Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Persistent trojan - can't seem to shake the little.... [Solved]


  • This topic is locked This topic is locked

#1
chrisg6152

chrisg6152

    Member

  • Member
  • PipPipPip
  • 102 posts
Hi and thank you in advance for looking at my problem.

I am running Windows XP Pro with MS Security Essentials and ZoneAlarm firewall. I appear to be having a problem with a trojan that I can't seem to shake.

I first noticed that something was amiss when I started up my PC and MS Security Essentials gave a warning that it couldn't load as part of the program was missing so I uninstalled it and the installed again.

I then ran a quick scan and a couple of trojans were identified and removed. I then ran Malwarebytes Anti-malware and it too identified a trojan. Having removed the offending items I restarted the PC and ran the scans again and both came up clean.

All was fine until a couple of days later and the same thing happened again.

I have included an OTL log - could you possibly see if there is anything amiss?

Many thanks in advance

Chris G

OTL logfile created on: 05/04/2013 16:36:42 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

1.99 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.68% Memory free
3.84 Gb Paging File | 2.65 Gb Available in Paging File | 69.03% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 52.70 Gb Total Space | 9.89 Gb Free Space | 18.77% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 301.16 Gb Free Space | 64.66% Space Free | Partition Type: NTFS
Drive E: | 18.61 Gb Total Space | 18.53 Gb Free Space | 99.60% Space Free | Partition Type: NTFS

Computer Name: MAINCOMP-364806 | User Name: Chris Clair | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/04/05 16:24:29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\Downloads\OTL.exe
PRC - [2013/02/12 11:43:56 | 000,248,208 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2013/02/12 11:43:56 | 000,093,072 | ---- | M] (TomTom) -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2013/01/27 11:11:46 | 000,284,304 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MpCmdRun.exe
PRC - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2013/01/27 11:11:06 | 000,947,152 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2013/01/02 15:10:28 | 002,448,032 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
PRC - [2013/01/02 14:38:50 | 000,073,984 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
PRC - [2012/12/16 19:08:29 | 000,161,768 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2012/11/22 15:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
PRC - [2012/07/03 10:04:58 | 000,507,312 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe
PRC - [2010/07/30 17:12:54 | 002,195,824 | ---- | M] (GFI Software Ltd.) -- C:\Program Files\GFI\GFI Backup 2009 - Home Edition\GFIAgent.exe
PRC - [2010/07/30 17:12:52 | 000,858,480 | ---- | M] (GFI Software Ltd.) -- C:\Program Files\GFI\GFI Backup 2009 - Home Edition\GFIHInst.exe
PRC - [2010/07/30 17:12:50 | 002,324,848 | ---- | M] (GFI Software Ltd.) -- C:\Program Files\GFI\GFI Backup 2009 - Home Edition\GFIHSched.exe
PRC - [2010/07/04 20:13:56 | 000,095,576 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
PRC - [2010/07/04 20:07:40 | 000,238,952 | ---- | M] (Teruten) -- C:\WINDOWS\system32\FsUsbExService.Exe
PRC - [2010/05/12 18:04:48 | 000,599,480 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\wfcrun32.exe
PRC - [2010/05/12 18:03:22 | 000,300,472 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\Citrix\ICA Client\concentr.exe
PRC - [2010/01/13 04:07:52 | 001,638,400 | ---- | M] (Edimax Technology Co.) -- C:\Program Files\Edimax\Common\RaUI.exe
PRC - [2009/12/17 07:49:00 | 000,185,632 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files\Edimax\Common\RaRegistry.exe
PRC - [2008/04/14 13:00:00 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/14 13:00:00 | 000,056,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\sol.exe
PRC - [2008/04/14 06:42:30 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Outlook Express\msimn.exe
PRC - [2007/11/26 15:47:40 | 000,598,856 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Washer\WasherSvc.exe
PRC - [2007/11/26 15:47:30 | 001,206,600 | ---- | M] (Webroot Software, Inc.) -- C:\Program Files\Webroot\Washer\wwDisp.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/02 00:26:32 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/11/02 00:26:12 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/17 01:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 16:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/10/07 02:35:32 | 000,901,120 | ---- | M] () -- C:\Program Files\Edimax\Common\RaWLAPI.dll
MOD - [2009/10/06 12:57:48 | 000,147,456 | ---- | M] () -- C:\WINDOWS\system32\DiagFunc.dll
MOD - [2007/11/26 15:47:34 | 000,038,216 | ---- | M] () -- C:\Program Files\Webroot\Washer\Languages\English.dll


========== Services (SafeList) ==========

SRV - [2013/04/04 09:07:29 | 000,253,656 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/02/12 11:43:56 | 000,093,072 | ---- | M] (TomTom) [Auto | Running] -- C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe -- (TomTomHOMEService)
SRV - [2013/01/27 11:11:46 | 000,020,456 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2013/01/02 15:10:28 | 002,448,032 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe -- (vsmon)
SRV - [2012/12/16 19:08:29 | 000,161,768 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/11/22 15:33:18 | 000,497,320 | ---- | M] (Check Point Software Technologies) [Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe -- (IswSvc)
SRV - [2012/09/20 14:28:48 | 030,785,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/07/30 17:12:52 | 000,858,480 | ---- | M] (GFI Software Ltd.) [Auto | Running] -- C:\Program Files\GFI\GFI Backup 2009 - Home Edition\GFIHInst.exe -- (GFIBckHAtt)
SRV - [2010/07/30 17:12:50 | 002,324,848 | ---- | M] (GFI Software Ltd.) [Auto | Running] -- C:\Program Files\GFI\GFI Backup 2009 - Home Edition\GFIHSched.exe -- (GFIBckHSched)
SRV - [2010/07/04 20:07:40 | 000,238,952 | ---- | M] (Teruten) [Auto | Running] -- C:\WINDOWS\system32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2009/12/17 07:49:00 | 000,185,632 | ---- | M] (Ralink Technology, Corp.) [Auto | Running] -- C:\Program Files\Edimax\Common\RaRegistry.exe -- (RalinkRegistryWriter)
SRV - [2007/11/26 15:47:40 | 000,598,856 | ---- | M] (Webroot Software, Inc.) [Auto | Running] -- C:\Program Files\Webroot\Washer\WasherSvc.exe -- (wwEngineSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2013/04/05 16:20:56 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{534D87AD-D447-4779-8178-AD91F136C556}\MpKslec2dc354.sys -- (MpKslec2dc354)
DRV - [2013/01/02 14:38:52 | 000,528,000 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\vsdatant.sys -- (Vsdatant)
DRV - [2012/11/22 15:33:30 | 000,027,056 | ---- | M] (Check Point Software Technologies) [Kernel | Auto | Running] -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (ISWKL)
DRV - [2010/06/14 10:32:54 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/11/26 16:49:54 | 001,197,312 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2860.sys -- (RT80x86)
DRV - [2009/10/06 12:57:48 | 000,019,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Scutum50.sys -- (Scutum50)
DRV - [2009/10/05 11:08:42 | 000,065,584 | ---- | M] (Citrix Systems, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ctxusbm.sys -- (ctxusbm)
DRV - [2006/11/02 08:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2006/02/10 13:19:12 | 001,107,224 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{1B598576-DD78-4AEA-9731-7FB92C2E543B}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.talktalk.co.uk/
IE - HKCU\..\SearchScopes,DefaultScope = {1B598576-DD78-4AEA-9731-7FB92C2E543B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\..\SearchScopes\{1B598576-DD78-4AEA-9731-7FB92C2E543B}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\..\SearchScopes\{75717B20-C780-42D9-8BAD-CB287238F5A6}: "URL" = http://websearch.ask...70-F257A6F67A40
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2013/01/22 08:26:06 | 000,000,000 | ---D | M]

[2013/02/22 16:39:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\Mozilla\Extensions
[2013/02/22 16:39:52 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\Mozilla\Extensions\[email protected]

Hosts file not found
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [ISW] File not found
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe File not found
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKCU..\Run: [GFI Backup 2009 - Home Edition] C:\Program Files\GFI\GFI Backup 2009 - Home Edition\GFIAgent.exe (GFI Software Ltd.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe (Webroot Software, Inc.)
O4 - Startup: C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup\Wireless Utility.lnk = C:\Program Files\Edimax\Common\RaUI.exe (Edimax Technology Co.)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51BFF88B-287E-43C7-A3A0-050FA66A1E24}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/10 13:04:08 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/04/04 18:00:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2013/03/23 12:56:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\CSC
[2013/03/20 14:04:46 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Recent
[2013/03/19 14:49:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\iTunes
[2013/03/19 14:48:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/03/13 20:36:53 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/05 16:35:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/04/05 16:19:15 | 000,000,366 | -H-- | M] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2013/04/05 15:41:01 | 000,000,896 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/05 15:03:30 | 000,000,384 | -H-- | M] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/04/05 14:55:15 | 000,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/04/05 14:53:30 | 000,000,892 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/05 14:53:12 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/04/05 09:18:30 | 000,002,057 | ---- | M] () -- C:\WINDOWS\epplauncher.mif
[2013/04/05 09:15:16 | 000,436,316 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/04/05 09:15:16 | 000,068,828 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/04/04 12:28:22 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/04/01 09:48:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2013/03/27 20:22:41 | 002,777,088 | ---- | M] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\assignment 201meg.wps
[2013/03/19 14:49:26 | 000,001,542 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2013/03/18 18:19:24 | 003,169,622 | ---- | M] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\Toshiba C660 Manual.pdf
[2013/03/13 21:21:23 | 008,043,008 | ---- | M] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\megs floristry work do not lose xx.wps
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/05 09:30:58 | 000,000,366 | -H-- | C] () -- C:\WINDOWS\tasks\MpIdleTask.job
[2013/04/04 18:26:43 | 000,000,384 | -H-- | C] () -- C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2013/04/04 18:00:25 | 000,001,698 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Microsoft Security Essentials.lnk
[2013/03/27 20:22:38 | 002,777,088 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\assignment 201meg.wps
[2013/03/19 14:49:26 | 000,001,542 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2013/03/18 18:19:24 | 003,169,622 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\Toshiba C660 Manual.pdf
[2013/03/13 21:21:22 | 008,043,008 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\My Documents\megs floristry work do not lose xx.wps
[2012/12/16 19:17:23 | 000,000,085 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\jagex_cl_loginapplet_LIVE.dat
[2012/12/16 19:09:49 | 000,000,083 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\jagex_cl_runescape_LIVE.dat
[2012/12/16 19:09:49 | 000,000,024 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\random.dat
[2012/11/28 15:17:18 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2012/11/28 15:17:18 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012/11/28 15:17:18 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012/11/28 15:17:18 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012/02/16 10:54:16 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/02/09 19:04:43 | 000,001,191 | ---- | C] () -- C:\WINDOWS\System32\W32N55.INI
[2012/02/09 19:04:43 | 000,000,480 | ---- | C] () -- C:\WINDOWS\System32\DiagFunc.ini
[2012/02/09 19:04:42 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\DiagFunc.dll
[2012/02/09 19:04:01 | 000,013,931 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2012/01/31 20:42:29 | 000,160,482 | ---- | C] () -- C:\WINDOWS\hpoins27.dat
[2012/01/31 20:42:29 | 000,000,932 | ---- | C] () -- C:\WINDOWS\hpomdl27.dat
[2012/01/27 19:45:21 | 000,010,752 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/25 16:54:14 | 000,063,140 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2012/01/22 11:21:33 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2012/01/15 19:04:12 | 000,110,592 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDevice.Dll
[2012/01/15 19:04:12 | 000,036,608 | ---- | C] () -- C:\WINDOWS\System32\FsUsbExDisk.Sys
[2012/01/15 19:04:04 | 000,002,528 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\$_hpcst$.hpc
[2012/01/14 17:37:26 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2012/01/14 16:44:55 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Ÿ9Ÿ9
[2012/01/13 16:41:41 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2012/01/13 16:35:46 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2012/01/13 16:11:21 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2012/01/13 16:10:02 | 000,294,072 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT

========== ZeroAccess Check ==========

[2013/04/04 09:01:35 | 000,000,000 | -HSD | M] -- C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L
[2013/04/05 16:36:27 | 000,000,000 | -HSD | M] -- C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\U
[2013/04/04 08:49:08 | 000,000,804 | ---- | M] () -- C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L\00000004.@
[2012/01/16 20:40:22 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
"ThreadingModel" = Both
"" = shell32.dll -- [2012/06/08 15:26:20 | 008,462,848 | ---- | M] (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/11/01 21:35:20 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = fastprox.dll -- [2009/02/09 13:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/14 13:00:00 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/03/19 14:49:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/12/16 19:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Ask
[2012/01/13 17:57:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\CheckPoint
[2012/01/15 14:47:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Citrix
[2013/02/27 19:53:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Driving Test Success
[2012/02/09 19:03:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Edimax Driver
[2013/01/22 08:26:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Samsung
[2012/01/14 17:36:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/05/04 18:00:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\Audacity
[2012/06/04 09:39:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\CheckPoint
[2012/12/19 17:14:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoft
[2012/09/18 11:12:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers
[2012/01/15 15:02:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\ICAClient
[2012/08/06 15:46:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\ML
[2012/09/03 13:57:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\OpenCandy
[2012/05/29 20:38:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\pdfforge
[2013/01/22 08:26:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\Samsung
[2012/12/19 20:47:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\searchresultstb
[2012/01/27 16:20:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\Serif
[2012/12/19 20:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\TFP
[2013/02/22 16:39:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\TomTom
[2013/02/02 18:50:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\Unity

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#2
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello chrisg6152

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.


Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!


  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.




These are the programs I would like you to run next, if you have any problems with these just skip it and run the next one.

-Security Check-

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

-AdwCleaner-

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.


--RogueKiller--

  • Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+

Gringo
  • 0

#3
chrisg6152

chrisg6152

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
Hi Gringo

Many thanks for the expedient reply!

I have run the 3 scans as requested and have pasted the logs below. (For some reason Rogue Killer appears to have produced 2 logs - I have enclosed both)

For info - the PC booted up OK this morning, MS Security Essentials started without any issues.

Regards

Chris G

*********************************************

Results of screen317's Security Check version 0.99.62
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Security Center service is not running! This report may not be accurate!
Please wait while WMIC compiles updated MOF files.d
i
s
p
l
a
y
N
a
m
e
ECHO is off.
M
i
c
r
o
s
o
f
t
ECHO is off.
S
e
c
u
r
i
t
y
ECHO is off.
E
s
e
n
t
i
a
l
s
ECHO is off.
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.70.0.1100
CCleaner
Java 7 Update 9
Java version out of Date!
Adobe Flash Player 11.6.602.180
Adobe Reader 9 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
CheckPoint ZoneAlarm vsmon.exe
CheckPoint ZoneAlarm zatray.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 21% Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````


_______________________________________________________________________________________

# AdwCleaner v2.200 - Logfile created 04/06/2013 at 10:32:39
# Updated 02/04/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Chris Clair - MAINCOMP-364806
# Boot Mode : Normal
# Running from : C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Documents and Settings\All Users.WINDOWS\Application Data\Ask
Folder Deleted : C:\Program Files\Viewpoint

***** [Registry] *****

Key Deleted : HKCU\Software\DataMngr
Key Deleted : HKCU\Software\DataMngr_Toolbar
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{79A765E1-C399-405B-85AF-466F52E918B0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\iLividSRTB
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0E12F736682067FDE4D1158D5940A82E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1A24B5BB8521B03E0C8D908F5ABC0AE6
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2B0D56C4F4C46D844A57FFED6F0D2852
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\49D4375FE41653242AEA4C969E4E65E0
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6AA0923513360135B272E8289C5F13FA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6F7467AF8F29C134CBBAB394ECCFDE96
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\922525DCC5199162F8935747CA3D8E59
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BCDA179D619B91648538E3394CAC94CC
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D677B1A9671D4D4004F6F2A4469E86EA
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DD1402A9DD4215A43ABDE169A41AFA0E
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\E36E114A0EAD2AD46B381D23AD69CDDF
Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EF8E618DB3AEDFBB384561B5C548F65E
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\conduitEngine
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

*************************

AdwCleaner[S1].txt - [3980 octets] - [06/04/2013 10:32:39]

########## EOF - C:\AdwCleaner[S1].txt - [4040 octets] ##########


RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo...13-roguekiller/
Website : http://tigzy.geeksto...roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Chris Clair [Admin rights]
Mode : Scan -- Date : 04/06/2013 10:39:57
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 1 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\U --> FOUND
[ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-21-343818398-73586283-1644491937-1003\$1fc684a7d7de8ff1a37180b8577b1748\U --> FOUND
[ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L --> FOUND
[ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-21-343818398-73586283-1644491937-1003\$1fc684a7d7de8ff1a37180b8577b1748\L --> FOUND

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: HDS728080PLA380 +++++
--- User ---
[MBR] 3dccddb4f03a07aac55d1396968c8a50
[BSP] ae203e84dcb456630d870d8f3155a2b5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 80325 | Size: 53968 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 110607525 | Size: 19053 Mo
3 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 149629410 | Size: 3223 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1]_S_04062013_02d1039.txt >>
RKreport[1]_S_04062013_02d1039.txt



RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo...13-roguekiller/
Website : http://tigzy.geeksto...roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : Chris Clair [Admin rights]
Mode : Remove -- Date : 04/06/2013 10:41:35
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 1 ¤¤¤
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\U --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-21-343818398-73586283-1644491937-1003\$1fc684a7d7de8ff1a37180b8577b1748\U --> REMOVED
[Del.Parent][FILE] 00000004.@ : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L\00000004.@ [-] --> REMOVED
[Del.Parent][FILE] 201d3dde : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L\201d3dde [-] --> REMOVED
[Del.Parent][FILE] 6715e287 : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L\6715e287 [-] --> REMOVED
[Del.Parent][FILE] 76603ac3 : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L\76603ac3 [-] --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-18\$1fc684a7d7de8ff1a37180b8577b1748\L --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\RECYCLER\S-1-5-21-343818398-73586283-1644491937-1003\$1fc684a7d7de8ff1a37180b8577b1748\L --> REMOVED

¤¤¤ Driver : [LOADED] ¤¤¤

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\WINDOWS\system32\drivers\etc\hosts



¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: HDS728080PLA380 +++++
--- User ---
[MBR] 3dccddb4f03a07aac55d1396968c8a50
[BSP] ae203e84dcb456630d870d8f3155a2b5 : Windows XP MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 80325 | Size: 53968 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 110607525 | Size: 19053 Mo
3 - [XXXXXX] UNKNOWN (0xdb) [VISIBLE] Offset (sectors): 149629410 | Size: 3223 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2]_D_04062013_02d1041.txt >>
RKreport[1]_S_04062013_02d1039.txt ; RKreport[2]_D_04062013_02d1041.txt
  • 0

#4
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello chrisg6152

I Would like you to do the following.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
  • 0

#5
chrisg6152

chrisg6152

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
Hi Gringo

I have managed to run Combofix but not without a couple of problems!

I first tried to run it yesterday afternoon but I had to abort it after it had failed to complete after six hours! I tried again this morning but part way through encountered a 'serious Windows Error' and so the PC shut itself down. Tried again but the program just froze.

I then ran Combofix in Safe Mode which seemed to do the trick - apart from an error message 'PEV.exe has encountered a problem and needs to close' - but it didn't seem to affect the scan.

The log is pasted below.

Regards

Chris G

ComboFix 13-04-06.01 - Chris Clair 07/04/2013 10:13:38.3.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2038.1634 [GMT 1:00]
Running from: c:\documents and settings\Chris Clair.MAINCOMP-364806\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Documents
c:\windows\system32\muzapp.exe
c:\windows\system32\URTTemp
.
.
((((((((((((((((((((((((( Files Created from 2013-03-07 to 2013-04-07 )))))))))))))))))))))))))))))))
.
.
2013-04-05 08:19 . 2013-04-05 08:19 -------- d-----w- c:\windows\system32\wbem\Repository
2013-04-04 17:03 . 2013-03-19 04:50 7108640 ------w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{534D87AD-D447-4779-8178-AD91F136C556}\mpengine.dll
2013-04-04 17:00 . 2013-04-05 08:19 -------- d-----w- c:\program files\Microsoft Security Client
2013-03-23 14:15 . 2013-03-23 14:15 -------- d-sh--w- c:\documents and settings\Administrator.MAINCOMP-364806\PrivacIE
2013-03-23 11:57 . 2013-03-23 11:57 -------- d-----w- c:\documents and settings\Administrator.MAINCOMP-364806\Application Data\Malwarebytes
2013-03-19 13:48 . 2013-03-19 13:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-03-16 16:25 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-03-13 19:36 . 2013-03-13 19:36 -------- d-----w- c:\program files\MSECache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-04 08:07 . 2012-11-29 19:17 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-04 08:07 . 2012-11-29 19:17 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-12 00:10 . 2012-01-13 18:17 237088 ------w- c:\windows\system32\MpSigStub.exe
2013-02-12 00:32 . 2008-04-14 12:00 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-05 20:05 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-01-26 03:55 . 2008-04-14 12:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-20 14:59 . 2013-01-20 14:59 195296 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2007-11-26 1206600]
"GFI Backup 2009 - Home Edition"="c:\progra~1\GFI\GFIBAC~1\GFIAgent.exe" [2010-07-30 2195824]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2013-02-12 248208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2013-01-02 73984]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-05-12 300472]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-12-21 519584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Wireless Utility.lnk - c:\program files\Edimax\Common\RaUI.exe [2012-2-9 1638400]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [05/10/2009 11:08 65584]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [15/01/2012 19:04 238952]
S2 GFIBckHAtt;GFI Backup 2009 - Home Edition Attendant Service;c:\progra~1\GFI\GFIBAC~1\GFIHInst.exe [24/03/2011 14:11 858480]
S2 GFIBckHSched;GFI Backup 2009 - Home Edition Scheduler Service;c:\progra~1\GFI\GFIBAC~1\GFIHSC~1.EXE [24/03/2011 14:11 2324848]
S2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [14/10/2009 14:30 27056]
S2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [14/10/2009 14:30 497320]
S2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [09/02/2012 19:04 19072]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [12/02/2013 11:43 93072]
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [15/01/2012 16:17 598856]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys --> c:\windows\system32\drivers\dgderdrv.sys [?]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [15/01/2012 19:04 36608]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [09/02/2012 19:04 1197312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-29 08:07]
.
2013-04-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 17:57]
.
2013-04-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-04 18:22]
.
2013-04-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-04 18:22]
.
2013-04-07 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 10:11]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.talktalk.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-NPSStartup - (no file)
HKLM-Run-ISW - (no file)
AddRemove-MyFreeCodec - d:\max\Tablet\1.0b beta\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-07 10:30
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2013-04-07 10:33:22
ComboFix-quarantined-files.txt 2013-04-07 09:33
.
Pre-Run: 12,583,714,816 bytes free
Post-Run: 15,139,373,056 bytes free
.
- - End Of File - - F6E8712FF16283AB3BB3F8962C0EDE61
  • 0

#6
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello chrisg6152


I would like you to try and run these next.

TDSSKiller

Please download the latest version of TDSSKiller from here and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
  • Put a checkmark beside loaded modules.
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
  • Click the Start Scan button.
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
  • If malicious objects are found, they will show in the Scan results
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

    Note** this report can be very long - so if the website gives you an error saying it is to long you may attache it

    If the forum still complains about it being to long send me everything that is at the end of the report after where it says

    ==================
    Scan finished
    ==================

and I will see if I want to see the whole report

Malwarebytes Anti-Rootkit

1.Download Malwarebytes Anti-Rootkit
2.Unzip the contents to a folder in a convenient location.
3.Open the folder where the contents were unzipped and run mbar.exe
4.Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
5.Click on the Cleanup button to remove any threats and reboot if prompted to do so.
6.Wait while the system shuts down and the cleanup process is performed.
7.Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
8.If no additional threats were found, verify that your system is now running normally, making sure that the following items are functional:
•Internet access
•Windows Update
•Windows Firewall9.If there are additional problems with your system, such as any of those listed above or other system issues, then run the 'fixdamage' tool included with Malwarebytes Anti-Rootkit and reboot.
10.Verify that your system is now functioning normally.

If you have any problems running either one come back and let me know

please reply with the reports from TDSSKiller and MBAR

Gringo
  • 0

#7
chrisg6152

chrisg6152

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
Hi Gringo

TDSSKiller ran OK - detected 7 mailcious objects but there wasn't an option to 'Cure', just 'Skip'. Finished the scan, rebooted and ran the scan again - nothing detected on the second one. (logs pasted at end of reply)

Malwarebytes Anti-Rootkit ran OK - No threats detected so no cleanup required (log pasted at end of reply)

I have full internet access, firewall and Security Essentials start up OK. The only issue I appear to have now is when I start the PC up, I get a C:\Windows\system32\cmd.exe dialog box in the middle of the screen. Start up stops until I close the box down.

Other than that, eveything seems OK

regards

Chris G

Logs as promised


15:38:52.0343 2648 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
15:38:52.0703 2648 ============================================================
15:38:52.0703 2648 Current date / time: 2013/04/07 15:38:52.0703
15:38:52.0703 2648 SystemInfo:
15:38:52.0703 2648
15:38:52.0703 2648 OS Version: 5.1.2600 ServicePack: 3.0
15:38:52.0703 2648 Product type: Workstation
15:38:52.0703 2648 ComputerName: MAINCOMP-364806
15:38:52.0703 2648 UserName: Chris Clair
15:38:52.0703 2648 Windows directory: C:\WINDOWS
15:38:52.0703 2648 System windows directory: C:\WINDOWS
15:38:52.0703 2648 Processor architecture: Intel x86
15:38:52.0703 2648 Number of processors: 2
15:38:52.0703 2648 Page size: 0x1000
15:38:52.0703 2648 Boot type: Normal boot
15:38:52.0703 2648 ============================================================
15:38:57.0781 2648 BG loaded
15:38:58.0390 2648 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
15:38:58.0437 2648 ============================================================
15:38:58.0437 2648 \Device\Harddisk0\DR0:
15:38:58.0437 2648 MBR partitions:
15:38:58.0437 2648 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x69682E0
15:38:58.0437 2648 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x697BCA5, BlocksNum 0x2536D3D
15:38:58.0437 2648 ============================================================
15:38:58.0500 2648 C: <-> \Device\Harddisk0\DR0\Partition1
15:38:58.0546 2648 E: <-> \Device\Harddisk0\DR0\Partition2
15:38:58.0625 2648 ============================================================
15:38:58.0625 2648 Initialize success
15:38:58.0640 2648 ============================================================
15:40:12.0656 3956 ============================================================
15:40:12.0656 3956 Scan started
15:40:12.0656 3956 Mode: Manual; SigCheck; TDLFS;
15:40:12.0656 3956 ============================================================
15:40:13.0843 3956 ================ Scan system memory ========================
15:40:13.0843 3956 System memory - ok
15:40:13.0843 3956 ================ Scan services =============================
15:40:13.0984 3956 Abiosdsk - ok
15:40:13.0984 3956 abp480n5 - ok
15:40:14.0046 3956 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
15:40:14.0500 3956 ACPI - ok
15:40:14.0546 3956 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
15:40:14.0750 3956 ACPIEC - ok
15:40:14.0828 3956 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
15:40:14.0875 3956 AdobeFlashPlayerUpdateSvc - ok
15:40:14.0875 3956 adpu160m - ok
15:40:14.0921 3956 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
15:40:15.0078 3956 aec - ok
15:40:15.0125 3956 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
15:40:15.0187 3956 AFD - ok
15:40:15.0187 3956 Aha154x - ok
15:40:15.0203 3956 aic78u2 - ok
15:40:15.0203 3956 aic78xx - ok
15:40:15.0250 3956 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
15:40:15.0390 3956 Alerter - ok
15:40:15.0421 3956 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
15:40:15.0500 3956 ALG - ok
15:40:15.0500 3956 AliIde - ok
15:40:15.0515 3956 amsint - ok
15:40:15.0656 3956 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:40:15.0671 3956 Apple Mobile Device - ok
15:40:15.0734 3956 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
15:40:15.0828 3956 AppMgmt - ok
15:40:15.0828 3956 asc - ok
15:40:15.0828 3956 asc3350p - ok
15:40:15.0843 3956 asc3550 - ok
15:40:15.0968 3956 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
15:40:16.0000 3956 aspnet_state - ok
15:40:16.0031 3956 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
15:40:16.0187 3956 AsyncMac - ok
15:40:16.0218 3956 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
15:40:16.0375 3956 atapi - ok
15:40:16.0390 3956 Atdisk - ok
15:40:16.0421 3956 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
15:40:16.0562 3956 Atmarpc - ok
15:40:16.0578 3956 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
15:40:16.0750 3956 AudioSrv - ok
15:40:16.0796 3956 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
15:40:16.0937 3956 audstub - ok
15:40:16.0984 3956 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
15:40:17.0140 3956 Beep - ok
15:40:17.0187 3956 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
15:40:17.0421 3956 BITS - ok
15:40:17.0515 3956 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
15:40:17.0546 3956 Bonjour Service - ok
15:40:17.0593 3956 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
15:40:17.0656 3956 Browser - ok
15:40:17.0796 3956 catchme - ok
15:40:17.0828 3956 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
15:40:18.0031 3956 cbidf2k - ok
15:40:18.0031 3956 cd20xrnt - ok
15:40:18.0093 3956 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
15:40:18.0312 3956 Cdaudio - ok
15:40:18.0343 3956 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
15:40:18.0546 3956 Cdfs - ok
15:40:18.0593 3956 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
15:40:18.0828 3956 Cdrom - ok
15:40:18.0843 3956 Changer - ok
15:40:18.0859 3956 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
15:40:19.0078 3956 CiSvc - ok
15:40:19.0125 3956 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
15:40:19.0359 3956 ClipSrv - ok
15:40:19.0390 3956 [ 7FA87325900183197BC9710D1CE4C9FA ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:40:19.0515 3956 clr_optimization_v2.0.50727_32 - ok
15:40:19.0515 3956 CmdIde - ok
15:40:19.0531 3956 COMSysApp - ok
15:40:19.0546 3956 Cpqarray - ok
15:40:19.0578 3956 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
15:40:19.0828 3956 CryptSvc - ok
15:40:19.0890 3956 [ CB6FF7012BB5D59D7C12350DB795CE1F ] ctxusbm C:\WINDOWS\system32\DRIVERS\ctxusbm.sys
15:40:20.0000 3956 ctxusbm - ok
15:40:20.0000 3956 dac2w2k - ok
15:40:20.0015 3956 dac960nt - ok
15:40:20.0078 3956 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
15:40:20.0171 3956 DcomLaunch - ok
15:40:20.0187 3956 dgderdrv - ok
15:40:20.0250 3956 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
15:40:20.0453 3956 Dhcp - ok
15:40:20.0468 3956 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
15:40:20.0703 3956 Disk - ok
15:40:20.0703 3956 dmadmin - ok
15:40:20.0984 3956 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
15:40:21.0296 3956 dmboot - ok
15:40:21.0359 3956 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
15:40:21.0531 3956 dmio - ok
15:40:21.0546 3956 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
15:40:21.0734 3956 dmload - ok
15:40:21.0781 3956 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
15:40:21.0937 3956 dmserver - ok
15:40:21.0984 3956 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
15:40:22.0187 3956 DMusic - ok
15:40:22.0218 3956 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
15:40:22.0265 3956 Dnscache - ok
15:40:22.0328 3956 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
15:40:22.0500 3956 Dot3svc - ok
15:40:22.0500 3956 dpti2o - ok
15:40:22.0546 3956 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
15:40:22.0765 3956 drmkaud - ok
15:40:22.0812 3956 [ 95974E66D3DE4951D29E28E8BC0B644C ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
15:40:22.0859 3956 E100B - ok
15:40:22.0890 3956 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
15:40:23.0140 3956 EapHost - ok
15:40:23.0171 3956 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
15:40:23.0406 3956 ERSvc - ok
15:40:23.0453 3956 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
15:40:23.0515 3956 Eventlog - ok
15:40:23.0578 3956 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
15:40:23.0656 3956 EventSystem - ok
15:40:23.0750 3956 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
15:40:23.0921 3956 Fastfat - ok
15:40:23.0968 3956 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
15:40:24.0015 3956 FastUserSwitchingCompatibility - ok
15:40:24.0031 3956 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
15:40:24.0187 3956 Fdc - ok
15:40:24.0218 3956 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
15:40:24.0359 3956 Fips - ok
15:40:24.0359 3956 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
15:40:24.0500 3956 Flpydisk - ok
15:40:24.0546 3956 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
15:40:24.0796 3956 FltMgr - ok
15:40:24.0843 3956 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
15:40:24.0875 3956 FontCache3.0.0.0 - ok
15:40:24.0921 3956 [ CBE5F69A5E5B918225F420BA748F3742 ] FsUsbExDisk C:\WINDOWS\system32\FsUsbExDisk.SYS
15:40:24.0937 3956 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
15:40:24.0937 3956 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
15:40:24.0968 3956 [ 96633419F4A1E37ACB89B45EBCCFE001 ] FsUsbExService C:\WINDOWS\system32\FsUsbExService.Exe
15:40:25.0000 3956 FsUsbExService - ok
15:40:25.0031 3956 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
15:40:25.0187 3956 Fs_Rec - ok
15:40:25.0218 3956 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
15:40:25.0375 3956 Ftdisk - ok
15:40:25.0421 3956 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
15:40:25.0437 3956 GEARAspiWDM - ok
15:40:25.0546 3956 [ 94FCCE83CDEE9C8149667110093E701E ] GFIBckHAtt C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe
15:40:25.0593 3956 GFIBckHAtt - ok
15:40:25.0671 3956 [ E95911BD88EF967125724428772FDDD8 ] GFIBckHSched C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE
15:40:25.0750 3956 GFIBckHSched - ok
15:40:25.0796 3956 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
15:40:25.0968 3956 Gpc - ok
15:40:26.0078 3956 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
15:40:26.0093 3956 gupdate - ok
15:40:26.0109 3956 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
15:40:26.0125 3956 gupdatem - ok
15:40:26.0171 3956 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
15:40:26.0187 3956 gusvc - ok
15:40:26.0234 3956 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
15:40:26.0375 3956 HDAudBus - ok
15:40:26.0437 3956 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
15:40:26.0593 3956 helpsvc - ok
15:40:26.0656 3956 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
15:40:26.0796 3956 HidServ - ok
15:40:26.0828 3956 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
15:40:26.0984 3956 hidusb - ok
15:40:27.0031 3956 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
15:40:27.0171 3956 hkmsvc - ok
15:40:27.0187 3956 hpn - ok
15:40:27.0312 3956 [ F50F7984FDD151EDD8A70A8DBD9E2A44 ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
15:40:27.0328 3956 hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning
15:40:27.0328 3956 hpqcxs08 - detected UnsignedFile.Multi.Generic (1)
15:40:27.0328 3956 [ DF446BA625CC441617843E87798CE048 ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
15:40:27.0343 3956 hpqddsvc ( UnsignedFile.Multi.Generic ) - warning
15:40:27.0343 3956 hpqddsvc - detected UnsignedFile.Multi.Generic (1)
15:40:27.0390 3956 [ D03D10F7DED688FECF50F8FBF1EA9B8A ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
15:40:27.0500 3956 HPZid412 - ok
15:40:27.0531 3956 [ 89F41658929393487B6B7D13C8528CE3 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
15:40:27.0562 3956 HPZipr12 - ok
15:40:27.0578 3956 [ ABCB05CCDBF03000354B9553820E39F8 ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
15:40:27.0625 3956 HPZius12 - ok
15:40:27.0671 3956 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
15:40:27.0750 3956 HTTP - ok
15:40:27.0796 3956 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
15:40:27.0953 3956 HTTPFilter - ok
15:40:27.0953 3956 i2omgmt - ok
15:40:27.0968 3956 i2omp - ok
15:40:28.0000 3956 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\drivers\i8042prt.sys
15:40:28.0156 3956 i8042prt - ok
15:40:28.0234 3956 [ 5A8E05F1D5C36ABD58CFFA111EB325EA ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
15:40:28.0312 3956 ialm - ok
15:40:28.0437 3956 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
15:40:28.0500 3956 idsvc - ok
15:40:28.0531 3956 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
15:40:28.0671 3956 Imapi - ok
15:40:28.0718 3956 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
15:40:28.0875 3956 ImapiService - ok
15:40:28.0875 3956 ini910u - ok
15:40:28.0921 3956 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
15:40:29.0046 3956 IntelIde - ok
15:40:29.0093 3956 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
15:40:29.0218 3956 intelppm - ok
15:40:29.0234 3956 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
15:40:29.0375 3956 Ip6Fw - ok
15:40:29.0421 3956 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
15:40:29.0578 3956 IpFilterDriver - ok
15:40:29.0640 3956 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
15:40:32.0328 3956 IpInIp - ok
15:40:32.0359 3956 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
15:40:32.0515 3956 IpNat - ok
15:40:32.0578 3956 [ E46B17060D3962A384AE484094614788 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
15:40:32.0625 3956 iPod Service - ok
15:40:32.0687 3956 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
15:40:32.0843 3956 IPSec - ok
15:40:32.0859 3956 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
15:40:32.0921 3956 IRENUM - ok
15:40:32.0953 3956 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
15:40:33.0093 3956 isapnp - ok
15:40:33.0171 3956 [ 724A6A9AB5E1807665C5DB71C30BFC5F ] ISWKL C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
15:40:33.0187 3956 ISWKL - ok
15:40:33.0218 3956 [ 57FE873B8246DEF1372503CBC57A7499 ] IswSvc C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
15:40:33.0250 3956 IswSvc - ok
15:40:33.0375 3956 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
15:40:33.0390 3956 JavaQuickStarterService - ok
15:40:33.0437 3956 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
15:40:33.0578 3956 Kbdclass - ok
15:40:33.0609 3956 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
15:40:33.0750 3956 kbdhid - ok
15:40:33.0781 3956 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
15:40:33.0937 3956 kmixer - ok
15:40:33.0968 3956 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
15:40:34.0093 3956 KSecDD - ok
15:40:34.0156 3956 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
15:40:34.0234 3956 LanmanServer - ok
15:40:34.0281 3956 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
15:40:34.0359 3956 lanmanworkstation - ok
15:40:34.0359 3956 lbrtfdc - ok
15:40:34.0421 3956 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
15:40:34.0578 3956 LmHosts - ok
15:40:34.0593 3956 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
15:40:34.0765 3956 Messenger - ok
15:40:34.0875 3956 Microsoft SharePoint Workspace Audit Service - ok
15:40:34.0906 3956 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
15:40:35.0062 3956 mnmdd - ok
15:40:35.0078 3956 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
15:40:35.0234 3956 mnmsrvc - ok
15:40:35.0265 3956 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
15:40:35.0406 3956 Modem - ok
15:40:35.0437 3956 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
15:40:35.0593 3956 Mouclass - ok
15:40:35.0625 3956 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
15:40:35.0765 3956 mouhid - ok
15:40:35.0796 3956 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
15:40:35.0953 3956 MountMgr - ok
15:40:36.0000 3956 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys
15:40:36.0031 3956 MpFilter - ok
15:40:36.0031 3956 mraid35x - ok
15:40:36.0062 3956 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
15:40:36.0218 3956 MRxDAV - ok
15:40:36.0265 3956 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
15:40:36.0343 3956 MRxSmb - ok
15:40:36.0375 3956 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
15:40:36.0515 3956 MSDTC - ok
15:40:36.0531 3956 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
15:40:36.0671 3956 Msfs - ok
15:40:36.0687 3956 MSIServer - ok
15:40:36.0718 3956 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
15:40:36.0859 3956 MSKSSRV - ok
15:40:36.0921 3956 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
15:40:36.0937 3956 MsMpSvc - ok
15:40:36.0968 3956 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
15:40:37.0125 3956 MSPCLOCK - ok
15:40:37.0125 3956 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
15:40:37.0265 3956 MSPQM - ok
15:40:37.0296 3956 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
15:40:37.0437 3956 mssmbios - ok
15:40:37.0484 3956 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
15:40:37.0515 3956 Mup - ok
15:40:37.0578 3956 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
15:40:37.0718 3956 napagent - ok
15:40:37.0734 3956 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
15:40:37.0859 3956 NDIS - ok
15:40:37.0906 3956 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
15:40:37.0968 3956 NdisTapi - ok
15:40:38.0015 3956 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
15:40:38.0171 3956 Ndisuio - ok
15:40:38.0203 3956 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
15:40:38.0343 3956 NdisWan - ok
15:40:38.0390 3956 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
15:40:38.0421 3956 NDProxy - ok
15:40:38.0468 3956 [ 51C6D8BFBD4EA5B62A1BA7F4469250D3 ] Net Driver HPZ12 C:\WINDOWS\system32\HPZinw12.dll
15:40:38.0484 3956 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
15:40:38.0484 3956 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
15:40:38.0515 3956 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
15:40:38.0656 3956 NetBIOS - ok
15:40:38.0671 3956 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
15:40:38.0812 3956 NetBT - ok
15:40:38.0859 3956 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
15:40:38.0984 3956 NetDDE - ok
15:40:39.0000 3956 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
15:40:39.0140 3956 NetDDEdsdm - ok
15:40:39.0156 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
15:40:39.0296 3956 Netlogon - ok
15:40:39.0328 3956 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
15:40:39.0484 3956 Netman - ok
15:40:39.0515 3956 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:40:39.0531 3956 NetTcpPortSharing - ok
15:40:39.0578 3956 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
15:40:39.0593 3956 Nla - ok
15:40:39.0609 3956 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
15:40:39.0750 3956 Npfs - ok
15:40:39.0812 3956 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
15:40:39.0968 3956 Ntfs - ok
15:40:40.0000 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
15:40:40.0140 3956 NtLmSsp - ok
15:40:40.0203 3956 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
15:40:40.0343 3956 NtmsSvc - ok
15:40:40.0375 3956 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
15:40:40.0515 3956 Null - ok
15:40:40.0562 3956 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
15:40:40.0703 3956 NwlnkFlt - ok
15:40:40.0718 3956 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
15:40:40.0859 3956 NwlnkFwd - ok
15:40:40.0968 3956 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:40:40.0984 3956 ose - ok
15:40:41.0234 3956 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
15:40:41.0406 3956 osppsvc - ok
15:40:41.0453 3956 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
15:40:41.0593 3956 Parport - ok
15:40:41.0625 3956 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
15:40:41.0796 3956 PartMgr - ok
15:40:41.0812 3956 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
15:40:41.0953 3956 ParVdm - ok
15:40:41.0984 3956 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
15:40:42.0125 3956 PCI - ok
15:40:42.0125 3956 PCIDump - ok
15:40:42.0140 3956 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys
15:40:42.0265 3956 PCIIde - ok
15:40:42.0328 3956 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
15:40:42.0468 3956 Pcmcia - ok
15:40:42.0484 3956 PDCOMP - ok
15:40:42.0484 3956 PDFRAME - ok
15:40:42.0500 3956 PDRELI - ok
15:40:42.0500 3956 PDRFRAME - ok
15:40:42.0500 3956 perc2 - ok
15:40:42.0515 3956 perc2hib - ok
15:40:42.0546 3956 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
15:40:42.0578 3956 PlugPlay - ok
15:40:42.0609 3956 [ 79834AA2FBF9FE81EEBB229024F6F7FC ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.dll
15:40:42.0640 3956 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
15:40:42.0640 3956 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
15:40:42.0656 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
15:40:42.0812 3956 PolicyAgent - ok
15:40:42.0812 3956 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
15:40:43.0015 3956 PptpMiniport - ok
15:40:43.0015 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
15:40:43.0171 3956 ProtectedStorage - ok
15:40:43.0171 3956 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
15:40:43.0312 3956 PSched - ok
15:40:43.0328 3956 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
15:40:43.0484 3956 Ptilink - ok
15:40:43.0500 3956 ql1080 - ok
15:40:43.0500 3956 Ql10wnt - ok
15:40:43.0515 3956 ql12160 - ok
15:40:43.0515 3956 ql1240 - ok
15:40:43.0515 3956 ql1280 - ok
15:40:43.0609 3956 [ 720FEA3AAA15FE7E0BEAB10AC2E6D2B0 ] RalinkRegistryWriter C:\Program Files\Edimax\Common\RaRegistry.exe
15:40:43.0625 3956 RalinkRegistryWriter - ok
15:40:43.0640 3956 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
15:40:43.0781 3956 RasAcd - ok
15:40:43.0843 3956 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
15:40:43.0984 3956 RasAuto - ok
15:40:43.0984 3956 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
15:40:44.0109 3956 Rasl2tp - ok
15:40:44.0140 3956 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
15:40:44.0281 3956 RasMan - ok
15:40:44.0281 3956 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
15:40:44.0437 3956 RasPppoe - ok
15:40:44.0453 3956 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
15:40:44.0578 3956 Raspti - ok
15:40:44.0609 3956 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
15:40:44.0781 3956 Rdbss - ok
15:40:44.0796 3956 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
15:40:44.0937 3956 RDPCDD - ok
15:40:44.0984 3956 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
15:40:45.0109 3956 rdpdr - ok
15:40:45.0156 3956 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
15:40:45.0234 3956 RDPWD - ok
15:40:45.0296 3956 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
15:40:45.0437 3956 RDSessMgr - ok
15:40:45.0453 3956 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
15:40:45.0593 3956 redbook - ok
15:40:45.0640 3956 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
15:40:45.0781 3956 RemoteAccess - ok
15:40:45.0812 3956 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
15:40:45.0968 3956 RemoteRegistry - ok
15:40:46.0015 3956 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
15:40:46.0140 3956 RpcLocator - ok
15:40:46.0171 3956 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
15:40:46.0203 3956 RpcSs - ok
15:40:46.0250 3956 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
15:40:46.0375 3956 RSVP - ok
15:40:46.0468 3956 [ F0F38AAEA933DD4F114643FCB5DC1842 ] RT80x86 C:\WINDOWS\system32\DRIVERS\RT2860.sys
15:40:46.0515 3956 RT80x86 ( UnsignedFile.Multi.Generic ) - warning
15:40:46.0515 3956 RT80x86 - detected UnsignedFile.Multi.Generic (1)
15:40:46.0546 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
15:40:46.0687 3956 SamSs - ok
15:40:46.0734 3956 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
15:40:46.0875 3956 SCardSvr - ok
15:40:46.0921 3956 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
15:40:47.0062 3956 Schedule - ok
15:40:47.0109 3956 [ F34C06D1C706A6D9433570B087A18B02 ] Scutum50 C:\WINDOWS\system32\Drivers\Scutum50.sys
15:40:47.0156 3956 Scutum50 ( UnsignedFile.Multi.Generic ) - warning
15:40:47.0156 3956 Scutum50 - detected UnsignedFile.Multi.Generic (1)
15:40:47.0171 3956 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
15:40:47.0250 3956 Secdrv - ok
15:40:47.0281 3956 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
15:40:47.0421 3956 seclogon - ok
15:40:47.0437 3956 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
15:40:47.0578 3956 SENS - ok
15:40:47.0625 3956 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
15:40:47.0765 3956 Serial - ok
15:40:47.0796 3956 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
15:40:47.0937 3956 Sfloppy - ok
15:40:47.0984 3956 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
15:40:48.0140 3956 SharedAccess - ok
15:40:48.0171 3956 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
15:40:48.0187 3956 ShellHWDetection - ok
15:40:48.0203 3956 Simbad - ok
15:40:48.0203 3956 Sparrow - ok
15:40:48.0265 3956 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
15:40:48.0390 3956 splitter - ok
15:40:48.0437 3956 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
15:40:48.0468 3956 Spooler - ok
15:40:48.0515 3956 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
15:40:48.0593 3956 sr - ok
15:40:48.0625 3956 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
15:40:48.0687 3956 srservice - ok
15:40:48.0718 3956 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
15:40:48.0781 3956 Srv - ok
15:40:48.0843 3956 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
15:40:48.0906 3956 SSDPSRV - ok
15:40:48.0984 3956 [ 0AA91BBE468B3F46072091F18003ECAA ] STHDA C:\WINDOWS\system32\drivers\sthda.sys
15:40:49.0046 3956 STHDA - ok
15:40:49.0109 3956 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
15:40:49.0265 3956 stisvc - ok
15:40:49.0281 3956 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
15:40:49.0437 3956 swenum - ok
15:40:49.0468 3956 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
15:40:49.0578 3956 swmidi - ok
15:40:49.0593 3956 SwPrv - ok
15:40:49.0593 3956 symc810 - ok
15:40:49.0609 3956 symc8xx - ok
15:40:49.0609 3956 sym_hi - ok
15:40:49.0625 3956 sym_u3 - ok
15:40:49.0671 3956 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
15:40:49.0828 3956 sysaudio - ok
15:40:49.0859 3956 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
15:40:50.0000 3956 SysmonLog - ok
15:40:50.0062 3956 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
15:40:50.0203 3956 TapiSrv - ok
15:40:50.0234 3956 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
15:40:50.0265 3956 Tcpip - ok
15:40:50.0296 3956 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
15:40:50.0421 3956 TDPIPE - ok
15:40:50.0437 3956 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
15:40:50.0562 3956 TDTCP - ok
15:40:50.0593 3956 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
15:40:50.0750 3956 TermDD - ok
15:40:50.0765 3956 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
15:40:50.0921 3956 TermService - ok
15:40:50.0953 3956 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
15:40:50.0968 3956 Themes - ok
15:40:51.0031 3956 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
15:40:51.0109 3956 TlntSvr - ok
15:40:51.0203 3956 [ A21E58F345F337316A98C5121CBE17E8 ] TomTomHOMEService C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
15:40:51.0218 3956 TomTomHOMEService - ok
15:40:51.0218 3956 TosIde - ok
15:40:51.0234 3956 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
15:40:51.0390 3956 TrkWks - ok
15:40:51.0421 3956 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
15:40:51.0546 3956 Udfs - ok
15:40:51.0562 3956 ultra - ok
15:40:51.0625 3956 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
15:40:51.0765 3956 Update - ok
15:40:51.0828 3956 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
15:40:51.0906 3956 upnphost - ok
15:40:51.0937 3956 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
15:40:52.0078 3956 UPS - ok
15:40:52.0125 3956 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys
15:40:52.0171 3956 USBAAPL - ok
15:40:52.0218 3956 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
15:40:52.0343 3956 usbccgp - ok
15:40:52.0359 3956 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
15:40:52.0500 3956 usbehci - ok
15:40:52.0546 3956 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
15:40:52.0671 3956 usbhub - ok
15:40:52.0687 3956 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
15:40:52.0828 3956 usbprint - ok
15:40:52.0859 3956 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
15:40:53.0015 3956 usbscan - ok
15:40:53.0031 3956 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
15:40:53.0171 3956 usbstor - ok
15:40:53.0203 3956 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
15:40:53.0343 3956 usbuhci - ok
15:40:53.0359 3956 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
15:40:53.0484 3956 VgaSave - ok
15:40:53.0500 3956 ViaIde - ok
15:40:53.0515 3956 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
15:40:53.0640 3956 VolSnap - ok
15:40:53.0703 3956 [ 5C826F02FF76F07B332C764BB9644F27 ] Vsdatant C:\WINDOWS\system32\vsdatant.sys
15:40:53.0734 3956 Vsdatant - ok
15:40:53.0781 3956 vsmon - ok
15:40:53.0859 3956 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
15:40:53.0937 3956 VSS - ok
15:40:53.0984 3956 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
15:40:54.0125 3956 W32Time - ok
15:40:54.0140 3956 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
15:40:54.0265 3956 Wanarp - ok
15:40:54.0328 3956 [ BBCFEAB7E871CDDAC2D397EE7FA91FDC ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys
15:40:54.0359 3956 Wdf01000 - ok
15:40:54.0359 3956 WDICA - ok
15:40:54.0406 3956 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
15:40:54.0546 3956 wdmaud - ok
15:40:54.0578 3956 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
15:40:54.0734 3956 WebClient - ok
15:40:54.0828 3956 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
15:40:54.0953 3956 winmgmt - ok
15:40:55.0000 3956 [ FD600B032E741EB6AAB509FC630F7C42 ] WinUSB C:\WINDOWS\system32\DRIVERS\WinUSB.sys
15:40:55.0031 3956 WinUSB - ok
15:40:55.0046 3956 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
15:40:55.0156 3956 WmdmPmSN - ok
15:40:55.0187 3956 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
15:40:55.0250 3956 Wmi - ok
15:40:55.0281 3956 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
15:40:55.0437 3956 WmiApSrv - ok
15:40:55.0546 3956 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
15:40:55.0593 3956 WMPNetworkSvc - ok
15:40:55.0625 3956 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
15:40:55.0640 3956 WpdUsb - ok
15:40:55.0671 3956 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
15:40:55.0812 3956 WS2IFSL - ok
15:40:55.0843 3956 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
15:40:55.0984 3956 wscsvc - ok
15:40:56.0031 3956 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
15:40:56.0203 3956 wuauserv - ok
15:40:56.0250 3956 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
15:40:56.0296 3956 WudfPf - ok
15:40:56.0328 3956 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
15:40:56.0359 3956 WudfRd - ok
15:40:56.0390 3956 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
15:40:56.0421 3956 WudfSvc - ok
15:40:56.0484 3956 [ BE0B3774113713059527FCF071CCDBFE ] wwEngineSvc C:\Program Files\Webroot\Washer\WasherSvc.exe
15:40:56.0515 3956 wwEngineSvc - ok
15:40:56.0578 3956 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
15:40:56.0750 3956 WZCSVC - ok
15:40:56.0781 3956 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
15:40:56.0968 3956 xmlprov - ok
15:40:56.0968 3956 ================ Scan global ===============================
15:40:57.0015 3956 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
15:40:57.0062 3956 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:40:57.0078 3956 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:40:57.0125 3956 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
15:40:57.0125 3956 [Global] - ok
15:40:57.0125 3956 ================ Scan MBR ==================================
15:40:57.0156 3956 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
15:40:57.0453 3956 \Device\Harddisk0\DR0 - ok
15:40:57.0453 3956 ================ Scan VBR ==================================
15:40:57.0453 3956 [ 9D6139F0B54E5C5428B9446ADDDB5F9E ] \Device\Harddisk0\DR0\Partition1
15:40:57.0453 3956 \Device\Harddisk0\DR0\Partition1 - ok
15:40:57.0468 3956 [ 6C42BEBF2A612522B6AB5F8EBEBDE291 ] \Device\Harddisk0\DR0\Partition2
15:40:57.0468 3956 \Device\Harddisk0\DR0\Partition2 - ok
15:40:57.0468 3956 ================ Scan active images ========================
15:40:57.0468 3956 [ 8C953733D8F36EB2133F5BB58808B66B ] C:\WINDOWS\system32\drivers\intelppm.sys
15:40:57.0468 3956 C:\WINDOWS\system32\drivers\intelppm.sys - ok
15:40:57.0484 3956 [ E28726B72C46821A28830E077D39A55B ] C:\WINDOWS\system32\drivers\videoprt.sys
15:40:57.0484 3956 C:\WINDOWS\system32\drivers\videoprt.sys - ok
15:40:57.0484 3956 [ 5A8E05F1D5C36ABD58CFFA111EB325EA ] C:\WINDOWS\system32\drivers\ialmnt5.sys
15:40:57.0484 3956 C:\WINDOWS\system32\drivers\ialmnt5.sys - ok
15:40:57.0500 3956 [ 573C7D0A32852B48F3058CFD8026F511 ] C:\WINDOWS\system32\drivers\hdaudbus.sys
15:40:57.0500 3956 C:\WINDOWS\system32\drivers\hdaudbus.sys - ok
15:40:57.0500 3956 [ 791912E524CC2CC6F50B5F2B52D1EB71 ] C:\WINDOWS\system32\drivers\usbport.sys
15:40:57.0500 3956 C:\WINDOWS\system32\drivers\usbport.sys - ok
15:40:57.0500 3956 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] C:\WINDOWS\system32\drivers\usbuhci.sys
15:40:57.0500 3956 C:\WINDOWS\system32\drivers\usbuhci.sys - ok
15:40:57.0515 3956 [ F0F38AAEA933DD4F114643FCB5DC1842 ] C:\WINDOWS\system32\drivers\rt2860.sys
15:40:57.0515 3956 C:\WINDOWS\system32\drivers\rt2860.sys - ok
15:40:57.0515 3956 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] C:\WINDOWS\system32\drivers\usbehci.sys
15:40:57.0515 3956 C:\WINDOWS\system32\drivers\usbehci.sys - ok
15:40:57.0515 3956 [ 95974E66D3DE4951D29E28E8BC0B644C ] C:\WINDOWS\system32\drivers\e100b325.sys
15:40:57.0515 3956 C:\WINDOWS\system32\drivers\e100b325.sys - ok
15:40:57.0531 3956 [ 083A052659F5310DD8B6A6CB05EDCF8E ] C:\WINDOWS\system32\drivers\imapi.sys
15:40:57.0531 3956 C:\WINDOWS\system32\drivers\imapi.sys - ok
15:40:57.0531 3956 [ 1F4260CC5B42272D71F79E570A27A4FE ] C:\WINDOWS\system32\drivers\cdrom.sys
15:40:57.0531 3956 C:\WINDOWS\system32\drivers\cdrom.sys - ok
15:40:57.0531 3956 [ 0753515F78DF7F271A5E61C20BCD36A1 ] C:\WINDOWS\system32\drivers\ks.sys
15:40:57.0531 3956 C:\WINDOWS\system32\drivers\ks.sys - ok
15:40:57.0546 3956 [ F828DD7E1419B6653894A8F97A0094C5 ] C:\WINDOWS\system32\drivers\redbook.sys
15:40:57.0546 3956 C:\WINDOWS\system32\drivers\redbook.sys - ok
15:40:57.0546 3956 [ D9F724AA26C010A217C97606B160ED68 ] C:\WINDOWS\system32\drivers\audstub.sys
15:40:57.0546 3956 C:\WINDOWS\system32\drivers\audstub.sys - ok
15:40:57.0546 3956 [ 185ADA973B5020655CEE342059A86CBB ] C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
15:40:57.0546 3956 C:\WINDOWS\system32\drivers\GEARAspiWDM.sys - ok
15:40:57.0562 3956 [ 0109C4F3850DFBAB279542515386AE22 ] C:\WINDOWS\system32\drivers\ndistapi.sys
15:40:57.0562 3956 C:\WINDOWS\system32\drivers\ndistapi.sys - ok
15:40:57.0562 3956 [ EDC1531A49C80614B2CFDA43CA8659AB ] C:\WINDOWS\system32\drivers\ndiswan.sys
15:40:57.0562 3956 C:\WINDOWS\system32\drivers\ndiswan.sys - ok
15:40:57.0562 3956 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] C:\WINDOWS\system32\drivers\rasl2tp.sys
15:40:57.0562 3956 C:\WINDOWS\system32\drivers\rasl2tp.sys - ok
15:40:57.0578 3956 [ 5BC962F2654137C9909C3D4603587DEE ] C:\WINDOWS\system32\drivers\raspppoe.sys
15:40:57.0578 3956 C:\WINDOWS\system32\drivers\raspppoe.sys - ok
15:40:57.0578 3956 [ 0539D5E53587F82D1B4FD74C5BE205CF ] C:\WINDOWS\system32\drivers\tdi.sys
15:40:57.0578 3956 C:\WINDOWS\system32\drivers\tdi.sys - ok
15:40:57.0578 3956 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] C:\WINDOWS\system32\drivers\msgpc.sys
15:40:57.0578 3956 C:\WINDOWS\system32\drivers\msgpc.sys - ok
15:40:57.0593 3956 [ 09298EC810B07E5D582CB3A3F9255424 ] C:\WINDOWS\system32\drivers\psched.sys
15:40:57.0593 3956 C:\WINDOWS\system32\drivers\psched.sys - ok
15:40:57.0593 3956 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] C:\WINDOWS\system32\drivers\raspptp.sys
15:40:57.0593 3956 C:\WINDOWS\system32\drivers\raspptp.sys - ok
15:40:57.0593 3956 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] C:\WINDOWS\system32\drivers\ptilink.sys
15:40:57.0593 3956 C:\WINDOWS\system32\drivers\ptilink.sys - ok
15:40:57.0609 3956 [ FDBB1D60066FCFBB7452FD8F9829B242 ] C:\WINDOWS\system32\drivers\raspti.sys
15:40:57.0609 3956 C:\WINDOWS\system32\drivers\raspti.sys - ok
15:40:57.0609 3956 [ 15CABD0F7C00C47C70124907916AF3F1 ] C:\WINDOWS\system32\drivers\rdpdr.sys
15:40:57.0609 3956 C:\WINDOWS\system32\drivers\rdpdr.sys - ok
15:40:57.0609 3956 [ 463C1EC80CD17420A542B7F36A36F128 ] C:\WINDOWS\system32\drivers\kbdclass.sys
15:40:57.0609 3956 C:\WINDOWS\system32\drivers\kbdclass.sys - ok
15:40:57.0625 3956 [ 88155247177638048422893737429D9E ] C:\WINDOWS\system32\drivers\termdd.sys
15:40:57.0625 3956 C:\WINDOWS\system32\drivers\termdd.sys - ok
15:40:57.0625 3956 [ 35C9E97194C8CFB8430125F8DBC34D04 ] C:\WINDOWS\system32\drivers\mouclass.sys
15:40:57.0625 3956 C:\WINDOWS\system32\drivers\mouclass.sys - ok
15:40:57.0625 3956 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] C:\WINDOWS\system32\drivers\swenum.sys
15:40:57.0625 3956 C:\WINDOWS\system32\drivers\swenum.sys - ok
15:40:57.0640 3956 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] C:\WINDOWS\system32\drivers\update.sys
15:40:57.0640 3956 C:\WINDOWS\system32\drivers\update.sys - ok
15:40:57.0640 3956 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] C:\WINDOWS\system32\drivers\mssmbios.sys
15:40:57.0640 3956 C:\WINDOWS\system32\drivers\mssmbios.sys - ok
15:40:57.0640 3956 [ 9282BD12DFB069D3889EB3FCC1000A9B ] C:\WINDOWS\system32\drivers\ndproxy.sys
15:40:57.0640 3956 C:\WINDOWS\system32\drivers\ndproxy.sys - ok
15:40:57.0656 3956 [ 6CB08593487F5701D2D2254E693EAFCE ] C:\WINDOWS\system32\drivers\drmk.sys
15:40:57.0656 3956 C:\WINDOWS\system32\drivers\drmk.sys - ok
15:40:57.0656 3956 [ E82A496C3961EFC6828B508C310CE98F ] C:\WINDOWS\system32\drivers\portcls.sys
15:40:57.0656 3956 C:\WINDOWS\system32\drivers\portcls.sys - ok
15:40:57.0656 3956 [ 0AA91BBE468B3F46072091F18003ECAA ] C:\WINDOWS\system32\drivers\sthda.sys
15:40:57.0656 3956 C:\WINDOWS\system32\drivers\sthda.sys - ok
15:40:57.0671 3956 [ 596EB39B50D6EBD9B734DC4AE0544693 ] C:\WINDOWS\system32\drivers\usbd.sys
15:40:57.0671 3956 C:\WINDOWS\system32\drivers\usbd.sys - ok
15:40:57.0671 3956 [ 1AB3CDDE553B6E064D2E754EFE20285C ] C:\WINDOWS\system32\drivers\usbhub.sys
15:40:57.0671 3956 C:\WINDOWS\system32\drivers\usbhub.sys - ok
15:40:57.0671 3956 [ C1B486A7658353D33A10CC15211A873B ] C:\WINDOWS\system32\drivers\cdaudio.sys
15:40:57.0671 3956 C:\WINDOWS\system32\drivers\cdaudio.sys - ok
15:40:57.0687 3956 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] C:\WINDOWS\system32\drivers\fdc.sys
15:40:57.0687 3956 C:\WINDOWS\system32\drivers\fdc.sys - ok
15:40:57.0687 3956 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] C:\WINDOWS\system32\drivers\flpydisk.sys
15:40:57.0687 3956 C:\WINDOWS\system32\drivers\flpydisk.sys - ok
15:40:57.0687 3956 [ 8E6B8C671615D126FDC553D1E2DE5562 ] C:\WINDOWS\system32\drivers\sfloppy.sys
15:40:57.0687 3956 C:\WINDOWS\system32\drivers\sfloppy.sys - ok
15:40:57.0703 3956 [ DA1F27D85E0D1525F6621372E7B685E9 ] C:\WINDOWS\system32\drivers\beep.sys
15:40:57.0703 3956 C:\WINDOWS\system32\drivers\beep.sys - ok
15:40:57.0703 3956 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] C:\WINDOWS\system32\drivers\fs_rec.sys
15:40:57.0703 3956 C:\WINDOWS\system32\drivers\fs_rec.sys - ok
15:40:57.0703 3956 [ 96ECCF28FDBF1B2CC12725818A63628D ] C:\WINDOWS\system32\drivers\hidparse.sys
15:40:57.0703 3956 C:\WINDOWS\system32\drivers\hidparse.sys - ok
15:40:57.0718 3956 [ 4A0B06AA8943C1E332520F7440C0AA30 ] C:\WINDOWS\system32\drivers\i8042prt.sys
15:40:57.0718 3956 C:\WINDOWS\system32\drivers\i8042prt.sys - ok
15:40:57.0734 3956 [ 9EF487A186DEA361AA06913A75B3FA99 ] C:\WINDOWS\system32\drivers\kbdhid.sys
15:40:57.0734 3956 C:\WINDOWS\system32\drivers\kbdhid.sys - ok
15:40:57.0734 3956 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] C:\WINDOWS\system32\drivers\null.sys
15:40:57.0734 3956 C:\WINDOWS\system32\drivers\null.sys - ok
15:40:57.0750 3956 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] C:\WINDOWS\system32\drivers\vga.sys
15:40:57.0750 3956 C:\WINDOWS\system32\drivers\vga.sys - ok
15:40:57.0750 3956 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] C:\WINDOWS\system32\drivers\mnmdd.sys
15:40:57.0750 3956 C:\WINDOWS\system32\drivers\mnmdd.sys - ok
15:40:57.0750 3956 [ 4912D5B403614CE99C28420F75353332 ] C:\WINDOWS\system32\drivers\rdpcdd.sys
15:40:57.0750 3956 C:\WINDOWS\system32\drivers\rdpcdd.sys - ok
15:40:57.0765 3956 [ C941EA2454BA8350021D774DAF0F1027 ] C:\WINDOWS\system32\drivers\msfs.sys
15:40:57.0765 3956 C:\WINDOWS\system32\drivers\msfs.sys - ok
15:40:57.0765 3956 [ 3182D64AE053D6FB034F44B6DEF8034A ] C:\WINDOWS\system32\drivers\npfs.sys
15:40:57.0765 3956 C:\WINDOWS\system32\drivers\npfs.sys - ok
15:40:57.0765 3956 [ 23C74D75E36E7158768DD63D92789A91 ] C:\WINDOWS\system32\drivers\ipsec.sys
15:40:57.0765 3956 C:\WINDOWS\system32\drivers\ipsec.sys - ok
15:40:57.0765 3956 [ FE0D99D6F31E4FAD8159F690D68DED9C ] C:\WINDOWS\system32\drivers\rasacd.sys
15:40:57.0765 3956 C:\WINDOWS\system32\drivers\rasacd.sys - ok
15:40:57.0781 3956 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] C:\WINDOWS\system32\drivers\tcpip.sys
15:40:57.0781 3956 C:\WINDOWS\system32\drivers\tcpip.sys - ok
15:40:57.0781 3956 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] C:\WINDOWS\system32\drivers\netbt.sys
15:40:57.0781 3956 C:\WINDOWS\system32\drivers\netbt.sys - ok
15:40:57.0781 3956 [ CC748EA12C6EFFDE940EE98098BF96BB ] C:\WINDOWS\system32\drivers\ipnat.sys
15:40:57.0781 3956 C:\WINDOWS\system32\drivers\ipnat.sys - ok
15:40:57.0796 3956 [ E20B95BAEDB550F32DD489265C1DA1F6 ] C:\WINDOWS\system32\drivers\wanarp.sys
15:40:57.0796 3956 C:\WINDOWS\system32\drivers\wanarp.sys - ok
15:40:57.0796 3956 [ 5C826F02FF76F07B332C764BB9644F27 ] C:\WINDOWS\system32\vsdatant.sys
15:40:57.0796 3956 C:\WINDOWS\system32\vsdatant.sys - ok
15:40:57.0796 3956 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] C:\WINDOWS\system32\drivers\ws2ifsl.sys
15:40:57.0796 3956 C:\WINDOWS\system32\drivers\ws2ifsl.sys - ok
15:40:57.0812 3956 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] C:\WINDOWS\system32\drivers\afd.sys
15:40:57.0812 3956 C:\WINDOWS\system32\drivers\afd.sys - ok
15:40:57.0812 3956 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] C:\WINDOWS\system32\drivers\netbios.sys
15:40:57.0812 3956 C:\WINDOWS\system32\drivers\netbios.sys - ok
15:40:57.0812 3956 [ 7AD224AD1A1437FE28D89CF22B17780A ] C:\WINDOWS\system32\drivers\rdbss.sys
15:40:57.0812 3956 C:\WINDOWS\system32\drivers\rdbss.sys - ok
15:40:57.0828 3956 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] C:\WINDOWS\system32\drivers\mrxsmb.sys
15:40:57.0828 3956 C:\WINDOWS\system32\drivers\mrxsmb.sys - ok
15:40:57.0828 3956 [ D45926117EB9FA946A6AF572FBE1CAA3 ] C:\WINDOWS\system32\drivers\fips.sys
15:40:57.0828 3956 C:\WINDOWS\system32\drivers\fips.sys - ok
15:40:57.0828 3956 [ CB6FF7012BB5D59D7C12350DB795CE1F ] C:\WINDOWS\system32\drivers\ctxusbm.sys
15:40:57.0828 3956 C:\WINDOWS\system32\drivers\ctxusbm.sys - ok
15:40:57.0843 3956 [ F8F0D25CA553E39DDE485D8FC7FCCE89 ] C:\WINDOWS\system32\ntdll.dll
15:40:57.0843 3956 C:\WINDOWS\system32\ntdll.dll - ok
15:40:57.0843 3956 [ 5F816C1F539266D2D4C78694239DA0B5 ] C:\WINDOWS\system32\smss.exe
15:40:57.0843 3956 C:\WINDOWS\system32\smss.exe - ok
15:40:57.0843 3956 [ 23043C91A0F9DFB4B9E9F87B680863B4 ] C:\WINDOWS\system32\autochk.exe
15:40:57.0843 3956 C:\WINDOWS\system32\autochk.exe - ok
15:40:57.0859 3956 [ 173F317CE0DB8E21322E71B7E60A27E8 ] C:\WINDOWS\system32\drivers\usbccgp.sys
15:40:57.0859 3956 C:\WINDOWS\system32\drivers\usbccgp.sys - ok
15:40:57.0859 3956 [ 9DD07AF82244867CA36681EA2D29CE79 ] C:\WINDOWS\system32\sfcfiles.dll
15:40:57.0859 3956 C:\WINDOWS\system32\sfcfiles.dll - ok
15:40:57.0875 3956 [ C885B02847F5D2FD45A24E219ED93B32 ] C:\WINDOWS\system32\drivers\cdfs.sys
15:40:57.0875 3956 C:\WINDOWS\system32\drivers\cdfs.sys - ok
15:40:57.0875 3956 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] C:\WINDOWS\system32\drivers\usbscan.sys
15:40:57.0875 3956 C:\WINDOWS\system32\drivers\usbscan.sys - ok
15:40:57.0875 3956 [ A717C8721046828520C9EDF31288FC00 ] C:\WINDOWS\system32\drivers\usbprint.sys
15:40:57.0875 3956 C:\WINDOWS\system32\drivers\usbprint.sys - ok
15:40:57.0890 3956 [ ABCB05CCDBF03000354B9553820E39F8 ] C:\WINDOWS\system32\drivers\HPZius12.sys
15:40:57.0890 3956 C:\WINDOWS\system32\drivers\HPZius12.sys - ok
15:40:57.0890 3956 [ D03D10F7DED688FECF50F8FBF1EA9B8A ] C:\WINDOWS\system32\drivers\HPZid412.sys
15:40:57.0890 3956 C:\WINDOWS\system32\drivers\HPZid412.sys - ok
15:40:57.0890 3956 [ 89F41658929393487B6B7D13C8528CE3 ] C:\WINDOWS\system32\drivers\HPZipr12.sys
15:40:57.0890 3956 C:\WINDOWS\system32\drivers\HPZipr12.sys - ok
15:40:57.0906 3956 [ 1AF592532532A402ED7C060F6954004F ] C:\WINDOWS\system32\drivers\hidclass.sys
15:40:57.0906 3956 C:\WINDOWS\system32\drivers\hidclass.sys - ok
15:40:57.0906 3956 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] C:\WINDOWS\system32\drivers\hidusb.sys
15:40:57.0906 3956 C:\WINDOWS\system32\drivers\hidusb.sys - ok
15:40:57.0906 3956 [ B1C303E17FB9D46E87A98E4BA6769685 ] C:\WINDOWS\system32\drivers\mouhid.sys
15:40:57.0906 3956 C:\WINDOWS\system32\drivers\mouhid.sys - ok
15:40:57.0906 3956 [ 2F31B7F954BED437F2C75026C65CAF7B ] C:\WINDOWS\system32\drivers\wmilib.sys
15:40:57.0906 3956 C:\WINDOWS\system32\drivers\wmilib.sys - ok
15:40:57.0921 3956 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] C:\WINDOWS\system32\drivers\atapi.sys
15:40:57.0921 3956 C:\WINDOWS\system32\drivers\atapi.sys - ok
15:40:57.0921 3956 [ FE97D0343ACFDEBDD578FC67CC91FA87 ] C:\WINDOWS\system32\drivers\dxapi.sys
15:40:57.0921 3956 C:\WINDOWS\system32\drivers\dxapi.sys - ok
15:40:57.0921 3956 [ 9A10AACBFDC4922715375FB4065EC930 ] C:\WINDOWS\system32\watchdog.sys
15:40:57.0921 3956 C:\WINDOWS\system32\watchdog.sys - ok
15:40:57.0937 3956 [ BD39EC6064A1B5DFDABCF312A38A37EE ] C:\WINDOWS\system32\win32k.sys
15:40:57.0937 3956 C:\WINDOWS\system32\win32k.sys - ok
15:40:57.0937 3956 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
15:40:57.0937 3956 C:\WINDOWS\system32\basesrv.dll - ok
15:40:57.0937 3956 [ DD40363ABAD230A84C5E2178B11EFA88 ] C:\WINDOWS\system32\csrsrv.dll
15:40:57.0937 3956 C:\WINDOWS\system32\csrsrv.dll - ok
15:40:57.0953 3956 [ 44F275C64738EA2056E3D9580C23B60F ] C:\WINDOWS\system32\csrss.exe
15:40:57.0953 3956 C:\WINDOWS\system32\csrss.exe - ok
15:40:57.0953 3956 [ 8B1F3320AEBB536E021A5014409862DE ] C:\WINDOWS\system32\gdi32.dll
15:40:57.0953 3956 C:\WINDOWS\system32\gdi32.dll - ok
15:40:57.0953 3956 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:40:57.0953 3956 C:\WINDOWS\system32\winsrv.dll - ok
15:40:57.0968 3956 [ 6FE42512AB1B89F32A7407F261B1D2D0 ] C:\WINDOWS\system32\kernel32.dll
15:40:57.0968 3956 C:\WINDOWS\system32\kernel32.dll - ok
15:40:57.0968 3956 [ B26B135FF1B9F60C9388B4A7D16F600B ] C:\WINDOWS\system32\user32.dll
15:40:57.0968 3956 C:\WINDOWS\system32\user32.dll - ok
15:40:57.0968 3956 [ AC7280566A7BB85CB3291F04DDC1198E ] C:\WINDOWS\system32\drivers\dxg.sys
15:40:57.0968 3956 C:\WINDOWS\system32\drivers\dxg.sys - ok
15:40:57.0984 3956 [ A73F5D6705B1D820C19B18782E176EFD ] C:\WINDOWS\system32\drivers\dxgthk.sys
15:40:57.0984 3956 C:\WINDOWS\system32\drivers\dxgthk.sys - ok
15:40:57.0984 3956 [ A70E25C193FE92936665617D3B4973D6 ] C:\WINDOWS\system32\ialmdnt5.dll
15:40:57.0984 3956 C:\WINDOWS\system32\ialmdnt5.dll - ok
15:40:57.0984 3956 [ 4C3E431C30F13918B2B624839C5851D4 ] C:\WINDOWS\system32\ialmrnt5.dll
15:40:57.0984 3956 C:\WINDOWS\system32\ialmrnt5.dll - ok
15:40:58.0000 3956 [ ECB7591870F8BFB1A4C17B718AD5A4AA ] C:\WINDOWS\system32\vga.dll
15:40:58.0000 3956 C:\WINDOWS\system32\vga.dll - ok
15:40:58.0000 3956 [ D3F8D22ED63CDBB7F535AA4A914296C4 ] C:\WINDOWS\system32\ialmdev5.dll
15:40:58.0000 3956 C:\WINDOWS\system32\ialmdev5.dll - ok
15:40:58.0000 3956 [ ECAF48B8262DCEFCC605FABCBB15B6EF ] C:\WINDOWS\system32\ialmdd5.dll
15:40:58.0000 3956 C:\WINDOWS\system32\ialmdd5.dll - ok
15:40:58.0015 3956 [ ED0EF0A136DEC83DF69F04118870003E ] C:\WINDOWS\system32\winlogon.exe
15:40:58.0015 3956 C:\WINDOWS\system32\winlogon.exe - ok
15:40:58.0015 3956 [ E76F8807070ED04E7408A86D6D3A6137 ] C:\WINDOWS\system32\advapi32.dll
15:40:58.0015 3956 C:\WINDOWS\system32\advapi32.dll - ok
15:40:58.0015 3956 [ D4502F124289A31976130CCCB014C9AA ] C:\WINDOWS\system32\rpcrt4.dll
15:40:58.0015 3956 C:\WINDOWS\system32\rpcrt4.dll - ok
15:40:58.0031 3956 [ 5357826C8A8DD6A07F17C48BB45BE46E ] C:\WINDOWS\system32\secur32.dll
15:40:58.0031 3956 C:\WINDOWS\system32\secur32.dll - ok
15:40:58.0031 3956 [ 714705F29A917993536A6AB2DEDB0B7F ] C:\WINDOWS\system32\authz.dll
15:40:58.0031 3956 C:\WINDOWS\system32\authz.dll - ok
15:40:58.0031 3956 [ 355EDBB4D412B01F1740C17E3F50FA00 ] C:\WINDOWS\system32\msvcrt.dll
15:40:58.0031 3956 C:\WINDOWS\system32\msvcrt.dll - ok
15:40:58.0046 3956 [ 6BEE5D4EFF0A0341BCC4A462D81CCFC1 ] C:\WINDOWS\system32\crypt32.dll
15:40:58.0046 3956 C:\WINDOWS\system32\crypt32.dll - ok
15:40:58.0046 3956 [ 04D898830DF96A17A20FD35D7590F87E ] C:\WINDOWS\system32\msasn1.dll
15:40:58.0046 3956 C:\WINDOWS\system32\msasn1.dll - ok
15:40:58.0046 3956 [ 013C1148C1EC025596896E093F60F608 ] C:\WINDOWS\system32\nddeapi.dll
15:40:58.0046 3956 C:\WINDOWS\system32\nddeapi.dll - ok
15:40:58.0062 3956 [ FCFA1C55971CC229D353B3A15ACCD995 ] C:\WINDOWS\system32\profmap.dll
15:40:58.0062 3956 C:\WINDOWS\system32\profmap.dll - ok
15:40:58.0062 3956 [ CAC752BF84DB4666ED3CE0948E6EA937 ] C:\WINDOWS\system32\netapi32.dll
15:40:58.0062 3956 C:\WINDOWS\system32\netapi32.dll - ok
15:40:58.0062 3956 [ 43D13C80EBEC0135A3611E0F616F179B ] C:\WINDOWS\system32\userenv.dll
15:40:58.0062 3956 C:\WINDOWS\system32\userenv.dll - ok
15:40:58.0078 3956 [ 9CFCB3CA3D83B4EAA133F0644A2C6F31 ] C:\WINDOWS\system32\psapi.dll
15:40:58.0078 3956 C:\WINDOWS\system32\psapi.dll - ok
15:40:58.0078 3956 [ AF11C591F2F4AFF4A6CF699D376F618B ] C:\WINDOWS\system32\regapi.dll
15:40:58.0078 3956 C:\WINDOWS\system32\regapi.dll - ok
15:40:58.0078 3956 [ 24192246760E0E64435522E246B1D6C2 ] C:\WINDOWS\system32\setupapi.dll
15:40:58.0078 3956 C:\WINDOWS\system32\setupapi.dll - ok
15:40:58.0093 3956 [ C7CE131408739B0B3A318BE2D0032719 ] C:\WINDOWS\system32\version.dll
15:40:58.0093 3956 C:\WINDOWS\system32\version.dll - ok
15:40:58.0093 3956 [ 430CEB794F6E6EF8AC86958C242366D6 ] C:\WINDOWS\system32\winsta.dll
15:40:58.0093 3956 C:\WINDOWS\system32\winsta.dll - ok
15:40:58.0093 3956 [ D458B738B4C2CE33174CFB2CE12412DB ] C:\WINDOWS\system32\wintrust.dll
15:40:58.0093 3956 C:\WINDOWS\system32\wintrust.dll - ok
15:40:58.0109 3956 [ FFC01A72D1C25CCB39F61B202CE60819 ] C:\WINDOWS\system32\imagehlp.dll
15:40:58.0109 3956 C:\WINDOWS\system32\imagehlp.dll - ok
15:40:58.0109 3956 [ 2CCC474EB85CEAA3E1FA1726580A3E5A ] C:\WINDOWS\system32\ws2_32.dll
15:40:58.0109 3956 C:\WINDOWS\system32\ws2_32.dll - ok
15:40:58.0125 3956 [ 0DA85218E92526972A821587E6A8BF8F ] C:\WINDOWS\system32\imm32.dll
15:40:58.0125 3956 C:\WINDOWS\system32\imm32.dll - ok
15:40:58.0125 3956 [ 9789E95E1D88EEB4B922BF3EA7779C28 ] C:\WINDOWS\system32\ws2help.dll
15:40:58.0125 3956 C:\WINDOWS\system32\ws2help.dll - ok
15:40:58.0125 3956 [ DAB9952E3626D84E74CBF4958B1B1F52 ] C:\WINDOWS\system32\kbduk.dll
15:40:58.0125 3956 C:\WINDOWS\system32\kbduk.dll - ok
15:40:58.0140 3956 [ 56C5B179FE3308B655EB6208C3256FEC ] C:\WINDOWS\system32\kbdus.dll
15:40:58.0140 3956 C:\WINDOWS\system32\kbdus.dll - ok
15:40:58.0140 3956 [ D7B7A57C0E57C836F18CF12A4C62A1CA ] C:\WINDOWS\system32\msgina.dll
15:40:58.0140 3956 C:\WINDOWS\system32\msgina.dll - ok
15:40:58.0140 3956 [ 93AFB83FBC1F9443CAC722FCA63D73BF ] C:\WINDOWS\system32\comctl32.dll
15:40:58.0140 3956 C:\WINDOWS\system32\comctl32.dll - ok
15:40:58.0156 3956 [ 40B0F98BAD16AD5DEF894E88C3EF8014 ] C:\WINDOWS\system32\odbc32.dll
15:40:58.0156 3956 C:\WINDOWS\system32\odbc32.dll - ok
15:40:58.0156 3956 [ 86987A5000DFA3EBE2275C0456BCF2FE ] C:\WINDOWS\system32\comdlg32.dll
15:40:58.0156 3956 C:\WINDOWS\system32\comdlg32.dll - ok
15:40:58.0156 3956 [ 6843D54BC4A40CC8C5741AF750233D10 ] C:\WINDOWS\system32\shell32.dll
15:40:58.0156 3956 C:\WINDOWS\system32\shell32.dll - ok
15:40:58.0171 3956 [ C448A248B743F5FB935C787A5D97268B ] C:\WINDOWS\system32\shlwapi.dll
15:40:58.0171 3956 C:\WINDOWS\system32\shlwapi.dll - ok
15:40:58.0171 3956 [ 694503348B586E99D56C0E30AB5B3EF8 ] C:\WINDOWS\system32\sxs.dll
15:40:58.0171 3956 C:\WINDOWS\system32\sxs.dll - ok
15:40:58.0171 3956 [ 736B12B725AEB2B07F0241A9F680CB10 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
15:40:58.0171 3956 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll - ok
15:40:58.0171 3956 [ 6B7C6B32F8E84D56C6260D684019FEA2 ] C:\WINDOWS\system32\odbcint.dll
15:40:58.0171 3956 C:\WINDOWS\system32\odbcint.dll - ok
15:40:58.0187 3956 [ 99BC0B50F511924348BE19C7C7313BBF ] C:\WINDOWS\system32\shsvcs.dll
15:40:58.0187 3956 C:\WINDOWS\system32\shsvcs.dll - ok
15:40:58.0187 3956 [ 96E1C926F22EE1BFBAE82901A35F6BF3 ] C:\WINDOWS\system32\sfc.dll
15:40:58.0187 3956 C:\WINDOWS\system32\sfc.dll - ok
15:40:58.0187 3956 [ 6B5DB6789177A4FD0DEBC248041D0739 ] C:\WINDOWS\system32\sfc_os.dll
15:40:58.0187 3956 C:\WINDOWS\system32\sfc_os.dll - ok
15:40:58.0203 3956 [ 6BAD1BED9872E62049E487FB91AE2F3A ] C:\WINDOWS\system32\ole32.dll
15:40:58.0203 3956 C:\WINDOWS\system32\ole32.dll - ok
15:40:58.0203 3956 [ CF492D7E9AF1C628B3536D20EF6F5CC7 ] C:\WINDOWS\system32\apphelp.dll
15:40:58.0203 3956 C:\WINDOWS\system32\apphelp.dll - ok
15:40:58.0203 3956 [ BD31DC6DBE9333C4FBD4BDF0899F2160 ] C:\WINDOWS\system32\lsasrv.dll
15:40:58.0203 3956 C:\WINDOWS\system32\lsasrv.dll - ok
15:40:58.0218 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] C:\WINDOWS\system32\lsass.exe
15:40:58.0218 3956 C:\WINDOWS\system32\lsass.exe - ok
15:40:58.0218 3956 [ EC29A79F1E76DC509E24D401F29D0678 ] C:\WINDOWS\system32\ncobjapi.dll
15:40:58.0218 3956 C:\WINDOWS\system32\ncobjapi.dll - ok
15:40:58.0218 3956 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
15:40:58.0218 3956 C:\WINDOWS\system32\services.exe - ok
15:40:58.0234 3956 [ F404830F3CD9BF8F2515E489C0CDA297 ] C:\WINDOWS\system32\msvcp60.dll
15:40:58.0234 3956 C:\WINDOWS\system32\msvcp60.dll - ok
15:40:58.0234 3956 [ B24A42A413E694AD73FDFB7FBD492C31 ] C:\WINDOWS\system32\scesrv.dll
15:40:58.0234 3956 C:\WINDOWS\system32\scesrv.dll - ok
15:40:58.0234 3956 [ DD7BD97FB8BD800963789158A5E4B41D ] C:\WINDOWS\system32\mpr.dll
15:40:58.0234 3956 C:\WINDOWS\system32\mpr.dll - ok
15:40:58.0250 3956 [ 2EDFC2A8893435723AD80481803C6D5C ] C:\WINDOWS\system32\umpnpmgr.dll
15:40:58.0250 3956 C:\WINDOWS\system32\umpnpmgr.dll - ok
15:40:58.0250 3956 [ EC4C0D9BFD9F7E33F8B395AD54E13063 ] C:\WINDOWS\system32\ntdsapi.dll
15:40:58.0250 3956 C:\WINDOWS\system32\ntdsapi.dll - ok
15:40:58.0250 3956 [ 1F03103598BD817B1078DAB1326DDE11 ] C:\WINDOWS\system32\shimeng.dll
15:40:58.0250 3956 C:\WINDOWS\system32\shimeng.dll - ok
15:40:58.0265 3956 [ EA9EE60B408878E5F2012F9C783836DB ] C:\WINDOWS\AppPatch\AcAdProc.dll
15:40:58.0265 3956 C:\WINDOWS\AppPatch\AcAdProc.dll - ok
15:40:58.0265 3956 [ 389496118B3B03C2328024AF320132AC ] C:\WINDOWS\system32\dnsapi.dll
15:40:58.0265 3956 C:\WINDOWS\system32\dnsapi.dll - ok
15:40:58.0265 3956 [ 0492CF5870F0E616B0C71695A433D162 ] C:\WINDOWS\system32\wldap32.dll
15:40:58.0265 3956 C:\WINDOWS\system32\wldap32.dll - ok
15:40:58.0281 3956 [ 8329A39D5A402A75A74301D6A62ECDA1 ] C:\WINDOWS\system32\samlib.dll
15:40:58.0281 3956 C:\WINDOWS\system32\samlib.dll - ok
15:40:58.0281 3956 [ F05B8CDB7FE0E55DCCFB1D946CE80064 ] C:\WINDOWS\system32\samsrv.dll
15:40:58.0281 3956 C:\WINDOWS\system32\samsrv.dll - ok
15:40:58.0281 3956 [ 310C15FD8358B2C4CD7A5B98A112883F ] C:\WINDOWS\AppPatch\AcGenral.dll
15:40:58.0281 3956 C:\WINDOWS\AppPatch\AcGenral.dll - ok
15:40:58.0296 3956 [ 17A1D675C12BBF80CAAC54A4855C41D0 ] C:\WINDOWS\system32\cryptdll.dll
15:40:58.0296 3956 C:\WINDOWS\system32\cryptdll.dll - ok
15:40:58.0296 3956 [ EFF03460E542EEA6B0ABDEC6BF19C897 ] C:\WINDOWS\system32\oleaut32.dll
15:40:58.0296 3956 C:\WINDOWS\system32\oleaut32.dll - ok
15:40:58.0296 3956 [ 4A953F13942867BA8FB41F141EC1B80C ] C:\WINDOWS\system32\winmm.dll
15:40:58.0296 3956 C:\WINDOWS\system32\winmm.dll - ok
15:40:58.0312 3956 [ 2098AB52BD5316E59AA36F3437B13BE6 ] C:\WINDOWS\system32\msacm32.dll
15:40:58.0312 3956 C:\WINDOWS\system32\msacm32.dll - ok
15:40:58.0312 3956 [ 7A2CC3719B255E6B5D74396183B7715B ] C:\WINDOWS\system32\uxtheme.dll
15:40:58.0312 3956 C:\WINDOWS\system32\uxtheme.dll - ok
15:40:58.0312 3956 [ F24B12786D60A17008319E3F2AEE7799 ] C:\WINDOWS\system32\msapsspc.dll
15:40:58.0312 3956 C:\WINDOWS\system32\msapsspc.dll - ok
15:40:58.0328 3956 [ 7A660EDC0757849DF5F8706FB6E9F740 ] C:\WINDOWS\system32\msvcrt40.dll
15:40:58.0328 3956 C:\WINDOWS\system32\msvcrt40.dll - ok
15:40:58.0328 3956 [ 3D76DD0CBC536E0F8C45D23ED230BEB2 ] C:\WINDOWS\system32\digest.dll
15:40:58.0328 3956 C:\WINDOWS\system32\digest.dll - ok
15:40:58.0328 3956 [ 0F64207B49390C8063C36AE7CBF9C2DB ] C:\WINDOWS\system32\schannel.dll
15:40:58.0328 3956 C:\WINDOWS\system32\schannel.dll - ok
15:40:58.0343 3956 [ A4388DF80E52695AE92EE5F3F61F1619 ] C:\WINDOWS\system32\msnsspc.dll
15:40:58.0343 3956 C:\WINDOWS\system32\msnsspc.dll - ok
15:40:58.0343 3956 [ A525C96C51D55111FDF3BEA9FFFFC7AE ] C:\WINDOWS\system32\kerberos.dll
15:40:58.0343 3956 C:\WINDOWS\system32\kerberos.dll - ok
15:40:58.0343 3956 [ 5733177BCF16EE78B99543C9B0AB81EA ] C:\WINDOWS\system32\MSCTFIME.IME
15:40:58.0343 3956 C:\WINDOWS\system32\MSCTFIME.IME - ok
15:40:58.0359 3956 [ C6BB1D1500DB4A0E224CB65E6C7E8A80 ] C:\WINDOWS\system32\msprivs.dll
15:40:58.0359 3956 C:\WINDOWS\system32\msprivs.dll - ok
15:40:58.0359 3956 [ 517561A1113B04E51D936CD018DE1C1F ] C:\WINDOWS\system32\msv1_0.dll
15:40:58.0359 3956 C:\WINDOWS\system32\msv1_0.dll - ok
15:40:58.0359 3956 [ C11D10A3C164AC222BC9AAB3650A88B3 ] C:\WINDOWS\system32\atmfd.dll
15:40:58.0359 3956 C:\WINDOWS\system32\atmfd.dll - ok
15:40:58.0375 3956 [ AF07DC9B7CC455629E732340C7B15F3A ] C:\WINDOWS\system32\iphlpapi.dll
15:40:58.0375 3956 C:\WINDOWS\system32\iphlpapi.dll - ok
15:40:58.0375 3956 [ 1B7F071C51B77C272875C3A23E1E4550 ] C:\WINDOWS\system32\netlogon.dll
15:40:58.0375 3956 C:\WINDOWS\system32\netlogon.dll - ok
15:40:58.0375 3956 [ 54AF4B1D5459500EF0937F6D33B1914F ] C:\WINDOWS\system32\w32time.dll
15:40:58.0375 3956 C:\WINDOWS\system32\w32time.dll - ok
15:40:58.0390 3956 [ 54DAE3EA34802B4ED9AE1C6B1209FA56 ] C:\WINDOWS\system32\rsaenh.dll
15:40:58.0390 3956 C:\WINDOWS\system32\rsaenh.dll - ok
15:40:58.0390 3956 [ 3AAF9B35939FF9E58CCD18D41655C2FC ] C:\WINDOWS\system32\wdigest.dll
15:40:58.0390 3956 C:\WINDOWS\system32\wdigest.dll - ok
15:40:58.0390 3956 [ 02988B904C386B500CD08639C4C20EEA ] C:\WINDOWS\system32\winscard.dll
15:40:58.0390 3956 C:\WINDOWS\system32\winscard.dll - ok
15:40:58.0406 3956 [ 0E2735281FBB9A764D5584C2A5DCBA59 ] C:\WINDOWS\system32\wtsapi32.dll
15:40:58.0406 3956 C:\WINDOWS\system32\wtsapi32.dll - ok
15:40:58.0406 3956 [ A86BB5E61BF3E39B62AB4C7E7085A084 ] C:\WINDOWS\system32\scecli.dll
15:40:58.0406 3956 C:\WINDOWS\system32\scecli.dll - ok
15:40:58.0406 3956 [ 27C6D03BCDB8CFEB96B716F3D8BE3E18 ] C:\WINDOWS\system32\svchost.exe
15:40:58.0406 3956 C:\WINDOWS\system32\svchost.exe - ok
15:40:58.0421 3956 [ 549290DBC280C887681D7652978DBBE0 ] C:\WINDOWS\system32\ntmarta.dll
15:40:58.0421 3956 C:\WINDOWS\system32\ntmarta.dll - ok
15:40:58.0421 3956 [ 6B27A5C03DFB94B4245739065431322C ] C:\WINDOWS\system32\rpcss.dll
15:40:58.0421 3956 C:\WINDOWS\system32\rpcss.dll - ok
15:40:58.0421 3956 [ 16403217AB6FC5C30C14C6B12098AD4B ] C:\WINDOWS\system32\xpsp2res.dll
15:40:58.0421 3956 C:\WINDOWS\system32\xpsp2res.dll - ok
15:40:58.0437 3956 [ 6D4FEB43EE538FC5428CC7F0565AA656 ] C:\WINDOWS\system32\eventlog.dll
15:40:58.0437 3956 C:\WINDOWS\system32\eventlog.dll - ok
15:40:58.0437 3956 [ 943337D786A56729263071623BBB9DE5 ] C:\WINDOWS\system32\mswsock.dll
15:40:58.0437 3956 C:\WINDOWS\system32\mswsock.dll - ok
15:40:58.0437 3956 [ 3CB32D3B8CBE79899D63280BB7A83CD9 ] C:\WINDOWS\system32\hnetcfg.dll
15:40:58.0437 3956 C:\WINDOWS\system32\hnetcfg.dll - ok
15:40:58.0437 3956 [ 4E3D06D6E68EEDB52565080F55B460D3 ] C:\WINDOWS\system32\wshtcpip.dll
15:40:58.0437 3956 C:\WINDOWS\system32\wshtcpip.dll - ok
15:40:58.0453 3956 [ 40947436A70E0034E41123DF5A0A7702 ] C:\Program Files\Bonjour\mdnsNSP.dll
15:40:58.0453 3956 C:\Program Files\Bonjour\mdnsNSP.dll - ok
15:40:58.0453 3956 [ D72B9EC3337B247A666F098F3D6B43DE ] C:\WINDOWS\system32\winrnr.dll
15:40:58.0453 3956 C:\WINDOWS\system32\winrnr.dll - ok
15:40:58.0468 3956 [ 6F9BEF24C578D5D6740E080BEDD6A448 ] C:\WINDOWS\system32\rasadhlp.dll
15:40:58.0468 3956 C:\WINDOWS\system32\rasadhlp.dll - ok
15:40:58.0468 3956 [ F556912E70B22D740C9C99E310E3C11F ] C:\Program Files\Microsoft Security Client\MpSvc.dll
15:40:58.0468 3956 C:\Program Files\Microsoft Security Client\MpSvc.dll - ok
15:40:58.0468 3956 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] C:\Program Files\Microsoft Security Client\MsMpEng.exe
15:40:58.0468 3956 C:\Program Files\Microsoft Security Client\MsMpEng.exe - ok
15:40:58.0468 3956 [ 3D9381A332E4373F8811C71BA5078B31 ] C:\Program Files\Microsoft Security Client\MpClient.dll
15:40:58.0468 3956 C:\Program Files\Microsoft Security Client\MpClient.dll - ok
15:40:58.0484 3956 [ 05231C04253C5BC30B26CBAAE680ED89 ] C:\WINDOWS\system32\WudfSvc.dll
15:40:58.0484 3956 C:\WINDOWS\system32\WudfSvc.dll - ok
15:40:58.0484 3956 [ 5CAF91E865FE0C85048A233E594544D2 ] C:\WINDOWS\system32\WudfPlatform.dll
15:40:58.0484 3956 C:\WINDOWS\system32\WudfPlatform.dll - ok
15:40:58.0500 3956 [ AA87D7709021503687326432DC59590D ] C:\Program Files\Microsoft Security Client\MpRTP.dll
15:40:58.0500 3956 C:\Program Files\Microsoft Security Client\MpRTP.dll - ok
15:40:58.0500 3956 [ 5D43C9A33F18C707BA169AFDA88BDF30 ] C:\WINDOWS\system32\fltlib.dll
15:40:58.0500 3956 C:\WINDOWS\system32\fltlib.dll - ok
15:40:58.0500 3956 [ 2081A5B5E4ABA206A0A8A1A97DF0FB23 ] C:\WINDOWS\system32\logonui.exe
15:40:58.0500 3956 C:\WINDOWS\system32\logonui.exe - ok
15:40:58.0515 3956 [ 515A7FAE2070C2B0242B2353443E2F11 ] C:\WINDOWS\system32\cscdll.dll
15:40:58.0515 3956 C:\WINDOWS\system32\cscdll.dll - ok
15:40:58.0515 3956 [ 3D41A9326F0376FC73AF961DD23B1FB1 ] C:\WINDOWS\system32\duser.dll
15:40:58.0515 3956 C:\WINDOWS\system32\duser.dll - ok
15:40:58.0515 3956 [ E2092F0A1D7ABC243F9C2362483D150D ] C:\WINDOWS\system32\dimsntfy.dll
15:40:58.0515 3956 C:\WINDOWS\system32\dimsntfy.dll - ok
15:40:58.0531 3956 [ 2CC34E8BB667EEF78899546E12649196 ] C:\WINDOWS\system32\wlnotify.dll
15:40:58.0531 3956 C:\WINDOWS\system32\wlnotify.dll - ok
15:40:58.0531 3956 [ BD83ABA61E8ACCC8D9FFB869F29418CE ] C:\WINDOWS\system32\winspool.drv
15:40:58.0531 3956 C:\WINDOWS\system32\winspool.drv - ok
15:40:58.0531 3956 [ F34C06D1C706A6D9433570B087A18B02 ] C:\WINDOWS\system32\drivers\Scutum50.sys
15:40:58.0531 3956 C:\WINDOWS\system32\drivers\Scutum50.sys - ok
15:40:58.0546 3956 [ F927A4434C5028758A842943EF1A3849 ] C:\WINDOWS\system32\drivers\ndisuio.sys
15:40:58.0546 3956 C:\WINDOWS\system32\drivers\ndisuio.sys - ok
15:40:58.0546 3956 [ 5E38D7684A49CACFB752B046357E0589 ] C:\WINDOWS\system32\dhcpcsvc.dll
15:40:58.0546 3956 C:\WINDOWS\system32\dhcpcsvc.dll - ok
15:40:58.0546 3956 [ AFFC87E2501FCE8F09D4C10BA6421CCF ] C:\WINDOWS\system32\msimg32.dll
15:40:58.0546 3956 C:\WINDOWS\system32\msimg32.dll - ok
15:40:58.0562 3956 [ 20200EE3CFE10E9F0C028D8653BE11C6 ] C:\WINDOWS\system32\oleacc.dll
15:40:58.0562 3956 C:\WINDOWS\system32\oleacc.dll - ok
15:40:58.0562 3956 [ 02CF580510234E519736559A7F19EA20 ] C:\WINDOWS\system32\WgaLogon.dll
15:40:58.0562 3956 C:\WINDOWS\system32\WgaLogon.dll - ok
15:40:58.0562 3956 [ F137A0CA70003DB20448D540651FA003 ] C:\WINDOWS\system32\clbcatq.dll
15:40:58.0562 3956 C:\WINDOWS\system32\clbcatq.dll - ok
15:40:58.0578 3956 [ 5F7E24FA9EAB896051FFB87F840730D2 ] C:\WINDOWS\system32\dnsrslvr.dll
15:40:58.0578 3956 C:\WINDOWS\system32\dnsrslvr.dll - ok
15:40:58.0578 3956 [ 1280A158C722FA95A80FB7AEBE78FA7D ] C:\WINDOWS\system32\comres.dll
15:40:58.0578 3956 C:\WINDOWS\system32\comres.dll - ok
15:40:58.0578 3956 [ ACFEE2392503DD5E457363A0510B8BCB ] C:\WINDOWS\system32\msxml3.dll
15:40:58.0578 3956 C:\WINDOWS\system32\msxml3.dll - ok
15:40:58.0593 3956 [ E5EDBD51476DB5001ABF5C82AE5C3DD1 ] C:\WINDOWS\system32\shgina.dll
15:40:58.0593 3956 C:\WINDOWS\system32\shgina.dll - ok
15:40:58.0593 3956 [ 3D4E199942E29207970E04315D02AD3B ] C:\WINDOWS\system32\cryptsvc.dll
15:40:58.0593 3956 C:\WINDOWS\system32\cryptsvc.dll - ok
15:40:58.0593 3956 [ A7DB739AE99A796D91580147E919CC59 ] C:\WINDOWS\system32\lmhsvc.dll
15:40:58.0593 3956 C:\WINDOWS\system32\lmhsvc.dll - ok
15:40:58.0609 3956 [ 00709952D444EAE14DBBD30D36FBAE0F ] C:\WINDOWS\system32\certcli.dll
15:40:58.0609 3956 C:\WINDOWS\system32\certcli.dll - ok
15:40:58.0609 3956 [ 224FB925C641DA16CEB6D60F40CA4C75 ] C:\WINDOWS\system32\atl.dll
15:40:58.0609 3956 C:\WINDOWS\system32\atl.dll - ok
15:40:58.0609 3956 [ 6E4BE11D50F8A8DE2BAD644C9C9DE8D3 ] C:\WINDOWS\system32\cryptui.dll
15:40:58.0609 3956 C:\WINDOWS\system32\cryptui.dll - ok
15:40:58.0625 3956 [ 5AACF4B4DEE1972B7952E8A747122232 ] C:\WINDOWS\system32\wininet.dll
15:40:58.0625 3956 C:\WINDOWS\system32\wininet.dll - ok
15:40:58.0625 3956 [ 10753A3ADC3E39A3B10CC3F08E98E6B4 ] C:\WINDOWS\system32\normaliz.dll
15:40:58.0625 3956 C:\WINDOWS\system32\normaliz.dll - ok
15:40:58.0625 3956 [ C332870084DB9164F465D6F1B7472728 ] C:\WINDOWS\system32\urlmon.dll
15:40:58.0625 3956 C:\WINDOWS\system32\urlmon.dll - ok
15:40:58.0640 3956 [ 47464CA4943F82E1B8FCB2C57DA15F83 ] C:\WINDOWS\system32\iertutil.dll
15:40:58.0640 3956 C:\WINDOWS\system32\iertutil.dll - ok
15:40:58.0640 3956 [ 9F4003841689C663254D54177EB97219 ] C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{672C0FA1-C712-4379-928A-1DBC39B85ED1}\mpengine.dll
15:40:58.0640 3956 C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{672C0FA1-C712-4379-928A-1DBC39B85ED1}\mpengine.dll - ok
15:40:58.0640 3956 [ F5B754CDEA20BBB3A31E16A776EDE6D6 ] C:\WINDOWS\system32\esent.dll
15:40:58.0640 3956 C:\WINDOWS\system32\esent.dll - ok
15:40:58.0656 3956 [ C1FAEA15E41F62D7BFA7FBC395C24BA6 ] C:\WINDOWS\system32\riched20.dll
15:40:58.0656 3956 C:\WINDOWS\system32\riched20.dll - ok
15:40:58.0656 3956 [ 7C89F125919D8DF7E413CA1751A6412E ] C:\Program Files\CheckPoint\ZoneAlarm\vsdata.dll
15:40:58.0656 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsdata.dll - ok
15:40:58.0656 3956 [ E50A1E6A7D17C79F0A433F5D748FE725 ] C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
15:40:58.0656 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe - ok
15:40:58.0671 3956 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] C:\WINDOWS\system32\wzcsvc.dll
15:40:58.0671 3956 C:\WINDOWS\system32\wzcsvc.dll - ok
15:40:58.0671 3956 [ 655CBD271A6DFC5AC80E5F3E11E4B38B ] C:\Program Files\CheckPoint\ZoneAlarm\vsinit.dll
15:40:58.0671 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsinit.dll - ok
15:40:58.0671 3956 [ 4C39358EBDD2FFCD9132A30E1EC31E16 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
15:40:58.0671 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll - ok
15:40:58.0687 3956 [ 876CCF164E08D6B903CD14398E056DD2 ] C:\WINDOWS\system32\rtutils.dll
15:40:58.0687 3956 C:\WINDOWS\system32\rtutils.dll - ok
15:40:58.0687 3956 [ E6EF7BC927D9F8F9BA1584BFC39E0C6F ] C:\WINDOWS\system32\eapolqec.dll
15:40:58.0687 3956 C:\WINDOWS\system32\eapolqec.dll - ok
15:40:58.0687 3956 [ 7B0770526801F05D58C51A3DFB87B4BD ] C:\WINDOWS\system32\wmi.dll
15:40:58.0703 3956 C:\WINDOWS\system32\wmi.dll - ok
15:40:58.0703 3956 [ 8AE93AACC648921BAACB8602991AC4B3 ] C:\WINDOWS\system32\qutil.dll
15:40:58.0703 3956 C:\WINDOWS\system32\qutil.dll - ok
15:40:58.0703 3956 [ 8E2CC37BA87D8F681066E0E9C8A19F73 ] C:\WINDOWS\system32\dot3api.dll
15:40:58.0703 3956 C:\WINDOWS\system32\dot3api.dll - ok
15:40:58.0703 3956 [ CDBE9690CF2B8409FACAD94FAC9479C9 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
15:40:58.0703 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll - ok
15:40:58.0718 3956 [ A39BE37C9237DB5F1990D61B268EA555 ] C:\WINDOWS\system32\rastls.dll
15:40:58.0718 3956 C:\WINDOWS\system32\rastls.dll - ok
15:40:58.0718 3956 [ EA5B8BECA3F279C757578CD7F1E95855 ] C:\WINDOWS\system32\mprapi.dll
15:40:58.0718 3956 C:\WINDOWS\system32\mprapi.dll - ok
15:40:58.0734 3956 [ 2CDAE321B8E878A278BA2D2FA013060B ] C:\WINDOWS\system32\activeds.dll
15:40:58.0734 3956 C:\WINDOWS\system32\activeds.dll - ok
15:40:58.0734 3956 [ 67156D5A9AC356DC99D7BCCB388E3316 ] C:\WINDOWS\system32\wsock32.dll
15:40:58.0734 3956 C:\WINDOWS\system32\wsock32.dll - ok
15:40:58.0750 3956 [ B5A2AE4566EF65A36886FEC57131BE56 ] C:\Program Files\CheckPoint\ZoneAlarm\vsutil.dll
15:40:58.0750 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsutil.dll - ok
15:40:58.0750 3956 [ 0D84657DBF93DB98673DEFDF2B29E25A ] C:\WINDOWS\system32\adsldpc.dll
15:40:58.0750 3956 C:\WINDOWS\system32\adsldpc.dll - ok
15:40:58.0750 3956 [ 92C4F48B62B0B876194584C3FF09CCB6 ] C:\WINDOWS\system32\rasapi32.dll
15:40:58.0750 3956 C:\WINDOWS\system32\rasapi32.dll - ok
15:40:58.0765 3956 [ 4DEF926F6A0545AE486A03C84F2EE482 ] C:\WINDOWS\system32\rasman.dll
15:40:58.0765 3956 C:\WINDOWS\system32\rasman.dll - ok
15:40:58.0765 3956 [ 00AABF131B4823785818DB99A075A313 ] C:\WINDOWS\system32\tapi32.dll
15:40:58.0765 3956 C:\WINDOWS\system32\tapi32.dll - ok
15:40:58.0765 3956 [ 56CE97FF94B7662A300D359CD6F4D601 ] C:\WINDOWS\system32\raschap.dll
15:40:58.0765 3956 C:\WINDOWS\system32\raschap.dll - ok
15:40:58.0765 3956 [ DD072705435259D5ABB5D7E0C348EB35 ] C:\Program Files\CheckPoint\ZoneAlarm\dbghelp.dll
15:40:58.0781 3956 C:\Program Files\CheckPoint\ZoneAlarm\dbghelp.dll - ok
15:40:58.0781 3956 [ 66F67AA5A830BAED4CBBB00032AB0514 ] C:\Program Files\CheckPoint\ZoneAlarm\icslta.dll
15:40:58.0781 3956 C:\Program Files\CheckPoint\ZoneAlarm\icslta.dll - ok
15:40:58.0781 3956 [ AC148E516BF11F3E5A369910042E140C ] C:\Program Files\CheckPoint\ZoneAlarm\ssleay32.dll
15:40:58.0781 3956 C:\Program Files\CheckPoint\ZoneAlarm\ssleay32.dll - ok
15:40:58.0781 3956 [ 378F3604E16B3C758C409683FA712288 ] C:\Program Files\CheckPoint\ZoneAlarm\vsdb.dll
15:40:58.0781 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsdb.dll - ok
15:40:58.0796 3956 [ 0DDB0DA30505B719A71B7F3C02778005 ] C:\Program Files\CheckPoint\ZoneAlarm\vsxml.dll
15:40:58.0796 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsxml.dll - ok
15:40:58.0796 3956 [ 109A7562602FA3B596123062DA8C9AD9 ] C:\Program Files\CheckPoint\ZoneAlarm\fbl.dll
15:40:58.0796 3956 C:\Program Files\CheckPoint\ZoneAlarm\fbl.dll - ok
15:40:58.0812 3956 [ 0C0138667F0D0285F4E569D96B60BBB0 ] C:\Program Files\CheckPoint\ZoneAlarm\featuremap.dll
15:40:58.0812 3956 C:\Program Files\CheckPoint\ZoneAlarm\featuremap.dll - ok
15:40:58.0812 3956 [ 9DF55B85A5FA2BA585EDD3277A213A64 ] C:\Program Files\CheckPoint\ZoneAlarm\vswmi.dll
15:40:58.0812 3956 C:\Program Files\CheckPoint\ZoneAlarm\vswmi.dll - ok
15:40:58.0812 3956 [ C283605E6B2B354883AD28A73F4BA336 ] C:\Program Files\CheckPoint\ZoneAlarm\zlcomm.dll
15:40:58.0812 3956 C:\Program Files\CheckPoint\ZoneAlarm\zlcomm.dll - ok
15:40:58.0828 3956 [ 0807425682950F99F74CDC3C0BEDA5BE ] C:\Program Files\CheckPoint\ZoneAlarm\zlcommdb.dll
15:40:58.0828 3956 C:\Program Files\CheckPoint\ZoneAlarm\zlcommdb.dll - ok
15:40:58.0828 3956 [ 56D35F6344504904AA5DFD71BF2AF6C3 ] C:\Program Files\CheckPoint\ZoneAlarm\vsruledb.dll
15:40:58.0828 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsruledb.dll - ok
15:40:58.0828 3956 [ B714735C12A70171DE28657948FD91F1 ] C:\WINDOWS\system32\mlang.dll
15:40:58.0828 3956 C:\WINDOWS\system32\mlang.dll - ok
15:40:58.0843 3956 [ 566382CA5F2C41FEAEEEFAC908F1EB92 ] C:\WINDOWS\system32\xmlprovi.dll
15:40:58.0843 3956 C:\WINDOWS\system32\xmlprovi.dll - ok
15:40:58.0843 3956 [ 767FF54A552732CE772C2302025FA82F ] C:\WINDOWS\system32\wzcsapi.dll
15:40:58.0843 3956 C:\WINDOWS\system32\wzcsapi.dll - ok
15:40:58.0843 3956 [ FCC3B0AABB49BE4915CCA18F1DFE161C ] C:\Program Files\CheckPoint\ZoneAlarm\vsvault.dll
15:40:58.0843 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsvault.dll - ok
15:40:58.0859 3956 [ CB6B671ED6D97F2E9F2274EADB7517B2 ] C:\Program Files\Microsoft Security Client\MpCmdRun.exe
15:40:58.0859 3956 C:\Program Files\Microsoft Security Client\MpCmdRun.exe - ok
15:40:58.0875 3956 [ F9D3C78CFE15271D80790677C893CE45 ] C:\WINDOWS\system32\cabinet.dll
15:40:58.0875 3956 C:\WINDOWS\system32\cabinet.dll - ok
15:40:58.0875 3956 [ 09DEF3ABB6A196749299359AC5578DD8 ] C:\WINDOWS\system32\msxml4.dll
15:40:58.0875 3956 C:\WINDOWS\system32\msxml4.dll - ok
15:40:58.0875 3956 [ C14350FC0D47D806699C4F907FC6785B ] C:\WINDOWS\system32\cryptnet.dll
15:40:58.0875 3956 C:\WINDOWS\system32\cryptnet.dll - ok
15:40:58.0890 3956 [ 3CBA2210FA39C6ED7895634842E930DD ] C:\WINDOWS\system32\sensapi.dll
15:40:58.0890 3956 C:\WINDOWS\system32\sensapi.dll - ok
15:40:58.0890 3956 [ 684559A03CBC1D05BA120A18B0D8BA5D ] C:\WINDOWS\system32\winhttp.dll
15:40:58.0890 3956 C:\WINDOWS\system32\winhttp.dll - ok
15:40:58.0906 3956 [ 205ADD80FF8099B1A8101EB490B933D1 ] C:\WINDOWS\system32\wbem\wbemprox.dll
15:40:58.0906 3956 C:\WINDOWS\system32\wbem\wbemprox.dll - ok
15:40:58.0906 3956 [ D95C71052E5EF63B55997FB31483D02F ] C:\WINDOWS\system32\wbem\wbemcomn.dll
15:40:58.0906 3956 C:\WINDOWS\system32\wbem\wbemcomn.dll - ok
15:40:58.0906 3956 [ 11056136E8EFF4B3B08F01259CF0EF5E ] C:\Program Files\CheckPoint\ZoneAlarm\scheduler.dll
15:40:58.0906 3956 C:\Program Files\CheckPoint\ZoneAlarm\scheduler.dll - ok
15:40:58.0906 3956 [ 1BBF1E9562EE56B1C97BA5426BC16C5E ] C:\Program Files\CheckPoint\ZoneAlarm\zlupdate.dll
15:40:58.0906 3956 C:\Program Files\CheckPoint\ZoneAlarm\zlupdate.dll - ok
15:40:58.0921 3956 [ 05765DB6997E2AA035B02C13A2C5E662 ] C:\Program Files\CheckPoint\ZoneAlarm\zdx.dll
15:40:58.0921 3956 C:\Program Files\CheckPoint\ZoneAlarm\zdx.dll - ok
15:40:58.0921 3956 [ 724A6A9AB5E1807665C5DB71C30BFC5F ] C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
15:40:58.0921 3956 C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys - ok
15:40:58.0921 3956 [ 57FE873B8246DEF1372503CBC57A7499 ] C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
15:40:58.0921 3956 C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe - ok
15:40:58.0937 3956 [ C9564CF4976E7E96B4052737AA2492B4 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
15:40:58.0937 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll - ok
15:40:58.0937 3956 [ 0B3595A4FF0B36D68E5FC67FD7D70FDC ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
15:40:58.0937 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll - ok
15:40:58.0937 3956 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] C:\WINDOWS\system32\schedsvc.dll
15:40:58.0937 3956 C:\WINDOWS\system32\schedsvc.dll - ok
15:40:58.0953 3956 [ 746989EB81B6050163F86EBBBE44F260 ] C:\Program Files\CheckPoint\ZAForceField\ISWUL.dll
15:40:58.0953 3956 C:\Program Files\CheckPoint\ZAForceField\ISWUL.dll - ok
15:40:58.0953 3956 [ 085ED2E391A871C7BAE87E0228B546BA ] C:\WINDOWS\system32\cscui.dll
15:40:58.0953 3956 C:\WINDOWS\system32\cscui.dll - ok
15:40:58.0953 3956 [ E47E364C96467FD54FA44D59F927C3AB ] C:\WINDOWS\system32\msidle.dll
15:40:58.0953 3956 C:\WINDOWS\system32\msidle.dll - ok
15:40:58.0968 3956 [ 60784F891563FB1B767F70117FC2428F ] C:\WINDOWS\system32\spoolsv.exe
15:40:58.0968 3956 C:\WINDOWS\system32\spoolsv.exe - ok
15:40:58.0968 3956 [ 50A166237A0FA771261275A405646CC0 ] C:\WINDOWS\system32\powrprof.dll
15:40:58.0968 3956 C:\WINDOWS\system32\powrprof.dll - ok
15:40:58.0968 3956 [ 6C26DCF01E2A92F183B97D434017268A ] C:\WINDOWS\system32\dpcdll.dll
15:40:58.0968 3956 C:\WINDOWS\system32\dpcdll.dll - ok
15:40:58.0984 3956 [ DEF7A7882BEC100FE0B2CE2549188F9D ] C:\WINDOWS\system32\audiosrv.dll
15:40:58.0984 3956 C:\WINDOWS\system32\audiosrv.dll - ok
15:40:58.0984 3956 [ A8888A5327621856C0CEC4E385F69309 ] C:\WINDOWS\system32\wkssvc.dll
15:40:58.0984 3956 C:\WINDOWS\system32\wkssvc.dll - ok
15:40:59.0000 3956 [ 6FE42512AB1B89F32A7407F261B1D2D0 ] C:\WINDOWS\temp\IswTmp\WH\0
15:40:59.0000 3956 C:\WINDOWS\temp\IswTmp\WH\0 - ok
15:40:59.0000 3956 [ 71F503BAD4C1141067AECA573908B4E9 ] C:\Program Files\CheckPoint\ZAForceField\ZDXUI.dll
15:40:59.0000 3956 C:\Program Files\CheckPoint\ZAForceField\ZDXUI.dll - ok
15:40:59.0000 3956 [ 258444AC2AAD2A51820E6975D5A1F556 ] C:\Program Files\CheckPoint\ZAForceField\FFApi.dll
15:40:59.0000 3956 C:\Program Files\CheckPoint\ZAForceField\FFApi.dll - ok
15:40:59.0015 3956 [ C9DF1AA04B09228D746536A90F01C73C ] C:\Program Files\CheckPoint\ZAForceField\ISWUILib.dll
15:40:59.0015 3956 C:\Program Files\CheckPoint\ZAForceField\ISWUILib.dll - ok
15:40:59.0015 3956 [ 80776884E7A05D6DA5040926F82B0273 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll
15:40:59.0015 3956 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll - ok
15:40:59.0015 3956 [ 9A7803D33692D1F373A99F7594D3145F ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll
15:40:59.0015 3956 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll - ok
15:40:59.0031 3956 [ AEDE14835589701A3BE1CC2BD7470364 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWMENUS.dll
15:40:59.0031 3956 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWMENUS.dll - ok
15:40:59.0031 3956 [ 1A3FB4E84D8FE3801BE6B2220F1E38C4 ] C:\Program Files\CheckPoint\ZAForceField\Zdx.dll
15:40:59.0031 3956 C:\Program Files\CheckPoint\ZAForceField\Zdx.dll - ok
15:40:59.0031 3956 [ 59292F5B1A88218F442B4485D0FD5C41 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSTATS.dll
15:40:59.0031 3956 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSTATS.dll - ok
15:40:59.0046 3956 [ 662D13021A8E793615D55B1F7E741655 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll
15:40:59.0046 3956 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll - ok
15:40:59.0046 3956 [ 42DD9011D54C3A91F14BDBBF50791DA9 ] C:\Program Files\Microsoft Security Client\MsseWat.dll
15:40:59.0046 3956 C:\Program Files\Microsoft Security Client\MsseWat.dll - ok
15:40:59.0046 3956 [ 7C7AB513C5D9920ACAFFFF698C3E9529 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWUPD.dll
15:40:59.0046 3956 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWUPD.dll - ok
15:40:59.0062 3956 [ A26E0A6A7EBB45815A3583E170C27031 ] C:\Program Files\Microsoft Security Client\LegitLib.dll
15:40:59.0062 3956 C:\Program Files\Microsoft Security Client\LegitLib.dll - ok
15:40:59.0062 3956 [ 680B56A8B62D1BCF4A0B2AAAD03D88E4 ] C:\WINDOWS\system32\wdmaud.drv
15:40:59.0062 3956 C:\WINDOWS\system32\wdmaud.drv - ok
15:40:59.0062 3956 [ 6768ACF64B18196494413695F0C3A00F ] C:\WINDOWS\system32\drivers\wdmaud.sys
15:40:59.0062 3956 C:\WINDOWS\system32\drivers\wdmaud.sys - ok
15:40:59.0078 3956 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] C:\WINDOWS\system32\drivers\sysaudio.sys
15:40:59.0078 3956 C:\WINDOWS\system32\drivers\sysaudio.sys - ok
15:40:59.0078 3956 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] C:\WINDOWS\system32\drivers\splitter.sys
15:40:59.0078 3956 C:\WINDOWS\system32\drivers\splitter.sys - ok
15:40:59.0078 3956 [ 8BED39E3C35D6A489438B8141717A557 ] C:\WINDOWS\system32\drivers\aec.sys
15:40:59.0078 3956 C:\WINDOWS\system32\drivers\aec.sys - ok
15:40:59.0078 3956 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] C:\WINDOWS\system32\drivers\swmidi.sys
15:40:59.0078 3956 C:\WINDOWS\system32\drivers\swmidi.sys - ok
15:40:59.0125 3956 [ 8A208DFCF89792A484E76C40E5F50B45 ] C:\WINDOWS\system32\drivers\DMusic.sys
15:40:59.0125 3956 C:\WINDOWS\system32\drivers\DMusic.sys - ok
15:40:59.0125 3956 [ 692BCF44383D056AED41B045A323D378 ] C:\WINDOWS\system32\drivers\kmixer.sys
15:40:59.0125 3956 C:\WINDOWS\system32\drivers\kmixer.sys - ok
15:40:59.0125 3956 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] C:\WINDOWS\system32\drivers\drmkaud.sys
15:40:59.0125 3956 C:\WINDOWS\system32\drivers\drmkaud.sys - ok
15:40:59.0125 3956 [ 9A3BD5F55AADFF859539142F6328A66E ] C:\WINDOWS\system32\msacm32.drv
15:40:59.0125 3956 C:\WINDOWS\system32\msacm32.drv - ok
15:40:59.0140 3956 [ 5C12660A97822F6E61576943B49AAAD6 ] C:\WINDOWS\system32\midimap.dll
15:40:59.0140 3956 C:\WINDOWS\system32\midimap.dll - ok
15:40:59.0140 3956 [ A93AEE1928A9D7CE3E16D24EC7380F89 ] C:\WINDOWS\system32\userinit.exe
15:40:59.0140 3956 C:\WINDOWS\system32\userinit.exe - ok
15:40:59.0140 3956 [ F02A533F517EB38333CB12A9E8963773 ] C:\Program Files\Google\Update\GoogleUpdate.exe
15:40:59.0140 3956 C:\Program Files\Google\Update\GoogleUpdate.exe - ok
15:40:59.0156 3956 [ B1296D52B0D2096EC4759EEEB806D759 ] C:\WINDOWS\system32\WgaTray.exe
15:40:59.0156 3956 C:\WINDOWS\system32\WgaTray.exe - ok
15:40:59.0156 3956 [ 2E5672EEA419A4DC9DACD714632E1DC3 ] C:\Program Files\Google\Update\1.3.21.135\goopdate.dll
15:40:59.0156 3956 C:\Program Files\Google\Update\1.3.21.135\goopdate.dll - ok
15:40:59.0156 3956 [ D3F72D50DE53F9F1F55240115AF4D42E ] C:\WINDOWS\system32\msi.dll
15:40:59.0156 3956 C:\WINDOWS\system32\msi.dll - ok
15:40:59.0156 3956 [ 12896823FB95BFB3DC9B46BCAEDC9923 ] C:\WINDOWS\explorer.exe
15:40:59.0156 3956 C:\WINDOWS\explorer.exe - ok
15:40:59.0171 3956 [ DEFEE5DEDD20C1E15532E88D5A4F7C96 ] C:\WINDOWS\system32\browseui.dll
15:40:59.0171 3956 C:\WINDOWS\system32\browseui.dll - ok
15:40:59.0171 3956 [ 5E283C987ED4BB42323A3C722EEBC081 ] C:\WINDOWS\system32\shdocvw.dll
15:40:59.0171 3956 C:\WINDOWS\system32\shdocvw.dll - ok
15:40:59.0171 3956 [ CC26451A90025F6C55F64146C333DEA5 ] C:\WINDOWS\system32\LegitCheckControl.dll
15:40:59.0171 3956 C:\WINDOWS\system32\LegitCheckControl.dll - ok
15:40:59.0187 3956 [ B6E6F3F5B63053D5DC1F4EE32992492F ] C:\WINDOWS\system32\dbghelp.dll
15:40:59.0187 3956 C:\WINDOWS\system32\dbghelp.dll - ok
15:40:59.0187 3956 [ BECDDA0990DEBD72A30096533521AD73 ] C:\Program Files\Google\Update\1.3.21.135\GoogleCrashHandler.exe
15:40:59.0187 3956 C:\Program Files\Google\Update\1.3.21.135\GoogleCrashHandler.exe - ok
15:40:59.0187 3956 [ 4044E880593FE1AC9942190FCE414BE7 ] C:\WINDOWS\system32\mstask.dll
15:40:59.0187 3956 C:\WINDOWS\system32\mstask.dll - ok
15:40:59.0203 3956 [ 660C8E78B94F483E44B0243A774A4746 ] C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
15:40:59.0203 3956 C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL - ok
15:40:59.0203 3956 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] C:\WINDOWS\system32\drivers\mrxdav.sys
15:40:59.0203 3956 C:\WINDOWS\system32\drivers\mrxdav.sys - ok
15:40:59.0203 3956 [ 58A14C45A5CD2528F10A889E7B0C3FC2 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
15:40:59.0203 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll - ok
15:40:59.0218 3956 [ E9901A7E569C4156FDA69F5C9356B8ED ] C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE14\Cultures\OFFICE.ODF
15:40:59.0218 3956 C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE14\Cultures\OFFICE.ODF - ok
15:40:59.0218 3956 [ 77A354E28153AD2D5E120A5A8687BC06 ] C:\WINDOWS\system32\webclnt.dll
15:40:59.0218 3956 C:\WINDOWS\system32\webclnt.dll - ok
15:40:59.0218 3956 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] C:\WINDOWS\system32\drivers\parport.sys
15:40:59.0218 3956 C:\WINDOWS\system32\drivers\parport.sys - ok
15:40:59.0234 3956 [ 676CCC08D9E9A3F4CA39CB04E97048DF ] C:\PROGRA~1\MICROS~3\Office14\1033\GrooveIntlResource.dll
15:40:59.0234 3956 C:\PROGRA~1\MICROS~3\Office14\1033\GrooveIntlResource.dll - ok
15:40:59.0234 3956 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] C:\WINDOWS\system32\drivers\serial.sys
15:40:59.0234 3956 C:\WINDOWS\system32\drivers\serial.sys - ok
15:40:59.0234 3956 [ 4FE5C6D40664AE07BE5105874357D2ED ] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:40:59.0234 3956 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - ok
15:40:59.0250 3956 [ 92DA9EDE07390B4352B29DD82079E398 ] C:\Program Files\Common Files\Apple\Apple Application Support\AppleVersions.dll
15:40:59.0250 3956 C:\Program Files\Common Files\Apple\Apple Application Support\AppleVersions.dll - ok
15:40:59.0250 3956 [ 64894527838C86454E2F378FF39FA336 ] C:\Program Files\Common Files\Apple\Apple Application Support\YSCrashDump.dll
15:40:59.0250 3956 C:\Program Files\Common Files\Apple\Apple Application Support\YSCrashDump.dll - ok
15:40:59.0250 3956 [ EF8CD3C64EE9C08980D6D06CCCE46C68 ] C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll
15:40:59.0250 3956 C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll - ok
15:40:59.0265 3956 [ 638C7596B493F5F77DB9EF6BAD8FE46C ] C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll
15:40:59.0265 3956 C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll - ok
15:40:59.0265 3956 [ 78865ABC5F5D13190F8B35BD9044714A ] C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll
15:40:59.0265 3956 C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll - ok
15:40:59.0265 3956 [ FF9831030678C7B6D70BAC00F68F8976 ] C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll
15:40:59.0265 3956 C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll - ok
15:40:59.0281 3956 [ 5A963C340DE1A01BA6E24945CE05D16A ] C:\Program Files\Common Files\Apple\Apple Application Support\libicuin.dll
15:40:59.0281 3956 C:\Program Files\Common Files\Apple\Apple Application Support\libicuin.dll - ok
15:40:59.0281 3956 [ F4BC62990E7E5C29799A895B80FC3177 ] C:\Program Files\Common Files\Apple\Apple Application Support\libicuuc.dll
15:40:59.0281 3956 C:\Program Files\Common Files\Apple\Apple Application Support\libicuuc.dll - ok
15:40:59.0281 3956 [ 149D74E1128A86DC9CFB2851FBEA11EB ] C:\Program Files\Common Files\Apple\Apple Application Support\icudt46.dll
15:40:59.0281 3956 C:\Program Files\Common Files\Apple\Apple Application Support\icudt46.dll - ok
15:40:59.0296 3956 [ B4ED498E3BFEE64E952BC44FC6057DB8 ] C:\WINDOWS\system32\desk.cpl
15:40:59.0296 3956 C:\WINDOWS\system32\desk.cpl - ok
15:40:59.0296 3956 [ A314EEA2A503A8E04085201E436384A5 ] C:\WINDOWS\system32\themeui.dll
15:40:59.0296 3956 C:\WINDOWS\system32\themeui.dll - ok
15:40:59.0296 3956 [ 912B67BB8249925A5C972FC5839EAE09 ] C:\WINDOWS\system32\actxprxy.dll
15:40:59.0296 3956 C:\WINDOWS\system32\actxprxy.dll - ok
15:40:59.0312 3956 [ F6FD367C9EAAEDF90CD7A7952AE0B336 ] C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll
15:40:59.0312 3956 C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll - ok
15:40:59.0312 3956 [ 4327CF9A9D0864CA0FFC97FCDA97315A ] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll
15:40:59.0312 3956 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll - ok
15:40:59.0312 3956 [ 062373995EAE5F0EAC9EAA9192136BFB ] C:\WINDOWS\system32\dnssd.dll
15:40:59.0312 3956 C:\WINDOWS\system32\dnssd.dll - ok
15:40:59.0328 3956 [ 6D778E0F95447E6546553EEEA709D03C ] C:\WINDOWS\system32\cmd.exe
15:40:59.0328 3956 C:\WINDOWS\system32\cmd.exe - ok
15:40:59.0328 3956 [ 59570CA554C9D75E72241AC3252E84BD ] C:\WINDOWS\system32\ieframe.dll
15:40:59.0328 3956 C:\WINDOWS\system32\ieframe.dll - ok
15:40:59.0328 3956 [ 24665B221424FFD7B71F0D2C398F2F4F ] C:\Program Files\Common Files\Apple\Mobile Device Support\MobileDevice.dll
15:40:59.0328 3956 C:\Program Files\Common Files\Apple\Mobile Device Support\MobileDevice.dll - ok
15:40:59.0343 3956 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] C:\Program Files\Bonjour\mDNSResponder.exe
15:40:59.0343 3956 C:\Program Files\Bonjour\mDNSResponder.exe - ok
15:40:59.0343 3956 [ 574738F61FCA2935F5265DC4E5691314 ] C:\WINDOWS\system32\qmgr.dll
15:40:59.0343 3956 C:\WINDOWS\system32\qmgr.dll - ok
15:40:59.0343 3956 [ 57EDEC2E5F59F0335E92F35184BC8631 ] C:\WINDOWS\system32\dmserver.dll
15:40:59.0343 3956 C:\WINDOWS\system32\dmserver.dll - ok
15:40:59.0359 3956 [ BC93B4A066477954555966D77FEC9ECB ] C:\WINDOWS\system32\ersvc.dll
15:40:59.0359 3956 C:\WINDOWS\system32\ersvc.dll - ok
15:40:59.0359 3956 [ 96633419F4A1E37ACB89B45EBCCFE001 ] C:\WINDOWS\system32\FsUsbExService.Exe
15:40:59.0359 3956 C:\WINDOWS\system32\FsUsbExService.Exe - ok
15:40:59.0375 3956 [ 0B467F470CC9918FDCEEDCFD7DC4D697 ] C:\WINDOWS\system32\oledlg.dll
15:40:59.0375 3956 C:\WINDOWS\system32\oledlg.dll - ok
15:40:59.0375 3956 [ D4991D98F2DB73C60D042F1AEF79EFAE ] C:\WINDOWS\system32\es.dll
15:40:59.0375 3956 C:\WINDOWS\system32\es.dll - ok
15:40:59.0375 3956 [ 2E14406E05789F91C9282AE7CFCA3A07 ] C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
15:40:59.0375 3956 C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll - ok
15:40:59.0375 3956 [ 5652F6CE1D9E9D8068B9D29BC21B5409 ] C:\WINDOWS\system32\olepro32.dll
15:40:59.0375 3956 C:\WINDOWS\system32\olepro32.dll - ok
15:40:59.0390 3956 [ AF54247F97CCF3539DE7505C09972FF9 ] C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll
15:40:59.0390 3956 C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll - ok
15:40:59.0390 3956 [ 94FCCE83CDEE9C8149667110093E701E ] C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe
15:40:59.0390 3956 C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe - ok
15:40:59.0390 3956 [ C14AA05881A35B6D6BB8D55B117EE22D ] C:\WINDOWS\system32\shfolder.dll
15:40:59.0390 3956 C:\WINDOWS\system32\shfolder.dll - ok
15:40:59.0406 3956 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] C:\WINDOWS\system32\netman.dll
15:40:59.0406 3956 C:\WINDOWS\system32\netman.dll - ok
15:40:59.0406 3956 [ 062F837C1FBDB6A0A75F82EFC2EE8E74 ] C:\WINDOWS\system32\netshell.dll
15:40:59.0406 3956 C:\WINDOWS\system32\netshell.dll - ok
15:40:59.0406 3956 [ 8BA9851E671E8B5E49E303748FFD530C ] C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll
15:40:59.0406 3956 C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll - ok
15:40:59.0421 3956 [ 5E33C164DC7FA74728D8A83036C438BB ] C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
15:40:59.0421 3956 C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll - ok
15:40:59.0421 3956 [ E95911BD88EF967125724428772FDDD8 ] C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE
15:40:59.0421 3956 C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE - ok
15:40:59.0421 3956 [ 235892E493845D64D890163CFEF90E97 ] C:\WINDOWS\system32\credui.dll
15:40:59.0421 3956 C:\WINDOWS\system32\credui.dll - ok
15:40:59.0437 3956 [ 4E8F3230BAC8C1CAADF01A8C728E1C5C ] C:\WINDOWS\system32\dot3dlg.dll
15:40:59.0437 3956 C:\WINDOWS\system32\dot3dlg.dll - ok
15:40:59.0437 3956 [ CA04959077AFE36369D37B3504740C87 ] C:\WINDOWS\system32\onex.dll
15:40:59.0437 3956 C:\WINDOWS\system32\onex.dll - ok
15:40:59.0437 3956 [ 5DB625E7D095604010CF84DE2D8ACFA6 ] C:\WINDOWS\system32\eappcfg.dll
15:40:59.0437 3956 C:\WINDOWS\system32\eappcfg.dll - ok
15:40:59.0453 3956 [ ABC4206543450C0666D152F4B65833B8 ] C:\WINDOWS\system32\eappprxy.dll
15:40:59.0453 3956 C:\WINDOWS\system32\eappprxy.dll - ok
15:40:59.0453 3956 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
15:40:59.0453 3956 C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll - ok
15:40:59.0453 3956 [ DEB04DA35CC871B6D309B77E1443C796 ] C:\WINDOWS\system32\hidserv.dll
15:40:59.0453 3956 C:\WINDOWS\system32\hidserv.dll - ok
15:40:59.0453 3956 [ 8973122796E3B5D6B5900FC186E55FEA ] C:\WINDOWS\system32\hid.dll
15:40:59.0453 3956 C:\WINDOWS\system32\hid.dll - ok
15:40:59.0468 3956 [ DF446BA625CC441617843E87798CE048 ] C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
15:40:59.0468 3956 C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll - ok
15:40:59.0468 3956 [ B591E761161D1EF547D76EF236EAA6A5 ] C:\Program Files\Java\jre7\bin\jqs.exe
15:40:59.0468 3956 C:\Program Files\Java\jre7\bin\jqs.exe - ok
15:40:59.0468 3956 [ C83C0791FC7FA3CBE9BE2825B8A47EAF ] C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll
15:40:59.0468 3956 C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll - ok
15:40:59.0484 3956 [ 67EC459E42D3081DD8FD34356F7CAFC1 ] C:\Program Files\Java\jre7\bin\msvcr100.dll
15:40:59.0484 3956 C:\Program Files\Java\jre7\bin\msvcr100.dll - ok
15:40:59.0484 3956 [ 79E3A8C328E7E569C32B0998377D9742 ] C:\WINDOWS\system32\spoolss.dll
15:40:59.0484 3956 C:\WINDOWS\system32\spoolss.dll - ok
15:40:59.0500 3956 [ 62CF83A6989312A0DD39BBFFB3D1C166 ] C:\WINDOWS\system32\pdh.dll
15:40:59.0500 3956 C:\WINDOWS\system32\pdh.dll - ok
15:40:59.0500 3956 [ 5677DFE438EC1F009273FC84FEED6B10 ] C:\WINDOWS\system32\localspl.dll
15:40:59.0500 3956 C:\WINDOWS\system32\localspl.dll - ok
15:40:59.0500 3956 [ 369F7B1A4F358B976176556A1A331F36 ] C:\WINDOWS\system32\odbcbcp.dll
15:40:59.0500 3956 C:\WINDOWS\system32\odbcbcp.dll - ok
15:40:59.0515 3956 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] C:\WINDOWS\system32\srvsvc.dll
15:40:59.0515 3956 C:\WINDOWS\system32\srvsvc.dll - ok
15:40:59.0515 3956 [ 51C6D8BFBD4EA5B62A1BA7F4469250D3 ] C:\WINDOWS\system32\HPZinw12.dll
15:40:59.0515 3956 C:\WINDOWS\system32\HPZinw12.dll - ok
15:40:59.0515 3956 [ 5D3D1AB0EF4EA55B731863050482C111 ] C:\WINDOWS\system32\cnbjmon.dll
15:40:59.0515 3956 C:\WINDOWS\system32\cnbjmon.dll - ok
15:40:59.0531 3956 [ CE9B98EE57685CF61ABAEF078BA0C704 ] C:\WINDOWS\system32\hpzll5mu.dll
15:40:59.0531 3956 C:\WINDOWS\system32\hpzll5mu.dll - ok
15:40:59.0531 3956 [ 20FD44370267CCD0A64A1B31861C21D2 ] C:\WINDOWS\system32\netmsg.dll
15:40:59.0531 3956 C:\WINDOWS\system32\netmsg.dll - ok
15:40:59.0531 3956 [ 79834AA2FBF9FE81EEBB229024F6F7FC ] C:\WINDOWS\system32\HPZipm12.dll
15:40:59.0531 3956 C:\WINDOWS\system32\HPZipm12.dll - ok
15:40:59.0546 3956 [ 332760FBA1655FCFD35BD6F4FD871300 ] C:\WINDOWS\system32\ipsecsvc.dll
15:40:59.0546 3956 C:\WINDOWS\system32\ipsecsvc.dll - ok
15:40:59.0546 3956 [ ACDAFCD14EC0ECE89198503746A5C147 ] C:\WINDOWS\system32\perfos.dll
15:40:59.0546 3956 C:\WINDOWS\system32\perfos.dll - ok
15:40:59.0546 3956 [ ABFB673B24A9B3287761D497529FB5B9 ] C:\WINDOWS\system32\perfdisk.dll
15:40:59.0546 3956 C:\WINDOWS\system32\perfdisk.dll - ok
15:40:59.0562 3956 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] C:\WINDOWS\system32\drivers\srv.sys
15:40:59.0562 3956 C:\WINDOWS\system32\drivers\srv.sys - ok
15:40:59.0562 3956 [ C5FF8682EADA5B3B27A865F1C3EF9270 ] C:\WINDOWS\system32\oakley.dll
15:40:59.0562 3956 C:\WINDOWS\system32\oakley.dll - ok
15:40:59.0562 3956 [ 720FEA3AAA15FE7E0BEAB10AC2E6D2B0 ] C:\Program Files\Edimax\Common\RaRegistry.exe
15:40:59.0562 3956 C:\Program Files\Edimax\Common\RaRegistry.exe - ok
15:40:59.0578 3956 [ F1F4E6EAFE2CD5CD079B73233FB71CE8 ] C:\WINDOWS\system32\pdfcmon.dll
15:40:59.0578 3956 C:\WINDOWS\system32\pdfcmon.dll - ok
15:40:59.0578 3956 [ 222DE7F5EDB9DDBE628384A1A8BE59CE ] C:\WINDOWS\system32\pjlmon.dll
15:40:59.0578 3956 C:\WINDOWS\system32\pjlmon.dll - ok
15:40:59.0578 3956 [ AE0382AD9C73D343D85E1A50C80B7C20 ] C:\WINDOWS\system32\tcpmon.dll
15:40:59.0578 3956 C:\WINDOWS\system32\tcpmon.dll - ok
15:40:59.0578 3956 [ 248712EA6BA17B9FF0C542A3828375DD ] C:\WINDOWS\system32\winipsec.dll
15:40:59.0578 3956 C:\WINDOWS\system32\winipsec.dll - ok
15:40:59.0593 3956 [ 853D0D0C6F02D7BFDF1CF99DD7553732 ] C:\WINDOWS\system32\pstorsvc.dll
15:40:59.0593 3956 C:\WINDOWS\system32\pstorsvc.dll - ok
15:40:59.0593 3956 [ F26385E8BA4549B5186B774EC0E45D86 ] C:\WINDOWS\system32\usbmon.dll
15:40:59.0593 3956 C:\WINDOWS\system32\usbmon.dll - ok
15:40:59.0593 3956 [ D4EEBF6E9559689034BB628B437BE7E4 ] C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
15:40:59.0593 3956 C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll - ok
15:40:59.0609 3956 [ EEE7F12D9FF46F68FBC0DA059A359E9E ] C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
15:40:59.0609 3956 C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll - ok
15:40:59.0609 3956 [ 22DD6D7D4BFE2B8CE705CC950C8AEA4C ] C:\WINDOWS\system32\win32spl.dll
15:40:59.0609 3956 C:\WINDOWS\system32\win32spl.dll - ok
15:40:59.0625 3956 [ B41D53899E37CC43DA85DA19998BEE81 ] C:\WINDOWS\system32\netrap.dll
15:40:59.0625 3956 C:\WINDOWS\system32\netrap.dll - ok
15:40:59.0625 3956 [ EE4C651A217B01D636B5364AC77DA892 ] C:\WINDOWS\system32\inetpp.dll
15:40:59.0625 3956 C:\WINDOWS\system32\inetpp.dll - ok
15:40:59.0625 3956 [ 22D89D84E8E081CDA529DBF8C0255A38 ] C:\WINDOWS\system32\psbase.dll
15:40:59.0625 3956 C:\WINDOWS\system32\psbase.dll - ok
15:40:59.0640 3956 [ 5B19B557B0C188210A56A6B699D90B8F ] C:\WINDOWS\system32\regsvc.dll
15:40:59.0640 3956 C:\WINDOWS\system32\regsvc.dll - ok
15:40:59.0640 3956 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] C:\WINDOWS\system32\sens.dll
15:40:59.0640 3956 C:\WINDOWS\system32\sens.dll - ok
15:40:59.0640 3956 [ 83F41D0D89645D7235C051AB1D9523AC ] C:\WINDOWS\system32\ipnathlp.dll
15:40:59.0640 3956 C:\WINDOWS\system32\ipnathlp.dll - ok
15:40:59.0656 3956 [ FEDE68BF80052BAD393AFD5C2E60DCB0 ] C:\WINDOWS\system32\dssenh.dll
15:40:59.0656 3956 C:\WINDOWS\system32\dssenh.dll - ok
15:40:59.0656 3956 [ 3805DF0AC4296A34BA4BF93B346CC378 ] C:\WINDOWS\system32\srsvc.dll
15:40:59.0656 3956 C:\WINDOWS\system32\srsvc.dll - ok
15:40:59.0656 3956 [ CBE612E2BB6A10E3563336191EDA1250 ] C:\WINDOWS\system32\seclogon.dll
15:40:59.0656 3956 C:\WINDOWS\system32\seclogon.dll - ok
15:40:59.0671 3956 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] C:\WINDOWS\system32\wiaservc.dll
15:40:59.0671 3956 C:\WINDOWS\system32\wiaservc.dll - ok
15:40:59.0671 3956 [ 5F0CE62E0831CF972EC6949FD3E37DA7 ] C:\WINDOWS\system32\cfgmgr32.dll
15:40:59.0671 3956 C:\WINDOWS\system32\cfgmgr32.dll - ok
15:40:59.0671 3956 [ 4AC2FA4A6F0DF2511BAC13393C06EFF1 ] C:\WINDOWS\system32\mscms.dll
15:40:59.0671 3956 C:\WINDOWS\system32\mscms.dll - ok
15:40:59.0687 3956 [ A21E58F345F337316A98C5121CBE17E8 ] C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
15:40:59.0687 3956 C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe - ok
15:40:59.0687 3956 [ 93686F0550566CD85F93A6A4CC029476 ] C:\WINDOWS\system32\hpowiax7.dll
15:40:59.0687 3956 C:\WINDOWS\system32\hpowiax7.dll - ok
15:40:59.0687 3956 [ 55BCA12F7F523D35CA3CB833C725F54E ] C:\WINDOWS\system32\trkwks.dll
15:40:59.0687 3956 C:\WINDOWS\system32\trkwks.dll - ok
15:40:59.0703 3956 [ 2D0E4ED081963804CCC196A0929275B5 ] C:\WINDOWS\system32\wbem\wmisvc.dll
15:40:59.0703 3956 C:\WINDOWS\system32\wbem\wmisvc.dll - ok
15:40:59.0703 3956 [ BE0B3774113713059527FCF071CCDBFE ] C:\Program Files\Webroot\Washer\WasherSvc.exe
15:40:59.0703 3956 C:\Program Files\Webroot\Washer\WasherSvc.exe - ok
15:40:59.0703 3956 [ ACACB8B14E66109B8ACD6644B5574B9A ] C:\WINDOWS\system32\vssapi.dll
15:40:59.0703 3956 C:\WINDOWS\system32\vssapi.dll - ok
15:40:59.0718 3956 [ FC3EC24FCE372C89423E015A2AC1A31E ] C:\WINDOWS\system32\wuaueng.dll
15:40:59.0718 3956 C:\WINDOWS\system32\wuaueng.dll - ok
15:40:59.0718 3956 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] C:\WINDOWS\system32\wuauserv.dll
15:40:59.0718 3956 C:\WINDOWS\system32\wuauserv.dll - ok
15:40:59.0718 3956 [ B85E95679B5ADC12311BCD3F5385D623 ] C:\WINDOWS\system32\mspatcha.dll
15:40:59.0718 3956 C:\WINDOWS\system32\mspatcha.dll - ok
15:40:59.0734 3956 [ CFD4E51402DA9838B5A04AE680AF54A0 ] C:\WINDOWS\system32\browser.dll
15:40:59.0734 3956 C:\WINDOWS\system32\browser.dll - ok
15:40:59.0734 3956 [ F0BF811622F2DD6C8E26EE4600D83731 ] C:\WINDOWS\system32\wbem\wbemcore.dll
15:40:59.0734 3956 C:\WINDOWS\system32\wbem\wbemcore.dll - ok
15:40:59.0750 3956 [ E4616430709F440CF1809D88DC2366EA ] C:\WINDOWS\system32\wbem\esscli.dll
15:40:59.0750 3956 C:\WINDOWS\system32\wbem\esscli.dll - ok
15:40:59.0750 3956 [ 378A0AEFB11D8B0DC8C27B9F7604B88D ] C:\WINDOWS\system32\wbem\fastprox.dll
15:40:59.0750 3956 C:\WINDOWS\system32\wbem\fastprox.dll - ok
15:40:59.0750 3956 [ 7C278E6408D1DCE642230C0585A854D5 ] C:\WINDOWS\system32\wscsvc.dll
15:40:59.0750 3956 C:\WINDOWS\system32\wscsvc.dll - ok
15:40:59.0765 3956 [ 010472D0AE758227C6F6E6933549C219 ] C:\WINDOWS\system32\wbem\wbemsvc.dll
15:40:59.0765 3956 C:\WINDOWS\system32\wbem\wbemsvc.dll - ok
15:40:59.0765 3956 [ ED0C0DF222209E43AD9AFBF3FE87DDE0 ] C:\WINDOWS\system32\comsvcs.dll
15:40:59.0765 3956 C:\WINDOWS\system32\comsvcs.dll - ok
15:40:59.0765 3956 [ 690D97864735E8ECD87F55777E266690 ] C:\WINDOWS\system32\colbact.dll
15:40:59.0765 3956 C:\WINDOWS\system32\colbact.dll - ok
15:40:59.0781 3956 [ 36795A645EAA47FE31D2A8F136A2C69B ] C:\WINDOWS\system32\mtxclu.dll
15:40:59.0781 3956 C:\WINDOWS\system32\mtxclu.dll - ok
15:40:59.0781 3956 [ DF82E222578DBE59FCBBD69A02E4C806 ] C:\WINDOWS\system32\clusapi.dll
15:40:59.0781 3956 C:\WINDOWS\system32\clusapi.dll - ok
15:40:59.0781 3956 [ F51EBB6FC536A6B2D588FD668D3A8249 ] C:\WINDOWS\system32\resutils.dll
15:40:59.0781 3956 C:\WINDOWS\system32\resutils.dll - ok
15:40:59.0796 3956 [ 3273D1565BF30225C115B480A3BB2C9D ] C:\WINDOWS\system32\wbem\wmiutils.dll
15:40:59.0796 3956 C:\WINDOWS\system32\wbem\wmiutils.dll - ok
15:40:59.0796 3956 [ 942A17D2901A31EA68627CBFFCD268CC ] C:\WINDOWS\system32\wbem\repdrvfs.dll
15:40:59.0796 3956 C:\WINDOWS\system32\wbem\repdrvfs.dll - ok
15:40:59.0796 3956 [ 3458EDA96E30FBD0477A2800D3FB1909 ] C:\WINDOWS\system32\wups.dll
15:40:59.0796 3956 C:\WINDOWS\system32\wups.dll - ok
15:40:59.0812 3956 [ BDC0C99E472176C8C2C853A68ADC5073 ] C:\WINDOWS\system32\wups2.dll
15:40:59.0812 3956 C:\WINDOWS\system32\wups2.dll - ok
15:40:59.0812 3956 [ 2E0B0A051FFAA86E358465BB0880D453 ] C:\WINDOWS\system32\wuauclt.exe
15:40:59.0812 3956 C:\WINDOWS\system32\wuauclt.exe - ok
15:40:59.0812 3956 [ 071143F687B4F887E21461CA6CC7EB29 ] C:\WINDOWS\system32\wbem\wmiprvsd.dll
15:40:59.0812 3956 C:\WINDOWS\system32\wbem\wmiprvsd.dll - ok
15:40:59.0812 3956 [ 26D881D27CBE51D3614E68D7313EA026 ] C:\WINDOWS\system32\wbem\wbemess.dll
15:40:59.0812 3956 C:\WINDOWS\system32\wbem\wbemess.dll - ok
15:40:59.0828 3956 [ 1A617835452EEE5060976C9B9F5FE635 ] C:\WINDOWS\system32\wuapi.dll
15:40:59.0828 3956 C:\WINDOWS\system32\wuapi.dll - ok
15:40:59.0828 3956 [ D26451B540720A7313A9BCBE794DAF62 ] C:\WINDOWS\system32\wbem\ncprov.dll
15:40:59.0828 3956 C:\WINDOWS\system32\wbem\ncprov.dll - ok
15:40:59.0828 3956 [ A21C2A8E47D40FCC40A2B1573E666A53 ] C:\Program Files\Java\jre7\bin\awt.dll
15:40:59.0828 3956 C:\Program Files\Java\jre7\bin\awt.dll - ok
15:40:59.0843 3956 [ 966CD21542A62F9AB237D84C451CC137 ] C:\Program Files\Java\jre7\bin\client\jvm.dll
15:40:59.0843 3956 C:\Program Files\Java\jre7\bin\client\jvm.dll - ok
15:40:59.0843 3956 [ 90760987BCCCF34D05EF6093EC278A96 ] C:\Program Files\Java\jre7\bin\dcpr.dll
15:40:59.0843 3956 C:\Program Files\Java\jre7\bin\dcpr.dll - ok
15:40:59.0843 3956 [ D2D31D7A394A70040FCAC5F54A130FBA ] C:\Program Files\Java\jre7\bin\deploy.dll
15:40:59.0843 3956 C:\Program Files\Java\jre7\bin\deploy.dll - ok
15:40:59.0859 3956 [ C09775FEB73BDF16BB87A509C5FF12AD ] C:\Program Files\Java\jre7\bin\fontmanager.dll
15:40:59.0859 3956 C:\Program Files\Java\jre7\bin\fontmanager.dll - ok
15:40:59.0859 3956 [ B98F28229D292B99FF449FF3647F31BA ] C:\Program Files\Java\jre7\bin\java.dll
15:40:59.0859 3956 C:\Program Files\Java\jre7\bin\java.dll - ok
15:40:59.0875 3956 [ 23C84DBECF3BD95687623F23BCD66441 ] C:\Program Files\Java\jre7\bin\javaw.exe
15:40:59.0875 3956 C:\Program Files\Java\jre7\bin\javaw.exe - ok
15:40:59.0875 3956 [ 0384126B913AC2E090804C642302945E ] C:\Program Files\Java\jre7\bin\jp2native.dll
15:40:59.0875 3956 C:\Program Files\Java\jre7\bin\jp2native.dll - ok
15:40:59.0875 3956 [ CB91CCFA95601066772A004550B55A85 ] C:\Program Files\Java\jre7\bin\jpeg.dll
15:40:59.0875 3956 C:\Program Files\Java\jre7\bin\jpeg.dll - ok
15:40:59.0890 3956 [ 2E4A927544CDA0279501AA757FFFB538 ] C:\Program Files\Java\jre7\bin\net.dll
15:40:59.0890 3956 C:\Program Files\Java\jre7\bin\net.dll - ok
15:40:59.0890 3956 [ 805766A11E747A44C7C5FBD7F26E9001 ] C:\Program Files\Java\jre7\bin\nio.dll
15:40:59.0890 3956 C:\Program Files\Java\jre7\bin\nio.dll - ok
15:40:59.0890 3956 [ 2D168A9627CFCE9C5AC20A90E54D66D4 ] C:\Program Files\Java\jre7\bin\verify.dll
15:40:59.0890 3956 C:\Program Files\Java\jre7\bin\verify.dll - ok
15:40:59.0906 3956 [ 9D54D4A8C18081F398FEC0D839340542 ] C:\Program Files\Java\jre7\bin\zip.dll
15:40:59.0906 3956 C:\Program Files\Java\jre7\bin\zip.dll - ok
15:40:59.0906 3956 [ 178A34E5554DCE485E1262DDF027960C ] C:\DOCUME~1\CHRISC~1.MAI\LOCALS~1\temp\BA1F5266-0711-46EC-AF5E-FF1D5CAB9D30.exe
15:40:59.0906 3956 C:\DOCUME~1\CHRISC~1.MAI\LOCALS~1\temp\BA1F5266-0711-46EC-AF5E-FF1D5CAB9D30.exe - ok
15:40:59.0906 3956 [ A70A2D85AD143D6BB823C246CEB699A5 ] C:\WINDOWS\system32\ntshrui.dll
15:40:59.0906 3956 C:\WINDOWS\system32\ntshrui.dll - ok
15:40:59.0921 3956 [ 91790D6749EBED90E2C40479C0A91879 ] C:\WINDOWS\system32\verclsid.exe
15:40:59.0921 3956 C:\WINDOWS\system32\verclsid.exe - ok
15:40:59.0921 3956 [ 2DC5A8019E2387987905F77C664E4BE2 ] C:\WINDOWS\system32\linkinfo.dll
15:40:59.0921 3956 C:\WINDOWS\system32\linkinfo.dll - ok
15:40:59.0921 3956 [ 2DE1190196EE9555DB548A57622022EB ] C:\WINDOWS\system32\drprov.dll
15:40:59.0921 3956 C:\WINDOWS\system32\drprov.dll - ok
15:40:59.0937 3956 [ 36468087E22C57A83DF758B3F90DF73F ] C:\WINDOWS\system32\ntlanman.dll
15:40:59.0937 3956 C:\WINDOWS\system32\ntlanman.dll - ok
15:40:59.0937 3956 [ AC5DF42FE314C1446B1DAD237BFCFFE0 ] C:\WINDOWS\system32\netui0.dll
15:40:59.0937 3956 C:\WINDOWS\system32\netui0.dll - ok
15:40:59.0937 3956 [ ED5A816D8E11E03F1937AC3C56826EE4 ] C:\WINDOWS\system32\netui1.dll
15:40:59.0937 3956 C:\WINDOWS\system32\netui1.dll - ok
15:40:59.0937 3956 [ FB8F8EEC8D9C2157789472DD61CDC78B ] C:\WINDOWS\system32\davclnt.dll
15:40:59.0937 3956 C:\WINDOWS\system32\davclnt.dll - ok
15:40:59.0953 3956 [ CC8915DB4E33E8FB29CA0D2DBF75306E ] C:\WINDOWS\system32\webcheck.dll
15:40:59.0953 3956 C:\WINDOWS\system32\webcheck.dll - ok
15:40:59.0953 3956 [ 2A8681AEA24003040CA7D677BE9F1702 ] C:\WINDOWS\system32\drivers\01075761.sys
15:40:59.0953 3956 C:\WINDOWS\system32\drivers\01075761.sys - ok
15:40:59.0953 3956 [ 50512FC9B7878E3C2C147BC17326A7DB ] C:\WINDOWS\system32\stobject.dll
15:40:59.0953 3956 C:\WINDOWS\system32\stobject.dll - ok
15:40:59.0968 3956 [ 231A0B0E3BA7ABFE469A8262FAA1FD71 ] C:\WINDOWS\system32\batmeter.dll
15:40:59.0968 3956 C:\WINDOWS\system32\batmeter.dll - ok
15:40:59.0968 3956 [ 045E228F71C31901084B64BE59093499 ] C:\WINDOWS\system32\WPDShServiceObj.dll
15:40:59.0968 3956 C:\WINDOWS\system32\WPDShServiceObj.dll - ok
15:40:59.0968 3956 [ 01848B246695D84FD5592C40136A0014 ] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
15:40:59.0968 3956 C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe - ok
15:40:59.0984 3956 [ 538A270F35A713C360B7ED4168BB7521 ] C:\WINDOWS\system32\mydocs.dll
15:40:59.0984 3956 C:\WINDOWS\system32\mydocs.dll - ok
15:40:59.0984 3956 [ 310FEC9E7EBBCBA72E50EE633A47DC4D ] C:\Program Files\CheckPoint\ZoneAlarm\zpeng25.dll
15:40:59.0984 3956 C:\Program Files\CheckPoint\ZoneAlarm\zpeng25.dll - ok
15:41:00.0000 3956 [ 062F3DB9AFA9C3CE0DA52F28595C0C6D ] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
15:41:00.0000 3956 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe - ok
15:41:00.0000 3956 [ 46DA8E7484AC7A52CE1D6E428398724B ] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
15:41:00.0000 3956 C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe - ok
15:41:00.0000 3956 [ 22358578CB321F3325496A3723029409 ] C:\WINDOWS\system32\PortableDeviceTypes.dll
15:41:00.0000 3956 C:\WINDOWS\system32\PortableDeviceTypes.dll - ok
15:41:00.0015 3956 [ 9D45B2201D0ECF9F42136C7B99DEB8B2 ] C:\WINDOWS\system32\PortableDeviceApi.dll
15:41:00.0015 3956 C:\WINDOWS\system32\PortableDeviceApi.dll - ok
15:41:00.0015 3956 [ 9B9F8D422F06B241F71CBE77C64BDC97 ] C:\Program Files\Citrix\ICA Client\concentr.exe
15:41:00.0015 3956 C:\Program Files\Citrix\ICA Client\concentr.exe - ok
15:41:00.0031 3956 [ 9DE762386E27E268CBA42830D527BE73 ] C:\Program Files\Citrix\ICA Client\ctxmui.dll
15:41:00.0031 3956 C:\Program Files\Citrix\ICA Client\ctxmui.dll - ok
15:41:00.0031 3956 [ CFA5D9A6905C821C032772A910A341B0 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ConfigWizard.zip.dll
15:41:00.0031 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\ConfigWizard.zip.dll - ok
15:41:00.0062 3956 [ 0600CB2613BEA0C6C0987B58D56D77B9 ] C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
15:41:00.0062 3956 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe - ok
15:41:00.0062 3956 [ 6CB0F58B3A78AB669099DF4E46CC7072 ] C:\Program Files\Citrix\ICA Client\CCMSDK.dll
15:41:00.0062 3956 C:\Program Files\Citrix\ICA Client\CCMSDK.dll - ok
15:41:00.0078 3956 [ 498259BB20BF84E5C744485F68EBCC4C ] C:\Program Files\CheckPoint\ZoneAlarm\lib\DashBoard.zip.dll
15:41:00.0078 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\DashBoard.zip.dll - ok
15:41:00.0093 3956 [ E11831E14CC4E1DDA220E377A2D7EF84 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\LicenseUI.zip.dll
15:41:00.0093 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\LicenseUI.zip.dll - ok
15:41:00.0109 3956 [ 5C4F6C55B7CB111D686F597EAAE74B28 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\MainLoop.zip.dll
15:41:00.0109 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\MainLoop.zip.dll - ok
15:41:00.0109 3956 [ 3CB07566302BCEEB898DE270A0BEC175 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
15:41:00.0109 3956 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe - ok
15:41:00.0125 3956 [ CAC6E79015AF82A3B5422FC988E3F08E ] C:\Program Files\CheckPoint\ZoneAlarm\lib\NavBar.zip.dll
15:41:00.0125 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\NavBar.zip.dll - ok
15:41:00.0125 3956 [ F4F7EE79D2BD88B6DEC9C117883F30B9 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\Overview.zip.dll
15:41:00.0125 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\Overview.zip.dll - ok
15:41:00.0140 3956 [ 813559706D756D82A56B779DC2749122 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\TrayTest.zip.dll
15:41:00.0140 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\TrayTest.zip.dll - ok
15:41:00.0140 3956 [ 5656D65A9A9F1E3D68D64A350CFF1732 ] C:\WINDOWS\system32\igfxtray.exe
15:41:00.0140 3956 C:\WINDOWS\system32\igfxtray.exe - ok
15:41:00.0156 3956 [ BFB52A1AA31FA93DA9926A58AF45EF82 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\UpdateUI.zip.dll
15:41:00.0156 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\UpdateUI.zip.dll - ok
15:41:00.0156 3956 [ ABBECE951B2AA6ED4E242E1CDF1BD0FE ] C:\Program Files\Citrix\ICA Client\resource\en\ctxmuiUI.dll
15:41:00.0156 3956 C:\Program Files\Citrix\ICA Client\resource\en\ctxmuiUI.dll - ok
15:41:00.0171 3956 [ 12BC9635B32DBEBB6C92DC7FB90FEDB2 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ZAlert.zip.dll
15:41:00.0171 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\ZAlert.zip.dll - ok
15:41:00.0171 3956 [ 218FA5991E1B47C8315CEB6A29CFE081 ] C:\Program Files\Citrix\ICA Client\resource\en\concenUI.dll
15:41:00.0171 3956 C:\Program Files\Citrix\ICA Client\resource\en\concenUI.dll - ok
15:41:00.0187 3956 [ 035029D2B692A5C73BECF7331F9C65B5 ] C:\WINDOWS\system32\hccutils.dll
15:41:00.0187 3956 C:\WINDOWS\system32\hccutils.dll - ok
15:41:00.0187 3956 [ D3C5CCD59F260C020D9F8D90CE7BF4FC ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ZClient.zip.dll
15:41:00.0187 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\ZClient.zip.dll - ok
15:41:00.0203 3956 [ 3F533D75631178A880AEFFDF117213BE ] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon_main.dll
15:41:00.0203 3956 C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon_main.dll - ok
15:41:00.0203 3956 [ 82ADC58B63E069AC4641A33EA9841E54 ] C:\WINDOWS\system32\hkcmd.exe
15:41:00.0203 3956 C:\WINDOWS\system32\hkcmd.exe - ok
15:41:00.0203 3956 [ D75F2D43C62DB1387656C1FC674DEE83 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zfde.zip.dll
15:41:00.0203 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\zfde.zip.dll - ok
15:41:00.0218 3956 [ D49C001BE285F727F24C75472705D5E7 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zmenu.zip.dll
15:41:00.0218 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\zmenu.zip.dll - ok
15:41:00.0218 3956 [ A0E2FFB7B0FCE82AA3BCC3105306C45C ] C:\WINDOWS\system32\igfxpers.exe
15:41:00.0218 3956 C:\WINDOWS\system32\igfxpers.exe - ok
15:41:00.0218 3956 [ 88A085071ED623D3792858D4D600E347 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zpy.zip.dll
15:41:00.0218 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\zpy.zip.dll - ok
15:41:00.0234 3956 [ 941A08CBDEEDF16B6C986B6BA7C9A5D0 ] C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
15:41:00.0234 3956 C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe - ok
15:41:00.0250 3956 [ 2888E77950D6E98A1B1D1BBD05FA4887 ] C:\WINDOWS\system32\igfxsrvc.exe
15:41:00.0250 3956 C:\WINDOWS\system32\igfxsrvc.exe - ok
15:41:00.0250 3956 [ C4E457DB4542C0707293EF03B2A6A9BA ] C:\Program Files\Citrix\ICA Client\wfcrun32.exe
15:41:00.0250 3956 C:\Program Files\Citrix\ICA Client\wfcrun32.exe - ok
15:41:00.0265 3956 [ 4928AB3A304DDF05C354DE3807A4A66B ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
15:41:00.0265 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll - ok
15:41:00.0265 3956 [ 12916E0642E92561C98B18A2A2D01B14 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
15:41:00.0265 3956 C:\Program Files\Common Files\Java\Java Update\jusched.exe - ok
15:41:00.0265 3956 [ 425DA3E03D3B3FA308D30A2A682B6499 ] C:\Program Files\Citrix\ICA Client\ProgressNotificationCommon.dll
15:41:00.0265 3956 C:\Program Files\Citrix\ICA Client\ProgressNotificationCommon.dll - ok
15:41:00.0281 3956 [ 8E2A7F1F62467A7DCB8AB2C0642F47CA ] C:\Program Files\iTunes\iTunesHelper.exe
15:41:00.0281 3956 C:\Program Files\iTunes\iTunesHelper.exe - ok
15:41:00.0281 3956 [ F2012DA44521414574C3191E2FABF24D ] C:\Program Files\Citrix\ICA Client\wfcwinn.dll
15:41:00.0281 3956 C:\Program Files\Citrix\ICA Client\wfcwinn.dll - ok
15:41:00.0281 3956 [ FA45A2EBB9419CED0A4BF9C9E9BF4498 ] C:\Program Files\Citrix\ICA Client\acrdlg.dll
15:41:00.0281 3956 C:\Program Files\Citrix\ICA Client\acrdlg.dll - ok
15:41:00.0296 3956 [ 7EF9AA6D19A6962383EFF5E570BE0CC1 ] C:\Program Files\Citrix\ICA Client\statuin.dll
15:41:00.0296 3956 C:\Program Files\Citrix\ICA Client\statuin.dll - ok
15:41:00.0296 3956 [ 4D2F7561D8A840450AABFAD3740B0E6B ] C:\Program Files\Microsoft Security Client\msseces.exe
15:41:00.0296 3956 C:\Program Files\Microsoft Security Client\msseces.exe - ok
15:41:00.0296 3956 [ 5082BC510FAD849630D09DA626BB7CDA ] C:\Program Files\iTunes\iTunesHelper.dll
15:41:00.0296 3956 C:\Program Files\iTunes\iTunesHelper.dll - ok
15:41:00.0312 3956 [ 348CBCBAF2179567FF0098B756F02E57 ] C:\Program Files\Citrix\ICA Client\confmgr.dll
15:41:00.0312 3956 C:\Program Files\Citrix\ICA Client\confmgr.dll - ok
15:41:00.0312 3956 [ A0A085DCB1DE464E3BCE8A1835967E6A ] C:\Program Files\Citrix\ICA Client\ctxlogging.dll
15:41:00.0312 3956 C:\Program Files\Citrix\ICA Client\ctxlogging.dll - ok
15:41:00.0312 3956 [ F27E6F727D8DB8A92D73513FC42201AA ] C:\Program Files\Citrix\ICA Client\icafile.dll
15:41:00.0312 3956 C:\Program Files\Citrix\ICA Client\icafile.dll - ok
15:41:00.0328 3956 [ 3CAEAE7608F1BD7BA873A3B02895B106 ] C:\WINDOWS\system32\sti.dll
15:41:00.0328 3956 C:\WINDOWS\system32\sti.dll - ok
15:41:00.0328 3956 [ 5B5FEA463340EE5DCE98F1A44E368E5A ] C:\Program Files\Webroot\Washer\wwDisp.exe
15:41:00.0328 3956 C:\Program Files\Webroot\Washer\wwDisp.exe - ok
15:41:00.0328 3956 [ 90098BD6DCBCCD8428F0A6668A28C42F ] C:\Program Files\Citrix\ICA Client\cst.dll
15:41:00.0328 3956 C:\Program Files\Citrix\ICA Client\cst.dll - ok
15:41:00.0328 3956 [ C35BD7743F5F928D503A5C0C1F877140 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zsys.zip.dll
15:41:00.0328 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\zsys.zip.dll - ok
15:41:00.0343 3956 [ D8584C7FB9A1BA8480F9000C1CA1B415 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
15:41:00.0343 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll - ok
15:41:00.0343 3956 [ F7AD9D0D7BE3C97FA0A802678B3AFF5F ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ztv.zip.dll
15:41:00.0343 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\ztv.zip.dll - ok
15:41:00.0343 3956 [ DBB3918350E09D38E164BE6851600D22 ] C:\Program Files\Citrix\ICA Client\resource\en\ProgressNotificationCommonUI.dll
15:41:00.0343 3956 C:\Program Files\Citrix\ICA Client\resource\en\ProgressNotificationCommonUI.dll - ok
15:41:00.0359 3956 [ BE643CD44DD06DA283634A3E51DC22BC ] C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.dll
15:41:00.0359 3956 C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.dll - ok
15:41:00.0359 3956 [ AFEEAFD7CF8ED6958A81ACC304C17B7D ] C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.dll
15:41:00.0359 3956 C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.dll - ok
15:41:00.0375 3956 [ F7FD34F43260D587F393305A97A9C2C4 ] C:\Program Files\Citrix\ICA Client\resource\en\statuiUI.dll
15:41:00.0375 3956 C:\Program Files\Citrix\ICA Client\resource\en\statuiUI.dll - ok
15:41:00.0375 3956 [ 965F92D5D32B3584EAE533D9F37DDDCF ] C:\WINDOWS\system32\igfxsrvc.dll
15:41:00.0375 3956 C:\WINDOWS\system32\igfxsrvc.dll - ok
15:41:00.0375 3956 [ 18C288F56F1D670682D64807914413BF ] C:\WINDOWS\system32\igfxdev.dll
15:41:00.0375 3956 C:\WINDOWS\system32\igfxdev.dll - ok
15:41:00.0390 3956 [ 0C1C620EE9A45032A720B9C8D20B0B8E ] C:\PROGRA~1\GFI\GFIBAC~1\GFIAgent.exe
15:41:00.0390 3956 C:\PROGRA~1\GFI\GFIBAC~1\GFIAgent.exe - ok
15:41:00.0390 3956 [ 5F687D7F798FD20C6B11B13F0B006037 ] C:\Program Files\Citrix\ICA Client\resource\en\cstUI.dll
15:41:00.0390 3956 C:\Program Files\Citrix\ICA Client\resource\en\cstUI.dll - ok
15:41:00.0390 3956 [ D331352334CF6F529DBFA73C391F85A9 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zui.zip.dll
15:41:00.0390 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\zui.zip.dll - ok
15:41:00.0406 3956 [ 6B3CDFD6A7903561B5ACAF5535927204 ] C:\WINDOWS\system32\igfxres.dll
15:41:00.0406 3956 C:\WINDOWS\system32\igfxres.dll - ok
15:41:00.0406 3956 [ 1E377D64DACD4E4656C86241CE5A1233 ] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
15:41:00.0406 3956 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe - ok
15:41:00.0406 3956 [ 22D71D1DB6FC789A1CE8AC6963580259 ] C:\WINDOWS\system32\hhctrl.ocx
15:41:00.0406 3956 C:\WINDOWS\system32\hhctrl.ocx - ok
15:41:00.0421 3956 [ 80AE01677E4B5D296A9C4E09FE66AA22 ] C:\Program Files\Citrix\ICA Client\resource\en\wfcrunUI.dll
15:41:00.0421 3956 C:\Program Files\Citrix\ICA Client\resource\en\wfcrunUI.dll - ok
15:41:00.0421 3956 [ 686B224B4987C22B153FBB545FEE9657 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
15:41:00.0421 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll - ok
15:41:00.0421 3956 [ 448B572F9505CE50A21BBD9312AEAAB4 ] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
15:41:00.0421 3956 C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe - ok
15:41:00.0437 3956 [ C03E8D9F44FC4E57BEDB41240FF96855 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpui.pyd
15:41:00.0437 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpui.pyd - ok
15:41:00.0437 3956 [ 5F1D5F88303D4A4DBC8E5F97BA967CC3 ] C:\WINDOWS\system32\ctfmon.exe
15:41:00.0437 3956 C:\WINDOWS\system32\ctfmon.exe - ok
15:41:00.0437 3956 [ 118D81523EA80B9E252CB840E94754C6 ] C:\Program Files\Microsoft Security Client\EppManifest.dll
15:41:00.0437 3956 C:\Program Files\Microsoft Security Client\EppManifest.dll - ok
15:41:00.0453 3956 [ 40C53C82AEEE5E20EF655BFCAA78735C ] C:\Program Files\Citrix\ICA Client\CCMProxy.dll
15:41:00.0453 3956 C:\Program Files\Citrix\ICA Client\CCMProxy.dll - ok
15:41:00.0453 3956 [ E40FCF943127DDC8FD60554B722D762B ] C:\WINDOWS\system32\MSCTF.dll
15:41:00.0453 3956 C:\WINDOWS\system32\MSCTF.dll - ok
15:41:00.0453 3956 [ 855F6333E3A4DFC6F3C8B0520C261FCD ] C:\WINDOWS\system32\msftedit.dll
15:41:00.0453 3956 C:\WINDOWS\system32\msftedit.dll - ok
15:41:00.0453 3956 [ 17AA58A54C00F1746B8654C050491F43 ] C:\WINDOWS\system32\msutb.dll
15:41:00.0453 3956 C:\WINDOWS\system32\msutb.dll - ok
15:41:00.0468 3956 [ EF8E5E4FD6C023B1E6F26E947EDD1DD4 ] C:\Program Files\CheckPoint\ZoneAlarm\zhtml.dll
15:41:00.0468 3956 C:\Program Files\CheckPoint\ZoneAlarm\zhtml.dll - ok
15:41:00.0468 3956 [ F6FAEC07446A78A9C5AF4558FF5BD118 ] C:\WINDOWS\ime\SPTIP.dll
15:41:00.0468 3956 C:\WINDOWS\ime\SPTIP.dll - ok
15:41:00.0468 3956 [ 562750567E899AC3C8D25A4B704F75AD ] C:\Program Files\Webroot\Washer\Languages\English.dll
15:41:00.0468 3956 C:\Program Files\Webroot\Washer\Languages\English.dll - ok
15:41:00.0484 3956 [ 37CF3324F46CEB3A4F2686C617CBB35C ] C:\Program Files\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll
15:41:00.0484 3956 C:\Program Files\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll - ok
15:41:00.0484 3956 [ B12C853961947ED89B9437966C7507B4 ] C:\Program Files\Samsung\Samsung New PC Studio\rapi.dll
15:41:00.0484 3956 C:\Program Files\Samsung\Samsung New PC Studio\rapi.dll - ok
15:41:00.0500 3956 [ 88BEEF09C654252F3E46B6167B7F4ECB ] C:\WINDOWS\system32\msisip.dll
15:41:00.0500 3956 C:\WINDOWS\system32\msisip.dll - ok
15:41:00.0500 3956 [ 43CCB246B3D0C385E54F14B04DF96E9F ] C:\Program Files\Samsung\Samsung New PC Studio\ceutil.dll
15:41:00.0500 3956 C:\Program Files\Samsung\Samsung New PC Studio\ceutil.dll - ok
15:41:00.0500 3956 [ 3A6D465F379E5C815F4AD565391E654C ] C:\WINDOWS\system32\wshext.dll
15:41:00.0500 3956 C:\WINDOWS\system32\wshext.dll - ok
15:41:00.0515 3956 [ D4931277DF5393E84A48B27DF40914E3 ] C:\WINDOWS\system32\riched32.dll
15:41:00.0515 3956 C:\WINDOWS\system32\riched32.dll - ok
15:41:00.0515 3956 [ F36BC7FB3A87DE9138AAECC40F7BC116 ] C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
15:41:00.0515 3956 C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll - ok
15:41:00.0515 3956 [ D9335549EAE48B14FB66EFCB6FFAE736 ] C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
15:41:00.0515 3956 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - ok
15:41:00.0531 3956 [ D475BBD6FEF8DB2DDE0DA7CCFD2C9042 ] C:\Program Files\Microsoft Security Client\SqmApi.dll
15:41:00.0531 3956 C:\Program Files\Microsoft Security Client\SqmApi.dll - ok
15:41:00.0531 3956 [ 69EE0CB3B05F619EFF7E46F978BBFEEA ] C:\WINDOWS\system32\asycfilt.dll
15:41:00.0531 3956 C:\WINDOWS\system32\asycfilt.dll - ok
15:41:00.0531 3956 [ 9E03DC5AB51CFD0190541CE2038D819D ] C:\WINDOWS\system32\usp10.dll
15:41:00.0531 3956 C:\WINDOWS\system32\usp10.dll - ok
15:41:00.0546 3956 [ AFDF60D3DC76BB725E2DDEB19BC16179 ] C:\Program Files\Edimax\Common\RaUI.exe
15:41:00.0546 3956 C:\Program Files\Edimax\Common\RaUI.exe - ok
15:41:00.0546 3956 [ 944FAEDBC4136707B76FB3086C9B1080 ] C:\Program Files\Webroot\Washer\WashIdx.exe
15:41:00.0546 3956 C:\Program Files\Webroot\Washer\WashIdx.exe - ok
15:41:00.0546 3956 [ 1FAE4969D8C1188F25509AE37F2732A4 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_ctypes.pyd
15:41:00.0546 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_ctypes.pyd - ok
15:41:00.0546 3956 [ 3EE222B084E86A34690012274A963FDF ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpdx.pyd
15:41:00.0546 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpdx.pyd - ok
15:41:00.0562 3956 [ 085AFA1FEBBD1C26CFD035122A8D36E9 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\pyexpat.pyd
15:41:00.0562 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\pyexpat.pyd - ok
15:41:00.0562 3956 [ DE628C450E3AEA8C25619B8B5BD4504F ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_socket.pyd
15:41:00.0562 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_socket.pyd - ok
15:41:00.0562 3956 [ 95EAFC02EA102B5AA683823B60FEF053 ] C:\Program Files\Edimax\Common\RaWLAPI.dll
15:41:00.0562 3956 C:\Program Files\Edimax\Common\RaWLAPI.dll - ok
15:41:00.0578 3956 [ 88A17CDE56BB9539C5D456F3D7CD1A0D ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zptv.pyd
15:41:00.0578 3956 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zptv.pyd - ok
15:41:00.0578 3956 [ 0AED8EAE3B351917FCA60AB741582A1E ] C:\Program Files\CheckPoint\ZoneAlarm\vspubapi.dll
15:41:00.0578 3956 C:\Program Files\CheckPoint\ZoneAlarm\vspubapi.dll - ok
15:41:00.0593 3956 [ DFD6589D0312D67B53A3468B88D06FC8 ] C:\WINDOWS\system32\Scutum.dll
15:41:00.0593 3956 C:\WINDOWS\system32\Scutum.dll - ok
15:41:00.0593 3956 [ 87FDE73EE2FD2AFFF64AD86EEAB4A8FA ] C:\WINDOWS\system32\DiagFunc.dll
15:41:00.0593 3956 C:\WINDOWS\system32\DiagFunc.dll - ok
15:41:00.0593 3956 [ A749AFABDDEDE3FD170D93A172C08AD9 ] C:\WINDOWS\system32\W32N55.dll
15:41:00.0593 3956 C:\WINDOWS\system32\W32N55.dll - ok
15:41:00.0609 3956 [ CDF9BD825AAE8B33F56A7FA6B42BFEB2 ] C:\WINDOWS\system32\libeay32.dll
15:41:00.0609 3956 C:\WINDOWS\system32\libeay32.dll - ok
15:41:00.0609 3956 [ 9C7D0E8D0A39DA0BFB26BB5FB76C03ED ] C:\WINDOWS\system32\ssleay32.dll
15:41:00.0609 3956 C:\WINDOWS\system32\ssleay32.dll - ok
15:41:00.0609 3956 [ 798A9E6828997EEF4517ADA8A2259831 ] C:\WINDOWS\system32\wbem\wmiprvse.exe
15:41:00.0609 3956 C:\WINDOWS\system32\wbem\wmiprvse.exe - ok
15:41:00.0625 3956 [ 8A7A42B60DD07FC30A451A60DD37EBAA ] C:\Program Files\CheckPoint\ZoneAlarm\vsmonapi.dll
15:41:00.0625 3956 C:\Program Files\CheckPoint\ZoneAlarm\vsmonapi.dll - ok
15:41:00.0625 3956 [ 960F6D3CD9A1BA6435D7AADD102B297F ] C:\WINDOWS\system32\wbem\wmiprov.dll
15:41:00.0625 3956 C:\WINDOWS\system32\wbem\wmiprov.dll - ok
15:41:00.0625 3956 [ E837FDBB92E9873E538395B623F45462 ] C:\WINDOWS\system32\wbem\cimwin32.dll
15:41:00.0625 3956 C:\WINDOWS\system32\wbem\cimwin32.dll - ok
15:41:00.0640 3956 [ 4306FA2F1099D7C606139255FDB62B19 ] C:\WINDOWS\system32\wbem\framedyn.dll
15:41:00.0640 3956 C:\WINDOWS\system32\wbem\framedyn.dll - ok
15:41:00.0640 3956 [ 8BCD11D38FCE43A519246A91CC40DE6A ] C:\WINDOWS\system32\security.dll
15:41:00.0640 3956 C:\WINDOWS\system32\security.dll - ok
15:41:00.0640 3956 [ C730F70351D950DDA7388C9A9763CF54 ] C:\WINDOWS\system32\wbem\wmipcima.dll
15:41:00.0640 3956 C:\WINDOWS\system32\wbem\wmipcima.dll - ok
15:41:00.0656 3956 [ 6404807ABC7AF52FA3792697AE638B50 ] C:\WINDOWS\system32\wbem\wbemcons.dll
15:41:00.0656 3956 C:\WINDOWS\system32\wbem\wbemcons.dll - ok
15:41:00.0656 3956 [ 3CB78C17BB664637787C9A1C98F79C38 ] C:\WINDOWS\system32\tapisrv.dll
15:41:00.0656 3956 C:\WINDOWS\system32\tapisrv.dll - ok
15:41:00.0656 3956 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] C:\WINDOWS\system32\rasmans.dll
15:41:00.0656 3956 C:\WINDOWS\system32\rasmans.dll - ok
15:41:00.0671 3956 [ FF3477C03BE7201C294C35F684B3479F ] C:\WINDOWS\system32\termsrv.dll
15:41:00.0671 3956 C:\WINDOWS\system32\termsrv.dll - ok
15:41:00.0671 3956 [ 37A62C6092AADD2EFDE0468DD8818E99 ] C:\WINDOWS\system32\netcfgx.dll
15:41:00.0671 3956 C:\WINDOWS\system32\netcfgx.dll - ok
15:41:00.0671 3956 [ DF6551E4C4C46655A0C76194F1FCEA5D ] C:\WINDOWS\system32\icaapi.dll
15:41:00.0671 3956 C:\WINDOWS\system32\icaapi.dll - ok
15:41:00.0687 3956 [ 2D65D56C2F8B6CC5EBFF8E7200C30304 ] C:\WINDOWS\system32\mstlsapi.dll
15:41:00.0687 3956 C:\WINDOWS\system32\mstlsapi.dll - ok
15:41:00.0687 3956 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] C:\WINDOWS\system32\imapi.exe
15:41:00.0687 3956 C:\WINDOWS\system32\imapi.exe - ok
15:41:00.0687 3956 [ 93C088C2AEB2F23E720BDA7E32BD5117 ] C:\WINDOWS\system32\upnp.dll
15:41:00.0687 3956 C:\WINDOWS\system32\upnp.dll - ok
15:41:00.0703 3956 [ F50F7984FDD151EDD8A70A8DBD9E2A44 ] C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
15:41:00.0703 3956 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll - ok
15:41:00.0703 3956 [ 6895427873D6C37A6D6DA7C3DB37DA14 ] C:\WINDOWS\system32\licwmi.dll
15:41:00.0703 3956 C:\WINDOWS\system32\licwmi.dll - ok
15:41:00.0703 3956 [ 3D075865DCC26931972F6476AD0497BE ] C:\WINDOWS\system32\ssdpapi.dll
15:41:00.0703 3956 C:\WINDOWS\system32\ssdpapi.dll - ok
15:41:00.0718 3956 [ CBE5F69A5E5B918225F420BA748F3742 ] C:\WINDOWS\system32\FsUsbExDisk.Sys
15:41:00.0718 3956 C:\WINDOWS\system32\FsUsbExDisk.Sys - ok
15:41:00.0734 3956 [ 5F7692CEC90E2E9AA32CD58321E234B8 ] C:\WINDOWS\system32\rastapi.dll
15:41:00.0734 3956 C:\WINDOWS\system32\rastapi.dll - ok
15:41:00.0734 3956 [ E46B17060D3962A384AE484094614788 ] C:\Program Files\iPod\bin\iPodService.exe
15:41:00.0734 3956 C:\Program Files\iPod\bin\iPodService.exe - ok
15:41:00.0750 3956 [ A693A49A67673F2C8D76797EA9A628D0 ] C:\WINDOWS\system32\licdll.dll
15:41:00.0750 3956 C:\WINDOWS\system32\licdll.dll - ok
15:41:00.0750 3956 [ AACE07FE34FADDDF973CE068A6424957 ] C:\WINDOWS\system32\unimdm.tsp
15:41:00.0750 3956 C:\WINDOWS\system32\unimdm.tsp - ok
15:41:00.0750 3956 [ 715AB41A22E0DE693CB101639070D3BE ] C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll
15:41:00.0750 3956 C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll - ok
15:41:00.0750 3956 [ 995252FCC4692B5B97EE17D596C9386E ] C:\WINDOWS\system32\uniplat.dll
15:41:00.0765 3956 C:\WINDOWS\system32\uniplat.dll - ok
15:41:00.0765 3956 [ F80A415EF82CD06FFAF0D971528EAD38 ] C:\WINDOWS\system32\drivers\http.sys
15:41:00.0765 3956 C:\WINDOWS\system32\drivers\http.sys - ok
15:41:00.0765 3956 [ 691BAF41144EBDE972A66C5EB5210FC8 ] C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.dll
15:41:00.0765 3956 C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.dll - ok
15:41:00.0765 3956 [ 665FBA44C65BAC9EE8AF9A5E37036640 ] C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll
15:41:00.0765 3956 C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll - ok
15:41:00.0781 3956 [ 5A4B93F78473F397C332A0BF6B8F093F ] C:\WINDOWS\system32\wbem\mofd.dll
15:41:00.0781 3956 C:\WINDOWS\system32\wbem\mofd.dll - ok
15:41:00.0781 3956 [ 0A5679B3714EDAB99E357057EE88FCA6 ] C:\WINDOWS\system32\ssdpsrv.dll
15:41:00.0781 3956 C:\WINDOWS\system32\ssdpsrv.dll - ok
15:41:00.0781 3956 [ F89E2E5B554CCEB5FCD344349C78FDED ] C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
15:41:00.0781 3956 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc - ok
15:41:00.0796 3956 [ 76EC97C5068D3D9FAA7774B0F659D31A ] C:\WINDOWS\system32\kmddsp.tsp
15:41:00.0796 3956 C:\WINDOWS\system32\kmddsp.tsp - ok
15:41:00.0796 3956 [ 8C515081584A38AA007909CD02020B3D ] C:\WINDOWS\system32\alg.exe
15:41:00.0796 3956 C:\WINDOWS\system32\alg.exe - ok
15:41:00.0796 3956 [ 4589963D84F2984FA5949A72162BA4F4 ] C:\WINDOWS\system32\ndptsp.tsp
15:41:00.0796 3956 C:\WINDOWS\system32\ndptsp.tsp - ok
15:41:00.0812 3956 [ 8B8A45DF7CEF36D93C7BD3E4C84003B8 ] C:\WINDOWS\system32\ipconf.tsp
15:41:00.0812 3956 C:\WINDOWS\system32\ipconf.tsp - ok
15:41:00.0812 3956 [ 8BC2B02DC11C98D14CEE43B8E8393FF3 ] C:\WINDOWS\system32\h323.tsp
15:41:00.0812 3956 C:\WINDOWS\system32\h323.tsp - ok
15:41:00.0812 3956 [ 6B552ED3BEE5AA3C4560478FF779BA98 ] C:\WINDOWS\system32\hidphone.tsp
15:41:00.0812 3956 C:\WINDOWS\system32\hidphone.tsp - ok
15:41:00.0828 3956 [ 9EFBB3055B3EECE5B0FC7BAED07A6EE9 ] C:\WINDOWS\system32\msxml6.dll
15:41:00.0828 3956 C:\WINDOWS\system32\msxml6.dll - ok
15:41:00.0828 3956 [ DAB8C1971354B1A55D271066674ED734 ] C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll
15:41:00.0828 3956 C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll - ok
15:41:00.0828 3956 [ D0545A010ED2259A740C8414899A938F ] C:\WINDOWS\system32\rasppp.dll
15:41:00.0828 3956 C:\WINDOWS\system32\rasppp.dll - ok
15:41:00.0843 3956 [ B464BD425D5D09ABE4192234D1577B22 ] C:\WINDOWS\system32\ntlsapi.dll
15:41:00.0843 3956 C:\WINDOWS\system32\ntlsapi.dll - ok
15:41:00.0843 3956 [ A655C88AA555BB8EF8957BD29408827F ] C:\WINDOWS\system32\rasqec.dll
15:41:00.0843 3956 C:\WINDOWS\system32\rasqec.dll - ok
15:41:00.0843 3956 [ 401A8C0BE0BAA7D7A470F0942244152D ] C:\WINDOWS\system32\rasdlg.dll
15:41:00.0843 3956 C:\WINDOWS\system32\rasdlg.dll - ok
15:41:00.0859 3956 [ 822FDAFB41056462F2DDA8A7BCC2B9EB ] C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll
15:41:00.0859 3956 C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll - ok
15:41:00.0859 3956 [ 4122925C28E461811C033276E25589E9 ] C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll
15:41:00.0859 3956 C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll - ok
15:41:00.0875 3956 [ 187924625A55EDC7B196B82777C5074A ] C:\Program Files\HP\Digital Imaging\bin\HpqCPTA.dll
15:41:00.0875 3956 C:\Program Files\HP\Digital Imaging\bin\HpqCPTA.dll - ok
15:41:00.0875 3956 [ A5699775554DE8897924A0F6EB5729C9 ] C:\Program Files\HP\Digital Imaging\bin\HpqSRTA.dll
15:41:00.0875 3956 C:\Program Files\HP\Digital Imaging\bin\HpqSRTA.dll - ok
15:41:00.0875 3956 [ FFAD5F0A4ED6C79BDAB71A3084FAA621 ] C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll
15:41:00.0875 3956 C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll - ok
15:41:00.0875 3956 [ 0F5B791DB1A18423C926F1791E2A43CB ] C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc
15:41:00.0875 3956 C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc - ok
15:41:00.0890 3956 [ 017BD724C977CEF95A01203AECA571D3 ] C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll
15:41:00.0890 3956 C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll - ok
15:41:00.0890 3956 [ EEC6910D6DA48E66390964735BC97B05 ] C:\Program Files\HP\Digital Imaging\bin\hpqxml2.dll
15:41:00.0890 3956 C:\Program Files\HP\Digital Imaging\bin\hpqxml2.dll - ok
15:41:00.0890 3956 [ 81E7E920312D372CF57A817049AC7C76 ] C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
15:41:00.0890 3956 C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL - ok
15:41:00.0906 3956 [ EBD98CF6E4D04D300E57F9EC15D3BEAD ] C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll
15:41:00.0906 3956 C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll - ok
15:41:00.0906 3956 [ F54FFF428BC887F08EB83674FBB321DA ] C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
15:41:00.0906 3956 C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll - ok
15:41:00.0906 3956 [ 4967AA8BD06D51AF10E629287C7A264D ] C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
15:41:00.0906 3956 C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll - ok
15:41:00.0921 3956 [ B70278D1459A677639D51892160FD365 ] C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
15:41:00.0921 3956 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe - ok
15:41:00.0921 3956 [ AF880166DAC5880219F748ED83902CB2 ] C:\WINDOWS\system32\HPZipr12.dll
15:41:00.0921 3956 C:\WINDOWS\system32\HPZipr12.dll - ok
15:41:00.0921 3956 [ 26AE2CA34FA4342749EC1157CB1FE954 ] C:\WINDOWS\system32\HPZidr12.dll
15:41:00.0921 3956 C:\WINDOWS\system32\HPZidr12.dll - ok
15:41:00.0937 3956 [ 3E9A33113D663D8BD5ED38858E669652 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
15:41:00.0937 3956 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll - ok
15:41:00.0937 3956 [ 02EBB12CC3FC2ED47AE832A7E91CAD49 ] C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
15:41:00.0937 3956 C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe - ok
15:41:00.0937 3956 [ 7E04B1ADE140F483A6581461568D8D9C ] C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
15:41:00.0937 3956 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe - ok
15:41:00.0953 3956 [ 998DA918F47769D570C9D3E42D441289 ] C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbutil.dll
15:41:00.0953 3956 C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbutil.dll - ok
15:41:00.0953 3956 [ 6104F2921F31E1422C72B97F05BD9C5F ] C:\Program Files\HP\Digital Imaging\bin\hpqwso08.dll
15:41:00.0953 3956 C:\Program Files\HP\Digital Imaging\bin\hpqwso08.dll - ok
15:41:00.0953 3956 [ 8F32BBB0083BE50B17CE150174EDDC4B ] C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll
15:41:00.0953 3956 C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll - ok
15:41:00.0953 3956 ============================================================
15:41:00.0953 3956 Scan finished
15:41:00.0953 3956 ============================================================
15:41:01.0078 3948 Detected object count: 7
15:41:01.0078 3948 Actual detected object count: 7
15:41:25.0765 3948 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:25.0765 3948 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:25.0765 3948 hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:25.0765 3948 hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:25.0765 3948 hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:25.0765 3948 hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:25.0781 3948 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:25.0781 3948 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:25.0781 3948 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:25.0781 3948 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:25.0781 3948 RT80x86 ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:25.0781 3948 RT80x86 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:41:25.0781 3948 Scutum50 ( UnsignedFile.Multi.Generic ) - skipped by user
15:41:25.0781 3948 Scutum50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:42:27.0187 3772 ============================================================
15:42:27.0187 3772 Scan started
15:42:27.0187 3772 Mode: Manual; SigCheck; TDLFS;
15:42:27.0187 3772 ============================================================
15:42:27.0390 3772 ================ Scan system memory ========================
15:42:27.0390 3772 System memory - ok
15:42:27.0390 3772 ================ Scan services =============================
15:42:27.0515 3772 Abiosdsk - ok
15:42:27.0531 3772 abp480n5 - ok
15:42:27.0578 3772 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
15:42:27.0828 3772 ACPI - ok
15:42:27.0859 3772 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
15:42:28.0000 3772 ACPIEC - ok
15:42:28.0078 3772 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
15:42:28.0109 3772 AdobeFlashPlayerUpdateSvc - ok
15:42:28.0109 3772 adpu160m - ok
15:42:28.0156 3772 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
15:42:28.0296 3772 aec - ok
15:42:28.0343 3772 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
15:42:28.0375 3772 AFD - ok
15:42:28.0375 3772 Aha154x - ok
15:42:28.0375 3772 aic78u2 - ok
15:42:28.0390 3772 aic78xx - ok
15:42:28.0421 3772 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
15:42:28.0562 3772 Alerter - ok
15:42:28.0578 3772 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
15:42:28.0656 3772 ALG - ok
15:42:28.0671 3772 AliIde - ok
15:42:28.0671 3772 amsint - ok
15:42:28.0812 3772 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:42:28.0828 3772 Apple Mobile Device - ok
15:42:28.0890 3772 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
15:42:28.0953 3772 AppMgmt - ok
15:42:28.0953 3772 asc - ok
15:42:28.0968 3772 asc3350p - ok
15:42:28.0968 3772 asc3550 - ok
15:42:29.0109 3772 [ 0E5E4957549056E2BF2C49F4F6B601AD ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
15:42:29.0125 3772 aspnet_state - ok
15:42:29.0156 3772 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
15:42:29.0312 3772 AsyncMac - ok
15:42:29.0343 3772 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
15:42:29.0500 3772 atapi - ok
15:42:29.0500 3772 Atdisk - ok
15:42:29.0515 3772 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
15:42:29.0640 3772 Atmarpc - ok
15:42:29.0687 3772 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
15:42:29.0828 3772 AudioSrv - ok
15:42:29.0875 3772 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
15:42:30.0015 3772 audstub - ok
15:42:30.0046 3772 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep C:\WINDOWS\system32\drivers\Beep.sys
15:42:30.0203 3772 Beep - ok
15:42:30.0250 3772 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
15:42:30.0406 3772 BITS - ok
15:42:30.0500 3772 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
15:42:30.0531 3772 Bonjour Service - ok
15:42:30.0562 3772 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
15:42:30.0609 3772 Browser - ok
15:42:30.0734 3772 catchme - ok
15:42:30.0765 3772 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
15:42:30.0906 3772 cbidf2k - ok
15:42:30.0906 3772 cd20xrnt - ok
15:42:30.0937 3772 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
15:42:31.0062 3772 Cdaudio - ok
15:42:31.0093 3772 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
15:42:31.0250 3772 Cdfs - ok
15:42:31.0281 3772 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
15:42:31.0437 3772 Cdrom - ok
15:42:31.0437 3772 Changer - ok
15:42:31.0453 3772 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
15:42:31.0593 3772 CiSvc - ok
15:42:31.0625 3772 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
15:42:31.0765 3772 ClipSrv - ok
15:42:31.0796 3772 [ 7FA87325900183197BC9710D1CE4C9FA ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
15:42:31.0828 3772 clr_optimization_v2.0.50727_32 - ok
15:42:31.0828 3772 CmdIde - ok
15:42:31.0843 3772 COMSysApp - ok
15:42:31.0843 3772 Cpqarray - ok
15:42:31.0859 3772 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
15:42:31.0984 3772 CryptSvc - ok
15:42:32.0031 3772 [ CB6FF7012BB5D59D7C12350DB795CE1F ] ctxusbm C:\WINDOWS\system32\DRIVERS\ctxusbm.sys
15:42:32.0046 3772 ctxusbm - ok
15:42:32.0062 3772 dac2w2k - ok
15:42:32.0062 3772 dac960nt - ok
15:42:32.0109 3772 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
15:42:32.0156 3772 DcomLaunch - ok
15:42:32.0156 3772 dgderdrv - ok
15:42:32.0187 3772 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
15:42:32.0328 3772 Dhcp - ok
15:42:32.0359 3772 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
15:42:32.0500 3772 Disk - ok
15:42:32.0500 3772 dmadmin - ok
15:42:32.0593 3772 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
15:42:32.0765 3772 dmboot - ok
15:42:32.0781 3772 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
15:42:32.0921 3772 dmio - ok
15:42:32.0968 3772 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
15:42:33.0109 3772 dmload - ok
15:42:33.0125 3772 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
15:42:33.0281 3772 dmserver - ok
15:42:33.0312 3772 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
15:42:33.0468 3772 DMusic - ok
15:42:33.0484 3772 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
15:42:33.0515 3772 Dnscache - ok
15:42:33.0562 3772 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
15:42:33.0703 3772 Dot3svc - ok
15:42:33.0718 3772 dpti2o - ok
15:42:33.0750 3772 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
15:42:33.0875 3772 drmkaud - ok
15:42:33.0937 3772 [ 95974E66D3DE4951D29E28E8BC0B644C ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
15:42:33.0953 3772 E100B - ok
15:42:33.0984 3772 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
15:42:34.0125 3772 EapHost - ok
15:42:34.0156 3772 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
15:42:34.0296 3772 ERSvc - ok
15:42:34.0328 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
15:42:34.0359 3772 Eventlog - ok
15:42:34.0406 3772 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
15:42:34.0421 3772 EventSystem - ok
15:42:34.0468 3772 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
15:42:34.0593 3772 Fastfat - ok
15:42:34.0640 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
15:42:34.0687 3772 FastUserSwitchingCompatibility - ok
15:42:34.0718 3772 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\drivers\Fdc.sys
15:42:34.0843 3772 Fdc - ok
15:42:34.0843 3772 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
15:42:34.0968 3772 Fips - ok
15:42:34.0984 3772 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\drivers\Flpydisk.sys
15:42:35.0125 3772 Flpydisk - ok
15:42:35.0171 3772 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\DRIVERS\fltMgr.sys
15:42:35.0296 3772 FltMgr - ok
15:42:35.0343 3772 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
15:42:35.0359 3772 FontCache3.0.0.0 - ok
15:42:35.0406 3772 [ CBE5F69A5E5B918225F420BA748F3742 ] FsUsbExDisk C:\WINDOWS\system32\FsUsbExDisk.SYS
15:42:35.0421 3772 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - warning
15:42:35.0421 3772 FsUsbExDisk - detected UnsignedFile.Multi.Generic (1)
15:42:35.0437 3772 [ 96633419F4A1E37ACB89B45EBCCFE001 ] FsUsbExService C:\WINDOWS\system32\FsUsbExService.Exe
15:42:35.0453 3772 FsUsbExService - ok
15:42:35.0468 3772 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
15:42:35.0609 3772 Fs_Rec - ok
15:42:35.0609 3772 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
15:42:35.0750 3772 Ftdisk - ok
15:42:35.0796 3772 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
15:42:35.0812 3772 GEARAspiWDM - ok
15:42:35.0921 3772 [ 94FCCE83CDEE9C8149667110093E701E ] GFIBckHAtt C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe
15:42:35.0953 3772 GFIBckHAtt - ok
15:42:36.0046 3772 [ E95911BD88EF967125724428772FDDD8 ] GFIBckHSched C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE
15:42:36.0125 3772 GFIBckHSched - ok
15:42:36.0171 3772 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
15:42:36.0312 3772 Gpc - ok
15:42:36.0421 3772 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
15:42:36.0453 3772 gupdate - ok
15:42:36.0453 3772 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
15:42:36.0484 3772 gupdatem - ok
15:42:36.0531 3772 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
15:42:36.0546 3772 gusvc - ok
15:42:36.0609 3772 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
15:42:36.0734 3772 HDAudBus - ok
15:42:36.0812 3772 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
15:42:36.0953 3772 helpsvc - ok
15:42:36.0984 3772 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ C:\WINDOWS\System32\hidserv.dll
15:42:37.0140 3772 HidServ - ok
15:42:37.0171 3772 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb C:\WINDOWS\system32\DRIVERS\hidusb.sys
15:42:37.0312 3772 hidusb - ok
15:42:37.0343 3772 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
15:42:37.0484 3772 hkmsvc - ok
15:42:37.0484 3772 hpn - ok
15:42:37.0625 3772 [ F50F7984FDD151EDD8A70A8DBD9E2A44 ] hpqcxs08 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
15:42:37.0625 3772 hpqcxs08 ( UnsignedFile.Multi.Generic ) - warning
15:42:37.0625 3772 hpqcxs08 - detected UnsignedFile.Multi.Generic (1)
15:42:37.0640 3772 [ DF446BA625CC441617843E87798CE048 ] hpqddsvc C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
15:42:37.0640 3772 hpqddsvc ( UnsignedFile.Multi.Generic ) - warning
15:42:37.0640 3772 hpqddsvc - detected UnsignedFile.Multi.Generic (1)
15:42:37.0687 3772 [ D03D10F7DED688FECF50F8FBF1EA9B8A ] HPZid412 C:\WINDOWS\system32\DRIVERS\HPZid412.sys
15:42:37.0750 3772 HPZid412 - ok
15:42:37.0765 3772 [ 89F41658929393487B6B7D13C8528CE3 ] HPZipr12 C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
15:42:37.0812 3772 HPZipr12 - ok
15:42:37.0828 3772 [ ABCB05CCDBF03000354B9553820E39F8 ] HPZius12 C:\WINDOWS\system32\DRIVERS\HPZius12.sys
15:42:37.0875 3772 HPZius12 - ok
15:42:37.0921 3772 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
15:42:37.0953 3772 HTTP - ok
15:42:37.0984 3772 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
15:42:38.0109 3772 HTTPFilter - ok
15:42:38.0125 3772 i2omgmt - ok
15:42:38.0125 3772 i2omp - ok
15:42:38.0156 3772 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\drivers\i8042prt.sys
15:42:38.0296 3772 i8042prt - ok
15:42:38.0375 3772 [ 5A8E05F1D5C36ABD58CFFA111EB325EA ] ialm C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
15:42:38.0453 3772 ialm - ok
15:42:38.0578 3772 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
15:42:38.0625 3772 idsvc - ok
15:42:38.0640 3772 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
15:42:38.0796 3772 Imapi - ok
15:42:38.0843 3772 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
15:42:38.0984 3772 ImapiService - ok
15:42:39.0000 3772 ini910u - ok
15:42:39.0046 3772 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
15:42:39.0156 3772 IntelIde - ok
15:42:39.0187 3772 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
15:42:39.0312 3772 intelppm - ok
15:42:39.0343 3772 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
15:42:39.0484 3772 Ip6Fw - ok
15:42:39.0531 3772 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
15:42:39.0671 3772 IpFilterDriver - ok
15:42:39.0671 3772 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
15:42:39.0812 3772 IpInIp - ok
15:42:39.0843 3772 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
15:42:39.0984 3772 IpNat - ok
15:42:40.0046 3772 [ E46B17060D3962A384AE484094614788 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
15:42:40.0078 3772 iPod Service - ok
15:42:40.0125 3772 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
15:42:40.0265 3772 IPSec - ok
15:42:40.0296 3772 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
15:42:40.0375 3772 IRENUM - ok
15:42:40.0406 3772 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
15:42:40.0531 3772 isapnp - ok
15:42:40.0625 3772 [ 724A6A9AB5E1807665C5DB71C30BFC5F ] ISWKL C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
15:42:40.0640 3772 ISWKL - ok
15:42:40.0656 3772 [ 57FE873B8246DEF1372503CBC57A7499 ] IswSvc C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
15:42:40.0703 3772 IswSvc - ok
15:42:40.0812 3772 [ B591E761161D1EF547D76EF236EAA6A5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
15:42:40.0843 3772 JavaQuickStarterService - ok
15:42:40.0875 3772 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
15:42:41.0031 3772 Kbdclass - ok
15:42:41.0046 3772 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
15:42:41.0171 3772 kbdhid - ok
15:42:41.0203 3772 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
15:42:41.0343 3772 kmixer - ok
15:42:41.0390 3772 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
15:42:41.0421 3772 KSecDD - ok
15:42:41.0468 3772 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] LanmanServer C:\WINDOWS\System32\srvsvc.dll
15:42:41.0500 3772 LanmanServer - ok
15:42:41.0546 3772 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
15:42:41.0578 3772 lanmanworkstation - ok
15:42:41.0593 3772 lbrtfdc - ok
15:42:41.0640 3772 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
15:42:41.0765 3772 LmHosts - ok
15:42:41.0781 3772 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
15:42:41.0906 3772 Messenger - ok
15:42:42.0015 3772 Microsoft SharePoint Workspace Audit Service - ok
15:42:42.0046 3772 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
15:42:42.0187 3772 mnmdd - ok
15:42:42.0218 3772 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
15:42:42.0343 3772 mnmsrvc - ok
15:42:42.0359 3772 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
15:42:42.0500 3772 Modem - ok
15:42:42.0531 3772 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
15:42:42.0671 3772 Mouclass - ok
15:42:42.0687 3772 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
15:42:42.0843 3772 mouhid - ok
15:42:42.0875 3772 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
15:42:43.0015 3772 MountMgr - ok
15:42:43.0046 3772 [ CF105EE42E3F71E648CEBB3F666E1CF0 ] MpFilter C:\WINDOWS\system32\DRIVERS\MpFilter.sys
15:42:43.0078 3772 MpFilter - ok
15:42:43.0093 3772 mraid35x - ok
15:42:43.0125 3772 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
15:42:43.0312 3772 MRxDAV - ok
15:42:43.0359 3772 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
15:42:43.0406 3772 MRxSmb - ok
15:42:43.0437 3772 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
15:42:43.0562 3772 MSDTC - ok
15:42:43.0562 3772 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
15:42:43.0703 3772 Msfs - ok
15:42:43.0718 3772 MSIServer - ok
15:42:43.0750 3772 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
15:42:43.0890 3772 MSKSSRV - ok
15:42:43.0937 3772 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] MsMpSvc C:\Program Files\Microsoft Security Client\MsMpEng.exe
15:42:43.0968 3772 MsMpSvc - ok
15:42:44.0000 3772 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
15:42:44.0109 3772 MSPCLOCK - ok
15:42:44.0125 3772 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
15:42:44.0265 3772 MSPQM - ok
15:42:44.0296 3772 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
15:42:44.0406 3772 mssmbios - ok
15:42:44.0468 3772 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
15:42:44.0500 3772 Mup - ok
15:42:44.0562 3772 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
15:42:44.0687 3772 napagent - ok
15:42:44.0718 3772 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
15:42:44.0843 3772 NDIS - ok
15:42:44.0890 3772 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
15:42:44.0937 3772 NdisTapi - ok
15:42:44.0968 3772 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
15:42:45.0093 3772 Ndisuio - ok
15:42:45.0125 3772 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
15:42:45.0250 3772 NdisWan - ok
15:42:45.0296 3772 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
15:42:45.0328 3772 NDProxy - ok
15:42:45.0375 3772 [ 51C6D8BFBD4EA5B62A1BA7F4469250D3 ] Net Driver HPZ12 C:\WINDOWS\system32\HPZinw12.dll
15:42:45.0406 3772 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
15:42:45.0406 3772 Net Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
15:42:45.0437 3772 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
15:42:45.0562 3772 NetBIOS - ok
15:42:45.0578 3772 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
15:42:45.0718 3772 NetBT - ok
15:42:45.0750 3772 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
15:42:45.0875 3772 NetDDE - ok
15:42:45.0890 3772 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
15:42:46.0015 3772 NetDDEdsdm - ok
15:42:46.0031 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
15:42:46.0156 3772 Netlogon - ok
15:42:46.0203 3772 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
15:42:46.0343 3772 Netman - ok
15:42:46.0375 3772 [ D34612C5D02D026535B3095D620626AE ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
15:42:46.0390 3772 NetTcpPortSharing - ok
15:42:46.0421 3772 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
15:42:46.0453 3772 Nla - ok
15:42:46.0468 3772 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
15:42:46.0593 3772 Npfs - ok
15:42:46.0640 3772 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
15:42:46.0781 3772 Ntfs - ok
15:42:46.0812 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
15:42:46.0937 3772 NtLmSsp - ok
15:42:47.0015 3772 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
15:42:47.0156 3772 NtmsSvc - ok
15:42:47.0187 3772 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
15:42:47.0328 3772 Null - ok
15:42:47.0359 3772 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
15:42:47.0484 3772 NwlnkFlt - ok
15:42:47.0500 3772 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
15:42:47.0625 3772 NwlnkFwd - ok
15:42:47.0734 3772 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
15:42:47.0750 3772 ose - ok
15:42:47.0953 3772 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
15:42:48.0093 3772 osppsvc - ok
15:42:48.0125 3772 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\drivers\Parport.sys
15:42:48.0265 3772 Parport - ok
15:42:48.0296 3772 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
15:42:48.0437 3772 PartMgr - ok
15:42:48.0453 3772 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
15:42:48.0593 3772 ParVdm - ok
15:42:48.0609 3772 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
15:42:48.0750 3772 PCI - ok
15:42:48.0765 3772 PCIDump - ok
15:42:48.0781 3772 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\drivers\PCIIde.sys
15:42:48.0906 3772 PCIIde - ok
15:42:48.0953 3772 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
15:42:49.0093 3772 Pcmcia - ok
15:42:49.0093 3772 PDCOMP - ok
15:42:49.0109 3772 PDFRAME - ok
15:42:49.0109 3772 PDRELI - ok
15:42:49.0125 3772 PDRFRAME - ok
15:42:49.0125 3772 perc2 - ok
15:42:49.0140 3772 perc2hib - ok
15:42:49.0171 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
15:42:49.0203 3772 PlugPlay - ok
15:42:49.0218 3772 [ 79834AA2FBF9FE81EEBB229024F6F7FC ] Pml Driver HPZ12 C:\WINDOWS\system32\HPZipm12.dll
15:42:49.0250 3772 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - warning
15:42:49.0250 3772 Pml Driver HPZ12 - detected UnsignedFile.Multi.Generic (1)
15:42:49.0265 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
15:42:49.0390 3772 PolicyAgent - ok
15:42:49.0406 3772 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
15:42:49.0546 3772 PptpMiniport - ok
15:42:49.0546 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
15:42:49.0671 3772 ProtectedStorage - ok
15:42:49.0671 3772 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
15:42:49.0796 3772 PSched - ok
15:42:49.0828 3772 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
15:42:49.0968 3772 Ptilink - ok
15:42:49.0968 3772 ql1080 - ok
15:42:49.0984 3772 Ql10wnt - ok
15:42:49.0984 3772 ql12160 - ok
15:42:49.0984 3772 ql1240 - ok
15:42:50.0000 3772 ql1280 - ok
15:42:50.0078 3772 [ 720FEA3AAA15FE7E0BEAB10AC2E6D2B0 ] RalinkRegistryWriter C:\Program Files\Edimax\Common\RaRegistry.exe
15:42:50.0109 3772 RalinkRegistryWriter - ok
15:42:50.0125 3772 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
15:42:50.0250 3772 RasAcd - ok
15:42:50.0296 3772 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
15:42:50.0421 3772 RasAuto - ok
15:42:50.0437 3772 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
15:42:50.0546 3772 Rasl2tp - ok
15:42:50.0593 3772 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
15:42:50.0718 3772 RasMan - ok
15:42:50.0718 3772 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
15:42:50.0843 3772 RasPppoe - ok
15:42:50.0843 3772 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
15:42:50.0984 3772 Raspti - ok
15:42:51.0015 3772 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
15:42:51.0171 3772 Rdbss - ok
15:42:51.0171 3772 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
15:42:51.0296 3772 RDPCDD - ok
15:42:51.0328 3772 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
15:42:51.0468 3772 rdpdr - ok
15:42:51.0515 3772 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
15:42:51.0562 3772 RDPWD - ok
15:42:51.0609 3772 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
15:42:51.0734 3772 RDSessMgr - ok
15:42:51.0765 3772 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
15:42:51.0890 3772 redbook - ok
15:42:51.0906 3772 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
15:42:52.0046 3772 RemoteAccess - ok
15:42:52.0093 3772 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
15:42:52.0250 3772 RemoteRegistry - ok
15:42:52.0281 3772 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
15:42:52.0406 3772 RpcLocator - ok
15:42:52.0437 3772 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
15:42:52.0468 3772 RpcSs - ok
15:42:52.0515 3772 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
15:42:52.0656 3772 RSVP - ok
15:42:52.0734 3772 [ F0F38AAEA933DD4F114643FCB5DC1842 ] RT80x86 C:\WINDOWS\system32\DRIVERS\RT2860.sys
15:42:52.0765 3772 RT80x86 ( UnsignedFile.Multi.Generic ) - warning
15:42:52.0765 3772 RT80x86 - detected UnsignedFile.Multi.Generic (1)
15:42:52.0796 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
15:42:52.0906 3772 SamSs - ok
15:42:52.0953 3772 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
15:42:53.0078 3772 SCardSvr - ok
15:42:53.0125 3772 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
15:42:53.0234 3772 Schedule - ok
15:42:53.0250 3772 [ F34C06D1C706A6D9433570B087A18B02 ] Scutum50 C:\WINDOWS\system32\Drivers\Scutum50.sys
15:42:53.0265 3772 Scutum50 ( UnsignedFile.Multi.Generic ) - warning
15:42:53.0265 3772 Scutum50 - detected UnsignedFile.Multi.Generic (1)
15:42:53.0281 3772 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
15:42:53.0343 3772 Secdrv - ok
15:42:53.0390 3772 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
15:42:53.0515 3772 seclogon - ok
15:42:53.0531 3772 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
15:42:53.0671 3772 SENS - ok
15:42:53.0703 3772 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\drivers\Serial.sys
15:42:53.0828 3772 Serial - ok
15:42:53.0843 3772 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
15:42:53.0984 3772 Sfloppy - ok
15:42:54.0015 3772 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
15:42:54.0171 3772 SharedAccess - ok
15:42:54.0203 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
15:42:54.0234 3772 ShellHWDetection - ok
15:42:54.0234 3772 Simbad - ok
15:42:54.0250 3772 Sparrow - ok
15:42:54.0296 3772 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
15:42:54.0406 3772 splitter - ok
15:42:54.0468 3772 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
15:42:54.0484 3772 Spooler - ok
15:42:54.0531 3772 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
15:42:54.0609 3772 sr - ok
15:42:54.0656 3772 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
15:42:54.0718 3772 srservice - ok
15:42:54.0765 3772 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
15:42:54.0828 3772 Srv - ok
15:42:54.0859 3772 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
15:42:54.0937 3772 SSDPSRV - ok
15:42:55.0015 3772 [ 0AA91BBE468B3F46072091F18003ECAA ] STHDA C:\WINDOWS\system32\drivers\sthda.sys
15:42:55.0046 3772 STHDA - ok
15:42:55.0093 3772 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
15:42:55.0250 3772 stisvc - ok
15:42:55.0281 3772 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
15:42:55.0406 3772 swenum - ok
15:42:55.0406 3772 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
15:42:55.0531 3772 swmidi - ok
15:42:55.0546 3772 SwPrv - ok
15:42:55.0546 3772 symc810 - ok
15:42:55.0546 3772 symc8xx - ok
15:42:55.0562 3772 sym_hi - ok
15:42:55.0562 3772 sym_u3 - ok
15:42:55.0578 3772 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
15:42:55.0734 3772 sysaudio - ok
15:42:55.0765 3772 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
15:42:55.0890 3772 SysmonLog - ok
15:42:55.0906 3772 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
15:42:56.0031 3772 TapiSrv - ok
15:42:56.0093 3772 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
15:42:56.0109 3772 Tcpip - ok
15:42:56.0140 3772 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
15:42:56.0281 3772 TDPIPE - ok
15:42:56.0296 3772 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
15:42:56.0421 3772 TDTCP - ok
15:42:56.0437 3772 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
15:42:56.0562 3772 TermDD - ok
15:42:56.0578 3772 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
15:42:56.0734 3772 TermService - ok
15:42:56.0765 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
15:42:56.0781 3772 Themes - ok
15:42:56.0843 3772 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
15:42:56.0906 3772 TlntSvr - ok
15:42:56.0984 3772 [ A21E58F345F337316A98C5121CBE17E8 ] TomTomHOMEService C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
15:42:57.0000 3772 TomTomHOMEService - ok
15:42:57.0015 3772 TosIde - ok
15:42:57.0031 3772 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
15:42:57.0203 3772 TrkWks - ok
15:42:57.0218 3772 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
15:42:57.0359 3772 Udfs - ok
15:42:57.0359 3772 ultra - ok
15:42:57.0421 3772 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
15:42:57.0546 3772 Update - ok
15:42:57.0609 3772 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
15:42:57.0671 3772 upnphost - ok
15:42:57.0703 3772 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
15:42:57.0843 3772 UPS - ok
15:42:57.0890 3772 [ 6E421CCC57059B0186C6259CA3B6DFC9 ] USBAAPL C:\WINDOWS\system32\Drivers\usbaapl.sys
15:42:57.0906 3772 USBAAPL - ok
15:42:57.0921 3772 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp C:\WINDOWS\system32\DRIVERS\usbccgp.sys
15:42:58.0046 3772 usbccgp - ok
15:42:58.0078 3772 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
15:42:58.0218 3772 usbehci - ok
15:42:58.0265 3772 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
15:42:58.0390 3772 usbhub - ok
15:42:58.0406 3772 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
15:42:58.0546 3772 usbprint - ok
15:42:58.0562 3772 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
15:42:58.0718 3772 usbscan - ok
15:42:58.0734 3772 [ A32426D9B14A089EAA1D922E0C5801A9 ] usbstor C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
15:42:58.0875 3772 usbstor - ok
15:42:58.0890 3772 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
15:42:59.0015 3772 usbuhci - ok
15:42:59.0046 3772 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
15:42:59.0171 3772 VgaSave - ok
15:42:59.0171 3772 ViaIde - ok
15:42:59.0203 3772 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
15:42:59.0328 3772 VolSnap - ok
15:42:59.0375 3772 [ 5C826F02FF76F07B332C764BB9644F27 ] Vsdatant C:\WINDOWS\system32\vsdatant.sys
15:42:59.0406 3772 Vsdatant - ok
15:42:59.0453 3772 vsmon - ok
15:42:59.0531 3772 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
15:42:59.0625 3772 VSS - ok
15:42:59.0656 3772 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time C:\WINDOWS\system32\w32time.dll
15:42:59.0796 3772 W32Time - ok
15:42:59.0828 3772 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
15:42:59.0953 3772 Wanarp - ok
15:43:00.0015 3772 [ BBCFEAB7E871CDDAC2D397EE7FA91FDC ] Wdf01000 C:\WINDOWS\system32\Drivers\wdf01000.sys
15:43:00.0046 3772 Wdf01000 - ok
15:43:00.0046 3772 WDICA - ok
15:43:00.0093 3772 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
15:43:00.0234 3772 wdmaud - ok
15:43:00.0265 3772 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
15:43:00.0406 3772 WebClient - ok
15:43:00.0484 3772 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
15:43:00.0609 3772 winmgmt - ok
15:43:00.0671 3772 [ FD600B032E741EB6AAB509FC630F7C42 ] WinUSB C:\WINDOWS\system32\DRIVERS\WinUSB.sys
15:43:00.0687 3772 WinUSB - ok
15:43:00.0734 3772 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
15:43:00.0750 3772 WmdmPmSN - ok
15:43:00.0796 3772 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
15:43:00.0859 3772 Wmi - ok
15:43:00.0890 3772 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
15:43:01.0031 3772 WmiApSrv - ok
15:43:01.0125 3772 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
15:43:01.0171 3772 WMPNetworkSvc - ok
15:43:01.0187 3772 [ CF4DEF1BF66F06964DC0D91844239104 ] WpdUsb C:\WINDOWS\system32\DRIVERS\wpdusb.sys
15:43:01.0218 3772 WpdUsb - ok
15:43:01.0234 3772 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
15:43:01.0359 3772 WS2IFSL - ok
15:43:01.0406 3772 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
15:43:01.0546 3772 wscsvc - ok
15:43:01.0578 3772 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
15:43:01.0703 3772 wuauserv - ok
15:43:01.0750 3772 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
15:43:01.0781 3772 WudfPf - ok
15:43:01.0796 3772 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
15:43:01.0843 3772 WudfRd - ok
15:43:01.0859 3772 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
15:43:01.0890 3772 WudfSvc - ok
15:43:01.0953 3772 [ BE0B3774113713059527FCF071CCDBFE ] wwEngineSvc C:\Program Files\Webroot\Washer\WasherSvc.exe
15:43:01.0984 3772 wwEngineSvc - ok
15:43:02.0046 3772 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
15:43:02.0218 3772 WZCSVC - ok
15:43:02.0250 3772 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
15:43:02.0375 3772 xmlprov - ok
15:43:02.0375 3772 ================ Scan global ===============================
15:43:02.0421 3772 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
15:43:02.0468 3772 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:43:02.0484 3772 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:43:02.0500 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
15:43:02.0500 3772 [Global] - ok
15:43:02.0500 3772 ================ Scan MBR ==================================
15:43:02.0531 3772 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
15:43:02.0781 3772 \Device\Harddisk0\DR0 - ok
15:43:02.0781 3772 ================ Scan VBR ==================================
15:43:02.0781 3772 [ 9D6139F0B54E5C5428B9446ADDDB5F9E ] \Device\Harddisk0\DR0\Partition1
15:43:02.0781 3772 \Device\Harddisk0\DR0\Partition1 - ok
15:43:02.0796 3772 [ 6C42BEBF2A612522B6AB5F8EBEBDE291 ] \Device\Harddisk0\DR0\Partition2
15:43:02.0812 3772 \Device\Harddisk0\DR0\Partition2 - ok
15:43:02.0812 3772 ================ Scan active images ========================
15:43:02.0812 3772 [ 8C953733D8F36EB2133F5BB58808B66B ] C:\WINDOWS\system32\drivers\intelppm.sys
15:43:02.0812 3772 C:\WINDOWS\system32\drivers\intelppm.sys - ok
15:43:02.0812 3772 [ E28726B72C46821A28830E077D39A55B ] C:\WINDOWS\system32\drivers\videoprt.sys
15:43:02.0812 3772 C:\WINDOWS\system32\drivers\videoprt.sys - ok
15:43:02.0812 3772 [ 5A8E05F1D5C36ABD58CFFA111EB325EA ] C:\WINDOWS\system32\drivers\ialmnt5.sys
15:43:02.0812 3772 C:\WINDOWS\system32\drivers\ialmnt5.sys - ok
15:43:02.0828 3772 [ 573C7D0A32852B48F3058CFD8026F511 ] C:\WINDOWS\system32\drivers\hdaudbus.sys
15:43:02.0828 3772 C:\WINDOWS\system32\drivers\hdaudbus.sys - ok
15:43:02.0828 3772 [ 791912E524CC2CC6F50B5F2B52D1EB71 ] C:\WINDOWS\system32\drivers\usbport.sys
15:43:02.0828 3772 C:\WINDOWS\system32\drivers\usbport.sys - ok
15:43:02.0828 3772 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] C:\WINDOWS\system32\drivers\usbuhci.sys
15:43:02.0828 3772 C:\WINDOWS\system32\drivers\usbuhci.sys - ok
15:43:02.0843 3772 [ F0F38AAEA933DD4F114643FCB5DC1842 ] C:\WINDOWS\system32\drivers\rt2860.sys
15:43:02.0843 3772 C:\WINDOWS\system32\drivers\rt2860.sys - ok
15:43:02.0843 3772 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] C:\WINDOWS\system32\drivers\usbehci.sys
15:43:02.0843 3772 C:\WINDOWS\system32\drivers\usbehci.sys - ok
15:43:02.0859 3772 [ 95974E66D3DE4951D29E28E8BC0B644C ] C:\WINDOWS\system32\drivers\e100b325.sys
15:43:02.0859 3772 C:\WINDOWS\system32\drivers\e100b325.sys - ok
15:43:02.0859 3772 [ 083A052659F5310DD8B6A6CB05EDCF8E ] C:\WINDOWS\system32\drivers\imapi.sys
15:43:02.0859 3772 C:\WINDOWS\system32\drivers\imapi.sys - ok
15:43:02.0859 3772 [ 1F4260CC5B42272D71F79E570A27A4FE ] C:\WINDOWS\system32\drivers\cdrom.sys
15:43:02.0859 3772 C:\WINDOWS\system32\drivers\cdrom.sys - ok
15:43:02.0875 3772 [ 0753515F78DF7F271A5E61C20BCD36A1 ] C:\WINDOWS\system32\drivers\ks.sys
15:43:02.0875 3772 C:\WINDOWS\system32\drivers\ks.sys - ok
15:43:02.0875 3772 [ F828DD7E1419B6653894A8F97A0094C5 ] C:\WINDOWS\system32\drivers\redbook.sys
15:43:02.0875 3772 C:\WINDOWS\system32\drivers\redbook.sys - ok
15:43:02.0875 3772 [ D9F724AA26C010A217C97606B160ED68 ] C:\WINDOWS\system32\drivers\audstub.sys
15:43:02.0875 3772 C:\WINDOWS\system32\drivers\audstub.sys - ok
15:43:02.0890 3772 [ 185ADA973B5020655CEE342059A86CBB ] C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
15:43:02.0890 3772 C:\WINDOWS\system32\drivers\GEARAspiWDM.sys - ok
15:43:02.0890 3772 [ 0109C4F3850DFBAB279542515386AE22 ] C:\WINDOWS\system32\drivers\ndistapi.sys
15:43:02.0890 3772 C:\WINDOWS\system32\drivers\ndistapi.sys - ok
15:43:02.0890 3772 [ EDC1531A49C80614B2CFDA43CA8659AB ] C:\WINDOWS\system32\drivers\ndiswan.sys
15:43:02.0890 3772 C:\WINDOWS\system32\drivers\ndiswan.sys - ok
15:43:02.0906 3772 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] C:\WINDOWS\system32\drivers\rasl2tp.sys
15:43:02.0906 3772 C:\WINDOWS\system32\drivers\rasl2tp.sys - ok
15:43:02.0906 3772 [ 5BC962F2654137C9909C3D4603587DEE ] C:\WINDOWS\system32\drivers\raspppoe.sys
15:43:02.0906 3772 C:\WINDOWS\system32\drivers\raspppoe.sys - ok
15:43:02.0906 3772 [ 0539D5E53587F82D1B4FD74C5BE205CF ] C:\WINDOWS\system32\drivers\tdi.sys
15:43:02.0906 3772 C:\WINDOWS\system32\drivers\tdi.sys - ok
15:43:02.0906 3772 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] C:\WINDOWS\system32\drivers\msgpc.sys
15:43:02.0906 3772 C:\WINDOWS\system32\drivers\msgpc.sys - ok
15:43:02.0921 3772 [ 09298EC810B07E5D582CB3A3F9255424 ] C:\WINDOWS\system32\drivers\psched.sys
15:43:02.0921 3772 C:\WINDOWS\system32\drivers\psched.sys - ok
15:43:02.0921 3772 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] C:\WINDOWS\system32\drivers\raspptp.sys
15:43:02.0921 3772 C:\WINDOWS\system32\drivers\raspptp.sys - ok
15:43:02.0921 3772 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] C:\WINDOWS\system32\drivers\ptilink.sys
15:43:02.0921 3772 C:\WINDOWS\system32\drivers\ptilink.sys - ok
15:43:02.0937 3772 [ FDBB1D60066FCFBB7452FD8F9829B242 ] C:\WINDOWS\system32\drivers\raspti.sys
15:43:02.0937 3772 C:\WINDOWS\system32\drivers\raspti.sys - ok
15:43:02.0937 3772 [ 15CABD0F7C00C47C70124907916AF3F1 ] C:\WINDOWS\system32\drivers\rdpdr.sys
15:43:02.0937 3772 C:\WINDOWS\system32\drivers\rdpdr.sys - ok
15:43:02.0937 3772 [ 463C1EC80CD17420A542B7F36A36F128 ] C:\WINDOWS\system32\drivers\kbdclass.sys
15:43:02.0937 3772 C:\WINDOWS\system32\drivers\kbdclass.sys - ok
15:43:02.0953 3772 [ 88155247177638048422893737429D9E ] C:\WINDOWS\system32\drivers\termdd.sys
15:43:02.0953 3772 C:\WINDOWS\system32\drivers\termdd.sys - ok
15:43:02.0953 3772 [ 35C9E97194C8CFB8430125F8DBC34D04 ] C:\WINDOWS\system32\drivers\mouclass.sys
15:43:02.0953 3772 C:\WINDOWS\system32\drivers\mouclass.sys - ok
15:43:02.0953 3772 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] C:\WINDOWS\system32\drivers\swenum.sys
15:43:02.0953 3772 C:\WINDOWS\system32\drivers\swenum.sys - ok
15:43:02.0968 3772 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] C:\WINDOWS\system32\drivers\update.sys
15:43:02.0968 3772 C:\WINDOWS\system32\drivers\update.sys - ok
15:43:02.0968 3772 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] C:\WINDOWS\system32\drivers\mssmbios.sys
15:43:02.0968 3772 C:\WINDOWS\system32\drivers\mssmbios.sys - ok
15:43:02.0968 3772 [ 9282BD12DFB069D3889EB3FCC1000A9B ] C:\WINDOWS\system32\drivers\ndproxy.sys
15:43:02.0968 3772 C:\WINDOWS\system32\drivers\ndproxy.sys - ok
15:43:02.0984 3772 [ 6CB08593487F5701D2D2254E693EAFCE ] C:\WINDOWS\system32\drivers\drmk.sys
15:43:02.0984 3772 C:\WINDOWS\system32\drivers\drmk.sys - ok
15:43:02.0984 3772 [ E82A496C3961EFC6828B508C310CE98F ] C:\WINDOWS\system32\drivers\portcls.sys
15:43:02.0984 3772 C:\WINDOWS\system32\drivers\portcls.sys - ok
15:43:02.0984 3772 [ 0AA91BBE468B3F46072091F18003ECAA ] C:\WINDOWS\system32\drivers\sthda.sys
15:43:03.0000 3772 C:\WINDOWS\system32\drivers\sthda.sys - ok
15:43:03.0000 3772 [ 596EB39B50D6EBD9B734DC4AE0544693 ] C:\WINDOWS\system32\drivers\usbd.sys
15:43:03.0000 3772 C:\WINDOWS\system32\drivers\usbd.sys - ok
15:43:03.0000 3772 [ 1AB3CDDE553B6E064D2E754EFE20285C ] C:\WINDOWS\system32\drivers\usbhub.sys
15:43:03.0000 3772 C:\WINDOWS\system32\drivers\usbhub.sys - ok
15:43:03.0000 3772 [ C1B486A7658353D33A10CC15211A873B ] C:\WINDOWS\system32\drivers\cdaudio.sys
15:43:03.0000 3772 C:\WINDOWS\system32\drivers\cdaudio.sys - ok
15:43:03.0015 3772 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] C:\WINDOWS\system32\drivers\fdc.sys
15:43:03.0015 3772 C:\WINDOWS\system32\drivers\fdc.sys - ok
15:43:03.0015 3772 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] C:\WINDOWS\system32\drivers\flpydisk.sys
15:43:03.0015 3772 C:\WINDOWS\system32\drivers\flpydisk.sys - ok
15:43:03.0015 3772 [ 8E6B8C671615D126FDC553D1E2DE5562 ] C:\WINDOWS\system32\drivers\sfloppy.sys
15:43:03.0015 3772 C:\WINDOWS\system32\drivers\sfloppy.sys - ok
15:43:03.0031 3772 [ DA1F27D85E0D1525F6621372E7B685E9 ] C:\WINDOWS\system32\drivers\beep.sys
15:43:03.0031 3772 C:\WINDOWS\system32\drivers\beep.sys - ok
15:43:03.0031 3772 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] C:\WINDOWS\system32\drivers\fs_rec.sys
15:43:03.0031 3772 C:\WINDOWS\system32\drivers\fs_rec.sys - ok
15:43:03.0031 3772 [ 96ECCF28FDBF1B2CC12725818A63628D ] C:\WINDOWS\system32\drivers\hidparse.sys
15:43:03.0031 3772 C:\WINDOWS\system32\drivers\hidparse.sys - ok
15:43:03.0046 3772 [ 4A0B06AA8943C1E332520F7440C0AA30 ] C:\WINDOWS\system32\drivers\i8042prt.sys
15:43:03.0046 3772 C:\WINDOWS\system32\drivers\i8042prt.sys - ok
15:43:03.0046 3772 [ 9EF487A186DEA361AA06913A75B3FA99 ] C:\WINDOWS\system32\drivers\kbdhid.sys
15:43:03.0046 3772 C:\WINDOWS\system32\drivers\kbdhid.sys - ok
15:43:03.0046 3772 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] C:\WINDOWS\system32\drivers\null.sys
15:43:03.0046 3772 C:\WINDOWS\system32\drivers\null.sys - ok
15:43:03.0062 3772 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] C:\WINDOWS\system32\drivers\vga.sys
15:43:03.0062 3772 C:\WINDOWS\system32\drivers\vga.sys - ok
15:43:03.0062 3772 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] C:\WINDOWS\system32\drivers\mnmdd.sys
15:43:03.0062 3772 C:\WINDOWS\system32\drivers\mnmdd.sys - ok
15:43:03.0062 3772 [ 4912D5B403614CE99C28420F75353332 ] C:\WINDOWS\system32\drivers\rdpcdd.sys
15:43:03.0062 3772 C:\WINDOWS\system32\drivers\rdpcdd.sys - ok
15:43:03.0078 3772 [ C941EA2454BA8350021D774DAF0F1027 ] C:\WINDOWS\system32\drivers\msfs.sys
15:43:03.0078 3772 C:\WINDOWS\system32\drivers\msfs.sys - ok
15:43:03.0078 3772 [ 3182D64AE053D6FB034F44B6DEF8034A ] C:\WINDOWS\system32\drivers\npfs.sys
15:43:03.0078 3772 C:\WINDOWS\system32\drivers\npfs.sys - ok
15:43:03.0078 3772 [ 23C74D75E36E7158768DD63D92789A91 ] C:\WINDOWS\system32\drivers\ipsec.sys
15:43:03.0078 3772 C:\WINDOWS\system32\drivers\ipsec.sys - ok
15:43:03.0093 3772 [ FE0D99D6F31E4FAD8159F690D68DED9C ] C:\WINDOWS\system32\drivers\rasacd.sys
15:43:03.0093 3772 C:\WINDOWS\system32\drivers\rasacd.sys - ok
15:43:03.0093 3772 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] C:\WINDOWS\system32\drivers\tcpip.sys
15:43:03.0093 3772 C:\WINDOWS\system32\drivers\tcpip.sys - ok
15:43:03.0109 3772 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] C:\WINDOWS\system32\drivers\netbt.sys
15:43:03.0109 3772 C:\WINDOWS\system32\drivers\netbt.sys - ok
15:43:03.0109 3772 [ CC748EA12C6EFFDE940EE98098BF96BB ] C:\WINDOWS\system32\drivers\ipnat.sys
15:43:03.0109 3772 C:\WINDOWS\system32\drivers\ipnat.sys - ok
15:43:03.0109 3772 [ E20B95BAEDB550F32DD489265C1DA1F6 ] C:\WINDOWS\system32\drivers\wanarp.sys
15:43:03.0109 3772 C:\WINDOWS\system32\drivers\wanarp.sys - ok
15:43:03.0125 3772 [ 5C826F02FF76F07B332C764BB9644F27 ] C:\WINDOWS\system32\vsdatant.sys
15:43:03.0125 3772 C:\WINDOWS\system32\vsdatant.sys - ok
15:43:03.0125 3772 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] C:\WINDOWS\system32\drivers\ws2ifsl.sys
15:43:03.0125 3772 C:\WINDOWS\system32\drivers\ws2ifsl.sys - ok
15:43:03.0125 3772 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] C:\WINDOWS\system32\drivers\afd.sys
15:43:03.0125 3772 C:\WINDOWS\system32\drivers\afd.sys - ok
15:43:03.0140 3772 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] C:\WINDOWS\system32\drivers\netbios.sys
15:43:03.0140 3772 C:\WINDOWS\system32\drivers\netbios.sys - ok
15:43:03.0140 3772 [ 7AD224AD1A1437FE28D89CF22B17780A ] C:\WINDOWS\system32\drivers\rdbss.sys
15:43:03.0140 3772 C:\WINDOWS\system32\drivers\rdbss.sys - ok
15:43:03.0140 3772 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] C:\WINDOWS\system32\drivers\mrxsmb.sys
15:43:03.0140 3772 C:\WINDOWS\system32\drivers\mrxsmb.sys - ok
15:43:03.0156 3772 [ D45926117EB9FA946A6AF572FBE1CAA3 ] C:\WINDOWS\system32\drivers\fips.sys
15:43:03.0156 3772 C:\WINDOWS\system32\drivers\fips.sys - ok
15:43:03.0156 3772 [ CB6FF7012BB5D59D7C12350DB795CE1F ] C:\WINDOWS\system32\drivers\ctxusbm.sys
15:43:03.0156 3772 C:\WINDOWS\system32\drivers\ctxusbm.sys - ok
15:43:03.0156 3772 [ F8F0D25CA553E39DDE485D8FC7FCCE89 ] C:\WINDOWS\system32\ntdll.dll
15:43:03.0156 3772 C:\WINDOWS\system32\ntdll.dll - ok
15:43:03.0171 3772 [ 5F816C1F539266D2D4C78694239DA0B5 ] C:\WINDOWS\system32\smss.exe
15:43:03.0171 3772 C:\WINDOWS\system32\smss.exe - ok
15:43:03.0171 3772 [ 23043C91A0F9DFB4B9E9F87B680863B4 ] C:\WINDOWS\system32\autochk.exe
15:43:03.0171 3772 C:\WINDOWS\system32\autochk.exe - ok
15:43:03.0171 3772 [ 173F317CE0DB8E21322E71B7E60A27E8 ] C:\WINDOWS\system32\drivers\usbccgp.sys
15:43:03.0171 3772 C:\WINDOWS\system32\drivers\usbccgp.sys - ok
15:43:03.0187 3772 [ 9DD07AF82244867CA36681EA2D29CE79 ] C:\WINDOWS\system32\sfcfiles.dll
15:43:03.0187 3772 C:\WINDOWS\system32\sfcfiles.dll - ok
15:43:03.0187 3772 [ C885B02847F5D2FD45A24E219ED93B32 ] C:\WINDOWS\system32\drivers\cdfs.sys
15:43:03.0187 3772 C:\WINDOWS\system32\drivers\cdfs.sys - ok
15:43:03.0187 3772 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] C:\WINDOWS\system32\drivers\usbscan.sys
15:43:03.0187 3772 C:\WINDOWS\system32\drivers\usbscan.sys - ok
15:43:03.0187 3772 [ A717C8721046828520C9EDF31288FC00 ] C:\WINDOWS\system32\drivers\usbprint.sys
15:43:03.0187 3772 C:\WINDOWS\system32\drivers\usbprint.sys - ok
15:43:03.0203 3772 [ ABCB05CCDBF03000354B9553820E39F8 ] C:\WINDOWS\system32\drivers\HPZius12.sys
15:43:03.0203 3772 C:\WINDOWS\system32\drivers\HPZius12.sys - ok
15:43:03.0203 3772 [ D03D10F7DED688FECF50F8FBF1EA9B8A ] C:\WINDOWS\system32\drivers\HPZid412.sys
15:43:03.0203 3772 C:\WINDOWS\system32\drivers\HPZid412.sys - ok
15:43:03.0203 3772 [ 89F41658929393487B6B7D13C8528CE3 ] C:\WINDOWS\system32\drivers\HPZipr12.sys
15:43:03.0203 3772 C:\WINDOWS\system32\drivers\HPZipr12.sys - ok
15:43:03.0218 3772 [ 1AF592532532A402ED7C060F6954004F ] C:\WINDOWS\system32\drivers\hidclass.sys
15:43:03.0218 3772 C:\WINDOWS\system32\drivers\hidclass.sys - ok
15:43:03.0218 3772 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] C:\WINDOWS\system32\drivers\hidusb.sys
15:43:03.0218 3772 C:\WINDOWS\system32\drivers\hidusb.sys - ok
15:43:03.0234 3772 [ B1C303E17FB9D46E87A98E4BA6769685 ] C:\WINDOWS\system32\drivers\mouhid.sys
15:43:03.0234 3772 C:\WINDOWS\system32\drivers\mouhid.sys - ok
15:43:03.0234 3772 [ 2F31B7F954BED437F2C75026C65CAF7B ] C:\WINDOWS\system32\drivers\wmilib.sys
15:43:03.0234 3772 C:\WINDOWS\system32\drivers\wmilib.sys - ok
15:43:03.0234 3772 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] C:\WINDOWS\system32\drivers\atapi.sys
15:43:03.0234 3772 C:\WINDOWS\system32\drivers\atapi.sys - ok
15:43:03.0250 3772 [ FE97D0343ACFDEBDD578FC67CC91FA87 ] C:\WINDOWS\system32\drivers\dxapi.sys
15:43:03.0250 3772 C:\WINDOWS\system32\drivers\dxapi.sys - ok
15:43:03.0250 3772 [ 9A10AACBFDC4922715375FB4065EC930 ] C:\WINDOWS\system32\watchdog.sys
15:43:03.0250 3772 C:\WINDOWS\system32\watchdog.sys - ok
15:43:03.0250 3772 [ BD39EC6064A1B5DFDABCF312A38A37EE ] C:\WINDOWS\system32\win32k.sys
15:43:03.0250 3772 C:\WINDOWS\system32\win32k.sys - ok
15:43:03.0265 3772 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
15:43:03.0265 3772 C:\WINDOWS\system32\basesrv.dll - ok
15:43:03.0265 3772 [ DD40363ABAD230A84C5E2178B11EFA88 ] C:\WINDOWS\system32\csrsrv.dll
15:43:03.0265 3772 C:\WINDOWS\system32\csrsrv.dll - ok
15:43:03.0265 3772 [ 44F275C64738EA2056E3D9580C23B60F ] C:\WINDOWS\system32\csrss.exe
15:43:03.0265 3772 C:\WINDOWS\system32\csrss.exe - ok
15:43:03.0281 3772 [ 8B1F3320AEBB536E021A5014409862DE ] C:\WINDOWS\system32\gdi32.dll
15:43:03.0281 3772 C:\WINDOWS\system32\gdi32.dll - ok
15:43:03.0281 3772 [ 8C7DCA4B158BF16894120786A7A5F366 ] C:\WINDOWS\system32\winsrv.dll
15:43:03.0281 3772 C:\WINDOWS\system32\winsrv.dll - ok
15:43:03.0281 3772 [ 6FE42512AB1B89F32A7407F261B1D2D0 ] C:\WINDOWS\system32\kernel32.dll
15:43:03.0281 3772 C:\WINDOWS\system32\kernel32.dll - ok
15:43:03.0296 3772 [ B26B135FF1B9F60C9388B4A7D16F600B ] C:\WINDOWS\system32\user32.dll
15:43:03.0296 3772 C:\WINDOWS\system32\user32.dll - ok
15:43:03.0296 3772 [ AC7280566A7BB85CB3291F04DDC1198E ] C:\WINDOWS\system32\drivers\dxg.sys
15:43:03.0296 3772 C:\WINDOWS\system32\drivers\dxg.sys - ok
15:43:03.0296 3772 [ A73F5D6705B1D820C19B18782E176EFD ] C:\WINDOWS\system32\drivers\dxgthk.sys
15:43:03.0296 3772 C:\WINDOWS\system32\drivers\dxgthk.sys - ok
15:43:03.0312 3772 [ A70E25C193FE92936665617D3B4973D6 ] C:\WINDOWS\system32\ialmdnt5.dll
15:43:03.0312 3772 C:\WINDOWS\system32\ialmdnt5.dll - ok
15:43:03.0312 3772 [ 4C3E431C30F13918B2B624839C5851D4 ] C:\WINDOWS\system32\ialmrnt5.dll
15:43:03.0312 3772 C:\WINDOWS\system32\ialmrnt5.dll - ok
15:43:03.0312 3772 [ ECB7591870F8BFB1A4C17B718AD5A4AA ] C:\WINDOWS\system32\vga.dll
15:43:03.0312 3772 C:\WINDOWS\system32\vga.dll - ok
15:43:03.0312 3772 [ D3F8D22ED63CDBB7F535AA4A914296C4 ] C:\WINDOWS\system32\ialmdev5.dll
15:43:03.0312 3772 C:\WINDOWS\system32\ialmdev5.dll - ok
15:43:03.0328 3772 [ ECAF48B8262DCEFCC605FABCBB15B6EF ] C:\WINDOWS\system32\ialmdd5.dll
15:43:03.0328 3772 C:\WINDOWS\system32\ialmdd5.dll - ok
15:43:03.0328 3772 [ ED0EF0A136DEC83DF69F04118870003E ] C:\WINDOWS\system32\winlogon.exe
15:43:03.0328 3772 C:\WINDOWS\system32\winlogon.exe - ok
15:43:03.0328 3772 [ E76F8807070ED04E7408A86D6D3A6137 ] C:\WINDOWS\system32\advapi32.dll
15:43:03.0328 3772 C:\WINDOWS\system32\advapi32.dll - ok
15:43:03.0343 3772 [ D4502F124289A31976130CCCB014C9AA ] C:\WINDOWS\system32\rpcrt4.dll
15:43:03.0343 3772 C:\WINDOWS\system32\rpcrt4.dll - ok
15:43:03.0343 3772 [ 5357826C8A8DD6A07F17C48BB45BE46E ] C:\WINDOWS\system32\secur32.dll
15:43:03.0343 3772 C:\WINDOWS\system32\secur32.dll - ok
15:43:03.0359 3772 [ 714705F29A917993536A6AB2DEDB0B7F ] C:\WINDOWS\system32\authz.dll
15:43:03.0359 3772 C:\WINDOWS\system32\authz.dll - ok
15:43:03.0359 3772 [ 355EDBB4D412B01F1740C17E3F50FA00 ] C:\WINDOWS\system32\msvcrt.dll
15:43:03.0359 3772 C:\WINDOWS\system32\msvcrt.dll - ok
15:43:03.0359 3772 [ 6BEE5D4EFF0A0341BCC4A462D81CCFC1 ] C:\WINDOWS\system32\crypt32.dll
15:43:03.0359 3772 C:\WINDOWS\system32\crypt32.dll - ok
15:43:03.0375 3772 [ 04D898830DF96A17A20FD35D7590F87E ] C:\WINDOWS\system32\msasn1.dll
15:43:03.0375 3772 C:\WINDOWS\system32\msasn1.dll - ok
15:43:03.0375 3772 [ 013C1148C1EC025596896E093F60F608 ] C:\WINDOWS\system32\nddeapi.dll
15:43:03.0375 3772 C:\WINDOWS\system32\nddeapi.dll - ok
15:43:03.0375 3772 [ FCFA1C55971CC229D353B3A15ACCD995 ] C:\WINDOWS\system32\profmap.dll
15:43:03.0375 3772 C:\WINDOWS\system32\profmap.dll - ok
15:43:03.0390 3772 [ CAC752BF84DB4666ED3CE0948E6EA937 ] C:\WINDOWS\system32\netapi32.dll
15:43:03.0390 3772 C:\WINDOWS\system32\netapi32.dll - ok
15:43:03.0390 3772 [ 43D13C80EBEC0135A3611E0F616F179B ] C:\WINDOWS\system32\userenv.dll
15:43:03.0390 3772 C:\WINDOWS\system32\userenv.dll - ok
15:43:03.0390 3772 [ 9CFCB3CA3D83B4EAA133F0644A2C6F31 ] C:\WINDOWS\system32\psapi.dll
15:43:03.0390 3772 C:\WINDOWS\system32\psapi.dll - ok
15:43:03.0406 3772 [ AF11C591F2F4AFF4A6CF699D376F618B ] C:\WINDOWS\system32\regapi.dll
15:43:03.0406 3772 C:\WINDOWS\system32\regapi.dll - ok
15:43:03.0406 3772 [ 24192246760E0E64435522E246B1D6C2 ] C:\WINDOWS\system32\setupapi.dll
15:43:03.0406 3772 C:\WINDOWS\system32\setupapi.dll - ok
15:43:03.0406 3772 [ C7CE131408739B0B3A318BE2D0032719 ] C:\WINDOWS\system32\version.dll
15:43:03.0406 3772 C:\WINDOWS\system32\version.dll - ok
15:43:03.0421 3772 [ 430CEB794F6E6EF8AC86958C242366D6 ] C:\WINDOWS\system32\winsta.dll
15:43:03.0421 3772 C:\WINDOWS\system32\winsta.dll - ok
15:43:03.0421 3772 [ D458B738B4C2CE33174CFB2CE12412DB ] C:\WINDOWS\system32\wintrust.dll
15:43:03.0421 3772 C:\WINDOWS\system32\wintrust.dll - ok
15:43:03.0421 3772 [ FFC01A72D1C25CCB39F61B202CE60819 ] C:\WINDOWS\system32\imagehlp.dll
15:43:03.0421 3772 C:\WINDOWS\system32\imagehlp.dll - ok
15:43:03.0437 3772 [ 2CCC474EB85CEAA3E1FA1726580A3E5A ] C:\WINDOWS\system32\ws2_32.dll
15:43:03.0437 3772 C:\WINDOWS\system32\ws2_32.dll - ok
15:43:03.0437 3772 [ 0DA85218E92526972A821587E6A8BF8F ] C:\WINDOWS\system32\imm32.dll
15:43:03.0437 3772 C:\WINDOWS\system32\imm32.dll - ok
15:43:03.0437 3772 [ 9789E95E1D88EEB4B922BF3EA7779C28 ] C:\WINDOWS\system32\ws2help.dll
15:43:03.0437 3772 C:\WINDOWS\system32\ws2help.dll - ok
15:43:03.0437 3772 [ DAB9952E3626D84E74CBF4958B1B1F52 ] C:\WINDOWS\system32\kbduk.dll
15:43:03.0437 3772 C:\WINDOWS\system32\kbduk.dll - ok
15:43:03.0453 3772 [ 56C5B179FE3308B655EB6208C3256FEC ] C:\WINDOWS\system32\kbdus.dll
15:43:03.0453 3772 C:\WINDOWS\system32\kbdus.dll - ok
15:43:03.0453 3772 [ D7B7A57C0E57C836F18CF12A4C62A1CA ] C:\WINDOWS\system32\msgina.dll
15:43:03.0453 3772 C:\WINDOWS\system32\msgina.dll - ok
15:43:03.0453 3772 [ 93AFB83FBC1F9443CAC722FCA63D73BF ] C:\WINDOWS\system32\comctl32.dll
15:43:03.0453 3772 C:\WINDOWS\system32\comctl32.dll - ok
15:43:03.0468 3772 [ 40B0F98BAD16AD5DEF894E88C3EF8014 ] C:\WINDOWS\system32\odbc32.dll
15:43:03.0468 3772 C:\WINDOWS\system32\odbc32.dll - ok
15:43:03.0468 3772 [ 86987A5000DFA3EBE2275C0456BCF2FE ] C:\WINDOWS\system32\comdlg32.dll
15:43:03.0468 3772 C:\WINDOWS\system32\comdlg32.dll - ok
15:43:03.0484 3772 [ 6843D54BC4A40CC8C5741AF750233D10 ] C:\WINDOWS\system32\shell32.dll
15:43:03.0484 3772 C:\WINDOWS\system32\shell32.dll - ok
15:43:03.0484 3772 [ C448A248B743F5FB935C787A5D97268B ] C:\WINDOWS\system32\shlwapi.dll
15:43:03.0484 3772 C:\WINDOWS\system32\shlwapi.dll - ok
15:43:03.0484 3772 [ 694503348B586E99D56C0E30AB5B3EF8 ] C:\WINDOWS\system32\sxs.dll
15:43:03.0484 3772 C:\WINDOWS\system32\sxs.dll - ok
15:43:03.0500 3772 [ 736B12B725AEB2B07F0241A9F680CB10 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
15:43:03.0500 3772 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll - ok
15:43:03.0500 3772 [ 6B7C6B32F8E84D56C6260D684019FEA2 ] C:\WINDOWS\system32\odbcint.dll
15:43:03.0500 3772 C:\WINDOWS\system32\odbcint.dll - ok
15:43:03.0500 3772 [ 99BC0B50F511924348BE19C7C7313BBF ] C:\WINDOWS\system32\shsvcs.dll
15:43:03.0500 3772 C:\WINDOWS\system32\shsvcs.dll - ok
15:43:03.0515 3772 [ 96E1C926F22EE1BFBAE82901A35F6BF3 ] C:\WINDOWS\system32\sfc.dll
15:43:03.0515 3772 C:\WINDOWS\system32\sfc.dll - ok
15:43:03.0515 3772 [ 6B5DB6789177A4FD0DEBC248041D0739 ] C:\WINDOWS\system32\sfc_os.dll
15:43:03.0515 3772 C:\WINDOWS\system32\sfc_os.dll - ok
15:43:03.0515 3772 [ 6BAD1BED9872E62049E487FB91AE2F3A ] C:\WINDOWS\system32\ole32.dll
15:43:03.0515 3772 C:\WINDOWS\system32\ole32.dll - ok
15:43:03.0531 3772 [ CF492D7E9AF1C628B3536D20EF6F5CC7 ] C:\WINDOWS\system32\apphelp.dll
15:43:03.0531 3772 C:\WINDOWS\system32\apphelp.dll - ok
15:43:03.0531 3772 [ BD31DC6DBE9333C4FBD4BDF0899F2160 ] C:\WINDOWS\system32\lsasrv.dll
15:43:03.0531 3772 C:\WINDOWS\system32\lsasrv.dll - ok
15:43:03.0531 3772 [ BF2466B3E18E970D8A976FB95FC1CA85 ] C:\WINDOWS\system32\lsass.exe
15:43:03.0531 3772 C:\WINDOWS\system32\lsass.exe - ok
15:43:03.0546 3772 [ EC29A79F1E76DC509E24D401F29D0678 ] C:\WINDOWS\system32\ncobjapi.dll
15:43:03.0546 3772 C:\WINDOWS\system32\ncobjapi.dll - ok
15:43:03.0546 3772 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
15:43:03.0546 3772 C:\WINDOWS\system32\services.exe - ok
15:43:03.0546 3772 [ F404830F3CD9BF8F2515E489C0CDA297 ] C:\WINDOWS\system32\msvcp60.dll
15:43:03.0546 3772 C:\WINDOWS\system32\msvcp60.dll - ok
15:43:03.0562 3772 [ B24A42A413E694AD73FDFB7FBD492C31 ] C:\WINDOWS\system32\scesrv.dll
15:43:03.0562 3772 C:\WINDOWS\system32\scesrv.dll - ok
15:43:03.0562 3772 [ DD7BD97FB8BD800963789158A5E4B41D ] C:\WINDOWS\system32\mpr.dll
15:43:03.0562 3772 C:\WINDOWS\system32\mpr.dll - ok
15:43:03.0562 3772 [ 2EDFC2A8893435723AD80481803C6D5C ] C:\WINDOWS\system32\umpnpmgr.dll
15:43:03.0562 3772 C:\WINDOWS\system32\umpnpmgr.dll - ok
15:43:03.0578 3772 [ EC4C0D9BFD9F7E33F8B395AD54E13063 ] C:\WINDOWS\system32\ntdsapi.dll
15:43:03.0578 3772 C:\WINDOWS\system32\ntdsapi.dll - ok
15:43:03.0578 3772 [ 1F03103598BD817B1078DAB1326DDE11 ] C:\WINDOWS\system32\shimeng.dll
15:43:03.0578 3772 C:\WINDOWS\system32\shimeng.dll - ok
15:43:03.0593 3772 [ EA9EE60B408878E5F2012F9C783836DB ] C:\WINDOWS\AppPatch\AcAdProc.dll
15:43:03.0593 3772 C:\WINDOWS\AppPatch\AcAdProc.dll - ok
15:43:03.0593 3772 [ 389496118B3B03C2328024AF320132AC ] C:\WINDOWS\system32\dnsapi.dll
15:43:03.0593 3772 C:\WINDOWS\system32\dnsapi.dll - ok
15:43:03.0593 3772 [ 0492CF5870F0E616B0C71695A433D162 ] C:\WINDOWS\system32\wldap32.dll
15:43:03.0593 3772 C:\WINDOWS\system32\wldap32.dll - ok
15:43:03.0609 3772 [ 8329A39D5A402A75A74301D6A62ECDA1 ] C:\WINDOWS\system32\samlib.dll
15:43:03.0609 3772 C:\WINDOWS\system32\samlib.dll - ok
15:43:03.0609 3772 [ F05B8CDB7FE0E55DCCFB1D946CE80064 ] C:\WINDOWS\system32\samsrv.dll
15:43:03.0609 3772 C:\WINDOWS\system32\samsrv.dll - ok
15:43:03.0625 3772 [ 310C15FD8358B2C4CD7A5B98A112883F ] C:\WINDOWS\AppPatch\AcGenral.dll
15:43:03.0625 3772 C:\WINDOWS\AppPatch\AcGenral.dll - ok
15:43:03.0625 3772 [ 17A1D675C12BBF80CAAC54A4855C41D0 ] C:\WINDOWS\system32\cryptdll.dll
15:43:03.0625 3772 C:\WINDOWS\system32\cryptdll.dll - ok
15:43:03.0625 3772 [ EFF03460E542EEA6B0ABDEC6BF19C897 ] C:\WINDOWS\system32\oleaut32.dll
15:43:03.0625 3772 C:\WINDOWS\system32\oleaut32.dll - ok
15:43:03.0640 3772 [ 4A953F13942867BA8FB41F141EC1B80C ] C:\WINDOWS\system32\winmm.dll
15:43:03.0640 3772 C:\WINDOWS\system32\winmm.dll - ok
15:43:03.0640 3772 [ 2098AB52BD5316E59AA36F3437B13BE6 ] C:\WINDOWS\system32\msacm32.dll
15:43:03.0640 3772 C:\WINDOWS\system32\msacm32.dll - ok
15:43:03.0640 3772 [ 7A2CC3719B255E6B5D74396183B7715B ] C:\WINDOWS\system32\uxtheme.dll
15:43:03.0640 3772 C:\WINDOWS\system32\uxtheme.dll - ok
15:43:03.0656 3772 [ F24B12786D60A17008319E3F2AEE7799 ] C:\WINDOWS\system32\msapsspc.dll
15:43:03.0656 3772 C:\WINDOWS\system32\msapsspc.dll - ok
15:43:03.0656 3772 [ 7A660EDC0757849DF5F8706FB6E9F740 ] C:\WINDOWS\system32\msvcrt40.dll
15:43:03.0656 3772 C:\WINDOWS\system32\msvcrt40.dll - ok
15:43:03.0656 3772 [ 3D76DD0CBC536E0F8C45D23ED230BEB2 ] C:\WINDOWS\system32\digest.dll
15:43:03.0656 3772 C:\WINDOWS\system32\digest.dll - ok
15:43:03.0671 3772 [ 0F64207B49390C8063C36AE7CBF9C2DB ] C:\WINDOWS\system32\schannel.dll
15:43:03.0671 3772 C:\WINDOWS\system32\schannel.dll - ok
15:43:03.0671 3772 [ A4388DF80E52695AE92EE5F3F61F1619 ] C:\WINDOWS\system32\msnsspc.dll
15:43:03.0671 3772 C:\WINDOWS\system32\msnsspc.dll - ok
15:43:03.0671 3772 [ A525C96C51D55111FDF3BEA9FFFFC7AE ] C:\WINDOWS\system32\kerberos.dll
15:43:03.0671 3772 C:\WINDOWS\system32\kerberos.dll - ok
15:43:03.0687 3772 [ 5733177BCF16EE78B99543C9B0AB81EA ] C:\WINDOWS\system32\MSCTFIME.IME
15:43:03.0687 3772 C:\WINDOWS\system32\MSCTFIME.IME - ok
15:43:03.0687 3772 [ C6BB1D1500DB4A0E224CB65E6C7E8A80 ] C:\WINDOWS\system32\msprivs.dll
15:43:03.0687 3772 C:\WINDOWS\system32\msprivs.dll - ok
15:43:03.0703 3772 [ 517561A1113B04E51D936CD018DE1C1F ] C:\WINDOWS\system32\msv1_0.dll
15:43:03.0703 3772 C:\WINDOWS\system32\msv1_0.dll - ok
15:43:03.0703 3772 [ C11D10A3C164AC222BC9AAB3650A88B3 ] C:\WINDOWS\system32\atmfd.dll
15:43:03.0703 3772 C:\WINDOWS\system32\atmfd.dll - ok
15:43:03.0703 3772 [ AF07DC9B7CC455629E732340C7B15F3A ] C:\WINDOWS\system32\iphlpapi.dll
15:43:03.0703 3772 C:\WINDOWS\system32\iphlpapi.dll - ok
15:43:03.0718 3772 [ 1B7F071C51B77C272875C3A23E1E4550 ] C:\WINDOWS\system32\netlogon.dll
15:43:03.0718 3772 C:\WINDOWS\system32\netlogon.dll - ok
15:43:03.0718 3772 [ 54AF4B1D5459500EF0937F6D33B1914F ] C:\WINDOWS\system32\w32time.dll
15:43:03.0718 3772 C:\WINDOWS\system32\w32time.dll - ok
15:43:03.0734 3772 [ 54DAE3EA34802B4ED9AE1C6B1209FA56 ] C:\WINDOWS\system32\rsaenh.dll
15:43:03.0734 3772 C:\WINDOWS\system32\rsaenh.dll - ok
15:43:03.0734 3772 [ 3AAF9B35939FF9E58CCD18D41655C2FC ] C:\WINDOWS\system32\wdigest.dll
15:43:03.0734 3772 C:\WINDOWS\system32\wdigest.dll - ok
15:43:03.0750 3772 [ 02988B904C386B500CD08639C4C20EEA ] C:\WINDOWS\system32\winscard.dll
15:43:03.0750 3772 C:\WINDOWS\system32\winscard.dll - ok
15:43:03.0750 3772 [ 0E2735281FBB9A764D5584C2A5DCBA59 ] C:\WINDOWS\system32\wtsapi32.dll
15:43:03.0750 3772 C:\WINDOWS\system32\wtsapi32.dll - ok
15:43:03.0750 3772 [ A86BB5E61BF3E39B62AB4C7E7085A084 ] C:\WINDOWS\system32\scecli.dll
15:43:03.0750 3772 C:\WINDOWS\system32\scecli.dll - ok
15:43:03.0765 3772 [ 27C6D03BCDB8CFEB96B716F3D8BE3E18 ] C:\WINDOWS\system32\svchost.exe
15:43:03.0765 3772 C:\WINDOWS\system32\svchost.exe - ok
15:43:03.0765 3772 [ 549290DBC280C887681D7652978DBBE0 ] C:\WINDOWS\system32\ntmarta.dll
15:43:03.0765 3772 C:\WINDOWS\system32\ntmarta.dll - ok
15:43:03.0765 3772 [ 6B27A5C03DFB94B4245739065431322C ] C:\WINDOWS\system32\rpcss.dll
15:43:03.0765 3772 C:\WINDOWS\system32\rpcss.dll - ok
15:43:03.0781 3772 [ 16403217AB6FC5C30C14C6B12098AD4B ] C:\WINDOWS\system32\xpsp2res.dll
15:43:03.0781 3772 C:\WINDOWS\system32\xpsp2res.dll - ok
15:43:03.0781 3772 [ 6D4FEB43EE538FC5428CC7F0565AA656 ] C:\WINDOWS\system32\eventlog.dll
15:43:03.0781 3772 C:\WINDOWS\system32\eventlog.dll - ok
15:43:03.0781 3772 [ 943337D786A56729263071623BBB9DE5 ] C:\WINDOWS\system32\mswsock.dll
15:43:03.0781 3772 C:\WINDOWS\system32\mswsock.dll - ok
15:43:03.0796 3772 [ 3CB32D3B8CBE79899D63280BB7A83CD9 ] C:\WINDOWS\system32\hnetcfg.dll
15:43:03.0796 3772 C:\WINDOWS\system32\hnetcfg.dll - ok
15:43:03.0796 3772 [ 4E3D06D6E68EEDB52565080F55B460D3 ] C:\WINDOWS\system32\wshtcpip.dll
15:43:03.0796 3772 C:\WINDOWS\system32\wshtcpip.dll - ok
15:43:03.0796 3772 [ 40947436A70E0034E41123DF5A0A7702 ] C:\Program Files\Bonjour\mdnsNSP.dll
15:43:03.0796 3772 C:\Program Files\Bonjour\mdnsNSP.dll - ok
15:43:03.0812 3772 [ D72B9EC3337B247A666F098F3D6B43DE ] C:\WINDOWS\system32\winrnr.dll
15:43:03.0812 3772 C:\WINDOWS\system32\winrnr.dll - ok
15:43:03.0812 3772 [ 6F9BEF24C578D5D6740E080BEDD6A448 ] C:\WINDOWS\system32\rasadhlp.dll
15:43:03.0812 3772 C:\WINDOWS\system32\rasadhlp.dll - ok
15:43:03.0812 3772 [ F556912E70B22D740C9C99E310E3C11F ] C:\Program Files\Microsoft Security Client\MpSvc.dll
15:43:03.0812 3772 C:\Program Files\Microsoft Security Client\MpSvc.dll - ok
15:43:03.0828 3772 [ C1F19D2BACBEE9AB64D9AE69E9859AC0 ] C:\Program Files\Microsoft Security Client\MsMpEng.exe
15:43:03.0828 3772 C:\Program Files\Microsoft Security Client\MsMpEng.exe - ok
15:43:03.0828 3772 [ 3D9381A332E4373F8811C71BA5078B31 ] C:\Program Files\Microsoft Security Client\MpClient.dll
15:43:03.0828 3772 C:\Program Files\Microsoft Security Client\MpClient.dll - ok
15:43:03.0828 3772 [ 05231C04253C5BC30B26CBAAE680ED89 ] C:\WINDOWS\system32\WudfSvc.dll
15:43:03.0828 3772 C:\WINDOWS\system32\WudfSvc.dll - ok
15:43:03.0843 3772 [ 5CAF91E865FE0C85048A233E594544D2 ] C:\WINDOWS\system32\WudfPlatform.dll
15:43:03.0843 3772 C:\WINDOWS\system32\WudfPlatform.dll - ok
15:43:03.0843 3772 [ AA87D7709021503687326432DC59590D ] C:\Program Files\Microsoft Security Client\MpRTP.dll
15:43:03.0843 3772 C:\Program Files\Microsoft Security Client\MpRTP.dll - ok
15:43:03.0859 3772 [ 5D43C9A33F18C707BA169AFDA88BDF30 ] C:\WINDOWS\system32\fltlib.dll
15:43:03.0859 3772 C:\WINDOWS\system32\fltlib.dll - ok
15:43:03.0859 3772 [ 2081A5B5E4ABA206A0A8A1A97DF0FB23 ] C:\WINDOWS\system32\logonui.exe
15:43:03.0859 3772 C:\WINDOWS\system32\logonui.exe - ok
15:43:03.0859 3772 [ 515A7FAE2070C2B0242B2353443E2F11 ] C:\WINDOWS\system32\cscdll.dll
15:43:03.0859 3772 C:\WINDOWS\system32\cscdll.dll - ok
15:43:03.0875 3772 [ 3D41A9326F0376FC73AF961DD23B1FB1 ] C:\WINDOWS\system32\duser.dll
15:43:03.0875 3772 C:\WINDOWS\system32\duser.dll - ok
15:43:03.0875 3772 [ E2092F0A1D7ABC243F9C2362483D150D ] C:\WINDOWS\system32\dimsntfy.dll
15:43:03.0875 3772 C:\WINDOWS\system32\dimsntfy.dll - ok
15:43:03.0875 3772 [ 2CC34E8BB667EEF78899546E12649196 ] C:\WINDOWS\system32\wlnotify.dll
15:43:03.0875 3772 C:\WINDOWS\system32\wlnotify.dll - ok
15:43:03.0890 3772 [ BD83ABA61E8ACCC8D9FFB869F29418CE ] C:\WINDOWS\system32\winspool.drv
15:43:03.0890 3772 C:\WINDOWS\system32\winspool.drv - ok
15:43:03.0890 3772 [ F34C06D1C706A6D9433570B087A18B02 ] C:\WINDOWS\system32\drivers\Scutum50.sys
15:43:03.0890 3772 C:\WINDOWS\system32\drivers\Scutum50.sys - ok
15:43:03.0890 3772 [ F927A4434C5028758A842943EF1A3849 ] C:\WINDOWS\system32\drivers\ndisuio.sys
15:43:03.0890 3772 C:\WINDOWS\system32\drivers\ndisuio.sys - ok
15:43:03.0890 3772 [ 5E38D7684A49CACFB752B046357E0589 ] C:\WINDOWS\system32\dhcpcsvc.dll
15:43:03.0890 3772 C:\WINDOWS\system32\dhcpcsvc.dll - ok
15:43:03.0906 3772 [ AFFC87E2501FCE8F09D4C10BA6421CCF ] C:\WINDOWS\system32\msimg32.dll
15:43:03.0906 3772 C:\WINDOWS\system32\msimg32.dll - ok
15:43:03.0906 3772 [ 20200EE3CFE10E9F0C028D8653BE11C6 ] C:\WINDOWS\system32\oleacc.dll
15:43:03.0906 3772 C:\WINDOWS\system32\oleacc.dll - ok
15:43:03.0906 3772 [ 02CF580510234E519736559A7F19EA20 ] C:\WINDOWS\system32\WgaLogon.dll
15:43:03.0906 3772 C:\WINDOWS\system32\WgaLogon.dll - ok
15:43:03.0921 3772 [ F137A0CA70003DB20448D540651FA003 ] C:\WINDOWS\system32\clbcatq.dll
15:43:03.0921 3772 C:\WINDOWS\system32\clbcatq.dll - ok
15:43:03.0921 3772 [ 5F7E24FA9EAB896051FFB87F840730D2 ] C:\WINDOWS\system32\dnsrslvr.dll
15:43:03.0921 3772 C:\WINDOWS\system32\dnsrslvr.dll - ok
15:43:03.0921 3772 [ 1280A158C722FA95A80FB7AEBE78FA7D ] C:\WINDOWS\system32\comres.dll
15:43:03.0921 3772 C:\WINDOWS\system32\comres.dll - ok
15:43:03.0937 3772 [ ACFEE2392503DD5E457363A0510B8BCB ] C:\WINDOWS\system32\msxml3.dll
15:43:03.0937 3772 C:\WINDOWS\system32\msxml3.dll - ok
15:43:03.0937 3772 [ E5EDBD51476DB5001ABF5C82AE5C3DD1 ] C:\WINDOWS\system32\shgina.dll
15:43:03.0937 3772 C:\WINDOWS\system32\shgina.dll - ok
15:43:03.0937 3772 [ 3D4E199942E29207970E04315D02AD3B ] C:\WINDOWS\system32\cryptsvc.dll
15:43:03.0937 3772 C:\WINDOWS\system32\cryptsvc.dll - ok
15:43:03.0953 3772 [ A7DB739AE99A796D91580147E919CC59 ] C:\WINDOWS\system32\lmhsvc.dll
15:43:03.0953 3772 C:\WINDOWS\system32\lmhsvc.dll - ok
15:43:03.0953 3772 [ 00709952D444EAE14DBBD30D36FBAE0F ] C:\WINDOWS\system32\certcli.dll
15:43:03.0953 3772 C:\WINDOWS\system32\certcli.dll - ok
15:43:03.0953 3772 [ 224FB925C641DA16CEB6D60F40CA4C75 ] C:\WINDOWS\system32\atl.dll
15:43:03.0953 3772 C:\WINDOWS\system32\atl.dll - ok
15:43:03.0968 3772 [ 6E4BE11D50F8A8DE2BAD644C9C9DE8D3 ] C:\WINDOWS\system32\cryptui.dll
15:43:03.0968 3772 C:\WINDOWS\system32\cryptui.dll - ok
15:43:03.0968 3772 [ 5AACF4B4DEE1972B7952E8A747122232 ] C:\WINDOWS\system32\wininet.dll
15:43:03.0968 3772 C:\WINDOWS\system32\wininet.dll - ok
15:43:03.0968 3772 [ 10753A3ADC3E39A3B10CC3F08E98E6B4 ] C:\WINDOWS\system32\normaliz.dll
15:43:03.0968 3772 C:\WINDOWS\system32\normaliz.dll - ok
15:43:03.0984 3772 [ C332870084DB9164F465D6F1B7472728 ] C:\WINDOWS\system32\urlmon.dll
15:43:03.0984 3772 C:\WINDOWS\system32\urlmon.dll - ok
15:43:03.0984 3772 [ 47464CA4943F82E1B8FCB2C57DA15F83 ] C:\WINDOWS\system32\iertutil.dll
15:43:03.0984 3772 C:\WINDOWS\system32\iertutil.dll - ok
15:43:03.0984 3772 [ 9F4003841689C663254D54177EB97219 ] C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{672C0FA1-C712-4379-928A-1DBC39B85ED1}\mpengine.dll
15:43:03.0984 3772 C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{672C0FA1-C712-4379-928A-1DBC39B85ED1}\mpengine.dll - ok
15:43:04.0000 3772 [ F5B754CDEA20BBB3A31E16A776EDE6D6 ] C:\WINDOWS\system32\esent.dll
15:43:04.0000 3772 C:\WINDOWS\system32\esent.dll - ok
15:43:04.0000 3772 [ C1FAEA15E41F62D7BFA7FBC395C24BA6 ] C:\WINDOWS\system32\riched20.dll
15:43:04.0000 3772 C:\WINDOWS\system32\riched20.dll - ok
15:43:04.0000 3772 [ 7C89F125919D8DF7E413CA1751A6412E ] C:\Program Files\CheckPoint\ZoneAlarm\vsdata.dll
15:43:04.0000 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsdata.dll - ok
15:43:04.0015 3772 [ E50A1E6A7D17C79F0A433F5D748FE725 ] C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
15:43:04.0015 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe - ok
15:43:04.0015 3772 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] C:\WINDOWS\system32\wzcsvc.dll
15:43:04.0015 3772 C:\WINDOWS\system32\wzcsvc.dll - ok
15:43:04.0015 3772 [ 655CBD271A6DFC5AC80E5F3E11E4B38B ] C:\Program Files\CheckPoint\ZoneAlarm\vsinit.dll
15:43:04.0015 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsinit.dll - ok
15:43:04.0031 3772 [ 4C39358EBDD2FFCD9132A30E1EC31E16 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
15:43:04.0031 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll - ok
15:43:04.0031 3772 [ 876CCF164E08D6B903CD14398E056DD2 ] C:\WINDOWS\system32\rtutils.dll
15:43:04.0031 3772 C:\WINDOWS\system32\rtutils.dll - ok
15:43:04.0031 3772 [ E6EF7BC927D9F8F9BA1584BFC39E0C6F ] C:\WINDOWS\system32\eapolqec.dll
15:43:04.0031 3772 C:\WINDOWS\system32\eapolqec.dll - ok
15:43:04.0046 3772 [ 7B0770526801F05D58C51A3DFB87B4BD ] C:\WINDOWS\system32\wmi.dll
15:43:04.0046 3772 C:\WINDOWS\system32\wmi.dll - ok
15:43:04.0046 3772 [ 8AE93AACC648921BAACB8602991AC4B3 ] C:\WINDOWS\system32\qutil.dll
15:43:04.0046 3772 C:\WINDOWS\system32\qutil.dll - ok
15:43:04.0046 3772 [ 8E2CC37BA87D8F681066E0E9C8A19F73 ] C:\WINDOWS\system32\dot3api.dll
15:43:04.0046 3772 C:\WINDOWS\system32\dot3api.dll - ok
15:43:04.0062 3772 [ CDBE9690CF2B8409FACAD94FAC9479C9 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
15:43:04.0062 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll - ok
15:43:04.0062 3772 [ A39BE37C9237DB5F1990D61B268EA555 ] C:\WINDOWS\system32\rastls.dll
15:43:04.0062 3772 C:\WINDOWS\system32\rastls.dll - ok
15:43:04.0062 3772 [ EA5B8BECA3F279C757578CD7F1E95855 ] C:\WINDOWS\system32\mprapi.dll
15:43:04.0062 3772 C:\WINDOWS\system32\mprapi.dll - ok
15:43:04.0078 3772 [ 2CDAE321B8E878A278BA2D2FA013060B ] C:\WINDOWS\system32\activeds.dll
15:43:04.0078 3772 C:\WINDOWS\system32\activeds.dll - ok
15:43:04.0078 3772 [ 67156D5A9AC356DC99D7BCCB388E3316 ] C:\WINDOWS\system32\wsock32.dll
15:43:04.0078 3772 C:\WINDOWS\system32\wsock32.dll - ok
15:43:04.0078 3772 [ B5A2AE4566EF65A36886FEC57131BE56 ] C:\Program Files\CheckPoint\ZoneAlarm\vsutil.dll
15:43:04.0078 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsutil.dll - ok
15:43:04.0093 3772 [ 0D84657DBF93DB98673DEFDF2B29E25A ] C:\WINDOWS\system32\adsldpc.dll
15:43:04.0093 3772 C:\WINDOWS\system32\adsldpc.dll - ok
15:43:04.0093 3772 [ 92C4F48B62B0B876194584C3FF09CCB6 ] C:\WINDOWS\system32\rasapi32.dll
15:43:04.0093 3772 C:\WINDOWS\system32\rasapi32.dll - ok
15:43:04.0109 3772 [ 4DEF926F6A0545AE486A03C84F2EE482 ] C:\WINDOWS\system32\rasman.dll
15:43:04.0109 3772 C:\WINDOWS\system32\rasman.dll - ok
15:43:04.0109 3772 [ 00AABF131B4823785818DB99A075A313 ] C:\WINDOWS\system32\tapi32.dll
15:43:04.0109 3772 C:\WINDOWS\system32\tapi32.dll - ok
15:43:04.0109 3772 [ 56CE97FF94B7662A300D359CD6F4D601 ] C:\WINDOWS\system32\raschap.dll
15:43:04.0109 3772 C:\WINDOWS\system32\raschap.dll - ok
15:43:04.0125 3772 [ DD072705435259D5ABB5D7E0C348EB35 ] C:\Program Files\CheckPoint\ZoneAlarm\dbghelp.dll
15:43:04.0125 3772 C:\Program Files\CheckPoint\ZoneAlarm\dbghelp.dll - ok
15:43:04.0125 3772 [ 66F67AA5A830BAED4CBBB00032AB0514 ] C:\Program Files\CheckPoint\ZoneAlarm\icslta.dll
15:43:04.0125 3772 C:\Program Files\CheckPoint\ZoneAlarm\icslta.dll - ok
15:43:04.0125 3772 [ AC148E516BF11F3E5A369910042E140C ] C:\Program Files\CheckPoint\ZoneAlarm\ssleay32.dll
15:43:04.0125 3772 C:\Program Files\CheckPoint\ZoneAlarm\ssleay32.dll - ok
15:43:04.0140 3772 [ 378F3604E16B3C758C409683FA712288 ] C:\Program Files\CheckPoint\ZoneAlarm\vsdb.dll
15:43:04.0140 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsdb.dll - ok
15:43:04.0140 3772 [ 0DDB0DA30505B719A71B7F3C02778005 ] C:\Program Files\CheckPoint\ZoneAlarm\vsxml.dll
15:43:04.0140 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsxml.dll - ok
15:43:04.0140 3772 [ 109A7562602FA3B596123062DA8C9AD9 ] C:\Program Files\CheckPoint\ZoneAlarm\fbl.dll
15:43:04.0140 3772 C:\Program Files\CheckPoint\ZoneAlarm\fbl.dll - ok
15:43:04.0156 3772 [ 0C0138667F0D0285F4E569D96B60BBB0 ] C:\Program Files\CheckPoint\ZoneAlarm\featuremap.dll
15:43:04.0156 3772 C:\Program Files\CheckPoint\ZoneAlarm\featuremap.dll - ok
15:43:04.0156 3772 [ 9DF55B85A5FA2BA585EDD3277A213A64 ] C:\Program Files\CheckPoint\ZoneAlarm\vswmi.dll
15:43:04.0156 3772 C:\Program Files\CheckPoint\ZoneAlarm\vswmi.dll - ok
15:43:04.0156 3772 [ C283605E6B2B354883AD28A73F4BA336 ] C:\Program Files\CheckPoint\ZoneAlarm\zlcomm.dll
15:43:04.0156 3772 C:\Program Files\CheckPoint\ZoneAlarm\zlcomm.dll - ok
15:43:04.0171 3772 [ 0807425682950F99F74CDC3C0BEDA5BE ] C:\Program Files\CheckPoint\ZoneAlarm\zlcommdb.dll
15:43:04.0171 3772 C:\Program Files\CheckPoint\ZoneAlarm\zlcommdb.dll - ok
15:43:04.0171 3772 [ 56D35F6344504904AA5DFD71BF2AF6C3 ] C:\Program Files\CheckPoint\ZoneAlarm\vsruledb.dll
15:43:04.0171 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsruledb.dll - ok
15:43:04.0171 3772 [ B714735C12A70171DE28657948FD91F1 ] C:\WINDOWS\system32\mlang.dll
15:43:04.0171 3772 C:\WINDOWS\system32\mlang.dll - ok
15:43:04.0171 3772 [ 566382CA5F2C41FEAEEEFAC908F1EB92 ] C:\WINDOWS\system32\xmlprovi.dll
15:43:04.0171 3772 C:\WINDOWS\system32\xmlprovi.dll - ok
15:43:04.0187 3772 [ 767FF54A552732CE772C2302025FA82F ] C:\WINDOWS\system32\wzcsapi.dll
15:43:04.0187 3772 C:\WINDOWS\system32\wzcsapi.dll - ok
15:43:04.0187 3772 [ FCC3B0AABB49BE4915CCA18F1DFE161C ] C:\Program Files\CheckPoint\ZoneAlarm\vsvault.dll
15:43:04.0187 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsvault.dll - ok
15:43:04.0187 3772 [ CB6B671ED6D97F2E9F2274EADB7517B2 ] C:\Program Files\Microsoft Security Client\MpCmdRun.exe
15:43:04.0187 3772 C:\Program Files\Microsoft Security Client\MpCmdRun.exe - ok
15:43:04.0203 3772 [ F9D3C78CFE15271D80790677C893CE45 ] C:\WINDOWS\system32\cabinet.dll
15:43:04.0203 3772 C:\WINDOWS\system32\cabinet.dll - ok
15:43:04.0203 3772 [ 09DEF3ABB6A196749299359AC5578DD8 ] C:\WINDOWS\system32\msxml4.dll
15:43:04.0203 3772 C:\WINDOWS\system32\msxml4.dll - ok
15:43:04.0203 3772 [ C14350FC0D47D806699C4F907FC6785B ] C:\WINDOWS\system32\cryptnet.dll
15:43:04.0203 3772 C:\WINDOWS\system32\cryptnet.dll - ok
15:43:04.0218 3772 [ 3CBA2210FA39C6ED7895634842E930DD ] C:\WINDOWS\system32\sensapi.dll
15:43:04.0218 3772 C:\WINDOWS\system32\sensapi.dll - ok
15:43:04.0218 3772 [ 684559A03CBC1D05BA120A18B0D8BA5D ] C:\WINDOWS\system32\winhttp.dll
15:43:04.0218 3772 C:\WINDOWS\system32\winhttp.dll - ok
15:43:04.0234 3772 [ 205ADD80FF8099B1A8101EB490B933D1 ] C:\WINDOWS\system32\wbem\wbemprox.dll
15:43:04.0234 3772 C:\WINDOWS\system32\wbem\wbemprox.dll - ok
15:43:04.0234 3772 [ D95C71052E5EF63B55997FB31483D02F ] C:\WINDOWS\system32\wbem\wbemcomn.dll
15:43:04.0234 3772 C:\WINDOWS\system32\wbem\wbemcomn.dll - ok
15:43:04.0234 3772 [ 11056136E8EFF4B3B08F01259CF0EF5E ] C:\Program Files\CheckPoint\ZoneAlarm\scheduler.dll
15:43:04.0234 3772 C:\Program Files\CheckPoint\ZoneAlarm\scheduler.dll - ok
15:43:04.0250 3772 [ 1BBF1E9562EE56B1C97BA5426BC16C5E ] C:\Program Files\CheckPoint\ZoneAlarm\zlupdate.dll
15:43:04.0250 3772 C:\Program Files\CheckPoint\ZoneAlarm\zlupdate.dll - ok
15:43:04.0250 3772 [ 05765DB6997E2AA035B02C13A2C5E662 ] C:\Program Files\CheckPoint\ZoneAlarm\zdx.dll
15:43:04.0250 3772 C:\Program Files\CheckPoint\ZoneAlarm\zdx.dll - ok
15:43:04.0250 3772 [ 724A6A9AB5E1807665C5DB71C30BFC5F ] C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys
15:43:04.0250 3772 C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys - ok
15:43:04.0250 3772 [ 57FE873B8246DEF1372503CBC57A7499 ] C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe
15:43:04.0250 3772 C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe - ok
15:43:04.0265 3772 [ C9564CF4976E7E96B4052737AA2492B4 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
15:43:04.0265 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll - ok
15:43:04.0265 3772 [ 0B3595A4FF0B36D68E5FC67FD7D70FDC ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
15:43:04.0265 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll - ok
15:43:04.0265 3772 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] C:\WINDOWS\system32\schedsvc.dll
15:43:04.0265 3772 C:\WINDOWS\system32\schedsvc.dll - ok
15:43:04.0281 3772 [ 746989EB81B6050163F86EBBBE44F260 ] C:\Program Files\CheckPoint\ZAForceField\ISWUL.dll
15:43:04.0281 3772 C:\Program Files\CheckPoint\ZAForceField\ISWUL.dll - ok
15:43:04.0281 3772 [ 085ED2E391A871C7BAE87E0228B546BA ] C:\WINDOWS\system32\cscui.dll
15:43:04.0281 3772 C:\WINDOWS\system32\cscui.dll - ok
15:43:04.0281 3772 [ E47E364C96467FD54FA44D59F927C3AB ] C:\WINDOWS\system32\msidle.dll
15:43:04.0281 3772 C:\WINDOWS\system32\msidle.dll - ok
15:43:04.0296 3772 [ 60784F891563FB1B767F70117FC2428F ] C:\WINDOWS\system32\spoolsv.exe
15:43:04.0296 3772 C:\WINDOWS\system32\spoolsv.exe - ok
15:43:04.0296 3772 [ 50A166237A0FA771261275A405646CC0 ] C:\WINDOWS\system32\powrprof.dll
15:43:04.0296 3772 C:\WINDOWS\system32\powrprof.dll - ok
15:43:04.0296 3772 [ 6C26DCF01E2A92F183B97D434017268A ] C:\WINDOWS\system32\dpcdll.dll
15:43:04.0296 3772 C:\WINDOWS\system32\dpcdll.dll - ok
15:43:04.0312 3772 [ DEF7A7882BEC100FE0B2CE2549188F9D ] C:\WINDOWS\system32\audiosrv.dll
15:43:04.0312 3772 C:\WINDOWS\system32\audiosrv.dll - ok
15:43:04.0312 3772 [ A8888A5327621856C0CEC4E385F69309 ] C:\WINDOWS\system32\wkssvc.dll
15:43:04.0312 3772 C:\WINDOWS\system32\wkssvc.dll - ok
15:43:04.0312 3772 [ 6FE42512AB1B89F32A7407F261B1D2D0 ] C:\WINDOWS\temp\IswTmp\WH\0
15:43:04.0312 3772 C:\WINDOWS\temp\IswTmp\WH\0 - ok
15:43:04.0328 3772 [ 71F503BAD4C1141067AECA573908B4E9 ] C:\Program Files\CheckPoint\ZAForceField\ZDXUI.dll
15:43:04.0328 3772 C:\Program Files\CheckPoint\ZAForceField\ZDXUI.dll - ok
15:43:04.0328 3772 [ 258444AC2AAD2A51820E6975D5A1F556 ] C:\Program Files\CheckPoint\ZAForceField\FFApi.dll
15:43:04.0328 3772 C:\Program Files\CheckPoint\ZAForceField\FFApi.dll - ok
15:43:04.0328 3772 [ C9DF1AA04B09228D746536A90F01C73C ] C:\Program Files\CheckPoint\ZAForceField\ISWUILib.dll
15:43:04.0328 3772 C:\Program Files\CheckPoint\ZAForceField\ISWUILib.dll - ok
15:43:04.0375 3772 [ 80776884E7A05D6DA5040926F82B0273 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll
15:43:04.0375 3772 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll - ok
15:43:04.0375 3772 [ 9A7803D33692D1F373A99F7594D3145F ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll
15:43:04.0375 3772 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWDMP.dll - ok
15:43:04.0375 3772 [ AEDE14835589701A3BE1CC2BD7470364 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWMENUS.dll
15:43:04.0375 3772 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWMENUS.dll - ok
15:43:04.0375 3772 [ 1A3FB4E84D8FE3801BE6B2220F1E38C4 ] C:\Program Files\CheckPoint\ZAForceField\Zdx.dll
15:43:04.0375 3772 C:\Program Files\CheckPoint\ZAForceField\Zdx.dll - ok
15:43:04.0375 3772 [ 59292F5B1A88218F442B4485D0FD5C41 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSTATS.dll
15:43:04.0375 3772 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWSTATS.dll - ok
15:43:04.0390 3772 [ 662D13021A8E793615D55B1F7E741655 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll
15:43:04.0390 3772 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWFWMON.dll - ok
15:43:04.0390 3772 [ 42DD9011D54C3A91F14BDBBF50791DA9 ] C:\Program Files\Microsoft Security Client\MsseWat.dll
15:43:04.0390 3772 C:\Program Files\Microsoft Security Client\MsseWat.dll - ok
15:43:04.0390 3772 [ 7C7AB513C5D9920ACAFFFF698C3E9529 ] C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWUPD.dll
15:43:04.0390 3772 C:\Program Files\CheckPoint\ZAForceField\Plugins\ISWUPD.dll - ok
15:43:04.0406 3772 [ A26E0A6A7EBB45815A3583E170C27031 ] C:\Program Files\Microsoft Security Client\LegitLib.dll
15:43:04.0406 3772 C:\Program Files\Microsoft Security Client\LegitLib.dll - ok
15:43:04.0406 3772 [ 680B56A8B62D1BCF4A0B2AAAD03D88E4 ] C:\WINDOWS\system32\wdmaud.drv
15:43:04.0406 3772 C:\WINDOWS\system32\wdmaud.drv - ok
15:43:04.0406 3772 [ 6768ACF64B18196494413695F0C3A00F ] C:\WINDOWS\system32\drivers\wdmaud.sys
15:43:04.0406 3772 C:\WINDOWS\system32\drivers\wdmaud.sys - ok
15:43:04.0421 3772 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] C:\WINDOWS\system32\drivers\sysaudio.sys
15:43:04.0421 3772 C:\WINDOWS\system32\drivers\sysaudio.sys - ok
15:43:04.0421 3772 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] C:\WINDOWS\system32\drivers\splitter.sys
15:43:04.0421 3772 C:\WINDOWS\system32\drivers\splitter.sys - ok
15:43:04.0421 3772 [ 8BED39E3C35D6A489438B8141717A557 ] C:\WINDOWS\system32\drivers\aec.sys
15:43:04.0421 3772 C:\WINDOWS\system32\drivers\aec.sys - ok
15:43:04.0437 3772 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] C:\WINDOWS\system32\drivers\swmidi.sys
15:43:04.0437 3772 C:\WINDOWS\system32\drivers\swmidi.sys - ok
15:43:04.0437 3772 [ 8A208DFCF89792A484E76C40E5F50B45 ] C:\WINDOWS\system32\drivers\DMusic.sys
15:43:04.0437 3772 C:\WINDOWS\system32\drivers\DMusic.sys - ok
15:43:04.0437 3772 [ 692BCF44383D056AED41B045A323D378 ] C:\WINDOWS\system32\drivers\kmixer.sys
15:43:04.0437 3772 C:\WINDOWS\system32\drivers\kmixer.sys - ok
15:43:04.0437 3772 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] C:\WINDOWS\system32\drivers\drmkaud.sys
15:43:04.0437 3772 C:\WINDOWS\system32\drivers\drmkaud.sys - ok
15:43:04.0453 3772 [ 9A3BD5F55AADFF859539142F6328A66E ] C:\WINDOWS\system32\msacm32.drv
15:43:04.0453 3772 C:\WINDOWS\system32\msacm32.drv - ok
15:43:04.0453 3772 [ 5C12660A97822F6E61576943B49AAAD6 ] C:\WINDOWS\system32\midimap.dll
15:43:04.0453 3772 C:\WINDOWS\system32\midimap.dll - ok
15:43:04.0453 3772 [ A93AEE1928A9D7CE3E16D24EC7380F89 ] C:\WINDOWS\system32\userinit.exe
15:43:04.0453 3772 C:\WINDOWS\system32\userinit.exe - ok
15:43:04.0468 3772 [ F02A533F517EB38333CB12A9E8963773 ] C:\Program Files\Google\Update\GoogleUpdate.exe
15:43:04.0468 3772 C:\Program Files\Google\Update\GoogleUpdate.exe - ok
15:43:04.0468 3772 [ B1296D52B0D2096EC4759EEEB806D759 ] C:\WINDOWS\system32\WgaTray.exe
15:43:04.0468 3772 C:\WINDOWS\system32\WgaTray.exe - ok
15:43:04.0468 3772 [ 2E5672EEA419A4DC9DACD714632E1DC3 ] C:\Program Files\Google\Update\1.3.21.135\goopdate.dll
15:43:04.0468 3772 C:\Program Files\Google\Update\1.3.21.135\goopdate.dll - ok
15:43:04.0484 3772 [ D3F72D50DE53F9F1F55240115AF4D42E ] C:\WINDOWS\system32\msi.dll
15:43:04.0484 3772 C:\WINDOWS\system32\msi.dll - ok
15:43:04.0484 3772 [ 12896823FB95BFB3DC9B46BCAEDC9923 ] C:\WINDOWS\explorer.exe
15:43:04.0484 3772 C:\WINDOWS\explorer.exe - ok
15:43:04.0500 3772 [ DEFEE5DEDD20C1E15532E88D5A4F7C96 ] C:\WINDOWS\system32\browseui.dll
15:43:04.0500 3772 C:\WINDOWS\system32\browseui.dll - ok
15:43:04.0500 3772 [ 5E283C987ED4BB42323A3C722EEBC081 ] C:\WINDOWS\system32\shdocvw.dll
15:43:04.0500 3772 C:\WINDOWS\system32\shdocvw.dll - ok
15:43:04.0500 3772 [ CC26451A90025F6C55F64146C333DEA5 ] C:\WINDOWS\system32\LegitCheckControl.dll
15:43:04.0500 3772 C:\WINDOWS\system32\LegitCheckControl.dll - ok
15:43:04.0515 3772 [ B6E6F3F5B63053D5DC1F4EE32992492F ] C:\WINDOWS\system32\dbghelp.dll
15:43:04.0515 3772 C:\WINDOWS\system32\dbghelp.dll - ok
15:43:04.0515 3772 [ BECDDA0990DEBD72A30096533521AD73 ] C:\Program Files\Google\Update\1.3.21.135\GoogleCrashHandler.exe
15:43:04.0515 3772 C:\Program Files\Google\Update\1.3.21.135\GoogleCrashHandler.exe - ok
15:43:04.0515 3772 [ 4044E880593FE1AC9942190FCE414BE7 ] C:\WINDOWS\system32\mstask.dll
15:43:04.0515 3772 C:\WINDOWS\system32\mstask.dll - ok
15:43:04.0515 3772 [ 660C8E78B94F483E44B0243A774A4746 ] C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
15:43:04.0515 3772 C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL - ok
15:43:04.0531 3772 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] C:\WINDOWS\system32\drivers\mrxdav.sys
15:43:04.0531 3772 C:\WINDOWS\system32\drivers\mrxdav.sys - ok
15:43:04.0531 3772 [ 58A14C45A5CD2528F10A889E7B0C3FC2 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll
15:43:04.0531 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_92453bb7\atl90.dll - ok
15:43:04.0531 3772 [ E9901A7E569C4156FDA69F5C9356B8ED ] C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE14\Cultures\OFFICE.ODF
15:43:04.0546 3772 C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE14\Cultures\OFFICE.ODF - ok
15:43:04.0546 3772 [ 77A354E28153AD2D5E120A5A8687BC06 ] C:\WINDOWS\system32\webclnt.dll
15:43:04.0546 3772 C:\WINDOWS\system32\webclnt.dll - ok
15:43:04.0546 3772 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] C:\WINDOWS\system32\drivers\parport.sys
15:43:04.0546 3772 C:\WINDOWS\system32\drivers\parport.sys - ok
15:43:04.0546 3772 [ 676CCC08D9E9A3F4CA39CB04E97048DF ] C:\PROGRA~1\MICROS~3\Office14\1033\GrooveIntlResource.dll
15:43:04.0546 3772 C:\PROGRA~1\MICROS~3\Office14\1033\GrooveIntlResource.dll - ok
15:43:04.0562 3772 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] C:\WINDOWS\system32\drivers\serial.sys
15:43:04.0562 3772 C:\WINDOWS\system32\drivers\serial.sys - ok
15:43:04.0562 3772 [ 4FE5C6D40664AE07BE5105874357D2ED ] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
15:43:04.0562 3772 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe - ok
15:43:04.0562 3772 [ 92DA9EDE07390B4352B29DD82079E398 ] C:\Program Files\Common Files\Apple\Apple Application Support\AppleVersions.dll
15:43:04.0562 3772 C:\Program Files\Common Files\Apple\Apple Application Support\AppleVersions.dll - ok
15:43:04.0578 3772 [ 64894527838C86454E2F378FF39FA336 ] C:\Program Files\Common Files\Apple\Apple Application Support\YSCrashDump.dll
15:43:04.0578 3772 C:\Program Files\Common Files\Apple\Apple Application Support\YSCrashDump.dll - ok
15:43:04.0578 3772 [ EF8CD3C64EE9C08980D6D06CCCE46C68 ] C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll
15:43:04.0578 3772 C:\Program Files\Common Files\Apple\Apple Application Support\CoreFoundation.dll - ok
15:43:04.0578 3772 [ 638C7596B493F5F77DB9EF6BAD8FE46C ] C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll
15:43:04.0578 3772 C:\Program Files\Common Files\Apple\Apple Application Support\pthreadVC2.dll - ok
15:43:04.0593 3772 [ 78865ABC5F5D13190F8B35BD9044714A ] C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll
15:43:04.0593 3772 C:\Program Files\Common Files\Apple\Apple Application Support\objc.dll - ok
15:43:04.0593 3772 [ FF9831030678C7B6D70BAC00F68F8976 ] C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll
15:43:04.0593 3772 C:\Program Files\Common Files\Apple\Apple Application Support\libdispatch.dll - ok
15:43:04.0593 3772 [ 5A963C340DE1A01BA6E24945CE05D16A ] C:\Program Files\Common Files\Apple\Apple Application Support\libicuin.dll
15:43:04.0593 3772 C:\Program Files\Common Files\Apple\Apple Application Support\libicuin.dll - ok
15:43:04.0609 3772 [ F4BC62990E7E5C29799A895B80FC3177 ] C:\Program Files\Common Files\Apple\Apple Application Support\libicuuc.dll
15:43:04.0609 3772 C:\Program Files\Common Files\Apple\Apple Application Support\libicuuc.dll - ok
15:43:04.0609 3772 [ 149D74E1128A86DC9CFB2851FBEA11EB ] C:\Program Files\Common Files\Apple\Apple Application Support\icudt46.dll
15:43:04.0609 3772 C:\Program Files\Common Files\Apple\Apple Application Support\icudt46.dll - ok
15:43:04.0625 3772 [ B4ED498E3BFEE64E952BC44FC6057DB8 ] C:\WINDOWS\system32\desk.cpl
15:43:04.0625 3772 C:\WINDOWS\system32\desk.cpl - ok
15:43:04.0625 3772 [ A314EEA2A503A8E04085201E436384A5 ] C:\WINDOWS\system32\themeui.dll
15:43:04.0625 3772 C:\WINDOWS\system32\themeui.dll - ok
15:43:04.0625 3772 [ 912B67BB8249925A5C972FC5839EAE09 ] C:\WINDOWS\system32\actxprxy.dll
15:43:04.0625 3772 C:\WINDOWS\system32\actxprxy.dll - ok
15:43:04.0640 3772 [ F6FD367C9EAAEDF90CD7A7952AE0B336 ] C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll
15:43:04.0640 3772 C:\Program Files\Common Files\Apple\Apple Application Support\ASL.dll - ok
15:43:04.0640 3772 [ 4327CF9A9D0864CA0FFC97FCDA97315A ] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll
15:43:04.0640 3772 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService_main.dll - ok
15:43:04.0640 3772 [ 062373995EAE5F0EAC9EAA9192136BFB ] C:\WINDOWS\system32\dnssd.dll
15:43:04.0640 3772 C:\WINDOWS\system32\dnssd.dll - ok
15:43:04.0656 3772 [ 6D778E0F95447E6546553EEEA709D03C ] C:\WINDOWS\system32\cmd.exe
15:43:04.0656 3772 C:\WINDOWS\system32\cmd.exe - ok
15:43:04.0656 3772 [ 59570CA554C9D75E72241AC3252E84BD ] C:\WINDOWS\system32\ieframe.dll
15:43:04.0656 3772 C:\WINDOWS\system32\ieframe.dll - ok
15:43:04.0656 3772 [ 24665B221424FFD7B71F0D2C398F2F4F ] C:\Program Files\Common Files\Apple\Mobile Device Support\MobileDevice.dll
15:43:04.0656 3772 C:\Program Files\Common Files\Apple\Mobile Device Support\MobileDevice.dll - ok
15:43:04.0671 3772 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] C:\Program Files\Bonjour\mDNSResponder.exe
15:43:04.0671 3772 C:\Program Files\Bonjour\mDNSResponder.exe - ok
15:43:04.0671 3772 [ 574738F61FCA2935F5265DC4E5691314 ] C:\WINDOWS\system32\qmgr.dll
15:43:04.0671 3772 C:\WINDOWS\system32\qmgr.dll - ok
15:43:04.0671 3772 [ 57EDEC2E5F59F0335E92F35184BC8631 ] C:\WINDOWS\system32\dmserver.dll
15:43:04.0671 3772 C:\WINDOWS\system32\dmserver.dll - ok
15:43:04.0687 3772 [ BC93B4A066477954555966D77FEC9ECB ] C:\WINDOWS\system32\ersvc.dll
15:43:04.0687 3772 C:\WINDOWS\system32\ersvc.dll - ok
15:43:04.0687 3772 [ 96633419F4A1E37ACB89B45EBCCFE001 ] C:\WINDOWS\system32\FsUsbExService.Exe
15:43:04.0687 3772 C:\WINDOWS\system32\FsUsbExService.Exe - ok
15:43:04.0687 3772 [ 0B467F470CC9918FDCEEDCFD7DC4D697 ] C:\WINDOWS\system32\oledlg.dll
15:43:04.0687 3772 C:\WINDOWS\system32\oledlg.dll - ok
15:43:04.0703 3772 [ D4991D98F2DB73C60D042F1AEF79EFAE ] C:\WINDOWS\system32\es.dll
15:43:04.0703 3772 C:\WINDOWS\system32\es.dll - ok
15:43:04.0703 3772 [ 2E14406E05789F91C9282AE7CFCA3A07 ] C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
15:43:04.0703 3772 C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll - ok
15:43:04.0703 3772 [ 5652F6CE1D9E9D8068B9D29BC21B5409 ] C:\WINDOWS\system32\olepro32.dll
15:43:04.0703 3772 C:\WINDOWS\system32\olepro32.dll - ok
15:43:04.0718 3772 [ AF54247F97CCF3539DE7505C09972FF9 ] C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll
15:43:04.0718 3772 C:\Program Files\Common Files\Apple\Apple Application Support\CFNetwork.dll - ok
15:43:04.0718 3772 [ 94FCCE83CDEE9C8149667110093E701E ] C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe
15:43:04.0718 3772 C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe - ok
15:43:04.0718 3772 [ C14AA05881A35B6D6BB8D55B117EE22D ] C:\WINDOWS\system32\shfolder.dll
15:43:04.0718 3772 C:\WINDOWS\system32\shfolder.dll - ok
15:43:04.0734 3772 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] C:\WINDOWS\system32\netman.dll
15:43:04.0734 3772 C:\WINDOWS\system32\netman.dll - ok
15:43:04.0734 3772 [ 062F837C1FBDB6A0A75F82EFC2EE8E74 ] C:\WINDOWS\system32\netshell.dll
15:43:04.0734 3772 C:\WINDOWS\system32\netshell.dll - ok
15:43:04.0750 3772 [ 8BA9851E671E8B5E49E303748FFD530C ] C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll
15:43:04.0750 3772 C:\Program Files\Common Files\Apple\Apple Application Support\SQLite3.dll - ok
15:43:04.0750 3772 [ 5E33C164DC7FA74728D8A83036C438BB ] C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
15:43:04.0750 3772 C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll - ok
15:43:04.0750 3772 [ E95911BD88EF967125724428772FDDD8 ] C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE
15:43:04.0750 3772 C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE - ok
15:43:04.0765 3772 [ 235892E493845D64D890163CFEF90E97 ] C:\WINDOWS\system32\credui.dll
15:43:04.0765 3772 C:\WINDOWS\system32\credui.dll - ok
15:43:04.0765 3772 [ 4E8F3230BAC8C1CAADF01A8C728E1C5C ] C:\WINDOWS\system32\dot3dlg.dll
15:43:04.0765 3772 C:\WINDOWS\system32\dot3dlg.dll - ok
15:43:04.0765 3772 [ CA04959077AFE36369D37B3504740C87 ] C:\WINDOWS\system32\onex.dll
15:43:04.0765 3772 C:\WINDOWS\system32\onex.dll - ok
15:43:04.0781 3772 [ 5DB625E7D095604010CF84DE2D8ACFA6 ] C:\WINDOWS\system32\eappcfg.dll
15:43:04.0781 3772 C:\WINDOWS\system32\eappcfg.dll - ok
15:43:04.0781 3772 [ ABC4206543450C0666D152F4B65833B8 ] C:\WINDOWS\system32\eappprxy.dll
15:43:04.0781 3772 C:\WINDOWS\system32\eappprxy.dll - ok
15:43:04.0781 3772 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
15:43:04.0781 3772 C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll - ok
15:43:04.0796 3772 [ DEB04DA35CC871B6D309B77E1443C796 ] C:\WINDOWS\system32\hidserv.dll
15:43:04.0796 3772 C:\WINDOWS\system32\hidserv.dll - ok
15:43:04.0796 3772 [ 8973122796E3B5D6B5900FC186E55FEA ] C:\WINDOWS\system32\hid.dll
15:43:04.0796 3772 C:\WINDOWS\system32\hid.dll - ok
15:43:04.0796 3772 [ DF446BA625CC441617843E87798CE048 ] C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll
15:43:04.0796 3772 C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll - ok
15:43:04.0796 3772 [ B591E761161D1EF547D76EF236EAA6A5 ] C:\Program Files\Java\jre7\bin\jqs.exe
15:43:04.0812 3772 C:\Program Files\Java\jre7\bin\jqs.exe - ok
15:43:04.0812 3772 [ C83C0791FC7FA3CBE9BE2825B8A47EAF ] C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll
15:43:04.0812 3772 C:\Program Files\HP\Digital Imaging\bin\hpqddcmn.dll - ok
15:43:04.0812 3772 [ 67EC459E42D3081DD8FD34356F7CAFC1 ] C:\Program Files\Java\jre7\bin\msvcr100.dll
15:43:04.0812 3772 C:\Program Files\Java\jre7\bin\msvcr100.dll - ok
15:43:04.0812 3772 [ 79E3A8C328E7E569C32B0998377D9742 ] C:\WINDOWS\system32\spoolss.dll
15:43:04.0812 3772 C:\WINDOWS\system32\spoolss.dll - ok
15:43:04.0828 3772 [ 62CF83A6989312A0DD39BBFFB3D1C166 ] C:\WINDOWS\system32\pdh.dll
15:43:04.0828 3772 C:\WINDOWS\system32\pdh.dll - ok
15:43:04.0828 3772 [ 5677DFE438EC1F009273FC84FEED6B10 ] C:\WINDOWS\system32\localspl.dll
15:43:04.0828 3772 C:\WINDOWS\system32\localspl.dll - ok
15:43:04.0828 3772 [ 369F7B1A4F358B976176556A1A331F36 ] C:\WINDOWS\system32\odbcbcp.dll
15:43:04.0828 3772 C:\WINDOWS\system32\odbcbcp.dll - ok
15:43:04.0843 3772 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] C:\WINDOWS\system32\srvsvc.dll
15:43:04.0843 3772 C:\WINDOWS\system32\srvsvc.dll - ok
15:43:04.0843 3772 [ 51C6D8BFBD4EA5B62A1BA7F4469250D3 ] C:\WINDOWS\system32\HPZinw12.dll
15:43:04.0843 3772 C:\WINDOWS\system32\HPZinw12.dll - ok
15:43:04.0843 3772 [ 5D3D1AB0EF4EA55B731863050482C111 ] C:\WINDOWS\system32\cnbjmon.dll
15:43:04.0843 3772 C:\WINDOWS\system32\cnbjmon.dll - ok
15:43:04.0859 3772 [ CE9B98EE57685CF61ABAEF078BA0C704 ] C:\WINDOWS\system32\hpzll5mu.dll
15:43:04.0859 3772 C:\WINDOWS\system32\hpzll5mu.dll - ok
15:43:04.0859 3772 [ 20FD44370267CCD0A64A1B31861C21D2 ] C:\WINDOWS\system32\netmsg.dll
15:43:04.0859 3772 C:\WINDOWS\system32\netmsg.dll - ok
15:43:04.0875 3772 [ 79834AA2FBF9FE81EEBB229024F6F7FC ] C:\WINDOWS\system32\HPZipm12.dll
15:43:04.0875 3772 C:\WINDOWS\system32\HPZipm12.dll - ok
15:43:04.0875 3772 [ 332760FBA1655FCFD35BD6F4FD871300 ] C:\WINDOWS\system32\ipsecsvc.dll
15:43:04.0875 3772 C:\WINDOWS\system32\ipsecsvc.dll - ok
15:43:04.0875 3772 [ ACDAFCD14EC0ECE89198503746A5C147 ] C:\WINDOWS\system32\perfos.dll
15:43:04.0875 3772 C:\WINDOWS\system32\perfos.dll - ok
15:43:04.0890 3772 [ ABFB673B24A9B3287761D497529FB5B9 ] C:\WINDOWS\system32\perfdisk.dll
15:43:04.0890 3772 C:\WINDOWS\system32\perfdisk.dll - ok
15:43:04.0890 3772 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] C:\WINDOWS\system32\drivers\srv.sys
15:43:04.0890 3772 C:\WINDOWS\system32\drivers\srv.sys - ok
15:43:04.0890 3772 [ C5FF8682EADA5B3B27A865F1C3EF9270 ] C:\WINDOWS\system32\oakley.dll
15:43:04.0890 3772 C:\WINDOWS\system32\oakley.dll - ok
15:43:04.0906 3772 [ 720FEA3AAA15FE7E0BEAB10AC2E6D2B0 ] C:\Program Files\Edimax\Common\RaRegistry.exe
15:43:04.0906 3772 C:\Program Files\Edimax\Common\RaRegistry.exe - ok
15:43:04.0906 3772 [ F1F4E6EAFE2CD5CD079B73233FB71CE8 ] C:\WINDOWS\system32\pdfcmon.dll
15:43:04.0906 3772 C:\WINDOWS\system32\pdfcmon.dll - ok
15:43:04.0906 3772 [ 222DE7F5EDB9DDBE628384A1A8BE59CE ] C:\WINDOWS\system32\pjlmon.dll
15:43:04.0906 3772 C:\WINDOWS\system32\pjlmon.dll - ok
15:43:04.0921 3772 [ AE0382AD9C73D343D85E1A50C80B7C20 ] C:\WINDOWS\system32\tcpmon.dll
15:43:04.0921 3772 C:\WINDOWS\system32\tcpmon.dll - ok
15:43:04.0921 3772 [ 248712EA6BA17B9FF0C542A3828375DD ] C:\WINDOWS\system32\winipsec.dll
15:43:04.0921 3772 C:\WINDOWS\system32\winipsec.dll - ok
15:43:04.0921 3772 [ 853D0D0C6F02D7BFDF1CF99DD7553732 ] C:\WINDOWS\system32\pstorsvc.dll
15:43:04.0921 3772 C:\WINDOWS\system32\pstorsvc.dll - ok
15:43:04.0937 3772 [ F26385E8BA4549B5186B774EC0E45D86 ] C:\WINDOWS\system32\usbmon.dll
15:43:04.0937 3772 C:\WINDOWS\system32\usbmon.dll - ok
15:43:04.0937 3772 [ D4EEBF6E9559689034BB628B437BE7E4 ] C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
15:43:04.0937 3772 C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll - ok
15:43:04.0937 3772 [ EEE7F12D9FF46F68FBC0DA059A359E9E ] C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
15:43:04.0937 3772 C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll - ok
15:43:04.0937 3772 [ 22DD6D7D4BFE2B8CE705CC950C8AEA4C ] C:\WINDOWS\system32\win32spl.dll
15:43:04.0937 3772 C:\WINDOWS\system32\win32spl.dll - ok
15:43:04.0953 3772 [ B41D53899E37CC43DA85DA19998BEE81 ] C:\WINDOWS\system32\netrap.dll
15:43:04.0953 3772 C:\WINDOWS\system32\netrap.dll - ok
15:43:04.0953 3772 [ EE4C651A217B01D636B5364AC77DA892 ] C:\WINDOWS\system32\inetpp.dll
15:43:04.0953 3772 C:\WINDOWS\system32\inetpp.dll - ok
15:43:04.0953 3772 [ 22D89D84E8E081CDA529DBF8C0255A38 ] C:\WINDOWS\system32\psbase.dll
15:43:04.0953 3772 C:\WINDOWS\system32\psbase.dll - ok
15:43:04.0968 3772 [ 5B19B557B0C188210A56A6B699D90B8F ] C:\WINDOWS\system32\regsvc.dll
15:43:04.0968 3772 C:\WINDOWS\system32\regsvc.dll - ok
15:43:04.0968 3772 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] C:\WINDOWS\system32\sens.dll
15:43:04.0968 3772 C:\WINDOWS\system32\sens.dll - ok
15:43:04.0968 3772 [ 83F41D0D89645D7235C051AB1D9523AC ] C:\WINDOWS\system32\ipnathlp.dll
15:43:04.0968 3772 C:\WINDOWS\system32\ipnathlp.dll - ok
15:43:04.0984 3772 [ FEDE68BF80052BAD393AFD5C2E60DCB0 ] C:\WINDOWS\system32\dssenh.dll
15:43:04.0984 3772 C:\WINDOWS\system32\dssenh.dll - ok
15:43:04.0984 3772 [ 3805DF0AC4296A34BA4BF93B346CC378 ] C:\WINDOWS\system32\srsvc.dll
15:43:04.0984 3772 C:\WINDOWS\system32\srsvc.dll - ok
15:43:05.0000 3772 [ CBE612E2BB6A10E3563336191EDA1250 ] C:\WINDOWS\system32\seclogon.dll
15:43:05.0000 3772 C:\WINDOWS\system32\seclogon.dll - ok
15:43:05.0000 3772 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] C:\WINDOWS\system32\wiaservc.dll
15:43:05.0000 3772 C:\WINDOWS\system32\wiaservc.dll - ok
15:43:05.0000 3772 [ 5F0CE62E0831CF972EC6949FD3E37DA7 ] C:\WINDOWS\system32\cfgmgr32.dll
15:43:05.0000 3772 C:\WINDOWS\system32\cfgmgr32.dll - ok
15:43:05.0015 3772 [ 4AC2FA4A6F0DF2511BAC13393C06EFF1 ] C:\WINDOWS\system32\mscms.dll
15:43:05.0015 3772 C:\WINDOWS\system32\mscms.dll - ok
15:43:05.0015 3772 [ A21E58F345F337316A98C5121CBE17E8 ] C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
15:43:05.0015 3772 C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe - ok
15:43:05.0015 3772 [ 93686F0550566CD85F93A6A4CC029476 ] C:\WINDOWS\system32\hpowiax7.dll
15:43:05.0015 3772 C:\WINDOWS\system32\hpowiax7.dll - ok
15:43:05.0031 3772 [ 55BCA12F7F523D35CA3CB833C725F54E ] C:\WINDOWS\system32\trkwks.dll
15:43:05.0031 3772 C:\WINDOWS\system32\trkwks.dll - ok
15:43:05.0031 3772 [ 2D0E4ED081963804CCC196A0929275B5 ] C:\WINDOWS\system32\wbem\wmisvc.dll
15:43:05.0031 3772 C:\WINDOWS\system32\wbem\wmisvc.dll - ok
15:43:05.0031 3772 [ BE0B3774113713059527FCF071CCDBFE ] C:\Program Files\Webroot\Washer\WasherSvc.exe
15:43:05.0031 3772 C:\Program Files\Webroot\Washer\WasherSvc.exe - ok
15:43:05.0031 3772 [ ACACB8B14E66109B8ACD6644B5574B9A ] C:\WINDOWS\system32\vssapi.dll
15:43:05.0031 3772 C:\WINDOWS\system32\vssapi.dll - ok
15:43:05.0046 3772 [ FC3EC24FCE372C89423E015A2AC1A31E ] C:\WINDOWS\system32\wuaueng.dll
15:43:05.0046 3772 C:\WINDOWS\system32\wuaueng.dll - ok
15:43:05.0046 3772 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] C:\WINDOWS\system32\wuauserv.dll
15:43:05.0046 3772 C:\WINDOWS\system32\wuauserv.dll - ok
15:43:05.0046 3772 [ B85E95679B5ADC12311BCD3F5385D623 ] C:\WINDOWS\system32\mspatcha.dll
15:43:05.0046 3772 C:\WINDOWS\system32\mspatcha.dll - ok
15:43:05.0062 3772 [ CFD4E51402DA9838B5A04AE680AF54A0 ] C:\WINDOWS\system32\browser.dll
15:43:05.0062 3772 C:\WINDOWS\system32\browser.dll - ok
15:43:05.0062 3772 [ F0BF811622F2DD6C8E26EE4600D83731 ] C:\WINDOWS\system32\wbem\wbemcore.dll
15:43:05.0062 3772 C:\WINDOWS\system32\wbem\wbemcore.dll - ok
15:43:05.0062 3772 [ E4616430709F440CF1809D88DC2366EA ] C:\WINDOWS\system32\wbem\esscli.dll
15:43:05.0062 3772 C:\WINDOWS\system32\wbem\esscli.dll - ok
15:43:05.0078 3772 [ 378A0AEFB11D8B0DC8C27B9F7604B88D ] C:\WINDOWS\system32\wbem\fastprox.dll
15:43:05.0078 3772 C:\WINDOWS\system32\wbem\fastprox.dll - ok
15:43:05.0078 3772 [ 7C278E6408D1DCE642230C0585A854D5 ] C:\WINDOWS\system32\wscsvc.dll
15:43:05.0078 3772 C:\WINDOWS\system32\wscsvc.dll - ok
15:43:05.0078 3772 [ 010472D0AE758227C6F6E6933549C219 ] C:\WINDOWS\system32\wbem\wbemsvc.dll
15:43:05.0078 3772 C:\WINDOWS\system32\wbem\wbemsvc.dll - ok
15:43:05.0093 3772 [ ED0C0DF222209E43AD9AFBF3FE87DDE0 ] C:\WINDOWS\system32\comsvcs.dll
15:43:05.0093 3772 C:\WINDOWS\system32\comsvcs.dll - ok
15:43:05.0093 3772 [ 690D97864735E8ECD87F55777E266690 ] C:\WINDOWS\system32\colbact.dll
15:43:05.0093 3772 C:\WINDOWS\system32\colbact.dll - ok
15:43:05.0093 3772 [ 36795A645EAA47FE31D2A8F136A2C69B ] C:\WINDOWS\system32\mtxclu.dll
15:43:05.0093 3772 C:\WINDOWS\system32\mtxclu.dll - ok
15:43:05.0109 3772 [ DF82E222578DBE59FCBBD69A02E4C806 ] C:\WINDOWS\system32\clusapi.dll
15:43:05.0109 3772 C:\WINDOWS\system32\clusapi.dll - ok
15:43:05.0109 3772 [ F51EBB6FC536A6B2D588FD668D3A8249 ] C:\WINDOWS\system32\resutils.dll
15:43:05.0109 3772 C:\WINDOWS\system32\resutils.dll - ok
15:43:05.0125 3772 [ 3273D1565BF30225C115B480A3BB2C9D ] C:\WINDOWS\system32\wbem\wmiutils.dll
15:43:05.0125 3772 C:\WINDOWS\system32\wbem\wmiutils.dll - ok
15:43:05.0125 3772 [ 942A17D2901A31EA68627CBFFCD268CC ] C:\WINDOWS\system32\wbem\repdrvfs.dll
15:43:05.0125 3772 C:\WINDOWS\system32\wbem\repdrvfs.dll - ok
15:43:05.0125 3772 [ 3458EDA96E30FBD0477A2800D3FB1909 ] C:\WINDOWS\system32\wups.dll
15:43:05.0125 3772 C:\WINDOWS\system32\wups.dll - ok
15:43:05.0140 3772 [ BDC0C99E472176C8C2C853A68ADC5073 ] C:\WINDOWS\system32\wups2.dll
15:43:05.0140 3772 C:\WINDOWS\system32\wups2.dll - ok
15:43:05.0140 3772 [ 2E0B0A051FFAA86E358465BB0880D453 ] C:\WINDOWS\system32\wuauclt.exe
15:43:05.0140 3772 C:\WINDOWS\system32\wuauclt.exe - ok
15:43:05.0140 3772 [ 071143F687B4F887E21461CA6CC7EB29 ] C:\WINDOWS\system32\wbem\wmiprvsd.dll
15:43:05.0140 3772 C:\WINDOWS\system32\wbem\wmiprvsd.dll - ok
15:43:05.0156 3772 [ 26D881D27CBE51D3614E68D7313EA026 ] C:\WINDOWS\system32\wbem\wbemess.dll
15:43:05.0156 3772 C:\WINDOWS\system32\wbem\wbemess.dll - ok
15:43:05.0156 3772 [ 1A617835452EEE5060976C9B9F5FE635 ] C:\WINDOWS\system32\wuapi.dll
15:43:05.0156 3772 C:\WINDOWS\system32\wuapi.dll - ok
15:43:05.0156 3772 [ D26451B540720A7313A9BCBE794DAF62 ] C:\WINDOWS\system32\wbem\ncprov.dll
15:43:05.0156 3772 C:\WINDOWS\system32\wbem\ncprov.dll - ok
15:43:05.0171 3772 [ A21C2A8E47D40FCC40A2B1573E666A53 ] C:\Program Files\Java\jre7\bin\awt.dll
15:43:05.0171 3772 C:\Program Files\Java\jre7\bin\awt.dll - ok
15:43:05.0171 3772 [ 966CD21542A62F9AB237D84C451CC137 ] C:\Program Files\Java\jre7\bin\client\jvm.dll
15:43:05.0171 3772 C:\Program Files\Java\jre7\bin\client\jvm.dll - ok
15:43:05.0171 3772 [ 90760987BCCCF34D05EF6093EC278A96 ] C:\Program Files\Java\jre7\bin\dcpr.dll
15:43:05.0171 3772 C:\Program Files\Java\jre7\bin\dcpr.dll - ok
15:43:05.0187 3772 [ D2D31D7A394A70040FCAC5F54A130FBA ] C:\Program Files\Java\jre7\bin\deploy.dll
15:43:05.0187 3772 C:\Program Files\Java\jre7\bin\deploy.dll - ok
15:43:05.0187 3772 [ C09775FEB73BDF16BB87A509C5FF12AD ] C:\Program Files\Java\jre7\bin\fontmanager.dll
15:43:05.0187 3772 C:\Program Files\Java\jre7\bin\fontmanager.dll - ok
15:43:05.0187 3772 [ B98F28229D292B99FF449FF3647F31BA ] C:\Program Files\Java\jre7\bin\java.dll
15:43:05.0187 3772 C:\Program Files\Java\jre7\bin\java.dll - ok
15:43:05.0203 3772 [ 23C84DBECF3BD95687623F23BCD66441 ] C:\Program Files\Java\jre7\bin\javaw.exe
15:43:05.0203 3772 C:\Program Files\Java\jre7\bin\javaw.exe - ok
15:43:05.0203 3772 [ 0384126B913AC2E090804C642302945E ] C:\Program Files\Java\jre7\bin\jp2native.dll
15:43:05.0203 3772 C:\Program Files\Java\jre7\bin\jp2native.dll - ok
15:43:05.0203 3772 [ CB91CCFA95601066772A004550B55A85 ] C:\Program Files\Java\jre7\bin\jpeg.dll
15:43:05.0203 3772 C:\Program Files\Java\jre7\bin\jpeg.dll - ok
15:43:05.0203 3772 [ 2E4A927544CDA0279501AA757FFFB538 ] C:\Program Files\Java\jre7\bin\net.dll
15:43:05.0203 3772 C:\Program Files\Java\jre7\bin\net.dll - ok
15:43:05.0218 3772 [ 805766A11E747A44C7C5FBD7F26E9001 ] C:\Program Files\Java\jre7\bin\nio.dll
15:43:05.0218 3772 C:\Program Files\Java\jre7\bin\nio.dll - ok
15:43:05.0218 3772 [ 2D168A9627CFCE9C5AC20A90E54D66D4 ] C:\Program Files\Java\jre7\bin\verify.dll
15:43:05.0218 3772 C:\Program Files\Java\jre7\bin\verify.dll - ok
15:43:05.0218 3772 [ 9D54D4A8C18081F398FEC0D839340542 ] C:\Program Files\Java\jre7\bin\zip.dll
15:43:05.0218 3772 C:\Program Files\Java\jre7\bin\zip.dll - ok
15:43:05.0234 3772 [ 178A34E5554DCE485E1262DDF027960C ] C:\DOCUME~1\CHRISC~1.MAI\LOCALS~1\temp\BA1F5266-0711-46EC-AF5E-FF1D5CAB9D30.exe
15:43:05.0234 3772 C:\DOCUME~1\CHRISC~1.MAI\LOCALS~1\temp\BA1F5266-0711-46EC-AF5E-FF1D5CAB9D30.exe - ok
15:43:05.0234 3772 [ A70A2D85AD143D6BB823C246CEB699A5 ] C:\WINDOWS\system32\ntshrui.dll
15:43:05.0234 3772 C:\WINDOWS\system32\ntshrui.dll - ok
15:43:05.0250 3772 [ 91790D6749EBED90E2C40479C0A91879 ] C:\WINDOWS\system32\verclsid.exe
15:43:05.0250 3772 C:\WINDOWS\system32\verclsid.exe - ok
15:43:05.0250 3772 [ 2DC5A8019E2387987905F77C664E4BE2 ] C:\WINDOWS\system32\linkinfo.dll
15:43:05.0250 3772 C:\WINDOWS\system32\linkinfo.dll - ok
15:43:05.0250 3772 [ 2DE1190196EE9555DB548A57622022EB ] C:\WINDOWS\system32\drprov.dll
15:43:05.0250 3772 C:\WINDOWS\system32\drprov.dll - ok
15:43:05.0265 3772 [ 36468087E22C57A83DF758B3F90DF73F ] C:\WINDOWS\system32\ntlanman.dll
15:43:05.0265 3772 C:\WINDOWS\system32\ntlanman.dll - ok
15:43:05.0265 3772 [ AC5DF42FE314C1446B1DAD237BFCFFE0 ] C:\WINDOWS\system32\netui0.dll
15:43:05.0265 3772 C:\WINDOWS\system32\netui0.dll - ok
15:43:05.0265 3772 [ ED5A816D8E11E03F1937AC3C56826EE4 ] C:\WINDOWS\system32\netui1.dll
15:43:05.0265 3772 C:\WINDOWS\system32\netui1.dll - ok
15:43:05.0281 3772 [ FB8F8EEC8D9C2157789472DD61CDC78B ] C:\WINDOWS\system32\davclnt.dll
15:43:05.0281 3772 C:\WINDOWS\system32\davclnt.dll - ok
15:43:05.0281 3772 [ CC8915DB4E33E8FB29CA0D2DBF75306E ] C:\WINDOWS\system32\webcheck.dll
15:43:05.0281 3772 C:\WINDOWS\system32\webcheck.dll - ok
15:43:05.0281 3772 [ 2A8681AEA24003040CA7D677BE9F1702 ] C:\WINDOWS\system32\drivers\01075761.sys
15:43:05.0281 3772 C:\WINDOWS\system32\drivers\01075761.sys - ok
15:43:05.0296 3772 [ 50512FC9B7878E3C2C147BC17326A7DB ] C:\WINDOWS\system32\stobject.dll
15:43:05.0296 3772 C:\WINDOWS\system32\stobject.dll - ok
15:43:05.0296 3772 [ 231A0B0E3BA7ABFE469A8262FAA1FD71 ] C:\WINDOWS\system32\batmeter.dll
15:43:05.0296 3772 C:\WINDOWS\system32\batmeter.dll - ok
15:43:05.0296 3772 [ 045E228F71C31901084B64BE59093499 ] C:\WINDOWS\system32\WPDShServiceObj.dll
15:43:05.0296 3772 C:\WINDOWS\system32\WPDShServiceObj.dll - ok
15:43:05.0296 3772 [ 01848B246695D84FD5592C40136A0014 ] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
15:43:05.0296 3772 C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe - ok
15:43:05.0312 3772 [ 538A270F35A713C360B7ED4168BB7521 ] C:\WINDOWS\system32\mydocs.dll
15:43:05.0312 3772 C:\WINDOWS\system32\mydocs.dll - ok
15:43:05.0312 3772 [ 310FEC9E7EBBCBA72E50EE633A47DC4D ] C:\Program Files\CheckPoint\ZoneAlarm\zpeng25.dll
15:43:05.0312 3772 C:\Program Files\CheckPoint\ZoneAlarm\zpeng25.dll - ok
15:43:05.0312 3772 [ 062F3DB9AFA9C3CE0DA52F28595C0C6D ] C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
15:43:05.0312 3772 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe - ok
15:43:05.0328 3772 [ 46DA8E7484AC7A52CE1D6E428398724B ] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
15:43:05.0328 3772 C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe - ok
15:43:05.0328 3772 [ 22358578CB321F3325496A3723029409 ] C:\WINDOWS\system32\PortableDeviceTypes.dll
15:43:05.0328 3772 C:\WINDOWS\system32\PortableDeviceTypes.dll - ok
15:43:05.0328 3772 [ 9D45B2201D0ECF9F42136C7B99DEB8B2 ] C:\WINDOWS\system32\PortableDeviceApi.dll
15:43:05.0328 3772 C:\WINDOWS\system32\PortableDeviceApi.dll - ok
15:43:05.0343 3772 [ 9B9F8D422F06B241F71CBE77C64BDC97 ] C:\Program Files\Citrix\ICA Client\concentr.exe
15:43:05.0343 3772 C:\Program Files\Citrix\ICA Client\concentr.exe - ok
15:43:05.0343 3772 [ 9DE762386E27E268CBA42830D527BE73 ] C:\Program Files\Citrix\ICA Client\ctxmui.dll
15:43:05.0343 3772 C:\Program Files\Citrix\ICA Client\ctxmui.dll - ok
15:43:05.0343 3772 [ CFA5D9A6905C821C032772A910A341B0 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ConfigWizard.zip.dll
15:43:05.0343 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\ConfigWizard.zip.dll - ok
15:43:05.0359 3772 [ 0600CB2613BEA0C6C0987B58D56D77B9 ] C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
15:43:05.0359 3772 C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe - ok
15:43:05.0359 3772 [ 6CB0F58B3A78AB669099DF4E46CC7072 ] C:\Program Files\Citrix\ICA Client\CCMSDK.dll
15:43:05.0359 3772 C:\Program Files\Citrix\ICA Client\CCMSDK.dll - ok
15:43:05.0375 3772 [ 498259BB20BF84E5C744485F68EBCC4C ] C:\Program Files\CheckPoint\ZoneAlarm\lib\DashBoard.zip.dll
15:43:05.0375 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\DashBoard.zip.dll - ok
15:43:05.0375 3772 [ E11831E14CC4E1DDA220E377A2D7EF84 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\LicenseUI.zip.dll
15:43:05.0375 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\LicenseUI.zip.dll - ok
15:43:05.0375 3772 [ 5C4F6C55B7CB111D686F597EAAE74B28 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\MainLoop.zip.dll
15:43:05.0375 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\MainLoop.zip.dll - ok
15:43:05.0390 3772 [ 3CB07566302BCEEB898DE270A0BEC175 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
15:43:05.0390 3772 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe - ok
15:43:05.0390 3772 [ CAC6E79015AF82A3B5422FC988E3F08E ] C:\Program Files\CheckPoint\ZoneAlarm\lib\NavBar.zip.dll
15:43:05.0390 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\NavBar.zip.dll - ok
15:43:05.0390 3772 [ F4F7EE79D2BD88B6DEC9C117883F30B9 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\Overview.zip.dll
15:43:05.0390 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\Overview.zip.dll - ok
15:43:05.0406 3772 [ 813559706D756D82A56B779DC2749122 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\TrayTest.zip.dll
15:43:05.0406 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\TrayTest.zip.dll - ok
15:43:05.0406 3772 [ 5656D65A9A9F1E3D68D64A350CFF1732 ] C:\WINDOWS\system32\igfxtray.exe
15:43:05.0406 3772 C:\WINDOWS\system32\igfxtray.exe - ok
15:43:05.0406 3772 [ BFB52A1AA31FA93DA9926A58AF45EF82 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\UpdateUI.zip.dll
15:43:05.0406 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\UpdateUI.zip.dll - ok
15:43:05.0421 3772 [ ABBECE951B2AA6ED4E242E1CDF1BD0FE ] C:\Program Files\Citrix\ICA Client\resource\en\ctxmuiUI.dll
15:43:05.0421 3772 C:\Program Files\Citrix\ICA Client\resource\en\ctxmuiUI.dll - ok
15:43:05.0421 3772 [ 12BC9635B32DBEBB6C92DC7FB90FEDB2 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ZAlert.zip.dll
15:43:05.0421 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\ZAlert.zip.dll - ok
15:43:05.0421 3772 [ 218FA5991E1B47C8315CEB6A29CFE081 ] C:\Program Files\Citrix\ICA Client\resource\en\concenUI.dll
15:43:05.0421 3772 C:\Program Files\Citrix\ICA Client\resource\en\concenUI.dll - ok
15:43:05.0437 3772 [ 035029D2B692A5C73BECF7331F9C65B5 ] C:\WINDOWS\system32\hccutils.dll
15:43:05.0437 3772 C:\WINDOWS\system32\hccutils.dll - ok
15:43:05.0437 3772 [ D3C5CCD59F260C020D9F8D90CE7BF4FC ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ZClient.zip.dll
15:43:05.0437 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\ZClient.zip.dll - ok
15:43:05.0437 3772 [ 3F533D75631178A880AEFFDF117213BE ] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon_main.dll
15:43:05.0437 3772 C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon_main.dll - ok
15:43:05.0453 3772 [ 82ADC58B63E069AC4641A33EA9841E54 ] C:\WINDOWS\system32\hkcmd.exe
15:43:05.0453 3772 C:\WINDOWS\system32\hkcmd.exe - ok
15:43:05.0453 3772 [ D75F2D43C62DB1387656C1FC674DEE83 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zfde.zip.dll
15:43:05.0453 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\zfde.zip.dll - ok
15:43:05.0453 3772 [ D49C001BE285F727F24C75472705D5E7 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zmenu.zip.dll
15:43:05.0453 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\zmenu.zip.dll - ok
15:43:05.0453 3772 [ A0E2FFB7B0FCE82AA3BCC3105306C45C ] C:\WINDOWS\system32\igfxpers.exe
15:43:05.0453 3772 C:\WINDOWS\system32\igfxpers.exe - ok
15:43:05.0468 3772 [ 88A085071ED623D3792858D4D600E347 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zpy.zip.dll
15:43:05.0468 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\zpy.zip.dll - ok
15:43:05.0468 3772 [ 941A08CBDEEDF16B6C986B6BA7C9A5D0 ] C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
15:43:05.0468 3772 C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe - ok
15:43:05.0468 3772 [ 2888E77950D6E98A1B1D1BBD05FA4887 ] C:\WINDOWS\system32\igfxsrvc.exe
15:43:05.0468 3772 C:\WINDOWS\system32\igfxsrvc.exe - ok
15:43:05.0484 3772 [ C4E457DB4542C0707293EF03B2A6A9BA ] C:\Program Files\Citrix\ICA Client\wfcrun32.exe
15:43:05.0484 3772 C:\Program Files\Citrix\ICA Client\wfcrun32.exe - ok
15:43:05.0484 3772 [ 4928AB3A304DDF05C354DE3807A4A66B ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll
15:43:05.0484 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80.dll - ok
15:43:05.0500 3772 [ 12916E0642E92561C98B18A2A2D01B14 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
15:43:05.0500 3772 C:\Program Files\Common Files\Java\Java Update\jusched.exe - ok
15:43:05.0500 3772 [ 425DA3E03D3B3FA308D30A2A682B6499 ] C:\Program Files\Citrix\ICA Client\ProgressNotificationCommon.dll
15:43:05.0500 3772 C:\Program Files\Citrix\ICA Client\ProgressNotificationCommon.dll - ok
15:43:05.0500 3772 [ 8E2A7F1F62467A7DCB8AB2C0642F47CA ] C:\Program Files\iTunes\iTunesHelper.exe
15:43:05.0500 3772 C:\Program Files\iTunes\iTunesHelper.exe - ok
15:43:05.0515 3772 [ F2012DA44521414574C3191E2FABF24D ] C:\Program Files\Citrix\ICA Client\wfcwinn.dll
15:43:05.0515 3772 C:\Program Files\Citrix\ICA Client\wfcwinn.dll - ok
15:43:05.0515 3772 [ FA45A2EBB9419CED0A4BF9C9E9BF4498 ] C:\Program Files\Citrix\ICA Client\acrdlg.dll
15:43:05.0515 3772 C:\Program Files\Citrix\ICA Client\acrdlg.dll - ok
15:43:05.0515 3772 [ 7EF9AA6D19A6962383EFF5E570BE0CC1 ] C:\Program Files\Citrix\ICA Client\statuin.dll
15:43:05.0515 3772 C:\Program Files\Citrix\ICA Client\statuin.dll - ok
15:43:05.0531 3772 [ 4D2F7561D8A840450AABFAD3740B0E6B ] C:\Program Files\Microsoft Security Client\msseces.exe
15:43:05.0531 3772 C:\Program Files\Microsoft Security Client\msseces.exe - ok
15:43:05.0531 3772 [ 5082BC510FAD849630D09DA626BB7CDA ] C:\Program Files\iTunes\iTunesHelper.dll
15:43:05.0531 3772 C:\Program Files\iTunes\iTunesHelper.dll - ok
15:43:05.0531 3772 [ 348CBCBAF2179567FF0098B756F02E57 ] C:\Program Files\Citrix\ICA Client\confmgr.dll
15:43:05.0531 3772 C:\Program Files\Citrix\ICA Client\confmgr.dll - ok
15:43:05.0546 3772 [ A0A085DCB1DE464E3BCE8A1835967E6A ] C:\Program Files\Citrix\ICA Client\ctxlogging.dll
15:43:05.0546 3772 C:\Program Files\Citrix\ICA Client\ctxlogging.dll - ok
15:43:05.0546 3772 [ F27E6F727D8DB8A92D73513FC42201AA ] C:\Program Files\Citrix\ICA Client\icafile.dll
15:43:05.0546 3772 C:\Program Files\Citrix\ICA Client\icafile.dll - ok
15:43:05.0546 3772 [ 3CAEAE7608F1BD7BA873A3B02895B106 ] C:\WINDOWS\system32\sti.dll
15:43:05.0546 3772 C:\WINDOWS\system32\sti.dll - ok
15:43:05.0546 3772 [ 5B5FEA463340EE5DCE98F1A44E368E5A ] C:\Program Files\Webroot\Washer\wwDisp.exe
15:43:05.0546 3772 C:\Program Files\Webroot\Washer\wwDisp.exe - ok
15:43:05.0562 3772 [ 90098BD6DCBCCD8428F0A6668A28C42F ] C:\Program Files\Citrix\ICA Client\cst.dll
15:43:05.0562 3772 C:\Program Files\Citrix\ICA Client\cst.dll - ok
15:43:05.0562 3772 [ C35BD7743F5F928D503A5C0C1F877140 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zsys.zip.dll
15:43:05.0562 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\zsys.zip.dll - ok
15:43:05.0562 3772 [ D8584C7FB9A1BA8480F9000C1CA1B415 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll
15:43:05.0562 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_0ccc058c\mfc80ENU.dll - ok
15:43:05.0578 3772 [ F7AD9D0D7BE3C97FA0A802678B3AFF5F ] C:\Program Files\CheckPoint\ZoneAlarm\lib\ztv.zip.dll
15:43:05.0578 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\ztv.zip.dll - ok
15:43:05.0578 3772 [ DBB3918350E09D38E164BE6851600D22 ] C:\Program Files\Citrix\ICA Client\resource\en\ProgressNotificationCommonUI.dll
15:43:05.0578 3772 C:\Program Files\Citrix\ICA Client\resource\en\ProgressNotificationCommonUI.dll - ok
15:43:05.0578 3772 [ BE643CD44DD06DA283634A3E51DC22BC ] C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.dll
15:43:05.0578 3772 C:\Program Files\iTunes\iTunesHelper.Resources\en.lproj\iTunesHelperLocalized.dll - ok
15:43:05.0593 3772 [ AFEEAFD7CF8ED6958A81ACC304C17B7D ] C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.dll
15:43:05.0593 3772 C:\Program Files\iTunes\iTunesHelper.Resources\iTunesHelper.dll - ok
15:43:05.0593 3772 [ F7FD34F43260D587F393305A97A9C2C4 ] C:\Program Files\Citrix\ICA Client\resource\en\statuiUI.dll
15:43:05.0593 3772 C:\Program Files\Citrix\ICA Client\resource\en\statuiUI.dll - ok
15:43:05.0593 3772 [ 965F92D5D32B3584EAE533D9F37DDDCF ] C:\WINDOWS\system32\igfxsrvc.dll
15:43:05.0593 3772 C:\WINDOWS\system32\igfxsrvc.dll - ok
15:43:05.0609 3772 [ 18C288F56F1D670682D64807914413BF ] C:\WINDOWS\system32\igfxdev.dll
15:43:05.0609 3772 C:\WINDOWS\system32\igfxdev.dll - ok
15:43:05.0609 3772 [ 0C1C620EE9A45032A720B9C8D20B0B8E ] C:\PROGRA~1\GFI\GFIBAC~1\GFIAgent.exe
15:43:05.0609 3772 C:\PROGRA~1\GFI\GFIBAC~1\GFIAgent.exe - ok
15:43:05.0625 3772 [ 5F687D7F798FD20C6B11B13F0B006037 ] C:\Program Files\Citrix\ICA Client\resource\en\cstUI.dll
15:43:05.0625 3772 C:\Program Files\Citrix\ICA Client\resource\en\cstUI.dll - ok
15:43:05.0625 3772 [ D331352334CF6F529DBFA73C391F85A9 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\zui.zip.dll
15:43:05.0625 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\zui.zip.dll - ok
15:43:05.0625 3772 [ 6B3CDFD6A7903561B5ACAF5535927204 ] C:\WINDOWS\system32\igfxres.dll
15:43:05.0625 3772 C:\WINDOWS\system32\igfxres.dll - ok
15:43:05.0640 3772 [ 1E377D64DACD4E4656C86241CE5A1233 ] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
15:43:05.0640 3772 C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe - ok
15:43:05.0640 3772 [ 22D71D1DB6FC789A1CE8AC6963580259 ] C:\WINDOWS\system32\hhctrl.ocx
15:43:05.0640 3772 C:\WINDOWS\system32\hhctrl.ocx - ok
15:43:05.0640 3772 [ 80AE01677E4B5D296A9C4E09FE66AA22 ] C:\Program Files\Citrix\ICA Client\resource\en\wfcrunUI.dll
15:43:05.0640 3772 C:\Program Files\Citrix\ICA Client\resource\en\wfcrunUI.dll - ok
15:43:05.0656 3772 [ 686B224B4987C22B153FBB545FEE9657 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll
15:43:05.0656 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_b77cec8e\mfc80u.dll - ok
15:43:05.0656 3772 [ 448B572F9505CE50A21BBD9312AEAAB4 ] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
15:43:05.0656 3772 C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe - ok
15:43:05.0656 3772 [ C03E8D9F44FC4E57BEDB41240FF96855 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpui.pyd
15:43:05.0656 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpui.pyd - ok
15:43:05.0671 3772 [ 5F1D5F88303D4A4DBC8E5F97BA967CC3 ] C:\WINDOWS\system32\ctfmon.exe
15:43:05.0671 3772 C:\WINDOWS\system32\ctfmon.exe - ok
15:43:05.0671 3772 [ 118D81523EA80B9E252CB840E94754C6 ] C:\Program Files\Microsoft Security Client\EppManifest.dll
15:43:05.0671 3772 C:\Program Files\Microsoft Security Client\EppManifest.dll - ok
15:43:05.0671 3772 [ 40C53C82AEEE5E20EF655BFCAA78735C ] C:\Program Files\Citrix\ICA Client\CCMProxy.dll
15:43:05.0671 3772 C:\Program Files\Citrix\ICA Client\CCMProxy.dll - ok
15:43:05.0687 3772 [ E40FCF943127DDC8FD60554B722D762B ] C:\WINDOWS\system32\MSCTF.dll
15:43:05.0687 3772 C:\WINDOWS\system32\MSCTF.dll - ok
15:43:05.0687 3772 [ 855F6333E3A4DFC6F3C8B0520C261FCD ] C:\WINDOWS\system32\msftedit.dll
15:43:05.0687 3772 C:\WINDOWS\system32\msftedit.dll - ok
15:43:05.0687 3772 [ 17AA58A54C00F1746B8654C050491F43 ] C:\WINDOWS\system32\msutb.dll
15:43:05.0687 3772 C:\WINDOWS\system32\msutb.dll - ok
15:43:05.0703 3772 [ EF8E5E4FD6C023B1E6F26E947EDD1DD4 ] C:\Program Files\CheckPoint\ZoneAlarm\zhtml.dll
15:43:05.0703 3772 C:\Program Files\CheckPoint\ZoneAlarm\zhtml.dll - ok
15:43:05.0703 3772 [ F6FAEC07446A78A9C5AF4558FF5BD118 ] C:\WINDOWS\ime\SPTIP.dll
15:43:05.0703 3772 C:\WINDOWS\ime\SPTIP.dll - ok
15:43:05.0703 3772 [ 562750567E899AC3C8D25A4B704F75AD ] C:\Program Files\Webroot\Washer\Languages\English.dll
15:43:05.0703 3772 C:\Program Files\Webroot\Washer\Languages\English.dll - ok
15:43:05.0718 3772 [ 37CF3324F46CEB3A4F2686C617CBB35C ] C:\Program Files\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll
15:43:05.0718 3772 C:\Program Files\Common Files\Apple\Mobile Device Support\iTunesMobileDevice.dll - ok
15:43:05.0718 3772 [ B12C853961947ED89B9437966C7507B4 ] C:\Program Files\Samsung\Samsung New PC Studio\rapi.dll
15:43:05.0718 3772 C:\Program Files\Samsung\Samsung New PC Studio\rapi.dll - ok
15:43:05.0718 3772 [ 88BEEF09C654252F3E46B6167B7F4ECB ] C:\WINDOWS\system32\msisip.dll
15:43:05.0718 3772 C:\WINDOWS\system32\msisip.dll - ok
15:43:05.0734 3772 [ 43CCB246B3D0C385E54F14B04DF96E9F ] C:\Program Files\Samsung\Samsung New PC Studio\ceutil.dll
15:43:05.0734 3772 C:\Program Files\Samsung\Samsung New PC Studio\ceutil.dll - ok
15:43:05.0734 3772 [ 3A6D465F379E5C815F4AD565391E654C ] C:\WINDOWS\system32\wshext.dll
15:43:05.0734 3772 C:\WINDOWS\system32\wshext.dll - ok
15:43:05.0750 3772 [ D4931277DF5393E84A48B27DF40914E3 ] C:\WINDOWS\system32\riched32.dll
15:43:05.0750 3772 C:\WINDOWS\system32\riched32.dll - ok
15:43:05.0750 3772 [ F36BC7FB3A87DE9138AAECC40F7BC116 ] C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
15:43:05.0750 3772 C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll - ok
15:43:05.0750 3772 [ D9335549EAE48B14FB66EFCB6FFAE736 ] C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
15:43:05.0750 3772 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe - ok
15:43:05.0765 3772 [ D475BBD6FEF8DB2DDE0DA7CCFD2C9042 ] C:\Program Files\Microsoft Security Client\SqmApi.dll
15:43:05.0765 3772 C:\Program Files\Microsoft Security Client\SqmApi.dll - ok
15:43:05.0765 3772 [ 69EE0CB3B05F619EFF7E46F978BBFEEA ] C:\WINDOWS\system32\asycfilt.dll
15:43:05.0765 3772 C:\WINDOWS\system32\asycfilt.dll - ok
15:43:05.0765 3772 [ 9E03DC5AB51CFD0190541CE2038D819D ] C:\WINDOWS\system32\usp10.dll
15:43:05.0765 3772 C:\WINDOWS\system32\usp10.dll - ok
15:43:05.0781 3772 [ AFDF60D3DC76BB725E2DDEB19BC16179 ] C:\Program Files\Edimax\Common\RaUI.exe
15:43:05.0781 3772 C:\Program Files\Edimax\Common\RaUI.exe - ok
15:43:05.0781 3772 [ 944FAEDBC4136707B76FB3086C9B1080 ] C:\Program Files\Webroot\Washer\WashIdx.exe
15:43:05.0781 3772 C:\Program Files\Webroot\Washer\WashIdx.exe - ok
15:43:05.0781 3772 [ 1FAE4969D8C1188F25509AE37F2732A4 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_ctypes.pyd
15:43:05.0781 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_ctypes.pyd - ok
15:43:05.0796 3772 [ 3EE222B084E86A34690012274A963FDF ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpdx.pyd
15:43:05.0796 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zpdx.pyd - ok
15:43:05.0796 3772 [ 085AFA1FEBBD1C26CFD035122A8D36E9 ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\pyexpat.pyd
15:43:05.0796 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\pyexpat.pyd - ok
15:43:05.0796 3772 [ DE628C450E3AEA8C25619B8B5BD4504F ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_socket.pyd
15:43:05.0796 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\_socket.pyd - ok
15:43:05.0812 3772 [ 95EAFC02EA102B5AA683823B60FEF053 ] C:\Program Files\Edimax\Common\RaWLAPI.dll
15:43:05.0812 3772 C:\Program Files\Edimax\Common\RaWLAPI.dll - ok
15:43:05.0812 3772 [ 88A17CDE56BB9539C5D456F3D7CD1A0D ] C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zptv.pyd
15:43:05.0812 3772 C:\Program Files\CheckPoint\ZoneAlarm\lib\pyd\zptv.pyd - ok
15:43:05.0812 3772 [ 0AED8EAE3B351917FCA60AB741582A1E ] C:\Program Files\CheckPoint\ZoneAlarm\vspubapi.dll
15:43:05.0812 3772 C:\Program Files\CheckPoint\ZoneAlarm\vspubapi.dll - ok
15:43:05.0828 3772 [ DFD6589D0312D67B53A3468B88D06FC8 ] C:\WINDOWS\system32\Scutum.dll
15:43:05.0828 3772 C:\WINDOWS\system32\Scutum.dll - ok
15:43:05.0828 3772 [ 87FDE73EE2FD2AFFF64AD86EEAB4A8FA ] C:\WINDOWS\system32\DiagFunc.dll
15:43:05.0828 3772 C:\WINDOWS\system32\DiagFunc.dll - ok
15:43:05.0828 3772 [ A749AFABDDEDE3FD170D93A172C08AD9 ] C:\WINDOWS\system32\W32N55.dll
15:43:05.0828 3772 C:\WINDOWS\system32\W32N55.dll - ok
15:43:05.0828 3772 [ CDF9BD825AAE8B33F56A7FA6B42BFEB2 ] C:\WINDOWS\system32\libeay32.dll
15:43:05.0828 3772 C:\WINDOWS\system32\libeay32.dll - ok
15:43:05.0843 3772 [ 9C7D0E8D0A39DA0BFB26BB5FB76C03ED ] C:\WINDOWS\system32\ssleay32.dll
15:43:05.0843 3772 C:\WINDOWS\system32\ssleay32.dll - ok
15:43:05.0843 3772 [ 798A9E6828997EEF4517ADA8A2259831 ] C:\WINDOWS\system32\wbem\wmiprvse.exe
15:43:05.0843 3772 C:\WINDOWS\system32\wbem\wmiprvse.exe - ok
15:43:05.0843 3772 [ 8A7A42B60DD07FC30A451A60DD37EBAA ] C:\Program Files\CheckPoint\ZoneAlarm\vsmonapi.dll
15:43:05.0843 3772 C:\Program Files\CheckPoint\ZoneAlarm\vsmonapi.dll - ok
15:43:05.0859 3772 [ 960F6D3CD9A1BA6435D7AADD102B297F ] C:\WINDOWS\system32\wbem\wmiprov.dll
15:43:05.0859 3772 C:\WINDOWS\system32\wbem\wmiprov.dll - ok
15:43:05.0859 3772 [ E837FDBB92E9873E538395B623F45462 ] C:\WINDOWS\system32\wbem\cimwin32.dll
15:43:05.0859 3772 C:\WINDOWS\system32\wbem\cimwin32.dll - ok
15:43:05.0875 3772 [ 4306FA2F1099D7C606139255FDB62B19 ] C:\WINDOWS\system32\wbem\framedyn.dll
15:43:05.0875 3772 C:\WINDOWS\system32\wbem\framedyn.dll - ok
15:43:05.0875 3772 [ 8BCD11D38FCE43A519246A91CC40DE6A ] C:\WINDOWS\system32\security.dll
15:43:05.0875 3772 C:\WINDOWS\system32\security.dll - ok
15:43:05.0875 3772 [ C730F70351D950DDA7388C9A9763CF54 ] C:\WINDOWS\system32\wbem\wmipcima.dll
15:43:05.0875 3772 C:\WINDOWS\system32\wbem\wmipcima.dll - ok
15:43:05.0890 3772 [ 6404807ABC7AF52FA3792697AE638B50 ] C:\WINDOWS\system32\wbem\wbemcons.dll
15:43:05.0890 3772 C:\WINDOWS\system32\wbem\wbemcons.dll - ok
15:43:05.0890 3772 [ 3CB78C17BB664637787C9A1C98F79C38 ] C:\WINDOWS\system32\tapisrv.dll
15:43:05.0890 3772 C:\WINDOWS\system32\tapisrv.dll - ok
15:43:05.0890 3772 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] C:\WINDOWS\system32\rasmans.dll
15:43:05.0890 3772 C:\WINDOWS\system32\rasmans.dll - ok
15:43:05.0906 3772 [ FF3477C03BE7201C294C35F684B3479F ] C:\WINDOWS\system32\termsrv.dll
15:43:05.0906 3772 C:\WINDOWS\system32\termsrv.dll - ok
15:43:05.0906 3772 [ 37A62C6092AADD2EFDE0468DD8818E99 ] C:\WINDOWS\system32\netcfgx.dll
15:43:05.0906 3772 C:\WINDOWS\system32\netcfgx.dll - ok
15:43:05.0906 3772 [ DF6551E4C4C46655A0C76194F1FCEA5D ] C:\WINDOWS\system32\icaapi.dll
15:43:05.0906 3772 C:\WINDOWS\system32\icaapi.dll - ok
15:43:05.0921 3772 [ 2D65D56C2F8B6CC5EBFF8E7200C30304 ] C:\WINDOWS\system32\mstlsapi.dll
15:43:05.0921 3772 C:\WINDOWS\system32\mstlsapi.dll - ok
15:43:05.0921 3772 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] C:\WINDOWS\system32\imapi.exe
15:43:05.0921 3772 C:\WINDOWS\system32\imapi.exe - ok
15:43:05.0921 3772 [ 93C088C2AEB2F23E720BDA7E32BD5117 ] C:\WINDOWS\system32\upnp.dll
15:43:05.0921 3772 C:\WINDOWS\system32\upnp.dll - ok
15:43:05.0937 3772 [ F50F7984FDD151EDD8A70A8DBD9E2A44 ] C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll
15:43:05.0937 3772 C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll - ok
15:43:05.0937 3772 [ 6895427873D6C37A6D6DA7C3DB37DA14 ] C:\WINDOWS\system32\licwmi.dll
15:43:05.0937 3772 C:\WINDOWS\system32\licwmi.dll - ok
15:43:05.0937 3772 [ 3D075865DCC26931972F6476AD0497BE ] C:\WINDOWS\system32\ssdpapi.dll
15:43:05.0937 3772 C:\WINDOWS\system32\ssdpapi.dll - ok
15:43:05.0953 3772 [ CBE5F69A5E5B918225F420BA748F3742 ] C:\WINDOWS\system32\FsUsbExDisk.Sys
15:43:05.0953 3772 C:\WINDOWS\system32\FsUsbExDisk.Sys - ok
15:43:05.0953 3772 [ 5F7692CEC90E2E9AA32CD58321E234B8 ] C:\WINDOWS\system32\rastapi.dll
15:43:05.0953 3772 C:\WINDOWS\system32\rastapi.dll - ok
15:43:05.0953 3772 [ E46B17060D3962A384AE484094614788 ] C:\Program Files\iPod\bin\iPodService.exe
15:43:05.0953 3772 C:\Program Files\iPod\bin\iPodService.exe - ok
15:43:05.0953 3772 [ A693A49A67673F2C8D76797EA9A628D0 ] C:\WINDOWS\system32\licdll.dll
15:43:05.0953 3772 C:\WINDOWS\system32\licdll.dll - ok
15:43:05.0968 3772 [ AACE07FE34FADDDF973CE068A6424957 ] C:\WINDOWS\system32\unimdm.tsp
15:43:05.0968 3772 C:\WINDOWS\system32\unimdm.tsp - ok
15:43:05.0968 3772 [ 715AB41A22E0DE693CB101639070D3BE ] C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll
15:43:05.0968 3772 C:\Program Files\HP\Digital Imaging\bin\hpquio08.dll - ok
15:43:05.0968 3772 [ 995252FCC4692B5B97EE17D596C9386E ] C:\WINDOWS\system32\uniplat.dll
15:43:05.0968 3772 C:\WINDOWS\system32\uniplat.dll - ok
15:43:05.0984 3772 [ F80A415EF82CD06FFAF0D971528EAD38 ] C:\WINDOWS\system32\drivers\http.sys
15:43:05.0984 3772 C:\WINDOWS\system32\drivers\http.sys - ok
15:43:05.0984 3772 [ 691BAF41144EBDE972A66C5EB5210FC8 ] C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.dll
15:43:05.0984 3772 C:\Program Files\iPod\bin\iPodService.Resources\en.lproj\iPodServiceLocalized.dll - ok
15:43:06.0000 3772 [ 665FBA44C65BAC9EE8AF9A5E37036640 ] C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll
15:43:06.0000 3772 C:\Program Files\iPod\bin\iPodService.Resources\iPodService.dll - ok
15:43:06.0000 3772 [ 5A4B93F78473F397C332A0BF6B8F093F ] C:\WINDOWS\system32\wbem\mofd.dll
15:43:06.0000 3772 C:\WINDOWS\system32\wbem\mofd.dll - ok
15:43:06.0000 3772 [ 0A5679B3714EDAB99E357057EE88FCA6 ] C:\WINDOWS\system32\ssdpsrv.dll
15:43:06.0000 3772 C:\WINDOWS\system32\ssdpsrv.dll - ok
15:43:06.0015 3772 [ F89E2E5B554CCEB5FCD344349C78FDED ] C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc
15:43:06.0015 3772 C:\Program Files\HP\Digital Imaging\bin\hpqtra08.rsc - ok
15:43:06.0015 3772 [ 76EC97C5068D3D9FAA7774B0F659D31A ] C:\WINDOWS\system32\kmddsp.tsp
15:43:06.0015 3772 C:\WINDOWS\system32\kmddsp.tsp - ok
15:43:06.0015 3772 [ 8C515081584A38AA007909CD02020B3D ] C:\WINDOWS\system32\alg.exe
15:43:06.0015 3772 C:\WINDOWS\system32\alg.exe - ok
15:43:06.0031 3772 [ 4589963D84F2984FA5949A72162BA4F4 ] C:\WINDOWS\system32\ndptsp.tsp
15:43:06.0031 3772 C:\WINDOWS\system32\ndptsp.tsp - ok
15:43:06.0031 3772 [ 8B8A45DF7CEF36D93C7BD3E4C84003B8 ] C:\WINDOWS\system32\ipconf.tsp
15:43:06.0031 3772 C:\WINDOWS\system32\ipconf.tsp - ok
15:43:06.0031 3772 [ 8BC2B02DC11C98D14CEE43B8E8393FF3 ] C:\WINDOWS\system32\h323.tsp
15:43:06.0031 3772 C:\WINDOWS\system32\h323.tsp - ok
15:43:06.0046 3772 [ 6B552ED3BEE5AA3C4560478FF779BA98 ] C:\WINDOWS\system32\hidphone.tsp
15:43:06.0046 3772 C:\WINDOWS\system32\hidphone.tsp - ok
15:43:06.0046 3772 [ 9EFBB3055B3EECE5B0FC7BAED07A6EE9 ] C:\WINDOWS\system32\msxml6.dll
15:43:06.0046 3772 C:\WINDOWS\system32\msxml6.dll - ok
15:43:06.0046 3772 [ DAB8C1971354B1A55D271066674ED734 ] C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll
15:43:06.0046 3772 C:\Program Files\HP\Digital Imaging\bin\hpqtao08.dll - ok
15:43:06.0046 3772 [ D0545A010ED2259A740C8414899A938F ] C:\WINDOWS\system32\rasppp.dll
15:43:06.0046 3772 C:\WINDOWS\system32\rasppp.dll - ok
15:43:06.0062 3772 [ B464BD425D5D09ABE4192234D1577B22 ] C:\WINDOWS\system32\ntlsapi.dll
15:43:06.0062 3772 C:\WINDOWS\system32\ntlsapi.dll - ok
15:43:06.0062 3772 [ A655C88AA555BB8EF8957BD29408827F ] C:\WINDOWS\system32\rasqec.dll
15:43:06.0062 3772 C:\WINDOWS\system32\rasqec.dll - ok
15:43:06.0062 3772 [ 401A8C0BE0BAA7D7A470F0942244152D ] C:\WINDOWS\system32\rasdlg.dll
15:43:06.0062 3772 C:\WINDOWS\system32\rasdlg.dll - ok
15:43:06.0078 3772 [ 822FDAFB41056462F2DDA8A7BCC2B9EB ] C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll
15:43:06.0078 3772 C:\Program Files\HP\Digital Imaging\bin\hpqrif08.dll - ok
15:43:06.0078 3772 [ 4122925C28E461811C033276E25589E9 ] C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll
15:43:06.0078 3772 C:\Program Files\HP\Digital Imaging\bin\hpqmif08.dll - ok
15:43:06.0078 3772 [ 187924625A55EDC7B196B82777C5074A ] C:\Program Files\HP\Digital Imaging\bin\HpqCPTA.dll
15:43:06.0078 3772 C:\Program Files\HP\Digital Imaging\bin\HpqCPTA.dll - ok
15:43:06.0093 3772 [ A5699775554DE8897924A0F6EB5729C9 ] C:\Program Files\HP\Digital Imaging\bin\HpqSRTA.dll
15:43:06.0093 3772 C:\Program Files\HP\Digital Imaging\bin\HpqSRTA.dll - ok
15:43:06.0093 3772 [ FFAD5F0A4ED6C79BDAB71A3084FAA621 ] C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll
15:43:06.0093 3772 C:\Program Files\HP\Digital Imaging\bin\hpotra08.dll - ok
15:43:06.0093 3772 [ 0F5B791DB1A18423C926F1791E2A43CB ] C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc
15:43:06.0093 3772 C:\Program Files\HP\Digital Imaging\bin\hpotra08.rsc - ok
15:43:06.0109 3772 [ 017BD724C977CEF95A01203AECA571D3 ] C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll
15:43:06.0109 3772 C:\Program Files\HP\Digital Imaging\bin\hpotradd.dll - ok
15:43:06.0109 3772 [ EEC6910D6DA48E66390964735BC97B05 ] C:\Program Files\HP\Digital Imaging\bin\hpqxml2.dll
15:43:06.0109 3772 C:\Program Files\HP\Digital Imaging\bin\hpqxml2.dll - ok
15:43:06.0125 3772 [ 81E7E920312D372CF57A817049AC7C76 ] C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
15:43:06.0125 3772 C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL - ok
15:43:06.0125 3772 [ EBD98CF6E4D04D300E57F9EC15D3BEAD ] C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll
15:43:06.0125 3772 C:\Program Files\HP\Digital Imaging\bin\hpocxi08.dll - ok
15:43:06.0125 3772 [ F54FFF428BC887F08EB83674FBB321DA ] C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll
15:43:06.0125 3772 C:\Program Files\HP\Digital Imaging\bin\hpqcob08.dll - ok
15:43:06.0140 3772 [ 4967AA8BD06D51AF10E629287C7A264D ] C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll
15:43:06.0140 3772 C:\Program Files\HP\Digital Imaging\bin\hpodio08.dll - ok
15:43:06.0140 3772 [ B70278D1459A677639D51892160FD365 ] C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
15:43:06.0140 3772 C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe - ok
15:43:06.0140 3772 [ AF880166DAC5880219F748ED83902CB2 ] C:\WINDOWS\system32\HPZipr12.dll
15:43:06.0140 3772 C:\WINDOWS\system32\HPZipr12.dll - ok
15:43:06.0156 3772 [ 26AE2CA34FA4342749EC1157CB1FE954 ] C:\WINDOWS\system32\HPZidr12.dll
15:43:06.0156 3772 C:\WINDOWS\system32\HPZidr12.dll - ok
15:43:06.0156 3772 [ 3E9A33113D663D8BD5ED38858E669652 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
15:43:06.0156 3772 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll - ok
15:43:06.0156 3772 [ 02EBB12CC3FC2ED47AE832A7E91CAD49 ] C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
15:43:06.0156 3772 C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe - ok
15:43:06.0171 3772 [ 7E04B1ADE140F483A6581461568D8D9C ] C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
15:43:06.0171 3772 C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe - ok
15:43:06.0171 3772 [ 998DA918F47769D570C9D3E42D441289 ] C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbutil.dll
15:43:06.0171 3772 C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbutil.dll - ok
15:43:06.0171 3772 [ 6104F2921F31E1422C72B97F05BD9C5F ] C:\Program Files\HP\Digital Imaging\bin\hpqwso08.dll
15:43:06.0171 3772 C:\Program Files\HP\Digital Imaging\bin\hpqwso08.dll - ok
15:43:06.0187 3772 [ 8F32BBB0083BE50B17CE150174EDDC4B ] C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll
15:43:06.0187 3772 C:\Program Files\HP\Digital Imaging\bin\hpqcxm08.dll - ok
15:43:06.0187 3772 [ 8F48362B61A6637D1B064278E549EF40 ] C:\Program Files\HP\Digital Imaging\bin\hpqddusr.dll
15:43:06.0187 3772 C:\Program Files\HP\Digital Imaging\bin\hpqddusr.dll - ok
15:43:06.0187 3772 [ EFB8937A7BF6DCEDD0A10A79D2E756E2 ] C:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll
15:43:06.0187 3772 C:\Program Files\HP\Digital Imaging\bin\hpqsti08.dll - ok
15:43:06.0203 3772 [ 2CC556F7106F0568787A0E28DA3A4DF7 ] C:\Program Files\HP\Digital Imaging\bin\hpqgpb01.dll
15:43:06.0203 3772 C:\Program Files\HP\Digital Imaging\bin\hpqgpb01.dll - ok
15:43:06.0203 3772 [ 8FC85C14B6316745670816F98693A100 ] C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
15:43:06.0203 3772 C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe - ok
15:43:06.0203 3772 [ 0689622E6484934EB6E5F4D3A96311F9 ] C:\WINDOWS\system32\jscript.dll
15:43:06.0203 3772 C:\WINDOWS\system32\jscript.dll - ok
15:43:06.0203 3772 [ 258977EFC45FD728E929A8EB95554050 ] C:\Program Files\HP\Digital Imaging\bin\hpqstp08.dll
15:43:06.0203 3772 C:\Program Files\HP\Digital Imaging\bin\hpqstp08.dll - ok
15:43:06.0218 3772 [ B3C25BE824AFF69567496BA8640218AA ] C:\Program Files\HP\Digital Imaging\bin\hpqstp08.rsc
15:43:06.0218 3772 C:\Program Files\HP\Digital Imaging\bin\hpqstp08.rsc - ok
15:43:06.0218 3772 [ 332889D2C21A5B728FBBD45D6C89661A ] C:\Program Files\HP\Digital Imaging\bin\hpqssm08.dll
15:43:06.0218 3772 C:\Program Files\HP\Digital Imaging\bin\hpqssm08.dll - ok
15:43:06.0218 3772 [ AC974EEF7F6599964BCC4033D8D60D82 ] C:\Program Files\HP\Digital Imaging\bin\hpqtap08.dll
15:43:06.0218 3772 C:\Program Files\HP\Digital Imaging\bin\hpqtap08.dll - ok
15:43:06.0234 3772 [ 759A94A551D8DCC47343E302B50FD8E6 ] C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc
15:43:06.0234 3772 C:\Program Files\HP\Digital Imaging\bin\hpqsem08.rsc - ok
15:43:06.0234 3772 [ 2AB5F9E7D0780364F8BFEA5CF3180240 ] C:\Program Files\HP\Digital Imaging\bin\hpqusg.dll
15:43:06.0234 3772 C:\Program Files\HP\Digital Imaging\bin\hpqusg.dll - ok
15:43:06.0250 3772 [ E88C8F90588E9F738A04FBF386FD987D ] C:\Program Files\HP\Digital Imaging\bin\HpqSplh08.dll
15:43:06.0250 3772 C:\Program Files\HP\Digital Imaging\bin\HpqSplh08.dll - ok
15:43:06.0250 3772 [ B2367E452786DE4EB15C3CF0498F31AA ] C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbevst.dll
15:43:06.0250 3772 C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprbevst.dll - ok
15:43:06.0250 3772 [ 80A84F2BFFEE284484D0D5A276596CD2 ] C:\Program Files\HP\Digital Imaging\Product Assistant\bin\c4dll.dll
15:43:06.0250 3772 C:\Program Files\HP\Digital Imaging\Product Assistant\bin\c4dll.dll - ok
15:43:06.0265 3772 [ 4F1151C408FF8265CECD7D4ED17D3B44 ] C:\Program Files\HP\Digital Imaging\bin\hpqgpreh.dll
15:43:06.0265 3772 C:\Program Files\HP\Digital Imaging\bin\hpqgpreh.dll - ok
15:43:06.0265 3772 ============================================================
15:43:06.0265 3772 Scan finished
15:43:06.0265 3772 ============================================================
15:43:06.0265 2124 Detected object count: 7
15:43:06.0265 2124 Actual detected object count: 7
15:43:26.0656 2124 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - skipped by user
15:43:26.0656 2124 FsUsbExDisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:43:26.0671 2124 hpqcxs08 ( UnsignedFile.Multi.Generic ) - skipped by user
15:43:26.0671 2124 hpqcxs08 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:43:26.0671 2124 hpqddsvc ( UnsignedFile.Multi.Generic ) - skipped by user
15:43:26.0671 2124 hpqddsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:43:26.0671 2124 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
15:43:26.0671 2124 Net Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:43:26.0671 2124 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - skipped by user
15:43:26.0671 2124 Pml Driver HPZ12 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:43:26.0671 2124 RT80x86 ( UnsignedFile.Multi.Generic ) - skipped by user
15:43:26.0671 2124 RT80x86 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:43:26.0671 2124 Scutum50 ( UnsignedFile.Multi.Generic ) - skipped by user
15:43:26.0671 2124 Scutum50 ( UnsignedFile.Multi.Generic ) - User select action: Skip
15:44:01.0703 2600 Deinitialize success

15:36:27.0159 3712 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
15:36:27.0441 3712 ============================================================
15:36:27.0441 3712 Current date / time: 2013/04/07 15:36:27.0441
15:36:27.0441 3712 SystemInfo:
15:36:27.0441 3712
15:36:27.0441 3712 OS Version: 5.1.2600 ServicePack: 3.0
15:36:27.0441 3712 Product type: Workstation
15:36:27.0441 3712 ComputerName: MAINCOMP-364806
15:36:27.0441 3712 UserName: Chris Clair
15:36:27.0441 3712 Windows directory: C:\WINDOWS
15:36:27.0441 3712 System windows directory: C:\WINDOWS
15:36:27.0441 3712 Processor architecture: Intel x86
15:36:27.0441 3712 Number of processors: 2
15:36:27.0441 3712 Page size: 0x1000
15:36:27.0441 3712 Boot type: Normal boot
15:36:27.0441 3712 ============================================================
15:36:29.0675 3712 Drive \Device\Harddisk0\DR0 - Size: 0x12A05F2000 (74.51 Gb), SectorSize: 0x200, Cylinders: 0x25FE, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
15:36:29.0675 3712 ============================================================
15:36:29.0675 3712 \Device\Harddisk0\DR0:
15:36:29.0675 3712 MBR partitions:
15:36:29.0675 3712 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x139C5, BlocksNum 0x69682E0
15:36:29.0675 3712 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x697BCA5, BlocksNum 0x2536D3D
15:36:29.0675 3712 ============================================================
15:36:29.0722 3712 C: <-> \Device\Harddisk0\DR0\Partition1
15:36:29.0753 3712 E: <-> \Device\Harddisk0\DR0\Partition2
15:36:29.0753 3712 ============================================================
15:36:29.0753 3712 Initialize success
15:36:29.0753 3712 ============================================================
15:36:46.0113 3812 Deinitialize success


Malwarebytes Anti-Rootkit BETA 1.01.0.1022
www.malwarebytes.org

Database version: v2013.04.07.04

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Chris Clair :: MAINCOMP-364806 [administrator]

07/04/2013 16:08:32
mbar-log-2013-04-07 (16-08-32).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
Scan options disabled:
Objects scanned: 29497
Time elapsed: 16 minute(s), 41 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
  • 0

#8
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello chrisg6152

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Please start by opening Notepad and copy/paste the text in the box into the window:

ClearJavaCache::



Save it to your desktop as CFScript.txt

Referring to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

  • 0

#9
chrisg6152

chrisg6152

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
Hi Gringo

I have run the Combofix script - once again it would only complete in Safe Mode!

I have pasted the log at the end of this reply.

The PC appears to be running OK - I didn't have the C\Windows\system32\cmd.exe dialog box problem (staying on screen until I closed it)on startup. AV and Firewall started up OK.

Log as requested

ComboFix 13-04-08.02 - Chris Clair 08/04/2013 16:53:07.5.2 - x86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.2038.1747 [GMT 1:00]
Running from: c:\documents and settings\Chris Clair.MAINCOMP-364806\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Chris Clair.MAINCOMP-364806\Desktop\CFScript.txt
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
FW: ZoneAlarm Free Firewall Firewall *Disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
.
.
((((((((((((((((((((((((( Files Created from 2013-03-08 to 2013-04-08 )))))))))))))))))))))))))))))))
.
.
2013-04-08 13:41 . 2013-03-19 04:50 7108640 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{E1935A64-594A-4195-B18E-7190928810F6}\mpengine.dll
2013-04-07 10:04 . 2013-03-19 04:50 7108640 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2013-04-07 09:56 . 2013-04-07 09:56 4734 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2013-04-05 08:19 . 2013-04-05 08:19 -------- d-----w- c:\windows\system32\wbem\Repository
2013-04-04 17:00 . 2013-04-05 08:19 -------- d-----w- c:\program files\Microsoft Security Client
2013-03-23 14:15 . 2013-03-23 14:15 -------- d-sh--w- c:\documents and settings\Administrator.MAINCOMP-364806\PrivacIE
2013-03-23 11:57 . 2013-03-23 11:57 -------- d-----w- c:\documents and settings\Administrator.MAINCOMP-364806\Application Data\Malwarebytes
2013-03-19 13:48 . 2013-03-19 13:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-03-16 16:25 . 2013-02-12 00:32 12928 -c----w- c:\windows\system32\dllcache\usb8023x.sys
2013-03-13 19:36 . 2013-03-13 19:36 -------- d-----w- c:\program files\MSECache
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-04-04 08:07 . 2012-11-29 19:17 73432 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-04-04 08:07 . 2012-11-29 19:17 693976 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-03-12 00:10 . 2012-01-13 18:17 237088 ------w- c:\windows\system32\MpSigStub.exe
2013-02-12 00:32 . 2008-04-14 12:00 12928 ----a-w- c:\windows\system32\drivers\usb8023.sys
2013-02-05 20:05 . 2008-04-14 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
2013-02-05 20:05 . 2008-04-14 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2013-02-05 20:05 . 2008-04-14 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2013-02-05 05:53 . 2008-04-14 12:00 385024 ----a-w- c:\windows\system32\html.iec
2013-01-26 03:55 . 2008-04-14 12:00 552448 ----a-w- c:\windows\system32\oleaut32.dll
2013-01-20 14:59 . 2013-01-20 14:59 195296 ----a-w- c:\windows\system32\drivers\MpFilter.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Window Washer"="c:\program files\Webroot\Washer\wwDisp.exe" [2007-11-26 1206600]
"GFI Backup 2009 - Home Edition"="c:\progra~1\GFI\GFIBAC~1\GFIAgent.exe" [2010-07-30 2195824]
"AutoStartNPSAgent"="c:\program files\Samsung\Samsung New PC Studio\NPSAgent.exe" [2010-07-04 95576]
"TomTomHOME.exe"="c:\program files\TomTom HOME 2\TomTomHOMERunner.exe" [2013-02-12 248208]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2013-01-02 73984]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-01-28 59720]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-05-12 300472]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-07-31 38872]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-12-03 946352]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-07-03 252848]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2013-02-20 152392]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2013-01-27 947152]
"ISW"="" [BU]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2010-12-21 519584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
.
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
Wireless Utility.lnk - c:\program files\Edimax\Common\RaUI.exe [2012-2-9 1638400]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
.
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [05/10/2009 11:08 65584]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [15/01/2012 19:04 238952]
S2 GFIBckHAtt;GFI Backup 2009 - Home Edition Attendant Service;c:\progra~1\GFI\GFIBAC~1\GFIHInst.exe [24/03/2011 14:11 858480]
S2 GFIBckHSched;GFI Backup 2009 - Home Edition Scheduler Service;c:\progra~1\GFI\GFIBAC~1\GFIHSC~1.EXE [24/03/2011 14:11 2324848]
S2 ISWKL;ZoneAlarm LTD Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [14/10/2009 14:30 27056]
S2 IswSvc;ZoneAlarm LTD Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [14/10/2009 14:30 497320]
S2 Scutum50;Scutum50 NDIS Protocol Driver;c:\windows\system32\drivers\Scutum50.sys [09/02/2012 19:04 19072]
S2 TomTomHOMEService;TomTomHOMEService;c:\program files\TomTom HOME 2\TomTomHOMEService.exe [12/02/2013 11:43 93072]
S2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [15/01/2012 16:17 598856]
S3 dgderdrv;dgderdrv;c:\windows\system32\drivers\dgderdrv.sys --> c:\windows\system32\drivers\dgderdrv.sys [?]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.Sys [15/01/2012 19:04 36608]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [09/02/2012 19:04 1197312]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-04-08 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-29 08:07]
.
2013-04-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 17:57]
.
2013-04-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-04 18:22]
.
2013-04-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-04-04 18:22]
.
2013-04-08 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2013-01-27 10:11]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.talktalk.co.uk/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\documents and settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: Free YouTube to MP3 Converter - c:\documents and settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
IE: Se&nd to OneNote - c:\progra~1\MICROS~3\Office14\ONBttnIE.dll/105
TCP: DhcpNameServer = 192.168.1.1
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-21609012.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-04-08 17:03
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2036)
c:\windows\system32\WININET.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~3\Office14\1033\GrooveIntlResource.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2013-04-08 17:05:46
ComboFix-quarantined-files.txt 2013-04-08 16:05
ComboFix2.txt 2013-04-07 09:33
.
Pre-Run: 14,382,051,328 bytes free
Post-Run: 14,368,620,544 bytes free
.
- - End Of File - - 757BCE2F177B5FF8D6A57EF23D21D8DC
  • 0

#10
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello chrisg6152

I would like to see a report that combofix makes.

extra combofix report

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box
C:\Qoobox\Add-Remove Programs.txt
  • click ok

copy and paste the report into this topic for me to review

Gringo
  • 0

Advertisements


#11
chrisg6152

chrisg6152

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
Hello Gringo

Report as requested

32 Bit HP CIO Components Installer
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader 9.5.2
Adobe Shockwave Player 11.6
Apple Application Support
Apple Mobile Device Support
Apple Software Update
ATI - Software Uninstall Utility
ATI Parental Control
Audacity 2.0
Bonjour
BTOffer
BufferChm
CCleaner
Citrix online plug-in - web
Citrix online plug-in (DV)
Citrix online plug-in (HDX)
Citrix online plug-in (USB)
Citrix online plug-in (Web)
Copy
CustomerResearchQFolder
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition
Dell Resource CD
Destination Component
DeviceDiscovery
DeviceManagementQFolder
DJ_AIO_03_F2200_ProductContext
DJ_AIO_03_F2200_Software
DJ_AIO_03_F2200_Software_Min
Driving Test Success - All Tests 2013 Edition (Update 1)
Edimax RT2860 Wireless LAN Card
eSupportQFolder
F2200
F2200_Help
Free DVD ISO Burner version 1.2
Free YouTube to MP3 Converter version 3.11.36.1201
GFI Backup 2009 - Home Edition
Google Toolbar for Internet Explorer
Google Update Helper
GPBaseService
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB2756822)
Hotfix for Windows XP (KB2779562)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB976002-v5)
HP Customer Participation Program 10.0
HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3
HP Imaging Device Functions 10.0
HP Photosmart Essential 2.5
HP Smart Web Printing
HP Solution Center 10.0
HP Update
HPProductAssistant
HPSSupply
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
iTunes
Java 7 Update 9
Java Auto Updater
LAME v3.99.3 (for Windows)
Malwarebytes Anti-Malware version 1.70.0.1100
MarketResearch
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework Client Profile
Microsoft Application Error Reporting
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft National Language Support Downlevel APIs
Microsoft Office 2010 Service Pack 1 (SP1)
Microsoft Office Access MUI (English) 2010
Microsoft Office Access Setup Metadata MUI (English) 2010
Microsoft Office Excel MUI (English) 2010
Microsoft Office Groove MUI (English) 2010
Microsoft Office InfoPath MUI (English) 2010
Microsoft Office OneNote MUI (English) 2010
Microsoft Office Outlook MUI (English) 2010
Microsoft Office PowerPoint MUI (English) 2010
Microsoft Office Professional Plus 2010
Microsoft Office Proof (English) 2010
Microsoft Office Proof (French) 2010
Microsoft Office Proof (Spanish) 2010
Microsoft Office Proofing (English) 2010
Microsoft Office Publisher MUI (English) 2010
Microsoft Office Shared MUI (English) 2010
Microsoft Office Shared Setup Metadata MUI (English) 2010
Microsoft Office Word MUI (English) 2010
Microsoft Security Client
Microsoft Security Essentials
Microsoft Silverlight
Microsoft Software Update for Web Folders (English) 14
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft WinUsb 1.0
Microsoft Works 6-9 Converter
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
Paint.NET v3.5.10
PDFCreator
PSSWCORE
Samsung New PC Studio
Scan
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft Excel 2010 (KB2597126) 32-Bit Edition
Security Update for Microsoft Filter Pack 2.0 (KB2553501) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687417) 32-Bit Edition
Security Update for Microsoft InfoPath 2010 (KB2687436) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553091)
Security Update for Microsoft Office 2010 (KB2553096)
Security Update for Microsoft Office 2010 (KB2553371) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2553447) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2589337) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2597986) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2598243) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687501) 32-Bit Edition
Security Update for Microsoft Office 2010 (KB2687510) 32-Bit Edition
Security Update for Microsoft OneNote 2010 (KB2760600) 32-Bit Edition
Security Update for Microsoft Visio 2010 (KB2760762) 32-Bit Edition
Security Update for Microsoft Visio Viewer 2010 (KB2687505) 32-Bit Edition
Security Update for Microsoft Windows (KB2564958)
Security Update for Microsoft Word 2010 (KB2760410) 32-Bit Edition
Security Update for Windows Internet Explorer 7 (KB982381)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2722913)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB2761465)
Security Update for Windows Internet Explorer 8 (KB2792100)
Security Update for Windows Internet Explorer 8 (KB2797052)
Security Update for Windows Internet Explorer 8 (KB2799329)
Security Update for Windows Internet Explorer 8 (KB2809289)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479943)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2510581)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2544521)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618444)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2619339)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2724197)
Security Update for Windows XP (KB2727528)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB2753842-v2)
Security Update for Windows XP (KB2753842)
Security Update for Windows XP (KB2757638)
Security Update for Windows XP (KB2758857)
Security Update for Windows XP (KB2761226)
Security Update for Windows XP (KB2770660)
Security Update for Windows XP (KB2778344)
Security Update for Windows XP (KB2779030)
Security Update for Windows XP (KB2780091)
Security Update for Windows XP (KB2799494)
Security Update for Windows XP (KB2802968)
Security Update for Windows XP (KB2807986)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982665)
Serif PhotoPlus Starter Edition
Shop for HP Supplies
SigmaTel Audio
SmartWebPrintingOC
SolutionCenter
Status
swMSM
TomTom HOME
TomTom HOME Visual Studio Merge Modules
Toolbox
TrayApp
Unity Web Player
UnloadSupport
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Office 2010 (KB2553065)
Update for Microsoft Office 2010 (KB2553092)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition
Update for Microsoft Office 2010 (KB2566458)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2661254-v2)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB2749655)
Update for Windows XP (KB898461)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
VC 9.0 Runtime
VideoToolkit01
Visual C++ 8.0 CRT (x86) WinSXS MSM
Visual C++ 8.0 CRT.Policy (x86) WinSXS MSM
WebFldrs XP
WebReg
Window Washer
Windows Feature Pack for Storage (32-bit) - IMAPI update for Blu-Ray
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 11
ZoneAlarm Firewall
ZoneAlarm Free Firewall
ZoneAlarm LTD Toolbar
ZoneAlarm Security
  • 0

#12
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello

These logs are looking allot better. But we still have some work to do.

Please print out these instructions, or copy them to a Notepad file. It will make it easier for you to follow the instructions and complete all of the necessary steps..

uninstall some programs

NOTE** Because of the cleanup process some of the programs I have listed may not be in add/remove anymore this is fine just move to the next item on the list.

You can remove these programs using add/remove or you can use the free uninstaller from Revo (Revo does allot better of a job)

Programs to remove


Adobe Reader 9.5.2
Java 7 Update 9

[/list]


  • Please download and install Revo Uninstaller Free
  • Double click Revo Uninstaller to run it.
  • From the list of programs double click on The Program to remove
  • When prompted if you want to uninstall click Yes.
  • Be sure the Moderate option is selected then click Next.
  • The program will run, If prompted again click Yes
  • when the built-in uninstaller is finished click on Next.
  • Once the program has searched for leftovers click Next.
  • Check/tick the bolded items only on the list then click Delete
  • when prompted click on Yes and then on next.
  • put a check on any folders that are found and select delete
  • when prompted select yes then on next
  • Once done click Finish.
.



Update Adobe reader

Recently there have been vulnerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.

You can download it from http://www.adobe.com.../readstep2.html
After installing the latest Adobe Reader, uninstall all previous versions.
If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

If you don't like Adobe Reader (53 MB), you can download Foxit PDF Reader(7 MB) from here. It's a much smaller file to download and uses a lot less resources than Adobe Reader.

Note: When installing FoxitReader, be careful not to install anything to do with AskBar.
[/list]


Clean Out Temp Files

  • This small application you may want to keep and use once a week to keep the computer clean.

    Download CCleaner from here http://www.ccleaner.com/

  • Run the installer to install the application.
  • When it gives you the option to install Yahoo toolbar uncheck the box next to it.
  • Run CCleaner. (make sure under Windows tab all the boxes of Internet Explorer and Windows explorer are checked. Under System check Empty Recycle Bin and Temporary Files. Under Application tab all the boxes should be checked).
  • Click Run Cleaner.
  • Close CCleaner.



: Malwarebytes' Anti-Malware :


I see You have MBAM installed on the computer - that is great!! it is a very good program! I would like you to run a quick scan for me now

  • Double-click mbam icon
  • go to the update tab at the top
  • click on check for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is Checked (ticked) except items in the C:\System Volume Information folder and click on Remove Selected.
  • When completed, a log will open in Notepad. please copy and paste the log into your next reply
  • If you accidentally close it, the log file is saved here and will be named like this:
  • C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt

Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately. Failure to reboot will prevent MBAM from removing all the malware.



Download HijackThis

  • Go Here to download HijackThis program
  • Save HijackThis to your desktop.
  • Right Click on Hijackthis and select "Run as Admin" (XP users just need to double click to run)
  • Click on "Do A system scan and save a logfile" (if you do not see "Do A system scan and save a logfile" then click on main menu)
  • copy and paste hijackthis report into the topic


"information and logs"

  • In your next post I need the following

  • Log From MBAM
  • report from Hijackthis
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo

  • 0

#13
chrisg6152

chrisg6152

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
Hello Gringo

All done - the only slight problem I had was when I was uninstalling AdobeReader 9.5.2, I was prompted to restart the PC before Revo had a chance to search for leftovers (sorry!)

Java 7 Update 9 removed without incident.

Ccleaner - no issues.

MBAM - no threats detected!

MBAM and HJT Logs pasted below.

Thanks again for your assistance.

Chris G

****************************************

Malwarebytes Anti-Malware 1.70.0.1100
www.malwarebytes.org

Database version: v2013.04.09.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
Chris Clair :: MAINCOMP-364806 [administrator]

09/04/2013 14:29:29
mbam-log-2013-04-09 (14-29-29).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 519981
Time elapsed: 6 minute(s), 34 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)


Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:39:31, on 09/04/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe
C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Citrix\ICA Client\concentr.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Citrix\ICA Client\wfcrun32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\GFI\GFIBAC~1\GFIAgent.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Edimax\Common\RaRegistry.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Webroot\Washer\WasherSvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Edimax\Common\RaUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.talktalk.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLL
O2 - BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [ZoneAlarm] "C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [ConnectionCenter] "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSC] "C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [GFI Backup 2009 - Home Edition] "C:\PROGRA~1\GFI\GFIBAC~1\GFIAgent.exe"
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "Chris Clair"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Wireless Utility.lnk = C:\Program Files\Edimax\Common\RaUI.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeytvdownloader.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Documents and Settings\Chris Clair.MAINCOMP-364806\Application Data\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
O23 - Service: GFI Backup 2009 - Home Edition Attendant Service (GFIBckHAtt) - GFI Software Ltd. - C:\PROGRA~1\GFI\GFIBAC~1\GFIHInst.exe
O23 - Service: GFI Backup 2009 - Home Edition Scheduler Service (GFIBckHSched) - GFI Software Ltd. - C:\PROGRA~1\GFI\GFIBAC~1\GFIHSC~1.EXE
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ZoneAlarm LTD Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Ralink Registry Writer (RalinkRegistryWriter) - Ralink Technology, Corp. - C:\Program Files\Edimax\Common\RaRegistry.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe

--
End of file - 10864 bytes
  • 0

#14
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Greetings

These logs are looking very good, we are almost done!!! Just one more scan to go.

:Remove unneeded start-up entries:

This part of the fix is purely optional
These are programs that start up when you turn on your computer but don't need to be, any of these programs you can click on their icons (or start from the control panel) and start the program when you need it. By stopping these programs you will boot up faster and your computer will work faster.

  • Run HijackThis (rightclick and run as admin)
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    • O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
      O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

  • Close all open windows and browsers/email, etc...
  • Click on the "Fix Checked" button
  • When completed, close the application.

    NOTE**You can research each of those lines >here< and see if you want to keep them or not
    just copy the name between the brackets and paste into the search space
    O4 - HKLM\..\Run: [IntelliPoint]


Eset Online Scanner

**Note** You will need to use Internet explorer for this scan - Vista and win 7 right click on IE shortcut and run as admin

Go Eset web page to run an online scanner from ESET.

  • Turn off the real time scanner of any existing antivirus program while performing the online scan
  • click on the Run ESET Online Scanner button
  • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
  • When asked, allow the add/on to be installed
    • Click Start
  • Make sure that the option Remove found threats is unticked
  • Click on Advanced Settings, ensure the options
    Scan for potentially unwanted applications, Scan for potentially unsafe applications, and Enable Anti-Stealth Technology are ticked.
  • Click Scan
  • wait for the virus definitions to be downloaded
  • Wait for the scan to finish

When the scan is complete

  • If no threats were found
  • put a checkmark in "Uninstall application on close"
  • close program
  • report to me that nothing was found

  • If threats were found
  • click on "list of threats found"
  • click on "export to text file" and save it as ESET SCAN and save to the desktop
  • Click on back
  • put a checkmark in "Uninstall application on close"
  • click on finish
  • close program
  • copy and paste the report here

Gringo
  • 0

#15
chrisg6152

chrisg6152

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 102 posts
Hi Gringo

And it was all going so well....!

I removed the unwanted start-up entries - no problems.

I then ran the ESET Scan and one threat was detected. (Sirefef.EZ trojan)

Log is pasted below

C:\System Volume Information\_restore{0BF980A5-C5BE-4BC1-BCBD-B7698AEDCB6E}\RP506\A0071817.ini Win32/Sirefef.EZ trojan



Cheers

Chris G
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP