:28:52.0415 0x0e30 [ 36D92AF3343C3A3E57FEF11C449AEA4C, ECC85AA1E530DF55B4A4545798219F87F0FCA66DDD2E37BCEF0850D3C9129DD2 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 23:28:52.0446 0x0e30 msisadrv - ok 23:28:52.0477 0x0e30 [ 810F8A0A0680662BB0CE44D0E2CEF90C, 5631B07911B7EF378CB1583A480A3C5715E59A5488B33A528F4D7A2F849B9113 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 23:28:52.0540 0x0e30 MSiSCSI - ok 23:28:52.0540 0x0e30 msiserver - ok 23:28:52.0571 0x0e30 [ A9BBBD2BAE6142253B9195E949AC2E8D, 599D2952D4E0B0B3E02D91E38A30F4900B1ADA330716B887B156A1CB9A3E6EE9 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 23:28:52.0649 0x0e30 MSKSSRV - ok 23:28:52.0665 0x0e30 [ 375E44168F2DFB91A68B8A3F619C5A7C, AC243E02E9A39D0B4DE9571F196941700EE6EB5E94F5B0BA8994FB551E73A7A8 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys 23:28:52.0743 0x0e30 MsLldp - ok 23:28:52.0774 0x0e30 [ 7B2128EB875DCBC006E6A913211006D6, 97BBD7FF770741FBFC0F181A609AD0954EA926DA203B742E8F08C89AD8FE476E ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 23:28:52.0821 0x0e30 MSPCLOCK - ok 23:28:52.0852 0x0e30 [ 1E88171579B218115C7A772F8DE04BD8, B9EAA835D0BF8F9C4DF8403D95EF1400E8AE38F28F9DBA87657DE2129FEF02D2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 23:28:52.0899 0x0e30 MSPQM - ok 23:28:52.0946 0x0e30 [ BBE2A455053E63BECBF42C2F9B21FAE0, 7C5DF563499DF59DF9895A1581E47ADF5FD54C94ECEF6C886CDB60E5E95A6DAE ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 23:28:52.0977 0x0e30 MsRPC - ok 23:28:52.0993 0x0e30 [ 8D6B7D515C5CBCDB75B928A0B73C3C5E, 1EB4DC3DD21D2627C78EC3F9931D9E5D033169087E43B5D7C17BF1FF2A0028CD ] mssmbios C:\Windows\System32\drivers\mssmbios.sys 23:28:53.0008 0x0e30 mssmbios - ok 23:28:53.0024 0x0e30 [ 115019AE01E0EB9C048530D2928AB4A2, 6E2275E85EACF2D0FC784792E0D72A165589D33CBAB3BCFA8E271CA09566C925 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 23:28:53.0071 0x0e30 MSTEE - ok 23:28:53.0087 0x0e30 [ 96D604A35070360F0DD4A7A8AF410B5E, F94DD1A3566C7C8D0A76D6E1E2530552A9B7F99C5DA0DE11829325EAB9F8B7ED ] MTConfig C:\Windows\System32\drivers\MTConfig.sys 23:28:53.0134 0x0e30 MTConfig - ok 23:28:53.0149 0x0e30 [ 619CA29326B82372621DB2C0964D8365, 4091F08E266DB45A6E33A4A8B1CE9FA78BB294B3111526AA9E3868620F30AFDF ] Mup C:\Windows\system32\Drivers\mup.sys 23:28:53.0165 0x0e30 Mup - ok 23:28:53.0180 0x0e30 [ B8C35C94DCB2DFEAF03BB42131F2F77F, F0FCF367CA8F722D6ABCF7F363CD406D890D71452E91C3FC6677B47AD74D6324 ] mvumis C:\Windows\system32\drivers\mvumis.sys 23:28:53.0196 0x0e30 mvumis - ok 23:28:53.0243 0x0e30 [ 41A45D2A75494EABF2806EA051E00376, EB2497561C8E33A4297C044604C717FF854C7F046882A9E4A400AE7679BF5467 ] napagent C:\Windows\system32\qagentRT.dll 23:28:53.0384 0x0e30 napagent - ok 23:28:53.0446 0x0e30 [ 26ACA481FAFEC59FE311D719E3027BBA, 16A24CCA95A38BDFE970580159F6ACAA13FF1B74CF2290B1B020D909F90D3347 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 23:28:53.0493 0x0e30 NativeWifiP - ok 23:28:53.0524 0x0e30 [ 71E3C0100AA19D11373CCEB2F51A6008, 58FBF35F5FE19BEABE483C11E9996BE93D76721C8C34465350FA98B465CA3672 ] NcaSvc C:\Windows\System32\ncasvc.dll 23:28:53.0602 0x0e30 NcaSvc - ok 23:28:53.0634 0x0e30 [ 51DF09CAB2CAC64FEE3E371D9028ED01, 9B81604D0D0359AF8F54FED6DA7116FFD2F40407895028EAD99FF1D7CFDC2D14 ] NcbService C:\Windows\System32\ncbservice.dll 23:28:53.0712 0x0e30 NcbService - ok 23:28:53.0743 0x0e30 [ 2586C4C167499210DCBF3ECFD8CCE210, D8129FEDE9918BF4FB0057CC58700D4E08457060E810B9CC25CA0F598506ADB8 ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll 23:28:53.0884 0x0e30 NcdAutoSetup - ok 23:28:53.0946 0x0e30 [ E4B4BE2D7750849C07589DA0B0AABA01, BB5AA727BA018A94B5DE2C4E0B594DD2E7A2B3457885446EE568F3A1E18AB3B0 ] NDIS C:\Windows\system32\drivers\ndis.sys 23:28:54.0024 0x0e30 NDIS - ok 23:28:54.0071 0x0e30 [ C6BB12BC35D1637CA17AE16D3A4725EB, 01C1D9FA738886A195166F88207EEB6715A1DE0608978ED6C5DC738AF5C02513 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys 23:28:54.0149 0x0e30 NdisCap - ok 23:28:54.0196 0x0e30 [ B1AA3B19A2E596A59224F893E01A5A75, E08696CA5E087E51AC3E64D4FB8490EEADD612DDF30C9A94DD1BD1BA124B71B7 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys 23:28:54.0290 0x0e30 NdisImPlatform - ok 23:28:54.0321 0x0e30 [ 9423421E735BD5394351E0C47C76BB92, 763E5D06F896C0EF8AD52515464F28BA85DB7A1560E451857AC9AA68FAFCBC66 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 23:28:54.0384 0x0e30 NdisTapi - ok 23:28:54.0415 0x0e30 [ B832B35055BA2B7B4181861FF94D8E59, 2E60E5D503E88D27E35ECFEE265D51328E93A9C7B9B931F86D9CBC947636BB00 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 23:28:54.0462 0x0e30 Ndisuio - ok 23:28:54.0493 0x0e30 [ 1F58E48EF75F34C35D8E93A0DC535CFE, D65619A6C4B1747F8B05DA08A44EF0E46B5CC384880E04E4755A2BA6CDB3C4EA ] NdisVirtualBus C:\Windows\System32\drivers\NdisVirtualBus.sys 23:28:54.0540 0x0e30 NdisVirtualBus - ok 23:28:54.0555 0x0e30 [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 23:28:54.0665 0x0e30 NdisWan - ok 23:28:54.0680 0x0e30 [ DEC29080202D4F9F17F55E18BCFCC41A, F7E543741B1F4F637A99C40543D6AEC6EBF893F74359BBA769D1F882E0AFB571 ] NdisWanLegacy C:\Windows\system32\DRIVERS\ndiswan.sys 23:28:54.0696 0x0e30 NdisWanLegacy - ok 23:28:54.0727 0x0e30 [ A5BD69A8812FA79D1A487691DD3FB244, 67B5EDE101943E0E8B8041DB2353D20C8B9F2D253E77964761CFE8F136C0BBC7 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 23:28:54.0899 0x0e30 NDProxy - ok 23:28:54.0930 0x0e30 [ 5A072F0B90C29C5233D78BE33EF5ED78, B32ED76A674B1FC743361FB7BBD4C915A78B14132AB056AADD445D5995AD4F32 ] Ndu C:\Windows\system32\drivers\Ndu.sys 23:28:55.0009 0x0e30 Ndu - ok 23:28:55.0024 0x0e30 [ A83D67D347A684F10B7D3019C8A6380C, 2B86832967981C8C786BF24C1CF8E13E01745ACE3333CF5C821DD93D623B96E4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 23:28:55.0102 0x0e30 NetBIOS - ok 23:28:55.0149 0x0e30 [ 0217532E19A748F0E5D569307363D5FD, C40C2E7AFA276057E7327A7BB173122689D6CEC9AE443C3850C3F94AF03DFBF5 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys 23:28:55.0259 0x0e30 NetBT - ok 23:28:55.0274 0x0e30 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] Netlogon C:\Windows\system32\lsass.exe 23:28:55.0290 0x0e30 Netlogon - ok 23:28:55.0321 0x0e30 [ B7AD851A21FEBA3BA214972627614207, 29605320CCC3DAAD062CAECF0009DACBC2F6D28ED4E8AF7CE76132129F5572A0 ] Netman C:\Windows\System32\netman.dll 23:28:55.0352 0x0e30 Netman - ok 23:28:55.0399 0x0e30 [ F0F0A372C2EF6358399C4936F91B6131, CE596C71EB4D1A5E104D3148F2D0D8789882C59FD198DCF33CCAC7A08B50E4EE ] netprofm C:\Windows\System32\netprofmsvc.dll 23:28:55.0477 0x0e30 netprofm - ok 23:28:55.0587 0x0e30 [ 76E90502D9001077DA92F81126D06C9B, 9E5B6DD3F1DAF49D303A7B3F6763A25C5F55F1E67A33AA8572204E9105B092EF ] netr28x C:\Windows\system32\DRIVERS\netr28x.sys 23:28:55.0665 0x0e30 netr28x - ok 23:28:56.0102 0x0e30 [ 1092B3190E69E0C5ECBCE90F171DE047, C16106EEFC324EE80E5F659CB71A5DD69FA800D36D829F5B0E6AD3393BD1BAF7 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 23:28:56.0212 0x0e30 NetTcpPortSharing - ok 23:28:56.0243 0x0e30 [ 70414DB660BFBB7BD58FCE8EA4364E1B, 6DFB3897CD55E22BA1EDF0AE672F4D7A6A1F512F8A0A26AF106765E6B1CF65AC ] netvsc C:\Windows\system32\DRIVERS\netvsc63.sys 23:28:56.0352 0x0e30 netvsc - ok 23:28:56.0556 0x0e30 [ 3A280F3B3C7A46E29C404ACD46ECBF5E, 81C3367A2A212DBCC65B8A0166FD092E3205AB31A146B4B737061335CEC51F9D ] NlaSvc C:\Windows\System32\nlasvc.dll 23:28:56.0727 0x0e30 NlaSvc - ok 23:28:56.0806 0x0e30 [ 8F44A2F57C9F1A19AC9C6288C10FB351, 310274DDBAC0FE4BE54ECD3B90C97D82A0F9F5CFCA7A35711A36164DE4B94074 ] Npfs C:\Windows\system32\drivers\Npfs.sys 23:28:56.0915 0x0e30 Npfs - ok 23:28:56.0931 0x0e30 [ CBDB4F0871C88DF930FC0E8588CA67FC, 7E4AA3EA81A9D532F236FD7896744F07ED07CA9B37A9F18A9778BCCCC67490F2 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys 23:28:56.0993 0x0e30 npsvctrig - ok 23:28:57.0040 0x0e30 [ 6E2271ED0C3E95B8E29F3752B91B9E84, 44026AD9757EA82967D7F7578455802FAD7FE0057EAC088E0AE207C15F594B86 ] nsi C:\Windows\system32\nsisvc.dll 23:28:57.0071 0x0e30 nsi - ok 23:28:57.0102 0x0e30 [ E490B459978CB87779E84C761D22B827, 1E5CA38626E41618E4CA16DD0C70EB2FA86E986F0CF21A749BDE2A17015DEEC6 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 23:28:57.0149 0x0e30 nsiproxy - ok 23:28:57.0243 0x0e30 [ 038C77D577900EE39410662478BB0D50, A33AAFD5750245C17A47EC71F3C6EAD2E0925CAD34C65AB3E6CEE44756C668E6 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 23:28:57.0321 0x0e30 Ntfs - ok 23:28:57.0352 0x0e30 [ EF1B290FC9F0E47CC0B537292BEE5904, DBC07BBC54EBC2D2E576B23A4CE116B3DA988577AD0D96CB7289A6748A60F9EA ] Null C:\Windows\system32\drivers\Null.sys 23:28:57.0415 0x0e30 Null - ok 23:28:57.0462 0x0e30 [ BC6B5942AFF25EBAF62DE43C3807EDF8, CB0FA194084B8C309039D571B5760FDA800E9531B8660C499B4F9977BA5C36D5 ] nvraid C:\Windows\system32\drivers\nvraid.sys 23:28:57.0493 0x0e30 nvraid - ok 23:28:57.0509 0x0e30 [ 1F43ABFFAC3D6CA356851D517392966E, 6FD7621F67BA94B0E1D8F43BEC2951DBCDEEA1E848BB265AC169E27C01DA68F2 ] nvstor C:\Windows\system32\drivers\nvstor.sys 23:28:57.0540 0x0e30 nvstor - ok 23:28:57.0556 0x0e30 [ 6934A936A7369DFE37B7DBA93F5E5E49, 0900FEEB0CE8D09F0FC60630B5B986034A8BCD3882ED66E47170810C32492892 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 23:28:57.0634 0x0e30 nv_agp - ok 23:28:57.0696 0x0e30 [ E287F157F7A0011D93179C64EF8ADCF2, C16FB92C7B18D634BB1344238D35B3111494C243FBD5853F05376F5051480D83 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll 23:28:57.0821 0x0e30 p2pimsvc - ok 23:28:57.0899 0x0e30 [ 2A57A937BC5B1B2D6AFE6A8C5925F50B, 00D84EFED5A7129AAD86945940030474795905C32D65CBD5B1A3EBADCED8F873 ] p2psvc C:\Windows\system32\p2psvc.dll 23:28:58.0040 0x0e30 p2psvc - ok 23:28:58.0056 0x0e30 [ 764B1121867B2D9B31C491668AC72B2B, 32C04B6FCE1DDD09697B81473A23BDCED8BEEFBCD0D2D58DDC9A11A33C756967 ] Parport C:\Windows\System32\drivers\parport.sys 23:28:58.0118 0x0e30 Parport - ok 23:28:58.0149 0x0e30 [ AD2D6AB5B18D0AD1328079AD5C873C38, 5693F18252186AC5F7644D9C667DEAE7074668F62180CFA83EEBA59BA542409E ] partmgr C:\Windows\system32\drivers\partmgr.sys 23:28:58.0181 0x0e30 partmgr - ok 23:28:58.0243 0x0e30 [ 9A5309EF92F39346CFD5A4C2C3D1BFAD, 5908E0C9562F9CB24784491BD9AE7983A33A6BDF81AFA0A08045518A0C9BB2B1 ] PcaSvc C:\Windows\System32\pcasvc.dll 23:28:58.0306 0x0e30 PcaSvc - ok 23:28:58.0352 0x0e30 [ 91ED124E261EA8FAA1C0FFDF2A71B0C4, 20E41A38067395D03184938983A9BE459717A1941352972DBC28D83D542319EC ] pci C:\Windows\system32\drivers\pci.sys 23:28:58.0399 0x0e30 pci - ok 23:28:58.0431 0x0e30 [ 346E38FCC6859A727DD28AFAD1F0AFF4, FF3DA26F79B3BC3A5B8A8AA0B9139B9EF70297F4EA1203B1E68FB5A212C3AA58 ] pciide C:\Windows\system32\drivers\pciide.sys 23:28:58.0446 0x0e30 pciide - ok 23:28:58.0462 0x0e30 [ 4D3BDCC1C7B40C9D7B6AD990E6DEC397, 27A7AF2127B699F4579CB77936F38DC102211E26E5E2947DB808756FE06FC98E ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 23:28:58.0493 0x0e30 pcmcia - ok 23:28:58.0524 0x0e30 [ BF28771D1436C88BE1D297D3098B0F7D, 5F7630916A76A8CF31289E9C577F522B999C74C39E541CD40E62BD53004BEF74 ] pcw C:\Windows\system32\drivers\pcw.sys 23:28:58.0556 0x0e30 pcw - ok 23:28:58.0571 0x0e30 [ B9D968D8E2B0F9C6301CEB39CFC9B9E4, 83F32831B0727F18B56DC3CAF37E45A3523D2BBCD54D1421F0DE5A0179D8A404 ] pdc C:\Windows\system32\drivers\pdc.sys 23:28:58.0587 0x0e30 pdc - ok 23:28:58.0618 0x0e30 [ 0ECEE590F2E2EF969FB74A6FC583A1E6, 1C611D9225C863CF32125F684B324C58BDE1942F4F283F5674133200AC505D44 ] PEAUTH C:\Windows\system32\drivers\peauth.sys 23:28:58.0712 0x0e30 PEAUTH - ok 23:28:58.0806 0x0e30 [ 8E3C640FFF5A963F570233AE99C0FFF3, 3DE978B005BF2E88BA858CE37D9E27BD3584642B8412E22C300A1E739743838A ] PerfHost C:\Windows\SysWow64\perfhost.exe 23:28:58.0884 0x0e30 PerfHost - ok 23:28:59.0009 0x0e30 [ 928061178CD9856CA6B67FFFCE6BA766, 71DE3C7CA7F83EAAA550CD8A68FB67DE042B0AE51BFACB1ECB8852D502E11F50 ] pla C:\Windows\system32\pla.dll 23:28:59.0118 0x0e30 pla - ok 23:28:59.0149 0x0e30 [ BC6849C62DB407573C6AD8CB1A4D2628, 5BDE0D60F85E4C27CEAD1B301155B54D841FB773BD5BB8AC5DDAEE31F8E94627 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 23:28:59.0181 0x0e30 PlugPlay - ok 23:28:59.0212 0x0e30 [ 045EB4F260606A03BE340D09DEAF3BA4, 6F34B8D414F7F69F4388F2F8A86E0F3AD179E423126990AF3E1EC4DCCB8E7693 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll 23:28:59.0228 0x0e30 PNRPAutoReg - ok 23:28:59.0243 0x0e30 [ E287F157F7A0011D93179C64EF8ADCF2, C16FB92C7B18D634BB1344238D35B3111494C243FBD5853F05376F5051480D83 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll 23:28:59.0274 0x0e30 PNRPsvc - ok 23:28:59.0306 0x0e30 [ C16097D77A232A288D65F299E2E01105, 5CE4B44B06FD26569C0F92FF1D3991D0128D8444AE7BC9EBEF5A33811D721BE8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 23:28:59.0353 0x0e30 PolicyAgent - ok 23:28:59.0384 0x0e30 [ 00E08B30E7F7C13ECE2CDF4F46A77311, 1807C0A64C1794E572C86730816C01DCF4D8F773ADE9CAEA3AC0658F7BD71A4E ] Power C:\Windows\system32\umpo.dll 23:28:59.0462 0x0e30 Power - ok 23:28:59.0493 0x0e30 [ E075CC071022BD4E9BE7C024717C0E0A, BE65A8C1082AE8DF8C37CA06B2BCC521478AC153EA7388B03F7FAE3913920E75 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 23:28:59.0509 0x0e30 PptpMiniport - ok 23:28:59.0665 0x0e30 [ C0B3AD50136FE57C2548BD75CAC49DA2, B5661CE7631C5D1B1C50F36EE66AF6DF2E9E69DA1D9BA7C852E74D206F72D8DB ] PrintNotify C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll 23:28:59.0899 0x0e30 Suspicious file ( Forged ): C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll. Real md5: C0B3AD50136FE57C2548BD75CAC49DA2, sha256: B5661CE7631C5D1B1C50F36EE66AF6DF2E9E69DA1D9BA7C852E74D206F72D8DB, fake md5: 3C96A45CA3403A276B0F045C448EC27B, fake sha256: C0011DB8C5A85817CAF815CC0095EE2C1CDD5964DCD8EAF4C35A2495D6A873CC 23:28:59.0915 0x0e30 PrintNotify - detected ForgedFile.Multi.Generic ( 1 ) 23:28:59.0915 0x0e30 PrintNotify ( ForgedFile.Multi.Generic ) - warning 23:28:59.0962 0x0e30 [ ECD373F9571C745894367CC2635EA44F, E08B2A1017DAE1BF10B986DAFAD14BDE20D79703E0EF3A8C700A3753908C1392 ] Processor C:\Windows\System32\drivers\processr.sys 23:29:00.0103 0x0e30 Processor - ok 23:29:00.0196 0x0e30 [ EF1F8B57323E5D3FC6A0A25F98F90DBC, F50E81151604DCD59BB647FD6767C1631AE48B5FCA6D3423C4E32535C94D6369 ] ProfSvc C:\Windows\system32\profsvc.dll 23:29:00.0353 0x0e30 ProfSvc - ok 23:29:00.0415 0x0e30 [ 8528BB05E4D4E25945F78B00B2555FB7, FF8E0D4580F93CD348080967F52FE6C2C68B56DAEACAE2EAEF04E19412A953AE ] Psched C:\Windows\system32\DRIVERS\pacer.sys 23:29:00.0540 0x0e30 Psched - ok 23:29:00.0571 0x0e30 [ DD3FD48D69F5FBBB21D46D1514C1C2DB, 2B188E3AC4BD9B608D375DD550507717852C2AF7C0F99FFED90098999B9D4F01 ] PSI C:\Windows\system32\DRIVERS\psi_mf_amd64.sys 23:29:00.0603 0x0e30 PSI - ok 23:29:00.0806 0x0e30 [ AF90BB44C99D6820BE52C9BBAA523283, 9772D9CC1666959EC8EE4ED740A5179473CE4F38762109F1123DD68010D20EA1 ] QWAVE C:\Windows\system32\qwave.dll 23:29:00.0978 0x0e30 QWAVE - ok 23:29:01.0009 0x0e30 [ 3FB466684609A4329858CF2EBD62E0FD, CFC8FBAB1436948F9D34CE6A2D6DE2F86F3E93E50B86851CED979C8CCE609798 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 23:29:01.0118 0x0e30 QWAVEdrv - ok 23:29:01.0165 0x0e30 [ 2C56F0EE27E4EF70CA4B4983D3638905, AFFDD686886CE982424B644D9168D61C6F86A5244FF97BC644DF75B321E415E5 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 23:29:01.0259 0x0e30 RasAcd - ok 23:29:01.0368 0x0e30 [ 674A4702E4E144E8710ED1A2EC6DD049, 613A921101A6815C9185D5EF3E251A592604E56FADE945BB7E256885CAD473BC ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys 23:29:01.0493 0x0e30 RasAgileVpn - ok 23:29:01.0540 0x0e30 [ 5F061AC45266841A2860C1858ED863B8, 9E0D52BAC8A50225C32D0397C35350601B996443E2481C808CC59D3B0763FEF0 ] RasAuto C:\Windows\System32\rasauto.dll 23:29:01.0571 0x0e30 RasAuto - ok 23:29:01.0603 0x0e30 [ BBB6272B7F46C4640A8CDB8A70C3450F, 4266C3ABD0D1D0219F715EA0F155744F7C1E3A7B722BE863831B57AE785419A2 ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 23:29:01.0790 0x0e30 Rasl2tp - ok 23:29:02.0056 0x0e30 [ 5C7B86EE33505E36026AFAAB62DA6364, 903BB1A355AC746BF09C2A7C87B068168648DB79DEF39AB1DC710B6A7A5F6556 ] RasMan C:\Windows\System32\rasmans.dll 23:29:02.0275 0x0e30 RasMan - ok 23:29:02.0321 0x0e30 [ 5247F308C4103CDC4FE12AE1D235800A, E567CD33CA1897D53795E071B7AFBAF98B2C8F725F8BED0BA90F5EF611520E48 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 23:29:02.0431 0x0e30 RasPppoe - ok 23:29:02.0478 0x0e30 [ 2B0F1677CDD08967005F34488559BC6F, FFF168EBD171C0B85A448AD1A04F66534E889AE1DC128F68EA3F35D5996C8D39 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 23:29:02.0571 0x0e30 RasSstp - ok 23:29:02.0743 0x0e30 [ A1A5E79C0D1352AFDC08328A623DA051, 01546DDE6F1FF159A7EB7F2BF104910445D3D863F1F37DEA695579BA60D84280 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 23:29:02.0806 0x0e30 rdbss - ok 23:29:02.0837 0x0e30 [ 6B21EBF892CD8CACB71669B35AB5DE32, 0AD8E14FEF16FB2559F5FC8AFBC9D49E4E24F43CF65F480DBF9FAB593269B419 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys 23:29:02.0993 0x0e30 rdpbus - ok 23:29:03.0056 0x0e30 [ 680C1DAE268B6FB67FA21B389A8B79EF, 856911F77BDD8830C3D683EBE8AF399FB3A54C7D8D0B34EA37D903377F0A39BD ] RDPDR C:\Windows\system32\drivers\rdpdr.sys 23:29:03.0196 0x0e30 RDPDR - ok 23:29:03.0228 0x0e30 [ 858776908AF838E3790F3261B799CDA6, 5BE4658540382D1B2F46E503CE175D74E3870FE492B8B8F37C3CFB34FF8E2DA8 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys 23:29:03.0321 0x0e30 RdpVideoMiniport - ok 23:29:03.0384 0x0e30 [ A26AEC49F318FEE141DDDB2C5F99B3E6, 246AD79FF27E79DEDCB0AAA7C22A8EA6349DEDAC863413A1E378E68FD94C9C4F ] rdyboost C:\Windows\system32\drivers\rdyboost.sys 23:29:03.0431 0x0e30 rdyboost - ok 23:29:03.0728 0x0e30 [ E515A287C8FAE901EB8FB42F168E14F2, 9AE8D608587713FD18BB728BADD402C86FFF06A67359B22ED9431705522BC310 ] ReFS C:\Windows\system32\drivers\ReFS.sys 23:29:03.0915 0x0e30 ReFS - ok 23:29:04.0118 0x0e30 [ BFFB40FBE6D2C3469F8D06EE5E4934AB, 5B6763F973A740DCD53CEA75156926457BED8B075965033C484877DDA8B97F39 ] RemoteAccess C:\Windows\System32\mprdim.dll 23:29:04.0181 0x0e30 RemoteAccess - ok 23:29:04.0243 0x0e30 [ 4DCCABE03D06955ED61BABBD8EF9F30F, 531CD60315AAF283B73E0F6CF77D4DE093B809E73C44D2AC43B7247500B3485E ] RemoteRegistry C:\Windows\system32\regsvc.dll 23:29:04.0306 0x0e30 RemoteRegistry - ok 23:29:04.0353 0x0e30 [ D894CBD7DA753C881EE8D5E33B583225, DA4472A85F10A3DF8CE969F731E67FE7C75EE6095908AB8AC2C44851DC5A3F8B ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll 23:29:04.0540 0x0e30 RpcEptMapper - ok 23:29:04.0587 0x0e30 [ 5CAE8F47B31D5CFC322B5B898C19E0FE, FDB5F0B6EA36403E031D9147AB0519011FAAD3AC8190DE5B1F17FB5472D79D47 ] RpcLocator C:\Windows\system32\locator.exe 23:29:04.0650 0x0e30 RpcLocator - ok 23:29:04.0868 0x0e30 [ 81979817943D830BF24571B7C1B28A1A, 9584D8F1FB3E6CF17BD465670B208C723A8E8B06775A3DA44F75D7710404EEA6 ] RpcSs C:\Windows\system32\rpcss.dll 23:29:04.0915 0x0e30 RpcSs - ok 23:29:05.0087 0x0e30 [ 8EAAC43684B9DE3F1532767EEB3DCA97, 70B0383649D489875BB6C2723557A598311995A02F87270740A353705B335ACD ] RSP2STOR C:\Windows\system32\DRIVERS\RtsP2Stor.sys 23:29:05.0228 0x0e30 RSP2STOR - ok 23:29:05.0259 0x0e30 [ 2D05A5508F4685412F2B89E8C2189ABC, 82F12B4E0E73411A121EFD35FBD3B44CBBC0AE96ACFBB45D8C3C3777E2EA320D ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 23:29:05.0493 0x0e30 rspndr - ok 23:29:05.0900 0x0e30 [ 3B7A94926B52D171C5B515EDECC2118E, 4D3A8F24AAA8DD155BE2B5814701FFE67C367BB29D31D615685277D2DEF0DB0A ] rtbth C:\Windows\System32\drivers\rtbth.sys 23:29:06.0009 0x0e30 rtbth - ok 23:29:06.0493 0x0e30 [ 34DA0D14F5C3F1883A331AFB975AB434, BB5D580C1DCAE59CC1DB75C411A5A4DDF435931469E7EBFF5DFDADBFE07ADEBF ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys 23:29:06.0556 0x0e30 RTL8168 - ok 23:29:06.0634 0x0e30 [ 1A063730F221B2746FF00457AE17E4F0, 39A3C258CBFE3BC566C63528C9020A3BC9409736AE5289C08A7BA471D8409263 ] s3cap C:\Windows\System32\drivers\vms3cap.sys 23:29:06.0728 0x0e30 s3cap - ok 23:29:06.0837 0x0e30 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] SamSs C:\Windows\system32\lsass.exe 23:29:06.0869 0x0e30 SamSs - ok 23:29:07.0009 0x0e30 [ C624A1B32211C3166EDB3F4AB02A30B7, 6B2A4607DB52D74242787ED9DF9067058983D310431D8612D2B0236E6201E681 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 23:29:07.0134 0x0e30 sbp2port - ok 23:29:07.0244 0x0e30 [ 47C497FA4DDEA908633CAA60CEBE6805, 4DF5742D4C99D3F7B6A5671AEDB1E5E47D3399D36B28BA19C105FA604D8D5A1C ] SCardSvr C:\Windows\System32\SCardSvr.dll 23:29:07.0494 0x0e30 SCardSvr - ok 23:29:07.0556 0x0e30 [ E76C4E98302AE39CC6FA5D20FC8B5438, B6B6B59CF427515087689285797F4A5763103440EBE5D87A61FA74F80F895BD0 ] ScDeviceEnum C:\Windows\System32\ScDeviceEnum.dll 23:29:07.0634 0x0e30 ScDeviceEnum - ok 23:29:07.0697 0x0e30 [ ABD0237B15DBD2B4695F4B7D734A58F7, D6831921F0CD3E03CBF1CA3ED5824EE0C75127842D12D4E897E74EC72B0792EB ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys 23:29:07.0775 0x0e30 scfilter - ok 23:29:08.0478 0x0e30 [ D3AE5DB16EAF913860EC28654CE00E6B, AD76B6044F7247C6E86F6DCB7CFD6B25BCA2B9F09A97A419F043A999E66726A2 ] Schedule C:\Windows\system32\schedsvc.dll 23:29:08.0775 0x0e30 Schedule - ok 23:29:08.0947 0x0e30 [ AB285CE3431FF3D2ACE669245874C1C7, 6AF4C3E86EFA51F7FB6F8492CB2CCB807C7775EAE0508B87F07134FDAC679BD7 ] SCPolicySvc C:\Windows\System32\certprop.dll 23:29:08.0978 0x0e30 SCPolicySvc - ok 23:29:09.0228 0x0e30 [ FDEC5799BA499D18AFA3A540538866E7, 551EE0945FE4EC213FFF623E524500B57531EFEA2D76FA7ED1D2D605E7E2168F ] sdbus C:\Windows\System32\drivers\sdbus.sys 23:29:09.0525 0x0e30 sdbus - ok 23:29:09.0650 0x0e30 [ 0B1E929D11A8E358106955603FAC65E8, A5EC91BFC0873EC6AB1D0DB4E91654BD35339BD680E7E82DA2DC64996B4AE515 ] sdstor C:\Windows\System32\drivers\sdstor.sys 23:29:09.0806 0x0e30 sdstor - ok 23:29:09.0853 0x0e30 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv C:\Windows\system32\drivers\secdrv.sys 23:29:09.0884 0x0e30 secdrv - ok 23:29:09.0947 0x0e30 [ C49009F897BA4F2F4F31043663AA1485, 48C8BE1E3A4F150662AD012AF4E0357ABA792AD1147AB90EFF6CB2630E2501B6 ] seclogon C:\Windows\system32\seclogon.dll 23:29:10.0025 0x0e30 seclogon - ok 23:29:10.0822 0x0e30 [ 398A81D590424441B2F5C5C08073CADB, 1E064DFCC49EB0D8A4150276BF796B9DFA030C451570A170EC940F8CBAAD80F3 ] Secunia PSI Agent C:\Program Files (x86)\Secunia\PSI\PSIA.exe 23:29:13.0056 0x0e30 Secunia PSI Agent - ok 23:29:13.0244 0x0e30 [ 8C2D3A80FC90A860F0F24DEB67471481, CE4D17B63149C44B4CD5CB7776FD4705DC675F6D2D077D53BE15578294EBC9D4 ] Secunia Update Agent C:\Program Files (x86)\Secunia\PSI\sua.exe 23:29:13.0291 0x0e30 Secunia Update Agent - ok 23:29:13.0369 0x0e30 [ A88882E64BDC1D8E8D6E727B71CCCC53, 12D2235F54D0CEEED8AA268C17CDE44020269F4FEFC70CE957DBBF99AF7F553D ] SENS C:\Windows\System32\sens.dll 23:29:13.0509 0x0e30 SENS - ok 23:29:13.0713 0x0e30 [ E66A7C8CE7ED22DED6DF1CA479FB4790, ADEB076F131E7A8C3AD96022B09BB33EB9AB26C9C831503B8C6960AA763B8975 ] SensrSvc C:\Windows\system32\sensrsvc.dll 23:29:13.0947 0x0e30 SensrSvc - ok 23:29:13.0994 0x0e30 [ DB2FF24CE0BDD15FE75870AFE312BA89, 7DB0D978C92CD0A0A81F7AB46FE323B4929CEA01585B0F330921E6DFA7DE1B85 ] SerCx C:\Windows\system32\drivers\SerCx.sys 23:29:14.0088 0x0e30 SerCx - ok 23:29:14.0259 0x0e30 [ 0044B31F93946D5D41982314381FE431, 95B8A94BA9EF770F29ACD5B23D447EC2B6CF1CB3D0030343BA1550AC31F6E2A5 ] SerCx2 C:\Windows\system32\drivers\SerCx2.sys 23:29:14.0353 0x0e30 SerCx2 - ok 23:29:14.0478 0x0e30 [ 3CD600C089C1251BEEB4CD4CD5164F9E, D9F81951B4454B24E821E33ACA53A851A61F3135E8EC6FBE6761A1A3E1CDCBE2 ] Serenum C:\Windows\System32\drivers\serenum.sys 23:29:14.0603 0x0e30 Serenum - ok 23:29:14.0806 0x0e30 [ D864381BC9C725FAB01D94C060660166, 132FED95222BBE3B0B25B3F1F0EFC5903D04564BD047BA4D2042AD51E3FDA724 ] Serial C:\Windows\System32\drivers\serial.sys 23:29:14.0869 0x0e30 Serial - ok 23:29:15.0010 0x0e30 [ 0BD2B65DCE756FDE95A2E5CCCBF7705D, F13FAFEC8FCF3E796196562717C433CE359A74A3E5876AB070647C717AF74028 ] sermouse C:\Windows\System32\drivers\sermouse.sys 23:29:15.0056 0x0e30 sermouse - ok 23:29:15.0322 0x0e30 [ D5C3776CBD8BC307DCCA3FD4CE667A37, 98E4253B770C25914C91A6148E2EA15ED0EF37ADCB042A47252DBA135972BF74 ] SessionEnv C:\Windows\system32\sessenv.dll 23:29:15.0478 0x0e30 SessionEnv - ok 23:29:15.0588 0x0e30 [ 472B7A5AC181C050888DB454663DD764, C950A8615D57BFD455E18880398350642B2E1D6B951EC9754FD8D429F3418835 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys 23:29:15.0728 0x0e30 sfloppy - ok 23:29:16.0088 0x0e30 [ F4414F57DF2CECB8FC969AA43A6B0D50, AD09A6E1294721507DD6BE82B91F2EEB0FF0151B9BC14A75840CD657DBFDECEC ] SharedAccess C:\Windows\System32\ipnathlp.dll 23:29:16.0353 0x0e30 SharedAccess - ok 23:29:16.0463 0x0e30 [ E476E4FE5FE152D2DAB49C87960254B7, 5C0CBBDCE2E23D116FE1317962CBC07A5A78C1A8E3BEC79BC4DD686942AD4363 ] Shdbus C:\Windows\system32\DRIVERS\Shdbus.sys 23:29:16.0525 0x0e30 Shdbus - ok 23:29:16.0791 0x0e30 [ 730BE85DC7AA176AEC7D8D76DD2400A1, 59CD7B3D33C05621AC136181448EA3E61F94CD1AC663A84FD2E48D7E40366501 ] ShdServ C:\Program Files\Shield\shdserv.exe 23:29:16.0822 0x0e30 ShdServ - ok 23:29:17.0119 0x0e30 [ 0D190D8B4B20446BE6299AC734DFADF1, 6551095971F99820BBFC5FED8FAB9591A3F8ABFA0F027887F3B71B79325FF6D9 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 23:29:17.0260 0x0e30 ShellHWDetection - ok 23:29:17.0385 0x0e30 [ 17F8B7B988B8FD75DF7595AC29A3F969, B398A07B8D9A68B0E3395CEF973A4237D758263CE0CE12E3881C0629C1FDAA55 ] Shield C:\Windows\system32\DRIVERS\shield.sys 23:29:17.0463 0x0e30 Shield - ok 23:29:17.0791 0x0e30 [ D709467DCC06E0487AEAF047DA431C4B, 72FE3EEAFE5942C9C0D172FBC8CD0D20990D44BD88B8BFDD53C6A23DFD49DADC ] ShieldClientService C:\Program Files\Shield\shieldclnt.exe 23:29:17.0822 0x0e30 ShieldClientService - detected UnsignedFile.Multi.Generic ( 1 ) 23:29:17.0822 0x0e30 ShieldClientService ( UnsignedFile.Multi.Generic ) - warning 23:29:17.0885 0x0e30 [ 24D20409F062C898FA8D6D111C8EB4B0, 80FBE92F0B458B55854E833F8792A8F5FF89ED8F42A900779EAC5DCF0745E3AC ] Shieldf C:\Windows\system32\DRIVERS\Shieldf.sys 23:29:18.0010 0x0e30 Shieldf - ok 23:29:18.0025 0x0e30 [ 1AE559D495E68D832684B8C5D8653469, 4C39B48AC2B8B2883C6EE6A617D7D9F65B8A0BDEFAD9F5BBFAF2FE008908C36A ] Shieldm C:\Windows\system32\DRIVERS\Shieldm.sys 23:29:18.0057 0x0e30 Shieldm - ok 23:29:18.0088 0x0e30 [ 2F518D13DD6F3053837FE606F1A2EA1F, 64109296CE95BD233525688A350D575CF97B9464659AA07CF78B307B6ADBC835 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys 23:29:18.0166 0x0e30 SiSRaid2 - ok 23:29:18.0197 0x0e30 [ 1AC9A200A9C49C4508F04AAFFCA34A3F, 972BCB2A39169155F74111FAC74ACCD8F50E34EADCF087833B0980827627BBF4 ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 23:29:18.0228 0x0e30 SiSRaid4 - ok 23:29:18.0291 0x0e30 [ 587ACA15210D1B01FBF272E07A08F91A, 1F3C13C218C5EA329C6E33E4AE7CFE88DAD59DA40F59FDE09D733AFD2E489000 ] smphost C:\Windows\System32\smphost.dll 23:29:18.0463 0x0e30 smphost - ok 23:29:18.0494 0x0e30 [ 49EEB92DE930B8566EF615D600781DB4, 0B7C929D24FAFC34F95BB4AA77DCBA29DDD8F1977EB42713B64228677D1FBFD3 ] SNMPTRAP C:\Windows\System32\snmptrap.exe 23:29:18.0541 0x0e30 SNMPTRAP - ok 23:29:18.0838 0x0e30 [ 240C5C3793206725AA05665851E8C214, 96ADFB85EB1623EB00C251C1C6A1F441A1795F0EBFD10B17DD1CA58E3AE8A90D ] spaceport C:\Windows\system32\drivers\spaceport.sys 23:29:18.0916 0x0e30 spaceport - ok 23:29:18.0947 0x0e30 [ F337BE11071818FC3F5DC2940B6BDE34, D5CFF00E5DF37045F71AEE101AC9B270EBB29F372F404757B58600E9966C7E4D ] SpbCx C:\Windows\system32\drivers\SpbCx.sys 23:29:18.0978 0x0e30 SpbCx - ok 23:29:19.0025 0x0e30 [ 42FEA9E0BA9761D9E65A4F167D91515B, 9A34CE83F3ACD50608671BDABE5E475F8E0C8335D3B8B7B3D7E84B2A319FA29F ] Spooler C:\Windows\System32\spoolsv.exe 23:29:19.0088 0x0e30 Spooler - ok 23:29:21.0432 0x0e30 [ C993A0B97BECD3AAF5158E3869878465, 8B86F37DEFCBE55DE507D830EC4980EBB39B3CCA30C2B3E76B588AAB282A50FC ] sppsvc C:\Windows\system32\sppsvc.exe 23:29:21.0744 0x0e30 sppsvc - ok 23:29:21.0854 0x0e30 [ 6416E79A58A8FCC33A447A4DDDD3BF04, 839E3107ACCD520C309BD6C8324DF7A8EB724EAD442AB1F1CACB0D83F84BE488 ] srv C:\Windows\system32\DRIVERS\srv.sys 23:29:21.0947 0x0e30 srv - ok 23:29:21.0994 0x0e30 [ 5BED3AB69797C8786EF70AEA8C33748B, 0474EE6C43D437CBA9848BCF25D1341B122D7E9F371A0FF3C62C83D14B2CB095 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 23:29:22.0057 0x0e30 srv2 - ok 23:29:22.0229 0x0e30 [ D047CD668E6277FD80F0C613946F034C, BD0209E7FD89F9295D4DE48C9652DF2A2990277C16AFA473B96704B1CBD2F338 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 23:29:22.0354 0x0e30 srvnet - ok 23:29:22.0494 0x0e30 [ BB9ED3EDD8E85008215A7250D325A72E, D3404E31B7706B25CDEA7CB4260C343B5F090E8CCB9A5FA203B0F94A9112F1B3 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 23:29:22.0713 0x0e30 SSDPSRV - ok 23:29:22.0838 0x0e30 [ 3911418AFDE10EA6823B7799E4815524, A73517C4C1271E666B2B3A747756070098E923742B41572AA16573170440AA07 ] SstpSvc C:\Windows\system32\sstpsvc.dll 23:29:22.0994 0x0e30 SstpSvc - ok 23:29:23.0104 0x0e30 [ 366DEA74BBA65B362BCCFC6FC2ADFD8B, 4D28122AB9D8DAB724021E6513B4474BD34FCEDF47769B1D27AC7551FCA002F8 ] stexstor C:\Windows\system32\drivers\stexstor.sys 23:29:23.0182 0x0e30 stexstor - ok 23:29:23.0369 0x0e30 [ D638904FE86A5FE542A1BA13A9D68E5C, 89A956F932316BC50DD99B54BAF4E2809DCAA084DBB04CB84D11E5470BEAF251 ] stisvc C:\Windows\System32\wiaservc.dll 23:29:23.0588 0x0e30 stisvc - ok 23:29:23.0651 0x0e30 [ 0ED2E318ABB68C1A35A8B8038BDB4C90, 5C3ABC245F4BCFE64E646D9C0E2F5E211244956C84D03084C71FF6A7E0CDED30 ] storahci C:\Windows\system32\drivers\storahci.sys 23:29:23.0666 0x0e30 storahci - ok 23:29:23.0682 0x0e30 [ 7A08CEE1535F5A448215634C5EA74E50, 41529CDC08A3956F8FE9D5759B147E2E56E3305149EA415EB200249F7CD32094 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys 23:29:23.0776 0x0e30 storflt - ok 23:29:23.0869 0x0e30 [ 6B06E2D11E604BE2B1A406C4CB3B90DE, 2DDEA1568A85AD64FCE5D10D348304FCD9BE6E96C2313353EF70A2933306D188 ] stornvme C:\Windows\system32\drivers\stornvme.sys 23:29:23.0932 0x0e30 stornvme - ok 23:29:24.0322 0x0e30 [ 3118058E3D07021A55324A943C6D722B, 0B255DF1977DADD2B9766EEEA814B464F0ABFA34D6439F3C453083850C121F16 ] StorSvc C:\Windows\system32\storsvc.dll 23:29:24.0479 0x0e30 StorSvc - ok 23:29:24.0588 0x0e30 [ 548759755BC73DAD663250239D7E0B9F, D31A05A8CE800B539420B6E545F1F4BF6E4B02EAF8366DE89CAF13A83C6CA48D ] storvsc C:\Windows\system32\drivers\storvsc.sys 23:29:24.0619 0x0e30 storvsc - ok 23:29:24.0729 0x0e30 [ D8E1AE075AB3E8AD56F69C44AA978596, CAFF5116DE7F0EEFFEBE38724BCEE7D11B44153AD35EE43E314C56D5E210758A ] svsvc C:\Windows\system32\svsvc.dll 23:29:24.0822 0x0e30 svsvc - ok 23:29:24.0901 0x0e30 [ 84E0F5D41C138C5CC975137A2A98F6D3, 1E36CED05E4F4365C2AB020CAF920E3959995D7F89F3FABD7B2FB05985F85F38 ] swenum C:\Windows\System32\drivers\swenum.sys 23:29:24.0994 0x0e30 swenum - ok 23:29:25.0416 0x0e30 [ 850EBB87584484DC16F917E7B6F4A304, C253D1DFFCDFB018432063602FB01DBCBDDD6E03458E5C366AABD4670F114B0C ] swprv C:\Windows\System32\swprv.dll 23:29:25.0557 0x0e30 swprv - ok 23:29:25.0682 0x0e30 [ 3F45C3FE208CA5E68832B65C597A35A6, EACE9AAFC01C2BA52F4DA129AEF7BFA3CF7F10146E4F4330CD344BFC39DC959C ] SynTP C:\Windows\system32\DRIVERS\SynTP.sys 23:29:25.0760 0x0e30 SynTP - ok 23:29:26.0026 0x0e30 [ 5041B5FAC484586CF6C515A3BF9747DC, EFA7405814FC3A8D052B23ED680F6C26A6E312DFABC19B8D3AA73278306CD1AD ] SysMain C:\Windows\system32\sysmain.dll 23:29:26.0323 0x0e30 SysMain - ok 23:29:26.0541 0x0e30 [ D65B1C952AEB864C2BAC7A770B17ECCE, 3EFAAFFF73390D9CB660E0F42B305512396CF66ED06E4A20ED67E8722FB4355B ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll 23:29:26.0635 0x0e30 Suspicious file ( Forged ): C:\Windows\System32\SystemEventsBrokerServer.dll. Real md5: D65B1C952AEB864C2BAC7A770B17ECCE, sha256: 3EFAAFFF73390D9CB660E0F42B305512396CF66ED06E4A20ED67E8722FB4355B, fake md5: FD4EA8E9232ADD51DC31C295DDEF2768, fake sha256: 3EA40D7376AB5AA5DA2BCF4745C79F7BF819363466967ECC3CD15ADECBFD7244 23:29:26.0635 0x0e30 SystemEventsBroker - detected ForgedFile.Multi.Generic ( 1 ) 23:29:26.0635 0x0e30 SystemEventsBroker ( ForgedFile.Multi.Generic ) - warning 23:29:26.0635 0x0e30 Force sending object to P2P due to detect: SystemEventsBroker 23:29:26.0682 0x0e30 Object send P2P result: false 23:29:26.0807 0x0e30 [ BA6DD39266A5E15515C8C14DA2DA3E5C, 5BC917BA4E7281A67CC6CEF2F4D1972DF04DECBEFB6DED0B08FFBD06E15D4B4F ] TabletInputService C:\Windows\System32\TabSvc.dll 23:29:26.0901 0x0e30 TabletInputService - ok 23:29:27.0057 0x0e30 [ B517410F157693043DACA21B19B258A6, 2224EECEB575CEA811036C43BB5B0A408DE5F59BC97235AB948968E4C3E438F2 ] TapiSrv C:\Windows\System32\tapisrv.dll 23:29:27.0369 0x0e30 TapiSrv - ok 23:29:28.0276 0x0e30 [ FEBAA7D782E30882FFF1CBCBBE8AD467, B54333F52CF901CADB3B71334BFAFA63C508A0F7EA7E700C5578FC20D780403E ] Tcpip C:\Windows\system32\drivers\tcpip.sys 23:29:28.0323 0x0e30 Suspicious file ( Forged ): C:\Windows\system32\drivers\tcpip.sys. Real md5: FEBAA7D782E30882FFF1CBCBBE8AD467, sha256: B54333F52CF901CADB3B71334BFAFA63C508A0F7EA7E700C5578FC20D780403E, fake md5: CCB3A2BB60FE5073F2DEA63FE83CF8FE, fake sha256: 02982136236DD595D8974E6645A008D663B4DD3BC3824721E4DE4377B97887C7 23:29:28.0323 0x0e30 Tcpip - detected ForgedFile.Multi.Generic ( 1 ) 23:29:28.0323 0x0e30 Object is SCO, delete is not allowed 23:29:28.0323 0x0e30 Tcpip ( ForgedFile.Multi.Generic ) - warning 23:29:28.0510 0x0e30 [ FEBAA7D782E30882FFF1CBCBBE8AD467, B54333F52CF901CADB3B71334BFAFA63C508A0F7EA7E700C5578FC20D780403E ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys 23:29:28.0557 0x0e30 Suspicious file ( Forged ): C:\Windows\system32\DRIVERS\tcpip.sys. Real md5: FEBAA7D782E30882FFF1CBCBBE8AD467, sha256: B54333F52CF901CADB3B71334BFAFA63C508A0F7EA7E700C5578FC20D780403E, fake md5: CCB3A2BB60FE5073F2DEA63FE83CF8FE, fake sha256: 02982136236DD595D8974E6645A008D663B4DD3BC3824721E4DE4377B97887C7 23:29:28.0557 0x0e30 TCPIP6 - detected ForgedFile.Multi.Generic ( 1 ) 23:29:28.0557 0x0e30 Object is SCO, delete is not allowed 23:29:28.0557 0x0e30 TCPIP6 ( ForgedFile.Multi.Generic ) - warning 23:29:28.0557 0x0e30 Force sending object to P2P due to detect: TCPIP6 23:29:28.0588 0x0e30 Object send P2P result: false 23:29:28.0604 0x0e30 [ 41CF802064F72E55F50CA0A221FD36D4, 70ABCDF9E96611E8C83042C581575E26649FE479475E8E118CD3FF6CB1C84C3F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 23:29:28.0635 0x0e30 tcpipreg - ok 23:29:28.0666 0x0e30 [ FFF28F9F6823EB1756C60F1649560BBF, 208DFF8BF0329D0D4761C7E31527AEED7FF5F3C36C5005953D01477F35408D5C ] tdx C:\Windows\system32\DRIVERS\tdx.sys 23:29:28.0713 0x0e30 tdx - ok 23:29:28.0745 0x0e30 [ 232D185D2337F141311D0CF1983E1431, 02EB56D3F26174AF1741C1A444CE30DE84D5BAF583C1A52C7A953BCC52445547 ] terminpt C:\Windows\System32\drivers\terminpt.sys 23:29:28.0838 0x0e30 terminpt - ok 23:29:29.0338 0x0e30 [ 3D748E5558FD9A9F03182CB2330698DC, 70B2069AB7912EB49AB3ABD18D4B42CB94AC99CA6DE3F63F4888B8EAAC78AAA2 ] TermService C:\Windows\System32\termsrv.dll 23:29:29.0620 0x0e30 TermService - ok 23:29:29.0682 0x0e30 [ 05FBE1F7C13E87AF7A414CDF288B1F62, 24079E1A6B2E33A1A8E76A77F73473B93DD6B379E44C982CE50D6CEED9747838 ] Themes C:\Windows\system32\themeservice.dll 23:29:29.0823 0x0e30 Themes - ok 23:29:29.0948 0x0e30 [ FD788C2D96EA91469A3C1D13E80D7473, 7B14D4BFDE18CECC19FBFFAA5AFF5FD78BFB7FCDA6613990740A8A7DD9873D26 ] THREADORDER C:\Windows\system32\mmcss.dll 23:29:29.0995 0x0e30 THREADORDER - ok 23:29:30.0120 0x0e30 [ 347A3E49CE18402305B8119A6EC7CFEB, 6768B20EE577880B0353FE84B980D4A18D323929A63FAE41F7A55123BBFC8DBA ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll 23:29:30.0323 0x0e30 TimeBroker - ok 23:29:30.0510 0x0e30 [ 82F909359600D3603FE852DB7F135626, 2EB2BB9D81AC9A2E432B2628E296B7B21F1C82EAE8009300EEF1B8596A9F418D ] TPM C:\Windows\system32\drivers\tpm.sys 23:29:30.0604 0x0e30 TPM - ok 23:29:30.0713 0x0e30 [ C97E14BB6A196B0554D6EB67D8818175, C00588C94988F10507F84584DFA4C0A43B8648AD1AD35E9BAE14CDD21FCF7B90 ] TrkWks C:\Windows\System32\trkwks.dll 23:29:30.0760 0x0e30 TrkWks - ok 23:29:31.0041 0x0e30 [ 325A512F98BEB97B1FFBE88927B8090D, 2A0C10516E3506D63290345DFAC98D5A623584767E034EBF652B9DBE6CF70547 ] trufos C:\Windows\system32\DRIVERS\trufos.sys 23:29:31.0135 0x0e30 trufos - ok 23:29:31.0307 0x0e30 [ 887CC44830D3F367CAD17A0CA7CCA5C8, D4022A76433A11FD66D0F41A1EB4D6893BC5B22317E7E9E021739109EB493B44 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 23:29:31.0432 0x0e30 TrustedInstaller - ok 23:29:31.0463 0x0e30 [ BF8F54CA37E9C9D6582C31C5761F8C93, 337C566792F6FB9B7FD5D1D4384B767CFE4CF5DBB2E4688CCC36CBB018A0DD0F ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys 23:29:31.0526 0x0e30 TsUsbFlt - ok 23:29:31.0604 0x0e30 [ E0088068DCE2EE82897027DDB8E05254, FA9C201D3C885DAD2ABE6A23343EDCC83CFB342EFF9E3005FA50B1D88B21D203 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys 23:29:31.0667 0x0e30 TsUsbGD - ok 23:29:31.0713 0x0e30 [ C8E0E78B5D284C2FF59BDFFDAF997242, BA1576C491A1246EF9866762426D110F4570F9DB42A68C174943C7D5020FE3E2 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 23:29:31.0792 0x0e30 tunnel - ok 23:29:31.0838 0x0e30 [ F6EEAD052943B5A3104C1405BB856C54, FE422813E6C1012E9F392EFF2AE4C6D3A4DBD9CB2BD5E6A5CAB57D4E89A29468 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 23:29:31.0854 0x0e30 uagp35 - ok 23:29:31.0885 0x0e30 [ FE6067B1FD4E63650C667B33D080565B, 2C330ED00E49BA55E25564230E0DFB8A35F2B5320EB18D4AF7CAACFA9A449044 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys 23:29:31.0948 0x0e30 UASPStor - ok 23:29:32.0026 0x0e30 [ B034A41891A36457B994307DFA772293, CA5E6500764A9777AE0E15B2AFB6F05982C90F01374E3F6DDC6DF3852282C66B ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys 23:29:32.0104 0x0e30 UCX01000 - ok 23:29:32.0135 0x0e30 [ 1EC649F112896FAE33250F0B97AC5D0B, 0C0A1C2C7615DEB298AD3073340FD1BF91FEBE611F133E3B48D994A6EAA8369F ] udfs C:\Windows\system32\DRIVERS\udfs.sys 23:29:32.0198 0x0e30 udfs - ok 23:29:32.0245 0x0e30 [ 9578691F297E1B1F519970FE6D47CB21, 080C352AAF22A16A4F3C4AB4DCEA5BFA656457C73F735CEBA30516FDACCF6301 ] UEFI C:\Windows\System32\drivers\UEFI.sys 23:29:32.0307 0x0e30 UEFI - ok 23:29:32.0354 0x0e30 [ 320878AFECDBBD61BBE98624A6CAAC08, 15C090EA32A24D976B5FCB1373B1281DCC2295C075299C814345D694AEB47CB9 ] UI0Detect C:\Windows\system32\UI0Detect.exe 23:29:32.0432 0x0e30 UI0Detect - ok 23:29:32.0448 0x0e30 [ 5EAB5117DDB24FC4D39E6FFFCF1837B9, 2BC709240867F161E94BE6625A04F478EAAA3EEE7BC7C37ED0DFA9EEA5928E98 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 23:29:32.0479 0x0e30 uliagpkx - ok 23:29:32.0542 0x0e30 [ DA34C39A18E60E7C3FA0630566408034, 2F162504214053894C72760D9933D01DBF3578609FE5E2376C3272818599FE32 ] umbus C:\Windows\System32\drivers\umbus.sys 23:29:32.0620 0x0e30 umbus - ok 23:29:32.0651 0x0e30 [ AE8294875E5446E359B1E8035D40C05E, AE0357BAB47C07C3576BC76951CD258C009BC5A1B93259D2122A841BD9CDA8FA ] UmPass C:\Windows\System32\drivers\umpass.sys 23:29:32.0682 0x0e30 UmPass - ok 23:29:32.0776 0x0e30 [ E3DDF7D43E05784FAA5E042605EEE528, 8E20E880FAB09AF4FF5C438BF9EAE9970D46C05167870110869B744E498FD761 ] UmRdpService C:\Windows\System32\umrdp.dll 23:29:32.0885 0x0e30 UmRdpService - ok 23:29:33.0229 0x0e30 [ DBE2E6388379D5CC78099650541E9566, 1914BC929F109A49FB18ED31F239A9813A010B0A3914BC8CD0D6A94A67A072D7 ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe 23:29:33.0292 0x0e30 UNS - ok 23:29:33.0479 0x0e30 [ 612AACDDFF7EF81375927C2D7E4E810C, 63B446E7DB4C31CBBA244F858335DAD386AE302E6B0EE8EABDE399439BC93D82 ] UPDATESRV C:\Program Files\Bitdefender\Bitdefender\updatesrv.exe 23:29:33.0510 0x0e30 UPDATESRV - ok 23:29:33.0620 0x0e30 [ 4A2FFDAC45F317E17DF642C7160EB633, F1AB762912FAA5F469F322407DA37C91556086C42D1643AD27516C12A84F74D0 ] upnphost C:\Windows\System32\upnphost.dll 23:29:33.0745 0x0e30 upnphost - ok 23:29:33.0807 0x0e30 [ FF78D053A05E5A394F4E3C1816CC65A8, 5DAE02414271231F5FDBB751AFEB99874779B467947020815D4AE54432D4269D ] usbccgp C:\Windows\System32\drivers\usbccgp.sys 23:29:33.0901 0x0e30 usbccgp - ok 23:29:33.0948 0x0e30 [ B3D6457D841A0CAEF4C52D88621715F2, CBDD76A8A28379B107B1FB530757B477B8AB74CD01F9F3CEDC7B1BA0C6E5A990 ] usbcir C:\Windows\System32\drivers\usbcir.sys 23:29:34.0042 0x0e30 usbcir - ok 23:29:34.0073 0x0e30 [ 48BA326A3DBA5B5BEB5F2777F4618696, B9EC8155F11A3A7644BD9DC8910681B46AE44AE3BF53F052DF50E9C5555E3229 ] usbehci C:\Windows\System32\drivers\usbehci.sys 23:29:34.0151 0x0e30 usbehci - ok 23:29:34.0385 0x0e30 [ FEF0BC107812B36849741C3211BA6B60, B3EF738BE1E6B6027F29C9713CD3F367EA067D2BE46580AFBC0FB58046EF6BBD ] usbhub C:\Windows\System32\drivers\usbhub.sys 23:29:34.0432 0x0e30 usbhub - ok 23:29:34.0651 0x0e30 [ 65392F3F3F65E4C6CC82A0F4F8A0B051, C11B662A28D95820717DFFC6B76DBB755E4876009A2342E5E3992DE32D6BFF61 ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys 23:29:34.0807 0x0e30 USBHUB3 - ok 23:29:34.0979 0x0e30 [ 3019097FB6C985EF24C058090FF3BDBD, 24AC518D34E338D94BF3D5B3F72E53F8A1369BAA7F32FEA3EDBCF928C4FF1D17 ] usbohci C:\Windows\System32\drivers\usbohci.sys 23:29:35.0401 0x0e30 usbohci - ok 23:29:35.0542 0x0e30 [ 4D655E3B684BE9B0F7FFD8A2935C348C, 3A7FC1748C5AEA8CFE0E7C22ADC77E3DCA475455FC16D9C6A5C16EB5E949A516 ] usbprint C:\Windows\System32\drivers\usbprint.sys 23:29:35.0807 0x0e30 usbprint - ok 23:29:35.0932 0x0e30 [ EA23453240137F6773174E0D93F61A69, 579AD09FB428C2BB8B4055128620A7AADD1B606C1EA44B87A01D69A84232A5D9 ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS 23:29:35.0995 0x0e30 Suspicious file ( Forged ): C:\Windows\System32\drivers\USBSTOR.SYS. Real md5: EA23453240137F6773174E0D93F61A69, sha256: 579AD09FB428C2BB8B4055128620A7AADD1B606C1EA44B87A01D69A84232A5D9, fake md5: 66732C13628BDB1AB0D6FD46027327C2, fake sha256: B582C0F348D8F79419CA5A58F10CA151E06D7CA3BE162344CADA46D9D7FED97C 23:29:35.0995 0x0e30 USBSTOR - detected ForgedFile.Multi.Generic ( 1 ) 23:29:35.0995 0x0e30 USBSTOR ( ForgedFile.Multi.Generic ) - warning 23:29:35.0995 0x0e30 Force sending object to P2P due to detect: USBSTOR 23:29:35.0995 0x0e30 Object send P2P result: false 23:29:36.0026 0x0e30 [ 064260B3A5868AC894A4943543BC7AB7, D3534E98B34C4AC9A430D7E0AB301A0E5E1511E3117C2FEA392636B0DE2C38E2 ] usbuhci C:\Windows\System32\drivers\usbuhci.sys 23:29:36.0135 0x0e30 usbuhci - ok 23:29:36.0276 0x0e30 [ 5C8F604F6DC74177CDD8372D7B1ADFF0, C1DE9A37A7A01CCCBFCE13C1E5B26683F620AB21EDA5A14C82022E2F49C84484 ] usbvideo C:\Windows\System32\Drivers\usbvideo.sys 23:29:36.0448 0x0e30 usbvideo - ok 23:29:36.0635 0x0e30 [ 48430B0313FC1CFE3D2400553F1A93CD, 92994DE6B131E904AFF2C9C4FBB4E6B0D58525A1539763327373DA18C9F08193 ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS 23:29:36.0729 0x0e30 USBXHCI - ok 23:29:36.0745 0x0e30 [ F6F209DDB94959BA104FC8FC87C53759, 8E862D41F4332EABF64BD034E2C0E3CC8109C7990CB4112C2B2880E8E6EDF2D3 ] VaultSvc C:\Windows\system32\lsass.exe 23:29:36.0760 0x0e30 VaultSvc - ok 23:29:36.0807 0x0e30 [ FEB26E3B8345A7E8D62F945C4AE86562, 3AAFE87C402FC8E92542DFE60EC9540559863065F88D429A16D7B1BF829223FF ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys 23:29:36.0886 0x0e30 vdrvroot - ok 23:29:37.0179 0x0e30 [ E3EF58D4123B5AA29C8E19825AF84A5E, FB1046722BC643E955DBC3B1459DBF2A6D575EBA2BCF7B20A0FA51E3993835E2 ] vds C:\Windows\System32\vds.exe 23:29:37.0273 0x0e30 vds - ok 23:29:37.0304 0x0e30 [ A026EDEAA5EECAE0B08E2748B616D4BD, 2525A54DC7F49DDFBB999C22BF3FAB6D9E9F70C0806E58D81E90AC59F9F46089 ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys 23:29:37.0320 0x0e30 VerifierExt - ok 23:29:37.0351 0x0e30 [ 52E483A3701A5A61A75A06993720347D, 689E812755E485DF6960D1E049740FBAFB812467D23B673DCAA40C03FEBB544F ] vhdmp C:\Windows\System32\drivers\vhdmp.sys 23:29:37.0445 0x0e30 vhdmp - ok 23:29:37.0476 0x0e30 [ 06D38968028E9AB19DE9B618C7B6D199, 62022297A47F440D1C82CA0B0E57C0C8E9D5033D83DD3B40492B218DF65EBF68 ] viaide C:\Windows\system32\drivers\viaide.sys 23:29:37.0508 0x0e30 viaide - ok 23:29:37.0523 0x0e30 [ C6305BDFC4F7CE51F72BB072C03D4ACE, 73E62869CA3104F48CC3B0C45E69CE9BF4F8D7D06E29C2F049B9347ABB50554D ] vmbus C:\Windows\system32\drivers\vmbus.sys 23:29:37.0539 0x0e30 vmbus - ok 23:29:37.0554 0x0e30 [ DA40BEA0A863CE768C940CA9723BF81F, 567C0C3F422325635808B0CF76E05D3B6187F96845C33F85F92F98C9FE53A5B8 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys 23:29:37.0601 0x0e30 VMBusHID - ok 23:29:37.0773 0x0e30 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicguestinterface C:\Windows\System32\ICSvc.dll 23:29:37.0914 0x0e30 vmicguestinterface - ok 23:29:37.0961 0x0e30 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicheartbeat C:\Windows\System32\ICSvc.dll 23:29:37.0992 0x0e30 vmicheartbeat - ok 23:29:38.0070 0x0e30 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmickvpexchange C:\Windows\System32\ICSvc.dll 23:29:38.0101 0x0e30 vmickvpexchange - ok 23:29:38.0211 0x0e30 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicrdv C:\Windows\System32\ICSvc.dll 23:29:38.0242 0x0e30 vmicrdv - ok 23:29:38.0258 0x0e30 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicshutdown C:\Windows\System32\ICSvc.dll 23:29:38.0289 0x0e30 vmicshutdown - ok 23:29:38.0305 0x0e30 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmictimesync C:\Windows\System32\ICSvc.dll 23:29:38.0320 0x0e30 vmictimesync - ok 23:29:38.0383 0x0e30 [ 9067880BBB1C18703DBFF27D731D7ECA, 0044246249F4B945D72BBC0FEF9BF3C31E62F57CBF77615A95213B36A29F0C71 ] vmicvss C:\Windows\System32\ICSvc.dll 23:29:38.0414 0x0e30 vmicvss - ok 23:29:38.0476 0x0e30 [ 55D7D963DE85162F1C49721E502F9744, 5AD34D6DB707EF3E5242BD8CA67B21D6258EE7E7FC477D5227BD15500AE7F45F ] volmgr C:\Windows\system32\drivers\volmgr.sys 23:29:38.0539 0x0e30 volmgr - ok 23:29:38.0648 0x0e30 [ CCB9E901F7254BF96D28EB1B0E5329B7, F0E3CA4EFA544CDAEF4092284CF3EC7DF07F806A770285E281816457AD8813F5 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 23:29:38.0680 0x0e30 volmgrx - ok 23:29:38.0726 0x0e30 [ 64CA2B4A49A8EAF495E435623ECCE7DB, 81151F295A54DE2B8B88C7F48C86BF58CDFF96F98493509C06D6F41484594386 ] volsnap C:\Windows\system32\drivers\volsnap.sys 23:29:38.0742 0x0e30 volsnap - ok 23:29:38.0758 0x0e30 [ 01355C98B5C3ED1EC446743CDA848FCE, B9FCF558C20E05DD0F53FFB70BBEF873EA57801E13A16701E636128D625C4B67 ] vpci C:\Windows\System32\drivers\vpci.sys 23:29:38.0773 0x0e30 vpci - ok 23:29:38.0789 0x0e30 [ 4539F45F9F4C9757A86A56C949421E07, DEC362314B2C66414F39354AFE79C02B18BF4EEF90787FB58307F6EB62237E2C ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 23:29:38.0836 0x0e30 vsmraid - ok 23:29:38.0914 0x0e30 [ E369C59F2C0852DDD090C07E0DDE0051, 4FAC94458EAAEED4F84A86FBAB8FBB332D0AF85BD528E63C0C058A2DA8E3011D ] VSS C:\Windows\system32\vssvc.exe 23:29:39.0008 0x0e30 VSS - ok 23:29:39.0398 0x0e30 [ 1D5CFF9D5751F9916DE9906472BF1E3D, E2E52485F00E93BEDD9C1930824494C00A19BA3CB16D7740FF28D5E83EC8139B ] VSSERV C:\Program Files\Bitdefender\Bitdefender\vsserv.exe 23:29:39.0461 0x0e30 VSSERV - ok 23:29:39.0586 0x0e30 [ 0849B7260F26FE05EA56DED0672E2F4B, 7EAC0E7988F45CB4133A15932955B7B03CE715C967A3BAC9999D81543EBCAEC5 ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys 23:29:39.0633 0x0e30 VSTXRAID - ok 23:29:39.0648 0x0e30 [ BE970C369E43B509C1EDA2B8FA7CECB0, 18951F2AA842A0795AA79A4E164EE925A35E6270EBE4C4CDB19D0A891830E383 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys 23:29:39.0726 0x0e30 vwifibus - ok 23:29:39.0742 0x0e30 [ 35BF5C5F5E3C9902C98978C7640574DA, C61E50B04000DCEC72365723F0C0725C2E005529DAF2777A59E624C14DA29E55 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys 23:29:39.0945 0x0e30 vwififlt - ok 23:29:39.0976 0x0e30 [ 65ED7B9CFEA893DF7748D5FF692690DE, 73AB9D8BB928B3247BDFC7BB47AD7FCA763B375DC250C251DB4E0573531040E8 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys 23:29:40.0148 0x0e30 vwifimp - ok 23:29:40.0258 0x0e30 [ 7599E582CA3A6AAA95A18FFE1172D339, A0410778FBBC4302EA91CF24B944427410B4706535F1192504D4F34C3ED4503E ] W32Time C:\Windows\system32\w32time.dll 23:29:40.0320 0x0e30 W32Time - ok 23:29:40.0320 0x0e30 [ 0910AB9ED404C1434E2D0376C2AD5D8B, 62585CA5F1375BDA440D28D5DF1ADDC9DE3DDFA196D49BBFF3456A5A09EE1C6B ] WacomPen C:\Windows\System32\drivers\wacompen.sys 23:29:40.0336 0x0e30 WacomPen - ok 23:29:40.0367 0x0e30 [ AFCD4054D61BD708B82991348ED1C763, EBDAC0E218F1DFC405DB3C8A2F014D20A17B0690EA381C750BED5C2AFCDFEBE3 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 23:29:40.0430 0x0e30 Wanarp - ok 23:29:40.0445 0x0e30 [ AFCD4054D61BD708B82991348ED1C763, EBDAC0E218F1DFC405DB3C8A2F014D20A17B0690EA381C750BED5C2AFCDFEBE3 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 23:29:40.0461 0x0e30 Wanarpv6 - ok 23:29:40.0523 0x0e30 [ 61692DB39AD3DF2F29392D68EAA7BB93, 854D4B9C7DD1676968598ED973500650ECEC02C420E44C0B3957C24F073AA5FB ] wbengine C:\Windows\system32\wbengine.exe 23:29:40.0773 0x0e30 wbengine - ok 23:29:41.0195 0x0e30 [ 3BC1D1D56637A32CD91C8AE08E2484AA, 9EE1BD3FB0D289E25F3DDD0D8F67DC1C701A6B1D5418FADF348D0E642B1DEBEB ] WbioSrvc C:\Windows\System32\wbiosrvc.dll 23:29:41.0305 0x0e30 WbioSrvc - ok 23:29:41.0539 0x0e30 [ A07CFC4B593D15B6BF06813C3B5B33BF, B57BD918E2AFF9943B51A24B95E0C4D3482B4DF73C0E2421E8CC67C2BC7A4C70 ] Wcmsvc C:\Windows\System32\wcmsvc.dll 23:29:41.0758 0x0e30 Wcmsvc - ok 23:29:41.0961 0x0e30 [ D2726823DF7E19F213F4805A9D6D145F, A7F582C99918D204264D3B374F70D75984BDA5805203041E3DECB8153D16E102 ] wcncsvc C:\Windows\System32\wcncsvc.dll 23:29:42.0180 0x0e30 wcncsvc - ok 23:29:42.0273 0x0e30 [ 846C02A8B48CBD921A3D6AB521AA0DC4, B07573A774A6C65D24E5718DC25DF378270EB5B40221CA5A53B21D47838381D3 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 23:29:42.0477 0x0e30 WcsPlugInService - ok 23:29:42.0508 0x0e30 [ F5D4FA3E1F4879C361FFF3855259D2C2, 48C60FE4AAB011E2250157506FF0624031BFA346F8F2F8C6DFDF6F3CAA4F3F42 ] WdBoot C:\Windows\system32\drivers\WdBoot.sys 23:29:42.0602 0x0e30 WdBoot - ok 23:29:43.0133 0x0e30 [ CB6C63FF8342B467E2EF76E98D5B934D, BE017CE91E3BAB293DE6ECF143797CCE3F33CC63024437472B4E38C6961AD884 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 23:29:43.0227 0x0e30 Wdf01000 - ok 23:29:43.0258 0x0e30 [ 019CC610AD95FF47EAD7C08B7A683B96, BB9D42F8ED90ECA2E7B8C906E06A1EA859FAD9BD1B3492BB1E28C0D00004812A ] WdFilter C:\Windows\system32\drivers\WdFilter.sys 23:29:43.0289 0x0e30 WdFilter - ok 23:29:43.0336 0x0e30 [ 40C67D1A4891120874767F6E6604D6C5, 4D9DD658566DE711ADF4D6C33FCB31DA351EE050E3ED188664D04526CCAAEEF5 ] WdiServiceHost C:\Windows\system32\wdi.dll 23:29:43.0367 0x0e30 WdiServiceHost - ok 23:29:43.0383 0x0e30 [ 40C67D1A4891120874767F6E6604D6C5, 4D9DD658566DE711ADF4D6C33FCB31DA351EE050E3ED188664D04526CCAAEEF5 ] WdiSystemHost C:\Windows\system32\wdi.dll 23:29:43.0399 0x0e30 WdiSystemHost - ok 23:29:43.0430 0x0e30 [ 6CC1BB8F6851A262E2E824F0E92D5EEF, 45A88A984179BBA38C1F4434C4D6C2823C1FE6AFBE8CB0F656DAE0092D1D5611 ] WdNisDrv C:\Windows\system32\Drivers\WdNisDrv.sys 23:29:43.0445 0x0e30 WdNisDrv - ok 23:29:43.0461 0x0e30 WdNisSvc - ok 23:29:43.0492 0x0e30 [ 91B18D7A1702ED589E67C6C81052B955, 5D1DA8B86106A28E50BBCCB36527CC130D41201F5BE1D3DC5F1D6F7ECCF807BA ] WebClient C:\Windows\System32\webclnt.dll 23:29:43.0539 0x0e30 WebClient - ok 23:29:43.0586 0x0e30 [ 3274312F263882B51B964329FAF49734, 99A020377ACF0762BE5ECD2D68EB5E1497B9D59963247E725F7F96FB5DF41FAD ] Wecsvc C:\Windows\system32\wecsvc.dll 23:29:43.0695 0x0e30 Wecsvc - ok 23:29:43.0711 0x0e30 [ 7CDD84E0023A0C5C230B06A7965EC65E, 6EC7DC18C76D66CF9A893C3DD20F9BE3ADD76546F9A9BA42CE4F24854709F9D9 ] WEPHOSTSVC C:\Windows\system32\wephostsvc.dll 23:29:43.0727 0x0e30 WEPHOSTSVC - ok 23:29:43.0758 0x0e30 [ 959534ACF085C137D2D094384EF89C45, D029F440789FE170A1C46217C6DE6D78DC0188A5CF33FCCC17FA65D3BC80C2B7 ] wercplsupport C:\Windows\System32\wercplsupport.dll 23:29:43.0914 0x0e30 wercplsupport - ok 23:29:43.0930 0x0e30 [ 82BCCF5FBE47AC9E8CBA2020994DFB3F, EA96C6BD98A701B465D0780EC10BDA92E45FE636D60C1385813AA3B456D8B931 ] WerSvc C:\Windows\System32\WerSvc.dll 23:29:43.0977 0x0e30 WerSvc - ok 23:29:44.0024 0x0e30 [ BFBE1C5F57FE7A885673A1962D5532B7, F0BD05B257108699FE6AB32EF11F927C31932F27062A705B3FEFA4F5B4C0D8C3 ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys 23:29:44.0055 0x0e30 WFPLWFS - ok 23:29:44.0086 0x0e30 [ E06AFE2F94BA7CFA2FE4FD2A449E60E2, 99A81E16366E9E77905D873B0246E4C11B383FE1E99E0E1D9A07FAD4E52EA9E4 ] WiaRpc C:\Windows\System32\wiarpc.dll 23:29:44.0117 0x0e30 WiaRpc - ok 23:29:44.0133 0x0e30 [ 867BCC69ED9C31C501465EB0E8BA9DFA, 678B7FF4D4E8624514301956CDA7FB451159BBFC83FF2E4E5E7DADAE3C7AB2EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys 23:29:44.0164 0x0e30 WIMMount - ok 23:29:44.0164 0x0e30 WinDefend - ok 23:29:44.0305 0x0e30 [ DD079EC8F44DCA3A176B345C6ADEFB66, 6CD9371B83EA23D2181891FAE1DB285BC111A78C35F374E57666ED09860C91A9 ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll 23:29:44.0461 0x0e30 WinHttpAutoProxySvc - ok 23:29:44.0727 0x0e30 [ 9DB490F3E823C5C3C070644B96CB9D59, 81937D0B331E43C7C61514E60B3AD51370C5201F7B4D12F8534840D91EDC32DD ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 23:29:44.0774 0x0e30 Winmgmt - ok 23:29:45.0305 0x0e30 [ C8D6344BDE2691A196E61C0D3372EAB7, FF8EB79D8A7E298343C22B83276FF68293D08A9DA438BB22600BEFC4CA93A91D ] WinRM C:\Windows\system32\WsmSvc.dll 23:29:45.0461 0x0e30 Suspicious file ( Forged ): C:\Windows\system32\WsmSvc.dll. Real md5: C8D6344BDE2691A196E61C0D3372EAB7, sha256: FF8EB79D8A7E298343C22B83276FF68293D08A9DA438BB22600BEFC4CA93A91D, fake md5: 9CE162EB9057CF079736F4DD00FC0D6C, fake sha256: 412C34557866D2A3B3CDAFA5A03B87C01AACF75E349802E511098B20137028D9 23:29:45.0461 0x0e30 WinRM - detected ForgedFile.Multi.Generic ( 1 ) 23:29:45.0461 0x0e30 Object is SCO, delete is not allowed 23:29:45.0461 0x0e30 WinRM ( ForgedFile.Multi.Generic ) - warning 23:29:45.0461 0x0e30 Force sending object to P2P due to detect: WinRM 23:29:45.0508 0x0e30 Object send P2P result: false 23:29:45.0899 0x0e30 [ 3F5EF31C6AA204B099EE76497DF80A26, CBE648A4E7E1D98A3D8C72582C1CB3C2FD2329EAA24EE4DCAD271AAA6F4D82CE ] WlanSvc C:\Windows\System32\wlansvc.dll 23:29:46.0008 0x0e30 WlanSvc - ok 23:29:46.0274 0x0e30 [ 5F56C0DE776C7AE43AF749845BFAA1EF, 837993C5853B7E682C7FB8401B7F5D951FFD15E5659EBB1B01DC3F5719ACEE19 ] wlidsvc C:\Windows\system32\wlidsvc.dll 23:29:46.0336 0x0e30 wlidsvc - ok 23:29:46.0555 0x0e30 [ 2834D9D3B4F554A39C72F00EA3F0E128, D10124343C67FE9A0B711AD569BB8080495FCEA0ECEF9AC3F3FBD6865F436A44 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys 23:29:46.0617 0x0e30 WmiAcpi - ok 23:29:46.0727 0x0e30 [ 7AFAC828F52D62F304A911EC32F42EEE, 4EDCF4149069413A166169F2E23F7505F47B39B7EC319E1EF6D2C46CD140AA24 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 23:29:46.0852 0x0e30 wmiApSrv - ok 23:29:46.0930 0x0e30 WMPNetworkSvc - ok 23:29:46.0992 0x0e30 [ 7FC5667DF73D4B04AA457CC3A4180E09, CB7B014945DCA16B6D120DBE0E5876C4C867A4ACD3C3536AEADC14B908613D4E ] Wof C:\Windows\system32\drivers\Wof.sys 23:29:47.0039 0x0e30 Wof - ok 23:29:47.0352 0x0e30 [ 61BF52E9FFAB27A0B6D621BE26088373, 81291D52C381360E69D51E7DEB05CFAC651A7E9EF781CA23062C0583D0C94708 ] workfolderssvc C:\Windows\system32\workfolderssvc.dll 23:29:47.0508 0x0e30 workfolderssvc - ok 23:29:47.0524 0x0e30 [ 182561A14F2E93E81E66FE3700D17A5A, FB9A06058A8BCCEDCDC5BF8899D9B2FBA5752C262C5FC6D2B8338884F3303D12 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys 23:29:47.0571 0x0e30 wpcfltr - ok 23:29:47.0649 0x0e30 [ 4E6A0F60DA7EF050D3D26417CD4D24E9, E6B3BFB007B641D41F8532ED086F92CB3D86E210023DBFAA9AD8152A9FD33CCA ] WPCSvc C:\Windows\System32\wpcsvc.dll 23:29:47.0742 0x0e30 WPCSvc - ok 23:29:47.0774 0x0e30 [ 618A19EB31ECA7B7F2AA0207BAF598A5, CB18CF9B781EAB3D775F8201F294A7135E058D6C963D2CC759DCA14D95EED538 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 23:29:47.0867 0x0e30 WPDBusEnum - ok 23:29:47.0946 0x0e30 [ 9F2904B55F6CECCD1A8D986B5CE2609A, E19ED4DD3CEF3A22C058FC324824604FB3FC98A029C94E6C2A3389F938D680B6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys 23:29:47.0992 0x0e30 WpdUpFltr - ok 23:29:48.0024 0x0e30 [ AE072B0339D0A18E455DC21666CAD572, AB1DAEA25E2C7AD610818D4B4783F6D4190D85EBB3963BBAD410E8CEA7899EDB ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 23:29:48.0086 0x0e30 ws2ifsl - ok 23:29:48.0133 0x0e30 [ 9654DE19551093CD73874281E1573C94, 5E3513EC0CB180D90904BE8970AB64A4434279E8C467AE2CF693254E47B1D11E ] wscsvc C:\Windows\System32\wscsvc.dll 23:29:48.0242 0x0e30 wscsvc - ok 23:29:48.0258 0x0e30 WSearch - ok 23:29:48.0899 0x0e30 [ 95B6670E6933E1DEE19686C55BE709A0, 4B9EB8F1712B7959A71F6DA445D29BD09B25EEFC6B30D736EFE30163D79B233E ] WSService C:\Windows\System32\WSService.dll 23:29:49.0118 0x0e30 WSService - ok 23:29:49.0821 0x0e30 [ D24002EB2F4A8A04897703067E81CC5D, 03806198D26DD7BA3E27EFE0911B49E5B48CAD8A05EC4F56AF45CF1E3FAD6916 ] wuauserv C:\Windows\system32\wuaueng.dll 23:29:49.0977 0x0e30 Suspicious file ( Forged ): C:\Windows\system32\wuaueng.dll. Real md5: D24002EB2F4A8A04897703067E81CC5D, sha256: 03806198D26DD7BA3E27EFE0911B49E5B48CAD8A05EC4F56AF45CF1E3FAD6916, fake md5: 9FDD8CD31F3FBA88F050318F32D640E2, fake sha256: BBCAFDA420E11D43BAD5D87D47607F4ADF0D817C1BF86D6389582B56EDD7C246 23:29:49.0977 0x0e30 wuauserv - detected ForgedFile.Multi.Generic ( 1 ) 23:29:49.0977 0x0e30 Object is SCO, delete is not allowed 23:29:49.0977 0x0e30 wuauserv ( ForgedFile.Multi.Generic ) - warning 23:29:50.0008 0x0e30 [ D537815E450A149752C15868392AD1F3, 8788CE493349299DB36E409C8CC3C6EA08301FA492C95D9D556E00BC13A05F13 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 23:29:50.0071 0x0e30 WudfPf - ok 23:29:50.0196 0x0e30 [ 7CCBBCEE408A5DBE3FE47297DB5A6CFC, FB44B65B37B1C1A12C618E16BEF195EF861A87179B9216E43024C671C3AE052C ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys 23:29:50.0289 0x0e30 WUDFRd - ok 23:29:50.0336 0x0e30 [ 7CCBBCEE408A5DBE3FE47297DB5A6CFC, FB44B65B37B1C1A12C618E16BEF195EF861A87179B9216E43024C671C3AE052C ] WUDFSensorLP C:\Windows\system32\DRIVERS\WUDFRd.sys 23:29:50.0352 0x0e30 WUDFSensorLP - ok 23:29:50.0399 0x0e30 [ 9CDC2059A23E3C9B57696178508777E7, B680A2E2EDA5C8C6A547E7D9B2F2F8E6407C3EA0A01B82A4B88D48A27913A597 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 23:29:50.0493 0x0e30 wudfsvc - ok 23:29:50.0743 0x0e30 [ 2FA9794CA36147756F3FDFD6CA29B46F, 4B86DC38C2411C281686E9A4E64DA6FB2992E39391371F78E012D6D8BB85123F ] WwanSvc C:\Windows\System32\wwansvc.dll 23:29:50.0883 0x0e30 WwanSvc - ok 23:29:50.0899 0x0e30 ================ Scan global =============================== 23:29:51.0024 0x0e30 [ C89780A6F58D113C28A96D85D1261DC5, 185114F33A60916C7904E4A0F278CA43258454343E614F01F0DAFA98BAC981B1 ] C:\Windows\system32\basesrv.dll 23:29:51.0243 0x0e30 [ 00DD4D2ACC2E72155A8AAA82018BEC0D, 9D7CA68B4A81240477FCC85A3CC11EF986093F9D6228A6C5AC608EDAD664068C ] C:\Windows\system32\winsrv.dll 23:29:51.0321 0x0e30 [ 9C1833ABD62876856836C5AE55C7CE86, 0A21E2C8B2FF3B0438C86DA7151A548F9C6F5C62CD402CBBEDB435994C8508F1 ] C:\Windows\system32\sxssrv.dll 23:29:51.0446 0x0e30 [ 067CB90C277DB4A737D5DEABA3055972, C681BF013170F2D92A3FC4D783FC3F200CDC0C8173373B7ECC27FCF32A03CCBD ] C:\Windows\system32\services.exe 23:29:51.0508 0x0e30 [ Global ] - ok 23:29:51.0508 0x0e30 ================ Scan MBR ================================== 23:29:51.0540 0x0e30 [ E88331828268C73B249C39A69DF123DD ] \Device\Harddisk0\DR0 23:29:52.0149 0x0e30 \Device\Harddisk0\DR0 - ok 23:29:52.0149 0x0e30 ================ Scan VBR ================================== 23:29:52.0165 0x0e30 [ 4221AA4C65A079263E1DEE8C40987EEC ] \Device\Harddisk0\DR0\Partition1 23:29:52.0211 0x0e30 \Device\Harddisk0\DR0\Partition1 - ok 23:29:52.0243 0x0e30 [ 58915D7089616360A2F7419F71FEC062 ] \Device\Harddisk0\DR0\Partition2 23:29:52.0274 0x0e30 \Device\Harddisk0\DR0\Partition2 - ok 23:29:52.0290 0x0e30 [ 38D4D3D267359B2CF4673554E6C8E652 ] \Device\Harddisk0\DR0\Partition3 23:29:52.0290 0x0e30 \Device\Harddisk0\DR0\Partition3 - ok 23:29:52.0336 0x0e30 [ 67150389500E2600FF4276CB89CDCC93 ] \Device\Harddisk0\DR0\Partition4 23:29:52.0430 0x0e30 \Device\Harddisk0\DR0\Partition4 - ok 23:29:52.0430 0x0e30 ================ Scan generic autorun ====================== 23:29:52.0508 0x0e30 [ 28062B17191C9450BF6C6C3EF8C7EB27, 4859C5708DFD119021F7B7FFB38F0B316675E1E4D5D51A10D4265F712CF8CDB6 ] C:\Windows\system32\igfxtray.exe 23:29:52.0555 0x0e30 IgfxTray - ok 23:29:52.0711 0x0e30 [ 28FC280487F0BAAE5E8119257C4EEF8C, F574BC70B79B77912FC683B3EB0BE6929E7758284ED5B47008E18B0E4A4A09FD ] C:\Windows\system32\hkcmd.exe 23:29:52.0743 0x0e30 HotKeysCmds - ok 23:29:52.0852 0x0e30 [ F29BEA821C753E4F00177690F70CDC13, 0EDB40F4A4C23553C0288E6E3AD65E7B523F6764C87C6C36C3ECB0C1940C5176 ] C:\Windows\system32\igfxpers.exe 23:29:52.0899 0x0e30 Persistence - ok 23:29:52.0899 0x0e30 SynTPEnh - ok 23:29:53.0290 0x0e30 [ 2FE68C938A006BA18EA3F6DB3F26F943, ED95B3C8223FCCEC63A4006317A214619EF518C4ED1C18644CC737A35F35CD2B ] C:\Program Files\Bitdefender\Bitdefender\bdagent.exe 23:29:53.0368 0x0e30 Bdagent - ok 23:29:53.0430 0x0e30 [ 78F3E73A8F850D35F3659E406CB5FA01, 16CD87FB103995A17AD805AE49997E8C5DD72187354AF6488EFA09C7F2FBA070 ] C:\Program Files\Shield\shdtray.exe 23:29:53.0461 0x0e30 Shield - ok 23:29:53.0711 0x0e30 [ DD79A6B15C2F28DE98DF4852AAF6B13B, 0F7E9023E0BA4B40E2DE9A9FA34E85FEAF72B93049AAB3E1D73AD046BB113E05 ] C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe 23:29:53.0743 0x0e30 NCPluginUpdater - ok 23:29:53.0790 0x0e30 [ 17FCC923211A74C0A73321D9F16EEA4C, 643EF0982F071AABC39ABF01CD04A55249B09F2BA5543B018FDE00D0B59882AE ] C:\Program Files\Bitdefender\Bitdefender\pmbxag.exe 23:29:53.0852 0x0e30 Agent Portfela Bitdefender - ok 23:29:53.0930 0x0e30 [ B4C91BAB60DA2B52AA2CFBF428B5DAD9, 1A2272882B814D085D3E91654603A1DFF66A5A450DEAF9C5B3701C54A2231766 ] C:\Program Files\Bitdefender\Bitdefender\pwdmanui.exe 23:29:53.0977 0x0e30 Portfel Bitdefender - ok 23:29:54.0212 0x0e30 [ 10273EAAC177B75F0ABFA995489F15DF, 61F53D4383893066C316B84F4F87524A20F4C8931196C91B3E583C74EEDD3C99 ] C:\Program Files\Bitdefender\Bitdefender\antispam32\bdapppassmgr.exe 23:29:54.0352 0x0e30 Agent aplikacji Portfel Bitdefender - ok 23:29:54.0977 0x0e30 AV detected via SS2: Bitdefender Antywirus, C:\Program Files\Bitdefender\Bitdefender\wscfix.exe ( 17.20.0.873 ), 0x41000 ( enabled : updated ) 23:29:55.0008 0x0e30 AV detected via SS2: Windows Defender, C:\Program Files\Windows Defender\MSASCui.exe ( 4.5.218.0 ), 0x60100 ( disabled : updated ) 23:29:55.0008 0x0e30 FW detected via SS2: Bitdefender Zapora sieciowa, C:\Program Files\Bitdefender\Bitdefender\wscfix.exe ( 17.20.0.873 ), 0x41010 ( enabled ) 23:29:55.0008 0x0e30 ============================================================ 23:29:55.0008 0x0e30 Scan finished 23:29:55.0024 0x0e30 ============================================================ 23:29:55.0040 0x0e90 Detected object count: 13 23:29:55.0040 0x0e90 Actual detected object count: 13 23:32:43.0464 0x0e90 Appinfo ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0464 0x0e90 Appinfo ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0464 0x0e90 BrokerInfrastructure ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0464 0x0e90 BrokerInfrastructure ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0464 0x0e90 CNG ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0464 0x0e90 CNG ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 iphlpsvc ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 iphlpsvc ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 KSecPkg ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 KSecPkg ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 PrintNotify ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 PrintNotify ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 ShieldClientService ( UnsignedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 ShieldClientService ( UnsignedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 SystemEventsBroker ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 SystemEventsBroker ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 Tcpip ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 Tcpip ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 TCPIP6 ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 TCPIP6 ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 USBSTOR ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 USBSTOR ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 WinRM ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 WinRM ( ForgedFile.Multi.Generic ) - User select action: Skip 23:32:43.0479 0x0e90 wuauserv ( ForgedFile.Multi.Generic ) - skipped by user 23:32:43.0479 0x0e90 wuauserv ( ForgedFile.Multi.Generic ) - User select action: Skip