Phishing y un secuestro semiresuelto, el problema lleva meses! Ayuda porfavor

Hola! Primero que nada, Saludos a toda la comunidad, a los moderadores y al ángel que espero me pueda ayudar.

Les platico mi caso: Hace algunos meses mis hijos instalaron algún juego o programa en mi Laptop de trabajo, de inmediato detecté que algo había mal en ella, después de pasar varios antivirus online se detectó que se descargó en el sistema un Trojano muy agresivo llamado Pitou, que a su vez instaló otras cosas peores, keyloggers y demás virus, incluso uno que comenzó a encriptar los archivos de mi PC a la vez de que me mandaban un mail a mi correo, pidiendo que pagara por los archivos secuestrados (Ransomware), afortunadamente tenía respaldo de mis archivos y tuve que restablecerlos, siguiendo estas guías logré eliminar la mayoría del malware, las dejo por acá por si a alguien le son de utilidad:

[How to Remove Trojan.Pitou] (How to Remove Trojan.Pitou)

Retire Pitou Troya y Bootkit por completo de su PC - Cómo, Foro de Tecnología y Seguridad PC

En estas guías aparece que el troyano se instala en el MBR (Master Boot Record) por lo que seguro la desinfección que hice no funcionó del todo o algo hice mal.

Después de la limpieza todo volvió a funcionar con normalidad, pero tuve que restablecer Windows sin borrar mis archivos porque en modo seguro parecía que todos los malwares ya habían sido eliminados.

También había un problema recurrente con la WIFI (se desconectaba continuamente la red y en los browsers me salía un mensaje como ERR: Network has changed o algo así o que la red no era segura, y me desconectaba el wifi hasta que lo conectara manualmente cada 5, 10, 15 min y otras veces nunca y todo normal) y asumí que la razón era otra, eventualmente se solucionó con algo que hice posiblemente relacionado con los comandos sfc / scanow y dism que por lo que entiendo escanean archivos corruptos, y se descargan de la nube los archivos del sistema a su forma original y como normalmente estoy conectado por Ethernet y este problema sólo ocurre cuando estoy conectado por la via inalámbrica, podría no darme cuenta de lo seguido que ocurría.

A lo largo de los meses posteriores, noté que el uso del disco se disparaba de 20% a 50% y luego hasta el 100% pero no le presté atención porque era un problema esporádico. Después el problema fue recurrente y el uso de disco se iba al 100% en toda ocasión pero el sistema seguía utilizable, hasta que ya era tan lento que no se podía ni escanear y lo adjudiqué a las instalaciones de Windows update y al Windows modules installer que consumían todos los recursos y no instalaban nada y se quedaban descargando e instalando en bucle. hice una reparación de Windows update con los mismos comandos y otros que encontré en foros, finalmente tuve que volver a cargar Windows con un Punto de Restauración anterior porque el sistema quedó inutilizado y funcionó los problemas se fueron, aclaro que con 3 antivirus; 2 online (ESET Online y Panda Online y el AVG instalado en PC no se detectó nada en modo a prueba de fallos.

Volví a instalar Chrome y de ahí craso error… Me salen mensajes de que la conexión no es segura, avisos de redireccionamiento, desconexiones de la WIFI, etc.

Ahora estoy convencido de que el o los bichos han vuelto y lo he comprobado porque ambos problemas volvieron y que tiene algo que ver con que desinstalé AVG Secure Browser (una versión de AVG Antivirus de Chrome) y haber vuelto a instalar Chrome normal. Al Desinstalar ambos el uso de disco disminuyó a la normalidad, pero volvió el problema de la WIFI.

Por último les comento que pensé que eran problemas de Windows y no sospechaba que podría seguir infectado porque ningún antivirus de los que son online detectaron nada en modo a prueba de fallos, pero sospecho que alguna directriz en el registro se pudo quedar y al momento de reinstalar el Chrome se volvió a montar algún bicho, por cierto, Panda Online ya lleva como 7 horas escaneando y se quedó trabado en bucle en el 54% ya esto es un calvario pero no he querido formatear completo aunque a veces pienso que ya es la última solución, tengo millones de archivos, juegos, música etc. que tomarían días y hasta semanas de instalar y dejar a tono.

De antemano gracias!!! ayúdenme pleaseee!

1 me gusta

Hola buenas @Miguel_Castillo1 foro. Al ser nuevo te recomiendo que te leas las políticas de este. No porque hayas hecho nada mal, sino para saber más acerca del funcionamiento de este.

Estas fuentes que has utilizado y sus respectivas herramientas no tienen muy buena reputación :-1:, no son fiables, y un largo etc de cosas :-1: malas podría decir.

Puede… es una posibilidad…

Cancela ese análisis.

Bien dicho todo lo anterior. Haremos esto:

Lo que debemos hacer es matar al bicho que está en tu máquina. Pero primero de todo y MUY IMPORTANTE desconecta todos tus otros dispositivos que tengas en la Red, absolutamente todos. Déjala solo con esta máquina conectada.

Y ni se te ocurra conectar ningún dispositivo externo como USBs, discos duros externos, NAS, SAN… pues es MUY PERO QUE MUY PROBABLE DE QUE TAMBIÉN PUEDA CIFRAR TODOS LOS DATOS QUE TENGAS ALLÍ.

:one: EN BUSCA / ELIMINACIÓN DE MALWARE

Por favor, descarga todo el software de los enlaces que pongo/de sus respectivos manuales.

Ahora ejecutarás una serie de herramientas respetando el orden los pasos con todos los programas cerrados incluidos los navegadores.

Inicia de nuevo el equipo desde el :arrow_forward: Modo Seguro – con funciones de Red, de Windows. Si no funcionasen los métodos que se explican en el anterior post, prueba estos otros. Más concretamente, primero el 3 (Seleccionando Red en lugar de Mínimo) y si no el 2 (también Red).

Una vez iniciado en este modo, empiezas haciendo todos los pasos que te pondré a continuación.

P.D.: Si el quipo no te arrancase en Modo seguro (cosa que puede pasar), me lo dices e intentaremos arreglar el sistema para que arranque en Modo Seguro. Pues hay malwares que ya se encargaran de que no puedas iniciar en Modo Seguro.

  1. Descarga y ejecuta RKill, más concretamente debes de descargar la que está renombrada bajo el nombre de iExplore.exe. Para evitar el bloqueo de posibles malwares que pueda haber en tu equipo. Una vez que esta haya sido ejecutada, es muy importante no reiniciar el sistema hasta que te lo solicite yo o alguno de los programas de desinfección de los que estemos utilizando.

Me explico, por ejemplo: has iniciado la máquina en Modo Seguro con funciones de Red, has ejecutado Rkill y seguidamente realizas un Análisis con Malwarebytes. Este te detecta infecciones y te pide reiniciar la máquina para poder finalizar exitosamente su desinfección. Seguidamente, yo te he indicado que ejecutes por ejemplo el ESET Online Scanner, pues bien como no hemos acabado de desinfectar la máquina y estamos realizando el proceso de desinfección, y has tenido que reiniciar, ya que te lo ha pedido Malwarebytes pues debes de ejecutar nuevamente Rkill y después acto seguido el ESET ONline.

¿Me entiendes?

Si por ejemplo, incluso con Rkill, Malwarebytes AntiMalware o la herramienta que sea que te he pedido que utilices, ves que se bloquea y que al cabo de un buen rato no responde. Pues pasas a la siguiente y me informas de ello. Y así con todas. ¿OK? ¿Se entiende?

Realizas lo siguiente:

  1. Manual Malwarebytes Anti-Rootkit Beta sigues las instrucciones de su manual y me traes sus correspondientes Informes de análisis: Mbar-log.txt y System-log.txt tal como se indica en su manual.

  2. Descarga, instala y ejecuta TDSKiller de acuerdo a su Manual TDSKiller. Marca todas las casillas (Loaded Modules, Verify file digital signatures y Detect TDLFS file system). Sí te pide reiniciar lo haces, ejecutas de nuevo la herramienta y al marcar nuevamente las casillas que te he dicho, ya te dejara analizar.

NOTA IMPORTANTE

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo:

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado.
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA (programas/software/complementos/extensiones del navegador…).
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…).
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

EN TU PRÓXIMA RESPUESTA

  • Respondes a las preguntas que te haya realizado.
  • Traes los reportes de Malwarebytes Anti-Rootkit y TDSKiller.
  • Comentas el estado en general del ordenador respecto al problema inicial planteado.

Salu2.

Estimado Marr0n:

Seguí los pasos que me indicaste: Inicié Windows en Modo a Prueba de Fallos con Red; inicié Rkill descargándolo de la liga que me diste guardándolo en el escritorio (por cierto en la liga sale como Rkill.exe, pero no hay nada como Iexplore.exe, lo corrí una vez como Rkill.exe y se colgó así que la renombré y corrí renombrada manualmente por mi):

Primer Reporte de Rkill (el que se colgó)

Performing miscellaneous checks:

  • Windows Defender Disabled

    [HKLM\SOFTWARE\Microsoft\Windows Defender] “DisableAntiSpyware” = dword:00000001

Es decir, no se cierra o me avisa si ya acabó pero creo que ya había terminado de analizar, no lo sé, se me generó un .TXT automáticamente en el escritorio:

Rkill 2.9.1 by Lawrence Abrams (Grinler)

Copyright 2008-2022 BleepingComputer.com More Information about Rkill can be found at this link: RKill - What it does and What it Doesn't - A brief introduction to the program - Anti-Virus, Anti-Malware, and Privacy Software

Program started at: 12/02/2022 01:44:20 AM in x64 mode. (Safe Mode) Windows Version: Windows 10 Pro

Checking for Windows services to stop:

  • No malware services found to stop.

Checking for processes to terminate:

  • No malware processes found to kill.

Checking Registry for malware related settings:

  • No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

  • Windows Defender Disabled

    [HKLM\SOFTWARE\Microsoft\Windows Defender] “DisableAntiSpyware” = dword:00000001

Segundo reporte de Rkill renombrado como Iexplore.exe: (ésta vez corrió sin problemas y salieron otras cosas)

Rkill 2.9.1 by Lawrence Abrams (Grinler)

Copyright 2008-2022 BleepingComputer.com More Information about Rkill can be found at this link: RKill - What it does and What it Doesn't - A brief introduction to the program - Anti-Virus, Anti-Malware, and Privacy Software

Program started at: 12/02/2022 02:24:50 AM in x64 mode. (Safe Mode) Windows Version: Windows 10 Pro

Checking for Windows services to stop:

  • No malware services found to stop.

Checking for processes to terminate:

  • No malware processes found to kill.

Checking Registry for malware related settings:

  • No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

  • Windows Defender Disabled

    [HKLM\SOFTWARE\Microsoft\Windows Defender] “DisableAntiSpyware” = dword:00000001

Searching for Missing Digital Signatures:

  • No issues found.

Checking HOSTS File:

  • HOSTS file entries found:

127.0.0.1 3dns.adobe.com 127.0.0.1 3dns-1.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-4.adobe.com 127.0.0.1 3dns-5.adobe.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate.wip1.adobe.com 127.0.0.1 activate.wip2.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 activate.wip4.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-1.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 adobe-dns-4.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 ereg.adobe.com

20 out of 136 HOSTS entries shown. Please review HOSTS file for further entries.

Program finished at: 12/02/2022 02:25:10 AM Execution time: 0 hours(s), 0 minute(s), and 19 seconds(s)

Estoy tratando de ser lo más descriptivo posible.

A Continuación traté de descargar MBAR desde Forospyware con la liga que me mandaste, pero no pude, hacia click en el botón y nunca abría la descarga pausé el adblock para ver si ya podía pero nada, como no pude hacerlo desde forospyware (por cierto, navegando la página de forospyware me encontré con un post de que Forospyware fue hackeado ForoSpyware Hackeado :( | InfoSpyware realmente no sé si ese post es actual) fuí a la página oficial de Malwarebytes, pero no lo encontré, luego recordé que en una ocasión anterior lo había descargado así que volví a poner el instalador en el escritorio, lo corrí como admin y lo actualicé, luego escanee y aquí está el reporte:

mbar-log.txt: (son 3 porque al parecer tengo 3 particiones, ni sabía)

Malwarebytes Anti-Rootkit BETA 1.10.3.1001

Database version: main: v2017.10.25.11 rootkit: v2017.10.14.01

Windows 10 x64 NTFS (Safe Mode/Networking) Internet Explorer 11.789.19041.0 co :: CIROCCO-LAP [administrator]

19/11/2022 07:25:51 a. m. mbar-log-2022-11-19 (07-25-51).txt

Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 460851 Time elapsed: 41 minute(s), 28 second(s)

Memory Processes Detected: 0 (No malicious items detected)

Memory Modules Detected: 0 (No malicious items detected)

Registry Keys Detected: 0 (No malicious items detected)

Registry Values Detected: 0 (No malicious items detected)

Registry Data Items Detected: 0 (No malicious items detected)

Folders Detected: 0 (No malicious items detected)

Files Detected: 0 (No malicious items detected)

Physical Sectors Detected: 0 (No malicious items detected)

(end)

Malwarebytes Anti-Rootkit BETA 1.10.3.1001

Database version: main: v2022.11.21.03 rootkit: v2022.11.21.03

Windows 10 x64 NTFS Internet Explorer 11.789.19041.0 co :: CIROCCO-LAP [administrator]

21/11/2022 04:20:22 a. m. mbar-log-2022-11-21 (04-20-22).txt

Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 298745 Time elapsed: 1 hour(s), 48 minute(s), 1 second(s)

Memory Processes Detected: 0 (No malicious items detected)

Memory Modules Detected: 0 (No malicious items detected)

Registry Keys Detected: 0 (No malicious items detected)

Registry Values Detected: 0 (No malicious items detected)

Registry Data Items Detected: 0 (No malicious items detected)

Folders Detected: 0 (No malicious items detected)

Files Detected: 0 (No malicious items detected)

Physical Sectors Detected: 0 (No malicious items detected)

(end)

Malwarebytes Anti-Rootkit BETA 1.10.3.1001

Database version: main: v2022.12.02.01 rootkit: v2022.12.02.01

Windows 10 x64 NTFS (Safe Mode/Networking) Internet Explorer 11.789.19041.0 co :: CIROCCO-LAP [administrator]

02/12/2022 02:43:53 a. m. mbar-log-2022-12-02 (02-43-53).txt

Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 297826 Time elapsed: 1 hour(s), 27 minute(s), 55 second(s)

Memory Processes Detected: 0 (No malicious items detected)

Memory Modules Detected: 0 (No malicious items detected)

Registry Keys Detected: 0 (No malicious items detected)

Registry Values Detected: 0 (No malicious items detected)

Registry Data Items Detected: 0 (No malicious items detected)

Folders Detected: 0 (No malicious items detected)

Files Detected: 0 (No malicious items detected)

Physical Sectors Detected: 0 (No malicious items detected)

(end)

System.log.txt:


Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 10.0.9200 Windows 10 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 11.789.19041.0

File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.794000 GHz Memory total: 8490455040, free: 6875521024

No address found

Initializing… Driver version: 4.3.0.15 ------------ Kernel report ------------ 11/19/2022 07:25:42 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\WppRecorder.sys \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\system32\drivers\SgrmAgent.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\IntelTA.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\isapnp.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\evbda.sys \SystemRoot\System32\drivers\pcmcia.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\intelide.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\sdbus.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\vmbus.sys \SystemRoot\System32\drivers\NDIS.SYS \SystemRoot\System32\drivers\NETIO.SYS \SystemRoot\System32\drivers\hvsocket.sys \SystemRoot\System32\drivers\vmbkmcl.sys \SystemRoot\System32\drivers\winhv.sys \SystemRoot\System32\drivers\vpci.sys \SystemRoot\System32\drivers\bxvbda.sys \SystemRoot\System32\drivers\nvraid.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\system32\drivers\urscx01000.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\iaStorV.sys \SystemRoot\System32\drivers\vsmraid.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\3ware.sys \SystemRoot\System32\drivers\amdsata.sys \SystemRoot\System32\drivers\amdxata.sys \SystemRoot\System32\drivers\amdsbs.sys \SystemRoot\System32\drivers\arcsas.sys \SystemRoot\System32\drivers\ItSas35i.sys \SystemRoot\System32\drivers\lsi_sas.sys \SystemRoot\System32\drivers\lsi_sas2i.sys \SystemRoot\System32\drivers\lsi_sas3i.sys \SystemRoot\System32\drivers\lsi_sss.sys \SystemRoot\System32\drivers\megasas.sys \SystemRoot\System32\drivers\MegaSas2i.sys \SystemRoot\System32\drivers\megasas35i.sys \SystemRoot\System32\drivers\megasr.sys \SystemRoot\System32\drivers\mvumis.sys \SystemRoot\System32\drivers\nvstor.sys \SystemRoot\System32\drivers\percsas2i.sys \SystemRoot\System32\drivers\percsas3i.sys \SystemRoot\System32\drivers\SiSRaid2.sys \SystemRoot\System32\drivers\sisraid4.sys \SystemRoot\System32\drivers\vstxraid.sys \SystemRoot\System32\drivers\stexstor.sys \SystemRoot\System32\drivers\cht4sx64.sys \SystemRoot\System32\drivers\iaStorAVC.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\stornvme.sys \SystemRoot\System32\drivers\iaStorAC.sys \SystemRoot\system32\DRIVERS\bhtsddr.sys \SystemRoot\System32\drivers\ADP80XX.SYS \SystemRoot\System32\drivers\HpSAMD.sys \SystemRoot\System32\drivers\SmartSAMD.sys \SystemRoot\System32\drivers\nvdimm.sys \SystemRoot\System32\drivers\EhStorTcgDrv.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\System32\drivers\storvsc.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\drivers\vmstorfl.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\stdcfltn.sys \SystemRoot\System32\drivers\bttflt.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\System32\drivers\USBSTOR.SYS \SystemRoot\System32\drivers\uaspstor.sys \SystemRoot\System32\drivers\storufs.sys \SystemRoot\System32\drivers\sdstor.sys \SystemRoot\System32\drivers\scmbus.sys \SystemRoot\System32\drivers\sbp2port.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\system32\DRIVERS\ramdisk.sys \SystemRoot\System32\drivers\pmem.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\system32\drivers\avgArDisk.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\system32\drivers\avgSP.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_fc93ae411c02f280\BasicDisplay.sys \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_ed345fdc37d65139\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\CimFS.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\avgRdr2.sys \SystemRoot\system32\drivers\afunix.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\System32\drivers\ndiscap.sys \SystemRoot\system32\drivers\avgNetHub.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys \SystemRoot\System32\drivers\CAD.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\TeeDriverW8x64.sys \SystemRoot\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_63a4db11c926c9ab\e1d68x64.sys \SystemRoot\System32\drivers\Netwbw02.sys \SystemRoot\System32\drivers\vwifibus.sys \SystemRoot\System32\drivers\i8042prt.sys \SystemRoot\system32\drivers\avgKbd.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\system32\DRIVERS\Apfiltr.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\DRIVERS\ST_Accel.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\DellRbtn.sys \SystemRoot\System32\drivers\mshidkmdf.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\IntcDAud.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\drivers\dump_iaStorAC.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\cdd.dll \SystemRoot\System32\drivers\WinUSB.SYS \SystemRoot\System32\drivers\WUDFRd.sys \SystemRoot\System32\DRIVERS\scfilter.sys \SystemRoot\system32\drivers\ndisuio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\drivers\msquic.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\System32\drivers\vwifimp.sys ??\C:\WINDOWS\system32\drivers\mbamchameleon.sys ??\C:\WINDOWS\system32\drivers\1262C2CE.sys ----------- End ----------- Done!

Scan started Database versions: main: v2017.10.25.11 rootkit: v2017.10.14.01

<<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffff9604eab31060, DeviceName: \Device\Harddisk0\DR0, DriverName: \Driver\disk
--------- Disk Stack ------ DevicePointer: 0xffff9604eab1ec20, DeviceName: Unknown, DriverName: \Driver\avgArDisk
DevicePointer: 0xffff9604eab308d0, DeviceName: Unknown, DriverName: \Driver\partmgr
DevicePointer: 0xffff9604eab31060, DeviceName: \Device\Harddisk0\DR0, DriverName: \Driver\disk
DevicePointer: 0xffff9604eab1cc20, DeviceName: Unknown, DriverName: \Driver\stdcfltn
DevicePointer: 0xffff9604ea84ad90, DeviceName: Unknown, DriverName: \Driver\ACPI
DevicePointer: 0xffff9604ea7df9a0, DeviceName: Unknown, DriverName: \Driver\ACPI
DevicePointer: 0xffff9604ea8a9050, DeviceName: \Device\00000037, DriverName: \Driver\iaStorAC
------------ End ---------- Alternate DeviceName: Unknown, DriverName: \Driver\partmgr
Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers… Done! Drive 0 This is a System drive Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: 550A084F

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63  Numsec = 80262
Partition is not bootable

Partition 1 type is Other (0x27)
Partition is ACTIVE.
Partition starts at LBA: 81920  Numsec = 24604672
Partition is bootable
Partition file system is NTFS

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 24686592  Numsec = 1928835072
Partition is not bootable
Partition file system is NTFS

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0  Numsec = 0
Partition is not bootable

Disk Size: 1000204886016 bytes Sector size: 512 bytes

Done! File “C:\Windows\SYSTEMAPPS\MICROSOFTWINDOWS.CLIENT.CBS_CW5N1H2TXYEWY\TEXTINPUTHOST.EXE” is sparse (flags = 32768) Scan finished

Removal queue found; removal started Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\MBR-0-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-0-63-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-1-81920-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-2-24686592-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\MBR-0-r.mbam… Removal finished

Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 10.0.9200 Windows 10 x64

Account is Administrative

Internet Explorer version: 11.789.19041.0

File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.794000 GHz Memory total: 8490455040, free: 3067064320

Downloaded database version: v2022.11.21.03 Downloaded database version: v2022.11.21.03 Downloaded database version: v2018.01.20.01

Initializing… Driver version: 4.3.0.15 ------------ Kernel report ------------ 11/21/2022 04:19:54 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\WppRecorder.sys \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\system32\drivers\mssecflt.sys \SystemRoot\system32\drivers\SgrmAgent.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\avgElam.sys \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\IntelTA.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\sdbus.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\system32\drivers\urscx01000.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\iaStorAC.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\system32\drivers\avgVmm.sys \SystemRoot\system32\drivers\avgRvrt.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\stdcfltn.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\System32\drivers\USBSTOR.SYS \SystemRoot\System32\drivers\uaspstor.sys \SystemRoot\System32\drivers\sdstor.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\system32\drivers\avgbuniv.sys \SystemRoot\system32\drivers\avgbidsh.sys \SystemRoot\system32\drivers\avgArDisk.sys \SystemRoot\system32\DRIVERS\ibtusb.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\drivers\BTHUSB.sys \SystemRoot\System32\drivers\BTHport.sys \SystemRoot\System32\Drivers\cvusbdrv.sys \SystemRoot\System32\drivers\rfcomm.sys \SystemRoot\System32\drivers\TDI.SYS \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\System32\drivers\BthEnum.sys \SystemRoot\system32\drivers\avgSP.sys \SystemRoot\System32\drivers\bthpan.sys \SystemRoot\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys \SystemRoot\System32\drivers\BthA2dp.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\btampm.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys \SystemRoot\System32\drivers\bthhfenum.sys \SystemRoot\system32\drivers\avgSnx.sys \SystemRoot\System32\drivers\BthHfAud.sys \SystemRoot\system32\drivers\filecrypt.sys \SystemRoot\system32\drivers\tbs.sys \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_fc93ae411c02f280\BasicDisplay.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\system32\drivers\avgMonFlt.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\drivers\Vid.sys \SystemRoot\System32\drivers\winhvr.sys \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys \SystemRoot\system32\drivers\avgKbd.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_ed345fdc37d65139\BasicRender.sys \SystemRoot\System32\drivers\DBUtilDrv2.sys \SystemRoot\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys \SystemRoot\System32\drivers\CAD.sys \SystemRoot\system32\DRIVERS\atikmpag.sys \SystemRoot\system32\DRIVERS\atikmdag.sys \SystemRoot\system32\DRIVERS\igdkmd64.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\TeeDriverW8x64.sys \SystemRoot\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_63a4db11c926c9ab\e1d68x64.sys \SystemRoot\System32\Drivers\usbvideo.sys \SystemRoot\System32\drivers\i8042prt.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\system32\DRIVERS\Apfiltr.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\parport.sys \SystemRoot\system32\DRIVERS\ST_Accel.sys \SystemRoot\System32\drivers\intelppm.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\CmBatt.sys \SystemRoot\System32\drivers\BATTC.SYS \SystemRoot\System32\drivers\DellRbtn.sys \SystemRoot\System32\drivers\mshidkmdf.sys \SystemRoot\System32\drivers\DellInstrumentation.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\system32\drivers\RTDVHD64.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\CimFS.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\avgRdr2.sys \SystemRoot\system32\drivers\afunix.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\System32\drivers\ndiscap.sys \SystemRoot\system32\drivers\avgNetHub.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\drivers\npsvctrig.sys \SystemRoot\System32\drivers\gpuenergydrv.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\drivers\bam.sys \SystemRoot\system32\drivers\avgbidsdriver.sys \SystemRoot\system32\drivers\avgArPot.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\drivers\dump_iaStorAC.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\drivers\monitor.sys \SystemRoot\System32\cdd.dll \SystemRoot\System32\drivers\WinUSB.SYS \SystemRoot\System32\drivers\WUDFRd.sys \SystemRoot\System32\DRIVERS\scfilter.sys \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\wcifs.sys \SystemRoot\system32\drivers\mmcss.sys \SystemRoot\system32\drivers\cldflt.sys \SystemRoot\system32\drivers\storqosflt.sys \SystemRoot\System32\Drivers\MbamChameleon.sys \SystemRoot\system32\drivers\msquic.sys \SystemRoot\system32\drivers\bindflt.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\System32\drivers\EZUSB.sys \SystemRoot\system32\drivers\lltdio.sys \SystemRoot\system32\drivers\mslldp.sys \SystemRoot\system32\drivers\rspndr.sys \SystemRoot\system32\drivers\avgStm.sys \SystemRoot\system32\drivers\ndisuio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\system32\drivers\Ndu.sys \SystemRoot\system32\drivers\peauth.sys ??\C:\WINDOWS\system32\Drivers\SSPORT.sys \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\rassstp.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\NDProxy.sys \SystemRoot\System32\drivers\AgileVpn.sys \SystemRoot\System32\drivers\rasl2tp.sys \SystemRoot\System32\drivers\raspptp.sys \SystemRoot\System32\DRIVERS\raspppoe.sys \SystemRoot\System32\DRIVERS\ndistapi.sys \SystemRoot\System32\drivers\ndiswan.sys \SystemRoot\System32\Drivers\mbamswissarmy.sys \SystemRoot\system32\DRIVERS\mwac.sys ??\C:\WINDOWS\system32\drivers\mbae64.sys \SystemRoot\system32\DRIVERS\farflt.sys ??\C:\WINDOWS\system32\DRIVERS\mbam.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\System32\drivers\Netwbw02.sys \SystemRoot\System32\drivers\vwifibus.sys \SystemRoot\System32\drivers\vwifimp.sys ??\C:\WINDOWS\system32\drivers\35634173.sys ----------- End ----------- Done!

Scan started Database versions: main: v2022.11.21.03 rootkit: v2022.11.21.03

<<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffff9c0488d32060, DeviceName: \Device\Harddisk0\DR0, DriverName: \Driver\disk
--------- Disk Stack ------ DevicePointer: 0xffff9c0488c3f8d0, DeviceName: Unknown, DriverName: \Driver\avgArDisk
DevicePointer: 0xffff9c0488d31850, DeviceName: Unknown, DriverName: \Driver\partmgr
DevicePointer: 0xffff9c0488d32060, DeviceName: \Device\Harddisk0\DR0, DriverName: \Driver\disk
DevicePointer: 0xffff9c0488d1ec60, DeviceName: Unknown, DriverName: \Driver\stdcfltn
DevicePointer: 0xffff9c0472d3a970, DeviceName: Unknown, DriverName: \Driver\ACPI
DevicePointer: 0xffff9c0472e199a0, DeviceName: Unknown, DriverName: \Driver\ACPI
DevicePointer: 0xffff9c0472eef050, DeviceName: \Device\00000037, DriverName: \Driver\iaStorAC
------------ End ---------- Alternate DeviceName: Unknown, DriverName: \Driver\partmgr
Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers… Done! Drive 0 This is a System drive Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: 550A084F

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63  Numsec = 80262
Partition is not bootable

Partition 1 type is Other (0x27)
Partition is ACTIVE.
Partition starts at LBA: 81920  Numsec = 24604672
Partition is bootable
Partition file system is NTFS

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 24686592  Numsec = 1928835072
Partition is not bootable
Partition file system is NTFS

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0  Numsec = 0
Partition is not bootable

Disk Size: 1000204886016 bytes Sector size: 512 bytes

Done! File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System\920e3d1d70447c3c10e69e6df0766568\System.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv759bfb78#\1f5d4944c864278deb61bdcdd201093f\System.ServiceProcess.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\3fc512c4cf717a111e39acefb2cc216c\System.Core.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\b22e42d48a01f8b3e778397c6817b196\SMDiagnostics.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\5fb882c7683a7146ed552a1e37db421a\System.ServiceModel.Internals.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\a35aa313c9d47f4574f98c53c215e3ec\System.Configuration.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\2062ed810929ec0e33254c02b0c61bb4\System.Xml.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\e866c0216a4ad45c5b16d8bd70bd92c7\System.Transactions.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\a3127677749631df61e96a8400ddcb87\System.Runtime.Serialization.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\d06877b5a0df441a8dc4c7b8d95b5d41\System.Numerics.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\e1503878d6648b1b94d533f95ebb9c6f\System.Data.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\68de365664d9a58c56faf83d6ab25333\System.Net.Http.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\96012833bebd5f21714fc508603cda97\System.Management.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\e1cd98a17ff5607f4be9d568f50baf62\System.Xaml.ni.dll” is sparse (flags = 32768) File “C:\Windows\SYSTEMAPPS\MICROSOFTWINDOWS.CLIENT.CBS_CW5N1H2TXYEWY\TEXTINPUTHOST.EXE” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\c2c5caeba5e37e85691cff471f71c4df\WindowsBase.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\20b6becfb89316b50a93b2ffc1329b72\PresentationCore.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\92ebb87728c59675aa663be0b22dd0b1\PresentationFramework.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\0c40eb7afa7d2ecc6715cd91d6efd867\PresentationFramework.Aero2.ni.dll” is sparse (flags = 32768) File “C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\fe4f7fb577b398b290c2d5d25fed0ad8\System.Drawing.ni.dll” is sparse (flags = 32768) File “C:\Users\Administrador\AppData\Local\Microsoft\OneDrive\OneDrive.exe” is sparse (flags = 32768) File “C:\Users\co\AppData\Local\Microsoft\OneDrive\OneDrive.exe” is sparse (flags = 32768) File “C:\ProgramData\Microsoft\Network\Downloader\qmgr.db” is sparse (flags = 32768) File “C:\Windows\System32\config\systemprofile\AppData\Local\DataSharing\Storage\DSTokenDB2.dat” is sparse (flags = 32768) Scan finished

Removal queue found; removal started Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\MBR-0-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-0-63-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-1-81920-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-2-24686592-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\MBR-0-r.mbam… Removal finished

Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 10.0.9200 Windows 10 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 11.789.19041.0

File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.794000 GHz Memory total: 8490455040, free: 5125488640

=======================================


Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 10.0.9200 Windows 10 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 11.789.19041.0

File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.794000 GHz Memory total: 8490455040, free: 5099790336

Downloaded database version: v2022.12.02.01 Downloaded database version: v2022.12.02.01


Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 10.0.9200 Windows 10 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 11.789.19041.0

File system is: NTFS Disk drives: C:\ DRIVE_FIXED CPU speed: 2.794000 GHz Memory total: 8490455040, free: 4958683136

Downloaded database version: v2022.12.02.01 Downloaded database version: v2022.12.02.01 Downloaded database version: v2018.01.20.01

Initializing… Driver version: 4.3.0.15 ------------ Kernel report ------------ 12/02/2022 02:43:45 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kd.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\System32\drivers\CLFS.SYS \SystemRoot\System32\drivers\tm.sys \SystemRoot\system32\PSHED.dll \SystemRoot\system32\BOOTVID.dll \SystemRoot\System32\drivers\FLTMGR.SYS \SystemRoot\System32\drivers\msrpc.sys \SystemRoot\System32\drivers\ksecdd.sys \SystemRoot\System32\drivers\clipsp.sys \SystemRoot\System32\drivers\cmimcext.sys \SystemRoot\System32\drivers\werkernel.sys \SystemRoot\System32\drivers\ntosext.sys \SystemRoot\system32\CI.dll \SystemRoot\System32\drivers\cng.sys \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\WppRecorder.sys \SystemRoot\system32\drivers\SleepStudyHelper.sys \SystemRoot\System32\Drivers\acpiex.sys \SystemRoot\system32\drivers\SgrmAgent.sys \SystemRoot\System32\drivers\ACPI.sys \SystemRoot\System32\drivers\WMILIB.SYS \SystemRoot\System32\drivers\intelpep.sys \SystemRoot\system32\drivers\WindowsTrustedRT.sys \SystemRoot\System32\drivers\IntelTA.sys \SystemRoot\System32\drivers\WindowsTrustedRTProxy.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\drivers\msisadrv.sys \SystemRoot\System32\drivers\isapnp.sys \SystemRoot\System32\drivers\pci.sys \SystemRoot\System32\drivers\vdrvroot.sys \SystemRoot\system32\drivers\ucx01000.sys \SystemRoot\system32\drivers\pdc.sys \SystemRoot\system32\drivers\CEA.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\System32\drivers\evbda.sys \SystemRoot\System32\drivers\pcmcia.sys \SystemRoot\System32\drivers\pciide.sys \SystemRoot\System32\drivers\PCIIDEX.SYS \SystemRoot\System32\drivers\spaceport.sys \SystemRoot\System32\drivers\intelide.sys \SystemRoot\System32\drivers\volmgr.sys \SystemRoot\System32\drivers\sdbus.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\vmbus.sys \SystemRoot\System32\drivers\NDIS.SYS \SystemRoot\System32\drivers\NETIO.SYS \SystemRoot\System32\drivers\hvsocket.sys \SystemRoot\System32\drivers\vmbkmcl.sys \SystemRoot\System32\drivers\winhv.sys \SystemRoot\System32\drivers\vpci.sys \SystemRoot\System32\drivers\bxvbda.sys \SystemRoot\System32\drivers\nvraid.sys \SystemRoot\System32\drivers\CLASSPNP.SYS \SystemRoot\system32\drivers\urscx01000.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\System32\drivers\iaStorV.sys \SystemRoot\System32\drivers\vsmraid.sys \SystemRoot\System32\drivers\storport.sys \SystemRoot\System32\drivers\3ware.sys \SystemRoot\System32\drivers\amdsata.sys \SystemRoot\System32\drivers\amdxata.sys \SystemRoot\System32\drivers\amdsbs.sys \SystemRoot\System32\drivers\arcsas.sys \SystemRoot\System32\drivers\ItSas35i.sys \SystemRoot\System32\drivers\lsi_sas.sys \SystemRoot\System32\drivers\lsi_sas2i.sys \SystemRoot\System32\drivers\lsi_sas3i.sys \SystemRoot\System32\drivers\lsi_sss.sys \SystemRoot\System32\drivers\megasas.sys \SystemRoot\System32\drivers\MegaSas2i.sys \SystemRoot\System32\drivers\megasas35i.sys \SystemRoot\System32\drivers\megasr.sys \SystemRoot\System32\drivers\mvumis.sys \SystemRoot\System32\drivers\nvstor.sys \SystemRoot\System32\drivers\percsas2i.sys \SystemRoot\System32\drivers\percsas3i.sys \SystemRoot\System32\drivers\SiSRaid2.sys \SystemRoot\System32\drivers\sisraid4.sys \SystemRoot\System32\drivers\vstxraid.sys \SystemRoot\System32\drivers\stexstor.sys \SystemRoot\System32\drivers\cht4sx64.sys \SystemRoot\System32\drivers\iaStorAVC.sys \SystemRoot\System32\drivers\atapi.sys \SystemRoot\System32\drivers\ataport.SYS \SystemRoot\System32\drivers\storahci.sys \SystemRoot\System32\drivers\stornvme.sys \SystemRoot\System32\drivers\iaStorAC.sys \SystemRoot\system32\DRIVERS\bhtsddr.sys \SystemRoot\System32\drivers\ADP80XX.SYS \SystemRoot\System32\drivers\HpSAMD.sys \SystemRoot\System32\drivers\SmartSAMD.sys \SystemRoot\System32\drivers\nvdimm.sys \SystemRoot\System32\drivers\EhStorTcgDrv.sys \SystemRoot\System32\drivers\EhStorClass.sys \SystemRoot\System32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\Wof.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\drivers\usbccgp.sys \SystemRoot\System32\drivers\USBD.SYS \SystemRoot\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys \SystemRoot\System32\drivers\usbhub.sys \SystemRoot\System32\drivers\UsbHub3.sys \SystemRoot\System32\drivers\storvsc.sys \SystemRoot\System32\drivers\usbehci.sys \SystemRoot\System32\drivers\USBPORT.SYS \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\System32\drivers\wfplwfs.sys \SystemRoot\System32\drivers\vmstorfl.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\DRIVERS\stdcfltn.sys \SystemRoot\System32\drivers\bttflt.sys \SystemRoot\System32\drivers\volume.sys \SystemRoot\System32\drivers\volsnap.sys \SystemRoot\System32\drivers\USBXHCI.SYS \SystemRoot\System32\drivers\USBSTOR.SYS \SystemRoot\System32\drivers\uaspstor.sys \SystemRoot\System32\drivers\storufs.sys \SystemRoot\System32\drivers\sdstor.sys \SystemRoot\System32\drivers\scmbus.sys \SystemRoot\System32\drivers\sbp2port.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\system32\DRIVERS\ramdisk.sys \SystemRoot\System32\drivers\pmem.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\system32\drivers\iorate.sys \SystemRoot\System32\drivers\disk.sys \SystemRoot\system32\drivers\avgArDisk.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\system32\drivers\avgSP.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_fc93ae411c02f280\BasicDisplay.sys \SystemRoot\System32\DriverStore\FileRepository\basicrender.inf_amd64_ed345fdc37d65139\BasicRender.sys \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\CimFS.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\drivers\avgRdr2.sys \SystemRoot\system32\drivers\afunix.sys \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\drivers\vwififlt.sys \SystemRoot\System32\drivers\pacer.sys \SystemRoot\System32\drivers\ndiscap.sys \SystemRoot\system32\drivers\avgNetHub.sys \SystemRoot\system32\drivers\netbios.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\ahcache.sys \SystemRoot\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys \SystemRoot\System32\drivers\kdnic.sys \SystemRoot\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys \SystemRoot\System32\drivers\CAD.sys \SystemRoot\System32\drivers\HDAudBus.sys \SystemRoot\System32\drivers\portcls.sys \SystemRoot\System32\drivers\drmk.sys \SystemRoot\System32\drivers\ks.sys \SystemRoot\System32\drivers\hidusb.sys \SystemRoot\System32\drivers\HIDCLASS.SYS \SystemRoot\System32\drivers\HIDPARSE.SYS \SystemRoot\System32\drivers\TeeDriverW8x64.sys \SystemRoot\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_63a4db11c926c9ab\e1d68x64.sys \SystemRoot\System32\drivers\Netwbw02.sys \SystemRoot\System32\drivers\vwifibus.sys \SystemRoot\System32\drivers\i8042prt.sys \SystemRoot\system32\drivers\avgKbd.sys \SystemRoot\System32\drivers\kbdclass.sys \SystemRoot\system32\DRIVERS\Apfiltr.sys \SystemRoot\System32\drivers\mouclass.sys \SystemRoot\System32\drivers\cdrom.sys \SystemRoot\system32\DRIVERS\ST_Accel.sys \SystemRoot\System32\drivers\wmiacpi.sys \SystemRoot\System32\drivers\DellRbtn.sys \SystemRoot\System32\drivers\mshidkmdf.sys \SystemRoot\System32\drivers\NdisVirtualBus.sys \SystemRoot\System32\drivers\mssmbios.sys \SystemRoot\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys \SystemRoot\System32\drivers\rdpbus.sys \SystemRoot\System32\drivers\IntcDAud.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\drivers\mouhid.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\Drivers\dump_diskdump.sys \SystemRoot\System32\win32kbase.sys \SystemRoot\System32\drivers\dump_iaStorAC.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\System32\win32kfull.sys \SystemRoot\System32\drivers\dxgmms2.sys \SystemRoot\System32\cdd.dll \SystemRoot\System32\drivers\WinUSB.SYS \SystemRoot\System32\drivers\WUDFRd.sys \SystemRoot\System32\DRIVERS\scfilter.sys \SystemRoot\system32\drivers\ndisuio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\drivers\msquic.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\drivers\condrv.sys \SystemRoot\System32\drivers\vwifimp.sys \SystemRoot\System32\Drivers\mbamswissarmy.sys ??\C:\WINDOWS\system32\drivers\mbamchameleon.sys ??\C:\WINDOWS\system32\drivers\275DD3F6.sys ----------- End ----------- Done!

Scan started Database versions: main: v2022.12.02.01 rootkit: v2022.12.02.01

<<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xffff800d5a120530, DeviceName: \Device\Harddisk0\DR0, DriverName: \Driver\disk
--------- Disk Stack ------ DevicePointer: 0xffff800d473bad20, DeviceName: Unknown, DriverName: \Driver\avgArDisk
DevicePointer: 0xffff800d473c68d0, DeviceName: Unknown, DriverName: \Driver\partmgr
DevicePointer: 0xffff800d5a120530, DeviceName: \Device\Harddisk0\DR0, DriverName: \Driver\disk
DevicePointer: 0xffff800d4738aca0, DeviceName: Unknown, DriverName: \Driver\stdcfltn
DevicePointer: 0xffff800d47199040, DeviceName: Unknown, DriverName: \Driver\ACPI
DevicePointer: 0xffff800d472079a0, DeviceName: Unknown, DriverName: \Driver\ACPI
DevicePointer: 0xffff800d4728d050, DeviceName: \Device\00000037, DriverName: \Driver\iaStorAC
------------ End ---------- Alternate DeviceName: Unknown, DriverName: \Driver\partmgr
Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers… Done! Drive 0 This is a System drive Scanning MBR on drive 0… Inspecting partition table: MBR Signature: 55AA Disk Signature: 550A084F

Partition information:

Partition 0 type is Other (0xde)
Partition is NOT ACTIVE.
Partition starts at LBA: 63  Numsec = 80262
Partition is not bootable

Partition 1 type is Other (0x27)
Partition is ACTIVE.
Partition starts at LBA: 81920  Numsec = 24604672
Partition is bootable
Partition file system is NTFS

Partition 2 type is Primary (0x7)
Partition is NOT ACTIVE.
Partition starts at LBA: 24686592  Numsec = 1928835072
Partition is not bootable
Partition file system is NTFS

Partition 3 type is Empty (0x0)
Partition is NOT ACTIVE.
Partition starts at LBA: 0  Numsec = 0
Partition is not bootable

Disk Size: 1000204886016 bytes Sector size: 512 bytes

Done! File “C:\Windows\SYSTEMAPPS\MICROSOFTWINDOWS.CLIENT.CBS_CW5N1H2TXYEWY\TEXTINPUTHOST.EXE” is sparse (flags = 32768) File “C:\Windows\System32\notepad.exe” is sparse (flags = 32768) File “C:\Users\Administrador\AppData\Local\Microsoft\OneDrive\OneDrive.exe” is sparse (flags = 32768) File “C:\Users\co\AppData\Local\Microsoft\OneDrive\OneDrive.exe” is sparse (flags = 32768) Scan finished

Removal queue found; removal started Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\MBR-0-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-0-63-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-1-81920-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\VBR-0-2-24686592-i.mbam… Removing C:\ProgramData\Malwarebytes’ Anti-Malware (portable)\MBR-0-r.mbam… Removal finished

Paso 3: Descargué TDSSKiller como me pediste de la pagina de Forospyware esta vez si me dejó descargarlo, seguí los pasos del manual, marqué las casillas que me indicaste y reinicié (al reiniciar Malwarebites me dijo que la protección en tiempo real estaba desactivada, supongo que al estar en Modo a prueba de fallos no carga, la activé y tomé un screenshot, si es necesario te lo mando), al haber tenido que reiniciar corrí RKill.exe nuevamente con el Rkill renombrado como iexplore.exe y esta vez se quedó pasmado en:

Performing miscellaneous checks:

  • Windows Defender Disabled

    [HKLM\SOFTWARE\Microsoft\Windows Defender] “DisableAntiSpyware” = dword:00000001

Lo cerré y lo volví a intentar, me dí cuenta que esta vez, se copió a si mismo 3 veces Iexplore.exe normal, Iexplore64.exe y Iexplore649968.exe, ahora si pasó (aunque tardó un rato pero aceptable) pongo reporte:

kill 2.9.1 by Lawrence Abrams (Grinler)

Copyright 2008-2022 BleepingComputer.com More Information about Rkill can be found at this link: RKill - What it does and What it Doesn't - A brief introduction to the program - Anti-Virus, Anti-Malware, and Privacy Software

Program started at: 12/02/2022 05:45:19 AM in x64 mode. (Safe Mode) Windows Version: Windows 10 Pro

Checking for Windows services to stop:

  • No malware services found to stop.

Checking for processes to terminate:

  • No malware processes found to kill.

Checking Registry for malware related settings:

  • No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

  • Windows Defender Disabled

    [HKLM\SOFTWARE\Microsoft\Windows Defender] “DisableAntiSpyware” = dword:00000001

Searching for Missing Digital Signatures:

  • No issues found.

Checking HOSTS File:

  • HOSTS file entries found:

127.0.0.1 3dns.adobe.com 127.0.0.1 3dns-1.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-4.adobe.com 127.0.0.1 3dns-5.adobe.com 127.0.0.1 activate.adobe.com 127.0.0.1 activate.wip1.adobe.com 127.0.0.1 activate.wip2.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 activate.wip4.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 activate-sjc0.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-1.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 adobe-dns-4.adobe.com 127.0.0.1 adobeereg.com 127.0.0.1 ereg.adobe.com

20 out of 136 HOSTS entries shown. Please review HOSTS file for further entries.

Program finished at: 12/02/2022 05:49:09 AM Execution time: 0 hours(s), 3 minute(s), and 49 seconds(s)

Luego abrí TDSSKiller como administrador y ya me dejó palomear Loaded Modules, Ok y Start Scan, acabó rapidisimo, en menos de un minuto:

Pongo reporte:

05:54:26.0550 0x1238 TDSS rootkit removing tool 3.1.0.28 Apr 9 2019 21:11:46 05:54:40.0947 0x1238 ============================================================ 05:54:40.0947 0x1238 Current date / time: 2022/12/02 05:54:40.0947 05:54:40.0947 0x1238 SystemInfo: 05:54:40.0947 0x1238
05:54:40.0947 0x1238 OS Version: 10.0.19044 ServicePack: 0.0 05:54:40.0947 0x1238 Product type: Workstation 05:54:40.0947 0x1238 ComputerName: CIROCCO-LAP 05:54:40.0947 0x1238 UserName: co 05:54:40.0947 0x1238 Windows directory: C:\WINDOWS 05:54:40.0947 0x1238 System windows directory: C:\WINDOWS 05:54:40.0947 0x1238 Running under WOW64 05:54:40.0947 0x1238 Processor architecture: Intel x64 05:54:40.0947 0x1238 Number of processors: 8 05:54:40.0947 0x1238 Page size: 0x1000 05:54:40.0947 0x1238 Boot type: Safe boot with network 05:54:40.0947 0x1238 CodeIntegrityOptions = 0x00000001 05:54:40.0947 0x1238 ============================================================ 05:54:40.0947 0x1238 KLMD ARK init status: drvProperties = 0xEF0F02, osBuild = 19041.0, osProperties = 0x1D 05:54:40.0947 0x1238 KLMD BG init status: drvProperties = 0xEF0F02, osBuild = 19041.0, osProperties = 0x1D 05:54:40.0947 0x1238 BG loaded 05:54:40.0994 0x1238 System UUID: {936349D8-36DC-D550-37D9-528261B96017} 05:54:41.0072 0x1238 !crdlk 05:54:41.0134 0x1238 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type ‘A’ 05:54:41.0150 0x1238 ============================================================ 05:54:41.0150 0x1238 \Device\Harddisk0\DR0: 05:54:41.0166 0x1238 MBR partitions: 05:54:41.0166 0x1238 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x178B000, BlocksNum 0x72F7B000 05:54:41.0166 0x1238 ============================================================ 05:54:41.0181 0x1238 C: <-> \Device\Harddisk0\DR0\Partition1 05:54:41.0181 0x1238 ============================================================ 05:54:41.0181 0x1238 Initialize success 05:54:41.0181 0x1238 ============================================================ 05:55:10.0560 0x12dc ============================================================ 05:55:10.0560 0x12dc Scan started 05:55:10.0560 0x12dc Mode: Manual; SigCheck; TDLFS; 05:55:10.0560 0x12dc ============================================================ 05:55:10.0560 0x12dc KSN ping started 05:55:10.0778 0x12dc KSN ping finished: true 05:55:19.0840 0x12dc ================ Scan BIOS ================================= 05:55:19.0840 0x12dc BIOS info: vendor = Dell Inc., version = A04, releaseDate = 11/14/2014 05:55:19.0840 0x12dc Base board info: manufacturer = Dell Inc., product = 0JTY19, version = A00 05:55:21.0918 0x12dc [ C1E46676CBD23EBD60FA836BB8089031, 2261F6A523CEC0AB0148ECD8FDA761FA67AC6AE0543FC68A0BF787C4C062F3AD ] BIOS 05:55:21.0918 0x12dc BIOS - ok 05:55:21.0918 0x12dc ================ Scan system memory ======================== 05:55:21.0918 0x12dc System memory - ok 05:55:21.0918 0x12dc ================ Scan services ============================= 05:55:22.0668 0x12dc [ AF50A9D10FF7B1D999BA99D00CC128B3, 3D6E0579821BFA91B7F0A6E6DDC6E03BD3389202AD1A079B825D18D2A76250A0 ] 1394ohci C:\WINDOWS\System32\drivers\1394ohci.sys 05:55:22.0809 0x12dc 1394ohci - ok 05:55:22.0824 0x12dc [ 1C29610EDF5FE3C9D313207BD65BCDD0, 5A29D80AF47D08998125CB81BC1D4E84093291A74DE422B63F7BBDA7BDE95311 ] 3ware C:\WINDOWS\system32\drivers\3ware.sys 05:55:22.0824 0x12dc 3ware - ok 05:55:22.0856 0x12dc [ 439278CCDD4A601E78ECC4B67E19A761, 221741F5E7F76587EA819A27DF0BB68C81529E24687E73EEDA354F45A0ADE96D ] AarSvc C:\WINDOWS\System32\AarSvc.dll 05:55:22.0902 0x12dc AarSvc - ok 05:55:22.0949 0x12dc [ 644498BD614668D4E43160BCEADED841, D95DFD8E8FBD35CDEDC51157E8E6390B1881946FA22279231FC15C9A5E7EED7B ] ACPI C:\WINDOWS\system32\drivers\ACPI.sys 05:55:22.0981 0x12dc ACPI - ok 05:55:22.0981 0x12dc [ 6A424E6ABD1970E23ECF3DA85725B6BF, 1D576471A8035AD3FF5B0616F47B79E43AA367ECDF009D7CADDA0F11F13A1345 ] AcpiDev C:\WINDOWS\System32\drivers\AcpiDev.sys 05:55:23.0012 0x12dc AcpiDev - ok 05:55:23.0043 0x12dc [ 70D9FC69CED08E86B888717CC5C37367, 34856C805B67F3EE4ABFD81B61879112344C343BC7E76A7A466FAD276E0E5165 ] acpiex C:\WINDOWS\system32\Drivers\acpiex.sys 05:55:23.0043 0x12dc acpiex - ok 05:55:23.0059 0x12dc [ EF7CB34FB2D56305EF942012499AB8F7, 3A9A504797FD22BB5447BB36597D5001320ABC0D4A1853D478C038EAC6847913 ] acpipagr C:\WINDOWS\System32\drivers\acpipagr.sys 05:55:23.0090 0x12dc acpipagr - ok 05:55:23.0090 0x12dc [ 33B5ED555018128792AFFCDC9AF7AFD2, 1E7C5FADA2486EE31289A4BEFB70AEA173190671C64995441651903CF31E5033 ] AcpiPmi C:\WINDOWS\System32\drivers\acpipmi.sys 05:55:23.0106 0x12dc AcpiPmi - ok 05:55:23.0106 0x12dc [ 85A86944A6163F0B7A8B10203B70CB9A, 72D35F5DB8714D38E4050A7F7A457C4AD99E3EA212040704F1C1ECBB70E865E9 ] acpitime C:\WINDOWS\System32\drivers\acpitime.sys 05:55:23.0137 0x12dc acpitime - ok 05:55:23.0152 0x12dc [ 494072BF9EC1FDFFD54C47A80821FE6E, 8F302F43314C2F5C80E1D22B17C0246EF8A275C63FDB3C1CDC0DD999C4715A77 ] Acx01000 C:\WINDOWS\system32\drivers\Acx01000.sys 05:55:23.0199 0x12dc Acx01000 - ok 05:55:23.0246 0x12dc [ 0B6178B0FEBD39F9ABF211B13DCBA2D4, 6AF57A7DA31749715BA29B3B55A2F4ACDD53A72B4F179398D2BCA80A6C4F4841 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 05:55:23.0277 0x12dc AdobeARMservice - ok 05:55:23.0309 0x12dc [ B4B75D49BFBCFB2762593F77E5BD7789, B83072D77685F973701EC6629D8AC2626FDEFD657A4DB9AA7D532960A29FC67C ] ADP80XX C:\WINDOWS\system32\drivers\ADP80XX.SYS 05:55:23.0340 0x12dc ADP80XX - ok 05:55:23.0371 0x12dc [ AADECAAEE10B5A45E75A9E4DACB49259, 13E86923888E703185951F965DC6582A552850D736DC224196613B4EC74A8EAA ] AFD C:\WINDOWS\system32\drivers\afd.sys 05:55:23.0387 0x12dc AFD - ok 05:55:23.0402 0x12dc [ 21266728FF51F5AE872678783C6EAB78, F21DB146C437676A984AD0A8142D772AAD8F4B6950DCC0CFBB58566C1F4ECCE5 ] afunix C:\WINDOWS\system32\drivers\afunix.sys 05:55:23.0434 0x12dc afunix - ok 05:55:23.0527 0x12dc [ 469A30573534050C19586CA7FB8176BA, F163D0AF4841483E80DB680B03E089AA5861B23D4DFACA90B4967FE2537F666E ] AGMService C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe 05:55:23.0652 0x12dc AGMService - ok 05:55:23.0871 0x12dc [ 9512338AA11FEB77C84AC2B1C36A3C70, E3897F9AB19621CCD4984CA086A0B404156C50FB6B3B0060670D666C60C01587 ] AGSService C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe 05:55:23.0980 0x12dc AGSService - ok 05:55:24.0012 0x12dc [ E6C21EB564C1A177B484C3A53AEA49BF, F2BBD6F46E55B64F0F5798A029DD51433E961712C1FED12999199FA49058776D ] ahcache C:\WINDOWS\system32\DRIVERS\ahcache.sys 05:55:24.0059 0x12dc ahcache - ok 05:55:24.0074 0x12dc [ 526FE18DB976D9A1AE19FBC53FA690B1, 4E2623243A9BB61F7211E591C24EDB70B07974A7FA21E3F14C683F27E975777F ] AJRouter C:\WINDOWS\System32\AJRouter.dll 05:55:24.0074 0x12dc AJRouter - ok 05:55:24.0105 0x12dc [ 551C155F4FCE82BBA4CC92E56F1ECB84, 6ABE94DF833EC0E6D145429BBA99FDCA9AD3FCBB685A432B20C04F74DE9A42A5 ] ALG C:\WINDOWS\System32\alg.exe 05:55:24.0152 0x12dc ALG - ok 05:55:24.0184 0x12dc [ FFA3C9C95FF0486529B644ADC8E720DB, 3C07DF55EE04AC595306BD7327C8F5CA4223E66F28E549EBC4DC7A92ACF200E7 ] AMD External Events Utility C:\WINDOWS\system32\atiesrxx.exe 05:55:24.0215 0x12dc AMD External Events Utility - ok 05:55:24.0215 0x12dc [ 55578CF027B0AE9F0D653B209C9F1B6D, 46A53925BAA34FA9D87E7C3157504A4557D81CD8B8608E7AB6CAF02F482F7792 ] amdgpio2 C:\WINDOWS\System32\drivers\amdgpio2.sys 05:55:24.0262 0x12dc amdgpio2 - ok 05:55:24.0277 0x12dc [ D0E26E590DE1424CCC4F77D1687049EF, 387811D57DEF06C9736D9F0BAB0DFB0F83DBAB19E5489BF9A6DCDCBD682DD8FE ] amdi2c C:\WINDOWS\System32\drivers\amdi2c.sys 05:55:24.0309 0x12dc amdi2c - ok 05:55:24.0309 0x12dc [ 0F1012F6A0E4A81D51F60B2A5F86BA9E, 36B43A91BE1FC52E26FE22511CC8E5538218C667ABABDBA718F4391AFA233875 ] AmdK8 C:\WINDOWS\System32\drivers\amdk8.sys 05:55:24.0324 0x12dc AmdK8 - ok 05:55:24.0324 0x12dc amdkmdag - ok 05:55:24.0340 0x12dc [ 59A5795A131800D30E8F682099EBEEF5, 85C8DE3B781C7B8E0EE305B8F89E84D9BD9960C482F5CD6019CCC6FA49E43CC6 ] amdkmdap C:\WINDOWS\system32\DRIVERS\atikmpag.sys 05:55:24.0371 0x12dc amdkmdap - ok 05:55:24.0387 0x12dc [ 0D5334CEBD138065DE26E1859CE3FE5F, 01B65924540F90FC6D5754C25715DE223A85874B4547C4EDE38FA9A5601DDAB7 ] AmdPPM C:\WINDOWS\System32\drivers\amdppm.sys 05:55:24.0402 0x12dc AmdPPM - ok 05:55:24.0402 0x12dc [ 70D7BE6BB8D22A38AD0040A1EC41C1FE, D5231F97E5432234A8A19904E59C324E825AF04881AA195C19CCC9E6A7684B14 ] amdsata C:\WINDOWS\system32\drivers\amdsata.sys 05:55:24.0418 0x12dc amdsata - ok 05:55:24.0434 0x12dc [ C47EDC5D81546677A772CFC86281ED29, 71C7E7E5AA74596A6725D8F70F1DE9A0C63D3C3E120D9CCF8A508854AC340A23 ] amdsbs C:\WINDOWS\system32\drivers\amdsbs.sys 05:55:24.0449 0x12dc amdsbs - ok 05:55:24.0449 0x12dc [ F1A1CA86A1E3782A0CABB07EF3663C70, 1FC1D4287DB56A387BDF917C0CB3BFC30CA5D792A350E2EDBBDDEBF8127E1AF9 ] amdxata C:\WINDOWS\system32\drivers\amdxata.sys 05:55:24.0449 0x12dc amdxata - ok 05:55:24.0480 0x12dc [ 08D7D6C8E139999D4D63BA032ED5CDE9, 28E4DF8607E65DBF9D08339983D0DA27D18C245C078D57201F006C004771172B ] ApfiltrService C:\WINDOWS\system32\DRIVERS\Apfiltr.sys 05:55:24.0512 0x12dc ApfiltrService - ok 05:55:24.0527 0x12dc [ B71D8DA2886734F056922829BF202777, D5370A780BA5D169A65208CA287B3F4C76377A06BDEA50BD495B142A854A0DE8 ] AppID C:\WINDOWS\system32\drivers\appid.sys 05:55:24.0543 0x12dc AppID - ok 05:55:24.0559 0x12dc [ C7D46154D1AF87D4069D21401867E9F7, AE8165250A9D5444B1AE6F660A53A3E61C754CED84A63456ACA127F1BF0E3BB4 ] AppIDSvc C:\WINDOWS\System32\appidsvc.dll 05:55:24.0574 0x12dc AppIDSvc - ok 05:55:24.0590 0x12dc [ 200EAA2A0B8170C7C59004943B252608, A0BE7615F3D37233B496B5E64571326FF72BDC475855158FD6D8ED166577C996 ] Appinfo C:\WINDOWS\System32\appinfo.dll 05:55:24.0652 0x12dc Appinfo - ok 05:55:24.0668 0x12dc [ 6E1EB60C2B106853CC471D29F639F0DA, E044B74FF494725D56B292ACE8D558E315AE406085EE3695D859AD97254897FA ] AppleKmdfFilter C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys 05:55:24.0715 0x12dc AppleKmdfFilter - ok 05:55:24.0715 0x12dc [ DA8376E75670EB1E25422AD6AFA967F8, 61C6533DADAD5C47BDCF996297E69501092FFB0D1F1DCC2AC6DF92E6043D5B43 ] AppleLowerFilter C:\WINDOWS\System32\drivers\AppleLowerFilter.sys 05:55:24.0730 0x12dc AppleLowerFilter - ok 05:55:24.0730 0x12dc [ B09951230F90E7A4B730854FD476D03A, 107BC1F482D2CCE8F288D512092A86C352EAA049A5A25CE64FDFE73B0E4066B7 ] applockerfltr C:\WINDOWS\system32\drivers\applockerfltr.sys 05:55:24.0762 0x12dc applockerfltr - ok 05:55:24.0777 0x12dc [ 9F7F9EF3CB7B2DB1DE97A8DC2A8053E7, 51EB3E2C8266AE07FDB1B69E3550FFD7B8500E0469A33D2064C4ECCAA942988C ] AppMgmt C:\WINDOWS\System32\appmgmts.dll 05:55:24.0793 0x12dc AppMgmt - ok 05:55:24.0809 0x12dc [ 188973F42C88B759B60AB3C39231C9DC, C406658C076AB5295F5B3830125D39E3A8049EF4E01C453FE4CB411C31D50C78 ] AppReadiness C:\WINDOWS\system32\AppReadiness.dll 05:55:24.0855 0x12dc AppReadiness - ok 05:55:24.0871 0x12dc [ 8AA76A19EC2DF7D757C549CB76B26729, 1BA4C7564BE56209C9CC12D3F7D7914711F47740F70EF56E5F54EC272150C23D ] AppVClient C:\WINDOWS\system32\AppVClient.exe 05:55:24.0902 0x12dc AppVClient - ok 05:55:24.0918 0x12dc [ A80DB58839496D2544B3274D747B12CB, F3BB5A568F9051382AA74AF85F47D6E2F2C055A3481E81E389BFA15F9A90D5A1 ] AppvStrm C:\WINDOWS\system32\drivers\AppvStrm.sys 05:55:24.0934 0x12dc AppvStrm - ok 05:55:24.0934 0x12dc [ C808B8230990D281B04DFB525295BF0A, D9C216525CAE8EB147952EC26CBDDD757DE6B3B5ADEE5E5FCBE2006E9C207670 ] AppvVemgr C:\WINDOWS\system32\drivers\AppvVemgr.sys 05:55:24.0949 0x12dc AppvVemgr - ok 05:55:24.0949 0x12dc [ 5241A590E4204B79F3315AF7F4D620A6, 3B93CA0D990BE833A023084209452CB85989AC66DD889AB103840948D405AFCC ] AppvVfs C:\WINDOWS\system32\drivers\AppvVfs.sys 05:55:24.0965 0x12dc AppvVfs - ok 05:55:25.0059 0x12dc [ D2E093B2B4BD5E9AD8466D7C06DF62AA, 3E00D25823994C4E633042408A415224E6CD533808380582AA331CDE12AFD48B ] AppXSvc C:\WINDOWS\system32\appxdeploymentserver.dll 05:55:25.0215 0x12dc AppXSvc - ok 05:55:25.0215 0x12dc [ 46FD8469080917EE12425AF692C4BC20, 96DCA25AE619F38640B22702A10BC3191626F3A36DE0E1B0EDA3B079EA9DEB24 ] arcsas C:\WINDOWS\system32\drivers\arcsas.sys 05:55:25.0230 0x12dc arcsas - ok 05:55:25.0277 0x12dc [ 167DE146ECE1CBA27354A26EC4A13A74, 8D6613DDD52A59E3320EB15C08BB770026582076654164E1C2D408819B26B53E ] AssignedAccessManagerSvc C:\WINDOWS\System32\assignedaccessmanagersvc.dll 05:55:25.0387 0x12dc AssignedAccessManagerSvc - ok 05:55:25.0387 0x12dc [ D930AAE80A55116D07C41E95DE5671DB, 14985D6D2D52689C1B012F64ED0D7C9C5F6BADB51C4528BF6456D3EAE2FE69A7 ] AsyncMac C:\WINDOWS\System32\drivers\asyncmac.sys 05:55:25.0402 0x12dc AsyncMac - ok 05:55:25.0402 0x12dc [ B2C716CEBC11930E3C1E38C3B6B9DDED, 0A3F019951B7E218401A18CA52ADAA0B7B84F8ACB8D0636BA7522DD2691D138E ] atapi C:\WINDOWS\system32\drivers\atapi.sys 05:55:25.0418 0x12dc atapi - ok 05:55:25.0465 0x12dc [ F24380B661B49849D377686D13687B4B, FF646D0CF0B0AFF20FDB477176924FBFAC58A74218EA39BE78CBF11291040BF2 ] AudioEndpointBuilder C:\WINDOWS\System32\AudioEndpointBuilder.dll 05:55:25.0496 0x12dc AudioEndpointBuilder - ok 05:55:25.0574 0x12dc [ 89E85F2EB9FE117F62138AD462D5F531, 0D2D87339F6DDEBAC35B0C61CF9221D7EB9E278A891BBA512D7312BB8B1AE85F ] Audiosrv C:\WINDOWS\System32\Audiosrv.dll 05:55:25.0637 0x12dc Audiosrv - ok 05:55:25.0668 0x12dc [ A0F7C552FA2B0D848758F5010A7B3AE3, 7DBF94761B806AB47DBC948E723D718852416DC0E311CB40F31A55DA0DCB267F ] autotimesvc C:\WINDOWS\System32\autotimesvc.dll 05:55:25.0715 0x12dc autotimesvc - ok 05:55:25.0777 0x12dc [ 67E3974D7F0660369478949B5BBA8DC2, AFD67B9A7810DB3E4DD08DAD6963F8639DFE9DACF2407C4835A571220B27E608 ] AVG Antivirus C:\Program Files\AVG\Antivirus\AVGSvc.exe 05:55:25.0808 0x12dc AVG Antivirus - ok 05:55:25.0824 0x12dc [ 06F83DBCBEE147C134AAF1E54FB40079, C7AA35F773924DC4987CC8B3E639929897237D8B14D2469338D62F4E2510305F ] AVG Tools C:\Program Files\AVG\Antivirus\avgToolsSvc.exe 05:55:25.0855 0x12dc AVG Tools - ok 05:55:25.0855 0x12dc [ EAB99E730E9C1A38985DABCEE5A8148E, 4ACA745448CBC01BD5CEF69A169D8A6DC0AF7523E8ABD63BED26F5DEC00CC4B6 ] avgArDisk C:\WINDOWS\system32\drivers\avgArDisk.sys 05:55:25.0871 0x12dc avgArDisk - ok 05:55:25.0887 0x12dc [ BB73ABC75D0113DE5513401D89664A65, 033A14D3863DCB5B990788697A1096FD1F03586694B7872BB47826953F69C9F0 ] avgArPot C:\WINDOWS\system32\drivers\avgArPot.sys 05:55:25.0902 0x12dc avgArPot - ok 05:55:26.0152 0x12dc [ 5B07FC731CC3EBE48EEAF86ED05671A6, ED471A6E72A44BB402342D7035A24F1FAA93086238BA58F6BBA06EAAA649122E ] avgbIDSAgent C:\Program Files\AVG\Antivirus\aswidsagent.exe 05:55:26.0480 0x12dc avgbIDSAgent - ok 05:55:26.0496 0x12dc [ 4074F15F914F6D50CF84A30C5F410E3D, 62C9AC9CB7B8D664589AB3AC4D65A72A900FED587496494D5758E4E8AA8D3841 ] avgbidsdriver C:\WINDOWS\system32\drivers\avgbidsdriver.sys 05:55:26.0527 0x12dc avgbidsdriver - ok 05:55:26.0543 0x12dc [ B4818E59AACA5A2F71406FCEDD0468DE, E52AA19BA3E00487746EC77C3A0F4090F92632316C53A6A34053267F718D100D ] avgbidsh C:\WINDOWS\system32\drivers\avgbidsh.sys 05:55:26.0558 0x12dc avgbidsh - ok 05:55:26.0558 0x12dc [ 81F69669DD162FF32F10B6D18C681B7E, 4C050CA20B3724170E2AC73B4A69B8E7B3CF3D519C4B88D54402FB27A77DDF2D ] avgbuniv C:\WINDOWS\system32\drivers\avgbuniv.sys 05:55:26.0574 0x12dc avgbuniv - ok 05:55:26.0590 0x12dc [ 3AB7DD53C5A5546A29E208C76100C189, 0ADCDB9F44E4BCA1D5AE538F1D0EFC71CE4C8127945878F64131F4B27881679B ] avgElam C:\WINDOWS\system32\drivers\avgElam.sys 05:55:26.0605 0x12dc avgElam - ok 05:55:26.0621 0x12dc [ E98A5AC18047CB0D1BE1963487AEF4D8, A7460EC184AE953323129AC175FE84936C2B01277C6718F3DC0E9173EFEBB1F0 ] avgKbd C:\WINDOWS\system32\drivers\avgKbd.sys 05:55:26.0621 0x12dc avgKbd - ok 05:55:26.0652 0x12dc [ 56E17094C88737B87232FEE5982D5B05, CCCE62450A3E8B2A80EC160F3A3FAD3A1BBB31D721E52226880F5A0D3F8EA89B ] avgMonFlt C:\WINDOWS\system32\drivers\avgMonFlt.sys 05:55:26.0668 0x12dc avgMonFlt - ok 05:55:26.0683 0x12dc [ 67572E4A7A4682F0D28D0545E9C33180, F2D4A8B96686E6E28E1AFC3E64B6A2A9B2A415BF635B5C8EB34AB09B188B4574 ] avgNetHub C:\WINDOWS\system32\drivers\avgNetHub.sys 05:55:26.0699 0x12dc avgNetHub - ok 05:55:26.0715 0x12dc [ 7979C2490286B11FD5BA9027E5E71677, 1C513EE6CFEE97BD53FFEF8BAE7C9631AD4D9BB8DEB9F332715D84E8FA776D92 ] avgRdr C:\WINDOWS\system32\drivers\avgRdr2.sys 05:55:26.0715 0x12dc avgRdr - ok 05:55:26.0730 0x12dc [ 160C9CE8E74D43BE303880BD39D87AA2, 2296CFB12EE06F2327459977EB1013721D19018F889DCB3F1241E409E60C0D8C ] avgRvrt C:\WINDOWS\system32\drivers\avgRvrt.sys 05:55:26.0746 0x12dc avgRvrt - ok 05:55:26.0762 0x12dc [ 4A4389CC7935B8B40C305871E0D0F3BB, AE9F464A4E696ECB56666608DD98D4AD22B3C38C3597158816E4ACAB21EF369D ] avgSnx C:\WINDOWS\system32\drivers\avgSnx.sys 05:55:26.0793 0x12dc avgSnx - ok 05:55:26.0808 0x12dc [ 10BF0B8B9F4161BF4173A6E08BC7409C, 089A57B9AA4E1BCF9F6F895BA88A9E60517B99C5C353C6279BF54C7FAA1714B5 ] avgSP C:\WINDOWS\system32\drivers\avgSP.sys 05:55:26.0840 0x12dc avgSP - ok 05:55:26.0840 0x12dc [ 9CFF9B76CBC40FE2118844227342D5C4, D4C45F059C5BBF06C47B630FB99505402608F6CC322ABBE65CFC85258104DCF0 ] avgStm C:\WINDOWS\system32\drivers\avgStm.sys 05:55:26.0855 0x12dc avgStm - ok 05:55:26.0871 0x12dc [ 068B22DCB047EB54A08864D0133DEF7F, 9F33206AE5F21FA5CCF892A2CD6383AF5E5E802D0F9457012A29D9E7C5A51E1E ] avgVmm C:\WINDOWS\system32\drivers\avgVmm.sys 05:55:26.0887 0x12dc avgVmm - ok 05:55:26.0902 0x12dc [ 75CA8458D560E6F26A7EE0475E650458, CF9C722DE59B6A7EBBA99620E45693F6F9AFFA8BE26A361FB5D6662E539DAC3A ] AvgWscReporter C:\Program Files\AVG\Antivirus\wsc_proxy.exe 05:55:26.0902 0x12dc AvgWscReporter - ok 05:55:26.0918 0x12dc [ FCE104053ECADACF4AFAFEC2FE805DBB, EB39D46FA07E7DC9028C671F45C5B51D8DC9B41977AC26D318AB39CD4382A0FB ] AxInstSV C:\WINDOWS\System32\AxInstSV.dll 05:55:26.0949 0x12dc AxInstSV - ok 05:55:26.0965 0x12dc [ 638C59D330A7AF943074678A70F22E7C, FEB2771428706126FEA1CC9A50EBE3CF4F8E8FB6FCB3CA19996497CA44FDAC45 ] b06bdrv C:\WINDOWS\system32\drivers\bxvbda.sys 05:55:26.0980 0x12dc b06bdrv - ok 05:55:26.0996 0x12dc [ 26E2320D24C66EB72B36EB71EBEF2558, 7D06B6499FE915480DF4DAD658281C8B85F7AD71F49B089A270AE0B45713F2E9 ] bam C:\WINDOWS\system32\drivers\bam.sys 05:55:27.0012 0x12dc bam - ok 05:55:27.0058 0x12dc [ 2CA1FD29DE910AEED426CF18A4ADB956, A2EBDDB0426D6E92744A3679B29CA08A9302295177FF5E02601D9181D4CB13CB ] BasicDisplay C:\WINDOWS\System32\DriverStore\FileRepository\basicdisplay.inf_amd64_fc93ae411c02f280\BasicDisplay.sys 05:55:27.0090 0x12dc BasicDisplay - ok 05:55:27.0121 0x12dc [ A2CAFE3F80961A59D5DE8CB91AE51E4B, C17C5FC2658CE24B187EF8E57BCD91ADB0226B03EDF97C468528212425BC89B1 ] BasicRender C:\WINDOWS\System32\DriverStore\FileRepository\basicrender.inf_amd64_ed345fdc37d65139\BasicRender.sys 05:55:27.0152 0x12dc BasicRender - ok 05:55:27.0199 0x12dc [ D8B686D3C74602B2D0A13F7C5D095EE8, D33D6E04BFEC9C8B3D68F6D2DE6B207F3F56D53CC192EDDE766A1A65DDD603FD ] BcastDVRUserService C:\WINDOWS\System32\BcastDVRUserService.dll 05:55:27.0261 0x12dc BcastDVRUserService - ok 05:55:27.0277 0x12dc [ 739D089777D2B66DBE7201E5EA4BA2D7, 9AD12E18A042C5B8EFB19297BC2E7BD1FEF75A138FEFB64C6BF0261FD3E53AB1 ] bcmfn2 C:\WINDOWS\System32\drivers\bcmfn2.sys 05:55:27.0324 0x12dc bcmfn2 - ok 05:55:27.0527 0x12dc [ 2CBF4B241954FFCBBA3CFFDF565E826D, 578E6F5A9CEEEDE16801105094B3C34A27E9599FCDC172AFB3DA3520EEA4EC86 ] BDESVC C:\WINDOWS\System32\bdesvc.dll 05:55:27.0636 0x12dc BDESVC - ok 05:55:27.0636 0x12dc [ 4280B427B81EB8C265F3206E2298761E, 121AF03BBE6ECC1622C2540805A30AE9555EB5D5FE25B55939C045ECE7FC37EB ] Beep C:\WINDOWS\system32\drivers\Beep.sys 05:55:27.0652 0x12dc Beep - ok 05:55:27.0699 0x12dc [ E64677E9BE47E2A376EC7BE57C7172BA, 1FB1CD0EEEE24830CB184AF23F42B44AC8322F797FFF250F8E887361187DE8AE ] BFE C:\WINDOWS\System32\bfe.dll 05:55:27.0746 0x12dc BFE - ok 05:55:27.0777 0x12dc [ 6548FA47F45A1AEE24CA5E563A186BB9, AF41EB6DDC06AAAA2707A9DEC14A435D13CCE0E921F7EBADFF6E456AAE055839 ] bhtsddr C:\WINDOWS\system32\DRIVERS\bhtsddr.sys 05:55:27.0793 0x12dc bhtsddr - ok 05:55:27.0808 0x12dc [ D254ECC59DECE4C5D2C42A4CAFE9C050, 9216911F306CA4EFE4E930F566461AF86CBB96AADA135D27F3DF2773E0E10679 ] bindflt C:\WINDOWS\system32\drivers\bindflt.sys 05:55:27.0824 0x12dc bindflt - ok 05:55:27.0855 0x12dc [ 3BDAEF58FB1CE7B0A4580E59BD7D6911, 23564C36F4DC2FFDC5FB165BEE0B6F73684C86A1F871FA9A3020C5A1F19CCAEC ] BITS C:\WINDOWS\System32\qmgr.dll 05:55:27.0918 0x12dc BITS - ok 05:55:27.0996 0x12dc [ 399F428646DE8D9B82B9C833FD9DBC32, E8034B600E9E1A56A8DE14988476B8C5556128E35967F95EBAF8DF153FA9ECB6 ] BluetoothUserService C:\WINDOWS\System32\Microsoft.Bluetooth.UserService.dll 05:55:28.0043 0x12dc BluetoothUserService - ok 05:55:28.0058 0x12dc [ 55A234D0C8BBDDD400214AEF7A2EC69C, 9B1366BBA4631F6D5A4923905332E0D0B83FD041764461CC96F873723E3C75B4 ] bowser C:\WINDOWS\system32\DRIVERS\bowser.sys 05:55:28.0074 0x12dc bowser - ok 05:55:28.0105 0x12dc [ 666794D3C28A67355B71406ACAC34C54, 172A1392937C7B8BEB91427918B5A47B1AD7FC329AD410527C3683289C739AA5 ] BrokerInfrastructure C:\WINDOWS\System32\psmsrv.dll 05:55:28.0121 0x12dc BrokerInfrastructure - ok 05:55:28.0152 0x12dc [ B3EEA459B367A168F8769625A76BF792, 0002AEED8641E41CB078E421177E359B801776206582FA0BE0EF7AF01D6ACC8A ] BTAGService C:\WINDOWS\System32\BTAGService.dll 05:55:28.0199 0x12dc BTAGService - ok 05:55:28.0199 0x12dc [ 2B008704767E827E81021743B2B6F336, 30E37705524FA79D8C09E48665B349F0FCD9021B8244DA1A16613CC8C2D58245 ] BthA2dp C:\WINDOWS\System32\drivers\BthA2dp.sys 05:55:28.0261 0x12dc BthA2dp - ok 05:55:28.0277 0x12dc [ CE43EF455E238036B73128A8B38D021E, 1A2470D2468A150965DE68FE279B998CEB7C5914FDE1948EB8A632DC34706F6C ] BthAvctpSvc C:\WINDOWS\System32\BthAvctpSvc.dll 05:55:28.0293 0x12dc BthAvctpSvc - ok 05:55:28.0308 0x12dc [ 2E526401D693B6F1533EB281D505C37D, E49DA2E316014BB32FC2AD7C0B014A643A3F24B7FA32F990501D8E8784953BD2 ] BthEnum C:\WINDOWS\System32\drivers\BthEnum.sys 05:55:28.0340 0x12dc BthEnum - ok 05:55:28.0355 0x12dc [ 703B29DFF67A57C4A9C67368D65C7D35, 11087E831C96FE02802BBBA34975EE4C073EB6FE9F4383D8EDE46877DD1C2021 ] BthHFAud C:\WINDOWS\System32\drivers\BthHfAud.sys 05:55:28.0355 0x12dc BthHFAud - ok 05:55:28.0386 0x12dc [ E7695E8EC994918210016D67D4E2512B, 4EEC1DEA3295DD5D292B1425CE34904A787ADEE0F5B0500CE3C9BC09230E8B41 ] BthHFEnum C:\WINDOWS\System32\drivers\bthhfenum.sys 05:55:28.0402 0x12dc BthHFEnum - ok 05:55:28.0418 0x12dc [ 0825C3B0D4A788E95DE80739E52C9174, 7B2C116DB586ADF3175AE4DC630C2BB9043CF3EE57A22A8DBFE55127F6065A51 ] BthLEEnum C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys 05:55:28.0465 0x12dc BthLEEnum - ok 05:55:28.0465 0x12dc [ 2540446D33997D647FB6174ADC6BE277, C4FF9B1EE50AC72C899A06A5F429B43D5E70A626BC89D29144C6D4785640AEEA ] BthMini C:\WINDOWS\System32\drivers\BTHMINI.sys 05:55:28.0480 0x12dc BthMini - ok 05:55:28.0496 0x12dc [ 11D609CC74F0EB1DF6C0171331CDE9A1, 9412DC92F16C0B8A937D6FB1AD83D7169F4EC0F08FAE0E2B244346428CE99EE1 ] BTHMODEM C:\WINDOWS\System32\drivers\bthmodem.sys 05:55:28.0511 0x12dc BTHMODEM - ok 05:55:28.0543 0x12dc [ 3AB6DD0A13F9AA1BC6A71E942CC45770, C39E471BD757CA12635F283FFC4407989447739D36830E81E8DD3E63E363B3D7 ] BthPan C:\WINDOWS\System32\drivers\bthpan.sys 05:55:28.0558 0x12dc BthPan - ok 05:55:28.0590 0x12dc [ E3433B0850882790180D1408020B1B8E, 6A922D55DFB8AD349B7EBEB5237203CAA48EA7E9B56143121C5B752E7005F2F7 ] BTHPORT C:\WINDOWS\System32\drivers\BTHport.sys 05:55:28.0652 0x12dc BTHPORT - ok 05:55:28.0699 0x12dc [ D293AC628357F2F75B8579087F732970, 1E536D8863D695944214D55E9B0B4BFE04F705DB7ECA18A0CF8B37AAF4893B1E ] bthserv C:\WINDOWS\system32\bthserv.dll 05:55:28.0715 0x12dc bthserv - ok 05:55:28.0715 0x12dc [ CCDFF72A41C00A1A149E7AEDC2038825, 28C1232C8B32B2D5AD1130D6CC34390DF1013EC1947E2A3906DE04E7C2AFA848 ] BTHUSB C:\WINDOWS\System32\drivers\BTHUSB.sys 05:55:28.0730 0x12dc BTHUSB - ok 05:55:28.0746 0x12dc [ 4FF20E869FE2B5A0B8CE2E8BE61C7F7F, 8DE3B7C87D88CF375417355A7C5052B2DE38805B563D61D0E483DB4AD96BD741 ] bttflt C:\WINDOWS\system32\drivers\bttflt.sys 05:55:28.0746 0x12dc bttflt - ok 05:55:28.0746 0x12dc [ EF2A1F3C5EC4EFFFBE9A69B892FBA29C, 16A900FBAB30D008F01F4CAE96347BF313D9D13C7FE430249A0BF4322534CB18 ] buttonconverter C:\WINDOWS\System32\drivers\buttonconverter.sys 05:55:28.0761 0x12dc buttonconverter - ok 05:55:28.0777 0x12dc [ E7690568D2A5FA3D4E6D28B42358A122, CDBD820B6D383EC0A8151EA4300435C2BAD085EC55DB185C5E16CAF961443888 ] CAD C:\WINDOWS\System32\drivers\CAD.sys 05:55:28.0777 0x12dc CAD - ok 05:55:28.0793 0x12dc [ 54C6958CF06D6BB1776844811C34868C, D3681399A0458B9183C12B7F26980959EBD4BB0AEA1084497F2436339AD9E758 ] camsvc C:\WINDOWS\system32\CapabilityAccessManager.dll 05:55:28.0840 0x12dc camsvc - ok 05:55:28.0871 0x12dc [ D73124119E80A2E13A1D5A7B7CD00889, 196215BFE0F198C8201B407C7E39A15E3180E8D03A051B3CEBE88FFFAB4072CE ] CaptureService C:\WINDOWS\System32\CaptureService.dll 05:55:28.0918 0x12dc CaptureService - ok 05:55:28.0964 0x12dc [ 37A8837CC731399AE7B3D141CF4ABF87, 9B1172915398724B30516A5A268FF25C19D35EF7A4C1BD39CF2366F565001FCF ] cbdhsvc C:\WINDOWS\System32\cbdhsvc.dll 05:55:29.0011 0x12dc cbdhsvc - ok 05:55:29.0105 0x12dc [ 1BC77C280A82D0514B4E0094DA92F68C, 81FF823A6AC4B5A890DC3732502AC08B6921C9DF03442234F70204A4E1E4DBF5 ] CCleanerPerformanceOptimizerService C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe 05:55:29.0168 0x12dc CCleanerPerformanceOptimizerService - ok 05:55:29.0168 0x12dc [ BD8897A464332FA5802486DC64248E03, 1F9B2C6642220814F6BAC150C91CB56819337F6B229004A39C76395217BBC407 ] cdfs C:\WINDOWS\system32\DRIVERS\cdfs.sys 05:55:29.0183 0x12dc cdfs - ok 05:55:29.0214 0x12dc [ 6B63D9B10FA9DB29E21CF24704A1D31A, 083E401584A137B4B9F181BC2D8E0DE0FB9826ADD3642B40F5933DA5EFE3F2FB ] CDPSvc C:\WINDOWS\System32\CDPSvc.dll 05:55:29.0277 0x12dc CDPSvc - ok 05:55:29.0324 0x12dc [ 6BC246E784720DD3221114372CB56E0A, 23ADB76423F436600E05038623E35707C66BEBB8A92C0E5AFA15CA3C670FF237 ] CDPUserSvc C:\WINDOWS\System32\CDPUserSvc.dll 05:55:29.0355 0x12dc CDPUserSvc - ok 05:55:29.0371 0x12dc [ 054ABC6C64AE969D033B7876C04D52B4, 492E4FD7A7CCE38D5A7E51C7B069FC0497BE3EFD2EEFEB6AFA3EA81D2A11BC0F ] cdrom C:\WINDOWS\System32\drivers\cdrom.sys 05:55:29.0386 0x12dc cdrom - ok 05:55:29.0418 0x12dc [ 90A4F493C691ABF5A0C231A62F309D88, 9319B5AA78248E53DA529567CBA4D57DD7D93A43218FD66C9EFE2A10C7430581 ] CertPropSvc C:\WINDOWS\System32\certprop.dll 05:55:29.0449 0x12dc CertPropSvc - ok 05:55:29.0464 0x12dc [ 198D403332FB8F2DA289BEBFEC8199AD, 5A7FD2D58C433B9B498A1B37A2F2D877061215360D8E6A752601F2ED4F283A8F ] cht4iscsi C:\WINDOWS\system32\drivers\cht4sx64.sys 05:55:29.0480 0x12dc cht4iscsi - ok 05:55:29.0558 0x12dc [ 77065056FBE4E29054CB1D20303B9F59, 83E2C81274DDBE695EF845E541F7A2DB60EF5E195AE14FACDEEEBD30C0EF4E67 ] cht4vbd C:\WINDOWS\System32\drivers\cht4vx64.sys 05:55:29.0621 0x12dc cht4vbd - ok 05:55:29.0621 0x12dc [ 19C97B053480D85166B78AD4BE476917, 3A2F9C09B5E8ACF7E0BB11C137490DD9E0AD85D67217CCF24EF6358C0E74A397 ] CimFS C:\WINDOWS\system32\drivers\CimFS.sys 05:55:29.0683 0x12dc CimFS - ok 05:55:29.0683 0x12dc [ 115CC1E142CE29C9006D59943108DF47, 564FA08C5BEC6DAF1A83C80C9139A6E1AA7E05D251DB3BA379B57C9FDAE83E1B ] circlass C:\WINDOWS\System32\drivers\circlass.sys 05:55:29.0699 0x12dc circlass - ok 05:55:29.0714 0x12dc [ F16E64E83F5C5884B2D06DD8C34230BB, 87DCA45E90411D0F0FAFF3877CE3F7D2EBF2A39D6B8BC2ED4BDF69DD25234988 ] CldFlt C:\WINDOWS\system32\drivers\cldflt.sys 05:55:29.0761 0x12dc CldFlt - ok 05:55:29.0777 0x12dc [ 4D0C65290F99E8F10325B1651EC3730C, 7B83E1C9A5BFAF2CC052553D1EB3CA563F07FF32BC757613F424D5C887C865D5 ] CLFS C:\WINDOWS\system32\drivers\CLFS.sys 05:55:29.0793 0x12dc CLFS - ok 05:55:29.0839 0x12dc [ A5FC7177CF56DE5005654B2C8317915E, BF42B90525DE343AA274039078FEFBACA5011F893A56E362D61158361B078F6C ] ClipSVC C:\WINDOWS\System32\ClipSVC.dll 05:55:29.0871 0x12dc ClipSVC - ok 05:55:29.0886 0x12dc [ 1C5BBC2CD8198622986F5B0028813347, 4D37A875EB3A7635C66FFC1CE63352FDDC39ECCFB737FFC6CF87E8AE2F741288 ] cloudidsvc C:\WINDOWS\system32\cloudidsvc.dll 05:55:29.0918 0x12dc cloudidsvc - ok 05:55:29.0933 0x12dc [ E127E772A705CD32BE34166F679C61C8, 209723632369404308EF6DF734077A99A295C2E380DB85AD1F8498CC8DFBC88A ] CmBatt C:\WINDOWS\System32\drivers\CmBatt.sys 05:55:29.0933 0x12dc CmBatt - ok 05:55:29.0964 0x12dc [ 9559F5D28D01D661D6B625F0987AA1B6, 087A998AA02B2BB2F57D57D8D48F285F939CC87346D5C3C34450671205A70408 ] CNG C:\WINDOWS\system32\Drivers\cng.sys 05:55:29.0996 0x12dc CNG - ok 05:55:30.0011 0x12dc [ A46B4D1484227900F7615FE2A569D828, A06B8002E7A708890222C777DDF8B67FED7015C0943C1FC4F9036E9F9DC14494 ] cnghwassist C:\WINDOWS\system32\DRIVERS\cnghwassist.sys 05:55:30.0027 0x12dc cnghwassist - ok 05:55:30.0027 0x12dc [ 99392FDADF3CE5EB47403E5A52866E6F, 63CEF51971EB85D9823CE9A95F1ED9907D20525ED8E32230068CC36E9082A8C3 ] CompositeBus C:\WINDOWS\System32\DriverStore\FileRepository\compositebus.inf_amd64_7500cffa210c6946\CompositeBus.sys 05:55:30.0058 0x12dc CompositeBus - ok 05:55:30.0058 0x12dc COMSysApp - ok 05:55:30.0074 0x12dc [ 37BAC4413D147BAC2C0DDA67890F0F10, E4AE23EB73BB9F525822DFAB09D3DED0E921255467FA1341267B6AE9BCAA01F7 ] condrv C:\WINDOWS\system32\drivers\condrv.sys 05:55:30.0074 0x12dc condrv - ok 05:55:30.0089 0x12dc [ 30567F197E1E1415FD5813FCE895E332, CAAC41134F6E01815888707D2FB76703B7A869912832D2173726B17511C3B17F ] ConsentUxUserSvc C:\WINDOWS\System32\ConsentUxClient.dll 05:55:30.0105 0x12dc ConsentUxUserSvc - ok 05:55:30.0136 0x12dc [ 724677D5055D40798DB093C26CEFD179, C01C15C82A8568BA99BF193FBC4893D990102B0CBAAFE04F4F02B9FE44AE6C76 ] CoreMessagingRegistrar C:\WINDOWS\system32\coremessaging.dll 05:55:30.0168 0x12dc CoreMessagingRegistrar - ok 05:55:30.0339 0x12dc [ ED08F130C70773B53EEB057F105112BB, A0051AD604A26DDC346D9F12132FDEB388206966DFC9DA52270ED1BE843E5020 ] cphs C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe 05:55:30.0371 0x12dc cphs - ok 05:55:30.0433 0x12dc [ 68BBADA76B7BE769B8CC0B96FC37F24E, F31C6DB40788838B11C77C93D5E219E96A1F866840A9D6D0345826C14504753D ] Credential Vault Host Control Service C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostControlService.exe 05:55:30.0480 0x12dc Credential Vault Host Control Service - ok 05:55:30.0496 0x12dc [ B0C99D40003FC790B0F183B1613044F6, B67A49AE15659BC1017611B5FA57F944F26B93B6D09B989DD2A8BEE147EAD9BA ] Credential Vault Host Storage C:\Program Files\Broadcom Corporation\Broadcom USH Host Components\CV\bin\HostStorageService.exe 05:55:30.0496 0x12dc Credential Vault Host Storage - ok 05:55:31.0167 0x12dc [ 33915D0533AE7883BD50657C99EA45A4, 2063A8145D63798B948ECF755D2592B4751D8386B2B47B3D13D42B5D95557DCF ] CredentialEnrollmentManagerUserSvc C:\WINDOWS\system32\CredentialEnrollmentManager.exe 05:55:31.0183 0x12dc CredentialEnrollmentManagerUserSvc - ok 05:55:31.0199 0x12dc [ 33915D0533AE7883BD50657C99EA45A4, 2063A8145D63798B948ECF755D2592B4751D8386B2B47B3D13D42B5D95557DCF ] CredentialEnrollmentManagerUserSvc_3740e C:\WINDOWS\system32\CredentialEnrollmentManager.exe 05:55:31.0214 0x12dc CredentialEnrollmentManagerUserSvc_3740e - ok 05:55:31.0214 0x12dc [ 8AB3568419872D1A8A7B45153AF7B3D4, 5171ED876E0EC5CAE2BE9161ACC90F4865FF6416EFA376C82D8A5B65724A8910 ] CryptSvc C:\WINDOWS\system32\cryptsvc.dll 05:55:31.0230 0x12dc CryptSvc - ok 05:55:31.0308 0x12dc [ 630470ED6E536352242E7014ADB9DBEE, 8847950F08FB52EEABFC05CBCFF4309FE4A5BE25EFA5EB4B46A73579F14D7109 ] CSC C:\WINDOWS\system32\drivers\csc.sys 05:55:31.0339 0x12dc CSC - ok 05:55:31.0355 0x12dc [ 26FC0AFFBA1051FEF73BBA040ACC6D12, 0BBBFDE91B48844B38B5C9A515D759C9D686CA1C22E835DA306C97CA1C1A1250 ] CscService C:\WINDOWS\System32\cscsvc.dll 05:55:31.0402 0x12dc CscService - ok 05:55:31.0417 0x12dc [ 407AA0793D65322DEFC0A8C56313E917, 26AC0C8019411E23AC33F62ECD12D68E5A959B9FCD7093747A92D3DFD718D045 ] cvusbdrv C:\WINDOWS\System32\Drivers\cvusbdrv.sys 05:55:31.0433 0x12dc cvusbdrv - ok 05:55:31.0433 0x12dc [ 4233BF1BA4FDD55A14DA16BE864B7504, 7B34CD50996D7F1B9636C8CD6612991039C4806B7094CC66CEECBB28E5F8D3F3 ] dam C:\WINDOWS\system32\drivers\dam.sys 05:55:31.0449 0x12dc dam - ok 05:55:31.0449 0x12dc [ D104621C93213942B7B43D65B5D8D33E, 71FE5AF0F1564DC187EEA8D59C0FBC897712AFA07D18316D2080330BA17CF009 ] DBUtilDrv2 C:\WINDOWS\System32\drivers\DBUtilDrv2.sys 05:55:31.0464 0x12dc DBUtilDrv2 - ok 05:55:31.0480 0x12dc [ 70FDCB22DAA406A35244723D45E734C2, 394F030DB0709F578CA696706B7CD3CC0408E5B0882C04C244B3447B37C37E70 ] dc3d C:\WINDOWS\System32\drivers\dc3d.sys 05:55:31.0511 0x12dc dc3d - ok 05:55:31.0558 0x12dc [ 23E572605024008FEB74562A2D483B94, 625B19568C4233DED550F6D43E0DB17F612CD698FD21B609288480B4C3496A3A ] DcomLaunch C:\WINDOWS\system32\rpcss.dll 05:55:31.0605 0x12dc DcomLaunch - ok 05:55:31.0636 0x12dc [ C47E754D781BE6A8AF7283D434FC5873, FACFC0583ADA6442D81A0B3E9755B703664ECA4550EDF55B3B80E9FCDCF373E5 ] DDDriver C:\WINDOWS\System32\drivers\dddriver64Dcsa.sys 05:55:31.0652 0x12dc DDDriver - ok 05:55:31.0714 0x12dc [ 2DAD821A7895EDD70BDF8DF323057E38, 45DE86862A45BCA685A0CCC919690375B4997FA1885774A324AE75BD95149554 ] DDVCollectorSvcApi C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe 05:55:31.0746 0x12dc DDVCollectorSvcApi - ok 05:55:31.0761 0x12dc [ 9C78736C472914A48A8566FEA9AD098C, 366A7DEDDADAC75282472ED8A7D175BE362D773BF4287FCD09B9F8012E4827FF ] DDVDataCollector C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe 05:55:31.0777 0x12dc DDVDataCollector - ok 05:55:31.0792 0x12dc [ 5BBB5DD24233570CF3214306A27439B5, 5643F6687731BA83912384FDC56DD6F4180BAEE655A8D1A9084D42481525CC13 ] DDVRulesProcessor C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe 05:55:31.0824 0x12dc DDVRulesProcessor - ok 05:55:31.0855 0x12dc [ F58B99912057ED256C3331D964CEF2BC, 99E3207E724D73C21CFE67E01AE28797948F40070376A26E9DEBB239075193AF ] defragsvc C:\WINDOWS\System32\defragsvc.dll 05:55:31.0886 0x12dc defragsvc - ok 05:55:31.0949 0x12dc [ 71DFE73D6B05EADA449F9EF3E7C9FE3E, 30A4D05E5147529807C99136E3CD1E16CC84643050C27C1DFB0E3CA0964EEDAD ] DellClientManagementService C:\Program Files (x86)\Dell\UpdateService\ServiceShell.exe 05:55:31.0964 0x12dc DellClientManagementService - ok 05:55:31.0964 0x12dc [ B661B53F80562F415BA5B1D60F1C2FA7, 8EAFEE67324F7A97FE4579445118A7D2C4D93438BF94CF243DBA55DB692AFFF0 ] DellInstrumentation C:\WINDOWS\System32\drivers\DellInstrumentation.sys 05:55:31.0980 0x12dc DellInstrumentation - ok 05:55:31.0996 0x12dc [ 2F5EB7375FC3D9DBB81BDFFE2BCCB9D0, 6D2C01CB29EA220C265D6B24C791D97482D05F1C9FF4C9816FAA3F3E05B42882 ] DellRbtn C:\WINDOWS\System32\drivers\DellRbtn.sys 05:55:31.0996 0x12dc DellRbtn - ok 05:55:32.0058 0x12dc [ 93BA8AE4B2227582C6091FA7FDF7D384, 00A23C9E72937F8EF9A46BFD5D4241C99AB51968A7D03C1B14480F3BEBF908BA ] DellTechHub C:\Program Files\Dell\TechHub\Dell.TechHub.exe 05:55:32.0089 0x12dc DellTechHub - ok 05:55:32.0136 0x12dc [ AEF193F2195ECF8E755F689F95D96718, 9C00296A90530D88349D61B9425FBB77B65CE80EB88B0E85A70420DE09A19B09 ] DeviceAssociationBrokerSvc C:\WINDOWS\System32\deviceaccess.dll 05:55:32.0152 0x12dc DeviceAssociationBrokerSvc - ok 05:55:32.0167 0x12dc [ 8AF8D1A8ACFBFFD65406193CFA4B9B37, CD0833890D34EA425E68B169F915AD61FFDAF29B78D5FA439FD2E8D257DF77D0 ] DeviceAssociationService C:\WINDOWS\system32\das.dll 05:55:32.0199 0x12dc DeviceAssociationService - ok 05:55:32.0230 0x12dc [ 47997A891009AD881DFA69E018D3DF41, 954BBFB9E4C7FF79A811123D31954840590837ECDC9108161717EE29C8EFB676 ] DeviceInstall C:\WINDOWS\system32\umpnpmgr.dll 05:55:32.0277 0x12dc DeviceInstall - ok 05:55:32.0324 0x12dc [ 14279A4BD2CC0F1F5C5AE77A3EFCD604, DBB2B93A2E2C8F006118A11385BF571907032A49C09CE4B7F97B5945EEF7396E ] DevicePickerUserSvc C:\WINDOWS\System32\Windows.Devices.Picker.dll 05:55:32.0402 0x12dc DevicePickerUserSvc - ok 05:55:32.0433 0x12dc [ 807C54C667F7FFD0F150B311168608C3, DCDED1C0A9FE2B7ACA99BA1C9B25DF8FEFFB70E86A14F378755A18D835245EC1 ] DevicesFlowUserSvc C:\WINDOWS\System32\DevicesFlowBroker.dll 05:55:32.0527 0x12dc DevicesFlowUserSvc - ok 05:55:32.0542 0x12dc [ F8BE99B9EA9B110F7CB3F46BA844C1FF, EABF953864C0AE4FB6426C0B7E92DD81EE4A8852081F9D2EA02B61D4C8DB6188 ] DevQueryBroker C:\WINDOWS\system32\DevQueryBroker.dll 05:55:32.0574 0x12dc DevQueryBroker - ok 05:55:32.0589 0x12dc [ E3A2D15717A96F83723D6AA731B553CB, C9A40A41C9ACE0EA1E1E1D566256033C8D494E6B3A5A3AF7CF58A33255C72841 ] Dfsc C:\WINDOWS\system32\Drivers\dfsc.sys 05:55:32.0605 0x12dc Dfsc - ok 05:55:32.0605 0x12dc [ 9593475FBC857A05D93BFF4FA7323C2B, D2A958AF5EFDC6136A6ABB7F8D5FE1F84C967E79BEA96C5BE3661A0145DEB907 ] dg_ssudbus C:\WINDOWS\System32\drivers\ssudbus.sys 05:55:32.0620 0x12dc dg_ssudbus - ok 05:55:32.0636 0x12dc [ F8F5CE7007DF2128D7A6FAB4BB8D8CB8, DB01D1F753DE0142D15775CCF8B0A00FDD37EBBA65011FA7645567AC5D396116 ] Dhcp C:\WINDOWS\system32\dhcpcore.dll 05:55:32.0667 0x12dc Dhcp - ok 05:55:32.0745 0x12dc [ 834FFB6194446D80212613701D50A07D, BF3B5723E80356CAF6777462705398DA52981FC7D80C467AA3BE6A5F06B36887 ] diagnosticshub.standardcollector.service C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe 05:55:32.0777 0x12dc diagnosticshub.standardcollector.service - ok 05:55:32.0792 0x12dc [ 83697F18D13EAE3557EE2A4DEB43C6B0, 1183CBD9B86F4F9999D64E83DA0CBA6B07407B37A91707B8F69AACA5CC6CE574 ] diagsvc C:\WINDOWS\system32\DiagSvc.dll 05:55:32.0839 0x12dc diagsvc - ok 05:55:32.0949 0x12dc [ A974199E2F84A286C768DC85D68E1F9E, EF950E4C5B7CF560053B4CAFC211E2D4423011FAC5CAEF4BD41FF998A05878EC ] DiagTrack C:\WINDOWS\system32\diagtrack.dll 05:55:33.0136 0x12dc DiagTrack - ok 05:55:33.0167 0x12dc [ DD44DBAC8E8CC0D514C02BEFE9A3EB8D, 2BC82CB90E77DD3D0EAA9F89AA6BB820DE47CE6A3DF91FB34B454CC64BA4DCFB ] DialogBlockingService C:\WINDOWS\System32\DialogBlockingService.dll 05:55:33.0230 0x12dc DialogBlockingService - ok 05:55:33.0230 0x12dc [ 953F239FFD563AFA513DBD9BAAF517A9, 1AB271B9E716D7A831AF7ABEE1E83D7AB6135F07321F862B5B2D6982485ECAA1 ] disk C:\WINDOWS\system32\drivers\disk.sys 05:55:33.0245 0x12dc disk - ok 05:55:33.0277 0x12dc [ 88A37D67ACA845EE72E9A07E15273EB1, 21779D6C7B4480873992C13908CFE58568D15073460A88AE452EA1BEE54037EF ] DispBrokerDesktopSvc C:\WINDOWS\System32\DispBroker.Desktop.dll 05:55:33.0308 0x12dc DispBrokerDesktopSvc - ok 05:55:33.0386 0x12dc [ 38D8C032C7AFBA2725A98719C2E03FCE, 43E01AEC265954E5E47EED1F9CA4872A1AEE9DCCE8536993AEA2CD5440BAF2CA ] DisplayEnhancementService C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll 05:55:33.0464 0x12dc DisplayEnhancementService - ok 05:55:33.0495 0x12dc [ 66DD6E2282E1219524E23178CEC81EAD, B7591C1CDD3A5A710FCDB571542D50CF1FDE25B6D363F40E6146B3903BB00B3C ] DmEnrollmentSvc C:\WINDOWS\system32\Windows.Internal.Management.dll 05:55:33.0558 0x12dc DmEnrollmentSvc - ok 05:55:33.0574 0x12dc [ 48AA813AAA7E347CD7D6D56FE32144C6, 6604DC0E7607E46B83F1239934646AC4ADF5CA4CC463FB9DF521B243F434579B ] dmvsc C:\WINDOWS\System32\drivers\dmvsc.sys 05:55:33.0574 0x12dc dmvsc - ok 05:55:33.0589 0x12dc [ 2E8A026D6680C301ADF6D4B301A4CE8B, 2FDB34E2A61457308B0FEC938A2D6351F63D02BB67DC87FE4F2534E0048C8E89 ] dmwappushservice C:\WINDOWS\system32\dmwappushsvc.dll 05:55:33.0636 0x12dc dmwappushservice - ok 05:55:33.0652 0x12dc [ 082A4CA4629513C8BB1D9C26013C3B0B, CD5F42EC6D6140CDB9E56969AE52FEB759A31B6E45D0EA6D5CC04B4E64AEB3C2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll 05:55:33.0699 0x12dc Dnscache - ok 05:55:33.0730 0x12dc [ 41F0771FFA096C6442963E3DDC62397B, 51EF96A78622098FF42B4557BD4EF1E3211EE6A28A0BBDC0947B4F7A3593B4AA ] dot3svc C:\WINDOWS\System32\dot3svc.dll 05:55:33.0761 0x12dc dot3svc - ok 05:55:33.0792 0x12dc [ 9E65C33CB7FB50453F7F4407070EAF53, A8707BD19D584DAECA39990A2E791194140AFCA4FCE31F23CC7E931DF8C17361 ] DPS C:\WINDOWS\system32\dps.dll 05:55:33.0824 0x12dc DPS - ok 05:55:33.0824 0x12dc [ 6ADB3F56899519673D735C3C09476234, 8A97F4C5FC8BB83C819409B1E3F70F87D13034B9E6F8F0A041E38ADAADED1D8D ] drmkaud C:\WINDOWS\System32\drivers\drmkaud.sys 05:55:33.0839 0x12dc drmkaud - ok 05:55:33.0902 0x12dc [ 9AA648CBBC95D90F4AB1AC025994ACE5, A1299C9EBBE00ECC4B21CDA43B9AB58BCFE402B5EE9E8553818AE12E02411A18 ] DSAService C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAService.exe 05:55:33.0933 0x12dc DSAService - ok 05:55:33.0964 0x12dc [ A72341F2CB44C11FB82DE47A9AA4A54F, 8831EF87E27CF515ABC97B11ABBADBB40AAE090150EB2EBCC34FF31A156B83AE ] DSAUpdateService C:\Program Files (x86)\Intel\Driver and Support Assistant\DSAUpdateService.exe 05:55:33.0980 0x12dc DSAUpdateService - ok 05:55:33.0995 0x12dc [ 25260949377D51A7DF55CC4116D1E328, 3C0FE5F039318C57C06FE733FAC00C2753B25905833DC4D76304757EBA5155A5 ] DsmSvc C:\WINDOWS\System32\DeviceSetupManager.dll 05:55:34.0027 0x12dc DsmSvc - ok 05:55:34.0058 0x12dc [ 4B903583999E571ED2B3B1CB6D694605, 30B4DD37228E0FE50C200F511505C09D3FD5B3395E5AE49931E752463424C302 ] DsSvc C:\WINDOWS\System32\DsSvc.dll 05:55:34.0074 0x12dc DsSvc - ok 05:55:34.0105 0x12dc [ 81DF23EC4009D307479D5C169539CD67, 65AEE1E876CBE801A763F14930D15CF2E6A10697620B5903AA04BA30585A5676 ] DusmSvc C:\WINDOWS\System32\dusmsvc.dll 05:55:34.0120 0x12dc DusmSvc - ok 05:55:34.0214 0x12dc [ A5418EB5247CC04A372716436E6F1A65, C5EEA6C76A42A22D990D556A0AF1B43845FD6E68F50E5D101BA92E0D8039ECC7 ] DXGKrnl C:\WINDOWS\System32\drivers\dxgkrnl.sys 05:55:34.0323 0x12dc DXGKrnl - ok 05:55:34.0448 0x12dc [ E74F6A1D1912DEFC571A2D7CE81613A8, 9DBB2813E645A2F97114DFA2D83556FDFB0F460C0766A7B7B3B60EDADE5D234D ] e1dexpress C:\WINDOWS\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_63a4db11c926c9ab\e1d68x64.sys 05:55:34.0480 0x12dc e1dexpress - ok 05:55:34.0511 0x12dc [ AF7B5676A104F8A7D87DDA84DDFD5240, C89BE2506C647924E94FA2F44AA4AF9EAA2F794FA444C8854FEA5B3F563AC185 ] Eaphost C:\WINDOWS\System32\eapsvc.dll 05:55:34.0573 0x12dc Eaphost - ok 05:55:34.0667 0x12dc [ E7B7E38AD720352CFE9A5FF3A82AB124, 48D9F61E943A7855562950FF26B866BD51A27D980757B065504FCD3F1A1D6F07 ] ebdrv C:\WINDOWS\system32\drivers\evbda.sys 05:55:34.0808 0x12dc ebdrv - ok 05:55:34.0902 0x12dc [ 608EE5E04B780CA18E9266C0CE7DA3B2, 945F276F4055CBC95DD9DBD29AEEC98EC746410BE0A082E59BB97454CCF1FC98 ] edgeupdate C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe 05:55:34.0917 0x12dc edgeupdate - ok 05:55:34.0933 0x12dc [ 608EE5E04B780CA18E9266C0CE7DA3B2, 945F276F4055CBC95DD9DBD29AEEC98EC746410BE0A082E59BB97454CCF1FC98 ] edgeupdatem C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe 05:55:34.0948 0x12dc edgeupdatem - ok 05:55:34.0948 0x12dc [ 289D6A47B7692510E2FD3B51979A9FED, 0777FD312394AE1AFEED0AD48AE2D7B5ED6E577117A4F40305EAEB4129233650 ] EFS C:\WINDOWS\System32\lsass.exe 05:55:34.0964 0x12dc EFS - ok 05:55:34.0964 0x12dc [ 75335F1918D78A10B8DBD220F394FA75, 7F5E80B866BAF62CD4A5667F91F05B6AF094BE2EBD4067BBBABA7A9C1C1E6ECB ] EhStorClass C:\WINDOWS\system32\drivers\EhStorClass.sys 05:55:34.0980 0x12dc EhStorClass - ok 05:55:34.0980 0x12dc [ 9F04CF369B93A78B2E56A3DF9B41F25F, 514A0687D2ABE6C52D6BFF8F0F5E47DD77EBEEDC4E6C6539B05BD0EC27B6704D ] EhStorTcgDrv C:\WINDOWS\system32\drivers\EhStorTcgDrv.sys 05:55:34.0995 0x12dc EhStorTcgDrv - ok 05:55:35.0011 0x12dc [ 48066A0A516271CF80868075216A7A41, DEC15E25420771EC4CB2D724D5F5B8627E9DFA3F56C4ACFFB01D8DF688D3617F ] embeddedmode C:\WINDOWS\System32\embeddedmodesvc.dll 05:55:35.0042 0x12dc embeddedmode - ok 05:55:35.0058 0x12dc [ F908856AE753EB97C23BACBECBAAEB4B, 93A64E8FD789952F7B566B54EE6D5F0ED5D5A2D4F0FAD7BDB46A9A9AF44671E1 ] EntAppSvc C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll 05:55:35.0120 0x12dc EntAppSvc - ok 05:55:35.0120 0x12dc [ E87F3FA1F9133DEEC1B3692976487777, BF14DB2762B48ACE54977E98DC2A4060B8B1122B58FDEFBB4C84546ABEB410A5 ] ErrDev C:\WINDOWS\System32\drivers\errdev.sys 05:55:35.0136 0x12dc ErrDev - ok 05:55:35.0245 0x12dc [ 0D7FFA6EE41573BA959DD57523739346, C5D856F0D9D5094BF38B0ADAE43338FBBA01E94B37E2CF5A532406EA9E8CA35D ] EventLog C:\WINDOWS\System32\wevtsvc.dll 05:55:35.0355 0x12dc EventLog - ok 05:55:35.0386 0x12dc [ 75AE3ECE8595A1BED76FFE607CBD5955, 375E0841098237B29CA57D7B4144638C67B0471CEEE33F998AD42A7E1BBAA069 ] EventSystem C:\WINDOWS\system32\es.dll 05:55:35.0417 0x12dc EventSystem - ok 05:55:35.0573 0x12dc [ 388C53EA4C612248566E42C85BEA2766, B02E417A7F206A72125705E5D784B22148BD10CACA2B597C81416A79314EE275 ] EvtEng C:\Program Files\Intel\WiFi\bin\EvtEng.exe 05:55:35.0589 0x12dc EvtEng - ok 05:55:35.0605 0x12dc [ 0BF32186C3EC11315C33CC29EA8DD86C, 82B43762A5BC9C0AB7B5D1F96DC47B34700924B598070A7CCB30C92EB5EE1599 ] ew_usbccgpfilter C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys 05:55:35.0683 0x12dc ew_usbccgpfilter - ok 05:55:35.0698 0x12dc [ FED99A20C3FCDA25A9877802D141092B, 3ECDB2094BFFD6D20FDC2690527714CD847BC09B7C30EFB3ED26F48F3EECF1C6 ] exfat C:\WINDOWS\system32\drivers\exfat.sys 05:55:35.0714 0x12dc exfat - ok 05:55:35.0730 0x12dc [ A3F919FCE55CA04BC5C970E217B155D7, F2666E697F43C525CD572FDA5EF83AD1F427BE1A60B4A4AEB75DEFDE38096B89 ] fastfat C:\WINDOWS\system32\drivers\fastfat.sys 05:55:35.0745 0x12dc fastfat - ok 05:55:35.0855 0x12dc [ 8C6D3BF6997E02544BE68D43DABE2F39, 37AD465000051B55553C1945318C66415FFFC40872B2BB5B25AB0480349F3850 ] Fax C:\WINDOWS\system32\fxssvc.exe 05:55:35.0948 0x12dc Fax - ok 05:55:35.0948 0x12dc [ F567A0C101AECF4548E0BF61EE25D332, 26BC9C2F1D42CE5BEF55E98DC0DA557F09B747186580C796003CF84229F6D151 ] fdc C:\WINDOWS\System32\drivers\fdc.sys 05:55:35.0964 0x12dc fdc - ok 05:55:35.0980 0x12dc [ 0439B82F6034ADA3E71C0C9F169082BD, 0918728669077235B2F2DB7EE22CE819FA570D8A7A497BA5F11E76774EA75099 ] fdPHost C:\WINDOWS\system32\fdPHost.dll 05:55:36.0011 0x12dc fdPHost - ok 05:55:36.0026 0x12dc [ AD64C91B3CC71226785DCE688842E5AB, 056E1091468D268E7970045AB329EB3DFF48BB6B22448046A14C309678847B6E ] FDResPub C:\WINDOWS\system32\fdrespub.dll 05:55:36.0042 0x12dc FDResPub - ok 05:55:36.0058 0x12dc [ 3AA883D460D1A6169A2A654C9596172F, 737195664878BBB629F731DC9805754FD42CABA36F9D72EAF562DDCC3E7AD567 ] fhsvc C:\WINDOWS\system32\fhsvc.dll 05:55:36.0105 0x12dc fhsvc - ok 05:55:36.0105 0x12dc [ 8E59D944EE4EFAED65A341A71297C4CD, CFFFD7007AB7FB04ECB44D0079BFE8EEB53AECC988135199C388AF425EBCF2AD ] FileCrypt C:\WINDOWS\system32\drivers\filecrypt.sys 05:55:36.0151 0x12dc FileCrypt - ok 05:55:36.0151 0x12dc [ EE7605E60374CBD2DDAAA120FA2E458A, 832BF32B9EFA04FBDD9638D00B209DFC88C4C69E0AEC7FF1B5AD4DDEC0F20878 ] FileInfo C:\WINDOWS\system32\drivers\fileinfo.sys 05:55:36.0167 0x12dc FileInfo - ok 05:55:36.0167 0x12dc [ C7F6F4B73E410087C6DE5658AAD70232, 42C56B93FF52CAC5B74CE0A16D9D4425E8B3E690B3BD76A5A3C657655B62A34A ] Filetrace C:\WINDOWS\system32\drivers\filetrace.sys 05:55:36.0183 0x12dc Filetrace - ok 05:55:36.0183 0x12dc [ C867FE1865F45469DD96957900073361, 1534A840C56912D34DEC8F487683C0A782070A89726BF87DFAAF7F953A18A1DA ] flpydisk C:\WINDOWS\System32\drivers\flpydisk.sys 05:55:36.0198 0x12dc flpydisk - ok 05:55:36.0214 0x12dc [ CDE9E75A5A330689B0E888D2949892D1, 3E2E32F57BB036C6783EB373E66E323338551692D04DA73EB353C0AEE9D87D2B ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys 05:55:36.0230 0x12dc FltMgr - ok 05:55:36.0308 0x12dc [ ABE7915F35A98A65BD53E71E71D5D37A, 0615FB9D48FC85481B6348BC7250B54E3FD4B4E5C3333572BB98B898DF57B891 ] FontCache C:\WINDOWS\system32\FntCache.dll 05:55:36.0386 0x12dc FontCache - ok 05:55:36.0573 0x12dc [ 91857D4F6633493CF03C22BD86ED7F81, 80982C4DA12FDD501C234782A14243DFFA8AA4D6EB94BA5E37E3575ADE53000D ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 05:55:36.0589 0x12dc FontCache3.0.0.0 - ok 05:55:36.0620 0x12dc [ A3CCAE333F3637080D5E3DD984EA4985, 067EE83B82B524802EB8954B631A055101E980A19DD359224EDC501E7E493A0B ] FrameServer C:\WINDOWS\system32\FrameServer.dll 05:55:36.0683 0x12dc FrameServer - ok 05:55:36.0698 0x12dc [ D444357297A81C6A23BFF8090F03DBC7, A5BBD7AC9F33D59DA8DB084E24EB7DA9EC76BB25A27A511FF0271EFC9B590A7D ] FsDepends C:\WINDOWS\system32\drivers\FsDepends.sys 05:55:36.0698 0x12dc FsDepends - ok 05:55:36.0714 0x12dc [ A3631ADDD926826110A436D6A04B31CA, 2073327E5C1E542EA2740CA0D43204940EB72652619B5209A2E4A4A0FB18D20A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys 05:55:36.0714 0x12dc Fs_Rec - ok 05:55:36.0745 0x12dc [ AB7418C8DFBBB97BEFB4F0ADED3D4663, 3BD5BB7E646E67469EC25A37CAA5131CF992759703B0FC170DF7AF265B9F8E74 ] FTDIBUS C:\WINDOWS\system32\drivers\ftdibus.sys 05:55:36.0745 0x12dc FTDIBUS - ok 05:55:36.0761 0x12dc [ B66678FF4E347E22146609B3D5B7B2C4, 7A303AA880CC746D13F71E565874FB7C174747372CCF358B928A72219D2A50DD ] FTSER2K C:\WINDOWS\system32\drivers\ftser2k.sys 05:55:36.0761 0x12dc FTSER2K - ok 05:55:36.0792 0x12dc [ 13304174CA218DCD2168DEBAFF8B2471, F992DD573190DC93D0999301BC235556C48483DD8FABE40FFE02F4F19C1C7EF5 ] fvevol C:\WINDOWS\system32\DRIVERS\fvevol.sys 05:55:36.0823 0x12dc fvevol - ok 05:55:36.0839 0x12dc [ A1E06E4E8CB863C74DE428D4D6681185, DA46502C009FD4C847A547610DEE2684A5A583467BF76009BD46104AAE2F6B1B ] gencounter C:\WINDOWS\System32\drivers\vmgencounter.sys 05:55:36.0839 0x12dc gencounter - ok 05:55:36.0933 0x12dc [ DF2344160D1E58AB5E1DDB174D46853D, B263D352479812A4DEB6BB8AF573150491EA9F5D55DCD00185AF6759FF2601F6 ] genericusbfn C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys 05:55:36.0964 0x12dc genericusbfn - ok 05:55:37.0089 0x12dc [ 006D37F122E848E0CB38777AC2884419, EDC25C68C42FF3A7DDEF973CCDFF035D6ED6149AAAA908939C58B7F71144A867 ] GoogleChromeElevationService C:\Program Files\Google\Chrome\Application\108.0.5359.71\elevation_service.exe 05:55:37.0151 0x12dc GoogleChromeElevationService - ok 05:55:37.0151 0x12dc [ E0C0B02E56EE1E639CA3928F55D59D59, 1019FF6F1B423CBF1512F15EA72536F93D0380B052D5C679313F5FFF8BB0A4DF ] GPIOClx0101 C:\WINDOWS\system32\Drivers\msgpioclx.sys 05:55:37.0167 0x12dc GPIOClx0101 - ok 05:55:37.0214 0x12dc [ EA9E9444D9E00A55433F12E8985DBED6, 49545521A549B9F045CF2DEE0EDA41DEEAB3F37E20735D7F905276B5F8980481 ] gpsvc C:\WINDOWS\System32\gpsvc.dll 05:55:37.0292 0x12dc gpsvc - ok 05:55:37.0308 0x12dc [ 8C06046B6A8C1ACDAEA15682058FDFB4, 3E0CC301249B7D8D5BEB932F4DFD1EAB8037679EC153772F63B430713903B0AC ] GpuEnergyDrv C:\WINDOWS\system32\drivers\gpuenergydrv.sys 05:55:37.0323 0x12dc GpuEnergyDrv - ok 05:55:37.0339 0x12dc [ 98C05369D9E8AFF249F6AB0837E87912, 7C059098A69C513CB93BF15583C9D11E4E83096FB94FD5C46584E74A988D6828 ] GraphicsPerfSvc C:\WINDOWS\System32\GraphicsPerfSvc.dll 05:55:37.0355 0x12dc GraphicsPerfSvc - ok 05:55:37.0401 0x12dc [ 54A010C60BE10B65EEE5506720FCCABB, 9A4B728A0B652056CBD312DD917ADC08C72C89B6F666472F4E3D59A1B8039D89 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 05:55:37.0417 0x12dc gupdate - ok 05:55:37.0433 0x12dc [ 54A010C60BE10B65EEE5506720FCCABB, 9A4B728A0B652056CBD312DD917ADC08C72C89B6F666472F4E3D59A1B8039D89 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe 05:55:37.0448 0x12dc gupdatem - ok 05:55:37.0448 0x12dc [ 6A3D89AC2F01A375CC6F12FEC588EFC9, 3BAB7BEB30ED64634587B6EBE625FB78A8C58058AED4151FF83231E0D5CBEFDE ] HdAudAddService C:\WINDOWS\System32\drivers\HdAudio.sys 05:55:37.0480 0x12dc HdAudAddService - ok 05:55:37.0495 0x12dc [ 4F39254C6E087D4789D2C3EBD3C7F744, 8500B5163642DF294E4039592A8FD959470989B32C1C42735583B25A67DD2EB7 ] HDAudBus C:\WINDOWS\System32\drivers\HDAudBus.sys 05:55:37.0526 0x12dc HDAudBus - ok 05:55:37.0620 0x12dc [ B9346EC7AFF954BB77B43CCE5A0DF6FD, 860C87490EB9AC32A763829C3A47AB422535E18CEE2ECB71E2AEB9DDC4A579C6 ] HfcDisableService C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_ecb9604542bb4ba6\HfcDisableService.exe 05:55:37.0683 0x12dc HfcDisableService - ok 05:55:37.0683 0x12dc [ 05FC1B768ACB2D5CADDCA2F2E89F579C, D773640F980BF832D74FBB5E19FC1FFC06F9401C10698C0C26CFB7C067F3DB73 ] HidBatt C:\WINDOWS\System32\drivers\HidBatt.sys 05:55:37.0698 0x12dc HidBatt - ok 05:55:37.0698 0x12dc [ BAA82FAEFCCA50270C6F38D4108403A3, 7704F6F7716D9DF1C3CD81A228B361574A5783DC89A8DFE9B27318EBE3131345 ] HidBth C:\WINDOWS\System32\drivers\hidbth.sys 05:55:37.0714 0x12dc HidBth - ok 05:55:37.0729 0x12dc [ 1E129E905072A79282D6CC929284DFE5, C161D2122638690CE4DA546CE8827B4BBD96747A4A7D799A776FEC5BC57D1582 ] hidi2c C:\WINDOWS\System32\drivers\hidi2c.sys 05:55:37.0761 0x12dc hidi2c - ok 05:55:37.0761 0x12dc [ 1E9F3C9B201614CF4816C5D5B6C570D8, 60CF06F1668FFFB870E76D8231A090AB3AD7EA44F1F45A36FC28814CC845B94D ] hidinterrupt C:\WINDOWS\System32\drivers\hidinterrupt.sys 05:55:37.0776 0x12dc hidinterrupt - ok 05:55:37.0776 0x12dc [ 6B46E3061EC0523CB46ED28060FCD946, 6089305AF73CC584963865482448CD5CA4252EC9BD3E72AF16D45E4F95C3EBF2 ] HidIr C:\WINDOWS\System32\drivers\hidir.sys 05:55:37.0792 0x12dc HidIr - ok 05:55:37.0808 0x12dc [ 2A41AF60430E686985E9101C07A77B80, 2B6EC0692A09E5943C5BBA0E3AEFC746E96412E1836C84B1857B4DCF242DD28B ] hidserv C:\WINDOWS\system32\hidserv.dll 05:55:37.0823 0x12dc hidserv - ok 05:55:37.0839 0x12dc [ 8E8C163D599B0F075841893DB1CAFB4B, EBE1B4498E2214AFD03B6FD8BEF52E07017A45BC7AB1501BA4BEC563C2F16F0D ] hidspi C:\WINDOWS\System32\drivers\hidspi.sys 05:55:37.0854 0x12dc hidspi - ok 05:55:37.0854 0x12dc [ F59F3C6CAD709A8EFAFC60F989A466EC, 3D7E7BCE4A5654AEEC62482C850869E20A1AB505B16BD690BA63886C20F25D1D ] HidUsb C:\WINDOWS\System32\drivers\hidusb.sys 05:55:37.0870 0x12dc HidUsb - ok 05:55:37.0870 0x12dc [ 530C0E730B5E6BA332FB4AC98F760789, 0ADE20523619D5705B941591DF0C19D6B0030F96FECEBBC7A4ADEF963A476383 ] HpSAMD C:\WINDOWS\system32\drivers\HpSAMD.sys 05:55:37.0886 0x12dc HpSAMD - ok 05:55:37.0917 0x12dc [ 04ED39F4A34EAFCCAEAA43D0783C4291, E1AEF623C8B6A15B557FAD3814898FB0BF6D5230574F83D1326F23FB57861CBF ] HTTP C:\WINDOWS\system32\drivers\HTTP.sys 05:55:37.0979 0x12dc HTTP - ok 05:55:37.0979 0x12dc [ 849A66D34BC2DAD0044FAC2FEE1AF956, A5F6858AA556D9180C303EA3ED02EB6D6D8EB55A100B3918654281A01198D8E8 ] hvcrash C:\WINDOWS\System32\drivers\hvcrash.sys 05:55:37.0979 0x12dc hvcrash - ok 05:55:38.0011 0x12dc [ 855F55BB462B7D8B6BC31A94A592DF3D, 776C772E69CF9D81D8511201813DD79F2106DC7D2547B4FA700432AE9B73C202 ] HvHost

Continua:

C:\WINDOWS\System32\hvhostsvc.dll 05:55:38.0026 0x12dc HvHost - ok 05:55:38.0026 0x12dc [ 508B8DCE8AD4CC1105B3C3C84F084B8A, AC04205FB611D53323C8E3CB44F2C1E6BB0A3E95AF8178ADD3D4B30C6BFB54AB ] hvservice C:\WINDOWS\system32\drivers\hvservice.sys 05:55:38.0042 0x12dc hvservice - ok 05:55:38.0058 0x12dc [ 8CF9D085951CF0D6DE2AC4105E440DE0, 300198709982026EF999CE5B341EC2BDB23351D8B4BD03C0190EE21F953CBF85 ] HWHandSet C:\WINDOWS\System32\drivers\hw_quusbmdm.sys 05:55:38.0151 0x12dc HWHandSet - ok 05:55:38.0151 0x12dc [ 5DC7DFED5FEDD923B874B51D0C6752BB, 69714A8B74EB02282572B34E156051FFC10693B816905CE18A8C6C8CCB95B846 ] HwNClx0101 C:\WINDOWS\system32\Drivers\mshwnclx.sys 05:55:38.0183 0x12dc HwNClx0101 - ok 05:55:38.0198 0x12dc [ D734926DC33F9D7E306F8B3BF68EAC57, F1CCE47AEC0E653CA6DC04C21CBC78EC6C6D74D4BF329D50BE9A7497ADD1FB3F ] hwpolicy C:\WINDOWS\system32\drivers\hwpolicy.sys 05:55:38.0198 0x12dc hwpolicy - ok 05:55:38.0214 0x12dc [ C6FCF40CFF3B8380723BD61158AF111E, 5758A0814CA8AA1E7447E1CBDF94352266EDEEE547AB896FCFF97727D8ECDE53 ] hwusb_cdcacm C:\WINDOWS\System32\drivers\hw_cdcacm.sys 05:55:38.0245 0x12dc hwusb_cdcacm - ok 05:55:38.0261 0x12dc [ 7920776AB1C59BD6EC70424952CC5FD4, FF4CFCE77613703BA1F5C58AF366CF96E982F6CB5DBCDA30173F957FD1117A74 ] hw_usbdev C:\WINDOWS\System32\drivers\hw_usbdev.sys 05:55:38.0308 0x12dc hw_usbdev - ok 05:55:38.0323 0x12dc [ 22362F7C8B7B1456DDF019BFB0523C26, 3DCA435A621FC3CD786E02D013B363ADA9399839E0A31F2969E094F69AD3A183 ] hyperkbd C:\WINDOWS\System32\drivers\hyperkbd.sys 05:55:38.0323 0x12dc hyperkbd - ok 05:55:38.0323 0x12dc [ BE7559280E3327E9B35E843414957438, 157D5626090149A2F71BB483C57CB20259B98C61C35185AA7C6FCD533ABE7D90 ] HyperVideo C:\WINDOWS\System32\drivers\HyperVideo.sys 05:55:38.0339 0x12dc HyperVideo - ok 05:55:38.0339 0x12dc [ E4B36C6EAAAB703CBFECB92EE590FB31, E1887A4E678BBA7226E7EBE5B49EC821C2F23642D321A9E1513F7477E4B9340D ] i8042prt C:\WINDOWS\System32\drivers\i8042prt.sys 05:55:38.0354 0x12dc i8042prt - ok 05:55:38.0370 0x12dc [ 9E5AECAB5F05218D9AC923E7CEA1CE15, FAAA46F22944E043A90AE6E9F0F86AF187FC2819C563DA375B2A409347BB2C35 ] iagpio C:\WINDOWS\System32\drivers\iagpio.sys 05:55:38.0370 0x12dc iagpio - ok 05:55:38.0386 0x12dc [ 48EDB9B5DAB7D294951A520330F13715, 9296A14590DFD94A3C728CAF3CA91BA211F27974F9CFF8417CDDC00D1453315C ] iai2c C:\WINDOWS\System32\drivers\iai2c.sys 05:55:38.0401 0x12dc iai2c - ok 05:55:38.0401 0x12dc [ 6C3EDE394C71D5A67A504F55E35B6F47, 6FF5D13EF69E8FBCB4772C7B5C4D5770C78E0B29F9164FA1611EFDE91CE876BE ] iaLPSS2i_GPIO2 C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys 05:55:38.0433 0x12dc iaLPSS2i_GPIO2 - ok 05:55:38.0448 0x12dc [ 806D14CEAF25E5F2DFCBA8E7E33B86BB, 2141DE558461B592D4111A0388D1AAC8062FA72CD1E2A2D2D68279A9633288E9 ] iaLPSS2i_GPIO2_BXT_P C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys 05:55:38.0479 0x12dc iaLPSS2i_GPIO2_BXT_P - ok 05:55:38.0495 0x12dc [ 87DDDAE1693484BD0A210C877BDA00C2, E353D90D0B79A70F976FD5EA1CB7E25A97835E25116962EA035424715B2F43FE ] iaLPSS2i_GPIO2_CNL C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys 05:55:38.0511 0x12dc iaLPSS2i_GPIO2_CNL - ok 05:55:38.0511 0x12dc [ 8D3E3C431367E3BA632B4396CA662E1A, 71FDC25244298D62A335769D6ED43394C33FBD8DB05AA54CA924A2977F37858F ] iaLPSS2i_GPIO2_GLK C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys 05:55:38.0526 0x12dc iaLPSS2i_GPIO2_GLK - ok 05:55:38.0558 0x12dc [ 149F1260537C4F68C3F67C363B62F3C5, 3F1F9EC7571D0F82D3F5BBA298965491260708F05EBAAA2CC23483521A5FF079 ] iaLPSS2i_I2C C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys 05:55:38.0589 0x12dc iaLPSS2i_I2C - ok 05:55:38.0604 0x12dc [ 3E641E905A6DBF29CBA1E72BBE349808, BF354297A55713D9E2DD4044D42810C007733EE54D5A80D58B96DD279D92C716 ] iaLPSS2i_I2C_BXT_P C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys 05:55:38.0636 0x12dc iaLPSS2i_I2C_BXT_P - ok 05:55:38.0636 0x12dc [ 897478D8FACEAE8681F6F3502201EC68, F105EDD16E38F5C0044CC7139E4084A04B0AE3212171A1C7F6FE759F3F5F77FC ] iaLPSS2i_I2C_CNL C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys 05:55:38.0651 0x12dc iaLPSS2i_I2C_CNL - ok 05:55:38.0667 0x12dc [ 2ED3B41C7CB4101ACB15D84D8AB5AA9D, A92487129B81376471C842B9932FF3A7B3ABBBB89797978E3FDEAF71A6FD5E3F ] iaLPSS2i_I2C_GLK C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys 05:55:38.0683 0x12dc iaLPSS2i_I2C_GLK - ok 05:55:38.0683 0x12dc [ 16A10CCEDCF5AC4CAAE43DC9FC40392F, F77696AE55B992154A3B35F7660BD73E0AB35A6ECEEC1931C0D35748CFA605C0 ] iaLPSSi_GPIO C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys 05:55:38.0698 0x12dc iaLPSSi_GPIO - ok 05:55:38.0698 0x12dc [ EB82A11613326691508D9ED9A4FE29E7, 8445E41BAB21964C7F014742795E462BDDC6C37A261990B3D6BF4E637A719547 ] iaLPSSi_I2C C:\WINDOWS\System32\drivers\iaLPSSi_I2C.sys 05:55:38.0714 0x12dc iaLPSSi_I2C - ok 05:55:38.0776 0x12dc [ 12859E1215AA083A42E7ADCDE5C061D1, 262F9C65C3FA7EB69C4FA7C6547E1C79DB49697A083309909BC78726A116557F ] iaStorA C:\WINDOWS\system32\drivers\iaStorA.sys 05:55:38.0823 0x12dc iaStorA - ok 05:55:38.0854 0x12dc [ 1910AA9F3343925B0C900C7A424C4E0C, 4F8BB4D51FBC3CAB6532C602B6D46630C7270D05098CB87E5D9D13385C4DF359 ] iaStorAC C:\WINDOWS\system32\drivers\iaStorAC.sys 05:55:38.0886 0x12dc iaStorAC - ok 05:55:38.0917 0x12dc [ FCC320C72B5E8336932FD5C166756E13, 8149E66E3641F28F325A4BBE25176A6E515CFAB7AA256310789B730AE4E43AC2 ] iaStorAfs C:\WINDOWS\System32\drivers\iaStorAfs.sys 05:55:38.0917 0x12dc iaStorAfs - ok 05:55:39.0026 0x12dc [ 8395340EEB68C394EF5596421EDC23FF, FD2B6D04CBB5B7E087B1924CA7B4C4F01F9D45AE4DD3EAAD426C623034DD5A6C ] iaStorAfsService C:\WINDOWS\System32\iaStorAfsService.exe 05:55:39.0136 0x12dc iaStorAfsService - ok 05:55:39.0167 0x12dc [ E2E64636CD6A6902BD81AC3B90089484, 7274F33E5EED8AF739FFCC80B9A62CDF12553EBD2724E2F8E93FD67376CC6E84 ] iaStorAVC C:\WINDOWS\system32\drivers\iaStorAVC.sys 05:55:39.0198 0x12dc iaStorAVC - ok 05:55:39.0214 0x12dc [ 215525477CBDCD07A82AC518BAE3DEC3, 30BEE94794953E2DBF0FC5AFCE0566F335AF022E89819DE145329E7C09C636BD ] iaStorV C:\WINDOWS\system32\drivers\iaStorV.sys 05:55:39.0245 0x12dc iaStorV - ok 05:55:39.0261 0x12dc [ 329F2FEC47FD8754FC44A8F3F283C915, 0F3E4F33B019B278B6657B4ECEC25D04B128578622539FF5855330BDB6537545 ] ibbus C:\WINDOWS\System32\drivers\ibbus.sys 05:55:39.0276 0x12dc ibbus - ok 05:55:39.0276 0x12dc ibtsiva - ok 05:55:39.0292 0x12dc [ 3501750E1D543A5C6A32D1ED5BBAA125, 95D351DEB154BC4B5A4F4D477D945845218736E35C776264BA549471E37D3CF4 ] ibtusb C:\WINDOWS\system32\DRIVERS\ibtusb.sys 05:55:39.0308 0x12dc ibtusb - ok 05:55:39.0339 0x12dc [ 933AB796194214F99353FE2525942BC9, 12AD73C3C3D5354AFF5284590288D3C664F40AA2437FBCB619F90C2F678CF9A3 ] icssvc C:\WINDOWS\System32\tetheringservice.dll 05:55:39.0354 0x12dc icssvc - ok 05:55:39.0526 0x12dc [ 031463C9451E5503A05807CDAF93B71A, A78BBE0E6882A97BF02A0CD032CA8394F9383FDEB200E4D59C43E887F9733A3D ] igfx C:\WINDOWS\system32\DRIVERS\igdkmd64.sys 05:55:39.0714 0x12dc igfx - ok 05:55:39.0776 0x12dc [ 471DEA24F41BF0577300B7952A7AE4A2, FC5E4049AD0BD0ED8366FAC57728C9941CD5C6619388944C9105F699903BFB55 ] igfxCUIService2.0.0.0 C:\WINDOWS\system32\igfxCUIService.exe 05:55:39.0792 0x12dc igfxCUIService2.0.0.0 - ok 05:55:39.0823 0x12dc [ F82BDF1B599BAF9A41EEB83E95E7F4EA, 3B6985A11CD3AD1F62FDBAB131E7D4D9D2B04D9CE914C42B2D4FEC0211283925 ] IKEEXT C:\WINDOWS\System32\ikeext.dll 05:55:39.0901 0x12dc IKEEXT - ok 05:55:39.0901 0x12dc [ 9B943585EF2A4917E1BC2186045E4B64, 2F4FE50C3ABB7A37E0ADB4429F18B8067EDE0608BC4539BAC626C2C6D75844B7 ] IndirectKmd C:\WINDOWS\System32\drivers\IndirectKmd.sys 05:55:39.0932 0x12dc IndirectKmd - ok 05:55:40.0026 0x12dc [ 5F025535261CE512CB01A39947D9DE09, 892F204975D1D696EC617EE8A528198DA00CE0610CA4C130C4A536D6652A3B34 ] InstallService C:\WINDOWS\system32\InstallService.dll 05:55:40.0151 0x12dc InstallService - ok 05:55:40.0245 0x12dc [ 1326E472568EAE256147F336E3F2FB64, 12148F0EEF5D4EF7B0DEF5808BE123A53BD024832DF1E4AA42063E4983C367AE ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RTDVHD64.sys 05:55:40.0339 0x12dc IntcAzAudAddService - ok 05:55:40.0370 0x12dc [ EAE20DB9DC1366B9A1C558C58229AD65, 966D79304A766DD38EAB1B7B71DDE0ECB23323C07F29C8CBB21EA94654F75DF1 ] IntcDAud C:\WINDOWS\System32\drivers\IntcDAud.sys 05:55:40.0386 0x12dc IntcDAud - ok 05:55:40.0479 0x12dc [ A0B66872DCF1BD5FDF5E26595D3A4A51, 76243493FB7CEAB10B540B693BB7E887F1F78B060FB339A99D4D5741A834B9D8 ] Intel(R) Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe 05:55:40.0511 0x12dc Intel(R) Capability Licensing Service TCP IP Interface - ok 05:55:40.0526 0x12dc [ D087B3CE15760ACEE7C09E99052DF197, 0C636DF08D58E319E570DFF961DD7D23985DD6A8E3008F13693A4BAA79B925F7 ] Intel(R) TPM Provisioning Service C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe 05:55:40.0542 0x12dc Intel(R) TPM Provisioning Service - ok 05:55:40.0557 0x12dc [ 1C05B2A3D4698256421A4B35D9DDFBAE, AA618C98778E941E471BC9CE865058A0EEB42BFDCD7A4E0D421DE156ADE5C40E ] intelide C:\WINDOWS\system32\drivers\intelide.sys 05:55:40.0557 0x12dc intelide - ok 05:55:40.0573 0x12dc [ 4B8355CFE8040201551215F760B051A8, 5D6958F2C527D465AED88B6604F9527B4612B4B5BC4F9F234E5200DEF7438BAD ] intelpep C:\WINDOWS\system32\drivers\intelpep.sys 05:55:40.0604 0x12dc intelpep - ok 05:55:40.0604 0x12dc [ AECBF5BE2F9A2A50B978E0BF31041A81, A62F436C66DEFEB438A7891857DFB830995714A7E4FE4BDCA6B4EB1606BD2101 ] intelpmax C:\WINDOWS\System32\drivers\intelpmax.sys 05:55:40.0620 0x12dc intelpmax - ok 05:55:40.0620 0x12dc [ 17F028925F5AF7AA0DADBAE008507366, 48268E8F0831E5393C78D02F12BFE386E04C9169408BEC8760078B9D017DC4B0 ] intelppm C:\WINDOWS\System32\drivers\intelppm.sys 05:55:40.0636 0x12dc intelppm - ok 05:55:40.0636 0x12dc [ BCDEA9631377ADEC401C734B48FD5E40, CD855142F264A9756ED8DF075C044C82117C1C0EAB84A1567EF3DC3B8E9CE1FF ] iorate C:\WINDOWS\system32\drivers\iorate.sys 05:55:40.0651 0x12dc iorate - ok 05:55:40.0667 0x12dc [ 2663BB5F755FD3FD3C66DAD3FA14B6DD, 5B68940160CAF89C9611E57A81571BE6EDE1EDF47C801B1F9AE714E5D64AB6A9 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 05:55:40.0682 0x12dc IpFilterDriver - ok 05:55:40.0714 0x12dc [ D8AFA4E5C071C63551234DB2E721C41C, BDD7FFE08D3CA8D49CC6904119B0DF23D0024ADB1B5B7B8DE4C9E4FD0114F480 ] iphlpsvc C:\WINDOWS\System32\iphlpsvc.dll 05:55:40.0776 0x12dc iphlpsvc - ok 05:55:40.0776 0x12dc [ 401845D7F55CD1EB6AC00DEBCA3FB0B5, B3B22C1098303A89A8BD15157C899634475AAC18A4A25383BC7D4C7185AD1B90 ] IPMIDRV C:\WINDOWS\System32\drivers\IPMIDrv.sys 05:55:40.0792 0x12dc IPMIDRV - ok 05:55:40.0792 0x12dc [ 7DAAF580A2C442BF7542C5CD43205AE8, 681E8E782F650BD425EC5C7E079FBEA60883FA3A4E42DAEB92B8F057EAA9A01C ] IPNAT C:\WINDOWS\system32\drivers\ipnat.sys 05:55:40.0807 0x12dc IPNAT - ok 05:55:40.0823 0x12dc [ B5B6D1F86E40E785D6650DB923DB6BEA, 7A2D92A2274E0379B5FA6351D18E2F0DD55960BB783EA3528FE9E303E1A4256D ] IPT C:\WINDOWS\System32\drivers\ipt.sys 05:55:40.0823 0x12dc IPT - ok 05:55:40.0839 0x12dc [ 77494E26B28465D2A09B9455F8A3B34E, B778D4BC71A5F5CF687175CA53AC342E4740156D4B96E6E96D918BD46C2C1459 ] IpxlatCfgSvc C:\WINDOWS\System32\IpxlatCfg.dll 05:55:40.0901 0x12dc IpxlatCfgSvc - ok 05:55:40.0901 0x12dc [ 7CD67E281BAAA6FB6509B1383BE5C8A9, 1C5E077FC688F309EA0EC052E2A94AEF18CF940C67A2251A3D69EF3426147973 ] isapnp C:\WINDOWS\system32\drivers\isapnp.sys 05:55:40.0917 0x12dc isapnp - ok 05:55:40.0932 0x12dc [ FB464357FD21D4931B84AD1DB6933FBA, D293B163B6233A5B1AA1F8783AE1C4EFF56D06AF3E83FD0695BBED094074284C ] iScsiPrt C:\WINDOWS\System32\drivers\msiscsi.sys 05:55:40.0948 0x12dc iScsiPrt - ok 05:55:40.0948 0x12dc [ 2DAB988FDD06CACD99B9DB2A05569449, A66C90009C7B20736A8B291889C518CBAF9D0C32A5EC720330EF25F30C056F1B ] ItSas35i C:\WINDOWS\system32\drivers\ItSas35i.sys 05:55:40.0964 0x12dc ItSas35i - ok 05:55:41.0026 0x12dc [ 7E3D6F5B7389F6FB30E38F46C3A3AC0E, 2BCAD927AED00694348C0515BE12EC56423D50648AAC708F1F8BE381FAD94312 ] jhi_service C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe 05:55:41.0042 0x12dc jhi_service - ok 05:55:41.0042 0x12dc [ 02A6967D5AEF2F15AA9C838DBF3E1C04, 7639DCD4328C14F3FB522EC501F4DF374CCBE87699EB4A2B238C9F9C526FDF59 ] kbdclass C:\WINDOWS\System32\drivers\kbdclass.sys 05:55:41.0057 0x12dc kbdclass - ok 05:55:41.0057 0x12dc [ DD56D35E1708207B5006B491AFBD47D7, 4DDDE0AF2816A5302511E99FD26F77517EA5C2C6D9BE76D70199A33BF3EE9FE3 ] kbdhid C:\WINDOWS\System32\drivers\kbdhid.sys 05:55:41.0073 0x12dc kbdhid - ok 05:55:41.0073 0x12dc [ F0B7FEB4D627FAA3E2BF8764D83F7479,

Continua:

0E483D46D22A2171DC844B53D31BC44E73DB90FAD7602E20FDDF3051FD2278D9 ] kbldfltr C:\WINDOWS\system32\drivers\kbldfltr.sys 05:55:41.0089 0x12dc kbldfltr - ok 05:55:41.0104 0x12dc [ 6B7422A382C1788AAF7C6CE6D4A4B375, F14AC6EF3695E05CD2D5CD9524AF7D0327E11A8B2BA9315A1EBF53828A608D33 ] kdnic C:\WINDOWS\System32\drivers\kdnic.sys 05:55:41.0120 0x12dc kdnic - ok 05:55:41.0120 0x12dc [ 289D6A47B7692510E2FD3B51979A9FED, 0777FD312394AE1AFEED0AD48AE2D7B5ED6E577117A4F40305EAEB4129233650 ] KeyIso C:\WINDOWS\system32\lsass.exe 05:55:41.0136 0x12dc KeyIso - ok 05:55:41.0136 0x12dc [ DC2F7867AC245DBB12FEC19494C0E9B1, 2883D42BF3020B02F2EB5F949F5D7B1BBC0E772BC0F585D51972EDA311D10A94 ] KSecDD C:\WINDOWS\system32\Drivers\ksecdd.sys 05:55:41.0151 0x12dc KSecDD - ok 05:55:41.0182 0x12dc [ 8CA13B2FC4617982B30C3A581966E4F7, F9A0C00C19AB003D9012EEBEC75D9C06564A19DEBB806F0BAD01C490E749FD06 ] KSecPkg C:\WINDOWS\system32\Drivers\ksecpkg.sys 05:55:41.0198 0x12dc KSecPkg - ok 05:55:41.0198 0x12dc [ E5304DE29BB9666DF0E57E5BA71C0E10, 491802A11F9E563369DB69E1D838C6F0F54F69F31BDC14018339CEE1B6C9C3CA ] ksthunk C:\WINDOWS\system32\drivers\ksthunk.sys 05:55:41.0229 0x12dc ksthunk - ok 05:55:41.0260 0x12dc [ DAE67BD7EC6ED569438F5CA38BFBB458, 672CA98525D6DD799A01A3BC3A62AB7B4544D62ECEB3615FAC05BFB97B389D23 ] KtmRm C:\WINDOWS\system32\msdtckrm.dll 05:55:41.0292 0x12dc KtmRm - ok 05:55:41.0307 0x12dc [ 7EE01F96BD7D26C87FB46A2D67A66D79, C1319471A154343636888DDC79FC2283A1D249C68E4CFBCB6F3624AF265E33EA ] LanmanServer C:\WINDOWS\system32\srvsvc.dll 05:55:41.0339 0x12dc LanmanServer - ok 05:55:41.0339 0x12dc [ A826ACB2318FD1FC0A26FCF5385074A1, F30163DE976659782175EEE736744AEB0794AED558A3E109A3BF41538D632984 ] LanmanWorkstation C:\WINDOWS\System32\wkssvc.dll 05:55:41.0370 0x12dc LanmanWorkstation - ok 05:55:41.0401 0x12dc [ A997488F4EDAAD59C748CF9FB1D9DAC0, A0B145041F984DD4E0A6F8D0E9C8363DA6F2DA7460E140F028C320CEAC03759C ] lfsvc C:\WINDOWS\System32\lfsvc.dll 05:55:41.0432 0x12dc lfsvc - ok 05:55:41.0448 0x12dc [ 98B6DF0BC14DC6BE7FEF49998FA36896, 2146FE84B3AC6EB3D91AC56F5A4A25D005E36FF7A1B01E1051271776C59538F6 ] LicenseManager C:\WINDOWS\system32\LicenseManagerSvc.dll 05:55:41.0479 0x12dc LicenseManager - ok 05:55:41.0479 0x12dc [ 78779BD92081CB27967E77561683AFBE, 05EC91E194336D1BB1EE323E70FAC54F6DC0CEF53FD4925F394399531A37A0DD ] lltdio C:\WINDOWS\system32\drivers\lltdio.sys 05:55:41.0495 0x12dc lltdio - ok 05:55:41.0526 0x12dc [ 199738EF3AFC628823A7A5C74D5CA887, 164B6C738FC416143C49BF0D1CFDCC952360693F41F799B79FEBA72CD542F9B6 ] lltdsvc C:\WINDOWS\System32\lltdsvc.dll 05:55:41.0573 0x12dc lltdsvc - ok 05:55:41.0573 0x12dc [ 4A501E9429650B678610ABCCAD1D2609, 71F33FD997D36B8CFB7FD36397CB768AEF1B6329B3882D445B72246621F3BD7E ] lmhosts C:\WINDOWS\System32\lmhsvc.dll 05:55:41.0589 0x12dc lmhosts - ok 05:55:41.0651 0x12dc [ 8451F78DB829135BD27111F55996A637, D0EAE0C90115C457663852E8AD6C9207D3F51B442DC0F3749FD8B8714D02A55B ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 05:55:41.0682 0x12dc LMS - ok 05:55:41.0682 0x12dc [ 89EB90814DA5FB6F5299240AD8B9C7A7, 36857AFABD064196B7D2A7CFAE3696D96C1FE13431DB49ACE161E706680231DA ] LSI_SAS C:\WINDOWS\system32\drivers\lsi_sas.sys 05:55:41.0698 0x12dc LSI_SAS - ok 05:55:41.0698 0x12dc [ 2FD85E518EA97BB642B018EEB453401A, 7EA218BB57843B80AB5A987BA915829B8262629F72EEC84238634A016D05504E ] LSI_SAS2i C:\WINDOWS\system32\drivers\lsi_sas2i.sys 05:55:41.0714 0x12dc LSI_SAS2i - ok 05:55:41.0714 0x12dc [ 8B7995D9E487C8F90BEA8F1EF6331C10, 2EE68AFEB6D5EC98A996C1722057275C1648411898359248D390B6AA9F697AB5 ] LSI_SAS3i C:\WINDOWS\system32\drivers\lsi_sas3i.sys 05:55:41.0729 0x12dc LSI_SAS3i - ok 05:55:41.0729 0x12dc [ ED902EBC8DEEF6E5FC00D0816DDFFB42, FFDDB7BA54C999D5689152E4EDACC838A769B6C479F0A0FCF294C8632F4E4C1F ] LSI_SSS C:\WINDOWS\system32\drivers\lsi_sss.sys 05:55:41.0745 0x12dc LSI_SSS - ok 05:55:41.0760 0x12dc [ 7EFBAD4742F4A45A78D9B96DD875CA43, B76BEA3B5E60EB9B101A49145761EED95592D635CA286C8AECBBE62CF9089458 ] LSM C:\WINDOWS\System32\lsm.dll 05:55:41.0823 0x12dc LSM - ok 05:55:41.0854 0x12dc [ E4576424DEB0492219D6CE56934A237B, 14273367C39F70488CD206B57196971FB165E67F8154690BAC65A8CC7A406B88 ] LTUSB C:\WINDOWS\System32\drivers\EZUSB.sys 05:55:41.0901 0x12dc LTUSB - ok 05:55:41.0917 0x12dc [ B592A9EC7CBDDDCA955FB6E74DC77F4E, 6C3CAE0F5E5D23E0E1F2E60E71013BC932138B4BE7E1C7BBEAD4490F8A86F093 ] luafv C:\WINDOWS\system32\drivers\luafv.sys 05:55:41.0948 0x12dc luafv - ok 05:55:41.0979 0x12dc [ EB179FC099244C26C5444720D65F8193, C8245BB54F1789E0A70A02713CCE04E8A06E8B2637B492EB5EEB7E11CE7C404A ] LxpSvc C:\WINDOWS\System32\LanguageOverlayServer.dll 05:55:42.0010 0x12dc LxpSvc - ok 05:55:42.0042 0x12dc [ AE03D8F1B7863268EAED2FE0105ED75F, F5172A1A3E24FC5271FCB0118861EA0EC33AA8ABB01AE9CAD50E2F032B92486C ] MapsBroker C:\WINDOWS\System32\moshost.dll 05:55:42.0073 0x12dc MapsBroker - ok 05:55:42.0089 0x12dc [ 6C965A0AC264AF1A8E0A69882A7EAFDC, DA40E73A7F584D944F58C7F489B701315B8D30A29E5A6C840C9D291302271834 ] mausbhost C:\WINDOWS\System32\drivers\mausbhost.sys 05:55:42.0120 0x12dc mausbhost - ok 05:55:42.0120 0x12dc [ 6C6C1EFC46A62091224333E1E9304FBC, AEADB11E2BE2EEB4BB5E4E13ADDA4633475022312AEE777CFE7FEB27C490B54C ] mausbip C:\WINDOWS\System32\drivers\mausbip.sys 05:55:42.0135 0x12dc mausbip - ok 05:55:42.0182 0x12dc [ 6A21162E1C8A9F65787B14BC439EB077, 8B7990E1C676F53918E41F6B18B20179D77E598352D9243B05E2EA22B2D9E4FE ] MBAMChameleon C:\WINDOWS\System32\Drivers\MbamChameleon.sys 05:55:42.0198 0x12dc MBAMChameleon - ok 05:55:42.0214 0x12dc [ 9E77C51E14FA9A323EE1635DC74ECC07, B5619D758AE6A65C1663F065E53E6B68A00511E7D7ACCB3E07ED94BFD0B1EDE0 ] MbamElam C:\WINDOWS\system32\DRIVERS\MbamElam.sys 05:55:42.0229 0x12dc MbamElam - ok 05:55:42.0495 0x12dc [ 1009C97D876BB3BFB9D19D31871252FF, 911DC770EFF89F7EA0EC8F3A73B209CC1B148020095AC9988C4F685844904F38 ] MBAMService C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe 05:55:42.0729 0x12dc MBAMService - ok 05:55:42.0760 0x12dc [ 1DC6D344EE9B6B024BA23278891DB9A5, 823E1C7321E177B006C1F3FD1EC8B99607A12D2C3C321F3A6CBBCF7030B6C240 ] MBAMSwissArmy C:\WINDOWS\System32\Drivers\mbamswissarmy.sys 05:55:42.0776 0x12dc MBAMSwissArmy - ok 05:55:42.0792 0x12dc [ 079D1EC6462AEA1BD9D6122F0514232D, 580C048AF400C1E9890A210C949DDCD2BDE1F855FD81E425A0C66A983E953B1B ] MbbCx C:\WINDOWS\system32\drivers\MbbCx.sys 05:55:42.0839 0x12dc MbbCx - ok 05:55:42.0870 0x12dc [ 1674722A97DD82B55F850DFB0719A3C1, D0AA4D480CD6D024BD8D7FD38485DB3EC0FA3F289DB5C161A79238D8A8452C17 ] McNeelUpdate c:\Program Files (x86)\McNeelUpdate\5.0\McNeelUpdateService.exe 05:55:42.0870 0x12dc McNeelUpdate - ok 05:55:42.0901 0x12dc [ 3CF9322793BD7F2D7234D72327A98BFF, 791E081787903B5367FFEEE3A82F0F096214670A0153837E1E2F50D0BE3377BF ] McpManagementService C:\WINDOWS\System32\McpManagementService.dll 05:55:42.0963 0x12dc McpManagementService - ok 05:55:42.0963 0x12dc [ CE4B01081B8FD211A7A34219D5E8154A, 9041FDEB932F2CBBCE4A017256C81B3733604403AA343D4532910436E8288CA9 ] megasas C:\WINDOWS\system32\drivers\megasas.sys 05:55:42.0979 0x12dc megasas - ok 05:55:42.0979 0x12dc [ F3C6B901E3FF70F27A17CFDDD7BA85AA, 6D67F52F0B63724126DD7B75B3489D14A6CBC3BD1E0D19188026DA21E85A620A ] megasas2i C:\WINDOWS\system32\drivers\MegaSas2i.sys 05:55:42.0995 0x12dc megasas2i - ok 05:55:42.0995 0x12dc [ EB84966D14F9342C8AD3D78BA9AA8754, 83C982FC61094A9E9F3E3CB5174B7409698C12FE3B6BF9B2F4C9365E56C642B2 ] megasas35i C:\WINDOWS\system32\drivers\megasas35i.sys 05:55:43.0010 0x12dc megasas35i - ok 05:55:43.0026 0x12dc [ A4DC7070D92AD82A7BDF2F69C155AF69, 8A902DDB6016E4D5C28808FBA5741751D94FFBD4B55724D47BBA0A8C29900E53 ] megasr C:\WINDOWS\system32\drivers\megasr.sys 05:55:43.0042 0x12dc megasr - ok 05:55:43.0057 0x12dc [ 0AC256421B38CEF110FD2C6A22421E65, 5D8AF9775DF9A1C3BA0AF87A042621B0587CA2F36BFCACEDF10F4CDCB0F0A2AB ] MEIx64 C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys 05:55:43.0073 0x12dc MEIx64 - ok 05:55:43.0073 0x12dc [ 38A4736FC5B74F176BDD592EF95AB035, 10411BA97B3479F22655C4A9949DFBD037843030538FAA881529048D28E8FC4E ] MessagingService C:\WINDOWS\System32\MessagingService.dll 05:55:43.0120 0x12dc MessagingService - ok 05:55:43.0276 0x12dc MicrosoftEdgeElevationService - ok 05:55:43.0307 0x12dc [ B74FFC6301B3312A9F59E04E487BC72A, 76F71824E80D10EB71BEDE5EE3A64CAD7CAC3DDFBB6670D1537E6B75FF0217E9 ] Microsoft_Bluetooth_AvrcpTransport C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys 05:55:43.0323 0x12dc Microsoft_Bluetooth_AvrcpTransport - ok 05:55:43.0323 0x12dc [ AF70C76096A5C905D195ED0F40E0A294, 2E78475D0F618A2F988727F5C21DC083546A6DDAB24E1152DCBF9C993EE419C7 ] MixedRealityOpenXRSvc C:\WINDOWS\System32\MixedRealityRuntime.dll 05:55:43.0338 0x12dc MixedRealityOpenXRSvc - ok 05:55:43.0370 0x12dc [ 517DC2DF12A391699F8432AF89947F2B, 2C6B268486AD0F3BFB82DE0F61D076DF7C334C1C94A0316084713EBDB0C9C518 ] mlx4_bus C:\WINDOWS\System32\drivers\mlx4_bus.sys 05:55:43.0401 0x12dc mlx4_bus - ok 05:55:43.0417 0x12dc [ F087703FAC478379323262C54CE85DD4, 56AC6F16B94E9BF9EB140B21C8397CBBE2DB9D6C6B01D2879C5ABEE060631138 ] MMCSS C:\WINDOWS\system32\drivers\mmcss.sys 05:55:43.0448 0x12dc MMCSS - ok 05:55:43.0448 0x12dc [ BF7ECB119071501EAB6C01374CBD25A0, F1DBC9307B3FCA67CFBF3DE4F1FF62B25B85BC832B2C05B96CA5EC0130B41108 ] Modem C:\WINDOWS\system32\drivers\modem.sys 05:55:43.0463 0x12dc Modem - ok 05:55:43.0463 0x12dc [ D279BFB856809EB1C2E1CED379DF897A, 7C8F7839463AB2ED09F8D8AA2D2910624BE18199FB197CF12D0D99BBDDEDDD57 ] monitor C:\WINDOWS\System32\drivers\monitor.sys 05:55:43.0495 0x12dc monitor - ok 05:55:43.0495 0x12dc [ 4352C109DD892A5A5413897A74103024, DB5D99DBFF8C84A7D87109DFB71396DF8E0F0754FC0D263E45116915A39735CE ] mouclass C:\WINDOWS\System32\drivers\mouclass.sys 05:55:43.0510 0x12dc mouclass - ok 05:55:43.0510 0x12dc [ 66E41E31DEBD4E1A2762945B4F15C780, 3A05D657E03B6CD9D62023061F9C652357F16DA2F2337FB6C617AEEFFAD794B4 ] mouhid C:\WINDOWS\System32\drivers\mouhid.sys 05:55:43.0526 0x12dc mouhid - ok 05:55:43.0526 0x12dc [ 180D9E273A958B6D2B55410DB2C431C4, EE3598DECA591E8735DE0F449F292E9DDDBCE28A8A7B814E78DFD90AC867B7F2 ] mountmgr C:\WINDOWS\system32\drivers\mountmgr.sys 05:55:43.0542 0x12dc mountmgr - ok 05:55:43.0542 0x12dc [ 19623B4213820840730EF00BA52201B6, E9AF731D982F2E6D6DEF9239E4912881043804E6C557C6DBA9B16AD6AE0473F7 ] mpsdrv C:\WINDOWS\system32\drivers\mpsdrv.sys 05:55:43.0557 0x12dc mpsdrv - ok 05:55:43.0588 0x12dc [ 5C181DC38D1E1089A190782896FDB8F8, A4C6B121FEB75E87C6A56282ECB1984410644B341C04FF921A043391E14E3C7C ] mpssvc C:\WINDOWS\system32\mpssvc.dll 05:55:43.0651 0x12dc mpssvc - ok 05:55:43.0682 0x12dc [ 27295840589657BE557D7F5801B5989A, 7073943E84D6221620D7B949AF9E15E35682542A9F344B30CDE5E5ABF603C1E6 ] MRxDAV C:\WINDOWS\system32\drivers\mrxdav.sys 05:55:43.0698 0x12dc MRxDAV - ok 05:55:43.0729 0x12dc [ 2754863CC7F7170C8225A3E66A1BE2BB, B4BA5C4E40496D0282F4AD37FA4EA326D69FC0914A4DCA7AE2EB8E42ED936564 ] mrxsmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 05:55:43.0745 0x12dc mrxsmb - ok 05:55:43.0760 0x12dc [ 8F2767E7F6C7C8F6009F675709C499BF, 142D5BA9B2B7A8524D6AED7B4E964AF3C427623D51C86D7D80C91D0CE1BDE557 ] mrxsmb20 C:\WINDOWS\system32\DRIVERS\mrxsmb20.sys 05:55:43.0776 0x12dc mrxsmb20 - ok 05:55:43.0776 0x12dc [ E587396A4C8151ABBF13A96C4465DE31, A3AA5D51E34657479CFCDC3DBB7821B7255F7CB57D5686B7F709A7953AD537EB ] MsBridge C:\WINDOWS\system32\drivers\bridge.sys 05:55:43.0792 0x12dc MsBridge - ok 05:55:43.0838 0x12dc [ 2EF846AC66E181BE820B513DBC15B5D2, EDFE71025C352D0DABEC7B9506C5945BB0EC11F8DB540DB8CB1116C2EA1648A8 ] MSDTC C:\WINDOWS\System32\msdtc.exe 05:55:43.0870 0x12dc MSDTC - ok 05:55:43.0885 0x12dc [ 4D8C5C0B06D8F4B28AAD865ACA6C5494, 8AC1A5358691DA4FBEC7BAA3711321EAD20439029031696F12BB287771E82893 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys 05:55:43.0885 0x12dc Msfs - ok 05:55:43.0901 0x12dc [ 6092FD060EC4132A799BDAD61845DDB7, B45F9D3A71FC8A73AED3C5B8CF6F14A25EBDD3D4D47C9F39FFCD75C7D22F4A9E ] msgpiowin32 C:\WINDOWS\System32\drivers\msgpiowin32.sys 05:55:43.0901 0x12dc msgpiowin32 - ok 05:55:43.0917 0x12dc [ 78689B7121F3DA06A879FBBD039B29AA, C656B13E0329B86663C2382943B1DD6F6E5080FAC71E3FEFA056D261F30E273E ] mshidkmdf C:\WINDOWS\System32\drivers\mshidkmdf.sys 05:55:43.0932 0x12dc mshidkmdf - ok 05:55:43.0932 0x12dc [ 9E90FE6DF363D2427A5C773120E7B27D, 1FDB7E28CCAF757603C4B754E1AC9C470E5E60E85DE067375902F108F5E34608 ] mshidumdf C:\WINDOWS\System32\drivers\mshidumdf.sys 05:55:43.0948 0x12dc mshidumdf - ok 05:55:43.0948 0x12dc [ 0C95F1C9D1ABF88CB82E5831E8CCE9AF, 46B2C56F21291D6375FBE33D8D48D0662BDD4770B8962D1D1AAA540893897A9A ] msisadrv C:\WINDOWS\system32\drivers\msisadrv.sys 05:55:43.0963 0x12dc msisadrv - ok 05:55:43.0979 0x12dc [ D81EC229265DBD93FB14DBA5A6A9B0EF, 6639D02B1FED24763FCAE3D8FB919DE67B3639951AD49A66A804B8304137C487 ] MSiSCSI C:\WINDOWS\system32\iscsiexe.dll 05:55:43.0995 0x12dc MSiSCSI - ok 05:55:44.0010 0x12dc msiserver - ok 05:55:44.0026 0x12dc [ F0B513D6ED7069B5FA37597476724B23, BBEA41AF0FEE32C7D08107375285289FD02056DA3543D518493D2484B1C955B6 ] MsKeyboardFilter C:\WINDOWS\System32\KeyboardFilterSvc.dll 05:55:44.0026 0x12dc MsKeyboardFilter - ok 05:55:44.0042 0x12dc [ 26854C1F5500455757BC00365CEF9483, 82C74A2AAACC3CD06187365D40EC1C122A01CDB6915B18FE2DD97E17764DAF21 ] MSKSSRV C:\WINDOWS\System32\drivers\MSKSSRV.sys 05:55:44.0057 0x12dc MSKSSRV - ok 05:55:44.0057 0x12dc [ 9FB5040C8CEAE4C32B7884ECBBCAFDAF, 0EC3E53C5B1B202440DE22A5BF7E1EBE9AF5BBB6BA69DB9D018A6D8EC97B477E ] MsLldp C:\WINDOWS\system32\drivers\mslldp.sys 05:55:44.0088 0x12dc MsLldp - ok 05:55:44.0104 0x12dc [ 4B5CD00DEAB6BC5FE650D5E90BA5719A, 6E5DAA5D9826A3165514CE2AC4AEC23033D7BA993F06D2BDFFC68052CA71C4A0 ] MSPCLOCK C:\WINDOWS\System32\drivers\MSPCLOCK.sys 05:55:44.0104 0x12dc MSPCLOCK - ok 05:55:44.0120 0x12dc [ 3FC09B334BB53D2EB289887CFBD79D0B, AD55F307A8146BC2ACB1B2437C19B405F7BC3F5E4A81DB685B0C046FEC4C30BC ] MSPQM C:\WINDOWS\System32\drivers\MSPQM.sys 05:55:44.0120 0x12dc MSPQM - ok 05:55:44.0135 0x12dc [ 1B9172B25182BE5F3560F76F4085A5B7, 65739D981DFD66C092F781FE1CB1BF07FCF4CD0DA969103E527D4982CA3A30AB ] MsQuic C:\WINDOWS\system32\drivers\msquic.sys 05:55:44.0151 0x12dc MsQuic - ok 05:55:44.0167 0x12dc [ CED8FF3BBF5E7F652515D4FE1BB251EB, 851F81CD07E043C1B173AE2D13F9BA66A510859F4CE29D0CA0767B1BA013162F ] MsRPC C:\WINDOWS\system32\drivers\MsRPC.sys 05:55:44.0182 0x12dc MsRPC - ok 05:55:44.0198 0x12dc [ 21D57B9DD70153B31375F9EE09C722D4, 57731311F386EF6744D361A02FC83CBC6FB331818A14391217BBBC88117A3F9E ] MsSecFlt C:\WINDOWS\system32\drivers\mssecflt.sys 05:55:44.0213 0x12dc MsSecFlt - ok 05:55:44.0213 0x12dc [ DB89919F84809686BD4F8C24EB6CB3FA, 360A199A6D4690FE248C6EAA4E84673F299FA4CA6C21E940F4DF1B28216BA23C ] mssmbios C:\WINDOWS\System32\drivers\mssmbios.sys 05:55:44.0229 0x12dc mssmbios - ok 05:55:44.0229 0x12dc [ 244C73253E165582DDC43AF4467D23DF, 808FF81F0030CC7390B4790F91CE1763EAC02CCECA6014A2D9D990A40DBD0580 ] MSTEE C:\WINDOWS\System32\drivers\MSTEE.sys 05:55:44.0245 0x12dc MSTEE - ok 05:55:44.0245 0x12dc [ 8EE2EEE12398FEA5BC8E37AAAFE59852, E37965B9EFD9ADA6A81585DD792A20CD03BFC28512E92FC63CD2CBAE9A41AD1A ] MTConfig C:\WINDOWS\System32\drivers\MTConfig.sys 05:55:44.0260 0x12dc MTConfig - ok 05:55:44.0276 0x12dc [ 6AD1255EDF789EDB771EB04B062BF007, 757E91D214B38D75819B8FE0E0D9D10E648660244CBEA79C588C9E62CB71AC74 ] Mup C:\WINDOWS\system32\Drivers\mup.sys 05:55:44.0292 0x12dc Mup - ok 05:55:44.0292 0x12dc [ 82B656712713424A707F1E127C68E02F, 69FBB0692C37DA498014CC6CDC609E612A3207A17B280EDE5C02248571F91F11 ] mvumis C:\WINDOWS\system32\drivers\mvumis.sys 05:55:44.0307 0x12dc mvumis - ok 05:55:44.0370 0x12dc [ 335DD15BDF7121806A435E7C1D574FC2, BB33EC622F37DD6BD9BD649C0A2EBBB925C31FC9291DA2B11C06AE26E33D4D14 ] MyWiFiDHCPDNS C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe 05:55:44.0385 0x12dc MyWiFiDHCPDNS - ok 05:55:44.0417 0x12dc [ 8CA2DD9A18327EFBD5D7E8E099E36BD4, 9784443A7CF84479DA31BE0A53CAE1443B3A0474D27A4DEE2CF28A4DCB332D07 ] NativeWifiP C:\WINDOWS\system32\DRIVERS\nwifi.sys 05:55:44.0448 0x12dc NativeWifiP - ok 05:55:44.0479 0x12dc [ 1E641165EADCE9085810CCD4E1AAF443, 9C7EC8118B3550829215665F2C7D537E691BA6035432CC36834039D8D64D8A60 ] NaturalAuthentication C:\WINDOWS\System32\NaturalAuth.dll 05:55:44.0510 0x12dc NaturalAuthentication - ok 05:55:44.0510 0x12dc [ D47A20839608B8213065D7AFC8C42195, 7B0187BE9705ED2F925616C13B3744BAC0A9C96B21BE503D96BC9EE7EE125B33 ] NcaSvc C:\WINDOWS\System32\ncasvc.dll 05:55:44.0604 0x12dc NcaSvc - ok 05:55:44.0620 0x12dc [ 9CC607630F19847E887D4846D8AF9BEC, 3022760F2DB65A4ECBEDAF0E60BF2733391ADF2F323014693BC6735789578E06 ] NcbService C:\WINDOWS\System32\ncbservice.dll 05:55:44.0666 0x12dc NcbService - ok 05:55:44.0713 0x12dc [ 8C938E851CDF2CE30BBEA14555B61820, F853F526C811893BD40B1124BAEC543099381E7BF091729B6A6665DF3CE10B94 ] NcdAutoSetup C:\WINDOWS\System32\NcdAutoSetup.dll 05:55:44.0807 0x12dc NcdAutoSetup - ok 05:55:44.0807 0x12dc [ D62777BD13AC73F8FB20039B701D5292, E3708D62DEA31BA03D7CE7EEF6A270DA2B3556559140B556F5AB4EA289F921E2 ] ndfltr C:\WINDOWS\System32\drivers\ndfltr.sys 05:55:44.0823 0x12dc ndfltr - ok 05:55:44.0870 0x12dc [ BE9D5B1670123A10905DE3CF80563F1E, 9268405FEACC07B4C64E7D913F41884BB925F15F6B6F56A2D5EE1FA4E9ACE947 ] NDIS C:\WINDOWS\system32\drivers\ndis.sys 05:55:44.0901 0x12dc NDIS - ok 05:55:44.0932 0x12dc [ 6BEC0929C7A7BF2A7C44F585ECC7DAEB, 5F6395268CBD26A4B90960479040C114B2C8A3F24C188C2D5F62D6AB43A637D1 ] NdisCap C:\WINDOWS\system32\drivers\ndiscap.sys 05:55:44.0963 0x12dc NdisCap - ok 05:55:44.0963 0x12dc [ FF4D48CB9B1FA642E9DE8C4EAF05C980, A8C470C3429D693678F16CE47BD104B8F1E8870600C54F81058951D4A0C8A125 ] NdisImPlatform C:\WINDOWS\system32\drivers\NdisImPlatform.sys 05:55:44.0979 0x12dc NdisImPlatform - ok 05:55:44.0979 0x12dc [ 8F6BC1F9E7331F564367456649CD3C84, 58FDA9DC5748D4F102F6B9BC6EEED687244ED74B32D584119750BF964ECD807E ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys 05:55:44.0995 0x12dc NdisTapi - ok 05:55:44.0995 0x12dc [ 09BD40437780ED584D06519373ACEDC7, 3D7685D3960382FB102E225634D54A2370DA53DEB89CAE4765AD00C9AFE030B7 ] Ndisuio C:\WINDOWS\system32\drivers\ndisuio.sys 05:55:45.0026 0x12dc Ndisuio - ok 05:55:45.0026 0x12dc [ 31AE9050FF9D6CBE1BC2A7EA5F98D6A3, 2960AF22637EDA95DF6ED154278B23AC157AF2DE6F342DA7D8083E4F7F70730F ] NdisVirtualBus C:\WINDOWS\System32\drivers\NdisVirtualBus.sys 05:55:45.0041 0x12dc NdisVirtualBus - ok 05:55:45.0041 0x12dc [ 2E37D4EDEA5E5B6F3151D38700FAFC09, 5480F7CBDC4CA366CDA6475AAA4FAF8BAD80C8542312FD6B225298EB0349753E ] NdisWan C:\WINDOWS\System32\drivers\ndiswan.sys 05:55:45.0057 0x12dc NdisWan - ok 05:55:45.0073 0x12dc [ 2E37D4EDEA5E5B6F3151D38700FAFC09, 5480F7CBDC4CA366CDA6475AAA4FAF8BAD80C8542312FD6B225298EB0349753E ] ndiswanlegacy C:\WINDOWS\system32\DRIVERS\ndiswan.sys 05:55:45.0088 0x12dc ndiswanlegacy - ok 05:55:45.0088 0x12dc [ 33CDAEDC7CBE8339A8324CEC2461BFB4, DAAEACDB4506D2BDDED61957D92FB4983E11D9CE6E7B25119B4CBFB431C945F4 ] NDKPing C:\WINDOWS\system32\drivers\NDKPing.sys 05:55:45.0104 0x12dc NDKPing - ok 05:55:45.0104 0x12dc [ EBB9D06E3C9F01FE299E9508D5B19BEB, 502AE6F59243354366ABE8DDB1F26BA79C5A08E56F9369525678CC072CF65486 ] ndproxy C:\WINDOWS\system32\DRIVERS\NDProxy.sys 05:55:45.0120 0x12dc ndproxy - ok 05:55:45.0135 0x12dc [ 77621E74FD79B267071A0D12C643A48A, 8228B7D1237A0FFABCCC150B299EA494C8F0CB4CCB51AB0DBFF08CBAA9EFC4BB ] Ndu C:\WINDOWS\system32\drivers\Ndu.sys 05:55:45.0151 0x12dc Ndu - ok 05:55:45.0166 0x12dc [ A46B30732B6ECA4824D11DF1218BFA29, C33BE6652D6FF2AF9F54FAA11ACC1EC1801977BE61DEF9425A594966F270B2C7 ] Netaapl C:\WINDOWS\System32\drivers\netaapl64.sys 05:55:45.0182 0x12dc Netaapl - ok 05:55:45.0182 0x12dc [ E60A2396F71BF2052429A5EF7DCC138E, 433C2957F7C314B377C5E042702D14AEE7DDFD88DCD0706F8111B827BAF35F5C ] NetAdapterCx C:\WINDOWS\system32\drivers\NetAdapterCx.sys 05:55:45.0229 0x12dc NetAdapterCx - ok 05:55:45.0245 0x12dc [ 4687FAC962855BDB1896C02334E95D54, E7F7F30D9513FDD2236FCFD5549DCD93101562BA1117213EA4DF32B70BB48A73 ] NetBIOS C:\WINDOWS\system32\drivers\netbios.sys 05:55:45.0245 0x12dc NetBIOS - ok 05:55:45.0260 0x12dc [ 49F7DE6F689C47B64A2C2D46CD98E327, 679A89E9078D5865C52FCAE3A86D5AD252BF22B819901303F186D55EC976E1CD ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys 05:55:45.0291 0x12dc NetBT - ok 05:55:45.0291 0x12dc [ 289D6A47B7692510E2FD3B51979A9FED, 0777FD312394AE1AFEED0AD48AE2D7B5ED6E577117A4F40305EAEB4129233650 ] Netlogon C:\WINDOWS\system32\lsass.exe 05:55:45.0307 0x12dc Netlogon - ok 05:55:45.0307 0x12dc [ 62D46DA273CB543BB1671FE708A280CA, 4AB8B86B076320DE116F42DACC83DC95C635CB32392F3EBBE0FC64F22E7BF70A ] Netman C:\WINDOWS\System32\netman.dll 05:55:45.0338 0x12dc Netman - ok 05:55:45.0385 0x12dc [ 20FC2B0CC00B738AED1A98E12A62AAC1, 0FA99BC961FE1BB673FCB33E9ED3C2FB4AAE9B58BE220D692EE1B667481E9F84 ] netprofm C:\WINDOWS\System32\netprofmsvc.dll 05:55:45.0448 0x12dc netprofm - ok 05:55:45.0463 0x12dc [ 3E080956CC2A9060350FA4A0DD711ACF, 335857359BEB61536819C9BC489C666C3CC103CE048C0DD9B80D16112D39AC79 ] NetSetupSvc C:\WINDOWS\System32\NetSetupSvc.dll 05:55:45.0479 0x12dc NetSetupSvc - ok 05:55:45.0557 0x12dc [ B9D455C60292DF5FCB064834CA5802AA, 75DCE4E5FA08CCEAF4D3D30FE8E26903FCDD14CC852E820F63B40F374C706DBD ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 05:55:45.0573 0x12dc NetTcpPortSharing - ok 05:55:45.0573 0x12dc [ A26CBC8D37237B5E0BC439507F008ADE, A4EE97A76EAC8D0966D262E55029250195ECC4F429F42086AA8E997AC18846F6 ] netvsc C:\WINDOWS\System32\drivers\netvsc.sys 05:55:45.0588 0x12dc netvsc - ok 05:55:45.0682 0x12dc [ 82CB9A9C54B561549F7EE11987607C3A, D8CCCA1F7415E459BD14F6E45DF65602AA1D404024D70A8BCE40F865B8D1F9BE ] NETwNb64 C:\WINDOWS\System32\drivers\Netwbw02.sys 05:55:45.0760 0x12dc NETwNb64 - ok 05:55:45.0807 0x12dc [ 9FEBF6D3CEE2C984D87E144854DF989E, 986BD2EEEAE0AB230286142A648056A19B4F44365689EF00BEDA1FD6CD9447CA ] NgcCtnrSvc C:\WINDOWS\System32\NgcCtnrSvc.dll 05:55:45.0854 0x12dc NgcCtnrSvc - ok 05:55:45.0885 0x12dc [ 9232FDD16C0B172C384A9E3528800BC4, 8B249860C8E10367012C1C554DD413895BA402C473997EAE3E9F1CBD2B02E15A ] NgcSvc C:\WINDOWS\system32\ngcsvc.dll 05:55:45.0979 0x12dc NgcSvc - ok 05:55:45.0995 0x12dc [ EDB7CF6CBECE6558E23159E68E690B71, 237475AF94FACA05327E88F2A19A3462BE3242B7635D63321074820CD03FF631 ] NlaSvc C:\WINDOWS\System32\nlasvc.dll 05:55:46.0026 0x12dc NlaSvc - ok 05:55:46.0041 0x12dc [ 833D836C1589DCB023382FA1178EADB2, 9E3C3E5E7C33DACC77D347DAD2CD37043F47E0DD93DBB6EE7710BD68AEE0B30B ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys 05:55:46.0041 0x12dc Npfs - ok 05:55:46.0057 0x12dc [ B2B57F620C085F2EA764BDF79AF7BE30, CA3657D9365D34FFECF6B5DE8E5905A2491756B1CC227D9AB8762B09111E9860 ] npsvctrig C:\WINDOWS\System32\drivers\npsvctrig.sys 05:55:46.0073 0x12dc npsvctrig - ok 05:55:46.0088 0x12dc [ 0FA6DD9E38FF747C54FF5AE05F304327, 85449DBDBD24D72E0BAD82C81306F5AEC18F7CF23631BCFC09E8AEE4C7C646BE ] nsi C:\WINDOWS\system32\nsisvc.dll 05:55:46.0104 0x12dc nsi - ok 05:55:46.0104 0x12dc [ 099D027B23831D009DEB40031795A915, 4E6E391847B90C796BC7B208614F66F48BD0A6CE253295DC24DFA47E9D214151 ] nsiproxy C:\WINDOWS\system32\drivers\nsiproxy.sys 05:55:46.0120 0x12dc nsiproxy - ok 05:55:46.0213 0x12dc [ 7113DE798267FE3B754E3D43727AFB37, E9125E44FB9F468B7B52563B79C6047F9F88D9C17D5771C2888445794370C8E6 ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys 05:55:46.0291 0x12dc Ntfs - ok 05:55:46.0338 0x12dc [ A0706FEA552415DB973DB27BDF2FF4F1, 52304E25745F96F3248E609E11F37CC112DC69A4DE47D70A3EE9E043428768F8 ] NuidFltr C:\WINDOWS\System32\drivers\NuidFltr.sys 05:55:46.0369 0x12dc NuidFltr - ok 05:55:46.0369 0x12dc [ 2CB7C3B739D8D34B9249F7DC6C8B5C1A, 318DD3D989EBED3F29A4C3F6FA819F060BE9C14C549B7DAD8ECA2B73C7932722 ] Null C:\WINDOWS\system32\drivers\Null.sys 05:55:46.0385 0x12dc Null - ok 05:55:46.0385 0x12dc [ BEB8637D4B098B286B8B4F46E88A57AD, C0515F0F429A3B60AEC5F9F2AEDCF387CF941D306A21C9BCB56571C83560C6C1 ] nvdimm C:\WINDOWS\system32\drivers\nvdimm.sys 05:55:46.0401 0x12dc nvdimm - ok 05:55:46.0416 0x12dc [ 5281A4F23E594AE6EDE1E38B1F8518E0, 628927EB91C6A323CA67B97EF743775B68D30599A0F0593BC3B5C0BA6C5AB82C ] nvraid C:\WINDOWS\system32\drivers\nvraid.sys 05:55:46.0432 0x12dc nvraid - ok 05:55:46.0432 0x12dc [ A11D15751217EEB734033BB5A929B1CD, F07CD88B7939C53DF83E93D40FB5AB115946393AFBE8DBA75FEE7247BF3063A9 ] nvstor C:\WINDOWS\system32\drivers\nvstor.sys 05:55:46.0448 0x12dc nvstor - ok 05:55:46.0463 0x12dc [ 8BBF06E5B2A4E5A1A74230003F6AAAA7, CE1B45DC50B6D82D85DAE5EEED4EA2A7D3E5AFAB24957437679CB366B6BE33C4 ] OneSyncSvc C:\WINDOWS\System32\APHostService.dll 05:55:46.0526 0x12dc OneSyncSvc - ok 05:55:46.0573 0x12dc [ F8CE0B4F1BC5E4FBDD66C1CAC4D58314, E7DC2FBA4CDBB0A35CC58E0FDF37D68891F18A80E449C0AA2C66C43A596EC4A9 ] p2pimsvc C:\WINDOWS\system32\pnrpsvc.dll 05:55:46.0588 0x12dc p2pimsvc - ok 05:55:46.0619 0x12dc [ EAC5988AC331CA82F46BABE6363F9A81, 0F461FABCDD9C23E78F5100E090F3A3088F16EE01480F8F0FEEE04EA78AB0320 ] p2psvc C:\WINDOWS\system32\p2psvc.dll 05:55:46.0651 0x12dc p2psvc - ok 05:55:46.0666 0x12dc [ 138FDB1EBCB61287A645BD3B06DBED5E, 1E59DE429B54E910688BF917F2AD97E66241EE3FB924C24E3627E9603E8A9C5D ] Parport C:\WINDOWS\System32\drivers\parport.sys 05:55:46.0682 0x12dc Parport - ok 05:55:46.0682 0x12dc [ 4A468541CAC91394555777882EC6342E, 7E4C7C7E996A80D53FBA43CD7A71CA770E631A21C8632030181A69C8327981A9 ] partmgr C:\WINDOWS\system32\drivers\partmgr.sys 05:55:46.0698 0x12dc partmgr - ok 05:55:46.0729 0x12dc [ D82A95146A0D207D8A4739B55C5865D0, 89DB4456D69751B36319AB2CBAD8F45D5A4982EB9BC00E7F76B4E56E655043CF ] PcaSvc C:\WINDOWS\System32\pcasvc.dll 05:55:46.0760 0x12dc PcaSvc - ok 05:55:46.0776 0x12dc [ DCFE198FA3BB2BCCBED7696D969A5C17, 515DB2D81A5305D2D0165AA8E5137076E423AF43D1C9512C37E5510C0972C71E ] pci C:\WINDOWS\system32\drivers\pci.sys 05:55:46.0791 0x12dc pci - ok 05:55:46.0791 0x12dc [ 5252320118508123B9902521CD70A8BA, 7207E0DAAFD9C7EC938CAD4107153DABDA111F67531860875D38F9DBBB998996 ] pciide C:\WINDOWS\system32\drivers\pciide.sys 05:55:46.0807 0x12dc pciide - ok 05:55:46.0807 0x12dc [ 0543F01C97CE2D3ABB4F8CEA56B99721, CD84890DEB63C782A51A7F4D962B88CAC9AA226C3C7DDC2D2B0A56E81B00B07C ] pcmcia C:\WINDOWS\system32\drivers\pcmcia.sys 05:55:46.0823 0x12dc pcmcia - ok 05:55:46.0823 0x12dc [ 81D246AE6AA07A244F77883F6D4B84D7, DD8BBCFDB88A0E23E639141B76A8F00B9685E888FCDD3C48CFDFB5453AEA1661 ] pcw C:\WINDOWS\system32\drivers\pcw.sys 05:55:46.0838 0x12dc pcw - ok 05:55:46.0869 0x12dc [ 7C5587B5911A96C10E670DFA54C9BB91, D9D4EC0EC8E7419263DC95F5CEBC24FD5F19E9FE902E902D45FAC46F4FA8E5E3 ] pdc C:\WINDOWS\system32\drivers\pdc.sys 05:55:46.0901 0x12dc pdc - ok 05:55:46.0916 0x12dc [ 3C76317D046F1CB772972346106C7D8E, F3779C108B4A1BD43ABDD49E75D60CE3E9A79C19DB9DD92B6DED1C38FD620443 ] PEAUTH C:\WINDOWS\system32\drivers\peauth.sys 05:55:47.0026 0x12dc PEAUTH - ok 05:55:47.0088 0x12dc [ B6C01FCE0A613DEF6502CF78D9D9F64C, 7A6A7F08C8066F68F60A006A095FA2E7B417C4CA65D40E2AA4D3859923DEE6C0 ] PeerDistSvc C:\WINDOWS\system32\peerdistsvc.dll 05:55:47.0213 0x12dc PeerDistSvc - ok 05:55:47.0276 0x12dc [ 217DD189B66B68149ED4F7E8C9BA1DD9, F4A1550BFEFBDC09DA82F53CE94EF3261C75DB1CC7C1EDD1074D31F828A47316 ] perceptionsimulation C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe 05:55:47.0369 0x12dc perceptionsimulation - ok 05:55:47.0369 0x12dc [ 2E2E8BA514A93C297F124BAB53F4E921, D6B8116E5C920032A5926D5D047BFD72B05ACBB08E26F177A0B0E6B4EC735FA1 ] percsas2i C:\WINDOWS\system32\drivers\percsas2i.sys 05:55:47.0385 0x12dc percsas2i - ok 05:55:47.0385 0x12dc [ 1C6720616FF300235509D5EFBB2CAE20, 92017ECB36EAA35AC454E890734915A658EB898C95970531D43C19461BE6562B ] percsas3i C:\WINDOWS\system32\drivers\percsas3i.sys 05:55:47.0401 0x12dc percsas3i - ok 05:55:47.0573 0x12dc [ 2FC7CFCEDBF7E038351C7CEB1036D2E1, 41D7DA706F0CF613DF768B6795CD09C5C1035F9F101051FB58F5042EB4352DB6 ] PerfHost C:\WINDOWS\SysWow64\perfhost.exe 05:55:47.0651 0x12dc PerfHost - ok 05:55:48.0291 0x12dc [ 33B70F1B11019590B02399716FF5FF04, F9B0FE71BACC70DBE55BAA7643776B68CE6D3718C0EB344B846E2674CE9CEC80 ] PhoneSvc C:\WINDOWS\System32\PhoneService.dll 05:55:48.0338 0x12dc PhoneSvc - ok 05:55:48.0354 0x12dc [ BF22C802EE5AF15C9136877146CBBA4B, 1F7C4D5AD502D3BCFD3DFB56BD0373465FDAD297549F23543CE48A0E7B4EEC6A ] PimIndexMaintenanceSvc C:\WINDOWS\System32\PimIndexMaintenance.dll 05:55:48.0401 0x12dc PimIndexMaintenanceSvc - ok 05:55:48.0479 0x12dc [ FA35E6864526D4B3B501033B1578A973, 4529688C08FBF3D17E4C556A2C51A9F17B94E2815A312E546AA61F171B0970D3 ] PktMon C:\WINDOWS\system32\drivers\PktMon.sys 05:55:48.0494 0x12dc PktMon - ok 05:55:48.0526 0x12dc [ 9E431A5D697432DD6F4DB48C9A185104, 44C16E194258C9143A45F4022F9C5DE229E217D6FF7F944F105FE631BE9EF4A7 ] pla C:\WINDOWS\system32\pla.dll 05:55:48.0635 0x12dc pla - ok 05:55:48.0651 0x12dc [ 47997A891009AD881DFA69E018D3DF41, 954BBFB9E4C7FF79A811123D31954840590837ECDC9108161717EE29C8EFB676 ] PlugPlay C:\WINDOWS\system32\umpnpmgr.dll 05:55:48.0666 0x12dc PlugPlay - ok 05:55:48.0682 0x12dc [ D3FA131E692F1FC4C4D6BE5293ED74A2, 6B57D69CF3BF0B266EB3139E11216B5E86C6329A1B2B7E7B11E313BA10F8E6F6 ] pmem C:\WINDOWS\system32\drivers\pmem.sys 05:55:48.0697 0x12dc pmem - ok 05:55:48.0697 0x12dc [ 2769F200292C0F941A10BD60C33EA4A6, B8345C32585C45E6248D7194B1071F2B8617718E7C9B270AAF44C132D029DB4C ] PNPMEM C:\WINDOWS\System32\drivers\pnpmem.sys 05:55:48.0713 0x12dc PNPMEM - ok 05:55:48.0729 0x12dc [ 6AAAC8AD69AEFBE5FE04738B687EE85E, 83427082298E2FC021D5D39A43DB4A5783D95213F2CA8D3A997DB6C815BD9CB2 ] PNRPAutoReg C:\WINDOWS\system32\pnrpauto.dll 05:55:48.0760 0x12dc PNRPAutoReg - ok 05:55:48.0791 0x12dc [ F8CE0B4F1BC5E4FBDD66C1CAC4D58314, E7DC2FBA4CDBB0A35CC58E0FDF37D68891F18A80E449C0AA2C66C43A596EC4A9 ] PNRPsvc C:\WINDOWS\system32\pnrpsvc.dll 05:55:48.0807 0x12dc PNRPsvc - ok 05:55:48.0822 0x12dc [ 37F907F88745FEFBC8985E926A72A92E, 41923E3D5FC3E5312A83673A72D58D6C9D40BD86AAC89F369B3D0CC7DEFA328D ] POADrvr C:\WINDOWS\system32\drivers\POADrvr.sys 05:55:48.0854 0x12dc POADrvr - ok 05:55:48.0869 0x12dc [ 4372FC65DAF6A5912DBA10118A20A386, 4A1A9EB440A417012234826034F3057745B2FE0D6C3E6CE6145AEF23EE49C06C ] PolicyAgent C:\WINDOWS\System32\ipsecsvc.dll 05:55:48.0901 0x12dc PolicyAgent - ok 05:55:48.0901 0x12dc [ 562B9409AA8777204E78C629647344EC, 65C33D25E0C00731D7DEF3F127523AA5178133481915287F3267A52C74577572 ] portcfg C:\WINDOWS\System32\drivers\portcfg.sys 05:55:48.0932 0x12dc portcfg - ok 05:55:48.0947 0x12dc [ FFDECF73BCDC6E124ACCEA0A3DC6DB3D, EE47BBDB755155592EC9D0C203E14D9E48CD3DC8FC9F9A136548046BF34FBEA7 ] Power C:\WINDOWS\system32\umpo.dll 05:55:48.0979 0x12dc Power - ok 05:55:48.0994 0x12dc [ B1A0C254C086F21715BFE3B984E49765, DEC7BA1F87007866A93EB90A250EE68F1AD17F6CA5139F5D0C973DDB35A8DDE3 ] PptpMiniport C:\WINDOWS\System32\drivers\raspptp.sys 05:55:48.0994 0x12dc PptpMiniport - ok 05:55:49.0182 0x12dc [ BA872272D6320D207E1AE65DD4B4450D, 1B7ECB2997846D1225744A6CD55F5267A530ED136E9273609E2D321D6E4C0498 ] PrintNotify C:\WINDOWS\system32\spool\drivers\x64\3\PrintConfig.dll 05:55:49.0354 0x12dc PrintNotify - ok 05:55:49.0401 0x12dc [ FD2B0B7A3121D240874288D66409151C, 96FAEBFD52FE5B9B1E78EAABB2F947F8E88DB959FDBFF0525BB5594739C9999F ] PrintWorkflowUserSvc C:\WINDOWS\System32\PrintWorkflowService.dll 05:55:49.0432 0x12dc PrintWorkflowUserSvc - ok 05:55:49.0432 0x12dc [ 7EECEAD543F5EBE53D4679892B1819C2, E8EE1B4F8FAE807191AE5E0CC9716067F6010CA0E8D0AAA635D7A9E15E81CEF7 ] Processor C:\WINDOWS\System32\drivers\processr.sys 05:55:49.0447 0x12dc Processor - ok 05:55:49.0463 0x12dc [ EBD0445D16293D3AA0B63025CE4A6A12, 74C267B00145CFC5E8AF1CECBC53BB7318D4ACDE8FA25D1C5599D59D506CDBD9 ] ProfSvc C:\WINDOWS\system32\profsvc.dll 05:55:49.0510 0x12dc ProfSvc - ok 05:55:49.0510 0x12dc [ 4E750557E2310F3875CC8CEAB4CCA2CB, 7906E70262F7D47A22CC18361749106E5B377660EF17A0F2AEB44B019F825A95 ] Psched C:\WINDOWS\system32\drivers\pacer.sys 05:55:49.0526 0x12dc Psched - ok 05:55:49.0526 0x12dc [ D271C14EE0EEEA27359CD9E14E49F0DE, C69234841EE8E9A584CABF12CE2FA965F038BD30E78C57702B28EF4B3667BD7C ] PSKMAD C:\WINDOWS\system32\DRIVERS\PSKMAD.sys 05:55:49.0541 0x12dc PSKMAD - ok 05:55:49.0572 0x12dc [ C1F787876FD293226ED816E2DC21E080, DA465F43A7EC3AE6621496B22007AF97104BC3ED6C81F2FBA20C87E9C26C7F32 ] PushToInstall C:\WINDOWS\system32\PushToInstall.dll 05:55:49.0604 0x12dc PushToInstall - ok 05:55:49.0619 0x12dc [ F7918495DF1CA8168C76AC44B44DBCEE, 85C2D9E06512318E85FFBD4F3DBF7EC389773D2BC9A2E9A26498828997E480D8 ] QWAVE C:\WINDOWS\system32\qwave.dll 05:55:49.0651 0x12dc QWAVE - ok 05:55:49.0651 0x12dc [ CE51A9A997D2830C6C64A36D7F8D8879, 706D683CAF92C259C121222446D34ED43F6E8872407C3615E2ED118ACD24D21D ] QWAVEdrv C:\WINDOWS\system32\drivers\qwavedrv.sys 05:55:49.0682 0x12dc QWAVEdrv - ok 05:55:49.0682 0x12dc [ 9D377A5872A0A7A33E258FFCBDB3F25F, D461798C6348C5D96EA002E4A1AC588B87A1A9B01AD84AB1FA6D9C6393616892 ] Ramdisk C:\WINDOWS\system32\DRIVERS\ramdisk.sys 05:55:49.0697 0x12dc Ramdisk - ok 05:55:49.0697 0x12dc [ 9500BA0F8F8E48449810BA0E802DF2CA, 3A79A1C48768C72B49913647336BF75CAFC10DCB8C6C54E4D05FBDC88FDADBCA ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys 05:55:49.0713 0x12dc RasAcd - ok 05:55:49.0744 0x12dc [ B8CCAFA23801DA081B78D06792C9B33C, 86631EE6AFF6A3A4403175D7EA68F6EDABC1B496E3CB711A914C7F28EC6C0483 ] RasAgileVpn C:\WINDOWS\System32\drivers\AgileVpn.sys 05:55:49.0776 0x12dc RasAgileVpn - ok 05:55:49.0791 0x12dc [ AC0179CC701DEBE60FF3ABACF1EFE18E, B9970819DB91FDF78D655A9A8A03ED9EE020B1F722DC4AB9D003CA0B3287FCCD ] RasAuto C:\WINDOWS\System32\rasauto.dll 05:55:49.0807 0x12dc RasAuto - ok 05:55:49.0822 0x12dc [ 5DA6019E2D404EB68A404B2993FB5237, E309C56CCD10F774927D348A9F252B4C2EFA677E47D5A95CA177FCC3A3AE493D ] Rasl2tp C:\WINDOWS\System32\drivers\rasl2tp.sys 05:55:49.0838 0x12dc Rasl2tp - ok 05:55:49.0869 0x12dc [ 2FDEC8DBA0C8CD2FAE9EDFF6BAF0D5BC, 3CE67123875921034273FFAB37703CEE7DA87B5EFFC6629DD98D01F99FEF263A ] RasMan C:\WINDOWS\System32\rasmans.dll 05:55:49.0916 0x12dc RasMan - ok 05:55:49.0916 0x12dc [ E250ADBB0C3E564BAF7CBBA4BAFE0A60, 83B6ABFC0C5700089EA967939564EF5FA2F5C40D2CA378D427CE59FFACD99D71 ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys 05:55:49.0932 0x12dc RasPppoe - ok 05:55:49.0947 0x12dc [ D2B5F1FDC2E56614B0CBFA76DDA4C65D, EF8611FD6540200D2E6C9F1376F01D1E662391CF224F34BDAA074D8DC9220775 ] RasSstp C:\WINDOWS\System32\drivers\rassstp.sys 05:55:49.0963 0x12dc RasSstp - ok 05:55:49.0979 0x12dc [ 9F9326A4CF8F4E4F1BCBA494F308CF4B, F4646F2D958CB73FB408BDA1E6DE74CA85E2E6245ED84D3AC1AE8E4A8D812613 ] rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys 05:55:49.0994 0x12dc rdbss - ok 05:55:49.0994 0x12dc [ B7BAD23CA994EFF8EA11261626326004, 056495FB4A54984CE9D28D7B45550990D4A4B0736669F0F69138BEF51A695EFA ] rdpbus C:\WINDOWS\System32\drivers\rdpbus.sys 05:55:50.0010 0x12dc rdpbus - ok 05:55:50.0010 0x12dc [ 64991B36F0BD38026F7589572C98E3D6, 9580C67C2891C34A23970B705BC64AC19CCA16AE5A6F141F59FA6AFD89F7EC44 ] RDPDR C:\WINDOWS\system32\drivers\rdpdr.sys 05:55:50.0025 0x12dc RDPDR - ok 05:55:50.0041 0x12dc [ D3E40CCDC3EFAA61D35B58DDEA06058B, AE15E37495B052C5A10C6BFB4D26D69A88021D0C3547CC25FA447BEFE919B646 ] RdpVideoMiniport C:\WINDOWS\system32\drivers\rdpvideominiport.sys 05:55:50.0057 0x12dc RdpVideoMiniport - ok 05:55:50.0057 0x12dc [ B4A6F3BFB5A07DAF4E18C14A6337A226, F906865E349390D24A3DCBC563154BBB9F307B97361832BE93BC9D44A9F3B486 ] rdyboost C:\WINDOWS\system32\drivers\rdyboost.sys 05:55:50.0072 0x12dc rdyboost - ok 05:55:50.0150 0x12dc [ B1FF8FE0794F7AEC48FB7CB141DD081A, E4DD36AB11953661916C7EBF84A59176449C6EB20654B9F939528EAB87883DED ] ReFS C:\WINDOWS\system32\drivers\ReFS.sys 05:55:50.0213 0x12dc ReFS - ok 05:55:50.0229 0x12dc [ 986822649671559AC722746CE9A37E3D, 0BC5FA256455EFB2A5C965A4B5456F810DD0169487E7F3A095D7F8BC25667250 ] ReFSv1 C:\WINDOWS\system32\drivers\ReFSv1.sys 05:55:50.0275 0x12dc ReFSv1 - ok 05:55:50.0354 0x12dc [ 7375E16F97F931B460714A33A8B4F46C, EADB1E069DFD5D5E5067D3AF83925206C23B55C01233A91FD9A2962C6795A02B ] RegSrvc C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 05:55:50.0354 0x12dc RegSrvc - ok 05:55:50.0432 0x12dc [ E70B77E333B22F06EC68DFE3E55E5E28, E75C7DDEBD2FFD5ACAB7E2FD14FB12CC4897E190F54ADCB20F6529B247A7FCC9 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll 05:55:50.0463 0x12dc RemoteAccess - ok 05:55:50.0479 0x12dc [ 844CD16309A20424F3FFAB15FBC804AD, 5FA4008B965632F8CAE398E68E9FE5797B25BD1CDD70DF5E3714A3EAB5A57E40 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll 05:55:50.0494 0x12dc RemoteRegistry - ok 05:55:50.0525 0x12dc [ 3432CBF3D68E3DC486BAA84B3DA715B2, 12C6773C1ADBB53F55900F751D5717D754D57E51A2FBFE5D53436910A677DE51 ] RetailDemo C:\WINDOWS\system32\RDXService.dll 05:55:50.0557 0x12dc RetailDemo - ok 05:55:50.0572 0x12dc [ D2EE9CCE0187C616E50D61EB30ECA262, 825C918D22FC8DBF3EE9BDB41D121A0AC3CCBFFBA147E2B26F0197552E0675DE ] RFCOMM C:\WINDOWS\System32\drivers\rfcomm.sys 05:55:50.0604 0x12dc RFCOMM - ok 05:55:50.0604 0x12dc [ 4DD0EFE49F0C020DAFEAE6F5F231362C, DF04978AF6CD34C8251B3DDE381CD77518684DCB1D2B16BD2DAFEE63AC9D5858 ] rhproxy C:\WINDOWS\System32\drivers\rhproxy.sys 05:55:50.0619 0x12dc rhproxy - ok 05:55:50.0635 0x12dc [ 2A10F8D56DB7BA8FD83FD7BAD2F9E94F, 0257C0CFBE9001DFC51D382977C77BB1B52984D01BE38E47C6B8A0018AF1CAB0 ] RmSvc C:\WINDOWS\System32\RMapi.dll 05:55:50.0666 0x12dc RmSvc - ok 05:55:50.0682 0x12dc [ E54BB972A5D80219D640F4C8FEB5D05A, 3B39E86C0434EE91765BF818B8D1001AC0B44B86665EDE87E770302D4102574E ] RpcEptMapper C:\WINDOWS\System32\RpcEpMap.dll 05:55:50.0713 0x12dc RpcEptMapper - ok 05:55:50.0760 0x12dc [ D45676C47616B9ABBFAEC97DD3B240A8, E13985D667F66B7A0082356F23270F61A57B8C2DD211B1E09D66D7970D7B4D6A ] RpcLocator C:\WINDOWS\system32\locator.exe 05:55:50.0791 0x12dc RpcLocator - ok 05:55:50.0822 0x12dc [ 23E572605024008FEB74562A2D483B94, 625B19568C4233DED550F6D43E0DB17F612CD698FD21B609288480B4C3496A3A ] RpcSs C:\WINDOWS\system32\rpcss.dll 05:55:50.0885 0x12dc RpcSs - ok 05:55:50.0900 0x12dc [ EABD30C39742A79913B595A5B6F809D4, 9067160F566220A2B21FEEE181729A796A3F3EECF75FFB75815BE5CCC7BBA64F ] rspndr C:\WINDOWS\system32\drivers\rspndr.sys 05:55:50.0916 0x12dc rspndr - ok 05:55:51.0088 0x12dc [ 7870D23C1E8AE7C8E140BD9B991700F5, F343A36A986AF1EA751606DE938292A9C130AFEDD3AE174E08212739266F1A66 ] RstMwService C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_ecb9604542bb4ba6\RstMwService.exe 05:55:51.0182 0x12dc RstMwService - ok 05:55:51.0229 0x12dc [ 3575E926BBD561784ABE3D6FAAC6AE8B, 584934B6A9C5F8137972AC16256EA34B536D0AFE301B466A89060FAA3E61BE2B ] RtkAudioService C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe 05:55:51.0244 0x12dc RtkAudioService - ok 05:55:51.0275 0x12dc [ 5914CC0C1E99A3C1711BDB1E224526D1, 54BB8636F27282B396D487B3FEA8BD73F2F6FE6DA4DE8D718EE498F75A6A5DCE ] s3cap C:\WINDOWS\System32\drivers\vms3cap.sys 05:55:51.0291 0x12dc s3cap - ok 05:55:51.0291 0x12dc [ 289D6A47B7692510E2FD3B51979A9FED, 0777FD312394AE1AFEED0AD48AE2D7B5ED6E577117A4F40305EAEB4129233650 ] SamSs C:\WINDOWS\system32\lsass.exe 05:55:51.0307 0x12dc SamSs - ok 05:55:51.0322 0x12dc [ 4CA372523A260F7DF3D9B3A931FB0ADC, 7C80A1D636C94918A14A3A58A818DFE94C0FCFA8BD152AE2B0A31D3F081E8914 ] sbp2port C:\WINDOWS\system32\drivers\sbp2port.sys 05:55:51.0338 0x12dc sbp2port - ok 05:55:51.0354 0x12dc [ 51EB2F7EE69BC9ED017D60441F0D1CE5, 7D40987B55BE7BA484E33CF60B63197059A3B92BBE84B3BD28CD0C25F6B02F92 ] SCardSvr C:\WINDOWS\System32\SCardSvr.dll 05:55:51.0385 0x12dc SCardSvr - ok 05:55:51.0385 0x12dc [ 238D26351D9394A1A4A1682CEC9BD868, 1C656503302139A11BAE19BBDBEAABF5B31F292BFA7D952E8B4693FB59018FAA ] ScDeviceEnum C:\WINDOWS\System32\ScDeviceEnum.dll 05:55:51.0432 0x12dc ScDeviceEnum - ok 05:55:51.0447 0x12dc [ EC9BDBAF319AB30D1BB25A478E169CEF, B4A2BFADDA5925DD02FBDBE9CD3F508840F8F241EA4C2E11FC35CDBC4C576F1A ] scfilter C:\WINDOWS\system32\DRIVERS\scfilter.sys 05:55:51.0463 0x12dc scfilter - ok 05:55:51.0494 0x12dc [ 1AFC01C57C5538D313BB7BE93B56A82D, F0C608933AAE705071B0ECE642BE4FCE159D6D9F633EE8C03B0A30FD697498C0 ] Schedule C:\WINDOWS\system32\schedsvc.dll 05:55:51.0525 0x12dc Schedule - ok 05:55:51.0541 0x12dc [ 7CA616D43C32CA2608D826EB8AB0D5C5, 0424A4B8F03F8EAD874C6A78190BA94781FB8E0BB7966109610CE4C653102A56 ] scmbus C:\WINDOWS\system32\drivers\scmbus.sys 05:55:51.0557 0x12dc scmbus - ok 05:55:51.0572 0x12dc [ 90A4F493C691ABF5A0C231A62F309D88, 9319B5AA78248E53DA529567CBA4D57DD7D93A43218FD66C9EFE2A10C7430581 ] SCPolicySvc C:\WINDOWS\System32\certprop.dll 05:55:51.0603 0x12dc SCPolicySvc - ok 05:55:51.0603 0x12dc [ 08ADF484ADFE02168209781258624D15, C5D8EDC0A45FBB42EA5F64E4F901C1D1D8A96FD10FB3887944AC58C04DD731F8 ] sdbus C:\WINDOWS\System32\drivers\sdbus.sys 05:55:51.0619 0x12dc sdbus - ok 05:55:51.0635 0x12dc [ 3200667DB433F0A2032FAF4DC02E2089, 5E940CA63AD21CEA08C334AC61D985BAFDBA7DCB2D388F355B5C72EFA3E23E0A ] SDFRd C:\WINDOWS\System32\drivers\SDFRd.sys 05:55:51.0635 0x12dc SDFRd - ok 05:55:51.0666 0x12dc [ CD44FB03C3F304F2853B48900DA27D7B, A3FFED33F2611EA6BC21EE5AF989163CC2C645719A0C8D402007E79BDAA3EFBD ] SDIOAssist C:\Windows\System32\SDIOAssist.exe 05:55:51.0713 0x12dc SDIOAssist - detected UnsignedFile.Multi.Generic ( 1 ) 05:55:52.0041 0x12dc Detect skipped due to KSN trusted 05:55:52.0041 0x12dc SDIOAssist - ok 05:55:52.0088 0x12dc [ 0DF317B9E48F9251716AF121BD346994, BC391CFB178DF8DF1F74C3E5B7B726975B5E99BEBCD67495660FF377DF59DE6E ] SDRSVC C:\WINDOWS\System32\SDRSVC.dll 05:55:52.0103 0x12dc SDRSVC - ok 05:55:52.0150 0x12dc [ 7688976856AB4B99BAA49C6D9FD54CFF, 32D055054EDB9D10C76AF7459DC39C6A119FF87022096F8CB4DFBCFE07EFB58A ] sdstor C:\WINDOWS\System32\drivers\sdstor.sys 05:55:52.0166 0x12dc sdstor - ok 05:55:52.0197 0x12dc [ 3D4D11111A1333E239D6890B0EA73B30, 60CB62CDF2C1863CCD9244C09BAEACA1BCFCBDEFA3650B7D201CC8FCA2183784 ] seclogon C:\WINDOWS\system32\seclogon.dll 05:55:52.0228 0x12dc seclogon - ok 05:55:52.0275 0x12dc [ ECEB454074BD9BB9216C24F147EC7164, 9B962CBDFAF32D0499614107B24888D1D5B838CE9B518042FC35AF200D8C5A1F ] SecurityHealthService C:\WINDOWS\system32\SecurityHealthService.exe 05:55:52.0307 0x12dc SecurityHealthService - ok 05:55:52.0338 0x12dc [ 9A0F874FF0FE0099A83706E6015DA522, 8D02A3274D684C7736F5C088C56C19A628EA225319CF56EE5FF366F4194A77C4 ] SEMgrSvc C:\WINDOWS\system32\SEMgrSvc.dll 05:55:52.0432 0x12dc SEMgrSvc - ok 05:55:52.0447 0x12dc [ 1EA7972A4C7163FF1D3EFE9988404D4E, 56A94B1617815C1E8A79D832B0F0CBA683C3080105CC4C87DBB9B8EAB4CD2690 ] SENS C:\WINDOWS\System32\sens.dll 05:55:52.0478 0x12dc SENS - ok 05:55:52.0478 0x12dc Sense - ok 05:55:52.0525 0x12dc [ 5A3B2A346DD3822803FAE613842839BE, C3DE970DAA10864AD81F1D9B264C2043F7C7C77288E4F7CC38A56E0C724CCFFC ] SensorDataService C:\WINDOWS\System32\SensorDataService.exe 05:55:52.0650 0x12dc SensorDataService - ok 05:55:52.0650 0x12dc [ 207FA2E4C1C74D930C61F01E3DD8EAD6, FD98FF3DF2A33E4893D0E8E8E48F88DEC42443B9CDA289EA755D53471988488A ] SensorService C:\WINDOWS\system32\SensorService.dll 05:55:52.0713 0x12dc SensorService - ok 05:55:52.0713 0x12dc [ 0BCFFAD6F3B180DD60C941B01768F733, A0B73C1BF636F14504B69606999287B6FE148C958A4F6E31E9022FF129A048E0 ] SensrSvc C:\WINDOWS\system32\sensrsvc.dll 05:55:52.0744 0x12dc SensrSvc - ok 05:55:52.0744 0x12dc [ 22068CA363EAF69A8EF6EBBBD580A8E8, 45F87C7D04B8F20290BBA8517BACE138D1E2112A268CCFFC2DFC407A81C0A197 ] SerCx C:\WINDOWS\system32\drivers\SerCx.sys 05:55:52.0760 0x12dc SerCx - ok 05:55:52.0760 0x12dc [ A5E6D99D319610030C3CA982DCAA3624, 8F1BCEDC5FEA5AF0260B573EE171E1D895EBAB5A51BEA1F84D3043F6612050A9 ] SerCx2 C:\WINDOWS\system32\drivers\SerCx2.sys 05:55:52.0775 0x12dc SerCx2 - ok 05:55:52.0791 0x12dc [ 7A289A4FFAA43D81F091A302512059A6, 9A4EC5EAF65ECB6518C462E837EB76286F1BA7A8C9E26DC46586DC4F189BD1B7 ] Serenum C:\WINDOWS\System32\drivers\serenum.sys 05:55:52.0791 0x12dc Serenum - ok 05:55:52.0807 0x12dc [ DCE5D050F3B06D30985EE126257DEEB6, 024C1F9FBEFDCBC174733A5C97B121A6D7AD30E836C1820054BCB45F99FB4373 ] Serial C:\WINDOWS\System32\drivers\serial.sys 05:55:52.0822 0x12dc Serial - ok 05:55:52.0822 0x12dc [ B13F5A8574F0B71B2E4C84B171C28724, C812F61726BDFEFFE468DFA3491E5F465D22835C54E3559E04B452940C0EEEEE ] sermouse C:\WINDOWS\System32\drivers\sermouse.sys 05:55:52.0838 0x12dc sermouse - ok 05:55:52.0869 0x12dc [ 86D26EBD7BFAECB399113AA4032B1654, B0E89BA9ECE9AFBD08EBA6F7DD9779A50A212D9D334F8DA5E32A8AFB0356CB3E ] SessionEnv C:\WINDOWS\system32\sessenv.dll 05:55:52.0900 0x12dc SessionEnv - ok 05:55:52.0900 0x12dc [ AD1B790A42984A825068B849A88AD322, 63881202D6D900656F50A0E40CB743D0769C2AD9810FE96387E9DAF2BC89E4C5 ] sfloppy C:\WINDOWS\System32\drivers\sfloppy.sys 05:55:52.0916 0x12dc sfloppy - ok 05:55:52.0932 0x12dc [ C05648C2BE6176BE557D9C7F02916388, C65D8FEDDCD9A52B04F42C64DAD2A499BF51246D36042E8DC09DD04C4C0B7BEE ] SgrmAgent C:\WINDOWS\system32\drivers\SgrmAgent.sys 05:55:52.0932 0x12dc SgrmAgent - ok 05:55:52.0947 0x12dc [ 3BA1A18A0DC30A0545E7765CB97D8E63, F9CBF1FF87D6F11920C4B7367EA2178BF13AA276C65D918950683983F268BC1F ] SgrmBroker C:\WINDOWS\system32\SgrmBroker.exe 05:55:52.0963 0x12dc SgrmBroker - ok 05:55:53.0025 0x12dc [ 5095EF2C7ECB1DD81522DA66C92C45E7, 8165AD250F490EA2CEA794BE35537ED80F984E34BCB2C05C36EA287952DBCBE9 ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll 05:55:53.0072 0x12dc SharedAccess - ok 05:55:53.0150 0x12dc [ 73355EA986F9B1D3C31460ED854B77A1, 080577CA05BE061DA02FBC5E87ACAB60DB7BB97BE761952774E521FD0B94F43F ] SharedRealitySvc C:\WINDOWS\System32\SharedRealitySvc.dll 05:55:53.0182 0x12dc SharedRealitySvc - ok 05:55:53.0260 0x12dc [ 66BC5712F8BCED56437B312F36076417, 4A3BAB6481B7B2E26021929E89C13DAAB415ED1ACB15CB2A4B934327AD2A4449 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll 05:55:53.0275 0x12dc ShellHWDetection - ok 05:55:53.0307 0x12dc [ D2A2FDF78F17AD1008EDC20F1D2105FB, CB736807C5442177DA7FAFE1BD9CB7BB7216C2613B592B1D5A1018EBDAFF3DE8 ] shpamsvc C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll 05:55:53.0338 0x12dc shpamsvc - ok 05:55:53.0338 0x12dc [ 9AB1BADC5A324DA39186B81BC6CE6E2E, 567710C90BD71600A31A3408DB065B43C844DCFD12045FDE04CD59D932DC8353 ] SiSRaid2 C:\WINDOWS\system32\drivers\SiSRaid2.sys 05:55:53.0353 0x12dc SiSRaid2 - ok 05:55:53.0353 0x12dc [ 60213AF297023C005453E1CBF7CB6FE7, 718C833E5EDFE642F3B254515E29641BF2D8E56E22F6B795024BF64721AB874E ] SiSRaid4 C:\WINDOWS\system32\drivers\sisraid4.sys 05:55:53.0369 0x12dc SiSRaid4 - ok 05:55:53.0369 0x12dc [ 196A46BA842A219EC6DE7B7B7D9AAB7E, 4EF7BE37F92557C8B0D30999541F284CC4A3E8FD98E0D78146F9F00D54E11BB9 ] SmartSAMD C:\WINDOWS\system32\drivers\SmartSAMD.sys 05:55:53.0385 0x12dc SmartSAMD - ok 05:55:53.0400 0x12dc [ FF75E3F42E77904238AED44E4E03BAEF, 535013A9E3324198E1016963EBF306F3D34583F7031EE753EC6095B15E2D492C ] smbdirect C:\WINDOWS\system32\DRIVERS\smbdirect.sys 05:55:53.0463 0x12dc smbdirect - ok 05:55:53.0494 0x12dc [ 67C32A981B42CD5243D4B5EA54A29734, 0144030B5513E7B8A71A8D600EAE8301F29F18D8675F757A774E7FC690B838AD ] smphost C:\WINDOWS\System32\smphost.dll 05:55:53.0525 0x12dc smphost - ok 05:55:53.0541 0x12dc [ AA35F8D0001485C5F56439A806F57F52, 798A317F7FC355673FA12FA0915CA96FEB7F92BC0BA3BEE593F793D98C82CF58 ] SmsRouter C:\WINDOWS\system32\SmsRouterSvc.dll 05:55:53.0603 0x12dc SmsRouter - ok 05:55:53.0650 0x12dc [ 1971BBC71602B928CF9257759E3C05E8, 9D665698FF26ED333AD385B4B7A6C0F2B6806371D278E281FA4188002A5317E8 ] SNMPTRAP C:\WINDOWS\System32\snmptrap.exe 05:55:53.0681 0x12dc SNMPTRAP - ok 05:55:53.0713 0x12dc [ 27B7D9E872939EBB34C30343F991893D, 879AFDC8C50487ED0D3CB58C70A206E185F94BE75C25C31C387F3F08740771F9 ] spaceparser C:\WINDOWS\system32\drivers\spaceparser.sys 05:55:53.0728 0x12dc spaceparser - ok 05:55:53.0744 0x12dc [ B0C788E3E6BB7000EEB4291EA1E8346C, 10A0A5BE505FEE3CBFBA87431FBF98510A8F15C23B206710662955EF3AB563E4 ] spaceport C:\WINDOWS\system32\drivers\spaceport.sys 05:55:53.0775 0x12dc spaceport - ok 05:55:53.0775 0x12dc [ AB3BDEC793187CEDF1229AC98BB7DEDF, D2EA0C5FC534C89310207AA26A8816B30FEEF3F2708A067D8BB93D3CFF9C3936 ] SpatialGraphFilter C:\WINDOWS\system32\drivers\SpatialGraphFilter.sys 05:55:53.0791 0x12dc SpatialGraphFilter - ok 05:55:53.0791 0x12dc [ B6029A86D8DE5AE85E01506E0222A491, E8A7BB7D299B457EF9E3E32893E5DCF3DEE1704B9E02A0583439941CA6E1C9AD ] SpbCx

  C:\WINDOWS\system32\drivers\SpbCx.sys

05:55:53.0806 0x12dc SpbCx - ok 05:55:53.0853 0x12dc [ 877D0CF65C2966F3602F7CCD0E6B5C39, 57ADE4D8A649A99CBFE0E438C76C0A12DDD1600148B4653DE7DD5A9AC7D47F43 ] spectrum C:\WINDOWS\system32\spectrum.exe 05:55:53.0885 0x12dc spectrum - ok 05:55:53.0916 0x12dc [ BC791006CA390D4DB83E60A649975405, 50B6FE5A4D331EC61F2B330497C714560CD667FCC150832ACA4231605905EC4C ] Spooler C:\WINDOWS\System32\spoolsv.exe 05:55:53.0947 0x12dc Spooler - ok 05:55:54.0103 0x12dc [ 6E35623027BF6EAD5F5C4E50143151DD, AF65DD88384ACA65A5FA46CF3C5246EF7B3862292466696CC9F6E4AD92163FE5 ] sppsvc C:\WINDOWS\system32\sppsvc.exe 05:55:54.0275 0x12dc sppsvc - ok 05:55:54.0291 0x12dc [ F0936C7F2506096436C3A458F40E5B1D, 7A10FEEDE17A4225FD611FC428940030CE3E2C63C36576DECF54397C7DC28583 ] srv2 C:\WINDOWS\system32\DRIVERS\srv2.sys 05:55:54.0338 0x12dc srv2 - ok 05:55:54.0353 0x12dc [ EDC2883E3E07A4974A08F85A8994CB03, 845FD59CE55546FA5D5CBD4D2254E5F5DE3CADCAC65AD7DC1C79E04740AFFA5B ] srvnet C:\WINDOWS\system32\DRIVERS\srvnet.sys 05:55:54.0385 0x12dc srvnet - ok 05:55:54.0385 0x12dc [ 3B111F9787071EC66F4CC226574C2D8B, DA2AAEAECA9FF7EB8D955805E5268D390F2A86CEB2C608EFA7636FFFEEAE7BA4 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll 05:55:54.0416 0x12dc SSDPSRV - ok 05:55:54.0431 0x12dc [ 66969AA56E77953E596470C73A9004E0, 71F4CC7595C6D5E93AAA14259DF817C6C1D4BBCF285545FD980F6DBC86A30379 ] ssh-agent C:\WINDOWS\System32\OpenSSH\ssh-agent.exe 05:55:54.0478 0x12dc ssh-agent - ok 05:55:54.0494 0x12dc [ AB269FA39C68AE41B0621BAA20EF384C, B456C0A46D41650B992C4EEBB1BA91052A8CB0E2BB1FB12DAA2D8A5FF0446758 ] SSPORT C:\WINDOWS\system32\Drivers\SSPORT.sys 05:55:54.0510 0x12dc SSPORT - ok 05:55:54.0510 0x12dc [ 2775EF3E0E76D9A44AB60D6143FA92A5, EDAE87919A509204967AFD9500021DCAE4EE9DC2D89DEF7960D5DDB1A594C9D3 ] SstpSvc C:\WINDOWS\system32\sstpsvc.dll 05:55:54.0541 0x12dc SstpSvc - ok 05:55:54.0556 0x12dc [ 32C73F69519D51B8775874E0F2808AA1, 591726261239A69CD9054A521B55E675C69EEE34BB93F54D2748B78680D17F83 ] ssudcdf C:\WINDOWS\System32\drivers\ssudcdf.sys 05:55:54.0588 0x12dc ssudcdf - ok 05:55:54.0635 0x12dc [ 423BAEA1A1A7FF889EC46C11A45F90B9, 6B4F61C00B56AC153748125EA8B81BFDB1C92B65CE7F9E23A252877D7B812A57 ] ssuddmgr C:\WINDOWS\System32\drivers\ssuddmgr.sys 05:55:54.0635 0x12dc ssuddmgr - ok 05:55:54.0666 0x12dc [ 117DF2CC1758A097CC30305C4B8908C6, C750E0115FC749F3D42589868F1DE5E421B18D9588A5191B7D1D6AC41DB8EC3C ] ssudobex C:\WINDOWS\System32\drivers\ssudobex.sys 05:55:54.0697 0x12dc ssudobex - ok 05:55:54.0713 0x12dc [ 5253D5FC68C3620D2F57774152D6B2D9, 7F2815E5E14EC96B35F172786F384801BD15E90A20724BDE18B0F3E8229D7F9F ] ssudqcfilter C:\WINDOWS\System32\drivers\ssudqcfilter.sys 05:55:54.0713 0x12dc ssudqcfilter - ok 05:55:54.0713 0x12dc [ BFB405D9197CE252B6D440F6250728FC, 2BA27199F80417A594E38B1AE9FB3B276FE92F999188D4C40CDAA3C170BC32F0 ] ssudrmnet C:\WINDOWS\System32\drivers\ssudrmnet.sys 05:55:54.0728 0x12dc ssudrmnet - ok 05:55:54.0728 0x12dc [ 76F7D7217FBDAB77798A2A244ACD641F, E65CF2CE789E721CEFCA35DF5100304C56135459DA2421DB2A0DF9E6E9DDE70F ] ssudserd C:\WINDOWS\System32\drivers\ssudserd.sys 05:55:54.0744 0x12dc ssudserd - ok 05:55:54.0744 0x12dc [ A82A4BED3D84BE21F83A97F0B7E86907, 41CD332DB0D73D51E32F3417918E0BBA290727DB14F8F0CFAC85BC91BA110CA6 ] ss_conn_usb_driver C:\WINDOWS\System32\Drivers\ss_conn_usb_driver.sys 05:55:54.0760 0x12dc ss_conn_usb_driver - ok 05:55:54.0916 0x12dc [ 4DCB636BA71692481C6FE8490D43C4DF, 09739CAE317DBA9D5E9CF3CD47BD121FF282AA936B3A00260FE01DCCE61849C6 ] StateRepository C:\WINDOWS\system32\windows.staterepository.dll 05:55:55.0088 0x12dc StateRepository - ok 05:55:55.0103 0x12dc [ B872A8B9BCE37FC1DCA51CEE7CDCF5CF, 341B96DCD01644EB1AA2A038867D4C40983C523E3794461842D022E25AED33F4 ] stdcfltn C:\WINDOWS\system32\DRIVERS\stdcfltn.sys 05:55:55.0119 0x12dc stdcfltn - ok 05:55:55.0244 0x12dc [ CF50980502600AFD6D2033EEBEF7A6C6, AC5A5D8B70E633001A524B2DBB1D4CB30C7E1DECBE7B96E50B58FEB5F6708A7D ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\steamservice.exe 05:55:55.0353 0x12dc Steam Client Service - ok 05:55:55.0353 0x12dc [ 09DC471B4573F3D01D7E448B526AE70A, 766FD1E1D2F73DE202FB337F6A6A5BA0317772AAAA644E9103BB5DF438162F51 ] stexstor C:\WINDOWS\system32\drivers\stexstor.sys 05:55:55.0369 0x12dc stexstor - ok 05:55:55.0400 0x12dc [ 4B6B76BEFA3C00BF87877D5B43F17696, DF5539656FA83CA4806F2274CBD2A9ED9A9A39AB8F135FFFB5262C8660347F30 ] stisvc C:\WINDOWS\System32\wiaservc.dll 05:55:55.0447 0x12dc stisvc - ok 05:55:55.0447 0x12dc [ 25BB6274EC9795A04AC3C08C8156D084, 44888AE5F7C4047BCF4246958D50941C331710162C64160FDF1C6A5BFCD190A2 ] storahci C:\WINDOWS\system32\drivers\storahci.sys 05:55:55.0463 0x12dc storahci - ok 05:55:55.0478 0x12dc [ 5A129E186A7A4E3CCBF090682D48F8EB, EEF4D748F421A65B0CEECC3F499574FD1B4B2E654428C0693D76074A2BC257B7 ] storflt C:\WINDOWS\system32\drivers\vmstorfl.sys 05:55:55.0478 0x12dc storflt - ok 05:55:55.0494 0x12dc [ 1DB2A5C777B1304173BC87CF105AE4A8, 62B6FB54F7331896CF3E7CA332C5253435FAD3036CBFD093913A48835994DBA5 ] stornvme C:\WINDOWS\system32\drivers\stornvme.sys 05:55:55.0509 0x12dc stornvme - ok 05:55:55.0509 0x12dc [ 995F082126674C6D1423E29FBCEA9F39, E86386156F982B59C00991D40A6E1862CA322F151BF965B14572D13AA207D614 ] storqosflt C:\WINDOWS\system32\drivers\storqosflt.sys 05:55:55.0525 0x12dc storqosflt - ok 05:55:55.0572 0x12dc [ D60F2B0B87D8CA3A41CBBD0ACCC303ED, 6EBEF14C5599C9A33B8446CE7ECED08BBD1483734A6ADB959E920C535F7B3118 ] StorSvc C:\WINDOWS\system32\storsvc.dll 05:55:55.0650 0x12dc StorSvc - ok 05:55:55.0666 0x12dc [ F2100E07D6196FA72FBEE2D39CB13816, FA783D5E6A2E11D5205EB00A1A4EAC7C9E3754704721FEEE5BE6B227683C2515 ] storufs C:\WINDOWS\system32\drivers\storufs.sys 05:55:55.0681 0x12dc storufs - ok 05:55:55.0681 0x12dc [ 0A13C67C267BFA1A0D1FE72A9D65BD5F, B44327F3134FA0166ED9E31BC724120B642AE5E96CEFF599867F03463ABB1406 ] storvsc C:\WINDOWS\system32\drivers\storvsc.sys 05:55:55.0697 0x12dc storvsc - ok 05:55:55.0697 0x12dc [ F2415E322E4BD11E8B13FB900DB44503, D3E0B9EA0AC36F7E95C08A5EE950AFA1D8AD646CBDB4670EE27315A3B7BF3F73 ] ST_Accel C:\WINDOWS\system32\DRIVERS\ST_Accel.sys 05:55:55.0713 0x12dc ST_Accel - ok 05:55:55.0775 0x12dc [ 82D2DA897ADAD3EFEC30633F9B3BE91F, 13C36B337F9B7B2D601E0BD14DEEA598F08200D287167673E04B6F236BFB4862 ] SupportAssistAgent C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe 05:55:56.0181 0x12dc SupportAssistAgent - ok 05:55:56.0197 0x12dc [ D73F83E795F3BC100C21EDA2BD6DE307, 0DC828C46E057ADA9934424BF00067B17EEB8E0108CE1E309C8DEA4CC42448BA ] svsvc C:\WINDOWS\system32\svsvc.dll 05:55:56.0244 0x12dc svsvc - ok 05:55:56.0353 0x12dc [ 0547BB19EFA07BEF0F679A054EB5CFEC, D618F57B78B3FFEC29E8C4472E0AA72EF1CA0C83DE968373B818ABA4D9747E2D ] swenum C:\WINDOWS\System32\DriverStore\FileRepository\swenum.inf_amd64_16a14542b63c02af\swenum.sys 05:55:56.0369 0x12dc swenum - ok 05:55:56.0400 0x12dc [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 05:55:56.0447 0x12dc SwitchBoard - detected UnsignedFile.Multi.Generic ( 1 ) 05:55:56.0744 0x12dc Detect skipped due to KSN trusted 05:55:56.0744 0x12dc SwitchBoard - ok 05:55:56.0791 0x12dc [ 983E28818E8754A18812EF9AAB681AAA, E0DA9FC35E54D6782ABC18EEE7CC7E62A217DD10683F9BBEABEF27B0258853B6 ] swprv C:\WINDOWS\System32\swprv.dll 05:55:56.0837 0x12dc swprv - ok 05:55:56.0900 0x12dc [ B39DC667DF14C7F1B9A58DE17BD45BE3, 52A4DBA20C16B2E34FBDDDE966700A3E8E183011A44ABECADCD4D3F93D29637B ] Synth3dVsc C:\WINDOWS\System32\drivers\Synth3dVsc.sys 05:55:56.0931 0x12dc Synth3dVsc - ok 05:55:56.0978 0x12dc [ 6C608C28F3469A3FBB1FC762945AED44, 07F5694D440B9807DB933E7091BC002C395B99F01A4423316118F1A860B60C1E ] SysMain C:\WINDOWS\system32\sysmain.dll 05:55:57.0025 0x12dc SysMain - ok 05:55:57.0041 0x12dc [ 423D06D055EF34814B8670C69452A6BD, 8FA9EFF2DDACF339499977D3602998150FC8CE0C62BE30CD390F98F95998ED76 ] SystemEventsBroker C:\WINDOWS\System32\SystemEventsBrokerServer.dll 05:55:57.0087 0x12dc SystemEventsBroker - ok 05:55:57.0103 0x12dc [ 055070E3AC1F342125E3296641BDC4D3, 6385EE02D392FCFFB41CE5C5D4CD03C245828D98DCB01F0B4358B431257F9F5B ] TabletInputService C:\WINDOWS\System32\TabSvc.dll 05:55:57.0134 0x12dc TabletInputService - ok 05:55:57.0150 0x12dc [ 20CEAECE4ECDEBC89C82F1998696D596, 439559DE34BE096824CB70A97524E843CE2802092A9C882167F4CB08FE9664A7 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll 05:55:57.0181 0x12dc TapiSrv - ok 05:55:57.0259 0x12dc [ 72AEEB1C0FA33AEA37A8B177B8A1F824, 06D3BE8D8AA1CAEE018E9CFAC126C47200AB8C7434ECCA61925AC35D1C0605C8 ] Tcpip C:\WINDOWS\system32\drivers\tcpip.sys 05:55:57.0337 0x12dc Tcpip - ok 05:55:57.0400 0x12dc [ 72AEEB1C0FA33AEA37A8B177B8A1F824, 06D3BE8D8AA1CAEE018E9CFAC126C47200AB8C7434ECCA61925AC35D1C0605C8 ] Tcpip6 C:\WINDOWS\system32\drivers\tcpip.sys 05:55:57.0478 0x12dc Tcpip6 - ok 05:55:57.0494 0x12dc [ 57BE670CF1D93717B628271B404D658A, EDD4C58EDAB985C87D6101D9CA5620146EE2BB8A1B899C635DD4CD36541DD46E ] tcpipreg C:\WINDOWS\system32\drivers\tcpipreg.sys 05:55:57.0509 0x12dc tcpipreg - ok 05:55:57.0525 0x12dc [ 2A8B28579A4964AA7EA8CEB1AC121243, BB34DC5199DE15F7D57AE52DF427C39D2FD34FAFA8136F783F2F089CDEBA0130 ] tdx C:\WINDOWS\system32\DRIVERS\tdx.sys 05:55:57.0525 0x12dc tdx - ok 05:55:57.0541 0x12dc [ 2213610676B404B157ADFFE312567458, B2E02C5049357A2DFF1CF4F6F64AC6E1DCCEDC245E96D5BC0585E88E7622D1B9 ] Telemetry C:\WINDOWS\system32\drivers\IntelTA.sys 05:55:57.0541 0x12dc Telemetry - ok 05:55:57.0556 0x12dc [ C225B94F2B27AC97C3E66C0550AEA249, 6F88375DD12A648B77BB6EB4BE527FF6678EE76A2059DB5B4CC971CDB31D0DB8 ] terminpt C:\WINDOWS\System32\drivers\terminpt.sys 05:55:57.0556 0x12dc terminpt - ok 05:55:57.0587 0x12dc [ ACF335ACC55F0AC19E3F738073A8E3C9, D131C26E62999B9FF68E2D40D316AC0D50407017E3970F45CA01089A3692359C ] TermService C:\WINDOWS\System32\termsrv.dll 05:55:57.0650 0x12dc TermService - ok 05:55:57.0666 0x12dc [ 8EC4197962A0349DFFBDC11586099DB8, 8DD5348A4983C376F63E6B209227D4D02300555F8C80A0E0DB2EA16074ABC334 ] Themes C:\WINDOWS\system32\themeservice.dll 05:55:57.0681 0x12dc Themes - ok 05:55:57.0712 0x12dc [ 761EBB96C8217CF5795ACF429BDF9E88, 4CCDB591EE16507879D8F12C0BDD40FACBEEF03BFC553A84270284D4930B433F ] TieringEngineService C:\WINDOWS\system32\TieringEngineService.exe 05:55:57.0728 0x12dc TieringEngineService - ok 05:55:57.0744 0x12dc [ 6B761253F07F46BE2B16C768B1F22551, C4E63135EB9BAAB1B7DE928C914CACEAB1E4862D6C5913B23EFC5B8986B1D91E ] TimeBrokerSvc C:\WINDOWS\System32\TimeBrokerServer.dll 05:55:57.0775 0x12dc TimeBrokerSvc - ok 05:55:57.0806 0x12dc [ 667698B4CA27F560125F74090602F16F, 6C72728D02DABFF7F95415C828372A343B4C7F12B3B32DDBED10644A040BCC4C ] TokenBroker C:\WINDOWS\System32\TokenBroker.dll 05:55:57.0884 0x12dc TokenBroker - ok 05:55:57.0900 0x12dc [ 8D0C4B0F6D48CF4750403971D7BF494D, 62ECE387CEAAD6296A35632AFC96E8A4E7018BD0A1037CD4AF8951F833AC38DA ] TPM C:\WINDOWS\System32\drivers\tpm.sys 05:55:57.0916 0x12dc TPM - ok 05:55:57.0931 0x12dc [ 6B7A6ABB160045852805449227F4F93D, 135192B2D889D498A1F2F27BDE332FDA75C36CF9267E69A4953718EFFDEAA374 ] TrkWks C:\WINDOWS\System32\trkwks.dll 05:55:57.0947 0x12dc TrkWks - ok 05:55:57.0978 0x12dc [ AEDC07787B52536F45303E8A141B6D6E, 2F227F26F9F0EFAB0725CA00AC17302F2D2D8C027B529470DE77E916B699487F ] TroubleshootingSvc C:\WINDOWS\system32\MitigationClient.dll 05:55:58.0009 0x12dc TroubleshootingSvc - ok 05:55:58.0056 0x12dc [ D098F2FC042FBF6879D47E3A86FBB4A1, 7F0E3E2682A24A6B27484226CC0C7B30F837EA08B01F82C7B7AC094BF0A88CE5 ] TrustedInstaller C:\WINDOWS\servicing\TrustedInstaller.exe 05:55:58.0072 0x12dc TrustedInstaller - ok 05:55:58.0072 0x12dc [ F613A8618CC19DD96D1E0C81C5DCB7D1, AD6DE675AC033BE6BF75FF6303EAED4B5C672689D3AEC6DB94816D60E19B7030 ] TsUsbFlt C:\WINDOWS\system32\drivers\tsusbflt.sys 05:55:58.0103 0x12dc TsUsbFlt - ok 05:55:58.0119 0x12dc [ 7845DD22FA7B91FDF0522344B1BDA012, 161A01BAC7E84B72BC6C2E83A63CC9E1DC7E2E9104C1645CD098D14094D2AC79 ] TsUsbGD C:\WINDOWS\System32\drivers\TsUsbGD.sys 05:55:58.0119 0x12dc TsUsbGD - ok 05:55:58.0134 0x12dc [ CC6D4A26254EB72C93AC848ECFCFB4AF, F7293644E8A4548907E6D34C41BA3AC60C0A623A0215D3191E6745ADEF811DA4 ] tsusbhub C:\WINDOWS\System32\drivers\tsusbhub.sys 05:55:58.0197 0x12dc tsusbhub - ok 05:55:58.0197 0x12dc [ 6244FD1056BF170E38245B4B9042BFDF, C32908B3C5800CD52EF9BDD26C77B8162831CFD19DBF1D399941B17FB909AD94 ] tunnel C:\WINDOWS\system32\drivers\tunnel.sys 05:55:58.0212 0x12dc tunnel - ok 05:55:58.0259 0x12dc [ A7C58987094E1EEBD63FB94BBE5FBC2C, 1E2E68E68380CFE42C2D975E826F6301AA7F35566E9A733B881BDC6271EC1981 ] tzautoupdate C:\WINDOWS\system32\tzautoupdate.dll 05:55:58.0322 0x12dc tzautoupdate - ok 05:55:58.0322 0x12dc [ B252C02C6606212D70B6D2AEED653E20, EA651602246A6E9EC5786CFC7B92E15F5529908CA1646CF0D8648841D986979C ] UASPStor C:\WINDOWS\System32\drivers\uaspstor.sys 05:55:58.0337 0x12dc UASPStor - ok 05:55:58.0337 0x12dc [ 1020E0CEB0EC9FB54F0A2C8E8D4CDA62, 6D952B704BF08DDF4740796230751027143F9434D651962E8CDDB8F6FE5F5A8A ] UcmCx0101 C:\WINDOWS\system32\Drivers\UcmCx.sys 05:55:58.0353 0x12dc UcmCx0101 - ok 05:55:58.0369 0x12dc [ 229B33B8499F4F2AAB1F3B590423611F, E70A2D9EEEF0C6894A0DB7990CFF6ECE3B8F389FD30B7B1949FCBDD3300B6148 ] UcmTcpciCx0101 C:\WINDOWS\system32\Drivers\UcmTcpciCx.sys 05:55:58.0384 0x12dc UcmTcpciCx0101 - ok 05:55:58.0416 0x12dc [ 7FDC3A6FD8547468CE554C8821640103, 3626760AEE42EE36E047DA6899A81E0646DFBA344A234270EAE5D635F049BE37 ] UcmUcsiAcpiClient C:\WINDOWS\System32\drivers\UcmUcsiAcpiClient.sys 05:55:58.0416 0x12dc UcmUcsiAcpiClient - ok 05:55:58.0431 0x12dc [ 1ADE4D1F65B4A1E52F701C69FB455769, 3E5CDCC098149853A7EFA05EA1B714182C82E4153F2DA3C50BA30DF2B3E05EB6 ] UcmUcsiCx0101 C:\WINDOWS\system32\Drivers\UcmUcsiCx.sys 05:55:58.0447 0x12dc UcmUcsiCx0101 - ok 05:55:58.0462 0x12dc [ D6BEDCCB2E48589944EDC675D335677E, 2F5A5BA7AEC40C1A440C8DFF81DCE5AB0BDF9CC70ADDE48F8B652665B61F9915 ] Ucx01000 C:\WINDOWS\system32\drivers\ucx01000.sys 05:55:58.0478 0x12dc Ucx01000 - ok 05:55:58.0478 0x12dc [ 6861422B7FFADDEAAA64A0539C910178, 4F8193C0A3525B78CA3CAF4731AE997A214F3DF180F0A3ADCEB2D31D3217850C ] UdeCx C:\WINDOWS\system32\drivers\udecx.sys 05:55:58.0509 0x12dc UdeCx - ok 05:55:58.0525 0x12dc [ 26D2727935221EFB0063B43A74B375BE, AB809F7EDC5C8A6EEE9610477A79131EA6C3D1BDD3D837B56B6AFF3572923DB7 ] udfs C:\WINDOWS\system32\DRIVERS\udfs.sys 05:55:58.0541 0x12dc udfs - ok 05:55:58.0619 0x12dc [ 6292A6E76DDEF0A7592C15E78C382D66, 762BBA5A06F8BA5CA1AF7CE95F6BA1F8162C6E8D363E754858098B94E8C5EBD1 ] UdkUserSvc C:\WINDOWS\System32\windowsudk.shellcommon.dll 05:55:58.0728 0x12dc UdkUserSvc - ok 05:55:58.0759 0x12dc [ 264C183C222EF95D4C64DFA8BA5F0479, 3EF244E91851E03BE77DE49FA7E36769DE287B0CB732CD0140C39FE5118D80B9 ] UEFI C:\WINDOWS\System32\DriverStore\FileRepository\uefi.inf_amd64_c1628ffa62c8e54c\UEFI.sys 05:55:58.0775 0x12dc UEFI - ok 05:55:58.0775 0x12dc [ 2EA13303C6C6071DB50A009248E6C53D, 144E970717517193390885971380828825F7955C215867D39DC5BF3D695312A0 ] UevAgentDriver C:\WINDOWS\system32\drivers\UevAgentDriver.sys 05:55:58.0790 0x12dc UevAgentDriver - ok 05:55:58.0822 0x12dc [ 484EEB13FEA9C005DB35B824FA398263, C2D567C90F21CDA34C1E8428E2446EA3EF178886A84AF36E9FDFE6D5B964569C ] UevAgentService C:\WINDOWS\system32\AgentService.exe 05:55:58.0931 0x12dc UevAgentService - ok 05:55:58.0962 0x12dc [ 01951AA29AC2A4E4EB957BA167044C27, 5F97E9D1343FE739E35B65CFA659037421A2E0A4081CF10AD4CE94B915C02BC2 ] Ufx01000 C:\WINDOWS\system32\drivers\ufx01000.sys 05:55:58.0978 0x12dc Ufx01000 - ok 05:55:58.0978 0x12dc [ EEEECAFD642DB20A8470090C2ACAA6AC, 70FEAD3371792160701D47A808FC78786766E4C7CA7C5ED8DA356BFC991A275A ] UfxChipidea C:\WINDOWS\System32\DriverStore\FileRepository\ufxchipidea.inf_amd64_1c78775fffab6a0a\UfxChipidea.sys 05:55:58.0994 0x12dc UfxChipidea - ok 05:55:59.0009 0x12dc [ E884B3B8DDA9442F58E41C2ADE3C4234, 51F112449305C5F03FEA6F046CA007A8056A65EF84986393A1B4203F53A08833 ] ufxsynopsys C:\WINDOWS\System32\drivers\ufxsynopsys.sys 05:55:59.0009 0x12dc ufxsynopsys - ok 05:55:59.0072 0x12dc [ 13B9189CA51D925FF78151A0E14C40CE, 78AEDD6D13C45B2E080BC26527CCF3BDABF764A2108249BA8B3AC4387C6A6376 ] uhssvc C:\Program Files\Microsoft Update Health Tools\uhssvc.exe 05:55:59.0103 0x12dc uhssvc - ok 05:55:59.0103 0x12dc [ E0E764F688DCACBA011BAEB2017B903F, 7802DCDA6F49494245EC9304AECED7BB2E90908BED25A4D47F1FF4615B03DED0 ] umbus C:\WINDOWS\System32\DriverStore\FileRepository\umbus.inf_amd64_b78a9c5b6fd62c27\umbus.sys 05:55:59.0119 0x12dc umbus - ok 05:55:59.0119 0x12dc [ 493AF687E60E144F59E3F5B7E27AA39B, 3062B25A7747BC417E1D498DB1B11C9631D80F57E4A048101EF5AA26206AE838 ] UmPass C:\WINDOWS\System32\drivers\umpass.sys 05:55:59.0134 0x12dc UmPass - ok 05:55:59.0165 0x12dc [ F15F32CEED183A2A2CE80132EF6B547B, 65BF62BAE95AF9CC0FB5D33D4B696410C22D77B779FA61A797890BCECD93E190 ] UmRdpService C:\WINDOWS\System32\umrdp.dll 05:55:59.0197 0x12dc UmRdpService - ok 05:55:59.0228 0x12dc [ 151F499802C7B8968CB518996C4CB6D2, 47432A0E6EACE87AB414A31F2EF6D7D42B3F9A6D3DEE9D00A1D5AF82BA841C7E ] UnistoreSvc C:\WINDOWS\System32\unistore.dll 05:55:59.0290 0x12dc UnistoreSvc - ok 05:55:59.0322 0x12dc [ 8BFFE0333C9EA9C54797C7F0E6F7769A, 0C0C7524F1A6D375D5D60DC8C602A75CB79B7311C0735956A2F42152A15C5F40 ] upnphost C:\WINDOWS\System32\upnphost.dll 05:55:59.0337 0x12dc upnphost - ok 05:55:59.0369 0x12dc [ 5C33B91675BE0C9693358C1AAA723D20, A5BB54ABBB0F7B13ACCA0997F567A81395688C6D68EB87F67F688737DC16918F ] UrsChipidea C:\WINDOWS\System32\DriverStore\FileRepository\urschipidea.inf_amd64_78ad1c14e33df968\urschipidea.sys 05:55:59.0384 0x12dc UrsChipidea - ok 05:55:59.0384 0x12dc [ ADFAB87405AE22290E24D0E8E6141AF1, BC0982BEFE4CABEA1E260C8A3266EA18A4CA158A07D1C5176890A04CC3B6A84A ] UrsCx01000 C:\WINDOWS\system32\drivers\urscx01000.sys 05:55:59.0400 0x12dc UrsCx01000 - ok 05:55:59.0400 0x12dc [ BBDE7BF496327115DD744E7D4105C7BC, 5A8CC47603A1C9D58A30A5E897F1BCDC56199B08317B9FF319D469D6DD6CAAF0 ] UrsSynopsys C:\WINDOWS\System32\DriverStore\FileRepository\urssynopsys.inf_amd64_057fa37902020500\urssynopsys.sys 05:55:59.0415 0x12dc UrsSynopsys - ok 05:55:59.0415 0x12dc [ D515F6E614AE8672243EE8CA9DCED1DF, 2A32F39CC8DBFF2F7F105C8DCB4612C3C103D16CC7CCC724B729623CB7EFBD94 ] usbaudio C:\WINDOWS\system32\drivers\usbaudio.sys 05:55:59.0462 0x12dc usbaudio - ok 05:55:59.0462 0x12dc [ FB9F25ACEBCBAEABFE30CACCB17D4EE6, 7D38FA294DA179E5535E3E481746F07E2AE47CE57192C2D1C5B780B583FD9C6D ] usbaudio2 C:\WINDOWS\System32\drivers\usbaudio2.sys 05:55:59.0494 0x12dc usbaudio2 - ok 05:55:59.0509 0x12dc [ 5F598C773A16E5D76BC45E66DAE7AEFD, 2AD99BA9A46DB659D5CC3BE0B9C2AAC7EA2824E6CE0F8EE411DE822BFB3CBAF1 ] usbccgp C:\WINDOWS\System32\drivers\usbccgp.sys 05:55:59.0509 0x12dc usbccgp - ok 05:55:59.0525 0x12dc [ 11561FC5BAA2DEB5AC8B179B591A882E, 2AD595BF4ABC146D8F533981848FF8271E983038566937BEB48A6A8F09BC60FB ] usbcir C:\WINDOWS\System32\drivers\usbcir.sys 05:55:59.0556 0x12dc usbcir - ok 05:55:59.0556 0x12dc [ D1E576C8A94A27D896B56F923ED4E4D6, 3AE5ED5EAFBC52028D082D3EC04B526EF60F5D74BBC79DD210A22D9238C61262 ] usbehci C:\WINDOWS\System32\drivers\usbehci.sys 05:55:59.0572 0x12dc usbehci - ok 05:55:59.0587 0x12dc [ 804C51B11057869624D9292040B45E56, 42404EC0F658121F6553B7DAA3511ED512B7F4B336C2032BA85CD91E8879EEAE ] usbhub C:\WINDOWS\System32\drivers\usbhub.sys 05:55:59.0603 0x12dc usbhub - ok 05:55:59.0619 0x12dc [ 2FCA9E51CFD11C0734D76013B6493C22, 54C736C9A40A769CEB7BC094D5458F2EC4FA2A5128ECB86DBCE2F2A83EAEB203 ] USBHUB3 C:\WINDOWS\System32\drivers\UsbHub3.sys 05:55:59.0650 0x12dc USBHUB3 - ok 05:55:59.0650 0x12dc [ 4E8C3BD185042836203F3AA26B1DE6BC, 8E2B1A8E3F8E1F88E73AE2A34B1726B5C5F6753BAE3FAB1E7CC82C53FF7EE891 ] usbohci C:\WINDOWS\System32\drivers\usbohci.sys 05:55:59.0665 0x12dc usbohci - ok 05:55:59.0665 0x12dc [ 7DA3D3715DFB90A171651FDBDED4E787, 8C4CE31471ABB2396CA94481D6BA0BBFD158D39DFF0F5B5779077F3702788EA7 ] usbprint C:\WINDOWS\System32\drivers\usbprint.sys 05:55:59.0681 0x12dc usbprint - ok 05:55:59.0697 0x12dc [ D4027A591DA934DF3E0085D80F3ED704, C9CAB808CA3D39AFC2A4C6F088B00E8711B0418EF74BF576626EE3ABB315CC2D ] usbser C:\WINDOWS\System32\drivers\usbser.sys 05:55:59.0712 0x12dc usbser - ok 05:55:59.0728 0x12dc [ 35F1074B2EE770E6EE1B962AFAA9955E, E068E0B161F5A44968C2E5AF7CD39CD5FD2EAF33294015DB06ACDE3BD4810A63 ] USBSTOR C:\WINDOWS\System32\drivers\USBSTOR.SYS 05:55:59.0728 0x12dc USBSTOR - ok 05:55:59.0744 0x12dc [ 3D45E616CC66D475E7261875344622F1, 3D602EA3F0A83F8FA7B9FED579B21881BB92272307634B24E0423A9A482D2CD6 ] usbuhci C:\WINDOWS\System32\drivers\usbuhci.sys 05:55:59.0759 0x12dc usbuhci - ok 05:55:59.0759 0x12dc [ 0D41A1D7DDE2FE5126AB633050ACDDB2, A5AF25E9A7BBEC2A2B9D4B085B0B1DA11D98876E1762DB593D276708517C2C36 ] usbvideo C:\WINDOWS\System32\Drivers\usbvideo.sys 05:55:59.0790 0x12dc usbvideo - ok 05:55:59.0822 0x12dc [ 7C9187D075A31CB888C421B6B54C79F5, 6A2161813473119912E75BDAF19033C8EDAAC2C2A946E1A82405FC7AFAE35D07 ] USBXHCI C:\WINDOWS\System32\drivers\USBXHCI.SYS 05:55:59.0853 0x12dc USBXHCI - ok 05:55:59.0915 0x12dc [ 66ECE7F6EFB169609D1819B2CBEDF11B, A815AC2154C822C48BEA8BBFDE56BF1BC2E72D2FFC952B34CD8976D50824ED77 ] UserDataSvc C:\WINDOWS\System32\userdataservice.dll 05:55:59.0994 0x12dc UserDataSvc - ok 05:56:00.0025 0x12dc [ F5465A51DA2C8A003C2E958C43CEC265, C5D35C1A99C5AC13175E24A7994D40092D41BB1ABD227FBA0BBFD9DE6A9D3E7B ] UserManager C:\WINDOWS\System32\usermgr.dll 05:56:00.0103 0x12dc UserManager - ok 05:56:00.0119 0x12dc [ 9A52B192FDC421B389798206847194F4, 1D598360565ECE1B9B71C3E6DE3311E25A5B12AED5A02B9EB9AB6FD35FCD9A36 ] UsoSvc C:\WINDOWS\system32\usosvc.dll 05:56:00.0165 0x12dc UsoSvc - ok 05:56:00.0197 0x12dc [ 5C5DC8E40CFC3979E793348A009434B7, 97AA8A487DAF0699E569B3E657EAC605302C74B75DAF2058856D799D32EA8026 ] VacSvc C:\WINDOWS\System32\vac.dll 05:56:00.0212 0x12dc VacSvc - ok 05:56:00.0228 0x12dc [ 289D6A47B7692510E2FD3B51979A9FED, 0777FD312394AE1AFEED0AD48AE2D7B5ED6E577117A4F40305EAEB4129233650 ] VaultSvc C:\WINDOWS\system32\lsass.exe 05:56:00.0244 0x12dc VaultSvc - ok 05:56:00.0244 0x12dc [ 661233B58190B487682839F1559A7962, 2BE132106C26A9073B6E9CB646E6A2C003558B8924ED0BDC3A0533FC98E03BF4 ] vdrvroot C:\WINDOWS\system32\drivers\vdrvroot.sys 05:56:00.0259 0x12dc vdrvroot - ok 05:56:00.0275 0x12dc [ 0781CE7ECCD9F6318BA72CD96B5B8992, 2ACEAC6D51E610F85F35175C3A511F59D5B080D95453662E58C9D578DED42A89 ] vds C:\WINDOWS\System32\vds.exe 05:56:00.0306 0x12dc vds - ok 05:56:00.0322 0x12dc [ 46684A95E908F0A6A2355AA46A3B2A77, A25DFDA0572EF014905619DF21427518EA5C01CFB13B9927ADA305B29DBBFEFE ] VerifierExt C:\WINDOWS\system32\drivers\VerifierExt.sys 05:56:00.0337 0x12dc VerifierExt - ok 05:56:00.0368 0x12dc [ 0761865C44CB46E538D09FACF7C91C35, 9E2BF492D41F558FA13622F0DB6156BA9B7BB45DC247194A1C3E0B07E703A325 ] vhdmp C:\WINDOWS\System32\drivers\vhdmp.sys 05:56:00.0400 0x12dc vhdmp - ok 05:56:00.0400 0x12dc [ 7F2F04A354582D3D34F5B2B4EFF07189, 98188182D328414832D06E957601A997AD2B2B0F088B089181EDE8FAB0AF733C ] vhf C:\WINDOWS\System32\drivers\vhf.sys 05:56:00.0431 0x12dc vhf - ok 05:56:00.0447 0x12dc [ B061B0986AE9946E4E19D9200F446C66, BB313E7DB32AC8CA3F3849E9CC71F6BC7A654ADB46FBFB2414036A85EE31AAD6 ] Vid C:\WINDOWS\System32\drivers\Vid.sys 05:56:00.0462 0x12dc Vid - ok 05:56:00.0509 0x12dc [ B37F0BF662BB504F0A9C247F24C281AD, 6281D573D9AD9AA204778C3823737726E882B17657B23CF5458C012FF7990E52 ] VirtualRender C:\WINDOWS\System32\DriverStore\FileRepository\vrd.inf_amd64_81fbd405ff2470fc\vrd.sys 05:56:00.0525 0x12dc VirtualRender - ok 05:56:00.0556 0x12dc [ C137D9B23F2E231DDAE9B998DF7027BD, 7A8C71123A368395011CFE3BD75840016BB28E9EF6B23A88BDB384D0846CDBFE ] vmbus C:\WINDOWS\system32\drivers\vmbus.sys 05:56:00.0572 0x12dc vmbus - ok 05:56:00.0572 0x12dc [ C29F63BB3B99B3F2030113160A741684, 43DF7A6DD305D1696D28A54E12B75AE041B075E789DB5D0C8DDF250E75585AA1 ] VMBusHID C:\WINDOWS\System32\drivers\VMBusHID.sys 05:56:00.0587 0x12dc VMBusHID - ok 05:56:00.0587 0x12dc [ E5BB075B6B5A1DA3C3F48CA5DFF54E77, E13E8F9523F51F976084561C9D0A843CAF550FA233521FF13FFE1C5634CA6472 ] vmgid C:\WINDOWS\System32\drivers\vmgid.sys 05:56:00.0603 0x12dc vmgid - ok 05:56:00.0618 0x12dc [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicguestinterface C:\WINDOWS\System32\icsvc.dll 05:56:00.0634 0x12dc vmicguestinterface - ok 05:56:00.0634 0x12dc [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicheartbeat C:\WINDOWS\System32\icsvc.dll 05:56:00.0650 0x12dc vmicheartbeat - ok 05:56:00.0665 0x12dc [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmickvpexchange C:\WINDOWS\System32\icsvc.dll 05:56:00.0681 0x12dc vmickvpexchange - ok 05:56:00.0697 0x12dc [ 86183A9A93B3D3293357B626015A99FD, 01FFB4245D5D1C54BE2879B3941D7402738956406A32DC3E9BB9FF435A04FD8E ] vmicrdv C:\WINDOWS\System32\icsvcext.dll 05:56:00.0712 0x12dc vmicrdv - ok 05:56:00.0728 0x12dc [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicshutdown C:\WINDOWS\System32\icsvc.dll 05:56:00.0743 0x12dc vmicshutdown - ok 05:56:00.0743 0x12dc [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmictimesync C:\WINDOWS\System32\icsvc.dll 05:56:00.0759 0x12dc vmictimesync - ok 05:56:00.0775 0x12dc [ 8486D6F63D5CF87CA08E3B3604DCB631, BD96CD0EF7B84C55DB525D655F19DE7B63756B7F3554AEBDF8F4A7A0BF2507FC ] vmicvmsession C:\WINDOWS\System32\icsvc.dll 05:56:00.0790 0x12dc vmicvmsession - ok 05:56:00.0790 0x12dc [ 86183A9A93B3D3293357B626015A99FD, 01FFB4245D5D1C54BE2879B3941D7402738956406A32DC3E9BB9FF435A04FD8E ] vmicvss C:\WINDOWS\System32\icsvcext.dll 05:56:00.0822 0x12dc vmicvss - ok 05:56:00.0822 0x12dc [ E152E9D68BC2EFB5C15107DE96EEDEE6, 3319913DA60D6A8A3E1EF1774AA209E7CFB70CFFF363656D627EEB8C0A62180A ] volmgr C:\WINDOWS\system32\drivers\volmgr.sys 05:56:00.0837 0x12dc volmgr - ok 05:56:00.0868 0x12dc [ 796F1C83861C02A97571D0EDAB490B70, 71CE8D930AE82C2B2628CBF3BB3AE1A8CF039BD702BDE912D499FCF45332F5A6 ] volmgrx C:\WINDOWS\system32\drivers\volmgrx.sys 05:56:00.0900 0x12dc volmgrx - ok 05:56:00.0900 0x12dc [ 988A7A685BB51BAC62F4E176BE5432AC, CFEE4616C10EB0CDA65D4FCC2488B879D577E0F95B5E9AB9B61258F249ED6AC6 ] volsnap C:\WINDOWS\system32\drivers\volsnap.sys 05:56:00.0931 0x12dc volsnap - ok 05:56:00.0931 0x12dc [ 770E710BEA3CCC595EE3703297B40D76, C03E3367B92307993BC169583CB298265FC1C35CF5973EC352C1E08FFCFD1928 ] volume C:\WINDOWS\system32\drivers\volume.sys 05:56:00.0947 0x12dc volume - ok 05:56:00.0962 0x12dc [ 2500B556478902E60166E0291A66F48E, F065E54B5606C59287C5628BCEAE3557B67DE8F203EDC6E7A83A7B25A6D424AC ] vpci C:\WINDOWS\system32\drivers\vpci.sys 05:56:00.0978 0x12dc vpci - ok 05:56:00.0978 0x12dc [ 1A4D9FAED669BC42E5A1CD8442729AB2, E70778AF6B0C9709CB8CEF655C6DD8B5A61CC70BFD35A43304C1308EA478C550 ] vsmraid C:\WINDOWS\system32\drivers\vsmraid.sys 05:56:00.0993 0x12dc vsmraid - ok 05:56:01.0056 0x12dc [ 875046AD4755396636A68F4A9EDB22A4, 82459B7D6CEEFF22E6E81CA445F9134C3EE917BDC3DF185700813F23AC7DB77E ] VSS C:\WINDOWS\system32\vssvc.exe 05:56:01.0118 0x12dc VSS - ok 05:56:01.0134 0x12dc [ 6E0092973E35BE6A1F5ED5CBDD202036, 33DAF53C81D5BAF9337192A84DF50C108BAE9B8A858081E2208939CCFF2622F8 ] VSTXRAID C:\WINDOWS\system32\drivers\vstxraid.sys 05:56:01.0150 0x12dc VSTXRAID - ok 05:56:01.0150 0x12dc [ 7BC30ADCCC9BCF2B0A29A320A395EC3B, 373C85F659F07366649697823B4A8B14313F0042A7A04E932429D049D18C7646 ] vwifibus C:\WINDOWS\System32\drivers\vwifibus.sys 05:56:01.0181 0x12dc vwifibus - ok 05:56:01.0181 0x12dc [ C111EE25F5130811A398B1F1496AD1C1, 13C3B69A5D0179ED3CC2C999FF97EDBAEDD63DA55DDB74427251C360706A3820 ] vwififlt C:\WINDOWS\system32\drivers\vwififlt.sys 05:56:01.0197 0x12dc vwififlt - ok 05:56:01.0228 0x12dc [ 39E78C9E9463C8D096021EA08682B5C3, 8E62D4CE0EE294B403AC2FC334C44D4AFFA3ACF07DF5E54645C271FFB0F27E40 ] vwifimp C:\WINDOWS\System32\drivers\vwifimp.sys 05:56:01.0243 0x12dc vwifimp - ok 05:56:01.0259 0x12dc [ BC5568C7E6AC6C38FC9F2150BBB1927C, 2D8BB6CB3C9A0C48AB7C2C6C90B422651849AA3DFC89B37DE5FF1FAFF33A2273 ] W32Time C:\WINDOWS\system32\w32time.dll 05:56:01.0290 0x12dc W32Time - ok 05:56:01.0337 0x12dc [ D8D8F9643CE7740F4BBEDB740659F187, 78C315EB38EE824C6FDF0A59EFCDF21B90E6CCDA1E3C98C80845F3B0F3F96204 ] WaaSMedicSvc C:\WINDOWS\System32\WaaSMedicSvc.dll 05:56:01.0368 0x12dc WaaSMedicSvc - ok 05:56:01.0368 0x12dc [ 1F16C8283230EF1F1C4E135D1C2C859B, E4F672C7E58490F82F859CAEEDD57D8ABCC31DE62A42A956BEE47113D365BE35 ] WacomPen C:\WINDOWS\System32\drivers\wacompen.sys 05:56:01.0415 0x12dc WacomPen - ok 05:56:01.0431 0x12dc [ D765B98325D89C076FEEAB1282CD08EA, AC2F0A68A2BCAAF2DECB0AAF1B50D652ED8B631B08D06B910B407FEF9069412E ] WalletService C:\WINDOWS\system32\WalletService.dll 05:56:01.0462 0x12dc WalletService - ok 05:56:01.0478 0x12dc [ 438B3E55D9D700C1C0424642872C2E28, 161F9F1F666717D95AF7EC984DDDC4D7E13844617108346FFC49A4EE99AE812F ] wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys 05:56:01.0493 0x12dc wanarp - ok 05:56:01.0493 0x12dc [ 438B3E55D9D700C1C0424642872C2E28, 161F9F1F666717D95AF7EC984DDDC4D7E13844617108346FFC49A4EE99AE812F ] wanarpv6 C:\WINDOWS\system32\DRIVERS\wanarp.sys 05:56:01.0509 0x12dc wanarpv6 - ok 05:56:01.0525 0x12dc [ 8449398F11D49864117105679B539816, 8FD3B9C72066D6A983D062DE72EEF9769339EACBF4E0D303B9E12343C9D5DE6C ] WarpJITSvc C:\WINDOWS\System32\Windows.WARP.JITService.dll 05:56:01.0540 0x12dc WarpJITSvc - ok 05:56:01.0587 0x12dc [ 17270A354A66590953C4AAC1CF54E507, 9954394B43783061F9290706320CC65597C29176D5B8E7A26FA1D6B3536832B4 ] wbengine C:\WINDOWS\system32\wbengine.exe 05:56:01.0681 0x12dc wbengine - ok 05:56:01.0712 0x12dc [ 9E2D304905CA820DFB0F00A52AD0ED89, 169116BE59C369E925F6094466E17FC940039EFE1E373FD2510B5D9CE15C1D7E ] WbioSrvc C:\WINDOWS\System32\wbiosrvc.dll 05:56:01.0775 0x12dc WbioSrvc - ok 05:56:01.0806 0x12dc [ 801B22AAFAA33ED37804A7F59C4AED31, 017CDFF28725BFB3A700EB77EFC5494581DAEDF3C2FEEA0EC72709A3D946C00C ] wcifs C:\WINDOWS\system32\drivers\wcifs.sys 05:56:01.0806 0x12dc wcifs - ok 05:56:01.0837 0x12dc [ 7807A4EFDF77E3D94A835A5C1B8AB5E0, 598B72344E49D5C490561E97FA741EA9D0F51F9A2B7CA7D33BE0B6F65E010858 ] Wcmsvc C:\WINDOWS\System32\wcmsvc.dll 05:56:01.0900 0x12dc Wcmsvc - ok 05:56:01.0931 0x12dc [ 6CDE91D497A3EC19796DE53DEBD74FB0, ACBBCBFE7A953F3CFF10A035A52984D7DB0C0B4C6B735F53006036F4CCC15059 ] wcncsvc C:\WINDOWS\System32\wcncsvc.dll 05:56:01.0962 0x12dc wcncsvc - ok 05:56:01.0978 0x12dc [ 33436DD2AA122E09A06FCD2A73B4E719, 3EB21704EC8B19B82DBABB1FA9FFCD69CB58119C36D5E9169AC1447B4CC1B358 ] wcnfs C:\WINDOWS\system32\drivers\wcnfs.sys 05:56:02.0009 0x12dc wcnfs - ok 05:56:02.0040 0x12dc WdBoot - ok 05:56:02.0056 0x12dc [ 256DEFB7A885F44D076D7E0984BA0EF3, BDABDD3DCA3D1F21DA70FF90A16550CE990B6B6A6567C37C3AE1ECCE2086FF6D ] Wdf01000 C:\WINDOWS\system32\drivers\Wdf01000.sys 05:56:02.0087 0x12dc Wdf01000 - ok 05:56:02.0087 0x12dc WdFilter - ok 05:56:02.0118 0x12dc [ BB37AF6E45E0F69222E057A74B4AFE1E, 4662064205BEC0DB7B10F1412E0A09A6E5E3B16DE443AEF7F79ACA3ACE24A51D ] WdiServiceHost C:\WINDOWS\system32\wdi.dll 05:56:02.0165 0x12dc WdiServiceHost - ok 05:56:02.0165 0x12dc [ BB37AF6E45E0F69222E057A74B4AFE1E, 4662064205BEC0DB7B10F1412E0A09A6E5E3B16DE443AEF7F79ACA3ACE24A51D ] WdiSystemHost C:\WINDOWS\system32\wdi.dll 05:56:02.0181 0x12dc WdiSystemHost - ok 05:56:02.0212 0x12dc [ B3B359E1793F3B8F8421382011B3D9AD, 10078EE520AC4D9468BF507C12824B81B34287F39E57ED12AAB40D73B6084609 ] wdiwifi C:\WINDOWS\system32\DRIVERS\wdiwifi.sys 05:56:02.0275 0x12dc wdiwifi - ok 05:56:02.0275 0x12dc [ A6C92A5F2982EBB8788E0690C19048C4, 85C54A99DD43DC1FAC7FD2A31288CEC7501F795DE8FA86857790F4CCD5AF7C18 ] WdmCompanionFilter C:\WINDOWS\system32\drivers\WdmCompanionFilter.sys 05:56:02.0290 0x12dc WdmCompanionFilter - ok 05:56:02.0306 0x12dc [ 8542EAE47D35CB658614C1813C7599A2, 67AEB01B5D4E6CA8C669EFB12A7876A378CEA4CAE2810DD790D2DAC5F07D6E52 ] wdm_usb C:\WINDOWS\System32\drivers\usb2ser.sys 05:56:02.0353 0x12dc wdm_usb - ok 05:56:02.0368 0x12dc WdNisDrv - ok 05:56:02.0415 0x12dc WdNisSvc - ok 05:56:02.0431 0x12dc [ 125E37627FA664B417DCD1EC8CA381FA, A4862F245A5D5C3E3B70F3ADB522B0017908352CE04E57802FE64DABD0BDF7E0 ] WebClient C:\WINDOWS\System32\webclnt.dll 05:56:02.0478 0x12dc WebClient - ok 05:56:02.0509 0x12dc [ BDD1061D880EC049CC42E5AED90AF4C6, B78334BEB2E83564A0775133F517D545B580ED14408D91F6C03A01C8AA8283EF ] Wecsvc C:\WINDOWS\system32\wecsvc.dll 05:56:02.0540 0x12dc Wecsvc - ok 05:56:02.0540 0x12dc [ CBA85827716DE89106F8E4AD7430620C, EF2FEAD68FE003DAC52BC2098962F397DF80B7DCD79A8F45012A050C7C0E2DB1 ] WEPHOSTSVC C:\WINDOWS\system32\wephostsvc.dll 05:56:02.0571 0x12dc WEPHOSTSVC - ok 05:56:02.0587 0x12dc [ 709E33220A2BA7CCD36993B7CEE6D1AA, B1F503DA3BCCAD661E628413B282345444AFB73D35A6B5E9068DC76CA60E6C02 ] wercplsupport C:\WINDOWS\System32\wercplsupport.dll 05:56:02.0603 0x12dc wercplsupport - ok 05:56:02.0618 0x12dc [ 733D7C71763D93B5E56C7EC30F345A33, 7B53059E6A7C86494061969A8B9294FAD534A919A260D66713D8A7D03EDC3709 ] WerSvc C:\WINDOWS\System32\WerSvc.dll 05:56:02.0650 0x12dc WerSvc - ok 05:56:02.0681 0x12dc [ 0B82A5E82CB96CDCFAE97C0F5DCB1B13, 1A6EB6464662F8EA5BA9AA9FA6B9E5A085F3931B1813F2E7C784F9AD4AB036B2 ] WFDSConMgrSvc C:\WINDOWS\System32\wfdsconmgrsvc.dll 05:56:02.0712 0x12dc WFDSConMgrSvc - ok 05:56:02.0728 0x12dc [ EF4FB4033519FF2F6118C8986AD3BC51, FEC2BA8A35BCB02E974CCD6916AC64EF73F758A3529610E32013639C8F5B98E4 ] WFPLWFS C:\WINDOWS\system32\drivers\wfplwfs.sys 05:56:02.0759 0x12dc WFPLWFS - ok 05:56:02.0806 0x12dc [ 79F49C7543FC31AAB0CB431B8D8E74F7, C4C5B3BB4E25F4D19994453224C6288EAEAA97CEE119685D9B8EDAA71E565975 ] WiaRpc C:\WINDOWS\System32\wiarpc.dll 05:56:02.0821 0x12dc WiaRpc - ok 05:56:02.0837 0x12dc [ 9B33BD737B6620E5DCD4909EFF719216, B32CFC5992FB390C1192979A02A03A2E166B4788F6C10AB3052B33B028805A27 ] Wibukey2_64 C:\WINDOWS\system32\drivers\wibukey2_64.sys 05:56:02.0884 0x12dc Wibukey2_64 - ok 05:56:02.0884 0x12dc [ 416B0938189ED0D4A8B5BBBE3F045269, 74B32619BE246D7DD6D520309692C32EE922852405DAB432CAF6012E72B495FF ] WIMMount C:\WINDOWS\system32\drivers\wimmount.sys 05:56:02.0900 0x12dc WIMMount - ok 05:56:02.0915 0x12dc WinDefend - ok 05:56:02.0915 0x12dc [ B434A84F46C70F4E67B70ED70F024B7F, 64EEB8093BA2590E83D83C5AF7C2A025B88AF5681143BCA83671104266FEEA99 ] WindowsTrustedRT C:\WINDOWS\system32\drivers\WindowsTrustedRT.sys 05:56:02.0931 0x12dc WindowsTrustedRT - ok 05:56:02.0962 0x12dc [ 982774B74EE1419D641CEB66E394A4BA, 090C4CE6B76B3904B5AE73E4F1EEBCE619194C358874D7584537012F954C54BE ] WindowsTrustedRTProxy C:\WINDOWS\system32\drivers\WindowsTrustedRTProxy.sys 05:56:02.0962 0x12dc WindowsTrustedRTProxy - ok 05:56:02.0993 0x12dc [ DA5EA7063F23E47532114FCD0969E0D1, 5F6BFA446B10A49B233CA20D65D07A955E02BEDF5E9281B25B8ADE1FEF9C6D79 ] WinHttpAutoProxySvc C:\WINDOWS\system32\winhttp.dll 05:56:03.0040 0x12dc WinHttpAutoProxySvc - ok 05:56:03.0040 0x12dc [ 0816C30E3395E667EFFFB92B4EA66A05, F6A9E7026AA60A6627680F232AE785EA9CF55FE970708E6E49151F601CC42FEE ] WinMad C:\WINDOWS\System32\drivers\winmad.sys 05:56:03.0056 0x12dc WinMad - ok 05:56:03.0087 0x12dc [ E2376F73AAA2A4BBEF5F94DE095C788A, 65E8FAF81245C08B6668EFB5B7264B2EEBCC90F30F714E1B60C2F7B60AE070C5 ] Winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll 05:56:03.0134 0x12dc Winmgmt - ok 05:56:03.0150 0x12dc [ E959DDD0BD1DE2D67591DA89B4D5C65F, 9C426AD484490BDE5D471DB638C197E36BC793D4A5F29976FDC4FDC15283575C ] WinNat C:\WINDOWS\system32\drivers\winnat.sys 05:56:03.0243 0x12dc WinNat - ok 05:56:03.0353 0x12dc [ D29D1A7DF46A6152DDB1791D896E7778, 0EFE30C33B3C6301511C5EDB52192DBAF5009A584F8F83556B8B2650DD15CD36 ] WinRM C:\WINDOWS\system32\WsmSvc.dll 05:56:03.0493 0x12dc WinRM - ok 05:56:03.0509 0x12dc [ 91D3DC62C6EDDB6554CE14C0E0B4290F, 6F8F89B350FC6BC0D23A50C593F02514854AB7D6CD234D8C8AD4B5DDDD586BA0 ] WINUSB C:\WINDOWS\System32\drivers\WinUSB.SYS 05:56:03.0540 0x12dc WINUSB - ok 05:56:03.0540 0x12dc [ F4C4FD42F8DD657157823DB617CC3A3D, D2A5ED039ED83010E0BB4BB1A69F9D142D42BE2C75E56CFCF3F157A735CB688E ] WinVerbs C:\WINDOWS\System32\drivers\winverbs.sys 05:56:03.0556 0x12dc WinVerbs - ok 05:56:03.0571 0x12dc [ 96C8DABA0B444BFE13FA2113ED5A89B4, C15812B630C8E38D782008E7DF0E950DEC343D53D242926FDD064685A222BEF0 ] WirelessKB850NotificationService C:\WINDOWS\System32\WirelessKB850NotificationService.exe 05:56:03.0587 0x12dc WirelessKB850NotificationService - ok 05:56:03.0634 0x12dc [ F125D0E005CF2C2428F7DD14148F33DB, D468ED282D25D11309B16547C362A3DA1F946538A4035AE1AE360537739A674D ] wisvc C:\WINDOWS\system32\flightsettings.dll 05:56:03.0665 0x12dc wisvc - ok 05:56:03.0743 0x12dc [ 955D212437986B78CEC488AF357D8619, 02B028FC6C5132D9580BA4717CC74DDA89CAEB7370F9F8A59D5BB1AB7D60139C ] WlanSvc C:\WINDOWS\System32\wlansvc.dll 05:56:03.0868 0x12dc WlanSvc - ok 05:56:03.0962 0x12dc [ 6DAEF6C6D68F922B07C0B9334E233238, 2431924DFBF7D5E4ACF6697BD8646A7649637CCCA261293E500469FBB2C432D2 ] wlidsvc C:\WINDOWS\system32\wlidsvc.dll 05:56:04.0071 0x12dc wlidsvc - ok 05:56:04.0134 0x12dc [ 1B279ADD6A4150FD49A6276147098803, 6CC12957A0E7FF3DCCA28D8B715EDE9C94F329FD5BAB3366D4C70362325B31CE ] wlpasvc C:\WINDOWS\System32\lpasvc.dll 05:56:04.0212 0x12dc wlpasvc - ok 05:56:04.0243 0x12dc [ 308D9054C0560499CEB2AE81AF0F98D4, D3077FDC54D87B7EBAA346B50118CE0E532B252B5BF333EE5C4A1CF411BC02AA ] WManSvc C:\WINDOWS\system32\Windows.Management.Service.dll 05:56:04.0274 0x12dc WManSvc - ok 05:56:04.0290 0x12dc [ E4F25E6E790747073A09F9F8C997889C, 98455DD24AE076A2413EA599F83E0894F608C335F3FF2F3624A17E8EAF3B3C42 ] WmiAcpi C:\WINDOWS\System32\drivers\wmiacpi.sys 05:56:04.0306 0x12dc WmiAcpi - ok 05:56:04.0321 0x12dc [ 9A48D32D7DBA794A40BF030DA500603B, CBF60ED17A5B9CF79523F1493BCCD52B3C39632C4C83DE1FD49CFD2B70F01530 ] wmiApSrv C:\WINDOWS\system32\wbem\WmiApSrv.exe 05:56:04.0337 0x12dc wmiApSrv - ok 05:56:04.0368 0x12dc WMPNetworkSvc - ok 05:56:04.0384 0x12dc [ 9405C703D91F07F1F181DE916594EED3, 7626111256C3BECD0EE9E299A41149A367A28BACEE89CC2CDD46D7499B1B7D34 ] Wof C:\WINDOWS\system32\drivers\Wof.sys 05:56:04.0399 0x12dc Wof - ok 05:56:04.0462 0x12dc [ C996632C873B749EF0ECA1A3F5318BD8, 4F411C75F7AB705BCF495B0E0BDAD1DF4B2AD7447E21CB14D2DFA1E82D1D881F ] workfolderssvc C:\WINDOWS\system32\workfolderssvc.dll 05:56:04.0556 0x12dc workfolderssvc - ok 05:56:04.0649 0x12dc [ DD1069783F5D35A14720894C7D596C04, 6C14DC41212C9BA888EF0633E8EF9AF328895BFAD74D44E24463470A7E2E4F41 ] WpcMonSvc C:\WINDOWS\System32\WpcDesktopMonSvc.dll 05:56:04.0712 0x12dc WpcMonSvc - ok 05:56:04.0728 0x12dc [ 77F69046600D63C8A585E7E40E212164, F0F6E5BF2F85E1F8E00BAEB5408665DFBA8157CD7C0578863EA0765438711B90 ] WPDBusEnum C:\WINDOWS\system32\wpdbusenum.dll 05:56:04.0806 0x12dc WPDBusEnum - ok 05:56:04.0806 0x12dc [ 024924C9E79F51560B9133EEAB866BBF, F4D464BC02C7B96EF72AA9229A99A1AD32F56390F97972C33525EF0D85304261 ] WpdUpFltr C:\WINDOWS\system32\drivers\WpdUpFltr.sys 05:56:04.0821 0x12dc WpdUpFltr - ok 05:56:04.0837 0x12dc [ B12FDDFD619C354D798E9E1C9FCF4642, 66F024A993834812277FB08AAD36FD69F79A92B403131FEB76E212ACFB58AB02 ] WpnService C:\WINDOWS\system32\WpnService.dll 05:56:04.0884 0x12dc WpnService - ok 05:56:04.0915 0x12dc [ 3D1B4E335BB9CA8A998CD5E1B2EDE855, ECD704FE62C8920D7AC2B3DC040E9D41D8A6BEBCB457888B411D133635291F36 ] WpnUserService C:\WINDOWS\System32\WpnUserService.dll 05:56:04.0978 0x12dc WpnUserService - ok 05:56:04.0978 0x12dc [ 2B98DFC181823C8D8AA39C4CC577DE3E, DAFF7CE8868299AF5EFA844C2E1F84B7EE7E498B1AFF16965CE41C2E75B2F4E4 ] ws2ifsl C:\WINDOWS\system32\drivers\ws2ifsl.sys 05:56:04.0993 0x12dc ws2ifsl - ok 05:56:05.0009 0x12dc [ 205FF7B4ED2DE3AD58D140C98A9C9FAC, 88EF7C09EEFFBCD7FB141C294AACA88D72E82E6FAA7D73C5D015F2C0F887E666 ] wscsvc C:\WINDOWS\System32\wscsvc.dll 05:56:05.0024 0x12dc wscsvc - ok 05:56:05.0024 0x12dc [ 63B845F9BB66EF7C0ACBE4275B78970B, B92BE420E5470711457F141D3433245DB71E818D6A73E1D1C347F795917FBD88 ] WSDPrintDevice C:\WINDOWS\System32\drivers\WSDPrint.sys 05:56:05.0040 0x12dc WSDPrintDevice - ok 05:56:05.0040 0x12dc [ EFB32CE8F17B4743B4CD76778BC66F1F, CA070D0BED90EDC890DBAFA7778001B9DC042EFA8AE17DDEBBA1F46CB61B6FC8 ] WSDScan C:\WINDOWS\System32\drivers\WSDScan.sys 05:56:05.0056 0x12dc WSDScan - ok 05:56:05.0071 0x12dc WSearch - ok 05:56:05.0165 0x12dc [ 6D29C1EF464FD3A33545875697360D25, B799AE7E94A651AC08E4B0115C3A7A4235CB99E27566BEEA2DF84928B7EE7A0C ] wuauserv C:\WINDOWS\system32\wuaueng.dll 05:56:05.0321 0x12dc wuauserv - ok 05:56:05.0337 0x12dc [ CF3D269E543296FC0E3EB09FA3F535F5, 46AADF6DC0F2E1034A48412DB4E2437C3212BC5FE05EFAC0D84D838685C2A485 ] WudfPf C:\WINDOWS\system32\drivers\WudfPf.sys 05:56:05.0353 0x12dc WudfPf - ok 05:56:05.0368 0x12dc [ 0B7A5464602DA68DA6BEFC2A1B5BE4C5, 7D99F44FC0474FA36B94002CBD420D18233F5E0BC14AEF3E33952A79EAE4BC20 ] WUDFRd C:\WINDOWS\System32\drivers\WUDFRd.sys 05:56:05.0384 0x12dc WUDFRd - ok 05:56:05.0399 0x12dc [ 0B7A5464602DA68DA6BEFC2A1B5BE4C5, 7D99F44FC0474FA36B94002CBD420D18233F5E0BC14AEF3E33952A79EAE4BC20 ] WUDFWpdFs C:\WINDOWS\system32\DRIVERS\WUDFRd.sys 05:56:05.0415 0x12dc WUDFWpdFs - ok 05:56:05.0431 0x12dc [ 0B7A5464602DA68DA6BEFC2A1B5BE4C5, 7D99F44FC0474FA36B94002CBD420D18233F5E0BC14AEF3E33952A79EAE4BC20 ] WUDFWpdMtp C:\WINDOWS\system32\DRIVERS\WUDFRd.sys 05:56:05.0446 0x12dc WUDFWpdMtp - ok 05:56:05.0493 0x12dc [ 0D8B1067D589EC26E90C9B39A90207DB, 877BC639A0C21EA23B433FEE798920CA70667DAB15308A47537F3B8C74DBF9D6 ] WwanSvc C:\WINDOWS\System32\wwansvc.dll 05:56:05.0556 0x12dc WwanSvc - ok 05:56:05.0602 0x12dc [ B62C41E672194A919028786E4A480541, 1A5DCE5775CD0A511F0EDCB23669525590F0F94455C567DDB76DD15C8F25D347 ] XblAuthManager C:\WINDOWS\System32\XblAuthManager.dll 05:56:05.0649 0x12dc XblAuthManager - ok 05:56:05.0681 0x12dc [ 411923E5B7992764DDB6BEADF7E7DEA6, B053C5956CCA3246D0450C01C8BD702EEDDA2B3AD865B6CA024227C67C5139B4 ] XblGameSave C:\WINDOWS\System32\XblGameSave.dll 05:56:05.0743 0x12dc XblGameSave - ok 05:56:05.0774 0x12dc [ 6E6E28D046627693CF1D2E905DC69BD1, 31D39CF82E1E98D367F631CFE5B6C6A42E13C1C01BBAABFE2CA35721627D4E43 ] xboxgip C:\WINDOWS\System32\drivers\xboxgip.sys 05:56:05.0806 0x12dc xboxgip - ok 05:56:05.0821 0x12dc [ 04BE9428D1E276DF3F6A7A5552AAB546, ACC3A8180601054BFD8FBE743A7F9CB5F2398FD463FD7EA5EF2EF78953BADBBD ] XboxGipSvc C:\WINDOWS\System32\XboxGipSvc.dll 05:56:05.0837 0x12dc XboxGipSvc - ok 05:56:05.0868 0x12dc [ 5A4F5B800B1AE1B196D3D09D1E973C9F, 8BB5D0ABF6DF5E48F17480AE72D568EBBF59E2D69E359AD951970A5BF35BFDD8 ] XboxNetApiSvc C:\WINDOWS\system32\XboxNetApiSvc.dll 05:56:05.0931 0x12dc XboxNetApiSvc - ok 05:56:05.0931 0x12dc [ C73809EA08CF05A9A78E7F65F63D3294, 4754266D964B7C2B7C4BF16B96FBBF790D90C2A96394544272444ECE9FF97DE6 ] xinputhid C:\WINDOWS\System32\drivers\xinputhid.sys 05:56:05.0962 0x12dc xinputhid - ok 05:56:06.0134 0x12dc [ ACF55BF09408960DDC21E9F3742E6795, A81582E8C6043824DF93401BE61457A96EB8D8E26E3131C1AA9927CA2214D1EF ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe 05:56:06.0259 0x12dc ZeroConfigService - ok 05:56:06.0274 0x12dc ================ Scan global =============================== 05:56:06.0290 0x12dc [ 522F9EFF8C957F906154B91A8DA698AE, FCB686BB58782506BA6A8C4F924B0872608249091C8FF9DD7129D0146ACC2BFE ] C:\WINDOWS\system32\basesrv.dll 05:56:06.0306 0x12dc [ 19979E1729CFA0E56EB4CCCB198DFD05, 7F2A683F28877562409D810946DDCA2F069715CDFB249602251DFA50065FFF7A ] C:\WINDOWS\system32\winsrv.dll 05:56:06.0306 0x12dc [ A936BCF2914B8B65532129C12EB704F7, 66E56AC990F36B5D8063766F01319477DAE0CE0A72AD190021A3AB730CA7CBF8 ] C:\WINDOWS\system32\sxssrv.dll 05:56:06.0337 0x12dc [ D8E577BF078C45954F4531885478D5A9, DFBEA9E8C316D9BC118B454B0C722CD674C30D0A256340200E2C3A7480CBA674 ] C:\WINDOWS\system32\services.exe 05:56:06.0337 0x12dc [ Global ] - ok 05:56:06.0352 0x12dc ================ Scan MBR ================================== 05:56:06.0352 0x12dc [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk0\DR0 05:56:06.0556 0x12dc \Device\Harddisk0\DR0 - ok 05:56:06.0556 0x12dc ================ Scan VBR ================================== 05:56:06.0556 0x12dc [ F2CB6A5948AD0A93EA5888C96C52333C ] \Device\Harddisk0\DR0\Partition1 05:56:06.0571 0x12dc \Device\Harddisk0\DR0\Partition1 - ok 05:56:06.0571 0x12dc ================ Scan active images ======================== 05:56:06.0571 0x12dc ================ Scan generic autorun ====================== 05:56:06.0587 0x12dc [ 783C99AFD4C2AE6950FA5694389D2CFA, 570B37A7A3FFDAFCCECCC33CBC1968FEB857B73CA3CB4DFFEDC2E67E9ABD0878 ] C:\WINDOWS\system32\SecurityHealthSystray.exe 05:56:06.0602 0x12dc SecurityHealth - ok 05:56:06.0665 0x12dc [ 925AB28AA5527B13235E065DC499C7B2, A7E5101A7F38A3195852D4C89EF27C28C025C9E8048DFF1E5DEC36FC172A9B90 ] C:\Program Files\DellTPad\Apoint.exe 05:56:06.0696 0x12dc Apoint - ok 05:56:06.0790 0x12dc [ 48515EEA1608ECD83FE26C7490460F59, C7C552D13ED12B4165FDE45F69E170D4F18B746D84B3B08E7254AAF8D9671D0C ] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe 05:56:06.0806 0x12dc AdobeAAMUpdater-1.0 - ok 05:56:06.0884 0x12dc [ 88BC7497AEE4EB09EA53FCF75BC01D99, AABED509D9342F2E855BD4445FAF98F659B103A50C3C179B6DC98E9332A2286C ] C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe 05:56:06.0993 0x12dc AdobeGCInvoker-1.0 - ok 05:56:07.0227 0x12dc [ D1F4486580E472526324C28E67AE1943, 2093BF24474A49B3C1D5E1CEF7797112C0E72F9152B6C39909C625F27686E670 ] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe 05:56:07.0509 0x12dc RtHDVCpl - ok 05:56:07.0555 0x12dc [ C83771A068C6C4477D7DB530292FB337, F70C2750A73DBE1F84CD285B14DF1674935C4904E4D26B1C9665AEDAC5FA341A ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe 05:56:07.0587 0x12dc RtHDVBg - ok 05:56:07.0618 0x12dc [ A0162348766152F43E9F7DFAA27660F3, E5F1134A373CDB78FDB386C2B42CC2F85253E399F279D1D8C7A866EBB83D77AF ] C:\Program Files\AVG\Antivirus\AvLaunch.exe 05:56:07.0634 0x12dc AVGUI.exe - ok 05:56:07.0680 0x12dc [ 8CC5E4DB25E4C22A308E2820E69D4950, A53BBE06FF226DA7E37C3ADA881AF4F856E439553DFA7D10DDECB07196545B39 ] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe 05:56:07.0696 0x12dc CDAServer - ok 05:56:07.0743 0x12dc [ 6A59DD6D7EBB0048D4BC485BCB00D62A, 4A85C9FD145FDDD94DDE2C378A898CF262C3159F220B93D1CE2813E2B31519C0 ] C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe 05:56:07.0774 0x12dc WavesSvc - ok 05:56:07.0821 0x12dc [ D5B783DACE1BBDD382A63C894BAB8E1E, 20BA7479B3BE8AC7771AA91DB9C4F3B46DADDFF9C48627A5C7C460546DD20AF3 ] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe 05:56:07.0837 0x12dc AdobeCS5ServiceManager - ok 05:56:07.0868 0x12dc [ F577910A133A592234EBAAD3F3AFA258, 36F514740EE2D2B2F7ABFFFA13D575233EC4CE774EB58BF889C09930FEF1F443 ] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe 05:56:07.0884 0x12dc SwitchBoard - detected UnsignedFile.Multi.Generic ( 1 ) 05:56:07.0884 0x12dc Detect skipped due to KSN trusted 05:56:07.0884 0x12dc SwitchBoard - ok 05:56:07.0993 0x12dc [ E2CB8918F91D39E24C4A488ED9F22325, F674C9AEECC6D2553E952B4D51BECEA3B18FA5AB191276FCA8D0434015971F67 ] C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe 05:56:08.0055 0x12dc Acrobat Assistant 8.0 - ok 05:56:08.0102 0x12dc [ 0B5CEADBC4A433501D954E88D3D53389, 551FD5DD8E994488D4FD63C03EEE2F5184483C80D93EF05B6C75F7EB67C72075 ] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe 05:56:08.0134 0x12dc IMSS - ok 05:56:08.0134 0x12dc {2D7561C3-E377-4D0B-A464-98CB4E201169} - ok 05:56:08.0290 0x12dc OneDriveSetup - ok 05:56:08.0305 0x12dc OneDriveSetup - ok 05:56:08.0430 0x12dc OneDrive - ok 05:56:08.0462 0x12dc CCleaner Smart Cleaning - ok 05:56:09.0055 0x12dc [ 984368D0C3A728D1EB3E7B58C0746EE1, 3B84962C10248D8128D52A3531432E786B236D5F4FCC2B24DF0127EB41741D67 ] C:\Users\co\AppData\Roaming\Spotify\Spotify.exe 05:56:09.0790 0x12dc Spotify - ok 05:56:09.0993 0x12dc [ DE4617D2E506813F270F570B027105D2, A9BF23D24E8B6B97054EF61D63E15B969E71CF9339E14E6B12139507484CAC11 ] C:\Program Files (x86)\Steam\steam.exe 05:56:10.0165 0x12dc Steam - ok 05:56:10.0396 0x12dc [ C55D516DC6C895265DEB4669A4966393, 3EB7E92CAE88F36D5306A95D8FCEFB1149F0E79EFE6D243CCAC5038F8D3E0BBF ] C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 05:56:10.0600 0x12dc MicrosoftEdgeAutoLaunch_8E81130D9298ACF87BB82792F8C95E90 - ok 05:56:10.0605 0x12dc OneDriveSetup - ok 05:56:10.0638 0x12dc [ 251E51E2FEDCE8BB82763D39D631EF89, 2682086ACE1970D5573F971669591B731F87D749406927BD7A7A4B58C3C662E9 ] C:\Program Files (x86)\Windows Mail\wab.exe 05:56:10.0747 0x12dc WAB Migrate - ok 05:56:10.0747 0x12dc OneDriveSetup - ok 05:56:10.0763 0x12dc [ 251E51E2FEDCE8BB82763D39D631EF89, 2682086ACE1970D5573F971669591B731F87D749406927BD7A7A4B58C3C662E9 ] C:\Program Files (x86)\Windows Mail\wab.exe 05:56:10.0794 0x12dc WAB Migrate - ok 05:56:10.0841 0x12dc OneDrive - ok 05:56:10.0966 0x12dc [ C55D516DC6C895265DEB4669A4966393, 3EB7E92CAE88F36D5306A95D8FCEFB1149F0E79EFE6D243CCAC5038F8D3E0BBF ] C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe 05:56:11.0075 0x12dc MicrosoftEdgeAutoLaunch_F051A690BAA67B3401A30F8EB7BB491E - ok 05:56:11.0685 0x12dc [ 8A2122E8162DBEF04694B9C3E0B6CDEE, B99D61D874728EDC0918CA0EB10EAB93D381E7367E377406E65963366C874450 ] C:\WINDOWS\system32\cmd.exe 05:56:11.0732 0x12dc Delete Cached Update Binary - ok 05:56:11.0732 0x12dc [ 8A2122E8162DBEF04694B9C3E0B6CDEE, B99D61D874728EDC0918CA0EB10EAB93D381E7367E377406E65963366C874450 ] C:\WINDOWS\system32\cmd.exe 05:56:11.0763 0x12dc Delete Cached Standalone Update Binary - ok 05:56:11.0935 0x12dc OneDriveSetup - ok 05:56:11.0950 0x12dc [ 251E51E2FEDCE8BB82763D39D631EF89, 2682086ACE1970D5573F971669591B731F87D749406927BD7A7A4B58C3C662E9 ] C:\Program Files (x86)\Windows Mail\wab.exe 05:56:11.0982 0x12dc WAB Migrate - ok 05:56:11.0982 0x12dc Waiting for KSN requests completion. In queue: 97 05:56:13.0466 0x12dc AV detected via SS2: Malwarebytes, C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe ( 3.0.0.225 ), 0x60000 ( disabled : updated ) 05:56:13.0466 0x12dc AV detected via SS2: Windows Defender, windowsdefender:// ( ), 0x60100 ( disabled : updated ) 05:56:13.0466 0x12dc AV detected via SS2: AVG Antivirus, C:\Program Files\AVG\Antivirus\wsc_proxy.exe ( 21.4.6162.0 ), 0x41000 ( enabled : updated ) 05:56:13.0528 0x12dc Win FW state via NFP2: enabled ( trusted ) 05:56:13.0700 0x12dc ============================================================ 05:56:13.0700 0x12dc Scan finished 05:56:13.0700 0x12dc ============================================================ 05:56:13.0700 0x12d4 Detected object count: 0 05:56:13.0700 0x12d4 Actual detected object count: 0

En fin, finalmente hice todos los pasos pero yo no veo nada sospechoso salvo unas entradas en el archivo Hosts y que el Rkill reasigna las extensiones .exe, .com y .bat, pero tu eres el experto, de antemano mil gracias por tu seguimiento y atenciones =D.

P.D. Sigo en Modo a Prueba de Fallos así que no sé si se ha solucionado el tema de la lentitud, uso de CPU 100% y Disco Duro 100%, así como desconexiones fortuitas de la Wifi.

Atte Miguel Castillo

1 me gusta

Hola buenas @Miguel_Castillo1

Disculpa en que haya tardado tanto en responder, pues he sufrido un accidente que me ha dejado indispuesto durante un tiempo.

¿Sigues necesitando mi ayuda?

Si es así, dímelo y seguiré prestándote ayuda.

Salu2.

1 me gusta

Hola Marr0n, Ojalá y ya te encuentres mejor, lo primero es la salud! todo puede esperar, pues lo primero siempre debe ser la gente, Ojalá y pronto te recuperes al 100%!

Con respecto al tema del foro, si, si aún me puedes ayudar, yo encantado, sólo que supongo que habría que iniciar el proceso nuevamente porque tuve que volver a entrar en mi Lap en modo normal, los programas de detección creo que no encontraron nada importante, pero tu dime, soy materia dispuesta para hacer lo sea necesario.

Mil gracias por tu atención.

1 me gusta

Hello? Anybody home?

1 me gusta

Hola buenas @Miguel_Castillo1

Disculpa en que haya tardado tanto en responder, pues como ya te dije hace un tiempo: he sufrido un accidente que me ha dejado indispuesto durante un tiempo.

Pensé que me recuperaría más rápido, pero no ha sido así.

Muchas gracias por tus palabras, ahora ay estoy mejor. Pero tengo poco tiempo para el foro. De todas formas. Seguiré con tu caso.

Sí, correcto como ha pasado un tiempo, tiene que volver a repetirse el proceso. Ahora te pongo exactamente que es lo que tiene que volverse a repetir para ver el estado actual y actuar en consecuencia.

Haz esto nuevamente:

:one: EN BUSCA / ELIMINACIÓN DE MALWARE

Por favor, descarga todo el software de los enlaces que pongo/de sus respectivos manuales.

Ahora ejecutarás una serie de herramientas respetando el orden los pasos con todos los programas cerrados incluidos los navegadores.

Inicia de nuevo el equipo desde el :arrow_forward: Modo Seguro – con funciones de Red, de Windows. Si no funcionasen los métodos que se explican en el anterior post, prueba estos otros. Más concretamente, primero el 3 (Seleccionando Red en lugar de Mínimo) y si no el 2 (también Red).

Una vez iniciado en este modo, empiezas haciendo todos los pasos que te pondré a continuación.

P.D.: Si el quipo no te arrancase en Modo seguro (cosa que puede pasar), me lo dices e intentaremos arreglar el sistema para que arranque en Modo Seguro. Pues hay malwares que ya se encargaran de que no puedas iniciar en Modo Seguro.

  1. Descarga y ejecuta RKill, más concretamente debes de descargar la que está renombrada bajo el nombre de iExplore.exe. Para evitar el bloqueo de posibles malwares que pueda haber en tu equipo. Una vez que esta haya sido ejecutada, es muy importante no reiniciar el sistema hasta que te lo solicite yo o alguno de los programas de desinfección de los que estemos utilizando.

Me explico, por ejemplo: has iniciado la máquina en Modo Seguro con funciones de Red, has ejecutado Rkill y seguidamente realizas un Análisis con Malwarebytes. Este te detecta infecciones y te pide reiniciar la máquina para poder finalizar exitosamente su desinfección. Seguidamente, yo te he indicado que ejecutes por ejemplo el ESET Online Scanner, pues bien como no hemos acabado de desinfectar la máquina y estamos realizando el proceso de desinfección, y has tenido que reiniciar, ya que te lo ha pedido Malwarebytes pues debes de ejecutar nuevamente Rkill y después acto seguido el ESET ONline.

¿Me entiendes?

Si por ejemplo, incluso con Rkill, Malwarebytes AntiMalware o la herramienta que sea que te he pedido que utilices, ves que se bloquea y que al cabo de un buen rato no responde. Pues pasas a la siguiente y me informas de ello. Y así con todas. ¿OK? ¿Se entiende?

Realizas lo siguiente:

  1. Manual Malwarebytes Anti-Rootkit Beta sigues las instrucciones de su manual y me traes sus correspondientes Informes de análisis: Mbar-log.txt y System-log.txt tal como se indica en su manual.

  2. Descarga, instala y ejecuta TDSKiller de acuerdo a su Manual TDSKiller. Marca todas las casillas (Loaded Modules, Verify file digital signatures y Detect TDLFS file system). Sí te pide reiniciar lo haces, ejecutas de nuevo la herramienta y al marcar nuevamente las casillas que te he dicho, ya te dejara analizar.

NOTA IMPORTANTE

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo:

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado.
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA (programas/software/complementos/extensiones del navegador…).
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…).
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

EN TU PRÓXIMA RESPUESTA

  • Respondes a las preguntas que te haya realizado.
  • Traes los reportes de rkill, Malwarebytes Anti-Rootkit y TDSKiller.
  • Comentas el estado en general del ordenador respecto al problema inicial planteado.

Salu2.

De nada.

Yes.