Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Several Viruses found on computer [Solved]


  • This topic is locked This topic is locked

#1
Ardant

Ardant

    Member

  • Member
  • PipPipPip
  • 229 posts
Well the kids are at it again. Some of my online games stopped working. File Hippo stated that I needed to update my drivers so I thought that may have something to do with it. I followed all the procedures to delete and install the drivers and that just started a chain reaction of problems. I have been getting the BSOD but only when using the internet if and when I could get access. I was getting Proxy set up problems that would not allow me access. Malwarebytes, Avast and Spybot found nothing. Trend Housecall Online Scanner found a rootkit. It was a Russian name but I never found the report afterwards. I ran ESET and it found 10 items. Log posted below. I ran Kapersky as well but can no longer find the program or report. I ran ADW cleaner and TFC.

I seem to have corrected a great many issues but still can not get access to some online games.

Please advise

OTL logfile created on: 21/06/2013 7:28:06 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\John Richardson\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.25 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 71.81% Memory free
7.96 Gb Paging File | 7.11 Gb Available in Paging File | 89.34% Paging File free
Paging file location(s): C:\pagefile.sys 4989 7500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.73 Gb Total Space | 59.50 Gb Free Space | 20.19% Space Free | Partition Type: NTFS
Drive D: | 630.37 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PARENT | User Name: John Richardson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/06/21 19:26:12 | 006,065,712 | ---- | M] (Blizzard Entertainment) -- C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1737\Agent.exe
PRC - [2013/06/21 19:18:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John Richardson\Desktop\OTL.exe
PRC - [2013/06/19 18:49:19 | 000,182,184 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2013/05/16 10:59:00 | 003,830,224 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013/05/16 10:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013/05/16 10:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013/05/09 04:58:30 | 004,858,968 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/09 04:58:30 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2013/03/21 00:10:12 | 003,560,832 | ---- | M] (Xfire Inc.) -- C:\Program Files\Xfire\Xfire.exe
PRC - [2013/03/20 18:52:54 | 019,258,488 | ---- | M] (Blizzard Entertainment) -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\Blizzard Launcher.exe
PRC - [2012/12/29 13:54:24 | 000,096,056 | ---- | M] (Siber Systems) -- C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2012/11/23 04:22:04 | 000,307,712 | ---- | M] (FileHippo.com) -- C:\Program Files\FileHippo.com\UpdateChecker.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/11/03 20:20:12 | 000,866,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006/11/03 20:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2006/03/30 10:15:44 | 000,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2003/08/29 20:05:35 | 000,360,448 | ---- | M] () -- C:\Program Files\SpywareGuard\sgmain.exe
PRC - [2003/08/29 12:14:56 | 000,233,472 | ---- | M] () -- C:\Program Files\SpywareGuard\sgbhp.exe
PRC - [2001/10/15 04:42:45 | 000,196,608 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe


========== Modules (No Company Name) ==========

MOD - [2013/06/21 18:06:32 | 002,089,984 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\13062103\algo.dll
MOD - [2013/05/16 10:55:28 | 000,161,112 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2013/05/16 10:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013/05/16 10:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2013/05/16 03:17:35 | 000,974,336 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\b24d7c1afb003e95c6f5d924c56b930c\System.Configuration.ni.dll
MOD - [2013/05/16 03:15:51 | 012,536,320 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fd283696d695cab0aca331cb9cbbcacd\System.Windows.Forms.ni.dll
MOD - [2013/05/16 03:11:49 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2013/03/20 18:52:53 | 010,837,504 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\QtWebKit4.dll
MOD - [2013/03/20 18:52:53 | 000,339,968 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\QtXml4.dll
MOD - [2013/03/20 18:52:52 | 008,173,568 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\QtGui4.dll
MOD - [2013/03/20 18:52:52 | 002,293,248 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\QtCore4.dll
MOD - [2013/03/20 18:52:52 | 000,970,752 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\QtNetwork4.dll
MOD - [2013/03/20 18:52:52 | 000,285,184 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\imageformats\qtiff4.dll
MOD - [2013/03/20 18:52:52 | 000,266,752 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\phonon4.dll
MOD - [2013/03/20 18:52:52 | 000,220,672 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\imageformats\qmng4.dll
MOD - [2013/03/20 18:52:52 | 000,196,608 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\imageformats\qjpeg4.dll
MOD - [2013/03/20 18:52:52 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\imageformats\qico4.dll
MOD - [2013/03/20 18:52:52 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Battle.net\Client\Blizzard Launcher.1974\imageformats\qgif4.dll
MOD - [2013/02/14 04:12:16 | 011,892,224 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\e40fa0e028ce1e45dea4270399281a4a\System.Web.ni.dll
MOD - [2013/02/14 04:11:09 | 001,712,640 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c784b72df85e3b35b4f8a4054a2e43e1\Microsoft.VisualBasic.ni.dll
MOD - [2013/01/09 09:06:42 | 008,397,312 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\898552cef448b07502cc2c9e9763c07a\System.ni.dll
MOD - [2013/01/09 09:06:37 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll
MOD - [2013/01/09 08:59:40 | 001,660,928 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\14c7539697f628595ed92cd51149db78\System.Drawing.ni.dll
MOD - [2013/01/09 08:59:33 | 005,764,608 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f2e0f6dacd8c58ef0e1bb788ca4347ee\System.Xml.ni.dll
MOD - [2012/08/23 10:38:24 | 000,574,840 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
MOD - [2012/04/03 17:06:14 | 000,565,640 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\av\BDSmartDB.dll
MOD - [2011/05/19 20:34:22 | 000,056,224 | ---- | M] () -- \\?\C:\Program Files\Spybot - Search & Destroy 2\av\avxdisk.dll
MOD - [2006/11/05 11:28:18 | 004,587,520 | R--- | M] () -- C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll
MOD - [2006/08/18 14:17:36 | 000,056,056 | ---- | M] () -- C:\WINDOWS\system32\DLAAPI_W.DLL
MOD - [2003/08/29 20:05:35 | 000,360,448 | ---- | M] () -- C:\Program Files\SpywareGuard\sgmain.exe
MOD - [2003/08/29 12:14:56 | 000,233,472 | ---- | M] () -- C:\Program Files\SpywareGuard\sgbhp.exe


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter -- (sprtsvc_dellsupportcenter)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Spybot -- (SDWSCService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - File not found [Auto | Stopped] -- c:\program files\common files\akamai/netsession_win_80c2ffa.dll -- (Akamai)
SRV - [2013/06/19 18:49:19 | 000,182,184 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013/06/11 20:59:18 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/11 18:26:17 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/05/09 04:58:30 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/07/06 19:28:00 | 003,980,648 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\WINDOWS\system32\GameMon.des -- (npggsvc)
SRV - [2006/11/03 20:19:58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2006/03/30 10:15:44 | 000,096,341 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | System | Stopped] -- -- (Beep)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\JOHNRI~1\LOCALS~1\Temp\aaudstum.sys -- (aaudstum)
DRV - [2013/05/09 04:59:10 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013/05/09 04:59:10 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013/05/09 04:59:10 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013/05/09 04:59:10 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013/05/09 04:59:10 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013/05/09 04:59:09 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013/05/09 04:59:09 | 000,049,760 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (AswRdr)
DRV - [2013/05/09 04:59:09 | 000,021,576 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswKbd.sys -- (aswKbd)
DRV - [2013/05/09 04:59:08 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012/12/29 16:59:38 | 000,024,184 | ---- | M] (Almico Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2012/11/16 17:04:28 | 007,874,560 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2012/09/04 01:54:46 | 000,022,640 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\Dell Support Center\pcdsrvc.pkms -- (PCDSRVC{E9D79540-57D5953E-06020101}_0)
DRV - [2012/05/14 02:12:12 | 000,103,040 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtihdXP3.sys -- (AtiHDAudioService)
DRV - [2008/01/15 19:17:58 | 004,652,544 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2007/08/28 21:52:20 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2006/08/18 14:18:08 | 000,009,400 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResM.SYS -- (DLADResM)
DRV - [2006/08/18 14:17:46 | 000,035,096 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABMFSM.SYS -- (DLABMFSM)
DRV - [2006/08/18 14:17:44 | 000,097,848 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2006/08/18 14:17:44 | 000,094,648 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2006/08/18 14:17:42 | 000,026,008 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2006/08/18 14:17:40 | 000,032,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2006/08/18 14:17:38 | 000,104,472 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2006/08/18 14:17:38 | 000,014,520 | ---- | M] (Roxio) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2006/08/11 11:35:18 | 000,012,920 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2006/08/11 11:35:16 | 000,028,184 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_M.SYS -- (DLARTL_M)
DRV - [2005/01/14 12:14:07 | 000,047,616 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01)
DRV - [2004/12/03 06:20:41 | 000,020,544 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfsync02.sys -- (sfsync02)
DRV - [2004/10/28 06:47:59 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02)
DRV - [2004/08/03 22:31:34 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\RTL8139.sys -- (rtl8139)
DRV - [1996/04/03 15:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=1080221
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=1080221
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=1080221
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.ca/ig/dell?hl=en&client=dell-row&channel=ca&ibd=1080221
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes\{4352F279-82F3-4FF2-8C18-74793B4E329F}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes\{4889824E-79B2-4D6E-8092-DCD218F66D7A}: "URL" = http://search.zoneal...Id=&ver=&&r=687
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes\{90D74DB8-5709-4054-911E-52EC8A817CAA}: "URL" = http://ca.search.yah...p={SearchTerms}
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\SearchScopes\{EDAD97F0-437A-4A6D-820C-6622DF6576FB}: "URL" = http://ca.search.yah...p={SearchTerms}
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-879840139-2802958703-907680667-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = localhost:21320

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.9
FF - prefs.js..extensions.enabledAddons: wrc%40avast.com:8.0.1489
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@fileplanet.com/fpdlm: C:\Program Files\Download Manager\npfpdlm.dll (IGN Entertainment)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@IObitBar.com/Plugin: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: File not found
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@raidcall.en/RCplugin: C:\Documents and Settings\John Richardson\Application Data\raidcall\plugins\nprcplugin.dll (Raidcall)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Documents and Settings\John Richardson\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/05/25 09:38:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2012/12/29 13:54:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/16 07:27:14 | 000,000,000 | ---D | M]

[2012/05/23 22:45:05 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\John Richardson\Application Data\Mozilla\Extensions
[2013/05/24 07:03:45 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\John Richardson\Application Data\Mozilla\Firefox\Profiles\zy5758f9.default\extensions
[2013/05/24 07:03:45 | 000,269,448 | ---- | M] () (No name found) -- C:\Documents and Settings\John Richardson\Application Data\Mozilla\Firefox\Profiles\zy5758f9.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2013/04/13 08:33:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/05/25 09:53:09 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/25 09:53:09 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/05/25 09:38:04 | 000,000,000 | ---D | M] (avast! Online Security) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/09/22 12:22:09 | 000,002,027 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml

========== Chrome ==========


O1 HOSTS File: ([2013/06/17 00:43:09 | 000,448,635 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15430 more lines...
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! EasyPass Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe (HP)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-879840139-2802958703-907680667-1005..\Run: [Akamai NetSession Interface] C:\Documents and Settings\John Richardson\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKU\S-1-5-21-879840139-2802958703-907680667-1005..\Run: [FileHippo.com] C:\Program Files\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKU\S-1-5-21-879840139-2802958703-907680667-1005..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKU\S-1-5-21-879840139-2802958703-907680667-1005..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKU\S-1-5-21-879840139-2802958703-907680667-1005..\Run: [Steam] C:\Program Files\Steam\Steam.exe (Valve Corporation)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk.disabled ()
O4 - Startup: C:\Documents and Settings\John Richardson\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O4 - Startup: C:\Documents and Settings\John Richardson\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Show avast! EasyPass Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
O9 - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
O9 - Extra 'Tools' menuitem : Show avast! EasyPass Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (AVAST Software)
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: microsoft.com ([windowsupdate] http in Local intranet)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: worldoftanks.com ([]http in Local intranet)
O15 - HKU\S-1-5-21-879840139-2802958703-907680667-1005\..Trusted Domains: worldoftanks.com ([]https in Trusted sites)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1348353807734 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1333671003155 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {CAFEEFAC-0017-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.71.255.204 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BD334E44-7F06-497C-A727-0B7C2627C830}: DhcpNameServer = 64.71.255.204 64.71.255.198
O18 - Protocol\Handler\dssrequest - No CLSID value found
O18 - Protocol\Handler\intu-qt2007 {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - C:\Program Files\QuickTax 2007\ic2007pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2008 - No CLSID value found
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\sacore - No CLSID value found
O18 - Protocol\Filter\application/x-mfe-ipt - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\WINDOWS\dell.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\dell.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2003/09/28 17:50:06 | 000,000,063 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (sdnclean.exe)
O34 - HKLM BootExecute: (aswBoot.exe /A:* /A:C: /A:*STARTUP-SHORT /A:*STARTUP /L:1033 /heur:100 /RA:chest /pup /archives /IA:0 /KBD:2 /dir:C:\Program)
O34 - HKLM BootExecute: (a)
O34 - HKLM BootExecute: (:1)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-879840139-2802958703-907680667-1005..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/06/21 19:18:44 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\John Richardson\Desktop\OTL.exe
[2013/06/21 19:04:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ATI
[2013/06/21 19:02:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Catalyst Control Center
[2013/06/21 18:59:45 | 000,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2013/06/21 18:59:41 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2013/06/21 18:58:49 | 000,000,000 | ---D | C] -- C:\AMD
[2013/06/21 18:40:34 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\John Richardson\Recent
[2013/06/20 20:10:41 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2013/06/19 19:10:26 | 000,256,904 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2013/06/19 18:49:14 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2013/06/19 18:34:28 | 000,792,704 | ---- | C] (AMD) -- C:\Documents and Settings\John Richardson\Desktop\amddriverdownloader(1).exe
[2013/06/14 18:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2013/06/12 20:36:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/06/12 20:36:21 | 000,015,224 | ---- | C] (Safer Networking Limited) -- C:\WINDOWS\System32\sdnclean.exe
[2013/05/25 13:24:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\John Richardson\Start Menu\Programs\Neverwinter
[2013/05/25 09:38:13 | 000,021,576 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswKbd.sys
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/21 19:18:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\John Richardson\Desktop\OTL.exe
[2013/06/21 19:16:03 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\John Richardson\Desktop\SpeedFan.lnk
[2013/06/21 19:16:02 | 000,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
[2013/06/21 19:06:45 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2013/06/21 19:04:49 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/06/21 19:04:44 | 000,000,364 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013/06/21 19:03:59 | 000,000,644 | ---- | M] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/06/21 19:03:48 | 000,000,900 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/21 19:03:48 | 000,000,414 | ---- | M] () -- C:\WINDOWS\tasks\ProgramUpdateCheck.job
[2013/06/21 19:03:37 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/06/21 19:03:30 | 3487,744,000 | -HS- | M] () -- C:\hiberfil.sys
[2013/06/21 19:03:30 | 000,220,040 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/06/21 18:59:17 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/06/21 18:59:02 | 000,000,904 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/21 18:43:41 | 000,008,992 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/06/21 18:29:36 | 000,000,396 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2013/06/20 20:48:15 | 000,000,470 | ---- | M] () -- C:\WINDOWS\tasks\ProgramRefresh-ATFST.job
[2013/06/19 23:05:12 | 000,000,918 | ---- | M] () -- C:\WINDOWS\DCEBOOT.RST
[2013/06/19 23:03:49 | 000,022,064 | ---- | M] () -- C:\WINDOWS\DCEBoot.exe
[2013/06/19 22:30:10 | 000,694,203 | ---- | M] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\census.cache
[2013/06/19 22:29:35 | 000,236,975 | ---- | M] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\ars.cache
[2013/06/19 18:34:30 | 000,792,704 | ---- | M] (AMD) -- C:\Documents and Settings\John Richardson\Desktop\amddriverdownloader(1).exe
[2013/06/19 07:16:52 | 000,000,616 | ---- | M] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/06/17 00:43:38 | 000,000,360 | RHS- | M] () -- C:\boot.ini
[2013/06/17 00:43:09 | 000,448,635 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013/06/14 18:37:28 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2013/06/14 18:36:20 | 000,001,689 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2013/06/12 20:39:20 | 000,447,019 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130617-004309.backup
[2013/06/12 20:37:47 | 000,000,446 | ---- | M] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/06/12 20:36:40 | 000,001,836 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk
[2013/06/12 20:27:20 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2013/06/12 07:20:00 | 000,446,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130612-203920.backup
[2013/06/11 02:03:03 | 000,000,568 | ---- | M] () -- C:\WINDOWS\tasks\PCDoctorBackgroundMonitorTask.job
[2013/06/08 22:51:54 | 000,648,201 | ---- | M] () -- C:\Documents and Settings\John Richardson\Desktop\adwcleaner.exe
[2013/06/05 07:24:32 | 000,446,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130612-072000.backup
[2013/06/05 07:22:58 | 000,446,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130605-072432.backup
[2013/06/05 07:21:38 | 000,446,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130605-072258.backup
[2013/06/05 07:19:16 | 000,446,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130605-072138.backup
[2013/06/04 07:50:42 | 000,446,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130605-071916.backup
[2013/05/29 07:19:36 | 000,446,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20130604-075042.backup
[2013/05/25 13:24:58 | 000,000,746 | ---- | M] () -- C:\Documents and Settings\John Richardson\Desktop\Neverwinter.lnk
[2013/05/25 09:53:12 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\John Richardson\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/05/25 09:53:12 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[1 C:\Program Files\*.tmp files -> C:\Program Files\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/21 19:00:02 | 000,246,000 | ---- | C] () -- C:\WINDOWS\System32\atiapfxx.blb
[2013/06/21 18:51:01 | 3487,744,000 | -HS- | C] () -- C:\hiberfil.sys
[2013/06/19 23:05:12 | 000,000,918 | ---- | C] () -- C:\WINDOWS\DCEBOOT.RST
[2013/06/19 23:03:39 | 000,022,064 | ---- | C] () -- C:\WINDOWS\DCEBoot.exe
[2013/06/14 18:36:20 | 000,001,689 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2013/06/12 20:37:42 | 000,000,446 | ---- | C] () -- C:\WINDOWS\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/06/12 20:37:41 | 000,000,616 | ---- | C] () -- C:\WINDOWS\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/06/12 20:37:39 | 000,000,644 | ---- | C] () -- C:\WINDOWS\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/06/12 20:36:41 | 000,001,842 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/06/12 20:36:40 | 000,001,836 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Spybot-S&D Start Center.lnk
[2013/06/08 22:51:51 | 000,648,201 | ---- | C] () -- C:\Documents and Settings\John Richardson\Desktop\adwcleaner.exe
[2013/05/25 13:24:58 | 000,000,746 | ---- | C] () -- C:\Documents and Settings\John Richardson\Desktop\Neverwinter.lnk
[2013/03/21 00:10:18 | 000,042,880 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2013/03/18 16:50:00 | 000,174,664 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswVmm.sys
[2013/03/18 16:50:00 | 000,049,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\aswRvrt.sys
[2013/02/14 04:32:34 | 000,201,806 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-879840139-2802958703-907680667-1005-0.dat
[2013/01/21 18:55:29 | 000,000,396 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2013/01/12 09:23:46 | 000,201,806 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2013/01/09 22:31:15 | 000,124,720 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2013/01/04 20:29:31 | 000,012,288 | ---- | C] () -- C:\Documents and Settings\All Users\NTUSER.rhk
[2012/12/24 16:46:30 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2012/06/03 11:44:02 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/05/25 19:04:09 | 010,223,616 | ---- | C] () -- C:\Documents and Settings\John Richardson\NTUSER.bak
[2012/05/23 22:26:32 | 000,034,814 | ---- | C] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\dt.dat
[2012/04/09 18:17:30 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/10/26 01:00:10 | 000,694,203 | ---- | C] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\census.cache
[2011/10/26 00:59:53 | 000,236,975 | ---- | C] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\ars.cache
[2011/10/25 23:25:51 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\housecall.guid.cache
[2011/03/13 11:38:17 | 000,000,463 | ---- | C] () -- C:\Documents and Settings\John Richardson\test
[2008/04/26 12:38:19 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\John Richardson\Application Data\wklnhst.dat
[2008/03/06 23:08:23 | 000,025,600 | ---- | C] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/25 20:02:55 | 000,000,138 | ---- | C] () -- C:\Documents and Settings\John Richardson\Local Settings\Application Data\fusioncache.dat

========== ZeroAccess Check ==========

[2004/08/11 18:21:56 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 20:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 08:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 20:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/19 20:09:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\IObit
[2012/05/24 21:09:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\wargaming.net
[2013/01/04 20:30:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Wise Registry Cleaner
[2012/10/16 19:29:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/08/21 19:42:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Battle.net
[2013/02/23 18:23:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CheckPoint
[2012/05/23 21:11:14 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2012/08/07 00:36:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Curse Client
[2011/06/05 18:49:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Electronic Arts
[2009/10/29 19:51:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Fallout3
[2011/01/04 19:07:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeApp
[2012/02/10 08:21:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit
[2013/04/11 18:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Licenses
[2012/05/24 21:22:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2011/06/05 18:52:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Origin
[2012/09/18 20:50:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCDr
[2012/04/03 18:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2012/12/29 13:54:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2012/04/05 07:33:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SupportSoft
[2011/06/05 17:52:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Default User\Application Data\IObit
[2008/12/27 18:13:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Acreon
[2012/05/26 09:04:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\AVG
[2012/05/23 21:52:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\AVG2012
[2012/11/03 20:35:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Bioshock
[2011/05/30 19:58:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\BugTrap Console Test108
[2008/03/01 15:34:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Canon
[2013/06/08 22:52:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\CheckPoint
[2012/12/24 17:50:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Cobra Mobile
[2012/06/03 13:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Downloaded Installations
[2010/03/28 14:51:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\FOG Downloader
[2011/08/20 12:16:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\IGG
[2012/10/06 12:27:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\IObit
[2011/03/27 12:56:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Itibiti
[2011/07/16 20:40:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Kalypso Media
[2012/04/05 07:28:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\PCDr
[2012/06/03 13:39:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\PingPlotter
[2012/12/19 22:44:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\raidcall
[2011/03/27 13:14:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\RegistryKeys
[2012/12/29 13:56:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\RoboForm
[2013/04/19 19:48:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Sony Online Entertainment
[2008/04/26 12:38:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Template
[2011/07/07 21:18:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Unity
[2011/05/03 21:16:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\wargaming.net
[2012/06/02 09:56:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\John Richardson\Application Data\Wise Registry Cleaner
[2009/02/15 13:29:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristi Richardson\Application Data\Canon
[2012/04/04 21:01:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristi Richardson\Application Data\IObit
[2008/05/05 12:37:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Kristi Richardson\Application Data\Template
[2009/12/11 11:57:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\SACore

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 76 bytes -> C:\WINDOWS\System32\XPSViewer:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\SxsCaPendDel:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\ie8updates:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\ie8:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB942288-v3$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2839229$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2829361$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2820197$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2761226$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2757638$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2756822$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2753842-v2$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2736233$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2731847$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2727528$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2724197$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2723135$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2719985$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2718704$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2718523$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2709162$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2698365$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2685939$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2661254-v2$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WINDOWS\$NtUninstallKB2655992$:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\WAR2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\World of Warcraft:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Ubisoft:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Sun:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\StarCraft II:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\SpywareBlaster:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\SpeedFan:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Sony Online Entertainment:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Siber Systems:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Reference Assemblies:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Railroad Tycoon 3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\RaidCall:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\QuickTax 2009:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\QuickTax 2008:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\QuickTax 2007:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\PingPlotter Standard:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Origin:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Origin Games:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\NOS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\MSECache:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\MSBuild:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Mozilla Maintenance Service:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Mozilla Firefox:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Microsoft.NET:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\IObit:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\FreeApps:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Firaxis Games:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\FileHippo.com:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\File Type Assistant:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\ESET:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\EA SPORTS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\DivX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Diablo III:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Common Files\Intuit:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Common Files\AnswerWorks 4.0:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\ATI:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\ATI Technologies:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\NetmarbleGlobal:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\ie-spyad_zo:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Download:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.010\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.009\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.008\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.007\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.006\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.005\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.004\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.003\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.002\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.001\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\TEMP.PARENT.000\Application Data\Roxio:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\LocalService\Application Data\SACore:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\LocalService\Application Data\McAfee:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\LocalService\Application Data\Macromedia:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\LocalService\Application Data\DivX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\LocalService\Application Data\Adobe:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Kristi Richardson\Application Data\IObit:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Kristi Richardson\Application Data\Intuit Canada:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Kristi Richardson\Application Data\Canon:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Start Menu\Programs\StarCraft II:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Start Menu\Programs\SpeedFan:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Start Menu\Programs\RaidCall:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Start Menu\Programs\Neverwinter:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Start Menu\Programs\Games:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Start Menu\Programs\FreeApps:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Start Menu\Programs\Administrative Tools:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\PrivacIE:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\StarCraft II:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\SH3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\QuickTax:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\ProcAlyzer Dumps:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\My Avast EasyPass Data:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\KOEI:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\Diablo III:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\My Documents\democracy2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\Temp:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\Sun:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\PCHealth:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\Origin:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\Electronic Arts:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\Dell:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\Blizzard Entertainment:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Local Settings\Application Data\Akamai:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\IECompatCache:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Desktop\ZonedOut:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Desktop\Runes_of_Magic_2.1.6.2049:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Desktop\New Hampshire Trip 2011:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Desktop\Adobe Reader 9 Installer:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\Sony Online Entertainment:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\RegistryKeys:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\raidcall:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\PingPlotter:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\Mozilla:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\Itibiti:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\Intuit Canada:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\FOG Downloader:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\Downloaded Installations:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\DivX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\CheckPoint:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\John Richardson\Application Data\Acreon:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\Default User\Application Data\Macromedia:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Ventrilo:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\StarCraft II:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBlaster:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy 2:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Smart Defrag:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Railroad Tycoon 3:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\QuickTax:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Origin:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\NetmarbleGlobal:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Firaxis Games:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\DivX:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\Diablo III:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Start Menu\Programs\avast! EasyPass:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Desktop\CC Support:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\RoboForm:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\Origin:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\NOS:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\Mozilla:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\MFAData:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\Licenses:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\Intuit Canada:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\FreeApp:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\Common Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\CheckPoint:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\Blizzard:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Documents and Settings\All Users\Application Data\Battle.net:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Config.Msi:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\b90c13be94acef04c636:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\AMD:Roxio EMC Stream
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34

< End of report >

OTL Extras logfile created on: 21/06/2013 7:28:06 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\John Richardson\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.25 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 71.81% Memory free
7.96 Gb Paging File | 7.11 Gb Available in Paging File | 89.34% Paging File free
Paging file location(s): C:\pagefile.sys 4989 7500 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.73 Gb Total Space | 59.50 Gb Free Space | 20.19% Space Free | Partition Type: NTFS
Drive D: | 630.37 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: PARENT | User Name: John Richardson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- "C:\Program Files\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [Digital Photo Professional] -- C:\Program Files\Canon\Digital Photo Professional\DPPViewer.exe /path "%1" (CANON INC.)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"UpdatesDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"58199:TCP" = 58199:TCP:*:Enabled:Pando Media Booster
"58199:UDP" = 58199:UDP:*:Enabled:Pando Media Booster
"59153:TCP" = 59153:TCP:*:Enabled:Pando Media Booster
"59153:UDP" = 59153:UDP:*:Enabled:Pando Media Booster

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"58199:TCP" = 58199:TCP:*:Enabled:Pando Media Booster
"58199:UDP" = 58199:UDP:*:Enabled:Pando Media Booster
"59153:TCP" = 59153:TCP:*:Enabled:Pando Media Booster
"59153:UDP" = 59153:UDP:*:Enabled:Pando Media Booster
"5985:TCP" = 5985:TCP:*:Disabled:Windows Remote Management

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\system32\sessmgr.exe" = %windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019 -- (Microsoft Corporation)
"%windir%\Network Diagnostic\xpnetdiag.exe" = %windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000 -- (Microsoft Corporation)
"C:\Program Files\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe" = C:\Program Files\Microsoft Games\Dungeon Siege 2\DungeonSiege2.exe:*:Enabled:Dungeon Siege 2 Game Executable -- (Gas Powered Games)
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main -- (Obsidian Entertainment, Inc.)
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD -- (Obsidian Entertainment, Inc.)
"C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater -- (Obsidian Entertainment, Inc.)
"C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe" = C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server -- (Obsidian Entertainment, Inc.)
"C:\Program Files\Xfire\Xfire.exe" = C:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire -- (Xfire Inc.)
"C:\Program Files\EA SPORTS\Madden NFL 07\Updater.exe" = C:\Program Files\EA SPORTS\Madden NFL 07\Updater.exe:*:Enabled:Updater
"C:\Program Files\Ventrilo\Ventrilo.exe" = C:\Program Files\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe -- ()
"C:\Program Files\StarCraft II\StarCraft II.exe" = C:\Program Files\StarCraft II\StarCraft II.exe:*:Enabled:Blizzard Launcher -- (Blizzard Entertainment)
"C:\Program Files\Steam\SteamApps\common\amd driver updater, xp, 32 bit\Setup.exe" = C:\Program Files\Steam\SteamApps\common\amd driver updater, xp, 32 bit\Setup.exe:*:Enabled:AMD Driver Updater, XP, 32 bit -- (Advanced Micro Devices, Inc.)
"C:\NetmarbleGlobal\MarbleStation\nmgDownloader\nmgDownload.exe" = C:\NetmarbleGlobal\MarbleStation\nmgDownloader\nmgDownload.exe:*:Enabled:nmgDownLoad -- ()
"C:\Program Files\Steam\SteamApps\common\FEAR2\FEAR2.exe" = C:\Program Files\Steam\SteamApps\common\FEAR2\FEAR2.exe:*:Enabled:F.E.A.R. 2: Project Origin -- (Monolith Productions, Inc.)
"C:\Program Files\Pando Networks\Media Booster\PMB.exe" = C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Enabled:Pando Media Booster -- ()
"C:\Documents and Settings\John Richardson\Local Settings\Application Data\Akamai\netsession_win.exe" = C:\Documents and Settings\John Richardson\Local Settings\Application Data\Akamai\netsession_win.exe:*:Enabled:Akamai NetSession Client -- (Akamai Technologies, Inc.)
"C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1363\Agent.exe" = C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1363\Agent.exe:*:Enabled:Battle.net Update Agent
"C:\Program Files\Diablo III\Diablo III.exe" = C:\Program Files\Diablo III\Diablo III.exe:*:Enabled:Diablo III -- (Blizzard Entertainment)
"C:\Program Files\Steam\SteamApps\common\king's bounty - the legend\kb.exe" = C:\Program Files\Steam\SteamApps\common\king's bounty - the legend\kb.exe:*:Enabled:King's Bounty: The Legend -- ()
"C:\Program Files\Steam\SteamApps\common\king's bounty - the legend\save_fixer.exe" = C:\Program Files\Steam\SteamApps\common\king's bounty - the legend\save_fixer.exe:*:Enabled:King's Bounty: The Legend -- ()
"C:\Program Files\Steam\SteamApps\common\kings bounty armored princess\kb.exe" = C:\Program Files\Steam\SteamApps\common\kings bounty armored princess\kb.exe:*:Enabled:King's Bounty: Armored Princess -- ()
"C:\Program Files\Steam\SteamApps\common\kings bounty crossworlds\kb.exe" = C:\Program Files\Steam\SteamApps\common\kings bounty crossworlds\kb.exe:*:Enabled:King's Bounty: Crossworlds -- ()
"C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1544\Agent.exe" = C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1544\Agent.exe:*:Enabled:Battle.net Update Agent
"C:\Program Files\Steam\SteamApps\common\dungeon siege iii\Dungeon Siege III.exe" = C:\Program Files\Steam\SteamApps\common\dungeon siege iii\Dungeon Siege III.exe:*:Enabled:Dungeon Siege III -- (Obsidian Entertainment, Inc.)
"C:\Program Files\Steam\SteamApps\common\Carrier Command Gaea Mission demo\carrier_demo.exe" = C:\Program Files\Steam\SteamApps\common\Carrier Command Gaea Mission demo\carrier_demo.exe:*:Enabled:Carrier Command: Gaea Mission Demo -- (Bohemia Interactive)
"C:\Documents and Settings\John Richardson\Local Settings\Apps\2.0\RCMH2E3C.XKX\N6C0O9YD.PBO\curs..tion_9e9e83ddf3ed3ead_0005.0001_f88ee66177b243ac\CurseClient.exe" = C:\Documents and Settings\John Richardson\Local Settings\Apps\2.0\RCMH2E3C.XKX\N6C0O9YD.PBO\curs..tion_9e9e83ddf3ed3ead_0005.0001_f88ee66177b243ac\CurseClient.exe:*:Enabled:Curse Client 4.0 -- (Curse)
"C:\Program Files\Steam\SteamApps\common\Mafia II\pc\mafia2.exe" = C:\Program Files\Steam\SteamApps\common\Mafia II\pc\mafia2.exe:*:Enabled:Mafia II -- (2K Czech)
"C:\Games\World_of_Tanks\WorldOfTanks.exe" = C:\Games\World_of_Tanks\WorldOfTanks.exe:*:Enabled:World of Tanks -- (Wargaming.net)
"C:\Program Files\Steam\SteamApps\common\sid meier's civilization v\Launcher.exe" = C:\Program Files\Steam\SteamApps\common\sid meier's civilization v\Launcher.exe:*:Enabled:Sid Meier's Civilization V -- (Firaxis Games)
"C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1675\Agent.exe" = C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1675\Agent.exe:*:Enabled:Battle.net Update Agent -- (Blizzard Entertainment)
"C:\WINDOWS\system32\dxdiag.exe" = C:\WINDOWS\system32\dxdiag.exe:*:Enabled:Microsoft DirectX Diagnostic Tool -- (Microsoft Corporation)
"C:\WINDOWS\system32\dpnsvr.exe" = C:\WINDOWS\system32\dpnsvr.exe:*:Enabled:Microsoft DirectPlay8 Server -- (Microsoft Corporation)
"C:\Program Files\Cryptic Studios\Star Trek Online\Live\GameClient.exe" = C:\Program Files\Cryptic Studios\Star Trek Online\Live\GameClient.exe:*:Enabled:GameClient -- ()
"C:\Program Files\File Type Assistant\TSAssist.exe" = C:\Program Files\File Type Assistant\TSAssist.exe:*:Enabled:ProgramUpdateCheck -- (Trusted Software ApS)
"C:\Program Files\Wing Commander Saga Prologue\wcsaga.exe" = C:\Program Files\Wing Commander Saga Prologue\wcsaga.exe:*:Enabled:FreeSpace -- (Volition Inc.)
"C:\Program Files\Cryptic Studios\Neverwinter\Live\GameClient.exe" = C:\Program Files\Cryptic Studios\Neverwinter\Live\GameClient.exe:*:Enabled:GameClient -- ()
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater -- (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service -- (Safer-Networking Ltd.)
"C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1737\Agent.exe" = C:\Documents and Settings\All Users\Application Data\Battle.net\Agent\Agent.1737\Agent.exe:*:Enabled:Battle.net Update Agent -- (Blizzard Entertainment)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0394CDC8-FABD-4ed8-B104-03393876DFDF}" = Roxio Creator Tools
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0483D29D-A3B6-178F-6ED1-46EFBB780317}" = Catalyst Control Center
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0D397393-9B50-4c52-84D5-77E344289F87}" = Roxio Creator Data
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{10721C8A-8288-98DC-5322-6561C1FBCEFD}" = CCC Help Chinese Standard
"{12270803-2287-60C7-F010-73A35969FA9D}" = ccc-utility
"{1266764D-FC4F-4FA7-B63B-884D53B1680F}" = NetAssistant
"{1E71BCE7-5A58-BC8A-791F-7505851E0F77}" = CCC Help Finnish
"{1EAC1D02-C6AC-4FA6-9A44-96258C37C812NA}_is1" = World of Tanks
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22EC35BD-F8F2-45EB-8DCB-1C7FB65D0A71}" = QuickTax 2007
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{281ECE39-F043-492B-8337-F2E546B5604A}" = PowerDVD
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2E2E3707-873D-69AE-F7CD-ABDF2A8ADC7C}" = CCC Help Japanese
"{2E660A2A-A55F-43CD-9F73-CAD7382EEB78}" = Microsoft Games for Windows - LIVE Redistributable
"{2F4C24E6-CBD4-4AAC-B56F-C9FD44DE5668}" = Roxio Drag-to-Disc
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon Camera WIA Driver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}" = Sonic Activation Module
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DDE5D5A-E667-349B-3D67-EC46F4559CA2}" = CCC Help Thai
"{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}" = NVIDIA PhysX
"{4250CCCA-E916-2A8D-1728-0059007732A9}" = CCC Help Russian
"{428D44EE-A9C7-8FB7-7825-07D95B147541}" = CCC Help Spanish
"{468D22C0-8080-11E2-B86E-B8AC6F98CCE3}" = Google Earth
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4D3C9F4B-4B7D-4E5D-99B9-0123AB0D51ED}" = Dell DataSafe Online
"{4DAE1F80-ECD3-3F50-2D03-3061061DBCA5}" = CCC Help Korean
"{4FBC7CC9-BF92-6E6C-09EA-AEA5F6A0D4AF}" = CCC Help Czech
"{4FDC50F6-1FA2-D82D-5FF7-AF014AF3DA55}" = CCC Help English
"{5375EB06-E8E0-B2E8-E1B5-4EDC5D0A0DC0}" = CCC Help Swedish
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}" = Roxio Creator Copy
"{62230596-37E5-4618-A329-0D21F529A86F}" = Browser Address Error Redirector
"{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon Camera WIA Driver
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler
"{677E934A-07CD-AA1A-2D16-BE2FA04F2955}" = CCC Help English
"{67D9647A-6211-0EE0-38C1-20696FC45BA7}" = CCC Help Norwegian
"{6895B14D-FE34-502A-CF35-4BD7573F65B4}" = Catalyst Control Center InstallProxy
"{68F134EB-52E5-45CB-93D3-CE2A341004D0}" = Microsoft Project 2010 SDK [EN-US]
"{69E8BEA4-6E98-68CA-8C1A-8448DB9F4AD6}" = CCC Help Turkish
"{6A993CF8-9F86-59D0-89CD-C720B4C53086}" = CCC Help Italian
"{6ACE51D9-0C91-FF14-93B7-235D6E8BD4DC}" = CCC Help Hungarian
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{730E03E4-350E-48E5-9D3E-4329903D454D}" = Itibiti RTC
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{767CC44C-9BBC-438D-BAD3-FD4595DD148B}" = VC80CRTRedist - 8.0.50727.762
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7E6C16AE-58EC-F03C-1E22-C13AF3824808}" = CCC Help Portuguese
"{836F070A-0E66-4597-5129-4EA44F54576F}" = CCC Help Danish
"{83FFCFC7-88C6-41c6-8752-958A45325C82}" = Roxio Creator Audio
"{880AF49C-34F7-4285-A8AD-8F7A3D1C33DC}" = Roxio Creator BDAV Plugin
"{8921E7CF-F47B-781E-E7AA-653E2AB2FD5B}" = Catalyst Control Center Graphics Previews Common
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DAE4336-2B71-11D4-9A6C-006067325E47}" = Baldur's Gate™ II - Shadows of Amn™
"{91E9B920-0BA0-8020-496A-622AF456337F}" = AMD Catalyst Install Manager
"{93F6FB3E-5134-B63B-0771-D5B928EA4AD9}" = Catalyst Control Center Localization All
"{95120000-003F-0409-0000-0000000FF1CE}" = Microsoft Office Excel Viewer
"{9534FAC9-E04C-4B5A-871C-A52A783986DB}" = Netmarble Launcher
"{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III
"{974C4B12-4D02-4879-85E0-61C95CC63E9E}" = Fallout 3
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9FD43D69-2E42-0526-D65B-6C6B8FA6A2F6}" = Catalyst Control Center Graphics Previews Common
"{A0087DDE-69D0-11E2-AD57-43CA6188709B}" = Adobe AIR
"{A06275F4-324B-4E85-95E6-87B2CD729401}" = Windows Defender
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A477AB54-7C38-A981-9820-551B8A8E216C}" = CCC Help German
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9308032-8E26-12DC-8D1C-52DB78753660}" = CCC Help Chinese Traditional
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B737CA01-BC17-6F51-FEDD-84FDCA78B13B}" = ccc-utility
"{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon Camera WIA Driver
"{BC538EFE-A1CF-40A5-A6FE-36DDE76FA9E0}" = PingPlotter Standard 3.40.1s
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}" = Roxio Creator DE
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D639085F-4B6E-4105-9F37-A0DBB023E2FB}" = Roxio MyDVD DE
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D98C9637-93DA-44DB-B73A-B11A1192AB26}" = GameShadow
"{DE29025A-091F-4998-AD2D-24C84421190F}" = Railroad Tycoon 3
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E48F2277-3BA3-A179-F0B5-37DE6BD9390B}" = CCC Help Polish
"{EA5D6A8A-56FD-3732-AECF-5A4876A0B93A}" = CCC Help Greek
"{ECB9C58E-C565-4683-9599-B72290BD3B25}" = QuickTax 2009
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F112F66E-25CA-42DD-983C-6118EB38F606}" = Microsoft Games for Windows - LIVE
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F20C1251-1D0A-4944-B2AE-678581B33B19}" = Neverwinter Nights 2
"{F4521DC3-AED8-AEB6-9823-B90FB5AAF4B6}" = CCC Help Dutch
"{FA03C438-AA0B-409C-B90D-93C3CEB42859}" = Wing Commander Saga Prologue
"{FCC1A1DB-F3BC-3CAF-FCB1-B191167BAEA4}" = CCC Help French
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"82A44D22-9452-49FB-00FB-CEC7DCAF7E23" = EA SPORTS online 2007
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AI RoboForm" = avast! EasyPass
"Akamai" = Akamai NetSession Interface Service
"avast" = avast! Free Antivirus
"Blueline_is1" = Blueline 1.1.1
"CAL" = Canon Camera Access Library
"CameraWindowDVC5" = Canon Camera Window DC_DV 5 for ZoomBrowser EX
"CameraWindowDVC6" = Canon Camera Window DC_DV 6 for ZoomBrowser EX
"CameraWindowMC" = Canon Camera Window MC 6 for ZoomBrowser EX
"CCleaner" = CCleaner
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"CSCLIB" = Canon Camera Support Core Library
"Diablo II" = Diablo II
"Diablo III" = Diablo III
"Download Manager" = Download Manager 2.3.6
"DPP" = Canon Utilities Digital Photo Professional 3.0
"DungeonSiege2" = Dungeon Siege 2
"EOS Utility" = Canon Utilities EOS Utility
"ERUNT_is1" = ERUNT 1.1j
"ESET Online Scanner" = ESET Online Scanner v3
"FileHippo.com" = FileHippo.com Update Checker
"FreeApp v1" = FreeApps
"Game Booster_is1" = Game Booster
"HijackThis" = HijackThis 2.0.2
"hp deskjet 656c series" = hp deskjet 656c series (Remove only)
"hp deskjet 656c series_Driver" = hp deskjet 656c series
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InstallShield_{33CF7CDF-9805-4500-9CC7-D19D52AD63C4}" = Canon EOS Kiss_N REBEL_XT 350D WIA Driver
"InstallShield_{652C4ADF-0A29-4B02-9211-EE61675847DE}" = Canon EOS-1Ds Mark II WIA Driver
"InstallShield_{9720C029-0C2C-4D1E-9DE0-E89971C4C8C7}" = Silent Hunter III
"InstallShield_{BB3AB664-D92B-4CB5-8B3E-D841841F4E68}" = Canon EOS 5D WIA Driver
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Mozilla Firefox 21.0 (x86 en-US)" = Mozilla Firefox 21.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"Neverwinter" = Neverwinter
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"ODSK" = Canon Utilities Original Data Security Tools
"OpenAL" = OpenAL
"Origin" = Origin
"PC-Doctor for Windows" = Dell Support Center
"PhotoStitch" = Canon Utilities PhotoStitch
"PROSet" = Intel® PRO Network Connections Drivers
"Protected Folder_is1" = Protected Folder
"RAW Image Task" = Canon RAW Image Task for ZoomBrowser EX
"RemoteCaptureTask" = Canon RemoteCapture Task for ZoomBrowser EX
"SearchAssist" = SearchAssist
"Sexy Lingerie Catalog_is1" = Electronic Database v. 2.0
"Sid Meier's Alpha Centauri" = Sid Meier's Alpha Centauri
"Smart Defrag_is1" = Smart Defrag
"SpeedFan" = SpeedFan (remove only)
"SpywareBlaster_is1" = SpywareBlaster 5.0
"SpywareGuard_is1" = SpywareGuard v2.2
"Star Trek Online" = Star Trek Online
"StarCraft II" = StarCraft II
"Steam App 16450" = F.E.A.R. 2: Project Origin
"Steam App 211" = Source SDK
"Steam App 215" = Source SDK Base
"Steam App 220" = Half-Life 2
"Steam App 222700" = Carrier Command: Gaea Mission Demo
"Steam App 25900" = King's Bounty: The Legend
"Steam App 3170" = King's Bounty: Armored Princess
"Steam App 320" = Half-Life 2: Deathmatch
"Steam App 340" = Half-Life 2: Lost Coast
"Steam App 39160" = Dungeon Siege III
"Steam App 50130" = Mafia II
"Steam App 63910" = King's Bounty: Crossworlds
"Steam App 8930" = Sid Meier's Civilization V
"Trusted Software Assistant_is1" = File Type Assistant
"WFTK" = Canon Utilities WFT-E1/E2 Utility
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"Wise Registry Cleaner_is1" = Wise Registry Cleaner 7.63
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"ZoomBrowser EX" = Canon Utilities ZoomBrowser EX

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-879840139-2802958703-907680667-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"NetAssistant" = NetAssistant for Firefox
"soe-PlanetSide 2" = PlanetSide 2
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 14/02/2013 4:03:21 AM | Computer Name = PARENT | Source = LoadPerf | ID = 3011
Description = Unloading the performance counter strings for service ASP.NET_2.0.50727
(ASP.NET_2.0.50727) failed. The Error code is the first DWORD in Data section.

Error - 14/02/2013 4:03:23 AM | Computer Name = PARENT | Source = LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is incorrectly
formatted.
The bogus string is 17766, the bogus index value is the first DWORD in Data section
while the last valid index values are the second and third DWORD in Data section.

Error - 19/03/2013 5:27:09 PM | Computer Name = PARENT | Source = WmiAdapter | ID = 4099
Description = Open of service failed.

Error - 06/04/2013 2:40:20 PM | Computer Name = PARENT | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: PARENT\John Richardson Checkpoint ID: 1 Error Code: 0x80070005

Error
description: Access is denied.

Error - 06/04/2013 2:40:20 PM | Computer Name = PARENT | Source = WinDefendRtp | ID = 3003
Description = %%827 Real-Time Protection checkpoint has encountered an error and
failed to start. User: PARENT\John Richardson Checkpoint ID: 1 Error Code: 0x8000ffff

Error
description: Catastrophic failure

Error - 16/05/2013 3:32:17 AM | Computer Name = PARENT | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown

Error - 12/06/2013 1:52:18 AM | Computer Name = PARENT | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 80240016, P2 begininstall, P3 install, P4
1.1.1593.0, P5 mpsigdwn.dll, P6 1.1.1593.0, P7 windows defender, P8 NIL, P9 NIL,
P10 NIL.

Error - 19/06/2013 7:06:17 PM | Computer Name = PARENT | Source = Microsoft Fax | ID = 32045
Description = Fax Service failed to initialize because it could not initialize the
TAPI devices. Verify that the fax modem was installed and configured correctly. Win32
error code: -2147483576. This error code indicates the cause of the error.

Error - 20/06/2013 7:24:20 AM | Computer Name = PARENT | Source = Microsoft Fax | ID = 32045
Description = Fax Service failed to initialize because it could not initialize the
TAPI devices. Verify that the fax modem was installed and configured correctly. Win32
error code: -2147483576. This error code indicates the cause of the error.

Error - 20/06/2013 7:34:41 AM | Computer Name = PARENT | Source = Microsoft Fax | ID = 32045
Description = Fax Service failed to initialize because it could not initialize the
TAPI devices. Verify that the fax modem was installed and configured correctly. Win32
error code: -2147483576. This error code indicates the cause of the error.

[ System Events ]
Error - 21/06/2013 6:43:44 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep

Error - 21/06/2013 6:52:09 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7023
Description = The Akamai NetSession Interface service terminated with the following
error: %%126

Error - 21/06/2013 6:52:09 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security
Center Service service to connect.

Error - 21/06/2013 6:52:09 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7000
Description = The Spybot-S&D 2 Security Center Service service failed to start due
to the following error: %%1053

Error - 21/06/2013 6:52:09 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7000
Description = The SupportSoft Sprocket Service (dellsupportcenter) service failed
to start due to the following error: %%2

Error - 21/06/2013 7:04:41 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7023
Description = The Akamai NetSession Interface service terminated with the following
error: %%126

Error - 21/06/2013 7:04:41 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7009
Description = Timeout (30000 milliseconds) waiting for the Spybot-S&D 2 Security
Center Service service to connect.

Error - 21/06/2013 7:04:41 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7000
Description = The Spybot-S&D 2 Security Center Service service failed to start due
to the following error: %%1053

Error - 21/06/2013 7:04:41 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7000
Description = The SupportSoft Sprocket Service (dellsupportcenter) service failed
to start due to the following error: %%2

Error - 21/06/2013 7:04:41 PM | Computer Name = PARENT | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Beep


< End of report >


C:\Documents and Settings\John Richardson\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\28\60f210dc-48ba4a71 multiple threats cleaned by deleting - quarantined
C:\Documents and Settings\John Richardson\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\4\4316fb04-6e958830 multiple threats cleaned by deleting - quarantined
C:\Documents and Settings\John Richardson\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\45\3c2de5ed-636855c9 multiple threats cleaned by deleting - quarantined
C:\Documents and Settings\John Richardson\Local Settings\Application Data\Sun\Java\Deployment\cache\6.0\5\72912385-55341822 Java/Exploit.Agent.NQR trojan cleaned by deleting - quarantined
C:\Documents and Settings\John Richardson\My Documents\Downloads\FreeFileViewer2011Setup.exe a variant of Win32/InstallIQ.A application cleaned by deleting - quarantined
C:\Documents and Settings\John Richardson\My Documents\Downloads\gamebooster(2).exe Win32/Toolbar.Widgi application cleaned by deleting - quarantined
C:\Documents and Settings\John Richardson\My Documents\Downloads\prologue_setup.exe.exe a variant of Win32/DownloadSponsor.A application cleaned by deleting - quarantined
C:\Documents and Settings\Kristi Richardson\Desktop\CouponPrinter.exe probably a variant of Win32/Adware.Softomate.AD application cleaned by deleting - quarantined
C:\Program Files\FreeApps\FreeApps.exe probably a variant of Win32/FreeNew application cleaned by deleting - quarantined
C:\RECYCLER\S-1-5-21-879840139-2802958703-907680667-1005\Dc9.exe a variant of Win32/ELEX application cleaned by deleting - quarantined
  • 0

Advertisements


#2
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello Ardant

I would like to welcome you to the Malware Removal section of the forum.

Around here they call me Gringo and I will be glad to help you with your malware problems.


Very Important --> Please read this post completely, I have spent my time to put together somethings for you to keep in mind while I am helping you to make things go easier, faster and smoother for both of us!


  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the "Follow This Topic" Button, make sure that the "Receive notification" box is checked and that it is set to "Instantly" - This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.


These are the programs I would like you to run next, if you have any problems with one of these just skip it and move on to the next one.

-AdwCleaner-

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

-Junkware-Removal-Tool-

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

When they are complete let me have the two reports and let me know how things are running.

Gringo
  • 0

#3
Ardant

Ardant

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 229 posts
I have run the programs as requested. The two online programs that were not working are still not working. Other than that the computer seems to be working fine. Any thoughts?

# AdwCleaner v2.303 - Logfile created 06/23/2013 at 08:53:25
# Updated 08/06/2013 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : John Richardson - PARENT
# Boot Mode : Normal
# Running from : C:\Documents and Settings\John Richardson\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v21.0 (en-US)

File : C:\Documents and Settings\John Richardson\Application Data\Mozilla\Firefox\Profiles\zy5758f9.default\prefs.js

[OK] File is clean.

File : C:\Documents and Settings\Kristi Richardson\Application Data\Mozilla\Firefox\Profiles\9nk0dnxl.default\prefs.js

[OK] File is clean.

File : C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\zk1rsv59.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Documents and Settings\John Richardson\Local Settings\Application Data\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [19857 octets] - [19/03/2013 17:22:23]
AdwCleaner[S2].txt - [2182 octets] - [12/05/2013 09:23:18]
AdwCleaner[S3].txt - [2398 octets] - [08/06/2013 22:52:12]
AdwCleaner[S4].txt - [1761 octets] - [21/06/2013 18:49:18]
AdwCleaner[S5].txt - [1692 octets] - [23/06/2013 08:53:25]

########## EOF - C:\AdwCleaner[S5].txt - [1752 octets] ##########

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.9.4 (05.06.2013:1)
OS: Microsoft Windows XP x86
Ran by John Richardson on 23/06/2013 at 9:11:07.07
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



~~~ Registry Keys



~~~ Files

Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll



~~~ Folders



~~~ FireFox

Successfully deleted: [File] C:\Documents and Settings\John Richardson\Application Data\mozilla\firefox\profiles\zy5758f9.default\invalidprefs.js
Successfully deleted the following from C:\Documents and Settings\John Richardson\Application Data\mozilla\firefox\profiles\zy5758f9.default\prefs.js

user_pref("extensions.crossrider.bic", "139b282983d1dd4eaba7f743f912dd4a");
user_pref("extensions.defaulttab.active.affiliate", 4501);
user_pref("extensions.defaulttab.active.overridechromesearch", false);
user_pref("extensions.defaulttab.active.overridekeywordsearch", false);
user_pref("extensions.defaulttab.browserID", "01ff8583858e9df66ff0b05664ee4fb1");
user_pref("extensions.defaulttab.firstrun", false);
user_pref("extensions.defaulttab.installedVersion", "1.4.2");
user_pref("extensions.defaulttab.lastUsed", 1347933591);





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 23/06/2013 at 9:13:44.90
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

#4
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello Ardant

I Would like you to do the following.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
  • 0

#5
Ardant

Ardant

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 229 posts
I had no problems running Combofix. Combofix claims that I have AVG Security 2012 on my computer but I don't so I ignored the warnings. The 2 Online games still do not run. I get a system Tray icon and at the bottomm of the screen it looks like the programs are running but no window opens. Task manager says it is there but no log in screen.

Here is the Combofix log.

ComboFix 13-06-22.01 - John Richardson 23/06/2013 9:40.6.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2450 [GMT -4:00]
Running from: c:\documents and settings\John Richardson\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Internet Security 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Internet Security 2012 *Enabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\PCDr\6032\AddOnDownloaded\1e512ef2-01fb-49fb-b09b-71de0eac4612.dll
c:\documents and settings\All Users\Application Data\PCDr\6032\AddOnDownloaded\27ada864-54d8-46c9-a6e3-8334fa39b525.dll
c:\documents and settings\All Users\Application Data\PCDr\6032\AddOnDownloaded\b69d9551-76e9-4872-95f8-075916f82d74.dll
c:\documents and settings\John Richardson\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2013-05-23 to 2013-06-23 )))))))))))))))))))))))))))))))
.
.
2013-06-23 13:11 . 2013-06-23 13:11 -------- d-----w- c:\windows\ERUNT
2013-06-23 13:10 . 2013-06-23 13:11 -------- d-----w- C:\JRT
2013-06-21 23:04 . 2013-06-21 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2013-06-21 23:00 . 2012-05-14 06:12 103040 ----a-w- c:\windows\system32\drivers\AtihdXP3.sys
2013-06-21 22:59 . 2013-06-21 23:01 -------- d---a-w- c:\program files\ATI Technologies
2013-06-21 22:59 . 2013-06-21 22:59 -------- d---a-w- c:\program files\ATI
2013-06-21 22:58 . 2013-06-21 22:58 -------- d---a-w- C:\AMD
2013-06-21 06:09 . 2013-06-12 04:18 7068072 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{036CA63A-9833-45DE-8AD6-3EACAF5654CF}\mpengine.dll
2013-06-21 00:10 . 2013-06-21 00:10 -------- d---a-w- c:\program files\ESET
2013-06-20 03:03 . 2013-06-20 03:03 22064 ----a-w- c:\windows\DCEBoot.exe
2013-06-19 22:49 . 2013-06-19 22:49 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-06-19 22:49 . 2013-06-19 22:49 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-19 22:49 . 2013-06-19 22:49 -------- d-----w- c:\program files\Java
2013-06-13 00:36 . 2009-01-25 17:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
2013-05-25 13:53 . 2013-05-11 22:27 262552 ----a-w- c:\program files\Mozilla Firefox\browser\components\browsercomps.dll
2013-05-25 13:38 . 2013-05-09 08:59 21576 ----a-w- c:\windows\system32\drivers\aswKbd.sys
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-19 22:49 . 2012-09-22 22:21 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-19 22:49 . 2011-10-28 22:44 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-12 04:18 . 2013-01-05 18:08 7068072 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-06-12 00:59 . 2012-04-05 01:15 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-12 00:59 . 2011-06-05 22:48 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-05-09 08:59 . 2013-03-18 20:50 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-05-09 08:59 . 2013-03-18 20:50 174664 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-05-09 08:59 . 2012-10-16 23:30 368944 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-05-09 08:59 . 2012-10-16 23:30 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-05-09 08:59 . 2012-10-16 23:30 765736 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-05-09 08:59 . 2013-03-18 20:49 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-05-09 08:59 . 2012-10-16 23:30 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-05-09 08:59 . 2012-10-16 23:30 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-05-09 08:58 . 2012-10-16 23:29 41664 ----a-w- c:\windows\avastSS.scr
2013-05-09 08:58 . 2012-10-16 23:29 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-05-07 22:30 . 2004-08-11 22:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-05-07 22:30 . 2004-08-11 22:00 43520 ------w- c:\windows\system32\licmgr10.dll
2013-05-07 22:30 . 2004-08-11 22:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2004-08-11 22:00 385024 ------w- c:\windows\system32\html.iec
2013-05-03 01:30 . 2004-08-11 22:00 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 2004-08-04 03:59 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 06:06 . 2013-01-05 18:08 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-20 00:13 . 2013-04-20 00:13 86016 ----a-w- c:\windows\system32\OpenAL32.dll
2013-04-20 00:13 . 2013-04-20 00:13 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2013-04-10 01:31 . 2004-08-11 22:00 1876352 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 18:50 . 2012-06-02 14:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-02 05:36 . 2012-06-03 17:36 44 ---h--w- c:\program files\d81f0199.tmp
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-05-14 1103216]
"Akamai NetSession Interface"="c:\documents and settings\John Richardson\Local Settings\Application Data\Akamai\netsession_win.exe" [2013-01-26 4480768]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-12-29 96056]
"Steam"="c:\program files\Steam\Steam.exe" [2013-06-06 1641896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-15 196608]
"RTHDCPL"="RTHDCPL.EXE" [2008-01-09 16859648]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-05-16 3830224]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-16 98304]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk.disabled [2008-11-10 767]
.
c:\documents and settings\John Richardson\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2013-3-21 3560832]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean.exe\0aswBoot.exe /A:* /A:C: /A:*STARTUP-SHORT /A:*STARTUP /L:1033 /heur:100 /RA:chest /pup /archives /IA:0 /KBD:2 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MarbleStation"=c:\netmarbleglobal\MarbleStation\GlbMSLauncher.exe
"AVG PC Tuneup"="c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe" -UseTray
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\amd driver updater, xp, 32 bit\\Setup.exe"=
"c:\\NetmarbleGlobal\\MarbleStation\\nmgDownloader\\nmgDownload.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\FEAR2\\FEAR2.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\John Richardson\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Diablo III\\Diablo III.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\king's bounty - the legend\\kb.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\king's bounty - the legend\\save_fixer.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\kings bounty armored princess\\kb.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\kings bounty crossworlds\\kb.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\dungeon siege iii\\Dungeon Siege III.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\Carrier Command Gaea Mission demo\\carrier_demo.exe"=
"c:\\Documents and Settings\\John Richardson\\Local Settings\\Apps\\2.0\\RCMH2E3C.XKX\\N6C0O9YD.PBO\\curs..tion_9e9e83ddf3ed3ead_0005.0001_f88ee66177b243ac\\CurseClient.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\Mafia II\\pc\\mafia2.exe"=
"c:\\Games\\World_of_Tanks\\WorldOfTanks.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\sid meier's civilization v\\Launcher.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Battle.net\\Agent\\Agent.1675\\Agent.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Cryptic Studios\\Star Trek Online\\Live\\GameClient.exe"=
"c:\\Program Files\\File Type Assistant\\TSAssist.exe"=
"c:\\Program Files\\Wing Commander Saga Prologue\\wcsaga.exe"=
"c:\\Program Files\\Cryptic Studios\\Neverwinter\\Live\\GameClient.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Battle.net\\Agent\\Agent.1737\\Agent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58199:TCP"= 58199:TCP:Pando Media Booster
"58199:UDP"= 58199:UDP:Pando Media Booster
"59153:TCP"= 59153:TCP:Pando Media Booster
"59153:UDP"= 59153:UDP:Pando Media Booster
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"1092:TCP"= 1092:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [18/03/2013 4:50 PM 49376]
R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [18/03/2013 4:50 PM 174664]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [25/05/2013 9:38 AM 21576]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [16/10/2012 7:30 PM 765736]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [16/10/2012 7:30 PM 368944]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [16/10/2012 7:30 PM 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [18/03/2013 4:49 PM 66336]
R2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [12/06/2013 8:36 PM 1817560]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [12/06/2013 8:36 PM 1033688]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 8:19 PM 13592]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [21/06/2013 7:00 PM 103040]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [11/08/2004 6:00 PM 14336]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [12/06/2013 8:36 PM 171928]
S3 aaudstum;aaudstum;\??\c:\docume~1\JOHNRI~1\LOCALS~1\Temp\aaudstum.sys --> c:\docume~1\JOHNRI~1\LOCALS~1\Temp\aaudstum.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\Dell Support Center\pcdsrvc.pkms [04/09/2012 1:54 AM 22640]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - SPEEDFAN
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-23 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 00:59]
.
2013-06-23 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-10-16 08:58]
.
2013-06-23 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2013-06-13 14:58]
.
2013-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-16 23:30]
.
2013-06-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-16 23:30]
.
2013-06-23 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
2013-06-11 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-09-19 03:48]
.
2013-06-23 c:\windows\Tasks\ProgramRefresh-ATFST.job
- c:\program files\File Type Assistant\TSASetup.exe [2013-01-08 00:48]
.
2013-06-23 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2011-03-27 17:09]
.
2013-06-19 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2013-06-13 14:57]
.
2013-06-13 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2013-06-13 14:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = localhost:21320
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://ca.search.yahoo.com/search?fr=mcafee&p=%s
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Show avast! EasyPass Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: soe.com
Trusted Zone: sony.com
Trusted Zone: worldoftanks.com
TCP: DhcpNameServer = 64.71.255.204 64.71.255.198
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
FF - ProfilePath - c:\documents and settings\John Richardson\Application Data\Mozilla\Firefox\Profiles\zy5758f9.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
Notify-SDWinLogon - SDWinLogon.dll
AddRemove-FreeApp v1 - c:\program files\FreeApps\FreeApps.exe
AddRemove-Game Booster_is1 - c:\program files\IObit\Game Booster\unins000.exe
AddRemove-Protected Folder_is1 - c:\program files\IObit\Protected Folder\unins000.exe
AddRemove-Sexy Lingerie Catalog_is1 - c:\program files\AAS\Database Catalog 2.0\unins000.exe
AddRemove-Smart Defrag_is1 - c:\program files\IObit\IObit SmartDefrag\unins000.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-23 09:47
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_80c2ffa.dll"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-879840139-2802958703-907680667-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:64,5f,aa,30,64,48,a5,e2,9f,c3,01,ee,47,f7,9e,7e,11,7d,de,3f,53,e3,61,
65,b7,0a,a4,67,96,3d,f0,d2,33,47,2f,b8,2d,b6,f7,26,49,ca,63,67,c0,74,0f,5b,\
"??"=hex:af,4b,db,31,8c,18,8b,1f,0f,e7,56,55,e3,4a,d7,19
.
[HKEY_USERS\S-1-5-21-879840139-2802958703-907680667-1005\Software\SecuROM\License information*]
"datasecu"=hex:79,3e,8d,fc,be,fb,61,b0,6d,87,b2,94,0d,99,ea,c1,09,89,90,16,35,
eb,c5,40,6c,5e,13,b8,a8,26,42,9a,f9,df,36,c4,46,b3,69,ce,a3,60,e4,b5,48,4f,\
"rkeysecu"=hex:a3,57,c4,0d,f8,95,92,51,5f,05,99,76,7c,43,56,19
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
Completion time: 2013-06-23 09:50:55
ComboFix-quarantined-files.txt 2013-06-23 13:50
.
Pre-Run: 63,325,102,080 bytes free
Post-Run: 63,287,627,776 bytes free
.
- - End Of File - - BC20A7965802984D4A798B8EAF843274
5CB90281D1A59B251F6603134774EEC3
  • 0

#6
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello Ardant

Which are the games that are not working? Can you send me links to them?

I would like to see a report that combofix makes.

extra combofix report

  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box
C:\Qoobox\Add-Remove Programs.txt
  • click ok

copy and paste the report into this topic for me to review

Gringo
  • 0

#7
Ardant

Ardant

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 229 posts
Extra Combo Report

Acrobat.com
Adobe AIR
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader XI (11.0.03)
Akamai NetSession Interface
Akamai NetSession Interface Service
AMD Catalyst Install Manager
avast! EasyPass
avast! Free Antivirus
Baldur's Gate™ II - Shadows of Amn™
Blueline 1.1.1
Browser Address Error Redirector
Canon Camera Access Library
Canon Camera Support Core Library
Canon Camera WIA Driver
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon EOS-1Ds Mark II WIA Driver
Canon EOS 5D WIA Driver
Canon EOS Kiss_N REBEL_XT 350D WIA Driver
Canon RAW Image Task for ZoomBrowser EX
Canon RemoteCapture Task for ZoomBrowser EX
Canon Utilities Digital Photo Professional 3.0
Canon Utilities EOS Utility
Canon Utilities Original Data Security Tools
Canon Utilities PhotoStitch
Canon Utilities WFT-E1/E2 Utility
Canon Utilities ZoomBrowser EX
Carrier Command: Gaea Mission Demo
Catalyst Control Center
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
ccc-utility
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCC Help Turkish
CCleaner
Dell DataSafe Online
Dell Driver Reset Tool
Dell Support Center
Dell System Restore
Diablo II
Diablo III
Download Manager 2.3.6
Dungeon Siege 2
Dungeon Siege III
EA SPORTS online 2007
Electronic Database v. 2.0
ERUNT 1.1j
ESET Online Scanner v3
F.E.A.R. 2: Project Origin
Fallout 3
File Type Assistant
FileHippo.com Update Checker
FreeApps
Game Booster
GameShadow
Google Earth
Google Update Helper
Half-Life 2
Half-Life 2: Deathmatch
Half-Life 2: Lost Coast
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows XP (KB2756822)
Hotfix for Windows XP (KB2779562)
Hotfix for Windows XP (KB942288-v3)
hp deskjet 656c series
hp deskjet 656c series (Remove only)
Intel® PRO Network Connections Drivers
Itibiti RTC
Java 7 Update 25
Java Auto Updater
King's Bounty: Armored Princess
King's Bounty: Crossworlds
King's Bounty: The Legend
Mafia II
Malwarebytes Anti-Malware version 1.75.0.1300
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2742597)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Extended
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Games for Windows - LIVE
Microsoft Games for Windows - LIVE Redistributable
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office Excel Viewer
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Project 2010 SDK [EN-US]
Microsoft Silverlight
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Works
Microsoft XML Parser
Microsoft XNA Framework Redistributable 4.0
Mozilla Firefox 21.0 (x86 en-US)
Mozilla Maintenance Service
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
NetAssistant
NetAssistant for Firefox
Netmarble Launcher
Neverwinter
Neverwinter Nights 2
NVIDIA PhysX
OpenAL
OpenOffice.org Installer 1.0
Origin
Pando Media Booster
PingPlotter Standard 3.40.1s
PlanetSide 2
PowerDVD
Protected Folder
QuickTax 2007
QuickTax 2008
QuickTax 2009
Railroad Tycoon 3
Realtek High Definition Audio Driver
Roxio Creator Audio
Roxio Creator BDAV Plugin
Roxio Creator Copy
Roxio Creator Data
Roxio Creator DE
Roxio Creator Tools
Roxio Drag-to-Disc
Roxio Express Labeler
Roxio MyDVD DE
Roxio Update Manager
SearchAssist
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2804576)
Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
Security Update for Microsoft .NET Framework 4 Extended (KB2656351)
Security Update for Microsoft .NET Framework 4 Extended (KB2742595)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2761465)
Security Update for Windows Internet Explorer 8 (KB2792100)
Security Update for Windows Internet Explorer 8 (KB2797052)
Security Update for Windows Internet Explorer 8 (KB2799329)
Security Update for Windows Internet Explorer 8 (KB2809289)
Security Update for Windows Internet Explorer 8 (KB2817183)
Security Update for Windows Internet Explorer 8 (KB2829530)
Security Update for Windows Internet Explorer 8 (KB2838727)
Security Update for Windows Internet Explorer 8 (KB2847204)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2724197)
Security Update for Windows XP (KB2727528)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB2753842-v2)
Security Update for Windows XP (KB2753842)
Security Update for Windows XP (KB2757638)
Security Update for Windows XP (KB2758857)
Security Update for Windows XP (KB2761226)
Security Update for Windows XP (KB2770660)
Security Update for Windows XP (KB2778344)
Security Update for Windows XP (KB2779030)
Security Update for Windows XP (KB2780091)
Security Update for Windows XP (KB2799494)
Security Update for Windows XP (KB2802968)
Security Update for Windows XP (KB2807986)
Security Update for Windows XP (KB2808735)
Security Update for Windows XP (KB2813170)
Security Update for Windows XP (KB2813345)
Security Update for Windows XP (KB2820197)
Security Update for Windows XP (KB2820917)
Security Update for Windows XP (KB2829361)
Security Update for Windows XP (KB2839229)
Sid Meier's Alpha Centauri
Sid Meier's Civilization V
Silent Hunter III
Smart Defrag
Sonic Activation Module
Source SDK
Source SDK Base
SpeedFan (remove only)
Spybot - Search & Destroy
SpywareBlaster 5.0
SpywareGuard v2.2
Star Trek Online
StarCraft II
Steam
Unity Web Player
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Windows XP (KB2661254-v2)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB2749655)
VC80CRTRedist - 8.0.50727.762
Ventrilo Client
WebFldrs XP
Windows Defender
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 11
Windows XP Service Pack 3
Wing Commander Saga Prologue
Wise Registry Cleaner 7.63
World of Tanks
Xfire (remove only)

Both programs are by Cryptic Studios.

Star Trek Online
Neverwinter Online

As I was playing these games when all heck broke loose it is possible that the log in is corrupted and needs to be reinstalled.
  • 0

#8
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello


first lets update flash and see if that helps - http://get.adobe.com/flashplayer/

if that does not work then try reinstalling the games


Gringo
  • 0

#9
Ardant

Ardant

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 229 posts
Hey Gringo

Reinstalling the Flash did not help. I have deleted the program and then ran into several difficulties trying to download the program. The download kept locking up. It locked up because of Avast and Spybot. I ended up having to turn off Avast and Spybot and then it locked up after the screensaver engaged so I had to keep moving my mouse around so I figured I would play solitaire while I did the download but the download locked up again. Basically I just sat there and moved my mouse until the download and installation finished. What a pain. Could this be an issue with Cryptic or an internet problem that was caused by whatever I had?
  • 0

#10
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello Ardant

I would like you to try and run these next.

TDSSKiller

Please download the latest version of TDSSKiller from here and save it to your Desktop.
  • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
  • Put a checkmark beside loaded modules.
  • A reboot will be needed to apply the changes. Do it.
  • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
  • Then click on Change parameters in TDSSKiller.
  • Check all boxes then click OK.
  • Click the Start Scan button.
  • The scan should take no longer than 2 minutes.
  • If a suspicious object is detected, the default action will be Skip, click on Continue.
  • If malicious objects are found, they will show in the Scan results
  • Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.
    Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
  • more than one report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". The one that I need is the larger one. Please copy and paste the contents of that file here.

    Note** this report can be very long - so if the website gives you an error saying it is to long you may attache it

    If the forum still complains about it being to long send me everything that is at the end of the report after where it says

    ==================
    Scan finished
    ==================

and I will see if I want to see the whole report

--RogueKiller--

Download & SAVE to your Desktop RogueKiller for 32bit or Roguekiller for 64bit
  • Quit all programs that you may have started.
  • Please disconnect any external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • the scan will make two reports the one I would like to see is called RKreport[2].txt on your Desktop
  • Exit/Close RogueKiller+

send me the reports made from TDSSKiller and Roguekiller and also let me know how the computer is doing at this time.

Gringo
  • 0

Advertisements


#11
Ardant

Ardant

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 229 posts
18:43:20.0250 1828 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
18:43:21.0390 1828 ============================================================
18:43:21.0390 1828 Current date / time: 2013/06/25 18:43:21.0390
18:43:21.0390 1828 SystemInfo:
18:43:21.0390 1828
18:43:21.0390 1828 OS Version: 5.1.2600 ServicePack: 3.0
18:43:21.0390 1828 Product type: Workstation
18:43:21.0390 1828 ComputerName: PARENT
18:43:21.0390 1828 UserName: John Richardson
18:43:21.0390 1828 Windows directory: C:\WINDOWS
18:43:21.0390 1828 System windows directory: C:\WINDOWS
18:43:21.0390 1828 Processor architecture: Intel x86
18:43:21.0390 1828 Number of processors: 2
18:43:21.0390 1828 Page size: 0x1000
18:43:21.0390 1828 Boot type: Normal boot
18:43:21.0390 1828 ============================================================
18:43:52.0765 1828 BG loaded
18:43:55.0015 1828 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
18:45:14.0359 1828 ============================================================
18:45:14.0359 1828 \Device\Harddisk0\DR0:
18:45:42.0687 1828 MBR partitions:
18:45:42.0687 1828 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1B747, BlocksNum 0x24D7788B
18:45:42.0687 1828 ============================================================
18:45:46.0937 1828 C: <-> \Device\Harddisk0\DR0\Partition1
18:45:46.0937 1828 ============================================================
18:45:46.0937 1828 Initialize success
18:45:46.0937 1828 ============================================================
18:49:45.0312 0404 ============================================================
18:49:45.0312 0404 Scan started
18:49:45.0312 0404 Mode: Manual; SigCheck; TDLFS;
18:49:45.0312 0404 ============================================================
18:49:47.0671 0404 ================ Scan system memory ========================
18:49:47.0671 0404 System memory - ok
18:49:47.0671 0404 ================ Scan services =============================
18:49:48.0046 0404 aaudstum - ok
18:49:48.0375 0404 Abiosdsk - ok
18:49:48.0390 0404 [ 6ABB91494FE6C59089B9336452AB2EA3 ] abp480n5 C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS
18:49:48.0968 0404 abp480n5 - ok
18:49:49.0140 0404 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI C:\WINDOWS\system32\DRIVERS\ACPI.sys
18:49:49.0375 0404 ACPI - ok
18:49:49.0406 0404 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC C:\WINDOWS\system32\drivers\ACPIEC.sys
18:49:49.0515 0404 ACPIEC - ok
18:49:49.0609 0404 [ 9915504F602D277EE47FD843A677FD15 ] AdobeFlashPlayerUpdateSvc C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:49:49.0656 0404 AdobeFlashPlayerUpdateSvc - ok
18:49:49.0687 0404 [ 9A11864873DA202C996558B2106B0BBC ] adpu160m C:\WINDOWS\system32\DRIVERS\adpu160m.sys
18:49:49.0828 0404 adpu160m - ok
18:49:49.0859 0404 [ 8BED39E3C35D6A489438B8141717A557 ] aec C:\WINDOWS\system32\drivers\aec.sys
18:49:49.0953 0404 aec - ok
18:49:50.0015 0404 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] AFD C:\WINDOWS\System32\drivers\afd.sys
18:49:50.0031 0404 AFD - ok
18:49:50.0093 0404 [ 08FD04AA961BDC77FB983F328334E3D7 ] agp440 C:\WINDOWS\system32\DRIVERS\agp440.sys
18:49:50.0203 0404 agp440 - ok
18:49:50.0203 0404 [ 03A7E0922ACFE1B07D5DB2EEB0773063 ] agpCPQ C:\WINDOWS\system32\DRIVERS\agpCPQ.sys
18:49:50.0296 0404 agpCPQ - ok
18:49:50.0312 0404 [ C23EA9B5F46C7F7910DB3EAB648FF013 ] Aha154x C:\WINDOWS\system32\DRIVERS\aha154x.sys
18:49:50.0453 0404 Aha154x - ok
18:49:50.0453 0404 [ 19DD0FB48B0C18892F70E2E7D61A1529 ] aic78u2 C:\WINDOWS\system32\DRIVERS\aic78u2.sys
18:49:50.0562 0404 aic78u2 - ok
18:49:50.0562 0404 [ B7FE594A7468AA0132DEB03FB8E34326 ] aic78xx C:\WINDOWS\system32\DRIVERS\aic78xx.sys
18:49:50.0656 0404 aic78xx - ok
18:49:50.0781 0404 Akamai - ok
18:49:50.0812 0404 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter C:\WINDOWS\system32\alrsvc.dll
18:49:50.0921 0404 Alerter - ok
18:49:50.0953 0404 [ 8C515081584A38AA007909CD02020B3D ] ALG C:\WINDOWS\System32\alg.exe
18:49:51.0046 0404 ALG - ok
18:49:51.0062 0404 [ 1140AB9938809700B46BB88E46D72A96 ] AliIde C:\WINDOWS\system32\DRIVERS\aliide.sys
18:49:51.0140 0404 AliIde - ok
18:49:51.0187 0404 [ CB08AED0DE2DD889A8A820CD8082D83C ] alim1541 C:\WINDOWS\system32\DRIVERS\alim1541.sys
18:49:51.0265 0404 alim1541 - ok
18:49:51.0265 0404 [ 95B4FB835E28AA1336CEEB07FD5B9398 ] amdagp C:\WINDOWS\system32\DRIVERS\amdagp.sys
18:49:51.0390 0404 amdagp - ok
18:49:51.0421 0404 [ 79F5ADD8D24BD6893F2903A3E2F3FAD6 ] amsint C:\WINDOWS\system32\DRIVERS\amsint.sys
18:49:51.0468 0404 amsint - ok
18:49:51.0500 0404 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt C:\WINDOWS\System32\appmgmts.dll
18:49:51.0578 0404 AppMgmt - ok
18:49:51.0609 0404 [ 62D318E9A0C8FC9B780008E724283707 ] asc C:\WINDOWS\system32\DRIVERS\asc.sys
18:49:51.0718 0404 asc - ok
18:49:51.0718 0404 [ 69EB0CC7714B32896CCBFD5EDCBEA447 ] asc3350p C:\WINDOWS\system32\DRIVERS\asc3350p.sys
18:49:51.0765 0404 asc3350p - ok
18:49:51.0781 0404 [ 5D8DE112AA0254B907861E9E9C31D597 ] asc3550 C:\WINDOWS\system32\DRIVERS\asc3550.sys
18:49:51.0890 0404 asc3550 - ok
18:49:52.0031 0404 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
18:49:52.0062 0404 aspnet_state - ok
18:49:52.0093 0404 [ 4AF5F360BA1E8794D32B366E45A64A0A ] aswFsBlk C:\WINDOWS\system32\drivers\aswFsBlk.sys
18:49:52.0140 0404 aswFsBlk - ok
18:49:52.0156 0404 [ 3FCA5C1A8F33CF9857220CC3A3076A3E ] aswKbd C:\WINDOWS\system32\drivers\aswKbd.sys
18:49:52.0171 0404 aswKbd - ok
18:49:52.0203 0404 [ 1F7094D4268D46F718C51286DC189791 ] aswMonFlt C:\WINDOWS\system32\drivers\aswMonFlt.sys
18:49:52.0218 0404 aswMonFlt - ok
18:49:52.0234 0404 [ 7B43265F92257A21CBFD88E7A651044C ] AswRdr C:\WINDOWS\system32\drivers\AswRdr.sys
18:49:52.0250 0404 AswRdr - ok
18:49:52.0265 0404 [ B680134BA1813B78B47FDD1DFF223CA5 ] aswRvrt C:\WINDOWS\system32\drivers\aswRvrt.sys
18:49:52.0281 0404 aswRvrt - ok
18:49:52.0328 0404 [ 6CAB0A5991C5C0FC63F5E66593E71D7E ] aswSnx C:\WINDOWS\system32\drivers\aswSnx.sys
18:49:52.0359 0404 aswSnx - ok
18:49:52.0406 0404 [ 99102F60F344BEBAF4F6114514FD28D3 ] aswSP C:\WINDOWS\system32\drivers\aswSP.sys
18:49:52.0421 0404 aswSP - ok
18:49:52.0453 0404 [ 1F71F170D90E42EFDE9633D81D5E12DC ] aswTdi C:\WINDOWS\system32\drivers\aswTdi.sys
18:49:52.0468 0404 aswTdi - ok
18:49:52.0515 0404 [ 16B8E3CD50A460EC32CA680C8210A0A9 ] aswVmm C:\WINDOWS\system32\drivers\aswVmm.sys
18:49:52.0531 0404 aswVmm - ok
18:49:52.0562 0404 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac C:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:49:52.0671 0404 AsyncMac - ok
18:49:52.0687 0404 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi C:\WINDOWS\system32\DRIVERS\atapi.sys
18:49:52.0796 0404 atapi - ok
18:49:52.0796 0404 Atdisk - ok
18:49:53.0031 0404 [ 43E17DA549BC8219EEE90AA9C6480AAA ] Ati HotKey Poller C:\WINDOWS\system32\Ati2evxx.exe
18:49:53.0234 0404 Ati HotKey Poller - ok
18:49:59.0390 0404 [ 50D7EE1C07BC1E549FAE797668A90E1E ] ati2mtag C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
18:50:00.0312 0404 ati2mtag - ok
18:50:00.0359 0404 [ 924971A182E07463765EF9FA8876F24F ] AtiHDAudioService C:\WINDOWS\system32\drivers\AtihdXP3.sys
18:50:00.0375 0404 AtiHDAudioService - ok
18:50:00.0484 0404 [ DC6957811FF95F2DD3004361B20D8D3F ] AtiHdmiService C:\WINDOWS\system32\drivers\AtiHdmi.sys
18:50:00.0546 0404 AtiHdmiService - ok
18:50:00.0562 0404 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc C:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:50:00.0671 0404 Atmarpc - ok
18:50:00.0734 0404 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv C:\WINDOWS\System32\audiosrv.dll
18:50:00.0890 0404 AudioSrv - ok
18:50:01.0187 0404 [ D9F724AA26C010A217C97606B160ED68 ] audstub C:\WINDOWS\system32\DRIVERS\audstub.sys
18:50:01.0296 0404 audstub - ok
18:50:01.0500 0404 [ 28D6701C710AD7BA3CB95E75F8F1A9AA ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:50:01.0515 0404 avast! Antivirus - ok
18:50:01.0531 0404 Beep - ok
18:50:01.0609 0404 [ 574738F61FCA2935F5265DC4E5691314 ] BITS C:\WINDOWS\system32\qmgr.dll
18:50:01.0859 0404 BITS - ok
18:50:01.0921 0404 [ CFD4E51402DA9838B5A04AE680AF54A0 ] Browser C:\WINDOWS\System32\browser.dll
18:50:02.0000 0404 Browser - ok
18:50:02.0000 0404 catchme - ok
18:50:02.0046 0404 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf C:\WINDOWS\system32\DRIVERS\cbidf2k.sys
18:50:02.0171 0404 cbidf - ok
18:50:02.0187 0404 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k C:\WINDOWS\system32\drivers\cbidf2k.sys
18:50:02.0281 0404 cbidf2k - ok
18:50:02.0390 0404 [ 20F89E232173985A455BC9A5F70D1166 ] CCALib8 C:\Program Files\Canon\CAL\CALMAIN.exe
18:50:02.0437 0404 CCALib8 ( UnsignedFile.Multi.Generic ) - warning
18:50:02.0437 0404 CCALib8 - detected UnsignedFile.Multi.Generic (1)
18:50:02.0468 0404 [ F3EC03299634490E97BBCE94CD2954C7 ] cd20xrnt C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys
18:50:02.0546 0404 cd20xrnt - ok
18:50:02.0578 0404 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio C:\WINDOWS\system32\drivers\Cdaudio.sys
18:50:02.0687 0404 Cdaudio - ok
18:50:02.0718 0404 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs C:\WINDOWS\system32\drivers\Cdfs.sys
18:50:02.0828 0404 Cdfs - ok
18:50:02.0843 0404 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom C:\WINDOWS\system32\DRIVERS\cdrom.sys
18:50:02.0937 0404 Cdrom - ok
18:50:02.0937 0404 Changer - ok
18:50:03.0093 0404 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc C:\WINDOWS\system32\cisvc.exe
18:50:03.0250 0404 CiSvc - ok
18:50:03.0312 0404 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv C:\WINDOWS\system32\clipsrv.exe
18:50:03.0484 0404 ClipSrv - ok
18:50:04.0031 0404 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:50:04.0421 0404 clr_optimization_v2.0.50727_32 - ok
18:50:04.0453 0404 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:50:04.0640 0404 clr_optimization_v4.0.30319_32 - ok
18:50:04.0703 0404 [ E5DCB56C533014ECBC556A8357C929D5 ] CmdIde C:\WINDOWS\system32\DRIVERS\cmdide.sys
18:50:04.0843 0404 CmdIde - ok
18:50:04.0843 0404 COMSysApp - ok
18:50:04.0875 0404 [ 3EE529119EED34CD212A215E8C40D4B6 ] Cpqarray C:\WINDOWS\system32\DRIVERS\cpqarray.sys
18:50:05.0015 0404 Cpqarray - ok
18:50:05.0187 0404 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc C:\WINDOWS\System32\cryptsvc.dll
18:50:05.0328 0404 CryptSvc - ok
18:50:05.0359 0404 [ E550E7418984B65A78299D248F0A7F36 ] dac2w2k C:\WINDOWS\system32\DRIVERS\dac2w2k.sys
18:50:05.0484 0404 dac2w2k - ok
18:50:05.0500 0404 [ 683789CAA3864EB46125AE86FF677D34 ] dac960nt C:\WINDOWS\system32\DRIVERS\dac960nt.sys
18:50:05.0609 0404 dac960nt - ok
18:50:05.0843 0404 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch C:\WINDOWS\system32\rpcss.dll
18:50:05.0937 0404 DcomLaunch - ok
18:50:05.0984 0404 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp C:\WINDOWS\System32\dhcpcsvc.dll
18:50:06.0109 0404 Dhcp - ok
18:50:06.0156 0404 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk C:\WINDOWS\system32\DRIVERS\disk.sys
18:50:06.0265 0404 Disk - ok
18:50:06.0453 0404 [ 0659E6E0A95564F958D9DF7313F7701E ] DLABMFSM C:\WINDOWS\system32\DLA\DLABMFSM.SYS
18:50:06.0468 0404 DLABMFSM - ok
18:50:06.0500 0404 [ 8691C78908F0BD66170669DB268369F2 ] DLABOIOM C:\WINDOWS\system32\DLA\DLABOIOM.SYS
18:50:06.0515 0404 DLABOIOM - ok
18:50:06.0515 0404 [ 76167B5EB2DFFC729EDC36386876B40B ] DLACDBHM C:\WINDOWS\system32\Drivers\DLACDBHM.SYS
18:50:06.0531 0404 DLACDBHM - ok
18:50:06.0562 0404 [ 5615744A1056933B90E6AC54FEB86F35 ] DLADResM C:\WINDOWS\system32\DLA\DLADResM.SYS
18:50:06.0609 0404 DLADResM - ok
18:50:06.0625 0404 [ 1AECA2AFA5005CE4A550CF8EB55A8C88 ] DLAIFS_M C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
18:50:06.0640 0404 DLAIFS_M - ok
18:50:06.0671 0404 [ 840E7F6ABB885C72B9FFDDB022EF5B6D ] DLAOPIOM C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
18:50:06.0687 0404 DLAOPIOM - ok
18:50:06.0687 0404 [ 0294D18731AC05DA80132CE88F8A876B ] DLAPoolM C:\WINDOWS\system32\DLA\DLAPoolM.SYS
18:50:06.0703 0404 DLAPoolM - ok
18:50:06.0734 0404 [ 91886FED52A3F9966207BCE46CFD794F ] DLARTL_M C:\WINDOWS\system32\Drivers\DLARTL_M.SYS
18:50:06.0750 0404 DLARTL_M - ok
18:50:06.0796 0404 [ CCA4E121D599D7D1706A30F603731E59 ] DLAUDFAM C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
18:50:06.0812 0404 DLAUDFAM - ok
18:50:06.0843 0404 [ 7DAB85C33135DF24419951DA4E7D38E5 ] DLAUDF_M C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
18:50:06.0843 0404 DLAUDF_M - ok
18:50:06.0859 0404 dmadmin - ok
18:50:07.0046 0404 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot C:\WINDOWS\system32\drivers\dmboot.sys
18:50:07.0734 0404 dmboot - ok
18:50:07.0812 0404 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio C:\WINDOWS\system32\drivers\dmio.sys
18:50:07.0968 0404 dmio - ok
18:50:07.0984 0404 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload C:\WINDOWS\system32\drivers\dmload.sys
18:50:08.0296 0404 dmload - ok
18:50:08.0375 0404 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver C:\WINDOWS\System32\dmserver.dll
18:50:08.0500 0404 dmserver - ok
18:50:08.0546 0404 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic C:\WINDOWS\system32\drivers\DMusic.sys
18:50:10.0078 0404 DMusic - ok
18:50:10.0125 0404 [ 5F7E24FA9EAB896051FFB87F840730D2 ] Dnscache C:\WINDOWS\System32\dnsrslvr.dll
18:50:10.0250 0404 Dnscache - ok
18:50:10.0265 0404 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc C:\WINDOWS\System32\dot3svc.dll
18:50:10.0375 0404 Dot3svc - ok
18:50:10.0390 0404 [ 40F3B93B4E5B0126F2F5C0A7A5E22660 ] dpti2o C:\WINDOWS\system32\DRIVERS\dpti2o.sys
18:50:10.0531 0404 dpti2o - ok
18:50:10.0640 0404 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud C:\WINDOWS\system32\drivers\drmkaud.sys
18:50:10.0750 0404 drmkaud - ok
18:50:10.0781 0404 [ C00440385CF9F3D142917C63F989E244 ] DRVMCDB C:\WINDOWS\system32\Drivers\DRVMCDB.SYS
18:50:10.0796 0404 DRVMCDB - ok
18:50:10.0796 0404 [ 6E6AB29D3C06E64CE81FEACDA85394B5 ] DRVNDDM C:\WINDOWS\system32\Drivers\DRVNDDM.SYS
18:50:10.0812 0404 DRVNDDM - ok
18:50:10.0828 0404 [ 3FCA03CBCA11269F973B70FA483C88EF ] E100B C:\WINDOWS\system32\DRIVERS\e100b325.sys
18:50:10.0937 0404 E100B - ok
18:50:11.0000 0404 [ 34AAA3B298A852B3663E6E0D94D12945 ] e1express C:\WINDOWS\system32\DRIVERS\e1e5132.sys
18:50:11.0015 0404 e1express - ok
18:50:11.0062 0404 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost C:\WINDOWS\System32\eapsvc.dll
18:50:11.0171 0404 EapHost - ok
18:50:11.0234 0404 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc C:\WINDOWS\System32\ersvc.dll
18:50:11.0359 0404 ERSvc - ok
18:50:11.0421 0404 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog C:\WINDOWS\system32\services.exe
18:50:11.0484 0404 Eventlog - ok
18:50:11.0531 0404 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem C:\WINDOWS\system32\es.dll
18:50:11.0546 0404 EventSystem - ok
18:50:11.0593 0404 [ 38D332A6D56AF32635675F132548343E ] Fastfat C:\WINDOWS\system32\drivers\Fastfat.sys
18:50:11.0687 0404 Fastfat - ok
18:50:11.0765 0404 [ 99BC0B50F511924348BE19C7C7313BBF ] FastUserSwitchingCompatibility C:\WINDOWS\System32\shsvcs.dll
18:50:11.0812 0404 FastUserSwitchingCompatibility - ok
18:50:11.0921 0404 [ E97D6A8684466DF94FF3BC24FB787A07 ] Fax C:\WINDOWS\system32\fxssvc.exe
18:50:12.0031 0404 Fax - ok
18:50:12.0093 0404 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc C:\WINDOWS\system32\DRIVERS\fdc.sys
18:50:12.0171 0404 Fdc - ok
18:50:12.0203 0404 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips C:\WINDOWS\system32\drivers\Fips.sys
18:50:12.0390 0404 Fips - ok
18:50:12.0421 0404 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk C:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:50:12.0515 0404 Flpydisk - ok
18:50:12.0546 0404 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr C:\WINDOWS\system32\drivers\fltmgr.sys
18:50:12.0656 0404 FltMgr - ok
18:50:12.0843 0404 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
18:50:12.0843 0404 FontCache3.0.0.0 - ok
18:50:12.0859 0404 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec C:\WINDOWS\system32\drivers\Fs_Rec.sys
18:50:12.0968 0404 Fs_Rec - ok
18:50:12.0968 0404 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk C:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:50:13.0078 0404 Ftdisk - ok
18:50:13.0125 0404 [ 77EBF3E9386DAA51551AF429052D88D0 ] giveio C:\WINDOWS\system32\giveio.sys
18:50:13.0156 0404 giveio ( UnsignedFile.Multi.Generic ) - warning
18:50:13.0156 0404 giveio - detected UnsignedFile.Multi.Generic (1)
18:50:13.0203 0404 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc C:\WINDOWS\system32\DRIVERS\msgpc.sys
18:50:13.0296 0404 Gpc - ok
18:50:13.0468 0404 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
18:50:13.0468 0404 gupdate - ok
18:50:13.0484 0404 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
18:50:13.0484 0404 gupdatem - ok
18:50:13.0562 0404 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus C:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:50:13.0656 0404 HDAudBus - ok
18:50:13.0812 0404 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
18:50:13.0921 0404 helpsvc - ok
18:50:13.0921 0404 HidServ - ok
18:50:14.0000 0404 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] HidUsb C:\WINDOWS\system32\DRIVERS\hidusb.sys
18:50:14.0093 0404 HidUsb - ok
18:50:14.0125 0404 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc C:\WINDOWS\System32\kmsvc.dll
18:50:14.0218 0404 hkmsvc - ok
18:50:14.0250 0404 [ B028377DEA0546A5FCFBA928A8AEFAE0 ] hpn C:\WINDOWS\system32\DRIVERS\hpn.sys
18:50:14.0343 0404 hpn - ok
18:50:14.0390 0404 [ F80A415EF82CD06FFAF0D971528EAD38 ] HTTP C:\WINDOWS\system32\Drivers\HTTP.sys
18:50:14.0421 0404 HTTP - ok
18:50:14.0421 0404 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter C:\WINDOWS\System32\w3ssl.dll
18:50:14.0515 0404 HTTPFilter - ok
18:50:14.0546 0404 [ 9368670BD426EBEA5E8B18A62416EC28 ] i2omgmt C:\WINDOWS\system32\drivers\i2omgmt.sys
18:50:14.0640 0404 i2omgmt - ok
18:50:14.0671 0404 [ F10863BF1CCC290BABD1A09188AE49E0 ] i2omp C:\WINDOWS\system32\DRIVERS\i2omp.sys
18:50:14.0765 0404 i2omp - ok
18:50:14.0765 0404 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt C:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:50:14.0906 0404 i8042prt - ok
18:50:14.0984 0404 [ 997E8F5939F2D12CD9F2E6B395724C16 ] iaStor C:\WINDOWS\system32\drivers\iaStor.sys
18:50:15.0031 0404 iaStor - ok
18:50:15.0156 0404 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
18:50:15.0187 0404 IDriverT ( UnsignedFile.Multi.Generic ) - warning
18:50:15.0187 0404 IDriverT - detected UnsignedFile.Multi.Generic (1)
18:50:15.0250 0404 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:50:15.0921 0404 idsvc - ok
18:50:15.0937 0404 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi C:\WINDOWS\system32\DRIVERS\imapi.sys
18:50:16.0031 0404 Imapi - ok
18:50:16.0093 0404 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService C:\WINDOWS\system32\imapi.exe
18:50:16.0187 0404 ImapiService - ok
18:50:16.0218 0404 [ 4A40E045FAEE58631FD8D91AFC620719 ] ini910u C:\WINDOWS\system32\DRIVERS\ini910u.sys
18:50:16.0328 0404 ini910u - ok
18:50:16.0453 0404 [ DBC702FBC70DC58D9122CE56EADBD659 ] IntcAzAudAddService C:\WINDOWS\system32\drivers\RtkHDAud.sys
18:50:16.0593 0404 IntcAzAudAddService - ok
18:50:16.0718 0404 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde C:\WINDOWS\system32\DRIVERS\intelide.sys
18:50:16.0828 0404 IntelIde - ok
18:50:16.0875 0404 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm C:\WINDOWS\system32\DRIVERS\intelppm.sys
18:50:16.0968 0404 intelppm - ok
18:50:17.0000 0404 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw C:\WINDOWS\system32\drivers\ip6fw.sys
18:50:17.0109 0404 Ip6Fw - ok
18:50:17.0156 0404 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:50:17.0250 0404 IpFilterDriver - ok
18:50:17.0281 0404 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp C:\WINDOWS\system32\DRIVERS\ipinip.sys
18:50:17.0375 0404 IpInIp - ok
18:50:17.0453 0404 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat C:\WINDOWS\system32\DRIVERS\ipnat.sys
18:50:17.0546 0404 IpNat - ok
18:50:17.0656 0404 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec C:\WINDOWS\system32\DRIVERS\ipsec.sys
18:50:17.0734 0404 IPSec - ok
18:50:17.0906 0404 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM C:\WINDOWS\system32\DRIVERS\irenum.sys
18:50:18.0015 0404 IRENUM - ok
18:50:18.0046 0404 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp C:\WINDOWS\system32\DRIVERS\isapnp.sys
18:50:18.0140 0404 isapnp - ok
18:50:18.0687 0404 [ 4F4D4AA1E0849FECC0CF5AACD59030B5 ] JavaQuickStarterService C:\Program Files\Java\jre7\bin\jqs.exe
18:50:18.0703 0404 JavaQuickStarterService - ok
18:50:18.0718 0404 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass C:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:50:18.0843 0404 Kbdclass - ok
18:50:19.0046 0404 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid C:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:50:19.0156 0404 kbdhid - ok
18:50:19.0171 0404 [ 692BCF44383D056AED41B045A323D378 ] kmixer C:\WINDOWS\system32\drivers\kmixer.sys
18:50:19.0281 0404 kmixer - ok
18:50:19.0328 0404 [ B467646C54CC746128904E1654C750C1 ] KSecDD C:\WINDOWS\system32\drivers\KSecDD.sys
18:50:19.0390 0404 KSecDD - ok
18:50:19.0578 0404 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] lanmanserver C:\WINDOWS\System32\srvsvc.dll
18:50:19.0906 0404 lanmanserver - ok
18:50:20.0000 0404 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation C:\WINDOWS\System32\wkssvc.dll
18:50:20.0062 0404 lanmanworkstation - ok
18:50:20.0062 0404 lbrtfdc - ok
18:50:20.0140 0404 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts C:\WINDOWS\System32\lmhsvc.dll
18:50:20.0218 0404 LmHosts - ok
18:50:20.0250 0404 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger C:\WINDOWS\System32\msgsvc.dll
18:50:20.0343 0404 Messenger - ok
18:50:20.0406 0404 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd C:\WINDOWS\system32\drivers\mnmdd.sys
18:50:20.0500 0404 mnmdd - ok
18:50:20.0828 0404 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc C:\WINDOWS\system32\mnmsrvc.exe
18:50:20.0953 0404 mnmsrvc - ok
18:50:21.0000 0404 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem C:\WINDOWS\system32\drivers\Modem.sys
18:50:21.0140 0404 Modem - ok
18:50:21.0187 0404 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass C:\WINDOWS\system32\DRIVERS\mouclass.sys
18:50:21.0281 0404 Mouclass - ok
18:50:21.0328 0404 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid C:\WINDOWS\system32\DRIVERS\mouhid.sys
18:50:21.0437 0404 mouhid - ok
18:50:21.0468 0404 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr C:\WINDOWS\system32\drivers\MountMgr.sys
18:50:21.0562 0404 MountMgr - ok
18:50:21.0609 0404 [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:50:21.0656 0404 MozillaMaintenance - ok
18:50:21.0687 0404 [ 3F4BB95E5A44F3BE34824E8E7CAF0737 ] mraid35x C:\WINDOWS\system32\DRIVERS\mraid35x.sys
18:50:21.0812 0404 mraid35x - ok
18:50:21.0843 0404 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV C:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:50:21.0953 0404 MRxDAV - ok
18:50:22.0000 0404 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] MRxSmb C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:50:22.0031 0404 MRxSmb - ok
18:50:22.0062 0404 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC C:\WINDOWS\system32\msdtc.exe
18:50:22.0156 0404 MSDTC - ok
18:50:22.0203 0404 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs C:\WINDOWS\system32\drivers\Msfs.sys
18:50:22.0281 0404 Msfs - ok
18:50:22.0281 0404 MSIServer - ok
18:50:22.0328 0404 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV C:\WINDOWS\system32\drivers\MSKSSRV.sys
18:50:22.0406 0404 MSKSSRV - ok
18:50:22.0437 0404 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK C:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:50:22.0515 0404 MSPCLOCK - ok
18:50:22.0562 0404 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM C:\WINDOWS\system32\drivers\MSPQM.sys
18:50:22.0671 0404 MSPQM - ok
18:50:22.0703 0404 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios C:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:50:22.0796 0404 mssmbios - ok
18:50:22.0812 0404 [ DE6A75F5C270E756C5508D94B6CF68F5 ] Mup C:\WINDOWS\system32\drivers\Mup.sys
18:50:22.0828 0404 Mup - ok
18:50:22.0875 0404 [ 0102140028FAD045756796E1C685D695 ] napagent C:\WINDOWS\System32\qagentrt.dll
18:50:22.0968 0404 napagent - ok
18:50:23.0031 0404 [ 1DF7F42665C94B825322FAE71721130D ] NDIS C:\WINDOWS\system32\drivers\NDIS.sys
18:50:23.0109 0404 NDIS - ok
18:50:23.0156 0404 [ 0109C4F3850DFBAB279542515386AE22 ] NdisTapi C:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:50:23.0171 0404 NdisTapi - ok
18:50:23.0187 0404 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio C:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:50:23.0281 0404 Ndisuio - ok
18:50:23.0312 0404 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan C:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:50:23.0421 0404 NdisWan - ok
18:50:23.0468 0404 [ 9282BD12DFB069D3889EB3FCC1000A9B ] NDProxy C:\WINDOWS\system32\drivers\NDProxy.sys
18:50:23.0484 0404 NDProxy - ok
18:50:23.0531 0404 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS C:\WINDOWS\system32\DRIVERS\netbios.sys
18:50:23.0625 0404 NetBIOS - ok
18:50:23.0656 0404 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT C:\WINDOWS\system32\DRIVERS\netbt.sys
18:50:23.0750 0404 NetBT - ok
18:50:23.0781 0404 [ B857BA82860D7FF85AE29B095645563B ] NetDDE C:\WINDOWS\system32\netdde.exe
18:50:23.0921 0404 NetDDE - ok
18:50:23.0921 0404 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm C:\WINDOWS\system32\netdde.exe
18:50:24.0015 0404 NetDDEdsdm - ok
18:50:24.0281 0404 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon C:\WINDOWS\system32\lsass.exe
18:50:24.0375 0404 Netlogon - ok
18:50:24.0406 0404 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman C:\WINDOWS\System32\netman.dll
18:50:24.0500 0404 Netman - ok
18:50:24.0546 0404 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:50:24.0593 0404 NetTcpPortSharing - ok
18:50:24.0640 0404 [ 943337D786A56729263071623BBB9DE5 ] Nla C:\WINDOWS\System32\mswsock.dll
18:50:24.0671 0404 Nla - ok
18:50:24.0703 0404 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs C:\WINDOWS\system32\drivers\Npfs.sys
18:50:24.0812 0404 Npfs - ok
18:50:24.0812 0404 npggsvc - ok
18:50:24.0859 0404 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs C:\WINDOWS\system32\drivers\Ntfs.sys
18:50:24.0968 0404 Ntfs - ok
18:50:25.0000 0404 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp C:\WINDOWS\system32\lsass.exe
18:50:25.0078 0404 NtLmSsp - ok
18:50:25.0125 0404 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc C:\WINDOWS\system32\ntmssvc.dll
18:50:25.0250 0404 NtmsSvc - ok
18:50:25.0265 0404 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null C:\WINDOWS\system32\drivers\Null.sys
18:50:25.0343 0404 Null - ok
18:50:25.0406 0404 [ 2B298519EDBFCF451D43E0F1E8F1006D ] nv C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
18:50:25.0593 0404 nv - ok
18:50:25.0625 0404 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:50:25.0750 0404 NwlnkFlt - ok
18:50:25.0750 0404 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:50:25.0859 0404 NwlnkFwd - ok
18:50:25.0921 0404 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport C:\WINDOWS\system32\DRIVERS\parport.sys
18:50:26.0046 0404 Parport - ok
18:50:26.0078 0404 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr C:\WINDOWS\system32\drivers\PartMgr.sys
18:50:26.0187 0404 PartMgr - ok
18:50:26.0203 0404 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm C:\WINDOWS\system32\drivers\ParVdm.sys
18:50:26.0328 0404 ParVdm - ok
18:50:28.0453 0404 [ 2DD9D5A9150C7015AC7F215EFA59E44F ] PCDSRVC{E9D79540-57D5953E-06020101}_0 c:\program files\dell support center\pcdsrvc.pkms
18:50:29.0187 0404 PCDSRVC{E9D79540-57D5953E-06020101}_0 - ok
18:50:29.0218 0404 [ A219903CCF74233761D92BEF471A07B1 ] PCI C:\WINDOWS\system32\DRIVERS\pci.sys
18:50:29.0328 0404 PCI - ok
18:50:29.0328 0404 PCIDump - ok
18:50:29.0359 0404 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde C:\WINDOWS\system32\DRIVERS\pciide.sys
18:50:29.0468 0404 PCIIde - ok
18:50:29.0500 0404 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia C:\WINDOWS\system32\drivers\Pcmcia.sys
18:50:29.0968 0404 Pcmcia - ok
18:50:29.0968 0404 PDCOMP - ok
18:50:29.0984 0404 PDFRAME - ok
18:50:29.0984 0404 PDRELI - ok
18:50:29.0984 0404 PDRFRAME - ok
18:50:30.0015 0404 [ 6C14B9C19BA84F73D3A86DBA11133101 ] perc2 C:\WINDOWS\system32\DRIVERS\perc2.sys
18:50:30.0125 0404 perc2 - ok
18:50:30.0156 0404 [ F50F7C27F131AFE7BEBA13E14A3B9416 ] perc2hib C:\WINDOWS\system32\DRIVERS\perc2hib.sys
18:50:30.0250 0404 perc2hib - ok
18:50:30.0296 0404 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay C:\WINDOWS\system32\services.exe
18:50:30.0328 0404 PlugPlay - ok
18:50:30.0359 0404 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent C:\WINDOWS\system32\lsass.exe
18:50:30.0468 0404 PolicyAgent - ok
18:50:30.0515 0404 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport C:\WINDOWS\system32\DRIVERS\raspptp.sys
18:50:30.0593 0404 PptpMiniport - ok
18:50:30.0593 0404 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage C:\WINDOWS\system32\lsass.exe
18:50:30.0687 0404 ProtectedStorage - ok
18:50:30.0703 0404 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched C:\WINDOWS\system32\DRIVERS\psched.sys
18:50:30.0796 0404 PSched - ok
18:50:30.0812 0404 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink C:\WINDOWS\system32\DRIVERS\ptilink.sys
18:50:30.0937 0404 Ptilink - ok
18:50:30.0984 0404 [ D86B4A68565E444D76457F14172C875A ] PxHelp20 C:\WINDOWS\system32\Drivers\PxHelp20.sys
18:50:31.0000 0404 PxHelp20 - ok
18:50:31.0015 0404 [ 0A63FB54039EB5662433CABA3B26DBA7 ] ql1080 C:\WINDOWS\system32\DRIVERS\ql1080.sys
18:50:31.0109 0404 ql1080 - ok
18:50:31.0140 0404 [ 6503449E1D43A0FF0201AD5CB1B8C706 ] Ql10wnt C:\WINDOWS\system32\DRIVERS\ql10wnt.sys
18:50:31.0234 0404 Ql10wnt - ok
18:50:31.0234 0404 [ 156ED0EF20C15114CA097A34A30D8A01 ] ql12160 C:\WINDOWS\system32\DRIVERS\ql12160.sys
18:50:31.0328 0404 ql12160 - ok
18:50:31.0343 0404 [ 70F016BEBDE6D29E864C1230A07CC5E6 ] ql1240 C:\WINDOWS\system32\DRIVERS\ql1240.sys
18:50:31.0453 0404 ql1240 - ok
18:50:31.0484 0404 [ 907F0AEEA6BC451011611E732BD31FCF ] ql1280 C:\WINDOWS\system32\DRIVERS\ql1280.sys
18:50:31.0578 0404 ql1280 - ok
18:50:31.0625 0404 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd C:\WINDOWS\system32\DRIVERS\rasacd.sys
18:50:31.0718 0404 RasAcd - ok
18:50:31.0765 0404 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto C:\WINDOWS\System32\rasauto.dll
18:50:31.0859 0404 RasAuto - ok
18:50:31.0890 0404 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:50:31.0984 0404 Rasl2tp - ok
18:50:32.0015 0404 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan C:\WINDOWS\System32\rasmans.dll
18:50:32.0156 0404 RasMan - ok
18:50:32.0187 0404 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe C:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:50:32.0265 0404 RasPppoe - ok
18:50:32.0281 0404 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti C:\WINDOWS\system32\DRIVERS\raspti.sys
18:50:32.0359 0404 Raspti - ok
18:50:32.0421 0404 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss C:\WINDOWS\system32\DRIVERS\rdbss.sys
18:50:32.0515 0404 Rdbss - ok
18:50:32.0531 0404 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:50:32.0625 0404 RDPCDD - ok
18:50:32.0625 0404 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr C:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:50:32.0734 0404 rdpdr - ok
18:50:32.0765 0404 [ 43AF5212BD8FB5BA6EED9754358BD8F7 ] RDPWD C:\WINDOWS\system32\drivers\RDPWD.sys
18:50:32.0781 0404 RDPWD - ok
18:50:32.0812 0404 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr C:\WINDOWS\system32\sessmgr.exe
18:50:32.0906 0404 RDSessMgr - ok
18:50:32.0953 0404 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook C:\WINDOWS\system32\DRIVERS\redbook.sys
18:50:33.0046 0404 redbook - ok
18:50:33.0093 0404 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess C:\WINDOWS\System32\mprdim.dll
18:50:33.0203 0404 RemoteAccess - ok
18:50:33.0234 0404 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry C:\WINDOWS\system32\regsvc.dll
18:50:33.0328 0404 RemoteRegistry - ok
18:50:33.0484 0404 [ EBCDE8B48FADC6479D96A56D0A432160 ] RoxMediaDB9 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
18:50:33.0500 0404 RoxMediaDB9 ( UnsignedFile.Multi.Generic ) - warning
18:50:33.0500 0404 RoxMediaDB9 - detected UnsignedFile.Multi.Generic (1)
18:50:33.0546 0404 [ AB2B1DE1C8F31EFCE2384B14B3DC4260 ] RoxWatch9 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
18:50:33.0562 0404 RoxWatch9 ( UnsignedFile.Multi.Generic ) - warning
18:50:33.0562 0404 RoxWatch9 - detected UnsignedFile.Multi.Generic (1)
18:50:33.0578 0404 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator C:\WINDOWS\system32\locator.exe
18:50:33.0671 0404 RpcLocator - ok
18:50:33.0703 0404 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs C:\WINDOWS\System32\rpcss.dll
18:50:33.0734 0404 RpcSs - ok
18:50:33.0781 0404 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP C:\WINDOWS\system32\rsvp.exe
18:50:33.0875 0404 RSVP - ok
18:50:33.0906 0404 [ D507C1400284176573224903819FFDA3 ] rtl8139 C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
18:50:34.0000 0404 rtl8139 - ok
18:50:34.0031 0404 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs C:\WINDOWS\system32\lsass.exe
18:50:34.0109 0404 SamSs - ok
18:50:34.0140 0404 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr C:\WINDOWS\System32\SCardSvr.exe
18:50:34.0265 0404 SCardSvr - ok
18:50:34.0312 0404 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule C:\WINDOWS\system32\schedsvc.dll
18:50:34.0406 0404 Schedule - ok
18:50:34.0578 0404 [ 95AA9E165C7DE1B64A11E8B18E91E499 ] SDScannerService C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
18:50:34.0625 0404 SDScannerService - ok
18:50:34.0687 0404 [ D31398D4BB4907B517B6E784C2100C4A ] SDUpdateService C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
18:50:34.0703 0404 SDUpdateService - ok
18:50:34.0734 0404 [ 6AE8E702D1027A9627DDE2B77BB9992B ] SDWSCService C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
18:50:34.0750 0404 SDWSCService - ok
18:50:34.0781 0404 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv C:\WINDOWS\system32\DRIVERS\secdrv.sys
18:50:34.0875 0404 Secdrv - ok
18:50:34.0937 0404 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon C:\WINDOWS\System32\seclogon.dll
18:50:35.0046 0404 seclogon - ok
18:50:35.0078 0404 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS C:\WINDOWS\system32\sens.dll
18:50:35.0281 0404 SENS - ok
18:50:35.0312 0404 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum C:\WINDOWS\system32\DRIVERS\serenum.sys
18:50:35.0421 0404 serenum - ok
18:50:35.0453 0404 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial C:\WINDOWS\system32\DRIVERS\serial.sys
18:50:35.0546 0404 Serial - ok
18:50:35.0593 0404 [ 56250672235BBE54BA8A4963B1AC997C ] sfdrv01 C:\WINDOWS\system32\drivers\sfdrv01.sys
18:50:35.0609 0404 sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
18:50:35.0609 0404 sfdrv01 - detected UnsignedFile.Multi.Generic (1)
18:50:35.0656 0404 [ 3AD2B15CCC03FEBFBAF5FF057822AA75 ] sfhlp02 C:\WINDOWS\system32\drivers\sfhlp02.sys
18:50:35.0671 0404 sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
18:50:35.0671 0404 sfhlp02 - detected UnsignedFile.Multi.Generic (1)
18:50:35.0671 0404 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy C:\WINDOWS\system32\drivers\Sfloppy.sys
18:50:35.0765 0404 Sfloppy - ok
18:50:35.0796 0404 [ 798D918D8F20380008277CE3CE5319D1 ] sfsync02 C:\WINDOWS\system32\drivers\sfsync02.sys
18:50:35.0812 0404 sfsync02 ( UnsignedFile.Multi.Generic ) - warning
18:50:35.0812 0404 sfsync02 - detected UnsignedFile.Multi.Generic (1)
18:50:35.0859 0404 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess C:\WINDOWS\System32\ipnathlp.dll
18:50:35.0984 0404 SharedAccess - ok
18:50:36.0015 0404 [ 99BC0B50F511924348BE19C7C7313BBF ] ShellHWDetection C:\WINDOWS\System32\shsvcs.dll
18:50:36.0031 0404 ShellHWDetection - ok
18:50:36.0031 0404 Simbad - ok
18:50:36.0109 0404 [ 6B33D0EBD30DB32E27D1D78FE946A754 ] sisagp C:\WINDOWS\system32\DRIVERS\sisagp.sys
18:50:36.0187 0404 sisagp - ok
18:50:36.0218 0404 [ 83C0F71F86D3BDAF915685F3D568B20E ] Sparrow C:\WINDOWS\system32\DRIVERS\sparrow.sys
18:50:36.0296 0404 Sparrow - ok
18:50:36.0328 0404 [ DC8D2952FB6FFBAEC67BD1B93A34DF11 ] speedfan C:\WINDOWS\system32\speedfan.sys
18:50:36.0343 0404 speedfan - ok
18:50:36.0375 0404 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter C:\WINDOWS\system32\drivers\splitter.sys
18:50:36.0484 0404 splitter - ok
18:50:36.0515 0404 [ 60784F891563FB1B767F70117FC2428F ] Spooler C:\WINDOWS\system32\spoolsv.exe
18:50:36.0546 0404 Spooler - ok
18:50:36.0562 0404 sprtsvc_dellsupportcenter - ok
18:50:36.0578 0404 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr C:\WINDOWS\system32\DRIVERS\sr.sys
18:50:36.0671 0404 sr - ok
18:50:36.0718 0404 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice C:\WINDOWS\system32\srsvc.dll
18:50:36.0828 0404 srservice - ok
18:50:36.0875 0404 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] Srv C:\WINDOWS\system32\DRIVERS\srv.sys
18:50:36.0890 0404 Srv - ok
18:50:36.0937 0404 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV C:\WINDOWS\System32\ssdpsrv.dll
18:50:37.0031 0404 SSDPSRV - ok
18:50:37.0062 0404 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc C:\WINDOWS\system32\wiaservc.dll
18:50:37.0156 0404 stisvc - ok
18:50:37.0218 0404 [ 51778FD315C9882F1CBD932743E62A72 ] stllssvr C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
18:50:37.0218 0404 stllssvr ( UnsignedFile.Multi.Generic ) - warning
18:50:37.0218 0404 stllssvr - detected UnsignedFile.Multi.Generic (1)
18:50:37.0265 0404 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum C:\WINDOWS\system32\DRIVERS\swenum.sys
18:50:37.0343 0404 swenum - ok
18:50:37.0390 0404 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi C:\WINDOWS\system32\drivers\swmidi.sys
18:50:37.0484 0404 swmidi - ok
18:50:37.0484 0404 SwPrv - ok
18:50:37.0500 0404 [ 1FF3217614018630D0A6758630FC698C ] symc810 C:\WINDOWS\system32\DRIVERS\symc810.sys
18:50:37.0593 0404 symc810 - ok
18:50:37.0593 0404 [ 070E001D95CF725186EF8B20335F933C ] symc8xx C:\WINDOWS\system32\DRIVERS\symc8xx.sys
18:50:37.0703 0404 symc8xx - ok
18:50:37.0734 0404 [ 80AC1C4ABBE2DF3B738BF15517A51F2C ] sym_hi C:\WINDOWS\system32\DRIVERS\sym_hi.sys
18:50:37.0843 0404 sym_hi - ok
18:50:37.0843 0404 [ BF4FAB949A382A8E105F46EBB4937058 ] sym_u3 C:\WINDOWS\system32\DRIVERS\sym_u3.sys
18:50:37.0953 0404 sym_u3 - ok
18:50:37.0984 0404 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio C:\WINDOWS\system32\drivers\sysaudio.sys
18:50:38.0093 0404 sysaudio - ok
18:50:38.0125 0404 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog C:\WINDOWS\system32\smlogsvc.exe
18:50:38.0218 0404 SysmonLog - ok
18:50:38.0250 0404 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv C:\WINDOWS\System32\tapisrv.dll
18:50:38.0343 0404 TapiSrv - ok
18:50:38.0390 0404 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip C:\WINDOWS\system32\DRIVERS\tcpip.sys
18:50:38.0421 0404 Tcpip - ok
18:50:38.0484 0404 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE C:\WINDOWS\system32\drivers\TDPIPE.sys
18:50:38.0593 0404 TDPIPE - ok
18:50:38.0640 0404 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP C:\WINDOWS\system32\drivers\TDTCP.sys
18:50:38.0718 0404 TDTCP - ok
18:50:38.0750 0404 [ 88155247177638048422893737429D9E ] TermDD C:\WINDOWS\system32\DRIVERS\termdd.sys
18:50:38.0843 0404 TermDD - ok
18:50:38.0890 0404 [ FF3477C03BE7201C294C35F684B3479F ] TermService C:\WINDOWS\System32\termsrv.dll
18:50:38.0984 0404 TermService - ok
18:50:39.0015 0404 [ 99BC0B50F511924348BE19C7C7313BBF ] Themes C:\WINDOWS\System32\shsvcs.dll
18:50:39.0031 0404 Themes - ok
18:50:39.0078 0404 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr C:\WINDOWS\system32\tlntsvr.exe
18:50:39.0187 0404 TlntSvr - ok
18:50:39.0265 0404 [ F2790F6AF01321B172AA62F8E1E187D9 ] TosIde C:\WINDOWS\system32\DRIVERS\toside.sys
18:50:39.0359 0404 TosIde - ok
18:50:39.0390 0404 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks C:\WINDOWS\system32\trkwks.dll
18:50:39.0500 0404 TrkWks - ok
18:50:39.0515 0404 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs C:\WINDOWS\system32\drivers\Udfs.sys
18:50:39.0625 0404 Udfs - ok
18:50:39.0640 0404 [ 1B698A51CD528D8DA4FFAED66DFC51B9 ] ultra C:\WINDOWS\system32\DRIVERS\ultra.sys
18:50:39.0687 0404 ultra - ok
18:50:39.0750 0404 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update C:\WINDOWS\system32\DRIVERS\update.sys
18:50:39.0843 0404 Update - ok
18:50:39.0875 0404 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost C:\WINDOWS\System32\upnphost.dll
18:50:39.0968 0404 upnphost - ok
18:50:39.0984 0404 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS C:\WINDOWS\System32\ups.exe
18:50:40.0062 0404 UPS - ok
18:50:40.0078 0404 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci C:\WINDOWS\system32\DRIVERS\usbehci.sys
18:50:40.0156 0404 usbehci - ok
18:50:40.0187 0404 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub C:\WINDOWS\system32\DRIVERS\usbhub.sys
18:50:40.0265 0404 usbhub - ok
18:50:40.0296 0404 [ A717C8721046828520C9EDF31288FC00 ] usbprint C:\WINDOWS\system32\DRIVERS\usbprint.sys
18:50:40.0406 0404 usbprint - ok
18:50:40.0453 0404 [ A0B8CF9DEB1184FBDD20784A58FA75D4 ] usbscan C:\WINDOWS\system32\DRIVERS\usbscan.sys
18:50:40.0531 0404 usbscan - ok
18:50:40.0578 0404 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:50:40.0656 0404 USBSTOR - ok
18:50:40.0703 0404 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci C:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:50:40.0796 0404 usbuhci - ok
18:50:40.0828 0404 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave C:\WINDOWS\System32\drivers\vga.sys
18:50:40.0921 0404 VgaSave - ok
18:50:40.0953 0404 [ 754292CE5848B3738281B4F3607EAEF4 ] viaagp C:\WINDOWS\system32\DRIVERS\viaagp.sys
18:50:41.0031 0404 viaagp - ok
18:50:41.0062 0404 [ 3B3EFCDA263B8AC14FDF9CBDD0791B2E ] ViaIde C:\WINDOWS\system32\DRIVERS\viaide.sys
18:50:41.0171 0404 ViaIde - ok
18:50:41.0218 0404 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap C:\WINDOWS\system32\drivers\VolSnap.sys
18:50:41.0312 0404 VolSnap - ok
18:50:41.0343 0404 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS C:\WINDOWS\System32\vssvc.exe
18:50:41.0437 0404 VSS - ok
18:50:41.0484 0404 [ 54AF4B1D5459500EF0937F6D33B1914F ] w32time C:\WINDOWS\system32\w32time.dll
18:50:41.0578 0404 w32time - ok
18:50:41.0625 0404 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp C:\WINDOWS\system32\DRIVERS\wanarp.sys
18:50:41.0718 0404 Wanarp - ok
18:50:41.0718 0404 WDICA - ok
18:50:41.0750 0404 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud C:\WINDOWS\system32\drivers\wdmaud.sys
18:50:41.0828 0404 wdmaud - ok
18:50:41.0875 0404 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient C:\WINDOWS\System32\webclnt.dll
18:50:41.0984 0404 WebClient - ok
18:50:42.0062 0404 [ F45DD1E1365D857DD08BC23563370D0E ] WinDefend C:\Program Files\Windows Defender\MsMpEng.exe
18:50:42.0078 0404 WinDefend - ok
18:50:42.0171 0404 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt C:\WINDOWS\system32\wbem\WMIsvc.dll
18:50:42.0250 0404 winmgmt - ok
18:50:42.0312 0404 [ 18F347402DA544A780949B8FDF83351B ] WinRM C:\WINDOWS\system32\WsmSvc.dll
18:50:42.0390 0404 WinRM - ok
18:50:42.0437 0404 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN C:\WINDOWS\system32\MsPMSNSv.dll
18:50:42.0468 0404 WmdmPmSN - ok
18:50:42.0546 0404 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi C:\WINDOWS\System32\advapi32.dll
18:50:42.0609 0404 Wmi - ok
18:50:42.0671 0404 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv C:\WINDOWS\system32\wbem\wmiapsrv.exe
18:50:42.0750 0404 WmiApSrv - ok
18:50:42.0812 0404 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc C:\Program Files\Windows Media Player\WMPNetwk.exe
18:50:42.0875 0404 WMPNetworkSvc - ok
18:50:42.0984 0404 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:50:43.0015 0404 WPFFontCache_v0400 - ok
18:50:43.0031 0404 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] WS2IFSL C:\WINDOWS\System32\drivers\ws2ifsl.sys
18:50:43.0125 0404 WS2IFSL - ok
18:50:43.0187 0404 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc C:\WINDOWS\system32\wscsvc.dll
18:50:43.0281 0404 wscsvc - ok
18:50:43.0312 0404 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv C:\WINDOWS\system32\wuauserv.dll
18:50:43.0421 0404 wuauserv - ok
18:50:43.0453 0404 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf C:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:50:43.0468 0404 WudfPf - ok
18:50:43.0500 0404 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd C:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:50:43.0515 0404 WudfRd - ok
18:50:43.0546 0404 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc C:\WINDOWS\System32\WUDFSvc.dll
18:50:43.0562 0404 WudfSvc - ok
18:50:43.0625 0404 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC C:\WINDOWS\System32\wzcsvc.dll
18:50:43.0781 0404 WZCSVC - ok
18:50:43.0828 0404 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov C:\WINDOWS\System32\xmlprov.dll
18:50:43.0937 0404 xmlprov - ok
18:50:43.0937 0404 ================ Scan global ===============================
18:50:43.0984 0404 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
18:50:44.0015 0404 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll
18:50:44.0046 0404 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll
18:50:44.0078 0404 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
18:50:44.0078 0404 [Global] - ok
18:50:44.0078 0404 ================ Scan MBR ==================================
18:50:44.0109 0404 [ 5CB90281D1A59B251F6603134774EEC3 ] \Device\Harddisk0\DR0
18:50:44.0375 0404 \Device\Harddisk0\DR0 - ok
18:50:44.0375 0404 ================ Scan VBR ==================================
18:50:44.0375 0404 [ B55EEB36CE799BB74124878095D89743 ] \Device\Harddisk0\DR0\Partition1
18:50:44.0375 0404 \Device\Harddisk0\DR0\Partition1 - ok
18:50:44.0390 0404 ================ Scan active images ========================
18:50:44.0390 0404 [ 8C953733D8F36EB2133F5BB58808B66B ] C:\WINDOWS\system32\drivers\intelppm.sys
18:50:44.0390 0404 C:\WINDOWS\system32\drivers\intelppm.sys - ok
18:50:44.0390 0404 [ E28726B72C46821A28830E077D39A55B ] C:\WINDOWS\system32\drivers\videoprt.sys
18:50:44.0390 0404 C:\WINDOWS\system32\drivers\videoprt.sys - ok
18:50:44.0390 0404 [ 50D7EE1C07BC1E549FAE797668A90E1E ] C:\WINDOWS\system32\drivers\ati2mtag.sys
18:50:44.0390 0404 C:\WINDOWS\system32\drivers\ati2mtag.sys - ok
18:50:44.0390 0404 [ 34AAA3B298A852B3663E6E0D94D12945 ] C:\WINDOWS\system32\drivers\e1e5132.sys
18:50:44.0390 0404 C:\WINDOWS\system32\drivers\e1e5132.sys - ok
18:50:44.0390 0404 [ 573C7D0A32852B48F3058CFD8026F511 ] C:\WINDOWS\system32\drivers\hdaudbus.sys
18:50:44.0390 0404 C:\WINDOWS\system32\drivers\hdaudbus.sys - ok
18:50:44.0390 0404 [ 791912E524CC2CC6F50B5F2B52D1EB71 ] C:\WINDOWS\system32\drivers\usbport.sys
18:50:44.0390 0404 C:\WINDOWS\system32\drivers\usbport.sys - ok
18:50:44.0390 0404 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] C:\WINDOWS\system32\drivers\usbuhci.sys
18:50:44.0390 0404 C:\WINDOWS\system32\drivers\usbuhci.sys - ok
18:50:44.0406 0404 [ 1F4260CC5B42272D71F79E570A27A4FE ] C:\WINDOWS\system32\drivers\cdrom.sys
18:50:44.0406 0404 C:\WINDOWS\system32\drivers\cdrom.sys - ok
18:50:44.0406 0404 [ 76167B5EB2DFFC729EDC36386876B40B ] C:\WINDOWS\system32\drivers\DLACDBHM.SYS
18:50:44.0406 0404 C:\WINDOWS\system32\drivers\DLACDBHM.SYS - ok
18:50:44.0406 0404 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] C:\WINDOWS\system32\drivers\fdc.sys
18:50:44.0406 0404 C:\WINDOWS\system32\drivers\fdc.sys - ok
18:50:44.0406 0404 [ 083A052659F5310DD8B6A6CB05EDCF8E ] C:\WINDOWS\system32\drivers\imapi.sys
18:50:44.0406 0404 C:\WINDOWS\system32\drivers\imapi.sys - ok
18:50:44.0406 0404 [ 0753515F78DF7F271A5E61C20BCD36A1 ] C:\WINDOWS\system32\drivers\ks.sys
18:50:44.0406 0404 C:\WINDOWS\system32\drivers\ks.sys - ok
18:50:44.0406 0404 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] C:\WINDOWS\system32\drivers\usbehci.sys
18:50:44.0406 0404 C:\WINDOWS\system32\drivers\usbehci.sys - ok
18:50:44.0421 0404 [ D9F724AA26C010A217C97606B160ED68 ] C:\WINDOWS\system32\drivers\audstub.sys
18:50:44.0421 0404 C:\WINDOWS\system32\drivers\audstub.sys - ok
18:50:44.0421 0404 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] C:\WINDOWS\system32\drivers\rasl2tp.sys
18:50:44.0421 0404 C:\WINDOWS\system32\drivers\rasl2tp.sys - ok
18:50:44.0421 0404 [ F828DD7E1419B6653894A8F97A0094C5 ] C:\WINDOWS\system32\drivers\redbook.sys
18:50:44.0421 0404 C:\WINDOWS\system32\drivers\redbook.sys - ok
18:50:44.0421 0404 [ 0109C4F3850DFBAB279542515386AE22 ] C:\WINDOWS\system32\drivers\ndistapi.sys
18:50:44.0421 0404 C:\WINDOWS\system32\drivers\ndistapi.sys - ok
18:50:44.0421 0404 [ EDC1531A49C80614B2CFDA43CA8659AB ] C:\WINDOWS\system32\drivers\ndiswan.sys
18:50:44.0421 0404 C:\WINDOWS\system32\drivers\ndiswan.sys - ok
18:50:44.0421 0404 [ 5BC962F2654137C9909C3D4603587DEE ] C:\WINDOWS\system32\drivers\raspppoe.sys
18:50:44.0421 0404 C:\WINDOWS\system32\drivers\raspppoe.sys - ok
18:50:44.0421 0404 [ 0539D5E53587F82D1B4FD74C5BE205CF ] C:\WINDOWS\system32\drivers\tdi.sys
18:50:44.0421 0404 C:\WINDOWS\system32\drivers\tdi.sys - ok
18:50:44.0437 0404 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] C:\WINDOWS\system32\drivers\msgpc.sys
18:50:44.0437 0404 C:\WINDOWS\system32\drivers\msgpc.sys - ok
18:50:44.0437 0404 [ 09298EC810B07E5D582CB3A3F9255424 ] C:\WINDOWS\system32\drivers\psched.sys
18:50:44.0437 0404 C:\WINDOWS\system32\drivers\psched.sys - ok
18:50:44.0437 0404 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] C:\WINDOWS\system32\drivers\raspptp.sys
18:50:44.0437 0404 C:\WINDOWS\system32\drivers\raspptp.sys - ok
18:50:44.0437 0404 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] C:\WINDOWS\system32\drivers\ptilink.sys
18:50:44.0437 0404 C:\WINDOWS\system32\drivers\ptilink.sys - ok
18:50:44.0437 0404 [ 463C1EC80CD17420A542B7F36A36F128 ] C:\WINDOWS\system32\drivers\kbdclass.sys
18:50:44.0437 0404 C:\WINDOWS\system32\drivers\kbdclass.sys - ok
18:50:44.0437 0404 [ 35C9E97194C8CFB8430125F8DBC34D04 ] C:\WINDOWS\system32\drivers\mouclass.sys
18:50:44.0437 0404 C:\WINDOWS\system32\drivers\mouclass.sys - ok
18:50:44.0453 0404 [ FDBB1D60066FCFBB7452FD8F9829B242 ] C:\WINDOWS\system32\drivers\raspti.sys
18:50:44.0453 0404 C:\WINDOWS\system32\drivers\raspti.sys - ok
18:50:44.0453 0404 [ 15CABD0F7C00C47C70124907916AF3F1 ] C:\WINDOWS\system32\drivers\rdpdr.sys
18:50:44.0453 0404 C:\WINDOWS\system32\drivers\rdpdr.sys - ok
18:50:44.0453 0404 [ 88155247177638048422893737429D9E ] C:\WINDOWS\system32\drivers\termdd.sys
18:50:44.0453 0404 C:\WINDOWS\system32\drivers\termdd.sys - ok
18:50:44.0453 0404 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] C:\WINDOWS\system32\drivers\mssmbios.sys
18:50:44.0453 0404 C:\WINDOWS\system32\drivers\mssmbios.sys - ok
18:50:44.0453 0404 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] C:\WINDOWS\system32\drivers\swenum.sys
18:50:44.0453 0404 C:\WINDOWS\system32\drivers\swenum.sys - ok
18:50:44.0453 0404 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] C:\WINDOWS\system32\drivers\update.sys
18:50:44.0453 0404 C:\WINDOWS\system32\drivers\update.sys - ok
18:50:44.0453 0404 [ 9282BD12DFB069D3889EB3FCC1000A9B ] C:\WINDOWS\system32\drivers\ndproxy.sys
18:50:44.0453 0404 C:\WINDOWS\system32\drivers\ndproxy.sys - ok
18:50:44.0468 0404 [ 6CB08593487F5701D2D2254E693EAFCE ] C:\WINDOWS\system32\drivers\drmk.sys
18:50:44.0468 0404 C:\WINDOWS\system32\drivers\drmk.sys - ok
18:50:44.0468 0404 [ E82A496C3961EFC6828B508C310CE98F ] C:\WINDOWS\system32\drivers\portcls.sys
18:50:44.0468 0404 C:\WINDOWS\system32\drivers\portcls.sys - ok
18:50:44.0468 0404 [ 924971A182E07463765EF9FA8876F24F ] C:\WINDOWS\system32\drivers\AtihdXP3.sys
18:50:44.0468 0404 C:\WINDOWS\system32\drivers\AtihdXP3.sys - ok
18:50:44.0468 0404 [ 596EB39B50D6EBD9B734DC4AE0544693 ] C:\WINDOWS\system32\drivers\usbd.sys
18:50:44.0468 0404 C:\WINDOWS\system32\drivers\usbd.sys - ok
18:50:44.0468 0404 [ 1AB3CDDE553B6E064D2E754EFE20285C ] C:\WINDOWS\system32\drivers\usbhub.sys
18:50:44.0468 0404 C:\WINDOWS\system32\drivers\usbhub.sys - ok
18:50:44.0468 0404 [ DBC702FBC70DC58D9122CE56EADBD659 ] C:\WINDOWS\system32\drivers\RtkHDAud.sys
18:50:44.0468 0404 C:\WINDOWS\system32\drivers\RtkHDAud.sys - ok
18:50:44.0468 0404 [ 8E6B8C671615D126FDC553D1E2DE5562 ] C:\WINDOWS\system32\drivers\sfloppy.sys
18:50:44.0468 0404 C:\WINDOWS\system32\drivers\sfloppy.sys - ok
18:50:44.0484 0404 [ C1B486A7658353D33A10CC15211A873B ] C:\WINDOWS\system32\drivers\cdaudio.sys
18:50:44.0484 0404 C:\WINDOWS\system32\drivers\cdaudio.sys - ok
18:50:44.0484 0404 [ 9368670BD426EBEA5E8B18A62416EC28 ] C:\WINDOWS\system32\drivers\i2omgmt.sys
18:50:44.0484 0404 C:\WINDOWS\system32\drivers\i2omgmt.sys - ok
18:50:44.0484 0404 [ 3FCA5C1A8F33CF9857220CC3A3076A3E ] C:\WINDOWS\system32\drivers\aswKbd.sys
18:50:44.0484 0404 C:\WINDOWS\system32\drivers\aswKbd.sys - ok
18:50:44.0484 0404 [ 91886FED52A3F9966207BCE46CFD794F ] C:\WINDOWS\system32\drivers\DLARTL_M.SYS
18:50:44.0484 0404 C:\WINDOWS\system32\drivers\DLARTL_M.SYS - ok
18:50:44.0484 0404 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] C:\WINDOWS\system32\drivers\fs_rec.sys
18:50:44.0484 0404 C:\WINDOWS\system32\drivers\fs_rec.sys - ok
18:50:44.0484 0404 [ 96ECCF28FDBF1B2CC12725818A63628D ] C:\WINDOWS\system32\drivers\hidparse.sys
18:50:44.0484 0404 C:\WINDOWS\system32\drivers\hidparse.sys - ok
18:50:44.0500 0404 [ 4A0B06AA8943C1E332520F7440C0AA30 ] C:\WINDOWS\system32\drivers\i8042prt.sys
18:50:44.0500 0404 C:\WINDOWS\system32\drivers\i8042prt.sys - ok
18:50:44.0500 0404 [ 9EF487A186DEA361AA06913A75B3FA99 ] C:\WINDOWS\system32\drivers\kbdhid.sys
18:50:44.0500 0404 C:\WINDOWS\system32\drivers\kbdhid.sys - ok
18:50:44.0500 0404 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] C:\WINDOWS\system32\drivers\mnmdd.sys
18:50:44.0500 0404 C:\WINDOWS\system32\drivers\mnmdd.sys - ok
18:50:44.0500 0404 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] C:\WINDOWS\system32\drivers\null.sys
18:50:44.0500 0404 C:\WINDOWS\system32\drivers\null.sys - ok
18:50:44.0500 0404 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] C:\WINDOWS\system32\drivers\vga.sys
18:50:44.0500 0404 C:\WINDOWS\system32\drivers\vga.sys - ok
18:50:44.0500 0404 [ C941EA2454BA8350021D774DAF0F1027 ] C:\WINDOWS\system32\drivers\msfs.sys
18:50:44.0500 0404 C:\WINDOWS\system32\drivers\msfs.sys - ok
18:50:44.0500 0404 [ 3182D64AE053D6FB034F44B6DEF8034A ] C:\WINDOWS\system32\drivers\npfs.sys
18:50:44.0515 0404 C:\WINDOWS\system32\drivers\npfs.sys - ok
18:50:44.0515 0404 [ 4912D5B403614CE99C28420F75353332 ] C:\WINDOWS\system32\drivers\rdpcdd.sys
18:50:44.0515 0404 C:\WINDOWS\system32\drivers\rdpcdd.sys - ok
18:50:44.0515 0404 [ 1F71F170D90E42EFDE9633D81D5E12DC ] C:\WINDOWS\system32\drivers\aswTdi.sys
18:50:44.0515 0404 C:\WINDOWS\system32\drivers\aswTdi.sys - ok
18:50:44.0515 0404 [ CC748EA12C6EFFDE940EE98098BF96BB ] C:\WINDOWS\system32\drivers\ipnat.sys
18:50:44.0515 0404 C:\WINDOWS\system32\drivers\ipnat.sys - ok
18:50:44.0515 0404 [ 23C74D75E36E7158768DD63D92789A91 ] C:\WINDOWS\system32\drivers\ipsec.sys
18:50:44.0515 0404 C:\WINDOWS\system32\drivers\ipsec.sys - ok
18:50:44.0515 0404 [ FE0D99D6F31E4FAD8159F690D68DED9C ] C:\WINDOWS\system32\drivers\rasacd.sys
18:50:44.0515 0404 C:\WINDOWS\system32\drivers\rasacd.sys - ok
18:50:44.0515 0404 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] C:\WINDOWS\system32\drivers\tcpip.sys
18:50:44.0515 0404 C:\WINDOWS\system32\drivers\tcpip.sys - ok
18:50:44.0531 0404 [ 7B43265F92257A21CBFD88E7A651044C ] C:\WINDOWS\system32\drivers\aswRdr.sys
18:50:44.0531 0404 C:\WINDOWS\system32\drivers\aswRdr.sys - ok
18:50:44.0531 0404 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] C:\WINDOWS\system32\drivers\netbt.sys
18:50:44.0531 0404 C:\WINDOWS\system32\drivers\netbt.sys - ok
18:50:44.0531 0404 [ E20B95BAEDB550F32DD489265C1DA1F6 ] C:\WINDOWS\system32\drivers\wanarp.sys
18:50:44.0531 0404 C:\WINDOWS\system32\drivers\wanarp.sys - ok
18:50:44.0531 0404 [ 6ABE6E225ADB5A751622A9CC3BC19CE8 ] C:\WINDOWS\system32\drivers\ws2ifsl.sys
18:50:44.0531 0404 C:\WINDOWS\system32\drivers\ws2ifsl.sys - ok
18:50:44.0531 0404 [ 1E44BC1E83D8FD2305F8D452DB109CF9 ] C:\WINDOWS\system32\drivers\afd.sys
18:50:44.0531 0404 C:\WINDOWS\system32\drivers\afd.sys - ok
18:50:44.0531 0404 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] C:\WINDOWS\system32\drivers\netbios.sys
18:50:44.0531 0404 C:\WINDOWS\system32\drivers\netbios.sys - ok
18:50:44.0531 0404 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] C:\WINDOWS\system32\drivers\serial.sys
18:50:44.0531 0404 C:\WINDOWS\system32\drivers\serial.sys - ok
18:50:44.0546 0404 [ 7D304A5EB4344EBEEAB53A2FE3FFB9F0 ] C:\WINDOWS\system32\drivers\mrxsmb.sys
18:50:44.0546 0404 C:\WINDOWS\system32\drivers\mrxsmb.sys - ok
18:50:44.0546 0404 [ 7AD224AD1A1437FE28D89CF22B17780A ] C:\WINDOWS\system32\drivers\rdbss.sys
18:50:44.0546 0404 C:\WINDOWS\system32\drivers\rdbss.sys - ok
18:50:44.0546 0404 [ 99102F60F344BEBAF4F6114514FD28D3 ] C:\WINDOWS\system32\drivers\aswSP.sys
18:50:44.0546 0404 C:\WINDOWS\system32\drivers\aswSP.sys - ok
18:50:44.0546 0404 [ D45926117EB9FA946A6AF572FBE1CAA3 ] C:\WINDOWS\system32\drivers\fips.sys
18:50:44.0546 0404 C:\WINDOWS\system32\drivers\fips.sys - ok
18:50:44.0546 0404 [ 6CAB0A5991C5C0FC63F5E66593E71D7E ] C:\WINDOWS\system32\drivers\aswSnx.sys
18:50:44.0546 0404 C:\WINDOWS\system32\drivers\aswSnx.sys - ok
18:50:44.0546 0404 [ F8F0D25CA553E39DDE485D8FC7FCCE89 ] C:\WINDOWS\system32\ntdll.dll
18:50:44.0546 0404 C:\WINDOWS\system32\ntdll.dll - ok
18:50:44.0562 0404 [ 5F816C1F539266D2D4C78694239DA0B5 ] C:\WINDOWS\system32\smss.exe
18:50:44.0562 0404 C:\WINDOWS\system32\smss.exe - ok
18:50:44.0562 0404 [ 23043C91A0F9DFB4B9E9F87B680863B4 ] C:\WINDOWS\system32\autochk.exe
18:50:44.0562 0404 C:\WINDOWS\system32\autochk.exe - ok
18:50:44.0562 0404 [ A9C25C9A8F9DA7F25C14D84C4CE845A3 ] C:\WINDOWS\system32\sdnclean.exe
18:50:44.0562 0404 C:\WINDOWS\system32\sdnclean.exe - ok
18:50:44.0562 0404 [ CFE4114B963AB0AB22F6EBEF89564194 ] C:\WINDOWS\system32\aswBoot.exe
18:50:44.0562 0404 C:\WINDOWS\system32\aswBoot.exe - ok
18:50:44.0562 0404 [ 9DD07AF82244867CA36681EA2D29CE79 ] C:\WINDOWS\system32\sfcfiles.dll
18:50:44.0562 0404 C:\WINDOWS\system32\sfcfiles.dll - ok
18:50:44.0562 0404 [ 1AF592532532A402ED7C060F6954004F ] C:\WINDOWS\system32\drivers\hidclass.sys
18:50:44.0562 0404 C:\WINDOWS\system32\drivers\hidclass.sys - ok
18:50:44.0562 0404 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] C:\WINDOWS\system32\drivers\hidusb.sys
18:50:44.0562 0404 C:\WINDOWS\system32\drivers\hidusb.sys - ok
18:50:44.0578 0404 [ A32426D9B14A089EAA1D922E0C5801A9 ] C:\WINDOWS\system32\drivers\usbstor.sys
18:50:44.0578 0404 C:\WINDOWS\system32\drivers\usbstor.sys - ok
18:50:44.0578 0404 [ B1C303E17FB9D46E87A98E4BA6769685 ] C:\WINDOWS\system32\drivers\mouhid.sys
18:50:44.0578 0404 C:\WINDOWS\system32\drivers\mouhid.sys - ok
18:50:44.0578 0404 [ C885B02847F5D2FD45A24E219ED93B32 ] C:\WINDOWS\system32\drivers\cdfs.sys
18:50:44.0578 0404 C:\WINDOWS\system32\drivers\cdfs.sys - ok
18:50:44.0578 0404 [ 2F31B7F954BED437F2C75026C65CAF7B ] C:\WINDOWS\system32\drivers\wmilib.sys
18:50:44.0578 0404 C:\WINDOWS\system32\drivers\wmilib.sys - ok
18:50:44.0578 0404 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] C:\WINDOWS\system32\drivers\atapi.sys
18:50:44.0578 0404 C:\WINDOWS\system32\drivers\atapi.sys - ok
18:50:44.0578 0404 [ FE97D0343ACFDEBDD578FC67CC91FA87 ] C:\WINDOWS\system32\drivers\dxapi.sys
18:50:44.0578 0404 C:\WINDOWS\system32\drivers\dxapi.sys - ok
18:50:44.0578 0404 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] C:\WINDOWS\system32\basesrv.dll
18:50:44.0578 0404 C:\WINDOWS\system32\basesrv.dll - ok
18:50:44.0593 0404 [ DD40363ABAD230A84C5E2178B11EFA88 ] C:\WINDOWS\system32\csrsrv.dll
18:50:44.0593 0404 C:\WINDOWS\system32\csrsrv.dll - ok
18:50:44.0593 0404 [ 44F275C64738EA2056E3D9580C23B60F ] C:\WINDOWS\system32\csrss.exe
18:50:44.0593 0404 C:\WINDOWS\system32\csrss.exe - ok
18:50:44.0593 0404 [ 9A10AACBFDC4922715375FB4065EC930 ] C:\WINDOWS\system32\watchdog.sys
18:50:44.0593 0404 C:\WINDOWS\system32\watchdog.sys - ok
18:50:44.0593 0404 [ FC8A1F72A8097910A11D5184BC3F887B ] C:\WINDOWS\system32\win32k.sys
18:50:44.0593 0404 C:\WINDOWS\system32\win32k.sys - ok
18:50:44.0593 0404 [ 69AE2B2E6968C316536E5B10B9702E63 ] C:\WINDOWS\system32\winsrv.dll
18:50:44.0593 0404 C:\WINDOWS\system32\winsrv.dll - ok
18:50:44.0593 0404 [ 8B1F3320AEBB536E021A5014409862DE ] C:\WINDOWS\system32\gdi32.dll
18:50:44.0593 0404 C:\WINDOWS\system32\gdi32.dll - ok
18:50:44.0609 0404 [ 6FE42512AB1B89F32A7407F261B1D2D0 ] C:\WINDOWS\system32\kernel32.dll
18:50:44.0609 0404 C:\WINDOWS\system32\kernel32.dll - ok
18:50:44.0609 0404 [ B26B135FF1B9F60C9388B4A7D16F600B ] C:\WINDOWS\system32\user32.dll
18:50:44.0609 0404 C:\WINDOWS\system32\user32.dll - ok
18:50:44.0609 0404 [ AC7280566A7BB85CB3291F04DDC1198E ] C:\WINDOWS\system32\drivers\dxg.sys
18:50:44.0609 0404 C:\WINDOWS\system32\drivers\dxg.sys - ok
18:50:44.0609 0404 [ A73F5D6705B1D820C19B18782E176EFD ] C:\WINDOWS\system32\drivers\dxgthk.sys
18:50:44.0609 0404 C:\WINDOWS\system32\drivers\dxgthk.sys - ok
18:50:44.0609 0404 [ F4766B84FF45A8181748C159580603A1 ] C:\WINDOWS\system32\ati2dvag.dll
18:50:44.0609 0404 C:\WINDOWS\system32\ati2dvag.dll - ok
18:50:44.0609 0404 [ BED6ECC514D45A53EB4899DC83F27FAC ] C:\WINDOWS\system32\ati2cqag.dll
18:50:44.0609 0404 C:\WINDOWS\system32\ati2cqag.dll - ok
18:50:44.0609 0404 [ 7A6569483AC12444681B9F486180B349 ] C:\WINDOWS\system32\atikvmag.dll
18:50:44.0609 0404 C:\WINDOWS\system32\atikvmag.dll - ok
18:50:44.0625 0404 [ ECB7591870F8BFB1A4C17B718AD5A4AA ] C:\WINDOWS\system32\vga.dll
18:50:44.0625 0404 C:\WINDOWS\system32\vga.dll - ok
18:50:44.0625 0404 [ 95FDC2E44C94C8DD7108409E5891893C ] C:\WINDOWS\system32\atiok3x2.dll
18:50:44.0625 0404 C:\WINDOWS\system32\atiok3x2.dll - ok
18:50:44.0625 0404 [ 5B096B2714FA2CE99A04992A5A6B85D3 ] C:\WINDOWS\system32\ati3duag.dll
18:50:44.0625 0404 C:\WINDOWS\system32\ati3duag.dll - ok
18:50:44.0625 0404 [ DE729DEC115A62387359D1AA3C612F84 ] C:\WINDOWS\system32\ativvaxx.dll
18:50:44.0625 0404 C:\WINDOWS\system32\ativvaxx.dll - ok
18:50:44.0625 0404 [ ED0EF0A136DEC83DF69F04118870003E ] C:\WINDOWS\system32\winlogon.exe
18:50:44.0625 0404 C:\WINDOWS\system32\winlogon.exe - ok
18:50:44.0625 0404 [ E76F8807070ED04E7408A86D6D3A6137 ] C:\WINDOWS\system32\advapi32.dll
18:50:44.0625 0404 C:\WINDOWS\system32\advapi32.dll - ok
18:50:44.0640 0404 [ D4502F124289A31976130CCCB014C9AA ] C:\WINDOWS\system32\rpcrt4.dll
18:50:44.0640 0404 C:\WINDOWS\system32\rpcrt4.dll - ok
18:50:44.0640 0404 [ 714705F29A917993536A6AB2DEDB0B7F ] C:\WINDOWS\system32\authz.dll
18:50:44.0640 0404 C:\WINDOWS\system32\authz.dll - ok
18:50:44.0640 0404 [ 355EDBB4D412B01F1740C17E3F50FA00 ] C:\WINDOWS\system32\msvcrt.dll
18:50:44.0640 0404 C:\WINDOWS\system32\msvcrt.dll - ok
18:50:44.0640 0404 [ 5357826C8A8DD6A07F17C48BB45BE46E ] C:\WINDOWS\system32\secur32.dll
18:50:44.0640 0404 C:\WINDOWS\system32\secur32.dll - ok
18:50:44.0640 0404 [ 6BEE5D4EFF0A0341BCC4A462D81CCFC1 ] C:\WINDOWS\system32\crypt32.dll
18:50:44.0640 0404 C:\WINDOWS\system32\crypt32.dll - ok
18:50:44.0640 0404 [ 04D898830DF96A17A20FD35D7590F87E ] C:\WINDOWS\system32\msasn1.dll
18:50:44.0640 0404 C:\WINDOWS\system32\msasn1.dll - ok
18:50:44.0640 0404 [ 013C1148C1EC025596896E093F60F608 ] C:\WINDOWS\system32\nddeapi.dll
18:50:44.0640 0404 C:\WINDOWS\system32\nddeapi.dll - ok
18:50:44.0656 0404 [ CAC752BF84DB4666ED3CE0948E6EA937 ] C:\WINDOWS\system32\netapi32.dll
18:50:44.0656 0404 C:\WINDOWS\system32\netapi32.dll - ok
18:50:44.0656 0404 [ FCFA1C55971CC229D353B3A15ACCD995 ] C:\WINDOWS\system32\profmap.dll
18:50:44.0656 0404 C:\WINDOWS\system32\profmap.dll - ok
18:50:44.0656 0404 [ 43D13C80EBEC0135A3611E0F616F179B ] C:\WINDOWS\system32\userenv.dll
18:50:44.0656 0404 C:\WINDOWS\system32\userenv.dll - ok
18:50:44.0656 0404 [ 9CFCB3CA3D83B4EAA133F0644A2C6F31 ] C:\WINDOWS\system32\psapi.dll
18:50:44.0656 0404 C:\WINDOWS\system32\psapi.dll - ok
18:50:44.0656 0404 [ AF11C591F2F4AFF4A6CF699D376F618B ] C:\WINDOWS\system32\regapi.dll
18:50:44.0656 0404 C:\WINDOWS\system32\regapi.dll - ok
18:50:44.0656 0404 [ 24192246760E0E64435522E246B1D6C2 ] C:\WINDOWS\system32\setupapi.dll
18:50:44.0656 0404 C:\WINDOWS\system32\setupapi.dll - ok
18:50:44.0671 0404 [ C7CE131408739B0B3A318BE2D0032719 ] C:\WINDOWS\system32\version.dll
18:50:44.0671 0404 C:\WINDOWS\system32\version.dll - ok
18:50:44.0671 0404 [ 430CEB794F6E6EF8AC86958C242366D6 ] C:\WINDOWS\system32\winsta.dll
18:50:44.0671 0404 C:\WINDOWS\system32\winsta.dll - ok
18:50:44.0671 0404 [ D458B738B4C2CE33174CFB2CE12412DB ] C:\WINDOWS\system32\wintrust.dll
18:50:44.0671 0404 C:\WINDOWS\system32\wintrust.dll - ok
18:50:44.0671 0404 [ FFC01A72D1C25CCB39F61B202CE60819 ] C:\WINDOWS\system32\imagehlp.dll
18:50:44.0671 0404 C:\WINDOWS\system32\imagehlp.dll - ok
18:50:44.0671 0404 [ 2CCC474EB85CEAA3E1FA1726580A3E5A ] C:\WINDOWS\system32\ws2_32.dll
18:50:44.0671 0404 C:\WINDOWS\system32\ws2_32.dll - ok
18:50:44.0671 0404 [ 0DA85218E92526972A821587E6A8BF8F ] C:\WINDOWS\system32\imm32.dll
18:50:44.0671 0404 C:\WINDOWS\system32\imm32.dll - ok
18:50:44.0671 0404 [ 56C5B179FE3308B655EB6208C3256FEC ] C:\WINDOWS\system32\kbdus.dll
18:50:44.0671 0404 C:\WINDOWS\system32\kbdus.dll - ok
18:50:44.0687 0404 [ 9789E95E1D88EEB4B922BF3EA7779C28 ] C:\WINDOWS\system32\ws2help.dll
18:50:44.0687 0404 C:\WINDOWS\system32\ws2help.dll - ok
18:50:44.0687 0404 [ D7B7A57C0E57C836F18CF12A4C62A1CA ] C:\WINDOWS\system32\msgina.dll
18:50:44.0687 0404 C:\WINDOWS\system32\msgina.dll - ok
18:50:44.0687 0404 [ 93AFB83FBC1F9443CAC722FCA63D73BF ] C:\WINDOWS\system32\comctl32.dll
18:50:44.0687 0404 C:\WINDOWS\system32\comctl32.dll - ok
18:50:44.0687 0404 [ 40B0F98BAD16AD5DEF894E88C3EF8014 ] C:\WINDOWS\system32\odbc32.dll
18:50:44.0687 0404 C:\WINDOWS\system32\odbc32.dll - ok
18:50:44.0687 0404 [ 86987A5000DFA3EBE2275C0456BCF2FE ] C:\WINDOWS\system32\comdlg32.dll
18:50:44.0687 0404 C:\WINDOWS\system32\comdlg32.dll - ok
18:50:44.0687 0404 [ 6843D54BC4A40CC8C5741AF750233D10 ] C:\WINDOWS\system32\shell32.dll
18:50:44.0687 0404 C:\WINDOWS\system32\shell32.dll - ok
18:50:44.0703 0404 [ C448A248B743F5FB935C787A5D97268B ] C:\WINDOWS\system32\shlwapi.dll
18:50:44.0703 0404 C:\WINDOWS\system32\shlwapi.dll - ok
18:50:44.0703 0404 [ 694503348B586E99D56C0E30AB5B3EF8 ] C:\WINDOWS\system32\sxs.dll
18:50:44.0703 0404 C:\WINDOWS\system32\sxs.dll - ok
18:50:44.0703 0404 [ 736B12B725AEB2B07F0241A9F680CB10 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
18:50:44.0703 0404 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll - ok
18:50:44.0703 0404 [ 6B7C6B32F8E84D56C6260D684019FEA2 ] C:\WINDOWS\system32\odbcint.dll
18:50:44.0703 0404 C:\WINDOWS\system32\odbcint.dll - ok
18:50:44.0703 0404 [ 6BAD1BED9872E62049E487FB91AE2F3A ] C:\WINDOWS\system32\ole32.dll
18:50:44.0703 0404 C:\WINDOWS\system32\ole32.dll - ok
18:50:44.0703 0404 [ 96E1C926F22EE1BFBAE82901A35F6BF3 ] C:\WINDOWS\system32\sfc.dll
18:50:44.0703 0404 C:\WINDOWS\system32\sfc.dll - ok
18:50:44.0703 0404 [ 6B5DB6789177A4FD0DEBC248041D0739 ] C:\WINDOWS\system32\sfc_os.dll
18:50:44.0703 0404 C:\WINDOWS\system32\sfc_os.dll - ok
18:50:44.0718 0404 [ 99BC0B50F511924348BE19C7C7313BBF ] C:\WINDOWS\system32\shsvcs.dll
18:50:44.0718 0404 C:\WINDOWS\system32\shsvcs.dll - ok
18:50:44.0718 0404 [ CF492D7E9AF1C628B3536D20EF6F5CC7 ] C:\WINDOWS\system32\apphelp.dll
18:50:44.0718 0404 C:\WINDOWS\system32\apphelp.dll - ok
18:50:44.0718 0404 [ BF2466B3E18E970D8A976FB95FC1CA85 ] C:\WINDOWS\system32\lsass.exe
18:50:44.0718 0404 C:\WINDOWS\system32\lsass.exe - ok
18:50:44.0718 0404 [ 65DF52F5B8B6E9BBD183505225C37315 ] C:\WINDOWS\system32\services.exe
18:50:44.0718 0404 C:\WINDOWS\system32\services.exe - ok
18:50:44.0718 0404 [ BD31DC6DBE9333C4FBD4BDF0899F2160 ] C:\WINDOWS\system32\lsasrv.dll
18:50:44.0718 0404 C:\WINDOWS\system32\lsasrv.dll - ok
18:50:44.0718 0404 [ EC29A79F1E76DC509E24D401F29D0678 ] C:\WINDOWS\system32\ncobjapi.dll
18:50:44.0718 0404 C:\WINDOWS\system32\ncobjapi.dll - ok
18:50:44.0718 0404 [ F404830F3CD9BF8F2515E489C0CDA297 ] C:\WINDOWS\system32\msvcp60.dll
18:50:44.0718 0404 C:\WINDOWS\system32\msvcp60.dll - ok
18:50:44.0734 0404 [ B24A42A413E694AD73FDFB7FBD492C31 ] C:\WINDOWS\system32\scesrv.dll
18:50:44.0734 0404 C:\WINDOWS\system32\scesrv.dll - ok
18:50:44.0734 0404 [ DD7BD97FB8BD800963789158A5E4B41D ] C:\WINDOWS\system32\mpr.dll
18:50:44.0734 0404 C:\WINDOWS\system32\mpr.dll - ok
18:50:44.0734 0404 [ 2EDFC2A8893435723AD80481803C6D5C ] C:\WINDOWS\system32\umpnpmgr.dll
18:50:44.0734 0404 C:\WINDOWS\system32\umpnpmgr.dll - ok
18:50:44.0734 0404 [ EC4C0D9BFD9F7E33F8B395AD54E13063 ] C:\WINDOWS\system32\ntdsapi.dll
18:50:44.0734 0404 C:\WINDOWS\system32\ntdsapi.dll - ok
18:50:44.0734 0404 [ EA9EE60B408878E5F2012F9C783836DB ] C:\WINDOWS\AppPatch\acadproc.dll
18:50:44.0734 0404 C:\WINDOWS\AppPatch\acadproc.dll - ok
18:50:44.0734 0404 [ 389496118B3B03C2328024AF320132AC ] C:\WINDOWS\system32\dnsapi.dll
18:50:44.0734 0404 C:\WINDOWS\system32\dnsapi.dll - ok
18:50:44.0750 0404 [ 1F03103598BD817B1078DAB1326DDE11 ] C:\WINDOWS\system32\shimeng.dll
18:50:44.0750 0404 C:\WINDOWS\system32\shimeng.dll - ok
18:50:44.0750 0404 [ 0492CF5870F0E616B0C71695A433D162 ] C:\WINDOWS\system32\wldap32.dll
18:50:44.0750 0404 C:\WINDOWS\system32\wldap32.dll - ok
18:50:44.0750 0404 [ 8329A39D5A402A75A74301D6A62ECDA1 ] C:\WINDOWS\system32\samlib.dll
18:50:44.0750 0404 C:\WINDOWS\system32\samlib.dll - ok
18:50:44.0750 0404 [ 17A1D675C12BBF80CAAC54A4855C41D0 ] C:\WINDOWS\system32\cryptdll.dll
18:50:44.0750 0404 C:\WINDOWS\system32\cryptdll.dll - ok
18:50:44.0750 0404 [ F05B8CDB7FE0E55DCCFB1D946CE80064 ] C:\WINDOWS\system32\samsrv.dll
18:50:44.0750 0404 C:\WINDOWS\system32\samsrv.dll - ok
18:50:44.0750 0404 [ 310C15FD8358B2C4CD7A5B98A112883F ] C:\WINDOWS\AppPatch\acgenral.dll
18:50:44.0750 0404 C:\WINDOWS\AppPatch\acgenral.dll - ok
18:50:44.0750 0404 [ EFF03460E542EEA6B0ABDEC6BF19C897 ] C:\WINDOWS\system32\oleaut32.dll
18:50:44.0750 0404 C:\WINDOWS\system32\oleaut32.dll - ok
18:50:44.0765 0404 [ 4A953F13942867BA8FB41F141EC1B80C ] C:\WINDOWS\system32\winmm.dll
18:50:44.0765 0404 C:\WINDOWS\system32\winmm.dll - ok
18:50:44.0765 0404 [ 2098AB52BD5316E59AA36F3437B13BE6 ] C:\WINDOWS\system32\msacm32.dll
18:50:44.0765 0404 C:\WINDOWS\system32\msacm32.dll - ok
18:50:44.0765 0404 [ 7A2CC3719B255E6B5D74396183B7715B ] C:\WINDOWS\system32\uxtheme.dll
18:50:44.0765 0404 C:\WINDOWS\system32\uxtheme.dll - ok
18:50:44.0765 0404 [ F24B12786D60A17008319E3F2AEE7799 ] C:\WINDOWS\system32\msapsspc.dll
18:50:44.0765 0404 C:\WINDOWS\system32\msapsspc.dll - ok
18:50:44.0765 0404 [ 7A660EDC0757849DF5F8706FB6E9F740 ] C:\WINDOWS\system32\msvcrt40.dll
18:50:44.0765 0404 C:\WINDOWS\system32\msvcrt40.dll - ok
18:50:44.0765 0404 [ 0F64207B49390C8063C36AE7CBF9C2DB ] C:\WINDOWS\system32\schannel.dll
18:50:44.0765 0404 C:\WINDOWS\system32\schannel.dll - ok
18:50:44.0765 0404 [ 3D76DD0CBC536E0F8C45D23ED230BEB2 ] C:\WINDOWS\system32\digest.dll
18:50:44.0765 0404 C:\WINDOWS\system32\digest.dll - ok
18:50:44.0781 0404 [ A4388DF80E52695AE92EE5F3F61F1619 ] C:\WINDOWS\system32\msnsspc.dll
18:50:44.0781 0404 C:\WINDOWS\system32\msnsspc.dll - ok
18:50:44.0781 0404 [ A525C96C51D55111FDF3BEA9FFFFC7AE ] C:\WINDOWS\system32\kerberos.dll
18:50:44.0781 0404 C:\WINDOWS\system32\kerberos.dll - ok
18:50:44.0781 0404 [ 5733177BCF16EE78B99543C9B0AB81EA ] C:\WINDOWS\system32\msctfime.ime
18:50:44.0781 0404 C:\WINDOWS\system32\msctfime.ime - ok
18:50:44.0781 0404 [ C6BB1D1500DB4A0E224CB65E6C7E8A80 ] C:\WINDOWS\system32\msprivs.dll
18:50:44.0781 0404 C:\WINDOWS\system32\msprivs.dll - ok
18:50:44.0781 0404 [ C11D10A3C164AC222BC9AAB3650A88B3 ] C:\WINDOWS\system32\atmfd.dll
18:50:44.0781 0404 C:\WINDOWS\system32\atmfd.dll - ok
18:50:44.0781 0404 [ AF07DC9B7CC455629E732340C7B15F3A ] C:\WINDOWS\system32\iphlpapi.dll
18:50:44.0781 0404 C:\WINDOWS\system32\iphlpapi.dll - ok
18:50:44.0781 0404 [ 517561A1113B04E51D936CD018DE1C1F ] C:\WINDOWS\system32\msv1_0.dll
18:50:44.0781 0404 C:\WINDOWS\system32\msv1_0.dll - ok
18:50:44.0796 0404 [ 1B7F071C51B77C272875C3A23E1E4550 ] C:\WINDOWS\system32\netlogon.dll
18:50:44.0796 0404 C:\WINDOWS\system32\netlogon.dll - ok
18:50:44.0796 0404 [ 54AF4B1D5459500EF0937F6D33B1914F ] C:\WINDOWS\system32\w32time.dll
18:50:44.0796 0404 C:\WINDOWS\system32\w32time.dll - ok
18:50:44.0796 0404 [ 54DAE3EA34802B4ED9AE1C6B1209FA56 ] C:\WINDOWS\system32\rsaenh.dll
18:50:44.0796 0404 C:\WINDOWS\system32\rsaenh.dll - ok
18:50:44.0796 0404 [ 3AAF9B35939FF9E58CCD18D41655C2FC ] C:\WINDOWS\system32\wdigest.dll
18:50:44.0796 0404 C:\WINDOWS\system32\wdigest.dll - ok
18:50:44.0796 0404 [ 02988B904C386B500CD08639C4C20EEA ] C:\WINDOWS\system32\winscard.dll
18:50:44.0796 0404 C:\WINDOWS\system32\winscard.dll - ok
18:50:44.0796 0404 [ 0E2735281FBB9A764D5584C2A5DCBA59 ] C:\WINDOWS\system32\wtsapi32.dll
18:50:44.0796 0404 C:\WINDOWS\system32\wtsapi32.dll - ok
18:50:44.0812 0404 [ A86BB5E61BF3E39B62AB4C7E7085A084 ] C:\WINDOWS\system32\scecli.dll
18:50:44.0812 0404 C:\WINDOWS\system32\scecli.dll - ok
18:50:44.0812 0404 [ 4AF5F360BA1E8794D32B366E45A64A0A ] C:\WINDOWS\system32\drivers\aswFsBlk.sys
18:50:44.0812 0404 C:\WINDOWS\system32\drivers\aswFsBlk.sys - ok
18:50:44.0812 0404 [ 1F7094D4268D46F718C51286DC189791 ] C:\WINDOWS\system32\drivers\aswMonFlt.sys
18:50:44.0812 0404 C:\WINDOWS\system32\drivers\aswMonFlt.sys - ok
18:50:44.0812 0404 [ 6E6AB29D3C06E64CE81FEACDA85394B5 ] C:\WINDOWS\system32\drivers\DRVNDDM.SYS
18:50:44.0812 0404 C:\WINDOWS\system32\drivers\DRVNDDM.SYS - ok
18:50:44.0812 0404 [ 43E17DA549BC8219EEE90AA9C6480AAA ] C:\WINDOWS\system32\ati2evxx.exe
18:50:44.0812 0404 C:\WINDOWS\system32\ati2evxx.exe - ok
18:50:44.0812 0404 [ 0659E6E0A95564F958D9DF7313F7701E ] C:\WINDOWS\system32\DLA\DLABMFSM.SYS
18:50:44.0812 0404 C:\WINDOWS\system32\DLA\DLABMFSM.SYS - ok
18:50:44.0812 0404 [ 8691C78908F0BD66170669DB268369F2 ] C:\WINDOWS\system32\DLA\DLABOIOM.SYS
18:50:44.0812 0404 C:\WINDOWS\system32\DLA\DLABOIOM.SYS - ok
18:50:44.0828 0404 [ 5615744A1056933B90E6AC54FEB86F35 ] C:\WINDOWS\system32\DLA\DLADResM.SYS
18:50:44.0828 0404 C:\WINDOWS\system32\DLA\DLADResM.SYS - ok
18:50:44.0828 0404 [ 1AECA2AFA5005CE4A550CF8EB55A8C88 ] C:\WINDOWS\system32\DLA\DLAIFS_M.SYS
18:50:44.0828 0404 C:\WINDOWS\system32\DLA\DLAIFS_M.SYS - ok
18:50:44.0828 0404 [ 840E7F6ABB885C72B9FFDDB022EF5B6D ] C:\WINDOWS\system32\DLA\DLAOPIOM.SYS
18:50:44.0828 0404 C:\WINDOWS\system32\DLA\DLAOPIOM.SYS - ok
18:50:44.0828 0404 [ 0294D18731AC05DA80132CE88F8A876B ] C:\WINDOWS\system32\DLA\DLAPoolM.SYS
18:50:44.0828 0404 C:\WINDOWS\system32\DLA\DLAPoolM.SYS - ok
18:50:44.0828 0404 [ CCA4E121D599D7D1706A30F603731E59 ] C:\WINDOWS\system32\DLA\DLAUDFAM.SYS
18:50:44.0828 0404 C:\WINDOWS\system32\DLA\DLAUDFAM.SYS - ok
18:50:44.0828 0404 [ 7DAB85C33135DF24419951DA4E7D38E5 ] C:\WINDOWS\system32\DLA\DLAUDF_M.SYS
18:50:44.0828 0404 C:\WINDOWS\system32\DLA\DLAUDF_M.SYS - ok
18:50:44.0828 0404 [ 50A166237A0FA771261275A405646CC0 ] C:\WINDOWS\system32\powrprof.dll
18:50:44.0828 0404 C:\WINDOWS\system32\powrprof.dll - ok
18:50:44.0843 0404 [ 5F0CE62E0831CF972EC6949FD3E37DA7 ] C:\WINDOWS\system32\cfgmgr32.dll
18:50:44.0843 0404 C:\WINDOWS\system32\cfgmgr32.dll - ok
18:50:44.0843 0404 [ 27C6D03BCDB8CFEB96B716F3D8BE3E18 ] C:\WINDOWS\system32\svchost.exe
18:50:44.0843 0404 C:\WINDOWS\system32\svchost.exe - ok
18:50:44.0843 0404 [ 549290DBC280C887681D7652978DBBE0 ] C:\WINDOWS\system32\ntmarta.dll
18:50:44.0843 0404 C:\WINDOWS\system32\ntmarta.dll - ok
18:50:44.0843 0404 [ 6B27A5C03DFB94B4245739065431322C ] C:\WINDOWS\system32\rpcss.dll
18:50:44.0843 0404 C:\WINDOWS\system32\rpcss.dll - ok
18:50:44.0843 0404 [ 16403217AB6FC5C30C14C6B12098AD4B ] C:\WINDOWS\system32\xpsp2res.dll
18:50:44.0843 0404 C:\WINDOWS\system32\xpsp2res.dll - ok
18:50:44.0843 0404 [ 6D4FEB43EE538FC5428CC7F0565AA656 ] C:\WINDOWS\system32\eventlog.dll
18:50:44.0843 0404 C:\WINDOWS\system32\eventlog.dll - ok
18:50:44.0843 0404 [ 632AFDAB679D581A69DD6722F189A975 ] C:\WINDOWS\system32\ati2edxx.dll
18:50:44.0843 0404 C:\WINDOWS\system32\ati2edxx.dll - ok
18:50:44.0859 0404 [ 2081A5B5E4ABA206A0A8A1A97DF0FB23 ] C:\WINDOWS\system32\logonui.exe
18:50:44.0859 0404 C:\WINDOWS\system32\logonui.exe - ok
18:50:44.0859 0404 [ 68F70E130A5BE2C7DECA90672DE6F6EB ] C:\WINDOWS\system32\atipdlxx.dll
18:50:44.0859 0404 C:\WINDOWS\system32\atipdlxx.dll - ok
18:50:44.0859 0404 [ 943337D786A56729263071623BBB9DE5 ] C:\WINDOWS\system32\mswsock.dll
18:50:44.0859 0404 C:\WINDOWS\system32\mswsock.dll - ok
18:50:44.0859 0404 [ 3D41A9326F0376FC73AF961DD23B1FB1 ] C:\WINDOWS\system32\duser.dll
18:50:44.0859 0404 C:\WINDOWS\system32\duser.dll - ok
18:50:44.0859 0404 [ 3CB32D3B8CBE79899D63280BB7A83CD9 ] C:\WINDOWS\system32\hnetcfg.dll
18:50:44.0859 0404 C:\WINDOWS\system32\hnetcfg.dll - ok
18:50:44.0859 0404 [ AFFC87E2501FCE8F09D4C10BA6421CCF ] C:\WINDOWS\system32\msimg32.dll
18:50:44.0859 0404 C:\WINDOWS\system32\msimg32.dll - ok
18:50:44.0875 0404 [ 20200EE3CFE10E9F0C028D8653BE11C6 ] C:\WINDOWS\system32\oleacc.dll
18:50:44.0875 0404 C:\WINDOWS\system32\oleacc.dll - ok
18:50:44.0875 0404 [ 4E3D06D6E68EEDB52565080F55B460D3 ] C:\WINDOWS\system32\wshtcpip.dll
18:50:44.0875 0404 C:\WINDOWS\system32\wshtcpip.dll - ok
18:50:44.0875 0404 [ D72B9EC3337B247A666F098F3D6B43DE ] C:\WINDOWS\system32\winrnr.dll
18:50:44.0875 0404 C:\WINDOWS\system32\winrnr.dll - ok
18:50:44.0875 0404 [ F45DD1E1365D857DD08BC23563370D0E ] C:\Program Files\Windows Defender\MsMpEng.exe
18:50:44.0875 0404 C:\Program Files\Windows Defender\MsMpEng.exe - ok
18:50:44.0875 0404 [ 6F9BEF24C578D5D6740E080BEDD6A448 ] C:\WINDOWS\system32\rasadhlp.dll
18:50:44.0875 0404 C:\WINDOWS\system32\rasadhlp.dll - ok
18:50:44.0875 0404 [ F137A0CA70003DB20448D540651FA003 ] C:\WINDOWS\system32\clbcatq.dll
18:50:44.0875 0404 C:\WINDOWS\system32\clbcatq.dll - ok
18:50:44.0875 0404 [ C9564CF4976E7E96B4052737AA2492B4 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll
18:50:44.0875 0404 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcr80.dll - ok
18:50:44.0890 0404 [ 1280A158C722FA95A80FB7AEBE78FA7D ] C:\WINDOWS\system32\comres.dll
18:50:44.0890 0404 C:\WINDOWS\system32\comres.dll - ok
18:50:44.0890 0404 [ 64898BEA32C12BADDA4218BE88DBD595 ] C:\Program Files\Windows Defender\MpSvc.dll
18:50:44.0890 0404 C:\Program Files\Windows Defender\MpSvc.dll - ok
18:50:44.0890 0404 [ 0B3595A4FF0B36D68E5FC67FD7D70FDC ] C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll
18:50:44.0890 0404 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\msvcp80.dll - ok
18:50:44.0890 0404 [ E5EDBD51476DB5001ABF5C82AE5C3DD1 ] C:\WINDOWS\system32\shgina.dll
18:50:44.0890 0404 C:\WINDOWS\system32\shgina.dll - ok
18:50:44.0890 0404 [ 6F44DD636C791B70ADE78FE974BE0A1D ] C:\Program Files\Windows Defender\MpClient.dll
18:50:44.0890 0404 C:\Program Files\Windows Defender\MpClient.dll - ok
18:50:44.0890 0404 [ F927A4434C5028758A842943EF1A3849 ] C:\WINDOWS\system32\drivers\ndisuio.sys
18:50:44.0890 0404 C:\WINDOWS\system32\drivers\ndisuio.sys - ok
18:50:44.0906 0404 [ 5E38D7684A49CACFB752B046357E0589 ] C:\WINDOWS\system32\dhcpcsvc.dll
18:50:44.0906 0404 C:\WINDOWS\system32\dhcpcsvc.dll - ok
18:50:44.0906 0404 [ 85E6133E81BDB7BCB705C9FC552D03A8 ] C:\WINDOWS\system32\ati2evxx.dll
18:50:44.0906 0404 C:\WINDOWS\system32\ati2evxx.dll - ok
18:50:44.0906 0404 [ 5F7E24FA9EAB896051FFB87F840730D2 ] C:\WINDOWS\system32\dnsrslvr.dll
18:50:44.0906 0404 C:\WINDOWS\system32\dnsrslvr.dll - ok
18:50:44.0906 0404 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] C:\WINDOWS\system32\wzcsvc.dll
18:50:44.0906 0404 C:\WINDOWS\system32\wzcsvc.dll - ok
18:50:44.0906 0404 [ 834A45BB471E2A3D7A5530D3E3F26624 ] C:\WINDOWS\system32\atiadlxx.dll
18:50:44.0906 0404 C:\WINDOWS\system32\atiadlxx.dll - ok
18:50:44.0906 0404 [ 876CCF164E08D6B903CD14398E056DD2 ] C:\WINDOWS\system32\rtutils.dll
18:50:44.0906 0404 C:\WINDOWS\system32\rtutils.dll - ok
18:50:44.0906 0404 [ 7B0770526801F05D58C51A3DFB87B4BD ] C:\WINDOWS\system32\wmi.dll
18:50:44.0906 0404 C:\WINDOWS\system32\wmi.dll - ok
18:50:44.0921 0404 [ E6EF7BC927D9F8F9BA1584BFC39E0C6F ] C:\WINDOWS\system32\eapolqec.dll
18:50:44.0921 0404 C:\WINDOWS\system32\eapolqec.dll - ok
18:50:44.0921 0404 [ 224FB925C641DA16CEB6D60F40CA4C75 ] C:\WINDOWS\system32\atl.dll
18:50:44.0921 0404 C:\WINDOWS\system32\atl.dll - ok
18:50:44.0921 0404 [ 515A7FAE2070C2B0242B2353443E2F11 ] C:\WINDOWS\system32\cscdll.dll
18:50:44.0921 0404 C:\WINDOWS\system32\cscdll.dll - ok
18:50:44.0921 0404 [ 8AE93AACC648921BAACB8602991AC4B3 ] C:\WINDOWS\system32\qutil.dll
18:50:44.0921 0404 C:\WINDOWS\system32\qutil.dll - ok
18:50:44.0921 0404 [ E2092F0A1D7ABC243F9C2362483D150D ] C:\WINDOWS\system32\dimsntfy.dll
18:50:44.0921 0404 C:\WINDOWS\system32\dimsntfy.dll - ok
18:50:44.0921 0404 [ 8E2CC37BA87D8F681066E0E9C8A19F73 ] C:\WINDOWS\system32\dot3api.dll
18:50:44.0921 0404 C:\WINDOWS\system32\dot3api.dll - ok
18:50:44.0921 0404 [ F5B754CDEA20BBB3A31E16A776EDE6D6 ] C:\WINDOWS\system32\esent.dll
18:50:44.0921 0404 C:\WINDOWS\system32\esent.dll - ok
18:50:44.0937 0404 [ BD83ABA61E8ACCC8D9FFB869F29418CE ] C:\WINDOWS\system32\winspool.drv
18:50:44.0937 0404 C:\WINDOWS\system32\winspool.drv - ok
18:50:44.0937 0404 [ 2CC34E8BB667EEF78899546E12649196 ] C:\WINDOWS\system32\wlnotify.dll
18:50:44.0937 0404 C:\WINDOWS\system32\wlnotify.dll - ok
18:50:44.0937 0404 [ 02CF580510234E519736559A7F19EA20 ] C:\WINDOWS\system32\WgaLogon.dll
18:50:44.0937 0404 C:\WINDOWS\system32\WgaLogon.dll - ok
18:50:44.0937 0404 [ ACFEE2392503DD5E457363A0510B8BCB ] C:\WINDOWS\system32\msxml3.dll
18:50:44.0937 0404 C:\WINDOWS\system32\msxml3.dll - ok
18:50:44.0937 0404 [ 28D6701C710AD7BA3CB95E75F8F1A9AA ] C:\Program Files\AVAST Software\Avast\AvastSvc.exe
18:50:44.0937 0404 C:\Program Files\AVAST Software\Avast\AvastSvc.exe - ok
18:50:44.0937 0404 [ A39BE37C9237DB5F1990D61B268EA555 ] C:\WINDOWS\system32\rastls.dll
18:50:44.0937 0404 C:\WINDOWS\system32\rastls.dll - ok
18:50:44.0937 0404 [ 54AE15322C30814FC23FC26907A563B3 ] C:\Program Files\AVAST Software\Avast\aswCmnBS.dll
18:50:44.0937 0404 C:\Program Files\AVAST Software\Avast\aswCmnBS.dll - ok
18:50:44.0953 0404 [ 6E4BE11D50F8A8DE2BAD644C9C9DE8D3 ] C:\WINDOWS\system32\cryptui.dll
18:50:44.0953 0404 C:\WINDOWS\system32\cryptui.dll - ok
18:50:44.0953 0404 [ CE5BA470204A3176E60721C4B63B8DF3 ] C:\WINDOWS\system32\wininet.dll
18:50:44.0953 0404 C:\WINDOWS\system32\wininet.dll - ok
18:50:44.0953 0404 [ 40F2889475EDC401F98FD7938F0BBF66 ] C:\Program Files\AVAST Software\Avast\aswCmnOS.dll
18:50:44.0953 0404 C:\Program Files\AVAST Software\Avast\aswCmnOS.dll - ok
18:50:44.0953 0404 [ 1F9319EA6D87522C70271A55AC3BE365 ] C:\Program Files\AVAST Software\Avast\aswCmnIS.dll
18:50:44.0953 0404 C:\Program Files\AVAST Software\Avast\aswCmnIS.dll - ok
18:50:44.0953 0404 [ 10753A3ADC3E39A3B10CC3F08E98E6B4 ] C:\WINDOWS\system32\normaliz.dll
18:50:44.0953 0404 C:\WINDOWS\system32\normaliz.dll - ok
18:50:44.0953 0404 [ F2ED64D23C94ACF512A81142F3431F4C ] C:\WINDOWS\system32\urlmon.dll
18:50:44.0953 0404 C:\WINDOWS\system32\urlmon.dll - ok
18:50:44.0968 0404 [ CDBE9690CF2B8409FACAD94FAC9479C9 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll
18:50:44.0968 0404 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcr90.dll - ok
18:50:44.0968 0404 [ F81E2C10BD6C4BE3B9A242018CEF7A98 ] C:\WINDOWS\system32\iertutil.dll
18:50:44.0968 0404 C:\WINDOWS\system32\iertutil.dll - ok
18:50:44.0968 0404 [ 4C39358EBDD2FFCD9132A30E1EC31E16 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll
18:50:44.0968 0404 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_31a54e43\msvcp90.dll - ok
18:50:44.0968 0404 [ 0C70F8F5CC8359AC633724BECF6ABAF3 ] C:\Program Files\AVAST Software\Avast\ashBase.dll
18:50:44.0968 0404 C:\Program Files\AVAST Software\Avast\ashBase.dll - ok
18:50:44.0968 0404 [ EA5B8BECA3F279C757578CD7F1E95855 ] C:\WINDOWS\system32\mprapi.dll
18:50:44.0968 0404 C:\WINDOWS\system32\mprapi.dll - ok
18:50:44.0968 0404 [ 2CDAE321B8E878A278BA2D2FA013060B ] C:\WINDOWS\system32\activeds.dll
18:50:44.0968 0404 C:\WINDOWS\system32\activeds.dll - ok
18:50:44.0968 0404 [ 0D84657DBF93DB98673DEFDF2B29E25A ] C:\WINDOWS\system32\adsldpc.dll
18:50:44.0968 0404 C:\WINDOWS\system32\adsldpc.dll - ok
18:50:44.0984 0404 [ 92C4F48B62B0B876194584C3FF09CCB6 ] C:\WINDOWS\system32\rasapi32.dll
18:50:44.0984 0404 C:\WINDOWS\system32\rasapi32.dll - ok
18:50:44.0984 0404 [ 4DEF926F6A0545AE486A03C84F2EE482 ] C:\WINDOWS\system32\rasman.dll
18:50:44.0984 0404 C:\WINDOWS\system32\rasman.dll - ok
18:50:44.0984 0404 [ 00AABF131B4823785818DB99A075A313 ] C:\WINDOWS\system32\tapi32.dll
18:50:44.0984 0404 C:\WINDOWS\system32\tapi32.dll - ok
18:50:44.0984 0404 [ 3E4F7CEF4D814584D3E9E390CA59DE5F ] C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{DED0CF99-AF2A-4BEC-8370-634B7D0C455F}\mpengine.dll
18:50:44.0984 0404 C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{DED0CF99-AF2A-4BEC-8370-634B7D0C455F}\mpengine.dll - ok
18:50:44.0984 0404 [ C1FAEA15E41F62D7BFA7FBC395C24BA6 ] C:\WINDOWS\system32\riched20.dll
18:50:44.0984 0404 C:\WINDOWS\system32\riched20.dll - ok
18:50:44.0984 0404 [ 67156D5A9AC356DC99D7BCCB388E3316 ] C:\WINDOWS\system32\wsock32.dll
18:50:44.0984 0404 C:\WINDOWS\system32\wsock32.dll - ok
18:50:45.0000 0404 [ F79B2469046122E24450FB66AE580C83 ] C:\Program Files\AVAST Software\Avast\aswEngLdr.dll
18:50:45.0000 0404 C:\Program Files\AVAST Software\Avast\aswEngLdr.dll - ok
18:50:45.0000 0404 [ C86121BF74BB07FC99DB9DB0ED1B49FF ] C:\Program Files\AVAST Software\Avast\avBugReport.exe
18:50:45.0000 0404 C:\Program Files\AVAST Software\Avast\avBugReport.exe - ok
18:50:45.0000 0404 [ 5C5E3AFD499E5146FEF1DA5EF8A23205 ] C:\Program Files\AVAST Software\Avast\dbghelp.dll
18:50:45.0000 0404 C:\Program Files\AVAST Software\Avast\dbghelp.dll - ok
18:50:45.0000 0404 [ 56CE97FF94B7662A300D359CD6F4D601 ] C:\WINDOWS\system32\raschap.dll
18:50:45.0000 0404 C:\WINDOWS\system32\raschap.dll - ok
18:50:45.0000 0404 [ 085ED2E391A871C7BAE87E0228B546BA ] C:\WINDOWS\system32\cscui.dll
18:50:45.0000 0404 C:\WINDOWS\system32\cscui.dll - ok
18:50:45.0000 0404 [ 684559A03CBC1D05BA120A18B0D8BA5D ] C:\WINDOWS\system32\winhttp.dll
18:50:45.0000 0404 C:\WINDOWS\system32\winhttp.dll - ok
18:50:45.0000 0404 [ 6C26DCF01E2A92F183B97D434017268A ] C:\WINDOWS\system32\dpcdll.dll
18:50:45.0000 0404 C:\WINDOWS\system32\dpcdll.dll - ok
18:50:45.0015 0404 [ D068312FEC645A9D7C1398808734B142 ] C:\Program Files\AVAST Software\Avast\aswProperty.dll
18:50:45.0015 0404 C:\Program Files\AVAST Software\Avast\aswProperty.dll - ok
18:50:45.0015 0404 [ 920B4D089E02FB4A3F8ADA8B4BEF9B26 ] C:\Program Files\AVAST Software\Avast\1033\Base.dll
18:50:45.0015 0404 C:\Program Files\AVAST Software\Avast\1033\Base.dll - ok
18:50:45.0015 0404 [ DA8B8A95780F406EBB213C1C5D4C0D90 ] C:\Program Files\AVAST Software\Avast\ashServ.dll
18:50:45.0015 0404 C:\Program Files\AVAST Software\Avast\ashServ.dll - ok
18:50:45.0015 0404 [ 64BF5CD9B9D7BD391CBC9EDE847A2902 ] C:\Program Files\AVAST Software\Avast\AavmRpch.dll
18:50:45.0015 0404 C:\Program Files\AVAST Software\Avast\AavmRpch.dll - ok
18:50:45.0015 0404 [ A93AEE1928A9D7CE3E16D24EC7380F89 ] C:\WINDOWS\system32\userinit.exe
18:50:45.0015 0404 C:\WINDOWS\system32\userinit.exe - ok
18:50:45.0015 0404 [ B1296D52B0D2096EC4759EEEB806D759 ] C:\WINDOWS\system32\WgaTray.exe
18:50:45.0015 0404 C:\WINDOWS\system32\WgaTray.exe - ok
18:50:45.0015 0404 [ 12896823FB95BFB3DC9B46BCAEDC9923 ] C:\WINDOWS\explorer.exe
18:50:45.0015 0404 C:\WINDOWS\explorer.exe - ok
18:50:45.0031 0404 [ D873AF6112E377CDBCBF3055B86C30A9 ] C:\Program Files\AVAST Software\Avast\aswAux.dll
18:50:45.0031 0404 C:\Program Files\AVAST Software\Avast\aswAux.dll - ok
18:50:45.0031 0404 [ 69B9DD83535C421F229227B0B303082A ] C:\Program Files\AVAST Software\Avast\ashTask.dll
18:50:45.0031 0404 C:\Program Files\AVAST Software\Avast\ashTask.dll - ok
18:50:45.0031 0404 [ 91F1D56F6DC6B2AEC45369765787B64D ] C:\Program Files\AVAST Software\Avast\ashTaskEx.dll
18:50:45.0031 0404 C:\Program Files\AVAST Software\Avast\ashTaskEx.dll - ok
18:50:45.0031 0404 [ E392E172687BE172F8600C5F41AB03D9 ] C:\WINDOWS\system32\browseui.dll
18:50:45.0031 0404 C:\WINDOWS\system32\browseui.dll - ok
18:50:45.0031 0404 [ 1919B2A6BB69BD206A4F0C20FBA5E4B6 ] C:\Program Files\AVAST Software\Avast\aswLog.dll
18:50:45.0031 0404 C:\Program Files\AVAST Software\Avast\aswLog.dll - ok
18:50:45.0031 0404 [ C14350FC0D47D806699C4F907FC6785B ] C:\WINDOWS\system32\cryptnet.dll
18:50:45.0031 0404 C:\WINDOWS\system32\cryptnet.dll - ok
18:50:45.0046 0404 [ 3CBA2210FA39C6ED7895634842E930DD ] C:\WINDOWS\system32\sensapi.dll
18:50:45.0046 0404 C:\WINDOWS\system32\sensapi.dll - ok
18:50:45.0046 0404 [ B3B4DDCD7263993FA3C42573066A16BE ] C:\Program Files\AVAST Software\Avast\aswSqLt.dll
18:50:45.0046 0404 C:\Program Files\AVAST Software\Avast\aswSqLt.dll - ok
18:50:45.0046 0404 [ CC26451A90025F6C55F64146C333DEA5 ] C:\WINDOWS\system32\LegitCheckControl.dll
18:50:45.0046 0404 C:\WINDOWS\system32\LegitCheckControl.dll - ok
18:50:45.0046 0404 [ 205ADD80FF8099B1A8101EB490B933D1 ] C:\WINDOWS\system32\wbem\wbemprox.dll
18:50:45.0046 0404 C:\WINDOWS\system32\wbem\wbemprox.dll - ok
18:50:45.0046 0404 [ D95C71052E5EF63B55997FB31483D02F ] C:\WINDOWS\system32\wbem\wbemcomn.dll
18:50:45.0046 0404 C:\WINDOWS\system32\wbem\wbemcomn.dll - ok
18:50:45.0046 0404 [ 7D289D7E6253BC998F51CAADB54C5192 ] C:\Program Files\AVAST Software\Avast\Aavm4h.dll
18:50:45.0046 0404 C:\Program Files\AVAST Software\Avast\Aavm4h.dll - ok
18:50:45.0046 0404 [ E43B269964099D96DDDAAED0E57F109E ] C:\Program Files\AVAST Software\Avast\avastIP.dll
18:50:45.0046 0404 C:\Program Files\AVAST Software\Avast\avastIP.dll - ok
18:50:45.0062 0404 [ 26CB10FA893F940AB09713FF46DCDADE ] C:\WINDOWS\system32\shdocvw.dll
18:50:45.0062 0404 C:\WINDOWS\system32\shdocvw.dll - ok
18:50:45.0062 0404 [ 79B5BAEC23456D3F7EC10FC8374DA2CC ] C:\Program Files\AVAST Software\Avast\aswIdle.dll
18:50:45.0062 0404 C:\Program Files\AVAST Software\Avast\aswIdle.dll - ok
18:50:45.0062 0404 [ BB2BE07A396B5B22AC56787FACF8D86F ] C:\Program Files\AVAST Software\Avast\aswDld.dll
18:50:45.0062 0404 C:\Program Files\AVAST Software\Avast\aswDld.dll - ok
18:50:45.0062 0404 [ 52D0FE133CBE687ED4E83FBDA70EBC9C ] C:\Program Files\AVAST Software\Avast\aswStrm.dll
18:50:45.0062 0404 C:\Program Files\AVAST Software\Avast\aswStrm.dll - ok
18:50:45.0062 0404 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] C:\WINDOWS\system32\schedsvc.dll
18:50:45.0062 0404 C:\WINDOWS\system32\schedsvc.dll - ok
18:50:45.0062 0404 [ E47E364C96467FD54FA44D59F927C3AB ] C:\WINDOWS\system32\msidle.dll
18:50:45.0062 0404 C:\WINDOWS\system32\msidle.dll - ok
18:50:45.0062 0404 [ 60784F891563FB1B767F70117FC2428F ] C:\WINDOWS\system32\spoolsv.exe
18:50:45.0062 0404 C:\WINDOWS\system32\spoolsv.exe - ok
18:50:45.0078 0404 [ DEF7A7882BEC100FE0B2CE2549188F9D ] C:\WINDOWS\system32\audiosrv.dll
18:50:45.0078 0404 C:\WINDOWS\system32\audiosrv.dll - ok
18:50:45.0078 0404 [ CD89FA96371429B0BEE893B156DB8932 ] C:\Program Files\AVAST Software\Avast\ashShell.dll
18:50:45.0078 0404 C:\Program Files\AVAST Software\Avast\ashShell.dll - ok
18:50:45.0078 0404 [ A8888A5327621856C0CEC4E385F69309 ] C:\WINDOWS\system32\wkssvc.dll
18:50:45.0078 0404 C:\WINDOWS\system32\wkssvc.dll - ok
18:50:45.0078 0404 [ 8C22083ED515DC94D575438662F0BE6A ] C:\WINDOWS\system32\msi.dll
18:50:45.0078 0404 C:\WINDOWS\system32\msi.dll - ok
18:50:45.0078 0404 [ 680B56A8B62D1BCF4A0B2AAAD03D88E4 ] C:\WINDOWS\system32\wdmaud.drv
18:50:45.0078 0404 C:\WINDOWS\system32\wdmaud.drv - ok
18:50:45.0078 0404 [ 6768ACF64B18196494413695F0C3A00F ] C:\WINDOWS\system32\drivers\wdmaud.sys
18:50:45.0078 0404 C:\WINDOWS\system32\drivers\wdmaud.sys - ok
18:50:45.0093 0404 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] C:\WINDOWS\system32\drivers\sysaudio.sys
18:50:45.0093 0404 C:\WINDOWS\system32\drivers\sysaudio.sys - ok
18:50:45.0093 0404 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] C:\WINDOWS\system32\drivers\splitter.sys
18:50:45.0093 0404 C:\WINDOWS\system32\drivers\splitter.sys - ok
18:50:45.0093 0404 [ 8BED39E3C35D6A489438B8141717A557 ] C:\WINDOWS\system32\drivers\aec.sys
18:50:45.0093 0404 C:\WINDOWS\system32\drivers\aec.sys - ok
18:50:45.0093 0404 [ 88B6D362E111D87CBCA6CA94E152B7C6 ] C:\Program Files\File Type Assistant\tsassist.exe
18:50:45.0093 0404 C:\Program Files\File Type Assistant\tsassist.exe - ok
18:50:45.0093 0404 [ F02A533F517EB38333CB12A9E8963773 ] C:\Program Files\Google\Update\GoogleUpdate.exe
18:50:45.0093 0404 C:\Program Files\Google\Update\GoogleUpdate.exe - ok
18:50:45.0093 0404 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] C:\WINDOWS\system32\drivers\swmidi.sys
18:50:45.0093 0404 C:\WINDOWS\system32\drivers\swmidi.sys - ok
18:50:45.0093 0404 [ 8A208DFCF89792A484E76C40E5F50B45 ] C:\WINDOWS\system32\drivers\dmusic.sys
18:50:45.0093 0404 C:\WINDOWS\system32\drivers\dmusic.sys - ok
18:50:45.0109 0404 [ 758D99511FD82B6C55E70494039E9F1A ] C:\Program Files\Google\Update\1.3.21.145\goopdate.dll
18:50:45.0109 0404 C:\Program Files\Google\Update\1.3.21.145\goopdate.dll - ok
18:50:45.0109 0404 [ 01F441F655D8CC4214BDF411D39D04AF ] C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
18:50:45.0109 0404 C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe - ok
18:50:45.0109 0404 [ 692BCF44383D056AED41B045A323D378 ] C:\WINDOWS\system32\drivers\kmixer.sys
18:50:45.0109 0404 C:\WINDOWS\system32\drivers\kmixer.sys - ok
18:50:45.0109 0404 [ 4C867B62F6100C107A3A8F5E7A10461D ] C:\Program Files\Spybot - Search & Destroy 2\rtl150.bpl
18:50:45.0109 0404 C:\Program Files\Spybot - Search & Destroy 2\rtl150.bpl - ok
18:50:45.0109 0404 [ 5CE2C1433B9B634591F0A1C4C1203A0B ] C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
18:50:45.0109 0404 C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe - ok
18:50:45.0109 0404 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] C:\WINDOWS\system32\drivers\drmkaud.sys
18:50:45.0109 0404 C:\WINDOWS\system32\drivers\drmkaud.sys - ok
18:50:45.0109 0404 [ 9A3BD5F55AADFF859539142F6328A66E ] C:\WINDOWS\system32\msacm32.drv
18:50:45.0109 0404 C:\WINDOWS\system32\msacm32.drv - ok
18:50:45.0125 0404 [ 5C12660A97822F6E61576943B49AAAD6 ] C:\WINDOWS\system32\midimap.dll
18:50:45.0125 0404 C:\WINDOWS\system32\midimap.dll - ok
18:50:45.0125 0404 [ 9F93FB3421EF78A5E4910E8FA5548AA2 ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswEngin.dll
18:50:45.0125 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswEngin.dll - ok
18:50:45.0125 0404 [ B4ED498E3BFEE64E952BC44FC6057DB8 ] C:\WINDOWS\system32\desk.cpl
18:50:45.0125 0404 C:\WINDOWS\system32\desk.cpl - ok
18:50:45.0125 0404 [ A314EEA2A503A8E04085201E436384A5 ] C:\WINDOWS\system32\themeui.dll
18:50:45.0125 0404 C:\WINDOWS\system32\themeui.dll - ok
18:50:45.0125 0404 [ C5A75EB48E2344ABDC162BDA79E16841 ] C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:50:45.0125 0404 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe - ok
18:50:45.0125 0404 [ 912B67BB8249925A5C972FC5839EAE09 ] C:\WINDOWS\system32\actxprxy.dll
18:50:45.0125 0404 C:\WINDOWS\system32\actxprxy.dll - ok
18:50:45.0140 0404 [ E5F7C30EDF0892667933BE879F067D67 ] C:\WINDOWS\system32\msvcr100_clr0400.dll
18:50:45.0140 0404 C:\WINDOWS\system32\msvcr100_clr0400.dll - ok
18:50:45.0140 0404 [ F9D82B82F1B7C0B2D2606A987073F58C ] C:\PROGRA~1\WIFD1F~1\MpShHook.dll
18:50:45.0140 0404 C:\PROGRA~1\WIFD1F~1\MpShHook.dll - ok
18:50:45.0140 0404 [ CDE968DF7EA866320EFB8762B50E0AD7 ] C:\Program Files\SpywareGuard\spywareguard.dll
18:50:45.0140 0404 C:\Program Files\SpywareGuard\spywareguard.dll - ok
18:50:45.0140 0404 [ 80776884E7A05D6DA5040926F82B0273 ] C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll
18:50:45.0140 0404 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.6002.22791_x-ww_c8dff154\GdiPlus.dll - ok
18:50:45.0140 0404 [ 64B33CC5BF131DEF2721394CF9B3F8ED ] C:\WINDOWS\system32\msvbvm60.dll
18:50:45.0140 0404 C:\WINDOWS\system32\msvbvm60.dll - ok
18:50:45.0140 0404 [ C14AA05881A35B6D6BB8D55B117EE22D ] C:\WINDOWS\system32\shfolder.dll
18:50:45.0140 0404 C:\WINDOWS\system32\shfolder.dll - ok
18:50:45.0140 0404 [ 5C8ED4086C01DFB7794A70F4E632BDBF ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswCmnIS.dll
18:50:45.0140 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswCmnIS.dll - ok
18:50:45.0171 0404 [ 08A73B0E7EE6E32983B5F9E540A8E380 ] C:\WINDOWS\system32\mscoree.dll
18:50:45.0171 0404 C:\WINDOWS\system32\mscoree.dll - ok
18:50:45.0171 0404 [ 40D0BB31817312CD0169C47BDDFA65C2 ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswCmnOS.dll
18:50:45.0171 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswCmnOS.dll - ok
18:50:45.0171 0404 [ 79E3A8C328E7E569C32B0998377D9742 ] C:\WINDOWS\system32\spoolss.dll
18:50:45.0171 0404 C:\WINDOWS\system32\spoolss.dll - ok
18:50:45.0171 0404 [ 3D4E199942E29207970E04315D02AD3B ] C:\WINDOWS\system32\cryptsvc.dll
18:50:45.0171 0404 C:\WINDOWS\system32\cryptsvc.dll - ok
18:50:45.0171 0404 [ 00709952D444EAE14DBBD30D36FBAE0F ] C:\WINDOWS\system32\certcli.dll
18:50:45.0171 0404 C:\WINDOWS\system32\certcli.dll - ok
18:50:45.0171 0404 [ B6E6F3F5B63053D5DC1F4EE32992492F ] C:\WINDOWS\system32\dbghelp.dll
18:50:45.0171 0404 C:\WINDOWS\system32\dbghelp.dll - ok
18:50:45.0171 0404 [ 5677DFE438EC1F009273FC84FEED6B10 ] C:\WINDOWS\system32\localspl.dll
18:50:45.0171 0404 C:\WINDOWS\system32\localspl.dll - ok
18:50:45.0187 0404 [ BC93B4A066477954555966D77FEC9ECB ] C:\WINDOWS\system32\ersvc.dll
18:50:45.0187 0404 C:\WINDOWS\system32\ersvc.dll - ok
18:50:45.0187 0404 [ 90B7D9022FE8EDDDDEC348A29BF99EF8 ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswCmnBS.dll
18:50:45.0187 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswCmnBS.dll - ok
18:50:45.0187 0404 [ D4991D98F2DB73C60D042F1AEF79EFAE ] C:\WINDOWS\system32\es.dll
18:50:45.0187 0404 C:\WINDOWS\system32\es.dll - ok
18:50:45.0187 0404 [ 5D3D1AB0EF4EA55B731863050482C111 ] C:\WINDOWS\system32\cnbjmon.dll
18:50:45.0187 0404 C:\WINDOWS\system32\cnbjmon.dll - ok
18:50:45.0187 0404 [ 6B94178802A0F6AB5418DF08C7554020 ] C:\WINDOWS\system32\hpzlnt04.dll
18:50:45.0187 0404 C:\WINDOWS\system32\hpzlnt04.dll - ok
18:50:45.0187 0404 [ CC6292CA575E851E5B74BF8883AB967A ] C:\WINDOWS\system32\fxsmon.dll
18:50:45.0187 0404 C:\WINDOWS\system32\fxsmon.dll - ok
18:50:45.0187 0404 [ D9AF104F7E21FA859EFA3C67E5522E88 ] C:\Program Files\Spybot - Search & Destroy 2\vcl150.bpl
18:50:45.0187 0404 C:\Program Files\Spybot - Search & Destroy 2\vcl150.bpl - ok
18:50:45.0203 0404 [ BDB83C844EDEC9BD01A94750D2C38DDF ] C:\WINDOWS\system32\fxsevent.dll
18:50:45.0203 0404 C:\WINDOWS\system32\fxsevent.dll - ok
18:50:45.0203 0404 [ 222DE7F5EDB9DDBE628384A1A8BE59CE ] C:\WINDOWS\system32\pjlmon.dll
18:50:45.0203 0404 C:\WINDOWS\system32\pjlmon.dll - ok
18:50:45.0203 0404 [ AE0382AD9C73D343D85E1A50C80B7C20 ] C:\WINDOWS\system32\tcpmon.dll
18:50:45.0203 0404 C:\WINDOWS\system32\tcpmon.dll - ok
18:50:45.0203 0404 [ 76B35CB0F3A4E69D6DFF27F542B9F856 ] C:\Program Files\Google\Update\1.3.21.145\GoogleCrashHandler.exe
18:50:45.0203 0404 C:\Program Files\Google\Update\1.3.21.145\GoogleCrashHandler.exe - ok
18:50:45.0203 0404 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll
18:50:45.0203 0404 C:\WINDOWS\pchealth\helpctr\binaries\pchsvc.dll - ok
18:50:45.0203 0404 [ F80A415EF82CD06FFAF0D971528EAD38 ] C:\WINDOWS\system32\drivers\http.sys
18:50:45.0203 0404 C:\WINDOWS\system32\drivers\http.sys - ok
18:50:45.0218 0404 [ 4044E880593FE1AC9942190FCE414BE7 ] C:\WINDOWS\system32\mstask.dll
18:50:45.0218 0404 C:\WINDOWS\system32\mstask.dll - ok
18:50:45.0218 0404 [ F26385E8BA4549B5186B774EC0E45D86 ] C:\WINDOWS\system32\usbmon.dll
18:50:45.0218 0404 C:\WINDOWS\system32\usbmon.dll - ok
18:50:45.0218 0404 [ EEE7F12D9FF46F68FBC0DA059A359E9E ] C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
18:50:45.0218 0404 C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll - ok
18:50:45.0218 0404 [ 0F167FBAF67B8472B128FC0C621B6FE1 ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswScan.dll
18:50:45.0218 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswScan.dll - ok
18:50:45.0218 0404 [ 22DD6D7D4BFE2B8CE705CC950C8AEA4C ] C:\WINDOWS\system32\win32spl.dll
18:50:45.0218 0404 C:\WINDOWS\system32\win32spl.dll - ok
18:50:45.0218 0404 [ 4F4D4AA1E0849FECC0CF5AACD59030B5 ] C:\Program Files\Java\jre7\bin\jqs.exe
18:50:45.0218 0404 C:\Program Files\Java\jre7\bin\jqs.exe - ok
18:50:45.0218 0404 [ B41D53899E37CC43DA85DA19998BEE81 ] C:\WINDOWS\system32\netrap.dll
18:50:45.0218 0404 C:\WINDOWS\system32\netrap.dll - ok
18:50:45.0234 0404 [ EE4C651A217B01D636B5364AC77DA892 ] C:\WINDOWS\system32\inetpp.dll
18:50:45.0234 0404 C:\WINDOWS\system32\inetpp.dll - ok
18:50:45.0234 0404 [ 67EC459E42D3081DD8FD34356F7CAFC1 ] C:\Program Files\Java\jre7\bin\msvcr100.dll
18:50:45.0234 0404 C:\Program Files\Java\jre7\bin\msvcr100.dll - ok
18:50:45.0234 0404 [ 32ED62D8C410117E09B0B7CA44FC4456 ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswRep.dll
18:50:45.0234 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswRep.dll - ok
18:50:45.0234 0404 [ 2399F8068E969D9C25A05B6F779A790A ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswFiDb.dll
18:50:45.0234 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswFiDb.dll - ok
18:50:45.0234 0404 [ 62CF83A6989312A0DD39BBFFB3D1C166 ] C:\WINDOWS\system32\pdh.dll
18:50:45.0234 0404 C:\WINDOWS\system32\pdh.dll - ok
18:50:45.0234 0404 [ 369F7B1A4F358B976176556A1A331F36 ] C:\WINDOWS\system32\odbcbcp.dll
18:50:45.0234 0404 C:\WINDOWS\system32\odbcbcp.dll - ok
18:50:45.0250 0404 [ 3A7C3CBE5D96B8AE96CE81F0B22FB527 ] C:\WINDOWS\system32\srvsvc.dll
18:50:45.0250 0404 C:\WINDOWS\system32\srvsvc.dll - ok
18:50:45.0250 0404 [ 332760FBA1655FCFD35BD6F4FD871300 ] C:\WINDOWS\system32\ipsecsvc.dll
18:50:45.0250 0404 C:\WINDOWS\system32\ipsecsvc.dll - ok
18:50:45.0250 0404 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] C:\WINDOWS\system32\netman.dll
18:50:45.0250 0404 C:\WINDOWS\system32\netman.dll - ok
18:50:45.0250 0404 [ ACDAFCD14EC0ECE89198503746A5C147 ] C:\WINDOWS\system32\perfos.dll
18:50:45.0250 0404 C:\WINDOWS\system32\perfos.dll - ok
18:50:45.0250 0404 [ 84C07D29912726032A583AEA2FF29B7D ] C:\Program Files\Windows Defender\MpRtPlug.dll
18:50:45.0250 0404 C:\Program Files\Windows Defender\MpRtPlug.dll - ok
18:50:45.0250 0404 [ ABFB673B24A9B3287761D497529FB5B9 ] C:\WINDOWS\system32\perfdisk.dll
18:50:45.0250 0404 C:\WINDOWS\system32\perfdisk.dll - ok
18:50:45.0250 0404 [ 062F837C1FBDB6A0A75F82EFC2EE8E74 ] C:\WINDOWS\system32\netshell.dll
18:50:45.0250 0404 C:\WINDOWS\system32\netshell.dll - ok
18:50:45.0265 0404 [ AB2B1DE1C8F31EFCE2384B14B3DC4260 ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
18:50:45.0265 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe - ok
18:50:45.0265 0404 [ C5FF8682EADA5B3B27A865F1C3EF9270 ] C:\WINDOWS\system32\oakley.dll
18:50:45.0265 0404 C:\WINDOWS\system32\oakley.dll - ok
18:50:45.0265 0404 [ 6D778E0F95447E6546553EEEA709D03C ] C:\WINDOWS\system32\cmd.exe
18:50:45.0265 0404 C:\WINDOWS\system32\cmd.exe - ok
18:50:45.0265 0404 [ 561FA2ABB31DFA8FAB762145F81667C2 ] C:\WINDOWS\system32\msvcp71.dll
18:50:45.0265 0404 C:\WINDOWS\system32\msvcp71.dll - ok
18:50:45.0265 0404 [ 248712EA6BA17B9FF0C542A3828375DD ] C:\WINDOWS\system32\winipsec.dll
18:50:45.0265 0404 C:\WINDOWS\system32\winipsec.dll - ok
18:50:45.0265 0404 [ 853D0D0C6F02D7BFDF1CF99DD7553732 ] C:\WINDOWS\system32\pstorsvc.dll
18:50:45.0265 0404 C:\WINDOWS\system32\pstorsvc.dll - ok
18:50:45.0265 0404 [ 22D89D84E8E081CDA529DBF8C0255A38 ] C:\WINDOWS\system32\psbase.dll
18:50:45.0265 0404 C:\WINDOWS\system32\psbase.dll - ok
18:50:45.0281 0404 [ FEDE68BF80052BAD393AFD5C2E60DCB0 ] C:\WINDOWS\system32\dssenh.dll
18:50:45.0281 0404 C:\WINDOWS\system32\dssenh.dll - ok
18:50:45.0281 0404 [ 0B467F470CC9918FDCEEDCFD7DC4D697 ] C:\WINDOWS\system32\oledlg.dll
18:50:45.0281 0404 C:\WINDOWS\system32\oledlg.dll - ok
18:50:45.0281 0404 [ 4E98097C6DAF780D145FB702C6EA625F ] C:\WINDOWS\system32\ieframe.dll
18:50:45.0281 0404 C:\WINDOWS\system32\ieframe.dll - ok
18:50:45.0281 0404 [ 86F1895AE8C5E8B17D99ECE768A70732 ] C:\WINDOWS\system32\msvcr71.dll
18:50:45.0281 0404 C:\WINDOWS\system32\msvcr71.dll - ok
18:50:45.0281 0404 [ F6C66188DEF298E2C3827AF6FB2C0637 ] C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\CPSCommonTools9.dll
18:50:45.0281 0404 C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\CPSCommonTools9.dll - ok
18:50:45.0281 0404 [ 3C03DB6F66C9792C9B6E30473E847CA2 ] C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll
18:50:45.0281 0404 C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\ROXIPP41.dll - ok
18:50:45.0296 0404 [ C1DD6288ABA16EECBA39C3299C4040FE ] C:\Program Files\AVAST Software\Avast\Setup\setiface.dll
18:50:45.0296 0404 C:\Program Files\AVAST Software\Avast\Setup\setiface.dll - ok
18:50:45.0296 0404 [ 57CB53804DDBD2F72C953C428C8E628D ] C:\Program Files\AVAST Software\Avast\defs\13062500\algo.dll
18:50:45.0296 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\algo.dll - ok
18:50:45.0296 0404 [ 235892E493845D64D890163CFEF90E97 ] C:\WINDOWS\system32\credui.dll
18:50:45.0296 0404 C:\WINDOWS\system32\credui.dll - ok
18:50:45.0296 0404 [ 25A2EEF8D22E36F3C7B368BCF245BDC3 ] C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
18:50:45.0296 0404 C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl - ok
18:50:45.0296 0404 [ 4E8F3230BAC8C1CAADF01A8C728E1C5C ] C:\WINDOWS\system32\dot3dlg.dll
18:50:45.0296 0404 C:\WINDOWS\system32\dot3dlg.dll - ok
18:50:45.0296 0404 [ CA04959077AFE36369D37B3504740C87 ] C:\WINDOWS\system32\onex.dll
18:50:45.0296 0404 C:\WINDOWS\system32\onex.dll - ok
18:50:45.0296 0404 [ 5DB625E7D095604010CF84DE2D8ACFA6 ] C:\WINDOWS\system32\eappcfg.dll
18:50:45.0296 0404 C:\WINDOWS\system32\eappcfg.dll - ok
18:50:45.0312 0404 [ 110145B6EC64C9800468C18ED81B6FC5 ] C:\Program Files\Spybot - Search & Destroy 2\snlBase150.bpl
18:50:45.0312 0404 C:\Program Files\Spybot - Search & Destroy 2\snlBase150.bpl - ok
18:50:45.0312 0404 [ ABC4206543450C0666D152F4B65833B8 ] C:\WINDOWS\system32\eappprxy.dll
18:50:45.0312 0404 C:\WINDOWS\system32\eappprxy.dll - ok
18:50:45.0312 0404 [ 767FF54A552732CE772C2302025FA82F ] C:\WINDOWS\system32\wzcsapi.dll
18:50:45.0312 0404 C:\WINDOWS\system32\wzcsapi.dll - ok
18:50:45.0312 0404 [ 20FD44370267CCD0A64A1B31861C21D2 ] C:\WINDOWS\system32\netmsg.dll
18:50:45.0312 0404 C:\WINDOWS\system32\netmsg.dll - ok
18:50:45.0312 0404 [ 47DDFC2F003F7F9F0592C6874962A2E7 ] C:\WINDOWS\system32\drivers\srv.sys
18:50:45.0312 0404 C:\WINDOWS\system32\drivers\srv.sys - ok
18:50:45.0312 0404 [ 5FCE5B36991DBAA99DA9E9C62D8E60AC ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\LeResourceLoader.dll
18:50:45.0312 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\LeResourceLoader.dll - ok
18:50:45.0328 0404 [ 1BAC818025403333C11817DAFBCEE283 ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSFileLoader.dll
18:50:45.0328 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSFileLoader.dll - ok
18:50:45.0328 0404 [ C7C30B24C8C57078654BA9574CE70E3D ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSCommonObjects.dll
18:50:45.0328 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSCommonObjects.dll - ok
18:50:45.0328 0404 [ 41857DA3EA7A2568E1AAE8FEDC8D8939 ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSCommonEnglish.dll
18:50:45.0328 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSCommonEnglish.dll - ok
18:50:45.0328 0404 [ 09DEF3ABB6A196749299359AC5578DD8 ] C:\WINDOWS\system32\msxml4.dll
18:50:45.0328 0404 C:\WINDOWS\system32\msxml4.dll - ok
18:50:45.0328 0404 [ 95AA9E165C7DE1B64A11E8B18E91E499 ] C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
18:50:45.0328 0404 C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe - ok
18:50:45.0328 0404 [ 776405A9F755BA8BA5CA9039F0D18067 ] C:\Program Files\Spybot - Search & Destroy 2\Jcl150.bpl
18:50:45.0328 0404 C:\Program Files\Spybot - Search & Destroy 2\Jcl150.bpl - ok
18:50:45.0328 0404 [ F9D3C78CFE15271D80790677C893CE45 ] C:\WINDOWS\system32\cabinet.dll
18:50:45.0328 0404 C:\WINDOWS\system32\cabinet.dll - ok
18:50:45.0343 0404 [ 75B5CCDAD97A2A6D245ACA1ACB415DA5 ] C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
18:50:45.0343 0404 C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl - ok
18:50:45.0343 0404 [ 816D64F554FBD234DD2C77F4E08C7D5C ] C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
18:50:45.0343 0404 C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl - ok
18:50:45.0343 0404 [ 14361FB2FD630988816A4F46AEAF0684 ] C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
18:50:45.0343 0404 C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll - ok
18:50:45.0343 0404 [ 5422CB64444C33F029483552A8FACE37 ] C:\Program Files\Spybot - Search & Destroy 2\vclx150.bpl
18:50:45.0343 0404 C:\Program Files\Spybot - Search & Destroy 2\vclx150.bpl - ok
18:50:45.0343 0404 [ 4AA01BD5CC7DA9888AF33C5FAB5BF1DD ] C:\Program Files\Spybot - Search & Destroy 2\vclimg150.bpl
18:50:45.0343 0404 C:\Program Files\Spybot - Search & Destroy 2\vclimg150.bpl - ok
18:50:45.0343 0404 [ 5652F6CE1D9E9D8068B9D29BC21B5409 ] C:\WINDOWS\system32\olepro32.dll
18:50:45.0343 0404 C:\WINDOWS\system32\olepro32.dll - ok
18:50:45.0359 0404 [ 9B375BB63F99B113C065A5DB4E632E23 ] C:\Program Files\Spybot - Search & Destroy 2\av\scan.dll
18:50:45.0359 0404 C:\Program Files\Spybot - Search & Destroy 2\av\scan.dll - ok
18:50:45.0359 0404 [ 46B5E0D4DE23D31E7B83E376BD99D7C6 ] C:\Program Files\Spybot - Search & Destroy 2\SDLicense.dll
18:50:45.0359 0404 C:\Program Files\Spybot - Search & Destroy 2\SDLicense.dll - ok
18:50:45.0359 0404 [ AC15528C51E5FE76B1B1C365EF82B86E ] C:\Program Files\Spybot - Search & Destroy 2\SDFileScanLibrary.dll
18:50:45.0359 0404 C:\Program Files\Spybot - Search & Destroy 2\SDFileScanLibrary.dll - ok
18:50:45.0359 0404 [ 178A34E5554DCE485E1262DDF027960C ] C:\DOCUME~1\JOHNRI~1\LOCALS~1\Temp\EA3DCB06-70CA-463B-8C6A-80E730CFAFD4.exe
18:50:45.0359 0404 C:\DOCUME~1\JOHNRI~1\LOCALS~1\Temp\EA3DCB06-70CA-463B-8C6A-80E730CFAFD4.exe - ok
18:50:45.0359 0404 [ A70A2D85AD143D6BB823C246CEB699A5 ] C:\WINDOWS\system32\ntshrui.dll
18:50:45.0359 0404 C:\WINDOWS\system32\ntshrui.dll - ok
18:50:45.0359 0404 [ 91790D6749EBED90E2C40479C0A91879 ] C:\WINDOWS\system32\verclsid.exe
18:50:45.0359 0404 C:\WINDOWS\system32\verclsid.exe - ok
18:50:45.0359 0404 [ 2DC5A8019E2387987905F77C664E4BE2 ] C:\WINDOWS\system32\linkinfo.dll
18:50:45.0359 0404 C:\WINDOWS\system32\linkinfo.dll - ok
18:50:45.0375 0404 [ 93C088C2AEB2F23E720BDA7E32BD5117 ] C:\WINDOWS\system32\upnp.dll
18:50:45.0375 0404 C:\WINDOWS\system32\upnp.dll - ok
18:50:45.0375 0404 [ FF3BF05021BFECC92DB81B8257EEB026 ] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
18:50:45.0375 0404 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe - ok
18:50:45.0375 0404 [ 3D075865DCC26931972F6476AD0497BE ] C:\WINDOWS\system32\ssdpapi.dll
18:50:45.0375 0404 C:\WINDOWS\system32\ssdpapi.dll - ok
18:50:45.0375 0404 [ 9ABF687071C649609BF7E177062A9008 ] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
18:50:45.0375 0404 C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe - ok
18:50:45.0375 0404 [ 38A06338E10BC8C636FC20E8ADFE6BCA ] C:\Program Files\Common Files\InstallShield\UpdateService\_ispmres.dll
18:50:45.0375 0404 C:\Program Files\Common Files\InstallShield\UpdateService\_ispmres.dll - ok
18:50:45.0375 0404 [ 7C6B5065E7326E3C91A62800DF3A31FA ] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
18:50:45.0375 0404 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe - ok
18:50:45.0390 0404 [ B52BCA0ABD463590BE48663962608D46 ] C:\WINDOWS\RTHDCPL.EXE
18:50:45.0390 0404 C:\WINDOWS\RTHDCPL.EXE - ok
18:50:45.0390 0404 [ 3F11B20D12D89365D7721BDC860CE5F0 ] C:\Program Files\AVAST Software\Avast\AvastUI.exe
18:50:45.0390 0404 C:\Program Files\AVAST Software\Avast\AvastUI.exe - ok
18:50:45.0390 0404 [ B714735C12A70171DE28657948FD91F1 ] C:\WINDOWS\system32\mlang.dll
18:50:45.0390 0404 C:\WINDOWS\system32\mlang.dll - ok
18:50:45.0390 0404 [ DEF3BCFBF5DD73886408754B2CEF8058 ] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzr3204.dll
18:50:45.0390 0404 C:\WINDOWS\system32\spool\drivers\w32x86\3\hpzr3204.dll - ok
18:50:45.0390 0404 [ F92B3868E3801653AF196C76078829FA ] C:\Program Files\AVAST Software\Avast\aswUtil.dll
18:50:45.0390 0404 C:\Program Files\AVAST Software\Avast\aswUtil.dll - ok
18:50:45.0390 0404 [ 4D83ED8BDDEC431FC8AD907B47CFB6E3 ] C:\WINDOWS\system32\dsound.dll
18:50:45.0390 0404 C:\WINDOWS\system32\dsound.dll - ok
18:50:45.0390 0404 [ 22D71D1DB6FC789A1CE8AC6963580259 ] C:\WINDOWS\system32\hhctrl.ocx
18:50:45.0390 0404 C:\WINDOWS\system32\hhctrl.ocx - ok
18:50:45.0406 0404 [ 6AE8E702D1027A9627DDE2B77BB9992B ] C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
18:50:45.0406 0404 C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe - ok
18:50:45.0406 0404 [ CC8915DB4E33E8FB29CA0D2DBF75306E ] C:\WINDOWS\system32\webcheck.dll
18:50:45.0406 0404 C:\WINDOWS\system32\webcheck.dll - ok
18:50:45.0406 0404 [ 9138E5C7FB95A70030324EDB430BF4B3 ] C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
18:50:45.0406 0404 C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe - ok
18:50:45.0406 0404 [ 50512FC9B7878E3C2C147BC17326A7DB ] C:\WINDOWS\system32\stobject.dll
18:50:45.0406 0404 C:\WINDOWS\system32\stobject.dll - ok
18:50:45.0406 0404 [ CA6ADE4F7761BB15B3325356DC3B82BB ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll
18:50:45.0406 0404 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_028bc148\mfc90u.dll - ok
18:50:45.0406 0404 [ 2A8681AEA24003040CA7D677BE9F1702 ] C:\WINDOWS\system32\drivers\99957243.sys
18:50:45.0406 0404 C:\WINDOWS\system32\drivers\99957243.sys - ok
18:50:45.0406 0404 [ 231A0B0E3BA7ABFE469A8262FAA1FD71 ] C:\WINDOWS\system32\batmeter.dll
18:50:45.0406 0404 C:\WINDOWS\system32\batmeter.dll - ok
18:50:45.0421 0404 [ 045E228F71C31901084B64BE59093499 ] C:\WINDOWS\system32\WPDShServiceObj.dll
18:50:45.0421 0404 C:\WINDOWS\system32\WPDShServiceObj.dll - ok
18:50:45.0421 0404 [ 22358578CB321F3325496A3723029409 ] C:\WINDOWS\system32\PortableDeviceTypes.dll
18:50:45.0421 0404 C:\WINDOWS\system32\PortableDeviceTypes.dll - ok
18:50:45.0421 0404 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] C:\WINDOWS\system32\sens.dll
18:50:45.0421 0404 C:\WINDOWS\system32\sens.dll - ok
18:50:45.0421 0404 [ 9D45B2201D0ECF9F42136C7B99DEB8B2 ] C:\WINDOWS\system32\PortableDeviceApi.dll
18:50:45.0421 0404 C:\WINDOWS\system32\PortableDeviceApi.dll - ok
18:50:45.0421 0404 [ 48BE298F7FD1BEF4D8FBACB04D8D95C4 ] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
18:50:45.0421 0404 C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe - ok
18:50:45.0421 0404 [ CBE612E2BB6A10E3563336191EDA1250 ] C:\WINDOWS\system32\seclogon.dll
18:50:45.0421 0404 C:\WINDOWS\system32\seclogon.dll - ok
18:50:45.0437 0404 [ 727CC4E1E55F35A75E217D04EEE1ECB2 ] C:\WINDOWS\system32\jsproxy.dll
18:50:45.0437 0404 C:\WINDOWS\system32\jsproxy.dll - ok
18:50:45.0437 0404 [ 3805DF0AC4296A34BA4BF93B346CC378 ] C:\WINDOWS\system32\srsvc.dll
18:50:45.0437 0404 C:\WINDOWS\system32\srsvc.dll - ok
18:50:45.0437 0404 [ 09E9425AD8C61664A37ED84B8B58BDCF ] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
18:50:45.0437 0404 C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe - ok
18:50:45.0437 0404 [ D63797E8E7781EE1500A810CB6194FA6 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
18:50:45.0437 0404 C:\Program Files\Common Files\Java\Java Update\jusched.exe - ok
18:50:45.0437 0404 [ 37A62C6092AADD2EFDE0468DD8818E99 ] C:\WINDOWS\system32\netcfgx.dll
18:50:45.0437 0404 C:\WINDOWS\system32\netcfgx.dll - ok
18:50:45.0437 0404 [ 77A54BDFBAD4604E6131AE68E3CF76D6 ] C:\WINDOWS\system32\srclient.dll
18:50:45.0437 0404 C:\WINDOWS\system32\srclient.dll - ok
18:50:45.0437 0404 [ 0A5679B3714EDAB99E357057EE88FCA6 ] C:\WINDOWS\system32\ssdpsrv.dll
18:50:45.0437 0404 C:\WINDOWS\system32\ssdpsrv.dll - ok
18:50:45.0453 0404 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] C:\WINDOWS\system32\wiaservc.dll
18:50:45.0453 0404 C:\WINDOWS\system32\wiaservc.dll - ok
18:50:45.0453 0404 [ 4306FA2F1099D7C606139255FDB62B19 ] C:\WINDOWS\system32\wbem\framedyn.dll
18:50:45.0453 0404 C:\WINDOWS\system32\wbem\framedyn.dll - ok
18:50:45.0453 0404 [ CC9521CB99428903AEF385FBE6C3B418 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
18:50:45.0453 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe - ok
18:50:45.0453 0404 [ FD51C70FC62C4D3384FE9F09F159BA9F ] C:\Program Files\Download Manager\DLM.exe
18:50:45.0453 0404 C:\Program Files\Download Manager\DLM.exe - ok
18:50:45.0453 0404 [ DF82E222578DBE59FCBBD69A02E4C806 ] C:\WINDOWS\system32\clusapi.dll
18:50:45.0453 0404 C:\WINDOWS\system32\clusapi.dll - ok
18:50:45.0453 0404 [ 4AC2FA4A6F0DF2511BAC13393C06EFF1 ] C:\WINDOWS\system32\mscms.dll
18:50:45.0453 0404 C:\WINDOWS\system32\mscms.dll - ok
18:50:45.0453 0404 [ D31398D4BB4907B517B6E784C2100C4A ] C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
18:50:45.0453 0404 C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe - ok
18:50:45.0468 0404 [ D21AB32F16E8DE67D45E5A383B5E52BA ] C:\Program Files\Spybot - Search & Destroy 2\ssleay32.dll
18:50:45.0468 0404 C:\Program Files\Spybot - Search & Destroy 2\ssleay32.dll - ok
18:50:45.0468 0404 [ AAB979089E192ACC0FE1E3C018F8B591 ] C:\Documents and Settings\John Richardson\Local Settings\Application Data\Akamai\netsession_win.exe
18:50:45.0468 0404 C:\Documents and Settings\John Richardson\Local Settings\Application Data\Akamai\netsession_win.exe - ok
18:50:45.0468 0404 [ 5532E51DE040535AB5F9FAB82BB8AB94 ] C:\Program Files\Download Manager\XceedZip.dll
18:50:45.0468 0404 C:\Program Files\Download Manager\XceedZip.dll - ok
18:50:45.0468 0404 [ 3CB78C17BB664637787C9A1C98F79C38 ] C:\WINDOWS\system32\tapisrv.dll
18:50:45.0468 0404 C:\WINDOWS\system32\tapisrv.dll - ok
18:50:45.0468 0404 [ FBFCA1A574D47EE575448B719CBBF2E4 ] C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll
18:50:45.0468 0404 C:\WINDOWS\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.6161_x-ww_730c3508\mfc90enu.dll - ok
18:50:45.0468 0404 [ 9B9F1C38D559047B8AC0DBA2D5FEBDE9 ] C:\WINDOWS\system32\ksuser.dll
18:50:45.0468 0404 C:\WINDOWS\system32\ksuser.dll - ok
18:50:45.0484 0404 [ 56DB34F4DC39CECBC871A895C6FCF1C3 ] C:\Program Files\AVAST Software\Avast\aswAra.dll
18:50:45.0484 0404 C:\Program Files\AVAST Software\Avast\aswAra.dll - ok
18:50:45.0484 0404 [ E7704CBF568815C1CAA6E513387BD3F2 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
18:50:45.0484 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe - ok
18:50:45.0484 0404 [ D72D08898E2BA14B8FD6E9533C714385 ] C:\Program Files\FileHippo.com\UpdateChecker.exe
18:50:45.0484 0404 C:\Program Files\FileHippo.com\UpdateChecker.exe - ok
18:50:45.0484 0404 [ 83BA5E873164A3711B44052F58C8FE9F ] C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll
18:50:45.0484 0404 C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscoreei.dll - ok
18:50:45.0484 0404 [ B009D6171147BE129636A49C4178E487 ] C:\Program Files\Spybot - Search & Destroy 2\libeay32.dll
18:50:45.0484 0404 C:\Program Files\Spybot - Search & Destroy 2\libeay32.dll - ok
18:50:45.0484 0404 [ B6A87D77CC1E839885EE875A77D89673 ] C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
18:50:45.0484 0404 C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe - ok
18:50:45.0484 0404 [ 27A48862C1474FB42D3C9E64DE790528 ] C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
18:50:45.0484 0404 C:\Program Files\Siber Systems\AI RoboForm\roboform.dll - ok
18:50:45.0500 0404 [ 2D0E4ED081963804CCC196A0929275B5 ] C:\WINDOWS\system32\wbem\wmisvc.dll
18:50:45.0500 0404 C:\WINDOWS\system32\wbem\wmisvc.dll - ok
18:50:45.0500 0404 [ FB53A700132D9A97D1E10E9F80BD6174 ] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
18:50:45.0500 0404 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll - ok
18:50:45.0500 0404 [ ACACB8B14E66109B8ACD6644B5574B9A ] C:\WINDOWS\system32\vssapi.dll
18:50:45.0500 0404 C:\WINDOWS\system32\vssapi.dll - ok
18:50:45.0500 0404 [ 44BD658E0E4D21C42023AD9EBEFFDB90 ] C:\Program Files\AVAST Software\Avast\ssleay32.dll
18:50:45.0500 0404 C:\Program Files\AVAST Software\Avast\ssleay32.dll - ok
18:50:45.0500 0404 [ 97D965A341C76FCB35B4344BFA2CBC06 ] C:\Program Files\Steam\Steam.exe
18:50:45.0500 0404 C:\Program Files\Steam\Steam.exe - ok
18:50:45.0500 0404 [ 8ED6DA45BAB5CFC809229F26D4D4A2CE ] C:\Program Files\AVAST Software\Avast\libeay32.dll
18:50:45.0500 0404 C:\Program Files\AVAST Software\Avast\libeay32.dll - ok
18:50:45.0500 0404 [ 58B8702C20DE211D1FCB248D2FDD71D1 ] C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe
18:50:45.0500 0404 C:\Program Files\Adobe\Reader 11.0\Reader\reader_sl.exe - ok
18:50:45.0515 0404 [ BC83108B18756547013ED443B8CDB31B ] C:\WINDOWS\system32\msvcp100.dll
18:50:45.0515 0404 C:\WINDOWS\system32\msvcp100.dll - ok
18:50:45.0515 0404 [ 5F1D5F88303D4A4DBC8E5F97BA967CC3 ] C:\WINDOWS\system32\ctfmon.exe
18:50:45.0515 0404 C:\WINDOWS\system32\ctfmon.exe - ok
18:50:45.0515 0404 [ E40FCF943127DDC8FD60554B722D762B ] C:\WINDOWS\system32\msctf.dll
18:50:45.0515 0404 C:\WINDOWS\system32\msctf.dll - ok
18:50:45.0515 0404 [ 5160A3D58EF8A6BD24A169508BB0A334 ] C:\WINDOWS\system32\asfsipc.dll
18:50:45.0515 0404 C:\WINDOWS\system32\asfsipc.dll - ok
18:50:45.0515 0404 [ 317C54DCAB9EE29CD4B9F55D197A90D1 ] C:\WINDOWS\system32\msisip.dll
18:50:45.0515 0404 C:\WINDOWS\system32\msisip.dll - ok
18:50:45.0515 0404 [ 3A6D465F379E5C815F4AD565391E654C ] C:\WINDOWS\system32\wshext.dll
18:50:45.0515 0404 C:\WINDOWS\system32\wshext.dll - ok
18:50:45.0531 0404 [ 7943A80F1A6FD37969AACD411B511F91 ] C:\WINDOWS\system32\WindowsPowerShell\v1.0\pwrshsip.dll
18:50:45.0531 0404 C:\WINDOWS\system32\WindowsPowerShell\v1.0\pwrshsip.dll - ok
18:50:45.0531 0404 [ F36BC7FB3A87DE9138AAECC40F7BC116 ] C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
18:50:45.0531 0404 C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll - ok
18:50:45.0531 0404 [ 0E37FBFA79D349D672456923EC5FBBE3 ] C:\WINDOWS\system32\msvcr100.dll
18:50:45.0531 0404 C:\WINDOWS\system32\msvcr100.dll - ok
18:50:45.0531 0404 [ 17AA58A54C00F1746B8654C050491F43 ] C:\WINDOWS\system32\msutb.dll
18:50:45.0531 0404 C:\WINDOWS\system32\msutb.dll - ok
18:50:45.0531 0404 [ 61C028ABA5E49573A6332F4A7C744E87 ] C:\Program Files\SpywareGuard\sgmain.exe
18:50:45.0531 0404 C:\Program Files\SpywareGuard\sgmain.exe - ok
18:50:45.0531 0404 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] C:\WINDOWS\system32\wuauserv.dll
18:50:45.0531 0404 C:\WINDOWS\system32\wuauserv.dll - ok
18:50:45.0531 0404 [ FC3EC24FCE372C89423E015A2AC1A31E ] C:\WINDOWS\system32\wuaueng.dll
18:50:45.0531 0404 C:\WINDOWS\system32\wuaueng.dll - ok
18:50:45.0546 0404 [ 8D7D6DF429B7D3CAC942FC5822B99DC8 ] C:\Program Files\Xfire\Xfire.exe
18:50:45.0546 0404 C:\Program Files\Xfire\Xfire.exe - ok
18:50:45.0546 0404 [ 09523AFBC5937D7CC786FC9C74D2D516 ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll
18:50:45.0546 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll - ok
18:50:45.0546 0404 [ BB7B759E9ED35321C934A620DC4BD9B0 ] C:\Program Files\Steam\crashhandler.dll
18:50:45.0546 0404 C:\Program Files\Steam\crashhandler.dll - ok
18:50:45.0546 0404 [ C8B5FB0ED09E9F24DB844905521AC205 ] C:\Program Files\Steam\steamerrorreporter.exe
18:50:45.0546 0404 C:\Program Files\Steam\steamerrorreporter.exe - ok
18:50:45.0546 0404 [ 529EFD4CD976A5418B88DFCDE40EC239 ] C:\Program Files\Steam\tier0_s.dll
18:50:45.0546 0404 C:\Program Files\Steam\tier0_s.dll - ok
18:50:45.0546 0404 [ 548CB85DE1EAD453292A7EA02C4CFCA9 ] C:\Program Files\Steam\vstdlib_s.dll
18:50:45.0546 0404 C:\Program Files\Steam\vstdlib_s.dll - ok
18:50:45.0546 0404 [ 8891EBB0BA7DBDAC80395952ACFBF5EC ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\898552cef448b07502cc2c9e9763c07a\System.ni.dll
18:50:45.0546 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\898552cef448b07502cc2c9e9763c07a\System.ni.dll - ok
18:50:45.0562 0404 [ A7532E66EA2F168A0970E829D8986423 ] C:\Program Files\Steam\dbghelp.dll
18:50:45.0562 0404 C:\Program Files\Steam\dbghelp.dll - ok
18:50:45.0562 0404 [ F6FAEC07446A78A9C5AF4558FF5BD118 ] C:\WINDOWS\ime\sptip.dll
18:50:45.0562 0404 C:\WINDOWS\ime\sptip.dll - ok
18:50:45.0562 0404 [ 382668323400BD3BCFE9FFF249515975 ] C:\WINDOWS\system32\avifil32.dll
18:50:45.0562 0404 C:\WINDOWS\system32\avifil32.dll - ok
18:50:45.0562 0404 [ B85E95679B5ADC12311BCD3F5385D623 ] C:\WINDOWS\system32\mspatcha.dll
18:50:45.0562 0404 C:\WINDOWS\system32\mspatcha.dll - ok
18:50:45.0562 0404 [ 8BCD11D38FCE43A519246A91CC40DE6A ] C:\WINDOWS\system32\security.dll
18:50:45.0562 0404 C:\WINDOWS\system32\security.dll - ok
18:50:45.0562 0404 [ 723528449ED0D1B0AD98AF3EDF23101D ] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
18:50:45.0562 0404 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll - ok
18:50:45.0562 0404 [ 3C611E94321D6A82EB4C5BCD34FC9F5D ] C:\Program Files\Spybot - Search & Destroy 2\SDResources.dll
18:50:45.0562 0404 C:\Program Files\Spybot - Search & Destroy 2\SDResources.dll - ok
18:50:45.0578 0404 [ 235B2311786AC007AD644B12A2DA8AC7 ] C:\WINDOWS\system32\msvfw32.dll
18:50:45.0578 0404 C:\WINDOWS\system32\msvfw32.dll - ok
18:50:45.0578 0404 [ 2D195CF5DCC1FCAF60EDF2AA1E1C8961 ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\14c7539697f628595ed92cd51149db78\System.Drawing.ni.dll
18:50:45.0578 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\14c7539697f628595ed92cd51149db78\System.Drawing.ni.dll - ok
18:50:45.0578 0404 [ CFD4E51402DA9838B5A04AE680AF54A0 ] C:\WINDOWS\system32\browser.dll
18:50:45.0578 0404 C:\WINDOWS\system32\browser.dll - ok
18:50:45.0578 0404 [ 20F89E232173985A455BC9A5F70D1166 ] C:\Program Files\Canon\CAL\CALMAIN.exe
18:50:45.0578 0404 C:\Program Files\Canon\CAL\CALMAIN.exe - ok
18:50:45.0578 0404 [ AA0507F0516A4DFF1B1279AB4A2ABB37 ] C:\WINDOWS\system32\dinput8.dll
18:50:45.0578 0404 C:\WINDOWS\system32\dinput8.dll - ok
18:50:45.0578 0404 [ 05CE41DEA7BCD37BA1B22461B42918E3 ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c784b72df85e3b35b4f8a4054a2e43e1\Microsoft.VisualBasic.ni.dll
18:50:45.0578 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\c784b72df85e3b35b4f8a4054a2e43e1\Microsoft.VisualBasic.ni.dll - ok
18:50:45.0593 0404 [ 7C278E6408D1DCE642230C0585A854D5 ] C:\WINDOWS\system32\wscsvc.dll
18:50:45.0593 0404 C:\WINDOWS\system32\wscsvc.dll - ok
18:50:45.0593 0404 [ 8973122796E3B5D6B5900FC186E55FEA ] C:\WINDOWS\system32\hid.dll
18:50:45.0593 0404 C:\WINDOWS\system32\hid.dll - ok
18:50:45.0593 0404 [ E97D6A8684466DF94FF3BC24FB787A07 ] C:\WINDOWS\system32\fxssvc.exe
18:50:45.0593 0404 C:\WINDOWS\system32\fxssvc.exe - ok
18:50:45.0593 0404 [ 3CAEAE7608F1BD7BA873A3B02895B106 ] C:\WINDOWS\system32\sti.dll
18:50:45.0593 0404 C:\WINDOWS\system32\sti.dll - ok
18:50:45.0593 0404 [ 3128388794EE8F7BE2A15C48A4969E09 ] C:\Program Files\Xfire\xfire_lang_us.dll
18:50:45.0593 0404 C:\Program Files\Xfire\xfire_lang_us.dll - ok
18:50:45.0593 0404 [ 03B0224FD1E2D8A6DBC2B18404092F21 ] C:\WINDOWS\system32\MSCOMCTL.OCX
18:50:45.0593 0404 C:\WINDOWS\system32\MSCOMCTL.OCX - ok
18:50:45.0609 0404 [ 83F41D0D89645D7235C051AB1D9523AC ] C:\WINDOWS\system32\ipnathlp.dll
18:50:45.0609 0404 C:\WINDOWS\system32\ipnathlp.dll - ok
18:50:45.0609 0404 [ 1144EF6B4BB72E33B41912AE1AE4F97A ] C:\WINDOWS\system32\fxstiff.dll
18:50:45.0609 0404 C:\WINDOWS\system32\fxstiff.dll - ok
18:50:45.0609 0404 [ F0BF811622F2DD6C8E26EE4600D83731 ] C:\WINDOWS\system32\wbem\wbemcore.dll
18:50:45.0609 0404 C:\WINDOWS\system32\wbem\wbemcore.dll - ok
18:50:45.0609 0404 [ 0329D0A4F230094B669A87BB3B85606E ] C:\WINDOWS\system32\fxsapi.dll
18:50:45.0609 0404 C:\WINDOWS\system32\fxsapi.dll - ok
18:50:45.0609 0404 [ E4616430709F440CF1809D88DC2366EA ] C:\WINDOWS\system32\wbem\esscli.dll
18:50:45.0609 0404 C:\WINDOWS\system32\wbem\esscli.dll - ok
18:50:45.0609 0404 [ 69EE0CB3B05F619EFF7E46F978BBFEEA ] C:\WINDOWS\system32\asycfilt.dll
18:50:45.0609 0404 C:\WINDOWS\system32\asycfilt.dll - ok
18:50:45.0625 0404 [ 378A0AEFB11D8B0DC8C27B9F7604B88D ] C:\WINDOWS\system32\wbem\fastprox.dll
18:50:45.0625 0404 C:\WINDOWS\system32\wbem\fastprox.dll - ok
18:50:45.0625 0404 [ EDF228582B23306F04E13E11B0D5F167 ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fd283696d695cab0aca331cb9cbbcacd\System.Windows.Forms.ni.dll
18:50:45.0625 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fd283696d695cab0aca331cb9cbbcacd\System.Windows.Forms.ni.dll - ok
18:50:45.0625 0404 [ EB4A8F35A70A887FE32F43A3AA7D4E9A ] C:\WINDOWS\system32\RICHTX32.OCX
18:50:45.0625 0404 C:\WINDOWS\system32\RICHTX32.OCX - ok
18:50:45.0625 0404 [ 2849F13593D2712CCB97FFBDD3C1232E ] C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
18:50:45.0625 0404 C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll - ok
18:50:45.0625 0404 [ F8DE742E9B6EA8A31F91AD210FA1DFCE ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\b24d7c1afb003e95c6f5d924c56b930c\System.Configuration.ni.dll
18:50:45.0625 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\b24d7c1afb003e95c6f5d924c56b930c\System.Configuration.ni.dll - ok
18:50:45.0625 0404 [ D4931277DF5393E84A48B27DF40914E3 ] C:\WINDOWS\system32\riched32.dll
18:50:45.0625 0404 C:\WINDOWS\system32\riched32.dll - ok
18:50:45.0625 0404 [ ED0C0DF222209E43AD9AFBF3FE87DDE0 ] C:\WINDOWS\system32\comsvcs.dll
18:50:45.0625 0404 C:\WINDOWS\system32\comsvcs.dll - ok
18:50:45.0640 0404 [ A80D0704537C0EF97DB2BEF24B99AF1A ] C:\Program Files\SpywareGuard\sgbhp.exe
18:50:45.0640 0404 C:\Program Files\SpywareGuard\sgbhp.exe - ok
18:50:45.0640 0404 [ ADD723D648DE42C62CB1B0C33E8135BC ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f2e0f6dacd8c58ef0e1bb788ca4347ee\System.Xml.ni.dll
18:50:45.0640 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\f2e0f6dacd8c58ef0e1bb788ca4347ee\System.Xml.ni.dll - ok
18:50:45.0640 0404 [ 0CE5F8AE9C371A965D17E3F2ED134809 ] C:\WINDOWS\system32\fxst30.dll
18:50:45.0640 0404 C:\WINDOWS\system32\fxst30.dll - ok
18:50:45.0640 0404 [ 2D583E2844FDD592D1629EB6B10E5702 ] C:\WINDOWS\system32\fxsroute.dll
18:50:45.0640 0404 C:\WINDOWS\system32\fxsroute.dll - ok
18:50:45.0640 0404 [ A86E5F8E16DA4F9E30E29C186D977BBF ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll
18:50:45.0640 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Implementation.dll - ok
18:50:45.0640 0404 [ 690D97864735E8ECD87F55777E266690 ] C:\WINDOWS\system32\colbact.dll
18:50:45.0640 0404 C:\WINDOWS\system32\colbact.dll - ok
18:50:45.0656 0404 [ 3851909899A5E6210C58DB9CC02068D3 ] C:\Program Files\AVAST Software\Avast\aswData.dll
18:50:45.0656 0404 C:\Program Files\AVAST Software\Avast\aswData.dll - ok
18:50:45.0656 0404 [ 36795A645EAA47FE31D2A8F136A2C69B ] C:\WINDOWS\system32\mtxclu.dll
18:50:45.0656 0404 C:\WINDOWS\system32\mtxclu.dll - ok
18:50:45.0656 0404 [ 5D43C9A33F18C707BA169AFDA88BDF30 ] C:\WINDOWS\system32\fltlib.dll
18:50:45.0656 0404 C:\WINDOWS\system32\fltlib.dll - ok
18:50:45.0656 0404 [ E385B9E07B08C3F686B45D52C9F5A9B9 ] C:\Program Files\AVAST Software\Avast\AhResBhv.dll
18:50:45.0656 0404 C:\Program Files\AVAST Software\Avast\AhResBhv.dll - ok
18:50:45.0656 0404 [ E28034BDEDD48E44C889FF40C462005D ] C:\Program Files\AVAST Software\Avast\AhResJs.dll
18:50:45.0656 0404 C:\Program Files\AVAST Software\Avast\AhResJs.dll - ok
18:50:45.0656 0404 [ B20C06BDE50900C33CEE861E5B288ABF ] C:\Program Files\AVAST Software\Avast\AhResMai.dll
18:50:45.0656 0404 C:\Program Files\AVAST Software\Avast\AhResMai.dll - ok
18:50:45.0656 0404 [ DAC5B3F300E08EFA9782F6DD0E4A9FDA ] C:\Program Files\AVAST Software\Avast\AhResMes.dll
18:50:45.0656 0404 C:\Program Files\AVAST Software\Avast\AhResMes.dll - ok
18:50:45.0671 0404 [ F51EBB6FC536A6B2D588FD668D3A8249 ] C:\WINDOWS\system32\resutils.dll
18:50:45.0671 0404 C:\WINDOWS\system32\resutils.dll - ok
18:50:45.0671 0404 [ 5B07E1B2414CE6A7F8942493F194B697 ] C:\Program Files\AVAST Software\Avast\AhResNS.dll
18:50:45.0671 0404 C:\Program Files\AVAST Software\Avast\AhResNS.dll - ok
18:50:45.0671 0404 [ D5C8A650F8F6BDC3F3847BD679992372 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.dll
18:50:45.0671 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.dll - ok
18:50:45.0671 0404 [ F9AA8285BE0CCB3BDD77549DFC817423 ] C:\Program Files\AVAST Software\Avast\AhResP2P.dll
18:50:45.0671 0404 C:\Program Files\AVAST Software\Avast\AhResP2P.dll - ok
18:50:45.0671 0404 [ AACE07FE34FADDDF973CE068A6424957 ] C:\WINDOWS\system32\unimdm.tsp
18:50:45.0671 0404 C:\WINDOWS\system32\unimdm.tsp - ok
18:50:45.0671 0404 [ 8479249A6E3ED306524D60AD1222F1CB ] C:\Program Files\AVAST Software\Avast\AhResSPM.dll
18:50:45.0671 0404 C:\Program Files\AVAST Software\Avast\AhResSPM.dll - ok
18:50:45.0687 0404 [ 90622E62EABD12FFEACEF083E765707C ] C:\Program Files\AVAST Software\Avast\AhResStd.dll
18:50:45.0687 0404 C:\Program Files\AVAST Software\Avast\AhResStd.dll - ok
18:50:45.0687 0404 [ B7F721185071CF20CAB25CC2869BE0C2 ] C:\Program Files\AVAST Software\Avast\AhResWS.dll
18:50:45.0687 0404 C:\Program Files\AVAST Software\Avast\AhResWS.dll - ok
18:50:45.0687 0404 [ 995252FCC4692B5B97EE17D596C9386E ] C:\WINDOWS\system32\uniplat.dll
18:50:45.0687 0404 C:\WINDOWS\system32\uniplat.dll - ok
18:50:45.0687 0404 [ 010472D0AE758227C6F6E6933549C219 ] C:\WINDOWS\system32\wbem\wbemsvc.dll
18:50:45.0687 0404 C:\WINDOWS\system32\wbem\wbemsvc.dll - ok
18:50:45.0687 0404 [ 9EEFE69139FDBB4A3C327630F8EB993A ] C:\WINDOWS\system32\wlanapi.dll
18:50:45.0687 0404 C:\WINDOWS\system32\wlanapi.dll - ok
18:50:45.0687 0404 [ 76EC97C5068D3D9FAA7774B0F659D31A ] C:\WINDOWS\system32\kmddsp.tsp
18:50:45.0687 0404 C:\WINDOWS\system32\kmddsp.tsp - ok
18:50:45.0687 0404 [ 3458EDA96E30FBD0477A2800D3FB1909 ] C:\WINDOWS\system32\wups.dll
18:50:45.0687 0404 C:\WINDOWS\system32\wups.dll - ok
18:50:45.0703 0404 [ BDC0C99E472176C8C2C853A68ADC5073 ] C:\WINDOWS\system32\wups2.dll
18:50:45.0703 0404 C:\WINDOWS\system32\wups2.dll - ok
18:50:45.0703 0404 [ 3903D13970361F49C01EB0BEE2C51ADD ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Private.dll
18:50:45.0703 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Private.dll - ok
18:50:45.0703 0404 [ 4589963D84F2984FA5949A72162BA4F4 ] C:\WINDOWS\system32\ndptsp.tsp
18:50:45.0703 0404 C:\WINDOWS\system32\ndptsp.tsp - ok
18:50:45.0703 0404 [ 173DE2DB117B0874368BD6BD115E715B ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.dll
18:50:45.0703 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.dll - ok
18:50:45.0703 0404 [ 3273D1565BF30225C115B480A3BB2C9D ] C:\WINDOWS\system32\wbem\wmiutils.dll
18:50:45.0703 0404 C:\WINDOWS\system32\wbem\wmiutils.dll - ok
18:50:45.0703 0404 [ 8B8A45DF7CEF36D93C7BD3E4C84003B8 ] C:\WINDOWS\system32\ipconf.tsp
18:50:45.0703 0404 C:\WINDOWS\system32\ipconf.tsp - ok
18:50:45.0703 0404 [ 942A17D2901A31EA68627CBFFCD268CC ] C:\WINDOWS\system32\wbem\repdrvfs.dll
18:50:45.0703 0404 C:\WINDOWS\system32\wbem\repdrvfs.dll - ok
18:50:45.0718 0404 [ B0F7BC16B936A6C30B3249D4F7FA1240 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Foundation.dll
18:50:45.0718 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.Foundation.dll - ok
18:50:45.0718 0404 [ 401A8C0BE0BAA7D7A470F0942244152D ] C:\WINDOWS\system32\rasdlg.dll
18:50:45.0718 0404 C:\WINDOWS\system32\rasdlg.dll - ok
18:50:45.0718 0404 [ 29BD913D8FD1FEB6728DC9B43B55C1D2 ] C:\WINDOWS\system32\msrating.dll
18:50:45.0718 0404 C:\WINDOWS\system32\msrating.dll - ok
18:50:45.0718 0404 [ 8BC2B02DC11C98D14CEE43B8E8393FF3 ] C:\WINDOWS\system32\h323.tsp
18:50:45.0718 0404 C:\WINDOWS\system32\h323.tsp - ok
18:50:45.0718 0404 [ D546BDE9F847B3723AD0B8BC9F3BEB89 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.Private.dll
18:50:45.0718 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\LOG.Foundation.Implementation.Private.dll - ok
18:50:45.0718 0404 [ 6B552ED3BEE5AA3C4560478FF779BA98 ] C:\WINDOWS\system32\hidphone.tsp
18:50:45.0718 0404 C:\WINDOWS\system32\hidphone.tsp - ok
18:50:45.0734 0404 [ 071143F687B4F887E21461CA6CC7EB29 ] C:\WINDOWS\system32\wbem\wmiprvsd.dll
18:50:45.0734 0404 C:\WINDOWS\system32\wbem\wmiprvsd.dll - ok
18:50:45.0734 0404 [ 05CF1926E4E7B6D91D66BD5CD54FC1F0 ] C:\WINDOWS\system32\mshtml.dll
18:50:45.0734 0404 C:\WINDOWS\system32\mshtml.dll - ok
18:50:45.0734 0404 [ 2E0B0A051FFAA86E358465BB0880D453 ] C:\WINDOWS\system32\wuauclt.exe
18:50:45.0734 0404 C:\WINDOWS\system32\wuauclt.exe - ok
18:50:45.0734 0404 [ 26D881D27CBE51D3614E68D7313EA026 ] C:\WINDOWS\system32\wbem\wbemess.dll
18:50:45.0734 0404 C:\WINDOWS\system32\wbem\wbemess.dll - ok
18:50:45.0734 0404 [ 2ACCD352451EC0F99AF2AD9DB6DB4439 ] C:\WINDOWS\system32\msls31.dll
18:50:45.0734 0404 C:\WINDOWS\system32\msls31.dll - ok
18:50:45.0734 0404 [ CCE5D71F19AB70D969F9819B5C88438D ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
18:50:45.0734 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe - ok
18:50:45.0734 0404 [ 0C5ACA496D806699C8936821DE27063A ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.Implementation.dll
18:50:45.0734 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.Implementation.dll - ok
18:50:45.0750 0404 [ 1A617835452EEE5060976C9B9F5FE635 ] C:\WINDOWS\system32\wuapi.dll
18:50:45.0750 0404 C:\WINDOWS\system32\wuapi.dll - ok
18:50:45.0750 0404 [ 2A7DDB03AEF3B92960780DAAFB953625 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.dll
18:50:45.0750 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.dll - ok
18:50:45.0750 0404 [ FF3477C03BE7201C294C35F684B3479F ] C:\WINDOWS\system32\termsrv.dll
18:50:45.0750 0404 C:\WINDOWS\system32\termsrv.dll - ok
18:50:45.0750 0404 [ D2E405C668BB218275DE80FF0DAA79D8 ] C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\e40fa0e028ce1e45dea4270399281a4a\System.Web.ni.dll
18:50:45.0750 0404 C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\e40fa0e028ce1e45dea4270399281a4a\System.Web.ni.dll - ok
18:50:45.0750 0404 [ 219AF0F9A54EBEEB3E7E20025D801034 ] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll
18:50:45.0750 0404 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Culture.dll - ok
18:50:45.0750 0404 [ A3BB91467FBDDA34039686C95A31C8C2 ] C:\Program Files\AVAST Software\Avast\1033\uiLangRes.dll
18:50:45.0750 0404 C:\Program Files\AVAST Software\Avast\1033\uiLangRes.dll - ok
18:50:45.0750 0404 [ DF6551E4C4C46655A0C76194F1FCEA5D ] C:\WINDOWS\system32\icaapi.dll
18:50:45.0750 0404 C:\WINDOWS\system32\icaapi.dll - ok
18:50:45.0765 0404 [ D26451B540720A7313A9BCBE794DAF62 ] C:\WINDOWS\system32\wbem\ncprov.dll
18:50:45.0765 0404 C:\WINDOWS\system32\wbem\ncprov.dll - ok
18:50:45.0765 0404 [ 2D65D56C2F8B6CC5EBFF8E7200C30304 ] C:\WINDOWS\system32\mstlsapi.dll
18:50:45.0765 0404 C:\WINDOWS\system32\mstlsapi.dll - ok
18:50:45.0765 0404 [ 5684CD3B207C1668DEE6BD2802C25B19 ] C:\Program Files\AVAST Software\Avast\CommonRes.dll
18:50:45.0765 0404 C:\Program Files\AVAST Software\Avast\CommonRes.dll - ok
18:50:45.0765 0404 [ 6404807ABC7AF52FA3792697AE638B50 ] C:\WINDOWS\system32\wbem\wbemcons.dll
18:50:45.0765 0404 C:\WINDOWS\system32\wbem\wbemcons.dll - ok
18:50:45.0765 0404 [ EBCDE8B48FADC6479D96A56D0A432160 ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
18:50:45.0765 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe - ok
18:50:45.0765 0404 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] C:\WINDOWS\system32\rasmans.dll
18:50:45.0765 0404 C:\WINDOWS\system32\rasmans.dll - ok
18:50:45.0781 0404 [ ADB2A6EF0AD67E4E1CACBFD253CE25F9 ] C:\Program Files\Xfire\icons.dll
18:50:45.0781 0404 C:\Program Files\Xfire\icons.dll - ok
18:50:45.0781 0404 [ 5F7692CEC90E2E9AA32CD58321E234B8 ] C:\WINDOWS\system32\rastapi.dll
18:50:45.0781 0404 C:\WINDOWS\system32\rastapi.dll - ok
18:50:45.0781 0404 [ D0545A010ED2259A740C8414899A938F ] C:\WINDOWS\system32\rasppp.dll
18:50:45.0781 0404 C:\WINDOWS\system32\rasppp.dll - ok
18:50:45.0781 0404 [ B464BD425D5D09ABE4192234D1577B22 ] C:\WINDOWS\system32\ntlsapi.dll
18:50:45.0781 0404 C:\WINDOWS\system32\ntlsapi.dll - ok
18:50:45.0781 0404 [ A655C88AA555BB8EF8957BD29408827F ] C:\WINDOWS\system32\rasqec.dll
18:50:45.0781 0404 C:\WINDOWS\system32\rasqec.dll - ok
18:50:45.0781 0404 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] C:\WINDOWS\system32\imapi.exe
18:50:45.0781 0404 C:\WINDOWS\system32\imapi.exe - ok
18:50:45.0781 0404 [ 7CB6D621C6B3F70866F102A71C50CD46 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.SkinFactory.dll
18:50:45.0781 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Component.SkinFactory.dll - ok
18:50:45.0796 0404 [ 54E10AD6EBBEDCB221ADED5D9F0C8F3F ] C:\Program Files\Common Files\Microsoft Shared\DAO\dao360.dll
18:50:45.0796 0404 C:\Program Files\Common Files\Microsoft Shared\DAO\dao360.dll - ok
18:50:45.0796 0404 [ 798A9E6828997EEF4517ADA8A2259831 ] C:\WINDOWS\system32\wbem\wmiprvse.exe
18:50:45.0796 0404 C:\WINDOWS\system32\wbem\wmiprvse.exe - ok
18:50:45.0796 0404 [ 96BF374B0E6C727D7D62294A7D747322 ] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.XManifest.dll
18:50:45.0796 0404 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Foundation.XManifest.dll - ok
18:50:45.0796 0404 [ 574738F61FCA2935F5265DC4E5691314 ] C:\WINDOWS\system32\qmgr.dll
18:50:45.0796 0404 C:\WINDOWS\system32\qmgr.dll - ok
18:50:45.0796 0404 [ 8C515081584A38AA007909CD02020B3D ] C:\WINDOWS\system32\alg.exe
18:50:45.0796 0404 C:\WINDOWS\system32\alg.exe - ok
18:50:45.0796 0404 [ 90A9B542C9300E540864D9FE1C42A130 ] C:\WINDOWS\system32\fxsst.dll
18:50:45.0796 0404 C:\WINDOWS\system32\fxsst.dll - ok
18:50:45.0812 0404 [ 142843A24FEBB7BDED976F42C8E91384 ] C:\Program Files\AVAST Software\Avast\defs\13062500\ArPot.dll
18:50:45.0812 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\ArPot.dll - ok
18:50:45.0812 0404 [ 6895427873D6C37A6D6DA7C3DB37DA14 ] C:\WINDOWS\system32\licwmi.dll
18:50:45.0812 0404 C:\WINDOWS\system32\licwmi.dll - ok
18:50:45.0812 0404 [ 9E70016C950B1F8FDEAA6F067E2E25A8 ] C:\WINDOWS\system32\msjet40.dll
18:50:45.0812 0404 C:\WINDOWS\system32\msjet40.dll - ok
18:50:45.0812 0404 [ A2EAE71B251BD27B0F4185CF9699A1C2 ] C:\Program Files\AVAST Software\Avast\ashMaiSv.dll
18:50:45.0812 0404 C:\Program Files\AVAST Software\Avast\ashMaiSv.dll - ok
18:50:45.0812 0404 [ F1DAC7969C1337AF790BD1D981AA780C ] C:\WINDOWS\system32\qmgrprxy.dll
18:50:45.0812 0404 C:\WINDOWS\system32\qmgrprxy.dll - ok
18:50:45.0812 0404 [ A693A49A67673F2C8D76797EA9A628D0 ] C:\WINDOWS\system32\licdll.dll
18:50:45.0812 0404 C:\WINDOWS\system32\licdll.dll - ok
18:50:45.0812 0404 [ 485E0C58DEFD200C87BB4E38346B207E ] C:\Program Files\Xfire\xfire_toucan_46139.dll
18:50:45.0812 0404 C:\Program Files\Xfire\xfire_toucan_46139.dll - ok
18:50:45.0812 0404 [ AFDC647D16B285B9AE6140335B3B3255 ] C:\WINDOWS\system32\mswstr10.dll
18:50:45.0812 0404 C:\WINDOWS\system32\mswstr10.dll - ok
18:50:45.0828 0404 [ CAFBD14F56A68E6C1A55C0EAC7E487FA ] C:\WINDOWS\system32\vbajet32.dll
18:50:45.0828 0404 C:\WINDOWS\system32\vbajet32.dll - ok
18:50:45.0828 0404 [ BE87245CE60329B31C94F1B4236E5832 ] C:\WINDOWS\system32\expsrv.dll
18:50:45.0828 0404 C:\WINDOWS\system32\expsrv.dll - ok
18:50:45.0828 0404 [ B6D90C99A72044AEF85A2B7D78FEBEF4 ] C:\Program Files\AVAST Software\Avast\defs\13062500\exts.dll
18:50:45.0828 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\exts.dll - ok
18:50:45.0828 0404 [ BF0873241C01C97E9E027C68863914C6 ] C:\Program Files\AVAST Software\Avast\ashWebSv.dll
18:50:45.0828 0404 C:\Program Files\AVAST Software\Avast\ashWebSv.dll - ok
18:50:45.0828 0404 [ 0F2B9A24F8463EEC4E363AA36F763917 ] C:\Program Files\AVAST Software\Avast\ashWsFtr.dll
18:50:45.0828 0404 C:\Program Files\AVAST Software\Avast\ashWsFtr.dll - ok
18:50:45.0828 0404 [ 10AA3E99691C9782308A4768F0485D8D ] C:\Program Files\AVAST Software\Avast\aswPatchMgt.dll
18:50:45.0828 0404 C:\Program Files\AVAST Software\Avast\aswPatchMgt.dll - ok
18:50:45.0843 0404 [ 8FC931CA97B8DA19A380AB653AC3D6B7 ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswAR.dll
18:50:45.0843 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswAR.dll - ok
18:50:45.0843 0404 [ 9EC1D983086E5FA14FFB3518B7E3B596 ] C:\Program Files\AVAST Software\Avast\defs\13062500\aswRawFS.dll
18:50:45.0843 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\aswRawFS.dll - ok
18:50:45.0843 0404 [ F72C76B8BF17E95EC73C85D77C20DB85 ] C:\Program Files\AVAST Software\Avast\defs\13062500\swhealthex.dll
18:50:45.0843 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\swhealthex.dll - ok
18:50:45.0843 0404 [ F099B129022170F2DF9E1C0185C9BCFB ] C:\WINDOWS\system32\d3d8.dll
18:50:45.0843 0404 C:\WINDOWS\system32\d3d8.dll - ok
18:50:45.0843 0404 [ 8DB479E065F2B546BFBD7323E5EE5B02 ] C:\WINDOWS\system32\Macromed\Flash\Flash32_11_7_700_224.ocx
18:50:45.0843 0404 C:\WINDOWS\system32\Macromed\Flash\Flash32_11_7_700_224.ocx - ok
18:50:45.0843 0404 [ 8598C2AE3A7C7281B1290297C7CCFD57 ] C:\Program Files\AVAST Software\Avast\Setup\avast.setup
18:50:45.0843 0404 C:\Program Files\AVAST Software\Avast\Setup\avast.setup - ok
18:50:45.0843 0404 [ 9EFBB3055B3EECE5B0FC7BAED07A6EE9 ] C:\WINDOWS\system32\msxml6.dll
18:50:45.0843 0404 C:\WINDOWS\system32\msxml6.dll - ok
18:50:45.0875 0404 [ 31B067C412FA1A9BAD3CA2A63D7DA440 ] C:\WINDOWS\system32\d3d8thk.dll
18:50:45.0875 0404 C:\WINDOWS\system32\d3d8thk.dll - ok
18:50:45.0875 0404 [ E73274AB53EB0E32B2EE0D090320DEB8 ] C:\Program Files\Java\jre7\bin\keytool.exe
18:50:45.0875 0404 C:\Program Files\Java\jre7\bin\keytool.exe - ok
18:50:45.0875 0404 [ F0A0EBF086597E645BC14B0D98F8BA58 ] C:\WINDOWS\system32\scrrun.dll
18:50:45.0875 0404 C:\WINDOWS\system32\scrrun.dll - ok
18:50:45.0875 0404 [ F3CD3269896D64ECAEA4CA34BCEAC381 ] C:\Program Files\AVAST Software\Avast\snxhk.dll
18:50:45.0875 0404 C:\Program Files\AVAST Software\Avast\snxhk.dll - ok
18:50:45.0875 0404 [ B7C7FA3BEDE83AC5F1DE03B30D494CC1 ] C:\WINDOWS\system32\httpapi.dll
18:50:45.0875 0404 C:\WINDOWS\system32\httpapi.dll - ok
18:50:45.0875 0404 [ 0607CBC6FA20114CB491EFE4B2F9EFAD ] C:\WINDOWS\system32\d3d9.dll
18:50:45.0875 0404 C:\WINDOWS\system32\d3d9.dll - ok
18:50:45.0875 0404 [ 86947F0A12A04408467305A8437140A6 ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSAlbumObjects.dll
18:50:45.0875 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSAlbumObjects.dll - ok
18:50:45.0890 0404 [ E5DE87DDDB8CBE4687EADF296E58452A ] C:\WINDOWS\system32\msjtes40.dll
18:50:45.0890 0404 C:\WINDOWS\system32\msjtes40.dll - ok
18:50:45.0890 0404 [ 67C00DCE9154BA38F653E28B6B674B80 ] C:\Program Files\Java\jre7\bin\jli.dll
18:50:45.0890 0404 C:\Program Files\Java\jre7\bin\jli.dll - ok
18:50:45.0890 0404 [ 860FAD57B4668A9F5F350A9D5444AE89 ] C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll
18:50:45.0890 0404 C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\diasymreader.dll - ok
18:50:45.0890 0404 [ 548AAB0656CA8F5A31D256ED5D488907 ] C:\Program Files\Steam\Steam.dll
18:50:45.0890 0404 C:\Program Files\Steam\Steam.dll - ok
18:50:45.0890 0404 [ E837FDBB92E9873E538395B623F45462 ] C:\WINDOWS\system32\wbem\cimwin32.dll
18:50:45.0890 0404 C:\WINDOWS\system32\wbem\cimwin32.dll - ok
18:50:45.0890 0404 [ 6100A808600F44D999CEBDEF8841C7A3 ] C:\WINDOWS\system32\w3ssl.dll
18:50:45.0890 0404 C:\WINDOWS\system32\w3ssl.dll - ok
18:50:45.0890 0404 [ 4A93B65CFB514F2EA76B59568D5F39CE ] C:\WINDOWS\system32\strmfilt.dll
18:50:45.0890 0404 C:\WINDOWS\system32\strmfilt.dll - ok
18:50:45.0906 0404 [ A340CD71EB535A3DD751B5F28723E50C ] C:\WINDOWS\system32\ddraw.dll
18:50:45.0906 0404 C:\WINDOWS\system32\ddraw.dll - ok
18:50:45.0906 0404 [ D8B91D94ECB123862B390FDE3250D3BB ] C:\WINDOWS\system32\dciman32.dll
18:50:45.0906 0404 C:\WINDOWS\system32\dciman32.dll - ok
18:50:45.0906 0404 [ EF8B383B78C689E3709733DC32D00E30 ] C:\Program Files\Java\jre7\bin\client\jvm.dll
18:50:45.0906 0404 C:\Program Files\Java\jre7\bin\client\jvm.dll - ok
18:50:45.0906 0404 [ 56ADB11F7D4D0816C0BE1E701C1B5E52 ] C:\WINDOWS\system32\d3dim700.dll
18:50:45.0906 0404 C:\WINDOWS\system32\d3dim700.dll - ok
18:50:45.0906 0404 [ 900A9D261859EC999C9C7243410C3203 ] C:\Program Files\Common Files\Roxio Shared\DLLShared\HomeUtils9.dll
18:50:45.0906 0404 C:\Program Files\Common Files\Roxio Shared\DLLShared\HomeUtils9.dll - ok
18:50:45.0906 0404 [ 5E28284F9B5F9097640D58A73D38AD4C ] C:\WINDOWS\system32\notepad.exe
18:50:45.0906 0404 C:\WINDOWS\system32\notepad.exe - ok
18:50:45.0921 0404 [ 072EB0B839C66230C0270FF456926398 ] C:\Program Files\Java\jre7\bin\verify.dll
18:50:45.0921 0404 C:\Program Files\Java\jre7\bin\verify.dll - ok
18:50:45.0921 0404 [ 4175947F6807534188BEA3BB0DD17C66 ] C:\Program Files\Common Files\Roxio Shared\DLLShared\rsl.dll
18:50:45.0921 0404 C:\Program Files\Common Files\Roxio Shared\DLLShared\rsl.dll - ok
18:50:45.0921 0404 [ 5C1F0537E61F87B435F56E00B4F20EE8 ] C:\WINDOWS\system32\snmpapi.dll
18:50:45.0921 0404 C:\WINDOWS\system32\snmpapi.dll - ok
18:50:45.0921 0404 [ 88D4171DA8B349B4BA1DF170E44D0775 ] C:\Program Files\Java\jre7\bin\java.dll
18:50:45.0921 0404 C:\Program Files\Java\jre7\bin\java.dll - ok
18:50:45.0921 0404 [ E86FEB7F883E356404A30BD55AF67AAB ] C:\Program Files\Java\jre7\bin\zip.dll
18:50:45.0921 0404 C:\Program Files\Java\jre7\bin\zip.dll - ok
18:50:45.0921 0404 [ F35A584E947A5B401FEB0FE01DB4A0D7 ] C:\WINDOWS\system32\mfc71.dll
18:50:45.0921 0404 C:\WINDOWS\system32\mfc71.dll - ok
18:50:45.0937 0404 [ C730F70351D950DDA7388C9A9763CF54 ] C:\WINDOWS\system32\wbem\wmipcima.dll
18:50:45.0937 0404 C:\WINDOWS\system32\wbem\wmipcima.dll - ok
18:50:45.0937 0404 [ 7E5B34D9610D311EE95A49DE3F2F1E3A ] C:\Program Files\AVAST Software\Avast\defs\13062500\uiext.dll
18:50:45.0937 0404 C:\Program Files\AVAST Software\Avast\defs\13062500\uiext.dll - ok
18:50:45.0937 0404 [ E11457C66FDD966EE415FBBC6D9BE643 ] C:\WINDOWS\system32\msimtf.dll
18:50:45.0937 0404 C:\WINDOWS\system32\msimtf.dll - ok
18:50:45.0937 0404 [ A7F361875622AA5829AA39BA248F68E9 ] C:\WINDOWS\system32\adsldp.dll
18:50:45.0937 0404 C:\WINDOWS\system32\adsldp.dll - ok
18:50:45.0937 0404 [ BAF751E7061FF626AA60F56D1D5D1FDC ] C:\WINDOWS\system32\MFC71ENU.DLL
18:50:45.0937 0404 C:\WINDOWS\system32\MFC71ENU.DLL - ok
18:50:45.0937 0404 [ 3C84FCA13C4EB607478A45F2D7E16DB3 ] C:\Program Files\Common Files\Roxio Shared\DLLShared\SonicHTTPClient9.dll
18:50:45.0937 0404 C:\Program Files\Common Files\Roxio Shared\DLLShared\SonicHTTPClient9.dll - ok
18:50:45.0937 0404 [ C19F74D59B294488E0A2D8A824C4E89B ] C:\Program Files\Steam\SteamUI.dll
18:50:45.0937 0404 C:\Program Files\Steam\SteamUI.dll - ok
18:50:45.0953 0404 [ B06633C5840EFBE99242F7B90D70C135 ] C:\Program Files\Steam\SDL2.dll
18:50:45.0953 0404 C:\Program Files\Steam\SDL2.dll - ok
18:50:45.0953 0404 [ 4EA92135C436D18975C2EBEC242B71DA ] C:\WINDOWS\system32\icmp.dll
18:50:45.0953 0404 C:\WINDOWS\system32\icmp.dll - ok
18:50:45.0953 0404 [ 173C217E677C4B0C4F8A6D54BA13BF9B ] C:\Program Files\Steam\CSERHelper.dll
18:50:45.0953 0404 C:\Program Files\Steam\CSERHelper.dll - ok
18:50:45.0953 0404 [ D5E1C86C58D6850B8CC45D845A3A5686 ] C:\Program Files\Steam\bin\filesystem_stdio.dll
18:50:45.0953 0404 C:\Program Files\Steam\bin\filesystem_stdio.dll - ok
18:50:45.0953 0404 [ C001720173C169ECD33C4C2958F185A8 ] C:\Program Files\Common Files\Roxio Shared\DLLShared\rcsl.dll
18:50:45.0953 0404 C:\Program Files\Common Files\Roxio Shared\DLLShared\rcsl.dll - ok
18:50:45.0953 0404 [ E4093B24A9530D13191660C2AD78EE64 ] C:\Program Files\Steam\bin\vgui2_s.dll
18:50:45.0953 0404 C:\Program Files\Steam\bin\vgui2_s.dll - ok
18:50:45.0953 0404 [ F5DF4C09808DBD4D84A3871A5A3DB91B ] C:\WINDOWS\system32\opengl32.dll
18:50:45.0953 0404 C:\WINDOWS\system32\opengl32.dll - ok
18:50:45.0968 0404 [ A78516D04DD71A18FDFDF820A6413634 ] C:\WINDOWS\system32\glu32.dll
18:50:45.0968 0404 C:\WINDOWS\system32\glu32.dll - ok
18:50:45.0968 0404 [ 81284914EE1FBF94B1F631C220639960 ] C:\Program Files\Java\jre7\bin\sunec.dll
18:50:45.0968 0404 C:\Program Files\Java\jre7\bin\sunec.dll - ok
18:50:45.0968 0404 [ 87085C67F547CD929D4A04AD3964DA5E ] C:\Program Files\Java\jre7\bin\sunmscapi.dll
18:50:45.0968 0404 C:\Program Files\Java\jre7\bin\sunmscapi.dll - ok
18:50:45.0968 0404 [ C5C8C2BB002BCD580CDF3AA61D9AB6BF ] C:\Program Files\Steam\bin\chromehtml.dll
18:50:45.0968 0404 C:\Program Files\Steam\bin\chromehtml.dll - ok
18:50:45.0968 0404 [ BB87F0D17A6E0C54918F488E1C68A55A ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSFileProtocolHandler.dll
18:50:45.0968 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSFileProtocolHandler.dll - ok
18:50:45.0968 0404 [ 00211A61489B5F43592D0D650038B5A3 ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSSkinProtocolHandler.dll
18:50:45.0968 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSSkinProtocolHandler.dll - ok
18:50:45.0984 0404 [ EF5A686DC00A9C60E3E7C02E1411DE96 ] C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSFormatLoaderPNG.dll
18:50:45.0984 0404 C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSFormatLoaderPNG.dll - ok
18:50:45.0984 0404 [ 327E2663D0EED74150250DAC0B2F0BB7 ] C:\Program Files\Java\jre7\bin\awt.dll
18:50:45.0984 0404 C:\Program Files\Java\jre7\bin\awt.dll - ok
18:50:45.0984 0404 [ 8A4EC001A4CBECD498A5B6EF62660B8D ] C:\Program Files\Java\jre7\bin\dcpr.dll
18:50:45.0984 0404 C:\Program Files\Java\jre7\bin\dcpr.dll - ok
18:50:45.0984 0404 [ B4B9479282BB984ECF4B47A47D73FF85 ] C:\Program Files\Java\jre7\bin\deploy.dll
18:50:45.0984 0404 C:\Program Files\Java\jre7\bin\deploy.dll - ok
18:50:45.0984 0404 [ 9DA621EE05B8F692ABC52B5D8076C3C7 ] C:\Program Files\Steam\bin\libcef.dll
18:50:45.0984 0404 C:\Program Files\Steam\bin\libcef.dll - ok
18:50:45.0984 0404 [ 9E03DC5AB51CFD0190541CE2038D819D ] C:\WINDOWS\system32\usp10.dll
18:50:45.0984 0404 C:\WINDOWS\system32\usp10.dll - ok
18:50:46.0000 0404 [ 91AD3759A90791F97C125DBCF3F6B70A ] C:\Program Files\Java\jre7\bin\fontmanager.dll
18:50:46.0000 0404 C:\Program Files\Java\jre7\bin\fontmanager.dll - ok
18:50:46.0000 0404 [ CDE345C0035DC9CFB6960C542B0C2489 ] C:\Program Files\Java\jre7\bin\javaw.exe
18:50:46.0000 0404 C:\Program Files\Java\jre7\bin\javaw.exe - ok
18:50:46.0000 0404 [ B79B11F61F48BCC06512F32D66BA9907 ] C:\Program Files\Java\jre7\bin\jp2native.dll
18:50:46.0000 0404 C:\Program Files\Java\jre7\bin\jp2native.dll - ok
18:50:46.0000 0404 [ 4F1BB3066C3009CD611B29FAB9F156B8 ] C:\Program Files\Java\jre7\bin\jpeg.dll
18:50:46.0000 0404 C:\Program Files\Java\jre7\bin\jpeg.dll - ok
18:50:46.0000 0404 [ 73EF623D4CD238F297A4A4B0FBAE6147 ] C:\Program Files\Java\jre7\bin\net.dll
18:50:46.0000 0404 C:\Program Files\Java\jre7\bin\net.dll - ok
18:50:46.0000 0404 [ 32BA0D6E18354360224F1F16CC36AD3B ] C:\Program Files\Java\jre7\bin\nio.dll
18:50:46.0000 0404 C:\Program Files\Java\jre7\bin\nio.dll - ok
18:50:46.0015 0404 [ 045D0F4F41CA53D4CB22BDC814A22B64 ] C:\Program Files\Steam\bin\icudt.dll
18:50:46.0015 0404 C:\Program Files\Steam\bin\icudt.dll - ok
18:50:46.0015 0404 [ BBA1FE328CEA501FCCE1E5DF16276439 ] C:\Program Files\Steam\bin\avcodec-53.dll
18:50:46.0015 0404 C:\Program Files\Steam\bin\avcodec-53.dll - ok
18:50:46.0015 0404 [ 2A8B8A15A58EDF3B443083EC29894E54 ] C:\Program Files\Steam\bin\avutil-51.dll
18:50:46.0015 0404 C:\Program Files\Steam\bin\avutil-51.dll - ok
18:50:46.0015 0404 [ C5CCB86CD745746B9908031A54315F90 ] C:\Program Files\Steam\bin\avformat-53.dll
18:50:46.0015 0404 C:\Program Files\Steam\bin\avformat-53.dll - ok
18:50:46.0015 0404 [ 4A0FCFEFD79635E46968B786194B5F55 ] C:\Program Files\Steam\steamclient.dll
18:50:46.0015 0404 C:\Program Files\Steam\steamclient.dll - ok
18:50:46.0015 0404 [ FAACDEBF241027F2469FA0C1769DF13B ] C:\Program Files\Steam\bin\steamservice.dll
18:50:46.0015 0404 C:\Program Files\Steam\bin\steamservice.dll - ok
18:50:46.0015 0404 [ 0689622E6484934EB6E5F4D3A96311F9 ] C:\WINDOWS\system32\jscript.dll
18:50:46.0015 0404 C:\WINDOWS\system32\jscript.dll - ok
18:50:46.0031 0404 [ 75B9DBF78C3A2CE8884822AA54838315 ] C:\WINDOWS\system32\iepeers.dll
18:50:46.0031 0404 C:\WINDOWS\system32\iepeers.dll - ok
18:50:46.0031 0404 ============================================================
18:50:46.0031 0404 Scan finished
18:50:46.0031 0404 ============================================================
18:50:46.0140 2764 Detected object count: 9
18:50:46.0140 2764 Actual detected object count: 9
18:51:32.0234 2764 CCALib8 ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0234 2764 CCALib8 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 giveio ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 giveio ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 RoxMediaDB9 ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 RoxMediaDB9 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 RoxWatch9 ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 RoxWatch9 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 sfsync02 ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 sfsync02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:51:32.0250 2764 stllssvr ( UnsignedFile.Multi.Generic ) - skipped by user
18:51:32.0250 2764 stllssvr ( UnsignedFile.Multi.Generic ) - User select action: Skip
18:54:50.0062 1392 Deinitialize success
  • 0

#12
Ardant

Ardant

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 229 posts
The computer is running ok. Just minor glitches here and there. The problems do not repeat often enough but have me wondering if I have missed something. Occasionally some of my start up programs do not load but the last few reboots seem to have gone without a hitch. Bootup sometimes is extremely slow but hasn't been too bad lately. Like I said no problem that I can pinpoint.



RogueKiller V8.6.1 [Jun 24 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo...13-roguekiller/
Website : http://tigzy.geeksto...roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User : John Richardson [Admin rights]
Mode : Remove -- Date : 06/25/2013 19:08:08
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (localhost:21320) -> NOT REMOVED, USE PROXYFIX
[HJ POL] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Scheduled tasks : 0 ¤¤¤

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [LOADED] ¤¤¤
[Address] IRP[IRP_MJ_INTERNAL_DEVICE_CONTROL] : atapi.sys -> HOOKED ([Address] sfsync02.sys @ 0xBA338D60)

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: ST3320620AS +++++
--- User ---
[MBR] a110db506313c885d4c833e65b82f59b
[BSP] dfe4c0bfa859120fb83a6a1aa43abcee : MBR Code unknown
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 54 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 112455 | Size: 301807 Mo
2 - [XXXXXX] UNKNOWN (0x00) [VISIBLE] Offset (sectors): 618213330 | Size: 3380 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_D_06252013_190808.txt >>
RKreport[0]_S_06252013_190512.txt
  • 0

#13
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello Ardant

I Would like you to do the following.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
  • 0

#14
Ardant

Ardant

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 229 posts
No real problems with running Combofix. Same Warnings about AVG being installed but it isnt.

No problems with the computer over the past couple of days. Guess I will just have to keep watching behaviour and repost if need be.

Here is the ComboFix report as requested.



ComboFix 13-06-22.01 - John Richardson 27/06/2013 19:00:30.7.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2283 [GMT -4:00]
Running from: c:\documents and settings\John Richardson\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
AV: AVG Internet Security 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: avast! Antivirus *Disabled* {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: AVG Internet Security 2012 *Enabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
.
((((((((((((((((((((((((( Files Created from 2013-05-27 to 2013-06-27 )))))))))))))))))))))))))))))))
.
.
2013-06-26 05:40 . 2013-06-26 05:40 60872 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{DED0CF99-AF2A-4BEC-8370-634B7D0C455F}\offreg.dll
2013-06-25 23:26 . 2013-06-18 14:22 263576 ----a-w- c:\program files\Mozilla Firefox\browser\components\browsercomps.dll
2013-06-25 06:04 . 2013-06-12 04:18 7068072 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\{DED0CF99-AF2A-4BEC-8370-634B7D0C455F}\mpengine.dll
2013-06-23 15:32 . 2013-06-23 15:48 -------- d---a-w- c:\program files\Cryptic Studios
2013-06-23 13:11 . 2013-06-23 13:11 -------- d-----w- c:\windows\ERUNT
2013-06-23 13:10 . 2013-06-23 13:11 -------- d-----w- C:\JRT
2013-06-21 23:04 . 2013-06-21 23:04 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2013-06-21 23:00 . 2012-05-14 06:12 103040 ----a-w- c:\windows\system32\drivers\AtihdXP3.sys
2013-06-21 22:59 . 2013-06-21 23:01 -------- d---a-w- c:\program files\ATI Technologies
2013-06-21 22:59 . 2013-06-21 22:59 -------- d---a-w- c:\program files\ATI
2013-06-21 22:58 . 2013-06-21 22:58 -------- d---a-w- C:\AMD
2013-06-21 00:10 . 2013-06-21 00:10 -------- d---a-w- c:\program files\ESET
2013-06-20 03:03 . 2013-06-20 03:03 22064 ----a-w- c:\windows\DCEBoot.exe
2013-06-19 22:49 . 2013-06-19 22:49 144896 ----a-w- c:\windows\system32\javacpl.cpl
2013-06-19 22:49 . 2013-06-19 22:49 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2013-06-19 22:49 . 2013-06-19 22:49 -------- d-----w- c:\program files\Java
2013-06-13 00:36 . 2009-01-25 17:14 15224 ----a-w- c:\windows\system32\sdnclean.exe
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-06-27 19:11 . 2013-03-18 20:50 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2013-06-27 19:11 . 2012-10-16 23:30 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2013-06-27 19:11 . 2012-10-16 23:30 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2013-06-23 14:53 . 2012-04-05 01:15 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-06-23 14:53 . 2011-06-05 22:48 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-06-19 22:49 . 2012-09-22 22:21 867240 ----a-w- c:\windows\system32\npDeployJava1.dll
2013-06-19 22:49 . 2011-10-28 22:44 789416 ----a-w- c:\windows\system32\deployJava1.dll
2013-06-12 04:18 . 2013-01-05 18:08 7068072 ----a-w- c:\documents and settings\All Users\Application Data\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll
2013-05-09 08:59 . 2013-03-18 20:50 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2013-05-09 08:59 . 2012-10-16 23:30 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2013-05-09 08:59 . 2013-05-25 13:38 21576 ----a-w- c:\windows\system32\drivers\aswKbd.sys
2013-05-09 08:59 . 2013-03-18 20:49 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2013-05-09 08:59 . 2012-10-16 23:30 49760 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2013-05-09 08:59 . 2012-10-16 23:30 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2013-05-09 08:58 . 2012-10-16 23:29 41664 ----a-w- c:\windows\avastSS.scr
2013-05-09 08:58 . 2012-10-16 23:29 229648 ----a-w- c:\windows\system32\aswBoot.exe
2013-05-07 22:30 . 2004-08-11 22:00 920064 ----a-w- c:\windows\system32\wininet.dll
2013-05-07 22:30 . 2004-08-11 22:00 43520 ------w- c:\windows\system32\licmgr10.dll
2013-05-07 22:30 . 2004-08-11 22:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
2013-05-07 21:53 . 2004-08-11 22:00 385024 ------w- c:\windows\system32\html.iec
2013-05-03 01:30 . 2004-08-11 22:00 2149888 ----a-w- c:\windows\system32\ntoskrnl.exe
2013-05-03 00:38 . 2004-08-04 03:59 2028544 ----a-w- c:\windows\system32\ntkrnlpa.exe
2013-05-02 06:06 . 2013-01-05 18:08 238872 ------w- c:\windows\system32\MpSigStub.exe
2013-04-20 00:13 . 2013-04-20 00:13 86016 ----a-w- c:\windows\system32\OpenAL32.dll
2013-04-20 00:13 . 2013-04-20 00:13 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2013-04-10 01:31 . 2004-08-11 22:00 1876352 ----a-w- c:\windows\system32\win32k.sys
2013-04-04 18:50 . 2012-06-02 14:54 22856 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-06-02 05:36 . 2012-06-03 17:36 44 ---h--w- c:\program files\d81f0199.tmp
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igndlm.exe"="c:\program files\Download Manager\DLM.exe" [2009-05-14 1103216]
"Akamai NetSession Interface"="c:\documents and settings\John Richardson\Local Settings\Application Data\Akamai\netsession_win.exe" [2013-01-26 4480768]
"FileHippo.com"="c:\program files\FileHippo.com\UpdateChecker.exe" [2012-11-23 307712]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2012-12-29 96056]
"Steam"="c:\program files\Steam\Steam.exe" [2013-06-06 1641896]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-10-15 196608]
"RTHDCPL"="RTHDCPL.EXE" [2008-01-09 16859648]
"avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"SDTray"="c:\program files\Spybot - Search & Destroy 2\SDTray.exe" [2013-05-16 3830224]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-11-16 98304]
.
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk.disabled [2008-11-10 767]
.
c:\documents and settings\John Richardson\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2013-3-21 3560832]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0sdnclean.exe\0aswBoot.exe /A:* /A:C: /A:*STARTUP-SHORT /A:*STARTUP /L:1033 /heur:100 /RA:chest /pup /archives /IA:0 /KBD:2 /dir:C:\Program
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MarbleStation"=c:\netmarbleglobal\MarbleStation\GlbMSLauncher.exe
"AVG PC Tuneup"="c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe" -UseTray
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Dungeon Siege 2\\DungeonSiege2.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2main_amdxp.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwupdate.exe"=
"c:\\Program Files\\Atari\\Neverwinter Nights 2\\nwn2server.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\StarCraft II\\StarCraft II.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\amd driver updater, xp, 32 bit\\Setup.exe"=
"c:\\NetmarbleGlobal\\MarbleStation\\nmgDownloader\\nmgDownload.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\FEAR2\\FEAR2.exe"=
"c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"c:\\Documents and Settings\\John Richardson\\Local Settings\\Application Data\\Akamai\\netsession_win.exe"=
"c:\\Program Files\\Diablo III\\Diablo III.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\king's bounty - the legend\\kb.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\king's bounty - the legend\\save_fixer.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\kings bounty armored princess\\kb.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\kings bounty crossworlds\\kb.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\dungeon siege iii\\Dungeon Siege III.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\Carrier Command Gaea Mission demo\\carrier_demo.exe"=
"c:\\Documents and Settings\\John Richardson\\Local Settings\\Apps\\2.0\\RCMH2E3C.XKX\\N6C0O9YD.PBO\\curs..tion_9e9e83ddf3ed3ead_0005.0001_f88ee66177b243ac\\CurseClient.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\Mafia II\\pc\\mafia2.exe"=
"c:\\Games\\World_of_Tanks\\WorldOfTanks.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\sid meier's civilization v\\Launcher.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Battle.net\\Agent\\Agent.1675\\Agent.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Cryptic Studios\\Star Trek Online\\Live\\GameClient.exe"=
"c:\\Program Files\\File Type Assistant\\TSAssist.exe"=
"c:\\Program Files\\Wing Commander Saga Prologue\\wcsaga.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDTray.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDFSSvc.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdate.exe"=
"c:\\Program Files\\Spybot - Search & Destroy 2\\SDUpdSvc.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Battle.net\\Agent\\Agent.1737\\Agent.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"58199:TCP"= 58199:TCP:Pando Media Booster
"58199:UDP"= 58199:UDP:Pando Media Booster
"59153:TCP"= 59153:TCP:Pando Media Booster
"59153:UDP"= 59153:UDP:Pando Media Booster
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
.
R0 aswRvrt;aswRvrt;c:\windows\system32\drivers\aswRvrt.sys [18/03/2013 4:50 PM 49376]
R0 aswVmm;aswVmm;c:\windows\system32\drivers\aswVmm.sys [18/03/2013 4:50 PM 175176]
R1 aswKbd;aswKbd;c:\windows\system32\drivers\aswKbd.sys [25/05/2013 9:38 AM 21576]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [16/10/2012 7:30 PM 770344]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [16/10/2012 7:30 PM 369584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [16/10/2012 7:30 PM 29816]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [18/03/2013 4:49 PM 66336]
R2 SDUpdateService;Spybot-S&D 2 Updating Service;c:\program files\Spybot - Search & Destroy 2\SDUpdSvc.exe [12/06/2013 8:36 PM 1033688]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 8:19 PM 13592]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [21/06/2013 7:00 PM 103040]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [11/08/2004 6:00 PM 14336]
S2 SDScannerService;Spybot-S&D 2 Scanner Service;c:\program files\Spybot - Search & Destroy 2\SDFSSvc.exe [12/06/2013 8:36 PM 1817560]
S2 SDWSCService;Spybot-S&D 2 Security Center Service;c:\program files\Spybot - Search & Destroy 2\SDWSCSvc.exe [12/06/2013 8:36 PM 171928]
S3 aaudstum;aaudstum;\??\c:\docume~1\JOHNRI~1\LOCALS~1\Temp\aaudstum.sys --> c:\docume~1\JOHNRI~1\LOCALS~1\Temp\aaudstum.sys [?]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
S3 PCDSRVC{E9D79540-57D5953E-06020101}_0;PCDSRVC{E9D79540-57D5953E-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\Dell Support Center\pcdsrvc.pkms [04/09/2012 1:54 AM 22640]
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - TRUESIGHT
*Deregistered* - TrueSight
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2013-06-27 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 14:53]
.
2013-06-27 c:\windows\Tasks\avast! Emergency Update.job
- c:\program files\AVAST Software\Avast\AvastEmUpdate.exe [2012-10-16 08:58]
.
2013-06-25 c:\windows\Tasks\Check for updates (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDUpdate.exe [2013-06-13 14:58]
.
2013-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-16 23:30]
.
2013-06-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-10-16 23:30]
.
2013-06-27 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 00:20]
.
2013-06-11 c:\windows\Tasks\PCDoctorBackgroundMonitorTask.job
- c:\program files\Dell Support Center\uaclauncher.exe [2012-09-19 03:48]
.
2013-06-27 c:\windows\Tasks\ProgramRefresh-ATFST.job
- c:\program files\File Type Assistant\TSASetup.exe [2013-01-08 00:48]
.
2013-06-27 c:\windows\Tasks\ProgramUpdateCheck.job
- c:\program files\File Type Assistant\tsassist.exe [2011-03-27 17:09]
.
2013-06-26 c:\windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDImmunize.exe [2013-06-13 14:57]
.
2013-06-13 c:\windows\Tasks\Scan the system (Spybot - Search & Destroy).job
- c:\program files\Spybot - Search & Destroy 2\SDScan.exe [2013-06-13 14:58]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>
uInternet Settings,ProxyServer = localhost:21320
uSearchAssistant = hxxp://www.google.com
uSearchURL,(Default) = hxxp://ca.search.yahoo.com/search?fr=mcafee&p=%s
IE: Customize Menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Fill Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
IE: Save Forms - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Show avast! EasyPass Toolbar - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: microsoft.com\windowsupdate
Trusted Zone: soe.com
Trusted Zone: sony.com
Trusted Zone: worldoftanks.com
TCP: DhcpNameServer = 64.71.255.204 64.71.255.198
Handler: intu-qt2007 - {026BF40D-BA05-467b-9F1F-AD0D7A3F5F11} - c:\program files\QuickTax 2007\ic2007pp.dll
FF - ProfilePath - c:\documents and settings\John Richardson\Application Data\Mozilla\Firefox\Profiles\zy5758f9.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
SafeBoot-92645568.sys
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2013-06-27 19:08
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\Akamai]
"ServiceDll"="c:\program files\common files\akamai/netsession_win_80c2ffa.dll"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
.
[HKEY_LOCAL_MACHINE\System\ControlSet004\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-879840139-2802958703-907680667-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:64,5f,aa,30,64,48,a5,e2,9f,c3,01,ee,47,f7,9e,7e,11,7d,de,3f,53,e3,61,
65,b7,0a,a4,67,96,3d,f0,d2,33,47,2f,b8,2d,b6,f7,26,49,ca,63,67,c0,74,0f,5b,\
"??"=hex:af,4b,db,31,8c,18,8b,1f,0f,e7,56,55,e3,4a,d7,19
.
[HKEY_USERS\S-1-5-21-879840139-2802958703-907680667-1005\Software\SecuROM\License information*]
"datasecu"=hex:79,3e,8d,fc,be,fb,61,b0,6d,87,b2,94,0d,99,ea,c1,09,89,90,16,35,
eb,c5,40,6c,5e,13,b8,a8,26,42,9a,f9,df,36,c4,46,b3,69,ce,a3,60,e4,b5,48,4f,\
"rkeysecu"=hex:a3,57,c4,0d,f8,95,92,51,5f,05,99,76,7c,43,56,19
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil32_11_7_700_224_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
.
- - - - - - - > 'explorer.exe'(4592)
c:\windows\system32\WININET.dll
c:\program files\Xfire\xfire_toucan_46139.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2013-06-27 19:11:18
ComboFix-quarantined-files.txt 2013-06-27 23:11
ComboFix2.txt 2013-06-23 13:50
.
Pre-Run: 72,562,327,552 bytes free
Post-Run: 72,533,061,632 bytes free
.
- - End Of File - - CB97C8FFDA5DF892D8EFDA1F4500EC7F
5CB90281D1A59B251F6603134774EEC3
  • 0

#15
gringo_pr

gringo_pr

    Trusted Helper

  • Malware Removal
  • 7,268 posts
Hello Ardant

At this time I would like you to run this script for me and it is a good time to check out the computer to see if there is anything else that needs to be addressed.

:Run CFScript:

Please start by opening Notepad and copy/paste the text in the box into the window:

ClearJavaCache::

Driver::
aaudstum

SecCenter::
AV: AVG Internet Security 2012 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: AVG Internet Security 2012 *Enabled* {17DDD097-36FF-435F-9E1B-52D74245D6BF}


Save it to your desktop as CFScript.txt

Referring to the picture above, drag CFScript.txt into ComboFix.exe
Posted Image
This will let ComboFix run again.
Restart if you have to.
Save the produced logfile to your desktop.

Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall

Note 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following

  • report from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now after running the script?

Gringo

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP