Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

All search results redirect to junk search sites


  • Please log in to reply

#1
RJLC

RJLC

    Member

  • Member
  • PipPip
  • 21 posts
Every search I do gives the normal results. If I click on any of the results it redirects to ad's or other junk search sites. Even results that are directed to known sites will redirect. This just started in the last two weeks.

Any help would be greatly appreciated!!!

Here is an OTL log I just ran:

d OTL logfile created on: 8/17/2012 10:36:56 AM - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Users\Rob Lutz\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 2.06 Gb Available Physical Memory | 51.48% Memory free
8.00 Gb Paging File | 5.71 Gb Available in Paging File | 71.42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 814.31 Gb Free Space | 87.43% Space Free | Partition Type: NTFS
Drive P: | 465.66 Gb Total Space | 380.14 Gb Free Space | 81.63% Space Free | Partition Type: NTFS
Drive Q: | 465.66 Gb Total Space | 380.14 Gb Free Space | 81.63% Space Free | Partition Type: NTFS
Drive U: | 465.66 Gb Total Space | 380.14 Gb Free Space | 81.63% Space Free | Partition Type: NTFS

Computer Name: RJL8 | User Name: Rob Lutz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rob Lutz\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Blue Iris\blueiris.exe (Perspective Software)
PRC - C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\LogMeIn Backup\BackupSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Blue Iris\BlueIrisService.exe ()
PRC - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files (x86)\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\LogMeIn Backup\LMIGuardian.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
PRC - C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe ()
PRC - C:\Windows\SysWOW64\XSrvSetup.exe ()
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3421b96c2885b8e4137a376ff3d95fa5\System.Deployment.ni.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\QBMAPILibrary.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\QBCompressor.DLL ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\mbpopup.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_serialization-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_regex-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\BackupLib.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\zlib1.dll ()
MOD - C:\Program Files (x86)\HP\ToolboxFX\bin\NativeUtils.dll ()
MOD - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (NisSrv) -- c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (LMIMaint) -- C:\Program Files (x86)\LogMeIn\x64\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (QBCFMonitorService) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (LogMeInBackupService.exe) -- C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe (LogMeIn, Inc.)
SRV - (LMIBackupVSSService.exe) -- C:\Program Files (x86)\LogMeIn Backup\lmibackupvssserviceX64.exe (LogMeIn, Inc.)
SRV - (BackupMaint) -- C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe (LogMeIn, Inc.)
SRV - (QBVSS) -- C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (QBFCService) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (QuickBooksDB22) -- C:\Program Files (x86)\Intuit\QuickBooks 2012\QBDBMgrN.exe (Intuit, Inc.)
SRV - (BlueIris) -- C:\Program Files (x86)\Blue Iris\BlueIrisService.exe ()
SRV - (PMBDeviceInfoProvider) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (LogMeIn) -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (HP LaserJet Service) -- C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FlipShare Service) -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (ES lite Service) -- C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe ()
SRV - (JMB36X) -- C:\Windows\SysWOW64\XSrvSetup.exe ()
SRV - (BCUService) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (LMIRfsClientNP) -- C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (FTDIBUS) -- C:\Windows\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (FTSER2K) -- C:\Windows\SysNative\drivers\ftser2k.sys (FTDI Ltd.)
DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (RTHDMIAzAudService) -- C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (LMIRfsDriver) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) -- C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows ® Server 2003 DDK provider)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (LMIInfo) -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C3 4A 9C 7B FE 7B CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/06/25 10:17:25 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (PE_IE_Helper Class) - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:\Program Files (x86)\IBM\Lotus Forms\Viewer\3.5\PEhelper.dll (IBM Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HP LaserJet M1522 MFP Series Fax] C:\Program Files (x86)\HP\hp LaserJet M1522\hppfaxprintersrv.exe (Hewlett-Packard Company)
O4:64bit: - HKLM..\Run: [HP LaserJet Professional M1530 MFP Series Fax] C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe (Hewlett-Packard Company)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [LogMeIn Backup GUI] C:\Program Files (x86)\LogMeIn Backup\BackupSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ToolboxFX] C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Akamai NetSession Interface] "C:\Users\Rob Lutz\AppData\Local\Akamai\netsession_win.exe" File not found
O4 - HKCU..\Run: [Ncr] File not found
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Blue Iris.lnk = C:\Program Files (x86)\Blue Iris\blueiris.exe (Perspective Software)
O4 - Startup: C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} http://download.giga...bject/Dldrv.ocx (Dldrv2 Control)
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} http://webiq005.webi...6-6D5536C585C9} (WebIQ Engine Application Object)
O16 - DPF: {33704B0F-9EB7-434B-B752-EA6CFFB87423} http://98.235.110.16...00/JpegInst.cab (pmjpegaudio Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...5.4.logging.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://qb.webex.com...ra/ieatgpc1.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EAEFAD15-8753-45EF-94B0-1BAA7970CC21} http://98.235.63.116:1100/MpegInst.cab (pmpeg4cam Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=928 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{799DB236-0B3B-40B9-AF2C-E90BB876816C}: DhcpNameServer = 10.1.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACCEC188-9853-406C-8461-E90D246B5915}: DhcpNameServer = 10.1.10.1
O18:64bit: - Protocol\Handler\intu-help-qb5 - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{573a1e77-27df-11e1-baab-6cf0495c6684}\Shell - "" = AutoRun
O33 - MountPoints2\{573a1e77-27df-11e1-baab-6cf0495c6684}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{af820449-38ea-11df-aa89-6cf0495c6684}\Shell - "" = AutoRun
O33 - MountPoints2\{af820449-38ea-11df-aa89-6cf0495c6684}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/17 10:34:34 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\Rob Lutz\Desktop\OTL.exe
[2012/08/17 10:23:07 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Roaming\Malwarebytes
[2012/08/17 10:22:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/17 10:22:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/17 10:22:39 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/08/17 10:22:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/17 10:20:34 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\Desktop\Malware
[2012/08/15 16:16:18 | 000,000,000 | R--D | C] -- C:\Users\Rob Lutz\Dropbox
[2012/08/15 16:14:30 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/08/15 16:10:01 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Roaming\Dropbox
[2012/08/13 13:00:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012/08/13 12:59:43 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Local\Google
[2012/08/13 12:59:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2012/07/27 23:43:12 | 000,070,144 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst_8.982.dll
[2012/07/27 22:10:34 | 000,534,528 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2012/07/27 22:09:44 | 000,239,616 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2012/07/27 22:08:20 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2012/07/27 22:08:04 | 000,021,504 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/17 10:34:46 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Rob Lutz\Desktop\OTL.exe
[2012/08/17 10:22:44 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/17 10:18:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/17 10:14:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/17 09:55:36 | 000,015,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/17 09:55:36 | 000,015,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/17 09:50:51 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/17 09:47:01 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/17 09:46:48 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/16 03:24:25 | 005,107,480 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/15 16:16:18 | 000,001,038 | ---- | M] () -- C:\Users\Rob Lutz\Desktop\Dropbox.lnk
[2012/08/15 16:14:56 | 000,001,048 | ---- | M] () -- C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/08/14 12:58:05 | 000,201,934 | ---- | M] () -- C:\Users\Rob Lutz\Desktop\4394 Chambers Hill Rd, Harrisburg, PA 17111 - Bing Maps.mht
[2012/08/13 16:00:26 | 000,083,874 | ---- | M] () -- C:\Users\Rob Lutz\Desktop\Josh Kramer.jpg
[2012/08/13 13:00:33 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2012/07/27 23:43:12 | 000,070,144 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst_8.982.dll
[2012/07/27 22:17:00 | 000,268,728 | ---- | M] () -- C:\Windows\SysWow64\atiapfxx.blb
[2012/07/27 22:17:00 | 000,268,728 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb
[2012/07/27 22:10:34 | 000,534,528 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2012/07/27 22:09:44 | 000,239,616 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2012/07/27 22:08:20 | 000,120,320 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2012/07/27 22:08:04 | 000,021,504 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2012/07/27 21:39:50 | 003,150,560 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap
[2012/07/27 21:30:54 | 003,187,136 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/17 10:22:44 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/15 16:16:18 | 000,001,038 | ---- | C] () -- C:\Users\Rob Lutz\Desktop\Dropbox.lnk
[2012/08/15 16:14:56 | 000,001,048 | ---- | C] () -- C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/08/14 12:58:04 | 000,201,934 | ---- | C] () -- C:\Users\Rob Lutz\Desktop\4394 Chambers Hill Rd, Harrisburg, PA 17111 - Bing Maps.mht
[2012/08/13 16:02:44 | 000,083,874 | ---- | C] () -- C:\Users\Rob Lutz\Desktop\Josh Kramer.jpg
[2012/08/13 13:00:33 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2012/08/13 12:59:50 | 000,000,902 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/13 12:59:49 | 000,000,898 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/08 10:28:32 | 000,001,097 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Content Viewer.lnk
[2012/07/27 22:17:00 | 000,268,728 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2012/07/27 22:17:00 | 000,268,728 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2012/07/27 21:39:50 | 003,150,560 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2012/07/27 21:30:54 | 003,187,136 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2012/03/09 00:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 00:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/01/31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/12 18:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/19 21:26:28 | 000,667,280 | ---- | C] () -- C:\Windows\SysWow64\tx12.dll
[2011/08/19 21:26:28 | 000,000,530 | ---- | C] () -- C:\Windows\SysWow64\tx12_ic.ini
[2011/08/19 21:26:28 | 000,000,186 | ---- | C] () -- C:\Windows\SysWow64\Gsw32.exe.config
[2011/03/25 11:11:07 | 000,833,024 | ---- | C] () -- C:\Windows\SysWow64\user.dat
[2010/10/28 13:35:43 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2010/10/09 16:27:00 | 000,800,364 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/04/26 13:58:19 | 000,003,584 | ---- | C] () -- C:\Users\Rob Lutz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== LOP Check ==========

[2010/05/07 18:34:58 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/29 17:50:23 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2012/06/14 11:41:52 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/08/17 09:49:23 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Dropbox
[2012/06/20 16:19:07 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\GlobalSCAPE
[2010/04/09 12:40:38 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Leadertech
[2010/11/05 14:09:02 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\PureEdge
[2012/01/19 12:58:59 | 000,032,574 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Download aswMBR.exe ( 511KB ) to your desktop.
Right click aswMBR.exe and Run as Administrator
uncheck trace disk IO calls
Click the "Scan" button to start scan (Accept the Avast Engine)
On completion of the scan if the Fix button is enabled (not the FixMBR button) press it and then run a new scan and click save log, save it to your desktop and post in your next reply
If the Fix button is not enabled then just click save log, save it to your desktop and post in your next reply

ComboFix

:!: It must be saved to your desktop, do not run it from your browser:!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Rightclick on ComboFix and select Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix.

A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.


Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then run it.
Right click on TDSSKiller.exe and select Run As Administrator to start the program.

If TDSSKiller alerts you that the system needs to reboot, please consent.

Run TDSSKiller again but this time:
before you hit the Scan hit Change Parameters and check the two items under Additional Options. OK then Scan.
In this mode it is prone to false positives so do not change the SKIP option to DELETE unless it says TDSS.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.



Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:
http://www.malwareby...lwarebytes_free

SAVE Malwarebytes' Anti-Malware to your desktop.

* Right-click mbam-setup.exe and select Run As Administrator to start the program.
* follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.


Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs. Right click on System and Clear Log, Clear. Repeat for Application.

Reboot.

Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).

sfc  /scannow



(This will check your critical system files. If it asks for a CD and you don't have one or it doesn't like your CD just tell it to SKIP.)


1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.


Copy the text in the code box:

DRIVES
nnetsvcs
%SYSTEMDRIVE%\*.exe
%systemroot%\assembly\GAC_32\*.ini
%systemroot%\assembly\GAC_64\*.ini
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.exe
%APPDATA%\*.
/md5start
pnrpnsp.dll 
nwprovau.dll
nlaapi.dll
napinsp.dll
mswsock.dll
winrnr.dll
wshelper.dll
services.exe
atapi.sys
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
csrss.exe
PrintIsolationHost.exe
consrv.dll
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
CREATERESTOREPOINT

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

Select the All option in the Extra Registry group then Run Scan.

You should get two logs. Please copy and paste both of them.


Ron
  • 0

#3
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
First, let me stay thank you for your time in helping me get this fixed. I do appreciate it greatly. Below is everything you asked for I hope. I did not have any problems with getting the logs. After the intallation of Malwarebytes, I have been getting a pop up window that Malware successfully block access to 206.161.121.3 port 49600. Each time it comes up it looks like the same ip but the ports keep going up.

Step 1 MBR report:


aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-08-20 09:33:39
-----------------------------
09:33:39.158 OS Version: Windows x64 6.1.7601 Service Pack 1
09:33:39.158 Number of processors: 4 586 0x403
09:33:39.158 ComputerName: RJL8 UserName:
09:33:42.169 Initialize success
09:37:51.592 AVAST engine defs: 12082000
09:38:25.273 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
09:38:25.273 Disk 0 Vendor: Hitachi_HDS721010CLA332 JP4OA39C Size: 953869MB BusType: 3
09:38:25.273 Disk 0 MBR read successfully
09:38:25.288 Disk 0 MBR scan
09:38:25.288 Disk 0 Windows 7 default MBR code
09:38:25.288 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
09:38:25.320 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 953767 MB offset 206848
09:38:25.366 Disk 0 scanning C:\Windows\system32\drivers
09:38:36.489 Service scanning
09:39:05.599 Modules scanning
09:39:07.455 AVAST engine scan C:\Windows
09:39:11.184 AVAST engine scan C:\Windows\system32
09:43:09.349 AVAST engine scan C:\Windows\system32\drivers
09:43:23.483 AVAST engine scan C:\Users\Rob Lutz
09:57:54.916 AVAST engine scan C:\ProgramData
09:59:45.645 Scan finished successfully
10:00:47.483 Disk 0 MBR has been saved successfully to "C:\Users\Rob Lutz\Desktop\Malware\MBR.dat"
10:00:47.530 The log file has been saved successfully to "C:\Users\Rob Lutz\Desktop\Malware\aswMBR.txt"
  • 0

#4
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Step 2 Combo Fix:

ComboFix 12-08-20.01 - Rob Lutz 08/20/2012 10:06:32.1.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.4094.1452 [GMT -4:00]
Running from: c:\users\Rob Lutz\Desktop\Malware\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\jyejbaa.tmp
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1076RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1076RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1076RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1076RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1092RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1092RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1092RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1092RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\11108RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\11108RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\11108RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\11108RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1128RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1128RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1128RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1128RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1132RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1132RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1132RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1132RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1136RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1136RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1136RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1136RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1200RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1200RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1200RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1200RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1236RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1236RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1236RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1236RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\124RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\124RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\124RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\124RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1300RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1300RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1300RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1300RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1324RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1324RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1324RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1324RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1396RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1396RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1396RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1396RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1528RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1528RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1528RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1528RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1564RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1564RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1564RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1564RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1704RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1704RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1704RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1704RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1748RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1748RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1748RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1748RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1760RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1760RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1760RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1760RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1888RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1888RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1888RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1888RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1960RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1960RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1960RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1960RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1980RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1980RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1980RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1980RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1992RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1992RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1992RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\1992RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\200RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\200RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\200RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\200RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\204RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\204RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\204RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\204RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2164RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2164RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2164RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2164RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2180RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2180RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2180RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2180RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2248RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2248RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2248RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2248RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2312RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2312RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2312RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2312RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2336RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2336RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2336RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2336RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2340RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2340RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2340RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2340RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2360RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2360RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2360RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2360RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2372RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2372RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2372RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2372RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2440RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2440RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2440RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2440RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2492RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2492RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2492RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2492RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2528RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2528RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2528RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2528RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2532RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2532RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2532RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2532RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2552RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2552RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2552RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2552RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2576RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2576RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2576RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2576RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2656RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2656RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2656RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2656RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2664RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2664RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2664RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2664RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2672RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2672RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2672RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2672RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2684RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2684RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2684RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2684RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2724RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2724RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2724RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2724RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2768RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2768RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2768RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2768RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2844RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2844RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2844RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2844RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2852RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2852RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2852RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2852RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2876RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2876RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2876RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2876RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2884RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2884RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2884RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2884RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2960RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2960RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2960RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\2960RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3000RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3000RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3000RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3000RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3004RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3004RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3004RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3004RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3020RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3020RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3020RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3020RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3028RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3028RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3028RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3028RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3044RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3044RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3044RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3044RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3052RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3052RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3052RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3052RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3108RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3108RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3108RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3108RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3124RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3124RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3124RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3124RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3156RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3156RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3156RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3156RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3168RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3168RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3168RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3168RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3184RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3184RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3184RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3184RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3204RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3204RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3204RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3204RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3228RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3228RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3228RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3228RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3232RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3232RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3232RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3232RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3236RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3236RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3236RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3236RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3248RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3248RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3248RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3248RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3264RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3264RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3264RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3264RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3300RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3300RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3300RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3300RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3392RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3392RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3392RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3392RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3436RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3436RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3436RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3436RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3488RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3488RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3488RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3488RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3500RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3500RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3500RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3500RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3512RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3512RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3512RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3512RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3516RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3516RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3516RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3516RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3536RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3536RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3536RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3536RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3540RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3540RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3540RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3540RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3544RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3544RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3544RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3544RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3556RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3556RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3556RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3556RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3580RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3580RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3580RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3580RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3604RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3604RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3604RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3604RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\360RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\360RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\360RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\360RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3612RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3612RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3612RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3612RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3624RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3624RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3624RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3624RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3636RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3636RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3636RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3636RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3684RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3684RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3684RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3684RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3704RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3704RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3704RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3704RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3728RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3728RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3728RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3728RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3736RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3736RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3736RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3736RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3752RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3752RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3752RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3752RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3764RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3764RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3764RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3764RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3780RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3780RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3780RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3780RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3784RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3784RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3784RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3784RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3788RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3788RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3788RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3788RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3796RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3796RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3796RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3796RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3808RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3808RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3808RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3808RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3812RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3812RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3812RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3812RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3832RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3832RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3832RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3832RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3844RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3844RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3844RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3844RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3852RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3852RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3852RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3852RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3868RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3868RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3868RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3868RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3872RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3872RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3872RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3872RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3884RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3884RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3884RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3884RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3904RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3904RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3904RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3904RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3912RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3912RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3912RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3912RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLC1pffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLC1reviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLC1reviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLC1taskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3932RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3952RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3952RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3952RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3952RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3968RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3968RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3968RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3968RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4004RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4004RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4004RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4004RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4020RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4020RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4020RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4020RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4024RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4024RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4024RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4024RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4048RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4048RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4048RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4048RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4052RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4052RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4052RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4052RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4056RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4056RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4056RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4056RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4068RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4068RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4068RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4068RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4104RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4104RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4104RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4104RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4128RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4128RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4128RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4128RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4136RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4136RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4136RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4136RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4144RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4144RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4144RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4144RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4188RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4188RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4188RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4188RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4204RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4204RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4204RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4204RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4324RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4324RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4324RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4324RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4440RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4440RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4440RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4440RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4444RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4444RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4444RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4444RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4452RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4452RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4452RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4452RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4484RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4484RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4484RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4484RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4496RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4496RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4496RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4496RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4500RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4500RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4500RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4500RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4624RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4624RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4624RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4624RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4632RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4632RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4632RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4632RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4640RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4640RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4640RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4640RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4728RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4728RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4728RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4728RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4956RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4956RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4956RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\4956RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5024RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5024RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5024RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5024RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5064RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5064RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5064RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5064RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5100RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5100RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5100RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5100RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5128RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5128RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5128RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5128RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5132RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5132RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5132RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5132RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5140RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5140RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5140RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5140RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5200RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5200RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5200RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5200RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5220RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5220RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5220RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5220RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5240RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5240RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5240RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5240RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5248RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5248RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5248RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5248RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5256RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5256RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5256RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5256RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5332RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5332RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5332RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5332RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5344RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5344RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5344RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5344RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5348RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5348RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5348RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5348RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5360RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5360RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5360RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5360RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5444RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5444RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5444RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5444RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5452RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5452RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5452RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5452RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5480RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5480RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5480RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5480RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5528RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5528RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5528RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5528RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5560RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5560RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5560RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5560RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5572RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5572RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5572RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5572RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5648RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5648RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5648RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5648RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5680RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5680RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5680RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5680RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5732RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5732RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5732RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5732RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5800RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5800RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5800RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5800RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5820RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5820RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5820RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5820RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5824RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5824RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5824RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5824RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5892RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5892RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5892RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5892RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5908RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5908RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5908RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5908RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5936RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5936RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5936RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5936RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5972RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5972RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5972RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5972RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5984RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5984RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5984RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\5984RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6036RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6036RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6036RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6036RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\604RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\604RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\604RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\604RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6112RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6112RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6112RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6112RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6116RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6116RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6116RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6116RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6224RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6224RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6224RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6224RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6240RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6240RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6240RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6240RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6440RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6440RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6440RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6440RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\648RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\648RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\648RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\648RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6500RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6500RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6500RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6500RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6500RJLCommunicationsLLCviewChanges.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6516RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6516RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6516RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6516RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6636RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6636RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6636RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6636RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6844RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6844RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6844RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6844RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6868RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6868RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6868RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6868RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6900RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6900RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6900RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\6900RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\692RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\692RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\692RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\692RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7112RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7112RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7112RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7112RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7144RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7144RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7144RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7144RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7144RJLCommunicationsLLCviewChanges.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\716RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\716RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\716RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\716RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7184RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7184RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7184RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7184RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7240RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7240RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7240RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\7240RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\728RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\728RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\728RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\728RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\860RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\860RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\860RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\860RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8700RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8700RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8700RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8700RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8760RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8760RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8760RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\8760RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\mootools.svn.js
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\pffCenter.css
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\pffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\pffCenter.js
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\reviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\reviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\taskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Temp\{16AA8FB8-4A98-4757-B7A5-0FF22C0A6E33}_1101_1\dbdata11.dll
c:\users\ROBLUT~1\AppData\Local\Temp\{16AA8FB8-4A98-4757-B7A5-0FF22C0A6E33}_1101_1\dbdata11.dll
c:\windows\Downloaded Program Files\Install.inf
c:\windows\SysWow64\aosmtp.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-07-20 to 2012-08-20 )))))))))))))))))))))))))))))))
.
.
2012-08-20 14:13 . 2012-08-20 14:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-20 14:01 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BD61C897-EE60-45BB-8D19-53170A6369F5}\mpengine.dll
2012-08-19 14:06 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-17 14:23 . 2012-08-17 14:23 -------- d-----w- c:\users\Rob Lutz\AppData\Roaming\Malwarebytes
2012-08-17 14:22 . 2012-08-17 14:22 -------- d-----w- c:\programdata\Malwarebytes
2012-08-17 14:22 . 2012-08-17 14:22 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-17 14:22 . 2012-07-03 17:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-16 01:36 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll
2012-08-16 01:36 . 2012-05-05 07:46 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2012-08-16 01:31 . 2012-02-11 06:43 751104 ----a-w- c:\windows\system32\win32spl.dll
2012-08-16 01:31 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-16 01:31 . 2012-02-11 05:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2012-08-16 01:31 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2012-08-16 01:30 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
2012-08-16 01:30 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
2012-08-16 01:30 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
2012-08-16 01:30 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
2012-08-16 01:30 . 2012-07-18 18:15 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-08-16 01:30 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2012-08-15 20:16 . 2012-08-17 13:49 -------- d-----r- c:\users\Rob Lutz\Dropbox
2012-08-15 20:10 . 2012-08-20 14:19 -------- d-----w- c:\users\Rob Lutz\AppData\Roaming\Dropbox
2012-08-13 16:59 . 2012-08-13 17:00 -------- d-----w- c:\users\Rob Lutz\AppData\Local\Google
2012-08-13 16:59 . 2012-08-13 17:00 -------- d-----w- c:\program files (x86)\Google
2012-07-28 04:09 . 2012-07-28 04:09 5538984 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-07-28 04:07 . 2012-07-28 04:07 10278912 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-07-28 03:43 . 2012-07-28 03:43 70144 ----a-w- c:\windows\system32\coinst_8.982.dll
2012-07-28 03:19 . 2012-07-28 03:19 24935424 ----a-w- c:\windows\system32\atio6axx.dll
2012-07-28 02:50 . 2012-07-28 02:50 20546560 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-07-28 02:15 . 2012-07-28 02:15 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-07-28 02:15 . 2012-07-28 02:15 931328 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-07-28 02:10 . 2012-07-28 02:10 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-07-28 02:10 . 2012-07-28 02:10 534528 ----a-w- c:\windows\system32\atieclxx.exe
2012-07-28 02:09 . 2012-07-28 02:09 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2012-07-28 02:08 . 2012-07-28 02:08 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-07-28 02:08 . 2012-07-28 02:08 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-07-28 02:07 . 2012-07-28 02:07 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-07-28 02:07 . 2012-07-28 02:07 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-07-28 02:07 . 2012-07-28 02:07 6430208 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-07-28 01:41 . 2012-07-28 01:41 4266496 ----a-w- c:\windows\system32\atiumd6a.dll
2012-07-28 01:35 . 2012-07-28 01:35 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-07-28 01:35 . 2012-07-28 01:35 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-07-28 01:35 . 2012-07-28 01:35 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-07-28 01:35 . 2012-07-28 01:35 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-07-28 01:34 . 2012-07-28 01:34 16034304 ----a-w- c:\windows\system32\aticaldd64.dll
2012-07-28 01:32 . 2012-07-28 01:32 4751872 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-07-28 01:30 . 2012-07-28 01:30 13605888 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-07-28 01:25 . 2012-07-28 01:25 6676480 ----a-w- c:\windows\system32\atiumd64.dll
2012-07-28 01:15 . 2012-07-28 01:15 540160 ----a-w- c:\windows\system32\atiadlxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-07-28 01:15 . 2012-07-28 01:15 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-07-28 01:14 . 2012-07-28 01:14 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-07-28 01:14 . 2012-07-28 01:14 368640 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-07-28 01:13 . 2012-07-28 01:13 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-07-28 01:13 . 2012-07-28 01:13 103936 ----a-w- c:\windows\system32\atiu9p64.dll
2012-07-28 01:12 . 2012-07-28 01:12 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-07-28 01:08 . 2012-07-28 01:08 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-07-28 01:08 . 2012-07-28 01:08 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-07-28 01:08 . 2012-07-28 01:08 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-07-28 01:08 . 2012-07-28 01:08 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-20 14:16 . 2010-03-23 20:11 25640 ----a-w- c:\windows\gdrv.sys
2012-08-16 07:00 . 2010-03-23 20:54 62134624 ----a-w- c:\windows\system32\MRT.exe
2012-08-15 16:18 . 2012-04-11 12:50 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-15 16:18 . 2011-05-20 18:44 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-28 02:13 . 2012-03-09 05:14 1100288 ----a-w- c:\windows\system32\aticfx64.dll
2012-07-28 01:51 . 2012-03-09 04:45 7052288 ----a-w- c:\windows\system32\atidxx64.dll
2012-07-28 01:13 . 2010-03-23 22:02 129536 ----a-w- c:\windows\system32\atiuxp64.dll
2012-07-28 01:13 . 2012-06-11 16:24 83456 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-07-11 16:48 . 2010-04-05 13:48 87488 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-07-11 16:48 . 2010-04-05 13:48 34720 ----a-w- c:\windows\system32\LMIport.dll
2012-07-11 16:48 . 2010-04-05 13:48 80800 ----a-w- c:\windows\system32\LMIinit.dll
2012-06-25 20:04 . 2012-06-25 20:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll
2012-06-11 17:50 . 2012-06-11 17:50 187392 ----a-w- c:\windows\system32\clinfo.exe
2012-06-11 17:50 . 2012-06-11 17:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-06-11 17:50 . 2012-06-11 17:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-06-11 17:50 . 2012-06-11 17:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-06-11 17:50 . 2012-06-11 17:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-06-11 17:50 . 2012-06-11 17:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
2012-06-11 17:49 . 2012-06-11 17:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-06-09 05:43 . 2012-07-10 21:51 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-06-06 12:49 . 2012-06-06 12:49 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2012-06-06 06:06 . 2012-07-10 21:51 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 06:06 . 2012-07-10 21:51 1881600 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 06:02 . 2012-07-10 21:51 1133568 ----a-w- c:\windows\system32\cdosys.dll
2012-06-06 05:05 . 2012-07-10 21:51 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
2012-06-06 05:05 . 2012-07-10 21:51 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2012-06-06 05:03 . 2012-07-10 21:51 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
2012-06-02 22:19 . 2012-06-21 17:21 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 17:21 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-21 17:21 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 17:21 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 17:21 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-21 17:21 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-21 17:21 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19 . 2012-06-21 17:20 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:15 . 2012-06-21 17:20 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 05:50 . 2012-07-10 21:51 458704 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 05:48 . 2012-07-10 21:51 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 05:48 . 2012-07-10 21:51 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 05:45 . 2012-07-10 21:51 340992 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 05:44 . 2012-07-10 21:51 307200 ----a-w- c:\windows\system32\ncrypt.dll
2012-06-02 04:40 . 2012-07-10 21:51 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-06-02 04:40 . 2012-07-10 21:51 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2012-06-02 04:39 . 2012-07-10 21:51 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
2012-06-02 04:34 . 2012-07-10 21:51 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-05-30 02:55 . 2012-05-30 02:55 163048 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10141.bin
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 57300E71DFBB58D8ED0D7B9813E55795 . 857600 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-09-25 106496]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]
"ToolboxFX"="c:\program files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" [2010-10-25 58936]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2011-03-15 650080]
"Intuit SyncManager"="c:\program files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2011-12-06 2215768]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"LogMeIn Backup GUI"="c:\program files (x86)\LogMeIn Backup\BackupSystray.exe" [2011-08-29 488848]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-06-25 1073352]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-04-04 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-04-04 815512]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Blue Iris.lnk - c:\program files (x86)\Blue Iris\blueiris.exe [2011-8-14 11807616]
Dropbox.lnk - c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-24 26909544]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Intuit Data Protect.lnk - c:\program files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe [2012-6-5 5982040]
QuickBooks Update Agent.lnk - c:\program files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2012-6-5 1176464]
QuickBooks_Standard_21.lnk - c:\program files (x86)\Intuit\QuickBooks 2012\QBW32.EXE [2012-6-5 1181584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 116648]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 116648]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-21 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-05 1255736]
R4 QuickBooksDB22;QuickBooksDB22;c:\progra~2\Intuit\QUICKB~2\QBDBMgrN.exe [2011-08-20 679936]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-07-28 239616]
S2 BackupMaint;LogMeIn Backup Maintenance Service;c:\program files (x86)\LogMeIn Backup\BackupMaint.exe [2011-08-29 140688]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
S2 BlueIris;Blue Iris Service;c:\program files (x86)\Blue Iris\BlueIrisService.exe [2011-03-24 55808]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-25 145920]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe [2009-08-06 65536]
S2 LMIBackupVSSService.exe;LogMeIn Backup VSS Service;c:\program files (x86)\LogMeIn Backup\LMIBackupVSSServiceX64.exe [2011-08-29 685456]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-07-11 375208]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2008-08-11 15928]
S2 LogMeInBackupService.exe;LogMeIn Backup Storage PC Service;c:\program files (x86)\LogMeIn Backup\LogmeInBackupService.exe [2011-08-29 1787280]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2011-03-15 428384]
S2 QBVSS;QBIDPService;c:\program files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-08-20 1248256]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-07-28 10278912]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-07-28 368640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-09-25 73728]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-09-25 178688]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 16:18]
.
2012-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 16:59]
.
2012-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 16:59]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-21 8306208]
"HP LaserJet M1522 MFP Series Fax"="c:\program files (x86)\HP\hp LaserJet M1522\hppfaxprintersrv.exe" [2009-09-22 3700736]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2008-08-11 57928]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"HP LaserJet Professional M1530 MFP Series Fax"="c:\program files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe" [2010-08-24 3706424]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - c:\program files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll
DPF: {EAEFAD15-8753-45EF-94B0-1BAA7970CC21} - hxxp://98.235.63.116:1100/MpegInst.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
Wow6432Node-HKCU-Run-Ncr - (no file)
Wow6432Node-HKCU-Run-Akamai NetSession Interface - c:\users\Rob Lutz\AppData\Local\Akamai\netsession_win.exe
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
@Denied: (2) (LocalSystem)
"{47833539-D0C5-4125-9FA8-0819E2EAAC93}"=hex:51,66,7a,6c,4c,1d,38,12,57,36,90,
43,f7,9e,4b,04,e0,be,4b,59,e7,b4,e8,87
"{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}"=hex:51,66,7a,6c,4c,1d,38,12,a0,ae,7a,
83,97,95,87,0d,d0,a3,24,f1,29,81,6a,75
"{0941C58F-E461-4E03-BD7D-44C27392ADE1}"=hex:51,66,7a,6c,4c,1d,38,12,e1,c6,52,
0d,53,aa,6d,0b,c2,6b,07,82,76,cc,e9,f5
"{18DF081C-E8AD-4283-A596-FA578C2EBDC3}"=hex:51,66,7a,6c,4c,1d,38,12,72,0b,cc,
1c,9f,a6,ed,07,da,80,b9,17,89,70,f9,d7
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"=hex:51,66,7a,6c,4c,1d,38,12,d5,94,07,
72,c2,98,42,03,c9,fd,97,9a,f4,87,69,57
"{AE7CD045-E861-484F-8273-0445EE161910}"=hex:51,66,7a,6c,4c,1d,38,12,2b,d3,6f,
aa,53,a6,21,0d,fd,65,47,05,eb,48,5d,04
"{B4F3A835-0E21-4959-BA22-42B3008E02FF}"=hex:51,66,7a,6c,4c,1d,38,12,5b,ab,e0,
b0,13,40,37,0c,c5,34,01,f3,05,d0,46,eb
"{DBC80044-A445-435B-BC74-9C25C1C588A9}"=hex:51,66,7a,6c,4c,1d,38,12,2a,03,db,
df,77,ea,35,06,c3,62,df,65,c4,9b,cc,bd
"{F4971EE7-DAA0-4053-9964-665D8EE6A077}"=hex:51,66,7a,6c,4c,1d,38,12,89,1d,84,
f0,92,94,3d,05,e6,72,25,1d,8b,b8,e4,63
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:33,0c,9b,a6,80,7b,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a6,47,e7,e3,c4,e0,0d,4f,9c,90,01,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a6,47,e7,e3,c4,e0,0d,4f,9c,90,01,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]
@Denied: (A) (Everyone)
"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]
"Key"="ActionsPane"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Flip Video\FlipShare\FlipShareService.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files (x86)\LogMeIn Backup\LMIGuardian.exe
c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files (x86)\LogMeIn Backup\LMIGuardian.exe
.
**************************************************************************
.
Completion time: 2012-08-20 10:24:30 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-20 14:24
.
Pre-Run: 878,998,102,016 bytes free
Post-Run: 883,044,528,128 bytes free
.
- - End Of File - - D296B2B86165F1E5E48F7F8322EA15F2
  • 0

#5
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Step 3 TDSS Killer:

10:27:37.0439 3320 TDSS rootkit removing tool 2.8.7.0 Aug 20 2012 17:30:03
10:27:37.0766 3320 ============================================================
10:27:37.0766 3320 Current date / time: 2012/08/20 10:27:37.0766
10:27:37.0766 3320 SystemInfo:
10:27:37.0766 3320
10:27:37.0766 3320 OS Version: 6.1.7601 ServicePack: 1.0
10:27:37.0766 3320 Product type: Workstation
10:27:37.0766 3320 ComputerName: RJL8
10:27:37.0766 3320 UserName: Rob Lutz
10:27:37.0766 3320 Windows directory: C:\Windows
10:27:37.0766 3320 System windows directory: C:\Windows
10:27:37.0766 3320 Running under WOW64
10:27:37.0766 3320 Processor architecture: Intel x64
10:27:37.0766 3320 Number of processors: 4
10:27:37.0766 3320 Page size: 0x1000
10:27:37.0766 3320 Boot type: Normal boot
10:27:37.0766 3320 ============================================================
10:27:38.0546 3320 Drive \Device\Harddisk0\DR0 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1F8B1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000040
10:27:38.0546 3320 ============================================================
10:27:38.0546 3320 \Device\Harddisk0\DR0:
10:27:38.0546 3320 MBR partitions:
10:27:38.0546 3320 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
10:27:38.0546 3320 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x746D3800
10:27:38.0546 3320 ============================================================
10:27:38.0577 3320 C: <-> \Device\Harddisk0\DR0\Partition2
10:27:38.0577 3320 ============================================================
10:27:38.0577 3320 Initialize success
10:27:38.0577 3320 ============================================================
10:28:08.0093 1208 ============================================================
10:28:08.0093 1208 Scan started
10:28:08.0093 1208 Mode: Manual;
10:28:08.0093 1208 ============================================================
10:28:09.0013 1208 ================ Scan system memory ========================
10:28:09.0013 1208 System memory - ok
10:28:09.0013 1208 ================ Scan services =============================
10:28:09.0138 1208 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
10:28:09.0138 1208 1394ohci - ok
10:28:09.0169 1208 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
10:28:09.0185 1208 ACPI - ok
10:28:09.0200 1208 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
10:28:09.0200 1208 AcpiPmi - ok
10:28:09.0278 1208 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
10:28:09.0278 1208 AdobeARMservice - ok
10:28:09.0403 1208 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
10:28:09.0403 1208 AdobeFlashPlayerUpdateSvc - ok
10:28:09.0450 1208 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
10:28:09.0465 1208 adp94xx - ok
10:28:09.0497 1208 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
10:28:09.0497 1208 adpahci - ok
10:28:09.0528 1208 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
10:28:09.0528 1208 adpu320 - ok
10:28:09.0543 1208 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
10:28:09.0543 1208 AeLookupSvc - ok
10:28:09.0590 1208 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
10:28:09.0590 1208 AFD - ok
10:28:09.0606 1208 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
10:28:09.0606 1208 agp440 - ok
10:28:09.0621 1208 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
10:28:09.0621 1208 ALG - ok
10:28:09.0637 1208 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
10:28:09.0637 1208 aliide - ok
10:28:09.0715 1208 [ B3B263B419FC9E7B1D41E61FDAE45BD9 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
10:28:09.0715 1208 AMD External Events Utility - ok
10:28:09.0731 1208 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
10:28:09.0746 1208 amdide - ok
10:28:09.0871 1208 [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys
10:28:09.0902 1208 amdiox64 - ok
10:28:09.0918 1208 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
10:28:09.0933 1208 AmdK8 - ok
10:28:10.0105 1208 [ 9A6E9363F7A5E5A06629D9DDC76EE6B5 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
10:28:10.0214 1208 amdkmdag - ok
10:28:10.0245 1208 [ 957A4C13E1981B1701E600EF1E823C68 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
10:28:10.0245 1208 amdkmdap - ok
10:28:10.0277 1208 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
10:28:10.0277 1208 AmdPPM - ok
10:28:10.0292 1208 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
10:28:10.0292 1208 amdsata - ok
10:28:10.0323 1208 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
10:28:10.0323 1208 amdsbs - ok
10:28:10.0339 1208 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
10:28:10.0339 1208 amdxata - ok
10:28:10.0370 1208 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
10:28:10.0370 1208 AppID - ok
10:28:10.0386 1208 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
10:28:10.0401 1208 AppIDSvc - ok
10:28:10.0417 1208 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
10:28:10.0417 1208 Appinfo - ok
10:28:10.0448 1208 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
10:28:10.0448 1208 AppMgmt - ok
10:28:10.0479 1208 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
10:28:10.0479 1208 arc - ok
10:28:10.0495 1208 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
10:28:10.0495 1208 arcsas - ok
10:28:10.0620 1208 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
10:28:10.0620 1208 aspnet_state - ok
10:28:10.0635 1208 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
10:28:10.0635 1208 AsyncMac - ok
10:28:10.0667 1208 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
10:28:10.0667 1208 atapi - ok
10:28:10.0729 1208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
10:28:10.0745 1208 AudioEndpointBuilder - ok
10:28:10.0760 1208 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
10:28:10.0760 1208 AudioSrv - ok
10:28:10.0791 1208 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
10:28:10.0791 1208 AxInstSV - ok
10:28:10.0823 1208 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
10:28:10.0838 1208 b06bdrv - ok
10:28:10.0854 1208 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
10:28:10.0869 1208 b57nd60a - ok
10:28:10.0916 1208 [ BE7FFC73A049D3696CCB53AEAA2E8C90 ] BackupMaint C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe
10:28:10.0916 1208 BackupMaint - ok
10:28:10.0963 1208 [ F29D375926E36E3A56AF4805C7749302 ] BCUService C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
10:28:10.0963 1208 BCUService - ok
10:28:10.0994 1208 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
10:28:10.0994 1208 BDESVC - ok
10:28:11.0010 1208 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
10:28:11.0010 1208 Beep - ok
10:28:11.0057 1208 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
10:28:11.0057 1208 BFE - ok
10:28:11.0088 1208 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
10:28:11.0088 1208 BITS - ok
10:28:11.0103 1208 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
10:28:11.0103 1208 blbdrive - ok
10:28:11.0150 1208 [ 7525C8CF307AAF9D92E5CF8A62EAC81A ] BlueIris C:\Program Files (x86)\Blue Iris\BlueIrisService.exe
10:28:11.0150 1208 BlueIris - ok
10:28:11.0166 1208 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
10:28:11.0181 1208 bowser - ok
10:28:11.0197 1208 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:28:11.0197 1208 BrFiltLo - ok
10:28:11.0197 1208 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:28:11.0197 1208 BrFiltUp - ok
10:28:11.0213 1208 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
10:28:11.0213 1208 BridgeMP - ok
10:28:11.0244 1208 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
10:28:11.0244 1208 Browser - ok
10:28:11.0259 1208 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
10:28:11.0259 1208 Brserid - ok
10:28:11.0259 1208 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
10:28:11.0275 1208 BrSerWdm - ok
10:28:11.0275 1208 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
10:28:11.0275 1208 BrUsbMdm - ok
10:28:11.0275 1208 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
10:28:11.0275 1208 BrUsbSer - ok
10:28:11.0275 1208 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
10:28:11.0275 1208 BTHMODEM - ok
10:28:11.0291 1208 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
10:28:11.0306 1208 bthserv - ok
10:28:11.0322 1208 catchme - ok
10:28:11.0322 1208 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
10:28:11.0322 1208 cdfs - ok
10:28:11.0353 1208 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
10:28:11.0369 1208 cdrom - ok
10:28:11.0400 1208 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
10:28:11.0400 1208 CertPropSvc - ok
10:28:11.0415 1208 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
10:28:11.0415 1208 circlass - ok
10:28:11.0431 1208 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
10:28:11.0447 1208 CLFS - ok
10:28:11.0493 1208 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:28:11.0493 1208 clr_optimization_v2.0.50727_32 - ok
10:28:11.0540 1208 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:28:11.0540 1208 clr_optimization_v2.0.50727_64 - ok
10:28:11.0603 1208 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:28:11.0618 1208 clr_optimization_v4.0.30319_32 - ok
10:28:11.0634 1208 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
10:28:11.0634 1208 clr_optimization_v4.0.30319_64 - ok
10:28:11.0665 1208 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
10:28:11.0665 1208 CmBatt - ok
10:28:11.0681 1208 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
10:28:11.0681 1208 cmdide - ok
10:28:11.0696 1208 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
10:28:11.0712 1208 CNG - ok
10:28:11.0727 1208 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
10:28:11.0727 1208 Compbatt - ok
10:28:11.0743 1208 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
10:28:11.0743 1208 CompositeBus - ok
10:28:11.0759 1208 COMSysApp - ok
10:28:11.0759 1208 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
10:28:11.0759 1208 crcdisk - ok
10:28:11.0790 1208 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll
10:28:11.0790 1208 CryptSvc - ok
10:28:11.0837 1208 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys
10:28:11.0852 1208 CSC - ok
10:28:11.0868 1208 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll
10:28:11.0883 1208 CscService - ok
10:28:11.0915 1208 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
10:28:11.0915 1208 DcomLaunch - ok
10:28:11.0946 1208 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
10:28:11.0946 1208 defragsvc - ok
10:28:11.0977 1208 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
10:28:11.0977 1208 DfsC - ok
10:28:12.0024 1208 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
10:28:12.0024 1208 Dhcp - ok
10:28:12.0039 1208 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
10:28:12.0039 1208 discache - ok
10:28:12.0071 1208 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
10:28:12.0071 1208 Disk - ok
10:28:12.0086 1208 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
10:28:12.0086 1208 Dnscache - ok
10:28:12.0117 1208 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
10:28:12.0117 1208 dot3svc - ok
10:28:12.0133 1208 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
10:28:12.0133 1208 DPS - ok
10:28:12.0164 1208 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
10:28:12.0164 1208 drmkaud - ok
10:28:12.0180 1208 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
10:28:12.0195 1208 DXGKrnl - ok
10:28:12.0195 1208 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
10:28:12.0211 1208 EapHost - ok
10:28:12.0258 1208 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
10:28:12.0289 1208 ebdrv - ok
10:28:12.0320 1208 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
10:28:12.0320 1208 EFS - ok
10:28:12.0351 1208 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
10:28:12.0351 1208 ehRecvr - ok
10:28:12.0367 1208 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
10:28:12.0367 1208 ehSched - ok
10:28:12.0383 1208 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
10:28:12.0398 1208 elxstor - ok
10:28:12.0398 1208 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
10:28:12.0398 1208 ErrDev - ok
10:28:12.0429 1208 [ B8FA96995726D1FA58476E352C02AD82 ] ES lite Service C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
10:28:12.0429 1208 ES lite Service - ok
10:28:12.0461 1208 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
10:28:12.0476 1208 EventSystem - ok
10:28:12.0492 1208 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
10:28:12.0507 1208 exfat - ok
10:28:12.0507 1208 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
10:28:12.0507 1208 fastfat - ok
10:28:12.0539 1208 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
10:28:12.0554 1208 Fax - ok
10:28:12.0570 1208 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
10:28:12.0570 1208 fdc - ok
10:28:12.0585 1208 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
10:28:12.0585 1208 fdPHost - ok
10:28:12.0601 1208 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
10:28:12.0601 1208 FDResPub - ok
10:28:12.0601 1208 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
10:28:12.0601 1208 FileInfo - ok
10:28:12.0617 1208 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
10:28:12.0617 1208 Filetrace - ok
10:28:12.0679 1208 [ 0B9167ADFE8E42B6B4C5E929BFBC7080 ] FlipShare Service C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
10:28:12.0679 1208 FlipShare Service - ok
10:28:12.0710 1208 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
10:28:12.0710 1208 flpydisk - ok
10:28:12.0741 1208 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
10:28:12.0741 1208 FltMgr - ok
10:28:12.0788 1208 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
10:28:12.0788 1208 FontCache - ok
10:28:12.0835 1208 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:28:12.0835 1208 FontCache3.0.0.0 - ok
10:28:12.0851 1208 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
10:28:12.0851 1208 FsDepends - ok
10:28:12.0882 1208 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
10:28:12.0882 1208 Fs_Rec - ok
10:28:12.0913 1208 [ 35FD2BB5131714E657B7AB3A78642854 ] FTDIBUS C:\Windows\system32\drivers\ftdibus.sys
10:28:12.0929 1208 FTDIBUS - ok
10:28:12.0929 1208 [ 196C9BDDBEF9B6D0973F398BEF5B2EEE ] FTSER2K C:\Windows\system32\drivers\ftser2k.sys
10:28:12.0944 1208 FTSER2K - ok
10:28:12.0975 1208 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
10:28:12.0975 1208 fvevol - ok
10:28:12.0991 1208 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
10:28:13.0007 1208 gagp30kx - ok
10:28:13.0022 1208 [ 7907E14F9BCF3A4689C9A74A1A873CB6 ] gdrv C:\Windows\gdrv.sys
10:28:13.0022 1208 gdrv - ok
10:28:13.0085 1208 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
10:28:13.0100 1208 gpsvc - ok
10:28:13.0163 1208 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:28:13.0163 1208 gupdate - ok
10:28:13.0163 1208 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:28:13.0163 1208 gupdatem - ok
10:28:13.0178 1208 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
10:28:13.0178 1208 hamachi - ok
10:28:13.0272 1208 [ 21D24138B736983F6E23823E092E9428 ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
10:28:13.0287 1208 Hamachi2Svc - ok
10:28:13.0319 1208 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
10:28:13.0319 1208 hcw85cir - ok
10:28:13.0365 1208 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
10:28:13.0381 1208 HdAudAddService - ok
10:28:13.0412 1208 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
10:28:13.0412 1208 HDAudBus - ok
10:28:13.0428 1208 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
10:28:13.0428 1208 HidBatt - ok
10:28:13.0428 1208 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
10:28:13.0428 1208 HidBth - ok
10:28:13.0428 1208 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
10:28:13.0428 1208 HidIr - ok
10:28:13.0443 1208 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
10:28:13.0475 1208 hidserv - ok
10:28:13.0490 1208 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
10:28:13.0490 1208 HidUsb - ok
10:28:13.0521 1208 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
10:28:13.0521 1208 hkmsvc - ok
10:28:13.0553 1208 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
10:28:13.0553 1208 HomeGroupListener - ok
10:28:13.0584 1208 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
10:28:13.0584 1208 HomeGroupProvider - ok
10:28:13.0631 1208 [ D1E9CB573A9EDF7BE12E9C57F32E97F7 ] HP LaserJet Service C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
10:28:13.0631 1208 HP LaserJet Service - ok
10:28:13.0677 1208 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
10:28:13.0677 1208 HpSAMD - ok
10:28:13.0724 1208 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
10:28:13.0724 1208 HTTP - ok
10:28:13.0755 1208 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
10:28:13.0755 1208 hwpolicy - ok
10:28:13.0771 1208 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
10:28:13.0771 1208 i8042prt - ok
10:28:13.0802 1208 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
10:28:13.0802 1208 iaStorV - ok
10:28:13.0849 1208 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:28:13.0865 1208 idsvc - ok
10:28:13.0896 1208 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
10:28:13.0896 1208 iirsp - ok
10:28:13.0911 1208 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
10:28:13.0927 1208 IKEEXT - ok
10:28:13.0989 1208 [ 59B0BBA422F04467E8C89B7CE6AE95E1 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
10:28:14.0021 1208 IntcAzAudAddService - ok
10:28:14.0021 1208 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
10:28:14.0021 1208 intelide - ok
10:28:14.0052 1208 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
10:28:14.0052 1208 intelppm - ok
10:28:14.0083 1208 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
10:28:14.0083 1208 IPBusEnum - ok
10:28:14.0114 1208 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:28:14.0130 1208 IpFilterDriver - ok
10:28:14.0145 1208 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
10:28:14.0161 1208 iphlpsvc - ok
10:28:14.0192 1208 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
10:28:14.0192 1208 IPMIDRV - ok
10:28:14.0208 1208 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
10:28:14.0223 1208 IPNAT - ok
10:28:14.0239 1208 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
10:28:14.0239 1208 IRENUM - ok
10:28:14.0255 1208 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
10:28:14.0255 1208 isapnp - ok
10:28:14.0286 1208 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
10:28:14.0286 1208 iScsiPrt - ok
10:28:14.0364 1208 [ B4CDA1B4263B53D249AC27A4892DA634 ] JMB36X C:\Windows\SysWOW64\XSrvSetup.exe
10:28:14.0364 1208 JMB36X - ok
10:28:14.0379 1208 [ 6EBE4832B1A7C063FDF87035AFC1E3DC ] JRAID C:\Windows\system32\DRIVERS\jraid.sys
10:28:14.0395 1208 JRAID - ok
10:28:14.0411 1208 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
10:28:14.0411 1208 kbdclass - ok
10:28:14.0442 1208 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
10:28:14.0442 1208 kbdhid - ok
10:28:14.0457 1208 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
10:28:14.0457 1208 KeyIso - ok
10:28:14.0473 1208 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
10:28:14.0473 1208 KSecDD - ok
10:28:14.0504 1208 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
10:28:14.0504 1208 KSecPkg - ok
10:28:14.0535 1208 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
10:28:14.0535 1208 ksthunk - ok
10:28:14.0567 1208 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
10:28:14.0567 1208 KtmRm - ok
10:28:14.0598 1208 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
10:28:14.0598 1208 LanmanServer - ok
10:28:14.0613 1208 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
10:28:14.0629 1208 LanmanWorkstation - ok
10:28:14.0707 1208 [ 7772DFAB22611050B79504E671B06E6E ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
10:28:14.0707 1208 LBTServ - ok
10:28:14.0723 1208 [ 241F2648ADF090E2A10095BD6D6F5DCB ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys
10:28:14.0738 1208 LHidFilt - ok
10:28:14.0754 1208 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
10:28:14.0754 1208 lltdio - ok
10:28:14.0769 1208 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
10:28:14.0769 1208 lltdsvc - ok
10:28:14.0801 1208 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
10:28:14.0801 1208 lmhosts - ok
10:28:14.0847 1208 [ EFE7F2D371F88D8F4DAF2FAE1F2B5E18 ] LMIBackupVSSService.exe C:\Program Files (x86)\LogMeIn Backup\LMIBackupVSSServiceX64.exe
10:28:14.0863 1208 LMIBackupVSSService.exe - ok
10:28:14.0941 1208 [ 98B0FCC176DFB711B67651BECB88C445 ] LMIGuardianSvc C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
10:28:14.0941 1208 LMIGuardianSvc - ok
10:28:14.0957 1208 [ 0317335B15FF3BDA8E10197E3434CFC0 ] LMIInfo C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
10:28:14.0957 1208 LMIInfo - ok
10:28:14.0972 1208 [ B712511029CBD68645A90A241FD6AE43 ] LMIMaint C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
10:28:14.0972 1208 LMIMaint - ok
10:28:14.0988 1208 [ 413ECDCFAD9A82804D3674C8D7EEC24E ] lmimirr C:\Windows\system32\DRIVERS\lmimirr.sys
10:28:14.0988 1208 lmimirr - ok
10:28:15.0003 1208 LMIRfsClientNP - ok
10:28:15.0019 1208 [ C57D3FAA50E6F395759FFB7C709BD944 ] LMIRfsDriver C:\Windows\system32\drivers\LMIRfsDriver.sys
10:28:15.0019 1208 LMIRfsDriver - ok
10:28:15.0050 1208 [ 342ED5A4B3326014438F36D22D803737 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys
10:28:15.0066 1208 LMouFilt - ok
10:28:15.0097 1208 [ D3760BC17E1755091B7120CF32DBF56B ] LogMeIn C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
10:28:15.0097 1208 LogMeIn - ok
10:28:15.0191 1208 [ 33BA2BFD2C8BC105C13B4723261559E4 ] LogMeInBackupService.exe C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe
10:28:15.0206 1208 LogMeInBackupService.exe - ok
10:28:15.0222 1208 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
10:28:15.0222 1208 LSI_FC - ok
10:28:15.0253 1208 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
10:28:15.0253 1208 LSI_SAS - ok
10:28:15.0253 1208 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
10:28:15.0253 1208 LSI_SAS2 - ok
10:28:15.0269 1208 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
10:28:15.0269 1208 LSI_SCSI - ok
10:28:15.0284 1208 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
10:28:15.0284 1208 luafv - ok
10:28:15.0315 1208 [ DC8490812A3B72811AE534F423B4C206 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
10:28:15.0315 1208 MBAMProtector - ok
10:28:15.0362 1208 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
10:28:15.0362 1208 MBAMService - ok
10:28:15.0393 1208 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
10:28:15.0393 1208 Mcx2Svc - ok
10:28:15.0456 1208 [ 7CF1B716372B89568AE4C0FE769F5869 ] MDM C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
10:28:15.0456 1208 MDM - ok
10:28:15.0487 1208 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
10:28:15.0487 1208 megasas - ok
10:28:15.0503 1208 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
10:28:15.0518 1208 MegaSR - ok
10:28:15.0534 1208 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
10:28:15.0534 1208 MMCSS - ok
10:28:15.0565 1208 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
10:28:15.0565 1208 Modem - ok
10:28:15.0596 1208 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
10:28:15.0596 1208 monitor - ok
10:28:15.0643 1208 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
10:28:15.0643 1208 mouclass - ok
10:28:15.0659 1208 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
10:28:15.0659 1208 mouhid - ok
10:28:15.0674 1208 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
10:28:15.0690 1208 mountmgr - ok
10:28:15.0721 1208 [ 94C66EDEDCDB6A126880472F9A704D8E ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
10:28:15.0721 1208 MpFilter - ok
10:28:15.0737 1208 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
10:28:15.0737 1208 mpio - ok
10:28:15.0768 1208 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
10:28:15.0783 1208 mpsdrv - ok
10:28:15.0815 1208 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
10:28:15.0830 1208 MpsSvc - ok
10:28:15.0846 1208 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
10:28:15.0846 1208 MRxDAV - ok
10:28:15.0877 1208 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
10:28:15.0877 1208 mrxsmb - ok
10:28:15.0908 1208 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:28:15.0908 1208 mrxsmb10 - ok
10:28:15.0908 1208 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:28:15.0924 1208 mrxsmb20 - ok
10:28:15.0939 1208 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
10:28:15.0939 1208 msahci - ok
10:28:15.0955 1208 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
10:28:15.0955 1208 msdsm - ok
10:28:15.0955 1208 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
10:28:15.0971 1208 MSDTC - ok
10:28:15.0986 1208 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
10:28:15.0986 1208 Msfs - ok
10:28:15.0986 1208 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
10:28:15.0986 1208 mshidkmdf - ok
10:28:16.0002 1208 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
10:28:16.0002 1208 msisadrv - ok
10:28:16.0017 1208 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
10:28:16.0017 1208 MSiSCSI - ok
10:28:16.0033 1208 msiserver - ok
10:28:16.0049 1208 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
10:28:16.0049 1208 MSKSSRV - ok
10:28:16.0095 1208 [ 59FAAF2C83C8169EA20F9E335E418907 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
10:28:16.0095 1208 MsMpSvc - ok
10:28:16.0111 1208 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
10:28:16.0111 1208 MSPCLOCK - ok
10:28:16.0111 1208 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
10:28:16.0111 1208 MSPQM - ok
10:28:16.0142 1208 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
10:28:16.0142 1208 MsRPC - ok
10:28:16.0158 1208 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
10:28:16.0158 1208 mssmbios - ok
10:28:16.0158 1208 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
10:28:16.0158 1208 MSTEE - ok
10:28:16.0173 1208 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
10:28:16.0173 1208 MTConfig - ok
10:28:16.0189 1208 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
10:28:16.0189 1208 Mup - ok
10:28:16.0205 1208 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
10:28:16.0220 1208 napagent - ok
10:28:16.0251 1208 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
10:28:16.0251 1208 NativeWifiP - ok
10:28:16.0283 1208 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys
10:28:16.0298 1208 NDIS - ok
10:28:16.0314 1208 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
10:28:16.0314 1208 NdisCap - ok
10:28:16.0314 1208 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
10:28:16.0314 1208 NdisTapi - ok
10:28:16.0345 1208 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
10:28:16.0345 1208 Ndisuio - ok
10:28:16.0376 1208 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
10:28:16.0392 1208 NdisWan - ok
10:28:16.0423 1208 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
10:28:16.0423 1208 NDProxy - ok
10:28:16.0454 1208 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
10:28:16.0454 1208 Net Driver HPZ12 - ok
10:28:16.0485 1208 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
10:28:16.0485 1208 NetBIOS - ok
10:28:16.0532 1208 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
10:28:16.0532 1208 NetBT - ok
10:28:16.0548 1208 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
10:28:16.0548 1208 Netlogon - ok
10:28:16.0595 1208 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
10:28:16.0595 1208 Netman - ok
10:28:16.0704 1208 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:28:16.0704 1208 NetMsmqActivator - ok
10:28:16.0735 1208 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:28:16.0735 1208 NetPipeActivator - ok
10:28:16.0766 1208 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
10:28:16.0782 1208 netprofm - ok
10:28:16.0782 1208 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:28:16.0797 1208 NetTcpActivator - ok
10:28:16.0797 1208 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:28:16.0797 1208 NetTcpPortSharing - ok
10:28:16.0829 1208 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
10:28:16.0829 1208 nfrd960 - ok
10:28:16.0860 1208 [ 91B4E0273D2F6C24EF845F2B41311289 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
10:28:16.0860 1208 NisDrv - ok
10:28:16.0891 1208 [ 10A43829A9E606AF3EEF25A1C1665923 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
10:28:16.0891 1208 NisSrv - ok
10:28:16.0938 1208 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
10:28:16.0953 1208 NlaSvc - ok
10:28:16.0969 1208 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
10:28:16.0969 1208 Npfs - ok
10:28:16.0985 1208 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
10:28:16.0985 1208 nsi - ok
10:28:17.0000 1208 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
10:28:17.0000 1208 nsiproxy - ok
10:28:17.0047 1208 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
10:28:17.0063 1208 Ntfs - ok
10:28:17.0094 1208 [ D4012918D3A3847B44B888D56BC095D6 ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys
10:28:17.0094 1208 NuidFltr - ok
10:28:17.0109 1208 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
10:28:17.0109 1208 Null - ok
10:28:17.0125 1208 [ A61B0AF4D6B934928CFD1140DEEA5C8D ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
10:28:17.0125 1208 nusb3hub - ok
10:28:17.0141 1208 [ FA4B2F20561BDBCC6B9AC3E3BDCD7E3F ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
10:28:17.0141 1208 nusb3xhc - ok
10:28:17.0172 1208 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
10:28:17.0172 1208 nvraid - ok
10:28:17.0187 1208 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
10:28:17.0187 1208 nvstor - ok
10:28:17.0219 1208 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
10:28:17.0219 1208 nv_agp - ok
10:28:17.0234 1208 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
10:28:17.0250 1208 ohci1394 - ok
10:28:17.0281 1208 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:28:17.0297 1208 ose - ok
10:28:17.0421 1208 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
10:28:17.0453 1208 osppsvc - ok
10:28:17.0468 1208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
10:28:17.0484 1208 p2pimsvc - ok
10:28:17.0499 1208 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
10:28:17.0499 1208 p2psvc - ok
10:28:17.0531 1208 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
10:28:17.0531 1208 Parport - ok
10:28:17.0562 1208 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
10:28:17.0562 1208 partmgr - ok
10:28:17.0577 1208 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
10:28:17.0593 1208 PcaSvc - ok
10:28:17.0609 1208 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
10:28:17.0609 1208 pci - ok
10:28:17.0624 1208 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
10:28:17.0624 1208 pciide - ok
10:28:17.0640 1208 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
10:28:17.0640 1208 pcmcia - ok
10:28:17.0655 1208 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
10:28:17.0655 1208 pcw - ok
10:28:17.0671 1208 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
10:28:17.0671 1208 PEAUTH - ok
10:28:17.0718 1208 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
10:28:17.0733 1208 PeerDistSvc - ok
10:28:17.0749 1208 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
10:28:17.0749 1208 PerfHost - ok
10:28:17.0811 1208 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
10:28:17.0843 1208 pla - ok
10:28:17.0874 1208 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
10:28:17.0874 1208 PlugPlay - ok
10:28:17.0967 1208 [ E9605A180001A6B5551112D91DE92CA1 ] PMBDeviceInfoProvider C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
10:28:17.0967 1208 PMBDeviceInfoProvider - ok
10:28:18.0030 1208 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
10:28:18.0030 1208 Pml Driver HPZ12 - ok
10:28:18.0045 1208 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
10:28:18.0045 1208 PNRPAutoReg - ok
10:28:18.0061 1208 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
10:28:18.0077 1208 PNRPsvc - ok
10:28:18.0108 1208 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
10:28:18.0108 1208 PolicyAgent - ok
10:28:18.0123 1208 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
10:28:18.0123 1208 Power - ok
10:28:18.0155 1208 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
10:28:18.0155 1208 PptpMiniport - ok
10:28:18.0170 1208 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
10:28:18.0186 1208 Processor - ok
10:28:18.0217 1208 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
10:28:18.0217 1208 ProfSvc - ok
10:28:18.0233 1208 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
10:28:18.0233 1208 ProtectedStorage - ok
10:28:18.0264 1208 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
10:28:18.0264 1208 Psched - ok
10:28:18.0326 1208 [ 291E76C02C0994E4E6F1F97A4BCF6C0E ] QBCFMonitorService C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
10:28:18.0326 1208 QBCFMonitorService - ok
10:28:18.0357 1208 [ 6BEE1814470DC12FA20C53DFC3C97EBB ] QBFCService C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
10:28:18.0373 1208 QBFCService - ok
10:28:18.0404 1208 [ 25FC19BADF78B7FB1D835AAC4B0B91A5 ] QBVSS C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
10:28:18.0420 1208 QBVSS - ok
10:28:18.0451 1208 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
10:28:18.0467 1208 ql2300 - ok
10:28:18.0482 1208 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
10:28:18.0498 1208 ql40xx - ok
10:28:18.0591 1208 QuickBooksDB22 - ok
10:28:18.0623 1208 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
10:28:18.0623 1208 QWAVE - ok
10:28:18.0638 1208 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
10:28:18.0638 1208 QWAVEdrv - ok
10:28:18.0638 1208 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
10:28:18.0654 1208 RasAcd - ok
10:28:18.0669 1208 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
10:28:18.0669 1208 RasAgileVpn - ok
10:28:18.0685 1208 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
10:28:18.0685 1208 RasAuto - ok
10:28:18.0716 1208 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
10:28:18.0716 1208 Rasl2tp - ok
10:28:18.0732 1208 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
10:28:18.0732 1208 RasMan - ok
10:28:18.0747 1208 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
10:28:18.0747 1208 RasPppoe - ok
10:28:18.0763 1208 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
10:28:18.0763 1208 RasSstp - ok
10:28:18.0794 1208 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
10:28:18.0794 1208 rdbss - ok
10:28:18.0810 1208 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
10:28:18.0810 1208 rdpbus - ok
10:28:18.0810 1208 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
10:28:18.0810 1208 RDPCDD - ok
10:28:18.0841 1208 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
10:28:18.0841 1208 RDPDR - ok
10:28:18.0857 1208 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
10:28:18.0857 1208 RDPENCDD - ok
10:28:18.0872 1208 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
10:28:18.0872 1208 RDPREFMP - ok
10:28:18.0888 1208 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
10:28:18.0888 1208 RDPWD - ok
10:28:18.0935 1208 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
10:28:18.0935 1208 rdyboost - ok
10:28:18.0950 1208 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
10:28:18.0966 1208 RemoteAccess - ok
10:28:18.0997 1208 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
10:28:18.0997 1208 RemoteRegistry - ok
10:28:19.0013 1208 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
10:28:19.0013 1208 RpcEptMapper - ok
10:28:19.0013 1208 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
10:28:19.0013 1208 RpcLocator - ok
10:28:19.0059 1208 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\System32\rpcss.dll
10:28:19.0059 1208 RpcSs - ok
10:28:19.0075 1208 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
10:28:19.0075 1208 rspndr - ok
10:28:19.0122 1208 [ 34F05C417F038FFA3BEF69B798D7D7DD ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys
10:28:19.0122 1208 RTHDMIAzAudService - ok
10:28:19.0153 1208 [ 3B01789EE4EAEE97F5EB46B711387D5E ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
10:28:19.0153 1208 RTL8167 - ok
10:28:19.0169 1208 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
10:28:19.0169 1208 s3cap - ok
10:28:19.0184 1208 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
10:28:19.0184 1208 SamSs - ok
10:28:19.0215 1208 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
10:28:19.0215 1208 sbp2port - ok
10:28:19.0247 1208 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
10:28:19.0247 1208 SCardSvr - ok
10:28:19.0278 1208 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
10:28:19.0278 1208 scfilter - ok
10:28:19.0309 1208 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
10:28:19.0325 1208 Schedule - ok
10:28:19.0356 1208 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
10:28:19.0356 1208 SCPolicySvc - ok
10:28:19.0371 1208 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
10:28:19.0387 1208 SDRSVC - ok
10:28:19.0418 1208 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
10:28:19.0418 1208 secdrv - ok
10:28:19.0434 1208 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
10:28:19.0434 1208 seclogon - ok
10:28:19.0449 1208 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
10:28:19.0465 1208 SENS - ok
10:28:19.0465 1208 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
10:28:19.0465 1208 SensrSvc - ok
10:28:19.0496 1208 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
10:28:19.0496 1208 Serenum - ok
10:28:19.0512 1208 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
10:28:19.0512 1208 Serial - ok
10:28:19.0543 1208 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
10:28:19.0543 1208 sermouse - ok
10:28:19.0574 1208 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
10:28:19.0574 1208 SessionEnv - ok
10:28:19.0590 1208 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
10:28:19.0590 1208 sffdisk - ok
10:28:19.0605 1208 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
10:28:19.0605 1208 sffp_mmc - ok
10:28:19.0621 1208 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
10:28:19.0621 1208 sffp_sd - ok
10:28:19.0637 1208 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
10:28:19.0637 1208 sfloppy - ok
10:28:19.0668 1208 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
10:28:19.0668 1208 SharedAccess - ok
10:28:19.0683 1208 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
10:28:19.0683 1208 ShellHWDetection - ok
10:28:19.0715 1208 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:28:19.0715 1208 SiSRaid2 - ok
10:28:19.0730 1208 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
10:28:19.0730 1208 SiSRaid4 - ok
10:28:19.0746 1208 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
10:28:19.0746 1208 Smb - ok
10:28:19.0777 1208 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
10:28:19.0777 1208 SNMPTRAP - ok
10:28:19.0777 1208 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
10:28:19.0777 1208 spldr - ok
10:28:19.0808 1208 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
10:28:19.0824 1208 Spooler - ok
10:28:19.0917 1208 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
10:28:19.0949 1208 sppsvc - ok
10:28:19.0995 1208 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
10:28:20.0011 1208 sppuinotify - ok
10:28:20.0089 1208 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
10:28:20.0105 1208 srv - ok
10:28:20.0198 1208 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
10:28:20.0198 1208 srv2 - ok
10:28:20.0214 1208 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
10:28:20.0229 1208 srvnet - ok
10:28:20.0245 1208 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
10:28:20.0261 1208 SSDPSRV - ok
10:28:20.0261 1208 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
10:28:20.0261 1208 SstpSvc - ok
10:28:20.0276 1208 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
10:28:20.0276 1208 stexstor - ok
10:28:20.0307 1208 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
10:28:20.0307 1208 StillCam - ok
10:28:20.0339 1208 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
10:28:20.0339 1208 stisvc - ok
10:28:20.0370 1208 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
10:28:20.0370 1208 storflt - ok
10:28:20.0385 1208 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll
10:28:20.0385 1208 StorSvc - ok
10:28:20.0401 1208 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys
10:28:20.0401 1208 storvsc - ok
10:28:20.0417 1208 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
10:28:20.0417 1208 swenum - ok
10:28:20.0510 1208 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
10:28:20.0510 1208 SwitchBoard - ok
10:28:20.0526 1208 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
10:28:20.0541 1208 swprv - ok
10:28:20.0588 1208 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
10:28:20.0604 1208 SysMain - ok
10:28:20.0635 1208 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
10:28:20.0635 1208 TabletInputService - ok
10:28:20.0651 1208 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
10:28:20.0651 1208 TapiSrv - ok
10:28:20.0666 1208 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
10:28:20.0666 1208 TBS - ok
10:28:20.0729 1208 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
10:28:20.0760 1208 Tcpip - ok
10:28:20.0775 1208 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
10:28:20.0791 1208 TCPIP6 - ok
10:28:20.0822 1208 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
10:28:20.0822 1208 tcpipreg - ok
10:28:20.0838 1208 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
10:28:20.0838 1208 TDPIPE - ok
10:28:20.0853 1208 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
10:28:20.0853 1208 TDTCP - ok
10:28:20.0869 1208 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
10:28:20.0869 1208 tdx - ok
10:28:20.0885 1208 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
10:28:20.0885 1208 TermDD - ok
10:28:20.0916 1208 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
10:28:20.0931 1208 TermService - ok
10:28:20.0963 1208 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
10:28:20.0963 1208 Themes - ok
10:28:20.0994 1208 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
10:28:20.0994 1208 THREADORDER - ok
10:28:21.0009 1208 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
10:28:21.0009 1208 TrkWks - ok
10:28:21.0041 1208 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
10:28:21.0056 1208 TrustedInstaller - ok
10:28:21.0087 1208 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
10:28:21.0087 1208 tssecsrv - ok
10:28:21.0119 1208 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
10:28:21.0134 1208 TsUsbFlt - ok
10:28:21.0165 1208 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
10:28:21.0165 1208 tunnel - ok
10:28:21.0181 1208 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
10:28:21.0181 1208 uagp35 - ok
10:28:21.0197 1208 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
10:28:21.0197 1208 udfs - ok
10:28:21.0228 1208 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
10:28:21.0228 1208 UI0Detect - ok
10:28:21.0243 1208 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
10:28:21.0243 1208 uliagpkx - ok
10:28:21.0275 1208 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
10:28:21.0275 1208 umbus - ok
10:28:21.0290 1208 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
10:28:21.0290 1208 UmPass - ok
10:28:21.0306 1208 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
10:28:21.0306 1208 UmRdpService - ok
10:28:21.0321 1208 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
10:28:21.0321 1208 upnphost - ok
10:28:21.0353 1208 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
10:28:21.0353 1208 usbccgp - ok
10:28:21.0384 1208 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
10:28:21.0384 1208 usbcir - ok
10:28:21.0399 1208 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
10:28:21.0399 1208 usbehci - ok
10:28:21.0431 1208 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
10:28:21.0431 1208 usbhub - ok
10:28:21.0462 1208 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
10:28:21.0462 1208 usbohci - ok
10:28:21.0477 1208 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
10:28:21.0493 1208 usbprint - ok
10:28:21.0540 1208 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:28:21.0540 1208 USBSTOR - ok
10:28:21.0571 1208 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
10:28:21.0571 1208 usbuhci - ok
10:28:21.0602 1208 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
10:28:21.0602 1208 UxSms - ok
10:28:21.0618 1208 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
10:28:21.0618 1208 VaultSvc - ok
10:28:21.0633 1208 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
10:28:21.0633 1208 vdrvroot - ok
10:28:21.0665 1208 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
10:28:21.0665 1208 vds - ok
10:28:21.0680 1208 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
10:28:21.0680 1208 vga - ok
10:28:21.0696 1208 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
10:28:21.0696 1208 VgaSave - ok
10:28:21.0727 1208 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
10:28:21.0727 1208 vhdmp - ok
10:28:21.0743 1208 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
10:28:21.0743 1208 viaide - ok
10:28:21.0774 1208 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
10:28:21.0774 1208 vmbus - ok
10:28:21.0789 1208 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
10:28:21.0789 1208 VMBusHID - ok
10:28:21.0789 1208 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
10:28:21.0789 1208 volmgr - ok
10:28:21.0821 1208 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
10:28:21.0821 1208 volmgrx - ok
10:28:21.0836 1208 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
10:28:21.0852 1208 volsnap - ok
10:28:21.0883 1208 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
10:28:21.0883 1208 vsmraid - ok
10:28:21.0930 1208 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
10:28:21.0945 1208 VSS - ok
10:28:21.0945 1208 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
10:28:21.0945 1208 vwifibus - ok
10:28:21.0977 1208 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
10:28:21.0977 1208 W32Time - ok
10:28:21.0992 1208 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
10:28:21.0992 1208 WacomPen - ok
10:28:22.0039 1208 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
10:28:22.0039 1208 WANARP - ok
10:28:22.0039 1208 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
10:28:22.0039 1208 Wanarpv6 - ok
10:28:22.0086 1208 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
10:28:22.0101 1208 WatAdminSvc - ok
10:28:22.0148 1208 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
10:28:22.0164 1208 wbengine - ok
10:28:22.0179 1208 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
10:28:22.0179 1208 WbioSrvc - ok
10:28:22.0211 1208 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
10:28:22.0211 1208 wcncsvc - ok
10:28:22.0226 1208 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
10:28:22.0226 1208 WcsPlugInService - ok
10:28:22.0242 1208 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
10:28:22.0242 1208 Wd - ok
10:28:22.0257 1208 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
10:28:22.0273 1208 Wdf01000 - ok
10:28:22.0289 1208 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
10:28:22.0289 1208 WdiServiceHost - ok
10:28:22.0289 1208 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
10:28:22.0289 1208 WdiSystemHost - ok
10:28:22.0320 1208 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
10:28:22.0320 1208 WebClient - ok
10:28:22.0335 1208 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
10:28:22.0335 1208 Wecsvc - ok
10:28:22.0351 1208 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
10:28:22.0351 1208 wercplsupport - ok
10:28:22.0382 1208 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
10:28:22.0382 1208 WerSvc - ok
10:28:22.0398 1208 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
10:28:22.0398 1208 WfpLwf - ok
10:28:22.0413 1208 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
10:28:22.0413 1208 WIMMount - ok
10:28:22.0429 1208 WinDefend - ok
10:28:22.0445 1208 WinHttpAutoProxySvc - ok
10:28:22.0491 1208 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
10:28:22.0491 1208 Winmgmt - ok
10:28:22.0538 1208 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
10:28:22.0554 1208 WinRM - ok
10:28:22.0585 1208 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
10:28:22.0585 1208 WinUsb - ok
10:28:22.0616 1208 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
10:28:22.0632 1208 Wlansvc - ok
10:28:22.0647 1208 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
10:28:22.0647 1208 WmiAcpi - ok
10:28:22.0663 1208 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
10:28:22.0663 1208 wmiApSrv - ok
10:28:22.0679 1208 WMPNetworkSvc - ok
10:28:22.0694 1208 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
10:28:22.0694 1208 WPCSvc - ok
10:28:22.0725 1208 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
10:28:22.0725 1208 WPDBusEnum - ok
10:28:22.0757 1208 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
10:28:22.0757 1208 ws2ifsl - ok
10:28:22.0772 1208 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
10:28:22.0772 1208 wscsvc - ok
10:28:22.0819 1208 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
10:28:22.0819 1208 WSDPrintDevice - ok
10:28:22.0819 1208 WSearch - ok
10:28:22.0866 1208 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
10:28:22.0897 1208 wuauserv - ok
10:28:22.0913 1208 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
10:28:22.0913 1208 WudfPf - ok
10:28:22.0944 1208 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
10:28:22.0944 1208 WUDFRd - ok
10:28:22.0959 1208 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
10:28:22.0975 1208 wudfsvc - ok
10:28:22.0991 1208 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
10:28:22.0991 1208 WwanSvc - ok
10:28:23.0006 1208 ================ Scan global ===============================
10:28:23.0037 1208 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
10:28:23.0053 1208 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
10:28:23.0069 1208 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
10:28:23.0084 1208 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
10:28:23.0100 1208 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
10:28:23.0100 1208 [Global] - ok
10:28:23.0100 1208 ================ Scan MBR ==================================
10:28:23.0100 1208 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
10:28:23.0287 1208 \Device\Harddisk0\DR0 - ok
10:28:23.0287 1208 ================ Scan VBR ==================================
10:28:23.0287 1208 [ 453475D7090DD3E0FD476E5DB9A8122E ] \Device\Harddisk0\DR0\Partition1
10:28:23.0303 1208 \Device\Harddisk0\DR0\Partition1 - ok
10:28:23.0303 1208 [ 70ABD2BFE3C435C7DF36D75A5E792DB4 ] \Device\Harddisk0\DR0\Partition2
10:28:23.0303 1208 \Device\Harddisk0\DR0\Partition2 - ok
10:28:23.0303 1208 ============================================================
10:28:23.0303 1208 Scan finished
10:28:23.0303 1208 ============================================================
10:28:23.0318 5236 Detected object count: 0
10:28:23.0318 5236 Actual detected object count: 0
10:29:12.0178 4236 ============================================================
10:29:12.0178 4236 Scan started
10:29:12.0178 4236 Mode: Manual; SigCheck; TDLFS;
10:29:12.0178 4236 ============================================================
10:29:12.0568 4236 ================ Scan system memory ========================
10:29:12.0568 4236 System memory - ok
10:29:12.0583 4236 ================ Scan services =============================
10:29:12.0692 4236 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
10:29:12.0770 4236 1394ohci - ok
10:29:12.0786 4236 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
10:29:12.0802 4236 ACPI - ok
10:29:12.0817 4236 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
10:29:12.0848 4236 AcpiPmi - ok
10:29:12.0926 4236 [ 62B7936F9036DD6ED36E6A7EFA805DC0 ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
10:29:12.0958 4236 AdobeARMservice - ok
10:29:13.0051 4236 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
10:29:13.0082 4236 AdobeFlashPlayerUpdateSvc - ok
10:29:13.0114 4236 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
10:29:13.0129 4236 adp94xx - ok
10:29:13.0145 4236 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
10:29:13.0145 4236 adpahci - ok
10:29:13.0160 4236 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
10:29:13.0176 4236 adpu320 - ok
10:29:13.0192 4236 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
10:29:13.0223 4236 AeLookupSvc - ok
10:29:13.0254 4236 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
10:29:13.0270 4236 AFD - ok
10:29:13.0301 4236 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
10:29:13.0316 4236 agp440 - ok
10:29:13.0332 4236 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
10:29:13.0363 4236 ALG - ok
10:29:13.0394 4236 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
10:29:13.0394 4236 aliide - ok
10:29:13.0426 4236 [ B3B263B419FC9E7B1D41E61FDAE45BD9 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
10:29:13.0472 4236 AMD External Events Utility - ok
10:29:13.0504 4236 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
10:29:13.0504 4236 amdide - ok
10:29:13.0535 4236 [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys
10:29:13.0535 4236 amdiox64 - ok
10:29:13.0550 4236 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
10:29:13.0566 4236 AmdK8 - ok
10:29:13.0722 4236 [ 9A6E9363F7A5E5A06629D9DDC76EE6B5 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
10:29:13.0816 4236 amdkmdag - ok
10:29:13.0831 4236 [ 957A4C13E1981B1701E600EF1E823C68 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
10:29:13.0862 4236 amdkmdap - ok
10:29:13.0894 4236 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
10:29:13.0925 4236 AmdPPM - ok
10:29:13.0956 4236 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
10:29:13.0972 4236 amdsata - ok
10:29:13.0987 4236 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
10:29:14.0003 4236 amdsbs - ok
10:29:14.0003 4236 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
10:29:14.0003 4236 amdxata - ok
10:29:14.0034 4236 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
10:29:14.0112 4236 AppID - ok
10:29:14.0128 4236 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
10:29:14.0174 4236 AppIDSvc - ok
10:29:14.0190 4236 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\Windows\System32\appinfo.dll
10:29:14.0206 4236 Appinfo - ok
10:29:14.0237 4236 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
10:29:14.0252 4236 AppMgmt - ok
10:29:14.0268 4236 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
10:29:14.0284 4236 arc - ok
10:29:14.0299 4236 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
10:29:14.0299 4236 arcsas - ok
10:29:14.0377 4236 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
10:29:14.0393 4236 aspnet_state - ok
10:29:14.0408 4236 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
10:29:14.0440 4236 AsyncMac - ok
10:29:14.0471 4236 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
10:29:14.0502 4236 atapi - ok
10:29:14.0533 4236 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
10:29:14.0580 4236 AudioEndpointBuilder - ok
10:29:14.0596 4236 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
10:29:14.0611 4236 AudioSrv - ok
10:29:14.0642 4236 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
10:29:14.0736 4236 AxInstSV - ok
10:29:14.0752 4236 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
10:29:14.0798 4236 b06bdrv - ok
10:29:14.0814 4236 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
10:29:14.0830 4236 b57nd60a - ok
10:29:14.0861 4236 [ BE7FFC73A049D3696CCB53AEAA2E8C90 ] BackupMaint C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe
10:29:14.0892 4236 BackupMaint - ok
10:29:14.0923 4236 [ F29D375926E36E3A56AF4805C7749302 ] BCUService C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
10:29:14.0939 4236 BCUService - ok
10:29:14.0954 4236 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
10:29:15.0001 4236 BDESVC - ok
10:29:15.0017 4236 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
10:29:15.0064 4236 Beep - ok
10:29:15.0095 4236 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
10:29:15.0126 4236 BFE - ok
10:29:15.0142 4236 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\system32\qmgr.dll
10:29:15.0173 4236 BITS - ok
10:29:15.0188 4236 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
10:29:15.0204 4236 blbdrive - ok
10:29:15.0235 4236 [ 7525C8CF307AAF9D92E5CF8A62EAC81A ] BlueIris C:\Program Files (x86)\Blue Iris\BlueIrisService.exe
10:29:15.0235 4236 BlueIris ( UnsignedFile.Multi.Generic ) - warning
10:29:15.0235 4236 BlueIris - detected UnsignedFile.Multi.Generic (1)
10:29:15.0266 4236 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
10:29:15.0282 4236 bowser - ok
10:29:15.0298 4236 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
10:29:15.0329 4236 BrFiltLo - ok
10:29:15.0344 4236 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
10:29:15.0344 4236 BrFiltUp - ok
10:29:15.0360 4236 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
10:29:15.0391 4236 BridgeMP - ok
10:29:15.0407 4236 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
10:29:15.0422 4236 Browser - ok
10:29:15.0422 4236 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
10:29:15.0469 4236 Brserid - ok
10:29:15.0485 4236 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
10:29:15.0516 4236 BrSerWdm - ok
10:29:15.0516 4236 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
10:29:15.0532 4236 BrUsbMdm - ok
10:29:15.0547 4236 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
10:29:15.0563 4236 BrUsbSer - ok
10:29:15.0563 4236 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
10:29:15.0594 4236 BTHMODEM - ok
10:29:15.0610 4236 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
10:29:15.0641 4236 bthserv - ok
10:29:15.0656 4236 catchme - ok
10:29:15.0656 4236 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
10:29:15.0703 4236 cdfs - ok
10:29:15.0719 4236 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
10:29:15.0750 4236 cdrom - ok
10:29:15.0781 4236 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
10:29:15.0844 4236 CertPropSvc - ok
10:29:15.0859 4236 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
10:29:15.0906 4236 circlass - ok
10:29:15.0937 4236 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
10:29:15.0953 4236 CLFS - ok
10:29:16.0031 4236 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
10:29:16.0062 4236 clr_optimization_v2.0.50727_32 - ok
10:29:16.0202 4236 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
10:29:16.0218 4236 clr_optimization_v2.0.50727_64 - ok
10:29:16.0296 4236 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
10:29:16.0296 4236 clr_optimization_v4.0.30319_32 - ok
10:29:16.0312 4236 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
10:29:16.0327 4236 clr_optimization_v4.0.30319_64 - ok
10:29:16.0358 4236 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
10:29:16.0374 4236 CmBatt - ok
10:29:16.0405 4236 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
10:29:16.0405 4236 cmdide - ok
10:29:16.0436 4236 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\Windows\system32\Drivers\cng.sys
10:29:16.0452 4236 CNG - ok
10:29:16.0468 4236 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
10:29:16.0468 4236 Compbatt - ok
10:29:16.0483 4236 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
10:29:16.0514 4236 CompositeBus - ok
10:29:16.0514 4236 COMSysApp - ok
10:29:16.0530 4236 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
10:29:16.0530 4236 crcdisk - ok
10:29:16.0561 4236 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\Windows\system32\cryptsvc.dll
10:29:16.0577 4236 CryptSvc - ok
10:29:16.0592 4236 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys
10:29:16.0639 4236 CSC - ok
10:29:16.0670 4236 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll
10:29:16.0717 4236 CscService - ok
10:29:16.0748 4236 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
10:29:16.0795 4236 DcomLaunch - ok
10:29:16.0811 4236 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
10:29:16.0826 4236 defragsvc - ok
10:29:16.0858 4236 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
10:29:16.0889 4236 DfsC - ok
10:29:16.0920 4236 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
10:29:16.0951 4236 Dhcp - ok
10:29:16.0982 4236 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
10:29:16.0998 4236 discache - ok
10:29:16.0998 4236 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
10:29:17.0014 4236 Disk - ok
10:29:17.0029 4236 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
10:29:17.0076 4236 Dnscache - ok
10:29:17.0092 4236 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
10:29:17.0170 4236 dot3svc - ok
10:29:17.0185 4236 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
10:29:17.0216 4236 DPS - ok
10:29:17.0248 4236 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
10:29:17.0294 4236 drmkaud - ok
10:29:17.0326 4236 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
10:29:17.0357 4236 DXGKrnl - ok
10:29:17.0372 4236 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
10:29:17.0404 4236 EapHost - ok
10:29:17.0497 4236 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
10:29:17.0560 4236 ebdrv - ok
10:29:17.0591 4236 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
10:29:17.0622 4236 EFS - ok
10:29:17.0638 4236 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
10:29:17.0700 4236 ehRecvr - ok
10:29:17.0716 4236 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\Windows\ehome\ehsched.exe
10:29:17.0778 4236 ehSched - ok
10:29:17.0840 4236 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
10:29:17.0872 4236 elxstor - ok
10:29:17.0887 4236 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
10:29:17.0903 4236 ErrDev - ok
10:29:17.0934 4236 [ B8FA96995726D1FA58476E352C02AD82 ] ES lite Service C:\Program Files (x86)\Gigabyte\EasySaver\ESSVR.EXE
10:29:17.0965 4236 ES lite Service - ok
10:29:17.0996 4236 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
10:29:18.0028 4236 EventSystem - ok
10:29:18.0043 4236 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
10:29:18.0074 4236 exfat - ok
10:29:18.0074 4236 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
10:29:18.0152 4236 fastfat - ok
10:29:18.0184 4236 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
10:29:18.0230 4236 Fax - ok
10:29:18.0262 4236 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
10:29:18.0293 4236 fdc - ok
10:29:18.0308 4236 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
10:29:18.0340 4236 fdPHost - ok
10:29:18.0355 4236 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
10:29:18.0386 4236 FDResPub - ok
10:29:18.0402 4236 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
10:29:18.0402 4236 FileInfo - ok
10:29:18.0418 4236 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
10:29:18.0449 4236 Filetrace - ok
10:29:18.0511 4236 [ 0B9167ADFE8E42B6B4C5E929BFBC7080 ] FlipShare Service C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
10:29:18.0542 4236 FlipShare Service - ok
10:29:18.0558 4236 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
10:29:18.0574 4236 flpydisk - ok
10:29:18.0589 4236 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
10:29:18.0605 4236 FltMgr - ok
10:29:18.0636 4236 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\Windows\system32\FntCache.dll
10:29:18.0683 4236 FontCache - ok
10:29:18.0730 4236 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
10:29:18.0730 4236 FontCache3.0.0.0 - ok
10:29:18.0745 4236 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
10:29:18.0776 4236 FsDepends - ok
10:29:18.0792 4236 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
10:29:18.0808 4236 Fs_Rec - ok
10:29:18.0823 4236 [ 35FD2BB5131714E657B7AB3A78642854 ] FTDIBUS C:\Windows\system32\drivers\ftdibus.sys
10:29:18.0839 4236 FTDIBUS - ok
10:29:18.0854 4236 [ 196C9BDDBEF9B6D0973F398BEF5B2EEE ] FTSER2K C:\Windows\system32\drivers\ftser2k.sys
10:29:18.0854 4236 FTSER2K - ok
10:29:18.0886 4236 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
10:29:18.0901 4236 fvevol - ok
10:29:18.0917 4236 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
10:29:18.0917 4236 gagp30kx - ok
10:29:18.0948 4236 [ 7907E14F9BCF3A4689C9A74A1A873CB6 ] gdrv C:\Windows\gdrv.sys
10:29:18.0948 4236 gdrv - ok
10:29:18.0979 4236 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
10:29:19.0010 4236 gpsvc - ok
10:29:19.0057 4236 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:29:19.0057 4236 gupdate - ok
10:29:19.0057 4236 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
10:29:19.0073 4236 gupdatem - ok
10:29:19.0088 4236 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
10:29:19.0088 4236 hamachi - ok
10:29:19.0151 4236 [ 21D24138B736983F6E23823E092E9428 ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
10:29:19.0182 4236 Hamachi2Svc - ok
10:29:19.0213 4236 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
10:29:19.0260 4236 hcw85cir - ok
10:29:19.0291 4236 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
10:29:19.0307 4236 HdAudAddService - ok
10:29:19.0322 4236 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
10:29:19.0338 4236 HDAudBus - ok
10:29:19.0338 4236 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
10:29:19.0354 4236 HidBatt - ok
10:29:19.0354 4236 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
10:29:19.0369 4236 HidBth - ok
10:29:19.0385 4236 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
10:29:19.0416 4236 HidIr - ok
10:29:19.0447 4236 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
10:29:19.0510 4236 hidserv - ok
10:29:19.0525 4236 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
10:29:19.0541 4236 HidUsb - ok
10:29:19.0556 4236 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
10:29:19.0634 4236 hkmsvc - ok
10:29:19.0666 4236 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
10:29:19.0697 4236 HomeGroupListener - ok
10:29:19.0728 4236 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
10:29:19.0759 4236 HomeGroupProvider - ok
10:29:19.0806 4236 [ D1E9CB573A9EDF7BE12E9C57F32E97F7 ] HP LaserJet Service C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
10:29:19.0806 4236 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - warning
10:29:19.0806 4236 HP LaserJet Service - detected UnsignedFile.Multi.Generic (1)
10:29:19.0837 4236 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
10:29:19.0868 4236 HpSAMD - ok
10:29:19.0900 4236 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
10:29:19.0946 4236 HTTP - ok
10:29:19.0962 4236 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
10:29:19.0978 4236 hwpolicy - ok
10:29:19.0993 4236 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
10:29:19.0993 4236 i8042prt - ok
10:29:20.0009 4236 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
10:29:20.0024 4236 iaStorV - ok
10:29:20.0056 4236 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
10:29:20.0071 4236 idsvc - ok
10:29:20.0087 4236 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
10:29:20.0102 4236 iirsp - ok
10:29:20.0118 4236 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
10:29:20.0165 4236 IKEEXT - ok
10:29:20.0227 4236 [ 59B0BBA422F04467E8C89B7CE6AE95E1 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
10:29:20.0274 4236 IntcAzAudAddService - ok
10:29:20.0290 4236 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
10:29:20.0290 4236 intelide - ok
10:29:20.0305 4236 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
10:29:20.0336 4236 intelppm - ok
10:29:20.0368 4236 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
10:29:20.0414 4236 IPBusEnum - ok
10:29:20.0446 4236 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
10:29:20.0477 4236 IpFilterDriver - ok
10:29:20.0492 4236 [ A34A587FFFD45FA649FBA6D03784D257 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
10:29:20.0539 4236 iphlpsvc - ok
10:29:20.0555 4236 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
10:29:20.0586 4236 IPMIDRV - ok
10:29:20.0617 4236 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
10:29:20.0680 4236 IPNAT - ok
10:29:20.0695 4236 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
10:29:20.0726 4236 IRENUM - ok
10:29:20.0726 4236 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
10:29:20.0742 4236 isapnp - ok
10:29:20.0758 4236 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
10:29:20.0758 4236 iScsiPrt - ok
10:29:20.0836 4236 [ B4CDA1B4263B53D249AC27A4892DA634 ] JMB36X C:\Windows\SysWOW64\XSrvSetup.exe
10:29:20.0836 4236 JMB36X ( UnsignedFile.Multi.Generic ) - warning
10:29:20.0836 4236 JMB36X - detected UnsignedFile.Multi.Generic (1)
10:29:20.0851 4236 [ 6EBE4832B1A7C063FDF87035AFC1E3DC ] JRAID C:\Windows\system32\DRIVERS\jraid.sys
10:29:20.0851 4236 JRAID - ok
10:29:20.0867 4236 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
10:29:20.0867 4236 kbdclass - ok
10:29:20.0882 4236 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
10:29:20.0898 4236 kbdhid - ok
10:29:20.0914 4236 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
10:29:20.0914 4236 KeyIso - ok
10:29:20.0929 4236 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
10:29:20.0945 4236 KSecDD - ok
10:29:20.0960 4236 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
10:29:20.0976 4236 KSecPkg - ok
10:29:20.0992 4236 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
10:29:21.0023 4236 ksthunk - ok
10:29:21.0054 4236 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
10:29:21.0085 4236 KtmRm - ok
10:29:21.0101 4236 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
10:29:21.0179 4236 LanmanServer - ok
10:29:21.0194 4236 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
10:29:21.0272 4236 LanmanWorkstation - ok
10:29:21.0335 4236 [ 7772DFAB22611050B79504E671B06E6E ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
10:29:21.0382 4236 LBTServ - ok
10:29:21.0397 4236 [ 241F2648ADF090E2A10095BD6D6F5DCB ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys
10:29:21.0413 4236 LHidFilt - ok
10:29:21.0428 4236 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
10:29:21.0475 4236 lltdio - ok
10:29:21.0506 4236 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
10:29:21.0553 4236 lltdsvc - ok
10:29:21.0569 4236 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
10:29:21.0584 4236 lmhosts - ok
10:29:21.0616 4236 [ EFE7F2D371F88D8F4DAF2FAE1F2B5E18 ] LMIBackupVSSService.exe C:\Program Files (x86)\LogMeIn Backup\LMIBackupVSSServiceX64.exe
10:29:21.0631 4236 LMIBackupVSSService.exe - ok
10:29:21.0694 4236 [ 98B0FCC176DFB711B67651BECB88C445 ] LMIGuardianSvc C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
10:29:21.0725 4236 LMIGuardianSvc - ok
10:29:21.0725 4236 [ 0317335B15FF3BDA8E10197E3434CFC0 ] LMIInfo C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
10:29:21.0740 4236 LMIInfo - ok
10:29:21.0756 4236 [ B712511029CBD68645A90A241FD6AE43 ] LMIMaint C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
10:29:21.0756 4236 LMIMaint - ok
10:29:21.0772 4236 [ 413ECDCFAD9A82804D3674C8D7EEC24E ] lmimirr C:\Windows\system32\DRIVERS\lmimirr.sys
10:29:21.0787 4236 lmimirr - ok
10:29:21.0787 4236 LMIRfsClientNP - ok
10:29:21.0787 4236 [ C57D3FAA50E6F395759FFB7C709BD944 ] LMIRfsDriver C:\Windows\system32\drivers\LMIRfsDriver.sys
10:29:21.0803 4236 LMIRfsDriver - ok
10:29:21.0834 4236 [ 342ED5A4B3326014438F36D22D803737 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys
10:29:21.0834 4236 LMouFilt - ok
10:29:21.0865 4236 [ D3760BC17E1755091B7120CF32DBF56B ] LogMeIn C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
10:29:21.0881 4236 LogMeIn - ok
10:29:21.0928 4236 [ 33BA2BFD2C8BC105C13B4723261559E4 ] LogMeInBackupService.exe C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe
10:29:21.0959 4236 LogMeInBackupService.exe - ok
10:29:21.0974 4236 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
10:29:21.0974 4236 LSI_FC - ok
10:29:22.0006 4236 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
10:29:22.0006 4236 LSI_SAS - ok
10:29:22.0021 4236 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
10:29:22.0037 4236 LSI_SAS2 - ok
10:29:22.0037 4236 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
10:29:22.0037 4236 LSI_SCSI - ok
10:29:22.0052 4236 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
10:29:22.0084 4236 luafv - ok
10:29:22.0115 4236 [ DC8490812A3B72811AE534F423B4C206 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
10:29:22.0130 4236 MBAMProtector - ok
10:29:22.0162 4236 [ 43683E970F008C93C9429EF428147A54 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
10:29:22.0193 4236 MBAMService - ok
10:29:22.0224 4236 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
10:29:22.0224 4236 Mcx2Svc - ok
10:29:22.0286 4236 [ 7CF1B716372B89568AE4C0FE769F5869 ] MDM C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
10:29:22.0302 4236 MDM ( UnsignedFile.Multi.Generic ) - warning
10:29:22.0302 4236 MDM - detected UnsignedFile.Multi.Generic (1)
10:29:22.0349 4236 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
10:29:22.0364 4236 megasas - ok
10:29:22.0380 4236 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
10:29:22.0396 4236 MegaSR - ok
10:29:22.0411 4236 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
10:29:22.0458 4236 MMCSS - ok
10:29:22.0474 4236 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
10:29:22.0552 4236 Modem - ok
10:29:22.0583 4236 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
10:29:22.0598 4236 monitor - ok
10:29:22.0630 4236 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
10:29:22.0630 4236 mouclass - ok
10:29:22.0645 4236 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
10:29:22.0661 4236 mouhid - ok
10:29:22.0676 4236 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
10:29:22.0692 4236 mountmgr - ok
10:29:22.0708 4236 [ 94C66EDEDCDB6A126880472F9A704D8E ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
10:29:22.0723 4236 MpFilter - ok
10:29:22.0739 4236 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
10:29:22.0754 4236 mpio - ok
10:29:22.0786 4236 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
10:29:22.0801 4236 mpsdrv - ok
10:29:22.0832 4236 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
10:29:22.0864 4236 MpsSvc - ok
10:29:22.0879 4236 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
10:29:22.0926 4236 MRxDAV - ok
10:29:22.0973 4236 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
10:29:23.0020 4236 mrxsmb - ok
10:29:23.0051 4236 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
10:29:23.0082 4236 mrxsmb10 - ok
10:29:23.0098 4236 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
10:29:23.0113 4236 mrxsmb20 - ok
10:29:23.0129 4236 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
10:29:23.0144 4236 msahci - ok
10:29:23.0144 4236 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
10:29:23.0160 4236 msdsm - ok
10:29:23.0176 4236 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
10:29:23.0191 4236 MSDTC - ok
10:29:23.0207 4236 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
10:29:23.0238 4236 Msfs - ok
10:29:23.0238 4236 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
10:29:23.0285 4236 mshidkmdf - ok
10:29:23.0300 4236 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
10:29:23.0300 4236 msisadrv - ok
10:29:23.0316 4236 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
10:29:23.0363 4236 MSiSCSI - ok
10:29:23.0363 4236 msiserver - ok
10:29:23.0378 4236 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
10:29:23.0394 4236 MSKSSRV - ok
10:29:23.0425 4236 [ 59FAAF2C83C8169EA20F9E335E418907 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
10:29:23.0441 4236 MsMpSvc - ok
10:29:23.0441 4236 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
10:29:23.0472 4236 MSPCLOCK - ok
10:29:23.0472 4236 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
10:29:23.0503 4236 MSPQM - ok
10:29:23.0534 4236 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
10:29:23.0534 4236 MsRPC - ok
10:29:23.0550 4236 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
10:29:23.0566 4236 mssmbios - ok
10:29:23.0566 4236 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
10:29:23.0612 4236 MSTEE - ok
10:29:23.0612 4236 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
10:29:23.0612 4236 MTConfig - ok
10:29:23.0644 4236 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
10:29:23.0644 4236 Mup - ok
10:29:23.0675 4236 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
10:29:23.0690 4236 napagent - ok
10:29:23.0706 4236 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
10:29:23.0722 4236 NativeWifiP - ok
10:29:23.0753 4236 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\Windows\system32\drivers\ndis.sys
10:29:23.0768 4236 NDIS - ok
10:29:23.0784 4236 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
10:29:23.0815 4236 NdisCap - ok
10:29:23.0815 4236 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
10:29:23.0846 4236 NdisTapi - ok
10:29:23.0862 4236 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
10:29:23.0893 4236 Ndisuio - ok
10:29:23.0909 4236 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
10:29:23.0987 4236 NdisWan - ok
10:29:24.0018 4236 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
10:29:24.0049 4236 NDProxy - ok
10:29:24.0065 4236 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll
10:29:24.0065 4236 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
10:29:24.0065 4236 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
10:29:24.0080 4236 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
10:29:24.0112 4236 NetBIOS - ok
10:29:24.0127 4236 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
10:29:24.0174 4236 NetBT - ok
10:29:24.0190 4236 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
10:29:24.0190 4236 Netlogon - ok
10:29:24.0221 4236 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
10:29:24.0268 4236 Netman - ok
10:29:24.0330 4236 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:29:24.0346 4236 NetMsmqActivator - ok
10:29:24.0346 4236 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:29:24.0377 4236 NetPipeActivator - ok
10:29:24.0392 4236 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
10:29:24.0439 4236 netprofm - ok
10:29:24.0439 4236 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:29:24.0455 4236 NetTcpActivator - ok
10:29:24.0455 4236 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
10:29:24.0455 4236 NetTcpPortSharing - ok
10:29:24.0486 4236 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
10:29:24.0486 4236 nfrd960 - ok
10:29:24.0517 4236 [ 91B4E0273D2F6C24EF845F2B41311289 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
10:29:24.0517 4236 NisDrv - ok
10:29:24.0533 4236 [ 10A43829A9E606AF3EEF25A1C1665923 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
10:29:24.0548 4236 NisSrv - ok
10:29:24.0580 4236 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\Windows\System32\nlasvc.dll
10:29:24.0611 4236 NlaSvc - ok
10:29:24.0626 4236 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
10:29:24.0658 4236 Npfs - ok
10:29:24.0673 4236 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
10:29:24.0689 4236 nsi - ok
10:29:24.0704 4236 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
10:29:24.0720 4236 nsiproxy - ok
10:29:24.0767 4236 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
10:29:24.0798 4236 Ntfs - ok
10:29:24.0814 4236 [ D4012918D3A3847B44B888D56BC095D6 ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys
10:29:24.0814 4236 NuidFltr - ok
10:29:24.0829 4236 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
10:29:24.0845 4236 Null - ok
10:29:24.0876 4236 [ A61B0AF4D6B934928CFD1140DEEA5C8D ] nusb3hub C:\Windows\system32\DRIVERS\nusb3hub.sys
10:29:24.0907 4236 nusb3hub - ok
10:29:24.0938 4236 [ FA4B2F20561BDBCC6B9AC3E3BDCD7E3F ] nusb3xhc C:\Windows\system32\DRIVERS\nusb3xhc.sys
10:29:24.0954 4236 nusb3xhc - ok
10:29:24.0985 4236 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
10:29:25.0001 4236 nvraid - ok
10:29:25.0001 4236 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
10:29:25.0016 4236 nvstor - ok
10:29:25.0032 4236 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
10:29:25.0048 4236 nv_agp - ok
10:29:25.0063 4236 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
10:29:25.0079 4236 ohci1394 - ok
10:29:25.0110 4236 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
10:29:25.0110 4236 ose - ok
10:29:25.0235 4236 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
10:29:25.0282 4236 osppsvc - ok
10:29:25.0313 4236 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
10:29:25.0360 4236 p2pimsvc - ok
10:29:25.0375 4236 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
10:29:25.0391 4236 p2psvc - ok
10:29:25.0406 4236 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
10:29:25.0406 4236 Parport - ok
10:29:25.0422 4236 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
10:29:25.0438 4236 partmgr - ok
10:29:25.0453 4236 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
10:29:25.0469 4236 PcaSvc - ok
10:29:25.0484 4236 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
10:29:25.0484 4236 pci - ok
10:29:25.0516 4236 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
10:29:25.0516 4236 pciide - ok
10:29:25.0531 4236 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
10:29:25.0531 4236 pcmcia - ok
10:29:25.0547 4236 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
10:29:25.0562 4236 pcw - ok
10:29:25.0578 4236 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
10:29:25.0625 4236 PEAUTH - ok
10:29:25.0672 4236 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
10:29:25.0718 4236 PeerDistSvc - ok
10:29:25.0734 4236 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
10:29:25.0781 4236 PerfHost - ok
10:29:25.0874 4236 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
10:29:25.0937 4236 pla - ok
10:29:25.0968 4236 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
10:29:26.0015 4236 PlugPlay - ok
10:29:26.0108 4236 [ E9605A180001A6B5551112D91DE92CA1 ] PMBDeviceInfoProvider C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
10:29:26.0124 4236 PMBDeviceInfoProvider - ok
10:29:26.0140 4236 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll
10:29:26.0140 4236 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
10:29:26.0140 4236 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
10:29:26.0171 4236 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
10:29:26.0202 4236 PNRPAutoReg - ok
10:29:26.0233 4236 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
10:29:26.0249 4236 PNRPsvc - ok
10:29:26.0311 4236 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
10:29:26.0405 4236 PolicyAgent - ok
10:29:26.0420 4236 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
10:29:26.0530 4236 Power - ok
10:29:26.0561 4236 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
10:29:26.0608 4236 PptpMiniport - ok
10:29:26.0623 4236 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
10:29:26.0654 4236 Processor - ok
10:29:26.0670 4236 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
10:29:26.0732 4236 ProfSvc - ok
10:29:26.0748 4236 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
10:29:26.0764 4236 ProtectedStorage - ok
10:29:26.0779 4236 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
10:29:26.0810 4236 Psched - ok
10:29:26.0857 4236 [ 291E76C02C0994E4E6F1F97A4BCF6C0E ] QBCFMonitorService C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
10:29:26.0873 4236 QBCFMonitorService ( UnsignedFile.Multi.Generic ) - warning
10:29:26.0873 4236 QBCFMonitorService - detected UnsignedFile.Multi.Generic (1)
10:29:26.0920 4236 [ 6BEE1814470DC12FA20C53DFC3C97EBB ] QBFCService C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
10:29:26.0935 4236 QBFCService ( UnsignedFile.Multi.Generic ) - warning
10:29:26.0935 4236 QBFCService - detected UnsignedFile.Multi.Generic (1)
10:29:26.0982 4236 [ 25FC19BADF78B7FB1D835AAC4B0B91A5 ] QBVSS C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
10:29:27.0013 4236 QBVSS ( UnsignedFile.Multi.Generic ) - warning
10:29:27.0013 4236 QBVSS - detected UnsignedFile.Multi.Generic (1)
10:29:27.0060 4236 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
10:29:27.0091 4236 ql2300 - ok
10:29:27.0122 4236 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
10:29:27.0122 4236 ql40xx - ok
10:29:27.0154 4236 QuickBooksDB22 - ok
10:29:27.0185 4236 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
10:29:27.0185 4236 QWAVE - ok
10:29:27.0200 4236 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
10:29:27.0232 4236 QWAVEdrv - ok
10:29:27.0247 4236 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
10:29:27.0310 4236 RasAcd - ok
10:29:27.0325 4236 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
10:29:27.0341 4236 RasAgileVpn - ok
10:29:27.0356 4236 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
10:29:27.0388 4236 RasAuto - ok
10:29:27.0419 4236 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
10:29:27.0434 4236 Rasl2tp - ok
10:29:27.0450 4236 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
10:29:27.0466 4236 RasMan - ok
10:29:27.0497 4236 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
10:29:27.0512 4236 RasPppoe - ok
10:29:27.0528 4236 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
10:29:27.0544 4236 RasSstp - ok
10:29:27.0575 4236 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
10:29:27.0590 4236 rdbss - ok
10:29:27.0590 4236 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
10:29:27.0622 4236 rdpbus - ok
10:29:27.0637 4236 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
10:29:27.0684 4236 RDPCDD - ok
10:29:27.0715 4236 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
10:29:27.0746 4236 RDPDR - ok
10:29:27.0746 4236 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
10:29:27.0793 4236 RDPENCDD - ok
10:29:27.0809 4236 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
10:29:27.0824 4236 RDPREFMP - ok
10:29:27.0856 4236 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
10:29:27.0871 4236 RDPWD - ok
10:29:27.0902 4236 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
10:29:27.0902 4236 rdyboost - ok
10:29:27.0934 4236 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
10:29:27.0996 4236 RemoteAccess - ok
10:29:28.0027 4236 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
10:29:28.0043 4236 RemoteRegistry - ok
10:29:28.0058 4236 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
10:29:28.0090 4236 RpcEptMapper - ok
10:29:28.0105 4236 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
10:29:28.0121 4236 RpcLocator - ok
10:29:28.0136 4236 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\System32\rpcss.dll
10:29:28.0199 4236 RpcSs - ok
10:29:28.0214 4236 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
10:29:28.0246 4236 rspndr - ok
10:29:28.0261 4236 [ 34F05C417F038FFA3BEF69B798D7D7DD ] RTHDMIAzAudService C:\Windows\system32\drivers\RtHDMIVX.sys
10:29:28.0308 4236 RTHDMIAzAudService - ok
10:29:28.0339 4236 [ 3B01789EE4EAEE97F5EB46B711387D5E ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
10:29:28.0370 4236 RTL8167 - ok
10:29:28.0402 4236 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
10:29:28.0448 4236 s3cap - ok
10:29:28.0464 4236 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
10:29:28.0464 4236 SamSs - ok
10:29:28.0495 4236 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
10:29:28.0511 4236 sbp2port - ok
10:29:28.0526 4236 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
10:29:28.0573 4236 SCardSvr - ok
10:29:28.0604 4236 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
10:29:28.0651 4236 scfilter - ok
10:29:28.0682 4236 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
10:29:28.0714 4236 Schedule - ok
10:29:28.0745 4236 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
10:29:28.0760 4236 SCPolicySvc - ok
10:29:28.0776 4236 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
10:29:28.0823 4236 SDRSVC - ok
10:29:28.0838 4236 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
10:29:28.0854 4236 secdrv - ok
10:29:28.0870 4236 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
10:29:28.0901 4236 seclogon - ok
10:29:28.0932 4236 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
10:29:28.0948 4236 SENS - ok
10:29:28.0963 4236 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
10:29:28.0979 4236 SensrSvc - ok
10:29:28.0979 4236 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
10:29:28.0994 4236 Serenum - ok
10:29:29.0026 4236 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
10:29:29.0026 4236 Serial - ok
10:29:29.0057 4236 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
10:29:29.0072 4236 sermouse - ok
10:29:29.0104 4236 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
10:29:29.0166 4236 SessionEnv - ok
10:29:29.0197 4236 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
10:29:29.0244 4236 sffdisk - ok
10:29:29.0260 4236 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
10:29:29.0260 4236 sffp_mmc - ok
10:29:29.0275 4236 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
10:29:29.0291 4236 sffp_sd - ok
10:29:29.0291 4236 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
10:29:29.0306 4236 sfloppy - ok
10:29:29.0322 4236 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
10:29:29.0353 4236 SharedAccess - ok
10:29:29.0369 4236 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
10:29:29.0400 4236 ShellHWDetection - ok
10:29:29.0416 4236 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
10:29:29.0416 4236 SiSRaid2 - ok
10:29:29.0431 4236 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
10:29:29.0431 4236 SiSRaid4 - ok
10:29:29.0431 4236 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
10:29:29.0462 4236 Smb - ok
10:29:29.0478 4236 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
10:29:29.0494 4236 SNMPTRAP - ok
10:29:29.0509 4236 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
10:29:29.0525 4236 spldr - ok
10:29:29.0556 4236 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
10:29:29.0556 4236 Spooler - ok
10:29:29.0634 4236 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
10:29:29.0728 4236 sppsvc - ok
10:29:29.0728 4236 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
10:29:29.0774 4236 sppuinotify - ok
10:29:29.0806 4236 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
10:29:29.0837 4236 srv - ok
10:29:29.0868 4236 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
10:29:29.0899 4236 srv2 - ok
10:29:29.0915 4236 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
10:29:29.0930 4236 srvnet - ok
10:29:29.0962 4236 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
10:29:29.0977 4236 SSDPSRV - ok
10:29:29.0993 4236 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
10:29:30.0024 4236 SstpSvc - ok
10:29:30.0024 4236 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
10:29:30.0040 4236 stexstor - ok
10:29:30.0055 4236 [ DECACB6921DED1A38642642685D77DAC ] StillCam C:\Windows\system32\DRIVERS\serscan.sys
10:29:30.0102 4236 StillCam - ok
10:29:30.0133 4236 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
10:29:30.0180 4236 stisvc - ok
10:29:30.0211 4236 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
10:29:30.0227 4236 storflt - ok
10:29:30.0258 4236 [ C40841817EF57D491F22EB103DA587CC ] StorSvc C:\Windows\system32\storsvc.dll
10:29:30.0274 4236 StorSvc - ok
10:29:30.0289 4236 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys
10:29:30.0305 4236 storvsc - ok
10:29:30.0305 4236 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
10:29:30.0320 4236 swenum - ok
10:29:30.0383 4236 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
10:29:30.0430 4236 SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
10:29:30.0430 4236 SwitchBoard - detected UnsignedFile.Multi.Generic (1)
10:29:30.0461 4236 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
10:29:30.0554 4236 swprv - ok
10:29:30.0617 4236 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
10:29:30.0695 4236 SysMain - ok
10:29:30.0726 4236 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
10:29:30.0757 4236 TabletInputService - ok
10:29:30.0773 4236 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
10:29:30.0804 4236 TapiSrv - ok
10:29:30.0835 4236 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
10:29:30.0851 4236 TBS - ok
10:29:30.0898 4236 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
10:29:30.0913 4236 Tcpip - ok
10:29:30.0929 4236 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
10:29:30.0960 4236 TCPIP6 - ok
10:29:30.0976 4236 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
10:29:31.0007 4236 tcpipreg - ok
10:29:31.0022 4236 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
10:29:31.0069 4236 TDPIPE - ok
10:29:31.0085 4236 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
10:29:31.0132 4236 TDTCP - ok
10:29:31.0163 4236 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
10:29:31.0194 4236 tdx - ok
10:29:31.0210 4236 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
10:29:31.0225 4236 TermDD - ok
10:29:31.0241 4236 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
10:29:31.0256 4236 TermService - ok
10:29:31.0288 4236 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
10:29:31.0319 4236 Themes - ok
10:29:31.0350 4236 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
10:29:31.0381 4236 THREADORDER - ok
10:29:31.0381 4236 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
10:29:31.0412 4236 TrkWks - ok
10:29:31.0475 4236 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
10:29:31.0506 4236 TrustedInstaller - ok
10:29:31.0553 4236 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
10:29:31.0631 4236 tssecsrv - ok
10:29:31.0662 4236 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
10:29:31.0693 4236 TsUsbFlt - ok
10:29:31.0756 4236 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
10:29:31.0787 4236 tunnel - ok
10:29:31.0802 4236 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
10:29:31.0802 4236 uagp35 - ok
10:29:31.0865 4236 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
10:29:31.0927 4236 udfs - ok
10:29:31.0943 4236 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
10:29:31.0958 4236 UI0Detect - ok
10:29:31.0990 4236 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
10:29:31.0990 4236 uliagpkx - ok
10:29:32.0005 4236 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
10:29:32.0021 4236 umbus - ok
10:29:32.0036 4236 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
10:29:32.0036 4236 UmPass - ok
10:29:32.0052 4236 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
10:29:32.0083 4236 UmRdpService - ok
10:29:32.0099 4236 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
10:29:32.0130 4236 upnphost - ok
10:29:32.0161 4236 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
10:29:32.0192 4236 usbccgp - ok
10:29:32.0224 4236 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
10:29:32.0239 4236 usbcir - ok
10:29:32.0239 4236 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
10:29:32.0255 4236 usbehci - ok
10:29:32.0286 4236 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
10:29:32.0317 4236 usbhub - ok
10:29:32.0333 4236 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
10:29:32.0364 4236 usbohci - ok
10:29:32.0380 4236 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
10:29:32.0426 4236 usbprint - ok
10:29:32.0458 4236 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
10:29:32.0473 4236 USBSTOR - ok
10:29:32.0489 4236 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
10:29:32.0504 4236 usbuhci - ok
10:29:32.0536 4236 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
10:29:32.0582 4236 UxSms - ok
10:29:32.0598 4236 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
10:29:32.0598 4236 VaultSvc - ok
10:29:32.0614 4236 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
10:29:32.0614 4236 vdrvroot - ok
10:29:32.0660 4236 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
10:29:32.0707 4236 vds - ok
10:29:32.0723 4236 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
10:29:32.0738 4236 vga - ok
10:29:32.0738 4236 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
10:29:32.0785 4236 VgaSave - ok
10:29:32.0816 4236 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
10:29:32.0816 4236 vhdmp - ok
10:29:32.0848 4236 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
10:29:32.0848 4236 viaide - ok
10:29:32.0863 4236 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
10:29:32.0879 4236 vmbus - ok
10:29:32.0879 4236 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
10:29:32.0894 4236 VMBusHID - ok
10:29:32.0894 4236 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
10:29:32.0910 4236 volmgr - ok
10:29:32.0941 4236 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
10:29:32.0941 4236 volmgrx - ok
10:29:32.0957 4236 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
10:29:32.0972 4236 volsnap - ok
10:29:32.0988 4236 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
10:29:32.0988 4236 vsmraid - ok
10:29:33.0035 4236 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
10:29:33.0082 4236 VSS - ok
10:29:33.0097 4236 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
10:29:33.0113 4236 vwifibus - ok
10:29:33.0128 4236 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
10:29:33.0160 4236 W32Time - ok
10:29:33.0175 4236 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
10:29:33.0175 4236 WacomPen - ok
10:29:33.0191 4236 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
10:29:33.0222 4236 WANARP - ok
10:29:33.0222 4236 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
10:29:33.0253 4236 Wanarpv6 - ok
10:29:33.0300 4236 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
10:29:33.0331 4236 WatAdminSvc - ok
10:29:33.0378 4236 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
10:29:33.0425 4236 wbengine - ok
10:29:33.0440 4236 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
10:29:33.0456 4236 WbioSrvc - ok
10:29:33.0487 4236 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
10:29:33.0518 4236 wcncsvc - ok
10:29:33.0534 4236 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
10:29:33.0550 4236 WcsPlugInService - ok
10:29:33.0550 4236 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
10:29:33.0565 4236 Wd - ok
10:29:33.0581 4236 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
10:29:33.0596 4236 Wdf01000 - ok
10:29:33.0596 4236 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
10:29:33.0674 4236 WdiServiceHost - ok
10:29:33.0674 4236 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
10:29:33.0690 4236 WdiSystemHost - ok
10:29:33.0706 4236 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
10:29:33.0737 4236 WebClient - ok
10:29:33.0768 4236 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
10:29:33.0799 4236 Wecsvc - ok
10:29:33.0815 4236 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
10:29:33.0846 4236 wercplsupport - ok
10:29:33.0846 4236 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
10:29:33.0893 4236 WerSvc - ok
10:29:33.0924 4236 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
10:29:33.0940 4236 WfpLwf - ok
10:29:33.0955 4236 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
10:29:33.0955 4236 WIMMount - ok
10:29:33.0955 4236 WinDefend - ok
10:29:33.0971 4236 WinHttpAutoProxySvc - ok
10:29:34.0002 4236 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
10:29:34.0033 4236 Winmgmt - ok
10:29:34.0096 4236 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
10:29:34.0127 4236 WinRM - ok
10:29:34.0142 4236 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
10:29:34.0142 4236 WinUsb - ok
10:29:34.0174 4236 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
10:29:34.0236 4236 Wlansvc - ok
10:29:34.0267 4236 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
10:29:34.0283 4236 WmiAcpi - ok
10:29:34.0298 4236 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
10:29:34.0330 4236 wmiApSrv - ok
10:29:34.0345 4236 WMPNetworkSvc - ok
10:29:34.0376 4236 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
10:29:34.0376 4236 WPCSvc - ok
10:29:34.0408 4236 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
10:29:34.0408 4236 WPDBusEnum - ok
10:29:34.0423 4236 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
10:29:34.0439 4236 ws2ifsl - ok
10:29:34.0454 4236 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
10:29:34.0486 4236 wscsvc - ok
10:29:34.0517 4236 [ 8D918B1DB190A4D9B1753A66FA8C96E8 ] WSDPrintDevice C:\Windows\system32\DRIVERS\WSDPrint.sys
10:29:34.0564 4236 WSDPrintDevice - ok
10:29:34.0579 4236 WSearch - ok
10:29:34.0626 4236 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
10:29:34.0673 4236 wuauserv - ok
10:29:34.0688 4236 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
10:29:34.0735 4236 WudfPf - ok
10:29:34.0751 4236 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
10:29:34.0766 4236 WUDFRd - ok
10:29:34.0798 4236 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
10:29:34.0813 4236 wudfsvc - ok
10:29:34.0829 4236 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\Windows\System32\wwansvc.dll
10:29:34.0860 4236 WwanSvc - ok
10:29:34.0860 4236 ================ Scan global ===============================
10:29:34.0891 4236 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
10:29:34.0907 4236 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
10:29:34.0922 4236 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\Windows\system32\winsrv.dll
10:29:34.0954 4236 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
10:29:34.0954 4236 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
10:29:34.0969 4236 [Global] - ok
10:29:34.0969 4236 ================ Scan MBR ==================================
10:29:34.0969 4236 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
10:29:35.0219 4236 \Device\Harddisk0\DR0 - ok
10:29:35.0219 4236 ================ Scan VBR ==================================
10:29:35.0219 4236 [ 453475D7090DD3E0FD476E5DB9A8122E ] \Device\Harddisk0\DR0\Partition1
10:29:35.0219 4236 \Device\Harddisk0\DR0\Partition1 - ok
10:29:35.0250 4236 [ 70ABD2BFE3C435C7DF36D75A5E792DB4 ] \Device\Harddisk0\DR0\Partition2
10:29:35.0250 4236 \Device\Harddisk0\DR0\Partition2 - ok
10:29:35.0250 4236 ============================================================
10:29:35.0250 4236 Scan finished
10:29:35.0250 4236 ============================================================
10:29:35.0281 5660 Detected object count: 10
10:29:35.0281 5660 Actual detected object count: 10
10:31:36.0181 5660 BlueIris ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0181 5660 BlueIris ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0181 5660 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0181 5660 HP LaserJet Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 JMB36X ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 JMB36X ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 MDM ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 MDM ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 QBCFMonitorService ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 QBCFMonitorService ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 QBFCService ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 QBFCService ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 QBVSS ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 QBVSS ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:31:36.0197 5660 SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
10:31:36.0197 5660 SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip
10:32:44.0919 4036 Deinitialize success
  • 0

#6
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Step 4 Malware Bytes:

Malwarebytes Anti-Malware (Trial) 1.62.0.1300
www.malwarebytes.org

Database version: v2012.08.20.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Rob Lutz :: RJL8 [administrator]

Protection: Disabled

8/20/2012 10:41:22 AM
mbam-log-2012-08-20 (10-41-22).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 200366
Time elapsed: 2 minute(s), 37 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
  • 0

#7
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Step 5 Event Viewers:

Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 20/08/2012 11:19:09 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 20/08/2012 2:58:14 PM
Type: Error Category: 2
Event: 4 Source: QuickBooks
An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Log: 'Application' Date/Time: 20/08/2012 2:58:14 PM
Type: Error Category: 2
Event: 4 Source: QuickBooks
An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Log: 'Application' Date/Time: 20/08/2012 2:58:14 PM
Type: Error Category: 2
Event: 4 Source: QuickBooks
An unexpected error has occured in "QuickBooks":
Returning NULL QBWinInstance Handle

Log: 'Application' Date/Time: 20/08/2012 2:56:56 PM
Type: Error Category: 1
Event: 104 Source: LogMeIn Guardian
LogMeIn Guardian has detected a problem with the LogMeIn software installed on this machine. The problem is locally identified by the following reference ID: 'a09f9ccaf7ba0019a058396888500fd0'.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 20/08/2012 2:55:07 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-98966919-3431210009-1179794609-1000:
Process 640 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-98966919-3431210009-1179794609-1000
Process 640 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-98966919-3431210009-1179794609-1000
Process 640 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-98966919-3431210009-1179794609-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 640 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-98966919-3431210009-1179794609-1000\Software\Microsoft\SystemCertificates\My
Process 640 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-98966919-3431210009-1179794609-1000\Software\Microsoft\SystemCertificates\CA


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++


Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 20/08/2012 11:17:39 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 20/08/2012 2:59:22 PM
Type: Error Category: 0
Event: 8032 Source: BROWSER
The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{ACCEC188-9853-406C-8461-E90D246B5915}. The backup browser is stopping.

Log: 'System' Date/Time: 20/08/2012 2:57:54 PM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

Log: 'System' Date/Time: 20/08/2012 2:57:02 PM
Type: Error Category: 0
Event: 7034 Source: Service Control Manager
The LogMeIn service terminated unexpectedly. It has done this 1 time(s).

Log: 'System' Date/Time: 20/08/2012 2:55:29 PM
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (30000 milliseconds) while waiting for the LogMeIn Backup Storage PC Service service to connect.

Log: 'System' Date/Time: 20/08/2012 2:55:29 PM
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (30000 milliseconds) while waiting for the LogMeIn Backup Storage PC Service service to connect.

Log: 'System' Date/Time: 20/08/2012 2:55:28 PM
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (30000 milliseconds) while waiting for the LogMeIn Backup Storage PC Service service to connect.

Log: 'System' Date/Time: 20/08/2012 2:55:28 PM
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (30000 milliseconds) while waiting for the LogMeIn Backup Storage PC Service service to connect.

Log: 'System' Date/Time: 20/08/2012 2:55:27 PM
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (30000 milliseconds) while waiting for the LogMeIn Backup Storage PC Service service to connect.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 20/08/2012 2:58:22 PM
Type: Warning Category: 0
Event: 8021 Source: BROWSER
The browser service was unable to retrieve a list of servers from the browser master \\RJLSERVER on the network \Device\NetBT_Tcpip_{ACCEC188-9853-406C-8461-E90D246B5915}. Browser master: \\RJLSERVER Network: \Device\NetBT_Tcpip_{ACCEC188-9853-406C-8461-E90D246B5915} This event may be caused by a temporary loss of network connectivity. If this message appears again, verify that the server is still connected to the network. The return code is in the Data text box.

Log: 'System' Date/Time: 20/08/2012 2:56:20 PM
Type: Warning Category: 0
Event: 1 Source: RTL8167
Realtek PCIe GBE Family Controller is disconnected from network.
  • 0

#8
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
And Step 6 OTL Logs:

OTL logfile created on: 8/20/2012 12:01:12 PM - Run 2
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Users\Rob Lutz\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 48.55% Memory free
8.00 Gb Paging File | 5.81 Gb Available in Paging File | 72.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 822.28 Gb Free Space | 88.28% Space Free | Partition Type: NTFS
Drive P: | 465.66 Gb Total Space | 379.10 Gb Free Space | 81.41% Space Free | Partition Type: NTFS
Drive Q: | 465.66 Gb Total Space | 379.10 Gb Free Space | 81.41% Space Free | Partition Type: NTFS
Drive U: | 465.66 Gb Total Space | 379.10 Gb Free Space | 81.41% Space Free | Partition Type: NTFS

Computer Name: RJL8 | User Name: Rob Lutz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Rob Lutz\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE (Intuit Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Blue Iris\blueiris.exe (Perspective Software)
PRC - C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\LogMeIn Backup\BackupSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Program Files (x86)\Blue Iris\BlueIrisService.exe ()
PRC - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
PRC - C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\LogMeIn Backup\LMIGuardian.exe (LogMeIn, Inc.)
PRC - C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
PRC - C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
PRC - C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe ()
PRC - C:\Windows\SysWOW64\XSrvSetup.exe ()
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3421b96c2885b8e4137a376ff3d95fa5\System.Deployment.ni.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\QBMAPILibrary.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\QBCompressor.DLL ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\mbpopup.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_serialization-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_regex-vc90-mt-p-1_33.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\BackupLib.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Intuit\QuickBooks 2012\zlib1.dll ()
MOD - C:\Program Files (x86)\HP\ToolboxFX\bin\NativeUtils.dll ()
MOD - C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (NisSrv) -- c:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (LMIMaint) -- C:\Program Files (x86)\LogMeIn\x64\ramaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (QBCFMonitorService) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (LogMeInBackupService.exe) -- C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe (LogMeIn, Inc.)
SRV - (LMIBackupVSSService.exe) -- C:\Program Files (x86)\LogMeIn Backup\lmibackupvssserviceX64.exe (LogMeIn, Inc.)
SRV - (BackupMaint) -- C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe (LogMeIn, Inc.)
SRV - (QBVSS) -- C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (QBFCService) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (QuickBooksDB22) -- C:\Program Files (x86)\Intuit\QuickBooks 2012\QBDBMgrN.exe (Intuit, Inc.)
SRV - (BlueIris) -- C:\Program Files (x86)\Blue Iris\BlueIrisService.exe ()
SRV - (PMBDeviceInfoProvider) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (LogMeIn) -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (HP LaserJet Service) -- C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe (HP)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (FlipShare Service) -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe ()
SRV - (ES lite Service) -- C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe ()
SRV - (JMB36X) -- C:\Windows\SysWOW64\XSrvSetup.exe ()
SRV - (BCUService) -- C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe (DeviceVM, Inc.)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (LMIRfsClientNP) -- C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (FTDIBUS) -- C:\Windows\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (FTSER2K) -- C:\Windows\SysNative\drivers\ftser2k.sys (FTDI Ltd.)
DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (LMouFilt) -- C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) -- C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (JRAID) -- C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (nusb3xhc) -- C:\Windows\SysNative\drivers\nusb3xhc.sys (NEC Electronics Corporation)
DRV:64bit: - (nusb3hub) -- C:\Windows\SysNative\drivers\nusb3hub.sys (NEC Electronics Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (RTHDMIAzAudService) -- C:\Windows\SysNative\drivers\RtHDMIVX.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (NuidFltr) -- C:\Windows\SysNative\drivers\nuidfltr.sys (Microsoft Corporation)
DRV:64bit: - (LMIRfsDriver) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) -- C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV - (gdrv) -- C:\Windows\gdrv.sys (Windows ® Server 2003 DDK provider)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (LMIInfo) -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = C3 4A 9C 7B FE 7B CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{19E81170-BEB0-4f39-85B5-A54536EE6989}: "URL" = http://search.yahoo....cevm&type=STDVM
IE - HKCU\..\SearchScopes\{81CE5430-D21E-4cc4-AC5E-054611FE9B1B}: "URL" = http://www.bing.com/...=SPLBR2&pc=SPLH
IE - HKCU\..\SearchScopes\{FB737EB6-3A3E-4e1b-B76B-4311552E3765}: "URL" = http://www.google.co...2788:4067623346
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_32: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/06/25 10:17:25 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2012/08/20 10:18:24 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (PE_IE_Helper Class) - {0941C58F-E461-4E03-BD7D-44C27392ADE1} - C:\Program Files (x86)\IBM\Lotus Forms\Viewer\3.5\PEhelper.dll (IBM Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [HP LaserJet M1522 MFP Series Fax] C:\Program Files (x86)\HP\hp LaserJet M1522\hppfaxprintersrv.exe (Hewlett-Packard Company)
O4:64bit: - HKLM..\Run: [HP LaserJet Professional M1530 MFP Series Fax] C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe (Hewlett-Packard Company)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCU] C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe (DeviceVM, Inc.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [LogMeIn Backup GUI] C:\Program Files (x86)\LogMeIn Backup\BackupSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ToolboxFX] C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe (Hewlett-Packard Company)
O4 - Startup: C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Blue Iris.lnk = C:\Program Files (x86)\Blue Iris\blueiris.exe (Perspective Software)
O4 - Startup: C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} http://download.giga...bject/Dldrv.ocx (Dldrv2 Control)
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} http://webiq005.webi...6-6D5536C585C9} (WebIQ Engine Application Object)
O16 - DPF: {33704B0F-9EB7-434B-B752-EA6CFFB87423} http://98.235.110.16...00/JpegInst.cab (pmjpegaudio Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.aka...5.4.logging.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://qb.webex.com...ra/ieatgpc1.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {EAEFAD15-8753-45EF-94B0-1BAA7970CC21} http://98.235.63.116:1100/MpegInst.cab (pmpeg4cam Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...trl.cab?lmi=928 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{799DB236-0B3B-40B9-AF2C-E90BB876816C}: DhcpNameServer = 10.1.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACCEC188-9853-406C-8461-E90D246B5915}: DhcpNameServer = 10.1.10.1
O18:64bit: - Protocol\Handler\intu-help-qb5 - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/20 10:40:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/20 10:40:18 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/08/20 10:40:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/20 10:24:32 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/08/20 10:18:31 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/08/20 10:05:10 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/08/20 10:05:10 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/08/20 10:05:10 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/08/20 10:05:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/08/20 10:04:47 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/17 10:34:34 | 000,596,992 | ---- | C] (OldTimer Tools) -- C:\Users\Rob Lutz\Desktop\OTL.exe
[2012/08/17 10:23:07 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Roaming\Malwarebytes
[2012/08/17 10:22:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/17 10:20:34 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\Desktop\Malware
[2012/08/16 03:03:22 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/08/16 03:03:22 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/08/16 03:03:22 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/08/16 03:03:21 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/08/16 03:03:21 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/08/16 03:03:20 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/08/16 03:03:20 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/08/16 03:03:20 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/08/16 03:03:20 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/08/16 03:03:19 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/08/16 03:03:19 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/08/16 03:03:18 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/08/16 03:03:18 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/08/15 21:36:41 | 000,503,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\srcore.dll
[2012/08/15 21:31:03 | 000,751,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2012/08/15 21:31:03 | 000,492,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2012/08/15 21:31:02 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\splwow64.exe
[2012/08/15 21:30:40 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\netapi32.dll
[2012/08/15 21:30:40 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\browcli.dll
[2012/08/15 21:30:40 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\browcli.dll
[2012/08/15 21:30:39 | 000,956,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\localspl.dll
[2012/08/15 16:16:18 | 000,000,000 | R--D | C] -- C:\Users\Rob Lutz\Dropbox
[2012/08/15 16:14:30 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/08/15 16:10:01 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Roaming\Dropbox
[2012/08/13 13:00:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2012/08/13 12:59:43 | 000,000,000 | ---D | C] -- C:\Users\Rob Lutz\AppData\Local\Google
[2012/08/13 12:59:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2012/07/28 00:09:20 | 005,538,984 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdag.dll
[2012/07/28 00:07:44 | 010,278,912 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmdag.sys
[2012/07/27 23:43:12 | 000,070,144 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst_8.982.dll
[2012/07/27 23:19:34 | 024,935,424 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atio6axx.dll
[2012/07/27 22:50:10 | 020,546,560 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atioglxx.dll
[2012/07/27 22:15:50 | 000,163,840 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiapfxx.exe
[2012/07/27 22:15:42 | 000,931,328 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\aticfx32.dll
[2012/07/27 22:10:40 | 000,442,368 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\ATIDEMGX.dll
[2012/07/27 22:10:34 | 000,534,528 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2012/07/27 22:09:44 | 000,239,616 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2012/07/27 22:08:20 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2012/07/27 22:08:04 | 000,021,504 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2012/07/27 22:07:58 | 000,059,392 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\SysNative\atiedu64.dll
[2012/07/27 22:07:52 | 000,043,520 | ---- | C] (ATI Technologies, Inc.) -- C:\Windows\SysWow64\ati2edxx.dll
[2012/07/27 22:07:10 | 006,430,208 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atidxx32.dll
[2012/07/27 21:41:32 | 004,266,496 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd6a.dll
[2012/07/27 21:35:10 | 000,051,200 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalrt64.dll
[2012/07/27 21:35:08 | 000,046,080 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalrt.dll
[2012/07/27 21:35:02 | 000,044,544 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalcl64.dll
[2012/07/27 21:35:00 | 000,044,032 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalcl.dll
[2012/07/27 21:34:48 | 016,034,304 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticaldd64.dll
[2012/07/27 21:32:32 | 004,751,872 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdva.dll
[2012/07/27 21:30:10 | 013,605,888 | ---- | C] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticaldd.dll
[2012/07/27 21:25:52 | 006,676,480 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd64.dll
[2012/07/27 21:15:32 | 000,540,160 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiadlxx.dll
[2012/07/27 21:15:22 | 000,368,640 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atiadlxy.dll
[2012/07/27 21:15:12 | 000,017,920 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6pxx.dll
[2012/07/27 21:15:08 | 000,014,848 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiglpxx.dll
[2012/07/27 21:15:08 | 000,014,848 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiglpxx.dll
[2012/07/27 21:15:04 | 000,041,984 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6txx.dll
[2012/07/27 21:14:56 | 000,033,280 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atigktxx.dll
[2012/07/27 21:14:46 | 000,368,640 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmpag.sys
[2012/07/27 21:13:48 | 000,109,568 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiuxpag.dll
[2012/07/27 21:13:40 | 000,103,936 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiu9p64.dll
[2012/07/27 21:12:54 | 000,053,248 | ---- | C] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\ati2erec.dll
[2012/07/27 21:08:42 | 000,056,320 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atimpc64.dll
[2012/07/27 21:08:42 | 000,056,320 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdpcom64.dll
[2012/07/27 21:08:36 | 000,056,832 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atimpc32.dll
[2012/07/27 21:08:36 | 000,056,832 | ---- | C] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdpcom32.dll
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/08/20 11:18:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/20 11:14:19 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/20 11:04:21 | 000,015,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/20 11:04:21 | 000,015,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/20 10:57:10 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/20 10:56:39 | 000,025,640 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\Windows\gdrv.sys
[2012/08/20 10:56:24 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/20 10:56:11 | 3220,037,632 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/20 10:40:19 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/20 10:18:24 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/08/17 10:34:46 | 000,596,992 | ---- | M] (OldTimer Tools) -- C:\Users\Rob Lutz\Desktop\OTL.exe
[2012/08/16 03:24:25 | 005,107,480 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/15 16:16:18 | 000,001,038 | ---- | M] () -- C:\Users\Rob Lutz\Desktop\Dropbox.lnk
[2012/08/15 16:14:56 | 000,001,048 | ---- | M] () -- C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/08/15 12:18:24 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/08/15 12:18:24 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/08/14 12:58:05 | 000,201,934 | ---- | M] () -- C:\Users\Rob Lutz\Desktop\4394 Chambers Hill Rd, Harrisburg, PA 17111 - Bing Maps.mht
[2012/08/13 16:00:26 | 000,083,874 | ---- | M] () -- C:\Users\Rob Lutz\Desktop\Josh Kramer.jpg
[2012/08/13 13:00:33 | 000,002,212 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2012/07/28 00:09:20 | 005,538,984 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdag.dll
[2012/07/28 00:07:44 | 010,278,912 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmdag.sys
[2012/07/27 23:43:12 | 000,070,144 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst_8.982.dll
[2012/07/27 23:19:34 | 024,935,424 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atio6axx.dll
[2012/07/27 22:50:10 | 020,546,560 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atioglxx.dll
[2012/07/27 22:17:00 | 000,268,728 | ---- | M] () -- C:\Windows\SysWow64\atiapfxx.blb
[2012/07/27 22:17:00 | 000,268,728 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb
[2012/07/27 22:15:50 | 000,163,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiapfxx.exe
[2012/07/27 22:15:42 | 000,931,328 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\aticfx32.dll
[2012/07/27 22:13:56 | 001,100,288 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\aticfx64.dll
[2012/07/27 22:10:40 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\ATIDEMGX.dll
[2012/07/27 22:10:34 | 000,534,528 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2012/07/27 22:09:44 | 000,239,616 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2012/07/27 22:08:20 | 000,120,320 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2012/07/27 22:08:04 | 000,021,504 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2012/07/27 22:07:58 | 000,059,392 | ---- | M] (ATI Technologies, Inc.) -- C:\Windows\SysNative\atiedu64.dll
[2012/07/27 22:07:52 | 000,043,520 | ---- | M] (ATI Technologies, Inc.) -- C:\Windows\SysWow64\ati2edxx.dll
[2012/07/27 22:07:10 | 006,430,208 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atidxx32.dll
[2012/07/27 21:51:12 | 007,052,288 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atidxx64.dll
[2012/07/27 21:41:32 | 004,266,496 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd6a.dll
[2012/07/27 21:39:50 | 003,150,560 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap
[2012/07/27 21:35:10 | 000,051,200 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalrt64.dll
[2012/07/27 21:35:08 | 000,046,080 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalrt.dll
[2012/07/27 21:35:02 | 000,044,544 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticalcl64.dll
[2012/07/27 21:35:00 | 000,044,032 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticalcl.dll
[2012/07/27 21:34:48 | 016,034,304 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysNative\aticaldd64.dll
[2012/07/27 21:32:32 | 004,751,872 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiumdva.dll
[2012/07/27 21:30:54 | 003,187,136 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap
[2012/07/27 21:30:10 | 013,605,888 | ---- | M] (Advanced Micro Devices Inc.) -- C:\Windows\SysWow64\aticaldd.dll
[2012/07/27 21:25:52 | 006,676,480 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiumd64.dll
[2012/07/27 21:15:32 | 000,540,160 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\atiadlxx.dll
[2012/07/27 21:15:22 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysWow64\atiadlxy.dll
[2012/07/27 21:15:12 | 000,017,920 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6pxx.dll
[2012/07/27 21:15:08 | 000,014,848 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiglpxx.dll
[2012/07/27 21:15:08 | 000,014,848 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiglpxx.dll
[2012/07/27 21:15:04 | 000,041,984 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atig6txx.dll
[2012/07/27 21:14:56 | 000,033,280 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atigktxx.dll
[2012/07/27 21:14:46 | 000,368,640 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\atikmpag.sys
[2012/07/27 21:13:54 | 000,129,536 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiuxp64.dll
[2012/07/27 21:13:48 | 000,109,568 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiuxpag.dll
[2012/07/27 21:13:40 | 000,103,936 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atiu9p64.dll
[2012/07/27 21:13:32 | 000,083,456 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atiu9pag.dll
[2012/07/27 21:12:54 | 000,053,248 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Windows\SysNative\drivers\ati2erec.dll
[2012/07/27 21:08:42 | 000,056,320 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\atimpc64.dll
[2012/07/27 21:08:42 | 000,056,320 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysNative\amdpcom64.dll
[2012/07/27 21:08:36 | 000,056,832 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\atimpc32.dll
[2012/07/27 21:08:36 | 000,056,832 | ---- | M] (Advanced Micro Devices, Inc. ) -- C:\Windows\SysWow64\amdpcom32.dll
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/08/20 10:40:19 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/20 10:05:10 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/08/20 10:05:10 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/08/20 10:05:10 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/08/20 10:05:10 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/08/20 10:05:10 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/08/15 16:16:18 | 000,001,038 | ---- | C] () -- C:\Users\Rob Lutz\Desktop\Dropbox.lnk
[2012/08/15 16:14:56 | 000,001,048 | ---- | C] () -- C:\Users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/08/14 12:58:04 | 000,201,934 | ---- | C] () -- C:\Users\Rob Lutz\Desktop\4394 Chambers Hill Rd, Harrisburg, PA 17111 - Bing Maps.mht
[2012/08/13 16:02:44 | 000,083,874 | ---- | C] () -- C:\Users\Rob Lutz\Desktop\Josh Kramer.jpg
[2012/08/13 13:00:33 | 000,002,212 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2012/08/13 12:59:50 | 000,000,902 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/13 12:59:49 | 000,000,898 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/08 10:28:32 | 000,001,097 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Content Viewer.lnk
[2012/07/27 22:17:00 | 000,268,728 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2012/07/27 22:17:00 | 000,268,728 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2012/07/27 21:39:50 | 003,150,560 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2012/07/27 21:30:54 | 003,187,136 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2012/03/09 00:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 00:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/01/31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011/09/12 18:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/19 21:26:28 | 000,667,280 | ---- | C] () -- C:\Windows\SysWow64\tx12.dll
[2011/08/19 21:26:28 | 000,000,530 | ---- | C] () -- C:\Windows\SysWow64\tx12_ic.ini
[2011/08/19 21:26:28 | 000,000,186 | ---- | C] () -- C:\Windows\SysWow64\Gsw32.exe.config
[2011/03/25 11:11:07 | 000,833,024 | ---- | C] () -- C:\Windows\SysWow64\user.dat
[2010/10/28 13:35:43 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2010/10/09 16:27:00 | 000,800,364 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/04/26 13:58:19 | 000,003,584 | ---- | C] () -- C:\Users\Rob Lutz\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== Custom Scans ==========

========== Drive Information ==========

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HDS721010CLA332 ATA Device
Partitions: 2
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 0.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 105906176
Hidden sectors: 0


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\assembly\GAC_32\*.ini >

< %systemroot%\assembly\GAC_64\*.ini >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*.exe >

< %APPDATA%\*. >
[2012/06/21 17:46:11 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Adobe
[2011/11/10 11:04:26 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Apple Computer
[2010/03/23 18:12:27 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\ATI
[2010/05/07 18:34:58 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/29 17:50:23 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2012/06/14 11:41:52 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/05/07 18:16:39 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Download Manager
[2012/08/20 10:58:18 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Dropbox
[2012/06/20 16:19:07 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\GlobalSCAPE
[2011/03/28 12:20:32 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Hewlett-Packard Company
[2010/03/25 16:47:46 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\HP
[2012/08/13 09:52:53 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\HpUpdate
[2010/03/23 15:21:06 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Identities
[2010/04/09 12:40:38 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Leadertech
[2012/05/14 15:07:40 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Logishrd
[2012/05/14 15:07:37 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Logitech
[2010/03/23 15:30:44 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Macromedia
[2012/08/17 10:23:07 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Malwarebytes
[2009/07/14 03:45:37 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Media Center Programs
[2012/06/18 15:08:26 | 000,000,000 | --SD | M] -- C:\Users\Rob Lutz\AppData\Roaming\Microsoft
[2010/11/05 14:09:02 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\PureEdge
[2011/08/30 17:02:54 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\Sony Corporation
[2012/08/10 18:35:15 | 000,000,000 | ---D | M] -- C:\Users\Rob Lutz\AppData\Roaming\U3

< MD5 for: ATAPI.SYS >
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\erdnt\cache64\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7600.16385_none_392d19c13b3ad543\atapi.sys
[2009/07/13 21:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: CSRSS.EXE >
[2009/07/13 21:39:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=60C2862B4BF0FD9F582EF344C2B1EC72 -- C:\Windows\SysNative\csrss.exe
[2009/07/13 21:39:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=60C2862B4BF0FD9F582EF344C2B1EC72 -- C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.1.7600.16385_none_b4d8d57efdc6b4f3\csrss.exe

< MD5 for: EXPLORER.EXE >
[2011/02/26 02:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\erdnt\cache86\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 02:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 02:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 02:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 02:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: MSWSOCK.DLL >
[2009/07/13 21:15:51 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=11A41F17527ED75D6B758FDD7F4FD00D -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_b829ad298e9f53ff\mswsock.dll
[2010/11/20 09:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\erdnt\cache64\mswsock.dll
[2010/11/20 09:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\SysNative\mswsock.dll
[2010/11/20 09:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_16795c7543eb48cf\mswsock.dll
[2010/11/20 08:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\erdnt\cache86\mswsock.dll
[2010/11/20 08:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\SysWOW64\mswsock.dll
[2010/11/20 08:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll
[2009/07/13 21:41:34 | 000,320,000 | ---- | M] (Microsoft Corporation) MD5=FC76FE3C1E1FDB761244D4F74EF560FD -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7600.16385_none_144848ad46fcc535\mswsock.dll

< MD5 for: NAPINSP.DLL >
[2009/07/13 21:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\SysWOW64\NapiNSP.dll
[2009/07/13 21:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\winsxs\x86_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.1.7600.16385_none_abf396ebf0847c31\NapiNSP.dll
[2009/07/13 21:41:52 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=58A0CDABEA255616827B1C22C9994466 -- C:\Windows\SysNative\NapiNSP.dll
[2009/07/13 21:41:52 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=58A0CDABEA255616827B1C22C9994466 -- C:\Windows\winsxs\amd64_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.1.7600.16385_none_0812326fa8e1ed67\NapiNSP.dll

< MD5 for: NLAAPI.DLL >
[2009/07/13 21:16:03 | 000,051,712 | ---- | M] (Microsoft Corporation) MD5=045DB4EAB4FBD23210E85ECC3F464A2E -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7600.16385_none_cdcf91c058fc0e07\nlaapi.dll
[2010/11/20 08:20:30 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=104A1070E90F1C530328E69B49718841 -- C:\Windows\SysWOW64\nlaapi.dll
[2010/11/20 08:20:30 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=104A1070E90F1C530328E69B49718841 -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17514_none_d000a58855ea91a1\nlaapi.dll
[2010/11/20 09:27:22 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=2DF36F15B2BC1571A6A542A3C2107920 -- C:\Windows\SysNative\nlaapi.dll
[2010/11/20 09:27:22 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=2DF36F15B2BC1571A6A542A3C2107920 -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17514_none_c5abfb362189cfa6\nlaapi.dll
[2009/07/13 21:41:52 | 000,070,144 | ---- | M] (Microsoft Corporation) MD5=86E3822A34D454032D8E88C72AE8CF2D -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7600.16385_none_c37ae76e249b4c0c\nlaapi.dll

< MD5 for: PNRPNSP.DLL >
[2009/07/13 21:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\SysWOW64\pnrpnsp.dll
[2009/07/13 21:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\winsxs\wow64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.1.7600.16385_none_d7c8b1ac70865dab\pnrpnsp.dll
[2009/07/13 21:41:53 | 000,086,016 | ---- | M] (Microsoft Corporation) MD5=613C8CE10A5FDE582BA5FA64C4D56AAA -- C:\Windows\SysNative\pnrpnsp.dll
[2009/07/13 21:41:53 | 000,086,016 | ---- | M] (Microsoft Corporation) MD5=613C8CE10A5FDE582BA5FA64C4D56AAA -- C:\Windows\winsxs\amd64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.1.7600.16385_none_cd74075a3c259bb0\pnrpnsp.dll

< MD5 for: PRINTISOLATIONHOST.EXE >
[2009/07/13 21:39:27 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=22F020C76E339EB2B2187BA73A7E4173 -- C:\Windows\SysNative\PrintIsolationHost.exe
[2009/07/13 21:39:27 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=22F020C76E339EB2B2187BA73A7E4173 -- C:\Windows\winsxs\amd64_microsoft-windows-p..ng-server-isolation_31bf3856ad364e35_6.1.7600.16385_none_f8a40495785334a9\PrintIsolationHost.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\erdnt\cache64\services.exe
[2009/07/13 21:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\erdnt\cache86\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\erdnt\cache64\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/13 21:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/07/28 14:42:58 | 000,040,960 | ---- | M] () MD5=26251A0B00004F17EB1F7BB443318E17 -- C:\Users\Rob Lutz\Documents\RJL Communications\Modem Information\Security Manager Removal\Security Removal\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\erdnt\cache86\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 21:39:48 | 000,030,208 | ---- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\erdnt\cache64\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 09:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\erdnt\cache64\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/28 03:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/28 02:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< MD5 for: WINRNR.DLL >
[2009/07/13 21:41:56 | 000,028,672 | ---- | M] (Microsoft Corporation) MD5=2E2072EB48238FCA8FBB7A9F5FABAC45 -- C:\Windows\SysNative\winrnr.dll
[2009/07/13 21:41:56 | 000,028,672 | ---- | M] (Microsoft Corporation) MD5=2E2072EB48238FCA8FBB7A9F5FABAC45 -- C:\Windows\winsxs\amd64_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.1.7600.16385_none_b543449669c73e11\winrnr.dll
[2009/07/13 21:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\SysWOW64\winrnr.dll
[2009/07/13 21:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.1.7600.16385_none_5924a912b169ccdb\winrnr.dll

< MD5 for: WSHELPER.DLL >
[2009/07/13 21:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\SysWOW64\wshelper.dll
[2009/07/13 21:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\winsxs\wow64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6ace9e67456cc40b\wshelper.dll
[2009/07/13 21:41:58 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=D314DA4B0B8DCD023D547FC568E34FB6 -- C:\Windows\SysNative\wshelper.dll
[2009/07/13 21:41:58 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=D314DA4B0B8DCD023D547FC568E34FB6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\wshelper.dll

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/05/11 09:50:14 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/05/11 09:50:14 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/05/11 09:50:14 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -extoff [2012/06/28 21:00:47 | 000,748,664 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" [2012/06/28 21:00:47 | 000,748,664 | ---- | M] (Microsoft Corporation)

< hklm\software\clients\startmenuinternet|command /64 /rs >
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2011/05/11 09:50:12 | 000,089,088 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2011/05/11 09:50:12 | 000,089,088 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2011/05/11 09:50:12 | 000,089,088 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2012/06/28 21:00:47 | 000,748,664 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" [2012/06/28 21:00:47 | 000,748,664 | ---- | M] (Microsoft Corporation)

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< End of report >


OTL Extras logfile created on: 8/20/2012 12:01:12 PM - Run 2
OTL by OldTimer - Version 3.2.57.0 Folder = C:\Users\Rob Lutz\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

4.00 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 48.55% Memory free
8.00 Gb Paging File | 5.81 Gb Available in Paging File | 72.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931.41 Gb Total Space | 822.28 Gb Free Space | 88.28% Space Free | Partition Type: NTFS
Drive P: | 465.66 Gb Total Space | 379.10 Gb Free Space | 81.41% Space Free | Partition Type: NTFS
Drive Q: | 465.66 Gb Total Space | 379.10 Gb Free Space | 81.41% Space Free | Partition Type: NTFS
Drive U: | 465.66 Gb Total Space | 379.10 Gb Free Space | 81.41% Space Free | Partition Type: NTFS

Computer Name: RJL8 | User Name: Rob Lutz | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = jsfile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = ComFile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = jsfile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files (x86)\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1302E774-897F-4021-B32B-0D3E72745271}" = rport=137 | protocol=17 | dir=out | app=system |
"{22BBFBA6-30EC-4465-A5A5-5F59DED51740}" = lport=49172 | protocol=6 | dir=in | name=akamai netsession interface |
"{2AB9994F-3074-4449-A0EF-AE1D41D54EBD}" = rport=139 | protocol=6 | dir=out | app=system |
"{3C6461BB-BC59-4DA5-B814-18410107D39F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{412D3A9C-7B3D-43CB-98FF-D1735455691E}" = rport=21 | protocol=6 | dir=out | name=ftp out |
"{43518E9A-E602-4C60-B15F-07E0E09D964D}" = lport=137 | protocol=17 | dir=in | app=system |
"{4C5D40EE-9F8B-4781-8096-06F8BD6E8BA6}" = lport=445 | protocol=6 | dir=in | app=system |
"{539349EE-A0A7-441B-87B3-5C3C0F313A18}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{574A98EB-EBD8-47BB-B5F0-4982118E9067}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{57D9F4D4-43CB-47C8-9FFE-638102AD341E}" = lport=21 | protocol=6 | dir=in | name=ftp inbound |
"{5DC16200-3F0A-4231-8AC9-B9F363AD2A48}" = lport=138 | protocol=17 | dir=in | app=system |
"{68FBCB03-5CE7-41BD-AAAF-E8936848CDF5}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{6BFDB751-7EDB-4ABE-ADC2-0198B717EEBC}" = rport=138 | protocol=17 | dir=out | app=system |
"{7EF1483C-904F-4F5D-9631-B1085EBDF7CD}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{AAD44955-2CE2-4A35-B43E-9EA938D79669}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{B4C6572E-B886-46DC-8B38-B3DD4E44D2B8}" = rport=445 | protocol=6 | dir=out | app=system |
"{CFD33093-C802-4F2E-AB54-9EC61E0C6C13}" = lport=139 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{02727ABD-D947-49D6-ADB4-2B8C5EF22995}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\dbmanagerexe.exe |
"{05A51B3A-894D-4E58-B9B9-B60836F40768}" = protocol=58 | dir=in | [email protected],-28545 |
"{079D6BE0-E7B1-44A4-9034-F6DC4D8C9B75}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\qbdbmgrn.exe |
"{098F1B28-C6AF-4137-BBA5-733D2CD9E6FF}" = protocol=17 | dir=in | app=c:\users\rob lutz\appdata\roaming\dropbox\bin\dropbox.exe |
"{0A4B349D-752D-49C7-B230-3BDCE2714439}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\filemanagement.exe |
"{11FFC1EB-8144-472F-91A3-34DB660D68EA}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\intuit\quickbooks\qbcfmonitorservice.exe |
"{1D7283D7-92B8-4F41-A2CC-23ED566BF996}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{2589037C-C06B-4AFA-A51F-0BEB954A1EA1}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{272D6726-46EF-4909-B53D-CA319595BD80}" = protocol=17 | dir=in | app=c:\program files (x86)\globalscape\cuteftp 8 home\cuteftp.exe |
"{2D637E98-5EFB-483F-AD1B-B752A7BF23A1}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{34C7CB27-B2DF-46AB-8D65-5E789C8AFF95}" = protocol=58 | dir=out | [email protected],-28546 |
"{376AD94C-AEF1-4FC2-B0DE-C23AADC2EBE9}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\qbdbmgrn.exe |
"{37F4DAF5-1631-4B52-A2FC-6AE938C59FD3}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\qbdbmgrn.exe |
"{3BE8065F-A215-49D5-A9CE-C5C4E4577377}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\filemanagement.exe |
"{405DE6B7-E2B9-40DD-86AD-F3FF6A7B2BB5}" = protocol=1 | dir=out | [email protected],-28544 |
"{40E5FDF8-3675-4C23-9088-ABF33DAD6C6B}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\dbmanagerexe.exe |
"{45784054-5022-49FD-A48D-6C3F47448E51}" = protocol=6 | dir=in | app=c:\program files (x86)\hp\hp laserjet m1522\fax config utility1.exe |
"{4A993A7E-B61E-40E2-A805-EB07CDE2076A}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\dbmanagerexe.exe |
"{5609E533-E067-45DE-927A-B2F6B6F2D3F6}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\qbw32.exe |
"{5742C498-6144-40DF-9B19-B3CAA7C56EDF}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\qbdbmgrn.exe |
"{601B1D2E-0A75-4068-B589-D9DD1044B14A}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\intuit\quickbooks\qblaunch.exe |
"{63513A58-8DED-42F7-A360-2299CC52549A}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\qbw32.exe |
"{64272A82-4A34-4F64-A2F8-AECDA89306F4}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\dbmanagerexe.exe |
"{64E911C0-98FC-43E4-AC2C-C1C36C77206D}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\qbw32.exe |
"{751890C9-315F-4052-86C3-F5252878A623}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\dbmanagerexe.exe |
"{7823F0AC-1FA7-466E-B8B4-CDC092385E84}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{7F26B9AA-B933-4959-B7D1-B9B41E1212A5}" = protocol=1 | dir=in | [email protected],-28543 |
"{83CCC6C2-07D3-47F6-B05A-6E5FDC085D61}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{8432727A-42C4-4210-978A-AE39B225826A}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{84A767C3-1149-43BC-8519-2957EFCB4D23}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\filemanagement.exe |
"{8C8F2C2C-16CC-43C3-8D3A-636B06B5813E}" = protocol=6 | dir=in | app=c:\program files (x86)\adobe\adobe dreamweaver cs6\dreamweaver.exe |
"{9ADA63E7-80AE-449A-A55E-FF1CEFDC89EE}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\filemanagement.exe |
"{9EB63A64-64B3-4727-B449-0FDBD64E22B1}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\intuit\quickbooks\qblaunch.exe |
"{A095CB74-95E7-4CE7-AB36-F127A470C233}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\dbmanagerexe.exe |
"{A2C2BDE7-156F-4951-BAA9-01C12D427ED1}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\qbdbmgrn.exe |
"{B749F1BF-6E57-4A87-9948-83F1B361ACC3}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\intuit\quickbooks\qbcfmonitorservice.exe |
"{BA3F01F1-62B6-41CC-B010-7D07B1CC40A1}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\qbw32.exe |
"{BBB70F4E-E7D6-4C2D-B155-9F511935478E}" = protocol=6 | dir=in | app=c:\users\rob lutz\appdata\roaming\dropbox\bin\dropbox.exe |
"{C3849E1D-85E4-4FA8-8D6D-7432DC21CDC0}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2011\qbw32.exe |
"{D8430559-32BD-4DC7-85D2-D4298C73833B}" = protocol=17 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\qbdbmgrn.exe |
"{DAD513BE-1376-4949-B87B-A96EE35992EA}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\qbw32.exe |
"{DF78853E-2ACE-495D-AF25-0A1C02E181B4}" = protocol=17 | dir=in | app=c:\program files (x86)\adobe\adobe dreamweaver cs6\dreamweaver.exe |
"{E2F12359-9480-422E-918B-3A5EF16FC1D2}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\live meeting 8\console\pwconsole.exe |
"{EC58E45A-86BC-4668-85E6-97A876116F5B}" = protocol=6 | dir=in | app=c:\program files (x86)\globalscape\cuteftp 8 home\cuteftp.exe |
"{F2824DD9-B3FD-448E-955B-4366E22E10C4}" = protocol=17 | dir=in | app=c:\program files (x86)\hp\hp laserjet m1522\fax config utility1.exe |
"{F7E95432-F50E-421C-8C0B-F0724140B6A9}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2010\filemanagement.exe |
"{FC51553B-C6C3-4ADB-ACB3-8EF7589C1E5D}" = protocol=6 | dir=in | app=c:\program files (x86)\intuit\quickbooks 2012\filemanagement.exe |
"TCP Query User{0C8C0CFA-BB62-4C8E-A67B-1B0D10AC8A2A}C:\timhillone\h264webcam\h264webcam.exe" = protocol=6 | dir=in | app=c:\timhillone\h264webcam\h264webcam.exe |
"TCP Query User{8D4F7F38-DB7D-4DA6-ADF9-132BE68E6212}C:\program files (x86)\hp\hp ut\bin\hppusg.exe" = protocol=6 | dir=in | app=c:\program files (x86)\hp\hp ut\bin\hppusg.exe |
"TCP Query User{90AFFD05-407C-4D33-B1BE-89B6CCA7204A}C:\users\rob lutz\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\rob lutz\appdata\local\akamai\netsession_win.exe |
"TCP Query User{9B3145D9-FD14-4CB0-8D98-B19C41171669}D:\netcam\easyconfig.exe" = protocol=6 | dir=in | app=d:\netcam\easyconfig.exe |
"TCP Query User{A5B27C26-D2CD-4A0D-B746-706461697FBC}C:\program files (x86)\timhillone\h264webcam\h264webcam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\timhillone\h264webcam\h264webcam.exe |
"TCP Query User{C096E9F0-468B-439D-A672-C22285A05537}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{C174C96F-78CD-49E9-98E3-38ED6B4622BC}C:\windows\explorer.exe" = protocol=6 | dir=in | app=c:\windows\explorer.exe |
"TCP Query User{D6070A3C-BA2A-4E66-9133-CA6DF62CB87B}C:\program files (x86)\logmein backup\logmeinbackup.exe" = protocol=6 | dir=in | app=c:\program files (x86)\logmein backup\logmeinbackup.exe |
"TCP Query User{F05176E0-835B-40CD-901F-5BD01B9551E9}C:\program files (x86)\blue iris\blueiris.exe" = protocol=6 | dir=in | app=c:\program files (x86)\blue iris\blueiris.exe |
"TCP Query User{F5E5C68D-E1FA-4CD4-BF81-F48B0676CC06}C:\users\rob lutz\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\rob lutz\appdata\local\akamai\netsession_win.exe |
"UDP Query User{4EDBD12C-F327-4A4A-B453-C81F4A50CCFD}C:\users\rob lutz\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\rob lutz\appdata\local\akamai\netsession_win.exe |
"UDP Query User{597A3222-A6DA-4022-9EEE-3C9C7700E53D}C:\windows\explorer.exe" = protocol=17 | dir=in | app=c:\windows\explorer.exe |
"UDP Query User{76741F9E-330B-4C01-ABC5-7DD915DF7E10}C:\users\rob lutz\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\rob lutz\appdata\local\akamai\netsession_win.exe |
"UDP Query User{7F6FB5F6-D832-4F85-813B-68E396824160}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{92C7D6C3-FF6A-420D-8F24-3B6060EBD4B4}C:\program files (x86)\timhillone\h264webcam\h264webcam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\timhillone\h264webcam\h264webcam.exe |
"UDP Query User{A50671EE-2D8F-4468-852A-87F9AC15D407}C:\program files (x86)\hp\hp ut\bin\hppusg.exe" = protocol=17 | dir=in | app=c:\program files (x86)\hp\hp ut\bin\hppusg.exe |
"UDP Query User{CCA2E416-4FFB-4C91-89FB-5D9B80D05170}C:\program files (x86)\blue iris\blueiris.exe" = protocol=17 | dir=in | app=c:\program files (x86)\blue iris\blueiris.exe |
"UDP Query User{CF143E3A-B376-4992-9A44-D4802932305D}D:\netcam\easyconfig.exe" = protocol=17 | dir=in | app=d:\netcam\easyconfig.exe |
"UDP Query User{E11457CD-3CCE-4670-8CF1-E2E0CB41FE66}C:\program files (x86)\logmein backup\logmeinbackup.exe" = protocol=17 | dir=in | app=c:\program files (x86)\logmein backup\logmeinbackup.exe |
"UDP Query User{F1FF029B-AA8D-4F7F-94C9-F4C8DE9497C7}C:\timhillone\h264webcam\h264webcam.exe" = protocol=17 | dir=in | app=c:\timhillone\h264webcam\h264webcam.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06DB2C4C-DC29-DA42-3B00-5581CBF545BB}" = AMD Drag and Drop Transcoding
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{3987279A-3504-2916-D063-741B910F0747}" = AMD Accelerated Video Transcoding
"{44B4F244-5B4D-856E-B3A6-E8DDBDC7F127}" = AMD Fuel
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{59B69525-1383-C84A-38EF-F442B63E69BC}" = AMD Media Foundation Decoders
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{af6131fc-32da-45ea-a1e7-fe634f8f2722}.sdb" = SignBlazer5.5 XP buttons
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{F4C71C2A-F068-8EEB-61AE-EA4707C57A1B}" = AMD Catalyst Install Manager
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HPExtendedCapabilities" = HP Customer Participation Program 9.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"sp6" = Logitech SetPoint 6.32

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B9.0904.1
"{079A4EB2-9A74-7B86-12C2-00B52E395801}" = CCC Help Danish
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F2F77E4-4053-4108-B153-81F0B42EDCF4}" = WebIQ Technology Engine
"{112DDD07-E419-2498-1E9E-2157F82AF5AA}" = CCC Help Turkish
"{172423F9-522A-483A-AD65-03600CE4CA4F}" = Microsoft Works 6-9 Converter
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1EFF07F5-98C3-4247-8FDE-EDC67C027DA2}" = Tuner Internet Update Application
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{229D6185-BD7E-494B-A73B-C5215BE0690E}" = HPLJUT
"{2556333D-27B8-4CCE-9DC3-A6CC382F3409}" = QuickBooks Premier: Contractor Edition 2012
"{25E202D1-D8E7-46AF-B4B0-157D9993A93E}" = QuickBooks
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java™ 6 Update 32
"{26E76762-7F20-4694-AD06-CC3A9B547A71}" = Microsoft Office Live Meeting 2007
"{28E7F407-DA2F-4960-AE9D-DC56CEEB933E}_is1" = Diamond 10.1 Win7Vista Installation
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2993B157-97AE-7981-F29A-E6575F991CDB}" = CCC Help Swedish
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{347966F8-E71A-E1A5-95E4-3A1C215383F6}" = CCC Help Chinese Traditional
"{34F93E31-E1A0-421C-8E86-BCF7C4193A91}" = LogMeIn
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = Gigabyte Raid Cinfigurer
"{3B3D81AB-51E2-695F-7E57-1CC30049F2A3}" = CCC Help French
"{3BCD05CE-8CDE-9503-8794-D8CDB9FA8562}" = Catalyst Control Center InstallProxy
"{3DF4DDEF-4629-44AA-8948-491CABB984D8}" = LogMeIn Backup
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{4006E354-3D24-49BA-A36F-7EB75D50D575}" = hppLaserJetService
"{402F6F2E-5683-491C-977D-0CA599A07CAF}" = Adobe CS6 Design and Web Premium
"{462C2036-3055-4369-D30B-8DA032331EAB}" = CCC Help Greek
"{487B0B9B-DCD4-440D-89A0-A6EDE1A545A3}" = HPSSupply
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{51054867-140B-8FBF-73A8-75386276BD98}" = CCC Help Spanish
"{5449FB4F-1802-4D5B-A6D8-087DB1142147}" = Realtek HDMI Audio Driver for ATI
"{586A5957-F21B-C8AD-F5C2-11D4D7DA5340}" = CCC Help German
"{5B363E1D-8C36-4458-BAE4-D5081999E094}" = Browser Configuration Utility
"{633414E3-AA2A-CD04-5976-E91F5F871396}" = CCC Help Japanese
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{74280B5D-A0AF-46c5-9C85-D9EA078262F1}" = HP LaserJet Professional M1530 MFP Series
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7E664C9F-0341-11F9-39F7-E2493FACF037}" = Adobe® Content Viewer
"{7FB413C8-3CAD-49F7-A67C-6EFEB4B04050}" = LogMeIn Hamachi
"{812FF572-F216-EBA0-123E-636C1B6EBC5B}" = CCC Help Korean
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{85BB7CA7-6B0D-0B27-F4FF-B3D04282B3D1}" = CCC Help Russian
"{865E1902-B6FE-4AF0-B61D-A82EBC53569E}" = hppSendFaxM1530
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows Vista and Later
"{883CCFC7-CA6B-5531-704B-F9A64546B309}" = CCC Help Thai
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B0527BE-427B-459B-93B1-D30ED8CB4F93}" = Network Camera Recorder
"{8BDD3EC9-27E9-E490-7607-AF97FA678046}" = CCC Help Italian
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010
"{90140000-0054-0409-0000-0000000FF1CE}_Office14.VISIOR_{CDC4310F-8189-485F-B47D-D972217CE173}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9112FEA9-0F64-453C-BEA5-9A782F87EDAA}" = hppTLBXFXM1530
"{91140000-0057-0000-0000-0000000FF1CE}" = Microsoft Office Visio 2010
"{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{01D8AE4B-A04D-47E5-81BF-E3F98B81B8C3}" = Microsoft Visio 2010 Service Pack 1 (SP1)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{949DBB22-2FB7-4de1-804C-23D495A988D8}" = CuteFTP 8 Home
"{9B97EC91-B3FD-4BFF-88FC-5345A26AC2E7}" = Adobe Illustrator CS5
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DA5221E-15DE-5B0F-D7BE-CCC7305575DD}" = CCC Help Dutch
"{A0BB1E68-1DD0-4acd-AD82-EDA0E49F0615}" = PMB Updater
"{A0BBF7AB-2F47-47DC-BB02-4C826F2BC73C}" = IBM Lotus Forms Viewer 3.5.1
"{A1400F57-65CC-0C22-6461-948EA2837670}" = CCC Help Hungarian
"{A1D53426-D6F3-4886-A72B-E1A8C82259E9}" = hppM1530LaserJetService
"{A3A18593-62BE-4AE1-AF3F-E35179CF042E}" = hpzTLBXFX
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A561BB5F-5A85-5D88-E520-0A4512D5E6C0}" = CCC Help Norwegian
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A82D0C46-EBDF-4B27-A731-D06EF2056E81}" = HP FWUpdateEDO3
"{A8B72907-B3F5-4C18-2D2B-F5E786A520DF}" = CCC Help Polish
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AD219F94-16F2-937F-076A-F22DAA8D0A0B}" = CCC Help Finnish
"{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
"{B2AA0F22-E167-4C4A-BAE2-E0025028E61B}" = HPLaserJetHelp_LearnCenter
"{B2B5B39B-4E8C-AC78-7FF1-7055C338D243}" = Catalyst Control Center Graphics Previews Common
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B8087CCE-B735-4485-BA45-08929FCCB101}" = Blue Iris
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C05002F1-06F8-4A15-B6F8-E4DC655C28AA}" = HP LJ M1530 MFP Series HP Scan
"{C462F75B-9A35-4A84-AE52-E8C9112AAE87}" = hppFaxUtilityM1530
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DD8ACFF8-098E-130C-2799-BCA4D41EBAB2}" = CCC Help Chinese Standard
"{DE123FE9-B7F6-A75A-920D-3937FB9F06E4}" = CCC Help Portuguese
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EE253E80-C298-4A31-BB22-7280DC8C7177}" = CCC Help Czech
"{EFBE6DD5-B224-96E5-72B9-68D328CB12A6}" = Adobe Widget Browser
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F648F088-B270-CF18-6486-AF8B1FE6BC09}" = CCC Help English
"{F7F23DFB-31E1-B7EC-7A6D-7668B595ADAE}" = FlipShare
"{FD575F8B-6141-455A-8AE5-F2D2E08520FC}" = hppFaxDrvM1530
"{FD85D9C0-783A-77B7-8EF8-326EC6C154D1}" = Catalyst Control Center Localization All
"3ivx MPEG-4 5.0.3" = 3ivx MPEG-4 5.0.3 (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.dmp.contentviewer" = Adobe® Content Viewer
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.adobe.WidgetBrowser" = Adobe Widget Browser
"InstallShield_{B8087CCE-B735-4485-BA45-08929FCCB101}" = Blue Iris
"InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}" = NEC Electronics USB 3.0 Host Controller Driver
"LogMeIn Backup" = LogMeIn Backup
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Microsoft Visual Studio 2005 Tools for Office Runtime
"Office14.SingleImage" = Microsoft Office Professional 2010
"Office14.VISIOR" = Microsoft Visio Professional 2010
"QB Connection Diagnostic Tool" = QB Connection Diagnostic Tool
"SB_USCutter_Elements_ID_is1" = SignBlazer Elements for USCutter release 6.0.21

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/20/2012 10:56:56 AM | Computer Name = RJL8 | Source = LogMeIn Guardian | ID = 131176
Description = LogMeIn Guardian has detected a problem with the LogMeIn software
installed on this machine. The problem is locally identified by the following reference
ID: 'a09f9ccaf7ba0019a058396888500fd0'.

Error - 8/20/2012 10:58:14 AM | Computer Name = RJL8 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 8/20/2012 10:58:14 AM | Computer Name = RJL8 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

Error - 8/20/2012 10:58:14 AM | Computer Name = RJL8 | Source = QuickBooks | ID = 4
Description = An unexpected error has occured in "QuickBooks": Returning NULL QBWinInstance
Hand

[ System Events ]
Error - 8/20/2012 10:55:27 AM | Computer Name = RJL8 | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the LogMeIn
Backup Storage PC Service service to connect.

Error - 8/20/2012 10:55:28 AM | Computer Name = RJL8 | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the LogMeIn
Backup Storage PC Service service to connect.

Error - 8/20/2012 10:55:28 AM | Computer Name = RJL8 | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the LogMeIn
Backup Storage PC Service service to connect.

Error - 8/20/2012 10:55:29 AM | Computer Name = RJL8 | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the LogMeIn
Backup Storage PC Service service to connect.

Error - 8/20/2012 10:55:29 AM | Computer Name = RJL8 | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the LogMeIn
Backup Storage PC Service service to connect.

Error - 8/20/2012 10:57:02 AM | Computer Name = RJL8 | Source = Service Control Manager | ID = 7034
Description = The LogMeIn service terminated unexpectedly. It has done this 1 time(s).

Error - 8/20/2012 10:57:54 AM | Computer Name = RJL8 | Source = DCOM | ID = 10016
Description =

Error - 8/20/2012 10:59:22 AM | Computer Name = RJL8 | Source = BROWSER | ID = 8032
Description =


< End of report >


I await your reply.
  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
Combofix says there is something wrong with user32.dll.

Copy the text between the lines of stars by highlighting and Ctrl + c.

******************************************

AtJob::

DirLook::
C:\Program Files\Common
%user%\library

FCopy::
c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll | c:\windows\SysWOW64\user32.dll

RegLock::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]

Registry::
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\Approved Extensions]
"{8769ADCE-DBA5-48E9-AFB5-67B12CDF2E61}"=-
******************************************

Now open notepad (Start, Run, notepad, OK) and Ctrl + V to paste the text into Notepad. Make sure you got it all then File, SAVE AS, (to your Desktop), CFScript , OK. Close notepad. (Overwrite the old one if it's still there.) You should see a file CFScript.txt on your desktop.

Pause your anti-virus.

Drag CFScript.txt over to Combofix and let go Combofix should start on its own.

Post the new log.

Are you still getting redirected?
Ron
  • 0

#10
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Here it is:

ComboFix 12-08-20.02 - Rob Lutz 08/20/2012 13:35:34.2.4 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.4094.1604 [GMT -4:00]
Running from: c:\users\Rob Lutz\Desktop\Malware\ComboFix.exe
Command switches used :: c:\users\Rob Lutz\Desktop\Malware\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\tbthbaa.tmp
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3756RJLCommunicationsLLCpffcenter.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3756RJLCommunicationsLLCreviewDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3756RJLCommunicationsLLCreviewNotesPopUp.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\3756RJLCommunicationsLLCtaskNotesDialog.html
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\mootools.svn.js
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\pffCenter.css
c:\users\Rob Lutz\AppData\Local\Microsoft\Windows\Temporary Internet Files\pffCenter.js
c:\users\Rob Lutz\AppData\Local\Temp\{16AA8FB8-4A98-4757-B7A5-0FF22C0A6E33}_1101_1\dbdata11.dll
c:\users\ROBLUT~1\AppData\Local\Temp\{16AA8FB8-4A98-4757-B7A5-0FF22C0A6E33}_1101_1\dbdata11.dll
.
.
--------------- FCopy ---------------
.
c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll --> c:\windows\SysWOW64\user32.dll
.
((((((((((((((((((((((((( Files Created from 2012-07-20 to 2012-08-20 )))))))))))))))))))))))))))))))
.
.
2012-08-20 17:39 . 2012-08-20 17:39 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-20 17:07 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{163F5BEE-70C5-402E-8B1C-CC50F0F0931D}\mpengine.dll
2012-08-20 14:40 . 2012-08-20 14:40 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-20 14:40 . 2012-07-03 17:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-19 14:06 . 2012-06-29 10:04 9133488 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-17 14:23 . 2012-08-17 14:23 -------- d-----w- c:\users\Rob Lutz\AppData\Roaming\Malwarebytes
2012-08-17 14:22 . 2012-08-17 14:22 -------- d-----w- c:\programdata\Malwarebytes
2012-08-16 01:36 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll
2012-08-16 01:36 . 2012-05-05 07:46 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2012-08-16 01:31 . 2012-02-11 06:43 751104 ----a-w- c:\windows\system32\win32spl.dll
2012-08-16 01:31 . 2012-02-11 06:36 559104 ----a-w- c:\windows\system32\spoolsv.exe
2012-08-16 01:31 . 2012-02-11 05:43 492032 ----a-w- c:\windows\SysWow64\win32spl.dll
2012-08-16 01:31 . 2012-02-11 06:36 67072 ----a-w- c:\windows\splwow64.exe
2012-08-16 01:30 . 2012-07-04 22:16 73216 ----a-w- c:\windows\system32\netapi32.dll
2012-08-16 01:30 . 2012-07-04 22:13 59392 ----a-w- c:\windows\system32\browcli.dll
2012-08-16 01:30 . 2012-07-04 22:13 136704 ----a-w- c:\windows\system32\browser.dll
2012-08-16 01:30 . 2012-07-04 21:14 41984 ----a-w- c:\windows\SysWow64\browcli.dll
2012-08-16 01:30 . 2012-07-18 18:15 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-08-16 01:30 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2012-08-15 20:16 . 2012-08-20 14:58 -------- d-----r- c:\users\Rob Lutz\Dropbox
2012-08-15 20:10 . 2012-08-20 14:58 -------- d-----w- c:\users\Rob Lutz\AppData\Roaming\Dropbox
2012-08-13 16:59 . 2012-08-13 17:00 -------- d-----w- c:\users\Rob Lutz\AppData\Local\Google
2012-08-13 16:59 . 2012-08-13 17:00 -------- d-----w- c:\program files (x86)\Google
2012-07-28 04:09 . 2012-07-28 04:09 5538984 ----a-w- c:\windows\SysWow64\atiumdag.dll
2012-07-28 04:07 . 2012-07-28 04:07 10278912 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2012-07-28 03:43 . 2012-07-28 03:43 70144 ----a-w- c:\windows\system32\coinst_8.982.dll
2012-07-28 03:19 . 2012-07-28 03:19 24935424 ----a-w- c:\windows\system32\atio6axx.dll
2012-07-28 02:50 . 2012-07-28 02:50 20546560 ----a-w- c:\windows\SysWow64\atioglxx.dll
2012-07-28 02:15 . 2012-07-28 02:15 163840 ----a-w- c:\windows\system32\atiapfxx.exe
2012-07-28 02:15 . 2012-07-28 02:15 931328 ----a-w- c:\windows\SysWow64\aticfx32.dll
2012-07-28 02:10 . 2012-07-28 02:10 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll
2012-07-28 02:10 . 2012-07-28 02:10 534528 ----a-w- c:\windows\system32\atieclxx.exe
2012-07-28 02:09 . 2012-07-28 02:09 239616 ----a-w- c:\windows\system32\atiesrxx.exe
2012-07-28 02:08 . 2012-07-28 02:08 120320 ----a-w- c:\windows\system32\atitmm64.dll
2012-07-28 02:08 . 2012-07-28 02:08 21504 ----a-w- c:\windows\system32\atimuixx.dll
2012-07-28 02:07 . 2012-07-28 02:07 59392 ----a-w- c:\windows\system32\atiedu64.dll
2012-07-28 02:07 . 2012-07-28 02:07 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll
2012-07-28 02:07 . 2012-07-28 02:07 6430208 ----a-w- c:\windows\SysWow64\atidxx32.dll
2012-07-28 01:41 . 2012-07-28 01:41 4266496 ----a-w- c:\windows\system32\atiumd6a.dll
2012-07-28 01:35 . 2012-07-28 01:35 51200 ----a-w- c:\windows\system32\aticalrt64.dll
2012-07-28 01:35 . 2012-07-28 01:35 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll
2012-07-28 01:35 . 2012-07-28 01:35 44544 ----a-w- c:\windows\system32\aticalcl64.dll
2012-07-28 01:35 . 2012-07-28 01:35 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll
2012-07-28 01:34 . 2012-07-28 01:34 16034304 ----a-w- c:\windows\system32\aticaldd64.dll
2012-07-28 01:32 . 2012-07-28 01:32 4751872 ----a-w- c:\windows\SysWow64\atiumdva.dll
2012-07-28 01:30 . 2012-07-28 01:30 13605888 ----a-w- c:\windows\SysWow64\aticaldd.dll
2012-07-28 01:25 . 2012-07-28 01:25 6676480 ----a-w- c:\windows\system32\atiumd64.dll
2012-07-28 01:15 . 2012-07-28 01:15 540160 ----a-w- c:\windows\system32\atiadlxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll
2012-07-28 01:15 . 2012-07-28 01:15 17920 ----a-w- c:\windows\system32\atig6pxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 14848 ----a-w- c:\windows\system32\atiglpxx.dll
2012-07-28 01:15 . 2012-07-28 01:15 41984 ----a-w- c:\windows\system32\atig6txx.dll
2012-07-28 01:14 . 2012-07-28 01:14 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll
2012-07-28 01:14 . 2012-07-28 01:14 368640 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2012-07-28 01:13 . 2012-07-28 01:13 109568 ----a-w- c:\windows\SysWow64\atiuxpag.dll
2012-07-28 01:13 . 2012-07-28 01:13 103936 ----a-w- c:\windows\system32\atiu9p64.dll
2012-07-28 01:12 . 2012-07-28 01:12 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2012-07-28 01:08 . 2012-07-28 01:08 56320 ----a-w- c:\windows\system32\atimpc64.dll
2012-07-28 01:08 . 2012-07-28 01:08 56320 ----a-w- c:\windows\system32\amdpcom64.dll
2012-07-28 01:08 . 2012-07-28 01:08 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll
2012-07-28 01:08 . 2012-07-28 01:08 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-20 17:41 . 2010-03-23 20:11 25640 ----a-w- c:\windows\gdrv.sys
2012-08-16 07:00 . 2010-03-23 20:54 62134624 ----a-w- c:\windows\system32\MRT.exe
2012-08-15 16:18 . 2012-04-11 12:50 426184 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-08-15 16:18 . 2011-05-20 18:44 70344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-07-28 02:13 . 2012-03-09 05:14 1100288 ----a-w- c:\windows\system32\aticfx64.dll
2012-07-28 01:51 . 2012-03-09 04:45 7052288 ----a-w- c:\windows\system32\atidxx64.dll
2012-07-28 01:13 . 2010-03-23 22:02 129536 ----a-w- c:\windows\system32\atiuxp64.dll
2012-07-28 01:13 . 2012-06-11 16:24 83456 ----a-w- c:\windows\SysWow64\atiu9pag.dll
2012-07-11 16:48 . 2010-04-05 13:48 87488 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-07-11 16:48 . 2010-04-05 13:48 34720 ----a-w- c:\windows\system32\LMIport.dll
2012-07-11 16:48 . 2010-04-05 13:48 80800 ----a-w- c:\windows\system32\LMIinit.dll
2012-06-25 20:04 . 2012-06-25 20:04 1394248 ----a-w- c:\windows\SysWow64\msxml4.dll
2012-06-11 17:50 . 2012-06-11 17:50 187392 ----a-w- c:\windows\system32\clinfo.exe
2012-06-11 17:50 . 2012-06-11 17:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll
2012-06-11 17:50 . 2012-06-11 17:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll
2012-06-11 17:50 . 2012-06-11 17:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll
2012-06-11 17:50 . 2012-06-11 17:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll
2012-06-11 17:50 . 2012-06-11 17:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll
2012-06-11 17:49 . 2012-06-11 17:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll
2012-06-09 05:43 . 2012-07-10 21:51 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-06-06 12:49 . 2012-06-06 12:49 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
2012-06-06 06:06 . 2012-07-10 21:51 2004480 ----a-w- c:\windows\system32\msxml6.dll
2012-06-06 06:06 . 2012-07-10 21:51 1881600 ----a-w- c:\windows\system32\msxml3.dll
2012-06-06 06:02 . 2012-07-10 21:51 1133568 ----a-w- c:\windows\system32\cdosys.dll
2012-06-06 05:05 . 2012-07-10 21:51 1390080 ----a-w- c:\windows\SysWow64\msxml6.dll
2012-06-06 05:05 . 2012-07-10 21:51 1236992 ----a-w- c:\windows\SysWow64\msxml3.dll
2012-06-06 05:03 . 2012-07-10 21:51 805376 ----a-w- c:\windows\SysWow64\cdosys.dll
2012-06-02 22:19 . 2012-06-21 17:21 38424 ----a-w- c:\windows\system32\wups.dll
2012-06-02 22:19 . 2012-06-21 17:21 2428952 ----a-w- c:\windows\system32\wuaueng.dll
2012-06-02 22:19 . 2012-06-21 17:21 44056 ----a-w- c:\windows\system32\wups2.dll
2012-06-02 22:19 . 2012-06-21 17:21 57880 ----a-w- c:\windows\system32\wuauclt.exe
2012-06-02 22:19 . 2012-06-21 17:21 701976 ----a-w- c:\windows\system32\wuapi.dll
2012-06-02 22:15 . 2012-06-21 17:21 2622464 ----a-w- c:\windows\system32\wucltux.dll
2012-06-02 22:15 . 2012-06-21 17:21 99840 ----a-w- c:\windows\system32\wudriver.dll
2012-06-02 19:19 . 2012-06-21 17:20 186752 ----a-w- c:\windows\system32\wuwebv.dll
2012-06-02 19:15 . 2012-06-21 17:20 36864 ----a-w- c:\windows\system32\wuapp.exe
2012-06-02 05:50 . 2012-07-10 21:51 458704 ----a-w- c:\windows\system32\drivers\cng.sys
2012-06-02 05:48 . 2012-07-10 21:51 151920 ----a-w- c:\windows\system32\drivers\ksecpkg.sys
2012-06-02 05:48 . 2012-07-10 21:51 95600 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2012-06-02 05:45 . 2012-07-10 21:51 340992 ----a-w- c:\windows\system32\schannel.dll
2012-06-02 05:44 . 2012-07-10 21:51 307200 ----a-w- c:\windows\system32\ncrypt.dll
2012-06-02 04:40 . 2012-07-10 21:51 22016 ----a-w- c:\windows\SysWow64\secur32.dll
2012-06-02 04:40 . 2012-07-10 21:51 225280 ----a-w- c:\windows\SysWow64\schannel.dll
2012-06-02 04:39 . 2012-07-10 21:51 219136 ----a-w- c:\windows\SysWow64\ncrypt.dll
2012-06-02 04:34 . 2012-07-10 21:51 96768 ----a-w- c:\windows\SysWow64\sspicli.dll
2012-05-30 02:55 . 2012-05-30 02:55 163048 ----a-w- c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10141.bin
.
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of %user%\library ----
.
.
---- Directory of c:\program files\Common ----
.
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . 57300E71DFBB58D8ED0D7B9813E55795 . 857600 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-20 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
[7] 2009-07-14 . E8B0FFC209E504CB7E79FC24E6C085F0 . 833024 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_3382083abb6e47d4\user32.dll
.
((((((((((((((((((((((((((((( [email protected]_14.18.36 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-08-16 07:33 . 2012-08-20 17:24 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\index.dat
- 2012-08-16 07:33 . 2012-08-20 13:59 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IEDownloadHistory\index.dat
+ 2012-08-20 14:39 . 2012-08-20 14:39 21504 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{DBBC5D38-EAD4-11E1-A85D-6CF0495C6684}.dat
+ 2012-08-20 15:06 . 2012-08-20 15:06 29184 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{A8BE467E-EAD8-11E1-9DA8-6CF0495C6684}.dat
+ 2012-08-20 17:33 . 2012-08-20 17:34 19968 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{384EF475-EAED-11E1-9DA8-6CF0495C6684}.dat
+ 2012-08-20 17:32 . 2012-08-20 17:34 16384 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{0528155E-EAED-11E1-9DA8-6CF0495C6684}.dat
- 2012-08-16 07:28 . 2012-08-20 13:49 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2012-08-16 07:28 . 2012-08-20 16:41 49152 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\DOMStore\index.dat
+ 2010-03-23 20:12 . 2012-08-20 17:44 47184 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-08-20 17:44 33484 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2010-03-23 19:36 . 2012-08-20 17:44 15168 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-98966919-3431210009-1179794609-1000_UserData.bin
- 2012-08-20 10:24 . 2012-08-20 13:59 3584 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\RecoveryStore.{3AC57FF8-EAB1-11E1-BFBC-6CF0495C6684}.dat
+ 2012-08-20 10:24 . 2012-08-20 17:24 3584 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\RecoveryStore.{3AC57FF8-EAB1-11E1-BFBC-6CF0495C6684}.dat
+ 2012-08-20 17:24 . 2012-08-20 17:24 6144 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Last Active\{EBD79D25-EAEB-11E1-9DA8-6CF0495C6684}.dat
+ 2012-08-20 14:39 . 2012-08-20 14:39 5120 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{DBBC5D37-EAD4-11E1-A85D-6CF0495C6684}.dat
+ 2012-08-20 15:06 . 2012-08-20 15:06 5120 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{9D14FACA-EAD8-11E1-9DA8-6CF0495C6684}.dat
+ 2012-08-20 17:32 . 2012-08-20 17:33 4608 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\RecoveryStore.{0528155D-EAED-11E1-9DA8-6CF0495C6684}.dat
+ 2012-08-20 14:39 . 2012-08-20 14:39 4096 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{E1F7372B-EAD4-11E1-A85D-6CF0495C6684}.dat
+ 2012-08-20 15:06 . 2012-08-20 15:06 6144 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Internet Explorer\Recovery\High\Active\{9D14FACC-EAD8-11E1-9DA8-6CF0495C6684}.dat
- 2012-08-20 14:15 . 2012-08-20 14:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-08-20 17:41 . 2012-08-20 17:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-08-20 17:41 . 2012-08-20 17:41 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-08-20 14:15 . 2012-08-20 14:15 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-08-12 07:20 . 2012-08-20 14:01 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
+ 2010-08-12 07:20 . 2012-08-20 17:10 262144 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
- 2009-07-14 04:54 . 2012-08-20 14:18 245760 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-08-20 17:42 245760 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-08-20 04:05 . 2012-08-20 17:32 212992 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012012082020120821\index.dat
+ 2009-07-14 05:01 . 2012-08-20 17:40 517096 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 05:01 . 2012-08-20 14:14 517096 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2012-08-16 07:27 . 2012-08-20 14:01 3047424 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
+ 2012-08-16 07:27 . 2012-08-20 17:32 3047424 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\PrivacIE\index.dat
+ 2009-07-14 04:54 . 2012-08-20 17:42 2080768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-08-20 14:18 2080768 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-08-20 17:42 6586368 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2012-08-16 14:07 . 2012-08-20 17:40 4794780 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-18-16384.dat
+ 2011-06-21 13:27 . 2012-08-20 17:40 40517764 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-98966919-3431210009-1179794609-1000-12288.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 94208 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]
"BCU"="c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe" [2009-08-04 346320]
"JMB36X IDE Setup"="c:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"NUSB3MON"="c:\program files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2009-09-25 106496]
"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-07-23 402432]
"ToolboxFX"="c:\program files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe" [2010-10-25 58936]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"PMBVolumeWatcher"="c:\program files (x86)\Sony\PMB\PMBVolumeWatcher.exe" [2011-03-15 650080]
"Intuit SyncManager"="c:\program files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2011-12-06 2215768]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-02-21 59240]
"LogMeIn Backup GUI"="c:\program files (x86)\LogMeIn Backup\BackupSystray.exe" [2011-08-29 488848]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS6ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" [2012-06-25 1073352]
"Adobe Acrobat Speed Launcher"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" [2012-04-04 36760]
"Acrobat Assistant 8.0"="c:\program files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" [2012-04-04 815512]
"LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2012-06-27 1996200]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
.
c:\users\Rob Lutz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Blue Iris.lnk - c:\program files (x86)\Blue Iris\blueiris.exe [2011-8-14 11807616]
Dropbox.lnk - c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-7-24 26909544]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Intuit Data Protect.lnk - c:\program files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe [2012-6-5 5982040]
QuickBooks Update Agent.lnk - c:\program files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2012-6-5 1176464]
QuickBooks_Standard_21.lnk - c:\program files (x86)\Intuit\QuickBooks 2012\QBW32.EXE [2012-6-5 1181584]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux1"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 116648]
R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-15 250056]
R3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys [2010-02-18 46136]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 116648]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-21 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]
R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-04-05 1255736]
R4 QuickBooksDB22;QuickBooksDB22;c:\progra~2\Intuit\QUICKB~2\QBDBMgrN.exe [2011-08-20 679936]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-07-28 239616]
S2 BackupMaint;LogMeIn Backup Maintenance Service;c:\program files (x86)\LogMeIn Backup\BackupMaint.exe [2011-08-29 140688]
S2 BCUService;Browser Configuration Utility Service;c:\program files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe [2009-08-04 219360]
S2 BlueIris;Blue Iris Service;c:\program files (x86)\Blue Iris\BlueIrisService.exe [2011-03-24 55808]
S2 ES lite Service;ES lite Service for program management.;c:\program files (x86)\Gigabyte\EasySaver\ESSVR.EXE [2009-08-24 68136]
S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-06-27 2369960]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [2010-10-25 145920]
S2 JMB36X;JMB36X;c:\windows\SysWOW64\XSrvSetup.exe [2009-08-06 65536]
S2 LMIBackupVSSService.exe;LogMeIn Backup VSS Service;c:\program files (x86)\LogMeIn Backup\LMIBackupVSSServiceX64.exe [2011-08-29 685456]
S2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [2012-07-11 375208]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files (x86)\LogMeIn\x64\RaInfo.sys [2008-08-11 15928]
S2 LogMeInBackupService.exe;LogMeIn Backup Storage PC Service;c:\program files (x86)\LogMeIn Backup\LogmeInBackupService.exe [2011-08-29 1787280]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;c:\program files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe [2011-03-15 428384]
S2 QBVSS;QBIDPService;c:\program files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [2011-08-20 1248256]
S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-07-28 10278912]
S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-07-28 368640]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 nusb3hub;NEC Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [2009-09-25 73728]
S3 nusb3xhc;NEC Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [2009-09-25 178688]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-08-20 239616]
S3 WSDPrintDevice;WSD Print Support via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 23040]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-20 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-11 16:18]
.
2012-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 16:59]
.
2012-08-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2012-08-13 16:59]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2012-06-30 04:19 97792 ----a-w- c:\users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-10-21 8306208]
"HP LaserJet M1522 MFP Series Fax"="c:\program files (x86)\HP\hp LaserJet M1522\hppfaxprintersrv.exe" [2009-09-22 3700736]
"LogMeIn GUI"="c:\program files (x86)\LogMeIn\x64\LogMeInSystray.exe" [2008-08-11 57928]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2012-04-04 446392]
"HP LaserJet Professional M1530 MFP Series Fax"="c:\program files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe" [2010-08-24 3706424]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
"EvtMgr6"="c:\program files\Logitech\SetPointP\SetPoint.exe" [2011-10-07 1744152]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = <local>
Handler: intu-help-qb5 - {867FCB77-9823-4cd6-8210-D85F968D466F} - c:\program files (x86)\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll
DPF: {EAEFAD15-8753-45EF-94B0-1BAA7970CC21} - hxxp://98.235.63.116:1100/MpegInst.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration]
@Denied: (2) (LocalSystem)
"Timestamp"=hex:33,0c,9b,a6,80,7b,cd,01
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a6,47,e7,e3,c4,e0,0d,4f,9c,90,01,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a6,47,e7,e3,c4,e0,0d,4f,9c,90,01,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_3_300_271_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_3_300_271.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]
@Denied: (A) (Everyone)
"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]
"Key"="ActionsPane"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Flip Video\FlipShare\FlipShareService.exe
c:\program files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files (x86)\LogMeIn Backup\LMIGuardian.exe
c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files (x86)\LogMeIn Backup\LMIGuardian.exe
.
**************************************************************************
.
Completion time: 2012-08-20 13:48:17 - machine was rebooted
ComboFix-quarantined-files.txt 2012-08-20 17:48
ComboFix2.txt 2012-08-20 14:24
.
Pre-Run: 883,075,854,336 bytes free
Post-Run: 882,738,106,368 bytes free
.
- - End Of File - - 8B36AC13C8AF6D74C95F7A5F76EC1F73
  • 0

Advertisements


#11
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Yes I am still getting redirected. Search results taking me to 63.209.69.107. Scour.com
  • 0

#12
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
We replaced user32.dll and it still shows it as bad so there is something we are not seeing.

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Type with an Enter after the line:

sfc  /scannow

Windows will probably replace the file too.


Download, Save and Run (win 7 or Vista => Right click and Run as Admin.) farbar service scanner

Posted Image

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

Use IE and go to http://eset.com/onlinescan and click on ESET online Scanner. Accept the terms then press Start (If you get a warning from your browser tell it you want to run it).

# Check Scan Archives
# Push the Start button.
# ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
# When the scan completes, push LIST OF THREATS FOUND
# Push EXPORT TO TEXT FILE , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
# Push the BACK button.
# Push Finish
# Once the scan is completed, you may close the window.
# Use Notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
# Copy and paste that log as a reply.


Let's also try the bitdefender quickscan.

http://quickscan.bitdefender.com/

When it finishes there is a View Report option at the bottom. Click on it and copy and paste the report (even if it says nothing found).
  • 0

#13
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Ran the SFC and rebooted. Log said it did replace some files and would take affect on the next reboot.

Here is the Farbar log:

Farbar Service Scanner Version: 06-08-2012
Ran by Rob Lutz (administrator) on 20-08-2012 at 17:58:58
Running from "C:\Users\Rob Lutz\Desktop\Malware"
Microsoft Windows 7 Professional Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****

Going to eset.com know and post when done.
  • 0

#14
RJLC

RJLC

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
OK that was like watching paint dry.

Eset found the following:

C:\Users\Rob Lutz\Documents\RJL Communications\Modem Information\Security Manager Removal\Security Removal\userinit.exe probably unknown NewHeur_PE virus
C:\Users\Rob Lutz\Downloads\cnet_H264WebCam_Setup_exe.exe a variant of Win32/InstallCore.D application

I cannot find a log file anywhere so I might of did something wrong.

Here is the Bitdefender log:


QuickScan 32-bit v0.9.9.118
---------------------------
Scan date: Tue Aug 21 07:19:23 2012
Machine ID: DCC290F3



No infection found.
-------------------



Processes
---------
hpwuSchd Application 3316 C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
AAM Updates Notifier Application 5880 C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
AcroTray - Adobe Acrobat Distiller help 3844 C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
Adobe Acrobat Update Service 1856 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
Adobe Reader and Acrobat Manager 3408 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
BlueIris 4956 C:\Program Files (x86)\Blue Iris\blueiris.exe
BlueIrisService.exe 4988 C:\Program Files (x86)\Blue Iris\BlueIrisService.exe
Browser Configuration Utility 3132 C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
Browser Configuration Utility 1932 C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
Dropbox 3872 C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe
essvr.exe 1988 C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe
FlipShare 2040 C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
Hamachi Client 3860 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
HPLaserJetService 4368 C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
Java™ Platform SE Auto Updater 2 0 3640 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
LMIGuardian 2952 C:\Program Files (x86)\LogMeIn Backup\LMIGuardian.exe
LMIGuardian 3692 C:\Program Files (x86)\LogMeIn Backup\LMIGuardian.exe
LogMeIn Backup 1892 C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe
LogMeIn Backup 3608 C:\Program Files (x86)\LogMeIn Backup\BackupSystray.exe
LogMeIn Backup 2912 C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe
Malwarebytes Anti-Malware 3900 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
Malwarebytes Anti-Malware 5896 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
Microsoft Outlook 6336 C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
Microsoft® Windows® Operating System 3988 C:\Windows\SysWOW64\msdt.exe
Microsoft® Windows® Operating System 3404 C:\Windows\SysWOW64\sdiagnhost.exe
PMB 2640 C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
PMB 3456 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
QBIDPService 1944 C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
QuickBooks 3252 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE
QuickBooks Automatic Update 3188 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
USB 3.0 Monitor 3196 C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
Windows® Internet Explorer 6772 C:\Program Files (x86)\Internet Explorer\iexplore.exe
Windows® Internet Explorer 6088 C:\Program Files (x86)\Internet Explorer\iexplore.exe
Windows® Internet Explorer 4340 C:\Program Files (x86)\Internet Explorer\iexplore.exe
XSrvSetup.exe 1272 C:\Windows\SysWOW64\XSrvSetup.exe
(verified) Microsoft® Visual Studio .NET 2944 C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\mdm.exe
(verified) Microsoft® Windows® Operating System 2812 C:\Windows\SysWOW64\svchost.exe


Network activity
----------------
Process LogmeInBackupService.exe (2912) connected on port 443 (HTTP over SSL) --> 64.94.18.143
Process Dropbox.exe (3872) connected on port 80 (HTTP) --> 199.47.218.149
Process blueiris.exe (4956) connected on port 80 (HTTP) --> 10.1.10.60
Process blueiris.exe (4956) connected on port 80 (HTTP) --> 10.1.10.60
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 23.33.63.139
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 74.125.226.237
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 74.125.226.237
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 173.194.43.8
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 173.194.43.8
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 173.194.43.8
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 74.125.226.249
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 74.125.226.249
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 173.194.75.103
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 173.194.75.103
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 66.235.142.20
Process iexplore.exe (6772) connected on port 80 (HTTP) --> 66.235.142.20

Process blueiris.exe (4956) listens on ports: 80 (HTTP)


Autoruns and critical files
---------------------------
hpwuSchd Application C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
AcroTray - Adobe Acrobat Distiller help C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
Adobe Acrobat C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe
Adobe CS5 Service Manager C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
Adobe CS6 Service Manager C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
Adobe Reader and Acrobat Manager C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Adobe Updater Startup Utility C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
Adobe® Flash® Player Update Service C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Apple Push C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
BlueIris C:\Program Files (x86)\Blue Iris\blueiris.exe
Browser Configuration Utility C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
Data Protect C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
Dropbox C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe
Google Update C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Hamachi Client C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
HP LaserJet Fax C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe
HP LaserJet Fax C:\Program Files (x86)\HP\hp LaserJet M1522\hppfaxprintersrv.exe
HPTLBXFX C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe
IntuitSyncManager C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe
Java™ Platform SE Auto Updater 2 0 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
Logitech SetPoint C:\Program Files\Logitech\SetPointP\SetPoint.exe
LogMeIn C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
LogMeIn Backup C:\Program Files (x86)\LogMeIn Backup\BackupSystray.exe
Malwarebytes Anti-Malware C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
Microsoft Security Client c:\Program Files\Microsoft Security Client\msseces.exe
Microsoft® Windows® Operating System C:\Windows\system32\Bubbles.scr
Microsoft® Windows® Operating System C:\Windows\system32\Cmd.exe
Microsoft® Windows® Operating System c:\windows\system32\userinit.exe
PMB C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
QuickBooks C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE
QuickBooks Automatic Update C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
QuickTime C:\Program Files (x86)\QuickTime\QTTask.exe
Realtek HD Audio Manager C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
SBSV 2010/02/19-11:02:07 C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
USB 3.0 Monitor C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
Windows® Internet Explorer c:\windows\syswow64\webcheck.dll
xInsIDE.exe C:\Windows\RaidTool\xInsIDE.exe


Browser plugins
---------------
AcroIEHelperShim Library c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
Adobe Acrobat C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
Adobe Acrobat C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
Adobe Acrobat C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll
Adobe PDF Toolbar for IE c:\program files (x86)\common files\adobe\acrobat\activex\acroiefavclient.dll
Adobe® Flash® Player ActiveX C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
Akamai Download Manager ActiveX Control C:\Windows\Downloaded Program Files\DownloadManagerV2.ocx
Akamai Download Manager ActiveX Control C:\Windows\Downloaded Program Files\Manager.exe
Bitdefender QuickScan C:\Windows\Downloaded Program Files\qsax.dll
Dldrv2 ActiveX Control Module C:\Windows\Downloaded Program Files\Dldrv.ocx
G726 Player Control C:\Windows\Downloaded Program Files\pmjpegaudio.ocx
Google Earth Plugin C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
Google Update C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
IBM® Lotus Forms™ Viewer c:\program files (x86)\ibm\lotus forms\viewer\3.5\pehelper.dll
Java Deployment Toolkit 6.0.320.5 C:\Windows\SysWOW64\npdeployJava1.dll
Java™ Platform SE 6 U32 c:\program files (x86)\java\jre6\bin\jp2ssv.dll
Java™ Platform SE 6 U32 C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
Java™ Platform SE 6 U32 c:\program files (x86)\java\jre6\bin\ssv.dll
LMIGuardianDll C:\Windows\Downloaded Program Files\LMIGuardianDll.dll
LMIGuardianEvt C:\Windows\Downloaded Program Files\LMIGuardianEvt.dll
LMIGuardianSvc C:\Windows\Downloaded Program Files\LMIGuardian.exe
LMIProxyHelper.exe C:\Windows\Downloaded Program Files\LMIProxyHelper.exe
LogMeIn, Inc. Remote Access Components C:\Windows\Downloaded Program Files\avutil-51.dll
LogMeIn, Inc. Remote Access Components C:\Windows\Downloaded Program Files\swscale-2.dll
LogMeIn, Inc. Remote Access Components C:\Windows\Downloaded Program Files\LMIBroker.exe
Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL
Microsoft Office 2010 C:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL
Microsoft Office 2010 c:\program files (x86)\microsoft office\office14\urlredir.dll
Microsoft® Windows® Operating System C:\Windows\System32\mswsock.dll
Microsoft® Windows® Operating System C:\Windows\system32\NLAapi.dll
pmjpegcam Control C:\Windows\Downloaded Program Files\pmjpegcam.ocx
QuickTime Plug-in 7.7.2 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll
QuickTime Plug-in 7.7.2 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll
QuickTime Plug-in 7.7.2 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll
QuickTime Plug-in 7.7.2 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll
QuickTime Plug-in 7.7.2 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll
QuickTime Plug-in 7.7.2 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll
QuickTime Plug-in 7.7.2 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll
RACtrl.dll C:\Windows\Downloaded Program Files\RACtrl.dll
Silverlight Plug-In c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
Windows® Internet Explorer C:\Windows\SysWOW64\ieframe.dll
(verified) Microsoft® Windows® Operating System C:\Windows\system32\napinsp.dll
(verified) Microsoft® Windows® Operating System C:\Windows\system32\pnrpnsp.dll
(verified) Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll


Scan
----
MD5: af2d37ab53313c8d8f152a3c2c5a0c1f C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe
MD5: f58c188993c1eeea643f39e1b67c8932 C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
MD5: 7ec56424e3e77ebf4bf5e0798175e4e5 C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll
MD5: 8cc28e27a7c19022f13a80d0e8ad894c C:\Program Files (x86)\Adobe\Acrobat 10.0\PDFMaker\Common\AdobePDFMakerX.dll
MD5: 60b30ad1db4e126e4e327febe588186b C:\Program Files (x86)\Adobe\Acrobat 10.0\PDFMaker\Mail\Outlook\PDFMOutlook.dll
MD5: 7ec56424e3e77ebf4bf5e0798175e4e5 C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
MD5: 5c37a77bb8c777e7df19f6a52cc2ed44 C:\Program Files (x86)\Blue Iris\blueiris.exe
MD5: 7525c8cf307aaf9d92e5cf8a62eac81a C:\Program Files (x86)\Blue Iris\BlueIrisService.exe
MD5: b721f1f5eadbb2ef465480e172d2ce41 C:\Program Files (x86)\Blue Iris\pthreadGC2.dll
MD5: a97ecc8fedcc42cc31fb63969c8c1eaf c:\program files (x86)\common files\adobe\acrobat\activex\acroiefavclient.dll
MD5: 60e5af8b7b4140c711b050fae5a3ab70 c:\program files (x86)\common files\adobe\acrobat\activex\acroiehelpershim.dll
MD5: b8e421c0890356cd4a793d8a346d9096 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
MD5: 62b7936f9036dd6ed36e6a7efa805dc0 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
MD5: 27cffb1e41a2be2a25957a679bd84e10 C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
MD5: 867ba8d62b2a821e0370f0f4087a04ae C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe
MD5: a3fe898e045c6557d3658f4fb0bc6beb C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\P6\adobe_oobelib.dll
MD5: ea5b870671079786f335ac7c10846c4f C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
MD5: 9c825b8bbef134fff112225202e22d1a C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\LogSession.dll
MD5: ada3ab542858a66153e9d6e0420e85b8 C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterCore.dll
MD5: 1315c5c5c54ce2aa37a155f97027db59 C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
MD5: f577910a133a592234ebaad3f3afa258 C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
MD5: 35ac4b63cbb9fb6b4472913e9948b517 C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
MD5: b961084d2fd400483f82d3d4d7021d2d C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe
MD5: 25fc19badf78b7fb1d835aac4b0b91a5 C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
MD5: 65e4bfc416f58b68d09bf2001c656679 C:\Program Files (x86)\Common Files\Intuit\Entitlement Client\v6.0\Client\EntitlementClientBootstrap.dll
MD5: f1abf7f07ccbf0ec5e498ee24cfe72f2 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\addinmgr2.dll
MD5: dd76260b9393d3fff1fa1915714bfd8f C:\Program Files (x86)\Common Files\Intuit\QuickBooks\CoLocator2.dll
MD5: 6bee1814470dc12fa20c53dfc3c97ebb C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
MD5: 291e76c02c0994e4e6f1f97a4bcf6c0e C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
MD5: a82c5d9e5972aeec9a21871283a3a3f2 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBInstanceFinder.dll
MD5: f5dd097058c147cde4c5aa476b2f3f2c C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\dbghelp.dll
MD5: 099a90aeff4b4faf237b5b7d73693f7b C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\QBMsgMgrps.dll
MD5: 31ac7c3e28666000217803f1c72b61c1 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\QBMsgRequestMgr.dll
MD5: 36b9b5bc9b1ec715290aa49ff4aeee5a C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\QBSendError20.dll
MD5: f1f70f17d1c2c8f27dc0a400e5614272 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\QBUChannel.dll
MD5: a3ff1233b62ed64659c16145aea5e8a7 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
MD5: 7f1711ce1c68c3643aa8b7d2944790c6 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\QBUServiceMgr.dll
MD5: fc2741a70b84d7e7ba5f51a352669ee8 C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\stlport_r50.dll
MD5: 2fca1e8a973e696de994b17772a266cb C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe
MD5: 98a078f838a70f84e1bd490d7c7675f4 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
MD5: 6d113e9c1210dfa7cba6f92a226c0748 C:\Program Files (x86)\Common Files\Microsoft Shared\office14\1033\MSOINTL.DLL
MD5: e9901a7e569c4156fda69f5c9356b8ed C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
MD5: 34e81b725e25d9184657667654d421a5 C:\Program Files (x86)\Common Files\Microsoft Shared\office14\mso.dll
MD5: a1cfdef143b1b4047e0fd3510f85de97 C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSPTLS.DLL
MD5: 4c0da2b69f8de16e97fcec0e19312923 C:\Program Files (x86)\Common Files\Microsoft Shared\office14\riched20.dll
MD5: 6df2076a4ac5e3655529142917b579a4 C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\USP10.DLL
MD5: 1d9c3d7a1f8838e6280fa3f7d1fe4ed8 C:\Program Files (x86)\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPC.DLL
MD5: dbea00b31017ab845fe97e2d118099d4 C:\Program Files (x86)\Common Files\SYSTEM\MSMAPI\1033\MSMAPI32.DLL
MD5: e2095c5cbe19cb17f8c6b07a5805b784 C:\Program Files (x86)\Common Files\System\Ole DB\oledb32.dll
MD5: 95a7e88a5f4ef79c605413f00a945cd3 C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCU.exe
MD5: f29d375926e36e3a56af4805c7749302 C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\BCUService.exe
MD5: 7c2dc40e725bcbb3b5f2757eb1443325 C:\Program Files (x86)\DeviceVM\Browser Configuration Utility\sqlite3.dll
MD5: f582c79814c604b589d085c0a02ca594 C:\Program Files (x86)\Flip Video\FlipShare\Core.dll
MD5: 0b9167adfe8e42b6b4c5e929bfbc7080 C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
MD5: 522bea25fbd2df7ba1101646cd8741c9 C:\Program Files (x86)\Flip Video\FlipShare\qca2.dll
MD5: c406e19f08b087eb01e26365b0f50558 C:\Program Files (x86)\Flip Video\FlipShare\QtCore4.dll
MD5: 41d22526f240bc9cb38656b6c328bd4d C:\Program Files (x86)\Flip Video\FlipShare\QtGui4.dll
MD5: c13844e25cffd2f9067694a0ddb69824 C:\Program Files (x86)\Flip Video\FlipShare\QtSql4.dll
MD5: 37162b93153135c25a9dea0952c0f41a C:\Program Files (x86)\Flip Video\FlipShare\QtXml4.dll
MD5: b8fa96995726d1fa58476e352c02ad82 C:\Program Files (x86)\Gigabyte\EasySaver\essvr.exe
MD5: db8edc434deb6ed687108817e6b3c7f3 C:\Program Files (x86)\Gigabyte\EasySaver\YCC.DLL
MD5: b78f4c2c592c87df54e8e0c6aaef3874 C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
MD5: 8f628060daecf76c537bd89a53228d3b C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
MD5: 506708142bc63daba64f2d3ad1dcd5bf C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
MD5: 63da875725652fb8fdf6fd0d38f1a42e C:\Program Files (x86)\HP\Digital Imaging\Fax\Fax Driver 0.6 Base\hppfaxprintersrv.exe
MD5: 4ec5e852a5e67b33966614a9b2c56d95 C:\Program Files (x86)\HP\hp LaserJet M1522\hppfaxprintersrv.exe
MD5: 3847caf217f87c2e8e5ba4c05ac28355 C:\Program Files (x86)\HP\HPLaserJetService\HPHTTPProxy.dll
MD5: d1e9cb573a9edf7be12e9c57f32e97f7 C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe
MD5: 4665992ece372ff4ec769df61e2fe673 C:\Program Files (x86)\HP\HPLaserJetService\HPServiceCommunicator.dll
MD5: 7191f5b574b286871469da95d2e2d71e C:\Program Files (x86)\HP\HPLaserJetService\HPTools.dll
MD5: d1cb8ab85a06c48f013a134100a9fde0 C:\Program Files (x86)\HP\HPLaserJetService\LEDMXMLObjects.dll
MD5: 10923cb228e1e591ac238c3c437bdf75 C:\Program Files (x86)\HP\ToolboxFX\bin\HPTLBXFX.exe
MD5: eafc0d1a6ef9f9a5093501793266107a c:\program files (x86)\ibm\lotus forms\viewer\3.5\pehelper.dll
MD5: 20aa5135c856c44b08333365ebfa8087 C:\Program Files (x86)\Internet Explorer\ieproxy.dll
MD5: 868722237aa095367491785e5c41ef0d C:\Program Files (x86)\Internet Explorer\IEShims.dll
MD5: 93569d46d79f9756ed077156496afe23 C:\Program Files (x86)\Internet Explorer\iexplore.exe
MD5: 7d894ed61ef0505277d8a476d7df43f1 C:\Program Files (x86)\Internet Explorer\plugins\nppdf32.dll
MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin.dll
MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin2.dll
MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin3.dll
MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin4.dll
MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin5.dll
MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin6.dll
MD5: 2f7480a40151eb2e483cf6524edba3f7 C:\Program Files (x86)\Internet Explorer\plugins\npqtplugin7.dll
MD5: 8ff2db82ae43e862d1d648b3f0fefa97 C:\Program Files (x86)\Intuit\QuickBooks 2012\abmapi.dll
MD5: a0961255b051a07241f857adae125806 C:\Program Files (x86)\Intuit\QuickBooks 2012\Accountant.dll
MD5: 8242517f746084b3c925e4b054e2f043 C:\Program Files (x86)\Intuit\QuickBooks 2012\ACE.dll
MD5: 3830244a5f532d7036488517ea57d522 C:\Program Files (x86)\Intuit\QuickBooks 2012\ACM.dll
MD5: 15f45ff0ed4f7a9c684a2f19406ccbf9 C:\Program Files (x86)\Intuit\QuickBooks 2012\ADR.dll
MD5: 1e0c2c2ccc3e3d0180cce8c82deb379c C:\Program Files (x86)\Intuit\QuickBooks 2012\APPCORE.dll
MD5: 45a1a5d64ca5e2cfb9e84aff4fa04856 C:\Program Files (x86)\Intuit\QuickBooks 2012\BackupLib.dll
MD5: f68f1a5434849892f133240c32d18254 C:\Program Files (x86)\Intuit\QuickBooks 2012\bizutil.dll
MD5: b681696e2901edb570e4aeecb26dfcfc C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_regex-vc90-mt-p-1_33.dll
MD5: 533e9750e9e07f317ce3520f42d11265 C:\Program Files (x86)\Intuit\QuickBooks 2012\boost_serialization-vc90-mt-p-1_33.dll
MD5: 20c56587b092e1734a61168fc39e9047 C:\Program Files (x86)\Intuit\QuickBooks 2012\cindexdb.dll
MD5: 213ef0c87376041e5945b71d8fd7da19 C:\Program Files (x86)\Intuit\QuickBooks 2012\DatabaseManager.dll
MD5: f5dd097058c147cde4c5aa476b2f3f2c C:\Program Files (x86)\Intuit\QuickBooks 2012\dbghelp.dll
MD5: deb0c6e41c81f4ac37eda3e526520981 C:\Program Files (x86)\Intuit\QuickBooks 2012\dbicu11.dll
MD5: 89769b8dae658e1f301fa085ea5b9ff0 C:\Program Files (x86)\Intuit\QuickBooks 2012\dbicudt11.dll
MD5: ca6caf4453b483765e6a25fb491b9b56 C:\Program Files (x86)\Intuit\QuickBooks 2012\dblgen11.dll
MD5: 1535273f63c2ce11e73d85c58abc6118 C:\Program Files (x86)\Intuit\QuickBooks 2012\dblib11.dll
MD5: d3457333710200a7a803ec4b0a2508d3 C:\Program Files (x86)\Intuit\QuickBooks 2012\dbtool11.dll
MD5: 1a3c94cd86e54463afd77e7887af8ecf C:\Program Files (x86)\Intuit\QuickBooks 2012\DMAccountant.dll
MD5: fc362ab6831b78bf2024ba47453f0c26 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMALIAS.dll
MD5: 66a1a7558ad2a9b29a10b5fbe080e4d5 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMAttachedDoc.dll
MD5: ebeb75a5aec43a6dc5f2ea9af758b9f5 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMAUDIT.dll
MD5: 410fb75d68c5f6c3e78c0f22c92bd15b C:\Program Files (x86)\Intuit\QuickBooks 2012\DMBUDGET.dll
MD5: d20b38e9c0bf739d2e19d73b1bfff145 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMCore.dll
MD5: c2750329907b689aee9c911ee1a88818 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMCustomerNotes.dll
MD5: 0800a350a29108d4b2b4f2cf33f38b3e C:\Program Files (x86)\Intuit\QuickBooks 2012\DMDATASYNC.dll
MD5: fa82f90fd9e56dade597bcaa8ea22175 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMDQE.dll
MD5: 8c7d02b1a581259e9b461220ec31a0aa C:\Program Files (x86)\Intuit\QuickBooks 2012\DMEDL.dll
MD5: 67c5313d31751a808f280757410b3b9c C:\Program Files (x86)\Intuit\QuickBooks 2012\DMGenPrefs.dll
MD5: a1ec037343a03d0b6c08177f9eb1f14f C:\Program Files (x86)\Intuit\QuickBooks 2012\DMInventory.dll
MD5: 38cf7590b3ea9fbf8d136bcbd4768c9c C:\Program Files (x86)\Intuit\QuickBooks 2012\DMMemorizedTransaction.dll
MD5: 90fd7fee8e01dd392d9169e039a27641 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMOLB.dll
MD5: 345a90c8f231da1d498f75baf39d156b C:\Program Files (x86)\Intuit\QuickBooks 2012\DMPAYROLL.dll
MD5: c2600262691011108a5f97b16296c9ed C:\Program Files (x86)\Intuit\QuickBooks 2012\DMPREFS.dll
MD5: bb7710c87f95d2a56269c376c8584545 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMTIME.dll
MD5: f54c445c756da613517068716d98e04c C:\Program Files (x86)\Intuit\QuickBooks 2012\DMTXN.dll
MD5: 3628d75b8d0719ff637fcc763dcee1d1 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMUI.dll
MD5: 38d9551e67341b9b5a6a9b1b20f561a2 C:\Program Files (x86)\Intuit\QuickBooks 2012\DMUSERS.dll
MD5: 498f8a8799d64a5b18338a535ced64e7 C:\Program Files (x86)\Intuit\QuickBooks 2012\DocumentManagement.dll
MD5: 58fbc453bb1b7b1f23a5097fea816a2c C:\Program Files (x86)\Intuit\QuickBooks 2012\ELCORE.dll
MD5: 8d163567e0f6141a7ba5a6ca3170212f C:\Program Files (x86)\Intuit\QuickBooks 2012\ESHELL.dll
MD5: 92c1a2946b05eb9dfa3c2206f026b824 C:\Program Files (x86)\Intuit\QuickBooks 2012\FeatureMgr.dll
MD5: 3ba5f98e9ed7768ae0ec8c5af96662f0 C:\Program Files (x86)\Intuit\QuickBooks 2012\Features.dll
MD5: dab9727c61b76822823e828669cc010d C:\Program Files (x86)\Intuit\QuickBooks 2012\FileManifest.dll
MD5: 6cc712ad9d916ea77e4bbdeed40f35e5 C:\Program Files (x86)\Intuit\QuickBooks 2012\mbpopup.dll
MD5: b5873b2d177dd3e618ea513c84c873f2 C:\Program Files (x86)\Intuit\QuickBooks 2012\msgDBAddIn.dll
MD5: 18bbf1e9a00baae89731899b89bd87d5 C:\Program Files (x86)\Intuit\QuickBooks 2012\NAAuthTool.dll
MD5: 6a738dd4ebafe78140170eb075c6b719 C:\Program Files (x86)\Intuit\QuickBooks 2012\OPAQUEBUFFER.dll
MD5: 2076a1470c7b2896570c85355edee70b C:\Program Files (x86)\Intuit\QuickBooks 2012\paycore.dll
MD5: 2e0e71e7d314d254fc94465ac6abbfd6 C:\Program Files (x86)\Intuit\QuickBooks 2012\PAYRES.dll
MD5: f4b59b8584b6647484921cc485dc5de1 C:\Program Files (x86)\Intuit\QuickBooks 2012\PAYSERV.dll
MD5: 9057bf9e5523521b5ddf72dffc1ecc1e C:\Program Files (x86)\Intuit\QuickBooks 2012\PAYUTIL.dll
MD5: 12c72b6981e3499c4b3e12538153c187 C:\Program Files (x86)\Intuit\QuickBooks 2012\payxsgen.dll
MD5: 6d7c5f47672adcc828cd9dd5dc6d9c53 C:\Program Files (x86)\Intuit\QuickBooks 2012\PM.dll
MD5: 67a090204a309ab38f27cf145ea41602 C:\Program Files (x86)\Intuit\QuickBooks 2012\PortFile.dll
MD5: f0a1b914958ef24463f334b88c160edf C:\Program Files (x86)\Intuit\QuickBooks 2012\PREFS.dll
MD5: a96fbd04944c2ba110be423623ce10de C:\Program Files (x86)\Intuit\QuickBooks 2012\PRLoader.dll
MD5: d779beb1a2a2283e3774aa79d0186f50 C:\Program Files (x86)\Intuit\QuickBooks 2012\PRNotificationLoader.dll
MD5: 5ac1c60be6262119a0cb766dfbb52b13 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBATTR32.dll
MD5: 731279db7cf33889829a205eb07e387c C:\Program Files (x86)\Intuit\QuickBooks 2012\qbbrow32.dll
MD5: 004a52e52751061d34d77a3d905a5533 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBCHAO32.dll
MD5: 112967dfa9b7cb88aaaa0038748a88c9 C:\Program Files (x86)\Intuit\QuickBooks 2012\qbci32.dll
MD5: e3533756fd82f66b92edfea25f72aeae C:\Program Files (x86)\Intuit\QuickBooks 2012\QBCompressor.dll
MD5: e7be54e6ccec26111020bd781a27cf6e C:\Program Files (x86)\Intuit\QuickBooks 2012\QBCONV32.dll
MD5: 30ab0523438b53f6e1b829814375fdda C:\Program Files (x86)\Intuit\QuickBooks 2012\QBDomain.dll
MD5: 680c0214e1477e1ff6855f2b9c6b279e C:\Program Files (x86)\Intuit\QuickBooks 2012\qbform32.dll
MD5: b7cad5f7e9e102f0c4642a76c57c703f C:\Program Files (x86)\Intuit\QuickBooks 2012\QBInbox.dll
MD5: 9350126ec4c72636b53cf7bfe18b59d4 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBINTR32.dll
MD5: 7123de019992325dd41d3b3d1cd8f5bb C:\Program Files (x86)\Intuit\QuickBooks 2012\QBITools.dll
MD5: e12ca6111a68875c31b0201bb19103cd C:\Program Files (x86)\Intuit\QuickBooks 2012\qblist32.dll
MD5: 097935840bf1b0579c31aa85d1035642 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBMAPILibrary.dll
MD5: 75e4958c8904c792c79f5a97b2ab0b7a C:\Program Files (x86)\Intuit\QuickBooks 2012\QBMAS32.dll
MD5: 50efd5abe231155bbda2822e7f63e0fb C:\Program Files (x86)\Intuit\QuickBooks 2012\QBMFCT32.dll
MD5: 2d2da26ab50ef9bbdcc19b37f6348312 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBMSIntg.DLL
MD5: 44fe3a36b67d8ae26f7536cb0af82316 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBOESD32.dll
MD5: 8e3ed2ac9cf5745349d6b1644576af34 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBONLI32.dll
MD5: 885f803ac160a7fd75bd3c30e2a69a9a C:\Program Files (x86)\Intuit\QuickBooks 2012\qbot.dll
MD5: dc1c84f70d52ca84b0de3fb80fc90869 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBQWUT32.DLL
MD5: 2df7173832bfce52bf06962078f7bff9 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBSDKNotify.dll
MD5: 36b9b5bc9b1ec715290aa49ff4aeee5a C:\Program Files (x86)\Intuit\QuickBooks 2012\QBSendError20.dll
MD5: 13dd45a33318a40a7364fbd1a3f6d095 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBSTYL32.dll
MD5: 6e5c05068c4b70f9c07fee379de426e8 C:\Program Files (x86)\Intuit\QuickBooks 2012\qbtool32.dll
MD5: da203ea3b7ea737935c4aeeed68af2e5 C:\Program Files (x86)\Intuit\QuickBooks 2012\qbtxn32.dll
MD5: fcf0890f9e75f6c30549a8df200f72c0 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBUtilities.dll
MD5: b8c1dd7650292d8a995d55e7424a9480 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBW32.EXE
MD5: 279923f9253d1a81347b6054790be57e C:\Program Files (x86)\Intuit\QuickBooks 2012\qbwfls32.dll
MD5: 3fad3a328f94a8fededb364c86d4a738 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBWIN32.dll
MD5: 4e522f034787e3b94a7bfbf438fb8b38 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBWMain.dll
MD5: eb2f0d3ed653578fb5374359e7a02981 C:\Program Files (x86)\Intuit\QuickBooks 2012\qbwpsrun.dll
MD5: 7b6548181c1ea6f3df6ec99ae7e41e86 C:\Program Files (x86)\Intuit\QuickBooks 2012\QBWRPT32.dll
MD5: eb9a6abb516ba648771ec6cb2953c893 C:\Program Files (x86)\Intuit\QuickBooks 2012\qbxladin.dll
MD5: 52e3b6e137924b534519e3c8e7306249 C:\Program Files (x86)\Intuit\QuickBooks 2012\ReportInterop.dll
MD5: 9f4a092b05e9f00986959e159b8d8676 C:\Program Files (x86)\Intuit\QuickBooks 2012\sdkutil.dll
MD5: a23dbc0cfdcf59d16ce6aab742469fc0 C:\Program Files (x86)\Intuit\QuickBooks 2012\skucore.dll
MD5: 7d19a64d6b085f15eef03b7a80cf0df1 C:\Program Files (x86)\Intuit\QuickBooks 2012\SSCE5232.dll
MD5: fc2741a70b84d7e7ba5f51a352669ee8 C:\Program Files (x86)\Intuit\QuickBooks 2012\stlport_r50.dll
MD5: 06d890bf0b6f5b83690a12d541bd9cbd C:\Program Files (x86)\Intuit\QuickBooks 2012\TEJ32.dll
MD5: d97ee2d56b95377b72bd16f11e2e4a8c C:\Program Files (x86)\Intuit\QuickBooks 2012\TRACKING.dll
MD5: 65138cf0cb4c702c82b799321437b80c C:\Program Files (x86)\Intuit\QuickBooks 2012\txncore.dll
MD5: 296643b2ec8fd9da3a9d07e627c9c827 C:\Program Files (x86)\Intuit\QuickBooks 2012\TXNFORM.dll
MD5: 7675f45ddab7f239c2cd3e497589c658 C:\Program Files (x86)\Intuit\QuickBooks 2012\ui.dll
MD5: 2834d9fc6f215c416ca8454d0c131f9e C:\Program Files (x86)\Intuit\QuickBooks 2012\UM.dll
MD5: af5f0020bb469450fa68dd3fedd63bba c:\program files (x86)\java\jre6\bin\jp2ssv.dll
MD5: 036ca317c20df6a8fe39ca31882290ad C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
MD5: 0917c10b217a56ec7d1b061eff355b95 c:\program files (x86)\java\jre6\bin\ssv.dll
MD5: be7ffc73a049d3696ccb53aeaa2e8c90 C:\Program Files (x86)\LogMeIn Backup\BackupMaint.exe
MD5: 075e69f0bd992131b1aaec6ea47d1a58 C:\Program Files (x86)\LogMeIn Backup\BackupSystray.exe
MD5: efe7f2d371f88d8f4daf2fae1f2b5e18 C:\Program Files (x86)\LogMeIn Backup\LMIBackupVSSServiceX64.exe
MD5: 8a6642758f2f954e1233758961e70dfd C:\Program Files (x86)\LogMeIn Backup\LMIGuardian.exe
MD5: 21970bb812422bc408cc20544814dc87 C:\Program Files (x86)\LogMeIn Backup\LMIGuardianDll.dll
MD5: 33ba2bfd2c8bc105c13b4723261559e4 C:\Program Files (x86)\LogMeIn Backup\LogmeInBackupService.exe
MD5: 7207b7a12f23949c9a497e52f99be56c C:\Program Files (x86)\LogMeIn Backup\rntfywnd.dll
MD5: 444ae42f662df4e463e0d51adebd4f15 C:\Program Files (x86)\LogMeIn Backup\xerces-c_2_7.dll
MD5: 77756f6645c441c1fc659007ce520f08 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
MD5: 21d24138b736983f6e23823e092e9428 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
MD5: 98b0fcc176dfb711b67651becb88c445 C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
MD5: d3760bc17e1755091b7120cf32dbf56b C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe
MD5: 223a96bac91792e1a954bfeb49fbe02c C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
MD5: 0317335b15ff3bda8e10197e3434cfc0 C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys
MD5: b712511029cbd68645a90a241fd6ae43 C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe
MD5: fb665485b6c8ee16fed0619adff8b27a C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll
MD5: 8f233c5bc68e34d18d38257b283ce96c C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.dll
MD5: 84db35f319e5b67838a4877c11748866 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
MD5: 24744f14e76174927aa2bd4600709192 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll
MD5: 43683e970f008c93c9429ef428147a54 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
MD5: 30b7e077c11dcc394069b3332c4622f5 c:\Program Files (x86)\Microsoft Office\Office14\1033\MAPIR.DLL
MD5: 7534b4a05d68c2fd50508a3494042e4a C:\Program Files (x86)\Microsoft Office\Office14\1033\omsintl.dll
MD5: 1f138e3c54f19d2bb39d21289f00be20 C:\Program Files (x86)\Microsoft Office\Office14\1033\OUTLLIBR.DLL
MD5: 09e3c0afa3c095a938bef6957b8e75bd C:\Program Files (x86)\Microsoft Office\Office14\1033\UmOutlookStrings.dll
MD5: 572b3225fd8c1d6c741bee61e8edc5de C:\Program Files (x86)\Microsoft Office\Office14\1033\wwintl.dll
MD5: 782e26dc7630ac0619ac58128ede5180 C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\ColleagueImport.dll
MD5: c2686ff303bca00915e38ec10f63359e C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
MD5: 0e596327b0916269015fda97643b09f9 c:\Program Files (x86)\Microsoft Office\Office14\CONTAB32.DLL
MD5: 80e0d27b9a1815619a45d3071906af42 c:\Program Files (x86)\Microsoft Office\Office14\EXSEC32.DLL
MD5: 140cce53806f79c2e45bd198e76dc79e C:\Program Files (x86)\Microsoft Office\Office14\gfx.dll
MD5: 7a48223093a2b6fecb00e4360c71dcc2 C:\Program Files (x86)\Microsoft Office\Office14\msproof7.dll
MD5: 8c9cb3006847d742a4fa70ad4a2fd176 c:\Program Files (x86)\Microsoft Office\Office14\MSPST32.DLL
MD5: a0ae3739a2b9a256df984244c763577c C:\Program Files (x86)\Microsoft Office\Office14\oart.dll
MD5: 9c88af1e803b3dcbcd83df5f9ae921ba c:\Program Files (x86)\Microsoft Office\Office14\OLMAPI32.DLL
MD5: 0bf193b4000a73894b970a50ce509c88 C:\Program Files (x86)\Microsoft Office\Office14\OMSMAIN.DLL
MD5: 8a0c2996e5528619263abedd08115e8c c:\Program Files (x86)\Microsoft Office\Office14\OMSXP32.DLL
MD5: b0a84b6b79837bba2a7150fe07aeed3a C:\Program Files (x86)\Microsoft Office\Office14\ONBttnOL.dll
MD5: 5b97a4f154e1dbba1d47a6a26ff8d4b8 C:\Program Files (x86)\Microsoft Office\Office14\OUTLFLTR.DLL
MD5: 2873d3f9501a1406bcc8be6a0ee5a9d4 C:\Program Files (x86)\Microsoft Office\Office14\OUTLMIME.DLL
MD5: 391dda05d6299f09ff41b4339fb963ec C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
MD5: 7a046cfd5a8e150e42b8dcd9ad36f18c c:\Program Files (x86)\Microsoft Office\Office14\OUTLPH.DLL
MD5: 4e66a61484a136641a0339374976d256 c:\Program Files (x86)\Microsoft Office\Office14\OUTLRPC.DLL
MD5: fd41ecec831c4d85e6fd42a6d5ec1b57 C:\Program Files (x86)\Microsoft Office\OFFICE14\PROOF\1033\MSGR3EN.DLL
MD5: fbf07f7833828bcd70e32c054c96417c c:\Program Files (x86)\Microsoft Office\Office14\RTFHTML.DLL
MD5: 97a59c059f2e63e9d6e00c92baf28d69 C:\Program Files (x86)\Microsoft Office\Office14\SHAREPOINTPROVIDER.DLL
MD5: 4622b6d3f72adb63ded8ad4f99f3ba0d C:\Program Files (x86)\Microsoft Office\Office14\SOCIALCONNECTOR.DLL
MD5: a5d08b86e8a437aa6deaf7a187bf6ca5 c:\program files (x86)\microsoft office\office14\urlredir.dll
MD5: 69f0de7620cbf347cfcf24d81de3118b C:\Program Files (x86)\Microsoft Office\Office14\wwlib.dll
MD5: 891348171414bf1fd6bbbd46159d5446 c:\Program Files (x86)\Microsoft Security Client\MpOAv.dll
MD5: 711a2e6a55ec7bfd59b5f649d58b704b c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
MD5: 72e83be153683087ebc2067655598323 C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.dll
MD5: 1a5024838562999647a7e1b6b62f91f4 C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
MD5: 916a2c4eb028604783fd5ea169236c1d C:\Program Files (x86)\QuickTime\QTTask.exe
MD5: e9605a180001a6b5551112d91de92ca1 C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
MD5: 1144f1a221f756e05525179b5e1682c1 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
MD5: 21627f3983773b624d16448640fb7505 C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcherLOC.DLL
MD5: 1a18ea36f750b320f816f4eaf104720d C:\Program Files (x86)\Sony\PMB\XpStorageDevice_WinXp2k.dll
MD5: 7772dfab22611050b79504e671b06e6e C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
MD5: df72d700cc33611206675b8a2fd4d4f9 C:\Program Files\Logitech\SetPointP\SetPoint.exe
MD5: 59faaf2c83c8169ea20f9e335e418907 c:\Program Files\Microsoft Security Client\MsMpEng.exe
MD5: 00490c2a421579311eff460addab7ad0 c:\Program Files\Microsoft Security Client\msseces.exe
MD5: 10a43829a9e606af3eef25a1c1665923 c:\Program Files\Microsoft Security Client\NisSrv.exe
MD5: d31e3530a549b3be3529773643a8fb75 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
MD5: a9f3bfc9345f49614d5859ec95b9e994 C:\Program Files\Windows Media Player\wmpnetwk.exe
MD5: 79ea8dc31d5c22ad7d183de881c0ca7b C:\PROGRA~2\Intuit\QUICKB~2\QBDBMgrN.exe
MD5: adc791328ea38ba2e3eec817c95a7d35 C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\Dropbox.exe
MD5: 6d74290856347cf8682277a54b433d4b C:\Users\Rob Lutz\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
MD5: 9c17dcd6ddfeb1a012544faf4f2789f6 C:\Windows\AppPatch\AcGenral.DLL
MD5: 6d7de520d8aa80a243347becd401eb54 C:\Windows\AppPatch\AcWow64.DLL
MD5: 35cab7cf3754c41aeb69dce1d5aca5a4 C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MD5: 90c3b9428bd325eeb67592f640b1c4b1 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\12715b7e3e89758161053520b57764b2\Microsoft.PowerShell.ConsoleHost.ni.dll
MD5: 64d4eef586c19ab70a8f9fe778da1bbd C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\1f1185444c8a12ace85ba4c2d49f41f8\Microsoft.PowerShell.Security.ni.dll
MD5: 2911a38961d7b360c6ed0e65fdc0a1cc C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\99ae5f32cd1dc3618659bc3c77f2b2a9\Microsoft.PowerShell.Commands.Utility.ni.dll
MD5: de2c1ca744590ce5a932932534c8de68 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\ba2ca86f5d270f493501848843d2f227\Microsoft.PowerShell.Commands.Management.ni.dll
MD5: b51e55d1d2e1d57eefb258d840ae4e17 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\d4c36b363fcd1ca494218e74ba606e99\Microsoft.PowerShell.Commands.Diagnostics.ni.dll
MD5: ef5bfddf2a85aaf9f91ac114ac5a1bfb C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\66cd99d2f576cde047074e98bd5e1848\Microsoft.Windows.Diagnosis.Commands.UpdateDiagReport.ni.dll
MD5: 0d85b2a3419a8169ecfb1381f4beb00d C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\91767cf3facefe10e00734c815e925ad\Microsoft.Windows.Diagnosis.Commands.WriteDiagProgress.ni.dll
MD5: 60039613c96ec9a2c22a3219ed32d61d C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\c6e9143be5afb36345875d56b61c444f\Microsoft.Windows.Diagnosis.Commands.GetDiagInput.ni.dll
MD5: 36e4555d4b5f697be39761e937ad1b99 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\cb8ad29814d9e5589bd400d38e7a0b10\Microsoft.Windows.Diagnosis.SDHost.ni.dll
MD5: e17b2d421736ce74b979c78e8ffcca95 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Windows.D#\d797123d55bb7b823120d0a7ffbbc2a7\Microsoft.Windows.Diagnosis.Commands.UpdateDiagRootcause.ni.dll
MD5: c51011e4c9d296bd97e479f64aec9040 C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.WSMan.Man#\070505350ec9daa3343b3cd2bc8cf59e\Microsoft.WSMan.Management.ni.dll
MD5: c2335d714efafffb4c7a3c164f2024b1 C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MD5: e4b5ce0f5ff43e8cf045294a7cbe7def C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\498d2033c60fe5b777cf923b71b25972\System.Configuration.Install.ni.dll
MD5: 10307046e19c8ec964c792a798b32bb3 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MD5: 5f44b1a92e09e8803b0a10da6b1d15c9 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MD5: 411c1c00a8b9e363dd9651b30ef9b6a7 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
MD5: 6f36d13ee887744ca30356c30e39c1a1 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\ef0d8a4790c24a3a091170958bc7b976\System.DirectoryServices.ni.dll
MD5: 1658cef509faa676493882e6ae2a111e C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a8495b797e6f7adddc5811a4e1f97db5\System.Management.Automation.ni.dll
MD5: e4993a704aca876fc68e3fe2ef858e1e C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\9b2f17fb61b7197f2a04108f5d1a1cc6\System.Management.ni.dll
MD5: a490b22bd077d42e385581047801b6b2 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MD5: 94688e6bbd0f9e2a47ae60ee39109c82 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\2ff4e90c5842525f7a7456639de090d8\System.Runtime.Serialization.Formatters.Soap.ni.dll
MD5: 17fadecb631ff8dbe735ba33409885c2 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\69ca4a43ba14b66689715ad62aed70e6\System.ServiceProcess.ni.dll
MD5: f33f62ed873d99ee045d3a0731e27342 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\80fae9f16f80075535e72458ef293f7a\System.Transactions.ni.dll
MD5: fab18e11587305bf8039ea6f8f731207 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
MD5: 2291d1fabc087e43d4122cace1ca30f9 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MD5: 26a68554f95a344b62e5771af598e0e8 C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MD5: 8495229cb7e717879c8e6a22ef661d09 C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MD5: 3896f4277963c628a3fc5100b4f47ecf C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\5552b27237c3dbe4f21a10e97adf2edc\System.ServiceProcess.ni.dll
MD5: 0d572d08224dc6f65e686a522dc1f4da C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MD5: 213dc90f1893e90f4e8da03fef91ff02 C:\Windows\Downloaded Program Files\avutil-51.dll
MD5: 5aeb62ca67c4b967d77168430f176a4f C:\Windows\Downloaded Program Files\Dldrv.ocx
MD5: 10addd17fb90dcc75827ebe4fa5946f6 C:\Windows\Downloaded Program Files\DownloadManagerV2.ocx
MD5: 67bfadd07b20acdc11da8569fe82af83 C:\Windows\Downloaded Program Files\LMIBroker.exe
MD5: 8ddb1dc9b41b152e2c01e6cc6b26e684 C:\Windows\Downloaded Program Files\LMIGuardian.exe
MD5: a02a4fde3191f652857d9c087c6c12a9 C:\Windows\Downloaded Program Files\LMIGuardianDll.dll
MD5: 990ed734254b1d43884bd4a856e75b2e C:\Windows\Downloaded Program Files\LMIGuardianEvt.dll
MD5: 61cd188d74823023f4d3ceeedf06da44 C:\Windows\Downloaded Program Files\Manager.exe
MD5: 342f560faedea525d83bd536f9d36a4e C:\Windows\Downloaded Program Files\pmjpegaudio.ocx
MD5: e3fb0c74ff1820eda188d757cb1d1ee5 C:\Windows\Downloaded Program Files\pmjpegcam.ocx
MD5: 56940b50ab0e5923822f47b0e4463885 C:\Windows\Downloaded Program Files\qsax.dll
MD5: 6d876930136a0e8814e0f99519f59208 C:\Windows\Downloaded Program Files\RACtrl.dll
MD5: 87c58d6b6e56b4ca2f005fa6ae7087a5 C:\Windows\Downloaded Program Files\swscale-2.dll
MD5: c4002b6b41975f057d98c439030cea07 C:\Windows\ehome\ehRecvr.exe
MD5: 332feab1435662fc6c672e25beb37be3 C:\Windows\Explorer.exe
MD5: 7907e14f9bcf3a4689c9a74a1a873cb6 C:\Windows\gdrv.sys
MD5: 5988fc40f8db5b0739cd1e3a5d0d78bd C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
MD5: a8b7f3818ab65695e3a0bb3279f6dce6 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
MD5: 7b46a076184b73aedc1a66a71d9131e8 C:\Windows\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
MD5: 75bcc4043512e41d83c8f224b168039c C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
MD5: 4552f8f61a7975c2359d19673483604d C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
MD5: 215ce077258cedd5be4c56e9d614db9f C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
MD5: 781bf72f57cc9e5f85cb109c24d00fdc C:\Windows\Microsoft.NET\Framework\v4.0.30319\clrjit.dll
MD5: f5df6846f30e9f54ea60ccaeb3fb2055 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
MD5: 35ed37326421112206caabc025fdcdab C:\Windows\Microsoft.NET\Framework\v4.0.30319\nlssorting.dll
MD5: db4e2d9c09a5762cb2551222b5e443b2 C:\Windows\RaidTool\xInsIDE.exe
MD5: 773212b2aaa24c1e31f10246b15b276c C:\Windows\servicing\TrustedInstaller.exe
MD5: 37ce7a79d901235504f9add99a7ac177 C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
MD5: 7a044b0746d957bfd7aae18cfd8422c5 C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
MD5: 0a12d948b2cc7fbb01e28daa5e7c01ea C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
MD5: cb4863f2bd46aa02d954b86b56a149da C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
MD5: 2cae4ed96aa903578452b85e5383940c C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
MD5: e96170a923a69711b4d08e885f05d889 C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
MD5: 44ca750001f0db8c308d1ca4abd0f8e5 C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
MD5: 15df9eb8daba744e4d0e9b117f760f49 C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
MD5: a2385b02cb492131af6f79959a42a93f C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
MD5: 3ad0832e8e29fbe9bd722e3354dd4f57 C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
MD5: 88dc1714e38d4eb41a4378aab98e753b C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
MD5: a1d4deb5176c96b1a80715f6a1fdfb4f C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
MD5: b302a1630e5aea2d830b76bbcd761d72 C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
MD5: 22f767bb3b704f79363999bd4a49e68e C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
MD5: 00b83152f99e846fefb139c574cd4a96 C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
MD5: 50035c36acee069d0c209288208626d9 C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
MD5: cdf677ad479fa99f2e4d9766b83ef53c C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
MD5: 12c34c7325b74e8347e8db75279a8f3f C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
MD5: 96324ed3218133a13fff82055afac733 C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
MD5: a7bdf88a46bcc218b73e383e6547ba5f C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
MD5: 573c70d7076f2f101752a727db7c2280 C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
MD5: 29b01d02e9ff3d8a63f8747b50a5a1a3 C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
MD5: 0cc90316b34118e3b8af760d92c262a4 C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
MD5: 6f399c3e562c4e69df96039743a7aa26 C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
MD5: f3b94e04053c2483a6fecf953d6661d6 C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
MD5: c6942a18444bfffc3cceca69a7e1879c C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
MD5: f47e08b025ae376ef1342fc9ecfecdf1 C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
MD5: 8a13e14b68e00ac2cb67420396d8a1c5 C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
MD5: 863f793d15b4026b1a5fdeca873d4d84 C:\Windows\system32\apphelp.dll
MD5: d94e699220451be0a3416943fd5a12ba C:\Windows\system32\aticfx32.dll
MD5: ad7b5c93f2f111619a1d187e18acfcce C:\Windows\system32\atidxx32.dll
MD5: 1f7cbdd1031c25df4e8075afad248d91 C:\Windows\system32\atiuxpag.dll
MD5: c940f2f5c60b3727c5f18840735b229c C:\Windows\system32\AUDIOSES.DLL
MD5: e24fe90e9de8d8ae70e59f7b01675def C:\Windows\system32\AVICAP32.dll
MD5: dceabba22e12cc44c2e7785c0eb9c6e3 C:\Windows\system32\AVIFIL32.dll
MD5: 72910f1deb838e6e08a9017bfb7d4f0b C:\Windows\system32\BROWCLI.DLL
MD5: 775c41c2f2ef3dd150a7444b95e631d0 C:\Windows\system32\Bubbles.scr
MD5: 7a6986dd659b96398a11af5173892715 C:\Windows\system32\Cabinet.dll
MD5: ad7b9c14083b52bc532fba5948342b98 C:\Windows\system32\Cmd.exe
MD5: 4e5fe39c1076d115ec8bfcfe14d75b80 C:\Windows\system32\credssp.dll
MD5: 6316957bb3431dfb06bffa98c0f1926e C:\Windows\system32\cryptnet.dll
MD5: 06e771aa596b8761107ab57e99f128d7 C:\Windows\system32\cryptsvc.dll
MD5: 465bea35f7ed4a4a57686dea7ea10f47 C:\Windows\system32\cscapi.dll
MD5: 35cede6439ff0d8903223a0817ffe46c C:\Windows\system32\d2d1.dll
MD5: 2de90400a63818fa38c4c5c9adb166bf C:\Windows\system32\d3d10_1.dll
MD5: 9c36a3ca80f9b204c670336d344f5df8 C:\Windows\system32\d3d10_1core.dll
MD5: 78b7a3bda25c90daa50d36a56a8d1351 C:\Windows\system32\D3D10Warp.dll
MD5: 284b59d7b56fc76c80e622ab856b1fab C:\Windows\System32\davclnt.dll
MD5: 53223b673a3fa2f9a4d1c31c8d3f6cd8 C:\Windows\system32\dbghelp.dll
MD5: 162d247e995eaebf3ef4289069e1111c C:\Windows\system32\DEVRTL.dll
MD5: e9e01eb683c132f7fa27cd607b8a2b63 C:\Windows\system32\dhcpcore.dll
MD5: b40420876b9288e0a1c8cca8a84e5dc9 C:\Windows\system32\DNSAPI.dll
MD5: a29d734f650f958424743be3baa052c8 C:\Windows\system32\DWrite.dll
MD5: 0411b7958c524bb2e91ee1b3035fe321 C:\Windows\system32\dxgi.dll
MD5: 8b88ebbb05a0e56b7dcc708498c02b3e C:\Windows\system32\Explorer.exe
MD5: e2a17bcc08d92f42e08af6ba2f93aba7 C:\Windows\system32\explorerframe.dll
MD5: 03a03a453f1aaae0c73aaaf895321c7a C:\Windows\System32\fwpuclnt.dll
MD5: ed6f6fbbcdec95483b7351e23f4fcdf6 C:\Windows\system32\IEADVPACK.DLL
MD5: 32e15ecf5854f5610bc895490bc3246a C:\Windows\system32\IEFRAME.dll
MD5: 2cc34eff09799a50fa44299599f6589f C:\Windows\system32\IEUI.dll
MD5: 68563ac389f92ee79f1c714288ba1dce C:\Windows\system32\ImgUtil.dll
MD5: a6f09e5669d9a19035f6d942caa15882 C:\Windows\system32\IMM32.DLL
MD5: 703de467af3e19d13fcde095761dd46d C:\Windows\system32\InetClnt.dll
MD5: ed27d1d75bf5e683ad3edd9e3123520a C:\Windows\system32\INETCOMM.dll
MD5: bf7ddbe14fa4b68aab6a3c78ef5c96b8 C:\Windows\system32\inetmib1.dll
MD5: a90dc9abd65db1a8902f361103029952 C:\Windows\system32\IPHLPAPI.DLL
MD5: 8ea53101ff2b15bdff934b62a8fb326d C:\Windows\system32\LOGONCLI.DLL
MD5: 8bc9db92c4b2f3be89185beab2afc1f6 C:\Windows\system32\MAPI32.dll
MD5: eec60615b9a089b5fc056d34f1a03ef9 C:\Windows\system32\mcmjpg32.dll
MD5: 243974ec02f7ae49e4179c54624143ab C:\Windows\system32\MMDevAPI.DLL
MD5: 7f8678c59f188528d60104e697c2361e C:\Windows\system32\mscms.dll
MD5: d83947a58613e9091b4c9cc0f1546a8d C:\Windows\SYSTEM32\MSCOREE.DLL
MD5: 7069aab8536f29ed7323140973a2894b C:\Windows\system32\msdmo.dll
MD5: 7940c04ce581288a3498d57ec4ee47d2 C:\Windows\system32\msfeeds.dll
MD5: 5e8e869e1342308752a37a2c90cca79d C:\Windows\system32\MSHTML.dll
MD5: a6c29db53eca94fa8591c5388d604b82 C:\Windows\system32\Msi.dll
MD5: eee470f2a771fc0b543bdeef74fceca0 C:\Windows\system32\msiexec.exe
MD5: 35aae2e841aa1a949775168e119482c9 C:\Windows\system32\msls31.dll
MD5: c5a99a4c0dc9f0f5a95ba0c83d30a549 C:\Windows\System32\mstask.dll
MD5: c335ec1182ac10b188705554e0bc1186 C:\Windows\system32\MSVFW32.dll
MD5: 8999b8631c7fd9f7f9ec3cafd953ba24 C:\Windows\System32\mswsock.dll
MD5: 1cdea9188899e76d4ffd54c9d512ccdb C:\Windows\System32\msxml3.dll
MD5: d9a9702e43a5859896f34898d5fd3fec C:\Windows\System32\msxml6.dll
MD5: 8b57a1ad493653bb57f281fe75dd175b C:\Windows\System32\NaturalLanguage6.dll
MD5: 591fe0a6ceb19bf886ceb1331f591940 C:\Windows\system32\ncrypt.dll
MD5: cc6301055e753eb22aa77a1c00fcdd39 C:\Windows\system32\ndfapi.dll
MD5: 2fca0d2c59a855c54bafa22aa329df0f C:\Windows\system32\netapi32.dll
MD5: 20b3934db73eaba2b49b7177873cb81f C:\Windows\system32\netutils.dll
MD5: 3d57ffbad3ed16b63de3879bab0fb56f C:\Windows\system32\NetworkExplorer.dll
MD5: 104a1070e90f1c530328e69b49718841 C:\Windows\system32\NLAapi.dll
MD5: d7b7159bc8374e87d8c45a30377a3440 C:\Windows\System32\ntlanman.dll
MD5: 03f3b770dfbed6131653ceda8ca780f0 C:\Windows\system32\ntshrui.dll
MD5: 66abbf38123d3113bb55ebafcf37ab92 C:\Windows\system32\odbccp32.dll
MD5: 8e01332cc4b68bc6b5b7effe374442aa C:\Windows\system32\OLEACC.dll
MD5: 414bba67a3ded1d28437eb66aeb8a720 C:\Windows\system32\pla.dll
MD5: e98278865e8daba21cfe5fe4be34210a C:\Windows\system32\PortableDeviceApi.dll
MD5: 12c45e3cb6d65f73209549e2d02eca7a C:\Windows\system32\propsys.dll
MD5: dbc02d918fff1cad628acbe0c0eaa8e8 C:\Windows\system32\provsvc.dll
MD5: 102cf6879887bbe846a00c459e6d4abc C:\Windows\system32\RICHED20.dll
MD5: b5506b451bfe7148eca7056bda2970bd C:\Windows\system32\RICHED32.DLL
MD5: 5997d769cdb108390dcfaebf442bf816 C:\Windows\system32\RpcRtRemote.dll
MD5: 0915c4db6dbc3bb9e11b7ecbbe4b7159 C:\Windows\system32\rtutils.dll
MD5: 68ecca523ed760aafc03c5d587569859 C:\Windows\system32\SAMCLI.DLL
MD5: 3d3cbd1847f980fb03343a63671e7886 C:\Windows\system32\schannel.DLL
MD5: a42e7748be906434c5fd17161d168c20 C:\Windows\system32\SCHEDCLI.DLL
MD5: b45934fdaeb1710cec3d8f797fd481ca C:\Windows\System32\sdiageng.dll
MD5: 236f286e103fd44bd85fdd93097fd5dd C:\Windows\system32\SearchIndexer.exe
MD5: f93674263f6b07c77956e966953242d9 C:\Windows\system32\secur32.dll
MD5: 4ae380f39a0032eab7dd953030b26d28 C:\Windows\system32\sessenv.dll
MD5: be247ae996a9fde007a27b51413a6c79 C:\Windows\system32\SHDOCVW.dll
MD5: 414da952a35bf5d50192e28263b40577 C:\Windows\System32\shsvcs.dll
MD5: 4b9e4ce667df26ada061aa81e9aa841d C:\Windows\system32\SPFILEQ.dll
MD5: 5ccdcd40e732d54e0f7451ac66ac1c87 C:\Windows\system32\srvcli.dll
MD5: 6a1e8deb746912df47cf651e138401d7 C:\Windows\System32\StructuredQuery.dll
MD5: 919001d2bb17df06ca3f8ac16ad039f6 C:\Windows\system32\SXS.DLL
MD5: 613bf4820361543956909043a265c6ac C:\Windows\System32\tapisrv.dll
MD5: 465dbf63a5049e4db4bc5c12ffe781cb C:\Windows\system32\tquery.dll
MD5: d15618a0ff8dbc2c5bf3726bacc75a0b C:\Windows\system32\userenv.dll
MD5: 61ac3efdfacfdd3f0f11dd4fd4044223 c:\windows\system32\userinit.exe
MD5: cfc7d8289d2b5f3cf8d16e2db7f93d4a C:\Windows\system32\wbem\fastprox.dll
MD5: 704314fd398c81d5f342caa5df7b7f21 C:\Windows\system32\wbemcomn.dll
MD5: 34eee0dfaadb4f691d6d5308a51315dc C:\Windows\System32\wcncsvc.dll
MD5: d205c24a9d069049fe2df2a1b38726a7 C:\Windows\system32\wdmaud.drv
MD5: a9d880f97530d5b8fee278923349929d C:\Windows\System32\webclnt.dll
MD5: fb19fc5951a88f3c523e35c2c98d23c0 C:\Windows\system32\webio.dll
MD5: 590d5c506044fe02ff7643e32ff9bdac C:\Windows\system32\wer.dll
MD5: 1db71a41daee6b3f8cd0dda8209fa2d5 C:\Windows\system32\windowscodecs.dll
MD5: ca9f7888b524d8100b977c81f44c3234 C:\Windows\system32\WINHTTP.dll
MD5: d5aefad57c08349a4393d987df7c715d C:\Windows\system32\WINMM.dll
MD5: 9e4b0e7472b4ceba9e17f440b8cb0ab8 C:\Windows\system32\winspool.drv
MD5: 418e881201583a3039d81f43e39e6c78 C:\Windows\system32\WINSTA.dll
MD5: e5a4a1326a02f8e7b59e6c3270ce7202 C:\Windows\system32\wkscli.dll
MD5: 0f416e23dd2eb4debe70608020cfd283 C:\Windows\system32\WMVCore.DLL
MD5: 1b91cd34ea3a90ab6a4ef0550174f4cc C:\Windows\system32\WsmSvc.dll
MD5: 6a6b2ee4565a178035be2a4ff6f2c968 C:\Windows\system32\wtsapi32.dll
MD5: edf2a5e96bec469da3f64e9bdd386111 C:\Windows\system32\xmllite.dll
MD5: 9ac5bc11be9fe8127cadd07240e0cfd3 C:\Windows\system32\xvidcore.dll
MD5: d2958325c1ae1ae37a83334c6229e3bc C:\Windows\SysWOW64\actxprxy.dll
MD5: 95e2376b3323f062eb562b8586d0f14a C:\Windows\syswow64\ADVAPI32.dll
MD5: f436e847fa799ecd75ad8c313673f450 C:\Windows\syswow64\CFGMGR32.dll
MD5: d1de1eafde97be41cf6585027ff3e732 C:\Windows\syswow64\comdlg32.dll
MD5: 1295338cfe6f249823ef9bc8d4368a84 C:\Windows\syswow64\CRYPT32.dll
MD5: 6316957bb3431dfb06bffa98c0f1926e C:\Windows\SysWOW64\cryptnet.dll
MD5: 2eeff4502f5e13b1bed4a04ccad64c08 C:\Windows\syswow64\DEVOBJ.dll
MD5: b40420876b9288e0a1c8cca8a84e5dc9 C:\Windows\SysWoW64\DNSAPI.dll
MD5: 4312debdacbe338f0b90e7f08e7672be C:\Windows\SysWOW64\Dxtmsft.dll
MD5: ca493a92da9880b6f1a89c3dbd54ba5b C:\Windows\SysWOW64\Dxtrans.dll
MD5: d6d3ad7bf1d6f6ce9547613ed5e170a2 C:\Windows\syswow64\GDI32.dll
MD5: ee9d715af1b928982f417238b9914484 C:\Windows\SysWOW64\ieapfltr.dll
MD5: 32e15ecf5854f5610bc895490bc3246a C:\Windows\SysWOW64\ieframe.dll
MD5: b17adbbbdc97148d28f995f32c380f2e C:\Windows\syswow64\iertutil.dll
MD5: b2db6aba2e292235749b80a9c3dfa867 C:\Windows\syswow64\Imagehlp.dll
MD5: a6f09e5669d9a19035f6d942caa15882 C:\Windows\syswow64\IMM32.dll
MD5: a90dc9abd65db1a8902f361103029952 C:\Windows\SysWoW64\IPHLPAPI.DLL
MD5: 9f179da6bf972f2b8b7f90978d02d719 C:\Windows\SysWOW64\jscript9.dll
MD5: 99c3f8e9cc59d95666eb8d8a8b4c2beb C:\Windows\syswow64\kernel32.dll
MD5: 5c2d21c9b6b6175b89bc5d7e3cb979e1 C:\Windows\syswow64\KERNELBASE.dll
MD5: 09cc3cb9b87dd31a6ebfe5f9b99fdd4c C:\Windows\SysWOW64\Macromed\Flash\Flash32_11_3_300_271.ocx
MD5: a9d3b95e8466bd58eeb8a1154654e162 C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
MD5: 938f39b50bafe13d6f58c7790682c010 C:\Windows\syswow64\MSASN1.dll
MD5: d83947a58613e9091b4c9cc0f1546a8d C:\Windows\SysWOW64\MSCOREE.DLL
MD5: f67a64c46de10425045af682802f5ba6 C:\Windows\SysWOW64\msdt.exe
MD5: 3a16ea01fcfaab40882db5bfee632322 C:\Windows\SysWOW64\MSFTEDIT.DLL
MD5: 5e8e869e1342308752a37a2c90cca79d C:\Windows\SysWOW64\mshtml.dll
MD5: 9dc80a8aaaaac397bdab3c67165a824e C:\Windows\syswow64\msvcrt.dll
MD5: a5dc9940fdf092a85faf9969270bce7d c:\Windows\SysWOW64\msxml4.dll
MD5: 591fe0a6ceb19bf886ceb1331f591940 C:\Windows\SysWOW64\ncrypt.dll
MD5: 1c27d3e29218b6eaddb87a6b335637e3 C:\Windows\SysWOW64\npdeployJava1.dll
MD5: e73b0f1819602cb6ef176fb78d76a47b C:\Windows\SysWOW64\ntdll.dll
MD5: 928cf7268086631f54c3d8e17238c6dd C:\Windows\syswow64\ole32.dll
MD5: 8e01332cc4b68bc6b5b7effe374442aa C:\Windows\SysWOW64\OLEACC.dll
MD5: 6c765e82b57f2e66ce9c54ac238471d9 C:\Windows\syswow64\OLEAUT32.dll
MD5: c5ad8083cf94201f1f8084ecc696a8b7 C:\Windows\syswow64\RPCRT4.dll
MD5: 5997d769cdb108390dcfaebf442bf816 C:\Windows\SysWOW64\RpcRtRemote.dll
MD5: 68ecca523ed760aafc03c5d587569859 C:\Windows\SysWOW64\samcli.dll
MD5: 3d3cbd1847f980fb03343a63671e7886 C:\Windows\SysWOW64\schannel.dll
MD5: 15f07e50407139aa93d3fb6e612d2f74 C:\Windows\SysWOW64\sdiagnhost.exe
MD5: f93674263f6b07c77956e966953242d9 C:\Windows\SysWOW64\secur32.dll
MD5: 10fb16b50affda6d44588f3c445dc273 C:\Windows\syswow64\SETUPAPI.dll
MD5: 29e9794708df51db5dc89fb2e903a0f6 C:\Windows\syswow64\SHELL32.dll
MD5: 8cc3c111d653e96f3ea1590891491d71 C:\Windows\syswow64\SHLWAPI.dll
MD5: eda7ad21df8945528f01f0a86d69e524 C:\Windows\syswow64\SspiCli.dll
MD5: 919001d2bb17df06ca3f8ac16ad039f6 C:\Windows\SysWOW64\SXS.DLL
MD5: 544eff88ac6c85df5a4d6f18dfe08cfc C:\Windows\SysWOW64\taskschd.dll
MD5: 672d7c5080acb003343006405da2e621 C:\Windows\SysWOW64\thumbcache.dll
MD5: 667981f2e7c26275f0694b58eee303b9 C:\Windows\syswow64\urlmon.dll
MD5: 57300e71dfbb58d8ed0d7b9813e55795 C:\Windows\syswow64\USER32.dll
MD5: d15618a0ff8dbc2c5bf3726bacc75a0b C:\Windows\SysWOW64\USERENV.dll
MD5: 804aaafebb3ad5f49334dd906bcb1de5 C:\Windows\syswow64\USP10.dll
MD5: 5193de33f3284c447e0d31dafbf92570 c:\windows\syswow64\webcheck.dll
MD5: 75a97a2c060e72ab49e071e08c7dd2ba C:\Windows\syswow64\WININET.dll
MD5: d5aefad57c08349a4393d987df7c715d C:\Windows\SysWOW64\WINMM.dll
MD5: 418e881201583a3039d81f43e39e6c78 C:\Windows\SysWOW64\WINSTA.dll
MD5: a7d79e9f660340ab20cd73f12910985f C:\Windows\syswow64\WINTRUST.dll
MD5: a8bb45f9ecad993461e0fef8e2a99152 C:\Windows\syswow64\WLDAP32.dll
MD5: 436b7c33425d6445fdc733083c823458 C:\Windows\SysWOW64\WMADMOE.DLL
MD5: ee1320789a5b398c8bc2a6216953f625 C:\Windows\SysWOW64\WMSPDMOE.DLL
MD5: e19af92d61dc3e377f9df9bf72c7a128 C:\Windows\SysWOW64\wmvencod.dll
MD5: 106237bc218d53a0fcebd2ac7add5721 C:\Windows\SysWOW64\wmvsencd.dll
MD5: 50e32b49ed0aac7403550b63dac2db68 C:\Windows\SysWOW64\wmvxencd.dll
MD5: 7ff15a4f092cd4a96055ba69f903e3e9 C:\Windows\syswow64\WS2_32.dll
MD5: b4cda1b4263b53d249ac27a4892da634 C:\Windows\SysWOW64\XSrvSetup.exe
MD5: 0b3595a4ff0b36d68e5fc67fd7d70fdc C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCP80.dll
MD5: c9564cf4976e7e96b4052737aa2492b4 C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\MSVCR80.dll
MD5: 58a14c45a5cd2528f10a889e7b0c3fc2 C:\Windows\WinSxS\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.6161_none_51cd0a7abbe4e19b\ATL90.DLL
MD5: d34a527493f39af4491b3e909dc697ca C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
MD5: 4c39358ebdd2ffcd9132a30e1ec31e16 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCP90.dll
MD5: cdbe9690cf2b8409facad94fac9479c9 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\MSVCR90.dll
MD5: 5963633010616b25503ee126f55e8de4 C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90.dll
MD5: ca6ade4f7761bb15b3325356dc3b82bb C:\Windows\WinSxS\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_4bf7e3e2bf9ada4c\mfc90u.dll
MD5: fbfca1a574d47ee575448b719cbbf2e4 C:\Windows\WinSxS\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.6161_none_49768ef57548175e\MFC90ENU.DLL
MD5: bdac1aa64495d0f7e1ff810ebbf1f018 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\COMCTL32.dll
MD5: 352b3dc62a0d259a82a052238425c872 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
MD5: 7717f84f483002815490033bf069dabd C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17825_none_72d273598668a06b\gdiplus.dll


No file uploaded.

Scan finished - communication took 3 sec
Total traffic - 0.03 MB sent, 1.44 KB recvd
Scanned 704 files and modules - 34 seconds

==============================================================================

Just an FYI, computer still redirecting to scour.
  • 0

#15
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,797 posts
  • MVP
OK. Let's try fixing the user32.dll with OTL. First uninstall Malwarebytes' Anti-Malware so it doesn't interfere.

Copy the text in the code box by highlighting and Ctrl + c

:processes
killallprocesses 

:files
c:\windows\SysWOW64\user32.dll|c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll


:Commands
[EMPTYTEMP]
[Reboot]


then Rightclick on OTL and select Run As Administrator to start. Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the RUN FIX button (NOT THE QUICK SCAN button!) at the top
Let the program run unhindered, OTL will reboot the PC when it is done. Save the log and copy and paste it into a reply.


Copy the text in the code box:

/md5start
user32.dll
/md5stop


Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes


Click on Run Scan.

You should get one log. Please copy and paste it.

Get Process Explorer

http://live.sysinter...com/procexp.exe
Save it to your desktop then run it (Vista or Win7 - right click and Run As Administrator).

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header to sort things by CPU usage with the big hitters at the top.

Wait a minute for things to settle down.

File, Save As, Save. Open the file Procexp.txt on your desktop and copy and paste the text to a reply.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP