Un virus me ha inutilizado mi malwarebites y no lo puedo volver a instalar

Tras hacer todo lo indicado, el pc, en principio, va perfecto. Pero hay procesos qye no he podido ejecutar como: JunkwareRemoval Tool ESET online, el mismo bloqueador de malware, no me dejaba abrirlo. Muchas gracias por todo. Si he d ehacer algo más, indícamelo @Marr0n Lo que pueda hacer por vosotros, yo encantado!

Hola, buenas @massbateria

Menudo Zoológico tienes por allí montado. Bien vamos por partes…

Respecto a RKill >> en este caso ha detectado que respecto al archivo Hosts del sistema no se puede editar, ya que no se han podido fijar los permisos. Síntomas muy típicos de diverso tipo de malware que tienes. Tienes/tenías (ya lo iremos viendo) el archivo HOSTS bastante corrompido.

Muchas infecciones informáticas modifican el archivo HOSTs de Windows para que no puedas acceder a varios sitios o para que cuando visites un sitio legítimo seas redirigido a uno bajo el control de los desarrolladores del malware. Una vez realizados estos cambios, ciertos programas maliciosos cambiarán los permisos del archivo HOSTS para que usted no pueda eliminarlo o modificarlo. Hosts-perm.bat restablecerá estos permisos para que vuelvas a tener acceso completo a él.

Si quieres saber más información sobre el archivo HOSTS o te pica la curiosidad, te dejo un artículo que explica perfectamente su funcionalidad: The Hosts File and what it can do for you

¿Por qué en tu post número 7 pones un reporte de mb-clean:3.1.0.1035? Si yo no te lo he indicado. :thinking: :thinking: :thinking:

Respecto a IFS >> tienes dos unidades con una fragmentación que no es recomendable. Ya nos encargaremos después de eso. Tienes Spybot - Search and Destroy que ya no sirve para nada, pues está muy desactualizado hoy en día para eliminar malware, después ya nos encargaremos de este, pues deberíamos de quitarlo. En su debido momento ya estabilizaremos la máquina y la fortificaremos un poco para evitar posibles infecciones. Te ha detectado malware de tipo Adware.

¿Por qué en tu post número 10 pones un reporte de Windows Registry Editor Version 5.00? Si yo no te lo he indicado. :thinking: :thinking: :thinking:

Aparte veo en ese log, de que tu Windows no es legal o bien de que al menos lo has activado ilegalmente con el KMSpico. ¿Verdad? Pues esa mierd… de CRAK del KMSpico siempre trae malware variopinto es como jugar a la ruleta rusa y esperar no morir en algún momento dado. Y al final… RIP.

Buena parte del malware que tienes es básicamente porque has descargado KEYGENS, CRACKS y etc… Nunca descargues cosas de estas en tu máquina principal o de uso diario, ya que después te traes sorpresas y pasa lo que pasa…

Respecto al AdwCleaner >> solo era necesario el log que te pedi de: C:\AdwCleaner\Logs\AdwCleaner[C0].txt

Te ha detectado bastantes Adwares todo y que los ha eliminado todos a excepción de uno que requiere obligatoriamente que reinicies la máquina. Así que hazlo. ¿Lo hiciste?

Respecto al TDSKiller >> ha detectado un buen Zoológico de malware diverso. También ha detectado los Adwares que se enviaron a la cuarentena del AdwCleaner como malware, en ese caso serían falsos positivos, ya que al estar en la cuarentena pues ya son inofensivos. De todas formas veo que o bien has mandado todo lo detectado a la cuarentena o lo has eliminado según las indicaciones del programa :+1: :+1:

OK. Me alegro de que vaya mejor ahora. Pero de momento aún no hemos finalizado, pues estoy segurísimo de que aún queda malware en tu PC.

¿Al intentar ejecutar el JRT que es lo que te lo ha impedido o que error te ha dado?

¿Al intentar ejecutar el ESET ONLINE que es lo que te lo ha impedido o que error te ha dado?

A que te refieres con:

No te entiendo. Explícate por favor. ¿OK?

De nada. OK, pues lo dicho de todas formas te lo resumo en:

:one: EN TU PRÓXIMA RESPUESTA

  • ¿Cuando has realizado todos estas análisis has conectado todos tus dispositivos externos como USBs, discos duros externos, etc? Por lo que veo los conectaste todos. ¿Correcto?
  • Respondes a las preguntas que te haya realizado a lo largo del post.

Salu2.

Hola @Marr0n , intentaré responder a todas las preguntas :wink:

“¿Por qué en tu post número 7 pones un reporte de mb-clean:3.1.0.1035 ? Si yo no te lo he indicado”.

¿Por qué en tu post número 10 pones un reporte de Windows Registry Editor Version 5.00 ? Si yo no te lo he indicado. :thinking: :thinking: :thinking:

A veces, no sé exactamente lo que me pides que ten envía y por eso, para no quedarme corto, te he enviado lo que creía que me pedías.

Te ha detectado bastantes Adwares todo y que los ha eliminado todos a excepción de uno que requiere obligatoriamente que reinicies la máquina. Así que hazlo. ¿Lo hiciste?

Efectivamente, lo he hecho.

Tras hacer todo lo indicado, el pc, en principio, va perfecto. Pero hay procesos qye no he podido ejecutar como: JunkwareRemoval Tool ESET online, el mismo bloqueador de malware, no me dejaba abrirlo. Muchas gracias por todo. Si he d ehacer algo más, indícamelo @Marr0n Lo que pueda hacer por vosotros, yo encantado!

Junkware, me dice vuestra página,que ya no la usábais y el enlace no estaba. ESET, no pude entrar. Le daba al enlace y volvía a la misma página. Al bloqueador, me refiero a una página de Adblock.

Y si, conecté todos mis dispositivos.

Muchas gracias por todo. Esepro instrucciones. Por cierto, ya he desinstalado Spybot. Ahora me sale algo como, que falta insertar una unidad de disco o algo así. Priemr me salió con SDCleaner.com y después de borrar Spybot, me sale lo mismo, pero con Spotify.com o.exe, no recuerdo.

Si me vuleve a salir, te adjuntaré captura de pantalla.

Hola, buenas nuevamente @massbateria

Ok. Vale bueno, entiendo que mis mensajes sean largos. Pero con todas las instrucciones que te doy una vez leídas y entendidas correctamente, pues queda bien claro lo que te pido. Así que no sé de donde has sacado lo de mb-clean:3.1.0.1035 y Windows Registry Editor Version 5.00, ya que he revisado mis anteriores respuestas y yo no te lo he indicado en ningún momento. Lo digo ya que en el futuro te pediré hacer unas cosas más y sí después haces cosas que yo no te he pedido y las haces por tu cuenta, pues pueden afectar negativamente al problema complicándolo aún más. Así que por favor cíñete y haz exactamente y estrictamente lo que yo te pida. Y si tienes algún tipo de duda / confusión, pues me lo preguntas. ¿Entendido?

Ok. Perfecto.

Sí que es verdad que está desactualizado y por ello ya te he hecho utilizar otras herramientas y otras que faltan. De todas formas en tu caso concreto sí que quiero que lo utilices. El enlace sí que funciona, pues lo acabo de probar yo mismo, simplemente le tienes que dar al botón de descarga, de todas formas te pongo el enlace de descarga directo de nuestro foro del JRT_DESCARGA.

Que extraño, ami me funciona perfectamente de todas formas vete a saber si con el malware que tienes más el Adblock tienes algún conflicto. Así que descárgalo de (descarga directa del fabricante): ESET_ONLINE_SCANNER_DESCARGAR

OK.

OK. PERFECTO.

De nada. OK, seguimos.

MAL MUY MAL. Pues lee mis mensajes por favor, sí que es cierto que te dije que estaba desactualizado, pero que ya lo quitaríamos de una forma que te diría en un momento dado. NO QUE LO QUITASES TU POR TU CUENTA, YA QUE AHORA PUEDEN QUEDAR RESTOS DE ESTE Y Será MÁS DIFÍCIL QUITARLOS SI ES QUE HAY. Lo que te dije fue:

Lee con más atención por favor. Y si no, preguntas.

:one: EN TU PRÓXIMA RESPUESTA

  • Realizas JRT y traes su reporte.
  • Realizas Eset Online Scaner y traes su reporte.
  • Realizas NUEVAMENTE Kasperky Virus Removal Tool y traes su reporte.
  • Todos ellos lo haces en base a las instrucciones que te di en su momento: Modo Seguro…, conectar todos los dispositivos, etc…
  • Respondes a las preguntas que te haya realizado a lo largo del post.

NOTA IMPORTANTE

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo:

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado.
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA (programas/software/complementos/extensiones del navegador…).
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…).
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

:warning: Muy Importante :warning: Coloca los diferentes reportes que te he pedido como se muestra en la siguiente imagen:

Salu2.

Hola @Marr0n buenos días. Resulta que el ordenador no me deja acceder a JRT. Clicko en el link y se cierra enseguida. Debe ser cosa del malware. Sí que me he podido descargar ESET. Díme que hago ahora. Instalo ESET o espero tus instrucciones?

Hola @massbateria

OK. No es lo más normal del mundo, pero podría ser.

Sí, utiliza el ESET tal y como te dije en:

Y me traes su reporte.

Ahora ejecutarás una serie de herramientas respetando el orden los pasos con todos los programas cerrados incluidos los navegadores.

Descarga, instala y ejectua ZHP Cleaner siguiendo su manual, lo descargas, instalas y ejecutas. Cuando termine, elimina todo lo que encuentre.

Inicia de nuevo el equipo desde el :arrow_forward: Modo Seguro – con funciones de Red, de Windows. Si no funcionasen los métodos que se explican en el anterior post, prueba estos otros. Más concretamente, primero el 3 (Seleccionando Red en lugar de Mínimo) y si no el 2 (también Red).

Una vez iniciado en este modo, empiezas haciendo todos los pasos que te pondré a continuación.

P.D.: Si el quipo no te arrancase en Modo seguro (cosa que puede pasar), me lo dices e intentaremos arreglar el sistema para que arranque en Modo Seguro. Pues hay malwares que ya se encargaran de que no puedas iniciar en Modo Seguro.

Realizas lo siguiente:

  1. Manual Malwarebytes Anti-Rootkit Beta sigues las instrucciones de su manual y me traes sus correspondientes Informes de análisis: Mbar-log.txt y System-log.txt tal como se indica en su manual.

  2. Descarga, instala y ejecuta TDSKiller de acuerdo a su Manual TDSKiller. Marca todas las casillas (Loaded Modules, Verify file digital signatures y Detect TDLFS file system). Sí te pide reiniciar lo haces, ejecutas de nuevo la herramienta y al marcar nuevamente las casillas que te he dicho, ya te dejara analizar.

NOTA IMPORTANTE

Por Favor, mientras estemos desinfectando tu maquina o terminando de hacerlo:

  • No realices pasos/acciones que NOSOTROS no te hayamos indicado.
  • No descargues NADA de Internet y/o conectes dispositivos externos a tu equipo.
  • No instales NADA (programas/software/complementos/extensiones del navegador…).
  • No ejecutes otros programas de seguridad (Antivirus, Antimalware, ANTINADA…).
  • No realices por tu cuenta otros procedimientos.
  • Usa tu equipo EXCLUSIVAMENTE para desinfectarlo siguiendo nuestras indicaciones.

:one: EN TU PRÓXIMA RESPUESTA

  • Traes los reportes de ESET Online Scanner, ZHP Cleaner, Malwarebytes Anti-Rootkit y TDSKiller.
  • Comentas el estado en general del ordenador respecto al problema inicial planteado.

Salu2.

Hola @Marr0n Aquí te traigo los reportes. Espero haberlo hecho bien ahora.

17/02/2021 7:21:27
Archivos analizados: 323795
Archivos detectados: 18
Archivos desinfectados: 18
Tiempo total de análisis 02:39:01
Estado del análisis: Finalizado


C:\AdwCleaner\Quarantine\bbSqWy6yhK\3a7891bf03ee5a01b397b6c44a8b332f.exe	una variante de Win32/Adware.Zdengo.EW aplicación	desinfectado por eliminación
C:\AdwCleaner\Quarantine\C\Program Files\DriverToolkit\DriverToolkit.exe.vir	una variante de Win32/UwS.DriverToolkit.A aplicación	desinfectado por eliminación
C:\AdwCleaner\Quarantine\C\Program Files\GSafe\nfapi.dll.vir	una variante de Win32/NetFilter.A aplicación potencialmente no segura	desinfectado por eliminación
C:\AdwCleaner\Quarantine\C\Program Files\GSafe\ProtocolFilters.dll.vir	una variante de Win32/NetFilter.A aplicación potencialmente no segura	desinfectado por eliminación
C:\AdwCleaner\Quarantine\v1\20210211.091018\9\windefender.exe#EE41CB463B852F74	una variante de WinGo/RanumBot.J Troyano	desinfectado por eliminación
C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45146.exe	una variante de Win32/uTorrent.C aplicación potencialmente no deseada	desinfectado por eliminación
C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45231.exe	una variante de Win32/uTorrent.C aplicación potencialmente no deseada	desinfectado por eliminación
C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45395.exe	una variante de Win32/uTorrent.C aplicación potencialmente no deseada	desinfectado por eliminación
C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45505.exe	una variante de Win32/uTorrent.C aplicación potencialmente no deseada	desinfectado por eliminación
C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45790.exe	una variante de Win32/uTorrent.C aplicación potencialmente no deseada	desinfectado por eliminación
C:\Users\massbateria\AppData\Roaming\uTorrent\uTorrent.rar	una variante de Win32/uTorrent.C aplicación potencialmente no deseada	eliminado
E:\datos borja\SONIDO\IZotope.iDrum.VSTi.RTAS.v1.6.1.Incl.Keygen-AiR.rar	una variante de Win32/Keygen.AD aplicación potencialmente no segura	eliminado
E:\datos borja\SONIDO\iZotope_Alloy_Setup_v1_00.rar	una variante de Win32/Keygen.AD aplicación potencialmente no segura	eliminado
E:\datos borja\SONIDO\Peavey_Electronics_ReValver_MK_III_APP_w_Universal_Patch_by_TheXROOster.zip	una variante de Win32/HackTool.Patcher.A aplicación potencialmente no segura	contenía archivos infectados
E:\datos borja\SONIDO\Revalver MK III win crack.zip	una variante de Win32/HackTool.Patcher.A aplicación potencialmente no segura	contenía archivos infectados
E:\Dropbox\Dropbox\Dropbox\tecnica\Finale 2011(1).rar	una variante de Win32/HackTool.Patcher.A aplicación potencialmente no segura	eliminado
E:\EZDrummer 2\R2R\Toontrack_KeyGen.exe	Win32/Keygen.ACE aplicación potencialmente no segura,Win32/Keygen.ML aplicación potencialmente no segura	desinfectado por eliminación
I:\Windows Loader.exe	Win32/HackTool.WinActivator.I aplicación potencialmente no segura	desinfectado por eliminación
[CODE][B]~~~~~~~~~~~| Inicio: [/B]

*IFS (InfoSpyware First Steps) v 1.3
*www.InfoSpyware.com | www.ForoSpyware.com
*Iniciado: 11/02/2021 a las 09h.00m.55s

[B]~~~~~~~~~~~|  Información del Sistema:[/B]

OS: Microsoft Windows 7 Ultimate  x64 Service Pack 1
Idioma: Spanish (Spain, International Sort) (España|es-ES)
Permisos de Administrador / ON
Windows se Inició en   Modo Seguro con Funciones de Red
Drive: C:\Windows (Install: \Device\HarddiskVolume3)

[B]~~~~~~~~~~~| Arquitectura Fisica:[/B]

CPU: System manufacturer
CPU Modelo: System Product Name
Procesador: AMD A4-5300 APU with Radeon(tm) HD Graphics     (x64-BasedPC)
Memoria RAM: 16 Gb. En Uso: 15 %
Video: NVIDIA GeForce GT 710
Chip: GeForce GT 710 Capacidad video:-2048 MB (Integrated RAMDAC)

[B]~~~~~~~~~~~| Unidades[/B]

C: [FIXED|NTFS|] - [189.8 Gb][21.3 Gb][168.5 Gb]
E: [FIXED|NTFS|NUEVO] - [931.5 Gb][289.9 Gb][641.6 Gb]
D: [REMOVABLE||] - [0 Gb][0 Gb][0 Gb]
F: [REMOVABLE||] - [0 Gb][0 Gb][0 Gb]
G: [REMOVABLE||] - [0 Gb][0 Gb][0 Gb]
H: [REMOVABLE||] - [0 Gb][0 Gb][0 Gb]
I: [REMOVABLE|NTFS|GRMCULFRER_ES_DVD] - [14.9 Gb][14.1 Gb][0.8 Gb]
J: [REMOVABLE|FAT32|UDISK] - [28.8 Gb][27.9 Gb][0.1 Gb]
[COLOR=#FF0000][B]C:\ Fragmentación total 35.83% - Desfragmentar unidad [/B][/COLOR]
[COLOR=#FF0000][B]E:\ Fragmentación total 26.86% - Desfragmentar unidad [/B][/COLOR]

[B]~~~~~~~~~~~| Seguridad del SO[/B]

SafeBoot: Inicio en Modo seguro Correcto
Security Center: Correcto (Servicio Activo)
Windows Update: [COLOR=#FF0000][B]El servicio no está activo[/B][/COLOR] [LST: 2019-12-29 11:24:20][LD: 2019-12-27 16:25:30][LI: 2019-12-27 16:26:22][LRP: 2020-03-23 09:24:16]
SP: Spybot - Search and Destroy *[COLOR=#FF0000][B]Protección Residente [OFF][/B][/COLOR] / [COLOR=#FF0000][B]Actualizar[/B][/COLOR]*
SP: Windows Defender *[COLOR=#FF0000][B]Protección Residente [OFF][/B][/COLOR] / Actualizado*
FW: Windows Firewall *Habilitado*

[B]~~~~~~~~~~~|  Update Check[/B]

Internet Explorer Versión Instalada 11
Google Chrome Versión Instalada 88.0.4324.150

[B]~~~~~~~~~~~| Process List[/B] 

MBAMTray.exe (Malwarebytes Anti-Malware)
MBAMservice.exe (Malwarebytes Anti-Malware)

[B]~~~~~~~~~~~| Install Check[/B] 


CCleaner [5.64]

[B]~~~~~~~~~~~| Registry Check[/B]

HKLM\Run(x64): [AdobeGCInvoker-1.0] "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe"
HKLM\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
HKLM\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
HKLM\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
HKLM\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
HKLM\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLL
HKLM\Run: [CTHelper] CTHELPER.EXE
HKLM\Run: [CTxfiHlp] CTXFIHLP.EXE
HKLM\Run: [haleng] C:\Users\MASSBA~1\AppData\Local\Temp\haleng.exe
HKLM\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
HKLM\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean
HKLM\Run: [GoogleChromeAutoLaunch_DA49533490B544962D76CEA7A7F9414D] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
HKLM\Run: [4982061] "C:\Users\massbateria\AppData\Roaming\id2fgb1k0de\bpdi2b0oa1i.exe" /VERYSILENT
HKLM\Run: [WinterSnowflake] "C:\Windows\rss\csrss.exe"
Winlogon(x64): Shell = explorer.exe
Winlogon: Shell = explorer.exe
Userinit(x64): Userinit = userinit.exe,
Userinit: Userinit = userinit.exe,

[HKCR\.\.open\command] -> Navegador Preferido es Google Chrome

[B]~~~~~~~~~~~| PUPs Check[/B]

HKCU\Software\simplitec
HKLM\Software\simplitec
HKCU64\Software\simplitec
HKCU\Software\Tencent
HKCU64\Software\Tencent

C:\Users\massbateria\AppData\Roaming\Tencent

[B]~~~~~~~~~~~| Listado 7 Días (Predeterminado)[/B]

[10/02/2021 23:14] - C:\Windows\ntbtlog.txt
[10/02/2021 19:10] - C:\Windows\rss
[10/02/2021 22:08] - C:\Windows\setupact.log
[10/02/2021 22:08] - C:\Windows\setuperr.log
[10/02/2021 19:05] - C:\Windows\trustedlogos
[10/02/2021 19:10] - C:\Windows\windefender.exe
[04/02/2021 10:43] - C:\Windows\{00000002-00000000-00000005-00001102-00000004-40011102}.CDF
[11/02/2021 09:00] - C:\FSTool
[11/02/2021 09:00] - C:\IFS.log

[B]~~~~~~~~~~~| C:\Windows\Tasks:[/B]

[25/01/2019 10:13] - C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
[25/01/2019 10:13] - C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job

[B]~~~~~~~~~~~| End Report[/B]
*Finalizado 09:05:05
*Se limpiaron los archivos temporales
*[1599815] C:\Users\massbateria\Downloads\IFS.exe
*Herramienta de Análisis e investigación [/CODE]
20:33:33 # product=EOS
# version=8
# esetonlinescanner.exe=3.4.7.0
# country="Spain"
# lang=3082
20:36:09 Updating
20:36:09 Update Init
20:36:10 Update Download
20:37:29 esets_scanner_reload returned 0
20:37:29 g_uiModuleBuild: 48496
20:37:29 Update Finalize
20:37:29 Call m_esets_charon_send
20:37:29 Call m_esets_charon_destroy
20:37:29 Updated modules version: 48496
20:37:40 Call m_esets_charon_setup_create
20:37:40 Call m_esets_charon_create
20:37:40 m_esets_charon_create OK
20:37:40 Call m_esets_charon_start_send_thread
20:37:40 Call m_esets_charon_setup_set
20:37:40 m_esets_charon_setup_set OK
20:37:40 Scanner engine: 48496
07:27:59 # product=EOS
# version=8
# flags=0
# av=0
# fw=7
# admin=1
# esetonlinescanner.exe=3.4.7.0
# EOSSerial=920782bdf68e1141b55e4c983bf4a557
# engine=48496
# end=finished
# bannerClicked=0
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# sfx_checked=true
# utc_time=2021-02-17 06:27:59
# local_time=2021-02-17 07:27:59 (+0100, Hora estándar romance)
# country="Spain"
# lang=3082
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 28591328 365173129 0 0
# compatibility_mode_1='Malwarebytes'
# compatibility_mode=18433 16777214 66 98 215643 516834 0 0
# scanned=323795
# found=18
# cleaned=18
# scan_time=9541
# scan_type=3
# flow=2021-02-16 20:33:33|scr|intro|2021-02-16 20:33:36|promo|eis|2021-02-16 20:34:22|scr|eula|2021-02-16 20:34:26|scr|welcome|2021-02-16 20:34:34|scr|consents|2021-02-16 20:35:00|scr|scan_type|2021-02-16 20:35:20|scr|custom_target|2021-02-16 20:35:35|scr|pua|2021-02-16 20:35:51|scr|adv_settings|2021-02-16 20:36:07|scr|pua|2021-02-16 20:36:09|scr|updating|2021-02-16 20:37:30|scr|scanning|2021-02-16 23:16:32|scr|all_cleaned|2021-02-17 07:21:27|click|save_report|2021-02-17 07:24:22|scr|report_cleaned|2021-02-17 07:24:22|click|resolved_detections|2021-02-17 07:24:31|scr|quarantine|2021-02-17 07:24:49|click|restore_now|2021-02-17 07:24:49|scr|quarantine|2021-02-17 07:25:48|scr|report_cleaned|2021-02-17 07:25:48|click|resolved_detections|2021-02-17 07:25:56|scr|periodic_offer|2021-02-17 07:26:02|scr|upsell|2021-02-17 07:26:06|scr|thanks
# periodic=0,1
# test=default
# email=
# stats_enabled=1
sh=2CBA68D19567A7FB6B6130B57F30000C1CBE1B6A ft=1 fh=0000000000046e00 vn="una variante de Win32/Adware.Zdengo.EW aplicación (desinfectado por eliminación)" ac=C fn="C:\AdwCleaner\Quarantine\bbSqWy6yhK\3a7891bf03ee5a01b397b6c44a8b332f.exe"
sh=B6FB443DDA2AA5FF7652D0C8D3F22C3E6E199458 ft=1 fh=000000000013e738 vn="una variante de Win32/UwS.DriverToolkit.A aplicación (desinfectado por eliminación)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\DriverToolkit\DriverToolkit.exe.vir"
sh=86D7310B8324601EDD2C4ED9B0463620B5B2DD9A ft=1 fh=000000000001f000 vn="una variante de Win32/NetFilter.A aplicación potencialmente no segura (desinfectado por eliminación)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\GSafe\nfapi.dll.vir"
sh=F69213B3EE5CF3F9F7C82F092D2A94D93474039E ft=1 fh=0000000000157000 vn="una variante de Win32/NetFilter.A aplicación potencialmente no segura (desinfectado por eliminación)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files\GSafe\ProtocolFilters.dll.vir"
sh=0000000000000000000000000000000000000000 ft=- fh=0000000000000000 vn="una variante de WinGo/RanumBot.J Troyano (desinfectado por eliminación)" ac=C fn="C:\AdwCleaner\Quarantine\v1\20210211.091018\9\windefender.exe#EE41CB463B852F74"
sh=FD28B39F6133E25C32D479F896AE8B283A72CBB8 ft=1 fh=00000000001e8bb8 vn="una variante de Win32/uTorrent.C aplicación potencialmente no deseada (desinfectado por eliminación)" ac=C fn="C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45146.exe"
sh=4D930FD21CC1E57F6E9EC9F65BF8CFE957D5635A ft=1 fh=00000000001e74e8 vn="una variante de Win32/uTorrent.C aplicación potencialmente no deseada (desinfectado por eliminación)" ac=C fn="C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45231.exe"
sh=804B164053222AF22E1BCC14D12713EB1620288A ft=1 fh=00000000001e98e8 vn="una variante de Win32/uTorrent.C aplicación potencialmente no deseada (desinfectado por eliminación)" ac=C fn="C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45395.exe"
sh=471FDD6F655CD964003C23D5ADAD650E33A50ED9 ft=1 fh=00000000001cbef0 vn="una variante de Win32/uTorrent.C aplicación potencialmente no deseada (desinfectado por eliminación)" ac=C fn="C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45505.exe"
sh=2747D0B1C62224C9BD1CB28EAEE3E1BDA711F583 ft=1 fh=0000000000203ed8 vn="una variante de Win32/uTorrent.C aplicación potencialmente no deseada (desinfectado por eliminación)" ac=C fn="C:\Users\massbateria\AppData\Roaming\uTorrent\updates\3.5.5_45790.exe"
sh=5FA8334249894EA9ACBD910AF861030E3C2A285E ft=0 fh=00000000001dca67 vn="una variante de Win32/uTorrent.C aplicación potencialmente no deseada (eliminado)" ac=C fn="C:\Users\massbateria\AppData\Roaming\uTorrent\uTorrent.rar"
sh=2FB383438837F31DA08A860323AC49595F24E85F ft=0 fh=000000000230916f vn="una variante de Win32/Keygen.AD aplicación potencialmente no segura (eliminado)" ac=C fn="E:\datos borja\SONIDO\IZotope.iDrum.VSTi.RTAS.v1.6.1.Incl.Keygen-AiR.rar"
sh=4E73CB4B44A3D74670FAA5CEF4ECA54282DFFE8B ft=0 fh=0000000000d34ac2 vn="una variante de Win32/Keygen.AD aplicación potencialmente no segura (eliminado)" ac=C fn="E:\datos borja\SONIDO\iZotope_Alloy_Setup_v1_00.rar"
sh=F800B75F25FA4F5990F26CAA4C249981CABC3D90 ft=0 fh=00000000034b9d7f vn="una variante de Win32/HackTool.Patcher.A aplicación potencialmente no segura (contenía archivos infectados)" ac=C fn="E:\datos borja\SONIDO\Peavey_Electronics_ReValver_MK_III_APP_w_Universal_Patch_by_TheXROOster.zip"
sh=7078B63DFBFF7454543F0CA02E3077AD7387E3B3 ft=0 fh=00000000034b817c vn="una variante de Win32/HackTool.Patcher.A aplicación potencialmente no segura (contenía archivos infectados)" ac=C fn="E:\datos borja\SONIDO\Revalver MK III win crack.zip"
sh=D4AB71AED646C0717AABCBEEBCBD2415AE1CE665 ft=0 fh=0000000016ca1c21 vn="una variante de Win32/HackTool.Patcher.A aplicación potencialmente no segura (eliminado)" ac=C fn="E:\Dropbox\Dropbox\Dropbox\tecnica\Finale 2011(1).rar"
sh=479EBD23C847E0E5E4A0ED76DE53FB87168F98A9 ft=1 fh=000000000009c858 vn="Win32/Keygen.ACE aplicación potencialmente no segura,Win32/Keygen.ML aplicación potencialmente no segura (desinfectado por eliminación)" ac=C fn="E:\EZDrummer 2\R2R\Toontrack_KeyGen.exe"
sh=0EFC35935957C25193BBE9A83AB6CAA25A487ADA ft=1 fh=00000000003d5b39 vn="Win32/HackTool.WinActivator.I aplicación potencialmente no segura (desinfectado por eliminación)" ac=C fn="I:\Windows Loader.exe"
07:28:00 Call m_esets_charon_send
07:28:00 Call m_esets_charon_destroy
Malwarebytes Anti-Rootkit BETA 1.10.3.1001
www.malwarebytes.org

Database version:
  main:    v2021.02.17.03
  rootkit: v2021.02.17.03

Windows 7 Service Pack 1 x64 NTFS (Safe Mode/Networking)
Internet Explorer 11.0.9600.19572
massbateria :: MASSBATERIA-PC [administrator]

17/02/2021 9:34:11
mbar-log-2021-02-17 (09-34-11).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 201728
Time elapsed: 26 minute(s), 47 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 9
HKLM\SOFTWARE\MICROSOFT\bestavicampaign563 (Adware.ICLoader) -> Delete on reboot. [de293e6f42a30f27fca168d87888ec14]
HKLM\SOFTWARE\MICROSOFT\campaign9961 (Adware.ICLoader) -> Delete on reboot. [0304beef549155e1326cb28e43bd2ed2]
HKLM\SOFTWARE\MICROSOFT\multitimercampaign84170 (Adware.ICLoader) -> Delete on reboot. [8e79793415d0c4722679063a33cdee12]
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F70818C7-92D7-4F2A-A79A-13288E9FF0CF} (Trojan.Glupteba.E) -> Delete on reboot. [7691614cffe672c41723a539f60a0ff1]
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\csrss (Trojan.Glupteba.E) -> Delete on reboot. [30d7b8f591542c0abb80716dfb05da26]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Winmon (Trojan.Glupteba.E) -> Delete on reboot. [f215e1ccfee76ec88fadc618f40c59a7]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinmonFS (Trojan.Glupteba.E) -> Delete on reboot. [bf489e0fe7fea5910d30e4fa7888e917]
HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinmonProcessMonitor (Trojan.Glupteba.E) -> Delete on reboot. [d730e1cc2abbf3439ba37d617c846f91]
HKU\S-1-5-21-3658098771-1424985918-529143646-1000\SOFTWARE\MICROSOFT\D0DD0EF0 (Trojan.Glupteba.E) -> Delete on reboot. [9a6db3fab03539fd1f18f5e9946c57a9]

Registry Values Detected: 2
HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F70818C7-92D7-4F2A-A79A-13288E9FF0CF}|Path (Trojan.Glupteba.E) -> Data: \csrss -> Delete on reboot. [7691614cffe672c41723a539f60a0ff1]
HKU\S-1-5-21-3658098771-1424985918-529143646-1000\SOFTWARE\MICROSOFT\d0dd0ef0|CampaignID (Trojan.Glupteba.E) -> Data: /77 -> Delete on reboot. [9a6db3fab03539fd1f18f5e9946c57a9]

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 2
C:\Windows\System32\Tasks\csrss (Trojan.Glupteba.E) -> Delete on reboot. [7d8a4c619451aa8cb083706e956bc43c]
C:\Program Files\Mozilla Firefox\defaults\pref\a.js (Adware.ProxyAgent) -> Delete on reboot. [57b0614c5095e4526d11e99fc93c48b8]

Physical Sectors Detected: 0
(No malicious items detected)

(end)
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.10.3.1001

(c) Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

System is currently in a safe mode

Account is Administrative

Internet Explorer version: 11.0.9600.19572

File system is: NTFS
Disk drives: C:\ DRIVE_FIXED, E:\ DRIVE_FIXED
CPU speed: 3.391000 GHz
Memory total: 17121009664, free: 14667825152

Downloaded database version: v2021.02.17.03
Downloaded database version: v2021.02.17.03
Downloaded database version: v2018.01.20.01
=======================================
Initializing...
Driver version: 4.3.0.15
------------ Kernel report ------------
     02/17/2021 09:34:00
------------ Loaded modules -----------
\SystemRoot\system32\ntkrnlmp.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\msahci.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\system32\DRIVERS\amd_sata.sys
\SystemRoot\system32\DRIVERS\storport.sys
\SystemRoot\system32\DRIVERS\amd_xata.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\usbohci.sys
\SystemRoot\system32\DRIVERS\USBPORT.SYS
\SystemRoot\system32\DRIVERS\usbfilter.sys
\SystemRoot\system32\DRIVERS\usbehci.sys
\SystemRoot\system32\DRIVERS\1394ohci.sys
\SystemRoot\system32\DRIVERS\asmtxhci.sys
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\drivers\wmiacpi.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\CompositeBus.sys
\SystemRoot\system32\drivers\mssmbios.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\rdpbus.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\BazisVirtualCDBus.sys
\SystemRoot\system32\DRIVERS\NIWinCDEmu.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\DRIVERS\exetools.sys
\SystemRoot\system32\DRIVERS\umbus.sys
\SystemRoot\system32\DRIVERS\nvvhci.sys
\SystemRoot\system32\drivers\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\aksusb.sys
\SystemRoot\system32\DRIVERS\AKSCLASS.SYS
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\akshasp.sys
\SystemRoot\system32\DRIVERS\akshhl.sys
\SystemRoot\system32\DRIVERS\asmthub3.sys
\SystemRoot\system32\DRIVERS\USBSTOR.SYS
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\System32\drivers\dxg.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\framebuf.dll
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_amd_sata.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\Drivers\fastfat.SYS
\SystemRoot\System32\Drivers\mbamswissarmy.sys
\??\C:\Windows\system32\drivers\MbamChameleon.sys
\??\C:\Windows\system32\drivers\B311439F.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2021.02.17.03
  rootkit: v2021.02.17.03

<<<2>>>
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa800d5ed060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800d5edb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800d5ed060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800cfbb040, DeviceName: Unknown, DriverName: \Driver\amd_xata\
DevicePointer: 0xfffffa800c5fc060, DeviceName: \Device\0000007a\, DriverName: \Driver\amd_sata\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa800d5ec060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800d5ecb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800d5ec060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800c5fcac0, DeviceName: Unknown, DriverName: \Driver\amd_xata\
DevicePointer: 0xfffffa800cfe19c0, DeviceName: \Device\00000079\, DriverName: \Driver\amd_sata\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 7F3BFE6

Partition information:

    Partition 0 type is Extended with LBA (0xf)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 16065  Numsec = 1953504000
    Partition is not bootable

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Done!
Drive 1
This is a System drive
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 7DA57DA5

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition is bootable
    Partition file system is NTFS

    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 398088192
    Partition is not bootable
    Partition file system is NTFS

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 203928109056 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 512
Drive: 2, DevicePointer: 0xfffffa800d99b060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800d9efb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800d99b060, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800dc07a10, DeviceName: \Device\0000008d\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 2
Scanning MBR on drive 2...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 0

Partition information:

    Partition 0 type is Other (0xb)
    Partition is ACTIVE.
    Partition starts at LBA: 8192  Numsec = 60359680
    Partition is not bootable
    Partition file system is FAT32

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 30908350464 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 0
Drive: 3, DevicePointer: 0xfffffa800d9a4790, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800d99c040, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800d9a4790, DeviceName: \Device\Harddisk3\DR3\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800d99cb60, DeviceName: \Device\0000008e\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 4, DevicePointer: 0xfffffa800d9a5060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800d996b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800d9a5060, DeviceName: \Device\Harddisk4\DR4\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800d99c660, DeviceName: \Device\0000008f\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 5, DevicePointer: 0xfffffa800d9a6060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800d9a5b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800d9a6060, DeviceName: \Device\Harddisk5\DR5\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800e5a3b60, DeviceName: \Device\00000090\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 0
Drive: 6, DevicePointer: 0xfffffa800d9a7060, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800d9a6b90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800d9a7060, DeviceName: \Device\Harddisk6\DR6\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800e593b60, DeviceName: \Device\00000091\, DriverName: \Driver\USBSTOR\
------------ End ----------
Physical Sector Size: 512
Drive: 7, DevicePointer: 0xfffffa800e57f060, DeviceName: \Device\Harddisk7\DR7\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa800da3bb90, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa800e57f060, DeviceName: \Device\Harddisk7\DR7\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800d9a7b60, DeviceName: \Device\00000092\, DriverName: \Driver\USBSTOR\
------------ End ----------
Alternate DeviceName: \Device\Harddisk7\DR7\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 7
Scanning MBR on drive 7...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 1B3AFD

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 31264768
    Partition is not bootable
    Partition file system is NTFS

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 16008609792 bytes
Sector size: 512 bytes

Done!
Infected: C:\Windows\System32\Tasks\csrss --> [Trojan.Glupteba.E]
Infected: HKLM\SOFTWARE\MICROSOFT\bestavicampaign563 --> [Adware.ICLoader]
Infected: HKLM\SOFTWARE\MICROSOFT\campaign9961 --> [Adware.ICLoader]
Infected: HKLM\SOFTWARE\MICROSOFT\multitimercampaign84170 --> [Adware.ICLoader]
Infected: HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F70818C7-92D7-4F2A-A79A-13288E9FF0CF}|Path --> [Trojan.Glupteba.E]
Infected: HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{F70818C7-92D7-4F2A-A79A-13288E9FF0CF} --> [Trojan.Glupteba.E]
Infected: HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\csrss --> [Trojan.Glupteba.E]
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Winmon --> [Trojan.Glupteba.E]
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinmonFS --> [Trojan.Glupteba.E]
Infected: HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\WinmonProcessMonitor --> [Trojan.Glupteba.E]
Infected: HKU\S-1-5-21-3658098771-1424985918-529143646-1000\SOFTWARE\MICROSOFT\d0dd0ef0|CampaignID --> [Trojan.Glupteba.E]
Infected: HKU\S-1-5-21-3658098771-1424985918-529143646-1000\SOFTWARE\MICROSOFT\D0DD0EF0 --> [Trojan.Glupteba.E]
Infected: C:\Program Files\Mozilla Firefox\defaults\pref\a.js --> [Adware.ProxyAgent]
Scan finished
10:18:14.0677 0x0748  TDSS rootkit removing tool 3.1.0.28 Apr  9 2019 21:11:46
10:18:20.0007 0x0748  ============================================================
10:18:20.0008 0x0748  Current date / time: 2021/02/17 10:18:20.0007
10:18:20.0008 0x0748  SystemInfo:
10:18:20.0008 0x0748  
10:18:20.0008 0x0748  OS Version: 6.1.7601 ServicePack: 1.0
10:18:20.0008 0x0748  Product type: Workstation
10:18:20.0008 0x0748  ComputerName: MASSBATERIA-PC
10:18:20.0008 0x0748  UserName: massbateria
10:18:20.0008 0x0748  Windows directory: C:\Windows
10:18:20.0008 0x0748  System windows directory: C:\Windows
10:18:20.0008 0x0748  Running under WOW64
10:18:20.0008 0x0748  Processor architecture: Intel x64
10:18:20.0008 0x0748  Number of processors: 2
10:18:20.0008 0x0748  Page size: 0x1000
10:18:20.0008 0x0748  Boot type: Safe boot with network
10:18:20.0008 0x0748  CodeIntegrityOptions = 0x00000000
10:18:20.0008 0x0748  ============================================================
10:18:20.0300 0x0748  KLMD registered as C:\Windows\system32\drivers\30313596.sys
10:18:20.0300 0x0748  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.24540, osProperties = 0x1
10:18:20.0836 0x0748  System UUID: {1FC65C9A-D402-13FA-AC1C-DBF001DC507E}
10:18:21.0404 0x0748  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:18:21.0412 0x0748  Drive \Device\Harddisk1\DR1 - Size: 0x2F7B100000 ( 189.92 Gb ), SectorSize: 0x200, Cylinders: 0x33733, SectorsPerTrack: 0xE, TracksPerCylinder: 0x87, Type 'K0', Flags 0x00000040
10:18:21.0416 0x0748  Drive \Device\Harddisk2\DR2 - Size: 0x732480000 ( 28.79 Gb ), SectorSize: 0x200, Cylinders: 0xEAD, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:18:21.0433 0x0748  Drive \Device\Harddisk7\DR7 - Size: 0x3BA300000 ( 14.91 Gb ), SectorSize: 0x200, Cylinders: 0x79A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:18:21.0435 0x0748  ============================================================
10:18:21.0435 0x0748  \Device\Harddisk0\DR0:
10:18:21.0435 0x0748  MBR partitions:
10:18:21.0439 0x0748  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x74701AC1
10:18:21.0439 0x0748  \Device\Harddisk1\DR1:
10:18:21.0439 0x0748  MBR partitions:
10:18:21.0439 0x0748  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
10:18:21.0439 0x0748  \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x17BA5800
10:18:21.0439 0x0748  \Device\Harddisk2\DR2:
10:18:21.0441 0x0748  MBR partitions:
10:18:21.0441 0x0748  \Device\Harddisk2\DR2\Partition1: MBR, Type 0xB, StartLBA 0x2000, BlocksNum 0x3990400
10:18:21.0441 0x0748  \Device\Harddisk7\DR7:
10:18:21.0442 0x0748  MBR partitions:
10:18:21.0442 0x0748  \Device\Harddisk7\DR7\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1DD1000
10:18:21.0442 0x0748  ============================================================
10:18:21.0488 0x0748  C: <-> \Device\Harddisk1\DR1\Partition2
10:18:21.0492 0x0748  E: <-> \Device\Harddisk0\DR0\Partition1
10:18:21.0492 0x0748  ============================================================
10:18:21.0492 0x0748  Initialize success
10:18:21.0492 0x0748  ============================================================
10:19:50.0121 0x0b6c  KLMD registered as C:\Windows\system32\drivers\53239925.sys
10:19:50.0699 0x0b6c  Deinitialize success
~ ZHPCleaner v2021.2.16.279 by Nicolas Coolman (2021/02/16)
~ Run by massbateria (Administrator)  (17/02/2021 09:05:08)
~ Web: https://www.nicolascoolman.com
~ Blog: https://nicolascoolman.eu/
~ Facebook : https://www.facebook.com/nicolascoolman1
~ State version : 
~ Certificate ZHPCleaner: Legal
~ Type : Reparar
~ Report : C:\Users\massbateria\Desktop\ZHPCleaner (R).txt
~ Quarantine : C:\Users\massbateria\AppData\Roaming\ZHP\ZHPCleaner_Reg.txt
~ UAC : Deactivate
~ Boot Mode : Normal (Normal boot)
Windows 7 Ultimate, 64-bit Service Pack 1 (Build 7601)

---\  Alternate Data Stream (ADS). (1)
MOVIDO carpeta ADS: C:\Users\massbateria\Desktop\PDFs - Acceso directo.lnk:com.dropbox.attrs  =>.SUP.FileADS

---\  Servicios (0)
~ No malintencionados o innecesarios artículos encontrados. (Servicio)

---\  Navegadores de Internet (0)
~ No malintencionados o innecesarios artículos encontrados. (Navegador)

---\  Hosts carpeta (1)
~ El archivo hosts es legítimo (15667)

---\  Tareas automáticas programadas. (0)
~ No malintencionados o innecesarios artículos encontrados. (Tarea)

---\  Explorador ( Archivos, Carpetas ) (7)
MOVIDO carpeta: C:\Users\massbateria\AppData\Local\Google\Chrome\User Data\Default\Preferences    =>Préférences Chromium
MOVIDO archivo: C:\Users\massbateria\AppData\Roaming\PDAppFlex  =>Trojan.Elpman
MOVIDO archivo: C:\Program Files\KMSpico  =>HackTool.KMSpico
MOVIDO archivo: C:\ProgramData\IG Stories Downloader  =>PUP.Optional.IGStories
MOVIDO archivo: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IG Stories Downloader  =>PUP.Optional.IGStories
MOVIDO archivo: C:\Program Files (x86)\QuickTime  =>Riskware.QuickTime
MOVIDO archivo: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime  =>Riskware.QuickTime

---\  Registro ( Claves, Valores, Datos) (5)
BORRADOS clave*: [X64] HKLM\SOFTWARE\029c4619-0385-5543-9426-46f9987161d9 []  =>Adware.CrossRider
BORRADOS clave*: [X64] HKLM\SOFTWARE\c6ba130a-455e-5073-9dbd-f9d1f65c1562 []  =>Adware.CrossRider
BORRADOS clave*: [X64] HKLM\SOFTWARE\Wow6432Node\c6ba130a-455e-5073-9dbd-f9d1f65c1562 []  =>Adware.CrossRider
BORRADOS clave*: HKCU\Software\undefined [AdditionalScan 148]  =>.SUP.Downloader
BORRADOS valor: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_DA49533490B544962D76CEA7A7F9414D ['C:\Program Files (x86)\Google\Chrome\Application\]  =>PUP.Optional.MyBrowser

---\  Resumen de elementos en su estación de trabajo (9)
https://nicolascoolman.eu/2018/01/04/ads-alternate-data-stream/  =>.SUP.FileADS
https://nicolascoolman.eu/forum/Topic/repaquetage-et-infection/  =>Préférences Chromium
https://nicolascoolman.eu/2017/09/23/trojan-elpman/  =>Trojan.Elpman
https://nicolascoolman.eu/2017/02/16/hacktool-kmspico/  =>HackTool.KMSpico
https://nicolascoolman.eu/forum/Topic/igstories-logiciel-potentiellement-indesirable-pup-lpi/  =>PUP.Optional.IGStories
https://nicolascoolman.eu/2017/01/15/riskware-quicktime/  =>Riskware.QuickTime
https://nicolascoolman.eu/2017/03/11/pup-optional-crossrider/  =>Adware.CrossRider
https://nicolascoolman.eu/2017/12/22/sup-downloader/  =>.SUP.Downloader
https://nicolascoolman.eu/2017/11/01/adware-mybrowser/  =>PUP.Optional.MyBrowser

---\ Limpieza adicional. (5)
~ Clave de registro Tracing borrados (5)
~ Quitar los antiguos informes de ZHPCleaner. (0)

---\ Resultado de la reparación.
~ Reparación llevada a cabo con éxito
~ Google Chrome OK
~ Mozilla Firefox OK
~ Internet Explorer OK

---\ STATISTIQUES
~ Items escaneado : 32806
~ Items encontrado : 0
~ artículos cancelados : 0
~ Ahorro de espacio (bytes) : 0
~ Items opciones : 9/17

---\ OPCIONES NO ACTIVAS
~ Análisis temporal de archivos
~ Análisis temporal de carpetas
~ Análisis de CLSID de carpetas vacías
~ Vaciar otro análisis de carpetas
~ Análisis de carpetas locales vacías
~ Análisis de archivos de instalación obsoleto
~ Iniciar navegadores con extensiones eliminadas

~ End of clean in 00h01mn36s

---\  Reporte (2)
ZHPCleaner-[S]-17022021-09_01_05.txt
ZHPCleaner-[R]-17022021-09_06_44.txt

@Marr0n Me falta el más largo de TDSSkiller. Si lo necesitas, dímelo y te lo paso.

Hola @massbateria

Sí, tráelo también. Aunque sea muy largo, ponlo todo. Lo traes y analizo todo.

Salu2.

10:22:27.0494 0x0370  TDSS rootkit removing tool 3.1.0.28 Apr  9 2019 21:11:46
10:22:31.0066 0x0370  ============================================================
10:22:31.0066 0x0370  Current date / time: 2021/02/17 10:22:31.0066
10:22:31.0066 0x0370  SystemInfo:
10:22:31.0066 0x0370  
10:22:31.0066 0x0370  OS Version: 6.1.7601 ServicePack: 1.0
10:22:31.0066 0x0370  Product type: Workstation
10:22:31.0066 0x0370  ComputerName: MASSBATERIA-PC
10:22:31.0066 0x0370  UserName: massbateria
10:22:31.0066 0x0370  Windows directory: C:\Windows
10:22:31.0066 0x0370  System windows directory: C:\Windows
10:22:31.0066 0x0370  Running under WOW64
10:22:31.0066 0x0370  Processor architecture: Intel x64
10:22:31.0066 0x0370  Number of processors: 2
10:22:31.0066 0x0370  Page size: 0x1000
10:22:31.0066 0x0370  Boot type: Safe boot with network
10:22:31.0066 0x0370  CodeIntegrityOptions = 0x00000000
10:22:31.0066 0x0370  ============================================================
10:22:31.0113 0x0370  KLMD ARK init status: drvProperties = 0xFFFF00, osBuild = 7601.24540, osProperties = 0x1
10:22:31.0113 0x0370  KLMD BG init status: drvProperties = 0xFFFF00, osBuild = 7601.24540, osProperties = 0x1
10:22:31.0113 0x0370  BG loaded
10:22:31.0441 0x0370  System UUID: {1FC65C9A-D402-13FA-AC1C-DBF001DC507E}
10:22:31.0846 0x0370  Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
10:22:31.0862 0x0370  Drive \Device\Harddisk1\DR1 - Size: 0x2F7B100000 ( 189.92 Gb ), SectorSize: 0x200, Cylinders: 0x33733, SectorsPerTrack: 0xE, TracksPerCylinder: 0x87, Type 'K0', Flags 0x00000040
10:22:31.0877 0x0370  Drive \Device\Harddisk2\DR2 - Size: 0x732480000 ( 28.79 Gb ), SectorSize: 0x200, Cylinders: 0xEAD, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:22:31.0877 0x0370  Drive \Device\Harddisk3\DR3 - Size: 0x3BA300000 ( 14.91 Gb ), SectorSize: 0x200, Cylinders: 0x79A, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:22:31.0893 0x0370  ============================================================
10:22:31.0893 0x0370  \Device\Harddisk0\DR0:
10:22:31.0893 0x0370  MBR partitions:
10:22:31.0909 0x0370  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F00, BlocksNum 0x74701AC1
10:22:31.0909 0x0370  \Device\Harddisk1\DR1:
10:22:31.0909 0x0370  MBR partitions:
10:22:31.0924 0x0370  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
10:22:31.0924 0x0370  \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x17BA5800
10:22:31.0924 0x0370  \Device\Harddisk2\DR2:
10:22:31.0924 0x0370  MBR partitions:
10:22:31.0924 0x0370  \Device\Harddisk2\DR2\Partition1: MBR, Type 0xB, StartLBA 0x2000, BlocksNum 0x3990400
10:22:31.0924 0x0370  \Device\Harddisk3\DR3:
10:22:31.0924 0x0370  MBR partitions:
10:22:31.0924 0x0370  \Device\Harddisk3\DR3\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x1DD1000
10:22:31.0924 0x0370  ============================================================
10:22:32.0049 0x0370  C: <-> \Device\Harddisk1\DR1\Partition2
10:22:32.0065 0x0370  E: <-> \Device\Harddisk0\DR0\Partition1
10:22:32.0065 0x0370  ============================================================
10:22:32.0065 0x0370  Initialize success
10:22:32.0065 0x0370  ============================================================
10:22:45.0231 0x07c4  ============================================================
10:22:45.0231 0x07c4  Scan started
10:22:45.0231 0x07c4  Mode: Manual; SigCheck; TDLFS; 
10:22:45.0231 0x07c4  ============================================================
10:22:45.0231 0x07c4  KSN ping started
10:22:45.0434 0x07c4  KSN ping finished: true
10:22:46.0682 0x07c4  ================ Scan BIOS =================================
10:22:46.0682 0x07c4  BIOS info: vendor = American Megatrends Inc., version = 1301, releaseDate = 12/05/2014
10:22:46.0682 0x07c4  Base board info: manufacturer = ASUSTeK COMPUTER INC., product = A58M-A/USB3, version = Rev X.0x
10:22:49.0443 0x07c4  [ 53497FAE53EBDEAACC1E62BE00298B5D, C082528139EBC5F710656148E0F0C517A483D56C5CFDB7F1C8513248D3EB8235 ] BIOS
10:22:49.0443 0x07c4  BIOS - ok
10:22:49.0443 0x07c4  ================ Scan system memory ========================
10:22:49.0459 0x07c4  System memory - ok
10:22:49.0459 0x07c4  ================ Scan services =============================
10:22:49.0599 0x07c4  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\DRIVERS\1394ohci.sys
10:22:49.0693 0x07c4  1394ohci - ok
10:22:49.0739 0x07c4  [ DCA5495CA17AEB2F4FD8AC60812C3999, 20A3FC0349294584C340C76D674EE5CA37BA69C886DDA6886CBCCFA437A51BD8 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
10:22:49.0771 0x07c4  ACPI - ok
10:22:49.0802 0x07c4  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
10:22:49.0880 0x07c4  AcpiPmi - ok
10:22:49.0942 0x07c4  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
10:22:49.0973 0x07c4  adp94xx - ok
10:22:50.0005 0x07c4  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci         C:\Windows\system32\drivers\adpahci.sys
10:22:50.0036 0x07c4  adpahci - ok
10:22:50.0051 0x07c4  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
10:22:50.0067 0x07c4  adpu320 - ok
10:22:50.0114 0x07c4  [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
10:22:50.0145 0x07c4  AeLookupSvc - ok
10:22:50.0207 0x07c4  [ 0DC2A9882540DEA4A55B08785E09D8FC, 69B15724B0034F9915AACE109A6C596D6AF2DA350FC18C9A0CD98C81CB7EDEE3 ] AFD             C:\Windows\system32\drivers\afd.sys
10:22:50.0285 0x07c4  AFD - ok
10:22:50.0566 0x07c4  [ DAE15469EE2E6B8B00E57F0C0A2341D4, 8B8B808BFF201542824F20CB95F5D43D536CF0B6D0FC412C9997AC09F0882152 ] AGMService      C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe
10:22:50.0753 0x07c4  AGMService - ok
10:22:50.0800 0x07c4  [ A964EADDD5D1F4374775E112C8859F20, 1F2DA3AF95C734DCB363F7D14CDC0690B8E2AB3A4C92CE56A23C49B5B9D1D655 ] agp440          C:\Windows\system32\drivers\agp440.sys
10:22:50.0800 0x07c4  agp440 - ok
10:22:50.0956 0x07c4  [ B1E856CFF6B7A35DFAD5226EE0832CEE, FD2814E04A4B878432C4ACF7E10D98F97E7CA93BD317CD2BEF397770B5A4C87D ] AGSService      C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
10:22:51.0128 0x07c4  AGSService - ok
10:22:51.0175 0x07c4  [ 3190C577746303CA4C65114441192FE2, AEE970D59E9FB314B559CF0C41DD2CD3C9C9B5DD060A339368000F975F4CD389 ] aksdf           C:\Windows\system32\drivers\aksdf.sys
10:22:51.0190 0x07c4  aksdf - ok
10:22:51.0237 0x07c4  [ 2845A05E5AF65B5C7A143D637F08496D, 38DB4590EDD8CBE735ED0C072A03F4E619A3CDA7B8D908FD1CA8E90728F077EF ] aksfridge       C:\Windows\system32\DRIVERS\aksfridge.sys
10:22:51.0237 0x07c4  aksfridge - ok
10:22:51.0299 0x07c4  [ 35E43EE8FE28CFD581E8CE42847DFE2B, 1A78FC49422CB73EFD4B0A09BD32B35244A91478DB2268C023FDDCA826C8EE5D ] akshasp         C:\Windows\system32\DRIVERS\akshasp.sys
10:22:51.0299 0x07c4  akshasp - ok
10:22:51.0346 0x07c4  [ 053B204554F104CB5DC3D94B61BDA458, 72EB2556AA4B83489D2908ADC40DEB2E5ACE98D7A6112E9395F46924BD60501E ] akshhl          C:\Windows\system32\DRIVERS\akshhl.sys
10:22:51.0346 0x07c4  akshhl - ok
10:22:51.0393 0x07c4  [ 8D584711424446969B5E4CB16870A898, 842FBE4FD5BEB044EC1F10EAD8B2F2AB5F38D544D136A09474AF94D83EFA4F35 ] aksusb          C:\Windows\system32\DRIVERS\aksusb.sys
10:22:51.0409 0x07c4  aksusb - ok
10:22:51.0455 0x07c4  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG             C:\Windows\System32\alg.exe
10:22:51.0487 0x07c4  ALG - ok
10:22:51.0533 0x07c4  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
10:22:51.0533 0x07c4  aliide - ok
10:22:51.0565 0x07c4  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
10:22:51.0580 0x07c4  amdide - ok
10:22:51.0611 0x07c4  [ 26CF0D8A24834D04B0DBE1979F96B035, FE9C52262D1D059AFBEFECC85AFF7B8F00C5238412981B1A7A8B070928EFAAE9 ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
10:22:51.0627 0x07c4  AmdK8 - ok
10:22:51.0674 0x07c4  [ 268FFCDC7840795D535A2F9CDCB98760, 800771C8EF6583F0357F6348F5B9B3925BCF97D8E3B4FA2B014B644BCF99476C ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
10:22:51.0705 0x07c4  AmdPPM - ok
10:22:51.0752 0x07c4  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
10:22:51.0767 0x07c4  amdsata - ok
10:22:51.0814 0x07c4  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
10:22:51.0830 0x07c4  amdsbs - ok
10:22:51.0845 0x07c4  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata         C:\Windows\system32\drivers\amdxata.sys
10:22:51.0861 0x07c4  amdxata - ok
10:22:51.0892 0x07c4  [ EBECBA1E37CE98BA2BD64A22A788DAC5, 247C474DAF9FFFF7FB46EB6185088B94B886A7685F98CABE1983EFEAEE1A8338 ] amd_sata        C:\Windows\system32\DRIVERS\amd_sata.sys
10:22:51.0923 0x07c4  amd_sata - ok
10:22:51.0955 0x07c4  [ 7F1B42E70FAE147B14B28B83E003F039, 093C2B57AFDC93E667A3AB1F74442DBA42B0DE2132388E73BDC3D09FDBB1B3D0 ] amd_xata        C:\Windows\system32\DRIVERS\amd_xata.sys
10:22:51.0955 0x07c4  amd_xata - ok
10:22:52.0017 0x07c4  [ 308AD515A8226EA89C7C100F9660EAC3, 40426D3811179847555BECECD999C3CE50188324218D8F2945121B13A30E36E6 ] AppID           C:\Windows\system32\drivers\appid.sys
10:22:52.0064 0x07c4  AppID - ok
10:22:52.0079 0x07c4  [ 3B8A172FCFCAC19DE442CA10826E2681, 5EED41902B3386D696BB487211E85C20B412E0A84EC9969992FB02BA919EEFB6 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
10:22:52.0111 0x07c4  AppIDSvc - ok
10:22:52.0142 0x07c4  [ 3639F533FDC865C741D9522AA3C11917, 5C15DFB10B6B78E3E24E772DE4B99318E2D2AF2C026D92C533EED2F2FC43BB16 ] Appinfo         C:\Windows\System32\appinfo.dll
10:22:52.0189 0x07c4  Appinfo - ok
10:22:52.0298 0x07c4  [ BC3CBB9C99DA7861D703D91BB74F36CA, 4AD6BAFDB6036018923B29D268BD52A238D4889D92CFEFA81C27251D3733C934 ] Apple Mobile Device Service C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
10:22:52.0298 0x07c4  Apple Mobile Device Service - ok
10:22:52.0345 0x07c4  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt         C:\Windows\System32\appmgmts.dll
10:22:52.0391 0x07c4  AppMgmt - ok
10:22:52.0438 0x07c4  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc             C:\Windows\system32\drivers\arc.sys
10:22:52.0438 0x07c4  arc - ok
10:22:52.0454 0x07c4  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\drivers\arcsas.sys
10:22:52.0469 0x07c4  arcsas - ok
10:22:52.0516 0x07c4  [ 6061E6BA14B709939EEE1E616A85585E, CAB0372F8518C169740EDA962BF53C63130754F096A5033B79E734133DB59874 ] asmthub3        C:\Windows\system32\DRIVERS\asmthub3.sys
10:22:52.0532 0x07c4  asmthub3 - ok
10:22:52.0610 0x07c4  [ 39EE5CB57D91AAE8BB9EAB8DF2FEEC9E, 8D0AF427CB10C600920344AC9AA7AB0620CD3C49E45FD4B3EA33CAC1E8484A31 ] asmtxhci        C:\Windows\system32\DRIVERS\asmtxhci.sys
10:22:52.0625 0x07c4  asmtxhci - ok
10:22:52.0735 0x07c4  [ 33C1061054002DDA02CDFD9C7746CCA7, CE621B9891E505D8A610EE91CF81B59E617DC2915B6134F5108ABA2ECDF1D182 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
10:22:52.0813 0x07c4  aspnet_state - ok
10:22:52.0875 0x07c4  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
10:22:53.0015 0x07c4  AsyncMac - ok
10:22:53.0078 0x07c4  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi           C:\Windows\system32\drivers\atapi.sys
10:22:53.0078 0x07c4  atapi - ok
10:22:53.0125 0x07c4  [ 738CD83A9C61ADFD00984433DBA3DC78, DC767CAB626623DDE276FAE636FD80D2E5771C8689B77228C8E4208BBFF28DF1 ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
10:22:53.0140 0x07c4  AtiHDAudioService - ok
10:22:53.0203 0x07c4  [ A585E162EBD575CC66801709458A7921, FF8D2B38A925358F24C5C582101F1667208AD15774202E74365FE30E27544214 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
10:22:53.0265 0x07c4  AudioEndpointBuilder - ok
10:22:53.0312 0x07c4  [ A585E162EBD575CC66801709458A7921, FF8D2B38A925358F24C5C582101F1667208AD15774202E74365FE30E27544214 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
10:22:53.0343 0x07c4  AudioSrv - ok
10:22:53.0390 0x07c4  [ 0D85F9CF8CF09502A816F4A009545CEC, BB73D8A1C92A9C3E417323FC106ED4790AE85B2A553B2A058357DC7EBD91CF04 ] AxInstSV        C:\Windows\System32\AxInstSV.dll
10:22:53.0421 0x07c4  AxInstSV - ok
10:22:53.0483 0x07c4  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
10:22:53.0530 0x07c4  b06bdrv - ok
10:22:53.0593 0x07c4  [ BDFA7A13CC73B180BBDF1ABA280E1CF7, BF97E7DF4CF526BF37408CFE30106981842F20769FA949B8EFDBE37306BF929A ] B311439F        C:\Windows\system32\drivers\B311439F.sys
10:22:53.0608 0x07c4  B311439F - ok
10:22:53.0639 0x07c4  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
10:22:53.0702 0x07c4  b57nd60a - ok
10:22:53.0764 0x07c4  [ 09391BA416AA29682298A612FDFDD7B8, D889679C25DA37212E2E0E08E4B2CF774FFF395E83BCD168B240A59E74204070 ] BazisVirtualCDBus C:\Windows\system32\DRIVERS\BazisVirtualCDBus.sys
10:22:53.0764 0x07c4  BazisVirtualCDBus - ok
10:22:53.0811 0x07c4  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
10:22:53.0842 0x07c4  BDESVC - ok
10:22:53.0889 0x07c4  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
10:22:53.0905 0x07c4  Beep - ok
10:22:53.0983 0x07c4  [ E3ED6C06462FDDE33100F7E45E8F5213, 71AA528F8912106FDAD83175A7529CF94B5B19093D2C63C25FAC198587286F87 ] BFE             C:\Windows\System32\bfe.dll
10:22:54.0029 0x07c4  BFE - ok
10:22:54.0092 0x07c4  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\System32\qmgr.dll
10:22:54.0248 0x07c4  BITS - ok
10:22:54.0295 0x07c4  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
10:22:54.0310 0x07c4  blbdrive - ok
10:22:54.0341 0x07c4  [ D7E5C916557268B3DCC9E7DAD58E7727, 439D76346E8762BA7D7F91B09580EFE8354F1A650F3B59101A3BEE2328D8F562 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
10:22:54.0388 0x07c4  bowser - ok
10:22:54.0404 0x07c4  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
10:22:54.0451 0x07c4  BrFiltLo - ok
10:22:54.0466 0x07c4  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
10:22:54.0497 0x07c4  BrFiltUp - ok
10:22:54.0544 0x07c4  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser         C:\Windows\System32\browser.dll
10:22:54.0575 0x07c4  Browser - ok
10:22:54.0622 0x07c4  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
10:22:54.0653 0x07c4  Brserid - ok
10:22:54.0669 0x07c4  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
10:22:54.0700 0x07c4  BrSerWdm - ok
10:22:54.0716 0x07c4  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
10:22:54.0716 0x07c4  BrUsbMdm - ok
10:22:54.0731 0x07c4  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
10:22:54.0747 0x07c4  BrUsbSer - ok
10:22:54.0778 0x07c4  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
10:22:54.0778 0x07c4  BTHMODEM - ok
10:22:54.0825 0x07c4  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv         C:\Windows\system32\bthserv.dll
10:22:54.0856 0x07c4  bthserv - ok
10:22:54.0903 0x07c4  [ B861DF1DC9CA9259934DBAC5E069681B, BA3AB966509CF07DE26FB9F8CBEA21F4771FC1677767824813F4F8B80E33C072 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
10:22:54.0950 0x07c4  cdfs - ok
10:22:54.0997 0x07c4  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
10:22:55.0012 0x07c4  cdrom - ok
10:22:55.0059 0x07c4  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc     C:\Windows\System32\certprop.dll
10:22:55.0106 0x07c4  CertPropSvc - ok
10:22:55.0121 0x07c4  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\drivers\circlass.sys
10:22:55.0153 0x07c4  circlass - ok
10:22:55.0199 0x07c4  [ 78CA84A35D09888E1FF21973E6E709C1, 9B2F03CCF816546591D8C4DC951D07D156C5CFA2B94EB6996ABB1EF261AFDBEB ] CLFS            C:\Windows\system32\CLFS.sys
10:22:55.0231 0x07c4  CLFS - ok
10:22:55.0652 0x07c4  [ ED356EA493F6AD81B0BCA331F96676C5, D93F6DAB94B428462674AF78A639ED50F708BD1F89A588525EB8372E27081238 ] ClickToRunSvc   C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
10:22:56.0198 0x07c4  ClickToRunSvc - ok
10:22:56.0229 0x07c4  CLMirrorDriver - ok
10:22:56.0291 0x07c4  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:22:56.0323 0x07c4  clr_optimization_v2.0.50727_32 - ok
10:22:56.0385 0x07c4  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:22:56.0416 0x07c4  clr_optimization_v2.0.50727_64 - ok
10:22:56.0494 0x07c4  [ 10197E3B5361932659D0CEA4DC3C49C2, 4D137BA8A71DA1707D01F5AA713C079DA08A7AA9BDD01815D6ACB1D0107899BF ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:22:56.0619 0x07c4  clr_optimization_v4.0.30319_32 - ok
10:22:56.0635 0x07c4  [ C152CF53E13F36547BCB4E775FD7C20F, 71B7A8D73988199104D5D19B38A2416404446C02C61A5CDE40F34072DDFD131B ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
10:22:56.0713 0x07c4  clr_optimization_v4.0.30319_64 - ok
10:22:56.0728 0x07c4  clwvd9 - ok
10:22:56.0759 0x07c4  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\drivers\CmBatt.sys
10:22:56.0791 0x07c4  CmBatt - ok
10:22:56.0806 0x07c4  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
10:22:56.0822 0x07c4  cmdide - ok
10:22:56.0900 0x07c4  [ 9DE8D00626F01DBD1879A6655D7A752D, 7624FEAEC4FBB2FAC484DA295FB748136BB331032FC58B426A45802F55F5C24D ] CNG             C:\Windows\system32\Drivers\cng.sys
10:22:56.0931 0x07c4  CNG - ok
10:22:56.0978 0x07c4  [ 9E10F4E7F4C7FF1EA3E94F9892BD067F, FF4B747ADE6AF37FBCD4E6DFFCDF08AD5556FEFE1E714FB864BC8428478EE5CE ] COMMONFX        C:\Windows\system32\drivers\COMMONFX.SYS
10:22:56.0978 0x07c4  COMMONFX - ok
10:22:57.0009 0x07c4  [ 9E10F4E7F4C7FF1EA3E94F9892BD067F, FF4B747ADE6AF37FBCD4E6DFFCDF08AD5556FEFE1E714FB864BC8428478EE5CE ] COMMONFX.SYS    C:\Windows\System32\drivers\COMMONFX.SYS
10:22:57.0009 0x07c4  COMMONFX.SYS - ok
10:22:57.0056 0x07c4  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
10:22:57.0056 0x07c4  Compbatt - ok
10:22:57.0087 0x07c4  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
10:22:57.0118 0x07c4  CompositeBus - ok
10:22:57.0134 0x07c4  COMSysApp - ok
10:22:57.0165 0x07c4  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
10:22:57.0165 0x07c4  crcdisk - ok
10:22:57.0212 0x07c4  [ 2F10C8ECB51E41C9993B90204F3A5F5E, FF50F28544FDAB545971FFA7113BD7967CCAE6CD83858ECF7346C6A0DDE9672A ] CryptSvc        C:\Windows\system32\cryptsvc.dll
10:22:57.0259 0x07c4  CryptSvc - ok
10:22:57.0290 0x07c4  [ 80BC9D418607974E4940EBC42F69BC8D, 83F1C21DCBAC4CCD970DD820C169C31DE97BD8A42D3384454B0D9C9A6053A297 ] CSC             C:\Windows\system32\drivers\csc.sys
10:22:57.0321 0x07c4  CSC - ok
10:22:57.0383 0x07c4  [ C593B028F399934C0A739AD7438B21BF, 8A288BD3F333ABBA9D96BD88E62B0BA782C7DF6027AC65DC2375800035655F9F ] CscService      C:\Windows\System32\cscsvc.dll
10:22:57.0446 0x07c4  CscService - ok
10:22:57.0477 0x07c4  [ F3D40F24BE053348B6E71ACE28FBA457, E59DE0507FA88EE3E28220EBABE925B16308835A9CFD4CFB98603681B6C5ADA5 ] CT20XUT         C:\Windows\system32\drivers\CT20XUT.SYS
10:22:57.0493 0x07c4  CT20XUT - ok
10:22:57.0524 0x07c4  [ F3D40F24BE053348B6E71ACE28FBA457, E59DE0507FA88EE3E28220EBABE925B16308835A9CFD4CFB98603681B6C5ADA5 ] CT20XUT.SYS     C:\Windows\System32\drivers\CT20XUT.SYS
10:22:57.0539 0x07c4  CT20XUT.SYS - ok
10:22:57.0602 0x07c4  [ C6575499CB77E3482D99AA610B7C354A, 3DF6E48196A1B2310FEB9E147F45FF71D56712037D0CB013E2856F0C05433AF5 ] ctac32k         C:\Windows\system32\drivers\ctac32k.sys
10:22:57.0617 0x07c4  ctac32k - ok
10:22:57.0664 0x07c4  [ 834F2E7BFDEE4F0E0301F1E16E141983, 9672E8CB076D6883EAF923DC4EDC34AA3429A920B696B7B7CB51AF8CB113243A ] ctaud2k         C:\Windows\system32\drivers\ctaud2k.sys
10:22:57.0680 0x07c4  ctaud2k - ok
10:22:57.0727 0x07c4  [ 15613C3987E336F0E29639723EDA1CE6, C2BDFF4BB3295DD2766F5073815C564B5DD4098F2084C72AC723FA05BCFA3746 ] CTAUDFX         C:\Windows\system32\drivers\CTAUDFX.SYS
10:22:57.0742 0x07c4  CTAUDFX - ok
10:22:57.0789 0x07c4  [ 15613C3987E336F0E29639723EDA1CE6, C2BDFF4BB3295DD2766F5073815C564B5DD4098F2084C72AC723FA05BCFA3746 ] CTAUDFX.SYS     C:\Windows\System32\drivers\CTAUDFX.SYS
10:22:57.0805 0x07c4  CTAUDFX.SYS - ok
10:22:57.0851 0x07c4  [ 3284CAB1DAD1F4A5FF84706EDE8C0AD0, BE729246DBEB345EB2B657DEF50E54E92256E32FD878848620ACB91EBAE088BC ] CTEAPSFX        C:\Windows\system32\drivers\CTEAPSFX.SYS
10:22:57.0851 0x07c4  CTEAPSFX - ok
10:22:57.0867 0x07c4  [ 3284CAB1DAD1F4A5FF84706EDE8C0AD0, BE729246DBEB345EB2B657DEF50E54E92256E32FD878848620ACB91EBAE088BC ] CTEAPSFX.SYS    C:\Windows\System32\drivers\CTEAPSFX.SYS
10:22:57.0883 0x07c4  CTEAPSFX.SYS - ok
10:22:57.0898 0x07c4  [ A8C84E9E9443D73195E869B4C9B74BAD, 8A77C553ED2BCEF9A87D314A8A1502C4A8EFA3412E8C9F133D2AF3F63FA94649 ] CTEDSPFX        C:\Windows\system32\drivers\CTEDSPFX.SYS
10:22:57.0914 0x07c4  CTEDSPFX - ok
10:22:57.0929 0x07c4  [ A8C84E9E9443D73195E869B4C9B74BAD, 8A77C553ED2BCEF9A87D314A8A1502C4A8EFA3412E8C9F133D2AF3F63FA94649 ] CTEDSPFX.SYS    C:\Windows\System32\drivers\CTEDSPFX.SYS
10:22:57.0945 0x07c4  CTEDSPFX.SYS - ok
10:22:57.0961 0x07c4  [ 5B354CA888A4EB1BA1A36D0D6589CCC7, 2154CB224E1D3B6718239345BC9DEF85685317612B16CC305792B76D520AEEB9 ] CTEDSPIO        C:\Windows\system32\drivers\CTEDSPIO.SYS
10:22:57.0976 0x07c4  CTEDSPIO - ok
10:22:58.0007 0x07c4  [ 5B354CA888A4EB1BA1A36D0D6589CCC7, 2154CB224E1D3B6718239345BC9DEF85685317612B16CC305792B76D520AEEB9 ] CTEDSPIO.SYS    C:\Windows\System32\drivers\CTEDSPIO.SYS
10:22:58.0023 0x07c4  CTEDSPIO.SYS - ok
10:22:58.0039 0x07c4  [ A0B1D9E47C33A6ADC1B48D668AAD12E1, AFB0D0A9C38060E3B33EDAD67F985E97E8A0AB182F119AA3BAA017E471A0091E ] CTEDSPSY        C:\Windows\system32\drivers\CTEDSPSY.SYS
10:22:58.0054 0x07c4  CTEDSPSY - ok
10:22:58.0085 0x07c4  [ A0B1D9E47C33A6ADC1B48D668AAD12E1, AFB0D0A9C38060E3B33EDAD67F985E97E8A0AB182F119AA3BAA017E471A0091E ] CTEDSPSY.SYS    C:\Windows\System32\drivers\CTEDSPSY.SYS
10:22:58.0085 0x07c4  CTEDSPSY.SYS - ok
10:22:58.0117 0x07c4  [ 36975325697A9100F105EFABC923D5B5, F232961CCC880EE4B72FBC311A56BA8776CB6505015B808133A5F154D61A2B66 ] CTERFXFX        C:\Windows\system32\drivers\CTERFXFX.SYS
10:22:58.0117 0x07c4  CTERFXFX - ok
10:22:58.0132 0x07c4  [ 36975325697A9100F105EFABC923D5B5, F232961CCC880EE4B72FBC311A56BA8776CB6505015B808133A5F154D61A2B66 ] CTERFXFX.SYS    C:\Windows\System32\drivers\CTERFXFX.SYS
10:22:58.0132 0x07c4  CTERFXFX.SYS - ok
10:22:58.0195 0x07c4  [ 5C7B8C1559FB630E8D17DDFDDCFE3DB9, EFE71134DCAA4A35B01DAE41F1B7C165193AC111B800E4A2311FDBBCAF7BB8B0 ] CTEXFIFX        C:\Windows\system32\drivers\CTEXFIFX.SYS
10:22:58.0257 0x07c4  CTEXFIFX - ok
10:22:58.0304 0x07c4  [ 5C7B8C1559FB630E8D17DDFDDCFE3DB9, EFE71134DCAA4A35B01DAE41F1B7C165193AC111B800E4A2311FDBBCAF7BB8B0 ] CTEXFIFX.SYS    C:\Windows\System32\drivers\CTEXFIFX.SYS
10:22:58.0351 0x07c4  CTEXFIFX.SYS - ok
10:22:58.0382 0x07c4  [ 92D7BE76504C0A459DA5AE9F983A8918, 1EDBD19A032A76C4B83F58ED28D38932D0981DE3B829376F7A74D25BE972A996 ] CTHWIUT         C:\Windows\system32\drivers\CTHWIUT.SYS
10:22:58.0397 0x07c4  CTHWIUT - ok
10:22:58.0397 0x07c4  [ 92D7BE76504C0A459DA5AE9F983A8918, 1EDBD19A032A76C4B83F58ED28D38932D0981DE3B829376F7A74D25BE972A996 ] CTHWIUT.SYS     C:\Windows\System32\drivers\CTHWIUT.SYS
10:22:58.0413 0x07c4  CTHWIUT.SYS - ok
10:22:58.0444 0x07c4  [ 767CF74A38F30097688D5DD8ED65EA5C, F4A97A5AC4E574EEA0BE13ADF441244E0C42D83187E100210C95749E1CBC6372 ] ctprxy2k        C:\Windows\system32\drivers\ctprxy2k.sys
10:22:58.0460 0x07c4  ctprxy2k - ok
10:22:58.0491 0x07c4  [ FED737BC339D7A92B4025A7609B55EA9, 3A85FFAECA905A052061E750D1D63B35EAFC7996E2A925EE7405AEED3E4CF4D4 ] CTSBLFX         C:\Windows\system32\drivers\CTSBLFX.SYS
10:22:58.0507 0x07c4  CTSBLFX - ok
10:22:58.0538 0x07c4  [ FED737BC339D7A92B4025A7609B55EA9, 3A85FFAECA905A052061E750D1D63B35EAFC7996E2A925EE7405AEED3E4CF4D4 ] CTSBLFX.SYS     C:\Windows\System32\drivers\CTSBLFX.SYS
10:22:58.0553 0x07c4  CTSBLFX.SYS - ok
10:22:58.0600 0x07c4  [ D17A852D6E00A112EC0196B8CCB17713, 700B3A83A0C4460DFE238AC2BFE52A5E809AC583EDC85B923340544211779BC0 ] ctsfm2k         C:\Windows\system32\drivers\ctsfm2k.sys
10:22:58.0616 0x07c4  ctsfm2k - ok
10:22:58.0678 0x07c4  [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdate        C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
10:22:58.0694 0x07c4  dbupdate - ok
10:22:58.0709 0x07c4  [ A1F58FFF448E4099297D6EE0641D4D0E, 47839789332AAF8861F7731BF2D3FBB5E0991EA0D0B457BB4C8C1784F76C73DC ] dbupdatem       C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
10:22:58.0725 0x07c4  dbupdatem - ok
10:22:58.0756 0x07c4  [ 15EE912B1056E8A498CB4B2FD4D011FD, 7E7771826F95EE8C081B0F6348EF76847C2093427DD57BA37419B629C2C0CBE4 ] DbxSvc          C:\Windows\system32\DbxSvc.exe
10:22:58.0772 0x07c4  DbxSvc - ok
10:22:58.0819 0x07c4  [ 5F3EB8162C7289C576BA23730193FB6A, 2D628832AF0BA61B1EB70A5070C71FAE8ECE0F6E136399B94BB38045CD040B3E ] DcomLaunch      C:\Windows\system32\rpcss.dll
10:22:58.0881 0x07c4  DcomLaunch - ok
10:22:58.0912 0x07c4  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc       C:\Windows\System32\defragsvc.dll
10:22:58.0959 0x07c4  defragsvc - ok
10:22:58.0990 0x07c4  [ 63705A08981F7EDD376241D6E0A9C2AC, 6965D64D164A4DBBC328D2611EE38A71D3FA66A6438AFC6E4830DC37ABC28729 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
10:22:59.0053 0x07c4  DfsC - ok
10:22:59.0099 0x07c4  [ 92286CCC501A4F588B2FAB8D1B6A236C, 9B96B92D9874DC8C24BD2B9DBB1C179175B36892B98C6638DCA0D5FA48D55A80 ] Dhcp            C:\Windows\system32\dhcpcore.dll
10:22:59.0146 0x07c4  Dhcp - ok
10:22:59.0255 0x07c4  [ 7DF76667FA6276EE94F3BEAA8105E1B3, 199934460BED7F8A655EF70677CFED68F5F8091B22F834216B0B2B41B876721D ] DiagTrack       C:\Windows\system32\diagtrack.dll
10:22:59.0458 0x07c4  DiagTrack - ok
10:22:59.0505 0x07c4  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
10:22:59.0536 0x07c4  discache - ok
10:22:59.0567 0x07c4  [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk            C:\Windows\system32\drivers\disk.sys
10:22:59.0583 0x07c4  Disk - ok
10:22:59.0630 0x07c4  [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc           C:\Windows\system32\drivers\dmvsc.sys
10:22:59.0661 0x07c4  dmvsc - ok
10:22:59.0708 0x07c4  [ EEEFC204476D5C44E4F6802F55697179, 0B67D193FF6389BE207F584F4D0C4C0B8BC9F4206851991AD270D894B95E314E ] Dnscache        C:\Windows\System32\dnsrslvr.dll
10:22:59.0755 0x07c4  Dnscache - ok
10:22:59.0786 0x07c4  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc         C:\Windows\System32\dot3svc.dll
10:22:59.0848 0x07c4  dot3svc - ok
10:22:59.0879 0x07c4  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS             C:\Windows\system32\dps.dll
10:22:59.0942 0x07c4  DPS - ok
10:22:59.0973 0x07c4  [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
10:22:59.0989 0x07c4  drmkaud - ok
10:23:00.0035 0x07c4  [ 65F3E2BDB187EF73CE65B92C770594DD, 13D6FB4D2284EC6B138740AAEF4C7F6AC82E78D59891F4E51C8656F05150DB8E ] DroidCam        C:\Windows\system32\DRIVERS\droidcam.sys
10:23:00.0051 0x07c4  DroidCam - ok
10:23:00.0098 0x07c4  [ DEA6132C81EE004EECB4F23889D9295F, 7CF48EA26FF350995F54FED592F94DB634CE3C96C7F9FD76D67993CE8F0FAD87 ] DroidCamVideo   C:\Windows\system32\DRIVERS\droidcamvideo.sys
10:23:00.0098 0x07c4  DroidCamVideo - ok
10:23:00.0176 0x07c4  [ E5D015CBF87B514F822D2E782B3D883D, 63215A6036CF1AA8487449E6BE9EE2DB5252ABCFF5C7E61CE9B905B5C92340AD ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
10:23:00.0223 0x07c4  DXGKrnl - ok
10:23:00.0269 0x07c4  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost         C:\Windows\System32\eapsvc.dll
10:23:00.0301 0x07c4  EapHost - ok
10:23:00.0441 0x07c4  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
10:23:00.0581 0x07c4  ebdrv - ok
10:23:00.0628 0x07c4  [ 3E71928C087FBB3B23A4D816C843B538, DCF9D744FE1B1CF47EC2870B44C852846C221D604B50DE8ADF79F60629A92A55 ] EFS             C:\Windows\System32\lsass.exe
10:23:00.0644 0x07c4  EFS - ok
10:23:00.0722 0x07c4  [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE1646471811F3A5679EF75F1 ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
10:23:00.0769 0x07c4  ehRecvr - ok
10:23:00.0784 0x07c4  [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45C11E3CFE30637D ] ehSched         C:\Windows\ehome\ehsched.exe
10:23:00.0815 0x07c4  ehSched - ok
10:23:00.0878 0x07c4  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
10:23:00.0909 0x07c4  elxstor - ok
10:23:00.0940 0x07c4  [ 2F20C75D94C3827192F808FCF1FF79EC, 4D4ED0AA1B7FC6733DE74FE0C681F951D8458CFF369A9908FB52FB6BD4912058 ] emupia          C:\Windows\system32\drivers\emupia2k.sys
10:23:00.0956 0x07c4  emupia - ok
10:23:00.0987 0x07c4  [ 9002EED07FD7FCFF6B8C5C06B454AC19, 0FCEF7D930316FF267841009DF83F29A7D9CD6ED710128F493EC15EC99D9ACD6 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
10:23:01.0018 0x07c4  ErrDev - ok
10:23:01.0081 0x07c4  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem     C:\Windows\system32\es.dll
10:23:01.0127 0x07c4  EventSystem - ok
10:23:01.0174 0x07c4  [ 6588D3501EE7692D3A46899ACF2E6EF6, A3B0A7C17319125424A618C3A1E3CB8D2A55A7C4B17B66E0EFC17701B5D7945B ] exetools        C:\Windows\system32\DRIVERS\exetools.sys
10:23:01.0190 0x07c4  exetools - detected UnsignedFile.Multi.Generic ( 1 )
10:23:01.0361 0x07c4  exetools ( UnsignedFile.Multi.Generic ) - warning
10:23:01.0361 0x07c4  Force sending object to P2P due to detect: exetools
10:23:01.0517 0x07c4  Object send P2P result: true
10:23:01.0642 0x07c4  [ 173F4A590EAD80CAAAD4DB346DF8DC89, 907C894E5141F7C461B5A86147CEAD9D655DCACCEE7CB698FB0E653C985B2F78 ] exfat           C:\Windows\system32\drivers\exfat.sys
10:23:01.0689 0x07c4  exfat - ok
10:23:01.0720 0x07c4  [ 87E0E4B0B83A77017D5A91A72C10986D, 7112DD76A8EE96E50B48DF23211E229EA30E550358105F3554ECF46666939B16 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
10:23:01.0767 0x07c4  fastfat - ok
10:23:01.0814 0x07c4  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax             C:\Windows\system32\fxssvc.exe
10:23:01.0861 0x07c4  Fax - ok
10:23:01.0892 0x07c4  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc             C:\Windows\system32\drivers\fdc.sys
10:23:01.0923 0x07c4  fdc - ok
10:23:01.0970 0x07c4  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost         C:\Windows\system32\fdPHost.dll
10:23:02.0001 0x07c4  fdPHost - ok
10:23:02.0001 0x07c4  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
10:23:02.0048 0x07c4  FDResPub - ok
10:23:02.0079 0x07c4  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
10:23:02.0095 0x07c4  FileInfo - ok
10:23:02.0110 0x07c4  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
10:23:02.0141 0x07c4  Filetrace - ok
10:23:02.0173 0x07c4  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
10:23:02.0204 0x07c4  flpydisk - ok
10:23:02.0251 0x07c4  [ DC591A7A196E99EFB5A48D708CB989FD, 1C34C0A4AEEE977D290EF5E79C3B13B1F1F18E051F49815013D360F62458D82A ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
10:23:02.0266 0x07c4  FltMgr - ok
10:23:02.0329 0x07c4  [ 17EC6A8CB448437B29721BDB6B585661, 0119A7A0D9179E7CD6915A1514BE9974C4A08A5CB23C3FB7DBD691CD60B2E3DA ] FontCache       C:\Windows\system32\FntCache.dll
10:23:02.0407 0x07c4  FontCache - ok
10:23:02.0469 0x07c4  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:23:02.0485 0x07c4  FontCache3.0.0.0 - ok
10:23:02.0516 0x07c4  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
10:23:02.0531 0x07c4  FsDepends - ok
10:23:02.0563 0x07c4  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
10:23:02.0578 0x07c4  Fs_Rec - ok
10:23:02.0625 0x07c4  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
10:23:02.0656 0x07c4  fvevol - ok
10:23:02.0672 0x07c4  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
10:23:02.0687 0x07c4  gagp30kx - ok
10:23:02.0906 0x07c4  [ 26F6932C680BA9D4C05C0E182F422C44, A7E8863202B322667BF00A4F4FFD7C6C009240CD637E4CDBFE4562551A1C808B ] GoogleChromeElevationService C:\Program Files (x86)\Google\Chrome\Application\88.0.4324.150\elevation_service.exe
10:23:02.0984 0x07c4  GoogleChromeElevationService - ok
10:23:03.0046 0x07c4  [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc           C:\Windows\System32\gpsvc.dll
10:23:03.0109 0x07c4  gpsvc - ok
10:23:03.0202 0x07c4  [ 79B804E8A81BFD9C6A3749B4F3EE86E2, BFBDD26604FC653E01976EF23C92CF7ADB59F9E80F47350F1A72B7876BBED60A ] gupdate         C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:23:03.0218 0x07c4  gupdate - ok
10:23:03.0265 0x07c4  [ 79B804E8A81BFD9C6A3749B4F3EE86E2, BFBDD26604FC653E01976EF23C92CF7ADB59F9E80F47350F1A72B7876BBED60A ] gupdatem        C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:23:03.0280 0x07c4  gupdatem - ok
10:23:03.0343 0x07c4  [ DDD48753EA2037A8F64ED377616E6D38, B506471464F7448DA56BB4DE6F074DB6C063358479F632E0DC7F81C68A5D3F36 ] ha10kx2k        C:\Windows\system32\drivers\ha10kx2k.sys
10:23:03.0374 0x07c4  ha10kx2k - ok
10:23:03.0421 0x07c4  [ 3921C845A24C62CA1F44EEF4826263E9, 4CB2CAB0B96F097B3BFC28EA12AA7C28131AEC114BF0920BC80789CDD6BF4019 ] hardlock        C:\Windows\system32\drivers\hardlock.sys
10:23:03.0436 0x07c4  hardlock - ok
10:23:03.0436 0x07c4  hasplms - ok
10:23:03.0467 0x07c4  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
10:23:03.0483 0x07c4  hcw85cir - ok
10:23:03.0545 0x07c4  [ 9AF4A0ACD548D31C46EDA7DD7EFE6139, A29FF1DEEADA0E1A958E9453A41D3C05441D3E70ADE6D9BAC28C7CB83735DAAA ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
10:23:03.0577 0x07c4  HdAudAddService - ok
10:23:03.0592 0x07c4  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
10:23:03.0623 0x07c4  HDAudBus - ok
10:23:03.0655 0x07c4  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
10:23:03.0670 0x07c4  HidBatt - ok
10:23:03.0717 0x07c4  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
10:23:03.0733 0x07c4  HidBth - ok
10:23:03.0764 0x07c4  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr           C:\Windows\system32\drivers\hidir.sys
10:23:03.0795 0x07c4  HidIr - ok
10:23:03.0826 0x07c4  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv         C:\Windows\system32\hidserv.dll
10:23:03.0857 0x07c4  hidserv - ok
10:23:03.0920 0x07c4  [ F3169EF73866BA0F98B505E5B5D8D811, C4F86BF848AF239D930D0A287B5099825DE89002A05E95CB60A7E7D8D4B0ED9E ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
10:23:03.0951 0x07c4  HidUsb - ok
10:23:03.0982 0x07c4  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
10:23:04.0013 0x07c4  hkmsvc - ok
10:23:04.0045 0x07c4  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
10:23:04.0076 0x07c4  HomeGroupListener - ok
10:23:04.0123 0x07c4  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
10:23:04.0138 0x07c4  HomeGroupProvider - ok
10:23:04.0185 0x07c4  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
10:23:04.0185 0x07c4  HpSAMD - ok
10:23:04.0247 0x07c4  [ 93C367EA831FB39DEE3BA96539A187FB, 8B912152CA8B89B4429278F93163481BAA07E2D940EE61CE1B7AD178AB13E105 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
10:23:04.0325 0x07c4  HTTP - ok
10:23:04.0341 0x07c4  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
10:23:04.0341 0x07c4  hwpolicy - ok
10:23:04.0388 0x07c4  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
10:23:04.0403 0x07c4  i8042prt - ok
10:23:04.0466 0x07c4  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
10:23:04.0481 0x07c4  iaStorV - ok
10:23:04.0544 0x07c4  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:23:04.0591 0x07c4  idsvc - ok
10:23:04.0606 0x07c4  IEEtwCollectorService - ok
10:23:04.0653 0x07c4  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
10:23:04.0653 0x07c4  iirsp - ok
10:23:04.0715 0x07c4  [ 25AF7D5C819F19D7C97F4A9607F2609A, 70142B97F1087E20758AFECF5A7AB2EC1FDBBF68019A3BEC6C49F168650FEFC8 ] IKEEXT          C:\Windows\System32\ikeext.dll
10:23:04.0793 0x07c4  IKEEXT - ok
10:23:04.0825 0x07c4  IntcAzAudAddService - ok
10:23:04.0856 0x07c4  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
10:23:04.0856 0x07c4  intelide - ok
10:23:04.0918 0x07c4  [ 6518C5A7088D16E0B258C976E9588D9F, 4C0139FFB81E495AC6384F707E901426A3ACECFBCA040AE0DC0074A951CA75E6 ] intelppm        C:\Windows\system32\drivers\intelppm.sys
10:23:04.0949 0x07c4  intelppm - ok
10:23:04.0981 0x07c4  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
10:23:05.0012 0x07c4  IPBusEnum - ok
10:23:05.0059 0x07c4  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:23:05.0074 0x07c4  IpFilterDriver - ok
10:23:05.0137 0x07c4  [ 5B364681859A10CA529B3009FEA461AF, 669CF62A9C27391559F3AECC1640C8ECADB96312B1E3ED8A326AA5516DA905AC ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
10:23:05.0199 0x07c4  iphlpsvc - ok
10:23:05.0230 0x07c4  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
10:23:05.0230 0x07c4  IPMIDRV - ok
10:23:05.0246 0x07c4  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
10:23:05.0293 0x07c4  IPNAT - ok
10:23:05.0339 0x07c4  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
10:23:05.0355 0x07c4  IRENUM - ok
10:23:05.0386 0x07c4  [ 7E1DBF664ED3F203B1D3770E8586589D, 94B880B2B76C42B13F074F099BCFFD0FB41FF5F5A5C1790A2602066A25612956 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
10:23:05.0402 0x07c4  isapnp - ok
10:23:05.0433 0x07c4  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
10:23:05.0480 0x07c4  iScsiPrt - ok
10:23:05.0495 0x07c4  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
10:23:05.0495 0x07c4  kbdclass - ok
10:23:05.0542 0x07c4  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
10:23:05.0558 0x07c4  kbdhid - ok
10:23:05.0589 0x07c4  [ 3E71928C087FBB3B23A4D816C843B538, DCF9D744FE1B1CF47EC2870B44C852846C221D604B50DE8ADF79F60629A92A55 ] KeyIso          C:\Windows\system32\lsass.exe
10:23:05.0589 0x07c4  KeyIso - ok
10:23:05.0636 0x07c4  [ 7EE31F75C06112AAC24CFA3421E7A2C0, AEEAB4B97BA4B64CE8ECB081E191C0B480A6F73C3B203D40235D89802FD5BD35 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
10:23:05.0651 0x07c4  KSecDD - ok
10:23:05.0667 0x07c4  [ 2218BEFC4EFE4BE5797BC62AC3B2D64A, 643B108A7356A54C34A42B43D994AEEC02D5E66AA87BC97B561975E72F202AD7 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
10:23:05.0683 0x07c4  KSecPkg - ok
10:23:05.0714 0x07c4  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
10:23:05.0761 0x07c4  ksthunk - ok
10:23:05.0807 0x07c4  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm           C:\Windows\system32\msdtckrm.dll
10:23:05.0854 0x07c4  KtmRm - ok
10:23:05.0901 0x07c4  [ CF4EE0CB960306B63FE21C73E9B2E19C, 26BCDC59E04CCAD7647D15C9546FF2FF47C2B1371E719DBDCEC45AA3738F273C ] LanmanServer    C:\Windows\system32\srvsvc.dll
10:23:05.0963 0x07c4  LanmanServer - ok
10:23:05.0995 0x07c4  [ 01C95A8CAE16CCF1EA1181395C872B9F, 0BB846AFC7335BB0CD52735AE32E0BCD5075865900C356493DC159795E8C8181 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
10:23:06.0041 0x07c4  LanmanWorkstation - ok
10:23:06.0088 0x07c4  [ 8B125674D81F0A307F1FD8D5C4C8DE4D, AB029B7E07ED4CD1805EC4F8E2E86C7C156997EE1CF90A95415F192E490572EC ] LHidFilt        C:\Windows\system32\DRIVERS\LHidFilt.Sys
10:23:06.0104 0x07c4  LHidFilt - ok
10:23:06.0151 0x07c4  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
10:23:06.0197 0x07c4  lltdio - ok
10:23:06.0229 0x07c4  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
10:23:06.0291 0x07c4  lltdsvc - ok
10:23:06.0307 0x07c4  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts         C:\Windows\System32\lmhsvc.dll
10:23:06.0353 0x07c4  lmhosts - ok
10:23:06.0385 0x07c4  [ 148E1E28CB6EEBEC7B7694F63C0A9933, 90A9E93C9EF03BDE409335F090FAA79F6255CD5754E3F8129F638831AD5709D0 ] LMouFilt        C:\Windows\system32\DRIVERS\LMouFilt.Sys
10:23:06.0385 0x07c4  LMouFilt - ok
10:23:06.0447 0x07c4  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
10:23:06.0447 0x07c4  LSI_FC - ok
10:23:06.0463 0x07c4  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
10:23:06.0478 0x07c4  LSI_SAS - ok
10:23:06.0494 0x07c4  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
10:23:06.0494 0x07c4  LSI_SAS2 - ok
10:23:06.0509 0x07c4  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
10:23:06.0525 0x07c4  LSI_SCSI - ok
10:23:06.0556 0x07c4  [ 33F4F8FA5A6978602AF6CA8F2B6C3F10, EDD5D993283F3FF2F8E09751815B992E800BDBB147385E303DEC26E120410C56 ] luafv           C:\Windows\system32\drivers\luafv.sys
10:23:06.0603 0x07c4  luafv - ok
10:23:06.0650 0x07c4  [ 95EB02FD1E681FF04EE726F487E5BED0, F7823F85523B031763EB94128F2FD78681FF17DDE3559AA12842F6D1B388D497 ] LUsbFilt        C:\Windows\system32\Drivers\LUsbFilt.Sys
10:23:06.0665 0x07c4  LUsbFilt - ok
10:23:06.0697 0x07c4  [ 29151389B7E4134C642ABB64DB02D63F, C0B14932004F79E823CBAC55141CB9A4930A0D99C8F81C56D316ECCE183D8D52 ] MBAMChameleon   C:\Windows\System32\Drivers\MbamChameleon.sys
10:23:06.0712 0x07c4  MBAMChameleon - ok
10:23:07.0040 0x07c4  [ 9A463A0386D75F5EE3D496966FA5E466, 340E72FF6E0AD4D48749EED73452EBB5A6B7679BFB98FBBEDF8C4C6A2B3D118C ] MBAMService     C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
10:23:07.0211 0x07c4  MBAMService - ok
10:23:07.0274 0x07c4  [ 0B17A8F4956ABD5FA1A0851B59FF960E, 1B62082ACA96EF78A61AFDB33EF77260292C5D08E5E35B56F7F8F0A3A837ED9B ] MBAMSwissArmy   C:\Windows\System32\Drivers\mbamswissarmy.sys
10:23:07.0289 0x07c4  MBAMSwissArmy - ok
10:23:07.0336 0x07c4  [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94509E3F0EEB7428 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
10:23:07.0336 0x07c4  Mcx2Svc - ok
10:23:07.0383 0x07c4  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas         C:\Windows\system32\drivers\megasas.sys
10:23:07.0399 0x07c4  megasas - ok
10:23:07.0414 0x07c4  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
10:23:07.0445 0x07c4  MegaSR - ok
10:23:07.0477 0x07c4  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS           C:\Windows\system32\mmcss.dll
10:23:07.0523 0x07c4  MMCSS - ok
10:23:07.0539 0x07c4  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem           C:\Windows\system32\drivers\modem.sys
10:23:07.0570 0x07c4  Modem - ok
10:23:07.0617 0x07c4  [ 0E8EBD8E54DB14F14412B90AD4B099BF, 5D6513AFB31B0907D84C79869660C578203281ACD221B970B69E16295F26D749 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
10:23:07.0648 0x07c4  monitor - ok
10:23:07.0679 0x07c4  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
10:23:07.0695 0x07c4  mouclass - ok
10:23:07.0742 0x07c4  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
10:23:07.0757 0x07c4  mouhid - ok
10:23:07.0789 0x07c4  [ D250A7B69B0BDC151F5F7B9C9FC78074, 6B6C8205A88FC1E4BB2669FA1433EC9B0CD23F2CC818E1F64FDC9802E5744579 ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
10:23:07.0804 0x07c4  mountmgr - ok
10:23:07.0820 0x07c4  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
10:23:07.0835 0x07c4  mpio - ok
10:23:07.0867 0x07c4  [ 3F829492638A86A3C4E0BB06778F0C23, A5B5FBE06E407C892E4668D53CC3F49BC6C7ACA12ED7AFB69FAC1C133003A890 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
10:23:07.0898 0x07c4  mpsdrv - ok
10:23:07.0991 0x07c4  [ C7A8706D5536D9BE35396C0116CAA8EE, AFB6B40B5CBA4F54C6AB3F82534CCA9D393C466EC5E3981CEBB33CB111C405D0 ] MpsSvc          C:\Windows\system32\mpssvc.dll
10:23:08.0054 0x07c4  MpsSvc - ok
10:23:08.0085 0x07c4  [ 98DB1790F0A584E0A2528B92B052417F, 9AA04CA73AFE599810CD233B9CEC212E16D44DCEDF5C7D0181C7257F498068B5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
10:23:08.0116 0x07c4  MRxDAV - ok
10:23:08.0147 0x07c4  [ 2EF08F96630129E503D0A9C13604574F, B0EF46082A9959F0E49CF4308D856F80041B9E81F27AAE4528FE2B19EF3CC4B1 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
10:23:08.0194 0x07c4  mrxsmb - ok
10:23:08.0241 0x07c4  [ DF0E99ABC53DFB2036386F3A90EF97BB, 94E381DDA78134ED142C9F07483B95D1D6E331503B9CD2BE6B110EC467549FBE ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:23:08.0288 0x07c4  mrxsmb10 - ok
10:23:08.0319 0x07c4  [ 3E8048CF0BE9784B65615EBA75C95823, 666595401CC49644C2C0DEFF97CEA799FE1250DC3466CBA34EB7CD8B9469A02F ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:23:08.0335 0x07c4  mrxsmb20 - ok
10:23:08.0381 0x07c4  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
10:23:08.0381 0x07c4  msahci - ok
10:23:08.0428 0x07c4  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
10:23:08.0444 0x07c4  msdsm - ok
10:23:08.0459 0x07c4  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC           C:\Windows\System32\msdtc.exe
10:23:08.0491 0x07c4  MSDTC - ok
10:23:08.0537 0x07c4  [ 45BD105115AF4C040383FEA51F04BD06, 3E0FDFF5FE65053B7DA9630F0244C3E65FEB687C214333456D545EAF0AF1C325 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
10:23:08.0569 0x07c4  Msfs - ok
10:23:08.0584 0x07c4  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
10:23:08.0615 0x07c4  mshidkmdf - ok
10:23:08.0647 0x07c4  [ 0F7F6C886C308976DB01EFE81084A77F, FAB0D03DFB66224700423165422D03FF249F998737A942D32C63BDBBF60ABBC2 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
10:23:08.0662 0x07c4  msisadrv - ok
10:23:08.0693 0x07c4  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
10:23:08.0740 0x07c4  MSiSCSI - ok
10:23:08.0740 0x07c4  msiserver - ok
10:23:08.0771 0x07c4  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
10:23:08.0803 0x07c4  MSKSSRV - ok
10:23:08.0818 0x07c4  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
10:23:08.0849 0x07c4  MSPCLOCK - ok
10:23:08.0881 0x07c4  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
10:23:08.0912 0x07c4  MSPQM - ok
10:23:08.0959 0x07c4  [ D8085534B90355013A9D84D253DE26EA, 5E54C4B0B6A30EF5A0EF7A0E2AAC219269C824BA735B76C6BA56772B63EF322E ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
10:23:08.0990 0x07c4  MsRPC - ok
10:23:09.0021 0x07c4  [ A5D45B7B91F95F825EB5ABD3A6B262EF, C27C7E89205255CDE6A785C0141F3533E8572D0AFC4B9F73855565BF9F746E04 ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
10:23:09.0037 0x07c4  mssmbios - ok
10:23:09.0083 0x07c4  MSSQLSERVER - ok
10:23:09.0099 0x07c4  [ C06EA83F6FC2959E897C117255B6B1D5, 012C6E5AA61BAAED47CB0E59E2F3E6E87941F555C5581ECAC7DF1051795AF681 ] MSSQLServerADHelper C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqladhlp90.exe
10:23:09.0115 0x07c4  MSSQLServerADHelper - ok
10:23:09.0146 0x07c4  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
10:23:09.0193 0x07c4  MSTEE - ok
10:23:09.0208 0x07c4  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
10:23:09.0239 0x07c4  MTConfig - ok
10:23:09.0255 0x07c4  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup             C:\Windows\system32\Drivers\mup.sys
10:23:09.0271 0x07c4  Mup - ok
10:23:09.0317 0x07c4  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
10:23:09.0380 0x07c4  napagent - ok
10:23:09.0427 0x07c4  [ 9FB2A095B1166CB3C9A06651863B3452, 808105C59C2D28C390FDE0CA48690A5CD052DE3D7F7327864EB45F80187D5BE9 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
10:23:09.0458 0x07c4  NativeWifiP - ok
10:23:09.0536 0x07c4  [ CBE5C2A3353A367734989E335D6AF194, E8927AD1202AC5E523717AC4ADB2345D31A00B304FA56056B27043792237CFEC ] NDIS            C:\Windows\system32\drivers\ndis.sys
10:23:09.0583 0x07c4  NDIS - ok
10:23:09.0598 0x07c4  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
10:23:09.0645 0x07c4  NdisCap - ok
10:23:09.0692 0x07c4  [ E8179074C0166D83BD8366169137669E, 44A3BCA1772F42CF0580C6BB0B48D106C678D0BB471DB6D81BC9C52895C9C16A ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
10:23:09.0707 0x07c4  NdisTapi - ok
10:23:09.0754 0x07c4  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
10:23:09.0785 0x07c4  Ndisuio - ok
10:23:09.0801 0x07c4  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
10:23:09.0848 0x07c4  NdisWan - ok
10:23:09.0879 0x07c4  [ D0FE24076ED3BA7B54D6E9819F8215A8, 42962676E322DCD9112740E6C43C8E49B8F9D998D7733645947771598FD3DD22 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
10:23:09.0895 0x07c4  NDProxy - ok
10:23:09.0941 0x07c4  [ 2E19EB10185992AB08BC3688AACA4CE2, D9E3A5CFE8887B7F66239000116723FAA119107870A6FB65FD6F108CE5C9D9EB ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
10:23:09.0973 0x07c4  NetBIOS - ok
10:23:10.0019 0x07c4  [ 0805034EA6F5273D4CB130D726AA5450, 3662B56226CF79A19174F3644D1902A4EE90CCBB86890B902DC387F3DFB492E7 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
10:23:10.0051 0x07c4  NetBT - ok
10:23:10.0082 0x07c4  [ 3E71928C087FBB3B23A4D816C843B538, DCF9D744FE1B1CF47EC2870B44C852846C221D604B50DE8ADF79F60629A92A55 ] Netlogon        C:\Windows\system32\lsass.exe
10:23:10.0097 0x07c4  Netlogon - ok
10:23:10.0129 0x07c4  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
10:23:10.0175 0x07c4  Netman - ok
10:23:10.0238 0x07c4  [ F2DAF801C4E356E6BE14F5C3A6EED943, BE90128B9FFE79D9E4E9FCE22A289353879991EBDB407A0302D3E87CFA05C312 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:23:10.0285 0x07c4  NetMsmqActivator - ok
10:23:10.0300 0x07c4  [ F2DAF801C4E356E6BE14F5C3A6EED943, BE90128B9FFE79D9E4E9FCE22A289353879991EBDB407A0302D3E87CFA05C312 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:23:10.0316 0x07c4  NetPipeActivator - ok
10:23:10.0347 0x07c4  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
10:23:10.0394 0x07c4  netprofm - ok
10:23:10.0425 0x07c4  [ F2DAF801C4E356E6BE14F5C3A6EED943, BE90128B9FFE79D9E4E9FCE22A289353879991EBDB407A0302D3E87CFA05C312 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:23:10.0425 0x07c4  NetTcpActivator - ok
10:23:10.0441 0x07c4  [ F2DAF801C4E356E6BE14F5C3A6EED943, BE90128B9FFE79D9E4E9FCE22A289353879991EBDB407A0302D3E87CFA05C312 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:23:10.0456 0x07c4  NetTcpPortSharing - ok
10:23:10.0487 0x07c4  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
10:23:10.0503 0x07c4  nfrd960 - ok
10:23:10.0550 0x07c4  [ EEECC4C67144A39BA5B9B6E351932606, C3CB9042D00559893EA37969898840D3D437703E6B13BCF21253AB40F6071446 ] NIWinCDEmu      C:\Windows\system32\DRIVERS\NIWinCDEmu.sys
10:23:10.0565 0x07c4  NIWinCDEmu - ok
10:23:10.0612 0x07c4  [ 93DEDBE8E24F31962755E6AA4AC2D7B0, 368B3F48F230514F496CE24339EC8943A87A6BB9815912AE192B73837AB3E3B7 ] NlaSvc          C:\Windows\System32\nlasvc.dll
10:23:10.0643 0x07c4  NlaSvc - ok
10:23:10.0690 0x07c4  [ F659AF9BC6E7555D89E39C5D0D8E236C, 92505AA42A27A1CA699E0FE6D1DE5503EBE043A923F6FCF0F7F77C3B909EE6BA ] Npfs            C:\Windows\system32\drivers\Npfs.sys
10:23:10.0706 0x07c4  Npfs - ok
10:23:10.0737 0x07c4  [ 668B9EFF5CCA4542F435D2CD9CE3C778, 7409EF35D1DC0DE2BAB752694981FFA1F1855C7F11310366B80BD1EC3513262E ] nsi             C:\Windows\system32\nsisvc.dll
10:23:10.0768 0x07c4  nsi - ok
10:23:10.0784 0x07c4  [ BE313E566EEA2A4B7F9AAC9782A567D4, 377C624737B1A4FBC1DFF988F029B8ED9A368827C33A4FEEBA1B7937A87C2B47 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
10:23:10.0831 0x07c4  nsiproxy - ok
10:23:10.0924 0x07c4  [ 1D728E2DA93EE1F7766DE97D0BEEFC57, 077C85AF6D788F1323648F5DD8B5873B06CD62B4AC33577453D01B16738BEFDE ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
10:23:11.0002 0x07c4  Ntfs - ok
10:23:11.0033 0x07c4  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
10:23:11.0065 0x07c4  Null - ok
10:23:11.0174 0x07c4  [ 63965E08F0EF74AE18114F146B3F6612, 0B582B44500B9BC6649A0F95BDF3C04A56004F4623E9892BCAAF185798425105 ] NVHDA           C:\Windows\system32\drivers\nvhda64v.sys
10:23:11.0189 0x07c4  NVHDA - ok
10:23:11.0221 0x07c4  nvlddmkm - ok
10:23:11.0252 0x07c4  [ 8E5EB7480832BBD4555CAB7D7FE1DD63, FC31E7E1B4709374C24E8F245A80CB810AFD7448263ED67875B75199534B9C3B ] NvModuleTracker C:\Windows\system32\DRIVERS\NvModuleTracker.sys
10:23:11.0252 0x07c4  NvModuleTracker - ok
10:23:11.0283 0x07c4  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
10:23:11.0299 0x07c4  nvraid - ok
10:23:11.0330 0x07c4  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
10:23:11.0345 0x07c4  nvstor - ok
10:23:11.0392 0x07c4  [ AD226D9879217AFE36EBBE9FA36F6048, A9F15A301414205060CFECD4984632F4993C9548D42405C55573305D9413C96F ] nvvad_WaveExtensible C:\Windows\system32\drivers\nvvad64v.sys
10:23:11.0408 0x07c4  nvvad_WaveExtensible - ok
10:23:11.0486 0x07c4  [ 8DA6939DF7D55222FC7B97C89487D15E, 69BF7571E15DF3785F421B4FAA25C10FA3278FD983F3EB76A9A294F1A3E3FDA5 ] nvvhci          C:\Windows\system32\DRIVERS\nvvhci.sys
10:23:11.0486 0x07c4  nvvhci - ok
10:23:11.0533 0x07c4  [ 6E1B8F7B9A0363AD0B3779BAB2E8E417, 5CDFC63B7A946E040FAA82DFEDE016F8DD228247A8C36813441413DF901E46B0 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
10:23:11.0548 0x07c4  nv_agp - ok
10:23:11.0579 0x07c4  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
10:23:11.0611 0x07c4  ohci1394 - ok
10:23:11.0704 0x07c4  [ EDA754369622042DEB8C1A9CEDE0244A, FCDF4E0D4C06BD284803B070C1AA45F95316E1B239D063EB2EF352948FF2B224 ] ose64           c:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:23:11.0735 0x07c4  ose64 - ok
10:23:11.0923 0x07c4  [ FE9C0029E1AF26350D9985D00520E5C8, 967079CCF7B2CBD4B48C9F076675C26AF93A1CEC26C96811F279414E34004EE6 ] osppsvc         c:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
10:23:12.0141 0x07c4  osppsvc - ok
10:23:12.0188 0x07c4  [ 960C6B84BFBD0839B0F33204CFF5FB56, ED7769C8BEEFC0DE2E301F1AE876D80EA5F7FCB477E1C12C9CEE053199677AFA ] ossrv           C:\Windows\system32\drivers\ctoss2k.sys
10:23:12.0203 0x07c4  ossrv - ok
10:23:12.0250 0x07c4  [ 7EA6044AB974F06410A51FCC7856B8BB, EC0C9505B42C123E506A175ECCDD2FB2D84F2DEFDF50624B2F1CC7BDB76AE193 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
10:23:12.0297 0x07c4  p2pimsvc - ok
10:23:12.0344 0x07c4  [ 79DB2B358BF0B152F15D1C5A525233BD, 374D9E8D7FBBC3EB14BDC651378120FCB075A36404F1E76A3F291F89CD5C3362 ] p2psvc          C:\Windows\system32\p2psvc.dll
10:23:12.0391 0x07c4  p2psvc - ok
10:23:12.0422 0x07c4  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport         C:\Windows\system32\drivers\parport.sys
10:23:12.0437 0x07c4  Parport - ok
10:23:12.0484 0x07c4  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
10:23:12.0484 0x07c4  partmgr - ok
10:23:12.0531 0x07c4  [ 5EF9936FC08352660CFDF17F2BE39BA1, 65D4628478BA3DDB19758B3EBE638B8A083D78CAE3E3550AC5E0129BBE8B6268 ] PcaSvc          C:\Windows\System32\pcasvc.dll
10:23:12.0562 0x07c4  PcaSvc - ok
10:23:12.0593 0x07c4  [ A1AD4E64D923498F9D03641E77176F52, 81D661290154EE5FA883F79549B9557D7A42BE85C48487C0E4241E5EEFBCA180 ] pci             C:\Windows\system32\drivers\pci.sys
10:23:12.0609 0x07c4  pci - ok
10:23:12.0640 0x07c4  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
10:23:12.0656 0x07c4  pciide - ok
10:23:12.0687 0x07c4  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
10:23:12.0718 0x07c4  pcmcia - ok
10:23:12.0734 0x07c4  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw             C:\Windows\system32\drivers\pcw.sys
10:23:12.0749 0x07c4  pcw - ok
10:23:12.0796 0x07c4  [ 70C2C4D9EB212093F3F88F5247AF057E, 3A82D82B4C35EDC86CA326A5D8D03654ED8692400FC78D8129DFEDA8C3B331CB ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
10:23:12.0859 0x07c4  PEAUTH - ok
10:23:12.0921 0x07c4  [ C59E17D5E30972ECA28A72004795AEA7, 24CE4698F578BB6BE51101BA083C5E4A6A1AA449439C125BA3E5793E54260525 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
10:23:12.0999 0x07c4  PeerDistSvc - ok
10:23:13.0077 0x07c4  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
10:23:13.0093 0x07c4  PerfHost - ok
10:23:13.0171 0x07c4  [ BC5F8C5C7ACCD0B884FCB8B67616F537, 5C99E9D7E7095CED52B1F5F4A569E54F124602C573DD2B25731E0D57FDA22A27 ] pla             C:\Windows\system32\pla.dll
10:23:13.0280 0x07c4  pla - ok
10:23:13.0342 0x07c4  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
10:23:13.0373 0x07c4  PlugPlay - ok
10:23:13.0405 0x07c4  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
10:23:13.0420 0x07c4  PNRPAutoReg - ok
10:23:13.0451 0x07c4  [ 7EA6044AB974F06410A51FCC7856B8BB, EC0C9505B42C123E506A175ECCDD2FB2D84F2DEFDF50624B2F1CC7BDB76AE193 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
10:23:13.0467 0x07c4  PNRPsvc - ok
10:23:13.0514 0x07c4  [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
10:23:13.0561 0x07c4  PolicyAgent - ok
10:23:13.0592 0x07c4  [ F249779586148090EF90EFC697E4FE97, AD0ECD98307595C3C0D4397A8C87327198F4E7C8003063D36E28023016168CEC ] Power           C:\Windows\system32\umpo.dll
10:23:13.0623 0x07c4  Power - ok
10:23:13.0670 0x07c4  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
10:23:13.0701 0x07c4  PptpMiniport - ok
10:23:13.0748 0x07c4  [ 626DAA3AFB2CD08CD21D9DBC5DD28134, 3BC9FE2577E633FA0040B5B8EBC668F1FB4B990D68ABB24E38D630C234479A4E ] Processor       C:\Windows\system32\drivers\processr.sys
10:23:13.0779 0x07c4  Processor - ok
10:23:13.0810 0x07c4  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc         C:\Windows\system32\profsvc.dll
10:23:13.0841 0x07c4  ProfSvc - ok
10:23:13.0873 0x07c4  [ 3E71928C087FBB3B23A4D816C843B538, DCF9D744FE1B1CF47EC2870B44C852846C221D604B50DE8ADF79F60629A92A55 ] ProtectedStorage C:\Windows\system32\lsass.exe
10:23:13.0888 0x07c4  ProtectedStorage - ok
10:23:13.0935 0x07c4  [ 4CE827A5433451551E99C2C1D20E4A43, B2E0806BB5C32A9126584941EE92526BFD45BB9EE18D7E598A2FFE7AAB495930 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
10:23:13.0966 0x07c4  Psched - ok
10:23:14.0091 0x07c4  [ 543A4EF0923BF70D126625B034EF25AF, 9CC82C5221F11850419A796D48D5452B3DEE0C8E8E85A818F4AAA869673F9740 ] PSI_SVC_2       c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
10:23:14.0107 0x07c4  PSI_SVC_2 - ok
10:23:14.0185 0x07c4  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
10:23:14.0247 0x07c4  ql2300 - ok
10:23:14.0263 0x07c4  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
10:23:14.0278 0x07c4  ql40xx - ok
10:23:14.0309 0x07c4  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE           C:\Windows\system32\qwave.dll
10:23:14.0341 0x07c4  QWAVE - ok
10:23:14.0356 0x07c4  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
10:23:14.0387 0x07c4  QWAVEdrv - ok
10:23:14.0419 0x07c4  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
10:23:14.0450 0x07c4  RasAcd - ok
10:23:14.0497 0x07c4  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
10:23:14.0528 0x07c4  RasAgileVpn - ok
10:23:14.0559 0x07c4  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto         C:\Windows\System32\rasauto.dll
10:23:14.0590 0x07c4  RasAuto - ok
10:23:14.0637 0x07c4  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
10:23:14.0668 0x07c4  Rasl2tp - ok
10:23:14.0715 0x07c4  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
10:23:14.0777 0x07c4  RasMan - ok
10:23:14.0809 0x07c4  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
10:23:14.0855 0x07c4  RasPppoe - ok
10:23:14.0871 0x07c4  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
10:23:14.0902 0x07c4  RasSstp - ok
10:23:14.0949 0x07c4  [ 6DB20EF6CAD4356B785A061071FA4ECC, FAB7B6A1FEB6C7861D3655058EB55013A255C5FA569ED20F257626A2E5F121CF ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
10:23:14.0980 0x07c4  rdbss - ok
10:23:15.0011 0x07c4  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
10:23:15.0043 0x07c4  rdpbus - ok
10:23:15.0058 0x07c4  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
10:23:15.0105 0x07c4  RDPCDD - ok
10:23:15.0136 0x07c4  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
10:23:15.0167 0x07c4  RDPDR - ok
10:23:15.0167 0x07c4  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
10:23:15.0214 0x07c4  RDPENCDD - ok
10:23:15.0230 0x07c4  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
10:23:15.0261 0x07c4  RDPREFMP - ok
10:23:15.0292 0x07c4  [ 7A8015F4CB7774537843464B4A108DD1, C25F87DFD020C7AEB47110CE1A2AD8B202D96B2B1535D206BC07943C0E97D4D4 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
10:23:15.0308 0x07c4  RdpVideoMiniport - ok
10:23:15.0355 0x07c4  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
10:23:15.0386 0x07c4  RDPWD - ok
10:23:15.0448 0x07c4  [ F4287A980C0AA41DE3073F053E5EA73C, 04A386884DE32C6813486FD2D8FD9B9B275758CE5354459D8862A60E7F134833 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
10:23:15.0464 0x07c4  rdyboost - ok
10:23:15.0511 0x07c4  [ 0301EEE83B03229F555C6F8025FB5540, 3ABBA482E59FF9FC831A0FEA75A8C937BAE5077108A0EB3F89205C72FEDC2CD9 ] RemoteAccess    C:\Windows\System32\mprdim.dll
10:23:15.0542 0x07c4  RemoteAccess - ok
10:23:15.0573 0x07c4  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
10:23:15.0604 0x07c4  RemoteRegistry - ok
10:23:15.0635 0x07c4  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
10:23:15.0667 0x07c4  RpcEptMapper - ok
10:23:15.0698 0x07c4  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
10:23:15.0729 0x07c4  RpcLocator - ok
10:23:15.0776 0x07c4  [ 5F3EB8162C7289C576BA23730193FB6A, 2D628832AF0BA61B1EB70A5070C71FAE8ECE0F6E136399B94BB38045CD040B3E ] RpcSs           C:\Windows\system32\rpcss.dll
10:23:15.0807 0x07c4  RpcSs - ok
10:23:15.0854 0x07c4  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
10:23:15.0869 0x07c4  rspndr - ok
10:23:15.0947 0x07c4  [ CD560A420015D36CBBCC0CD1D972E298, E776970A00DA0393CC8340E01C1833F3D822CF4C844E8B7F9A314DB69E9A9F8C ] RTL8167         C:\Windows\system32\DRIVERS\Rt64win7.sys
10:23:15.0979 0x07c4  RTL8167 - ok
10:23:16.0010 0x07c4  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
10:23:16.0041 0x07c4  s3cap - ok
10:23:16.0057 0x07c4  [ 3E71928C087FBB3B23A4D816C843B538, DCF9D744FE1B1CF47EC2870B44C852846C221D604B50DE8ADF79F60629A92A55 ] SamSs           C:\Windows\system32\lsass.exe
10:23:16.0072 0x07c4  SamSs - ok
10:23:16.0119 0x07c4  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
10:23:16.0119 0x07c4  sbp2port - ok
10:23:16.0166 0x07c4  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
10:23:16.0213 0x07c4  SCardSvr - ok
10:23:16.0244 0x07c4  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
10:23:16.0259 0x07c4  scfilter - ok
10:23:16.0337 0x07c4  [ F8EA90B3EB37EDD78E58C1AD2160136B, 4C0584083A1036400A1C30EEA47D0AF7C4D2ECF314F81DB1EF8F302B97B83796 ] Schedule        C:\Windows\system32\schedsvc.dll
10:23:16.0415 0x07c4  Schedule - ok
10:23:16.0462 0x07c4  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc     C:\Windows\System32\certprop.dll
10:23:16.0478 0x07c4  SCPolicySvc - ok
10:23:16.0525 0x07c4  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
10:23:16.0571 0x07c4  SDRSVC - ok
10:23:16.0603 0x07c4  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
10:23:16.0618 0x07c4  secdrv - ok
10:23:16.0649 0x07c4  [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon        C:\Windows\system32\seclogon.dll
10:23:16.0681 0x07c4  seclogon - ok
10:23:16.0696 0x07c4  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\System32\sens.dll
10:23:16.0743 0x07c4  SENS - ok
10:23:16.0759 0x07c4  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
10:23:16.0790 0x07c4  SensrSvc - ok
10:23:16.0821 0x07c4  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
10:23:16.0837 0x07c4  Serenum - ok
10:23:16.0883 0x07c4  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\DRIVERS\serial.sys
10:23:16.0915 0x07c4  Serial - ok
10:23:16.0946 0x07c4  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\drivers\sermouse.sys
10:23:16.0946 0x07c4  sermouse - ok
10:23:16.0993 0x07c4  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
10:23:17.0024 0x07c4  SessionEnv - ok
10:23:17.0039 0x07c4  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
10:23:17.0071 0x07c4  sffdisk - ok
10:23:17.0086 0x07c4  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
10:23:17.0086 0x07c4  sffp_mmc - ok
10:23:17.0133 0x07c4  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
10:23:17.0164 0x07c4  sffp_sd - ok
10:23:17.0164 0x07c4  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
10:23:17.0180 0x07c4  sfloppy - ok
10:23:17.0211 0x07c4  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
10:23:17.0273 0x07c4  SharedAccess - ok
10:23:17.0305 0x07c4  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
10:23:17.0351 0x07c4  ShellHWDetection - ok
10:23:17.0398 0x07c4  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
10:23:17.0398 0x07c4  SiSRaid2 - ok
10:23:17.0414 0x07c4  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
10:23:17.0429 0x07c4  SiSRaid4 - ok
10:23:17.0461 0x07c4  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
10:23:17.0507 0x07c4  Smb - ok
10:23:17.0539 0x07c4  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
10:23:17.0570 0x07c4  SNMPTRAP - ok
10:23:17.0601 0x07c4  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr           C:\Windows\system32\drivers\spldr.sys
10:23:17.0648 0x07c4  spldr - ok
10:23:17.0695 0x07c4  [ 8003D39B386EDCCFB08DC21AACC0683A, 99D6A4DBE810335A69AE3053DC4B6AAC267639AD7F9C568431FA0714F6E71F30 ] Spooler         C:\Windows\System32\spoolsv.exe
10:23:17.0757 0x07c4  Spooler - ok
10:23:17.0897 0x07c4  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
10:23:18.0053 0x07c4  sppsvc - ok
10:23:18.0085 0x07c4  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
10:23:18.0131 0x07c4  sppuinotify - ok