Friends Computer Needs a Checkup

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • PatL
    PCHF Member
    • Feb 2017
    • 83

    #16
    Forgot to post this the other day:
    [HEADING=1]AdwCleaner v6.045 - Logfile created 15/04/2017 at 20:14:27[/HEADING]
    [HEADING=1]Updated on 28/03/2017 by Malwarebytes[/HEADING]
    [HEADING=1]Database : 2017-03-28.2 [Local][/HEADING]
    [HEADING=1]Operating System : Windows 7 Home Premium Service Pack 1 (X64)[/HEADING]
    [HEADING=1]Username : Mitch - MITCH-PC[/HEADING]
    [HEADING=1]Running from : C:\Users\Mitch\Desktop\AdwCleaner.exe[/HEADING]
    [HEADING=1]Mode: Clean[/HEADING]
    [HEADING=1]Support : Malwarebytes Help Center[/HEADING]
    ***** [ Services ] *****

    ***** [ Folders ] *****

    [-] Folder deleted: C:\Users\Mitch\AppData\LocalLow\Veoh_Web_Player
    [-] Folder deleted: C:\Program Files (x86)\Veoh_Web_Player

    ***** [ Files ] *****

    [-] File deleted: C:\Program Files (x86)\Yahoo!\Common\unyt.exe

    ***** [ DLL ] *****

    ***** [ WMI ] *****

    ***** [ Shortcuts ] *****

    ***** [ Scheduled Tasks ] *****

    [-] Task deleted: RegSERVO

    ***** [ Registry ] *****

    [-] Key deleted: HKLM\SOFTWARE\Classes\Applications\iLividSetupV1 (1).exe
    [-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector
    [-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector.1
    [-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
    [-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
    [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector
    [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector.1
    [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
    [#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
    [-] Key deleted: HKLM\SOFTWARE\Classes\AppID{1CAE874F-F5C7-4BCC-BA46-9AD26DF35B93}
    [-] Key deleted: HKLM\SOFTWARE\Classes\AppID{39DCCEAF-C749-4390-9953-527CF916935C}
    [-] Key deleted: HKLM\SOFTWARE\Classes\AppID{EFC0651C-B6D7-49CD-A6E0-B1CE9AB5FE46}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{F56ACA29-1C99-40F1-AC64-2E44C4F6BC71}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{12D3E096-0FDF-42CC-8F44-04944F9C1648}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{22389F39-2CF4-47C4-B8B2-273BB16BF70C}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{23E3CEB3-D63A-433E-A5D0-4DB1C501B915}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{26A3152F-CF87-4C5B-8093-4D4B9EC084EB}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{29E3319C-4B3C-479F-8692-BDD2CA30BEDD}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{367BD1CD-74A3-451F-B1A4-6A2DE4129A2D}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{49F018EE-F362-4B5B-8EC8-BCF9246ABF21}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{63B73044-FC1A-4FE1-991B-FDBD4CDAA868}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{7207E52B-821E-4C05-A8D6-2965B2BE77CF}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{863FCF5D-DC39-4DA9-AF32-CB0025990EEE}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{B09E015A-4D4E-4F8D-A436-95E19140947D}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{B1E712C4-03AA-495F-B0F5-0F057E126E2A}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{D13DC65C-C77B-4986-9078-DEA3D34C71BB}
    [-] Key deleted: HKLM\SOFTWARE\Classes\Interface{F9A10D86-182A-4946-869B-70C3D109D14D}
    [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib{003028C2-EA1C-4676-A316-B5CB50917002}
    [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib{0548C79F-7B8C-455D-B228-97D35371BB62}
    [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib{61A2027D-B837-4080-A925-6E30E10DEF32}
    [-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Veoh_Web_Player
    [-] Key deleted: HKLM\SOFTWARE\Veoh_Web_Player
    [#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Veoh_Web_Player
    [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\yt.DLL
    [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\ytbbroker.EXE
    [-] Key deleted: HKLM\SOFTWARE\Classes\AppID\YTSingleInstance.DLL

    ***** [ Web browsers ] *****

    [-] [C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
    [-] [C:\Users\Mitch\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com


    :: “Tracing” keys deleted
    :: Winsock settings cleared


    C:\AdwCleaner\AdwCleaner[C0].txt - [4282 Bytes] - [15/04/2017 20:14:27]
    C:\AdwCleaner\AdwCleaner[S0].txt - [4256 Bytes] - [15/04/2017 20:13:59]

    ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4428 Bytes] ##########

    Comment

    • Malnutrition
      PCHF Moderator
      • Jul 2016
      • 7041

      #17
      Zoek Scan

      Disable your antivirus prior to this scan.
      Download Zoek
      Save the file to your desktop.
      Right click Zoek.exe and run as administrator. (Xp Users double click)
      Copy the items in red below, and paste them into Zoek.

      createsrpoint;
      ipconfig /flushdns;b
      emptyfolderscheck;delete
      emptyclsid;
      emptyalltemp;
      netsh winsock reset all;b
      autoclean;

      Now hit the run script button.
      The log will appear after a reboot, also you can find it on the C: drive.
      Post the log in your next reply.

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #18
        Re Run TDSS killer and select Cure or Delete for this…

        17:16:46.0466 0x0e54 \Device\Harddisk0\DR0 ( TDSS File System ) - skipped by user
        17:16:46.0466 0x0e54 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Skip

        Comment

        • Malnutrition
          PCHF Moderator
          • Jul 2016
          • 7041

          #19
          Quick Diag Fix.

          First please create a restore point!
          Right click on Quick Diag Run as Admin.
          Copy the content of the code box below to your clipboard.
          Click on the S within the User Interface of the program.
          Then click on Script.
          Allow completion.
          Post the log created in your next reply.

          Code:
          Key::
          [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\87566282.sys]
          [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\87566282.sys]
          [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Classes\Applications\FreeTorrentViewer.exe]
          [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Blehjoqlir]
          [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\MCAFEE]
          [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Strongvault]
          [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Tific]
          [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\Yahoo]
          [HKLM\Software\REGSERVO]
          [HKLM\Software\WOW6432Node\AdobeFlashPlayerUpdate]
          [HKLM\Software\WOW6432Node\Tific]
          [HKLM\SYSTEM\CurrentControlSet\Control\Class{03F52937-1FD6-44FB-82C6-FE988F1B1D61}]
          [HKLM\SYSTEM\CurrentControlSet\Control\Class{522119B9-1B9A-498A-AC52-148B533EFD50}]
          [HKLM\SYSTEM\CurrentControlSet\Control\Class{87C077B2-3D3B-4156-938A-EA51B451D6C6}]
          [HKLM\SYSTEM\CurrentControlSet\Control\Class{FB58BE68-EA9E-4803-847F-2CE814E7B159}]
          
          File::
          C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\ekdjfcdinekpfcedakhpngcnaamhiihn
          C:\Program Files (x86)\FreeTorrentViewer
          C:\windows\Installer\262be5.msi’
          C:\windows\Installer\9118a6.msi
          C:\windows\Installer\938618.msi
          C:\windows\System32\gatherNetworkInfo.vbs
          C:\Users\Mitch\AppData\Local\Tific
          C:\Users\Mitch\AppData\LocalLow\Yahoo!
          C:\Users\Mitch\AppData\Roaming\FreeTorrentViewer
          C:\Users\Mitch\AppData\Roaming\Tific
          C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeTorrentViewer
          C:\ProgramData\McAfee
          C:\ProgramData\REGSERVO64
          C:\ProgramData\Yahoo!
          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REGSERVO
          C:\Program Files (x86)\FreeTorrentViewer
          C:\Program Files (x86)\Yahoo!
          C:\ProgramData\Temp:373E1720
          C:\ProgramData\Temp:D1B5B4F1
          
          ADS::
          C:\ProgramData\Temp
          
          Clean::
          yes

          Comment

          • PatL
            PCHF Member
            • Feb 2017
            • 83

            #20
            Zoek didn’t complete it froze. I restarted and continued with your other instructions.

            Zoek.exe v5.0.0.1 Updated 27-09-2015
            Tool run by Mitch on Wed 04/19/2017 at 19:53:51.74.
            Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
            Running in: Safe Mode MINIMAL No Internet Access Detected
            Launched: C:\Users\Mitch\Desktop\zoek.exe [Scan all users] [Script inserted]

            ==== Older Logs ======================

            C:\zoek-results2015-09-09-020615.log 14334 bytes
            C:\zoek-results2015-09-09-152311.log 13972 bytes

            ==== Empty Folders Check ======================

            C:\PROGRA~3\Malwarebytes’ Anti-Malware (portable) deleted successfully
            C:\Users\Mitch\AppData\Local\VirtualStore deleted successfully

            ==== Deleting CLSID Registry Keys ======================

            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Stats{18DF081C-E8AD-4283-A596-FA578C2EBDC3} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Settings{18DF081C-E8AD-4283-A596-FA578C2EBDC3} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Stats{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Settings{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Stats{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Settings{DBC80044-A445-435B-BC74-9C25C1C588A9} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Stats{F3C88694-EFFA-4D78-B409-54B7B2535B14} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Settings{F3C88694-EFFA-4D78-B409-54B7B2535B14} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Stats{326E768D-4182-46FD-9C16-1449A49795F4} deleted successfully
            HKEY_USERS\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Microsoft\Windows\CurrentVersion\Ext \Settings{326E768D-4182-46FD-9C16-1449A49795F4} deleted successfully

            ==== Deleting CLSID Registry Values ======================

            ==== Deleting Services ======================

            ==== Batch Command(s) Run By Tool======================

            ==== Deleting Files \ Folders ======================

            C:\PROGRA~3\Malwarebytes’ Anti-Malware (portable) not found
            “C:\windows\Installer\2dfb0c.msi” not found
            C:\PROGRA~2\Uninstall Information\ib_uninst_455 deleted
            C:\PROGRA~2\Yahoo! deleted
            C:\install.exe deleted
            C:\PROGRA~3\Yahoo! deleted
            C:\Users\Mitch\AppData\LocalLow\Yahoo! deleted
            C:\components deleted
            C:\windows\SysNative\GroupPolicy\User deleted

            ==== Firefox Extensions Registry ======================

            [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Fi refox\Extensions]
            “{23fcfd51-4958-4f00-80a3-ae97e717ed8b}”=“C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5” [08/14/2012 02:42 PM]

            ==== Chromium Look ======================

            Google Chrome Version: 46.0.2490.86

            HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensio ns
            nneajnkjbffgblleaoojgaacokifdkhm - C:\Program Files (x86)\DivX\DivX Plus Web Player\chrome\DivXHTML5\DivXHTML5.crx[12/12/2011 06:13 AM]

            TheBflix - John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            TheBflix - John\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn
            Avast Online Security - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
            Avast Online Security - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
            Avast Online Security - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
            Avast Online Security - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
            Avast Online Security - Mitch\AppData\Local\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
            Avast Online Security - Mitch\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
            Avast Online Security - Mitch\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Application Data\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm
            Avast Online Security - Mitch\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegiea cbdmki
            OpenOffice for Chrome - Mitch\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlgfkngkdcjlfgcfdmjoafonkk hacilj
            Chrome Media Router - Mitch\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcj beemfm

            ==== Chromium Startpages ======================

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Application Data\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Preferences
            “homepage”: " http://start.toshiba.com ",
            “homepage”: " http://start.toshiba.com ",
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]
            “urls_to_restore_on_startup”: [ " http://start.toshiba.com " ]

            Comment

            • PatL
              PCHF Member
              • Feb 2017
              • 83

              #21
              20:21:29.0651 0x10fc TDSS rootkit removing tool 3.1.0.15 Apr 18 2017 11:34:02
              20:21:31.0968 0x10fc ================================================== ==========
              20:21:31.0968 0x10fc Current date / time: 2017/04/19 20:21:31.0968
              20:21:31.0968 0x10fc SystemInfo:
              20:21:31.0968 0x10fc
              20:21:31.0968 0x10fc OS Version: 6.1.7601 ServicePack: 1.0
              20:21:31.0968 0x10fc Product type: Workstation
              20:21:31.0968 0x10fc ComputerName: MITCH-PC
              20:21:31.0969 0x10fc UserName: Mitch
              20:21:31.0969 0x10fc Windows directory: C:\windows
              20:21:31.0969 0x10fc System windows directory: C:\windows
              20:21:31.0969 0x10fc Running under WOW64
              20:21:31.0969 0x10fc Processor architecture: Intel x64
              20:21:31.0969 0x10fc Number of processors: 4
              20:21:31.0969 0x10fc Page size: 0x1000
              20:21:31.0969 0x10fc Boot type: Normal boot
              20:21:31.0969 0x10fc CodeIntegrityOptions = 0x00000003
              20:21:31.0969 0x10fc ================================================== ==========
              20:21:33.0158 0x10fc KLMD registered as C:\windows\system32\drivers\12245035.sys
              20:21:33.0158 0x10fc KLMD ARK init status: drvProperties = 0xFFF00, osBuild = 7601.17835, osProperties = 0x1
              20:21:33.0867 0x10fc System UUID: {4AC945B0-CE72-7664-3072-5B55CC6AF9F4}
              20:21:34.0413 0x10fc Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 ( 465.76 Gb ), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type ‘K0’, Flags 0x00000040
              20:21:34.0416 0x10fc ================================================== ==========
              20:21:34.0416 0x10fc \Device\Harddisk0\DR0:
              20:21:34.0416 0x10fc MBR partitions:
              20:21:34.0417 0x10fc \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x3838A000
              20:21:34.0417 0x10fc ================================================== ==========
              20:21:34.0450 0x10fc C: ↔ \Device\Harddisk0\DR0\Partition1
              20:21:34.0450 0x10fc ================================================== ==========
              20:21:34.0450 0x10fc Initialize success
              20:21:34.0450 0x10fc ================================================== ==========
              20:21:43.0318 0x08e4 ================================================== ==========
              20:21:43.0318 0x08e4 Scan started
              20:21:43.0318 0x08e4 Mode: Manual; SigCheck; TDLFS;
              20:21:43.0318 0x08e4 ================================================== ==========
              20:21:43.0318 0x08e4 KSN ping started
              20:21:46.0146 0x08e4 KSN ping finished: true
              20:21:49.0475 0x08e4 ================ Scan system memory ========================
              20:21:49.0475 0x08e4 System memory - ok
              20:21:49.0475 0x08e4 ================ Scan services =============================
              20:21:49.0643 0x08e4 [ A87D604AEA360176311474C87A63BB88, B1507868C382CD5D2DBC0D62114FCFBF7A780904A2E3CA7C7C 1DD0844ADA9A8F ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
              20:21:49.0757 0x08e4 1394ohci - ok
              20:21:49.0809 0x08e4 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2, FDAAB7E23012B4D31537C5BDEF245BB0A12FA060A072C250E2 1C68E18B22E002 ] ACPI C:\windows\system32\drivers\ACPI.sys
              20:21:49.0845 0x08e4 ACPI - ok
              20:21:49.0874 0x08e4 [ 99F8E788246D495CE3794D7E7821D2CA, F91615463270AD2601F882CAED43B88E7EDA115B9FD03FC563 20E48119F15F76 ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
              20:21:49.0908 0x08e4 AcpiPmi - ok
              20:21:50.0032 0x08e4 [ 368290D0A612D62DA6F3D798B1BB8FE7, D573BF8543F37BC51B88A2473EDFD28AFBCCC446E8CADD54A9 0FA48D8739D222 ] AdobeFlashPlayerUpdateSvc C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe
              20:21:50.0049 0x08e4 AdobeFlashPlayerUpdateSvc - ok
              20:21:50.0130 0x08e4 [ 2F6B34B83843F0C5118B63AC634F5BF4, 43E3F5FBFB5D33981AC503DEE476868EC029815D459E7C36C4 ABC2D2F75B5735 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
              20:21:50.0163 0x08e4 adp94xx - ok
              20:21:50.0204 0x08e4 [ 597F78224EE9224EA1A13D6350CED962, DA7FD99BE5E3B7B98605BF5C13BF3F1A286C0DE1240617570B 46FE4605E59BDC ] adpahci C:\windows\system32\drivers\adpahci.sys
              20:21:50.0232 0x08e4 adpahci - ok
              20:21:50.0279 0x08e4 [ E109549C90F62FB570B9540C4B148E54, E804563735153EA00A00641814244BC8A347B578E7D63A16F4 3FB17566EE5559 ] adpu320 C:\windows\system32\drivers\adpu320.sys
              20:21:50.0301 0x08e4 adpu320 - ok
              20:21:50.0327 0x08e4 [ 4B78B431F225FD8624C5655CB1DE7B61, 198A5AF2125C7C41F531A652D200C083A55A97DC541E3C0B5B 253C7329949156 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
              20:21:50.0380 0x08e4 AeLookupSvc - ok
              20:21:50.0444 0x08e4 [ 1C7857B62DE5994A75B054A9FD4C3825, 83F963D7E636532B1AD30B1E727EC429317CA540F6EB3BB268 FCC0B163B67767 ] AFD C:\windows\system32\drivers\afd.sys
              20:21:50.0483 0x08e4 AFD - ok
              20:21:50.0525 0x08e4 [ 608C14DBA7299D8CB6ED035A68A15799, 45360F89640BF1127C82A32393BD76205E4FA067889C40C491 602F370C09282A ] agp440 C:\windows\system32\drivers\agp440.sys
              20:21:50.0542 0x08e4 agp440 - ok
              20:21:50.0576 0x08e4 [ 3290D6946B5E30E70414990574883DDB, 0E9294E1991572256B3CDA6B031DB9F39CA601385515EE59F1 F601725B889663 ] ALG C:\windows\System32\alg.exe
              20:21:50.0613 0x08e4 ALG - ok
              20:21:50.0651 0x08e4 [ 5812713A477A3AD7363C7438CA2EE038, A7316299470D2E57A11499C752A711BF4A71EB11C9CBA731ED 0945FF6A966721 ] aliide C:\windows\system32\drivers\aliide.sys
              20:21:50.0667 0x08e4 aliide - ok
              20:21:50.0679 0x08e4 [ 1FF8B4431C353CE385C875F194924C0C, 3EA3A7F426B0FFC2461EDF4FDB4B58ACC9D0730EDA5B728D1E A1346EA0A02720 ] amdide C:\windows\system32\drivers\amdide.sys
              20:21:50.0695 0x08e4 amdide - ok
              20:21:50.0731 0x08e4 [ 7024F087CFF1833A806193EF9D22CDA9, E7F27E488C38338388103D3B7EEDD61D05E14FB140992AEE6F 492FFC821BF529 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
              20:21:50.0751 0x08e4 AmdK8 - ok
              20:21:50.0767 0x08e4 [ 1E56388B3FE0D031C44144EB8C4D6217, E88CA76FD47BA0EB427D59CB9BE040DE133D89D4E62D03A8D6 22624531D27487 ] AmdPPM C:\windows\system32\drivers\amdppm.sys
              20:21:50.0801 0x08e4 AmdPPM - ok
              20:21:50.0839 0x08e4 [ D4121AE6D0C0E7E13AA221AA57EF2D49, 626F43C099BD197BE56648C367B711143C2BCCE96496BBDEF1 9F391D52FA01D0 ] amdsata C:\windows\system32\drivers\amdsata.sys
              20:21:50.0858 0x08e4 amdsata - ok
              20:21:50.0885 0x08e4 [ F67F933E79241ED32FF46A4F29B5120B, D6EF539058F159CC4DD14CA9B1FD924998FEAC9D325C823C7A 2DD21FEF1DC1A8 ] amdsbs C:\windows\system32\drivers\amdsbs.sys
              20:21:50.0908 0x08e4 amdsbs - ok
              20:21:50.0930 0x08e4 [ 540DAF1CEA6094886D72126FD7C33048, 296578572A93F5B74E1AD443E000B79DC99D1CBD25082E0270 4800F886A3065F ] amdxata C:\windows\system32\drivers\amdxata.sys
              20:21:50.0946 0x08e4 amdxata - ok
              20:21:50.0981 0x08e4 [ 89A69C3F2F319B43379399547526D952, 8ABDB4B8E106F96EBBA0D4D04C4F432296516E107E7BA5644E D2E50CF9BB491A ] AppID C:\windows\system32\drivers\appid.sys
              20:21:51.0042 0x08e4 AppID - ok
              20:21:51.0076 0x08e4 [ 0BC381A15355A3982216F7172F545DE1, C33AF13CB218F7BF52E967452573DF2ADD20A95C6BF9922979 4FEF07C4BBE725 ] AppIDSvc C:\windows\System32\appidsvc.dll
              20:21:51.0106 0x08e4 AppIDSvc - ok
              20:21:51.0121 0x08e4 [ 3977D4A871CA0D4F2ED1E7DB46829731, 2AF1C3225994769C3FD25CD7E9603964B035576F25B0B6D915 45566E0722FFAA ] Appinfo C:\windows\System32\appinfo.dll
              20:21:51.0151 0x08e4 Appinfo - ok
              20:21:51.0191 0x08e4 [ C484F8CEB1717C540242531DB7845C4E, C507CE26716EB923B864ED85E8FA0B24591E2784A2F4F0E78A EED7E9953311F6 ] arc C:\windows\system32\drivers\arc.sys
              20:21:51.0209 0x08e4 arc - ok
              20:21:51.0238 0x08e4 [ 019AF6924AEFE7839F61C830227FE79C, 5926B9DDFC9198043CDD6EA0B384C83B001EC225A8125628C4 A45A3E6C42C72A ] arcsas C:\windows\system32\drivers\arcsas.sys
              20:21:51.0263 0x08e4 arcsas - ok
              20:21:51.0297 0x08e4 [ A629E4799D4CD6361D1B5D573EA5C2CD, 0D62557BA9C081A3304C898FAADD596ED33271D266291917E1 CCBA6A0D52F901 ] aswHwid C:\windows\system32\drivers\aswHwid.sys
              20:21:51.0343 0x08e4 aswHwid - ok
              20:21:51.0441 0x08e4 [ 97F952A9050CAD88681F5F0F46B8D5A5, 5B939B906868EB4EF9E54E9769B84AA87B57EEB3883F9FC450 67A354315C9A89 ] aswKbd C:\windows\system32\drivers\aswKbd.sys
              20:21:51.0463 0x08e4 aswKbd - ok
              20:21:51.0497 0x08e4 [ 9C6C17C495E960E52EDE5D038EE92AE1, C056799A124C7473E871D73E3661D58B2EA01EE6F3614AEDB2 39463D0FBB9841 ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
              20:21:51.0527 0x08e4 aswMonFlt - ok
              20:21:51.0548 0x08e4 [ 8F492911129B1B32818BF894DC0C2C73, 1F6F2019EB3B3B20636F661A4692079FCAA521C626AF6A731D 5D493B415719A7 ] aswRdr C:\windows\system32\drivers\aswRdr2.sys
              20:21:51.0573 0x08e4 aswRdr - ok
              20:21:51.0605 0x08e4 [ 4ABDD84A67378E866BC15DDC9916BA71, 7F67252BE1B9979507F16C8B48D6B2D103B80C4B0765ED3E49 5DE48E5250EF63 ] aswRvrt C:\windows\system32\drivers\aswRvrt.sys
              20:21:51.0623 0x08e4 aswRvrt - ok
              20:21:51.0694 0x08e4 [ 409CDD1400B404F655EEC1B5850FD3BE, 2D8A141B18BA155632CE110343AC7A8AB790FB76781C7E7571 57D9B195CCD5BA ] aswSnx C:\windows\system32\drivers\aswSnx.sys
              20:21:51.0752 0x08e4 aswSnx - ok
              20:21:51.0823 0x08e4 [ CDB1BE967AFF65D8395B6DF2EA8CBCCF, B72DEDDE020AC0FA4DC382B7B1C5427B8D63E83DB34BB747DC 5008AFB9698E57 ] aswSP C:\windows\system32\drivers\aswSP.sys
              20:21:51.0855 0x08e4 aswSP - ok
              20:21:51.0877 0x08e4 [ F6B5E463A0BB934C26FB319EDC726F65, 8B4E94181E7C2B479F7F675C221419B42C55C74F02A0DD8FFD 9643A5A19AB944 ] aswStm C:\windows\system32\drivers\aswStm.sys
              20:21:51.0890 0x08e4 aswStm - ok
              20:21:51.0921 0x08e4 [ FE0EE5CA72BC0D41DCAAFCA70B78274B, 1D81CAF4EBAB4A9FE542F9C27D67617530295B889E3E2B2C72 C669BA55078364 ] aswVmm C:\windows\system32\drivers\aswVmm.sys
              20:21:51.0947 0x08e4 aswVmm - ok
              20:21:51.0987 0x08e4 [ 769765CE2CC62867468CEA93969B2242, 0D8F19D49869DF93A3876B4C2E249D12E83F9CE11DAE8917D3 68E292043D4D26 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
              20:21:52.0038 0x08e4 AsyncMac - ok
              20:21:52.0066 0x08e4 [ 02062C0B390B7729EDC9E69C680A6F3C, 0261683C6DC2706DCE491A1CDC954AC9C9E649376EC30760BB 4E225E18DC5273 ] atapi C:\windows\system32\drivers\atapi.sys
              20:21:52.0082 0x08e4 atapi - ok
              20:21:52.0170 0x08e4 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235 313A37FCE8F0F6 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
              20:21:52.0217 0x08e4 AudioEndpointBuilder - ok
              20:21:52.0234 0x08e4 [ F23FEF6D569FCE88671949894A8BECF1, FCE7B156ED663471CF9A736915F00302E93B50FC647563D235 313A37FCE8F0F6 ] AudioSrv C:\windows\System32\Audiosrv.dll
              20:21:52.0278 0x08e4 AudioSrv - ok
              20:21:52.0363 0x08e4 [ 8EF7C84BB20329D6DCAC09CF6B19345A, 98F2F312F273C52653DC72F8A69ACBD79F588FF1B53CC7DFA8 5C26B6F7EF620B ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
              20:21:52.0377 0x08e4 avast! Antivirus - ok
              20:21:52.0462 0x08e4 [ A6BF31A71B409DFA8CAC83159E1E2AFF, CBB83F73FFD3C3FB4F96605067739F8F7A4A40B2B05417FA49 E575E95628753F ] AxInstSV C:\windows\System32\AxInstSV.dll
              20:21:52.0505 0x08e4 AxInstSV - ok
              20:21:52.0569 0x08e4 [ 3E5B191307609F7514148C6832BB0842, DE011CB7AA4A2405FAF21575182E0793A1D83DFFC44E9A7864 D59F3D51D8D580 ] b06bdrv C:\windows\system32\drivers\bxvbda.sys
              20:21:52.0631 0x08e4 b06bdrv - ok
              20:21:52.0684 0x08e4 [ B5ACE6968304A3900EEB1EBFD9622DF2, 1DAA118D8CA3F97B34DF3D3CDA1C78EAB2ED225699FEABE89D 331AE0CB7679FA ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys
              20:21:52.0738 0x08e4 b57nd60a - ok
              20:21:52.0782 0x08e4 [ FDE360167101B4E45A96F939F388AEB0, 8D1457E866BBD645C4B9710DFBFF93405CC1193BF9AE42326F 2382500B713B82 ] BDESVC C:\windows\System32\bdesvc.dll
              20:21:52.0816 0x08e4 BDESVC - ok
              20:21:52.0867 0x08e4 [ 16A47CE2DECC9B099349A5F840654746, 77C008AEDB07FAC66413841D65C952DDB56FE7DCA5E9EF9C8F 4130336B838024 ] Beep C:\windows\system32\drivers\Beep.sys
              20:21:52.0942 0x08e4 Beep - ok
              20:21:53.0022 0x08e4 [ 82974D6A2FD19445CC5171FC378668A4, 075D25F47C0D2277E40AF8615571DAA5EB16B1824563632A9A 7EC62505C29A4A ] BFE C:\windows\System32\bfe.dll
              20:21:53.0090 0x08e4 BFE - ok
              20:21:53.0141 0x08e4 [ 1EA7969E3271CBC59E1730697DC74682, D511A34D63A6E0E6E7D1879068E2CD3D87ABEAF4936B2EA8CD DAD9F79D60FA04 ] BITS C:\windows\System32\qmgr.dll
              20:21:53.0193 0x08e4 BITS - ok
              20:21:53.0220 0x08e4 [ 61583EE3C3A17003C4ACD0475646B4D3, 17E4BECC309C450E7E44F59A9C0BBC24D21BDC66DFBA65B8F1 98A00BB47A9811 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
              20:21:53.0239 0x08e4 blbdrive - ok
              20:21:53.0275 0x08e4 [ 6C02A83164F5CC0A262F4199F0871CF5, AD4632A6A203CB40970D848315D8ADB9C898349E20D8DF4107 C2AE2703A2CF28 ] bowser C:\windows\system32\DRIVERS\bowser.sys
              20:21:53.0320 0x08e4 bowser - ok
              20:21:53.0372 0x08e4 [ F09EEE9EDC320B5E1501F749FDE686C8, 66691114C42E12F4CC6DC4078D4D2FA4029759ACDAF1B59D17 383487180E84E3 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
              20:21:53.0413 0x08e4 BrFiltLo - ok
              20:21:53.0436 0x08e4 [ B114D3098E9BDB8BEA8B053685831BE6, 0ED23C1897F35FA00B9C2848DE4ED200E18688AA7825674888 054BBC3A3EB92C ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
              20:21:53.0461 0x08e4 BrFiltUp - ok
              20:21:53.0541 0x08e4 [ 8EF0D5C41EC907751B8429162B1239ED, 9CC25F1F93FACA6F6CE23F78EB58590C39A2E3C8A3ACDF400E 8A9DE0757EADAE ] Browser C:\windows\System32\browser.dll
              20:21:53.0611 0x08e4 Browser - ok
              20:21:53.0669 0x08e4 [ 43BEA8D483BF1870F018E2D02E06A5BD, 4E6F5A5FD8C796A110B0DC9FF29E31EA78C04518FC1C840EF6 1BABD58AB10272 ] Brserid C:\windows\System32\Drivers\Brserid.sys
              20:21:53.0731 0x08e4 Brserid - ok
              20:21:53.0763 0x08e4 [ A6ECA2151B08A09CACECA35C07F05B42, E2875BB7768ABAF38C3377007AA0A3C281503474D1831E396F B6599721586B0C ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
              20:21:53.0804 0x08e4 BrSerWdm - ok
              20:21:53.0841 0x08e4 [ B79968002C277E869CF38BD22CD61524, 50631836502237AF4893ECDCEA43B9031C3DE97433F594D46A F7C3C77F331983 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
              20:21:53.0886 0x08e4 BrUsbMdm - ok
              20:21:53.0901 0x08e4 [ A87528880231C54E75EA7A44943B38BF, 4C8BBB29FDA76A96840AA47A8613C15D4466F9273A13941C19 507008629709C9 ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
              20:21:53.0920 0x08e4 BrUsbSer - ok
              20:21:53.0948 0x08e4 [ 9DA669F11D1F894AB4EB69BF546A42E8, B498B8B6CEF957B73179D1ADAF084BBB57BB3735D810F9BE2C 7B1D58A4FD25A4 ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
              20:21:53.0994 0x08e4 BTHMODEM - ok
              20:21:54.0052 0x08e4 [ 95F9C2976059462CBBF227F7AAB10DE9, 2797AE919FF7606B070FB039CECDB0707CD2131DCAC09C5DF1 4F443D881C9F34 ] bthserv C:\windows\system32\bthserv.dll
              20:21:54.0108 0x08e4 bthserv - ok
              20:21:54.0156 0x08e4 [ B8BD2BB284668C84865658C77574381A, 6C55BA288B626DF172FDFEA0BD7027FAEBA1F44EF20AB55160 D7C7DC6E717D65 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
              20:21:54.0243 0x08e4 cdfs - ok
              20:21:54.0273 0x08e4 [ F036CE71586E93D94DAB220D7BDF4416, BD07AAD9E20CEAF9FC84E4977C55EA2C45604A2C682AC70B9B 9A2199B6713D5B ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
              20:21:54.0326 0x08e4 cdrom - ok
              20:21:54.0358 0x08e4 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7E AEAA63F274B3E8 ] CertPropSvc C:\windows\System32\certprop.dll
              20:21:54.0416 0x08e4 CertPropSvc - ok
              20:21:54.0460 0x08e4 [ D7CD5C4E1B71FA62050515314CFB52CF, 513B5A849899F379F0BC6AB3A8A05C3493C2393C95F036612B 96EC6E252E1C64 ] circlass C:\windows\system32\drivers\circlass.sys
              20:21:54.0486 0x08e4 circlass - ok
              20:21:54.0531 0x08e4 [ FE1EC06F2253F691FE36217C592A0206, B9F122DB5E665ECDF29A5CB8BB6B531236F31A54A95769D6C5 C1924C87FE70CE ] CLFS C:\windows\system32\CLFS.sys
              20:21:54.0558 0x08e4 CLFS - ok
              20:21:54.0616 0x08e4 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85 D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\msco rsvw.exe
              20:21:54.0627 0x08e4 clr_optimization_v2.0.50727_32 - ok
              20:21:54.0680 0x08e4 [ D1CEEA2B47CB998321C579651CE3E4F8, 654013B8FD229A50017B08DEC6CA19C7DDA8CE0771260E057A 92625201D539B1 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\ms corsvw.exe
              20:21:54.0691 0x08e4 clr_optimization_v2.0.50727_64 - ok
              20:21:54.0789 0x08e4 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA 522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\msco rsvw.exe
              20:21:54.0801 0x08e4 clr_optimization_v4.0.30319_32 - ok
              20:21:54.0876 0x08e4 [ C6F9AF94DCD58122A4D7E89DB6BED29D, CB0E5AE60EC76323585FB86D89E8DB7ADB5EDF6EA3D0B27E9E CE75B8CAA8BFDE ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\ms corsvw.exe
              20:21:54.0887 0x08e4 clr_optimization_v4.0.30319_64 - ok
              20:21:54.0906 0x08e4 [ 0840155D0BDDF1190F84A663C284BD33, 696039FA63CFEB33487FAA8FD7BBDB220141E9C6E529355D76 8DFC87999A9C3A ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
              20:21:54.0943 0x08e4 CmBatt - ok
              20:21:54.0978 0x08e4 [ E19D3F095812725D88F9001985B94EDD, 46243C5CCC4981CAC6FA6452FFCEC33329BF172448F1852D52 592C9342E0E18B ] cmdide C:\windows\system32\drivers\cmdide.sys
              20:21:54.0994 0x08e4 cmdide - ok
              20:21:55.0043 0x08e4 [ 9AC4F97C2D3E93367E2148EA940CD2CD, 530E089E5CF868AECDB2B5548EBE76E0CA98FC74A72897292A B2485734402E3B ] CNG C:\windows\system32\Drivers\cng.sys
              20:21:55.0078 0x08e4 CNG - ok
              20:21:55.0165 0x08e4 [ 20506F12AFAD3DB588D007EA9325FBBC, 275ECBD0F668782ACE055AD5CA600A6885CFCDD4943BC52A2E A8339AF71EABAE ] CnxtHdAudService C:\windows\system32\drivers\CHDRT64.sys
              20:21:55.0226 0x08e4 CnxtHdAudService - ok
              20:21:55.0261 0x08e4 [ 102DE219C3F61415F964C88E9085AD14, CD74CB703381F1382C32CF892FF2F908F4C9412E1BC77234F8 FEA5D4666E1BF1 ] Compbatt C:\windows\system32\drivers\compbatt.sys
              20:21:55.0276 0x08e4 Compbatt - ok
              20:21:55.0299 0x08e4 [ 03EDB043586CCEBA243D689BDDA370A8, 0E4523AA332E242D5C2C61C5717DBA5AB6E42DADB5A7E51250 5FC2B6CC224959 ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys
              20:21:55.0338 0x08e4 CompositeBus - ok
              20:21:55.0362 0x08e4 COMSysApp - ok
              20:21:55.0378 0x08e4 [ 1C827878A998C18847245FE1F34EE597, 41EF7443D8B2733AA35CAC64B4F5F74FAC8BB0DA7D3936B69E C38E2DC3972E60 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
              20:21:55.0394 0x08e4 crcdisk - ok
              20:21:55.0425 0x08e4 [ 4F5414602E2544A4554D95517948B705, 50121AD32ACF73F541DF3B655020F7B610B3E7B5E8C7B39D37 D5958F28CB376E ] CryptSvc C:\windows\system32\cryptsvc.dll
              20:21:55.0463 0x08e4 CryptSvc - ok
              20:21:55.0563 0x08e4 [ 72794D112CBAFF3BC0C29BF7350D4741, 060C207F27306A3464FBCD8B08BDC97E34923ECA349933ECB0 59848BD08F41ED ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
              20:21:55.0590 0x08e4 cvhsvc - ok
              20:21:55.0650 0x08e4 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C 4D6400B354B401 ] DcomLaunch C:\windows\system32\rpcss.dll
              20:21:55.0693 0x08e4 DcomLaunch - ok
              20:21:55.0741 0x08e4 [ 3CEC7631A84943677AA8FA8EE5B6B43D, 32061DAC9ED6C1EBA3B367B18D0E965AEEC2DF635DCF794EC3 9D086D32503AC5 ] defragsvc C:\windows\System32\defragsvc.dll
              20:21:55.0791 0x08e4 defragsvc - ok
              20:21:55.0829 0x08e4 [ 9BB2EF44EAA163B29C4A4587887A0FE4, 03667BC3EA5003F4236929C10F23D8F108AFCB29DB5559E751 FB26DFB318636F ] DfsC C:\windows\system32\Drivers\dfsc.sys
              20:21:55.0888 0x08e4 DfsC - ok
              20:21:55.0957 0x08e4 [ 43D808F5D9E1A18E5EEB5EBC83969E4E, C10D1155D71EABE4ED44C656A8F13078A8A4E850C4A8FBB92D 52D173430972B8 ] Dhcp C:\windows\system32\dhcpcore.dll
              20:21:55.0995 0x08e4 Dhcp - ok
              20:21:56.0021 0x08e4 [ 13096B05847EC78F0977F2C0F79E9AB3, 1E44981B684F3E56F5D2439BB7FA78BD1BC876BB2265AE089A EC68F241B05B26 ] discache C:\windows\system32\drivers\discache.sys
              20:21:56.0090 0x08e4 discache - ok
              20:21:56.0162 0x08e4 [ 9819EEE8B5EA3784EC4AF3B137A5244C, 571BC886E87C888DA96282E381A746D273B58B9074E84D4CA9 1275E26056D427 ] Disk C:\windows\system32\drivers\disk.sys
              20:21:56.0180 0x08e4 Disk - ok
              20:21:56.0271 0x08e4 [ 16835866AAA693C7D7FCEBA8FFF706E4, 15891558F7C1F2BB57A98769601D447ED0D952354A8BB34731 2D034DC03E0242 ] Dnscache C:\windows\System32\dnsrslvr.dll
              20:21:56.0333 0x08e4 Dnscache - ok
              20:21:56.0380 0x08e4 [ B1FB3DDCA0FDF408750D5843591AFBC6, AB6AD9C5E7BA2E3646D0115B67C4800D1CB43B4B1271639765 7C7ADEEE807304 ] dot3svc C:\windows\System32\dot3svc.dll
              20:21:56.0432 0x08e4 dot3svc - ok
              20:21:56.0461 0x08e4 [ B26F4F737E8F9DF4F31AF6CF31D05820, 394BBBED4EC7FAD4110F62A43BFE0801D4AC56FFAC6C741C69 407B26402311C7 ] DPS C:\windows\system32\dps.dll
              20:21:56.0548 0x08e4 DPS - ok
              20:21:56.0583 0x08e4 [ 9B19F34400D24DF84C858A421C205754, 967AF267B4124BADA8F507CEBF25F2192D146A4D63BE71B45B FC03C5DA7F21A7 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
              20:21:56.0633 0x08e4 drmkaud - ok
              20:21:57.0462 0x08e4 [ F5BEE30450E18E6B83A5012C100616FD, 44D0577D159FC2BDF4EAD1DC2C7FD14925D075225EF97608CA C52DEE405B08FD ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
              20:21:57.0504 0x08e4 DXGKrnl - ok
              20:21:57.0579 0x08e4 [ E2DDA8726DA9CB5B2C4000C9018A9633, 0C967DBC3636A76A696997192A158AA92A1AF19F01E3C66D5B F91818A8FAEA76 ] EapHost C:\windows\System32\eapsvc.dll
              20:21:57.0633 0x08e4 EapHost - ok
              20:21:57.0866 0x08e4 [ DC5D737F51BE844D8C82C695EB17372F, 6D4022D9A46EDE89CEF0FAEADCC94C903234DFC460C0180D24 FF9E38E8853017 ] ebdrv C:\windows\system32\drivers\evbda.sys
              20:21:58.0040 0x08e4 ebdrv - ok
              20:21:58.0071 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF 8B1207F81B284D ] EFS C:\windows\System32\lsass.exe
              20:21:58.0117 0x08e4 EFS - ok
              20:21:58.0219 0x08e4 [ C4002B6B41975F057D98C439030CEA07, 3D2484FBB832EFB90504DD406ED1CF3065139B1FE164647181 1F3A5679EF75F1 ] ehRecvr C:\windows\ehome\ehRecvr.exe
              20:21:58.0277 0x08e4 ehRecvr - ok
              20:21:58.0311 0x08e4 [ 4705E8EF9934482C5BB488CE28AFC681, 359E9EC5693CE0BE89082E1D5D8F5C5439A5B985010FF0CB45 C11E3CFE30637D ] ehSched C:\windows\ehome\ehsched.exe
              20:21:58.0326 0x08e4 ehSched - ok
              20:21:58.0386 0x08e4 [ 0E5DA5369A0FCAEA12456DD852545184, 9A64AC5396F978C3B92794EDCE84DCA938E4662868250F8C18 FA7C2C172233F8 ] elxstor C:\windows\system32\drivers\elxstor.sys
              20:21:58.0419 0x08e4 elxstor - ok
              20:21:58.0428 0x08e4 [ 34A3C54752046E79A126E15C51DB409B, 7D5B5E150C7C73666F99CBAFF759029716C86F16B927E0078D 77F8A696616D75 ] ErrDev C:\windows\system32\drivers\errdev.sys
              20:21:58.0462 0x08e4 ErrDev - ok
              20:21:58.0503 0x08e4 [ 4166F82BE4D24938977DD1746BE9B8A0, 24121751B7306225AD1C808442D7B030DEF377E9316AA0A3C5 C7460E87317881 ] EventSystem C:\windows\system32\es.dll
              20:21:58.0558 0x08e4 EventSystem - ok
              20:21:58.0606 0x08e4 [ A510C654EC00C1E9BDD91EEB3A59823B, 76CD277730F7B08D375770CD373D786160F34D1481AF0536BA 1A5D2727E255F5 ] exfat C:\windows\system32\drivers\exfat.sys
              20:21:58.0649 0x08e4 exfat - ok
              20:21:58.0685 0x08e4 [ 0ADC83218B66A6DB380C330836F3E36D, 798D6F83B5DBCC1656595E0A96CF12087FCCBE19D1982890D0 CE5F629B328B29 ] fastfat C:\windows\system32\drivers\fastfat.sys
              20:21:58.0736 0x08e4 fastfat - ok
              20:21:58.0804 0x08e4 [ DBEFD454F8318A0EF691FDD2EAAB44EB, 7F52AE222FF28503B6FC4A5852BD0CAEAF187BE69AF4B577D3 DE474C24366099 ] Fax C:\windows\system32\fxssvc.exe
              20:21:58.0835 0x08e4 Fax - ok
              20:21:58.0861 0x08e4 [ D765D19CD8EF61F650C384F62FAC00AB, 9F0A483A043D3BA873232AD3BA5F7BF9173832550A27AF3E8B D433905BD2A0EE ] fdc C:\windows\system32\drivers\fdc.sys
              20:21:58.0896 0x08e4 fdc - ok
              20:21:58.0935 0x08e4 [ 0438CAB2E03F4FB61455A7956026FE86, 6D4DDC2973DB25CE0C7646BC85EFBCC004EBE35EA683F62162 AE317C6F1D8DFE ] fdPHost C:\windows\system32\fdPHost.dll
              20:21:58.0964 0x08e4 fdPHost - ok
              20:21:58.0980 0x08e4 [ 802496CB59A30349F9A6DD22D6947644, 52D59D3D628D5661F83F090F33F744F6916E0CC1F76E5A3398 3E06EB66AE19F8 ] FDResPub C:\windows\system32\fdrespub.dll
              20:21:59.0035 0x08e4 FDResPub - ok
              20:21:59.0081 0x08e4 [ 655661BE46B5F5F3FD454E2C3095B930, 549C8E2A2A37757E560D55FFA6BFDD838205F17E40561E67F0 124C934272CD1A ] FileInfo C:\windows\system32\drivers\fileinfo.sys
              20:21:59.0099 0x08e4 FileInfo - ok
              20:21:59.0119 0x08e4 [ 5F671AB5BC87EEA04EC38A6CD5962A47, 6B61D3363FF3F9C439BD51102C284972EAE96ACC0683B9DC7E 12D25D0ADC51B6 ] Filetrace C:\windows\system32\drivers\filetrace.sys
              20:21:59.0174 0x08e4 Filetrace - ok
              20:21:59.0208 0x08e4 [ C172A0F53008EAEB8EA33FE10E177AF5, 9175A95B323696D1B35C9EFEB7790DD64E6EE0B7021E6C18E2 F81009B169D77B ] flpydisk C:\windows\system32\drivers\flpydisk.sys
              20:21:59.0227 0x08e4 flpydisk - ok
              20:21:59.0246 0x08e4 [ DA6B67270FD9DB3697B20FCE94950741, F621A4462C9F2904063578C427FAF22D7D66AE9967605C11C7 98099817CE5331 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
              20:21:59.0271 0x08e4 FltMgr - ok
              20:21:59.0328 0x08e4 [ 5C4CB4086FB83115B153E47ADD961A0C, 0C3AB7D04BEB3A8FDE00B0C86E6FE064B1CEBB3E4DE1A29CD2 7830806FA300B3 ] FontCache C:\windows\system32\FntCache.dll
              20:21:59.0393 0x08e4 FontCache - ok
              20:21:59.0451 0x08e4 [ A8B7F3818AB65695E3A0BB3279F6DCE6, 89FCF10F599767E67A1E011753E34DA44EAA311F105DBF6954 9009ED932A60F0 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\Pres entationFontCache.exe
              20:21:59.0460 0x08e4 FontCache3.0.0.0 - ok
              20:21:59.0472 0x08e4 [ D43703496149971890703B4B1B723EAC, F06397B2EDCA61629249D2EF1CBB7827A8BEAB8488246BD85E F6AE1363C0DA6E ] FsDepends C:\windows\system32\drivers\FsDepends.sys
              20:21:59.0489 0x08e4 FsDepends - ok
              20:21:59.0522 0x08e4 [ 6BD9295CC032DD3077C671FCCF579A7B, 83622FBB0CB923798E7E584BF53CAAF75B8C016E3FF7F0FA35 880FF34D1DFE33 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
              20:21:59.0537 0x08e4 Fs_Rec - ok
              20:21:59.0572 0x08e4 [ 1F7B25B858FA27015169FE95E54108ED, 72DD12E924AA7273B3E4BDD2A2C581DECE304C8EF3D44EA79A BB032F3F95DCE5 ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
              20:21:59.0598 0x08e4 fvevol - ok
              20:21:59.0627 0x08e4 [ 8C778D335C9D272CFD3298AB02ABE3B6, 85F0B13926B0F693FA9E70AA58DE47100E4B6F893772EBE430 0C37D9A36E6005 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
              20:21:59.0645 0x08e4 gagp30kx - ok
              20:21:59.0712 0x08e4 [ C403C5DB49A0F9AAF4F2128EDC0106D8, 3C6948B63278022D8182F773C5FA15784514F76C1546118DDB ADBA322B962D12 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
              20:21:59.0726 0x08e4 GamesAppService - ok
              20:21:59.0776 0x08e4 Giraffic - ok
              20:21:59.0832 0x08e4 [ 277BBC7E1AA1EE957F573A10ECA7EF3A, 2EE60B924E583E847CC24E78B401EF95C69DB777A5B74E1EC9 63E18D47B94D24 ] gpsvc C:\windows\System32\gpsvc.dll
              20:21:59.0883 0x08e4 gpsvc - ok
              20:21:59.0951 0x08e4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3 418A1CF0BC53E9 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
              20:21:59.0962 0x08e4 gupdate - ok
              20:21:59.0976 0x08e4 [ DD7423ABBE2913E70D50E9318AD57EE4, 74BC123808F3FA60ADDC51C1383F8250608D3DBA3A8DC175B3 418A1CF0BC53E9 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
              20:21:59.0987 0x08e4 gupdatem - ok
              20:22:00.0038 0x08e4 [ CC839E8D766CC31A7710C9F38CF3E375, 327D57F18B4A2D1CB06C5682D3364097ECD3CF40C2719AA1F4 1D0B49A26003E4 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
              20:22:00.0051 0x08e4 gusvc - ok
              20:22:00.0107 0x08e4 [ F2523EF6460FC42405B12248338AB2F0, B2F3DE8DE1F512D871BC2BC2E8D0E33AB03335BFBC07627C5F 88B65024928E19 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
              20:22:00.0157 0x08e4 hcw85cir - ok
              20:22:00.0225 0x08e4 [ 975761C778E33CD22498059B91E7373A, 8304E15FBE6876BE57263A03621365DA8C88005EAC532A7703 03C06799D915D9 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
              20:22:00.0258 0x08e4 HdAudAddService - ok
              20:22:00.0301 0x08e4 [ 97BFED39B6B79EB12CDDBFEED51F56BB, 3CF981D668FB2381E52AF2E51E296C6CFB47B0D62249645278 479D0111A47955 ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys
              20:22:00.0357 0x08e4 HDAudBus - ok
              20:22:00.0394 0x08e4 [ 78E86380454A7B10A5EB255DC44A355F, 11F3ED7ACFFA3024B9BD504F81AC39F5B4CED5A8A425E8BADF 7132EFEDB9BD64 ] HidBatt C:\windows\system32\drivers\HidBatt.sys
              20:22:00.0430 0x08e4 HidBatt - ok
              20:22:00.0469 0x08e4 [ 7FD2A313F7AFE5C4DAB14798C48DD104, 94CBFD4506CBDE4162CEB3367BAB042D19ACA6785954DC0B55 4D4164B9FCD0D4 ] HidBth C:\windows\system32\drivers\hidbth.sys
              20:22:00.0493 0x08e4 HidBth - ok
              20:22:00.0523 0x08e4 [ 0A77D29F311B88CFAE3B13F9C1A73825, 8615DC6CEFB591505CE16E054A71A4F371B827DDFD5E980777 AB4233DCFDA01D ] HidIr C:\windows\system32\drivers\hidir.sys
              20:22:00.0545 0x08e4 HidIr - ok
              20:22:00.0574 0x08e4 [ BD9EB3958F213F96B97B1D897DEE006D, 4D01CBF898B528B3A4E5A683DF2177300AFABD7D4CB51F1A78 91B1B545499631 ] hidserv C:\windows\system32\hidserv.dll
              20:22:00.0681 0x08e4 hidserv - ok
              20:22:00.0724 0x08e4 [ 9592090A7E2B61CD582B612B6DF70536, FD11D5E02C32D658B28FCC35688AB66CCB5D3A0A0D74C82AE0 F0B6C67B568A0F ] HidUsb C:\windows\system32\drivers\hidusb.sys
              20:22:00.0763 0x08e4 HidUsb - ok
              20:22:00.0787 0x08e4 [ 387E72E739E15E3D37907A86D9FF98E2, 9935BE2E58788E79328293AF2F202CB0F6042441B176F75ACC 5AEA93C8E05531 ] hkmsvc C:\windows\system32\kmsvc.dll
              20:22:00.0851 0x08e4 hkmsvc - ok
              20:22:00.0911 0x08e4 [ EFDFB3DD38A4376F93E7985173813ABD, 70402FA73A5A2A8BB557AAC8F531E373077D28DE5F40A1F3F1 4B940BE01CD2E1 ] HomeGroupListener C:\windows\system32\ListSvc.dll
              20:22:00.0950 0x08e4 HomeGroupListener - ok
              20:22:01.0046 0x08e4 [ 908ACB1F594274965A53926B10C81E89, 7D34A742AC486294D82676F8465A3EF26C8AC3317C32B63F62 031CB007CFC208 ] HomeGroupProvider C:\windows\system32\provsvc.dll
              20:22:01.0096 0x08e4 HomeGroupProvider - ok
              20:22:01.0176 0x08e4 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC, E9E6A1665740CFBC2DD321010007EF42ABA2102AEB9772EE8A A3354664B1E205 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
              20:22:01.0193 0x08e4 HpSAMD - ok
              20:22:01.0238 0x08e4 [ 0EA7DE1ACB728DD5A369FD742D6EEE28, 21C489412EB33A12B22290EB701C19BA57006E8702E76F7309 54F0784DDE9779 ] HTTP C:\windows\system32\drivers\HTTP.sys
              20:22:01.0325 0x08e4 HTTP - ok
              20:22:01.0378 0x08e4 [ A5462BD6884960C9DC85ED49D34FF392, 53E65841AF5B06A2844D0BB6FC4DD3923A323FFA0E4BFC89B3 B5CAFB592A3D53 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
              20:22:01.0393 0x08e4 hwpolicy - ok
              20:22:01.0462 0x08e4 [ FA55C73D4AFFA7EE23AC4BE53B4592D3, 65CDDC62B89A60E942C5642C9D8B539EFB69DA8069B4A2E549 78154B314531CD ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
              20:22:01.0484 0x08e4 i8042prt - ok
              20:22:01.0524 0x08e4 [ D469B77687E12FE43E344806740B624D, DFDD486FD040813BF4E5DDB504CF9E0BFBF6D4E540DDDA4829 F9B675ACF63E89 ] iaStor C:\windows\system32\DRIVERS\iaStor.sys
              20:22:01.0551 0x08e4 iaStor - ok
              20:22:01.0603 0x08e4 [ AAAF44DB3BD0B9D1FB6969B23ECC8366, 805AA4A9464002D1AB3832E4106B2AAA1331F4281367E75956 062AAE99699385 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
              20:22:01.0633 0x08e4 iaStorV - ok
              20:22:01.0707 0x08e4 [ 1CF03C69B49ACB70C722DF92755C0C8C, C227850C133F29BB9DED91A26A22AE077FD69629CEF35B67D3 05F016C4BDAA81 ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              20:22:01.0729 0x08e4 IDriverT - detected UnsignedFile.Multi.Generic ( 1 )
              20:22:04.0482 0x08e4 Detect skipped due to KSN trusted
              20:22:04.0482 0x08e4 IDriverT - ok
              20:22:04.0601 0x08e4 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD, 2B9512324DBA4A97F6AC34E8067EE08E3B6874CD60F6CB4209 AFC22A34D2BE99 ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
              20:22:04.0631 0x08e4 idsvc - ok
              20:22:05.0682 0x08e4 [ 370C2A8629B30F910F740387795DDC6F, 7D2D69F0BC12E86236014003EEA7479BD0FDE9A469459B6550 DC3AED07A02030 ] igfx C:\windows\system32\DRIVERS\igdkmd64.sys
              20:22:06.0229 0x08e4 igfx - ok
              20:22:06.0305 0x08e4 [ 5C18831C61933628F5BB0EA2675B9D21, 5CD9DE2F8C0256623A417B5C55BF55BB2562BD7AB2C3C83BB3 D9886C2FBDA4E4 ] iirsp C:\windows\system32\drivers\iirsp.sys
              20:22:06.0325 0x08e4 iirsp - ok
              20:22:06.0390 0x08e4 [ FCD84C381E0140AF901E58D48882D26B, 76955FFC230C801E8ED890E32076075F04CD6E5EC79E594FDE 6D23797A36B406 ] IKEEXT C:\windows\System32\ikeext.dll
              20:22:06.0479 0x08e4 IKEEXT - ok
              20:22:06.0537 0x08e4 [ FC727061C0F47C8059E88E05D5C8E381, C7A3782F5D86C7FDE57AA1F2EE81638C5FC3072ACC6E572BA2 EC7B3CFF389800 ] IntcDAud C:\windows\system32\DRIVERS\IntcDAud.sys
              20:22:06.0557 0x08e4 IntcDAud - ok
              20:22:06.0576 0x08e4 [ F00F20E70C6EC3AA366910083A0518AA, E2F3E9FFD82C802C8BAC309893A3664ACF16A279959C0FDECC A64C3D3C60FD22 ] intelide C:\windows\system32\drivers\intelide.sys
              20:22:06.0593 0x08e4 intelide - ok
              20:22:06.0614 0x08e4 [ ADA036632C664CAA754079041CF1F8C1, F2386CC09AC6DE4C54189154F7D91C1DB7AA120B13FAE8BA5B 579ACF99FCC610 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
              20:22:06.0649 0x08e4 intelppm - ok
              20:22:06.0697 0x08e4 [ 098A91C54546A3B878DAD6A7E90A455B, 044CCE2A0DF56EBE1EFD99B4F6F0A5B9EE12498CA358CF4B2E 3A1CFD872823AA ] IPBusEnum C:\windows\system32\ipbusenum.dll
              20:22:06.0749 0x08e4 IPBusEnum - ok
              20:22:06.0786 0x08e4 [ C9F0E1BD74365A8771590E9008D22AB6, 728BC5A6AAE499FDC50EB01577AF16D83C2A9F3B09936DD2A8 9C01E074BA8E51 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
              20:22:06.0827 0x08e4 IpFilterDriver - ok
              20:22:06.0873 0x08e4 [ A34A587FFFD45FA649FBA6D03784D257, C9A2BCD4E2A5EB6E320092A3AFD5737ECDCDA0B83EE42314A2 3C4978F2974767 ] iphlpsvc C:\windows\System32\iphlpsvc.dll
              20:22:06.0941 0x08e4 iphlpsvc - ok
              20:22:06.0966 0x08e4 [ 0FC1AEA580957AA8817B8F305D18CA3A, 7161E4DE91AAFC3FA8BF24FAE4636390C2627DB931505247C0 D52C75A31473D9 ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
              20:22:07.0020 0x08e4 IPMIDRV - ok
              20:22:07.0047 0x08e4 [ AF9B39A7E7B6CAA203B3862582E9F2D0, 67128BE7EADBE6BD0205B050F96E268948E8660C4BAB259FB0 BE03935153D04E ] IPNAT C:\windows\system32\drivers\ipnat.sys
              20:22:07.0104 0x08e4 IPNAT - ok
              20:22:07.0145 0x08e4 [ 3ABF5E7213EB28966D55D58B515D5CE9, A352BCC5B6B9A28805B15CAFB235676F1FAFF0D2394F88C030 89EB157D6188AE ] IRENUM C:\windows\system32\drivers\irenum.sys
              20:22:07.0166 0x08e4 IRENUM - ok
              20:22:07.0184 0x08e4 [ 2F7B28DC3E1183E5EB418DF55C204F38, D40410A760965925D6F10959B2043F7BD4F68EAFCF5E743AF1 1AD860BD136548 ] isapnp C:\windows\system32\drivers\isapnp.sys
              20:22:07.0200 0x08e4 isapnp - ok
              20:22:07.0221 0x08e4 [ D931D7309DEB2317035B07C9F9E6B0BD, 13AD84172ED8C6153F8A98499C01733B74E48464CE07D09950 8E38D409913ED3 ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
              20:22:07.0246 0x08e4 iScsiPrt - ok
              20:22:07.0287 0x08e4 [ CD91D1BD200D9F39682A08E987F0DBE2, 45396B0DD37C7FAAE23F985D5F26C25E944EDA1B9A4248B5CB 16A4C4831E713B ] JLTECH0227 C:\windows\system32\Drivers\jl2005c.sys
              20:22:07.0305 0x08e4 JLTECH0227 - ok
              20:22:07.0323 0x08e4 [ BC02336F1CBA7DCC7D1213BB588A68A5, 450C5BAD54CCE2AFCDFF1B6E7F8E1A8446D9D3255DF9D36C29 A8F848048AAD93 ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
              20:22:07.0340 0x08e4 kbdclass - ok
              20:22:07.0364 0x08e4 [ 0705EFF5B42A9DB58548EEC3B26BB484, 86C6824ED7ED6FA8F306DB6319A0FD688AA91295AE571262F9 D8E96A32225E99 ] kbdhid C:\windows\system32\drivers\kbdhid.sys
              20:22:07.0398 0x08e4 kbdhid - ok
              20:22:07.0427 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF 8B1207F81B284D ] KeyIso C:\windows\system32\lsass.exe
              20:22:07.0439 0x08e4 KeyIso - ok
              20:22:07.0485 0x08e4 [ 97A7070AEA4C058B6418519E869A63B4, 15345C2D6CA159BD498002974A0BD21CAB611124D85E332024 8B47652AEF23C8 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
              20:22:07.0503 0x08e4 KSecDD - ok
              20:22:07.0518 0x08e4 [ 26C43A7C2862447EC59DEDA188D1DA07, 5363BF87E650FE2010ACA9417D6920FF4ED752256FF4773288 2E9B2BA1ED154B ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
              20:22:07.0539 0x08e4 KSecPkg - ok
              20:22:07.0569 0x08e4 [ 6869281E78CB31A43E969F06B57347C4, 866A23E69B32A78D378D6CB3B3DA3695FFDFF0FEC3C9F68C8C 3F988DF417044B ] ksthunk C:\windows\system32\drivers\ksthunk.sys
              20:22:07.0620 0x08e4 ksthunk - ok
              20:22:07.0670 0x08e4 [ 6AB66E16AA859232F64DEB66887A8C9C, 5F2B579BEA8098A2994B0DECECDAE7B396E7B5DC5F09645737 B9F28BEEA77FFF ] KtmRm C:\windows\system32\msdtckrm.dll
              20:22:07.0710 0x08e4 KtmRm - ok
              20:22:07.0744 0x08e4 [ EBED8B3FF4A823C1A6EEBEED7B29353F, 0942200EEDEDA1FF4E634CDC5182D8EDC9BC9F66E89A5DAB8D F82C3FBB2F0D59 ] L1C C:\windows\system32\DRIVERS\L1C62x64.sys
              20:22:07.0760 0x08e4 L1C - ok
              20:22:07.0807 0x08e4 [ D9F42719019740BAA6D1C6D536CBDAA6, 8757599D0AE5302C4CE50861BEBA3A8DD14D7B0DBD916FD540 4133688CDFCC40 ] LanmanServer C:\windows\system32\srvsvc.dll
              20:22:07.0862 0x08e4 LanmanServer - ok
              20:22:07.0914 0x08e4 [ 851A1382EED3E3A7476DB004F4EE3E1A, B1C67F47DD594D092E6E258F01DF5E7150227CE3131A908A24 4DEE9F8A1FABF9 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
              20:22:07.0964 0x08e4 LanmanWorkstation - ok
              20:22:08.0028 0x08e4 [ 1538831CF8AD2979A04C423779465827, E1729B0CC4CEEE494A0B8817A8E98FF232E3A32FB023566EF0 BC71A090262C0C ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
              20:22:08.0064 0x08e4 lltdio - ok
              20:22:08.0119 0x08e4 [ C1185803384AB3FEED115F79F109427F, 0414FE73532DCAB17E906438A14711E928CECCD5F579255410 C62984DD652700 ] lltdsvc C:\windows\System32\lltdsvc.dll
              20:22:08.0182 0x08e4 lltdsvc - ok
              20:22:08.0204 0x08e4 [ F993A32249B66C9D622EA5592A8B76B8, EE64672A990C6145DC5601E2B8CDBE089272A72732F59AF986 5DCBA8B1717E70 ] lmhosts C:\windows\System32\lmhsvc.dll
              20:22:08.0234 0x08e4 lmhosts - ok
              20:22:08.0345 0x08e4 [ 2ED1786B7542CDA261029F6B526EDF44, C6131B65B045EF5B4F62CF6CF089DF0921BA6A8EFC83BCBA45 D5DDE78E9D78E2 ] LMS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
              20:22:08.0360 0x08e4 LMS - ok
              20:22:08.0396 0x08e4 [ 1A93E54EB0ECE102495A51266DCDB6A6, DB6AA86AA36C3A7988BE96E87B5D3251BE7617C54EE8F894D9 DC2E267FE3255B ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
              20:22:08.0415 0x08e4 LSI_FC - ok
              20:22:08.0445 0x08e4 [ 1047184A9FDC8BDBFF857175875EE810, F2251EDB7736A26D388A0C5CC2FE5FB9C5E109CBB1E3800993 554CB21D81AE4B ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
              20:22:08.0464 0x08e4 LSI_SAS - ok
              20:22:08.0474 0x08e4 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93, 88D5740A4E9CC3FA80FA18035DAB441BDC5A039622D666BFDA A525CC9686BD06 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
              20:22:08.0491 0x08e4 LSI_SAS2 - ok
              20:22:08.0513 0x08e4 [ 0504EACAFF0D3C8AED161C4B0D369D4A, 4D272237C189646F5C80822FD3CBA7C2728E482E2DAAF7A09C 8AEF811C89C54D ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
              20:22:08.0532 0x08e4 LSI_SCSI - ok
              20:22:08.0545 0x08e4 [ 43D0F98E1D56CCDDB0D5254CFF7B356E, 5BA498183B5C4996C694CB0A9A6B66CE6C7A460F6C91BEB9F3 05486FCC3B7B22 ] luafv C:\windows\system32\drivers\luafv.sys
              20:22:08.0601 0x08e4 luafv - ok
              20:22:08.0663 0x08e4 [ A8D28D5B3E2A528D1EF0E338E44F2820, 40D1EFDD253BC0A0D984A5AD8A2721C3E83B15F14D53820471 4E6D5B00D92CEB ] MBAMProtector C:\windows\system32\drivers\mbam.sys
              20:22:08.0678 0x08e4 MBAMProtector - ok
              20:22:08.0758 0x08e4 [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F60 6A16768A11DB0C ] MBAMService C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
              20:22:08.0792 0x08e4 MBAMService - ok
              20:22:08.0833 0x08e4 [ AE757332EA130E94E646621CC695B52A, E688CF34A4206F32B5C7301119D8459C3456FC178FA1DAA621 5CE15F2C824C43 ] MBAMWebAccessControl C:\windows\system32\drivers\mwac.sys
              20:22:08.0849 0x08e4 MBAMWebAccessControl - ok
              20:22:08.0881 0x08e4 [ 0BE09CD858ABF9DF6ED259D57A1A1663, 2FD28889B93C8E801F74C1D0769673A461671E0189D0A22C94 509E3F0EEB7428 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
              20:22:08.0896 0x08e4 Mcx2Svc - ok
              20:22:08.0920 0x08e4 [ A55805F747C6EDB6A9080D7C633BD0F4, 2DA0E83BF3C8ADEF6F551B6CC1C0A3F6149CDBE6EC60413BA1 767C4DE425A728 ] megasas C:\windows\system32\drivers\megasas.sys
              20:22:08.0937 0x08e4 megasas - ok
              20:22:08.0968 0x08e4 [ BAF74CE0072480C3B6B7C13B2A94D6B3, 85CBB4949C090A904464F79713A3418338753D20D7FB811E68 F287FDAC1DD834 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
              20:22:08.0994 0x08e4 MegaSR - ok
              20:22:09.0031 0x08e4 [ A6518DCC42F7A6E999BB3BEA8FD87567, 8A9AE992F93F37E0723761EA271A7E1AA8172702C471041A17 324474FC96B9BC ] MEIx64 C:\windows\system32\DRIVERS\HECIx64.sys
              20:22:09.0047 0x08e4 MEIx64 - ok
              20:22:09.0083 0x08e4 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B17200 2B1561EC7E265A ] MMCSS C:\windows\system32\mmcss.dll
              20:22:09.0144 0x08e4 MMCSS - ok
              20:22:09.0198 0x08e4 [ 800BA92F7010378B09F9ED9270F07137, 94F9AF9E1BE80AE6AC39A2A74EF9FAB115DCAACC011D07DFA8 D6A1DDC8A93342 ] Modem C:\windows\system32\drivers\modem.sys
              20:22:09.0250 0x08e4 Modem - ok
              20:22:09.0277 0x08e4 [ B03D591DC7DA45ECE20B3B467E6AADAA, 701FB0CAD8138C58507BE28845D3E24CE269A040737C298859 44A0D851238732 ] monitor C:\windows\system32\DRIVERS\monitor.sys
              20:22:09.0319 0x08e4 monitor - ok
              20:22:09.0338 0x08e4 [ 7D27EA49F3C1F687D357E77A470AEA99, 7FE7CAF95959F127C6D932C01D539C06D80273C49A09761F6E 8331C05B1A7EE7 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
              20:22:09.0355 0x08e4 mouclass - ok
              20:22:09.0382 0x08e4 [ D3BF052C40B0C4166D9FD86A4288C1E6, 5E65264354CD94E844BF1838CA1B8E49080EFA34605A32CF2F 6A47A2B97FC183 ] mouhid C:\windows\system32\drivers\mouhid.sys
              20:22:09.0420 0x08e4 mouhid - ok
              20:22:09.0473 0x08e4 [ 32E7A3D591D671A6DF2DB515A5CBE0FA, 47CED0B9067AE8BF5EEF60B17ADEE5906BEDCC56E4CB460B7B FBC12BB9A69E63 ] mountmgr C:\windows\system32\drivers\mountmgr.sys
              20:22:09.0491 0x08e4 mountmgr - ok
              20:22:09.0506 0x08e4 [ A44B420D30BD56E145D6A2BC8768EC58, B1E4DCA5A1008FA7A0492DC091FB2B820406AE13FD3D44F124 E89B1037AF09B8 ] mpio C:\windows\system32\drivers\mpio.sys
              20:22:09.0527 0x08e4 mpio - ok
              20:22:09.0547 0x08e4 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F, 5A3FA2F110029CB4CC4384998EDB59203FDD65EC45E01B897F B684F8956EAD20 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
              20:22:09.0585 0x08e4 mpsdrv - ok
              20:22:09.0649 0x08e4 [ 54FFC9C8898113ACE189D4AA7199D2C1, 65F585C87F3F710FD5793FDFA96B740AD8D4317B0C120F4435 CCF777300EA4F2 ] MpsSvc C:\windows\system32\mpssvc.dll
              20:22:09.0701 0x08e4 MpsSvc - ok
              20:22:09.0724 0x08e4 [ DC722758B8261E1ABAFD31A3C0A66380, 88BBE073E2CCD1DAB4656DDC53D5161E8A91D035ADAC1465D0 CEBA86F1BB6D9A ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
              20:22:09.0767 0x08e4 MRxDAV - ok
              20:22:09.0800 0x08e4 [ A5D9106A73DC88564C825D317CAC68AC, 0457B2AEA4E05A91D0E43F317894A614434D8CEBE350207853 87F307E231FBE4 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
              20:22:09.0847 0x08e4 mrxsmb - ok
              20:22:09.0886 0x08e4 [ D711B3C1D5F42C0C2415687BE09FC163, 9B3013AC60BD2D0FF52086658BA5FF486ADE15954A552D7DD5 90580E8BAE3EFF ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
              20:22:09.0914 0x08e4 mrxsmb10 - ok
              20:22:09.0930 0x08e4 [ 9423E9D355C8D303E76B8CFBD8A5C30C, 220B33F120C2DD937FE4D5664F4B581DC0ACF78D62EB56B772 0888F67B9644CC ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
              20:22:09.0953 0x08e4 mrxsmb20 - ok
              20:22:09.0971 0x08e4 [ C25F0BAFA182CBCA2DD3C851C2E75796, 643E158A0948DF331807AEAA391F23960362E46C0A0CF6D22A 99020EAE7B10F8 ] msahci C:\windows\system32\DRIVERS\msahci.sys
              20:22:09.0987 0x08e4 msahci - ok
              20:22:10.0000 0x08e4 [ DB801A638D011B9633829EB6F663C900, B34FD33A215ACCF2905F4B7D061686CDB1CB9C652147AF56AE 14686C1F6E3C74 ] msdsm C:\windows\system32\drivers\msdsm.sys
              20:22:10.0021 0x08e4 msdsm - ok
              20:22:10.0035 0x08e4 [ DE0ECE52236CFA3ED2DBFC03F28253A8, 2FBBEC4CACB5161F68D7C2935852A5888945CA0F107CF8A1C0 1F4528CE407DE3 ] MSDTC C:\windows\System32\msdtc.exe
              20:22:10.0076 0x08e4 MSDTC - ok
              20:22:10.0115 0x08e4 [ AA3FB40E17CE1388FA1BEDAB50EA8F96, 69F93E15536644C8FD679A20190CFE577F4985D3B1B4A4AA25 0A168615AE1E99 ] Msfs C:\windows\system32\drivers\Msfs.sys
              20:22:10.0151 0x08e4 Msfs - ok
              20:22:10.0183 0x08e4 [ F9D215A46A8B9753F61767FA72A20326, 6F76642B45E0A7EF6BCAB8B37D55CCE2EAA310ED07B76D43FC B88987C2174141 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
              20:22:10.0241 0x08e4 mshidkmdf - ok
              20:22:10.0273 0x08e4 [ D916874BBD4F8B07BFB7FA9B3CCAE29D, B229DA150713DEDBC4F05386C9D9DC3BC095A74F44F3081E88 311AB73BC992A1 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
              20:22:10.0288 0x08e4 msisadrv - ok
              20:22:10.0321 0x08e4 [ 808E98FF49B155C522E6400953177B08, F873F5BFF0984C5165DF67E92874D3F6EB8D86F9B5AD17013A 0091CA33A1A3D5 ] MSiSCSI C:\windows\system32\iscsiexe.dll
              20:22:10.0371 0x08e4 MSiSCSI - ok
              20:22:10.0373 0x08e4 msiserver - ok
              20:22:10.0429 0x08e4 [ 49CCF2C4FEA34FFAD8B1B59D49439366, E5752EA57C7BDAD5F53E3BC441A415E909AC602CAE56234684 FB8789A20396C7 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
              20:22:10.0464 0x08e4 MSKSSRV - ok
              20:22:10.0485 0x08e4 [ BDD71ACE35A232104DDD349EE70E1AB3, 27464A66868513BE6A01B75D7FC5B0D6B71842E4E20CE3F76B 15C071A0618BBB ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
              20:22:10.0540 0x08e4 MSPCLOCK - ok
              20:22:10.0566 0x08e4 [ 4ED981241DB27C3383D72092B618A1D0, E12F121E641249DB3491141851B59E1496F4413EDF58E86338 8F1C229838DFCC ] MSPQM C:\windows\system32\drivers\MSPQM.sys
              20:22:10.0626 0x08e4 MSPQM - ok
              20:22:10.0659 0x08e4 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D, 64E3BC613EC4872B1B344CBF71EE15BE195592E3244C1EE099 C6F8B95A40F133 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
              20:22:10.0687 0x08e4 MsRPC - ok
              20:22:10.0711 0x08e4 [ 0EED230E37515A0EAEE3C2E1BC97B288, B1D8F8A75006B6E99214CA36D27A8594EF8D952F315BEB201E 9BAC9DE3E64D42 ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys
              20:22:10.0727 0x08e4 mssmbios - ok
              20:22:10.0749 0x08e4 [ 2E66F9ECB30B4221A318C92AC2250779, DF175E1AB6962303E57F26DAE5C5C1E40B8640333F3E352A64 F6A5F1301586CD ] MSTEE C:\windows\system32\drivers\MSTEE.sys
              20:22:10.0797 0x08e4 MSTEE - ok
              20:22:10.0820 0x08e4 [ 7EA404308934E675BFFDE8EDF0757BCD, 306CD02D89CFCFE576242360ED5F9EEEDCAFC43CD43B7D2977 AE960F9AEC3232 ] MTConfig C:\windows\system32\drivers\MTConfig.sys
              20:22:10.0838 0x08e4 MTConfig - ok
              20:22:10.0850 0x08e4 [ F9A18612FD3526FE473C1BDA678D61C8, 32F7975B5BAA447917F832D9E3499B4B6D3E90D73F478375D0 B70B36C524693A ] Mup C:\windows\system32\Drivers\mup.sys
              20:22:10.0867 0x08e4 Mup - ok
              20:22:10.0896 0x08e4 [ 582AC6D9873E31DFA28A4547270862DD, BD540499F74E8F59A020D935D18E36A3A97C1A6EC59C820843 6469A31B16B260 ] napagent C:\windows\system32\qagentRT.dll
              20:22:10.0939 0x08e4 napagent - ok
              20:22:10.0981 0x08e4 [ 1EA3749C4114DB3E3161156FFFFA6B33, 54C2E77BCE1037711A11313AC25B8706109098C10A31AA03AE B7A185E97800D7 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
              20:22:11.0032 0x08e4 NativeWifiP - ok
              20:22:11.0089 0x08e4 [ 79B47FD40D9A817E932F9D26FAC0A81C, 53E260B8BFC50BA45FA73BFCF4E58C233890D0EAA9DEFDCCBB 55FD3EB992FF2D ] NDIS C:\windows\system32\drivers\ndis.sys
              20:22:11.0137 0x08e4 NDIS - ok
              20:22:11.0164 0x08e4 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC, D7E5446E83909AE25506BB98FBDD878A529C87963E3C1125C4 ABAB25823572BC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
              20:22:11.0200 0x08e4 NdisCap - ok
              20:22:11.0221 0x08e4 [ 30639C932D9FEF22B31268FE25A1B6E5, 32873D95339600F6EEFA51847D12C563FF01F320DC59055B24 2FA2887C99F9D6 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
              20:22:11.0257 0x08e4 NdisTapi - ok
              20:22:11.0281 0x08e4 [ 136185F9FB2CC61E573E676AA5402356, BA3AD0A33416DA913B4242C6BE8C3E5812AD2B20BA6C11DD30 94F2E8EB56E683 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
              20:22:11.0316 0x08e4 Ndisuio - ok
              20:22:11.0336 0x08e4 [ 53F7305169863F0A2BDDC49E116C2E11, 881E9346D3C02405B7850ADC37E720990712EC9C666A0CE96E 252A487FD2CE77 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
              20:22:11.0390 0x08e4 NdisWan - ok
              20:22:11.0410 0x08e4 [ 015C0D8E0E0421B4CFD48CFFE2825879, 4242E2D42CCFC859B2C0275C5331798BC0BDA68E51CF4650B6 E64B1332071023 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
              20:22:11.0445 0x08e4 NDProxy - ok
              20:22:11.0471 0x08e4 [ 86743D9F5D2B1048062B14B1D84501C4, DBF6D6A60AB774FCB0F464FF2D285A7521D0A24006687B243A B46B17D8032062 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
              20:22:11.0527 0x08e4 NetBIOS - ok
              20:22:11.0610 0x08e4 [ 09594D1089C523423B32A4229263F068, 7426A9B8BA27D3225928DDEFBD399650ABB90798212F56B7D1 2158AC22CCCE37 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
              20:22:11.0654 0x08e4 NetBT - ok
              20:22:11.0671 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF 8B1207F81B284D ] Netlogon C:\windows\system32\lsass.exe
              20:22:11.0684 0x08e4 Netlogon - ok
              20:22:11.0725 0x08e4 [ 847D3AE376C0817161A14A82C8922A9E, 37AE692B3481323134125EF58F2C3CBC20177371AF2F5874F5 3DD32A827CB936 ] Netman C:\windows\System32\netman.dll
              20:22:11.0788 0x08e4 Netman - ok
              20:22:11.0817 0x08e4 [ 5F28111C648F1E24F7DBC87CDEB091B8, 2E8645285921EDB98BB2173E11E57459C888D52E80D85791D1 69C869DE8813B9 ] netprofm C:\windows\System32\netprofm.dll
              20:22:11.0860 0x08e4 netprofm - ok
              20:22:11.0892 0x08e4 [ 3E5A36127E201DDF663176B66828FAFE, 5A08BA9EFB1A72DF1DD839BA5FA2B8994012BA62A515588FF6 2333B33B60045B ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
              20:22:11.0903 0x08e4 NetTcpPortSharing - ok
              20:22:11.0947 0x08e4 [ 77889813BE4D166CDAB78DDBA990DA92, 2EF531AE502B943632EEC66A309A8BFCDD36120A5E1473F4AA F3C2393AD0E6A3 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
              20:22:11.0964 0x08e4 nfrd960 - ok
              20:22:11.0994 0x08e4 [ 1EE99A89CC788ADA662441D1E9830529, 6B4FDD74BB81E12BD4B25A3E8AECB0FA77FA0075D454DD1D6D C1790ADF1F2AA8 ] NlaSvc C:\windows\System32\nlasvc.dll
              20:22:12.0052 0x08e4 NlaSvc - ok
              20:22:12.0072 0x08e4 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7, D8957EF7060A69DBB3CD6B2C45B1E4143592AB8D018471E17A C04668157DC67F ] Npfs C:\windows\system32\drivers\Npfs.sys
              20:22:12.0108 0x08e4 Npfs - ok
              20:22:12.0139 0x08e4 [ D54BFDF3E0C953F823B3D0BFE4732528, 497A1DCC5646EC22119273216DF10D5442D16F83E4363770F5 07518CF6EAA53A ] nsi C:\windows\system32\nsisvc.dll
              20:22:12.0183 0x08e4 nsi - ok
              20:22:12.0210 0x08e4 [ E7F5AE18AF4168178A642A9247C63001, 133023B7E4BA8049C4CAED3282BDD25571D1CC25FAC3B820C7 F981D292689D76 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
              20:22:12.0269 0x08e4 nsiproxy - ok
              20:22:12.0337 0x08e4 [ A2F74975097F52A00745F9637451FDD8, C681DDBD3382C477C2A030E828B5CFB529CB57C7847BD9AFF2 5E2A5E58B2DAF3 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
              20:22:12.0409 0x08e4 Ntfs - ok
              20:22:12.0427 0x08e4 [ 9899284589F75FA8724FF3D16AED75C1, 181188599FD5D4DE33B97010D9E0CAEABAB9A3EF50712FE7F9 AA0735CD0666D6 ] Null C:\windows\system32\drivers\Null.sys
              20:22:12.0461 0x08e4 Null - ok
              20:22:12.0483 0x08e4 [ 0A92CB65770442ED0DC44834632F66AD, 581327F07A68DBD5CC749214BE5F1211FC2CE41C7A4F0656B6 80AFB51A35ACE7 ] nvraid C:\windows\system32\drivers\nvraid.sys
              20:22:12.0504 0x08e4 nvraid - ok
              20:22:12.0516 0x08e4 [ DAB0E87525C10052BF65F06152F37E4A, AD9BFF0D5FD3FFB95C758B478E1F6A9FE45E7B37AEC71EB507 0D292FEAAEDF37 ] nvstor C:\windows\system32\drivers\nvstor.sys
              20:22:12.0537 0x08e4 nvstor - ok
              20:22:12.0577 0x08e4 [ 270D7CD42D6E3979F6DD0146650F0E05, 752489E54C9004EDCBE1F1F208FFD864DA5C83E59A2DDE6B3E 0D63ECA996F76F ] nv_agp C:\windows\system32\drivers\nv_agp.sys
              20:22:12.0597 0x08e4 nv_agp - ok
              20:22:12.0629 0x08e4 [ 3589478E4B22CE21B41FA1BFC0B8B8A0, AD2469FC753FE552CB809FF405A9AB23E7561292FE89117E3B 3B62057EFF0203 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
              20:22:12.0650 0x08e4 ohci1394 - ok
              20:22:12.0694 0x08e4 [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A372 1FF007E69595CC ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
              20:22:12.0706 0x08e4 ose - ok
              20:22:12.0914 0x08e4 [ 61BFFB5F57AD12F83AB64B7181829B34, 1DD0DD35E4158F95765EE6639F217DF03A0A19E624E020DBA6 09268C08A13846 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EX E
              20:22:13.0099 0x08e4 osppsvc - ok
              20:22:13.0136 0x08e4 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6 EDEC0A183CFFC3 ] p2pimsvc C:\windows\system32\pnrpsvc.dll
              20:22:13.0173 0x08e4 p2pimsvc - ok
              20:22:13.0202 0x08e4 [ 927463ECB02179F88E4B9A17568C63C3, FEFD3447692C277D59EEC7BF218552C8BB6B8C98C26E973675 549628408B94CE ] p2psvc C:\windows\system32\p2psvc.dll
              20:22:13.0226 0x08e4 p2psvc - ok
              20:22:13.0255 0x08e4 [ 0086431C29C35BE1DBC43F52CC273887, 0D116D49EF9ABB57DA005764F25E692622210627FC2048F06A 989B12FA8D0A80 ] Parport C:\windows\system32\drivers\parport.sys
              20:22:13.0276 0x08e4 Parport - ok
              20:22:13.0299 0x08e4 [ E9766131EEADE40A27DC27D2D68FBA9C, 63C295EC96DBD25F1A8B908295CCB86B54F2A77A02AAA11E5D 9160C2C1A492B6 ] partmgr C:\windows\system32\drivers\partmgr.sys
              20:22:13.0317 0x08e4 partmgr - ok
              20:22:13.0348 0x08e4 [ 3AEAA8B561E63452C655DC0584922257, 04C072969B58657602EB0C21CEDF24FCEE14E61B90A0F758F9 3925EF2C9FC32D ] PcaSvc C:\windows\System32\pcasvc.dll
              20:22:13.0384 0x08e4 PcaSvc - ok
              20:22:13.0414 0x08e4 [ 94575C0571D1462A0F70BDE6BD6EE6B3, 7139BAC653EA94A3DD3821CAB35FC5E22F4CCA5ACC2BAABDAA 27E4C3C8B27FC9 ] pci C:\windows\system32\drivers\pci.sys
              20:22:13.0436 0x08e4 pci - ok
              20:22:13.0452 0x08e4 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA, F2A7CC645B96946CC65BF60E14E70DC09C848D27C7943CE5DE A0C01A6B863480 ] pciide C:\windows\system32\DRIVERS\pciide.sys
              20:22:13.0468 0x08e4 pciide - ok
              20:22:13.0492 0x08e4 [ B2E81D4E87CE48589F98CB8C05B01F2F, 6763BEE7270A4873B3E131BFB92313E2750FCBD0AD73C23D1C 4F98F7DF73DE14 ] pcmcia C:\windows\system32\drivers\pcmcia.sys
              20:22:13.0515 0x08e4 pcmcia - ok
              20:22:13.0532 0x08e4 [ D6B9C2E1A11A3A4B26A182FFEF18F603, BBA5FE08B1DDD6243118E11358FD61B10E850F090F061711C3 CB207CE5FBBD36 ] pcw C:\windows\system32\drivers\pcw.sys
              20:22:13.0549 0x08e4 pcw - ok
              20:22:13.0576 0x08e4 [ 68769C3356B3BE5D1C732C97B9A80D6E, FB2D61145980A2899D1B7729184C54070315B0E63C9A22400A 76CCD39E00029C ] PEAUTH C:\windows\system32\drivers\peauth.sys
              20:22:13.0654 0x08e4 PEAUTH - ok
              20:22:13.0727 0x08e4 [ E495E408C93141E8FC72DC0C6046DDFA, 489B957DADA0DC128A09468F1AD082DCC657E86053208EA06A 12937BE86FB919 ] PerfHost C:\windows\SysWow64\perfhost.exe
              20:22:13.0741 0x08e4 PerfHost - ok
              20:22:13.0777 0x08e4 [ 91111CEBBDE8015E822C46120ED9537C, 255B85FEF663C2E0652CECF3F9B67B12B576F924A34415DEE1 3F0F5137E1E7F7 ] PGEffect C:\windows\system32\DRIVERS\pgeffect.sys
              20:22:13.0792 0x08e4 PGEffect - ok
              20:22:13.0862 0x08e4 [ C7CF6A6E137463219E1259E3F0F0DD6C, 08D7244F52AA17DD669AA6F77C291DAC88E7B2D1887DE42250 9C1F83EC85F3DD ] pla C:\windows\system32\pla.dll
              20:22:13.0952 0x08e4 pla - ok
              20:22:14.0009 0x08e4 [ 25FBDEF06C4D92815B353F6E792C8129, 57D9764AE6BCE33B242C399CDFC10DD405975BD6411CA8C75F BCD06EEB8442A9 ] PlugPlay C:\windows\system32\umpnpmgr.dll
              20:22:14.0051 0x08e4 PlugPlay - ok
              20:22:14.0085 0x08e4 [ 7195581CEC9BB7D12ABE54036ACC2E38, 9C4E5D6EA984148F2663DC529083408B2248DFF6DAAC85D919 5F80A722782315 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
              20:22:14.0099 0x08e4 PNRPAutoReg - ok
              20:22:14.0135 0x08e4 [ 3EAC4455472CC2C97107B5291E0DCAFE, E51F373F2DBEAEE516B42BAE8C1B5BB68D00B881323E842CB6 EDEC0A183CFFC3 ] PNRPsvc C:\windows\system32\pnrpsvc.dll
              20:22:14.0155 0x08e4 PNRPsvc - ok
              20:22:14.0213 0x08e4 [ 4F15D75ADF6156BF56ECED6D4A55C389, 2ADA3EA69A5D7EC2A4D2DD89178DB94EAFDDF95F07B0070D65 4D9F7A5C12A044 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
              20:22:14.0274 0x08e4 PolicyAgent - ok
              20:22:14.0305 0x08e4 [ 6BA9D927DDED70BD1A9CADED45F8B184, 66203CE70A5EDE053929A940F38924C6792239CCCE10DD2C1D 90D5B4D6748B55 ] Power C:\windows\system32\umpo.dll
              20:22:14.0339 0x08e4 Power - ok
              20:22:14.0386 0x08e4 [ F92A2C41117A11A00BE01CA01A7FCDE9, 38ADC6052696D110CA5F393BC586791920663F5DA66934C2A8 24DDA9CD89C763 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
              20:22:14.0440 0x08e4 PptpMiniport - ok
              20:22:14.0462 0x08e4 [ 0D922E23C041EFB1C3FAC2A6F943C9BF, 855418A6A58DCAFB181A1A68613B3E203AFB0A9B3D9D26D0C5 21F9F613B4EAD5 ] Processor C:\windows\system32\drivers\processr.sys
              20:22:14.0482 0x08e4 Processor - ok
              20:22:14.0512 0x08e4 [ 53E83F1F6CF9D62F32801CF66D8352A8, 1225FED810BE8E0729EEAE5B340035CCBB9BACD3EF24783440 0F9B72D05ACE48 ] ProfSvc C:\windows\system32\profsvc.dll
              20:22:14.0553 0x08e4 ProfSvc - ok
              20:22:14.0571 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF 8B1207F81B284D ] ProtectedStorage C:\windows\system32\lsass.exe
              20:22:14.0585 0x08e4 ProtectedStorage - ok
              20:22:14.0610 0x08e4 [ 0557CF5A2556BD58E26384169D72438D, F6F83A616B1F1C6C0DF6D2EC2513E6C23FD4FAA6D36518B867 6C619AB74957B4 ] Psched C:\windows\system32\DRIVERS\pacer.sys
              20:22:14.0680 0x08e4 Psched - ok
              20:22:14.0746 0x08e4 [ C8FCB4899F8B70CC34E0D9876A80963C, E4CFC69C3EE1BC5C0FFF96CE034EAD8DD9727DA165A790CB57 979AA0A6CEE350 ] QIOMem C:\windows\system32\DRIVERS\QIOMem.sys
              20:22:14.0788 0x08e4 QIOMem - ok
              20:22:14.0869 0x08e4 [ A53A15A11EBFD21077463EE2C7AFEEF0, 6002B012A75045DEA62640A864A8721EADE2F8B65BEB5F5BA7 6D8CD819774489 ] ql2300 C:\windows\system32\drivers\ql2300.sys
              20:22:14.0947 0x08e4 ql2300 - ok
              20:22:14.0964 0x08e4 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8, FB6ABAB741CED66A79E31A45111649F2FA3E26CEE77209B529 6F789F6F7D08DE ] ql40xx C:\windows\system32\drivers\ql40xx.sys
              20:22:14.0990 0x08e4 ql40xx - ok
              20:22:15.0028 0x08e4 [ 906191634E99AEA92C4816150BDA3732, A0305436384104C3B559F9C73902DA19B96B518413379E397C 5CDAB0B2B9418F ] QWAVE C:\windows\system32\qwave.dll
              20:22:15.0058 0x08e4 QWAVE - ok
              20:22:15.0071 0x08e4 [ 76707BB36430888D9CE9D705398ADB6C, 35C1D1D05F98AC29A33D3781F497A0B40A3CB9CDF25FE1F28F 574E40DDF70535 ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
              20:22:15.0110 0x08e4 QWAVEdrv - ok
              20:22:15.0137 0x08e4 [ 5A0DA8AD5762FA2D91678A8A01311704, 8A64EB5DBAB7048A9E42A21CEB62CCD5B007A80C199892D7F8 C69B48E8A255EF ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
              20:22:15.0208 0x08e4 RasAcd - ok
              20:22:15.0257 0x08e4 [ 7ECFF9B22276B73F43A99A15A6094E90, 62C70DA127F48F796F8897BBFA23AB6EB080CC923F0F091DFA 384A93F5C90CA1 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
              20:22:15.0294 0x08e4 RasAgileVpn - ok
              20:22:15.0328 0x08e4 [ 8F26510C5383B8DBE976DE1CD00FC8C7, 60E618C010E8A723960636415573FA17EA0BBEF79647196B3B C0B8DEE680E090 ] RasAuto C:\windows\System32\rasauto.dll
              20:22:15.0376 0x08e4 RasAuto - ok
              20:22:15.0397 0x08e4 [ 471815800AE33E6F1C32FB1B97C490CA, 27307265F743DE3A3A3EC1B2C472A3D85FDD0AEC458E0B1177 593141EE072698 ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
              20:22:15.0458 0x08e4 Rasl2tp - ok
              20:22:15.0490 0x08e4 [ EE867A0870FC9E4972BA9EAAD35651E2, 1B848D81705081FD2E18AC762DA7F51455657DAF860BF363DC 15925A148BCADA ] RasMan C:\windows\System32\rasmans.dll
              20:22:15.0529 0x08e4 RasMan - ok
              20:22:15.0543 0x08e4 [ 855C9B1CD4756C5E9A2AA58A15F58C25, A514F8A9C304D54BDA8DC60F5A64259B057EC83A1CAAF6D2B5 8CFD55E9561F72 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
              20:22:15.0603 0x08e4 RasPppoe - ok
              20:22:15.0644 0x08e4 [ E8B1E447B008D07FF47D016C2B0EEECB, FEC789F82B912F3E14E49524D40FEAA4373B221156F14045E6 45D7C37859258C ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
              20:22:15.0696 0x08e4 RasSstp - ok
              20:22:15.0732 0x08e4 [ 77F665941019A1594D887A74F301FA2F, 1FDC6F6853400190C086042933F157814D915C54F26793CAD3 6CD2607D8810DA ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
              20:22:15.0777 0x08e4 rdbss - ok
              20:22:15.0794 0x08e4 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D, 1DF3501BBFFB56C3ECC39DBCC4287D3302216C2208CE22428B 8C4967E5DE9D17 ] rdpbus C:\windows\system32\drivers\rdpbus.sys
              20:22:15.0846 0x08e4 rdpbus - ok
              20:22:15.0892 0x08e4 [ CEA6CC257FC9B7715F1C2B4849286D24, A78144D18352EA802C39D9D42921CF97A3E0211766B2169B67 55C6FC2D77A804 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
              20:22:15.0927 0x08e4 RDPCDD - ok
              20:22:15.0936 0x08e4 [ BB5971A4F00659529A5C44831AF22365, 9AAA5C0D448E821FD85589505D99DF7749715A046BBD211F13 9E4E652ADDE41F ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
              20:22:15.0990 0x08e4 RDPENCDD - ok
              20:22:16.0014 0x08e4 [ 216F3FA57533D98E1F74DED70113177A, 60C126A1409D1E9C39F1C9E95F70115BF4AF07780AB499F6E1 0A612540F173F4 ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
              20:22:16.0051 0x08e4 RDPREFMP - ok
              20:22:16.0072 0x08e4 [ E61608AA35E98999AF9AAEEEA6114B0A, F754CDE89DC96786D2A3C4D19EE2AEF1008E634E4DE3C0CBF9 27436DE90C04A6 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
              20:22:16.0097 0x08e4 RDPWD - ok
              20:22:16.0133 0x08e4 [ 34ED295FA0121C241BFEF24764FC4520, AAEE5F00CAA763A5BA51CF56BD7262C03409CD72BD5601490E 3EC3FFF929BB5F ] rdyboost C:\windows\system32\drivers\rdyboost.sys
              20:22:16.0156 0x08e4 rdyboost - ok
              20:22:16.0186 0x08e4 [ 254FB7A22D74E5511C73A3F6D802F192, 3D0FB5840364200DE394F8CC28DA0E334C2B5FA8FF28A41656 EE72287F3D3836 ] RemoteAccess C:\windows\System32\mprdim.dll
              20:22:16.0218 0x08e4 RemoteAccess - ok
              20:22:16.0255 0x08e4 [ E4D94F24081440B5FC5AA556C7C62702, 147CAA03568DC480F9506E30B84891AB7E433B5EBC05F34FF1 0F72B00E1C6B22 ] RemoteRegistry C:\windows\system32\regsvc.dll
              20:22:16.0289 0x08e4 RemoteRegistry - ok
              20:22:16.0307 0x08e4 [ E4DC58CF7B3EA515AE917FF0D402A7BB, 665B5CD9FE905B0EE3F59A7B1A94760F5393EBEE729877D858 4349754C2867E8 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
              20:22:16.0358 0x08e4 RpcEptMapper - ok
              20:22:16.0385 0x08e4 [ D5BA242D4CF8E384DB90E6A8ED850B8C, CB4CB2608B5E31B55FB1A2CF4051E6D08A0C2A5FB231B2116F 95938D7577334E ] RpcLocator C:\windows\system32\locator.exe
              20:22:16.0398 0x08e4 RpcLocator - ok
              20:22:16.0430 0x08e4 [ 5C627D1B1138676C0A7AB2C2C190D123, C5003F2C912C5CA990E634818D3B4FD72F871900AF2948BD6C 4D6400B354B401 ] RpcSs C:\windows\system32\rpcss.dll
              20:22:16.0470 0x08e4 RpcSs - ok
              20:22:16.0488 0x08e4 [ DDC86E4F8E7456261E637E3552E804FF, D250C69CCC75F2D88E7E624FCC51300E75637333317D53908C CA7E0F117173DD ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
              20:22:16.0548 0x08e4 rspndr - ok
              20:22:16.0604 0x08e4 [ 135A64530D7699AD48F29D73A658DD11, 35838AE8ACFD9047C68DD0C8910557A82998E5CD778D5B98D4 767AFA4BCE85BB ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys
              20:22:16.0628 0x08e4 RSUSBSTOR - ok
              20:22:16.0646 0x08e4 [ E5DC911D0FEB72CAFF2BBDD6E7C3672F, E50825E0413049898A81DDF2AFE24BC92E48A0E9AA7653776F 0F6EEE7D82E5D6 ] RSUSBVSTOR C:\windows\system32\Drivers\RTSUVSTOR.sys
              20:22:16.0671 0x08e4 RSUSBVSTOR - ok
              20:22:16.0736 0x08e4 [ 64FDF4FE366CA42DA2B7D9D424B6E39B, FC3844152E29B703373788F24862CDD307837AA53D21F978FB 9C038A34593B95 ] RTL8192Ce C:\windows\system32\DRIVERS\rtl8192Ce.sys
              20:22:16.0781 0x08e4 RTL8192Ce - ok
              20:22:16.0794 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF 8B1207F81B284D ] SamSs C:\windows\system32\lsass.exe
              20:22:16.0808 0x08e4 SamSs - ok
              20:22:16.0841 0x08e4 [ AC03AF3329579FFFB455AA2DAABBE22B, 7AD3B62ADFEC166F9E256F9FF8BAA0568B2ED7308142BF8F52 69E6EAA5E0A656 ] sbp2port C:\windows\system32\drivers\sbp2port.sys
              20:22:16.0860 0x08e4 sbp2port - ok
              20:22:16.0908 0x08e4 [ 9B7395789E3791A3B6D000FE6F8B131E, E5F067F3F212BF5481668BE1779CBEF053F511F8967589BE2E 865ACB9A620024 ] SCardSvr C:\windows\System32\SCardSvr.dll
              20:22:16.0943 0x08e4 SCardSvr - ok
              20:22:16.0961 0x08e4 [ 253F38D0D7074C02FF8DEB9836C97D2B, CB5CAFCB8628BB22877F74ACF1DED0BBAED8F4573A74DA7FE9 4BBBA584889116 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
              20:22:17.0014 0x08e4 scfilter - ok
              20:22:17.0067 0x08e4 [ 262F6592C3299C005FD6BEC90FC4463A, 54095E37F0B6CC677A3E9BDD40F4647C713273D197DB341063 AA7F342A60C4A7 ] Schedule C:\windows\system32\schedsvc.dll
              20:22:17.0147 0x08e4 Schedule - ok
              20:22:17.0182 0x08e4 [ F17D1D393BBC69C5322FBFAFACA28C7F, 62A1A92B3C52ADFD0B808D7F69DD50238B5F202421F1786F7E AEAA63F274B3E8 ] SCPolicySvc C:\windows\System32\certprop.dll
              20:22:17.0211 0x08e4 SCPolicySvc - ok
              20:22:17.0238 0x08e4 [ 6EA4234DC55346E0709560FE7C2C1972, 64011E044C16E2F92689E5F7E4666A075E27BBFA61F3264E5D 51CE1656C1D5B8 ] SDRSVC C:\windows\System32\SDRSVC.dll
              20:22:17.0269 0x08e4 SDRSVC - ok
              20:22:17.0320 0x08e4 [ 3EA8A16169C26AFBEB544E0E48421186, 34BBB0459C96B3DE94CCB0D73461562935C583D7BF93828DA4 E20A6BC9B7301D ] secdrv C:\windows\system32\drivers\secdrv.sys
              20:22:17.0369 0x08e4 secdrv - ok
              20:22:17.0395 0x08e4 [ BC617A4E1B4FA8DF523A061739A0BD87, 10C4057F6B321EB5237FF619747B74F5401BC17D15A8C70608 29E8204A2297F9 ] seclogon C:\windows\system32\seclogon.dll
              20:22:17.0426 0x08e4 seclogon - ok
              20:22:17.0448 0x08e4 [ C32AB8FA018EF34C0F113BD501436D21, E0EB8E80B51E45CA7EB061E705DA0BC07878759418A8519AE6 E12326FE79E7C7 ] SENS C:\windows\System32\sens.dll
              20:22:17.0497 0x08e4 SENS - ok
              20:22:17.0536 0x08e4 [ 0336CFFAFAAB87A11541F1CF1594B2B2, 8B8A6A33E78A12FB05E29B2E2775850626574AFD2EF88748D6 5E690A07B10B8D ] SensrSvc C:\windows\system32\sensrsvc.dll
              20:22:17.0550 0x08e4 SensrSvc - ok
              20:22:17.0596 0x08e4 [ CB624C0035412AF0DEBEC78C41F5CA1B, A4D937F11E06CAE914347CA1362F4C98EC5EE0C0C80321E360 EA1ABD6726F8D4 ] Serenum C:\windows\system32\drivers\serenum.sys
              20:22:17.0638 0x08e4 Serenum - ok
              20:22:17.0684 0x08e4 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6, 8F9776FB84C5D11068EAF1FF1D1A46466C655D64D256A8B1E3 1DC0C23B5DD22D ] Serial C:\windows\system32\drivers\serial.sys
              20:22:17.0723 0x08e4 Serial - ok
              20:22:17.0772 0x08e4 [ 1C545A7D0691CC4A027396535691C3E3, 065C30BE598FF4DC55C37E0BBE0CEDF10A370AE2BF5404B42E BBB867A3FFED6D ] sermouse C:\windows\system32\drivers\sermouse.sys
              20:22:17.0810 0x08e4 sermouse - ok
              20:22:17.0874 0x08e4 [ 0B6231BF38174A1628C4AC812CC75804, E569BF1F7F5689E2E917FA6516DB53388A5B8B1C6699DEE030 147E853218811D ] SessionEnv C:\windows\system32\sessenv.dll
              20:22:17.0922 0x08e4 SessionEnv - ok
              20:22:17.0940 0x08e4 [ A554811BCD09279536440C964AE35BBF, DA8F893722F803E189D7D4D6C6232ED34505B63A64ED3A0132 A5BB7A2BABDE55 ] sffdisk C:\windows\system32\drivers\sffdisk.sys
              20:22:17.0960 0x08e4 sffdisk - ok
              20:22:17.0975 0x08e4 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF, B81EF5D26AEB572CAB590F7AD7CA8C89F296420089EF5E6148 E972F2DBCA1042 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
              20:22:18.0018 0x08e4 sffp_mmc - ok
              20:22:18.0042 0x08e4 [ DD85B78243A19B59F0637DCF284DA63C, 6730D4F2BAE7E24615746ACC41B42D01DB6068D6504982008A DA1890DE900197 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
              20:22:18.0086 0x08e4 sffp_sd - ok
              20:22:18.0108 0x08e4 [ A9D601643A1647211A1EE2EC4E433FF4, 7AC60B4AB48D4BBF1F9681C12EC2A75C72E6E12D30FABC564A 24394310E9A5F9 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
              20:22:18.0152 0x08e4 sfloppy - ok
              20:22:18.0216 0x08e4 [ C6CC9297BD53E5229653303E556AA539, 921E21EDED244FEE15B56564B97C97785F45AB862C1012BFA0 B96B121DC90076 ] Sftfs C:\windows\system32\DRIVERS\Sftfslh.sys
              20:22:18.0253 0x08e4 Sftfs - ok
              20:22:18.0323 0x08e4 [ 13693B6354DD6E72DC5131DA7D764B90, 447EFDA7CFB1F62EA316219D996406C8DC374097DB903F362D 6E945227D8BB2D ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
              20:22:18.0343 0x08e4 sftlist - ok
              20:22:18.0447 0x08e4 [ 390AA7BC52CEE43F6790CDEA1E776703, 0D008289E4B14EF56D5233B7C8C789A36503FBAA8896660776 557D6F08808FA7 ] Sftplay C:\windows\system32\DRIVERS\Sftplaylh.sys
              20:22:18.0469 0x08e4 Sftplay - ok
              20:22:18.0483 0x08e4 [ 617E29A0B0A2807466560D4C4E338D3E, 5E95D38DB9A6776EB4A15A952FA7949831D6F660EED8C3E79B D09D102BAC5D67 ] Sftredir C:\windows\system32\DRIVERS\Sftredirlh.sys
              20:22:18.0498 0x08e4 Sftredir - ok
              20:22:18.0521 0x08e4 [ 8F571F016FA1976F445147E9E6C8AE9B, 527AB960F2E08F598D1B953BDA4EA749831DD3C765DA278044 B8AB22365F02B5 ] Sftvol C:\windows\system32\DRIVERS\Sftvollh.sys
              20:22:18.0536 0x08e4 Sftvol - ok
              20:22:18.0563 0x08e4 [ C3CDDD18F43D44AB713CF8C4916F7696, 38093295825AFDD08D7E32CC4EF2A6C447F6D6E3C6F7EA5554 C25E7C3F16FC92 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
              20:22:18.0576 0x08e4 sftvsa - ok
              20:22:18.0615 0x08e4 [ B95F6501A2F8B2E78C697FEC401970CE, 758B73A32902299A313348CE7EC189B20EB4CB398D0180E4EE 24B84DAD55F291 ] SharedAccess C:\windows\System32\ipnathlp.dll
              20:22:18.0654 0x08e4 SharedAccess - ok
              20:22:18.0686 0x08e4 [ AAF932B4011D14052955D4B212A4DA8D, 2A3BFD0FA9569288E91AE3E72CA1EC39E1450D01E6473CE511 57E0F138257923 ] ShellHWDetection C:\windows\System32\shsvcs.dll
              20:22:18.0747 0x08e4 ShellHWDetection - ok
              20:22:18.0776 0x08e4 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1, 89CA9F516E42A6B905474D738CDA2C121020A07DBD4E66CFE5 69DD77D79D7820 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
              20:22:18.0795 0x08e4 SiSRaid2 - ok
              20:22:18.0815 0x08e4 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4, 87B85C66DF7EB6FDB8A2341D05FAA5261FF68A90CCFC63F0E4 A03824F1E33E5E ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
              20:22:18.0835 0x08e4 SiSRaid4 - ok
              20:22:18.0873 0x08e4 [ 548260A7B8654E024DC30BF8A7C5BAA4, 4A7E58331D7765A12F53DC2371739DC9A463940B13E16157CE 10DB80E958D740 ] Smb C:\windows\system32\DRIVERS\smb.sys
              20:22:18.0912 0x08e4 Smb - ok
              20:22:18.0949 0x08e4 [ 6313F223E817CC09AA41811DAA7F541D, D787061043BEEDB9386B048CB9E680E6A88A1CBAE9BD4A8C02 09155BFB76C630 ] SNMPTRAP C:\windows\System32\snmptrap.exe
              20:22:18.0964 0x08e4 SNMPTRAP - ok
              20:22:18.0972 0x08e4 [ B9E31E5CACDFE584F34F730A677803F9, 21A5130BD00089C609522A372018A719F8E37103D2DD22C59E ACB393BE35A063 ] spldr C:\windows\system32\drivers\spldr.sys
              20:22:18.0989 0x08e4 spldr - ok
              20:22:19.0022 0x08e4 [ B96C17B5DC1424D56EEA3A99E97428CD, AF0A85066A7983878DC1C663811CE61C6CA1912DC956184F87 8B7B82DB93C651 ] Spooler C:\windows\System32\spoolsv.exe
              20:22:19.0066 0x08e4 Spooler - ok
              20:22:19.0182 0x08e4 [ E17E0188BB90FAE42D83E98707EFA59C, FC075F7B39E86CC8EF6DA4E339FE946917E319C347AC70FB0C 50AAF36F97E27F ] sppsvc C:\windows\system32\sppsvc.exe
              20:22:19.0298 0x08e4 sppsvc - ok
              20:22:19.0327 0x08e4 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45, 36D48B23B8243BE5229707375FCD11C2DCAC96983199345365 F065A0CBF33314 ] sppuinotify C:\windows\system32\sppuinotify.dll
              20:22:19.0359 0x08e4 sppuinotify - ok
              20:22:19.0394 0x08e4 [ 441FBA48BFF01FDB9D5969EBC1838F0B, 306128F1AD489F87161A089D1BDC1542A4CB742D91A0C12A7C D1863FDB8932C0 ] srv C:\windows\system32\DRIVERS\srv.sys
              20:22:19.0445 0x08e4 srv - ok
              20:22:19.0483 0x08e4 [ B4ADEBBF5E3677CCE9651E0F01F7CC28, 726DB2283113AB2A9681E8E9F61132303D6D86E9CD034C40EE 4A8C9DB29E87F7 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
              20:22:19.0536 0x08e4 srv2 - ok
              20:22:19.0586 0x08e4 [ 0C4540311E11664B245A263E1154CEF8, 63376322BFFAFF2F166AF3FDD3F1A346C21FAE21F406F659F8 630779D1D6525D ] SrvHsfHDA C:\windows\system32\DRIVERS\VSTAZL6.SYS
              20:22:19.0616 0x08e4 SrvHsfHDA - ok
              20:22:19.0670 0x08e4 [ 02071D207A9858FBE3A48CBFD59C4A04, FEA4DEBAEC3465E0C7C1E8B721805922F6BBCB96A60A193B11 688F4252F4B89E ] SrvHsfV92 C:\windows\system32\DRIVERS\VSTDPV6.SYS
              20:22:19.0765 0x08e4 SrvHsfV92 - ok
              20:22:19.0817 0x08e4 [ 18E40C245DBFAF36FD0134A7EF2DF396, 0138A68958112101A5D3BD94114F320CE80B0C9A93E009AC78 DE7415FCCC7DE7 ] SrvHsfWinac C:\windows\system32\DRIVERS\VSTCNXT6.SYS
              20:22:19.0862 0x08e4 SrvHsfWinac - ok
              20:22:19.0881 0x08e4 [ 27E461F0BE5BFF5FC737328F749538C3, AFA4704ED8FFC1A0BAB40DFB81D3AE3F3D933A3C9BF54DDAF3 9FF9AF3646D9E6 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
              20:22:19.0904 0x08e4 srvnet - ok
              20:22:19.0941 0x08e4 [ 51B52FBD583CDE8AA9BA62B8B4298F33, 2E2403F8AA39E79D1281CA006B51B43139C32A5FDD64BD34DA A4B935338BD740 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
              20:22:19.0998 0x08e4 SSDPSRV - ok
              20:22:20.0019 0x08e4 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB, D21CDBC4C2AA0DB5B4455D5108B0CAF4282A2E664B9035708F 212CC094569D9D ] SstpSvc C:\windows\system32\sstpsvc.dll
              20:22:20.0052 0x08e4 SstpSvc - ok
              20:22:20.0078 0x08e4 [ F3817967ED533D08327DC73BC4D5542A, 1B204454408A690C0A86447F3E4AA9E7C58A9CFB567C94C17C 21920BA648B4D5 ] stexstor C:\windows\system32\drivers\stexstor.sys
              20:22:20.0096 0x08e4 stexstor - ok
              20:22:20.0159 0x08e4 [ 8DD52E8E6128F4B2DA92CE27402871C1, 1101C38BE8FC383B5F2F9FA402F9652B23B88A764DE2B584DF E62B88B11DEF92 ] stisvc C:\windows\System32\wiaservc.dll
              20:22:20.0192 0x08e4 stisvc - ok
              20:22:20.0210 0x08e4 [ D01EC09B6711A5F8E7E6564A4D0FBC90, 3CB922291DBADC92B46B9E28CCB6810CD8CCDA3E74518EC952 2B58B998E1F969 ] swenum C:\windows\system32\DRIVERS\swenum.sys
              20:22:20.0227 0x08e4 swenum - ok
              20:22:20.0272 0x08e4 [ E08E46FDD841B7184194011CA1955A0B, 9C3725BB1F08F92744C980A22ED5C874007D3B5863C7E1F140 F50061052AC418 ] swprv C:\windows\System32\swprv.dll
              20:22:20.0318 0x08e4 swprv - ok
              20:22:20.0424 0x08e4 [ F5B46DF59FEAA48A442AED7EEB754D4B, 8415FDD5E7B4D4819BB9B0937CDF254548C871045787958BCF 708096204B1714 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
              20:22:20.0461 0x08e4 SynTP - ok
              20:22:20.0571 0x08e4 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D, 3C13217548BE61F2BDB8BD41F77345CDDA1F97BF0AE17241C3 35B9807EB3DBB8 ] SysMain C:\windows\system32\sysmain.dll
              20:22:20.0659 0x08e4 SysMain - ok
              20:22:20.0689 0x08e4 [ E3C61FD7B7C2557E1F1B0B4CEC713585, 01F0E116606D185BF93B540868075BFB1A398197F6AABD9949 83DBFF56B3A8A0 ] TabletInputService C:\windows\System32\TabSvc.dll
              20:22:20.0709 0x08e4 TabletInputService - ok
              20:22:20.0737 0x08e4 [ 40F0849F65D13EE87B9A9AE3C1DD6823, E251A7EF3D0FD2973AF33A62FC457A7E8D5E8694208F811F52 455F7C2426121F ] TapiSrv C:\windows\System32\tapisrv.dll
              20:22:20.0775 0x08e4 TapiSrv - ok
              20:22:20.0801 0x08e4 [ 1BE03AC720F4D302EA01D40F588162F6, AB644862BF1D2E824FD846180DEC4E2C0FAFCC517451486DE5 A92E5E78A952E4 ] TBS C:\windows\System32\tbssvc.dll
              20:22:20.0833 0x08e4 TBS - ok
              20:22:20.0930 0x08e4 [ ACB82BDA8F46C84F465C1AFA517DC4B9, DE785AC33A0D63699E5E3E85E4C33694A15FBC9B93D432E886 5C88E44CDF3E17 ] Tcpip C:\windows\system32\drivers\tcpip.sys
              20:22:21.0011 0x08e4 Tcpip - ok
              20:22:21.0069 0x08e4 [ ACB82BDA8F46C84F465C1AFA517DC4B9, DE785AC33A0D63699E5E3E85E4C33694A15FBC9B93D432E886 5C88E44CDF3E17 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
              20:22:21.0141 0x08e4 TCPIP6 - ok
              20:22:21.0176 0x08e4 [ DF687E3D8836BFB04FCC0615BF15A519, 7C5B1E72673B4299DFC21E869F0FBB28198CA54DF4F4AF7080 005F2D82467784 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
              20:22:21.0227 0x08e4 tcpipreg - ok
              20:22:21.0262 0x08e4 [ FD542B661BD22FA69CA789AD0AC58C29, 75FFAF1834B1E22DF37608ED451F161052FF1FE3C681B4E20A 68DCA92CC7FD8C ] tdcmdpst C:\windows\system32\DRIVERS\tdcmdpst.sys
              20:22:21.0276 0x08e4 tdcmdpst - ok
              20:22:21.0292 0x08e4 [ 3371D21011695B16333A3934340C4E7C, 7416F9BBFC1BA9D875EA7D1C7A0D912FC6977B49A865D67E3F 9C4E18A965082D ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
              20:22:21.0311 0x08e4 TDPIPE - ok
              20:22:21.0347 0x08e4 [ 51C5ECEB1CDEE2468A1748BE550CFBC8, 4E8F83877330B421F7B5D8393D34BC44C6450E69209DAA95B2 9CB298166A5DF9 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
              20:22:21.0364 0x08e4 TDTCP - ok
              20:22:21.0391 0x08e4 [ DDAD5A7AB24D8B65F8D724F5C20FD806, B71F2967A4EE7395E4416C1526CB85368AEA988BDD1F2C9719 C48B08FAFA9661 ] tdx C:\windows\system32\DRIVERS\tdx.sys
              20:22:21.0429 0x08e4 tdx - ok
              20:22:21.0453 0x08e4 [ 561E7E1F06895D78DE991E01DD0FB6E5, 83BFA50A528762EC52A011302AC3874636FB7E26628CD7ACFB F2BDC9FAA8110D ] TermDD C:\windows\system32\DRIVERS\termdd.sys
              20:22:21.0470 0x08e4 TermDD - ok
              20:22:21.0516 0x08e4 [ 2E648163254233755035B46DD7B89123, 6FA0D07CE18A3A69D82EE49D875F141E39406E92C34EAC76AC 4EB052E6EBCBCD ] TermService C:\windows\System32\termsrv.dll
              20:22:21.0578 0x08e4 TermService - ok
              20:22:21.0604 0x08e4 [ F0344071948D1A1FA732231785A0664C, DB9886C2C858FAF45AEA15F8E42860343F73EB8685C53EC2E8 CCC10586CB0832 ] Themes C:\windows\system32\themeservice.dll
              20:22:21.0622 0x08e4 Themes - ok
              20:22:21.0639 0x08e4 [ E40E80D0304A73E8D269F7141D77250B, 0DB4AC13A264F19A84DC0BCED54E8E404014CC09C993B17200 2B1561EC7E265A ] THREADORDER C:\windows\system32\mmcss.dll
              20:22:21.0670 0x08e4 THREADORDER - ok
              20:22:21.0745 0x08e4 [ 71C321649B28638EE80A2EEB164C1DC8, D75D296B506DCC38A4DED82C71141388AEB60B065785DCC5BC 2F4B3B77ACEDC7 ] TMachInfo C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
              20:22:21.0755 0x08e4 TMachInfo - ok
              20:22:21.0776 0x08e4 [ 8E2C799D3476EAC32C3BA0DF7CE6AF19, CFE8A69E3F2A42C3BA2B38EC9233076D0AD32C441500E64072 19F2E866905D9B ] TODDSrv C:\Windows\system32\TODDSrv.exe
              20:22:21.0788 0x08e4 TODDSrv - ok
              20:22:21.0899 0x08e4 [ 1C73689B900428C7D054A41C4687F55C, 6DD3CDC09E4A62F40A81872789A5C8678C0FE23DD911C2951D FF5494B6BFC012 ] TosCoSrv C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
              20:22:21.0921 0x08e4 TosCoSrv - ok
              20:22:21.0984 0x08e4 [ 63AAFCF3EA5DBB17123E0BAE9AFE4D58, ACAD9D96CE58EDB620AC13ACA8C6F4122BA8B2AF78468A760F 21A01B43D93312 ] TOSHIBA eco Utility Service C:\Program Files\TOSHIBA\TECO\TecoService.exe
              20:22:21.0997 0x08e4 TOSHIBA eco Utility Service - ok
              20:22:22.0047 0x08e4 [ 29D0886CF250FCEF1BF9E65AB8D2C0C8, 8D852DB100AC68A07A6E2AD21198410EAAB36E83BB8BAEA71C B698680B5DCE71 ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
              20:22:22.0057 0x08e4 TOSHIBA HDD SSD Alert Service - ok
              20:22:22.0097 0x08e4 [ 09FF7B0B1B5C3D225495CB6F5A9B39F8, 0D2CC72B7E02B92C9A1D6B76300B75A39427046903326642B9 D511A51A795027 ] tos_sps64 C:\windows\system32\DRIVERS\tos_sps64.sys
              20:22:22.0127 0x08e4 tos_sps64 - ok
              20:22:22.0206 0x08e4 [ 098B8A408C17E125A3D9A8E1166780C8, F25F09F62713C8234CB2B6A40A4455502C8004090BFB9EE946 5546AD48369956 ] TPCHSrv C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
              20:22:22.0230 0x08e4 TPCHSrv - ok
              20:22:22.0262 0x08e4 [ 7E7AFD841694F6AC397E99D75CEAD49D, DE87F203FD8E6BDCCFCA1860A85F283301A365846FB703D9BB 86278D8AC96B07 ] TrkWks C:\windows\System32\trkwks.dll
              20:22:22.0316 0x08e4 TrkWks - ok
              20:22:22.0381 0x08e4 [ 0D5A09B08568760AE85A801FCBC0F83D, 347ACBA74FDCBEAC671521739F8A34EC0E378CAF716C31F556 16F9F843E4D0D3 ] TrueSight C:\Windows\System32\drivers\TrueSight.sys
              20:22:22.0397 0x08e4 TrueSight - ok
              20:22:22.0448 0x08e4 [ 773212B2AAA24C1E31F10246B15B276C, F2EF85F5ABA307976D9C649D710B408952089458DDE97D4DEF 321DF14E46A046 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
              20:22:22.0505 0x08e4 TrustedInstaller - ok
              20:22:22.0519 0x08e4 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30, CA302C2ED6A6BF4670BAAA4F5C14C0238CF0C80316856AA0DB 053F4D593033AC ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
              20:22:22.0554 0x08e4 tssecsrv - ok
              20:22:22.0593 0x08e4 [ D11C783E3EF9A3C52C0EBE83CC5000E9, A136C355D4C8945729163D15801364A614E23217B15F9313C8 5BA45BB71A74EB ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
              20:22:22.0612 0x08e4 TsUsbFlt - ok
              20:22:22.0628 0x08e4 [ 9CC2CCAE8A84820EAECB886D477CBCB8, 50D8AA2D7477A6618A0C31BB4D1C4887B457865FB1105E2E7B 984EEFA337B804 ] TsUsbGD C:\windows\system32\drivers\TsUsbGD.sys
              20:22:22.0665 0x08e4 TsUsbGD - ok
              20:22:22.0702 0x08e4 [ 3566A8DAAFA27AF944F5D705EAA64894, AE9D8B648DA08AF667B9456C3FE315489859C157510A258559 F18238F2CC92B8 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
              20:22:22.0741 0x08e4 tunnel - ok
              20:22:22.0770 0x08e4 [ 550B567F9364D8F7684C3FB3EA665A72, A214BBBBAB9F0DD525FA5A818CEB8E9294B4A96676317255D7 ACF6049049C933 ] TVALZ C:\windows\system32\DRIVERS\TVALZ_O.SYS
              20:22:22.0784 0x08e4 TVALZ - ok
              20:22:22.0795 0x08e4 [ 9C7191F4B2E49BFF47A6C1144B5923FA, DF4E663499946F4E68B7528CA399574D1EB69797FF81F68194 3B84F3E5E6A40E ] TVALZFL C:\windows\system32\DRIVERS\TVALZFL.sys
              20:22:22.0809 0x08e4 TVALZFL - ok
              20:22:22.0830 0x08e4 [ B4DD609BD7E282BFC683CEC7EAAAAD67, EF131DB6F6411CAD36A989A421AF93F89DD61601AC524D2FF1 1C10FF6E3E9123 ] uagp35 C:\windows\system32\drivers\uagp35.sys
              20:22:22.0848 0x08e4 uagp35 - ok
              20:22:22.0884 0x08e4 [ FF4232A1A64012BAA1FD97C7B67DF593, D8591B4EB056899C7B604E4DD852D82D4D9809F508ABCED4A0 3E1BE6D5D456E3 ] udfs C:\windows\system32\DRIVERS\udfs.sys
              20:22:22.0952 0x08e4 udfs - ok
              20:22:22.0996 0x08e4 [ 3CBDEC8D06B9968ABA702EBA076364A1, B8DAB8AA804FC23021BFEBD7AE4D40FBE648D6C6BA21CC008E 26D1C084972F9B ] UI0Detect C:\windows\system32\UI0Detect.exe
              20:22:23.0041 0x08e4 UI0Detect - ok
              20:22:23.0078 0x08e4 [ 4BFE1BC28391222894CBF1E7D0E42320, 5918B1ED2030600DF77BDACF1C808DF6EADDD8BF3E7003AF1D 72050D8B102B3A ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
              20:22:23.0097 0x08e4 uliagpkx - ok
              20:22:23.0127 0x08e4 [ DC54A574663A895C8763AF0FA1FF7561, 09A3F3597E91CBEB2F38E96E75134312B60CAE5574B2AD4606 C2D3E992AEDDFE ] umbus C:\windows\system32\DRIVERS\umbus.sys
              20:22:23.0165 0x08e4 umbus - ok
              20:22:23.0198 0x08e4 [ B2E8E8CB557B156DA5493BBDDCC1474D, F547509A08C0679ACB843E20C9C0CF51BED1B06530BBC529DF B0944504564A43 ] UmPass C:\windows\system32\drivers\umpass.sys
              20:22:23.0217 0x08e4 UmPass - ok
              20:22:23.0390 0x08e4 [ 7E5E1603D0FF2D240AE70295C5C3FEFC, 1E5F8E415ACE3C6DFBE636473DBE051329174F2A085516B6FC 1515A54014D02B ] UNS C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
              20:22:23.0458 0x08e4 UNS - ok
              20:22:23.0495 0x08e4 [ D47EC6A8E81633DD18D2436B19BAF6DE, 0FB461E2D5E0B75BB5958F6362F4880BFA4C36AD930542609B CAF574941AA7AE ] upnphost C:\windows\System32\upnphost.dll
              20:22:23.0556 0x08e4 upnphost - ok
              20:22:23.0594 0x08e4 [ 6F1A3157A1C89435352CEB543CDB359C, 325B46220779C5FE3B6F19FF794474837FAB9675D9C98ACB68 CCE47B1CFE5F12 ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
              20:22:23.0615 0x08e4 usbccgp - ok
              20:22:23.0647 0x08e4 [ AF0892A803FDDA7492F595368E3B68E7, F263346DEB4D742EB436CF578F187AC8521D84CED52E98475E 6198EC52244F07 ] usbcir C:\windows\system32\drivers\usbcir.sys
              20:22:23.0672 0x08e4 usbcir - ok
              20:22:23.0684 0x08e4 [ C025055FE7B87701EB042095DF1A2D7B, D7B34B6C2C5BD3C8141895AC21BB637EA5E3C4F7A85EEF4C4C 36E6BB2045A3D9 ] usbehci C:\windows\system32\DRIVERS\usbehci.sys
              20:22:23.0720 0x08e4 usbehci - ok
              20:22:23.0759 0x08e4 [ 287C6C9410B111B68B52CA298F7B8C24, 98900C08FE662A00DF8B37837B2BEBF9ACB7989C387AF36B21 09B05A4F462D4E ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
              20:22:23.0806 0x08e4 usbhub - ok
              20:22:23.0836 0x08e4 [ 9840FC418B4CBD632D3D0A667A725C31, 776D86A032DCA2842EF7AADB35473193CA80547223EFAA7F11 0F296C377077B0 ] usbohci C:\windows\system32\drivers\usbohci.sys
              20:22:23.0873 0x08e4 usbohci - ok
              20:22:23.0891 0x08e4 [ 73188F58FB384E75C4063D29413CEE3D, B485463933306036B1D490722CB1674DC85670753D79FA0EF7 EBCA7BBAAD9F7C ] usbprint C:\windows\system32\drivers\usbprint.sys
              20:22:23.0931 0x08e4 usbprint - ok
              20:22:23.0953 0x08e4 [ FED648B01349A3C8395A5169DB5FB7D6, DC4D7594C24ADD076927B9347F1B50B91CF03A4ABDB284248D 5711D9C19DEB96 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
              20:22:23.0991 0x08e4 USBSTOR - ok
              20:22:24.0012 0x08e4 [ 62069A34518BCF9C1FD9E74B3F6DB7CD, C58E21424718729324B285BEE1C96551540FCC3FD650B2D108 95EBA48D981E25 ] usbuhci C:\windows\system32\drivers\usbuhci.sys
              20:22:24.0030 0x08e4 usbuhci - ok
              20:22:24.0066 0x08e4 [ 454800C2BC7F3927CE030141EE4F4C50, 10901E62DAA70657C499AD590DECCCA6E46FDDF4A193B2F192 79E1B8ED7B1E44 ] usbvideo C:\windows\system32\Drivers\usbvideo.sys
              20:22:24.0093 0x08e4 usbvideo - ok
              20:22:24.0115 0x08e4 [ EDBB23CBCF2CDF727D64FF9B51A6070E, 7202484C8E1BFB2AFD64D8C81668F3EDE0E3BF5EB27572877A 0A7B337AE5AE42 ] UxSms C:\windows\System32\uxsms.dll
              20:22:24.0168 0x08e4 UxSms - ok
              20:22:24.0194 0x08e4 [ C118A82CD78818C29AB228366EBF81C3, 00820F3065871DCBA52A27C7F73BA470C4F2CB26EFB7F76FEF 8B1207F81B284D ] VaultSvc C:\windows\system32\lsass.exe
              20:22:24.0207 0x08e4 VaultSvc - ok
              20:22:24.0222 0x08e4 [ C5C876CCFC083FF3B128F933823E87BD, 6FE0FBB6C3207E09300E0789E2168F76668D87C317FE9F263E 733827ADCFBE0D ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
              20:22:24.0239 0x08e4 vdrvroot - ok
              20:22:24.0269 0x08e4 [ 8D6B481601D01A456E75C3210F1830BE, A2CEF483F4231367138EEF7E67FD5BE5364FC0780C44CA1368 E36CE4AA3D0633 ] vds C:\windows\System32\vds.exe
              20:22:24.0328 0x08e4 vds - ok
              20:22:24.0374 0x08e4 [ DA4DA3F5E02943C2DC8C6ED875DE68DD, EDE604536DB78C512D68C92B26DA77C8811AC109D1F0A47367 3F0A82D15A2838 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
              20:22:24.0395 0x08e4 vga - ok
              20:22:24.0410 0x08e4 [ 53E92A310193CB3C03BEA963DE7D9CFC, 45898604375B42EB1246C17A22D91C2440F11C746FF6459AD3 8027C1BC2E3125 ] VgaSave C:\windows\System32\drivers\vga.sys
              20:22:24.0467 0x08e4 VgaSave - ok
              20:22:24.0498 0x08e4 [ 2CE2DF28C83AEAF30084E1B1EB253CBB, D1946816A1CB89F825CBEA58F94A4C9D0CE7249355CD391556 3F54054EE564BF ] vhdmp C:\windows\system32\drivers\vhdmp.sys
              20:22:24.0522 0x08e4 vhdmp - ok
              20:22:24.0538 0x08e4 [ E5689D93FFE4E5D66C0178761240DD54, 6D35CED80681B12AAF63BFA0DA1C386E71D3838839B68A6869 90AA8031949D27 ] viaide C:\windows\system32\drivers\viaide.sys
              20:22:24.0554 0x08e4 viaide - ok
              20:22:24.0587 0x08e4 [ D2AAFD421940F640B407AEFAAEBD91B0, 31EF342A60AF04F4108759A71F8FB7B8C8819216CF3D16A95B 2BA0E33A8A9161 ] volmgr C:\windows\system32\drivers\volmgr.sys
              20:22:24.0605 0x08e4 volmgr - ok
              20:22:24.0626 0x08e4 [ A255814907C89BE58B79EF2F189B843B, 463DB771851352185B6AC323BD93B9084D47291E53C1F7B628 B65D6918B2E28F ] volmgrx C:\windows\system32\drivers\volmgrx.sys
              20:22:24.0654 0x08e4 volmgrx - ok
              20:22:24.0673 0x08e4 [ DF8126BD41180351A093A3AD2FC8903B, AEFF4AA89CDDAAAD43CDE17C6B6EB2A397A0AC1651CBD51B88 9161EC2BC6527A ] volsnap C:\windows\system32\drivers\volsnap.sys
              20:22:24.0699 0x08e4 volsnap - ok
              20:22:24.0724 0x08e4 [ 5E2016EA6EBACA03C04FEAC5F330D997, 53106EB877459FE55A459111F7AB0EE320BB3B4C954D3DB6FA 1642396001F2AC ] vsmraid C:\windows\system32\drivers\vsmraid.sys
              20:22:24.0746 0x08e4 vsmraid - ok
              20:22:24.0816 0x08e4 [ B60BA0BC31B0CB414593E169F6F21CC2, 47B801E623254CF0202B3591CB5C019CABFB52F123C7D47E29 D19B32F1F2B915 ] VSS C:\windows\system32\vssvc.exe
              20:22:24.0888 0x08e4 VSS - ok
              20:22:24.0916 0x08e4 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1, 3254523C85C70EBA2DBAC05DB2DBA89EDF8E9195F390F7C21F 96458FB6B2E3D7 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
              20:22:24.0937 0x08e4 vwifibus - ok
              20:22:24.0947 0x08e4 [ 6A3D66263414FF0D6FA754C646612F3F, 30F6BA594B0D3B94113064015A16D97811CD989DF1715CCE21 CEAB9894C1B4FB ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
              20:22:24.0971 0x08e4 vwififlt - ok
              20:22:25.0020 0x08e4 [ 1C9D80CC3849B3788048078C26486E1A, 34A89F31E53F6B6C209B286F580CC2257AE6D057E4E20741F2 41C9C167947962 ] W32Time C:\windows\system32\w32time.dll
              20:22:25.0060 0x08e4 W32Time - ok
              20:22:25.0083 0x08e4 [ 4E9440F4F152A7B944CB1663D3935A3E, 8FE04EBD3BC612EE943A21A3E56F37E5C9B578CDACA6044048 181DAD81816D53 ] WacomPen C:\windows\system32\drivers\wacompen.sys
              20:22:25.0124 0x08e4 WacomPen - ok
              20:22:25.0154 0x08e4 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC531 1386EDFCB18399 ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
              20:22:25.0235 0x08e4 WANARP - ok
              20:22:25.0239 0x08e4 [ 356AFD78A6ED4457169241AC3965230C, CE4D1EE3525C10AC658B20776C3E444DE44874C837713DC531 1386EDFCB18399 ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
              20:22:25.0277 0x08e4 Wanarpv6 - ok
              20:22:25.0374 0x08e4 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C, 4150DAB33E8D61076F1D4767BCAFC9B4ECCCCBD58FD4FB3CFE 5B8D27DCDCAB61 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
              20:22:25.0414 0x08e4 WatAdminSvc - ok
              20:22:25.0484 0x08e4 [ 78F4E7F5C56CB9716238EB57DA4B6A75, 46A4E78CE5F2A4B26F4E9C3FF04A99D9B727A82AC2E390A82A 1611C3F6E0C9AF ] wbengine C:\windows\system32\wbengine.exe
              20:22:25.0560 0x08e4 wbengine - ok
              20:22:25.0585 0x08e4 [ 3AA101E8EDAB2DB4131333F4325C76A3, 4F7BD3DA5E58B18BFF106CFF7B45E75FD13EE556D433C695BA 23EC80827E49DE ] WbioSrvc C:\windows\System32\wbiosrvc.dll
              20:22:25.0608 0x08e4 WbioSrvc - ok
              20:22:25.0642 0x08e4 [ 7368A2AFD46E5A4481D1DE9D14848EDD, 8039C478FC2D9F095F5883A4FA47F9E6EDF57CC88A4AA74F07 C88445F90DED57 ] wcncsvc C:\windows\System32\wcncsvc.dll
              20:22:25.0690 0x08e4 wcncsvc - ok
              20:22:25.0722 0x08e4 [ 20F7441334B18CEE52027661DF4A6129, 7B8E0247234B740FED2BE9B833E9CE8DD7453340123AB43F6B 495A7E6A27B0DD ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
              20:22:25.0736 0x08e4 WcsPlugInService - ok
              20:22:25.0758 0x08e4 [ 72889E16FF12BA0F235467D6091B17DC, F2FD0BBD075E33608D93F350D216F97442AB89ABD540513C2D 568C78096E12A8 ] Wd C:\windows\system32\drivers\wd.sys
              20:22:25.0774 0x08e4 Wd - ok
              20:22:25.0804 0x08e4 [ 441BD2D7B4F98134C3A4F9FA570FD250, FF20815273014C5A27C2B75E2C70FE674809293627056199F5 02DFDF4CECFCA1 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
              20:22:25.0842 0x08e4 Wdf01000 - ok
              20:22:25.0861 0x08e4 [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793 A3E219EB961209 ] WdiServiceHost C:\windows\system32\wdi.dll
              20:22:25.0897 0x08e4 WdiServiceHost - ok
              20:22:25.0901 0x08e4 [ BF1FC3F79B863C914687A737C2F3D681, B2DF47AC4931ACFB243775767B77065CC0D98778FC0243C793 A3E219EB961209 ] WdiSystemHost C:\windows\system32\wdi.dll
              20:22:25.0921 0x08e4 WdiSystemHost - ok
              20:22:25.0954 0x08e4 [ 3DB6D04E1C64272F8B14EB8BC4616280, 9138642B1C19F895D4ECFD930160C80FBF15813CE63BBF4C89 9842C300FD3026 ] WebClient C:\windows\System32\webclnt.dll
              20:22:25.0996 0x08e4 WebClient - ok
              20:22:26.0019 0x08e4 [ C749025A679C5103E575E3B48E092C43, B71171D07EE7AB085A24BF3A1072FF2CE7EA021AAE695F6A90 640E6EE8EB55C1 ] Wecsvc C:\windows\system32\wecsvc.dll
              20:22:26.0089 0x08e4 Wecsvc - ok
              20:22:26.0110 0x08e4 [ 7E591867422DC788B9E5BD337A669A08, 484E6BCCDF7ADCE9A1AACAD1BC7C7D7694B9E40FA90D94B14D 80C607784F6C75 ] wercplsupport C:\windows\System32\wercplsupport.dll
              20:22:26.0143 0x08e4 wercplsupport - ok
              20:22:26.0189 0x08e4 [ 6D137963730144698CBD10F202E9F251, A9F522A125158D94F540544CCD4DBF47B9DCE2EA878C33675A FE40F80E8F4979 ] WerSvc C:\windows\System32\WerSvc.dll
              20:22:26.0221 0x08e4 WerSvc - ok
              20:22:26.0229 0x08e4 [ 611B23304BF067451A9FDEE01FBDD725, 0AF2734B978165FC6FD22B64862132CCE32528A21C698A49D1 76129446E099C8 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
              20:22:26.0264 0x08e4 WfpLwf - ok
              20:22:26.0285 0x08e4 [ 05ECAEC3E4529A7153B3136CEB49F0EC, 9995CB2CEC70A633EA33CBB0DEAD2BB28CB67132B41E9444BD AB9E75744C9A50 ] WIMMount C:\windows\system32\drivers\wimmount.sys
              20:22:26.0301 0x08e4 WIMMount - ok
              20:22:26.0304 0x08e4 WinHttpAutoProxySvc - ok
              20:22:26.0369 0x08e4 [ 19B07E7E8915D701225DA41CB3877306, D6555E8D276DBB11358246E0FE215F76F1FB358791C76B88D8 2C2A66A42DA19F ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
              20:22:26.0405 0x08e4 Winmgmt - ok
              20:22:26.0489 0x08e4 [ BCB1310604AA415C4508708975B3931E, 9D943F086D454345153A0DD426B4432532A44FD87950386B18 6E1CAD2AC70565 ] WinRM C:\windows\system32\WsmSvc.dll
              20:22:26.0573 0x08e4 WinRM - ok
              20:22:26.0633 0x08e4 [ 4FADA86E62F18A1B2F42BA18AE24E6AA, CE1683386886BF34862681A46199EA7E7FB4232A186047DA7F BD8EC240AF6726 ] Wlansvc C:\windows\System32\wlansvc.dll
              20:22:26.0694 0x08e4 Wlansvc - ok
              20:22:26.0750 0x08e4 [ 06C8FA1CF39DE6A735B54D906BA791C6, D8FEC7DE227781CDA876904701B2AA995268F74DCD6CB34AA0 296C557FC283B6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
              20:22:26.0760 0x08e4 wlcrasvc - ok
              20:22:26.0907 0x08e4 [ 2BACD71123F42CEA603F4E205E1AE337, 1FEF20554110371D738F462ECFFA999158EFEED02062414C58 C1B61C422BF0B9 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
              20:22:26.0971 0x08e4 wlidsvc - ok
              20:22:27.0012 0x08e4 [ F6FF8944478594D0E414D3F048F0D778, 6F75E0AE6127B33A92A88E59D4B048FD4C15F997807BE7BF0E FE76F95235B1D9 ] WmiAcpi C:\windows\system32\DRIVERS\wmiacpi.sys
              20:22:27.0049 0x08e4 WmiAcpi - ok
              20:22:27.0089 0x08e4 [ 38B84C94C5A8AF291ADFEA478AE54F93, 1AC267AC73670BEA5F3785C9AD9DB146F8E993A862C843742B 21FDB90D102B2A ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
              20:22:27.0108 0x08e4 wmiApSrv - ok
              20:22:27.0141 0x08e4 WMPNetworkSvc - ok
              20:22:27.0163 0x08e4 [ 96C6E7100D724C69FCF9E7BF590D1DCA, 2E63C9B0893B4FC03B7A71BAEA6202D3D3DB1B52F364346782 9B5A573FD7655B ] WPCSvc C:\windows\System32\wpcsvc.dll
              20:22:27.0176 0x08e4 WPCSvc - ok
              20:22:27.0199 0x08e4 [ 93221146D4EBBF314C29B23CD6CC391D, C0750858A65BF51E210CD244C825C121D67E025CD2D2455139 991AAC289A90FE ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
              20:22:27.0217 0x08e4 WPDBusEnum - ok
              20:22:27.0235 0x08e4 [ 6BCC1D7D2FD2453957C5479A32364E52, E48554D31FBDCF8F985C1C72524CAA9106F5B7CC2B79064F8F 5E2562D517F090 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
              20:22:27.0270 0x08e4 ws2ifsl - ok
              20:22:27.0291 0x08e4 [ E8B1FE6669397D1772D8196DF0E57A9E, 39FE0819360719F756BD31A1884A0508A1E2371ACC723E25E0 05CBEC0A7B02FA ] wscsvc C:\windows\System32\wscsvc.dll
              20:22:27.0311 0x08e4 wscsvc - ok
              20:22:27.0314 0x08e4 WSearch - ok
              20:22:27.0408 0x08e4 [ D9EF901DCA379CFE914E9FA13B73B4C4, 3BE9693B7B2AFEE23D72AF5DA211379724D752F0EC18ACB7D3 DE3DDFC5AE0004 ] wuauserv C:\windows\system32\wuaueng.dll
              20:22:27.0478 0x08e4 wuauserv - ok
              20:22:27.0502 0x08e4 [ D3381DC54C34D79B22CEE0D65BA91B7C, 70DC4ADCA4C0C28BB133287511E329D1B6B9B97F96CDE5B1D2 F1F59FE1A965D9 ] WudfPf C:\windows\system32\drivers\WudfPf.sys
              20:22:27.0562 0x08e4 WudfPf - ok
              20:22:27.0606 0x08e4 [ CF8D590BE3373029D57AF80914190682, FB9641777E90A58C063FBE95F081DC6D2F4770827DE19108A9 DC3E3D6B17B4BF ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
              20:22:27.0648 0x08e4 WUDFRd - ok
              20:22:27.0675 0x08e4 [ 7A95C95B6C4CF292D689106BCAE49543, 9029F489E1E817CE12839B8C6656E46190497D445DC3F43C20 CF96E5E6BD0691 ] wudfsvc C:\windows\System32\WUDFSvc.dll
              20:22:27.0707 0x08e4 wudfsvc - ok
              20:22:27.0732 0x08e4 [ 9A3452B3C2A46C073166C5CF49FAD1AE, D6F95F51D8E37BA4CF403965EC08CCFEEA9EEFDBFC7752432E AEC19925BDA115 ] WwanSvc C:\windows\System32\wwansvc.dll
              20:22:27.0776 0x08e4 WwanSvc - ok
              20:22:27.0851 0x08e4 [ 21E13F2CB269DEFEAE5E1D09887D47BB, 543991CA8D1C65113DFF039B85AE3F9A87F503DAEC30F46929 FD454BC57E5A91 ] ZAM C:\windows\System32\drivers\zam64.sys
              20:22:27.0873 0x08e4 ZAM - ok
              20:22:28.0721 0x08e4 [ C78761C2A5475EA16ADCD438CC17841F, 2EC81397DE7BEF39EA1E1758FE778A0A31C8D04B6AD76D9C09 17D95808366A70 ] ZAMSvc C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
              20:22:29.0018 0x08e4 ZAMSvc - ok
              20:22:29.0109 0x08e4 [ 21E13F2CB269DEFEAE5E1D09887D47BB, 543991CA8D1C65113DFF039B85AE3F9A87F503DAEC30F46929 FD454BC57E5A91 ] ZAM_Guard C:\windows\System32\drivers\zamguard64.sys
              20:22:29.0130 0x08e4 ZAM_Guard - ok
              20:22:29.0133 0x08e4 ================ Scan global ===============================
              20:22:29.0159 0x08e4 [ BA0CD8C393E8C9F83354106093832C7B, 18D8A4780A2BAA6CEF7FBBBDA0EF6BF2DADF146E1E578A618D D5859E8ADBF1A8 ] C:\windows\system32\basesrv.dll
              20:22:29.0197 0x08e4 [ EB6A48CC998E1090E44E8E7F1009A640, 94001F8AEB2A398E7C267C90183ABED2AFA6FC4C219027C861 C6C1329093464A ] C:\windows\system32\winsrv.dll
              20:22:29.0209 0x08e4 [ EB6A48CC998E1090E44E8E7F1009A640, 94001F8AEB2A398E7C267C90183ABED2AFA6FC4C219027C861 C6C1329093464A ] C:\windows\system32\winsrv.dll
              20:22:29.0231 0x08e4 [ D6160F9D869BA3AF0B787F971DB56368, 0033E6212DD8683E4EE611B290931FDB227B4795F0B17C309D C686C696790529 ] C:\windows\system32\sxssrv.dll
              20:22:29.0271 0x08e4 [ 24ACB7E5BE595468E3B9AA488B9B4FCB, 63541E3432FCE953F266AE553E7A394978D6EE3DB52388D885 F668CF42C5E7E2 ] C:\windows\system32\services.exe
              20:22:29.0279 0x08e4 [ Global ] - ok
              20:22:29.0279 0x08e4 ================ Scan MBR ==================================
              20:22:29.0290 0x08e4 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0
              20:22:29.0702 0x08e4 \Device\Harddisk0\DR0 - detected TDSS File System ( 1 )
              20:22:29.0702 0x08e4 \Device\Harddisk0\DR0 ( TDSS File System ) - warning
              20:22:32.0533 0x08e4 ================ Scan VBR ==================================
              20:22:32.0588 0x08e4 [ 8AC23BED265B9837B514C7AD0AE3474B ] \Device\Harddisk0\DR0\Partition1
              20:22:32.0589 0x08e4 \Device\Harddisk0\DR0\Partition1 - ok
              20:22:32.0589 0x08e4 ================ Scan generic autorun ======================
              20:22:32.0590 0x08e4 TPwrMain - ok
              20:22:32.0591 0x08e4 HSON - ok
              20:22:32.0592 0x08e4 TCrdMain - ok
              20:22:32.0658 0x08e4 [ 6B640D9B1C114DDB8A534A9101DCEF29, 2993E6282D8DC6CD431D7B79C9C7EB3AF9AB3BBDD8F90C8514 2D14DC2575BB99 ] C:\Program Files\CONEXANT\SAII\SAIICpl.exe
              20:22:32.0672 0x08e4 SmartAudio - ok
              20:22:32.0727 0x08e4 [ 8D8839FDB43DE6F35D4A26294B8B9549, 536C38B0D78A170180495098AAE6187DA428C8338E971F264B 083808C8949EBF ] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent 64.exe
              20:22:32.0746 0x08e4 cAudioFilterAgent - ok
              20:22:32.0747 0x08e4 SynTPEnh - ok
              20:22:32.0770 0x08e4 Teco - ok
              20:22:32.0770 0x08e4 TosWaitSrv - ok
              20:22:32.0807 0x08e4 [ F82483A80D49ACCA81193A294FB233CD, 7EEA9E7F62A92AD98569B1A4F4809D91D7ED671821A738EB75 BC6E469DB44494 ] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
              20:22:32.0815 0x08e4 TosVolRegulator - ok
              20:22:32.0883 0x08e4 [ 426350B428CD70D037A3326EB9E5EDFD, B7B1A20D1D75661533CF983EA0C6E520B928AF6FCCDA70C488 FC8FC566B5AF7F ] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
              20:22:32.0904 0x08e4 TosSENotify - ok
              20:22:32.0906 0x08e4 TosNC - ok
              20:22:32.0908 0x08e4 TosReelTimeMonitor - ok
              20:22:33.0450 0x08e4 [ C78761C2A5475EA16ADCD438CC17841F, 2EC81397DE7BEF39EA1E1758FE778A0A31C8D04B6AD76D9C09 17D95808366A70 ] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
              20:22:33.0743 0x08e4 ZAM - ok
              20:22:33.0800 0x08e4 [ BB752714D14CB1F13969D721F1A3A60F, 32B95C75704BE37B349E0493AA8D2FCDAE8007275124646125 650456D3A1563F ] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
              20:22:33.0813 0x08e4 TSleepSrv - ok
              20:22:33.0977 0x08e4 [ 02F4246866BF35BF2244E5CF72E25895, AA08D3E65CCF6F4F79D169575C9B4FE8BA078246BFB30C3809 39A4A3B6092074 ] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe
              20:22:34.0049 0x08e4 NortonOnlineBackupReminder - ok
              20:22:34.0102 0x08e4 [ 2D7816ACDA1CC85C873CBC19A4121D58, 3F3E41EBEF81DB8C2A84A8E75D1E4852046A10A5DCB8CCCC2A DF7FD0DC8EEF66 ] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe
              20:22:34.0135 0x08e4 ToshibaAppPlace - detected UnsignedFile.Multi.Generic ( 1 )
              20:22:36.0883 0x08e4 Detect skipped due to KSN trusted
              20:22:36.0883 0x08e4 ToshibaAppPlace - ok
              20:22:36.0965 0x08e4 [ 4EB0C6C3EF4D8885CF2B5D0062F31E44, A3967758E30609D29A4856F373DD2C971B341F914825D72038 7ACFD7499EDC3D ] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
              20:22:36.0997 0x08e4 DivXUpdate - ok
              20:22:37.0479 0x08e4 [ 70050353213574B62CA9EC28F65F2F3E, 3EBC0ABFC9ABFE4508E21A032A28D12B73CB91DE1FD830069F F902336A271E68 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
              20:22:37.0818 0x08e4 AvastUI.exe - ok
              20:22:37.0917 0x08e4 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D4 8F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
              20:22:37.0976 0x08e4 Sidebar - ok
              20:22:38.0014 0x08e4 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B72 5CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
              20:22:38.0048 0x08e4 mctadmin - ok
              20:22:38.0105 0x08e4 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D4 8F42FCA5B343D8 ] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe
              20:22:38.0145 0x08e4 Sidebar - ok
              20:22:38.0169 0x08e4 [ 0FA760BF380B08D0B67B5507CD8B32AA, 0F73A7F64C4FDAB98CD3A865CC54B3A7195761530FCB115B72 5CC5A9FB738739 ] C:\Windows\System32\mctadmin.exe
              20:22:38.0188 0x08e4 mctadmin - ok
              20:22:38.0470 0x08e4 [ FB5B78A3DE88FD3B725DA574497BC225, 0096C3ED0E29153E6A9E84C121B79A170FEDFE521AEA1BC602 BC536E1795E5F3 ] C:\Program Files\CCleaner\CCleaner64.exe
              20:22:38.0642 0x08e4 CCleaner - ok
              20:22:38.0649 0x08e4 Waiting for KSN requests completion. In queue: 13
              20:22:39.0649 0x08e4 Waiting for KSN requests completion. In queue: 13
              20:22:40.0649 0x08e4 Waiting for KSN requests completion. In queue: 13
              20:22:41.0721 0x08e4 AV detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 12.1.3076.0 ), 0x41000 ( enabled : updated )
              20:22:41.0723 0x08e4 FW detected via SS2: avast! Antivirus, C:\Program Files\AVAST Software\Avast\VisthAux.exe ( 12.1.3076.0 ), 0x40010 ( disabled )
              20:22:41.0726 0x08e4 Win FW state via NFP2: enabled ( trusted )
              20:22:44.0549 0x08e4 ================================================== ==========
              20:22:44.0549 0x08e4 Scan finished
              20:22:44.0549 0x08e4 ================================================== ==========
              20:22:44.0555 0x1518 Detected object count: 1
              20:22:44.0555 0x1518 Actual detected object count: 1
              20:23:05.0003 0x1518 \Device\Harddisk0\DR0\TDLFS - deleted
              20:23:05.0003 0x1518 \Device\Harddisk0\DR0 ( TDSS File System ) - User select action: Delete
              20:23:09.0012 0x0714 Deinitialize success

              Comment

              • PatL
                PCHF Member
                • Feb 2017
                • 83

                #22
                --------------- QuickScript | g3n-h@ckm@n | V3_02.04.17.1 ---------------

                ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 19/04/2017 20:24:50

                Updated 02/04/2017 | 14.30 (GMT) by g3n-h@ckm@n
                Contact : http://www.sosvirus.net/

                Time Zone : (UTC-08:00) Pacific Time (US & Canada)
                [Mitch (Administrator)] - [MITCH-PC] (S-1-5-21-2113883840-1160270776-2747418757-1000)

                System: Microsoft Windows 7 Home Premium - Service Pack 1 - (6.1.7601) - BuildType: Multiprocessor Free - OSLanguage: 1033 (0409)
                System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
                Boot : Microsoft Windows 7 Home Premium |C:\windows|\Device\Harddisk0\Partition2
                Boot : Normal boot
                PC: Satellite L755 - TOSHIBA - IdNumber: XB319792W - UUID: 71136460-FBBA-11E0-961F-047D7B056E26
                Processor : X64 - 2394 Mhz - Intel(R) Core™ i5-2430M CPU @ 2.40GHz
                InsydeH2O Version 03.60.453.40 - en|US|iso8859-1 - INSYDE - S/N: XB319792W - 3.40 - TOSQCI - 1
                CoreTemp : ? Celsius

                ----------| Script

                Registry saved : C:\QuickDiag\Save\Registry [19.04.2017 @ 20_24_51]

                Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\87566282.sys] Deleted Successfully
                Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\87566282.sys] Deleted Successfully
                Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Classes\Applications\FreeTorrentView er.exe] Deleted Successfully
                Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Blehjoqlir] Deleted Successfully
                Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\MCAFEE] Deleted Successfully
                Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Strongvault] Deleted Successfully
                Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Tific] Not Found !
                Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\Yahoo] Deleted Successfully
                Key : [HKLM\Software\REGSERVO] Deleted Successfully
                Key : [HKLM\Software\WOW6432Node\AdobeFlashPlayerUpdate] Deleted Successfully
                Key : [HKLM\Software\WOW6432Node\Tific] Not Found !
                Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class{522119 B9-1B9A-498A-AC52-148B533EFD50}] Deleted Successfully
                Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class{87C077 B2-3D3B-4156-938A-EA51B451D6C6}] Deleted Successfully
                Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class{FB58BE 68-EA9E-4803-847F-2CE814E7B159}] Deleted Successfully
                C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn Moved Successfully
                C:\Program Files (x86)\FreeTorrentViewer Moved Successfully
                C:\windows\Installer\262be5.msi’ Not Found !
                C:\windows\Installer\9118a6.msi Moved Successfully
                C:\windows\Installer\938618.msi Moved Successfully
                C:\windows\System32\gatherNetworkInfo.vbs Moved Successfully
                C:\Users\Mitch\AppData\Local\Tific Moved Successfully
                C:\Users\Mitch\AppData\LocalLow\Yahoo! Not Found !
                C:\Users\Mitch\AppData\Roaming\FreeTorrentViewer Moved Successfully
                C:\Users\Mitch\AppData\Roaming\Tific Not Found !
                C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\FreeTorrentViewer Moved Successfully
                C:\ProgramData\McAfee Moved Successfully
                C:\ProgramData\REGSERVO64 Moved Successfully
                C:\ProgramData\Yahoo! Not Found !
                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REGSERVO Moved Successfully
                C:\Program Files (x86)\FreeTorrentViewer Not Found !
                C:\Program Files (x86)\Yahoo! Not Found !
                C:\ProgramData\Temp:373E1720 Not Moved ! → Reboot !
                C:\ProgramData\Temp1B5B4F1 Not Moved ! → Reboot !
                ADS : @C:\ProgramData\Temp:373E1720 Deleted successfully
                ADS : @C:\ProgramData\Temp1B5B4F1 Deleted successfully

                -------------- | CleanDisk :

                FreeSpace : 411439
                Cleaning…
                FreeSpace : 411439

                ----------(EOF)----------

                Comment

                • PatL
                  PCHF Member
                  • Feb 2017
                  • 83

                  #23
                  What now??

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #24
                    I’d like you to re-run the Quick Diag fix, I had edited in a couple new items, just re run the entire fix for me, making sure to create a new restore point prior and reboot after.

                    Eliminate restrictive settings with this tool.

                    [ul]
                    [li]Temporarily disable your antivirus — Your antivirus may flag this tool as malware, it is safe to run I assure you.[/li]
                    [li]Download SupRestric.exe save to your desktop.[/li][li]Close all running programs.[/li][li]Double click the file to launch it.[/li][li]Windows: 7/8/10 Vista and run as administrator[/li][li]Click Yes at any prompt.[/li]
                    [li]The analysis takes only a few moments.[/li][li]The report is on the desktop ( CTR.txt )[/li][li]Copy paste report in next reply.[/li][li]A reboot is needed to complete the repairs.[/li][/ul]
                    HijackThis.

                    1- Please Click HERE to download HijackThis. – Unzip to your desktop.
                    2- Right click run as admin.
                    3- Click on the Main Menu button if not already there.
                    4- Select Do a system scan and save a logfile.
                    5- Copy paste the log here.

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #25
                      AdsFix Scan and clean.
                      [ul]
                      [li]Disable Windows Defender, Firewall & Antivirus prior to running this tool!![/li][li]Save AdsFix to your desktop.[/li][li]Right Click & Run As Administrator.[/li][li]With an infected machine, it could take several seconds to be charged.[/li][li]You will then be prompted to install Certificates.[/li][li]Install then click OK.[/li][li]Right Click & Run As Administrator Again.[/li][/ul]


                      [ul]
                      [li]Click Options then select Unlock the deletion.[/li][li]Then click on clean.[/li][li]Enter your country[/li][li]Don’t use the machine while scanning and be patient[/li][li]Once the scan has completed, please copy and paste the report in your next reply.[/li][li]The report will be C:\AdsFix_date_hour.txt or on your dektop with the same name.[/li][/ul]

                      Then go ahead and remove the out dated version of malwarebytes that is installed.


                      Malwarebytes.
                      [ul]
                      [li]Download MalwareBytes Anti-Malware : https://www.malwarebytes.com/mwb-download/ take the free version ( on the left )[/li][li]Perform the installation[/li][li]Uncheck “Enable Free Trial of Malwarebytes Anti-Malware Premium” if it’s asked[/li][li]Malwarebytes will update, let this update,[/li][li]Click on the “Settings” tab and then on the “Detection and Protection” tab, Check the box “Search for Rootkits”[/li][li]Click on the “Analysis” tab and then on “Start analysis”[/li][li]Once the review is complete, check that all detections are checked and then click [Delete Selection][/li][li]If Malwarebytes asks you to restart your PC, click “Yes”[/li][li]When restarting your PC, restarts Malwarebytes[/li][li]Opens the “History” tab and then “Application logs”[/li][li]Double click on the last Scan Log in date (the one above)[/li][li]At the bottom click [Export] → select “Text file (* .txt)”[/li][li]In the explorer selects the desktop, name it mbam.txt, click [Save][/li][/ul]

                      Comment

                      • PatL
                        PCHF Member
                        • Feb 2017
                        • 83

                        #26
                        re-ran quick fix:
                        --------------- QuickScript | g3n-h@ckm@n | V3_02.04.17.1 ---------------

                        ----- XP | Vista | 7 | 8 | 8.1 | 10 - 32/64 bits ----- - Start 19/04/2017 20:49:25

                        Updated 02/04/2017 | 14.30 (GMT) by g3n-h@ckm@n
                        Contact : http://www.sosvirus.net/

                        Time Zone : (UTC-08:00) Pacific Time (US & Canada)
                        [Mitch (Administrator)] - [MITCH-PC] (S-1-5-21-2113883840-1160270776-2747418757-1000)

                        System: Microsoft Windows 7 Home Premium - Service Pack 1 - (6.1.7601) - BuildType: Multiprocessor Free - OSLanguage: 1033 (0409)
                        System: AutoReboot: True - DebugFilePath: %SystemRoot%\MEMORY.DMP - KernelDumpOnly: False - OverwriteExistingDebugFile: True - WriteDebugInfo: True - WriteToSystemLog: True
                        Boot : Microsoft Windows 7 Home Premium |C:\windows|\Device\Harddisk0\Partition2
                        Boot : Normal boot
                        PC: Satellite L755 - TOSHIBA - IdNumber: XB319792W - UUID: 71136460-FBBA-11E0-961F-047D7B056E26
                        Processor : X64 - 2394 Mhz - Intel(R) Core™ i5-2430M CPU @ 2.40GHz
                        InsydeH2O Version 03.60.453.40 - en|US|iso8859-1 - INSYDE - S/N: XB319792W - 3.40 - TOSQCI - 1
                        CoreTemp : ? Celsius

                        ----------| Script

                        Registry saved : C:\QuickDiag\Save\Registry [19.04.2017 @ 20_49_26]

                        Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Min imal\87566282.sys] Not Found !
                        Key : [HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Net work\87566282.sys] Not Found !
                        Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\Classes\Applications\FreeTorrentView er.exe] Not Found !
                        Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Blehjoqlir] Not Found !
                        Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\MCAFEE] Not Found !
                        Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Strongvault] Not Found !
                        Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\Software\Tific] Not Found !
                        Key : [HKU\S-1-5-21-2113883840-1160270776-2747418757-1000\SOFTWARE\AppDataLow\Software\Yahoo] Not Found !
                        Key : [HKLM\Software\REGSERVO] Not Found !
                        Key : [HKLM\Software\WOW6432Node\AdobeFlashPlayerUpdate] Not Found !
                        Key : [HKLM\Software\WOW6432Node\Tific] Not Found !
                        Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class{03F529 37-1FD6-44FB-82C6-FE988F1B1D61}] Deleted Successfully
                        Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class{522119 B9-1B9A-498A-AC52-148B533EFD50}] Deleted Successfully
                        Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class{87C077 B2-3D3B-4156-938A-EA51B451D6C6}] Deleted Successfully
                        Key : [HKLM\SYSTEM\CurrentControlSet\Control\Class{FB58BE 68-EA9E-4803-847F-2CE814E7B159}] Deleted Successfully
                        C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\extensions\ekdjfcdinekpfcedakhpngcnaa mhiihn Not Found !
                        C:\Program Files (x86)\FreeTorrentViewer Not Found !
                        C:\windows\Installer\262be5.msi’ Not Found !
                        C:\windows\Installer\9118a6.msi Not Found !
                        C:\windows\Installer\938618.msi Not Found !
                        C:\windows\System32\gatherNetworkInfo.vbs Not Found !
                        C:\Users\Mitch\AppData\Local\Tific Not Found !
                        C:\Users\Mitch\AppData\LocalLow\Yahoo! Not Found !
                        C:\Users\Mitch\AppData\Roaming\FreeTorrentViewer Not Found !
                        C:\Users\Mitch\AppData\Roaming\Tific Not Found !
                        C:\Users\Mitch\AppData\Roaming\Microsoft\Windows\S tart Menu\Programs\FreeTorrentViewer Not Found !
                        C:\ProgramData\McAfee Not Found !
                        C:\ProgramData\REGSERVO64 Not Found !
                        C:\ProgramData\Yahoo! Not Found !
                        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REGSERVO Not Found !
                        C:\Program Files (x86)\FreeTorrentViewer Not Found !
                        C:\Program Files (x86)\Yahoo! Not Found !
                        C:\ProgramData\Temp:373E1720 Not Found !
                        C:\ProgramData\Temp1B5B4F1 Not Found !

                        -------------- | CleanDisk :

                        FreeSpace : 411401
                        Cleaning…
                        FreeSpace : 411401

                        ----------(EOF)----------

                        Comment

                        • PatL
                          PCHF Member
                          • Feb 2017
                          • 83

                          #27
                          SuspRestrict
                          Report Restricted to Pierre13 (CTR version 2.5.0.0) of 19 \ 04 \ 2017 at 20:53:28
                          Mitch’s PC
                          Microsoft Windows 7 Home Premium Service Pack 1 (64-bit) [6.1.7601]

                          Repair error 2203 performed.

                          Control presence restrictions

                          [BKDR_BLACKEN.A] key DisableFirstRunCustomize deleted.
                          [BKDR_BLACKEN.A] key WarnOnClose corrected.
                          Authorization installation Java (x86) deleted.
                          Authorization installation Java (x64) deleted.
                          Restriction Display Recent documents deleted.
                          Restriction Display Documents deleted.
                          Restriction Synchronization Background Information Streams and Web Slices Removed.
                          Restriction discovery of RSS feeds and Web Slices deleted.
                          Numeric keypad active.
                          User Restriction for Windows Installer Removed.
                          Windows Update Search Reverted.
                          Windows Firewall service enabled.
                          Windows Firewall settings restored by default and enabled.

                          240 controlled restrictions.

                          12 Restricted Restriction (s).
                          Reboot the PC to take the repair (s) into account.

                          The report is on the desktop (C: \ Users \ Mitch \ Desktop \ CTR.txt)

                          Comment

                          • PatL
                            PCHF Member
                            • Feb 2017
                            • 83

                            #28
                            Logfile of HiJackThis Fork (Alpha) by Alex Dragokas v.2.6.4.17

                            Platform: x64 Windows 7 (Home Premium), 6.1.7601, Service Pack: 1
                            Time: 19.04.2017 - 20:57
                            Language: OS: English (0x409). Display: English (0x409). Non-Unicode: English (0x409)
                            Elevated: Yes
                            Ran by: Mitch (group: Administrator) on MITCH-PC

                            Chrome: 57.0.2987.133
                            Internet Explorer: 9.0.8112.16447

                            Boot mode: Normal

                            Running processes:
                            Number | Path
                            1 C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
                            1 C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
                            1 C:\Program Files (x86)\Giraffic\Veoh_Giraffic.exe
                            1 C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
                            9 C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
                            1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
                            1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
                            1 C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
                            1 C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
                            1 C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
                            1 C:\Program Files\AVAST Software\Avast\AvastSvc.exe
                            1 C:\Program Files\AVAST Software\Avast\avastui.exe
                            1 C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent 64.exe
                            1 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
                            1 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
                            1 C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
                            1 C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
                            1 C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
                            1 C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                            1 C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
                            1 C:\Program Files\Toshiba\TECO\Teco.exe
                            1 C:\Program Files\Toshiba\TECO\TecoService.exe
                            1 C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
                            1 C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
                            1 C:\Program Files\Toshiba\TPHM\TPCHSrv.exe
                            1 C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
                            1 C:\Program Files\Windows Media Player\wmpnetwk.exe
                            1 C:\Users\Mitch\Desktop\HiJackThis\HiJackThis.exe
                            1 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\Pres entationFontCache.exe
                            1 C:\Windows\System32\SearchFilterHost.exe
                            1 C:\Windows\System32\SearchIndexer.exe
                            1 C:\Windows\System32\SearchProtocolHost.exe
                            1 C:\Windows\System32\TODDSrv.exe
                            1 C:\Windows\System32\audiodg.exe
                            2 C:\Windows\System32\csrss.exe
                            1 C:\Windows\System32\dwm.exe
                            1 C:\Windows\System32\lsass.exe
                            1 C:\Windows\System32\lsm.exe
                            1 C:\Windows\System32\notepad.exe
                            1 C:\Windows\System32\services.exe
                            1 C:\Windows\System32\smss.exe
                            1 C:\Windows\System32\spoolsv.exe
                            1 C:\Windows\System32\sppsvc.exe
                            9 C:\Windows\System32\svchost.exe
                            1 C:\Windows\System32\taskeng.exe
                            1 C:\Windows\System32\wbem\WmiPrvSE.exe
                            1 C:\Windows\System32\wininit.exe
                            1 C:\Windows\System32\winlogon.exe
                            1 C:\Windows\explorer.exe

                            R4 - HKCU\Software\Microsoft\Internet Explorer\SearchScopes{012E1000-F331-11DB-8314-0800200C9A66} - Google - Google {searchTerms}
                            O4 - HKCU..\Run: [CCleaner] C:\Program Files\CCleaner\CCleaner64.exe /AUTO
                            O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe
                            O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
                            O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                            O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE
                            O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe /r
                            O4 - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
                            O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
                            O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
                            O4 - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
                            O4 - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe
                            O4 - HKLM..\Run: [ZAM] C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe /minimized
                            O4 - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent 64.exe
                            O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
                            O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe
                            O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
                            O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe
                            O4-32 - HKLM..\Run: [AvastUI.exe] C:\Program Files\AVAST Software\Avast\AvastUI.exe /nogui
                            O4-32 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW
                            O4-32 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe UNATTENDED
                            O4-32 - HKLM..\Run: [TSleepSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
                            O4-32 - HKLM..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe
                            O9-32 - Extra ‘Tools’ menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (HKLM)
                            O9-32 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (HKLM)
                            O16-32 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) - http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
                            O17 - DHCP DNS - 1: 192.168.1.1
                            O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
                            O22 - Task (Disabled): \OfficeSoftwareProtectionPlatform\SvcRestartTask - C:\windows\system32\sc.exe start osppsvc
                            O22 - Task (Queued): \Microsoft\Windows Live\SOXE\Extractor Definitions Update Task - {3519154C-227E-47F3-9CC9-12C3F05817F1} - (no file)
                            O22 - Task (Queued): \Microsoft\Windows\Application Experience\ProgramDataUpdater - C:\windows\system32\rundll32.exe aepdu.dll,AePduRunUpdate
                            O22 - Task (Queued): avast! Emergency Update - C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
                            O22 - Task (Ready): CCleanerSkipUAC - C:\Program Files\CCleaner\CCleaner.exe $(Arg0)
                            O22 - Task (Ready): GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
                            O22 - Task (Ready): GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
                            O22 - Task (Ready): SafeZone scheduled Autoupdate 1463186051 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
                            O22 - Task (Ready): \AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
                            O22 - Task (Ready): \Microsoft\Windows\Media Center\mcupdate_scheduled - C:\windows\ehome\mcupdate.exe -crl -hms -pscn 15
                            O22 - Task (Ready): \Microsoft\Windows\NetTrace\GatherNetworkInfo - C:\windows\system32\gatherNetworkInfo.vbs (file missing)
                            O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTask - C:\windows\system32\Wat\WatAdminSvc.exe /run
                            O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - C:\windows\system32\schtasks.exe /run /I /TN “\Microsoft\Windows\Windows Activation Technologies\ValidationTask”
                            O22 - Task (Ready): {1426D1E5-5A00-4D59-985A-2107F1BEF83C} - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
                            O22 - Task (Ready): {2FB9F27A-DE3A-4CD6-B8B6-B233E63B6955} - C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE
                            O22 - Task (Ready): {65C76270-92BA-4F63-B82C-13F0D18DD623} - C:\windows\system32\pcalua.exe -a “C:\Users\Mitch\Desktop\OpenOffice 4.1.1 (en-US) Installation Files\setup.exe” -d “C:\Users\Mitch\Desktop\OpenOffice 4.1.1 (en-US) Installation Files”
                            O22 - Task (Ready): {A8D2B036-36FC-403B-8061-05969D1469A2} - C:\Program Files (x86)\Microsoft Office\Options14\MSOO.EXE
                            O22 - Task (Ready): {E210F47C-43C1-4A1F-B297-CCB4BE5B7E4D} - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
                            O23 - Service R2: Avast Antivirus - (avast! Antivirus) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
                            O23 - Service R2: Intel(R) Management and Security Application Local Management Service - (LMS) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
                            O23 - Service R2: Intel(R) Management and Security Application User Notification Service - (UNS) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
                            O23 - Service R2: TOSHIBA Optical Disc Drive Service - (TODDSrv) - C:\Windows\system32\TODDSrv.exe
                            O23 - Service R2: TOSHIBA Power Saver - (TosCoSrv) - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                            O23 - Service R2: TOSHIBA eco Utility Service - C:\Program Files\TOSHIBA\TECO\TecoService.exe
                            O23 - Service R2: Veoh Giraffic Video Accelerator - (Giraffic) - C:\Program Files (x86)\Giraffic\Veoh_GirafficWatchdog.exe
                            O23 - Service R2: ZAM Controller Service - (ZAMSvc) - C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
                            O23 - Service R3: TOSHIBA HDD SSD Alert Service - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
                            O23 - Service R3: TPCH Service - (TPCHSrv) - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
                            O23 - Service S2: Google Update Service (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                            O23 - Service S2: MBAMService - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
                            O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe
                            O23 - Service S3: GamesAppService - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
                            O23 - Service S3: Google Software Updater - (gusvc) - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service S3: Google Update Service (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
                            O23 - Service S3: InstallDriver Table Manager - (IDriverT) - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                            O23 - Service S3: TMachInfo - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe


                            End of file - Time spent: 15 sec. - 21546 bytes, CRC32: FFFFFFFF. Sign: ⁽ⷿ

                            Comment

                            • Malnutrition
                              PCHF Moderator
                              • Jul 2016
                              • 7041

                              #29
                              : Hijack This Fix.

                              Start HijackThis , Right Click Run as Admin.
                              Close all other open programs prior to running this tool!!
                              Click System Scan Only.
                              Then check mark the items listed below.

                              O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe
                              O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
                              O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                              O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE
                              O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe /r
                              O4 - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe
                              O4 - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
                              O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
                              O4 - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe
                              O4 - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe
                              O4 - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent 64.exe
                              O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
                              O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
                              O4-32 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe /CHECKNOW
                              O4-32 - HKLM..\Run: [TSleepSrv] C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
                              O4-32 - HKLM..\Run: [ToshibaAppPlace] C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe
                              O22 - Task (Queued): \Microsoft\Windows Live\SOXE\Extractor Definitions Update Task - {3519154C-227E-47F3-9CC9-12C3F05817F1} - (no file)
                              O22 - Task (Queued): \Microsoft\Windows\Application Experience\ProgramDataUpdater - C:\windows\system32\rundll32.exe aepdu.dll,AePduRunUpdate
                              O22 - Task (Ready): \Microsoft\Windows\Media Center\mcupdate_scheduled - C:\windows\ehome\mcupdate.exe -crl -hms -pscn 15
                              O22 - Task (Ready): \Microsoft\Windows\NetTrace\GatherNetworkInfo - C:\windows\system32\gatherNetworkInfo.vbs (file missing)
                              O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTask - C:\windows\system32\Wat\WatAdminSvc.exe /run
                              O22 - Task (Ready): \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - C:\windows\system32\schtasks.exe /run /I /TN “\Microsoft\Windows\Windows Activation Technologies\ValidationTask”
                              O22 - Task (Ready): {1426D1E5-5A00-4D59-985A-2107F1BEF83C} - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
                              O23 - Service R2: TOSHIBA Power Saver - (TosCoSrv) - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
                              O23 - Service R2: TOSHIBA eco Utility Service - C:\Program Files\TOSHIBA\TECO\TecoService.exe
                              O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpda teService.exe
                              O23 - Service S3: GamesAppService - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe

                              Now click on fix checked.
                              After the fix is complete, then reboot your machine.

                              Comment

                              • PatL
                                PCHF Member
                                • Feb 2017
                                • 83

                                #30
                                We got a problem. My friend had to leave and had me close the AdsFix program when it was at 51%. It had deleted 41 items by then, but I couldn’t grab any log file. I will see him again next week, would interrupting that fix cause any significant issues? And are you willing to wait a week to continue with the logs/fixes?

                                Comment

                                Working...