Ir para conteúdo

BABOO e KTS 2018 no YouTube Loja online do BABOO

MAX-SP

Participante
  • Postagens

    297
  • Desde

  • Última visita

Perfil

  • Estado
    São Paulo
  • Sexo
    masculino
  1. Reinicio sem motivo do Windows 10

    Boa tarde Paulo É um notebook e não tenho como arrumar memória para testar. Há como testar sem trocar o pente de memória? Um programa que teste a memória e seja confiável?
  2. Tela Azul - Reiniciando W10

    Boa tarde Sim. Aqui foi a primeira vez no W10.
  3. Reinicio sem motivo do Windows 10

    Ciro Acabei criando um tópico na área de Hardware sobre este problema. Para não duplicar segue o link do tópico. Desde já agradeço a atenção.
  4. Tela Azul - Reiniciando W10

    Boa tarde. Ja fiz os procedimentos do tópico Procedimentos para ajuda na identificação de problemas com tela azul e segue abaixo o log. O notebook é o HP14, abaixo imagem com as configurações básicas. Log BluescreenView ================================================== Filename : ntoskrnl.exe Address In Stack : From Address : fffff800`7e08b000 To Address : fffff800`7e95d000 Size : 0x008d2000 Time Stamp : 0x59efff9b Time String : 25/10/2017 01:06:03 Product Name : Microsoft® Windows® Operating System File Description : NT Kernel & System File Version : 10.0.16299.64 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\ntoskrnl.exe ================================================== ================================================== Filename : hal.dll Address In Stack : From Address : fffff800`7e00c000 To Address : fffff800`7e08b000 Size : 0x0007f000 Time Stamp : 0x869c055b Time String : 25/07/2041 11:32:11 Product Name : Microsoft® Windows® Operating System File Description : Hardware Abstraction Layer DLL File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\hal.dll ================================================== ================================================== Filename : kd.dll Address In Stack : From Address : fffff800`7ea00000 To Address : fffff800`7ea0b000 Size : 0x0000b000 Time Stamp : 0xfa8983cb Time String : 14/03/2103 09:49:31 Product Name : Microsoft® Windows® Operating System File Description : Local Kernel Debugger File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\kd.dll ================================================== ================================================== Filename : mcupdate_GenuineIntel.dll Address In Stack : From Address : fffff800`30910000 To Address : fffff800`30a07000 Size : 0x000f7000 Time Stamp : 0x04488d19 Time String : Product Name : Microsoft® Windows® Operating System File Description : Intel Microcode Update Library File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\mcupdate_GenuineIntel.dll ================================================== ================================================== Filename : msrpc.sys Address In Stack : From Address : fffff800`30a10000 To Address : fffff800`30a71000 Size : 0x00061000 Time Stamp : 0x687ce037 Time String : 20/07/2025 10:25:27 Product Name : Microsoft® Windows® Operating System File Description : Kernel Remote Procedure Call Provider File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\msrpc.sys ================================================== ================================================== Filename : ksecdd.sys Address In Stack : From Address : fffff800`30a80000 To Address : fffff800`30aa9000 Size : 0x00029000 Time Stamp : 0x9a56383f Time String : 20/01/2052 03:35:59 Product Name : Microsoft® Windows® Operating System File Description : Kernel Security Support Provider Interface File Version : 10.0.16299.19 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ksecdd.sys ================================================== ================================================== Filename : werkernel.sys Address In Stack : From Address : fffff800`30ab0000 To Address : fffff800`30ac1000 Size : 0x00011000 Time Stamp : 0x623ce798 Time String : 24/03/2022 19:50:16 Product Name : Microsoft® Windows® Operating System File Description : Windows Error Reporting Kernel Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\werkernel.sys ================================================== ================================================== Filename : CLFS.SYS Address In Stack : From Address : fffff800`30ad0000 To Address : fffff800`30b32000 Size : 0x00062000 Time Stamp : 0xa160bbbb Time String : 18/10/2055 09:21:31 Product Name : Microsoft® Windows® Operating System File Description : Common Log File System Driver File Version : 10.0.16299.19 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\CLFS.SYS ================================================== ================================================== Filename : tm.sys Address In Stack : From Address : fffff800`30b40000 To Address : fffff800`30b64000 Size : 0x00024000 Time Stamp : 0x50fbcec0 Time String : 20/01/2013 09:02:24 Product Name : Microsoft® Windows® Operating System File Description : Kernel Transaction Manager Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\tm.sys ================================================== ================================================== Filename : PSHED.dll Address In Stack : From Address : fffff800`30b70000 To Address : fffff800`30b87000 Size : 0x00017000 Time Stamp : 0xfe1a7c40 Time String : 03/02/2105 21:56:48 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Erro de Hardware Específico da Plataforma File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\PSHED.dll ================================================== ================================================== Filename : BOOTVID.dll Address In Stack : From Address : fffff800`30b90000 To Address : fffff800`30b9b000 Size : 0x0000b000 Time Stamp : 0x2fb571ea Time String : 14/05/1995 00:58:50 Product Name : Microsoft® Windows® Operating System File Description : VGA Boot Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\BOOTVID.dll ================================================== ================================================== Filename : FLTMGR.SYS Address In Stack : From Address : fffff800`2fc00000 To Address : fffff800`2fc68000 Size : 0x00068000 Time Stamp : 0x7ad26c51 Time String : 19/04/2035 13:50:41 Product Name : Sistema Operacional Microsoft® Windows® File Description : Gerenciador de Filtro do Filesystem Microsoft File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\FLTMGR.SYS ================================================== ================================================== Filename : clipsp.sys Address In Stack : From Address : fffff800`2fc70000 To Address : fffff800`2fd71000 Size : 0x00101000 Time Stamp : 0x59cda999 Time String : 29/09/2017 00:02:01 Product Name : Microsoft® Windows® Operating System File Description : CLIP Service File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\clipsp.sys ================================================== ================================================== Filename : cmimcext.sys Address In Stack : From Address : fffff800`2fd80000 To Address : fffff800`2fd8e000 Size : 0x0000e000 Time Stamp : 0xd4eadf74 Time String : 13/03/2083 09:20:20 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Exportação do Host da Extensão de Configuração Inicial do Gerenciador de Configurações do Kernel File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\cmimcext.sys ================================================== ================================================== Filename : ntosext.sys Address In Stack : From Address : fffff800`2fd90000 To Address : fffff800`2fd9c000 Size : 0x0000c000 Time Stamp : 0x1b6da4c4 Time String : Product Name : Microsoft® Windows® Operating System File Description : NTOS extension host driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ntosext.sys ================================================== ================================================== Filename : CI.dll Address In Stack : From Address : fffff800`2fda0000 To Address : fffff800`2fe52000 Size : 0x000b2000 Time Stamp : 0xf4192337 Time String : 10/10/2099 02:01:59 Product Name : Microsoft® Windows® Operating System File Description : Code Integrity Module File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\CI.dll ================================================== ================================================== Filename : cng.sys Address In Stack : From Address : fffff800`2fe60000 To Address : fffff800`2ff0a000 Size : 0x000aa000 Time Stamp : 0x5b765f04 Time String : 17/08/2018 03:37:08 Product Name : Microsoft® Windows® Operating System File Description : Kernel Cryptography, Next Generation File Version : 10.0.16299.19 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\cng.sys ================================================== ================================================== Filename : Wdf01000.sys Address In Stack : From Address : fffff800`2ff10000 To Address : fffff800`2fff3000 Size : 0x000e3000 Time Stamp : 0xb77a3803 Time String : 18/07/2067 16:44:19 Product Name : Sistema Operacional Microsoft® Windows® File Description : Tempo de Execução da Estrutura de Driver em Modo Kernel File Version : 1.23.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Wdf01000.sys ================================================== ================================================== Filename : WDFLDR.SYS Address In Stack : From Address : fffff800`30000000 To Address : fffff800`30013000 Size : 0x00013000 Time Stamp : 0xb5732650 Time String : 19/06/2066 23:22:24 Product Name : Microsoft® Windows® Operating System File Description : Kernel Mode Driver Framework Loader File Version : 1.23.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\WDFLDR.SYS ================================================== ================================================== Filename : WppRecorder.sys Address In Stack : From Address : fffff800`30020000 To Address : fffff800`3002e000 Size : 0x0000e000 Time Stamp : 0xa67a2b71 Time String : 04/07/2058 14:06:09 Product Name : Microsoft® Windows® Operating System File Description : WPP Trace Recorder File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\WppRecorder.sys ================================================== ================================================== Filename : SleepStudyHelper.sys Address In Stack : From Address : fffff800`30030000 To Address : fffff800`3003f000 Size : 0x0000f000 Time Stamp : 0xa0e1b647 Time String : 14/07/2055 01:00:23 Product Name : Microsoft® Windows® Operating System File Description : Sleep Study Helper File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\SleepStudyHelper.sys ================================================== ================================================== Filename : acpiex.sys Address In Stack : From Address : fffff800`30040000 To Address : fffff800`30063000 Size : 0x00023000 Time Stamp : 0x8f81b543 Time String : 18/04/2046 03:33:55 Product Name : Microsoft® Windows® Operating System File Description : ACPIEx Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\acpiex.sys ================================================== ================================================== Filename : ACPI.sys Address In Stack : From Address : fffff800`30070000 To Address : fffff800`30129000 Size : 0x000b9000 Time Stamp : 0xf288db9e Time String : 10/12/2098 11:09:50 Product Name : Sistema Operacional Microsoft® Windows® File Description : ACPI Driver for NT File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ACPI.sys ================================================== ================================================== Filename : WMILIB.SYS Address In Stack : From Address : fffff800`30130000 To Address : fffff800`3013c000 Size : 0x0000c000 Time Stamp : 0xfd702a37 Time String : 27/09/2104 17:21:27 Product Name : Microsoft® Windows® Operating System File Description : WMILIB WMI support library Dll File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\WMILIB.SYS ================================================== ================================================== Filename : intelpep.sys Address In Stack : From Address : fffff800`30150000 To Address : fffff800`30175000 Size : 0x00025000 Time Stamp : 0xeb730b5b Time String : 05/03/2095 15:41:47 Product Name : Microsoft® Windows® Operating System File Description : Intel Power Engine Plugin File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\intelpep.sys ================================================== ================================================== Filename : WindowsTrustedRT.sys Address In Stack : From Address : fffff800`30180000 To Address : fffff800`30196000 Size : 0x00016000 Time Stamp : 0x61748520 Time String : 23/10/2021 19:56:48 Product Name : Microsoft® Windows® Operating System File Description : Windows Trusted Runtime Interface Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\WindowsTrustedRT.sys ================================================== ================================================== Filename : WindowsTrustedRTProxy.sys Address In Stack : From Address : fffff800`301a0000 To Address : fffff800`301ab000 Size : 0x0000b000 Time Stamp : 0xc6109ce2 Time String : 20/04/2075 07:18:26 Product Name : Microsoft® Windows® Operating System File Description : Windows Trusted Runtime Service Proxy Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\WindowsTrustedRTProxy.sys ================================================== ================================================== Filename : pcw.sys Address In Stack : From Address : fffff800`301b0000 To Address : fffff800`301c4000 Size : 0x00014000 Time Stamp : 0xb45241a0 Time String : 12/11/2065 20:13:52 Product Name : Microsoft® Windows® Operating System File Description : Performance Counters for Windows Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\pcw.sys ================================================== ================================================== Filename : klupd_klif_arkmon.sys Address In Stack : From Address : fffff800`301d0000 To Address : fffff800`30209000 Size : 0x00039000 Time Stamp : 0x59ee05f5 Time String : 23/10/2017 13:08:37 Product Name : Kaspersky Anti-Virus File Description : Kaspersky Lab Anti-Rootkit Monitor File Version : 1.13.5.0 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klupd_klif_arkmon.sys ================================================== ================================================== Filename : msisadrv.sys Address In Stack : From Address : fffff800`30210000 To Address : fffff800`3021b000 Size : 0x0000b000 Time Stamp : 0x2b3273bc Time String : 18/12/1992 22:58:36 Product Name : Microsoft® Windows® Operating System File Description : ISA Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\msisadrv.sys ================================================== ================================================== Filename : pci.sys Address In Stack : From Address : fffff800`30220000 To Address : fffff800`3027d000 Size : 0x0005d000 Time Stamp : 0xf05d50d8 Time String : 15/10/2097 01:49:44 Product Name : Sistema Operacional Microsoft® Windows® File Description : Enumerador NT Plug and Play PCI File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\pci.sys ================================================== ================================================== Filename : vdrvroot.sys Address In Stack : From Address : fffff800`30280000 To Address : fffff800`30292000 Size : 0x00012000 Time Stamp : 0x53abaac2 Time String : 26/06/2014 03:08:18 Product Name : Microsoft® Windows® Operating System File Description : Virtual Drive Root Enumerator File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\vdrvroot.sys ================================================== ================================================== Filename : cm_km.sys Address In Stack : From Address : fffff800`302a0000 To Address : fffff800`302d9000 Size : 0x00039000 Time Stamp : 0x585249b4 Time String : 15/12/2016 05:43:48 Product Name : Crypto PDK File Description : Cryptographic Module Driver x64 (56 bit) File Version : 4.1.28.0 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\cm_km.sys ================================================== ================================================== Filename : pdc.sys Address In Stack : From Address : fffff800`302e0000 To Address : fffff800`30305000 Size : 0x00025000 Time Stamp : 0x4003a619 Time String : 13/01/2004 06:02:33 Product Name : Microsoft® Windows® Operating System File Description : Power Dependency Coordinator Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\pdc.sys ================================================== ================================================== Filename : CEA.sys Address In Stack : From Address : fffff800`30310000 To Address : fffff800`30329000 Size : 0x00019000 Time Stamp : 0xce9b9dfb Time String : 04/11/2079 04:30:19 Product Name : Microsoft® Windows® Operating System File Description : Event Aggregation Kernel Mode Library File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\CEA.sys ================================================== ================================================== Filename : partmgr.sys Address In Stack : From Address : fffff800`30330000 To Address : fffff800`3035d000 Size : 0x0002d000 Time Stamp : 0x0902ae71 Time String : Product Name : Microsoft® Windows® Operating System File Description : Partition driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\partmgr.sys ================================================== ================================================== Filename : spaceport.sys Address In Stack : From Address : fffff800`30360000 To Address : fffff800`303f0000 Size : 0x00090000 Time Stamp : 0x5f19e50c Time String : 23/07/2020 17:29:16 Product Name : Microsoft® Windows® Operating System File Description : Storage Spaces Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\spaceport.sys ================================================== ================================================== Filename : volmgr.sys Address In Stack : From Address : fffff800`303f0000 To Address : fffff800`30409000 Size : 0x00019000 Time Stamp : 0xb0634e71 Time String : 11/10/2063 01:16:01 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Gerenciador de Volumes File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\volmgr.sys ================================================== ================================================== Filename : volmgrx.sys Address In Stack : From Address : fffff800`30410000 To Address : fffff800`3046e000 Size : 0x0005e000 Time Stamp : 0xbd8710a6 Time String : 05/10/2070 12:37:26 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Extensão do Gerenciador de Volumes File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\volmgrx.sys ================================================== ================================================== Filename : klbackupdisk.sys Address In Stack : From Address : fffff800`30470000 To Address : fffff800`3047f000 Size : 0x0000f000 Time Stamp : 0x59ce1f48 Time String : 29/09/2017 08:24:08 Product Name : System Interceptors PDK File Description : Backup Disk Filter [fre_wnet_x64] File Version : 14.0.0.6 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klbackupdisk.sys ================================================== ================================================== Filename : mountmgr.sys Address In Stack : From Address : fffff800`30480000 To Address : fffff800`3049e000 Size : 0x0001e000 Time Stamp : 0xada090fe Time String : 22/04/2062 23:27:26 Product Name : Sistema Operacional Microsoft® Windows® File Description : Gerenciador de Pontos de Montagem File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mountmgr.sys ================================================== ================================================== Filename : iaStorA.sys Address In Stack : From Address : fffff800`304a0000 To Address : fffff800`3075a000 Size : 0x002ba000 Time Stamp : 0x520e5fb9 Time String : 16/08/2013 15:22:01 Product Name : Intel Rapid Storage Technology driver File Description : Intel Rapid Storage Technology driver - x64 File Version : 12.8.1.1000 Company : Intel Corporation Full Path : C:\Windows\system32\drivers\iaStorA.sys ================================================== ================================================== Filename : storport.sys Address In Stack : From Address : fffff800`30760000 To Address : fffff800`307ee000 Size : 0x0008e000 Time Stamp : 0xd70f552a Time String : 02/05/2084 09:44:42 Product Name : Microsoft® Windows® Operating System File Description : Microsoft Storage Port Driver File Version : 10.0.16299.64 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\storport.sys ================================================== ================================================== Filename : fileinfo.sys Address In Stack : From Address : fffff800`30810000 To Address : fffff800`3082a000 Size : 0x0001a000 Time Stamp : 0x19c04773 Time String : Product Name : Microsoft® Windows® Operating System File Description : FileInfo Filter Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\fileinfo.sys ================================================== ================================================== Filename : Wof.sys Address In Stack : From Address : fffff800`30830000 To Address : fffff800`3086b000 Size : 0x0003b000 Time Stamp : 0xf9d43cdf Time String : 27/10/2102 21:46:39 Product Name : Sistema Operacional Microsoft® Windows® File Description : Filtro de sobreposição do Windows File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Wof.sys ================================================== ================================================== Filename : NTFS.sys Address In Stack : From Address : fffff800`314d0000 To Address : fffff800`31726000 Size : 0x00256000 Time Stamp : 0xdc11487c Time String : 30/12/2086 18:56:28 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver do Sistema de Arquivos NT File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\NTFS.sys ================================================== ================================================== Filename : Fs_Rec.sys Address In Stack : From Address : fffff800`31730000 To Address : fffff800`3173d000 Size : 0x0000d000 Time Stamp : 0x00000000 Time String : Product Name : Microsoft® Windows® Operating System File Description : File System Recognizer Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Fs_Rec.sys ================================================== ================================================== Filename : ndis.sys Address In Stack : From Address : fffff800`30c00000 To Address : fffff800`30d3f000 Size : 0x0013f000 Time Stamp : 0xaf6c5053 Time String : 06/04/2063 16:54:11 Product Name : Sistema Operacional Microsoft® Windows® File Description : NDIS (Especificação de Interface de Driver de Rede) File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ndis.sys ================================================== ================================================== Filename : NETIO.SYS Address In Stack : From Address : fffff800`30d40000 To Address : fffff800`30dc8000 Size : 0x00088000 Time Stamp : 0x302c3e5d Time String : 12/08/1995 03:38:37 Product Name : Microsoft® Windows® Operating System File Description : Network I/O Subsystem File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\NETIO.SYS ================================================== ================================================== Filename : ksecpkg.sys Address In Stack : From Address : fffff800`30dd0000 To Address : fffff800`30e00000 Size : 0x00030000 Time Stamp : 0xa2d0764a Time String : 23/07/2056 07:39:22 Product Name : Microsoft® Windows® Operating System File Description : Kernel Security Support Provider Interface Packages File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ksecpkg.sys ================================================== ================================================== Filename : tcpip.sys Address In Stack : From Address : fffff800`30e00000 To Address : fffff800`310b2000 Size : 0x002b2000 Time Stamp : 0xc818c3b3 Time String : 18/05/2076 20:22:43 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver TCP/IP File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\tcpip.sys ================================================== ================================================== Filename : fwpkclnt.sys Address In Stack : From Address : fffff800`310c0000 To Address : fffff800`31131000 Size : 0x00071000 Time Stamp : 0xcaec7f62 Time String : 18/11/2077 19:32:18 Product Name : Microsoft® Windows® Operating System File Description : FWP/IPsec Kernel-Mode API File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\fwpkclnt.sys ================================================== ================================================== Filename : wfplwfs.sys Address In Stack : From Address : fffff800`31140000 To Address : fffff800`3116c000 Size : 0x0002c000 Time Stamp : 0xe5844f93 Time String : 08/01/2092 15:59:47 Product Name : Microsoft® Windows® Operating System File Description : WFP NDIS 6.30 Lightweight Filter Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\wfplwfs.sys ================================================== ================================================== Filename : fvevol.sys Address In Stack : From Address : fffff800`31170000 To Address : fffff800`31228000 Size : 0x000b8000 Time Stamp : 0x2493bbe7 Time String : 12/06/1989 11:34:31 Product Name : Microsoft® Windows® Operating System File Description : BitLocker Drive Encryption Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\fvevol.sys ================================================== ================================================== Filename : volume.sys Address In Stack : From Address : fffff800`31230000 To Address : fffff800`3123b000 Size : 0x0000b000 Time Stamp : 0x1c3359ec Time String : Product Name : Microsoft® Windows® Operating System File Description : Volume driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\volume.sys ================================================== ================================================== Filename : volsnap.sys Address In Stack : From Address : fffff800`31240000 To Address : fffff800`312a6000 Size : 0x00066000 Time Stamp : 0xc10d9ca3 Time String : 20/08/2072 02:59:15 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Cópia de Sombra de Volume File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\volsnap.sys ================================================== ================================================== Filename : rdyboost.sys Address In Stack : From Address : fffff800`312b0000 To Address : fffff800`312fc000 Size : 0x0004c000 Time Stamp : 0x32e813ee Time String : 23/01/1997 23:44:14 Product Name : Microsoft® Windows® Operating System File Description : ReadyBoost Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\rdyboost.sys ================================================== ================================================== Filename : mup.sys Address In Stack : From Address : fffff800`31300000 To Address : fffff800`31324000 Size : 0x00024000 Time Stamp : 0x454d52cc Time String : 05/11/2006 00:56:12 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Provedor UNC Múltiplo File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mup.sys ================================================== ================================================== Filename : klupd_klif_klbg.sys Address In Stack : From Address : fffff800`31330000 To Address : fffff800`3134a000 Size : 0x0001a000 Time Stamp : 0x59ee01bc Time String : 23/10/2017 12:50:36 Product Name : Kaspersky Anti-Virus File Description : Kaspersky Lab Boot Guard Driver File Version : 10.7.6.0 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klupd_klif_klbg.sys ================================================== ================================================== Filename : kl1.sys Address In Stack : From Address : fffff800`320e0000 To Address : fffff800`327e9000 Size : 0x00709000 Time Stamp : 0x56fe83ac Time String : 01/04/2016 12:20:28 Product Name : Kaspersky Anti-Virus File Description : Kaspersky Unified Driver File Version : 6.8.0.67 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\kl1.sys ================================================== ================================================== Filename : iorate.sys Address In Stack : From Address : fffff800`31800000 To Address : fffff800`31811000 Size : 0x00011000 Time Stamp : 0x6f697c3c Time String : 25/03/2029 23:47:40 Product Name : Sistema Operacional Microsoft® Windows® File Description : Filtro de controle de taxa de E/S File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\iorate.sys ================================================== ================================================== Filename : disk.sys Address In Stack : From Address : fffff800`31830000 To Address : fffff800`3184c000 Size : 0x0001c000 Time Stamp : 0x490a737c Time String : 31/10/2008 00:54:52 Product Name : Microsoft® Windows® Operating System File Description : PnP Disk Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\disk.sys ================================================== ================================================== Filename : CLASSPNP.SYS Address In Stack : From Address : fffff800`31850000 To Address : fffff800`318b8000 Size : 0x00068000 Time Stamp : 0xbf85bfae Time String : 27/10/2071 21:20:14 Product Name : Microsoft® Windows® Operating System File Description : SCSI Class System Dll File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\CLASSPNP.SYS ================================================== ================================================== Filename : crashdmp.sys Address In Stack : From Address : fffff800`318e0000 To Address : fffff800`318fb000 Size : 0x0001b000 Time Stamp : 0x8dc80a7c Time String : 18/05/2045 03:15:40 Product Name : Microsoft® Windows® Operating System File Description : Crash Dump Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\crashdmp.sys ================================================== ================================================== Filename : klhk.sys Address In Stack : From Address : fffff800`31ee0000 To Address : fffff800`31fa0000 Size : 0x000c0000 Time Stamp : 0x59cf6b7d Time String : 30/09/2017 08:01:33 Product Name : System Interceptors PDK File Description : klhk [fre_win8_x64] File Version : 13.0.136.62 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klhk.sys ================================================== ================================================== Filename : cdrom.sys Address In Stack : From Address : fffff800`31fa0000 To Address : fffff800`31fce000 Size : 0x0002e000 Time Stamp : 0x1424f070 Time String : Product Name : Microsoft® Windows® Operating System File Description : SCSI CD-ROM Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\cdrom.sys ================================================== ================================================== Filename : klbackupflt.sys Address In Stack : From Address : fffff800`31fd0000 To Address : fffff800`31fe4000 Size : 0x00014000 Time Stamp : 0x59c408af Time String : 21/09/2017 16:45:03 Product Name : System Interceptors PDK File Description : Backup File Filter [fre_win8_x64] File Version : 14.0.0.17 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klbackupflt.sys ================================================== ================================================== Filename : klflt.sys Address In Stack : From Address : fffff800`31ff0000 To Address : fffff800`32030000 Size : 0x00040000 Time Stamp : 0x596f49fa Time String : 19/07/2017 10:00:58 Product Name : System Interceptors PDK File Description : Filter Core [fre_win8_x64] File Version : 13.0.56.0 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klflt.sys ================================================== ================================================== Filename : filecrypt.sys Address In Stack : From Address : fffff800`32030000 To Address : fffff800`32044000 Size : 0x00014000 Time Stamp : 0x518a49bf Time String : 08/05/2013 10:49:03 Product Name : Microsoft® Windows® Operating System File Description : Windows sandboxing and encryption filter File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\filecrypt.sys ================================================== ================================================== Filename : tbs.sys Address In Stack : From Address : fffff800`32050000 To Address : fffff800`3205d000 Size : 0x0000d000 Time Stamp : 0x237a7c1d Time String : 11/11/1988 03:35:25 Product Name : Microsoft® Windows® Operating System File Description : Export driver for kernel mode TPM API File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\tbs.sys ================================================== ================================================== Filename : klif.sys Address In Stack : From Address : fffff800`31350000 To Address : fffff800`31457000 Size : 0x00107000 Time Stamp : 0x59cf6ca2 Time String : 30/09/2017 08:06:26 Product Name : System Interceptors PDK File Description : Core System Interceptors [fre_win8_x64] File Version : 13.0.340.0 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klif.sys ================================================== ================================================== Filename : ks.sys Address In Stack : From Address : fffff800`32060000 To Address : fffff800`320c8000 Size : 0x00068000 Time Stamp : 0xc5b6b465 Time String : 11/02/2075 02:34:45 Product Name : Microsoft® Windows® Operating System File Description : Kernel CSA Library File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ks.sys ================================================== ================================================== Filename : klpd.sys Address In Stack : From Address : fffff800`320d0000 To Address : fffff800`320db000 Size : 0x0000b000 Time Stamp : 0x58d522be Time String : 24/03/2017 11:44:30 Product Name : System Interceptors PDK File Description : Format Recognizer [fre_wnet_x64] File Version : 13.0.0.9 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klpd.sys ================================================== ================================================== Filename : Null.SYS Address In Stack : From Address : fffff800`327f0000 To Address : fffff800`327fa000 Size : 0x0000a000 Time Stamp : 0x00000000 Time String : Product Name : Microsoft® Windows® Operating System File Description : NULL Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Null.SYS ================================================== ================================================== Filename : Beep.SYS Address In Stack : From Address : fffff800`31820000 To Address : fffff800`3182a000 Size : 0x0000a000 Time Stamp : 0x85f9535b Time String : 24/03/2041 01:45:31 Product Name : Microsoft® Windows® Operating System File Description : BEEP Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Beep.SYS ================================================== ================================================== Filename : BasicDisplay.sys Address In Stack : From Address : fffff800`31460000 To Address : fffff800`31475000 Size : 0x00015000 Time Stamp : 0xd192c744 Time String : 02/06/2081 00:36:52 Product Name : Microsoft® Windows® Operating System File Description : Microsoft Basic Display Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\BasicDisplay.sys ================================================== ================================================== Filename : watchdog.sys Address In Stack : From Address : fffff800`31480000 To Address : fffff800`31494000 Size : 0x00014000 Time Stamp : 0xee73d2b8 Time String : 08/10/2096 18:53:12 Product Name : Microsoft® Windows® Operating System File Description : Watchdog Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\watchdog.sys ================================================== ================================================== Filename : dxgkrnl.sys Address In Stack : From Address : fffff800`33aa0000 To Address : fffff800`33d19000 Size : 0x00279000 Time Stamp : 0xaed43450 Time String : 12/12/2062 07:50:08 Product Name : Microsoft® Windows® Operating System File Description : DirectX Graphics Kernel File Version : 10.0.16299.64 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\dxgkrnl.sys ================================================== ================================================== Filename : vmbkmclr.sys Address In Stack : From Address : fffff800`33d20000 To Address : fffff800`33d3a000 Size : 0x0001a000 Time Stamp : 0x3fdefdb5 Time String : 16/12/2003 10:42:29 Product Name : Microsoft® Windows® Operating System File Description : Hyper-V VMBus Root KMCL File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\vmbkmclr.sys ================================================== ================================================== Filename : BasicRender.sys Address In Stack : From Address : fffff800`33d40000 To Address : fffff800`33d50000 Size : 0x00010000 Time Stamp : 0x6e438d32 Time String : 15/08/2028 00:53:38 Product Name : Microsoft® Windows® Operating System File Description : Microsoft Basic Render Driver File Version : 10.0.16299.19 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\BasicRender.sys ================================================== ================================================== Filename : Npfs.SYS Address In Stack : From Address : fffff800`33d50000 To Address : fffff800`33d6b000 Size : 0x0001b000 Time Stamp : 0x1a9900ef Time String : Product Name : Microsoft® Windows® Operating System File Description : NPFS Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Npfs.SYS ================================================== ================================================== Filename : Msfs.SYS Address In Stack : From Address : fffff800`33d70000 To Address : fffff800`33d80000 Size : 0x00010000 Time Stamp : 0xb74d7d9a Time String : 14/06/2067 18:29:14 Product Name : Microsoft® Windows® Operating System File Description : Mailslot driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Msfs.SYS ================================================== ================================================== Filename : gbpddfac64.sys Address In Stack : From Address : fffff800`33d80000 To Address : fffff800`33d8c000 Size : 0x0000c000 Time Stamp : 0x551064ae Time String : 23/03/2015 17:08:30 Product Name : gbpddfac File Description : GAS Tecnologia - FAC File Version : 1,0,0,2 Company : GAS Tecnologia Full Path : C:\Windows\system32\drivers\gbpddfac64.sys ================================================== ================================================== Filename : klwfp.sys Address In Stack : From Address : fffff800`33d90000 To Address : fffff800`33da6000 Size : 0x00016000 Time Stamp : 0x583d5922 Time String : 29/11/2016 08:32:02 Product Name : System Interceptors PDK File Description : WFP Network Filter [fre_win8_x64] File Version : 13.0.0.19 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klwfp.sys ================================================== ================================================== Filename : tdx.sys Address In Stack : From Address : fffff800`33db0000 To Address : fffff800`33dd3000 Size : 0x00023000 Time Stamp : 0x0cbc8cf3 Time String : Product Name : Microsoft® Windows® Operating System File Description : TDI Translation Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\tdx.sys ================================================== ================================================== Filename : TDI.SYS Address In Stack : From Address : fffff800`33de0000 To Address : fffff800`33df0000 Size : 0x00010000 Time Stamp : 0x1bbdca2c Time String : Product Name : Microsoft® Windows® Operating System File Description : TDI Wrapper File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\TDI.SYS ================================================== ================================================== Filename : netbt.sys Address In Stack : From Address : fffff800`32e00000 To Address : fffff800`32e56000 Size : 0x00056000 Time Stamp : 0x39fa0bbd Time String : 27/10/2000 21:11:57 Product Name : Microsoft® Windows® Operating System File Description : MBT Transport driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\netbt.sys ================================================== ================================================== Filename : afd.sys Address In Stack : From Address : fffff800`32e60000 To Address : fffff800`32efb000 Size : 0x0009b000 Time Stamp : 0xae5da66c Time String : 13/09/2062 09:37:16 Product Name : Sistema Operacional Microsoft® Windows® File Description : Ancillary Function Driver for WinSock File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\afd.sys ================================================== ================================================== Filename : klwtp.sys Address In Stack : From Address : fffff800`32f00000 To Address : fffff800`32f20000 Size : 0x00020000 Time Stamp : 0x58d5230e Time String : 24/03/2017 11:45:50 Product Name : System Interceptors PDK File Description : WFP Network Connection Filter Driver [fre_win8_x64] File Version : 13.0.0.33 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klwtp.sys ================================================== ================================================== Filename : klim6.sys Address In Stack : From Address : fffff800`32f20000 To Address : fffff800`32f2c000 Size : 0x0000c000 Time Stamp : 0x57ee6a18 Time String : 30/09/2016 11:35:20 Product Name : System Interceptors PDK File Description : Packet Network Filter [fre_win8_x64] File Version : 13.0.0.8 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klim6.sys ================================================== ================================================== Filename : vwififlt.sys Address In Stack : From Address : fffff800`32f30000 To Address : fffff800`32f4a000 Size : 0x0001a000 Time Stamp : 0xf55574e7 Time String : 07/06/2100 00:26:47 Product Name : Microsoft® Windows® Operating System File Description : Virtual WiFi Filter Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\vwififlt.sys ================================================== ================================================== Filename : pacer.sys Address In Stack : From Address : fffff800`32f50000 To Address : fffff800`32f79000 Size : 0x00029000 Time Stamp : 0x50537457 Time String : 14/09/2012 16:15:51 Product Name : Sistema Operacional Microsoft® Windows® File Description : Agendador de pacotes de serviço File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\pacer.sys ================================================== ================================================== Filename : netbios.sys Address In Stack : From Address : fffff800`32f80000 To Address : fffff800`32f92000 Size : 0x00012000 Time Stamp : 0x1af61494 Time String : Product Name : Microsoft® Windows® Operating System File Description : NetBIOS interface driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\netbios.sys ================================================== ================================================== Filename : rdbss.sys Address In Stack : From Address : fffff800`32fa0000 To Address : fffff800`33014000 Size : 0x00074000 Time Stamp : 0xed45145e Time String : 22/02/2096 03:36:30 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver do Subsistema de Buffer da Unidade Redirecionado File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\rdbss.sys ================================================== ================================================== Filename : nsiproxy.sys Address In Stack : From Address : fffff800`33020000 To Address : fffff800`33032000 Size : 0x00012000 Time Stamp : 0x955a981e Time String : 27/05/2049 13:32:46 Product Name : Microsoft® Windows® Operating System File Description : NSI Proxy File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\nsiproxy.sys ================================================== ================================================== Filename : npsvctrig.sys Address In Stack : From Address : fffff800`33040000 To Address : fffff800`3304d000 Size : 0x0000d000 Time Stamp : 0xbcbd5b64 Time String : 05/05/2070 12:38:28 Product Name : Microsoft® Windows® Operating System File Description : Named pipe service triggers File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\npsvctrig.sys ================================================== ================================================== Filename : mssmbios.sys Address In Stack : From Address : fffff800`33050000 To Address : fffff800`3305f000 Size : 0x0000f000 Time Stamp : 0x34839a22 Time String : 02/12/1997 03:18:26 Product Name : Microsoft® Windows® Operating System File Description : System Management BIOS Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mssmbios.sys ================================================== ================================================== Filename : kneps.sys Address In Stack : From Address : fffff800`33060000 To Address : fffff800`3308d000 Size : 0x0002d000 Time Stamp : 0x5937cd3d Time String : 07/06/2017 07:54:05 Product Name : System Interceptors PDK File Description : Network Processor [fre_wnet_x64] File Version : 13.0.0.35 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\kneps.sys ================================================== ================================================== Filename : gpuenergydrv.sys Address In Stack : From Address : fffff800`330c0000 To Address : fffff800`330ca000 Size : 0x0000a000 Time Stamp : 0x4e8d39d4 Time String : 06/10/2011 03:17:08 Product Name : Microsoft® Windows® Operating System File Description : GPU Energy Kernel Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\gpuenergydrv.sys ================================================== ================================================== Filename : mbae64.sys Address In Stack : From Address : fffff800`330d0000 To Address : fffff800`330de6c0 Size : 0x0000e6c0 Time Stamp : 0x58766670 Time String : 11/01/2017 15:08:00 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : dfsc.sys Address In Stack : From Address : fffff800`330e0000 To Address : fffff800`3310a000 Size : 0x0002a000 Time Stamp : 0x94c5d3e2 Time String : 03/02/2049 17:20:02 Product Name : Microsoft® Windows® Operating System File Description : DFS Namespace Client Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\dfsc.sys ================================================== ================================================== Filename : CLVirtualDrive.sys Address In Stack : From Address : fffff800`33130000 To Address : fffff800`3314a000 Size : 0x0001a000 Time Stamp : 0x5281a118 Time String : 12/11/2013 01:31:36 Product Name : CyberLink Virtual Device Driver File Description : It is a virtual device driver which could create multiple virtual devices and mount image files. File Version : 1.0.0.3512 Company : CyberLink Full Path : C:\Windows\system32\drivers\CLVirtualDrive.sys ================================================== ================================================== Filename : bam.sys Address In Stack : From Address : fffff800`33150000 To Address : fffff800`33164000 Size : 0x00014000 Time Stamp : 0x0cd64a3a Time String : Product Name : Microsoft® Windows® Operating System File Description : BAM Kernel Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\bam.sys ================================================== ================================================== Filename : ahcache.sys Address In Stack : From Address : fffff800`33170000 To Address : fffff800`331b2000 Size : 0x00042000 Time Stamp : 0xd84c012d Time String : 28/12/2084 14:34:53 Product Name : Microsoft® Windows® Operating System File Description : Application Compatibility Cache File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ahcache.sys ================================================== ================================================== Filename : kltap.sys Address In Stack : From Address : fffff800`331c0000 To Address : fffff800`331cc000 Size : 0x0000c000 Time Stamp : 0x573a35dc Time String : 16/05/2016 19:04:28 Product Name : TAP-Windows Virtual Network Driver (NDIS 6.0) File Description : TAP-Windows Virtual Network Driver (NDIS 6.0) File Version : 9.21.1 9/21 built by: WinDDK Company : The OpenVPN Project Full Path : C:\Windows\system32\drivers\kltap.sys ================================================== ================================================== Filename : CompositeBus.sys Address In Stack : From Address : fffff800`331d0000 To Address : fffff800`331e1000 Size : 0x00011000 Time Stamp : 0x3d0fa01a Time String : 18/06/2002 19:03:22 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : kdnic.sys Address In Stack : From Address : fffff800`331f0000 To Address : fffff800`331fd000 Size : 0x0000d000 Time Stamp : 0xe91c9c29 Time String : 06/12/2093 17:31:53 Product Name : Microsoft Kernel Debugger Network Adapter (NDIS 6.20 Miniport) File Description : Microsoft Kernel Debugger Network Miniport File Version : 6.01.00.0000 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\kdnic.sys ================================================== ================================================== Filename : umbus.sys Address In Stack : From Address : fffff800`33200000 To Address : fffff800`33215000 Size : 0x00015000 Time Stamp : 0x6e2974cf Time String : 26/07/2028 05:50:39 Product Name : Microsoft® Windows® Operating System File Description : User-Mode Bus Enumerator File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\umbus.sys ================================================== ================================================== Filename : CAD.sys Address In Stack : From Address : fffff800`33220000 To Address : fffff800`33235000 Size : 0x00015000 Time Stamp : 0xe63e7d90 Time String : 28/05/2092 21:17:36 Product Name : Microsoft® Windows® Operating System File Description : Charge Arbiration Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\CAD.sys ================================================== ================================================== Filename : igdkmd64.sys Address In Stack : From Address : fffff800`33240000 To Address : fffff800`335f8000 Size : 0x003b8000 Time Stamp : 0x5678572a Time String : 21/12/2015 17:46:50 Product Name : Intel HD Graphics Drivers for Windows 8(R) File Description : Intel Graphics Kernel Mode Driver File Version : 10.18.10.4358 Company : Intel Corporation Full Path : C:\Windows\system32\drivers\igdkmd64.sys ================================================== ================================================== Filename : USBXHCI.SYS Address In Stack : From Address : fffff800`33600000 To Address : fffff800`33670000 Size : 0x00070000 Time Stamp : 0xef002eb6 Time String : 23/01/2097 06:03:02 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver USB XHCI File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\USBXHCI.SYS ================================================== ================================================== Filename : ucx01000.sys Address In Stack : From Address : fffff800`33670000 To Address : fffff800`336ac000 Size : 0x0003c000 Time Stamp : 0xa2a8c6ad Time String : 23/06/2056 05:11:41 Product Name : Microsoft® Windows® Operating System File Description : USB Controller Extension File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ucx01000.sys ================================================== ================================================== Filename : TeeDriverx64.sys Address In Stack : From Address : fffff800`336b0000 To Address : fffff800`336cc000 Size : 0x0001c000 Time Stamp : 0x5228c72a Time String : 05/09/2013 16:02:18 Product Name : Intel(R) Management Engine Interface File Description : Intel(R) Management Engine Interface File Version : 9.5.15.1730 Company : Intel Corporation Full Path : C:\Windows\system32\drivers\TeeDriverx64.sys ================================================== ================================================== Filename : usbehci.sys Address In Stack : From Address : fffff800`336d0000 To Address : fffff800`336eb000 Size : 0x0001b000 Time Stamp : 0x69c38152 Time String : 25/03/2026 04:31:46 Product Name : Microsoft® Windows® Operating System File Description : EHCI eUSB Miniport Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\usbehci.sys ================================================== ================================================== Filename : USBPORT.SYS Address In Stack : From Address : fffff800`336f0000 To Address : fffff800`33764000 Size : 0x00074000 Time Stamp : 0xcee28d3d Time String : 27/12/2079 23:49:49 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Porta USB 1.1 e 2.0 File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\USBPORT.SYS ================================================== ================================================== Filename : HDAudBus.sys Address In Stack : From Address : fffff800`33770000 To Address : fffff800`3378d000 Size : 0x0001d000 Time Stamp : 0x186192d8 Time String : Product Name : Microsoft® Windows® Operating System File Description : High Definition Audio Bus Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\HDAudBus.sys ================================================== ================================================== Filename : portcls.sys Address In Stack : From Address : fffff800`33790000 To Address : fffff800`337f3000 Size : 0x00063000 Time Stamp : 0xa7aad0f5 Time String : 20/02/2059 16:01:25 Product Name : Microsoft® Windows® Operating System File Description : Port Class (Class Driver for Port/Miniport Devices) File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\portcls.sys ================================================== ================================================== Filename : drmk.sys Address In Stack : From Address : fffff800`33800000 To Address : fffff800`33821000 Size : 0x00021000 Time Stamp : 0x53353e64 Time String : 28/03/2014 07:18:28 Product Name : Microsoft® Windows® Operating System File Description : Microsoft Trusted Audio Drivers File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\drmk.sys ================================================== ================================================== Filename : Rt630x64.sys Address In Stack : From Address : fffff800`33830000 To Address : fffff800`338fd000 Size : 0x000cd000 Time Stamp : 0x520c73ff Time String : 15/08/2013 04:23:59 Product Name : Realtek 8136/8168/8169 PCI/PCIe Adapters File Description : Realtek 8101E/8168/8169 NDIS 6.30 64-bit Driver File Version : 8.020.0815.2013 Company : Realtek Full Path : C:\Windows\system32\drivers\Rt630x64.sys ================================================== ================================================== Filename : athw8x.sys Address In Stack : From Address : fffff800`34cc0000 To Address : fffff800`350e7000 Size : 0x00427000 Time Stamp : 0x56a9e4f6 Time String : 28/01/2016 07:52:54 Product Name : Driver for Qualcomm Atheros CB42/CB43/MB42/MB43 Network Adapter File Description : Qualcomm Atheros Extensible Wireless LAN device driver File Version : 3.0.2.201 Company : Qualcomm Atheros Communications, Inc. Full Path : C:\Windows\system32\drivers\athw8x.sys ================================================== ================================================== Filename : vwifibus.sys Address In Stack : From Address : fffff800`350f0000 To Address : fffff800`350fe000 Size : 0x0000e000 Time Stamp : 0x2ad49d54 Time String : 08/10/1992 18:43:00 Product Name : Microsoft® Windows® Operating System File Description : Virtual Wireless Bus Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\vwifibus.sys ================================================== ================================================== Filename : CmBatt.sys Address In Stack : From Address : fffff800`35150000 To Address : fffff800`3515e000 Size : 0x0000e000 Time Stamp : 0xce35fd36 Time String : 19/08/2079 02:25:26 Product Name : Microsoft® Windows® Operating System File Description : Control Method Battery Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\CmBatt.sys ================================================== ================================================== Filename : BATTC.SYS Address In Stack : From Address : fffff800`35160000 To Address : fffff800`35170000 Size : 0x00010000 Time Stamp : 0x7d849485 Time String : 24/09/2036 01:46:13 Product Name : Microsoft® Windows® Operating System File Description : Battery Class Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\BATTC.SYS ================================================== ================================================== Filename : i8042prt.sys Address In Stack : From Address : fffff800`35170000 To Address : fffff800`3518f000 Size : 0x0001f000 Time Stamp : 0xa9e87bdf Time String : 30/04/2060 19:19:27 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de porta i8042 File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\i8042prt.sys ================================================== ================================================== Filename : klkbdflt.sys Address In Stack : From Address : fffff800`35190000 To Address : fffff800`3519e000 Size : 0x0000e000 Time Stamp : 0x5859ab5a Time String : 20/12/2016 20:06:18 Product Name : System Interceptors PDK File Description : Keyboard Device Filter [fre_win8_x64] File Version : 13.0.0.8 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klkbdflt.sys ================================================== ================================================== Filename : kbdclass.sys Address In Stack : From Address : fffff800`351a0000 To Address : fffff800`351b3000 Size : 0x00013000 Time Stamp : 0xe1050ca8 Time String : 18/08/2089 09:55:20 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Classe de Teclado File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\kbdclass.sys ================================================== ================================================== Filename : Apfiltr.sys Address In Stack : From Address : fffff800`34400000 To Address : fffff800`3449d000 Size : 0x0009d000 Time Stamp : 0x55a769f2 Time String : 16/07/2015 06:23:14 Product Name : Alps Touch Pad Driver File Description : Alps Touch Pad Driver File Version : 8,1,0,512 built by: WinDDK Company : Alps Electric Co., Ltd. Full Path : C:\Windows\system32\drivers\Apfiltr.sys ================================================== ================================================== Filename : klmouflt.sys Address In Stack : From Address : fffff800`344a0000 To Address : fffff800`344af000 Size : 0x0000f000 Time Stamp : 0x583e86b0 Time String : 30/11/2016 05:58:40 Product Name : System Interceptors PDK File Description : Mouse Device Filter [fre_win8_x64] File Version : 13.0.0.5 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klmouflt.sys ================================================== ================================================== Filename : mouclass.sys Address In Stack : From Address : fffff800`344b0000 To Address : fffff800`344c2000 Size : 0x00012000 Time Stamp : 0x92a73cab Time String : 20/12/2047 03:46:19 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de classe modem File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mouclass.sys ================================================== ================================================== Filename : GEARAspiWDM.sys Address In Stack : From Address : fffff800`344d0000 To Address : fffff800`344d6c00 Size : 0x00006c00 Time Stamp : 0x4fa2e2e1 Time String : 03/05/2012 17:56:17 Product Name : CD DVD Filter File Description : CD DVD Filter File Version : 2.02.03.00 Company : GEAR Software Inc. Full Path : C:\Windows\system32\drivers\GEARAspiWDM.sys ================================================== ================================================== Filename : WirelessButtonDriver64.sys Address In Stack : From Address : fffff800`344e0000 To Address : fffff800`344eb000 Size : 0x0000b000 Time Stamp : 0x5948de91 Time String : 20/06/2017 06:36:33 Product Name : HP Wireless Button Driver File Description : HP Wireless Button Driver File Version : 1.1.20.1 Company : HP Full Path : C:\Windows\system32\drivers\WirelessButtonDriver64.sys ================================================== ================================================== Filename : HIDCLASS.SYS Address In Stack : From Address : fffff800`344f0000 To Address : fffff800`34525000 Size : 0x00035000 Time Stamp : 0xa4b57241 Time String : 26/07/2057 04:31:29 Product Name : Sistema Operacional Microsoft® Windows® File Description : Biblioteca de Classes Hid File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\HIDCLASS.SYS ================================================== ================================================== Filename : HIDPARSE.SYS Address In Stack : From Address : fffff800`34530000 To Address : fffff800`34543000 Size : 0x00013000 Time Stamp : 0x3b5ca86c Time String : 23/07/2001 20:42:52 Product Name : Microsoft® Windows® Operating System File Description : Hid Parsing Library File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\HIDPARSE.SYS ================================================== ================================================== Filename : intelppm.sys Address In Stack : From Address : fffff800`34550000 To Address : fffff800`3458c000 Size : 0x0003c000 Time Stamp : 0x4e7b113f Time String : 22/09/2011 08:43:11 Product Name : Microsoft® Windows® Operating System File Description : Processor Device Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\intelppm.sys ================================================== ================================================== Filename : wmiacpi.sys Address In Stack : From Address : fffff800`34590000 To Address : fffff800`3459c000 Size : 0x0000c000 Time Stamp : 0xde409228 Time String : 28/02/2088 00:27:52 Product Name : Microsoft® Windows® Operating System File Description : Windows Management Interface for ACPI File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\wmiacpi.sys ================================================== ================================================== Filename : NdisVirtualBus.sys Address In Stack : From Address : fffff800`345a0000 To Address : fffff800`345ad000 Size : 0x0000d000 Time Stamp : 0x74d36d6e Time String : 10/02/2032 06:06:06 Product Name : Sistema Operacional Microsoft® Windows® File Description : Enumerador de Adaptador de Rede Virtual Microsoft File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\NdisVirtualBus.sys ================================================== ================================================== Filename : swenum.sys Address In Stack : From Address : fffff800`345b0000 To Address : fffff800`345bc000 Size : 0x0000c000 Time Stamp : 0x3c18d717 Time String : 13/12/2001 14:28:07 Product Name : Microsoft® Windows® Operating System File Description : Plug and Play Software Device Enumerator File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\swenum.sys ================================================== ================================================== Filename : iwdbus.sys Address In Stack : From Address : fffff800`345c0000 To Address : fffff800`345cc000 Size : 0x0000c000 Time Stamp : 0x564e5d46 Time String : 19/11/2015 21:37:42 Product Name : Intel® WiDi Solution File Description : Intel® WiDi Solution File Version : 4.5.71.0 built by: WinDDK Company : Intel Corporation Full Path : C:\Windows\system32\drivers\iwdbus.sys ================================================== ================================================== Filename : rdpbus.sys Address In Stack : From Address : fffff800`345d0000 To Address : fffff800`345de000 Size : 0x0000e000 Time Stamp : 0xbf7d986c Time String : 21/10/2071 16:54:36 Product Name : Microsoft® Windows® Operating System File Description : Microsoft RDP Bus Device driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\rdpbus.sys ================================================== ================================================== Filename : clwvd.sys Address In Stack : From Address : fffff800`345e0000 To Address : fffff800`345ed000 Size : 0x0000d000 Time Stamp : 0x52e72aec Time String : 28/01/2014 01:58:36 Product Name : CyberLink WebCam Virtual Driver File Description : CyberLink WebCam Virtual Driver File Version : 1.0.27893.6128 Company : CyberLink Corporation Full Path : C:\Windows\system32\drivers\clwvd.sys ================================================== ================================================== Filename : ksthunk.sys Address In Stack : From Address : fffff800`345f0000 To Address : fffff800`345ff000 Size : 0x0000f000 Time Stamp : 0x3e950951 Time String : 10/04/2003 04:04:01 Product Name : Microsoft® Windows® Operating System File Description : Kernel Streaming WOW Thunk Service File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ksthunk.sys ================================================== ================================================== Filename : usbhub.sys Address In Stack : From Address : fffff800`34610000 To Address : fffff800`34693000 Size : 0x00083000 Time Stamp : 0xaed85696 Time String : 15/12/2062 11:05:26 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Hub Padrão para USB File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\usbhub.sys ================================================== ================================================== Filename : USBD.SYS Address In Stack : From Address : fffff800`346a0000 To Address : fffff800`346ae000 Size : 0x0000e000 Time Stamp : 0x638fcb99 Time String : 06/12/2022 21:09:13 Product Name : Microsoft® Windows® Operating System File Description : Universal Serial Bus Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\USBD.SYS ================================================== ================================================== Filename : UsbHub3.sys Address In Stack : From Address : fffff800`346b0000 To Address : fffff800`3473c000 Size : 0x0008c000 Time Stamp : 0xa50fd5f3 Time String : 02/10/2057 18:00:51 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de HUB USB3 File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\UsbHub3.sys ================================================== ================================================== Filename : RTKVHD64.sys Address In Stack : From Address : fffff800`34740000 To Address : fffff800`34bc5000 Size : 0x00485000 Time Stamp : 0x55929a9d Time String : 30/06/2015 11:33:17 Product Name : Realtek(r) High Definition Audio Function Driver File Description : Realtek(r) High Definition Audio Function Driver File Version : 6.0.1.7548 built by: WinDDK Company : Realtek Semiconductor Corp. Full Path : C:\Windows\system32\drivers\RTKVHD64.sys ================================================== ================================================== Filename : IntcDAud.sys Address In Stack : From Address : fffff800`34be0000 To Address : fffff800`34c53000 Size : 0x00073000 Time Stamp : 0x540eeecd Time String : 09/09/2014 10:13:01 Product Name : Intel(R) Display Audio File Description : Intel(R) Display Audio Driver File Version : 6.16.00.3154 Company : Intel(R) Corporation Full Path : C:\Windows\system32\drivers\IntcDAud.sys ================================================== ================================================== Filename : usbccgp.sys Address In Stack : From Address : fffff800`34c70000 To Address : fffff800`34c9f000 Size : 0x0002f000 Time Stamp : 0xd5e154c6 Time String : 16/09/2083 07:58:30 Product Name : Microsoft® Windows® Operating System File Description : USB Common Class Generic Parent Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\usbccgp.sys ================================================== ================================================== Filename : hidusb.sys Address In Stack : From Address : fffff800`34ca0000 To Address : fffff800`34cb2000 Size : 0x00012000 Time Stamp : 0x2e8a200f Time String : 29/09/1994 00:01:51 Product Name : Microsoft® Windows® Operating System File Description : USB Miniport Driver for Input Devices File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\hidusb.sys ================================================== ================================================== Filename : kbdhid.sys Address In Stack : From Address : fffff800`35100000 To Address : fffff800`35110000 Size : 0x00010000 Time Stamp : 0x30e4f78a Time String : 30/12/1995 06:25:46 Product Name : Sistema Operacional Microsoft® Windows® File Description : HID Mouse Filter Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\kbdhid.sys ================================================== ================================================== Filename : mouhid.sys Address In Stack : From Address : fffff800`35110000 To Address : fffff800`3511f000 Size : 0x0000f000 Time Stamp : 0x25b918d8 Time String : 21/01/1990 00:05:12 Product Name : Sistema Operacional Microsoft® Windows® File Description : HID Mouse Filter Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mouhid.sys ================================================== ================================================== Filename : usbvideo.sys Address In Stack : From Address : fffff800`33900000 To Address : fffff800`3394b000 Size : 0x0004b000 Time Stamp : 0xd45dd794 Time String : 26/11/2082 09:57:08 Product Name : Microsoft® Windows® Operating System File Description : USB Video Class Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\usbvideo.sys ================================================== ================================================== Filename : fastfat.SYS Address In Stack : From Address : fffff800`33950000 To Address : fffff800`339af000 Size : 0x0005f000 Time Stamp : 0x67829b1c Time String : 11/01/2025 14:23:56 Product Name : Microsoft® Windows® Operating System File Description : Fast FAT File System Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\fastfat.SYS ================================================== ================================================== Filename : win32k.sys Address In Stack : From Address : ffff972b`207a0000 To Address : ffff972b`20817000 Size : 0x00077000 Time Stamp : 0x00000000 Time String : Product Name : Microsoft® Windows® Operating System File Description : Full/Desktop Multi-User Win32 Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\win32k.sys ================================================== ================================================== Filename : win32kfull.sys Address In Stack : From Address : ffff972b`1fe00000 To Address : ffff972b`20194000 Size : 0x00394000 Time Stamp : 0x00000000 Time String : Product Name : Microsoft® Windows® Operating System File Description : Full/Desktop Win32k Kernel Driver File Version : 10.0.16299.64 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\win32kfull.sys ================================================== ================================================== Filename : win32kbase.sys Address In Stack : From Address : ffff972b`201a0000 To Address : ffff972b`203b2000 Size : 0x00212000 Time Stamp : 0x00000000 Time String : Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Kernel de Win32k Base File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\win32kbase.sys ================================================== ================================================== Filename : dump_diskdump.sys Address In Stack : From Address : fffff800`35130000 To Address : fffff800`3513f000 Size : 0x0000f000 Time Stamp : 0x988d6cde Time String : 07/02/2051 15:54:38 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : dump_iaStorA.sys Address In Stack : From Address : fffff800`31bc0000 To Address : fffff800`31e7a000 Size : 0x002ba000 Time Stamp : 0x520e5fb9 Time String : 16/08/2013 15:22:01 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : dump_dumpfve.sys Address In Stack : From Address : fffff800`351e0000 To Address : fffff800`351fd000 Size : 0x0001d000 Time Stamp : 0xc2b56cb9 Time String : 07/07/2073 14:15:53 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : dxgmms1.sys Address In Stack : From Address : fffff800`339b0000 To Address : fffff800`33a19000 Size : 0x00069000 Time Stamp : 0x71590ce5 Time String : 05/04/2030 21:16:53 Product Name : Microsoft® Windows® Operating System File Description : DirectX Graphics MMS File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\dxgmms1.sys ================================================== ================================================== Filename : monitor.sys Address In Stack : From Address : fffff800`33a20000 To Address : fffff800`33a31000 Size : 0x00011000 Time Stamp : 0xcbd8b938 Time String : 16/05/2078 23:54:00 Product Name : Microsoft® Windows® Operating System File Description : Monitor Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\monitor.sys ================================================== ================================================== Filename : dxgmms2.sys Address In Stack : From Address : fffff800`31740000 To Address : fffff800`317fc000 Size : 0x000bc000 Time Stamp : 0x344826e5 Time String : 18/10/1997 01:03:01 Product Name : Microsoft® Windows® Operating System File Description : DirectX Graphics MMS File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\dxgmms2.sys ================================================== ================================================== Filename : TSDDD.dll Address In Stack : From Address : ffff972b`203d0000 To Address : ffff972b`203da000 Size : 0x0000a000 Time Stamp : 0x00000000 Time String : Product Name : Microsoft® Windows® Operating System File Description : Framebuffer Display Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\TSDDD.dll ================================================== ================================================== Filename : mmcss.sys Address In Stack : From Address : fffff800`33a40000 To Address : fffff800`33a53000 Size : 0x00013000 Time Stamp : 0x66344614 Time String : 03/05/2024 00:04:04 Product Name : Microsoft® Windows® Operating System File Description : MMCSS Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mmcss.sys ================================================== ================================================== Filename : luafv.sys Address In Stack : From Address : fffff800`33a60000 To Address : fffff800`33a86000 Size : 0x00026000 Time Stamp : 0x025c967c Time String : Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver do Filtro de Virtualização do Arquivo LUA File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\luafv.sys ================================================== ================================================== Filename : wcifs.sys Address In Stack : From Address : fffff800`31e80000 To Address : fffff800`31ea7000 Size : 0x00027000 Time Stamp : 0x061d81cb Time String : Product Name : Microsoft® Windows® Operating System File Description : Windows Container Isolation FS Filter Driver File Version : 10.0.16299.64 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\wcifs.sys ================================================== ================================================== Filename : cldflt.sys Address In Stack : From Address : fffff800`30870000 To Address : fffff800`308d6000 Size : 0x00066000 Time Stamp : 0xb5077a79 Time String : 30/03/2066 07:16:41 Product Name : Microsoft® Windows® Operating System File Description : Cloud Files Mini Filter Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\cldflt.sys ================================================== ================================================== Filename : storqosflt.sys Address In Stack : From Address : fffff800`33110000 To Address : fffff800`33129000 Size : 0x00019000 Time Stamp : 0x426b6c81 Time String : 24/04/2005 07:53:05 Product Name : Sistema Operacional Microsoft® Windows® File Description : Filtro QoS de Armazenamento File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\storqosflt.sys ================================================== ================================================== Filename : wsftprp64.sys Address In Stack : From Address : fffff800`34600000 To Address : fffff800`3460a000 Size : 0x0000a000 Time Stamp : 0x53ad7d3e Time String : 27/06/2014 12:18:38 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : lltdio.sys Address In Stack : From Address : fffff800`31eb0000 To Address : fffff800`31ec6000 Size : 0x00016000 Time Stamp : 0x562d4851 Time String : 25/10/2015 19:23:29 Product Name : Microsoft® Windows® Operating System File Description : Link-Layer Topology Mapper I/O Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\lltdio.sys ================================================== ================================================== Filename : mslldp.sys Address In Stack : From Address : fffff800`314a0000 To Address : fffff800`314ba000 Size : 0x0001a000 Time Stamp : 0x0a882621 Time String : Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver do Protocolo Microsoft LLDP File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mslldp.sys ================================================== ================================================== Filename : rspndr.sys Address In Stack : From Address : fffff800`308e0000 To Address : fffff800`308fa000 Size : 0x0001a000 Time Stamp : 0x808aaecd Time String : 04/05/2038 05:52:45 Product Name : Microsoft® Windows® Operating System File Description : Link-Layer Topology Responder Driver for NDIS 6 File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\rspndr.sys ================================================== ================================================== Filename : wanarp.sys Address In Stack : From Address : fffff800`30ba0000 To Address : fffff800`30bbb000 Size : 0x0001b000 Time Stamp : 0xf9058884 Time String : 24/05/2102 02:50:12 Product Name : Microsoft® Windows® Operating System File Description : MS Remote Access and Routing ARP Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\wanarp.sys ================================================== ================================================== Filename : ndisuio.sys Address In Stack : From Address : fffff800`30bc0000 To Address : fffff800`30bd6000 Size : 0x00016000 Time Stamp : 0x9abf995e Time String : 09/04/2052 01:58:22 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de E/S do modo de usuário NDIS File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ndisuio.sys ================================================== ================================================== Filename : nwifi.sys Address In Stack : From Address : fffff800`34100000 To Address : fffff800`34187000 Size : 0x00087000 Time Stamp : 0x870c410f Time String : 18/10/2041 14:40:47 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver da Miniporta NativeWiFi File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\nwifi.sys ================================================== ================================================== Filename : HTTP.sys Address In Stack : From Address : fffff800`33e00000 To Address : fffff800`33f13000 Size : 0x00113000 Time Stamp : 0x8e07c76c Time String : 05/07/2045 11:34:36 Product Name : Sistema Operacional Microsoft® Windows® File Description : Pilha do protocolo HTTP File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\HTTP.sys ================================================== ================================================== Filename : vwifimp.sys Address In Stack : From Address : fffff800`33f20000 To Address : fffff800`33f30000 Size : 0x00010000 Time Stamp : 0x5ba3cdb8 Time String : 20/09/2018 14:41:28 Product Name : Microsoft® Windows® Operating System File Description : Virtual WiFi Miniport Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\vwifimp.sys ================================================== ================================================== Filename : bowser.sys Address In Stack : From Address : fffff800`33f30000 To Address : fffff800`33f51000 Size : 0x00021000 Time Stamp : 0xa73b9d41 Time String : 28/11/2058 07:39:13 Product Name : Microsoft® Windows® Operating System File Description : NT Lan Manager Datagram Receiver Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\bowser.sys ================================================== ================================================== Filename : mpsdrv.sys Address In Stack : From Address : fffff800`33f60000 To Address : fffff800`33f79000 Size : 0x00019000 Time Stamp : 0xdfb7e613 Time String : 08/12/2088 17:05:55 Product Name : Microsoft® Windows® Operating System File Description : Microsoft Protection Service Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mpsdrv.sys ================================================== ================================================== Filename : mrxsmb.sys Address In Stack : From Address : fffff800`33f80000 To Address : fffff800`34001000 Size : 0x00081000 Time Stamp : 0x01cf6bb1 Time String : Product Name : Sistema Operacional Microsoft® Windows® File Description : Minirdr SMB do Windows NT File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mrxsmb.sys ================================================== ================================================== Filename : mrxsmb20.sys Address In Stack : From Address : fffff800`34010000 To Address : fffff800`3404d000 Size : 0x0003d000 Time Stamp : 0x00e219fd Time String : Product Name : Microsoft® Windows® Operating System File Description : Longhorn SMB 2.0 Redirector File Version : 10.0.16299.19 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mrxsmb20.sys ================================================== ================================================== Filename : srvnet.sys Address In Stack : From Address : fffff800`34050000 To Address : fffff800`34097000 Size : 0x00047000 Time Stamp : 0x0af35505 Time String : Product Name : Microsoft® Windows® Operating System File Description : Server Network driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\srvnet.sys ================================================== ================================================== Filename : srv2.sys Address In Stack : From Address : fffff800`36040000 To Address : fffff800`360f9000 Size : 0x000b9000 Time Stamp : 0xe8166d43 Time String : 21/05/2093 20:37:55 Product Name : Sistema Operacional Microsoft® Windows® File Description : Driver de Servidor Smb 2.0 File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\srv2.sys ================================================== ================================================== Filename : kldisk.sys Address In Stack : From Address : fffff800`36100000 To Address : fffff800`36112000 Size : 0x00012000 Time Stamp : 0x567cf4a7 Time String : 25/12/2015 05:47:51 Product Name : System Interceptors PDK File Description : Virtual Disk [fre_wnet_x64] File Version : 12.0.0.1 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\kldisk.sys ================================================== ================================================== Filename : mrxsmb10.sys Address In Stack : From Address : fffff800`36120000 To Address : fffff800`3616e000 Size : 0x0004e000 Time Stamp : 0x45cf2c63 Time String : 11/02/2007 12:46:59 Product Name : Microsoft® Windows® Operating System File Description : Longhorn SMB Downlevel SubRdr File Version : 10.0.16299.19 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\mrxsmb10.sys ================================================== ================================================== Filename : Ndu.sys Address In Stack : From Address : fffff800`36170000 To Address : fffff800`36195000 Size : 0x00025000 Time Stamp : 0x59cb3f21 Time String : 27/09/2017 04:03:13 Product Name : Microsoft® Windows® Operating System File Description : Windows Network Data Usage Monitoring Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\Ndu.sys ================================================== ================================================== Filename : peauth.sys Address In Stack : From Address : fffff800`35200000 To Address : fffff800`352c1000 Size : 0x000c1000 Time Stamp : 0x544f2396 Time String : 28/10/2014 03:03:18 Product Name : Microsoft® Windows® Operating System File Description : Protected Environment Authentication and Authorization Export Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\peauth.sys ================================================== ================================================== Filename : srv.sys Address In Stack : From Address : fffff800`352d0000 To Address : fffff800`35360000 Size : 0x00090000 Time Stamp : 0x82d0caf7 Time String : 19/07/2039 18:52:07 Product Name : Microsoft® Windows® Operating System File Description : Server driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\srv.sys ================================================== ================================================== Filename : tcpipreg.sys Address In Stack : From Address : fffff800`35360000 To Address : fffff800`35373000 Size : 0x00013000 Time Stamp : 0x5b8d9a48 Time String : 03/09/2018 18:32:08 Product Name : Microsoft® Windows® Operating System File Description : TCP/IP Registry Compatibility Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\tcpipreg.sys ================================================== ================================================== Filename : gbprcm64.sys Address In Stack : From Address : fffff800`35380000 To Address : fffff800`3538a000 Size : 0x0000a000 Time Stamp : 0x5576ffcc Time String : 09/06/2015 13:01:32 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : condrv.sys Address In Stack : From Address : fffff800`35390000 To Address : fffff800`353a2000 Size : 0x00012000 Time Stamp : 0xa6ea12b5 Time String : 27/09/2058 11:14:29 Product Name : Microsoft® Windows® Operating System File Description : Console Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\condrv.sys ================================================== ================================================== Filename : rassstp.sys Address In Stack : From Address : fffff800`353b0000 To Address : fffff800`353cb000 Size : 0x0001b000 Time Stamp : 0xd487583c Time String : 27/12/2082 21:29:00 Product Name : Microsoft® Windows® Operating System File Description : RAS SSTP Miniport Call Manager File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\rassstp.sys ================================================== ================================================== Filename : NDProxy.sys Address In Stack : From Address : fffff800`353d0000 To Address : fffff800`353e6000 Size : 0x00016000 Time Stamp : 0xb13fce45 Time String : 26/03/2064 07:20:05 Product Name : Microsoft® Windows® Operating System File Description : NDIS Proxy File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\NDProxy.sys ================================================== ================================================== Filename : AgileVpn.sys Address In Stack : From Address : fffff800`353f0000 To Address : fffff800`35417000 Size : 0x00027000 Time Stamp : 0xbdd34c6e Time String : 02/12/2070 08:24:46 Product Name : Sistema Operacional Microsoft® Windows® File Description : Gerenciador de Chamadas de Miniporta VPN RAS Agile File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\AgileVpn.sys ================================================== ================================================== Filename : rasl2tp.sys Address In Stack : From Address : fffff800`35420000 To Address : fffff800`35440000 Size : 0x00020000 Time Stamp : 0xedecef5f Time String : 28/06/2096 11:19:27 Product Name : Microsoft® Windows® Operating System File Description : RAS L2TP mini-port/call-manager driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\rasl2tp.sys ================================================== ================================================== Filename : raspptp.sys Address In Stack : From Address : fffff800`35440000 To Address : fffff800`3545f000 Size : 0x0001f000 Time Stamp : 0x30102aa9 Time String : 21/07/1995 20:31:05 Product Name : Microsoft® Windows® Operating System File Description : Peer-to-Peer Tunneling Protocol File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\raspptp.sys ================================================== ================================================== Filename : raspppoe.sys Address In Stack : From Address : fffff800`35460000 To Address : fffff800`3547b000 Size : 0x0001b000 Time Stamp : 0xa080d0be Time String : 01/05/2055 13:03:26 Product Name : Microsoft® Windows® Operating System File Description : RAS PPPoE mini-port/call-manager driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\raspppoe.sys ================================================== ================================================== Filename : ndistapi.sys Address In Stack : From Address : fffff800`35480000 To Address : fffff800`3548f000 Size : 0x0000f000 Time Stamp : 0x66b12a51 Time String : 05/08/2024 17:38:57 Product Name : Microsoft® Windows® Operating System File Description : NDIS 3.0 connection wrapper driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ndistapi.sys ================================================== ================================================== Filename : ndiswan.sys Address In Stack : From Address : fffff800`35490000 To Address : fffff800`354c7000 Size : 0x00037000 Time Stamp : 0xf58ec2fa Time String : 20/07/2100 11:39:06 Product Name : Microsoft® Windows® Operating System File Description : MS PPP Framing Driver (Strong Encryption) File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\ndiswan.sys ================================================== ================================================== Filename : klupd_klif_kimul.sys Address In Stack : From Address : fffff800`354f0000 To Address : fffff800`35507000 Size : 0x00017000 Time Stamp : 0x5898596d Time String : 06/02/2017 09:09:33 Product Name : Kaspersky Anti-Virus File Description : Kernel heuristics engine File Version : 0.0.0.46 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klupd_klif_kimul.sys ================================================== ================================================== Filename : klupd_klif_mark.sys Address In Stack : From Address : fffff800`35510000 To Address : fffff800`3553b000 Size : 0x0002b000 Time Stamp : 0x59ee04b2 Time String : 23/10/2017 13:03:14 Product Name : Kaspersky Anti-Virus File Description : Kaspersky Lab Anti-Rootkit Engine File Version : 5.13.5.0 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klupd_klif_mark.sys ================================================== ================================================== Filename : klids.sys Address In Stack : From Address : fffff800`35540000 To Address : fffff800`3556d000 Size : 0x0002d000 Time Stamp : 0x59cec5d8 Time String : 29/09/2017 20:14:48 Product Name : File Description : File Version : Company : Full Path : ================================================== ================================================== Filename : klupd_klif_klark.sys Address In Stack : From Address : fffff800`35570000 To Address : fffff800`355ae000 Size : 0x0003e000 Time Stamp : 0x59ee01ba Time String : 23/10/2017 12:50:34 Product Name : Kaspersky Anti-Virus File Description : Kaspersky Lab Anti-Rootkit File Version : 3.7.7.0 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klupd_klif_klark.sys ================================================== ================================================== Filename : klpnpflt.sys Address In Stack : From Address : fffff800`355c0000 To Address : fffff800`355cb000 Size : 0x0000b000 Time Stamp : 0x588236eb Time String : 20/01/2017 14:12:27 Product Name : System Interceptors PDK File Description : Generic PnP filter [fre_win8_x64] File Version : 13.0.0.9 Company : AO Kaspersky Lab Full Path : C:\Windows\system32\drivers\klpnpflt.sys ================================================== ================================================== Filename : rdpvideominiport.sys Address In Stack : From Address : fffff800`355e0000 To Address : fffff800`355ed000 Size : 0x0000d000 Time Stamp : 0x834709a4 Time String : 17/10/2039 11:27:00 Product Name : Microsoft® Windows® Operating System File Description : Microsoft RDP Video Miniport driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\rdpvideominiport.sys ================================================== ================================================== Filename : asyncmac.sys Address In Stack : From Address : fffff800`359e0000 To Address : fffff800`359ee000 Size : 0x0000e000 Time Stamp : 0x8a403ec7 Time String : 02/07/2043 14:09:43 Product Name : Microsoft® Windows® Operating System File Description : MS Remote Access serial network driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\drivers\asyncmac.sys ================================================== ================================================== Filename : cdd.dll Address In Stack : From Address : ffff972b`204c0000 To Address : ffff972b`20501000 Size : 0x00041000 Time Stamp : 0x00000000 Time String : Product Name : Microsoft® Windows® Operating System File Description : Canonical Display Driver File Version : 10.0.16299.15 (WinBuild.160101.0800) Company : Microsoft Corporation Full Path : C:\Windows\system32\cdd.dll ==================================================
  5. Reinicio sem motivo do Windows 10

    Boa tarde Hoje enfrentei este mesmo problema, reinicio sem motivo aparente pois estava usando apenas o navegador Chrome no momento. No log de eventos nível critico aparece a mensagem abaixo. System - Provider [ Name] Microsoft-Windows-Kernel-Power [ Guid] {331C3B3A-2005-44C2-AC5E-77220C37D6B4} EventID 41 Version 6 Level 1 Task 63 Opcode 0 Keywords 0x8000400000000002 - TimeCreated [ SystemTime] 2017-11-25T16:05:54.948466400Z EventRecordID 3525 Correlation - Execution [ ProcessID] 4 [ ThreadID] 8 Channel System Computer - - Security [ UserID] S-1-5-18 - EventData BugcheckCode 265 BugcheckParameter1 0xa3a0066103f3d8c2 BugcheckParameter2 0xb3b712e75675a4b9 BugcheckParameter3 0xc0000082 BugcheckParameter4 0x7 SleepInProgress 0 PowerButtonTimestamp 0 BootAppStatus 0 Checkpoint 0 ConnectedStandbyInProgress false SystemSleepTransitionsToOn 2 CsEntryScenarioInstanceId 0 BugcheckInfoFromEFI true CheckpointStatus 0 Solicito ajuda na solução deste problema. Desde já agradeço.
  6. Mcafee LiveSafe

    Boa noite A licença do meu antivírus vencerá em breve e encontrei o Mcafee LiveSafe gratuito por um ano no sharewareonsale. https://sharewareonsale.com/s/free-mcafee-livesafe-100-discount. Gostaria de saber se é um bom produto e oferece realmente uma boa proteção. MAX-SP
  7. Ataque smart arp e smart dns

    Boa noite Houve um ataque smart arp hoje. O endereço MAC identificado foi o do tablet. Pode ser que ele esteja com malware?
  8. Ataque smart arp e smart dns

    Boa tarde Nas configurações do roteador em firewall todas as opções estão ativadas.
  9. Ataque smart arp e smart dns

    Boa noite Não é com frequência e soube desses ataques porque visualizei o relatório de eventos do firewall. O Panda não exibiu nenhum aviso quanto ao bloqueio do ataque. Foram 3 ataques smart arp e 1 smart dns. Quanto ao roteador é o Tp-link WR841ND (BR).
  10. Ataque smart arp e smart dns

    Boa noite Acredito que eu não tenha com o que me preocupar, pela explicação. O Panda Internet Security está realizando a proteção de forma adequada. Quanto as configurações do roteador acredito que estejam ok. Alterei o dns para o DNS do Google, não exibir SSID para outros dispositivos e manter oculta a rede, alteração da senha padrão. Não utilizo nenhuma regra DMZ.
  11. Ataque smart arp e smart dns

    Boa noite Utilizo o Panda Internet Security e no registro do firewall constam ataques SMART ARP e SMART DNS, ambos bloqueados. Fiz o escaneamento com o antivírus Panda e nada foi encontrado. Nos ataques SMART ARP consta os endereços MAC do roteador, do tablet com proteção Eset e também do smartphone com proteção Lookout que se conectam ao roteador via WiFi. No ataque SMART DNS consta o endereço MAC do roteador. Gostaria de saber o que são estes ataques e o que fazer para manter o roteador e os outros dispositivos seguros. MAX-SP
  12. Solicitação análise de log

    O PC está apresentando mensagens informando que algumas extensões de arquivo foram redefinidas para serem abertas por outros aplicativos com frequência. Até o momento só apresentou isso de diferente.
  13. Solicitação análise de log

    Zoek.exe v5.0.0.1 Updated 31-December-2015 Tool run by Shirlei on 01/09/2016 at 18:06:16,03. Microsoft Windows 10 Home Single Language 10.0.10586 x64 Running in: Normal Mode Internet Access Detected Launched: C:\Users\Shirlei\Downloads\zoek.exe [Scan all users] [Script inserted] ==== System Restore Info ====================== 01/09/2016 18:07:17 Zoek.exe System Restore Point Created Successfully. ==== Reset Hosts File ====================== # Copyright (c) 1993-2006 Microsoft Corp. # # This is a sample HOSTS file used by Microsoft TCP/IP for Windows. # # This file contains the mappings of IP addresses to host names. Each # entry should be kept on an individual line. The IP address should # be placed in the first column followed by the corresponding host name. # The IP address and the host name should be separated by at least one # space. # # Additionally, comments (such as these) may be inserted on individual # lines or following the machine name denoted by a '#' symbol. # # For example: # # 102.54.94.97 rhino.acme.com # source server # 38.25.63.10 x.acme.com # x client host 127.0.0.1 localhost ==== Empty Folders Check ====================== C:\PROGRA~2\Avira deleted successfully C:\Program Files\Diebold deleted successfully C:\PROGRA~3\Comms deleted successfully C:\PROGRA~3\SoftwareDistribution deleted successfully C:\Users\Administrador\AppData\LocalLow deleted successfully C:\Users\Administrador\AppData\Local\ActiveSync deleted successfully C:\Users\Shirlei\AppData\Local\ActiveSync deleted successfully C:\Users\Shirlei\AppData\Local\EmieBrowserModeList deleted successfully C:\Users\Shirlei\AppData\Local\EmieSiteList deleted successfully C:\Users\Shirlei\AppData\Local\EmieUserList deleted successfully C:\Users\Shirlei\AppData\Local\MediaShow deleted successfully ==== Deleting CLSID Registry Keys ====================== ==== Deleting CLSID Registry Values ====================== ==== Deleting Services ====================== ==== Deleting Files \ Folders ====================== C:\PROGRA~2\Avira not found C:\PROGRA~3\{18165758-115C-4DC0-9EC2-FF89F725767F} deleted C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted ==== Chromium Look ====================== Web of Trust - Shirlei\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp uBlockâ‚€ - Shirlei\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm Ghostery - Shirlei\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij ==== Set IE to Default ====================== Old Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://g.msn.com/HPCON14/3" New Values: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main] "Start Page"="http://g.msn.com/HPCON14/3" ==== All HKLM and HKCU SearchScopes ====================== HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&PC=CPNTDFJS HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&PC=CPNTDFJS HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms} HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&PC=CPNTDFJS ==== Reset Google Chrome ====================== C:\Users\Shirlei\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully C:\Users\Shirlei\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully C:\Users\Shirlei\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully C:\Users\Shirlei\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully ==== shortcuts on Users Desktops ====================== C:\Users\Shirlei\Desktop\Google Chrome.lnk - C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe ==== shortcuts on All Users Desktop ====================== C:\Users\Public\Desktop\HP Support Assistant.lnk - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /p 2 C:\Users\Public\Desktop\iTunes.lnk - C:\Program Files (x86)\iTunes\iTunes.exe C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Malware\mbam.exe C:\Users\Public\Desktop\Panda Free antivírus.lnk - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\Users\Public\Desktop\WildTangent Games For HP.lnk - C:\Program Files (x86)\WildTangent Games\App\GameConsole-wt.exe /src desktopoem /dp hpcnb3c13 ==== shortcuts in Users Start Menu ====================== C:\Users\Shirlei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk - C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk - C:\Users\Shirlei\AppData\Local\Microsoft\OneDrive\OneDrive.exe C:\Users\Shirlei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Internet Explorer.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe ==== shortcuts in All Users Start Menu ====================== C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free antivírus.lnk - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk - C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit\Malwarebytes Anti-Exploit.lnk - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\mbae.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit\Uninstall Malwarebytes Anti-Exploit.lnk - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Desinstalar Malwarebytes Anti-Malware.lnk - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Malware\unins000.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware Notifications.lnk - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Malware\mbam.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Malwarebytes Anti-Malware.lnk - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Malware\mbam.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware\Tools\Malwarebytes Anti-Malware Chameleon.lnk - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\chameleon.chm C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free antivírus\Ajuda.lnk - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe /URL:WebHelp C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free antivírus\Ideias e soluções.lnk - C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free antivírus\Panda Free antivírus.lnk - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Free antivírus\Suporte técnico on-line.lnk - ==== shortcuts in Quick Launch ====================== C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Default User\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Shirlei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk - C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk - C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Shirlei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\Shirlei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - C:\Users\Shirlei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\File Explorer.lnk - C:\Users\Shirlei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk - C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\HP Utility Center.lnk - C:\Program Files\Hewlett-Packard\HP Utility Center\HPPU.exe C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk - C:\Users\USURIO~1\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk - ==== Reset IE Proxy ====================== Value(s) before fix: "ProxyEnable"=dword:00000000 Value(s) after fix: "ProxyEnable"=dword:00000000 ==== Empty IE Cache ====================== C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully C:\Users\Administrador\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Shirlei\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Shirlei\AppData\Local\Microsoft\Windows\INetCache\Low\Content.IE5 emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully C:\Users\Administrador\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Shirlei\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\Users\Shirlei\AppData\Local\Microsoft\Windows\INetCache\Low\IE emptied successfully C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully ==== Empty FireFox Cache ====================== No FireFox Profiles found ==== Empty Chrome Cache ====================== C:\Users\Shirlei\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully ==== Empty All Flash Cache ====================== No Flash Cache Found ==== Empty All Java Cache ====================== No Java Cache Found ==== C:\zoek_backup content ====================== C:\zoek_backup (files=3 folders=1 45529842 bytes) ==== Empty Temp Folders ====================== C:\WINDOWS\Temp will be emptied at reboot ==== After Reboot ====================== ==== Empty Temp Folders ====================== C:\WINDOWS\Temp successfully emptied C:\Users\Shirlei\AppData\Local\Temp successfully emptied ==== Empty Recycle Bin ====================== C:\$RECYCLE.BIN successfully emptied ==== EOF on 01/09/2016 at 18:29:15,91 ====================== Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 18:31:27, on 01/09/2016 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.10586.0545) Boot mode: Normal Running processes: C:\PROGRA~2\GbPlugin\GbpSv.exe C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe C:\WINDOWS\SysWOW64\notepad.exe C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\mbae.exe C:\Program Files (x86)\CyberLink\YouCam\Youcam_webcam_camera_video.exe C:\Users\Shirlei\Downloads\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON14/3 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON14/3 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/HPCON14/3 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit= O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL O2 - BHO: G-Buster Browser Defense Itaú Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\Program Files (x86)\GbPlugin\gbiehuni.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe O4 - HKLM\..\Run: [PSUAMain] "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe" /LaunchSysTray O4 - HKLM\..\Run: [Malwarebytes Anti-Exploit] C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\mbae.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Shirlei\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Shirlei\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Shirlei\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64" O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVIÇO DE REDE') O8 - Extra context menu item: &Enviar para o OneNote - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: www.google.com.br O15 - Trusted Zone: www.itau.b.br O15 - Trusted Zone: *.itau.b.br O15 - Trusted Zone: bankline.itau.com.br O15 - Trusted Zone: banklineplus.itau.com.br O15 - Trusted Zone: clickbanking.itau.com.br O15 - Trusted Zone: guardiao.itau.com.br O15 - Trusted Zone: www.itau.com.br O15 - Trusted Zone: http://www.itau.com.br O15 - Trusted Zone: *.itau.com.br O15 - Trusted Zone: www.itaupersonnalite.com.br O15 - Trusted Zone: http://www.itaupersonnalite.com.br O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginUni - C:\Program Files (x86)\GbPlugin\gbiehUni.dll O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: @oem31.inf,%HidMonitor.SvcDisp%;Alps HID Monitor Service (ApHidMonitorService) - Alps Electric Co., Ltd. - C:\Program Files\Apoint2K\HidMonitorSvc.exe O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: HP SimplePass Cachedrv Service (Cachedrv server) - Unknown owner - C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) Update Manager (iumsvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Malwarebytes Anti-Exploit Service (MbaeSvc) - Malwarebytes Corporation - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: Panda Protection Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe O23 - Service: Panda Devices Agent (PandaAgent) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe O23 - Service: Panda Product Service (PSUAService) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 14174 bytes
  14. Solicitação análise de log

    Abaixo os logs. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.0.7 (07.03.2016) Operating System: Windows 10 Home Single Language x64 Ran by Shirlei (Administrator) on 01/09/2016 at 17:05:43,65 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 2 Successfully deleted: C:\WINDOWS\prefetch\FREEAV.EXE-B45A9603.pf (File) Successfully deleted: C:\WINDOWS\prefetch\PANDAFREEAV.EXE-38CCCDEF.pf (File) Registry: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 01/09/2016 at 17:08:22,07 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ # AdwCleaner v6.010 - Relatório criado 01/09/2016 às 17:01:09 # *Updated on 12/08/2016 by ToolsLib # Banco de dados : 2016-09-01.1 [Servidor] # Sistema operacional : Windows 10 Home Single Language (X64) # Usuário : Shirlei - SHIRLEI # Executando de : C:\Users\Shirlei\Desktop\AdwCleaner.exe # Limpar # Apoio : https://toolslib.net/forum ***** [ Serviços ] ***** ***** [ Pastas ] ***** ***** [ Arquivos ] ***** ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Atalhos ] ***** ***** [ Tarefas agendadas ] ***** ***** [ Registro ] ***** ***** [ Navegadores ] ***** ************************* :: Chaves "Tracing" excluídas :: Configurações Winsock restauradas ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [776 *Bytes] - [01/09/2016 17:01:09] C:\AdwCleaner\AdwCleaner[S0].txt - [1143 *Bytes] - [01/09/2016 17:00:41] ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [923 *Bytes] ########## Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:16:24, on 01/09/2016 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v11.0 (11.00.10586.0545) Boot mode: Normal Running processes: C:\PROGRA~2\GbPlugin\GbpSv.exe C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\mbae.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\AppData\Local\Google\Chrome\Application\chrome.exe C:\Users\Shirlei\Downloads\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON14/3 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON14/3 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/HPCON14/3 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit= O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office15\URLREDIR.DLL O2 - BHO: G-Buster Browser Defense Itaú Unibanco - {C41A1C0E-EA6C-11D4-B1B8-444553540008} - C:\Program Files (x86)\GbPlugin\gbiehuni.dll O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe O4 - HKLM\..\Run: [PSUAMain] "C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAMain.exe" /LaunchSysTray O4 - HKLM\..\Run: [Malwarebytes Anti-Exploit] C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\mbae.exe O4 - HKCU\..\Run: [Google Update] "C:\Users\Shirlei\AppData\Local\Google\Update\GoogleUpdate.exe" /c O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe O4 - HKCU\..\RunOnce: [Uninstall C:\Users\Shirlei\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64] C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Shirlei\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64" O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVIÇO LOCAL') O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'SERVIÇO DE REDE') O8 - Extra context menu item: &Enviar para o OneNote - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105 O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll O9 - Extra button: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra 'Tools' menuitem: Clique para Telefonar do Lync - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll O9 - Extra button: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: &Anotações Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: www.google.com.br O15 - Trusted Zone: www.itau.b.br O15 - Trusted Zone: *.itau.b.br O15 - Trusted Zone: bankline.itau.com.br O15 - Trusted Zone: banklineplus.itau.com.br O15 - Trusted Zone: clickbanking.itau.com.br O15 - Trusted Zone: guardiao.itau.com.br O15 - Trusted Zone: www.itau.com.br O15 - Trusted Zone: http://www.itau.com.br O15 - Trusted Zone: *.itau.com.br O15 - Trusted Zone: www.itaupersonnalite.com.br O15 - Trusted Zone: http://www.itaupersonnalite.com.br O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL O20 - Winlogon Notify: GbPluginUni - C:\Program Files (x86)\GbPlugin\gbiehUni.dll O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing) O23 - Service: @oem31.inf,%HidMonitor.SvcDisp%;Alps HID Monitor Service (ApHidMonitorService) - Alps Electric Co., Ltd. - C:\Program Files\Apoint2K\HidMonitorSvc.exe O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: Serviço do Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: HP SimplePass Cachedrv Service (Cachedrv server) - Unknown owner - C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing) O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing) O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe O23 - Service: Gbp Service (GbpSv) - GAS Tecnologia - C:\PROGRA~2\GbPlugin\GbpSv.exe O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\WINDOWS\system32\igfxCUIService.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) Update Manager (iumsvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: Malwarebytes Anti-Exploit Service (MbaeSvc) - Malwarebytes Corporation - C:\Arquivos de Programas (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing) O23 - Service: Panda Protection Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSANHost.exe O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe O23 - Service: Panda Devices Agent (PandaAgent) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Devices Agent\AgentSvc.exe O23 - Service: Panda Product Service (PSUAService) - Panda Security, S.L. - C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAService.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing) O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing) O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 14493 bytes
×