Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Unable to open anti-virus websites, microsoft website, [Closed]


  • This topic is locked This topic is locked

#1
ADR

ADR

    New Member

  • Member
  • Pip
  • 6 posts
Hi,

I'm new to this forum and this is my first post. Please help me out.

I'm not able to open any anti-virus website. Also, the microsoft website does not open. I'm able to boot in normal mode, but when I try safe mode, it just reboots immediately. I'm attaching the OTL log files if those help you to get an idea of the problem.


Please help me.

Regards,
ADRAttached File  OTL.Txt   225.07KB   77 downloads



OTL.txt
OTL logfile created on: 12/19/2012 8:44:14 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Samhita\My Documents\Downloads
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1014.36 Mb Total Physical Memory | 329.66 Mb Available Physical Memory | 32.50% Memory free
2.38 Gb Paging File | 1.81 Gb Available in Paging File | 76.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 15.61 Gb Total Space | 1.92 Gb Free Space | 12.33% Space Free | Partition Type: FAT32
Drive D: | 76.17 Gb Total Space | 33.84 Gb Free Space | 44.43% Space Free | Partition Type: NTFS
Drive E: | 7.01 Gb Total Space | 2.15 Gb Free Space | 30.71% Space Free | Partition Type: NTFS
Drive F: | 12.98 Gb Total Space | 6.83 Gb Free Space | 52.61% Space Free | Partition Type: NTFS

Computer Name: WIN2006 | User Name: Samhita | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Samhita\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\acs.exe (Atheros)
PRC - C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe ()
PRC - C:\Program Files\EzButton\EzButton.EXE (Dritek System Inc.)
PRC - C:\Program Files\Lenovo\EnergyCut\utilty.exe (Lenovo(Beijing)Limited)
PRC - C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe (Lenovo (Beijing) Limited)
PRC - C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\wincfi39.dll ()
MOD - C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe ()
MOD - C:\WINDOWS\system32\cpwmon2k.dll ()
MOD - C:\Program Files\Lenovo\EnergyCut\KbdHook.dll ()
MOD - C:\Program Files\Lenovo\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\Program Files\Lenovo\EnergyCut\HookLib.dll ()


========== Services (SafeList) ==========

SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) -- C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (NCO) -- C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSvcHst.exe (Symantec Corporation)
SRV - (NAV) -- C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvcHst.exe (Symantec Corporation)
SRV - (ACS) -- C:\WINDOWS\system32\acs.exe (Atheros)
SRV - (jswpsapi) -- C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WPS\jswpsapi.exe (wireless)
SRV - (HWDeviceService.exe) -- C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe ()
SRV - (btwdins) -- C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.)
SRV - (WMConnectCDS) -- C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (Micorsoft Windows Service) -- C:\DOCUME~1\Samhita\LOCALS~1\Temp\jdjxnhbu.sys File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (NAVEX15) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20121218.016\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20121218.016\NAVENG.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV - (ew_hwusbdev) -- C:\WINDOWS\system32\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV - (huawei_enumerator) -- C:\WINDOWS\system32\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV - (IDSxpx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20121215.001\IDSXpx86.sys (Symantec Corporation)
DRV - (BHDrvx86) -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20121130.005\BHDrvx86.sys (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\WINDOWS\system32\drivers\NAV\1402000.013\srtsp.sys (Symantec Corporation)
DRV - (SymEFA) -- C:\WINDOWS\system32\drivers\NAV\1402000.013\SymEFA.sys (Symantec Corporation)
DRV - (SymDS) -- C:\WINDOWS\system32\drivers\NAV\1402000.013\SymDS.sys (Symantec Corporation)
DRV - (ccSet_NST) -- C:\WINDOWS\system32\drivers\NST\7DD02000.012\ccSetx86.sys (Symantec Corporation)
DRV - (ccSet_NAV) -- C:\WINDOWS\system32\drivers\NAV\1402000.013\ccSetx86.sys (Symantec Corporation)
DRV - (SYMTDI) -- C:\WINDOWS\system32\drivers\NAV\1402000.013\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) -- C:\WINDOWS\system32\drivers\NAV\1402000.013\Ironx86.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\WINDOWS\system32\drivers\NAV\1402000.013\srtspx.sys (Symantec Corporation)
DRV - (AR9271) -- C:\WINDOWS\system32\drivers\athuw.sys (Atheros Communications, Inc.)
DRV - (WSIMD) -- C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.)
DRV - (JSWSCIMD) -- C:\WINDOWS\system32\drivers\jswscimd.sys (Atheros Communications, Inc.)
DRV - (WDC_SAM) -- C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (DritekPortIO) -- C:\Program Files\EzButton\DPortIO.sys (Dritek System Inc.)
DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.)
DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.)
DRV - (ApfiltrService) -- C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (IntcAzAudAddService) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (NETw4x32) -- C:\WINDOWS\system32\drivers\NETw4x32.sys (Intel Corporation)
DRV - (ACPIVPC) -- C:\WINDOWS\system32\drivers\AcpiVpc.sys (Lenovo Corporation)
DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (b57w2k) -- C:\WINDOWS\system32\drivers\b57xp32.sys (Broadcom Corporation)
DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-sea...000001b3800eee9
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://nortonsafe.se...ct=sb&qsrc=2869
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_110.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\IPSFFPlgn\ [2012/11/27 00:32:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F04D2D30-776C-4d02-8627-8E4385ECA58D}: C:\Documents and Settings\All Users\Application Data\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2013.2.0.18\coFFPlgn\ [2012/12/19 08:36:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/12/03 10:31:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2012/11/27 01:26:20 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Samhita\Application Data\Mozilla\Extensions
[2012/12/03 10:31:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/12/03 10:31:32 | 000,262,112 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/11/19 18:17:14 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/11/19 18:17:14 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/11/30 00:39:48 | 000,006,532 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\babylon.xml

O1 HOSTS File: ([2001/08/23 11:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Norton Identity Protection) - {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} - C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Norton Identity Safe Toolbar) - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\CoIEPlg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Identity Safe Toolbar) - {A13C2648-91D4-4BF3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [EnergyCut] C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe (Lenovo (Beijing) Limited)
O4 - HKLM..\Run: [EnergyUtility] C:\Program Files\Lenovo\EnergyCut\utilty.exe (Lenovo(Beijing)Limited)
O4 - HKLM..\Run: [EzButton] C:\Program Files\EzButton\EzButton.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKCU..\Run: [CriQnkii] C:\Documents and Settings\Samhita\Local Settings\Application Data\tlqedhyu\criqnkii.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B8D9B07-E3E6-40B0-B3B3-94B4C3D3CCC5}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{82DB0FD0-AA8B-45E1-9009-DD1F2540D717}: NameServer = 172.16.0.1
O20 - AppInit_DLLs: (c:\docume~1\alluse~1\applic~1\browse~1\25911~1.18\{c16c1~1\mngr.dll) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Documents and Settings\Samhita\Local Settings\Application Data\tlqedhyu\criqnkii.exe) - C:\Documents and Settings\Samhita\Local Settings\Application Data\tlqedhyu\criqnkii.exe File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/11/26 22:33:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ FAT32 ]
O33 - MountPoints2\{672403af-3ba4-11e2-8549-001b3800eee9}\Shell - "" = AutoRun
O33 - MountPoints2\{672403af-3ba4-11e2-8549-001b3800eee9}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{672403af-3ba4-11e2-8549-001b3800eee9}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{9cb90118-3815-11e2-be29-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{9cb90118-3815-11e2-be29-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9cb90118-3815-11e2-be29-806d6172696f}\Shell\AutoRun\command - "" = H:\setup.exe
O33 - MountPoints2\{cd64b460-387e-11e2-8533-c10e40fafa18}\Shell - "" = AutoRun
O33 - MountPoints2\{cd64b460-387e-11e2-8533-c10e40fafa18}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{cd64b460-387e-11e2-8533-c10e40fafa18}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - %SystemRoot%\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/19 07:56:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2012/12/19 07:56:04 | 000,000,000 | -HSD | C] -- C:\FOUND.002
[2012/12/18 23:09:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\Anni
[2012/12/18 23:06:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Local Settings\Application Data\tlqedhyu
[2012/12/13 21:54:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Local Settings\Application Data\CutePDF Writer
[2012/12/13 21:54:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\CutePDF
[2012/12/13 21:53:47 | 000,000,000 | ---D | C] -- C:\Program Files\Acro Software
[2012/12/13 21:52:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Start Menu\Programs\Ghostscript
[2012/12/13 21:52:42 | 000,000,000 | ---D | C] -- C:\Program Files\gs
[2012/12/04 21:16:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2012/12/03 10:31:19 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2012/12/02 11:18:38 | 000,159,232 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusd.dll
[2012/12/02 11:18:38 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ptpusb.dll
[2012/12/01 23:12:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\My Documents\Symantec
[2012/12/01 16:57:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Auslogics
[2012/12/01 16:57:45 | 000,000,000 | ---D | C] -- C:\Program Files\Auslogics
[2012/12/01 15:43:04 | 000,502,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usp10.dll
[2012/12/01 15:43:04 | 000,406,528 | ---- | C] (Microsoft Corporation) -- C:\usp10.dll
[2012/12/01 15:42:58 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Thawbrkr.dll
[2012/12/01 15:42:58 | 000,005,120 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdgeo.dll
[2012/12/01 15:42:58 | 000,005,120 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdarmw.dll
[2012/12/01 15:42:58 | 000,005,120 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdarme.dll
[2012/12/01 15:42:56 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinpun.dll
[2012/12/01 15:42:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdintel.dll
[2012/12/01 15:42:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdintam.dll
[2012/12/01 15:42:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinmar.dll
[2012/12/01 15:42:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinkan.dll
[2012/12/01 15:42:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinhin.dll
[2012/12/01 15:42:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdinguj.dll
[2012/12/01 15:42:55 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\c_iscii.dll
[2012/12/01 15:42:55 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdvntc.dll
[2012/12/01 15:42:55 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdindev.dll
[2012/12/01 15:42:52 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdurdu.dll
[2012/12/01 15:42:52 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsyr2.dll
[2012/12/01 15:42:52 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsyr1.dll
[2012/12/01 15:42:52 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbddiv2.dll
[2012/12/01 15:42:52 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbddiv1.dll
[2012/12/01 15:42:51 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdfa.dll
[2012/12/01 15:42:51 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbda3.dll
[2012/12/01 15:42:51 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbda2.dll
[2012/12/01 15:42:51 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbda1.dll
[2012/12/01 15:42:51 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdusa.dll
[2012/12/01 15:42:48 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdheb.dll
[2012/12/01 15:42:43 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdth3.dll
[2012/12/01 15:42:43 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdth2.dll
[2012/12/01 15:42:42 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ftlx041e.dll
[2012/12/01 15:42:42 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdth1.dll
[2012/12/01 15:42:42 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdth0.dll
[2012/12/01 15:42:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avro Keyboard
[2012/12/01 15:42:10 | 001,884,672 | ---- | C] (OmicronLab) -- C:\WINDOWS\System32\AvroSpell.dll
[2012/12/01 15:42:08 | 000,000,000 | ---D | C] -- C:\Program Files\Avro Keyboard
[2012/12/01 15:42:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avro Keyboard
[2012/12/01 09:20:32 | 000,011,520 | ---- | C] (Western Digital Technologies) -- C:\WINDOWS\System32\drivers\wdcsam.sys
[2012/12/01 09:20:32 | 000,000,000 | ---D | C] -- C:\Program Files\Western Digital
[2012/11/30 10:11:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\Old Firefox Data
[2012/11/30 07:21:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\WinRAR
[2012/11/30 07:20:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2012/11/30 07:20:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Start Menu\Programs\WinRAR
[2012/11/30 07:20:42 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012/11/30 02:00:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2012/11/30 00:39:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2012/11/30 00:39:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\Babylon
[2012/11/30 00:38:38 | 000,000,000 | ---D | C] -- C:\Program Files\TornTV.com
[2012/11/30 00:38:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Start Menu\Programs\TornTV.com
[2012/11/30 00:11:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\vlc
[2012/11/30 00:10:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2012/11/30 00:09:51 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2012/11/29 23:53:53 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\My Documents\My Videos
[2012/11/29 23:33:32 | 000,000,000 | -HSD | C] -- C:\Recycled
[2012/11/29 23:19:25 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2012/11/29 23:16:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\uTorrent
[2012/11/28 10:24:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Core Temp
[2012/11/28 10:24:31 | 000,000,000 | ---D | C] -- C:\Program Files\Core Temp
[2012/11/28 08:17:58 | 000,000,000 | ---D | C] -- C:\Downloads
[2012/11/28 08:16:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\Free Download Manager
[2012/11/28 08:16:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Free Download Manager
[2012/11/28 08:16:49 | 000,000,000 | ---D | C] -- C:\Program Files\Free Download Manager
[2012/11/28 08:09:00 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2012/11/27 11:32:32 | 000,000,000 | -HSD | C] -- C:\FOUND.001
[2012/11/27 10:21:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\LogFiles
[2012/11/27 10:14:51 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun
[2012/11/27 10:14:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Local Settings\Application Data\Sun
[2012/11/27 10:14:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Sun
[2012/11/27 10:14:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/11/27 10:14:17 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
[2012/11/27 10:14:17 | 000,746,984 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012/11/27 10:14:17 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012/11/27 10:14:17 | 000,143,872 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012/11/27 10:13:52 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012/11/27 10:13:52 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012/11/27 10:13:52 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/11/27 10:13:33 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/11/27 10:03:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\Sun
[2012/11/27 10:00:19 | 000,895,464 | ---- | C] (Oracle Corporation) -- C:\Documents and Settings\Samhita\Desktop\JavaSetup7u9.exe
[2012/11/27 09:14:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012/11/27 04:36:25 | 000,697,272 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/11/27 04:36:24 | 000,073,656 | ---- | C] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/11/27 04:26:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\DanuSoft
[2012/11/27 04:25:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Local Settings\Application Data\Adobe
[2012/11/27 04:25:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\Adobe
[2012/11/27 04:23:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012/11/27 04:23:35 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012/11/27 03:09:09 | 000,411,136 | ---- | C] (mHotspot) -- C:\Documents and Settings\All Users\Desktop\mHotspot.exe
[2012/11/27 03:08:10 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Samhita\PrivacIE
[2012/11/27 03:04:58 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Samhita\IETldCache
[2012/11/27 02:49:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\WBEM
[2012/11/27 02:47:59 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2012/11/27 02:47:59 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US
[2012/11/27 02:45:02 | 000,016,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll
[2012/11/27 02:44:55 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$
[2012/11/27 02:44:52 | 000,297,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msctf.dll
[2012/11/27 02:38:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\TP-LINK
[2012/11/27 02:37:39 | 000,405,582 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\jswscsup.dll
[2012/11/27 02:37:39 | 000,057,440 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\jswscimd.sys
[2012/11/27 02:37:39 | 000,057,440 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\drivers\jswscimd.sys
[2012/11/27 02:37:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TP-LINK
[2012/11/27 02:37:35 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data\Atheros
[2012/11/27 02:37:31 | 000,499,796 | ---- | C] (Atheros) -- C:\WINDOWS\System32\acs.exe
[2012/11/27 02:37:08 | 001,269,854 | ---- | C] (Devicescape) -- C:\WINDOWS\System32\dsa.dll
[2012/11/27 02:37:08 | 000,254,022 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\wsfwDS.dll
[2012/11/27 02:37:08 | 000,249,924 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\wsimd.dll
[2012/11/27 02:37:08 | 000,082,017 | ---- | C] (Devicescape, Inc.) -- C:\WINDOWS\System32\dsaNac.dll
[2012/11/27 02:37:08 | 000,058,208 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\wsimd.sys
[2012/11/27 02:37:08 | 000,058,208 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\drivers\wsimd.sys
[2012/11/27 02:37:06 | 000,405,504 | ---- | C] (Atheros) -- C:\WINDOWS\System32\wcapi.dll
[2012/11/27 02:37:06 | 000,360,539 | ---- | C] (Atheros) -- C:\WINDOWS\System32\wcapiU.dll
[2012/11/27 02:37:06 | 000,311,390 | ---- | C] (Atheros) -- C:\WINDOWS\System32\athcfg20U.dll
[2012/11/27 02:37:06 | 000,237,568 | ---- | C] (Atheros) -- C:\WINDOWS\System32\athcfg20.dll
[2012/11/27 02:37:06 | 000,127,079 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\athcfg20resU.dll
[2012/11/27 02:37:06 | 000,127,053 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\athcfg20res.dll
[2012/11/27 02:37:05 | 000,000,000 | ---D | C] -- C:\Program Files\TP-LINK
[2012/11/27 02:36:36 | 001,763,584 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\drivers\athuw.sys
[2012/11/27 02:36:36 | 001,763,584 | ---- | C] (Atheros Communications, Inc.) -- C:\WINDOWS\System32\athuw.sys
[2012/11/27 02:36:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TP-LINK
[2012/11/27 02:23:59 | 000,000,000 | ---D | C] -- C:\Program Files\Connector
[2012/11/27 02:20:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\My Documents\Downloads
[2012/11/27 01:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Local Settings\Application Data\Mozilla
[2012/11/27 01:26:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\Mozilla
[2012/11/27 01:25:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe
[2012/11/27 01:24:17 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012/11/27 01:24:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Mozilla
[2012/11/27 01:08:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\New Folder
[2012/11/27 01:08:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\N.PDF.Pro.7.4.x86
[2012/11/27 01:08:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\make bootable
[2012/11/27 01:08:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\HDFC rewards
[2012/11/27 01:08:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\grub4dos
[2012/11/27 01:08:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\FI
[2012/11/27 01:08:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop\Barfi
[2012/11/27 01:05:39 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mdimon.dll
[2012/11/27 01:05:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office
[2012/11/27 01:04:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2012/11/27 01:04:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2012/11/27 01:04:42 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2012/11/27 01:04:41 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/11/27 00:57:15 | 000,160,256 | R--- | C] (Broadcom Corporation) -- C:\WINDOWS\System32\drivers\b57xp32.sys
[2012/11/27 00:57:08 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2012/11/27 00:51:16 | 002,772,992 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\NETw4r32.dll
[2012/11/27 00:51:16 | 000,684,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\NETw4c32.dll
[2012/11/27 00:51:15 | 002,208,512 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\drivers\NETw4x32.sys
[2012/11/27 00:49:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Bluetooth Software
[2012/11/27 00:49:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\My Documents\Bluetooth Exchange Folder
[2012/11/27 00:47:59 | 000,106,557 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\btw_ci.dll
[2012/11/27 00:47:59 | 000,067,672 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btwusb.sys
[2012/11/27 00:47:58 | 000,862,922 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\drivers\btkrnl.sys
[2012/11/27 00:45:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\RTCOM
[2012/11/27 00:45:03 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2012/11/27 00:45:02 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll
[2012/11/27 00:45:01 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\portcls.sys
[2012/11/27 00:45:00 | 000,060,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys
[2012/11/27 00:44:56 | 009,715,200 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTLCPL.exe
[2012/11/27 00:44:56 | 001,191,936 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlUpd.exe
[2012/11/27 00:44:56 | 000,282,624 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\RTSndMgr.cpl
[2012/11/27 00:44:56 | 000,086,016 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SoundMan.exe
[2012/11/27 00:44:55 | 004,614,656 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys
[2012/11/27 00:44:55 | 002,808,832 | ---- | C] (RealTek Semicoductor Corp.) -- C:\WINDOWS\alcwzrd.exe
[2012/11/27 00:44:55 | 002,165,760 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\MicCal.exe
[2012/11/27 00:44:55 | 000,299,008 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\ALSndMgr.cpl
[2012/11/27 00:44:55 | 000,069,632 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\Alcmtr.exe
[2012/11/27 00:44:54 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012/11/27 00:44:50 | 000,520,192 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlExUpd.dll
[2012/11/27 00:44:50 | 000,315,392 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\HideWin.exe
[2012/11/27 00:44:17 | 000,039,936 | ---- | C] (REDC) -- C:\WINDOWS\System32\drivers\rimmptsk.sys
[2012/11/27 00:44:17 | 000,037,376 | ---- | C] (REDC) -- C:\WINDOWS\System32\drivers\rixdptsk.sys
[2012/11/27 00:44:16 | 000,090,112 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\snymsico.dll
[2012/11/27 00:44:16 | 000,042,496 | ---- | C] (REDC) -- C:\WINDOWS\System32\drivers\rimsptsk.sys
[2012/11/27 00:43:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lenovo
[2012/11/27 00:43:38 | 000,009,344 | ---- | C] (Lenovo Corporation) -- C:\WINDOWS\System32\drivers\AcpiVpc.sys
[2012/11/27 00:43:37 | 000,000,000 | ---D | C] -- C:\Program Files\Lenovo
[2012/11/27 00:43:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\InstallShield
[2012/11/27 00:42:57 | 000,094,592 | ---- | C] (Alps Electric Co., Ltd.) -- C:\WINDOWS\System32\drivers\Apfiltr.sys
[2012/11/27 00:42:57 | 000,087,821 | ---- | C] (Alps Electric Co., Ltd.) -- C:\WINDOWS\System32\Vxdif.dll
[2012/11/27 00:42:57 | 000,000,000 | ---D | C] -- C:\Program Files\Apoint2K
[2012/11/27 00:42:56 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2012/11/27 00:42:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2012/11/27 00:42:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Easy Button
[2012/11/27 00:42:28 | 000,000,000 | ---D | C] -- C:\Program Files\EzButton
[2012/11/27 00:42:24 | 000,000,000 | ---D | C] -- C:\Drivers
[2012/11/27 00:41:48 | 000,172,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxres.dll
[2012/11/27 00:40:16 | 003,293,184 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxress.dll
[2012/11/27 00:40:16 | 002,575,360 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpdx32.dll
[2012/11/27 00:40:16 | 002,400,256 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\ig4icd32.dll
[2012/11/27 00:40:16 | 001,615,808 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpdv32.dll
[2012/11/27 00:40:16 | 001,527,808 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\ig4dev32.dll
[2012/11/27 00:40:16 | 000,520,192 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxcfg.exe
[2012/11/27 00:40:16 | 000,204,800 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxpph.dll
[2012/11/27 00:40:16 | 000,192,512 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrell.lrc
[2012/11/27 00:40:16 | 000,192,512 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrdeu.lrc
[2012/11/27 00:40:16 | 000,188,416 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrnld.lrc
[2012/11/27 00:40:16 | 000,188,416 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrita.lrc
[2012/11/27 00:40:16 | 000,188,416 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxresp.lrc
[2012/11/27 00:40:16 | 000,184,320 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrfra.lrc
[2012/11/27 00:40:16 | 000,180,224 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrrus.lrc
[2012/11/27 00:40:16 | 000,180,224 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrptg.lrc
[2012/11/27 00:40:16 | 000,180,224 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrptb.lrc
[2012/11/27 00:40:16 | 000,180,224 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrplk.lrc
[2012/11/27 00:40:16 | 000,180,224 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrhun.lrc
[2012/11/27 00:40:16 | 000,176,128 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrsky.lrc
[2012/11/27 00:40:16 | 000,176,128 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrfin.lrc
[2012/11/27 00:40:16 | 000,176,128 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrcsy.lrc
[2012/11/27 00:40:16 | 000,172,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrtrk.lrc
[2012/11/27 00:40:16 | 000,172,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrsve.lrc
[2012/11/27 00:40:16 | 000,172,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrslv.lrc
[2012/11/27 00:40:16 | 000,172,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrnor.lrc
[2012/11/27 00:40:16 | 000,172,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrenu.lrc
[2012/11/27 00:40:16 | 000,172,032 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrdan.lrc
[2012/11/27 00:40:16 | 000,163,840 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxzoom.exe
[2012/11/27 00:40:16 | 000,163,840 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrtha.lrc
[2012/11/27 00:40:16 | 000,159,744 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrara.lrc
[2012/11/27 00:40:16 | 000,155,648 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrheb.lrc
[2012/11/27 00:40:16 | 000,150,528 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxpgd32.dll
[2012/11/27 00:40:16 | 000,135,168 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxdo.dll
[2012/11/27 00:40:16 | 000,131,072 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrjpn.lrc
[2012/11/27 00:40:16 | 000,126,976 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrkor.lrc
[2012/11/27 00:40:16 | 000,122,880 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxcpl.cpl
[2012/11/27 00:40:16 | 000,110,592 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrcht.lrc
[2012/11/27 00:40:16 | 000,110,592 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxrchs.lrc
[2012/11/27 00:40:16 | 000,102,400 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\hccutils.dll
[2012/11/27 00:40:16 | 000,057,344 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igxprd32.dll
[2012/11/27 00:40:16 | 000,048,128 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxsrvc.dll
[2012/11/27 00:40:16 | 000,024,576 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\igfxexps.dll
[2012/11/27 00:40:13 | 000,920,088 | ---- | C] (Intel® Corporation) -- C:\WINDOWS\System32\igxpun.exe
[2012/11/27 00:40:13 | 000,319,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\difxapi.dll
[2012/11/27 00:40:13 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2012/11/27 00:36:22 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups
[2012/11/27 00:36:19 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2012/11/27 00:36:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE
[2012/11/27 00:36:06 | 000,000,000 | ---D | C] -- C:\Intel
[2012/11/27 00:31:55 | 000,134,304 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NST\7DD02000.012\ccSetx86.sys
[2012/11/27 00:31:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NST
[2012/11/27 00:31:49 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NST\7DD02000.012
[2012/11/27 00:31:48 | 000,000,000 | ---D | C] -- C:\Program Files\Norton Identity Safe
[2012/11/27 00:31:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Norton Identity Safe
[2012/11/27 00:31:42 | 000,142,496 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/11/27 00:31:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012/11/27 00:31:42 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/11/27 00:31:27 | 000,927,904 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymEFA.sys
[2012/11/27 00:31:27 | 000,586,400 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\srtsp.sys
[2012/11/27 00:31:27 | 000,394,656 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\symtdi.sys
[2012/11/27 00:31:27 | 000,368,288 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymDS.sys
[2012/11/27 00:31:27 | 000,350,368 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\symtdiv.sys
[2012/11/27 00:31:27 | 000,338,592 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\symnets.sys
[2012/11/27 00:31:27 | 000,032,888 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\srtspx.sys
[2012/11/27 00:31:27 | 000,021,400 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymELAM.sys
[2012/11/27 00:31:26 | 000,175,264 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\Ironx86.sys
[2012/11/27 00:31:26 | 000,134,304 | R--- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\NAV\1402000.013\ccSetx86.sys
[2012/11/27 00:30:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NAV
[2012/11/27 00:30:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\NAV\1402000.013
[2012/11/27 00:30:43 | 000,000,000 | ---D | C] -- C:\Program Files\Norton AntiVirus
[2012/11/27 00:30:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Norton AntiVirus
[2012/11/27 00:30:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Norton
[2012/11/27 00:30:24 | 000,000,000 | ---D | C] -- C:\Program Files\NortonInstaller
[2012/11/27 00:30:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2012/11/26 22:43:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\Macromedia
[2012/11/26 22:41:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Tata Photon+
[2012/11/26 22:40:44 | 000,014,640 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsgXP_2k3.dll
[2012/11/26 22:40:43 | 000,026,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe
[2012/11/26 22:40:38 | 001,112,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfcoinstaller01007.dll
[2012/11/26 22:40:38 | 001,112,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WdfCoInstaller01007.dll
[2012/11/26 22:40:38 | 000,861,696 | ---- | C] (DiBcom SA) -- C:\WINDOWS\System32\drivers\mod7700.sys
[2012/11/26 22:40:38 | 000,235,392 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbnet.sys
[2012/11/26 22:40:38 | 000,193,792 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys
[2012/11/26 22:40:38 | 000,102,784 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_hwusbdev.sys
[2012/11/26 22:40:38 | 000,090,112 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_jucdcacm.sys
[2012/11/26 22:40:38 | 000,073,216 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_jubusenum.sys
[2012/11/26 22:40:38 | 000,064,384 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_jucdcecm.sys
[2012/11/26 22:40:38 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbccid.sys
[2012/11/26 22:40:38 | 000,026,624 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_juextctrl.sys
[2012/11/26 22:40:38 | 000,025,856 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys
[2012/11/26 22:40:38 | 000,019,200 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_hwupgrade.sys
[2012/11/26 22:40:38 | 000,011,136 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys
[2012/11/26 22:40:29 | 000,000,000 | ---D | C] -- C:\Program Files\Tata Photon+
[2012/11/26 22:40:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DatacardService
[2012/11/26 22:39:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Application Data\Identities
[2012/11/26 22:39:23 | 000,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2012/11/26 22:39:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\My Documents\My Pictures
[2012/11/26 22:39:19 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\My Documents\My Music
[2012/11/26 22:38:58 | 000,000,000 | -HSD | C] -- C:\FOUND.000
[2012/11/26 22:35:51 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly
[2012/11/26 22:35:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET
[2012/11/26 22:34:55 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Samhita\Application Data\Microsoft
[2012/11/26 22:34:55 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Samhita\SendTo
[2012/11/26 22:34:55 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Samhita\Recent
[2012/11/26 22:34:55 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Samhita\Application Data
[2012/11/26 22:34:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\Start Menu\Programs\Startup
[2012/11/26 22:34:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\Start Menu
[2012/11/26 22:34:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\My Documents
[2012/11/26 22:34:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\Favorites
[2012/11/26 22:34:55 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Samhita\Start Menu\Programs\Accessories
[2012/11/26 22:34:55 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Samhita\Cookies
[2012/11/26 22:34:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Samhita\Templates
[2012/11/26 22:34:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Samhita\PrintHood
[2012/11/26 22:34:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Samhita\NetHood
[2012/11/26 22:34:55 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\Samhita\Local Settings
[2012/11/26 22:34:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Local Settings\Application Data\Microsoft
[2012/11/26 22:34:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Samhita\Desktop
[2012/11/26 22:34:22 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/11/26 22:34:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2012/11/26 22:34:20 | 000,000,000 | --SD | C] -- C:\WINDOWS\System32\Microsoft
[2012/11/26 22:34:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2012/11/26 22:34:19 | 000,000,000 | --SD | C] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2012/11/26 22:34:02 | 000,000,000 | --SD | C] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2012/11/26 22:34:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2012/11/26 22:32:44 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mapi32.dll
[2012/11/26 22:31:49 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\DRM
[2012/11/26 22:31:38 | 000,000,000 | --SD | C] -- C:\WINDOWS\Downloaded Program Files
[2012/11/26 22:31:38 | 000,000,000 | R--D | C] -- C:\WINDOWS\Offline Web Pages
[2012/11/26 22:31:26 | 000,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2012/11/26 22:31:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DirectX
[2012/11/26 22:30:46 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\atrace.dll
[2012/11/26 22:30:37 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmevtmsg.dll
[2012/11/26 22:30:35 | 000,064,512 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\acctres.dll
[2012/11/26 22:30:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Services
[2012/11/26 22:30:32 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icfgnt5.dll
[2012/11/26 22:30:32 | 000,000,000 | --SD | C] -- C:\WINDOWS\Tasks
[2012/11/26 22:30:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2012/11/26 22:30:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\srchasst
[2012/11/26 22:30:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Macromed
[2012/11/26 22:30:24 | 000,194,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng1.dll
[2012/11/26 22:30:24 | 000,172,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuauclt1.exe
[2012/11/26 22:30:24 | 000,127,256 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll
[2012/11/26 22:30:24 | 000,041,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wups.dll
[2012/11/26 22:30:23 | 000,465,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll
[2012/11/26 22:30:23 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qmgrprxy.dll
[2012/11/26 22:30:23 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx2.dll
[2012/11/26 22:30:23 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bitsprx3.dll
[2012/11/26 22:30:20 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2012/11/26 22:30:15 | 000,045,568 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrslv.dll
[2012/11/26 22:30:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrcdlg.dll
[2012/11/26 22:30:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\racpldlg.dll
[2012/11/26 22:30:15 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\safrdm.dll
[2012/11/26 22:30:12 | 000,022,528 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\fltMc.exe
[2012/11/26 22:30:11 | 000,239,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\srrstr.dll
[2012/11/26 22:30:11 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ils.dll
[2012/11/26 22:30:11 | 000,032,768 | ---- | C] (Intel Corporation) -- C:\WINDOWS\System32\isrdbg32.dll
[2012/11/26 22:30:11 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Restore
[2012/11/26 22:30:10 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msconf.dll
[2012/11/26 22:30:10 | 000,034,560 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mnmdd.dll
[2012/11/26 22:30:10 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\nmmkcert.dll
[2012/11/26 22:30:08 | 000,000,000 | ---D | C] -- C:\Program Files\NetMeeting
[2012/11/26 22:30:07 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoeacct.dll
[2012/11/26 22:30:07 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msoert2.dll
[2012/11/26 22:30:06 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetres.dll
[2012/11/26 22:30:05 | 000,000,000 | ---D | C] -- C:\Program Files\Outlook Express
[2012/11/26 22:30:04 | 000,274,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\inetcfg.dll
[2012/11/26 22:30:04 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\isign32.dll
[2012/11/26 22:30:04 | 000,073,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwdial.dll
[2012/11/26 22:30:04 | 000,065,536 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\icwphbk.dll
[2012/11/26 22:30:04 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mstinit.exe
[2012/11/26 22:29:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\System
[2012/11/26 22:29:53 | 000,000,000 | ---D | C] -- C:\Program Files\Internet Explorer
[2012/11/26 22:29:50 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Pictures
[2012/11/26 22:29:26 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Games
[2012/11/26 22:29:13 | 000,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2012/11/26 22:29:07 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools
[2012/11/26 22:29:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\Registration
[2012/11/26 22:29:01 | 000,000,000 | ---D | C] -- C:\Program Files\Online Services
[2012/11/26 22:28:52 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Player
[2012/11/26 22:28:51 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Media Connect 2
[2012/11/26 22:28:49 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger
[2012/11/26 22:28:46 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\write.exe
[2012/11/26 22:28:46 | 000,000,000 | ---D | C] -- C:\Program Files\MSN Gaming Zone
[2012/11/26 22:28:37 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avtapi.dll
[2012/11/26 22:28:37 | 000,138,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndvol32.exe
[2012/11/26 22:28:37 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avwav.dll
[2012/11/26 22:28:37 | 000,044,544 | ---- | C] (Hilgraeve, Inc.) -- C:\WINDOWS\System32\hticons.dll
[2012/11/26 22:28:37 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\avmeter.dll
[2012/11/26 22:28:36 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winchat.exe
[2012/11/26 22:28:30 | 000,605,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\getuname.dll
[2012/11/26 22:28:29 | 000,119,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\winmine.exe
[2012/11/26 22:28:29 | 000,114,688 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\calc.exe
[2012/11/26 22:28:29 | 000,080,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\charmap.exe
[2012/11/26 22:28:29 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sol.exe
[2012/11/26 22:28:28 | 000,126,976 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mshearts.exe
[2012/11/26 22:28:28 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\freecell.exe
[2012/11/26 22:28:28 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsshutdn.exe
[2012/11/26 22:28:28 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tskill.exe
[2012/11/26 22:28:28 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rwinsta.exe
[2012/11/26 22:28:28 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tsdiscon.exe
[2012/11/26 22:28:28 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscon.exe
[2012/11/26 22:28:28 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\shadow.exe
[2012/11/26 22:28:28 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reset.exe
[2012/11/26 22:28:27 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\regini.exe
[2012/11/26 22:28:27 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qwinsta.exe
[2012/11/26 22:28:27 | 000,020,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msg.exe
[2012/11/26 22:28:27 | 000,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qappsrv.exe
[2012/11/26 22:28:27 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cdmodem.dll
[2012/11/26 22:28:27 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\logoff.exe
[2012/11/26 22:28:27 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpcfgex.dll
[2012/11/26 22:28:26 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comrepl.dll
[2012/11/26 22:28:26 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comaddin.dll
[2012/11/26 22:28:26 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxlegih.dll
[2012/11/26 22:28:26 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxdm.dll
[2012/11/26 22:28:26 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dcomcnfg.exe
[2012/11/26 22:28:26 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mtxex.dll
[2012/11/26 22:28:25 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comsnap.dll
[2012/11/26 22:28:25 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\stclient.dll
[2012/11/26 22:28:12 | 000,000,000 | ---D | C] -- C:\Program Files\MSN
[2012/11/26 22:28:11 | 000,183,808 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\accwiz.exe
[2012/11/26 22:28:11 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\sndrec32.exe
[2012/11/26 22:28:11 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mplay32.exe
[2012/11/26 22:28:11 | 000,068,608 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\access.cpl
[2012/11/26 22:28:10 | 000,347,136 | ---- | C] (Hilgraeve, Inc.) -- C:\WINDOWS\System32\hypertrm.dll
[2012/11/26 22:28:10 | 000,343,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mspaint.exe
[2012/11/26 22:28:10 | 000,102,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clipbrd.exe
[2012/11/26 22:28:10 | 000,000,000 | ---D | C] -- C:\Program Files\Windows NT
[2012/11/26 22:28:09 | 000,538,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spider.exe
[2012/11/26 22:28:09 | 000,093,696 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscfgwmi.dll
[2012/11/26 22:28:08 | 000,147,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdchost.dll
[2012/11/26 22:28:08 | 000,087,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpwsx.dll
[2012/11/26 22:28:08 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdshost.exe
[2012/11/26 22:28:08 | 000,062,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpclip.exe
[2012/11/26 22:28:08 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\tscupgrd.exe
[2012/11/26 22:28:08 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\qprocess.exe
[2012/11/26 22:28:08 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdpsnd.dll
[2012/11/26 22:28:08 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\rdsaddin.exe
[2012/11/26 22:28:07 | 000,955,904 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtctm.dll
[2012/11/26 22:28:07 | 000,425,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcprx.dll
[2012/11/26 22:28:07 | 000,161,280 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtcuiu.dll
[2012/11/26 22:28:07 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cfgbkend.dll
[2012/11/26 22:28:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MsDtc
[2012/11/26 22:28:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\catsrvps.dll
[2012/11/26 22:28:06 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msdtclog.dll
[2012/11/26 22:28:06 | 000,011,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xolehlp.dll
[2012/11/26 22:28:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Com
[2012/11/26 22:28:05 | 000,539,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\comuid.dll
[2012/11/26 22:28:05 | 000,110,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\clbcatex.dll
[2012/11/26 22:27:59 | 000,185,344 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\cmprops.dll
[2012/11/26 22:27:59 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\licwmi.dll
[2012/11/26 22:27:59 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\servdeps.dll
[2012/11/26 22:27:59 | 000,017,408 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mmfutil.dll
[2012/11/26 22:27:52 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Videos
[2012/11/26 22:27:32 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Accessories
[2012/11/26 22:24:35 | 000,014,080 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\battc.sys
[2012/11/26 22:24:15 | 000,006,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\enum1394.sys
[2012/11/26 22:23:54 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbui.dll
[2012/11/26 22:21:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music
[2012/11/26 22:21:05 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer
[2012/11/26 22:21:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC
[2012/11/26 22:21:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines
[2012/11/26 22:21:01 | 000,000,000 | R--D | C] -- C:\Program Files
[2012/11/26 22:21:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared
[2012/11/26 22:21:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files
[2012/11/26 22:20:58 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuq.dll
[2012/11/26 22:20:58 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuf.dll
[2012/11/26 22:20:58 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdazel.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycc.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbduzb.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdur.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtat.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru1.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmon.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkyr.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkaz.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbu.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdblr.dll
[2012/11/26 22:20:56 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdaze.dll
[2012/11/26 22:20:54 | 000,008,192 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhept.dll
[2012/11/26 22:20:54 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela3.dll
[2012/11/26 22:20:54 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela2.dll
[2012/11/26 22:20:54 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe319.dll
[2012/11/26 22:20:53 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdgkl.dll
[2012/11/26 22:20:53 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe220.dll
[2012/11/26 22:20:53 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe.dll
[2012/11/26 22:20:52 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv1.dll
[2012/11/26 22:20:52 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv.dll
[2012/11/26 22:20:52 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdest.dll
[2012/11/26 22:20:52 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt1.dll
[2012/11/26 22:20:52 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt.dll
[2012/11/26 22:20:50 | 000,007,168 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycl.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl1.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz2.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz1.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcr.dll
[2012/11/26 22:20:50 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\KBDAL.DLL
[2012/11/26 22:20:50 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdro.dll
[2012/11/26 22:20:50 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl1.dll
[2012/11/26 22:20:50 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu1.dll
[2012/11/26 22:20:46 | 000,176,157 | ---- | C] (Digi International, Inc.) -- C:\WINDOWS\System32\dgrpsetu.dll
[2012/11/26 22:20:46 | 000,103,424 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\EqnClass.Dll
[2012/11/26 22:20:46 | 000,085,020 | ---- | C] (Digi International) -- C:\WINDOWS\System32\dgsetup.dll
[2012/11/26 22:20:46 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\spxcoins.dll
[2012/11/26 22:20:46 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll
[2012/11/26 22:20:45 | 000,126,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MSVIDEO.DLL
[2012/11/26 22:20:45 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLECLI.DLL
[2012/11/26 22:20:45 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLESVR.DLL
[2012/11/26 22:20:45 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TAPI.DLL
[2012/11/26 22:20:45 | 000,013,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WFWNET.DRV
[2012/11/26 22:20:45 | 000,009,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VER.DLL
[2012/11/26 22:20:45 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SHELL.DLL
[2012/11/26 22:20:45 | 000,004,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TIMER.DRV
[2012/11/26 22:20:45 | 000,003,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SYSTEM.DRV
[2012/11/26 22:20:45 | 000,002,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VGA.DRV
[2012/11/26 22:20:45 | 000,001,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SOUND.DRV
[2012/11/26 22:20:44 | 000,109,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVIFILE.DLL
[2012/11/26 22:20:44 | 000,073,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIAVI.DRV
[2012/11/26 22:20:44 | 000,069,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVICAP.DLL
[2012/11/26 22:20:44 | 000,032,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMMDLG.DLL
[2012/11/26 22:20:44 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIWAVE.DRV
[2012/11/26 22:20:44 | 000,025,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCISEQ.DRV
[2012/11/26 22:20:44 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE
[2012/11/26 22:20:44 | 000,009,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\LZEXPAND.DLL
[2012/11/26 22:20:44 | 000,002,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MOUSE.DRV
[2012/11/26 22:20:44 | 000,002,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\KEYBOARD.DRV
[2012/11/26 22:20:44 | 000,001,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMTASK.TSK
[2012/11/26 22:20:43 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WINSPOOL.DRV
[2012/11/26 22:20:43 | 000,068,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMSYSTEM.DLL
[2012/11/26 22:20:43 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll
[2012/11/26 22:20:42 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll
[2012/11/26 22:20:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2012/11/26 22:20:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu
[2012/11/26 22:20:34 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents
[2012/11/26 22:20:34 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates
[2012/11/26 22:20:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites
[2012/11/26 22:20:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop
[2012/11/26 22:19:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2012/11/26 22:19:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot
[2012/11/26 22:19:30 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft
[2012/11/26 22:19:30 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data
[2012/11/26 22:17:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings
[2012/11/26 22:13:48 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts
[2012/11/26 22:13:48 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2012/11/26 22:13:48 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web
[2012/11/26 22:13:48 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\system
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\security
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\java
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028
[2012/11/26 22:13:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025
[5 C:\*.tmp files -> C:\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/12/19 08:36:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/12/19 08:22:32 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/12/18 00:21:24 | 000,042,141 | ---- | M] () -- C:\Documents and Settings\Samhita\My Documents\22244928_1355770146975.pdf
[2012/12/15 15:08:24 | 000,001,423 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Notepad.lnk
[2012/12/13 22:04:10 | 000,099,907 | ---- | M] () -- C:\Documents and Settings\Samhita\My Documents\IRCTC Ltd,Booked Ticket Printing-SDAH_NJP.pdf
[2012/12/13 21:55:00 | 000,100,375 | ---- | M] () -- C:\Documents and Settings\Samhita\My Documents\IRCTC Ltd,Booked Ticket Printing-FLK_SDAH.pdf
[2012/12/13 09:58:04 | 000,000,733 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to calc.exe.lnk
[2012/12/09 08:51:34 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/12/08 10:22:50 | 000,012,800 | ---- | M] () -- C:\Documents and Settings\Samhita\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/04 21:17:40 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2012/12/01 17:00:06 | 000,192,976 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/12/01 16:57:50 | 000,000,918 | ---- | M] () -- C:\Documents and Settings\Samhita\Desktop\Auslogics Duplicate File Finder.lnk
[2012/12/01 15:42:22 | 000,000,773 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avro Spell Checker.lnk
[2012/12/01 15:42:22 | 000,000,754 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Avro Keyboard.lnk
[2012/12/01 15:42:22 | 000,000,736 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avro Keyboard.lnk
[2012/12/01 09:20:36 | 000,507,720 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\Cat.DB
[2012/11/30 00:10:48 | 000,000,623 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/11/30 00:09:16 | 022,912,657 | ---- | M] () -- C:\Documents and Settings\Samhita\Desktop\vlc-2-0-4-win32.exe
[2012/11/29 23:19:28 | 000,000,552 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/11/29 23:19:28 | 000,000,534 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2012/11/28 10:24:34 | 000,000,720 | ---- | M] () -- C:\Documents and Settings\Samhita\Desktop\Core Temp.lnk
[2012/11/28 10:21:00 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2012/11/28 08:16:58 | 000,000,646 | ---- | M] () -- C:\Documents and Settings\Samhita\Desktop\Free Download Manager.lnk
[2012/11/27 10:13:40 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\WindowsAccessBridge.dll
[2012/11/27 10:13:38 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\npDeployJava1.dll
[2012/11/27 10:13:38 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2012/11/27 10:13:38 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2012/11/27 10:13:38 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2012/11/27 10:13:38 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2012/11/27 10:13:38 | 000,143,872 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2012/11/27 10:00:34 | 000,895,464 | ---- | M] (Oracle Corporation) -- C:\Documents and Settings\Samhita\Desktop\JavaSetup7u9.exe
[2012/11/27 09:46:04 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerApp.exe
[2012/11/27 09:46:04 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012/11/27 04:23:46 | 000,001,638 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2012/11/27 03:05:06 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/11/27 02:49:46 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/11/27 02:37:40 | 000,001,806 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TP-LINK Wireless Configuration Utility.lnk
[2012/11/27 02:24:00 | 000,000,618 | ---- | M] () -- C:\Documents and Settings\Samhita\Desktop\IPConnect.lnk
[2012/11/27 02:14:06 | 000,013,946 | ---- | M] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\VT20121114.016
[2012/11/27 01:24:22 | 000,000,646 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/11/27 01:24:20 | 000,000,628 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/11/27 01:05:46 | 000,000,376 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2012/11/27 01:00:30 | 000,476,034 | ---- | M] () -- C:\Documents and Settings\Samhita\Desktop\IPConnectInstaller.exe
[2012/11/27 00:51:08 | 000,684,032 | ---- | M] (Intel Corporation) -- C:\WINDOWS\System32\NETw4c32.dll
[2012/11/27 00:47:56 | 000,000,633 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
[2012/11/27 00:46:52 | 000,940,794 | ---- | M] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2012/11/27 00:46:52 | 000,146,650 | ---- | M] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2012/11/27 00:44:52 | 000,315,392 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\HideWin.exe
[2012/11/27 00:42:32 | 000,000,077 | ---- | M] () -- C:\WINDOWS\EzButton.UNI
[2012/11/27 00:31:44 | 000,142,496 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2012/11/27 00:31:44 | 000,007,446 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/11/27 00:31:44 | 000,000,806 | ---- | M] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/11/27 00:31:38 | 000,001,789 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.LNK
[2012/11/26 22:41:18 | 000,000,745 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Tata Photon+.lnk
[2012/11/26 22:41:18 | 000,000,727 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Tata Photon+.lnk
[2012/11/26 22:40:56 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
[2012/11/26 22:40:54 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/11/26 22:40:34 | 001,112,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wdfcoinstaller01007.dll
[2012/11/26 22:40:34 | 001,112,288 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\WdfCoInstaller01007.dll
[2012/11/26 22:40:34 | 000,861,696 | ---- | M] (DiBcom SA) -- C:\WINDOWS\System32\drivers\mod7700.sys
[2012/11/26 22:40:34 | 000,235,392 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbnet.sys
[2012/11/26 22:40:34 | 000,193,792 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewusbmdm.sys
[2012/11/26 22:40:34 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_hwusbdev.sys
[2012/11/26 22:40:34 | 000,090,112 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_jucdcacm.sys
[2012/11/26 22:40:34 | 000,073,216 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_jubusenum.sys
[2012/11/26 22:40:34 | 000,064,384 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_jucdcecm.sys
[2012/11/26 22:40:34 | 000,028,672 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbccid.sys
[2012/11/26 22:40:34 | 000,026,624 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_juextctrl.sys
[2012/11/26 22:40:34 | 000,025,856 | ---- | M] (Huawei Tech. Co., Ltd.) -- C:\WINDOWS\System32\drivers\ewdcsc.sys
[2012/11/26 22:40:34 | 000,019,200 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_hwupgrade.sys
[2012/11/26 22:40:34 | 000,011,136 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\WINDOWS\System32\drivers\ew_usbenumfilter.sys
[2012/11/26 22:39:50 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/11/26 22:34:06 | 000,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD
[2012/11/26 22:33:28 | 000,000,658 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2012/11/26 22:33:00 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/26 22:33:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2012/11/26 22:33:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012/11/26 22:33:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2012/11/26 22:33:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2012/11/26 22:32:52 | 000,316,640 | ---- | M] () -- C:\WINDOWS\WMSysPr9.prx
[2012/11/26 22:32:52 | 000,023,392 | ---- | M] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/11/26 22:32:52 | 000,016,832 | ---- | M] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/11/26 22:32:46 | 000,004,161 | ---- | M] () -- C:\WINDOWS\ODBCINST.INI
[2012/11/26 22:29:26 | 000,021,640 | ---- | M] () -- C:\WINDOWS\System32\emptyregdb.dat
[5 C:\*.tmp files -> C:\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/12/18 00:21:22 | 000,042,141 | ---- | C] () -- C:\Documents and Settings\Samhita\My Documents\22244928_1355770146975.pdf
[2012/12/15 15:08:22 | 000,001,423 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Notepad.lnk
[2012/12/13 22:04:06 | 000,099,907 | ---- | C] () -- C:\Documents and Settings\Samhita\My Documents\IRCTC Ltd,Booked Ticket Printing-SDAH_NJP.pdf
[2012/12/13 21:54:55 | 000,100,375 | ---- | C] () -- C:\Documents and Settings\Samhita\My Documents\IRCTC Ltd,Booked Ticket Printing-FLK_SDAH.pdf
[2012/12/13 21:53:55 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2012/12/13 09:58:03 | 000,000,733 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to calc.exe.lnk
[2012/12/01 16:57:47 | 000,000,918 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Auslogics Duplicate File Finder.lnk
[2012/12/01 15:43:03 | 000,252,820 | ---- | C] () -- C:\vrinda.ttf
[2012/12/01 15:42:20 | 000,000,773 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avro Spell Checker.lnk
[2012/12/01 15:42:20 | 000,000,754 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Avro Keyboard.lnk
[2012/12/01 15:42:20 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avro Keyboard.lnk
[2012/12/01 15:42:18 | 000,000,756 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Avro Keyboard.lnk
[2012/11/30 00:10:46 | 000,000,623 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2012/11/29 23:59:57 | 022,912,657 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\vlc-2-0-4-win32.exe
[2012/11/29 23:19:26 | 000,000,552 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/11/29 23:19:26 | 000,000,534 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2012/11/28 10:24:32 | 000,000,720 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Core Temp.lnk
[2012/11/28 10:20:57 | 000,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2012/11/28 08:16:56 | 000,000,646 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Free Download Manager.lnk
[2012/11/27 04:23:45 | 000,001,638 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Adobe Reader XI.lnk
[2012/11/27 04:23:44 | 000,001,804 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2012/11/27 02:37:39 | 000,035,967 | ---- | C] () -- C:\WINDOWS\System32\jswscimdp.cat
[2012/11/27 02:37:39 | 000,035,538 | ---- | C] () -- C:\WINDOWS\System32\jswscimd.cat
[2012/11/27 02:37:39 | 000,005,529 | ---- | C] () -- C:\WINDOWS\System32\jswscimdp.inf
[2012/11/27 02:37:39 | 000,002,231 | ---- | C] () -- C:\WINDOWS\System32\jswscimd.inf
[2012/11/27 02:37:38 | 000,001,806 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TP-LINK Wireless Configuration Utility.lnk
[2012/11/27 02:37:31 | 000,262,216 | ---- | C] () -- C:\WINDOWS\System32\IPTests.dll
[2012/11/27 02:37:08 | 000,042,067 | ---- | C] () -- C:\WINDOWS\System32\wsimdp.cat
[2012/11/27 02:37:08 | 000,042,052 | ---- | C] () -- C:\WINDOWS\System32\wsimd.cat
[2012/11/27 02:37:08 | 000,005,363 | ---- | C] () -- C:\WINDOWS\System32\wsimdp.inf
[2012/11/27 02:37:08 | 000,002,179 | ---- | C] () -- C:\WINDOWS\System32\wsimd.inf
[2012/11/27 02:37:06 | 000,422,000 | ---- | C] () -- C:\WINDOWS\System32\wgapi.dll
[2012/11/27 02:36:37 | 000,045,171 | ---- | C] () -- C:\WINDOWS\System32\netathuw.inf
[2012/11/27 02:36:37 | 000,008,818 | ---- | C] () -- C:\WINDOWS\System32\netathuw.cat
[2012/11/27 02:23:59 | 000,000,618 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\IPConnect.lnk
[2012/11/27 02:14:55 | 000,013,946 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\VT20121114.016
[2012/11/27 01:24:19 | 000,000,646 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/11/27 01:24:19 | 000,000,634 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/11/27 01:24:19 | 000,000,628 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/11/27 01:09:22 | 000,284,997 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\TCS India Policy - Health Insurance.pdf
[2012/11/27 01:09:22 | 000,080,580 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\TCS India FAQs- Health Insurance Scheme.pdf
[2012/11/27 01:09:21 | 002,096,325 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\instructions_for_new_joinees.pdf
[2012/11/27 01:09:21 | 000,654,632 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Investment.zip
[2012/11/27 01:09:21 | 000,313,765 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Lic 1.pdf
[2012/11/27 01:09:21 | 000,312,372 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Lic 2.pdf
[2012/11/27 01:09:21 | 000,143,489 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Lici 01.jpg
[2012/11/27 01:09:21 | 000,142,727 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Lici 02.jpg
[2012/11/27 01:09:20 | 000,014,829 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\hdfc life.pdf
[2012/11/27 01:09:19 | 000,713,627 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\a04ec1a0-c39b-2c10-6889-f6f69625f3f3.pdf
[2012/11/27 01:09:19 | 000,114,399 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\711357.pdf
[2012/11/27 01:09:19 | 000,038,621 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Credit Card Bill Payments.pdf
[2012/11/27 01:09:19 | 000,029,549 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\Appointment Letter.pdf
[2012/11/27 01:09:19 | 000,019,491 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\CP_AnnualPremium_59327339_FY.pdf
[2012/11/27 01:09:18 | 000,169,307 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\541290_3301602317404_822967889_n.jpg
[2012/11/27 01:05:44 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2012/11/27 01:00:28 | 000,476,034 | ---- | C] () -- C:\Documents and Settings\Samhita\Desktop\IPConnectInstaller.exe
[2012/11/27 00:48:36 | 000,000,324 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\My Bluetooth Places.lnk
[2012/11/27 00:47:54 | 000,000,633 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
[2012/11/27 00:46:51 | 000,940,794 | ---- | C] () -- C:\WINDOWS\System32\LoopyMusic.wav
[2012/11/27 00:46:51 | 000,146,650 | ---- | C] () -- C:\WINDOWS\System32\BuzzingBee.wav
[2012/11/27 00:45:30 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\ChCfg.exe
[2012/11/27 00:44:17 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2012/11/27 00:42:31 | 000,000,077 | ---- | C] () -- C:\WINDOWS\EzButton.UNI
[2012/11/27 00:40:16 | 001,174,000 | ---- | C] () -- C:\WINDOWS\System32\igmedkrn.dll
[2012/11/27 00:40:16 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4864.dll
[2012/11/27 00:40:16 | 000,104,636 | ---- | C] () -- C:\WINDOWS\System32\igmedcompkrn.dll
[2012/11/27 00:40:16 | 000,026,160 | ---- | C] () -- C:\WINDOWS\System32\igxpxs32.vp
[2012/11/27 00:40:16 | 000,002,096 | ---- | C] () -- C:\WINDOWS\System32\igxpxk32.vp
[2012/11/27 00:38:29 | 000,012,800 | ---- | C] () -- C:\Documents and Settings\Samhita\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/27 00:33:01 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/11/27 00:32:12 | 000,507,720 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\Cat.DB
[2012/11/27 00:31:49 | 000,007,611 | R--- | C] () -- C:\WINDOWS\System32\drivers\NST\7DD02000.012\ccSetx86.cat
[2012/11/27 00:31:49 | 000,000,827 | R--- | C] () -- C:\WINDOWS\System32\drivers\NST\7DD02000.012\ccSetx86.inf
[2012/11/27 00:31:49 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NST\7DD02000.012\isolate.ini
[2012/11/27 00:31:42 | 000,007,446 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.CAT
[2012/11/27 00:31:42 | 000,000,806 | ---- | C] () -- C:\WINDOWS\System32\drivers\SYMEVENT.INF
[2012/11/27 00:31:36 | 000,001,789 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton AntiVirus.LNK
[2012/11/27 00:31:09 | 000,003,433 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymEFA.inf
[2012/11/27 00:31:09 | 000,002,851 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymDS.inf
[2012/11/27 00:31:09 | 000,001,468 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymNetV.inf
[2012/11/27 00:31:09 | 000,001,440 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymNet.inf
[2012/11/27 00:31:09 | 000,001,388 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\srtsp.inf
[2012/11/27 00:31:09 | 000,001,387 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\srtspx.inf
[2012/11/27 00:31:09 | 000,000,996 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\symELAM.inf
[2012/11/27 00:31:09 | 000,000,827 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\ccSetx86.inf
[2012/11/27 00:31:09 | 000,000,737 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\Iron.inf
[2012/11/27 00:30:48 | 000,009,670 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymELAM.cat
[2012/11/27 00:30:48 | 000,009,103 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymVTcer.dat
[2012/11/27 00:30:48 | 000,007,877 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\symnetv.cat
[2012/11/27 00:30:48 | 000,007,601 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymNet.cat
[2012/11/27 00:30:47 | 000,007,611 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\ccSetx86.cat
[2012/11/27 00:30:47 | 000,007,599 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymEFA.cat
[2012/11/27 00:30:47 | 000,007,597 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\srtspx.cat
[2012/11/27 00:30:47 | 000,007,593 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\SymDS.cat
[2012/11/27 00:30:47 | 000,007,593 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\srtsp.cat
[2012/11/27 00:30:47 | 000,007,593 | R--- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\iron.cat
[2012/11/27 00:30:47 | 000,000,172 | ---- | C] () -- C:\WINDOWS\System32\drivers\NAV\1402000.013\isolate.ini
[2012/11/26 22:41:17 | 000,000,745 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Tata Photon+.lnk
[2012/11/26 22:41:17 | 000,000,727 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Tata Photon+.lnk
[2012/11/26 22:40:54 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_ew_jubusenum_01007.Wdf
[2012/11/26 22:40:53 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
[2012/11/26 22:39:48 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
[2012/11/26 22:39:25 | 000,000,642 | ---- | C] () -- C:\Documents and Settings\Samhita\Start Menu\Programs\Outlook Express.lnk
[2012/11/26 22:39:23 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\Samhita\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/11/26 22:39:23 | 000,000,707 | ---- | C] () -- C:\Documents and Settings\Samhita\Start Menu\Programs\Internet Explorer.lnk
[2012/11/26 22:34:55 | 000,001,503 | ---- | C] () -- C:\Documents and Settings\Samhita\Start Menu\Programs\Remote Assistance.lnk
[2012/11/26 22:34:55 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\Samhita\Start Menu\Programs\Windows Media Player.lnk
[2012/11/26 22:34:05 | 000,008,192 | ---- | C] () -- C:\WINDOWS\REGLOCS.OLD
[2012/11/26 22:33:23 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/11/26 22:32:59 | 000,002,577 | ---- | C] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/11/26 22:32:59 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2012/11/26 22:32:59 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2012/11/26 22:32:59 | 000,000,000 | ---- | C] () -- C:\CONFIG.SYS
[2012/11/26 22:32:59 | 000,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2012/11/26 22:32:50 | 000,023,392 | ---- | C] () -- C:\WINDOWS\System32\nscompat.tlb
[2012/11/26 22:32:50 | 000,016,832 | ---- | C] () -- C:\WINDOWS\System32\amcompat.tlb
[2012/11/26 22:32:49 | 000,316,640 | ---- | C] () -- C:\WINDOWS\WMSysPr9.prx
[2012/11/26 22:31:25 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Movie Maker.lnk
[2012/11/26 22:30:44 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt256.bmp
[2012/11/26 22:30:44 | 000,048,680 | -HS- | C] () -- C:\WINDOWS\winnt.bmp
[2012/11/26 22:29:26 | 000,000,609 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows Messenger.lnk
[2012/11/26 22:29:24 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/11/26 22:29:01 | 000,001,890 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\MSN.lnk
[2012/11/26 22:28:31 | 000,065,954 | ---- | C] () -- C:\WINDOWS\Prairie Wind.bmp
[2012/11/26 22:28:31 | 000,065,832 | ---- | C] () -- C:\WINDOWS\Santa Fe Stucco.bmp
[2012/11/26 22:28:31 | 000,026,680 | ---- | C] () -- C:\WINDOWS\River Sumida.bmp
[2012/11/26 22:28:31 | 000,026,582 | ---- | C] () -- C:\WINDOWS\Greenstone.bmp
[2012/11/26 22:28:31 | 000,017,362 | ---- | C] () -- C:\WINDOWS\Rhododendron.bmp
[2012/11/26 22:28:31 | 000,017,336 | ---- | C] () -- C:\WINDOWS\Gone Fishing.bmp
[2012/11/26 22:28:31 | 000,017,062 | ---- | C] () -- C:\WINDOWS\Coffee Bean.bmp
[2012/11/26 22:28:31 | 000,016,730 | ---- | C] () -- C:\WINDOWS\FeatherTexture.bmp
[2012/11/26 22:28:31 | 000,009,522 | ---- | C] () -- C:\WINDOWS\Zapotec.bmp
[2012/11/26 22:28:30 | 000,065,978 | ---- | C] () -- C:\WINDOWS\Soap Bubbles.bmp
[2012/11/26 22:28:30 | 000,001,272 | ---- | C] () -- C:\WINDOWS\Blue Lace 16.bmp
[2012/11/26 22:28:28 | 000,003,286 | ---- | C] () -- C:\WINDOWS\System32\tslabels.h
[2012/11/26 22:28:28 | 000,001,161 | ---- | C] () -- C:\WINDOWS\System32\usrlogon.cmd
[2012/11/26 22:28:27 | 000,000,768 | ---- | C] () -- C:\WINDOWS\System32\msdtcprf.h
[2012/11/26 22:28:20 | 000,063,488 | ---- | C] () -- C:\WINDOWS\System32\wmimgmt.msc
[2012/11/26 22:21:09 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/11/26 22:21:04 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/11/26 22:20:43 | 000,001,688 | ---- | C] () -- C:\WINDOWS\System32\AUTOEXEC.NT
[2012/11/26 22:19:49 | 000,141,702 | ---- | C] () -- C:\WINDOWS\System32\dllcache\netfx.cat
[2012/11/26 22:19:49 | 000,031,965 | ---- | C] () -- C:\WINDOWS\System32\dllcache\mediactr.cat
[2012/11/26 22:19:49 | 000,024,209 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn7.cat
[2012/11/26 22:19:49 | 000,011,651 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msn9.cat
[2012/11/26 22:19:48 | 000,797,189 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012/11/26 22:19:48 | 000,399,645 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012/11/26 22:19:48 | 000,110,116 | ---- | C] () -- C:\WINDOWS\System32\dllcache\tabletpc.cat
[2012/11/26 22:19:48 | 000,037,484 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MW770.CAT
[2012/11/26 22:19:48 | 000,031,281 | ---- | C] () -- C:\WINDOWS\System32\dllcache\FP4.CAT
[2012/11/26 22:19:48 | 000,013,753 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IMS.CAT
[2012/11/26 22:19:48 | 000,013,472 | ---- | C] () -- C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012/11/26 22:19:48 | 000,009,581 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2012/11/26 22:19:48 | 000,008,574 | ---- | C] () -- C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012/11/26 22:19:48 | 000,007,382 | ---- | C] () -- C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012/11/26 22:19:48 | 000,007,334 | ---- | C] () -- C:\WINDOWS\System32\dllcache\wmerrenu.cat
[2012/11/26 22:19:48 | 000,007,245 | ---- | C] () -- C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2012/11/26 22:19:47 | 001,042,903 | ---- | C] () -- C:\WINDOWS\System32\dllcache\SP2.CAT
[2012/11/26 22:19:46 | 002,012,670 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5.CAT
[2012/11/26 22:19:46 | 000,502,724 | ---- | C] () -- C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2012/11/26 22:17:48 | 000,192,976 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/11/26 22:17:25 | 000,000,211 | -HS- | C] () -- C:\boot.ini
[2012/11/26 22:17:21 | 000,000,658 | ---- | C] () -- C:\WINDOWS\System32\$winnt$.inf

========== ZeroAccess Check ==========

[2012/11/26 22:35:54 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2009/01/07 18:20:52 | 001,497,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2004/08/03 09:56:44 | 000,472,064 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2004/08/03 09:56:48 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/11/26 22:40:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DatacardService
[2012/11/27 02:36:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TP-LINK
[2012/11/30 00:39:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2012/12/01 15:42:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avro Keyboard
[2012/11/27 02:38:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samhita\Application Data\TP-LINK
[2012/11/27 04:26:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samhita\Application Data\DanuSoft
[2012/11/28 08:17:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samhita\Application Data\Free Download Manager
[2012/11/29 23:16:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samhita\Application Data\uTorrent
[2012/11/30 00:39:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Samhita\Application Data\Babylon

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2005/02/02 04:45:50 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2004/08/03 19:38:34 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2012/12/04 21:17:40 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2012/11/26 22:33:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2012/11/26 22:33:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2012/11/26 22:33:00 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2012/11/26 22:33:00 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2007/01/02 11:54:46 | 000,252,820 | ---- | M] () -- C:\vrinda.ttf
[2004/08/03 21:56:48 | 000,406,528 | ---- | M] (Microsoft Corporation) -- C:\usp10.dll
[2012/12/19 08:36:02 | 1598,029,824 | -HS- | M] () -- C:\pagefile.sys
[5 C:\*.tmp files -> C:\*.tmp -> ]

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2012/11/26 22:32:24 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/18 17:31:48 | 000,018,944 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2012/11/26 22:17:24 | 000,909,312 | ---- | M] () -- C:\WINDOWS\System32\config\system.sav
[2012/11/26 22:17:24 | 000,659,456 | ---- | M] () -- C:\WINDOWS\System32\config\software.sav
[2012/11/26 22:17:24 | 000,094,208 | ---- | M] () -- C:\WINDOWS\System32\config\default.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
[2012/11/26 22:33:06 | 000,000,294 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
[2012/11/26 22:33:06 | 000,001,411 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
[2012/11/26 22:33:06 | 000,000,398 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Windows Catalog.lnk
[2012/11/26 22:33:06 | 000,001,511 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
[2012/11/27 00:48:38 | 000,000,324 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\My Bluetooth Places.lnk
[2012/11/29 23:19:26 | 000,000,534 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\µTorrent.lnk

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.EXE >
[2005/10/15 16:07:16 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=45757077A47C68A603A79B03A1A836AB -- C:\WINDOWS\explorer.exe

< MD5 for: EXPLORER.EXE-082F38A9.PF >
[2012/12/19 07:57:56 | 000,068,702 | ---- | M] () MD5=28FF883AE0867F6442C1124273A1A3D7 -- C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

< MD5 for: EXPLORER.SCF >
[2001/08/23 11:00:00 | 000,000,080 | ---- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 -- C:\WINDOWS\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | ---- | M] () MD5=1435F4731719DF5F57D17DC38196245D -- C:\WINDOWS\Help\iexplore.chm
[2004/07/17 08:40:18 | 000,204,810 | ---- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE -- C:\WINDOWS\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | ---- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E -- C:\WINDOWS\system32\dllcache\iexplore.exe
[2004/08/03 09:56:52 | 000,093,184 | ---- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 -- C:\WINDOWS\ie8\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Program Files\Internet Explorer\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2012/12/19 08:27:04 | 000,142,204 | ---- | M] () MD5=B4DF521E5417E63EAE8CAC7C46DEF4ED -- C:\WINDOWS\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2001/08/23 11:00:00 | 000,180,335 | ---- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 -- C:\WINDOWS\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2004/08/03 21:56:58 | 000,502,272 | ---- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE -- C:\WINDOWS\system32\winlogon.exe

< MD5 for: WINLOGON.EXE-32C57D49.PF >
[2012/12/19 07:57:54 | 000,057,726 | ---- | M] () MD5=59916D799ACBF5FAD2F02226AB7B8967 -- C:\WINDOWS\Prefetch\WINLOGON.EXE-32C57D49.pf

< End of report >

Attached Files


Edited by ADR, 18 December 2012 - 11:51 PM.

  • 0

Advertisements


#2
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Greetings and Welcome to The Forums!!

My name is Gringo and I'll be glad to help you with your malware problems.

I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.




These are the programs I would like you to run next, if you have any problems with these just skip it and run the next one.

-Security Check-

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

-AdwCleaner-

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

--RogueKiller--

  • Download & SAVE to your Desktop RogueKiller or from here
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+

Gringo
  • 0

#3
ADR

ADR

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Gringo,

Thanks a lot for your kind attention. I've run all those three programs and the reports are attached below.

Regards,
ADR


Results of screen317's Security Check version 0.99.56
Windows XP Service Pack 2 x86
Out of date service pack!!
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Please wait while WMIC compiles updated MOF files.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
N
o
r
t
o
n
ECHO is off.
A
n
t
i
V
i
r
u
s
ECHO is off.
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Java 7 Update 9
Adobe Flash Player 11.5.502.110
Adobe Reader XI
Mozilla Firefox (17.0.1)
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
Norton AntiVirus Engine 20.2.0.19 ccSvcHst.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 28% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````




# AdwCleaner v2.101 - Logfile created 12/19/2012 at 21:38:31
# Updated 16/12/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 2 (32 bits)
# User : Samhita - WIN2006
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Samhita\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
Folder Deleted : C:\Documents and Settings\All Users\Application Data\Babylon
Folder Deleted : C:\Documents and Settings\Samhita\Application Data\Babylon

***** [Registry] *****

Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{000F18F2-09EB-4A59-82B2-5AE4184C39C3}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9E131A93-EED7-4BEB-B015-A0ADB30B5646}
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKCU\Software\SweetIM
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{608D3067-77E8-463D-9084-908966806826}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph
Key Deleted : HKLM\Software\Iminent
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\BabylonToolbar
Key Deleted : HKLM\Software\SweetIM
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [bProtectorDefaultScope]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v17.0.1 (en-US)

Profile name : default-1354313503781 [Profil par défaut]
File : C:\Documents and Settings\Samhita\Application Data\Mozilla\Firefox\Profiles\t60pwtpc.default-1354313503781\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [2740 octets] - [19/12/2012 21:38:31]

########## EOF - C:\AdwCleaner[S1].txt - [2800 octets] ##########







RogueKiller V8.4.0 [Dec 18 2012] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo...13-roguekiller/
Website : http://tigzy.geeksto...roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 2) 32 bits version
Started in : Normal mode
User : Samhita [Admin rights]
Mode : Scan -- Date : 12/19/2012 21:42:01

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 7 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : CriQnkii (C:\Documents and Settings\Samhita\Local Settings\Application Data\tlqedhyu\criqnkii.exe) -> FOUND
[RUN][SUSP PATH] HKUS\S-1-5-21-1960408961-1229272821-839522115-1003[...]\Run : CriQnkii (C:\Documents and Settings\Samhita\Local Settings\Application Data\tlqedhyu\criqnkii.exe) -> FOUND
[DNS] HKLM\[...]\ControlSet001\Services\Interfaces\{82DB0FD0-AA8B-45E1-9009-DD1F2540D717} : NameServer (172.16.0.1) -> FOUND
[DNS] HKLM\[...]\ControlSet002\Services\Interfaces\{82DB0FD0-AA8B-45E1-9009-DD1F2540D717} : NameServer (172.16.0.1) -> FOUND
[HJ] HKLM\[...]\SystemRestore : DisableSR (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[APPINIT][SUSP PATH] HKLM\[...]\Windows : AppInit_DLLs (c:\docume~1\alluse~1\applic~1\browse~1\25911~1.18\{c16c1~1\mngr.dll) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[12] : NtAlertResumeThread @ 0x805D334A -> HOOKED (Unknown @ 0x8651BA90)
SSDT[13] : NtAlertThread @ 0x805D32FA -> HOOKED (Unknown @ 0x8647A7A8)
SSDT[17] : NtAllocateVirtualMemory @ 0x805A74E2 -> HOOKED (Unknown @ 0x8618F058)
SSDT[19] : NtAssignProcessToJobObject @ 0x805D4E0E -> HOOKED (Unknown @ 0x8618FE90)
SSDT[31] : NtConnectPort @ 0x805A2FF8 -> HOOKED (Unknown @ 0x861BC0E8)
SSDT[43] : NtCreateMutant @ 0x806154E8 -> HOOKED (Unknown @ 0x864570C8)
SSDT[52] : NtCreateSymbolicLinkObject @ 0x805C35EC -> HOOKED (Unknown @ 0x86325F80)
SSDT[53] : NtCreateThread @ 0x805CF844 -> HOOKED (Unknown @ 0x8631B698)
SSDT[57] : NtDebugActiveProcess @ 0x80640FA0 -> HOOKED (Unknown @ 0x8618FF70)
SSDT[68] : NtDuplicateObject @ 0x805BC894 -> HOOKED (Unknown @ 0x862160A0)
SSDT[83] : NtFreeVirtualMemory @ 0x805B194A -> HOOKED (Unknown @ 0x863250A0)
SSDT[89] : NtImpersonateAnonymousToken @ 0x805F728A -> HOOKED (Unknown @ 0x8647CAF0)
SSDT[91] : NtImpersonateThread @ 0x805D5FCE -> HOOKED (Unknown @ 0x8651BAC8)
SSDT[97] : NtLoadDriver @ 0x80582E16 -> HOOKED (Unknown @ 0x862AB108)
SSDT[108] : NtMapViewOfSection @ 0x805B09D2 -> HOOKED (Unknown @ 0x863D2190)
SSDT[114] : NtOpenEvent @ 0x8060CED2 -> HOOKED (Unknown @ 0x8641B340)
SSDT[122] : NtOpenProcess @ 0x805C9C86 -> HOOKED (Unknown @ 0x8629E2A8)
SSDT[123] : NtOpenProcessToken @ 0x805EBF7A -> HOOKED (Unknown @ 0x8632A988)
SSDT[125] : NtOpenSection @ 0x805A8E16 -> HOOKED (Unknown @ 0x863EC248)
SSDT[128] : NtOpenThread @ 0x805C9F12 -> HOOKED (Unknown @ 0x8629E1F8)
SSDT[137] : NtProtectVirtualMemory @ 0x805B6DA6 -> HOOKED (Unknown @ 0x861C9F18)
SSDT[206] : unknown @ 0x805D3186 -> HOOKED (Unknown @ 0x86477468)
SSDT[213] : NtSetContextThread @ 0x805CFF7E -> HOOKED (Unknown @ 0x86327088)
SSDT[228] : NtSetInformationProcess @ 0x805CC6D0 -> HOOKED (Unknown @ 0x8628E008)
SSDT[240] : NtSetSystemInformation @ 0x8060DB8A -> HOOKED (Unknown @ 0x8629DEC0)
SSDT[253] : NtSuspendProcess @ 0x805D324E -> HOOKED (Unknown @ 0x86402B30)
SSDT[254] : NtSuspendThread @ 0x805D30C0 -> HOOKED (Unknown @ 0x86512D80)
SSDT[257] : NtTerminateProcess @ 0x805D11AE -> HOOKED (Unknown @ 0x863A16E0)
SSDT[258] : NtTerminateThread @ 0x805D13A8 -> HOOKED (Unknown @ 0x863DB840)
SSDT[267] : NtUnmapViewOfSection @ 0x805B17E0 -> HOOKED (Unknown @ 0x86327200)
SSDT[277] : NtWriteVirtualMemory @ 0x805B2D60 -> HOOKED (Unknown @ 0x861C9058)
S_SSDT[307] : NtUserAttachThreadInput -> HOOKED (Unknown @ 0x862824A8)
S_SSDT[383] : NtUserGetAsyncKeyState -> HOOKED (Unknown @ 0x864152B0)
S_SSDT[414] : NtUserGetKeyboardState -> HOOKED (Unknown @ 0x8615B260)
S_SSDT[416] : NtUserGetKeyState -> HOOKED (Unknown @ 0x862532B0)
S_SSDT[428] : NtUserGetRawInputData -> HOOKED (Unknown @ 0x8638AAF8)
S_SSDT[460] : NtUserMessageCall -> HOOKED (Unknown @ 0x865167C8)
S_SSDT[475] : NtUserPostMessage -> HOOKED (Unknown @ 0x86521C08)
S_SSDT[476] : NtUserPostThreadMessage -> HOOKED (Unknown @ 0x86487320)
S_SSDT[549] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x86212188)
S_SSDT[552] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x86353DD0)

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: Hitachi HTS541612J9SA00 +++++
--- User ---
[MBR] 1a1a854ee1d44d18bf6618008f1ecc18
[BSP] 8040c4c250de957fa75f5359f0fce795 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 63 | Size: 16002 Mo
1 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 32772600 | Size: 98468 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1]_S_12192012_02d2142.txt >>
RKreport[1]_S_12192012_02d2142.txt
  • 0

#4
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello

I Would like you to do the following.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
  • 0

#5
ADR

ADR

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Gringo,

Thanks for your reply. Below are some points I wish to highlight at this moment.

1. Before running Combofix today, I installed MBAM last day and it removed some suspicious registry entries. Today I've found that the antivirus websites and microsoft website are opening in firefox. But internet explorer still does not work. It's not able to open any website.
I wanted to take a back up of my norton antivirus from my account there. But when I clicked on 'Account' button in Norton application, it tried to open internet explorer though my default browser is firefox. After that everything goes back to previous stage means no antivirus site are not opening again. :(

2. I'm not able to run combofix directly. I had to change the extension to .com to make it run. Otherwise it was closing immediately.

3. Combofix ran and downloaded recovery console from microsoft website. Then after completion of around 50 stages it deleted some files from Application Data folder. But after restart, it's trying to do something which gives something like physical memory dump(Blue Screen) and system reboots immediately. So, I'm not able to get any log from it.

4. Another thing I've noticed last day in norton antivirus history tab: in every 5 second, there is a log stating 'Unauthorized access blocked(Protect Virtual Memory)'. Below is the details of the log:
Actor: C:\WINDOWS\SYSTEM32\SVCHOST.EXE
Target: C:\Program Files\Notron Antivirus\Engine\20.2.0.19\ccSvcHst.exe
Action: Protect virtual memory
Reaction: Unauthorized access blocked.


Please let me know if you need any more information from my side to help you to analyze further. I'll update you if I find something else.

Thanks a lot for you time and attention.

Regards,
ADR
  • 0

#6
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Greetings ADR

thank you for the feedback - it always helps

I want you to run these next,

Please download the latest version of TDSSKiller from here and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
  • Put a checkmark beside loaded modules.
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
  • Click the Start Scan button.
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
  • If malicious objects are found, they will show in the Scan results
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.



Please download aswMBR to your desktop.
  • Double click the aswMBR.exe icon to run it
  • it will ask to download extra definitions - ALLOW IT
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

If you have any problems running either one come back and let me know

please reply with the reports from TDSSKiller and aswMBR

Gringo
  • 0

#7
ADR

ADR

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Greetings Gringo.

I could not download the files from my PC as the websites did not open. Anyway I managed to download those from a different PC and ran scan.
TDSKiller found 7 threats but the cure option were not available.
The reports are as below.

Regards,
ADR

TDSKiller:
21:34:10.0109 1248 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
21:34:11.0296 1248 ============================================================
21:34:11.0296 1248 Current date / time: 2012/12/21 21:34:11.0296
21:34:11.0296 1248 SystemInfo:
21:34:11.0296 1248
21:34:11.0296 1248 OS Version: 5.1.2600 ServicePack: 2.0
21:34:11.0296 1248 Product type: Workstation
21:34:11.0296 1248 ComputerName: WIN2006
21:34:11.0296 1248 UserName: Samhita
21:34:11.0296 1248 Windows directory: C:\WINDOWS
21:34:11.0296 1248 System windows directory: C:\WINDOWS
21:34:11.0296 1248 Processor architecture: Intel x86
21:34:11.0296 1248 Number of processors: 2
21:34:11.0296 1248 Page size: 0x1000
21:34:11.0296 1248 Boot type: Normal boot
21:34:11.0296 1248 ============================================================
21:34:13.0656 1248 BG loaded
21:34:14.0015 1248 Drive \Device\Harddisk0\DR0 - Size: 0x1BF2976000 (111.79 Gb), SectorSize: 0x200, Cylinders: 0x3901, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
21:34:14.0156 1248 ============================================================
21:34:14.0156 1248 \Device\Harddisk0\DR0:
21:34:14.0328 1248 MBR partitions:
21:34:14.0328 1248 \Device\Harddisk0\DR0\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x1F411B9
21:34:14.0343 1248 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1F41237, BlocksNum 0x9859899
21:34:14.0406 1248 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xB79AB0F, BlocksNum 0xE04B94
21:34:14.0671 1248 \Device\Harddisk0\DR0\Partition4: MBR, Type 0x7, StartLBA 0xC59F6E2, BlocksNum 0x19F40DF
21:34:14.0671 1248 ============================================================
21:34:14.0843 1248 C: <-> \Device\Harddisk0\DR0\Partition1
21:34:15.0109 1248 D: <-> \Device\Harddisk0\DR0\Partition2
21:34:15.0265 1248 E: <-> \Device\Harddisk0\DR0\Partition3
21:34:15.0609 1248 F: <-> \Device\Harddisk0\DR0\Partition4
21:34:15.0796 1248 ============================================================
21:34:15.0796 1248 Initialize success
21:34:15.0796 1248 ============================================================
21:35:19.0125 2968 ============================================================
21:35:19.0125 2968 Scan started
21:35:19.0125 2968 Mode: Manual; SigCheck; TDLFS;
21:35:19.0125 2968 ============================================================
21:35:19.0984 2968 ================ Scan system memory ========================
21:35:19.0984 2968 System memory - ok
21:35:19.0984 2968 ================ Scan services =============================
21:35:20.0062 2968 Abiosdsk - ok
21:35:20.0062 2968 abp480n5 - ok
21:35:20.0125 2968 [ A10C7534F7223F4A73A948967D00E69B ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
21:35:21.0921 2968 ACPI - ok
21:35:21.0968 2968 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\DRIVERS\ACPIEC.sys
21:35:22.0156 2968 ACPIEC - ok
21:35:22.0250 2968 [ D6F2A9900D295C08FBEF217AB50226A8 ] ACPIVPC C:\WINDOWS\system32\DRIVERS\AcpiVpc.sys
21:35:22.0265 2968 ACPIVPC - ok
21:35:22.0453 2968 [ 5AC144F03B31AFAB6717AD3622D1680D ] ACS C:\WINDOWS\system32\acs.exe
21:35:22.0500 2968 ACS ( UnsignedFile.Multi.Generic ) - warning
21:35:22.0500 2968 ACS - detected UnsignedFile.Multi.Generic (1)
21:35:22.0515 2968 adpu160m - ok
21:35:22.0562 2968 [ 1EE7B434BA961EF845DE136224C30FEC ] aec C:\WINDOWS\system32\drivers\aec.sys
21:35:22.0843 2968 aec - ok
21:35:22.0906 2968 [ 5AC495F4CB807B2B98AD2AD591E6D92E ] AFD C:\WINDOWS\System32\drivers\afd.sys
21:35:23.0484 2968 AFD - ok
21:35:23.0484 2968 Aha154x - ok
21:35:23.0500 2968 aic78u2 - ok
21:35:23.0500 2968 aic78xx - ok
21:35:23.0531 2968 [ C7AE0FD3867DB0D42B03B73C18F3D671 ] Alerter C:\WINDOWS\system32\alrsvc.dll
21:35:23.0750 2968 Alerter - ok
21:35:23.0859 2968 [ F1958FBF86D5C004CF19A5951A9514B7 ] ALG C:\WINDOWS\System32\alg.exe
21:35:23.0921 2968 ALG - ok
21:35:23.0937 2968 AliIde - ok
21:35:23.0937 2968 amsint - ok
21:35:23.0984 2968 [ 3B72E032779042953BD2B1B4B02F7BC0 ] ApfiltrService C:\WINDOWS\system32\DRIVERS\Apfiltr.sys
21:35:24.0015 2968 ApfiltrService - ok
21:35:24.0046 2968 [ 9C3C12975C97119412802B181FBEEFFE ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
21:35:24.0125 2968 AppMgmt - ok
21:35:24.0234 2968 [ 7141E281D840699D9D79B18F4062DD58 ] AR9271 C:\WINDOWS\system32\DRIVERS\athuw.sys
21:35:24.0343 2968 AR9271 ( UnsignedFile.Multi.Generic ) - warning
21:35:24.0343 2968 AR9271 - detected UnsignedFile.Multi.Generic (1)
21:35:24.0390 2968 [ F0D692B0BFFB46E30EB3CEA168BBC49F ] Arp1394 C:\WINDOWS\system32\DRIVERS\arp1394.sys
21:35:24.0531 2968 Arp1394 - ok
21:35:24.0546 2968 asc - ok
21:35:24.0546 2968 asc3350p - ok
21:35:24.0562 2968 asc3550 - ok
21:35:24.0718 2968 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
21:35:24.0718 2968 aspnet_state - ok
21:35:24.0765 2968 [ 02000ABF34AF4C218C35D257024807D6 ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
21:35:24.0906 2968 AsyncMac - ok
21:35:24.0937 2968 [ C4B52426B79C6F6664B70B8E63B1B837 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
21:35:25.0046 2968 atapi - ok
21:35:25.0062 2968 Atdisk - ok
21:35:25.0078 2968 [ EC88DA854AB7D7752EC8BE11A741BB7F ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
21:35:25.0234 2968 Atmarpc - ok
21:35:25.0281 2968 [ DB66DB626E4882EBEF55F136F12C1829 ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
21:35:25.0437 2968 AudioSrv - ok
21:35:25.0453 2968 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
21:35:25.0593 2968 audstub - ok
21:35:25.0640 2968 [ F96038AA1EC4013A93D2420FC689D1E9 ] b57w2k C:\WINDOWS\system32\DRIVERS\b57xp32.sys
21:35:25.0656 2968 b57w2k - ok
21:35:25.0687 2968 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
21:35:25.0812 2968 Beep - ok
21:35:25.0984 2968 [ 9DFFCB249663AA3C2ECB67202280054E ] BHDrvx86 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20121130.005\BHDrvx86.sys
21:35:26.0046 2968 BHDrvx86 - ok
21:35:26.0125 2968 [ 2C69EC7E5A311334D10DD95F338FCCEA ] BITS C:\WINDOWS\system32\qmgr.dll
21:35:26.0296 2968 BITS - ok
21:35:26.0343 2968 [ E3CFCCDDA4EDD1D0DC9168B2E18F27B8 ] Browser C:\WINDOWS\System32\browser.dll
21:35:26.0484 2968 Browser - ok
21:35:26.0562 2968 [ D84166D41A05F66D9084039427E5025B ] BTKRNL C:\WINDOWS\system32\DRIVERS\btkrnl.sys
21:35:26.0671 2968 BTKRNL - ok
21:35:26.0796 2968 [ B1E5C0065102FCB92E1F0231AF0AE7C3 ] btwdins C:\Program Files\Lenovo\Bluetooth Software\bin\btwdins.exe
21:35:26.0812 2968 btwdins ( UnsignedFile.Multi.Generic ) - warning
21:35:26.0812 2968 btwdins - detected UnsignedFile.Multi.Generic (1)
21:35:26.0828 2968 [ A01FD9851406DE0870C23759E2F7B6EA ] BTWUSB C:\WINDOWS\system32\Drivers\btwusb.sys
21:35:26.0843 2968 BTWUSB - ok
21:35:26.0921 2968 catchme - ok
21:35:26.0953 2968 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
21:35:27.0109 2968 cbidf2k - ok
21:35:27.0171 2968 [ 1277AD8F053CC60C17CAFAB411F3CF40 ] ccSet_NAV C:\WINDOWS\system32\drivers\NAV\1402000.013\ccSetx86.sys
21:35:27.0187 2968 ccSet_NAV - ok
21:35:27.0234 2968 [ 1277AD8F053CC60C17CAFAB411F3CF40 ] ccSet_NST C:\WINDOWS\system32\drivers\NST\7DD02000.012\ccSetx86.sys
21:35:27.0250 2968 ccSet_NST - ok
21:35:27.0265 2968 cd20xrnt - ok
21:35:27.0312 2968 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
21:35:27.0500 2968 Cdaudio - ok
21:35:27.0546 2968 [ CD7D5152DF32B47F4E36F710B35AAE02 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
21:35:27.0687 2968 Cdfs - ok
21:35:27.0734 2968 [ AF9C19B3100FE010496B1A27181FBF72 ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
21:35:27.0875 2968 Cdrom - ok
21:35:27.0890 2968 Changer - ok
21:35:27.0953 2968 [ 3192BD04D032A9C4A85A3278C268A13A ] CiSvc C:\WINDOWS\system32\cisvc.exe
21:35:28.0093 2968 CiSvc - ok
21:35:28.0109 2968 [ C8DEC22C4137D7A90F8BDF41CA4B82AE ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
21:35:28.0265 2968 ClipSrv - ok
21:35:28.0406 2968 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:35:28.0421 2968 clr_optimization_v4.0.30319_32 - ok
21:35:28.0453 2968 [ 4266BE808F85826AEDF3C64C1E240203 ] CmBatt C:\WINDOWS\system32\DRIVERS\CmBatt.sys
21:35:28.0593 2968 CmBatt - ok
21:35:28.0593 2968 CmdIde - ok
21:35:28.0625 2968 [ DF1B1A24BF52D0EBC01ED4ECE8979F50 ] Compbatt C:\WINDOWS\system32\DRIVERS\compbatt.sys
21:35:28.0968 2968 Compbatt - ok
21:35:29.0031 2968 COMSysApp - ok
21:35:29.0031 2968 Cpqarray - ok
21:35:29.0078 2968 [ 10654F9DDCEA9C46CFB77554231BE73B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
21:35:29.0234 2968 CryptSvc - ok
21:35:29.0234 2968 dac2w2k - ok
21:35:29.0250 2968 dac960nt - ok
21:35:29.0359 2968 [ A4254FFC7B7894D118D8E6E57E34C660 ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
21:35:29.0515 2968 DcomLaunch - ok
21:35:29.0546 2968 [ 095FF903BC31321D3844976B52D513FC ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
21:35:29.0687 2968 Dhcp - ok
21:35:29.0718 2968 [ 00CA44E4534865F8A3B64F7C0984BFF0 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
21:35:29.0859 2968 Disk - ok
21:35:29.0953 2968 [ 32273CD4CDF7ECB186EC1849EB232A63 ] DKbFltr C:\WINDOWS\system32\DRIVERS\DKbFltr.sys
21:35:29.0968 2968 DKbFltr - ok
21:35:29.0984 2968 dmadmin - ok
21:35:30.0062 2968 [ C0FBB516E06E243F0CF31F597E7EBF7D ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
21:35:30.0234 2968 dmboot - ok
21:35:30.0359 2968 [ F5E7B358A732D09F4BCF2824B88B9E28 ] dmio C:\WINDOWS\system32\drivers\dmio.sys
21:35:30.0500 2968 dmio - ok
21:35:30.0531 2968 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
21:35:30.0671 2968 dmload - ok
21:35:30.0718 2968 [ 1639D9964C9E1B2ECCA95C8217D3E70D ] dmserver C:\WINDOWS\System32\dmserver.dll
21:35:30.0859 2968 dmserver - ok
21:35:30.0937 2968 [ A6F881284AC1150E37D9AE47FF601267 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
21:35:31.0078 2968 DMusic - ok
21:35:31.0109 2968 [ 7379DE06FD196E396A00AA97B990C00D ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
21:35:31.0250 2968 Dnscache - ok
21:35:31.0250 2968 dpti2o - ok
21:35:31.0390 2968 [ 5C918D413F5837E67A85775C9873775E ] DritekPortIO C:\PROGRA~1\EzButton\DPortIO.sys
21:35:31.0406 2968 DritekPortIO - ok
21:35:31.0421 2968 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
21:35:31.0578 2968 drmkaud - ok
21:35:31.0656 2968 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:35:31.0671 2968 eeCtrl - ok
21:35:31.0703 2968 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:35:31.0718 2968 EraserUtilRebootDrv - ok
21:35:31.0734 2968 [ 67DFF7BBBD0E80AAB7B3CF061448DB8A ] ERSvc C:\WINDOWS\System32\ersvc.dll
21:35:31.0890 2968 ERSvc - ok
21:35:31.0937 2968 [ C6CE6EEC82F187615D1002BB3BB50ED4 ] Eventlog C:\WINDOWS\system32\services.exe
21:35:32.0078 2968 Eventlog - ok
21:35:32.0156 2968 [ 6AD7DFD0BB21CE2A95D34A346C4B537B ] EventSystem C:\WINDOWS\system32\es.dll
21:35:32.0250 2968 EventSystem - ok
21:35:32.0281 2968 [ 57C171EA22F0A7F068FCB0CAEDD1E8E7 ] ew_hwusbdev C:\WINDOWS\system32\DRIVERS\ew_hwusbdev.sys
21:35:32.0312 2968 ew_hwusbdev - ok
21:35:32.0343 2968 [ 144CA88C1BFDB5ED724138D9C08D44C3 ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
21:35:32.0406 2968 Fastfat - ok
21:35:32.0453 2968 [ E7518DC542D3EBDCB80EDD98462C7821 ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
21:35:32.0593 2968 FastUserSwitchingCompatibility - ok
21:35:32.0625 2968 [ CED2E8396A8838E59D8FD529C680E02C ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
21:35:32.0765 2968 Fdc - ok
21:35:32.0796 2968 [ E153AB8A11DE5452BCF5AC7652DBF3ED ] Fips C:\WINDOWS\system32\drivers\Fips.sys
21:35:32.0921 2968 Fips - ok
21:35:32.0937 2968 [ 0DD1DE43115B93F4D85E889D7A86F548 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
21:35:33.0171 2968 Flpydisk - ok
21:35:33.0203 2968 [ 157754F0DF355A9E0A6F54721914F9C6 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
21:35:33.0343 2968 FltMgr - ok
21:35:33.0437 2968 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
21:35:33.0578 2968 Fs_Rec - ok
21:35:33.0921 2968 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
21:35:34.0062 2968 Ftdisk - ok
21:35:34.0078 2968 [ C0F1D4A21DE5A415DF8170616703DEBF ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
21:35:34.0218 2968 Gpc - ok
21:35:34.0265 2968 [ 3FCC124B6E08EE0E9351F717DD136939 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
21:35:34.0296 2968 HDAudBus - ok
21:35:34.0343 2968 [ 8827911A8C37E40C027CBFC88E69D967 ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
21:35:34.0468 2968 helpsvc - ok
21:35:34.0531 2968 HidServ - ok
21:35:34.0546 2968 hpn - ok
21:35:34.0578 2968 [ 3247A2DB333D1521680E6864A8295A47 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
21:35:34.0656 2968 HTTP - ok
21:35:34.0687 2968 [ 064D8581ADF77C25133E7D751D917D83 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
21:35:34.0843 2968 HTTPFilter - ok
21:35:34.0921 2968 [ F44461E66F1B7DD267957FE9BAA63ED0 ] huawei_enumerator C:\WINDOWS\system32\DRIVERS\ew_jubusenum.sys
21:35:35.0000 2968 huawei_enumerator - ok
21:35:35.0031 2968 [ F547F862B8907F1BCBD9B72A72A6449E ] hwdatacard C:\WINDOWS\system32\DRIVERS\ewusbmdm.sys
21:35:35.0078 2968 hwdatacard - ok
21:35:35.0125 2968 HWDeviceService.exe - ok
21:35:35.0125 2968 i2omgmt - ok
21:35:35.0140 2968 i2omp - ok
21:35:35.0156 2968 [ 5502B58EEF7486EE6F93F3F164DCB808 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
21:35:35.0312 2968 i8042prt - ok
21:35:35.0625 2968 [ BFFA387180121DF1E4646C4CED3E16CA ] ialm C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
21:35:36.0046 2968 ialm - ok
21:35:36.0218 2968 [ C19BF2A07BE972A110220DF6B1E89D14 ] IDSxpx86 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20121220.001\IDSxpx86.sys
21:35:36.0250 2968 IDSxpx86 - ok
21:35:36.0281 2968 [ AD5E8A6C823F24882A6826D7DBCCF4A3 ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
21:35:36.0375 2968 Imapi - ok
21:35:36.0468 2968 [ FA788520BCAC0F5D9D5CDE5615C0D931 ] ImapiService C:\WINDOWS\system32\imapi.exe
21:35:36.0656 2968 ImapiService - ok
21:35:36.0687 2968 ini910u - ok
21:35:36.0953 2968 [ 274FF777C369CC8F05A4B4F9A243335B ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
21:35:37.0156 2968 IntcAzAudAddService - ok
21:35:37.0203 2968 IntelIde - ok
21:35:37.0250 2968 [ DB8A1859CF9E48914DCC0A7206D87BE5 ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
21:35:37.0328 2968 intelppm - ok
21:35:37.0375 2968 [ 4448006B6BC60E6C027932CFC38D6855 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
21:35:37.0578 2968 Ip6Fw - ok
21:35:37.0625 2968 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
21:35:37.0750 2968 IpFilterDriver - ok
21:35:37.0750 2968 [ E1EC7F5DA720B640CD8FB8424F1B14BB ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
21:35:37.0953 2968 IpInIp - ok
21:35:38.0031 2968 [ D58ECD3B3969A670E68588F1640920B6 ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
21:35:38.0078 2968 IpNat - ok
21:35:38.0109 2968 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
21:35:38.0234 2968 IPSec - ok
21:35:38.0343 2968 [ 50708DAA1B1CBB7D6AC1CF8F56A24410 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
21:35:38.0406 2968 IRENUM - ok
21:35:38.0437 2968 [ E504F706CCB699C2596E9A3DA1596E87 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
21:35:38.0562 2968 isapnp - ok
21:35:38.0656 2968 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
21:35:38.0671 2968 JavaQuickStarterService - ok
21:35:38.0750 2968 [ FFDB868A2A069F8D58C0E9A1203378C5 ] jswpsapi C:\Program Files\TP-LINK\TP-LINK Wireless Configuration Utility\WPS\jswpsapi.exe
21:35:38.0765 2968 jswpsapi ( UnsignedFile.Multi.Generic ) - warning
21:35:38.0765 2968 jswpsapi - detected UnsignedFile.Multi.Generic (1)
21:35:38.0812 2968 [ AD67795900AA8C05CC4570F5349E0639 ] JSWSCIMD C:\WINDOWS\system32\DRIVERS\jswscimd.sys
21:35:39.0250 2968 JSWSCIMD - ok
21:35:39.0281 2968 [ EBDEE8A2EE5393890A1ACEE971C4C246 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
21:35:39.0406 2968 Kbdclass - ok
21:35:39.0453 2968 [ D93CAD07C5683DB066B0B2D2D3790EAD ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
21:35:39.0609 2968 kmixer - ok
21:35:39.0625 2968 [ EB7FFE87FD367EA8FCA0506F74A87FBB ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
21:35:39.0765 2968 KSecDD - ok
21:35:39.0828 2968 [ 4E9EA6CC8DB8DCEF7FB37F2C9B4CC556 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
21:35:39.0875 2968 lanmanserver - ok
21:35:39.0906 2968 [ 2C0A7B2AE9C26F2C163627679B42783C ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
21:35:40.0046 2968 lanmanworkstation - ok
21:35:40.0046 2968 lbrtfdc - ok
21:35:40.0093 2968 [ B3EFF6D938C572E90A07B3D87A3C7657 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
21:35:40.0218 2968 LmHosts - ok
21:35:40.0250 2968 [ 95FD808E4AC22ABA025A7B3EAC0375D2 ] Messenger C:\WINDOWS\System32\msgsvc.dll
21:35:40.0375 2968 Messenger - ok
21:35:40.0437 2968 Micorsoft Windows Service - ok
21:35:40.0468 2968 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
21:35:40.0593 2968 mnmdd - ok
21:35:40.0671 2968 [ F6415361201915B9FE3896B0E4E724FF ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
21:35:40.0796 2968 mnmsrvc - ok
21:35:40.0828 2968 [ 6FC6F9D7ACC36DCA9B914565A3AEDA05 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
21:35:40.0968 2968 Modem - ok
21:35:40.0984 2968 [ 34E1F0031153E491910E12551400192C ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
21:35:41.0125 2968 Mouclass - ok
21:35:41.0218 2968 [ 65653F3B4477F3C63E68A9659F85EE2E ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
21:35:41.0359 2968 MountMgr - ok
21:35:41.0406 2968 [ 8C7336950F1E69CDFD811CBBD9CF00A2 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
21:35:41.0421 2968 MozillaMaintenance - ok
21:35:41.0437 2968 mraid35x - ok
21:35:41.0468 2968 [ 46EDCC8F2DB2F322C24F48785CB46366 ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
21:35:41.0593 2968 MRxDAV - ok
21:35:41.0656 2968 [ F6BFAE0CC79784D0A72DF6684C173437 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
21:35:41.0734 2968 MRxSmb - ok
21:35:41.0781 2968 [ C7C3D89EB0A6F3DBA622EA737FA335B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
21:35:41.0921 2968 MSDTC - ok
21:35:42.0015 2968 [ 561B3A4333CA2DBDBA28B5B956822519 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
21:35:42.0171 2968 Msfs - ok
21:35:42.0187 2968 MSIServer - ok
21:35:42.0203 2968 [ AE431A8DD3C1D0D0610CDBAC16057AD0 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
21:35:42.0343 2968 MSKSSRV - ok
21:35:42.0421 2968 [ 13E75FEF9DFEB08EEDED9D0246E1F448 ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
21:35:42.0546 2968 MSPCLOCK - ok
21:35:42.0562 2968 [ 1988A33FF19242576C3D0EF9CE785DA7 ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
21:35:42.0703 2968 MSPQM - ok
21:35:42.0734 2968 [ 469541F8BFD2B32659D5D463A6714BCE ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
21:35:42.0875 2968 mssmbios - ok
21:35:42.0906 2968 [ F66B6B1CDDEE6CA87CEFC016EB7A0D8E ] Mup C:\WINDOWS\system32\drivers\Mup.sys
21:35:43.0000 2968 Mup - ok
21:35:43.0062 2968 [ 4A9258B9597A31DB68EC9740F3A8A70B ] NAV C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvcHst.exe
21:35:43.0078 2968 NAV - ok
21:35:43.0171 2968 [ 8E4C77AD9BB279900C00F870CC0C674B ] NAVENG C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20121221.004\NAVENG.SYS
21:35:43.0187 2968 NAVENG - ok
21:35:43.0281 2968 [ 826F699B69E88A3920C70F344DD42D88 ] NAVEX15 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\VirusDefs\20121221.004\NAVEX15.SYS
21:35:43.0343 2968 NAVEX15 - ok
21:35:43.0437 2968 [ 4A9258B9597A31DB68EC9740F3A8A70B ] NCO C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSvcHst.exe
21:35:43.0453 2968 NCO - ok
21:35:43.0484 2968 [ 558635D3AF1C7546D26067D5D9B6959E ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
21:35:43.0640 2968 NDIS - ok
21:35:43.0671 2968 [ 08D43BBDACDF23F34D79E44ED35C1B4C ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
21:35:43.0843 2968 NdisTapi - ok
21:35:43.0921 2968 [ EEFA1CE63805D2145978621BE5C6D955 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
21:35:44.0015 2968 Ndisuio - ok
21:35:44.0062 2968 [ 0B90E255A9490166AB368CD55A529893 ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
21:35:44.0171 2968 NdisWan - ok
21:35:44.0187 2968 [ 59FC3FB44D2669BC144FD87826BB571F ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
21:35:44.0312 2968 NDProxy - ok
21:35:44.0343 2968 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
21:35:44.0468 2968 NetBIOS - ok
21:35:44.0500 2968 [ 0C80E410CD2F47134407EE7DD19CC86B ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
21:35:44.0625 2968 NetBT - ok
21:35:44.0718 2968 [ 05AFB5AD06462257BEA7495283C86D50 ] NetDDE C:\WINDOWS\system32\netdde.exe
21:35:44.0843 2968 NetDDE - ok
21:35:44.0859 2968 [ 05AFB5AD06462257BEA7495283C86D50 ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
21:35:44.0984 2968 NetDDEdsdm - ok
21:35:45.0015 2968 [ 84885F9B82F4D55C6146EBF6065D75D2 ] Netlogon C:\WINDOWS\system32\lsass.exe
21:35:45.0156 2968 Netlogon - ok
21:35:45.0203 2968 [ 3516D8A18B36784B1005B950B84232E1 ] Netman C:\WINDOWS\System32\netman.dll
21:35:45.0312 2968 Netman - ok
21:35:45.0515 2968 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
21:35:45.0531 2968 NetTcpPortSharing - ok
21:35:45.0687 2968 [ A9574F52E2FD5C1C1B4807A326E0488F ] NETw4x32 C:\WINDOWS\system32\DRIVERS\NETw4x32.sys
21:35:45.0796 2968 NETw4x32 - ok
21:35:45.0859 2968 [ E1532AD506E0E874D1E6B4581C4F64AE ] NIC1394 C:\WINDOWS\system32\DRIVERS\nic1394.sys
21:35:45.0921 2968 NIC1394 - ok
21:35:46.0000 2968 [ 4E74AF063C3271FBEA20DD940CFD1184 ] Nla C:\WINDOWS\System32\mswsock.dll
21:35:46.0140 2968 Nla - ok
21:35:46.0218 2968 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
21:35:46.0343 2968 Npfs - ok
21:35:46.0406 2968 [ 04E2D8D0DE4C76CEE33B7A7A0BCAF8C5 ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
21:35:46.0500 2968 Ntfs - ok
21:35:46.0515 2968 [ 84885F9B82F4D55C6146EBF6065D75D2 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
21:35:46.0640 2968 NtLmSsp - ok
21:35:46.0703 2968 [ B62F29C00AC55A761B2E45877D85EA0F ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
21:35:46.0843 2968 NtmsSvc - ok
21:35:46.0875 2968 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
21:35:47.0000 2968 Null - ok
21:35:47.0015 2968 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
21:35:47.0140 2968 NwlnkFlt - ok
21:35:47.0156 2968 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
21:35:47.0265 2968 NwlnkFwd - ok
21:35:47.0312 2968 [ FC128C3D7D5AD30A13742DC3737B9DF7 ] ohci1394 C:\WINDOWS\system32\DRIVERS\ohci1394.sys
21:35:47.0406 2968 ohci1394 - ok
21:35:47.0500 2968 [ 7A56CF3E3F12E8AF599963B16F50FB6A ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:35:47.0500 2968 ose - ok
21:35:47.0531 2968 [ 29744EB4CE659DFE3B4122DEB45BC478 ] Parport C:\WINDOWS\system32\drivers\Parport.sys
21:35:47.0656 2968 Parport - ok
21:35:47.0687 2968 [ 3334430C29DC338092F79C38EF7B4CD0 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
21:35:47.0796 2968 PartMgr - ok
21:35:47.0812 2968 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
21:35:47.0953 2968 ParVdm - ok
21:35:47.0984 2968 [ DE1D9A5D50166A6D8A51DAA936FC56A4 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
21:35:48.0031 2968 PCI - ok
21:35:48.0046 2968 PCIDump - ok
21:35:48.0078 2968 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
21:35:48.0203 2968 PCIIde - ok
21:35:48.0234 2968 [ 36458AB24389AF198194F73B9C6DB8FE ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
21:35:48.0343 2968 Pcmcia - ok
21:35:48.0343 2968 PDCOMP - ok
21:35:48.0343 2968 PDFRAME - ok
21:35:48.0359 2968 PDRELI - ok
21:35:48.0359 2968 PDRFRAME - ok
21:35:48.0375 2968 perc2 - ok
21:35:48.0375 2968 perc2hib - ok
21:35:48.0406 2968 [ C6CE6EEC82F187615D1002BB3BB50ED4 ] PlugPlay C:\WINDOWS\system32\services.exe
21:35:48.0531 2968 PlugPlay - ok
21:35:48.0546 2968 [ 84885F9B82F4D55C6146EBF6065D75D2 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
21:35:48.0671 2968 PolicyAgent - ok
21:35:48.0718 2968 [ 1C5CC65AAC0783C344F16353E60B72AC ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
21:35:49.0078 2968 PptpMiniport - ok
21:35:49.0078 2968 [ 84885F9B82F4D55C6146EBF6065D75D2 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
21:35:49.0203 2968 ProtectedStorage - ok
21:35:49.0296 2968 [ 48671F327553DCF1D27F6197F622A668 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
21:35:49.0437 2968 PSched - ok
21:35:49.0468 2968 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
21:35:49.0640 2968 Ptilink - ok
21:35:49.0640 2968 ql1080 - ok
21:35:49.0640 2968 Ql10wnt - ok
21:35:49.0656 2968 ql12160 - ok
21:35:49.0656 2968 ql1240 - ok
21:35:49.0656 2968 ql1280 - ok
21:35:49.0703 2968 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
21:35:49.0812 2968 RasAcd - ok
21:35:49.0921 2968 [ 44DB7A9BDD2FB58747D123FBF1D35ADB ] RasAuto C:\WINDOWS\System32\rasauto.dll
21:35:50.0046 2968 RasAuto - ok
21:35:50.0062 2968 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
21:35:50.0203 2968 Rasl2tp - ok
21:35:50.0250 2968 [ 41A3C11E3517C962C9B44893BCEC3B34 ] RasMan C:\WINDOWS\System32\rasmans.dll
21:35:50.0375 2968 RasMan - ok
21:35:50.0406 2968 [ 7306EEED8895454CBED4669BE9F79FAA ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
21:35:50.0515 2968 RasPppoe - ok
21:35:50.0593 2968 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
21:35:50.0718 2968 Raspti - ok
21:35:50.0812 2968 [ D0FEF8156D2D2FEC557C100956D76887 ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
21:35:50.0890 2968 Rdbss - ok
21:35:50.0921 2968 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
21:35:51.0046 2968 RDPCDD - ok
21:35:51.0093 2968 [ A2CAE2C60BC37E0751EF9DDA7CEAF4AD ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
21:35:51.0218 2968 rdpdr - ok
21:35:51.0328 2968 [ 047BEA21274C8A4A233674A76C958C2C ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
21:35:51.0406 2968 RDPWD - ok
21:35:51.0453 2968 [ 729798E0933076B8FCFCD9934698F164 ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
21:35:51.0578 2968 RDSessMgr - ok
21:35:51.0609 2968 [ B31B4588E4086D8D84ADBF9845C2402B ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
21:35:51.0734 2968 redbook - ok
21:35:51.0750 2968 [ 3046DB917E3CFA040632799DD9B14865 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
21:35:51.0890 2968 RemoteAccess - ok
21:35:51.0921 2968 [ 3151427DB7D87107D1C5BE58FAC53960 ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
21:35:52.0046 2968 RemoteRegistry - ok
21:35:52.0093 2968 [ 355AAC141B214BEF1DBC1483AFD9BD50 ] rimmptsk C:\WINDOWS\system32\DRIVERS\rimmptsk.sys
21:35:52.0125 2968 rimmptsk - ok
21:35:52.0156 2968 [ A4216C71DD4F60B26418CCFD99CD0815 ] rimsptsk C:\WINDOWS\system32\DRIVERS\rimsptsk.sys
21:35:52.0171 2968 rimsptsk - ok
21:35:52.0187 2968 [ D231B577024AA324AF13A42F3A807D10 ] rismxdp C:\WINDOWS\system32\DRIVERS\rixdptsk.sys
21:35:52.0234 2968 rismxdp - ok
21:35:52.0265 2968 [ 793F04A09B15E7C6C11DBDFFAF06C0AB ] RpcLocator C:\WINDOWS\system32\locator.exe
21:35:52.0390 2968 RpcLocator - ok
21:35:52.0453 2968 [ A4254FFC7B7894D118D8E6E57E34C660 ] RpcSs C:\WINDOWS\System32\rpcss.dll
21:35:52.0546 2968 RpcSs - ok
21:35:52.0562 2968 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
21:35:52.0687 2968 RSVP - ok
21:35:52.0703 2968 [ 84885F9B82F4D55C6146EBF6065D75D2 ] SamSs C:\WINDOWS\system32\lsass.exe
21:35:52.0828 2968 SamSs - ok
21:35:52.0859 2968 [ 25D8DE134DF108E3DBC8D7D23B1AA58E ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
21:35:52.0984 2968 SCardSvr - ok
21:35:53.0015 2968 [ 92360854316611F6CC471612213C3D92 ] Schedule C:\WINDOWS\system32\schedsvc.dll
21:35:53.0171 2968 Schedule - ok
21:35:53.0203 2968 [ D9561DDB3FD6BA04441266F1A42B344E ] sdbus C:\WINDOWS\system32\DRIVERS\sdbus.sys
21:35:53.0250 2968 sdbus - ok
21:35:53.0296 2968 [ 07F7F501AD50DE2BA2D5842D9B6D6155 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
21:35:53.0296 2968 Secdrv ( UnsignedFile.Multi.Generic ) - warning
21:35:53.0296 2968 Secdrv - detected UnsignedFile.Multi.Generic (1)
21:35:53.0343 2968 [ B1E0CE09895376871746F36DC5773B4F ] seclogon C:\WINDOWS\System32\seclogon.dll
21:35:53.0468 2968 seclogon - ok
21:35:53.0500 2968 [ DFD9870CF39C791D86C4C209DA9FA919 ] SENS C:\WINDOWS\system32\sens.dll
21:35:53.0625 2968 SENS - ok
21:35:53.0687 2968 [ CD9404D115A00D249F70A371B46D5A26 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
21:35:53.0828 2968 Serial - ok
21:35:53.0875 2968 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
21:35:53.0984 2968 Sfloppy - ok
21:35:54.0046 2968 [ 36CC8C01B5E50163037BEF56CB96DEFF ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
21:35:54.0171 2968 SharedAccess - ok
21:35:54.0203 2968 [ E7518DC542D3EBDCB80EDD98462C7821 ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
21:35:54.0328 2968 ShellHWDetection - ok
21:35:54.0343 2968 Simbad - ok
21:35:54.0359 2968 Sparrow - ok
21:35:54.0375 2968 [ 8E186B8F23295D1E42C573B82B80D548 ] splitter C:\WINDOWS\system32\drivers\splitter.sys
21:35:54.0500 2968 splitter - ok
21:35:54.0531 2968 [ AD3D9D191AEA7B5445FE1D82FFBB4788 ] Spooler C:\WINDOWS\system32\spoolsv.exe
21:35:54.0625 2968 Spooler - ok
21:35:54.0640 2968 [ E41B6D037D6CD08461470AF04500DC24 ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
21:35:54.0734 2968 sr - ok
21:35:54.0781 2968 [ 92BDF74F12D6CBEC43C94D4B7F804838 ] srservice C:\WINDOWS\system32\srsvc.dll
21:35:54.0843 2968 srservice - ok
21:35:54.0921 2968 [ 26C1B59C80FEF94B025DF5C3C1B791A7 ] SRTSP C:\WINDOWS\system32\drivers\NAV\1402000.013\SRTSP.SYS
21:35:54.0953 2968 SRTSP - ok
21:35:54.0984 2968 [ 21AC3AE81E8263061624C4ED3B11509A ] SRTSPX C:\WINDOWS\system32\drivers\NAV\1402000.013\SRTSPX.SYS
21:35:54.0984 2968 SRTSPX - ok
21:35:55.0046 2968 [ 54E79B08D0ABC9C551D0FE69CC2F87EC ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
21:35:55.0171 2968 Srv - ok
21:35:55.0218 2968 [ 4B8D61792F7175BED48859CC18CE4E38 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
21:35:55.0296 2968 SSDPSRV - ok
21:35:55.0343 2968 [ D9F6C4F6B1E188ADAFC42B561D9BC2E6 ] stisvc C:\WINDOWS\system32\wiaservc.dll
21:35:55.0468 2968 stisvc - ok
21:35:55.0500 2968 [ 03C1BAE4766E2450219D20B993D6E046 ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
21:35:55.0625 2968 swenum - ok
21:35:55.0671 2968 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
21:35:55.0781 2968 swmidi - ok
21:35:55.0828 2968 SwPrv - ok
21:35:55.0828 2968 symc810 - ok
21:35:55.0843 2968 symc8xx - ok
21:35:55.0890 2968 [ FB69A67FEEE3026C7F99774A1C405326 ] SymDS C:\WINDOWS\system32\drivers\NAV\1402000.013\SYMDS.SYS
21:35:55.0921 2968 SymDS - ok
21:35:55.0968 2968 [ 28C5FAFA7FD1C522B8DCD59694D39412 ] SymEFA C:\WINDOWS\system32\drivers\NAV\1402000.013\SYMEFA.SYS
21:35:56.0015 2968 SymEFA - ok
21:35:56.0046 2968 [ C940F10C31E2C60CC967FFD6A370720C ] SymEvent C:\WINDOWS\system32\Drivers\SYMEVENT.SYS
21:35:56.0062 2968 SymEvent - ok
21:35:56.0093 2968 [ 8C9B9036E301A9965CF15BEC91C58A12 ] SymIRON C:\WINDOWS\system32\drivers\NAV\1402000.013\Ironx86.SYS
21:35:56.0109 2968 SymIRON - ok
21:35:56.0156 2968 [ EC979002EBA25C9D109B2FE0E03457DA ] SYMTDI C:\WINDOWS\system32\drivers\NAV\1402000.013\SYMTDI.SYS
21:35:56.0171 2968 SYMTDI - ok
21:35:56.0187 2968 sym_hi - ok
21:35:56.0187 2968 sym_u3 - ok
21:35:56.0234 2968 [ 650AD082D46BAC0E64C9C0E0928492FD ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
21:35:56.0359 2968 sysaudio - ok
21:35:56.0453 2968 [ 8B54AA346D1B1B113FFAA75501B8B1B2 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
21:35:56.0578 2968 SysmonLog - ok
21:35:56.0625 2968 [ 1418A3A6E76E5A2E3F5E43866E793A8B ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
21:35:56.0718 2968 TapiSrv - ok
21:35:56.0765 2968 [ B51B0046D15982530AF09F3D01FF48AB ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
21:35:56.0890 2968 Tcpip - ok
21:35:57.0015 2968 [ 38D437CF2D98965F239B0ABCD66DCB0F ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
21:35:57.0125 2968 TDPIPE - ok
21:35:57.0140 2968 [ ED0580AF02502D00AD8C4C066B156BE9 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
21:35:57.0281 2968 TDTCP - ok
21:35:57.0296 2968 [ A540A99C281D933F3D69D55E48727F47 ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
21:35:57.0421 2968 TermDD - ok
21:35:57.0500 2968 [ C29A5286E64D97385178452D5F307B98 ] TermService C:\WINDOWS\System32\termsrv.dll
21:35:57.0593 2968 TermService - ok
21:35:57.0625 2968 [ E7518DC542D3EBDCB80EDD98462C7821 ] Themes C:\WINDOWS\System32\shsvcs.dll
21:35:57.0750 2968 Themes - ok
21:35:57.0781 2968 [ 37DB0A7D097310E8B4DE803FC3119C78 ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
21:35:57.0843 2968 TlntSvr - ok
21:35:57.0859 2968 TosIde - ok
21:35:57.0890 2968 [ 6D9AC544B30F96C57F8206566C1FB6A1 ] TrkWks C:\WINDOWS\system32\trkwks.dll
21:35:58.0015 2968 TrkWks - ok
21:35:58.0093 2968 [ 5468714EFDCC70E24981E5874B5A6CE5 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
21:35:58.0187 2968 Udfs - ok
21:35:58.0203 2968 ultra - ok
21:35:58.0234 2968 [ 9651E5D850B6F6BD7C77C70AA06F02BF ] UMWdf C:\WINDOWS\system32\wdfmgr.exe
21:35:58.0265 2968 UMWdf - ok
21:35:58.0312 2968 [ A4815A4884898F355A3513E60843A4FD ] Update C:\WINDOWS\system32\DRIVERS\update.sys
21:35:58.0375 2968 Update - ok
21:35:58.0421 2968 [ 0546477BDE979E33294FE97F6B3DE84A ] upnphost C:\WINDOWS\System32\upnphost.dll
21:35:58.0515 2968 upnphost - ok
21:35:58.0531 2968 [ 3F5DF65B0758675F95A2D43918A740A3 ] UPS C:\WINDOWS\System32\ups.exe
21:35:58.0671 2968 UPS - ok
21:35:58.0718 2968 [ DD0B8C7B96107CBF8F70201A6EF7156E ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
21:35:58.0828 2968 usbccgp - ok
21:35:58.0937 2968 [ 708579B01FED227AADB393CB0C3B4A2C ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
21:35:59.0093 2968 usbehci - ok
21:35:59.0125 2968 [ D31E07BF822C7F2BD32714E9DDCA8BE2 ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
21:35:59.0171 2968 usbhub - ok
21:35:59.0218 2968 [ A6BC71402F4F7DD5B77FD7F4A8DDBA85 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
21:35:59.0328 2968 usbscan - ok
21:35:59.0359 2968 [ D31343BC16E50AD3B639E7D8D2639816 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
21:35:59.0406 2968 usbstor - ok
21:35:59.0421 2968 [ F8FD1400092E23C8F2F31406EF06167B ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
21:35:59.0562 2968 usbuhci - ok
21:35:59.0578 2968 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
21:35:59.0703 2968 VgaSave - ok
21:35:59.0703 2968 ViaIde - ok
21:35:59.0734 2968 [ EE4660083DEBA849FF6C485D944B379B ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
21:35:59.0859 2968 VolSnap - ok
21:35:59.0890 2968 [ 3EE00364AE0FD8D604F46CBAF512838A ] VSS C:\WINDOWS\System32\vssvc.exe
21:35:59.0984 2968 VSS - ok
21:36:00.0031 2968 [ 2B281958F5D0CF99ED626E3EF39D5C8D ] W32Time C:\WINDOWS\system32\w32time.dll
21:36:00.0156 2968 W32Time - ok
21:36:00.0171 2968 [ 984EF0B9788ABF89974CFED4BFBAACBC ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
21:36:00.0296 2968 Wanarp - ok
21:36:00.0328 2968 [ D6EFAF429FD30C5DF613D220E344CCE7 ] WDC_SAM C:\WINDOWS\system32\DRIVERS\wdcsam.sys
21:36:00.0359 2968 WDC_SAM - ok
21:36:00.0421 2968 [ BBCFEAB7E871CDDAC2D397EE7FA91FDC ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys
21:36:00.0437 2968 Wdf01000 - ok
21:36:00.0453 2968 WDICA - ok
21:36:00.0484 2968 [ 2797F33EBF50466020C430EE4F037933 ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
21:36:00.0609 2968 wdmaud - ok
21:36:00.0640 2968 [ 5D0A442864BFBF3B19DCCA4CD29F6E99 ] WebClient C:\WINDOWS\System32\webclnt.dll
21:36:00.0750 2968 WebClient - ok
21:36:00.0812 2968 [ F399242A80C4066FD155EFA4CF96658E ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
21:36:00.0937 2968 winmgmt - ok
21:36:01.0062 2968 [ CD99C9FEAE87C1963273F6B150251E33 ] WMConnectCDS C:\Program Files\Windows Media Connect 2\wmccds.exe
21:36:01.0093 2968 WMConnectCDS ( UnsignedFile.Multi.Generic ) - warning
21:36:01.0093 2968 WMConnectCDS - detected UnsignedFile.Multi.Generic (1)
21:36:01.0171 2968 [ B9715B9C18BC6C8F4B66733D208CC9F7 ] WmdmPmSN C:\WINDOWS\system32\mspmsnsv.dll
21:36:01.0203 2968 WmdmPmSN - ok
21:36:01.0281 2968 [ 1AFF244CA134956C54474F4E2433E4CE ] Wmi C:\WINDOWS\System32\advapi32.dll
21:36:01.0421 2968 Wmi - ok
21:36:01.0437 2968 [ AE2C8544E747C20062DB27456EA2D67A ] WmiAcpi C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
21:36:01.0562 2968 WmiAcpi - ok
21:36:01.0609 2968 [ BA8CECC3E813E1F7C441B20393D4F86C ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
21:36:01.0734 2968 WmiApSrv - ok
21:36:01.0890 2968 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:36:01.0921 2968 WPFFontCache_v0400 - ok
21:36:01.0953 2968 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
21:36:02.0078 2968 WS2IFSL - ok
21:36:02.0125 2968 [ 478995B4555958E52388496618D9C678 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
21:36:02.0187 2968 wscsvc - ok
21:36:02.0234 2968 [ 0091D78C5F8FDE0CDF2B214823DE6E48 ] WSIMD C:\WINDOWS\system32\DRIVERS\wsimd.sys
21:36:02.0250 2968 WSIMD ( UnsignedFile.Multi.Generic ) - warning
21:36:02.0250 2968 WSIMD - detected UnsignedFile.Multi.Generic (1)
21:36:02.0296 2968 [ 13D72740963CBA12D9FF76A7F218BCD8 ] wuauserv C:\WINDOWS\system32\wuauserv.dll
21:36:02.0421 2968 wuauserv - ok
21:36:02.0468 2968 [ 23BB7F97459D674A68E74CE58482B1F0 ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
21:36:02.0609 2968 WZCSVC - ok
21:36:02.0640 2968 [ EEF46DAB68229A14DA3D8E73C99E2959 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
21:36:02.0765 2968 xmlprov - ok
21:36:02.0781 2968 ================ Scan global ===============================
21:36:02.0859 2968 [ 00EF9C3AF83EDBAF18CA7A2837750117 ] C:\WINDOWS\system32\basesrv.dll
21:36:02.0890 2968 [ 3642C99D14EC986DDE123C9D2846427D ] C:\WINDOWS\system32\winsrv.dll
21:36:02.0921 2968 [ 3642C99D14EC986DDE123C9D2846427D ] C:\WINDOWS\system32\winsrv.dll
21:36:02.0953 2968 [ C6CE6EEC82F187615D1002BB3BB50ED4 ] C:\WINDOWS\system32\services.exe
21:36:02.0953 2968 [Global] - ok
21:36:02.0953 2968 ================ Scan MBR ==================================
21:36:02.0968 2968 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
21:36:03.0265 2968 \Device\Harddisk0\DR0 - ok
21:36:03.0265 2968 ================ Scan VBR ==================================
21:36:03.0265 2968 [ 6E29C75B2CF04ED677FE7D82D255CFC8 ] \Device\Harddisk0\DR0\Partition1
21:36:03.0265 2968 \Device\Harddisk0\DR0\Partition1 - ok
21:36:03.0281 2968 [ 5BD4690EA1B2B9309B938B79C29EED17 ] \Device\Harddisk0\DR0\Partition2
21:36:03.0281 2968 \Device\Harddisk0\DR0\Partition2 - ok
21:36:03.0296 2968 [ 6E2A89ABF8A2CDFCB16BD1AC65A93A3A ] \Device\Harddisk0\DR0\Partition3
21:36:03.0296 2968 \Device\Harddisk0\DR0\Partition3 - ok
21:36:03.0312 2968 [ 363F307AD91C9DD93F99A303EF1EE047 ] \Device\Harddisk0\DR0\Partition4
21:36:03.0312 2968 \Device\Harddisk0\DR0\Partition4 - ok
21:36:03.0312 2968 ================ Scan active images ========================
21:36:03.0328 2968 [ DB8A1859CF9E48914DCC0A7206D87BE5 ] C:\WINDOWS\System32\drivers\INTELPPM.SYS
21:36:03.0328 2968 C:\WINDOWS\System32\drivers\INTELPPM.SYS - ok
21:36:03.0328 2968 [ AE2C8544E747C20062DB27456EA2D67A ] C:\WINDOWS\System32\drivers\WMIACPI.SYS
21:36:03.0328 2968 C:\WINDOWS\System32\drivers\WMIACPI.SYS - ok
21:36:03.0328 2968 [ D5A9D123F5ED7C9965A481BD20CF66D8 ] C:\WINDOWS\System32\drivers\VIDEOPRT.SYS
21:36:03.0328 2968 C:\WINDOWS\System32\drivers\VIDEOPRT.SYS - ok
21:36:03.0343 2968 [ BFFA387180121DF1E4646C4CED3E16CA ] C:\WINDOWS\System32\drivers\IGXPMP32.SYS
21:36:03.0343 2968 C:\WINDOWS\System32\drivers\IGXPMP32.SYS - ok
21:36:03.0343 2968 [ A6DF50BA7534B13C5A34D0D22CFEBE0C ] C:\WINDOWS\System32\drivers\USBPORT.SYS
21:36:03.0343 2968 C:\WINDOWS\System32\drivers\USBPORT.SYS - ok
21:36:03.0359 2968 [ F8FD1400092E23C8F2F31406EF06167B ] C:\WINDOWS\System32\drivers\USBUHCI.SYS
21:36:03.0359 2968 C:\WINDOWS\System32\drivers\USBUHCI.SYS - ok
21:36:03.0359 2968 [ 708579B01FED227AADB393CB0C3B4A2C ] C:\WINDOWS\System32\drivers\USBEHCI.SYS
21:36:03.0359 2968 C:\WINDOWS\System32\drivers\USBEHCI.SYS - ok
21:36:03.0359 2968 [ 3FCC124B6E08EE0E9351F717DD136939 ] C:\WINDOWS\System32\drivers\HDAUDBUS.SYS
21:36:03.0359 2968 C:\WINDOWS\System32\drivers\HDAUDBUS.SYS - ok
21:36:03.0375 2968 [ A9574F52E2FD5C1C1B4807A326E0488F ] C:\WINDOWS\System32\drivers\NETw4x32.sys
21:36:03.0375 2968 C:\WINDOWS\System32\drivers\NETw4x32.sys - ok
21:36:03.0375 2968 [ F96038AA1EC4013A93D2420FC689D1E9 ] C:\WINDOWS\System32\drivers\B57XP32.SYS
21:36:03.0375 2968 C:\WINDOWS\System32\drivers\B57XP32.SYS - ok
21:36:03.0390 2968 [ E1532AD506E0E874D1E6B4581C4F64AE ] C:\WINDOWS\System32\drivers\NIC1394.SYS
21:36:03.0390 2968 C:\WINDOWS\System32\drivers\NIC1394.SYS - ok
21:36:03.0390 2968 [ D9561DDB3FD6BA04441266F1A42B344E ] C:\WINDOWS\System32\drivers\SDBUS.SYS
21:36:03.0390 2968 C:\WINDOWS\System32\drivers\SDBUS.SYS - ok
21:36:03.0390 2968 [ 4266BE808F85826AEDF3C64C1E240203 ] C:\WINDOWS\System32\drivers\CmBatt.sys
21:36:03.0390 2968 C:\WINDOWS\System32\drivers\CmBatt.sys - ok
21:36:03.0406 2968 [ 355AAC141B214BEF1DBC1483AFD9BD50 ] C:\WINDOWS\System32\drivers\RIMMPTSK.SYS
21:36:03.0406 2968 C:\WINDOWS\System32\drivers\RIMMPTSK.SYS - ok
21:36:03.0406 2968 [ A4216C71DD4F60B26418CCFD99CD0815 ] C:\WINDOWS\System32\drivers\RIMSPTSK.SYS
21:36:03.0406 2968 C:\WINDOWS\System32\drivers\RIMSPTSK.SYS - ok
21:36:03.0421 2968 [ D231B577024AA324AF13A42F3A807D10 ] C:\WINDOWS\System32\drivers\RIXDPTSK.SYS
21:36:03.0421 2968 C:\WINDOWS\System32\drivers\RIXDPTSK.SYS - ok
21:36:03.0421 2968 [ D6F2A9900D295C08FBEF217AB50226A8 ] C:\WINDOWS\System32\drivers\AcpiVpc.sys
21:36:03.0421 2968 C:\WINDOWS\System32\drivers\AcpiVpc.sys - ok
21:36:03.0437 2968 [ 5502B58EEF7486EE6F93F3F164DCB808 ] C:\WINDOWS\System32\drivers\I8042PRT.SYS
21:36:03.0437 2968 C:\WINDOWS\System32\drivers\I8042PRT.SYS - ok
21:36:03.0437 2968 [ 32273CD4CDF7ECB186EC1849EB232A63 ] C:\WINDOWS\System32\drivers\DKbFltr.SYS
21:36:03.0437 2968 C:\WINDOWS\System32\drivers\DKbFltr.SYS - ok
21:36:03.0437 2968 [ EBDEE8A2EE5393890A1ACEE971C4C246 ] C:\WINDOWS\System32\drivers\KBDCLASS.SYS
21:36:03.0437 2968 C:\WINDOWS\System32\drivers\KBDCLASS.SYS - ok
21:36:03.0453 2968 [ 3B72E032779042953BD2B1B4B02F7BC0 ] C:\WINDOWS\System32\drivers\Apfiltr.sys
21:36:03.0453 2968 C:\WINDOWS\System32\drivers\Apfiltr.sys - ok
21:36:03.0453 2968 [ 34E1F0031153E491910E12551400192C ] C:\WINDOWS\System32\drivers\MOUCLASS.SYS
21:36:03.0453 2968 C:\WINDOWS\System32\drivers\MOUCLASS.SYS - ok
21:36:03.0468 2968 [ AD5E8A6C823F24882A6826D7DBCCF4A3 ] C:\WINDOWS\System32\drivers\IMAPI.SYS
21:36:03.0468 2968 C:\WINDOWS\System32\drivers\IMAPI.SYS - ok
21:36:03.0468 2968 [ AF9C19B3100FE010496B1A27181FBF72 ] C:\WINDOWS\System32\drivers\CDROM.SYS
21:36:03.0468 2968 C:\WINDOWS\System32\drivers\CDROM.SYS - ok
21:36:03.0468 2968 [ B9540E258F952650DE8DEC68719A5C97 ] C:\WINDOWS\System32\drivers\KS.SYS
21:36:03.0468 2968 C:\WINDOWS\System32\drivers\KS.SYS - ok
21:36:03.0484 2968 [ B31B4588E4086D8D84ADBF9845C2402B ] C:\WINDOWS\System32\drivers\REDBOOK.SYS
21:36:03.0484 2968 C:\WINDOWS\System32\drivers\REDBOOK.SYS - ok
21:36:03.0484 2968 [ D84166D41A05F66D9084039427E5025B ] C:\WINDOWS\System32\drivers\BTKRNL.SYS
21:36:03.0484 2968 C:\WINDOWS\System32\drivers\BTKRNL.SYS - ok
21:36:03.0500 2968 [ AD67795900AA8C05CC4570F5349E0639 ] C:\WINDOWS\System32\drivers\JSWSCIMD.SYS
21:36:03.0500 2968 C:\WINDOWS\System32\drivers\JSWSCIMD.SYS - ok
21:36:03.0500 2968 [ D9F724AA26C010A217C97606B160ED68 ] C:\WINDOWS\System32\drivers\AUDSTUB.SYS
21:36:03.0500 2968 C:\WINDOWS\System32\drivers\AUDSTUB.SYS - ok
21:36:03.0515 2968 [ 98FAEB4A4DCF812BA1C6FCA4AA3E115C ] C:\WINDOWS\System32\drivers\RASL2TP.SYS
21:36:03.0515 2968 C:\WINDOWS\System32\drivers\RASL2TP.SYS - ok
21:36:03.0515 2968 [ 08D43BBDACDF23F34D79E44ED35C1B4C ] C:\WINDOWS\System32\drivers\NDISTAPI.SYS
21:36:03.0515 2968 C:\WINDOWS\System32\drivers\NDISTAPI.SYS - ok
21:36:03.0515 2968 [ 0B90E255A9490166AB368CD55A529893 ] C:\WINDOWS\System32\drivers\NDISWAN.SYS
21:36:03.0515 2968 C:\WINDOWS\System32\drivers\NDISWAN.SYS - ok
21:36:03.0531 2968 [ 7306EEED8895454CBED4669BE9F79FAA ] C:\WINDOWS\System32\drivers\RASPPPOE.SYS
21:36:03.0531 2968 C:\WINDOWS\System32\drivers\RASPPPOE.SYS - ok
21:36:03.0531 2968 [ 6891B74AB9A016064E82A419388D0601 ] C:\WINDOWS\System32\drivers\TDI.SYS
21:36:03.0531 2968 C:\WINDOWS\System32\drivers\TDI.SYS - ok
21:36:03.0546 2968 [ 48671F327553DCF1D27F6197F622A668 ] C:\WINDOWS\System32\drivers\PSCHED.SYS
21:36:03.0546 2968 C:\WINDOWS\System32\drivers\PSCHED.SYS - ok
21:36:03.0546 2968 [ 1C5CC65AAC0783C344F16353E60B72AC ] C:\WINDOWS\System32\drivers\RASPPTP.SYS
21:36:03.0546 2968 C:\WINDOWS\System32\drivers\RASPPTP.SYS - ok
21:36:03.0546 2968 [ C0F1D4A21DE5A415DF8170616703DEBF ] C:\WINDOWS\System32\drivers\MSGPC.SYS
21:36:03.0546 2968 C:\WINDOWS\System32\drivers\MSGPC.SYS - ok
21:36:03.0562 2968 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] C:\WINDOWS\System32\drivers\PTILINK.SYS
21:36:03.0562 2968 C:\WINDOWS\System32\drivers\PTILINK.SYS - ok
21:36:03.0562 2968 [ FDBB1D60066FCFBB7452FD8F9829B242 ] C:\WINDOWS\System32\drivers\RASPTI.SYS
21:36:03.0562 2968 C:\WINDOWS\System32\drivers\RASPTI.SYS - ok
21:36:03.0578 2968 [ A2CAE2C60BC37E0751EF9DDA7CEAF4AD ] C:\WINDOWS\System32\drivers\RDPDR.SYS
21:36:03.0578 2968 C:\WINDOWS\System32\drivers\RDPDR.SYS - ok
21:36:03.0578 2968 [ A540A99C281D933F3D69D55E48727F47 ] C:\WINDOWS\System32\drivers\TERMDD.SYS
21:36:03.0578 2968 C:\WINDOWS\System32\drivers\TERMDD.SYS - ok
21:36:03.0593 2968 [ 03C1BAE4766E2450219D20B993D6E046 ] C:\WINDOWS\System32\drivers\SWENUM.SYS
21:36:03.0593 2968 C:\WINDOWS\System32\drivers\SWENUM.SYS - ok
21:36:03.0593 2968 [ A4815A4884898F355A3513E60843A4FD ] C:\WINDOWS\System32\drivers\UPDATE.SYS
21:36:03.0593 2968 C:\WINDOWS\System32\drivers\UPDATE.SYS - ok
21:36:03.0593 2968 [ 469541F8BFD2B32659D5D463A6714BCE ] C:\WINDOWS\System32\drivers\MSSMBIOS.SYS
21:36:03.0593 2968 C:\WINDOWS\System32\drivers\MSSMBIOS.SYS - ok
21:36:03.0609 2968 [ F44461E66F1B7DD267957FE9BAA63ED0 ] C:\WINDOWS\System32\drivers\ew_jubusenum.sys
21:36:03.0609 2968 C:\WINDOWS\System32\drivers\ew_jubusenum.sys - ok
21:36:03.0609 2968 [ 6AA8BB224B30A20A5D07A2734568D6D7 ] C:\WINDOWS\System32\drivers\WDFLDR.SYS
21:36:03.0609 2968 C:\WINDOWS\System32\drivers\WDFLDR.SYS - ok
21:36:03.0625 2968 [ BBCFEAB7E871CDDAC2D397EE7FA91FDC ] C:\WINDOWS\System32\drivers\WDF01000.SYS
21:36:03.0625 2968 C:\WINDOWS\System32\drivers\WDF01000.SYS - ok
21:36:03.0625 2968 [ 0091D78C5F8FDE0CDF2B214823DE6E48 ] C:\WINDOWS\System32\drivers\WSIMD.SYS
21:36:03.0625 2968 C:\WINDOWS\System32\drivers\WSIMD.SYS - ok
21:36:03.0625 2968 [ 59FC3FB44D2669BC144FD87826BB571F ] C:\WINDOWS\System32\drivers\NDPROXY.SYS
21:36:03.0625 2968 C:\WINDOWS\System32\drivers\NDPROXY.SYS - ok
21:36:03.0640 2968 [ 596EB39B50D6EBD9B734DC4AE0544693 ] C:\WINDOWS\System32\drivers\USBD.SYS
21:36:03.0640 2968 C:\WINDOWS\System32\drivers\USBD.SYS - ok
21:36:03.0640 2968 [ D31E07BF822C7F2BD32714E9DDCA8BE2 ] C:\WINDOWS\System32\drivers\USBHUB.SYS
21:36:03.0640 2968 C:\WINDOWS\System32\drivers\USBHUB.SYS - ok
21:36:03.0656 2968 [ FF86422268DE771D571E123EB7092C6A ] C:\WINDOWS\System32\drivers\DRMK.SYS
21:36:03.0656 2968 C:\WINDOWS\System32\drivers\DRMK.SYS - ok
21:36:03.0656 2968 [ 580D49724DCD58D56F09CDD367DCB669 ] C:\WINDOWS\System32\drivers\PORTCLS.SYS
21:36:03.0656 2968 C:\WINDOWS\System32\drivers\PORTCLS.SYS - ok
21:36:03.0671 2968 [ 274FF777C369CC8F05A4B4F9A243335B ] C:\WINDOWS\System32\drivers\RtkHDAud.sys
21:36:03.0671 2968 C:\WINDOWS\System32\drivers\RtkHDAud.sys - ok
21:36:03.0671 2968 [ CED2E8396A8838E59D8FD529C680E02C ] C:\WINDOWS\System32\drivers\FDC.SYS
21:36:03.0671 2968 C:\WINDOWS\System32\drivers\FDC.SYS - ok
21:36:03.0671 2968 [ 0DD1DE43115B93F4D85E889D7A86F548 ] C:\WINDOWS\System32\drivers\FLPYDISK.SYS
21:36:03.0671 2968 C:\WINDOWS\System32\drivers\FLPYDISK.SYS - ok
21:36:03.0687 2968 [ 0D13B6DF6E9E101013A7AFB0CE629FE0 ] C:\WINDOWS\System32\drivers\SFLOPPY.SYS
21:36:03.0687 2968 C:\WINDOWS\System32\drivers\SFLOPPY.SYS - ok
21:36:03.0687 2968 [ 1277AD8F053CC60C17CAFAB411F3CF40 ] C:\WINDOWS\System32\drivers\NAV\1402000.013\ccSetx86.sys
21:36:03.0687 2968 C:\WINDOWS\System32\drivers\NAV\1402000.013\ccSetx86.sys - ok
21:36:03.0703 2968 [ 8C9B9036E301A9965CF15BEC91C58A12 ] C:\WINDOWS\System32\drivers\NAV\1402000.013\Ironx86.sys
21:36:03.0703 2968 C:\WINDOWS\System32\drivers\NAV\1402000.013\Ironx86.sys - ok
21:36:03.0703 2968 [ 1277AD8F053CC60C17CAFAB411F3CF40 ] C:\WINDOWS\System32\drivers\NST\7DD02000.012\ccSetx86.sys
21:36:03.0703 2968 C:\WINDOWS\System32\drivers\NST\7DD02000.012\ccSetx86.sys - ok
21:36:03.0718 2968 [ C1B486A7658353D33A10CC15211A873B ] C:\WINDOWS\System32\drivers\CDAUDIO.SYS
21:36:03.0718 2968 C:\WINDOWS\System32\drivers\CDAUDIO.SYS - ok
21:36:03.0718 2968 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] C:\WINDOWS\System32\drivers\FS_REC.SYS
21:36:03.0718 2968 C:\WINDOWS\System32\drivers\FS_REC.SYS - ok
21:36:03.0718 2968 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] C:\WINDOWS\System32\drivers\NULL.SYS
21:36:03.0718 2968 C:\WINDOWS\System32\drivers\NULL.SYS - ok
21:36:03.0734 2968 [ DA1F27D85E0D1525F6621372E7B685E9 ] C:\WINDOWS\System32\drivers\BEEP.SYS
21:36:03.0734 2968 C:\WINDOWS\System32\drivers\BEEP.SYS - ok
21:36:03.0734 2968 [ 8A60EDD72B4EA5AEA8202DAF0E427925 ] C:\WINDOWS\System32\drivers\VGA.SYS
21:36:03.0734 2968 C:\WINDOWS\System32\drivers\VGA.SYS - ok
21:36:03.0750 2968 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] C:\WINDOWS\System32\drivers\MNMDD.SYS
21:36:03.0750 2968 C:\WINDOWS\System32\drivers\MNMDD.SYS - ok
21:36:03.0750 2968 [ 4912D5B403614CE99C28420F75353332 ] C:\WINDOWS\System32\drivers\RDPCDD.SYS
21:36:03.0750 2968 C:\WINDOWS\System32\drivers\RDPCDD.SYS - ok
21:36:03.0765 2968 [ 561B3A4333CA2DBDBA28B5B956822519 ] C:\WINDOWS\System32\drivers\MSFS.SYS
21:36:03.0765 2968 C:\WINDOWS\System32\drivers\MSFS.SYS - ok
21:36:03.0765 2968 [ 4F601BCB8F64EA3AC0994F98FED03F8E ] C:\WINDOWS\System32\drivers\NPFS.SYS
21:36:03.0765 2968 C:\WINDOWS\System32\drivers\NPFS.SYS - ok
21:36:03.0765 2968 [ FE0D99D6F31E4FAD8159F690D68DED9C ] C:\WINDOWS\System32\drivers\RASACD.SYS
21:36:03.0765 2968 C:\WINDOWS\System32\drivers\RASACD.SYS - ok
21:36:03.0781 2968 [ 64537AA5C003A6AFEEE1DF819062D0D1 ] C:\WINDOWS\System32\drivers\IPSEC.SYS
21:36:03.0781 2968 C:\WINDOWS\System32\drivers\IPSEC.SYS - ok
21:36:03.0781 2968 [ B51B0046D15982530AF09F3D01FF48AB ] C:\WINDOWS\System32\drivers\TCPIP.SYS
21:36:03.0781 2968 C:\WINDOWS\System32\drivers\TCPIP.SYS - ok
21:36:03.0796 2968 [ D58ECD3B3969A670E68588F1640920B6 ] C:\WINDOWS\System32\drivers\IPNAT.SYS
21:36:03.0796 2968 C:\WINDOWS\System32\drivers\IPNAT.SYS - ok
21:36:03.0796 2968 [ EC979002EBA25C9D109B2FE0E03457DA ] C:\WINDOWS\System32\drivers\NAV\1402000.013\SYMTDI.SYS
21:36:03.0796 2968 C:\WINDOWS\System32\drivers\NAV\1402000.013\SYMTDI.SYS - ok
21:36:03.0812 2968 [ C940F10C31E2C60CC967FFD6A370720C ] C:\WINDOWS\System32\drivers\SYMEVENT.SYS
21:36:03.0812 2968 C:\WINDOWS\System32\drivers\SYMEVENT.SYS - ok
21:36:03.0812 2968 [ C19BF2A07BE972A110220DF6B1E89D14 ] C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20121220.001\IDSXpx86.sys
21:36:03.0812 2968 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\IPSDefs\20121220.001\IDSXpx86.sys - ok
21:36:03.0812 2968 [ 0C80E410CD2F47134407EE7DD19CC86B ] C:\WINDOWS\System32\drivers\NETBT.SYS
21:36:03.0812 2968 C:\WINDOWS\System32\drivers\NETBT.SYS - ok
21:36:03.0828 2968 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] C:\WINDOWS\System32\drivers\WS2IFSL.SYS
21:36:03.0828 2968 C:\WINDOWS\System32\drivers\WS2IFSL.SYS - ok
21:36:03.0828 2968 [ 5AC495F4CB807B2B98AD2AD591E6D92E ] C:\WINDOWS\System32\drivers\AFD.SYS
21:36:03.0828 2968 C:\WINDOWS\System32\drivers\AFD.SYS - ok
21:36:03.0843 2968 [ 3A2ACA8FC1D7786902CA434998D7CEB4 ] C:\WINDOWS\System32\drivers\NETBIOS.SYS
21:36:03.0843 2968 C:\WINDOWS\System32\drivers\NETBIOS.SYS - ok
21:36:03.0843 2968 [ 21AC3AE81E8263061624C4ED3B11509A ] C:\WINDOWS\System32\drivers\NAV\1402000.013\SRTSPX.SYS
21:36:03.0843 2968 C:\WINDOWS\System32\drivers\NAV\1402000.013\SRTSPX.SYS - ok
21:36:03.0859 2968 [ D0FEF8156D2D2FEC557C100956D76887 ] C:\WINDOWS\System32\drivers\RDBSS.SYS
21:36:03.0859 2968 C:\WINDOWS\System32\drivers\RDBSS.SYS - ok
21:36:03.0859 2968 [ F6BFAE0CC79784D0A72DF6684C173437 ] C:\WINDOWS\System32\drivers\MRXSMB.SYS
21:36:03.0859 2968 C:\WINDOWS\System32\drivers\MRXSMB.SYS - ok
21:36:03.0875 2968 [ E153AB8A11DE5452BCF5AC7652DBF3ED ] C:\WINDOWS\System32\drivers\FIPS.SYS
21:36:03.0875 2968 C:\WINDOWS\System32\drivers\FIPS.SYS - ok
21:36:03.0875 2968 [ 85B8B4032A895A746D46A288A9B30DED ] C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
21:36:03.0875 2968 C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys - ok
21:36:03.0875 2968 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
21:36:03.0875 2968 C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys - ok
21:36:03.0890 2968 [ 9DFFCB249663AA3C2ECB67202280054E ] C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20121130.005\BHDrvx86.sys
21:36:03.0890 2968 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20121130.005\BHDrvx86.sys - ok
21:36:03.0890 2968 [ BB5CBFFC096497506167BCE1D9690EF2 ] C:\WINDOWS\System32\ntdll.dll
21:36:03.0890 2968 C:\WINDOWS\System32\ntdll.dll - ok
21:36:03.0906 2968 [ BD7FB0957C716F1A60333AEE04DE2178 ] C:\WINDOWS\System32\SMSS.EXE
21:36:03.0906 2968 C:\WINDOWS\System32\SMSS.EXE - ok
21:36:03.0906 2968 [ B3415B9D6026F65E43089ABED096C38C ] C:\WINDOWS\System32\AUTOCHK.EXE
21:36:03.0906 2968 C:\WINDOWS\System32\AUTOCHK.EXE - ok
21:36:03.0921 2968 [ 04E2D8D0DE4C76CEE33B7A7A0BCAF8C5 ] C:\WINDOWS\System32\drivers\NTFS.SYS
21:36:03.0921 2968 C:\WINDOWS\System32\drivers\NTFS.SYS - ok
21:36:03.0921 2968 [ A01FD9851406DE0870C23759E2F7B6EA ] C:\WINDOWS\System32\drivers\BTWUSB.SYS
21:36:03.0921 2968 C:\WINDOWS\System32\drivers\BTWUSB.SYS - ok
21:36:03.0921 2968 [ 984EF0B9788ABF89974CFED4BFBAACBC ] C:\WINDOWS\System32\drivers\WANARP.SYS
21:36:03.0921 2968 C:\WINDOWS\System32\drivers\WANARP.SYS - ok
21:36:03.0937 2968 [ F0D692B0BFFB46E30EB3CEA168BBC49F ] C:\WINDOWS\System32\drivers\ARP1394.SYS
21:36:03.0937 2968 C:\WINDOWS\System32\drivers\ARP1394.SYS - ok
21:36:03.0937 2968 [ 30A609E00BD1D4FFC49D6B5A432BE7F2 ] C:\WINDOWS\System32\SFCFILES.DLL
21:36:03.0937 2968 C:\WINDOWS\System32\SFCFILES.DLL - ok
21:36:03.0953 2968 [ CD7D5152DF32B47F4E36F710B35AAE02 ] C:\WINDOWS\System32\drivers\CDFS.SYS
21:36:03.0953 2968 C:\WINDOWS\System32\drivers\CDFS.SYS - ok
21:36:03.0953 2968 [ 2F31B7F954BED437F2C75026C65CAF7B ] C:\WINDOWS\System32\drivers\WMILIB.SYS
21:36:03.0953 2968 C:\WINDOWS\System32\drivers\WMILIB.SYS - ok
21:36:03.0953 2968 [ C4B52426B79C6F6664B70B8E63B1B837 ] C:\WINDOWS\System32\drivers\ATAPI.SYS
21:36:03.0953 2968 C:\WINDOWS\System32\drivers\ATAPI.SYS - ok
21:36:03.0968 2968 [ FE97D0343ACFDEBDD578FC67CC91FA87 ] C:\WINDOWS\System32\drivers\DXAPI.SYS
21:36:03.0968 2968 C:\WINDOWS\System32\drivers\DXAPI.SYS - ok
21:36:03.0968 2968 [ C9BF2F12C4E6C12F8A85FBA4B6BC6208 ] C:\WINDOWS\System32\WATCHDOG.SYS
21:36:03.0968 2968 C:\WINDOWS\System32\WATCHDOG.SYS - ok
21:36:03.0984 2968 [ 98D0393AEBA65F52FE5B66845C5F3A6A ] C:\WINDOWS\System32\WIN32K.SYS
21:36:03.0984 2968 C:\WINDOWS\System32\WIN32K.SYS - ok
21:36:03.0984 2968 [ F12B178B1678D778CFD3FF1FC38C71FB ] C:\WINDOWS\System32\CSRSS.EXE
21:36:03.0984 2968 C:\WINDOWS\System32\CSRSS.EXE - ok
21:36:03.0984 2968 [ 00EF9C3AF83EDBAF18CA7A2837750117 ] C:\WINDOWS\System32\BASESRV.DLL
21:36:03.0984 2968 C:\WINDOWS\System32\BASESRV.DLL - ok
21:36:04.0000 2968 [ D06EAA8B23BC1F671B11D18CFEA65115 ] C:\WINDOWS\System32\CSRSRV.DLL
21:36:04.0000 2968 C:\WINDOWS\System32\CSRSRV.DLL - ok
21:36:04.0000 2968 [ 3642C99D14EC986DDE123C9D2846427D ] C:\WINDOWS\System32\WINSRV.DLL
21:36:04.0000 2968 C:\WINDOWS\System32\WINSRV.DLL - ok
21:36:04.0015 2968 [ FEC4F1A72629C67EEA37D9E25384A2F9 ] C:\WINDOWS\System32\GDI32.DLL
21:36:04.0015 2968 C:\WINDOWS\System32\GDI32.DLL - ok
21:36:04.0015 2968 [ 7CAE94A8F0B4648EE2B2398308B9782E ] C:\WINDOWS\System32\KERNEL32.DLL
21:36:04.0015 2968 C:\WINDOWS\System32\KERNEL32.DLL - ok
21:36:04.0015 2968 [ 1800F293BCCC8EDE8A70E12B88D80036 ] C:\WINDOWS\System32\USER32.DLL
21:36:04.0015 2968 C:\WINDOWS\System32\USER32.DLL - ok
21:36:04.0031 2968 [ 74D66B3DE265E8789153414E75175F26 ] C:\WINDOWS\System32\LPK.DLL
21:36:04.0031 2968 C:\WINDOWS\System32\LPK.DLL - ok
21:36:04.0031 2968 [ 2547D2CF090AC7636898F16957EBCEDC ] C:\WINDOWS\System32\USP10.DLL
21:36:04.0031 2968 C:\WINDOWS\System32\USP10.DLL - ok
21:36:04.0046 2968 [ B0FEFA816D61EC66AA765DDF534EAB5E ] C:\WINDOWS\System32\MSVCRT.DLL
21:36:04.0046 2968 C:\WINDOWS\System32\MSVCRT.DLL - ok
21:36:04.0046 2968 [ 1AFF244CA134956C54474F4E2433E4CE ] C:\WINDOWS\System32\ADVAPI32.DLL
21:36:04.0046 2968 C:\WINDOWS\System32\ADVAPI32.DLL - ok
21:36:04.0046 2968 [ E734259698D7B0097F201ECA44B0CC5C ] C:\WINDOWS\System32\RPCRT4.DLL
21:36:04.0046 2968 C:\WINDOWS\System32\RPCRT4.DLL - ok
21:36:04.0062 2968 [ D3DAC8432110AAD0B02A58B4459AB835 ] C:\WINDOWS\System32\drivers\DXG.SYS
21:36:04.0062 2968 C:\WINDOWS\System32\drivers\DXG.SYS - ok
21:36:04.0062 2968 [ A73F5D6705B1D820C19B18782E176EFD ] C:\WINDOWS\System32\drivers\DXGTHK.SYS
21:36:04.0062 2968 C:\WINDOWS\System32\drivers\DXGTHK.SYS - ok
21:36:04.0078 2968 [ 80A33FB42AA778184DCE02D40E191F1E ] C:\WINDOWS\System32\IGXPGD32.DLL
21:36:04.0078 2968 C:\WINDOWS\System32\IGXPGD32.DLL - ok
21:36:04.0078 2968 [ DDF63B49DDF6116D0A5A066684ADC5CD ] C:\WINDOWS\System32\IGXPRD32.DLL
21:36:04.0078 2968 C:\WINDOWS\System32\IGXPRD32.DLL - ok
21:36:04.0078 2968 [ ECB7591870F8BFB1A4C17B718AD5A4AA ] C:\WINDOWS\System32\VGA.DLL
21:36:04.0078 2968 C:\WINDOWS\System32\VGA.DLL - ok
21:36:04.0093 2968 [ B0E690AAD95B52812394889432BF43CF ] C:\WINDOWS\System32\IGXPDV32.DLL
21:36:04.0093 2968 C:\WINDOWS\System32\IGXPDV32.DLL - ok
21:36:04.0093 2968 [ D8F51918D985AEAC22F46E994B56E639 ] C:\WINDOWS\System32\IGXPDX32.DLL
21:36:04.0093 2968 C:\WINDOWS\System32\IGXPDX32.DLL - ok
21:36:04.0109 2968 [ 01C3346C241652F43AED8E2149881BFE ] C:\WINDOWS\System32\WINLOGON.EXE
21:36:04.0109 2968 C:\WINDOWS\System32\WINLOGON.EXE - ok
21:36:04.0109 2968 [ 7EEDFDDC9DE2F088BD159DDC8180A813 ] C:\WINDOWS\System32\AUTHZ.DLL
21:36:04.0109 2968 C:\WINDOWS\System32\AUTHZ.DLL - ok
21:36:04.0109 2968 [ EFC958396A7A7EF7E6D4A52B97512E18 ] C:\WINDOWS\System32\CRYPT32.DLL
21:36:04.0109 2968 C:\WINDOWS\System32\CRYPT32.DLL - ok
21:36:04.0125 2968 [ 3CD1CE106CA2A9B4CC626D7DF03FBD6F ] C:\WINDOWS\System32\MSASN1.DLL
21:36:04.0125 2968 C:\WINDOWS\System32\MSASN1.DLL - ok
21:36:04.0125 2968 [ 458AB591E8CF240CC105A23671F2C3D6 ] C:\WINDOWS\System32\NDDEAPI.DLL
21:36:04.0125 2968 C:\WINDOWS\System32\NDDEAPI.DLL - ok
21:36:04.0140 2968 [ FE4F71711CF5C17ADE5E506348132D24 ] C:\WINDOWS\System32\PROFMAP.DLL
21:36:04.0140 2968 C:\WINDOWS\System32\PROFMAP.DLL - ok
21:36:04.0140 2968 [ 2695631601EA11BE0C2367AABFC9F2FD ] C:\WINDOWS\System32\NETAPI32.DLL
21:36:04.0140 2968 C:\WINDOWS\System32\NETAPI32.DLL - ok
21:36:04.0140 2968 [ 2B9B56A89A8A42E917511972A6DB36E3 ] C:\WINDOWS\System32\USERENV.DLL
21:36:04.0140 2968 C:\WINDOWS\System32\USERENV.DLL - ok
21:36:04.0156 2968 [ 96E48C7EB9089D1DBF6F85CA11B264DF ] C:\WINDOWS\System32\PSAPI.DLL
21:36:04.0156 2968 C:\WINDOWS\System32\PSAPI.DLL - ok
21:36:04.0156 2968 [ 899ED710FDC37EB7D0115C2932C2B1EB ] C:\WINDOWS\System32\REGAPI.DLL
21:36:04.0156 2968 C:\WINDOWS\System32\REGAPI.DLL - ok
21:36:04.0171 2968 [ 81459CB8E975003AD28B8ABB8DFA8329 ] C:\WINDOWS\System32\SECUR32.DLL
21:36:04.0171 2968 C:\WINDOWS\System32\SECUR32.DLL - ok
21:36:04.0171 2968 [ 7808313CBC634EE08346D5DDFEF1CC5F ] C:\WINDOWS\System32\SETUPAPI.DLL
21:36:04.0171 2968 C:\WINDOWS\System32\SETUPAPI.DLL - ok
21:36:04.0171 2968 [ D38408967BE738D0C1B47005BCE8CEEB ] C:\WINDOWS\System32\VERSION.DLL
21:36:04.0171 2968 C:\WINDOWS\System32\VERSION.DLL - ok
21:36:04.0187 2968 [ 7BC4BA4C33ADF3EF5CD370D99BC60B04 ] C:\WINDOWS\System32\WINSTA.DLL
21:36:04.0187 2968 C:\WINDOWS\System32\WINSTA.DLL - ok
21:36:04.0187 2968 [ B015A20C60D2A751777A9C8207A7BA82 ] C:\WINDOWS\System32\WINTRUST.DLL
21:36:04.0187 2968 C:\WINDOWS\System32\WINTRUST.DLL - ok
21:36:04.0203 2968 [ 5AFCE94E8286B2F57A04DA37F01BF21A ] C:\WINDOWS\System32\IMAGEHLP.DLL
21:36:04.0203 2968 C:\WINDOWS\System32\IMAGEHLP.DLL - ok
21:36:04.0203 2968 [ 2ED0B7F12A60F90092081C50FA0EC2B2 ] C:\WINDOWS\System32\WS2_32.DLL
21:36:04.0203 2968 C:\WINDOWS\System32\WS2_32.DLL - ok
21:36:04.0203 2968 [ 87CA7CE6469577F059297B9D6556D66D ] C:\WINDOWS\System32\IMM32.DLL
21:36:04.0203 2968 C:\WINDOWS\System32\IMM32.DLL - ok
21:36:04.0218 2968 [ 9BEACB911CA61E5881102188AB7FB431 ] C:\WINDOWS\System32\WS2HELP.DLL
21:36:04.0218 2968 C:\WINDOWS\System32\WS2HELP.DLL - ok
21:36:04.0218 2968 [ 56C5B179FE3308B655EB6208C3256FEC ] C:\WINDOWS\System32\KBDUS.DLL
21:36:04.0218 2968 C:\WINDOWS\System32\KBDUS.DLL - ok
21:36:04.0234 2968 [ A29AF639AA180CC68C59242A10E1D3B1 ] C:\WINDOWS\System32\MSGINA.DLL
21:36:04.0234 2968 C:\WINDOWS\System32\MSGINA.DLL - ok
21:36:04.0234 2968 [ 02A57CA7AB70A60A8A945AC9769DA827 ] C:\WINDOWS\System32\SHELL32.DLL
21:36:04.0234 2968 C:\WINDOWS\System32\SHELL32.DLL - ok
21:36:04.0234 2968 [ 3A7CAF09DECFD090C0C75828B1A7B401 ] C:\WINDOWS\System32\SHLWAPI.DLL
21:36:04.0234 2968 C:\WINDOWS\System32\SHLWAPI.DLL - ok
21:36:04.0250 2968 [ 4FA5EF9FC22F219D155D4AEF812371F1 ] C:\WINDOWS\System32\COMCTL32.DLL
21:36:04.0250 2968 C:\WINDOWS\System32\COMCTL32.DLL - ok
21:36:04.0250 2968 [ 1EDB1BB89D021955E6F7265911175B8D ] C:\WINDOWS\System32\COMDLG32.DLL
21:36:04.0250 2968 C:\WINDOWS\System32\COMDLG32.DLL - ok
21:36:04.0265 2968 [ F79D7D98CD764499ECCBAAF3F800D349 ] C:\WINDOWS\System32\ODBC32.DLL
21:36:04.0265 2968 C:\WINDOWS\System32\ODBC32.DLL - ok
21:36:04.0265 2968 [ 3862AFE249063AE6C3BBC8687D6CC601 ] C:\WINDOWS\System32\SXS.DLL
21:36:04.0265 2968 C:\WINDOWS\System32\SXS.DLL - ok
21:36:04.0265 2968 [ E5AD764825ED2873170289683DB835D9 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b\COMCTL32.DLL
21:36:04.0265 2968 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b\COMCTL32.DLL - ok
21:36:04.0281 2968 [ C237FB08F52F27823C4E4E6705ECD196 ] C:\WINDOWS\System32\ODBCINT.DLL
21:36:04.0281 2968 C:\WINDOWS\System32\ODBCINT.DLL - ok
21:36:04.0281 2968 [ E7518DC542D3EBDCB80EDD98462C7821 ] C:\WINDOWS\System32\SHSVCS.DLL
21:36:04.0281 2968 C:\WINDOWS\System32\SHSVCS.DLL - ok
21:36:04.0296 2968 [ E8A12A12EA9088B4327D49EDCA3ADD3E ] C:\WINDOWS\System32\SFC.DLL
21:36:04.0296 2968 C:\WINDOWS\System32\SFC.DLL - ok
21:36:04.0296 2968 [ 5D6BEA32F4F7FB6703FFB7DC0CFBAA08 ] C:\WINDOWS\System32\OLE32.DLL
21:36:04.0296 2968 C:\WINDOWS\System32\OLE32.DLL - ok
21:36:04.0312 2968 [ 499ED4D094C15C0FE93C8194B324BBD6 ] C:\WINDOWS\System32\SFC_OS.DLL
21:36:04.0312 2968 C:\WINDOWS\System32\SFC_OS.DLL - ok
21:36:04.0312 2968 [ ECA24AB73FCFFA754D4070CDB03529E3 ] C:\WINDOWS\System32\APPHELP.DLL
21:36:04.0312 2968 C:\WINDOWS\System32\APPHELP.DLL - ok
21:36:04.0312 2968 [ 9A42C1F3154545A4D32E5043038B01FA ] C:\WINDOWS\System32\SCESRV.DLL
21:36:04.0312 2968 C:\WINDOWS\System32\SCESRV.DLL - ok
21:36:04.0328 2968 [ C6CE6EEC82F187615D1002BB3BB50ED4 ] C:\WINDOWS\System32\SERVICES.EXE
21:36:04.0328 2968 C:\WINDOWS\System32\SERVICES.EXE - ok
21:36:04.0328 2968 [ 7C06751F19A3196698B4EE5609D8A6DB ] C:\WINDOWS\System32\LSASRV.DLL
21:36:04.0328 2968 C:\WINDOWS\System32\LSASRV.DLL - ok
21:36:04.0343 2968 [ 84885F9B82F4D55C6146EBF6065D75D2 ] C:\WINDOWS\System32\LSASS.EXE
21:36:04.0343 2968 C:\WINDOWS\System32\LSASS.EXE - ok
21:36:04.0343 2968 [ 226B26D72CDE7F802D013347ABB99DA5 ] C:\WINDOWS\System32\UMPNPMGR.DLL
21:36:04.0343 2968 C:\WINDOWS\System32\UMPNPMGR.DLL - ok
21:36:04.0343 2968 [ 1F57EB5B92B2AC7F9D71A77D184D8C13 ] C:\WINDOWS\System32\MSVCP60.DLL
21:36:04.0343 2968 C:\WINDOWS\System32\MSVCP60.DLL - ok
21:36:04.0359 2968 [ DA201A0A309B96381FD674D0FAB5DA86 ] C:\WINDOWS\System32\NCOBJAPI.DLL
21:36:04.0359 2968 C:\WINDOWS\System32\NCOBJAPI.DLL - ok
21:36:04.0359 2968 [ 2CFE80AA3428C09E6DE67FAC50DA65CF ] C:\WINDOWS\System32\MPR.DLL
21:36:04.0359 2968 C:\WINDOWS\System32\MPR.DLL - ok
21:36:04.0375 2968 [ 43DA983415EA533F9E667FDB415F4655 ] C:\WINDOWS\System32\SHIMENG.DLL
21:36:04.0375 2968 C:\WINDOWS\System32\SHIMENG.DLL - ok
21:36:04.0375 2968 [ 8B683A79F57A758CC80C84BCBEF3D96E ] C:\WINDOWS\AppPatch\AcGenral.dll
21:36:04.0375 2968 C:\WINDOWS\AppPatch\AcGenral.dll - ok
21:36:04.0375 2968 [ 6201BACF384292A5FE94CE73364AE53A ] C:\WINDOWS\System32\NTDSAPI.DLL
21:36:04.0375 2968 C:\WINDOWS\System32\NTDSAPI.DLL - ok
21:36:04.0390 2968 [ C76735BFB7214907B4590DD35AE64A79 ] C:\WINDOWS\System32\DNSAPI.DLL
21:36:04.0390 2968 C:\WINDOWS\System32\DNSAPI.DLL - ok
21:36:04.0390 2968 [ 10F36FA092D7A309A0647FCDC764AE6C ] C:\WINDOWS\System32\WLDAP32.DLL
21:36:04.0390 2968 C:\WINDOWS\System32\WLDAP32.DLL - ok
21:36:04.0406 2968 [ EBE12F403FDE45E7312E7BF764BFB6C6 ] C:\WINDOWS\System32\SAMLIB.DLL
21:36:04.0406 2968 C:\WINDOWS\System32\SAMLIB.DLL - ok
21:36:04.0406 2968 [ E15154E7FDA8A580A8F74C7CC16B1FFE ] C:\WINDOWS\System32\SAMSRV.DLL
21:36:04.0406 2968 C:\WINDOWS\System32\SAMSRV.DLL - ok
21:36:04.0406 2968 [ EF5B64A9CD71ED27E837165C08DA4CC1 ] C:\WINDOWS\System32\CRYPTDLL.DLL
21:36:04.0406 2968 C:\WINDOWS\System32\CRYPTDLL.DLL - ok
21:36:04.0421 2968 [ 90FDAA22F38D9E911F91FA3B8A1F7E5D ] C:\WINDOWS\System32\WINMM.DLL
21:36:04.0421 2968 C:\WINDOWS\System32\WINMM.DLL - ok
21:36:04.0421 2968 [ B3742DEE858B243E77C73D2B8F7C8223 ] C:\WINDOWS\System32\OLEAUT32.DLL
21:36:04.0421 2968 C:\WINDOWS\System32\OLEAUT32.DLL - ok
21:36:04.0437 2968 [ 975D12353B1D525C0F3444C447FB3B9A ] C:\WINDOWS\System32\MSACM32.DLL
21:36:04.0437 2968 C:\WINDOWS\System32\MSACM32.DLL - ok
21:36:04.0437 2968 [ C74E2B7930BE58EE70764451363771CF ] C:\WINDOWS\System32\UXTHEME.DLL
21:36:04.0437 2968 C:\WINDOWS\System32\UXTHEME.DLL - ok
21:36:04.0437 2968 [ 29632E787DCFC0085A555C681EB82693 ] C:\WINDOWS\System32\SCHANNEL.DLL
21:36:04.0437 2968 C:\WINDOWS\System32\SCHANNEL.DLL - ok
21:36:04.0453 2968 [ 6BEC17053284E847CF1FBB8C9A181E1E ] C:\WINDOWS\System32\MSPRIVS.DLL
21:36:04.0453 2968 C:\WINDOWS\System32\MSPRIVS.DLL - ok
21:36:04.0453 2968 [ 3B06408BE5E4FF3003FC210D5CE56BFE ] C:\WINDOWS\System32\KERBEROS.DLL
21:36:04.0453 2968 C:\WINDOWS\System32\KERBEROS.DLL - ok
21:36:04.0468 2968 [ D87041EAA67ECA4394F6D5D09C0C2885 ] C:\WINDOWS\System32\MSCTFIME.IME
21:36:04.0468 2968 C:\WINDOWS\System32\MSCTFIME.IME - ok
21:36:04.0468 2968 [ 77C41F9146450C89534704A75836CE56 ] C:\WINDOWS\System32\MSV1_0.DLL
21:36:04.0468 2968 C:\WINDOWS\System32\MSV1_0.DLL - ok
21:36:04.0468 2968 [ 42A1912DBDF8BCC087A1CAE008DB060C ] C:\WINDOWS\System32\IPHLPAPI.DLL
21:36:04.0468 2968 C:\WINDOWS\System32\IPHLPAPI.DLL - ok
21:36:04.0484 2968 [ 96353FCECBA774BB8DA74A1C6507015A ] C:\WINDOWS\System32\NETLOGON.DLL
21:36:04.0484 2968 C:\WINDOWS\System32\NETLOGON.DLL - ok
21:36:04.0484 2968 [ 2B281958F5D0CF99ED626E3EF39D5C8D ] C:\WINDOWS\System32\W32TIME.DLL
21:36:04.0484 2968 C:\WINDOWS\System32\W32TIME.DLL - ok
21:36:04.0500 2968 [ A8B82C5D30B7AB937E164AB349478FBA ] C:\WINDOWS\System32\WDIGEST.DLL
21:36:04.0500 2968 C:\WINDOWS\System32\WDIGEST.DLL - ok
21:36:04.0500 2968 [ 26ACBD865F8CFF730F1791C4D0854352 ] C:\WINDOWS\System32\RSAENH.DLL
21:36:04.0500 2968 C:\WINDOWS\System32\RSAENH.DLL - ok
21:36:04.0500 2968 [ 7BCB23FA39CE266AF4347A6BEAB60F8C ] C:\WINDOWS\System32\WINSCARD.DLL
21:36:04.0500 2968 C:\WINDOWS\System32\WINSCARD.DLL - ok
21:36:04.0515 2968 [ 67F2D109AB373FECEB819F420DB11F03 ] C:\WINDOWS\System32\WTSAPI32.DLL
21:36:04.0515 2968 C:\WINDOWS\System32\WTSAPI32.DLL - ok
21:36:04.0515 2968 [ 0F78E27F563F2AAF74B91A49E2ABF19A ] C:\WINDOWS\System32\SCECLI.DLL
21:36:04.0515 2968 C:\WINDOWS\System32\SCECLI.DLL - ok
21:36:04.0531 2968 [ 8F078AE4ED187AAABC0A305146DE6716 ] C:\WINDOWS\System32\SVCHOST.EXE
21:36:04.0531 2968 C:\WINDOWS\System32\SVCHOST.EXE - ok
21:36:04.0531 2968 [ DAA91B358E685FC6CCA9ACA72BE6FE85 ] C:\WINDOWS\System32\NTMARTA.DLL
21:36:04.0531 2968 C:\WINDOWS\System32\NTMARTA.DLL - ok
21:36:04.0531 2968 [ A4254FFC7B7894D118D8E6E57E34C660 ] C:\WINDOWS\System32\RPCSS.DLL
21:36:04.0531 2968 C:\WINDOWS\System32\RPCSS.DLL - ok
21:36:04.0546 2968 [ 1320AEA7057A26A671D9548CC7BEBDA5 ] C:\WINDOWS\System32\XPSP2RES.DLL
21:36:04.0546 2968 C:\WINDOWS\System32\XPSP2RES.DLL - ok
21:36:04.0546 2968 [ 82B24CB70E5944E6E34662205A2A5B78 ] C:\WINDOWS\System32\EVENTLOG.DLL
21:36:04.0546 2968 C:\WINDOWS\System32\EVENTLOG.DLL - ok
21:36:04.0562 2968 [ 4E74AF063C3271FBEA20DD940CFD1184 ] C:\WINDOWS\System32\MSWSOCK.DLL
21:36:04.0562 2968 C:\WINDOWS\System32\MSWSOCK.DLL - ok
21:36:04.0562 2968 [ 765B30C776A1780B46B479FE614F707C ] C:\WINDOWS\System32\HNETCFG.DLL
21:36:04.0562 2968 C:\WINDOWS\System32\HNETCFG.DLL - ok
21:36:04.0562 2968 [ A7F95A53EE055115DF03588997A47D4D ] C:\WINDOWS\System32\WSHTCPIP.DLL
21:36:04.0562 2968 C:\WINDOWS\System32\WSHTCPIP.DLL - ok
21:36:04.0578 2968 [ 2C8FDB176F22629EA5342DB474FAC391 ] C:\WINDOWS\System32\WINRNR.DLL
21:36:04.0578 2968 C:\WINDOWS\System32\WINRNR.DLL - ok
21:36:04.0578 2968 [ 4CAEC028C1E21C75E17877D4522D3DB4 ] C:\WINDOWS\System32\RASADHLP.DLL
21:36:04.0578 2968 C:\WINDOWS\System32\RASADHLP.DLL - ok
21:36:04.0593 2968 [ 7DB59FFF2AF32C27EB2276424FA5EDDB ] C:\WINDOWS\System32\LOGONUI.EXE
21:36:04.0593 2968 C:\WINDOWS\System32\LOGONUI.EXE - ok
21:36:04.0593 2968 [ ED7E847905DD2797565B4B695E92F42B ] C:\WINDOWS\System32\DUSER.DLL
21:36:04.0593 2968 C:\WINDOWS\System32\DUSER.DLL - ok
21:36:04.0593 2968 [ B5331F2B6F37C66C29C847F3B94FF900 ] C:\WINDOWS\System32\MSIMG32.DLL
21:36:04.0593 2968 C:\WINDOWS\System32\MSIMG32.DLL - ok
21:36:04.0609 2968 [ 5F2DBE3CB563741C8084657BF956CE64 ] C:\WINDOWS\System32\OLEACC.DLL
21:36:04.0609 2968 C:\WINDOWS\System32\OLEACC.DLL - ok
21:36:04.0609 2968 [ F44C85A737E9E90408CAAFF1329A2A0B ] C:\WINDOWS\System32\CLBCATQ.DLL
21:36:04.0609 2968 C:\WINDOWS\System32\CLBCATQ.DLL - ok
21:36:04.0609 2968 [ 587729679B4FE04CE06A5C61D6C56DCD ] C:\WINDOWS\System32\CSCDLL.DLL
21:36:04.0609 2968 C:\WINDOWS\System32\CSCDLL.DLL - ok
21:36:04.0625 2968 [ 6728270CB7DBB776ED086F5AC4C82310 ] C:\WINDOWS\System32\COMRES.DLL
21:36:04.0625 2968 C:\WINDOWS\System32\COMRES.DLL - ok
21:36:04.0625 2968 [ A599E5E366C1408E48AA5D37882D4E3E ] C:\WINDOWS\System32\WLNOTIFY.DLL
21:36:04.0625 2968 C:\WINDOWS\System32\WLNOTIFY.DLL - ok
21:36:04.0640 2968 [ 777EB29D0135D81AD9828A2B05443496 ] C:\WINDOWS\System32\WINSPOOL.DRV
21:36:04.0640 2968 C:\WINDOWS\System32\WINSPOOL.DRV - ok
21:36:04.0640 2968 [ 1D3A8A40F8045100A3E35C5F9BC6C5DE ] C:\WINDOWS\System32\SHGINA.DLL
21:36:04.0640 2968 C:\WINDOWS\System32\SHGINA.DLL - ok
21:36:04.0656 2968 [ 34258244F176EEC4C0831872BB0238C8 ] C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20121130.005\UMEngx86.dll
21:36:04.0656 2968 C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_20.2.0.19\Definitions\BASHDefs\20121130.005\UMEngx86.dll - ok
21:36:04.0656 2968 [ B1E5C0065102FCB92E1F0231AF0AE7C3 ] C:\Program Files\Lenovo\Bluetooth Software\BIN\BTWDINS.EXE
21:36:04.0656 2968 C:\Program Files\Lenovo\Bluetooth Software\BIN\BTWDINS.EXE - ok
21:36:04.0671 2968 [ A7E06854EA2A20AEE8EC32BD8C754298 ] C:\WINDOWS\System32\MPNOTIFY.EXE
21:36:04.0671 2968 C:\WINDOWS\System32\MPNOTIFY.EXE - ok
21:36:04.0671 2968 [ 18AFEE0EDE045B6255408D634372DC29 ] C:\WINDOWS\System32\HID.DLL
21:36:04.0671 2968 C:\WINDOWS\System32\HID.DLL - ok
21:36:04.0671 2968 [ EEFA1CE63805D2145978621BE5C6D955 ] C:\WINDOWS\System32\drivers\NDISUIO.SYS
21:36:04.0671 2968 C:\WINDOWS\System32\drivers\NDISUIO.SYS - ok
21:36:04.0687 2968 [ 095FF903BC31321D3844976B52D513FC ] C:\WINDOWS\System32\DHCPCSVC.DLL
21:36:04.0687 2968 C:\WINDOWS\System32\DHCPCSVC.DLL - ok
21:36:04.0687 2968 [ 51230212AE7F8159A90F06A7EA30DD8A ] C:\WINDOWS\System32\CSCUI.DLL
21:36:04.0687 2968 C:\WINDOWS\System32\CSCUI.DLL - ok
21:36:04.0703 2968 [ 1B5F6923ABB450692E9FE0672C897AED ] C:\WINDOWS\System32\POWRPROF.DLL
21:36:04.0703 2968 C:\WINDOWS\System32\POWRPROF.DLL - ok
21:36:04.0703 2968 [ F7FC12EDD4F0C19490D37AF9570C50F8 ] C:\WINDOWS\System32\DPCDLL.DLL
21:36:04.0703 2968 C:\WINDOWS\System32\DPCDLL.DLL - ok
21:36:04.0703 2968 [ 7379DE06FD196E396A00AA97B990C00D ] C:\WINDOWS\System32\DNSRSLVR.DLL
21:36:04.0703 2968 C:\WINDOWS\System32\DNSRSLVR.DLL - ok
21:36:04.0718 2968 [ 39B1FFB03C2296323832ACBAE50D2AFF ] C:\WINDOWS\System32\USERINIT.EXE
21:36:04.0718 2968 C:\WINDOWS\System32\USERINIT.EXE - ok
21:36:04.0718 2968 [ BA511AFC5B695F11139690885131D084 ] C:\Documents and Settings\Samhita\Local Settings\Application Data\TLQEDHYU\CRIQNKII.EXE
21:36:04.0718 2968 C:\Documents and Settings\Samhita\Local Settings\Application Data\TLQEDHYU\CRIQNKII.EXE - ok
21:36:04.0734 2968 [ 45757077A47C68A603A79B03A1A836AB ] C:\WINDOWS\EXPLORER.EXE
21:36:04.0734 2968 C:\WINDOWS\EXPLORER.EXE - ok
21:36:04.0734 2968 [ B99FF349BF53BD91FBDDCD6B1EDE8980 ] C:\WINDOWS\System32\BROWSEUI.DLL
21:36:04.0734 2968 C:\WINDOWS\System32\BROWSEUI.DLL - ok
21:36:04.0734 2968 [ 559B2D22A1EE947A7EAED530C7FF9320 ] C:\WINDOWS\System32\SHDOCVW.DLL
21:36:04.0734 2968 C:\WINDOWS\System32\SHDOCVW.DLL - ok
21:36:04.0750 2968 [ 4AC302BF714DC163E685D0A187A36D0F ] C:\WINDOWS\System32\CRYPTUI.DLL
21:36:04.0750 2968 C:\WINDOWS\System32\CRYPTUI.DLL - ok
21:36:04.0750 2968 [ B3EFF6D938C572E90A07B3D87A3C7657 ] C:\WINDOWS\System32\LMHSVC.DLL
21:36:04.0750 2968 C:\WINDOWS\System32\LMHSVC.DLL - ok
21:36:04.0765 2968 [ 23BB7F97459D674A68E74CE58482B1F0 ] C:\WINDOWS\System32\WZCSVC.DLL
21:36:04.0765 2968 C:\WINDOWS\System32\WZCSVC.DLL - ok
21:36:04.0765 2968 [ 2030FA027E7C3E0A145649C03171457B ] C:\WINDOWS\System32\RTUTILS.DLL
21:36:04.0765 2968 C:\WINDOWS\System32\RTUTILS.DLL - ok
21:36:04.0765 2968 [ 6CE32F7778061CCC5814D5E0F282D369 ] C:\WINDOWS\System32\WININET.DLL
21:36:04.0765 2968 C:\WINDOWS\System32\WININET.DLL - ok
21:36:04.0781 2968 [ E682696D7F982494A8CFC80C5B59D422 ] C:\WINDOWS\System32\WMI.DLL
21:36:04.0781 2968 C:\WINDOWS\System32\WMI.DLL - ok
21:36:04.0781 2968 [ 0A70ACFDC256D856FCFCBC316DF91619 ] C:\WINDOWS\System32\ESENT.DLL
21:36:04.0781 2968 C:\WINDOWS\System32\ESENT.DLL - ok
21:36:04.0781 2968 [ 10753A3ADC3E39A3B10CC3F08E98E6B4 ] C:\WINDOWS\System32\NORMALIZ.DLL
21:36:04.0781 2968 C:\WINDOWS\System32\NORMALIZ.DLL - ok
21:36:04.0796 2968 [ 05642AE6A7BDAA7541A7451F5A4C6512 ] C:\WINDOWS\System32\URLMON.DLL
21:36:04.0796 2968 C:\WINDOWS\System32\URLMON.DLL - ok
21:36:04.0796 2968 [ 58BD4689E1DCD40A903721D7EF45F2EC ] C:\WINDOWS\System32\IERTUTIL.DLL
21:36:04.0796 2968 C:\WINDOWS\System32\IERTUTIL.DLL - ok
21:36:04.0812 2968 [ 2D40EDB9BF811590DAD7406DEC67B926 ] C:\WINDOWS\System32\ATL.DLL
21:36:04.0812 2968 C:\WINDOWS\System32\ATL.DLL - ok
21:36:04.0812 2968 [ ADEAC063A3757E8FBC242BB4414D632B ] C:\WINDOWS\System32\RASTLS.DLL
21:36:04.0812 2968 C:\WINDOWS\System32\RASTLS.DLL - ok
21:36:04.0812 2968 [ A0BC687A49542C40EB60B7308F454E8A ] C:\WINDOWS\System32\RICHED20.DLL
21:36:04.0812 2968 C:\WINDOWS\System32\RICHED20.DLL - ok
21:36:04.0828 2968 [ 9F78F329B1858E845087B923B4DBA0F3 ] C:\WINDOWS\System32\MPRAPI.DLL
21:36:04.0828 2968 C:\WINDOWS\System32\MPRAPI.DLL - ok
21:36:04.0828 2968 [ 875D770F477E0AE0088BE1810D537B23 ] C:\WINDOWS\System32\ACTIVEDS.DLL
21:36:04.0828 2968 C:\WINDOWS\System32\ACTIVEDS.DLL - ok
21:36:04.0843 2968 [ 12A581CA44E53B09D24C5B94F252C78D ] C:\WINDOWS\System32\ADSLDPC.DLL
21:36:04.0843 2968 C:\WINDOWS\System32\ADSLDPC.DLL - ok
21:36:04.0843 2968 [ E931B4DD87DFACE46468FD506FDCD262 ] C:\WINDOWS\System32\DESK.CPL
21:36:04.0843 2968 C:\WINDOWS\System32\DESK.CPL - ok
21:36:04.0843 2968 [ E6796D51CED309E46D29C0B787735615 ] C:\WINDOWS\System32\THEMEUI.DLL
21:36:04.0843 2968 C:\WINDOWS\System32\THEMEUI.DLL - ok
21:36:04.0859 2968 [ CD1F7ED9842138BEADF9ECBF37818BEF ] C:\WINDOWS\System32\RASAPI32.DLL
21:36:04.0859 2968 C:\WINDOWS\System32\RASAPI32.DLL - ok
21:36:04.0859 2968 [ 30E244A707E6CE0A4B099CD6384EC6CA ] C:\WINDOWS\System32\RASMAN.DLL
21:36:04.0859 2968 C:\WINDOWS\System32\RASMAN.DLL - ok
21:36:04.0875 2968 [ 6307A1B82F6CA87D7E0CDF49E6E7BC00 ] C:\WINDOWS\System32\TAPI32.DLL
21:36:04.0875 2968 C:\WINDOWS\System32\TAPI32.DLL - ok
21:36:04.0875 2968 [ 729DA5D23A9AD20A6AA353156A126420 ] C:\WINDOWS\System32\IEFRAME.DLL
21:36:04.0875 2968 C:\WINDOWS\System32\IEFRAME.DLL - ok
21:36:04.0875 2968 [ EEB024F2C81F0D55936FB825D21A91D6 ] C:\WINDOWS\System32\CMD.EXE
21:36:04.0875 2968 C:\WINDOWS\System32\CMD.EXE - ok
21:36:04.0890 2968 [ 33CA7E710BE973BCAE327FD6EDF79F5C ] C:\WINDOWS\System32\BT2K_INS.DLL
21:36:04.0890 2968 C:\WINDOWS\System32\BT2K_INS.DLL - ok
21:36:04.0890 2968 [ 1B0F0FC350C77B62A4B927810E53B2BF ] C:\WINDOWS\System32\RASCHAP.DLL
21:36:04.0890 2968 C:\WINDOWS\System32\RASCHAP.DLL - ok
21:36:04.0906 2968 [ 76A530B286B4C5033ED91B3C472C20C5 ] C:\WINDOWS\System32\MLANG.DLL
21:36:04.0906 2968 C:\WINDOWS\System32\MLANG.DLL - ok
21:36:04.0906 2968 [ 59E9857ABC6C62AF55EB29FA68354805 ] C:\WINDOWS\System32\xmlprovi.dll
21:36:04.0906 2968 C:\WINDOWS\System32\xmlprovi.dll - ok
21:36:04.0906 2968 [ 3B03F270B1F79DCD696778FB21A118E5 ] C:\WINDOWS\System32\WZCSAPI.DLL
21:36:04.0906 2968 C:\WINDOWS\System32\WZCSAPI.DLL - ok
21:36:04.0921 2968 [ EBC984F0CE40E0DAF0454D806EC2A7EC ] C:\Documents and Settings\Samhita\Local Settings\Temp\614C2B07-53C8-4EF9-B813-39C84FE4D6EB.exe
21:36:04.0921 2968 C:\Documents and Settings\Samhita\Local Settings\Temp\614C2B07-53C8-4EF9-B813-39C84FE4D6EB.exe - ok
21:36:04.0921 2968 [ EA82A55F22654FBEDCBD82D2D4305B45 ] C:\WINDOWS\System32\WINHTTP.DLL
21:36:04.0921 2968 C:\WINDOWS\System32\WINHTTP.DLL - ok
21:36:04.0937 2968 [ 3516D8A18B36784B1005B950B84232E1 ] C:\WINDOWS\System32\NETMAN.DLL
21:36:04.0937 2968 C:\WINDOWS\System32\NETMAN.DLL - ok
21:36:04.0937 2968 [ 6BA7F91ECB1D058A1BFE50B1883E0054 ] C:\WINDOWS\System32\NETSHELL.DLL
21:36:04.0937 2968 C:\WINDOWS\System32\NETSHELL.DLL - ok
21:36:04.0953 2968 [ 1ECB753D7CEEC8F5A94C9781CA64EC44 ] C:\WINDOWS\System32\CREDUI.DLL
21:36:04.0953 2968 C:\WINDOWS\System32\CREDUI.DLL - ok
21:36:04.0953 2968 [ 92360854316611F6CC471612213C3D92 ] C:\WINDOWS\System32\SCHEDSVC.DLL
21:36:04.0953 2968 C:\WINDOWS\System32\SCHEDSVC.DLL - ok
21:36:04.0953 2968 [ AD3D9D191AEA7B5445FE1D82FFBB4788 ] C:\WINDOWS\System32\SPOOLSV.EXE
21:36:04.0953 2968 C:\WINDOWS\System32\SPOOLSV.EXE - ok
21:36:04.0968 2968 [ 249817F51C84D283E96E6B2580D21FFD ] C:\WINDOWS\System32\MSIDLE.DLL
21:36:04.0968 2968 C:\WINDOWS\System32\MSIDLE.DLL - ok
21:36:04.0968 2968 [ DB66DB626E4882EBEF55F136F12C1829 ] C:\WINDOWS\System32\AUDIOSRV.DLL
21:36:04.0968 2968 C:\WINDOWS\System32\AUDIOSRV.DLL - ok
21:36:04.0984 2968 [ 13510490BEA0997DB625DAA0178CBFCA ] C:\WINDOWS\System32\ACTXPRXY.DLL
21:36:04.0984 2968 C:\WINDOWS\System32\ACTXPRXY.DLL - ok
21:36:04.0984 2968 [ 5AC144F03B31AFAB6717AD3622D1680D ] C:\WINDOWS\System32\ACS.EXE
21:36:04.0984 2968 C:\WINDOWS\System32\ACS.EXE - ok
21:36:04.0984 2968 [ 765C5D415CF6054526CCD00B1FBB2325 ] C:\WINDOWS\System32\athcfg20U.dll
21:36:04.0984 2968 C:\WINDOWS\System32\athcfg20U.dll - ok
21:36:05.0000 2968 [ D6A8DC8C374EEA24744F2D4E87CA0E7E ] C:\WINDOWS\System32\WDMAUD.DRV
21:36:05.0000 2968 C:\WINDOWS\System32\WDMAUD.DRV - ok
21:36:05.0000 2968 [ 2797F33EBF50466020C430EE4F037933 ] C:\WINDOWS\System32\drivers\WDMAUD.SYS
21:36:05.0000 2968 C:\WINDOWS\System32\drivers\WDMAUD.SYS - ok
21:36:05.0015 2968 [ 650AD082D46BAC0E64C9C0E0928492FD ] C:\WINDOWS\System32\drivers\SYSAUDIO.SYS
21:36:05.0015 2968 C:\WINDOWS\System32\drivers\SYSAUDIO.SYS - ok
21:36:05.0015 2968 [ 0FCB11B39AF688035E1CDE754684EE5C ] C:\WINDOWS\System32\CFGMGR32.DLL
21:36:05.0015 2968 C:\WINDOWS\System32\CFGMGR32.DLL - ok
21:36:05.0015 2968 [ 8E186B8F23295D1E42C573B82B80D548 ] C:\WINDOWS\System32\drivers\SPLITTER.SYS
21:36:05.0031 2968 C:\WINDOWS\System32\drivers\SPLITTER.SYS - ok
21:36:05.0031 2968 [ 1EE7B434BA961EF845DE136224C30FEC ] C:\WINDOWS\System32\drivers\AEC.SYS
21:36:05.0031 2968 C:\WINDOWS\System32\drivers\AEC.SYS - ok
21:36:05.0031 2968 [ 648BF0B4DDE4F7A1156DAE7174D36EFA ] C:\WINDOWS\System32\LINKINFO.DLL
21:36:05.0031 2968 C:\WINDOWS\System32\LINKINFO.DLL - ok
21:36:05.0046 2968 [ 53AF9F2B2CE4B6EFF41C70417359D010 ] C:\WINDOWS\System32\WSOCK32.DLL
21:36:05.0046 2968 C:\WINDOWS\System32\WSOCK32.DLL - ok
21:36:05.0046 2968 [ 94ABC808FC4B6D7D2BBF42B85E25BB4D ] C:\WINDOWS\System32\drivers\SWMIDI.SYS
21:36:05.0046 2968 C:\WINDOWS\System32\drivers\SWMIDI.SYS - ok
21:36:05.0062 2968 [ AA808DD00AF4FF04283BC719A8E070CD ] C:\WINDOWS\System32\MFC42U.DLL
21:36:05.0062 2968 C:\WINDOWS\System32\MFC42U.DLL - ok
21:36:05.0062 2968 [ A6F881284AC1150E37D9AE47FF601267 ] C:\WINDOWS\System32\drivers\DMusic.sys
21:36:05.0062 2968 C:\WINDOWS\System32\drivers\DMusic.sys - ok
21:36:05.0078 2968 [ 385E9AEC6E100DBEBEE5BD1F27A55E1D ] C:\WINDOWS\System32\NTSHRUI.DLL
21:36:05.0078 2968 C:\WINDOWS\System32\NTSHRUI.DLL - ok
21:36:05.0078 2968 [ D93CAD07C5683DB066B0B2D2D3790EAD ] C:\WINDOWS\System32\drivers\KMIXER.SYS
21:36:05.0078 2968 C:\WINDOWS\System32\drivers\KMIXER.SYS - ok
21:36:05.0078 2968 [ 1CBC000ECD2DE2E6FD2B19BC9AABCC52 ] C:\WINDOWS\System32\MSI.DLL
21:36:05.0078 2968 C:\WINDOWS\System32\MSI.DLL - ok
21:36:05.0093 2968 [ 1ED4DBBAE9F5D558DBBA4CC450E3EB2E ] C:\WINDOWS\System32\drivers\DRMKAUD.SYS
21:36:05.0093 2968 C:\WINDOWS\System32\drivers\DRMKAUD.SYS - ok
21:36:05.0093 2968 [ 073DD9B9B9A6BDFF47465141F708F26B ] C:\WINDOWS\System32\athcfg20resU.dll
21:36:05.0093 2968 C:\WINDOWS\System32\athcfg20resU.dll - ok
21:36:05.0109 2968 [ 9A3BD5F55AADFF859539142F6328A66E ] C:\WINDOWS\System32\MSACM32.DRV
21:36:05.0109 2968 C:\WINDOWS\System32\MSACM32.DRV - ok
21:36:05.0109 2968 [ 5F74A7A9AFBF875B719CABFEFC3FE3E8 ] C:\WINDOWS\System32\PDH.DLL
21:36:05.0109 2968 C:\WINDOWS\System32\PDH.DLL - ok
21:36:05.0109 2968 [ 3B4702155BB2AE9DC00C06A68834BDFA ] C:\WINDOWS\System32\MIDIMAP.DLL
21:36:05.0109 2968 C:\WINDOWS\System32\MIDIMAP.DLL - ok
21:36:05.0125 2968 [ 7AA15CCBE1DD20339200659AF99D588F ] C:\WINDOWS\System32\ODBCBCP.DLL
21:36:05.0125 2968 C:\WINDOWS\System32\ODBCBCP.DLL - ok
21:36:05.0125 2968 [ DB36F8A42DCDABEB28E5897C7B84486B ] C:\WINDOWS\System32\MSVCIRT.DLL
21:36:05.0125 2968 C:\WINDOWS\System32\MSVCIRT.DLL - ok
21:36:05.0140 2968 [ 46EDCC8F2DB2F322C24F48785CB46366 ] C:\WINDOWS\System32\drivers\MRXDAV.SYS
21:36:05.0140 2968 C:\WINDOWS\System32\drivers\MRXDAV.SYS - ok
21:36:05.0140 2968 [ 4D2CF321256AFE32D6875285A34F1C2C ] C:\WINDOWS\System32\wsfwDS.dll
21:36:05.0140 2968 C:\WINDOWS\System32\wsfwDS.dll - ok
21:36:05.0156 2968 [ 79D8A229FA677BFB9C653146CADD6F5A ] C:\WINDOWS\System32\HCCUTILS.DLL
21:36:05.0156 2968 C:\WINDOWS\System32\HCCUTILS.DLL - ok
21:36:05.0156 2968 [ 32BAD6E0A48FC9917B850EBFFA826D9F ] C:\WINDOWS\System32\IGFXTRAY.EXE
21:36:05.0156 2968 C:\WINDOWS\System32\IGFXTRAY.EXE - ok
21:36:05.0171 2968 [ 165AE7A443F2139DD2C078AD87699F91 ] C:\Program Files\Microsoft Office\OFFICE11\MSOHEV.DLL
21:36:05.0171 2968 C:\Program Files\Microsoft Office\OFFICE11\MSOHEV.DLL - ok
21:36:05.0171 2968 [ 175AECCD3A08223B3D6902E6EEE5B66C ] C:\WINDOWS\System32\WSIMD.DLL
21:36:05.0171 2968 C:\WINDOWS\System32\WSIMD.DLL - ok
21:36:05.0187 2968 [ 88C316A6431D1AA2B6CF3CE938863990 ] C:\WINDOWS\System32\HKCMD.EXE
21:36:05.0187 2968 C:\WINDOWS\System32\HKCMD.EXE - ok
21:36:05.0187 2968 [ BE90AD430CECC63102CACE16EB4826C9 ] C:\WINDOWS\System32\DSA.DLL
21:36:05.0187 2968 C:\WINDOWS\System32\DSA.DLL - ok
21:36:05.0203 2968 [ 2C0A7B2AE9C26F2C163627679B42783C ] C:\WINDOWS\System32\WKSSVC.DLL
21:36:05.0203 2968 C:\WINDOWS\System32\WKSSVC.DLL - ok
21:36:05.0203 2968 [ B6ACB3B2E821316D501D75113EAF51B5 ] C:\WINDOWS\System32\IGFXSRVC.EXE
21:36:05.0203 2968 C:\WINDOWS\System32\IGFXSRVC.EXE - ok
21:36:05.0218 2968 [ 5D0A442864BFBF3B19DCCA4CD29F6E99 ] C:\WINDOWS\System32\WEBCLNT.DLL
21:36:05.0218 2968 C:\WINDOWS\System32\WEBCLNT.DLL - ok
21:36:05.0218 2968 [ E1F6CB286D09A14B8749DE036374D347 ] C:\WINDOWS\System32\IGFXPERS.EXE
21:36:05.0218 2968 C:\WINDOWS\System32\IGFXPERS.EXE - ok
21:36:05.0234 2968 [ 2A8681AEA24003040CA7D677BE9F1702 ] C:\WINDOWS\System32\drivers\14613383.sys
21:36:05.0234 2968 C:\WINDOWS\System32\drivers\14613383.sys - ok
21:36:05.0234 2968 [ 96C45C3B7A6E8A5CCBCCD3784E8F6039 ] C:\Program Files\EzButton\EzButton.EXE
21:36:05.0234 2968 C:\Program Files\EzButton\EzButton.EXE - ok
21:36:05.0250 2968 [ 7623127F3D6E51F1A1EF9D581ED3E55A ] C:\Program Files\EzButton\SZUPFUTL.DLL
21:36:05.0250 2968 C:\Program Files\EzButton\SZUPFUTL.DLL - ok
21:36:05.0250 2968 [ AB228AE247A95706A0749F38582D78EF ] C:\Program Files\EzButton\OSDUTL.DLL
21:36:05.0250 2968 C:\Program Files\EzButton\OSDUTL.DLL - ok
21:36:05.0265 2968 [ 2D40BFD0E72BC5206BA4F22197907256 ] C:\WINDOWS\System32\IGFXSRVC.DLL
21:36:05.0265 2968 C:\WINDOWS\System32\IGFXSRVC.DLL - ok
21:36:05.0265 2968 [ E8FF9B447928AEB22E0FCF235E36DBF5 ] C:\Program Files\Apoint2K\Apoint.exe
21:36:05.0265 2968 C:\Program Files\Apoint2K\Apoint.exe - ok
21:36:05.0281 2968 [ 795097F63B169E2D58A2F2B278A920D8 ] C:\Program Files\EzButton\RGNMAKER.DLL
21:36:05.0281 2968 C:\Program Files\EzButton\RGNMAKER.DLL - ok
21:36:05.0281 2968 [ BA511AFC5B695F11139690885131D084 ] C:\Documents and Settings\Samhita\Local Settings\Temp\twglpmhrrkyxfwkg.exe
21:36:05.0281 2968 C:\Documents and Settings\Samhita\Local Settings\Temp\twglpmhrrkyxfwkg.exe - ok
21:36:05.0296 2968 [ AA93267F394211ED13137ADC983A5F02 ] C:\WINDOWS\System32\IGFXDEV.DLL
21:36:05.0296 2968 C:\WINDOWS\System32\IGFXDEV.DLL - ok
21:36:05.0296 2968 [ 6B770520CF06B338E1E03B60F21008CD ] C:\Program Files\EzButton\CDROMUTL.DLL
21:36:05.0296 2968 C:\Program Files\EzButton\CDROMUTL.DLL - ok
21:36:05.0312 2968 [ EF46442BE1DC9309010E01906076AEF8 ] C:\Program Files\Lenovo\EnergyCut\UTILTY.EXE
21:36:05.0312 2968 C:\Program Files\Lenovo\EnergyCut\UTILTY.EXE - ok
21:36:05.0312 2968 [ 9CD4C33E2115E4EFF7836ADA562847D6 ] C:\WINDOWS\System32\OLEDLG.DLL
21:36:05.0312 2968 C:\WINDOWS\System32\OLEDLG.DLL - ok
21:36:05.0312 2968 [ 5601639D80B365239CCFC1A731DCB9FE ] C:\Program Files\EzButton\MIXERUTL.DLL
21:36:05.0312 2968 C:\Program Files\EzButton\MIXERUTL.DLL - ok
21:36:05.0328 2968 [ 28C58901CE9B7965474E7CEF36AD5919 ] C:\Program Files\EzButton\COMFNUTL.DLL
21:36:05.0328 2968 C:\Program Files\EzButton\COMFNUTL.DLL - ok
21:36:05.0328 2968 [ B6050E962827E937AA98211495F13C0A ] C:\WINDOWS\System32\IGFXRES.DLL
21:36:05.0328 2968 C:\WINDOWS\System32\IGFXRES.DLL - ok
21:36:05.0343 2968 [ FA9B5305CDD401B1A5ACAACC994726EB ] C:\Program Files\EzButton\LGKCUTL.DLL
21:36:05.0343 2968 C:\Program Files\EzButton\LGKCUTL.DLL - ok
21:36:05.0343 2968 [ A94397F5710E49ECC51CABC6EF33097F ] C:\Program Files\EzButton\WND2FILE.DLL
21:36:05.0343 2968 C:\Program Files\EzButton\WND2FILE.DLL - ok
21:36:05.0343 2968 [ 02FF1061B635D8D0D2B96D37A40C8F5C ] C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe
21:36:05.0343 2968 C:\Program Files\Lenovo\EnergyCut\EnergyCut.exe - ok
21:36:05.0359 2968 [ C67951E42A9882CBA5D7E179D4055048 ] C:\WINDOWS\System32\Vxdif.dll
21:36:05.0359 2968 C:\WINDOWS\System32\Vxdif.dll - ok
21:36:05.0359 2968 [ F0F356AF63C0693058D9905C1B14B701 ] C:\WINDOWS\System32\IGFXRESS.DLL
21:36:05.0359 2968 C:\WINDOWS\System32\IGFXRESS.DLL - ok
21:36:05.0375 2968 [ 53204CD212E3379AB1FEC2A38F409B78 ] C:\Program Files\EzButton\TKBARUTL.DLL
21:36:05.0375 2968 C:\Program Files\EzButton\TKBARUTL.DLL - ok
21:36:05.0375 2968 [ 7DA88947B8561E16B288E4861D8DC0E8 ] C:\Program Files\Apoint2K\Apoint.dll
21:36:05.0375 2968 C:\Program Files\Apoint2K\Apoint.dll - ok
21:36:05.0375 2968 [ 14BB715BB0752CF6D7E0404D0C9E56CF ] C:\Program Files\Apoint2K\EzAuto.dll
21:36:05.0375 2968 C:\Program Files\Apoint2K\EzAuto.dll - ok
21:36:05.0390 2968 [ 7FC644A11016EA78AD828AE1B0B8E943 ] C:\Program Files\Lenovo\EnergyCut\HookLib.dll
21:36:05.0390 2968 C:\Program Files\Lenovo\EnergyCut\HookLib.dll - ok
21:36:05.0390 2968 [ 8DC2548DC4E29386CB48DF44CEDA3982 ] C:\WINDOWS\RTHDCPL.EXE
21:36:05.0390 2968 C:\WINDOWS\RTHDCPL.EXE - ok
21:36:05.0406 2968 [ CC8915DB4E33E8FB29CA0D2DBF75306E ] C:\WINDOWS\System32\WEBCHECK.DLL
21:36:05.0406 2968 C:\WINDOWS\System32\WEBCHECK.DLL - ok
21:36:05.0406 2968 [ 55E148C01296696588EAFA425782C3E8 ] C:\WINDOWS\System32\DSOUND.DLL
21:36:05.0406 2968 C:\WINDOWS\System32\DSOUND.DLL - ok
21:36:05.0406 2968 [ 4E6EEEA8EB9302D604603D4758C05E75 ] C:\WINDOWS\System32\BATMETER.DLL
21:36:05.0406 2968 C:\WINDOWS\System32\BATMETER.DLL - ok
21:36:05.0421 2968 [ 297101A925ECFFDCDF7F6341FFBB6C1A ] C:\WINDOWS\System32\STOBJECT.DLL
21:36:05.0421 2968 C:\WINDOWS\System32\STOBJECT.DLL - ok
21:36:05.0421 2968 [ 81D3F22F018C189FDC8B369B6EE090E2 ] C:\WINDOWS\System32\HHCTRL.OCX
21:36:05.0421 2968 C:\WINDOWS\System32\HHCTRL.OCX - ok
21:36:05.0437 2968 [ FE821F6FA60E9DF9FDEE69A23488BBAB ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
21:36:05.0437 2968 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe - ok
21:36:05.0437 2968 [ 6E205319848B8AF2A0DA52B8D63DB91E ] C:\WINDOWS\System32\SENSAPI.DLL
21:36:05.0437 2968 C:\WINDOWS\System32\SENSAPI.DLL - ok
21:36:05.0453 2968 [ CCA1B81492B40890E44B2B20A780EE1F ] C:\Program Files\Apoint2K\ApntEx.exe
21:36:05.0453 2968 C:\Program Files\Apoint2K\ApntEx.exe - ok
21:36:05.0453 2968 [ 12916E0642E92561C98B18A2A2D01B14 ] C:\Program Files\Common Files\Java\Java Update\JUSCHED.EXE
21:36:05.0453 2968 C:\Program Files\Common Files\Java\Java Update\JUSCHED.EXE - ok
21:36:05.0468 2968 [ 46F09758992F28966196D48F2B81D17D ] C:\ComboFix\CF6148.3XE
21:36:05.0468 2968 C:\ComboFix\CF6148.3XE - ok
21:36:05.0468 2968 [ 24232996A38C0B0CF151C2140AE29FC8 ] C:\WINDOWS\System32\ctfmon.exe
21:36:05.0468 2968 C:\WINDOWS\System32\ctfmon.exe - ok
21:36:05.0468 2968 [ CE489E8D071E93CAE63E025A54D0CE19 ] C:\WINDOWS\System32\MSCTF.DLL
21:36:05.0468 2968 C:\WINDOWS\System32\MSCTF.DLL - ok
21:36:05.0484 2968 [ 2D4B95800065EE32D21F46423D410DBE ] C:\Program Files\Lenovo\EnergyCut\KbdHook.dll
21:36:05.0484 2968 C:\Program Files\Lenovo\EnergyCut\KbdHook.dll - ok
21:36:05.0484 2968 [ 9EEA0CA999A33C9D2EABE82E4C624CC3 ] C:\WINDOWS\System32\MSUTB.dll
21:36:05.0484 2968 C:\WINDOWS\System32\MSUTB.dll - ok
21:36:05.0500 2968 [ DA23A12845607133ACF1DB3502D4E575 ] C:\WINDOWS\System32\MSISIP.DLL
21:36:05.0500 2968 C:\WINDOWS\System32\MSISIP.DLL - ok
21:36:05.0500 2968 [ 1905F39172A4864F8ABAD9337BDCAD22 ] C:\WINDOWS\System32\WSHEXT.DLL
21:36:05.0500 2968 C:\WINDOWS\System32\WSHEXT.DLL - ok
21:36:05.0515 2968 [ 58B8702C20DE211D1FCB248D2FDD71D1 ] C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe
21:36:05.0515 2968 C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe - ok
21:36:05.0515 2968 [ 4602907535FD682195DFFF9117365826 ] C:\WINDOWS\System32\MFC42.DLL
21:36:05.0515 2968 C:\WINDOWS\System32\MFC42.DLL - ok
21:36:05.0531 2968 [ E3C817F7FE44CC870ECDBCBC3EA36132 ] C:\WINDOWS\System32\MSVCP100.DLL
21:36:05.0531 2968 C:\WINDOWS\System32\MSVCP100.DLL - ok
21:36:05.0531 2968 [ 4038EE8AC13C15A067536D292A93D697 ] C:\WINDOWS\IME\sptip.dll
21:36:05.0531 2968 C:\WINDOWS\IME\sptip.dll - ok
21:36:05.0531 2968 [ BF38660A9125935658CFA3E53FDC7D65 ] C:\WINDOWS\System32\MSVCR100.DLL
21:36:05.0531 2968 C:\WINDOWS\System32\MSVCR100.DLL - ok
21:36:05.0546 2968 [ F0B0D86C7E5CE1781BB92F300169A257 ] C:\Program Files\Microsoft Office\OFFICE11\MCPS.DLL
21:36:05.0546 2968 C:\Program Files\Microsoft Office\OFFICE11\MCPS.DLL - ok
21:36:05.0546 2968 [ 787FA787CF109F10286F9DFA072A01D2 ] C:\Program Files\Apoint2K\EzLaunch.dll
21:36:05.0546 2968 C:\Program Files\Apoint2K\EzLaunch.dll - ok
21:36:05.0562 2968 [ E9069F5FAC8075F6FECC5FD36D87F18D ] C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe
21:36:05.0562 2968 C:\Program Files\Lenovo\Bluetooth Software\BTTray.exe - ok
21:36:05.0562 2968 [ D8B22C220344D03850BA674E85F4AD08 ] C:\WINDOWS\System32\WBTAPI.DLL
21:36:05.0562 2968 C:\WINDOWS\System32\WBTAPI.DLL - ok
21:36:05.0578 2968 [ 7EF8B4C5EA211DE0765052B0B8A3D5CB ] C:\WINDOWS\System32\BTOSIF.DLL
21:36:05.0578 2968 C:\WINDOWS\System32\BTOSIF.DLL - ok
21:36:05.0578 2968 [ 3EA330E8B0F70216BDE5ECE077C657C6 ] C:\WINDOWS\System32\BTWHIDCS.DLL
21:36:05.0578 2968 C:\WINDOWS\System32\BTWHIDCS.DLL - ok
21:36:05.0578 2968 [ 10250765DE4486A02A689ED88AC69422 ] C:\Program Files\Lenovo\Bluetooth Software\BtBalloon.dll
21:36:05.0593 2968 C:\Program Files\Lenovo\Bluetooth Software\BtBalloon.dll - ok
21:36:05.0593 2968 [ 273F09A32B4B513DC45022412B3729BC ] C:\WINDOWS\System32\BTREZ.DLL
21:36:05.0593 2968 C:\WINDOWS\System32\BTREZ.DLL - ok
21:36:05.0593 2968 [ CBCD254547689BFF80C9F547B20911E9 ] C:\WINDOWS\System32\KSUSER.DLL
21:36:05.0593 2968 C:\WINDOWS\System32\KSUSER.DLL - ok
21:36:05.0609 2968 [ 5C1EDF4C541E45D139FCB179AB980BA6 ] C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe
21:36:05.0609 2968 C:\Program Files\Lenovo\Bluetooth Software\BTStackServer.exe - ok
21:36:05.0609 2968 [ 54BA9B6F6ABDF4FB2D817BCA1B40B4B4 ] C:\WINDOWS\System32\BTINS.DLL
21:36:05.0609 2968 C:\WINDOWS\System32\BTINS.DLL - ok
21:36:05.0625 2968 [ E68848FA772F1356A5D6A300DD87C0AD ] C:\Program Files\Lenovo\Bluetooth Software\BTKeyInd.dll
21:36:05.0625 2968 C:\Program Files\Lenovo\Bluetooth Software\BTKeyInd.dll - ok
21:36:05.0625 2968 [ 31BB21CB8BD1D597810A5100049F15BE ] C:\WINDOWS\System32\BtMmHook.dll
21:36:05.0625 2968 C:\WINDOWS\System32\BtMmHook.dll - ok
21:36:05.0640 2968 [ 17F62311923696258B6CF9B2BE27E0C1 ] C:\WINDOWS\System32\BtAudioHelper.dll
21:36:05.0640 2968 C:\WINDOWS\System32\BtAudioHelper.dll - ok
21:36:05.0640 2968 [ B6ADDB78E953507C8C2269B737B824CE ] C:\WINDOWS\System32\btosif_ol.dll
21:36:05.0640 2968 C:\WINDOWS\System32\btosif_ol.dll - ok
21:36:05.0656 2968 [ 874ECC18F2ADBAE2AE2B0C658C4DF300 ] C:\WINDOWS\System32\btosif_olx.dll
21:36:05.0656 2968 C:\WINDOWS\System32\btosif_olx.dll - ok
21:36:05.0656 2968 [ E81BBE78A8EF85ACD490B3E64EF63A7C ] C:\WINDOWS\System32\MAPI32.DLL
21:36:05.0656 2968 C:\WINDOWS\System32\MAPI32.DLL - ok
21:36:05.0656 2968 [ DD675273543037E4D8A43B850810308E ] C:\WINDOWS\System32\btosif_notes.dll
21:36:05.0656 2968 C:\WINDOWS\System32\btosif_notes.dll - ok
21:36:05.0671 2968 [ 87B85BC1E1F6E0228876204A20A9C24C ] C:\WINDOWS\System32\SPOOLSS.DLL
21:36:05.0671 2968 C:\WINDOWS\System32\SPOOLSS.DLL - ok
21:36:05.0671 2968 [ 94D8CA96E033B54D7E23C3E4644C85AB ] C:\WINDOWS\System32\LOCALSPL.DLL
21:36:05.0671 2968 C:\WINDOWS\System32\LOCALSPL.DLL - ok
21:36:05.0687 2968 [ 7105749E78925FDFFD078DD54A8C2B70 ] C:\WINDOWS\System32\CNBJMON.DLL
21:36:05.0687 2968 C:\WINDOWS\System32\CNBJMON.DLL - ok
21:36:05.0687 2968 [ E4178B1B92D1FF4A3C1B69AC628093F6 ] C:\WINDOWS\System32\BTHCRP.DLL
21:36:05.0687 2968 C:\WINDOWS\System32\BTHCRP.DLL - ok
21:36:05.0703 2968 [ EA456E3B07C9B0899D59D83D399B9963 ] C:\WINDOWS\System32\WidcommSdk.dll
21:36:05.0703 2968 C:\WINDOWS\System32\WidcommSdk.dll - ok
21:36:05.0703 2968 [ 58C8D45C571AA9235FB296B383B89887 ] C:\WINDOWS\System32\CPWMON2K.DLL
21:36:05.0703 2968 C:\WINDOWS\System32\CPWMON2K.DLL - ok
21:36:05.0718 2968 [ CF0376023360AADD55C89BA50564AFDC ] C:\WINDOWS\System32\MDIMON.DLL
21:36:05.0718 2968 C:\WINDOWS\System32\MDIMON.DLL - ok
21:36:05.0718 2968 [ C44BC10BA73575C91FF50CDAF4D8E370 ] C:\WINDOWS\System32\PJLMON.DLL
21:36:05.0718 2968 C:\WINDOWS\System32\PJLMON.DLL - ok
21:36:05.0718 2968 [ A3F853629F7F2537157EA6EA9857EA56 ] C:\WINDOWS\System32\TCPMON.DLL
21:36:05.0718 2968 C:\WINDOWS\System32\TCPMON.DLL - ok
21:36:05.0734 2968 [ 242D07D7FC72AD897944BFF932D57C3C ] C:\WINDOWS\System32\USBMON.DLL
21:36:05.0734 2968 C:\WINDOWS\System32\USBMON.DLL - ok
21:36:05.0734 2968 [ 58E13A2292839321D3CDC918D5A4F5AE ] C:\WINDOWS\System32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
21:36:05.0734 2968 C:\WINDOWS\System32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL - ok
21:36:05.0750 2968 [ A1C10F87248529173F39F4B4734DF14B ] C:\WINDOWS\System32\WIN32SPL.DLL
21:36:05.0750 2968 C:\WINDOWS\System32\WIN32SPL.DLL - ok
21:36:05.0750 2968 [ 84A5644AE4731202A4A02E6342D29BA6 ] C:\WINDOWS\System32\NETRAP.DLL
21:36:05.0750 2968 C:\WINDOWS\System32\NETRAP.DLL - ok
21:36:05.0765 2968 [ F14A6BD840E4D7CD4C0535CB3CEF2887 ] C:\WINDOWS\System32\INETPP.DLL
21:36:05.0765 2968 C:\WINDOWS\System32\INETPP.DLL - ok
21:36:05.0765 2968 [ D7BB5232ABB80AAA92D05B22850995E2 ] C:\WINDOWS\System32\BTDEV.DLL
21:36:05.0765 2968 C:\WINDOWS\System32\BTDEV.DLL - ok
21:36:05.0765 2968 [ 29744EB4CE659DFE3B4122DEB45BC478 ] C:\WINDOWS\System32\drivers\PARPORT.SYS
21:36:05.0765 2968 C:\WINDOWS\System32\drivers\PARPORT.SYS - ok
21:36:05.0781 2968 [ CD9404D115A00D249F70A371B46D5A26 ] C:\WINDOWS\System32\drivers\SERIAL.SYS
21:36:05.0781 2968 C:\WINDOWS\System32\drivers\SERIAL.SYS - ok
21:36:05.0781 2968 [ C5A75EB48E2344ABDC162BDA79E16841 ] C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\MSCORSVW.EXE
21:36:05.0781 2968 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\MSCORSVW.EXE - ok
21:36:05.0796 2968 [ E5F7C30EDF0892667933BE879F067D67 ] C:\WINDOWS\System32\msvcr100_clr0400.dll
21:36:05.0796 2968 C:\WINDOWS\System32\msvcr100_clr0400.dll - ok
21:36:05.0796 2968 [ B04DB1F0B2652FCBCCC5FD0C46579F0F ] C:\WINDOWS\System32\MSCOREE.DLL
21:36:05.0796 2968 C:\WINDOWS\System32\MSCOREE.DLL - ok
21:36:05.0796 2968 [ 5C918D413F5837E67A85775C9873775E ] C:\Program Files\EzButton\DPortIO.sys
21:36:05.0796 2968 C:\Program Files\EzButton\DPortIO.sys - ok
21:36:05.0812 2968 [ 10654F9DDCEA9C46CFB77554231BE73B ] C:\WINDOWS\System32\CRYPTSVC.DLL
21:36:05.0812 2968 C:\WINDOWS\System32\CRYPTSVC.DLL - ok
21:36:05.0812 2968 [ AD44C5BC21213F394F6AFCB55CC39293 ] C:\WINDOWS\System32\CERTCLI.DLL
21:36:05.0812 2968 C:\WINDOWS\System32\CERTCLI.DLL - ok
21:36:05.0828 2968 [ E956C0614367D4106A4411F151D494A5 ] C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe
21:36:05.0828 2968 C:\Documents and Settings\All Users\Application Data\DatacardService\HWDeviceService.exe - ok
21:36:05.0828 2968 [ 1639D9964C9E1B2ECCA95C8217D3E70D ] C:\WINDOWS\System32\DMSERVER.DLL
21:36:05.0828 2968 C:\WINDOWS\System32\DMSERVER.DLL - ok
21:36:05.0828 2968 [ 67DFF7BBBD0E80AAB7B3CF061448DB8A ] C:\WINDOWS\System32\ERSVC.DLL
21:36:05.0828 2968 C:\WINDOWS\System32\ERSVC.DLL - ok
21:36:05.0843 2968 [ 6AD7DFD0BB21CE2A95D34A346C4B537B ] C:\WINDOWS\System32\ES.DLL
21:36:05.0843 2968 C:\WINDOWS\System32\ES.DLL - ok
21:36:05.0843 2968 [ B591E761161D1EF547D76EF236EAA6A5 ] C:\Program Files\Java\JRE7\BIN\JQS.EXE
21:36:05.0843 2968 C:\Program Files\Java\JRE7\BIN\JQS.EXE - ok
21:36:05.0859 2968 [ 67EC459E42D3081DD8FD34356F7CAFC1 ] C:\Program Files\Java\JRE7\BIN\MSVCR100.DLL
21:36:05.0859 2968 C:\Program Files\Java\JRE7\BIN\MSVCR100.DLL - ok
21:36:05.0859 2968 [ 8827911A8C37E40C027CBFC88E69D967 ] C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHSVC.DLL
21:36:05.0859 2968 C:\WINDOWS\PCHEALTH\HELPCTR\BINARIES\PCHSVC.DLL - ok
21:36:05.0875 2968 [ 4A9258B9597A31DB68EC9740F3A8A70B ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvcHst.exe
21:36:05.0875 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvcHst.exe - ok
21:36:05.0875 2968 [ E3C817F7FE44CC870ECDBCBC3EA36132 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\MSVCP100.DLL
21:36:05.0875 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\MSVCP100.DLL - ok
21:36:05.0875 2968 [ 4E9EA6CC8DB8DCEF7FB37F2C9B4CC556 ] C:\WINDOWS\System32\SRVSVC.DLL
21:36:05.0875 2968 C:\WINDOWS\System32\SRVSVC.DLL - ok
21:36:05.0890 2968 [ 20FD44370267CCD0A64A1B31861C21D2 ] C:\WINDOWS\System32\NETMSG.DLL
21:36:05.0890 2968 C:\WINDOWS\System32\NETMSG.DLL - ok
21:36:05.0890 2968 [ BF38660A9125935658CFA3E53FDC7D65 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\MSVCR100.DLL
21:36:05.0890 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\MSVCR100.DLL - ok
21:36:05.0906 2968 [ 54E79B08D0ABC9C551D0FE69CC2F87EC ] C:\WINDOWS\System32\drivers\SRV.SYS
21:36:05.0906 2968 C:\WINDOWS\System32\drivers\SRV.SYS - ok
21:36:05.0906 2968 [ 947D20D286D8C8D9405158DD13EC7D00 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccL120U.dll
21:36:05.0906 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccL120U.dll - ok
21:36:05.0921 2968 [ 6479A184873F7CA797FF0375D711E9A6 ] C:\WINDOWS\System32\DBGHELP.DLL
21:36:05.0921 2968 C:\WINDOWS\System32\DBGHELP.DLL - ok
21:36:05.0921 2968 [ 2C148C79EEDCD3AB9830E8B66413A891 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccVrTrst.dll
21:36:05.0921 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccVrTrst.dll - ok
21:36:05.0937 2968 [ 296B4C4BF16C4DFAB2DD72D60459C223 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\EFACli.dll
21:36:05.0937 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\EFACli.dll - ok
21:36:05.0937 2968 [ 4A9258B9597A31DB68EC9740F3A8A70B ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSvcHst.exe
21:36:05.0937 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSvcHst.exe - ok
21:36:05.0953 2968 [ E3C817F7FE44CC870ECDBCBC3EA36132 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\MSVCP100.DLL
21:36:05.0953 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\MSVCP100.DLL - ok
21:36:05.0953 2968 [ 42500A9FC8D6A025CF2D839053A240DE ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvc.dll
21:36:05.0953 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSvc.dll - ok
21:36:05.0968 2968 [ 2393B4D684AF9E3FBD26C37ACF7FB629 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\Srtsp32.dll
21:36:05.0968 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\Srtsp32.dll - ok
21:36:05.0968 2968 [ BF38660A9125935658CFA3E53FDC7D65 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\MSVCR100.DLL
21:36:05.0968 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\MSVCR100.DLL - ok
21:36:05.0968 2968 [ A21C2A8E47D40FCC40A2B1573E666A53 ] C:\Program Files\Java\JRE7\BIN\AWT.DLL
21:36:05.0968 2968 C:\Program Files\Java\JRE7\BIN\AWT.DLL - ok
21:36:05.0984 2968 [ 6DC6C59DCBD3AB604A9F3703BE770790 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccIPC.dll
21:36:05.0984 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccIPC.dll - ok
21:36:05.0984 2968 [ 8F1DE0C717BEE342D9838C6A9E78DA6B ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\diMaster.dll
21:36:05.0984 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\diMaster.dll - ok
21:36:06.0000 2968 [ 947D20D286D8C8D9405158DD13EC7D00 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccL120U.dll
21:36:06.0000 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccL120U.dll - ok
21:36:06.0000 2968 [ 966CD21542A62F9AB237D84C451CC137 ] C:\Program Files\Java\JRE7\BIN\CLIENT\JVM.DLL
21:36:06.0000 2968 C:\Program Files\Java\JRE7\BIN\CLIENT\JVM.DLL - ok
21:36:06.0015 2968 [ 5EF95EC020E8772D12742A74F235DE4B ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSet.dll
21:36:06.0015 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ccSet.dll - ok
21:36:06.0015 2968 [ 8B09F292C71D2BEDDEEF3C5466D42A6C ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ISDataSv.dll
21:36:06.0015 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\ISDataSv.dll - ok
21:36:06.0031 2968 [ 378D2F34B3E266BC15A54DD3A7664614 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\isDataPr.dll
21:36:06.0031 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\isDataPr.dll - ok
21:36:06.0031 2968 [ 2C148C79EEDCD3AB9830E8B66413A891 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccVrTrst.dll
21:36:06.0031 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccVrTrst.dll - ok
21:36:06.0046 2968 [ B2D922BAD7C686B88FA871042311F7C7 ] C:\WINDOWS\System32\IPSECSVC.DLL
21:36:06.0046 2968 C:\WINDOWS\System32\IPSECSVC.DLL - ok
21:36:06.0046 2968 [ A76128BE63EEA6A3AF521A0576D3EBF7 ] C:\WINDOWS\System32\OAKLEY.DLL
21:36:06.0046 2968 C:\WINDOWS\System32\OAKLEY.DLL - ok
21:36:06.0062 2968 [ 2B2F31E3F2CE3723C1B0F3700C8BE28B ] C:\WINDOWS\System32\WINIPSEC.DLL
21:36:06.0062 2968 C:\WINDOWS\System32\WINIPSEC.DLL - ok
21:36:06.0062 2968 [ 306B30A036DB25FCB76B507FEDE07D58 ] C:\WINDOWS\System32\PSTORSVC.DLL
21:36:06.0062 2968 C:\WINDOWS\System32\PSTORSVC.DLL - ok
21:36:06.0062 2968 [ 07F7F501AD50DE2BA2D5842D9B6D6155 ] C:\WINDOWS\System32\drivers\SECDRV.SYS
21:36:06.0062 2968 C:\WINDOWS\System32\drivers\SECDRV.SYS - ok
21:36:06.0078 2968 [ 4D3CCDF22D2B4BAE229BA73B81D13E26 ] C:\WINDOWS\System32\PSBASE.DLL
21:36:06.0078 2968 C:\WINDOWS\System32\PSBASE.DLL - ok
21:36:06.0078 2968 [ 335FF3E253F33D774BE397DBC8BDD654 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\NPCTray.dll
21:36:06.0078 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\NPCTray.dll - ok
21:36:06.0093 2968 [ CACD2C63A79268D131EA37E85524CC44 ] C:\WINDOWS\System32\DSSENH.DLL
21:36:06.0093 2968 C:\WINDOWS\System32\DSSENH.DLL - ok
21:36:06.0093 2968 [ 3151427DB7D87107D1C5BE58FAC53960 ] C:\WINDOWS\System32\REGSVC.DLL
21:36:06.0093 2968 C:\WINDOWS\System32\REGSVC.DLL - ok
21:36:06.0093 2968 [ DE955485DF0140A80C079C925EA1F961 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\uiMain.dll
21:36:06.0093 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\uiMain.dll - ok
21:36:06.0109 2968 [ 42500A9FC8D6A025CF2D839053A240DE ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSvc.dll
21:36:06.0109 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSvc.dll - ok
21:36:06.0109 2968 [ D67BDBBDA86CC9AEEBBAF3217C1717D8 ] C:\WINDOWS\System32\D3D9.DLL
21:36:06.0109 2968 C:\WINDOWS\System32\D3D9.DLL - ok
21:36:06.0125 2968 [ 6DC6C59DCBD3AB604A9F3703BE770790 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccIPC.dll
21:36:06.0125 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccIPC.dll - ok
21:36:06.0125 2968 [ 90760987BCCCF34D05EF6093EC278A96 ] C:\Program Files\Java\JRE7\BIN\DCPR.DLL
21:36:06.0125 2968 C:\Program Files\Java\JRE7\BIN\DCPR.DLL - ok
21:36:06.0140 2968 [ CAD4AA32E7ECA00C23CC39C0EB833F9D ] C:\WINDOWS\System32\CRYPTNET.DLL
21:36:06.0140 2968 C:\WINDOWS\System32\CRYPTNET.DLL - ok
21:36:06.0140 2968 [ 08F0190AE201EC331B4CA3B0FA2D2CCE ] C:\WINDOWS\System32\CABINET.DLL
21:36:06.0140 2968 C:\WINDOWS\System32\CABINET.DLL - ok
21:36:06.0140 2968 [ B1E0CE09895376871746F36DC5773B4F ] C:\WINDOWS\System32\SECLOGON.DLL
21:36:06.0140 2968 C:\WINDOWS\System32\SECLOGON.DLL - ok
21:36:06.0156 2968 [ D2D31D7A394A70040FCAC5F54A130FBA ] C:\Program Files\Java\JRE7\BIN\DEPLOY.DLL
21:36:06.0156 2968 C:\Program Files\Java\JRE7\BIN\DEPLOY.DLL - ok
21:36:06.0156 2968 [ 8F1DE0C717BEE342D9838C6A9E78DA6B ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\diMaster.dll
21:36:06.0156 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\diMaster.dll - ok
21:36:06.0171 2968 [ 5EF95EC020E8772D12742A74F235DE4B ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSet.dll
21:36:06.0171 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSet.dll - ok
21:36:06.0171 2968 [ C09775FEB73BDF16BB87A509C5FF12AD ] C:\Program Files\Java\JRE7\BIN\fontmanager.dll
21:36:06.0171 2968 C:\Program Files\Java\JRE7\BIN\fontmanager.dll - ok
21:36:06.0187 2968 [ 38037E0B9A784759C6571B70686E2E48 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coSvcPlg.dll
21:36:06.0187 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coSvcPlg.dll - ok
21:36:06.0187 2968 [ 8D9210E9858D525646251DFA1FE37EBE ] C:\WINDOWS\System32\D3D8THK.DLL
21:36:06.0187 2968 C:\WINDOWS\System32\D3D8THK.DLL - ok
21:36:06.0203 2968 [ DFD9870CF39C791D86C4C209DA9FA919 ] C:\WINDOWS\System32\SENS.DLL
21:36:06.0203 2968 C:\WINDOWS\System32\SENS.DLL - ok
21:36:06.0203 2968 [ 48E33D9B6C2E9ED45E3E63ECBCED2941 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccGEvt.dll
21:36:06.0203 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccGEvt.dll - ok
21:36:06.0218 2968 [ B98F28229D292B99FF449FF3647F31BA ] C:\Program Files\Java\JRE7\BIN\JAVA.DLL
21:36:06.0218 2968 C:\Program Files\Java\JRE7\BIN\JAVA.DLL - ok
21:36:06.0218 2968 [ 102008784225A3DEB2709626B82D43B6 ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\SymHTML.dll
21:36:06.0218 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\SymHTML.dll - ok
21:36:06.0234 2968 [ 130EA63F8E1760FDB1A0FF5368610F36 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccGLog.dll
21:36:06.0234 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccGLog.dll - ok
21:36:06.0234 2968 [ 4415A44671D23575BDD4409A3ED844D6 ] C:\WINDOWS\System32\BTNCopy.dll
21:36:06.0234 2968 C:\WINDOWS\System32\BTNCopy.dll - ok
21:36:06.0234 2968 [ 23C84DBECF3BD95687623F23BCD66441 ] C:\Program Files\Java\JRE7\BIN\JAVAW.EXE
21:36:06.0234 2968 C:\Program Files\Java\JRE7\BIN\JAVAW.EXE - ok
21:36:06.0250 2968 [ DD6D5ABAD9B8C13CEDA4752370BA982C ] C:\WINDOWS\System32\MYDOCS.DLL
21:36:06.0250 2968 C:\WINDOWS\System32\MYDOCS.DLL - ok
21:36:06.0250 2968 [ 92BDF74F12D6CBEC43C94D4B7F804838 ] C:\WINDOWS\System32\SRSVC.DLL
21:36:06.0250 2968 C:\WINDOWS\System32\SRSVC.DLL - ok
21:36:06.0265 2968 [ 0384126B913AC2E090804C642302945E ] C:\Program Files\Java\JRE7\BIN\jp2native.dll
21:36:06.0265 2968 C:\Program Files\Java\JRE7\BIN\jp2native.dll - ok
21:36:06.0265 2968 [ 5B5F77CFC1D2AD465A4639259BD2C937 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccJobMgr.dll
21:36:06.0265 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccJobMgr.dll - ok
21:36:06.0281 2968 [ 5848CACC81F3C081EC43967DD4B51D74 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSubEng.dll
21:36:06.0281 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccSubEng.dll - ok
21:36:06.0281 2968 [ E0C464D663F4D362F619120BBC0F6AAC ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccEmlPxy.dll
21:36:06.0281 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ccEmlPxy.dll - ok
21:36:06.0281 2968 [ 6A30447888A32EC1E789B512F17E2AEB ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\SpocClnt.dll
21:36:06.0281 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\SpocClnt.dll - ok
21:36:06.0296 2968 [ CA0D17C1DD55F0832F405FBC4E8B8849 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\DataStor.dll
21:36:06.0296 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\DataStor.dll - ok
21:36:06.0296 2968 [ 5273DB2A6847CD2DC49C172FF1CF02D5 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coFFPlgn.dll
21:36:06.0296 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coFFPlgn.dll - ok
21:36:06.0312 2968 [ CB91CCFA95601066772A004550B55A85 ] C:\Program Files\Java\JRE7\BIN\JPEG.DLL
21:36:06.0312 2968 C:\Program Files\Java\JRE7\BIN\JPEG.DLL - ok
21:36:06.0312 2968 [ 1EB1EC4C57B8DDBB9598FC040D4C75B2 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\SQLite.dll
21:36:06.0312 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\SQLite.dll - ok
21:36:06.0328 2968 [ D91EE56D00661C87EE7DEB547093CC9E ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\Comm.dll
21:36:06.0328 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\Comm.dll - ok
21:36:06.0328 2968 [ 2E4A927544CDA0279501AA757FFFB538 ] C:\Program Files\Java\JRE7\BIN\net.dll
21:36:06.0328 2968 C:\Program Files\Java\JRE7\BIN\net.dll - ok
21:36:06.0343 2968 [ C916116D04CEEFCEF1B5A046123E431C ] C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\diStRptr.dll
21:36:06.0343 2968 C:\Program Files\Norton AntiVirus\Engine\20.2.0.19\diStRptr.dll - ok
21:36:06.0343 2968 [ F3F38AC8D5C1C35CFA48A597ECBB1290 ] C:\WINDOWS\System32\WindowsCodecs.dll
21:36:06.0343 2968 C:\WINDOWS\System32\WindowsCodecs.dll - ok
21:36:06.0359 2968 [ 805766A11E747A44C7C5FBD7F26E9001 ] C:\Program Files\Java\JRE7\BIN\nio.dll
21:36:06.0359 2968 C:\Program Files\Java\JRE7\BIN\nio.dll - ok
21:36:06.0359 2968 [ 556241BBC3F4B22EAFB5FE301824A0B7 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coDataPr.dll
21:36:06.0359 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coDataPr.dll - ok
21:36:06.0359 2968 [ 2D168A9627CFCE9C5AC20A90E54D66D4 ] C:\Program Files\Java\JRE7\BIN\verify.dll
21:36:06.0359 2968 C:\Program Files\Java\JRE7\BIN\verify.dll - ok
21:36:06.0375 2968 [ C76DD749BFD788CE22557EA0CA009332 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coShdObj.dll
21:36:06.0375 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coShdObj.dll - ok
21:36:06.0375 2968 [ 9D54D4A8C18081F398FEC0D839340542 ] C:\Program Files\Java\JRE7\BIN\zip.dll
21:36:06.0375 2968 C:\Program Files\Java\JRE7\BIN\zip.dll - ok
21:36:06.0390 2968 [ 6D9AC544B30F96C57F8206566C1FB6A1 ] C:\WINDOWS\System32\TRKWKS.DLL
21:36:06.0390 2968 C:\WINDOWS\System32\TRKWKS.DLL - ok
21:36:06.0390 2968 [ D9F6C4F6B1E188ADAFC42B561D9BC2E6 ] C:\WINDOWS\System32\WIASERVC.DLL
21:36:06.0390 2968 C:\WINDOWS\System32\WIASERVC.DLL - ok
21:36:06.0406 2968 [ 9A946A4680CB90EF22D403493482B4AF ] C:\WINDOWS\System32\MSCMS.DLL
21:36:06.0406 2968 C:\WINDOWS\System32\MSCMS.DLL - ok
21:36:06.0406 2968 [ 13D72740963CBA12D9FF76A7F218BCD8 ] C:\WINDOWS\System32\WUAUSERV.DLL
21:36:06.0406 2968 C:\WINDOWS\System32\WUAUSERV.DLL - ok
21:36:06.0406 2968 [ 61FDDD18F95B1EBE5447DDF4AF48B8E3 ] C:\WINDOWS\System32\WUAUENG.DLL
21:36:06.0406 2968 C:\WINDOWS\System32\WUAUENG.DLL - ok
21:36:06.0421 2968 [ 7446F60479ACD132F142FECDE892D81E ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ProxyClt.dll
21:36:06.0421 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\ProxyClt.dll - ok
21:36:06.0421 2968 [ 8FED1E0A491D4990853D23F21C59C730 ] C:\WINDOWS\System32\ADVPACK.DLL
21:36:06.0421 2968 C:\WINDOWS\System32\ADVPACK.DLL - ok
21:36:06.0437 2968 [ 7C8F371C924DAA376217E553378275BA ] C:\WINDOWS\System32\SHFOLDER.DLL
21:36:06.0437 2968 C:\WINDOWS\System32\SHFOLDER.DLL - ok
21:36:06.0437 2968 [ 7EB8D9157EFBBBAF1F0EEC2C01980B53 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coActMgr.dll
21:36:06.0437 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\coActMgr.dll - ok
21:36:06.0453 2968 [ 45D5610E63EA3EAFCE94B12EC3F3EF7E ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\wincfi39.dll
21:36:06.0453 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\wincfi39.dll - ok
21:36:06.0453 2968 [ 633C197292B4051D986903827DE561A3 ] C:\WINDOWS\System32\MSPATCHA.DLL
21:36:06.0453 2968 C:\WINDOWS\System32\MSPATCHA.DLL - ok
21:36:06.0453 2968 [ E3CFCCDDA4EDD1D0DC9168B2E18F27B8 ] C:\WINDOWS\System32\BROWSER.DLL
21:36:06.0453 2968 C:\WINDOWS\System32\BROWSER.DLL - ok
21:36:06.0468 2968 [ 431E6D5DF08187278EFC5911640155BE ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2695_x-ww_54a6ed4b\GdiPlus.dll
21:36:06.0468 2968 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.2695_x-ww_54a6ed4b\GdiPlus.dll - ok
21:36:06.0468 2968 [ F399242A80C4066FD155EFA4CF96658E ] C:\WINDOWS\System32\WBEM\WMISVC.DLL
21:36:06.0484 2968 C:\WINDOWS\System32\WBEM\WMISVC.DLL - ok
21:36:06.0484 2968 [ 79DABB124D00ADF19852AE879C201890 ] C:\WINDOWS\System32\VSSAPI.DLL
21:36:06.0484 2968 C:\WINDOWS\System32\VSSAPI.DLL - ok
21:36:06.0484 2968 [ 36CC8C01B5E50163037BEF56CB96DEFF ] C:\WINDOWS\System32\IPNATHLP.DLL
21:36:06.0484 2968 C:\WINDOWS\System32\IPNATHLP.DLL - ok
21:36:06.0500 2968 [ 478995B4555958E52388496618D9C678 ] C:\WINDOWS\System32\WSCSVC.DLL
21:36:06.0500 2968 C:\WINDOWS\System32\WSCSVC.DLL - ok
21:36:06.0500 2968 [ 9EA9275658FB752860B46820320CD6F3 ] C:\WINDOWS\System32\COMSVCS.DLL
21:36:06.0500 2968 C:\WINDOWS\System32\COMSVCS.DLL - ok
21:36:06.0500 2968 [ 756383DA0C5943923D68A35107596765 ] C:\WINDOWS\System32\COLBACT.DLL
21:36:06.0500 2968 C:\WINDOWS\System32\COLBACT.DLL - ok
21:36:06.0515 2968 [ CAB13A9E6993FFF702CE5A56AD760BC5 ] C:\WINDOWS\System32\MTXCLU.DLL
21:36:06.0515 2968 C:\WINDOWS\System32\MTXCLU.DLL - ok
21:36:06.0515 2968 [ C916116D04CEEFCEF1B5A046123E431C ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\diStRptr.dll
21:36:06.0515 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\diStRptr.dll - ok
21:36:06.0531 2968 [ 98C1FF6676E02D43DA208802286A6EE7 ] C:\WINDOWS\System32\CLUSAPI.DLL
21:36:06.0531 2968 C:\WINDOWS\System32\CLUSAPI.DLL - ok
21:36:06.0531 2968 [ 2738C8A33FF07DD3C99C7C8F0A85DA72 ] C:\WINDOWS\System32\RESUTILS.DLL
21:36:06.0531 2968 C:\WINDOWS\System32\RESUTILS.DLL - ok
21:36:06.0546 2968 [ 851547797C2A7F8A04841644C471A567 ] C:\WINDOWS\System32\WBEM\WBEMPROX.DLL
21:36:06.0546 2968 C:\WINDOWS\System32\WBEM\WBEMPROX.DLL - ok
21:36:06.0546 2968 [ 4E39C36213E95FB971A61A247BDE2F61 ] C:\WINDOWS\System32\WBEM\WBEMCOMN.DLL
21:36:06.0546 2968 C:\WINDOWS\System32\WBEM\WBEMCOMN.DLL - ok
21:36:06.0546 2968 [ 36360B625D7290BBA2CD03AD4975E1BC ] C:\WINDOWS\System32\WBEM\WBEMCORE.DLL
21:36:06.0546 2968 C:\WINDOWS\System32\WBEM\WBEMCORE.DLL - ok
21:36:06.0562 2968 [ C8C7DE6765F98F0F5341692991F4E75E ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\cltAlDis.dll
21:36:06.0562 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\cltAlDis.dll - ok
21:36:06.0562 2968 [ DE578E4E6844954823FC7688625F00C8 ] C:\WINDOWS\System32\WBEM\ESSCLI.DLL
21:36:06.0562 2968 C:\WINDOWS\System32\WBEM\ESSCLI.DLL - ok
21:36:06.0578 2968 [ C29A5286E64D97385178452D5F307B98 ] C:\WINDOWS\System32\TERMSRV.DLL
21:36:06.0578 2968 C:\WINDOWS\System32\TERMSRV.DLL - ok
21:36:06.0578 2968 [ C28500101BC66FDABD830F8DE51A59A0 ] C:\WINDOWS\System32\WBEM\FASTPROX.DLL
21:36:06.0578 2968 C:\WINDOWS\System32\WBEM\FASTPROX.DLL - ok
21:36:06.0593 2968 [ 37E7DB460A5315E4609B212C6C014527 ] C:\WINDOWS\System32\ICAAPI.DLL
21:36:06.0593 2968 C:\WINDOWS\System32\ICAAPI.DLL - ok
21:36:06.0593 2968 [ 7D676AC8CC19341117C77C261647BA07 ] C:\WINDOWS\System32\WBEM\WBEMSVC.DLL
21:36:06.0593 2968 C:\WINDOWS\System32\WBEM\WBEMSVC.DLL - ok
21:36:06.0593 2968 [ F5EE7CACD1784241F138A5E55B715897 ] C:\WINDOWS\System32\MSTLSAPI.DLL
21:36:06.0593 2968 C:\WINDOWS\System32\MSTLSAPI.DLL - ok
21:36:06.0609 2968 [ 0A1161DB4FCCF7821736C70D70A0F5A3 ] C:\WINDOWS\System32\WBEM\WMIUTILS.DLL
21:36:06.0609 2968 C:\WINDOWS\System32\WBEM\WMIUTILS.DLL - ok
21:36:06.0609 2968 [ 9A66728EFE501D855D0FFE3DE023CE32 ] C:\WINDOWS\System32\WBEM\REPDRVFS.DLL
21:36:06.0609 2968 C:\WINDOWS\System32\WBEM\REPDRVFS.DLL - ok
21:36:06.0625 2968 [ FA788520BCAC0F5D9D5CDE5615C0D931 ] C:\WINDOWS\System32\IMAPI.EXE
21:36:06.0625 2968 C:\WINDOWS\System32\IMAPI.EXE - ok
21:36:06.0625 2968 [ 339089D6C3FC3BC5CED8D9049C4D2101 ] C:\WINDOWS\System32\UPNP.DLL
21:36:06.0625 2968 C:\WINDOWS\System32\UPNP.DLL - ok
21:36:06.0625 2968 [ 5B8DFA748FA4845BC04445A30126F2E9 ] C:\WINDOWS\System32\SSDPAPI.DLL
21:36:06.0625 2968 C:\WINDOWS\System32\SSDPAPI.DLL - ok
21:36:06.0640 2968 [ 1F080CCC567D222A2DCB7CC285C6A7AD ] C:\WINDOWS\System32\WBEM\WMIPRVSD.DLL
21:36:06.0640 2968 C:\WINDOWS\System32\WBEM\WMIPRVSD.DLL - ok
21:36:06.0640 2968 [ 3247A2DB333D1521680E6864A8295A47 ] C:\WINDOWS\System32\drivers\HTTP.SYS
21:36:06.0640 2968 C:\WINDOWS\System32\drivers\HTTP.SYS - ok
21:36:06.0656 2968 [ 9630EB50A7A90F8FB628C391D10ED7A7 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\cltPE.dll
21:36:06.0656 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\cltPE.dll - ok
21:36:06.0656 2968 [ 4B8D61792F7175BED48859CC18CE4E38 ] C:\WINDOWS\System32\ssdpsrv.dll
21:36:06.0656 2968 C:\WINDOWS\System32\ssdpsrv.dll - ok
21:36:06.0656 2968 [ 1418A3A6E76E5A2E3F5E43866E793A8B ] C:\WINDOWS\System32\tapisrv.dll
21:36:06.0656 2968 C:\WINDOWS\System32\tapisrv.dll - ok
21:36:06.0671 2968 [ 6708E1DDF12CAB2D5B5A2B66B76E0038 ] C:\WINDOWS\System32\WBEM\WBEMESS.DLL
21:36:06.0671 2968 C:\WINDOWS\System32\WBEM\WBEMESS.DLL - ok
21:36:06.0671 2968 [ E3AE8DC04643850D2DFD431443558B28 ] C:\WINDOWS\System32\NETCFGX.DLL
21:36:06.0671 2968 C:\WINDOWS\System32\NETCFGX.DLL - ok
21:36:06.0687 2968 [ 8A473A9DB2B1EEA71F01E743245B4468 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\UserCtxt.dll
21:36:06.0687 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\UserCtxt.dll - ok
21:36:06.0687 2968 [ 23511B7C2D462D4D1D0F69707A68B211 ] C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\naHelper.dll
21:36:06.0687 2968 C:\Program Files\Norton Identity Safe\Engine\2013.2.0.18\naHelper.dll - ok
21:36:06.0703 2968 [ 234011DB508BEE7F2AAA0905BE2136F3 ] C:\WINDOWS\System32\WUAPI.DLL
21:36:06.0703 2968 C:\WINDOWS\System32\WUAPI.DLL - ok
21:36:06.0703 2968 [ 41A3C11E3517C962C9B44893BCEC3B34 ] C:\WINDOWS\System32\rasmans.dll
21:36:06.0703 2968 C:\WINDOWS\System32\rasmans.dll - ok
21:36:06.0703 2968 [ FD610CC0CD802EBC09BEF48BC3E3DA42 ] C:\WINDOWS\System32\unimdm.tsp
21:36:06.0703 2968 C:\WINDOWS\System32\unimdm.tsp - ok
21:36:06.0718 2968 [ 3AB4213BF48F9062E087B909832AA8E6 ] C:\WINDOWS\System32\uniplat.dll
21:36:06.0718 2968 C:\WINDOWS\System32\uniplat.dll - ok
21:36:06.0718 2968 [ 1D536BEBC30DD8D0D3B6FF3B0CD2D32B ] C:\WINDOWS\System32\rastapi.dll
21:36:06.0718 2968 C:\WINDOWS\System32\rastapi.dll - ok
21:36:06.0734 2968 [ 6AE613FFF9F9DFEE552652662BFABE41 ] C:\WINDOWS\System32\WBEM\ncprov.dll
21:36:06.0734 2968 C:\WINDOWS\System32\WBEM\ncprov.dll - ok
21:36:06.0734 2968 [ F1958FBF86D5C004CF19A5951A9514B7 ] C:\WINDOWS\System32\alg.exe
21:36:06.0734 2968 C:\WINDOWS\System32\alg.exe - ok
21:36:06.0734 2968 [ 7735385C0FA821961F9A1EBA94F2AC98 ] C:\WINDOWS\System32\kmddsp.tsp
21:36:06.0734 2968 C:\WINDOWS\System32\kmddsp.tsp - ok
21:36:06.0750 2968 [ 37D7005A87F6405DEA87F50098CE03F7 ] C:\WINDOWS\System32\ndptsp.tsp
21:36:06.0750 2968 C:\WINDOWS\System32\ndptsp.tsp - ok
21:36:06.0750 2968 [ A4C40AF21BF9F90E08A3C1DD0DC79E0B ] C:\WINDOWS\System32\ipconf.tsp
21:36:06.0750 2968 C:\WINDOWS\System32\ipconf.tsp - ok
21:36:06.0765 2968 [ 49361F295DF887AC32CD660CA94ACAA5 ] C:\WINDOWS\System32\h323.tsp
21:36:06.0765 2968 C:\WINDOWS\System32\h323.tsp - ok
21:36:06.0765 2968 [ 83168270F2E73A20E981B0F38A34958F ] C:\WINDOWS\System32\hidphone.tsp
21:36:06.0765 2968 C:\WINDOWS\System32\hidphone.tsp - ok
21:36:06.0765 2968 [ D18D28CEF9FEA09359C7DE7BE3669F66 ] C:\WINDOWS\System32\WBEM\wbemcons.dll
21:36:06.0765 2968 C:\WINDOWS\System32\WBEM\wbemcons.dll - ok
21:36:06.0781 2968 [ 04ECEC0447F79419AD25227205B8277D ] C:\WINDOWS\System32\rasppp.dll
21:36:06.0781 2968 C:\WINDOWS\System32\rasppp.dll - ok
21:36:06.0781 2968 [ C5EF2A4F6CB968B3119B43F43C64A1A6 ] C:\WINDOWS\System32\ntlsapi.dll
21:36:06.0781 2968 C:\WINDOWS\System32\ntlsapi.dll - ok
21:36:06.0796 2968 [ BA5D5FD3CCA6F64A429E2E0E1A1A0917 ] C:\WINDOWS\System32\RASDLG.dll
21:36:06.0796 2968 C:\WINDOWS\System32\RASDLG.dll - ok
21:36:06.0796 2968 [ 4C04D0D0F6F480832A2E336C61F18850 ] C:\WINDOWS\System32\browselc.dll
21:36:06.0796 2968 C:\WINDOWS\System32\browselc.dll - ok
21:36:06.0796 2968 [ C39CD25443CCCDD121BF1F807564DCFA ] C:\WINDOWS\System32\drprov.dll
21:36:06.0796 2968 C:\WINDOWS\System32\drprov.dll - ok
21:36:06.0812 2968 [ 01520B46830C8178E1B2C05A4F3F6C16 ] C:\WINDOWS\System32\NETUI0.dll
21:36:06.0812 2968 C:\WINDOWS\System32\NETUI0.dll - ok
21:36:06.0812 2968 [ 6539CED6E5AB5684AA09E6B0ABBF4124 ] C:\WINDOWS\System32\ntlanman.dll
21:36:06.0812 2968 C:\WINDOWS\System32\ntlanman.dll - ok
21:36:06.0828 2968 [ 88B918E7FB3B09595DD8A0FD09A35B8F ] C:\WINDOWS\System32\NETUI1.dll
21:36:06.0828 2968 C:\WINDOWS\System32\NETUI1.dll - ok
21:36:06.0828 2968 [ 716A078B2FC6CC0BB3030B2559EC143F ] C:\WINDOWS\System32\davclnt.dll
21:36:06.0828 2968 C:\WINDOWS\System32\davclnt.dll - ok
21:36:06.0828 2968 [ D2CAB5C09C568BD76016E97E4B7B74B0 ] C:\WINDOWS\System32\audiodev.dll
21:36:06.0828 2968 C:\WINDOWS\System32\audiodev.dll - ok
21:36:06.0843 2968 [ DDB0F28E684A9C6E5178352ED30B5CD7 ] C:\WINDOWS\System32\WMVCore.DLL
21:36:06.0843 2968 C:\WINDOWS\System32\WMVCore.DLL - ok
21:36:06.0843 2968 [ 8145D7C7D9F51B11F67D95E531295B0D ] C:\WINDOWS\System32\WMASF.DLL
21:36:06.0843 2968 C:\WINDOWS\System32\WMASF.DLL - ok
21:36:06.0859 2968 [ 40F4689EEDF449A6BD9CE05AAB7F5F0A ] C:\WINDOWS\System32\wiashext.dll
21:36:06.0859 2968 C:\WINDOWS\System32\wiashext.dll - ok
21:36:06.0859 2968 [ F6719362645C184049B2180110F0253F ] C:\WINDOWS\System32\sti.dll
21:36:06.0859 2968 C:\WINDOWS\System32\sti.dll - ok
21:36:06.0859 2968 [ 4F99145EF64D7076709A14AC8B17D2BD ] C:\WINDOWS\System32\msxml3.dll
21:36:06.0859 2968 C:\WINDOWS\System32\msxml3.dll - ok
21:36:06.0875 2968 [ 1C5F8CB84D34E5427C9048AE472A8D35 ] C:\WINDOWS\System32\httpapi.dll
21:36:06.0875 2968 C:\WINDOWS\System32\httpapi.dll - ok
21:36:06.0875 2968 [ C9C3E09700E38C01929EAE057FF18736 ] C:\WINDOWS\System32\strmfilt.dll
21:36:06.0875 2968 C:\WINDOWS\System32\strmfilt.dll - ok
21:36:06.0890 2968 [ 064D8581ADF77C25133E7D751D917D83 ] C:\WINDOWS\System32\w3ssl.dll
21:36:06.0890 2968 C:\WINDOWS\System32\w3ssl.dll - ok
21:36:06.0890 2968 [ B93EFA9D3638782DEF6C91E89B7A8D70 ] C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll
21:36:06.0890 2968 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll - ok
21:36:06.0890 2968 [ 813945BD5AFFD215B49AE107B131C2F2 ] C:\WINDOWS\System32\shimgvw.dll
21:36:06.0890 2968 C:\WINDOWS\System32\shimgvw.dll - ok
21:36:06.0906 2968 [ 1EEA7DD2F1EA6EFEF380B99A90228D2F ] C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
21:36:06.0906 2968 C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE - ok
21:36:06.0906 2968 [ 251C11444F614DE5FA47ECF7275E7BF1 ] C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL
21:36:06.0906 2968 C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSO.DLL - ok
21:36:06.0921 2968 [ 8CAF5C1748401032EFABB3D52E27C1BE ] C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL
21:36:06.0921 2968 C:\Program Files\Common Files\Microsoft Shared\OFFICE11\RICHED20.DLL - ok
21:36:06.0921 2968 [ 5939AA0776E72091F7A9AF6FF5811094 ] C:\WINDOWS\System32\btsendto_office.dll
21:36:06.0921 2968 C:\WINDOWS\System32\btsendto_office.dll - ok
21:36:06.0937 2968 [ 887574E670F885AF049845ED06BDEA44 ] C:\WINDOWS\System32\BTSENDTO.DLL
21:36:06.0937 2968 C:\WINDOWS\System32\BTSENDTO.DLL - ok
21:36:06.0937 2968 [ F29A80F607703CA1FC5D25993CC7FEDA ] C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL
21:36:06.0937 2968 C:\Program Files\Common Files\Microsoft Shared\PROOF\MSSPELL3.DLL - ok
21:36:06.0937 2968 [ 9CF99B650334066A9A6BCD8AD67D7622 ] C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL
21:36:06.0937 2968 C:\Program Files\Common Files\Microsoft Shared\PROOF\1033\MSGR3EN.DLL - ok
21:36:06.0953 2968 [ 50EA3EBAAC8D47CBFC2C7A88A51979D4 ] C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL
21:36:06.0953 2968 C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\VBE6.DLL - ok
21:36:06.0953 2968 [ 8E3602C4B7A1E559861CC9B1CEF21FA5 ] C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\1033\VBE6INTL.DLL
21:36:06.0953 2968 C:\Program Files\Common Files\Microsoft Shared\VBA\VBA6\1033\VBE6INTL.DLL - ok
21:36:06.0968 2968 [ DEAA0F5FF041981E34CA79257BA44414 ] C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FNAME.DLL
21:36:06.0968 2968 C:\Program Files\Common Files\Microsoft Shared\Smart Tag\FNAME.DLL - ok
21:36:06.0968 2968 [ DCFB56397025955B179A9F4F4C2FA469 ] C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\stintl.dll
21:36:06.0968 2968 C:\Program Files\Common Files\Microsoft Shared\Smart Tag\1033\stintl.dll - ok
21:36:06.0984 2968 [ 365D6248953729F90D8A0CAEAEDFCC7A ] C:\WINDOWS\System32\SPOOL\drivers\W32X86\3\mdigraph.dll
21:36:06.0984 2968 C:\WINDOWS\System32\SPOOL\drivers\W32X86\3\mdigraph.dll - ok
21:36:06.0984 2968 [ 4CA195A73CF64142D50B387B07289A64 ] C:\WINDOWS\System32\SPOOL\drivers\W32X86\3\mdiui.dll
21:36:06.0984 2968 C:\WINDOWS\System32\SPOOL\drivers\W32X86\3\mdiui.dll - ok
21:36:07.0000 2968 [ EBF1AB7E4FC05CABF2F4680D2A45F827 ] C:\WINDOWS\System32\wuauclt.exe
21:36:07.0000 2968 C:\WINDOWS\System32\wuauclt.exe - ok
21:36:07.0000 2968 [ 49BE3B5B6BDDC5D2BFB77CFD340BF127 ] C:\WINDOWS\System32\WUAUCPL.CPL
21:36:07.0000 2968 C:\WINDOWS\System32\WUAUCPL.CPL - ok
21:36:07.0000 2968 [ 63C4FAF446B312687ECF4B73B7ADC2C1 ] C:\WINDOWS\System32\WUPS.DLL
21:36:07.0000 2968 C:\WINDOWS\System32\WUPS.DLL - ok
21:36:07.0015 2968 ============================================================
21:36:07.0015 2968 Scan finished
21:36:07.0015 2968 ============================================================
21:36:07.0125 2924 Detected object count: 7
21:36:07.0125 2924 Actual detected object count: 7
21:37:22.0062 2924 ACS ( UnsignedFile.Multi.Generic ) - skipped by user
21:37:22.0062 2924 ACS ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:37:22.0078 2924 AR9271 ( UnsignedFile.Multi.Generic ) - skipped by user
21:37:22.0078 2924 AR9271 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:37:22.0078 2924 btwdins ( UnsignedFile.Multi.Generic ) - skipped by user
21:37:22.0078 2924 btwdins ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:37:22.0078 2924 jswpsapi ( UnsignedFile.Multi.Generic ) - skipped by user
21:37:22.0078 2924 jswpsapi ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:37:22.0078 2924 Secdrv ( UnsignedFile.Multi.Generic ) - skipped by user
21:37:22.0078 2924 Secdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:37:22.0078 2924 WMConnectCDS ( UnsignedFile.Multi.Generic ) - skipped by user
21:37:22.0078 2924 WMConnectCDS ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:37:22.0078 2924 WSIMD ( UnsignedFile.Multi.Generic ) - skipped by user
21:37:22.0078 2924 WSIMD ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:37:29.0093 0936 Deinitialize success




aswMBR:
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2012-12-21 21:38:30
-----------------------------
21:38:30.687 OS Version: Windows 5.1.2600 Service Pack 2
21:38:30.687 Number of processors: 2 586 0xF0D
21:38:30.687 ComputerName: WIN2006 UserName: Samhita
21:38:32.671 Initialize success
21:38:49.734 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
21:38:49.734 Disk 0 Vendor: Hitachi_HTS541612J9SA00 SBDOC70P Size: 114473MB BusType: 3
21:38:49.796 Disk 0 MBR read successfully
21:38:49.796 Disk 0 MBR scan
21:38:49.796 Disk 0 Windows XP default MBR code
21:38:49.812 Disk 0 Partition 1 80 (A) 0C FAT32 LBA MSDOS5.0 16002 MB offset 63
21:38:49.812 Disk 0 Partition - 00 0F Extended LBA 98468 MB offset 32772600
21:38:49.843 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 78003 MB offset 32772663
21:38:49.843 Disk 0 Partition - 00 05 Extended 7177 MB offset 192522960
21:38:49.875 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 7177 MB offset 192523023
21:38:49.890 Disk 0 Partition - 00 05 Extended 13288 MB offset 366972795
21:38:49.921 Disk 0 Partition 4 00 07 HPFS/NTFS NTFS 13288 MB offset 207222498
21:38:49.937 Disk 0 scanning sectors +234436545
21:38:49.968 Disk 0 scanning C:\WINDOWS\system32\drivers
21:38:55.765 Service scanning
21:39:10.062 Modules scanning
21:39:24.890 Disk 0 trace - called modules:
21:39:24.921 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
21:39:24.921 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86550ab8]
21:39:24.937 3 CLASSPNP.SYS[f761e05b] -> nt!IofCallDriver -> \Device\00000082[0x865559e8]
21:39:24.953 5 ACPI.sys[f7466620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86555d98]
21:39:24.984 Scan finished successfully
21:39:52.828 Disk 0 MBR has been saved successfully to "C:\MBR.dat"
21:39:52.843 The log file has been saved successfully to "C:\aswMBR.txt"
  • 0

#8
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello


I want you to go here and download SP3 and get it installed on this computer


http://www.microsoft...ails.aspx?id=24
  • 0

#9
ADR

ADR

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Gringo,

Thanks for your reply. But if I install SP3, that will be a fresh installation, right? Or just to put SP3 on top of SP2?

I'm not able to download that now, I'll try it from somewhere else tomorrow.

Regards,
ADR
  • 0

#10
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
service packs are not the operating system - this will only update the os to where it should be now



gringo
  • 0

#11
ADR

ADR

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts
Hi Gringo,

I've installed SP3 as instructed by you. But, still no luck. :(

Regards,
ADR
  • 0

#12
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Malwarebytes Anti-Rootkit

1.Download Malwarebytes Anti-Rootkit
2.Unzip the contents to a folder in a convenient location.
3.Open the folder where the contents were unzipped and run mbar.exe
4.Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
5.Click on the Cleanup button to remove any threats and reboot if prompted to do so.
6.Wait while the system shuts down and the cleanup process is performed.
7.Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
8.If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
•Internet access
•Windows Update
•Windows Firewall9.If there are additional problems with your system, such as any of those listed above or other system issues, then run the 'fixdamage' tool included with Malwarebytes Anti-Rootkit and reboot.
10.Verify that your system is now functioning normally.
  • 0

#13
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Greetings


I have not heard from you in a couple of days so I am coming by to check on you to see if you are having problems or you just need some more time.

Also to remind you that it is very important that we finish the process completely so as to not get reinfected. I will let you know when we are complete and I will ask to remove our tools




Gringo
  • 0

#14
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo
  • 0

#15
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP