Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93083 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Just looking for a 2nd opinion...... [Solved]

Trojan:Win32/Dynamer!dtc

  • This topic is locked This topic is locked
29 replies to this topic

#1 Nub

Nub

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 12 March 2017 - 06:30 AM

It would appear I have somehow got infected with Trojan Win32 Dynamer!dtc according to this program's scan(though the program itself doesn't tell me WHICH file it is that's infected with this malware......silly Microsoft scanner....): Trojan_Win32_Dynamer_dtc.png

 

...which might explain why KillingFloor.exe is deleting itself presumably because it *failed* to do its job so it deletes itself to make sure I won't notice.....but obviously will since I go on that often.......and the fact that KIS 2016 popped up many times regarding this fact but will only pop up if it themselves deleted/quarantined it and NOT the file delete itself or from some other means:

qwd.png

 

So yeah...it must have been a file I downloaded recently or something or maybe from a previous session that is has become dormant until now(not that I doubt the help of the malware removal specialist that helped me - you did great! :D Perhaps it was just being dormant and hiding itself? idk...maybe I shouldn't have pointed back to this...).....and no this time I haven't been looking at trainers... :P

 

So yeah, I've re-scanned with KIS 2016, Malwarebytes Anti-Malware, SUPERAntiSpyware and even Spybot Search and Destroy.....and followed this guide here: https://dl.packetsto...are-removal.pdf...which means I've done TDSSKiller, another but quicker scan of Malwarebytes(as before I ran a *complete* scan over a threat scan and this guide points to a threat scan on the newer malwarebytes version) and Hitman Pro. Didn't need to do step 3 because it says I don't need to if the above programs ran fine... And have ran Ccleaner, got KeyScambler for a while now, so should be good without needing to re-changing passwords again and I don't have any restore points as the service itself is disabled....

 

So yeah, it started basically a few days ago...if there's anything I missed out that you would like to know, ask and you shall be given! B)

 

EDIT: Nope, KIS 2016 still deletes it on the account of *suspicious* activity..... Even uploaded the file to virustotal.com and that says it's clean......the program must be injecting to the exe file *upon* launch or during execution as that's when KIS 2016 detects the changes and deletes the file....... Otherwise, I'm sure if I scanned the exe file with all my suites (KIS, Malwarebytes, SuperAntiSpyware, Spybot and even virustotal) BEFORE executing it, it would have at least flagged up as such......or it could also be a false positive and KIS 2016 being too overprotective.....but then again.....that Trojan:Win32/Dynamer!dtc that Microsoft's scanner picked up and *partially removed* doesn't sound promising....would have been nice if it stated the location of said infected file...and perhaps a log of what it did.....but nope no log files provided....

 

I was just in a game too....and then suddenly I crashed to the desktop thinking "What the hell?" hahahaha, then a popup from KIS stated the game executable did something suspicious that warranted it force deleting and crashing the game I was having....and if you want, here's a more recent(as it just happened a few minutes ago...) screenshot of reports:

recent.png

 

Hmmmmmm..........

 

I guess I'll have to postpone my work on that game then until this is solved....

 

EDIT2: I've move the exe file one folder above so I don't have to verify the entire game if all it's missing is just the executable file for the game(I can just copy it from there and paste it into the System directory whenever it gets deleted.....though a more ideal solution would be to stop this auto delete issue whether it be from KIS or left over *trojan*....)(I've also modded the game a fair bit so I don't want the verification to override them with the stock files.....); so far nothing's happened to that file that got moved up....exact same file, just not in the System folder anymore, one folder up, so in the game root directory folder. And have also left it there for a couple of days there and hasn't deleted itself *yet*.....so it does appear to be targeting this specific file at this specific location.........maybe I could try rename the file? But then I won't be able to play or do any of my work on it as steam would think it's still not there and redownload the file again which will result(unless cleaned up 100%) in the above actions as described......and no, I can't really work on if I were to just execute the file itself without steam as you *need* steam for the perk and achievements......

 

EDIT3: Hmmmm...I did a test by making a blank exe file of the same name (so zero bytes) and that got deleted upon next turn on today which I did yesterday. So I've made another zero byte(today) same name file exe and have tried to do some more tests with it.....so left it as is without executing the blank file: restarted - file still there; shutdown and then turn back on - file still there; boot into safe mode and then restart - file still there(also whilst I was in that mode, I did another scan with the Microsoft scanner and the same malware got picked up and as was shown last time - *partially removed* with no further information on which file(s) it/they were - so looks like even in safe mode that program can't remove this trojan completely....); log off and login - file still there....

 

I checked my Services thingy and noticed this:

qwd1.png

 

As I've not seen this before in the services, I don't think that's supposed to happen, right....? Well at least the description part of it...

 

And another strange service which I don't recall seeing before in a usual windows install is this:

qwd1.png

 

The path to the executable is blank........even running the services program as admin, still shows ....blank..... Now I googled it up and *apparently* it's to do with Kaspersky, but Kaspersky already has one named klvssbridge64 as shown here:

qwd1.png

 

Well at least I'm guessing this is the one for Kaspersky and ...maybe the other one too? But why is the path to executable blank then and not pointing to a file in the same directory of Kaspersky install?

 

Ok so anyways....did another run, executing the blank file, and then log off, and or restart and file is still there....so that would mean it only happens if the game was *executed* correctly.........hmmm, perhaps this mysterious event is targeting a specific file in memory and trying to alter it somehow whilst in memory and if that doesn't work - ie nothing happens and KIS 2016 hasn't picked up anything suspicious, it then deletes itself or at least the executable game file....but if it *does* work(but not to the point of *successfully* pulling it off because ...), KIS 2016 picks it up and blocks it anyways and deletes the file.

 

Hmmmm, I'm guessing it either deletes itself upon shutdown *or* it deletes itself upon booting up...not sure which and I am not sure how to find this out either...


Edited by Nub, 13 March 2017 - 03:32 AM.

    Advertisements

Register to Remove


#2 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 13 March 2017 - 08:23 AM

:welcome:

 

What we can do is have you run a couple of scans and post the logs and lets see whats going on.  At this point dont run any other programs and change anything as it may interfere with out analysis. From what I have been reading there may be issues when running killingfloor. It also looks like the files you posted about are related to Kaspersky .

 

All of our tools and scanners run more efficiently when run from the desktop
 
 

1QYkxTZ.jpg Please download aswMBR to your DESKTOP <<<<<
 
  •  
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
 
 
I just want to see the report....Please Do Not Fix Anything
 
============================================================================
 
 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP<<<<<<
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start --> Computer (right click) --> Properties
 
FRST_zps5d956a1a.jpg
 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
 

 



 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#3 Nub

Nub

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 14 March 2017 - 02:18 AM

:welcome:

 

What we can do is have you run a couple of scans and post the logs and lets see whats going on.  At this point dont run any other programs and change anything as it may interfere with out analysis. From what I have been reading there may be issues when running killingfloor. It also looks like the files you posted about are related to Kaspersky .

Hiya!

 

It didn't have these issues before...... Yes if that's what you say about those screenshots on edit 3.....but what about the one without an valid path?

 

 


1QYkxTZ.jpg Please download aswMBR to your DESKTOP <<<<<
 
  •  
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
 
 
I just want to see the report....Please Do Not Fix Anything

It appears to crash upon scanning a specific file(tried it desktop as well as in the default download folder - same result):

 

qwd1.png

 

In this case, the file is Audiosrv.dll.... and a google search and according to this, appears to be a valid safe file...

 

 

Please download Farbar Recovery Scan Tool and save it to your DESKTOP<<<<<<
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start --> Computer (right click) --> Properties
 
FRST_zps5d956a1a.jpg
 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.

Attached are the two files you requested.Attached File  Addition.txt   62.33KB   313 downloadsAttached File  FRST.txt   43.28KB   262 downloads



#4 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 14 March 2017 - 04:11 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-03-2017
Ran by Manectric (administrator) on RAIKOU (14-03-2017 16:05:26)
Running from C:\Users\Electrike\Downloads
Loaded Profiles: Manectric & Electrike (Available Profiles: Manectric & Electrike)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
() C:\Program Files\GIGABYTE\SmartManagerV3\ElevateService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
() C:\Program Files\Smart Update\Update_Service.exe
() C:\Program Files (x86)\Windscribe\WindscribeService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
(Ruiware) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
(Razer USA Ltd) C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
(QFX Software Corporation) C:\Program Files (x86)\KeyScrambler\KeyScrambler.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(QFX Software Corporation) C:\Program Files (x86)\KeyScrambler\x64\KeyScrambler.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6064.exe
(Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SandboxieRpcSs.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SandboxieDcomLaunch.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SandboxieCrypto.exe
(Valve Corporation) E:\Steam\Steam.exe
(Valve Corporation) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) E:\Sandbox\Steambox\drive\C\S\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) E:\Sandbox\Steambox\drive\C\S\bin\cef\cef.win7\steamwebhelper.exe
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\32\SbieSvc.exe
(Valve Corporation) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
() C:\Users\Electrike\Downloads\Idle Master\IdleMaster.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Users\Electrike\Downloads\Idle Master\steam-idle.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
(Valve Corporation) E:\Sandbox\Steambox\drive\C\S\bin\cef\cef.win7\steamwebhelper.exe
(AVAST Software) C:\Users\Electrike\Desktop\aswMBR.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3276040 2014-05-21] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13675736 2014-08-14] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1396592 2014-09-01] (Realtek Semiconductor)
HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [508656 2012-09-01] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [Razer Naga Driver] => C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe [953232 2011-11-16] (Razer USA Ltd)
HKLM-x32\...\Run: [KeyScrambler] => C:\Program Files (x86)\KeyScrambler\keyscrambler.exe [515600 2016-08-01] (QFX Software Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2014-06-28] (Intel Corporation)
HKLM Group Policy restriction on software: C:\Windows\System32\VSSAdmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.WSF <====== ATTENTION
HKLM Group Policy restriction on software: *.JSE <====== ATTENTION
HKLM Group Policy restriction on software: *.JS <====== ATTENTION
HKLM Group Policy restriction on software: %appdata% <====== ATTENTION
HKLM Group Policy restriction on software: *.WSH <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile% <====== ATTENTION
HKLM Group Policy restriction on software: *.VBE <====== ATTENTION
HKLM Group Policy restriction on software: *.VBS <====== ATTENTION
HKLM\...\Policies\Explorer: [NoThumbnailCache] 1
HKLM\...\Policies\Explorer: [DisableThumbnailsOnNetworkFolders] 1
HKLM\...\Policies\Explorer: [NoCDBurning] 1
HKLM\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [799376 2016-12-14] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7946144 2017-02-16] (SUPERAntiSpyware)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4015216 2016-12-15] (Tonec Inc.)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [9161720 2016-12-23] (Binary Fortress Software)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1231240 2016-11-14] (Ruiware)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\Run: [SandboxieControl] => C:\Program Files\Sandboxie\SbieCtrl.exe [799376 2016-12-14] (Sandboxie Holdings, LLC)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [9161720 2016-12-23] (Binary Fortress Software)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1231240 2016-11-14] (Ruiware)
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7946144 2017-02-16] (SUPERAntiSpyware)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> 
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [170360 2017-02-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148016 2017-02-10] (NVIDIA Corporation)
IFEO\taskmgr.exe: [Debugger] "C:\PROGRAM FILES (X86)\PROCESSEXPLORER\PROCEXP.EXE"
ShellIconOverlayIdentifiers: [   IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\..\Interfaces\{0326CB5A-1274-4DD9-8EB4-1BE8C95AE083}: [NameServer] 8.8.8.8,203.12.160.35
Tcpip\..\Interfaces\{4F65E33E-CBEB-441C-B813-D5B11989BAD0}: [DhcpNameServer] 10.110.234.1
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://localoem.msn.com/?pc=SBJB
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://localoem.msn.com/?pc=SBJB
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=620947&OCID=AVRES007&pc=UE06
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://localoem.msn.com/?pc=SBJB
SearchScopes: HKLM -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
Toolbar: HKLM - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\x64\IEExt\ie_plugin.dll [2016-12-02] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {001032CB-B0AC-4F2C-A650-AD4B2B26E5DA} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\IEExt\ie_plugin.dll [2016-12-02] (AO Kaspersky Lab)
 
FireFox:
========
FF DefaultProfile: ipvqxq4h.default
FF ProfilePath: C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default [2017-03-12]
FF Extension: (HTTPS-Everywhere) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\https-everywhere@eff.org [2016-01-22]
FF Extension: (TrafficLight) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\trafficlight@bitdefender.com.xpi [2016-01-22]
FF Extension: (Flagfox) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}.xpi [2016-01-22]
FF Extension: (NoScript) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2016-06-11]
FF Extension: (No Name) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2017-03-11] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_ACF0E80077C511E59DED005056C00008@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\FFExt\light_plugin_firefox\addon.xpi [2016-12-02]
FF HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2017-01-26]
FF HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Manectric\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Manectric\AppData\Roaming\IDM\idmmzcc5 [2017-02-24] [not signed]
FF HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Electrike\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Electrike\AppData\Roaming\IDM\idmmzcc5 [2017-02-12] [not signed]
FF HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-14] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-14] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-30] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-04-30] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-01-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-01-26] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-24] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR HKLM\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-01-26]
CHR HKLM-x32\...\Chrome\Extension: [lpeeaghdjmhlakojjcgfdhgcejdaefmi] - hxxps://chrome.google.com/webstore/detail/lpeeaghdjmhlakojjcgfdhgcejdaefmi
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2017-01-26]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-02-16] (SUPERAntiSpyware.com)
R2 AVP16.0.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe [236928 2015-12-22] (AO Kaspersky Lab)
R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [5098008 2016-12-23] (Binary Fortress Software)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [229648 2016-10-06] (EasyAntiCheat Ltd)
R2 ElevateService; C:\Program Files\GIGABYTE\SmartManagerV3\ElevateService.exe [14336 2014-10-29] () [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [18584 2014-10-10] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [344168 2015-10-15] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-02-01] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-04-30] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [177376 2016-08-12] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [154584 2014-04-30] (Intel Corporation)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\x64\vssbridge64.exe [152488 2015-12-22] (AO Kaspersky Lab)
S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265936 2014-08-19] ()
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-02-10] (NVIDIA Corporation)
S4 PAExec; C:\Windows\PAExec.exe [189112 2017-02-24] (Power Admin LLC)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [197776 2016-12-14] (Sandboxie Holdings, LLC)
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10351856 2016-12-15] (TeamViewer GmbH)
R2 Update_Service; C:\Program Files\Smart Update\Update_Service.exe [135680 2016-11-02] () [File not signed]
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-09-02] (Microsoft Corporation)
R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [53352 2016-12-08] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3817168 2014-08-19] (Intel® Corporation)
S2 AVP16.0.0; no ImagePath
S4 fsssvc; no ImagePath
S3 Futuremark SystemInfo Service; no ImagePath
S4 TBS; %SystemRoot%\System32\tbssvc.dll [X]
S3 vssbrigde64; no ImagePath
S4 wlidsvc; no ImagePath
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 btmaux; C:\Windows\System32\DRIVERS\btmaux.sys [141624 2014-05-14] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\System32\DRIVERS\btmhsf.sys [1424184 2014-05-14] (Motorola Solutions, Inc.)
S3 btmlehid; C:\Windows\system32\drivers\btmlehid.sys [83256 2014-02-04] (Motorola Solutions, Inc.)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [389816 2015-07-06] (Kaspersky Lab ZAO)
S3 fssfltr; no ImagePath
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [30360 2014-10-09] (Intel Corporation)
R3 ibtusb; C:\Windows\System32\DRIVERS\ibtusb.sys [210376 2014-07-04] (Intel Corporation)
R3 KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [224720 2015-08-19] (QFX Software Corporation)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-09-11] (Kaspersky Lab ZAO)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [53432 2015-06-06] (Kaspersky Lab ZAO)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [79240 2015-12-01] (AO Kaspersky Lab)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [78200 2015-12-02] (AO Kaspersky Lab)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [182152 2015-12-11] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [236432 2016-12-02] (AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP16.0.1\Bases\klids.sys [182360 2017-03-14] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1001304 2016-08-25] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [50776 2016-04-29] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [52608 2015-11-11] (AO Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [41648 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45960 2015-12-07] (AO Kaspersky Lab)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-06-11] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [110424 2016-08-25] (AO Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [194440 2015-12-03] (AO Kaspersky Lab)
R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [140672 2016-03-10] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [118272 2014-04-30] (Intel Corporation)
R3 NETwNs64; C:\Windows\System32\DRIVERS\Netwsw02.sys [3438872 2015-02-22] (Intel Corporation)
R3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [429272 2014-10-22] (Realsil Semiconductor Corporation)
R3 RzSynapse; C:\Windows\System32\DRIVERS\RzSynapse.sys [126464 2011-11-15] (Razer USA Ltd)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-23] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [205968 2016-12-14] (Sandboxie Holdings, LLC)
S1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [131144 2017-01-16] (Oracle Corporation)
R2 {687703DE-DC6D-4649-892B-B8497854A6AB}; C:\Program Files (x86)\CyberLink\PowerDVD15\Common\NavFilter\000.fcl [29896 2015-10-05] (CyberLink Corp.)
U4 npcap_wifi; no ImagePath
U3 aswMBR; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-14 16:05 - 2017-03-14 16:05 - 00024718 _____ C:\Users\Electrike\Downloads\FRST.txt
2017-03-14 16:04 - 2017-03-14 16:05 - 00000000 ____D C:\FRST
2017-03-14 16:04 - 2017-03-14 16:04 - 02424832 _____ (Farbar) C:\Users\Electrike\Downloads\FRST64.exe
2017-03-14 15:44 - 2017-03-14 15:44 - 05198336 _____ (AVAST Software) C:\Users\Electrike\Desktop\aswMBR.exe
2017-03-13 20:15 - 2017-03-13 20:16 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\vlc
2017-03-13 20:15 - 2017-03-13 20:15 - 00001076 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-03-13 20:15 - 2017-03-13 20:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-03-13 20:15 - 2017-03-13 20:15 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2017-03-13 20:10 - 2017-03-13 20:11 - 30533688 _____ C:\Users\Electrike\Downloads\vlc-2.2.4-win32.exe
2017-03-13 20:06 - 2017-03-13 20:06 - 00000000 ____D C:\Users\Electrike\Downloads\f
2017-03-13 18:03 - 2017-03-13 18:03 - 00170497 _____ C:\Users\Electrike\Downloads\WO-089055.pdf
2017-03-13 14:50 - 2017-03-13 16:47 - 00233482 _____ C:\Windows\ntbtlog.txt
2017-03-13 09:15 - 2017-03-13 09:16 - 14079474 _____ C:\Users\Electrike\Downloads\f.zip
2017-03-13 07:08 - 2017-03-14 00:05 - 00000000 ____D C:\Users\Electrike\Downloads\SAT
2017-03-13 05:47 - 2017-03-13 05:47 - 00335960 _____ C:\Windows\system32\FNTCACHE.DAT
2017-03-13 05:47 - 2017-03-13 05:47 - 00084896 _____ C:\Users\Electrike\AppData\Local\GDIPFONTCACHEV1.DAT
2017-03-12 22:05 - 2017-03-12 22:05 - 00007662 _____ C:\Users\Manectric\AppData\Local\Resmon.ResmonCfg
2017-03-12 19:48 - 2017-03-12 19:53 - 00000000 ____D C:\ProgramData\HitmanPro
2017-03-12 19:41 - 2017-03-12 19:43 - 11581544 _____ (SurfRight B.V.) C:\Users\Electrike\Downloads\HitmanPro_x64.exe
2017-03-12 19:35 - 2017-03-12 19:36 - 00230058 _____ C:\TDSSKiller.3.1.0.12_12.03.2017_19.35.05_log.txt
2017-03-12 19:33 - 2017-03-12 19:34 - 04656523 _____ C:\Users\Electrike\Downloads\tdsskiller.zip
2017-03-12 19:33 - 2017-03-12 19:33 - 00000354 _____ C:\TDSSKiller.2.8.16.0_12.03.2017_19.33.34_log.txt
2017-03-12 19:33 - 2016-11-07 07:10 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Electrike\Downloads\TDSSKiller.exe
2017-03-10 23:10 - 2017-03-12 16:31 - 00000000 ____D C:\Users\Electrike\Downloads\Idle Master
2017-03-03 17:44 - 2017-03-03 17:44 - 00000202 _____ C:\Users\Electrike\Desktop\Fiends of Imprisonment.url
2017-03-03 17:43 - 2017-03-03 17:43 - 00000202 _____ C:\Users\Electrike\Desktop\Break Into Zatwor.url
2017-02-24 22:05 - 2017-03-10 19:25 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\NVIDIA
2017-02-24 21:55 - 2017-02-24 21:55 - 00000000 ____D C:\Users\Electrike\AppData\Local\NVIDIA Corporation
2017-02-24 21:54 - 2017-02-24 21:54 - 00000000 ____D C:\Windows\SysWOW64\NV
2017-02-24 21:54 - 2017-02-24 21:54 - 00000000 ____D C:\Windows\system32\NV
2017-02-24 21:54 - 2017-02-24 21:54 - 00000000 ____D C:\Users\Manectric\AppData\Local\NVIDIA Corporation
2017-02-24 21:53 - 2017-03-14 11:48 - 00000000 ____D C:\ProgramData\NVIDIA
2017-02-24 21:53 - 2017-02-24 21:53 - 00003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-24 21:53 - 2017-02-24 21:53 - 00003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-24 21:53 - 2017-02-24 21:53 - 00003676 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-24 21:53 - 2017-02-24 21:53 - 00003500 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-24 21:53 - 2017-02-24 21:53 - 00003440 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-02-24 21:53 - 2017-02-24 21:53 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-02-24 21:53 - 2017-02-24 21:53 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-02-24 21:53 - 2017-02-10 08:52 - 00418752 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2017-02-24 21:53 - 2017-02-10 07:13 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-02-24 21:53 - 2017-02-10 06:57 - 07791217 _____ C:\Windows\system32\nvcoproc.bin
2017-02-24 21:53 - 2017-02-10 06:57 - 06403640 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2017-02-24 21:53 - 2017-02-10 06:57 - 02477504 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2017-02-24 21:53 - 2017-02-10 06:57 - 01764408 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2017-02-24 21:53 - 2017-02-10 06:57 - 00548288 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2017-02-24 21:53 - 2017-02-10 06:57 - 00393784 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2017-02-24 21:53 - 2017-02-10 06:57 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2017-02-24 21:53 - 2017-02-10 06:57 - 00071224 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2017-02-24 21:53 - 2017-01-26 08:13 - 00103936 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2017-02-24 21:53 - 2017-01-26 08:12 - 00326656 _____ C:\Windows\SysWOW64\vulkan-1.dll
2017-02-24 21:53 - 2017-01-26 08:09 - 00322560 _____ C:\Windows\system32\vulkan-1.dll
2017-02-24 21:53 - 2017-01-26 08:09 - 00118272 _____ C:\Windows\system32\vulkaninfo.exe
2017-02-24 21:52 - 2017-02-24 21:52 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-02-24 21:52 - 2017-02-10 08:52 - 40192056 _____ C:\Windows\system32\nvcompiler.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 34937280 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 28212280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 19110088 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 19006832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 16510160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 16398896 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 14674896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 14373824 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-02-24 21:52 - 2017-02-10 08:52 - 13377072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 11122912 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 11019704 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 09305984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 08990072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 04064088 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 03627064 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 03583560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 03187256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 01983424 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437866.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 01589696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437866.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 01051584 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00989120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00961080 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00912440 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00687224 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00611384 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00504104 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00500792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00492744 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00425288 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00408272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00153184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00131720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00042606 _____ C:\Windows\system32\nvinfo.pb
2017-02-24 21:52 - 2017-02-10 08:52 - 00039992 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys
2017-02-24 21:52 - 2017-02-10 08:52 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-02-24 21:52 - 2017-02-10 08:52 - 00000669 _____ C:\Windows\system32\nv-vk64.json
2017-02-24 20:24 - 2017-02-10 08:52 - 00514616 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2017-02-24 19:35 - 2017-02-24 19:35 - 00189112 _____ (Power Admin LLC) C:\Windows\PAExec.exe
2017-02-24 18:56 - 2017-02-10 08:52 - 00170360 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-02-24 18:56 - 2017-02-10 08:52 - 00148016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-02-24 18:29 - 2017-02-24 18:30 - 00001908 _____ C:\Windows\diagwrn.xml
2017-02-24 18:29 - 2017-02-24 18:30 - 00001908 _____ C:\Windows\diagerr.xml
2017-02-24 18:29 - 2017-02-24 18:29 - 00000000 ____D C:\$WINDOWS.~BT
2017-02-23 23:22 - 2017-02-23 23:22 - 00001928 _____ C:\Users\Public\Desktop\DOSBox 0.74.lnk
2017-02-23 23:22 - 2017-02-23 23:22 - 00000000 ____D C:\Users\Electrike\AppData\Local\DOSBox
2017-02-23 23:22 - 2017-02-23 23:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DOSBox-0.74
2017-02-23 23:22 - 2017-02-23 23:22 - 00000000 ____D C:\Program Files (x86)\DOSBox-0.74
2017-02-23 13:04 - 2017-02-23 13:04 - 00000000 ____D C:\Users\Electrike\Downloads\hw64_544
2017-02-22 21:19 - 2017-03-02 18:49 - 00000000 ____D C:\Users\Electrike\Documents\OpenXcom
2017-02-21 19:23 - 2017-02-21 19:27 - 00000650 _____ C:\Users\Electrike\Downloads\gfjydty.txt
2017-02-20 22:08 - 2017-02-20 23:31 - 00000000 ____D C:\Users\Manectric\Documents\OpenXcom
2017-02-20 22:08 - 2017-02-20 22:08 - 00000000 ____D C:\Users\Manectric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenXcom
2017-02-17 12:10 - 2017-03-14 16:02 - 00000518 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e4d34f86-8653-4a93-bc58-a1e3600e97f4.job
2017-02-17 12:10 - 2017-02-17 12:10 - 00003522 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task e4d34f86-8653-4a93-bc58-a1e3600e97f4
2017-02-12 18:35 - 2017-03-12 22:06 - 00000000 ____D C:\Users\Electrike\Downloads\b
2017-02-12 08:12 - 2017-02-12 08:12 - 00001270 _____ C:\Users\Manectric\Desktop\4K Video Downloader.lnk
2017-02-12 08:12 - 2017-02-12 08:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\4K Download
2017-02-12 08:12 - 2017-02-12 08:12 - 00000000 ____D C:\Program Files (x86)\4KDownload
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-14 16:04 - 2016-08-13 10:46 - 00029436 __RSH C:\ProgramData\ntuser.pol
2017-03-14 15:56 - 2016-08-08 20:01 - 00000000 ____D C:\Users\Manectric\AppData\Local\CrashDumps
2017-03-14 15:31 - 2016-03-06 10:01 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2017-03-14 15:04 - 2016-10-06 14:55 - 00000000 ____D C:\Users\Electrike\AppData\Local\DisplayFusion
2017-03-14 14:04 - 2016-08-25 12:59 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2017-03-14 12:41 - 2009-07-14 13:13 - 00847142 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-14 12:41 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\inf
2017-03-14 11:59 - 2016-06-26 17:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-14 11:57 - 2009-07-14 12:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-03-14 11:57 - 2009-07-14 12:45 - 00016976 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-03-14 11:52 - 2016-01-23 11:54 - 00000000 __SHD C:\Users\Electrike\IntelGraphicsProfiles
2017-03-14 11:48 - 2017-01-27 13:29 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2017-03-14 11:48 - 2009-07-14 13:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-14 00:05 - 2017-01-02 20:10 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\HLSW
2017-03-13 22:45 - 2015-01-12 17:26 - 00133910 _____ C:\Users\Electrike\Documents\%$##!!@.TXT
2017-03-13 20:03 - 2016-01-23 17:21 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-03-12 20:04 - 2016-08-22 14:14 - 00000000 ____D C:\Windows\pss
2017-03-12 20:03 - 2016-05-11 05:36 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\IDM
2017-03-12 20:03 - 2016-04-29 15:47 - 00000000 ____D C:\Users\Electrike\AppData\Local\CrashDumps
2017-03-12 20:03 - 2016-04-29 10:46 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\FileZilla
2017-03-12 20:03 - 2016-01-22 17:02 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-03-12 19:40 - 2016-01-22 19:04 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-03-12 18:41 - 2016-08-06 09:44 - 01125745 _____ C:\Users\Electrike\Downloads\Trainer for Oil Rush.zip
2017-03-12 17:41 - 2016-01-22 11:28 - 00008934 _____ C:\Windows\Sandboxie.ini
2017-03-12 15:16 - 2016-08-26 14:01 - 00001368 _____ C:\Users\Electrike\Desktop\Steam(_bot_3).lnk
2017-03-12 15:15 - 2016-06-25 10:18 - 00001301 _____ C:\Users\Electrike\Desktop\Steam(BFF18).lnk
2017-03-12 02:08 - 2016-07-08 13:09 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2017-03-12 02:08 - 2014-10-22 14:55 - 00000000 ____D C:\ProgramData\Temp
2017-03-12 01:43 - 2016-08-03 05:57 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-03-12 01:43 - 2016-03-06 09:48 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-03-10 23:13 - 2017-01-02 20:10 - 00000961 _____ C:\Users\Manectric\Desktop\HLSW.lnk
2017-03-10 23:13 - 2017-01-02 20:10 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HLSW
2017-03-10 23:13 - 2017-01-02 20:10 - 00000000 ___SD C:\Program Files (x86)\HLSW
2017-03-10 23:13 - 2017-01-02 20:10 - 00000000 ____D C:\Users\Manectric\AppData\Roaming\HLSW
2017-03-09 17:28 - 2017-01-30 17:19 - 00002242 ____H C:\Users\Electrike\Documents\Default.rdp
2017-03-05 21:06 - 2016-08-13 09:21 - 00003148 _____ C:\Windows\System32\Tasks\FRAPS
2017-03-05 21:06 - 2016-01-22 17:01 - 00000000 ____D C:\Fraps
2017-03-02 13:19 - 2016-01-22 11:24 - 00003832 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1453433047
2017-03-02 13:19 - 2016-01-22 11:24 - 00000000 ____D C:\Program Files (x86)\Opera
2017-03-01 23:49 - 2016-04-29 10:46 - 00001864 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2017-03-01 23:49 - 2016-04-29 10:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2017-03-01 23:49 - 2016-04-29 10:46 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2017-02-24 21:54 - 2016-01-19 10:59 - 00000000 __SHD C:\Users\Manectric\IntelGraphicsProfiles
2017-02-24 21:53 - 2014-10-22 14:26 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-02-24 21:53 - 2014-10-22 14:26 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-02-24 21:53 - 2009-07-14 11:20 - 00000000 ____D C:\Windows\Help
2017-02-24 20:38 - 2016-03-11 08:40 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-24 03:02 - 2016-01-22 20:48 - 00000000 ____D C:\Windows\system32\MRT
2017-02-24 03:00 - 2016-01-22 20:48 - 138020592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-02-23 23:22 - 2016-01-23 11:55 - 00000000 ____D C:\Users\Electrike\AppData\Local\VirtualStore
2017-02-20 02:01 - 2016-06-23 22:12 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\Skype
2017-02-18 20:01 - 2016-08-14 00:10 - 00079093 _____ C:\Users\Electrike\Desktop\Group Policy.msc
2017-02-17 12:10 - 2016-01-22 21:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2017-02-17 10:39 - 2016-01-22 21:44 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-02-15 12:31 - 2016-08-03 05:57 - 00003890 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-02-15 12:31 - 2016-03-06 10:01 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-02-15 12:31 - 2016-03-06 10:01 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-02-15 12:31 - 2016-03-06 10:01 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-02-15 12:31 - 2016-03-06 09:48 - 00000000 ____D C:\Windows\system32\Macromed
2017-02-12 18:35 - 2016-05-11 05:36 - 00000000 ____D C:\Users\Electrike\AppData\Roaming\DMCache
 
==================== Files in the root of some directories =======
 
2016-01-19 10:59 - 2016-01-22 17:20 - 0000020 _____ () C:\Users\Manectric\AppData\Roaming\db.ini
2017-03-12 22:05 - 2017-03-12 22:05 - 0007662 _____ () C:\Users\Manectric\AppData\Local\Resmon.ResmonCfg
2014-08-20 12:06 - 2014-08-20 12:06 - 0000020 _____ () C:\ProgramData\db.ini
2014-10-22 13:49 - 2014-10-22 13:49 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-03-04 13:45
 
==================== End of FRST.txt ============================
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2017
Ran by Manectric (14-03-2017 16:05:45)
Running from C:\Users\Electrike\Downloads
Windows 7 Professional Service Pack 1 (X64) (2016-01-19 02:59:00)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2798084944-1211984927-2140173799-500 - Administrator - Disabled)
Electrike (S-1-5-21-2798084944-1211984927-2140173799-1001 - Limited - Enabled) => C:\Users\Electrike
Guest (S-1-5-21-2798084944-1211984927-2140173799-501 - Limited - Disabled)
Manectric (S-1-5-21-2798084944-1211984927-2140173799-1000 - Administrator - Enabled) => C:\Users\Manectric
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kaspersky Internet Security (Enabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AS: Kaspersky Internet Security (Enabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
3DMark (HKLM-x32\...\Steam App 223850) (Version:  - Futuremark)
4K Video Downloader 4.2 (HKLM-x32\...\4K Video Downloader_is1) (Version: 4.2.1.2185 - Open Media LLC)
7 Days to Die (HKLM\...\Steam App 251570) (Version:  - The Fun Pimps)
8BitBoy (HKLM-x32\...\Steam App 296910) (Version:  - AwesomeBlade)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
AmCap version 9.01 (HKLM-x32\...\{0F45BECF-4C85-4301-A8A4-D2E2AE2A2C08}_is1) (Version: 9.01 - Gigabyte, Inc.)
Ansel (Version: 378.66 - NVIDIA Corporation) Hidden
Auslogics BoostSpeed 7 (HKLM-x32\...\{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1) (Version: 7.9.0.0 - Auslogics Labs Pty Ltd)
BioShock (HKLM-x32\...\Steam App 7670) (Version:  - 2K Boston)
BioShock Remastered (HKLM\...\Steam App 409710) (Version:  - 2K Boston)
Blender (HKLM\...\{437221A8-91D1-42A0-9E04-0AD64B502374}) (Version: 2.78.1 - Blender Foundation)
Break Into Zatwor (HKLM\...\Steam App 395980) (Version:  - Zonitron Productions)
Breakout Invaders (HKLM-x32\...\Steam App 366700) (Version:  - DreamsSoftGames)
Broforce (HKLM\...\Steam App 274190) (Version:  - Free Lives)
Canon Easy-PhotoPrint EX - Additional Materials DL_AN1 (HKLM-x32\...\Easy-PhotoPrint EX - DL_AN1) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_AN2 (HKLM-x32\...\Easy-PhotoPrint EX - DL_AN2) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_AN3 (HKLM-x32\...\Easy-PhotoPrint EX - DL_AN3) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_AN4 (HKLM-x32\...\Easy-PhotoPrint EX - DL_AN4) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_AN5 (HKLM-x32\...\Easy-PhotoPrint EX - DL_AN5) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_FA1 (HKLM-x32\...\Easy-PhotoPrint EX - DL_FA1) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_FA2 (HKLM-x32\...\Easy-PhotoPrint EX - DL_FA2) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_FA3 (HKLM-x32\...\Easy-PhotoPrint EX - DL_FA3) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_FA4 (HKLM-x32\...\Easy-PhotoPrint EX - DL_FA4) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_FA5 (HKLM-x32\...\Easy-PhotoPrint EX - DL_FA5) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_ST1 (HKLM-x32\...\Easy-PhotoPrint EX - DL_ST1) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_ST2 (HKLM-x32\...\Easy-PhotoPrint EX - DL_ST2) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_ST3 (HKLM-x32\...\Easy-PhotoPrint EX - DL_ST3) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_ST4 (HKLM-x32\...\Easy-PhotoPrint EX - DL_ST4) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_ST5 (HKLM-x32\...\Easy-PhotoPrint EX - DL_ST5) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_ST6 (HKLM-x32\...\Easy-PhotoPrint EX - DL_ST6) (Version:  - )
Canon Easy-PhotoPrint EX - Additional Materials DL_ST7 (HKLM-x32\...\Easy-PhotoPrint EX - DL_ST7) (Version:  - )
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: 4.1.6 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version:  - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MG6200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6200_series) (Version:  - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.21 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6499 - CDBurnerXP)
Chivalry: Medieval Warfare (HKLM-x32\...\Steam App 219640) (Version:  - Torn Banner Studios)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
CyberLink PowerDVD 15 (HKLM-x32\...\{DE85B8F3-D088-4D6E-A970-EE0BC7883A66}) (Version: 15.0.2205.58 - CyberLink Corp.)
DayZ (HKLM-x32\...\Steam App 221100) (Version:  - Bohemia Interactive)
DisplayFusion (HKLM\...\Steam App 227260) (Version:  - Binary Fortress Software)
DisplayFusion 8.1.2 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 8.1.2.0 - Binary Fortress Software)
Dolby Home Theater v4 (HKLM-x32\...\{B26438B4-BF51-49C3-9567-7F14A5E40CB9}) (Version: 7.2.8000.17 - Dolby Laboratories Inc)
Edge of Space (HKLM-x32\...\Steam App 238240) (Version:  - Handyman Studios)
ELAN Touchpad 11.14.7.1_X64_WHQL (HKLM\...\Elantech) (Version: 11.14.7.1 - ELAN Microelectronic Corp.)
Fiends of Imprisonment (HKLM\...\Steam App 410590) (Version:  - Zonitron Productions)
FileZilla Client 3.24.1 (HKLM-x32\...\FileZilla Client) (Version: 3.24.1 - Tim Kosse)
FRAFS AVI Info version 0.2.2.2 (HKLM-x32\...\{3DC088C4-41EB-4CEF-9B45-940555A818D3}_is1) (Version: 0.2.2.2 - raffriff42)
Fraps (remove only) (HKLM-x32\...\Fraps) (Version:  - )
Game Dev Tycoon version 1.5.24 (HKLM-x32\...\{5BBB8682-1335-410F-A79F-8E5611A54BD0}_is1) (Version: 1.5.24 - Greenheart Games Pty. Ltd.)
Garry's Mod (HKLM\...\Steam App 4000) (Version:  - Facepunch Studios)
GIGABYTE Smart USB Backup 2.0.20141014 (HKLM-x32\...\GIGABYTE Smart USB Backup) (Version: 2.0.20141014 - GIGABYTE TECHNOLOGY CO.,LTD.)
Gone Home (HKLM-x32\...\GoneHome) (Version:  - )
GRID (HKLM\...\Steam App 12750) (Version:  - Codemasters Studios)
Hard Disk Sentinel (HKLM-x32\...\Hard Disk Sentinel_is1) (Version: 4.71 - Janos Mathe)
Hell Yeah! (HKLM-x32\...\Steam App 205230) (Version:  - Arkedo)
HLSW v1.4.0.5 (HKLM-x32\...\HLSW_is1) (Version:  - Stripf Software)
Hyperdimension Neptunia Re;Birth1 (HKLM-x32\...\Steam App 282900) (Version:  - Idea Factory, Inc.)
Hyperdimension Neptunia Re;Birth2 Sisters Generation (HKLM-x32\...\Steam App 351710) (Version:  - Compile Heart)
Intel® Chipset Device Software (x32 Version: 10.0.22 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.2.1000 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.14.4294 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.5.0.1056 - Intel Corporation)
Intel® Update Manager (HKLM-x32\...\{7224B7CE-196C-4E2A-A1AE-1D7BF259FD36}) (Version: 3.4.1942 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.0.34 - Intel Corporation)
Intel® Wireless Bluetooth®(patch version 17.0.1427.2) (HKLM\...\{302600C1-6BDF-4FD1-1406-148929CC1385}) (Version: 17.1.1406.0472 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{7991b5ae-96d7-4df2-97fb-a605b7cb638b}) (Version: 17.12.0 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Jet Set Radio (HKLM-x32\...\Steam App 205950) (Version:  - Blit Software)
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{F575F386-57EF-4943-B003-A13F13B05EEB}) (Version: 16.0.1.445 - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: 16.0.1.445 - Kaspersky Lab) Hidden
KeyScrambler (HKLM-x32\...\KeyScrambler) (Version: 3.10.0.0 - QFX Software Corporation)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
Killing Floor 2 - SDK (HKLM\...\Steam App 232150) (Version:  - )
Killing Floor 2 (HKLM-x32\...\Steam App 232090) (Version:  - Tripwire Interactive)
Killing Floor SDK (HKLM\...\Steam App 1260) (Version:  - Tripwire Interactive)
Kingdom Wars (HKLM\...\Steam App 227180) (Version:  - Reverie World Studios, INC)
LanOptimizer (HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\{B416A23D-C2BD-4956-8BAE-5C3BAFF1AC1E}) (Version: 1.00.0000 - Realtek)
Left 4 Dead (HKLM-x32\...\Steam App 500) (Version:  - Valve)
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MediaInfo 0.7.78 (HKLM\...\MediaInfo) (Version: 0.7.78 - MediaArea.net)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional 2007 (HKLM-x32\...\PROR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210 (HKLM-x32\...\{f144e08f-9cbe-4f09-9a8c-f2b858b7ee7f}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 45.8.0 ESR (x86 en-US) (HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\Mozilla Firefox 45.8.0 ESR (x86 en-US)) (Version: 45.8.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.3.0 - Mozilla)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
Mumble 1.2.17 (HKLM-x32\...\{95A0093C-0C81-4D0B-BCA7-3CE11755A6BD}) (Version: 1.2.17 - Thorvald Natvig)
My MP4Box GUI 0.6.0.6 (HKLM\...\{3FBE3061-F2BC-4D3A-B4A9-8FB15C503F87}_is1) (Version: 0.6.0.6 - Matt Bodin)
NTLite v1.2.0.4750 (HKLM\...\NTLite_is1) (Version: 1.2.0.4750 - Nlitesoft)
NVIDIA Graphics Driver 378.66 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.66 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 17.0.0 - OBS Project)
Omikron - The Nomad Soul (HKLM-x32\...\Steam App 243000) (Version:  - Quantic Dream)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
OpenXcom 1.0 (HKLM-x32\...\OpenXcom) (Version: 1.0.0.0 - OpenXcom Developers)
Opera Stable 43.0.2442.1144 (HKLM-x32\...\Opera 43.0.2442.1144) (Version: 43.0.2442.1144 - Opera Software)
ORION: Prelude (HKLM-x32\...\Steam App 104900) (Version:  - Spiral Game Studios)
Razer Naga (HKLM-x32\...\{ED4108A9-60FD-4F18-AF42-122219977773}) (Version: 3.03.01 - Razer USA Ltd.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.21239 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.82.317.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7348 - Realtek Semiconductor Corp.)
Renegade Ops (HKLM-x32\...\Steam App 99300) (Version:  - Avalanche Studios)
Revo Uninstaller Pro 3.1.7 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.7 - VS Revo Group, Ltd.)
Rise of the Tomb Raider (HKLM\...\Steam App 391220) (Version:  - Crystal Dynamics)
Sandboxie 5.16 (64-bit) (HKLM\...\Sandboxie) (Version: 5.16 - Sandboxie Holdings, LLC)
Savage Resurrection (HKLM\...\Steam App 366440) (Version:  - S2 Games, LLC)
SEGA Genesis & Mega Drive Classics (HKLM-x32\...\Steam App 34270) (Version:  - Sega)
Skype™ 7.26 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Smart Manager V3 Ver 4.4.3 (HKLM\...\Smart Manager V3) (Version: Ver 4.4.3 - GIGABYTE)
Smart Update v3.3.1 (HKLM-x32\...\Smart Update) (Version: v3.3.1 - GIGABYTE TECHNOLOGY CO.,LTD.)
Sniper Elite: Nazi Zombie Army (HKLM\...\Steam App 227100) (Version:  - Rebellion)
Sniper Elite: Nazi Zombie Army 2 (HKLM-x32\...\Steam App 247910) (Version:  - )
Soulbringer (HKLM-x32\...\Steam App 283310) (Version:  - Infogames Europe SA)
SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.04.0000 - Electronic Arts)
SPORE™ Creepy & Cute Parts Pack (HKLM-x32\...\{C07F8D75-7A8D-400E-A8F9-A3F396B49BB1}) (Version: 1.00.0000 - Electronic Arts)
SPORE™ Galactic Adventures (HKLM-x32\...\{63CEA2E4-4FE7-4F2C-B388-C1313D24157C}) (Version: 1.00.0000 - Electronic Arts)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited)
SpywareBlaster 5.5 (HKLM-x32\...\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
Star Wars - Battlefront II (HKLM-x32\...\Steam App 6060) (Version:  - Pandemic Studios)
Starbound - Unstable (HKLM\...\Steam App 367540) (Version:  - )
Starbound (HKLM-x32\...\Steam App 211820) (Version:  - )
State of Decay (HKLM-x32\...\Steam App 241540) (Version:  - Undead Labs)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Street Racing Syndicate (HKLM-x32\...\Steam App 292410) (Version:  - Eutechnyx)
Super Meat Boy (HKLM-x32\...\Steam App 40800) (Version:  - Team Meat)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1212 - SUPERAntiSpyware.com)
TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.72365 - TeamViewer)
Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)
The Elder Scrolls V: Skyrim Special Edition (HKLM\...\Steam App 489830) (Version:  - Bethesda Game Studios)
The Ship (HKLM-x32\...\Steam App 2400) (Version:  - Outerlight Ltd.)
Trainz (HKLM-x32\...\{F03D7004-F232-4B7A-A4A0-4B8FC118C4BD}) (Version:  - )
UE Explorer (HKLM-x32\...\{73C686EA-0FF6-4491-BD0D-FE52A62E8B63}) (Version: 1.2.71 - Eliot)
UE3Redist (HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\InstallShield_{6530FDAA-5B1F-4830-95BB-650E9804D239}) (Version: 1.00.0000 - Epic Games)
UE3Redist (x32 Version: 1.00.0000 - Epic Games) Hidden
Viking: Battle for Asgard (HKLM-x32\...\Steam App 211160) (Version:  - Creative Assembly, PC Port - Hardlight)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.)
Windows Automated Installation Kit (HKLM\...\{31E8F586-4EF7-4500-844D-BA8756474FF1}) (Version: 2.0.0.0 - Microsoft Corporation)
Windscribe version 1.61 build 9 (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 1.61 build 9 - Windscribe)
WinPatrol (HKLM-x32\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 34.11.2016.27 - Ruiware)
WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
X-COM: UFO Defense (HKLM\...\Steam App 7760) (Version:  - MicroProse Software, Inc)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001_Classes\CLSID\{869C14C8-1830-491F-B575-5F9AB40D2B42}\InprocServer32 -> C:\Program Files\MediaInfo\MediaInfo_InfoTip.dll (MediaArea.net)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {056FFE8C-A857-4FBF-8FCF-1A17169A23E7} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {09A737C1-5415-4850-916F-39F71D37506D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {0E440603-5998-4E6F-A468-6534CE21E6F8} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-10] (NVIDIA Corporation)
Task: {23999207-D116-4723-BBA3-00FDCAD2E369} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2016-08-12] (Intel Corporation)
Task: {4191DB8E-F288-4967-9413-3A887B0857B4} - System32\Tasks\SUPERAntiSpyware Scheduled Task e4d34f86-8653-4a93-bc58-a1e3600e97f4 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-08] (SUPERAdBlocker.com)
Task: {9C42B084-9500-4777-9C27-56A5BC51522B} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-02-10] (NVIDIA Corporation)
Task: {B76B62E6-4816-41E9-928B-167DC7901818} - System32\Tasks\Opera scheduled Autoupdate 1453433047 => C:\Program Files (x86)\Opera\launcher.exe [2017-02-27] (Opera Software)
Task: {CB6F5C92-84A9-4643-A25F-B79D4542047C} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe [2015-09-05] (Beepa P/L)
Task: {D23151EE-5256-4901-9127-5EE10B45EBD6} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-10] (NVIDIA Corporation)
Task: {D2443CEE-28E7-4E8E-B014-09D96E0D998C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-06] (Piriform Ltd)
Task: {E1B701B4-8889-46F5-A1E8-6226A5212985} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-02-15] (Adobe Systems Incorporated)
Task: {EB01EC40-DA06-4B4E-88A7-BA219EC53B4F} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-02-10] (NVIDIA Corporation)
Task: {FF4E6B6D-7A57-4A57-8419-5585F849144D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-02-10] (NVIDIA Corporation)
Task: {FFE4DF80-8C39-4568-8C64-A70E97751AF6} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe [2017-02-15] (Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e4d34f86-8653-4a93-bc58-a1e3600e97f4.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe  C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-02-24 21:52 - 2017-02-10 08:52 - 00018880 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2017-02-24 21:53 - 2017-02-10 06:57 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-10-29 15:01 - 2014-10-29 15:01 - 00014336 _____ () C:\Program Files\GIGABYTE\SmartManagerV3\ElevateService.exe
2016-11-02 11:52 - 2016-11-02 11:52 - 00135680 _____ () C:\Program Files\Smart Update\Update_Service.exe
2016-12-28 09:42 - 2016-12-08 01:15 - 00053352 _____ () C:\Program Files (x86)\Windscribe\WindscribeService.exe
2017-02-22 05:09 - 2017-02-22 05:09 - 00052392 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2017-03-12 15:40 - 2017-01-06 01:55 - 01958400 _____ () C:\Users\Electrike\Downloads\Idle Master\IdleMaster.exe
2017-03-12 15:40 - 2015-02-10 01:44 - 00497664 _____ () C:\Users\Electrike\Downloads\Idle Master\steam-idle.exe
2015-12-22 02:47 - 2015-12-22 02:47 - 00794920 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\kpcengine.2.3.dll
2014-04-30 07:23 - 2014-04-30 07:23 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2017-02-24 21:52 - 2017-02-10 08:52 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2016-01-15 06:37 - 2017-02-03 09:42 - 00668960 _____ () E:\Steam\SDL2.dll
2016-01-15 06:37 - 2016-09-01 09:02 - 04969248 _____ () E:\Steam\v8.dll
2016-01-15 06:37 - 2016-09-01 09:02 - 01563936 _____ () E:\Steam\icui18n.dll
2016-01-15 06:37 - 2016-09-01 09:02 - 01195296 _____ () E:\Steam\icuuc.dll
2016-01-15 06:37 - 2017-03-14 06:04 - 02465056 _____ () E:\Steam\video.dll
2016-01-15 06:37 - 2016-01-27 15:49 - 02549760 _____ () E:\Steam\libavcodec-56.dll
2016-01-15 06:37 - 2016-01-27 15:49 - 00442880 _____ () E:\Steam\libavutil-54.dll
2016-01-15 06:37 - 2016-01-27 15:49 - 00491008 _____ () E:\Steam\libavformat-56.dll
2016-01-15 06:37 - 2016-01-27 15:49 - 00332800 _____ () E:\Steam\libavresample-2.dll
2016-01-15 06:37 - 2016-01-27 15:49 - 00485888 _____ () E:\Steam\libswscale-3.dll
2016-01-15 06:31 - 2017-03-14 06:04 - 00838944 _____ () E:\Steam\bin\chromehtml.DLL
2016-03-10 10:38 - 2016-07-05 06:17 - 00266560 _____ () E:\Steam\openvr_api.dll
2016-12-13 10:17 - 2017-01-31 05:41 - 68875552 _____ () E:\Steam\bin\cef\cef.win7\libcef.dll
2016-01-15 06:37 - 2017-03-14 06:04 - 00383776 _____ () E:\Steam\steam.dll
2016-01-15 06:37 - 2015-09-25 07:52 - 00119208 _____ () E:\Steam\winh264.dll
2017-03-12 15:42 - 2015-09-25 07:52 - 00119208 _____ () E:\Sandbox\Steambox\drive\C\S\winh264.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [125]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PAexec => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com
 
There are 7932 more sites.
 
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\...\1-2005-search.com -> www.1-2005-search.com
 
There are 12749 more sites.
 
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\...\1-2005-search.com -> www.1-2005-search.com
 
There are 12749 more sites.
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2016-12-27 22:20 - 2017-03-12 02:03 - 00454766 ____R C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
127.0.0.1 tonec.com
127.0.0.1 www.tonec.com
127.0.0.1 registeridm.com
127.0.0.1 www.registeridm.com
127.0.0.1 secure.registeridm.com
127.0.0.1 internetdownloadmanager.com
127.0.0.1 www.internetdownloadmanager.com
127.0.0.1 secure.internetdownloadmanager.com
127.0.0.1 mirror.internetdownloadmanager.com
127.0.0.1 mirror2.internetdownloadmanager.com
127.0.0.1       cap.cyberlink.com
127.0.0.1       activation.cyberlink.com127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
 
There are 15601 more lines.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2798084944-1211984927-2140173799-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Manectric\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-2798084944-1211984927-2140173799-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Electrike\AppData\Local\DisplayFusion\Wallpaper_1
DNS Servers: 8.8.8.8 - 203.12.160.35
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^GBOSDV3.lnk => C:\Windows\pss\GBOSDV3.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^update_start.lnk => C:\Windows\pss\update_start.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Welcome.lnk => C:\Windows\pss\Welcome.lnk.CommonStartup
MSCONFIG\startupreg: CleanUp RzWizard => C:\Program Files (x86)\Razer\RzWizard\RzInstallerDeletion.vbs
MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
MSCONFIG\startupreg: NvBackend => "C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
MSCONFIG\startupreg: SmartUpdate => C:\Program Files\Smart Update\urgent.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{ED44402E-6B9E-4DB1-B967-E19AA4AE59D5}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{066D6F27-71F5-4E62-A6E1-7CBE8CC659B8}] => (Allow) LPort=2869
FirewallRules: [{DB872E6F-011D-4F33-9FAC-0FDC2FF78F8E}] => (Allow) LPort=1900
FirewallRules: [{8AA98205-C1F8-4F48-929E-28A6F5C66746}] => (Allow) E:\Steam\Steam.exe
FirewallRules: [{218FBBB7-0A07-424B-9DBA-25DEE324042F}] => (Allow) E:\Steam\Steam.exe
FirewallRules: [{BA275EC0-0E29-4CB2-851E-0DF94DD3B256}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD.exe
FirewallRules: [{D7B7FE81-F7C1-4CC2-9A5D-3BFBC4F8B092}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Kernel\DMS\CLMSServerPDVD15.exe
FirewallRules: [{158CD4F6-032B-4273-826C-217282EBB367}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe
FirewallRules: [{1923CDDD-D237-42FD-8C23-BC5FB283A78E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Movie\PowerDVDMovie.exe
FirewallRules: [{AE2A9A89-B88B-4683-B869-8B2EF65AD275}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Movie\PowerDVD Cinema\PowerDVDCinema.exe
FirewallRules: [{23E604FA-4DDA-45B1-9908-9EBFB959E3DF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1B14BB29-0D4F-4A8C-8ABC-6888D216BD83}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{42E4617A-5FCA-4251-8EFB-91382308D1CF}] => (Allow) E:\Steam\steamapps\common\3DMark\3DMarkLauncher.exe
FirewallRules: [{5915F504-940F-4CF9-8851-E2D9D34CCF8B}] => (Allow) E:\Steam\steamapps\common\3DMark\3DMarkLauncher.exe
FirewallRules: [{977B611B-A28C-4028-B3BC-1039ED8857E6}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\Binaries\Win64\CMW.exe
FirewallRules: [{6E11EF2F-6830-49D3-BD5C-667A4C9A40F6}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\Binaries\Win64\CMW.exe
FirewallRules: [{19406A0C-DDD7-46E7-A82F-38E6F9627D2A}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\CDW\Binaries\Win64\CDW.exe
FirewallRules: [{2513EA08-BD87-41FE-A41B-2C727C0E0AA2}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\CDW\Binaries\Win64\CDW.exe
FirewallRules: [{31FED2C9-495D-4342-8B10-7966E278394C}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\Binaries\Win32\CMW.exe
FirewallRules: [{61BC3A19-BF39-4DD6-A1A6-0D58AEE19178}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\Binaries\Win32\CMW.exe
FirewallRules: [{106113F8-9421-4270-820D-CC76EEA2A2B3}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\CDW\Binaries\Win32\CDW.exe
FirewallRules: [{DBF93726-DD05-4DD9-BC9F-9948951E75B1}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\CDW\Binaries\Win32\CDW.exe
FirewallRules: [{D0CE9C82-7250-46DC-94CF-0CA3B4E0A5AC}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{B70D3706-95ED-49E3-AF67-CBE783281915}] => (Allow) E:\Steam\steamapps\common\chivalrymedievalwarfare\ChivLauncher.exe
FirewallRules: [{B7138CFE-00E4-4F1A-B081-EAF371CC90C5}] => (Allow) E:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{2DC418BB-D092-44D7-B9D5-2AAF21966D87}] => (Allow) E:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{080F40DB-3587-4EB6-818C-FE2225702188}] => (Allow) E:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{441B589F-AC8B-4E86-9F8A-536B5BB1D1BB}] => (Allow) E:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{1AC40D78-85FC-44D5-97B1-05DE752CE4AB}] => (Allow) E:\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{16E5442B-B244-434D-89BC-122C4DC23666}] => (Allow) E:\Steam\steamapps\common\DayZ\DayZ_BE.exe
FirewallRules: [{0659532C-2FC0-41DE-A1FE-F884355EFCA2}] => (Allow) E:\Steam\steamapps\common\Edge of Space\Launcher.exe
FirewallRules: [{E7546CF8-5893-4099-B834-70CE3F0A815D}] => (Allow) E:\Steam\steamapps\common\Edge of Space\Launcher.exe
FirewallRules: [{0E8AC9E3-CCC1-4B56-A403-CAF7318C1872}] => (Allow) E:\Steam\steamapps\common\left 4 dead\left4dead.exe
FirewallRules: [{0B8EAF10-34D3-4982-97C4-7B8909D7ABA1}] => (Allow) E:\Steam\steamapps\common\left 4 dead\left4dead.exe
FirewallRules: [{4B4DA01D-819F-4EFF-A0FD-2C0BE6406682}] => (Allow) E:\Steam\steamapps\common\Star Wars Battlefront II\GameData\BattlefrontII.exe
FirewallRules: [{54884BF2-8338-451F-B9E7-46AB96619750}] => (Allow) E:\Steam\steamapps\common\Star Wars Battlefront II\GameData\BattlefrontII.exe
FirewallRules: [{E61D0B2A-5D79-4977-AF7D-2F0B7106C268}] => (Allow) E:\Steam\steamapps\common\Super Meat Boy\SuperMeatBoy.exe
FirewallRules: [{3DCB6A24-1389-4942-92D5-3843075404E4}] => (Allow) E:\Steam\steamapps\common\Super Meat Boy\SuperMeatBoy.exe
FirewallRules: [{DBA18D9C-8ACA-49E2-AAC4-3562035A8C57}] => (Allow) E:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{BBEFBE26-BED3-48B4-B121-E489A3ADF5B1}] => (Allow) E:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{33926AC4-D51F-4479-8FC0-6A47B2055EEF}] => (Allow) E:\Steam\steamapps\common\Neptunia Rebirth1\NeptuniaReBirth1.exe
FirewallRules: [{1C996CF8-6816-406F-B0E0-7F5346B9A085}] => (Allow) E:\Steam\steamapps\common\Neptunia Rebirth1\NeptuniaReBirth1.exe
FirewallRules: [{8EB3D9BC-0F02-45D3-9DAB-C24D00AB72C1}] => (Allow) E:\Steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{11A7FAF0-73F9-4D6F-BE83-AE1B847685DE}] => (Allow) E:\Steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{9BD875E2-2851-4332-AE83-1C609C0F596E}] => (Allow) E:\Steam\steamapps\common\The Ship\ship.exe
FirewallRules: [{B64A9B7C-6C69-4C35-B792-9697435EB025}] => (Allow) E:\Steam\steamapps\common\The Ship\ship.exe
FirewallRules: [{C7B05986-D0C4-4108-BF55-AA0DB2F9B964}] => (Allow) E:\Steam\steamapps\common\Orion Dino Beatdown\Binaries\Win32\DinoHordeGame.exe
FirewallRules: [{86B27BFA-B00C-4819-AC2E-2698A8D1D867}] => (Allow) E:\Steam\steamapps\common\Orion Dino Beatdown\Binaries\Win32\DinoHordeGame.exe
FirewallRules: [{0CB72F27-4441-44FA-9C5A-5441E38EE959}] => (Allow) E:\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{1D8F9B21-75A4-4095-925D-37EF588122EC}] => (Allow) E:\Steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{D1FBB2F4-3AEB-4A10-B314-1997BF169FD9}] => (Allow) E:\Steam\steamapps\common\Sniper Elite Nazi Zombie Army 2\bin\NZA2.exe
FirewallRules: [{746B90D7-A441-49B8-9D00-634C77BA026A}] => (Allow) E:\Steam\steamapps\common\Sniper Elite Nazi Zombie Army 2\bin\NZA2.exe
FirewallRules: [{DBE2503B-EFAA-4652-A651-B03A21CBF6F6}] => (Allow) E:\Steam\steamapps\common\Neptunia Rebirth2\NeptuniaReBirth2.exe
FirewallRules: [{2DF07BBF-0773-4A95-9F7F-1E5853B86F17}] => (Allow) E:\Steam\steamapps\common\Neptunia Rebirth2\NeptuniaReBirth2.exe
FirewallRules: [{53DFE6F9-4512-43A8-9878-0A28C814363E}] => (Allow) E:\Steam\steamapps\common\8BitBoy\8bitboy.exe
FirewallRules: [{79D7B79F-14C8-41B4-AF2B-E5A83CD0A94E}] => (Allow) E:\Steam\steamapps\common\8BitBoy\8bitboy.exe
FirewallRules: [{BE1625A0-5C22-4012-B36E-CBEB9D1D0B44}] => (Allow) E:\Steam\steamapps\common\Soulbringer\Soulbringer.exe
FirewallRules: [{732E4072-52AD-437F-832B-8788A54BC722}] => (Allow) E:\Steam\steamapps\common\Soulbringer\Soulbringer.exe
FirewallRules: [{B8112D4F-B895-48FD-A761-07233224E301}] => (Allow) E:\Steam\steamapps\common\Soulbringer\SBLang.exe
FirewallRules: [{7B73DB18-60C1-48C2-8BC7-EDB9EA198B1A}] => (Allow) E:\Steam\steamapps\common\Soulbringer\SBLang.exe
FirewallRules: [{DBB54C42-A404-4750-9EA6-CE7EC5EBF23F}] => (Allow) E:\Steam\steamapps\common\Omikron\Runtime.exe
FirewallRules: [{4394EE80-8ACE-407E-952B-CC4B6719971F}] => (Allow) E:\Steam\steamapps\common\Omikron\Runtime.exe
FirewallRules: [{ACA46DCF-C461-4ED4-BED5-2C3C4850A8F3}] => (Allow) E:\Steam\steamapps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{273E2CC8-617A-48CB-9CCF-B94AA9D96ECD}] => (Allow) E:\Steam\steamapps\common\State of Decay\StateOfDecay.exe
FirewallRules: [{172E3FBA-DEE4-43F4-8A2D-B9B8D68CACA0}] => (Allow) E:\Steam\steamapps\common\Bioshock\Builds\Release\Bioshock.exe
FirewallRules: [{E94AD05B-C733-4A92-B5A2-BD09EB05A410}] => (Allow) E:\Steam\steamapps\common\Bioshock\Builds\Release\Bioshock.exe
FirewallRules: [{5D6F89F7-F555-4AFF-87D7-8917694FB047}] => (Allow) E:\Steam\steamapps\common\Hell Yeah\HELLYEAH.exe
FirewallRules: [{4881C23D-6B79-4AC8-8E02-130174DB56C6}] => (Allow) E:\Steam\steamapps\common\Hell Yeah\HELLYEAH.exe
FirewallRules: [{3FE16417-2CD9-440A-BB2C-706CE915A875}] => (Allow) E:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{36087A05-0CF8-4B27-BDF8-9CF302C67AA5}] => (Allow) E:\Steam\steamapps\common\7 Days To Die\7DaysToDie_EAC.exe
FirewallRules: [{1019BCF9-BD0D-4A13-9E3C-06A6AC454A6E}] => (Allow) E:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{A00A786A-C640-42D3-BECB-E15D111B895D}] => (Allow) E:\Steam\steamapps\common\7 Days To Die\7DaysToDie.exe
FirewallRules: [{085CECB5-F16A-4FEA-A367-635ECAF8AE68}] => (Allow) E:\Steam\steamapps\common\7 Days To Die\7dLauncher.exe
FirewallRules: [{9B0C99E4-2915-4FF2-808A-3D312E5B96A5}] => (Allow) E:\Steam\steamapps\common\7 Days To Die\7dLauncher.exe
FirewallRules: [{91F06AFB-8E75-44AB-B0C6-96E7EA655247}] => (Allow) E:\Steam\steamapps\common\Rise of the Tomb Raider\ROTTR.exe
FirewallRules: [{0967B77F-C7CF-4CB1-B661-58A2C9D4BD8A}] => (Allow) E:\Steam\steamapps\common\Rise of the Tomb Raider\ROTTR.exe
FirewallRules: [{283F00F6-FC06-4202-A2BC-1D6A71A602D5}] => (Allow) E:\Steam\steamapps\common\NZA\bin\NZA.exe
FirewallRules: [{DC835193-8257-4F17-8766-DF1FB666B42D}] => (Allow) E:\Steam\steamapps\common\NZA\bin\NZA.exe
FirewallRules: [{3E197E6E-E3C9-40F3-9604-1AB1DDD83215}] => (Allow) E:\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{262CE7D0-859A-4BCB-BF53-863D3E54387D}] => (Allow) E:\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{AE3F9038-B0B2-484A-A0B1-3D461F707A25}] => (Allow) E:\Steam\steamapps\common\DisplayFusion\DisplayFusionLauncher.exe
FirewallRules: [{88FFB1AB-B4BB-4CB1-8339-5C300B57DF88}] => (Allow) E:\Steam\steamapps\common\DisplayFusion\DisplayFusionLauncher.exe
FirewallRules: [{00D6D883-169F-4CD5-A134-1E5E3108437F}] => (Allow) E:\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{46943071-DCB0-4546-972B-D4B05FDE06AC}] => (Allow) E:\Steam\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{F980B93B-B3F1-4AA1-AD53-E7B190E3AAD7}] => (Allow) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{A2B82D57-252F-4C4F-A1A7-A1188351003D}] => (Allow) E:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{EAE36BAF-20C0-4176-B891-C93AAB4ED7DA}] => (Allow) E:\Steam\steamapps\common\3DMark\bin\x86\3DMark.exe
FirewallRules: [{67C6681C-C526-4AC0-BED8-57D394792A05}] => (Allow) E:\Steam\steamapps\common\3DMark\bin\x86\3DMark.exe
FirewallRules: [{EBD6F8DB-25EB-4CF6-9090-B5F73AD0A7D1}] => (Allow) E:\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe
FirewallRules: [{17F768BA-5DE3-4570-8749-48DE6DEE3874}] => (Allow) E:\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe
FirewallRules: [{F0BF232F-0E90-43F5-BAB8-9E1936900147}] => (Allow) E:\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe
FirewallRules: [{D8856E62-B3BA-457A-A248-9959B0346D43}] => (Allow) E:\Steam\steamapps\common\BioShock Remastered\Build\Final\BioshockHD.exe
FirewallRules: [{AB2AE5A7-16A8-4447-A239-51F2FE8E1FF8}] => (Allow) E:\Steam\steamapps\common\Broforce\Broforce_beta.exe
FirewallRules: [{D0A56F3B-A64F-49EE-A0B5-9A4C1887BC00}] => (Allow) E:\Steam\steamapps\common\Broforce\Broforce_beta.exe
FirewallRules: [{554683F5-2875-4102-866B-E2927BD9EFF1}] => (Allow) E:\Steam\steamapps\common\Grid\grid.exe
FirewallRules: [{1DBBC372-00BA-42C8-BEFE-3B3A884381D7}] => (Allow) E:\Steam\steamapps\common\Grid\grid.exe
FirewallRules: [{E83FF4F2-6B3F-4B21-B9DC-9F432AE9D98B}] => (Allow) E:\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe
FirewallRules: [{D77029EA-9252-4050-A4DE-5A2CC74A9EA4}] => (Allow) E:\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFGame.exe
FirewallRules: [{B776EDE2-9CD3-45DE-A25A-22B3D50AC5C1}] => (Allow) E:\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFEditor.exe
FirewallRules: [{4E67D89B-1B83-41DA-B727-2B2874D0239F}] => (Allow) E:\Steam\steamapps\common\killingfloor2\Binaries\Win64\KFEditor.exe
FirewallRules: [{19A0D37B-FA82-4321-AE25-55588203A217}] => (Allow) E:\Steam\steamapps\common\killingfloor2\Binaries\SDKFrontend.exe
FirewallRules: [{559BF878-03EA-4C81-A386-2C3BFC462225}] => (Allow) E:\Steam\steamapps\common\killingfloor2\Binaries\SDKFrontend.exe
FirewallRules: [{66496B66-92ED-44AA-A642-DA5C257C9123}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{918EB967-F962-4314-BD81-2F28F8521144}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{8FDB7ABE-5DCF-4542-A141-3C9793D7DC3D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{3A591451-8A66-4923-A9AB-6346E9F97557}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{526EE4AE-3507-4266-B353-17A721CEC874}] => (Allow) E:\Steam\steamapps\common\XCom UFO Defense\dosbox.exe
FirewallRules: [{AC5DE1F3-4BE0-4DBD-B24D-B445FBEE3B09}] => (Allow) E:\Steam\steamapps\common\XCom UFO Defense\dosbox.exe
FirewallRules: [{512F06A7-AFB7-4145-AD29-42794DDD341E}] => (Allow) E:\Steam\steamapps\common\XCom UFO Defense\XCOM\UFO Defense_Patched.exe
FirewallRules: [{8DC36634-33C8-4E4B-874E-894ED4F2B1FB}] => (Allow) E:\Steam\steamapps\common\XCom UFO Defense\XCOM\UFO Defense_Patched.exe
FirewallRules: [{E1AF0320-DDA2-45D7-8071-AD597B84097F}] => (Allow) C:\Program Files (x86)\Opera\43.0.2442.991\opera.exe
FirewallRules: [{15D6FF85-65B8-4C2C-9829-FD57567056D4}] => (Allow) C:\Program Files (x86)\Opera\43.0.2442.1144\opera.exe
FirewallRules: [{87CA3F26-AE3E-445A-AD8E-2FA27074829A}] => (Allow) E:\Steam\steamapps\common\Break Into Zatwor\BreakIntoZatwor.exe
FirewallRules: [{53AB99E8-63AB-414E-AD57-CD1420A53428}] => (Allow) E:\Steam\steamapps\common\Break Into Zatwor\BreakIntoZatwor.exe
FirewallRules: [{6B1058F9-48A7-43A0-B735-FF3E11DCEFE3}] => (Allow) E:\Steam\steamapps\common\Fiends of Imprisonment\FOI.exe
FirewallRules: [{25FC8068-B1D3-4219-BE8E-399467389486}] => (Allow) E:\Steam\steamapps\common\Fiends of Imprisonment\FOI.exe
FirewallRules: [{464199AF-E7E6-4394-B850-124D7B616A2C}] => (Allow) E:\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{26767745-BC9E-4ADF-8146-5BEDAE24A855}] => (Allow) E:\Steam\steamapps\common\Starbound\win64\starbound.exe
FirewallRules: [{5C7714B4-02FF-4607-94E0-9FB515E5E531}] => (Allow) E:\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{1B1E2960-FB4C-4BBB-A142-8B6C503C9A02}] => (Allow) E:\Steam\steamapps\common\Starbound\win64\starbound_server.exe
FirewallRules: [{FD9CFDF3-17E1-4711-A3D2-06D9648D82C8}] => (Allow) E:\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{7BEEAB4F-9A78-41D2-AD8E-67AD02241823}] => (Allow) E:\Steam\steamapps\common\Starbound\win64\mod_uploader.exe
FirewallRules: [{4A22E1D3-267E-41B8-BD28-BA6D78667A89}] => (Allow) E:\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{6BEA73E4-3F8B-41BE-90D7-5CB88A72D889}] => (Allow) E:\Steam\steamapps\common\Starbound\win32\starbound.exe
FirewallRules: [{5A5EA93C-58AF-486E-9DE6-74CA542004DF}] => (Allow) E:\Steam\steamapps\common\Savage Resurrection\Savage\Binaries\Win64\Savage-Win64-Shipping.exe
FirewallRules: [{7459045A-6894-4297-9CEF-43A8B0D9781F}] => (Allow) E:\Steam\steamapps\common\Savage Resurrection\Savage\Binaries\Win64\Savage-Win64-Shipping.exe
FirewallRules: [{89D2E6FA-5EB4-4CA2-8A3F-5E386B6A67D2}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win64\starbound.exe
FirewallRules: [{B02A18C5-A6EB-4EB8-B1A9-866D8F9F74A2}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win64\starbound.exe
FirewallRules: [{E9972893-BD74-4117-BB06-5F9EF2CAF303}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win64\starbound_server.exe
FirewallRules: [{D7916A5A-2760-44DC-970A-7D60E36FF048}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win64\starbound_server.exe
FirewallRules: [{0DC80C9F-6D3D-4913-AF9E-CE4002B8ED3A}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win64\mod_uploader.exe
FirewallRules: [{0AAEAADE-CBD3-46C7-9CE0-CB92F4E77DA3}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win64\mod_uploader.exe
FirewallRules: [{F5589897-B5DE-4A27-9919-D5E825B0C52C}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win32\starbound.exe
FirewallRules: [{C50E1C8E-2BC2-4EC3-8135-EB81498AC855}] => (Allow) E:\Steam\steamapps\common\Starbound - Unstable\win32\starbound.exe
 
==================== Restore Points =========================
 
ATTENTION: System Restore is disabled
 
==================== Faulty Device Manager Devices =============
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
Name: Npcap Loopback Adapter
Description: Microsoft Loopback Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: msloop
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/14/2017 04:02:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Faulting module name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Exception code: 0xc0000005
Fault offset: 0x0004e010
Faulting process id: 0xf44
Faulting application start time: 0x01d29c98ae0b1fdf
Faulting application path: C:\Users\Electrike\Desktop\aswMBR.exe
Faulting module path: C:\Users\Electrike\Desktop\aswMBR.exe
Report Id: 931de159-088c-11e7-baa7-f81654f7d0d1
 
Error: (03/14/2017 03:55:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Faulting module name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Exception code: 0xc0000005
Fault offset: 0x0004e010
Faulting process id: 0x1d78
Faulting application start time: 0x01d29c97a57760f9
Faulting application path: C:\Users\Electrike\Downloads\aswMBR.exe
Faulting module path: C:\Users\Electrike\Downloads\aswMBR.exe
Report Id: 913c5637-088b-11e7-baa7-f81654f7d0d1
 
Error: (03/14/2017 03:49:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Faulting module name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Exception code: 0xc0000005
Fault offset: 0x0004e010
Faulting process id: 0x1f84
Faulting application start time: 0x01d29c96e1ec1386
Faulting application path: C:\Users\Electrike\Downloads\aswMBR.exe
Faulting module path: C:\Users\Electrike\Downloads\aswMBR.exe
Report Id: c9f865c4-088a-11e7-baa7-f81654f7d0d1
 
Error: (03/14/2017 11:48:56 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0
 
Error: (03/14/2017 11:48:56 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0
 
Error: (03/14/2017 11:48:56 AM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0
 
Error: (03/13/2017 05:02:58 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0
 
Error: (03/13/2017 05:02:58 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=25, authorId=9, vendorId=0, vendorType=0
 
Error: (03/13/2017 05:02:58 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=17, authorId=9, vendorId=0, vendorType=0
 
Error: (03/13/2017 04:48:25 PM) (Source: Microsoft-Windows-EapHost) (EventID: 2002) (User: NT AUTHORITY)
Description: Skipping: Eap method DLL path name validation failed. Error: typeId=43, authorId=9, vendorId=0, vendorType=0
 
 
System errors:
=============
Error: (03/14/2017 03:59:27 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer CHARMANDER
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0326CB5A-1274-4DD9-8EB4-1BE8C95AE083}.
The master browser is stopping or an election is being forced.
 
Error: (03/14/2017 01:35:30 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer CHARMANDER
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0326CB5A-1274-4DD9-8EB4-1BE8C95AE083}.
The master browser is stopping or an election is being forced.
 
Error: (03/14/2017 12:06:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Steam Client Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (03/14/2017 12:06:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Steam Client Service service to connect.
 
Error: (03/14/2017 11:52:29 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Provider Host service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
 
Error: (03/14/2017 11:49:38 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Superfetch service terminated with the following error: 
The system cannot find the file specified.
 
Error: (03/14/2017 11:49:00 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
VBoxNetAdp
 
Error: (03/14/2017 11:48:57 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Kaspersky Anti-Virus Service 16.0.0 service failed to start due to the following error: 
The system cannot find the path specified.
 
Error: (03/14/2017 11:48:49 AM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!
 
Error: (03/13/2017 07:28:14 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer CHARMANDER
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{0326CB5A-1274-4DD9-8EB4-1BE8C95AE083}.
The master browser is stopping or an election is being forced.
 
 
CodeIntegrity:
===================================
  Date: 2016-01-22 13:37:14.199
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-22 13:37:14.198
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-22 13:37:14.196
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-22 13:37:14.194
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-22 13:37:14.193
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-01-22 13:37:14.192
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.0\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-4710HQ CPU @ 2.50GHz
Percentage of memory in use: 34%
Total physical RAM: 16302.39 MB
Available physical RAM: 10661.18 MB
Total Virtual: 16300.58 MB
Available Virtual: 10371.83 MB
 
==================== Drives ================================
 
Drive b: (FRAPS) (Fixed) (Total:931.51 GB) (Free:867.86 GB) NTFS
Drive c: (SYSTEM) (Fixed) (Total:103.99 GB) (Free:21.62 GB) NTFS
Drive e: (Game Drive) (Fixed) (Total:1863.01 GB) (Free:1332.86 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: E71727C5)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 119.2 GB) (Disk ID: AEFDE666)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=260 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=104 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 69318C77)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#5 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 14 March 2017 - 05:04 AM

You have a lot going on on this system, not all bad but just so many games and programs it could be hard to try to determine whats causing the issues

 

Is your audio working ok, its possible that the file is infected, you can try uploading it to Jotti

 

You need to Enable Windows to Show all Files and Folders, you can find the instructions Here
 
Go to Jotti's Malware Scan and submit this file for analysis. Just Choose file and then Submit file , when done and the report loads just copy and paste the URL back into this thread for me to see
 
C:\Windows\system32\Audiosrv.dll<--This file
 
 
 
 
Did you set these group policies ?
 
HKLM Group Policy restriction on software: C:\Windows\System32\VSSAdmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.WSF <====== ATTENTION
HKLM Group Policy restriction on software: *.JSE <====== ATTENTION
HKLM Group Policy restriction on software: *.JS <====== ATTENTION
HKLM Group Policy restriction on software: %appdata% <====== ATTENTION
HKLM Group Policy restriction on software: *.WSH <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile% <====== ATTENTION
HKLM Group Policy restriction on software: *.VBE <====== ATTENTION
HKLM Group Policy restriction on software: *.VBS <====== ATTENTION
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION

 



 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#6 Nub

Nub

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 14 March 2017 - 06:52 AM

Heh, I didn't want to clog the thread up with all that stuff which is why I just attached the .txt files instead....looks like you don't care.....but other forums *do* care if you clog it up with all this stuff on it....and I've sort of defaulted on that thinking....

You have a lot going on on this system, not all bad but just so many games and programs it could be hard to try to determine whats causing the issues

 

Is your audio working ok, its possible that the file is infected, you can try uploading it to Jotti

 

You need to Enable Windows to Show all Files and Folders, you can find the instructions Here
 
Go to Jotti's Malware Scan and submit this file for analysis. Just Choose file and then Submit file , when done and the report loads just copy and paste the URL back into this thread for me to see
 
C:\Windows\system32\Audiosrv.dll<--This file

Hm, yeah...well I do play games a lot! Hahaha :weee: :lol: :P ^_^ Not so much on the programs side... well at least not as much as others who are hardcored video editors and such! 

 

Audio is working fine, no problems even since the trojan was first stopped by KIS 2016! :)

 

Hmmm, looks like the file does *not* exists...... :scratch:

1_2.png

 

I tried using the drag and drop method and get this(Oh this is on Opera, on Firefox it seems to be stuck on uploading...):

recent.png

 

Firefox:

3_2.png

 

:scratch: ...tried it on the equivalent website called virustotal and got this(I used the drag and drop method as using the other method also came back with the file does not exist....and I can't even select it either so had to type in the full filename...same with the other scanner too but forgot to mention!  :blush: ):

qwd1.png

 

Looks like someone or something, I highly doubt Kaspersky is actively blocking this, doesn't want us uploading the full file....which is 665KB in size according to my window:

1_2.png

 

I can upload and scan the other files fine that are around there...but not this specific file for some reason...or at least the full version and not a zero byte file if going by virustotal...

 

Hmm....it could be that you can't scan the file if it's being opened? No that can't be it....I just scanned firefox.exe and firefox is opened and that went through fine....and did it on Opera as well...

 


Did you set these group policies ?
 
HKLM Group Policy restriction on software: C:\Windows\System32\VSSAdmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.WSF <====== ATTENTION
HKLM Group Policy restriction on software: *.JSE <====== ATTENTION
HKLM Group Policy restriction on software: *.JS <====== ATTENTION
HKLM Group Policy restriction on software: %appdata% <====== ATTENTION
HKLM Group Policy restriction on software: *.WSH <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile% <====== ATTENTION
HKLM Group Policy restriction on software: *.VBE <====== ATTENTION
HKLM Group Policy restriction on software: *.VBS <====== ATTENTION
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION

 

You mean here:

2_2.png

 

? If so yeah.....it's supposed to be an added layer of security on top of what I already have..... :thumbup: I did ask this sometime ago.......and you guys suggested I go to a more specialized forum for an answer......but forgot to and just kinda lived with what I had here.....might have to post on those specialized forums, windows 7 forums, for example, and ask what they think about it... But anyways, so far so good, it seems to be doing a good job ....but not good enough to stop this trojan from installing itself somehow....not even sure how it did as I was told/read that most of the malware run from the appdate path and roaming folders....but since they're all blocked off.....well most of the time, not all of the times, as I had to unblock it to run some programs.....*gasps* :huh: :o :smack: :oops: --it might have slipped through those intervals I had it unblocked!  :smack:  :smack:  :smack:  :smack: :wall: :unsure: ...what quick and smart badboy(s) - is there more than one? If that's how it got through my defenses!

 

EDIT: Hmmm

1_2.png

 

Fancy that even Spybot can't scan it......yet adds entries to the other files fine.....it's empty.... Malwarebyts, SUPERAntiSpyware and KIS 2016 is able to scan it and came clean...maybe they were also scanning the zero byte file, mmm?


Edited by Nub, 14 March 2017 - 07:08 AM.


#7 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 14 March 2017 - 07:59 AM

I prefer to have the logs copied and pasted to the threads in lieu of attaching them but there is no reason to post and quote what I posted as my previous posts do not go away

 

 

 

You have some programs may be blocking you from doing things, try disabling Spybots tea timer

https://forums.spybo...abling-Teatimer

 

 

 

Open notepad , Go to Start --> All Programs --> Accessories --> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
FF Extension: (No Name) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2017-03-11] [not signed]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
S4 TBS; %SystemRoot%\System32\tbssvc.dll [X]
U3 aswMBR; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
CMD: ipconfig /flushdns
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

 

 

 



 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#8 Nub

Nub

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 14 March 2017 - 08:39 AM

I prefer to have the logs copied and pasted to the threads in lieu of attaching them but there is no reason to post and quote what I posted as my previous posts do not go away

Fair enough. Sorry it's a habit I've now picked up by using the quoting system throughout my foruming experiences.... :P They may not go away, but at least I am answering to whatever it was/is the answer was for rather than you go back and re-read what you had before and go "Uhh, that's what he was on about" where you can just go "Oh, that's what you're on about" without having to look back what my answer was targeted to.... ;)

 

 

You have some programs may be blocking you from doing things, try disabling Spybots tea timer

https://forums.spybo...abling-Teatimer

 

No, that still did not allow Jotti's malware scanner to upload the file successfully and scan it....also here, take a look at this screenshot:

1_2.png

 

Notice anything...strange? Well I've basically marked it out for you! Bahahaha :P :lol:  Just wanted you to take note on that's all.....nothing else happening there besides those files(yes there is more than one file that is hidden from that browser window) being hidden and yes I had the "Hide protected operating system files (Recommended)" checkbox, unticked, "Hide extentions for known file types" unticked and had a mark for"Show hidden files, folders, and drives" on. :huh:

 

 

Open notepad , Go to Start --> All Programs --> Accessories --> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL = 
FF Extension: (No Name) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2017-03-11] [not signed]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
S4 TBS; %SystemRoot%\System32\tbssvc.dll [X]
U3 aswMBR; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
CMD: ipconfig /flushdns
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

 

Here ya go:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 13-03-2017
Ran by Manectric (14-03-2017 22:22:17) Run:1
Running from C:\Users\Electrike\Desktop
Loaded Profiles: Manectric & Electrike (Available Profiles: Manectric & Electrike)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
Winsock: Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {B0C9ACC6-6B01-470F-B98A-DCC12B58795A} URL =
FF Extension: (No Name) - C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2017-03-11] [not signed]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
S4 TBS; %SystemRoot%\System32\tbssvc.dll [X]
U3 aswMBR; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\MANECT~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************

Processes closed successfully.
Error: (0) Failed to create a restore point.
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000007 => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000008 => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000007 => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries64\000000000008 => key removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer => key removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B0C9ACC6-6B01-470F-B98A-DCC12B58795A} => key removed successfully
HKCR\CLSID\{B0C9ACC6-6B01-470F-B98A-DCC12B58795A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B0C9ACC6-6B01-470F-B98A-DCC12B58795A} => key removed successfully
HKCR\Wow6432Node\CLSID\{B0C9ACC6-6B01-470F-B98A-DCC12B58795A} => key not found.
C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} => moved successfully
C:\Users\Manectric\AppData\Roaming\Mozilla\Firefox\Profiles\ipvqxq4h.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} => path removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully
HKLM\System\CurrentControlSet\Services\TBS => key removed successfully
TBS => service removed successfully
HKLM\System\CurrentControlSet\Services\aswMBR => key removed successfully
aswMBR => service removed successfully
HKLM\System\CurrentControlSet\Services\aswVmm => key removed successfully
aswVmm => service removed successfully

========= ipconfig /flushdns =========


Windows IP Configuration

Could not flush the DNS Resolver Cache: Function failed during execution.


========= End of CMD: =========


=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 9680196 B
Java, Flash, Steam htmlcache => 33835920 B
Windows/system/drivers => 4351824 B
Edge => 0 B
Chrome => 0 B
Firefox => 4178208 B
Opera => 113664 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 16802 B
systemprofile32 => 66088 B
LocalService => 0 B
NetworkService => 0 B
Manectric => 410429951 B
Electrike => 2195948 B

RecycleBin => 0 B
EmptyTemp: => 443.3 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 22:22:21 ====



#9 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 14 March 2017 - 08:48 AM

Lets see if ESET finds anything

 

3330203e-7304-4336-aa0a-eb3d8b6e3b35_zps
 
  •  
  • Please be patient, depending on your system the scan can complete in 30 minutes and on others much longer.
  • You want the Online One-Time Scan
  • Note: It will run using Internet Explorer, Firefox or Chome.
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is NOT TICKED, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
 


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#10 Nub

Nub

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 14 March 2017 - 09:02 AM

Whilst I wait for ESET to update its definition database and scan, I wanna show you the TDSSK log I did earlier with the guide of that pdf I linked:

 

19:35:05.0869 0x2680  TDSS rootkit removing tool 3.1.0.12 Nov  7 2016 07:10:01
19:35:11.0268 0x2680  ============================================================
19:35:11.0268 0x2680  Current date / time: 2017/03/12 19:35:11.0268
19:35:11.0268 0x2680  SystemInfo:
19:35:11.0268 0x2680  
19:35:11.0268 0x2680  OS Version: 6.1.7601 ServicePack: 1.0
19:35:11.0268 0x2680  Product type: Workstation
19:35:11.0268 0x2680  ComputerName: RAIKOU
19:35:11.0268 0x2680  UserName: Manectric
19:35:11.0268 0x2680  Windows directory: C:\Windows
19:35:11.0268 0x2680  System windows directory: C:\Windows
19:35:11.0268 0x2680  Running under WOW64
19:35:11.0268 0x2680  Processor architecture: Intel x64
19:35:11.0268 0x2680  Number of processors: 8
19:35:11.0268 0x2680  Page size: 0x1000
19:35:11.0268 0x2680  Boot type: Normal boot
19:35:11.0268 0x2680  CodeIntegrityOptions = 0x00000001
19:35:11.0268 0x2680  ============================================================
19:35:11.0440 0x2680  KLMD registered as C:\Windows\system32\drivers\79711858.sys
19:35:11.0440 0x2680  KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.23572, osProperties = 0x1
19:35:11.0541 0x2680  System UUID: {E31D36F3-3314-3CA9-1C4D-00FB41EB199B}
19:35:12.0130 0x2680  Drive \Device\Harddisk0\DR0 - Size: 0x1D1C1116000 ( 1863.02 Gb ), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:35:12.0134 0x2680  Drive \Device\Harddisk1\DR1 - Size: 0x1DCF856000 ( 119.24 Gb ), SectorSize: 0x200, Cylinders: 0x3CCE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:35:12.0137 0x2680  Drive \Device\Harddisk2\DR2 - Size: 0xE8E0DB6000 ( 931.51 Gb ), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
19:35:12.0142 0x2680  Drive \Device\Harddisk3\DR3 - Size: 0xE70000000 ( 57.75 Gb ), SectorSize: 0x200, Cylinders: 0x1D72, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
19:35:12.0143 0x2680  ============================================================
19:35:12.0143 0x2680  \Device\Harddisk0\DR0:
19:35:12.0143 0x2680  MBR partitions:
19:35:12.0143 0x2680  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E078B0
19:35:12.0143 0x2680  \Device\Harddisk1\DR1:
19:35:12.0143 0x2680  MBR partitions:
19:35:12.0143 0x2680  \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x1E00800, BlocksNum 0x82000
19:35:12.0143 0x2680  \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0x1E82800, BlocksNum 0xCFF9000
19:35:12.0143 0x2680  \Device\Harddisk2\DR2:
19:35:12.0144 0x2680  MBR partitions:
19:35:12.0144 0x2680  \Device\Harddisk2\DR2\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x74705800
19:35:12.0144 0x2680  \Device\Harddisk3\DR3:
19:35:12.0144 0x2680  MBR partitions:
19:35:12.0144 0x2680  \Device\Harddisk3\DR3\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x737F800
19:35:12.0144 0x2680  ============================================================
19:35:12.0145 0x2680  C: <-> \Device\Harddisk1\DR1\Partition2
19:35:12.0174 0x2680  E: <-> \Device\Harddisk0\DR0\Partition1
19:35:12.0177 0x2680  B: <-> \Device\Harddisk2\DR2\Partition1
19:35:12.0177 0x2680  ============================================================
19:35:12.0177 0x2680  Initialize success
19:35:12.0177 0x2680  ============================================================
19:35:30.0216 0x230c  ============================================================
19:35:30.0216 0x230c  Scan started
19:35:30.0216 0x230c  Mode: Manual; SigCheck; TDLFS;
19:35:30.0216 0x230c  ============================================================
19:35:30.0216 0x230c  KSN ping started
19:35:31.0190 0x230c  KSN ping finished: true
19:35:32.0632 0x230c  ================ Scan system memory ========================
19:35:32.0633 0x230c  System memory - ok
19:35:32.0633 0x230c  ================ Scan services =============================
19:35:32.0638 0x230c  [ 98E06CAC2C508118450095E581202230, 8FC6C08487F2A481A28F1E5E500B61A21B7A0D44B342F9F887017D6FAE4F87F4 ] !SASCORE        C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
19:35:32.0677 0x230c  !SASCORE - ok
19:35:32.0709 0x230c  [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C1DD0844ADA9A8F ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
19:35:32.0734 0x230c  1394ohci - ok
19:35:32.0742 0x230c  [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E21C68E18B22E002 ] ACPI            C:\Windows\system32\drivers\ACPI.sys
19:35:32.0766 0x230c  ACPI - ok
19:35:32.0769 0x230c  [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC56320E48119F15F76 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
19:35:32.0789 0x230c  AcpiPmi - ok
19:35:32.0795 0x230c  [ B932E0EE190778D840F1442DFC0F9612, 8780963F14D57279FDD585BE945ED40F24590D32676C7A9EF94002D38B8BA643 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
19:35:32.0806 0x230c  AdobeARMservice - ok
19:35:32.0823 0x230c  [ 874B1D3B016BB6051EED24E6F94DA18B, 7E5898F2A54CC014693BAC86BCCE5861E70A8FAA07D837589BE3CB47458665BB ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
19:35:32.0836 0x230c  AdobeFlashPlayerUpdateSvc - ok
19:35:32.0847 0x230c  [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4ABC2D2F75B5735 ] adp94xx         C:\Windows\system32\drivers\adp94xx.sys
19:35:32.0868 0x230c  adp94xx - ok
19:35:32.0876 0x230c  [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B46FE4605E59BDC ] adpahci         C:\Windows\system32\drivers\adpahci.sys
19:35:32.0900 0x230c  adpahci - ok
19:35:32.0906 0x230c  [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F43FB17566EE5559 ] adpu320         C:\Windows\system32\drivers\adpu320.sys
19:35:32.0924 0x230c  adpu320 - ok
19:35:32.0929 0x230c  [ 262D7C87D0AC20B96EF9877D3CA478A0, 54F7E5A5F8991C5525500C1ECCF3D3135D13F48866C366E52DF1D052DB2EE15B ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
19:35:32.0942 0x230c  AeLookupSvc - ok
19:35:32.0953 0x230c  [ 9A4A1EEE802BF2F878EE8EAB407B21B7, 177EB7DF4B35FE4C0E45E775A0FD5D48D39B410052E3EE18BDEEC809E152D9D8 ] AFD             C:\Windows\system32\drivers\afd.sys
19:35:32.0978 0x230c  AFD - ok
19:35:32.0981 0x230c  [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491602F370C09282A ] agp440          C:\Windows\system32\drivers\agp440.sys
19:35:32.0997 0x230c  agp440 - ok
19:35:33.0000 0x230c  [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1F601725B889663 ] ALG             C:\Windows\System32\alg.exe
19:35:33.0013 0x230c  ALG - ok
19:35:33.0017 0x230c  [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED0945FF6A966721 ] aliide          C:\Windows\system32\drivers\aliide.sys
19:35:33.0031 0x230c  aliide - ok
19:35:33.0034 0x230c  [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1EA1346EA0A02720 ] amdide          C:\Windows\system32\drivers\amdide.sys
19:35:33.0048 0x230c  amdide - ok
19:35:33.0051 0x230c  [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F492FFC821BF529 ] AmdK8           C:\Windows\system32\drivers\amdk8.sys
19:35:33.0068 0x230c  AmdK8 - ok
19:35:33.0071 0x230c  [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D622624531D27487 ] AmdPPM          C:\Windows\system32\drivers\amdppm.sys
19:35:33.0087 0x230c  AmdPPM - ok
19:35:33.0091 0x230c  [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF19F391D52FA01D0 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
19:35:33.0108 0x230c  amdsata - ok
19:35:33.0114 0x230c  [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A2DD21FEF1DC1A8 ] amdsbs          C:\Windows\system32\drivers\amdsbs.sys
19:35:33.0133 0x230c  amdsbs - ok
19:35:33.0136 0x230c  [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E02704800F886A3065F ] amdxata         C:\Windows\system32\drivers\amdxata.sys
19:35:33.0150 0x230c  amdxata - ok
19:35:33.0153 0x230c  [ FCE5C79717A487BDC71F3DEC78A684CA, F5520F112A4EBDD10444AA5E9FDB9125219FCF768FEB95AB608BC84D60136816 ] AppID           C:\Windows\system32\drivers\appid.sys
19:35:33.0173 0x230c  AppID - ok
19:35:33.0175 0x230c  [ 8921E1D8AE5171691F186A7C5B98B630, 4A37313BB94D4B49D0294C9439AD0793DE328F9F4DA1C47E34E6ACEA46AF6E14 ] AppIDSvc        C:\Windows\System32\appidsvc.dll
19:35:33.0185 0x230c  AppIDSvc - ok
19:35:33.0188 0x230c  [ DE23E052E557580674785CDF45B613F3, A955ADC6CC7D816BA7CE1065F911E7A3295A1908C22BE0A3C506C38CFEE8DE0D ] Appinfo         C:\Windows\System32\appinfo.dll
19:35:33.0198 0x230c  Appinfo - ok
19:35:33.0204 0x230c  [ 4ABA3E75A76195A3E38ED2766C962899, E2001ACD44DA270B8289DA362D26416676301773AB22616C211F31CF2E7869AA ] AppMgmt         C:\Windows\System32\appmgmts.dll
19:35:33.0217 0x230c  AppMgmt - ok
19:35:33.0222 0x230c  [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78AEED7E9953311F6 ] arc             C:\Windows\system32\drivers\arc.sys
19:35:33.0236 0x230c  arc - ok
19:35:33.0240 0x230c  [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4A45A3E6C42C72A ] arcsas          C:\Windows\system32\drivers\arcsas.sys
19:35:33.0256 0x230c  arcsas - ok
19:35:33.0264 0x230c  [ EE424A5CE56E3923D59BB7DE2E15036D, 8B8196870EFE74D43EDA72674021A46846D370E97A6A058134D84A721AECD091 ] aspnet_state    C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
19:35:33.0273 0x230c  aspnet_state - ok
19:35:33.0275 0x230c  [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D368E292043D4D26 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
19:35:33.0316 0x230c  AsyncMac - ok
19:35:33.0322 0x230c  [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB4E225E18DC5273 ] atapi           C:\Windows\system32\drivers\atapi.sys
19:35:33.0336 0x230c  atapi - ok
19:35:33.0349 0x230c  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
19:35:33.0372 0x230c  AudioEndpointBuilder - ok

19:35:33.0383 0x230c  [ 67C717EC24FCAAE7B518D9E06AD036AB, F08550E4FCEC2899FACEF2A18CEE3D068D5911FFD2FF5534E4921E56FB0AEF59 ] AudioSrv        C:\Windows\System32\Audiosrv.dll
19:35:33.0402 0x230c  AudioSrv - ok

19:35:33.0415 0x230c  [ 09F0E4D1F66C40AB770AD1540758C59E, 78591F6B94B5A5B9A6D434AC54A0BD5D606099A6FE48B25D17B2E01942CAEAE3 ] AVP16.0.1       C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe
19:35:33.0431 0x230c  AVP16.0.1 - ok
19:35:33.0436 0x230c  [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49E575E95628753F ] AxInstSV        C:\Windows\System32\AxInstSV.dll
19:35:33.0449 0x230c  AxInstSV - ok
19:35:33.0459 0x230c  [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864D59F3D51D8D580 ] b06bdrv         C:\Windows\system32\drivers\bxvbda.sys
19:35:33.0481 0x230c  b06bdrv - ok
19:35:33.0489 0x230c  [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D331AE0CB7679FA ] b57nd60a        C:\Windows\system32\DRIVERS\b57nd60a.sys
19:35:33.0511 0x230c  b57nd60a - ok
19:35:33.0516 0x230c  [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F2382500B713B82 ] BDESVC          C:\Windows\System32\bdesvc.dll
19:35:33.0528 0x230c  BDESVC - ok
19:35:33.0531 0x230c  [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F4130336B838024 ] Beep            C:\Windows\system32\drivers\Beep.sys
19:35:33.0561 0x230c  Beep - ok
19:35:33.0574 0x230c  [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A7EC62505C29A4A ] BFE             C:\Windows\System32\bfe.dll
19:35:33.0596 0x230c  BFE - ok
19:35:33.0613 0x230c  [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CDDAD9F79D60FA04 ] BITS            C:\Windows\System32\qmgr.dll
19:35:33.0666 0x230c  BITS - ok
19:35:33.0669 0x230c  [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F198A00BB47A9811 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
19:35:33.0685 0x230c  blbdrive - ok
19:35:33.0707 0x230c  [ FEFF60CA0FBC86A043495FA79581CEA9, E8C4762AB9168C59DE6BABF6CEF5D02918D79F255FA86E7EA4324384C91733D0 ] Bluetooth Device Monitor C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
19:35:33.0733 0x230c  Bluetooth Device Monitor - ok
19:35:33.0764 0x230c  [ C4477B9FD0B11BB2B0D1F459483AE6F8, F43E94AB8A83C97BB92AFAE9F466C231EB5893B998FF2344C47AC0552F3D159A ] Bluetooth Media Service C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
19:35:33.0795 0x230c  Bluetooth Media Service - ok
19:35:33.0816 0x230c  [ 075D93A7094E1BCBDE3A2D8EBA803745, 9E141EB26358D5B526D30A224DBF4EBE00EFAA19A78A22881AAF5E51C20DBED6 ] Bluetooth OBEX Service C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
19:35:33.0840 0x230c  Bluetooth OBEX Service - ok
19:35:33.0845 0x230c  [ ABA3984C822E4D3F889699912D85D6C5, 2251FA135CC290DA13DAE4743F393C7CC9E6A737C054707CB8D72C369D1FFACB ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
19:35:33.0865 0x230c  bowser - ok
19:35:33.0868 0x230c  [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17383487180E84E3 ] BrFiltLo        C:\Windows\system32\drivers\BrFiltLo.sys
19:35:33.0884 0x230c  BrFiltLo - ok
19:35:33.0886 0x230c  [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888054BBC3A3EB92C ] BrFiltUp        C:\Windows\system32\drivers\BrFiltUp.sys
19:35:33.0902 0x230c  BrFiltUp - ok
19:35:33.0907 0x230c  [ 05F5A0D14A2EE1D8255C2AA0E9E8E694, 40011138869F5496A3E78D38C9900B466B6F3877526AC22952DCD528173F4645 ] Browser         C:\Windows\System32\browser.dll
19:35:33.0919 0x230c  Browser - ok
19:35:33.0927 0x230c  [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF61BABD58AB10272 ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
19:35:33.0953 0x230c  Brserid - ok
19:35:33.0955 0x230c  [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396FB6599721586B0C ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
19:35:33.0972 0x230c  BrSerWdm - ok
19:35:33.0975 0x230c  [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46AF7C3C77F331983 ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
19:35:33.0990 0x230c  BrUsbMdm - ok
19:35:33.0993 0x230c  [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19507008629709C9 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
19:35:34.0007 0x230c  BrUsbSer - ok
19:35:34.0010 0x230c  [ CF98190A94F62E405C8CB255018B2315, E1B2540023C4FE9FD588E4B6AE6347DFA565EB3898F21E5360882BF3E8B5E781 ] BthEnum         C:\Windows\system32\DRIVERS\BthEnum.sys
19:35:34.0027 0x230c  BthEnum - ok
19:35:34.0047 0x230c  [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C7B1D58A4FD25A4 ] BTHMODEM        C:\Windows\system32\drivers\bthmodem.sys
19:35:34.0068 0x230c  BTHMODEM - ok
19:35:34.0073 0x230c  [ 02DD601B708DD0667E1331FA8518E9FF, 7DE6CC4DBB621CD03B01D9CE6CF66EAFE31D39030A391562CD0E278E1D70ADE1 ] BthPan          C:\Windows\system32\DRIVERS\bthpan.sys
19:35:34.0091 0x230c  BthPan - ok
19:35:34.0103 0x230c  [ 738D0E9272F59EB7A1449C3EC118E6C4, FE3D32C2A5E4DC21376A0F89C0B2EE024ECF1A3FB99213CC9BBC986ADF7AF080 ] BTHPORT         C:\Windows\system32\Drivers\BTHport.sys
19:35:34.0127 0x230c  BTHPORT - ok
19:35:34.0132 0x230c  [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF14F443D881C9F34 ] bthserv         C:\Windows\system32\bthserv.dll
19:35:34.0155 0x230c  bthserv - ok
19:35:34.0162 0x230c  [ F188B7394D81010767B6DF3178519A37, 576304E92FD94908F093A6AB5F4D328F25829BE32EC3CA0D29EBFDF5DE83539B ] BTHUSB          C:\Windows\system32\Drivers\BTHUSB.sys
19:35:34.0179 0x230c  BTHUSB - ok
19:35:34.0184 0x230c  [ 70F8310E8B36DFCAD9A11720929E20ED, 1E591FE15F59474CD9D9241197F7EB784F331B800BA2DCF9F5680D4408CE0D9C ] btmaux          C:\Windows\system32\DRIVERS\btmaux.sys
19:35:34.0201 0x230c  btmaux - ok
19:35:34.0227 0x230c  [ F7C23035D12C568E71353F76D3B6765B, 7344BD45CC0B57D63E48759F0DB756FE884500159040EE2C18094B4001B8D5DD ] btmhsf          C:\Windows\system32\DRIVERS\btmhsf.sys
19:35:34.0262 0x230c  btmhsf - ok
19:35:34.0267 0x230c  [ 71CCE3A6FF39B5E8998E839687E5A9FB, C6B3778F33A16D75D311143941B90190C6DA2EEE93FABA7C6B535C46577FC070 ] btmlehid        C:\Windows\system32\drivers\btmlehid.sys
19:35:34.0281 0x230c  btmlehid - ok
19:35:34.0285 0x230c  [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160D7C7DC6E717D65 ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
19:35:34.0316 0x230c  cdfs - ok
19:35:34.0321 0x230c  [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B9A2199B6713D5B ] cdrom           C:\Windows\system32\DRIVERS\cdrom.sys
19:35:34.0339 0x230c  cdrom - ok
19:35:34.0343 0x230c  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] CertPropSvc     C:\Windows\System32\certprop.dll
19:35:34.0368 0x230c  CertPropSvc - ok
19:35:34.0371 0x230c  [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B96EC6E252E1C64 ] circlass        C:\Windows\system32\drivers\circlass.sys
19:35:34.0390 0x230c  circlass - ok
19:35:34.0397 0x230c  [ 3D67C27DD17B254D7915FA16A5AE3573, 5B3A6C6A7F940C06362775DAF13CEADA37C7AA84A509458A57C23B4369970A90 ] CLFS            C:\Windows\system32\CLFS.sys
19:35:34.0411 0x230c  CLFS - ok
19:35:34.0416 0x230c  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
19:35:34.0425 0x230c  clr_optimization_v2.0.50727_32 - ok
19:35:34.0429 0x230c  [ B4D73F04E9BC076F7CDAC4327DF636BB, 1ADED20D5A0D0A76E2F85CB778FD06BAB814868D35F8532E17D67045FF4770C2 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
19:35:34.0437 0x230c  clr_optimization_v2.0.50727_64 - ok
19:35:34.0443 0x230c  [ 5BAF4F1296D4D91FC28560CDB4C37C4B, ACA4BC57ED1F8432F18F0F215EC7FF956BAEF6E02760779E264E4008A979E9DD ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
19:35:34.0454 0x230c  clr_optimization_v4.0.30319_32 - ok
19:35:34.0458 0x230c  [ 569B54004A7E85A74FD92841DE6058E2, 58949313D0F6B1C06359B2F3C68E29940B1655A17E93FFC3718F6D2EAE1633E4 ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
19:35:34.0469 0x230c  clr_optimization_v4.0.30319_64 - ok
19:35:34.0472 0x230c  [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D768DFC87999A9C3A ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
19:35:34.0487 0x230c  CmBatt - ok
19:35:34.0489 0x230c  [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52592C9342E0E18B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
19:35:34.0503 0x230c  cmdide - ok
19:35:34.0512 0x230c  [ B2A6D2A30E93B6F215F74AC7E1733C9C, 960299F7BF2501B46296EDEA050BF30313C17A9B785574B56B79C070BD1B6E1A ] cm_km           C:\Windows\system32\DRIVERS\cm_km.sys
19:35:34.0537 0x230c  cm_km - ok
19:35:34.0547 0x230c  [ A98CED39AD91B445E2E442A9BD67E8B4, B4189DEEF1C0EE22AE983119047B1A40FFDD8F3E163DFFABD7C2706231B0B1B0 ] CNG             C:\Windows\system32\Drivers\cng.sys
19:35:34.0566 0x230c  CNG - ok
19:35:34.0569 0x230c  [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8FEA5D4666E1BF1 ] Compbatt        C:\Windows\system32\drivers\compbatt.sys
19:35:34.0583 0x230c  Compbatt - ok
19:35:34.0585 0x230c  [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E512505FC2B6CC224959 ] CompositeBus    C:\Windows\system32\DRIVERS\CompositeBus.sys
19:35:34.0603 0x230c  CompositeBus - ok
19:35:34.0605 0x230c  COMSysApp - ok
19:35:34.0620 0x230c  [ 2DABFF8ACA637B9AA8DD65518408A362, EABE794AC842FA491724E51DB56844DFAC6234DF6E2DF8FA8E0009CAE108EBF2 ] cphs            C:\Windows\SysWow64\IntelCpHeciSvc.exe
19:35:34.0633 0x230c  cphs - ok
19:35:34.0636 0x230c  [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69EC38E2DC3972E60 ] crcdisk         C:\Windows\system32\drivers\crcdisk.sys
19:35:34.0650 0x230c  crcdisk - ok
19:35:34.0657 0x230c  [ 2C6632CECFDBBE793FDA8AF9CA55A9CC, 335188515F798483660E529204A13012E4D21B0ECA489224A11C26F91A5B3CCE ] CryptSvc        C:\Windows\system32\cryptsvc.dll
19:35:34.0671 0x230c  CryptSvc - ok
19:35:34.0682 0x230c  [ 54DA3DFD29ED9F1619B6F53F3CE55E49, 9177C6907A983296BF188892A894B668A09FFA058FD56B50FE12940D54B0FA5E ] CSC             C:\Windows\system32\drivers\csc.sys
19:35:34.0706 0x230c  CSC - ok
19:35:34.0719 0x230c  [ 3AB183AB4D2C79DCF459CD2C1266B043, 72B0187EBA9DC74E61EC5CB3DC24058DDB768843E865801894AAEAA211610C56 ] CscService      C:\Windows\System32\cscsvc.dll
19:35:34.0740 0x230c  CscService - ok
19:35:34.0752 0x230c  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] DcomLaunch      C:\Windows\system32\rpcss.dll
19:35:34.0770 0x230c  DcomLaunch - ok
19:35:34.0778 0x230c  [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC39D086D32503AC5 ] defragsvc       C:\Windows\System32\defragsvc.dll
19:35:34.0810 0x230c  defragsvc - ok
19:35:34.0814 0x230c  [ 9B38580063D281A99E68EF5813022A5F, D91676B0E0A8E2A090E3E5DD340ABCFC20AE0F55B4C82869D6CFB34239BD27DA ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
19:35:34.0827 0x230c  DfsC - ok
19:35:34.0836 0x230c  [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D52D173430972B8 ] Dhcp            C:\Windows\system32\dhcpcore.dll
19:35:34.0852 0x230c  Dhcp - ok
19:35:34.0876 0x230c  [ EE9954237F15BE4DD9304D12E4D305ED, F295C9BAF20F0E669B673AFCC16B4969EE31B6A3808980DAB93D9B0F167DA3C0 ] DiagTrack       C:\Windows\system32\diagtrack.dll
19:35:34.0911 0x230c  DiagTrack - ok
19:35:34.0915 0x230c  [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089AEC68F241B05B26 ] discache        C:\Windows\system32\drivers\discache.sys
19:35:34.0946 0x230c  discache - ok
19:35:34.0950 0x230c  [ 616387BBD83372220B09DE95F4E67BBC, 5E2D5280BB775576E7CDE3FA6BDE494E183123635E5908CF7EBF1FF52966D07D ] Disk            C:\Windows\system32\drivers\disk.sys
19:35:34.0966 0x230c  Disk - ok
19:35:35.0049 0x230c  [ 54A22C7AA70469DA0F2674AE0B42A41C, 1476AD13A4DB941E92AE2824E6742140BC3AB87A250623C941460ACBCBCCBCD5 ] DisplayFusionService C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
19:35:35.0148 0x230c  DisplayFusionService - ok
19:35:35.0156 0x230c  [ 5DB085A8A6600BE6401F2B24EECB5415, 5FC5C7C1B4DB7BF6EFD0992E91DB41FD047E90D1ABA0B8F868CB72557F88FB13 ] dmvsc           C:\Windows\system32\drivers\dmvsc.sys
19:35:35.0174 0x230c  dmvsc - ok
19:35:35.0179 0x230c  [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB347312D034DC03E0242 ] Dnscache        C:\Windows\System32\dnsrslvr.dll
19:35:35.0192 0x230c  Dnscache - ok
19:35:35.0199 0x230c  [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B12716397657C7ADEEE807304 ] dot3svc         C:\Windows\System32\dot3svc.dll
19:35:35.0224 0x230c  dot3svc - ok
19:35:35.0229 0x230c  [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69407B26402311C7 ] DPS             C:\Windows\system32\dps.dll
19:35:35.0253 0x230c  DPS - ok
19:35:35.0255 0x230c  [ 26FE888505E5A945B0536AF9A2A27A6F, A6B16ED498BAFE300E1F0E0A241E3D62F7A1C5973EE775904ED14F33A2BC08A6 ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
19:35:35.0271 0x230c  drmkaud - ok
19:35:35.0289 0x230c  [ 3A9D7D464BDB3B70D7ECF689ADABBD4D, B4F5B23705EA1BA453FE30791CA245E1A5F7FBEABAD026E4A8A15A9FC44E8C9C ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
19:35:35.0313 0x230c  DXGKrnl - ok
19:35:35.0318 0x230c  [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5BF91818A8FAEA76 ] EapHost         C:\Windows\System32\eapsvc.dll
19:35:35.0342 0x230c  EapHost - ok
19:35:35.0344 0x230c  EasyAntiCheat - ok
19:35:35.0398 0x230c  [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24FF9E38E8853017 ] ebdrv           C:\Windows\system32\drivers\evbda.sys
19:35:35.0472 0x230c  ebdrv - ok
19:35:35.0478 0x230c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] EFS             C:\Windows\System32\lsass.exe
19:35:35.0489 0x230c  EFS - ok
19:35:35.0493 0x230c  [ E6CDC154435243E6676AFBB323FA2956, C6C30221A981F46C6F671F64E1CDE98874836E0C3048D2C7DC164F0941ED4E27 ] ElevateService  C:\Program Files\GIGABYTE\SmartManagerV3\ElevateService.exe
19:35:35.0496 0x230c  ElevateService - detected UnsignedFile.Multi.Generic ( 1 )
19:35:36.0352 0x230c  ElevateService ( UnsignedFile.Multi.Generic ) - warning
19:35:37.0701 0x230c  [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18FA7C2C172233F8 ] elxstor         C:\Windows\system32\drivers\elxstor.sys
19:35:37.0722 0x230c  elxstor - ok
19:35:37.0725 0x230c  [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D77F8A696616D75 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
19:35:37.0739 0x230c  ErrDev - ok
19:35:37.0750 0x230c  [ 3DAD84C5F865A45787EEFACF59355032, 6D42B71F6A34073DC44EB01138ECF033F47138AECD1019AD3D3A47B98648D7A1 ] ETD             C:\Windows\system32\DRIVERS\ETD.sys
19:35:37.0775 0x230c  ETD - ok
19:35:37.0786 0x230c  [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5C7460E87317881 ] EventSystem     C:\Windows\system32\es.dll
19:35:37.0817 0x230c  EventSystem - ok
19:35:37.0832 0x230c  [ A0F7DF30B3E110B70B9AE5304AA74053, 340435B40990DA444CE1A0A57C2B2DF2100C76DDFD3631FC425B7A6B7DBDC316 ] EvtEng          C:\Program Files\Intel\WiFi\bin\EvtEng.exe
19:35:37.0854 0x230c  EvtEng - ok
19:35:37.0861 0x230c  [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA1A5D2727E255F5 ] exfat           C:\Windows\system32\drivers\exfat.sys
19:35:37.0895 0x230c  exfat - ok
19:35:37.0901 0x230c  [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0CE5F629B328B29 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
19:35:37.0936 0x230c  fastfat - ok
19:35:37.0950 0x230c  [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3DE474C24366099 ] Fax             C:\Windows\system32\fxssvc.exe
19:35:37.0971 0x230c  Fax - ok
19:35:37.0974 0x230c  [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8BD433905BD2A0EE ] fdc             C:\Windows\system32\drivers\fdc.sys
19:35:37.0990 0x230c  fdc - ok
19:35:37.0993 0x230c  [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162AE317C6F1D8DFE ] fdPHost         C:\Windows\system32\fdPHost.dll
19:35:38.0016 0x230c  fdPHost - ok
19:35:38.0018 0x230c  [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A33983E06EB66AE19F8 ] FDResPub        C:\Windows\system32\fdrespub.dll
19:35:38.0041 0x230c  FDResPub - ok
19:35:38.0045 0x230c  [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0124C934272CD1A ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
19:35:38.0060 0x230c  FileInfo - ok
19:35:38.0063 0x230c  [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E12D25D0ADC51B6 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
19:35:38.0096 0x230c  Filetrace - ok
19:35:38.0098 0x230c  [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2F81009B169D77B ] flpydisk        C:\Windows\system32\drivers\flpydisk.sys
19:35:38.0114 0x230c  flpydisk - ok
19:35:38.0121 0x230c  [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C798099817CE5331 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
19:35:38.0145 0x230c  FltMgr - ok
19:35:38.0165 0x230c  [ 700A5373FA66F1DAAECBD2CFB88C73ED, D6C1C4C846BC24EB6539ECC701A456FA53BB6679C79391F5B70580D47B6CE395 ] FontCache       C:\Windows\system32\FntCache.dll
19:35:38.0195 0x230c  FontCache - ok
19:35:38.0199 0x230c  [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF69549009ED932A60F0 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
19:35:38.0206 0x230c  FontCache3.0.0.0 - ok
19:35:38.0209 0x230c  [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85EF6AE1363C0DA6E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
19:35:38.0224 0x230c  FsDepends - ok
19:35:38.0226 0x230c  fssfltr - ok
19:35:38.0230 0x230c  [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35880FF34D1DFE33 ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
19:35:38.0244 0x230c  Fs_Rec - ok
19:35:38.0251 0x230c  [ 8F6322049018354F45F05A2FD2D4E5E0, 73BF0FB4EBD7887E992DDEBB79E906958D6678F8D1107E8C368F5A0514D80359 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
19:35:38.0273 0x230c  fvevol - ok
19:35:38.0276 0x230c  [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE4300C37D9A36E6005 ] gagp30kx        C:\Windows\system32\drivers\gagp30kx.sys
19:35:38.0291 0x230c  gagp30kx - ok
19:35:38.0306 0x230c  [ E4AE497857409127ED57562AF913A903, 262ADD713B1FBF6200550967D1F8635B55D01BBD8FA2E753536E71A4EC87867B ] gpsvc           C:\Windows\System32\gpsvc.dll
19:35:38.0329 0x230c  gpsvc - ok
19:35:38.0332 0x230c  [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F88B65024928E19 ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
19:35:38.0348 0x230c  hcw85cir - ok
19:35:38.0356 0x230c  [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A770303C06799D915D9 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
19:35:38.0383 0x230c  HdAudAddService - ok
19:35:38.0388 0x230c  [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278479D0111A47955 ] HDAudBus        C:\Windows\system32\DRIVERS\HDAudBus.sys
19:35:38.0407 0x230c  HDAudBus - ok
19:35:38.0409 0x230c  [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF7132EFEDB9BD64 ] HidBatt         C:\Windows\system32\drivers\HidBatt.sys
19:35:38.0425 0x230c  HidBatt - ok
19:35:38.0429 0x230c  [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B554D4164B9FCD0D4 ] HidBth          C:\Windows\system32\drivers\hidbth.sys
19:35:38.0449 0x230c  HidBth - ok
19:35:38.0452 0x230c  [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777AB4233DCFDA01D ] HidIr           C:\Windows\system32\drivers\hidir.sys
19:35:38.0470 0x230c  HidIr - ok
19:35:38.0473 0x230c  [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A7891B1B545499631 ] hidserv         C:\Windows\system32\hidserv.dll
19:35:38.0496 0x230c  hidserv - ok
19:35:38.0499 0x230c  [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0F0B6C67B568A0F ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
19:35:38.0516 0x230c  HidUsb - ok
19:35:38.0519 0x230c  [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC5AEA93C8E05531 ] hkmsvc          C:\Windows\system32\kmsvc.dll
19:35:38.0542 0x230c  hkmsvc - ok
19:35:38.0548 0x230c  [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F14B940BE01CD2E1 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
19:35:38.0562 0x230c  HomeGroupListener - ok
19:35:38.0568 0x230c  [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62031CB007CFC208 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
19:35:38.0579 0x230c  HomeGroupProvider - ok
19:35:38.0583 0x230c  [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8AA3354664B1E205 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
19:35:38.0599 0x230c  HpSAMD - ok
19:35:38.0614 0x230c  [ F61634BEC53F73702A10DE69F6DCAF57, BBA7344CF3AB96A46D1A6F1D50F2758EA8D097FE558C38B4EF45C8C334AF96E1 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
19:35:38.0643 0x230c  HTTP - ok
19:35:38.0646 0x230c  [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3B5CAFB592A3D53 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
19:35:38.0661 0x230c  hwpolicy - ok
19:35:38.0664 0x230c  [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E54978154B314531CD ] i8042prt        C:\Windows\system32\DRIVERS\i8042prt.sys
19:35:38.0682 0x230c  i8042prt - ok
19:35:38.0708 0x230c  [ BA2C068FC92EF7232527FC66566F08FB, C25644A7F286F724181363C21D006A02D651D2B819086F7490B7F4B7869D1DF3 ] iaStorA         C:\Windows\system32\drivers\iaStorA.sys
19:35:38.0736 0x230c  iaStorA - ok
19:35:38.0741 0x230c  [ 6C99DF5B6A6EB1D8D6F3FD60A0C614D6, 66147DE733FDAEF14660663764E90313E7A2CE3C6467ABAB99F71D00B96C4EB3 ] IAStorDataMgrSvc C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
19:35:38.0748 0x230c  IAStorDataMgrSvc - ok
19:35:38.0751 0x230c  [ A60EB8258D6FC9220CEBB9D8E9FD6124, 9757E615E37FCEFD576610EE53147211666A1F99638069152F036FF52F576552 ] iaStorF         C:\Windows\system32\drivers\iaStorF.sys
19:35:38.0764 0x230c  iaStorF - ok
19:35:38.0773 0x230c  [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956062AAE99699385 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
19:35:38.0798 0x230c  iaStorV - ok
19:35:38.0806 0x230c  [ 7902CA35304134B670BE33F27AB416E8, 8C1FC851D189EAD3C9578442CC8E7F0B760361ED09AB56B094D26AFB6FC38B9D ] ibtusb          C:\Windows\system32\DRIVERS\ibtusb.sys
19:35:38.0824 0x230c  ibtusb - ok
19:35:38.0831 0x230c  [ 0EF1E8299F58E1369B067F7B65D9F773, BAFD8F6947E1D4D6F1CC0CC9EDAE7262E56831EE64518FD2E34DCAE4CC646F7B ] IDMWFP          C:\Windows\system32\DRIVERS\idmwfp.sys
19:35:38.0854 0x230c  IDMWFP - ok
19:35:38.0871 0x230c  [ C98A5B9D932430AD8EEBD3EF73756EF7, DF7E1D391A0F3345AD61154363922C27BD557DEEACE395A6A8A8A16BFD1BB9A8 ] idsvc           C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
19:35:38.0891 0x230c  idsvc - ok
19:35:38.0896 0x230c  IEEtwCollectorService - ok
19:35:38.0976 0x230c  [ 94383F4B913B0CA9DC1466DB83D0C067, 19247A02E6EE3556136962CE80410A7A94FFF2527760AD5A4E5EF570CDCC3803 ] igfx            C:\Windows\system32\DRIVERS\igdkmd64.sys
19:35:39.0082 0x230c  igfx - ok
19:35:39.0095 0x230c  [ 55ECDB4226F2405F48039CE545101278, 417D3BDE9A271648F1008026250E3EE49DE8F8E94B5C6973EF11FDBD632F9341 ] igfxCUIService1.0.0.0 C:\Windows\system32\igfxCUIService.exe
19:35:39.0108 0x230c  igfxCUIService1.0.0.0 - ok
19:35:39.0111 0x230c  [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3D9886C2FBDA4E4 ] iirsp           C:\Windows\system32\drivers\iirsp.sys
19:35:39.0125 0x230c  iirsp - ok
19:35:39.0141 0x230c  [ 344789398EC3EE5A4E00C52B31847946, 3DA5F08E4B46F4E63456AA588D49E39A6A09A97D0509880C00F327623DB6122D ] IKEEXT          C:\Windows\System32\ikeext.dll
19:35:39.0163 0x230c  IKEEXT - ok
19:35:39.0229 0x230c  [ 3AB7D8548788C167F970E87B5D829901, 6C7FF62B0DD2364E174212D646AA098CB6F53442170E0BBE235B5B4303B38D53 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
19:35:39.0315 0x230c  IntcAzAudAddService - ok
19:35:39.0330 0x230c  [ 9D01DDF5EA8494BBCBB73FF385E35D35, C575DC65275BEA8558A855C7DC6CFA84BD7F48D24BB0C522084E89DDC5CB02A7 ] IntcDAud        C:\Windows\system32\DRIVERS\IntcDAud.sys
19:35:39.0352 0x230c  IntcDAud - ok
19:35:39.0369 0x230c  [ 4C17F57E43645E75800E9E84787E34E5, 6A1531D97462BA3B3DBDAD472AF15B717C958AA8C5CE2373DE0B2A41C35BE33E ] Intel® Capability Licensing Service TCP IP Interface C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
19:35:39.0389 0x230c  Intel® Capability Licensing Service TCP IP Interface - ok
19:35:39.0394 0x230c  [ 9417DBC88A3A80F6177BCA204B16A016, A1CAEEDB634C5858D6C448F38BB1464F555D9AC1EC4340DFD0E10E69B4F3CF07 ] Intel® ME Service C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
19:35:39.0403 0x230c  Intel® ME Service - ok
19:35:39.0405 0x230c  [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECCA64C3D3C60FD22 ] intelide        C:\Windows\system32\drivers\intelide.sys
19:35:39.0419 0x230c  intelide - ok
19:35:39.0422 0x230c  [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B579ACF99FCC610 ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
19:35:39.0438 0x230c  intelppm - ok
19:35:39.0442 0x230c  [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E3A1CFD872823AA ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
19:35:39.0469 0x230c  IPBusEnum - ok
19:35:39.0473 0x230c  [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A89C01E074BA8E51 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
19:35:39.0503 0x230c  IpFilterDriver - ok
19:35:39.0515 0x230c  [ 08C2957BB30058E663720C5606885653, E13EDF6701512E2A9977A531454932CA5023087CB50E1D2F416B8BCDD92B67BE ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
19:35:39.0535 0x230c  iphlpsvc - ok
19:35:39.0539 0x230c  [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0D52C75A31473D9 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
19:35:39.0557 0x230c  IPMIDRV - ok
19:35:39.0560 0x230c  [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0BE03935153D04E ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
19:35:39.0592 0x230c  IPNAT - ok
19:35:39.0595 0x230c  [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C03089EB157D6188AE ] IRENUM          C:\Windows\system32\drivers\irenum.sys
19:35:39.0613 0x230c  IRENUM - ok
19:35:39.0615 0x230c  [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF11AD860BD136548 ] isapnp          C:\Windows\system32\drivers\isapnp.sys
19:35:39.0630 0x230c  isapnp - ok
19:35:39.0638 0x230c  [ 96BB922A0981BC7432C8CF52B5410FE6, 236C05509B1040059B15021CBBDBDAF3B9C0F00910142BE5887B2C7561BAAFBA ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
19:35:39.0657 0x230c  iScsiPrt - ok
19:35:39.0663 0x230c  [ 622BF9C46A47CF17608C501320E8EFBD, 059F99D4306216324E100FCDAF02093B2CD662F2C6BE8565A4281E7760F8B575 ] iumsvc          C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe
19:35:39.0682 0x230c  iumsvc - ok
19:35:39.0685 0x230c  [ 61662AFF4AF0413F461F2780167703AE, 55CCBA4F09581871B3EB81A40A3FB59013AD988CEED109E18C58609AD469117A ] iusb3hcs        C:\Windows\system32\drivers\iusb3hcs.sys
19:35:39.0699 0x230c  iusb3hcs - ok
19:35:39.0707 0x230c  [ 923030D5F4B1C801AE5219551F7B490B, C00D9CCE8D04FEFA9391725F79BBD77F03ED3E3DB53E02E80ABC008B2F179043 ] iusb3hub        C:\Windows\system32\DRIVERS\iusb3hub.sys
19:35:39.0733 0x230c  iusb3hub - ok
19:35:39.0748 0x230c  [ 234E2245AF65CFC021874F64C40E206B, 4254180327F7B58AAE1A158DADE53A06C02139F6CDD2A657E5E9B2868B96F806 ] iusb3xhc        C:\Windows\system32\DRIVERS\iusb3xhc.sys
19:35:39.0774 0x230c  iusb3xhc - ok
19:35:39.0780 0x230c  [ 0B93A01F786F37A4B1EDE84E639FFF10, 8747109A2FA2B80C8C5F5B6D2372C1B0DA4F4BF9DC1D551195ADF0715C260223 ] jhi_service     C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
19:35:39.0789 0x230c  jhi_service - ok
19:35:39.0792 0x230c  [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29A8F848048AAD93 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
19:35:39.0807 0x230c  kbdclass - ok
19:35:39.0810 0x230c  [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9D8E96A32225E99 ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
19:35:39.0826 0x230c  kbdhid - ok
19:35:39.0829 0x230c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] KeyIso          C:\Windows\system32\lsass.exe
19:35:39.0839 0x230c  KeyIso - ok
19:35:39.0846 0x230c  [ 89073D9FAF1A7C4781B26CCC9A28D2B6, 0D0C498DF6E3C236636B544D829771DEE49DE34C581985AE675674873619F953 ] KeyScrambler    C:\Windows\system32\drivers\keyscrambler.sys
19:35:39.0867 0x230c  KeyScrambler - ok
19:35:39.0877 0x230c  [ 62EBD4202B505ACADE2FBC56CC73E0A2, 2FCA80096B7DB5B42E76F527D9ABCF29AF7D52FC60BED6DD4C11C1BACA0D63F1 ] kl1             C:\Windows\system32\DRIVERS\kl1.sys
19:35:39.0900 0x230c  kl1 - ok
19:35:39.0904 0x230c  [ 86F40D79CE80ACBE6BEBAC8CE89D75A0, 8B800425160D1AF3C32EF7B5CA794658EE09CD3EE782473D8D38E1C7706076B3 ] klbackupdisk    C:\Windows\system32\DRIVERS\klbackupdisk.sys
19:35:39.0921 0x230c  klbackupdisk - ok
19:35:39.0925 0x230c  [ D3BEF82D7A5A1560F667D5FCC0E90387, 35473F72346DBAA02EB98319B4AD587550B996607B8B714D356D04A4B28E2F09 ] klbackupflt     C:\Windows\system32\DRIVERS\klbackupflt.sys
19:35:39.0942 0x230c  klbackupflt - ok
19:35:39.0946 0x230c  [ B12242478186B62B2E214288B7DB3612, D3381C6B95A27D75348DC51411BABE144A4C333E1441077C4BF13A3BFBB4CA06 ] kldisk          C:\Windows\system32\DRIVERS\kldisk.sys
19:35:39.0964 0x230c  kldisk - ok
19:35:39.0970 0x230c  [ 3025DB68C9BFFF3EA67986C91340EC12, 74E61837A0EEA5F56104F0FFC7B8FEFB7BFB7A22D7F0903C4A7AEAE1E1532920 ] klflt           C:\Windows\system32\DRIVERS\klflt.sys
19:35:39.0992 0x230c  klflt - ok
19:35:39.0999 0x230c  [ 53E82813D132491C84AA7A4B0CA2707A, 94F0E5819593A7D2BF7D8FC9A6B0A11363788A50D0B9E8A7F3E3B941BCFD7709 ] klhk            C:\Windows\system32\DRIVERS\klhk.sys
19:35:40.0020 0x230c  klhk - ok
19:35:40.0030 0x230c  [ 7796EAD58D8C1A42AAB6B6CA9A3F106C, 7DA8A05A0210F63C7D120DCF0101AD895D53368C0DED23E275F2BA79239FCE28 ] klids           C:\ProgramData\Kaspersky Lab\AVP16.0.1\Bases\klids.sys
19:35:40.0050 0x230c  klids - ok
19:35:40.0069 0x230c  [ D90C2622A2D717704C0AA33134BAA07E, 5DE2FCBE4043DD79F472C99FED8A8189A0AD231F9DB7453F1781775CE67CBF47 ] KLIF            C:\Windows\system32\DRIVERS\klif.sys
19:35:40.0095 0x230c  KLIF - ok
19:35:40.0099 0x230c  [ E540E1C90970FAFEBCCCE3EEC3B8673F, BA2229A237A5088D3FBAA567069C56CDE7EBB4B37D5FB24F691BFF6FE1B0BD69 ] KLIM6           C:\Windows\system32\DRIVERS\klim6.sys
19:35:40.0114 0x230c  KLIM6 - ok
19:35:40.0118 0x230c  [ 0D5E3D54FDFE598CF570312310C0D8E5, B1DAF9B19531D4C9CB7584D90341C429E3A3793B9A6FEDCC5CF8B70508240FE7 ] klkbdflt        C:\Windows\system32\DRIVERS\klkbdflt.sys
19:35:40.0134 0x230c  klkbdflt - ok
19:35:40.0136 0x230c  klkbdflt2 - ok
19:35:40.0139 0x230c  [ D792857D47B8DF5BFEC02534C1933BE2, BDD483FA8E2DC50DB4E54D475867455F0D7E115494E2A31CD27A065C7EC26951 ] klmouflt        C:\Windows\system32\DRIVERS\klmouflt.sys
19:35:40.0153 0x230c  klmouflt - ok
19:35:40.0156 0x230c  [ 26E1917517E613D07F2A122CEEBB8161, A03C4F9FA37DBB48AB00330A4F0ACC7841D425DAE7E374508AD53BC010C0F746 ] klpd            C:\Windows\system32\DRIVERS\klpd.sys
19:35:40.0171 0x230c  klpd - ok
19:35:40.0174 0x230c  [ B36DEE2A91F9388C4D3ED744592DE81D, 78D64539A375C80250FB9FA5E1DDA208B331A85916E19ED1353623DDF750EC58 ] kltdi           C:\Windows\system32\DRIVERS\kltdi.sys
19:35:40.0190 0x230c  kltdi - ok
19:35:40.0201 0x230c  [ B48F79A7B58EB9A5E4894A96453C6957, B05176A40DA7321409866D77DA03A36B44DA386C45C6AF149B14F65C2B9C8A6B ] klvssbrigde64   C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\x64\vssbridge64.exe
19:35:40.0210 0x230c  klvssbrigde64 - ok
19:35:40.0215 0x230c  [ 7FAE98B11E1218C707A28F993CFE271C, 7BD94243B7004C8A719733A03BB1320FCDF9F53FB7240058F7006C1DFE9E59B0 ] Klwtp           C:\Windows\system32\DRIVERS\klwtp.sys
19:35:40.0232 0x230c  Klwtp - ok
19:35:40.0238 0x230c  [ 58CD685752080EDAEB4EEC7E6428546D, 59E280A025A91BCEC029D21B4DCC6342F354B9D6592C0EE14217BF5B32FB259B ] kneps           C:\Windows\system32\DRIVERS\kneps.sys
19:35:40.0258 0x230c  kneps - ok
19:35:40.0262 0x230c  [ 6F5F0C6160EF237F0243C1E416EEBA98, 8BA8AA0D71350A74E294A731226B1638C6059013D645ABDE7188F7733E320FBD ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
19:35:40.0279 0x230c  KSecDD - ok
19:35:40.0285 0x230c  [ 05529E53B286FD60E7EF04EF138CABFD, 6C045750DCD3EE76F748582513AD4FA99C0E8E56B616725CD48DCA1068FF8923 ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
19:35:40.0304 0x230c  KSecPkg - ok
19:35:40.0307 0x230c  [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C3F988DF417044B ] ksthunk         C:\Windows\system32\drivers\ksthunk.sys
19:35:40.0338 0x230c  ksthunk - ok
19:35:40.0347 0x230c  [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737B9F28BEEA77FFF ] KtmRm           C:\Windows\system32\msdtckrm.dll
19:35:40.0377 0x230c  KtmRm - ok
19:35:40.0384 0x230c  [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD5404133688CDFCC40 ] LanmanServer    C:\Windows\system32\srvsvc.dll
19:35:40.0411 0x230c  LanmanServer - ok
19:35:40.0415 0x230c  [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A244DEE9F8A1FABF9 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
19:35:40.0439 0x230c  LanmanWorkstation - ok
19:35:40.0443 0x230c  [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0BC71A090262C0C ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
19:35:40.0473 0x230c  lltdio - ok
19:35:40.0481 0x230c  [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410C62984DD652700 ] lltdsvc         C:\Windows\System32\lltdsvc.dll
19:35:40.0508 0x230c  lltdsvc - ok
19:35:40.0510 0x230c  [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF9865DCBA8B1717E70 ] lmhosts         C:\Windows\System32\lmhsvc.dll
19:35:40.0533 0x230c  lmhosts - ok
19:35:40.0543 0x230c  [ C31139E0907170E2A3FA8D19DCC23D35, C504E93D2018E9E487A428483C646C67B4ECE122560CF0FA49A1626E1509EEAE ] LMS             C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
19:35:40.0556 0x230c  LMS - ok
19:35:40.0562 0x230c  [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9DC2E267FE3255B ] LSI_FC          C:\Windows\system32\drivers\lsi_fc.sys
19:35:40.0578 0x230c  LSI_FC - ok
19:35:40.0582 0x230c  [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993554CB21D81AE4B ] LSI_SAS         C:\Windows\system32\drivers\lsi_sas.sys
19:35:40.0598 0x230c  LSI_SAS - ok
19:35:40.0601 0x230c  [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDAA525CC9686BD06 ] LSI_SAS2        C:\Windows\system32\drivers\lsi_sas2.sys
19:35:40.0616 0x230c  LSI_SAS2 - ok
19:35:40.0620 0x230c  [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C8AEF811C89C54D ] LSI_SCSI        C:\Windows\system32\drivers\lsi_scsi.sys
19:35:40.0638 0x230c  LSI_SCSI - ok
19:35:40.0642 0x230c  [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F305486FCC3B7B22 ] luafv           C:\Windows\system32\drivers\luafv.sys
19:35:40.0674 0x230c  luafv - ok
19:35:40.0679 0x230c  [ 1239597BAB7EED2BB16D035AF87E65D9, 67A4F1C8BA77502404629C3411BA76729435012CFA6D7794C46F31BBC118064E ] mbamchameleon   C:\Windows\system32\drivers\mbamchameleon.sys
19:35:40.0696 0x230c  mbamchameleon - ok
19:35:40.0699 0x230c  [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1767C4DE425A728 ] megasas         C:\Windows\system32\drivers\megasas.sys
19:35:40.0713 0x230c  megasas - ok
19:35:40.0721 0x230c  [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68F287FDAC1DD834 ] MegaSR          C:\Windows\system32\drivers\MegaSR.sys
19:35:40.0743 0x230c  MegaSR - ok
19:35:40.0747 0x230c  [ 8751062F2F7EC78DE92D778A08099DDE, F10BE771FF9E02A51CF3A167BB967167DE4F66647D7F1508CB27D8FDD8623700 ] MEIx64          C:\Windows\system32\DRIVERS\TeeDriverx64.sys
19:35:40.0763 0x230c  MEIx64 - ok
19:35:40.0767 0x230c  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] MMCSS           C:\Windows\system32\mmcss.dll
19:35:40.0790 0x230c  MMCSS - ok
19:35:40.0793 0x230c  [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8D6A1DDC8A93342 ] Modem           C:\Windows\system32\drivers\modem.sys
19:35:40.0822 0x230c  Modem - ok
19:35:40.0825 0x230c  [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C29885944A0D851238732 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
19:35:40.0842 0x230c  monitor - ok
19:35:40.0845 0x230c  [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E8331C05B1A7EE7 ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
19:35:40.0859 0x230c  mouclass - ok
19:35:40.0862 0x230c  [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F6A47A2B97FC183 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
19:35:40.0879 0x230c  mouhid - ok
19:35:40.0883 0x230c  [ 8ADB5445B29941CB41AF2846FD5C93C7, 689582430FE29EC0845B1DB841D3CC49D5D09DE264586E3999EEFE616986D12B ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
19:35:40.0892 0x230c  mountmgr - ok
19:35:40.0897 0x230c  [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124E89B1037AF09B8 ] mpio            C:\Windows\system32\drivers\mpio.sys
19:35:40.0917 0x230c  mpio - ok
19:35:40.0922 0x230c  [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897FB684F8956EAD20 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
19:35:40.0957 0x230c  mpsdrv - ok
19:35:40.0974 0x230c  [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435CCF777300EA4F2 ] MpsSvc          C:\Windows\system32\mpssvc.dll
19:35:41.0011 0x230c  MpsSvc - ok
19:35:41.0016 0x230c  [ 98DB1790F0A584E0A2528B92B052417F, 9AA04CA73AFE599810CD233B9CEC212E16D44DCEDF5C7D0181C7257F498068B5 ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
19:35:41.0035 0x230c  MRxDAV - ok
19:35:41.0041 0x230c  [ 632E8A00090E4F85F304E152C92C7F2C, A3098941251A8327C95E6B1122384D54FB0ED705A9215577D968EA5B5FD88C87 ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
19:35:41.0063 0x230c  mrxsmb - ok
19:35:41.0071 0x230c  [ 0D9C05484F2F4BD9D33A615D5DBE67EA, 1E164B631B1CD85DD5B205284CB547B189609946490AAABD22741743BFB413DF ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
19:35:41.0095 0x230c  mrxsmb10 - ok
19:35:41.0100 0x230c  [ 6123E6FECC1C164022868FB1982271BE, 417E6C7AFF8B014B31AFCC202B0DCEECBDBB73205DF8C3EFC7E313664E284178 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
19:35:41.0120 0x230c  mrxsmb20 - ok
19:35:41.0123 0x230c  [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A99020EAE7B10F8 ] msahci          C:\Windows\system32\drivers\msahci.sys
19:35:41.0136 0x230c  msahci - ok
19:35:41.0141 0x230c  [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE14686C1F6E3C74 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
19:35:41.0159 0x230c  msdsm - ok
19:35:41.0164 0x230c  [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C01F4528CE407DE3 ] MSDTC           C:\Windows\System32\msdtc.exe
19:35:41.0176 0x230c  MSDTC - ok
19:35:41.0181 0x230c  [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA250A168615AE1E99 ] Msfs            C:\Windows\system32\drivers\Msfs.sys
19:35:41.0210 0x230c  Msfs - ok
19:35:41.0212 0x230c  [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FCB88987C2174141 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
19:35:41.0241 0x230c  mshidkmdf - ok
19:35:41.0243 0x230c  [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88311AB73BC992A1 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
19:35:41.0256 0x230c  msisadrv - ok
19:35:41.0261 0x230c  [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A0091CA33A1A3D5 ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
19:35:41.0286 0x230c  MSiSCSI - ok
19:35:41.0288 0x230c  msiserver - ok
19:35:41.0290 0x230c  [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684FB8789A20396C7 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
19:35:41.0319 0x230c  MSKSSRV - ok
19:35:41.0322 0x230c  [ 103B3BBE23AB774B009D182276EC6786, 823AF63D5D47B56455078DD20DF000D11A0BD2E094E9002E5B9E8245D7AEAE68 ] msloop          C:\Windows\system32\DRIVERS\loop.sys
19:35:41.0338 0x230c  msloop - ok
19:35:41.0340 0x230c  [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B15C071A0618BBB ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
19:35:41.0369 0x230c  MSPCLOCK - ok
19:35:41.0371 0x230c  [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E863388F1C229838DFCC ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
19:35:41.0400 0x230c  MSPQM - ok
19:35:41.0408 0x230c  [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099C6F8B95A40F133 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
19:35:41.0427 0x230c  MsRPC - ok
19:35:41.0430 0x230c  [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E9BAC9DE3E64D42 ] mssmbios        C:\Windows\system32\DRIVERS\mssmbios.sys
19:35:41.0444 0x230c  mssmbios - ok
19:35:41.0447 0x230c  [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64F6A5F1301586CD ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
19:35:41.0475 0x230c  MSTEE - ok
19:35:41.0477 0x230c  [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977AE960F9AEC3232 ] MTConfig        C:\Windows\system32\drivers\MTConfig.sys
19:35:41.0492 0x230c  MTConfig - ok
19:35:41.0496 0x230c  [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0B70B36C524693A ] Mup             C:\Windows\system32\Drivers\mup.sys
19:35:41.0511 0x230c  Mup - ok
19:35:41.0518 0x230c  [ 821249A8AC2BBB95A43ABEC6E0253658, 3A8E104430B7AD2C8CCF3563F5682A050763467C340AD4DA82462CB56A9F2C4B ] MyWiFiDHCPDNS   C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
19:35:41.0528 0x230c  MyWiFiDHCPDNS - ok
19:35:41.0538 0x230c  [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C8208436469A31B16B260 ] napagent        C:\Windows\system32\qagentRT.dll
19:35:41.0569 0x230c  napagent - ok
19:35:41.0577 0x230c  [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AEB7A185E97800D7 ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
19:35:41.0605 0x230c  NativeWifiP - ok
19:35:41.0622 0x230c  [ F7309F42555F8AAB7144A51A1F2585B0, 065277A8AFAEE3888C997A76D2F751070F92DF4C3354D16B194860B4BDAFF937 ] NDIS            C:\Windows\system32\drivers\ndis.sys
19:35:41.0645 0x230c  NDIS - ok
19:35:41.0649 0x230c  [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4ABAB25823572BC ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
19:35:41.0681 0x230c  NdisCap - ok
19:35:41.0684 0x230c  [ 8DC4CF52E4BA1C85EDEF32A8F9444EDA, 5E6D01591211DF13ED035707125668DB91F2E6A2BA5FDC9B03B71413F00AE279 ] ndisrd          C:\Windows\system32\DRIVERS\ndisrd.sys
19:35:41.0692 0x230c  ndisrd - ok
19:35:41.0695 0x230c  [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B242FA2887C99F9D6 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
19:35:41.0725 0x230c  NdisTapi - ok
19:35:41.0728 0x230c  [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD3094F2E8EB56E683 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
19:35:41.0757 0x230c  Ndisuio - ok
19:35:41.0762 0x230c  [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E252A487FD2CE77 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
19:35:41.0795 0x230c  NdisWan - ok
19:35:41.0798 0x230c  [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6E64B1332071023 ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
19:35:41.0827 0x230c  NDProxy - ok
19:35:41.0830 0x230c  [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243AB46B17D8032062 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
19:35:41.0860 0x230c  NetBIOS - ok
19:35:41.0866 0x230c  [ E47D571FEC2C76E867935109AB2A770C, F349D25890B6F476B106FD75BFB081DB737CA9B224D95E44927942FFF2DF82CD ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
19:35:41.0891 0x230c  NetBT - ok
19:35:41.0894 0x230c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] Netlogon        C:\Windows\system32\lsass.exe
19:35:41.0904 0x230c  Netlogon - ok
19:35:41.0913 0x230c  [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F53DD32A827CB936 ] Netman          C:\Windows\System32\netman.dll
19:35:41.0944 0x230c  Netman - ok
19:35:41.0950 0x230c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:35:41.0960 0x230c  NetMsmqActivator - ok
19:35:41.0964 0x230c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:35:41.0978 0x230c  NetPipeActivator - ok
19:35:41.0988 0x230c  [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D169C869DE8813B9 ] netprofm        C:\Windows\System32\netprofm.dll
19:35:42.0018 0x230c  netprofm - ok
19:35:42.0022 0x230c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:35:42.0032 0x230c  NetTcpActivator - ok
19:35:42.0035 0x230c  [ 0BEF1F19F32C9F3DBE9A503F2E66CC22, 4F4812CDDB675C5D655B5B90375F188A3A5AA52A2BC2CED383B03449CF8210C8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
19:35:42.0045 0x230c  NetTcpPortSharing - ok
19:35:42.0104 0x230c  [ C748556F948B0559C0EFF577E5C6F09C, 96F2EEDDE70FB3DF1AE099D1F99364638DC449C0061A48FCD1A1C8256C1A7EB5 ] NETwNs64        C:\Windows\system32\DRIVERS\Netwsw02.sys
19:35:42.0205 0x230c  NETwNs64 - ok
19:35:42.0211 0x230c  [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AAF3C2393AD0E6A3 ] nfrd960         C:\Windows\system32\drivers\nfrd960.sys
19:35:42.0226 0x230c  nfrd960 - ok
19:35:42.0234 0x230c  [ 8B301D474B478E9A92823BAB50A7BC49, 8181816035F41B1DABEC05E65E4F67BCD785F56760A61F1049E91BA39D42F01D ] NlaSvc          C:\Windows\System32\nlasvc.dll
19:35:42.0258 0x230c  NlaSvc - ok
19:35:42.0263 0x230c  [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17AC04668157DC67F ] Npfs            C:\Windows\system32\drivers\Npfs.sys
19:35:42.0292 0x230c  Npfs - ok
19:35:42.0295 0x230c  [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F507518CF6EAA53A ] nsi             C:\Windows\system32\nsisvc.dll
19:35:42.0323 0x230c  nsi - ok
19:35:42.0326 0x230c  [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7F981D292689D76 ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
19:35:42.0354 0x230c  nsiproxy - ok
19:35:42.0384 0x230c  [ 47B2D0B31BDC3EBE6090228E2BA3764D, 984A4B38300954164BCBF57EC1A09C18B53779E60A26E9618B50E26016735787 ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
19:35:42.0426 0x230c  Ntfs - ok
19:35:42.0430 0x230c  [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9AA0735CD0666D6 ] Null            C:\Windows\system32\drivers\Null.sys
19:35:42.0458 0x230c  Null - ok
19:35:42.0678 0x230c  [ 5953E6353A3D22275F7CE92A7F00A8BB, 9B83285245684C2919355850EF195C2AD6D9A4CCB0B2C67012F1191E5D184666 ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
19:35:42.0948 0x230c  nvlddmkm - ok
19:35:42.0969 0x230c  [ 9B3803EF5C0229EC7051A17D8169DB5F, 505B86AEB8A2399917F0823E86434C46CC27D96A6609544EC927A1142BD999C7 ] nvpciflt        C:\Windows\system32\DRIVERS\nvpciflt.sys
19:35:42.0983 0x230c  nvpciflt - ok
19:35:42.0988 0x230c  [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B680AFB51A35ACE7 ] nvraid          C:\Windows\system32\drivers\nvraid.sys
19:35:43.0005 0x230c  nvraid - ok
19:35:43.0010 0x230c  [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB5070D292FEAAEDF37 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
19:35:43.0028 0x230c  nvstor - ok
19:35:43.0032 0x230c  [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E0D63ECA996F76F ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
19:35:43.0049 0x230c  nv_agp - ok
19:35:43.0059 0x230c  [ 785F487A64950F3CB8E9F16253BA3B7B, 02445344BD214370A6D48B1CA04921D8EFCB13E676B5648266DD0E076C0822B6 ] odserv          C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
19:35:43.0072 0x230c  odserv - ok
19:35:43.0076 0x230c  [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B3B62057EFF0203 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
19:35:43.0093 0x230c  ohci1394 - ok
19:35:43.0098 0x230c  [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose             C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
19:35:43.0107 0x230c  ose - ok
19:35:43.0115 0x230c  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
19:35:43.0129 0x230c  p2pimsvc - ok
19:35:43.0139 0x230c  [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675549628408B94CE ] p2psvc          C:\Windows\system32\p2psvc.dll
19:35:43.0155 0x230c  p2psvc - ok
19:35:43.0164 0x230c  PAExec - ok
19:35:43.0170 0x230c  [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A989B12FA8D0A80 ] Parport         C:\Windows\system32\drivers\parport.sys
19:35:43.0187 0x230c  Parport - ok
19:35:43.0191 0x230c  [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D9160C2C1A492B6 ] partmgr         C:\Windows\system32\drivers\partmgr.sys
19:35:43.0206 0x230c  partmgr - ok
19:35:43.0211 0x230c  [ 3CD83692C43D87088E85E3C916146FFB, 9E812535E8FBA045FDA30F68E9EB2031132C37721D542A2DC9D4C33E2B137FCF ] PcaSvc          C:\Windows\System32\pcasvc.dll
19:35:43.0225 0x230c  PcaSvc - ok
19:35:43.0231 0x230c  [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA27E4C3C8B27FC9 ] pci             C:\Windows\system32\drivers\pci.sys
19:35:43.0249 0x230c  pci - ok
19:35:43.0252 0x230c  [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DEA0C01A6B863480 ] pciide          C:\Windows\system32\drivers\pciide.sys
19:35:43.0265 0x230c  pciide - ok
19:35:43.0271 0x230c  [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C4F98F7DF73DE14 ] pcmcia          C:\Windows\system32\drivers\pcmcia.sys
19:35:43.0292 0x230c  pcmcia - ok
19:35:43.0294 0x230c  [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3CB207CE5FBBD36 ] pcw             C:\Windows\system32\drivers\pcw.sys
19:35:43.0309 0x230c  pcw - ok
19:35:43.0322 0x230c  [ EA4D67448BE493D543F1730D6CD04694, 24717C5E41B7CA522F3330EF2228B6685E710A5259396E9887A1C1E7A413F8CA ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
19:35:43.0346 0x230c  PEAUTH - ok
19:35:43.0370 0x230c  [ B9B0A4299DD2D76A4243F75FD54DC680, BBF62E9628131FA396EB08D63B76D2D5FBDD61339E92B759125A066470D1C039 ] PeerDistSvc     C:\Windows\system32\peerdistsvc.dll
19:35:43.0403 0x230c  PeerDistSvc - ok
19:35:43.0415 0x230c  [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A12937BE86FB919 ] PerfHost        C:\Windows\SysWow64\perfhost.exe
19:35:43.0425 0x230c  PerfHost - ok
19:35:43.0452 0x230c  [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE422509C1F83EC85F3DD ] pla             C:\Windows\system32\pla.dll
19:35:43.0496 0x230c  pla - ok
19:35:43.0507 0x230c  [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75FBCD06EEB8442A9 ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
19:35:43.0523 0x230c  PlugPlay - ok
19:35:43.0526 0x230c  [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D9195F80A722782315 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
19:35:43.0536 0x230c  PNRPAutoReg - ok
19:35:43.0543 0x230c  [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6EDEC0A183CFFC3 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
19:35:43.0557 0x230c  PNRPsvc - ok
19:35:43.0568 0x230c  [ 80D6B0563ED2BF10656B1D4748331082, B7E6B5E1148B7EE537E8D5C3A65450876B61CD45A395267D08699746E98AD574 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
19:35:43.0585 0x230c  PolicyAgent - ok
19:35:43.0591 0x230c  [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D90D5B4D6748B55 ] Power           C:\Windows\system32\umpo.dll
19:35:43.0616 0x230c  Power - ok
19:35:43.0620 0x230c  [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A824DDA9CD89C763 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
19:35:43.0650 0x230c  PptpMiniport - ok
19:35:43.0653 0x230c  [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C521F9F613B4EAD5 ] Processor       C:\Windows\system32\drivers\processr.sys
19:35:43.0669 0x230c  Processor - ok
19:35:43.0675 0x230c  [ B6A58491307B4CADA572583D863DC602, 5C44936605E52C9533E4CE22F18FAB8211475877F71EFD88DA4D02FD608C90A3 ] ProfSvc         C:\Windows\system32\profsvc.dll
19:35:43.0688 0x230c  ProfSvc - ok
19:35:43.0691 0x230c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] ProtectedStorage C:\Windows\system32\lsass.exe
19:35:43.0700 0x230c  ProtectedStorage - ok
19:35:43.0704 0x230c  [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B8676C619AB74957B4 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
19:35:43.0727 0x230c  Psched - ok
19:35:43.0753 0x230c  [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA76D8CD819774489 ] ql2300          C:\Windows\system32\drivers\ql2300.sys
19:35:43.0791 0x230c  ql2300 - ok
19:35:43.0796 0x230c  [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B5296F789F6F7D08DE ] ql40xx          C:\Windows\system32\drivers\ql40xx.sys
19:35:43.0813 0x230c  ql40xx - ok
19:35:43.0820 0x230c  [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C5CDAB0B2B9418F ] QWAVE           C:\Windows\system32\qwave.dll
19:35:43.0836 0x230c  QWAVE - ok
19:35:43.0838 0x230c  [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F574E40DDF70535 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
19:35:43.0857 0x230c  QWAVEdrv - ok
19:35:43.0860 0x230c  [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8C69B48E8A255EF ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
19:35:43.0888 0x230c  RasAcd - ok
19:35:43.0891 0x230c  [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA384A93F5C90CA1 ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
19:35:43.0921 0x230c  RasAgileVpn - ok
19:35:43.0925 0x230c  [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3BC0B8DEE680E090 ] RasAuto         C:\Windows\System32\rasauto.dll
19:35:43.0949 0x230c  RasAuto - ok
19:35:43.0954 0x230c  [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177593141EE072698 ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
19:35:43.0995 0x230c  Rasl2tp - ok
19:35:44.0004 0x230c  [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC15925A148BCADA ] RasMan          C:\Windows\System32\rasmans.dll
19:35:44.0033 0x230c  RasMan - ok
19:35:44.0036 0x230c  [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B58CFD55E9561F72 ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
19:35:44.0067 0x230c  RasPppoe - ok
19:35:44.0071 0x230c  [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E645D7C37859258C ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
19:35:44.0102 0x230c  RasSstp - ok
19:35:44.0110 0x230c  [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD36CD2607D8810DA ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
19:35:44.0147 0x230c  rdbss - ok
19:35:44.0150 0x230c  [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B8C4967E5DE9D17 ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
19:35:44.0166 0x230c  rdpbus - ok
19:35:44.0169 0x230c  [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B6755C6FC2D77A804 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
19:35:44.0196 0x230c  RDPCDD - ok
19:35:44.0203 0x230c  [ 1B6163C503398B23FF8B939C67747683, 339A5AA7970FF34FAAB213B655860C5B0DEC5F983A4A11A088017D849F320ACE ] RDPDR           C:\Windows\system32\drivers\rdpdr.sys
19:35:44.0224 0x230c  RDPDR - ok
19:35:44.0226 0x230c  [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F139E4E652ADDE41F ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
19:35:44.0253 0x230c  RDPENCDD - ok
19:35:44.0256 0x230c  [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E10A612540F173F4 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
19:35:44.0284 0x230c  RDPREFMP - ok
19:35:44.0288 0x230c  [ 313F68E1A3E6345A4F47A36B07062F34, B8318A0AE06BDE278931CA52F960B9FE226FD9894B076858DDB755AE26E1E66F ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
19:35:44.0304 0x230c  RdpVideoMiniport - ok
19:35:44.0310 0x230c  [ FE571E088C2D83619D2D48D4E961BF41, 88C5A2FCB1D0E528657842E39963471A6E42FCA3FCDF37955AEC8258AB4C48EA ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
19:35:44.0333 0x230c  RDPWD - ok
19:35:44.0339 0x230c  [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E3EC3FFF929BB5F ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
19:35:44.0358 0x230c  rdyboost - ok
19:35:44.0364 0x230c  [ 621B25188ADF78DDBE11DBA3C8C2A4A9, 126407EACE90DD01B9566D8129E9635313EACFA78F015B5977E19143DF51B234 ] RegSrvc         C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
19:35:44.0373 0x230c  RegSrvc - ok
19:35:44.0377 0x230c  [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656EE72287F3D3836 ] RemoteAccess    C:\Windows\System32\mprdim.dll
19:35:44.0401 0x230c  RemoteAccess - ok
19:35:44.0406 0x230c  [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF10F72B00E1C6B22 ] RemoteRegistry  C:\Windows\system32\regsvc.dll
19:35:44.0431 0x230c  RemoteRegistry - ok
19:35:44.0434 0x230c  [ 9C3AC71A9934B884FAC567A8807E9C4D, 0B6B2970098E3C21E1E54A25785544903E8CD415B527FCEF86ABC7B33BEC83E7 ] Revoflt         C:\Windows\system32\DRIVERS\revoflt.sys
19:35:44.0448 0x230c  Revoflt - ok
19:35:44.0453 0x230c  [ 3DD798846E2C28102B922C56E71B7932, 30B111615D74CB2213997A5C08DD9C8613ADE441D9423CC1C49A753D13CE524D ] RFCOMM          C:\Windows\system32\DRIVERS\rfcomm.sys
19:35:44.0474 0x230c  RFCOMM - ok
19:35:44.0477 0x230c  [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D8584349754C2867E8 ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
19:35:44.0501 0x230c  RpcEptMapper - ok
19:35:44.0504 0x230c  [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F95938D7577334E ] RpcLocator      C:\Windows\system32\locator.exe
19:35:44.0513 0x230c  RpcLocator - ok
19:35:44.0524 0x230c  [ 622C96AFB07BB82C8650B47172137AC4, B74CEA5A3F4945E5A3EAE7AF1B1FA75F611C65C6FACE393052A512FA81B0C17C ] RpcSs           C:\Windows\system32\rpcss.dll
19:35:44.0541 0x230c  RpcSs - ok
19:35:44.0545 0x230c  [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908CCA7E0F117173DD ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
19:35:44.0576 0x230c  rspndr - ok
19:35:44.0593 0x230c  [ EB287A54E91FE224FCDB12F0B6C3FA05, 45E0A93A9147CF747E388DCDA1EF3500AFFB29A6C0FEA87A492028505B193144 ] RTL8167         C:\Windows\system32\DRIVERS\Rt64win7.sys
19:35:44.0620 0x230c  RTL8167 - ok
19:35:44.0631 0x230c  [ 78CA6B333D92B3344AE6DC54013203A6, 368647BD2A737ECF079D8D1BEF3FFC379A563136FCCB0880861333B9EF150283 ] RTSPER          C:\Windows\system32\DRIVERS\RtsPer.sys
19:35:44.0649 0x230c  RTSPER - ok
19:35:44.0654 0x230c  [ 24510C4A77ABA3B07AEFA840DB888637, 6756CE67A9F7DBC81F4F74ABF74B5A0DF02BD91AF1C689A2E441951270E123A3 ] RzSynapse       C:\Windows\system32\DRIVERS\RzSynapse.sys
19:35:44.0665 0x230c  RzSynapse - ok
19:35:44.0667 0x230c  [ E60C0A09F997826C7627B244195AB581, E8630ED74B38B98BF584E353D992C1311BC36AB7F20A1BB66C9CD65CE1E46F8D ] s3cap           C:\Windows\system32\drivers\vms3cap.sys
19:35:44.0681 0x230c  s3cap - ok
19:35:44.0683 0x230c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] SamSs           C:\Windows\system32\lsass.exe
19:35:44.0692 0x230c  SamSs - ok
19:35:44.0695 0x230c  [ 3289766038DB2CB14D07DC84392138D5, A7790B787690CC1A8B97E4532090C5295350A836A9474DEA74CEB3E81CF26124 ] SASDIFSV        C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
19:35:44.0707 0x230c  SASDIFSV - ok
19:35:44.0709 0x230c  [ 58A38E75F3316A83C23DF6173D41F2B5, B0A8CDA1D164B7534FB41AB80792861384709BF0F914F44553275CF20194F1A1 ] SASKUTIL        C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
19:35:44.0720 0x230c  SASKUTIL - ok
19:35:44.0727 0x230c  [ 186151BC8CEE2CF3E942E81527AAFF1A, 33D68239D655054CE8822438E96D2648193419D8D94F979A4B67AF57BCEF6CBD ] SbieDrv         C:\Program Files\Sandboxie\SbieDrv.sys
19:35:44.0738 0x230c  SbieDrv - ok
19:35:44.0744 0x230c  [ 12820DA4BB0079BBC709C7028A22BA63, C15EDCC83CC4931C871D04F09A6FC6199C9DCD4332CDF4C80D1E6E5A2AFD4DE1 ] SbieSvc         C:\Program Files\Sandboxie\SbieSvc.exe
19:35:44.0755 0x230c  SbieSvc - ok
19:35:44.0759 0x230c  [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F5269E6EAA5E0A656 ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
19:35:44.0775 0x230c  sbp2port - ok
19:35:44.0796 0x230c  [ 794D4B48DFB6E999537C7C3947863463, 93DA8AA20D6B02A3360E7F56150F126E75266E9372E6409D42B89DA588EF49C3 ] SBSDWSCService  C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
19:35:44.0821 0x230c  SBSDWSCService - ok
19:35:44.0827 0x230c  [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E865ACB9A620024 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
19:35:44.0854 0x230c  SCardSvr - ok
19:35:44.0857 0x230c  [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE94BBBA584889116 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
19:35:44.0885 0x230c  scfilter - ok
19:35:44.0906 0x230c  [ 40686B59C127F0C93B4234E4A1E3472A, B2DD61CB796C6AA8AFD285D43472B94646CA6D331D282818E0FDC9DE28DDE9CF ] Schedule        C:\Windows\system32\schedsvc.dll
19:35:44.0936 0x230c  Schedule - ok
19:35:44.0940 0x230c  [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7EAEAA63F274B3E8 ] SCPolicySvc     C:\Windows\System32\certprop.dll
19:35:44.0963 0x230c  SCPolicySvc - ok
19:35:44.0969 0x230c  [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D51CE1656C1D5B8 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
19:35:44.0984 0x230c  SDRSVC - ok
19:35:44.0988 0x230c  [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4E20A6BC9B7301D ] secdrv          C:\Windows\system32\drivers\secdrv.sys
19:35:45.0005 0x230c  secdrv - ok
19:35:45.0008 0x230c  [ A19623BDD61E66A12AB53992002B4F3A, E351CEEC086084A417BA3BD0EEF46114D3147EC38E3EF8BE49B724F9D028CC56 ] seclogon        C:\Windows\system32\seclogon.dll
19:35:45.0018 0x230c  seclogon - ok
19:35:45.0022 0x230c  [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6E12326FE79E7C7 ] SENS            C:\Windows\System32\sens.dll
19:35:45.0045 0x230c  SENS - ok
19:35:45.0049 0x230c  [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D65E690A07B10B8D ] SensrSvc        C:\Windows\system32\sensrsvc.dll
19:35:45.0059 0x230c  SensrSvc - ok
19:35:45.0062 0x230c  [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360EA1ABD6726F8D4 ] Serenum         C:\Windows\system32\drivers\serenum.sys
19:35:45.0078 0x230c  Serenum - ok
19:35:45.0082 0x230c  [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E31DC0C23B5DD22D ] Serial          C:\Windows\system32\drivers\serial.sys
19:35:45.0100 0x230c  Serial - ok
19:35:45.0103 0x230c  [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42EBBB867A3FFED6D ] sermouse        C:\Windows\system32\drivers\sermouse.sys
19:35:45.0118 0x230c  sermouse - ok
19:35:45.0126 0x230c  [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030147E853218811D ] SessionEnv      C:\Windows\system32\sessenv.dll
19:35:45.0150 0x230c  SessionEnv - ok
19:35:45.0152 0x230c  [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132A5BB7A2BABDE55 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
19:35:45.0170 0x230c  sffdisk - ok
19:35:45.0172 0x230c  [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148E972F2DBCA1042 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
19:35:45.0192 0x230c  sffp_mmc - ok
19:35:45.0195 0x230c  [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008ADA1890DE900197 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
19:35:45.0212 0x230c  sffp_sd - ok
19:35:45.0215 0x230c  [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A24394310E9A5F9 ] sfloppy         C:\Windows\system32\drivers\sfloppy.sys
19:35:45.0232 0x230c  sfloppy - ok
19:35:45.0242 0x230c  [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE24B84DAD55F291 ] SharedAccess    C:\Windows\System32\ipnathlp.dll
19:35:45.0270 0x230c  SharedAccess - ok
19:35:45.0279 0x230c  [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE51157E0F138257923 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
19:35:45.0307 0x230c  ShellHWDetection - ok
19:35:45.0310 0x230c  [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE569DD77D79D7820 ] SiSRaid2        C:\Windows\system32\drivers\SiSRaid2.sys
19:35:45.0324 0x230c  SiSRaid2 - ok
19:35:45.0327 0x230c  [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4A03824F1E33E5E ] SiSRaid4        C:\Windows\system32\drivers\sisraid4.sys
19:35:45.0342 0x230c  SiSRaid4 - ok
19:35:45.0346 0x230c  [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE10DB80E958D740 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
19:35:45.0377 0x230c  Smb - ok
19:35:45.0382 0x230c  [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C0209155BFB76C630 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
19:35:45.0392 0x230c  SNMPTRAP - ok
19:35:45.0394 0x230c  [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59EACB393BE35A063 ] spldr           C:\Windows\system32\drivers\spldr.sys
19:35:45.0408 0x230c  spldr - ok
19:35:45.0423 0x230c  [ 85DAA09A98C9286D4EA2BA8D0E644377, F9C324E2EF81193FE831C7EECC44A100CA06F82FA731BF555D9EA4D91DA13329 ] Spooler         C:\Windows\System32\spoolsv.exe
19:35:45.0442 0x230c  Spooler - ok
19:35:45.0499 0x230c  [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C50AAF36F97E27F ] sppsvc          C:\Windows\system32\sppsvc.exe
19:35:45.0590 0x230c  sppsvc - ok
19:35:45.0596 0x230c  [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365F065A0CBF33314 ] sppuinotify     C:\Windows\system32\sppuinotify.dll
19:35:45.0620 0x230c  sppuinotify - ok
19:35:45.0630 0x230c  [ EC666682FE8344CF7E6ED69E74FA9F4F, DCD2A1C046425630689E2C9A6A6E356FE5A2A6664D12C20CFE236FCB32240DF9 ] srv             C:\Windows\system32\DRIVERS\srv.sys
19:35:45.0653 0x230c  srv - ok
19:35:45.0664 0x230c  [ E450C0318DCE8ED28ED272C8806B8495, D2FD459F8C5E42103EF2F71421FA175A4F0821F8C2A3763093122D433D1C50FB ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
19:35:45.0690 0x230c  srv2 - ok
19:35:45.0695 0x230c  [ 9C12C78AD36C23D925711A4640228225, FF72C23F2A08EDF0C41BAF1EB0245AB44FF91365C5466F09C47A8F0928D20994 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
19:35:45.0715 0x230c  srvnet - ok
19:35:45.0721 0x230c  [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DAA4B935338BD740 ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
19:35:45.0748 0x230c  SSDPSRV - ok
19:35:45.0752 0x230c  [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F212CC094569D9D ] SstpSvc         C:\Windows\system32\sstpsvc.dll
19:35:45.0775 0x230c  SstpSvc - ok
19:35:45.0803 0x230c  [ 852CD3468C70249D47B1E137EE8264DC, 7C1D43FD6A2E0687E28E8E031206C338969AEB7E5C32BA6F0EC4E1F28A556115 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe
19:35:45.0833 0x230c  Steam Client Service - ok
19:35:45.0838 0x230c  [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C21920BA648B4D5 ] stexstor        C:\Windows\system32\drivers\stexstor.sys
19:35:45.0851 0x230c  stexstor - ok
19:35:45.0865 0x230c  [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DFE62B88B11DEF92 ] stisvc          C:\Windows\System32\wiaservc.dll
19:35:45.0887 0x230c  stisvc - ok
19:35:45.0891 0x230c  [ 7785DC213270D2FC066538DAF94087E7, F09CB2895241719CA5147B2EE9F7ECBD0303AFFB5CD896F06D4D29BAAAFC207B ] storflt         C:\Windows\system32\drivers\vmstorfl.sys
19:35:45.0905 0x230c  storflt - ok
19:35:45.0909 0x230c  [ C40841817EF57D491F22EB103DA587CC, 5FAA2DE43BADC16A898C0C290C44C41E4411D919A95FE8C6FF45EA7A34495079 ] StorSvc         C:\Windows\system32\storsvc.dll
19:35:45.0920 0x230c  StorSvc - ok
19:35:45.0923 0x230c  [ D34E4943D5AC096C8EDEEBFD80D76E23, 1DD7F6F97060B5F763A04ACA1F75E59DAB09EF824FD09B83FC3C192837D006DE ] storvsc         C:\Windows\system32\drivers\storvsc.sys
19:35:45.0938 0x230c  storvsc - ok
19:35:45.0941 0x230c  [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC9522B58B998E1F969 ] swenum          C:\Windows\system32\DRIVERS\swenum.sys
19:35:45.0954 0x230c  swenum - ok
19:35:45.0965 0x230c  [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140F50061052AC418 ] swprv           C:\Windows\System32\swprv.dll
19:35:45.0998 0x230c  swprv - ok
19:35:46.0031 0x230c  [ 2E730941CC5BF6200A4F56D1E9C24AAD, 758836D55DC84F3EBE9917DC6FAB8E6170A5B238FEDBCFDB6D7C5C6EA98E08B2 ] SysMain         C:\Windows\system32\sysmain.dll
19:35:46.0068 0x230c  SysMain - ok
19:35:46.0074 0x230c  [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD994983DBFF56B3A8A0 ] TabletInputService C:\Windows\System32\TabSvc.dll
19:35:46.0088 0x230c  TabletInputService - ok
19:35:46.0091 0x230c  [ D765F43CBEA72D14C04AF3D2B9C8E54B, 89C5CA1440DF186497CE158EB71C0C6BF570A75B6BC1880EAC7C87A0250201C0 ] tap0901         C:\Windows\system32\DRIVERS\tap0901.sys
19:35:46.0107 0x230c  tap0901 - ok
19:35:46.0115 0x230c  [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52455F7C2426121F ] TapiSrv         C:\Windows\System32\tapisrv.dll
19:35:46.0143 0x230c  TapiSrv - ok
19:35:46.0145 0x230c  TBS - ok
19:35:46.0179 0x230c  [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
19:35:46.0225 0x230c  Tcpip - ok
19:35:46.0255 0x230c  [ B2875D7ABB82867DC3AA03D991940201, F954C33FBA912A517B59330F6438C1953F9F1D8F4D8FD25945EB836A1DB07ABB ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
19:35:46.0290 0x230c  TCPIP6 - ok
19:35:46.0297 0x230c  [ 7FE5586314EE7D6AA8483264A089E5AF, 4E3EA68713A45C22F1B9A1AA125E15D06D0C5E637B815537431ADFB6D7563879 ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
19:35:46.0313 0x230c  tcpipreg - ok
19:35:46.0318 0x230c  [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F9C4E18A965082D ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
19:35:46.0333 0x230c  TDPIPE - ok
19:35:46.0335 0x230c  [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B29CB298166A5DF9 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
19:35:46.0350 0x230c  TDTCP - ok
19:35:46.0355 0x230c  [ AA77EB517D2F07A947294F260E3ACA83, B7A5DF3066830C0C2302B059778A67419792058A0D300C471DE40AB245EA7E58 ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
19:35:46.0373 0x230c  tdx - ok
19:35:46.0569 0x230c  [ 44449A0EB8EBD8DCBC3ED4BB62BA3A5F, 168197015D1E5ED71775250084C224A1100E0F989A6D1CC4102004E5AAD74F3A ] TeamViewer      C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
19:35:46.0757 0x230c  TeamViewer - ok
19:35:46.0772 0x230c  [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFBF2BDC9FAA8110D ] TermDD          C:\Windows\system32\DRIVERS\termdd.sys
19:35:46.0788 0x230c  TermDD - ok
19:35:46.0791 0x230c  [ EF4469AB69EB15E5D3754E6AEAFBCD3D, 3609214C3D5181364B544EBF17E9A109952BE1C4C35BE0A8727BFA8F49ECB130 ] terminpt        C:\Windows\system32\drivers\terminpt.sys
19:35:46.0807 0x230c  terminpt - ok
19:35:46.0821 0x230c  [ 008CD4EBFABCF78D0F19B3778492648C, 9050490EEE0AD86E73F0A82D83E4FC29DF84F6B6FDB389AE135FD712B5F425BE ] TermService     C:\Windows\System32\termsrv.dll
19:35:46.0843 0x230c  TermService - ok
19:35:46.0848 0x230c  [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8CCC10586CB0832 ] Themes          C:\Windows\system32\themeservice.dll
19:35:46.0861 0x230c  Themes - ok
19:35:46.0865 0x230c  [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B172002B1561EC7E265A ] THREADORDER     C:\Windows\system32\mmcss.dll
19:35:46.0889 0x230c  THREADORDER - ok
19:35:46.0893 0x230c  [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB86278D8AC96B07 ] TrkWks          C:\Windows\System32\trkwks.dll
19:35:46.0920 0x230c  TrkWks - ok
19:35:46.0926 0x230c  [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF321DF14E46A046 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
19:35:46.0951 0x230c  TrustedInstaller - ok
19:35:46.0955 0x230c  [ E232A3B43A894BB327FC161529BD9ED1, F2673DA8C920F21ACCECC25F7C59A05822E5E577D47F126EDF9C94FEB4B30C5F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
19:35:46.0970 0x230c  tssecsrv - ok
19:35:46.0973 0x230c  [ 17C6B51CBCCDED95B3CC14E22791F85E, EE417C19E9B2C258D62A74F1F2421AFFBAC67ACD62481CAA08F5B6A3439C1D7C ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
19:35:46.0990 0x230c  TsUsbFlt - ok
19:35:46.0994 0x230c  [ AD64450A4ABE076F5CB34CC08EEACB07, B5C386635441A19178E7FEEE299BA430C8D72F9110866C13A216B12A1080AD12 ] TsUsbGD         C:\Windows\system32\drivers\TsUsbGD.sys
19:35:47.0010 0x230c  TsUsbGD - ok
19:35:47.0016 0x230c  [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559F18238F2CC92B8 ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
19:35:47.0048 0x230c  tunnel - ok
19:35:47.0052 0x230c  [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF11C10FF6E3E9123 ] uagp35          C:\Windows\system32\drivers\uagp35.sys
19:35:47.0067 0x230c  uagp35 - ok
19:35:47.0075 0x230c  [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A03E1BE6D5D456E3 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
19:35:47.0114 0x230c  udfs - ok
19:35:47.0120 0x230c  [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E26D1C084972F9B ] UI0Detect       C:\Windows\system32\UI0Detect.exe
19:35:47.0131 0x230c  UI0Detect - ok
19:35:47.0134 0x230c  [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D72050D8B102B3A ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
19:35:47.0149 0x230c  uliagpkx - ok
19:35:47.0153 0x230c  [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606C2D3E992AEDDFE ] umbus           C:\Windows\system32\DRIVERS\umbus.sys
19:35:47.0168 0x230c  umbus - ok
19:35:47.0171 0x230c  [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DFB0944504564A43 ] UmPass          C:\Windows\system32\drivers\umpass.sys
19:35:47.0185 0x230c  UmPass - ok
19:35:47.0190 0x230c  [ A293DCD756D04D8492A750D03B9A297C, 203600ED0B7F8BA4C6D6F4ED810F4DF5AB70928B06EC4131C5D8ADF628444ED1 ] UmRdpService    C:\Windows\System32\umrdp.dll
19:35:47.0204 0x230c  UmRdpService - ok
19:35:47.0210 0x230c  [ D475271F1A8F06E25753CFE570D0E555, EE24597B2407AC8E6783DAFF8C1A270FC3972F980A082104B4F6FC5103B27D10 ] Update_Service  C:\Program Files\Smart Update\Update_Service.exe
19:35:47.0219 0x230c  Update_Service - detected UnsignedFile.Multi.Generic ( 1 )
19:35:48.0268 0x230c  Update_Service ( UnsignedFile.Multi.Generic ) - warning
19:35:49.0345 0x230c  [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609BCAF574941AA7AE ] upnphost        C:\Windows\System32\upnphost.dll
19:35:49.0376 0x230c  upnphost - ok
19:35:49.0391 0x230c  [ 28B81917A195B67617AF7DCF4DFE5736, 40A4D2AAE1BDE5ABA8708ED150396E913C566ECD5CDA40D6C6DB256F1B9FD4A9 ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
19:35:49.0407 0x230c  usbccgp - ok
19:35:49.0407 0x230c  [ 80B0F7D5CCF86CEB5D402EAAF61FEC31, 140C62116A425DEAD25FE8D82DE283BC92C482A9F643658D512F9F67061F28AD ] usbcir          C:\Windows\system32\drivers\usbcir.sys
19:35:49.0423 0x230c  usbcir - ok
19:35:49.0438 0x230c  [ B626F048318DAE65A3317F0592BE592C, 284D8FFE1D35F852EFDA182A72288AC3A10D6ED825FE2CC5812497D3FE291AF1 ] usbehci         C:\Windows\system32\drivers\usbehci.sys
19:35:49.0454 0x230c  usbehci - ok
19:35:49.0469 0x230c  [ 390109E8E05BA00375DCB1ED64DC60AF, B8628502590B423BEFB6F7C8C69FAD0667AD0746FF6B444EE02016E8E1052B78 ] usbhub          C:\Windows\system32\drivers\usbhub.sys
19:35:49.0485 0x230c  usbhub - ok
19:35:49.0485 0x230c  [ B4DF0F4C1D9D25DFE1DAD1D8670F1D4F, 4317C2DEDC639527B53864BAEC46CBE022D298C0503E29E1072DD1C851D92BFC ] usbohci         C:\Windows\system32\drivers\usbohci.sys
19:35:49.0501 0x230c  usbohci - ok
19:35:49.0501 0x230c  [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7EBCA7BBAAD9F7C ] usbprint        C:\Windows\system32\drivers\usbprint.sys
19:35:49.0532 0x230c  usbprint - ok
19:35:49.0532 0x230c  [ D029DD09E22EB24318A8FC3D8138BA43, C95805E8BF75ECB939520AE86420B16467B0771C161C51C9F1A37649ADFADCD0 ] USBSTOR         C:\Windows\system32\DRIVERS\USBSTOR.SYS
19:35:49.0547 0x230c  USBSTOR - ok
19:35:49.0547 0x230c  [ DD253AFC3BC6CBA412342DE60C3647F3, 146F8613F1057AC054DC3593E84BC52899DA27EA33B0E72ACFB78C3699ADCDE7 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
19:35:49.0563 0x230c  usbuhci - ok
19:35:49.0579 0x230c  [ 1F775DA4CF1A3A1834207E975A72E9D7, 6D3DE5BD3EF3A76E997E5BAF900C51D25308F5A9682D1F62017F577A24095B90 ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
19:35:49.0594 0x230c  usbvideo - ok
19:35:49.0594 0x230c  [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A0A7B337AE5AE42 ] UxSms           C:\Windows\System32\uxsms.dll
19:35:49.0625 0x230c  UxSms - ok
19:35:49.0625 0x230c  [ 1F9335A2C68B65E7D95985FA50968EA0, A0918C943F9CF5C6DB9440222B8E3B0DD645068B44E18253F275509550C0DF4D ] VaultSvc        C:\Windows\system32\lsass.exe
19:35:49.0641 0x230c  VaultSvc - ok
19:35:49.0641 0x230c  [ 45633D58D5DB28E5F210CF51588E537D, DF88F66E360535966557249127AC17EC11746F478DC73210526E2545422C77FF ] VBoxNetAdp      C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys
19:35:49.0657 0x230c  VBoxNetAdp - ok
19:35:49.0657 0x230c  [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E733827ADCFBE0D ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
19:35:49.0672 0x230c  vdrvroot - ok
19:35:49.0688 0x230c  [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368E36CE4AA3D0633 ] vds             C:\Windows\System32\vds.exe
19:35:49.0719 0x230c  vds - ok
19:35:49.0719 0x230c  [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A473673F0A82D15A2838 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
19:35:49.0735 0x230c  vga - ok
19:35:49.0735 0x230c  [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD38027C1BC2E3125 ] VgaSave         C:\Windows\System32\drivers\vga.sys
19:35:49.0766 0x230c  VgaSave - ok
19:35:49.0781 0x230c  [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD3915563F54054EE564BF ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
19:35:49.0797 0x230c  vhdmp - ok
19:35:49.0797 0x230c  [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A686990AA8031949D27 ] viaide          C:\Windows\system32\drivers\viaide.sys
19:35:49.0813 0x230c  viaide - ok
19:35:49.0828 0x230c  [ 86EA3E79AE350FEA5331A1303054005F, 7E7D6027EB41E591633C7383A5D29A3BA8ECFC08C177D2BCF741EE27686B1691 ] vmbus           C:\Windows\system32\drivers\vmbus.sys
19:35:49.0844 0x230c  vmbus - ok
19:35:49.0844 0x230c  [ 7DE90B48F210D29649380545DB45A187, 09522F84285D62B961868DA98C40B82E746CA4D24A9780905673A2349D6B07F4 ] VMBusHID        C:\Windows\system32\drivers\VMBusHID.sys
19:35:49.0859 0x230c  VMBusHID - ok
19:35:49.0859 0x230c  [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B2BA0E33A8A9161 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
19:35:49.0875 0x230c  volmgr - ok
19:35:49.0891 0x230c  [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628B65D6918B2E28F ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
19:35:49.0906 0x230c  volmgrx - ok
19:35:49.0922 0x230c  [ 0D08D2F3B3FF84E433346669B5E0F639, 3D6716CEC95B8861A7CC5778E91F310528DC6BEE0E57A3C8757FC675154EBDEC ] volsnap         C:\Windows\system32\drivers\volsnap.sys
19:35:49.0937 0x230c  volsnap - ok
19:35:49.0937 0x230c  [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA1642396001F2AC ] vsmraid         C:\Windows\system32\drivers\vsmraid.sys
19:35:49.0969 0x230c  vsmraid - ok
19:35:49.0984 0x230c  [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29D19B32F1F2B915 ] VSS             C:\Windows\system32\vssvc.exe
19:35:50.0047 0x230c  VSS - ok
19:35:50.0047 0x230c  [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F96458FB6B2E3D7 ] vwifibus        C:\Windows\system32\DRIVERS\vwifibus.sys
19:35:50.0062 0x230c  vwifibus - ok
19:35:50.0062 0x230c  [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21CEAB9894C1B4FB ] vwififlt        C:\Windows\system32\DRIVERS\vwififlt.sys
19:35:50.0093 0x230c  vwififlt - ok
19:35:50.0093 0x230c  [ 6A638FC4BFDDC4D9B186C28C91BD1A01, 5521F1DC515586777EC4837E0AEAA3E613CC178AF1074031C4D0D0C695A93168 ] vwifimp         C:\Windows\system32\DRIVERS\vwifimp.sys
19:35:50.0109 0x230c  vwifimp - ok
19:35:50.0125 0x230c  [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F241C9C167947962 ] W32Time         C:\Windows\system32\w32time.dll
19:35:50.0140 0x230c  W32Time - ok
19:35:50.0156 0x230c  [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048181DAD81816D53 ] WacomPen        C:\Windows\system32\drivers\wacompen.sys
19:35:50.0171 0x230c  WacomPen - ok
19:35:50.0171 0x230c  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
19:35:50.0203 0x230c  WANARP - ok
19:35:50.0203 0x230c  [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC5311386EDFCB18399 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
19:35:50.0234 0x230c  Wanarpv6 - ok
19:35:50.0249 0x230c  [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE5B8D27DCDCAB61 ] WatAdminSvc     C:\Windows\system32\Wat\WatAdminSvc.exe
19:35:50.0281 0x230c  WatAdminSvc - ok
19:35:50.0312 0x230c  [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A1611C3F6E0C9AF ] wbengine        C:\Windows\system32\wbengine.exe
19:35:50.0343 0x230c  wbengine - ok
19:35:50.0343 0x230c  [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA23EC80827E49DE ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
19:35:50.0359 0x230c  WbioSrvc - ok
19:35:50.0374 0x230c  [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07C88445F90DED57 ] wcncsvc         C:\Windows\System32\wcncsvc.dll
19:35:50.0390 0x230c  wcncsvc - ok
19:35:50.0390 0x230c  [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B495A7E6A27B0DD ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
19:35:50.0405 0x230c  WcsPlugInService - ok
19:35:50.0405 0x230c  [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D568C78096E12A8 ] Wd              C:\Windows\system32\drivers\wd.sys
19:35:50.0421 0x230c  Wd - ok
19:35:50.0449 0x230c  [ E2C933EDBC389386EBE6D2BA953F43D8, AF1DEADD5F1267CCEBD226E8EEB971D1946EA6A5A9645A36F5D111F758AF2F07 ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
19:35:50.0479 0x230c  Wdf01000 - ok
19:35:50.0484 0x230c  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiServiceHost  C:\Windows\system32\wdi.dll
19:35:50.0497 0x230c  WdiServiceHost - ok
19:35:50.0501 0x230c  [ C6F7473B55510F0B93961DA03D8E3B38, 4BAB9274DED8F7AC4A52B8739F501323FFFA0367CAA24BFAFDB5523812E0CE39 ] WdiSystemHost   C:\Windows\system32\wdi.dll
19:35:50.0512 0x230c  WdiSystemHost - ok
19:35:50.0520 0x230c  [ EE841B6D1F2B9508D3ABAE52AC05A94F, F1AE981FCDBFC4672A4EABABD41382E93762EFC2EDAD96E75530E7ACA5AF1FD8 ] WebClient       C:\Windows\System32\webclnt.dll
19:35:50.0536 0x230c  WebClient - ok
19:35:50.0542 0x230c  [ CBA25A299ECDBAE3A2300B68598AABA3, 5AC6F75FBDA58CD9D17922AF2780A37B89067EB4A97EE792A644B238BE94490D ] Wecsvc          C:\Windows\system32\wecsvc.dll
19:35:50.0558 0x230c  Wecsvc - ok
19:35:50.0563 0x230c  [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D80C607784F6C75 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
19:35:50.0589 0x230c  wercplsupport - ok
19:35:50.0593 0x230c  [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675AFE40F80E8F4979 ] WerSvc          C:\Windows\System32\WerSvc.dll
19:35:50.0620 0x230c  WerSvc - ok
19:35:50.0623 0x230c  [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D176129446E099C8 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
19:35:50.0654 0x230c  WfpLwf - ok
19:35:50.0657 0x230c  [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BDAB9E75744C9A50 ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
19:35:50.0679 0x230c  WIMMount - ok
19:35:50.0683 0x230c  WinDefend - ok
19:35:50.0696 0x230c  [ DD0B0F39942C8790F9D10769A462A551, 53EA26CC227BF5A7871C0A91CFB5834A39E136CDE6D7622FA6CBB4B1896C00FE ] WindscribeService C:\Program Files (x86)\Windscribe\WindscribeService.exe
19:35:50.0706 0x230c  WindscribeService - ok
19:35:50.0707 0x230c  WinHttpAutoProxySvc - ok
19:35:50.0717 0x230c  [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D82C2A66A42DA19F ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
19:35:50.0749 0x230c  Winmgmt - ok
19:35:50.0787 0x230c  [ EBDA1B0F15CB9B2CBCC6C94824E4E054, C51314F7D611E4903DA00EFA8EB99365414436324D256083CE0B5A8E055E8E06 ] WinRM           C:\Windows\system32\WsmSvc.dll
19:35:50.0831 0x230c  WinRM - ok
19:35:50.0839 0x230c  [ FE88B288356E7B47B74B13372ADD906D, A16B166F6BB32EF9D2A142F27B9EC54CBC7B3AC915799783CF4C40E525BC9E03 ] WinUsb          C:\Windows\system32\DRIVERS\WinUsb.sys
19:35:50.0857 0x230c  WinUsb - ok
19:35:50.0875 0x230c  [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7FBD8EC240AF6726 ] Wlansvc         C:\Windows\System32\wlansvc.dll
19:35:50.0906 0x230c  Wlansvc - ok
19:35:50.0911 0x230c  [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0EFE76F95235B1D9 ] WmiAcpi         C:\Windows\system32\DRIVERS\wmiacpi.sys
19:35:50.0926 0x230c  WmiAcpi - ok
19:35:50.0934 0x230c  [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B21FDB90D102B2A ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
19:35:50.0947 0x230c  wmiApSrv - ok
19:35:50.0949 0x230c  WMPNetworkSvc - ok
19:35:50.0952 0x230c  [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F3643467829B5A573FD7655B ] WPCSvc          C:\Windows\System32\wpcsvc.dll
19:35:50.0963 0x230c  WPCSvc - ok
19:35:50.0968 0x230c  [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139991AAC289A90FE ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
19:35:50.0983 0x230c  WPDBusEnum - ok
19:35:50.0986 0x230c  [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F5E2562D517F090 ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
19:35:51.0016 0x230c  ws2ifsl - ok
19:35:51.0020 0x230c  [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E005CBEC0A7B02FA ] wscsvc          C:\Windows\System32\wscsvc.dll
19:35:51.0037 0x230c  wscsvc - ok
19:35:51.0039 0x230c  WSearch - ok
19:35:51.0086 0x230c  [ 31F32E0C1A8BA9A37EEC23DE5F27F847, 0180832BC6172C9A4C32B5B222BB3F91EA615A5EBDA98DB79ED4FED258C2D257 ] wuauserv        C:\Windows\system32\wuaueng.dll
19:35:51.0139 0x230c  wuauserv - ok
19:35:51.0145 0x230c  [ AB886378EEB55C6C75B4F2D14B6C869F, D6C4602EB8F291DADEDF3CD211013D4AC752DDE7E799C2D8D74AA4F5477CAED6 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
19:35:51.0163 0x230c  WudfPf - ok
19:35:51.0169 0x230c  [ DDA4CAF29D8C0A297F886BFE561E6659, 94E5DD649B5D86FA1A7C7D30FCF9644D0EE048D312E626111458ADF66BFBE978 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
19:35:51.0188 0x230c  WUDFRd - ok
19:35:51.0192 0x230c  [ B20F051B03A966392364C83F009F7D17, 88ECEB55AE91F58F592B96EBC10B572747D5A2F9B7629E8F371761E4F7408A65 ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
19:35:51.0203 0x230c  wudfsvc - ok
19:35:51.0210 0x230c  [ 04F82965C09CBDF646B487E145060301, 2CD8533EDBE24C3E42EB7550E20F8A2EB9E5E345B165DEF543163A6BC1FDD18B ] WwanSvc         C:\Windows\System32\wwansvc.dll
19:35:51.0224 0x230c  WwanSvc - ok
19:35:51.0287 0x230c  [ 1BB69A5EA8F2024AF1799E35EB96FCAB, 9982F1E3E81E5FDB1B8E2289877F1D1F770B1C06234EED805432C03E20F073F4 ] ZeroConfigService C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
19:35:51.0356 0x230c  ZeroConfigService - ok
19:35:51.0372 0x230c  [ E18D808B3BCDFE689A4C95665F45959F, 8B245B1EC2CEA1BE3EDA92BA3CC175A4AE196C4C1EF07081E3B5FA4DB69B4D95 ] {687703DE-DC6D-4649-892B-B8497854A6AB} C:\Program Files (x86)\CyberLink\PowerDVD15\Common\NavFilter\000.fcl
19:35:51.0385 0x230c  {687703DE-DC6D-4649-892B-B8497854A6AB} - ok
19:35:51.0389 0x230c  ================ Scan global ===============================
19:35:51.0394 0x230c  [ 168EA9CD9BD6056BB6F60B57D5304BBE, 5A2F98754F042A7D80E7483842967EB362F01D57CE9720B24C7EDAA047F24C6F ] C:\Windows\system32\basesrv.dll
19:35:51.0407 0x230c  [ 93E5D2B763374F484918A0909724B3EB, 900F1CCAEFCF77AB678C74D542ABDDA7134CD33D7811537E2829FC69E99F2B3E ] C:\Windows\system32\winsrv.dll
19:35:51.0416 0x230c  [ 93E5D2B763374F484918A0909724B3EB, 900F1CCAEFCF77AB678C74D542ABDDA7134CD33D7811537E2829FC69E99F2B3E ] C:\Windows\system32\winsrv.dll
19:35:51.0421 0x230c  [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309DC686C696790529 ] C:\Windows\system32\sxssrv.dll
19:35:51.0434 0x230c  [ 71C85477DF9347FE8E7BC55768473FCA, A86D6A6D1F5A0EFCD649792A06F3AE9B37158D48493D2ECA7F52DCC1CB9B6536 ] C:\Windows\system32\services.exe
19:35:51.0439 0x230c  [ Global ] - ok
19:35:51.0440 0x230c  ================ Scan MBR ==================================
19:35:51.0442 0x230c  [ CFEC0BC28E237AB24B54AEBEB03049FB ] \Device\Harddisk0\DR0
19:35:51.0694 0x230c  \Device\Harddisk0\DR0 - ok
19:35:51.0698 0x230c  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
19:35:51.0741 0x230c  \Device\Harddisk1\DR1 - ok
19:35:51.0745 0x230c  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk2\DR2
19:35:51.0755 0x230c  \Device\Harddisk2\DR2 - ok
19:35:51.0756 0x230c  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk3\DR3
19:35:51.0794 0x230c  \Device\Harddisk3\DR3 - ok
19:35:51.0794 0x230c  ================ Scan VBR ==================================
19:35:51.0795 0x230c  [ 499803679FE89130894BB402F0AA6673 ] \Device\Harddisk0\DR0\Partition1
19:35:51.0796 0x230c  \Device\Harddisk0\DR0\Partition1 - ok
19:35:51.0798 0x230c  [ B5E2F4273B4676661707E9915D2DE0A8 ] \Device\Harddisk1\DR1\Partition1
19:35:51.0799 0x230c  \Device\Harddisk1\DR1\Partition1 - ok
19:35:51.0801 0x230c  [ AD95300FB846A4EC9028E4E6E6A7E781 ] \Device\Harddisk1\DR1\Partition2
19:35:51.0801 0x230c  \Device\Harddisk1\DR1\Partition2 - ok
19:35:51.0803 0x230c  [ 8FEE75E9EBDA5037363BCA22055BA7DC ] \Device\Harddisk2\DR2\Partition1
19:35:51.0804 0x230c  \Device\Harddisk2\DR2\Partition1 - ok
19:35:51.0806 0x230c  [ 39AC28398387FB0F445D02FC9CA971F6 ] \Device\Harddisk3\DR3\Partition1
19:35:51.0806 0x230c  \Device\Harddisk3\DR3\Partition1 - ok
19:35:51.0807 0x230c  ================ Scan generic autorun ======================
19:35:51.0808 0x230c  BTMTrayAgent - ok
19:35:51.0808 0x230c  ETDCtrl - ok
19:35:52.0013 0x230c  [ FD2BA533158566CD5A82318D8189C773, 45B265442EAC828442C7A8DCC543A87B86FA494238A6EF7CF2A8D7C68A613F53 ] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
19:35:52.0254 0x230c  RtHDVCpl - ok
19:35:52.0291 0x230c  [ EC7059FE43C74A6281ECC08253B6D5DB, AE14E00733C0AC394457BFCD4A5ECD884286038BE2C7AAE34E3D32F3F992F29F ] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
19:35:52.0321 0x230c  RtHDVBg_Dolby - ok
19:35:52.0332 0x230c  [ EE864CD35936E4AAD8120321907DA8F5, D4A37E70302DF0A76E20F1AC1CD427A831BA80A8E1729E0E5637DC48E7A85DF3 ] C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe
19:35:52.0346 0x230c  Dolby Home Theater v4 - ok
19:35:52.0365 0x230c  [ 68A85B8EA26B65C91B73BE8D0ED52C3F, 4D00624CBF2FC739CF1672220062F5E0A54A56D4127A0B0AF093F12BF2E79C2F ] C:\Program Files (x86)\Razer\Naga\RazerNagaSysTray.exe
19:35:52.0386 0x230c  Razer Naga Driver - ok
19:35:52.0398 0x230c  [ E251950F118A13066C48BA934FED839B, 4F04BFCBE8B589C3733D27438D67BD897BA1DBD05639C5721A55CF834D128ED5 ] C:\Program Files (x86)\KeyScrambler\keyscrambler.exe
19:35:52.0414 0x230c  KeyScrambler - ok
19:35:52.0421 0x230c  [ F19BB9A114A0F85E6E8C4395322E7191, FDFAFE5535442031A1102F0AE2B50213BDACA291EF958DE59E9C3CD556BF5DA7 ] C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
19:35:52.0432 0x230c  USB3MON - ok
19:35:52.0439 0x230c  [ BABD82CCBF72F386AEB1C4FA523129B4, 738A0CFB09AEF8F2852C021902DFA915C61C42B66F92CB1E348D35E8585A970C ] C:\Program Files\Smart Update\urgent.exe
19:35:52.0446 0x230c  SmartUpdate - detected UnsignedFile.Multi.Generic ( 1 )
19:35:53.0213 0x230c  SmartUpdate ( UnsignedFile.Multi.Generic ) - warning
19:35:54.0524 0x230c  [ 1A2214CF882CE18EF513BF2A33907C51, C1E9349EA50A239F440F0353CEEE544322F2C7F731166B3256F68108F1448C1A ] C:\Program Files\Sandboxie\SbieCtrl.exe
19:35:54.0545 0x230c  SandboxieControl - ok
19:35:54.0671 0x230c  [ 1DD91AE56A07B57DE293344413D29B08, 96458434FA4630CAE33498AA6DEFE4F9032C356E71FB6ABF1CD0E92799FE351C ] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
19:35:54.0817 0x230c  SUPERAntiSpyware - ok
19:35:54.0887 0x230c  [ 466A91126359C1C626D97F3665212C57, F0C3D67C0A29F975DC5AA22769A4AC43CB337567F062852B0CFED244DD21B0F2 ] C:\Program Files (x86)\Internet Download Manager\IDMan.exe
19:35:55.0173 0x230c  IDMan - ok
19:35:55.0320 0x230c  [ EB05343AA5BEEBCD5249C10B974F1F9A, 008B879F518448669E92D66D1EFC119BB156129CAED664A6B57776B14FA9BE4F ] C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe
19:35:55.0467 0x230c  DisplayFusion - ok
19:35:55.0498 0x230c  [ 8419F773455D7A7EC572AB1CC69BEA9E, AE859B41D282FF024D3539A775C1B143B22CAB912BDBB3ED86E95F5265628F04 ] C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe
19:35:55.0526 0x230c  WinPatrol - ok
19:35:55.0544 0x230c  [ 1A2214CF882CE18EF513BF2A33907C51, C1E9349EA50A239F440F0353CEEE544322F2C7F731166B3256F68108F1448C1A ] C:\Program Files\Sandboxie\SbieCtrl.exe
19:35:55.0563 0x230c  SandboxieControl - ok
19:35:55.0706 0x230c  [ EB05343AA5BEEBCD5249C10B974F1F9A, 008B879F518448669E92D66D1EFC119BB156129CAED664A6B57776B14FA9BE4F ] C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe
19:35:55.0844 0x230c  DisplayFusion - ok
19:35:55.0890 0x230c  [ 390679F7A217A5E73D756276C40AE887, 3EDFB645B2F58864E653C66516D6D48C4F9D691CFD51D91D4D88E316EE7B7177 ] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
19:35:55.0931 0x230c  SpybotSD TeaTimer - detected UnsignedFile.Multi.Generic ( 1 )
19:35:57.0348 0x230c  Detect skipped due to KSN trusted
19:35:57.0348 0x230c  SpybotSD TeaTimer - ok
19:35:57.0375 0x230c  [ 8419F773455D7A7EC572AB1CC69BEA9E, AE859B41D282FF024D3539A775C1B143B22CAB912BDBB3ED86E95F5265628F04 ] C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe
19:35:57.0400 0x230c  WinPatrol - ok
19:35:57.0524 0x230c  [ 1DD91AE56A07B57DE293344413D29B08, 96458434FA4630CAE33498AA6DEFE4F9032C356E71FB6ABF1CD0E92799FE351C ] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
19:35:57.0645 0x230c  SUPERAntiSpyware - ok
19:35:57.0651 0x230c  Waiting for KSN requests completion. In queue: 115
19:35:58.0651 0x230c  Waiting for KSN requests completion. In queue: 115
19:35:59.0673 0x230c  AV detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\wmiav.exe ( 16.0.1.445 ), 0x41000 ( enabled : updated )
19:35:59.0674 0x230c  FW detected via SS2: Kaspersky Internet Security, C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 16.0.1\wmiav.exe ( 16.0.1.445 ), 0x41010 ( enabled )
19:36:00.0871 0x230c  ============================================================
19:36:00.0871 0x230c  Scan finished
19:36:00.0871 0x230c  ============================================================
19:36:00.0876 0x2668  Detected object count: 3
19:36:00.0876 0x2668  Actual detected object count: 3
19:36:20.0286 0x2668  ElevateService ( UnsignedFile.Multi.Generic ) - skipped by user
19:36:20.0286 0x2668  ElevateService ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:36:20.0286 0x2668  Update_Service ( UnsignedFile.Multi.Generic ) - skipped by user
19:36:20.0286 0x2668  Update_Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:36:20.0287 0x2668  SmartUpdate ( UnsignedFile.Multi.Generic ) - skipped by user
19:36:20.0287 0x2668  SmartUpdate ( UnsignedFile.Multi.Generic ) - User select action: Skip
19:36:24.0766 0x246c  Deinitialize success
 

TDSSK went over that and found *two* Audiosrv.dll files...but I can only see one; what do make of this?

 

I will upload ESET's log file when it's done by the way(either by editing this post or if you've posted a reply, the next reply will have the log) - I just wanted to ask you this question in the meantime... :scratch:

 

EDIT: Found a reason why Jotti and virustotal might not be able to open the file to scan:

 

A system file is in use when the OS is up and running and to remove or open it while it's in use would crash the system. Oh, you could open it, but you would have to jump through hoops resetting the permissions to do it.

from here.


Edited by Nub, 14 March 2017 - 09:26 AM.

    Advertisements

Register to Remove


#11 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 14 March 2017 - 09:34 AM

Why dont you cancel the ESET scan for the time being unless it looks like its almost done in that case let it finish. Before we run TDSSKiller again to fix what it found, run this excellent rootkit scanner from Malwarebytes

 

Please download Malwarebytes Anti-Rootkit (MBAR) from Here and save it to your desktop. 
  •  
  • Unzip the contents to a folder in a convenient location.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • When done, please post the two logs produced they will be in the MBAR folder... mbar-log.txt and system-log.txt
 


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#12 Nub

Nub

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 14 March 2017 - 06:35 PM

Sorry I went to sleep and left it running on your last reply.... :P

 

Anyways, so it finished......there is no log file in "C:\Program Files\EsetOnlineScanner\log.txt".... Where's the log file so I can post it here? ....because it did find 4 items............

 

Also MBAR picked this up upon start:

1_2.png

 

I clicked No to see what would happen...will click yes next time if it crashes/fail to scan....

 

EDIT: Well cleanup finished and found nothing!

 

Here are them logs you requested:

 

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org

Database version:
  main:    v2017.03.14.10
  rootkit: v2017.03.11.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18537
Manectric :: RAIKOU [administrator]

15/03/2017 8:37:39 AM
mbar-log-2017-03-15 (08-37-39).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled:
Objects scanned: 346139
Time elapsed: 5 minute(s), 21 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
 

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.09.3.1001

© Malwarebytes Corporation 2011-2012

OS version: 6.1.7601 Windows 7 Service Pack 1 x64

Account is Administrative

Internet Explorer version: 11.0.9600.18537

File system is: NTFS
Disk drives: B:\ DRIVE_FIXED, C:\ DRIVE_FIXED, E:\ DRIVE_FIXED
CPU speed: 2.494000 GHz
Memory total: 17094299648, free: 12158771200

Downloaded database version: v2017.03.14.10
Downloaded database version: v2017.03.11.01
Downloaded database version: v2017.03.14.01
=======================================
Initializing...
Driver version: 0.3.0.4
------------ Kernel report ------------
     03/15/2017 08:37:33
------------ Loaded modules -----------
\SystemRoot\system32\ntoskrnl.exe
\SystemRoot\system32\hal.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_GenuineIntel.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\DRIVERS\kl1.sys
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\system32\drivers\iusb3hcs.sys
\SystemRoot\system32\DRIVERS\cm_km.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\compbatt.sys
\SystemRoot\system32\drivers\BATTC.SYS
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\DRIVERS\klbackupdisk.sys
\SystemRoot\system32\DRIVERS\FLTMGR.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\iaStorA.sys
\SystemRoot\system32\drivers\storport.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\msrpc.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\system32\drivers\ndis.sys
\SystemRoot\system32\drivers\NETIO.SYS
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\vmstorfl.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\system32\DRIVERS\nvpciflt.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\system32\drivers\iaStorF.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\drivers\disk.sys
\SystemRoot\system32\drivers\CLASSPNP.SYS
\SystemRoot\system32\DRIVERS\klhk.sys
\SystemRoot\system32\DRIVERS\cdrom.sys
\SystemRoot\system32\DRIVERS\klbackupflt.sys
\SystemRoot\system32\DRIVERS\klflt.sys
\SystemRoot\system32\DRIVERS\klif.sys
\SystemRoot\system32\DRIVERS\ks.sys
\SystemRoot\system32\DRIVERS\klpd.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\DRIVERS\TDI.SYS
\SystemRoot\system32\DRIVERS\kltdi.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\vwififlt.sys
\SystemRoot\system32\DRIVERS\ndisrd.sys
\SystemRoot\system32\DRIVERS\klim6.sys
\SystemRoot\system32\DRIVERS\klwtp.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\DRIVERS\termdd.sys
\??\C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
\??\C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\DRIVERS\mssmbios.sys
\SystemRoot\system32\DRIVERS\kneps.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\system32\drivers\csc.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\DRIVERS\igdkmd64.sys
\SystemRoot\system32\DRIVERS\HDAudBus.sys
\SystemRoot\system32\DRIVERS\iusb3xhc.sys
\SystemRoot\system32\DRIVERS\USBD.SYS
\SystemRoot\system32\DRIVERS\TeeDriverx64.sys
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\DRIVERS\Rt64win7.sys
\SystemRoot\system32\DRIVERS\Netwsw02.sys
\SystemRoot\system32\DRIVERS\vwifibus.sys
\SystemRoot\system32\DRIVERS\RtsPer.sys
\SystemRoot\system32\DRIVERS\i8042prt.sys
\SystemRoot\System32\drivers\keyscrambler.sys
\SystemRoot\system32\DRIVERS\ETD.sys
\SystemRoot\system32\DRIVERS\klkbdflt.sys
\SystemRoot\system32\DRIVERS\kbdclass.sys
\SystemRoot\system32\DRIVERS\klmouflt.sys
\SystemRoot\system32\DRIVERS\mouclass.sys
\SystemRoot\system32\DRIVERS\CmBatt.sys
\SystemRoot\system32\DRIVERS\wmiacpi.sys
\SystemRoot\system32\DRIVERS\intelppm.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\DRIVERS\tap0901.sys
\SystemRoot\system32\DRIVERS\swenum.sys
\SystemRoot\system32\drivers\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\DRIVERS\IntcDAud.sys
\SystemRoot\system32\DRIVERS\portcls.sys
\SystemRoot\system32\DRIVERS\drmk.sys
\SystemRoot\system32\drivers\ksthunk.sys
\SystemRoot\system32\DRIVERS\iusb3hub.sys
\SystemRoot\system32\drivers\RTKVHD64.sys
\SystemRoot\system32\DRIVERS\usbccgp.sys
\SystemRoot\system32\DRIVERS\hidusb.sys
\SystemRoot\system32\DRIVERS\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\system32\DRIVERS\RzSynapse.sys
\SystemRoot\system32\DRIVERS\kbdhid.sys
\SystemRoot\system32\DRIVERS\ibtusb.sys
\SystemRoot\system32\DRIVERS\btmhsf.sys
\SystemRoot\System32\Drivers\BTHUSB.sys
\SystemRoot\System32\Drivers\bthport.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\DRIVERS\rfcomm.sys
\SystemRoot\system32\DRIVERS\BthEnum.sys
\SystemRoot\system32\DRIVERS\bthpan.sys
\SystemRoot\system32\DRIVERS\btmaux.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\System32\ATMFD.DLL
\SystemRoot\system32\drivers\luafv.sys
\??\C:\Program Files\Sandboxie\SbieDrv.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\idmwfp.sys
\SystemRoot\system32\DRIVERS\kldisk.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\??\C:\Program Files (x86)\CyberLink\PowerDVD15\Common\NavFilter\000.fcl
\SystemRoot\system32\DRIVERS\vwifimp.sys
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\??\C:\ProgramData\Kaspersky Lab\AVP16.0.1\Bases\klids.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\nsi.dll
\Windows\System32\psapi.dll
\Windows\System32\oleaut32.dll
\Windows\System32\msctf.dll
\Windows\System32\imagehlp.dll
\Windows\System32\ole32.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\wininet.dll
\Windows\System32\comdlg32.dll
\Windows\System32\user32.dll
\Windows\System32\difxapi.dll
\Windows\System32\kernel32.dll
\Windows\System32\lpk.dll
\Windows\System32\clbcatq.dll
\Windows\System32\urlmon.dll
\Windows\System32\msvcrt.dll
\Windows\System32\iertutil.dll
\Windows\System32\imm32.dll
\Windows\System32\usp10.dll
\Windows\System32\shlwapi.dll
\Windows\System32\advapi32.dll
\Windows\System32\Wldap32.dll
\Windows\System32\shell32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\normaliz.dll
\Windows\System32\setupapi.dll
\Windows\System32\sechost.dll
\Windows\System32\gdi32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\wintrust.dll
\Windows\System32\crypt32.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\comctl32.dll
\Windows\System32\KernelBase.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\devobj.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\userenv.dll
\Windows\System32\profapi.dll
\Windows\System32\msasn1.dll
\Windows\SysWOW64\normaliz.dll
----------- End -----------
Done!

Scan started
Database versions:
  main:    v2017.03.14.10
  rootkit: v2017.03.11.01

<<<2>>>
Physical Sector Size: 512
Drive: 1, DevicePointer: 0xfffffa8010055790, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa80100552c0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa8010055790, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800ff6d860, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa800d97b320, DeviceName: \Device\00000071\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xfffffa801007f790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa801007f2c0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa801007f790, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800ff6dc50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa800d9809c0, DeviceName: \Device\0000006f\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 0
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: E71727C5

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 3907025072
    Partition is not bootable
    Partition file system is NTFS

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 2000398934016 bytes
Sector size: 512 bytes

Done!
Drive 1
This is a System drive
Scanning MBR on drive 1...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: AEFDE666

Partition information:

    Partition 0 type is Other (0x27)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 31457280
    Partition is bootable
    Partition file system is NTFS

    Partition 1 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 31459328  Numsec = 532480
    Partition is bootable
    Partition file system is NTFS

    Partition 2 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 31991808  Numsec = 218075136
    Partition is not bootable
    Partition file system is NTFS

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 128035676160 bytes
Sector size: 512 bytes

Done!
Physical Sector Size: 512
Drive: 2, DevicePointer: 0xfffffa801005b790, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xfffffa801005b2c0, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xfffffa801005b790, DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
DevicePointer: 0xfffffa800ff70c50, DeviceName: Unknown, DriverName: \Driver\iaStorF\
DevicePointer: 0xfffffa800d9a4060, DeviceName: \Device\00000072\, DriverName: \Driver\iaStorA\
------------ End ----------
Alternate DeviceName: \Device\Harddisk2\DR2\, DriverName: \Driver\Disk\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
Drive 2
Scanning MBR on drive 2...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 69318C77

Partition information:

    Partition 0 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 2048  Numsec = 1953519616
    Partition is not bootable
    Partition file system is NTFS

    Partition 1 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
    Partition is not bootable

Disk Size: 1000204886016 bytes
Sector size: 512 bytes

Done!
Scan finished
=======================================


Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-1-31459328-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-1-2-31991808-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-1-r.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-2-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-2-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-2-r.mbam...
Removal finished
 


Edited by Nub, 14 March 2017 - 06:45 PM.


#13 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 14 March 2017 - 08:07 PM

ESET report should be here C:\Program Files\EsetOnlineScanner\log.txt, not sure why you cant see it, Sometimes it picks up false positives and sometimes just bad cookies

 

 

Before we fix anything with Malwarebytes Anti Rootkit let run one more program and see what it finds

 

RK2_zps0modv4gs.jpg
Download RogueKiller from Here or Here To your DESKTOP
  •  
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Windows Vista,  Windows 7, 8 or 10  right-click on RogueKiller and select "Run as  Administrator" to start the program.
  • For Windows XP, double-click on RogueKiller to start the program.
  • If the program has been blocked by malware, try to rename it to winlogon.exe, or change its file extension with .com (ex: Roguekiller.com)
  • If a message pops up telling you your running the 32 bit version just click on "Run Anyway"
  • The free version will not allow you to change any setting so just leave it all be.
  • The scan is triggered with the Start Scan button. The scan does not modify your system. 
  • Wait until the Status box shows "Scan Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller
 


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#14 Nub

Nub

    New Member

  • Authentic Member
  • Pip
  • 17 posts

Posted 14 March 2017 - 08:31 PM

Ok, well then help me find where this folder is located if this is what I'm looking at:

1_2.png

 

No EsetOnlineScanner folder in this directory.... The only folder here that starts with the letter "E" is Elentech....

 

Portable version can be downloaded here: http://www.adlice.co...ad/roguekiller/as the other two links just downloads the full installer....

 

Will edit this post for report or next post if you reply.

 

EDIT: Here you go, the report:

 

RogueKiller V12.10.0.0 (x64) [Mar 13 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.co...ad/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Manectric [Administrator]
Started from : C:\Users\Electrike\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 03/15/2017 10:34:53 (Duration : 00:10:39)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 12 ¤¤¤
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://localoem.msn.com/?pc=SBJB -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://localoem.msn.com/?pc=SBJB -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://localoem.msn.com/?pc=SBJB -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://localoem.msn.com/?pc=SBJB -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://localoem.msn.com/?pc=SBJB -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://localoem.msn.com/?pc=SBJB -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{4F65E33E-CBEB-441C-B813-D5B11989BAD0} | DhcpNameServer : 10.110.234.1 ([])  -> Found
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Tcpip\Parameters\Interfaces\{4F65E33E-CBEB-441C-B813-D5B11989BAD0} | DhcpNameServer : 10.110.234.1 ([])  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0  -> Found
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-2798084944-1211984927-2140173799-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 [Too big!] ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST2000LM 003 HN-M201RAD SCSI Disk Device +++++
--- User ---
[MBR] 9785cd012b1facaba5d7aacf5799958f
[BSP] 6fec8cdfe5da352767da8b647f06dfca : Unknown MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: LITEON IT LMT-128L9M SCSI Disk Device +++++
--- User ---
[MBR] bb323068ddfef9e4a572143b408c0afe
[BSP] 941eb51cd018b3a762cbbb204701b1e5 : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 31459328 | Size: 260 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 31991808 | Size: 106482 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive2: Samsung SSD 850 EVO mSAT SCSI Disk Device +++++
--- User ---
[MBR] 91c51107eb5ddc7e86930c5e1adf8fd5
[BSP] 775fb707e9e1f36b14bce732c0fbba1d : Windows Vista/7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
 

And I don't see the file "RKreport[1].txt" on my desktop....yes I ran it from the desktop.... :P

 

EDIT2: What do you think of TRON?


Edited by Nub, 15 March 2017 - 05:22 AM.


#15 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 15 March 2017 - 06:17 AM

This will fix your host file which is showing that its too big. The rest of Roguekiller looks ok

 

 
Open notepad , Go to Start --> All Programs --> Accessories --> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
 
I would run TDSSKiller again and this time select CURE
 
 
It looks like ESET just didnt create a log, happens sometimes, try this one
 
 
Most systems run just fine and protection is adequete with just one AV and one anti spyware so its up to you if you want get envolved fooling around with other programs, I am not familiar with TRON


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users