Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Malware is blank white screen with audio playing that is unintelligibl


  • This topic is locked This topic is locked

#46
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Also run GMER.

Please download GMER from one of the following locations and save it to your desktop:


  • Main Mirror which will download a randomly named file
  • Zipped Mirror - Unzip the file to its own folder such as C:\gmer
  • Disconnect from the Internet and close all running programs
  • Temporarily disable any real-time active protection
  • It is very important you do not use your computer while GMER is running
  • Double-click on the randomly named GMER Posted Image icon
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan
  • If you receive a warning about rootkit activity and are asked to fully scan your system click NO
  • Please check in the Quick scan box
  • Please uncheck the following:

    • IAT/EAT
    • Show All <<< Important

    Posted Image
  • Click Scan
  • If you see a rootkit warning window click OK
  • When the scan is finished, Save the results to your desktop as gmer.log
  • Click Copy then paste the results in your reply
  • Exit GMER and be sure to re-enable your Antivirus, Firewall and any other security programs you had disabled

Note:

  • If you encounter any problems, try running GMER in Safe Mode
  • If GMER crashes or keeps resulting in a Blue Screen of Death, uncheck Devices on the right side before scanning

  • 0

Advertisements


#47
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts
When I opened OTL to run the /md5start
HOSTS
/md5stop

scan, the below log opened. I'm going to run the OTL scan now.


Files\Folders moved on Reboot...
File\Folder C:\Windows\temp\fla6115.tmp not found!
File\Folder C:\Windows\temp\fla77C2.tmp not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\![1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\300x250[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\3171[1].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\4158391789223988633[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\5dca6a65-0fdf-4ea3-8a10-c0ce7803cbbc[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\adoapn_AppNexusDemoActionTag_1[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\adoapn_AppNexusDemoActionTag_1[2].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\ads[3].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\ads[4].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\ad[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\an_brightroll_com[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\aT01NDA0LHM9MTYweDYwMCxuPWlmcmFtZQ==[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\B7706797[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\beacon[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[1].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[2].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[3].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[4].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[5].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[6].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[7].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\bounce[8].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\cas_blank[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\cas_blank[2].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\celebritycenter[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\clk[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\cs[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\ddc[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\ddc[2].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\ddc[3].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\ddc[5].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\Diamond-Jewel[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\dk[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\doclix_synd_ifrm[1].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\doclix_synd_overlay[1].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\doclix_synd_toolbar[1].js not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\d[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\emily[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\gv2_emercial_back2[1].gif not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\iframeads[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\if[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\if[2].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\if[3].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\if[4].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\if[5].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\if[6].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\if[7].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\meta[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\net[1].htm not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\p-01-0VIaSjnOLg[1].gif not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\p-01-0VIaSjnOLg[2].gif not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\p-01-0VIaSjnOLg[3].gif not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\p-01-0VIaSjnOLg[4].gif not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\p-01-0VIaSjnOLg[5].gif not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UMTTVVLW\Pug[4].gif not found!
File\Folder C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OV0Y8EBZ\filmannex_com[2].htm not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 0

#48
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts

Something is like intervening with the HOSTS and producing .mp4 files in the temp folder. Lets increase the number of days there were changes in the computer.

Run OTL as follows:

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • OTL should now start. Change the following settings
    • Under File Scans, change File age to 90
  • Under the Custom Scan box paste this in



    /md5start
    HOSTS
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt (first run only). These are saved in the same location as OTL.
    • Please post the contents of the OTL.txt file and attach the Extras.Txt, if any, in your next reply.



LOG:


OTL logfile created on: 6/11/2013 6:02:49 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dianne\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.97 Gb Total Physical Memory | 2.08 Gb Available Physical Memory | 52.55% Memory free
8.14 Gb Paging File | 5.74 Gb Available in Paging File | 70.55% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.58 Gb Total Space | 531.44 Gb Free Space | 77.74% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 0.02 Gb Free Space | 0.12% Space Free | Partition Type: NTFS
Drive E: | 48.38 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DIANNE-PC | User Name: dianne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

========== Processes (SafeList) ==========

PRC - [2013/06/05 18:17:00 | 001,015,984 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
PRC - [2013/05/04 18:45:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dianne\Desktop\OTL.exe
PRC - [2013/04/30 18:27:15 | 000,216,968 | ---- | M] (Google Inc.) -- C:\Users\dianne\AppData\Local\Google\Update\1.3.21.145\GoogleCrashHandler.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/11/22 11:29:16 | 003,290,304 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2010/09/28 18:13:24 | 000,791,360 | ---- | M] (Interactive Brands Inc.) -- C:\Program Files (x86)\PDF Suite 2010\ConversionService.exe
PRC - [2009/05/21 08:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/04/13 09:48:12 | 000,828,656 | ---- | M] (Dell Inc.) -- c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe


========== Modules (No Company Name) ==========

MOD - [2013/05/29 01:27:38 | 000,393,168 | ---- | M] () -- C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll
MOD - [2013/05/29 01:27:35 | 004,051,408 | ---- | M] () -- C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
MOD - [2013/05/29 01:26:36 | 001,597,392 | ---- | M] () -- C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/07/11 14:54:58 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2011/04/27 16:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2011/04/27 16:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/07/09 19:48:34 | 001,044,648 | ---- | M] ( ) [Disabled | Stopped] -- C:\Windows\SysNative\dldtcoms.exe -- (dldt_device)
SRV:64bit: - [2009/07/09 19:48:28 | 000,033,448 | ---- | M] () [Disabled | Stopped] -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldtserv.exe -- (dldtCATSCustConnectService)
SRV:64bit: - [2008/12/18 14:05:28 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Stopped] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV:64bit: - [2008/07/18 08:42:16 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/06/05 18:17:00 | 001,015,984 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe -- (vToolbarUpdater15.2.0)
SRV - [2013/04/30 18:45:18 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/11/22 11:29:16 | 003,290,304 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/07/13 14:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2010/09/28 18:13:24 | 000,791,360 | ---- | M] (Interactive Brands Inc.) [Auto | Running] -- C:\Program Files (x86)\PDF Suite 2010\ConversionService.exe -- (PDF Suite 2010 Service)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/24 16:42:56 | 000,386,424 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2009/08/11 23:25:12 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2009/07/09 19:48:28 | 000,033,448 | ---- | M] () [Disabled | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\\dldtserv.exe -- (dldtCATSCustConnectService)
SRV - [2009/05/21 08:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter)
SRV - [2009/04/17 10:17:02 | 000,636,144 | ---- | M] (SoftThinks) [Disabled | Stopped] -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe -- (SftService)
SRV - [2009/04/13 09:48:12 | 000,828,656 | ---- | M] (Dell Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe -- (hnmsvc)
SRV - [2009/04/13 09:48:10 | 000,189,680 | ---- | M] (SingleClick Systems) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe -- (dsl-fs-sync)
SRV - [2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/11/03 19:15:32 | 000,242,424 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008/02/25 12:38:12 | 000,595,184 | ---- | M] ( ) [Disabled | Stopped] -- C:\Windows\SysWOW64\dldtcoms.exe -- (dldt_device)
SRV - [2007/09/21 14:26:34 | 000,015,872 | ---- | M] (Apache Software Foundation) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe -- (Apache2.2)
SRV - [2007/09/14 14:35:04 | 005,730,304 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe -- (dsl-db)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/06/05 18:17:03 | 000,045,856 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/02/29 09:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/07/22 12:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 17:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/04/27 14:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/09/30 20:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009/02/23 05:47:04 | 000,126,464 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2008/07/21 07:18:30 | 000,026,624 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\RtNdPt60.sys -- (RtNdPt60)
DRV:64bit: - [2008/07/15 08:14:10 | 000,395,288 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\iastor.sys -- (iaStor)
DRV:64bit: - [2008/07/10 07:28:50 | 000,170,496 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:64bit: - [2008/06/18 17:48:54 | 000,029,184 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\packet.sys -- (Packet)
DRV:64bit: - [2008/01/20 22:46:55 | 000,317,952 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys -- (e1express)
DRV:64bit: - [2007/11/14 03:00:00 | 000,053,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2007/04/03 10:30:14 | 001,418,112 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\Ph3xIB64.sys -- (Ph3xIB64)
DRV:64bit: - [2006/11/02 03:48:50 | 002,488,320 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (R300)
DRV - [2008/06/17 12:01:06 | 000,022,016 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\packet.sys -- (Packet)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec}: "URL" = http://search.mywebs...r={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comca...insDate11132012
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {E65EABE4-E694-4222-8333-E9ABBE5AB189}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" = http://search.comcas...q={searchTerms}
IE - HKCU\..\SearchScopes\{1DC242E9-1AB7-4413-8EE9-8A0005BCEC7C}: "URL" = http://search.avg.co...}&iy=b&ychte=us
IE - HKCU\..\SearchScopes\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}: "URL" = http://search.alot.c...n=2.5.15000.521
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7ADFA_enUS361
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...sa&d=2013-06-05 18:46:55&v=15.2.0.5&pid=avg&sg=&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKCU\..\SearchScopes\{B2CF385E-4E62-4BDA-A734-DBE9B5C2EB30}: "URL" = http://search.condui...q={searchTerms}
IE - HKCU\..\SearchScopes\{C34CE811-7235-4423-B317-2940DF564B8E}: "URL" = http://ws.infospace....r?_iceUrl=true user_id=%userid&tool_id=60231&qkw={searchTerms}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\..\SearchScopes\{E65EABE4-E694-4222-8333-E9ABBE5AB189}: "URL" = http://search.condui...3829527319&UM=2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\npEpicPlayDisplayHost: C:\Program Files (x86)\EpicPlay\npEpicHost.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\dianne\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\dianne\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX

[2011/02/27 23:36:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dianne\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: EpicPlay NPAPI Display Host (Enabled) = C:\Program Files (x86)\EpicPlay\npEpicHost.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files (x86)\MyFunCards_5m\bar\1.bin\NP5mStub.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Roblox Launcher Plugin (Enabled) = C:\Users\dianne\AppData\Local\Roblox\Versions\version-09a201d8e5f247c7\\NPRobloxProxy.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Skype Click to Call = C:\Users\dianne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.4.0.11328_0\
CHR - Extension: Skype Click to Call = C:\Users\dianne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.4.0.11328_0\

O1 - HOSTS file present but inaccessible!
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (PDF Suite Helper) - {1AD61D5B-58A3-4592-9B34-DC84688FF805} - C:\Program Files (x86)\PDF Suite 2010\PDFIEHelper.dll (Interactive Brands Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PDF Suite Toolbar) - {261F6A8B-7AAF-4BF5-8552-6610F4D67819} - C:\Program Files (x86)\PDF Suite 2010\PDFIEPlugin.dll (Interactive Brands Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe (AVG Secure Search)
O4 - HKCU..\Run: [Driver Pro] C:\Program Files (x86)\Driver Pro\DPLauncher.exe (PC Utilities Pro)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9592D7CB-CDCE-4358-BC20-5FC63CC64C0D}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\1600x1200_blue.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\1600x1200_blue.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/03 12:46:04 | 000,000,101 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 90 Days ==========

[2013/06/08 15:03:13 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/06/07 21:29:50 | 000,000,000 | ---D | C] -- C:\MyPoppy9426M
[2013/06/07 21:04:08 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/06/07 16:26:34 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/06/07 16:26:34 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/06/07 16:26:33 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/06/07 12:14:27 | 000,000,000 | ---D | C] -- C:\MyPoppy
[2013/06/06 21:08:17 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013/06/06 17:53:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013/06/05 22:08:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/06/05 22:08:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/06/05 22:08:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/06/05 21:52:13 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/06/05 21:51:43 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/06/05 21:49:04 | 005,078,746 | R--- | C] (Swearware) -- C:\Users\dianne\Desktop\MyPoppy.exe
[2013/06/05 18:48:48 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\AVG2013
[2013/06/05 18:46:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
[2013/06/05 18:43:57 | 000,000,000 | ---D | C] -- C:\$AVG
[2013/06/05 18:43:56 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013/06/05 18:38:00 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\Avg2013
[2013/06/05 18:23:08 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\AVG Secure Search
[2013/06/05 18:09:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Roblox
[2013/05/31 11:36:31 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2013/05/27 04:20:49 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\Tuguu SL
[2013/05/25 03:31:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Iminent
[2013/05/25 03:28:28 | 000,000,000 | ---D | C] -- C:\Program Files\Uninstaller
[2013/05/25 03:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vafmusic2
[2013/05/25 03:23:17 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\Uniblue
[2013/05/25 03:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Uniblue
[2013/05/25 03:22:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SingAlong
[2013/05/25 03:22:45 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\DownloadTerms
[2013/05/23 04:34:59 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\Systweak
[2013/05/22 22:46:18 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\IAC
[2013/05/15 02:31:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShopAtHome.com Toolbar
[2013/05/15 02:31:11 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\ShopAtHome
[2013/05/05 18:06:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/05/05 18:06:21 | 000,866,720 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013/05/05 18:06:06 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/05/05 16:33:29 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\Malwarebytes
[2013/05/05 16:33:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/05/05 16:33:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/05/05 16:33:12 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/05/05 16:33:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/05/04 23:06:09 | 000,000,000 | ---D | C] -- C:\FRST
[2013/05/04 18:45:52 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\dianne\Desktop\OTL.exe
[2013/05/01 13:47:25 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/05/01 13:47:25 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/05/01 13:47:22 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/05/01 13:47:22 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/05/01 13:47:22 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/05/01 13:47:22 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/05/01 13:47:21 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/05/01 13:47:21 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/05/01 13:47:20 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/05/01 13:47:20 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/05/01 13:47:19 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/05/01 13:47:19 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/05/01 13:47:18 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/05/01 13:47:18 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/05/01 13:47:18 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/04/30 18:14:44 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2013/04/30 17:50:23 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2013/04/30 08:13:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Coupon Savings
[2013/04/19 12:36:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WhiteSmoke_New
[2013/04/19 12:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
[2013/04/19 12:35:20 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\Driver Pro
[2013/04/19 12:35:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver Pro
[2013/04/19 12:35:04 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\CRE
[2013/04/19 12:34:43 | 000,000,000 | ---D | C] -- C:\Program Files\DomaIQ Uninstaller
[2013/04/19 12:34:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2013/04/19 12:33:38 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\player
[2013/04/19 12:29:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SweetIM
[2013/04/19 12:28:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro
[2013/04/16 16:38:46 | 000,049,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\circbogd.sys
[2013/04/09 20:28:44 | 004,691,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013/04/09 20:28:43 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2013/04/09 20:28:43 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2013/04/09 20:28:40 | 000,451,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013/04/09 20:28:37 | 002,425,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2013/04/09 20:28:37 | 002,067,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2013/03/20 16:41:27 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
[2009/08/19 09:41:49 | 008,653,312 | ---- | C] (Dell, Inc. ) -- C:\Users\dianne\AppData\Roaming\DataSafeDotNet.exe

========== Files - Modified Within 90 Days ==========

[2013/06/11 17:45:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/11 17:34:22 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/11 17:34:22 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/11 17:32:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1424625615-964005803-1290662544-1000UA.job
[2013/06/11 17:22:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/10 18:32:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1424625615-964005803-1290662544-1000Core.job
[2013/06/10 18:22:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/10 09:34:26 | 000,000,288 | ---- | M] () -- C:\Windows\tasks\RtlNICDiagVistaStart.job
[2013/06/10 09:33:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/08 18:45:30 | 000,000,632 | RHS- | M] () -- C:\Users\dianne\ntuser.pol
[2013/06/08 15:01:55 | 635,361,307 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013/06/07 21:16:06 | 000,272,616 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/07 21:10:26 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/06/07 12:13:03 | 005,078,746 | R--- | M] (Swearware) -- C:\Users\dianne\Desktop\MyPoppy.exe
[2013/06/06 17:43:19 | 000,001,810 | ---- | M] () -- C:\Users\dianne\Desktop\Microsoft Security Essentials.lnk
[2013/06/06 17:36:22 | 000,002,090 | ---- | M] () -- C:\Users\dianne\Desktop\Google Chrome.lnk
[2013/06/05 18:17:03 | 000,045,856 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/05/05 18:05:34 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/05/05 18:05:24 | 000,263,584 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/05/05 18:05:23 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/05/05 18:05:22 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/05/05 18:05:20 | 000,866,720 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013/05/05 18:05:20 | 000,788,896 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013/05/05 17:53:09 | 000,000,772 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/05/05 16:33:22 | 000,000,950 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/05 16:16:20 | 000,004,700 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013/05/05 16:09:46 | 000,759,750 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/05 16:09:46 | 000,642,736 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/05/05 16:09:46 | 000,119,888 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/05/04 18:45:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dianne\Desktop\OTL.exe
[2013/04/30 18:45:17 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/04/30 18:45:17 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/04/21 03:14:36 | 000,754,664 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/04/19 12:35:26 | 000,000,867 | ---- | M] () -- C:\Users\dianne\Desktop\Driver Pro.lnk
[2013/04/19 12:28:06 | 000,000,903 | ---- | M] () -- C:\Users\dianne\Desktop\Optimizer Pro.lnk
[2013/04/16 16:38:46 | 000,049,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\circbogd.sys
[2013/04/12 23:34:30 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2013/04/04 21:08:44 | 002,312,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/04/04 20:59:24 | 001,494,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/04/04 20:58:59 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/04/04 20:56:16 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/04/04 20:55:57 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/04/04 20:55:47 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/04/04 20:54:50 | 000,729,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/04/04 20:51:52 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/04/04 20:46:50 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/04/04 18:02:59 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/04/04 18:01:35 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/04/04 17:58:51 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/04/04 17:58:24 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/04/04 17:54:42 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/04/04 17:50:34 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2013/06/08 15:01:55 | 635,361,307 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2013/06/07 21:15:46 | 000,272,616 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/06 17:43:19 | 000,001,810 | ---- | C] () -- C:\Users\dianne\Desktop\Microsoft Security Essentials.lnk
[2013/06/05 22:08:39 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/06/05 22:08:39 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/06/05 22:08:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/06/05 22:08:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/06/05 22:08:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/05/05 16:33:22 | 000,000,950 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/05 16:16:05 | 000,004,700 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013/04/19 12:35:26 | 000,000,867 | ---- | C] () -- C:\Users\dianne\Desktop\Driver Pro.lnk
[2013/04/19 12:28:06 | 000,000,903 | ---- | C] () -- C:\Users\dianne\Desktop\Optimizer Pro.lnk
[2011/12/04 14:19:52 | 000,000,632 | RHS- | C] () -- C:\Users\dianne\ntuser.pol
[2011/10/28 11:58:25 | 000,754,664 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/25 18:01:22 | 002,052,096 | ---- | C] () -- C:\Users\dianne\s-1-5-21-1424625615-964005803-1290662544-1000.rrr
[2010/07/25 16:25:20 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/10/04 20:39:28 | 000,005,632 | ---- | C] () -- C:\Users\dianne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/14 20:58:57 | 000,007,728 | ---- | C] () -- C:\Users\dianne\AppData\Local\d3d9caps.dat

========== ZeroAccess Check ==========

[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 13:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 13:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/04/11 03:11:14 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2009/04/11 02:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008/01/20 22:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll

========== Custom Scans ==========

< MD5 for: HOSTS >
[2006/09/18 17:37:24 | 000,000,761 | ---- | M] () MD5=01505BB3F7004537F4F2C0FBBA349A1F -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6001.18000_none_60a39df1afb86c9f\hosts

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:5D432CE3

< End of report >
  • 0

#49
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts

Also run GMER.

Please download GMER from one of the following locations and save it to your desktop:


  • Main Mirror which will download a randomly named file
  • Zipped Mirror - Unzip the file to its own folder such as C:\gmer
  • Disconnect from the Internet and close all running programs
  • Temporarily disable any real-time active protection
  • It is very important you do not use your computer while GMER is running
  • Double-click on the randomly named GMER Posted Image icon
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan
  • If you receive a warning about rootkit activity and are asked to fully scan your system click NO
  • Please check in the Quick scan box
  • Please uncheck the following:

    • IAT/EAT
    • Show All <<< Important

    Posted Image
  • Click Scan
  • If you see a rootkit warning window click OK
  • When the scan is finished, Save the results to your desktop as gmer.log
  • Click Copy then paste the results in your reply
  • Exit GMER and be sure to re-enable your Antivirus, Firewall and any other security programs you had disabled

Note:

  • If you encounter any problems, try running GMER in Safe Mode
  • If GMER crashes or keeps resulting in a Blue Screen of Death, uncheck Devices on the right side before scanning




GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-11 18:30:05
Windows 6.0.6002 Service Pack 2 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3750528AS rev.CC44 698.64GB
Running: zu0omelh.exe; Driver: C:\Users\dianne\AppData\Local\Temp\pwdirpog.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification

---- User code sections - GMER 2.1 ----

.text C:\Windows\system32\svchost.exe[516] C:\Windows\system32\WININET.dll!HttpSendRequestW 000000007721d1e8 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[516] C:\Windows\system32\WININET.dll!HttpSendRequestA 0000000077299dd0 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[516] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe366510 9 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[516] C:\Windows\system32\ole32.dll!CoCreateInstance + 11 000007fefe36651b 3 bytes [00, 00, 00]
.text C:\Windows\system32\svchost.exe[516] C:\Windows\system32\ole32.dll!CoGetClassObject 000007fefe369d94 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[516] C:\Windows\system32\WS2_32.dll!GetAddrInfoW + 1 000007fefe7e2ba1 13 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[516] C:\Windows\system32\winmm.dll!waveOutOpen 000007fefc753170 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077ab9475 7 bytes {MOV EDX, 0x37c228; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 0000000077ab969d 7 bytes {MOV EDX, 0x37c268; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 0000000077ab96cd 7 bytes {MOV EDX, 0x37c1a8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 0000000077ab96e5 7 bytes {MOV EDX, 0x37c128; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 0000000077ab96fd 7 bytes {MOV EDX, 0x37c328; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 0000000077ab972d 7 bytes {MOV EDX, 0x37c368; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 0000000077ab97a5 7 bytes {MOV EDX, 0x37c2e8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 0000000077ab97bd 7 bytes {MOV EDX, 0x37c2a8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077ab9805 7 bytes {MOV EDX, 0x37c068; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 0000000077ab98f5 7 bytes {MOV EDX, 0x37c0a8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077ab9b35 7 bytes {MOV EDX, 0x37c028; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 0000000077abaa45 7 bytes {MOV EDX, 0x37c1e8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 0000000077abaabd 7 bytes {MOV EDX, 0x37c168; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[90780] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 0000000077abacb5 7 bytes {MOV EDX, 0x37c0e8; JMP RDX}

---- Devices - GMER 2.1 ----

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 fffffa80068070a8

---- Kernel code sections - GMER 2.1 ----

INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification

---- Trace I/O - GMER 2.1 ----

Trace ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys >>UNKNOWN [0xfffffa80068070a8]<< hal.dll fffffa80068070a8
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c8c5b0] fffffa8004c8c5b0
Trace 3 CLASSPNP.SYS[fffffa6000ba5c33] -> nt!IofCallDriver -> [0xfffffa8004928760] fffffa8004928760
Trace 5 acpi.sys[fffffa60008ddfde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800491e940] fffffa800491e940
Trace \Driver\atapi[0xfffffa80066731a0] -> IRP_MJ_CREATE -> 0xfffffa80068070a8 fffffa80068070a8

---- Registry - GMER 2.1 ----

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore@Flags 4
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore\AllowedDomains
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore\AllowedDomains\roblox.com

---- Disk sectors - GMER 2.1 ----

Disk \Device\Harddisk0\DR0 Windows VISTA default MBR code found via API
Disk \Device\Harddisk0\DR0 unknown MBR code
Disk \Device\Harddisk0\DR0 sector 0: rootkit-like behavior

---- EOF - GMER 2.1 ----
  • 0

#50
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
We are closer to the problem.

Run OTL as follows:
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • OTL should now start.
  • Under the Custom Scan box paste this in



    /md5start
    ntoskrnl.exe
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt (first run only). These are saved in the same location as OTL.
  • Please post the contents of the OTL.txt file and attach the Extras.Txt, if any, in your next reply.

  • 0

#51
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts

We are closer to the problem.

Run OTL as follows:

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • OTL should now start.
  • Under the Custom Scan box paste this in



    /md5start
    ntoskrnl.exe
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt (first run only). These are saved in the same location as OTL.
  • Please post the contents of the OTL.txt file and attach the Extras.Txt, if any, in your next reply.


Sounds good, can't wait to get this fixed. Running back and forth to her place is a pain. I appreciate your efforts.

OTL logfile created on: 6/12/2013 7:34:48 AM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dianne\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.97 Gb Total Physical Memory | 1.56 Gb Available Physical Memory | 39.33% Memory free
8.14 Gb Paging File | 5.37 Gb Available in Paging File | 65.98% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 683.58 Gb Total Space | 532.08 Gb Free Space | 77.84% Space Free | Partition Type: NTFS
Drive D: | 15.00 Gb Total Space | 0.02 Gb Free Space | 0.12% Space Free | Partition Type: NTFS
Drive E: | 48.38 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: DIANNE-PC | User Name: dianne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days

========== Processes (SafeList) ==========

PRC - [2013/06/05 18:46:33 | 001,226,928 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\AVG Secure Search\vprot.exe
PRC - [2013/06/05 18:17:00 | 001,015,984 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
PRC - [2013/05/04 18:45:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dianne\Desktop\OTL.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/11/22 11:29:16 | 003,290,304 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2010/09/28 18:13:24 | 000,791,360 | ---- | M] (Interactive Brands Inc.) -- C:\Program Files (x86)\PDF Suite 2010\ConversionService.exe
PRC - [2009/05/21 08:59:14 | 001,025,264 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\gs_agent\dsc.exe
PRC - [2009/05/21 08:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/05/21 08:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/13 09:48:12 | 000,828,656 | ---- | M] (Dell Inc.) -- c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
PRC - [2008/12/18 14:05:28 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/09/14 14:35:04 | 005,730,304 | ---- | M] () -- C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe


========== Modules (No Company Name) ==========

MOD - [2013/06/05 18:17:03 | 000,158,384 | ---- | M] () -- C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\SiteSafety.dll
MOD - [2013/05/29 01:27:38 | 000,393,168 | ---- | M] () -- C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll
MOD - [2013/05/29 01:27:35 | 004,051,408 | ---- | M] () -- C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
MOD - [2013/05/29 01:26:36 | 001,597,392 | ---- | M] () -- C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll
MOD - [2013/01/09 04:31:11 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll
MOD - [2013/01/09 04:30:09 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll
MOD - [2013/01/09 04:30:05 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/07/11 14:54:58 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2011/04/27 16:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2011/04/27 16:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/07/09 19:48:34 | 001,044,648 | ---- | M] ( ) [Disabled | Stopped] -- C:\Windows\SysNative\dldtcoms.exe -- (dldt_device)
SRV:64bit: - [2009/07/09 19:48:28 | 000,033,448 | ---- | M] () [Disabled | Stopped] -- C:\Windows\SysNative\spool\DRIVERS\x64\3\\dldtserv.exe -- (dldtCATSCustConnectService)
SRV:64bit: - [2008/12/18 14:05:28 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV:64bit: - [2008/07/18 08:42:16 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\SysNative\AERTSr64.exe -- (AERTFilters)
SRV:64bit: - [2008/01/20 22:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/06/05 18:17:00 | 001,015,984 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe -- (vToolbarUpdater15.2.0)
SRV - [2013/04/30 18:45:18 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/11/22 11:29:16 | 003,290,304 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/07/13 14:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2010/09/28 18:13:24 | 000,791,360 | ---- | M] (Interactive Brands Inc.) [Auto | Running] -- C:\Program Files (x86)\PDF Suite 2010\ConversionService.exe -- (PDF Suite 2010 Service)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/24 16:42:56 | 000,386,424 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2009/08/11 23:25:12 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2009/07/09 19:48:28 | 000,033,448 | ---- | M] () [Disabled | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\\dldtserv.exe -- (dldtCATSCustConnectService)
SRV - [2009/05/21 08:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter)
SRV - [2009/04/17 10:17:02 | 000,636,144 | ---- | M] (SoftThinks) [Disabled | Stopped] -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe -- (SftService)
SRV - [2009/04/13 09:48:12 | 000,828,656 | ---- | M] (Dell Inc.) [Auto | Running] -- c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe -- (hnmsvc)
SRV - [2009/04/13 09:48:10 | 000,189,680 | ---- | M] (SingleClick Systems) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe -- (dsl-fs-sync)
SRV - [2009/03/30 00:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/11/03 19:15:32 | 000,242,424 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2008/02/25 12:38:12 | 000,595,184 | ---- | M] ( ) [Disabled | Stopped] -- C:\Windows\SysWOW64\dldtcoms.exe -- (dldt_device)
SRV - [2007/09/21 14:26:34 | 000,015,872 | ---- | M] (Apache Software Foundation) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe -- (Apache2.2)
SRV - [2007/09/14 14:35:04 | 005,730,304 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe -- (dsl-db)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/06/05 18:17:03 | 000,045,856 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/02/29 09:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/07/22 12:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 17:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/04/27 14:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/09/30 20:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009/02/23 05:47:04 | 000,126,464 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2008/07/21 07:18:30 | 000,026,624 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\RtNdPt60.sys -- (RtNdPt60)
DRV:64bit: - [2008/07/15 08:14:10 | 000,395,288 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\iastor.sys -- (iaStor)
DRV:64bit: - [2008/07/10 07:28:50 | 000,170,496 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:64bit: - [2008/06/18 17:48:54 | 000,029,184 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\packet.sys -- (Packet)
DRV:64bit: - [2008/01/20 22:46:55 | 000,317,952 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys -- (e1express)
DRV:64bit: - [2007/11/14 03:00:00 | 000,053,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2007/04/03 10:30:14 | 001,418,112 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\Ph3xIB64.sys -- (Ph3xIB64)
DRV:64bit: - [2006/11/02 03:48:50 | 002,488,320 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (R300)
DRV - [2008/06/17 12:01:06 | 000,022,016 | ---- | M] (SingleClick Systems) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\drivers\packet.sys -- (Packet)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec}: "URL" = http://search.mywebs...r={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xfinity.comca...insDate11132012
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: - No CLSID value found
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn3\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {E65EABE4-E694-4222-8333-E9ABBE5AB189}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{180780f0-b348-4b44-8210-94a8f3ee15b2}: "URL" = http://search.comcas...q={searchTerms}
IE - HKCU\..\SearchScopes\{1DC242E9-1AB7-4413-8EE9-8A0005BCEC7C}: "URL" = http://search.avg.co...}&iy=b&ychte=us
IE - HKCU\..\SearchScopes\{5AA2BA46-9913-4DC7-9620-69AB0FA17AE7}: "URL" = http://search.alot.c...n=2.5.15000.521
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7ADFA_enUS361
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...sa&d=2013-06-05 18:46:55&v=15.2.0.5&pid=avg&sg=&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{acbd5593-e5ee-4c15-b48f-1823ce819dec}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKCU\..\SearchScopes\{B2CF385E-4E62-4BDA-A734-DBE9B5C2EB30}: "URL" = http://search.condui...q={searchTerms}
IE - HKCU\..\SearchScopes\{C34CE811-7235-4423-B317-2940DF564B8E}: "URL" = http://ws.infospace....r?_iceUrl=true user_id=%userid&tool_id=60231&qkw={searchTerms}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\..\SearchScopes\{E65EABE4-E694-4222-8333-E9ABBE5AB189}: "URL" = http://search.condui...3829527319&UM=2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\npEpicPlayDisplayHost: C:\Program Files (x86)\EpicPlay\npEpicHost.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\dianne\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\dianne\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}: C:\PROGRAM FILES\UPDATER BY SWEETPACKS\FIREFOX

[2011/02/27 23:36:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\dianne\AppData\Roaming\Mozilla\Extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: EpicPlay NPAPI Display Host (Enabled) = C:\Program Files (x86)\EpicPlay\npEpicHost.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: MindSpark Toolbar Platform Plugin Stub (Enabled) = C:\Program Files (x86)\MyFunCards_5m\bar\1.bin\NP5mStub.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Roblox Launcher Plugin (Enabled) = C:\Users\dianne\AppData\Local\Roblox\Versions\version-09a201d8e5f247c7\\NPRobloxProxy.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Skype Click to Call = C:\Users\dianne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.4.0.11328_0\
CHR - Extension: Skype Click to Call = C:\Users\dianne\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.4.0.11328_0\

O1 - HOSTS file present but inaccessible!
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (PDF Suite Helper) - {1AD61D5B-58A3-4592-9B34-DC84688FF805} - C:\Program Files (x86)\PDF Suite 2010\PDFIEHelper.dll (Interactive Brands Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (PDF Suite Toolbar) - {261F6A8B-7AAF-4BF5-8552-6610F4D67819} - C:\Program Files (x86)\PDF Suite 2010\PDFIEPlugin.dll (Interactive Brands Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll (AVG Secure Search)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe (AVG Secure Search)
O4 - HKCU..\Run: [Driver Pro] C:\Program Files (x86)\Driver Pro\DPLauncher.exe (PC Utilities Pro)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Windows\SysNative\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWow64\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9592D7CB-CDCE-4358-BC20-5FC63CC64C0D}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.2.0\ViProtocol.dll (AVG Secure Search)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\1600x1200_blue.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\1600x1200_blue.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/05/03 12:46:04 | 000,000,101 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 90 Days ==========

[2013/06/12 03:01:12 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/06/12 03:01:12 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/06/12 03:01:10 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/06/12 03:01:10 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/06/12 03:01:10 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/06/12 03:01:09 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/06/12 03:01:09 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/06/12 03:01:09 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/06/12 03:01:07 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/06/12 03:01:07 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/06/12 03:01:07 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/06/12 03:01:06 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/06/12 03:01:06 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/06/12 03:01:06 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/06/12 03:01:05 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/06/12 02:40:20 | 001,269,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013/06/12 02:40:20 | 001,078,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe
[2013/06/12 02:40:20 | 000,812,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe
[2013/06/12 02:40:19 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2013/06/12 02:40:19 | 000,050,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\certenc.dll
[2013/06/12 02:40:19 | 000,041,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\certenc.dll
[2013/06/12 02:40:11 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cryptdlg.dll
[2013/06/12 02:40:11 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptdlg.dll
[2013/06/12 02:40:06 | 000,686,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2013/06/12 02:40:06 | 000,443,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2013/06/12 02:40:06 | 000,037,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\printcom.dll
[2013/06/08 15:03:13 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/06/07 21:29:50 | 000,000,000 | ---D | C] -- C:\MyPoppy9426M
[2013/06/07 21:04:08 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/06/07 16:26:34 | 000,263,584 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/06/07 16:26:34 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/06/07 16:26:33 | 000,174,496 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/06/07 12:14:27 | 000,000,000 | ---D | C] -- C:\MyPoppy
[2013/06/06 21:08:17 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013/06/06 17:53:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013/06/05 22:08:39 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/06/05 22:08:39 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/06/05 22:08:39 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/06/05 21:52:13 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/06/05 21:51:43 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/06/05 21:49:04 | 005,078,746 | R--- | C] (Swearware) -- C:\Users\dianne\Desktop\MyPoppy.exe
[2013/06/05 18:48:48 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\AVG2013
[2013/06/05 18:46:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG Secure Search
[2013/06/05 18:43:57 | 000,000,000 | ---D | C] -- C:\$AVG
[2013/06/05 18:43:56 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
[2013/06/05 18:38:00 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\Avg2013
[2013/06/05 18:23:08 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\AVG Secure Search
[2013/06/05 18:09:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Roblox
[2013/05/31 11:36:31 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2013/05/27 04:20:49 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\Tuguu SL
[2013/05/25 03:31:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Iminent
[2013/05/25 03:28:28 | 000,000,000 | ---D | C] -- C:\Program Files\Uninstaller
[2013/05/25 03:24:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Vafmusic2
[2013/05/25 03:23:17 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\Uniblue
[2013/05/25 03:23:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Uniblue
[2013/05/25 03:22:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SingAlong
[2013/05/25 03:22:45 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\DownloadTerms
[2013/05/23 04:34:59 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\Systweak
[2013/05/22 22:46:18 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\IAC
[2013/05/15 02:31:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShopAtHome.com Toolbar
[2013/05/15 02:31:11 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\ShopAtHome
[2013/05/05 18:06:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/05/05 18:06:21 | 000,866,720 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013/05/05 18:06:06 | 000,095,648 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/05/05 16:33:29 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\Malwarebytes
[2013/05/05 16:33:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/05/05 16:33:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/05/05 16:33:12 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/05/05 16:33:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/05/04 23:06:09 | 000,000,000 | ---D | C] -- C:\FRST
[2013/05/04 18:45:52 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\dianne\Desktop\OTL.exe
[2013/04/30 18:14:44 | 000,047,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2013/04/30 17:50:23 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2013/04/30 08:13:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Coupon Savings
[2013/04/19 12:36:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WhiteSmoke_New
[2013/04/19 12:35:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Pro
[2013/04/19 12:35:20 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\Driver Pro
[2013/04/19 12:35:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver Pro
[2013/04/19 12:35:04 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Local\CRE
[2013/04/19 12:34:43 | 000,000,000 | ---D | C] -- C:\Program Files\DomaIQ Uninstaller
[2013/04/19 12:34:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Tarma Installer
[2013/04/19 12:33:38 | 000,000,000 | ---D | C] -- C:\Users\dianne\AppData\Roaming\player
[2013/04/19 12:29:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SweetIM
[2013/04/19 12:28:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro
[2013/04/16 16:38:46 | 000,049,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\circbogd.sys
[2013/04/09 20:28:44 | 004,691,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013/04/09 20:28:43 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2013/04/09 20:28:43 | 000,075,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2013/04/09 20:28:40 | 000,451,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2013/04/09 20:28:37 | 002,425,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2013/04/09 20:28:37 | 002,067,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2013/03/20 16:41:27 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
[2009/08/19 09:41:49 | 008,653,312 | ---- | C] (Dell, Inc. ) -- C:\Users\dianne\AppData\Roaming\DataSafeDotNet.exe

========== Files - Modified Within 90 Days ==========

[2013/06/12 07:32:02 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1424625615-964005803-1290662544-1000UA.job
[2013/06/12 07:31:54 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/12 07:31:41 | 000,000,288 | ---- | M] () -- C:\Windows\tasks\RtlNICDiagVistaStart.job
[2013/06/12 07:23:32 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/12 07:23:32 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/12 07:22:01 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/12 06:45:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/12 03:22:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/11 18:44:17 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1424625615-964005803-1290662544-1000Core.job
[2013/06/11 18:14:09 | 000,377,856 | ---- | M] () -- C:\Users\dianne\Desktop\zu0omelh.exe
[2013/06/08 18:45:30 | 000,000,632 | RHS- | M] () -- C:\Users\dianne\ntuser.pol
[2013/06/08 15:01:55 | 635,361,307 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2013/06/07 21:16:06 | 000,272,616 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/07 21:10:26 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/06/07 12:13:03 | 005,078,746 | R--- | M] (Swearware) -- C:\Users\dianne\Desktop\MyPoppy.exe
[2013/06/06 17:43:19 | 000,001,810 | ---- | M] () -- C:\Users\dianne\Desktop\Microsoft Security Essentials.lnk
[2013/06/06 17:36:22 | 000,002,090 | ---- | M] () -- C:\Users\dianne\Desktop\Google Chrome.lnk
[2013/06/05 18:17:03 | 000,045,856 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013/05/16 23:09:56 | 002,312,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013/05/16 23:01:13 | 001,494,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2013/05/16 23:00:22 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/05/16 22:56:09 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2013/05/16 22:56:00 | 000,599,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2013/05/16 22:55:59 | 000,816,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013/05/16 22:54:09 | 000,729,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/05/16 22:51:49 | 000,096,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/05/16 22:46:31 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/05/16 18:27:30 | 001,427,968 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2013/05/16 18:26:07 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/05/16 18:21:37 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2013/05/16 18:21:34 | 000,717,824 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013/05/16 18:17:21 | 000,073,216 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/05/16 18:12:55 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/05/05 18:05:34 | 000,095,648 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/05/05 18:05:24 | 000,263,584 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/05/05 18:05:23 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/05/05 18:05:22 | 000,174,496 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/05/05 18:05:20 | 000,866,720 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npDeployJava1.dll
[2013/05/05 18:05:20 | 000,788,896 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013/05/05 17:53:09 | 000,000,772 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/05/05 16:33:22 | 000,000,950 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/05 16:16:20 | 000,004,700 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013/05/05 16:09:46 | 000,759,750 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/05/05 16:09:46 | 000,642,736 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/05/05 16:09:46 | 000,119,888 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/05/04 18:45:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\dianne\Desktop\OTL.exe
[2013/05/02 00:16:27 | 000,686,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\win32spl.dll
[2013/05/02 00:04:25 | 000,443,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\win32spl.dll
[2013/05/02 00:03:42 | 000,037,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\printcom.dll
[2013/04/30 18:45:17 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/04/30 18:45:17 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/04/24 00:09:48 | 001,269,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\crypt32.dll
[2013/04/24 00:09:48 | 000,132,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cryptnet.dll
[2013/04/24 00:09:41 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\certenc.dll
[2013/04/24 00:00:24 | 000,041,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\certenc.dll
[2013/04/23 22:10:00 | 001,078,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\certutil.exe
[2013/04/23 21:46:29 | 000,812,544 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\certutil.exe
[2013/04/21 03:14:36 | 000,754,664 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/04/19 12:35:26 | 000,000,867 | ---- | M] () -- C:\Users\dianne\Desktop\Driver Pro.lnk
[2013/04/19 12:28:06 | 000,000,903 | ---- | M] () -- C:\Users\dianne\Desktop\Optimizer Pro.lnk
[2013/04/17 09:04:03 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cryptdlg.dll
[2013/04/17 08:30:06 | 000,024,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\cryptdlg.dll
[2013/04/16 16:38:46 | 000,049,872 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\circbogd.sys
[2013/04/12 23:34:30 | 000,047,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2013/04/04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2013/06/11 18:14:06 | 000,377,856 | ---- | C] () -- C:\Users\dianne\Desktop\zu0omelh.exe
[2013/06/08 15:01:55 | 635,361,307 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2013/06/07 21:15:46 | 000,272,616 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/06 17:43:19 | 000,001,810 | ---- | C] () -- C:\Users\dianne\Desktop\Microsoft Security Essentials.lnk
[2013/06/05 22:08:39 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/06/05 22:08:39 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/06/05 22:08:39 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/06/05 22:08:39 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/06/05 22:08:39 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/05/05 16:33:22 | 000,000,950 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/05 16:16:05 | 000,004,700 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013/04/19 12:35:26 | 000,000,867 | ---- | C] () -- C:\Users\dianne\Desktop\Driver Pro.lnk
[2013/04/19 12:28:06 | 000,000,903 | ---- | C] () -- C:\Users\dianne\Desktop\Optimizer Pro.lnk
[2011/12/04 14:19:52 | 000,000,632 | RHS- | C] () -- C:\Users\dianne\ntuser.pol
[2011/10/28 11:58:25 | 000,754,664 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/25 18:01:22 | 002,052,096 | ---- | C] () -- C:\Users\dianne\s-1-5-21-1424625615-964005803-1290662544-1000.rrr
[2010/07/25 16:25:20 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009/10/04 20:39:28 | 000,005,632 | ---- | C] () -- C:\Users\dianne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/14 20:58:57 | 000,007,728 | ---- | C] () -- C:\Users\dianne\AppData\Local\d3d9caps.dat

========== ZeroAccess Check ==========

[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 13:59:03 | 012,899,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 13:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/04/11 03:11:14 | 000,891,392 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2009/04/11 02:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2008/01/20 22:50:58 | 000,513,024 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll

========== Custom Scans ==========

< MD5 for: NTOSKRNL.EXE >
[2009/04/24 23:26:03 | 004,413,704 | ---- | M] (Microsoft Corporation) MD5=00B97773349204592B772FCE3035E99C -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20940_none_c6c71f658897fc89\ntoskrnl.exe
[2009/08/05 10:12:46 | 004,682,824 | ---- | M] (Microsoft Corporation) MD5=0170600F2A613CE3E8CC2B66A6DC7885 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22489_none_c88b22db85d6de74\ntoskrnl.exe
[2009/08/05 10:56:15 | 004,691,016 | ---- | M] (Microsoft Corporation) MD5=043EB4B7C74C189E06584411B2C9EB8F -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18304_none_c85303fe6c7ce06f\ntoskrnl.exe
[2010/06/08 14:10:22 | 004,688,256 | ---- | M] (Microsoft Corporation) MD5=04C706018E9F0A2C835A427A8AB6EBA1 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22420_none_caa9776382d49f58\ntoskrnl.exe
[2009/08/05 10:09:23 | 004,693,576 | ---- | M] (Microsoft Corporation) MD5=0DD0FCFB9609403352FF75656826E82F -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22191_none_ca5ec287830c84d1\ntoskrnl.exe
[2013/03/11 09:33:42 | 004,678,504 | ---- | M] (Microsoft Corporation) MD5=1873B95FCEAA40EC9CADF2C1BB61ABF2 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.23076_none_ca794b2382f7e81c\ntoskrnl.exe
[2012/08/29 07:40:01 | 004,699,520 | ---- | M] (Microsoft Corporation) MD5=1A14913D51571403CF8A3941BDC3BA67 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18686_none_c9e5027e69e236b3\ntoskrnl.exe
[2009/04/11 03:15:36 | 004,699,608 | ---- | M] (Microsoft Corporation) MD5=1B60CCC70788044404EEFBBB389FC111 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18005_none_ca3a763069a24eea\ntoskrnl.exe
[2013/03/11 09:33:42 | 004,691,304 | ---- | M] (Microsoft Corporation) MD5=1F8B1075A863117A35EE94436E2962E7 -- C:\Windows\erdnt\cache64\ntoskrnl.exe
[2013/03/11 09:33:42 | 004,691,304 | ---- | M] (Microsoft Corporation) MD5=1F8B1075A863117A35EE94436E2962E7 -- C:\Windows\SysNative\ntoskrnl.exe
[2013/03/11 09:33:42 | 004,691,304 | ---- | M] (Microsoft Corporation) MD5=1F8B1075A863117A35EE94436E2962E7 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18805_none_ca3a856069a23822\ntoskrnl.exe
[2009/04/24 23:32:04 | 004,694,584 | ---- | M] (Microsoft Corporation) MD5=247A2AAF7E5189716192EE19EC6EC6FB -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18145_none_c828c0cc6c9c6f3c\ntoskrnl.exe
[2010/10/15 10:02:22 | 004,689,808 | ---- | M] (Microsoft Corporation) MD5=255A6D981139EFEF605A88E003D1B2A2 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22505_none_cac41a9382bfe350\ntoskrnl.exe
[2009/04/24 23:32:04 | 004,429,368 | ---- | M] (Microsoft Corporation) MD5=2A87B3D380E3800BF247D82E58F0FCBA -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16754_none_c636b1f06f7ee0e5\ntoskrnl.exe
[2010/06/08 13:18:30 | 004,675,976 | ---- | M] (Microsoft Corporation) MD5=31F137EEB5121654A9448904D89209A2 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22707_none_c8dfa7598597c3b3\ntoskrnl.exe
[2012/08/29 07:40:01 | 004,686,208 | ---- | M] (Microsoft Corporation) MD5=34C970A45CCC0D65A4A0F8D306E12844 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22920_none_caa980e182d4911b\ntoskrnl.exe
[2010/10/15 10:02:22 | 004,678,032 | ---- | M] (Microsoft Corporation) MD5=3A22B135BC4341025E19B9ADFB26C02A -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22777_none_c893f7e585d0874a\ntoskrnl.exe
[2010/10/15 10:02:22 | 004,699,024 | ---- | M] (Microsoft Corporation) MD5=4065E920FB6ED05B5F62A1FB6908C6C5 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18327_none_ca26dc9e69b0b0ef\ntoskrnl.exe
[2010/02/18 11:01:52 | 004,690,832 | ---- | M] (Microsoft Corporation) MD5=413D579C2CDEF19CD842F4DF4A90C4ED -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18427_none_c84066ea6c8a617d\ntoskrnl.exe
[2009/12/08 17:05:14 | 004,412,504 | ---- | M] (Microsoft Corporation) MD5=46B167601033C2DB4E1A727569A8CA31 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21175_none_c6ab8b1b88abff78\ntoskrnl.exe
[2009/07/21 11:52:38 | 004,691,032 | ---- | M] (Microsoft Corporation) MD5=4F9F4E0AEDF19C4C3E3AF8D981663996 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18295_none_c7f2b3166cc4f818\ntoskrnl.exe
[2009/12/08 17:09:06 | 004,425,304 | ---- | M] (Microsoft Corporation) MD5=5183EBE8114DA62A532E275CFB3729CC -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16973_none_c620159a6f8ff9be\ntoskrnl.exe
[2009/04/24 23:32:04 | 004,694,584 | ---- | M] (Microsoft Corporation) MD5=5E31190EF331709EAB9FB66C3683540B -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22269_none_c8a0bee785c6ac44\ntoskrnl.exe
[2009/08/05 11:14:15 | 004,412,488 | ---- | M] (Microsoft Corporation) MD5=5E99FFD02816FF54247294C7C9C003B9 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21101_none_c6f339678876d685\ntoskrnl.exe
[2009/08/12 02:51:47 | 004,691,424 | ---- | M] (Microsoft Corporation) MD5=65252FED486E5BF1E384CA65C16148C7 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22389_none_c88b20f585d6e14d\ntoskrnl.exe
[2008/01/20 22:49:27 | 004,694,072 | ---- | M] (Microsoft Corporation) MD5=6760643D6400CA78640E9DD3824115B1 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18000_none_c84efd246c80839e\ntoskrnl.exe
[2009/12/08 17:13:24 | 004,678,232 | ---- | M] (Microsoft Corporation) MD5=6DC7FC9EB17EF1CB809AED351DE91DB9 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22577_none_c893f41985d08cfc\ntoskrnl.exe
[2009/04/24 23:31:35 | 004,694,584 | ---- | M] (Microsoft Corporation) MD5=6DEA6827709FC6F047580111651DFF02 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18063_none_c8111e7a6cae7749\ntoskrnl.exe
[2012/04/03 04:22:15 | 004,699,520 | ---- | M] (Microsoft Corporation) MD5=7180984A68411B9D2F2495E03561B47E -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18607_none_ca3c822869a07082\ntoskrnl.exe
[2010/02/18 10:28:01 | 004,697,992 | ---- | M] (Microsoft Corporation) MD5=72FD908E7D1F176C00F1EF8F3D1445B0 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18209_none_ca3e7b24699eae94\ntoskrnl.exe
[2010/10/15 10:02:22 | 004,692,368 | ---- | M] (Microsoft Corporation) MD5=760A67A51D409EB396D1942D5555435C -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18538_none_c836992e6c9193ec\ntoskrnl.exe
[2010/06/08 14:00:36 | 004,697,992 | ---- | M] (Microsoft Corporation) MD5=825926D6AD714A529F4069D9EBBD1D3B -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18267_none_c9fb9b0869d1238c\ntoskrnl.exe
[2013/01/05 01:37:50 | 004,695,400 | ---- | M] (Microsoft Corporation) MD5=8A3AB79510C3384BF14D1731DD1ED963 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18765_none_c9f9a3f269d2e2a1\ntoskrnl.exe
[2009/08/12 02:51:49 | 004,427,232 | ---- | M] (Microsoft Corporation) MD5=8B3095B00E832ABFC7047A04E681CCDE -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16830_none_c64852866f7240ce\ntoskrnl.exe
[2010/02/18 11:05:21 | 004,424,072 | ---- | M] (Microsoft Corporation) MD5=8E3658ABC4A2053DBEA37C84E416DEB5 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.17021_none_c653fcc46f696e9d\ntoskrnl.exe
[2009/08/04 08:47:29 | 004,698,168 | ---- | M] (Microsoft Corporation) MD5=8E43DA6C8040C68446AA4B5D84C8127A -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18082_none_c9e0f5f269e5e26d\ntoskrnl.exe
[2009/12/08 16:22:09 | 004,698,184 | ---- | M] (Microsoft Corporation) MD5=9668520760E72E1B1B9EDFB7BFB6A691 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18160_none_c9f4971c69d77504\ntoskrnl.exe
[2012/03/06 02:44:22 | 004,699,520 | ---- | M] (Microsoft Corporation) MD5=98581CA6B029D491F60E32A045BC4FF1 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18595_none_c9d9306269eb3c26\ntoskrnl.exe
[2009/04/24 23:31:35 | 004,694,584 | ---- | M] (Microsoft Corporation) MD5=A1DC0EFF401FE35688F1046F10BEE5BF -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22167_none_c89ebc6d85c87c6f\ntoskrnl.exe
[2011/06/20 04:45:17 | 004,699,536 | ---- | M] (Microsoft Corporation) MD5=A26DE9288D67E4EAC2D1205043AFD430 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18484_none_c9e2fe1e69e409b7\ntoskrnl.exe
[2009/04/24 23:26:03 | 004,692,232 | ---- | M] (Microsoft Corporation) MD5=A541C4EB6704F0276882631A87A3F22F -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22291_none_c8784cd385e6355f\ntoskrnl.exe
[2009/07/22 15:55:02 | 004,698,696 | ---- | M] (Microsoft Corporation) MD5=AC1AE1A7F7771A64FD4ACDC5D08334A6 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.18075_none_c9eec6bc69db1281\ntoskrnl.exe
[2010/02/18 10:22:01 | 004,690,304 | ---- | M] (Microsoft Corporation) MD5=AE0C10C55347383C0CD6CFF3F4794FD7 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22341_none_ca94d5ef82e3f36a\ntoskrnl.exe
[2010/02/18 11:10:08 | 004,411,272 | ---- | M] (Microsoft Corporation) MD5=AF706D838B59A6C30D8B46C5C2D9D2FD -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21226_none_c6e29ce788828a41\ntoskrnl.exe
[2013/01/22 09:12:35 | 004,681,592 | ---- | M] (Microsoft Corporation) MD5=B1266A731C2326EBE8E01F46F18728AC -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.23025_none_caae5a7582d04310\ntoskrnl.exe
[2012/03/06 02:44:22 | 004,687,744 | ---- | M] (Microsoft Corporation) MD5=B448C24F801DC79661E30DBC8E739DB2 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22811_none_cab54f3182cb915a\ntoskrnl.exe
[2012/04/03 04:22:16 | 004,687,232 | ---- | M] (Microsoft Corporation) MD5=B59E026F49BF06B435795F867AD46009 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22831_none_ca9faf5982dbc93c\ntoskrnl.exe
[2010/02/18 11:04:01 | 004,678,032 | ---- | M] (Microsoft Corporation) MD5=C0EC74895F90E5E788061C7F305F57D1 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22636_none_c8be356585b10108\ntoskrnl.exe
[2009/08/05 11:07:10 | 004,425,288 | ---- | M] (Microsoft Corporation) MD5=C53B06CB817845873A3D32C1BAD33727 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16901_none_c669c47a6f590379\ntoskrnl.exe
[2009/12/08 16:05:33 | 004,691,528 | ---- | M] (Microsoft Corporation) MD5=CBA7366E93C4DCAA62005A177EEC2FCE -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22283_none_ca6b94ed830298b5\ntoskrnl.exe
[2009/08/12 02:51:49 | 004,413,936 | ---- | M] (Microsoft Corporation) MD5=CC172711FF2FCE0673321A951B02C379 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.21023_none_c6df983d888543ee\ntoskrnl.exe
[2010/06/08 13:47:14 | 004,690,832 | ---- | M] (Microsoft Corporation) MD5=CCCD9EE56C92778385A3E715DC3D5ABF -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18488_none_c80087ac6cba227a\ntoskrnl.exe
[2011/06/20 04:45:17 | 004,688,784 | ---- | M] (Microsoft Corporation) MD5=D14B8C4AB6C05B89D430D3911FE2833B -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22662_none_ca803c1382f33c18\ntoskrnl.exe
[2009/04/24 23:27:40 | 004,692,232 | ---- | M] (Microsoft Corporation) MD5=D626D71E63BC5F22DBA5050C5A2A4E6D -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22318_none_c8d5d01f859f045f\ntoskrnl.exe
[2009/07/23 15:54:41 | 004,693,560 | ---- | M] (Microsoft Corporation) MD5=D8BB403D63BA0A113E9A4F8E3BF81F8B -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6002.22183_none_ca6b930783029b8e\ntoskrnl.exe
[2009/12/08 16:59:29 | 004,691,032 | ---- | M] (Microsoft Corporation) MD5=E50C900C7F479886F26FA60ADBEE5852 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18377_none_c80a55686cb2f00b\ntoskrnl.exe
[2009/08/12 02:51:47 | 004,692,448 | ---- | M] (Microsoft Corporation) MD5=ED97E8551F0B1844250ED1B07393B10D -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.18226_none_c83f62d46c8b4dd8\ntoskrnl.exe
[2009/04/24 23:32:04 | 004,416,056 | ---- | M] (Microsoft Corporation) MD5=EFAAC7A874B65DF3F26B5092291D4859 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20921_none_c6ddbf878886ddfe\ntoskrnl.exe
[2009/07/23 15:48:10 | 004,682,840 | ---- | M] (Microsoft Corporation) MD5=FDA61279138FDC0CEF095F80EC3CB828 -- C:\Windows\winsxs\amd64_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6001.22478_none_c894f27d85cfa92c\ntoskrnl.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:5D432CE3

< End of report >
  • 0

#52
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
GMER shows a suspicious modification on the ntoskrnl.exe file, but my research finds no problems with it. I will attempt to contact the developer and see if he can explain this results.

In the MBR, however, it shows a rootkit behavior. Lets deal with that. We will need to do this in the Recovery Console.

Please download the latest Farbar Recovery Scan Tool and save it to a flash drive.

Also download the enclosed file and save it next to FRST64, overwriting the existing one:

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

Plug the flash drive into the infected PC.
  • If you are using Windows 8 consult How to use the Windows 8 System Recovery Environment Command Prompt to enter System Recovery Command prompt.

    If you are using Vista or Windows 7 enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.
  • Note: In case you can not enter System Recovery Options by using F8 method, you can use Windows installation disc, or make a repair disc. Any Windows installation disc or a repair disc made on another computer can be used.
    To make a repair disk on Windows 7 consult: http://www.sevenforu...isc-create.html



    To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select US as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.
  • On the System Recovery Options menu you will get the following options:
  • Startup Repair
  • System Restore
  • Windows Complete PC Restore
  • Windows Memory Diagnostic Tool
  • Command Prompt
  • Select Command Prompt

    Once in the Command Prompt:
  • In the command window type in notepad and press Enter.
  • The notepad opens. Under File menu select Open.
  • Select "Computer" and find your flash drive letter and close the notepad.
  • In the command window type e:\frst (for x64 bit version type e:\frst64) and press Enter
    Note: Replace letter e with the drive letter of your flash drive.
  • The tool will start to run.
  • When the tool opens click Yes to disclaimer.
  • Press Fix button.
  • It will make a log (Fixlog.txt) on the flash drive. Please copy and paste it to your reply.

Boot in Normal Mode. Let me know if there has been an improvement.
  • 0

#53
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts
Malwarebytes is still blocking the malware from playing. Fixlog:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-06-2013
Ran by SYSTEM at 2013-06-12 18:32:18 Run:6
Running from F:\
Boot Mode: Recovery
==============================================


========= bootrec /FixMbr =========

ÿ₫T h e o p e r a t i o n c o m p l e t e d s u c c e s s f u l l y .

========= End of CMD: =========


========= bcdedit /set {default} winpe no =========

The operation completed successfully.

========= End of CMD: =========


=========== Control: ===========

The operation completed successfully.

==== End of Control: ====

==== End of Fixlog ====
  • 0

#54
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Run GMER once again to confirm.
  • 0

#55
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts

Run GMER once again to confirm.



GMER 2.1.19163 - http://www.gmer.net
Rootkit scan 2013-06-13 16:18:06
Windows 6.0.6002 Service Pack 2 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST3750528AS rev.CC44 698.64GB
Running: zu0omelh.exe; Driver: C:\Users\dianne\AppData\Local\Temp\pwdirpog.sys


---- User code sections - GMER 2.1 ----

.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\WININET.dll!HttpSendRequestW 0000000076ffd1e8 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\WININET.dll!HttpSendRequestA 0000000077079dd0 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefe076510 9 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\ole32.dll!CoCreateInstance + 11 000007fefe07651b 3 bytes [00, 00, 00]
.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\ole32.dll!CoGetClassObject 000007fefe079d94 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\WS2_32.dll!GetAddrInfoW + 1 000007fefe002ba1 13 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\winmm.dll!waveOutOpen 000007fefbb63170 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Windows\system32\svchost.exe[12] C:\Windows\system32\dsound.dll!DirectSoundCreate 000007fefcf71ed8 14 bytes {JMP QWORD [RIP+0x0]}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationThread + 5 0000000077489475 7 bytes {MOV EDX, 0x1c5628; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadToken + 5 000000007748969d 7 bytes {MOV EDX, 0x1c5668; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcess + 5 00000000774896cd 7 bytes {MOV EDX, 0x1c55a8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtSetInformationFile + 5 00000000774896e5 7 bytes {MOV EDX, 0x1c5528; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtMapViewOfSection + 5 00000000774896fd 7 bytes {MOV EDX, 0x1c5728; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection + 5 000000007748972d 7 bytes {MOV EDX, 0x1c5768; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtOpenThreadTokenEx + 5 00000000774897a5 7 bytes {MOV EDX, 0x1c56e8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessTokenEx + 5 00000000774897bd 7 bytes {MOV EDX, 0x1c56a8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 5 0000000077489805 7 bytes {MOV EDX, 0x1c5468; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtQueryAttributesFile + 5 00000000774898f5 7 bytes {MOV EDX, 0x1c54a8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 5 0000000077489b35 7 bytes {MOV EDX, 0x1c5428; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtOpenProcessToken + 5 000000007748aa45 7 bytes {MOV EDX, 0x1c55e8; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtOpenThread + 5 000000007748aabd 7 bytes {MOV EDX, 0x1c5568; JMP RDX}
.text C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe[3084] C:\Windows\SysWOW64\ntdll.dll!NtQueryFullAttributesFile + 5 000000007748acb5 7 bytes {MOV EDX, 0x1c54e8; JMP RDX}

---- Devices - GMER 2.1 ----

Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-0 fffffa800693d0a8

---- Kernel code sections - GMER 2.1 ----

INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification
INITKDBG C:\Windows\system32\ntoskrnl.exe suspicious modification

---- Trace I/O - GMER 2.1 ----

Trace ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys >>UNKNOWN [0xfffffa800693d0a8]<< hal.dll fffffa800693d0a8
Trace 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004db2790] fffffa8004db2790
Trace 3 CLASSPNP.SYS[fffffa6000b9dc33] -> nt!IofCallDriver -> [0xfffffa8004940520] fffffa8004940520
Trace 5 acpi.sys[fffffa60008eafde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800493c940] fffffa800493c940
Trace \Driver\atapi[0xfffffa800678f300] -> IRP_MJ_CREATE -> 0xfffffa800693d0a8 fffffa800693d0a8

---- Threads - GMER 2.1 ----

Thread C:\Windows\system32\SearchIndexer.exe [2708:852] 000007fef73d39f0

---- Registry - GMER 2.1 ----

Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore@Flags 4
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore\AllowedDomains
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{76D50904-6780-4c8b-8986-1A7EE0B1716D}\iexplore\AllowedDomains\roblox.com

---- Disk sectors - GMER 2.1 ----

Disk \Device\Harddisk0\DR0 Windows VISTA default MBR code found via API
Disk \Device\Harddisk0\DR0 unknown MBR code
Disk \Device\Harddisk0\DR0 sector 0: rootkit-like behavior

---- EOF - GMER 2.1 ----
  • 0

Advertisements


#56
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts
Do you think tdsskiller can get rid of it? I've never used it before, no experience using it.
  • 0

#57
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Lets try that:

Please download the latest version of TDSSKiller from here and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
    Posted Image
  • Put a checkmark beside loaded modules.
    Posted Image
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
    Posted Image
  • Click the Start Scan button.
    Posted Image
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
    Posted Image
  • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
    Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Posted Image
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

  • 0

#58
JSntgRvr

JSntgRvr

    Global Moderator

  • Global Moderator
  • 11,579 posts
Also download aswMBR.exe ( 511KB ) to your desktop. If you already have this application, this is a new version I need you to download.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image

The tool will also produce a copy of the mbrdump labeled MBR.dat. Please upload that file here.
  • 0

#59
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts
There are 3 TDSS Killer logs, I will post all of them:

21:32:10.0955 6168 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:32:11.0782 6168 ============================================================
21:32:11.0782 6168 Current date / time: 2013/06/13 21:32:11.0782
21:32:11.0782 6168 SystemInfo:
21:32:11.0782 6168
21:32:11.0782 6168 OS Version: 6.0.6002 ServicePack: 2.0
21:32:11.0782 6168 Product type: Workstation
21:32:11.0782 6168 ComputerName: DIANNE-PC
21:32:11.0782 6168 UserName: dianne
21:32:11.0782 6168 Windows directory: C:\Windows
21:32:11.0782 6168 System windows directory: C:\Windows
21:32:11.0782 6168 Running under WOW64
21:32:11.0782 6168 Processor architecture: Intel x64
21:32:11.0782 6168 Number of processors: 4
21:32:11.0782 6168 Page size: 0x1000
21:32:11.0782 6168 Boot type: Normal boot
21:32:11.0782 6168 ============================================================
21:32:13.0248 6168 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:32:13.0279 6168 ============================================================
21:32:13.0279 6168 \Device\Harddisk0\DR0:
21:32:13.0279 6168 MBR partitions:
21:32:13.0279 6168 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B800, BlocksNum 0x1E00000
21:32:13.0279 6168 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1E1B800, BlocksNum 0x5572A000
21:32:13.0279 6168 ============================================================
21:32:13.0435 6168 C: <-> \Device\Harddisk0\DR0\Partition2
21:32:13.0467 6168 D: <-> \Device\Harddisk0\DR0\Partition1
21:32:13.0467 6168 ============================================================
21:32:13.0467 6168 Initialize success
21:32:13.0467 6168 ============================================================
21:33:34.0349 6452 Deinitialize success


2nd:

21:36:39.0448 3532 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:36:40.0306 3532 ============================================================
21:36:40.0306 3532 Current date / time: 2013/06/13 21:36:40.0306
21:36:40.0306 3532 SystemInfo:
21:36:40.0306 3532
21:36:40.0306 3532 OS Version: 6.0.6002 ServicePack: 2.0
21:36:40.0306 3532 Product type: Workstation
21:36:40.0306 3532 ComputerName: DIANNE-PC
21:36:40.0306 3532 UserName: dianne
21:36:40.0306 3532 Windows directory: C:\Windows
21:36:40.0306 3532 System windows directory: C:\Windows
21:36:40.0306 3532 Running under WOW64
21:36:40.0306 3532 Processor architecture: Intel x64
21:36:40.0306 3532 Number of processors: 4
21:36:40.0306 3532 Page size: 0x1000
21:36:40.0306 3532 Boot type: Normal boot
21:36:40.0306 3532 ============================================================
21:36:50.0597 3532 BG loaded
21:36:51.0440 3532 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:36:51.0459 3532 ============================================================
21:36:51.0459 3532 \Device\Harddisk0\DR0:
21:36:51.0461 3532 MBR partitions:
21:36:51.0461 3532 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B800, BlocksNum 0x1E00000
21:36:51.0461 3532 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1E1B800, BlocksNum 0x5572A000
21:36:51.0461 3532 ============================================================
21:36:51.0683 3532 C: <-> \Device\Harddisk0\DR0\Partition2
21:36:51.0712 3532 D: <-> \Device\Harddisk0\DR0\Partition1
21:36:51.0712 3532 ============================================================
21:36:51.0712 3532 Initialize success
21:36:51.0712 3532 ============================================================
21:38:31.0482 1936 ============================================================
21:38:31.0482 1936 Scan started
21:38:31.0482 1936 Mode: Manual; SigCheck; TDLFS;
21:38:31.0482 1936 ============================================================
21:38:32.0948 1936 ================ Scan system memory ========================
21:38:32.0948 1936 System memory - ok
21:38:32.0948 1936 ================ Scan services =============================
21:38:33.0057 1936 [ 581D88B25C4D4121824FED2CA38E562F ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
21:38:33.0213 1936 !SASCORE ( UnsignedFile.Multi.Generic ) - warning
21:38:33.0213 1936 !SASCORE - detected UnsignedFile.Multi.Generic (1)
21:38:33.0369 1936 [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI C:\Windows\system32\drivers\acpi.sys
21:38:33.0385 1936 ACPI - ok
21:38:33.0510 1936 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
21:38:33.0541 1936 AdobeFlashPlayerUpdateSvc - ok
21:38:33.0588 1936 [ F14215E37CF124104575073F782111D2 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
21:38:33.0650 1936 adp94xx - ok
21:38:33.0681 1936 [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci C:\Windows\system32\drivers\adpahci.sys
21:38:33.0697 1936 adpahci - ok
21:38:33.0728 1936 [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m C:\Windows\system32\drivers\adpu160m.sys
21:38:33.0759 1936 adpu160m - ok
21:38:33.0900 1936 [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
21:38:33.0931 1936 adpu320 - ok
21:38:33.0993 1936 [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
21:38:34.0290 1936 AeLookupSvc - ok
21:38:34.0305 1936 [ 0D7A11395C0A33D9E7587CDB9866EFAD ] AERTFilters C:\Windows\system32\AERTSr64.exe
21:38:34.0352 1936 AERTFilters - ok
21:38:34.0399 1936 [ C4F6CE6087760AD70960C9EB130E7943 ] AFD C:\Windows\system32\drivers\afd.sys
21:38:34.0461 1936 AFD - ok
21:38:34.0477 1936 [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440 C:\Windows\system32\drivers\agp440.sys
21:38:34.0492 1936 agp440 - ok
21:38:34.0508 1936 [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx C:\Windows\system32\drivers\djsvs.sys
21:38:34.0524 1936 aic78xx - ok
21:38:34.0539 1936 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG C:\Windows\System32\alg.exe
21:38:34.0664 1936 ALG - ok
21:38:34.0695 1936 [ 9544C2C55541C0C6BFD7B489D0E7D430 ] aliide C:\Windows\system32\drivers\aliide.sys
21:38:34.0711 1936 aliide - ok
21:38:34.0742 1936 [ 970FA5059E61E30D25307B99903E991E ] amdide C:\Windows\system32\drivers\amdide.sys
21:38:34.0742 1936 amdide - ok
21:38:34.0773 1936 [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys
21:38:35.0179 1936 AmdK8 - ok
21:38:35.0740 1936 [ EA504A3E708A37CDA81D214D09B8A62F ] Apache2.2 C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe
21:38:35.0772 1936 Apache2.2 ( UnsignedFile.Multi.Generic ) - warning
21:38:35.0772 1936 Apache2.2 - detected UnsignedFile.Multi.Generic (1)
21:38:35.0803 1936 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo C:\Windows\System32\appinfo.dll
21:38:35.0834 1936 Appinfo - ok
21:38:35.0865 1936 [ BA8417D4765F3988FF921F30F630E303 ] arc C:\Windows\system32\drivers\arc.sys
21:38:35.0881 1936 arc - ok
21:38:35.0896 1936 [ 9D41C435619733B34CC16A511E644B11 ] arcsas C:\Windows\system32\drivers\arcsas.sys
21:38:35.0912 1936 arcsas - ok
21:38:36.0021 1936 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
21:38:36.0068 1936 aspnet_state - ok
21:38:36.0084 1936 [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
21:38:36.0146 1936 AsyncMac - ok
21:38:36.0162 1936 [ E68D9B3A3905619732F7FE039466A623 ] atapi C:\Windows\system32\drivers\atapi.sys
21:38:36.0177 1936 atapi - ok
21:38:36.0224 1936 [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
21:38:36.0271 1936 AudioEndpointBuilder - ok
21:38:36.0271 1936 [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv C:\Windows\System32\Audiosrv.dll
21:38:36.0318 1936 AudioSrv - ok
21:38:36.0349 1936 [ 3B5657B6C11CDA87F664DD6F7DD0702D ] avgtp C:\Windows\system32\drivers\avgtpx64.sys
21:38:36.0380 1936 avgtp - ok
21:38:36.0396 1936 Beep - ok
21:38:36.0427 1936 [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE C:\Windows\System32\bfe.dll
21:38:36.0474 1936 BFE - ok
21:38:36.0505 1936 [ 6D316F4859634071CC25C4FD4589AD2C ] BITS C:\Windows\system32\qmgr.dll
21:38:36.0583 1936 BITS - ok
21:38:36.0614 1936 [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys
21:38:36.0645 1936 blbdrive - ok
21:38:36.0676 1936 [ 2348447A80920B2493A9B582A23E81E1 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
21:38:36.0708 1936 bowser - ok
21:38:36.0723 1936 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys
21:38:36.0786 1936 BrFiltLo - ok
21:38:36.0801 1936 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys
21:38:36.0832 1936 BrFiltUp - ok
21:38:36.0848 1936 [ A1B39DE453433B115B4EA69EE0343816 ] Browser C:\Windows\System32\browser.dll
21:38:36.0895 1936 Browser - ok
21:38:36.0910 1936 [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid C:\Windows\system32\drivers\brserid.sys
21:38:37.0160 1936 Brserid - ok
21:38:37.0191 1936 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys
21:38:37.0254 1936 BrSerWdm - ok
21:38:37.0269 1936 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys
21:38:37.0347 1936 BrUsbMdm - ok
21:38:37.0410 1936 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys
21:38:37.0472 1936 BrUsbSer - ok
21:38:37.0488 1936 [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys
21:38:37.0566 1936 BTHMODEM - ok
21:38:37.0581 1936 catchme - ok
21:38:37.0597 1936 ccxwbksp - ok
21:38:37.0628 1936 [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
21:38:37.0675 1936 cdfs - ok
21:38:37.0706 1936 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
21:38:37.0722 1936 cdrom - ok
21:38:37.0753 1936 [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc C:\Windows\System32\certprop.dll
21:38:37.0800 1936 CertPropSvc - ok
21:38:37.0800 1936 [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass C:\Windows\system32\drivers\circlass.sys
21:38:37.0862 1936 circlass - ok
21:38:37.0893 1936 [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS C:\Windows\system32\CLFS.sys
21:38:37.0924 1936 CLFS - ok
21:38:38.0018 1936 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
21:38:38.0034 1936 clr_optimization_v2.0.50727_32 - ok
21:38:38.0080 1936 [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
21:38:38.0096 1936 clr_optimization_v2.0.50727_64 - ok
21:38:38.0143 1936 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:38:38.0221 1936 clr_optimization_v4.0.30319_32 - ok
21:38:38.0236 1936 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:38:38.0268 1936 clr_optimization_v4.0.30319_64 - ok
21:38:38.0299 1936 [ E5D5499A1C50A54B5161296B6AFE6192 ] cmdide C:\Windows\system32\drivers\cmdide.sys
21:38:38.0299 1936 cmdide - ok
21:38:38.0330 1936 [ 34A6AA82AA36C87FC8816F2097EFA345 ] Compbatt C:\Windows\system32\drivers\compbatt.sys
21:38:38.0346 1936 Compbatt - ok
21:38:38.0361 1936 COMSysApp - ok
21:38:38.0361 1936 [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys
21:38:38.0377 1936 crcdisk - ok
21:38:38.0408 1936 [ 1B22BC0B71F65001479DAB792C3F626C ] CryptSvc C:\Windows\system32\cryptsvc.dll
21:38:38.0455 1936 CryptSvc - ok
21:38:38.0502 1936 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch C:\Windows\system32\rpcss.dll
21:38:38.0564 1936 DcomLaunch - ok
21:38:38.0611 1936 [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
21:38:38.0642 1936 DfsC - ok
21:38:39.0001 1936 [ C647F468F7DE343DF8C143655C5557D4 ] DFSR C:\Windows\system32\DFSR.exe
21:38:39.0297 1936 DFSR - ok
21:38:39.0391 1936 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp C:\Windows\System32\dhcpcsvc.dll
21:38:39.0890 1936 Dhcp - ok
21:38:39.0907 1936 [ B0107E40ECDB5FA692EBF832F295D905 ] disk C:\Windows\system32\drivers\disk.sys
21:38:39.0923 1936 disk - ok
21:38:40.0117 1936 [ 1E53C9D46995487DAE3FA9F4236DCEF1 ] dldtCATSCustConnectService C:\Windows\system32\spool\DRIVERS\x64\3\\dldtserv.exe
21:38:40.0158 1936 dldtCATSCustConnectService - ok
21:38:40.0162 1936 dldt_device - ok
21:38:40.0204 1936 [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache C:\Windows\System32\dnsrslvr.dll
21:38:40.0272 1936 Dnscache - ok
21:38:40.0340 1936 [ 0840ABBBDF438691EE65A20040635CBE ] DockLoginService C:\Program Files\Dell\DellDock\DockLogin.exe
21:38:40.0372 1936 DockLoginService ( UnsignedFile.Multi.Generic ) - warning
21:38:40.0372 1936 DockLoginService - detected UnsignedFile.Multi.Generic (1)
21:38:40.0444 1936 [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc C:\Windows\System32\dot3svc.dll
21:38:40.0498 1936 dot3svc - ok
21:38:40.0521 1936 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS C:\Windows\system32\dps.dll
21:38:40.0599 1936 DPS - ok
21:38:40.0630 1936 [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
21:38:40.0724 1936 drmkaud - ok
21:38:41.0488 1936 [ 0BB913F9F02677BD4AE96D4967CACFEE ] dsl-db C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe
21:38:42.0003 1936 dsl-db ( UnsignedFile.Multi.Generic ) - warning
21:38:42.0003 1936 dsl-db - detected UnsignedFile.Multi.Generic (1)
21:38:42.0066 1936 [ E9949205D0B0DBAF153FA968ADDA9EFA ] dsl-fs-sync C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe
21:38:42.0081 1936 dsl-fs-sync - ok
21:38:42.0112 1936 [ F3932288EEECD776FF1F9F653AD878F3 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
21:38:42.0144 1936 DXGKrnl - ok
21:38:42.0190 1936 [ 17D40652EF3E55EEAE187A89DF40965A ] e1express C:\Windows\system32\DRIVERS\e1e6032e.sys
21:38:42.0253 1936 e1express - ok
21:38:42.0268 1936 [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60 C:\Windows\system32\DRIVERS\E1G6032E.sys
21:38:42.0315 1936 E1G60 - ok
21:38:42.0346 1936 [ C2303883FD9BE49DC36A6400643002EA ] EapHost C:\Windows\System32\eapsvc.dll
21:38:42.0378 1936 EapHost - ok
21:38:42.0409 1936 [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache C:\Windows\system32\drivers\ecache.sys
21:38:42.0424 1936 Ecache - ok
21:38:42.0487 1936 [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr C:\Windows\ehome\ehRecvr.exe
21:38:42.0518 1936 ehRecvr - ok
21:38:42.0565 1936 [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched C:\Windows\ehome\ehsched.exe
21:38:42.0580 1936 ehSched - ok
21:38:42.0612 1936 [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart C:\Windows\ehome\ehstart.dll
21:38:42.0643 1936 ehstart - ok
21:38:42.0674 1936 [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor C:\Windows\system32\drivers\elxstor.sys
21:38:42.0690 1936 elxstor - ok
21:38:42.0721 1936 [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt C:\Windows\system32\emdmgmt.dll
21:38:42.0752 1936 EMDMgmt - ok
21:38:42.0768 1936 [ 991FAB6AA066E1214EFB5B496FB7959A ] ErrDev C:\Windows\system32\drivers\errdev.sys
21:38:42.0814 1936 ErrDev - ok
21:38:42.0861 1936 [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem C:\Windows\system32\es.dll
21:38:42.0908 1936 EventSystem - ok
21:38:42.0924 1936 [ 486844F47B6636044A42454614ED4523 ] exfat C:\Windows\system32\drivers\exfat.sys
21:38:42.0955 1936 exfat - ok
21:38:42.0986 1936 [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat C:\Windows\system32\drivers\fastfat.sys
21:38:43.0033 1936 fastfat - ok
21:38:43.0064 1936 [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
21:38:43.0111 1936 fdc - ok
21:38:43.0142 1936 [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost C:\Windows\system32\fdPHost.dll
21:38:43.0220 1936 fdPHost - ok
21:38:43.0267 1936 [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub C:\Windows\system32\fdrespub.dll
21:38:43.0314 1936 FDResPub - ok
21:38:43.0329 1936 [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
21:38:43.0345 1936 FileInfo - ok
21:38:43.0360 1936 [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace C:\Windows\system32\drivers\filetrace.sys
21:38:43.0423 1936 Filetrace - ok
21:38:43.0454 1936 [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
21:38:43.0501 1936 flpydisk - ok
21:38:43.0516 1936 [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
21:38:43.0548 1936 FltMgr - ok
21:38:43.0626 1936 [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] FontCache C:\Windows\system32\FntCache.dll
21:38:43.0672 1936 FontCache - ok
21:38:43.0766 1936 [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
21:38:43.0782 1936 FontCache3.0.0.0 - ok
21:38:43.0875 1936 [ 6C06701BF1DB05405804D7EB610991CE ] fssfltr C:\Windows\system32\DRIVERS\fssfltr.sys
21:38:43.0891 1936 fssfltr - ok
21:38:44.0156 1936 [ 40CDFAD174B3D5E80F95DDA003C0B97F ] fsssvc C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe
21:38:44.0218 1936 fsssvc - ok
21:38:44.0250 1936 [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
21:38:44.0281 1936 Fs_Rec - ok
21:38:44.0312 1936 [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
21:38:44.0328 1936 gagp30kx - ok
21:38:44.0404 1936 [ 37331304E89A773B1A86FE681FCA150D ] GameConsoleService C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe
21:38:44.0419 1936 GameConsoleService - ok
21:38:44.0465 1936 [ D3316F6E3C011435F36E3D6E49B3196C ] GoToAssist C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe
21:38:44.0489 1936 GoToAssist - ok
21:38:44.0527 1936 [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc C:\Windows\System32\gpsvc.dll
21:38:44.0564 1936 gpsvc - ok
21:38:44.0632 1936 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:38:44.0643 1936 gupdate - ok
21:38:44.0650 1936 [ 8F0DE4FEF8201E306F9938B0905AC96A ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:38:44.0661 1936 gupdatem - ok
21:38:44.0708 1936 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
21:38:44.0723 1936 gusvc - ok
21:38:44.0752 1936 [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
21:38:44.0843 1936 HDAudBus - ok
21:38:44.0862 1936 [ B4881C84A180E75B8C25DC1D726C375F ] HidBth C:\Windows\system32\drivers\hidbth.sys
21:38:44.0926 1936 HidBth - ok
21:38:44.0940 1936 [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr C:\Windows\system32\drivers\hidir.sys
21:38:45.0015 1936 HidIr - ok
21:38:45.0048 1936 [ 59361D38A297755D46A540E450202B2A ] hidserv C:\Windows\System32\hidserv.dll
21:38:45.0108 1936 hidserv - ok
21:38:45.0126 1936 [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
21:38:45.0165 1936 HidUsb - ok
21:38:45.0179 1936 [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc C:\Windows\system32\kmsvc.dll
21:38:45.0223 1936 hkmsvc - ok
21:38:45.0297 1936 [ 853BABC289F2B46F8150DF0E0CF0B537 ] hnmsvc c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
21:38:45.0327 1936 hnmsvc - ok
21:38:45.0339 1936 [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys
21:38:45.0353 1936 HpCISSs - ok
21:38:45.0392 1936 [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP C:\Windows\system32\drivers\HTTP.sys
21:38:45.0428 1936 HTTP - ok
21:38:45.0441 1936 [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp C:\Windows\system32\drivers\i2omp.sys
21:38:45.0454 1936 i2omp - ok
21:38:45.0467 1936 [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
21:38:45.0512 1936 i8042prt - ok
21:38:45.0544 1936 [ 07FB761600EFF44AF02C35B8B57E5863 ] iaStor C:\Windows\system32\drivers\iastor.sys
21:38:45.0564 1936 iaStor - ok
21:38:45.0601 1936 [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV C:\Windows\system32\drivers\iastorv.sys
21:38:45.0619 1936 iaStorV - ok
21:38:45.0724 1936 [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
21:38:45.0771 1936 idsvc - ok
21:38:46.0146 1936 [ 677AA5991026A65ADA128C4B59CF2BAD ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys
21:38:46.0520 1936 igfx - ok
21:38:46.0536 1936 [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp C:\Windows\system32\drivers\iirsp.sys
21:38:46.0551 1936 iirsp - ok
21:38:46.0567 1936 [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT C:\Windows\System32\ikeext.dll
21:38:46.0614 1936 IKEEXT - ok
21:38:46.0660 1936 [ 0DD17D4B59D0EC40E3C86A505BB0B6DD ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
21:38:46.0707 1936 IntcAzAudAddService - ok
21:38:46.0738 1936 [ BE1CB000C655396C9DEF09AEE3EA2D67 ] IntcHdmiAddService C:\Windows\system32\drivers\IntcHdmi.sys
21:38:46.0770 1936 IntcHdmiAddService - ok
21:38:46.0785 1936 [ DF797A12176F11B2D301C5B234BB200E ] intelide C:\Windows\system32\DRIVERS\intelide.sys
21:38:46.0801 1936 intelide - ok
21:38:46.0801 1936 [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
21:38:46.0832 1936 intelppm - ok
21:38:46.0863 1936 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
21:38:46.0894 1936 IPBusEnum - ok
21:38:46.0926 1936 [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
21:38:46.0972 1936 IpFilterDriver - ok
21:38:47.0004 1936 [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
21:38:47.0050 1936 iphlpsvc - ok
21:38:47.0050 1936 IpInIp - ok
21:38:47.0082 1936 [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys
21:38:47.0128 1936 IPMIDRV - ok
21:38:47.0160 1936 [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys
21:38:47.0206 1936 IPNAT - ok
21:38:47.0238 1936 [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM C:\Windows\system32\drivers\irenum.sys
21:38:47.0284 1936 IRENUM - ok
21:38:47.0300 1936 [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp C:\Windows\system32\drivers\isapnp.sys
21:38:47.0316 1936 isapnp - ok
21:38:47.0331 1936 [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
21:38:47.0347 1936 iScsiPrt - ok
21:38:47.0378 1936 [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi C:\Windows\system32\drivers\iteatapi.sys
21:38:47.0394 1936 iteatapi - ok
21:38:47.0394 1936 [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid C:\Windows\system32\drivers\iteraid.sys
21:38:47.0409 1936 iteraid - ok
21:38:47.0440 1936 [ 423696F3BA6472DD17699209B933BC26 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
21:38:47.0456 1936 kbdclass - ok
21:38:47.0456 1936 [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
21:38:47.0487 1936 kbdhid - ok
21:38:47.0534 1936 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso C:\Windows\system32\lsass.exe
21:38:47.0565 1936 KeyIso - ok
21:38:47.0628 1936 [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
21:38:47.0643 1936 KSecDD - ok
21:38:47.0690 1936 [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
21:38:47.0737 1936 ksthunk - ok
21:38:47.0799 1936 [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm C:\Windows\system32\msdtckrm.dll
21:38:47.0862 1936 KtmRm - ok
21:38:47.0893 1936 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer C:\Windows\System32\srvsvc.dll
21:38:47.0940 1936 LanmanServer - ok
21:38:47.0955 1936 [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
21:38:47.0986 1936 LanmanWorkstation - ok
21:38:48.0002 1936 lierbluu - ok
21:38:48.0018 1936 [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
21:38:48.0064 1936 lltdio - ok
21:38:48.0080 1936 [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc C:\Windows\System32\lltdsvc.dll
21:38:48.0127 1936 lltdsvc - ok
21:38:48.0174 1936 [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts C:\Windows\System32\lmhsvc.dll
21:38:48.0205 1936 lmhosts - ok
21:38:48.0236 1936 [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys
21:38:48.0252 1936 LSI_FC - ok
21:38:48.0283 1936 [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
21:38:48.0283 1936 LSI_SAS - ok
21:38:48.0314 1936 [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
21:38:48.0330 1936 LSI_SCSI - ok
21:38:48.0345 1936 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv C:\Windows\system32\drivers\luafv.sys
21:38:48.0376 1936 luafv - ok
21:38:48.0392 1936 lvwxpala - ok
21:38:48.0423 1936 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
21:38:48.0439 1936 MBAMProtector - ok
21:38:48.0517 1936 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
21:38:48.0532 1936 MBAMScheduler - ok
21:38:48.0595 1936 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
21:38:48.0626 1936 MBAMService - ok
21:38:48.0657 1936 [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
21:38:48.0673 1936 Mcx2Svc - ok
21:38:48.0704 1936 [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas C:\Windows\system32\drivers\megasas.sys
21:38:48.0704 1936 megasas - ok
21:38:48.0735 1936 [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR C:\Windows\system32\drivers\megasr.sys
21:38:48.0766 1936 MegaSR - ok
21:38:48.0782 1936 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS C:\Windows\system32\mmcss.dll
21:38:48.0844 1936 MMCSS - ok
21:38:48.0891 1936 [ 59848D5CC74606F0EE7557983BB73C2E ] Modem C:\Windows\system32\drivers\modem.sys
21:38:48.0969 1936 Modem - ok
21:38:48.0969 1936 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
21:38:49.0016 1936 monitor - ok
21:38:49.0032 1936 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
21:38:49.0047 1936 mouclass - ok
21:38:49.0063 1936 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
21:38:49.0110 1936 mouhid - ok
21:38:49.0125 1936 [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr C:\Windows\system32\drivers\mountmgr.sys
21:38:49.0141 1936 MountMgr - ok
21:38:49.0172 1936 [ C177A7EBF5E8A0B596F618870516CAB8 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
21:38:49.0188 1936 MpFilter - ok
21:38:49.0203 1936 [ F8276EB8698142884498A528DFEA8478 ] mpio C:\Windows\system32\drivers\mpio.sys
21:38:49.0219 1936 mpio - ok
21:38:49.0234 1936 [ 8FBF6B31FE8AF1833D93C5913D5B4D55 ] MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys
21:38:49.0250 1936 MpNWMon - ok
21:38:49.0250 1936 [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
21:38:49.0297 1936 mpsdrv - ok
21:38:49.0329 1936 [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc C:\Windows\system32\mpssvc.dll
21:38:49.0372 1936 MpsSvc - ok
21:38:49.0389 1936 [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys
21:38:49.0417 1936 Mraid35x - ok
21:38:49.0439 1936 [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
21:38:49.0532 1936 MRxDAV - ok
21:38:49.0548 1936 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
21:38:49.0624 1936 mrxsmb - ok
21:38:49.0652 1936 [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
21:38:49.0689 1936 mrxsmb10 - ok
21:38:49.0734 1936 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
21:38:49.0781 1936 mrxsmb20 - ok
21:38:49.0830 1936 [ 730B784962D22D2C6481EAE2370E7C8C ] msahci C:\Windows\system32\drivers\msahci.sys
21:38:49.0843 1936 msahci - ok
21:38:49.0877 1936 [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm C:\Windows\system32\drivers\msdsm.sys
21:38:49.0911 1936 msdsm - ok
21:38:49.0938 1936 [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC C:\Windows\System32\msdtc.exe
21:38:50.0007 1936 MSDTC - ok
21:38:50.0023 1936 [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs C:\Windows\system32\drivers\Msfs.sys
21:38:50.0085 1936 Msfs - ok
21:38:50.0098 1936 [ 00EBC952961664780D43DCA157E79B27 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
21:38:50.0126 1936 msisadrv - ok
21:38:50.0147 1936 [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
21:38:50.0210 1936 MSiSCSI - ok
21:38:50.0215 1936 msiserver - ok
21:38:50.0230 1936 [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
21:38:50.0307 1936 MSKSSRV - ok
21:38:50.0365 1936 [ 157E9E498206A3366BAA7E4697BDD947 ] MsMpSvc c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
21:38:50.0378 1936 MsMpSvc - ok
21:38:50.0404 1936 [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
21:38:50.0465 1936 MSPCLOCK - ok
21:38:50.0510 1936 [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
21:38:50.0603 1936 MSPQM - ok
21:38:50.0634 1936 [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
21:38:50.0666 1936 MsRPC - ok
21:38:50.0697 1936 [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
21:38:50.0712 1936 mssmbios - ok
21:38:50.0728 1936 [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
21:38:50.0806 1936 MSTEE - ok
21:38:50.0822 1936 [ 0CC49F78D8ACA0877D885F149084E543 ] Mup C:\Windows\system32\Drivers\mup.sys
21:38:50.0837 1936 Mup - ok
21:38:50.0868 1936 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent C:\Windows\system32\qagentRT.dll
21:38:50.0915 1936 napagent - ok
21:38:50.0962 1936 [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
21:38:50.0978 1936 NativeWifiP - ok
21:38:51.0009 1936 [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS C:\Windows\system32\drivers\ndis.sys
21:38:51.0040 1936 NDIS - ok
21:38:51.0071 1936 [ 64DF698A425478E321981431AC171334 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
21:38:51.0102 1936 NdisTapi - ok
21:38:51.0134 1936 [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
21:38:51.0180 1936 Ndisuio - ok
21:38:51.0196 1936 [ F8158771905260982CE724076419EF19 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
21:38:51.0243 1936 NdisWan - ok
21:38:51.0258 1936 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
21:38:51.0305 1936 NDProxy - ok
21:38:51.0336 1936 [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
21:38:51.0383 1936 NetBIOS - ok
21:38:51.0461 1936 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt C:\Windows\system32\DRIVERS\netbt.sys
21:38:51.0492 1936 netbt - ok
21:38:51.0508 1936 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon C:\Windows\system32\lsass.exe
21:38:51.0524 1936 Netlogon - ok
21:38:51.0570 1936 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman C:\Windows\System32\netman.dll
21:38:51.0633 1936 Netman - ok
21:38:51.0664 1936 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:38:51.0695 1936 NetMsmqActivator - ok
21:38:51.0695 1936 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:38:51.0711 1936 NetPipeActivator - ok
21:38:51.0726 1936 [ 7846D0136CC2B264926A73047BA7688A ] netprofm C:\Windows\System32\netprofm.dll
21:38:51.0773 1936 netprofm - ok
21:38:51.0789 1936 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:38:51.0789 1936 NetTcpActivator - ok
21:38:51.0804 1936 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing c:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
21:38:51.0804 1936 NetTcpPortSharing - ok
21:38:51.0836 1936 [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
21:38:51.0851 1936 nfrd960 - ok
21:38:51.0867 1936 [ 5F7D72CBCDD025AF1F38FDEEE5646968 ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
21:38:51.0882 1936 NisDrv - ok
21:38:51.0898 1936 [ 566DDD5D82520DA01D75F81428AC4C38 ] NisSrv c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe
21:38:51.0929 1936 NisSrv - ok
21:38:51.0929 1936 [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc C:\Windows\System32\nlasvc.dll
21:38:51.0976 1936 NlaSvc - ok
21:38:51.0992 1936 [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs C:\Windows\system32\drivers\Npfs.sys
21:38:52.0038 1936 Npfs - ok
21:38:52.0070 1936 [ ACB62BAA1C319B17752553DF3026EEEB ] nsi C:\Windows\system32\nsisvc.dll
21:38:52.0116 1936 nsi - ok
21:38:52.0148 1936 [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
21:38:52.0210 1936 nsiproxy - ok
21:38:52.0335 1936 [ 2ACCAA3C3C55370A32F17B3595E1A217 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
21:38:52.0413 1936 Ntfs - ok
21:38:52.0444 1936 [ DD5D684975352B85B52E3FD5347C20CB ] Null C:\Windows\system32\drivers\Null.sys
21:38:52.0491 1936 Null - ok
21:38:52.0538 1936 [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid C:\Windows\system32\drivers\nvraid.sys
21:38:52.0569 1936 nvraid - ok
21:38:52.0569 1936 [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor C:\Windows\system32\drivers\nvstor.sys
21:38:52.0584 1936 nvstor - ok
21:38:52.0631 1936 [ 19067CA93075EF4823E3938A686F532F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
21:38:52.0662 1936 nv_agp - ok
21:38:52.0662 1936 NwlnkFlt - ok
21:38:52.0678 1936 NwlnkFwd - ok
21:38:52.0834 1936 [ 785F487A64950F3CB8E9F16253BA3B7B ] odserv C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
21:38:52.0881 1936 odserv - ok
21:38:52.0928 1936 [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
21:38:52.0943 1936 ohci1394 - ok
21:38:52.0974 1936 [ 5A432A042DAE460ABE7199B758E8606C ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
21:38:52.0990 1936 ose - ok
21:38:53.0021 1936 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc C:\Windows\system32\p2psvc.dll
21:38:53.0052 1936 p2pimsvc - ok
21:38:53.0099 1936 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc C:\Windows\system32\p2psvc.dll
21:38:53.0130 1936 p2psvc - ok
21:38:53.0162 1936 [ 43E24699A18126F11E3D9BF6DB85518B ] Packet C:\Windows\system32\DRIVERS\packet.sys
21:38:53.0193 1936 Packet - ok
21:38:53.0208 1936 [ AECD57F94C887F58919F307C35498EA0 ] Parport C:\Windows\system32\drivers\parport.sys
21:38:53.0255 1936 Parport - ok
21:38:53.0286 1936 [ B43751085E2ABE389DA466BC62A4B987 ] partmgr C:\Windows\system32\drivers\partmgr.sys
21:38:53.0302 1936 partmgr - ok
21:38:53.0318 1936 [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc C:\Windows\System32\pcasvc.dll
21:38:53.0349 1936 PcaSvc - ok
21:38:53.0364 1936 [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci C:\Windows\system32\drivers\pci.sys
21:38:53.0380 1936 pci - ok
21:38:53.0411 1936 [ 2657F6C0B78C36D95034BE109336E382 ] pciide C:\Windows\system32\drivers\pciide.sys
21:38:53.0427 1936 pciide - ok
21:38:53.0458 1936 [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
21:38:53.0474 1936 pcmcia - ok
21:38:53.0505 1936 [ C8F8521648697B284E39477DD2BA5ECD ] PDF Suite 2010 Service C:\Program Files (x86)\PDF Suite 2010\ConversionService.exe
21:38:53.0536 1936 PDF Suite 2010 Service - ok
21:38:53.0614 1936 [ 58865916F53592A61549B04941BFD80D ] PEAUTH C:\Windows\system32\drivers\peauth.sys
21:38:53.0708 1936 PEAUTH - ok
21:38:54.0113 1936 [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost C:\Windows\SysWow64\perfhost.exe
21:38:54.0176 1936 PerfHost - ok
21:38:54.0285 1936 [ E9158FA6923E80BD57CF068CE9CDDAA2 ] Ph3xIB64 C:\Windows\system32\DRIVERS\Ph3xIB64.sys
21:38:54.0347 1936 Ph3xIB64 - ok
21:38:54.0378 1936 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla C:\Windows\system32\pla.dll
21:38:54.0441 1936 pla - ok
21:38:54.0488 1936 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
21:38:54.0519 1936 PlugPlay - ok
21:38:54.0597 1936 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg C:\Windows\system32\p2psvc.dll
21:38:54.0628 1936 PNRPAutoReg - ok
21:38:54.0659 1936 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc C:\Windows\system32\p2psvc.dll
21:38:54.0675 1936 PNRPsvc - ok
21:38:54.0706 1936 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
21:38:54.0737 1936 PolicyAgent - ok
21:38:54.0768 1936 [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
21:38:54.0800 1936 PptpMiniport - ok
21:38:54.0815 1936 [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor C:\Windows\system32\drivers\processr.sys
21:38:54.0862 1936 Processor - ok
21:38:54.0878 1936 [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc C:\Windows\system32\profsvc.dll
21:38:54.0909 1936 ProfSvc - ok
21:38:54.0940 1936 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe
21:38:54.0956 1936 ProtectedStorage - ok
21:38:54.0987 1936 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched C:\Windows\system32\DRIVERS\pacer.sys
21:38:55.0018 1936 PSched - ok
21:38:55.0049 1936 [ 46851BC18322DA70F3F2299A1007C479 ] PxHlpa64 C:\Windows\system32\Drivers\PxHlpa64.sys
21:38:55.0065 1936 PxHlpa64 - ok
21:38:55.0065 1936 qfcyrvgz - ok
21:38:55.0112 1936 [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300 C:\Windows\system32\drivers\ql2300.sys
21:38:55.0158 1936 ql2300 - ok
21:38:55.0205 1936 [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx C:\Windows\system32\drivers\ql40xx.sys
21:38:55.0205 1936 ql40xx - ok
21:38:55.0236 1936 [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE C:\Windows\system32\qwave.dll
21:38:55.0268 1936 QWAVE - ok
21:38:55.0268 1936 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
21:38:55.0283 1936 QWAVEdrv - ok
21:38:55.0486 1936 [ 2A09A6B271D1F50ADF5E33B37D460DE6 ] R300 C:\Windows\system32\DRIVERS\atikmdag.sys
21:38:55.0658 1936 R300 - ok
21:38:55.0689 1936 [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
21:38:55.0751 1936 RasAcd - ok
21:38:55.0767 1936 [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto C:\Windows\System32\rasauto.dll
21:38:55.0814 1936 RasAuto - ok
21:38:55.0845 1936 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
21:38:55.0876 1936 Rasl2tp - ok
21:38:55.0892 1936 [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan C:\Windows\System32\rasmans.dll
21:38:55.0938 1936 RasMan - ok
21:38:55.0954 1936 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
21:38:56.0001 1936 RasPppoe - ok
21:38:56.0032 1936 [ C6A593B51F34C33E5474539544072527 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
21:38:56.0048 1936 RasSstp - ok
21:38:56.0079 1936 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
21:38:56.0110 1936 rdbss - ok
21:38:56.0126 1936 [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
21:38:56.0157 1936 RDPCDD - ok
21:38:56.0188 1936 [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys
21:38:56.0219 1936 rdpdr - ok
21:38:56.0235 1936 [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
21:38:56.0282 1936 RDPENCDD - ok
21:38:56.0297 1936 [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
21:38:56.0328 1936 RDPWD - ok
21:38:56.0360 1936 [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess C:\Windows\System32\mprdim.dll
21:38:56.0406 1936 RemoteAccess - ok
21:38:56.0438 1936 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry C:\Windows\system32\regsvc.dll
21:38:56.0484 1936 RemoteRegistry - ok
21:38:56.0500 1936 [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator C:\Windows\system32\locator.exe
21:38:56.0531 1936 RpcLocator - ok
21:38:56.0562 1936 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs C:\Windows\System32\rpcss.dll
21:38:56.0609 1936 RpcSs - ok
21:38:56.0640 1936 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
21:38:56.0703 1936 rspndr - ok
21:38:56.0750 1936 [ F49D8DF8895D809CB0A4DEB44113DE6F ] RTL8169 C:\Windows\system32\DRIVERS\Rtlh64.sys
21:38:56.0781 1936 RTL8169 - ok
21:38:56.0812 1936 [ 5532C4BF15173270757A75B46BAEB960 ] RtNdPt60 C:\Windows\system32\DRIVERS\RtNdPt60.sys
21:38:56.0859 1936 RtNdPt60 - ok
21:38:56.0874 1936 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs C:\Windows\system32\lsass.exe
21:38:56.0874 1936 SamSs - ok
21:38:56.0937 1936 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
21:38:56.0937 1936 SASDIFSV - ok
21:38:56.0952 1936 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
21:38:56.0968 1936 SASKUTIL - ok
21:38:56.0984 1936 [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
21:38:56.0999 1936 sbp2port - ok
21:38:57.0015 1936 [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr C:\Windows\System32\SCardSvr.dll
21:38:57.0046 1936 SCardSvr - ok
21:38:57.0077 1936 [ 0F838C811AD295D2A4489B9993096C63 ] Schedule C:\Windows\system32\schedsvc.dll
21:38:57.0108 1936 Schedule - ok
21:38:57.0124 1936 [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc C:\Windows\System32\certprop.dll
21:38:57.0155 1936 SCPolicySvc - ok
21:38:57.0186 1936 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC C:\Windows\System32\SDRSVC.dll
21:38:57.0218 1936 SDRSVC - ok
21:38:57.0249 1936 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
21:38:57.0311 1936 secdrv - ok
21:38:57.0342 1936 [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon C:\Windows\system32\seclogon.dll
21:38:57.0389 1936 seclogon - ok
21:38:57.0405 1936 [ 90973A64B96CD647FF81C79443618EED ] SENS C:\Windows\system32\sens.dll
21:38:57.0452 1936 SENS - ok
21:38:57.0483 1936 [ F71BFE7AC6C52273B7C82CBF1BB2A222 ] Serenum C:\Windows\system32\drivers\serenum.sys
21:38:57.0545 1936 Serenum - ok
21:38:57.0576 1936 [ E62FAC91EE288DB29A9696A9D279929C ] Serial C:\Windows\system32\drivers\serial.sys
21:38:57.0670 1936 Serial - ok
21:38:57.0686 1936 [ A842F04833684BCEEA7336211BE478DF ] sermouse C:\Windows\system32\drivers\sermouse.sys
21:38:57.0748 1936 sermouse - ok
21:38:57.0764 1936 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv C:\Windows\system32\sessenv.dll
21:38:57.0810 1936 SessionEnv - ok
21:38:57.0826 1936 [ 14D4B4465193A87C127933978E8C4106 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
21:38:57.0873 1936 sffdisk - ok
21:38:57.0888 1936 [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
21:38:57.0935 1936 sffp_mmc - ok
21:38:57.0951 1936 [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
21:38:57.0982 1936 sffp_sd - ok
21:38:57.0998 1936 [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy C:\Windows\system32\drivers\sfloppy.sys
21:38:58.0060 1936 sfloppy - ok
21:38:58.0107 1936 [ 4EF8FC5158AA1A01DF37FDB3FADDA077 ] SftService C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
21:38:58.0122 1936 SftService - ok
21:38:58.0169 1936 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess C:\Windows\System32\ipnathlp.dll
21:38:58.0200 1936 SharedAccess - ok
21:38:58.0372 1936 [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
21:38:58.0388 1936 ShellHWDetection - ok
21:38:58.0403 1936 [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys
21:38:58.0419 1936 SiSRaid2 - ok
21:38:58.0434 1936 [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
21:38:58.0450 1936 SiSRaid4 - ok
21:38:58.0590 1936 [ 3740B83AEC21D981065D7E819BD7E878 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
21:38:58.0700 1936 Skype C2C Service - ok
21:38:58.0746 1936 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
21:38:58.0762 1936 SkypeUpdate - ok
21:38:58.0949 1936 [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc C:\Windows\system32\SLsvc.exe
21:38:59.0012 1936 slsvc - ok
21:38:59.0074 1936 [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify C:\Windows\system32\SLUINotify.dll
21:38:59.0121 1936 SLUINotify - ok
21:38:59.0152 1936 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb C:\Windows\system32\DRIVERS\smb.sys
21:38:59.0183 1936 Smb - ok
21:38:59.0199 1936 smmilxmn - ok
21:38:59.0214 1936 [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP C:\Windows\System32\snmptrap.exe
21:38:59.0246 1936 SNMPTRAP - ok
21:38:59.0277 1936 [ 386C3C63F00A7040C7EC5E384217E89D ] spldr C:\Windows\system32\drivers\spldr.sys
21:38:59.0292 1936 spldr - ok
21:38:59.0308 1936 [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler C:\Windows\System32\spoolsv.exe
21:38:59.0355 1936 Spooler - ok
21:38:59.0433 1936 [ D630B6F2E8379B6F10DC16E82A426552 ] sprtsvc_DellSupportCenter C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
21:38:59.0448 1936 sprtsvc_DellSupportCenter - ok
21:38:59.0495 1936 [ 880A57FCCB571EBD063D4DD50E93E46D ] srv C:\Windows\system32\DRIVERS\srv.sys
21:38:59.0542 1936 srv - ok
21:38:59.0573 1936 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
21:38:59.0651 1936 srv2 - ok
21:38:59.0682 1936 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
21:38:59.0714 1936 srvnet - ok
21:38:59.0729 1936 [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
21:38:59.0792 1936 SSDPSRV - ok
21:38:59.0823 1936 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc C:\Windows\system32\sstpsvc.dll
21:38:59.0838 1936 SstpSvc - ok
21:38:59.0885 1936 [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc C:\Windows\System32\wiaservc.dll
21:38:59.0932 1936 stisvc - ok
21:38:59.0979 1936 [ 1D0063597C3666404FCF97698ABEB019 ] stllssvr C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
21:39:00.0010 1936 stllssvr - ok
21:39:00.0150 1936 [ 42FEF84684D217870F3C8813B6F58276 ] SupportSoft RemoteAssist C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe
21:39:00.0166 1936 SupportSoft RemoteAssist - ok
21:39:00.0197 1936 [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum C:\Windows\system32\DRIVERS\swenum.sys
21:39:00.0197 1936 swenum - ok
21:39:00.0244 1936 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv C:\Windows\System32\swprv.dll
21:39:00.0306 1936 swprv - ok
21:39:00.0322 1936 [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys
21:39:00.0369 1936 Symc8xx - ok
21:39:00.0384 1936 [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys
21:39:00.0416 1936 Sym_hi - ok
21:39:00.0447 1936 [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys
21:39:00.0447 1936 Sym_u3 - ok
21:39:00.0494 1936 [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain C:\Windows\system32\sysmain.dll
21:39:00.0540 1936 SysMain - ok
21:39:00.0556 1936 [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll
21:39:00.0587 1936 TabletInputService - ok
21:39:00.0665 1936 [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv C:\Windows\System32\tapisrv.dll
21:39:00.0712 1936 TapiSrv - ok
21:39:00.0728 1936 [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS C:\Windows\System32\tbssvc.dll
21:39:00.0774 1936 TBS - ok
21:39:00.0977 1936 [ 19A5E570048788BE9343FA96C15CEF6F ] Tcpip C:\Windows\system32\drivers\tcpip.sys
21:39:01.0024 1936 Tcpip - ok
21:39:01.0071 1936 [ 19A5E570048788BE9343FA96C15CEF6F ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys
21:39:01.0149 1936 Tcpip6 - ok
21:39:01.0164 1936 [ F6F46226D0104D997AF8B2ADFABE4B24 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
21:39:01.0211 1936 tcpipreg - ok
21:39:01.0242 1936 [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
21:39:01.0289 1936 TDPIPE - ok
21:39:01.0289 1936 [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
21:39:01.0352 1936 TDTCP - ok
21:39:01.0367 1936 [ 458919C8C42E398DC4802178D5FFEE27 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
21:39:01.0414 1936 tdx - ok
21:39:01.0445 1936 [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
21:39:01.0461 1936 TermDD - ok
21:39:01.0508 1936 [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService C:\Windows\System32\termsrv.dll
21:39:01.0539 1936 TermService - ok
21:39:01.0554 1936 [ 56793271ECDEDD350C5ADD305603E963 ] Themes C:\Windows\system32\shsvcs.dll
21:39:01.0570 1936 Themes - ok
21:39:01.0601 1936 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER C:\Windows\system32\mmcss.dll
21:39:01.0632 1936 THREADORDER - ok
21:39:01.0648 1936 tpzwnznc - ok
21:39:01.0648 1936 tqgruidu - ok
21:39:01.0710 1936 [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks C:\Windows\System32\trkwks.dll
21:39:01.0742 1936 TrkWks - ok
21:39:01.0788 1936 [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
21:39:01.0835 1936 TrustedInstaller - ok
21:39:01.0866 1936 [ 9E5409CD17C8BEF193AAD498F3BC2CB8 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
21:39:01.0929 1936 tssecsrv - ok
21:39:01.0944 1936 [ 89EC74A9E602D16A75A4170511029B3C ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys
21:39:01.0976 1936 tunmp - ok
21:39:02.0007 1936 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
21:39:02.0022 1936 tunnel - ok
21:39:02.0038 1936 [ FEC266EF401966311744BD0F359F7F56 ] uagp35 C:\Windows\system32\drivers\uagp35.sys
21:39:02.0054 1936 uagp35 - ok
21:39:02.0085 1936 [ FAF2640A2A76ED03D449E443194C4C34 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
21:39:02.0116 1936 udfs - ok
21:39:02.0116 1936 ufetxbtx - ok
21:39:02.0147 1936 [ 060507C4113391394478F6953A79EEDC ] UI0Detect C:\Windows\system32\UI0Detect.exe
21:39:02.0194 1936 UI0Detect - ok
21:39:02.0210 1936 [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
21:39:02.0225 1936 uliagpkx - ok
21:39:02.0241 1936 [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci C:\Windows\system32\drivers\uliahci.sys
21:39:02.0256 1936 uliahci - ok
21:39:02.0272 1936 [ 31707F09846056651EA2C37858F5DDB0 ] UlSata C:\Windows\system32\drivers\ulsata.sys
21:39:02.0288 1936 UlSata - ok
21:39:02.0303 1936 [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys
21:39:02.0319 1936 ulsata2 - ok
21:39:02.0334 1936 [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
21:39:02.0381 1936 umbus - ok
21:39:02.0397 1936 [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost C:\Windows\System32\upnphost.dll
21:39:02.0459 1936 upnphost - ok
21:39:02.0490 1936 [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
21:39:02.0553 1936 usbaudio - ok
21:39:02.0584 1936 [ 07E3498FC60834219D2356293DA0FECC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
21:39:02.0631 1936 usbccgp - ok
21:39:02.0678 1936 [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir C:\Windows\system32\drivers\usbcir.sys
21:39:02.0756 1936 usbcir - ok
21:39:02.0802 1936 [ 827E44DE934A736EA31E91D353EB126F ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
21:39:02.0849 1936 usbehci - ok
21:39:02.0896 1936 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
21:39:02.0943 1936 usbhub - ok
21:39:02.0958 1936 [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci C:\Windows\system32\drivers\usbohci.sys
21:39:03.0036 1936 usbohci - ok
21:39:03.0083 1936 [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
21:39:03.0130 1936 usbprint - ok
21:39:03.0161 1936 [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
21:39:03.0177 1936 usbscan - ok
21:39:03.0208 1936 [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
21:39:03.0224 1936 USBSTOR - ok
21:39:03.0255 1936 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
21:39:03.0286 1936 usbuhci - ok
21:39:03.0317 1936 [ FC33099877790D51B0927B7039059855 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
21:39:03.0395 1936 usbvideo - ok
21:39:03.0411 1936 [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms C:\Windows\System32\uxsms.dll
21:39:03.0442 1936 UxSms - ok
21:39:03.0473 1936 [ 294945381DFA7CE58CECF0A9896AF327 ] vds C:\Windows\System32\vds.exe
21:39:03.0504 1936 vds - ok
21:39:03.0536 1936 [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
21:39:03.0567 1936 vga - ok
21:39:03.0582 1936 [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave C:\Windows\System32\drivers\vga.sys
21:39:03.0614 1936 VgaSave - ok
21:39:03.0676 1936 [ 8294B6C3FDB6C33F24E150DE647ECDAA ] viaide C:\Windows\system32\drivers\viaide.sys
21:39:03.0692 1936 viaide - ok
21:39:03.0707 1936 [ 2B7E885ED951519A12C450D24535DFCA ] volmgr C:\Windows\system32\drivers\volmgr.sys
21:39:03.0723 1936 volmgr - ok
21:39:03.0754 1936 [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
21:39:03.0770 1936 volmgrx - ok
21:39:03.0801 1936 [ 582F710097B46140F5A89A19A6573D4B ] volsnap C:\Windows\system32\drivers\volsnap.sys
21:39:03.0816 1936 volsnap - ok
21:39:03.0832 1936 [ A68F455ED2673835209318DD61BFBB0E ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
21:39:03.0848 1936 vsmraid - ok
21:39:03.0894 1936 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS C:\Windows\system32\vssvc.exe
21:39:03.0957 1936 VSS - ok
21:39:04.0035 1936 [ 4B817450226F93C31ADD5BCC27FED27A ] vToolbarUpdater15.2.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
21:39:04.0066 1936 vToolbarUpdater15.2.0 - ok
21:39:04.0097 1936 [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time C:\Windows\system32\w32time.dll
21:39:04.0144 1936 W32Time - ok
21:39:04.0160 1936 [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen C:\Windows\system32\drivers\wacompen.sys
21:39:04.0206 1936 WacomPen - ok
21:39:04.0238 1936 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
21:39:04.0269 1936 Wanarp - ok
21:39:04.0269 1936 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
21:39:04.0300 1936 Wanarpv6 - ok
21:39:04.0316 1936 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc C:\Windows\System32\wcncsvc.dll
21:39:04.0347 1936 wcncsvc - ok
21:39:04.0362 1936 [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
21:39:04.0409 1936 WcsPlugInService - ok
21:39:04.0440 1936 [ 0C17A0816F65B89E362E682AD5E7266E ] Wd C:\Windows\system32\drivers\wd.sys
21:39:04.0456 1936 Wd - ok
21:39:04.0487 1936 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
21:39:04.0518 1936 Wdf01000 - ok
21:39:04.0550 1936 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost C:\Windows\system32\wdi.dll
21:39:04.0581 1936 WdiServiceHost - ok
21:39:04.0596 1936 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost C:\Windows\system32\wdi.dll
21:39:04.0628 1936 WdiSystemHost - ok
21:39:04.0643 1936 [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient C:\Windows\System32\webclnt.dll
21:39:04.0674 1936 WebClient - ok
21:39:04.0690 1936 [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc C:\Windows\system32\wecsvc.dll
21:39:04.0721 1936 Wecsvc - ok
21:39:04.0784 1936 [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport C:\Windows\System32\wercplsupport.dll
21:39:04.0815 1936 wercplsupport - ok
21:39:04.0846 1936 [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc C:\Windows\System32\WerSvc.dll
21:39:04.0877 1936 WerSvc - ok
21:39:04.0877 1936 whmvkqmf - ok
21:39:04.0893 1936 WinDefend - ok
21:39:04.0908 1936 WinHttpAutoProxySvc - ok
21:39:04.0955 1936 [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
21:39:05.0002 1936 Winmgmt - ok
21:39:05.0064 1936 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM C:\Windows\system32\WsmSvc.dll
21:39:05.0142 1936 WinRM - ok
21:39:05.0220 1936 [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc C:\Windows\System32\wlansvc.dll
21:39:05.0267 1936 Wlansvc - ok
21:39:05.0454 1936 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:39:05.0517 1936 wlidsvc - ok
21:39:05.0548 1936 [ 7999DFB1C555EFC0DB69576F70027867 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
21:39:05.0564 1936 WmiAcpi - ok
21:39:05.0595 1936 [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
21:39:05.0626 1936 wmiApSrv - ok
21:39:05.0626 1936 WMPNetworkSvc - ok
21:39:05.0657 1936 [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc C:\Windows\System32\wpcsvc.dll
21:39:05.0673 1936 WPCSvc - ok
21:39:05.0704 1936 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
21:39:05.0735 1936 WPDBusEnum - ok
21:39:05.0766 1936 [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys
21:39:05.0782 1936 WpdUsb - ok
21:39:06.0063 1936 [ 991E2C2CF3BC204C2BB2EE1476149E4E ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:39:06.0094 1936 WPFFontCache_v0400 - ok
21:39:06.0141 1936 [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
21:39:06.0203 1936 ws2ifsl - ok
21:39:06.0219 1936 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc C:\Windows\system32\wscsvc.dll
21:39:06.0234 1936 wscsvc - ok
21:39:06.0250 1936 WSearch - ok
21:39:06.0344 1936 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll
21:39:06.0422 1936 wuauserv - ok
21:39:06.0453 1936 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
21:39:06.0484 1936 WudfPf - ok
21:39:06.0500 1936 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
21:39:06.0531 1936 WUDFRd - ok
21:39:06.0562 1936 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
21:39:06.0578 1936 wudfsvc - ok
21:39:06.0640 1936 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] YahooAUService C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
21:39:06.0656 1936 YahooAUService - ok
21:39:06.0671 1936 ================ Scan global ===============================
21:39:06.0702 1936 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll
21:39:06.0765 1936 [ D665D594B7E11133D29D726BDDC7A5B0 ] C:\Windows\system32\winsrv.dll
21:39:06.0780 1936 [ D665D594B7E11133D29D726BDDC7A5B0 ] C:\Windows\system32\winsrv.dll
21:39:06.0843 1936 [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe
21:39:06.0843 1936 [Global] - ok
21:39:06.0843 1936 ================ Scan MBR ==================================
21:39:06.0858 1936 [ 9711BF5A8929C6DBE3455A72C790BEF0 ] \Device\Harddisk0\DR0
21:39:06.0858 1936 Suspicious mbr (Forged): \Device\Harddisk0\DR0
21:39:06.0921 1936 \Device\Harddisk0\DR0 ( Rootkit.Boot.Harbinger.a ) - infected
21:39:06.0921 1936 \Device\Harddisk0\DR0 - detected Rootkit.Boot.Harbinger.a (0)
21:39:07.0482 1936 ================ Scan VBR ==================================
21:39:07.0514 1936 [ 79EA9381F8F4CB7D3DAF493255D741A0 ] \Device\Harddisk0\DR0\Partition1
21:39:07.0529 1936 \Device\Harddisk0\DR0\Partition1 - ok
21:39:07.0545 1936 [ FC8BB07EA9EE3601330EB7DCC665D409 ] \Device\Harddisk0\DR0\Partition2
21:39:07.0560 1936 \Device\Harddisk0\DR0\Partition2 - ok
21:39:07.0560 1936 ================ Scan active images ========================
21:39:07.0560 1936 [ E68D9B3A3905619732F7FE039466A623 ] C:\Windows\System32\drivers\atapi.sys
21:39:07.0560 1936 C:\Windows\System32\drivers\atapi.sys - ok
21:39:07.0560 1936 [ 4F4E1093ADFBAE48544DA6E7CCF09FE4 ] C:\Windows\System32\drivers\crashdmp.sys
21:39:07.0560 1936 C:\Windows\System32\drivers\crashdmp.sys - ok
21:39:07.0576 1936 [ 7E7270D67964C9EDDE6BFDAAC07B7999 ] C:\Windows\System32\drivers\Dumpata.sys
21:39:07.0576 1936 C:\Windows\System32\drivers\Dumpata.sys - ok
21:39:07.0576 1936 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] C:\Windows\System32\drivers\tunnel.sys
21:39:07.0576 1936 C:\Windows\System32\drivers\tunnel.sys - ok
21:39:07.0576 1936 [ 89EC74A9E602D16A75A4170511029B3C ] C:\Windows\System32\drivers\TUNMP.SYS
21:39:07.0576 1936 C:\Windows\System32\drivers\TUNMP.SYS - ok
21:39:07.0592 1936 [ BFD84AF32FA1BAD6231C4585CB469630 ] C:\Windows\System32\drivers\intelppm.sys
21:39:07.0592 1936 C:\Windows\System32\drivers\intelppm.sys - ok
21:39:07.0592 1936 [ 677AA5991026A65ADA128C4B59CF2BAD ] C:\Windows\System32\drivers\igdkmd64.sys
21:39:07.0592 1936 C:\Windows\System32\drivers\igdkmd64.sys - ok
21:39:07.0592 1936 [ F3932288EEECD776FF1F9F653AD878F3 ] C:\Windows\System32\drivers\dxgkrnl.sys
21:39:07.0592 1936 C:\Windows\System32\drivers\dxgkrnl.sys - ok
21:39:07.0607 1936 [ 2F956EA22FCCE4C9F15C64175C891A1E ] C:\Windows\System32\drivers\watchdog.sys
21:39:07.0607 1936 C:\Windows\System32\drivers\watchdog.sys - ok
21:39:07.0607 1936 [ 827E44DE934A736EA31E91D353EB126F ] C:\Windows\System32\drivers\usbehci.sys
21:39:07.0607 1936 C:\Windows\System32\drivers\usbehci.sys - ok
21:39:07.0607 1936 [ A60FDA63F3901AE49C244FF988427A9C ] C:\Windows\System32\drivers\usbport.sys
21:39:07.0607 1936 C:\Windows\System32\drivers\usbport.sys - ok
21:39:07.0623 1936 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] C:\Windows\System32\drivers\usbuhci.sys
21:39:07.0623 1936 C:\Windows\System32\drivers\usbuhci.sys - ok
21:39:07.0623 1936 [ F942C5820205F2FB453243EDFEC82A3D ] C:\Windows\System32\drivers\hdaudbus.sys
21:39:07.0623 1936 C:\Windows\System32\drivers\hdaudbus.sys - ok
21:39:07.0623 1936 [ 4BA7814D6067E313A8713CAEB7239594 ] C:\Windows\System32\drivers\1394bus.sys
21:39:07.0623 1936 C:\Windows\System32\drivers\1394bus.sys - ok
21:39:07.0638 1936 [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] C:\Windows\System32\drivers\ohci1394.sys
21:39:07.0638 1936 C:\Windows\System32\drivers\ohci1394.sys - ok
21:39:07.0638 1936 [ F49D8DF8895D809CB0A4DEB44113DE6F ] C:\Windows\System32\drivers\Rtlh64.sys
21:39:07.0638 1936 C:\Windows\System32\drivers\Rtlh64.sys - ok
21:39:07.0638 1936 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] C:\Windows\System32\drivers\cdrom.sys
21:39:07.0638 1936 C:\Windows\System32\drivers\cdrom.sys - ok
21:39:07.0654 1936 [ F78A39ED87D918058A14F36159DE5BDA ] C:\Windows\System32\drivers\Storport.sys
21:39:07.0654 1936 C:\Windows\System32\drivers\Storport.sys - ok
21:39:07.0654 1936 [ E4FDF99599F27EC25D2CF6D754243520 ] C:\Windows\System32\drivers\msiscsi.sys
21:39:07.0654 1936 C:\Windows\System32\drivers\msiscsi.sys - ok
21:39:07.0670 1936 [ C39A90534C5B1E28B8BC8B38A3900AFF ] C:\Windows\System32\drivers\tdi.sys
21:39:07.0670 1936 C:\Windows\System32\drivers\tdi.sys - ok
21:39:07.0670 1936 [ 6DF6A6E5642D97B07214B1FBED4A15B3 ] C:\Windows\System32\drivers\ks.sys
21:39:07.0670 1936 C:\Windows\System32\drivers\ks.sys - ok
21:39:07.0685 1936 [ 40014A6251A68D1EC48001B1653CCEE0 ] C:\Windows\System32\drivers\bdasup.sys
21:39:07.0685 1936 C:\Windows\System32\drivers\bdasup.sys - ok
21:39:07.0685 1936 [ E9158FA6923E80BD57CF068CE9CDDAA2 ] C:\Windows\System32\drivers\Ph3xIB64.sys
21:39:07.0685 1936 C:\Windows\System32\drivers\Ph3xIB64.sys - ok
21:39:07.0685 1936 [ 1D419CF43DB29396ECD7113D129D94EB ] C:\Windows\System32\drivers\ksthunk.sys
21:39:07.0685 1936 C:\Windows\System32\drivers\ksthunk.sys - ok
21:39:07.0701 1936 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] C:\Windows\System32\drivers\rasl2tp.sys
21:39:07.0701 1936 C:\Windows\System32\drivers\rasl2tp.sys - ok
21:39:07.0701 1936 [ 64DF698A425478E321981431AC171334 ] C:\Windows\System32\drivers\ndistapi.sys
21:39:07.0701 1936 C:\Windows\System32\drivers\ndistapi.sys - ok
21:39:07.0701 1936 [ F8158771905260982CE724076419EF19 ] C:\Windows\System32\drivers\ndiswan.sys
21:39:07.0701 1936 C:\Windows\System32\drivers\ndiswan.sys - ok
21:39:07.0716 1936 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] C:\Windows\System32\drivers\raspppoe.sys
21:39:07.0716 1936 C:\Windows\System32\drivers\raspppoe.sys - ok
21:39:07.0716 1936 [ 23386E9952025F5F21C368971E2E7301 ] C:\Windows\System32\drivers\raspptp.sys
21:39:07.0716 1936 C:\Windows\System32\drivers\raspptp.sys - ok
21:39:07.0716 1936 [ C6A593B51F34C33E5474539544072527 ] C:\Windows\System32\drivers\rassstp.sys
21:39:07.0716 1936 C:\Windows\System32\drivers\rassstp.sys - ok
21:39:07.0732 1936 [ 8C19678D22649EC002EF2282EAE92F98 ] C:\Windows\System32\drivers\termdd.sys
21:39:07.0732 1936 C:\Windows\System32\drivers\termdd.sys - ok
21:39:07.0732 1936 [ 423696F3BA6472DD17699209B933BC26 ] C:\Windows\System32\drivers\kbdclass.sys
21:39:07.0732 1936 C:\Windows\System32\drivers\kbdclass.sys - ok
21:39:07.0732 1936 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] C:\Windows\System32\drivers\mouclass.sys
21:39:07.0732 1936 C:\Windows\System32\drivers\mouclass.sys - ok
21:39:07.0748 1936 [ 855796E59DF77EA93AF46F20155BF55B ] C:\Windows\System32\drivers\mssmbios.sys
21:39:07.0748 1936 C:\Windows\System32\drivers\mssmbios.sys - ok
21:39:07.0748 1936 [ 8A851CA908B8B974F89C50D2E18D4F0C ] C:\Windows\System32\drivers\swenum.sys
21:39:07.0748 1936 C:\Windows\System32\drivers\swenum.sys - ok
21:39:07.0763 1936 [ 46E9A994C4FED537DD951F60B86AD3F4 ] C:\Windows\System32\drivers\umbus.sys
21:39:07.0763 1936 C:\Windows\System32\drivers\umbus.sys - ok
21:39:07.0763 1936 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] C:\Windows\System32\drivers\usbhub.sys
21:39:07.0763 1936 C:\Windows\System32\drivers\usbhub.sys - ok
21:39:07.0763 1936 [ A54FA007FD0349AB68DE6D3016A95C8C ] C:\Windows\System32\drivers\drmk.sys
21:39:07.0763 1936 C:\Windows\System32\drivers\drmk.sys - ok
21:39:07.0779 1936 [ 7B7820082CACF593D6FF343D082A3AA3 ] C:\Windows\System32\drivers\portcls.sys
21:39:07.0779 1936 C:\Windows\System32\drivers\portcls.sys - ok
21:39:07.0779 1936 [ 0DD17D4B59D0EC40E3C86A505BB0B6DD ] C:\Windows\System32\drivers\RTKVHD64.sys
21:39:07.0779 1936 C:\Windows\System32\drivers\RTKVHD64.sys - ok
21:39:07.0779 1936 [ BE1CB000C655396C9DEF09AEE3EA2D67 ] C:\Windows\System32\drivers\IntcHdmi.sys
21:39:07.0779 1936 C:\Windows\System32\drivers\IntcHdmi.sys - ok
21:39:07.0794 1936 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] C:\Windows\System32\drivers\ndproxy.sys
21:39:07.0794 1936 C:\Windows\System32\drivers\ndproxy.sys - ok
21:39:07.0794 1936 [ C177A7EBF5E8A0B596F618870516CAB8 ] C:\Windows\System32\drivers\MpFilter.sys
21:39:07.0794 1936 C:\Windows\System32\drivers\MpFilter.sys - ok
21:39:07.0794 1936 [ 5779B86CD8B32519FBECB136394D946A ] C:\Windows\System32\drivers\fs_rec.sys
21:39:07.0794 1936 C:\Windows\System32\drivers\fs_rec.sys - ok
21:39:07.0810 1936 [ DD5D684975352B85B52E3FD5347C20CB ] C:\Windows\System32\drivers\null.sys
21:39:07.0810 1936 C:\Windows\System32\drivers\null.sys - ok
21:39:07.0810 1936 [ 3B5657B6C11CDA87F664DD6F7DD0702D ] C:\Windows\System32\drivers\avgtpx64.sys
21:39:07.0810 1936 C:\Windows\System32\drivers\avgtpx64.sys - ok
21:39:07.0810 1936 [ B13C6930BE914AA433C320E01B0182F3 ] C:\Windows\System32\drivers\hidparse.sys
21:39:07.0810 1936 C:\Windows\System32\drivers\hidparse.sys - ok
21:39:07.0826 1936 [ DBDF75D51464FBC47D0104EC3D572C05 ] C:\Windows\System32\drivers\kbdhid.sys
21:39:07.0826 1936 C:\Windows\System32\drivers\kbdhid.sys - ok
21:39:07.0826 1936 [ B83AB16B51FEDA65DD81B8C59D114D63 ] C:\Windows\System32\drivers\vga.sys
21:39:07.0826 1936 C:\Windows\System32\drivers\vga.sys - ok
21:39:07.0826 1936 [ 84F9479F8BD5EF517E98CBBD8D3300F7 ] C:\Windows\System32\drivers\videoprt.sys
21:39:07.0826 1936 C:\Windows\System32\drivers\videoprt.sys - ok
21:39:07.0841 1936 [ 704F59BFC4512D2BB0146AEC31B10A7C ] C:\Windows\System32\drivers\msfs.sys
21:39:07.0841 1936 C:\Windows\System32\drivers\msfs.sys - ok
21:39:07.0841 1936 [ 603900CC05F6BE65CCBF373800AF3716 ] C:\Windows\System32\drivers\RDPCDD.sys
21:39:07.0841 1936 C:\Windows\System32\drivers\RDPCDD.sys - ok
21:39:07.0841 1936 [ CAB9421DAF3D97B33D0D055858E2C3AB ] C:\Windows\System32\drivers\RDPENCDD.sys
21:39:07.0841 1936 C:\Windows\System32\drivers\RDPENCDD.sys - ok
21:39:07.0857 1936 [ B298874F8E0EA93F06EC40AA8D146478 ] C:\Windows\System32\drivers\npfs.sys
21:39:07.0857 1936 C:\Windows\System32\drivers\npfs.sys - ok
21:39:07.0857 1936 [ 1013B3B663A56D3DDD784F581C1BD005 ] C:\Windows\System32\drivers\rasacd.sys
21:39:07.0857 1936 C:\Windows\System32\drivers\rasacd.sys - ok
21:39:07.0857 1936 [ 07E3498FC60834219D2356293DA0FECC ] C:\Windows\System32\drivers\usbccgp.sys
21:39:07.0857 1936 C:\Windows\System32\drivers\usbccgp.sys - ok
21:39:07.0857 1936 [ 4C01941132AF4405D43668302CC59D2F ] C:\Windows\System32\drivers\usbd.sys
21:39:07.0857 1936 C:\Windows\System32\drivers\usbd.sys - ok
21:39:07.0872 1936 [ DC83A8659514AB95972B13C71F50D0CB ] C:\Windows\System32\drivers\FWPKCLNT.SYS
21:39:07.0872 1936 C:\Windows\System32\drivers\FWPKCLNT.SYS - ok
21:39:07.0872 1936 [ 19A5E570048788BE9343FA96C15CEF6F ] C:\Windows\System32\drivers\tcpip.sys
21:39:07.0872 1936 C:\Windows\System32\drivers\tcpip.sys - ok
21:39:07.0872 1936 [ 70B7902B8DDD3C4B88AC3FC278A9B987 ] C:\Windows\System32\drivers\hidclass.sys
21:39:07.0872 1936 C:\Windows\System32\drivers\hidclass.sys - ok
21:39:07.0888 1936 [ 443BDD2D30BB4F00795C797E2CF99EDF ] C:\Windows\System32\drivers\hidusb.sys
21:39:07.0888 1936 C:\Windows\System32\drivers\hidusb.sys - ok
21:39:07.0888 1936 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] C:\Windows\System32\drivers\smb.sys
21:39:07.0888 1936 C:\Windows\System32\drivers\smb.sys - ok
21:39:07.0888 1936 [ 458919C8C42E398DC4802178D5FFEE27 ] C:\Windows\System32\drivers\tdx.sys
21:39:07.0888 1936 C:\Windows\System32\drivers\tdx.sys - ok
21:39:07.0904 1936 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] C:\Windows\System32\drivers\netbt.sys
21:39:07.0904 1936 C:\Windows\System32\drivers\netbt.sys - ok
21:39:07.0904 1936 [ C4F6CE6087760AD70960C9EB130E7943 ] C:\Windows\System32\drivers\afd.sys
21:39:07.0904 1936 C:\Windows\System32\drivers\afd.sys - ok
21:39:07.0904 1936 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] C:\Windows\System32\drivers\mouhid.sys
21:39:07.0904 1936 C:\Windows\System32\drivers\mouhid.sys - ok
21:39:07.0919 1936 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] C:\Windows\System32\drivers\pacer.sys
21:39:07.0919 1936 C:\Windows\System32\drivers\pacer.sys - ok
21:39:07.0919 1936 [ 8A900348370E359B6BFF6A550E4649E1 ] C:\Windows\System32\drivers\ws2ifsl.sys
21:39:07.0919 1936 C:\Windows\System32\drivers\ws2ifsl.sys - ok
21:39:07.0919 1936 [ 58A38E75F3316A83C23DF6173D41F2B5 ] C:\Program Files\SUPERAntiSpyware\saskutil64.sys
21:39:07.0919 1936 C:\Program Files\SUPERAntiSpyware\saskutil64.sys - ok
21:39:07.0935 1936 [ A499294F5029A7862ADC115BDA7371CE ] C:\Windows\System32\drivers\netbios.sys
21:39:07.0935 1936 C:\Windows\System32\drivers\netbios.sys - ok
21:39:07.0935 1936 [ B8E7049622300D20BA6D8BE0C47C0CFD ] C:\Windows\System32\drivers\wanarp.sys
21:39:07.0935 1936 C:\Windows\System32\drivers\wanarp.sys - ok
21:39:07.0935 1936 [ 3289766038DB2CB14D07DC84392138D5 ] C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys
21:39:07.0935 1936 C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys - ok
21:39:07.0950 1936 [ 1523AF19EE8B030BA682F7A53537EAEB ] C:\Windows\System32\drivers\nsiproxy.sys
21:39:07.0950 1936 C:\Windows\System32\drivers\nsiproxy.sys - ok
21:39:07.0950 1936 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] C:\Windows\System32\drivers\rdbss.sys
21:39:07.0950 1936 C:\Windows\System32\drivers\rdbss.sys - ok
21:39:07.0950 1936 [ 8B722BA35205C71E7951CDC4CDBADE19 ] C:\Windows\System32\drivers\dfsc.sys
21:39:07.0950 1936 C:\Windows\System32\drivers\dfsc.sys - ok
21:39:07.0966 1936 [ 784491AA0A781059AA3EC0BCB7AD760A ] C:\Windows\System32\ntdll.dll
21:39:07.0966 1936 C:\Windows\System32\ntdll.dll - ok
21:39:07.0966 1936 [ 34B7B826716B166778ED454B7628EF5E ] C:\Windows\System32\smss.exe
21:39:07.0966 1936 C:\Windows\System32\smss.exe - ok
21:39:07.0966 1936 [ E24D4475713CB382A720D003BDDA9628 ] C:\Windows\System32\autochk.exe
21:39:07.0966 1936 C:\Windows\System32\autochk.exe - ok
21:39:07.0982 1936 [ B4D787DB8D30793A4D4DF9FEED18F136 ] C:\Windows\System32\drivers\cdfs.sys
21:39:07.0982 1936 C:\Windows\System32\drivers\cdfs.sys - ok
21:39:07.0982 1936 [ BE2E23B3DD533B33338D9B3D826574DA ] C:\Windows\System32\setupapi.dll
21:39:07.0982 1936 C:\Windows\System32\setupapi.dll - ok
21:39:07.0982 1936 [ 4FBE96D97A1E070A06F76F67255C756D ] C:\Windows\System32\wininet.dll
21:39:07.0982 1936 C:\Windows\System32\wininet.dll - ok
21:39:07.0997 1936 [ BB8C4784AA400BDC3D51B6ACAA077E96 ] C:\Windows\System32\advapi32.dll
21:39:07.0997 1936 C:\Windows\System32\advapi32.dll - ok
21:39:07.0997 1936 [ 2C74308C8A20F3F3A2226DFE36914CBF ] C:\Windows\System32\msvcrt.dll
21:39:07.0997 1936 C:\Windows\System32\msvcrt.dll - ok
21:39:08.0013 1936 [ 8E0189219E941613B1512431604114E0 ] C:\Windows\System32\rpcrt4.dll
21:39:08.0013 1936 C:\Windows\System32\rpcrt4.dll - ok
21:39:08.0013 1936 [ 3B2671CBC989F1B2084290D787DE8499 ] C:\Windows\System32\oleaut32.dll
21:39:08.0013 1936 C:\Windows\System32\oleaut32.dll - ok
21:39:08.0013 1936 [ 533B3BA63E5DB49FC59A842A1DE3121F ] C:\Windows\System32\normaliz.dll
21:39:08.0013 1936 C:\Windows\System32\normaliz.dll - ok
21:39:08.0028 1936 [ 0CB93E3F36C4F4122E7CBBAA731F67D1 ] C:\Windows\System32\ole32.dll
21:39:08.0028 1936 C:\Windows\System32\ole32.dll - ok
21:39:08.0028 1936 [ DE3DC975F1A9F82BAB9812A272018810 ] C:\Windows\System32\iertutil.dll
21:39:08.0028 1936 C:\Windows\System32\iertutil.dll - ok
21:39:08.0028 1936 [ 891E1D0DCDE747C8F1EE71E61EA193F5 ] C:\Windows\System32\lpk.dll
21:39:08.0028 1936 C:\Windows\System32\lpk.dll - ok
21:39:08.0044 1936 [ 6542163C675E19A1F1A638734662F0AA ] C:\Windows\System32\urlmon.dll
21:39:08.0044 1936 C:\Windows\System32\urlmon.dll - ok
21:39:08.0044 1936 [ F3F5549E69AE8509342E67E4F972CA1C ] C:\Windows\System32\user32.dll
21:39:08.0044 1936 C:\Windows\System32\user32.dll - ok
21:39:08.0044 1936 [ C669ABA2C3298B4B4F252EB6A5AE8964 ] C:\Windows\System32\gdi32.dll
21:39:08.0044 1936 C:\Windows\System32\gdi32.dll - ok
21:39:08.0060 1936 [ A02EB771DAE80667E3C877CF19E3F6EE ] C:\Windows\System32\kernel32.dll
21:39:08.0060 1936 C:\Windows\System32\kernel32.dll - ok
21:39:08.0060 1936 [ 09ED5DF1622C759B5EB9C40B89FD310A ] C:\Windows\System32\imagehlp.dll
21:39:08.0060 1936 C:\Windows\System32\imagehlp.dll - ok
21:39:08.0060 1936 [ 604384D4459F4A68FF88E7C212C43F61 ] C:\Windows\System32\shlwapi.dll
21:39:08.0060 1936 C:\Windows\System32\shlwapi.dll - ok
21:39:08.0075 1936 [ 62C15795629FA290656C6A7E5CD25F52 ] C:\Windows\System32\imm32.dll
21:39:08.0075 1936 C:\Windows\System32\imm32.dll - ok
21:39:08.0075 1936 [ BAB10B35E2D5EE0DC3DE05A177C52C50 ] C:\Windows\System32\ws2_32.dll
21:39:08.0075 1936 C:\Windows\System32\ws2_32.dll - ok
21:39:08.0075 1936 [ AA09B70F619CBF499EFC22E7A63E3CE6 ] C:\Windows\System32\comdlg32.dll
21:39:08.0075 1936 C:\Windows\System32\comdlg32.dll - ok
21:39:08.0091 1936 [ DB310BF331A32FD208CADA64ABA2903A ] C:\Windows\System32\clbcatq.dll
21:39:08.0091 1936 C:\Windows\System32\clbcatq.dll - ok
21:39:08.0091 1936 [ 87CB61DF57FEC0948A26F9E671ADD81A ] C:\Windows\System32\msctf.dll
21:39:08.0091 1936 C:\Windows\System32\msctf.dll - ok
21:39:08.0091 1936 [ 7CAF51D586DFE475147DFB158BEBB3F8 ] C:\Windows\System32\nsi.dll
21:39:08.0091 1936 C:\Windows\System32\nsi.dll - ok
21:39:08.0106 1936 [ 11EAF90B44A9E378CB6F4ECBF2471F60 ] C:\Windows\System32\usp10.dll
21:39:08.0106 1936 C:\Windows\System32\usp10.dll - ok
21:39:08.0106 1936 [ ADC1964755BB12485A15070A4D4F2697 ] C:\Windows\System32\Wldap32.dll
21:39:08.0106 1936 C:\Windows\System32\Wldap32.dll - ok
21:39:08.0122 1936 [ 487C3C0927F67331681294B867A4141B ] C:\Windows\System32\shell32.dll
21:39:08.0122 1936 C:\Windows\System32\shell32.dll - ok
21:39:08.0122 1936 [ 74ABE02BF1937B32C6FC169A782FCF60 ] C:\Windows\System32\comctl32.dll
21:39:08.0122 1936 C:\Windows\System32\comctl32.dll - ok
21:39:08.0122 1936 [ AEF2D8B0B518A5623FC5F9832F622677 ] C:\Windows\System32\psapi.dll
21:39:08.0122 1936 C:\Windows\System32\psapi.dll - ok
21:39:08.0122 1936 [ 6F29236AB5926100972924BD29D9D225 ] C:\Windows\SysWOW64\normaliz.dll
21:39:08.0122 1936 C:\Windows\SysWOW64\normaliz.dll - ok
21:39:08.0138 1936 [ 4C2DC63036D452FDB636D58D8EA7BC90 ] C:\Windows\System32\drivers\dxapi.sys
21:39:08.0138 1936 C:\Windows\System32\drivers\dxapi.sys - ok
21:39:08.0138 1936 [ 570DAA0D122E136209823FA8C042EF65 ] C:\Windows\System32\win32k.sys
21:39:08.0138 1936 C:\Windows\System32\win32k.sys - ok
21:39:08.0138 1936 [ 38CE04857A9A2AE83A4673C691E68D10 ] C:\Windows\System32\csrsrv.dll
21:39:08.0138 1936 C:\Windows\System32\csrsrv.dll - ok
21:39:08.0153 1936 [ B4ABE68596B173FF2AB2076BC7C35EB4 ] C:\Windows\System32\csrss.exe
21:39:08.0153 1936 C:\Windows\System32\csrss.exe - ok
21:39:08.0153 1936 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\System32\basesrv.dll
21:39:08.0153 1936 C:\Windows\System32\basesrv.dll - ok
21:39:08.0153 1936 [ D665D594B7E11133D29D726BDDC7A5B0 ] C:\Windows\System32\winsrv.dll
21:39:08.0153 1936 C:\Windows\System32\winsrv.dll - ok
21:39:08.0153 1936 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] C:\Windows\System32\drivers\monitor.sys
21:39:08.0153 1936 C:\Windows\System32\drivers\monitor.sys - ok
21:39:08.0169 1936 [ 86173B7125321C93E355DF3837039244 ] C:\Windows\System32\tsddd.dll
21:39:08.0169 1936 C:\Windows\System32\tsddd.dll - ok
21:39:08.0169 1936 [ 117EA87DF785CA1B9D821F6F213DCE07 ] C:\Windows\System32\wininit.exe
21:39:08.0169 1936 C:\Windows\System32\wininit.exe - ok
21:39:08.0169 1936 [ 95E848589698D6CF716ECF1403925DFC ] C:\Windows\System32\userenv.dll
21:39:08.0169 1936 C:\Windows\System32\userenv.dll - ok
21:39:08.0184 1936 [ FEA83138B1C1D6EB55046C4612905888 ] C:\Windows\System32\secur32.dll
21:39:08.0184 1936 C:\Windows\System32\secur32.dll - ok
21:39:08.0184 1936 [ 16687F0351E513BF2019073ABF02B585 ] C:\Windows\System32\sxs.dll
21:39:08.0184 1936 C:\Windows\System32\sxs.dll - ok
21:39:08.0184 1936 [ 46662CD685A6341AB4AED86D134D80E9 ] C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll
21:39:08.0184 1936 C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd\comctl32.dll - ok
21:39:08.0200 1936 [ 89A722B06A83706797E283016181BEAB ] C:\Windows\System32\KBDUS.DLL
21:39:08.0200 1936 C:\Windows\System32\KBDUS.DLL - ok
21:39:08.0200 1936 [ D1BDCF6DE24D16E16FC57AEE4A1BE9AE ] C:\Windows\System32\WlS0WndH.dll
21:39:08.0200 1936 C:\Windows\System32\WlS0WndH.dll - ok
21:39:08.0200 1936 [ 6D798629B0A33D33E0BFED45BC438E1E ] C:\Windows\System32\cdd.dll
21:39:08.0200 1936 C:\Windows\System32\cdd.dll - ok
21:39:08.0216 1936 [ F33E804A031F160D128AB78990DE7C91 ] C:\Windows\System32\apphelp.dll
21:39:08.0216 1936 C:\Windows\System32\apphelp.dll - ok
21:39:08.0216 1936 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] C:\Windows\System32\lsass.exe
21:39:08.0216 1936 C:\Windows\System32\lsass.exe - ok
21:39:08.0216 1936 [ 54D814DC2FA54AA847D240D4EA0E6586 ] C:\Windows\System32\lsm.exe
21:39:08.0216 1936 C:\Windows\System32\lsm.exe - ok
21:39:08.0231 1936 [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\System32\services.exe
21:39:08.0231 1936 C:\Windows\System32\services.exe - ok
21:39:08.0231 1936 [ 902F14A1FDF1B4A543326A35CB21EB1F ] C:\Windows\System32\lsasrv.dll
21:39:08.0231 1936 C:\Windows\System32\lsasrv.dll - ok
21:39:08.0231 1936 [ 6D0773A3A65D28B663F334C90441D01A ] C:\Windows\System32\winlogon.exe
21:39:08.0231 1936 C:\Windows\System32\winlogon.exe - ok
21:39:08.0247 1936 [ 60EEC5440C2D05E5FDA04900E45FF717 ] C:\Windows\System32\samsrv.dll
21:39:08.0247 1936 C:\Windows\System32\samsrv.dll - ok
21:39:08.0247 1936 [ 419CE835359938213BD32A7AA327F2B9 ] C:\Windows\System32\cryptdll.dll
21:39:08.0247 1936 C:\Windows\System32\cryptdll.dll - ok
21:39:08.0247 1936 [ E4C283A98F118CEC9E087EAC4E9EFB6A ] C:\Windows\System32\dnsapi.dll
21:39:08.0247 1936 C:\Windows\System32\dnsapi.dll - ok
21:39:08.0262 1936 [ F3E5C76AA1175D29F6459BDB7DF345EC ] C:\Windows\System32\netapi32.dll
21:39:08.0262 1936 C:\Windows\System32\netapi32.dll - ok
21:39:08.0262 1936 [ 009456399B31D69C67654F6C3618D9A8 ] C:\Windows\System32\sysntfy.dll
21:39:08.0262 1936 C:\Windows\System32\sysntfy.dll - ok
21:39:08.0262 1936 [ 0C2E0A8562FE4B33D00E175A97E05793 ] C:\Windows\System32\wmsgapi.dll
21:39:08.0262 1936 C:\Windows\System32\wmsgapi.dll - ok
21:39:08.0278 1936 [ 5279672A8BDAF3CFB0A4C6E0591987AC ] C:\Windows\System32\samlib.dll
21:39:08.0278 1936 C:\Windows\System32\samlib.dll - ok
21:39:08.0278 1936 [ 301D19A870E40C12540BE46034BD6B20 ] C:\Windows\System32\msasn1.dll
21:39:08.0278 1936 C:\Windows\System32\msasn1.dll - ok
21:39:08.0278 1936 [ 33741BA808457C9AF07055C0FBEFE973 ] C:\Windows\System32\ntdsapi.dll
21:39:08.0278 1936 C:\Windows\System32\ntdsapi.dll - ok
21:39:08.0294 1936 [ 9396E00D2C2DA91E22C98D2245968AF3 ] C:\Windows\System32\crypt32.dll
21:39:08.0294 1936 C:\Windows\System32\crypt32.dll - ok
21:39:08.0294 1936 [ D7924B0F3AB5574BF59CA2892BE8961A ] C:\Windows\System32\feclient.dll
21:39:08.0294 1936 C:\Windows\System32\feclient.dll - ok
21:39:08.0294 1936 [ B3EBBD687BDFCBBBBCB6115B682D1845 ] C:\Windows\System32\mpr.dll
21:39:08.0294 1936 C:\Windows\System32\mpr.dll - ok
21:39:08.0309 1936 [ EE11F2630840479C4AA784AF3770F8E2 ] C:\Windows\System32\SLC.dll
21:39:08.0309 1936 C:\Windows\System32\SLC.dll - ok
21:39:08.0309 1936 [ 45B4004F43B48E4A3F12B85891F81221 ] C:\Windows\System32\wevtapi.dll
21:39:08.0309 1936 C:\Windows\System32\wevtapi.dll - ok
21:39:08.0309 1936 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] C:\Windows\System32\dhcpcsvc.dll
21:39:08.0309 1936 C:\Windows\System32\dhcpcsvc.dll - ok
21:39:08.0325 1936 [ A9D70295BA8F31D5EA118B0A6B74183E ] C:\Windows\System32\IPHLPAPI.DLL
21:39:08.0325 1936 C:\Windows\System32\IPHLPAPI.DLL - ok
21:39:08.0325 1936 [ 495EB57ACF30983AA441B70A8DE2B7ED ] C:\Windows\System32\scesrv.dll
21:39:08.0325 1936 C:\Windows\System32\scesrv.dll - ok
21:39:08.0325 1936 [ 956148910C7EB6A8C095D9B4E6F94E62 ] C:\Windows\System32\dhcpcsvc6.dll
21:39:08.0325 1936 C:\Windows\System32\dhcpcsvc6.dll - ok
21:39:08.0340 1936 [ 58AAAEA100F45F4F44297D6DE9ACF8ED ] C:\Windows\System32\winnsi.dll
21:39:08.0340 1936 C:\Windows\System32\winnsi.dll - ok
21:39:08.0340 1936 [ 5EF9205E045643A5A75A82B116395B25 ] C:\Windows\System32\authz.dll
21:39:08.0340 1936 C:\Windows\System32\authz.dll - ok
21:39:08.0340 1936 [ 21322B1A2AD337C579F4A65EA0D25193 ] C:\Windows\System32\cngaudit.dll
21:39:08.0340 1936 C:\Windows\System32\cngaudit.dll - ok
21:39:08.0356 1936 [ FA19D9DE54B122316274703D50F34130 ] C:\Windows\System32\ncobjapi.dll
21:39:08.0356 1936 C:\Windows\System32\ncobjapi.dll - ok
21:39:08.0356 1936 [ FD51DED28EEC823940432D05BACE2490 ] C:\Windows\System32\ncrypt.dll
21:39:08.0356 1936 C:\Windows\System32\ncrypt.dll - ok
21:39:08.0356 1936 [ 02EE316487BCC8F4F6017CAD538365CC ] C:\Windows\System32\bcrypt.dll
21:39:08.0356 1936 C:\Windows\System32\bcrypt.dll - ok
21:39:08.0372 1936 [ 0F421175574BFE0BF2F4D8E910A253BB ] C:\Windows\System32\aelupsvc.dll
21:39:08.0372 1936 C:\Windows\System32\aelupsvc.dll - ok
21:39:08.0372 1936 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] C:\Windows\System32\alg.exe
21:39:08.0372 1936 C:\Windows\System32\alg.exe - ok
21:39:08.0372 1936 [ B7CCDC4B877DC3CC665DE8F322F2BD9E ] C:\Windows\System32\credssp.dll
21:39:08.0372 1936 C:\Windows\System32\credssp.dll - ok
21:39:08.0387 1936 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] C:\Windows\System32\appinfo.dll
21:39:08.0387 1936 C:\Windows\System32\appinfo.dll - ok
21:39:08.0387 1936 [ CD6D49EA9DBBD3EA9E449FD84C51C731 ] C:\Windows\System32\kerberos.dll
21:39:08.0387 1936 C:\Windows\System32\kerberos.dll - ok
21:39:08.0387 1936 [ F7097878AE102618656A04F03951C339 ] C:\Windows\System32\msprivs.dll
21:39:08.0387 1936 C:\Windows\System32\msprivs.dll - ok
21:39:08.0387 1936 [ 15C815573011719585EB836614ED1DF1 ] C:\Windows\System32\rascfg.dll
21:39:08.0387 1936 C:\Windows\System32\rascfg.dll - ok
21:39:08.0403 1936 [ 79318C744693EC983D20E9337A2F8196 ] C:\Windows\System32\audiosrv.dll
21:39:08.0403 1936 C:\Windows\System32\audiosrv.dll - ok
21:39:08.0403 1936 [ 1671EF15434501ABBE9E7BE905EF998B ] C:\Windows\System32\winsta.dll
21:39:08.0403 1936 C:\Windows\System32\winsta.dll - ok
21:39:08.0403 1936 [ 253607D6C54A1604436F08E67CCED044 ] C:\Windows\System32\WSHTCPIP.DLL
21:39:08.0403 1936 C:\Windows\System32\WSHTCPIP.DLL - ok
21:39:08.0418 1936 [ FFB96C2589FFA60473EAD78B39FBDE29 ] C:\Windows\System32\BFE.DLL
21:39:08.0418 1936 C:\Windows\System32\BFE.DLL - ok
21:39:08.0418 1936 [ 6D316F4859634071CC25C4FD4589AD2C ] C:\Windows\System32\qmgr.dll
21:39:08.0418 1936 C:\Windows\System32\qmgr.dll - ok
21:39:08.0418 1936 [ 2C305F6445662EFF9A08B1BA41784CC0 ] C:\Windows\System32\wship6.dll
21:39:08.0418 1936 C:\Windows\System32\wship6.dll - ok
21:39:08.0434 1936 [ 599DA6EB260D9601D2D67AE177F95568 ] C:\Windows\System32\wshqos.dll
21:39:08.0434 1936 C:\Windows\System32\wshqos.dll - ok
21:39:08.0434 1936 [ BB08D93011B82883EC33C7707A9627BE ] C:\Windows\System32\mswsock.dll
21:39:08.0434 1936 C:\Windows\System32\mswsock.dll - ok
21:39:08.0434 1936 [ 062972C53BDC6819CE0BAAAA5382F758 ] C:\Windows\System32\NapiNSP.dll
21:39:08.0434 1936 C:\Windows\System32\NapiNSP.dll - ok
21:39:08.0450 1936 [ F145BF4C4668E7E312069F81EF847CFC ] C:\Windows\System32\nlasvc.dll
21:39:08.0450 1936 C:\Windows\System32\nlasvc.dll - ok
21:39:08.0450 1936 [ E1BAEEE7949ED5019259E69393367400 ] C:\Windows\System32\pnrpnsp.dll
21:39:08.0450 1936 C:\Windows\System32\pnrpnsp.dll - ok
21:39:08.0450 1936 [ A1B39DE453433B115B4EA69EE0343816 ] C:\Windows\System32\browser.dll
21:39:08.0450 1936 C:\Windows\System32\browser.dll - ok
21:39:08.0450 1936 [ 5A268127633C7EE2A7FB87F39D748D56 ] C:\Windows\System32\certprop.dll
21:39:08.0450 1936 C:\Windows\System32\certprop.dll - ok
21:39:08.0465 1936 [ DDEE5FE5C3C3141CE02DE6B7B2BF686B ] C:\Windows\System32\comres.dll
21:39:08.0465 1936 C:\Windows\System32\comres.dll - ok
21:39:08.0465 1936 [ 434B2B82B237FC2F4F8F6844A8FF1909 ] C:\Windows\System32\msv1_0.dll
21:39:08.0465 1936 C:\Windows\System32\msv1_0.dll - ok
21:39:08.0465 1936 [ A3F1B171702CA04744EE514243B45BFB ] C:\Windows\System32\netlogon.dll
21:39:08.0465 1936 C:\Windows\System32\netlogon.dll - ok
21:39:08.0481 1936 [ CA307C0BD127FA7ADE5E6FEE8750F046 ] C:\Windows\System32\winbrand.dll
21:39:08.0481 1936 C:\Windows\System32\winbrand.dll - ok
21:39:08.0481 1936 [ 1B22BC0B71F65001479DAB792C3F626C ] C:\Windows\System32\cryptsvc.dll
21:39:08.0481 1936 C:\Windows\System32\cryptsvc.dll - ok
21:39:08.0496 1936 [ CE7183F26642FAFE46C8374AE70A66DB ] C:\Windows\System32\oleres.dll
21:39:08.0496 1936 C:\Windows\System32\oleres.dll - ok
21:39:08.0496 1936 [ 2E4733239CB09A2212C44FCD1C1B4CC9 ] C:\Windows\System32\dfsrres.dll
21:39:08.0496 1936 C:\Windows\System32\dfsrres.dll - ok
21:39:08.0496 1936 [ 4C7F1DA7E2BF41EB19208540DD5574C8 ] C:\Windows\System32\schannel.dll
21:39:08.0496 1936 C:\Windows\System32\schannel.dll - ok
21:39:08.0496 1936 [ 1A7156DD1E850E9914E5E991E3225B94 ] C:\Windows\System32\dot3svc.dll
21:39:08.0496 1936 C:\Windows\System32\dot3svc.dll - ok
21:39:08.0512 1936 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] C:\Windows\System32\dps.dll
21:39:08.0512 1936 C:\Windows\System32\dps.dll - ok
21:39:08.0512 1936 [ C2303883FD9BE49DC36A6400643002EA ] C:\Windows\System32\eapsvc.dll
21:39:08.0512 1936 C:\Windows\System32\eapsvc.dll - ok
21:39:08.0512 1936 [ B4A04D5AA66E8F77DE19E0EB89C52D2B ] C:\Windows\System32\wdigest.dll
21:39:08.0512 1936 C:\Windows\System32\wdigest.dll - ok
21:39:08.0528 1936 [ 14CE384D2E27B64C256BDA4DC39C312D ] C:\Windows\ehome\ehrecvr.exe
21:39:08.0528 1936 C:\Windows\ehome\ehrecvr.exe - ok
21:39:08.0528 1936 [ 899F834C330A96A80EC36DAEDA2FF018 ] C:\Windows\System32\gpapi.dll
21:39:08.0528 1936 C:\Windows\System32\gpapi.dll - ok
21:39:08.0528 1936 [ 4D27759CC69F69E4B3228A970FF55F88 ] C:\Windows\System32\rsaenh.dll
21:39:08.0528 1936 C:\Windows\System32\rsaenh.dll - ok
21:39:08.0543 1936 [ BC69DA355B62C898DFEA93851335EAF0 ] C:\Windows\System32\TSpkg.dll
21:39:08.0543 1936 C:\Windows\System32\TSpkg.dll - ok
21:39:08.0543 1936 [ B93159C1313D66FDFBBE876F5189CD52 ] C:\Windows\ehome\ehsched.exe
21:39:08.0543 1936 C:\Windows\ehome\ehsched.exe - ok
21:39:08.0543 1936 [ F5EE2527D74449868E3C3227A59BCD28 ] C:\Windows\ehome\ehstart.dll
21:39:08.0543 1936 C:\Windows\ehome\ehstart.dll - ok
21:39:08.0543 1936 [ A9B18B63A4FD6BAAB83326706D857FAB ] C:\Windows\System32\emdmgmt.dll
21:39:08.0543 1936 C:\Windows\System32\emdmgmt.dll - ok
21:39:08.0559 1936 [ B3564B747D0B059D99E888F8369E56BC ] C:\Windows\System32\wevtsvc.dll
21:39:08.0559 1936 C:\Windows\System32\wevtsvc.dll - ok
21:39:08.0559 1936 [ BB9267ACACD8B7533DD936C34A0CBA5E ] C:\Windows\System32\fdPHost.dll
21:39:08.0559 1936 C:\Windows\System32\fdPHost.dll - ok
21:39:08.0559 1936 [ 300C80931EABBE1DB7591C516EFE8D0F ] C:\Windows\System32\FDResPub.dll
21:39:08.0559 1936 C:\Windows\System32\FDResPub.dll - ok
21:39:08.0574 1936 [ BE1C5BD1CA7ED015BC6FA1AE67E592C8 ] C:\Windows\System32\FntCache.dll
21:39:08.0574 1936 C:\Windows\System32\FntCache.dll - ok
21:39:08.0574 1936 [ E60BB0CDC5EA153F6D24C51AAD4A73FD ] C:\Windows\System32\PresentationHost.exe
21:39:08.0574 1936 C:\Windows\System32\PresentationHost.exe - ok
21:39:08.0574 1936 [ 59361D38A297755D46A540E450202B2A ] C:\Windows\System32\hidserv.dll
21:39:08.0574 1936 C:\Windows\System32\hidserv.dll - ok
21:39:08.0590 1936 [ B12F367EA39C0795FD57E31242CE1A5A ] C:\Windows\System32\KMSVC.DLL
21:39:08.0590 1936 C:\Windows\System32\KMSVC.DLL - ok
21:39:08.0590 1936 [ 42161FDC47A49CD513D29BACB99D6E0D ] C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll
21:39:08.0590 1936 C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\ServiceModelInstallRC.dll - ok
21:39:08.0590 1936 [ 0C9EA6E654E7B0471741E343A6C671AF ] C:\Windows\System32\IKEEXT.DLL
21:39:08.0590 1936 C:\Windows\System32\IKEEXT.DLL - ok
21:39:08.0606 1936 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] C:\Windows\System32\IPBusEnum.dll
21:39:08.0606 1936 C:\Windows\System32\IPBusEnum.dll - ok
21:39:08.0606 1936 [ BF0DBFA9792C5C14FA00F61C75116C1B ] C:\Windows\System32\iphlpsvc.dll
21:39:08.0606 1936 C:\Windows\System32\iphlpsvc.dll - ok
21:39:08.0606 1936 [ C6336D1625515CC5F70E5630CFF14182 ] C:\Windows\System32\keyiso.dll
21:39:08.0606 1936 C:\Windows\System32\keyiso.dll - ok
21:39:08.0621 1936 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] C:\Windows\System32\srvsvc.dll
21:39:08.0621 1936 C:\Windows\System32\srvsvc.dll - ok
21:39:08.0621 1936 [ 4698036AE905F88E02C3F69BA77981FB ] C:\Windows\ehome\ehres.dll
21:39:08.0621 1936 C:\Windows\ehome\ehres.dll - ok
21:39:08.0621 1936 [ 4B8C95B49C58D7A41BF3FE38AA64DC6C ] C:\Windows\System32\lltdres.dll
21:39:08.0621 1936 C:\Windows\System32\lltdres.dll - ok
21:39:08.0637 1936 [ A47F8080CACC23C91FE823AD19AA5612 ] C:\Windows\System32\lmhsvc.dll
21:39:08.0637 1936 C:\Windows\System32\lmhsvc.dll - ok
21:39:08.0637 1936 [ CAF86FC1388BE1E470F1A7B43E348ADB ] C:\Windows\System32\wkssvc.dll
21:39:08.0637 1936 C:\Windows\System32\wkssvc.dll - ok
21:39:08.0637 1936 [ FFA2B274A5CC6C9A03CBDCF5B8F0239A ] C:\Windows\System32\FirewallAPI.dll
21:39:08.0637 1936 C:\Windows\System32\FirewallAPI.dll - ok
21:39:08.0652 1936 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] C:\Windows\System32\mmcss.dll
21:39:08.0652 1936 C:\Windows\System32\mmcss.dll - ok
21:39:08.0652 1936 [ 1371FA9D8B1E567AE852E0F74D41D040 ] C:\Windows\System32\iscsidsc.dll
21:39:08.0652 1936 C:\Windows\System32\iscsidsc.dll - ok
21:39:08.0652 1936 [ FCD84867883C365A24C61E50AF8A6DB9 ] C:\Windows\System32\msimsg.dll
21:39:08.0652 1936 C:\Windows\System32\msimsg.dll - ok
21:39:08.0652 1936 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] C:\Windows\System32\QAGENTRT.DLL
21:39:08.0652 1936 C:\Windows\System32\QAGENTRT.DLL - ok
21:39:08.0668 1936 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] C:\Windows\System32\netman.dll
21:39:08.0668 1936 C:\Windows\System32\netman.dll - ok
21:39:08.0668 1936 [ 5DE1EB779116F20869B732CEF1DC689A ] C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll
21:39:08.0668 1936 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll - ok
21:39:08.0668 1936 [ 0341CB05512AA87BB64A834DE6264C34 ] C:\Windows\System32\netprof.dll
21:39:08.0668 1936 C:\Windows\System32\netprof.dll - ok
21:39:08.0684 1936 [ E2BFFF77EA019A175B1A655F41B33FF1 ] C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll
21:39:08.0684 1936 C:\Program Files\Microsoft Security Client\Antimalware\MpAsDesc.dll - ok
21:39:08.0684 1936 [ ACB62BAA1C319B17752553DF3026EEEB ] C:\Windows\System32\nsisvc.dll
21:39:08.0684 1936 C:\Windows\System32\nsisvc.dll - ok
21:39:08.0684 1936 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] C:\Windows\System32\p2psvc.dll
21:39:08.0684 1936 C:\Windows\System32\p2psvc.dll - ok
21:39:08.0699 1936 [ 9AB157B374192FF276C1628FBDBA2B0E ] C:\Windows\System32\pcasvc.dll
21:39:08.0699 1936 C:\Windows\System32\pcasvc.dll - ok
21:39:08.0699 1936 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] C:\Windows\System32\pla.dll
21:39:08.0699 1936 C:\Windows\System32\pla.dll - ok
21:39:08.0715 1936 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] C:\Windows\System32\umpnpmgr.dll
21:39:08.0715 1936 C:\Windows\System32\umpnpmgr.dll - ok
21:39:08.0715 1936 [ F7BEA2085635CA9B2B991D8EDC426D3A ] C:\Windows\System32\polstore.dll
21:39:08.0715 1936 C:\Windows\System32\polstore.dll - ok
21:39:08.0715 1936 [ E058CE4FC2449D8BFA14739C83B7FF2A ] C:\Windows\System32\profsvc.dll
21:39:08.0715 1936 C:\Windows\System32\profsvc.dll - ok
21:39:08.0715 1936 [ 43A4F5B4EAC81FA11DAC3143ADC77CBA ] C:\Windows\System32\psbase.dll
21:39:08.0715 1936 C:\Windows\System32\psbase.dll - ok
21:39:08.0730 1936 [ 90574842C3DA781E279061A3EFF91F07 ] C:\Windows\System32\qwave.dll
21:39:08.0730 1936 C:\Windows\System32\qwave.dll - ok
21:39:08.0730 1936 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] C:\Windows\System32\drivers\qwavedrv.sys
21:39:08.0730 1936 C:\Windows\System32\drivers\qwavedrv.sys - ok
21:39:08.0730 1936 [ B2AE18F847D07F0044404DDF7CB04497 ] C:\Windows\System32\rasauto.dll
21:39:08.0730 1936 C:\Windows\System32\rasauto.dll - ok
21:39:08.0746 1936 [ 3AD83E4046C43BE510DE681588ACB8AF ] C:\Windows\System32\rasmans.dll
21:39:08.0746 1936 C:\Windows\System32\rasmans.dll - ok
21:39:08.0746 1936 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] C:\Windows\System32\sstpsvc.dll
21:39:08.0746 1936 C:\Windows\System32\sstpsvc.dll - ok
21:39:08.0746 1936 [ C612B9557DA73F70D41F8A6FBC8E5344 ] C:\Windows\System32\mprdim.dll
21:39:08.0746 1936 C:\Windows\System32\mprdim.dll - ok
21:39:08.0762 1936 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] C:\Windows\System32\regsvc.dll
21:39:08.0762 1936 C:\Windows\System32\regsvc.dll - ok
21:39:08.0762 1936 [ F46C457840D4B7A4DAAFEE739CE04102 ] C:\Windows\System32\Locator.exe
21:39:08.0762 1936 C:\Windows\System32\Locator.exe - ok
21:39:08.0762 1936 [ FD1CDCF108D5EF3366F00D18B70FB89B ] C:\Windows\System32\SCardSvr.dll
21:39:08.0762 1936 C:\Windows\System32\SCardSvr.dll - ok
21:39:08.0762 1936 [ 0F838C811AD295D2A4489B9993096C63 ] C:\Windows\System32\schedsvc.dll
21:39:08.0762 1936 C:\Windows\System32\schedsvc.dll - ok
21:39:08.0777 1936 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] C:\Windows\System32\sdrsvc.dll
21:39:08.0777 1936 C:\Windows\System32\sdrsvc.dll - ok
21:39:08.0777 1936 [ 5ACDCBC67FCF894A1815B9F96D704490 ] C:\Windows\System32\seclogon.dll
21:39:08.0777 1936 C:\Windows\System32\seclogon.dll - ok
21:39:08.0793 1936 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] C:\Windows\System32\ipnathlp.dll
21:39:08.0793 1936 C:\Windows\System32\ipnathlp.dll - ok
21:39:08.0793 1936 [ 90973A64B96CD647FF81C79443618EED ] C:\Windows\System32\Sens.dll
21:39:08.0793 1936 C:\Windows\System32\Sens.dll - ok
21:39:08.0793 1936 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] C:\Windows\System32\SessEnv.dll
21:39:08.0793 1936 C:\Windows\System32\SessEnv.dll - ok
21:39:08.0793 1936 [ 56793271ECDEDD350C5ADD305603E963 ] C:\Windows\System32\shsvcs.dll
21:39:08.0793 1936 C:\Windows\System32\shsvcs.dll - ok
21:39:08.0808 1936 [ A9A27A8E257B45A604FDAD4F26FE7241 ] C:\Windows\System32\SLsvc.exe
21:39:08.0808 1936 C:\Windows\System32\SLsvc.exe - ok
21:39:08.0808 1936 [ FD74B4B7C2088E390A30C85A896FC3AF ] C:\Windows\System32\SLUINotify.dll
21:39:08.0808 1936 C:\Windows\System32\SLUINotify.dll - ok
21:39:08.0808 1936 [ F8F08779E7D997913607B0146710CC04 ] C:\Windows\System32\tcpipcfg.dll
21:39:08.0808 1936 C:\Windows\System32\tcpipcfg.dll - ok
21:39:08.0824 1936 [ F8F47F38909823B1AF28D60B96340CFF ] C:\Windows\System32\snmptrap.exe
21:39:08.0824 1936 C:\Windows\System32\snmptrap.exe - ok
21:39:08.0824 1936 [ F66FF751E7EFC816D266977939EF5DC3 ] C:\Windows\System32\spoolsv.exe
21:39:08.0824 1936 C:\Windows\System32\spoolsv.exe - ok
21:39:08.0840 1936 [ 192C74646EC5725AEF3F80D19FF75F6A ] C:\Windows\System32\ssdpsrv.dll
21:39:08.0840 1936 C:\Windows\System32\ssdpsrv.dll - ok
21:39:08.0840 1936 [ 15825C1FBFB8779992CB65087F316AF5 ] C:\Windows\System32\wiaservc.dll
21:39:08.0840 1936 C:\Windows\System32\wiaservc.dll - ok
21:39:08.0840 1936 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] C:\Windows\System32\swprv.dll
21:39:08.0840 1936 C:\Windows\System32\swprv.dll - ok
21:39:08.0855 1936 [ 92D7A8B0F87B036F17D25885937897A6 ] C:\Windows\System32\sysmain.dll
21:39:08.0855 1936 C:\Windows\System32\sysmain.dll - ok
21:39:08.0855 1936 [ 005CE42567F9113A3BCCB3B20073B029 ] C:\Windows\System32\TabSvc.dll
21:39:08.0855 1936 C:\Windows\System32\TabSvc.dll - ok
21:39:08.0855 1936 [ CC2562B4D55E0B6A4758C65407F63B79 ] C:\Windows\System32\tapisrv.dll
21:39:08.0855 1936 C:\Windows\System32\tapisrv.dll - ok
21:39:08.0871 1936 [ CDBE8D7C1E201B911CDC346D06617FB5 ] C:\Windows\System32\tbssvc.dll
21:39:08.0871 1936 C:\Windows\System32\tbssvc.dll - ok
21:39:08.0871 1936 [ 5CDD30BC217082DAC71A9878D9BFD566 ] C:\Windows\System32\termsrv.dll
21:39:08.0871 1936 C:\Windows\System32\termsrv.dll - ok
21:39:08.0871 1936 [ 66328B08EF5A9305D8EDE36B93930369 ] C:\Windows\servicing\TrustedInstaller.exe
21:39:08.0871 1936 C:\Windows\servicing\TrustedInstaller.exe - ok
21:39:08.0886 1936 [ F4689F05AF472A651A7B1B7B02D200E7 ] C:\Windows\System32\trkwks.dll
21:39:08.0886 1936 C:\Windows\System32\trkwks.dll - ok
21:39:08.0886 1936 [ 060507C4113391394478F6953A79EEDC ] C:\Windows\System32\UI0Detect.exe
21:39:08.0886 1936 C:\Windows\System32\UI0Detect.exe - ok
21:39:08.0886 1936 [ 449F5AB17863698F12F0BC8E99079AA6 ] C:\Windows\System32\dwm.exe
21:39:08.0886 1936 C:\Windows\System32\dwm.exe - ok
21:39:08.0902 1936 [ 7093799FF80E9DECA0680D2E3535BE60 ] C:\Windows\System32\upnphost.dll
21:39:08.0902 1936 C:\Windows\System32\upnphost.dll - ok
21:39:08.0902 1936 [ 294945381DFA7CE58CECF0A9896AF327 ] C:\Windows\System32\vds.exe
21:39:08.0902 1936 C:\Windows\System32\vds.exe - ok
21:39:08.0902 1936 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] C:\Windows\System32\VSSVC.exe
21:39:08.0902 1936 C:\Windows\System32\VSSVC.exe - ok
21:39:08.0918 1936 [ F14A7DE2EA41883E250892E1E5230A9A ] C:\Windows\System32\w32time.dll
21:39:08.0918 1936 C:\Windows\System32\w32time.dll - ok
21:39:08.0918 1936 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] C:\Windows\System32\wcncsvc.dll
21:39:08.0918 1936 C:\Windows\System32\wcncsvc.dll - ok
21:39:08.0918 1936 [ 442783E2CB0DA19873B7A63833FF4CB4 ] C:\Windows\System32\drivers\Wdf01000.sys
21:39:08.0918 1936 C:\Windows\System32\drivers\Wdf01000.sys - ok
21:39:08.0918 1936 [ EA4B369560E986F19D93F45A881484AC ] C:\Windows\System32\WcsPlugInService.dll
21:39:08.0918 1936 C:\Windows\System32\WcsPlugInService.dll - ok
21:39:08.0933 1936 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] C:\Windows\System32\wdi.dll
21:39:08.0933 1936 C:\Windows\System32\wdi.dll - ok
21:39:08.0933 1936 [ 3E6D05381CF35F75EBB055544A8ED9AC ] C:\Windows\System32\WebClnt.dll
21:39:08.0933 1936 C:\Windows\System32\WebClnt.dll - ok
21:39:08.0933 1936 [ 8D40BC587993F876658BF9FB0F7D3462 ] C:\Windows\System32\wecsvc.dll
21:39:08.0933 1936 C:\Windows\System32\wecsvc.dll - ok
21:39:08.0949 1936 [ 9C980351D7E96288EA0C23AE232BD065 ] C:\Windows\System32\wercplsupport.dll
21:39:08.0949 1936 C:\Windows\System32\wercplsupport.dll - ok
21:39:08.0949 1936 [ 66B9ECEBC46683F47EDC06333C075FEF ] C:\Windows\System32\wersvc.dll
21:39:08.0949 1936 C:\Windows\System32\wersvc.dll - ok
21:39:08.0949 1936 [ A2D043408A2DC9CDE48CFF88FCD74662 ] C:\Windows\System32\winhttp.dll
21:39:08.0949 1936 C:\Windows\System32\winhttp.dll - ok
21:39:08.0964 1936 [ D2E7296ED1BD26D8DB2799770C077A02 ] C:\Windows\System32\wbem\WMIsvc.dll
21:39:08.0964 1936 C:\Windows\System32\wbem\WMIsvc.dll - ok
21:39:08.0964 1936 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] C:\Windows\System32\WsmSvc.dll
21:39:08.0964 1936 C:\Windows\System32\WsmSvc.dll - ok
21:39:08.0964 1936 [ EC339C8115E91BAED835957E9A677F16 ] C:\Windows\System32\wlansvc.dll
21:39:08.0964 1936 C:\Windows\System32\wlansvc.dll - ok
21:39:08.0980 1936 [ 21FA389E65A852698B6A1341F36EE02D ] C:\Windows\System32\wbem\WmiApSrv.exe
21:39:08.0980 1936 C:\Windows\System32\wbem\WmiApSrv.exe - ok
21:39:08.0980 1936 [ 56382A5EB85A25446745E3BD6D50A3A5 ] C:\Program Files\Windows Media Player\wmpnetwk.exe
21:39:08.0980 1936 C:\Program Files\Windows Media Player\wmpnetwk.exe - ok
21:39:08.0980 1936 [ CBC156C913F099E6680D1DF9307DB7A8 ] C:\Windows\System32\wpcsvc.dll
21:39:08.0980 1936 C:\Windows\System32\wpcsvc.dll - ok
21:39:08.0996 1936 [ 991E2C2CF3BC204C2BB2EE1476149E4E ] C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe
21:39:08.0996 1936 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe - ok
21:39:08.0996 1936 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] C:\Windows\System32\wpdbusenum.dll
21:39:08.0996 1936 C:\Windows\System32\wpdbusenum.dll - ok
21:39:08.0996 1936 [ A2AC37A1EEF83BD9E912B0EFCBEA06BD ] C:\Windows\System32\SearchIndexer.exe
21:39:08.0996 1936 C:\Windows\System32\SearchIndexer.exe - ok
21:39:09.0011 1936 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] C:\Windows\System32\wscsvc.dll
21:39:09.0011 1936 C:\Windows\System32\wscsvc.dll - ok
21:39:09.0011 1936 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] C:\Windows\System32\wuaueng.dll
21:39:09.0011 1936 C:\Windows\System32\wuaueng.dll - ok
21:39:09.0011 1936 [ AB886378EEB55C6C75B4F2D14B6C869F ] C:\Windows\System32\drivers\WUDFPf.sys
21:39:09.0011 1936 C:\Windows\System32\drivers\WUDFPf.sys - ok
21:39:09.0011 1936 [ B20F051B03A966392364C83F009F7D17 ] C:\Windows\System32\WUDFSvc.dll
21:39:09.0011 1936 C:\Windows\System32\WUDFSvc.dll - ok
21:39:09.0027 1936 [ 9922ADB6DCA8F0F5EA038BEFF339C08B ] C:\Windows\System32\scecli.dll
21:39:09.0027 1936 C:\Windows\System32\scecli.dll - ok
21:39:09.0027 1936 [ EE3718BCF5CEF1C457C10A745E410959 ] C:\Windows\System32\ntmarta.dll
21:39:09.0027 1936 C:\Windows\System32\ntmarta.dll - ok
21:39:09.0027 1936 [ CDA9F1373805AF88F6FA4F2064BBA24D ] C:\Windows\System32\svchost.exe
21:39:09.0027 1936 C:\Windows\System32\svchost.exe - ok
21:39:09.0042 1936 [ 7823A58BF0FE3CAAA555C12B5CF91290 ] C:\Windows\System32\powrprof.dll
21:39:09.0042 1936 C:\Windows\System32\powrprof.dll - ok
21:39:09.0042 1936 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] C:\Windows\System32\drivers\luafv.sys
21:39:09.0042 1936 C:\Windows\System32\drivers\luafv.sys - ok
21:39:09.0042 1936 [ 0BB97D43299910CBFBA59C461B99B910 ] C:\Windows\System32\drivers\mbam.sys
21:39:09.0042 1936 C:\Windows\System32\drivers\mbam.sys - ok
21:39:09.0058 1936 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] C:\Windows\System32\rpcss.dll
21:39:09.0058 1936 C:\Windows\System32\rpcss.dll - ok
21:39:09.0058 1936 [ EA3D2B63BA304EB6EDABBAFA21599B47 ] C:\Windows\System32\version.dll
21:39:09.0058 1936 C:\Windows\System32\version.dll - ok
21:39:09.0074 1936 [ 0EEECDBEF762EA200CDA68989F229A95 ] C:\Windows\System32\wpclsp.dll
21:39:09.0074 1936 C:\Windows\System32\wpclsp.dll - ok
21:39:09.0074 1936 [ 157E9E498206A3366BAA7E4697BDD947 ] C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe
21:39:09.0074 1936 C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe - ok
21:39:09.0074 1936 [ BAD79FECE1387CDD8388A3314645757F ] C:\Windows\System32\LogonUI.exe
21:39:09.0074 1936 C:\Windows\System32\LogonUI.exe - ok
21:39:09.0089 1936 [ 3BE92BF6408373B3CD8249D8CCBFB589 ] C:\Program Files\Microsoft Security Client\Antimalware\MpSvc.dll
21:39:09.0089 1936 C:\Program Files\Microsoft Security Client\Antimalware\MpSvc.dll - ok
21:39:09.0089 1936 [ BC8BEA88A6FB74C7D2E2FD101F83088E ] C:\Program Files\Microsoft Security Client\Antimalware\MpClient.dll
21:39:09.0089 1936 C:\Program Files\Microsoft Security Client\Antimalware\MpClient.dll - ok
21:39:09.0089 1936 [ 08C16507241D274FF9B583E5C4F9DBC8 ] C:\Windows\System32\wintrust.dll
21:39:09.0089 1936 C:\Windows\System32\wintrust.dll - ok
21:39:09.0105 1936 [ 6C2D2558DECB89C83873F80160D19F2C ] C:\Windows\System32\wtsapi32.dll
21:39:09.0105 1936 C:\Windows\System32\wtsapi32.dll - ok
21:39:09.0105 1936 [ 363D07C0F427C72BDE0B6D6492A205C9 ] C:\Windows\System32\authui.dll
21:39:09.0105 1936 C:\Windows\System32\authui.dll - ok
21:39:09.0105 1936 [ AE2CFE0E07E3A1368455621E9F389A74 ] C:\Program Files\Microsoft Security Client\eppmanifest.dll
21:39:09.0105 1936 C:\Program Files\Microsoft Security Client\eppmanifest.dll - ok
21:39:09.0120 1936 [ D883BD7C5BA86AE7D442C3A24F13A46D ] C:\Windows\System32\p2pcollab.dll
21:39:09.0120 1936 C:\Windows\System32\p2pcollab.dll - ok
21:39:09.0120 1936 [ 6B58266234B36ABCDD43C797B0D1932E ] C:\Windows\System32\msimg32.dll
21:39:09.0120 1936 C:\Windows\System32\msimg32.dll - ok
21:39:09.0120 1936 [ 88DBC757681093478BC80211C21695E5 ] C:\Windows\System32\uxtheme.dll
21:39:09.0120 1936 C:\Windows\System32\uxtheme.dll - ok
21:39:09.0136 1936 [ 4EAC411F90DCDE41D05D8184DE335524 ] C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_56abd97bb593eaca\GdiPlus.dll
21:39:09.0136 1936 C:\Windows\winsxs\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_56abd97bb593eaca\GdiPlus.dll - ok
21:39:09.0136 1936 [ 16881B42E07390FAA8C7331E9B8316A7 ] C:\Windows\System32\duser.dll
21:39:09.0136 1936 C:\Windows\System32\duser.dll - ok
21:39:09.0136 1936 [ 273E922CAC941789D2CEC9575868A007 ] C:\Program Files\Microsoft Security Client\Antimalware\MpRTP.dll
21:39:09.0136 1936 C:\Program Files\Microsoft Security Client\Antimalware\MpRTP.dll - ok
21:39:09.0152 1936 [ 4809DCE75464A833A5F37FB9AF5FB824 ] C:\Windows\System32\fltLib.dll
21:39:09.0152 1936 C:\Windows\System32\fltLib.dll - ok
21:39:09.0152 1936 [ 656CF740A2FDB99664A91C439D05C0ED ] C:\Windows\System32\xmllite.dll
21:39:09.0152 1936 C:\Windows\System32\xmllite.dll - ok
21:39:09.0167 1936 [ C177A7EBF5E8A0B596F618870516CAB8 ] C:\Program Files\Microsoft Security Client\Antimalware\Drivers\mpfilter\mpfilter.sys
21:39:09.0167 1936 C:\Program Files\Microsoft Security Client\Antimalware\Drivers\mpfilter\mpfilter.sys - ok
21:39:09.0167 1936 [ EDB781CD523181E15C85C78379153BE6 ] C:\Program Files\Microsoft Security Client\Antimalware\MsMpLics.dll
21:39:09.0167 1936 C:\Program Files\Microsoft Security Client\Antimalware\MsMpLics.dll - ok
21:39:09.0183 1936 [ 7834915B94BB680736F629A61BABABD3 ] C:\Program Files\Microsoft Security Client\Antimalware\NisIpsPlugin.dll
21:39:09.0183 1936 C:\Program Files\Microsoft Security Client\Antimalware\NisIpsPlugin.dll - ok
21:39:09.0183 1936 [ 75C6A1BC1E47BC5B5E2EF503F8A7CE8F ] C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpengine.dll
21:39:09.0183 1936 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpengine.dll - ok
21:39:09.0183 1936 [ C501852F1CA40FFC55363ACC0D2DF5BA ] C:\Windows\System32\SmartcardCredentialProvider.dll
21:39:09.0183 1936 C:\Windows\System32\SmartcardCredentialProvider.dll - ok
21:39:09.0198 1936 [ E3041BC26D6930D61F42AEDB79C91720 ] C:\Windows\System32\drivers\fltMgr.sys
21:39:09.0198 1936 C:\Windows\System32\drivers\fltMgr.sys - ok
21:39:09.0198 1936 [ F59CF3BFE865EB795C5DE5850F48B321 ] C:\Windows\System32\rasplap.dll
21:39:09.0198 1936 C:\Windows\System32\rasplap.dll - ok
21:39:09.0198 1936 [ 99AA51A6AE40DED4A74776E6E1C066C1 ] C:\Windows\System32\adtschema.dll
21:39:09.0198 1936 C:\Windows\System32\adtschema.dll - ok
21:39:09.0214 1936 [ A4F3F34A7146D8633FA8D346535A9CAA ] C:\Windows\System32\rasapi32.dll
21:39:09.0214 1936 C:\Windows\System32\rasapi32.dll - ok
21:39:09.0214 1936 [ C30BD20F185A47DCD4FD05F5AE1BC077 ] C:\Windows\System32\rasman.dll
21:39:09.0214 1936 C:\Windows\System32\rasman.dll - ok
21:39:09.0214 1936 [ F0884FA3E83C79775BF89C74DD28B616 ] C:\Windows\System32\tapi32.dll
21:39:09.0214 1936 C:\Windows\System32\tapi32.dll - ok
21:39:09.0230 1936 [ F1D25FB6A8BF8FBAE49717B684670393 ] C:\Windows\System32\rtutils.dll
21:39:09.0230 1936 C:\Windows\System32\rtutils.dll - ok
21:39:09.0230 1936 [ 7500278FEF4A66B0D76D8438F0295F4E ] C:\Windows\System32\winmm.dll
21:39:09.0230 1936 C:\Windows\System32\winmm.dll - ok
21:39:09.0230 1936 [ 9E693C6146932B5369DFFA584E805EF6 ] C:\Windows\System32\PSHED.DLL
21:39:09.0230 1936 C:\Windows\System32\PSHED.DLL - ok
21:39:09.0245 1936 [ D58A65112AE355CADFABEEFC8D329A8F ] C:\Windows\System32\oleacc.dll
21:39:09.0245 1936 C:\Windows\System32\oleacc.dll - ok
21:39:09.0245 1936 [ B1D4BB8DFD7128A90982562268920724 ] C:\Windows\System32\WinSCard.dll
21:39:09.0245 1936 C:\Windows\System32\WinSCard.dll - ok
21:39:09.0245 1936 [ FE13271EF661F8BE83A1A0D3366164D0 ] C:\Windows\System32\propsys.dll
21:39:09.0245 1936 C:\Windows\System32\propsys.dll - ok
21:39:09.0261 1936 [ 4CEA4255CAE84BF21FCA9A2827E16CBB ] C:\Windows\System32\shacct.dll
21:39:09.0261 1936 C:\Windows\System32\shacct.dll - ok
21:39:09.0261 1936 [ 00C7DAFAD08FAD59E51EB9A1F90925DE ] C:\Windows\System32\shgina.dll
21:39:09.0261 1936 C:\Windows\System32\shgina.dll - ok
21:39:09.0261 1936 [ 303C4EB5C2FB40F194E2B24CAD7148EF ] C:\Windows\System32\MMDevAPI.dll
21:39:09.0261 1936 C:\Windows\System32\MMDevAPI.dll - ok
21:39:09.0276 1936 [ 73F18E253DF8E0A9CE5FC45E62FB1945 ] C:\Windows\System32\cabinet.dll
21:39:09.0276 1936 C:\Windows\System32\cabinet.dll - ok
21:39:09.0276 1936 [ 514A07C903607458B6B5A430B09BF794 ] C:\Windows\System32\avrt.dll
21:39:09.0276 1936 C:\Windows\System32\avrt.dll - ok
21:39:09.0276 1936 [ EA47AF4FBF17580D093C0C36C4E49921 ] C:\Windows\System32\dsound.dll
21:39:09.0276 1936 C:\Windows\System32\dsound.dll - ok
21:39:09.0292 1936 [ BBE908D577A51C6D684CAB6126FBF7F2 ] C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpasbase.vdm
21:39:09.0292 1936 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpasbase.vdm - ok
21:39:09.0292 1936 [ 7F633AC83782EB0E8ADE513B8A1A9BC8 ] C:\Windows\System32\audiodg.exe
21:39:09.0292 1936 C:\Windows\System32\audiodg.exe - ok
21:39:09.0292 1936 [ 360DBFEC6D5F4B6EE2431742D295DF88 ] C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpasdlta.vdm
21:39:09.0292 1936 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpasdlta.vdm - ok
21:39:09.0308 1936 [ 00000000000000000000000000000000 ] C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpavbase.vdm
21:39:09.0308 1936 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpavbase.vdm - ok
21:39:09.0308 1936 [ A2786F1F49E354EFEE7BF5BCDB9E0231 ] C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpavdlta.vdm
21:39:09.0308 1936 C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1297FF89-3CC9-4AEC-BEF5-9C4705AB0BD4}\mpavdlta.vdm - ok
21:39:09.0323 1936 [ 7972615E382EF39785FD45F136F64D8C ] C:\Windows\System32\FWPUCLNT.DLL
21:39:09.0323 1936 C:\Windows\System32\FWPUCLNT.DLL - ok
21:39:09.0323 1936 [ 705C190BF4A86B35C97A7622A539EDD1 ] C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe
21:39:09.0323 1936 C:\Program Files\Microsoft Security Client\Antimalware\MpCmdRun.exe - ok
21:39:09.0323 1936 [ 2CAB7B034B867AAB48D298F93D04BD3E ] C:\Windows\System32\wscapi.dll
21:39:09.0323 1936 C:\Windows\System32\wscapi.dll - ok
21:39:09.0339 1936 [ 6659BE539FCC60D9605167DE4C09ACA4 ] C:\Program Files\Microsoft Security Client\MsseWat.dll
21:39:09.0339 1936 C:\Program Files\Microsoft Security Client\MsseWat.dll - ok
21:39:09.0339 1936 [ D092AA9740076D7B55BA7E3ECD22DFA7 ] C:\Windows\System32\msi.dll
21:39:09.0339 1936 C:\Windows\System32\msi.dll - ok
21:39:09.0339 1936 [ 6B5DC9711FD15A0E944A4F17366E2300 ] C:\Windows\System32\slwga.dll
21:39:09.0339 1936 C:\Windows\System32\slwga.dll - ok
21:39:09.0354 1936 [ EBFA7A306C65010DED108F5A26598642 ] C:\Windows\System32\wscisvif.dll
21:39:09.0354 1936 C:\Windows\System32\wscisvif.dll - ok
21:39:09.0354 1936 [ 52A4F6983D85E74275DA0573FCD36094 ] C:\Windows\System32\wscproxystub.dll
21:39:09.0354 1936 C:\Windows\System32\wscproxystub.dll - ok
21:39:09.0354 1936 [ 7FC9AFDD2A2ACFCB52FB05D57FE8C2F4 ] C:\Windows\System32\atl.dll
21:39:09.0354 1936 C:\Windows\System32\atl.dll - ok
21:39:09.0370 1936 [ A0E1B575BA8F504968CD40C0FAEB2384 ] C:\Windows\System32\gpsvc.dll
21:39:09.0370 1936 C:\Windows\System32\gpsvc.dll - ok
21:39:09.0370 1936 [ C5EDECA7546B009484B23FAD0E9724C1 ] C:\Windows\System32\nlaapi.dll
21:39:09.0370 1936 C:\Windows\System32\nlaapi.dll - ok
21:39:09.0370 1936 [ 57D469072472C9F14125A347C522DD18 ] C:\Windows\System32\ci.dll
21:39:09.0370 1936 C:\Windows\System32\ci.dll - ok
21:39:09.0370 1936 [ 75C881C65CEF2C7B911EB0A351957368 ] C:\Windows\System32\drivers\spsys.sys
21:39:09.0370 1936 C:\Windows\System32\drivers\spsys.sys - ok
21:39:09.0386 1936 [ 48FEF0CD6C0D4CA428DE7024F297E1CD ] C:\Windows\System32\WindowsCodecs.dll
21:39:09.0386 1936 C:\Windows\System32\WindowsCodecs.dll - ok
21:39:09.0386 1936 [ E12F22B73F153DECE721CD45EC05B4AF ] C:\Windows\System32\es.dll
21:39:09.0386 1936 C:\Windows\System32\es.dll - ok
21:39:09.0386 1936 [ 56697D33950E5E83A4049F477BE7C320 ] C:\Windows\System32\hid.dll
21:39:09.0386 1936 C:\Windows\System32\hid.dll - ok
21:39:09.0401 1936 [ 0840ABBBDF438691EE65A20040635CBE ] C:\Program Files\Dell\DellDock\DockLogin.exe
21:39:09.0401 1936 C:\Program Files\Dell\DellDock\DockLogin.exe - ok
21:39:09.0401 1936 [ 6AAF63A85181E39F94EC0641C55A4EF0 ] C:\Windows\SysWOW64\ntdll.dll
21:39:09.0401 1936 C:\Windows\SysWOW64\ntdll.dll - ok
21:39:09.0401 1936 [ 813C216E14005CB42BBD1B037FCF030F ] C:\Windows\System32\wow64.dll
21:39:09.0401 1936 C:\Windows\System32\wow64.dll - ok
21:39:09.0417 1936 [ 8FE910915F14C9C6A9561D8032B603D3 ] C:\Windows\System32\wow64win.dll
21:39:09.0417 1936 C:\Windows\System32\wow64win.dll - ok
21:39:09.0417 1936 [ CA9EECC6092B9C2CE86D95C04B51BA20 ] C:\Windows\System32\wow64cpu.dll
21:39:09.0417 1936 C:\Windows\System32\wow64cpu.dll - ok
21:39:09.0417 1936 [ D59DD2AAFF94EAB9BD6C7940C2851735 ] C:\Windows\SysWOW64\kernel32.dll
21:39:09.0417 1936 C:\Windows\SysWOW64\kernel32.dll - ok
21:39:09.0432 1936 [ 50CAA7072C171B9887215C83D52069E4 ] C:\Windows\SysWOW64\advapi32.dll
21:39:09.0432 1936 C:\Windows\SysWOW64\advapi32.dll - ok
21:39:09.0432 1936 [ 17AF64D727545F2804F6E6D998327E3F ] C:\Windows\SysWOW64\msvcrt.dll
21:39:09.0432 1936 C:\Windows\SysWOW64\msvcrt.dll - ok
21:39:09.0432 1936 [ 0ABE67004EB4C162F4456E64F90A11FD ] C:\Windows\SysWOW64\rpcrt4.dll
21:39:09.0432 1936 C:\Windows\SysWOW64\rpcrt4.dll - ok
21:39:09.0448 1936 [ F42483814FC39170B3982A184EC5AAA2 ] C:\Windows\SysWOW64\wtsapi32.dll
21:39:09.0448 1936 C:\Windows\SysWOW64\wtsapi32.dll - ok
21:39:09.0448 1936 [ 05C8C8767E29163FC251164FF6839EA5 ] C:\Windows\SysWOW64\gdi32.dll
21:39:09.0448 1936 C:\Windows\SysWOW64\gdi32.dll - ok
21:39:09.0448 1936 [ 3D4DD2D3D59ABE3BA902778C57D2E004 ] C:\Windows\SysWOW64\secur32.dll
21:39:09.0448 1936 C:\Windows\SysWOW64\secur32.dll - ok
21:39:09.0464 1936 [ 420B075CD71AB9E58D15DD258958FBA3 ] C:\Windows\SysWOW64\shlwapi.dll
21:39:09.0464 1936 C:\Windows\SysWOW64\shlwapi.dll - ok
21:39:09.0464 1936 [ D29FDB5DEDBDC1BD882164DC6DC4DD53 ] C:\Windows\SysWOW64\user32.dll
21:39:09.0464 1936 C:\Windows\SysWOW64\user32.dll - ok
21:39:09.0464 1936 [ B8FBE5F40B09F5D20E1E5CCFEF893D62 ] C:\Windows\SysWOW64\imm32.dll
21:39:09.0464 1936 C:\Windows\SysWOW64\imm32.dll - ok
21:39:09.0479 1936 [ DF37346EA13082E3E1B423B54014E641 ] C:\Windows\SysWOW64\lpk.dll
21:39:09.0479 1936 C:\Windows\SysWOW64\lpk.dll - ok
21:39:09.0479 1936 [ E3C3BD69701CE6B7B17101E4F7740534 ] C:\Windows\SysWOW64\msctf.dll
21:39:09.0479 1936 C:\Windows\SysWOW64\msctf.dll - ok
21:39:09.0479 1936 [ 80FFF14F1757B9AF8BE9D314FC1AE88B ] C:\Windows\SysWOW64\usp10.dll
21:39:09.0479 1936 C:\Windows\SysWOW64\usp10.dll - ok
21:39:09.0495 1936 [ BE3C082837866C4C291ADAF163C10EA6 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
21:39:09.0495 1936 C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll - ok
21:39:09.0495 1936 [ 9586E7CB2255A8B097A7E4538202585E ] C:\Windows\SysWOW64\ole32.dll
21:39:09.0495 1936 C:\Windows\SysWOW64\ole32.dll - ok
21:39:09.0495 1936 [ B218342214D9BBA0F54EA12BA2E9278C ] C:\Windows\SysWOW64\oleaut32.dll
21:39:09.0495 1936 C:\Windows\SysWOW64\oleaut32.dll - ok
21:39:09.0495 1936 [ 71D8D1FD4989932674CD1F5743191286 ] C:\Windows\SysWOW64\urlmon.dll
21:39:09.0495 1936 C:\Windows\SysWOW64\urlmon.dll - ok
21:39:09.0510 1936 [ 6057AA7FDF03309A18FAE4E9FCFE7D8F ] C:\Windows\SysWOW64\iertutil.dll
21:39:09.0510 1936 C:\Windows\SysWOW64\iertutil.dll - ok
21:39:09.0510 1936 [ D76E231E4850BB3F88A3D9A78DF191E3 ] C:\Windows\System32\uxsms.dll
21:39:09.0510 1936 C:\Windows\System32\uxsms.dll - ok
21:39:09.0510 1936 [ 6A25377A76479A0C0BF3DB6FC42FE09A ] C:\Windows\SysWOW64\wininet.dll
21:39:09.0510 1936 C:\Windows\SysWOW64\wininet.dll - ok
21:39:09.0526 1936 [ B1DF2D87DC8BF6072699AC8301B37796 ] C:\Windows\System32\WUDFPlatform.dll
21:39:09.0526 1936 C:\Windows\System32\WUDFPlatform.dll - ok
21:39:09.0526 1936 [ 96ECE2659B6654C10A0C310AE3A6D02C ] C:\Windows\System32\drivers\lltdio.sys
21:39:09.0526 1936 C:\Windows\System32\drivers\lltdio.sys - ok
21:39:09.0542 1936 [ 43E24699A18126F11E3D9BF6DB85518B ] C:\Windows\System32\drivers\packet.sys
21:39:09.0542 1936 C:\Windows\System32\drivers\packet.sys - ok
21:39:09.0542 1936 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] C:\Windows\System32\drivers\rspndr.sys
21:39:09.0542 1936 C:\Windows\System32\drivers\rspndr.sys - ok
21:39:09.0542 1936 [ 5532C4BF15173270757A75B46BAEB960 ] C:\Windows\System32\drivers\RtNdPt60.sys
21:39:09.0542 1936 C:\Windows\System32\drivers\RtNdPt60.sys - ok
21:39:09.0557 1936 [ 06230F1B721494A6DF8D47FD395BB1B0 ] C:\Windows\System32\dnsrslvr.dll
21:39:09.0557 1936 C:\Windows\System32\dnsrslvr.dll - ok
21:39:09.0557 1936 [ 09451F87CFF73FF22D9479FB0A73861C ] C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_41466cae55469b30\comctl32.dll
21:39:09.0557 1936 C:\Windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_41466cae55469b30\comctl32.dll - ok
21:39:09.0557 1936 [ 6B6D0747C1D56D5742F5171B57E8CB6F ] C:\Windows\System32\ktmw32.dll
21:39:09.0557 1936 C:\Windows\System32\ktmw32.dll - ok
21:39:09.0573 1936 [ 3ADB1950539C78F82EFD392BE98BE80D ] C:\Windows\System32\taskcomp.dll
21:39:09.0573 1936 C:\Windows\System32\taskcomp.dll - ok
21:39:09.0573 1936 [ 098F1E4E5C9CB5B0063A959063631610 ] C:\Windows\System32\drivers\http.sys
21:39:09.0573 1936 C:\Windows\System32\drivers\http.sys - ok
21:39:09.0573 1936 [ 808A26DA7028B02A081A5A1BCBF69A2A ] C:\Windows\System32\wiarpc.dll
21:39:09.0573 1936 C:\Windows\System32\wiarpc.dll - ok
21:39:09.0573 1936 [ D48445B07F61CAFE2FE8972AAB4E31B8 ] C:\Windows\System32\spoolss.dll
21:39:09.0573 1936 C:\Windows\System32\spoolss.dll - ok
21:39:09.0588 1936 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] C:\Windows\System32\drivers\srvnet.sys
21:39:09.0588 1936 C:\Windows\System32\drivers\srvnet.sys - ok
21:39:09.0588 1936 [ 2348447A80920B2493A9B582A23E81E1 ] C:\Windows\System32\drivers\bowser.sys
21:39:09.0588 1936 C:\Windows\System32\drivers\bowser.sys - ok
21:39:09.0588 1936 [ C92B9ABDB65A5991E00C28F13491DBA2 ] C:\Windows\System32\drivers\mpsdrv.sys
21:39:09.0588 1936 C:\Windows\System32\drivers\mpsdrv.sys - ok
21:39:09.0604 1936 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] C:\Windows\System32\drivers\mrxsmb.sys
21:39:09.0604 1936 C:\Windows\System32\drivers\mrxsmb.sys - ok
21:39:09.0604 1936 [ 897E3BAF68BA406A61682AE39C83900C ] C:\Windows\System32\MPSSVC.dll
21:39:09.0604 1936 C:\Windows\System32\MPSSVC.dll - ok
21:39:09.0604 1936 [ 3B929A60C833FC615FD97FBA82BC7632 ] C:\Windows\System32\drivers\mrxsmb10.sys
21:39:09.0604 1936 C:\Windows\System32\drivers\mrxsmb10.sys - ok
21:39:09.0620 1936 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] C:\Windows\System32\drivers\mrxsmb20.sys
21:39:09.0620 1936 C:\Windows\System32\drivers\mrxsmb20.sys - ok
21:39:09.0620 1936 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] C:\Windows\System32\drivers\srv2.sys
21:39:09.0620 1936 C:\Windows\System32\drivers\srv2.sys - ok
21:39:09.0620 1936 [ 880A57FCCB571EBD063D4DD50E93E46D ] C:\Windows\System32\drivers\srv.sys
21:39:09.0620 1936 C:\Windows\System32\drivers\srv.sys - ok
21:39:09.0635 1936 [ D1E792408F710173E4E4FB6BFB248DB3 ] C:\Windows\System32\wfapigp.dll
21:39:09.0635 1936 C:\Windows\System32\wfapigp.dll - ok
21:39:09.0635 1936 [ 87B1E9B5DBFADA04D9FFDC52D16CB000 ] C:\Windows\System32\mscms.dll
21:39:09.0635 1936 C:\Windows\System32\mscms.dll - ok
21:39:09.0635 1936 [ 7C00C608FE4C8EDE9E30940837B9AC8B ] C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll
21:39:09.0635 1936 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ServiceModelEvents.dll - ok
21:39:09.0635 1936 [ BED93F434CD291DEC110901F7343E000 ] C:\Windows\System32\dllhost.exe
21:39:09.0635 1936 C:\Windows\System32\dllhost.exe - ok
21:39:09.0651 1936 [ 129F59470F770A2675A39C245BC5AB3F ] C:\Windows\System32\WsmRes.dll
21:39:09.0651 1936 C:\Windows\System32\WsmRes.dll - ok
21:39:09.0651 1936 [ 1E68A512FB6010B600CBC3577147AC50 ] C:\Windows\System32\plasrv.exe
21:39:09.0651 1936 C:\Windows\System32\plasrv.exe - ok
21:39:09.0651 1936 [ AAF101900A23D75AE1AE00840FA6F3B8 ] C:\Windows\SysWOW64\shell32.dll
21:39:09.0651 1936 C:\Windows\SysWOW64\shell32.dll - ok
21:39:09.0666 1936 [ ED4EC7C21A3607A4CB7D36E9C5B90AB2 ] C:\Windows\System32\AtBroker.exe
21:39:09.0666 1936 C:\Windows\System32\AtBroker.exe - ok
21:39:09.0666 1936 [ A0AB2BB9A92293D9CE66E252719AB5FE ] C:\Windows\System32\userinit.exe
21:39:09.0666 1936 C:\Windows\System32\userinit.exe - ok
21:39:09.0666 1936 [ 1AD703C14E705F69D4ADF79154054173 ] C:\Windows\System32\dwmapi.dll
21:39:09.0666 1936 C:\Windows\System32\dwmapi.dll - ok
21:39:09.0682 1936 [ 665417528489096BBCB8AEA46D3DA924 ] C:\Windows\SysWOW64\userenv.dll
21:39:09.0682 1936 C:\Windows\SysWOW64\userenv.dll - ok
21:39:09.0682 1936 [ 4AAFC7461633848AA87A363B2CBEC522 ] C:\Windows\SysWOW64\winsta.dll
21:39:09.0682 1936 C:\Windows\SysWOW64\winsta.dll - ok
21:39:09.0682 1936 [ 98B656EAF128CD06F625B09C84D959E1 ] C:\Windows\SysWOW64\netapi32.dll
21:39:09.0682 1936 C:\Windows\SysWOW64\netapi32.dll - ok
21:39:09.0698 1936 [ 93A1732F7F997E36A5C3893539E2FF02 ] C:\Windows\SysWOW64\psapi.dll
21:39:09.0698 1936 C:\Windows\SysWOW64\psapi.dll - ok
21:39:09.0698 1936 [ EA85B96A8BFB435749C9004BC7340347 ] C:\Windows\System32\taskeng.exe
21:39:09.0698 1936 C:\Windows\System32\taskeng.exe - ok
21:39:09.0698 1936 [ 8449D81B9FB1CCADEC3E64F30E1076C7 ] C:\Windows\System32\winrnr.dll
21:39:09.0698 1936 C:\Windows\System32\winrnr.dll - ok
21:39:09.0713 1936 [ 70071E1657823DA231713D74A9CC8ECA ] C:\Windows\System32\rasadhlp.dll
21:39:09.0713 1936 C:\Windows\System32\rasadhlp.dll - ok
21:39:09.0713 1936 [ A78E7E16E8696172FF3F4147E6050DC3 ] C:\Windows\System32\dwmredir.dll
21:39:09.0713 1936 C:\Windows\System32\dwmredir.dll - ok
21:39:09.0713 1936 [ B77AD1818DBD476245B1281016E075E4 ] C:\Windows\System32\milcore.dll
21:39:09.0713 1936 C:\Windows\System32\milcore.dll - ok
21:39:09.0729 1936 [ 38573C7D9D91B316E6EE76E0C94F749E ] C:\Windows\System32\localspl.dll
21:39:09.0729 1936 C:\Windows\System32\localspl.dll - ok
21:39:09.0729 1936 [ 57D1DE90D43E25C9E645D81FFC4FB678 ] C:\Windows\System32\umb.dll
21:39:09.0729 1936 C:\Windows\System32\umb.dll - ok
21:39:09.0729 1936 [ 2CCA759379C220D29F0066CA49E9259F ] C:\Windows\System32\sfc.dll
21:39:09.0729 1936 C:\Windows\System32\sfc.dll - ok
21:39:09.0744 1936 [ FEB771AF00A645DCA8A7D07CC33F7E8E ] C:\Windows\System32\winspool.drv
21:39:09.0744 1936 C:\Windows\System32\winspool.drv - ok
21:39:09.0744 1936 [ D4175BE7CA634C7BB9205F7EE4F3F7E4 ] C:\Windows\System32\d3d9.dll
21:39:09.0744 1936 C:\Windows\System32\d3d9.dll - ok
21:39:09.0744 1936 [ E6409B960CCAA48F292A4808E00167C8 ] C:\Windows\System32\d3d8thk.dll
21:39:09.0744 1936 C:\Windows\System32\d3d8thk.dll - ok
21:39:09.0760 1936 [ 9C253164E7016B42591F08BEB90FB494 ] C:\Windows\System32\igdumd64.dll
21:39:09.0760 1936 C:\Windows\System32\igdumd64.dll - ok
21:39:09.0760 1936 [ 74D59F72104C9FF8D154D1AB372A5A57 ] C:\Windows\System32\tcpmon.dll
21:39:09.0760 1936 C:\Windows\System32\tcpmon.dll - ok
21:39:09.0760 1936 [ 6B08E54A451B3F95E4109DBA7E594270 ] C:\Windows\explorer.exe
21:39:09.0760 1936 C:\Windows\explorer.exe - ok
21:39:09.0776 1936 [ 943F05B78BC03F3463FCE26D4B5B81A9 ] C:\Windows\System32\snmpapi.dll
21:39:09.0776 1936 C:\Windows\System32\snmpapi.dll - ok
21:39:09.0776 1936 [ 57120423BC6342F0EAE16E3720184D5A ] C:\Windows\System32\wsnmp32.dll
21:39:09.0776 1936 C:\Windows\System32\wsnmp32.dll - ok
21:39:09.0776 1936 [ 18ADF933B54C8953FCC3EEAB4EAF4A63 ] C:\Windows\System32\TSChannel.dll
21:39:09.0776 1936 C:\Windows\System32\TSChannel.dll - ok
21:39:09.0776 1936 [ 8F0DE4FEF8201E306F9938B0905AC96A ] C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
21:39:09.0776 1936 C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - ok
21:39:09.0791 1936 [ 8B517F63A5B87F8FFAC2145F0673498A ] C:\Windows\System32\msxml6.dll
21:39:09.0791 1936 C:\Windows\System32\msxml6.dll - ok
21:39:09.0791 1936 [ 4B7BB89AFC32632F775D8A3E62FCA979 ] C:\Windows\System32\mgmtapi.dll
21:39:09.0791 1936 C:\Windows\System32\mgmtapi.dll - ok
21:39:09.0791 1936 [ 7BCB22C93FF0E90683F3513531E2990B ] C:\Windows\System32\tcpmib.dll
21:39:09.0791 1936 C:\Windows\System32\tcpmib.dll - ok
21:39:09.0807 1936 [ 5948F2B4FECE4F3301D290771F5183CF ] C:\Windows\System32\usbmon.dll
21:39:09.0807 1936 C:\Windows\System32\usbmon.dll - ok
21:39:09.0807 1936 [ 4DBD8795D3B9DC5BF13CF116464D2B69 ] C:\Windows\System32\dldtlmpm.dll
21:39:09.0807 1936 C:\Windows\System32\dldtlmpm.dll - ok
21:39:09.0807 1936 [ 53878FDAD2538A20A5FF5D5794FE67B0 ] C:\Windows\System32\dldtcomc.dll
21:39:09.0807 1936 C:\Windows\System32\dldtcomc.dll - ok
21:39:09.0822 1936 [ 7B005E3F9825A98312E089CBA0F83DAA ] C:\Windows\System32\uDWM.dll
21:39:09.0822 1936 C:\Windows\System32\uDWM.dll - ok
21:39:09.0822 1936 [ 83C40E549A455843A387A75E112DA490 ] C:\Windows\System32\dldtcoms.exe
21:39:09.0822 1936 C:\Windows\System32\dldtcoms.exe - ok
21:39:09.0822 1936 [ 5F0501B0C731E7F2DDE196E3A32E3500 ] C:\Windows\System32\PlaySndSrv.dll
21:39:09.0822 1936 C:\Windows\System32\PlaySndSrv.dll - ok
21:39:09.0838 1936 [ AD8DDBB13B341B931CC9229BBC9D0625 ] C:\Windows\System32\HotStartUserAgent.dll
21:39:09.0838 1936 C:\Windows\System32\HotStartUserAgent.dll - ok
21:39:09.0838 1936 [ B420EB9D254C2C16CCFBB09BCC6AB113 ] C:\Windows\System32\MsCtfMonitor.dll
21:39:09.0838 1936 C:\Windows\System32\MsCtfMonitor.dll - ok
21:39:09.0838 1936 [ AD27B41DA928C0338E6F364BE928D3F7 ] C:\Windows\System32\msutb.dll
21:39:09.0838 1936 C:\Windows\System32\msutb.dll - ok
21:39:09.0854 1936 [ 9DCAA0F7D8EC0C07BBBE724041DB7AC5 ] C:\Windows\System32\shdocvw.dll
21:39:09.0854 1936 C:\Windows\System32\shdocvw.dll - ok
21:39:09.0854 1936 [ EE9040473EB1339E75E79A75FA47A825 ] C:\Windows\System32\browseui.dll
21:39:09.0854 1936 C:\Windows\System32\browseui.dll - ok
21:39:09.0854 1936 [ 17BF3BF5296936B153FDDDA189B60E07 ] C:\Windows\System32\ksuser.dll
21:39:09.0854 1936 C:\Windows\System32\ksuser.dll - ok
21:39:09.0869 1936 [ 35FBB6F5993C9EE70CDB72CC8AAB5D38 ] C:\Windows\System32\wdmaud.drv
21:39:09.0869 1936 C:\Windows\System32\wdmaud.drv - ok
21:39:09.0869 1936 [ EEFDA2A090E8000740D46B09DCDBEAFF ] C:\Windows\System32\AudioSes.dll
21:39:09.0869 1936 C:\Windows\System32\AudioSes.dll - ok
21:39:09.0869 1936 [ CE2D962D80B6066DCBAE1F2E789A33B3 ] C:\Windows\System32\dldtserv.dll
21:39:09.0869 1936 C:\Windows\System32\dldtserv.dll - ok
21:39:09.0885 1936 [ B2E32F41E1D6500F62CAEF5EF2B17196 ] C:\Windows\System32\EhStorShell.dll
21:39:09.0885 1936 C:\Windows\System32\EhStorShell.dll - ok
21:39:09.0885 1936 [ A1A408E9F8C2DB9C3B3BA21C25CCF9C3 ] C:\Windows\System32\AudioEng.dll
21:39:09.0885 1936 C:\Windows\System32\AudioEng.dll - ok
21:39:09.0885 1936 [ EDC41901878A99EA11765F5536CCAE67 ] C:\Windows\System32\imageres.dll
21:39:09.0885 1936 C:\Windows\System32\imageres.dll - ok
21:39:09.0900 1936 [ 215DFBEF790637C2B9C02BB23C9887EB ] C:\Windows\System32\msacm32.dll
21:39:09.0900 1936 C:\Windows\System32\msacm32.dll - ok
21:39:09.0900 1936 [ 9A328CC4E4490E929E30332AC902CAC1 ] C:\Windows\System32\msacm32.drv
21:39:09.0900 1936 C:\Windows\System32\msacm32.drv - ok
21:39:09.0900 1936 [ 1107BD574A84367735FEC38B9BD64E6B ] C:\Windows\SysWOW64\apphelp.dll
21:39:09.0900 1936 C:\Windows\SysWOW64\apphelp.dll - ok
21:39:09.0916 1936 [ 1DACD1530C6E58AEAE9F6DE7DA851935 ] C:\Windows\SysWOW64\shimeng.dll
21:39:09.0916 1936 C:\Windows\SysWOW64\shimeng.dll - ok
21:39:09.0916 1936 [ 758D99511FD82B6C55E70494039E9F1A ] C:\Program Files (x86)\Google\Update\1.3.21.145\goopdate.dll
21:39:09.0916 1936 C:\Program Files (x86)\Google\Update\1.3.21.145\goopdate.dll - ok
21:39:09.0916 1936 [ 39E31335D6F6BC1C8E3AB89784D8EB1F ] C:\Windows\System32\dldtinpa.dll
21:39:09.0916 1936 C:\Windows\System32\dldtinpa.dll - ok
21:39:09.0916 1936 [ 62BDB059ED8AE0C63E33BBF990941E0F ] C:\Windows\System32\midimap.dll
21:39:09.0916 1936 C:\Windows\System32\midimap.dll - ok
21:39:09.0932 1936 [ 4FE8425F21B3F0F8C4B4726351D43EAA ] C:\Windows\SysWOW64\IPHLPAPI.DLL
21:39:09.0932 1936 C:\Windows\SysWOW64\IPHLPAPI.DLL - ok
21:39:09.0932 1936 [ C7B465BE6D908AAFF0D8DBAFA95B089F ] C:\Windows\System32\dldtiesc.dll
21:39:09.0932 1936 C:\Windows\System32\dldtiesc.dll - ok
21:39:09.0932 1936 [ 54289361E9150C2D03E68AA6DEEF171F ] C:\Windows\SysWOW64\crypt32.dll
21:39:09.0932 1936 C:\Windows\SysWOW64\crypt32.dll - ok
21:39:09.0947 1936 [ 9028559C132146FB75EB7ACF384B086A ] C:\Windows\SysWOW64\dhcpcsvc.dll
21:39:09.0947 1936 C:\Windows\SysWOW64\dhcpcsvc.dll - ok
21:39:09.0947 1936 [ DFB6B71CDABA9DFB49C9D2B318B97A1A ] C:\Windows\SysWOW64\dhcpcsvc6.dll
21:39:09.0947 1936 C:\Windows\SysWOW64\dhcpcsvc6.dll - ok
21:39:09.0947 1936 [ 85E861D0B88DB2B54ACB0839654C09F7 ] C:\Windows\SysWOW64\dnsapi.dll
21:39:09.0947 1936 C:\Windows\SysWOW64\dnsapi.dll - ok
21:39:09.0963 1936 [ A64AEBC6C78B4CFD7F41A7277879DF8F ] C:\Windows\SysWOW64\nsi.dll
21:39:09.0963 1936 C:\Windows\SysWOW64\nsi.dll - ok
21:39:09.0963 1936 [ 6B09105742C75DF80CEF21700F20F55A ] C:\Windows\SysWOW64\winnsi.dll
21:39:09.0963 1936 C:\Windows\SysWOW64\winnsi.dll - ok
21:39:09.0963 1936 [ B304D47D5744BA20FCB99FB8B2C07B0B ] C:\Windows\SysWOW64\ws2_32.dll
21:39:09.0963 1936 C:\Windows\SysWOW64\ws2_32.dll - ok
21:39:09.0978 1936 [ 33EB2C6C0A1F011638E33B3FDCE9451E ] C:\Windows\System32\dldtusb1.dll
21:39:09.0978 1936 C:\Windows\System32\dldtusb1.dll - ok
21:39:09.0978 1936 [ EB49FAA5EBBC06356FB12476438781B9 ] C:\Windows\SysWOW64\imagehlp.dll
21:39:09.0978 1936 C:\Windows\SysWOW64\imagehlp.dll - ok
21:39:09.0978 1936 [ EE2FF9A3FC4404234BE3B7C6AA383AF8 ] C:\Windows\SysWOW64\msasn1.dll
21:39:09.0978 1936 C:\Windows\SysWOW64\msasn1.dll - ok
21:39:09.0978 1936 [ 401DFFDBBBD3F07C747ED1AE2BB88106 ] C:\Windows\SysWOW64\msi.dll
21:39:09.0978 1936 C:\Windows\SysWOW64\msi.dll - ok
21:39:09.0994 1936 [ 8F5484CC5EF3E6B1AA5D45BB84E3F047 ] C:\Windows\System32\dldthbn3.dll
21:39:09.0994 1936 C:\Windows\System32\dldthbn3.dll - ok
21:39:09.0994 1936 [ B62ADA3FB14ADD4AE11F79DB8A4BE9D6 ] C:\Windows\System32\DLDThcp.dll
21:39:09.0994 1936 C:\Windows\System32\DLDThcp.dll - ok
21:39:09.0994 1936 [ D922592AB65C5D9B88B30B4510A3464E ] C:\Windows\SysWOW64\cscapi.dll
21:39:09.0994 1936 C:\Windows\SysWOW64\cscapi.dll - ok
21:39:09.0994 1936 [ 69827805A221C21450BA22F4326A2EE3 ] C:\Windows\SysWOW64\version.dll
21:39:09.0994 1936 C:\Windows\SysWOW64\version.dll - ok
21:39:10.0010 1936 [ B2E569EF26DAC9D6994A2AFF4F601B7A ] C:\Windows\SysWOW64\wintrust.dll
21:39:10.0010 1936 C:\Windows\SysWOW64\wintrust.dll - ok
21:39:10.0010 1936 [ 4934241CD20AC87D78121352E3BA8318 ] C:\Windows\SysWOW64\dbghelp.dll
21:39:10.0010 1936 C:\Windows\SysWOW64\dbghelp.dll - ok
21:39:10.0010 1936 [ CD08EEC61C591AF59A39F4363C567D30 ] C:\Windows\SysWOW64\ntmarta.dll
21:39:10.0010 1936 C:\Windows\SysWOW64\ntmarta.dll - ok
21:39:10.0025 1936 [ 453DE2958C885527E20C79A3FEFE6AF7 ] C:\Windows\SysWOW64\samlib.dll
21:39:10.0025 1936 C:\Windows\SysWOW64\samlib.dll - ok
21:39:10.0025 1936 [ B8A609FB5EFB4E44FC1355B1C01C64BC ] C:\Windows\SysWOW64\Wldap32.dll
21:39:10.0025 1936 C:\Windows\SysWOW64\Wldap32.dll - ok
21:39:10.0025 1936 [ 76B35CB0F3A4E69D6DFF27F542B9F856 ] C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe
21:39:10.0025 1936 C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe - ok
21:39:10.0041 1936 [ A45D8543AE13502984366767D7A4B4CD ] C:\Windows\System32\IconCodecService.dll
21:39:10.0041 1936 C:\Windows\System32\IconCodecService.dll - ok
21:39:10.0041 1936 [ 4E252E85E5DC31BD645E809222AFAF27 ] C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe
21:39:10.0041 1936 C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe - ok
21:39:10.0041 1936 [ C394079EB162E812D682C73FA96AF6E4 ] C:\Windows\SysWOW64\clbcatq.dll
21:39:10.0041 1936 C:\Windows\SysWOW64\clbcatq.dll - ok
21:39:10.0056 1936 [ 73FD66B14D3C4252F7A524B8836A4359 ] C:\Windows\SysWOW64\mstask.dll
21:39:10.0056 1936 C:\Windows\SysWOW64\mstask.dll - ok
21:39:10.0056 1936 [ 4AA2A0E26CEF1A803741253DCF9A1503 ] C:\Windows\SysWOW64\comdlg32.dll
21:39:10.0056 1936 C:\Windows\SysWOW64\comdlg32.dll - ok
21:39:10.0056 1936 [ 7F0F1D4B0D847696F8E309423D227DCE ] C:\Windows\SysWOW64\ntdsapi.dll
21:39:10.0056 1936 C:\Windows\SysWOW64\ntdsapi.dll - ok
21:39:10.0072 1936 [ 75C34D22D3E7D1D0238B62C55F604BFC ] C:\Windows\System32\cscapi.dll
21:39:10.0072 1936 C:\Windows\System32\cscapi.dll - ok
21:39:10.0072 1936 [ 900B9B25C345AAA4F90913BA9AECABF4 ] C:\Windows\System32\dbghelp.dll
21:39:10.0072 1936 C:\Windows\System32\dbghelp.dll - ok
21:39:10.0072 1936 [ 2EDBDB75D2F41386804B2CB53C572E75 ] C:\Windows\System32\TMM.dll
21:39:10.0072 1936 C:\Windows\System32\TMM.dll - ok
21:39:10.0088 1936 [ 26FCA3C514D316FF52560577990CD693 ] C:\Windows\System32\igfxTMM.dll
21:39:10.0088 1936 C:\Windows\System32\igfxTMM.dll - ok
21:39:10.0088 1936 [ DE0EED5106BD03CE11CDBF690285FE6C ] C:\Windows\System32\WSDMon.dll
21:39:10.0088 1936 C:\Windows\System32\WSDMon.dll - ok
21:39:10.0088 1936 [ 6542A767BD7A90F5383605E6849FDF48 ] C:\Windows\System32\WSDApi.dll
21:39:10.0088 1936 C:\Windows\System32\WSDApi.dll - ok
21:39:10.0088 1936 [ 0C063350E73B443666B17F225BB9FEC7 ] C:\Windows\System32\cfgmgr32.dll
21:39:10.0088 1936 C:\Windows\System32\cfgmgr32.dll - ok
21:39:10.0103 1936 [ 7F80E2C493079E9D42CCECC715790E10 ] C:\Windows\System32\fundisc.dll
21:39:10.0103 1936 C:\Windows\System32\fundisc.dll - ok
21:39:10.0103 1936 [ 65247F45AADA547397134AF688EFE471 ] C:\Windows\System32\httpapi.dll
21:39:10.0103 1936 C:\Windows\System32\httpapi.dll - ok
21:39:10.0103 1936 [ 19BDFEDD205E79B89809813A510033FA ] C:\Windows\System32\msxml3.dll
21:39:10.0103 1936 C:\Windows\System32\msxml3.dll - ok
21:39:10.0119 1936 [ 03AB48C5DB022A0C0D07BADCF7F64DD1 ] C:\Windows\System32\spool\prtprocs\x64\dldtdrpp.dll
21:39:10.0119 1936 C:\Windows\System32\spool\prtprocs\x64\dldtdrpp.dll - ok
21:39:10.0119 1936 [ 76937D85DBA50B75A49F9AB24A73044E ] C:\Windows\System32\win32spl.dll
21:39:10.0119 1936 C:\Windows\System32\win32spl.dll - ok
21:39:10.0119 1936 [ 961F7B0A130E1FA3976ED1E9573D4D36 ] C:\Windows\System32\netrap.dll
21:39:10.0119 1936 C:\Windows\System32\netrap.dll - ok
21:39:10.0134 1936 [ 19CB8D7776D3656006496C4D890F5312 ] C:\Windows\System32\printcom.dll
21:39:10.0134 1936 C:\Windows\System32\printcom.dll - ok
21:39:10.0134 1936 [ 0842A765D31D6E4AE50D6DF7DED61748 ] C:\Windows\System32\SensApi.dll
21:39:10.0134 1936 C:\Windows\System32\SensApi.dll - ok
21:39:10.0134 1936 [ A5A54257E6FD4AF082CCB0470AD4FC98 ] C:\Windows\System32\inetpp.dll
21:39:10.0134 1936 C:\Windows\System32\inetpp.dll - ok
21:39:10.0150 1936 [ 24DC07F75E0683A3D4AB16FA38290A18 ] C:\Windows\System32\ntprint.dll
21:39:10.0150 1936 C:\Windows\System32\ntprint.dll - ok
21:39:10.0150 1936 [ A77267CDDE66443FB779CEE39CEE2141 ] C:\Windows\System32\QAGENT.DLL
21:39:10.0150 1936 C:\Windows\System32\QAGENT.DLL - ok
21:39:10.0150 1936 [ ED99B5F4B9DFE4BECA711F3B0340F931 ] C:\Windows\System32\QUTIL.DLL
21:39:10.0150 1936 C:\Windows\System32\QUTIL.DLL - ok
21:39:10.0166 1936 [ 2BFD160AB9531CD20EDC9639EB0CD711 ] C:\Windows\System32\clusapi.dll
21:39:10.0166 1936 C:\Windows\System32\clusapi.dll - ok
21:39:10.0166 1936 [ DE3C091D7E05093B7ABA93DA5952F0FD ] C:\Windows\System32\netmsg.dll
21:39:10.0166 1936 C:\Windows\System32\netmsg.dll - ok
21:39:10.0166 1936 [ 476616A17AE5F69CE583D8E1E2A7B134 ] C:\Windows\System32\sscore.dll
21:39:10.0166 1936 C:\Windows\System32\sscore.dll - ok
21:39:10.0181 1936 [ 45C5EAB112D3481A25485B0CF7E3597D ] C:\Windows\System32\activeds.dll
21:39:10.0181 1936 C:\Windows\System32\activeds.dll - ok
21:39:10.0181 1936 [ 80B8B7FF3AADD2156EE969C048644CAF ] C:\Windows\System32\adsldpc.dll
21:39:10.0181 1936 C:\Windows\System32\adsldpc.dll - ok
21:39:10.0181 1936 [ 77C276A0E431203EE56E52600A2575EA ] C:\Windows\System32\credui.dll
21:39:10.0181 1936 C:\Windows\System32\credui.dll - ok
21:39:10.0197 1936 [ D55A487295CC38D9E533C5AD87C1EB69 ] C:\Windows\System32\resutils.dll
21:39:10.0197 1936 C:\Windows\System32\resutils.dll - ok
21:39:10.0197 1936 [ 581D88B25C4D4121824FED2CA38E562F ] C:\Program Files\SUPERAntiSpyware\SASCore64.exe
21:39:10.0197 1936 C:\Program Files\SUPERAntiSpyware\SASCore64.exe - ok
21:39:10.0197 1936 [ 0D7A11395C0A33D9E7587CDB9866EFAD ] C:\Windows\System32\AERTSr64.exe
21:39:10.0197 1936 C:\Windows\System32\AERTSr64.exe - ok
21:39:10.0197 1936 [ 0BB913F9F02677BD4AE96D4967CACFEE ] C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe
21:39:10.0197 1936 C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe - ok
21:39:10.0212 1936 [ 290A15C136531024982698A124F299FB ] C:\Windows\System32\taskschd.dll
21:39:10.0212 1936 C:\Windows\System32\taskschd.dll - ok
21:39:10.0212 1936 [ 2E10EB73ED1E094E9A113D0798058B88 ] C:\Windows\System32\vssapi.dll
21:39:10.0212 1936 C:\Windows\System32\vssapi.dll - ok
21:39:10.0212 1936 [ E8AECB69B2057EB308BE15A77AF2489E ] C:\Windows\System32\vsstrace.dll
21:39:10.0212 1936 C:\Windows\System32\vsstrace.dll - ok
21:39:10.0228 1936 [ C246F83CA9E84890EF612EDCE6AE2218 ] C:\Windows\System32\cryptnet.dll
21:39:10.0228 1936 C:\Windows\System32\cryptnet.dll - ok
21:39:10.0228 1936 [ E582816A4855914DEFFC212E12B3B744 ] C:\Windows\SysWOW64\wsock32.dll
21:39:10.0228 1936 C:\Windows\SysWOW64\wsock32.dll - ok
21:39:10.0228 1936 [ 22CFAEB9172F5F198048401485CD0571 ] C:\Windows\SysWOW64\WSHTCPIP.DLL
21:39:10.0228 1936 C:\Windows\SysWOW64\WSHTCPIP.DLL - ok
21:39:10.0244 1936 [ 853BABC289F2B46F8150DF0E0CF0B537 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
21:39:10.0244 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe - ok
21:39:10.0244 1936 [ A6BCDC241B6578C7DB57B5973B99FE7E ] C:\Windows\System32\wdscore.dll
21:39:10.0244 1936 C:\Windows\System32\wdscore.dll - ok
21:39:10.0244 1936 [ 9E80FF0752E365F97FD2D1D68C2AFDA1 ] C:\Windows\SysWOW64\wship6.dll
21:39:10.0244 1936 C:\Windows\SysWOW64\wship6.dll - ok
21:39:10.0259 1936 [ 05C3B38DB95BA5585817A4F898EE5581 ] C:\Windows\SysWOW64\wshqos.dll
21:39:10.0259 1936 C:\Windows\SysWOW64\wshqos.dll - ok
21:39:10.0259 1936 [ A8FFFBA5C5FC63E65BBDF5D54174721B ] C:\Program Files (x86)\Windows Live\Messenger\msgsres.dll
21:39:10.0259 1936 C:\Program Files (x86)\Windows Live\Messenger\msgsres.dll - ok
21:39:10.0259 1936 [ FC62A635063B762E1C3C60EA77279378 ] C:\Windows\SysWOW64\NapiNSP.dll
21:39:10.0259 1936 C:\Windows\SysWOW64\NapiNSP.dll - ok
21:39:10.0259 1936 [ D1A84F7D4CAFCFE2A32149FF418056E5 ] C:\Windows\SysWOW64\nlaapi.dll
21:39:10.0259 1936 C:\Windows\SysWOW64\nlaapi.dll - ok
21:39:10.0275 1936 [ 690D41DF1D555F96D4898A0F54EBA065 ] C:\Windows\SysWOW64\pnrpnsp.dll
21:39:10.0275 1936 C:\Windows\SysWOW64\pnrpnsp.dll - ok
21:39:10.0275 1936 [ 8617350C9B590B63E620881092751BCB ] C:\Windows\SysWOW64\mswsock.dll
21:39:10.0275 1936 C:\Windows\SysWOW64\mswsock.dll - ok
21:39:10.0275 1936 [ A7D525E5C0D91C8C1D84C6BCD25AD77D ] C:\Windows\SysWOW64\rasadhlp.dll
21:39:10.0275 1936 C:\Windows\SysWOW64\rasadhlp.dll - ok
21:39:10.0290 1936 [ C411C80F90D6732380352B98B37BBD53 ] C:\Windows\SysWOW64\winrnr.dll
21:39:10.0290 1936 C:\Windows\SysWOW64\winrnr.dll - ok
21:39:10.0290 1936 [ DD1D685D387A8AC666BA3B7539C774E8 ] C:\Windows\SysWOW64\wpclsp.dll
21:39:10.0290 1936 C:\Windows\SysWOW64\wpclsp.dll - ok
21:39:10.0306 1936 [ 1A4BEE34277784619DDAF0422C0C6E23 ] C:\Windows\System32\drivers\fastfat.sys
21:39:10.0306 1936 C:\Windows\System32\drivers\fastfat.sys - ok
21:39:10.0306 1936 [ 74B8C2EA72D43727142D12397D5A49F9 ] C:\Windows\SysWOW64\wbemcomn.dll
21:39:10.0306 1936 C:\Windows\SysWOW64\wbemcomn.dll - ok
21:39:10.0306 1936 [ 30F0DC266B46118E9FBCF5B2A30EB1DB ] C:\Windows\SysWOW64\wbem\wbemprox.dll
21:39:10.0306 1936 C:\Windows\SysWOW64\wbem\wbemprox.dll - ok
21:39:10.0322 1936 [ E14170AEA125119B98FA2BDE3FF4F462 ] C:\Windows\SysWOW64\rsaenh.dll
21:39:10.0322 1936 C:\Windows\SysWOW64\rsaenh.dll - ok
21:39:10.0322 1936 [ 12E8A79644955A6D1D371CBD7DA7C871 ] C:\Windows\SysWOW64\inetmib1.dll
21:39:10.0322 1936 C:\Windows\SysWOW64\inetmib1.dll - ok
21:39:10.0322 1936 [ AF24A9DF84637BF9858EC6FB88EBA7B2 ] C:\Windows\SysWOW64\snmpapi.dll
21:39:10.0322 1936 C:\Windows\SysWOW64\snmpapi.dll - ok
21:39:10.0337 1936 [ 148423FDBC7F0B07D8D166414C95B8AB ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\dbghelp.dll
21:39:10.0337 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\dbghelp.dll - ok
21:39:10.0337 1936 [ 1A3F335D2F0F9B3022D7799202F1F607 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi.dll
21:39:10.0337 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi.dll - ok
21:39:10.0337 1936 [ 3CB863B78642405371CB3A71C07E2382 ] C:\Windows\SysWOW64\rasapi32.dll
21:39:10.0337 1936 C:\Windows\SysWOW64\rasapi32.dll - ok
21:39:10.0353 1936 [ 3A1DDA77F331D107BA40DB06E4D666E9 ] C:\Windows\SysWOW64\rasman.dll
21:39:10.0353 1936 C:\Windows\SysWOW64\rasman.dll - ok
21:39:10.0353 1936 [ 3D418A22A56471295AEB1CEB9027C3DA ] C:\Windows\SysWOW64\rtutils.dll
21:39:10.0353 1936 C:\Windows\SysWOW64\rtutils.dll - ok
21:39:10.0353 1936 [ 70F08ECE7A30A639D3F0C8C433685C7D ] C:\Windows\SysWOW64\tapi32.dll
21:39:10.0353 1936 C:\Windows\SysWOW64\tapi32.dll - ok
21:39:10.0368 1936 [ 14FF750EFE13B0C21E5A06507C3A97B1 ] C:\Windows\SysWOW64\winmm.dll
21:39:10.0368 1936 C:\Windows\SysWOW64\winmm.dll - ok
21:39:10.0368 1936 [ 11CEB8B1A2162EFC19AC069749440065 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_comm.dll
21:39:10.0368 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_comm.dll - ok
21:39:10.0384 1936 [ 56C41C076E3614502737D7C42A42F45A ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_crypt.dll
21:39:10.0384 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_crypt.dll - ok
21:39:10.0384 1936 [ 9BAAB558CD422F6DE44ECB67FFF08CA9 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_dev.dll
21:39:10.0384 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_dev.dll - ok
21:39:10.0384 1936 [ DC15AB7168C0309D8F04FD95B6240422 ] C:\Windows\SysWOW64\oleacc.dll
21:39:10.0384 1936 C:\Windows\SysWOW64\oleacc.dll - ok
21:39:10.0400 1936 [ 1EDE113859276E4B0F19B80F39E2CC95 ] C:\Windows\SysWOW64\wsnmp32.dll
21:39:10.0400 1936 C:\Windows\SysWOW64\wsnmp32.dll - ok
21:39:10.0400 1936 [ 551F51B66E5EA87A38D8197EB3BDB57A ] C:\Windows\SysWOW64\setupapi.dll
21:39:10.0400 1936 C:\Windows\SysWOW64\setupapi.dll - ok
21:39:10.0400 1936 [ 996819EE2B10E7D64AEB5D29D4431884 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_dun.dll
21:39:10.0400 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_dun.dll - ok
21:39:10.0415 1936 [ 1ED152D37CF339433B0D822FD2EB0FF3 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_ip_hlpr.dll
21:39:10.0415 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_ip_hlpr.dll - ok
21:39:10.0415 1936 [ 631F939DD53E176D6C168200D297D66C ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_oui.dll
21:39:10.0415 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_oui.dll - ok
21:39:10.0415 1936 [ 68F846C2CB75784AEBA816179C032632 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_registry.dll
21:39:10.0415 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_registry.dll - ok
21:39:10.0431 1936 [ B80588599CD4FAE3D9B2A16BE56F086A ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_snetcfg.dll
21:39:10.0431 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_snetcfg.dll - ok
21:39:10.0431 1936 [ 2AECE2DB8B4ED0DB94E8E5F6EC43006F ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_socket.dll
21:39:10.0431 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_socket.dll - ok
21:39:10.0446 1936 [ F47B99CC90846AEAC5DC3D4AE29BDBE1 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_sys32.dll
21:39:10.0446 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_sys32.dll - ok
21:39:10.0446 1936 [ 1F94EA31C9543B855F53BDAC7792DA4E ] C:\Windows\SysWOW64\mpr.dll
21:39:10.0446 1936 C:\Windows\SysWOW64\mpr.dll - ok
21:39:10.0446 1936 [ 5EC8FB83F31AA2D6F421F02C3F4F4475 ] C:\Windows\SysWOW64\winspool.drv
21:39:10.0446 1936 C:\Windows\SysWOW64\winspool.drv - ok
21:39:10.0462 1936 [ 0A8015BF129B101DA6FE281DD6E298B6 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_wmi.dll
21:39:10.0462 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_wmi.dll - ok
21:39:10.0462 1936 [ 7C8101A9ECC5E0B2F3CC7A27CB062736 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\packet_api.dll
21:39:10.0462 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\packet_api.dll - ok
21:39:10.0462 1936 [ 8CBCA984930B7100C38DCC701B3A5813 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_http.dll
21:39:10.0462 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_http.dll - ok
21:39:10.0478 1936 [ 6501A49B41CEDEFE89E5DE4C85AAE6BB ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_icc.dll
21:39:10.0478 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_icc.dll - ok
21:39:10.0478 1936 [ 1D4C9438DACBFD1A1A013A1EE6C996D0 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_sha.dll
21:39:10.0478 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_sha.dll - ok
21:39:10.0478 1936 [ 85ADD4227903766330EA5F7EC3DFDAA5 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_ipc.dll
21:39:10.0478 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_ipc.dll - ok
21:39:10.0493 1936 [ DBD02E3E6F061EBBBF9B99A9D7CBA30B ] C:\Windows\SysWOW64\winhttp.dll
21:39:10.0493 1936 C:\Windows\SysWOW64\winhttp.dll - ok
21:39:10.0493 1936 [ 70455A491A7B93ADC9830294A28B9618 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_upnp.dll
21:39:10.0493 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_upnp.dll - ok
21:39:10.0509 1936 [ 2A8EA7D07EF4019B23F5B1C5B3F7FD49 ] C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_wireless.dll
21:39:10.0509 1936 C:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\ezi_wireless.dll - ok
21:39:10.0509 1936 [ 88B630F6AEB5A11F6AD064930B38C2C0 ] C:\Windows\SysWOW64\uxtheme.dll
21:39:10.0509 1936 C:\Windows\SysWOW64\uxtheme.dll - ok
21:39:10.0509 1936 [ 65085456FD9A74D7F1A999520C299ECB ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
21:39:10.0509 1936 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe - ok
21:39:10.0509 1936 [ 6BC5FCEF351E4CB5A269C1E84B5A06DA ] C:\Windows\SysWOW64\netcfgx.dll
21:39:10.0509 1936 C:\Windows\SysWOW64\netcfgx.dll - ok
21:39:10.0524 1936 [ C6DF7A87063D006ECF1FD8156CB6DE3F ] C:\Windows\SysWOW64\SLC.dll
21:39:10.0524 1936 C:\Windows\SysWOW64\SLC.dll - ok
21:39:10.0524 1936 [ EF39CCCC9AD927A25334AE0B41A8A343 ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll
21:39:10.0524 1936 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll - ok
21:39:10.0524 1936 [ 9275F02BEA644F43A459E316A932658F ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll
21:39:10.0524 1936 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll - ok
21:39:10.0540 1936 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
21:39:10.0540 1936 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe - ok
21:39:10.0540 1936 [ 80D8679BF84A9383BFF33E07D5D9FC35 ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.dll
21:39:10.0540 1936 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.dll - ok
21:39:10.0540 1936 [ C8F8521648697B284E39477DD2BA5ECD ] C:\Program Files (x86)\PDF Suite 2010\ConversionService.exe
21:39:10.0540 1936 C:\Program Files (x86)\PDF Suite 2010\ConversionService.exe - ok
21:39:10.0556 1936 [ 5E1D96076745F73C56B1307FEE6BEDFE ] C:\Windows\System32\ncsi.dll
21:39:10.0556 1936 C:\Windows\System32\ncsi.dll - ok
21:39:10.0556 1936 [ 467FBA22AD764B6AB85BE58C25EEF15D ] C:\Windows\System32\ssdpapi.dll
21:39:10.0556 1936 C:\Windows\System32\ssdpapi.dll - ok
21:39:10.0556 1936 [ 58865916F53592A61549B04941BFD80D ] C:\Windows\System32\drivers\PEAuth.sys
21:39:10.0556 1936 C:\Windows\System32\drivers\PEAuth.sys - ok
21:39:10.0571 1936 [ 3EA8A16169C26AFBEB544E0E48421186 ] C:\Windows\System32\drivers\secdrv.sys
21:39:10.0571 1936 C:\Windows\System32\drivers\secdrv.sys - ok
21:39:10.0571 1936 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] C:\Windows\System32\IPSECSVC.DLL
21:39:10.0571 1936 C:\Windows\System32\IPSECSVC.DLL - ok
21:39:10.0571 1936 [ D1D5DAB39DCB4BE0359943738D87409B ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
21:39:10.0571 1936 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe - ok
21:39:10.0587 1936 [ 3740B83AEC21D981065D7E819BD7E878 ] C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
21:39:10.0587 1936 C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe - ok
21:39:10.0587 1936 [ 14DC30962660BA05F1F54EB11AA5A2B4 ] C:\Windows\System32\FwRemoteSvr.dll
21:39:10.0587 1936 C:\Windows\System32\FwRemoteSvr.dll - ok
21:39:10.0587 1936 [ F07AF60B152221472FBDB2FECEC4896D ] C:\Program Files (x86)\Skype\Updater\Updater.exe
21:39:10.0587 1936 C:\Program Files (x86)\Skype\Updater\Updater.exe - ok
21:39:10.0602 1936 [ 42FEF84684D217870F3C8813B6F58276 ] C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe
21:39:10.0602 1936 C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe - ok
21:39:10.0602 1936 [ 3E5EF481EAA9695181B6C02A2B88983E ] C:\Windows\System32\wiatrace.dll
21:39:10.0602 1936 C:\Windows\System32\wiatrace.dll - ok
21:39:10.0602 1936 [ 8E10B36901325C1ABE28E71FB8E437D9 ] C:\Windows\System32\wsdchngr.dll
21:39:10.0602 1936 C:\Windows\System32\wsdchngr.dll - ok
21:39:10.0618 1936 [ 84E689F423E2AFA8DD36E01BD6FC8F45 ] C:\Program Files (x86)\Common Files\supportsoft\bin\vnchooks.dll
21:39:10.0618 1936 C:\Program Files (x86)\Common Files\supportsoft\bin\vnchooks.dll - ok
21:39:10.0618 1936 [ F6F46226D0104D997AF8B2ADFABE4B24 ] C:\Windows\System32\drivers\tcpipreg.sys
21:39:10.0618 1936 C:\Windows\System32\drivers\tcpipreg.sys - ok
21:39:10.0618 1936 [ 4B817450226F93C31ADD5BCC27FED27A ] C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe
21:39:10.0618 1936 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.2.0\ToolbarUpdater.exe - ok
21:39:10.0634 1936 [ 4E1CC9DB8B680795F17F20FC6C51974B ] C:\Windows\System32\icaapi.dll
21:39:10.0634 1936 C:\Windows\System32\icaapi.dll - ok
21:39:10.0634 1936 [ CC1959AB3929997F4198AA69C854086F ] C:\Windows\SysWOW64\regsvr32.exe
21:39:10.0634 1936 C:\Windows\SysWOW64\regsvr32.exe - ok
21:39:10.0634 1936 [ 66E3D868845C013B5F39FBDF40B8D921 ] C:\Program Files (x86)\Common Files\supportsoft\bin\sprtlisten.exe
21:39:10.0634 1936 C:\Program Files (x86)\Common Files\supportsoft\bin\sprtlisten.exe - ok
21:39:10.0649 1936 [ 10490F6BCE6DDDD271751021E2AF4B1E ] C:\PROGRA~2\COMMON~1\SUPPOR~1\bin\SPRTHE~1.EXE
21:39:10.0649 1936 C:\PROGRA~2\COMMON~1\SUPPOR~1\bin\SPRTHE~1.EXE - ok
21:39:10.0649 1936 [ FD647CA82ACF232DBE5F20345647B948 ] C:\Windows\AppPatch\AcGenral.dll
21:39:10.0649 1936 C:\Windows\AppPatch\AcGenral.dll - ok
21:39:10.0649 1936 [ BDBB449425991154135E5ED1559927E6 ] C:\Windows\SysWOW64\msacm32.dll
21:39:10.0649 1936 C:\Windows\SysWOW64\msacm32.dll - ok
21:39:10.0665 1936 [ F4E1AA5D59C849A4AB47E895DC76B9C8 ] C:\Windows\SysWOW64\sfc.dll
21:39:10.0665 1936 C:\Windows\SysWOW64\sfc.dll - ok
21:39:10.0665 1936 [ 9B96F6952186336CC6E3D4E08BE2E0AF ] C:\Windows\SysWOW64\dwmapi.dll
21:39:10.0665 1936 C:\Windows\SysWOW64\dwmapi.dll - ok
21:39:10.0665 1936 [ 12BCF4DAD8E5A1B3D5FA7AB4A79DA105 ] C:\Windows\SysWOW64\sfc_os.dll
21:39:10.0665 1936 C:\Windows\SysWOW64\sfc_os.dll - ok
21:39:10.0680 1936 [ 2BACD71123F42CEA603F4E205E1AE337 ] C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
21:39:10.0680 1936 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE - ok
21:39:10.0680 1936 [ E9DBC876EC1C78A74A55D8D121016344 ] C:\Windows\System32\wbemcomn.dll
21:39:10.0680 1936 C:\Windows\System32\wbemcomn.dll - ok
21:39:10.0680 1936 [ B25321F9C037BA9AE1DD68B36913ACAC ] C:\Windows\System32\wbem\WinMgmtR.dll
21:39:10.0680 1936 C:\Windows\System32\wbem\WinMgmtR.dll - ok
21:39:10.0696 1936 [ 93812FDC01AA864195816CD814445F95 ] C:\Program Files\Common Files\Microsoft Shared\Windows Live\SQMAPI.DLL
21:39:10.0696 1936 C:\Program Files\Common Files\Microsoft Shared\Windows Live\SQMAPI.DLL - ok
21:39:10.0696 1936 [ 589CDC23CCDC419C36DDD200BEB00944 ] C:\Windows\System32\wer.dll
21:39:10.0696 1936 C:\Windows\System32\wer.dll - ok
21:39:10.0696 1936 [ 898804F8043BA721AC2E9F45AA55558B ] C:\Windows\System32\PortableDeviceApi.dll
21:39:10.0696 1936 C:\Windows\System32\PortableDeviceApi.dll - ok
21:39:10.0712 1936 [ 41F84775AE00035887A98EE774914939 ] C:\Windows\System32\PortableDeviceConnectApi.dll
21:39:10.0712 1936 C:\Windows\System32\PortableDeviceConnectApi.dll - ok
21:39:10.0712 1936 [ 6FF25F418D373097C199E3ACCFA06E78 ] C:\Windows\System32\tquery.dll
21:39:10.0712 1936 C:\Windows\System32\tquery.dll - ok
21:39:10.0712 1936 [ DC1BBA01FFB5745B8862931E7DE7304A ] C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
21:39:10.0712 1936 C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll - ok
21:39:10.0727 1936 [ A0B762992A52FA8A657A97C34BEEA807 ] C:\Windows\System32\mssrch.dll
21:39:10.0727 1936 C:\Windows\System32\mssrch.dll - ok
21:39:10.0727 1936 [ 2A46FFE841EC43001D5A293A54DB34DE ] C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
21:39:10.0727 1936 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE - ok
21:39:10.0743 1936 [ 21F36392598072A73C7576CD8AFD6E70 ] C:\Windows\System32\wbem\wbemprox.dll
21:39:10.0743 1936 C:\Windows\System32\wbem\wbemprox.dll - ok
21:39:10.0743 1936 [ D642A49B5E19B3F5B0B4647FAE27817E ] C:\Windows\System32\wbem\wbemcore.dll
21:39:10.0743 1936 C:\Windows\System32\wbem\wbemcore.dll - ok
21:39:10.0743 1936 [ BA019C21DAC7CAC193C93E86B9F2F3CB ] C:\Windows\System32\wsock32.dll
21:39:10.0743 1936 C:\Windows\System32\wsock32.dll - ok
21:39:10.0758 1936 [ 54BEFBE0B681A7254FD74E1E5288F7F6 ] C:\Windows\System32\msidle.dll
21:39:10.0758 1936 C:\Windows\System32\msidle.dll - ok
21:39:10.0758 1936 [ 37B697901FE364144D634128369098FF ] C:\Windows\System32\wbem\esscli.dll
21:39:10.0758 1936 C:\Windows\System32\wbem\esscli.dll - ok
21:39:10.0758 1936 [ DD0042F0C3B606A6A8B92D49AFB18AD6 ] C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
21:39:10.0758 1936 C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe - ok
21:39:10.0774 1936 [ 11F705A35F4CB2B4D6FA51606A9B8C54 ] C:\Windows\System32\wbem\fastprox.dll
21:39:10.0774 1936 C:\Windows\System32\wbem\fastprox.dll - ok
21:39:10.0774 1936 [ 27F479DFA5E1BD942E056888DCF5C270 ] C:\Windows\System32\Query.dll
21:39:10.0774 1936 C:\Windows\System32\Query.dll - ok
21:39:10.0774 1936 [ 8F8380E73A04BCB85340B1A3653FB8A5 ] C:\Windows\System32\wbem\wbemsvc.dll
21:39:10.0774 1936 C:\Windows\System32\wbem\wbemsvc.dll - ok
21:39:10.0774 1936 [ 1AE49D81622BE6364194F70045F07194 ] C:\Windows\System32\wbem\wmiutils.dll
21:39:10.0774 1936 C:\Windows\System32\wbem\wmiutils.dll - ok
21:39:10.0790 1936 [ 5103B1E343F2D5FBDFA8D0318ABC59C4 ] C:\Windows\System32\wbem\repdrvfs.dll
21:39:10.0790 1936 C:\Windows\System32\wbem\repdrvfs.dll - ok
21:39:10.0790 1936 [ D89585872F9C5130226CB42A0C42C220 ] C:\Windows\System32\dssenh.dll
21:39:10.0790 1936 C:\Windows\System32\dssenh.dll - ok
21:39:10.0805 1936 [ E862E8D392590D03A67C7FBBFAC149A3 ] C:\Windows\System32\wermgr.exe
21:39:10.0805 1936 C:\Windows\System32\wermgr.exe - ok
21:39:10.0805 1936 [ E946553F786521C073AABC7CD0714807 ] C:\Windows\System32\wbem\WmiPrvSD.dll
21:39:10.0805 1936 C:\Windows\System32\wbem\WmiPrvSD.dll - ok
21:39:10.0805 1936 [ 8D94313E7A7786997B4C362B7CCB5D29 ] C:\Windows\System32\wbem\wbemess.dll
21:39:10.0805 1936 C:\Windows\System32\wbem\wbemess.dll - ok
21:39:10.0821 1936 [ 7846D0136CC2B264926A73047BA7688A ] C:\Windows\System32\netprofm.dll
21:39:10.0821 1936 C:\Windows\System32\netprofm.dll - ok
21:39:10.0821 1936 [ 1894F161AF417784AAECFAFE77DE940E ] C:\Windows\System32\sqmapi.dll
21:39:10.0821 1936 C:\Windows\System32\sqmapi.dll - ok
21:39:10.0821 1936 [ A5D8AD128FBB763F147F29F3D6A1C084 ] C:\Windows\System32\npmproxy.dll
21:39:10.0821 1936 C:\Windows\System32\npmproxy.dll - ok
21:39:10.0836 1936 [ 8F8E0EE62D73C72015D43E91BBF62B01 ] C:\Windows\System32\rastapi.dll
21:39:10.0836 1936 C:\Windows\System32\rastapi.dll - ok
21:39:10.0836 1936 [ C1AE82B8F60ADB630C00DCE48E571CDD ] C:\Windows\System32\netcfgx.dll
21:39:10.0836 1936 C:\Windows\System32\netcfgx.dll - ok
21:39:10.0836 1936 [ 8139F933EF1559D4E7187E48F93EA136 ] C:\Windows\System32\unimdm.tsp
21:39:10.0836 1936 C:\Windows\System32\unimdm.tsp - ok
21:39:10.0852 1936 [ CDBAE31A2B6C8819DDBC5CF8432E3B3E ] C:\Windows\System32\en-US\tquery.dll.mui
21:39:10.0852 1936 C:\Windows\System32\en-US\tquery.dll.mui - ok
21:39:10.0852 1936 [ D23E5184266747DDCE9D0C6581D916B3 ] C:\Windows\System32\hnetcfg.dll
21:39:10.0852 1936 C:\Windows\System32\hnetcfg.dll - ok
21:39:10.0852 1936 [ B3F777F027078644A7EC57C1EA40A5F1 ] C:\Windows\System32\uniplat.dll
21:39:10.0852 1936 C:\Windows\System32\uniplat.dll - ok
21:39:10.0868 1936 [ E21FFFE678FF09BAA6BF5F76BD8805C6 ] C:\Windows\System32\esent.dll
21:39:10.0868 1936 C:\Windows\System32\esent.dll - ok
21:39:10.0868 1936 [ AE865C840368BEEF09E2E2C619E8DB48 ] C:\Windows\System32\hidphone.tsp
21:39:10.0868 1936 C:\Windows\System32\hidphone.tsp - ok
21:39:10.0868 1936 [ ABCA3F75096C7CAF510CE0117FA29397 ] C:\Windows\System32\kmddsp.tsp
21:39:10.0868 1936 C:\Windows\System32\kmddsp.tsp - ok
21:39:10.0883 1936 [ A39C6C710DAC32A2D3B0677F648FD711 ] C:\Windows\System32\ndptsp.tsp
21:39:10.0883 1936 C:\Windows\System32\ndptsp.tsp - ok
21:39:10.0883 1936 [ 4500B574CB7F5ED6EE8E0BBC72AE2E31 ] C:\Windows\System32\rasppp.dll
21:39:10.0883 1936 C:\Windows\System32\rasppp.dll - ok
21:39:10.0883 1936 [ F77B49A32331FA80F11C86877A6700DB ] C:\Windows\System32\mprapi.dll
21:39:10.0883 1936 C:\Windows\System32\mprapi.dll - ok
21:39:10.0899 1936 [ A44E61A183FD6D65C655E31A330ECA7E ] C:\Windows\System32\msscb.dll
21:39:10.0899 1936 C:\Windows\System32\msscb.dll - ok
21:39:10.0899 1936 [ BFDF69526CB6476992540D4C477CC27A ] C:\Windows\System32\raschap.dll
21:39:10.0899 1936 C:\Windows\System32\raschap.dll - ok
21:39:10.0899 1936 [ 88C3F45AAF528E67D85C6F303958AA0C ] C:\Windows\System32\rasqec.dll
21:39:10.0899 1936 C:\Windows\System32\rasqec.dll - ok
21:39:10.0914 1936 [ 0160AD4F8F4F817428CA74358612EC48 ] C:\Windows\System32\rastls.dll
21:39:10.0914 1936 C:\Windows\System32\rastls.dll - ok
21:39:10.0914 1936 [ A361672E1AE1581B475F035607F4FD87 ] C:\Windows\System32\cryptui.dll
21:39:10.0914 1936 C:\Windows\System32\cryptui.dll - ok
21:39:10.0914 1936 [ AA6FAA30D3D0D4424DBA3D74D1CA1E14 ] C:\Windows\System32\netshell.dll
21:39:10.0914 1936 C:\Windows\System32\netshell.dll - ok
21:39:10.0930 1936 [ 85155AC913CA65ADE0323DC751AF3391 ] C:\Windows\System32\bitsperf.dll
21:39:10.0930 1936 C:\Windows\System32\bitsperf.dll - ok
21:39:10.0930 1936 [ 7E451C585AD79B895D03A3301EC5A675 ] C:\Windows\System32\shfolder.dll
21:39:10.0930 1936 C:\Windows\System32\shfolder.dll - ok
21:39:10.0930 1936 [ DB0F37DBA4C245C61E5936DDBDE62438 ] C:\Windows\SysWOW64\wbem\wbemsvc.dll
21:39:10.0930 1936 C:\Windows\SysWOW64\wbem\wbemsvc.dll - ok
21:39:10.0946 1936 [ 980F1A36B970F5AE361C5C2A90C9E972 ] C:\Windows\System32\bitsigd.dll
21:39:10.0946 1936 C:\Windows\System32\bitsigd.dll - ok
21:39:10.0946 1936 [ 7371D6B52B85190971CB3F35FA0CED05 ] C:\Windows\System32\diagperf.dll
21:39:10.0946 1936 C:\Windows\System32\diagperf.dll - ok
21:39:10.0946 1936 [ 1B7A24F2BFA1BB09CC67D4688B411039 ] C:\Windows\System32\pcadm.dll
21:39:10.0946 1936 C:\Windows\System32\pcadm.dll - ok
21:39:10.0961 1936 [ BC5A34B6A14C93BF04E3F4E8EA57090A ] C:\Windows\SysWOW64\wbem\fastprox.dll
21:39:10.0961 1936 C:\Windows\SysWOW64\wbem\fastprox.dll - ok
21:39:10.0961 1936 [ 595BAC1B188813CEAE88A599738E60F8 ] C:\Windows\System32\mssprxy.dll
21:39:10.0961 1936 C:\Windows\System32\mssprxy.dll - ok
21:39:10.0961 1936 [ 9BBD858EEC0AA9894B8063218CF1D19D ] C:\Windows\System32\upnp.dll
21:39:10.0961 1936 C:\Windows\System32\upnp.dll - ok
21:39:10.0977 1936 [ E97B6931B5629D7E9F6EE29A68FD6123 ] C:\Windows\System32\wbem\WmiPrvSE.exe
21:39:10.0977 1936 C:\Windows\System32\wbem\WmiPrvSE.exe - ok
21:39:10.0977 1936 [ 0FD5754319A388FBD2E13C21E806AC42 ] C:\Windows\System32\pnpts.dll
21:39:10.0977 1936 C:\Windows\System32\pnpts.dll - ok
21:39:10.0977 1936 [ 0C03B4C202B3C12C6E7D8BC9E0E02AF4 ] C:\Windows\System32\qmgrprxy.dll
21:39:10.0977 1936 C:\Windows\System32\qmgrprxy.dll - ok
21:39:10.0992 1936 [ 10F13FFF542FEC4A2C4FA734EEBE56B9 ] C:\Windows\SysWOW64\qmgrprxy.dll
21:39:10.0992 1936 C:\Windows\SysWOW64\qmgrprxy.dll - ok
21:39:10.0992 1936 [ 376FAD0BD6E157205C8144D23A66493D ] C:\Windows\System32\wbem\cimwin32.dll
21:39:10.0992 1936 C:\Windows\System32\wbem\cimwin32.dll - ok
21:39:10.0992 1936 [ BFEFE6082328C37E7A441143E5ADCA31 ] C:\Windows\System32\framedynos.dll
21:39:10.0992 1936 C:\Windows\System32\framedynos.dll - ok
21:39:11.0008 1936 [ F347FD7DD03B3408691049CDE0ABB6B6 ] C:\Windows\System32\wbem\wmiprov.dll
21:39:11.0008 1936 C:\Windows\System32\wbem\wmiprov.dll - ok
21:39:11.0008 1936 [ 98C42F36A13C25E099F1E081EB4EC59D ] C:\Windows\System32\wmi.dll
21:39:11.0008 1936 C:\Windows\System32\wmi.dll - ok
21:39:11.0024 1936 [ A483A370982BB46F7962C3190EB468FD ] C:\Windows\System32\security.dll
21:39:11.0024 1936 C:\Windows\System32\security.dll - ok
21:39:11.0024 1936 [ B0D12F4344EB2AE96E487D2DF6F74413 ] C:\Windows\SysWOW64\FWPUCLNT.DLL
21:39:11.0024 1936 C:\Windows\SysWOW64\FWPUCLNT.DLL - ok
21:39:11.0024 1936 [ BE01E566D1F569AAB32D0335613E1EEA ] C:\Windows\SysWOW64\dllhost.exe
21:39:11.0024 1936 C:\Windows\SysWOW64\dllhost.exe - ok
21:39:11.0039 1936 [ 690619A8CFC7EC9048CD71682F4CE9DC ] C:\Windows\SysWOW64\en-US\crypt32.dll.mui
21:39:11.0039 1936 C:\Windows\SysWOW64\en-US\crypt32.dll.mui - ok
21:39:11.0039 1936 [ 70932D6C3D59B416CBD2BE5A3B3D4BE6 ] C:\Windows\SysWOW64\shacct.dll
21:39:11.0039 1936 C:\Windows\SysWOW64\shacct.dll - ok
21:39:11.0039 1936 [ 7DACD94118E2D8B6D72F47ADEB0367BF ] C:\Windows\SysWOW64\propsys.dll
21:39:11.0039 1936 C:\Windows\SysWOW64\propsys.dll - ok
21:39:11.0039 1936 [ 50E3E76B0901BB4FC029BB88BFA5CE79 ] C:\Windows\SysWOW64\schannel.dll
21:39:11.0039 1936 C:\Windows\SysWOW64\schannel.dll - ok
21:39:11.0055 1936 [ 9A6A653ADF28D9D69670B48F535E6B90 ] C:\Windows\SysWOW64\runonce.exe
21:39:11.0055 1936 C:\Windows\SysWOW64\runonce.exe - ok
21:39:11.0055 1936 [ 26F139DDEC6407508071930D3D07337E ] C:\Windows\SysWOW64\credssp.dll
21:39:11.0055 1936 C:\Windows\SysWOW64\credssp.dll - ok
21:39:11.0070 1936 [ 5398BD3BA9735ECF658487A2826C0885 ] C:\Windows\System32\runonce.exe
21:39:11.0070 1936 C:\Windows\System32\runonce.exe - ok
21:39:11.0070 1936 [ A18F3826069B955B6AA79EE78E8621CD ] C:\Windows\SysWOW64\en-US\runonce.exe.mui
21:39:11.0070 1936 C:\Windows\SysWOW64\en-US\runonce.exe.mui - ok
21:39:11.0070 1936 [ C8DBFEF835FF54467425C8F3ABCF7046 ] C:\Windows\SysWOW64\dssenh.dll
21:39:11.0070 1936 C:\Windows\SysWOW64\dssenh.dll - ok
21:39:11.0086 1936 [ D0CAF531E33112D5B9CE5D6C338D4C73 ] C:\Windows\SysWOW64\en-US\setupapi.dll.mui
21:39:11.0086 1936 C:\Windows\SysWOW64\en-US\setupapi.dll.mui - ok
21:39:11.0086 1936 [ 13CC59C1B04E9F20A87987C68CD4BE3F ] C:\Windows\SysWOW64\ncrypt.dll
21:39:11.0086 1936 C:\Windows\SysWOW64\ncrypt.dll - ok
21:39:11.0086 1936 [ 4ACF748A8E576761E4C610ACAB67B1BC ] C:\Windows\SysWOW64\bcrypt.dll
21:39:11.0086 1936 C:\Windows\SysWOW64\bcrypt.dll - ok
21:39:11.0102 1936 [ 88B462F0FB08B3DAB4DED85ACC54E1FB ] C:\Windows\SysWOW64\en-US\shell32.dll.mui
21:39:11.0102 1936 C:\Windows\SysWOW64\en-US\shell32.dll.mui - ok
21:39:11.0102 1936 [ 0F420E81062757EA8363CBACD4D40D6D ] C:\Windows\SysWOW64\gpapi.dll
21:39:11.0102 1936 C:\Windows\SysWOW64\gpapi.dll - ok
21:39:11.0102 1936 [ 5CAAE5333EF36DB4A8D294418AB37E80 ] C:\Windows\SysWOW64\p2pcollab.dll
21:39:11.0102 1936 C:\Windows\SysWOW64\p2pcollab.dll - ok
21:39:11.0117 1936 [ 111C47816F39A91EAAA18DA0A54E8E63 ] C:\Windows\SysWOW64\imageres.dll
21:39:11.0117 1936 C:\Windows\SysWOW64\imageres.dll - ok
21:39:11.0117 1936 [ A44BB035874EF794CD8750579B26801A ] C:\Windows\SysWOW64\en-US\imageres.dll.mui
21:39:11.0117 1936 C:\Windows\SysWOW64\en-US\imageres.dll.mui - ok
21:39:11.0117 1936 [ 00D1FB0073B4A8BD2989EA8FF4CC792B ] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
21:39:11.0117 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe - ok
21:39:11.0133 1936 [ 74F26FC01B180D4A99A168ED69C30A53 ] C:\Windows\SysWOW64\cmd.exe
21:39:11.0133 1936 C:\Windows\SysWOW64\cmd.exe - ok
21:39:11.0133 1936 [ 72A73B43C20902760022FBC91B3EC948 ] C:\Windows\System32\cmd.exe
21:39:11.0133 1936 C:\Windows\System32\cmd.exe - ok
21:39:11.0133 1936 [ B81388E9FE895065FD5CEAF3C11FDC3F ] C:\Windows\SysWOW64\ieframe.dll
21:39:11.0133 1936 C:\Windows\SysWOW64\ieframe.dll - ok
21:39:11.0148 1936 [ 167AC31450C0C53A01FA1491E94D7678 ] C:\Windows\SysWOW64\shdocvw.dll
21:39:11.0148 1936 C:\Windows\SysWOW64\shdocvw.dll - ok
21:39:11.0148 1936 [ 178A34E5554DCE485E1262DDF027960C ] C:\Users\dianne\AppData\Local\Temp\0BD16C83-2351-4234-B3A1-33EE388F7F87.exe
21:39:11.0148 1936 C:\Users\dianne\AppData\Local\Temp\0BD16C83-2351-4234-B3A1-33EE388F7F87.exe - ok
21:39:11.0164 1936 [ 9340105C246B16EE661FD8FCE579B117 ] C:\Windows\SysWOW64\cryptnet.dll
21:39:11.0164 1936 C:\Windows\SysWOW64\cryptnet.dll - ok
21:39:11.0164 1936 [ EC760B0B76A4353DE49D66520EB2141F ] C:\Windows\SysWOW64\SensApi.dll
21:39:11.0164 1936 C:\Windows\SysWOW64\SensApi.dll - ok
21:39:11.0164 1936 [ A99871BA522CB2539AE275AC18CACC8F ] C:\Windows\SysWOW64\cabinet.dll
21:39:11.0164 1936 C:\Windows\SysWOW64\cabinet.dll - ok
21:39:11.0180 1936 [ 6836D001FC733F205ACB80A7986CB6C9 ] C:\Windows\SysWOW64\WindowsCodecs.dll
21:39:11.0180 1936 C:\Windows\SysWOW64\WindowsCodecs.dll - ok
21:39:11.0180 1936 [ 14E4470BF8ACA69A85D741BA99F75F96 ] C:\Windows\SysWOW64\EhStorShell.dll
21:39:11.0180 1936 C:\Windows\SysWOW64\EhStorShell.dll - ok
21:39:11.0180 1936 [ 87CDFFCBD09C1CA03A068343D5D93250 ] C:\Windows\SysWOW64\wmi.dll
21:39:11.0180 1936 C:\Windows\SysWOW64\wmi.dll - ok
21:39:11.0195 1936 [ 17FC3EDA0162F513E858B8C8FA7FA6E0 ] C:\Windows\SysWOW64\vssapi.dll
21:39:11.0195 1936 C:\Windows\SysWOW64\vssapi.dll - ok
21:39:11.0195 1936 [ 409F36C8BD06FCE184631EB4142B009A ] C:\Windows\SysWOW64\atl.dll
21:39:11.0195 1936 C:\Windows\SysWOW64\atl.dll - ok
21:39:11.0195 1936 [ DC3AE9F1554DCD97F90983DDBDACD83D ] C:\Windows\SysWOW64\vsstrace.dll
21:39:11.0195 1936 C:\Windows\SysWOW64\vsstrace.dll - ok
21:39:11.0211 1936 [ 1AE011BB950A5E0B05023D2AFEC3666D ] C:\Windows\SysWOW64\authz.dll
21:39:11.0211 1936 C:\Windows\SysWOW64\authz.dll - ok
21:39:11.0211 1936 [ 1908CC7673F72601AFFDCA022689CEDF ] C:\Windows\SysWOW64\xmllite.dll
21:39:11.0211 1936 C:\Windows\SysWOW64\xmllite.dll - ok
21:39:11.0211 1936 [ 67058C46504BC12D821F38CF99B7B28F ] C:\Windows\SysWOW64\es.dll
21:39:11.0211 1936 C:\Windows\SysWOW64\es.dll - ok
21:39:11.0226 1936 [ 95F1EB99B81CFD6F581C85F0A0AA9B2B ] C:\Windows\SysWOW64\FirewallAPI.dll
21:39:11.0226 1936 C:\Windows\SysWOW64\FirewallAPI.dll - ok
21:39:11.0226 1936 [ 6950BBCEB21F9C3CB3B52E90960109C3 ] C:\Windows\SysWOW64\devenum.dll
21:39:11.0226 1936 C:\Windows\SysWOW64\devenum.dll - ok
21:39:11.0242 1936 [ B8AEFF80ABD57E6ABC6A46EAC7F4515F ] C:\Windows\SysWOW64\msdmo.dll
21:39:11.0242 1936 C:\Windows\SysWOW64\msdmo.dll - ok
21:39:11.0242 1936 [ 928C90E02E05244D2290C1551DF732C8 ] C:\Windows\SysWOW64\avicap32.dll
21:39:11.0242 1936 C:\Windows\SysWOW64\avicap32.dll - ok
21:39:11.0258 1936 [ EACACA0F2FF4CC54A909E3C5721FCDE8 ] C:\Windows\SysWOW64\msvfw32.dll
21:39:11.0258 1936 C:\Windows\SysWOW64\msvfw32.dll - ok
21:39:11.0258 1936 [ 65C092EF598DCCA1D665D52F06829512 ] C:\Windows\SysWOW64\vfwwdm32.dll
21:39:11.0258 1936 C:\Windows\SysWOW64\vfwwdm32.dll - ok
21:39:11.0258 1936 [ 4DF066ECEE5A7B20BF8B39EF4D646600 ] C:\Windows\SysWOW64\wdmaud.drv
21:39:11.0258 1936 C:\Windows\SysWOW64\wdmaud.drv - ok
21:39:11.0273 1936 [ 919CC2A0476D5A6A4C935D4B88E29912 ] C:\Windows\SysWOW64\ksuser.dll
21:39:11.0273 1936 C:\Windows\SysWOW64\ksuser.dll - ok
21:39:11.0273 1936 [ 56B5914070B2C243DFB3D186070DA89D ] C:\Windows\SysWOW64\MMDevAPI.dll
21:39:11.0273 1936 C:\Windows\SysWOW64\MMDevAPI.dll - ok
21:39:11.0273 1936 [ C9244BCAC83B259B920BBEE18A97BFE1 ] C:\Windows\SysWOW64\avrt.dll
21:39:11.0273 1936 C:\Windows\SysWOW64\avrt.dll - ok
21:39:11.0289 1936 [ 7258434974EA735725FD2D4A65C5E821 ] C:\Windows\SysWOW64\AudioSes.dll
21:39:11.0289 1936 C:\Windows\SysWOW64\AudioSes.dll - ok
21:39:11.0289 1936 [ DA7478BA9E41B60B3D5DA456E253002A ] C:\Windows\SysWOW64\AudioEng.dll
21:39:11.0289 1936 C:\Windows\SysWOW64\AudioEng.dll - ok
21:39:11.0289 1936 [ 166F004D73EA2CF4AC61800CA469458D ] C:\Windows\SysWOW64\msacm32.drv
21:39:11.0289 1936 C:\Windows\SysWOW64\msacm32.drv - ok
21:39:11.0304 1936 [ 83199EF88D691E730B80666E29F90D58 ] C:\Windows\SysWOW64\midimap.dll
21:39:11.0304 1936 C:\Windows\SysWOW64\midimap.dll - ok
21:39:11.0304 1936 [ 22DC784B32BEE306A99F50D6DC2460BC ] C:\Windows\SysWOW64\esent.dll
21:39:11.0304 1936 C:\Windows\SysWOW64\esent.dll - ok
21:39:11.0304 1936 [ 11D415DB881C617288D3CB81BB1FE51D ] C:\Windows\System32\wbem\NCProv.dll
21:39:11.0304 1936 C:\Windows\System32\wbem\NCProv.dll - ok
21:39:11.0320 1936 [ 06FDEA0167BAD4CDE26210F92F33FDBA ] C:\Windows\System32\wbem\wbemcons.dll
21:39:11.0320 1936 C:\Windows\System32\wbem\wbemcons.dll - ok
21:39:11.0320 1936 [ E98E402067978DB38282158F9E8609CA ] C:\Windows\SysWOW64\netshell.dll
21:39:11.0320 1936 C:\Windows\SysWOW64\netshell.dll - ok
21:39:11.0320 1936 [ 05411EF3E66659C63803563BB06C2E17 ] C:\Windows\System32\dimsjob.dll
21:39:11.0320 1936 C:\Windows\System32\dimsjob.dll - ok
21:39:11.0336 1936 [ 70C6489D56008D75DEDF73226FA63C11 ] C:\Windows\SysWOW64\dimsjob.dll
21:39:11.0336 1936 C:\Windows\SysWOW64\dimsjob.dll - ok
21:39:11.0336 1936 [ 48DC4268BAA33F8770F498F96100E301 ] C:\Windows\System32\pautoenr.dll
21:39:11.0336 1936 C:\Windows\System32\pautoenr.dll - ok
21:39:11.0336 1936 [ 98638A4CA187245C469DA0DEC4F04A45 ] C:\Windows\SysWOW64\pautoenr.dll
21:39:11.0336 1936 C:\Windows\SysWOW64\pautoenr.dll - ok
21:39:11.0351 1936 [ C88208718545410FA0F11E06F6E7F01B ] C:\Windows\System32\certcli.dll
21:39:11.0351 1936 C:\Windows\System32\certcli.dll - ok
21:39:11.0351 1936 [ AC48FD62E22C4425879FCA5A63F50497 ] C:\Windows\SysWOW64\certcli.dll
21:39:11.0351 1936 C:\Windows\SysWOW64\certcli.dll - ok
21:39:11.0351 1936 [ 0053319C4438CDE659AA75C19BBD22F1 ] C:\Windows\SysWOW64\CertEnroll.dll
21:39:11.0351 1936 C:\Windows\SysWOW64\CertEnroll.dll - ok
21:39:11.0367 1936 [ 5AF34B08C676F16A070A7D7EF2AB4C3E ] C:\Windows\System32\CertEnroll.dll
21:39:11.0367 1936 C:\Windows\System32\CertEnroll.dll - ok
21:39:11.0367 1936 [ 627920CFF5DFCF8CF54CF2D592D61307 ] C:\Windows\SysWOW64\WinSCard.dll
21:39:11.0367 1936 C:\Windows\SysWOW64\WinSCard.dll - ok
21:39:11.0382 1936 [ B519848DFA30AE2B306576B51321D102 ] C:\Windows\System32\ie4uinit.exe
21:39:11.0382 1936 C:\Windows\System32\ie4uinit.exe - ok
21:39:11.0382 1936 [ 4B19A9A4191353007E9819A832B81186 ] C:\Windows\SysWOW64\timedate.cpl
21:39:11.0382 1936 C:\Windows\SysWOW64\timedate.cpl - ok
21:39:11.0382 1936 [ DBBB05E1AD745B842BA790A3835637C8 ] C:\Windows\System32\timedate.cpl
21:39:11.0382 1936 C:\Windows\System32\timedate.cpl - ok
21:39:11.0398 1936 [ 27CEEAA8E6149FC6F2F9EE5E0BDAC5A5 ] C:\Windows\System32\actxprxy.dll
21:39:11.0398 1936 C:\Windows\System32\actxprxy.dll - ok
21:39:11.0398 1936 [ 8D78BA30DB4AE040A52EDEE725782715 ] C:\Windows\SysWOW64\actxprxy.dll
21:39:11.0398 1936 C:\Windows\SysWOW64\actxprxy.dll - ok
21:39:11.0398 1936 [ 72910BC4A218C49EA8E43D1FAEC403A5 ] C:\Windows\SysWOW64\winbrand.dll
21:39:11.0398 1936 C:\Windows\SysWOW64\winbrand.dll - ok
21:39:11.0414 1936 [ 5C45623C1A5EC70BCCB3090DB21BF075 ] C:\Windows\System32\msshsq.dll
21:39:11.0414 1936 C:\Windows\System32\msshsq.dll - ok
21:39:11.0414 1936 [ FF41E1AC301F51E16F61AD7C0F45467C ] C:\Windows\SysWOW64\msshsq.dll
21:39:11.0414 1936 C:\Windows\SysWOW64\msshsq.dll - ok
21:39:11.0414 1936 [ 1E642FBD902FB74778F57A76F8D620F5 ] C:\Windows\System32\NaturalLanguage6.dll
21:39:11.0414 1936 C:\Windows\System32\NaturalLanguage6.dll - ok
21:39:11.0429 1936 [ 1CE4A2790EB4A96F4ED1E4264866AFE6 ] C:\Windows\SysWOW64\NaturalLanguage6.dll
21:39:11.0429 1936 C:\Windows\SysWOW64\NaturalLanguage6.dll - ok
21:39:11.0429 1936 [ 90FABA79E004399E5FC69BBBD016CAF9 ] C:\Windows\System32\NlsData0009.dll
21:39:11.0429 1936 C:\Windows\System32\NlsData0009.dll - ok
21:39:11.0429 1936 [ AA111488C03C58A2BF66509ABB4FDE60 ] C:\Windows\SysWOW64\NlsData0009.dll
21:39:11.0429 1936 C:\Windows\SysWOW64\NlsData0009.dll - ok
21:39:11.0445 1936 [ C8E7E069468BC0DEAFE69375421FE839 ] C:\Windows\System32\NlsLexicons0009.dll
21:39:11.0445 1936 C:\Windows\System32\NlsLexicons0009.dll - ok
21:39:11.0445 1936 [ 8629B71343F61E1140243581C63BC0C7 ] C:\Windows\SysWOW64\NlsLexicons0009.dll
21:39:11.0445 1936 C:\Windows\SysWOW64\NlsLexicons0009.dll - ok
21:39:11.0445 1936 [ 58C2521D87C494831A625202C80354AD ] C:\Windows\SysWOW64\authui.dll
21:39:11.0445 1936 C:\Windows\SysWOW64\authui.dll - ok
21:39:11.0460 1936 [ 2EC53B5A351C4D443896DBAD117F7E82 ] C:\Windows\SysWOW64\msimg32.dll
21:39:11.0460 1936 C:\Windows\SysWOW64\msimg32.dll - ok
21:39:11.0460 1936 [ DE7F813217EC88C0A6D4D8F2F39D7949 ] C:\Windows\SysWOW64\msiltcfg.dll
21:39:11.0460 1936 C:\Windows\SysWOW64\msiltcfg.dll - ok
21:39:11.0460 1936 [ 0058E2924F2B6483591FAA7C2A6595A7 ] C:\Windows\System32\msiltcfg.dll
21:39:11.0460 1936 C:\Windows\System32\msiltcfg.dll - ok
21:39:11.0476 1936 [ 24F90AEFEBE601D427CB4511E74CDCB6 ] C:\Windows\SysWOW64\linkinfo.dll
21:39:11.0476 1936 C:\Windows\SysWOW64\linkinfo.dll - ok
21:39:11.0476 1936 [ 8BDE3074EE7BB92030448419E33635C7 ] C:\Windows\System32\linkinfo.dll
21:39:11.0476 1936 C:\Windows\System32\linkinfo.dll - ok
21:39:11.0476 1936 [ 64A3B1E55FBB7E36AE856FD1A8A4E00C ] C:\Windows\System32\ieframe.dll
21:39:11.0476 1936 C:\Windows\System32\ieframe.dll - ok
21:39:11.0492 1936 [ 1423FF1BFD2ECD9CFC8C17EA4F98B20F ] C:\Program Files\Internet Explorer\iexplore.exe
21:39:11.0492 1936 C:\Program Files\Internet Explorer\iexplore.exe - ok
21:39:11.0492 1936 [ E572915DB4DAD7F062D99334D9F10BFF ] C:\Windows\System32\networkexplorer.dll
21:39:11.0492 1936 C:\Windows\System32\networkexplorer.dll - ok
21:39:11.0492 1936 [ 82955BAF6EE545110F7CE768AECA4144 ] C:\Windows\System32\thumbcache.dll
21:39:11.0492 1936 C:\Windows\System32\thumbcache.dll - ok
21:39:11.0507 1936 [ 5016B8FC59AD616F03813FBE63295081 ] C:\Windows\SysWOW64\thumbcache.dll
21:39:11.0507 1936 C:\Windows\SysWOW64\thumbcache.dll - ok
21:39:11.0507 1936 [ B51A921F2CA7A068F5025D6EF3C5C8DD ] C:\Program Files\Windows Mail\WinMail.exe
21:39:11.0507 1936 C:\Program Files\Windows Mail\WinMail.exe - ok
21:39:11.0507 1936 [ BADC359C9A0D9C217B7E8DA17BF3F5BB ] C:\Windows\SysWOW64\ntshrui.dll
21:39:11.0507 1936 C:\Windows\SysWOW64\ntshrui.dll - ok
21:39:11.0523 1936 [ 079C4723655133D5F74A93E232A2E8A8 ] C:\Windows\System32\ntshrui.dll
21:39:11.0523 1936 C:\Windows\System32\ntshrui.dll - ok
21:39:11.0523 1936 [ 61216539E55DDF2F78E421E7EF140650 ] C:\Windows\SysWOW64\ExplorerFrame.dll
21:39:11.0523 1936 C:\Windows\SysWOW64\ExplorerFrame.dll - ok
21:39:11.0523 1936 [ 61C090AFC693640742904A4FA2409BBC ] C:\Windows\System32\ExplorerFrame.dll
21:39:11.0523 1936 C:\Windows\System32\ExplorerFrame.dll - ok
21:39:11.0523 1936 [ 27336F3CC6B3B53043D0666AC0CA4A7F ] C:\Windows\System32\notepad.exe
21:39:11.0523 1936 C:\Windows\System32\notepad.exe - ok
21:39:11.0538 1936 [ 0495EEF29F5B39AB4763BF5DE28FA3AA ] C:\Windows\SysWOW64\AUDIOKSE.dll
21:39:11.0538 1936 C:\Windows\SysWOW64\AUDIOKSE.dll - ok
21:39:11.0538 1936 [ E08935E54CEE225BEB3CC220CBCC734A ] C:\Windows\System32\AUDIOKSE.dll
21:39:11.0538 1936 C:\Windows\System32\AUDIOKSE.dll - ok
21:39:11.0538 1936 [ 661CEEDE98A2E0E5CDD7DE239EB38353 ] C:\PROGRA~2\WI1F86~1\MESSEN~1\msgslang.dll
21:39:11.0538 1936 C:\PROGRA~2\WI1F86~1\MESSEN~1\msgslang.dll - ok
21:39:11.0554 1936 [ 5F1825CB31F8B0DB5D478CDB2111FD2B ] C:\Windows\System32\CTAPO64.dll
21:39:11.0554 1936 C:\Windows\System32\CTAPO64.dll - ok
21:39:11.0554 1936 [ D40502554F623E736E93820898AA7CE4 ] C:\Windows\System32\DaisyWrp.dll
21:39:11.0554 1936 C:\Windows\System32\DaisyWrp.dll - ok
21:39:11.0570 1936 [ 814B65E22070E087479A275AAE1931AC ] C:\Windows\System32\control.exe
21:39:11.0570 1936 C:\Windows\System32\control.exe - ok
21:39:11.0570 1936 [ 484ACF6AF85A29AC52F3CF054DFDE9D3 ] C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
21:39:11.0570 1936 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe - ok
21:39:11.0570 1936 [ 9E341BB55760A87268862E40DBA1CEF0 ] C:\Windows\System32\accessibilitycpl.dll
21:39:11.0570 1936 C:\Windows\System32\accessibilitycpl.dll - ok
21:39:11.0585 1936 [ 649760A96BF5F9869F3040673900334F ] C:\Program Files\Microsoft Security Client\msseces.exe
21:39:11.0585 1936 C:\Program Files\Microsoft Security Client\msseces.exe - ok
21:39:11.0585 1936 [ DFFB91500638FACA4CDEA50E4E1F02F9 ] C:\Windows\System32\Magnify.exe
21:39:11.0585 1936 C:\Windows\System32\Magnify.exe - ok
21:39:11.0585 1936 [ E5C50D7F326AC51105B2737D31EEBDDB ] C:\Program Files\CCleaner\CCleaner64.exe
21:39:11.0585 1936 C:\Program Files\CCleaner\CCleaner64.exe - ok
21:39:11.0601 1936 [ 320889E9BD1F1A041CB69E6A81E484EC ] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
21:39:11.0601 1936 C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE - ok
21:39:11.0601 1936 [ 8A777C49978A4E03C4F1442E8FDC5CC2 ] C:\Windows\System32\osk.exe
21:39:11.0601 1936 C:\Windows\System32\osk.exe - ok
21:39:11.0601 1936 [ 9E3244FE8BA484E98461B8619C86F0D5 ] C:\Program Files\Windows Calendar\WinCal.exe
21:39:11.0601 1936 C:\Program Files\Windows Calendar\WinCal.exe - ok
21:39:11.0601 1936 [ 3842B5B168EF5CC382E99D2BDCAC1CA7 ] C:\Windows\System32\spool\drivers\x64\3\dldtpswx.exe
21:39:11.0601 1936 C:\Windows\System32\spool\drivers\x64\3\dldtpswx.exe - ok
21:39:11.0616 1936 [ 95A53EF79DF3A45643917EE485A9DB93 ] C:\Program Files\Defraggler\Defraggler64.exe
21:39:11.0616 1936 C:\Program Files\Defraggler\Defraggler64.exe - ok
21:39:11.0616 1936 [ 48DD40677817CE1053C2315F5A87E0D3 ] C:\Program Files\Windows Defender\MSASCui.exe
21:39:11.0616 1936 C:\Program Files\Windows Defender\MSASCui.exe - ok
21:39:11.0616 1936 [ 13E47C975E14031E7DC611191B70FD35 ] C:\Program Files\Movie Maker\DVDMaker.exe
21:39:11.0616 1936 C:\Program Files\Movie Maker\DVDMaker.exe - ok
21:39:11.0632 1936 [ FF0729002E081668620A681182D63FE6 ] C:\Windows\System32\wuapp.exe
21:39:11.0632 1936 C:\Windows\System32\wuapp.exe - ok
21:39:11.0632 1936 [ 50EBD31C3527366FAFA468BD609F7352 ] C:\Windows\System32\wucltux.dll
21:39:11.0632 1936 C:\Windows\System32\wucltux.dll - ok
21:39:11.0632 1936 [ BF2DD8B1253FB01CADB9C7C152984C89 ] C:\Windows\ehome\ehshell.exe
21:39:11.0632 1936 C:\Windows\ehome\ehshell.exe - ok
21:39:11.0648 1936 [ 8F50FB284B7C97C241F6F53E4C88453B ] C:\Program Files\Windows Collaboration\WinCollab.exe
21:39:11.0648 1936 C:\Program Files\Windows Collaboration\WinCollab.exe - ok
21:39:11.0648 1936 [ 5DD36EC36334E0ED4275AA3A55F5D22C ] C:\Program Files\Movie Maker\MOVIEMK.exe
21:39:11.0648 1936 C:\Program Files\Movie Maker\MOVIEMK.exe - ok
21:39:11.0648 1936 [ 7FB82497FBBF96ACC9E143E7F183BFA7 ] C:\Program Files\Windows Photo Gallery\WindowsPhotoGallery.exe
21:39:11.0648 1936 C:\Program Files\Windows Photo Gallery\WindowsPhotoGallery.exe - ok
21:39:11.0663 1936 [ C72A515E6835CB775A01BA4F42B1A730 ] C:\Windows\System32\calc.exe
21:39:11.0663 1936 C:\Windows\System32\calc.exe - ok
21:39:11.0663 1936 [ DB4A027E320B226D33F68C71D85103F6 ] C:\Windows\System32\mblctr.exe
21:39:11.0663 1936 C:\Windows\System32\mblctr.exe - ok
21:39:11.0663 1936 [ 32BFF048169F9A57B9BBAF2DC90EAC1B ] C:\Windows\System32\stobject.dll
21:39:11.0663 1936 C:\Windows\System32\stobject.dll - ok
21:39:11.0679 1936 [ 35ACD5EA63D75E97DD0E9A1629E582B2 ] C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_88f3a38569c2c436\comctl32.dll
21:39:11.0679 1936 C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6002.18305_none_88f3a38569c2c436\comctl32.dll - ok
21:39:11.0679 1936 [ B5950DF243837D8217F4E597919B224A ] C:\Windows\SysWOW64\stobject.dll
21:39:11.0679 1936 C:\Windows\SysWOW64\stobject.dll - ok
21:39:11.0679 1936 [ 2BE701D26CB99B94027142AA15535A35 ] C:\Windows\System32\RtkAPO64.dll
21:39:11.0679 1936 C:\Windows\System32\RtkAPO64.dll - ok
21:39:11.0679 1936 [ DE2B9C350BB7C9CF355972AB8CB9B865 ] C:\Windows\System32\WMALFXGFXDSP.dll
21:39:11.0679 1936 C:\Windows\System32\WMALFXGFXDSP.dll - ok
21:39:11.0694 1936 [ BF142D4F8C61ED3629A9CDD7BA867900 ] C:\Windows\SysWOW64\mfplat.dll
21:39:11.0694 1936 C:\Windows\SysWOW64\mfplat.dll - ok
21:39:11.0694 1936 [ B7BD00787568A178CDE26A83B5C847BE ] C:\Windows\System32\mfplat.dll
21:39:11.0694 1936 C:\Windows\System32\mfplat.dll - ok
21:39:11.0710 1936 [ EC69B16644C613F41A57169F8D068F1D ] C:\Windows\SysWOW64\batmeter.dll
21:39:11.0710 1936 C:\Windows\SysWOW64\batmeter.dll - ok
21:39:11.0710 1936 [ 93E888DA525F3DA1D8A94C174DDCC7C0 ] C:\Windows\System32\batmeter.dll
21:39:11.0710 1936 C:\Windows\System32\batmeter.dll - ok
21:39:11.0710 1936 [ 48B306A0F08606FEB6C6DD9BDF6E4E0F ] C:\Windows\System32\NetProj.exe
21:39:11.0710 1936 C:\Windows\System32\NetProj.exe - ok
21:39:11.0726 1936 [ D713FBECECD754FB7110CC5C4E0948F5 ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll
21:39:11.0726 1936 C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamext.dll - ok
21:39:11.0726 1936 [ 61D4DBC6D1C1C98DC935888295A89D01 ] C:\Windows\System32\NetProjW.dll
21:39:11.0726 1936 C:\Windows\System32\NetProjW.dll - ok
21:39:11.0726 1936 [ ABB1B50F36CCBEF119FBEF8FDF14AD61 ] C:\Program Files\SUPERAntiSpyware\SASCTXMN64.DLL
21:39:11.0726 1936 C:\Program Files\SUPERAntiSpyware\SASCTXMN64.DLL - ok
21:39:11.0741 1936 [ EC17B7D4A75411094727DAE280176F8A ] C:\PROGRA~1\MICROS~3\shellext.dll
21:39:11.0741 1936 C:\PROGRA~1\MICROS~3\shellext.dll - ok
21:39:11.0741 1936 [ 9FE95CFB68C4AC52B3D6683DD6276309 ] C:\Program Files (x86)\Driver Pro\DPLauncher.exe
21:39:11.0741 1936 C:\Program Files (x86)\Driver Pro\DPLauncher.exe - ok
21:39:11.0757 1936 [ EC0A7FB35A11EEF77C76781E122BAF0C ] C:\Windows\System32\mspaint.exe
21:39:11.0757 1936 C:\Windows\System32\mspaint.exe - ok
21:39:11.0757 1936 [ B5BACDED609EAF588A47CB4621C7E038 ] C:\Windows\SysWOW64\msxml3.dll
21:39:11.0757 1936 C:\Windows\SysWOW64\msxml3.dll - ok
21:39:11.0757 1936 [ 75EB974222F293159427F9A77A5F3C6A ] C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
21:39:11.0757 1936 C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll - ok
21:39:11.0772 1936 [ F146E2BA475893DD77B2370DC1211FC6 ] C:\Windows\System32\drivers\32480393.sys
21:39:11.0772 1936 C:\Windows\System32\drivers\32480393.sys - ok
21:39:11.0772 1936 [ B7A99C2F89380EC7A2C07D5190DEB228 ] C:\Program Files (x86)\AVG Secure Search\vprot.exe
21:39:11.0772 1936 C:\Program Files (x86)\AVG Secure Search\vprot.exe - ok
21:39:11.0772 1936 [ 4E1784B96F81FA2F561E5524CCD5FC7E ] C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4016_none_88dc01492fb256de\msvcr80.dll
21:39:11.0772 1936 C:\Windows\winsxs\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4016_none_88dc01492fb256de\msvcr80.dll - ok
21:39:11.0788 1936 [ 30485EC6C84241DDB0BD7B8A2EB6BB3C ] C:\Windows\System32\mstsc.exe
21:39:11.0788 1936 C:\Windows\System32\mstsc.exe - ok
21:39:11.0788 1936 [ 5C8C51B679B947F3DF948533C0926240 ] C:\Windows\System32\SndVolSSO.dll
21:39:11.0788 1936 C:\Windows\System32\SndVolSSO.dll - ok
21:39:11.0788 1936 [ 30F02D9C55053367E26A11482F51E255 ] C:\Windows\SysWOW64\SndVolSSO.dll
21:39:11.0788 1936 C:\Windows\SysWOW64\SndVolSSO.dll - ok
21:39:11.0804 1936 [ A8C05DD686FD7521914AAE742DECB0DA ] C:\Program Files\Common Files\Microsoft Shared\OFFICE11\msxml5.dll
21:39:11.0804 1936 C:\Program Files\Common Files\Microsoft Shared\OFFICE11\msxml5.dll - ok
21:39:11.0804 1936 [ 0CFCDE5D9D074D96B78D1F1CBF1AAB1D ] C:\Windows\SysWOW64\riched20.dll
21:39:11.0804 1936 C:\Windows\SysWOW64\riched20.dll - ok
21:39:11.0804 1936 [ 2EEEF8544DCAFE322301B68AA7F1D989 ] C:\Program Files (x86)\Dell Support Center\bin\sprtmessage.dll
21:39:11.0804 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtmessage.dll - ok
21:39:11.0819 1936 [ 11456E7C78A6C3D43E5D81CE8A899FA6 ] C:\Program Files (x86)\Dell Support Center\bin\sprtsched.dll
21:39:11.0819 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtsched.dll - ok
21:39:11.0819 1936 [ AF9B7F55AAB8229241E29FB82177DB30 ] C:\Program Files (x86)\Dell Support Center\bin\sprtevent.dll
21:39:11.0819 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtevent.dll - ok
21:39:11.0819 1936 [ 9A95D747564222F9DEAA57A09CB6714F ] C:\Program Files (x86)\Dell Support Center\bin\sprtfod.dll
21:39:11.0819 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtfod.dll - ok
21:39:11.0835 1936 [ 9F87943E4AEB051E37C8E157D14DD4F2 ] C:\Program Files\Defraggler\DefragglerShell64.dll
21:39:11.0835 1936 C:\Program Files\Defraggler\DefragglerShell64.dll - ok
21:39:11.0835 1936 [ 2424231BBD703A677D115C29983B4293 ] C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
21:39:11.0835 1936 C:\PROGRA~2\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL - ok
21:39:11.0835 1936 [ 9C5A0F070196B601D629F5BA9AA921F8 ] C:\Program Files\Windows Sidebar\sidebar.exe
21:39:11.0835 1936 C:\Program Files\Windows Sidebar\sidebar.exe - ok
21:39:11.0850 1936 [ 52E129522C1775DBB8CC252E7A0655C7 ] C:\Windows\SysWOW64\taskschd.dll
21:39:11.0850 1936 C:\Windows\SysWOW64\taskschd.dll - ok
21:39:11.0850 1936 [ 27DF2E313052DB2270972AD7CB15C8DB ] C:\Program Files (x86)\Dell Support Center\bin\sprtsync.dll
21:39:11.0850 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtsync.dll - ok
21:39:11.0850 1936 [ C9564CF4976E7E96B4052737AA2492B4 ] C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll
21:39:11.0850 1936 C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.6195_none_d09154e044272b9a\msvcr80.dll - ok
21:39:11.0866 1936 [ A395ABC175604A4F863A0ECF9EE794CA ] C:\Program Files (x86)\Dell Support Center\bin\sprtui.dll
21:39:11.0866 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtui.dll - ok
21:39:11.0866 1936 [ 128DD9AF8640DBCC711940903C8B554F ] C:\Windows\SysWOW64\mscoree.dll
21:39:11.0866 1936 C:\Windows\SysWOW64\mscoree.dll - ok
21:39:11.0866 1936 [ FF253B202C460492B9A35C457066CCC0 ] C:\Windows\ehome\ehSSO.dll
21:39:11.0866 1936 C:\Windows\ehome\ehSSO.dll - ok
21:39:11.0866 1936 [ F5DF6846F30E9F54EA60CCAEB3FB2055 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
21:39:11.0866 1936 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll - ok
21:39:11.0882 1936 [ 8269CC01940A202BBB9FDF26705DBD67 ] C:\Windows\SysWOW64\hid.dll
21:39:11.0882 1936 C:\Windows\SysWOW64\hid.dll - ok
21:39:11.0882 1936 [ 0B40AAC953EE451373FB8E26A73ADC94 ] C:\Windows\System32\SnippingTool.exe
21:39:11.0882 1936 C:\Windows\System32\SnippingTool.exe - ok
21:39:11.0882 1936 [ 6ECCE07B6A918E8A8639EA1178BDF32D ] C:\Windows\SysWOW64\syncui.dll
21:39:11.0897 1936 C:\Windows\SysWOW64\syncui.dll - ok
21:39:11.0897 1936 [ 9DBA941FCC46A45C55C7A2105FB794AC ] C:\Windows\System32\syncui.dll
21:39:11.0897 1936 C:\Windows\System32\syncui.dll - ok
21:39:11.0897 1936 [ 950343D413EEDC3A24472BB2046CFB59 ] C:\Windows\SysWOW64\synceng.dll
21:39:11.0897 1936 C:\Windows\SysWOW64\synceng.dll - ok
21:39:11.0897 1936 [ F7A5CC67E7ECEAFD6982F08A7AC60BD3 ] C:\Windows\System32\synceng.dll
21:39:11.0897 1936 C:\Windows\System32\synceng.dll - ok
21:39:11.0913 1936 [ 4E289C24E5BEB5FF9CF5B118AB96FDB0 ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
21:39:11.0913 1936 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - ok
21:39:11.0913 1936 [ F54D10EA2FE5EC846603A4CABDD6F235 ] C:\Windows\System32\mstask.dll
21:39:11.0913 1936 C:\Windows\System32\mstask.dll - ok
21:39:11.0913 1936 [ 5EFB4A0B6F794DA7380859F56E16CF8D ] C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll
21:39:11.0913 1936 C:\Program Files (x86)\AVG Secure Search\15.2.0.5\AVG Secure Search_toolbar.dll - ok
21:39:11.0928 1936 [ 75AD59B9B12EB194486BE8D97B062994 ] C:\Windows\SysWOW64\pnidui.dll
21:39:11.0928 1936 C:\Windows\SysWOW64\pnidui.dll - ok
21:39:11.0928 1936 [ DE95622B09554A70DB4F035D197330BF ] C:\Windows\System32\pnidui.dll
21:39:11.0928 1936 C:\Windows\System32\pnidui.dll - ok
21:39:11.0928 1936 [ 769D027B977CED05658C85E698D3C5B1 ] C:\Windows\SysWOW64\QUTIL.DLL
21:39:11.0928 1936 C:\Windows\SysWOW64\QUTIL.DLL - ok
21:39:11.0944 1936 [ 4DE3C4D07BAFDE616EFA0ADE076CBAC2 ] C:\Windows\SysWOW64\wevtapi.dll
21:39:11.0944 1936 C:\Windows\SysWOW64\wevtapi.dll - ok
21:39:11.0944 1936 [ 6A3CA5BEBA4598338E14DEE535144773 ] C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\15.2.0\ScriptHelper.exe
21:39:11.0944 1936 C:\Program Files (x86)\Common Files\AVG Secure Search\ScriptHelperInstaller\15.2.0\ScriptHelper.exe - ok
21:39:11.0944 1936 [ B0D16BC319E37E875C4B491460807051 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll
21:39:11.0944 1936 C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll - ok
21:39:11.0960 1936 [ EB2170D0DDF3B2A92506AE16BC524B0B ] C:\Windows\SysWOW64\wlanutil.dll
21:39:11.0960 1936 C:\Windows\SysWOW64\wlanutil.dll - ok
21:39:11.0960 1936 [ A8E2F76F136A0E664B68A48028D4AF93 ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
21:39:11.0960 1936 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll - ok
21:39:11.0960 1936 [ 4DD86EDDA09715DC235E41C1F698F041 ] C:\Windows\System32\wlanutil.dll
21:39:11.0960 1936 C:\Windows\System32\wlanutil.dll - ok
21:39:11.0975 1936 [ ECBAA8694660229262B781BEB7DDD625 ] C:\Windows\System32\SoundRecorder.exe
21:39:11.0975 1936 C:\Windows\System32\SoundRecorder.exe - ok
21:39:11.0975 1936 [ BE6FAC6F0745C67DAE7522C96406D083 ] C:\Windows\SysWOW64\sxs.dll
21:39:11.0975 1936 C:\Windows\SysWOW64\sxs.dll - ok
21:39:11.0975 1936 [ 4EDA94333BDB75B1BC0A7610BED34F00 ] C:\Windows\SysWOW64\fundisc.dll
21:39:11.0975 1936 C:\Windows\SysWOW64\fundisc.dll - ok
21:39:11.0975 1936 [ D5213329522F620A50EF2DBDC7F4D0D7 ] C:\Windows\SysWOW64\stdole2.tlb
21:39:11.0975 1936 C:\Windows\SysWOW64\stdole2.tlb - ok
21:39:11.0991 1936 [ 7FB90E3A267EFF618CA1E50014AB81AE ] C:\Windows\SysWOW64\en-US\tzres.dll.mui
21:39:11.0991 1936 C:\Windows\SysWOW64\en-US\tzres.dll.mui - ok
21:39:11.0991 1936 [ CEA69EEC43978AEEE8E3E02E07AD1A54 ] C:\Windows\SysWOW64\tzres.dll
21:39:11.0991 1936 C:\Windows\SysWOW64\tzres.dll - ok
21:39:12.0006 1936 [ ABAEAEE763E287BDD39094C4165E1F3F ] C:\Windows\SysWOW64\fdProxy.dll
21:39:12.0006 1936 C:\Windows\SysWOW64\fdProxy.dll - ok
21:39:12.0006 1936 [ 9DD626CC4FB7CAAC19B2F4C33CD6A2A3 ] C:\Windows\System32\fdProxy.dll
21:39:12.0006 1936 C:\Windows\System32\fdProxy.dll - ok
21:39:12.0006 1936 [ A41D6AFF8AFD743507887FD7747B35D3 ] C:\Windows\System32\mobsync.exe
21:39:12.0006 1936 C:\Windows\System32\mobsync.exe - ok
21:39:12.0022 1936 [ DFCAB29E8FD38F95650CC1E203E8D318 ] C:\Windows\SysWOW64\npmproxy.dll
21:39:12.0022 1936 C:\Windows\SysWOW64\npmproxy.dll - ok
21:39:12.0022 1936 [ 31519A9B25D4A8998EEC9C81E69269D9 ] C:\Windows\System32\fdWSD.dll
21:39:12.0022 1936 C:\Windows\System32\fdWSD.dll - ok
21:39:12.0022 1936 [ 8E29B921BC400F51276F781C4CFB87F6 ] C:\Windows\System32\oobefldr.dll
21:39:12.0022 1936 C:\Windows\System32\oobefldr.dll - ok
21:39:12.0038 1936 [ 5C5209B04B1942A534259C2AB7BB1EEA ] C:\Program Files (x86)\Dell Support Center\bin\libeay32.dll
21:39:12.0038 1936 C:\Program Files (x86)\Dell Support Center\bin\libeay32.dll - ok
21:39:12.0038 1936 [ 4BAEC13BCAA595639EBB5185278DEFEA ] C:\Windows\SysWOW64\fdWSD.dll
21:39:12.0038 1936 C:\Windows\SysWOW64\fdWSD.dll - ok
21:39:12.0038 1936 [ A151EF45E062C71B0CA34054C40BC6E4 ] C:\Program Files (x86)\Dell Support Center\bin\SupportSoft.Agent.Sprocket.SupportMessage.dll
21:39:12.0038 1936 C:\Program Files (x86)\Dell Support Center\bin\SupportSoft.Agent.Sprocket.SupportMessage.dll - ok
21:39:12.0053 1936 [ 3EB6D30D82F0E300FCFBAD0498F654FD ] C:\Windows\SysWOW64\mlang.dll
21:39:12.0053 1936 C:\Windows\SysWOW64\mlang.dll - ok
21:39:12.0053 1936 [ 2DD6AF8E97F59C9D39329BBC2A81F13F ] C:\Windows\SysWOW64\rasdlg.dll
21:39:12.0053 1936 C:\Windows\SysWOW64\rasdlg.dll - ok
21:39:12.0053 1936 [ A6FA5D45ACF2E855F890FAC505EFEDB2 ] C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll
21:39:12.0053 1936 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsec.dll - ok
21:39:12.0069 1936 [ F50B03EB7C150E44DF2843F2138D4F70 ] C:\Windows\System32\mlang.dll
21:39:12.0069 1936 C:\Windows\System32\mlang.dll - ok
21:39:12.0069 1936 [ 39872A309B2DB96738AF44402F7BD43C ] C:\Windows\System32\rasdlg.dll
21:39:12.0069 1936 C:\Windows\System32\rasdlg.dll - ok
21:39:12.0069 1936 [ DDCDE414B6DB14707DBD504EB23EF13E ] C:\Windows\System32\fdSSDP.dll
21:39:12.0069 1936 C:\Windows\System32\fdSSDP.dll - ok
21:39:12.0069 1936 [ 443C5961CACD4ABC16648874AF06E4A0 ] C:\Windows\SysWOW64\fdSSDP.dll
21:39:12.0084 1936 C:\Windows\SysWOW64\fdSSDP.dll - ok
21:39:12.0084 1936 [ F3851A4F60518BA1113C93B50F047EE1 ] C:\Windows\System32\hhctrl.ocx
21:39:12.0084 1936 C:\Windows\System32\hhctrl.ocx - ok
21:39:12.0084 1936 [ 56E315ACFB08A177B4D01E42B9044DB5 ] C:\Windows\SysWOW64\mprapi.dll
21:39:12.0084 1936 C:\Windows\SysWOW64\mprapi.dll - ok
21:39:12.0084 1936 [ 6468C3FF6D0C7874FA8C619AF3E23B22 ] C:\Windows\SysWOW64\activeds.dll
21:39:12.0084 1936 C:\Windows\SysWOW64\activeds.dll - ok
21:39:12.0100 1936 [ E9B9C1B98C8D6D48407E1C1203EAC659 ] C:\Windows\SysWOW64\adsldpc.dll
21:39:12.0100 1936 C:\Windows\SysWOW64\adsldpc.dll - ok
21:39:12.0100 1936 [ 93E317D7AD783D8EAEE2E3500BFE889D ] C:\Windows\SysWOW64\credui.dll
21:39:12.0100 1936 C:\Windows\SysWOW64\credui.dll - ok
21:39:12.0100 1936 [ 05B6A5CE1C7767C32DF35966107CB1EC ] C:\Windows\SysWOW64\hhctrl.ocx
21:39:12.0100 1936 C:\Windows\SysWOW64\hhctrl.ocx - ok
21:39:12.0100 1936 [ FAFD25FE1BE024AE20605DCD01F1C435 ] C:\Program Files\Windows NT\Accessories\wordpad.exe
21:39:12.0100 1936 C:\Program Files\Windows NT\Accessories\wordpad.exe - ok
21:39:12.0116 1936 [ B6A7E7F43234BFA6A8E6CC4110CB9448 ] C:\Program Files\Windows Media Player\wmpnscfg.exe
21:39:12.0116 1936 C:\Program Files\Windows Media Player\wmpnscfg.exe - ok
21:39:12.0116 1936 [ 98947A11E0EB117C8E503DE3EBD3955D ] C:\Program Files (x86)\Dell Support Center\bin\SupportSoft.Agent.Sprocket.dll
21:39:12.0116 1936 C:\Program Files (x86)\Dell Support Center\bin\SupportSoft.Agent.Sprocket.dll - ok
21:39:12.0116 1936 [ 2F3390C8E3620B3991D7D82014E26AA7 ] C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe
21:39:12.0116 1936 C:\Users\dianne\AppData\Local\Google\Chrome\Application\chrome.exe - ok
21:39:12.0131 1936 [ 376D1B585060CD65BEEFE15A8577FCA0 ] C:\Windows\System32\sfc_os.dll
21:39:12.0131 1936 C:\Windows\System32\sfc_os.dll - ok
21:39:12.0131 1936 [ 17C0E094BEE5BC03CF491972F71AA6EF ] C:\Windows\SysWOW64\wlanapi.dll
21:39:12.0131 1936 C:\Windows\SysWOW64\wlanapi.dll - ok
21:39:12.0131 1936 [ 483E6FE556B3146D5A634B8552FDD15C ] C:\Windows\System32\wlanapi.dll
21:39:12.0131 1936 C:\Windows\System32\wlanapi.dll - ok
21:39:12.0147 1936 [ 92D1B7E3981A24B8F3093CE42AB31C68 ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll
21:39:12.0147 1936 C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll - ok
21:39:12.0147 1936 [ B64AC7967D6B9FB2D6152AC768A1CB88 ] C:\Windows\SysWOW64\onex.dll
21:39:12.0147 1936 C:\Windows\SysWOW64\onex.dll - ok
21:39:12.0147 1936 [ DED15764B578A26BE9E45E7692820549 ] C:\Windows\System32\onex.dll
21:39:12.0147 1936 C:\Windows\System32\onex.dll - ok
21:39:12.0162 1936 [ 9D9FFC923FADBB575E0452EA0BBB15BD ] C:\Windows\SysWOW64\eappprxy.dll
21:39:12.0162 1936 C:\Windows\SysWOW64\eappprxy.dll - ok
21:39:12.0162 1936 [ B50D0BF177657752B826697259341858 ] C:\Windows\System32\eappprxy.dll
21:39:12.0162 1936 C:\Windows\System32\eappprxy.dll - ok
21:39:12.0162 1936 [ 5D0FE613570CABE3992F7DBCD68E61D1 ] C:\Windows\SysWOW64\eappcfg.dll
21:39:12.0162 1936 C:\Windows\SysWOW64\eappcfg.dll - ok
21:39:12.0178 1936 [ 03FDED7449428CE493432EE35FE5A2FB ] C:\Windows\System32\eappcfg.dll
21:39:12.0178 1936 C:\Windows\System32\eappcfg.dll - ok
21:39:12.0178 1936 [ CE881FB400AAFE32D3DC0A7561B547C2 ] C:\Windows\Speech\Common\sapisvr.exe
21:39:12.0178 1936 C:\Windows\Speech\Common\sapisvr.exe - ok
21:39:12.0178 1936 [ 4FDF6B8B9449D4AF1D98A0705CB6747D ] C:\Windows\System32\Speech\SpeechUX\sapi.cpl
21:39:12.0178 1936 C:\Windows\System32\Speech\SpeechUX\sapi.cpl - ok
21:39:12.0178 1936 [ F4D9ED6BD74AD7CC0BEC83C43A1CB76B ] C:\Windows\SysWOW64\ncsi.dll
21:39:12.0178 1936 C:\Windows\SysWOW64\ncsi.dll - ok
21:39:12.0194 1936 [ C1303E3D550F2934BA825A80D335D18A ] C:\Windows\System32\sdclt.exe
21:39:12.0194 1936 C:\Windows\System32\sdclt.exe - ok
21:39:12.0194 1936 [ 697D6CAF74F39C7F0017088C6F6B5C33 ] C:\Program Files\Windows Media Player\wmpnssci.dll
21:39:12.0194 1936 C:\Program Files\Windows Media Player\wmpnssci.dll - ok
21:39:12.0194 1936 [ FDAC777249FC4A5ED75FF3F563817FA1 ] C:\Windows\System32\AltTab.dll
21:39:12.0194 1936 C:\Windows\System32\AltTab.dll - ok
21:39:12.0209 1936 [ 4A839160ED1963F9A1526DDA2D1233B2 ] C:\Windows\SysWOW64\AltTab.dll
21:39:12.0209 1936 C:\Windows\SysWOW64\AltTab.dll - ok
21:39:12.0209 1936 [ 38D057FA41217FB904B3A0BC34B8D367 ] C:\Windows\System32\charmap.exe
21:39:12.0209 1936 C:\Windows\System32\charmap.exe - ok
21:39:12.0209 1936 [ 6B28D35E4C2C9D9ABA083EE4F9FD51CC ] C:\Windows\System32\WPDShServiceObj.dll
21:39:12.0209 1936 C:\Windows\System32\WPDShServiceObj.dll - ok
21:39:12.0225 1936 [ 6B5C53E0932C510606D700B7A896EF73 ] C:\Windows\SysWOW64\WPDShServiceObj.dll
21:39:12.0225 1936 C:\Windows\SysWOW64\WPDShServiceObj.dll - ok
21:39:12.0225 1936 [ A0A92B5F2926C52A3FF415E928BC9301 ] C:\Windows\System32\PortableDeviceTypes.dll
21:39:12.0225 1936 C:\Windows\System32\PortableDeviceTypes.dll - ok
21:39:12.0225 1936 [ 883D02AB5D350BC45E0F60E8CFA97FDC ] C:\Windows\SysWOW64\PortableDeviceTypes.dll
21:39:12.0225 1936 C:\Windows\SysWOW64\PortableDeviceTypes.dll - ok
21:39:12.0240 1936 [ 961359F17AE51A7E2D105F7A2B3F4ACE ] C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll
21:39:12.0240 1936 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll - ok
21:39:12.0240 1936 [ 2205A220A264E8C8B86492BF3D112907 ] C:\Windows\SysWOW64\PortableDeviceApi.dll
21:39:12.0240 1936 C:\Windows\SysWOW64\PortableDeviceApi.dll - ok
21:39:12.0240 1936 [ FEA6D21F78922D641A0C9346D885133B ] C:\Windows\SysWOW64\mssprxy.dll
21:39:12.0240 1936 C:\Windows\SysWOW64\mssprxy.dll - ok
21:39:12.0256 1936 [ B6D5917CF9FDA3B434AD908559EBD2B3 ] C:\Windows\System32\srchadmin.dll
21:39:12.0256 1936 C:\Windows\System32\srchadmin.dll - ok
21:39:12.0256 1936 [ 744F08CF9ACFFB1C715191D04DEEE907 ] C:\Windows\SysWOW64\srchadmin.dll
21:39:12.0256 1936 C:\Windows\SysWOW64\srchadmin.dll - ok
21:39:12.0256 1936 [ 4ABCE74D012971305249E45E095E9EA6 ] C:\Windows\SysWOW64\msv1_0.dll
21:39:12.0256 1936 C:\Windows\SysWOW64\msv1_0.dll - ok
21:39:12.0272 1936 [ 459B48188494490707DCA8BAA91AA185 ] C:\Windows\SysWOW64\cryptdll.dll
21:39:12.0272 1936 C:\Windows\SysWOW64\cryptdll.dll - ok
21:39:12.0272 1936 [ 5193DE33F3284C447E0D31DAFBF92570 ] C:\Windows\SysWOW64\webcheck.dll
21:39:12.0272 1936 C:\Windows\SysWOW64\webcheck.dll - ok
21:39:12.0272 1936 [ D7CEAEDD5F75D2C8A2E80887D7C114CE ] C:\Windows\System32\webcheck.dll
21:39:12.0272 1936 C:\Windows\System32\webcheck.dll - ok
21:39:12.0287 1936 [ FDFE2FB34497CF0166070DE685207839 ] C:\Windows\System32\bitsprx2.dll
21:39:12.0287 1936 C:\Windows\System32\bitsprx2.dll - ok
21:39:12.0287 1936 [ EE8E76761A4AEE5685D92A770A3B4B1F ] C:\Program Files (x86)\Dell Support Center\gs_agent\dsc.exe
21:39:12.0287 1936 C:\Program Files (x86)\Dell Support Center\gs_agent\dsc.exe - ok
21:39:12.0287 1936 [ 3A0084039D1A845BE595E5AE62DB687A ] C:\Windows\SysWOW64\bitsprx2.dll
21:39:12.0287 1936 C:\Windows\SysWOW64\bitsprx2.dll - ok
21:39:12.0303 1936 [ E1748B86DC11BACA3400B92BB21913CE ] C:\Windows\System32\dfrgui.exe
21:39:12.0303 1936 C:\Windows\System32\dfrgui.exe - ok
21:39:12.0303 1936 [ 7E38DA8C11833B99766A97CEE3F80F07 ] C:\Windows\SysWOW64\oleaccrc.dll
21:39:12.0303 1936 C:\Windows\SysWOW64\oleaccrc.dll - ok
21:39:12.0303 1936 [ BEFEA8615D5D216784D9A4EB9C070D85 ] C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\npsitesafety.dll
21:39:12.0303 1936 C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\npsitesafety.dll - ok
21:39:12.0318 1936 [ E55DE59CD89138BD973602F9F202E84D ] C:\Windows\System32\SyncCenter.dll
21:39:12.0318 1936 C:\Windows\System32\SyncCenter.dll - ok
21:39:12.0318 1936 [ 9AB7D66BB3542560176A3B58FC6D96AA ] C:\Windows\System32\bitsprx4.dll
21:39:12.0318 1936 C:\Windows\System32\bitsprx4.dll - ok
21:39:12.0318 1936 [ 9F8E9C1021FB88CDD057EFAD97F7FB58 ] C:\Windows\SysWOW64\bitsprx4.dll
21:39:12.0318 1936 C:\Windows\SysWOW64\bitsprx4.dll - ok
21:39:12.0334 1936 [ 4ACEA0C4BB15ACE55E3AE5EC4E88DD55 ] C:\Windows\SysWOW64\SyncCenter.dll
21:39:12.0334 1936 C:\Windows\SysWOW64\SyncCenter.dll - ok
21:39:12.0334 1936 [ 0B5AC46982E77CAF3EC1D55C9AC6AB56 ] C:\Windows\SysWOW64\wscntfy.dll
21:39:12.0334 1936 C:\Windows\SysWOW64\wscntfy.dll - ok
21:39:12.0334 1936 [ 70DD82E202BD8022452DC8D2B73231AA ] C:\Windows\System32\wscntfy.dll
21:39:12.0334 1936 C:\Windows\System32\wscntfy.dll - ok
21:39:12.0350 1936 [ A0F4852A5DB9754BEC06F84B400AE743 ] C:\Windows\SysWOW64\wscapi.dll
21:39:12.0350 1936 C:\Windows\SysWOW64\wscapi.dll - ok
21:39:12.0350 1936 [ ED10D55B28FCD8A6DEA09AE3FE20EC3A ] C:\Windows\System32\imapi2.dll
21:39:12.0350 1936 C:\Windows\System32\imapi2.dll - ok
21:39:12.0350 1936 [ 3114B77580977DE57E497745BDA1644C ] C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\icudt.dll
21:39:12.0350 1936 C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\icudt.dll - ok
21:39:12.0365 1936 [ 648AB74D9C104FB500B6C4EEDC6A8772 ] C:\Windows\SysWOW64\wmpmde.dll
21:39:12.0365 1936 C:\Windows\SysWOW64\wmpmde.dll - ok
21:39:12.0365 1936 [ 2620C17442BAA264DBE18953FFD10889 ] C:\Windows\System32\wmpmde.dll
21:39:12.0365 1936 C:\Windows\System32\wmpmde.dll - ok
21:39:12.0365 1936 [ 9B0726A03B790E5B82BED44D24009BEF ] C:\Windows\SysWOW64\imapi2.dll
21:39:12.0365 1936 C:\Windows\SysWOW64\imapi2.dll - ok
21:39:12.0365 1936 [ A0E5DA35F70271364C7B33227D4A4FFC ] C:\Windows\SysWOW64\KBDUS.DLL
21:39:12.0365 1936 C:\Windows\SysWOW64\KBDUS.DLL - ok
21:39:12.0381 1936 [ CD5622760DA7B442261C9571C07D63C7 ] C:\Windows\SysWOW64\en-US\MMDevAPI.dll.mui
21:39:12.0381 1936 C:\Windows\SysWOW64\en-US\MMDevAPI.dll.mui - ok
21:39:12.0381 1936 [ BDE89AB6F15F0093A2A7861D1FC413ED ] C:\Windows\SysWOW64\QAGENT.DLL
21:39:12.0381 1936 C:\Windows\SysWOW64\QAGENT.DLL - ok
21:39:12.0381 1936 [ C0ABD66F31C0B84CD944802E6D3D02C2 ] C:\Windows\SysWOW64\bthprops.cpl
21:39:12.0381 1936 C:\Windows\SysWOW64\bthprops.cpl - ok
21:39:12.0396 1936 [ DBC0B012A13C7738871D569005DEB5D1 ] C:\Windows\System32\bthprops.cpl
21:39:12.0412 1936 C:\Windows\System32\bthprops.cpl - ok
21:39:12.0412 1936 [ 10DEAF6B32EB834F5C534EB942111FA8 ] C:\Windows\System32\migwiz\migwiz.exe
21:39:12.0412 1936 C:\Windows\System32\migwiz\migwiz.exe - ok
21:39:12.0412 1936 [ 67D16247C56C26A4F0D79D1A7F272B8F ] C:\Windows\SysWOW64\mf.dll
21:39:12.0412 1936 C:\Windows\SysWOW64\mf.dll - ok
21:39:12.0412 1936 [ C56EBA7C1D396FCAF3C8D6867EF1C10E ] C:\Windows\System32\mf.dll
21:39:12.0412 1936 C:\Windows\System32\mf.dll - ok
21:39:12.0428 1936 [ A4AF702E6BB80D014C56EDE22C6BC423 ] C:\Windows\System32\msinfo32.exe
21:39:12.0428 1936 C:\Windows\System32\msinfo32.exe - ok
21:39:12.0428 1936 [ 8DBF26D220D8EE44D7A6286BE2F2C767 ] C:\Windows\System32\rstrui.exe
21:39:12.0428 1936 C:\Windows\System32\rstrui.exe - ok
21:39:12.0428 1936 [ DB83DA870C2C9A612A07A635444BA846 ] C:\Windows\System32\miguiresource.dll
21:39:12.0428 1936 C:\Windows\System32\miguiresource.dll - ok
21:39:12.0443 1936 [ 549D573FE2B83C3ECF7553E8996DFA17 ] C:\Windows\System32\StikyNot.exe
21:39:12.0443 1936 C:\Windows\System32\StikyNot.exe - ok
21:39:12.0443 1936 [ A4E789205FB6C1FC0FB2FD3898455F57 ] C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
21:39:12.0443 1936 C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe - ok
21:39:12.0443 1936 [ 76EAEF4DDEBBC7C38853F586C0E91DCE ] C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\GdiPlus.dll
21:39:12.0443 1936 C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18581_none_9e591052ca1013d0\GdiPlus.dll - ok
21:39:12.0459 1936 [ 75EB73E64F5B4655D9797D20F26DE320 ] C:\Windows\SysWOW64\duser.dll
21:39:12.0459 1936 C:\Windows\SysWOW64\duser.dll - ok
21:39:12.0459 1936 [ 4F69B3864A6FA36744E275BABD731B74 ] C:\Program Files\Windows Journal\Journal.exe
21:39:12.0459 1936 C:\Program Files\Windows Journal\Journal.exe - ok
21:39:12.0474 1936 [ A9662BCF218BC76869A8D91635D5F93A ] C:\Windows\SysWOW64\Wpc.dll
21:39:12.0474 1936 C:\Windows\SysWOW64\Wpc.dll - ok
21:39:12.0474 1936 [ 2495C4204C63678F8FD5D488CA7DAD26 ] C:\Windows\SysWOW64\evr.dll
21:39:12.0474 1936 C:\Windows\SysWOW64\evr.dll - ok
21:39:12.0474 1936 [ AF96CCADA9B7ADB6488DDB6A60374821 ] C:\Windows\System32\evr.dll
21:39:12.0474 1936 C:\Windows\System32\evr.dll - ok
21:39:12.0474 1936 [ F9F9E7F0D4EBAC06334C9BF76C9E11B4 ] C:\Windows\SysWOW64\sud.dll
21:39:12.0474 1936 C:\Windows\SysWOW64\sud.dll - ok
21:39:12.0490 1936 [ A194808A2D7726151CAA835D69605BD2 ] C:\Windows\SysWOW64\en-US\user32.dll.mui
21:39:12.0490 1936 C:\Windows\SysWOW64\en-US\user32.dll.mui - ok
21:39:12.0490 1936 [ 9A7F4B2EDACD11444D048AA19CBB26AF ] C:\Windows\SysWOW64\powrprof.dll
21:39:12.0490 1936 C:\Windows\SysWOW64\powrprof.dll - ok
21:39:12.0490 1936 [ 3A72AB0BAF2DC1AE0BA6E1EE28FFCC0B ] C:\Windows\SysWOW64\msftedit.dll
21:39:12.0490 1936 C:\Windows\SysWOW64\msftedit.dll - ok
21:39:12.0506 1936 [ 4CAAD229A00C0DEFFF51841AE2B93B46 ] C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshmsg.dll
21:39:12.0506 1936 C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshmsg.dll - ok
21:39:12.0506 1936 [ 4DF10CE50010D70152944B51E03588B0 ] C:\Windows\SysWOW64\wmdrmsdk.dll
21:39:12.0506 1936 C:\Windows\SysWOW64\wmdrmsdk.dll - ok
21:39:12.0506 1936 [ BADF546E20F3B6A8630EA80EB9E657C3 ] C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
21:39:12.0506 1936 C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe - ok
21:39:12.0521 1936 [ 590D8BF1D514FC519CEFE9C1815FE41D ] C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe
21:39:12.0521 1936 C:\Windows\System32\WindowsPowerShell\v1.0\powershell_ise.exe - ok
21:39:12.0521 1936 [ A6F5B25905CD01AE714990E02C7205A5 ] C:\Windows\SysWOW64\mshtml.dll
21:39:12.0521 1936 C:\Windows\SysWOW64\mshtml.dll - ok
21:39:12.0521 1936 [ 520083E0BBA384EC5CBE44A2EB8ADF49 ] C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll
21:39:12.0521 1936 C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\pdf.dll - ok
21:39:12.0537 1936 [ 19C3F7E0FC407E2F307D82FAB0858DDE ] C:\Windows\System32\WindowsPowerShell\v1.0\pwrshmsg.dll
21:39:12.0537 1936 C:\Windows\System32\WindowsPowerShell\v1.0\pwrshmsg.dll - ok
21:39:12.0537 1936 [ A949AA49376F8CB91D19EA8A7ADC94D4 ] C:\Windows\System32\wmdrmsdk.dll
21:39:12.0537 1936 C:\Windows\System32\wmdrmsdk.dll - ok
21:39:12.0537 1936 [ 8AA015739AA5D31E19E853FD1554C769 ] C:\Windows\System32\mycomput.dll
21:39:12.0537 1936 C:\Windows\System32\mycomput.dll - ok
21:39:12.0552 1936 [ F91D87E625D94F74477525861F7B38D7 ] C:\Windows\System32\odbcad32.exe
21:39:12.0552 1936 C:\Windows\System32\odbcad32.exe - ok
21:39:12.0552 1936 [ 53E401AE1E8CEF522E00576650CC11EB ] C:\Windows\System32\odbcint.dll
21:39:12.0552 1936 C:\Windows\System32\odbcint.dll - ok
21:39:12.0552 1936 [ EFD278F8129EE12F1D4AE0250494B791 ] C:\Windows\SysWOW64\dxva2.dll
21:39:12.0552 1936 C:\Windows\SysWOW64\dxva2.dll - ok
21:39:12.0568 1936 [ F041AB49DE23CC8BDB404EE59CD1935D ] C:\Windows\System32\dxva2.dll
21:39:12.0568 1936 C:\Windows\System32\dxva2.dll - ok
21:39:12.0568 1936 [ 3192ED5E2FFDF5B630541B9643AE1AA3 ] C:\Windows\SysWOW64\upnp.dll
21:39:12.0568 1936 C:\Windows\SysWOW64\upnp.dll - ok
21:39:12.0568 1936 [ 688844EFB733D426D90A56499B5DC6CD ] C:\Windows\System32\iscsicpl.exe
21:39:12.0568 1936 C:\Windows\System32\iscsicpl.exe - ok
21:39:12.0584 1936 [ 01BCD91CC2B0EFDA4890F547010750BD ] C:\Windows\SysWOW64\ssdpapi.dll
21:39:12.0584 1936 C:\Windows\SysWOW64\ssdpapi.dll - ok
21:39:12.0584 1936 [ 8BAFE3351162FB7CD8E392BA93B25EB4 ] C:\Windows\System32\iscsicpl.dll
21:39:12.0584 1936 C:\Windows\System32\iscsicpl.dll - ok
21:39:12.0584 1936 [ DE489A291F364B1473D6858560107113 ] C:\Windows\System32\wmp.dll
21:39:12.0584 1936 C:\Windows\System32\wmp.dll - ok
21:39:12.0599 1936 [ BEEBCBC84D58FC34B3C9DD3A24BB8F24 ] C:\Windows\System32\MdSched.exe
21:39:12.0599 1936 C:\Windows\System32\MdSched.exe - ok
21:39:12.0599 1936 [ 832726DEFA39BBA2D34C9E20CEA471C0 ] C:\Windows\System32\wdc.dll
21:39:12.0599 1936 C:\Windows\System32\wdc.dll - ok
21:39:12.0599 1936 [ 256AD83B5C6B3F36247AFCF3A95EFCF9 ] C:\Windows\System32\filemgmt.dll
21:39:12.0599 1936 C:\Windows\System32\filemgmt.dll - ok
21:39:12.0615 1936 [ F1F799F596CA296EE9725EFEA01A63D7 ] C:\Windows\System32\msconfig.exe
21:39:12.0615 1936 C:\Windows\System32\msconfig.exe - ok
21:39:12.0615 1936 [ 03C1410DBD7B35D105B732424FEB7516 ] C:\Windows\System32\AuthFWGP.dll
21:39:12.0615 1936 C:\Windows\System32\AuthFWGP.dll - ok
21:39:12.0615 1936 [ 67EE46FD4D3B56531C5DD1BDC149275A ] C:\Program Files (x86)\Internet Explorer\iexplore.exe
21:39:12.0615 1936 C:\Program Files (x86)\Internet Explorer\iexplore.exe - ok
21:39:12.0630 1936 [ 31AD317E7A1CF817AA7790FA5C7948F3 ] C:\Program Files\Dell V305\Install\x64\Uninst.exe
21:39:12.0630 1936 C:\Program Files\Dell V305\Install\x64\Uninst.exe - ok
21:39:12.0630 1936 [ 8579C0D9B4850EC834507B51B635EA74 ] C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\chrome.dll
21:39:12.0630 1936 C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\chrome.dll - ok
21:39:12.0630 1936 [ B5EF1DA337DB9859709A387638AC5E07 ] C:\Windows\SysWOW64\SearchProtocolHost.exe
21:39:12.0630 1936 C:\Windows\SysWOW64\SearchProtocolHost.exe - ok
21:39:12.0630 1936 [ 1DEAF8D21FCCB72FFCF374E0FE6C1DB5 ] C:\Windows\System32\SearchProtocolHost.exe
21:39:12.0630 1936 C:\Windows\System32\SearchProtocolHost.exe - ok
21:39:12.0646 1936 [ DEB9D08750423069647C3A066CEC7A1B ] C:\Windows\SysWOW64\tquery.dll
21:39:12.0646 1936 C:\Windows\SysWOW64\tquery.dll - ok
21:39:12.0646 1936 [ 582BE479E7E286BB3B31C5A4C3DC3987 ] C:\Windows\SysWOW64\msshooks.dll
21:39:12.0646 1936 C:\Windows\SysWOW64\msshooks.dll - ok
21:39:12.0646 1936 [ AAB5FEAABF4CB6F76D794203831C8D94 ] C:\Windows\SysWOW64\msidle.dll
21:39:12.0646 1936 C:\Windows\SysWOW64\msidle.dll - ok
21:39:12.0662 1936 [ 771AF583BC58373A84496CCD52C36E33 ] C:\Windows\SysWOW64\mssvp.dll
21:39:12.0662 1936 C:\Windows\SysWOW64\mssvp.dll - ok
21:39:12.0662 1936 [ 98C77FD99F3DB37B2C03F32B8F837B65 ] C:\Windows\SysWOW64\mapi32.dll
21:39:12.0662 1936 C:\Windows\SysWOW64\mapi32.dll - ok
21:39:12.0662 1936 [ 351319EF11C263C95FB721AC76F436D6 ] C:\Windows\SysWOW64\mssph.dll
21:39:12.0662 1936 C:\Windows\SysWOW64\mssph.dll - ok
21:39:12.0677 1936 [ 365828E555E9479246EFD9090C41C2D7 ] C:\Windows\SysWOW64\sti.dll
21:39:12.0677 1936 C:\Windows\SysWOW64\sti.dll - ok
21:39:12.0677 1936 [ E953EB7C4E1A369EE98E3B25006891CA ] C:\Program Files\Microsoft Office\Office12\ONFILTER.DLL
21:39:12.0677 1936 C:\Program Files\Microsoft Office\Office12\ONFILTER.DLL - ok
21:39:12.0677 1936 [ 28B9DBA6201AEDDC65C15FA48939804A ] C:\Windows\SysWOW64\wmp.dll
21:39:12.0677 1936 C:\Windows\SysWOW64\wmp.dll - ok
21:39:12.0693 1936 [ AC6B8F8058EE27932F9AF8A2D959D201 ] C:\Windows\SysWOW64\msimtf.dll
21:39:12.0693 1936 C:\Windows\SysWOW64\msimtf.dll - ok
21:39:12.0693 1936 [ 19C69E1F96A4E4D92822002D6EEE9913 ] C:\Windows\System32\msvfw32.dll
21:39:12.0693 1936 C:\Windows\System32\msvfw32.dll - ok
21:39:12.0693 1936 [ C2CDBB424CF2461199322D6825F7B426 ] C:\Windows\SysWOW64\msfeeds.dll
21:39:12.0693 1936 C:\Windows\SysWOW64\msfeeds.dll - ok
21:39:12.0708 1936 [ 35AAE2E841AA1A949775168E119482C9 ] C:\Windows\SysWOW64\msls31.dll
21:39:12.0708 1936 C:\Windows\SysWOW64\msls31.dll - ok
21:39:12.0708 1936 [ 94D616EBF8A3D2F7F8300F255E377A80 ] C:\Windows\System32\wmploc.DLL
21:39:12.0708 1936 C:\Windows\System32\wmploc.DLL - ok
21:39:12.0708 1936 [ 79D62639853A5C1B5AD4A822F627ADD1 ] C:\Users\dianne\AppData\Local\Google\Chrome\Application\wow_helper.exe
21:39:12.0708 1936 C:\Users\dianne\AppData\Local\Google\Chrome\Application\wow_helper.exe - ok
21:39:12.0724 1936 [ 57E68AE0BCEB0F70C8AA1C4A6D5C2050 ] C:\Windows\SysWOW64\jscript9.dll
21:39:12.0724 1936 C:\Windows\SysWOW64\jscript9.dll - ok
21:39:12.0724 1936 [ 5F1DEC3824E566457F53F24F493FEF08 ] C:\Windows\SysWOW64\mscms.dll
21:39:12.0724 1936 C:\Windows\SysWOW64\mscms.dll - ok
21:39:12.0724 1936 [ E4D4500B9F619DF2F1765FE259B12A4F ] C:\Windows\System32\WindowsAnytimeUpgrade.exe
21:39:12.0724 1936 C:\Windows\System32\WindowsAnytimeUpgrade.exe - ok
21:39:12.0740 1936 [ 23E4E5A6876082BADECA7B80DD7B21C0 ] C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll
21:39:12.0740 1936 C:\Windows\System32\WindowsAnytimeUpgradeCPL.dll - ok
21:39:12.0740 1936 [ E9B39C81C87E5B790FCE121DA9E02701 ] C:\Windows\SysWOW64\d2d1.dll
21:39:12.0740 1936 C:\Windows\SysWOW64\d2d1.dll - ok
21:39:12.0740 1936 [ CABD1B34BD05C986B4DBC18BC0E947EE ] C:\Windows\SysWOW64\DWrite.dll
21:39:12.0740 1936 C:\Windows\SysWOW64\DWrite.dll - ok
21:39:12.0755 1936 [ 3794B461C45882E06856F282EEF025AF ] C:\Windows\SysWOW64\svchost.exe
21:39:12.0755 1936 C:\Windows\SysWOW64\svchost.exe - ok
21:39:12.0755 1936 [ B64607864E8FF80DE35DB20D1F6BF489 ] C:\Windows\SysWOW64\en-US\svchost.exe.mui
21:39:12.0755 1936 C:\Windows\SysWOW64\en-US\svchost.exe.mui - ok
21:39:12.0771 1936 [ CA0B849566776A17F35F0339BE17DFD9 ] C:\Windows\SysWOW64\ktmw32.dll
21:39:12.0771 1936 C:\Windows\SysWOW64\ktmw32.dll - ok
21:39:12.0771 1936 [ DF4F9708003752B4C475300BEC1F042B ] C:\Program Files\Microsoft Games\Chess\Chess.exe
21:39:12.0771 1936 C:\Program Files\Microsoft Games\Chess\Chess.exe - ok
21:39:12.0771 1936 [ EBCEDFD064A4F210037AD21EC8AFC220 ] C:\Windows\System32\msshooks.dll
21:39:12.0771 1936 C:\Windows\System32\msshooks.dll - ok
21:39:12.0786 1936 [ D9F0D37D97862C15D1417903B8FCBF5C ] C:\Windows\System32\mssvp.dll
21:39:12.0786 1936 C:\Windows\System32\mssvp.dll - ok
21:39:12.0786 1936 [ CD2B49ACFAD057AD5577AA26040CC052 ] C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe
21:39:12.0786 1936 C:\Program Files\Microsoft Games\FreeCell\FreeCell.exe - ok
21:39:12.0786 1936 [ D5EA86C4F2533F5515C614138A120F22 ] C:\Windows\System32\mapi32.dll
21:39:12.0786 1936 C:\Windows\System32\mapi32.dll - ok
21:39:12.0786 1936 [ 93655E5D1E940E5A0F73F5A1719A0DA0 ] C:\Windows\System32\mssph.dll
21:39:12.0786 1936 C:\Windows\System32\mssph.dll - ok
21:39:12.0802 1936 [ AB32F17AAC815660530F50E688234DAA ] C:\Windows\System32\msfeeds.dll
21:39:12.0802 1936 C:\Windows\System32\msfeeds.dll - ok
21:39:12.0802 1936 [ F2DB8923DBF9491BC7D387E305505CF5 ] C:\Windows\System32\gameux.dll
21:39:12.0802 1936 C:\Windows\System32\gameux.dll - ok
21:39:12.0802 1936 [ C9EE7FF225EAC1CB9C78C413667CDB80 ] C:\Windows\SysWOW64\SearchFilterHost.exe
21:39:12.0802 1936 C:\Windows\SysWOW64\SearchFilterHost.exe - ok
21:39:12.0818 1936 [ BBDE232916FC116C8CB46011683AD854 ] C:\Windows\System32\SearchFilterHost.exe
21:39:12.0818 1936 C:\Windows\System32\SearchFilterHost.exe - ok
21:39:12.0818 1936 [ B458B58F7BB97C48D01AC3CF5805AAAC ] C:\Windows\SysWOW64\Query.dll
21:39:12.0818 1936 C:\Windows\SysWOW64\Query.dll - ok
21:39:12.0818 1936 [ 69C0460E837047E172A3B92858ED7AB3 ] C:\Program Files\Microsoft Games\Hearts\Hearts.exe
21:39:12.0818 1936 C:\Program Files\Microsoft Games\Hearts\Hearts.exe - ok
21:39:12.0833 1936 [ B4761127BA6B6353566FF735EC22F4A4 ] C:\Program Files\Microsoft Games\inkball\inkball.exe
21:39:12.0833 1936 C:\Program Files\Microsoft Games\inkball\inkball.exe - ok
21:39:12.0833 1936 [ 9441A231C0AA0712F7CF3B10D9CFCF76 ] C:\Windows\SysWOW64\wmploc.DLL
21:39:12.0833 1936 C:\Windows\SysWOW64\wmploc.DLL - ok
21:39:12.0833 1936 [ A0CB916FDBB52C039F5D482701645E86 ] C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe
21:39:12.0833 1936 C:\Program Files\Microsoft Games\Mahjong\Mahjong.exe - ok
21:39:12.0849 1936 [ 6B80D55576B222FDF6F8407D6237EFC6 ] C:\Windows\System32\wmpps.dll
21:39:12.0849 1936 C:\Windows\System32\wmpps.dll - ok
21:39:12.0849 1936 [ 94BEEEBD916F7836EEF2CCA38218BD31 ] C:\Windows\SysWOW64\wmpps.dll
21:39:12.0849 1936 C:\Windows\SysWOW64\wmpps.dll - ok
21:39:12.0849 1936 [ 2EF3BBE22E5A5ACD1428EE387A0D0172 ] C:\Windows\SysWOW64\netprofm.dll
21:39:12.0849 1936 C:\Windows\SysWOW64\netprofm.dll - ok
21:39:12.0849 1936 [ 45EEA3DBE0182FBCFCF9B1F286178BB9 ] C:\Program Files\Microsoft Games\Minesweeper\MineSweeper.exe
21:39:12.0849 1936 C:\Program Files\Microsoft Games\Minesweeper\MineSweeper.exe - ok
21:39:12.0864 1936 [ C4E6DF4D491A82DFF4EA56BD4C3A6633 ] C:\Program Files\Microsoft Games\Purble Place\PurblePlace.exe
21:39:12.0864 1936 C:\Program Files\Microsoft Games\Purble Place\PurblePlace.exe - ok
21:39:12.0864 1936 [ 4774AD6C447E02E954BD9A793614EBEC ] C:\Windows\SysWOW64\lsm.exe
21:39:12.0864 1936 C:\Windows\SysWOW64\lsm.exe - ok
21:39:12.0864 1936 [ ABFC76B48BB6C96E3338D8943C5D93B5 ] C:\Windows\SysWOW64\wdi.dll
21:39:12.0864 1936 C:\Windows\SysWOW64\wdi.dll - ok
21:39:12.0880 1936 [ 91E6B2F642DC66C7519EF55C4BA5C9F1 ] C:\Windows\SysWOW64\clb.dll
21:39:12.0880 1936 C:\Windows\SysWOW64\clb.dll - ok
21:39:12.0880 1936 [ 4EF7F56C5D3D3FC63E7296F2A3D283D5 ] C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe
21:39:12.0880 1936 C:\Program Files\Microsoft Games\Solitaire\Solitaire.exe - ok
21:39:12.0880 1936 [ EF4C006CC67119A5E3EA534EC85BEA23 ] C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe
21:39:12.0880 1936 C:\Program Files\Microsoft Games\SpiderSolitaire\SpiderSolitaire.exe - ok
21:39:12.0896 1936 [ EF6D2BC5AF87B6DDFB52245FF77046B7 ] C:\Windows\System32\brcpl.dll
21:39:12.0896 1936 C:\Windows\System32\brcpl.dll - ok
21:39:12.0896 1936 [ AAAE543C535ED596ECAD2AB8761C2C6F ] C:\Windows\SysWOW64\dxgi.dll
21:39:12.0896 1936 C:\Windows\SysWOW64\dxgi.dll - ok
21:39:12.0896 1936 [ 5256383D1D266A9EEFCDB270340C0E5C ] C:\Windows\SysWOW64\d3d10_1.dll
21:39:12.0896 1936 C:\Windows\SysWOW64\d3d10_1.dll - ok
21:39:12.0896 1936 [ A441F5B43EAF4BD4E3ACFBE38841B46B ] C:\Windows\SysWOW64\d3d10_1core.dll
21:39:12.0896 1936 C:\Windows\SysWOW64\d3d10_1core.dll - ok
21:39:12.0911 1936 [ 406121C827A2901E72DAB2197DAE180E ] C:\Windows\System32\wercon.exe
21:39:12.0911 1936 C:\Windows\System32\wercon.exe - ok
21:39:12.0911 1936 [ 4A4C71376ECA305D6DEA021F1A44816D ] C:\Windows\SysWOW64\d3d10warp.dll
21:39:12.0911 1936 C:\Windows\SysWOW64\d3d10warp.dll - ok
21:39:12.0911 1936 [ BA38C50F523DC053488AC3F9EF99AA0B ] C:\Windows\SysWOW64\igdumdx32.dll
21:39:12.0911 1936 C:\Windows\SysWOW64\igdumdx32.dll - ok
21:39:12.0927 1936 [ 5767ED421A03FA524B5F18A2C28C1143 ] C:\Windows\System32\msra.exe
21:39:12.0927 1936 C:\Windows\System32\msra.exe - ok
21:39:12.0927 1936 [ 21EF4BB2A6FF4116FD83FAEE52D4A416 ] C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
21:39:12.0927 1936 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe - ok
21:39:12.0927 1936 [ 8B02D2ECC7EF6E1F6AF08459E3F741F6 ] C:\Windows\SysWOW64\d3d10.dll
21:39:12.0927 1936 C:\Windows\SysWOW64\d3d10.dll - ok
21:39:12.0942 1936 [ 9C7094F537782A82B6A29B4A7172E180 ] C:\Windows\SysWOW64\d3d10core.dll
21:39:12.0942 1936 C:\Windows\SysWOW64\d3d10core.dll - ok
21:39:12.0942 1936 [ 7E2CF680C69680064D43F4FFE5831DD1 ] C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
21:39:12.0942 1936 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe - ok
21:39:12.0942 1936 [ C0F4A57BA5E09A28AE3D2F67ED219EEA ] C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
21:39:12.0942 1936 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe - ok
21:39:12.0958 1936 [ 16BA0262B8F268E62732650CFFEC4347 ] C:\PROGRA~1\COMMON~1\MICROS~1\Filters\offfiltx.dll
21:39:12.0958 1936 C:\PROGRA~1\COMMON~1\MICROS~1\Filters\offfiltx.dll - ok
21:39:12.0958 1936 [ FF6669F7A1782D54E338F5C6EC806E1E ] C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
21:39:12.0958 1936 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe - ok
21:39:12.0958 1936 [ E1AB2AC4A4D50B479DF1B1CEA4A7409B ] C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
21:39:12.0958 1936 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe - ok
21:39:12.0974 1936 [ 3E5AA6A816FA331E64C38A45C6FF5637 ] C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
21:39:12.0974 1936 C:\Windows\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe - ok
21:39:12.0974 1936 [ 1BE86CAA2F2B22AFFADC5758AA24E015 ] C:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIconDll
21:39:12.0974 1936 C:\Windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIconDll - ok
21:39:12.0974 1936 [ 557BAC2FC662137A9457DDD0A6531DB2 ] C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\SiteSafety.dll
21:39:12.0974 1936 C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\15.2.0\SiteSafety.dll - ok
21:39:12.0989 1936 [ AC545DF9370A3E1BF538E403ABE51CC0 ] C:\Windows\System32\msiexec.exe
21:39:12.0989 1936 C:\Windows\System32\msiexec.exe - ok
21:39:12.0989 1936 [ 0296DAEB5555A248E8ABF7E5012A37A6 ] C:\Windows\SysWOW64\msxml6.dll
21:39:12.0989 1936 C:\Windows\SysWOW64\msxml6.dll - ok
21:39:12.0989 1936 [ 4C39358EBDD2FFCD9132A30E1EC31E16 ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll
21:39:12.0989 1936 C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcp90.dll - ok
21:39:13.0005 1936 [ FED96A7CA1154437416C2CD01BC5FE45 ] C:\Windows\SysWOW64\joy.cpl
21:39:13.0005 1936 C:\Windows\SysWOW64\joy.cpl - ok
21:39:13.0005 1936 [ CDBE9690CF2B8409FACAD94FAC9479C9 ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll
21:39:13.0005 1936 C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcr90.dll - ok
21:39:13.0005 1936 [ 5F1EC52CED30D4A44369430ADF1B7C6F ] C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\15.2.0\avgdttbx.dll
21:39:13.0005 1936 C:\Program Files (x86)\Common Files\AVG Secure Search\DNTInstaller\15.2.0\avgdttbx.dll - ok
21:39:13.0020 1936 [ F21509C6DF8A350412780D689CF2AB95 ] C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll
21:39:13.0020 1936 C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll - ok
21:39:13.0020 1936 [ 6DD4400A918BB4265A94FFC2D1AB0D8D ] C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll
21:39:13.0020 1936 C:\Users\dianne\AppData\Local\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll - ok
21:39:13.0020 1936 [ 7DC262AEEA66CCD6ED86DAAB16C4CDFF ] C:\Windows\System32\ntlanman.dll
21:39:13.0020 1936 C:\Windows\System32\ntlanman.dll - ok
21:39:13.0036 1936 [ 3A2EEE8444A8E5C1A454C57B2198F5FC ] C:\Windows\SysWOW64\ntlanman.dll
21:39:13.0036 1936 C:\Windows\SysWOW64\ntlanman.dll - ok
21:39:13.0036 1936 [ 2790F04DFDDA00B7B6DE6719399A8739 ] C:\Windows\System32\drprov.dll
21:39:13.0036 1936 C:\Windows\System32\drprov.dll - ok
21:39:13.0036 1936 [ 582EFE56FC0858E58A6CEBA2A64B02C7 ] C:\Windows\SysWOW64\drprov.dll
21:39:13.0036 1936 C:\Windows\SysWOW64\drprov.dll - ok
21:39:13.0052 1936 [ AAC4DFF79689736D8B316FC05A3E25EC ] C:\Windows\System32\davclnt.dll
21:39:13.0052 1936 C:\Windows\System32\davclnt.dll - ok
21:39:13.0052 1936 [ CFBD2E1FE18B50748A76703A2DC6D4E3 ] C:\Windows\SysWOW64\davclnt.dll
21:39:13.0052 1936 C:\Windows\SysWOW64\davclnt.dll - ok
21:39:13.0052 1936 [ 84C8AFD609A3DE18F40AA64CDEB40194 ] C:\Windows\SysWOW64\url.dll
21:39:13.0052 1936 C:\Windows\SysWOW64\url.dll - ok
21:39:13.0052 1936 [ 1959E5AAEE0D988C10F19CEC7DFF2242 ] C:\Windows\SysWOW64\wdc.dll
21:39:13.0052 1936 C:\Windows\SysWOW64\wdc.dll - ok
21:39:13.0067 1936 [ 877F2939794EBA4F3D1BB967007E99E8 ] C:\Windows\SysWOW64\osk.exe
21:39:13.0067 1936 C:\Windows\SysWOW64\osk.exe - ok
21:39:13.0067 1936 [ 4C96E5B53EAF63BCBEA6FA79C9A0AE59 ] C:\Windows\SysWOW64\VAN.dll
21:39:13.0067 1936 C:\Windows\SysWOW64\VAN.dll - ok
21:39:13.0067 1936 [ 0BF28E777209EF48AD215C809AD2CBB5 ] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
21:39:13.0067 1936 C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll - ok
21:39:13.0083 1936 [ 0C4DBE758A44E7B02DB4CE5C27CBA3A8 ] C:\Program Files (x86)\EpicPlay\npEpicHost.dll
21:39:13.0083 1936 C:\Program Files (x86)\EpicPlay\npEpicHost.dll - ok
21:39:13.0083 1936 [ 3D928B3FE97C403A33F803B3D1A260C9 ] C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll
21:39:13.0083 1936 C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll - ok
21:39:13.0083 1936 [ 8F24103AB984847AA2939F58F19CCC98 ] C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
21:39:13.0083 1936 C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll - ok
21:39:13.0098 1936 [ 24E990B1E6D55428001843CF7217DD81 ] C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
21:39:13.0098 1936 C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll - ok
21:39:13.0098 1936 [ 0A1FF0B674E2F268799442A434A63BB3 ] C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
21:39:13.0098 1936 C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll - ok
21:39:13.0098 1936 [ 0DFF081C371B989CFC264DDC9E551363 ] C:\Program Files (x86)\Yahoo!\Shared\npYState.dll
21:39:13.0098 1936 C:\Program Files (x86)\Yahoo!\Shared\npYState.dll - ok
21:39:13.0114 1936 [ 3D928B3FE97C403A33F803B3D1A260C9 ] C:\Users\dianne\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll
21:39:13.0114 1936 C:\Users\dianne\AppData\Local\Google\Update\1.3.21.145\npGoogleUpdate3.dll - ok
21:39:13.0114 1936 [ ADC539F67D3198679F480974EE203678 ] C:\Windows\SysWOW64\npDeployJava1.dll
21:39:13.0114 1936 C:\Windows\SysWOW64\npDeployJava1.dll - ok
21:39:13.0114 1936 [ 81D388824634378A37765FD943FB3144 ] C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
21:39:13.0114 1936 C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll - ok
21:39:13.0130 1936 [ A5C14075B571AF1C9592595BE724D9D2 ] C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
21:39:13.0130 1936 C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll - ok
21:39:13.0130 1936 [ AB87EEFFD18F2BAAFC274E7075EA6C67 ] C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
21:39:13.0130 1936 C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll - ok
21:39:13.0145 1936 [ 5C9541EFCE477BFCFFD0EF9B1A175457 ] C:\Windows\SysWOW64\ulib.dll
21:39:13.0145 1936 C:\Windows\SysWOW64\ulib.dll - ok
21:39:13.0145 1936 [ CE7F6F3E9C107382A72F7D33B1E2C9FA ] C:\Windows\SysWOW64\main.cpl
21:39:13.0145 1936 C:\Windows\SysWOW64\main.cpl - ok
21:39:13.0145 1936 [ A9BBAB5759771E523F55563D6CBE140F ] C:\Windows\SysWOW64\Sens.dll
21:39:13.0145 1936 C:\Windows\SysWOW64\Sens.dll - ok
21:39:13.0161 1936 [ 3458EDA96E30FBD0477A2800D3FB1909 ] C:\Windows\SysWOW64\wups.dll
21:39:13.0161 1936 C:\Windows\SysWOW64\wups.dll - ok
21:39:13.0161 1936 [ 490C755CD179B16E0C9EB7804BD9E578 ] C:\Windows\SysWOW64\intl.cpl
21:39:13.0161 1936 C:\Windows\SysWOW64\intl.cpl - ok
21:39:13.0161 1936 [ E50A273F78F7F2E1D71E9E4D477D0961 ] C:\Windows\SysWOW64\msra.exe
21:39:13.0161 1936 C:\Windows\SysWOW64\msra.exe - ok
21:39:13.0161 1936 [ 9ABCF91512AE8120F3E931301E28B6C1 ] C:\Windows\System32\EhStorAPI.dll
21:39:13.0161 1936 C:\Windows\System32\EhStorAPI.dll - ok
21:39:13.0176 1936 [ 9E5C1D19851FAE2ACDBA118AB20D55AC ] C:\Windows\SysWOW64\EhStorAPI.dll
21:39:13.0176 1936 C:\Windows\SysWOW64\EhStorAPI.dll - ok
21:39:13.0176 1936 [ 69405254E704895F4F519422818D35B6 ] C:\Windows\SysWOW64\mmsys.cpl
21:39:13.0176 1936 C:\Windows\SysWOW64\mmsys.cpl - ok
21:39:13.0176 1936 [ 09C91E1F199C53E1114396B59B3B4D9E ] C:\Windows\SysWOW64\aclui.dll
21:39:13.0176 1936 C:\Windows\SysWOW64\aclui.dll - ok
21:39:13.0192 1936 [ 62C92BE2414AC9D0BC0196CA52D2CD2B ] C:\Windows\SysWOW64\wscui.cpl
21:39:13.0192 1936 C:\Windows\SysWOW64\wscui.cpl - ok
21:39:13.0192 1936 [ FA2A3AFADC4FB47DBC234A4E57F92CDB ] C:\Windows\SysWOW64\ddraw.dll
21:39:13.0192 1936 C:\Windows\SysWOW64\ddraw.dll - ok
21:39:13.0192 1936 [ C6DA42ADA0C5FC8CB05744229D632B47 ] C:\Windows\SysWOW64\msutb.dll
21:39:13.0192 1936 C:\Windows\SysWOW64\msutb.dll - ok
21:39:13.0208 1936 [ E389EA130C4A9A4DBA0F138222261056 ] C:\Program Files\SUPERAntiSpyware\SSUpdate64.exe
21:39:13.0208 1936 C:\Program Files\SUPERAntiSpyware\SSUpdate64.exe - ok
21:39:13.0208 1936 [ DA887F28054D78EE8637BEBB924A2DB5 ] C:\Windows\SysWOW64\slwga.dll
21:39:13.0208 1936 C:\Windows\SysWOW64\slwga.dll - ok
21:39:13.0208 1936 [ F8873D15018F411588BEC02C1725BADA ] C:\Windows\SysWOW64\TSpkg.dll
21:39:13.0208 1936 C:\Windows\SysWOW64\TSpkg.dll - ok
21:39:13.0223 1936 [ F0062778F50838145AC46B384FFB4FA3 ] C:\Windows\SysWOW64\pcadm.dll
21:39:13.0223 1936 C:\Windows\SysWOW64\pcadm.dll - ok
21:39:13.0223 1936 [ 1A617835452EEE5060976C9B9F5FE635 ] C:\Windows\SysWOW64\wuapi.dll
21:39:13.0223 1936 C:\Windows\SysWOW64\wuapi.dll - ok
21:39:13.0223 1936 [ 7D7960C85E4259F3B90EB4B742616BFF ] C:\Windows\SysWOW64\EAPQEC.DLL
21:39:13.0223 1936 C:\Windows\SysWOW64\EAPQEC.DLL - ok
21:39:13.0239 1936 [ C7230FBEE14437716701C15BE02C27B8 ] C:\Windows\SysWOW64\shsvcs.dll
21:39:13.0239 1936 C:\Windows\SysWOW64\shsvcs.dll - ok
21:39:13.0239 1936 [ 2955A48BE10FD1F7A112B0A890A6271D ] C:\Windows\SysWOW64\msisip.dll
21:39:13.0239 1936 C:\Windows\SysWOW64\msisip.dll - ok
21:39:13.0239 1936 [ 7D4E50C9B39CE079A903000140C9B937 ] C:\Windows\System32\dispci.dll
21:39:13.0239 1936 C:\Windows\System32\dispci.dll - ok
21:39:13.0254 1936 [ 2327C11B043FCEB80BE00CC8D077E9AA ] C:\Windows\SysWOW64\dfrgui.exe
21:39:13.0254 1936 C:\Windows\SysWOW64\dfrgui.exe - ok
21:39:13.0254 1936 [ 9C50130E941A24805A608E6F3D2A3C8F ] C:\Windows\SysWOW64\wshext.dll
21:39:13.0254 1936 C:\Windows\SysWOW64\wshext.dll - ok
21:39:13.0254 1936 [ 197A6855F30CE60D3C93E6072EF742A7 ] C:\Windows\SysWOW64\tsgqec.dll
21:39:13.0254 1936 C:\Windows\SysWOW64\tsgqec.dll - ok
21:39:13.0254 1936 [ 3DB1530CDD7AEF2BCFA6FB77D097CDDA ] C:\Windows\SysWOW64\scrrun.dll
21:39:13.0254 1936 C:\Windows\SysWOW64\scrrun.dll - ok
21:39:13.0270 1936 [ AF25ECAA3D7F85DC13E348A6F79AD40D ] C:\Windows\SysWOW64\vss_ps.dll
21:39:13.0270 1936 C:\Windows\SysWOW64\vss_ps.dll - ok
21:39:13.0270 1936 [ 96DD35AB1C1420E0CD70EF9ECD32B825 ] C:\Windows\SysWOW64\SndVol.exe
21:39:13.0270 1936 C:\Windows\SysWOW64\SndVol.exe - ok
21:39:13.0270 1936 [ 8B645890A93F1FBBC7DA3E07CC72D762 ] C:\Windows\SysWOW64\rasppp.dll
21:39:13.0270 1936 C:\Windows\SysWOW64\rasppp.dll - ok
21:39:13.0286 1936 [ 1EC876F77C79E6A81FF66F2ECED40B35 ] C:\Windows\System32\collab.cpl
21:39:13.0286 1936 C:\Windows\System32\collab.cpl - ok
21:39:13.0286 1936 [ 2F6776ACEFE41EE889C464EA407918F2 ] C:\Windows\SysWOW64\ndptsp.tsp
21:39:13.0286 1936 C:\Windows\SysWOW64\ndptsp.tsp - ok
21:39:13.0286 1936 [ 74C2F29CC612B2B34231BEBD824D2FB2 ] C:\Windows\SysWOW64\keyiso.dll
21:39:13.0286 1936 C:\Windows\SysWOW64\keyiso.dll - ok
21:39:13.0301 1936 [ 5CAA965A14ADBDEF4359F3D2BEA9D9F7 ] C:\Windows\SysWOW64\devmgr.dll
21:39:13.0301 1936 C:\Windows\SysWOW64\devmgr.dll - ok
21:39:13.0301 1936 [ A6250DF429D0D78DACFBC6B87074E584 ] C:\Windows\SysWOW64\regapi.dll
21:39:13.0301 1936 C:\Windows\SysWOW64\regapi.dll - ok
21:39:13.0301 1936 [ E1B80644E7125231AAEF62FC2C81C8FE ] C:\Windows\SysWOW64\newdev.dll
21:39:13.0301 1936 C:\Windows\SysWOW64\newdev.dll - ok
21:39:13.0301 1936 [ 3B0489DE8CC3058B48471660C60A7B75 ] C:\Windows\SysWOW64\rastls.dll
21:39:13.0301 1936 C:\Windows\SysWOW64\rastls.dll - ok
21:39:13.0317 1936 [ 7241639333A70BA66D9AEFA5D9E55A80 ] C:\Windows\System32\wpccpl.dll
21:39:13.0317 1936 C:\Windows\System32\wpccpl.dll - ok
21:39:13.0317 1936 [ 0EB1CC5EBFCAAB7DBAEE881E2887F7F9 ] C:\Windows\SysWOW64\WSDMon.dll
21:39:13.0317 1936 C:\Windows\SysWOW64\WSDMon.dll - ok
21:39:13.0317 1936 [ 4BF053944E973C073339BE841C9ECF28 ] C:\Windows\SysWOW64\netrap.dll
21:39:13.0317 1936 C:\Windows\SysWOW64\netrap.dll - ok
21:39:13.0332 1936 [ D90911B3FA05D7B930C1286084B404DE ] C:\Windows\SysWOW64\scesrv.dll
21:39:13.0332 1936 C:\Windows\SysWOW64\scesrv.dll - ok
21:39:13.0332 1936 [ 8FC182167381E9915651267044105EE1 ] C:\Windows\SysWOW64\scecli.dll
21:39:13.0332 1936 C:\Windows\SysWOW64\scecli.dll - ok
21:39:13.0332 1936 [ 06BEFFD308C5796D3D6FD2FAD267A6C2 ] C:\Windows\System32\rdpwsx.dll
21:39:13.0332 1936 C:\Windows\System32\rdpwsx.dll - ok
21:39:13.0348 1936 [ C1BB3EF5FAFCBC9573DEEB57E8DF9309 ] C:\Windows\SysWOW64\cscdll.dll
21:39:13.0348 1936 C:\Windows\SysWOW64\cscdll.dll - ok
21:39:13.0348 1936 [ 1BAF5FE4C31D20CF805B2FA7A7C2B886 ] C:\Windows\SysWOW64\hdwwiz.exe
21:39:13.0348 1936 C:\Windows\SysWOW64\hdwwiz.exe - ok
21:39:13.0348 1936 [ 19DF185D42AA0DE80AD78C58D4A4E936 ] C:\Windows\SysWOW64\appwiz.cpl
21:39:13.0348 1936 C:\Windows\SysWOW64\appwiz.cpl - ok
21:39:13.0364 1936 [ BB0EB921877A1A7EF15AE2D97A71CBA9 ] C:\Windows\SysWOW64\tcpmon.dll
21:39:13.0364 1936 C:\Windows\SysWOW64\tcpmon.dll - ok
21:39:13.0364 1936 [ AF706FAB59FECEBB576F584ECB3ECBD2 ] C:\Windows\SysWOW64\sscore.dll
21:39:13.0364 1936 C:\Windows\SysWOW64\sscore.dll - ok
21:39:13.0364 1936 [ 88225070DD2F7B0B2ED51E7935078641 ] C:\Windows\SysWOW64\rasqec.dll
21:39:13.0364 1936 C:\Windows\SysWOW64\rasqec.dll - ok
21:39:13.0364 1936 [ E6AA6695662F37C54747257B79187391 ] C:\Windows\SysWOW64\hdwwiz.cpl
21:39:13.0364 1936 C:\Windows\SysWOW64\hdwwiz.cpl - ok
21:39:13.0379 1936 [ 031DA76A5A7DC13F015DD3491394865E ] C:\Windows\SysWOW64\advpack.dll
21:39:13.0379 1936 C:\Windows\SysWOW64\advpack.dll - ok
21:39:13.0379 1936 [ 88198AEB7F71DD2F8B6176533D70F63E ] C:\Windows\SysWOW64\fontext.dll
21:39:13.0379 1936 C:\Windows\SysWOW64\fontext.dll - ok
21:39:13.0379 1936 [ 248A1F31ABB58DDDDC01490EF0BDC777 ] C:\Windows\SysWOW64\cryptui.dll
21:39:13.0379 1936 C:\Windows\SysWOW64\cryptui.dll - ok
21:39:13.0395 1936 [ 30A742FFCEA6661E501C44DC273C77B1 ] C:\Windows\SysWOW64\dinput8.dll
21:39:13.0395 1936 C:\Windows\SysWOW64\dinput8.dll - ok
21:39:13.0395 1936 [ 1D6B95871DC006190964B04E5657E35F ] C:\Windows\SysWOW64\rastapi.dll
21:39:13.0395 1936 C:\Windows\SysWOW64\rastapi.dll - ok
21:39:13.0395 1936 [ DBA747919344CD1353F8107134A20D62 ] C:\Windows\SysWOW64\inetcpl.cpl
21:39:13.0395 1936 C:\Windows\SysWOW64\inetcpl.cpl - ok
21:39:13.0410 1936 [ 71F5A7104FDF16C0AC5283A6CE666553 ] C:\Windows\SysWOW64\sysntfy.dll
21:39:13.0410 1936 C:\Windows\SysWOW64\sysntfy.dll - ok
21:39:13.0410 1936 [ 4CF66D8014ECB3BF517E38C5B90AAC74 ] C:\Windows\SysWOW64\themeui.dll
21:39:13.0410 1936 C:\Windows\SysWOW64\themeui.dll - ok
21:39:13.0410 1936 [ B49CEF589D47D9D3F602E118B1F5F3B5 ] C:\Windows\SysWOW64\jscript.dll
21:39:13.0410 1936 C:\Windows\SysWOW64\jscript.dll - ok
21:39:13.0426 1936 [ 62D577288B48998FC6667BF22DC5B690 ] C:\Windows\SysWOW64\LogonUI.exe
21:39:13.0426 1936 C:\Windows\SysWOW64\LogonUI.exe - ok
21:39:13.0426 1936 [ 84067081F3318162797385E11A8F0582 ] C:\Windows\SysWOW64\hidserv.dll
21:39:13.0426 1936 C:\Windows\SysWOW64\hidserv.dll - ok
21:39:13.0426 1936 [ F86293D93760C70ADF4F19E66E3FA5E8 ] C:\Windows\SysWOW64\httpapi.dll
21:39:13.0426 1936 C:\Windows\SysWOW64\httpapi.dll - ok
21:39:13.0426 1936 [ CD6DA5770CAE9D5E6E86722E17B442E0 ] C:\Windows\SysWOW64\d3d8thk.dll
21:39:13.0426 1936 C:\Windows\SysWOW64\d3d8thk.dll - ok
21:39:13.0442 1936 [ E47C854A28A81F2939F42CBE9FEA994C ] C:\Windows\SysWOW64\Magnify.exe
21:39:13.0442 1936 C:\Windows\SysWOW64\Magnify.exe - ok
21:39:13.0442 1936 [ AEC6EF113ADB5308F178975EB9C52E71 ] C:\Windows\System32\consent.exe
21:39:13.0442 1936 C:\Windows\System32\consent.exe - ok
21:39:13.0442 1936 [ 04C37D8107320312FBAE09926103D5E2 ] C:\Windows\SysWOW64\WebClnt.dll
21:39:13.0442 1936 C:\Windows\SysWOW64\WebClnt.dll - ok
21:39:13.0457 1936 [ 0DAAF8032546D1B4543D7B101B53FD6C ] C:\Windows\SysWOW64\odbcint.dll
21:39:13.0457 1936 C:\Windows\SysWOW64\odbcint.dll - ok
21:39:13.0457 1936 [ FAF3D589C7E28315EBFCDFA4EE9C610E ] C:\Windows\SysWOW64\DHCPQEC.DLL
21:39:13.0457 1936 C:\Windows\SysWOW64\DHCPQEC.DLL - ok
21:39:13.0457 1936 [ 9DC3723519F52B6BC63EACD4BD411313 ] C:\Windows\SysWOW64\rasplap.dll
21:39:13.0457 1936 C:\Windows\SysWOW64\rasplap.dll - ok
21:39:13.0473 1936 [ C559672F31ABE6BA7277DD73C4502238 ] C:\Windows\SysWOW64\msiexec.exe
21:39:13.0473 1936 C:\Windows\SysWOW64\msiexec.exe - ok
21:39:13.0473 1936 [ F0321DA5203F1E71917F3B7A13DC4912 ] C:\Windows\SysWOW64\wmsgapi.dll
21:39:13.0473 1936 C:\Windows\SysWOW64\wmsgapi.dll - ok
21:39:13.0473 1936 [ 9B89B3BB79EA1ACF041F40A7B6FC5827 ] C:\Windows\SysWOW64\mobsync.exe
21:39:13.0473 1936 C:\Windows\SysWOW64\mobsync.exe - ok
21:39:13.0488 1936 [ BB4910DE8B6C5E30DF39EC97308D44BA ] C:\Windows\SysWOW64\charmap.exe
21:39:13.0488 1936 C:\Windows\SysWOW64\charmap.exe - ok
21:39:13.0488 1936 [ 0745D6EAD386710110817FBEC03F5161 ] C:\Windows\SysWOW64\wfapigp.dll
21:39:13.0488 1936 C:\Windows\SysWOW64\wfapigp.dll - ok
21:39:13.0488 1936 [ D2193326F729B163125610DBF3E17D57 ] C:\Windows\SysWOW64\SessEnv.dll
21:39:13.0488 1936 C:\Windows\SysWOW64\SessEnv.dll - ok
21:39:13.0504 1936 [ 93620229F3CC3B67A3528BF39F064C30 ] C:\Windows\SysWOW64\wdigest.dll
21:39:13.0504 1936 C:\Windows\SysWOW64\wdigest.dll - ok
21:39:13.0504 1936 [ D7673E4B38CE21EE54C59EEEB65E2483 ] C:\Windows\SysWOW64\tapisrv.dll
21:39:13.0504 1936 C:\Windows\SysWOW64\tapisrv.dll - ok
21:39:13.0504 1936 [ E7D0F91E44D9D3B2116FA549BDCDB756 ] C:\Windows\SysWOW64\wdscore.dll
21:39:13.0504 1936 C:\Windows\SysWOW64\wdscore.dll - ok
21:39:13.0504 1936 [ C99403A5B641520DAED0021DDA06F272 ] C:\Windows\SysWOW64\milcore.dll
21:39:13.0504 1936 C:\Windows\SysWOW64\milcore.dll - ok
21:39:13.0520 1936 [ 82A79D5BE740D0AE9C91AA6DE4B3AC5A ] C:\Windows\SysWOW64\raschap.dll
21:39:13.0520 1936 C:\Windows\SysWOW64\raschap.dll - ok
21:39:13.0520 1936 [ 3437B9E218A2E4586BEF4F7A3BD00777 ] C:\Windows\SysWOW64\audiodg.exe
21:39:13.0520 1936 C:\Windows\SysWOW64\audiodg.exe - ok
21:39:13.0520 1936 [ 665790240511DF6BC40A30E01731F49F ] C:\Windows\SysWOW64\irprops.cpl
21:39:13.0520 1936 C:\Windows\SysWOW64\irprops.cpl - ok
21:39:13.0535 1936 [ E3CE1997725EE8E14F7B4A7CD746538E ] C:\Windows\SysWOW64\usercpl.dll
21:39:13.0535 1936 C:\Windows\SysWOW64\usercpl.dll - ok
21:39:13.0535 1936 [ 3D50C4B10352367D5CB20ED1F50F8DA2 ] C:\Windows\SysWOW64\taskeng.exe
21:39:13.0535 1936 C:\Windows\SysWOW64\taskeng.exe - ok
21:39:13.0535 1936 [ D333058925CE305E39DE8D5AD2B52A46 ] C:\Windows\SysWOW64\clusapi.dll
21:39:13.0535 1936 C:\Windows\SysWOW64\clusapi.dll - ok
21:39:13.0551 1936 [ 43697D7CDAEAE3EBBADE2C05107418FF ] C:\Windows\SysWOW64\vbscript.dll
21:39:13.0551 1936 C:\Windows\SysWOW64\vbscript.dll - ok
21:39:13.0551 1936 [ 928060167F0EB1B4F605327DB66CB0C7 ] C:\Windows\SysWOW64\RstrtMgr.dll
21:39:13.0551 1936 C:\Windows\SysWOW64\RstrtMgr.dll - ok
21:39:13.0551 1936 [ 7F15B4953378C8B5161D65C26D5FED4D ] C:\Windows\SysWOW64\cngaudit.dll
21:39:13.0551 1936 C:\Windows\SysWOW64\cngaudit.dll - ok
21:39:13.0566 1936 [ 0ADED25D371AE14665CE514E413988E7 ] C:\Windows\SysWOW64\AuthFWGP.dll
21:39:13.0566 1936 C:\Windows\SysWOW64\AuthFWGP.dll - ok
21:39:13.0566 1936 [ 3AB4023CBD406AC33AB8CDFF6C8079A0 ] C:\Windows\SysWOW64\eapphost.dll
21:39:13.0566 1936 C:\Windows\SysWOW64\eapphost.dll - ok
21:39:13.0566 1936 [ 965AC9FBF2C67231C157E99C03C58D24 ] C:\Windows\SysWOW64\feclient.dll
21:39:13.0566 1936 C:\Windows\SysWOW64\feclient.dll - ok
21:39:13.0566 1936 [ D3D1CE8FF30786D50272DA3085149904 ] C:\Windows\SysWOW64\msinfo32.exe
21:39:13.0566 1936 C:\Windows\SysWOW64\msinfo32.exe - ok
21:39:13.0582 1936 [ 34B7FA82A85231348C170EF39B636DB4 ] C:\Windows\SysWOW64\icardres.dll
21:39:13.0582 1936 C:\Windows\SysWOW64\icardres.dll - ok
21:39:13.0582 1936 [ 4A1FEEBF039B283258B0E479FA135DBA ] C:\Windows\SysWOW64\osbaseln.dll
21:39:13.0582 1936 C:\Windows\SysWOW64\osbaseln.dll - ok
21:39:13.0582 1936 [ 1FAF6926F3416D3DA05C5B265491BDAE ] C:\Windows\System32\msdtckrm.dll
21:39:13.0582 1936 C:\Windows\System32\msdtckrm.dll - ok
21:39:13.0598 1936 [ 3EDE4C1F9672C972479201544969ADCB ] C:\Windows\SysWOW64\cryptsvc.dll
21:39:13.0598 1936 C:\Windows\SysWOW64\cryptsvc.dll - ok
21:39:13.0598 1936 [ B9F3FF52B84FD9E3CAFB29B8EE385E5B ] C:\Windows\SysWOW64\resutils.dll
21:39:13.0598 1936 C:\Windows\SysWOW64\resutils.dll - ok
21:39:13.0598 1936 [ 2FA16465F64DB54B1F7F511395EB4FD7 ] C:\Windows\SysWOW64\ncobjapi.dll
21:39:13.0598 1936 C:\Windows\SysWOW64\ncobjapi.dll - ok
21:39:13.0613 1936 [ F21F255B91CA4F04E4250DECD2067CBB ] C:\Windows\SysWOW64\bitsperf.dll
21:39:13.0613 1936 C:\Windows\SysWOW64\bitsperf.dll - ok
21:39:13.0613 1936 [ F84D0B1B90404D0A27E86F159FBDAC81 ] C:\Windows\SysWOW64\iscsicpl.dll
21:39:13.0613 1936 C:\Windows\SysWOW64\iscsicpl.dll - ok
21:39:13.0613 1936 [ 1CB1B95D67BC380FBCCFAEA3CF2DDA80 ] C:\Windows\SysWOW64\iscsicpl.exe
21:39:13.0613 1936 C:\Windows\SysWOW64\iscsicpl.exe - ok
21:39:13.0613 1936 [ 1A09CB187440993FA5E24DE1EEB7B916 ] C:\Windows\SysWOW64\cfgmgr32.dll
21:39:13.0613 1936 C:\Windows\SysWOW64\cfgmgr32.dll - ok
21:39:13.0629 1936 [ 8DDC387167FA0234F3656EB34C78BFFB ] C:\Windows\SysWOW64\powercpl.dll
21:39:13.0629 1936 C:\Windows\SysWOW64\powercpl.dll - ok
21:39:13.0629 1936 [ 210FFD034BDB5108B55B6EC23CD4CE6E ] C:\Windows\SysWOW64\wsecedit.dll
21:39:13.0629 1936 C:\Windows\SysWOW64\wsecedit.dll - ok
21:39:13.0644 1936 [ 0A990AFB9F2726323D61C8ECB8B70B17 ] C:\Windows\SysWOW64\security.dll
21:39:13.0644 1936 C:\Windows\SysWOW64\security.dll - ok
21:39:13.0644 1936 [ 4DBA143F06BAD1DF935CB9603140CF2A ] C:\Windows\SysWOW64\wsdchngr.dll
21:39:13.0644 1936 C:\Windows\SysWOW64\wsdchngr.dll - ok
21:39:13.0644 1936 [ 86AB3F6C784197DC1D994A83AF4259CD ] C:\Windows\SysWOW64\cleanmgr.exe
21:39:13.0644 1936 C:\Windows\SysWOW64\cleanmgr.exe - ok
21:39:13.0660 1936 [ 95DAECF0FB120A7B5DA679CC54E37DDE ] C:\Windows\SysWOW64\netlogon.dll
21:39:13.0660 1936 C:\Windows\SysWOW64\netlogon.dll - ok
21:39:13.0660 1936 [ 2A6A2C09ECC2CB495628E45F1379ECE8 ] C:\Windows\SysWOW64\taskcomp.dll
21:39:13.0660 1936 C:\Windows\SysWOW64\taskcomp.dll - ok
21:39:13.0660 1936 [ 2AE61DEF9112DA8948EEAB3631FF4525 ] C:\Windows\SysWOW64\autoplay.dll
21:39:13.0660 1936 C:\Windows\SysWOW64\autoplay.dll - ok
21:39:13.0676 1936 [ 8F58544719E1C435BC36A8B207096581 ] C:\Windows\SysWOW64\verclsid.exe
21:39:13.0676 1936 C:\Windows\SysWOW64\verclsid.exe - ok
21:39:13.0676 1936 [ BC8E5F6AAF447364A6F6A00D3F8FAF29 ] C:\Windows\SysWOW64\srclient.dll
21:39:13.0676 1936 C:\Windows\SysWOW64\srclient.dll - ok
21:39:13.0676 1936 [ 3606CE1AC3D6A9A9CB7DB35D7F5C54EC ] C:\Windows\SysWOW64\shfolder.dll
21:39:13.0676 1936 C:\Windows\SysWOW64\shfolder.dll - ok
21:39:13.0691 1936 [ AA01497884F9CBAC89470120AF78D2B1 ] C:\Windows\SysWOW64\kerberos.dll
21:39:13.0691 1936 C:\Windows\SysWOW64\kerberos.dll - ok
21:39:13.0691 1936 [ E92143D1B2E32FAF6CC56FD97B908F6A ] C:\Windows\SysWOW64\wpdshext.dll
21:39:13.0691 1936 C:\Windows\SysWOW64\wpdshext.dll - ok
21:39:13.0691 1936 [ 1C474C0C4CB5F15A555FE912CBF4549C ] C:\Windows\SysWOW64\odbcad32.exe
21:39:13.0691 1936 C:\Windows\SysWOW64\odbcad32.exe - ok
21:39:13.0691 1936 [ 90438B514A5AC6A23602484A907E20A7 ] C:\Windows\SysWOW64\filemgmt.dll
21:39:13.0691 1936 C:\Windows\SysWOW64\filemgmt.dll - ok
21:39:13.0707 1936 [ 3D85663DB8A364B5A20ECD588CF4C870 ] C:\Windows\splwow64.exe
21:39:13.0707 1936 C:\Windows\splwow64.exe - ok
21:39:13.0707 1936 [ 57CF7F07E92195E84AB41B2F96FF627F ] C:\Windows\SysWOW64\unregmp2.exe
21:39:13.0707 1936 C:\Windows\SysWOW64\unregmp2.exe - ok
21:39:13.0707 1936 [ BF2156D8D9866983B55D95382131DC4A ] C:\Windows\SysWOW64\lsmproxy.dll
21:39:13.0707 1936 C:\Windows\SysWOW64\lsmproxy.dll - ok
21:39:13.0722 1936 [ C5A75EB48E2344ABDC162BDA79E16841 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
21:39:13.0722 1936 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe - ok
21:39:13.0722 1936 [ E5F7C30EDF0892667933BE879F067D67 ] C:\Windows\SysWOW64\msvcr100_clr0400.dll
21:39:13.0722 1936 C:\Windows\SysWOW64\msvcr100_clr0400.dll - ok
21:39:13.0722 1936 [ 428FF21418ADCD6FAD6189CD9520A67B ] C:\Windows\SysWOW64\wiatrace.dll
21:39:13.0722 1936 C:\Windows\SysWOW64\wiatrace.dll - ok
21:39:13.0738 1936 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
21:39:13.0738 1936 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe - ok
21:39:13.0738 1936 [ EE60FC8F65B94C392DE0F75533C014FB ] C:\Windows\SysWOW64\mstlsapi.dll
21:39:13.0738 1936 C:\Windows\SysWOW64\mstlsapi.dll - ok
21:39:13.0738 1936 [ CB21CD39637AC13F3455454B2F648257 ] C:\Windows\System32\msvcr100_clr0400.dll
21:39:13.0738 1936 C:\Windows\System32\msvcr100_clr0400.dll - ok
21:39:13.0754 1936 [ 72AB6633E9B39EC7FEBEDF083A9061E5 ] C:\Windows\System32\mscoree.dll
21:39:13.0754 1936 C:\Windows\System32\mscoree.dll - ok
21:39:13.0754 1936 [ 56DF028F2EE4A2C2972E06907815C822 ] C:\Windows\SysWOW64\mshtmled.dll
21:39:13.0754 1936 C:\Windows\SysWOW64\mshtmled.dll - ok
21:39:13.0754 1936 [ 4504819D18FAC09B6108D8728467E5B2 ] C:\Windows\SysWOW64\browseui.dll
21:39:13.0754 1936 C:\Windows\SysWOW64\browseui.dll - ok
21:39:13.0769 1936 [ 11AFB3767663997E0CE911CD015599C9 ] C:\Program Files (x86)\Google\Update\1.3.21.145\goopdateres_en.dll
21:39:13.0769 1936 C:\Program Files (x86)\Google\Update\1.3.21.145\goopdateres_en.dll - ok
21:39:13.0769 1936 [ 2CB350B72FEA6FB5A010099A4444B636 ] C:\Windows\SysWOW64\mycomput.dll
21:39:13.0769 1936 C:\Windows\SysWOW64\mycomput.dll - ok
21:39:13.0785 1936 [ 28622FC22E0D46EE0A494EF084235F74 ] C:\Windows\SysWOW64\netcenter.dll
21:39:13.0785 1936 C:\Windows\SysWOW64\netcenter.dll - ok
21:39:13.0785 1936 [ D630B6F2E8379B6F10DC16E82A426552 ] C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
21:39:13.0785 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe - ok
21:39:13.0785 1936 [ 3FCB7347D2DE38488C85A31EA7838A3C ] C:\Windows\SysWOW64\WinSATAPI.dll
21:39:13.0785 1936 C:\Windows\SysWOW64\WinSATAPI.dll - ok
21:39:13.0800 1936 [ B11FDCA4410D6252964EF97F9A47DE74 ] C:\Windows\SysWOW64\TSChannel.dll
21:39:13.0800 1936 C:\Windows\SysWOW64\TSChannel.dll - ok
21:39:13.0800 1936 [ EC43D9CC95C3BB5FEFDBCF22D375E1F5 ] C:\Windows\SysWOW64\adtschema.dll
21:39:13.0800 1936 C:\Windows\SysWOW64\adtschema.dll - ok
21:39:13.0800 1936 [ 681D46C02A26F00C5F767B78BDAC7D1E ] C:\Windows\SysWOW64\networkmap.dll
21:39:13.0800 1936 C:\Windows\SysWOW64\networkmap.dll - ok
21:39:13.0800 1936 [ 16A37E6E522EE1F2B1BDBD6A0BAF7C23 ] C:\Program Files (x86)\Dell Support Center\bin\sprtupdate.dll
21:39:13.0800 1936 C:\Program Files (x86)\Dell Support Center\bin\sprtupdate.dll - ok
21:39:13.0816 1936 [ A1400CCB4D99E0B9E76EB45782D5C7FC ] C:\Windows\SysWOW64\ieui.dll
21:39:13.0816 1936 C:\Windows\SysWOW64\ieui.dll - ok
21:39:13.0816 1936 [ 57125869A7B9638A5D11DD685AA65EB4 ] C:\Windows\SysWOW64\PlaySndSrv.dll
21:39:13.0816 1936 C:\Windows\SysWOW64\PlaySndSrv.dll - ok
21:39:13.0816 1936 [ 67BB7141F7F5F37411F796943B3418B6 ] C:\Windows\SysWOW64\framedynos.dll
21:39:13.0816 1936 C:\Windows\SysWOW64\framedynos.dll - ok
21:39:13.0832 1936 [ 43E1054C713C48D252A1826C5E14AACA ] C:\Windows\SysWOW64\MsCtfMonitor.dll
21:39:13.0832 1936 C:\Windows\SysWOW64\MsCtfMonitor.dll - ok
21:39:13.0832 1936 [ B13A8D6F708AA2034A9DE0979F81D890 ] C:\Windows\SysWOW64\miguiresource.dll
21:39:13.0832 1936 C:\Windows\SysWOW64\miguiresource.dll - ok
21:39:13.0832 1936 [ FBF628702A408977FEB0845D48F4F154 ] C:\Windows\SysWOW64\migwiz\migwiz.exe
21:39:13.0832 1936 C:\Windows\SysWOW64\migwiz\migwiz.exe - ok
21:39:13.0847 1936 [ A16A6853CCDC07790E59D51A922D02CD ] C:\Windows\SysWOW64\migwiz\MIGUIRes.dll
21:39:13.0847 1936 C:\Windows\SysWOW64\migwiz\MIGUIRes.dll - ok
21:39:13.0847 1936 [ 08578F3CA5365F896D90CE2BF97FD000 ] C:\Windows\SysWOW64\IconCodecService.dll
21:39:13.0847 1936 C:\Windows\SysWOW64\IconCodecService.dll - ok
21:39:13.0847 1936 [ 941486AB385556BF6A62342F8CA15BD8 ] C:\Windows\SysWOW64\accessibilitycpl.dll
21:39:13.0847 1936 C:\Windows\SysWOW64\accessibilitycpl.dll - ok
21:39:13.0863 1936 [ CDE9F06A3F1D7907599329561D71C8F3 ] C:\Windows\SysWOW64\FirewallSettings.exe
21:39:13.0863 1936 C:\Windows\SysWOW64\FirewallSettings.exe - ok
21:39:13.0863 1936 [ 79B0EC7806B563475A211C5B0F9A4B9C ] C:\Windows\SysWOW64\AuxiliaryDisplayCpl.dll
21:39:13.0863 1936 C:\Windows\SysWOW64\AuxiliaryDisplayCpl.dll - ok
21:39:13.0863 1936 [ 780E82F54147B3D11F52D3128B727534 ] C:\Windows\SysWOW64\FunctionDiscoveryFolder.dll
21:39:13.0863 1936 C:\Windows\SysWOW64\FunctionDiscoveryFolder.dll - ok
21:39:13.0878 1936 [ FCBF244FE64C227839EC365333CBE79B ] C:\Windows\System32\AuxiliaryDisplayServices.dll
21:39:13.0878 1936 C:\Windows\System32\AuxiliaryDisplayServices.dll - ok
21:39:13.0878 1936 [ B25DBBA6C63A61FF4AFDB5ADAB4E70CB ] C:\Windows\SysWOW64\SmartcardCredentialProvider.dll
21:39:13.0878 1936 C:\Windows\SysWOW64\SmartcardCredentialProvider.dll - ok
21:39:13.0878 1936 [ 36CCD8A79539C4ACE3BABE09C2CFBA16 ] C:\Windows\SysWOW64\WMASF.DLL
21:39:13.0878 1936 C:\Windows\SysWOW64\WMASF.DLL - ok
21:39:13.0894 1936 [ 2C7B4E944A48B9A07B7BF2AB262F197E ] C:\Windows\SysWOW64\icm32.dll
21:39:13.0894 1936 C:\Windows\SysWOW64\icm32.dll - ok
21:39:13.0894 1936 [ CB1F79A5B3551273E55F69DDDCB919E3 ] C:\Windows\SysWOW64\dispex.dll
21:39:13.0894 1936 C:\Windows\SysWOW64\dispex.dll - ok
21:39:13.0894 1936 [ 84B8827562B005C118CADBA0F25DB2C6 ] C:\Windows\SysWOW64\dsound.dll
21:39:13.0894 1936 C:\Windows\SysWOW64\dsound.dll - ok
21:39:13.0910 1936 [ 218B73EA8341EA9FDF018D43052E790A ] C:\Windows\SysWOW64\mssrch.dll
21:39:13.0910 1936 C:\Windows\SysWOW64\mssrch.dll - ok
21:39:13.0910 1936 [ C47F35CC6FA4F1BDBEF8F87AC1A46537 ] C:\Windows\System32\wuapi.dll
21:39:13.0910 1936 C:\Windows\System32\wuapi.dll - ok
21:39:13.0910 1936 [ BF7E4D6F60A6D9E866432855C6F8C262 ] C:\Windows\SysWOW64\sqmapi.dll
21:39:13.0910 1936 C:\Windows\SysWOW64\sqmapi.dll - ok
21:39:13.0910 1936 [ 5E41139EC6EFBCAFFD96D46925E544AB ] C:\Windows\SysWOW64\mspatcha.dll
21:39:13.0910 1936 C:\Windows\SysWOW64\mspatcha.dll - ok
21:39:13.0925 1936 [ E746ED90132C6B6313CE9179F56BD31D ] C:\Windows\System32\wups.dll
21:39:13.0925 1936 C:\Windows\System32\wups.dll - ok
21:39:13.0925 1936 [ 468B4C4E57F4F371F13990F0F3B010C4 ] C:\Windows\System32\mspatcha.dll
21:39:13.0925 1936 C:\Windows\System32\mspatcha.dll - ok
21:39:13.0925 1936 [ BFA034AAC103D8A6F591AC9364688339 ] C:\Windows\SysWOW64\t2embed.dll
21:39:13.0925 1936 C:\Windows\SysWOW64\t2embed.dll - ok
21:39:13.0941 1936 [ C1C03EA437EDDA8A7D4D8786E5AE6751 ] C:\Windows\System32\wuauclt.exe
21:39:13.0941 1936 C:\Windows\System32\wuauclt.exe - ok
21:39:13.0941 1936 [ F51059EE3C543CB364A069CAFB252031 ] C:\Windows\System32\igfxdev.dll
21:39:13.0941 1936 C:\Windows\System32\igfxdev.dll - ok
21:39:13.0941 1936 [ 7FE0D0C8F53735EA17C9AE93EFE7AD5A ] C:\Windows\System32\wups2.dll
21:39:13.0941 1936 C:\Windows\System32\wups2.dll - ok
21:39:13.0956 1936 [ 68563AC389F92EE79F1C714288BA1DCE ] C:\Windows\SysWOW64\imgutil.dll
21:39:13.0956 1936 C:\Windows\SysWOW64\imgutil.dll - ok
21:39:13.0956 1936 [ E79FDA8D320147FDC347C504B3487F87 ] C:\Windows\SysWOW64\spoolss.dll
21:39:13.0956 1936 C:\Windows\SysWOW64\spoolss.dll - ok
21:39:13.0956 1936 [ 734DAA4FEAC6905BCFB30410D6C7E003 ] C:\Windows\SysWOW64\ddrawex.dll
21:39:13.0956 1936 C:\Windows\SysWOW64\ddrawex.dll - ok
21:39:13.0956 1936 [ CA493A92DA9880B6F1A89C3DBD54BA5B ] C:\Windows\SysWOW64\dxtrans.dll
21:39:13.0956 1936 C:\Windows\SysWOW64\dxtrans.dll - ok
21:39:13.0972 1936 [ 801F1E963F7EEFFDA3F9EF89DB3EF133 ] C:\Windows\SysWOW64\radardt.dll
21:39:13.0972 1936 C:\Windows\SysWOW64\radardt.dll - ok
21:39:13.0972 1936 [ D0A95E567224B4C347CBDD6541E5D928 ] C:\Windows\SysWOW64\wscisvif.dll
21:39:13.0972 1936 C:\Windows\SysWOW64\wscisvif.dll - ok
21:39:13.0972 1936 [ FE3702015BE4D214808A2FBC07B8E5FF ] C:\Windows\SysWOW64\wscproxystub.dll
21:39:13.0972 1936 C:\Windows\SysWOW64\wscproxystub.dll - ok
21:39:13.0988 1936 [ EF764E33878B3A4A9E5A2FB5D0D031D0 ] C:\Windows\SysWOW64\dciman32.dll
21:39:13.0988 1936 C:\Windows\SysWOW64\dciman32.dll - ok
21:39:13.0988 1936 [ BC83108B18756547013ED443B8CDB31B ] C:\Windows\SysWOW64\msvcp100.dll
21:39:13.0988 1936 C:\Windows\SysWOW64\msvcp100.dll - ok
21:39:13.0988 1936 [ 898E7C06A350D4A1A64A9EA264D55452 ] C:\Windows\SysWOW64\winlogon.exe
21:39:13.0988 1936 C:\Windows\SysWOW64\winlogon.exe - ok
21:39:14.0003 1936 [ A4E7946B71BBDF8708C7AC97FD9E9008 ] C:\Windows\SysWOW64\win32spl.dll
21:39:14.0003 1936 C:\Windows\SysWOW64\win32spl.dll - ok
21:39:14.0003 1936 [ 31A6D4B8803CCBA44271F05E08C4955A ] C:\Windows\System32\igfxsrvc.dll
21:39:14.0003 1936 C:\Windows\System32\igfxsrvc.dll - ok
21:39:14.0003 1936 [ 352C7C2470C03AFD41889236D849D75C ] C:\Windows\System32\igfxrenu.lrc
21:39:14.0003 1936 C:\Windows\System32\igfxrenu.lrc - ok
21:39:14.0003 1936 [ 67C30FAFA58BD7E02A9DA8BE28512934 ] C:\Windows\SysWOW64\audiodev.dll
21:39:14.0003 1936 C:\Windows\SysWOW64\audiodev.dll - ok
21:39:14.0019 1936 [ A6950BA89334D51EC281904781B89BD2 ] C:\Windows\SysWOW64\asycfilt.dll
21:39:14.0019 1936 C:\Windows\SysWOW64\asycfilt.dll - ok
21:39:14.0019 1936 [ 10AB9C9ADB89816BEFB077E72659D029 ] C:\Windows\SysWOW64\igdumd32.dll
21:39:14.0019 1936 C:\Windows\SysWOW64\igdumd32.dll - ok
21:39:14.0019 1936 [ EE9D715AF1B928982F417238B9914484 ] C:\Windows\SysWOW64\ieapfltr.dll
21:39:14.0019 1936 C:\Windows\SysWOW64\ieapfltr.dll - ok
21:39:14.0034 1936 [ 4B555106290BD117334E9A08761C035A ] C:\Windows\SysWOW64\rundll32.exe
21:39:14.0034 1936 C:\Windows\SysWOW64\rundll32.exe - ok
21:39:14.0034 1936 [ F6AD58179B79C7D6272588FF468AA1AB ] C:\Windows\SysWOW64\dldtcoms.exe
21:39:14.0034 1936 C:\Windows\SysWOW64\dldtcoms.exe - ok
21:39:14.0034 1936 [ CDE36A70A5280FC0696E6E4363C4C71D ] C:\Windows\SysWOW64\TaskSchdPS.dll
21:39:14.0034 1936 C:\Windows\SysWOW64\TaskSchdPS.dll - ok
21:39:14.0050 1936 [ 9D80E0BE979C3EDAF2863F23B88F4DE6 ] C:\Windows\SysWOW64\drivers\packet.sys
21:39:14.0050 1936 C:\Windows\SysWOW64\drivers\packet.sys - ok
21:39:14.0050 1936 [ 04044BF8E6989BE45FA718C24407CA28 ] C:\Windows\SysWOW64\networkexplorer.dll
21:39:14.0050 1936 C:\Windows\SysWOW64\networkexplorer.dll - ok
21:39:14.0050 1936 [ DFE1F53A9D02FD6CDB4F152F7FFC5255 ] C:\Users\dianne\Downloads\ccsetup328.exe
21:39:14.0050 1936 C:\Users\dianne\Downloads\ccsetup328.exe - ok
21:39:14.0050 1936 [ A050A0366D7040FF84F6E40994405253 ] C:\Users\dianne\Downloads\dfsetup207.exe
21:39:14.0050 1936 C:\Users\dianne\Downloads\dfsetup207.exe - ok
21:39:14.0066 1936 ============================================================
21:39:14.0066 1936 Scan finished
21:39:14.0066 1936 ============================================================
21:39:14.0066 2440 Detected object count: 5
21:39:14.0066 2440 Actual detected object count: 5
21:39:45.0141 2440 !SASCORE ( UnsignedFile.Multi.Generic ) - skipped by user
21:39:45.0141 2440 !SASCORE ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:39:45.0141 2440 Apache2.2 ( UnsignedFile.Multi.Generic ) - skipped by user
21:39:45.0141 2440 Apache2.2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:39:45.0141 2440 DockLoginService ( UnsignedFile.Multi.Generic ) - skipped by user
21:39:45.0141 2440 DockLoginService ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:39:45.0141 2440 dsl-db ( UnsignedFile.Multi.Generic ) - skipped by user
21:39:45.0141 2440 dsl-db ( UnsignedFile.Multi.Generic ) - User select action: Skip
21:39:47.0153 2440 \Device\Harddisk0\DR0\# - copied to quarantine
21:39:47.0153 2440 \Device\Harddisk0\DR0 - copied to quarantine
21:39:47.0621 2440 \Device\Harddisk0\DR0 ( Rootkit.Boot.Harbinger.a ) - will be cured on reboot
21:39:47.0621 2440 \Device\Harddisk0\DR0 - ok
21:39:47.0637 2440 \Device\Harddisk0\DR0 ( Rootkit.Boot.Harbinger.a ) - User select action: Cure
21:40:53.0287 3336 Deinitialize success


3rd:

21:43:06.0393 3876 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
21:43:06.0986 3876 ============================================================
21:43:06.0986 3876 Current date / time: 2013/06/13 21:43:06.0986
21:43:06.0986 3876 SystemInfo:
21:43:06.0986 3876
21:43:06.0986 3876 OS Version: 6.0.6002 ServicePack: 2.0
21:43:06.0986 3876 Product type: Workstation
21:43:06.0986 3876 ComputerName: DIANNE-PC
21:43:06.0986 3876 UserName: dianne
21:43:06.0986 3876 Windows directory: C:\Windows
21:43:06.0986 3876 System windows directory: C:\Windows
21:43:06.0986 3876 Running under WOW64
21:43:06.0986 3876 Processor architecture: Intel x64
21:43:06.0986 3876 Number of processors: 4
21:43:06.0986 3876 Page size: 0x1000
21:43:06.0986 3876 Boot type: Normal boot
21:43:06.0986 3876 ============================================================
21:43:10.0013 3876 BG loaded
21:43:10.0481 3876 Drive \Device\Harddisk0\DR0 - Size: 0xAEA8CDE000 (698.64 Gb), SectorSize: 0x200, Cylinders: 0x16441, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
21:43:10.0481 3876 ============================================================
21:43:10.0481 3876 \Device\Harddisk0\DR0:
21:43:10.0512 3876 MBR partitions:
21:43:10.0512 3876 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B800, BlocksNum 0x1E00000
21:43:10.0512 3876 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1E1B800, BlocksNum 0x5572A000
21:43:10.0512 3876 ============================================================
21:43:10.0660 3876 C: <-> \Device\Harddisk0\DR0\Partition2
21:43:10.0802 3876 D: <-> \Device\Harddisk0\DR0\Partition1
21:43:10.0802 3876 ============================================================
21:43:10.0802 3876 Initialize success
21:43:10.0802 3876 ============================================================
21:45:30.0175 3724 Deinitialize success
  • 0

#60
jtroop

jtroop

    Member

  • Topic Starter
  • Member
  • PipPip
  • 70 posts

Also download aswMBR.exe ( 511KB ) to your desktop. If you already have this application, this is a new version I need you to download.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image

The tool will also produce a copy of the mbrdump labeled MBR.dat. Please upload that file here.



The file was submitted to your link. Here is the Log:

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-06-13 21:54:32
-----------------------------
21:54:32.807 OS Version: Windows x64 6.0.6002 Service Pack 2
21:54:32.807 Number of processors: 4 586 0x170A
21:54:32.807 ComputerName: DIANNE-PC UserName: dianne
21:54:35.059 Initialize success
21:55:08.061 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
21:55:08.061 Disk 0 Vendor: ST3750528AS CC44 Size: 715404MB BusType: 3
21:55:08.419 Disk 0 MBR read successfully
21:55:08.419 Disk 0 MBR scan
21:55:08.435 Disk 0 Windows VISTA default MBR code
21:55:08.466 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63
21:55:08.575 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 15360 MB offset 112640
21:55:08.607 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 699988 MB offset 31569920
21:55:08.809 Disk 0 scanning C:\Windows\system32\drivers
21:55:24.144 Service scanning
21:55:30.088 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
21:55:35.704 Modules scanning
21:55:35.704 Disk 0 trace - called modules:
21:55:35.719 ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys ataport.SYS pciide.sys PCIIDEX.SYS hal.dll atapi.sys
21:55:36.234 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004cb2790]
21:55:36.234 3 CLASSPNP.SYS[fffffa6000bc4c33] -> nt!IofCallDriver -> [0xfffffa800494f520]
21:55:36.234 5 acpi.sys[fffffa60008defde] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa800494d4b0]
21:55:36.234 Scan finished successfully
21:56:02.671 Disk 0 MBR has been saved successfully to "C:\Users\dianne\Desktop\MBR.dat"
21:56:02.671 The log file has been saved successfully to "C:\Users\dianne\Desktop\aswMBR.txt"

Edited by jtroop, 13 June 2013 - 08:01 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP