Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

IRC Trojan Regedit Help Remove


  • Please log in to reply

#1
Sangoino

Sangoino

    Member

  • Member
  • PipPip
  • 40 posts
hello , I have scanned with a lof of software but nothing found, and I try CA -anti spyware with trial
it detect 2 virus :

1 Irc flood ( trojan) located at hkeyusers S-1-5-21-3059339421-2526555134-8052.... And I have not the rest, help me to remove it please..
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
Download OTL from
http://www.geekstogo...timers-list-it/
and Save it to your desktop.


Copy the text in the code box:

DRIVES
nnetsvcs
%SYSTEMDRIVE%\*.exe
%systemroot%\assembly\GAC_32\*.ini
%systemroot%\assembly\GAC_64\*.ini
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.exe
%APPDATA%\*.
/md5start
rsvpsp.dll
pnrpnsp.dll 
nwprovau.dll
nlaapi.dll
napinsp.dll
mswsock.dll
winrnr.dll
wshelper.dll
services.exe
atapi.sys
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
csrss.exe
PrintIsolationHost.exe
consrv.dll
user32.dll
/md5stop
C:\Windows\assembly\tmp\U\*.* /s
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%ProgramFiles%\WINDOWS NT\*.* /s
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemdrive%\$Recycle.Bin|@;true;true;true /fp 
CREATERESTOREPOINT

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

Select the All option in the Extra Registry group then Run Scan.

You should get two logs. Please copy and paste both of them.


Ron
  • 0

#3
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
HERE THE RESULTAT

OTL logfile created on: 14/02/2013 17:20:23 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\phil\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

2,75 Gb Total Physical Memory | 1,38 Gb Available Physical Memory | 50,06% Memory free
5,50 Gb Paging File | 3,96 Gb Available in Paging File | 72,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,79 Gb Total Space | 216,46 Gb Free Space | 92,99% Space Free | Partition Type: NTFS

Computer Name: PHIL-PC | User Name: phil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\phil\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\UnHackMe\gwebupdate.exe (Greais Software)
PRC - C:\Program Files\UnHackMe\hackmon.exe (Greatis Software)
PRC - C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesApp32.exe (TuneUp Software)
PRC - C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
PRC - C:\Program Files\Comodo\COMODO Internet Security\cis.exe (COMODO)
PRC - C:\Program Files\Comodo\COMODO Internet Security\CisTray.exe (COMODO)
PRC - C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (COMODO)
PRC - C:\Program Files\Comodo\Dragon\dragon_updater.exe ()
PRC - C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe (Uniblue Systems Ltd)
PRC - C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation)
PRC - C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
PRC - C:\Program Files\AntiLogger\AntiLogger.exe (Zemana Ltd.)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
PRC - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
PRC - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
PRC - C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\PC Tools\PC Tools Security\SpamMonitor\SMPlugin.dll ()
MOD - C:\Program Files\PC Tools\PC Tools Security\pctui\PCTUI.DLL ()
MOD - C:\Program Files\Unlocker\UnlockerCOM.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (TuneUp.UtilitiesSvc) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesService32.exe (TuneUp Software)
SRV - (cmdAgent) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (COMODO)
SRV - (cmdvirth) -- C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe (COMODO)
SRV - (DragonUpdater) -- C:\Program Files\Comodo\Dragon\dragon_updater.exe ()
SRV - (CLPSLauncher) -- C:\Program Files\Common Files\Comodo\launcher_service.exe (Comodo Security Solutions Inc.)
SRV - (sdCoreService) -- C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) -- C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (Browser Defender Update Service) -- C:\Program Files\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
SRV - (CSUService) -- C:\Program Files\COMODO\COMODO System Utilities\CSUService.exe (Comodo Security Solutions, Inc.)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SRV - (HsfXAudioService) -- C:\Windows\System32\XAudio32.dll (Conexant Systems, Inc.)


========== Driver Services (SafeList) ==========

DRV - (udsstub) -- C:\Windows\System32\drivers\udsstub.sys (SysNucleus)
DRV - (DrvAgent32) -- C:\Windows\System32\drivers\DrvAgent32.sys (Phoenix Technologies)
DRV - (RegGuard) -- C:\Windows\System32\drivers\regguard.sys (Greatis Software)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (athr) -- C:\Windows\System32\drivers\athr.sys (Qualcomm Atheros Communications, Inc.)
DRV - (iusb3hcs) -- C:\Windows\System32\drivers\iusb3hcs.sys (Intel Corporation)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (RSUSBSTOR) -- C:\Windows\System32\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV - (Partizan) -- C:\Windows\System32\drivers\Partizan.sys (Greatis Software)
DRV - (inspect) -- C:\Windows\System32\drivers\inspect.sys (COMODO)
DRV - (cmdHlp) -- C:\Windows\System32\drivers\cmdhlp.sys (COMODO)
DRV - (cmdGuard) -- C:\Windows\System32\drivers\cmdguard.sys (COMODO)
DRV - (cmderd) -- C:\Windows\System32\drivers\cmderd.sys (COMODO)
DRV - (TuneUpUtilitiesDrv) -- C:\Program Files\TuneUp Utilities 2013\TuneUpUtilitiesDriver32.sys (TuneUp Software)
DRV - (pctplfw) -- C:\Windows\System32\drivers\pctplfw.sys (PC Tools)
DRV - (pctplsm) -- C:\Windows\System32\drivers\pctplsm.sys (PC Tools)
DRV - (pctplsg) -- C:\Windows\System32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) -- C:\Windows\System32\drivers\PCTSD.sys (PC Tools)
DRV - (pctgntdi) -- C:\Windows\System32\drivers\pctgntdi.sys (PC Tools)
DRV - (PCTBD) -- C:\Windows\System32\drivers\PCTBD.sys (PC Tools)
DRV - (PCTCore) -- C:\Windows\System32\drivers\PCTCore.sys (PC Tools)
DRV - (PCTAppEvent) -- C:\Windows\System32\drivers\PCTAppEvent.sys (PC Tools)
DRV - (pctNdisLW) -- C:\Windows\System32\drivers\pctNdisLW.sys (PC Tools)
DRV - (PCTFW-PacketFilter) -- C:\Windows\System32\drivers\pctNdis-PacketFilter.sys (PC Tools)
DRV - (CFRMD) -- C:\Windows\System32\drivers\CFRMD.sys (Windows ® Win 7 DDK provider)
DRV - (pctDS) -- C:\Windows\System32\drivers\pctDS.sys (PC Tools)
DRV - (AntiLog32) -- C:\Windows\System32\drivers\AntiLog32.sys (Zemana Ltd.)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (vmbus) -- C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (dmvsc) -- C:\Windows\System32\drivers\dmvsc.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbGD) -- C:\Windows\System32\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (NVNET) -- C:\Windows\System32\drivers\nvmf6232.sys (NVIDIA Corporation)
DRV - (UnlockerDriver5) -- C:\Program Files\Unlocker\UnlockerDriver5.sys ()
DRV - (NVENETFD) -- C:\Windows\System32\drivers\nvm62x32.sys (NVIDIA Corporation)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio32.sys (Conexant Systems, Inc.)
DRV - (CnxtHdAudService) -- C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://fr.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 9E 33 1A 96 09 CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.google.fr/"
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.4.4
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll ()

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools\PC Tools Security\BDT\Firefox\ [2013/02/13 09:34:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/12 15:58:46 | 000,000,000 | ---D | M]

[2012/02/12 15:58:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\Extensions
[2013/02/13 04:10:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\Firefox\Profiles\krngak3h.default\extensions
[2013/02/13 04:09:51 | 000,533,536 | ---- | M] () (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\firefox\profiles\krngak3h.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/02/13 04:10:16 | 000,817,973 | ---- | M] () (No name found) -- C:\Users\phil\AppData\Roaming\mozilla\firefox\profiles\krngak3h.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/02/12 15:58:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\mozilla firefox\extensions
[2013/02/01 19:21:57 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/02/01 20:18:09 | 000,001,609 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2013/02/01 20:18:09 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/01 20:18:09 | 000,002,035 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2013/02/01 20:18:09 | 000,001,476 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2013/02/01 20:18:09 | 000,001,399 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2013/02/01 20:18:09 | 000,001,169 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml

O1 HOSTS File: ([2009/06/10 22:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [AntiLogger] C:\Program Files\AntiLogger\AntiLogger.exe (Zemana Ltd.)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cistray.exe (COMODO)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools\PC Tools Security\pctsGui.exe (PC Tools)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F1D3689F-46BD-4FE0-B67B-6BA907E93430}: NameServer = 109.0.66.10,109.0.66.20
O20 - HKLM Winlogon: Shell - (C:\Windows\explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (PowerRemover.exe)
O34 - HKLM BootExecute: (autocheck autochk /k:D *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: lanmanserver - File not found
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Remoteaccess - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: TermService - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: SessionEnv - File not found
NetSvcs: AppMgmt - File not found


SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: Netlogon - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: sdAuxService - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SafeBootMin: sdCoreService - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet: AppMgmt - Service
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: DnsCache - File not found
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: IKEEXT - Service
SafeBootNet: LanmanServer - File not found
SafeBootNet: LanmanWorkstation - Service
SafeBootNet: LmHosts - Service
SafeBootNet: Messenger - File not found
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Netlogon - Service
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: sdAuxService - C:\Program Files\PC Tools\PC Tools Security\pctsAuxs.exe (PC Tools)
SafeBootNet: sdCoreService - C:\Program Files\PC Tools\PC Tools Security\pctsSvc.exe (PC Tools)
SafeBootNet: SharedAccess - File not found
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: VaultSvc - Service
SafeBootNet: vmms - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\mpsvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 12.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD} - .NET Framework
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\System32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1021

========== Files/Folders - Created Within 30 Days ==========

[2013/02/14 15:39:31 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013/02/14 15:39:11 | 000,000,000 | -H-D | C] -- C:\Windows\AxInstSV
[2013/02/14 10:46:05 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker
[2013/02/14 10:46:04 | 000,000,000 | ---D | C] -- C:\Program Files\Unlocker
[2013/02/14 10:23:19 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2013/02/14 08:13:23 | 000,040,656 | ---- | C] (COMODO) -- C:\Windows\System32\cmdkbd32.dll
[2013/02/14 08:13:22 | 000,263,888 | ---- | C] (COMODO) -- C:\Windows\System32\cmdvrt32.dll
[2013/02/14 06:48:14 | 000,627,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/02/14 06:48:11 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/02/14 06:48:11 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/02/14 06:48:10 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/02/14 06:48:10 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/02/14 06:48:07 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/02/14 06:48:05 | 000,284,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbport.sys
[2013/02/14 06:48:01 | 000,005,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\usbd.sys
[2013/02/14 06:47:44 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fsutil.exe
[2013/02/14 06:47:43 | 000,148,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys
[2013/02/14 06:46:45 | 000,187,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\FWPKCLNT.SYS
[2013/02/14 06:46:40 | 003,967,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2013/02/14 06:46:39 | 003,913,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2013/02/14 06:42:57 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Users\phil\Desktop\ATF-Cleaner.exe
[2013/02/14 06:37:57 | 000,016,000 | ---- | C] (SysNucleus) -- C:\Windows\System32\drivers\udsstub.sys
[2013/02/14 06:18:22 | 000,000,000 | ---D | C] -- C:\UsbFix
[2013/02/14 05:41:21 | 000,000,000 | ---D | C] -- C:\Users\phil\Documents\Nouveau dossier
[2013/02/14 05:17:18 | 000,000,000 | ---D | C] -- C:\Program Files\RegCleaner
[2013/02/14 04:34:22 | 000,061,024 | ---- | C] (NirSoft) -- C:\Users\phil\Desktop\USBDeview.exe
[2013/02/14 03:44:46 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\ShamurShamur
[2013/02/14 01:45:13 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\NeoSmart_Technologies
[2013/02/14 01:23:42 | 000,000,000 | ---D | C] -- C:\NST
[2013/02/14 00:54:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NeoSmart Technologies
[2013/02/14 00:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\NeoSmart Technologies
[2013/02/14 00:40:07 | 000,023,456 | ---- | C] (Phoenix Technologies) -- C:\Windows\System32\drivers\DrvAgent32.sys
[2013/02/13 19:16:45 | 000,024,416 | ---- | C] (Greatis Software) -- C:\Windows\System32\drivers\regguard.sys
[2013/02/13 18:45:52 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\GlarySoft
[2013/02/13 18:45:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities
[2013/02/13 18:45:13 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities
[2013/02/13 15:02:31 | 000,000,000 | ---D | C] -- C:\SwSetup
[2013/02/13 14:33:01 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\WinRAR
[2013/02/13 14:33:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/02/13 14:33:00 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2013/02/13 14:32:58 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2013/02/13 11:34:18 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\PC Tools
[2013/02/13 11:34:13 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Spam Monitor
[2013/02/13 09:34:46 | 000,062,688 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTBD.sys
[2013/02/13 09:34:45 | 002,280,568 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2013/02/13 09:34:45 | 001,690,744 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2013/02/13 09:34:45 | 000,150,648 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2013/02/13 09:33:58 | 000,909,728 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctEFA.sys
[2013/02/13 09:33:58 | 000,342,168 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctDS.sys
[2013/02/13 09:33:57 | 000,260,760 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2013/02/13 09:33:57 | 000,178,584 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2013/02/13 09:33:55 | 000,368,616 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2013/02/13 09:33:55 | 000,163,288 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2013/02/13 09:33:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2013/02/13 09:33:53 | 000,202,280 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTSD.sys
[2013/02/13 09:33:53 | 000,019,464 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctBTFix.sys
[2013/02/13 09:33:52 | 000,577,176 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfSysMon.sys
[2013/02/13 09:33:52 | 000,055,008 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfFsMon.sys
[2013/02/13 09:33:52 | 000,036,456 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfNetMon.sys
[2013/02/13 09:33:43 | 000,128,024 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplfw.sys
[2013/02/13 09:33:43 | 000,092,608 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-PacketFilter.sys
[2013/02/13 09:33:43 | 000,060,128 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdisLW.sys
[2013/02/13 09:33:43 | 000,033,512 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctNdis-DNS.sys
[2013/02/13 09:33:41 | 000,071,752 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2013/02/13 09:33:41 | 000,068,272 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsm.sys
[2013/02/13 09:33:32 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools
[2013/02/13 09:33:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2013/02/13 09:20:21 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013/02/13 09:20:19 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2013/02/13 09:20:17 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\TestApp
[2013/02/13 09:02:25 | 000,032,032 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2013/02/13 09:02:25 | 000,021,792 | ---- | C] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2013/02/13 09:02:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013
[2013/02/13 09:02:13 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\TuneUp Software
[2013/02/13 09:02:01 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2013
[2013/02/13 09:01:56 | 000,000,000 | ---D | C] -- C:\ProgramData\TuneUp Software
[2013/02/13 09:01:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}
[2013/02/13 09:01:47 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2013/02/13 08:52:05 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2013/02/13 08:45:07 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\phil\Desktop\tdsskiller.exe
[2013/02/13 06:59:10 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\Diagnostics
[2013/02/13 06:43:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/02/13 06:43:35 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013/02/13 06:35:45 | 000,000,000 | --SD | C] -- C:\ProgramData\Shared Space
[2013/02/13 06:34:20 | 000,000,000 | ---D | C] -- C:\ProgramData\COMODO
[2013/02/13 06:34:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Comodo
[2013/02/13 06:34:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo
[2013/02/13 06:34:06 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\Comodo
[2013/02/13 06:34:04 | 000,047,368 | ---- | C] (COMODO CA Limited) -- C:\Windows\System32\certsentry.dll
[2013/02/13 06:33:56 | 000,000,000 | ---D | C] -- C:\Program Files\Comodo
[2013/02/13 06:33:54 | 001,700,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll
[2013/02/13 06:33:54 | 001,060,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll
[2013/02/13 06:33:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2013/02/13 06:28:23 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Macromedia
[2013/02/13 06:28:23 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Local\Macromedia
[2013/02/13 06:28:23 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Adobe
[2013/02/13 06:28:01 | 000,691,568 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/02/13 06:28:01 | 000,071,024 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/02/13 06:28:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2013/02/13 05:57:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIDA32 - Personal System Information
[2013/02/13 05:57:35 | 000,000,000 | ---D | C] -- C:\Program Files\AIDA32 - Personal System Information
[2013/02/13 05:44:59 | 000,000,000 | ---D | C] -- C:\Users\phil\Desktop\Tgl0beSCRIPT
[2013/02/13 05:21:38 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2013/02/13 05:15:14 | 002,557,880 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvsvcr.dll
[2013/02/13 05:14:44 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2013/02/13 05:14:21 | 012,641,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll
[2013/02/13 05:14:20 | 020,450,232 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2013/02/13 05:14:20 | 008,904,632 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2013/02/13 05:14:20 | 006,263,784 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvopencl.dll
[2013/02/13 05:14:20 | 001,017,272 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2013/02/13 05:14:20 | 000,889,784 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvdispgenco32.dll
[2013/02/13 05:14:19 | 017,560,504 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2013/02/13 05:14:19 | 007,931,896 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2013/02/13 05:14:19 | 002,720,696 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2013/02/13 05:14:19 | 001,985,976 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2013/02/13 05:10:04 | 003,078,656 | ---- | C] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athr.sys
[2013/02/13 05:08:46 | 001,461,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01009.dll
[2013/02/13 05:08:46 | 000,015,640 | ---- | C] (Intel Corporation) -- C:\Windows\System32\drivers\iusb3hcs.sys
[2013/02/13 05:07:57 | 000,884,072 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvhdagenco3220103.dll
[2013/02/13 05:07:57 | 000,028,008 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvhdap32.dll
[2013/02/13 05:07:56 | 000,149,352 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvhda32v.sys
[2013/02/13 05:07:56 | 000,067,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvapo32v.dll
[2013/02/13 04:58:34 | 000,000,000 | ---D | C] -- C:\Windows\System32\sda
[2013/02/13 04:58:32 | 009,888,360 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtsUStoricon.dll
[2013/02/13 04:58:32 | 000,313,960 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtsUStor.dll
[2013/02/13 04:58:32 | 000,197,224 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RtsUStor.sys
[2013/02/13 04:46:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Uniblue
[2013/02/13 04:46:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Uniblue
[2013/02/13 04:46:44 | 000,000,000 | ---D | C] -- C:\Users\phil\AppData\Roaming\Uniblue
[2013/02/13 04:46:44 | 000,000,000 | ---D | C] -- C:\Program Files\Uniblue
[2013/02/13 04:10:47 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\phil\Desktop\TFC.exe
[2013/02/13 04:03:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHP
[2013/02/13 04:03:37 | 000,000,000 | ---D | C] -- C:\Program Files\ZHPDiag
[2013/02/13 03:59:42 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/02/13 03:59:40 | 000,758,784 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\cohelper.dll
[2013/02/13 03:59:40 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2013/02/13 03:59:02 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\phil\Desktop\OTL.exe
[2013/02/13 03:58:18 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2013/02/13 03:58:08 | 000,000,000 | ---D | C] -- C:\ZHP
[2013/02/13 03:57:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZHPFix 1.3
[2013/02/13 03:57:37 | 000,000,000 | ---D | C] -- C:\Program Files\ZHPFix
[2013/02/13 03:55:21 | 000,124,928 | ---- | C] (Tigzy) -- C:\Users\phil\Desktop\LogAnalyzer.exe
[2013/02/13 03:55:01 | 000,000,000 | ---D | C] -- C:\Program Files\CONEXANT
[2013/02/13 03:38:40 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2013/02/13 03:38:39 | 000,035,816 | ---- | C] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2013/02/13 03:38:34 | 000,000,000 | ---D | C] -- C:\Users\phil\Documents\RegRun2
[2013/02/13 03:38:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
[2013/02/13 03:38:33 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
[2013/02/13 03:38:32 | 000,012,800 | ---- | C] (Greatis Software, LLC.) -- C:\Windows\System32\drivers\UnHackMeDrv.sys
[2013/02/13 03:38:28 | 000,000,000 | ---D | C] -- C:\Program Files\UnHackMe
[2013/02/13 03:34:56 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2013/02/13 03:31:59 | 000,000,000 | ---D | C] -- C:\Windows\System32\Wat
[2013/02/13 03:29:35 | 000,295,424 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2013/02/13 03:29:35 | 000,070,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fontsub.dll
[2013/02/13 03:29:35 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2013/02/13 03:08:17 | 000,047,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\WdfLdr.sys
[2013/02/13 03:08:17 | 000,009,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wdfres.dll
[2013/02/13 03:07:37 | 000,172,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFPlatform.dll
[2013/02/13 03:07:36 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFx.dll
[2013/02/13 03:07:36 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUDFCoinstaller.dll
[2013/02/13 03:05:54 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2013/02/13 03:01:05 | 000,604,776 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvuninst.exe
[2013/02/12 19:06:24 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013/02/12 17:54:25 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\RNDISMP.sys
[2013/02/12 17:54:06 | 000,376,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpnet.dll
[2013/02/12 17:53:52 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2013/02/12 17:53:45 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2013/02/12 17:53:45 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisrndr.ax
[2013/02/12 17:53:41 | 000,245,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\OxpsConverter.exe
[2013/02/12 17:53:30 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3r.dll
[2013/02/12 17:53:20 | 000,240,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\netio.sys
[2013/02/12 17:53:20 | 000,175,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netcorehc.dll
[2013/02/12 17:53:20 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncsi.dll
[2013/02/12 17:53:20 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netevent.dll
[2013/02/12 17:53:18 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\packager.dll
[2013/02/12 17:53:15 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2013/02/12 17:53:15 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013/02/12 17:53:14 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/02/12 17:53:14 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/02/12 17:53:14 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/02/12 17:53:14 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/02/12 17:53:14 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/02/12 17:53:14 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/02/12 17:53:14 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/02/12 17:53:14 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/02/12 17:53:14 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/02/12 17:53:14 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/02/12 17:53:09 | 000,805,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cdosys.dll
[2013/02/12 17:53:07 | 000,400,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\srcore.dll
[2013/02/12 17:53:06 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browcli.dll
[2013/02/12 17:53:05 | 000,288,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsGdiConverter.dll
[2013/02/12 17:53:04 | 000,850,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2013/02/12 17:53:04 | 000,642,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2013/02/12 17:53:04 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2013/02/12 17:53:03 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\quartz.dll
[2013/02/12 17:53:03 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qdvd.dll
[2013/02/12 17:52:49 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2013/02/12 17:52:47 | 000,870,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XpsPrint.dll
[2013/02/12 17:52:39 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2013/02/12 17:52:35 | 000,031,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\prevhost.exe
[2013/02/12 17:52:34 | 002,616,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\explorer.exe
[2013/02/12 17:52:33 | 001,549,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tquery.dll
[2013/02/12 17:52:33 | 001,401,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssrch.dll
[2013/02/12 17:52:33 | 000,666,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssvp.dll
[2013/02/12 17:52:33 | 000,337,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssph.dll
[2013/02/12 17:52:33 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mssphtb.dll
[2013/02/12 17:52:33 | 000,059,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msscntrs.dll
[2013/02/12 17:52:29 | 000,490,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013/02/12 17:52:29 | 000,478,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\timedate.cpl
[2013/02/12 17:52:20 | 002,576,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gameux.dll
[2013/02/12 17:52:20 | 000,308,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Wpc.dll
[2013/02/12 17:52:20 | 000,055,296 | ---- | C] (Microsoft) -- C:\Windows\System32\cero.rs
[2013/02/12 17:52:20 | 000,051,712 | ---- | C] (Microsoft) -- C:\Windows\System32\esrb.rs
[2013/02/12 17:52:20 | 000,046,592 | ---- | C] (Microsoft) -- C:\Windows\System32\fpb.rs
[2013/02/12 17:52:20 | 000,045,568 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc-nz.rs
[2013/02/12 17:52:20 | 000,044,544 | ---- | C] (Microsoft) -- C:\Windows\System32\pegibbfc.rs
[2013/02/12 17:52:20 | 000,043,520 | ---- | C] (Microsoft) -- C:\Windows\System32\csrr.rs
[2013/02/12 17:52:20 | 000,040,960 | ---- | C] (Microsoft) -- C:\Windows\System32\cob-au.rs
[2013/02/12 17:52:20 | 000,030,720 | ---- | C] (Microsoft) -- C:\Windows\System32\usk.rs
[2013/02/12 17:52:20 | 000,023,552 | ---- | C] (Microsoft) -- C:\Windows\System32\oflc.rs
[2013/02/12 17:52:20 | 000,021,504 | ---- | C] (Microsoft) -- C:\Windows\System32\grb.rs
[2013/02/12 17:52:20 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-pt.rs
[2013/02/12 17:52:20 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi-fi.rs
[2013/02/12 17:52:20 | 000,020,480 | ---- | C] (Microsoft) -- C:\Windows\System32\pegi.rs
[2013/02/12 17:52:20 | 000,015,360 | ---- | C] (Microsoft) -- C:\Windows\System32\djctq.rs
[2013/02/12 17:52:15 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbcjt32.dll
[2013/02/12 17:52:15 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbctrac.dll
[2013/02/12 17:52:15 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccp32.dll
[2013/02/12 17:52:15 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccu32.dll
[2013/02/12 17:52:15 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\odbccr32.dll
[2013/02/12 17:52:14 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2013/02/12 17:52:14 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2013/02/12 17:52:13 | 000,220,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncrypt.dll
[2013/02/12 17:52:12 | 000,129,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorekmts.dll
[2013/02/12 17:52:12 | 000,058,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpwsx.dll
[2013/02/12 17:52:12 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdrmemptylst.exe
[2013/02/12 17:52:11 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013/02/12 17:52:10 | 000,078,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2013/02/12 17:52:07 | 000,049,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
[2013/02/12 17:52:06 | 001,077,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013/02/12 17:52:05 | 000,193,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcore6.dll
[2013/02/12 17:52:05 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dhcpcsvc6.dll
[2013/02/12 17:51:52 | 001,137,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2013/02/12 17:51:50 | 001,164,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2013/02/12 17:51:46 | 000,123,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\poqexec.exe
[2013/02/12 17:44:42 | 000,027,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Diskdump.sys
[2013/02/12 17:44:34 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2013/02/12 17:44:25 | 000,219,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dxgmms1.sys
[2013/02/12 17:41:28 | 000,826,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2013/01/24 22:43:02 | 000,354,752 | ---- | C] (COMODO) -- C:\Windows\System32\guard32.dll
[2013/01/24 22:43:02 | 000,035,488 | ---- | C] (COMODO) -- C:\Windows\System32\cmdcsr.dll
[2013/01/16 19:51:44 | 000,084,416 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\inspect.sys
[2013/01/16 19:51:44 | 000,043,728 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys
[2013/01/16 19:51:42 | 000,576,768 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmdguard.sys
[2013/01/16 19:51:42 | 000,020,072 | ---- | C] (COMODO) -- C:\Windows\System32\drivers\cmderd.sys

========== Files - Modified Within 30 Days ==========

[2013/02/14 17:24:19 | 001,474,832 | ---- | M] () -- C:\Windows\System32\drivers\sfi.dat
[2013/02/14 17:14:24 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/14 17:14:19 | 000,031,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/14 17:14:18 | 000,031,312 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/14 17:14:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/14 14:25:37 | 000,704,480 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2013/02/14 14:25:37 | 000,616,008 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/02/14 14:25:37 | 000,130,754 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2013/02/14 14:25:37 | 000,106,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/02/14 14:21:11 | 2213,351,424 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/14 14:17:11 | 000,268,256 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/02/14 11:33:28 | 000,000,057 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
[2013/02/14 06:42:58 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Users\phil\Desktop\ATF-Cleaner.exe
[2013/02/14 06:37:57 | 000,016,000 | ---- | M] (SysNucleus) -- C:\Windows\System32\drivers\udsstub.sys
[2013/02/14 05:33:30 | 000,001,207 | ---- | M] () -- C:\Users\phil\Desktop\BiosAgent Plus.lnk
[2013/02/14 05:33:11 | 000,001,154 | ---- | M] () -- C:\Users\Public\Desktop\COMODO System Utilities.lnk
[2013/02/14 05:17:28 | 000,000,928 | ---- | M] () -- C:\Users\phil\Desktop\RegCleaner.lnk
[2013/02/14 00:55:08 | 000,032,768 | ---- | M] () -- C:\Users\phil\Documents\Sauvegarde EasyBCD (2013-02-14).bcd
[2013/02/14 00:54:47 | 000,001,171 | ---- | M] () -- C:\Users\Public\Desktop\EasyBCD 2.2.lnk
[2013/02/14 00:40:07 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\Windows\System32\drivers\DrvAgent32.sys
[2013/02/14 00:24:21 | 000,047,368 | ---- | M] (COMODO CA Limited) -- C:\Windows\System32\certsentry.dll
[2013/02/13 20:33:03 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/02/13 20:33:03 | 000,001,688 | ---- | M] () -- C:\Windows\System32\autoexec.nt
[2013/02/13 20:33:03 | 000,000,002 | RHS- | M] () -- C:\Windows\winstart.bat
[2013/02/13 19:16:45 | 000,024,416 | ---- | M] (Greatis Software) -- C:\Windows\System32\drivers\regguard.sys
[2013/02/13 18:45:16 | 000,001,048 | ---- | M] () -- C:\Users\phil\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities.lnk
[2013/02/13 18:45:16 | 000,001,024 | ---- | M] () -- C:\Users\phil\Desktop\Glary Utilities.lnk
[2013/02/13 18:17:13 | 000,000,000 | ---- | M] () -- C:\Windows\System32\SM.lock
[2013/02/13 09:33:54 | 000,002,193 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2013/02/13 09:02:23 | 000,002,171 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Maintenance en 1 clic.lnk
[2013/02/13 09:02:23 | 000,002,135 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2013/02/13 08:45:19 | 002,237,968 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\phil\Desktop\tdsskiller.exe
[2013/02/13 06:43:39 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/02/13 06:36:10 | 000,001,993 | ---- | M] () -- C:\Users\Public\Desktop\Virtual Comodo Dragon.lnk
[2013/02/13 06:36:10 | 000,001,838 | ---- | M] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013/02/13 06:36:10 | 000,000,593 | ---- | M] () -- C:\Users\Public\Desktop\Shared Space.lnk
[2013/02/13 06:34:15 | 000,002,017 | ---- | M] () -- C:\Users\Public\Desktop\AntiError.lnk
[2013/02/13 06:34:15 | 000,002,013 | ---- | M] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/02/13 06:34:07 | 000,001,074 | ---- | M] () -- C:\Users\Public\Desktop\Comodo Dragon.lnk
[2013/02/13 06:33:54 | 001,700,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\gdiplus.dll
[2013/02/13 06:33:54 | 001,060,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mfc71.dll
[2013/02/13 06:28:01 | 000,691,568 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/02/13 06:28:01 | 000,071,024 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/02/13 05:57:36 | 000,001,041 | ---- | M] () -- C:\Users\phil\Desktop\AIDA32.lnk
[2013/02/13 05:14:21 | 012,641,120 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvwgf2um.dll
[2013/02/13 05:14:21 | 006,263,784 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvopencl.dll
[2013/02/13 05:14:20 | 020,450,232 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2013/02/13 05:14:20 | 015,129,064 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvd3dum.dll
[2013/02/13 05:14:20 | 008,904,632 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2013/02/13 05:14:20 | 001,017,272 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvdispco32.dll
[2013/02/13 05:14:20 | 000,889,784 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvdispgenco32.dll
[2013/02/13 05:14:20 | 000,013,153 | ---- | M] () -- C:\Windows\System32\nvinfo.pb
[2013/02/13 05:14:19 | 017,560,504 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2013/02/13 05:14:19 | 007,931,896 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2013/02/13 05:14:19 | 002,720,696 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2013/02/13 05:14:19 | 002,504,248 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapi.dll
[2013/02/13 05:14:19 | 001,985,976 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2013/02/13 05:10:04 | 003,078,656 | ---- | M] (Qualcomm Atheros Communications, Inc.) -- C:\Windows\System32\drivers\athr.sys
[2013/02/13 05:09:10 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/02/13 05:08:46 | 001,461,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WdfCoInstaller01009.dll
[2013/02/13 05:08:46 | 000,015,640 | ---- | M] (Intel Corporation) -- C:\Windows\System32\drivers\iusb3hcs.sys
[2013/02/13 05:07:57 | 000,884,072 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvhdagenco3220103.dll
[2013/02/13 05:07:57 | 000,028,008 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvhdap32.dll
[2013/02/13 05:07:56 | 000,149,352 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvhda32v.sys
[2013/02/13 05:07:56 | 000,067,432 | ---- | M] (NVIDIA Corporation) -- C:\Windows\System32\nvapo32v.dll
[2013/02/13 04:58:32 | 009,888,360 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtsUStoricon.dll
[2013/02/13 04:58:32 | 000,313,960 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\RtsUStor.dll
[2013/02/13 04:58:32 | 000,197,224 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\System32\drivers\RtsUStor.sys
[2013/02/13 04:46:46 | 000,001,171 | ---- | M] () -- C:\Users\phil\Application Data\Microsoft\Internet Explorer\Quick Launch\DriverScanner.lnk
[2013/02/13 04:46:46 | 000,001,147 | ---- | M] () -- C:\Users\Public\Desktop\DriverScanner.lnk
[2013/02/13 04:10:48 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\phil\Desktop\TFC.exe
[2013/02/13 04:07:32 | 000,000,000 | ---- | M] () -- C:\Users\phil\Desktop\LogAnalyZer.ini
[2013/02/13 04:03:38 | 000,000,956 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/02/13 04:03:38 | 000,000,949 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/02/13 04:03:38 | 000,000,944 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/02/13 03:59:04 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\phil\Desktop\OTL.exe
[2013/02/13 03:58:24 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2013/02/13 03:55:22 | 000,124,928 | ---- | M] (Tigzy) -- C:\Users\phil\Desktop\LogAnalyzer.exe
[2013/02/13 03:38:39 | 000,035,816 | ---- | M] (Greatis Software) -- C:\Windows\System32\drivers\Partizan.sys
[2013/02/13 03:38:34 | 000,000,913 | ---- | M] () -- C:\Users\phil\Desktop\UnHackMe.lnk
[2013/02/12 14:06:22 | 000,012,800 | ---- | M] (Greatis Software, LLC.) -- C:\Windows\System32\drivers\UnHackMeDrv.sys
[2013/02/06 09:39:36 | 000,061,024 | ---- | M] (NirSoft) -- C:\Users\phil\Desktop\USBDeview.exe
[2013/01/31 10:52:14 | 000,032,032 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2013/01/31 10:52:10 | 000,021,792 | ---- | M] (TuneUp Software) -- C:\Windows\System32\authuitu.dll
[2013/01/24 23:42:49 | 000,263,888 | ---- | M] (COMODO) -- C:\Windows\System32\cmdvrt32.dll
[2013/01/24 23:42:48 | 000,040,656 | ---- | M] (COMODO) -- C:\Windows\System32\cmdkbd32.dll
[2013/01/24 22:43:02 | 000,354,752 | ---- | M] (COMODO) -- C:\Windows\System32\guard32.dll
[2013/01/24 22:43:02 | 000,035,488 | ---- | M] (COMODO) -- C:\Windows\System32\cmdcsr.dll
[2013/01/16 19:51:44 | 000,084,416 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\inspect.sys
[2013/01/16 19:51:44 | 000,043,728 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdhlp.sys
[2013/01/16 19:51:42 | 000,576,768 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmdguard.sys
[2013/01/16 19:51:42 | 000,020,072 | ---- | M] (COMODO) -- C:\Windows\System32\drivers\cmderd.sys

========== Files Created - No Company Name ==========

[2013/02/14 14:16:55 | 000,268,256 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/02/14 05:33:11 | 000,001,154 | ---- | C] () -- C:\Users\Public\Desktop\COMODO System Utilities.lnk
[2013/02/14 05:17:20 | 000,000,928 | ---- | C] () -- C:\Users\phil\Desktop\RegCleaner.lnk
[2013/02/14 00:55:08 | 000,032,768 | ---- | C] () -- C:\Users\phil\Documents\Sauvegarde EasyBCD (2013-02-14).bcd
[2013/02/14 00:54:47 | 000,001,171 | ---- | C] () -- C:\Users\Public\Desktop\EasyBCD 2.2.lnk
[2013/02/13 18:45:16 | 000,001,048 | ---- | C] () -- C:\Users\phil\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Utilities.lnk
[2013/02/13 18:45:16 | 000,001,024 | ---- | C] () -- C:\Users\phil\Desktop\Glary Utilities.lnk
[2013/02/13 18:17:13 | 000,000,000 | ---- | C] () -- C:\Windows\System32\SM.lock
[2013/02/13 09:34:45 | 000,769,144 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2013/02/13 09:34:45 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2013/02/13 09:34:45 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2013/02/13 09:34:45 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2013/02/13 09:34:45 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2013/02/13 09:33:54 | 000,002,193 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2013/02/13 09:02:23 | 000,002,171 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Maintenance en 1 clic.lnk
[2013/02/13 09:02:23 | 000,002,135 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2013.lnk
[2013/02/13 09:02:22 | 000,002,147 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2013.lnk
[2013/02/13 06:43:39 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/02/13 06:36:10 | 000,001,993 | ---- | C] () -- C:\Users\Public\Desktop\Virtual Comodo Dragon.lnk
[2013/02/13 06:36:10 | 000,001,838 | ---- | C] () -- C:\Users\Public\Desktop\COMODO Internet Security.lnk
[2013/02/13 06:36:09 | 000,000,593 | ---- | C] () -- C:\Users\Public\Desktop\Shared Space.lnk
[2013/02/13 06:36:04 | 001,474,832 | ---- | C] () -- C:\Windows\System32\drivers\sfi.dat
[2013/02/13 06:34:15 | 000,002,017 | ---- | C] () -- C:\Users\Public\Desktop\AntiError.lnk
[2013/02/13 06:34:15 | 000,002,013 | ---- | C] () -- C:\Users\Public\Desktop\GeekBuddy.lnk
[2013/02/13 06:34:07 | 000,001,074 | ---- | C] () -- C:\Users\Public\Desktop\Comodo Dragon.lnk
[2013/02/13 06:28:01 | 000,001,002 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/02/13 05:57:36 | 000,001,041 | ---- | C] () -- C:\Users\phil\Desktop\AIDA32.lnk
[2013/02/13 05:14:20 | 000,013,153 | ---- | C] () -- C:\Windows\System32\nvinfo.pb
[2013/02/13 05:09:10 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_iusb3hcs_01009.Wdf
[2013/02/13 04:46:46 | 000,001,171 | ---- | C] () -- C:\Users\phil\Application Data\Microsoft\Internet Explorer\Quick Launch\DriverScanner.lnk
[2013/02/13 04:46:46 | 000,001,147 | ---- | C] () -- C:\Users\Public\Desktop\DriverScanner.lnk
[2013/02/13 04:03:38 | 000,000,956 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/02/13 04:03:38 | 000,000,949 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/02/13 03:59:40 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2013/02/13 03:58:24 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2013/02/13 03:57:38 | 000,000,944 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/02/13 03:55:50 | 000,000,000 | ---- | C] () -- C:\Users\phil\Desktop\LogAnalyZer.ini
[2013/02/13 03:38:36 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
[2013/02/13 03:38:34 | 000,000,913 | ---- | C] () -- C:\Users\phil\Desktop\UnHackMe.lnk
[2013/02/13 03:09:49 | 000,001,207 | ---- | C] () -- C:\Users\phil\Desktop\BiosAgent Plus.lnk
[2013/02/13 03:08:18 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/02/13 03:07:36 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2011/04/12 02:35:45 | 000,704,480 | ---- | C] () -- C:\Windows\System32\perfh00C.dat
[2011/04/12 02:35:45 | 000,344,522 | ---- | C] () -- C:\Windows\System32\perfi00C.dat
[2011/04/12 02:35:45 | 000,130,754 | ---- | C] () -- C:\Windows\System32\perfc00C.dat
[2011/04/12 02:35:45 | 000,038,160 | ---- | C] () -- C:\Windows\System32\perfd00C.dat

========== ZeroAccess Check ==========

[2009/07/14 05:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 05:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 02:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== Custom Scans ==========

========== Drive Information ==========

Physical Drives
---------------

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: TOSHIBA MK2552GSX ATA Device
Partitions: 2
Status: OK
Status Info: 0

Partitions
---------------

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 100,00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 233,00GB
Starting Offset: 105906176
Hidden sectors: 0


< %SYSTEMDRIVE%\*.exe >

< %systemroot%\assembly\GAC_32\*.ini >

< %systemroot%\assembly\GAC_64\*.ini >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*.exe >

< %APPDATA%\*. >
[2013/02/13 06:28:23 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Adobe
[2013/02/13 18:45:52 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\GlarySoft
[2012/02/12 15:29:57 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Identities
[2013/02/13 06:28:23 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Macromedia
[2011/04/12 02:44:56 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Media Center Programs
[2013/02/13 06:28:23 | 000,000,000 | --SD | M] -- C:\Users\phil\AppData\Roaming\Microsoft
[2012/02/12 15:58:58 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Mozilla
[2013/02/13 11:34:18 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\PC Tools
[2013/02/13 11:34:13 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Spam Monitor
[2013/02/13 09:20:17 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\TestApp
[2013/02/13 09:02:13 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\TuneUp Software
[2013/02/13 04:46:44 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\Uniblue
[2013/02/13 14:33:06 | 000,000,000 | ---D | M] -- C:\Users\phil\AppData\Roaming\WinRAR

< MD5 for: ATAPI.SYS >
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\drivers\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_neutral_fab873f3e8a3315c\atapi.sys
[2009/07/14 02:26:15 | 000,021,584 | ---- | M] (Microsoft Corporation) MD5=338C86357871C167A96AB976519BF59E -- C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_df3f92057fcbe7a7\atapi.sys

< MD5 for: CSRSS.EXE >
[2009/07/14 02:14:16 | 000,006,144 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\csrss.exe
[2009/07/14 02:14:16 | 000,006,144 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-csrss_31bf3856ad364e35_6.1.7600.16385_none_58ba39fb456943bd\csrss.exe

< MD5 for: EXPLORER.EXE >
[2011/02/26 06:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_54149f9ef14031fc\explorer.exe
[2010/11/20 22:29:20 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_5389023fd8245f84\explorer.exe

< MD5 for: MSWSOCK.DLL >
[2010/11/20 22:29:12 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\System32\mswsock.dll
[2010/11/20 22:29:12 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll

< MD5 for: NAPINSP.DLL >
[2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\System32\NapiNSP.dll
[2009/07/14 02:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\winsxs\x86_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.1.7600.16385_none_abf396ebf0847c31\NapiNSP.dll

< MD5 for: NLAAPI.DLL >
[2010/11/20 22:29:11 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=104A1070E90F1C530328E69B49718841 -- C:\Windows\winsxs\x86_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17514_none_698d5fb2692c5e70\nlaapi.dll
[2012/10/03 17:29:27 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=11B8C7970C10650827D060AA81BEE63F -- C:\Windows\winsxs\x86_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.22124_none_6a0c0c4b82524209\nlaapi.dll
[2012/10/03 17:42:26 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=50E0DD0A5B8D8BC353578F2F73926697 -- C:\Windows\System32\nlaapi.dll
[2012/10/03 17:42:26 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=50E0DD0A5B8D8BC353578F2F73926697 -- C:\Windows\winsxs\x86_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17964_none_695757ae6954dec1\nlaapi.dll

< MD5 for: PNRPNSP.DLL >
[2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\System32\pnrpnsp.dll
[2009/07/14 02:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\winsxs\x86_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.1.7600.16385_none_71556bd683c82a7a\pnrpnsp.dll

< MD5 for: PRINTISOLATIONHOST.EXE >
[2009/07/14 02:14:29 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=640A476C8867AEAAD8FF9F59A61AFE2F -- C:\Windows\System32\PrintIsolationHost.exe
[2009/07/14 02:14:29 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=640A476C8867AEAAD8FF9F59A61AFE2F -- C:\Windows\winsxs\x86_microsoft-windows-p..ng-server-isolation_31bf3856ad364e35_6.1.7600.16385_none_9c856911bff5c373\PrintIsolationHost.exe

< MD5 for: SERVICES.EXE >
[2009/07/14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\services.exe
[2009/07/14 02:14:36 | 000,259,072 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\svchost.exe
[2009/07/14 02:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USER32.DLL >
[2010/11/20 22:29:20 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\System32\user32.dll
[2010/11/20 22:29:20 | 000,811,520 | ---- | M] (Microsoft Corporation) MD5=F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 -- C:\Windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_cf3fd62ccb9e983d\user32.dll

< MD5 for: USERINIT.EXE >
[2010/11/20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\System32\userinit.exe
[2010/11/20 22:29:06 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\winlogon.exe
[2010/11/20 22:29:06 | 000,286,720 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe

< MD5 for: WINRNR.DLL >
[2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\System32\winrnr.dll
[2009/07/14 02:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.1.7600.16385_none_5924a912b169ccdb\winrnr.dll

< MD5 for: WSHELPER.DLL >
[2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\System32\wshelper.dll
[2009/07/14 02:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_045b589158ae90da\wshelper.dll

< C:\Windows\assembly\tmp\U\*.* /s >

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\ReinstallCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --make-default-browser [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\HideIconsCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --hide-icons [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\ShowIconsCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --show-icons [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\shell\open\command\\: "C:\Program Files\Comodo\Dragon\dragon.exe" [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2013/02/01 20:18:37 | 000,866,784 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2013/02/01 20:18:37 | 000,866,784 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013/02/01 20:18:37 | 000,866,784 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2013/02/01 19:21:00 | 000,917,400 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2013/02/01 19:21:00 | 000,917,400 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2013/02/01 19:21:00 | 000,917,400 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2010/11/20 22:29:32 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2010/11/20 22:29:32 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2010/11/20 22:29:32 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2010/11/20 22:29:33 | 000,673,040 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2010/11/20 22:29:33 | 000,673,040 | ---- | M] (Microsoft Corporation)

< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\ReinstallCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --make-default-browser [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\HideIconsCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --hide-icons [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\InstallInfo\\ShowIconsCommand: "C:\Program Files\Comodo\Dragon\dragon.exe" --show-icons [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Dragon\shell\open\command\\: "C:\Program Files\Comodo\Dragon\dragon.exe" [2013/01/24 12:52:00 | 001,761,424 | ---- | M] (Comodo)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2013/02/01 20:18:37 | 000,866,784 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2013/02/01 20:18:37 | 000,866,784 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013/02/01 20:18:37 | 000,866,784 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2013/02/01 19:21:00 | 000,917,400 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2013/02/01 19:21:00 | 000,917,400 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2013/02/01 19:21:00 | 000,917,400 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2010/11/20 22:29:32 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2010/11/20 22:29:32 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2010/11/20 22:29:32 | 000,176,128 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2010/11/20 22:29:33 | 000,673,040 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: C:\Program Files\Internet Explorer\iexplore.exe [2010/11/20 22:29:33 | 000,673,040 | ---- | M] (Microsoft Corporation)

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %ProgramFiles%\WINDOWS NT\*.* /s >
[2010/11/20 22:29:25 | 004,247,040 | ---- | M] (Microsoft Corporation) -- C:\Program Files\WINDOWS NT\Accessories\wordpad.exe
[2009/07/14 02:16:20 | 000,194,560 | ---- | M] (Microsoft Corporation) -- C:\Program Files\WINDOWS NT\Accessories\WordpadFilter.dll
[2011/04/12 02:35:21 | 000,186,880 | ---- | M] (Microsoft Corporation) -- C:\Program Files\WINDOWS NT\Accessories\fr-FR\wordpad.exe.mui
[2009/07/14 02:16:15 | 000,325,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\WINDOWS NT\TableTextService\TableTextService.dll
[2009/06/10 22:43:18 | 000,016,212 | ---- | M] () -- C:\Program Files\WINDOWS NT\TableTextService\TableTextServiceAmharic.txt
[2009/06/10 22:43:18 | 001,272,822 | ---- | M] () -- C:\Program Files\WINDOWS NT\TableTextService\TableTextServiceArray.txt
[2009/06/10 22:43:18 | 000,980,102 | ---- | M] () -- C:\Program Files\WINDOWS NT\TableTextService\TableTextServiceDaYi.txt
[2009/06/10 22:43:19 | 001,665,878 | ---- | M] () -- C:\Program Files\WINDOWS NT\TableTextService\TableTextServiceSimplifiedQuanPin.txt
[2009/06/10 22:43:19 | 001,445,430 | ---- | M] () -- C:\Program Files\WINDOWS NT\TableTextService\TableTextServiceSimplifiedShuangPin.txt
[2009/06/10 22:43:19 | 001,810,352 | ---- | M] () -- C:\Program Files\WINDOWS NT\TableTextService\TableTextServiceSimplifiedZhengMa.txt
[2009/06/10 22:43:19 | 000,044,968 | ---- | M] () -- C:\Program Files\WINDOWS NT\TableTextService\TableTextServiceYi.txt
[2011/04/12 02:35:14 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files\WINDOWS NT\TableTextService\fr-FR\TableTextService.dll.mui

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Alternate Data Streams ==========

@Alternate Data Stream - 202 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84

< End of report >

OTL Extras logfile created on: 14/02/2013 17:20:23 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\phil\Desktop
Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy

2,75 Gb Total Physical Memory | 1,38 Gb Available Physical Memory | 50,06% Memory free
5,50 Gb Paging File | 3,96 Gb Available in Paging File | 72,11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,79 Gb Total Space | 216,46 Gb Free Space | 92,99% Space Free | Partition Type: NTFS

Computer Name: PHIL-PC | User Name: phil | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\System32\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\System32\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\System32\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\System32\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\System32\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0F5B4A82-9DAF-3D13-8CB8-AEB25E4A614E}" = Microsoft .NET Framework 4 Client Profile FRA Language Pack
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{43C0CACD-F9A8-4F17-A84C-0A203B2BAE6D}" = GeekBuddy
"{A7DA4247-9F22-4d4a-974A-DD455CCF43B6}" = COMODO System Utilities
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = Panneau de configuration NVIDIA 310.90
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{BCC0552D-76C0-4130-BFBD-49BE49ACC594}" = COMODO Internet Security
"{C2F8CA82-2BD9-4513-B2D1-08A47914C1DA}_is1" = DriverScanner
"{C4ABDBC8-1C81-42C9-BFFC-4A68511E9E4F}" = TuneUp Utilities 2013
"{CCD96AE0-7A64-431F-ADEF-4AC02C82DBF2}" = TuneUp Utilities Language Pack (fr-FR)
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AIDA32_is1" = AIDA32 v3.93
"Browser Defender_is1" = Browser Guard 4.0
"CCleaner" = CCleaner
"Comodo Dragon" = Comodo Dragon
"EasyBCD" = EasyBCD 2.2
"ESET Online Scanner" = ESET Online Scanner v3
"Glary Utilities_is1" = Glary Utilities 2.53.0.1726
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Client Profile FRA Language Pack" = Module linguistique Microsoft .NET Framework 4 Client Profile FRA
"Mozilla Firefox 18.0.2 (x86 fr)" = Mozilla Firefox 18.0.2 (x86 fr)
"NVIDIA Drivers" = NVIDIA Drivers
"Spyware Doctor" = PC Tools Internet Security 9.1
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"TuneUp Utilities 2013" = TuneUp Utilities 2013
"UnHackMe_is1" = UnHackMe 5.99 release
"Unlocker" = Unlocker 1.9.1
"Usbfix" = UsbFix By El Desaparecido
"WinRAR archiver" = WinRAR 4.20 (32-bit)
"ZHPDiag_is1" = ZHPDiag 1.3.5
"ZHPFix_is1" = ZHPFix 1.3

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 14/02/2013 08:55:44 | Computer Name = phil-PC | Source = VSS | ID = 8193
Description =

Error - 14/02/2013 08:57:21 | Computer Name = phil-PC | Source = WinMgmt | ID = 10
Description =

Error - 14/02/2013 09:03:02 | Computer Name = phil-PC | Source = VSS | ID = 8193
Description =

Error - 14/02/2013 09:04:32 | Computer Name = phil-PC | Source = WinMgmt | ID = 10
Description =

Error - 14/02/2013 09:07:43 | Computer Name = phil-PC | Source = VSS | ID = 8193
Description =

Error - 14/02/2013 09:09:13 | Computer Name = phil-PC | Source = WinMgmt | ID = 10
Description =

Error - 14/02/2013 09:17:09 | Computer Name = phil-PC | Source = VSS | ID = 8193
Description =

Error - 14/02/2013 09:17:56 | Computer Name = phil-PC | Source = WinMgmt | ID = 10
Description =

Error - 14/02/2013 09:21:17 | Computer Name = phil-PC | Source = VSS | ID = 8193
Description =

Error - 14/02/2013 09:22:54 | Computer Name = phil-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 14/02/2013 08:55:46 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7024
Description = Le service Pare-feu Windows s’est arrêté avec l’erreur service particulière
%%5.

Error - 14/02/2013 09:03:04 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7024
Description = Le service Pare-feu Windows s’est arrêté avec l’erreur service particulière
%%5.

Error - 14/02/2013 09:07:45 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7024
Description = Le service Pare-feu Windows s’est arrêté avec l’erreur service particulière
%%5.

Error - 14/02/2013 09:07:45 | Computer Name = phil-PC | Source = Microsoft-Windows-WHEA-Logger | ID = 20
Description = Une erreur matérielle irrécupérable s’est produite. Composant : AMD
Northbridge Source de l’erreur : 3 Type d’erreur : 11 ID du processeur : 0 Pour plus
d’informations, consultez les détails de cette entrée.

Error - 14/02/2013 09:15:17 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7034
Description = Le service COMODO LPS Launcher s’est terminé de façon inattendue pour
la 1ème fois.

Error - 14/02/2013 09:17:11 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7024
Description = Le service Pare-feu Windows s’est arrêté avec l’erreur service particulière
%%5.

Error - 14/02/2013 09:21:17 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7024
Description = Le service Pare-feu Windows s’est arrêté avec l’erreur service particulière
%%5.

Error - 14/02/2013 10:34:02 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7003
Description = Le service Fournisseur HomeGroup dépend du service suivant : fdphost.
Ce dernier n’est peut-être pas installé.

Error - 14/02/2013 12:14:14 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7011
Description = Le dépassement de délai (30000 millisecondes) a été atteint lors de
l’attente de la réponse transactionnelle du service sdCoreService.

Error - 14/02/2013 12:14:18 | Computer Name = phil-PC | Source = Service Control Manager | ID = 7003
Description = Le service Fournisseur HomeGroup dépend du service suivant : fdphost.
Ce dernier n’est peut-être pas installé.


< End of report >

Attached Files


  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
I don't see anything bad. We can run some scans and see if anything turns up.



Download aswMBR.exe to your desktop.
Right click aswMBR.exe and Run as Administrator
uncheck trace disk IO calls
Click the "Scan" button to start scan (Accept the Avast Engine)
On completion of the scan if the Fix button is enabled (not the FixMBR button) press it and then run a new scan and click save log, save it to your desktop and post in your next reply
If the Fix button is not enabled then just click save log, save it to your desktop and post in your next reply

ComboFix

:!: It must be saved to your desktop, do not run it from your browser:!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Rightclick on ComboFix and select Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix.

A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.


Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then run it by right clicking and Run As Admin.


If TDSSKiller alerts you that the system needs to reboot, please consent.

Run TDSSKiller again but this time:
before you hit the Scan hit Change Parameters and check the two items under Additional Options. OK then Scan.
In this mode it is prone to false positives so do not change the SKIP option to DELETE unless it says TDSS.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.



Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:
http://www.malwareby...lwarebytes_free

SAVE Malwarebytes' Anti-Malware to your desktop.

* Right-click mbam-setup.exe and select Run As Administrator to start the program.
* follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.


Download the adwCleaner

  • Run the Tool
    Windows Vista and Windows 7 users:
    Right click in the adwCleaner.exe and select the option
    Posted Image
  • Select the Delete button.
  • When the scan completes, it will open a notepad windows.
  • Please, copy the content of this file in your next reply.

Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).

sfc  /scannow



(Does this complain that it could not fix all of your files?)


Right click on (My) Computer and select Manage (Continue) Then click on the arrow in front of Event Viewer. Next Click on the arrow in front of Windows Logs Right click on System and Clear Log, Clear. Repeat for Application.

Reboot.

1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application. VEW will overwrite the log at C:\vew.txt each time it runs so either post your System results before running VEW for Applications or copy the file c:\vew.txt to a new location.



Download, Save and Run (win 7 or Vista => Right click and Run as Admin.) farbar service scanner

Posted Image

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

Ron
  • 0

#5
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-02-19 16:55:25
-----------------------------
16:55:25.165 OS Version: Windows 6.1.7601 Service Pack 1
16:55:25.165 Number of processors: 2 586 0x301
16:55:25.165 ComputerName: PHIL-PC UserName: phil
16:55:26.117 Initialize success
16:58:22.997 AVAST engine defs: 13021900
16:58:27.957 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-5
16:58:27.973 Disk 0 Vendor: TOSHIBA_MK2552GSX LV011C Size: 238475MB BusType: 3
16:58:28.020 Disk 0 MBR read successfully
16:58:28.035 Disk 0 MBR scan
16:58:28.051 Disk 0 Windows 7 default MBR code
16:58:28.067 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 100 MB offset 2048
16:58:28.082 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 206848
16:58:28.098 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 238273 MB offset 411648
16:58:28.113 Disk 0 scanning sectors +488394752
16:58:28.191 Disk 0 scanning C:\Windows\system32\drivers
16:58:38.363 Service scanning
16:59:07.004 Modules scanning
16:59:16.161 AVAST engine scan C:\Windows
16:59:19.157 AVAST engine scan C:\Windows\system32
17:02:29.492 AVAST engine scan C:\Windows\system32\drivers
17:02:43.080 AVAST engine scan C:\Users\phil
17:03:47.321 AVAST engine scan C:\ProgramData
17:03:58.740 Scan finished successfully
17:04:27.943 Disk 0 MBR has been saved successfully to "C:\Users\phil\Desktop\MBR.dat"
17:04:27.959 The log file has been saved successfully to "C:\Users\phil\Desktop\aswMBR.txt"
  • 0

#6
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
ComboFix 13-02-18.02 - phil 19/02/2013 17:09:35.1.2 - x86
Microsoft Windows 7 Professionnel 6.1.7601.1.1252.33.1036.18.2814.1913 [GMT 1:00]
Lancé depuis: c:\users\phil\Desktop\ComboFix.exe
AV: AVG Anti-Virus 2013 *Disabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: AVG Anti-Virus 2013 *Disabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2013-01-19 au 2013-02-19 ))))))))))))))))))))))))))))))))))))
.
.
2013-02-19 16:14 . 2013-02-19 16:14 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-02-19 14:50 . 2013-02-19 14:50 -------- d-----w- c:\users\TEMP
2013-02-19 14:45 . 2013-02-19 14:45 -------- d-----w- c:\programdata\Malwarebytes
2013-02-19 14:45 . 2013-02-19 14:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-02-19 14:45 . 2012-12-14 15:49 21104 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-02-19 14:42 . 2013-02-19 14:42 -------- d-----w- c:\program files\mIRC
2013-02-19 14:38 . 2013-02-19 14:40 -------- d-----w- c:\program files\Universal Extractor
2013-02-19 14:31 . 2010-03-04 17:04 758784 ----a-r- c:\windows\system32\cohelper.dll
2013-02-19 14:31 . 2010-02-22 06:45 10084 ----a-r- c:\windows\system32\drivers\nvphy.bin
2013-02-19 14:31 . 2010-03-04 17:26 296936 ----a-w- c:\windows\system32\drivers\nvmf6232.sys
2013-02-19 14:31 . 2010-03-04 17:04 953856 ----a-w- c:\windows\system32\fdco2.dll
2013-02-19 14:31 . 2010-03-04 00:49 207464 ----a-w- c:\windows\system32\nvconrm.dll
2013-02-19 14:30 . 2010-03-22 17:29 18944 ----a-w- c:\windows\system32\drivers\nvsmu.sys
2013-02-19 14:30 . 2010-03-22 11:28 215656 ----a-w- c:\windows\system32\NVCOSMU.DLL
2013-02-19 14:08 . 2013-02-19 14:08 -------- d-----w- c:\program files\Software Informer
2013-02-19 14:01 . 2013-02-19 14:01 23456 ----a-w- c:\windows\system32\drivers\DrvAgent32.sys
2013-02-19 12:17 . 2013-02-19 12:17 -------- d-----w- c:\programdata\Babylon
2013-02-19 11:09 . 2013-02-19 11:10 -------- d-----w- c:\program files\NetWaiting
2013-02-19 11:09 . 2013-02-19 11:09 -------- d-----w- c:\program files\CONEXANT
2013-02-19 11:08 . 2013-02-19 11:08 -------- d-----w- C:\SWSETUP
2013-02-19 10:52 . 2013-02-19 10:52 -------- d-----w- c:\program files\AGEIA Technologies
2013-02-19 10:50 . 2012-12-29 08:25 2557880 ----a-w- c:\windows\system32\nvsvcr.dll
2013-02-19 10:48 . 2012-12-29 10:26 53176 ----a-w- c:\windows\system32\OpenCL.dll
2013-02-19 10:48 . 2013-02-19 10:48 -------- d-----w- c:\programdata\NVIDIA Corporation
2013-02-19 10:46 . 2013-02-19 14:30 -------- d-----w- c:\program files\NVIDIA Corporation
2013-02-19 10:11 . 2013-02-19 10:11 -------- d-----w- c:\programdata\Kaspersky Lab
2013-02-19 09:49 . 2013-02-19 13:00 -------- d-----w- c:\programdata\AVG2013
2013-02-19 09:49 . 2013-02-19 09:49 -------- d-----w- C:\$AVG
2013-02-19 09:48 . 2013-02-19 09:48 -------- d-----w- c:\program files\AVG
2013-02-19 09:45 . 2013-02-19 14:33 -------- d-----w- c:\programdata\MFAData
2013-02-19 09:45 . 2013-02-19 09:45 -------- d--h--w- c:\programdata\Common Files
2013-02-19 09:31 . 2013-02-19 09:33 -------- d-----w- c:\program files\NoVirusThanks
2013-02-19 08:51 . 2013-02-19 10:45 -------- d-----w- C:\NVIDIA
2013-02-19 07:39 . 2013-02-19 07:39 -------- d-----w- c:\program files\ma-config.com
2013-02-19 07:39 . 2013-02-19 07:39 -------- d-----w- c:\programdata\ma-config.com
2013-02-19 02:33 . 2013-02-19 02:33 -------- d-----w- c:\windows\system32\sda
2013-02-19 02:33 . 2013-02-19 11:10 -------- d--h--w- c:\program files\InstallShield Installation Information
2013-02-19 02:32 . 2010-10-29 15:11 197224 ----a-w- c:\windows\system32\drivers\RtsUStor.sys
2013-02-19 02:32 . 2013-02-19 02:32 -------- d-----w- c:\program files\Realtek
2013-02-19 02:32 . 2010-10-29 15:11 9888360 ----a-w- c:\windows\system32\RtsUStoricon.dll
2013-02-19 02:32 . 2010-10-29 15:11 313960 ----a-w- c:\windows\system32\RtsUStor.dll
2013-02-19 02:25 . 2013-02-19 13:02 -------- d-----w- c:\program files\Unlocker
2013-02-19 02:13 . 2013-02-19 13:10 -------- dc-h--w- c:\programdata\{A2866E3C-DFD9-4FD0-B6A2-96CB2431AC40}
2013-02-19 01:27 . 2013-02-19 14:48 -------- d-----w- c:\programdata\NVIDIA
2013-02-19 01:18 . 2013-02-19 01:18 -------- d-----w- c:\program files\NeoSmart Technologies
2013-02-19 00:47 . 2013-01-18 11:17 6991832 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{7E75CBB5-8CBC-4401-ADD5-42D4B1DF5FF8}\mpengine.dll
2013-02-19 00:47 . 2013-01-17 00:28 232336 ------w- c:\windows\system32\MpSigStub.exe
2013-02-19 00:39 . 2013-02-19 13:10 -------- d-sh--w- c:\windows\Installer
2013-02-19 00:39 . 2010-03-03 15:36 600680 ----a-w- c:\windows\system32\nvuninst.exe
2013-02-19 00:38 . 2012-02-17 05:34 826880 ----a-w- c:\windows\system32\rdpcore.dll
2013-02-19 00:38 . 2012-02-17 04:14 183808 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2013-02-19 00:38 . 2012-02-17 04:13 24576 ----a-w- c:\windows\system32\drivers\tdtcp.sys
2013-02-19 00:34 . 2012-06-02 22:19 53784 ----a-w- c:\windows\system32\wuauclt.exe
2013-02-19 00:34 . 2012-06-02 22:19 45080 ----a-w- c:\windows\system32\wups2.dll
2013-02-19 00:34 . 2012-06-02 22:19 1933848 ----a-w- c:\windows\system32\wuaueng.dll
2013-02-19 00:34 . 2012-06-02 22:12 2422272 ----a-w- c:\windows\system32\wucltux.dll
2013-02-19 00:34 . 2012-06-02 14:19 171904 ----a-w- c:\windows\system32\wuwebv.dll
2013-02-19 00:34 . 2012-06-02 14:12 33792 ----a-w- c:\windows\system32\wuapp.exe
2013-02-18 19:49 . 2013-02-19 00:30 -------- d-----w- c:\windows\Panther
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-29 10:26 . 2009-07-23 20:01 2504248 ----a-w- c:\windows\system32\nvapi.dll
2012-12-29 10:26 . 2009-07-23 20:01 15129064 ----a-w- c:\windows\system32\nvd3dum.dll
2012-12-29 10:26 . 2009-07-23 20:01 12641120 ----a-w- c:\windows\system32\nvwgf2um.dll
2012-12-29 08:26 . 2009-07-23 14:39 4129720 ----a-w- c:\windows\system32\nvcpl.dll
2012-12-29 08:26 . 2009-07-23 14:39 3001272 ----a-w- c:\windows\system32\nvsvc.dll
2012-12-29 08:25 . 2009-07-23 14:39 639928 ----a-w- c:\windows\system32\nvvsvc.exe
2012-12-29 08:25 . 2009-07-23 14:39 62904 ----a-w- c:\windows\system32\nvshext.dll
2012-12-29 08:25 . 2009-07-23 14:39 108984 ----a-w- c:\windows\system32\nvmctray.dll
2013-02-01 18:21 . 2013-02-19 00:46 262552 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2010-07-04 17408]
"AVG_UI"="c:\program files\AVG\AVG2013\avgui.exe" [2012-12-11 3147384]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2013\avgidsagent.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [x]
R3 DrvAgent32;DrvAgent32;c:\windows\system32\Drivers\DrvAgent32.sys [x]
R3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [x]
R3 SrvHsfHDA;SrvHsfHDA;c:\windows\system32\DRIVERS\VSTAZL3.SYS [x]
R3 SrvHsfV92;SrvHsfV92;c:\windows\system32\DRIVERS\VSTDPV3.SYS [x]
R3 SrvHsfWinac;SrvHsfWinac;c:\windows\system32\DRIVERS\VSTCNXT3.SYS [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [x]
S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [x]
S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [x]
S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [x]
S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [x]
S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [x]
S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [x]
S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [x]
S2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2013\avgwdsvc.exe [x]
S2 HsfXAudioService;HsfXAudioService;c:\windows\system32\svchost.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
.
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - ASWMBR
*Deregistered* - aswMBR
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HsfXAudioService REG_MULTI_SZ HsfXAudioService
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.babylon.com/?affID=14335&babsrc=HP_ss&mntrId=e0e0a82200000000000000226972a432
TCP: DhcpNameServer = 192.168.1.1
FF - ProfilePath - c:\users\phil\AppData\Roaming\Mozilla\Firefox\Profiles\yfysizgh.default\
FF - ExtSQL: 2013-02-19 01:47; {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}; c:\users\phil\AppData\Roaming\Mozilla\Firefox\Profiles\yfysizgh.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
.
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Heure de fin: 2013-02-19 17:16:12
ComboFix-quarantined-files.txt 2013-02-19 16:16
.
Avant-CF: 229 278 273 536 octets libres
Après-CF: 229 182 828 544 octets libres
.
- - End Of File - - 1BBDB8498CB714B8FE4B7C12A03827D3
  • 0

#7
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
17:21:52.0908 3496 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
17:21:53.0032 3496 ============================================================
17:21:53.0032 3496 Current date / time: 2013/02/19 17:21:53.0032
17:21:53.0032 3496 SystemInfo:
17:21:53.0032 3496
17:21:53.0032 3496 OS Version: 6.1.7601 ServicePack: 1.0
17:21:53.0032 3496 Product type: Workstation
17:21:53.0032 3496 ComputerName: PHIL-PC
17:21:53.0048 3496 UserName: phil
17:21:53.0048 3496 Windows directory: C:\Windows
17:21:53.0048 3496 System windows directory: C:\Windows
17:21:53.0048 3496 Processor architecture: Intel x86
17:21:53.0048 3496 Number of processors: 2
17:21:53.0048 3496 Page size: 0x1000
17:21:53.0048 3496 Boot type: Normal boot
17:21:53.0048 3496 ============================================================
17:21:55.0840 3496 BG loaded
17:21:57.0260 3496 Drive \Device\Harddisk0\DR0 - Size: 0x3A38B2E000 (232.89 Gb), SectorSize: 0x200, Cylinders: 0x76C1, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
17:21:57.0260 3496 ============================================================
17:21:57.0260 3496 \Device\Harddisk0\DR0:
17:21:57.0276 3496 MBR partitions:
17:21:57.0276 3496 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
17:21:57.0276 3496 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x32000
17:21:57.0276 3496 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x64800, BlocksNum 0x1D160800
17:21:57.0276 3496 ============================================================
17:21:57.0498 3496 C: <-> \Device\Harddisk0\DR0\Partition3
17:21:57.0529 3496 D: <-> \Device\Harddisk0\DR0\Partition1
17:21:57.0529 3496 ============================================================
17:21:57.0529 3496 Initialize success
17:21:57.0529 3496 ============================================================
17:22:10.0667 3820 ============================================================
17:22:10.0667 3820 Scan started
17:22:10.0667 3820 Mode: Manual; SigCheck; TDLFS;
17:22:10.0667 3820 ============================================================
17:22:11.0821 3820 ================ Scan system memory ========================
17:22:11.0837 3820 System memory - ok
17:22:11.0837 3820 ================ Scan services =============================
17:22:12.0024 3820 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
17:22:12.0242 3820 1394ohci - ok
17:22:12.0274 3820 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\Windows\system32\drivers\ACPI.sys
17:22:12.0320 3820 ACPI - ok
17:22:12.0336 3820 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
17:22:12.0430 3820 AcpiPmi - ok
17:22:12.0492 3820 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
17:22:12.0539 3820 adp94xx - ok
17:22:12.0554 3820 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\Windows\system32\drivers\adpahci.sys
17:22:12.0586 3820 adpahci - ok
17:22:12.0586 3820 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
17:22:12.0617 3820 adpu320 - ok
17:22:12.0664 3820 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:22:12.0835 3820 AeLookupSvc - ok
17:22:12.0866 3820 [ 1151FD4FB0216CFED887BFDE29EBD516 ] AFD C:\Windows\system32\drivers\afd.sys
17:22:12.0944 3820 AFD - ok
17:22:12.0976 3820 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\Windows\system32\drivers\agp440.sys
17:22:12.0991 3820 agp440 - ok
17:22:13.0022 3820 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
17:22:13.0038 3820 aic78xx - ok
17:22:13.0085 3820 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\Windows\System32\alg.exe
17:22:13.0163 3820 ALG - ok
17:22:13.0178 3820 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\Windows\system32\drivers\aliide.sys
17:22:13.0194 3820 aliide - ok
17:22:13.0210 3820 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\Windows\system32\drivers\amdagp.sys
17:22:13.0225 3820 amdagp - ok
17:22:13.0225 3820 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\Windows\system32\drivers\amdide.sys
17:22:13.0241 3820 amdide - ok
17:22:13.0256 3820 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
17:22:13.0288 3820 AmdK8 - ok
17:22:13.0303 3820 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:22:13.0334 3820 AmdPPM - ok
17:22:13.0366 3820 [ E7F4D42D8076EC60E21715CD11743A0D ] amdsata C:\Windows\system32\drivers\amdsata.sys
17:22:13.0366 3820 amdsata - ok
17:22:13.0397 3820 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
17:22:13.0412 3820 amdsbs - ok
17:22:13.0412 3820 [ 146459D2B08BFDCBFA856D9947043C81 ] amdxata C:\Windows\system32\drivers\amdxata.sys
17:22:13.0428 3820 amdxata - ok
17:22:13.0444 3820 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\Windows\system32\drivers\appid.sys
17:22:13.0475 3820 AppID - ok
17:22:13.0506 3820 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:22:13.0600 3820 AppIDSvc - ok
17:22:13.0600 3820 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\Windows\System32\appinfo.dll
17:22:13.0662 3820 Appinfo - ok
17:22:13.0724 3820 [ A45D184DF6A8803DA13A0B329517A64A ] AppMgmt C:\Windows\System32\appmgmts.dll
17:22:13.0802 3820 AppMgmt - ok
17:22:13.0865 3820 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\Windows\system32\drivers\arc.sys
17:22:13.0912 3820 arc - ok
17:22:13.0912 3820 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\Windows\system32\drivers\arcsas.sys
17:22:13.0927 3820 arcsas - ok
17:22:13.0958 3820 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:22:14.0114 3820 AsyncMac - ok
17:22:14.0130 3820 [ 338C86357871C167A96AB976519BF59E ] atapi C:\Windows\system32\drivers\atapi.sys
17:22:14.0130 3820 atapi - ok
17:22:14.0208 3820 [ 76BAB0C824E2D05B940C4DD40A9B08BF ] athr C:\Windows\system32\DRIVERS\athr.sys
17:22:14.0239 3820 athr - ok
17:22:14.0286 3820 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:22:14.0333 3820 AudioEndpointBuilder - ok
17:22:14.0348 3820 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:22:14.0380 3820 Audiosrv - ok
17:22:14.0785 3820 [ 4AFC14AFA58878FAA1D249E7E90EA54B ] AVGIDSAgent C:\Program Files\AVG\AVG2013\avgidsagent.exe
17:22:14.0910 3820 AVGIDSAgent - ok
17:22:14.0957 3820 [ 7BB2C605094DBCA536D127B434214862 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdriverx.sys
17:22:15.0050 3820 AVGIDSDriver - ok
17:22:15.0097 3820 [ 8F50F98686C9A397A19FCBAE284DB1C5 ] AVGIDSHX C:\Windows\system32\DRIVERS\avgidshx.sys
17:22:15.0113 3820 AVGIDSHX - ok
17:22:15.0144 3820 [ A8DE230CC8536790CA07D37FBCD87A74 ] AVGIDSShim C:\Windows\system32\DRIVERS\avgidsshimx.sys
17:22:15.0160 3820 AVGIDSShim - ok
17:22:15.0175 3820 [ D53D35031365A0ECCB1DC1BC1B15B18E ] Avgldx86 C:\Windows\system32\DRIVERS\avgldx86.sys
17:22:15.0191 3820 Avgldx86 - ok
17:22:15.0269 3820 [ 95889A9D23F3133250FA8AD13C982D58 ] Avglogx C:\Windows\system32\DRIVERS\avglogx.sys
17:22:15.0316 3820 Avglogx - ok
17:22:15.0331 3820 [ AF7AA9BA434CD28833A66E90993E8DFD ] Avgmfx86 C:\Windows\system32\DRIVERS\avgmfx86.sys
17:22:15.0331 3820 Avgmfx86 - ok
17:22:15.0394 3820 [ F3D57358DE0B8B3491013C615754A7C7 ] Avgrkx86 C:\Windows\system32\DRIVERS\avgrkx86.sys
17:22:15.0394 3820 Avgrkx86 - ok
17:22:15.0425 3820 [ BA73B38E9033FC6018DB736B635706AE ] Avgtdix C:\Windows\system32\DRIVERS\avgtdix.sys
17:22:15.0440 3820 Avgtdix - ok
17:22:15.0487 3820 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] avgwd C:\Program Files\AVG\AVG2013\avgwdsvc.exe
17:22:15.0503 3820 avgwd - ok
17:22:15.0550 3820 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:22:15.0643 3820 AxInstSV - ok
17:22:15.0690 3820 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\Windows\system32\drivers\bxvbdx.sys
17:22:15.0752 3820 b06bdrv - ok
17:22:15.0784 3820 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:22:15.0815 3820 b57nd60x - ok
17:22:15.0877 3820 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\Windows\System32\bdesvc.dll
17:22:15.0924 3820 BDESVC - ok
17:22:15.0940 3820 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\Windows\system32\drivers\Beep.sys
17:22:15.0971 3820 Beep - ok
17:22:16.0018 3820 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\Windows\System32\bfe.dll
17:22:16.0064 3820 BFE - ok
17:22:16.0127 3820 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\Windows\system32\qmgr.dll
17:22:16.0189 3820 BITS - ok
17:22:16.0220 3820 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:22:16.0236 3820 blbdrive - ok
17:22:16.0252 3820 [ FCAFAEF6798D7B51FF029F99A9898961 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:22:16.0298 3820 bowser - ok
17:22:16.0298 3820 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\Windows\system32\drivers\BrFiltLo.sys
17:22:16.0330 3820 BrFiltLo - ok
17:22:16.0345 3820 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\Windows\system32\drivers\BrFiltUp.sys
17:22:16.0376 3820 BrFiltUp - ok
17:22:16.0423 3820 [ 77361D72A04F18809D0EFB6CCEB74D4B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
17:22:16.0486 3820 BridgeMP - ok
17:22:16.0517 3820 [ 6E11F33D14D020F58D5E02E4D67DFA19 ] Browser C:\Windows\System32\browser.dll
17:22:16.0595 3820 Browser - ok
17:22:16.0626 3820 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:22:16.0688 3820 Brserid - ok
17:22:16.0704 3820 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:22:16.0766 3820 BrSerWdm - ok
17:22:16.0813 3820 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:22:16.0829 3820 BrUsbMdm - ok
17:22:16.0844 3820 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:22:16.0876 3820 BrUsbSer - ok
17:22:16.0891 3820 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
17:22:16.0922 3820 BTHMODEM - ok
17:22:16.0969 3820 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\Windows\system32\bthserv.dll
17:22:17.0016 3820 bthserv - ok
17:22:17.0141 3820 catchme - ok
17:22:17.0203 3820 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:22:17.0297 3820 cdfs - ok
17:22:17.0328 3820 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:22:17.0390 3820 cdrom - ok
17:22:17.0422 3820 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\Windows\System32\certprop.dll
17:22:17.0468 3820 CertPropSvc - ok
17:22:17.0515 3820 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\Windows\system32\drivers\circlass.sys
17:22:17.0531 3820 circlass - ok
17:22:17.0562 3820 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\Windows\system32\CLFS.sys
17:22:17.0578 3820 CLFS - ok
17:22:17.0671 3820 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:22:17.0718 3820 clr_optimization_v2.0.50727_32 - ok
17:22:17.0734 3820 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:22:17.0765 3820 CmBatt - ok
17:22:17.0780 3820 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\Windows\system32\drivers\cmdide.sys
17:22:17.0796 3820 cmdide - ok
17:22:17.0812 3820 [ 1B675691ED940766149C93E8F4488D68 ] CNG C:\Windows\system32\Drivers\cng.sys
17:22:17.0843 3820 CNG - ok
17:22:17.0858 3820 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:22:17.0874 3820 Compbatt - ok
17:22:17.0905 3820 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
17:22:17.0936 3820 CompositeBus - ok
17:22:17.0952 3820 COMSysApp - ok
17:22:17.0983 3820 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
17:22:17.0983 3820 crcdisk - ok
17:22:18.0030 3820 [ A585BEBF7D054BD9618EDA0922D5484A ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:22:18.0092 3820 CryptSvc - ok
17:22:18.0124 3820 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] CSC C:\Windows\system32\drivers\csc.sys
17:22:18.0186 3820 CSC - ok
17:22:18.0233 3820 [ 15F93B37F6801943360D9EB42485D5D3 ] CscService C:\Windows\System32\cscsvc.dll
17:22:18.0264 3820 CscService - ok
17:22:18.0311 3820 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\Windows\system32\rpcss.dll
17:22:18.0373 3820 DcomLaunch - ok
17:22:18.0420 3820 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\Windows\System32\defragsvc.dll
17:22:18.0498 3820 defragsvc - ok
17:22:18.0529 3820 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:22:18.0592 3820 DfsC - ok
17:22:18.0623 3820 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:22:18.0670 3820 Dhcp - ok
17:22:18.0685 3820 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\Windows\system32\drivers\discache.sys
17:22:18.0748 3820 discache - ok
17:22:18.0763 3820 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\Windows\system32\drivers\disk.sys
17:22:18.0794 3820 Disk - ok
17:22:18.0841 3820 [ 2A958EF85DB1B61FFCA65044FA4BCE9E ] dmvsc C:\Windows\system32\drivers\dmvsc.sys
17:22:18.0888 3820 dmvsc - ok
17:22:18.0919 3820 [ 2FE30D71919C51131405797620E0A714 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:22:18.0982 3820 Dnscache - ok
17:22:19.0013 3820 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\Windows\System32\dot3svc.dll
17:22:19.0075 3820 dot3svc - ok
17:22:19.0091 3820 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\Windows\system32\dps.dll
17:22:19.0153 3820 DPS - ok
17:22:19.0231 3820 [ 0F1189883690949BA7A9F68339587E51 ] driverhardwarev2 C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys
17:22:19.0278 3820 driverhardwarev2 - ok
17:22:19.0309 3820 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:22:19.0340 3820 drmkaud - ok
17:22:19.0418 3820 [ 651554E483712B708EDE864D0CA1AA73 ] DrvAgent32 C:\Windows\system32\Drivers\DrvAgent32.sys
17:22:19.0434 3820 DrvAgent32 ( UnsignedFile.Multi.Generic ) - warning
17:22:19.0434 3820 DrvAgent32 - detected UnsignedFile.Multi.Generic (1)
17:22:19.0496 3820 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:22:19.0543 3820 DXGKrnl - ok
17:22:19.0574 3820 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\Windows\System32\eapsvc.dll
17:22:19.0637 3820 EapHost - ok
17:22:19.0793 3820 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\Windows\system32\drivers\evbdx.sys
17:22:19.0886 3820 ebdrv - ok
17:22:19.0918 3820 [ F42309C4191C506B71DB5D1126D26318 ] EFS C:\Windows\System32\lsass.exe
17:22:19.0949 3820 EFS - ok
17:22:20.0027 3820 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\Windows\ehome\ehRecvr.exe
17:22:20.0105 3820 ehRecvr - ok
17:22:20.0120 3820 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\Windows\ehome\ehsched.exe
17:22:20.0152 3820 ehSched - ok
17:22:20.0198 3820 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\Windows\system32\drivers\elxstor.sys
17:22:20.0214 3820 elxstor - ok
17:22:20.0230 3820 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\Windows\system32\drivers\errdev.sys
17:22:20.0245 3820 ErrDev - ok
17:22:20.0323 3820 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\Windows\system32\es.dll
17:22:20.0386 3820 EventSystem - ok
17:22:20.0401 3820 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\Windows\system32\drivers\exfat.sys
17:22:20.0464 3820 exfat - ok
17:22:20.0479 3820 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:22:20.0526 3820 fastfat - ok
17:22:20.0557 3820 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\Windows\system32\fxssvc.exe
17:22:20.0604 3820 Fax - ok
17:22:20.0635 3820 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\Windows\system32\drivers\fdc.sys
17:22:20.0666 3820 fdc - ok
17:22:20.0682 3820 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\Windows\system32\fdPHost.dll
17:22:20.0760 3820 fdPHost - ok
17:22:20.0791 3820 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\Windows\system32\fdrespub.dll
17:22:20.0854 3820 FDResPub - ok
17:22:20.0854 3820 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:22:20.0869 3820 FileInfo - ok
17:22:20.0885 3820 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:22:20.0932 3820 Filetrace - ok
17:22:20.0947 3820 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\Windows\system32\drivers\flpydisk.sys
17:22:20.0978 3820 flpydisk - ok
17:22:20.0994 3820 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:22:21.0010 3820 FltMgr - ok
17:22:21.0056 3820 [ FA6C66E4364D7DA57AADE5DCC03BB999 ] FontCache C:\Windows\system32\FntCache.dll
17:22:21.0088 3820 FontCache - ok
17:22:21.0134 3820 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:22:21.0150 3820 FontCache3.0.0.0 - ok
17:22:21.0197 3820 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:22:21.0197 3820 FsDepends - ok
17:22:21.0212 3820 [ A574B4360E438977038AAE4BF60D79A2 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:22:21.0228 3820 Fs_Rec - ok
17:22:21.0244 3820 [ 8A73E79089B282100B9393B644CB853B ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:22:21.0259 3820 fvevol - ok
17:22:21.0275 3820 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
17:22:21.0290 3820 gagp30kx - ok
17:22:21.0337 3820 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\Windows\System32\gpsvc.dll
17:22:21.0384 3820 gpsvc - ok
17:22:21.0400 3820 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:22:21.0431 3820 hcw85cir - ok
17:22:21.0478 3820 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:22:21.0509 3820 HdAudAddService - ok
17:22:21.0524 3820 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
17:22:21.0556 3820 HDAudBus - ok
17:22:21.0571 3820 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\Windows\system32\drivers\HidBatt.sys
17:22:21.0587 3820 HidBatt - ok
17:22:21.0602 3820 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\Windows\system32\drivers\hidbth.sys
17:22:21.0634 3820 HidBth - ok
17:22:21.0649 3820 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\Windows\system32\drivers\hidir.sys
17:22:21.0665 3820 HidIr - ok
17:22:21.0696 3820 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\Windows\System32\hidserv.dll
17:22:21.0743 3820 hidserv - ok
17:22:21.0790 3820 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:22:21.0821 3820 HidUsb - ok
17:22:21.0836 3820 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:22:21.0883 3820 hkmsvc - ok
17:22:21.0899 3820 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:22:21.0930 3820 HomeGroupListener - ok
17:22:21.0961 3820 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:22:22.0008 3820 HomeGroupProvider - ok
17:22:22.0055 3820 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
17:22:22.0086 3820 HpSAMD - ok
17:22:22.0164 3820 [ 210388FD8225B02BD83D77628AAE64A9 ] HsfXAudioService C:\Windows\system32\XAudio32.dll
17:22:22.0211 3820 HsfXAudioService - ok
17:22:22.0258 3820 [ 227C3BA25012752BB7450235392C719F ] HSF_DPV C:\Windows\system32\DRIVERS\HSX_DPV.sys
17:22:22.0289 3820 HSF_DPV - ok
17:22:22.0320 3820 [ 4DF5C76302DC2F8F3465966C8426A292 ] HSXHWAZL C:\Windows\system32\DRIVERS\HSXHWAZL.sys
17:22:22.0351 3820 HSXHWAZL - ok
17:22:22.0382 3820 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:22:22.0414 3820 HTTP - ok
17:22:22.0429 3820 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:22:22.0445 3820 hwpolicy - ok
17:22:22.0460 3820 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
17:22:22.0492 3820 i8042prt - ok
17:22:22.0523 3820 [ A3CAE5D281DB4CFF7CFF8233507EE5AD ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
17:22:22.0554 3820 iaStorV - ok
17:22:22.0632 3820 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:22:22.0694 3820 idsvc - ok
17:22:22.0710 3820 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\Windows\system32\drivers\iirsp.sys
17:22:22.0726 3820 iirsp - ok
17:22:22.0772 3820 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\Windows\System32\ikeext.dll
17:22:22.0850 3820 IKEEXT - ok
17:22:22.0882 3820 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\Windows\system32\drivers\intelide.sys
17:22:22.0897 3820 intelide - ok
17:22:22.0928 3820 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\Windows\system32\drivers\intelppm.sys
17:22:22.0944 3820 intelppm - ok
17:22:22.0960 3820 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:22:22.0991 3820 IPBusEnum - ok
17:22:23.0006 3820 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:22:23.0053 3820 IpFilterDriver - ok
17:22:23.0131 3820 [ 4D65A07B795D6674312F879D09AA7663 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:22:23.0240 3820 iphlpsvc - ok
17:22:23.0272 3820 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
17:22:23.0287 3820 IPMIDRV - ok
17:22:23.0287 3820 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:22:23.0334 3820 IPNAT - ok
17:22:23.0365 3820 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:22:23.0396 3820 IRENUM - ok
17:22:23.0412 3820 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\Windows\system32\drivers\isapnp.sys
17:22:23.0428 3820 isapnp - ok
17:22:23.0443 3820 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
17:22:23.0459 3820 iScsiPrt - ok
17:22:23.0490 3820 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:22:23.0506 3820 kbdclass - ok
17:22:23.0521 3820 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\Windows\system32\drivers\kbdhid.sys
17:22:23.0552 3820 kbdhid - ok
17:22:23.0568 3820 [ F42309C4191C506B71DB5D1126D26318 ] KeyIso C:\Windows\system32\lsass.exe
17:22:23.0584 3820 KeyIso - ok
17:22:23.0599 3820 [ 412CEA1AA78CC02A447F5C9E62B32FF1 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:22:23.0615 3820 KSecDD - ok
17:22:23.0630 3820 [ 26C046977E85B95036453D7B88BA1820 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:22:23.0646 3820 KSecPkg - ok
17:22:23.0677 3820 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\Windows\system32\msdtckrm.dll
17:22:23.0724 3820 KtmRm - ok
17:22:23.0755 3820 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\Windows\System32\srvsvc.dll
17:22:23.0786 3820 LanmanServer - ok
17:22:23.0833 3820 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:22:23.0880 3820 LanmanWorkstation - ok
17:22:23.0927 3820 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:22:23.0974 3820 lltdio - ok
17:22:24.0005 3820 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:22:24.0052 3820 lltdsvc - ok
17:22:24.0067 3820 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\Windows\System32\lmhsvc.dll
17:22:24.0098 3820 lmhosts - ok
17:22:24.0130 3820 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
17:22:24.0130 3820 LSI_FC - ok
17:22:24.0161 3820 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
17:22:24.0176 3820 LSI_SAS - ok
17:22:24.0192 3820 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
17:22:24.0192 3820 LSI_SAS2 - ok
17:22:24.0223 3820 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
17:22:24.0239 3820 LSI_SCSI - ok
17:22:24.0239 3820 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\Windows\system32\drivers\luafv.sys
17:22:24.0286 3820 luafv - ok
17:22:24.0332 3820 [ 6EFFF93AB5144493879CF849FE55EF13 ] maconfservice C:\Program Files\ma-config.com\maconfservice.exe
17:22:24.0348 3820 maconfservice - ok
17:22:24.0410 3820 [ 629CABB0421668C9D3D402A3C3D77E14 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
17:22:24.0442 3820 MBAMProtector - ok
17:22:24.0520 3820 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:22:24.0551 3820 MBAMScheduler - ok
17:22:24.0598 3820 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:22:24.0644 3820 MBAMService - ok
17:22:24.0676 3820 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
17:22:24.0707 3820 Mcx2Svc - ok
17:22:24.0722 3820 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] mdmxsdk C:\Windows\system32\DRIVERS\mdmxsdk.sys
17:22:24.0738 3820 mdmxsdk - ok
17:22:24.0769 3820 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\Windows\system32\drivers\megasas.sys
17:22:24.0785 3820 megasas - ok
17:22:24.0847 3820 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
17:22:24.0894 3820 MegaSR - ok
17:22:24.0925 3820 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\Windows\system32\mmcss.dll
17:22:24.0988 3820 MMCSS - ok
17:22:24.0988 3820 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\Windows\system32\drivers\modem.sys
17:22:25.0050 3820 Modem - ok
17:22:25.0066 3820 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:22:25.0112 3820 monitor - ok
17:22:25.0128 3820 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:22:25.0128 3820 mouclass - ok
17:22:25.0159 3820 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:22:25.0190 3820 mouhid - ok
17:22:25.0190 3820 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:22:25.0206 3820 mountmgr - ok
17:22:25.0237 3820 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\Windows\system32\drivers\mpio.sys
17:22:25.0253 3820 mpio - ok
17:22:25.0253 3820 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:22:25.0300 3820 mpsdrv - ok
17:22:25.0346 3820 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:22:25.0393 3820 MpsSvc - ok
17:22:25.0409 3820 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:22:25.0456 3820 MRxDAV - ok
17:22:25.0487 3820 [ B272B4C3E085EA860C12F2E4FAF2FFA2 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:22:25.0534 3820 mrxsmb - ok
17:22:25.0549 3820 [ 9AC33EF26C8A3AD0F117D00EB7301D03 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:22:25.0596 3820 mrxsmb10 - ok
17:22:25.0627 3820 [ E0ABDB5ED7E199E242A7D028E76C1D3A ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:22:25.0658 3820 mrxsmb20 - ok
17:22:25.0658 3820 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\Windows\system32\drivers\msahci.sys
17:22:25.0674 3820 msahci - ok
17:22:25.0705 3820 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\Windows\system32\drivers\msdsm.sys
17:22:25.0721 3820 msdsm - ok
17:22:25.0752 3820 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\Windows\System32\msdtc.exe
17:22:25.0783 3820 MSDTC - ok
17:22:25.0799 3820 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:22:25.0846 3820 Msfs - ok
17:22:25.0861 3820 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:22:25.0908 3820 mshidkmdf - ok
17:22:25.0924 3820 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
17:22:25.0939 3820 msisadrv - ok
17:22:25.0970 3820 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:22:26.0017 3820 MSiSCSI - ok
17:22:26.0017 3820 msiserver - ok
17:22:26.0048 3820 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:22:26.0095 3820 MSKSSRV - ok
17:22:26.0111 3820 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:22:26.0173 3820 MSPCLOCK - ok
17:22:26.0173 3820 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:22:26.0220 3820 MSPQM - ok
17:22:26.0236 3820 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:22:26.0251 3820 MsRPC - ok
17:22:26.0267 3820 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
17:22:26.0282 3820 mssmbios - ok
17:22:26.0298 3820 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:22:26.0329 3820 MSTEE - ok
17:22:26.0329 3820 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\Windows\system32\drivers\MTConfig.sys
17:22:26.0360 3820 MTConfig - ok
17:22:26.0376 3820 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\Windows\system32\Drivers\mup.sys
17:22:26.0376 3820 Mup - ok
17:22:26.0407 3820 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\Windows\system32\qagentRT.dll
17:22:26.0454 3820 napagent - ok
17:22:26.0501 3820 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:22:26.0548 3820 NativeWifiP - ok
17:22:26.0610 3820 [ E7C54812A2AAF43316EB6930C1FFA108 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:22:26.0626 3820 NDIS - ok
17:22:26.0641 3820 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:22:26.0688 3820 NdisCap - ok
17:22:26.0719 3820 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:22:26.0766 3820 NdisTapi - ok
17:22:26.0797 3820 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:22:26.0844 3820 Ndisuio - ok
17:22:26.0844 3820 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:22:26.0891 3820 NdisWan - ok
17:22:26.0906 3820 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:22:26.0969 3820 NDProxy - ok
17:22:26.0984 3820 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:22:27.0016 3820 NetBIOS - ok
17:22:27.0031 3820 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:22:27.0078 3820 NetBT - ok
17:22:27.0094 3820 [ F42309C4191C506B71DB5D1126D26318 ] Netlogon C:\Windows\system32\lsass.exe
17:22:27.0109 3820 Netlogon - ok
17:22:27.0140 3820 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\Windows\System32\netman.dll
17:22:27.0187 3820 Netman - ok
17:22:27.0203 3820 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\Windows\System32\netprofm.dll
17:22:27.0250 3820 netprofm - ok
17:22:27.0281 3820 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
17:22:27.0328 3820 NetTcpPortSharing - ok
17:22:27.0374 3820 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
17:22:27.0390 3820 nfrd960 - ok
17:22:27.0406 3820 [ 912084381D30D8B89EC4E293053F4710 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:22:27.0452 3820 NlaSvc - ok
17:22:27.0452 3820 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:22:27.0499 3820 Npfs - ok
17:22:27.0530 3820 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\Windows\system32\nsisvc.dll
17:22:27.0577 3820 nsi - ok
17:22:27.0593 3820 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:22:27.0640 3820 nsiproxy - ok
17:22:27.0686 3820 [ 33C3093D09017CFE2E219F2472BFF6EB ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:22:27.0749 3820 Ntfs - ok
17:22:27.0780 3820 [ F9756A98D69098DCA8945D62858A812C ] Null C:\Windows\system32\drivers\Null.sys
17:22:27.0811 3820 Null - ok
17:22:27.0858 3820 [ B5E37E31C053BC9950455A257526514B ] NVENETFD C:\Windows\system32\DRIVERS\nvm62x32.sys
17:22:27.0889 3820 NVENETFD - ok
17:22:27.0967 3820 [ 77F9F9A199B87FE3F852E12F5419240B ] NVHDA C:\Windows\system32\drivers\nvhda32v.sys
17:22:27.0998 3820 NVHDA - ok
17:22:28.0342 3820 [ 2FA5434344AF84D73F66BA402FF78690 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:22:28.0560 3820 nvlddmkm - ok
17:22:28.0669 3820 [ 0219B05730635FCAB3A9925D3374C464 ] NVNET C:\Windows\system32\DRIVERS\nvmf6232.sys
17:22:28.0700 3820 NVNET - ok
17:22:28.0732 3820 [ AF2EEC9580C1D32FB7EAF105D9784061 ] nvraid C:\Windows\system32\drivers\nvraid.sys
17:22:28.0747 3820 nvraid - ok
17:22:28.0825 3820 [ 02A9F366BCB94B286E34825B2094CB38 ] nvsmu C:\Windows\system32\DRIVERS\nvsmu.sys
17:22:28.0888 3820 nvsmu - ok
17:22:28.0934 3820 [ 9283C58EBAA2618F93482EB5DABCEC82 ] nvstor C:\Windows\system32\drivers\nvstor.sys
17:22:28.0966 3820 nvstor - ok
17:22:29.0028 3820 [ B785320CBCF5021DE9945C803696C511 ] nvsvc C:\Windows\system32\nvvsvc.exe
17:22:29.0075 3820 nvsvc - ok
17:22:29.0215 3820 [ D2B064796C369F82E96397F721C4A29D ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
17:22:29.0262 3820 nvUpdatusService - ok
17:22:29.0278 3820 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
17:22:29.0293 3820 nv_agp - ok
17:22:29.0309 3820 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
17:22:29.0340 3820 ohci1394 - ok
17:22:29.0387 3820 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:22:29.0465 3820 p2pimsvc - ok
17:22:29.0496 3820 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\Windows\system32\p2psvc.dll
17:22:29.0512 3820 p2psvc - ok
17:22:29.0543 3820 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\Windows\system32\drivers\parport.sys
17:22:29.0558 3820 Parport - ok
17:22:29.0558 3820 [ BF8F6AF06DA75B336F07E23AEF97D93B ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:22:29.0574 3820 partmgr - ok
17:22:29.0590 3820 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\Windows\system32\drivers\parvdm.sys
17:22:29.0605 3820 Parvdm - ok
17:22:29.0621 3820 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:22:29.0636 3820 PcaSvc - ok
17:22:29.0668 3820 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\Windows\system32\drivers\pci.sys
17:22:29.0668 3820 pci - ok
17:22:29.0683 3820 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\Windows\system32\drivers\pciide.sys
17:22:29.0699 3820 pciide - ok
17:22:29.0746 3820 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
17:22:29.0808 3820 pcmcia - ok
17:22:29.0808 3820 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\Windows\system32\drivers\pcw.sys
17:22:29.0824 3820 pcw - ok
17:22:29.0855 3820 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:22:29.0902 3820 PEAUTH - ok
17:22:29.0948 3820 [ AF4D64D2A57B9772CF3801950B8058A6 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:22:29.0995 3820 PeerDistSvc - ok
17:22:30.0089 3820 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\Windows\system32\pla.dll
17:22:30.0182 3820 pla - ok
17:22:30.0245 3820 [ 92DC6E68D2C856C5C2F21AE9E22112B8 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:22:30.0307 3820 PlugPlay - ok
17:22:30.0338 3820 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:22:30.0370 3820 PNRPAutoReg - ok
17:22:30.0385 3820 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:22:30.0432 3820 PNRPsvc - ok
17:22:30.0463 3820 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:22:30.0494 3820 PolicyAgent - ok
17:22:30.0541 3820 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\Windows\system32\umpo.dll
17:22:30.0572 3820 Power - ok
17:22:30.0619 3820 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:22:30.0666 3820 PptpMiniport - ok
17:22:30.0682 3820 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\Windows\system32\drivers\processr.sys
17:22:30.0728 3820 Processor - ok
17:22:30.0760 3820 [ 43CA4CCC22D52FB58E8988F0198851D0 ] ProfSvc C:\Windows\system32\profsvc.dll
17:22:30.0791 3820 ProfSvc - ok
17:22:30.0806 3820 [ F42309C4191C506B71DB5D1126D26318 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:22:30.0822 3820 ProtectedStorage - ok
17:22:30.0853 3820 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:22:30.0884 3820 Psched - ok
17:22:30.0978 3820 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\Windows\system32\drivers\ql2300.sys
17:22:31.0025 3820 ql2300 - ok
17:22:31.0040 3820 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
17:22:31.0056 3820 ql40xx - ok
17:22:31.0087 3820 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\Windows\system32\qwave.dll
17:22:31.0118 3820 QWAVE - ok
17:22:31.0134 3820 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:22:31.0150 3820 QWAVEdrv - ok
17:22:31.0150 3820 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:22:31.0181 3820 RasAcd - ok
17:22:31.0212 3820 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:22:31.0243 3820 RasAgileVpn - ok
17:22:31.0259 3820 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\Windows\System32\rasauto.dll
17:22:31.0290 3820 RasAuto - ok
17:22:31.0306 3820 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:22:31.0352 3820 Rasl2tp - ok
17:22:31.0399 3820 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\Windows\System32\rasmans.dll
17:22:31.0446 3820 RasMan - ok
17:22:31.0477 3820 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:22:31.0508 3820 RasPppoe - ok
17:22:31.0524 3820 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:22:31.0555 3820 RasSstp - ok
17:22:31.0586 3820 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:22:31.0633 3820 rdbss - ok
17:22:31.0649 3820 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:22:31.0664 3820 rdpbus - ok
17:22:31.0664 3820 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:22:31.0711 3820 RDPCDD - ok
17:22:31.0758 3820 [ B973FCFC50DC1434E1970A146F7E3885 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:22:31.0805 3820 RDPDR - ok
17:22:31.0820 3820 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:22:31.0867 3820 RDPENCDD - ok
17:22:31.0898 3820 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:22:31.0930 3820 RDPREFMP - ok
17:22:31.0945 3820 [ 244C83332F44589AE98FC347F11B2693 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:22:31.0976 3820 RDPWD - ok
17:22:32.0008 3820 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:22:32.0039 3820 rdyboost - ok
17:22:32.0070 3820 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\Windows\System32\mprdim.dll
17:22:32.0086 3820 RemoteAccess - ok
17:22:32.0117 3820 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:22:32.0148 3820 RemoteRegistry - ok
17:22:32.0179 3820 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:22:32.0210 3820 RpcEptMapper - ok
17:22:32.0242 3820 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\Windows\system32\locator.exe
17:22:32.0273 3820 RpcLocator - ok
17:22:32.0304 3820 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\Windows\system32\rpcss.dll
17:22:32.0335 3820 RpcSs - ok
17:22:32.0382 3820 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:22:32.0444 3820 rspndr - ok
17:22:32.0491 3820 [ 247B0A8164069CD4FE6F3094C581B13B ] RSUSBSTOR C:\Windows\system32\Drivers\RtsUStor.sys
17:22:32.0522 3820 RSUSBSTOR - ok
17:22:32.0554 3820 [ 7FA7F2E249A5DCBB7970630E15E1F482 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
17:22:32.0585 3820 s3cap - ok
17:22:32.0600 3820 [ F42309C4191C506B71DB5D1126D26318 ] SamSs C:\Windows\system32\lsass.exe
17:22:32.0616 3820 SamSs - ok
17:22:32.0647 3820 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
17:22:32.0663 3820 sbp2port - ok
17:22:32.0678 3820 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:22:32.0741 3820 SCardSvr - ok
17:22:32.0756 3820 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:22:32.0803 3820 scfilter - ok
17:22:32.0850 3820 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\Windows\system32\schedsvc.dll
17:22:32.0928 3820 Schedule - ok
17:22:32.0944 3820 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\Windows\System32\certprop.dll
17:22:32.0959 3820 SCPolicySvc - ok
17:22:32.0990 3820 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:22:33.0006 3820 SDRSVC - ok
17:22:33.0037 3820 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:22:33.0084 3820 secdrv - ok
17:22:33.0100 3820 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\Windows\system32\seclogon.dll
17:22:33.0146 3820 seclogon - ok
17:22:33.0178 3820 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\Windows\system32\sens.dll
17:22:33.0209 3820 SENS - ok
17:22:33.0224 3820 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:22:33.0271 3820 SensrSvc - ok
17:22:33.0287 3820 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\Windows\system32\drivers\serenum.sys
17:22:33.0318 3820 Serenum - ok
17:22:33.0334 3820 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\Windows\system32\drivers\serial.sys
17:22:33.0412 3820 Serial - ok
17:22:33.0412 3820 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\Windows\system32\drivers\sermouse.sys
17:22:33.0443 3820 sermouse - ok
17:22:33.0474 3820 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\Windows\system32\sessenv.dll
17:22:33.0505 3820 SessionEnv - ok
17:22:33.0521 3820 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
17:22:33.0536 3820 sffdisk - ok
17:22:33.0552 3820 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
17:22:33.0568 3820 sffp_mmc - ok
17:22:33.0568 3820 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
17:22:33.0583 3820 sffp_sd - ok
17:22:33.0599 3820 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
17:22:33.0630 3820 sfloppy - ok
17:22:33.0646 3820 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:22:33.0677 3820 SharedAccess - ok
17:22:33.0692 3820 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:22:33.0739 3820 ShellHWDetection - ok
17:22:33.0755 3820 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\Windows\system32\drivers\sisagp.sys
17:22:33.0770 3820 sisagp - ok
17:22:33.0786 3820 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
17:22:33.0802 3820 SiSRaid2 - ok
17:22:33.0802 3820 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
17:22:33.0817 3820 SiSRaid4 - ok
17:22:33.0833 3820 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:22:33.0880 3820 Smb - ok
17:22:33.0911 3820 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:22:33.0926 3820 SNMPTRAP - ok
17:22:33.0942 3820 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\Windows\system32\drivers\spldr.sys
17:22:33.0942 3820 spldr - ok
17:22:33.0989 3820 [ 866A43013535DC8587C258E43579C764 ] Spooler C:\Windows\System32\spoolsv.exe
17:22:34.0036 3820 Spooler - ok
17:22:34.0176 3820 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\Windows\system32\sppsvc.exe
17:22:34.0301 3820 sppsvc - ok
17:22:34.0348 3820 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:22:34.0379 3820 sppuinotify - ok
17:22:34.0394 3820 [ 112127C3B2E64D7680CC39CD0A39DD7E ] srv C:\Windows\system32\DRIVERS\srv.sys
17:22:34.0426 3820 srv - ok
17:22:34.0441 3820 [ E5DD784A4EE5EBC72A86C677C988FCDB ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:22:34.0488 3820 srv2 - ok
17:22:34.0535 3820 [ E00FDFAFF025E94F9821153750C35A6D ] SrvHsfHDA C:\Windows\system32\DRIVERS\VSTAZL3.SYS
17:22:34.0550 3820 SrvHsfHDA - ok
17:22:34.0597 3820 [ CEB4E3B6890E1E42DCA6694D9E59E1A0 ] SrvHsfV92 C:\Windows\system32\DRIVERS\VSTDPV3.SYS
17:22:34.0644 3820 SrvHsfV92 - ok
17:22:34.0706 3820 [ BC0C7EA89194C299F051C24119000E17 ] SrvHsfWinac C:\Windows\system32\DRIVERS\VSTCNXT3.SYS
17:22:34.0738 3820 SrvHsfWinac - ok
17:22:34.0769 3820 [ CDBE627E16CC9E98F343D73F8E81D258 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:22:34.0800 3820 srvnet - ok
17:22:34.0816 3820 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:22:34.0862 3820 SSDPSRV - ok
17:22:34.0894 3820 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:22:34.0925 3820 SstpSvc - ok
17:22:34.0956 3820 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\Windows\system32\drivers\stexstor.sys
17:22:34.0956 3820 stexstor - ok
17:22:35.0003 3820 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\Windows\System32\wiaservc.dll
17:22:35.0050 3820 StiSvc - ok
17:22:35.0065 3820 [ 472AF0311073DCECEAA8FA18BA2BDF89 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
17:22:35.0081 3820 storflt - ok
17:22:35.0128 3820 [ 0BF669F0A910BEDA4A32258D363AF2A5 ] StorSvc C:\Windows\system32\storsvc.dll
17:22:35.0159 3820 StorSvc - ok
17:22:35.0174 3820 [ DCAFFD62259E0BDB433DD67B5BB37619 ] storvsc C:\Windows\system32\drivers\storvsc.sys
17:22:35.0190 3820 storvsc - ok
17:22:35.0206 3820 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
17:22:35.0221 3820 swenum - ok
17:22:35.0252 3820 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\Windows\System32\swprv.dll
17:22:35.0299 3820 swprv - ok
17:22:35.0330 3820 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\Windows\system32\sysmain.dll
17:22:35.0377 3820 SysMain - ok
17:22:35.0377 3820 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:22:35.0408 3820 TabletInputService - ok
17:22:35.0424 3820 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\Windows\System32\tapisrv.dll
17:22:35.0471 3820 TapiSrv - ok
17:22:35.0502 3820 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\Windows\System32\tbssvc.dll
17:22:35.0549 3820 TBS - ok
17:22:35.0611 3820 [ 37E8FA3779668837CA9E2C36D2415949 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:22:35.0642 3820 Tcpip - ok
17:22:35.0689 3820 [ 37E8FA3779668837CA9E2C36D2415949 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:22:35.0720 3820 TCPIP6 - ok
17:22:35.0752 3820 [ CCA24162E055C3714CE5A88B100C64ED ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:22:35.0783 3820 tcpipreg - ok
17:22:35.0798 3820 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:22:35.0814 3820 TDPIPE - ok
17:22:35.0845 3820 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:22:35.0861 3820 TDTCP - ok
17:22:35.0861 3820 [ B459575348C20E8121D6039DA063C704 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:22:35.0908 3820 tdx - ok
17:22:35.0923 3820 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
17:22:35.0939 3820 TermDD - ok
17:22:35.0986 3820 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\Windows\System32\termsrv.dll
17:22:36.0017 3820 TermService - ok
17:22:36.0032 3820 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\Windows\system32\themeservice.dll
17:22:36.0064 3820 Themes - ok
17:22:36.0079 3820 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\Windows\system32\mmcss.dll
17:22:36.0126 3820 THREADORDER - ok
17:22:36.0157 3820 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\Windows\System32\trkwks.dll
17:22:36.0188 3820 TrkWks - ok
17:22:36.0251 3820 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:22:36.0344 3820 TrustedInstaller - ok
17:22:36.0360 3820 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:22:36.0391 3820 tssecsrv - ok
17:22:36.0407 3820 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
17:22:36.0438 3820 TsUsbFlt - ok
17:22:36.0469 3820 [ 01246F0BAAD7B68EC0F472AA41E33282 ] TsUsbGD C:\Windows\system32\drivers\TsUsbGD.sys
17:22:36.0500 3820 TsUsbGD - ok
17:22:36.0516 3820 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:22:36.0547 3820 tunnel - ok
17:22:36.0578 3820 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\Windows\system32\drivers\uagp35.sys
17:22:36.0578 3820 uagp35 - ok
17:22:36.0594 3820 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:22:36.0641 3820 udfs - ok
17:22:36.0672 3820 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:22:36.0688 3820 UI0Detect - ok
17:22:36.0719 3820 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
17:22:36.0734 3820 uliagpkx - ok
17:22:36.0750 3820 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\Windows\system32\DRIVERS\umbus.sys
17:22:36.0781 3820 umbus - ok
17:22:36.0797 3820 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\Windows\system32\drivers\umpass.sys
17:22:36.0828 3820 UmPass - ok
17:22:36.0859 3820 [ 409994A8EACEEE4E328749C0353527A0 ] UmRdpService C:\Windows\System32\umrdp.dll
17:22:36.0875 3820 UmRdpService - ok
17:22:36.0906 3820 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\Windows\System32\upnphost.dll
17:22:36.0953 3820 upnphost - ok
17:22:36.0968 3820 [ 7E72E7D7E0757D59481D530FD2B0BFAE ] usbccgp C:\Windows\system32\drivers\usbccgp.sys
17:22:37.0000 3820 usbccgp - ok
17:22:37.0015 3820 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\Windows\system32\drivers\usbcir.sys
17:22:37.0031 3820 usbcir - ok
17:22:37.0046 3820 [ CFBCE999C057D78979A181C9C60F208E ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:22:37.0062 3820 usbehci - ok
17:22:37.0093 3820 [ 9D22AAD9AC6A07C691A1113E5F860868 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:22:37.0109 3820 usbhub - ok
17:22:37.0124 3820 [ A6FB7957EA7AFB1165991E54CE934B74 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:22:37.0140 3820 usbohci - ok
17:22:37.0156 3820 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\Windows\system32\drivers\usbprint.sys
17:22:37.0187 3820 usbprint - ok
17:22:37.0202 3820 [ BF63EBFC6979FEFB2BC03DF7989A0C1A ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:22:37.0218 3820 USBSTOR - ok
17:22:37.0218 3820 [ 78780C3EBCE17405B1CCD07A3A8A7D72 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
17:22:37.0249 3820 usbuhci - ok
17:22:37.0280 3820 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\Windows\System32\uxsms.dll
17:22:37.0312 3820 UxSms - ok
17:22:37.0327 3820 [ F42309C4191C506B71DB5D1126D26318 ] VaultSvc C:\Windows\system32\lsass.exe
17:22:37.0343 3820 VaultSvc - ok
17:22:37.0374 3820 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
17:22:37.0390 3820 vdrvroot - ok
17:22:37.0421 3820 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\Windows\System32\vds.exe
17:22:37.0468 3820 vds - ok
17:22:37.0468 3820 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:22:37.0499 3820 vga - ok
17:22:37.0514 3820 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:22:37.0546 3820 VgaSave - ok
17:22:37.0561 3820 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
17:22:37.0577 3820 vhdmp - ok
17:22:37.0592 3820 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\Windows\system32\drivers\viaagp.sys
17:22:37.0608 3820 viaagp - ok
17:22:37.0624 3820 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\Windows\system32\drivers\viac7.sys
17:22:37.0639 3820 ViaC7 - ok
17:22:37.0639 3820 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\Windows\system32\drivers\viaide.sys
17:22:37.0655 3820 viaide - ok
17:22:37.0686 3820 [ C2F2911156FDC7817C52829C86DA494E ] vmbus C:\Windows\system32\drivers\vmbus.sys
17:22:37.0733 3820 vmbus - ok
17:22:37.0748 3820 [ D4D77455211E204F370D08F4963063CE ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
17:22:37.0780 3820 VMBusHID - ok
17:22:37.0795 3820 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\Windows\system32\drivers\volmgr.sys
17:22:37.0811 3820 volmgr - ok
17:22:37.0826 3820 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:22:37.0842 3820 volmgrx - ok
17:22:37.0858 3820 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\Windows\system32\drivers\volsnap.sys
17:22:37.0873 3820 volsnap - ok
17:22:37.0904 3820 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
17:22:37.0920 3820 vsmraid - ok
17:22:37.0982 3820 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\Windows\system32\vssvc.exe
17:22:38.0029 3820 VSS - ok
17:22:38.0045 3820 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
17:22:38.0060 3820 vwifibus - ok
17:22:38.0107 3820 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
17:22:38.0138 3820 vwififlt - ok
17:22:38.0138 3820 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\Windows\system32\w32time.dll
17:22:38.0185 3820 W32Time - ok
17:22:38.0201 3820 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
17:22:38.0232 3820 WacomPen - ok
17:22:38.0248 3820 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:22:38.0279 3820 WANARP - ok
17:22:38.0279 3820 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:22:38.0310 3820 Wanarpv6 - ok
17:22:38.0388 3820 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\Windows\system32\wbengine.exe
17:22:38.0450 3820 wbengine - ok
17:22:38.0466 3820 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:22:38.0513 3820 WbioSrvc - ok
17:22:38.0528 3820 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:22:38.0560 3820 wcncsvc - ok
17:22:38.0575 3820 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:22:38.0606 3820 WcsPlugInService - ok
17:22:38.0638 3820 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\Windows\system32\drivers\wd.sys
17:22:38.0653 3820 Wd - ok
17:22:38.0669 3820 [ 9950E3D0F08141C7E89E64456AE7DC73 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:22:38.0700 3820 Wdf01000 - ok
17:22:38.0731 3820 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:22:38.0809 3820 WdiServiceHost - ok
17:22:38.0809 3820 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:22:38.0840 3820 WdiSystemHost - ok
17:22:38.0856 3820 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\Windows\System32\webclnt.dll
17:22:38.0903 3820 WebClient - ok
17:22:38.0918 3820 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:22:38.0950 3820 Wecsvc - ok
17:22:38.0981 3820 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:22:39.0028 3820 wercplsupport - ok
17:22:39.0059 3820 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\Windows\System32\WerSvc.dll
17:22:39.0090 3820 WerSvc - ok
17:22:39.0137 3820 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:22:39.0184 3820 WfpLwf - ok
17:22:39.0184 3820 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:22:39.0199 3820 WIMMount - ok
17:22:39.0277 3820 [ 8B976D4CA270110111DF4F313DA0E6E8 ] winachsf C:\Windows\system32\DRIVERS\HSX_CNXT.sys
17:22:39.0324 3820 winachsf - ok
17:22:39.0402 3820 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:22:39.0464 3820 WinDefend - ok
17:22:39.0464 3820 WinHttpAutoProxySvc - ok
17:22:39.0542 3820 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:22:39.0605 3820 Winmgmt - ok
17:22:39.0667 3820 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\Windows\system32\WsmSvc.dll
17:22:39.0745 3820 WinRM - ok
17:22:39.0823 3820 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:22:39.0854 3820 Wlansvc - ok
17:22:39.0886 3820 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
17:22:39.0901 3820 WmiAcpi - ok
17:22:39.0932 3820 [ 6EB6B66517B048D87DC1856DDF1F4C3F ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:22:39.0964 3820 wmiApSrv - ok
17:22:40.0073 3820 [ 3B40D3A61AA8C21B88AE57C58AB3122E ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
17:22:40.0135 3820 WMPNetworkSvc - ok
17:22:40.0166 3820 [ A2F0EC770A92F2B3F9DE6D518E11409C ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:22:40.0198 3820 WPCSvc - ok
17:22:40.0198 3820 [ AA53356D60AF47EACC85BC617A4F3F66 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:22:40.0307 3820 WPDBusEnum - ok
17:22:40.0338 3820 [ 6DB3276587B853BF886B69528FDB048C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:22:40.0385 3820 ws2ifsl - ok
17:22:40.0400 3820 [ 6F5D49EFE0E7164E03AE773A3FE25340 ] wscsvc C:\Windows\system32\wscsvc.dll
17:22:40.0447 3820 wscsvc - ok
17:22:40.0447 3820 WSearch - ok
17:22:40.0572 3820 [ FC3EC24FCE372C89423E015A2AC1A31E ] wuauserv C:\Windows\system32\wuaueng.dll
17:22:40.0619 3820 wuauserv - ok
17:22:40.0650 3820 [ E714A1C0354636837E20CCBF00888EE7 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:22:40.0681 3820 WudfPf - ok
17:22:40.0712 3820 [ 1023EE888C9B47178C5293ED5336AB69 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:22:40.0759 3820 WUDFRd - ok
17:22:40.0806 3820 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:22:40.0884 3820 wudfsvc - ok
17:22:40.0900 3820 [ FF2D745B560F7C71B31F30F4D49F73D2 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:22:40.0915 3820 WwanSvc - ok
17:22:40.0946 3820 [ 894F963BE999BA9DB5AAC3AED55B115D ] XAudio C:\Windows\system32\DRIVERS\XAudio32.sys
17:22:40.0962 3820 XAudio - ok
17:22:40.0993 3820 ================ Scan global ===============================
17:22:41.0024 3820 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\system32\basesrv.dll
17:22:41.0040 3820 [ A9F564F254E9DDDE120A7135767EC24B ] C:\Windows\system32\winsrv.dll
17:22:41.0056 3820 [ A9F564F254E9DDDE120A7135767EC24B ] C:\Windows\system32\winsrv.dll
17:22:41.0071 3820 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\system32\sxssrv.dll
17:22:41.0118 3820 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\system32\services.exe
17:22:41.0134 3820 [Global] - ok
17:22:41.0134 3820 ================ Scan MBR ==================================
17:22:41.0165 3820 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:22:41.0555 3820 \Device\Harddisk0\DR0 - ok
17:22:41.0555 3820 ================ Scan VBR ==================================
17:22:41.0602 3820 [ AE2A303C61797E45FA6D0E8EC1B275BB ] \Device\Harddisk0\DR0\Partition1
17:22:41.0602 3820 \Device\Harddisk0\DR0\Partition1 - ok
17:22:41.0617 3820 [ 217DF6A3DC1C7097F5BD70D4A9D3838F ] \Device\Harddisk0\DR0\Partition2
17:22:41.0633 3820 \Device\Harddisk0\DR0\Partition2 - ok
17:22:41.0633 3820 [ 14F3809B516DEB0DBEC897ED3BC4016A ] \Device\Harddisk0\DR0\Partition3
17:22:41.0648 3820 \Device\Harddisk0\DR0\Partition3 - ok
17:22:41.0648 3820 ================ Scan active images ========================
17:22:41.0648 3820 [ B7EFEF22FF426EC4158A177CB3B558D3 ] C:\Windows\System32\drivers\crashdmp.sys
17:22:41.0648 3820 C:\Windows\System32\drivers\crashdmp.sys - ok
17:22:41.0664 3820 [ 338C86357871C167A96AB976519BF59E ] C:\Windows\System32\drivers\atapi.sys
17:22:41.0664 3820 C:\Windows\System32\drivers\atapi.sys - ok
17:22:41.0680 3820 [ 5428227D4730EBDFC842E9FB593F8C8A ] C:\Windows\System32\drivers\Dumpata.sys
17:22:41.0680 3820 C:\Windows\System32\drivers\Dumpata.sys - ok
17:22:41.0680 3820 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] C:\Windows\System32\drivers\cdrom.sys
17:22:41.0680 3820 C:\Windows\System32\drivers\cdrom.sys - ok
17:22:41.0695 3820 [ 505506526A9D467307B3C393DEDAF858 ] C:\Windows\System32\drivers\beep.sys
17:22:41.0695 3820 C:\Windows\System32\drivers\beep.sys - ok
17:22:41.0695 3820 [ F9756A98D69098DCA8945D62858A812C ] C:\Windows\System32\drivers\null.sys
17:22:41.0695 3820 C:\Windows\System32\drivers\null.sys - ok
17:22:41.0711 3820 [ 8E38096AD5C8570A6F1570A61E251561 ] C:\Windows\System32\drivers\vga.sys
17:22:41.0711 3820 C:\Windows\System32\drivers\vga.sys - ok
17:22:41.0726 3820 [ 15C126D1B55814B9E5CAB10A9C1F4C67 ] C:\Windows\System32\drivers\videoprt.sys
17:22:41.0726 3820 C:\Windows\System32\drivers\videoprt.sys - ok
17:22:41.0726 3820 [ CB45A417C8EF7BA6BAC67EDCDDED8700 ] C:\Windows\System32\drivers\watchdog.sys
17:22:41.0726 3820 C:\Windows\System32\drivers\watchdog.sys - ok
17:22:41.0742 3820 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] C:\Windows\System32\drivers\msfs.sys
17:22:41.0742 3820 C:\Windows\System32\drivers\msfs.sys - ok
17:22:41.0742 3820 [ 23DAE03F29D253AE74C44F99E515F9A1 ] C:\Windows\System32\drivers\RDPCDD.sys
17:22:41.0742 3820 C:\Windows\System32\drivers\RDPCDD.sys - ok
17:22:41.0758 3820 [ 5A53CA1598DD4156D44196D200C94B8A ] C:\Windows\System32\drivers\RDPENCDD.sys
17:22:41.0758 3820 C:\Windows\System32\drivers\RDPENCDD.sys - ok
17:22:41.0773 3820 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] C:\Windows\System32\drivers\RDPREFMP.sys
17:22:41.0773 3820 C:\Windows\System32\drivers\RDPREFMP.sys - ok
17:22:41.0773 3820 [ 1DB262A9F8C087E8153D89BEF3D2235F ] C:\Windows\System32\drivers\npfs.sys
17:22:41.0773 3820 C:\Windows\System32\drivers\npfs.sys - ok
17:22:41.0789 3820 [ 2F885864D5BC8A16C86BEE595969A48A ] C:\Windows\System32\drivers\tdi.sys
17:22:41.0789 3820 C:\Windows\System32\drivers\tdi.sys - ok
17:22:41.0789 3820 [ B459575348C20E8121D6039DA063C704 ] C:\Windows\System32\drivers\tdx.sys
17:22:41.0789 3820 C:\Windows\System32\drivers\tdx.sys - ok
17:22:41.0804 3820 [ BA73B38E9033FC6018DB736B635706AE ] C:\Windows\System32\drivers\avgtdix.sys
17:22:41.0804 3820 C:\Windows\System32\drivers\avgtdix.sys - ok
17:22:41.0820 3820 [ 280122DDCF04B378EDD1AD54D71C1E54 ] C:\Windows\System32\drivers\netbt.sys
17:22:41.0820 3820 C:\Windows\System32\drivers\netbt.sys - ok
17:22:41.0820 3820 [ 1151FD4FB0216CFED887BFDE29EBD516 ] C:\Windows\System32\drivers\afd.sys
17:22:41.0820 3820 C:\Windows\System32\drivers\afd.sys - ok
17:22:41.0836 3820 [ 6DB3276587B853BF886B69528FDB048C ] C:\Windows\System32\drivers\ws2ifsl.sys
17:22:41.0836 3820 C:\Windows\System32\drivers\ws2ifsl.sys - ok
17:22:41.0851 3820 [ 6270CCAE2A86DE6D146529FE55B3246A ] C:\Windows\System32\drivers\pacer.sys
17:22:41.0851 3820 C:\Windows\System32\drivers\pacer.sys - ok
17:22:41.0867 3820 [ 7090D3436EEB4E7DA3373090A23448F7 ] C:\Windows\System32\drivers\vwififlt.sys
17:22:41.0867 3820 C:\Windows\System32\drivers\vwififlt.sys - ok
17:22:41.0867 3820 [ 8B9A943F3B53861F2BFAF6C186168F79 ] C:\Windows\System32\drivers\wfplwf.sys
17:22:41.0867 3820 C:\Windows\System32\drivers\wfplwf.sys - ok
17:22:41.0882 3820 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] C:\Windows\System32\drivers\netbios.sys
17:22:41.0882 3820 C:\Windows\System32\drivers\netbios.sys - ok
17:22:41.0898 3820 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] C:\Windows\System32\drivers\wanarp.sys
17:22:41.0898 3820 C:\Windows\System32\drivers\wanarp.sys - ok
17:22:41.0914 3820 [ FC6B9FF600CC585EA38B12589BD4E246 ] C:\Windows\System32\drivers\mssmbios.sys
17:22:41.0914 3820 C:\Windows\System32\drivers\mssmbios.sys - ok
17:22:41.0914 3820 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] C:\Windows\System32\drivers\nsiproxy.sys
17:22:41.0914 3820 C:\Windows\System32\drivers\nsiproxy.sys - ok
17:22:41.0929 3820 [ D528BC58A489409BA40334EBF96A311B ] C:\Windows\System32\drivers\rdbss.sys
17:22:41.0929 3820 C:\Windows\System32\drivers\rdbss.sys - ok
17:22:41.0929 3820 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] C:\Windows\System32\drivers\termdd.sys
17:22:41.0929 3820 C:\Windows\System32\drivers\termdd.sys - ok
17:22:41.0945 3820 [ 3C2177A897B4CA2788C6FB0C3FD81D4B ] C:\Windows\System32\drivers\csc.sys
17:22:41.0945 3820 C:\Windows\System32\drivers\csc.sys - ok
17:22:41.0960 3820 [ 1A050B0274BFB3890703D490F330C0DA ] C:\Windows\System32\drivers\discache.sys
17:22:41.0960 3820 C:\Windows\System32\drivers\discache.sys - ok
17:22:41.0960 3820 [ D53D35031365A0ECCB1DC1BC1B15B18E ] C:\Windows\System32\drivers\avgldx86.sys
17:22:41.0960 3820 C:\Windows\System32\drivers\avgldx86.sys - ok
17:22:41.0976 3820 [ 2287078ED48FCFC477B05B20CF38F36F ] C:\Windows\System32\drivers\blbdrive.sys
17:22:41.0976 3820 C:\Windows\System32\drivers\blbdrive.sys - ok
17:22:41.0976 3820 [ F024449C97EC1E464AAFFDA18593DB88 ] C:\Windows\System32\drivers\dfsc.sys
17:22:41.0976 3820 C:\Windows\System32\drivers\dfsc.sys - ok
17:22:41.0992 3820 [ A8DE230CC8536790CA07D37FBCD87A74 ] C:\Windows\System32\drivers\avgidsshimx.sys
17:22:41.0992 3820 C:\Windows\System32\drivers\avgidsshimx.sys - ok
17:22:41.0992 3820 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] C:\Windows\System32\drivers\amdppm.sys
17:22:42.0007 3820 C:\Windows\System32\drivers\amdppm.sys - ok
17:22:42.0007 3820 [ 7BB2C605094DBCA536D127B434214862 ] C:\Windows\System32\drivers\avgidsdriverx.sys
17:22:42.0007 3820 C:\Windows\System32\drivers\avgidsdriverx.sys - ok
17:22:42.0023 3820 [ B2FA25D9B17A68BB93D58B0556E8C90D ] C:\Windows\System32\drivers\tunnel.sys
17:22:42.0023 3820 C:\Windows\System32\drivers\tunnel.sys - ok
17:22:42.0023 3820 [ ED60C95C805DBAEE92C90C3AB930085A ] C:\Windows\System32\ntdll.dll
17:22:42.0023 3820 C:\Windows\System32\ntdll.dll - ok
17:22:42.0038 3820 [ 16742790895960690237A5143CEDEC8B ] C:\Windows\System32\smss.exe
17:22:42.0038 3820 C:\Windows\System32\smss.exe - ok
17:22:42.0038 3820 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] C:\Windows\System32\drivers\i8042prt.sys
17:22:42.0038 3820 C:\Windows\System32\drivers\i8042prt.sys - ok
17:22:42.0054 3820 [ ADEF52CA1AEAE82B50DF86B56413107E ] C:\Windows\System32\drivers\kbdclass.sys
17:22:42.0054 3820 C:\Windows\System32\drivers\kbdclass.sys - ok
17:22:42.0070 3820 [ 0217679B8FCA58714C3BF2726D2CA84E ] C:\Windows\System32\drivers\wmiacpi.sys
17:22:42.0070 3820 C:\Windows\System32\drivers\wmiacpi.sys - ok
17:22:42.0070 3820 [ DEA805815E587DAD1DD2C502220B5616 ] C:\Windows\System32\drivers\CmBatt.sys
17:22:42.0070 3820 C:\Windows\System32\drivers\CmBatt.sys - ok
17:22:42.0085 3820 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] C:\Windows\System32\drivers\mouclass.sys
17:22:42.0085 3820 C:\Windows\System32\drivers\mouclass.sys - ok
17:22:42.0085 3820 [ 02A9F366BCB94B286E34825B2094CB38 ] C:\Windows\System32\drivers\nvsmu.sys
17:22:42.0085 3820 C:\Windows\System32\drivers\nvsmu.sys - ok
17:22:42.0101 3820 [ F3ADCFB2F0BA791A26AC8E9C33D7E20E ] C:\Windows\System32\drivers\usbport.sys
17:22:42.0101 3820 C:\Windows\System32\drivers\usbport.sys - ok
17:22:42.0116 3820 [ 9036377B8A6C15DC2EEC53E489D159B5 ] C:\Windows\System32\drivers\hdaudbus.sys
17:22:42.0116 3820 C:\Windows\System32\drivers\hdaudbus.sys - ok
17:22:42.0116 3820 [ CFBCE999C057D78979A181C9C60F208E ] C:\Windows\System32\drivers\usbehci.sys
17:22:42.0116 3820 C:\Windows\System32\drivers\usbehci.sys - ok
17:22:42.0132 3820 [ A6FB7957EA7AFB1165991E54CE934B74 ] C:\Windows\System32\drivers\usbohci.sys
17:22:42.0132 3820 C:\Windows\System32\drivers\usbohci.sys - ok
17:22:42.0132 3820 [ 0219B05730635FCAB3A9925D3374C464 ] C:\Windows\System32\drivers\nvmf6232.sys
17:22:42.0132 3820 C:\Windows\System32\drivers\nvmf6232.sys - ok
17:22:42.0148 3820 [ 2FA5434344AF84D73F66BA402FF78690 ] C:\Windows\System32\drivers\nvlddmkm.sys
17:22:42.0148 3820 C:\Windows\System32\drivers\nvlddmkm.sys - ok
17:22:42.0163 3820 [ 5A1908A46DF8D6C88E441740E526B4B7 ] C:\Windows\System32\drivers\nvBridge.kmd
17:22:42.0163 3820 C:\Windows\System32\drivers\nvBridge.kmd - ok
17:22:42.0163 3820 [ 23F5D28378A160352BA8F817BD8C71CB ] C:\Windows\System32\drivers\dxgkrnl.sys
17:22:42.0163 3820 C:\Windows\System32\drivers\dxgkrnl.sys - ok
17:22:42.0179 3820 [ 1893ACD253854AC385042DB594FA23FF ] C:\Windows\System32\drivers\dxgmms1.sys
17:22:42.0179 3820 C:\Windows\System32\drivers\dxgmms1.sys - ok
17:22:42.0179 3820 [ 76BAB0C824E2D05B940C4DD40A9B08BF ] C:\Windows\System32\drivers\athr.sys
17:22:42.0179 3820 C:\Windows\System32\drivers\athr.sys - ok
17:22:42.0194 3820 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] C:\Windows\System32\drivers\vwifibus.sys
17:22:42.0194 3820 C:\Windows\System32\drivers\vwifibus.sys - ok
17:22:42.0194 3820 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] C:\Windows\System32\drivers\CompositeBus.sys
17:22:42.0194 3820 C:\Windows\System32\drivers\CompositeBus.sys - ok
17:22:42.0210 3820 [ 57EC4AEF73660166074D8F7F31C0D4FD ] C:\Windows\System32\drivers\agilevpn.sys
17:22:42.0210 3820 C:\Windows\System32\drivers\agilevpn.sys - ok
17:22:42.0210 3820 [ D9F91EAFEC2815365CBE6D167E4E332A ] C:\Windows\System32\drivers\rasl2tp.sys
17:22:42.0226 3820 C:\Windows\System32\drivers\rasl2tp.sys - ok
17:22:42.0226 3820 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] C:\Windows\System32\drivers\ndistapi.sys
17:22:42.0226 3820 C:\Windows\System32\drivers\ndistapi.sys - ok
17:22:42.0241 3820 [ 38FBE267E7E6983311179230FACB1017 ] C:\Windows\System32\drivers\ndiswan.sys
17:22:42.0241 3820 C:\Windows\System32\drivers\ndiswan.sys - ok
17:22:42.0241 3820 [ 0FE8B15916307A6AC12BFB6A63E45507 ] C:\Windows\System32\drivers\raspppoe.sys
17:22:42.0241 3820 C:\Windows\System32\drivers\raspppoe.sys - ok
17:22:42.0257 3820 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] C:\Windows\System32\drivers\raspptp.sys
17:22:42.0257 3820 C:\Windows\System32\drivers\raspptp.sys - ok
17:22:42.0257 3820 [ 44101F495A83EA6401D886E7FD70096B ] C:\Windows\System32\drivers\rassstp.sys
17:22:42.0257 3820 C:\Windows\System32\drivers\rassstp.sys - ok
17:22:42.0272 3820 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] C:\Windows\System32\drivers\rdpbus.sys
17:22:42.0272 3820 C:\Windows\System32\drivers\rdpbus.sys - ok
17:22:42.0288 3820 [ 5DCEF0C32BE0F33277326586FA503689 ] C:\Windows\System32\drivers\ks.sys
17:22:42.0288 3820 C:\Windows\System32\drivers\ks.sys - ok
17:22:42.0288 3820 [ E58C78A848ADD9610A4DB6D214AF5224 ] C:\Windows\System32\drivers\swenum.sys
17:22:42.0288 3820 C:\Windows\System32\drivers\swenum.sys - ok
17:22:42.0304 3820 [ D295BED4B898F0FD999FCFA9B32B071B ] C:\Windows\System32\drivers\umbus.sys
17:22:42.0304 3820 C:\Windows\System32\drivers\umbus.sys - ok
17:22:42.0304 3820 [ 9D22AAD9AC6A07C691A1113E5F860868 ] C:\Windows\System32\drivers\usbhub.sys
17:22:42.0304 3820 C:\Windows\System32\drivers\usbhub.sys - ok
17:22:42.0319 3820 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] C:\Windows\System32\drivers\ndproxy.sys
17:22:42.0319 3820 C:\Windows\System32\drivers\ndproxy.sys - ok
17:22:42.0335 3820 [ 27F9288AF019E6DACA281EDE51FF5928 ] C:\Windows\System32\drivers\drmk.sys
17:22:42.0335 3820 C:\Windows\System32\drivers\drmk.sys - ok
17:22:42.0335 3820 [ A5EF29D5315111C80A5C1ABAD14C8972 ] C:\Windows\System32\drivers\HdAudio.sys
17:22:42.0335 3820 C:\Windows\System32\drivers\HdAudio.sys - ok
17:22:42.0350 3820 [ D72708C9F49500C13D7D067E169B7715 ] C:\Windows\System32\drivers\portcls.sys
17:22:42.0350 3820 C:\Windows\System32\drivers\portcls.sys - ok
17:22:42.0350 3820 [ 4DF5C76302DC2F8F3465966C8426A292 ] C:\Windows\System32\drivers\HSXHWAZL.sys
17:22:42.0350 3820 C:\Windows\System32\drivers\HSXHWAZL.sys - ok
17:22:42.0366 3820 [ 227C3BA25012752BB7450235392C719F ] C:\Windows\System32\drivers\HSX_DPV.sys
17:22:42.0366 3820 C:\Windows\System32\drivers\HSX_DPV.sys - ok
17:22:42.0366 3820 [ 8B976D4CA270110111DF4F313DA0E6E8 ] C:\Windows\System32\drivers\HSX_CNXT.sys
17:22:42.0366 3820 C:\Windows\System32\drivers\HSX_CNXT.sys - ok
17:22:42.0382 3820 [ F001861E5700EE84E2D4E52C712F4964 ] C:\Windows\System32\drivers\modem.sys
17:22:42.0382 3820 C:\Windows\System32\drivers\modem.sys - ok
17:22:42.0397 3820 [ 77F9F9A199B87FE3F852E12F5419240B ] C:\Windows\System32\drivers\nvhda32v.sys
17:22:42.0397 3820 C:\Windows\System32\drivers\nvhda32v.sys - ok
17:22:42.0397 3820 [ F88A52EB62019D6A62FDD9E08034DBD8 ] C:\Windows\System32\autochk.exe
17:22:42.0397 3820 C:\Windows\System32\autochk.exe - ok
17:22:42.0413 3820 [ 544D486301588C8199187C9AB5778B4B ] C:\PROGRA~1\AVG\AVG2013\avgrsx.exe
17:22:42.0413 3820 C:\PROGRA~1\AVG\AVG2013\avgrsx.exe - ok
17:22:42.0413 3820 [ 484987420BC8DED2CB26C6F4EC9BA7F2 ] C:\Program Files\AVG\AVG2013\avgsysx.dll
17:22:42.0413 3820 C:\Program Files\AVG\AVG2013\avgsysx.dll - ok
17:22:42.0428 3820 [ 42836D10270B1940F9A2FF77AE679537 ] C:\Program Files\AVG\AVG2013\avgntopensslx.dll
17:22:42.0428 3820 C:\Program Files\AVG\AVG2013\avgntopensslx.dll - ok
17:22:42.0444 3820 [ 1C2E1FC9F8ED794CC191E92F27D1391C ] C:\Program Files\AVG\AVG2013\avglogx.dll
17:22:42.0444 3820 C:\Program Files\AVG\AVG2013\avglogx.dll - ok
17:22:42.0444 3820 [ 18E71EA0E063037A5C3C8272A5262B7C ] C:\Windows\System32\drivers\usbd.sys
17:22:42.0444 3820 C:\Windows\System32\drivers\usbd.sys - ok
17:22:42.0460 3820 [ 247B0A8164069CD4FE6F3094C581B13B ] C:\Windows\System32\drivers\RtsUStor.sys
17:22:42.0460 3820 C:\Windows\System32\drivers\RtsUStor.sys - ok
17:22:42.0460 3820 [ 0E297F71CBFAA611F830407D1054DC70 ] C:\PROGRA~1\AVG\AVG2013\avgchjwx.dll
17:22:42.0460 3820 C:\PROGRA~1\AVG\AVG2013\avgchjwx.dll - ok
17:22:42.0475 3820 [ 76FFA2433FEB42E78FB5421A50C8FBE3 ] C:\PROGRA~1\AVG\AVG2013\avgclitx.dll
17:22:42.0475 3820 C:\PROGRA~1\AVG\AVG2013\avgclitx.dll - ok
17:22:42.0475 3820 [ CCF775179F42797A3EE8BA5678543621 ] C:\PROGRA~1\AVG\AVG2013\avgcclix.dll
17:22:42.0475 3820 C:\PROGRA~1\AVG\AVG2013\avgcclix.dll - ok
17:22:42.0491 3820 [ 99997FA9056ACB38AA388BDA134CEF6E ] C:\Program Files\AVG\AVG2013\avgcsrvx.exe
17:22:42.0491 3820 C:\Program Files\AVG\AVG2013\avgcsrvx.exe - ok
17:22:42.0506 3820 [ 43B6BD4F2702A4704DCB02172E7B6C30 ] C:\Program Files\AVG\AVG2013\avgcorex.dll
17:22:42.0506 3820 C:\Program Files\AVG\AVG2013\avgcorex.dll - ok
17:22:42.0506 3820 [ 95EFDCB44DD093EDAD447F1D21C8A3F7 ] C:\Program Files\AVG\AVG2013\avgcertx.dll
17:22:42.0506 3820 C:\Program Files\AVG\AVG2013\avgcertx.dll - ok
17:22:42.0522 3820 [ 6F19639188F792BBB234B2A3FCB0C8C9 ] C:\Program Files\AVG\AVG2013\avgchclx.dll
17:22:42.0522 3820 C:\Program Files\AVG\AVG2013\avgchclx.dll - ok
17:22:42.0522 3820 [ A6251155B7017D4B4A77A3531A8DA6D8 ] C:\Program Files\AVG\AVG2013\avgcommx.dll
17:22:42.0522 3820 C:\Program Files\AVG\AVG2013\avgcommx.dll - ok
17:22:42.0538 3820 [ F820B93E4ABCCABD698A175FD5FC83FE ] C:\Program Files\AVG\AVG2013\avgntsqlitex.dll
17:22:42.0538 3820 C:\Program Files\AVG\AVG2013\avgntsqlitex.dll - ok
17:22:42.0553 3820 [ 028D74F61952756C9DFFF7969162BB39 ] C:\Windows\System32\oleaut32.dll
17:22:42.0553 3820 C:\Windows\System32\oleaut32.dll - ok
17:22:42.0553 3820 [ B2FD31E20B423335FE3273B4BF95813C ] C:\Windows\System32\imagehlp.dll
17:22:42.0553 3820 C:\Windows\System32\imagehlp.dll - ok
17:22:42.0569 3820 [ E46D48A7FE961401F1CBF85531CDF05D ] C:\Windows\System32\msvcrt.dll
17:22:42.0569 3820 C:\Windows\System32\msvcrt.dll - ok
17:22:42.0569 3820 [ 804AAAFEBB3AD5F49334DD906BCB1DE5 ] C:\Windows\System32\usp10.dll
17:22:42.0569 3820 C:\Windows\System32\usp10.dll - ok
17:22:42.0584 3820 [ E87F5393F7D8CE2FACC4DFF703531392 ] C:\Windows\System32\gdi32.dll
17:22:42.0584 3820 C:\Windows\System32\gdi32.dll - ok
17:22:42.0584 3820 [ 6377051C63D5552A311935C67E9FDFDC ] C:\Windows\System32\nsi.dll
17:22:42.0584 3820 C:\Windows\System32\nsi.dll - ok
17:22:42.0600 3820 [ 10FB16B50AFFDA6D44588F3C445DC273 ] C:\Windows\System32\setupapi.dll
17:22:42.0600 3820 C:\Windows\System32\setupapi.dll - ok
17:22:42.0616 3820 [ EBB431C6332107651CD2E2715A707994 ] C:\Windows\System32\urlmon.dll
17:22:42.0616 3820 C:\Windows\System32\urlmon.dll - ok
17:22:42.0616 3820 [ A8BB45F9ECAD993461E0FEF8E2A99152 ] C:\Windows\System32\Wldap32.dll
17:22:42.0616 3820 C:\Windows\System32\Wldap32.dll - ok
17:22:42.0631 3820 [ 070C5B9D3006602A07757179D9B56F5D ] C:\Windows\System32\difxapi.dll
17:22:42.0631 3820 C:\Windows\System32\difxapi.dll - ok
17:22:42.0631 3820 [ 44214C94911C7CFB1D52CB64D5E8368D ] C:\Windows\System32\wininet.dll
17:22:42.0631 3820 C:\Windows\System32\wininet.dll - ok
17:22:42.0647 3820 [ 6400774E903729ADD0A62A24A334EE56 ] C:\Windows\System32\rpcrt4.dll
17:22:42.0647 3820 C:\Windows\System32\rpcrt4.dll - ok
17:22:42.0662 3820 [ 16AB4BD2ACC52109F43739BF0E89E18F ] C:\Windows\System32\shell32.dll
17:22:42.0662 3820 C:\Windows\System32\shell32.dll - ok
17:22:42.0662 3820 [ D1DE1EAFDE97BE41CF6585027FF3E732 ] C:\Windows\System32\comdlg32.dll
17:22:42.0662 3820 C:\Windows\System32\comdlg32.dll - ok
17:22:42.0678 3820 [ C9618BC9B2B0FD7C1138D8774795A79B ] C:\Windows\System32\msctf.dll
17:22:42.0678 3820 C:\Windows\System32\msctf.dll - ok
17:22:42.0678 3820 [ A543AC1F7138376D778D630A35FCBC4C ] C:\Windows\System32\psapi.dll
17:22:42.0678 3820 C:\Windows\System32\psapi.dll - ok
17:22:42.0694 3820 [ F1DD3ACAEE5E6B4BBC69BC6DF75CEF66 ] C:\Windows\System32\user32.dll
17:22:42.0694 3820 C:\Windows\System32\user32.dll - ok
17:22:42.0709 3820 [ 4A8E2F20809CC161107FAA94F6CF2685 ] C:\Windows\System32\imm32.dll
17:22:42.0709 3820 C:\Windows\System32\imm32.dll - ok
17:22:42.0709 3820 [ 4F154D2C9C6DF951FD6E5AABBAE6B5EE ] C:\Windows\System32\lpk.dll
17:22:42.0725 3820 C:\Windows\System32\lpk.dll - ok
17:22:42.0740 3820 [ 9C278785347BCC991F8EA2999D90F58D ] C:\Windows\System32\normaliz.dll
17:22:42.0740 3820 C:\Windows\System32\normaliz.dll - ok
17:22:42.0740 3820 [ 928CF7268086631F54C3D8E17238C6DD ] C:\Windows\System32\ole32.dll
17:22:42.0740 3820 C:\Windows\System32\ole32.dll - ok
17:22:42.0756 3820 [ 95E2376B3323F062EB562B8586D0F14A ] C:\Windows\System32\advapi32.dll
17:22:42.0756 3820 C:\Windows\System32\advapi32.dll - ok
17:22:42.0756 3820 [ 683E0C9DA9E1EB9E4691DFAE0EC83E36 ] C:\Windows\System32\iertutil.dll
17:22:42.0756 3820 C:\Windows\System32\iertutil.dll - ok
17:22:42.0772 3820 [ 8CC3C111D653E96F3EA1590891491D71 ] C:\Windows\System32\shlwapi.dll
17:22:42.0772 3820 C:\Windows\System32\shlwapi.dll - ok
17:22:42.0787 3820 [ 7FF15A4F092CD4A96055BA69F903E3E9 ] C:\Windows\System32\ws2_32.dll
17:22:42.0787 3820 C:\Windows\System32\ws2_32.dll - ok
17:22:42.0787 3820 [ FF5688D309347F2720911D8796912834 ] C:\Windows\System32\clbcatq.dll
17:22:42.0787 3820 C:\Windows\System32\clbcatq.dll - ok
17:22:42.0803 3820 [ CC4ED8BEA78B0DCA6F217E014C3291A7 ] C:\Windows\System32\devobj.dll
17:22:42.0803 3820 C:\Windows\System32\devobj.dll - ok
17:22:42.0803 3820 [ 5553784D774CA845380650E010BBDA2C ] C:\Windows\System32\kernel32.dll
17:22:42.0803 3820 C:\Windows\System32\kernel32.dll - ok
17:22:42.0818 3820 [ CFC97F07904067A1E5FAE195D534DA3A ] C:\Windows\System32\sechost.dll
17:22:42.0818 3820 C:\Windows\System32\sechost.dll - ok
17:22:42.0834 3820 [ BDAC1AA64495D0F7E1FF810EBBF1F018 ] C:\Windows\System32\comctl32.dll
17:22:42.0834 3820 C:\Windows\System32\comctl32.dll - ok
17:22:42.0834 3820 [ 454E292861A4EF1D72F43F42BBAF6917 ] C:\Windows\System32\crypt32.dll
17:22:42.0834 3820 C:\Windows\System32\crypt32.dll - ok
17:22:42.0850 3820 [ AA7E805AF3F7DB2DA9EA350423E87DFD ] C:\Windows\System32\KernelBase.dll
17:22:42.0850 3820 C:\Windows\System32\KernelBase.dll - ok
17:22:42.0850 3820 [ 2D0D2DA87BEA7144F2A17F19D0D17E4C ] C:\Windows\System32\wintrust.dll
17:22:42.0850 3820 C:\Windows\System32\wintrust.dll - ok
17:22:42.0865 3820 [ 3FFAEA12666E565FF51BF2FCA674F543 ] C:\Windows\System32\cfgmgr32.dll
17:22:42.0865 3820 C:\Windows\System32\cfgmgr32.dll - ok
17:22:42.0896 3820 [ 938F39B50BAFE13D6F58C7790682C010 ] C:\Windows\System32\msasn1.dll
17:22:42.0896 3820 C:\Windows\System32\msasn1.dll - ok
17:22:42.0896 3820 [ 5FCD3320AAE71506B43F9E12E4E72172 ] C:\Windows\System32\drivers\dxapi.sys
17:22:42.0896 3820 C:\Windows\System32\drivers\dxapi.sys - ok
17:22:42.0912 3820 [ 687464342342B933D6B7FAA4A907AF4C ] C:\Windows\System32\win32k.sys
17:22:42.0912 3820 C:\Windows\System32\win32k.sys - ok
17:22:42.0928 3820 [ DAB748AE0439955ED2FA22357533DDDB ] C:\Windows\System32\basesrv.dll
17:22:42.0928 3820 C:\Windows\System32\basesrv.dll - ok
17:22:42.0943 3820 [ 10DE24CCCD418C31107813682EB73542 ] C:\Windows\System32\csrsrv.dll
17:22:42.0943 3820 C:\Windows\System32\csrsrv.dll - ok
17:22:42.0943 3820 [ 342271F6142E7C70805B8A81E1BA5F5C ] C:\Windows\System32\csrss.exe
17:22:42.0943 3820 C:\Windows\System32\csrss.exe - ok
17:22:42.0959 3820 [ A9F564F254E9DDDE120A7135767EC24B ] C:\Windows\System32\winsrv.dll
17:22:42.0959 3820 C:\Windows\System32\winsrv.dll - ok
17:22:42.0959 3820 [ 6C26122F1931D4D7810240F32DDCE890 ] C:\Windows\System32\drivers\hidparse.sys
17:22:42.0959 3820 C:\Windows\System32\drivers\hidparse.sys - ok
17:22:42.0974 3820 [ 931A1DF1520ABC6E84BA4A75E6957025 ] C:\Windows\System32\drivers\hidclass.sys
17:22:42.0974 3820 C:\Windows\System32\drivers\hidclass.sys - ok
17:22:42.0990 3820 [ 10C19F8290891AF023EAEC0832E1EB4D ] C:\Windows\System32\drivers\hidusb.sys
17:22:42.0990 3820 C:\Windows\System32\drivers\hidusb.sys - ok
17:22:42.0990 3820 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] C:\Windows\System32\drivers\mouhid.sys
17:22:42.0990 3820 C:\Windows\System32\drivers\mouhid.sys - ok
17:22:43.0006 3820 [ 79D10964DE86B292320E9DFE02282A23 ] C:\Windows\System32\drivers\monitor.sys
17:22:43.0006 3820 C:\Windows\System32\drivers\monitor.sys - ok
17:22:43.0006 3820 [ 7C76B61A5E1EF5D1FA554CF134100F18 ] C:\Windows\System32\tsddd.dll
17:22:43.0006 3820 C:\Windows\System32\tsddd.dll - ok
17:22:43.0021 3820 [ 364455805E64882844EE9ACB72522830 ] C:\Windows\System32\sxssrv.dll
17:22:43.0021 3820 C:\Windows\System32\sxssrv.dll - ok
17:22:43.0021 3820 [ B5C5DCAD3899512020D135600129D665 ] C:\Windows\System32\wininit.exe
17:22:43.0021 3820 C:\Windows\System32\wininit.exe - ok
17:22:43.0037 3820 [ C733D233B623B7FFCE5031E4B756EE26 ] C:\Windows\System32\profapi.dll
17:22:43.0037 3820 C:\Windows\System32\profapi.dll - ok
17:22:43.0037 3820 [ CAEF9CD6C10B1017E2C298D849CD31DB ] C:\Windows\System32\cdd.dll
17:22:43.0037 3820 C:\Windows\System32\cdd.dll - ok
17:22:43.0052 3820 [ 44496D13ECA356728E1CD71A5473DA4D ] C:\Windows\System32\KBDFR.DLL
17:22:43.0052 3820 C:\Windows\System32\KBDFR.DLL - ok
17:22:43.0068 3820 [ 5997D769CDB108390DCFAEBF442BF816 ] C:\Windows\System32\RpcRtRemote.dll
17:22:43.0068 3820 C:\Windows\System32\RpcRtRemote.dll - ok
17:22:43.0068 3820 [ 357B990A4249D7F7485B230C0CC8825A ] C:\Windows\System32\KBDUS.DLL
17:22:43.0068 3820 C:\Windows\System32\KBDUS.DLL - ok
17:22:43.0084 3820 [ 919001D2BB17DF06CA3F8AC16AD039F6 ] C:\Windows\System32\sxs.dll
17:22:43.0084 3820 C:\Windows\System32\sxs.dll - ok
17:22:43.0099 3820 [ 633C2C060CF857099F6C4F8D75C952B1 ] C:\Windows\System32\WlS0WndH.dll
17:22:43.0099 3820 C:\Windows\System32\WlS0WndH.dll - ok
17:22:43.0099 3820 [ F08F6FCD09F9BE94C37ACC1B344685FF ] C:\Windows\System32\cryptbase.dll
17:22:43.0099 3820 C:\Windows\System32\cryptbase.dll - ok
17:22:43.0115 3820 [ 863F793D15B4026B1A5FDECA873D4D84 ] C:\Windows\System32\apphelp.dll
17:22:43.0115 3820 C:\Windows\System32\apphelp.dll - ok
17:22:43.0115 3820 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6 ] C:\Windows\System32\services.exe
17:22:43.0115 3820 C:\Windows\System32\services.exe - ok
17:22:43.0130 3820 [ F42309C4191C506B71DB5D1126D26318 ] C:\Windows\System32\lsass.exe
17:22:43.0130 3820 C:\Windows\System32\lsass.exe - ok
17:22:43.0130 3820 [ 8AEA9A37C1A3565A204D37C5E72AB791 ] C:\Windows\System32\lsm.exe
17:22:43.0130 3820 C:\Windows\System32\lsm.exe - ok
17:22:43.0146 3820 [ 3369D021265E369D57317D61FA86DD79 ] C:\Windows\System32\scext.dll
17:22:43.0146 3820 C:\Windows\System32\scext.dll - ok
17:22:43.0162 3820 [ A8CE0C7F1D37E0B8082608A148B6B976 ] C:\Windows\System32\secur32.dll
17:22:43.0162 3820 C:\Windows\System32\secur32.dll - ok
17:22:43.0162 3820 [ 331534632D1DA3377440493848E4A70E ] C:\Windows\System32\sspicli.dll
17:22:43.0162 3820 C:\Windows\System32\sspicli.dll - ok
17:22:43.0177 3820 [ 4902ECF2A155A51F6FF7C013B7E212CD ] C:\Windows\System32\sspisrv.dll
17:22:43.0177 3820 C:\Windows\System32\sspisrv.dll - ok
17:22:43.0193 3820 [ BA51FFE170C5B3AE8EC4F5BD2581A29E ] C:\Windows\System32\sysntfy.dll
17:22:43.0193 3820 C:\Windows\System32\sysntfy.dll - ok
17:22:43.0193 3820 [ 1128637CAD49A8E3C8B5FA5D0A061525 ] C:\Windows\System32\cryptdll.dll
17:22:43.0193 3820 C:\Windows\System32\cryptdll.dll - ok
17:22:43.0208 3820 [ 7D388177BA300BE55264411DF6354D0D ] C:\Windows\System32\lsasrv.dll
17:22:43.0208 3820 C:\Windows\System32\lsasrv.dll - ok
17:22:43.0224 3820 [ 245F4691314F42D4D1BC06442F0B2086 ] C:\Windows\System32\samsrv.dll
17:22:43.0224 3820 C:\Windows\System32\samsrv.dll - ok
17:22:43.0224 3820 [ 250AA41DE690561AF1282D598914564C ] C:\Windows\System32\scesrv.dll
17:22:43.0224 3820 C:\Windows\System32\scesrv.dll - ok
17:22:43.0240 3820 [ 5CCDCD40E732D54E0F7451AC66AC1C87 ] C:\Windows\System32\srvcli.dll
17:22:43.0240 3820 C:\Windows\System32\srvcli.dll - ok
17:22:43.0255 3820 [ 82C089EA2A3EEFADF3588EA71E8BDADA ] C:\Windows\System32\wevtapi.dll
17:22:43.0255 3820 C:\Windows\System32\wevtapi.dll - ok
17:22:43.0255 3820 [ D412B1B72C5AB020218E9A047D90CA05 ] C:\Windows\System32\wmsgapi.dll
17:22:43.0255 3820 C:\Windows\System32\wmsgapi.dll - ok
17:22:43.0271 3820 [ FB4EB9352B7D698E6B3C2AA2ED724DAD ] C:\Windows\System32\authz.dll
17:22:43.0271 3820 C:\Windows\System32\authz.dll - ok
17:22:43.0286 3820 [ FC7650224790CAE75A5E9231961FDEC5 ] C:\Windows\System32\bcrypt.dll
17:22:43.0286 3820 C:\Windows\System32\bcrypt.dll - ok
17:22:43.0286 3820 [ 1180159EE45AD1B110F6E482F244899E ] C:\Windows\System32\bridgeres.dll
17:22:43.0286 3820 C:\Windows\System32\bridgeres.dll - ok
17:22:43.0302 3820 [ 50BA656134F78AF64E4DD3C8B6FEFD7E ] C:\Windows\System32\cngaudit.dll
17:22:43.0302 3820 C:\Windows\System32\cngaudit.dll - ok
17:22:43.0302 3820 [ C20FF1A17726C357461A7AC5B3BFC3AD ] C:\Windows\System32\ncrypt.dll
17:22:43.0302 3820 C:\Windows\System32\ncrypt.dll - ok
17:22:43.0318 3820 [ C90878913DF3DC504790282043DB5F4C ] C:\Windows\System32\msprivs.dll
17:22:43.0318 3820 C:\Windows\System32\msprivs.dll - ok
17:22:43.0333 3820 [ 6DCFAEC6D1334AA6CDF8961DB4633CBF ] C:\Windows\System32\negoexts.dll
17:22:43.0333 3820 C:\Windows\System32\negoexts.dll - ok
17:22:43.0333 3820 [ E343CABBD8D600ABAF3F11625D33B3D0 ] C:\Windows\System32\netjoin.dll
17:22:43.0333 3820 C:\Windows\System32\netjoin.dll - ok
17:22:43.0349 3820 [ 7321F18D1F820612ED0E9F2D4B578A7E ] C:\Windows\System32\cryptsp.dll
17:22:43.0349 3820 C:\Windows\System32\cryptsp.dll - ok
17:22:43.0364 3820 [ D9415DBA9FC6BAA8858FB0DD7D1176EB ] C:\Windows\System32\kerberos.dll
17:22:43.0364 3820 C:\Windows\System32\kerberos.dll - ok
17:22:43.0380 3820 [ 4C1E16B9A53102C8D6FBA587CBCB95DE ] C:\Windows\System32\msv1_0.dll
17:22:43.0380 3820 C:\Windows\System32\msv1_0.dll - ok
17:22:43.0380 3820 [ 8999B8631C7FD9F7F9EC3CAFD953BA24 ] C:\Windows\System32\mswsock.dll
17:22:43.0380 3820 C:\Windows\System32\mswsock.dll - ok
17:22:43.0396 3820 [ 73E8667A19FEEDD856DF2695E9E511D4 ] C:\Windows\System32\wship6.dll
17:22:43.0396 3820 C:\Windows\System32\wship6.dll - ok
17:22:43.0411 3820 [ 59DF156711A76BCB993253EC6C9BBF41 ] C:\Windows\System32\dnsapi.dll
17:22:43.0411 3820 C:\Windows\System32\dnsapi.dll - ok
17:22:43.0411 3820 [ 8EA53101FF2B15BDFF934B62A8FB326D ] C:\Windows\System32\logoncli.dll
17:22:43.0411 3820 C:\Windows\System32\logoncli.dll - ok
17:22:43.0427 3820 [ C1809B9907ADEDAF16F50C894100883B ] C:\Windows\System32\netlogon.dll
17:22:43.0427 3820 C:\Windows\System32\netlogon.dll - ok
17:22:43.0442 3820 [ 135F7AC9BE35AB1DF727FAF2E60E92F8 ] C:\Windows\System32\schannel.dll
17:22:43.0442 3820 C:\Windows\System32\schannel.dll - ok
17:22:43.0458 3820 [ 0450CF487ECD8A67B56F59F9A96D024D ] C:\Windows\System32\wdigest.dll
17:22:43.0458 3820 C:\Windows\System32\wdigest.dll - ok
17:22:43.0458 3820 [ ED8EC63F7522DF4852147C84EC62C36A ] C:\Windows\System32\rsaenh.dll
17:22:43.0458 3820 C:\Windows\System32\rsaenh.dll - ok
17:22:43.0474 3820 [ E8449FE262D7406BCB2AC2A45C53EC5F ] C:\Windows\System32\bcryptprimitives.dll
17:22:43.0474 3820 C:\Windows\System32\bcryptprimitives.dll - ok
17:22:43.0474 3820 [ FD1D6C73E6333BE727CBCC6054247654 ] C:\Windows\System32\drivers\TsUsbFlt.sys
17:22:43.0474 3820 C:\Windows\System32\drivers\TsUsbFlt.sys - ok
17:22:43.0489 3820 [ 37CC990D4E2CDFAE12AC47F6B620FC13 ] C:\Windows\System32\pku2u.dll
17:22:43.0489 3820 C:\Windows\System32\pku2u.dll - ok
17:22:43.0505 3820 [ D29E45078CF4020CE0AAC82EC652D1EA ] C:\Windows\System32\TSpkg.dll
17:22:43.0505 3820 C:\Windows\System32\TSpkg.dll - ok
17:22:43.0505 3820 [ 4E5FE39C1076D115EC8BFCFE14D75B80 ] C:\Windows\System32\credssp.dll
17:22:43.0505 3820 C:\Windows\System32\credssp.dll - ok
17:22:43.0520 3820 [ 91F434FF6606ED9BDC6A05D651B69553 ] C:\Windows\System32\efslsaext.dll
17:22:43.0520 3820 C:\Windows\System32\efslsaext.dll - ok
17:22:43.0536 3820 [ 8124944EC89D6A1815E4E53F5B96AAF4 ] C:\Windows\System32\scecli.dll
17:22:43.0536 3820 C:\Windows\System32\scecli.dll - ok
17:22:43.0536 3820 [ 7222995615BF93B628DCEA4BD6CCACF7 ] C:\Windows\System32\ubpm.dll
17:22:43.0536 3820 C:\Windows\System32\ubpm.dll - ok
17:22:43.0552 3820 [ 6D13E1406F50C66E2A95D97F22C47560 ] C:\Windows\System32\winlogon.exe
17:22:43.0552 3820 C:\Windows\System32\winlogon.exe - ok
17:22:43.0552 3820 [ 418E881201583A3039D81F43E39E6C78 ] C:\Windows\System32\winsta.dll
17:22:43.0552 3820 C:\Windows\System32\winsta.dll - ok
17:22:43.0567 3820 [ FD07F21E0A19C27ED4E1EEC2B07452B3 ] C:\Windows\System32\devrtl.dll
17:22:43.0567 3820 C:\Windows\System32\devrtl.dll - ok
17:22:43.0567 3820 [ 4BDBBE5E4208022DD794F7EEEB0F7366 ] C:\Windows\System32\SPInf.dll
17:22:43.0567 3820 C:\Windows\System32\SPInf.dll - ok
17:22:43.0583 3820 [ 54A47F6B5E09A77E61649109C6A08866 ] C:\Windows\System32\svchost.exe
17:22:43.0583 3820 C:\Windows\System32\svchost.exe - ok
17:22:43.0598 3820 [ 92DC6E68D2C856C5C2F21AE9E22112B8 ] C:\Windows\System32\umpnpmgr.dll
17:22:43.0598 3820 C:\Windows\System32\umpnpmgr.dll - ok
17:22:43.0598 3820 [ 1097F3035BAF46CED8B332B3564C5108 ] C:\Windows\System32\gpapi.dll
17:22:43.0598 3820 C:\Windows\System32\gpapi.dll - ok
17:22:43.0614 3820 [ D15618A0FF8DBC2C5BF3726BACC75A0B ] C:\Windows\System32\userenv.dll
17:22:43.0614 3820 C:\Windows\System32\userenv.dll - ok
17:22:43.0630 3820 [ 5893EBDCE371174AC89ECD7731DD6D77 ] C:\Windows\System32\pcwum.dll
17:22:43.0630 3820 C:\Windows\System32\pcwum.dll - ok
17:22:43.0630 3820 [ F87D30E72E03D579A5199CCB3831D6EA ] C:\Windows\System32\umpo.dll
17:22:43.0630 3820 C:\Windows\System32\umpo.dll - ok
17:22:43.0645 3820 [ 08DFDBD2FD4EA951DC46B1C7661ED35A ] C:\Windows\System32\powrprof.dll
17:22:43.0645 3820 C:\Windows\System32\powrprof.dll - ok
17:22:43.0661 3820 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] C:\Windows\System32\drivers\luafv.sys
17:22:43.0661 3820 C:\Windows\System32\drivers\luafv.sys - ok
17:22:43.0661 3820 [ 629CABB0421668C9D3D402A3C3D77E14 ] C:\Windows\System32\drivers\mbam.sys
17:22:43.0661 3820 C:\Windows\System32\drivers\mbam.sys - ok
17:22:43.0676 3820 [ E714A1C0354636837E20CCBF00888EE7 ] C:\Windows\System32\drivers\WUDFPf.sys
17:22:43.0676 3820 C:\Windows\System32\drivers\WUDFPf.sys - ok
17:22:43.0692 3820 [ B785320CBCF5021DE9945C803696C511 ] C:\Windows\System32\nvvsvc.exe
17:22:43.0692 3820 C:\Windows\System32\nvvsvc.exe - ok
17:22:43.0692 3820 [ 6A6B2EE4565A178035BE2A4FF6F2C968 ] C:\Windows\System32\wtsapi32.dll
17:22:43.0692 3820 C:\Windows\System32\wtsapi32.dll - ok
17:22:43.0708 3820 [ 7660F01D3B38ACA1747E397D21D790AF ] C:\Windows\System32\rpcss.dll
17:22:43.0708 3820 C:\Windows\System32\rpcss.dll - ok
17:22:43.0723 3820 [ 78D072F35BC45D9E4E1B61895C152234 ] C:\Windows\System32\RpcEpMap.dll
17:22:43.0723 3820 C:\Windows\System32\RpcEpMap.dll - ok
17:22:43.0723 3820 [ EE5C8E27C37B79CB54A2FCEEED2DC262 ] C:\Windows\System32\WSHTCPIP.DLL
17:22:43.0723 3820 C:\Windows\System32\WSHTCPIP.DLL - ok
17:22:43.0739 3820 [ 81F08948A0F1475894C99D4D19A158A8 ] C:\Windows\System32\wshqos.dll
17:22:43.0739 3820 C:\Windows\System32\wshqos.dll - ok
17:22:43.0754 3820 [ 3F50200237961034FACE602373838980 ] C:\Windows\System32\FirewallAPI.dll
17:22:43.0754 3820 C:\Windows\System32\FirewallAPI.dll - ok
17:22:43.0754 3820 [ 702254574E7E52052DE39408457B7149 ] C:\Windows\System32\version.dll
17:22:43.0754 3820 C:\Windows\System32\version.dll - ok
17:22:43.0770 3820 [ 3EF0D8AB08385AAB5802E773511A2E6A ] C:\Windows\System32\LogonUI.exe
17:22:43.0770 3820 C:\Windows\System32\LogonUI.exe - ok
17:22:43.0786 3820 [ 241E015DD809CFB23242F890B1FC575B ] C:\Windows\System32\wevtsvc.dll
17:22:43.0786 3820 C:\Windows\System32\wevtsvc.dll - ok
17:22:43.0786 3820 [ CDD35C1CE1EBFE80C055691CDC8DF443 ] C:\Windows\System32\authui.dll
17:22:43.0786 3820 C:\Windows\System32\authui.dll - ok
17:22:43.0801 3820 [ 28CA821606669BB9215CE010767720FA ] C:\Windows\System32\cryptui.dll
17:22:43.0801 3820 C:\Windows\System32\cryptui.dll - ok
17:22:43.0817 3820 [ 352B3DC62A0D259A82A052238425C872 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
17:22:43.0817 3820 C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll - ok
17:22:43.0817 3820 [ F14A9B1778376D0B1788E402AC1F831A ] C:\Windows\System32\shacct.dll
17:22:43.0817 3820 C:\Windows\System32\shacct.dll - ok
17:22:43.0832 3820 [ 12C45E3CB6D65F73209549E2D02ECA7A ] C:\Windows\System32\propsys.dll
17:22:43.0832 3820 C:\Windows\System32\propsys.dll - ok
17:22:43.0832 3820 [ C30A3E5DEEEBA22E782AC54C5AF5F352 ] C:\Windows\System32\samlib.dll
17:22:43.0832 3820 C:\Windows\System32\samlib.dll - ok
17:22:43.0848 3820 [ 63BFDF555DA2075A77D677829C3CCCD0 ] C:\Windows\System32\uxtheme.dll
17:22:43.0848 3820 C:\Windows\System32\uxtheme.dll - ok
17:22:43.0864 3820 [ 16935C98FF639D185086A3529B1F2067 ] C:\Windows\System32\wlansvc.dll
17:22:43.0864 3820 C:\Windows\System32\wlansvc.dll - ok
17:22:43.0864 3820 [ 0029EBA325F2FC9B6BA46BEE33F32A09 ] C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll
17:22:43.0864 3820 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.17514_none_72d18a4386696c80\GdiPlus.dll - ok
17:22:43.0879 3820 [ AC8C80DC4F1A6E60C9A762C1799F0B39 ] C:\Windows\System32\adtschema.dll
17:22:43.0879 3820 C:\Windows\System32\adtschema.dll - ok
17:22:43.0895 3820 [ EE06B85BC69F18826302348A2AD089E0 ] C:\Windows\System32\dui70.dll
17:22:43.0895 3820 C:\Windows\System32\dui70.dll - ok
17:22:43.0895 3820 [ 6E1F8165C365D35C8E3C045AF0CDD481 ] C:\Windows\System32\duser.dll
17:22:43.0895 3820 C:\Windows\System32\duser.dll - ok
17:22:43.0910 3820 [ 63DF770DF74ACB370EF5A16727069AAF ] C:\Windows\System32\hid.dll
17:22:43.0910 3820 C:\Windows\System32\hid.dll - ok
17:22:43.0926 3820 [ 2CFA4569350B7F84F815E9EC34E85766 ] C:\Windows\System32\SndVolSSO.dll
17:22:43.0926 3820 C:\Windows\System32\SndVolSSO.dll - ok
17:22:43.0942 3820 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] C:\Windows\System32\audiosrv.dll
17:22:43.0942 3820 C:\Windows\System32\audiosrv.dll - ok
17:22:43.0942 3820 [ 39C5F32747B3414D1BB216FDB1DEFC58 ] C:\Windows\System32\dwmapi.dll
17:22:43.0942 3820 C:\Windows\System32\dwmapi.dll - ok
17:22:43.0957 3820 [ 243974EC02F7AE49E4179C54624143AB ] C:\Windows\System32\MMDevAPI.dll
17:22:43.0957 3820 C:\Windows\System32\MMDevAPI.dll - ok
17:22:43.0973 3820 [ 7BF5EA753D4CC056B9462A02AC51B160 ] C:\Windows\System32\xmllite.dll
17:22:43.0973 3820 C:\Windows\System32\xmllite.dll - ok
17:22:43.0973 3820 [ 139D3AB6AA920C34C50CBFFB9EB7D222 ] C:\Windows\System32\avrt.dll
17:22:43.0973 3820 C:\Windows\System32\avrt.dll - ok
17:22:43.0988 3820 [ 146B6F43A673379A3C670E86D89BE5EA ] C:\Windows\System32\mmcss.dll
17:22:43.0988 3820 C:\Windows\System32\mmcss.dll - ok
17:22:44.0004 3820 [ 1DB71A41DAEE6B3F8CD0DDA8209FA2D5 ] C:\Windows\System32\WindowsCodecs.dll
17:22:44.0004 3820 C:\Windows\System32\WindowsCodecs.dll - ok
17:22:44.0004 3820 [ 8B0B4C5927A333A05513791758350DC4 ] C:\Windows\System32\microsoft-windows-kernel-power-events.dll
17:22:44.0004 3820 C:\Windows\System32\microsoft-windows-kernel-power-events.dll - ok
17:22:44.0020 3820 [ 7520EC808E0C35E0EE6F841294316653 ] C:\Windows\System32\drivers\fltMgr.sys
17:22:44.0020 3820 C:\Windows\System32\drivers\fltMgr.sys - ok
17:22:44.0035 3820 [ D93A937A2A9D2CBC06B3A615A197011F ] C:\Windows\System32\PSHED.DLL
17:22:44.0035 3820 C:\Windows\System32\PSHED.DLL - ok
17:22:44.0035 3820 [ 8C338238C16777A802D6A9211EB2BA50 ] C:\Windows\System32\netprofm.dll
17:22:44.0035 3820 C:\Windows\System32\netprofm.dll - ok
17:22:44.0051 3820 [ 326C7F76A29897A892AA7726E91C1C67 ] C:\Windows\System32\winbrand.dll
17:22:44.0051 3820 C:\Windows\System32\winbrand.dll - ok
17:22:44.0066 3820 [ 1F5497D7D3D79C7BF0AB0C8B4C5BFE6E ] C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll
17:22:44.0066 3820 C:\Windows\System32\microsoft-windows-kernel-processor-power-events.dll - ok
17:22:44.0066 3820 [ 05BF975CA428E04B462FB90841B37C95 ] C:\Windows\System32\SmartcardCredentialProvider.dll
17:22:44.0066 3820 C:\Windows\System32\SmartcardCredentialProvider.dll - ok
17:22:44.0082 3820 [ 65BF13016A3C22775F3E17591AE5268A ] C:\Windows\System32\VaultCredProvider.dll
17:22:44.0082 3820 C:\Windows\System32\VaultCredProvider.dll - ok
17:22:44.0082 3820 [ E59F08ED9D2A128CE436BBFC232247F6 ] C:\Windows\System32\BioCredProv.dll
17:22:44.0082 3820 C:\Windows\System32\BioCredProv.dll - ok
17:22:44.0098 3820 [ 3FAD263CE1E2A6FFF40D00043B2275E3 ] C:\Windows\System32\winbio.dll
17:22:44.0098 3820 C:\Windows\System32\winbio.dll - ok
17:22:44.0098 3820 [ 108C2CFA5527458C096A699929ECBD80 ] C:\Windows\System32\credui.dll
17:22:44.0098 3820 C:\Windows\System32\credui.dll - ok
17:22:44.0113 3820 [ 9835584E999D25004E1EE8E5F3E3B881 ] C:\Windows\System32\MPSSVC.dll
17:22:44.0113 3820 C:\Windows\System32\MPSSVC.dll - ok
17:22:44.0113 3820 [ 8CE1A6D16B9077E91E192499EB611C5F ] C:\Windows\System32\netapi32.dll
17:22:44.0113 3820 C:\Windows\System32\netapi32.dll - ok
17:22:44.0129 3820 [ 20B3934DB73EABA2B49B7177873CB81F ] C:\Windows\System32\netutils.dll
17:22:44.0129 3820 C:\Windows\System32\netutils.dll - ok
17:22:44.0144 3820 [ 68ECCA523ED760AAFC03C5D587569859 ] C:\Windows\System32\samcli.dll
17:22:44.0144 3820 C:\Windows\System32\samcli.dll - ok
17:22:44.0144 3820 [ 36B8D5903CEEF0AA42A1EE002BD27FF1 ] C:\Windows\System32\vaultcli.dll
17:22:44.0144 3820 C:\Windows\System32\vaultcli.dll - ok
17:22:44.0160 3820 [ E5A4A1326A02F8E7B59E6C3270CE7202 ] C:\Windows\System32\wkscli.dll
17:22:44.0160 3820 C:\Windows\System32\wkscli.dll - ok
17:22:44.0160 3820 [ 6D8CACF3B1B54943EFCF420C2D667B37 ] C:\Windows\System32\certCredProvider.dll
17:22:44.0160 3820 C:\Windows\System32\certCredProvider.dll - ok
17:22:44.0176 3820 [ FFE4BEC5C187C426A17AE76A773063A6 ] C:\Windows\System32\rasplap.dll
17:22:44.0176 3820 C:\Windows\System32\rasplap.dll - ok
17:22:44.0191 3820 [ 839F96DBAAFD3353E0B248A5E0BD2A51 ] C:\Windows\System32\rasapi32.dll
17:22:44.0191 3820 C:\Windows\System32\rasapi32.dll - ok
17:22:44.0191 3820 [ FFA7172354B9256DBB2CDD75F16F33FE ] C:\Windows\System32\rasman.dll
17:22:44.0191 3820 C:\Windows\System32\rasman.dll - ok
17:22:44.0207 3820 [ 0915C4DB6DBC3BB9E11B7ECBBE4B7159 ] C:\Windows\System32\rtutils.dll
17:22:44.0207 3820 C:\Windows\System32\rtutils.dll - ok
17:22:44.0207 3820 [ F68194F74350D4A2ADE98961E33F884C ] C:\Windows\System32\audiodg.exe
17:22:44.0207 3820 C:\Windows\System32\audiodg.exe - ok
17:22:44.0222 3820 [ CBD010BFBED9657C3813400AAD03CF8A ] C:\Windows\System32\oleacc.dll
17:22:44.0222 3820 C:\Windows\System32\oleacc.dll - ok
17:22:44.0238 3820 [ FD049C25A168D3DE310D9207B7B6367B ] C:\Windows\System32\UIAutomationCore.dll
17:22:44.0238 3820 C:\Windows\System32\UIAutomationCore.dll - ok
17:22:44.0238 3820 [ 18AB2E5A40064ED5F7791AC5946A90F3 ] C:\Windows\System32\msimg32.dll
17:22:44.0238 3820 C:\Windows\System32\msimg32.dll - ok
17:22:44.0254 3820 [ 3FD15B4611D9BDA3F8013548C0ECAECA ] C:\Windows\System32\ntmarta.dll
17:22:44.0254 3820 C:\Windows\System32\ntmarta.dll - ok
17:22:44.0269 3820 [ 15F93B37F6801943360D9EB42485D5D3 ] C:\Windows\System32\cscsvc.dll
17:22:44.0269 3820 C:\Windows\System32\cscsvc.dll - ok
17:22:44.0269 3820 [ E897EAF5ED6BA41E081060C9B447A673 ] C:\Windows\System32\gpsvc.dll
17:22:44.0269 3820 C:\Windows\System32\gpsvc.dll - ok
17:22:44.0285 3820 [ D205C24A9D069049FE2DF2A1B38726A7 ] C:\Windows\System32\wdmaud.drv
17:22:44.0285 3820 C:\Windows\System32\wdmaud.drv - ok
17:22:44.0285 3820 [ D5AEFAD57C08349A4393D987DF7C715D ] C:\Windows\System32\winmm.dll
17:22:44.0285 3820 C:\Windows\System32\winmm.dll - ok
17:22:44.0300 3820 [ 9C67F6BBDA3881CFD02095160CF91576 ] C:\Windows\System32\ksuser.dll
17:22:44.0300 3820 C:\Windows\System32\ksuser.dll - ok
17:22:44.0300 3820 [ 104A1070E90F1C530328E69B49718841 ] C:\Windows\System32\nlaapi.dll
17:22:44.0300 3820 C:\Windows\System32\nlaapi.dll - ok
17:22:44.0316 3820 [ 772F44012DBE49DE894976AE2259A659 ] C:\Windows\System32\PeerDist.dll
17:22:44.0316 3820 C:\Windows\System32\PeerDist.dll - ok
17:22:44.0332 3820 [ 43CA4CCC22D52FB58E8988F0198851D0 ] C:\Windows\System32\profsvc.dll
17:22:44.0332 3820 C:\Windows\System32\profsvc.dll - ok
17:22:44.0332 3820 [ F10E5311E5093FA3C00FF88C54C32FCA ] C:\Windows\System32\atl.dll
17:22:44.0332 3820 C:\Windows\System32\atl.dll - ok
17:22:44.0347 3820 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] C:\Windows\System32\themeservice.dll
17:22:44.0347 3820 C:\Windows\System32\themeservice.dll - ok
17:22:44.0363 3820 [ 2F040CF0613A6D64DCBBA9EE81F5A5AE ] C:\Windows\System32\dsrole.dll
17:22:44.0363 3820 C:\Windows\System32\dsrole.dll - ok
17:22:44.0378 3820 [ 8B74CEC6980D4816B0037AE9A27E538F ] C:\Windows\System32\slc.dll
17:22:44.0378 3820 C:\Windows\System32\slc.dll - ok
17:22:44.0378 3820 [ 544EFF88AC6C85DF5A4D6F18DFE08CFC ] C:\Windows\System32\taskschd.dll
17:22:44.0378 3820 C:\Windows\System32\taskschd.dll - ok
17:22:44.0394 3820 [ C5A99A4C0DC9F0F5A95BA0C83D30A549 ] C:\Windows\System32\mstask.dll
17:22:44.0394 3820 C:\Windows\System32\mstask.dll - ok
17:22:44.0410 3820 [ C940F2F5C60B3727C5F18840735B229C ] C:\Windows\System32\AudioSes.dll
17:22:44.0410 3820 C:\Windows\System32\AudioSes.dll - ok
17:22:44.0410 3820 [ F6916EFC29D9953D5D0DF06882AE8E16 ] C:\Windows\System32\es.dll
17:22:44.0410 3820 C:\Windows\System32\es.dll - ok
17:22:44.0425 3820 [ 5A12C364AD1D4FCC0AD0E56DBBC34462 ] C:\Windows\System32\midimap.dll
17:22:44.0425 3820 C:\Windows\System32\midimap.dll - ok
17:22:44.0425 3820 [ 85683DF1F917E4D7F6BE1A04986BF1C8 ] C:\Windows\System32\msacm32.dll
17:22:44.0425 3820 C:\Windows\System32\msacm32.dll - ok
17:22:44.0441 3820 [ 07393A09C46083588E751B63B03C8301 ] C:\Windows\System32\msacm32.drv
17:22:44.0441 3820 C:\Windows\System32\msacm32.drv - ok
17:22:44.0456 3820 [ 808D8A8B2A3074002852BC856D419576 ] C:\Windows\System32\comres.dll
17:22:44.0456 3820 C:\Windows\System32\comres.dll - ok
17:22:44.0456 3820 [ DCB7FCDCC97F87360F75D77425B81737 ] C:\Windows\System32\Sens.dll
17:22:44.0456 3820 C:\Windows\System32\Sens.dll - ok
17:22:44.0472 3820 [ 081E6E1C91AEC36758902A9F727CD23C ] C:\Windows\System32\uxsms.dll
17:22:44.0472 3820 C:\Windows\System32\uxsms.dll - ok
17:22:44.0472 3820 [ 9FBCFD7E88A7ACE0E94456504895DD7F ] C:\Windows\System32\WUDFPlatform.dll
17:22:44.0472 3820 C:\Windows\System32\WUDFPlatform.dll - ok
17:22:44.0488 3820 [ 8D1E1E529A2C9E9B6A85B55A345F7629 ] C:\Windows\System32\WUDFSvc.dll
17:22:44.0488 3820 C:\Windows\System32\WUDFSvc.dll - ok
17:22:44.0503 3820 [ BBA9D5A730D5E304117AD26923EBD8AA ] C:\Windows\System32\AudioEng.dll
17:22:44.0503 3820 C:\Windows\System32\AudioEng.dll - ok
17:22:44.0503 3820 [ 96F0F8F4DEE598C8D12AD9633E0CFE2A ] C:\Windows\System32\AUDIOKSE.dll
17:22:44.0503 3820 C:\Windows\System32\AUDIOKSE.dll - ok
17:22:44.0519 3820 [ A12829E9974F57E9B5DBFEA7C93190F6 ] C:\Windows\System32\UXInit.dll
17:22:44.0519 3820 C:\Windows\System32\UXInit.dll - ok
17:22:44.0519 3820 [ 40B82688907A7DBA4DB3B5ADDE3EAB3B ] C:\Windows\System32\mfplat.dll
17:22:44.0519 3820 C:\Windows\System32\mfplat.dll - ok
17:22:44.0534 3820 [ 4E30ED3E551E867ADD1C8D58F5EDD9DF ] C:\Windows\System32\WMALFXGFXDSP.dll
17:22:44.0534 3820 C:\Windows\System32\WMALFXGFXDSP.dll - ok
17:22:44.0550 3820 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] C:\Windows\System32\drivers\lltdio.sys
17:22:44.0550 3820 C:\Windows\System32\drivers\lltdio.sys - ok
17:22:44.0550 3820 [ 26384429FCD85D83746F63E798AB1480 ] C:\Windows\System32\drivers\nwifi.sys
17:22:44.0550 3820 C:\Windows\System32\drivers\nwifi.sys - ok
17:22:44.0566 3820 [ D8A65DAFB3EB41CBB622745676FCD072 ] C:\Windows\System32\drivers\ndisuio.sys
17:22:44.0566 3820 C:\Windows\System32\drivers\ndisuio.sys - ok
17:22:44.0581 3820 [ 032B0D36AD92B582D869879F5AF5B928 ] C:\Windows\System32\drivers\rspndr.sys
17:22:44.0581 3820 C:\Windows\System32\drivers\rspndr.sys - ok
17:22:44.0581 3820 [ 55CA01BA19D0006C8F2639B6C045E08B ] C:\Windows\System32\lmhsvc.dll
17:22:44.0581 3820 C:\Windows\System32\lmhsvc.dll - ok
17:22:44.0597 3820 [ A90DC9ABD65DB1A8902F361103029952 ] C:\Windows\System32\IPHLPAPI.DLL
17:22:44.0597 3820 C:\Windows\System32\IPHLPAPI.DLL - ok
17:22:44.0612 3820 [ BA387E955E890C8A88306D9B8D06BF17 ] C:\Windows\System32\nsisvc.dll
17:22:44.0612 3820 C:\Windows\System32\nsisvc.dll - ok
17:22:44.0628 3820 [ CFF35B879D1618D42C86644C717BA947 ] C:\Windows\System32\winnsi.dll
17:22:44.0628 3820 C:\Windows\System32\winnsi.dll - ok
17:22:44.0628 3820 [ D2A937964199F647B1C3BC435712E5D9 ] C:\Windows\System32\nrpsrv.dll
17:22:44.0628 3820 C:\Windows\System32\nrpsrv.dll - ok
17:22:44.0644 3820 [ E9E01EB683C132F7FA27CD607B8A2B63 ] C:\Windows\System32\dhcpcore.dll
17:22:44.0644 3820 C:\Windows\System32\dhcpcore.dll - ok
17:22:44.0659 3820 [ 990A58A0B01720E419B55EFC5FF387F8 ] C:\Windows\System32\dhcpcore6.dll
17:22:44.0659 3820 C:\Windows\System32\dhcpcore6.dll - ok
17:22:44.0659 3820 [ D70C62728D1D83BB756ADC6142826A08 ] C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll
17:22:44.0659 3820 C:\Program Files\NVIDIA Corporation\Display\nvxdbat.dll - ok
17:22:44.0675 3820 [ 2FE30D71919C51131405797620E0A714 ] C:\Windows\System32\dnsrslvr.dll
17:22:44.0675 3820 C:\Windows\System32\dnsrslvr.dll - ok
17:22:44.0675 3820 [ AF75DBA674E55221B7A055B0A4345F16 ] C:\Windows\System32\keyiso.dll
17:22:44.0675 3820 C:\Windows\System32\keyiso.dll - ok
17:22:44.0690 3820 [ 8600142FA91C1B96367D3300AD0F3F3A ] C:\Windows\System32\eapsvc.dll
17:22:44.0690 3820 C:\Windows\System32\eapsvc.dll - ok
17:22:44.0706 3820 [ D8B5EACD4AF25E92FF9CE3C4980C0D73 ] C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
17:22:44.0706 3820 C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe - ok
17:22:44.0706 3820 [ 03A03A453F1AAAE0C73AAAF895321C7A ] C:\Windows\System32\FWPUCLNT.DLL
17:22:44.0706 3820 C:\Windows\System32\FWPUCLNT.DLL - ok
17:22:44.0722 3820 [ 9A892B3439884C62B04718F0303A49E9 ] C:\Windows\System32\eapphost.dll
17:22:44.0722 3820 C:\Windows\System32\eapphost.dll - ok
17:22:44.0737 3820 [ 7B4CC023D64C2CC7942A26860A6791FC ] C:\Windows\System32\nvsvc.dll
17:22:44.0737 3820 C:\Windows\System32\nvsvc.dll - ok
17:22:44.0737 3820 [ 100103C6535C66265267F5EEA5F5846E ] C:\Windows\System32\dnsext.dll
17:22:44.0737 3820 C:\Windows\System32\dnsext.dll - ok
17:22:44.0753 3820 [ 7F8678C59F188528D60104E697C2361E ] C:\Windows\System32\mscms.dll
17:22:44.0753 3820 C:\Windows\System32\mscms.dll - ok
17:22:44.0768 3820 [ 388F19F237C069F9072C9340DADE7EEB ] C:\Windows\System32\nvapi.dll
17:22:44.0768 3820 C:\Windows\System32\nvapi.dll - ok
17:22:44.0768 3820 [ B29ED37ADC88D961211D88F6B4B6BCD2 ] C:\Windows\System32\nvsvcr.dll
17:22:44.0768 3820 C:\Windows\System32\nvsvcr.dll - ok
17:22:44.0784 3820 [ 9A85ABCE0FDD1AF8E79E731EB0B679F3 ] C:\Windows\System32\dhcpcsvc.dll
17:22:44.0784 3820 C:\Windows\System32\dhcpcsvc.dll - ok
17:22:44.0800 3820 [ 20D11690EA35B4BD3D2364F61E0DADBA ] C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll
17:22:44.0800 3820 C:\Program Files\NVIDIA Corporation\Display\nvxdapix.dll - ok
17:22:44.0800 3820 [ 29CA5974FAB0E8AE4AA7814FE05CF832 ] C:\Windows\System32\dhcpcsvc6.dll
17:22:44.0800 3820 C:\Windows\System32\dhcpcsvc6.dll - ok
17:22:44.0815 3820 [ D33E95C0A2754061233B58DC41F8094C ] C:\Windows\System32\umb.dll
17:22:44.0815 3820 C:\Windows\System32\umb.dll - ok
17:22:44.0831 3820 [ 6853FF54B5E3C1DFCE6F86EBC380CA70 ] C:\Program Files\NVIDIA Corporation\Display\nvui.dll
17:22:44.0831 3820 C:\Program Files\NVIDIA Corporation\Display\nvui.dll - ok
17:22:44.0831 3820 [ 3C9035085141162416A0DD34DBF3F3C1 ] C:\Windows\System32\wlanmsm.dll
17:22:44.0831 3820 C:\Windows\System32\wlanmsm.dll - ok
17:22:44.0846 3820 [ 20C06A50DFC097E134BC6FA8444CA9BC ] C:\Windows\System32\wlansec.dll
17:22:44.0846 3820 C:\Windows\System32\wlansec.dll - ok
17:22:44.0846 3820 [ 827CB0D6C3F8057EA037FF271F8E9795 ] C:\Windows\System32\imageres.dll
17:22:44.0846 3820 C:\Windows\System32\imageres.dll - ok
17:22:44.0862 3820 [ F748F53FE09D21D8ECBB6421E6792024 ] C:\Windows\System32\onex.dll
17:22:44.0862 3820 C:\Windows\System32\onex.dll - ok
17:22:44.0878 3820 [ BDAC1AA64495D0F7E1FF810EBBF1F018 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
17:22:44.0878 3820 C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll - ok
17:22:44.0893 3820 [ 666E57B6B51824D1D235F80A3DD70A13 ] C:\Windows\System32\eappprxy.dll
17:22:44.0893 3820 C:\Windows\System32\eappprxy.dll - ok
17:22:44.0893 3820 [ 5A5FEDDF02588B8F9FE4A95E5E7EAE97 ] C:\Windows\System32\eappcfg.dll
17:22:44.0893 3820 C:\Windows\System32\eappcfg.dll - ok
17:22:44.0909 3820 [ 9E4B0E7472B4CEBA9E17F440B8CB0AB8 ] C:\Windows\System32\winspool.drv
17:22:44.0909 3820 C:\Windows\System32\winspool.drv - ok
17:22:44.0909 3820 [ 749F9795F01C35EEBE100A87D82B9681 ] C:\Windows\System32\wlgpclnt.dll
17:22:44.0909 3820 C:\Windows\System32\wlgpclnt.dll - ok
17:22:44.0924 3820 [ C1585EAA67C37A05BF6F93726FAFC069 ] C:\Windows\System32\l2gpstore.dll
17:22:44.0924 3820 C:\Windows\System32\l2gpstore.dll - ok
17:22:44.0940 3820 [ 1D6A771D1D702AE07919DB52C889A249 ] C:\Windows\System32\wlanutil.dll
17:22:44.0940 3820 C:\Windows\System32\wlanutil.dll - ok
17:22:44.0940 3820 [ 9419ABF3163B6F0E3AD3DD2B381C879F ] C:\Windows\System32\WinSCard.dll
17:22:44.0940 3820 C:\Windows\System32\WinSCard.dll - ok
17:22:44.0956 3820 [ 269D867585CDA04D3972A39F3694E7DF ] C:\Windows\System32\msxml6.dll
17:22:44.0956 3820 C:\Windows\System32\msxml6.dll - ok
17:22:44.0956 3820 [ 4FE4AF2A03F90E8FDB21FCA87CDDCE64 ] C:\Program Files\NVIDIA Corporation\Display\nvuir.dll
17:22:44.0956 3820 C:\Program Files\NVIDIA Corporation\Display\nvuir.dll - ok
17:22:44.0971 3820 [ E1433E4C5F3CA83E210995CBB030B0ED ] C:\Windows\System32\nvcpl.dll
17:22:44.0971 3820 C:\Windows\System32\nvcpl.dll - ok
17:22:44.0987 3820 [ 414DA952A35BF5D50192E28263B40577 ] C:\Windows\System32\shsvcs.dll
17:22:44.0987 3820 C:\Windows\System32\shsvcs.dll - ok
17:22:44.0987 3820 [ 17CF854B917F151AFE10E10CD89AEDF5 ] C:\Program Files\NVIDIA Corporation\Display\nvxdplcy.dll
17:22:44.0987 3820 C:\Program Files\NVIDIA Corporation\Display\nvxdplcy.dll - ok
17:22:45.0002 3820 [ A04BB13F8A72F8B6E8B4071723E4E336 ] C:\Windows\System32\schedsvc.dll
17:22:45.0002 3820 C:\Windows\System32\schedsvc.dll - ok
17:22:45.0002 3820 [ 38B13C0DF479DBA23ECFA815159BA86E ] C:\Windows\System32\ktmw32.dll
17:22:45.0002 3820 C:\Windows\System32\ktmw32.dll - ok
17:22:45.0018 3820 [ 1FF7E4F548C7C372C804938F0D5B36AE ] C:\Windows\System32\netcfgx.dll
17:22:45.0018 3820 C:\Windows\System32\netcfgx.dll - ok
17:22:45.0034 3820 [ E6D90DC604F407B3B5E0FD285E46B2A0 ] C:\Windows\System32\fveapi.dll
17:22:45.0034 3820 C:\Windows\System32\fveapi.dll - ok
17:22:45.0034 3820 [ C87F28A34B3840F4B40011D170B1A159 ] C:\Windows\System32\fvecerts.dll
17:22:45.0034 3820 C:\Windows\System32\fvecerts.dll - ok
17:22:45.0049 3820 [ EAFC149CD3BD78C443E31BB157841197 ] C:\Windows\System32\tbs.dll
17:22:45.0049 3820 C:\Windows\System32\tbs.dll - ok
17:22:45.0049 3820 [ 1C3E8371377E988B683797A132EFFE1B ] C:\Windows\System32\taskcomp.dll
17:22:45.0049 3820 C:\Windows\System32\taskcomp.dll - ok
17:22:45.0065 3820 [ 871917B07A141BFF43D76D8844D48106 ] C:\Windows\System32\drivers\http.sys
17:22:45.0065 3820 C:\Windows\System32\drivers\http.sys - ok
17:22:45.0080 3820 [ 866A43013535DC8587C258E43579C764 ] C:\Windows\System32\spoolsv.exe
17:22:45.0080 3820 C:\Windows\System32\spoolsv.exe - ok
17:22:45.0080 3820 [ E2D56AE1D40E3725084054CD8E9CFBB1 ] C:\Windows\System32\wiarpc.dll
17:22:45.0080 3820 C:\Windows\System32\wiarpc.dll - ok
17:22:45.0096 3820 [ 1E2BAC209D184BB851E1A187D8A29136 ] C:\Windows\System32\BFE.DLL
17:22:45.0096 3820 C:\Windows\System32\BFE.DLL - ok
17:22:45.0096 3820 [ FCAFAEF6798D7B51FF029F99A9898961 ] C:\Windows\System32\drivers\bowser.sys
17:22:45.0096 3820 C:\Windows\System32\drivers\bowser.sys - ok
17:22:45.0112 3820 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] C:\Windows\System32\drivers\mpsdrv.sys
17:22:45.0112 3820 C:\Windows\System32\drivers\mpsdrv.sys - ok
17:22:45.0127 3820 [ B272B4C3E085EA860C12F2E4FAF2FFA2 ] C:\Windows\System32\drivers\mrxsmb.sys
17:22:45.0127 3820 C:\Windows\System32\drivers\mrxsmb.sys - ok
17:22:45.0127 3820 [ 9AC33EF26C8A3AD0F117D00EB7301D03 ] C:\Windows\System32\drivers\mrxsmb10.sys
17:22:45.0127 3820 C:\Windows\System32\drivers\mrxsmb10.sys - ok
17:22:45.0143 3820 [ E0ABDB5ED7E199E242A7D028E76C1D3A ] C:\Windows\System32\drivers\mrxsmb20.sys
17:22:45.0143 3820 C:\Windows\System32\drivers\mrxsmb20.sys - ok
17:22:45.0143 3820 [ 58405E4F68BA8E4057C6E914F326ABA2 ] C:\Windows\System32\wkssvc.dll
17:22:45.0143 3820 C:\Windows\System32\wkssvc.dll - ok
17:22:45.0158 3820 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] C:\Windows\System32\drivers\parport.sys
17:22:45.0158 3820 C:\Windows\System32\drivers\parport.sys - ok
17:22:45.0158 3820 [ 019C372B1A9DA73A22D0D35A4D40F5C9 ] C:\Windows\System32\wfapigp.dll
17:22:45.0158 3820 C:\Windows\System32\wfapigp.dll - ok
17:22:45.0174 3820 [ 4AFC14AFA58878FAA1D249E7E90EA54B ] C:\Program Files\AVG\AVG2013\avgidsagent.exe
17:22:45.0174 3820 C:\Program Files\AVG\AVG2013\avgidsagent.exe - ok
17:22:45.0190 3820 [ 358AB7956D3160000726574083DFC8A6 ] C:\Windows\System32\pcasvc.dll
17:22:45.0190 3820 C:\Windows\System32\pcasvc.dll - ok
17:22:45.0190 3820 [ 6A984831644ECA1A33FFEAE4126F4F37 ] C:\Windows\System32\snmptrap.exe
17:22:45.0190 3820 C:\Windows\System32\snmptrap.exe - ok
17:22:45.0205 3820 [ E3C817F7FE44CC870ECDBCBC3EA36132 ] C:\Windows\System32\msvcp100.dll
17:22:45.0205 3820 C:\Windows\System32\msvcp100.dll - ok
17:22:45.0205 3820 [ BF38660A9125935658CFA3E53FDC7D65 ] C:\Windows\System32\msvcr100.dll
17:22:45.0205 3820 C:\Windows\System32\msvcr100.dll - ok
17:22:45.0221 3820 [ F036DB9CF05B3C21405403FF074A78D9 ] C:\Program Files\AVG\AVG2013\avgopensslx.dll
17:22:45.0221 3820 C:\Program Files\AVG\AVG2013\avgopensslx.dll - ok
17:22:45.0236 3820 [ A2F17346CC5C502D4E29EF986BD17D34 ] C:\Windows\System32\PeerDistSh.dll
17:22:45.0236 3820 C:\Windows\System32\PeerDistSh.dll - ok
17:22:45.0236 3820 [ D318F23BE45D5E3A107469EB64815B50 ] C:\Windows\System32\sstpsvc.dll
17:22:45.0236 3820 C:\Windows\System32\sstpsvc.dll - ok
17:22:45.0252 3820 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] C:\Windows\System32\provsvc.dll
17:22:45.0252 3820 C:\Windows\System32\provsvc.dll - ok
17:22:45.0252 3820 [ B40F5DCD59ED2A46EED8AE340CC167FB ] C:\Program Files\AVG\AVG2013\avgcfgx.dll
17:22:45.0252 3820 C:\Program Files\AVG\AVG2013\avgcfgx.dll - ok
17:22:45.0268 3820 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] C:\Program Files\AVG\AVG2013\avgwdsvc.exe
17:22:45.0268 3820 C:\Program Files\AVG\AVG2013\avgwdsvc.exe - ok
17:22:45.0283 3820 [ A585BEBF7D054BD9618EDA0922D5484A ] C:\Windows\System32\cryptsvc.dll
17:22:45.0283 3820 C:\Windows\System32\cryptsvc.dll - ok
17:22:45.0283 3820 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] C:\Windows\System32\dps.dll
17:22:45.0283 3820 C:\Windows\System32\dps.dll - ok
17:22:45.0299 3820 [ 13337A3FB17F2242487FD45488ED0485 ] C:\Windows\System32\vssapi.dll
17:22:45.0299 3820 C:\Windows\System32\vssapi.dll - ok
17:22:45.0299 3820 [ B940289C83121046BD6A60ACC6028593 ] C:\Windows\System32\vsstrace.dll
17:22:45.0299 3820 C:\Windows\System32\vsstrace.dll - ok
17:22:45.0314 3820 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
17:22:45.0314 3820 C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe - ok
17:22:45.0330 3820 [ 210388FD8225B02BD83D77628AAE64A9 ] C:\Windows\System32\XAudio32.dll
17:22:45.0330 3820 C:\Windows\System32\XAudio32.dll - ok
17:22:45.0330 3820 [ 8624E0E2418413614EE1FECDB7B76B88 ] C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll
17:22:45.0330 3820 C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll - ok
17:22:45.0346 3820 [ D4467A285C91752018F67CDBA8680BAB ] C:\Program Files\Malwarebytes' Anti-Malware\mbamnet.dll
17:22:45.0346 3820 C:\Program Files\Malwarebytes' Anti-Malware\mbamnet.dll - ok
17:22:45.0346 3820 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
17:22:45.0346 3820 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe - ok
17:22:45.0361 3820 [ 40CAEEE0EAF1B8569F7C8DF6420F2CB9 ] C:\Windows\System32\sfc.dll
17:22:45.0361 3820 C:\Windows\System32\sfc.dll - ok
17:22:45.0377 3820 [ 84799328D87B3091A3BDD251E1AD31F9 ] C:\Windows\System32\sfc_os.dll
17:22:45.0377 3820 C:\Windows\System32\sfc_os.dll - ok
17:22:45.0377 3820 [ 4BE1DCAD76BE96D1EC887A41E570C404 ] C:\Program Files\Malwarebytes' Anti-Malware\mbamcore.dll
17:22:45.0377 3820 C:\Program Files\Malwarebytes' Anti-Malware\mbamcore.dll - ok
17:22:45.0392 3820 [ B9A8CBCFCD3EC9D2EA4740AF347BF108 ] C:\Windows\System32\mpr.dll
17:22:45.0392 3820 C:\Windows\System32\mpr.dll - ok
17:22:45.0408 3820 [ 0CEA2D0D3FA284B85ED5B68365114F76 ] C:\Windows\System32\drivers\mdmxsdk.sys
17:22:45.0408 3820 C:\Windows\System32\drivers\mdmxsdk.sys - ok
17:22:45.0408 3820 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] C:\Windows\System32\netman.dll
17:22:45.0408 3820 C:\Windows\System32\netman.dll - ok
17:22:45.0424 3820 [ 9E0104BA49F4E6973749A02BF41344ED ] C:\Windows\System32\drivers\PEAuth.sys
17:22:45.0424 3820 C:\Windows\System32\drivers\PEAuth.sys - ok
17:22:45.0424 3820 [ 75EA62927355189876081EF863064982 ] C:\Windows\System32\ncsi.dll
17:22:45.0424 3820 C:\Windows\System32\ncsi.dll - ok
17:22:45.0439 3820 [ 912084381D30D8B89EC4E293053F4710 ] C:\Windows\System32\nlasvc.dll
17:22:45.0439 3820 C:\Windows\System32\nlasvc.dll - ok
17:22:45.0455 3820 [ 90A3935D05B494A5A39D37E71F09A677 ] C:\Windows\System32\drivers\secdrv.sys
17:22:45.0455 3820 C:\Windows\System32\drivers\secdrv.sys - ok
17:22:45.0455 3820 [ CDBE627E16CC9E98F343D73F8E81D258 ] C:\Windows\System32\drivers\srvnet.sys
17:22:45.0455 3820 C:\Windows\System32\drivers\srvnet.sys - ok
17:22:45.0470 3820 [ 02C61D8AD469417F5508225C75DE3236 ] C:\Windows\System32\webio.dll
17:22:45.0470 3820 C:\Windows\System32\webio.dll - ok
17:22:45.0470 3820 [ CA9F7888B524D8100B977C81F44C3234 ] C:\Windows\System32\winhttp.dll
17:22:45.0470 3820 C:\Windows\System32\winhttp.dll - ok
17:22:45.0486 3820 [ A59B3A4442C52060CC7A85293AA3546F ] C:\Windows\System32\seclogon.dll
17:22:45.0486 3820 C:\Windows\System32\seclogon.dll - ok
17:22:45.0502 3820 [ 28E2231BD34A39C854BDF3923AB2FF86 ] C:\Windows\System32\ssdpapi.dll
17:22:45.0502 3820 C:\Windows\System32\ssdpapi.dll - ok
17:22:45.0502 3820 [ 36650D618CA34C9D357DFD3D89B2C56F ] C:\Windows\System32\sysmain.dll
17:22:45.0502 3820 C:\Windows\System32\sysmain.dll - ok
17:22:45.0517 3820 [ 613BF4820361543956909043A265C6AC ] C:\Windows\System32\tapisrv.dll
17:22:45.0517 3820 C:\Windows\System32\tapisrv.dll - ok
17:22:45.0517 3820 [ CCA24162E055C3714CE5A88B100C64ED ] C:\Windows\System32\drivers\tcpipreg.sys
17:22:45.0517 3820 C:\Windows\System32\drivers\tcpipreg.sys - ok
17:22:45.0533 3820 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] C:\Windows\System32\trkwks.dll
17:22:45.0533 3820 C:\Windows\System32\trkwks.dll - ok
17:22:45.0548 3820 [ 8CD1DEE212E52B9C22E66DBA44991D32 ] C:\Windows\System32\httpapi.dll
17:22:45.0548 3820 C:\Windows\System32\httpapi.dll - ok
17:22:45.0548 3820 [ 894F963BE999BA9DB5AAC3AED55B115D ] C:\Windows\System32\drivers\XAudio32.sys
17:22:45.0548 3820 C:\Windows\System32\drivers\XAudio32.sys - ok
17:22:45.0564 3820 [ F62E510B6AD4C21EB9FE8668ED251826 ] C:\Windows\System32\wbem\WMIsvc.dll
17:22:45.0564 3820 C:\Windows\System32\wbem\WMIsvc.dll - ok
17:22:45.0564 3820 [ 704314FD398C81D5F342CAA5DF7B7F21 ] C:\Windows\System32\wbemcomn.dll
17:22:45.0564 3820 C:\Windows\System32\wbemcomn.dll - ok
17:22:45.0580 3820 [ E5DD784A4EE5EBC72A86C677C988FCDB ] C:\Windows\System32\drivers\srv2.sys
17:22:45.0580 3820 C:\Windows\System32\drivers\srv2.sys - ok
17:22:45.0595 3820 [ 112127C3B2E64D7680CC39CD0A39DD7E ] C:\Windows\System32\drivers\srv.sys
17:22:45.0595 3820 C:\Windows\System32\drivers\srv.sys - ok
17:22:45.0611 3820 [ 4D65A07B795D6674312F879D09AA7663 ] C:\Windows\System32\iphlpsvc.dll
17:22:45.0611 3820 C:\Windows\System32\iphlpsvc.dll - ok
17:22:45.0611 3820 [ 701C9EB15E1E23D22F7C7184C0506673 ] C:\Windows\System32\wbem\WmiDcPrv.dll
17:22:45.0611 3820 C:\Windows\System32\wbem\WmiDcPrv.dll - ok
17:22:45.0626 3820 [ CFC7D8289D2B5F3CF8D16E2DB7F93D4A ] C:\Windows\System32\wbem\fastprox.dll
17:22:45.0626 3820 C:\Windows\System32\wbem\fastprox.dll - ok
17:22:45.0642 3820 [ CE292C4C10B8DB6070F262EA2733F0DC ] C:\Windows\System32\sqmapi.dll
17:22:45.0642 3820 C:\Windows\System32\sqmapi.dll - ok
17:22:45.0658 3820 [ A399514D3B28C9A3453A486BBAAFF1C7 ] C:\Windows\System32\wdscore.dll
17:22:45.0658 3820 C:\Windows\System32\wdscore.dll - ok
17:22:45.0704 3820 [ E3E811471DE781900FF21C1FD84E941E ] C:\Windows\System32\ntdsapi.dll
17:22:45.0704 3820 C:\Windows\System32\ntdsapi.dll - ok
17:22:45.0720 3820 [ 881D9F2D6E04E1C323050CF1574870F7 ] C:\Windows\System32\wbem\WinMgmtR.dll
17:22:45.0720 3820 C:\Windows\System32\wbem\WinMgmtR.dll - ok
17:22:45.0736 3820 [ C5B0324DB461559ADD070E632A6919FA ] C:\Windows\System32\wbem\wbemprox.dll
17:22:45.0736 3820 C:\Windows\System32\wbem\wbemprox.dll - ok
17:22:45.0736 3820 [ 6E11F33D14D020F58D5E02E4D67DFA19 ] C:\Windows\System32\browser.dll
17:22:45.0736 3820 C:\Windows\System32\browser.dll - ok
17:22:45.0751 3820 [ D64AF876D53ECA3668BB97B51B4E70AB ] C:\Windows\System32\srvsvc.dll
17:22:45.0751 3820 C:\Windows\System32\srvsvc.dll - ok
17:22:45.0767 3820 [ E4B72E71EC37A59FE574A998A0C0EB9B ] C:\Windows\System32\netmsg.dll
17:22:45.0767 3820 C:\Windows\System32\netmsg.dll - ok
17:22:45.0782 3820 [ 89E783711AF91AF09E1EF30EF3107446 ] C:\Windows\System32\sscore.dll
17:22:45.0782 3820 C:\Windows\System32\sscore.dll - ok
17:22:45.0782 3820 [ AE9898D5600A232CD8AE3298692162E5 ] C:\Windows\System32\clusapi.dll
17:22:45.0782 3820 C:\Windows\System32\clusapi.dll - ok
17:22:45.0798 3820 [ 2AF094C822BD6094F14A8E85FB51D52A ] C:\Windows\System32\resutils.dll
17:22:45.0798 3820 C:\Windows\System32\resutils.dll - ok
17:22:45.0814 3820 [ 6383C60EC0133B14F5705F96369421B2 ] C:\Windows\System32\hnetcfg.dll
17:22:45.0814 3820 C:\Windows\System32\hnetcfg.dll - ok
17:22:45.0814 3820 [ CB9E04DC05EACF5B9A36CA276D475006 ] C:\Windows\System32\rasmans.dll
17:22:45.0814 3820 C:\Windows\System32\rasmans.dll - ok
17:22:45.0829 3820 [ 585EB475E7AF55C9065256E8FFB751A1 ] C:\Windows\System32\wbem\wbemcore.dll
17:22:45.0829 3820 C:\Windows\System32\wbem\wbemcore.dll - ok
17:22:45.0845 3820 [ 5AE88135C6A86FCD67BA16AFBB1C8389 ] C:\Windows\System32\wbem\esscli.dll
17:22:45.0845 3820 C:\Windows\System32\wbem\esscli.dll - ok
17:22:45.0845 3820 [ 776AE0564F8B1C282E331FD95A1BDC5F ] C:\Windows\System32\wbem\wbemsvc.dll
17:22:45.0845 3820 C:\Windows\System32\wbem\wbemsvc.dll - ok
17:22:45.0860 3820 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] C:\Program Files\Windows Defender\MpSvc.dll
17:22:45.0860 3820 C:\Program Files\Windows Defender\MpSvc.dll - ok
17:22:45.0876 3820 [ B2E1E4A16EDD02396F451F915FA3CBFA ] C:\Windows\System32\rastapi.dll
17:22:45.0876 3820 C:\Windows\System32\rastapi.dll - ok
17:22:45.0892 3820 [ BA32509D9B340162327B341013DE6522 ] C:\Windows\System32\tapi32.dll
17:22:45.0892 3820 C:\Windows\System32\tapi32.dll - ok
17:22:45.0892 3820 [ ED6EE83D61EBC683C2CD8E899EA6FEBE ] C:\Windows\System32\rasadhlp.dll
17:22:45.0892 3820 C:\Windows\System32\rasadhlp.dll - ok
17:22:45.0907 3820 [ 371E3B05894549113D07CD3081ED55EF ] C:\Windows\System32\wbem\repdrvfs.dll
17:22:45.0907 3820 C:\Windows\System32\wbem\repdrvfs.dll - ok
17:22:45.0923 3820 [ 5610B0425518D185331CB8E968D060E6 ] C:\Windows\System32\wbem\wmiutils.dll
17:22:45.0923 3820 C:\Windows\System32\wbem\wmiutils.dll - ok
17:22:45.0923 3820 [ 20308CF0675AD7CE5AAA6712DB823216 ] C:\Program Files\Windows Defender\MpClient.dll
17:22:45.0923 3820 C:\Program Files\Windows Defender\MpClient.dll - ok
17:22:45.0938 3820 [ 377F0C1DDBFA6A43CB7E7568BC0ECED0 ] C:\Windows\System32\unimdm.tsp
17:22:45.0938 3820 C:\Windows\System32\unimdm.tsp - ok
17:22:45.0954 3820 [ 3CDE2911462FEC80064A409C07710C06 ] C:\Windows\System32\wbem\WmiPrvSD.dll
17:22:45.0954 3820 C:\Windows\System32\wbem\WmiPrvSD.dll - ok
17:22:45.0970 3820 [ A4CC7227A452C4909F9499D91B184364 ] C:\Windows\System32\ncobjapi.dll
17:22:45.0970 3820 C:\Windows\System32\ncobjapi.dll - ok
17:22:45.0970 3820 [ B350509B6C9296529BC464C60FEEAEF1 ] C:\Windows\System32\wbem\wbemess.dll
17:22:45.0970 3820 C:\Windows\System32\wbem\wbemess.dll - ok
17:22:45.0985 3820 [ E675DE8CF57D8814218733B3DAE896D7 ] C:\Windows\System32\uniplat.dll
17:22:45.0985 3820 C:\Windows\System32\uniplat.dll - ok
17:22:46.0001 3820 [ 53CA6BF58658815FCB472205291DD953 ] C:\Windows\System32\unimdmat.dll
17:22:46.0001 3820 C:\Windows\System32\unimdmat.dll - ok
17:22:46.0001 3820 [ 4EAF682E27490A3D45C0EBB6537EE6A8 ] C:\Windows\System32\modemui.dll
17:22:46.0001 3820 C:\Windows\System32\modemui.dll - ok
17:22:46.0016 3820 [ F3FB146CDBDD26FCD0CF7941C547BEE4 ] C:\Windows\System32\kmddsp.tsp
17:22:46.0016 3820 C:\Windows\System32\kmddsp.tsp - ok
17:22:46.0032 3820 [ AA11A26692E0DB2996CAEFE9EC61F61F ] C:\Windows\System32\ndptsp.tsp
17:22:46.0032 3820 C:\Windows\System32\ndptsp.tsp - ok
17:22:46.0048 3820 [ E2F6CC0D191361EE94FEA3957653F531 ] C:\Windows\System32\hidphone.tsp
17:22:46.0048 3820 C:\Windows\System32\hidphone.tsp - ok
17:22:46.0063 3820 [ 67F9B5C7E215B48F9256757E9CC09A7B ] C:\Windows\System32\rasppp.dll
17:22:46.0063 3820 C:\Windows\System32\rasppp.dll - ok
17:22:46.0079 3820 [ 80B562B5B59ED850C328DD75F964F3D8 ] C:\Windows\System32\vpnike.dll
17:22:46.0079 3820 C:\Windows\System32\vpnike.dll - ok
17:22:46.0079 3820 [ 207CF171B1C6B8AE50C1FBF87363EEBC ] C:\Windows\System32\raschap.dll
17:22:46.0079 3820 C:\Windows\System32\raschap.dll - ok
17:22:46.0094 3820 [ D1A079A0DE2EA524513B6930C24527A2 ] C:\Windows\System32\ipnathlp.dll
17:22:46.0094 3820 C:\Windows\System32\ipnathlp.dll - ok
17:22:46.0110 3820 [ D4191EFAB91E00FC09257AA5EBAF503B ] C:\Windows\System32\mprapi.dll
17:22:46.0110 3820 C:\Windows\System32\mprapi.dll - ok
17:22:46.0110 3820 [ EAB975DB4C2805927FE5BD047D05C9AA ] C:\Windows\System32\netshell.dll
17:22:46.0110 3820 C:\Windows\System32\netshell.dll - ok
17:22:46.0126 3820 [ 57616A5583E6406F88BC71A5A5E0C165 ] C:\Program Files\AVG\AVG2013\avgwd.dll
17:22:46.0126 3820 C:\Program Files\AVG\AVG2013\avgwd.dll - ok
17:22:46.0141 3820 [ 9E30B21B14FB24C383AC255BDFA47E0E ] C:\Program Files\AVG\AVG2013\avgsecapix.dll
17:22:46.0141 3820 C:\Program Files\AVG\AVG2013\avgsecapix.dll - ok
17:22:46.0141 3820 [ 491918E4C46ED4CEB6E7A90F7B73924D ] C:\Program Files\AVG\AVG2013\avgxpl.dll
17:22:46.0157 3820 C:\Program Files\AVG\AVG2013\avgxpl.dll - ok
17:22:46.0157 3820 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] C:\Windows\System32\wdi.dll
17:22:46.0157 3820 C:\Windows\System32\wdi.dll - ok
17:22:46.0172 3820 [ AA53356D60AF47EACC85BC617A4F3F66 ] C:\Windows\System32\wpdbusenum.dll
17:22:46.0172 3820 C:\Windows\System32\wpdbusenum.dll - ok
17:22:46.0188 3820 [ ECF036299AA554B5E0455262857B39D0 ] C:\Windows\System32\diagperf.dll
17:22:46.0188 3820 C:\Windows\System32\diagperf.dll - ok
17:22:46.0188 3820 [ 7E82616BEE76BF5EAA5B30F681414E21 ] C:\Windows\System32\perftrack.dll
17:22:46.0188 3820 C:\Windows\System32\perftrack.dll - ok
17:22:46.0204 3820 [ E98278865E8DABA21CFE5FE4BE34210A ] C:\Windows\System32\PortableDeviceApi.dll
17:22:46.0204 3820 C:\Windows\System32\PortableDeviceApi.dll - ok
17:22:46.0219 3820 [ 590D5C506044FE02FF7643E32FF9BDAC ] C:\Windows\System32\wer.dll
17:22:46.0219 3820 C:\Windows\System32\wer.dll - ok
17:22:46.0219 3820 [ F8E882C10AF4C29E378D1E28D4817CB1 ] C:\Windows\System32\pnpts.dll
17:22:46.0219 3820 C:\Windows\System32\pnpts.dll - ok
17:22:46.0235 3820 [ F0016853FA3F38F55FD868FF74C0359B ] C:\Windows\System32\wdiasqmmodule.dll
17:22:46.0235 3820 C:\Windows\System32\wdiasqmmodule.dll - ok
17:22:46.0250 3820 [ 8B794AE6D5C7D42092804BC39A2EB8F6 ] C:\Windows\System32\aepic.dll
17:22:46.0250 3820 C:\Windows\System32\aepic.dll - ok
17:22:46.0266 3820 [ D99621C0735B21DCC8BC4FEF02F379EF ] C:\Windows\System32\Apphlpdm.dll
17:22:46.0266 3820 C:\Windows\System32\Apphlpdm.dll - ok
17:22:46.0266 3820 [ 15E298B5EC5B89C5994A59863969D9FF ] C:\Windows\System32\npmproxy.dll
17:22:46.0266 3820 C:\Windows\System32\npmproxy.dll - ok
17:22:46.0282 3820 [ C693E642ACFBDD76433AF6BE3C3EEE6F ] C:\Windows\System32\PortableDeviceConnectApi.dll
17:22:46.0282 3820 C:\Windows\System32\PortableDeviceConnectApi.dll - ok
17:22:46.0297 3820 [ F7FE730CE31B54145DEE1F1482BCCDD7 ] C:\Windows\System32\ndiscapCfg.dll
17:22:46.0297 3820 C:\Windows\System32\ndiscapCfg.dll - ok
17:22:46.0313 3820 [ 761A3A4038C1FD4F5795427907C28484 ] C:\Windows\System32\rascfg.dll
17:22:46.0313 3820 C:\Windows\System32\rascfg.dll - ok
17:22:46.0313 3820 [ 9A7B54D57594233EEB17892BAD309970 ] C:\Windows\System32\mprmsg.dll
17:22:46.0313 3820 C:\Windows\System32\mprmsg.dll - ok
17:22:46.0328 3820 [ CAFC0B884E5590B5E80D84F592388B3D ] C:\Windows\System32\tcpipcfg.dll
17:22:46.0328 3820 C:\Windows\System32\tcpipcfg.dll - ok
17:22:46.0344 3820 [ 78DE417B7921DACA072059E6BF410FC7 ] C:\Windows\System32\wshnetbs.dll
17:22:46.0344 3820 C:\Windows\System32\wshnetbs.dll - ok
17:22:46.0344 3820 [ 45D9F6CD2469CDB6A640DD4BD2B01471 ] C:\Windows\System32\nci.dll
17:22:46.0344 3820 C:\Windows\System32\nci.dll - ok
17:22:46.0360 3820 [ 9E6AF823733C70E207D9FB6731A63B3D ] C:\Windows\System32\wlaninst.dll
17:22:46.0360 3820 C:\Windows\System32\wlaninst.dll - ok
17:22:46.0360 3820 [ 5B6EF0861BB5AC0EC347548E85C24A1D ] C:\Windows\System32\wwaninst.dll
17:22:46.0360 3820 C:\Windows\System32\wwaninst.dll - ok
17:22:46.0375 3820 [ F67480EE1AC3CB32C63AF86B0AE57AC9 ] C:\Program Files\AVG\AVG2013\avgwdwsc.dll
17:22:46.0375 3820 C:\Program Files\AVG\AVG2013\avgwdwsc.dll - ok
17:22:46.0391 3820 [ A8CDF3768604FF95B54669E20053D569 ] C:\Windows\System32\wscapi.dll
17:22:46.0391 3820 C:\Windows\System32\wscapi.dll - ok
17:22:46.0406 3820 [ 1CA7C04957F8419E426E334B5FF2D0FA ] C:\Program Files\AVG\AVG2013\avgnsx.exe
17:22:46.0406 3820 C:\Program Files\AVG\AVG2013\avgnsx.exe - ok
17:22:46.0406 3820 [ A4932026499FFE9A493E3E9BBFDAA682 ] C:\Program Files\AVG\AVG2013\avgemcx.exe
17:22:46.0406 3820 C:\Program Files\AVG\AVG2013\avgemcx.exe - ok
17:22:46.0422 3820 [ 8622AE563E2AC2F8BF9FAFEE726FC7B8 ] C:\Program Files\AVG\AVG2013\avgsched.dll
17:22:46.0422 3820 C:\Program Files\AVG\AVG2013\avgsched.dll - ok
17:22:46.0422 3820 [ E9296800685ED622132C0E1FA9241F92 ] C:\Program Files\AVG\AVG2013\avgkrnlapix.dll
17:22:46.0422 3820 C:\Program Files\AVG\AVG2013\avgkrnlapix.dll - ok
17:22:46.0438 3820 [ 6F8E3B7B70E1BBA871212940C1FBDF60 ] C:\Windows\System32\SensApi.dll
17:22:46.0438 3820 C:\Windows\System32\SensApi.dll - ok
17:22:46.0438 3820 [ FF9AFBD2864BBEA6A9E7F90F8C94F6B7 ] C:\Program Files\AVG\AVG2013\avgidpsdkx.dll
17:22:46.0438 3820 C:\Program Files\AVG\AVG2013\avgidpsdkx.dll - ok
17:22:46.0453 3820 [ DB34611AFB2647628D215BB215095181 ] C:\Program Files\AVG\AVG2013\avgcmgr.exe
17:22:46.0453 3820 C:\Program Files\AVG\AVG2013\avgcmgr.exe - ok
17:22:46.0469 3820 [ 156F20E7A89573C2FD7CBC305DFC181F ] C:\Windows\System32\conhost.exe
17:22:46.0469 3820 C:\Windows\System32\conhost.exe - ok
17:22:46.0469 3820 [ A63DC5C2EA944E6657203E0C8EDEAF61 ] C:\Windows\System32\dllhost.exe
17:22:46.0469 3820 C:\Windows\System32\dllhost.exe - ok
17:22:46.0484 3820 [ 7FFD52D73352806969D424EF327D10A7 ] C:\Windows\System32\radardt.dll
17:22:46.0484 3820 C:\Windows\System32\radardt.dll - ok
17:22:46.0484 3820 [ 3977E4863FBA44B07B278A115074544A ] C:\Program Files\AVG\AVG2013\avgcslx.dll
17:22:46.0484 3820 C:\Program Files\AVG\AVG2013\avgcslx.dll - ok
17:22:46.0500 3820 [ 0B31464B7B2D616BD5F7036673588EC1 ] C:\Windows\System32\IDStore.dll
17:22:46.0500 3820 C:\Windows\System32\IDStore.dll - ok
17:22:46.0516 3820 [ 7FA8BA5A780E4757964AC9D4238302B9 ] C:\Windows\System32\taskhost.exe
17:22:46.0516 3820 C:\Windows\System32\taskhost.exe - ok
17:22:46.0516 3820 [ 7853D2AB445C10F97610B2B05FA4CF0A ] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
17:22:46.0516 3820 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe - ok
17:22:46.0531 3820 [ 61AC3EFDFACFDD3F0F11DD4FD4044223 ] C:\Windows\System32\userinit.exe
17:22:46.0531 3820 C:\Windows\System32\userinit.exe - ok
17:22:46.0531 3820 [ F58516E2DC0D963EF70D6BFC21FD82C4 ] C:\Windows\System32\PlaySndSrv.dll
17:22:46.0531 3820 C:\Windows\System32\PlaySndSrv.dll - ok
17:22:46.0547 3820 [ 505BF4D1CADEB8D4F8BCD08D944DE25D ] C:\Windows\System32\dwm.exe
17:22:46.0547 3820 C:\Windows\System32\dwm.exe - ok
17:22:46.0547 3820 [ 7319102526BD11B45FD66335CF90CA12 ] C:\Windows\System32\HotStartUserAgent.dll
17:22:46.0547 3820 C:\Windows\System32\HotStartUserAgent.dll - ok
17:22:46.0562 3820 [ 754AFC50022C95DA7C86B7020DB78136 ] C:\Windows\System32\dwmredir.dll
17:22:46.0562 3820 C:\Windows\System32\dwmredir.dll - ok
17:22:46.0578 3820 [ B43687C534A49700BF4B3C9898763752 ] C:\Windows\System32\MsCtfMonitor.dll
17:22:46.0578 3820 C:\Windows\System32\MsCtfMonitor.dll - ok
17:22:46.0578 3820 [ 56CEED370508F69A1BA04939BD1BADDA ] C:\Windows\System32\msutb.dll
17:22:46.0578 3820 C:\Windows\System32\msutb.dll - ok
17:22:46.0594 3820 [ 497E59D9F01C6F247E72222A61835119 ] C:\Windows\System32\dwmcore.dll
17:22:46.0594 3820 C:\Windows\System32\dwmcore.dll - ok
17:22:46.0594 3820 [ 6E05F39AF5B91CEE0D2A84501EEEDBD8 ] C:\Windows\System32\d3d10_1.dll
17:22:46.0594 3820 C:\Windows\System32\d3d10_1.dll - ok
17:22:46.0609 3820 [ 40D777B7A95E00593EB1568C68514493 ] C:\Windows\explorer.exe
17:22:46.0609 3820 C:\Windows\explorer.exe - ok
17:22:46.0625 3820 [ 9C36A3CA80F9B204C670336D344F5DF8 ] C:\Windows\System32\d3d10_1core.dll
17:22:46.0625 3820 C:\Windows\System32\d3d10_1core.dll - ok
17:22:46.0625 3820 [ 0411B7958C524BB2E91EE1B3035FE321 ] C:\Windows\System32\dxgi.dll
17:22:46.0625 3820 C:\Windows\System32\dxgi.dll - ok
17:22:46.0640 3820 [ E2A17BCC08D92F42E08AF6BA2F93ABA7 ] C:\Windows\System32\ExplorerFrame.dll
17:22:46.0640 3820 C:\Windows\System32\ExplorerFrame.dll - ok
17:22:46.0640 3820 [ 8B32E98FB3AE379DB6D00BB17BC92D71 ] C:\Windows\System32\nvwgf2um.dll
17:22:46.0640 3820 C:\Windows\System32\nvwgf2um.dll - ok
17:22:46.0656 3820 [ 2100560AF3F7F2948F2676E44DFB4ECF ] C:\Windows\System32\uDWM.dll
17:22:46.0656 3820 C:\Windows\System32\uDWM.dll - ok
17:22:46.0656 3820 [ 846D0E4DB261CFAF363902E41498E961 ] C:\Windows\System32\EhStorShell.dll
17:22:46.0656 3820 C:\Windows\System32\EhStorShell.dll - ok
17:22:46.0672 3820 [ 3EC541C196DE18ED9A0D0AC82A694D4C ] C:\Windows\System32\cscui.dll
17:22:46.0672 3820 C:\Windows\System32\cscui.dll - ok
17:22:46.0687 3820 [ 57A51217581614DE07F30E34D6BB4993 ] C:\Windows\System32\cscdll.dll
17:22:46.0687 3820 C:\Windows\System32\cscdll.dll - ok
17:22:46.0687 3820 [ 465BEA35F7ED4A4A57686DEA7EA10F47 ] C:\Windows\System32\cscapi.dll
17:22:46.0687 3820 C:\Windows\System32\cscapi.dll - ok
17:22:46.0703 3820 [ EB77DB354791A5932CA559B6F6374E95 ] C:\Windows\System32\ntshrui.dll
17:22:46.0703 3820 C:\Windows\System32\ntshrui.dll - ok
17:22:46.0718 3820 [ 523CF74A52C9A1762DA8B83AEE734498 ] C:\Windows\System32\IconCodecService.dll
17:22:46.0718 3820 C:\Windows\System32\IconCodecService.dll - ok
17:22:46.0718 3820 [ FB1959012294D6AD43E5304DF65E3C26 ] C:\Windows\System32\appinfo.dll
17:22:46.0718 3820 C:\Windows\System32\appinfo.dll - ok
17:22:46.0734 3820 [ D44741F65A1D71F65814A12CF6E2400A ] C:\Windows\System32\runonce.exe
17:22:46.0734 3820 C:\Windows\System32\runonce.exe - ok
17:22:46.0734 3820 [ AD7B9C14083B52BC532FBA5948342B98 ] C:\Windows\System32\cmd.exe
17:22:46.0734 3820 C:\Windows\System32\cmd.exe - ok
17:22:46.0750 3820 [ 2F03490092C032392FB6FF635222B9B2 ] C:\Windows\System32\apisetschema.dll
17:22:46.0750 3820 C:\Windows\System32\apisetschema.dll - ok
17:22:46.0765 3820 [ F042EE4C8D66248D9B86DCF52ABAE416 ] C:\Windows\PEV.exe
17:22:46.0765 3820 C:\Windows\PEV.exe - ok
17:22:46.0765 3820 [ 4619E14B2DF4137907CD988ACA4B30A5 ] C:\Windows\System32\ieframe.dll
17:22:46.0765 3820 C:\Windows\System32\ieframe.dll - ok
17:22:46.0781 3820 [ BE247AE996A9FDE007A27B51413A6C79 ] C:\Windows\System32\shdocvw.dll
17:22:46.0781 3820 C:\Windows\System32\shdocvw.dll - ok
17:22:46.0796 3820 [ 178A34E5554DCE485E1262DDF027960C ] C:\Users\phil\AppData\Local\Temp\7AE393AD-44F0-4DE1-AC54-65CECC13583B.exe
17:22:46.0796 3820 C:\Users\phil\AppData\Local\Temp\7AE393AD-44F0-4DE1-AC54-65CECC13583B.exe - ok
17:22:46.0812 3820 [ 04D16553664796613FE98D441A0C35D7 ] C:\Windows\System32\cryptnet.dll
17:22:46.0812 3820 C:\Windows\System32\cryptnet.dll - ok
17:22:46.0812 3820 [ 7A6986DD659B96398A11AF5173892715 ] C:\Windows\System32\cabinet.dll
17:22:46.0812 3820 C:\Windows\System32\cabinet.dll - ok
17:22:46.0828 3820 [ 12C4E95F468A5FD3FBB8166E27ED4D53 ] C:\Windows\System32\localspl.dll
17:22:46.0828 3820 C:\Windows\System32\localspl.dll - ok
17:22:46.0843 3820 [ 629181C26A78EB66B0B4E774E5AC2882 ] C:\Windows\System32\spoolss.dll
17:22:46.0843 3820 C:\Windows\System32\spoolss.dll - ok
17:22:46.0859 3820 [ 03CF941D031F30272D3063E5A4D686F5 ] C:\Windows\System32\PrintIsolationProxy.dll
17:22:46.0859 3820 C:\Windows\System32\PrintIsolationProxy.dll - ok
17:22:46.0859 3820 [ 126F8331BD023178C7F0EF2F5EDE16B3 ] C:\Windows\System32\FXSMON.dll
17:22:46.0859 3820 C:\Windows\System32\FXSMON.dll - ok
17:22:46.0874 3820 [ B390C1D825C7687493BEDE237C6C2F25 ] C:\Windows\System32\tcpmon.dll
17:22:46.0874 3820 C:\Windows\System32\tcpmon.dll - ok
17:22:46.0890 3820 [ 1220595CABA75AB91A6B3FA3B89483CC ] C:\Windows\System32\snmpapi.dll
17:22:46.0890 3820 C:\Windows\System32\snmpapi.dll - ok
17:22:46.0906 3820 [ 6357E2B68753A1F5CF4A68A25C4FD14A ] C:\Windows\System32\wsnmp32.dll
17:22:46.0906 3820 C:\Windows\System32\wsnmp32.dll - ok
17:22:46.0906 3820 [ 923CDD30092DB73EC4A0EBCDDD16C686 ] C:\Windows\System32\usbmon.dll
17:22:46.0906 3820 C:\Windows\System32\usbmon.dll - ok
17:22:46.0921 3820 [ A8EB761DE499242BECF153B2B34F020E ] C:\Windows\System32\WSDMon.dll
17:22:46.0921 3820 C:\Windows\System32\WSDMon.dll - ok
17:22:46.0921 3820 [ 73F6C5223F7E9B5780DD4A6C30FCF569 ] C:\Windows\System32\WSDApi.dll
17:22:46.0921 3820 C:\Windows\System32\WSDApi.dll - ok
17:22:46.0937 3820 [ DB846EECA70EE9D2E2FF31147C57B0F4 ] C:\Windows\System32\webservices.dll
17:22:46.0937 3820 C:\Windows\System32\webservices.dll - ok
17:22:46.0937 3820 [ 89D90579E5FB1469CB0464F6512E42B7 ] C:\Windows\System32\fundisc.dll
17:22:46.0937 3820 C:\Windows\System32\fundisc.dll - ok
17:22:46.0952 3820 [ F34CFADA6C48DAA41B996D24C7D8D3CA ] C:\Windows\System32\fdPnp.dll
17:22:46.0952 3820 C:\Windows\System32\fdPnp.dll - ok
17:22:46.0968 3820 [ CD72C6406BA561BED6D42CB145E55307 ] C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll
17:22:46.0968 3820 C:\Windows\System32\spool\prtprocs\w32x86\winprint.dll - ok
17:22:46.0968 3820 [ 536E06B5A05C6E39C8748E3941FB083D ] C:\Windows\System32\win32spl.dll
17:22:46.0968 3820 C:\Windows\System32\win32spl.dll - ok
17:22:46.0984 3820 [ D27DDE7E0444C7F1819F958469EB7D93 ] C:\Windows\System32\inetpp.dll
17:22:46.0984 3820 C:\Windows\System32\inetpp.dll - ok
17:22:46.0984 3820 [ 89F5770AD1E9D9CEF93D00303135EC33 ] C:\Windows\System32\ntprint.dll
17:22:46.0984 3820 C:\Windows\System32\ntprint.dll - ok
17:22:46.0999 3820 [ BE542DCCC88A8B08BF2D6D17D18B5D4E ] C:\Program Files\NVIDIA Corporation\Display\nvsmartmax.dll
17:22:46.0999 3820 C:\Program Files\NVIDIA Corporation\Display\nvsmartmax.dll - ok
17:22:47.0015 3820 [ 46BAB9B8225F4E90F6BEADA249E36AAA ] C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
17:22:47.0015 3820 C:\Program Files\NVIDIA Corporation\Display\nvtray.exe - ok
17:22:47.0015 3820 [ BA71BE20910A5AE4CE884B6FF9B82EDD ] C:\Program Files\NVIDIA Corporation\Update Common\NvUpdt.dll
17:22:47.0015 3820 C:\Program Files\NVIDIA Corporation\Update Common\NvUpdt.dll - ok
17:22:47.0030 3820 [ 2164F291AB56BFB08B1C30E423D05CA2 ] C:\Program Files\NVIDIA Corporation\Update Common\EasyDaemonAPIU.dll
17:22:47.0030 3820 C:\Program Files\NVIDIA Corporation\Update Common\EasyDaemonAPIU.dll - ok
17:22:47.0030 3820 [ CFF769477F901840149A4E392F815979 ] C:\Program Files\NVIDIA Corporation\Update Common\NvUpdtr.dll
17:22:47.0046 3820 C:\Program Files\NVIDIA Corporation\Update Common\NvUpdtr.dll - ok
17:22:47.0046 3820 [ 0B7E85364CB878E2AD531DB7B601A9E5 ] C:\Windows\System32\NapiNSP.dll
17:22:47.0046 3820 C:\Windows\System32\NapiNSP.dll - ok
17:22:47.0062 3820 [ 5CF640EDDB1E40A5AB1BB743BCDEC610 ] C:\Windows\System32\pnrpnsp.dll
17:22:47.0062 3820 C:\Windows\System32\pnrpnsp.dll - ok
17:22:47.0062 3820 [ 5DF5D8CFD9B9573FA3B2C89D9061A240 ] C:\Windows\System32\winrnr.dll
17:22:47.0062 3820 C:\Windows\System32\winrnr.dll - ok
17:22:47.0077 3820 [ 256503028879103E9741A276FA24D65D ] C:\Windows\System32\esent.dll
17:22:47.0077 3820 C:\Windows\System32\esent.dll - ok
17:22:47.0077 3820 [ F148865E4AC4F715E322EA06E6E21D84 ] C:\Windows\System32\wbem\NCProv.dll
17:22:47.0077 3820 C:\Windows\System32\wbem\NCProv.dll - ok
17:22:47.0093 3820 [ 0E4A28030C7C6B8A57A60BAF494B114D ] C:\Windows\System32\iedkcs32.dll
17:22:47.0093 3820 C:\Windows\System32\iedkcs32.dll - ok
17:22:47.0093 3820 [ 0EE3BD34729C40BD0853825753ACB319 ] C:\Windows\System32\ie4uinit.exe
17:22:47.0108 3820 C:\Windows\System32\ie4uinit.exe - ok
17:22:47.0108 3820 [ 83C9840CF87A0CA55526327801716D27 ] C:\Windows\System32\timedate.cpl
17:22:47.0108 3820 C:\Windows\System32\timedate.cpl - ok
17:22:47.0124 3820 [ D2958325C1AE1AE37A83334C6229E3BC ] C:\Windows\System32\actxprxy.dll
17:22:47.0124 3820 C:\Windows\System32\actxprxy.dll - ok
17:22:47.0124 3820 [ 5987EA8A82C53359BCD2C29D6588583E ] C:\Windows\System32\linkinfo.dll
17:22:47.0124 3820 C:\Windows\System32\linkinfo.dll - ok
17:22:47.0140 3820 [ 3A16EA01FCFAAB40882DB5BFEE632322 ] C:\Windows\System32\msftedit.dll
17:22:47.0140 3820 C:\Windows\System32\msftedit.dll - ok
17:22:47.0155 3820 [ 19BC13711AC403FEB830522E4831701B ] C:\Windows\System32\gameux.dll
17:22:47.0155 3820 C:\Windows\System32\gameux.dll - ok
17:22:47.0155 3820 [ 175383778EB24D98C84E624021E3AA0B ] C:\Windows\System32\aeevts.dll
17:22:47.0155 3820 C:\Windows\System32\aeevts.dll - ok
17:22:47.0171 3820 [ 26025A46FB3FDB40FF06BBF1834093B5 ] C:\Windows\System32\msls31.dll
17:22:47.0171 3820 C:\Windows\System32\msls31.dll - ok
17:22:47.0186 3820 [ 7896EFFDEE215C172BE724A64931EF1C ] C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
17:22:47.0186 3820 C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll - ok
17:22:47.0202 3820 [ 255E405D801CF01247390F38F92D8042 ] C:\Program Files\Unlocker\UnlockerAssistant.exe
17:22:47.0202 3820 C:\Program Files\Unlocker\UnlockerAssistant.exe - ok
17:22:47.0202 3820 [ 2A39F32E0067CBF221611FE1FA8C6D8F ] C:\Windows\System32\DeviceCenter.dll
17:22:47.0202 3820 C:\Windows\System32\DeviceCenter.dll - ok
17:22:47.0218 3820 [ ABBEE3E367F6E6ED415D33C78121FFA9 ] C:\Program Files\Unlocker\UnlockerHook.dll
17:22:47.0218 3820 C:\Program Files\Unlocker\UnlockerHook.dll - ok
17:22:47.0233 3820 [ 9DADF1A809ECEC86F04BDE35190D59FE ] C:\Program Files\AVG\AVG2013\avgui.exe
17:22:47.0233 3820 C:\Program Files\AVG\AVG2013\avgui.exe - ok
17:22:47.0233 3820 [ 672D7C5080ACB003343006405DA2E621 ] C:\Windows\System32\thumbcache.dll
17:22:47.0233 3820 C:\Windows\System32\thumbcache.dll - ok
17:22:47.0249 3820 [ 2A8681AEA24003040CA7D677BE9F1702 ] C:\Windows\System32\drivers\20150398.sys
17:22:47.0249 3820 C:\Windows\System32\drivers\20150398.sys - ok
17:22:47.0264 3820 [ 3D57FFBAD3ED16B63DE3879BAB0FB56F ] C:\Windows\System32\networkexplorer.dll
17:22:47.0264 3820 C:\Windows\System32\networkexplorer.dll - ok
17:22:47.0264 3820 [ F32077DF74EFD435A1DCDF415E189DF1 ] C:\Windows\System32\mfc100u.dll
17:22:47.0264 3820 C:\Windows\System32\mfc100u.dll - ok
17:22:47.0280 3820 [ DCCA4B04AF87E52EF9EAA2190E06CBAC ] C:\Program Files\Windows Sidebar\sidebar.exe
17:22:47.0280 3820 C:\Program Files\Windows Sidebar\sidebar.exe - ok
17:22:47.0296 3820 [ ECAF994DBDDE7409A4C2270CDA8177A6 ] C:\Windows\System32\mfc100fra.dll
17:22:47.0296 3820 C:\Windows\System32\mfc100fra.dll - ok
17:22:47.0311 3820 [ 0CE4D3BD306DA6D1F6F233C403F5B667 ] C:\Windows\System32\msi.dll
17:22:47.0311 3820 C:\Windows\System32\msi.dll - ok
17:22:47.0311 3820 [ 4205CA4CD43E725DB9FF02B0A588A8C6 ] C:\Windows\System32\msxml3.dll
17:22:47.0311 3820 C:\Windows\System32\msxml3.dll - ok
17:22:47.0327 3820 [ 30E30FEE2209D3C42BAFD1B9E6DB058A ] C:\Windows\System32\fr-FR\KernelBase.dll.mui
17:22:47.0327 3820 C:\Windows\System32\fr-FR\KernelBase.dll.mui - ok
17:22:47.0327 3820 [ 102CF6879887BBE846A00C459E6D4ABC ] C:\Windows\System32\riched20.dll
17:22:47.0327 3820 C:\Windows\System32\riched20.dll - ok
17:22:47.0342 3820 [ 31C2ADCC585BF23219EAC12923EC4B8C ] C:\Windows\System32\msxml3r.dll
17:22:47.0342 3820 C:\Windows\System32\msxml3r.dll - ok
17:22:47.0342 3820 [ 9730643AB698D3B7F19D9192E4D3E4B0 ] C:\Program Files\AVG\AVG2013\avgidpmx.dll
17:22:47.0342 3820 C:\Program Files\AVG\AVG2013\avgidpmx.dll - ok
17:22:47.0358 3820 [ 0DCA6A11D09D4C2CBE6B898B897EA915 ] C:\Windows\System32\UIAnimation.dll
17:22:47.0358 3820 C:\Windows\System32\UIAnimation.dll - ok
17:22:47.0358 3820 [ DE35D659575C700BA4E8E912671EA4BA ] C:\Program Files\AVG\AVG2013\avgdiagex.exe
17:22:47.0358 3820 C:\Program Files\AVG\AVG2013\avgdiagex.exe - ok
17:22:47.0374 3820 [ C50799F0D47DFB9774F721521B6C41D5 ] C:\Windows\System32\mshtml.dll
17:22:47.0374 3820 C:\Windows\System32\mshtml.dll - ok
17:22:47.0389 3820 [ 487F44B08EFEAF5AD087878357B9403D ] C:\Windows\System32\pdh.dll
17:22:47.0389 3820 C:\Windows\System32\pdh.dll - ok
17:22:47.0389 3820 [ 751EEDB874FD17A6F26B9E2CC5E19170 ] C:\Program Files\AVG\AVG2013\avglngx.dll
17:22:47.0389 3820 C:\Program Files\AVG\AVG2013\avglngx.dll - ok
17:22:47.0405 3820 [ 1D1EAA16D193C6A2D45981ED3914D22A ] C:\Windows\System32\msimtf.dll
17:22:47.0405 3820 C:\Windows\System32\msimtf.dll - ok
17:22:47.0405 3820 [ 912649A1B3F9E6ACB3899FBDABA2ED5F ] C:\Windows\System32\stobject.dll
17:22:47.0405 3820 C:\Windows\System32\stobject.dll - ok
17:22:47.0420 3820 [ EB74C861075ECFA1B51B396615387657 ] C:\Program Files\AVG\AVG2013\avguires.dll
17:22:47.0420 3820 C:\Program Files\AVG\AVG2013\avguires.dll - ok
17:22:47.0436 3820 [ 67C1B58706B47EEBA4E117AC197289E6 ] C:\Windows\System32\batmeter.dll
17:22:47.0436 3820 C:\Windows\System32\batmeter.dll - ok
17:22:47.0436 3820 [ F7E915FA38C119101873AE5E0E7C8B66 ] C:\Program Files\AVG\AVG2013\avgapps.dll
17:22:47.0436 3820 C:\Program Files\AVG\AVG2013\avgapps.dll - ok
17:22:47.0452 3820 [ 90FB1802D488FFA9029854A77D4F3F27 ] C:\Windows\System32\oleaccrc.dll
17:22:47.0452 3820 C:\Windows\System32\oleaccrc.dll - ok
17:22:47.0452 3820 [ C8333F1F77A1B2E25F2202E892CAF634 ] C:\Windows\System32\prnfldr.dll
17:22:47.0452 3820 C:\Windows\System32\prnfldr.dll - ok
17:22:47.0467 3820 [ F22F10918F02BC39F7EA93455A2D8CD7 ] C:\Windows\System32\jscript.dll
17:22:47.0467 3820 C:\Windows\System32\jscript.dll - ok
17:22:47.0483 3820 [ ADDB05C93272A62606599B24730BD645 ] C:\Windows\System32\DXP.dll
17:22:47.0483 3820 C:\Windows\System32\DXP.dll - ok
17:22:47.0483 3820 [ 51138BEEA3E2C21EC44D0932C71762A8 ] C:\Windows\System32\rundll32.exe
17:22:47.0483 3820 C:\Windows\System32\rundll32.exe - ok
17:22:47.0498 3820 [ 856CFFCD835528136367BB1A8FE1DB87 ] C:\Windows\System32\Syncreg.dll
17:22:47.0498 3820 C:\Windows\System32\Syncreg.dll - ok
17:22:47.0514 3820 [ 368B2BEE3F88BFB883D2C74A258DE6F6 ] C:\Windows\AppPatch\AcLayers.dll
17:22:47.0514 3820 C:\Windows\AppPatch\AcLayers.dll - ok
17:22:47.0530 3820 [ F8F03D206F7D5811D630349A23E9B9B9 ] C:\Windows\ehome\ehSSO.dll
17:22:47.0530 3820 C:\Windows\ehome\ehSSO.dll - ok
17:22:47.0530 3820 [ 89F4D0DD6606A2FE15931E6888DBBC8D ] C:\Windows\System32\stdole2.tlb
17:22:47.0530 3820 C:\Windows\System32\stdole2.tlb - ok
17:22:47.0545 3820 [ 8EE6BDE1D572677AA35707C52C585F75 ] C:\Windows\System32\mlang.dll
17:22:47.0545 3820 C:\Windows\System32\mlang.dll - ok
17:22:47.0545 3820 [ B2B3DAE040F6B5AE1DF52B0CD7631A18 ] C:\Windows\System32\AltTab.dll
17:22:47.0545 3820 C:\Windows\System32\AltTab.dll - ok
17:22:47.0561 3820 [ 518A6B6C832E60865BF78192E64CE02E ] C:\Program Files\AVG\AVG2013\avgsbgx.dll
17:22:47.0561 3820 C:\Program Files\AVG\AVG2013\avgsbgx.dll - ok
17:22:47.0576 3820 [ 735263DA17BF5BAF9CCD483843BF9D5A ] C:\Windows\System32\WPDShServiceObj.dll
17:22:47.0576 3820 C:\Windows\System32\WPDShServiceObj.dll - ok
17:22:47.0576 3820 [ ADB45A977BD9E45790CA496DB84BA148 ] C:\Windows\System32\PortableDeviceTypes.dll
17:22:47.0576 3820 C:\Windows\System32\PortableDeviceTypes.dll - ok
17:22:47.0592 3820 [ 3D6F22551D422F97AACB0BB927E4C846 ] C:\Windows\System32\pnidui.dll
17:22:47.0592 3820 C:\Windows\System32\pnidui.dll - ok
17:22:47.0608 3820 [ BD626EF05967D14C772B8096292731A3 ] C:\Windows\System32\QUTIL.DLL
17:22:47.0608 3820 C:\Windows\System32\QUTIL.DLL - ok
17:22:47.0608 3820 [ 622D95520182F6D3D05310D5810CA8B3 ] C:\Windows\System32\SearchIndexer.exe
17:22:47.0608 3820 C:\Windows\System32\SearchIndexer.exe - ok
17:22:47.0623 3820 [ CF4274CEEA9F7791FB7FC40A066BC2C7 ] C:\Windows\System32\cscobj.dll
17:22:47.0623 3820 C:\Windows\System32\cscobj.dll - ok
17:22:47.0639 3820 [ 674B0C0F6A448EB185CAAB9C51D44032 ] C:\Windows\System32\srchadmin.dll
17:22:47.0639 3820 C:\Windows\System32\srchadmin.dll - ok
17:22:47.0639 3820 [ 3CD99E5B2487A4018AACBCEB19EE65D0 ] C:\Windows\System32\tquery.dll
17:22:47.0639 3820 C:\Windows\System32\tquery.dll - ok
17:22:47.0654 3820 [ FBE743D60132CFA9982860C8E2D99154 ] C:\Windows\System32\mssrch.dll
17:22:47.0654 3820 C:\Windows\System32\mssrch.dll - ok
17:22:47.0654 3820 [ D39DA70FEA6BD713682F70635587DA9E ] C:\Windows\System32\rasdlg.dll
17:22:47.0654 3820 C:\Windows\System32\rasdlg.dll - ok
17:22:47.0670 3820 [ 93117349047DDB7B3FF24EB006207606 ] C:\Windows\System32\imgutil.dll
17:22:47.0670 3820 C:\Windows\System32\imgutil.dll - ok
17:22:47.0686 3820 [ 9A39A2A5F443A756C568C6ED5748AFE4 ] C:\Windows\System32\ActionCenter.dll
17:22:47.0686 3820 C:\Windows\System32\ActionCenter.dll - ok
17:22:47.0701 3820 [ EED5AE4EF38893DD1743A95760C98704 ] C:\Windows\System32\pngfilt.dll
17:22:47.0701 3820 C:\Windows\System32\pngfilt.dll - ok
17:22:47.0717 3820 [ 1CBF15FDB0310345A68972EB5C5B948F ] C:\Windows\System32\mssprxy.dll
17:22:47.0717 3820 C:\Windows\System32\mssprxy.dll - ok
17:22:47.0717 3820 [ 04B88428A872390D235BE52D38A9D4EF ] C:\Windows\System32\dot3api.dll
17:22:47.0717 3820 C:\Windows\System32\dot3api.dll - ok
17:22:47.0732 3820 [ 81600E2E27ED61427AAD865B9BCDDB9D ] C:\Windows\System32\msidle.dll
17:22:47.0732 3820 C:\Windows\System32\msidle.dll - ok
17:22:47.0748 3820 [ 8063046AA70B97CA9985672B8848FB2E ] C:\Windows\System32\wlanhlp.dll
17:22:47.0748 3820 C:\Windows\System32\wlanhlp.dll - ok
17:22:47.0764 3820 [ B010CF886420EE29C2C276646721D255 ] C:\Windows\System32\wlanapi.dll
17:22:47.0764 3820 C:\Windows\System32\wlanapi.dll - ok
17:22:47.0764 3820 [ C02AA67276FEE0C15CC4D6D616BDE95E ] C:\Windows\System32\WWanAPI.dll
17:22:47.0764 3820 C:\Windows\System32\WWanAPI.dll - ok
17:22:47.0779 3820 [ F2ED6D00921CA138289E5E0CCB9ABF87 ] C:\Windows\System32\wwapi.dll
17:22:47.0779 3820 C:\Windows\System32\wwapi.dll - ok
17:22:47.0795 3820 [ 02530B0B7E048DD5AC8D52DAEACAEB2B ] C:\Windows\System32\QAGENT.DLL
17:22:47.0795 3820 C:\Windows\System32\QAGENT.DLL - ok
17:22:47.0795 3820 [ E3D5E244807AD655787FCD25477CC1BC ] C:\Windows\System32\bthprops.cpl
17:22:47.0795 3820 C:\Windows\System32\bthprops.cpl - ok
17:22:47.0810 3820 [ A4EE3D80E31D5A3CA8EBE6A67A06CEC0 ] C:\Windows\System32\webcheck.dll
17:22:47.0810 3820 C:\Windows\System32\webcheck.dll - ok
17:22:47.0826 3820 [ 89ED7C028A487340B7D93D5A38FDCB54 ] C:\Windows\System32\SearchProtocolHost.exe
17:22:47.0826 3820 C:\Windows\System32\SearchProtocolHost.exe - ok
17:22:47.0826 3820 [ 2DDEA2C345DA5BC589EFD398F220DB0E ] C:\Windows\System32\SyncCenter.dll
17:22:47.0826 3820 C:\Windows\System32\SyncCenter.dll - ok
17:22:47.0842 3820 [ C2D6A4475B87651D5909E364439FDA52 ] C:\Windows\System32\FXSST.dll
17:22:47.0842 3820 C:\Windows\System32\FXSST.dll - ok
17:22:47.0842 3820 [ A5D237B8673025B052C0E6FDB6A883E8 ] C:\Windows\System32\msshooks.dll
17:22:47.0842 3820 C:\Windows\System32\msshooks.dll - ok
17:22:47.0857 3820 [ 942E57152F1CD0533644AB30EF1A4728 ] C:\Windows\System32\FXSAPI.dll
17:22:47.0857 3820 C:\Windows\System32\FXSAPI.dll - ok
17:22:47.0873 3820 [ C4096CA42199428B3D63DC206C197F0E ] C:\Windows\System32\FXSRESM.dll
17:22:47.0873 3820 C:\Windows\System32\FXSRESM.dll - ok
17:22:47.0873 3820 [ 8A674F9AB20B4937357BF6F5A0938EBF ] C:\Windows\System32\SearchFilterHost.exe
17:22:47.0873 3820 C:\Windows\System32\SearchFilterHost.exe - ok
17:22:47.0888 3820 [ 967EA5B213E9984CBE270205DF37755B ] C:\Windows\System32\FXSSVC.exe
17:22:47.0888 3820 C:\Windows\System32\FXSSVC.exe - ok
17:22:47.0888 3820 [ 2D11BC8B460957E62E4420373A0D8BDA ] C:\Windows\System32\imapi2.dll
17:22:47.0888 3820 C:\Windows\System32\imapi2.dll - ok
17:22:47.0904 3820 [ D83947A58613E9091B4C9CC0F1546A8D ] C:\Windows\System32\mscoree.dll
17:22:47.0904 3820 C:\Windows\System32\mscoree.dll - ok
17:22:47.0920 3820 [ C7952D0A4C43A965A1741916BB134751 ] C:\Windows\System32\hgcpl.dll
17:22:47.0920 3820 C:\Windows\System32\hgcpl.dll - ok
17:22:47.0920 3820 [ 32AAEABFF6299834E5D38C3A442CCF36 ] C:\Windows\System32\mssph.dll
17:22:47.0920 3820 C:\Windows\System32\mssph.dll - ok
17:22:47.0935 3820 [ 8BC9DB92C4B2F3BE89185BEAB2AFC1F6 ] C:\Windows\System32\mapi32.dll
17:22:47.0935 3820 C:\Windows\System32\mapi32.dll - ok
17:22:47.0935 3820 ============================================================
17:22:47.0935 3820 Scan finished
17:22:47.0935 3820 ============================================================
17:22:47.0951 3808 Detected object count: 1
17:22:47.0951 3808 Actual detected object count: 1
17:24:03.0284 3808 DrvAgent32 ( UnsignedFile.Multi.Generic ) - skipped by user
17:24:03.0284 3808 DrvAgent32 ( UnsignedFile.Multi.Generic ) - User select action: Skip
17:24:10.0523 3240 Deinitialize success
  • 0

#8
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
Malwarebytes Anti-Malware (Essai) 1.70.0.1100
www.malwarebytes.org

Version de la base de données: v2013.02.19.05

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 8.0.7601.17514
phil :: PHIL-PC [administrateur]

Protection: Activé

19/02/2013 17:27:02
mbam-log-2013-02-19 (17-27-02).txt

Type d'examen: Examen rapide
Options d'examen activées: Mémoire | Démarrage | Registre | Système de fichiers | Heuristique/Extra | Heuristique/Shuriken | PUP | PUM
Options d'examen désactivées: P2P
Elément(s) analysé(s): 208385
Temps écoulé: 4 minute(s), 51 seconde(s)

Processus mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Module(s) mémoire détecté(s): 0
(Aucun élément nuisible détecté)

Clé(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Valeur(s) du Registre détectée(s): 0
(Aucun élément nuisible détecté)

Elément(s) de données du Registre détecté(s): 0
(Aucun élément nuisible détecté)

Dossier(s) détecté(s): 0
(Aucun élément nuisible détecté)

Fichier(s) détecté(s): 0
(Aucun élément nuisible détecté)

(fin)
  • 0

#9
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
# AdwCleaner v2.112 - Rapport créé le 19/02/2013 à 17:32:57
# Mis à jour le 10/02/2013 par Xplode
# Système d'exploitation : Windows 7 Professional Service Pack 1 (32 bits)
# Nom d'utilisateur : phil - PHIL-PC
# Mode de démarrage : Normal
# Exécuté depuis : C:\Users\phil\Desktop\adwcleaner0.exe
# Option [Suppression]


***** [Services] *****


***** [Fichiers / Dossiers] *****

Dossier Supprimé : C:\ProgramData\Babylon
Dossier Supprimé : C:\Users\phil\AppData\Local\Babylon
Dossier Supprimé : C:\Users\phil\AppData\Roaming\Babylon
Fichier Supprimé : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml

***** [Registre] *****

Clé Supprimée : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Clé Supprimée : HKLM\Software\Babylon
Clé Supprimée : HKLM\Software\BabylonToolbar
Clé Supprimée : HKLM\SOFTWARE\Classes\Prod.cap

***** [Navigateurs] *****

-\\ Internet Explorer v8.0.7601.17514

Remplacé : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.babylon.com/?affID=14335&babsrc=HP_ss&mntrId=e0e0a82200000000000000226972a432 --> hxxp://www.google.com
Remplacé : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://search.babylon.com/?affID=14335&babsrc=NT_ss&mntrId=e0e0a82200000000000000226972a432 --> hxxp://www.google.com

-\\ Mozilla Firefox v18.0.2 (fr)

Fichier : C:\Users\phil\AppData\Roaming\Mozilla\Firefox\Profiles\yfysizgh.default\prefs.js

[OK] Le fichier ne contient aucune entrée illégitime.

*************************

AdwCleaner[S1].txt - [1580 octets] - [19/02/2013 17:32:57]

########## EOF - C:\AdwCleaner[S1].txt - [1640 octets] ##########
  • 0

#10
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
Vino's Event Viewer v01c run on Windows 2008 in French
Report run at 19/02/2013 17:53:24

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Erreur Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/02/2013 16:51:00
Type: Erreur Category: 0
Event: 20 Source: Microsoft-Windows-WHEA-Logger
Une erreur matérielle irrécupérable s’est produite. Composant : AMD Northbridge Source de l’erreur : Exception de vérification d’ordinateur Type d’erreur : 11 ID du processeur : 0 Pour plus d’informations, consultez les détails de cette entrée.

Log: 'System' Date/Time: 19/02/2013 16:50:56
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 16:49:05
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 16:35:23
Type: Erreur Category: 0
Event: 20 Source: Microsoft-Windows-WHEA-Logger
Une erreur matérielle irrécupérable s’est produite. Composant : AMD Northbridge Source de l’erreur : Exception de vérification d’ordinateur Type d’erreur : 11 ID du processeur : 0 Pour plus d’informations, consultez les détails de cette entrée.

Log: 'System' Date/Time: 19/02/2013 16:35:16
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 16:35:11
Type: Erreur Category: 0
Event: 45 Source: volmgr
Le système n'a pas pu charger le pilote du fichier de vidage sur incident.

Log: 'System' Date/Time: 19/02/2013 16:34:36
Type: Erreur Category: 0
Event: 45 Source: volmgr
Le système n'a pas pu charger le pilote du fichier de vidage sur incident.

Log: 'System' Date/Time: 19/02/2013 16:33:23
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 16:20:36
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 16:20:30
Type: Erreur Category: 0
Event: 45 Source: volmgr
Le système n'a pas pu charger le pilote du fichier de vidage sur incident.

Log: 'System' Date/Time: 19/02/2013 16:19:53
Type: Erreur Category: 0
Event: 45 Source: volmgr
Le système n'a pas pu charger le pilote du fichier de vidage sur incident.

Log: 'System' Date/Time: 19/02/2013 16:14:38
Type: Erreur Category: 0
Event: 7030 Source: Service Control Manager
Le service PEVSystemStart est marqué comme étant interactif. Cependant, le système est configuré pour ne pas autoriser les services interactifs. Ce service peut ne pas fonctionner correctement.

Log: 'System' Date/Time: 19/02/2013 16:11:46
Type: Erreur Category: 0
Event: 7030 Source: Service Control Manager
Le service PEVSystemStart est marqué comme étant interactif. Cependant, le système est configuré pour ne pas autoriser les services interactifs. Ce service peut ne pas fonctionner correctement.

Log: 'System' Date/Time: 19/02/2013 16:09:27
Type: Erreur Category: 0
Event: 7030 Source: Service Control Manager
Le service PEVSystemStart est marqué comme étant interactif. Cependant, le système est configuré pour ne pas autoriser les services interactifs. Ce service peut ne pas fonctionner correctement.

Log: 'System' Date/Time: 19/02/2013 14:48:49
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 14:48:43
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 14:48:38
Type: Erreur Category: 0
Event: 45 Source: volmgr
Le système n'a pas pu charger le pilote du fichier de vidage sur incident.

Log: 'System' Date/Time: 19/02/2013 14:48:04
Type: Erreur Category: 0
Event: 45 Source: volmgr
Le système n'a pas pu charger le pilote du fichier de vidage sur incident.

Log: 'System' Date/Time: 19/02/2013 14:46:47
Type: Erreur Category: 0
Event: 7006 Source: Service Control Manager
L’appel ScRegSetValueExW a échoué pour FailureActions avec l’erreur : Accès refusé.

Log: 'System' Date/Time: 19/02/2013 13:52:59
Type: Erreur Category: 0
Event: 20 Source: Microsoft-Windows-WHEA-Logger
Une erreur matérielle irrécupérable s’est produite. Composant : AMD Northbridge Source de l’erreur : Exception de vérification d’ordinateur Type d’erreur : 11 ID du processeur : 0 Pour plus d’informations, consultez les détails de cette entrée.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Avertissement Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 19/02/2013 16:52:14
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 0 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 11 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 16:52:14
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 1 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 11 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 16:49:07
Type: Avertissement Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Log: 'System' Date/Time: 19/02/2013 16:36:31
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 0 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 13 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 16:36:31
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 1 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 13 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 16:33:26
Type: Avertissement Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Log: 'System' Date/Time: 19/02/2013 16:21:48
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 0 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 13 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 16:21:48
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 1 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 13 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 16:18:42
Type: Avertissement Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Log: 'System' Date/Time: 19/02/2013 14:46:49
Type: Avertissement Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Log: 'System' Date/Time: 19/02/2013 14:32:40
Type: Avertissement Category: 0
Event: 1014 Source: Microsoft-Windows-DNS-Client
La résolution du nom update.avg.com a expiré lorsqu’aucun des serveurs DNS configurés n’a répondu.

Log: 'System' Date/Time: 19/02/2013 14:24:49
Type: Avertissement Category: 0
Event: 54 Source: TrueSight
The event description cannot be found.

Log: 'System' Date/Time: 19/02/2013 14:23:29
Type: Avertissement Category: 0
Event: 54 Source: TrueSight
The event description cannot be found.

Log: 'System' Date/Time: 19/02/2013 13:38:42
Type: Avertissement Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Log: 'System' Date/Time: 19/02/2013 13:34:11
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 0 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 32 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 13:34:11
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 1 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 32 secondes depuis le dernier rapport.

Log: 'System' Date/Time: 19/02/2013 13:31:19
Type: Avertissement Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
Le Service d’autoconfiguration WLAN s’est arrêté correctement.

Log: 'System' Date/Time: 19/02/2013 13:26:10
Type: Avertissement Category: 0
Event: 54 Source: TrueSight
The event description cannot be found.

Log: 'System' Date/Time: 19/02/2013 13:23:56
Type: Avertissement Category: 0
Event: 54 Source: TrueSight
The event description cannot be found.

Log: 'System' Date/Time: 19/02/2013 13:09:16
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 0 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 24 secondes depuis le dernier rapport.
  • 0

#11
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
Farbar Service Scanner Version: 18-02-2013
Ran by phil (administrator) on 19-02-2013 at 17:55:51
Running from "C:\Users\phil\Desktop"
Windows 7 Professional Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Attempt to access Google IP returned error. Google IP is offline
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll
[2010-11-20 22:29] - [2010-11-20 22:29] - 0132608 ____A (Microsoft Corporation) 2FE30D71919C51131405797620E0A714

C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\ipnathlp.dll => MD5 is legit
C:\Windows\system32\iphlpsvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****
  • 0

#12
Sangoino

Sangoino

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
The ventilator makes a lot of noise, I dont know why ..
  • 0

#13
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,598 posts
  • MVP
No malware that I can see other than the Babylon adware.

I would say the thing is overheating. That's usually what this error means:

Log: 'System' Date/Time: 19/02/2013 16:52:14
Type: Avertissement Category: 7
Event: 37 Source: Microsoft-Windows-Kernel-Processor-Power
La vitesse du processeur 0 du groupe 0 est limitée par le microprogramme du système. Le processeur a connu cet état de performances réduites pendant 11 secondes depuis le dernier rapport.


That the fan is making a lot of noise is another sign of overheating. You can verify the overheating by getting Speedfan.

http://www.almico.com/sfdownload.php

Download, save and Install it (Win 7 or Vista right click and Run As Admin.) then run it.

It will tell you your temperatures. I'm pretty sure they will be much higher than 50. Make sure you are not blocking any vents. (Laptops most be on a hard servface and not on a lap or on the bed.) You probably need to open it up and vacuum out all of the dust. If that doesn't help, you may need to replace the fan. Is this a laptop or a desktop?
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP