Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

AVG not running, unable to reinstall


  • Please log in to reply

#1
klmk

klmk

    Member

  • Member
  • PipPip
  • 25 posts
I noticed all of a sudden that AVG was not running, though it should be. Attempts to install and scan with MBAM are met with run-time error 372 for vbalsgrid6.ocx. I managed eventually to remove AVG with their own uninstall tool, but reinstallation is met with an error describing that 'This package could not be opened' and that it is not a valid Microsoft Installer package. I've tried re-downloading to no avail. I tried running ComboFix a couple of times, knowning that I shouldn't have started there without having been advised to run it. It came up with some files that it removed but the problem persists. Below is pasted the log for OTL. Please help, and thank you.

--

OTL logfile created on: 21.7.2013 18:07:09 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D:\
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = )
Locale: 0000040b | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,51 Gb Available Physical Memory | 62,87% Memory free
8,00 Gb Paging File | 6,28 Gb Available in Paging File | 78,58% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 151,46 Gb Total Space | 13,56 Gb Free Space | 8,95% Space Free | Partition Type: NTFS
Drive D: | 322,26 Gb Total Space | 14,07 Gb Free Space | 4,37% Space Free | Partition Type: NTFS
Drive E: | 122,44 Gb Total Space | 4,31 Gb Free Space | 3,52% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 12,90 Gb Free Space | 2,77% Space Free | Partition Type: NTFS
Drive G: | 301,36 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

Computer Name: PC-GHOST | User Name: Ghost | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --
PRC - [2013.07.01 20:58:21 | 001,598,128 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
PRC - [2013.06.15 14:13:35 | 001,104,384 | ---- | M] (Spotify Ltd) -- D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013.05.10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.04.04 14:50:32 | 000,887,432 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013.04.04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.10.05 23:57:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\OTL.exe
PRC - [2012.02.21 20:39:30 | 002,043,904 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe
PRC - [2011.03.07 15:42:42 | 000,969,216 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
PRC - [2010.04.16 17:10:58 | 000,036,864 | ---- | M] (Realtek) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
PRC - [2009.07.24 19:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2008.07.22 12:18:44 | 000,163,840 | ---- | M] () -- D:\Ohjelmat\Desktop Media\mediadetect.exe
PRC - [2005.09.30 19:22:50 | 000,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files (x86)\Canon\CAL\CALMAIN.exe


========== Modules (No Company Name) ==========

MOD - [2011.03.07 15:21:06 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
MOD - [2011.03.07 15:21:02 | 000,433,664 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
MOD - [2008.07.22 12:18:44 | 000,163,840 | ---- | M] () -- D:\Ohjelmat\Desktop Media\mediadetect.exe


========== Services (SafeList) ==========

SRV:64bit: - [2013.06.04 14:44:06 | 000,182,848 | ---- | M] (Soluto) [Auto | Running] -- C:\Program Files\Soluto\SolutoLauncherService.exe -- (SolutoLauncherService)
SRV:64bit: - [2013.06.04 14:44:04 | 000,746,048 | ---- | M] (Soluto) [Auto | Running] -- C:\Program Files\Soluto\SolutoService.exe -- (SolutoService)
SRV:64bit: - [2013.06.04 14:40:24 | 001,671,680 | ---- | M] (GlavSoft LLC.) [On_Demand | Stopped] -- C:\Program Files\Soluto\SolutoRemoteService.exe -- (SolutoRemoteService)
SRV:64bit: - [2013.05.27 08:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV:64bit: - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV:64bit: - [2012.04.06 05:16:02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.06.06 15:25:32 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010.05.06 12:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009.10.07 01:47:10 | 000,191,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:64bit: - [2009.09.23 14:34:04 | 000,073,728 | ---- | M] (Tablet Driver) [Auto | Running] -- C:\Windows\SysNative\drivers\WTSrv.exe -- (WinTabService)
SRV:64bit: - [2009.07.14 04:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.07.01 20:58:21 | 001,598,128 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe -- (vToolbarUpdater15.3.0)
SRV - [2013.05.15 00:49:36 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.04.19 15:14:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.02.14 04:14:02 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.12.19 10:49:34 | 000,732,648 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012.01.18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011.03.28 15:41:12 | 002,111,368 | ---- | M] (LogMeIn Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2010.11.29 20:31:21 | 000,075,136 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.10.09 04:57:25 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)
SRV - [2010.06.06 15:23:59 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.04.16 17:10:58 | 000,036,864 | ---- | M] (Realtek) [Auto | Running] -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.07.24 19:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009.06.11 00:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.08.15 05:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
SRV - [2005.09.30 19:22:50 | 000,096,341 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files (x86)\Canon\CAL\CALMAIN.exe -- (CCALib8)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2013.07.01 20:58:21 | 000,045,856 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013.06.04 14:40:06 | 000,054,728 | ---- | M] (Soluto LTD.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Soluto.sys -- (Soluto)
DRV:64bit: - [2013.04.04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.11.09 16:33:30 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2012.11.09 16:33:30 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2012.11.09 16:33:30 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2012.11.09 16:33:30 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2012.10.17 14:53:46 | 000,026,112 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2012.08.23 17:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 17:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.05.14 09:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.04.06 08:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.04.06 08:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.04.06 04:10:44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.03.01 09:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.18 06:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2012.01.18 06:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2011.08.11 14:46:46 | 000,694,376 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su)
DRV:64bit: - [2011.06.10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.05.10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.03.11 09:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 09:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.23 15:48:46 | 000,818,424 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.11.20 16:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010.11.09 16:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2010.04.27 16:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2010.04.27 16:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2010.04.27 14:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2010.04.27 14:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2010.03.30 23:27:42 | 000,015,360 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Spyder3.sys -- (Spyder3)
DRV:64bit: - [2010.03.18 12:00:40 | 000,041,040 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2010.03.18 12:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010.03.18 12:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2010.03.09 13:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.12.18 01:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2009.10.07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2009.10.07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009.08.10 00:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2009.07.14 04:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 04:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 04:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 03:09:02 | 000,120,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\irda.sys -- (irda)
DRV:64bit: - [2009.06.18 11:42:34 | 000,022,696 | ---- | M] (Tablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCTblHid.sys -- (UCTblHid)
DRV:64bit: - [2009.06.18 11:42:16 | 000,027,304 | ---- | M] (Tablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TClass2k.sys -- (TClass2k)
DRV:64bit: - [2009.06.18 11:41:58 | 000,017,064 | ---- | M] (PenTablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PTSimHid.sys -- (PTSimHid)
DRV:64bit: - [2009.06.18 11:41:46 | 000,027,304 | ---- | M] (PenTablet Driver) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PTSimBus.sys -- (PTSimBus)
DRV:64bit: - [2009.06.10 23:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 23:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 23:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 23:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2008.01.19 06:36:12 | 000,027,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\irsir.sys -- (irsir)
DRV - [2009.07.14 04:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fi
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2A 21 4A 5A D4 00 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files (x86)\Download_Energy\prxtbDown.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...fr&d=2012-07-24 12:44:52&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.condui...&ctid=CT1269415
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Download Energy Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "DuckDuckGo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10
FF - prefs.js..extensions.enabledAddons: %7BE173B749-DB5B-4fd2-BA0E-94ECEA0CA55B%7D:7.4
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.16
FF - prefs.js..extensions.enabledAddons: webdavlauncher%40benryan.com:1.0.7
FF - prefs.js..extensions.enabledAddons: %7B888d99e7-e8b5-46a3-851e-1ec45da1e644%7D:17.0.0
FF - prefs.js..extensions.enabledAddons: crossriderapp14917%40crossrider.com:0.91.62
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.9.6
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.011.025.001
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.1
FF - prefs.js..extensions.enabledItems: {d650973c-0444-4ac7-9d00-19e3613c83b9}:3.6.7
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.5
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Ghost\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.17 08:38:41 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.06.25 20:08:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2011.03.11 18:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Extensions
[2011.03.11 18:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.07.11 20:24:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions
[2010.05.31 20:41:37 | 000,000,000 | ---D | M] (Whitehart) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{d650973c-0444-4ac7-9d00-19e3613c83b9}
[2011.11.28 10:56:07 | 000,000,000 | ---D | M] (Memory Fox) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
[2010.12.27 01:16:42 | 000,000,000 | ---D | M] (Chromifox Basic) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.06.25 21:45:11 | 000,000,000 | ---D | M] ("Chat Undetected") -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.07.11 20:24:52 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2012.12.20 18:23:30 | 000,000,000 | ---D | M] (Foxdie) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2012.12.21 13:15:10 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.04.16 20:36:13 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.04.30 21:44:45 | 000,000,000 | ---D | M] (rein) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.06.25 21:45:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]\chrome\content\extensionCode
[2012.09.06 09:25:29 | 000,240,755 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.05.01 16:10:58 | 000,014,909 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.05.27 11:25:07 | 000,534,431 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
[2013.04.17 20:36:12 | 000,282,569 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2013.06.03 13:23:46 | 000,030,502 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
[2013.05.09 21:04:45 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.10.30 11:38:54 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2013.04.05 11:57:36 | 000,714,654 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013.07.18 20:41:00 | 000,002,684 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\ann-encyclopedia.xml
[2013.07.17 22:48:03 | 000,010,316 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\duckduckgo.xml
[2013.07.18 20:41:00 | 000,004,873 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\isohunt--bt-search.xml
[2010.06.01 21:15:20 | 000,001,011 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\torrentz-search.xml
[2012.07.25 18:37:47 | 000,000,705 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\webster.xml
[2013.05.15 00:49:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.05.15 00:49:38 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011.10.26 21:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2013.02.20 22:08:13 | 000,003,714 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml

========== Chrome ==========


O1 HOSTS File: ([2013.07.18 22:44:17 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Soluto] c:\program files\soluto\soluto.exe (Soluto)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Spotify Web Helper] D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Ghost\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - ftp Prefix: missing
O13 - gopher Prefix: missing
O13 - home Prefix: missing
O13 - mosaic Prefix: missing
O13 - www Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.241.198.245 62.241.198.246
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F28F71D-B0F7-4600-8842-2F30750E759B}: DhcpNameServer = 62.241.198.245 62.241.198.246
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Value error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll (AVG Secure Search)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.08.18 05:02:26 | 000,000,069 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013.07.21 17:57:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.07.19 00:08:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.07.18 23:51:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.07.18 23:51:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.07.18 23:41:18 | 000,000,000 | --SD | C] -- C:\ComboFix
[2013.07.18 23:39:43 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.07.18 23:39:42 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.07.18 23:39:42 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.07.18 23:24:33 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\MFAData
[2013.07.18 23:24:33 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\Avg2013
[2013.07.18 23:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2013.07.18 23:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2013.07.18 23:01:41 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Spybot - Search & Destroy
[2013.07.18 23:00:39 | 036,364,784 | ---- | C] (Safer-Networking Ltd. ) -- C:\Users\Ghost\Desktop\spybotsd-2.1.20-SR1.exe
[2013.07.18 22:29:31 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.07.18 20:45:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2013.07.18 20:41:55 | 000,000,000 | ---D | C] -- C:\Users\Ghost\Desktop\SUPERSetup
[2013.07.18 20:41:23 | 026,611,408 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
[2013.07.18 20:30:58 | 000,000,000 | ---D | C] -- C:\Malwarebytes
[2013.07.18 20:30:11 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Ghost\Desktop\mbam-setup-1.75.0.1300.exe
[2013.07.18 19:21:40 | 000,000,000 | ---D | C] -- C:\Application Data
[2013.07.06 14:20:39 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\Opera Software
[2013.07.06 14:20:37 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Opera Software
[2013.06.25 20:08:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.06.25 01:25:19 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\TuneUp Software
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013.07.21 18:04:07 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.21 18:04:07 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.21 17:57:16 | 000,000,250 | ---- | M] () -- C:\Users\Ghost\Desktop\UBCD503 (G).lnk
[2013.07.21 17:57:08 | 000,000,224 | ---- | M] () -- C:\Windows\tasks\AutoRearm.job
[2013.07.21 17:56:28 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.21 17:56:23 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
[2013.07.21 17:56:08 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.21 17:55:54 | 3220,824,064 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.19 00:35:20 | 000,222,290 | ---- | M] () -- C:\Users\Ghost\Desktop\AVGInstLog.cab
[2013.07.18 23:39:43 | 000,000,914 | ---- | M] () -- C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.18 23:27:52 | 000,001,137 | ---- | M] () -- C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
[2013.07.18 23:12:01 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.18 22:44:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.07.18 21:37:05 | 000,064,178 | ---- | M] () -- C:\Users\Ghost\Documents\cc_20130718_213659.reg
[2013.07.18 20:21:11 | 026,611,408 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
[2013.07.17 23:00:12 | 101,083,484 | ---- | M] () -- C:\Users\Ghost\Desktop\DHBTPO.rar
[2013.07.17 22:42:20 | 048,537,823 | ---- | M] () -- C:\Users\Ghost\Desktop\LJD.rar
[2013.07.17 22:31:53 | 067,966,879 | ---- | M] () -- C:\Users\Ghost\Desktop\NTBD.rar
[2013.07.17 21:59:03 | 002,297,856 | ---- | M] () -- C:\Users\Ghost\Desktop\Baby_shower.indd
[2013.07.17 20:40:27 | 000,001,165 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.07.16 10:00:58 | 005,199,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.07.12 02:11:07 | 001,367,650 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.07.12 02:11:07 | 000,652,166 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.12 02:11:07 | 000,479,386 | ---- | M] () -- C:\Windows\SysNative\perfh00B.dat
[2013.07.12 02:11:07 | 000,121,098 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.07.12 02:11:07 | 000,100,162 | ---- | M] () -- C:\Windows\SysNative\perfc00B.dat
[2013.07.01 20:58:48 | 000,003,716 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.07.01 20:58:21 | 000,045,856 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013.06.30 19:39:52 | 000,002,070 | ---- | M] () -- C:\Users\Ghost\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2013.06.25 00:58:24 | 000,173,429 | ---- | M] () -- C:\Users\Ghost\Desktop\Threadless_130624.pdf
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.07.21 18:06:00 | 000,602,112 | ---- | C] () -- \OTL.exe
[2013.07.19 00:35:20 | 000,222,290 | ---- | C] () -- C:\Users\Ghost\Desktop\AVGInstLog.cab
[2013.07.18 23:39:43 | 000,000,914 | ---- | C] () -- C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.18 23:38:58 | 000,000,250 | ---- | C] () -- C:\Users\Ghost\Desktop\UBCD503 (G).lnk
[2013.07.18 23:33:25 | 001,064,736 | ---- | C] () -- \VB6.0-KB290887-X86.exe
[2013.07.18 23:27:52 | 000,001,137 | ---- | C] () -- C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
[2013.07.18 21:43:14 | 004,463,512 | ---- | C] () -- \start.exe
[2013.07.18 21:41:40 | 001,565,744 | ---- | C] () -- \AVG_Remover_en.exe
[2013.07.18 21:37:03 | 000,064,178 | ---- | C] () -- C:\Users\Ghost\Documents\cc_20130718_213659.reg
[2013.07.17 22:28:17 | 067,966,879 | ---- | C] () -- C:\Users\Ghost\Desktop\NTBD.rar
[2013.07.17 22:27:03 | 101,083,484 | ---- | C] () -- C:\Users\Ghost\Desktop\DHBTPO.rar
[2013.07.17 22:25:43 | 048,537,823 | ---- | C] () -- C:\Users\Ghost\Desktop\LJD.rar
[2013.07.17 21:58:58 | 002,297,856 | ---- | C] () -- C:\Users\Ghost\Desktop\Baby_shower.indd
[2013.07.17 20:40:27 | 000,001,165 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.06.25 00:58:24 | 000,173,429 | ---- | C] () -- C:\Users\Ghost\Desktop\Threadless_130624.pdf
[2013.05.21 13:54:43 | 000,003,716 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.02.15 17:20:04 | 001,325,198 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.02.15 12:56:11 | 000,000,132 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.07.21 09:40:05 | 000,001,456 | ---- | C] () -- C:\Users\Ghost\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.06.24 21:29:42 | 000,925,184 | ---- | C] () -- C:\Windows\expstart.exe
[2012.03.09 07:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.03.09 07:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.02.28 18:28:04 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.01.18 06:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.11.23 22:03:49 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011.11.23 21:58:43 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2011.11.02 08:50:27 | 000,001,556 | ---- | C] () -- C:\Users\Ghost\.davmail.properties
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011.09.13 01:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.09.06 19:55:55 | 000,335,872 | ---- | C] () -- C:\Windows\SetupX32.EXE
[2011.05.30 20:17:54 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2011.05.17 20:03:05 | 000,114,688 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\fontdb.mdb
[2011.03.23 00:02:15 | 000,000,266 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\rftg
[2011.03.21 01:20:29 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.10.19 19:47:31 | 000,005,642 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010.09.09 23:55:23 | 000,007,603 | ---- | C] () -- C:\Users\Ghost\AppData\Local\Resmon.ResmonCfg
[2010.06.11 17:16:52 | 000,000,000 | ---- | C] () -- C:\Users\Ghost\AppData\Local\prvlcl.dat
[2010.06.06 14:44:52 | 000,011,496 | ---- | C] () -- \Setup.xml
[2010.05.10 22:45:26 | 000,014,854 | ---- | C] () -- \Tallenne.amr
[2010.05.10 22:45:26 | 000,008,070 | ---- | C] () -- \Sound clip 01.amr

========== ZeroAccess Check ==========

[2009.07.14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 08:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 07:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 15:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2011.03.30 22:42:36 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Axialis
[2011.05.17 21:05:47 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\BorWare
[2012.07.17 22:36:48 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Braid
[2010.12.23 15:23:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Canneverbe Limited
[2010.06.06 12:13:25 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Canon
[2012.05.22 09:05:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013.05.29 12:00:33 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\com.destroytoday.destroytwitter
[2010.08.02 22:30:58 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Command and Conquer 4
[2010.08.16 21:26:02 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Crayon Physics Deluxe
[2011.05.30 21:11:42 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\dBpoweramp
[2013.07.17 20:25:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Dropbox
[2011.02.14 20:25:57 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\FontExplorerX
[2011.09.12 10:07:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\foobar2000
[2012.03.05 19:45:25 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\FuzzyClock
[2011.07.12 10:34:32 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\HandBrake
[2011.02.08 13:04:56 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\IcoFX
[2011.01.11 23:51:38 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\ifolor
[2010.08.20 07:45:44 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\ImgBurn
[2011.02.09 08:01:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\iPodder
[2010.09.07 16:09:40 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\KC Softwares
[2010.08.14 13:10:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Leadertech
[2013.07.17 23:19:42 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Mp3tag
[2012.03.09 09:37:00 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\NexusFont
[2012.06.24 22:00:18 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Nokia
[2010.11.14 22:26:45 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Nokia Ovi Suite
[2011.04.03 17:32:52 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Notepad++
[2010.06.30 22:16:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\OpenOffice.org
[2010.08.02 19:05:56 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Opera
[2013.07.06 14:20:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Opera Software
[2013.06.04 19:46:58 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Origin
[2012.09.07 18:00:54 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\PC Suite
[2010.06.07 21:28:43 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Simple Sudoku
[2011.03.29 21:43:26 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Soluto
[2013.07.11 23:00:18 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Spotify
[2012.03.01 01:48:50 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.04.09 21:30:25 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\StreamTorrent
[2011.09.12 10:23:01 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\streamWriter
[2011.03.11 18:55:04 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Thunderbird
[2013.06.25 01:25:19 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\TuneUp Software
[2011.02.24 20:57:52 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Unity
[2013.07.18 21:34:59 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\uTorrent
[2011.03.06 16:39:32 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\wargaming.net
[2013.02.02 15:52:14 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Waterfox Limited

========== Purity Check ==========



========== Files - Unicode (All) ==========
[2011.12.18 13:48:12 | 000,004,314 | ---- | M] ()(C:\Users\Ghost\Documents\H??kuvat.mds) -- C:\Users\Ghost\Documents\H¦¦kuvat.mds
[2011.12.18 13:48:12 | 000,004,314 | ---- | C] ()(C:\Users\Ghost\Documents\H??kuvat.mds) -- C:\Users\Ghost\Documents\H¦¦kuvat.mds
[2011.12.18 13:48:11 | 2439,053,312 | ---- | M] ()(C:\Users\Ghost\Documents\H??kuvat.iso) -- C:\Users\Ghost\Documents\H¦¦kuvat.iso
[2011.12.18 13:45:00 | 2439,053,312 | ---- | C] ()(C:\Users\Ghost\Documents\H??kuvat.iso) -- C:\Users\Ghost\Documents\H¦¦kuvat.iso

< End of report >
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Download aswMBR.exe to your desktop.
Right click aswMBR.exe and Run as Administrator
uncheck trace disk IO calls
Change the A-V Scan from Quickscan to C:\
Click the "Scan" button to start scan (Accept the Avast Engine)
On completion of the scan if the Fix button is enabled (not the FixMBR button) press it and then run a new scan and click save log, save it to your desktop and post in your next reply
If the Fix button is not enabled then just click save log, save it to your desktop and post in your next reply

ComboFix

Since you have already run Combofix just post your last log.

C:\Combofix.txt or c:\combofix\combofix.txt.


Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then run it by right clicking and Run As Admin.


If TDSSKiller alerts you that the system needs to reboot, please consent.

Run TDSSKiller again but this time:
before you hit the Scan hit Change Parameters and check the two items under Additional Options. OK then Scan.
In this mode it is prone to false positives so do not change the SKIP option to DELETE unless it says TDSS.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.



Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:
http://www.malwareby...lwarebytes_free

SAVE Malwarebytes' Anti-Malware to your desktop.

* Right-click mbam-setup.exe and select Run As Administrator to start the program.
* follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.


Download the adwCleaner

  • Run the Tool
    Windows Vista and Windows 7 users:
    Right click in the adwCleaner.exe and select the option
    Posted Image
  • Select the Delete button.
  • When the scan completes, it will open a notepad windows.
  • Please, copy the content of this file in your next reply.

Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).

sfc  /scannow



(Does this complain that it could not fix all of your files?)


Right click on (My) Computer and select Manage (Continue) Then click on the arrow in front of Event Viewer. Next Click on the arrow in front of Windows Logs Right click on System and Clear Log, Clear. Repeat for Application.

Download ESET's Service Repair http://kb.eset.com/l...vicesRepair.exe and Save it then right click on it and Run As Admin.

If it doesn't do it for you:

Reboot.

1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application. VEW will overwrite the log at C:\vew.txt each time it runs so either post your System results before running VEW for Applications or copy the file c:\vew.txt to a new location.


Copy the text in the code box:

DRIVES
nnetsvcs
%SYSTEMDRIVE%\*.exe
%systemroot%\assembly\GAC_32\*.ini
%systemroot%\assembly\GAC_64\*.ini
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.exe
%APPDATA%\*.
/md5start
pnrpnsp.dll 
nwprovau.dll
nlaapi.dll
napinsp.dll
mswsock.dll
winrnr.dll
wshelper.dll
services.exe
atapi.sys
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
csrss.exe
PrintIsolationHost.exe
consrv.dll
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemdrive%\$Recycle.Bin|@;true;true;true /fp
%systemroot%\system32\drivers\*.sys /lockedfiles
CREATERESTOREPOINT

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

Select the All option in the Extra Registry group then Run Scan.

You should get two logs. Please copy and paste both of them.



Download, Save and Run (win 7 or Vista => Right click and Run as Admin.) farbar service scanner

Posted Image

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

Ron
  • 0

#3
klmk

klmk

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Hi

Thanks for your reply. I was able to run most of what you suggested. aswMBR came up with Fix disabled. TDSSKiller didn't show TDSS or suggest reboot. MBAM uninstall from Add/Remove claims software already uninstalled, suggests removing from list. Used CCleaner to uninstall instead. Re-installation from fresh d/l completes but unable to run due to same vbalsgrid6 error as before. During the whole process of running these scans, MBAM shows up in systray, but I'm unable to open the program due to the same error. The adwCleaner tip lacked a screenshot I think (shows only the text Posted Image), and so I didn't know what option you wanted me to select. SFC from prompt failed as some corrupt files were found that it wasn't able to fix. Running Event Viewer Tool failed with an "Invalid Picture" error. The logs from the completed scans are pasted below. Thank you for your help.


aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-07-22 09:44:47
-----------------------------
09:44:47.187 OS Version: Windows x64 6.1.7601 Service Pack 1
09:44:47.187 Number of processors: 4 586 0x402
09:44:47.187 ComputerName: PC-GHOST UserName: Ghost
09:44:47.483 Initialize success
09:53:53.502 AVAST engine defs: 13072101
09:54:36.714 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
09:54:36.714 Disk 0 Vendor: WDC_WD6400AAKS-22A7B2 01.03B01 Size: 610480MB BusType: 3
09:54:36.714 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T1L0-3
09:54:36.714 Disk 1 Vendor: ST3500418AS CC34 Size: 476940MB BusType: 3
09:54:36.808 Disk 0 MBR read successfully
09:54:36.808 Disk 0 MBR scan
09:54:36.808 Disk 0 Windows 7 default MBR code
09:54:36.824 Disk 0 Partition 1 00 07 HPFS/NTFS NTFS 329999 MB offset 2048
09:54:36.839 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 155097 MB offset 675842048
09:54:36.855 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 125379 MB offset 993482752
09:54:36.886 Disk 0 scanning C:\Windows\system32\drivers
09:54:46.854 Service scanning
09:55:02.049 Service Tablet2k C:\Windows\"%SystemRoot%\System32\Drivers\Tablet2k.sys" **LOCKED** 123
09:55:06.651 Modules scanning
09:55:07.150 AVAST engine scan C:\
11:54:39.857 Scan finished successfully
11:55:17.219 Disk 0 MBR has been saved successfully to "C:\Users\Ghost\Desktop\MBR.dat"
11:55:17.219 The log file has been saved successfully to "C:\Users\Ghost\Desktop\aswMBR.txt"


ComboFix 13-07-18.04 - Ghost 18.07.2013 23:52:53.2.4 - x64
Microsoft Windows 7 Ultimate 6.1.7601.1.1252.358.1033.18.4095.2744 [GMT 3:00]
Sijainti: c:\users\Ghost\Desktop\ComboFix.exe
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((( Muut poistot ))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Ghost\Desktop\Setup.exe
D:\explorer.exe
.
.
((((( Tiedostot, jotka on luotu seuraavalla aikavälillä: 2013-06-18 to 2013-07-18 )))))))))))))))))
.
.
2013-07-18 21:00 . 2013-07-18 21:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2013-07-18 20:39 . 2013-07-18 20:43 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2013-07-18 20:39 . 2013-04-04 11:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2013-07-18 20:24 . 2013-07-18 20:24 -------- d-----w- c:\users\Ghost\AppData\Local\MFAData
2013-07-18 20:24 . 2013-07-18 20:24 -------- d-----w- c:\users\Ghost\AppData\Local\Avg2013
2013-07-18 20:03 . 2013-07-18 20:03 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2013-07-18 20:03 . 2013-07-18 20:03 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2013-07-18 20:01 . 2013-07-18 20:17 -------- d-----w- c:\users\Ghost\AppData\Roaming\Spybot - Search & Destroy
2013-07-18 17:45 . 2013-07-18 17:47 -------- d-----w- c:\windows\system32\MRT
2013-07-18 17:30 . 2013-07-18 17:30 -------- d-----w- C:\Malwarebytes
2013-07-18 17:06 . 2013-07-15 00:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0AE0C581-3E51-4550-AC70-A59414EB07D1}\mpengine.dll
2013-07-18 16:21 . 2013-07-18 16:21 -------- d-----w- C:\Application Data
2013-07-11 17:44 . 2013-05-27 05:50 1011712 ----a-w- c:\program files\Windows Defender\MpSvc.dll
2013-07-11 17:44 . 2013-05-27 05:50 571904 ----a-w- c:\program files\Windows Defender\MpClient.dll
2013-07-11 17:44 . 2013-05-27 05:50 314880 ----a-w- c:\program files\Windows Defender\MpCommu.dll
2013-07-11 17:44 . 2013-05-27 04:57 54784 ----a-w- c:\program files (x86)\Windows Defender\MpOAV.dll
2013-07-11 17:44 . 2013-05-27 04:57 392704 ----a-w- c:\program files (x86)\Windows Defender\MpClient.dll
2013-07-11 17:44 . 2013-05-27 03:15 9216 ----a-w- c:\program files (x86)\Windows Defender\MpAsDesc.dll
2013-07-11 17:44 . 2013-05-27 04:57 4608 ----a-w- c:\program files (x86)\Windows Defender\MsMpLics.dll
2013-07-11 17:43 . 2013-06-04 06:00 624128 ----a-w- c:\windows\system32\qedit.dll
2013-07-11 17:43 . 2013-06-04 04:53 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2013-07-11 17:43 . 2013-05-06 06:03 1887744 ----a-w- c:\windows\system32\WMVDECOD.DLL
2013-07-11 17:43 . 2013-05-06 04:56 1620480 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL
2013-07-11 17:39 . 2013-06-05 03:34 3153920 ----a-w- c:\windows\system32\win32k.sys
2013-07-11 17:39 . 2013-04-10 05:48 1732608 ----a-w- c:\program files\Windows Journal\NBDoc.DLL
2013-07-11 17:39 . 2013-04-10 05:46 1393152 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll
2013-07-11 17:39 . 2013-04-10 05:46 1367040 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 17:39 . 2013-04-10 05:46 1402880 ----a-w- c:\program files\Windows Journal\JNWDRV.dll
2013-07-11 17:39 . 2013-04-10 05:03 936448 ----a-w- c:\program files (x86)\Common Files\Microsoft Shared\ink\journal.dll
2013-07-11 17:35 . 2013-04-02 22:51 1643520 ----a-w- c:\windows\system32\DWrite.dll
2013-07-11 17:35 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\SysWow64\DWrite.dll
2013-07-06 11:20 . 2013-07-06 11:20 -------- d-----w- c:\users\Ghost\AppData\Local\Opera Software
2013-07-06 11:20 . 2013-07-06 11:20 -------- d-----w- c:\users\Ghost\AppData\Roaming\Opera Software
2013-06-25 17:08 . 2013-06-30 16:39 -------- d-----w- c:\program files (x86)\Mozilla Thunderbird
2013-06-24 22:25 . 2013-06-24 22:25 -------- d-----w- c:\users\Ghost\AppData\Roaming\TuneUp Software
2013-06-20 15:31 . 2013-06-12 18:47 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M-raportti ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-07-01 17:58 . 2012-07-24 09:44 45856 ----a-w- c:\windows\system32\drivers\avgtpx64.sys
2013-06-23 21:57 . 2010-05-31 16:18 78277128 ----a-w- c:\windows\system32\MRT.exe
2013-06-15 14:23 . 2012-04-03 05:04 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2013-06-15 14:23 . 2011-05-15 11:49 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-06-12 18:48 . 2012-07-10 17:55 867240 ----a-w- c:\windows\SysWow64\npdeployJava1.dll
2013-06-12 18:48 . 2010-06-06 16:25 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll
2013-06-04 11:40 . 2012-08-29 08:52 54728 ----a-w- c:\windows\system32\drivers\Soluto.sys
2013-05-16 03:31 . 2010-06-24 09:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2013-05-13 05:51 . 2013-06-15 10:10 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2013-05-13 05:51 . 2013-06-15 10:10 1464320 ----a-w- c:\windows\system32\crypt32.dll
2013-05-13 05:51 . 2013-06-15 10:10 139776 ----a-w- c:\windows\system32\cryptnet.dll
2013-05-13 05:50 . 2013-06-15 10:10 52224 ----a-w- c:\windows\system32\certenc.dll
2013-05-13 04:45 . 2013-06-15 10:10 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2013-05-13 04:45 . 2013-06-15 10:10 1160192 ----a-w- c:\windows\SysWow64\crypt32.dll
2013-05-13 04:45 . 2013-06-15 10:10 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2013-05-13 03:43 . 2013-06-15 10:10 1192448 ----a-w- c:\windows\system32\certutil.exe
2013-05-13 03:08 . 2013-06-15 10:10 903168 ----a-w- c:\windows\SysWow64\certutil.exe
2013-05-13 03:08 . 2013-06-15 10:10 43008 ----a-w- c:\windows\SysWow64\certenc.dll
2013-05-10 07:57 . 2013-05-10 07:57 27208 ----a-w- c:\windows\system32\AdobePDFUI.dll
2013-05-10 07:57 . 2013-05-10 07:57 55872 ----a-w- c:\windows\system32\AdobePDF.dll
2013-05-10 05:49 . 2013-06-15 10:10 30720 ----a-w- c:\windows\system32\cryptdlg.dll
2013-05-10 03:20 . 2013-06-15 10:10 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll
2013-05-08 06:39 . 2013-06-15 10:10 1910632 ----a-w- c:\windows\system32\drivers\tcpip.sys
2013-05-01 23:06 . 2010-05-31 16:15 278800 ------w- c:\windows\system32\MpSigStub.exe
2013-04-30 21:50 . 2013-04-30 21:50 226304 ----a-w- c:\windows\system32\elshyph.dll
2013-04-30 21:50 . 2013-04-30 21:50 185344 ----a-w- c:\windows\SysWow64\elshyph.dll
2013-04-30 21:50 . 2013-04-30 21:50 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe
2013-04-30 21:50 . 2013-04-30 21:50 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll
2013-04-30 21:50 . 2013-04-30 21:50 158720 ----a-w- c:\windows\SysWow64\msls31.dll
2013-04-30 21:50 . 2013-04-30 21:50 150528 ----a-w- c:\windows\SysWow64\iexpress.exe
2013-04-30 21:50 . 2013-04-30 21:50 138752 ----a-w- c:\windows\SysWow64\wextract.exe
2013-04-30 21:50 . 2013-04-30 21:50 523264 ----a-w- c:\windows\SysWow64\vbscript.dll
2013-04-30 21:50 . 2013-04-30 21:50 38400 ----a-w- c:\windows\SysWow64\imgutil.dll
2013-04-30 21:50 . 2013-04-30 21:50 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe
2013-04-30 21:50 . 2013-04-30 21:50 12800 ----a-w- c:\windows\SysWow64\mshta.exe
2013-04-30 21:50 . 2013-04-30 21:50 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe
2013-04-30 21:50 . 2013-04-30 21:50 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll
2013-04-30 21:50 . 2013-04-30 21:50 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll
2013-04-30 21:50 . 2013-04-30 21:50 61952 ----a-w- c:\windows\SysWow64\tdc.ocx
2013-04-30 21:50 . 2013-04-30 21:50 361984 ----a-w- c:\windows\SysWow64\html.iec
2013-04-30 21:50 . 2013-04-30 21:50 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll
2013-04-30 21:50 . 2013-04-30 21:50 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2013-04-30 21:50 . 2013-04-30 21:50 81408 ----a-w- c:\windows\system32\icardie.dll
2013-04-30 21:50 . 2013-04-30 21:50 762368 ----a-w- c:\windows\system32\ieapfltr.dll
2013-04-30 21:50 . 2013-04-30 21:50 452096 ----a-w- c:\windows\system32\dxtmsft.dll
2013-04-30 21:50 . 2013-04-30 21:50 441856 ----a-w- c:\windows\system32\html.iec
2013-04-30 21:50 . 2013-04-30 21:50 281600 ----a-w- c:\windows\system32\dxtrans.dll
2013-04-30 21:50 . 2013-04-30 21:50 216064 ----a-w- c:\windows\system32\msls31.dll
2013-04-30 21:50 . 2013-04-30 21:50 197120 ----a-w- c:\windows\system32\msrating.dll
2013-04-30 21:50 . 2013-04-30 21:50 1400416 ----a-w- c:\windows\system32\ieapfltr.dat
2013-04-30 21:50 . 2013-04-30 21:50 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll
2013-04-30 21:50 . 2013-04-30 21:50 270848 ----a-w- c:\windows\system32\iedkcs32.dll
2013-04-30 21:50 . 2013-04-30 21:50 247296 ----a-w- c:\windows\system32\webcheck.dll
2013-04-30 21:50 . 2013-04-30 21:50 235008 ----a-w- c:\windows\system32\url.dll
2013-04-30 21:50 . 2013-04-30 21:50 1509376 ----a-w- c:\windows\system32\inetcpl.cpl
2013-04-30 21:50 . 2013-04-30 21:50 97280 ----a-w- c:\windows\system32\mshtmled.dll
2013-04-30 21:50 . 2013-04-30 21:50 27648 ----a-w- c:\windows\system32\licmgr10.dll
2013-04-30 21:50 . 2013-04-30 21:50 144896 ----a-w- c:\windows\system32\wextract.exe
2013-04-30 21:50 . 2013-04-30 21:50 102912 ----a-w- c:\windows\system32\inseng.dll
2013-04-30 21:50 . 2013-04-30 21:50 599552 ----a-w- c:\windows\system32\vbscript.dll
2013-04-30 21:50 . 2013-04-30 21:50 173568 ----a-w- c:\windows\system32\ieUnatt.exe
2013-04-30 21:50 . 2013-04-30 21:50 167424 ----a-w- c:\windows\system32\iexpress.exe
2013-04-30 21:50 . 2013-04-30 21:50 62976 ----a-w- c:\windows\system32\pngfilt.dll
2013-04-30 21:50 . 2013-04-30 21:50 51200 ----a-w- c:\windows\system32\imgutil.dll
2013-04-30 21:50 . 2013-04-30 21:50 149504 ----a-w- c:\windows\system32\occache.dll
2013-04-30 21:50 . 2013-04-30 21:50 13824 ----a-w- c:\windows\system32\mshta.exe
2013-04-30 21:50 . 2013-04-30 21:50 136192 ----a-w- c:\windows\system32\iepeers.dll
2013-04-30 21:49 . 2013-04-30 21:49 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe
2013-04-30 21:49 . 2013-04-30 21:49 52224 ----a-w- c:\windows\system32\msfeedsbs.dll
2013-04-30 21:49 . 2013-04-30 21:49 48640 ----a-w- c:\windows\system32\mshtmler.dll
2013-04-30 21:49 . 2013-04-30 21:49 135680 ----a-w- c:\windows\system32\IEAdvpack.dll
2013-04-30 21:49 . 2013-04-30 21:49 12800 ----a-w- c:\windows\system32\msfeedssync.exe
2013-04-30 21:49 . 2013-04-30 21:49 77312 ----a-w- c:\windows\system32\tdc.ocx
2013-04-26 05:51 . 2013-06-15 10:10 751104 ----a-w- c:\windows\system32\win32spl.dll
2013-04-26 04:55 . 2013-06-15 10:10 492544 ----a-w- c:\windows\SysWow64\win32spl.dll
2013-04-25 23:30 . 2013-06-15 10:08 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2006-05-03 10:06 163328 --sha-r- c:\windows\SysWOW64\flvDX.dll
2007-02-21 11:47 31232 --sha-r- c:\windows\SysWOW64\msfDX.dll
2008-03-16 13:30 216064 --sha-r- c:\windows\SysWOW64\nbDX.dll
2010-01-06 22:00 107520 --sha-r- c:\windows\SysWOW64\TAKDSDecoder.dll
.
.
(((((((((((((((((((((((((((((( Rekisterin käynnistyskohteet )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Huom* Tyhjiä arvoja ja laillisia oletusarvoja ei näytetä
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ad708c09-d51b-45b3-9d28-4eba2681febf}"= "c:\program files (x86)\Download_Energy\prxtbDown.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{ad708c09-d51b-45b3-9d28-4eba2681febf}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Spotify Web Helper"="d:\ohjelmat\Spotify\Data\SpotifyWebHelper.exe" [2013-06-15 1104384]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2013-04-04 532040]
.
c:\users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Ghost\AppData\Roaming\Dropbox\bin\Dropbox.exe [2013-5-25 27776968]
EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2011-3-7 969216]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Desktop Media.lnk - d:\ohjelmat\Desktop Media\mediadetect.exe [2010-2-2 163840]
Spyder3Utility.lnk - c:\program files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe [2010-7-26 7667970]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SolutoService]
@="Service"
.
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys;c:\windows\SYSNATIVE\Drivers\sptd.sys [x]
R2 AODDriver4.01;AODDriver4.01;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 KMService;KMService;c:\windows\system32\srvany.exe;c:\windows\SYSNATIVE\srvany.exe [x]
R2 LVPrcS64;Process Monitor;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe;c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe;c:\program files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [x]
R3 cpuz130;cpuz130;c:\users\Ghost\AppData\Local\Temp\cpuz130\cpuz_x64.sys;c:\users\Ghost\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x]
R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x]
R3 GPU-Z;GPU-Z;c:\users\Ghost\AppData\Local\Temp\GPU-Z.sys;c:\users\Ghost\AppData\Local\Temp\GPU-Z.sys [x]
R3 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x]
R3 LVRS64;Logitech RightSound Filter Driver;c:\windows\system32\DRIVERS\lvrs64.sys;c:\windows\SYSNATIVE\DRIVERS\lvrs64.sys [x]
R3 LVUVC64;Logitech Webcam 600(UVC);c:\windows\system32\DRIVERS\lvuvc64.sys;c:\windows\SYSNATIVE\DRIVERS\lvuvc64.sys [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 PTSimHid;PenTablet Simulated HID MiniDriver;c:\windows\system32\DRIVERS\PTSimHid.sys;c:\windows\SYSNATIVE\DRIVERS\PTSimHid.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 SolutoRemoteService;Soluto Remote Service;c:\program files\Soluto\SolutoRemoteService.exe;c:\program files\Soluto\SolutoRemoteService.exe [x]
R3 Spyder3;Datacolor Spyder3;c:\windows\system32\DRIVERS\Spyder3.sys;c:\windows\SYSNATIVE\DRIVERS\Spyder3.sys [x]
R3 SwitchBoard;SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [x]
R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys;c:\windows\SYSNATIVE\drivers\synth3dvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys;c:\windows\SYSNATIVE\drivers\tsusbhub.sys [x]
R3 UMVPFSrv;UMVPFSrv;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe;c:\program files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys;c:\windows\SYSNATIVE\drivers\rdvgkmd.sys [x]
S0 Soluto;Soluto;c:\windows\system32\DRIVERS\Soluto.sys;c:\windows\SYSNATIVE\DRIVERS\Soluto.sys [x]
S1 avgtp;avgtp;c:\windows\system32\drivers\avgtpx64.sys;c:\windows\SYSNATIVE\drivers\avgtpx64.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 cpuz135;cpuz135;c:\windows\system32\drivers\cpuz135_x64.sys;c:\windows\SYSNATIVE\drivers\cpuz135_x64.sys [x]
S2 Realtek11nSU;Realtek11nSU;c:\program files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe;c:\program files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [x]
S2 SolutoLauncherService;Soluto Launcher Service;c:\program files\Soluto\SolutoLauncherService.exe;c:\program files\Soluto\SolutoLauncherService.exe [x]
S2 SolutoService;Soluto PCGenome Core Service;c:\program files\Soluto\SolutoService.exe;c:\program files\Soluto\SolutoService.exe [x]
S2 vToolbarUpdater15.3.0;vToolbarUpdater15.3.0;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe;c:\program files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [x]
S3 amdiox64;AMD IO Driver;c:\windows\system32\DRIVERS\amdiox64.sys;c:\windows\SYSNATIVE\DRIVERS\amdiox64.sys [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 cpuz136;cpuz136;c:\windows\TEMP\cpuz136\cpuz136_x64.sys;c:\windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 LVPr2M64;Logitech LVPr2M64 Driver;c:\windows\system32\DRIVERS\LVPr2M64.sys;c:\windows\SYSNATIVE\DRIVERS\LVPr2M64.sys [x]
S3 PTSimBus;PenTablet Bus Enumerator;c:\windows\system32\DRIVERS\PTSimBus.sys;c:\windows\SYSNATIVE\DRIVERS\PTSimBus.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8192su;Realtek RTL8192SU Wireless LAN 802.11n USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192su.sys [x]
.
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\Ghost\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\Ghost\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\Ghost\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2013-05-25 00:36 164016 ----a-w- c:\users\Ghost\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]
"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-03-30 499608]
"Soluto"="c:\program files\soluto\soluto.exe" [2013-06-04 1230400]
.
------- Täydentävä tarkistus -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 62.241.198.245 62.241.198.246
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll
FF - ProfilePath - c:\users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - DuckDuckGo
FF - prefs.js: browser.startup.homepage - about:home
FF - prefs.js: network.proxy.type - 0
FF - ExtSQL: 2013-06-03 13:23; {888d99e7-e8b5-46a3-851e-1ec45da1e644}; c:\users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
.
- - - - POISTETUT JÄMÄRIVIT - - - -
.
Wow6432Node-HKCU-Run-AdobeBridge - (no file)
.
.
.
--------------------- LUKITUT REKISTERIAVAIMET ---------------------
.
[HKEY_USERS\S-1-5-21-3981131050-3490162696-685170398-1001\Software\SecuROM\License information*]
"datasecu"=hex:c0,1b,97,96,6b,ff,ae,ab,b8,96,f3,d8,c6,9e,4d,7c,ae,26,a0,53,64,
f4,c3,c3,3b,79,ec,6c,a8,48,fe,c7,50,64,9e,d6,81,16,64,c8,2a,ef,c1,69,a6,5c,\
"rkeysecu"=hex:e4,89,5a,9d,e3,4f,fd,12,aa,c7,71,64,e8,b4,f8,1d
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_2_202_235_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_2_202_235.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Valmistumisajankohta: 2013-07-19 00:08:27
ComboFix-quarantined-files.txt 2013-07-18 21:08
.
Ennen ajoa: 14 595 026 944 bytes free
Ajon jälkeen: 14 518 849 536 bytes free
.
- - End Of File - - D66532BAD87987E7CB726AA555710837
A36C5E4F47E84449FF07ED3517B43A31


11:56:02.0378 2844 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
11:56:02.0830 2844 ============================================================
11:56:02.0830 2844 Current date / time: 2013/07/22 11:56:02.0830
11:56:02.0830 2844 SystemInfo:
11:56:02.0830 2844
11:56:02.0830 2844 OS Version: 6.1.7601 ServicePack: 1.0
11:56:02.0830 2844 Product type: Workstation
11:56:02.0830 2844 ComputerName: PC-GHOST
11:56:02.0830 2844 UserName: Ghost
11:56:02.0830 2844 Windows directory: C:\Windows
11:56:02.0830 2844 System windows directory: C:\Windows
11:56:02.0830 2844 Running under WOW64
11:56:02.0830 2844 Processor architecture: Intel x64
11:56:02.0830 2844 Number of processors: 4
11:56:02.0830 2844 Page size: 0x1000
11:56:02.0830 2844 Boot type: Normal boot
11:56:02.0830 2844 ============================================================
11:56:03.0813 2844 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:56:07.0526 2844 Drive \Device\Harddisk1\DR1 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
11:56:07.0542 2844 ============================================================
11:56:07.0542 2844 \Device\Harddisk0\DR0:
11:56:07.0604 2844 MBR partitions:
11:56:07.0604 2844 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x28487800
11:56:07.0604 2844 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x28488800, BlocksNum 0x12EECFF8
11:56:07.0604 2844 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x3B375800, BlocksNum 0xF4E1800
11:56:07.0604 2844 \Device\Harddisk1\DR1:
11:56:07.0604 2844 MBR partitions:
11:56:07.0604 2844 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x3A384800
11:56:07.0604 2844 ============================================================
11:56:07.0651 2844 C: <-> \Device\Harddisk0\DR0\Partition2
11:56:07.0682 2844 D: <-> \Device\Harddisk0\DR0\Partition1
11:56:07.0713 2844 E: <-> \Device\Harddisk0\DR0\Partition3
11:56:07.0791 2844 F: <-> \Device\Harddisk1\DR1\Partition1
11:56:07.0791 2844 ============================================================
11:56:07.0791 2844 Initialize success
11:56:07.0791 2844 ============================================================
11:56:15.0560 0352 ============================================================
11:56:15.0560 0352 Scan started
11:56:15.0560 0352 Mode: Manual;
11:56:15.0560 0352 ============================================================
11:56:15.0966 0352 ================ Scan system memory ========================
11:56:15.0966 0352 System memory - ok
11:56:15.0966 0352 ================ Scan services =============================
11:56:16.0091 0352 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
11:56:16.0106 0352 1394ohci - ok
11:56:16.0137 0352 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:56:16.0153 0352 ACPI - ok
11:56:16.0184 0352 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:56:16.0184 0352 AcpiPmi - ok
11:56:16.0215 0352 [ 2F0683FD2DF1D92E891CACA14B45A8C1 ] adfs C:\Windows\system32\drivers\adfs.sys
11:56:16.0215 0352 adfs - ok
11:56:16.0325 0352 [ 57A3B9A69F14414ACE12AFD6BA701773 ] Adobe Version Cue CS4 C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
11:56:16.0325 0352 Adobe Version Cue CS4 - ok
11:56:16.0403 0352 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:56:16.0403 0352 AdobeARMservice - ok
11:56:16.0449 0352 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
11:56:16.0543 0352 adp94xx - ok
11:56:16.0574 0352 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
11:56:16.0590 0352 adpahci - ok
11:56:16.0605 0352 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
11:56:16.0605 0352 adpu320 - ok
11:56:16.0621 0352 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:56:16.0637 0352 AeLookupSvc - ok
11:56:16.0683 0352 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
11:56:16.0683 0352 AFD - ok
11:56:16.0715 0352 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
11:56:16.0730 0352 agp440 - ok
11:56:16.0730 0352 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
11:56:16.0730 0352 ALG - ok
11:56:16.0746 0352 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
11:56:16.0746 0352 aliide - ok
11:56:16.0793 0352 [ 20C8A3E435A47F0408A1EA674AFA6194 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
11:56:16.0793 0352 AMD External Events Utility - ok
11:56:16.0808 0352 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
11:56:16.0808 0352 amdide - ok
11:56:16.0839 0352 [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys
11:56:16.0839 0352 amdiox64 - ok
11:56:16.0855 0352 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
11:56:16.0871 0352 AmdK8 - ok
11:56:17.0058 0352 [ 0B45C18B0F3EE996D25BAA4E74884B83 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:56:17.0245 0352 amdkmdag - ok
11:56:17.0292 0352 [ 0E57258E5CC4CC7A9A9A877AFDF0CEC6 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
11:56:17.0292 0352 amdkmdap - ok
11:56:17.0323 0352 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
11:56:17.0323 0352 AmdPPM - ok
11:56:17.0354 0352 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:56:17.0354 0352 amdsata - ok
11:56:17.0463 0352 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
11:56:17.0463 0352 amdsbs - ok
11:56:17.0479 0352 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:56:17.0495 0352 amdxata - ok
11:56:17.0557 0352 AODDriver4.01 - ok
11:56:17.0588 0352 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
11:56:17.0588 0352 AppID - ok
11:56:17.0619 0352 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:56:17.0619 0352 AppIDSvc - ok
11:56:17.0651 0352 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
11:56:17.0651 0352 Appinfo - ok
11:56:17.0713 0352 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
11:56:17.0713 0352 Apple Mobile Device - ok
11:56:17.0744 0352 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
11:56:17.0744 0352 AppMgmt - ok
11:56:17.0775 0352 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
11:56:17.0775 0352 arc - ok
11:56:17.0775 0352 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
11:56:17.0791 0352 arcsas - ok
11:56:17.0869 0352 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
11:56:17.0869 0352 aspnet_state - ok
11:56:17.0900 0352 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:56:17.0900 0352 AsyncMac - ok
11:56:17.0931 0352 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
11:56:17.0931 0352 atapi - ok
11:56:17.0978 0352 [ B0790FF0E25B7A2674296052F2162C1A ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
11:56:17.0978 0352 AtiHDAudioService - ok
11:56:17.0994 0352 [ 7E2F5A758F63F80F8B03F889B4E6B19F ] AtiHdmiService C:\Windows\system32\drivers\AtiHdmi.sys
11:56:18.0009 0352 AtiHdmiService - ok
11:56:18.0337 0352 [ 0B45C18B0F3EE996D25BAA4E74884B83 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:56:18.0399 0352 atikmdag - ok
11:56:18.0462 0352 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:56:18.0477 0352 AudioEndpointBuilder - ok
11:56:18.0493 0352 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
11:56:18.0509 0352 AudioSrv - ok
11:56:18.0555 0352 [ 34E9A86B0EF71BA72B58D72215EBFABC ] avgtp C:\Windows\system32\drivers\avgtpx64.sys
11:56:18.0555 0352 avgtp - ok
11:56:18.0587 0352 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:56:18.0602 0352 AxInstSV - ok
11:56:18.0618 0352 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
11:56:18.0633 0352 b06bdrv - ok
11:56:18.0665 0352 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
11:56:18.0665 0352 b57nd60a - ok
11:56:18.0696 0352 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
11:56:18.0696 0352 BDESVC - ok
11:56:18.0711 0352 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
11:56:18.0711 0352 Beep - ok
11:56:18.0774 0352 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
11:56:18.0789 0352 BFE - ok
11:56:18.0836 0352 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
11:56:18.0852 0352 BITS - ok
11:56:18.0867 0352 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:56:18.0867 0352 blbdrive - ok
11:56:18.0945 0352 [ F2060A34C8A75BC24A9222EB4F8C07BD ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
11:56:18.0945 0352 Bonjour Service - ok
11:56:18.0977 0352 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:56:18.0977 0352 bowser - ok
11:56:18.0992 0352 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:56:18.0992 0352 BrFiltLo - ok
11:56:19.0008 0352 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:56:19.0008 0352 BrFiltUp - ok
11:56:19.0055 0352 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
11:56:19.0055 0352 BridgeMP - ok
11:56:19.0070 0352 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
11:56:19.0086 0352 Browser - ok
11:56:19.0086 0352 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:56:19.0086 0352 Brserid - ok
11:56:19.0101 0352 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:56:19.0101 0352 BrSerWdm - ok
11:56:19.0117 0352 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:56:19.0117 0352 BrUsbMdm - ok
11:56:19.0133 0352 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:56:19.0133 0352 BrUsbSer - ok
11:56:19.0148 0352 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
11:56:19.0148 0352 BTHMODEM - ok
11:56:19.0179 0352 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
11:56:19.0179 0352 bthserv - ok
11:56:19.0226 0352 catchme - ok
11:56:19.0273 0352 [ 5753532C476B83119D85AA43B1B10AB3 ] CCALib8 C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
11:56:19.0273 0352 CCALib8 - ok
11:56:19.0304 0352 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:56:19.0304 0352 cdfs - ok
11:56:19.0335 0352 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys
11:56:19.0335 0352 cdrom - ok
11:56:19.0367 0352 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
11:56:19.0367 0352 CertPropSvc - ok
11:56:19.0382 0352 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
11:56:19.0382 0352 circlass - ok
11:56:19.0413 0352 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
11:56:19.0429 0352 CLFS - ok
11:56:19.0460 0352 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:56:19.0460 0352 clr_optimization_v2.0.50727_32 - ok
11:56:19.0491 0352 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
11:56:19.0491 0352 clr_optimization_v2.0.50727_64 - ok
11:56:19.0569 0352 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:56:19.0569 0352 clr_optimization_v4.0.30319_32 - ok
11:56:19.0601 0352 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
11:56:19.0601 0352 clr_optimization_v4.0.30319_64 - ok
11:56:19.0616 0352 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:56:19.0616 0352 CmBatt - ok
11:56:19.0632 0352 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:56:19.0632 0352 cmdide - ok
11:56:19.0663 0352 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
11:56:19.0679 0352 CNG - ok
11:56:19.0679 0352 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:56:19.0679 0352 Compbatt - ok
11:56:19.0710 0352 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
11:56:19.0710 0352 CompositeBus - ok
11:56:19.0710 0352 COMSysApp - ok
11:56:19.0850 0352 cpuz130 - ok
11:56:19.0897 0352 [ 262969A3FAB32B9E17E63E2D17A57744 ] cpuz135 C:\Windows\system32\drivers\cpuz135_x64.sys
11:56:19.0913 0352 cpuz135 - ok
11:56:19.0959 0352 cpuz136 - ok
11:56:19.0975 0352 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
11:56:19.0975 0352 crcdisk - ok
11:56:20.0022 0352 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:56:20.0022 0352 CryptSvc - ok
11:56:20.0053 0352 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys
11:56:20.0069 0352 CSC - ok
11:56:20.0100 0352 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll
11:56:20.0115 0352 CscService - ok
11:56:20.0178 0352 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
11:56:20.0193 0352 DcomLaunch - ok
11:56:20.0240 0352 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
11:56:20.0240 0352 defragsvc - ok
11:56:20.0271 0352 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:56:20.0271 0352 DfsC - ok
11:56:20.0303 0352 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
11:56:20.0318 0352 Dhcp - ok
11:56:20.0334 0352 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
11:56:20.0334 0352 discache - ok
11:56:20.0365 0352 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
11:56:20.0365 0352 Disk - ok
11:56:20.0396 0352 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:56:20.0396 0352 Dnscache - ok
11:56:20.0427 0352 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
11:56:20.0427 0352 dot3svc - ok
11:56:20.0459 0352 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
11:56:20.0459 0352 DPS - ok
11:56:20.0490 0352 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:56:20.0490 0352 drmkaud - ok
11:56:20.0521 0352 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:56:20.0537 0352 DXGKrnl - ok
11:56:20.0583 0352 EagleX64 - ok
11:56:20.0583 0352 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
11:56:20.0599 0352 EapHost - ok
11:56:20.0646 0352 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
11:56:20.0708 0352 ebdrv - ok
11:56:20.0739 0352 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
11:56:20.0739 0352 EFS - ok
11:56:20.0755 0352 [ 9A47AC3DFCF81D30922CDAAF1C2D579F ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys
11:56:20.0755 0352 ElbyCDIO - ok
11:56:20.0786 0352 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
11:56:20.0802 0352 elxstor - ok
11:56:20.0817 0352 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:56:20.0817 0352 ErrDev - ok
11:56:20.0849 0352 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
11:56:20.0864 0352 EventSystem - ok
11:56:20.0864 0352 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
11:56:20.0880 0352 exfat - ok
11:56:20.0895 0352 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:56:20.0895 0352 fastfat - ok
11:56:20.0942 0352 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
11:56:20.0958 0352 Fax - ok
11:56:20.0989 0352 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:56:20.0989 0352 fdc - ok
11:56:21.0005 0352 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
11:56:21.0005 0352 fdPHost - ok
11:56:21.0036 0352 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
11:56:21.0036 0352 FDResPub - ok
11:56:21.0051 0352 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:56:21.0051 0352 FileInfo - ok
11:56:21.0051 0352 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:56:21.0051 0352 Filetrace - ok
11:56:21.0098 0352 [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
11:56:21.0114 0352 FLEXnet Licensing Service - ok
11:56:21.0192 0352 [ 1C3FB052A0BB72EDAED90785C34D6EED ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
11:56:21.0207 0352 FLEXnet Licensing Service 64 - ok
11:56:21.0223 0352 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:56:21.0223 0352 flpydisk - ok
11:56:21.0254 0352 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:56:21.0270 0352 FltMgr - ok
11:56:21.0317 0352 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
11:56:21.0332 0352 FontCache - ok
11:56:21.0426 0352 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:56:21.0426 0352 FontCache3.0.0.0 - ok
11:56:21.0441 0352 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:56:21.0441 0352 FsDepends - ok
11:56:21.0473 0352 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:56:21.0473 0352 Fs_Rec - ok
11:56:21.0504 0352 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:56:21.0504 0352 fvevol - ok
11:56:21.0519 0352 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
11:56:21.0519 0352 gagp30kx - ok
11:56:21.0551 0352 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
11:56:21.0551 0352 GEARAspiWDM - ok
11:56:21.0582 0352 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
11:56:21.0613 0352 gpsvc - ok
11:56:21.0738 0352 GPU-Z - ok
11:56:21.0800 0352 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:56:21.0800 0352 gupdate - ok
11:56:21.0816 0352 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:56:21.0816 0352 gupdatem - ok
11:56:21.0847 0352 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
11:56:21.0847 0352 gusvc - ok
11:56:21.0878 0352 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
11:56:21.0878 0352 hamachi - ok
11:56:22.0081 0352 [ 3FD2090563AAA835C554FEFF728D5509 ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
11:56:22.0190 0352 Hamachi2Svc - ok
11:56:22.0206 0352 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:56:22.0206 0352 hcw85cir - ok
11:56:22.0253 0352 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:56:22.0253 0352 HdAudAddService - ok
11:56:22.0284 0352 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
11:56:22.0284 0352 HDAudBus - ok
11:56:22.0299 0352 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
11:56:22.0299 0352 HidBatt - ok
11:56:22.0299 0352 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
11:56:22.0299 0352 HidBth - ok
11:56:22.0315 0352 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
11:56:22.0315 0352 HidIr - ok
11:56:22.0331 0352 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
11:56:22.0331 0352 hidserv - ok
11:56:22.0362 0352 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
11:56:22.0362 0352 HidUsb - ok
11:56:22.0393 0352 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:56:22.0393 0352 hkmsvc - ok
11:56:22.0424 0352 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:56:22.0424 0352 HomeGroupListener - ok
11:56:22.0471 0352 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:56:22.0471 0352 HomeGroupProvider - ok
11:56:22.0502 0352 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:56:22.0502 0352 HpSAMD - ok
11:56:22.0549 0352 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:56:22.0565 0352 HTTP - ok
11:56:22.0596 0352 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:56:22.0596 0352 hwpolicy - ok
11:56:22.0627 0352 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
11:56:22.0627 0352 i8042prt - ok
11:56:22.0674 0352 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:56:22.0674 0352 iaStorV - ok
11:56:22.0783 0352 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
11:56:22.0783 0352 IDriverT - ok
11:56:22.0830 0352 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
11:56:22.0845 0352 idsvc - ok
11:56:22.0861 0352 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
11:56:22.0861 0352 iirsp - ok
11:56:22.0877 0352 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
11:56:22.0908 0352 IKEEXT - ok
11:56:22.0986 0352 [ BC64B75E8E0A0B8982AB773483164E72 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
11:56:23.0017 0352 IntcAzAudAddService - ok
11:56:23.0033 0352 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
11:56:23.0033 0352 intelide - ok
11:56:23.0048 0352 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:56:23.0064 0352 intelppm - ok
11:56:23.0079 0352 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:56:23.0079 0352 IPBusEnum - ok
11:56:23.0111 0352 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:56:23.0111 0352 IpFilterDriver - ok
11:56:23.0142 0352 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:56:23.0142 0352 iphlpsvc - ok
11:56:23.0173 0352 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:56:23.0173 0352 IPMIDRV - ok
11:56:23.0189 0352 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:56:23.0189 0352 IPNAT - ok
11:56:23.0267 0352 [ D38469601B72D2DA4F847FC642174E21 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
11:56:23.0282 0352 iPod Service - ok
11:56:23.0313 0352 [ 05360B1EA5A2ABF620D1D96EBD8BD8F1 ] irda C:\Windows\system32\DRIVERS\irda.sys
11:56:23.0313 0352 irda - ok
11:56:23.0407 0352 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:56:23.0407 0352 IRENUM - ok
11:56:23.0438 0352 [ 3848384AB383F0A8F506C4370635C1F9 ] Irmon C:\Windows\System32\irmon.dll
11:56:23.0454 0352 Irmon - ok
11:56:23.0563 0352 [ D2CA12736624BA636F8357DC3EF0757E ] irsir C:\Windows\system32\DRIVERS\irsir.sys
11:56:23.0563 0352 irsir - ok
11:56:23.0594 0352 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:56:23.0594 0352 isapnp - ok
11:56:23.0625 0352 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:56:23.0625 0352 iScsiPrt - ok
11:56:23.0657 0352 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
11:56:23.0657 0352 kbdclass - ok
11:56:23.0672 0352 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
11:56:23.0672 0352 kbdhid - ok
11:56:23.0703 0352 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
11:56:23.0703 0352 KeyIso - ok
11:56:23.0719 0352 KMService - ok
11:56:23.0735 0352 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:56:23.0735 0352 KSecDD - ok
11:56:23.0766 0352 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:56:23.0766 0352 KSecPkg - ok
11:56:23.0781 0352 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
11:56:23.0781 0352 ksthunk - ok
11:56:23.0797 0352 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
11:56:23.0797 0352 KtmRm - ok
11:56:23.0828 0352 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
11:56:23.0828 0352 LanmanServer - ok
11:56:23.0859 0352 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:56:23.0859 0352 LanmanWorkstation - ok
11:56:23.0937 0352 [ 7447F069CE66633DAFA0B2DEEE7AF5BA ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
11:56:23.0937 0352 LBTServ - ok
11:56:23.0969 0352 [ 0A7D6ED578D85F0C35353424EE3F5245 ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys
11:56:23.0969 0352 LHidFilt - ok
11:56:24.0000 0352 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:56:24.0000 0352 lltdio - ok
11:56:24.0015 0352 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:56:24.0015 0352 lltdsvc - ok
11:56:24.0031 0352 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
11:56:24.0031 0352 lmhosts - ok
11:56:24.0062 0352 [ 6542E2E6DB58118FBB1B82A68CE3AFF9 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys
11:56:24.0062 0352 LMouFilt - ok
11:56:24.0078 0352 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
11:56:24.0078 0352 LSI_FC - ok
11:56:24.0093 0352 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
11:56:24.0093 0352 LSI_SAS - ok
11:56:24.0109 0352 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:56:24.0109 0352 LSI_SAS2 - ok
11:56:24.0125 0352 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:56:24.0125 0352 LSI_SCSI - ok
11:56:24.0156 0352 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
11:56:24.0156 0352 luafv - ok
11:56:24.0187 0352 [ DA3494DF01C62D821911ED91CE5E1642 ] LUsbFilt C:\Windows\system32\Drivers\LUsbFilt.Sys
11:56:24.0187 0352 LUsbFilt - ok
11:56:24.0218 0352 [ DED333DBDBBCC3555A6E6244522E2F1A ] LVPr2M64 C:\Windows\system32\DRIVERS\LVPr2M64.sys
11:56:24.0218 0352 LVPr2M64 - ok
11:56:24.0249 0352 [ DED333DBDBBCC3555A6E6244522E2F1A ] LVPr2Mon C:\Windows\system32\DRIVERS\LVPr2M64.sys
11:56:24.0249 0352 LVPr2Mon - ok
11:56:24.0296 0352 [ A35679E56E78091E1042A2D7ADBF2958 ] LVPrcS64 C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
11:56:24.0296 0352 LVPrcS64 - ok
11:56:24.0327 0352 [ 0C85B2B6FB74B36A251792D45E0EF860 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys
11:56:24.0343 0352 LVRS64 - ok
11:56:24.0437 0352 [ FF3A488924B0032B1A9CA6948C1FA9E8 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys
11:56:24.0546 0352 LVUVC64 - ok
11:56:24.0593 0352 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
11:56:24.0593 0352 MBAMProtector - ok
11:56:24.0655 0352 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
11:56:24.0655 0352 MBAMScheduler - ok
11:56:24.0702 0352 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
11:56:24.0717 0352 MBAMService - ok
11:56:24.0717 0352 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
11:56:24.0733 0352 megasas - ok
11:56:24.0733 0352 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
11:56:24.0733 0352 MegaSR - ok
11:56:24.0764 0352 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
11:56:24.0764 0352 MMCSS - ok
11:56:24.0780 0352 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
11:56:24.0780 0352 Modem - ok
11:56:24.0811 0352 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:56:24.0811 0352 monitor - ok
11:56:24.0842 0352 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
11:56:24.0842 0352 mouclass - ok
11:56:24.0858 0352 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:56:24.0858 0352 mouhid - ok
11:56:24.0889 0352 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:56:24.0889 0352 mountmgr - ok
11:56:24.0936 0352 [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:56:24.0936 0352 MozillaMaintenance - ok
11:56:24.0967 0352 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
11:56:24.0967 0352 mpio - ok
11:56:24.0983 0352 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:56:24.0983 0352 mpsdrv - ok
11:56:25.0029 0352 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:56:25.0045 0352 MpsSvc - ok
11:56:25.0076 0352 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:56:25.0092 0352 MRxDAV - ok
11:56:25.0107 0352 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:56:25.0107 0352 mrxsmb - ok
11:56:25.0139 0352 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:56:25.0139 0352 mrxsmb10 - ok
11:56:25.0170 0352 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:56:25.0170 0352 mrxsmb20 - ok
11:56:25.0201 0352 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
11:56:25.0201 0352 msahci - ok
11:56:25.0217 0352 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:56:25.0217 0352 msdsm - ok
11:56:25.0232 0352 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
11:56:25.0232 0352 MSDTC - ok
11:56:25.0263 0352 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:56:25.0263 0352 Msfs - ok
11:56:25.0263 0352 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:56:25.0263 0352 mshidkmdf - ok
11:56:25.0295 0352 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:56:25.0295 0352 msisadrv - ok
11:56:25.0326 0352 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:56:25.0326 0352 MSiSCSI - ok
11:56:25.0326 0352 msiserver - ok
11:56:25.0357 0352 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:56:25.0357 0352 MSKSSRV - ok
11:56:25.0388 0352 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:56:25.0388 0352 MSPCLOCK - ok
11:56:25.0388 0352 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:56:25.0388 0352 MSPQM - ok
11:56:25.0419 0352 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:56:25.0419 0352 MsRPC - ok
11:56:25.0451 0352 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
11:56:25.0451 0352 mssmbios - ok
11:56:25.0451 0352 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:56:25.0466 0352 MSTEE - ok
11:56:25.0466 0352 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
11:56:25.0466 0352 MTConfig - ok
11:56:25.0497 0352 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
11:56:25.0497 0352 Mup - ok
11:56:25.0529 0352 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
11:56:25.0544 0352 napagent - ok
11:56:25.0575 0352 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:56:25.0575 0352 NativeWifiP - ok
11:56:25.0622 0352 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:56:25.0638 0352 NDIS - ok
11:56:25.0669 0352 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:56:25.0669 0352 NdisCap - ok
11:56:25.0700 0352 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:56:25.0700 0352 NdisTapi - ok
11:56:25.0731 0352 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:56:25.0731 0352 Ndisuio - ok
11:56:25.0763 0352 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:56:25.0763 0352 NdisWan - ok
11:56:25.0778 0352 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:56:25.0778 0352 NDProxy - ok
11:56:25.0794 0352 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:56:25.0794 0352 NetBIOS - ok
11:56:25.0825 0352 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:56:25.0825 0352 NetBT - ok
11:56:25.0841 0352 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
11:56:25.0841 0352 Netlogon - ok
11:56:25.0887 0352 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
11:56:25.0887 0352 Netman - ok
11:56:25.0965 0352 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:25.0965 0352 NetMsmqActivator - ok
11:56:25.0981 0352 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:25.0981 0352 NetPipeActivator - ok
11:56:26.0028 0352 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
11:56:26.0028 0352 netprofm - ok
11:56:26.0028 0352 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:26.0028 0352 NetTcpActivator - ok
11:56:26.0043 0352 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:26.0043 0352 NetTcpPortSharing - ok
11:56:26.0043 0352 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
11:56:26.0043 0352 nfrd960 - ok
11:56:26.0090 0352 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
11:56:26.0090 0352 NlaSvc - ok
11:56:26.0137 0352 [ 4903177FC90E77ABEB19021451E9475E ] nmwcd C:\Windows\system32\drivers\ccdcmbx64.sys
11:56:26.0137 0352 nmwcd - ok
11:56:26.0184 0352 [ E6844A4C97E5409BBE24BB4ED000320D ] nmwcdc C:\Windows\system32\drivers\ccdcmbox64.sys
11:56:26.0184 0352 nmwcdc - ok
11:56:26.0199 0352 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:56:26.0199 0352 Npfs - ok
11:56:26.0199 0352 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
11:56:26.0199 0352 nsi - ok
11:56:26.0215 0352 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:56:26.0215 0352 nsiproxy - ok
11:56:26.0262 0352 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:56:26.0293 0352 Ntfs - ok
11:56:26.0293 0352 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
11:56:26.0293 0352 Null - ok
11:56:26.0324 0352 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:56:26.0340 0352 nvraid - ok
11:56:26.0340 0352 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:56:26.0340 0352 nvstor - ok
11:56:26.0387 0352 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:56:26.0387 0352 nv_agp - ok
11:56:26.0418 0352 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:56:26.0418 0352 ohci1394 - ok
11:56:26.0465 0352 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:56:26.0465 0352 ose64 - ok
11:56:26.0699 0352 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:56:26.0730 0352 osppsvc - ok
11:56:26.0745 0352 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:56:26.0761 0352 p2pimsvc - ok
11:56:26.0777 0352 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
11:56:26.0792 0352 p2psvc - ok
11:56:26.0808 0352 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:56:26.0808 0352 Parport - ok
11:56:26.0839 0352 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:56:26.0839 0352 partmgr - ok
11:56:26.0839 0352 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:56:26.0839 0352 PcaSvc - ok
11:56:26.0901 0352 [ 3FDE033DFB0D07F8B7D5C9A3044AA121 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
11:56:26.0901 0352 pccsmcfd - ok
11:56:26.0933 0352 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
11:56:26.0933 0352 pci - ok
11:56:26.0948 0352 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
11:56:26.0948 0352 pciide - ok
11:56:26.0964 0352 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:56:26.0964 0352 pcmcia - ok
11:56:26.0979 0352 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
11:56:26.0979 0352 pcw - ok
11:56:26.0995 0352 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:56:27.0011 0352 PEAUTH - ok
11:56:27.0089 0352 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
11:56:27.0104 0352 PeerDistSvc - ok
11:56:27.0167 0352 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
11:56:27.0167 0352 PerfHost - ok
11:56:27.0213 0352 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
11:56:27.0229 0352 pla - ok
11:56:27.0276 0352 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:56:27.0276 0352 PlugPlay - ok
11:56:27.0307 0352 PnkBstrA - ok
11:56:27.0323 0352 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:56:27.0323 0352 PNRPAutoReg - ok
11:56:27.0338 0352 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:56:27.0338 0352 PNRPsvc - ok
11:56:27.0369 0352 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:56:27.0385 0352 PolicyAgent - ok
11:56:27.0401 0352 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
11:56:27.0401 0352 Power - ok
11:56:27.0432 0352 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:56:27.0447 0352 PptpMiniport - ok
11:56:27.0447 0352 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:56:27.0447 0352 Processor - ok
11:56:27.0479 0352 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
11:56:27.0479 0352 ProfSvc - ok
11:56:27.0494 0352 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:56:27.0494 0352 ProtectedStorage - ok
11:56:27.0525 0352 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:56:27.0525 0352 Psched - ok
11:56:27.0557 0352 [ 0B6DEA0A1662CAB8F2BF339DC0752EF4 ] PSI_SVC_2 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
11:56:27.0572 0352 PSI_SVC_2 - ok
11:56:27.0603 0352 [ 225D3660F926FE761BC8CE10C512AA02 ] PTSimBus C:\Windows\system32\DRIVERS\PTSimBus.sys
11:56:27.0603 0352 PTSimBus - ok
11:56:27.0635 0352 [ BD2194786ABAF4860F41118C0C103E7B ] PTSimHid C:\Windows\system32\DRIVERS\PTSimHid.sys
11:56:27.0635 0352 PTSimHid - ok
11:56:27.0681 0352 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:56:27.0713 0352 ql2300 - ok
11:56:27.0728 0352 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:56:27.0744 0352 ql40xx - ok
11:56:27.0759 0352 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
11:56:27.0759 0352 QWAVE - ok
11:56:27.0759 0352 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:56:27.0775 0352 QWAVEdrv - ok
11:56:27.0775 0352 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:56:27.0775 0352 RasAcd - ok
11:56:27.0822 0352 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:56:27.0822 0352 RasAgileVpn - ok
11:56:27.0822 0352 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
11:56:27.0822 0352 RasAuto - ok
11:56:27.0853 0352 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:56:27.0853 0352 Rasl2tp - ok
11:56:27.0884 0352 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
11:56:27.0884 0352 RasMan - ok
11:56:27.0915 0352 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:56:27.0931 0352 RasPppoe - ok
11:56:27.0947 0352 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:56:27.0947 0352 RasSstp - ok
11:56:27.0978 0352 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:56:27.0978 0352 rdbss - ok
11:56:27.0993 0352 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:56:27.0993 0352 rdpbus - ok
11:56:27.0993 0352 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:56:27.0993 0352 RDPCDD - ok
11:56:28.0025 0352 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
11:56:28.0025 0352 RDPDR - ok
11:56:28.0056 0352 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:56:28.0056 0352 RDPENCDD - ok
11:56:28.0056 0352 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:56:28.0056 0352 RDPREFMP - ok
11:56:28.0103 0352 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
11:56:28.0103 0352 RdpVideoMiniport - ok
11:56:28.0134 0352 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:56:28.0134 0352 RDPWD - ok
11:56:28.0165 0352 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:56:28.0165 0352 rdyboost - ok
11:56:28.0227 0352 [ EA569D48B2E755AF6D96F03F3335D98A ] Realtek11nSU C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
11:56:28.0227 0352 Realtek11nSU - ok
11:56:28.0243 0352 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
11:56:28.0243 0352 RemoteAccess - ok
11:56:28.0274 0352 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:56:28.0274 0352 RemoteRegistry - ok
11:56:28.0305 0352 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:56:28.0305 0352 RpcEptMapper - ok
11:56:28.0305 0352 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
11:56:28.0321 0352 RpcLocator - ok
11:56:28.0352 0352 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
11:56:28.0352 0352 RpcSs - ok
11:56:28.0368 0352 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:56:28.0368 0352 rspndr - ok
11:56:28.0399 0352 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
11:56:28.0399 0352 RTL8167 - ok
11:56:28.0430 0352 [ 5EDFCEE5682237607082880338415AA6 ] RTL8192su C:\Windows\system32\DRIVERS\RTL8192su.sys
11:56:28.0461 0352 RTL8192su - ok
11:56:28.0508 0352 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
11:56:28.0508 0352 s3cap - ok
11:56:28.0524 0352 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
11:56:28.0524 0352 SamSs - ok
11:56:28.0524 0352 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:56:28.0539 0352 sbp2port - ok
11:56:28.0539 0352 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:56:28.0555 0352 SCardSvr - ok
11:56:28.0571 0352 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:56:28.0586 0352 scfilter - ok
11:56:28.0773 0352 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
11:56:28.0805 0352 Schedule - ok
11:56:28.0836 0352 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
11:56:28.0836 0352 SCPolicySvc - ok
11:56:28.0883 0352 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:56:28.0883 0352 SDRSVC - ok
11:56:28.0914 0352 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:56:28.0914 0352 secdrv - ok
11:56:28.0945 0352 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
11:56:28.0945 0352 seclogon - ok
11:56:28.0961 0352 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
11:56:28.0961 0352 SENS - ok
11:56:28.0961 0352 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:56:28.0961 0352 SensrSvc - ok
11:56:28.0992 0352 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:56:28.0992 0352 Serenum - ok
11:56:28.0992 0352 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:56:29.0007 0352 Serial - ok
11:56:29.0023 0352 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:56:29.0023 0352 sermouse - ok
11:56:29.0085 0352 [ 289E853881E688286AD24299FCC485D8 ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
11:56:29.0101 0352 ServiceLayer - ok
11:56:29.0148 0352 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
11:56:29.0148 0352 SessionEnv - ok
11:56:29.0163 0352 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:56:29.0163 0352 sffdisk - ok
11:56:29.0179 0352 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:56:29.0179 0352 sffp_mmc - ok
11:56:29.0195 0352 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:56:29.0195 0352 sffp_sd - ok
11:56:29.0210 0352 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:56:29.0210 0352 sfloppy - ok
11:56:29.0226 0352 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:56:29.0226 0352 SharedAccess - ok
11:56:29.0273 0352 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:56:29.0273 0352 ShellHWDetection - ok
11:56:29.0288 0352 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:56:29.0288 0352 SiSRaid2 - ok
11:56:29.0288 0352 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:56:29.0288 0352 SiSRaid4 - ok
11:56:29.0335 0352 [ CA355B308AA537C6B9D67CD3A5485AF9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
11:56:29.0335 0352 SkypeUpdate - ok
11:56:29.0366 0352 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:56:29.0366 0352 Smb - ok
11:56:29.0382 0352 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:56:29.0382 0352 SNMPTRAP - ok
11:56:29.0429 0352 [ F9369327409492097B0BB7CE86BD29DE ] Soluto C:\Windows\system32\DRIVERS\Soluto.sys
11:56:29.0429 0352 Soluto - ok
11:56:29.0491 0352 [ A3A7A1A356245534E3EA87368BA085E5 ] SolutoLauncherService C:\Program Files\Soluto\SolutoLauncherService.exe
11:56:29.0491 0352 SolutoLauncherService - ok
11:56:29.0538 0352 [ 43E926974ADB9F14A29FD362ADB57421 ] SolutoRemoteService C:\Program Files\Soluto\SolutoRemoteService.exe
11:56:29.0569 0352 SolutoRemoteService - ok
11:56:29.0616 0352 [ A169CE9EF099E0679CE89490998C2069 ] SolutoService C:\Program Files\Soluto\SolutoService.exe
11:56:29.0616 0352 SolutoService - ok
11:56:29.0663 0352 [ 5F9785E7535F8F602CB294A54962C9E7 ] speedfan C:\Windows\syswow64\speedfan.sys
11:56:29.0663 0352 speedfan - ok
11:56:29.0678 0352 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
11:56:29.0678 0352 spldr - ok
11:56:29.0709 0352 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
11:56:29.0725 0352 Spooler - ok
11:56:29.0803 0352 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
11:56:29.0850 0352 sppsvc - ok
11:56:29.0865 0352 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:56:29.0865 0352 sppuinotify - ok
11:56:29.0928 0352 [ 53185C3EF3DECF428B3149AEBD4F6C86 ] sptd C:\Windows\system32\Drivers\sptd.sys
11:56:29.0943 0352 sptd - ok
11:56:29.0975 0352 [ D8B882C520FC83547E22014FF5EC66D7 ] Spyder3 C:\Windows\system32\DRIVERS\Spyder3.sys
11:56:29.0975 0352 Spyder3 - ok
11:56:30.0006 0352 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
11:56:30.0021 0352 srv - ok
11:56:30.0053 0352 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:56:30.0053 0352 srv2 - ok
11:56:30.0068 0352 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:56:30.0068 0352 srvnet - ok
11:56:30.0099 0352 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:56:30.0099 0352 SSDPSRV - ok
11:56:30.0115 0352 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:56:30.0115 0352 SstpSvc - ok
11:56:30.0146 0352 Steam Client Service - ok
11:56:30.0162 0352 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:56:30.0162 0352 stexstor - ok
11:56:30.0209 0352 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
11:56:30.0224 0352 stisvc - ok
11:56:30.0271 0352 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
11:56:30.0271 0352 storflt - ok
11:56:30.0287 0352 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys
11:56:30.0302 0352 storvsc - ok
11:56:30.0318 0352 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
11:56:30.0318 0352 swenum - ok
11:56:30.0411 0352 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
11:56:30.0427 0352 SwitchBoard - ok
11:56:30.0443 0352 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
11:56:30.0458 0352 swprv - ok
11:56:30.0458 0352 Synth3dVsc - ok
11:56:30.0521 0352 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
11:56:30.0552 0352 SysMain - ok
11:56:30.0583 0352 Tablet2k - ok
11:56:30.0630 0352 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:56:30.0630 0352 TabletInputService - ok
11:56:30.0661 0352 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
11:56:30.0661 0352 TapiSrv - ok
11:56:30.0677 0352 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
11:56:30.0677 0352 TBS - ok
11:56:30.0708 0352 [ 530A7F0966493DD437E4342F12CCD63B ] TClass2k C:\Windows\system32\DRIVERS\TClass2k.sys
11:56:30.0708 0352 TClass2k - ok
11:56:30.0770 0352 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:56:30.0801 0352 Tcpip - ok
11:56:30.0833 0352 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:56:30.0833 0352 TCPIP6 - ok
11:56:30.0864 0352 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:56:30.0864 0352 tcpipreg - ok
11:56:30.0879 0352 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:56:30.0879 0352 TDPIPE - ok
11:56:30.0895 0352 [ E4245BDA3190A582D55ED09E137401A9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:56:30.0895 0352 TDTCP - ok
11:56:30.0926 0352 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:56:30.0926 0352 tdx - ok
11:56:30.0942 0352 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:56:30.0942 0352 TermDD - ok
11:56:30.0973 0352 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
11:56:30.0989 0352 TermService - ok
11:56:31.0035 0352 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
11:56:31.0035 0352 Themes - ok
11:56:31.0051 0352 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
11:56:31.0051 0352 THREADORDER - ok
11:56:31.0067 0352 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
11:56:31.0067 0352 TrkWks - ok
11:56:31.0113 0352 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:56:31.0113 0352 TrustedInstaller - ok
11:56:31.0145 0352 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:56:31.0145 0352 tssecsrv - ok
11:56:31.0176 0352 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:56:31.0176 0352 TsUsbFlt - ok
11:56:31.0176 0352 tsusbhub - ok
11:56:31.0207 0352 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:56:31.0207 0352 tunnel - ok
11:56:31.0223 0352 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:56:31.0223 0352 uagp35 - ok
11:56:31.0254 0352 [ 01662B4865FDB282677B11CF416757CE ] UCTblHid C:\Windows\system32\DRIVERS\UCTblHid.sys
11:56:31.0254 0352 UCTblHid - ok
11:56:31.0285 0352 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:56:31.0285 0352 udfs - ok
11:56:31.0301 0352 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:56:31.0301 0352 UI0Detect - ok
11:56:31.0316 0352 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:56:31.0316 0352 uliagpkx - ok
11:56:31.0332 0352 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
11:56:31.0332 0352 umbus - ok
11:56:31.0347 0352 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:56:31.0347 0352 UmPass - ok
11:56:31.0379 0352 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
11:56:31.0379 0352 UmRdpService - ok
11:56:31.0488 0352 [ 67A95B9D129ED5399E7965CD09CF30E7 ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
11:56:31.0488 0352 UMVPFSrv - ok
11:56:31.0519 0352 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
11:56:31.0519 0352 upnphost - ok
11:56:31.0550 0352 [ 907F50B8695DAA65A9445D27AD306E65 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
11:56:31.0550 0352 upperdev - ok
11:56:31.0613 0352 [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
11:56:31.0613 0352 USBAAPL64 - ok
11:56:31.0644 0352 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
11:56:31.0644 0352 usbaudio - ok
11:56:31.0675 0352 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:56:31.0675 0352 usbccgp - ok
11:56:31.0691 0352 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:56:31.0691 0352 usbcir - ok
11:56:31.0722 0352 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
11:56:31.0722 0352 usbehci - ok
11:56:31.0769 0352 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:56:31.0769 0352 usbhub - ok
11:56:31.0784 0352 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
11:56:31.0784 0352 usbohci - ok
11:56:31.0800 0352 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:56:31.0800 0352 usbprint - ok
11:56:31.0831 0352 [ 4ACEE387FA8FD39F83564FCD2FC234F2 ] usbser C:\Windows\system32\drivers\usbser.sys
11:56:31.0831 0352 usbser - ok
11:56:31.0878 0352 [ 3F7498527B48657091C355F683BEB0DD ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
11:56:31.0878 0352 UsbserFilt - ok
11:56:31.0878 0352 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:56:31.0878 0352 USBSTOR - ok
11:56:31.0909 0352 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
11:56:31.0909 0352 usbuhci - ok
11:56:31.0940 0352 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
11:56:31.0940 0352 usbvideo - ok
11:56:31.0956 0352 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
11:56:31.0956 0352 UxSms - ok
11:56:31.0956 0352 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
11:56:31.0956 0352 VaultSvc - ok
11:56:32.0003 0352 [ 84BB306B7863883018D7F3EB0C453BD5 ] VClone C:\Windows\system32\DRIVERS\VClone.sys
11:56:32.0003 0352 VClone - ok
11:56:32.0034 0352 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:56:32.0034 0352 vdrvroot - ok
11:56:32.0065 0352 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
11:56:32.0081 0352 vds - ok
11:56:32.0127 0352 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:56:32.0127 0352 vga - ok
11:56:32.0143 0352 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
11:56:32.0143 0352 VgaSave - ok
11:56:32.0143 0352 VGPU - ok
11:56:32.0174 0352 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:56:32.0174 0352 vhdmp - ok
11:56:32.0205 0352 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
11:56:32.0205 0352 viaide - ok
11:56:32.0221 0352 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
11:56:32.0237 0352 vmbus - ok
11:56:32.0252 0352 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
11:56:32.0252 0352 VMBusHID - ok
11:56:32.0268 0352 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:56:32.0268 0352 volmgr - ok
11:56:32.0315 0352 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:56:32.0315 0352 volmgrx - ok
11:56:32.0455 0352 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:56:32.0455 0352 volsnap - ok
11:56:32.0471 0352 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:56:32.0471 0352 vsmraid - ok
11:56:32.0533 0352 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
11:56:32.0549 0352 VSS - ok
11:56:32.0658 0352 [ 254E8F9BA44E9F55416B0E51DBFF3C5F ] vToolbarUpdater15.3.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
11:56:32.0673 0352 vToolbarUpdater15.3.0 - ok
11:56:32.0673 0352 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
11:56:32.0673 0352 vwifibus - ok
11:56:32.0689 0352 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
11:56:32.0689 0352 vwififlt - ok
11:56:32.0705 0352 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
11:56:32.0705 0352 vwifimp - ok
11:56:32.0720 0352 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
11:56:32.0720 0352 W32Time - ok
11:56:32.0736 0352 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:56:32.0736 0352 WacomPen - ok
11:56:32.0783 0352 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:56:32.0783 0352 WANARP - ok
11:56:32.0798 0352 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:56:32.0798 0352 Wanarpv6 - ok
11:56:32.0845 0352 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:56:32.0861 0352 WatAdminSvc - ok
11:56:32.0923 0352 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
11:56:32.0954 0352 wbengine - ok
11:56:32.0985 0352 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:56:33.0001 0352 WbioSrvc - ok
11:56:33.0017 0352 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:56:33.0032 0352 wcncsvc - ok
11:56:33.0048 0352 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:56:33.0048 0352 WcsPlugInService - ok
11:56:33.0048 0352 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:56:33.0048 0352 Wd - ok
11:56:33.0095 0352 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:56:33.0110 0352 Wdf01000 - ok
11:56:33.0110 0352 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:56:33.0110 0352 WdiServiceHost - ok
11:56:33.0126 0352 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:56:33.0126 0352 WdiSystemHost - ok
11:56:33.0157 0352 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
11:56:33.0157 0352 WebClient - ok
11:56:33.0173 0352 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:56:33.0173 0352 Wecsvc - ok
11:56:33.0173 0352 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:56:33.0188 0352 wercplsupport - ok
11:56:33.0204 0352 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
11:56:33.0204 0352 WerSvc - ok
11:56:33.0219 0352 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:56:33.0219 0352 WfpLwf - ok
11:56:33.0219 0352 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:56:33.0219 0352 WIMMount - ok
11:56:33.0235 0352 WinDefend - ok
11:56:33.0251 0352 WinHttpAutoProxySvc - ok
11:56:33.0282 0352 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:56:33.0297 0352 Winmgmt - ok
11:56:33.0344 0352 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
11:56:33.0375 0352 WinRM - ok
11:56:33.0422 0352 [ 935471EC43505CB23DA16600562EE19A ] WinTabService C:\Windows\System32\Drivers\WTSRV.EXE
11:56:33.0422 0352 WinTabService - ok
11:56:33.0469 0352 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:56:33.0469 0352 WinUsb - ok
11:56:33.0500 0352 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
11:56:33.0516 0352 Wlansvc - ok
11:56:33.0781 0352 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:56:33.0797 0352 wlidsvc - ok
11:56:33.0812 0352 [ 680A7846370000D20D7E74917D5B7936 ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys
11:56:33.0812 0352 WmBEnum - ok
11:56:33.0859 0352 [ 14C35BA8189C6F65D839163AA285E954 ] WmFilter C:\Windows\system32\drivers\WmFilter.sys
11:56:33.0859 0352 WmFilter - ok
11:56:33.0875 0352 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:56:33.0890 0352 WmiAcpi - ok
11:56:33.0984 0352 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:56:33.0999 0352 wmiApSrv - ok
11:56:34.0077 0352 WMPNetworkSvc - ok
11:56:34.0109 0352 [ 8488DD91A3EE54A8E29F02AD7BB8201E ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys
11:56:34.0109 0352 WmVirHid - ok
11:56:34.0140 0352 [ 14802B3A30AA849C97CB968CCC813BF3 ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys
11:56:34.0140 0352 WmXlCore - ok
11:56:34.0140 0352 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:56:34.0140 0352 WPCSvc - ok
11:56:34.0171 0352 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:56:34.0187 0352 WPDBusEnum - ok
11:56:34.0202 0352 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:56:34.0202 0352 ws2ifsl - ok
11:56:34.0218 0352 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
11:56:34.0218 0352 wscsvc - ok
11:56:34.0233 0352 WSearch - ok
11:56:34.0265 0352 wuauserv - ok
11:56:34.0280 0352 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:56:34.0280 0352 WudfPf - ok
11:56:34.0296 0352 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:56:34.0296 0352 WUDFRd - ok
11:56:34.0327 0352 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:56:34.0327 0352 wudfsvc - ok
11:56:34.0358 0352 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll
11:56:34.0374 0352 WwanSvc - ok
11:56:34.0405 0352 ================ Scan global ===============================
11:56:34.0421 0352 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
11:56:34.0452 0352 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
11:56:34.0467 0352 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
11:56:34.0483 0352 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
11:56:34.0499 0352 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
11:56:34.0514 0352 [Global] - ok
11:56:34.0514 0352 ================ Scan MBR ==================================
11:56:34.0530 0352 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:56:34.0842 0352 \Device\Harddisk0\DR0 - ok
11:56:34.0842 0352 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk1\DR1
11:56:34.0857 0352 \Device\Harddisk1\DR1 - ok
11:56:34.0857 0352 ================ Scan VBR ==================================
11:56:34.0873 0352 [ 80FC1ED3AF29C35DFEB4F51E51385A78 ] \Device\Harddisk0\DR0\Partition1
11:56:34.0873 0352 \Device\Harddisk0\DR0\Partition1 - ok
11:56:34.0873 0352 [ CF7AB788CE10F4FCE3AE42A3821E154F ] \Device\Harddisk0\DR0\Partition2
11:56:34.0873 0352 \Device\Harddisk0\DR0\Partition2 - ok
11:56:34.0889 0352 [ 175871C4CEA9D3FC51052F569F26D6A5 ] \Device\Harddisk0\DR0\Partition3
11:56:34.0889 0352 \Device\Harddisk0\DR0\Partition3 - ok
11:56:34.0904 0352 [ 89CEA528869D28A7CF89A0F99B0D0DC3 ] \Device\Harddisk1\DR1\Partition1
11:56:34.0904 0352 \Device\Harddisk1\DR1\Partition1 - ok
11:56:34.0904 0352 ============================================================
11:56:34.0904 0352 Scan finished
11:56:34.0904 0352 ============================================================
11:56:34.0904 4012 Detected object count: 0
11:56:34.0904 4012 Actual detected object count: 0
11:56:46.0277 0668 ============================================================
11:56:46.0277 0668 Scan started
11:56:46.0277 0668 Mode: Manual; SigCheck; TDLFS;
11:56:46.0277 0668 ============================================================
11:56:46.0542 0668 ================ Scan system memory ========================
11:56:46.0542 0668 System memory - ok
11:56:46.0542 0668 ================ Scan services =============================
11:56:46.0651 0668 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
11:56:46.0667 0668 1394ohci ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0667 0668 1394ohci - detected UnsignedFile.Multi.Generic (1)
11:56:46.0698 0668 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\Windows\system32\drivers\ACPI.sys
11:56:46.0698 0668 ACPI ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0698 0668 ACPI - detected UnsignedFile.Multi.Generic (1)
11:56:46.0729 0668 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
11:56:46.0729 0668 AcpiPmi ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0729 0668 AcpiPmi - detected UnsignedFile.Multi.Generic (1)
11:56:46.0760 0668 [ 2F0683FD2DF1D92E891CACA14B45A8C1 ] adfs C:\Windows\system32\drivers\adfs.sys
11:56:46.0760 0668 adfs ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0760 0668 adfs - detected UnsignedFile.Multi.Generic (1)
11:56:46.0854 0668 [ 57A3B9A69F14414ACE12AFD6BA701773 ] Adobe Version Cue CS4 C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe
11:56:46.0869 0668 Adobe Version Cue CS4 ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0869 0668 Adobe Version Cue CS4 - detected UnsignedFile.Multi.Generic (1)
11:56:46.0916 0668 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
11:56:46.0916 0668 AdobeARMservice ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0916 0668 AdobeARMservice - detected UnsignedFile.Multi.Generic (1)
11:56:46.0947 0668 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
11:56:46.0947 0668 adp94xx ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0947 0668 adp94xx - detected UnsignedFile.Multi.Generic (1)
11:56:46.0963 0668 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
11:56:46.0979 0668 adpahci ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0979 0668 adpahci - detected UnsignedFile.Multi.Generic (1)
11:56:46.0979 0668 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
11:56:46.0979 0668 adpu320 ( UnsignedFile.Multi.Generic ) - warning
11:56:46.0979 0668 adpu320 - detected UnsignedFile.Multi.Generic (1)
11:56:46.0994 0668 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
11:56:46.0994 0668 AeLookupSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0010 0668 AeLookupSvc - detected UnsignedFile.Multi.Generic (1)
11:56:47.0025 0668 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\Windows\system32\drivers\afd.sys
11:56:47.0025 0668 AFD ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0025 0668 AFD - detected UnsignedFile.Multi.Generic (1)
11:56:47.0057 0668 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\Windows\system32\drivers\agp440.sys
11:56:47.0057 0668 agp440 ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0057 0668 agp440 - detected UnsignedFile.Multi.Generic (1)
11:56:47.0057 0668 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\Windows\System32\alg.exe
11:56:47.0072 0668 ALG ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0072 0668 ALG - detected UnsignedFile.Multi.Generic (1)
11:56:47.0072 0668 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\Windows\system32\drivers\aliide.sys
11:56:47.0072 0668 aliide ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0072 0668 aliide - detected UnsignedFile.Multi.Generic (1)
11:56:47.0103 0668 [ 20C8A3E435A47F0408A1EA674AFA6194 ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
11:56:47.0103 0668 AMD External Events Utility ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0103 0668 AMD External Events Utility - detected UnsignedFile.Multi.Generic (1)
11:56:47.0119 0668 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\Windows\system32\drivers\amdide.sys
11:56:47.0119 0668 amdide ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0119 0668 amdide - detected UnsignedFile.Multi.Generic (1)
11:56:47.0135 0668 [ 6A2EEB0C4133B20773BB3DD0B7B377B4 ] amdiox64 C:\Windows\system32\DRIVERS\amdiox64.sys
11:56:47.0135 0668 amdiox64 ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0135 0668 amdiox64 - detected UnsignedFile.Multi.Generic (1)
11:56:47.0150 0668 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
11:56:47.0150 0668 AmdK8 ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0150 0668 AmdK8 - detected UnsignedFile.Multi.Generic (1)
11:56:47.0337 0668 [ 0B45C18B0F3EE996D25BAA4E74884B83 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:56:47.0415 0668 amdkmdag ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0415 0668 amdkmdag - detected UnsignedFile.Multi.Generic (1)
11:56:47.0447 0668 [ 0E57258E5CC4CC7A9A9A877AFDF0CEC6 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
11:56:47.0447 0668 amdkmdap ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0447 0668 amdkmdap - detected UnsignedFile.Multi.Generic (1)
11:56:47.0462 0668 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
11:56:47.0462 0668 AmdPPM ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0462 0668 AmdPPM - detected UnsignedFile.Multi.Generic (1)
11:56:47.0493 0668 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\Windows\system32\drivers\amdsata.sys
11:56:47.0493 0668 amdsata ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0493 0668 amdsata - detected UnsignedFile.Multi.Generic (1)
11:56:47.0509 0668 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
11:56:47.0509 0668 amdsbs ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0509 0668 amdsbs - detected UnsignedFile.Multi.Generic (1)
11:56:47.0525 0668 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\Windows\system32\drivers\amdxata.sys
11:56:47.0525 0668 amdxata ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0525 0668 amdxata - detected UnsignedFile.Multi.Generic (1)
11:56:47.0571 0668 AODDriver4.01 - ok
11:56:47.0603 0668 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\Windows\system32\drivers\appid.sys
11:56:47.0603 0668 AppID ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0603 0668 AppID - detected UnsignedFile.Multi.Generic (1)
11:56:47.0618 0668 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\Windows\System32\appidsvc.dll
11:56:47.0618 0668 AppIDSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0618 0668 AppIDSvc - detected UnsignedFile.Multi.Generic (1)
11:56:47.0649 0668 [ 9D2A2369AB4B08A4905FE72DB104498F ] Appinfo C:\Windows\System32\appinfo.dll
11:56:47.0649 0668 Appinfo ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0649 0668 Appinfo - detected UnsignedFile.Multi.Generic (1)
11:56:47.0696 0668 [ 20F6F19FE9E753F2780DC2FA083AD597 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
11:56:47.0696 0668 Apple Mobile Device ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0696 0668 Apple Mobile Device - detected UnsignedFile.Multi.Generic (1)
11:56:47.0727 0668 [ 4ABA3E75A76195A3E38ED2766C962899 ] AppMgmt C:\Windows\System32\appmgmts.dll
11:56:47.0727 0668 AppMgmt ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0727 0668 AppMgmt - detected UnsignedFile.Multi.Generic (1)
11:56:47.0727 0668 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\Windows\system32\DRIVERS\arc.sys
11:56:47.0727 0668 arc ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0727 0668 arc - detected UnsignedFile.Multi.Generic (1)
11:56:47.0743 0668 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
11:56:47.0743 0668 arcsas ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0743 0668 arcsas - detected UnsignedFile.Multi.Generic (1)
11:56:47.0805 0668 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe
11:56:47.0821 0668 aspnet_state ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0821 0668 aspnet_state - detected UnsignedFile.Multi.Generic (1)
11:56:47.0821 0668 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
11:56:47.0837 0668 AsyncMac ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0837 0668 AsyncMac - detected UnsignedFile.Multi.Generic (1)
11:56:47.0868 0668 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\Windows\system32\drivers\atapi.sys
11:56:47.0868 0668 atapi ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0868 0668 atapi - detected UnsignedFile.Multi.Generic (1)
11:56:47.0899 0668 [ B0790FF0E25B7A2674296052F2162C1A ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW76.sys
11:56:47.0899 0668 AtiHDAudioService ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0899 0668 AtiHDAudioService - detected UnsignedFile.Multi.Generic (1)
11:56:47.0915 0668 [ 7E2F5A758F63F80F8B03F889B4E6B19F ] AtiHdmiService C:\Windows\system32\drivers\AtiHdmi.sys
11:56:47.0915 0668 AtiHdmiService ( UnsignedFile.Multi.Generic ) - warning
11:56:47.0915 0668 AtiHdmiService - detected UnsignedFile.Multi.Generic (1)
11:56:48.0117 0668 [ 0B45C18B0F3EE996D25BAA4E74884B83 ] atikmdag C:\Windows\system32\DRIVERS\atikmdag.sys
11:56:48.0195 0668 atikmdag ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0195 0668 atikmdag - detected UnsignedFile.Multi.Generic (1)
11:56:48.0227 0668 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
11:56:48.0242 0668 AudioEndpointBuilder ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0242 0668 AudioEndpointBuilder - detected UnsignedFile.Multi.Generic (1)
11:56:48.0258 0668 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\Windows\System32\Audiosrv.dll
11:56:48.0258 0668 AudioSrv ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0258 0668 AudioSrv - detected UnsignedFile.Multi.Generic (1)
11:56:48.0289 0668 [ 34E9A86B0EF71BA72B58D72215EBFABC ] avgtp C:\Windows\system32\drivers\avgtpx64.sys
11:56:48.0289 0668 avgtp ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0289 0668 avgtp - detected UnsignedFile.Multi.Generic (1)
11:56:48.0320 0668 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\Windows\System32\AxInstSV.dll
11:56:48.0320 0668 AxInstSV ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0320 0668 AxInstSV - detected UnsignedFile.Multi.Generic (1)
11:56:48.0336 0668 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\Windows\system32\DRIVERS\bxvbda.sys
11:56:48.0336 0668 b06bdrv ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0336 0668 b06bdrv - detected UnsignedFile.Multi.Generic (1)
11:56:48.0351 0668 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\Windows\system32\DRIVERS\b57nd60a.sys
11:56:48.0351 0668 b57nd60a ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0351 0668 b57nd60a - detected UnsignedFile.Multi.Generic (1)
11:56:48.0367 0668 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\Windows\System32\bdesvc.dll
11:56:48.0367 0668 BDESVC ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0383 0668 BDESVC - detected UnsignedFile.Multi.Generic (1)
11:56:48.0383 0668 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\Windows\system32\drivers\Beep.sys
11:56:48.0383 0668 Beep ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0383 0668 Beep - detected UnsignedFile.Multi.Generic (1)
11:56:48.0429 0668 [ 82974D6A2FD19445CC5171FC378668A4 ] BFE C:\Windows\System32\bfe.dll
11:56:48.0429 0668 BFE ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0429 0668 BFE - detected UnsignedFile.Multi.Generic (1)
11:56:48.0476 0668 [ 1EA7969E3271CBC59E1730697DC74682 ] BITS C:\Windows\System32\qmgr.dll
11:56:48.0476 0668 BITS ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0476 0668 BITS - detected UnsignedFile.Multi.Generic (1)
11:56:48.0492 0668 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
11:56:48.0492 0668 blbdrive ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0492 0668 blbdrive - detected UnsignedFile.Multi.Generic (1)
11:56:48.0523 0668 [ F2060A34C8A75BC24A9222EB4F8C07BD ] Bonjour Service C:\Program Files (x86)\Bonjour\mDNSResponder.exe
11:56:48.0523 0668 Bonjour Service ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0523 0668 Bonjour Service - detected UnsignedFile.Multi.Generic (1)
11:56:48.0554 0668 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
11:56:48.0554 0668 bowser ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0554 0668 bowser - detected UnsignedFile.Multi.Generic (1)
11:56:48.0570 0668 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
11:56:48.0570 0668 BrFiltLo ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0570 0668 BrFiltLo - detected UnsignedFile.Multi.Generic (1)
11:56:48.0585 0668 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
11:56:48.0585 0668 BrFiltUp ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0585 0668 BrFiltUp - detected UnsignedFile.Multi.Generic (1)
11:56:48.0585 0668 [ 5C2F352A4E961D72518261257AAE204B ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
11:56:48.0585 0668 BridgeMP ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0585 0668 BridgeMP - detected UnsignedFile.Multi.Generic (1)
11:56:48.0617 0668 [ 05F5A0D14A2EE1D8255C2AA0E9E8E694 ] Browser C:\Windows\System32\browser.dll
11:56:48.0617 0668 Browser ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0617 0668 Browser - detected UnsignedFile.Multi.Generic (1)
11:56:48.0632 0668 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\Windows\System32\Drivers\Brserid.sys
11:56:48.0632 0668 Brserid ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0632 0668 Brserid - detected UnsignedFile.Multi.Generic (1)
11:56:48.0648 0668 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
11:56:48.0648 0668 BrSerWdm ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0648 0668 BrSerWdm - detected UnsignedFile.Multi.Generic (1)
11:56:48.0648 0668 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
11:56:48.0648 0668 BrUsbMdm ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0648 0668 BrUsbMdm - detected UnsignedFile.Multi.Generic (1)
11:56:48.0663 0668 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
11:56:48.0663 0668 BrUsbSer ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0663 0668 BrUsbSer - detected UnsignedFile.Multi.Generic (1)
11:56:48.0679 0668 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
11:56:48.0679 0668 BTHMODEM ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0679 0668 BTHMODEM - detected UnsignedFile.Multi.Generic (1)
11:56:48.0695 0668 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\Windows\system32\bthserv.dll
11:56:48.0695 0668 bthserv ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0695 0668 bthserv - detected UnsignedFile.Multi.Generic (1)
11:56:48.0726 0668 catchme - ok
11:56:48.0757 0668 [ 5753532C476B83119D85AA43B1B10AB3 ] CCALib8 C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
11:56:48.0757 0668 CCALib8 ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0757 0668 CCALib8 - detected UnsignedFile.Multi.Generic (1)
11:56:48.0773 0668 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
11:56:48.0773 0668 cdfs ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0773 0668 cdfs - detected UnsignedFile.Multi.Generic (1)
11:56:48.0804 0668 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\Windows\system32\drivers\cdrom.sys
11:56:48.0804 0668 cdrom ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0804 0668 cdrom - detected UnsignedFile.Multi.Generic (1)
11:56:48.0835 0668 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\Windows\System32\certprop.dll
11:56:48.0835 0668 CertPropSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0835 0668 CertPropSvc - detected UnsignedFile.Multi.Generic (1)
11:56:48.0835 0668 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\Windows\system32\DRIVERS\circlass.sys
11:56:48.0835 0668 circlass ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0835 0668 circlass - detected UnsignedFile.Multi.Generic (1)
11:56:48.0866 0668 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\Windows\system32\CLFS.sys
11:56:48.0866 0668 CLFS ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0866 0668 CLFS - detected UnsignedFile.Multi.Generic (1)
11:56:48.0913 0668 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
11:56:48.0913 0668 clr_optimization_v2.0.50727_32 ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0913 0668 clr_optimization_v2.0.50727_32 - detected UnsignedFile.Multi.Generic (1)
11:56:48.0944 0668 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
11:56:48.0944 0668 clr_optimization_v2.0.50727_64 ( UnsignedFile.Multi.Generic ) - warning
11:56:48.0944 0668 clr_optimization_v2.0.50727_64 - detected UnsignedFile.Multi.Generic (1)
11:56:49.0007 0668 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
11:56:49.0007 0668 clr_optimization_v4.0.30319_32 ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0007 0668 clr_optimization_v4.0.30319_32 - detected UnsignedFile.Multi.Generic (1)
11:56:49.0022 0668 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
11:56:49.0022 0668 clr_optimization_v4.0.30319_64 ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0022 0668 clr_optimization_v4.0.30319_64 - detected UnsignedFile.Multi.Generic (1)
11:56:49.0038 0668 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
11:56:49.0038 0668 CmBatt ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0038 0668 CmBatt - detected UnsignedFile.Multi.Generic (1)
11:56:49.0038 0668 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\Windows\system32\drivers\cmdide.sys
11:56:49.0038 0668 cmdide ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0038 0668 cmdide - detected UnsignedFile.Multi.Generic (1)
11:56:49.0085 0668 [ AAFCB52FE0037207FB6FBEA070D25EFE ] CNG C:\Windows\system32\Drivers\cng.sys
11:56:49.0085 0668 CNG ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0085 0668 CNG - detected UnsignedFile.Multi.Generic (1)
11:56:49.0100 0668 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
11:56:49.0100 0668 Compbatt ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0100 0668 Compbatt - detected UnsignedFile.Multi.Generic (1)
11:56:49.0100 0668 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
11:56:49.0100 0668 CompositeBus ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0100 0668 CompositeBus - detected UnsignedFile.Multi.Generic (1)
11:56:49.0100 0668 COMSysApp - ok
11:56:49.0272 0668 cpuz130 - ok
11:56:49.0287 0668 [ 262969A3FAB32B9E17E63E2D17A57744 ] cpuz135 C:\Windows\system32\drivers\cpuz135_x64.sys
11:56:49.0287 0668 cpuz135 ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0287 0668 cpuz135 - detected UnsignedFile.Multi.Generic (1)
11:56:49.0350 0668 cpuz136 - ok
11:56:49.0365 0668 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
11:56:49.0365 0668 crcdisk ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0365 0668 crcdisk - detected UnsignedFile.Multi.Generic (1)
11:56:49.0412 0668 [ D8129C49798CBBFB2E4351D4B7B8EF9C ] CryptSvc C:\Windows\system32\cryptsvc.dll
11:56:49.0412 0668 CryptSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0412 0668 CryptSvc - detected UnsignedFile.Multi.Generic (1)
11:56:49.0521 0668 [ 54DA3DFD29ED9F1619B6F53F3CE55E49 ] CSC C:\Windows\system32\drivers\csc.sys
11:56:49.0521 0668 CSC ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0521 0668 CSC - detected UnsignedFile.Multi.Generic (1)
11:56:49.0553 0668 [ 3AB183AB4D2C79DCF459CD2C1266B043 ] CscService C:\Windows\System32\cscsvc.dll
11:56:49.0568 0668 CscService ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0568 0668 CscService - detected UnsignedFile.Multi.Generic (1)
11:56:49.0599 0668 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\Windows\system32\rpcss.dll
11:56:49.0615 0668 DcomLaunch ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0615 0668 DcomLaunch - detected UnsignedFile.Multi.Generic (1)
11:56:49.0631 0668 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\Windows\System32\defragsvc.dll
11:56:49.0631 0668 defragsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0631 0668 defragsvc - detected UnsignedFile.Multi.Generic (1)
11:56:49.0662 0668 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
11:56:49.0662 0668 DfsC ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0662 0668 DfsC - detected UnsignedFile.Multi.Generic (1)
11:56:49.0693 0668 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\Windows\system32\dhcpcore.dll
11:56:49.0709 0668 Dhcp ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0709 0668 Dhcp - detected UnsignedFile.Multi.Generic (1)
11:56:49.0709 0668 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\Windows\system32\drivers\discache.sys
11:56:49.0709 0668 discache ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0709 0668 discache - detected UnsignedFile.Multi.Generic (1)
11:56:49.0724 0668 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\Windows\system32\DRIVERS\disk.sys
11:56:49.0724 0668 Disk ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0724 0668 Disk - detected UnsignedFile.Multi.Generic (1)
11:56:49.0755 0668 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\Windows\System32\dnsrslvr.dll
11:56:49.0755 0668 Dnscache ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0755 0668 Dnscache - detected UnsignedFile.Multi.Generic (1)
11:56:49.0787 0668 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\Windows\System32\dot3svc.dll
11:56:49.0787 0668 dot3svc ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0787 0668 dot3svc - detected UnsignedFile.Multi.Generic (1)
11:56:49.0818 0668 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\Windows\system32\dps.dll
11:56:49.0818 0668 DPS ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0818 0668 DPS - detected UnsignedFile.Multi.Generic (1)
11:56:49.0833 0668 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
11:56:49.0833 0668 drmkaud ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0833 0668 drmkaud - detected UnsignedFile.Multi.Generic (1)
11:56:49.0880 0668 [ AF2E16242AA723F68F461B6EAE2EAD3D ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
11:56:49.0880 0668 DXGKrnl ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0880 0668 DXGKrnl - detected UnsignedFile.Multi.Generic (1)
11:56:49.0896 0668 EagleX64 - ok
11:56:49.0911 0668 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\Windows\System32\eapsvc.dll
11:56:49.0911 0668 EapHost ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0911 0668 EapHost - detected UnsignedFile.Multi.Generic (1)
11:56:49.0974 0668 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\Windows\system32\DRIVERS\evbda.sys
11:56:49.0989 0668 ebdrv ( UnsignedFile.Multi.Generic ) - warning
11:56:49.0989 0668 ebdrv - detected UnsignedFile.Multi.Generic (1)
11:56:50.0021 0668 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\Windows\System32\lsass.exe
11:56:50.0021 0668 EFS ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0021 0668 EFS - detected UnsignedFile.Multi.Generic (1)
11:56:50.0036 0668 [ 9A47AC3DFCF81D30922CDAAF1C2D579F ] ElbyCDIO C:\Windows\system32\Drivers\ElbyCDIO.sys
11:56:50.0036 0668 ElbyCDIO ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0036 0668 ElbyCDIO - detected UnsignedFile.Multi.Generic (1)
11:56:50.0067 0668 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
11:56:50.0067 0668 elxstor ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0067 0668 elxstor - detected UnsignedFile.Multi.Generic (1)
11:56:50.0083 0668 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\Windows\system32\drivers\errdev.sys
11:56:50.0099 0668 ErrDev ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0099 0668 ErrDev - detected UnsignedFile.Multi.Generic (1)
11:56:50.0114 0668 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\Windows\system32\es.dll
11:56:50.0114 0668 EventSystem ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0114 0668 EventSystem - detected UnsignedFile.Multi.Generic (1)
11:56:50.0130 0668 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\Windows\system32\drivers\exfat.sys
11:56:50.0130 0668 exfat ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0130 0668 exfat - detected UnsignedFile.Multi.Generic (1)
11:56:50.0145 0668 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\Windows\system32\drivers\fastfat.sys
11:56:50.0145 0668 fastfat ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0145 0668 fastfat - detected UnsignedFile.Multi.Generic (1)
11:56:50.0177 0668 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\Windows\system32\fxssvc.exe
11:56:50.0177 0668 Fax ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0177 0668 Fax - detected UnsignedFile.Multi.Generic (1)
11:56:50.0208 0668 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\Windows\system32\DRIVERS\fdc.sys
11:56:50.0208 0668 fdc ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0208 0668 fdc - detected UnsignedFile.Multi.Generic (1)
11:56:50.0208 0668 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\Windows\system32\fdPHost.dll
11:56:50.0208 0668 fdPHost ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0208 0668 fdPHost - detected UnsignedFile.Multi.Generic (1)
11:56:50.0239 0668 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\Windows\system32\fdrespub.dll
11:56:50.0239 0668 FDResPub ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0239 0668 FDResPub - detected UnsignedFile.Multi.Generic (1)
11:56:50.0239 0668 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
11:56:50.0239 0668 FileInfo ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0239 0668 FileInfo - detected UnsignedFile.Multi.Generic (1)
11:56:50.0255 0668 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
11:56:50.0255 0668 Filetrace ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0255 0668 Filetrace - detected UnsignedFile.Multi.Generic (1)
11:56:50.0301 0668 [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
11:56:50.0301 0668 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0301 0668 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)
11:56:50.0379 0668 [ 1C3FB052A0BB72EDAED90785C34D6EED ] FLEXnet Licensing Service 64 C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
11:56:50.0379 0668 FLEXnet Licensing Service 64 ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0379 0668 FLEXnet Licensing Service 64 - detected UnsignedFile.Multi.Generic (1)
11:56:50.0395 0668 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
11:56:50.0395 0668 flpydisk ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0395 0668 flpydisk - detected UnsignedFile.Multi.Generic (1)
11:56:50.0426 0668 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
11:56:50.0426 0668 FltMgr ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0426 0668 FltMgr - detected UnsignedFile.Multi.Generic (1)
11:56:50.0473 0668 [ C4C183E6551084039EC862DA1C945E3D ] FontCache C:\Windows\system32\FntCache.dll
11:56:50.0473 0668 FontCache ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0473 0668 FontCache - detected UnsignedFile.Multi.Generic (1)
11:56:50.0535 0668 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
11:56:50.0535 0668 FontCache3.0.0.0 ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0535 0668 FontCache3.0.0.0 - detected UnsignedFile.Multi.Generic (1)
11:56:50.0551 0668 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
11:56:50.0551 0668 FsDepends ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0551 0668 FsDepends - detected UnsignedFile.Multi.Generic (1)
11:56:50.0582 0668 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
11:56:50.0582 0668 Fs_Rec ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0582 0668 Fs_Rec - detected UnsignedFile.Multi.Generic (1)
11:56:50.0613 0668 [ 8F6322049018354F45F05A2FD2D4E5E0 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
11:56:50.0613 0668 fvevol ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0613 0668 fvevol - detected UnsignedFile.Multi.Generic (1)
11:56:50.0613 0668 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
11:56:50.0613 0668 gagp30kx ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0613 0668 gagp30kx - detected UnsignedFile.Multi.Generic (1)
11:56:50.0645 0668 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
11:56:50.0645 0668 GEARAspiWDM ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0645 0668 GEARAspiWDM - detected UnsignedFile.Multi.Generic (1)
11:56:50.0691 0668 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\Windows\System32\gpsvc.dll
11:56:50.0691 0668 gpsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0691 0668 gpsvc - detected UnsignedFile.Multi.Generic (1)
11:56:50.0801 0668 GPU-Z - ok
11:56:50.0847 0668 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:56:50.0847 0668 gupdate ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0847 0668 gupdate - detected UnsignedFile.Multi.Generic (1)
11:56:50.0863 0668 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
11:56:50.0863 0668 gupdatem ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0863 0668 gupdatem - detected UnsignedFile.Multi.Generic (1)
11:56:50.0879 0668 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
11:56:50.0879 0668 gusvc ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0879 0668 gusvc - detected UnsignedFile.Multi.Generic (1)
11:56:50.0910 0668 [ 1E6438D4EA6E1174A3B3B1EDC4DE660B ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
11:56:50.0910 0668 hamachi ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0910 0668 hamachi - detected UnsignedFile.Multi.Generic (1)
11:56:50.0972 0668 [ 3FD2090563AAA835C554FEFF728D5509 ] Hamachi2Svc C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
11:56:50.0988 0668 Hamachi2Svc ( UnsignedFile.Multi.Generic ) - warning
11:56:50.0988 0668 Hamachi2Svc - detected UnsignedFile.Multi.Generic (1)
11:56:51.0003 0668 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
11:56:51.0019 0668 hcw85cir ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0019 0668 hcw85cir - detected UnsignedFile.Multi.Generic (1)
11:56:51.0035 0668 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
11:56:51.0050 0668 HdAudAddService ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0050 0668 HdAudAddService - detected UnsignedFile.Multi.Generic (1)
11:56:51.0066 0668 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
11:56:51.0066 0668 HDAudBus ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0066 0668 HDAudBus - detected UnsignedFile.Multi.Generic (1)
11:56:51.0081 0668 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
11:56:51.0081 0668 HidBatt ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0081 0668 HidBatt - detected UnsignedFile.Multi.Generic (1)
11:56:51.0081 0668 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
11:56:51.0081 0668 HidBth ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0081 0668 HidBth - detected UnsignedFile.Multi.Generic (1)
11:56:51.0097 0668 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
11:56:51.0097 0668 HidIr ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0097 0668 HidIr - detected UnsignedFile.Multi.Generic (1)
11:56:51.0113 0668 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\Windows\System32\hidserv.dll
11:56:51.0113 0668 hidserv ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0113 0668 hidserv - detected UnsignedFile.Multi.Generic (1)
11:56:51.0128 0668 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
11:56:51.0144 0668 HidUsb ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0144 0668 HidUsb - detected UnsignedFile.Multi.Generic (1)
11:56:51.0159 0668 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\Windows\system32\kmsvc.dll
11:56:51.0175 0668 hkmsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0175 0668 hkmsvc - detected UnsignedFile.Multi.Generic (1)
11:56:51.0206 0668 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\Windows\system32\ListSvc.dll
11:56:51.0206 0668 HomeGroupListener ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0206 0668 HomeGroupListener - detected UnsignedFile.Multi.Generic (1)
11:56:51.0237 0668 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
11:56:51.0237 0668 HomeGroupProvider ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0237 0668 HomeGroupProvider - detected UnsignedFile.Multi.Generic (1)
11:56:51.0269 0668 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
11:56:51.0269 0668 HpSAMD ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0269 0668 HpSAMD - detected UnsignedFile.Multi.Generic (1)
11:56:51.0315 0668 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\Windows\system32\drivers\HTTP.sys
11:56:51.0315 0668 HTTP ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0315 0668 HTTP - detected UnsignedFile.Multi.Generic (1)
11:56:51.0347 0668 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
11:56:51.0347 0668 hwpolicy ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0347 0668 hwpolicy - detected UnsignedFile.Multi.Generic (1)
11:56:51.0378 0668 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
11:56:51.0378 0668 i8042prt ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0378 0668 i8042prt - detected UnsignedFile.Multi.Generic (1)
11:56:51.0409 0668 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
11:56:51.0409 0668 iaStorV ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0409 0668 iaStorV - detected UnsignedFile.Multi.Generic (1)
11:56:51.0471 0668 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
11:56:51.0471 0668 IDriverT ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0471 0668 IDriverT - detected UnsignedFile.Multi.Generic (1)
11:56:51.0518 0668 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
11:56:51.0518 0668 idsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0518 0668 idsvc - detected UnsignedFile.Multi.Generic (1)
11:56:51.0534 0668 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
11:56:51.0534 0668 iirsp ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0534 0668 iirsp - detected UnsignedFile.Multi.Generic (1)
11:56:51.0565 0668 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\Windows\System32\ikeext.dll
11:56:51.0565 0668 IKEEXT ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0565 0668 IKEEXT - detected UnsignedFile.Multi.Generic (1)
11:56:51.0705 0668 [ BC64B75E8E0A0B8982AB773483164E72 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys
11:56:51.0705 0668 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0705 0668 IntcAzAudAddService - detected UnsignedFile.Multi.Generic (1)
11:56:51.0737 0668 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\Windows\system32\drivers\intelide.sys
11:56:51.0752 0668 intelide ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0752 0668 intelide - detected UnsignedFile.Multi.Generic (1)
11:56:51.0768 0668 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
11:56:51.0768 0668 intelppm ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0768 0668 intelppm - detected UnsignedFile.Multi.Generic (1)
11:56:51.0783 0668 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\Windows\system32\ipbusenum.dll
11:56:51.0783 0668 IPBusEnum ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0783 0668 IPBusEnum - detected UnsignedFile.Multi.Generic (1)
11:56:51.0815 0668 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
11:56:51.0815 0668 IpFilterDriver ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0815 0668 IpFilterDriver - detected UnsignedFile.Multi.Generic (1)
11:56:51.0846 0668 [ 08C2957BB30058E663720C5606885653 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
11:56:51.0861 0668 iphlpsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0861 0668 iphlpsvc - detected UnsignedFile.Multi.Generic (1)
11:56:51.0877 0668 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
11:56:51.0877 0668 IPMIDRV ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0877 0668 IPMIDRV - detected UnsignedFile.Multi.Generic (1)
11:56:51.0893 0668 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
11:56:51.0893 0668 IPNAT ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0893 0668 IPNAT - detected UnsignedFile.Multi.Generic (1)
11:56:51.0955 0668 [ D38469601B72D2DA4F847FC642174E21 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
11:56:51.0971 0668 iPod Service ( UnsignedFile.Multi.Generic ) - warning
11:56:51.0971 0668 iPod Service - detected UnsignedFile.Multi.Generic (1)
11:56:52.0002 0668 [ 05360B1EA5A2ABF620D1D96EBD8BD8F1 ] irda C:\Windows\system32\DRIVERS\irda.sys
11:56:52.0002 0668 irda ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0002 0668 irda - detected UnsignedFile.Multi.Generic (1)
11:56:52.0017 0668 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\Windows\system32\drivers\irenum.sys
11:56:52.0017 0668 IRENUM ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0017 0668 IRENUM - detected UnsignedFile.Multi.Generic (1)
11:56:52.0033 0668 [ 3848384AB383F0A8F506C4370635C1F9 ] Irmon C:\Windows\System32\irmon.dll
11:56:52.0033 0668 Irmon ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0033 0668 Irmon - detected UnsignedFile.Multi.Generic (1)
11:56:52.0064 0668 [ D2CA12736624BA636F8357DC3EF0757E ] irsir C:\Windows\system32\DRIVERS\irsir.sys
11:56:52.0064 0668 irsir ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0064 0668 irsir - detected UnsignedFile.Multi.Generic (1)
11:56:52.0080 0668 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\Windows\system32\drivers\isapnp.sys
11:56:52.0080 0668 isapnp ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0080 0668 isapnp - detected UnsignedFile.Multi.Generic (1)
11:56:52.0111 0668 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
11:56:52.0111 0668 iScsiPrt ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0111 0668 iScsiPrt - detected UnsignedFile.Multi.Generic (1)
11:56:52.0142 0668 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
11:56:52.0142 0668 kbdclass ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0142 0668 kbdclass - detected UnsignedFile.Multi.Generic (1)
11:56:52.0158 0668 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
11:56:52.0158 0668 kbdhid ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0158 0668 kbdhid - detected UnsignedFile.Multi.Generic (1)
11:56:52.0173 0668 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\Windows\system32\lsass.exe
11:56:52.0173 0668 KeyIso ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0173 0668 KeyIso - detected UnsignedFile.Multi.Generic (1)
11:56:52.0173 0668 KMService - ok
11:56:52.0205 0668 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
11:56:52.0205 0668 KSecDD ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0205 0668 KSecDD - detected UnsignedFile.Multi.Generic (1)
11:56:52.0236 0668 [ 7EFB9333E4ECCE6AE4AE9D777D9E553E ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
11:56:52.0236 0668 KSecPkg ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0236 0668 KSecPkg - detected UnsignedFile.Multi.Generic (1)
11:56:52.0251 0668 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
11:56:52.0251 0668 ksthunk ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0251 0668 ksthunk - detected UnsignedFile.Multi.Generic (1)
11:56:52.0267 0668 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\Windows\system32\msdtckrm.dll
11:56:52.0267 0668 KtmRm ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0267 0668 KtmRm - detected UnsignedFile.Multi.Generic (1)
11:56:52.0298 0668 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\Windows\System32\srvsvc.dll
11:56:52.0298 0668 LanmanServer ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0298 0668 LanmanServer - detected UnsignedFile.Multi.Generic (1)
11:56:52.0314 0668 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
11:56:52.0314 0668 LanmanWorkstation ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0314 0668 LanmanWorkstation - detected UnsignedFile.Multi.Generic (1)
11:56:52.0376 0668 [ 7447F069CE66633DAFA0B2DEEE7AF5BA ] LBTServ C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
11:56:52.0392 0668 LBTServ ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0392 0668 LBTServ - detected UnsignedFile.Multi.Generic (1)
11:56:52.0423 0668 [ 0A7D6ED578D85F0C35353424EE3F5245 ] LHidFilt C:\Windows\system32\DRIVERS\LHidFilt.Sys
11:56:52.0423 0668 LHidFilt ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0423 0668 LHidFilt - detected UnsignedFile.Multi.Generic (1)
11:56:52.0439 0668 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
11:56:52.0439 0668 lltdio ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0439 0668 lltdio - detected UnsignedFile.Multi.Generic (1)
11:56:52.0454 0668 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\Windows\System32\lltdsvc.dll
11:56:52.0454 0668 lltdsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0454 0668 lltdsvc - detected UnsignedFile.Multi.Generic (1)
11:56:52.0470 0668 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\Windows\System32\lmhsvc.dll
11:56:52.0470 0668 lmhosts ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0470 0668 lmhosts - detected UnsignedFile.Multi.Generic (1)
11:56:52.0485 0668 [ 6542E2E6DB58118FBB1B82A68CE3AFF9 ] LMouFilt C:\Windows\system32\DRIVERS\LMouFilt.Sys
11:56:52.0485 0668 LMouFilt ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0485 0668 LMouFilt - detected UnsignedFile.Multi.Generic (1)
11:56:52.0501 0668 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
11:56:52.0501 0668 LSI_FC ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0501 0668 LSI_FC - detected UnsignedFile.Multi.Generic (1)
11:56:52.0517 0668 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
11:56:52.0517 0668 LSI_SAS ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0517 0668 LSI_SAS - detected UnsignedFile.Multi.Generic (1)
11:56:52.0532 0668 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
11:56:52.0532 0668 LSI_SAS2 ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0532 0668 LSI_SAS2 - detected UnsignedFile.Multi.Generic (1)
11:56:52.0548 0668 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
11:56:52.0548 0668 LSI_SCSI ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0548 0668 LSI_SCSI - detected UnsignedFile.Multi.Generic (1)
11:56:52.0563 0668 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\Windows\system32\drivers\luafv.sys
11:56:52.0563 0668 luafv ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0563 0668 luafv - detected UnsignedFile.Multi.Generic (1)
11:56:52.0579 0668 [ DA3494DF01C62D821911ED91CE5E1642 ] LUsbFilt C:\Windows\system32\Drivers\LUsbFilt.Sys
11:56:52.0579 0668 LUsbFilt ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0579 0668 LUsbFilt - detected UnsignedFile.Multi.Generic (1)
11:56:52.0610 0668 [ DED333DBDBBCC3555A6E6244522E2F1A ] LVPr2M64 C:\Windows\system32\DRIVERS\LVPr2M64.sys
11:56:52.0610 0668 LVPr2M64 ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0610 0668 LVPr2M64 - detected UnsignedFile.Multi.Generic (1)
11:56:52.0610 0668 [ DED333DBDBBCC3555A6E6244522E2F1A ] LVPr2Mon C:\Windows\system32\DRIVERS\LVPr2M64.sys
11:56:52.0610 0668 LVPr2Mon ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0610 0668 LVPr2Mon - detected UnsignedFile.Multi.Generic (1)
11:56:52.0673 0668 [ A35679E56E78091E1042A2D7ADBF2958 ] LVPrcS64 C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
11:56:52.0673 0668 LVPrcS64 ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0673 0668 LVPrcS64 - detected UnsignedFile.Multi.Generic (1)
11:56:52.0704 0668 [ 0C85B2B6FB74B36A251792D45E0EF860 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys
11:56:52.0704 0668 LVRS64 ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0704 0668 LVRS64 - detected UnsignedFile.Multi.Generic (1)
11:56:52.0813 0668 [ FF3A488924B0032B1A9CA6948C1FA9E8 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys
11:56:52.0844 0668 LVUVC64 ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0844 0668 LVUVC64 - detected UnsignedFile.Multi.Generic (1)
11:56:52.0860 0668 [ 0BB97D43299910CBFBA59C461B99B910 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
11:56:52.0860 0668 MBAMProtector ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0860 0668 MBAMProtector - detected UnsignedFile.Multi.Generic (1)
11:56:52.0907 0668 [ 65085456FD9A74D7F1A999520C299ECB ] MBAMScheduler C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
11:56:52.0922 0668 MBAMScheduler ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0922 0668 MBAMScheduler - detected UnsignedFile.Multi.Generic (1)
11:56:52.0938 0668 [ E0D7732F2D2E24B2DB3F67B6750295B8 ] MBAMService C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
11:56:52.0938 0668 MBAMService ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0938 0668 MBAMService - detected UnsignedFile.Multi.Generic (1)
11:56:52.0953 0668 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
11:56:52.0953 0668 megasas ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0953 0668 megasas - detected UnsignedFile.Multi.Generic (1)
11:56:52.0969 0668 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
11:56:52.0969 0668 MegaSR ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0969 0668 MegaSR - detected UnsignedFile.Multi.Generic (1)
11:56:52.0985 0668 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\Windows\system32\mmcss.dll
11:56:52.0985 0668 MMCSS ( UnsignedFile.Multi.Generic ) - warning
11:56:52.0985 0668 MMCSS - detected UnsignedFile.Multi.Generic (1)
11:56:53.0000 0668 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\Windows\system32\drivers\modem.sys
11:56:53.0000 0668 Modem ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0000 0668 Modem - detected UnsignedFile.Multi.Generic (1)
11:56:53.0016 0668 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\Windows\system32\DRIVERS\monitor.sys
11:56:53.0016 0668 monitor ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0016 0668 monitor - detected UnsignedFile.Multi.Generic (1)
11:56:53.0031 0668 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
11:56:53.0031 0668 mouclass ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0031 0668 mouclass - detected UnsignedFile.Multi.Generic (1)
11:56:53.0047 0668 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
11:56:53.0047 0668 mouhid ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0047 0668 mouhid - detected UnsignedFile.Multi.Generic (1)
11:56:53.0078 0668 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
11:56:53.0078 0668 mountmgr ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0078 0668 mountmgr - detected UnsignedFile.Multi.Generic (1)
11:56:53.0109 0668 [ 825BF0E46B4470A463AEB641480C5FCA ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
11:56:53.0109 0668 MozillaMaintenance ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0109 0668 MozillaMaintenance - detected UnsignedFile.Multi.Generic (1)
11:56:53.0141 0668 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\Windows\system32\drivers\mpio.sys
11:56:53.0141 0668 mpio ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0141 0668 mpio - detected UnsignedFile.Multi.Generic (1)
11:56:53.0156 0668 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
11:56:53.0156 0668 mpsdrv ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0156 0668 mpsdrv - detected UnsignedFile.Multi.Generic (1)
11:56:53.0203 0668 [ 54FFC9C8898113ACE189D4AA7199D2C1 ] MpsSvc C:\Windows\system32\mpssvc.dll
11:56:53.0203 0668 MpsSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0203 0668 MpsSvc - detected UnsignedFile.Multi.Generic (1)
11:56:53.0234 0668 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
11:56:53.0234 0668 MRxDAV ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0234 0668 MRxDAV - detected UnsignedFile.Multi.Generic (1)
11:56:53.0281 0668 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
11:56:53.0281 0668 mrxsmb ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0281 0668 mrxsmb - detected UnsignedFile.Multi.Generic (1)
11:56:53.0297 0668 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
11:56:53.0297 0668 mrxsmb10 ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0297 0668 mrxsmb10 - detected UnsignedFile.Multi.Generic (1)
11:56:53.0328 0668 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
11:56:53.0328 0668 mrxsmb20 ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0328 0668 mrxsmb20 - detected UnsignedFile.Multi.Generic (1)
11:56:53.0359 0668 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\Windows\system32\drivers\msahci.sys
11:56:53.0359 0668 msahci ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0359 0668 msahci - detected UnsignedFile.Multi.Generic (1)
11:56:53.0375 0668 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\Windows\system32\drivers\msdsm.sys
11:56:53.0375 0668 msdsm ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0375 0668 msdsm - detected UnsignedFile.Multi.Generic (1)
11:56:53.0390 0668 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\Windows\System32\msdtc.exe
11:56:53.0390 0668 MSDTC ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0390 0668 MSDTC - detected UnsignedFile.Multi.Generic (1)
11:56:53.0406 0668 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\Windows\system32\drivers\Msfs.sys
11:56:53.0406 0668 Msfs ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0406 0668 Msfs - detected UnsignedFile.Multi.Generic (1)
11:56:53.0421 0668 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
11:56:53.0421 0668 mshidkmdf ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0421 0668 mshidkmdf - detected UnsignedFile.Multi.Generic (1)
11:56:53.0453 0668 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
11:56:53.0453 0668 msisadrv ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0453 0668 msisadrv - detected UnsignedFile.Multi.Generic (1)
11:56:53.0484 0668 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\Windows\system32\iscsiexe.dll
11:56:53.0484 0668 MSiSCSI ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0484 0668 MSiSCSI - detected UnsignedFile.Multi.Generic (1)
11:56:53.0484 0668 msiserver - ok
11:56:53.0499 0668 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
11:56:53.0499 0668 MSKSSRV ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0499 0668 MSKSSRV - detected UnsignedFile.Multi.Generic (1)
11:56:53.0499 0668 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
11:56:53.0499 0668 MSPCLOCK ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0499 0668 MSPCLOCK - detected UnsignedFile.Multi.Generic (1)
11:56:53.0515 0668 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
11:56:53.0515 0668 MSPQM ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0515 0668 MSPQM - detected UnsignedFile.Multi.Generic (1)
11:56:53.0546 0668 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
11:56:53.0546 0668 MsRPC ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0546 0668 MsRPC - detected UnsignedFile.Multi.Generic (1)
11:56:53.0577 0668 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
11:56:53.0577 0668 mssmbios ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0577 0668 mssmbios - detected UnsignedFile.Multi.Generic (1)
11:56:53.0577 0668 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
11:56:53.0577 0668 MSTEE ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0577 0668 MSTEE - detected UnsignedFile.Multi.Generic (1)
11:56:53.0593 0668 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
11:56:53.0593 0668 MTConfig ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0593 0668 MTConfig - detected UnsignedFile.Multi.Generic (1)
11:56:53.0609 0668 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\Windows\system32\Drivers\mup.sys
11:56:53.0609 0668 Mup ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0609 0668 Mup - detected UnsignedFile.Multi.Generic (1)
11:56:53.0655 0668 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\Windows\system32\qagentRT.dll
11:56:53.0655 0668 napagent ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0655 0668 napagent - detected UnsignedFile.Multi.Generic (1)
11:56:53.0671 0668 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
11:56:53.0671 0668 NativeWifiP ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0671 0668 NativeWifiP - detected UnsignedFile.Multi.Generic (1)
11:56:53.0718 0668 [ 760E38053BF56E501D562B70AD796B88 ] NDIS C:\Windows\system32\drivers\ndis.sys
11:56:53.0718 0668 NDIS ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0718 0668 NDIS - detected UnsignedFile.Multi.Generic (1)
11:56:53.0749 0668 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
11:56:53.0749 0668 NdisCap ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0749 0668 NdisCap - detected UnsignedFile.Multi.Generic (1)
11:56:53.0765 0668 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
11:56:53.0765 0668 NdisTapi ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0765 0668 NdisTapi - detected UnsignedFile.Multi.Generic (1)
11:56:53.0780 0668 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
11:56:53.0780 0668 Ndisuio ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0780 0668 Ndisuio - detected UnsignedFile.Multi.Generic (1)
11:56:53.0811 0668 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
11:56:53.0811 0668 NdisWan ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0811 0668 NdisWan - detected UnsignedFile.Multi.Generic (1)
11:56:53.0827 0668 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
11:56:53.0827 0668 NDProxy ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0827 0668 NDProxy - detected UnsignedFile.Multi.Generic (1)
11:56:53.0843 0668 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
11:56:53.0858 0668 NetBIOS ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0858 0668 NetBIOS - detected UnsignedFile.Multi.Generic (1)
11:56:53.0889 0668 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
11:56:53.0889 0668 NetBT ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0889 0668 NetBT - detected UnsignedFile.Multi.Generic (1)
11:56:53.0905 0668 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\Windows\system32\lsass.exe
11:56:53.0905 0668 Netlogon ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0905 0668 Netlogon - detected UnsignedFile.Multi.Generic (1)
11:56:53.0967 0668 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\Windows\System32\netman.dll
11:56:53.0967 0668 Netman ( UnsignedFile.Multi.Generic ) - warning
11:56:53.0967 0668 Netman - detected UnsignedFile.Multi.Generic (1)
11:56:54.0030 0668 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:54.0030 0668 NetMsmqActivator ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0030 0668 NetMsmqActivator - detected UnsignedFile.Multi.Generic (1)
11:56:54.0030 0668 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:54.0030 0668 NetPipeActivator ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0030 0668 NetPipeActivator - detected UnsignedFile.Multi.Generic (1)
11:56:54.0045 0668 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\Windows\System32\netprofm.dll
11:56:54.0045 0668 netprofm ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0045 0668 netprofm - detected UnsignedFile.Multi.Generic (1)
11:56:54.0061 0668 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:54.0061 0668 NetTcpActivator ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0061 0668 NetTcpActivator - detected UnsignedFile.Multi.Generic (1)
11:56:54.0061 0668 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
11:56:54.0061 0668 NetTcpPortSharing ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0061 0668 NetTcpPortSharing - detected UnsignedFile.Multi.Generic (1)
11:56:54.0077 0668 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
11:56:54.0077 0668 nfrd960 ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0077 0668 nfrd960 - detected UnsignedFile.Multi.Generic (1)
11:56:54.0108 0668 [ 8AD77806D336673F270DB31645267293 ] NlaSvc C:\Windows\System32\nlasvc.dll
11:56:54.0108 0668 NlaSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0108 0668 NlaSvc - detected UnsignedFile.Multi.Generic (1)
11:56:54.0139 0668 [ 4903177FC90E77ABEB19021451E9475E ] nmwcd C:\Windows\system32\drivers\ccdcmbx64.sys
11:56:54.0139 0668 nmwcd ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0139 0668 nmwcd - detected UnsignedFile.Multi.Generic (1)
11:56:54.0170 0668 [ E6844A4C97E5409BBE24BB4ED000320D ] nmwcdc C:\Windows\system32\drivers\ccdcmbox64.sys
11:56:54.0170 0668 nmwcdc ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0170 0668 nmwcdc - detected UnsignedFile.Multi.Generic (1)
11:56:54.0186 0668 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\Windows\system32\drivers\Npfs.sys
11:56:54.0186 0668 Npfs ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0186 0668 Npfs - detected UnsignedFile.Multi.Generic (1)
11:56:54.0201 0668 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\Windows\system32\nsisvc.dll
11:56:54.0201 0668 nsi ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0201 0668 nsi - detected UnsignedFile.Multi.Generic (1)
11:56:54.0201 0668 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
11:56:54.0201 0668 nsiproxy ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0201 0668 nsiproxy - detected UnsignedFile.Multi.Generic (1)
11:56:54.0248 0668 [ B98F8C6E31CD07B2E6F71F7F648E38C0 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
11:56:54.0264 0668 Ntfs ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0264 0668 Ntfs - detected UnsignedFile.Multi.Generic (1)
11:56:54.0279 0668 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\Windows\system32\drivers\Null.sys
11:56:54.0279 0668 Null ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0279 0668 Null - detected UnsignedFile.Multi.Generic (1)
11:56:54.0373 0668 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\Windows\system32\drivers\nvraid.sys
11:56:54.0373 0668 nvraid ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0373 0668 nvraid - detected UnsignedFile.Multi.Generic (1)
11:56:54.0404 0668 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\Windows\system32\drivers\nvstor.sys
11:56:54.0404 0668 nvstor ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0404 0668 nvstor - detected UnsignedFile.Multi.Generic (1)
11:56:54.0451 0668 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
11:56:54.0451 0668 nv_agp ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0451 0668 nv_agp - detected UnsignedFile.Multi.Generic (1)
11:56:54.0498 0668 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
11:56:54.0498 0668 ohci1394 ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0498 0668 ohci1394 - detected UnsignedFile.Multi.Generic (1)
11:56:54.0591 0668 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:56:54.0591 0668 ose64 ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0591 0668 ose64 - detected UnsignedFile.Multi.Generic (1)
11:56:54.0888 0668 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
11:56:54.0919 0668 osppsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0919 0668 osppsvc - detected UnsignedFile.Multi.Generic (1)
11:56:54.0950 0668 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
11:56:54.0966 0668 p2pimsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0966 0668 p2pimsvc - detected UnsignedFile.Multi.Generic (1)
11:56:54.0981 0668 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\Windows\system32\p2psvc.dll
11:56:54.0981 0668 p2psvc ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0981 0668 p2psvc - detected UnsignedFile.Multi.Generic (1)
11:56:54.0997 0668 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\Windows\system32\DRIVERS\parport.sys
11:56:54.0997 0668 Parport ( UnsignedFile.Multi.Generic ) - warning
11:56:54.0997 0668 Parport - detected UnsignedFile.Multi.Generic (1)
11:56:55.0028 0668 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\Windows\system32\drivers\partmgr.sys
11:56:55.0028 0668 partmgr ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0028 0668 partmgr - detected UnsignedFile.Multi.Generic (1)
11:56:55.0028 0668 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\Windows\System32\pcasvc.dll
11:56:55.0028 0668 PcaSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0028 0668 PcaSvc - detected UnsignedFile.Multi.Generic (1)
11:56:55.0059 0668 [ 3FDE033DFB0D07F8B7D5C9A3044AA121 ] pccsmcfd C:\Windows\system32\DRIVERS\pccsmcfdx64.sys
11:56:55.0059 0668 pccsmcfd ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0059 0668 pccsmcfd - detected UnsignedFile.Multi.Generic (1)
11:56:55.0091 0668 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\Windows\system32\drivers\pci.sys
11:56:55.0091 0668 pci ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0091 0668 pci - detected UnsignedFile.Multi.Generic (1)
11:56:55.0106 0668 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\Windows\system32\drivers\pciide.sys
11:56:55.0106 0668 pciide ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0106 0668 pciide - detected UnsignedFile.Multi.Generic (1)
11:56:55.0122 0668 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
11:56:55.0122 0668 pcmcia ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0122 0668 pcmcia - detected UnsignedFile.Multi.Generic (1)
11:56:55.0122 0668 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\Windows\system32\drivers\pcw.sys
11:56:55.0137 0668 pcw ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0137 0668 pcw - detected UnsignedFile.Multi.Generic (1)
11:56:55.0153 0668 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\Windows\system32\drivers\peauth.sys
11:56:55.0153 0668 PEAUTH ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0153 0668 PEAUTH - detected UnsignedFile.Multi.Generic (1)
11:56:55.0184 0668 [ B9B0A4299DD2D76A4243F75FD54DC680 ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
11:56:55.0200 0668 PeerDistSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0200 0668 PeerDistSvc - detected UnsignedFile.Multi.Generic (1)
11:56:55.0247 0668 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\Windows\SysWow64\perfhost.exe
11:56:55.0262 0668 PerfHost ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0262 0668 PerfHost - detected UnsignedFile.Multi.Generic (1)
11:56:55.0293 0668 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\Windows\system32\pla.dll
11:56:55.0309 0668 pla ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0309 0668 pla - detected UnsignedFile.Multi.Generic (1)
11:56:55.0340 0668 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
11:56:55.0340 0668 PlugPlay ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0340 0668 PlugPlay - detected UnsignedFile.Multi.Generic (1)
11:56:55.0356 0668 PnkBstrA - ok
11:56:55.0356 0668 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
11:56:55.0371 0668 PNRPAutoReg ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0371 0668 PNRPAutoReg - detected UnsignedFile.Multi.Generic (1)
11:56:55.0387 0668 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
11:56:55.0387 0668 PNRPsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0387 0668 PNRPsvc - detected UnsignedFile.Multi.Generic (1)
11:56:55.0418 0668 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
11:56:55.0418 0668 PolicyAgent ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0418 0668 PolicyAgent - detected UnsignedFile.Multi.Generic (1)
11:56:55.0434 0668 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\Windows\system32\umpo.dll
11:56:55.0449 0668 Power ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0449 0668 Power - detected UnsignedFile.Multi.Generic (1)
11:56:55.0465 0668 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
11:56:55.0465 0668 PptpMiniport ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0465 0668 PptpMiniport - detected UnsignedFile.Multi.Generic (1)
11:56:55.0481 0668 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\Windows\system32\DRIVERS\processr.sys
11:56:55.0481 0668 Processor ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0481 0668 Processor - detected UnsignedFile.Multi.Generic (1)
11:56:55.0512 0668 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\Windows\system32\profsvc.dll
11:56:55.0512 0668 ProfSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0512 0668 ProfSvc - detected UnsignedFile.Multi.Generic (1)
11:56:55.0512 0668 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\Windows\system32\lsass.exe
11:56:55.0512 0668 ProtectedStorage ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0512 0668 ProtectedStorage - detected UnsignedFile.Multi.Generic (1)
11:56:55.0543 0668 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\Windows\system32\DRIVERS\pacer.sys
11:56:55.0543 0668 Psched ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0543 0668 Psched - detected UnsignedFile.Multi.Generic (1)
11:56:55.0574 0668 [ 0B6DEA0A1662CAB8F2BF339DC0752EF4 ] PSI_SVC_2 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
11:56:55.0574 0668 PSI_SVC_2 ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0574 0668 PSI_SVC_2 - detected UnsignedFile.Multi.Generic (1)
11:56:55.0605 0668 [ 225D3660F926FE761BC8CE10C512AA02 ] PTSimBus C:\Windows\system32\DRIVERS\PTSimBus.sys
11:56:55.0605 0668 PTSimBus ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0605 0668 PTSimBus - detected UnsignedFile.Multi.Generic (1)
11:56:55.0621 0668 [ BD2194786ABAF4860F41118C0C103E7B ] PTSimHid C:\Windows\system32\DRIVERS\PTSimHid.sys
11:56:55.0621 0668 PTSimHid ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0621 0668 PTSimHid - detected UnsignedFile.Multi.Generic (1)
11:56:55.0668 0668 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
11:56:55.0668 0668 ql2300 ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0668 0668 ql2300 - detected UnsignedFile.Multi.Generic (1)
11:56:55.0683 0668 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
11:56:55.0699 0668 ql40xx ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0699 0668 ql40xx - detected UnsignedFile.Multi.Generic (1)
11:56:55.0715 0668 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\Windows\system32\qwave.dll
11:56:55.0715 0668 QWAVE ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0715 0668 QWAVE - detected UnsignedFile.Multi.Generic (1)
11:56:55.0730 0668 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
11:56:55.0730 0668 QWAVEdrv ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0730 0668 QWAVEdrv - detected UnsignedFile.Multi.Generic (1)
11:56:55.0730 0668 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
11:56:55.0730 0668 RasAcd ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0730 0668 RasAcd - detected UnsignedFile.Multi.Generic (1)
11:56:55.0746 0668 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
11:56:55.0746 0668 RasAgileVpn ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0746 0668 RasAgileVpn - detected UnsignedFile.Multi.Generic (1)
11:56:55.0761 0668 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\Windows\System32\rasauto.dll
11:56:55.0761 0668 RasAuto ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0761 0668 RasAuto - detected UnsignedFile.Multi.Generic (1)
11:56:55.0793 0668 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
11:56:55.0793 0668 Rasl2tp ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0793 0668 Rasl2tp - detected UnsignedFile.Multi.Generic (1)
11:56:55.0824 0668 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\Windows\System32\rasmans.dll
11:56:55.0824 0668 RasMan ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0824 0668 RasMan - detected UnsignedFile.Multi.Generic (1)
11:56:55.0839 0668 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
11:56:55.0839 0668 RasPppoe ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0839 0668 RasPppoe - detected UnsignedFile.Multi.Generic (1)
11:56:55.0855 0668 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
11:56:55.0855 0668 RasSstp ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0855 0668 RasSstp - detected UnsignedFile.Multi.Generic (1)
11:56:55.0886 0668 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
11:56:55.0886 0668 rdbss ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0886 0668 rdbss - detected UnsignedFile.Multi.Generic (1)
11:56:55.0886 0668 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
11:56:55.0902 0668 rdpbus ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0902 0668 rdpbus - detected UnsignedFile.Multi.Generic (1)
11:56:55.0902 0668 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
11:56:55.0902 0668 RDPCDD ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0902 0668 RDPCDD - detected UnsignedFile.Multi.Generic (1)
11:56:55.0933 0668 [ 1B6163C503398B23FF8B939C67747683 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
11:56:55.0933 0668 RDPDR ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0933 0668 RDPDR - detected UnsignedFile.Multi.Generic (1)
11:56:55.0949 0668 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
11:56:55.0949 0668 RDPENCDD ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0949 0668 RDPENCDD - detected UnsignedFile.Multi.Generic (1)
11:56:55.0949 0668 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
11:56:55.0949 0668 RDPREFMP ( UnsignedFile.Multi.Generic ) - warning
11:56:55.0949 0668 RDPREFMP - detected UnsignedFile.Multi.Generic (1)
11:56:56.0011 0668 [ 313F68E1A3E6345A4F47A36B07062F34 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
11:56:56.0011 0668 RdpVideoMiniport ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0011 0668 RdpVideoMiniport - detected UnsignedFile.Multi.Generic (1)
11:56:56.0042 0668 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
11:56:56.0042 0668 RDPWD ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0042 0668 RDPWD - detected UnsignedFile.Multi.Generic (1)
11:56:56.0073 0668 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
11:56:56.0089 0668 rdyboost ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0089 0668 rdyboost - detected UnsignedFile.Multi.Generic (1)
11:56:56.0120 0668 [ EA569D48B2E755AF6D96F03F3335D98A ] Realtek11nSU C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
11:56:56.0120 0668 Realtek11nSU ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0120 0668 Realtek11nSU - detected UnsignedFile.Multi.Generic (1)
11:56:56.0151 0668 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\Windows\System32\mprdim.dll
11:56:56.0151 0668 RemoteAccess ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0151 0668 RemoteAccess - detected UnsignedFile.Multi.Generic (1)
11:56:56.0167 0668 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\Windows\system32\regsvc.dll
11:56:56.0167 0668 RemoteRegistry ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0167 0668 RemoteRegistry - detected UnsignedFile.Multi.Generic (1)
11:56:56.0167 0668 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
11:56:56.0183 0668 RpcEptMapper ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0183 0668 RpcEptMapper - detected UnsignedFile.Multi.Generic (1)
11:56:56.0183 0668 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\Windows\system32\locator.exe
11:56:56.0183 0668 RpcLocator ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0183 0668 RpcLocator - detected UnsignedFile.Multi.Generic (1)
11:56:56.0214 0668 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\Windows\system32\rpcss.dll
11:56:56.0229 0668 RpcSs ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0229 0668 RpcSs - detected UnsignedFile.Multi.Generic (1)
11:56:56.0229 0668 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
11:56:56.0229 0668 rspndr ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0229 0668 rspndr - detected UnsignedFile.Multi.Generic (1)
11:56:56.0261 0668 [ EE082E06A82FF630351D1E0EBBD3D8D0 ] RTL8167 C:\Windows\system32\DRIVERS\Rt64win7.sys
11:56:56.0276 0668 RTL8167 ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0276 0668 RTL8167 - detected UnsignedFile.Multi.Generic (1)
11:56:56.0307 0668 [ 5EDFCEE5682237607082880338415AA6 ] RTL8192su C:\Windows\system32\DRIVERS\RTL8192su.sys
11:56:56.0307 0668 RTL8192su ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0307 0668 RTL8192su - detected UnsignedFile.Multi.Generic (1)
11:56:56.0339 0668 [ E60C0A09F997826C7627B244195AB581 ] s3cap C:\Windows\system32\drivers\vms3cap.sys
11:56:56.0339 0668 s3cap ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0339 0668 s3cap - detected UnsignedFile.Multi.Generic (1)
11:56:56.0354 0668 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\Windows\system32\lsass.exe
11:56:56.0354 0668 SamSs ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0354 0668 SamSs - detected UnsignedFile.Multi.Generic (1)
11:56:56.0385 0668 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
11:56:56.0385 0668 sbp2port ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0385 0668 sbp2port - detected UnsignedFile.Multi.Generic (1)
11:56:56.0385 0668 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\Windows\System32\SCardSvr.dll
11:56:56.0401 0668 SCardSvr ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0401 0668 SCardSvr - detected UnsignedFile.Multi.Generic (1)
11:56:56.0432 0668 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
11:56:56.0432 0668 scfilter ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0432 0668 scfilter - detected UnsignedFile.Multi.Generic (1)
11:56:56.0463 0668 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\Windows\system32\schedsvc.dll
11:56:56.0479 0668 Schedule ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0479 0668 Schedule - detected UnsignedFile.Multi.Generic (1)
11:56:56.0495 0668 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\Windows\System32\certprop.dll
11:56:56.0495 0668 SCPolicySvc ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0495 0668 SCPolicySvc - detected UnsignedFile.Multi.Generic (1)
11:56:56.0510 0668 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\Windows\System32\SDRSVC.dll
11:56:56.0510 0668 SDRSVC ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0510 0668 SDRSVC - detected UnsignedFile.Multi.Generic (1)
11:56:56.0526 0668 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
11:56:56.0526 0668 secdrv ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0526 0668 secdrv - detected UnsignedFile.Multi.Generic (1)
11:56:56.0557 0668 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\Windows\system32\seclogon.dll
11:56:56.0557 0668 seclogon ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0557 0668 seclogon - detected UnsignedFile.Multi.Generic (1)
11:56:56.0557 0668 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\Windows\system32\sens.dll
11:56:56.0557 0668 SENS ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0557 0668 SENS - detected UnsignedFile.Multi.Generic (1)
11:56:56.0573 0668 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\Windows\system32\sensrsvc.dll
11:56:56.0573 0668 SensrSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0573 0668 SensrSvc - detected UnsignedFile.Multi.Generic (1)
11:56:56.0573 0668 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
11:56:56.0588 0668 Serenum ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0588 0668 Serenum - detected UnsignedFile.Multi.Generic (1)
11:56:56.0588 0668 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\Windows\system32\DRIVERS\serial.sys
11:56:56.0588 0668 Serial ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0588 0668 Serial - detected UnsignedFile.Multi.Generic (1)
11:56:56.0619 0668 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
11:56:56.0619 0668 sermouse ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0619 0668 sermouse - detected UnsignedFile.Multi.Generic (1)
11:56:56.0666 0668 [ 289E853881E688286AD24299FCC485D8 ] ServiceLayer C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
11:56:56.0682 0668 ServiceLayer ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0682 0668 ServiceLayer - detected UnsignedFile.Multi.Generic (1)
11:56:56.0713 0668 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\Windows\system32\sessenv.dll
11:56:56.0713 0668 SessionEnv ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0713 0668 SessionEnv - detected UnsignedFile.Multi.Generic (1)
11:56:56.0729 0668 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
11:56:56.0729 0668 sffdisk ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0729 0668 sffdisk - detected UnsignedFile.Multi.Generic (1)
11:56:56.0744 0668 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
11:56:56.0744 0668 sffp_mmc ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0744 0668 sffp_mmc - detected UnsignedFile.Multi.Generic (1)
11:56:56.0760 0668 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
11:56:56.0760 0668 sffp_sd ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0760 0668 sffp_sd - detected UnsignedFile.Multi.Generic (1)
11:56:56.0775 0668 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
11:56:56.0775 0668 sfloppy ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0775 0668 sfloppy - detected UnsignedFile.Multi.Generic (1)
11:56:56.0791 0668 [ B95F6501A2F8B2E78C697FEC401970CE ] SharedAccess C:\Windows\System32\ipnathlp.dll
11:56:56.0791 0668 SharedAccess ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0791 0668 SharedAccess - detected UnsignedFile.Multi.Generic (1)
11:56:56.0838 0668 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\Windows\System32\shsvcs.dll
11:56:56.0838 0668 ShellHWDetection ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0838 0668 ShellHWDetection - detected UnsignedFile.Multi.Generic (1)
11:56:56.0853 0668 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
11:56:56.0853 0668 SiSRaid2 ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0853 0668 SiSRaid2 - detected UnsignedFile.Multi.Generic (1)
11:56:56.0869 0668 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
11:56:56.0869 0668 SiSRaid4 ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0869 0668 SiSRaid4 - detected UnsignedFile.Multi.Generic (1)
11:56:56.0916 0668 [ CA355B308AA537C6B9D67CD3A5485AF9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
11:56:56.0916 0668 SkypeUpdate ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0916 0668 SkypeUpdate - detected UnsignedFile.Multi.Generic (1)
11:56:56.0963 0668 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\Windows\system32\DRIVERS\smb.sys
11:56:56.0963 0668 Smb ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0963 0668 Smb - detected UnsignedFile.Multi.Generic (1)
11:56:56.0978 0668 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\Windows\System32\snmptrap.exe
11:56:56.0978 0668 SNMPTRAP ( UnsignedFile.Multi.Generic ) - warning
11:56:56.0978 0668 SNMPTRAP - detected UnsignedFile.Multi.Generic (1)
11:56:57.0009 0668 [ F9369327409492097B0BB7CE86BD29DE ] Soluto C:\Windows\system32\DRIVERS\Soluto.sys
11:56:57.0009 0668 Soluto ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0009 0668 Soluto - detected UnsignedFile.Multi.Generic (1)
11:56:57.0056 0668 [ A3A7A1A356245534E3EA87368BA085E5 ] SolutoLauncherService C:\Program Files\Soluto\SolutoLauncherService.exe
11:56:57.0056 0668 SolutoLauncherService ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0056 0668 SolutoLauncherService - detected UnsignedFile.Multi.Generic (1)
11:56:57.0103 0668 [ 43E926974ADB9F14A29FD362ADB57421 ] SolutoRemoteService C:\Program Files\Soluto\SolutoRemoteService.exe
11:56:57.0119 0668 SolutoRemoteService ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0119 0668 SolutoRemoteService - detected UnsignedFile.Multi.Generic (1)
11:56:57.0150 0668 [ A169CE9EF099E0679CE89490998C2069 ] SolutoService C:\Program Files\Soluto\SolutoService.exe
11:56:57.0165 0668 SolutoService ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0165 0668 SolutoService - detected UnsignedFile.Multi.Generic (1)
11:56:57.0197 0668 [ 5F9785E7535F8F602CB294A54962C9E7 ] speedfan C:\Windows\syswow64\speedfan.sys
11:56:57.0197 0668 speedfan ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0197 0668 speedfan - detected UnsignedFile.Multi.Generic (1)
11:56:57.0197 0668 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\Windows\system32\drivers\spldr.sys
11:56:57.0197 0668 spldr ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0197 0668 spldr - detected UnsignedFile.Multi.Generic (1)
11:56:57.0243 0668 [ 85DAA09A98C9286D4EA2BA8D0E644377 ] Spooler C:\Windows\System32\spoolsv.exe
11:56:57.0243 0668 Spooler ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0243 0668 Spooler - detected UnsignedFile.Multi.Generic (1)
11:56:57.0431 0668 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\Windows\system32\sppsvc.exe
11:56:57.0462 0668 sppsvc ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0462 0668 sppsvc - detected UnsignedFile.Multi.Generic (1)
11:56:57.0477 0668 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\Windows\system32\sppuinotify.dll
11:56:57.0493 0668 sppuinotify ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0493 0668 sppuinotify - detected UnsignedFile.Multi.Generic (1)
11:56:57.0524 0668 [ 53185C3EF3DECF428B3149AEBD4F6C86 ] sptd C:\Windows\system32\Drivers\sptd.sys
11:56:57.0540 0668 sptd ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0540 0668 sptd - detected UnsignedFile.Multi.Generic (1)
11:56:57.0571 0668 [ D8B882C520FC83547E22014FF5EC66D7 ] Spyder3 C:\Windows\system32\DRIVERS\Spyder3.sys
11:56:57.0571 0668 Spyder3 ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0571 0668 Spyder3 - detected UnsignedFile.Multi.Generic (1)
11:56:57.0602 0668 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\Windows\system32\DRIVERS\srv.sys
11:56:57.0602 0668 srv ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0602 0668 srv - detected UnsignedFile.Multi.Generic (1)
11:56:57.0649 0668 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
11:56:57.0649 0668 srv2 ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0649 0668 srv2 - detected UnsignedFile.Multi.Generic (1)
11:56:57.0665 0668 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
11:56:57.0665 0668 srvnet ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0665 0668 srvnet - detected UnsignedFile.Multi.Generic (1)
11:56:57.0665 0668 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
11:56:57.0680 0668 SSDPSRV ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0680 0668 SSDPSRV - detected UnsignedFile.Multi.Generic (1)
11:56:57.0680 0668 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\Windows\system32\sstpsvc.dll
11:56:57.0696 0668 SstpSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0696 0668 SstpSvc - detected UnsignedFile.Multi.Generic (1)
11:56:57.0711 0668 Steam Client Service - ok
11:56:57.0727 0668 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
11:56:57.0727 0668 stexstor ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0727 0668 stexstor - detected UnsignedFile.Multi.Generic (1)
11:56:57.0758 0668 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\Windows\System32\wiaservc.dll
11:56:57.0774 0668 stisvc ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0774 0668 stisvc - detected UnsignedFile.Multi.Generic (1)
11:56:57.0789 0668 [ 7785DC213270D2FC066538DAF94087E7 ] storflt C:\Windows\system32\drivers\vmstorfl.sys
11:56:57.0789 0668 storflt ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0789 0668 storflt - detected UnsignedFile.Multi.Generic (1)
11:56:57.0821 0668 [ D34E4943D5AC096C8EDEEBFD80D76E23 ] storvsc C:\Windows\system32\drivers\storvsc.sys
11:56:57.0821 0668 storvsc ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0821 0668 storvsc - detected UnsignedFile.Multi.Generic (1)
11:56:57.0836 0668 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\Windows\system32\drivers\swenum.sys
11:56:57.0852 0668 swenum ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0852 0668 swenum - detected UnsignedFile.Multi.Generic (1)
11:56:57.0945 0668 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
11:56:57.0945 0668 SwitchBoard ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0945 0668 SwitchBoard - detected UnsignedFile.Multi.Generic (1)
11:56:57.0961 0668 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\Windows\System32\swprv.dll
11:56:57.0961 0668 swprv ( UnsignedFile.Multi.Generic ) - warning
11:56:57.0961 0668 swprv - detected UnsignedFile.Multi.Generic (1)
11:56:57.0977 0668 Synth3dVsc - ok
11:56:58.0039 0668 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\Windows\system32\sysmain.dll
11:56:58.0055 0668 SysMain ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0055 0668 SysMain - detected UnsignedFile.Multi.Generic (1)
11:56:58.0055 0668 Tablet2k - ok
11:56:58.0101 0668 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\Windows\System32\TabSvc.dll
11:56:58.0101 0668 TabletInputService ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0101 0668 TabletInputService - detected UnsignedFile.Multi.Generic (1)
11:56:58.0148 0668 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\Windows\System32\tapisrv.dll
11:56:58.0148 0668 TapiSrv ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0148 0668 TapiSrv - detected UnsignedFile.Multi.Generic (1)
11:56:58.0164 0668 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\Windows\System32\tbssvc.dll
11:56:58.0164 0668 TBS ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0164 0668 TBS - detected UnsignedFile.Multi.Generic (1)
11:56:58.0179 0668 [ 530A7F0966493DD437E4342F12CCD63B ] TClass2k C:\Windows\system32\DRIVERS\TClass2k.sys
11:56:58.0179 0668 TClass2k ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0179 0668 TClass2k - detected UnsignedFile.Multi.Generic (1)
11:56:58.0242 0668 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] Tcpip C:\Windows\system32\drivers\tcpip.sys
11:56:58.0257 0668 Tcpip ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0257 0668 Tcpip - detected UnsignedFile.Multi.Generic (1)
11:56:58.0304 0668 [ 9849EA3843A2ADBDD1497E97A85D8CAE ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
11:56:58.0320 0668 TCPIP6 ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0320 0668 TCPIP6 - detected UnsignedFile.Multi.Generic (1)
11:56:58.0351 0668 [ 1B16D0BD9841794A6E0CDE0CEF744ABC ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
11:56:58.0351 0668 tcpipreg ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0351 0668 tcpipreg - detected UnsignedFile.Multi.Generic (1)
11:56:58.0367 0668 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
11:56:58.0367 0668 TDPIPE ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0367 0668 TDPIPE - detected UnsignedFile.Multi.Generic (1)
11:56:58.0367 0668 [ E4245BDA3190A582D55ED09E137401A9 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
11:56:58.0367 0668 TDTCP ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0367 0668 TDTCP - detected UnsignedFile.Multi.Generic (1)
11:56:58.0398 0668 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
11:56:58.0398 0668 tdx ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0398 0668 tdx - detected UnsignedFile.Multi.Generic (1)
11:56:58.0398 0668 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\Windows\system32\drivers\termdd.sys
11:56:58.0413 0668 TermDD ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0413 0668 TermDD - detected UnsignedFile.Multi.Generic (1)
11:56:58.0445 0668 [ 2E648163254233755035B46DD7B89123 ] TermService C:\Windows\System32\termsrv.dll
11:56:58.0445 0668 TermService ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0445 0668 TermService - detected UnsignedFile.Multi.Generic (1)
11:56:58.0460 0668 [ F0344071948D1A1FA732231785A0664C ] Themes C:\Windows\system32\themeservice.dll
11:56:58.0460 0668 Themes ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0460 0668 Themes - detected UnsignedFile.Multi.Generic (1)
11:56:58.0476 0668 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\Windows\system32\mmcss.dll
11:56:58.0476 0668 THREADORDER ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0476 0668 THREADORDER - detected UnsignedFile.Multi.Generic (1)
11:56:58.0491 0668 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\Windows\System32\trkwks.dll
11:56:58.0491 0668 TrkWks ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0491 0668 TrkWks - detected UnsignedFile.Multi.Generic (1)
11:56:58.0538 0668 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
11:56:58.0538 0668 TrustedInstaller ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0538 0668 TrustedInstaller - detected UnsignedFile.Multi.Generic (1)
11:56:58.0569 0668 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
11:56:58.0569 0668 tssecsrv ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0569 0668 tssecsrv - detected UnsignedFile.Multi.Generic (1)
11:56:58.0601 0668 [ 17C6B51CBCCDED95B3CC14E22791F85E ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
11:56:58.0601 0668 TsUsbFlt ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0601 0668 TsUsbFlt - detected UnsignedFile.Multi.Generic (1)
11:56:58.0601 0668 tsusbhub - ok
11:56:58.0632 0668 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
11:56:58.0632 0668 tunnel ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0632 0668 tunnel - detected UnsignedFile.Multi.Generic (1)
11:56:58.0647 0668 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
11:56:58.0647 0668 uagp35 ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0647 0668 uagp35 - detected UnsignedFile.Multi.Generic (1)
11:56:58.0679 0668 [ 01662B4865FDB282677B11CF416757CE ] UCTblHid C:\Windows\system32\DRIVERS\UCTblHid.sys
11:56:58.0679 0668 UCTblHid ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0679 0668 UCTblHid - detected UnsignedFile.Multi.Generic (1)
11:56:58.0694 0668 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
11:56:58.0710 0668 udfs ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0710 0668 udfs - detected UnsignedFile.Multi.Generic (1)
11:56:58.0710 0668 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\Windows\system32\UI0Detect.exe
11:56:58.0710 0668 UI0Detect ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0710 0668 UI0Detect - detected UnsignedFile.Multi.Generic (1)
11:56:58.0725 0668 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
11:56:58.0725 0668 uliagpkx ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0725 0668 uliagpkx - detected UnsignedFile.Multi.Generic (1)
11:56:58.0757 0668 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\Windows\system32\drivers\umbus.sys
11:56:58.0757 0668 umbus ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0757 0668 umbus - detected UnsignedFile.Multi.Generic (1)
11:56:58.0757 0668 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
11:56:58.0757 0668 UmPass ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0757 0668 UmPass - detected UnsignedFile.Multi.Generic (1)
11:56:58.0772 0668 [ A293DCD756D04D8492A750D03B9A297C ] UmRdpService C:\Windows\System32\umrdp.dll
11:56:58.0772 0668 UmRdpService ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0772 0668 UmRdpService - detected UnsignedFile.Multi.Generic (1)
11:56:58.0866 0668 [ 67A95B9D129ED5399E7965CD09CF30E7 ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
11:56:58.0866 0668 UMVPFSrv ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0866 0668 UMVPFSrv - detected UnsignedFile.Multi.Generic (1)
11:56:58.0881 0668 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\Windows\System32\upnphost.dll
11:56:58.0897 0668 upnphost ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0897 0668 upnphost - detected UnsignedFile.Multi.Generic (1)
11:56:58.0928 0668 [ 907F50B8695DAA65A9445D27AD306E65 ] upperdev C:\Windows\system32\DRIVERS\usbser_lowerfltx64.sys
11:56:58.0928 0668 upperdev ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0928 0668 upperdev - detected UnsignedFile.Multi.Generic (1)
11:56:58.0944 0668 [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys
11:56:58.0944 0668 USBAAPL64 ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0944 0668 USBAAPL64 - detected UnsignedFile.Multi.Generic (1)
11:56:58.0959 0668 [ 82E8F44688E6FAC57B5B7C6FC7ADBC2A ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
11:56:58.0959 0668 usbaudio ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0959 0668 usbaudio - detected UnsignedFile.Multi.Generic (1)
11:56:58.0991 0668 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
11:56:58.0991 0668 usbccgp ( UnsignedFile.Multi.Generic ) - warning
11:56:58.0991 0668 usbccgp - detected UnsignedFile.Multi.Generic (1)
11:56:59.0022 0668 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\Windows\system32\drivers\usbcir.sys
11:56:59.0022 0668 usbcir ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0022 0668 usbcir - detected UnsignedFile.Multi.Generic (1)
11:56:59.0053 0668 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
11:56:59.0053 0668 usbehci ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0053 0668 usbehci - detected UnsignedFile.Multi.Generic (1)
11:56:59.0084 0668 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
11:56:59.0084 0668 usbhub ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0084 0668 usbhub - detected UnsignedFile.Multi.Generic (1)
11:56:59.0100 0668 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
11:56:59.0100 0668 usbohci ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0100 0668 usbohci - detected UnsignedFile.Multi.Generic (1)
11:56:59.0115 0668 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
11:56:59.0115 0668 usbprint ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0115 0668 usbprint - detected UnsignedFile.Multi.Generic (1)
11:56:59.0147 0668 [ 4ACEE387FA8FD39F83564FCD2FC234F2 ] usbser C:\Windows\system32\drivers\usbser.sys
11:56:59.0147 0668 usbser ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0147 0668 usbser - detected UnsignedFile.Multi.Generic (1)
11:56:59.0162 0668 [ 3F7498527B48657091C355F683BEB0DD ] UsbserFilt C:\Windows\system32\DRIVERS\usbser_lowerfltjx64.sys
11:56:59.0178 0668 UsbserFilt ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0178 0668 UsbserFilt - detected UnsignedFile.Multi.Generic (1)
11:56:59.0193 0668 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
11:56:59.0193 0668 USBSTOR ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0193 0668 USBSTOR - detected UnsignedFile.Multi.Generic (1)
11:56:59.0209 0668 [ 81FB2216D3A60D1284455D511797DB3D ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
11:56:59.0209 0668 usbuhci ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0209 0668 usbuhci - detected UnsignedFile.Multi.Generic (1)
11:56:59.0225 0668 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys
11:56:59.0225 0668 usbvideo ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0225 0668 usbvideo - detected UnsignedFile.Multi.Generic (1)
11:56:59.0256 0668 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\Windows\System32\uxsms.dll
11:56:59.0256 0668 UxSms ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0256 0668 UxSms - detected UnsignedFile.Multi.Generic (1)
11:56:59.0256 0668 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\Windows\system32\lsass.exe
11:56:59.0256 0668 VaultSvc ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0256 0668 VaultSvc - detected UnsignedFile.Multi.Generic (1)
11:56:59.0287 0668 [ 84BB306B7863883018D7F3EB0C453BD5 ] VClone C:\Windows\system32\DRIVERS\VClone.sys
11:56:59.0303 0668 VClone ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0303 0668 VClone - detected UnsignedFile.Multi.Generic (1)
11:56:59.0318 0668 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
11:56:59.0318 0668 vdrvroot ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0318 0668 vdrvroot - detected UnsignedFile.Multi.Generic (1)
11:56:59.0349 0668 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\Windows\System32\vds.exe
11:56:59.0365 0668 vds ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0365 0668 vds - detected UnsignedFile.Multi.Generic (1)
11:56:59.0365 0668 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
11:56:59.0381 0668 vga ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0381 0668 vga - detected UnsignedFile.Multi.Generic (1)
11:56:59.0381 0668 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\Windows\System32\drivers\vga.sys
11:56:59.0396 0668 VgaSave ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0396 0668 VgaSave - detected UnsignedFile.Multi.Generic (1)
11:56:59.0396 0668 VGPU - ok
11:56:59.0427 0668 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
11:56:59.0427 0668 vhdmp ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0427 0668 vhdmp - detected UnsignedFile.Multi.Generic (1)
11:56:59.0459 0668 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\Windows\system32\drivers\viaide.sys
11:56:59.0459 0668 viaide ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0459 0668 viaide - detected UnsignedFile.Multi.Generic (1)
11:56:59.0474 0668 [ 86EA3E79AE350FEA5331A1303054005F ] vmbus C:\Windows\system32\drivers\vmbus.sys
11:56:59.0474 0668 vmbus ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0474 0668 vmbus - detected UnsignedFile.Multi.Generic (1)
11:56:59.0490 0668 [ 7DE90B48F210D29649380545DB45A187 ] VMBusHID C:\Windows\system32\drivers\VMBusHID.sys
11:56:59.0490 0668 VMBusHID ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0490 0668 VMBusHID - detected UnsignedFile.Multi.Generic (1)
11:56:59.0521 0668 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\Windows\system32\drivers\volmgr.sys
11:56:59.0521 0668 volmgr ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0521 0668 volmgr - detected UnsignedFile.Multi.Generic (1)
11:56:59.0552 0668 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
11:56:59.0568 0668 volmgrx ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0568 0668 volmgrx - detected UnsignedFile.Multi.Generic (1)
11:56:59.0583 0668 [ 0D08D2F3B3FF84E433346669B5E0F639 ] volsnap C:\Windows\system32\drivers\volsnap.sys
11:56:59.0583 0668 volsnap ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0583 0668 volsnap - detected UnsignedFile.Multi.Generic (1)
11:56:59.0599 0668 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
11:56:59.0599 0668 vsmraid ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0599 0668 vsmraid - detected UnsignedFile.Multi.Generic (1)
11:56:59.0646 0668 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\Windows\system32\vssvc.exe
11:56:59.0661 0668 VSS ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0661 0668 VSS - detected UnsignedFile.Multi.Generic (1)
11:56:59.0786 0668 [ 254E8F9BA44E9F55416B0E51DBFF3C5F ] vToolbarUpdater15.3.0 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
11:56:59.0802 0668 vToolbarUpdater15.3.0 ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0802 0668 vToolbarUpdater15.3.0 - detected UnsignedFile.Multi.Generic (1)
11:56:59.0817 0668 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\Windows\system32\DRIVERS\vwifibus.sys
11:56:59.0817 0668 vwifibus ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0817 0668 vwifibus - detected UnsignedFile.Multi.Generic (1)
11:56:59.0833 0668 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
11:56:59.0833 0668 vwififlt ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0833 0668 vwififlt - detected UnsignedFile.Multi.Generic (1)
11:56:59.0833 0668 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\Windows\system32\DRIVERS\vwifimp.sys
11:56:59.0833 0668 vwifimp ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0833 0668 vwifimp - detected UnsignedFile.Multi.Generic (1)
11:56:59.0880 0668 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\Windows\system32\w32time.dll
11:56:59.0880 0668 W32Time ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0880 0668 W32Time - detected UnsignedFile.Multi.Generic (1)
11:56:59.0911 0668 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
11:56:59.0911 0668 WacomPen ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0911 0668 WacomPen - detected UnsignedFile.Multi.Generic (1)
11:56:59.0973 0668 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
11:56:59.0973 0668 WANARP ( UnsignedFile.Multi.Generic ) - warning
11:56:59.0973 0668 WANARP - detected UnsignedFile.Multi.Generic (1)
11:57:00.0020 0668 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
11:57:00.0020 0668 Wanarpv6 ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0020 0668 Wanarpv6 - detected UnsignedFile.Multi.Generic (1)
11:57:00.0129 0668 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
11:57:00.0129 0668 WatAdminSvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0129 0668 WatAdminSvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0192 0668 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\Windows\system32\wbengine.exe
11:57:00.0207 0668 wbengine ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0207 0668 wbengine - detected UnsignedFile.Multi.Generic (1)
11:57:00.0207 0668 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
11:57:00.0223 0668 WbioSrvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0223 0668 WbioSrvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0254 0668 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\Windows\System32\wcncsvc.dll
11:57:00.0254 0668 wcncsvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0254 0668 wcncsvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0270 0668 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
11:57:00.0270 0668 WcsPlugInService ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0270 0668 WcsPlugInService - detected UnsignedFile.Multi.Generic (1)
11:57:00.0285 0668 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\Windows\system32\DRIVERS\wd.sys
11:57:00.0285 0668 Wd ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0285 0668 Wd - detected UnsignedFile.Multi.Generic (1)
11:57:00.0317 0668 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
11:57:00.0332 0668 Wdf01000 ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0332 0668 Wdf01000 - detected UnsignedFile.Multi.Generic (1)
11:57:00.0332 0668 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\Windows\system32\wdi.dll
11:57:00.0348 0668 WdiServiceHost ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0348 0668 WdiServiceHost - detected UnsignedFile.Multi.Generic (1)
11:57:00.0348 0668 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\Windows\system32\wdi.dll
11:57:00.0348 0668 WdiSystemHost ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0348 0668 WdiSystemHost - detected UnsignedFile.Multi.Generic (1)
11:57:00.0363 0668 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\Windows\System32\webclnt.dll
11:57:00.0379 0668 WebClient ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0379 0668 WebClient - detected UnsignedFile.Multi.Generic (1)
11:57:00.0395 0668 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\Windows\system32\wecsvc.dll
11:57:00.0395 0668 Wecsvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0395 0668 Wecsvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0395 0668 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\Windows\System32\wercplsupport.dll
11:57:00.0395 0668 wercplsupport ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0395 0668 wercplsupport - detected UnsignedFile.Multi.Generic (1)
11:57:00.0410 0668 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\Windows\System32\WerSvc.dll
11:57:00.0410 0668 WerSvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0410 0668 WerSvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0426 0668 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
11:57:00.0426 0668 WfpLwf ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0426 0668 WfpLwf - detected UnsignedFile.Multi.Generic (1)
11:57:00.0426 0668 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\Windows\system32\drivers\wimmount.sys
11:57:00.0426 0668 WIMMount ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0441 0668 WIMMount - detected UnsignedFile.Multi.Generic (1)
11:57:00.0441 0668 WinDefend - ok
11:57:00.0457 0668 WinHttpAutoProxySvc - ok
11:57:00.0488 0668 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
11:57:00.0488 0668 Winmgmt ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0488 0668 Winmgmt - detected UnsignedFile.Multi.Generic (1)
11:57:00.0551 0668 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\Windows\system32\WsmSvc.dll
11:57:00.0566 0668 WinRM ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0566 0668 WinRM - detected UnsignedFile.Multi.Generic (1)
11:57:00.0597 0668 [ 935471EC43505CB23DA16600562EE19A ] WinTabService C:\Windows\System32\Drivers\WTSRV.EXE
11:57:00.0597 0668 WinTabService ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0597 0668 WinTabService - detected UnsignedFile.Multi.Generic (1)
11:57:00.0629 0668 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
11:57:00.0629 0668 WinUsb ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0629 0668 WinUsb - detected UnsignedFile.Multi.Generic (1)
11:57:00.0644 0668 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\Windows\System32\wlansvc.dll
11:57:00.0660 0668 Wlansvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0660 0668 Wlansvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0738 0668 [ 7E47C328FC4768CB8BEAFBCFAFA70362 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
11:57:00.0753 0668 wlidsvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0753 0668 wlidsvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0785 0668 [ 680A7846370000D20D7E74917D5B7936 ] WmBEnum C:\Windows\system32\drivers\WmBEnum.sys
11:57:00.0785 0668 WmBEnum ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0785 0668 WmBEnum - detected UnsignedFile.Multi.Generic (1)
11:57:00.0816 0668 [ 14C35BA8189C6F65D839163AA285E954 ] WmFilter C:\Windows\system32\drivers\WmFilter.sys
11:57:00.0816 0668 WmFilter ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0816 0668 WmFilter - detected UnsignedFile.Multi.Generic (1)
11:57:00.0847 0668 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
11:57:00.0847 0668 WmiAcpi ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0847 0668 WmiAcpi - detected UnsignedFile.Multi.Generic (1)
11:57:00.0863 0668 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
11:57:00.0863 0668 wmiApSrv ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0863 0668 wmiApSrv - detected UnsignedFile.Multi.Generic (1)
11:57:00.0863 0668 WMPNetworkSvc - ok
11:57:00.0878 0668 [ 8488DD91A3EE54A8E29F02AD7BB8201E ] WmVirHid C:\Windows\system32\drivers\WmVirHid.sys
11:57:00.0894 0668 WmVirHid ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0894 0668 WmVirHid - detected UnsignedFile.Multi.Generic (1)
11:57:00.0925 0668 [ 14802B3A30AA849C97CB968CCC813BF3 ] WmXlCore C:\Windows\system32\drivers\WmXlCore.sys
11:57:00.0925 0668 WmXlCore ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0925 0668 WmXlCore - detected UnsignedFile.Multi.Generic (1)
11:57:00.0925 0668 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\Windows\System32\wpcsvc.dll
11:57:00.0925 0668 WPCSvc ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0925 0668 WPCSvc - detected UnsignedFile.Multi.Generic (1)
11:57:00.0956 0668 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
11:57:00.0956 0668 WPDBusEnum ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0956 0668 WPDBusEnum - detected UnsignedFile.Multi.Generic (1)
11:57:00.0987 0668 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
11:57:00.0987 0668 ws2ifsl ( UnsignedFile.Multi.Generic ) - warning
11:57:00.0987 0668 ws2ifsl - detected UnsignedFile.Multi.Generic (1)
11:57:01.0003 0668 [ E8B1FE6669397D1772D8196DF0E57A9E ] wscsvc C:\Windows\system32\wscsvc.dll
11:57:01.0003 0668 wscsvc ( UnsignedFile.Multi.Generic ) - warning
11:57:01.0003 0668 wscsvc - detected UnsignedFile.Multi.Generic (1)
11:57:01.0003 0668 WSearch - ok
11:57:01.0003 0668 wuauserv - ok
11:57:01.0034 0668 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
11:57:01.0034 0668 WudfPf ( UnsignedFile.Multi.Generic ) - warning
11:57:01.0034 0668 WudfPf - detected UnsignedFile.Multi.Generic (1)
11:57:01.0065 0668 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
11:57:01.0065 0668 WUDFRd ( UnsignedFile.Multi.Generic ) - warning
11:57:01.0065 0668 WUDFRd - detected UnsignedFile.Multi.Generic (1)
11:57:01.0097 0668 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
11:57:01.0097 0668 wudfsvc ( UnsignedFile.Multi.Generic ) - warning
11:57:01.0097 0668 wudfsvc - detected UnsignedFile.Multi.Generic (1)
11:57:01.0128 0668 [ FE90B750AB808FB9DD8FBB428B5FF83B ] WwanSvc C:\Windows\System32\wwansvc.dll
11:57:01.0128 0668 WwanSvc ( UnsignedFile.Multi.Generic ) - warning
11:57:01.0128 0668 WwanSvc - detected UnsignedFile.Multi.Generic (1)
11:57:01.0143 0668 ================ Scan global ===============================
11:57:01.0159 0668 [ BA0CD8C393E8C9F83354106093832C7B ] C:\Windows\system32\basesrv.dll
11:57:01.0190 0668 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
11:57:01.0190 0668 [ 0C27239FEA4DB8A2AAC9E502186B7264 ] C:\Windows\system32\winsrv.dll
11:57:01.0206 0668 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\Windows\system32\sxssrv.dll
11:57:01.0221 0668 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\Windows\system32\services.exe
11:57:01.0237 0668 [Global] - ok
11:57:01.0237 0668 ================ Scan MBR ==================================
11:57:01.0253 0668 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
11:57:01.0596 0668 \Device\Harddisk0\DR0 - ok
11:57:01.0596 0668 [ 5C616939100B85E558DA92B899A0FC36 ] \Device\Harddisk1\DR1
11:57:01.0658 0668 \Device\Harddisk1\DR1 - ok
11:57:01.0658 0668 ================ Scan VBR ==================================
11:57:01.0674 0668 [ 80FC1ED3AF29C35DFEB4F51E51385A78 ] \Device\Harddisk0\DR0\Partition1
11:57:01.0689 0668 \Device\Harddisk0\DR0\Partition1 - ok
11:57:01.0689 0668 [ CF7AB788CE10F4FCE3AE42A3821E154F ] \Device\Harddisk0\DR0\Partition2
11:57:01.0689 0668 \Device\Harddisk0\DR0\Partition2 - ok
11:57:01.0705 0668 [ 175871C4CEA9D3FC51052F569F26D6A5 ] \Device\Harddisk0\DR0\Partition3
11:57:01.0705 0668 \Device\Harddisk0\DR0\Partition3 - ok
11:57:01.0721 0668 [ 89CEA528869D28A7CF89A0F99B0D0DC3 ] \Device\Harddisk1\DR1\Partition1
11:57:01.0721 0668 \Device\Harddisk1\DR1\Partition1 - ok
11:57:01.0721 0668 ============================================================
11:57:01.0721 0668 Scan finished
11:57:01.0721 0668 ============================================================
11:57:01.0721 1908 Detected object count: 460
11:57:01.0721 1908 Actual detected object count: 460
12:03:43.0172 1908 1394ohci ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 1394ohci ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 ACPI ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 ACPI ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 AcpiPmi ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 AcpiPmi ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 adfs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 adfs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 Adobe Version Cue CS4 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 Adobe Version Cue CS4 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 AdobeARMservice ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 AdobeARMservice ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 adp94xx ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 adp94xx ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 adpahci ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 adpahci ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 adpu320 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 adpu320 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0172 1908 AeLookupSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0172 1908 AeLookupSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 AFD ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 AFD ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 agp440 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 agp440 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 ALG ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 ALG ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 aliide ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 aliide ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 AMD External Events Utility ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 AMD External Events Utility ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 amdide ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 amdide ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 amdiox64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 amdiox64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 AmdK8 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 AmdK8 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 amdkmdag ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 amdkmdag ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 amdkmdap ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 amdkmdap ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 AmdPPM ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 AmdPPM ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0187 1908 amdsata ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0187 1908 amdsata ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 amdsbs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 amdsbs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 amdxata ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 amdxata ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 AppID ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 AppID ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 AppIDSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 AppIDSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 Appinfo ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 Appinfo ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 Apple Mobile Device ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 Apple Mobile Device ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 AppMgmt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 AppMgmt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 arc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 arc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 arcsas ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 arcsas ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 aspnet_state ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 aspnet_state ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 AsyncMac ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 AsyncMac ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 atapi ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 atapi ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0203 1908 AtiHDAudioService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0203 1908 AtiHDAudioService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 AtiHdmiService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 AtiHdmiService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 atikmdag ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 atikmdag ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 AudioEndpointBuilder ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 AudioEndpointBuilder ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 AudioSrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 AudioSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 avgtp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 avgtp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 AxInstSV ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 AxInstSV ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 b06bdrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 b06bdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 b57nd60a ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 b57nd60a ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 BDESVC ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 BDESVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 Beep ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 Beep ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 BFE ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 BFE ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 BITS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 BITS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0218 1908 blbdrive ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0218 1908 blbdrive ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 Bonjour Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 Bonjour Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 bowser ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 bowser ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 BrFiltLo ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 BrFiltLo ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 BrFiltUp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 BrFiltUp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 BridgeMP ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 BridgeMP ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 Browser ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 Browser ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 Brserid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 Brserid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 BrSerWdm ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 BrSerWdm ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 BrUsbMdm ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 BrUsbMdm ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 BrUsbSer ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 BrUsbSer ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 BTHMODEM ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 BTHMODEM ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0234 1908 bthserv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0234 1908 bthserv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 CCALib8 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 CCALib8 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 cdfs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 cdfs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 cdrom ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 cdrom ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 CertPropSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 CertPropSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 circlass ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 circlass ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 CLFS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 CLFS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 clr_optimization_v2.0.50727_32 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 clr_optimization_v2.0.50727_32 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 clr_optimization_v2.0.50727_64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 clr_optimization_v2.0.50727_64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 clr_optimization_v4.0.30319_32 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 clr_optimization_v4.0.30319_32 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 clr_optimization_v4.0.30319_64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 clr_optimization_v4.0.30319_64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 CmBatt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 CmBatt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 cmdide ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 cmdide ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0250 1908 CNG ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0250 1908 CNG ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 Compbatt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 Compbatt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 CompositeBus ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 CompositeBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 cpuz135 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 cpuz135 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 crcdisk ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 crcdisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 CryptSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 CryptSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 CSC ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 CSC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 CscService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 CscService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 DcomLaunch ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 DcomLaunch ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 defragsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 defragsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 DfsC ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 DfsC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 Dhcp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 Dhcp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0265 1908 discache ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0265 1908 discache ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 Disk ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 Disk ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 Dnscache ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 Dnscache ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 dot3svc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 dot3svc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 DPS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 DPS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 drmkaud ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 drmkaud ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 DXGKrnl ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 DXGKrnl ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 EapHost ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 EapHost ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 ebdrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 ebdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 EFS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 EFS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 ElbyCDIO ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 ElbyCDIO ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 elxstor ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 elxstor ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 ErrDev ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 ErrDev ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0281 1908 EventSystem ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0281 1908 EventSystem ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 exfat ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 exfat ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 fastfat ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 fastfat ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 Fax ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 Fax ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 fdc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 fdc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 fdPHost ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 fdPHost ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 FDResPub ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 FDResPub ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 FileInfo ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 FileInfo ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 Filetrace ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 Filetrace ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 FLEXnet Licensing Service 64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 FLEXnet Licensing Service 64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 flpydisk ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 flpydisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 FltMgr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 FltMgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0296 1908 FontCache ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0296 1908 FontCache ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 FontCache3.0.0.0 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 FontCache3.0.0.0 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 FsDepends ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 FsDepends ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 Fs_Rec ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 Fs_Rec ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 fvevol ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 fvevol ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 gagp30kx ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 gagp30kx ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 GEARAspiWDM ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 GEARAspiWDM ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 gpsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 gpsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 gupdate ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 gupdate ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 gupdatem ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 gupdatem ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 gusvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 gusvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 hamachi ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 hamachi ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0312 1908 Hamachi2Svc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0312 1908 Hamachi2Svc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 hcw85cir ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 hcw85cir ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HdAudAddService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HdAudAddService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HDAudBus ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HDAudBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HidBatt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HidBatt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HidBth ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HidBth ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HidIr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HidIr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 hidserv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 hidserv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HidUsb ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HidUsb ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 hkmsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 hkmsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HomeGroupListener ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HomeGroupListener ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HomeGroupProvider ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HomeGroupProvider ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HpSAMD ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HpSAMD ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0328 1908 HTTP ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0328 1908 HTTP ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 hwpolicy ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 hwpolicy ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 i8042prt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 i8042prt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 iaStorV ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 iaStorV ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 IDriverT ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 IDriverT ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 idsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 idsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 iirsp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 iirsp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 IKEEXT ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 IKEEXT ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 IntcAzAudAddService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 intelide ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 intelide ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 intelppm ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 intelppm ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 IPBusEnum ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 IPBusEnum ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0343 1908 IpFilterDriver ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0343 1908 IpFilterDriver ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 iphlpsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 iphlpsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 IPMIDRV ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 IPMIDRV ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 IPNAT ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 IPNAT ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 iPod Service ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 iPod Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 irda ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 irda ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 IRENUM ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 IRENUM ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 Irmon ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 Irmon ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 irsir ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 irsir ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 isapnp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 isapnp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 iScsiPrt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 iScsiPrt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 kbdclass ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 kbdclass ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 kbdhid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 kbdhid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0359 1908 KeyIso ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0359 1908 KeyIso ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 KSecDD ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 KSecDD ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 KSecPkg ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 KSecPkg ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 ksthunk ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 ksthunk ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 KtmRm ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 KtmRm ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 LanmanServer ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 LanmanServer ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 LanmanWorkstation ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 LanmanWorkstation ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 LBTServ ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 LBTServ ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 LHidFilt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 LHidFilt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 lltdio ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 lltdio ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 lltdsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 lltdsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 lmhosts ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 lmhosts ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0374 1908 LMouFilt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0374 1908 LMouFilt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LSI_FC ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LSI_FC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LSI_SAS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LSI_SAS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LSI_SAS2 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LSI_SAS2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LSI_SCSI ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LSI_SCSI ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 luafv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 luafv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LUsbFilt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LUsbFilt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LVPr2M64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LVPr2M64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LVPr2Mon ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LVPr2Mon ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LVPrcS64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LVPrcS64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LVRS64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LVRS64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 LVUVC64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 LVUVC64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 MBAMProtector ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 MBAMProtector ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0390 1908 MBAMScheduler ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0390 1908 MBAMScheduler ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 MBAMService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 MBAMService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 megasas ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 megasas ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 MegaSR ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 MegaSR ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 MMCSS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 MMCSS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 Modem ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 Modem ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 monitor ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 monitor ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 mouclass ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 mouclass ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 mouhid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 mouhid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 mountmgr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 mountmgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 MozillaMaintenance ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 MozillaMaintenance ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 mpio ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 mpio ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 mpsdrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 mpsdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0406 1908 MpsSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0406 1908 MpsSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 MRxDAV ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 MRxDAV ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 mrxsmb ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 mrxsmb ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 mrxsmb10 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 mrxsmb10 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 mrxsmb20 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 mrxsmb20 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 msahci ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 msahci ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 msdsm ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 msdsm ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 MSDTC ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 MSDTC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 Msfs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 Msfs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 mshidkmdf ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 mshidkmdf ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 msisadrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 msisadrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 MSiSCSI ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 MSiSCSI ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0421 1908 MSKSSRV ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0421 1908 MSKSSRV ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 MSPCLOCK ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 MSPCLOCK ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 MSPQM ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 MSPQM ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 MsRPC ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 MsRPC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 mssmbios ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 mssmbios ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 MSTEE ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 MSTEE ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 MTConfig ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 MTConfig ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 Mup ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 Mup ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 napagent ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 napagent ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 NativeWifiP ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 NativeWifiP ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 NDIS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 NDIS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 NdisCap ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 NdisCap ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 NdisTapi ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 NdisTapi ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 Ndisuio ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 Ndisuio ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0437 1908 NdisWan ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0437 1908 NdisWan ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NDProxy ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NDProxy ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NetBIOS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NetBIOS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NetBT ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NetBT ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 Netlogon ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 Netlogon ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 Netman ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 Netman ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NetMsmqActivator ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NetMsmqActivator ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NetPipeActivator ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NetPipeActivator ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 netprofm ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 netprofm ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NetTcpActivator ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NetTcpActivator ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NetTcpPortSharing ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NetTcpPortSharing ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 nfrd960 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 nfrd960 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 NlaSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 NlaSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0452 1908 nmwcd ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0452 1908 nmwcd ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 nmwcdc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 nmwcdc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 Npfs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 Npfs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 nsi ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 nsi ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 nsiproxy ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 nsiproxy ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 Ntfs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 Ntfs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 Null ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 Null ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 nvraid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 nvraid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 nvstor ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 nvstor ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 nv_agp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 nv_agp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 ohci1394 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 ohci1394 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 ose64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 ose64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0468 1908 osppsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0468 1908 osppsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 p2pimsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 p2pimsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 p2psvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 p2psvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 Parport ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 Parport ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 partmgr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 partmgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 PcaSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 PcaSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 pccsmcfd ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 pccsmcfd ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 pci ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 pci ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 pciide ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 pciide ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 pcmcia ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 pcmcia ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 pcw ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 pcw ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 PEAUTH ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 PEAUTH ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0484 1908 PeerDistSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0484 1908 PeerDistSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 PerfHost ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 PerfHost ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 pla ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 pla ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 PlugPlay ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 PlugPlay ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 PNRPAutoReg ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 PNRPAutoReg ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 PNRPsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 PNRPsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 PolicyAgent ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 PolicyAgent ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 Power ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 Power ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 PptpMiniport ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 PptpMiniport ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 Processor ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 Processor ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 ProfSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 ProfSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 ProtectedStorage ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 ProtectedStorage ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 Psched ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 Psched ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0499 1908 PSI_SVC_2 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0499 1908 PSI_SVC_2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 PTSimBus ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 PTSimBus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 PTSimHid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 PTSimHid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 ql2300 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 ql2300 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 ql40xx ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 ql40xx ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 QWAVE ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 QWAVE ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 QWAVEdrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 QWAVEdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 RasAcd ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 RasAcd ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 RasAgileVpn ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 RasAgileVpn ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 RasAuto ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 RasAuto ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 Rasl2tp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 Rasl2tp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 RasMan ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 RasMan ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 RasPppoe ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 RasPppoe ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0515 1908 RasSstp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0515 1908 RasSstp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 rdbss ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 rdbss ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 rdpbus ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 rdpbus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RDPCDD ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RDPCDD ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RDPDR ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RDPDR ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RDPENCDD ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RDPENCDD ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RDPREFMP ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RDPREFMP ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RdpVideoMiniport ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RdpVideoMiniport ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RDPWD ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RDPWD ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 rdyboost ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 rdyboost ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 Realtek11nSU ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 Realtek11nSU ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RemoteAccess ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RemoteAccess ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RemoteRegistry ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RemoteRegistry ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0530 1908 RpcEptMapper ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0530 1908 RpcEptMapper ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 RpcLocator ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 RpcLocator ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 RpcSs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 RpcSs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 rspndr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 rspndr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 RTL8167 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 RTL8167 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 RTL8192su ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 RTL8192su ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 s3cap ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 s3cap ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 SamSs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 SamSs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 sbp2port ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 sbp2port ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 SCardSvr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 SCardSvr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 scfilter ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 scfilter ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 Schedule ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 Schedule ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 SCPolicySvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 SCPolicySvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0546 1908 SDRSVC ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0546 1908 SDRSVC ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 secdrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 secdrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 seclogon ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 seclogon ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 SENS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 SENS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 SensrSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 SensrSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 Serenum ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 Serenum ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 Serial ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 Serial ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 sermouse ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 sermouse ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 ServiceLayer ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 ServiceLayer ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 SessionEnv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 SessionEnv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 sffdisk ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 sffdisk ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 sffp_mmc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 sffp_mmc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0562 1908 sffp_sd ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0562 1908 sffp_sd ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 sfloppy ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 sfloppy ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SharedAccess ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SharedAccess ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 ShellHWDetection ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 ShellHWDetection ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SiSRaid2 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SiSRaid2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SiSRaid4 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SiSRaid4 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SkypeUpdate ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SkypeUpdate ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 Smb ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 Smb ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SNMPTRAP ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SNMPTRAP ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 Soluto ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 Soluto ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SolutoLauncherService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SolutoLauncherService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SolutoRemoteService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SolutoRemoteService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 SolutoService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 SolutoService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0577 1908 speedfan ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0577 1908 speedfan ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 spldr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 spldr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 Spooler ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 Spooler ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 sppsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 sppsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 sppuinotify ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 sppuinotify ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 sptd ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 sptd ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 Spyder3 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 Spyder3 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 srv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 srv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 srv2 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 srv2 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 srvnet ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 srvnet ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 SSDPSRV ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 SSDPSRV ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 SstpSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 SstpSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0593 1908 stexstor ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0593 1908 stexstor ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 stisvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 stisvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 storflt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 storflt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 storvsc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 storvsc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 swenum ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 swenum ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 SwitchBoard ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 SwitchBoard ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 swprv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 swprv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 SysMain ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 SysMain ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 TabletInputService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 TabletInputService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 TapiSrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 TapiSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 TBS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 TBS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 TClass2k ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 TClass2k ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 Tcpip ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 Tcpip ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0608 1908 TCPIP6 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0608 1908 TCPIP6 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 tcpipreg ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 tcpipreg ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 TDPIPE ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 TDPIPE ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 TDTCP ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 TDTCP ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 tdx ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 tdx ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 TermDD ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 TermDD ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 TermService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 TermService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 Themes ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 Themes ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 THREADORDER ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 THREADORDER ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 TrkWks ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 TrkWks ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 TrustedInstaller ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 TrustedInstaller ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 tssecsrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 tssecsrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0624 1908 TsUsbFlt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0624 1908 TsUsbFlt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 tunnel ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 tunnel ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 uagp35 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 uagp35 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 UCTblHid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 UCTblHid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 udfs ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 udfs ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 UI0Detect ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 UI0Detect ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 uliagpkx ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 uliagpkx ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 umbus ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 umbus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 UmPass ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 UmPass ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 UmRdpService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 UmRdpService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 UMVPFSrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 UMVPFSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 upnphost ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 upnphost ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 upperdev ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 upperdev ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0640 1908 USBAAPL64 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0640 1908 USBAAPL64 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbaudio ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbaudio ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbccgp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbccgp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbcir ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbcir ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbehci ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbehci ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbhub ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbhub ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbohci ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbohci ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbprint ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbprint ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbser ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbser ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 UsbserFilt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 UsbserFilt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 USBSTOR ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 USBSTOR ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbuhci ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbuhci ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0655 1908 usbvideo ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0655 1908 usbvideo ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 UxSms ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 UxSms ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 VaultSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 VaultSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 VClone ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 VClone ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 vdrvroot ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 vdrvroot ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 vds ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 vds ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 vga ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 vga ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 VgaSave ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 VgaSave ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 vhdmp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 vhdmp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 viaide ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 viaide ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 vmbus ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 vmbus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 VMBusHID ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 VMBusHID ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 volmgr ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 volmgr ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0671 1908 volmgrx ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0671 1908 volmgrx ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 volsnap ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 volsnap ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 vsmraid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 vsmraid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 VSS ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 VSS ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 vToolbarUpdater15.3.0 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 vToolbarUpdater15.3.0 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 vwifibus ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 vwifibus ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 vwififlt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 vwififlt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 vwifimp ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 vwifimp ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 W32Time ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 W32Time ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 WacomPen ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 WacomPen ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 WANARP ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 WANARP ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 Wanarpv6 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 Wanarpv6 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0686 1908 WatAdminSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0686 1908 WatAdminSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 wbengine ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 wbengine ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WbioSrvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WbioSrvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 wcncsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 wcncsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WcsPlugInService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WcsPlugInService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 Wd ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 Wd ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 Wdf01000 ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 Wdf01000 ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WdiServiceHost ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WdiServiceHost ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WdiSystemHost ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WdiSystemHost ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WebClient ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WebClient ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 Wecsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 Wecsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 wercplsupport ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 wercplsupport ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WerSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WerSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WfpLwf ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WfpLwf ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0702 1908 WIMMount ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0702 1908 WIMMount ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 Winmgmt ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 Winmgmt ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WinRM ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WinRM ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WinTabService ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WinTabService ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WinUsb ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WinUsb ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 Wlansvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 Wlansvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 wlidsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 wlidsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WmBEnum ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WmBEnum ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WmFilter ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WmFilter ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WmiAcpi ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WmiAcpi ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 wmiApSrv ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 wmiApSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WmVirHid ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WmVirHid ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0718 1908 WmXlCore ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0718 1908 WmXlCore ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 WPCSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 WPCSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 WPDBusEnum ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 WPDBusEnum ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 ws2ifsl ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 ws2ifsl ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 wscsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 wscsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 WudfPf ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 WudfPf ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 WUDFRd ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 WUDFRd ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 wudfsvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 wudfsvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:03:43.0733 1908 WwanSvc ( UnsignedFile.Multi.Generic ) - skipped by user
12:03:43.0733 1908 WwanSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip
12:04:26.0469 2396 Deinitialize success
  • 0

#4
klmk

klmk

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
OTL logfile created on: 22.7.2013 12:29:14 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ghost\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = )
Locale: 0000040b | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 62,47% Memory free
8,00 Gb Paging File | 6,06 Gb Available in Paging File | 75,74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 151,46 Gb Total Space | 13,45 Gb Free Space | 8,88% Space Free | Partition Type: NTFS
Drive D: | 322,26 Gb Total Space | 14,06 Gb Free Space | 4,36% Space Free | Partition Type: NTFS
Drive E: | 122,44 Gb Total Space | 4,31 Gb Free Space | 3,52% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 12,90 Gb Free Space | 2,77% Space Free | Partition Type: NTFS

Computer Name: PC-GHOST | User Name: Ghost | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --
PRC - [2013.07.01 20:58:21 | 001,598,128 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
PRC - [2013.06.28 20:41:52 | 001,376,608 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe
PRC - [2013.06.28 20:41:51 | 001,754,976 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\opera_autoupdate.exe
PRC - [2013.06.28 20:41:49 | 039,477,088 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
PRC - [2013.06.15 14:13:35 | 001,104,384 | ---- | M] (Spotify Ltd) -- D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013.05.15 00:49:37 | 000,920,472 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013.05.10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012.10.05 23:57:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ghost\Desktop\OTL.exe
PRC - [2012.02.21 20:39:30 | 002,043,904 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe
PRC - [2011.04.16 12:18:52 | 000,647,168 | ---- | M] (IDEVFH) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}\components\afom.exe
PRC - [2011.03.07 15:42:42 | 000,969,216 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
PRC - [2010.04.16 17:10:58 | 000,036,864 | ---- | M] (Realtek) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
PRC - [2009.07.24 19:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2008.07.22 12:18:44 | 000,163,840 | ---- | M] () -- D:\Ohjelmat\Desktop Media\mediadetect.exe
PRC - [2005.09.30 19:22:50 | 000,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files (x86)\Canon\CAL\CALMAIN.exe


========== Modules (No Company Name) ==========

MOD - [2013.06.28 20:41:58 | 000,977,248 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\ffmpegsumo.dll
MOD - [2013.06.28 20:41:52 | 001,376,608 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe
MOD - [2013.06.28 20:41:51 | 001,754,976 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\opera_autoupdate.exe
MOD - [2013.05.15 00:49:35 | 003,128,728 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011.03.07 15:21:06 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
MOD - [2011.03.07 15:21:02 | 000,433,664 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
MOD - [2008.07.22 12:18:44 | 000,163,840 | ---- | M] () -- D:\Ohjelmat\Desktop Media\mediadetect.exe


========== Services (SafeList) ==========

SRV:64bit: - [2013.06.04 14:44:06 | 000,182,848 | ---- | M] (Soluto) [Auto | Running] -- C:\Program Files\Soluto\SolutoLauncherService.exe -- (SolutoLauncherService)
SRV:64bit: - [2013.06.04 14:44:04 | 000,746,048 | ---- | M] (Soluto) [Auto | Running] -- C:\Program Files\Soluto\SolutoService.exe -- (SolutoService)
SRV:64bit: - [2013.06.04 14:40:24 | 001,671,680 | ---- | M] (GlavSoft LLC.) [On_Demand | Stopped] -- C:\Program Files\Soluto\SolutoRemoteService.exe -- (SolutoRemoteService)
SRV:64bit: - [2013.05.27 08:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012.04.06 05:16:02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.06.06 15:25:32 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010.05.06 12:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009.10.07 01:47:10 | 000,191,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:64bit: - [2009.09.23 14:34:04 | 000,073,728 | ---- | M] (Tablet Driver) [Auto | Running] -- C:\Windows\SysNative\drivers\WTSrv.exe -- (WinTabService)
SRV:64bit: - [2009.07.14 04:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.07.01 20:58:21 | 001,598,128 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe -- (vToolbarUpdater15.3.0)
SRV - [2013.05.15 00:49:36 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.04.19 15:14:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.02.14 04:14:02 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.12.19 10:49:34 | 000,732,648 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012.01.18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011.03.28 15:41:12 | 002,111,368 | ---- | M] (LogMeIn Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2010.11.29 20:31:21 | 000,075,136 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.10.09 04:57:25 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)
SRV - [2010.06.06 15:23:59 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.04.16 17:10:58 | 000,036,864 | ---- | M] (Realtek) [Auto | Running] -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.07.24 19:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009.06.11 00:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.08.15 05:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
SRV - [2005.09.30 19:22:50 | 000,096,341 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files (x86)\Canon\CAL\CALMAIN.exe -- (CCALib8)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2013.07.01 20:58:21 | 000,045,856 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013.06.04 14:40:06 | 000,054,728 | ---- | M] (Soluto LTD.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Soluto.sys -- (Soluto)
DRV:64bit: - [2012.11.09 16:33:30 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2012.11.09 16:33:30 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2012.11.09 16:33:30 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2012.11.09 16:33:30 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2012.10.17 14:53:46 | 000,026,112 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2012.08.23 17:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 17:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.05.14 09:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.04.06 08:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.04.06 08:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.04.06 04:10:44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.03.01 09:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.18 06:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2012.01.18 06:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2011.08.11 14:46:46 | 000,694,376 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su)
DRV:64bit: - [2011.06.10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.05.10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.03.11 09:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 09:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.23 15:48:46 | 000,818,424 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.11.20 16:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010.11.09 16:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2010.04.27 16:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2010.04.27 16:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2010.04.27 14:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2010.04.27 14:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2010.03.30 23:27:42 | 000,015,360 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Spyder3.sys -- (Spyder3)
DRV:64bit: - [2010.03.18 12:00:40 | 000,041,040 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2010.03.18 12:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010.03.18 12:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2010.03.09 13:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.12.18 01:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2009.10.07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2009.10.07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009.08.10 00:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2009.07.14 04:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 04:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 04:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 03:09:02 | 000,120,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\irda.sys -- (irda)
DRV:64bit: - [2009.06.18 11:42:34 | 000,022,696 | ---- | M] (Tablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCTblHid.sys -- (UCTblHid)
DRV:64bit: - [2009.06.18 11:42:16 | 000,027,304 | ---- | M] (Tablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TClass2k.sys -- (TClass2k)
DRV:64bit: - [2009.06.18 11:41:58 | 000,017,064 | ---- | M] (PenTablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PTSimHid.sys -- (PTSimHid)
DRV:64bit: - [2009.06.18 11:41:46 | 000,027,304 | ---- | M] (PenTablet Driver) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PTSimBus.sys -- (PTSimBus)
DRV:64bit: - [2009.06.10 23:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 23:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 23:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 23:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2008.01.19 06:36:12 | 000,027,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\irsir.sys -- (irsir)
DRV - [2009.07.14 04:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fi
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2A 21 4A 5A D4 00 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files (x86)\Download_Energy\prxtbDown.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.c...fr&d=2012-07-24 12:44:52&v=15.2.0.5&pid=avg&sg=0&sap=dsp&q={searchTerms}
IE - HKCU\..\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}: "URL" = http://search.condui...&ctid=CT1269415
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Download Energy Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "DuckDuckGo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: %7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10
FF - prefs.js..extensions.enabledAddons: %7BE173B749-DB5B-4fd2-BA0E-94ECEA0CA55B%7D:7.4
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.16
FF - prefs.js..extensions.enabledAddons: webdavlauncher%40benryan.com:1.0.7
FF - prefs.js..extensions.enabledAddons: %7B888d99e7-e8b5-46a3-851e-1ec45da1e644%7D:17.0.0
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.9.6
FF - prefs.js..extensions.enabledAddons: crossriderapp14917%40crossrider.com:0.91.64
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.011.025.001
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.1
FF - prefs.js..extensions.enabledItems: {d650973c-0444-4ac7-9d00-19e3613c83b9}:3.6.7
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.5
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Ghost\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.17 08:38:41 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.06.25 20:08:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2011.03.11 18:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Extensions
[2011.03.11 18:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.07.22 09:43:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions
[2010.05.31 20:41:37 | 000,000,000 | ---D | M] (Whitehart) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{d650973c-0444-4ac7-9d00-19e3613c83b9}
[2011.11.28 10:56:07 | 000,000,000 | ---D | M] (Memory Fox) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
[2010.12.27 01:16:42 | 000,000,000 | ---D | M] (Chromifox Basic) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.07.22 09:43:01 | 000,000,000 | ---D | M] ("Chat Undetected") -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.07.11 20:24:52 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2012.12.20 18:23:30 | 000,000,000 | ---D | M] (Foxdie) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2012.12.21 13:15:10 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.04.16 20:36:13 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.04.30 21:44:45 | 000,000,000 | ---D | M] (rein) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.07.22 09:43:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]\chrome\content\extensionCode
[2012.09.06 09:25:29 | 000,240,755 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.05.01 16:10:58 | 000,014,909 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.05.27 11:25:07 | 000,534,431 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
[2013.04.17 20:36:12 | 000,282,569 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2013.06.03 13:23:46 | 000,030,502 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
[2013.05.09 21:04:45 | 000,870,680 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.10.30 11:38:54 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2013.04.05 11:57:36 | 000,714,654 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013.07.18 20:41:00 | 000,002,684 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\ann-encyclopedia.xml
[2013.07.17 22:48:03 | 000,010,316 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\duckduckgo.xml
[2013.07.18 20:41:00 | 000,004,873 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\isohunt--bt-search.xml
[2010.06.01 21:15:20 | 000,001,011 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\torrentz-search.xml
[2012.07.25 18:37:47 | 000,000,705 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\webster.xml
[2013.05.15 00:49:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.05.15 00:49:38 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011.10.26 21:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2013.02.20 22:08:13 | 000,003,714 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml

========== Chrome ==========


O1 HOSTS File: ([2013.07.18 22:44:17 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Soluto] c:\program files\soluto\soluto.exe (Soluto)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Spotify Web Helper] D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Ghost\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - ftp Prefix: missing
O13 - gopher Prefix: missing
O13 - home Prefix: missing
O13 - mosaic Prefix: missing
O13 - www Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.241.198.245 62.241.198.246
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F28F71D-B0F7-4600-8842-2F30750E759B}: DhcpNameServer = 62.241.198.245 62.241.198.246
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Value error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\15.3.0\ViProtocol.dll (AVG Secure Search)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

MsConfig:64bit - State: "bootini" - Reg Error: Key error.

SafeBootMin:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootMin:64bit: Base - Driver Group
SafeBootMin:64bit: Boot Bus Extender - Driver Group
SafeBootMin:64bit: Boot file system - Driver Group
SafeBootMin:64bit: File system - Driver Group
SafeBootMin:64bit: Filter - Driver Group
SafeBootMin:64bit: HelpSvc - Service
SafeBootMin:64bit: PCI Configuration - Driver Group
SafeBootMin:64bit: PNP Filter - Driver Group
SafeBootMin:64bit: Primary disk - Driver Group
SafeBootMin:64bit: sacsvr - Service
SafeBootMin:64bit: SCSI Class - Driver Group
SafeBootMin:64bit: SolutoService - C:\Program Files\Soluto\SolutoService.exe (Soluto)
SafeBootMin:64bit: System Bus Extender - Driver Group
SafeBootMin:64bit: vmms - Service
SafeBootMin:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: vmms - Service
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

SafeBootNet:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SafeBootNet:64bit: Base - Driver Group
SafeBootNet:64bit: Boot Bus Extender - Driver Group
SafeBootNet:64bit: Boot file system - Driver Group
SafeBootNet:64bit: File system - Driver Group
SafeBootNet:64bit: Filter - Driver Group
SafeBootNet:64bit: HelpSvc - Service
SafeBootNet:64bit: Messenger - Service
SafeBootNet:64bit: NDIS Wrapper - Driver Group
SafeBootNet:64bit: NetBIOSGroup - Driver Group
SafeBootNet:64bit: NetDDEGroup - Driver Group
SafeBootNet:64bit: Network - Driver Group
SafeBootNet:64bit: NetworkProvider - Driver Group
SafeBootNet:64bit: PCI Configuration - Driver Group
SafeBootNet:64bit: PNP Filter - Driver Group
SafeBootNet:64bit: PNP_TDI - Driver Group
SafeBootNet:64bit: Primary disk - Driver Group
SafeBootNet:64bit: rdsessmgr - Service
SafeBootNet:64bit: sacsvr - Service
SafeBootNet:64bit: SCSI Class - Driver Group
SafeBootNet:64bit: SolutoService - C:\Program Files\Soluto\SolutoService.exe (Soluto)
SafeBootNet:64bit: Streams Drivers - Driver Group
SafeBootNet:64bit: System Bus Extender - Driver Group
SafeBootNet:64bit: TDI - Driver Group
SafeBootNet:64bit: vmms - Service
SafeBootNet:64bit: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet:64bit: WudfUsbccidDriver - Driver
SafeBootNet:64bit: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet:64bit: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet:64bit: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet:64bit: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet:64bit: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet:64bit: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet:64bit: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet:64bit: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet:64bit: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet:64bit: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet:64bit: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet:64bit: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet:64bit: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet:64bit: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet:64bit: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet:64bit: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet:64bit: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet:64bit: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet:64bit: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet:64bit: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet:64bit: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet:64bit: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: Hamachi2Svc - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vmms - Service
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices

ActiveX:64bit: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Reg Error: Key error.
ActiveX:64bit: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX:64bit: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
ActiveX:64bit: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX:64bit: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX:64bit: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX:64bit: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX:64bit: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.6
ActiveX:64bit: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX:64bit: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX:64bit: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Reg Error: Key error.
ActiveX:64bit: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX:64bit: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX:64bit: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\System32\ie4uinit.exe -UserConfig
ActiveX:64bit: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX:64bit: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX:64bit: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX:64bit: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX:64bit: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX:64bit: {F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4} - .NET Framework
ActiveX:64bit: {FEBEF00C-046D-438D-8A88-BF94A6C9E703} - .NET Framework
ActiveX:64bit: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - %SystemRoot%\system32\unregmp2.exe /ShowWMP

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)

CREATERESTOREPOINT
System Restore Service not available.

========== Files/Folders - Created Within 30 Days ==========

[2013.07.22 12:25:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ghost\Desktop\OTL.exe
[2013.07.22 12:22:14 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.07.22 12:22:13 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.07.22 12:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.07.22 12:18:18 | 000,000,000 | ---D | C] -- C:\CC Support
[2013.07.22 12:18:18 | 000,000,000 | ---D | C] -- \CC Support
[2013.07.22 11:55:39 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Ghost\Desktop\tdsskiller.exe
[2013.07.22 09:43:48 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Ghost\Desktop\aswMBR.exe
[2013.07.21 17:57:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.07.21 17:57:14 | 000,000,000 | -HSD | C] -- \$RECYCLE.BIN
[2013.07.19 00:08:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.07.18 23:51:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.07.18 23:51:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.07.18 23:51:02 | 000,000,000 | ---D | C] -- \Qoobox
[2013.07.18 23:41:18 | 000,000,000 | --SD | C] -- C:\ComboFix
[2013.07.18 23:41:18 | 000,000,000 | --SD | C] -- \ComboFix
[2013.07.18 23:24:33 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\MFAData
[2013.07.18 23:24:33 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\Avg2013
[2013.07.18 23:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2013.07.18 23:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2013.07.18 23:01:41 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Spybot - Search & Destroy
[2013.07.18 23:00:39 | 036,364,784 | ---- | C] (Safer-Networking Ltd. ) -- C:\Users\Ghost\Desktop\spybotsd-2.1.20-SR1.exe
[2013.07.18 22:29:31 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.07.18 20:45:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2013.07.18 20:41:55 | 000,000,000 | ---D | C] -- C:\Users\Ghost\Desktop\SUPERSetup
[2013.07.18 20:41:23 | 026,611,408 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
[2013.07.18 20:30:58 | 000,000,000 | ---D | C] -- C:\Malwarebytes
[2013.07.18 20:30:58 | 000,000,000 | ---D | C] -- \Malwarebytes
[2013.07.18 20:30:11 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Ghost\Desktop\mbam-setup-1.75.0.1300.exe
[2013.07.18 20:02:44 | 017,737,608 | ---- | C] (Adobe Systems Incorporated) -- C:\Users\Ghost\Desktop\install_flash_player.exe
[2013.07.18 19:21:40 | 000,000,000 | ---D | C] -- C:\Application Data
[2013.07.18 19:21:40 | 000,000,000 | ---D | C] -- \Application Data
[2013.07.12 02:02:18 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.07.12 02:02:18 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.07.12 02:02:17 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013.07.12 02:02:17 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013.07.12 02:02:17 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013.07.12 02:02:17 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013.07.12 02:02:17 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013.07.12 02:02:17 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013.07.12 02:02:17 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013.07.12 02:02:17 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013.07.12 02:02:17 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013.07.12 02:02:16 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.07.12 02:02:16 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.07.12 02:02:16 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.07.12 02:02:15 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.07.11 20:43:58 | 000,624,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
[2013.07.11 20:43:58 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
[2013.07.11 20:43:56 | 001,887,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2013.07.11 20:43:55 | 001,620,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2013.07.11 20:35:54 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2013.07.06 14:20:39 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\Opera Software
[2013.07.06 14:20:37 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Opera Software
[2013.06.25 20:08:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.06.25 01:25:19 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\TuneUp Software
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013.07.22 12:27:10 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.22 12:27:10 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.22 12:22:14 | 000,000,914 | ---- | M] () -- C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.22 12:20:00 | 000,000,224 | ---- | M] () -- C:\Windows\tasks\AutoRearm.job
[2013.07.22 12:19:27 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.22 12:19:26 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
[2013.07.22 12:19:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.22 12:19:14 | 3220,824,064 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.22 12:12:00 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.22 12:10:00 | 000,666,633 | ---- | M] () -- C:\Users\Ghost\Desktop\adwcleaner.exe
[2013.07.22 12:08:47 | 000,171,135 | ---- | M] () -- C:\Users\Ghost\Desktop\3001-8022_4-10804572.html
[2013.07.22 11:55:17 | 000,000,512 | ---- | M] () -- C:\Users\Ghost\Desktop\MBR.dat
[2013.07.19 00:35:20 | 000,222,290 | ---- | M] () -- C:\Users\Ghost\Desktop\AVGInstLog.cab
[2013.07.18 23:27:52 | 000,001,137 | ---- | M] () -- C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
[2013.07.18 22:44:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.07.18 21:37:05 | 000,064,178 | ---- | M] () -- C:\Users\Ghost\Documents\cc_20130718_213659.reg
[2013.07.18 20:21:11 | 026,611,408 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
[2013.07.18 20:03:00 | 017,737,608 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Ghost\Desktop\install_flash_player.exe
[2013.07.17 23:00:12 | 101,083,484 | ---- | M] () -- C:\Users\Ghost\Desktop\DHBTPO.rar
[2013.07.17 22:42:20 | 048,537,823 | ---- | M] () -- C:\Users\Ghost\Desktop\LJD.rar
[2013.07.17 22:31:53 | 067,966,879 | ---- | M] () -- C:\Users\Ghost\Desktop\NTBD.rar
[2013.07.17 21:59:03 | 002,297,856 | ---- | M] () -- C:\Users\Ghost\Desktop\Baby_shower.indd
[2013.07.17 20:40:27 | 000,001,165 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.07.16 10:00:58 | 005,199,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.07.12 02:11:07 | 001,367,650 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.07.12 02:11:07 | 000,652,166 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.12 02:11:07 | 000,479,386 | ---- | M] () -- C:\Windows\SysNative\perfh00B.dat
[2013.07.12 02:11:07 | 000,121,098 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.07.12 02:11:07 | 000,100,162 | ---- | M] () -- C:\Windows\SysNative\perfc00B.dat
[2013.07.01 20:58:48 | 000,003,716 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.07.01 20:58:21 | 000,045,856 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013.06.30 19:39:52 | 000,002,070 | ---- | M] () -- C:\Users\Ghost\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2013.06.25 00:58:24 | 000,173,429 | ---- | M] () -- C:\Users\Ghost\Desktop\Threadless_130624.pdf
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.07.22 12:22:28 | 000,061,440 | ---- | C] ( ) -- C:\Users\Ghost\Desktop\VEW.exe
[2013.07.22 12:22:14 | 000,000,914 | ---- | C] () -- C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.22 12:18:01 | 004,009,167 | ---- | C] () -- C:\Users\Ghost\Desktop\ServicesRepair.exe
[2013.07.22 12:10:02 | 000,666,633 | ---- | C] () -- C:\Users\Ghost\Desktop\adwcleaner.exe
[2013.07.22 12:08:58 | 000,171,135 | ---- | C] () -- C:\Users\Ghost\Desktop\3001-8022_4-10804572.html
[2013.07.22 11:55:17 | 000,000,512 | ---- | C] () -- C:\Users\Ghost\Desktop\MBR.dat
[2013.07.19 00:35:20 | 000,222,290 | ---- | C] () -- C:\Users\Ghost\Desktop\AVGInstLog.cab
[2013.07.18 23:27:52 | 000,001,137 | ---- | C] () -- C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
[2013.07.18 21:37:03 | 000,064,178 | ---- | C] () -- C:\Users\Ghost\Documents\cc_20130718_213659.reg
[2013.07.17 22:28:17 | 067,966,879 | ---- | C] () -- C:\Users\Ghost\Desktop\NTBD.rar
[2013.07.17 22:27:03 | 101,083,484 | ---- | C] () -- C:\Users\Ghost\Desktop\DHBTPO.rar
[2013.07.17 22:25:43 | 048,537,823 | ---- | C] () -- C:\Users\Ghost\Desktop\LJD.rar
[2013.07.17 21:58:58 | 002,297,856 | ---- | C] () -- C:\Users\Ghost\Desktop\Baby_shower.indd
[2013.07.17 20:40:27 | 000,001,165 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.06.25 00:58:24 | 000,173,429 | ---- | C] () -- C:\Users\Ghost\Desktop\Threadless_130624.pdf
[2013.05.21 13:54:43 | 000,003,716 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.02.15 17:20:04 | 001,325,198 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.02.15 12:56:11 | 000,000,132 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.07.21 09:40:05 | 000,001,456 | ---- | C] () -- C:\Users\Ghost\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.06.24 21:29:42 | 000,925,184 | ---- | C] () -- C:\Windows\expstart.exe
[2012.03.09 07:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.03.09 07:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.02.28 18:28:04 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.01.18 06:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.11.23 22:03:49 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011.11.23 21:58:43 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2011.11.02 08:50:27 | 000,001,556 | ---- | C] () -- C:\Users\Ghost\.davmail.properties
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011.09.13 01:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.09.06 19:55:55 | 000,335,872 | ---- | C] () -- C:\Windows\SetupX32.EXE
[2011.05.30 20:17:54 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2011.05.17 20:03:05 | 000,114,688 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\fontdb.mdb
[2011.03.23 00:02:15 | 000,000,266 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\rftg
[2011.03.21 01:20:29 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.10.19 19:47:31 | 000,005,642 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010.09.09 23:55:23 | 000,007,603 | ---- | C] () -- C:\Users\Ghost\AppData\Local\Resmon.ResmonCfg
[2010.06.11 17:16:52 | 000,000,000 | ---- | C] () -- C:\Users\Ghost\AppData\Local\prvlcl.dat
[2010.06.01 05:02:35 | 000,008,192 | RHS- | C] () -- \BOOTSECT.BAK
[2010.06.01 05:02:34 | 000,383,786 | RHS- | C] () -- \bootmgr
[2010.05.31 18:11:07 | 000,203,836 | RHS- | C] () -- \grldr
[2010.05.31 18:11:07 | 000,000,000 | RHS- | C] () -- \winx.ld
[2010.05.31 18:03:42 | 3220,824,064 | -HS- | C] () -- \hiberfil.sys
[2007.11.07 08:12:28 | 000,232,960 | ---- | C] () -- \VC_RED.MSI
[2007.11.07 08:09:22 | 001,442,522 | ---- | C] () -- \VC_RED.cab
[2007.11.07 08:03:18 | 000,097,296 | ---- | C] () -- \install.res.1036.dll
[2007.11.07 08:03:18 | 000,096,272 | ---- | C] () -- \install.res.3082.dll
[2007.11.07 08:03:18 | 000,096,272 | ---- | C] () -- \install.res.1031.dll
[2007.11.07 08:03:18 | 000,095,248 | ---- | C] () -- \install.res.1040.dll
[2007.11.07 08:03:18 | 000,091,152 | ---- | C] () -- \install.res.1033.dll
[2007.11.07 08:03:18 | 000,081,424 | ---- | C] () -- \install.res.1041.dll
[2007.11.07 08:03:18 | 000,079,888 | ---- | C] () -- \install.res.1042.dll
[2007.11.07 08:03:18 | 000,076,304 | ---- | C] () -- \install.res.1028.dll
[2007.11.07 08:03:18 | 000,075,792 | ---- | C] () -- \install.res.2052.dll
[2007.11.07 08:00:40 | 000,005,686 | ---- | C] () -- \vcredist.bmp
[2007.11.07 08:00:40 | 000,001,110 | ---- | C] () -- \globdata.ini
[2007.11.07 08:00:40 | 000,000,843 | ---- | C] () -- \install.ini

========== ZeroAccess Check ==========

[2009.07.14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 08:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 07:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 15:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

========== Drive Information ==========

Physical Drives
---------------

Error accessing drive info (0)
Error accessing drive info (0)

Partitions
---------------

Error accessing partition info (0)
Error accessing partition info (0)

< %SYSTEMDRIVE%\*.exe >

< %systemroot%\assembly\GAC_32\*.ini >

< %systemroot%\assembly\GAC_64\*.ini >

< %SYSTEMDRIVE%\*.exe >

< %ALLUSERSPROFILE%\Application Data\*.exe >

< %APPDATA%\*. >
[2011.05.30 21:10:29 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\AccurateRip
[2013.01.10 01:17:20 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Adobe
[2012.03.01 01:48:50 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Adobe Mini Bridge CS5.1
[2011.01.12 03:00:48 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Apple Computer
[2010.05.31 19:11:23 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\ATI
[2010.05.31 21:52:49 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\atitray
[2011.03.30 22:42:36 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Axialis
[2011.05.17 21:05:47 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\BorWare
[2012.07.17 22:36:48 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Braid
[2010.12.23 15:23:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Canneverbe Limited
[2010.06.06 12:13:25 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Canon
[2012.05.22 09:05:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013.05.29 12:00:33 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\com.destroytoday.destroytwitter
[2010.08.02 22:30:58 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Command and Conquer 4
[2010.10.19 21:09:11 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Corel
[2010.08.16 21:26:02 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Crayon Physics Deluxe
[2010.08.09 22:16:00 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\CyberLink
[2011.05.30 21:11:42 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\dBpoweramp
[2013.07.17 20:25:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Dropbox
[2013.01.31 00:48:51 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\dvdcss
[2011.02.14 20:25:57 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\FontExplorerX
[2011.09.12 10:07:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\foobar2000
[2012.03.05 19:45:25 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\FuzzyClock
[2011.07.12 10:34:32 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\HandBrake
[2011.02.08 13:04:56 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\IcoFX
[2010.05.31 18:09:48 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Identities
[2011.01.11 23:51:38 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\ifolor
[2010.08.20 07:45:44 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\ImgBurn
[2011.02.09 08:01:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\iPodder
[2010.09.07 16:09:40 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\KC Softwares
[2010.08.14 13:10:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Leadertech
[2010.08.14 13:08:29 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Logishrd
[2010.08.14 13:10:14 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Logitech
[2010.05.31 21:44:23 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Macromedia
[2011.07.12 15:00:11 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Malwarebytes
[2009.07.14 10:45:14 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Media Center Programs
[2013.07.18 21:34:59 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Media Player Classic
[2013.06.06 22:44:15 | 000,000,000 | --SD | M] -- C:\Users\Ghost\AppData\Roaming\Microsoft
[2010.05.31 19:12:47 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Mozilla
[2011.02.14 04:22:24 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\MozillaControl
[2013.07.17 23:19:42 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Mp3tag
[2012.03.09 09:37:00 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\NexusFont
[2012.06.24 22:00:18 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Nokia
[2010.11.14 22:26:45 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Nokia Ovi Suite
[2011.04.03 17:32:52 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Notepad++
[2010.06.30 22:16:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\OpenOffice.org
[2010.08.02 19:05:56 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Opera
[2013.07.06 14:20:37 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Opera Software
[2013.06.04 19:46:58 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Origin
[2012.09.07 18:00:54 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\PC Suite
[2010.05.31 23:17:58 | 000,000,000 | RH-D | M] -- C:\Users\Ghost\AppData\Roaming\SecuROM
[2010.06.07 21:28:43 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Simple Sudoku
[2013.07.02 10:27:39 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Skype
[2011.03.29 21:43:26 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Soluto
[2013.07.11 23:00:18 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Spotify
[2013.07.18 23:17:16 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Spybot - Search & Destroy
[2012.03.01 01:48:50 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.04.09 21:30:25 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\StreamTorrent
[2011.09.12 10:23:01 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\streamWriter
[2011.03.11 18:55:04 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Thunderbird
[2013.06.25 01:25:19 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\TuneUp Software
[2011.02.24 20:57:52 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Unity
[2013.07.18 21:34:59 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\uTorrent
[2013.07.17 23:56:10 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\vlc
[2011.03.06 16:39:32 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\wargaming.net
[2013.02.02 15:52:14 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Waterfox Limited
[2013.07.18 21:35:00 | 000,000,000 | ---D | M] -- C:\Users\Ghost\AppData\Roaming\Winamp

< MD5 for: ATAPI.SYS >
[2009.07.14 04:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\drivers\atapi.sys
[2009.07.14 04:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009.07.14 04:52:21 | 000,024,128 | ---- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C -- C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys

< MD5 for: CSRSS.EXE >
[2009.07.14 04:39:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=60C2862B4BF0FD9F582EF344C2B1EC72 -- C:\Windows\SysNative\csrss.exe
[2009.07.14 04:39:02 | 000,007,680 | ---- | M] (Microsoft Corporation) MD5=60C2862B4BF0FD9F582EF344C2B1EC72 -- C:\Windows\winsxs\amd64_microsoft-windows-csrss_31bf3856ad364e35_6.1.7600.16385_none_b4d8d57efdc6b4f3\csrss.exe

< MD5 for: EXPLORER.EXE >
[2011.02.26 08:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011.02.25 09:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011.02.25 09:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011.02.26 09:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010.11.20 15:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011.02.25 08:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011.02.25 08:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010.11.20 16:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: MSWSOCK.DLL >
[2010.11.20 16:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\SysNative\mswsock.dll
[2010.11.20 16:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_16795c7543eb48cf\mswsock.dll
[2010.11.20 15:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\SysWOW64\mswsock.dll
[2010.11.20 15:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll

< MD5 for: NAPINSP.DLL >
[2009.07.14 04:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\SysWOW64\NapiNSP.dll
[2009.07.14 04:16:02 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0B7E85364CB878E2AD531DB7B601A9E5 -- C:\Windows\winsxs\x86_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.1.7600.16385_none_abf396ebf0847c31\NapiNSP.dll
[2009.07.14 04:41:52 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=58A0CDABEA255616827B1C22C9994466 -- C:\Windows\SysNative\NapiNSP.dll
[2009.07.14 04:41:52 | 000,068,096 | ---- | M] (Microsoft Corporation) MD5=58A0CDABEA255616827B1C22C9994466 -- C:\Windows\winsxs\amd64_microsoft-windows-n..ider-infrastructure_31bf3856ad364e35_6.1.7600.16385_none_0812326fa8e1ed67\NapiNSP.dll

< MD5 for: NLAAPI.DLL >
[2012.01.13 10:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0BA65122FFA7E37564EE86422DBF7AE8 -- C:\Windows\SysWOW64\nlaapi.dll
[2012.01.13 10:12:03 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=0BA65122FFA7E37564EE86422DBF7AE8 -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17964_none_cfca9d84561311f2\nlaapi.dll
[2010.11.20 15:20:30 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=104A1070E90F1C530328E69B49718841 -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17514_none_d000a58855ea91a1\nlaapi.dll
[2012.10.03 19:29:27 | 000,052,224 | ---- | M] (Microsoft Corporation) MD5=11B8C7970C10650827D060AA81BEE63F -- C:\Windows\winsxs\wow64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.22124_none_d07f52216f10753a\nlaapi.dll
[2010.11.20 16:27:22 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=2DF36F15B2BC1571A6A542A3C2107920 -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17514_none_c5abfb362189cfa6\nlaapi.dll
[2012.10.03 20:44:21 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=46BB91A169B9B31FF44EB04C48EC1D41 -- C:\Windows\SysNative\nlaapi.dll
[2012.10.03 20:44:21 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=46BB91A169B9B31FF44EB04C48EC1D41 -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.17964_none_c575f33221b24ff7\nlaapi.dll
[2012.10.03 20:32:48 | 000,070,656 | ---- | M] (Microsoft Corporation) MD5=C98BCE54F31113D5E736C1097FD086DC -- C:\Windows\winsxs\amd64_microsoft-windows-nlasvc_31bf3856ad364e35_6.1.7601.22124_none_c62aa7cf3aafb33f\nlaapi.dll

< MD5 for: PNRPNSP.DLL >
[2009.07.14 04:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\SysWOW64\pnrpnsp.dll
[2009.07.14 04:16:12 | 000,065,024 | ---- | M] (Microsoft Corporation) MD5=5CF640EDDB1E40A5AB1BB743BCDEC610 -- C:\Windows\winsxs\wow64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.1.7600.16385_none_d7c8b1ac70865dab\pnrpnsp.dll
[2009.07.14 04:41:53 | 000,086,016 | ---- | M] (Microsoft Corporation) MD5=613C8CE10A5FDE582BA5FA64C4D56AAA -- C:\Windows\SysNative\pnrpnsp.dll
[2009.07.14 04:41:53 | 000,086,016 | ---- | M] (Microsoft Corporation) MD5=613C8CE10A5FDE582BA5FA64C4D56AAA -- C:\Windows\winsxs\amd64_microsoft-windows-peertopeerpnrp_31bf3856ad364e35_6.1.7600.16385_none_cd74075a3c259bb0\pnrpnsp.dll

< MD5 for: PRINTISOLATIONHOST.EXE >
[2009.07.14 04:39:27 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=22F020C76E339EB2B2187BA73A7E4173 -- C:\Windows\SysNative\PrintIsolationHost.exe
[2009.07.14 04:39:27 | 000,018,944 | ---- | M] (Microsoft Corporation) MD5=22F020C76E339EB2B2187BA73A7E4173 -- C:\Windows\winsxs\amd64_microsoft-windows-p..ng-server-isolation_31bf3856ad364e35_6.1.7600.16385_none_f8a40495785334a9\PrintIsolationHost.exe

< MD5 for: SERVICES.EXE >
[2009.07.14 04:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009.07.14 04:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009.07.14 04:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009.07.14 04:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009.07.14 04:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009.07.14 04:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010.11.20 15:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010.11.20 15:17:48 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010.11.20 16:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010.11.20 16:25:24 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010.11.20 16:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\SysNative\winlogon.exe
[2010.11.20 16:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2013.04.04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINRNR.DLL >
[2009.07.14 04:41:56 | 000,028,672 | ---- | M] (Microsoft Corporation) MD5=2E2072EB48238FCA8FBB7A9F5FABAC45 -- C:\Windows\SysNative\winrnr.dll
[2009.07.14 04:41:56 | 000,028,672 | ---- | M] (Microsoft Corporation) MD5=2E2072EB48238FCA8FBB7A9F5FABAC45 -- C:\Windows\winsxs\amd64_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.1.7600.16385_none_b543449669c73e11\winrnr.dll
[2009.07.14 04:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\SysWOW64\winrnr.dll
[2009.07.14 04:16:19 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=5DF5D8CFD9B9573FA3B2C89D9061A240 -- C:\Windows\winsxs\x86_microsoft-windows-dns-client-winrnr_31bf3856ad364e35_6.1.7600.16385_none_5924a912b169ccdb\winrnr.dll

< MD5 for: WSHELPER.DLL >
[2009.07.14 04:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\SysWOW64\wshelper.dll
[2009.07.14 04:16:20 | 000,015,360 | ---- | M] (Microsoft Corporation) MD5=5B90BB3171504C9DAF3C5CB44B203CA7 -- C:\Windows\winsxs\wow64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6ace9e67456cc40b\wshelper.dll
[2009.07.14 04:41:58 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=D314DA4B0B8DCD023D547FC568E34FB6 -- C:\Windows\SysNative\wshelper.dll
[2009.07.14 04:41:58 | 000,019,968 | ---- | M] (Microsoft Corporation) MD5=D314DA4B0B8DCD023D547FC568E34FB6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\wshelper.dll

< %systemroot%\*. /mp /s >

< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2013.05.15 00:49:33 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2013.05.15 00:49:33 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013.05.15 00:49:33 | 000,865,968 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files (x86)\Mozilla Firefox\firefox.exe [2013.05.15 00:49:37 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -preferences [2013.05.15 00:49:37 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -safe-mode [2013.05.15 00:49:37 | 000,920,472 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --make-default-browser [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --hide-icons [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --show-icons [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2013.06.12 05:28:00 | 000,775,256 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files (x86)\Internet Explorer\iexplore.exe" [2013.06.12 03:23:57 | 000,770,648 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Opera\Opera.exe" /ShowIconsCommand [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Opera\Opera.exe" /HideIconsCommand [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Opera\Opera.exe" /ReInstallBrowser [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\shell\open\command\\: "C:\Program Files (x86)\Opera\Opera.exe" [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\InstallInfo\\ShowIconsCommand: "C:\Program Files (x86)\Opera\Launcher.exe" --showicons [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\InstallInfo\\HideIconsCommand: "C:\Program Files (x86)\Opera\Launcher.exe" --hideicons [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\InstallInfo\\ReinstallCommand: "C:\Program Files (x86)\Opera\Launcher.exe" --makedefaultbrowser [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\shell\open\command\\: "C:\Program Files (x86)\Opera\Launcher.exe" [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Waterfox\uninstall\helper.exe" /HideShortcuts [2013.01.20 01:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Waterfox\uninstall\helper.exe" /ShowShortcuts [2013.01.20 01:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Waterfox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2013.01.20 01:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\open\command\\: C:\Program Files\Waterfox\waterfox.exe [2013.01.20 01:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\properties\command\\: "C:\Program Files\Waterfox\waterfox.exe" -preferences [2013.01.20 01:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\safemode\command\\: "C:\Program Files\Waterfox\waterfox.exe" -safe-mode [2013.01.20 01:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)

< hklm\software\clients\startmenuinternet|command /64 /rs >
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2013.05.15 00:49:33 | 000,865,968 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2013.05.15 00:49:33 | 000,865,968 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2013.05.15 00:49:33 | 000,865,968 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE [2013.05.15 00:49:37 | 000,920,472 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -PREFERENCES [2013.05.15 00:49:37 | 000,920,472 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\FIREFOX.EXE" -SAFE-MODE [2013.05.15 00:49:37 | 000,920,472 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --MAKE-DEFAULT-BROWSER [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --HIDE-ICONS [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" --SHOW-ICONS [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\PROGRAM FILES (X86)\GOOGLE\CHROME\APPLICATION\CHROME.EXE" [2013.07.12 21:49:47 | 000,846,288 | ---- | M] (Google Inc.)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -SHOW [2013.06.12 02:26:36 | 000,051,712 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -REINSTALL [2013.06.12 02:26:36 | 000,051,712 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\WINDOWS\SYSTEM32\IE4UINIT.EXE" -HIDE [2013.06.12 02:26:36 | 000,051,712 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE" -EXTOFF [2013.06.12 05:28:00 | 000,775,256 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\PROGRAM FILES (X86)\INTERNET EXPLORER\IEXPLORE.EXE" [2013.06.12 03:23:57 | 000,770,648 | ---- | M] (Microsoft Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\OPERA\OPERA.EXE" /SHOWICONSCOMMAND [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\OPERA\OPERA.EXE" /HIDEICONSCOMMAND [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\OPERA\OPERA.EXE" /REINSTALLBROWSER [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera\shell\open\command\\: "C:\PROGRAM FILES (X86)\OPERA\OPERA.EXE" [2011.12.20 13:12:05 | 000,949,104 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES (X86)\OPERA\LAUNCHER.EXE" --SHOWICONS [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES (X86)\OPERA\LAUNCHER.EXE" --HIDEICONS [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES (X86)\OPERA\LAUNCHER.EXE" --MAKEDEFAULTBROWSER [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\OperaStable\shell\open\command\\: "C:\PROGRAM FILES (X86)\OPERA\LAUNCHER.EXE" [2013.06.28 20:41:47 | 000,487,776 | ---- | M] (Opera Software)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\HideIconsCommand: "C:\PROGRAM FILES\WATERFOX\UNINSTALL\HELPER.EXE" /HIDESHORTCUTS [2013.01.20 01:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\PROGRAM FILES\WATERFOX\UNINSTALL\HELPER.EXE" /SHOWSHORTCUTS [2013.01.20 01:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\InstallInfo\\ReinstallCommand: "C:\PROGRAM FILES\WATERFOX\UNINSTALL\HELPER.EXE" /SETASDEFAULTAPPGLOBAL [2013.01.20 01:26:16 | 000,844,016 | ---- | M] (waterfoxproject.org)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\open\command\\: C:\PROGRAM FILES\WATERFOX\WATERFOX.EXE [2013.01.20 01:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\properties\command\\: "C:\PROGRAM FILES\WATERFOX\WATERFOX.EXE" -PREFERENCES [2013.01.20 01:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)
64bit-HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\WATERFOX.EXE\shell\safemode\command\\: "C:\PROGRAM FILES\WATERFOX\WATERFOX.EXE" -SAFE-MODE [2013.01.20 01:26:15 | 000,718,960 | ---- | M] (Mozilla Corporation)

< %systemroot%\system32\*.dll /lockedfiles >

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

========== Files - Unicode (All) ==========
[2011.12.18 13:48:12 | 000,004,314 | ---- | M] ()(C:\Users\Ghost\Documents\H??kuvat.mds) -- C:\Users\Ghost\Documents\H¦¦kuvat.mds
[2011.12.18 13:48:12 | 000,004,314 | ---- | C] ()(C:\Users\Ghost\Documents\H??kuvat.mds) -- C:\Users\Ghost\Documents\H¦¦kuvat.mds
[2011.12.18 13:48:11 | 2439,053,312 | ---- | M] ()(C:\Users\Ghost\Documents\H??kuvat.iso) -- C:\Users\Ghost\Documents\H¦¦kuvat.iso
[2011.12.18 13:45:00 | 2439,053,312 | ---- | C] ()(C:\Users\Ghost\Documents\H??kuvat.iso) -- C:\Users\Ghost\Documents\H¦¦kuvat.iso

< End of report >


OTL Extras logfile created on: 22.7.2013 12:29:14 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ghost\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = )
Locale: 0000040b | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,50 Gb Available Physical Memory | 62,47% Memory free
8,00 Gb Paging File | 6,06 Gb Available in Paging File | 75,74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 151,46 Gb Total Space | 13,45 Gb Free Space | 8,88% Space Free | Partition Type: NTFS
Drive D: | 322,26 Gb Total Space | 14,06 Gb Free Space | 4,36% Space Free | Partition Type: NTFS
Drive E: | 122,44 Gb Total Space | 4,31 Gb Free Space | 3,52% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 12,90 Gb Free Space | 2,77% Space Free | Partition Type: NTFS

Computer Name: PC-GHOST | User Name: Ghost | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = jsfile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = jsfile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Waterfox\waterfox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Ohjelmat\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "D:\Ohjelmat\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Ohjelmat\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Ohjelmat\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Ohjelmat\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "D:\Ohjelmat\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Ohjelmat\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Ohjelmat\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06CC555C-3C0C-436C-93DB-04F9F76D1C36}" = lport=7935 | protocol=6 | dir=in | name=adobe flash builder 4.5 |
"{0A70EC99-BEB9-4218-92A6-776F511DA93C}" = lport=57174 | protocol=17 | dir=in | name=pando media booster |
"{27563C54-340D-4262-A34A-1C1A079236A1}" = lport=67 | protocol=17 | dir=in | name=rtldhcp-port |
"{367FE8BF-00FF-4C90-BC50-5CD00B6EA122}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{4191DCCA-516F-4E05-BCD4-AC94E46AFE8A}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{65F2905A-72AD-49F1-A84F-D273CE56225A}" = lport=1542 | protocol=17 | dir=in | name=realtek wps udp prot |
"{758A484D-F095-4505-AA9D-27B67749AC57}" = lport=57174 | protocol=6 | dir=in | name=pando media booster |
"{7DD10E04-D5CB-49DC-82BB-109E9946EBF9}" = lport=53 | protocol=17 | dir=in | name=realtek ap udp prot |
"{83F1A3EE-82BC-449A-B808-A868A80F9559}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{87DF290E-1A24-43EC-803D-4C919BCB83CE}" = lport=53 | protocol=17 | dir=in | name=rtldns-port-2 |
"{8B3C5C6A-F112-4B4D-96A8-8CF4613744E2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{9524594B-6142-4502-805A-DDAA7D025C77}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{9D85C712-EB00-4302-BF2E-720CC74AA321}" = lport=53 | protocol=6 | dir=in | name=rtldns-port |
"{AE22A9D7-E312-4B98-914D-96CFE9F0A944}" = lport=57174 | protocol=6 | dir=in | name=pando media booster |
"{AFF98C5D-7CE8-492A-BF10-BC94E0F50C90}" = lport=68 | protocol=17 | dir=in | name=rtldhcp-port-2 |
"{C684B152-1C7F-4B56-8E0B-EDC774D1C1CA}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{E0780ECD-304B-4CD8-8701-EA53A80435F5}" = lport=1542 | protocol=6 | dir=in | name=realtek wps tcp prot |
"{E0EE8052-241B-412E-B6C6-E1DD5B10FF33}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{E97ED8BA-0E2E-4CA5-B470-32C3C9A83740}" = lport=57174 | protocol=17 | dir=in | name=pando media booster |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00838FBB-4128-4A5E-B989-9F4E50A2EDF3}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\machinarium demo\machinarium.exe |
"{00DDBAFE-536B-48D7-95A6-050E291EAE2E}" = protocol=17 | dir=in | app=c:\users\ghost\appdata\roaming\dropbox\bin\dropbox.exe |
"{051B2617-8123-4BB2-8709-C8E35AE13D26}" = protocol=6 | dir=in | app=c:\users\ghost\appdata\roaming\dropbox\bin\dropbox.exe |
"{094AD716-F39E-4D6E-98FD-0123BABC27C5}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{09ABA972-4575-47F3-A858-F964E8766703}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{0C099537-408E-4212-9496-16B1049CBE12}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{0E0CA6C0-D70D-459D-A559-2D553BE190C0}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{0E0F4078-2021-47DB-8E0F-CC6C125BEF19}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\homefront - dev diary 2\smp.exe |
"{0E8DB0E8-5887-46B5-BE05-08B61F0DABD2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{0F1FBB60-06FB-4E7C-A1F7-F613875C3CCB}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 teaser\smp.exe |
"{132DB705-FC2C-4E4B-8EBA-89D3EB816D2F}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{154AD296-8D34-4552-A6E2-DF6B131179B1}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 teaser\smp.exe |
"{1D0E0CD0-F670-4E19-8A44-0BE1F383FDA8}" = protocol=17 | dir=in | app=d:\ohjelmat\utorrent\utorrent.exe |
"{1E3A81A7-CA1A-4647-B332-8BDA11F582CC}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\brink - teaser trailer\smp.exe |
"{24C7CB00-087A-4648-A88E-8A860E85F965}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{2C3AF0F5-C2C8-4674-AD8D-72859357B269}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{2C77B1C7-3A84-4A37-AED6-FBD2539958E3}" = dir=in | app=c:\program files\soluto\solutoupdateservice.exe |
"{2CD547DB-16F7-43C0-B5B1-AE939AD7EC71}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 co-op trailer\smp.exe |
"{2DF622BD-C3FE-4A63-B760-83A1DF1FC562}" = protocol=6 | dir=in | app=d:\ohjelmat\adobe\adobe flash builder 4.5\flashbuilder.exe |
"{317028D7-D29F-4D2F-B751-F2772F2D28AD}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\ghoulone\source sdk base 2007\hl2.exe |
"{3BA204D8-0EE7-4319-AB8F-50D3E6AD928F}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{4525E3F7-1350-44F9-B545-AFF47ECC1986}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{453DD4BB-01EC-4C8E-8754-8671AEF234BB}" = dir=in | app=c:\program files\soluto\solutoservice.exe |
"{454D9169-8BC9-43EF-A520-8D26E7067F02}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\bastion demo\bastion.exe |
"{484F90B3-7594-4CFC-B2DD-06B5922D0F9E}" = dir=in | app=d:\ohjelmat\itunes\itunes.exe |
"{49A750B5-A094-494B-AE35-2C2EE25A0F30}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{49BA3119-C81A-4AB8-8C93-F63A7D5F284C}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{4AF77EDD-4E0E-437A-8757-BA0243D6D1C3}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\ghoulone\source sdk base 2007\hl2.exe |
"{4F08461C-48CD-4BB1-B65D-9FDA78298B89}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{4F1A7BD1-951A-47EF-9A28-FEFB80709E9D}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{5134357F-37BF-4805-A11F-171340B6774D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{56B6313D-7309-4F51-9EAD-2C1BD510D61D}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\the undergarden\theundergarden.exe |
"{57ECF4DE-109E-4EEF-B4C6-9B6977B7DB93}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\swarm.exe |
"{6124EDB5-04E7-46AC-B354-DB8A928AC6A4}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 co-op trailer\smp.exe |
"{6FC4426E-0ADC-4024-8AE9-E56FC37CE493}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\srcds.exe |
"{6FF52BB1-DA78-42E3-82D3-C913D3B9E0D0}" = protocol=17 | dir=in | app=d:\ohjelmat\adobe\adobe flash builder 4.5\flashbuilder.exe |
"{75A811D9-86B8-4CB3-BB59-2D2A4741B127}" = protocol=6 | dir=in | app=d:\ohjelmat\utorrent\utorrent.exe |
"{7668F4E6-0699-40AC-BFB8-AD6DA36CD472}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\nimbus\nimbus.exe |
"{78351D70-88F3-40C6-AAF3-D7E29A6AA8D4}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\the undergarden\theundergarden.exe |
"{7CD132D7-4D45-4164-A72B-3B66E95EDDA8}" = dir=in | app=c:\program files (x86)\realtek\11n usb wireless lan utility\rtldhcp.exe |
"{7E040714-C506-44AD-8618-585668A6F078}" = protocol=6 | dir=in | app=c:\program files (x86)\realtek\11n usb wireless lan utility\rtwlan.exe |
"{80D867EE-73AD-4E96-95AF-606D98DB5156}" = dir=in | app=c:\program files\soluto\soluto.exe |
"{8359F027-4CEC-4973-BD1E-17C364CFB3C5}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{85915FB6-9B66-456F-8936-9B2147DD00C2}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{85DF9D7B-8A32-479B-AB55-556845504162}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{8813CD25-99E7-4ACA-ABB8-5F2C18E5A464}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{898060F9-9DF4-4156-B131-B20AF02E06AF}" = dir=in | app=c:\program files\soluto\solutoconsole.exe |
"{8CB81D74-8BCC-43EB-AB7E-1C6F0F975EC9}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\machinarium demo\machinarium.exe |
"{8E2800D8-F88F-4A3A-8546-7E89EB074385}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8F6A5ED9-4405-4F90-86CD-4335CFB40403}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |
"{92EF1CEE-1768-49AD-930D-BDA3EE7FF098}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{931168A0-101B-4CD9-A260-6FF14FAF75BC}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{93C2AEC8-2AC6-4C46-92D4-4528FF7B1A43}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{9731D42A-AB7F-4570-BE22-FA40F7516CE3}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{9876CB94-5273-489F-9895-93B9F7C709EF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{99EC7B45-2D2A-490F-A7FE-6FEEB177B81D}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steam.exe |
"{A8A4DBD4-8FBF-4A61-B7A5-8E9A278ED846}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\deus ex human revolution gameplay trailer\smp.exe |
"{ABA648A4-5FC3-402B-B99C-5FC3973DCB76}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{B1C99F76-7935-4AA5-A2DE-897CB5C9C760}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{B1F499DF-D4A2-4B39-A4D2-70A6A6E20752}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B305EF28-9E7E-4D0E-BCB8-CE9A04F9EC1D}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\homefront - dev diary 2\smp.exe |
"{B744E4DE-8C82-4963-BB9F-D05C93852AFD}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\red faction armageddon trailer\smp.exe |
"{B9DB07BA-736B-4567-B5D6-42C98A8DC051}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |
"{C0E7516A-A643-4E6E-8FDC-CFBF918EFD5A}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{C30DB6FA-65AE-42E9-96CF-BEE104060F9F}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\braid\braid.exe |
"{C529B113-FC0F-405A-A97D-D1C297873760}" = protocol=17 | dir=in | app=d:\ohjelmat\streamtorrent 1.0\streamtorrent.exe |
"{CE8F9BC7-8337-49D3-B915-4984D58CF0AC}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\deus ex human revolution gameplay trailer\smp.exe |
"{CF7C7306-647A-4ACE-8096-49824C98346A}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{CFACB63D-3F2B-4353-A78F-8AC88206E3D3}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\space marine\smp.exe |
"{D3C3C849-F815-40A7-B382-9D94F55729E9}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\srcds.exe |
"{D632879A-39B9-40B6-99F1-84366C2A77D1}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\red faction armageddon trailer\smp.exe |
"{D6E4027F-8E51-4512-A337-244A7A274871}" = protocol=6 | dir=in | app=d:\ohjelmat\streamtorrent 1.0\streamtorrent.exe |
"{DBFC8786-F4BC-472B-9AC0-2A13E12A5BCA}" = protocol=17 | dir=in | app=c:\program files (x86)\realtek\11n usb wireless lan utility\rtwlan.exe |
"{DFA59D44-E8E0-420F-BD0C-3AF2F820C940}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\space marine\smp.exe |
"{E4441AA5-B30A-42EA-B941-42BA2B9A80A4}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\bastion demo\bastion.exe |
"{F1FAB12F-9E6D-4249-8BB0-F48F722B0974}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steam.exe |
"{F2958A22-DFCA-42EE-98E8-05363F1F4B11}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\brink - teaser trailer\smp.exe |
"{F4A7FC6F-D6CE-41EB-83A8-A174DAD8A06B}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{F5B34EB2-3E7C-4B0C-8284-9271FC0A0201}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F798A0C9-05D5-4BAC-A3E4-91F0FB03C4DA}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{F89FBA8D-F606-4BB4-9FD2-4543F5329334}" = dir=in | app=c:\program files\soluto\solutocleanup.exe |
"{FC4155BE-423B-4A38-B668-3A0EF30B0730}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\swarm.exe |
"{FC715B17-F79F-4715-B898-A3BD058F97B4}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\nimbus\nimbus.exe |
"{FDCD7243-76A5-4E82-9206-3726581576AB}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\braid\braid.exe |
"TCP Query User{04B32F37-E0B9-4738-B936-CB2C052760E8}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=6 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"TCP Query User{1BB2142A-39DA-424F-ADAA-57913E6BF9DC}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"TCP Query User{227ADC52-2516-48D4-9CC6-DABFD3AF1842}C:\program files (x86)\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe |
"TCP Query User{23CD3322-EDB7-4E4B-928D-821EB22D4167}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{37921191-AEA0-43AD-B8C6-D39787A2114F}D:\ohjelmat\miranda im\miranda32.exe" = protocol=6 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"TCP Query User{3D16CBCA-2141-40B0-BD92-83F9CFC8746C}D:\ohjelmat\miranda im\miranda32.exe" = protocol=6 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"TCP Query User{57DA972D-E438-42BE-B353-D92A9D168024}D:\pelit\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\pelit\world_of_tanks\wotlauncher.exe |
"TCP Query User{5ADF9970-4E07-46E6-BDD0-BD80D89D2BAD}D:\ohjelmat\miranda im\miranda64.exe" = protocol=6 | dir=in | app=d:\ohjelmat\miranda im\miranda64.exe |
"TCP Query User{647E04C0-617B-44FD-BBB2-D604D13D89E8}D:\ohjelmat\winamp\winamp.exe" = protocol=6 | dir=in | app=d:\ohjelmat\winamp\winamp.exe |
"TCP Query User{67BA863E-FF18-4841-B77B-9D376E5E91AE}D:\ohjelmat\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=d:\ohjelmat\sopcast\adv\sopadver.exe |
"TCP Query User{6E5BBDA9-2739-4105-AF33-9D470F7A3EBD}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=6 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"TCP Query User{7824DFF4-C92E-4345-A5C4-274B3BDE5BB0}D:\ohjelmat\sopcast\sopcast.exe" = protocol=6 | dir=in | app=d:\ohjelmat\sopcast\sopcast.exe |
"TCP Query User{923BC80F-935B-4EEB-87B4-BDDC5CC0FED9}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"TCP Query User{9D07418D-3E9D-4035-9F4B-00D56E9AAEEA}D:\pelit\magic workstation\mwsplay.exe" = protocol=6 | dir=in | app=d:\pelit\magic workstation\mwsplay.exe |
"TCP Query User{9DE40345-20F9-4ACE-BC71-94A50D7567EF}D:\ohjelmat\spotify\spotify.exe" = protocol=6 | dir=in | app=d:\ohjelmat\spotify\spotify.exe |
"TCP Query User{C3E5F13C-9B38-46CC-A2CD-346BDA4D8A96}C:\program files (x86)\streamtorrent 1.0\streamtorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\streamtorrent 1.0\streamtorrent.exe |
"TCP Query User{C83B0CE5-3318-4DF5-93C6-44AD4A93000E}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{C8AFE3DB-13D3-40D7-A5D8-E1455B08502C}D:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=d:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{D515D45B-B5DE-4B8E-8C0E-CF649991ACBE}D:\pelit\wings 2\bin\wings.exe" = protocol=6 | dir=in | app=d:\pelit\wings 2\bin\wings.exe |
"TCP Query User{DC1CB7E6-8BC5-49B0-B676-9231A568CBE2}C:\program files (x86)\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe |
"TCP Query User{E18B7829-295C-4269-B4A6-2DBFE0558D03}D:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=d:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{F35E2854-381C-4D8D-A3CB-807034FFBC67}C:\program files (x86)\mektek.net\mtx\mtx.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mektek.net\mtx\mtx.exe |
"TCP Query User{F934AA10-88D6-466D-848B-EA2DA2A26280}D:\pelit\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=d:\pelit\world_of_tanks\worldoftanks.exe |
"UDP Query User{04E25E59-E42B-4185-A473-08DC573FEF17}D:\pelit\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=d:\pelit\world_of_tanks\worldoftanks.exe |
"UDP Query User{0BB4E2A0-3908-40F9-B410-CA560EDD4563}D:\pelit\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\pelit\world_of_tanks\wotlauncher.exe |
"UDP Query User{0EF1A7C6-8A0F-475F-BE3E-4113916FDF59}D:\pelit\magic workstation\mwsplay.exe" = protocol=17 | dir=in | app=d:\pelit\magic workstation\mwsplay.exe |
"UDP Query User{130DF8B3-CB7C-462D-9B0C-2A68D534FA49}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"UDP Query User{1AB34845-40CE-4214-A2EE-F45A8F407DBF}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{209AB83A-089A-4C56-A85D-438A564131A9}D:\ohjelmat\miranda im\miranda64.exe" = protocol=17 | dir=in | app=d:\ohjelmat\miranda im\miranda64.exe |
"UDP Query User{2A04F2A5-1E57-43A7-B55E-B39CACF1A104}D:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=d:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{609C844D-497C-4D21-A035-C5500512E03E}D:\ohjelmat\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=d:\ohjelmat\sopcast\adv\sopadver.exe |
"UDP Query User{63F43DA4-49B6-4E59-A169-32A7ED6F82F8}C:\program files (x86)\mektek.net\mtx\mtx.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mektek.net\mtx\mtx.exe |
"UDP Query User{668D1C9C-7D6A-444C-B83B-A7967E30BD06}C:\program files (x86)\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe |
"UDP Query User{7B578158-51C4-4463-A2D5-A4DC4E1F163D}D:\ohjelmat\sopcast\sopcast.exe" = protocol=17 | dir=in | app=d:\ohjelmat\sopcast\sopcast.exe |
"UDP Query User{A213D92D-E3AA-4E6E-BFCF-D3D174E723B8}C:\program files (x86)\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe |
"UDP Query User{A5E9853B-41FA-4CDC-B18F-5ED07C88968F}C:\program files (x86)\streamtorrent 1.0\streamtorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\streamtorrent 1.0\streamtorrent.exe |
"UDP Query User{AD43633A-D31D-4076-9BAB-F8BF883F84AF}D:\pelit\wings 2\bin\wings.exe" = protocol=17 | dir=in | app=d:\pelit\wings 2\bin\wings.exe |
"UDP Query User{ADAB22D9-20BD-4F92-89B1-2B99ECC671A3}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=17 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"UDP Query User{B71645CA-0944-4B07-A211-DE7FA7523C0C}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{CCC2E477-4A44-4412-BC3D-84B0FFD4E097}D:\ohjelmat\winamp\winamp.exe" = protocol=17 | dir=in | app=d:\ohjelmat\winamp\winamp.exe |
"UDP Query User{CF24B148-EE8E-4444-A16A-D7D46CF20083}D:\ohjelmat\miranda im\miranda32.exe" = protocol=17 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"UDP Query User{D1610428-648E-48B9-8A04-6A9F7503B2F1}D:\ohjelmat\miranda im\miranda32.exe" = protocol=17 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"UDP Query User{D4FE3F32-D846-4712-8313-8C6527CE5D71}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=17 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"UDP Query User{E07113BF-6472-4124-9ABE-4483B08BCB6B}D:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=d:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{EAF84206-B1A1-4523-B032-27B7DFA5FD89}D:\ohjelmat\spotify\spotify.exe" = protocol=17 | dir=in | app=d:\ohjelmat\spotify\spotify.exe |
"UDP Query User{FDB2711D-6977-4AE0-A3F9-D3BCCED3B24C}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08347912-0AA5-C85E-BC02-416568E741B4}" = AMD Drag and Drop Transcoding
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{129C5584-DB98-4A98-B28F-299C45E1E355}" = Microsoft Camera Codec Pack
"{1444D2EE-C7AD-44A8-844F-2634B49353D1}" = Logitech Gaming Software 5.10
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = Media Player Classic - Home Cinema v1.4.2499.0 x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{36E47D1C-2AD0-429C-8C1A-91A23C949B54}" = Soluto
"{3987279A-3504-2916-D063-741B910F0747}" = AMD Accelerated Video Transcoding
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{46DA7FD9-8BC1-7BA8-98D1-27F46647871B}" = AMD Catalyst Install Manager
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}" = IconHandler 64 bit
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{63CE6C32-1EB3-4C51-89FC-9FD96A661A9C}" = AMD Media Foundation Decoders
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{66C10F29-31F0-4A9B-B2CF-465F488AE086}" = CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit
"{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F05E704-30A6-421A-97A7-8EEB1C7FF011}" = Corel Shell Extension - 64Bit
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUS_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUS_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUS_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AA72DFB8-BA38-49C9-B5A4-A95FD62641F8}" = BOINC
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{BCF07271-A853-4D3A-B668-4B752174CAA8}" = iTunes
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{D759947B-8C5A-4480-B0DB-FC391F061C85}" = Adobe Photoshop Lightroom 4.3 64-bit
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FD7DEB7B-8CEA-44E5-AB2D-7C66786C0563}" = Waterfox
"62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F" = Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Autopano Giga" = Autopano Giga
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.58
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"SP6" = Logitech SetPoint 6.15

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Chromium" = Chromium
"Dropbox" = Dropbox
"Hawken" = Hawken
"Limbo" = LIMBO
"SOE-C:/Users/Public/Sony Online Entertainment/Installed Games/PlanetSide 2 PSG" = gamelauncher-ps2-psg
"soe-PlanetSide 2 PSG" = PlanetSide 2
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 22.7.2013 5:20:05 | Computer Name = PC-Ghost | Source = Application Error | ID = 1000
Description = Faulting application name: Spyder3Utility.exe, version: 1.1.9.1, time
stamp: 0x4b6afb1e Faulting module name: Spyder3Utility.exe, version: 1.1.9.1, time
stamp: 0x4b6afb1e Exception code: 0xc0000005 Fault offset: 0x000c52aa Faulting process
id: 0xdb4 Faulting application start time: 0x01ce86bca634e4de Faulting application
path: C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe Faulting
module path: C:\Program Files (x86)\Datacolor\Spyder3Pro\Utility\Spyder3Utility.exe
Report
Id: e4a5d916-f2af-11e2-b44d-003018a769c1

Error - 22.7.2013 5:27:39 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:27:39 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:27:40 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:28:11 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:28:11 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:28:11 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:28:29 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:28:29 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 5:28:30 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

[ System Events ]
Error - 22.7.2013 5:41:56 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:41:58 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:01 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:06 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:10 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:11 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:12 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:15 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:18 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 5:42:18 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.


< End of report >


Farbar Service Scanner Version: 13-07-2013
Ran by Ghost (administrator) on 22-07-2013 at 12:44:34
Running from "C:\Users\Ghost\Desktop"
Windows 7 Ultimate Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============


Windows Update:
============
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is OK.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.


Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============

Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll
[2009-07-14 02:21] - [2009-07-14 04:41] - 0025600 ____A (Microsoft Corporation)

C:\Windows\System32\drivers\nsiproxy.sys
[2009-07-14 02:21] - [2009-07-14 02:21] - 0024576 ____A (Microsoft Corporation)

C:\Windows\System32\dhcpcore.dll
[2011-02-23 13:58] - [2010-11-20 16:26] - 0317952 ____A (Microsoft Corporation)

C:\Windows\System32\drivers\afd.sys
[2012-02-16 18:14] - [2011-12-28 06:59] - 0498688 ____A (Microsoft Corporation)

C:\Windows\System32\drivers\tdx.sys
[2011-02-23 13:58] - [2010-11-20 12:21] - 0119296 ____A (Microsoft Corporation)

C:\Windows\System32\Drivers\tcpip.sys
[2013-06-15 13:10] - [2013-05-08 09:39] - 1910632 ____A (Microsoft Corporation)

C:\Windows\System32\dnsrslvr.dll
[2011-04-16 17:30] - [2011-03-03 09:24] - 0183296 ____A (Microsoft Corporation)

C:\Windows\System32\mpssvc.dll
[2011-02-23 13:58] - [2010-11-20 16:26] - 0828416 ____A (Microsoft Corporation)

C:\Windows\System32\bfe.dll
[2011-02-23 13:57] - [2010-11-20 16:25] - 0705024 ____A (Microsoft Corporation)

C:\Windows\System32\drivers\mpsdrv.sys
[2009-07-14 03:08] - [2009-07-14 03:08] - 0077312 ____A (Microsoft Corporation)

C:\Windows\System32\SDRSVC.dll
[2011-02-23 13:57] - [2010-11-20 16:27] - 0170496 ____A (Microsoft Corporation)

C:\Windows\System32\vssvc.exe
[2011-02-23 13:58] - [2010-11-20 16:25] - 1600512 ____A (Microsoft Corporation)

C:\Windows\System32\wscsvc.dll
[2009-07-14 02:48] - [2009-07-14 04:41] - 0097280 ____A (Microsoft Corporation)

C:\Windows\System32\wbem\WMIsvc.dll
[2009-07-14 02:47] - [2009-07-14 04:41] - 0242688 ____A (Microsoft Corporation)


ATTENTION!=====> C:\Windows\System32\wuaueng.dll FILE IS MISSING AND SHOULD BE RESTORED.

C:\Windows\System32\qmgr.dll
[2011-02-23 13:58] - [2010-11-20 16:27] - 0849920 ____A (Microsoft Corporation)

C:\Windows\System32\es.dll
[2009-07-14 03:00] - [2009-07-14 04:40] - 0402944 ____A (Microsoft Corporation)

C:\Windows\System32\cryptsvc.dll
[2013-06-15 13:10] - [2013-05-13 08:51] - 0184320 ____A (Microsoft Corporation)

C:\Program Files\Windows Defender\MpSvc.dll
[2013-07-11 20:44] - [2013-05-27 08:50] - 1011712 ____A (Microsoft Corporation)

C:\Windows\System32\ipnathlp.dll
[2009-07-14 03:10] - [2009-07-14 04:41] - 0359424 ____A (Microsoft Corporation)

C:\Windows\System32\iphlpsvc.dll
[2012-11-16 14:21] - [2012-10-03 20:42] - 0569344 ____A (Microsoft Corporation)

C:\Windows\System32\svchost.exe
[2009-07-14 02:31] - [2009-07-14 04:39] - 0027136 ____A (Microsoft Corporation)

C:\Windows\System32\rpcss.dll
[2011-02-23 13:58] - [2010-11-20 16:27] - 0512000 ____A (Microsoft Corporation)



**** End of log ****
  • 0

#5
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
AVG had a false positive on vbalsgrid6.ocx and probably removed it.
download, Save and install the Microsoft Visual Basic Common Controls http://www.microsoft...s.aspx?id=10019

Then see if MBAM will run.

aswMBR found this:

09:55:02.049 Service Tablet2k C:\Windows\"%SystemRoot%\System32\Drivers\Tablet2k.sys" **LOCKED** 123

This is a very odd path so it is suspicious. Can you submit the file to virustotal.com?

TDSS Killer is showing all files as unsigned so something is wrong in verification. This is confirmed by the error:

Error - 22.7.2013 5:27:39 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .



Run the Fixit here: http://support.micro....com/kb/2328240


Error - 22.7.2013 5:41:56 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.


This is not a good thing. Let's see if running Disk Check will fix it:

1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs. Right click on System and Clear Log, Clear. Repeat for Application.

Reboot.

The disk check will run and will probably take an hour or more to finish. I see you have multiple drives so have it do a disk check on each drive as it is difficult to know which drive Windows means. It should not need to reboot on the other drives.

Let's try sfc again.

Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).
sfc  /scannow

(This will check your critical system files. Does this finish without complaint? IF it says it couldn't fix everything then:

Copy the next two lines:

findstr /c:"[SR]" \windows\logs\cbs\cbs.log > \windows\logs\cbs\junk.txt
notepad \windows\logs\cbs\junk.txt

Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Right click and Paste or Edit then Paste and the copied line should appear.
Hit Enter. Copy and paste the text from notepad or if it is too big, just attach the file c:\windows\logs\cbs\junk.txt.)

Not sure what happened to my adwcleaner post. Just click on Delete.


Copy the text in the code box:

DRIVES
/md5start
wuaueng.dll
vbalsgrid6.ocx
/md5stop

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

Select the All option in the Extra Registry group then Run Scan.

You should get two logs. Please copy and paste both of them.
  • 0

#6
klmk

klmk

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Quick update before running Disk Check. The VB Common Controls didn't help. Had an instance in systray again, tried to launch, same error. Uninstalled via CCleaner and re-installed, same error. Also cannot find Tablet2k.sys, not in the path mentioned. A search on C: also seems to hang after a bit, the green progress indicator in the address bar reaches almost but not quite the end and no results are shown.
  • 0

#7
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
OK. Maybe things will work better after the disk check.
  • 0

#8
klmk

klmk

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
junk.txt, the log from adwcleaner and an OTL log:

2013-07-22 12:12:29, Info CSI 00000009 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:29, Info CSI 0000000a [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:31, Info CSI 0000000c [SR] Verify complete
2013-07-22 12:12:32, Info CSI 0000000d [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:32, Info CSI 0000000e [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:34, Info CSI 00000010 [SR] Verify complete
2013-07-22 12:12:34, Info CSI 00000011 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:34, Info CSI 00000012 [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:36, Info CSI 00000014 [SR] Verify complete
2013-07-22 12:12:36, Info CSI 00000015 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:36, Info CSI 00000016 [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:38, Info CSI 00000018 [SR] Verify complete
2013-07-22 12:12:39, Info CSI 00000019 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:39, Info CSI 0000001a [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:41, Info CSI 0000001c [SR] Verify complete
2013-07-22 12:12:41, Info CSI 0000001d [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:41, Info CSI 0000001e [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:43, Info CSI 00000020 [SR] Verify complete
2013-07-22 12:12:44, Info CSI 00000021 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:44, Info CSI 00000022 [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:47, Info CSI 00000024 [SR] Verify complete
2013-07-22 12:12:47, Info CSI 00000025 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:47, Info CSI 00000026 [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:49, Info CSI 00000028 [SR] Verify complete
2013-07-22 12:12:49, Info CSI 00000029 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:49, Info CSI 0000002a [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:52, Info CSI 0000002c [SR] Verify complete
2013-07-22 12:12:52, Info CSI 0000002d [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:52, Info CSI 0000002e [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:55, Info CSI 00000030 [SR] Verify complete
2013-07-22 12:12:55, Info CSI 00000031 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:55, Info CSI 00000032 [SR] Beginning Verify and Repair transaction
2013-07-22 12:12:57, Info CSI 00000034 [SR] Verify complete
2013-07-22 12:12:57, Info CSI 00000035 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:12:57, Info CSI 00000036 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:00, Info CSI 00000038 [SR] Verify complete
2013-07-22 12:13:00, Info CSI 00000039 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:00, Info CSI 0000003a [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:03, Info CSI 0000003c [SR] Verify complete
2013-07-22 12:13:03, Info CSI 0000003d [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:03, Info CSI 0000003e [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:04, Info CSI 00000040 [SR] Verify complete
2013-07-22 12:13:04, Info CSI 00000041 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:04, Info CSI 00000042 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:06, Info CSI 00000044 [SR] Verify complete
2013-07-22 12:13:06, Info CSI 00000045 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:06, Info CSI 00000046 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:09, Info CSI 00000048 [SR] Verify complete
2013-07-22 12:13:09, Info CSI 00000049 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:09, Info CSI 0000004a [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:13, Info CSI 0000004d [SR] Verify complete
2013-07-22 12:13:13, Info CSI 0000004e [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:13, Info CSI 0000004f [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:18, Info CSI 00000053 [SR] Verify complete
2013-07-22 12:13:18, Info CSI 00000054 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:18, Info CSI 00000055 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:21, Info CSI 00000057 [SR] Verify complete
2013-07-22 12:13:21, Info CSI 00000058 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:21, Info CSI 00000059 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:25, Info CSI 0000005e [SR] Verify complete
2013-07-22 12:13:25, Info CSI 0000005f [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:25, Info CSI 00000060 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:28, Info CSI 00000062 [SR] Verify complete
2013-07-22 12:13:28, Info CSI 00000063 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:28, Info CSI 00000064 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:32, Info CSI 00000066 [SR] Verify complete
2013-07-22 12:13:32, Info CSI 00000067 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:32, Info CSI 00000068 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:38, Info CSI 0000008d [SR] Verify complete
2013-07-22 12:13:38, Info CSI 0000008e [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:38, Info CSI 0000008f [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:42, Info CSI 00000091 [SR] Verify complete
2013-07-22 12:13:43, Info CSI 00000092 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:43, Info CSI 00000093 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:47, Info CSI 00000095 [SR] Verify complete
2013-07-22 12:13:47, Info CSI 00000096 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:47, Info CSI 00000097 [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:51, Info CSI 00000099 [SR] Verify complete
2013-07-22 12:13:51, Info CSI 0000009a [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:51, Info CSI 0000009b [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:54, Info CSI 0000009d [SR] Verify complete
2013-07-22 12:13:55, Info CSI 0000009e [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:55, Info CSI 0000009f [SR] Beginning Verify and Repair transaction
2013-07-22 12:13:58, Info CSI 000000a1 [SR] Verify complete
2013-07-22 12:13:58, Info CSI 000000a2 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:13:58, Info CSI 000000a3 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:02, Info CSI 000000a5 [SR] Verify complete
2013-07-22 12:14:02, Info CSI 000000a6 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:02, Info CSI 000000a7 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:08, Info CSI 000000ca [SR] Verify complete
2013-07-22 12:14:08, Info CSI 000000cb [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:08, Info CSI 000000cc [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:14, Info CSI 000000ce [SR] Verify complete
2013-07-22 12:14:14, Info CSI 000000cf [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:14, Info CSI 000000d0 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:21, Info CSI 000000d2 [SR] Verify complete
2013-07-22 12:14:21, Info CSI 000000d3 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:21, Info CSI 000000d4 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:27, Info CSI 000000d6 [SR] Verify complete
2013-07-22 12:14:27, Info CSI 000000d7 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:27, Info CSI 000000d8 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:33, Info CSI 000000dc [SR] Verify complete
2013-07-22 12:14:33, Info CSI 000000dd [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:33, Info CSI 000000de [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:36, Info CSI 000000e0 [SR] Verify complete
2013-07-22 12:14:36, Info CSI 000000e1 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:36, Info CSI 000000e2 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:38, Info CSI 000000e4 [SR] Verify complete
2013-07-22 12:14:38, Info CSI 000000e5 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:38, Info CSI 000000e6 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:39, Info CSI 000000e8 [SR] Verify complete
2013-07-22 12:14:39, Info CSI 000000e9 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:39, Info CSI 000000ea [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:41, Info CSI 000000ec [SR] Verify complete
2013-07-22 12:14:41, Info CSI 000000ed [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:41, Info CSI 000000ee [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:46, Info CSI 000000fa [SR] Verify complete
2013-07-22 12:14:46, Info CSI 000000fb [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:46, Info CSI 000000fc [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:50, Info CSI 00000105 [SR] Verify complete
2013-07-22 12:14:50, Info CSI 00000106 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:50, Info CSI 00000107 [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:51, Info CSI 00000109 [SR] Verify complete
2013-07-22 12:14:51, Info CSI 0000010a [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:51, Info CSI 0000010b [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:54, Info CSI 0000010d [SR] Verify complete
2013-07-22 12:14:54, Info CSI 0000010e [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:54, Info CSI 0000010f [SR] Beginning Verify and Repair transaction
2013-07-22 12:14:56, Info CSI 00000111 [SR] Verify complete
2013-07-22 12:14:56, Info CSI 00000112 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:14:56, Info CSI 00000113 [SR] Beginning Verify and Repair transaction
2013-07-22 12:15:01, Info CSI 00000116 [SR] Verify complete
2013-07-22 12:15:02, Info CSI 00000117 [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:15:02, Info CSI 00000118 [SR] Beginning Verify and Repair transaction
2013-07-22 12:15:09, Info CSI 0000011b [SR] Verify complete
2013-07-22 12:15:09, Info CSI 0000011c [SR] Verifying 100 (0x0000000000000064) components
2013-07-22 12:15:09, Info CSI 0000011d [SR] Beginning Verify and Repair transaction
2013-07-23 00:15:58, Info CSI 00000009 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:15:58, Info CSI 0000000a [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:01, Info CSI 0000000c [SR] Verify complete
2013-07-23 00:16:01, Info CSI 0000000d [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:01, Info CSI 0000000e [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:03, Info CSI 00000010 [SR] Verify complete
2013-07-23 00:16:03, Info CSI 00000011 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:03, Info CSI 00000012 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:05, Info CSI 00000014 [SR] Verify complete
2013-07-23 00:16:06, Info CSI 00000015 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:06, Info CSI 00000016 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:08, Info CSI 00000018 [SR] Verify complete
2013-07-23 00:16:08, Info CSI 00000019 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:08, Info CSI 0000001a [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:10, Info CSI 0000001c [SR] Verify complete
2013-07-23 00:16:10, Info CSI 0000001d [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:10, Info CSI 0000001e [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:12, Info CSI 00000020 [SR] Verify complete
2013-07-23 00:16:12, Info CSI 00000021 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:12, Info CSI 00000022 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:15, Info CSI 00000024 [SR] Verify complete
2013-07-23 00:16:15, Info CSI 00000025 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:15, Info CSI 00000026 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:17, Info CSI 00000028 [SR] Verify complete
2013-07-23 00:16:18, Info CSI 00000029 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:18, Info CSI 0000002a [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:20, Info CSI 0000002c [SR] Verify complete
2013-07-23 00:16:20, Info CSI 0000002d [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:20, Info CSI 0000002e [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:23, Info CSI 00000030 [SR] Verify complete
2013-07-23 00:16:23, Info CSI 00000031 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:23, Info CSI 00000032 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:25, Info CSI 00000034 [SR] Verify complete
2013-07-23 00:16:25, Info CSI 00000035 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:25, Info CSI 00000036 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:28, Info CSI 00000038 [SR] Verify complete
2013-07-23 00:16:28, Info CSI 00000039 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:28, Info CSI 0000003a [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:31, Info CSI 0000003c [SR] Verify complete
2013-07-23 00:16:31, Info CSI 0000003d [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:31, Info CSI 0000003e [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:32, Info CSI 00000040 [SR] Verify complete
2013-07-23 00:16:32, Info CSI 00000041 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:32, Info CSI 00000042 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:33, Info CSI 00000044 [SR] Verify complete
2013-07-23 00:16:34, Info CSI 00000045 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:34, Info CSI 00000046 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:37, Info CSI 00000048 [SR] Verify complete
2013-07-23 00:16:37, Info CSI 00000049 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:37, Info CSI 0000004a [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:41, Info CSI 0000004d [SR] Verify complete
2013-07-23 00:16:42, Info CSI 0000004e [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:42, Info CSI 0000004f [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:46, Info CSI 00000053 [SR] Verify complete
2013-07-23 00:16:46, Info CSI 00000054 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:46, Info CSI 00000055 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:49, Info CSI 00000057 [SR] Verify complete
2013-07-23 00:16:50, Info CSI 00000058 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:50, Info CSI 00000059 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:53, Info CSI 0000005e [SR] Verify complete
2013-07-23 00:16:53, Info CSI 0000005f [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:53, Info CSI 00000060 [SR] Beginning Verify and Repair transaction
2013-07-23 00:16:57, Info CSI 00000062 [SR] Verify complete
2013-07-23 00:16:57, Info CSI 00000063 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:16:57, Info CSI 00000064 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:00, Info CSI 00000066 [SR] Verify complete
2013-07-23 00:17:01, Info CSI 00000067 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:01, Info CSI 00000068 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:07, Info CSI 0000008d [SR] Verify complete
2013-07-23 00:17:07, Info CSI 0000008e [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:07, Info CSI 0000008f [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:11, Info CSI 00000091 [SR] Verify complete
2013-07-23 00:17:11, Info CSI 00000092 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:11, Info CSI 00000093 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:16, Info CSI 00000095 [SR] Verify complete
2013-07-23 00:17:16, Info CSI 00000096 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:16, Info CSI 00000097 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:20, Info CSI 00000099 [SR] Verify complete
2013-07-23 00:17:20, Info CSI 0000009a [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:20, Info CSI 0000009b [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:23, Info CSI 0000009d [SR] Verify complete
2013-07-23 00:17:23, Info CSI 0000009e [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:23, Info CSI 0000009f [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:27, Info CSI 000000a1 [SR] Verify complete
2013-07-23 00:17:27, Info CSI 000000a2 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:27, Info CSI 000000a3 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:31, Info CSI 000000a5 [SR] Verify complete
2013-07-23 00:17:31, Info CSI 000000a6 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:31, Info CSI 000000a7 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:36, Info CSI 000000ca [SR] Verify complete
2013-07-23 00:17:37, Info CSI 000000cb [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:37, Info CSI 000000cc [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:42, Info CSI 000000ce [SR] Verify complete
2013-07-23 00:17:42, Info CSI 000000cf [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:42, Info CSI 000000d0 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:49, Info CSI 000000d2 [SR] Verify complete
2013-07-23 00:17:49, Info CSI 000000d3 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:49, Info CSI 000000d4 [SR] Beginning Verify and Repair transaction
2013-07-23 00:17:55, Info CSI 000000d6 [SR] Verify complete
2013-07-23 00:17:56, Info CSI 000000d7 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:17:56, Info CSI 000000d8 [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:01, Info CSI 000000dc [SR] Verify complete
2013-07-23 00:18:01, Info CSI 000000dd [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:01, Info CSI 000000de [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:04, Info CSI 000000e0 [SR] Verify complete
2013-07-23 00:18:04, Info CSI 000000e1 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:04, Info CSI 000000e2 [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:06, Info CSI 000000e4 [SR] Verify complete
2013-07-23 00:18:06, Info CSI 000000e5 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:06, Info CSI 000000e6 [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:08, Info CSI 000000e8 [SR] Verify complete
2013-07-23 00:18:08, Info CSI 000000e9 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:08, Info CSI 000000ea [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:09, Info CSI 000000ec [SR] Verify complete
2013-07-23 00:18:10, Info CSI 000000ed [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:10, Info CSI 000000ee [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:15, Info CSI 000000fa [SR] Verify complete
2013-07-23 00:18:15, Info CSI 000000fb [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:15, Info CSI 000000fc [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:18, Info CSI 00000105 [SR] Verify complete
2013-07-23 00:18:18, Info CSI 00000106 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:18, Info CSI 00000107 [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:20, Info CSI 00000109 [SR] Verify complete
2013-07-23 00:18:20, Info CSI 0000010a [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:20, Info CSI 0000010b [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:23, Info CSI 0000010d [SR] Verify complete
2013-07-23 00:18:23, Info CSI 0000010e [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:23, Info CSI 0000010f [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:25, Info CSI 00000111 [SR] Verify complete
2013-07-23 00:18:25, Info CSI 00000112 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:25, Info CSI 00000113 [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:29, Info CSI 00000116 [SR] Verify complete
2013-07-23 00:18:30, Info CSI 00000117 [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:30, Info CSI 00000118 [SR] Beginning Verify and Repair transaction
2013-07-23 00:18:37, Info CSI 0000011b [SR] Verify complete
2013-07-23 00:18:37, Info CSI 0000011c [SR] Verifying 100 (0x0000000000000064) components
2013-07-23 00:18:37, Info CSI 0000011d [SR] Beginning Verify and Repair transaction


# AdwCleaner v2.306 - Logfile created 07/23/2013 at 00:10:09
# Updated 19/07/2013 by Xplode
# Operating system : Service Pack 1 (64 bits)
# User : Ghost - PC-GHOST
# Boot Mode : Normal
# Running from : C:\Users\Ghost\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Ghost\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Ghost\AppData\Local\AVG Security Toolbar
Folder Deleted : C:\Users\Ghost\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Ghost\AppData\LocalLow\AVG Security Toolbar
Folder Deleted : C:\Users\Ghost\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Ghost\AppData\LocalLow\ConduitEngine
Folder Deleted : C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\conduitEngine
Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
Key Deleted : HKCU\Software\AppDataLow\Toolbar
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\Software\AVG Secure Search
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6536801B-F50C-449B-9476-093DFD3789E3}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\BabylonHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Conduit.Engine
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT1269415
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}

***** [Internet Browsers] *****

-\\ Internet Explorer v

[OK] Registry is clean.

-\\ Mozilla Firefox v [Unable to get version]

File : C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\prefs.js

Deleted : user_pref("avg.install.installDirPath", "C:\\ProgramData\\AVG Secure Search\\10.2.0.3");
Deleted : user_pref("browser.search.defaultthis.engineName", "Download Energy Customized Web Search");
Deleted : user_pref("browser.search.defaulturl", "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1269415&Sea[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.InstallationTime", 1357492152);
Deleted : user_pref("extensions.crossriderapp14917.14917.active", true);
Deleted : user_pref("extensions.crossriderapp14917.14917.addressbar", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.addressbarenhanced", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.asyncdb_dbWasSet", true);
Deleted : user_pref("extensions.crossriderapp14917.14917.asyncinternaldb_dbWasSet", true);
Deleted : user_pref("extensions.crossriderapp14917.14917.backgroundjs", "\n\n//appAPI.onRequest(function(resou[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.backgroundver", 6);
Deleted : user_pref("extensions.crossriderapp14917.14917.can_run_bg_code", true);
Deleted : user_pref("extensions.crossriderapp14917.14917.certdomaininstaller", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.changeprevious", false);
Deleted : user_pref("extensions.crossriderapp14917.14917.cookie.CrossriderNotifier_channels.expiration", "Fri [...]
Deleted : user_pref("extensions.crossriderapp14917.14917.cookie.CrossriderNotifier_channels.value", "%7B%22app[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.cookie.CrossriderNotifier_geolocation.expiration", "T[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.cookie.CrossriderNotifier_geolocation.value", "%22FI%[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.cookie.InstallationTime.expiration", "Fri Feb 01 2030[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.cookie.InstallationTime.value", "1357492152");
Deleted : user_pref("extensions.crossriderapp14917.14917.description", "Facebook Undetected lets you disable F[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.domain", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.enablesearch", false);
Deleted : user_pref("extensions.crossriderapp14917.14917.fbremoteurl", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.group", 0);
Deleted : user_pref("extensions.crossriderapp14917.14917.homepage", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.iframe", false);
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_appVer.expiration", "Fri Feb 01 [...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_appVer.value", "61");
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_lastVersion.expiration", "Fri Fe[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_lastVersion.value", "0");
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_meta.expiration", "Fri Feb 01 20[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_meta.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_queue.expiration", "Fri Feb 01 2[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_queue.value", "%7B%7D");
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_remote_resources.expiration", "F[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.Resources_remote_resources.value", "%7B%22[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.__crossrider_daily_ping__.expiration", "Fr[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb.__crossrider_daily_ping__.value", "1374166[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb._sanity_pings_counter.expiration", "Fri Fe[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.internaldb._sanity_pings_counter.value", "116");
Deleted : user_pref("extensions.crossriderapp14917.14917.js", "\n\nappAPI.ready(function($) {\n\n});\n\n");
Deleted : user_pref("extensions.crossriderapp14917.14917.manifesturl", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.name", "Chat Undetected");
Deleted : user_pref("extensions.crossriderapp14917.14917.newtab", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.opensearch", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_1.code", "appAPI._cr_config={appID:fun[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_1.name", "base");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_1.ver", 6);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_13.code", "(function(a){a.selectedText[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_13.name", "CrossriderAppUtils");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_13.ver", 3);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_14.code", "if(typeof(appAPI)===\"undef[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_14.name", "CrossriderUtils");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_14.ver", 9);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_16.code", "if((typeof isBackground===\[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_16.name", "FFAppAPIWrapper");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_16.ver", 9);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_17.code", "if(typeof window!==\"undefi[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_17.name", "jQuery");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_17.ver", 4);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_21.code", "var CrossriderDebugManager=[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_21.name", "debug");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_21.ver", 4);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_22.code", "(function(a){appAPI.queueMa[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_22.name", "resources");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_22.ver", 4);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_28.code", "var CrossriderInitializerPl[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_28.name", "initializer");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_28.ver", 3);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_4.code", "var jQuery = $jquery_171 = $[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_4.name", "jquery_1_7_1");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_4.ver", 4);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_47.code", "(function(){appAPI.ready=fu[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_47.name", "resources_background");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_47.ver", 3);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_5.code", "(function(f){f.ui=f.ui||{};v[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_5.name", "notifications");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_5.ver", 5);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_64.code", "(function(){var h=\"__CR_EM[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_64.name", "appApiMessage");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_64.ver", 2);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_7.code", "appAPI.hooks={$:$jquery_171,[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_7.name", "hooks");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_7.ver", 2);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_72.code", "if(appAPI.__should_activate[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_72.name", "appApiValidation");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_72.ver", 3);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_78.code", "if(typeof jQuery!==\"undefi[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_78.name", "CrossriderInfo");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_78.ver", 3);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_79.code", "(function(){function a(){tr[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_79.name", "CrossriderDailyPing");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_79.ver", 10);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_9.code", "appAPI.hooks.addHook(\"searc[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_9.name", "search_engine_hook");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_9.ver", 2);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_98.code", "(function(){var b=\"cr_\"+a[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_98.name", "omniCommands");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins.plugin_98.ver", 2);
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins_lists.plugins_0", "4,14,78,16,64,47,72,98");
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins_lists.plugins_1", "17,14,78,13,16,64,4,1,21,2[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.plugins_lists.plugins_5", "4,14,78,13,16,64,47,72");
Deleted : user_pref("extensions.crossriderapp14917.14917.pluginsurl", "hxxps://w9u6a2p6.ssl.hwcdn.net/plugin/a[...]
Deleted : user_pref("extensions.crossriderapp14917.14917.pluginsversion", 25);
Deleted : user_pref("extensions.crossriderapp14917.14917.publisher", "Crossrider");
Deleted : user_pref("extensions.crossriderapp14917.14917.searchstatus", 0);
Deleted : user_pref("extensions.crossriderapp14917.14917.setnewtab", false);
Deleted : user_pref("extensions.crossriderapp14917.14917.settingsurl", "");
Deleted : user_pref("extensions.crossriderapp14917.14917.thankyou", "hxxp://crossrider.com/thank_you/14917");
Deleted : user_pref("extensions.crossriderapp14917.14917.updateinterval", 360);
Deleted : user_pref("extensions.crossriderapp14917.14917.ver", 64);
Deleted : user_pref("extensions.crossriderapp14917.apps", "14917");
Deleted : user_pref("extensions.crossriderapp14917.bic", "13c10d664fb9f9f7d7cd5c7c28c0994d");
Deleted : user_pref("extensions.crossriderapp14917.cid", 14917);
Deleted : user_pref("extensions.crossriderapp14917.firstrun", false);
Deleted : user_pref("extensions.crossriderapp14917.hadappinstalled", true);
Deleted : user_pref("extensions.crossriderapp14917.installationdate", 1357492152);
Deleted : user_pref("extensions.crossriderapp14917.lastcheck", 22908454);
Deleted : user_pref("extensions.crossriderapp14917.lastcheckitem", 22908485);
Deleted : user_pref("extensions.crossriderapp14917.modetype", "production");
Deleted : user_pref("extensions.crossriderapp14917.reportInstall", true);
Deleted : user_pref("extensions.crossriderapp14917.statsDailyCounter", 128);
Deleted : user_pref("[email protected]", true);
Deleted : user_pref("extensions.enabledAddons", "%7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10,%7BE173B749[...]
Deleted : user_pref("[email protected]", true);
Deleted : user_pref("vshare.install.date", "1313847120");
Deleted : user_pref("vshare.install.finished", "1.0.0");
Deleted : user_pref("vshare.install.fresh", "false");
Deleted : user_pref("vshare.install.guid", "{84ac94f0-1b4c-48da-a1e9-a0a6b3b3409b}");
Deleted : user_pref("vshare.install.newtab", false);

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Ghost\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Chromium v29.0.1512.0

File : C:\Users\Ghost\AppData\Local\Chromium\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v [Unable to get version]

File : C:\Users\Ghost\AppData\Roaming\Opera\Opera\operaprefs.ini

Deleted : application/x-winampx-1.0.0.1=6,,C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll,Winamp A[...]
Deleted : application/x-winampx-1.0.0.1=,0

*************************

AdwCleaner[S1].txt - [18806 octets] - [23/07/2013 00:10:09]

########## EOF - C:\AdwCleaner[S1].txt - [18867 octets] ##########


OTL logfile created on: 23.7.2013 0:22:02 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ghost\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = )
Locale: 0000040b | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,55 Gb Available Physical Memory | 63,83% Memory free
8,00 Gb Paging File | 6,27 Gb Available in Paging File | 78,42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 151,46 Gb Total Space | 13,30 Gb Free Space | 8,78% Space Free | Partition Type: NTFS
Drive D: | 322,26 Gb Total Space | 14,06 Gb Free Space | 4,36% Space Free | Partition Type: NTFS
Drive E: | 122,44 Gb Total Space | 4,31 Gb Free Space | 3,52% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 12,90 Gb Free Space | 2,77% Space Free | Partition Type: NTFS

Computer Name: PC-GHOST | User Name: Ghost | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --
PRC - [2013.07.01 20:58:21 | 001,598,128 | ---- | M] (AVG Secure Search) -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
PRC - [2013.06.28 20:41:52 | 001,376,608 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe
PRC - [2013.06.28 20:41:49 | 039,477,088 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\15.0.1147.130\opera.exe
PRC - [2013.06.15 14:13:35 | 001,104,384 | ---- | M] (Spotify Ltd) -- D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe
PRC - [2013.05.10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013.04.04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012.10.05 23:57:15 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ghost\Desktop\OTL.exe
PRC - [2012.02.21 20:39:30 | 002,043,904 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe
PRC - [2011.03.07 15:42:42 | 000,969,216 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
PRC - [2010.04.16 17:10:58 | 000,036,864 | ---- | M] (Realtek) -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
PRC - [2009.07.24 19:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2008.07.22 12:18:44 | 000,163,840 | ---- | M] () -- D:\Ohjelmat\Desktop Media\mediadetect.exe
PRC - [2005.09.30 19:22:50 | 000,096,341 | ---- | M] (Canon Inc.) -- C:\Program Files (x86)\Canon\CAL\CALMAIN.exe


========== Modules (No Company Name) ==========

MOD - [2013.06.28 20:41:58 | 000,977,248 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\ffmpegsumo.dll
MOD - [2013.06.28 20:41:52 | 001,376,608 | ---- | M] () -- C:\Program Files (x86)\Opera\15.0.1147.130\opera_crashreporter.exe
MOD - [2011.03.07 15:21:06 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libtidy.dll
MOD - [2011.03.07 15:21:02 | 000,433,664 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libxml2.dll
MOD - [2008.07.22 12:18:44 | 000,163,840 | ---- | M] () -- D:\Ohjelmat\Desktop Media\mediadetect.exe


========== Services (SafeList) ==========

SRV:64bit: - [2013.06.04 14:44:06 | 000,182,848 | ---- | M] (Soluto) [Auto | Running] -- C:\Program Files\Soluto\SolutoLauncherService.exe -- (SolutoLauncherService)
SRV:64bit: - [2013.06.04 14:44:04 | 000,746,048 | ---- | M] (Soluto) [Auto | Running] -- C:\Program Files\Soluto\SolutoService.exe -- (SolutoService)
SRV:64bit: - [2013.06.04 14:40:24 | 001,671,680 | ---- | M] (GlavSoft LLC.) [On_Demand | Stopped] -- C:\Program Files\Soluto\SolutoRemoteService.exe -- (SolutoRemoteService)
SRV:64bit: - [2013.05.27 08:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2013.04.04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV:64bit: - [2013.04.04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV:64bit: - [2012.04.06 05:16:02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010.06.06 15:25:32 | 001,038,088 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010.05.06 12:30:22 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009.10.07 01:47:10 | 000,191,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:64bit: - [2009.09.23 14:34:04 | 000,073,728 | ---- | M] (Tablet Driver) [Auto | Running] -- C:\Windows\SysNative\drivers\WTSrv.exe -- (WinTabService)
SRV:64bit: - [2009.07.14 04:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013.07.01 20:58:21 | 001,598,128 | ---- | M] (AVG Secure Search) [Auto | Running] -- C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe -- (vToolbarUpdater15.3.0)
SRV - [2013.05.15 00:49:36 | 000,117,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013.05.10 00:57:24 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013.04.19 15:14:16 | 000,161,384 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013.02.14 04:14:02 | 000,543,144 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012.12.19 10:49:34 | 000,732,648 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2012.01.18 06:44:52 | 000,450,848 | ---- | M] (Logitech Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2011.03.28 15:41:12 | 002,111,368 | ---- | M] (LogMeIn Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2010.11.29 20:31:21 | 000,075,136 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010.10.09 04:57:25 | 000,008,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\SysWOW64\srvany.exe -- (KMService)
SRV - [2010.06.06 15:23:59 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010.04.16 17:10:58 | 000,036,864 | ---- | M] (Realtek) [Auto | Running] -- C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe -- (Realtek11nSU)
SRV - [2010.03.18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.07.24 19:38:50 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2009.06.11 00:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008.08.15 05:46:20 | 000,284,016 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe -- (Adobe Version Cue CS4)
SRV - [2005.09.30 19:22:50 | 000,096,341 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files (x86)\Canon\CAL\CALMAIN.exe -- (CCALib8)


========== Driver Services (SafeList) ==========

DRV:64bit: - File not found [Kernel | Auto | Stopped] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys -- (AODDriver4.01)
DRV:64bit: - [2013.07.01 20:58:21 | 000,045,856 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtpx64.sys -- (avgtp)
DRV:64bit: - [2013.06.04 14:40:06 | 000,054,728 | ---- | M] (Soluto LTD.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Soluto.sys -- (Soluto)
DRV:64bit: - [2013.04.04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012.11.09 16:33:30 | 000,027,136 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbox64.sys -- (nmwcdc)
DRV:64bit: - [2012.11.09 16:33:30 | 000,019,968 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ccdcmbx64.sys -- (nmwcd)
DRV:64bit: - [2012.11.09 16:33:30 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltjx64.sys -- (UsbserFilt)
DRV:64bit: - [2012.11.09 16:33:30 | 000,009,216 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser_lowerfltx64.sys -- (upperdev)
DRV:64bit: - [2012.10.17 14:53:46 | 000,026,112 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2012.08.23 17:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012.08.23 17:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012.05.14 09:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012.04.06 08:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2012.04.06 08:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012.04.06 04:10:44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012.03.01 09:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012.01.18 06:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2012.01.18 06:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2011.08.11 14:46:46 | 000,694,376 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su)
DRV:64bit: - [2011.06.10 06:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011.05.10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011.03.11 09:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011.03.11 09:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010.12.23 15:48:46 | 000,818,424 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010.11.20 16:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010.11.20 13:43:57 | 000,032,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbser.sys -- (usbser)
DRV:64bit: - [2010.11.09 16:35:24 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:64bit: - [2010.04.27 16:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2010.04.27 16:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2010.04.27 14:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2010.04.27 14:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2010.03.30 23:27:42 | 000,015,360 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Spyder3.sys -- (Spyder3)
DRV:64bit: - [2010.03.18 12:00:40 | 000,041,040 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2010.03.18 12:00:16 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2010.03.18 12:00:00 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2010.03.09 13:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2010.02.18 09:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009.12.18 01:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2009.10.07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2009.10.07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009.08.10 00:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2009.07.14 04:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009.07.14 04:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009.07.14 04:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009.07.14 03:09:02 | 000,120,320 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\irda.sys -- (irda)
DRV:64bit: - [2009.06.18 11:42:34 | 000,022,696 | ---- | M] (Tablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\UCTblHid.sys -- (UCTblHid)
DRV:64bit: - [2009.06.18 11:42:16 | 000,027,304 | ---- | M] (Tablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TClass2k.sys -- (TClass2k)
DRV:64bit: - [2009.06.18 11:41:58 | 000,017,064 | ---- | M] (PenTablet Driver) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PTSimHid.sys -- (PTSimHid)
DRV:64bit: - [2009.06.18 11:41:46 | 000,027,304 | ---- | M] (PenTablet Driver) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PTSimBus.sys -- (PTSimBus)
DRV:64bit: - [2009.06.10 23:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009.06.10 23:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009.06.10 23:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009.06.10 23:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009.05.18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009.03.18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2008.06.27 07:51:10 | 000,088,632 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\adfs.sys -- (adfs)
DRV:64bit: - [2008.01.19 06:36:12 | 000,027,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\irsir.sys -- (irsir)
DRV - [2009.07.14 04:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fi
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2A 21 4A 5A D4 00 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {ad708c09-d51b-45b3-9d28-4eba2681febf} - C:\Program Files (x86)\Download_Energy\prxtbDown.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.selectedEngine: "DuckDuckGo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70}:7.3.3.42
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: avg@igeared:6.011.025.001
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe30}:0.7.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.1
FF - prefs.js..extensions.enabledItems: {d650973c-0444-4ac7-9d00-19e3613c83b9}:3.6.7
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.4
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.5
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Ghost\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013.05.17 08:38:41 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2013.06.25 20:08:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Thunderbird 17.0.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2011.03.11 18:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Extensions
[2011.03.11 18:55:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013.07.23 00:10:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions
[2010.05.31 20:41:37 | 000,000,000 | ---D | M] (Whitehart) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{d650973c-0444-4ac7-9d00-19e3613c83b9}
[2011.11.28 10:56:07 | 000,000,000 | ---D | M] (Memory Fox) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}
[2010.12.27 01:16:42 | 000,000,000 | ---D | M] (Chromifox Basic) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.07.11 20:24:52 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2012.12.20 18:23:30 | 000,000,000 | ---D | M] (Foxdie) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2012.12.21 13:15:10 | 000,000,000 | ---D | M] (Foxdie (Graphite)) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.04.16 20:36:13 | 000,000,000 | ---D | M] (DOM Inspector) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.04.30 21:44:45 | 000,000,000 | ---D | M] (rein) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2012.09.06 09:25:29 | 000,240,755 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.05.01 16:10:58 | 000,014,909 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\[email protected]
[2013.05.27 11:25:07 | 000,534,431 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi
[2013.04.17 20:36:12 | 000,282,569 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi
[2013.06.03 13:23:46 | 000,030,502 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
[2013.07.22 18:39:28 | 000,818,491 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011.10.30 11:38:54 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2013.04.05 11:57:36 | 000,714,654 | ---- | M] () (No name found) -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013.07.18 20:41:00 | 000,002,684 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\ann-encyclopedia.xml
[2013.07.17 22:48:03 | 000,010,316 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\duckduckgo.xml
[2013.07.18 20:41:00 | 000,004,873 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\isohunt--bt-search.xml
[2010.06.01 21:15:20 | 000,001,011 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\torrentz-search.xml
[2012.07.25 18:37:47 | 000,000,705 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\searchplugins\webster.xml
[2013.05.15 00:49:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013.05.15 00:49:38 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
File not found (No name found) -- C:\USERS\GHOST\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\NMNJP6BC.DEFAULT\EXTENSIONS\[email protected]
[2011.10.26 21:49:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2013.02.20 22:08:13 | 000,003,714 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml

========== Chrome ==========

CHR - default_search_provider: DuckDuckGo (Enabled)
CHR - default_search_provider: search_url = https://duckduckgo.c...q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Chromoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = D:\Ohjelmat\chrome-win32\ppGoogleNaClPluginChrome.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\13.2.0\\npsitesafety.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U11 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Nokia Suite Enabler Plugin (Enabled) = C:\Program Files (x86)\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: QUAKE LIVE (Enabled) = C:\ProgramData\id Software\QuakeLive\npquakezero.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Ghost\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\ohjelmat\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Picasa (Enabled) = d:\ohjelmat\Google\Picasa3\npPicasa3.dll

O1 HOSTS File: ([2013.07.18 22:44:17 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Soluto] c:\program files\soluto\soluto.exe (Soluto)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Spotify Web Helper] D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe (Spotify Ltd)
O4 - Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Ghost\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - ftp Prefix: missing
O13 - gopher Prefix: missing
O13 - home Prefix: missing
O13 - mosaic Prefix: missing
O13 - www Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 62.241.198.245 62.241.198.246
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4F28F71D-B0F7-4600-8842-2F30750E759B}: DhcpNameServer = 62.241.198.245 62.241.198.246
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Value error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\LogiShrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013.07.22 18:35:54 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013.07.22 18:35:53 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013.07.22 18:35:53 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2013.07.22 18:34:38 | 000,935,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Ghost\Desktop\VisualBasic6-KB896559-v1-ENU.exe
[2013.07.22 12:44:00 | 000,357,077 | ---- | C] (Farbar) -- C:\Users\Ghost\Desktop\FSS.exe
[2013.07.22 12:25:22 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ghost\Desktop\OTL.exe
[2013.07.22 12:18:18 | 000,000,000 | ---D | C] -- C:\CC Support
[2013.07.22 12:18:18 | 000,000,000 | ---D | C] -- \CC Support
[2013.07.22 11:55:39 | 002,237,968 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Ghost\Desktop\tdsskiller.exe
[2013.07.22 09:43:48 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\Ghost\Desktop\aswMBR.exe
[2013.07.21 17:57:14 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013.07.21 17:57:14 | 000,000,000 | -HSD | C] -- \$RECYCLE.BIN
[2013.07.19 00:08:29 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013.07.18 23:51:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013.07.18 23:51:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013.07.18 23:51:02 | 000,000,000 | ---D | C] -- \Qoobox
[2013.07.18 23:41:18 | 000,000,000 | --SD | C] -- C:\ComboFix
[2013.07.18 23:41:18 | 000,000,000 | --SD | C] -- \ComboFix
[2013.07.18 23:24:33 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\MFAData
[2013.07.18 23:24:33 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\Avg2013
[2013.07.18 23:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2013.07.18 23:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2013.07.18 23:01:41 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Spybot - Search & Destroy
[2013.07.18 23:00:39 | 036,364,784 | ---- | C] (Safer-Networking Ltd. ) -- C:\Users\Ghost\Desktop\spybotsd-2.1.20-SR1.exe
[2013.07.18 22:29:31 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013.07.18 20:45:19 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2013.07.18 20:41:55 | 000,000,000 | ---D | C] -- C:\Users\Ghost\Desktop\SUPERSetup
[2013.07.18 20:41:23 | 026,611,408 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
[2013.07.18 20:30:58 | 000,000,000 | ---D | C] -- C:\Malwarebytes
[2013.07.18 20:30:58 | 000,000,000 | ---D | C] -- \Malwarebytes
[2013.07.18 20:30:11 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Ghost\Desktop\mbam-setup-1.75.0.1300.exe
[2013.07.18 20:02:44 | 017,737,608 | ---- | C] (Adobe Systems Incorporated) -- C:\Users\Ghost\Desktop\install_flash_player.exe
[2013.07.18 19:21:40 | 000,000,000 | ---D | C] -- C:\Application Data
[2013.07.18 19:21:40 | 000,000,000 | ---D | C] -- \Application Data
[2013.07.12 02:02:18 | 000,526,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013.07.12 02:02:18 | 000,391,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013.07.12 02:02:17 | 000,136,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2013.07.12 02:02:17 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2013.07.12 02:02:17 | 000,089,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013.07.12 02:02:17 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013.07.12 02:02:17 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2013.07.12 02:02:17 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2013.07.12 02:02:17 | 000,051,712 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2013.07.12 02:02:17 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2013.07.12 02:02:17 | 000,033,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2013.07.12 02:02:16 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2013.07.12 02:02:16 | 000,690,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2013.07.12 02:02:16 | 000,603,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013.07.12 02:02:15 | 003,958,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2013.07.11 20:43:58 | 000,624,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qedit.dll
[2013.07.11 20:43:58 | 000,509,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qedit.dll
[2013.07.11 20:43:56 | 001,887,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2013.07.11 20:43:55 | 001,620,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2013.07.11 20:35:54 | 001,643,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2013.07.06 14:20:39 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Local\Opera Software
[2013.07.06 14:20:37 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\Opera Software
[2013.06.25 20:08:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Thunderbird
[2013.06.25 01:25:19 | 000,000,000 | ---D | C] -- C:\Users\Ghost\AppData\Roaming\TuneUp Software
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013.07.23 00:20:28 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013.07.23 00:20:28 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013.07.23 00:13:27 | 000,000,224 | ---- | M] () -- C:\Windows\tasks\AutoRearm.job
[2013.07.23 00:12:55 | 000,001,002 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013.07.23 00:12:52 | 000,000,350 | ---- | M] () -- C:\Windows\tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
[2013.07.23 00:12:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013.07.23 00:12:40 | 3220,824,064 | -HS- | M] () -- C:\hiberfil.sys
[2013.07.23 00:12:03 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013.07.22 18:35:54 | 000,000,914 | ---- | M] () -- C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.22 12:10:00 | 000,666,633 | ---- | M] () -- C:\Users\Ghost\Desktop\adwcleaner.exe
[2013.07.22 12:08:47 | 000,171,135 | ---- | M] () -- C:\Users\Ghost\Desktop\3001-8022_4-10804572.html
[2013.07.22 11:55:17 | 000,000,512 | ---- | M] () -- C:\Users\Ghost\Desktop\MBR.dat
[2013.07.19 00:35:20 | 000,222,290 | ---- | M] () -- C:\Users\Ghost\Desktop\AVGInstLog.cab
[2013.07.18 23:27:52 | 000,001,137 | ---- | M] () -- C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
[2013.07.18 22:44:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013.07.18 21:37:05 | 000,064,178 | ---- | M] () -- C:\Users\Ghost\Documents\cc_20130718_213659.reg
[2013.07.18 20:21:11 | 026,611,408 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
[2013.07.18 20:03:00 | 017,737,608 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Ghost\Desktop\install_flash_player.exe
[2013.07.17 23:00:12 | 101,083,484 | ---- | M] () -- C:\Users\Ghost\Desktop\DHBTPO.rar
[2013.07.17 22:42:20 | 048,537,823 | ---- | M] () -- C:\Users\Ghost\Desktop\LJD.rar
[2013.07.17 22:31:53 | 067,966,879 | ---- | M] () -- C:\Users\Ghost\Desktop\NTBD.rar
[2013.07.17 21:59:03 | 002,297,856 | ---- | M] () -- C:\Users\Ghost\Desktop\Baby_shower.indd
[2013.07.17 20:40:27 | 000,001,165 | ---- | M] () -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.07.16 10:00:58 | 005,199,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013.07.13 15:55:40 | 000,357,077 | ---- | M] (Farbar) -- C:\Users\Ghost\Desktop\FSS.exe
[2013.07.12 02:11:07 | 001,367,650 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013.07.12 02:11:07 | 000,652,166 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013.07.12 02:11:07 | 000,479,386 | ---- | M] () -- C:\Windows\SysNative\perfh00B.dat
[2013.07.12 02:11:07 | 000,121,098 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013.07.12 02:11:07 | 000,100,162 | ---- | M] () -- C:\Windows\SysNative\perfc00B.dat
[2013.07.01 20:58:48 | 000,003,716 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.07.01 20:58:21 | 000,045,856 | ---- | M] (AVG Technologies) -- C:\Windows\SysNative\drivers\avgtpx64.sys
[2013.06.30 19:39:52 | 000,002,070 | ---- | M] () -- C:\Users\Ghost\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2013.06.25 00:58:24 | 000,173,429 | ---- | M] () -- C:\Users\Ghost\Desktop\Threadless_130624.pdf
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013.07.22 18:37:53 | 000,662,016 | ---- | C] () -- C:\Users\Ghost\Desktop\MicrosoftFixit50531.msi
[2013.07.22 18:35:54 | 000,000,914 | ---- | C] () -- C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
[2013.07.22 12:22:28 | 000,061,440 | ---- | C] ( ) -- C:\Users\Ghost\Desktop\VEW.exe
[2013.07.22 12:18:01 | 004,009,167 | ---- | C] () -- C:\Users\Ghost\Desktop\ServicesRepair.exe
[2013.07.22 12:10:02 | 000,666,633 | ---- | C] () -- C:\Users\Ghost\Desktop\adwcleaner.exe
[2013.07.22 12:08:58 | 000,171,135 | ---- | C] () -- C:\Users\Ghost\Desktop\3001-8022_4-10804572.html
[2013.07.22 11:55:17 | 000,000,512 | ---- | C] () -- C:\Users\Ghost\Desktop\MBR.dat
[2013.07.19 00:35:20 | 000,222,290 | ---- | C] () -- C:\Users\Ghost\Desktop\AVGInstLog.cab
[2013.07.18 23:27:52 | 000,001,137 | ---- | C] () -- C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
[2013.07.18 21:37:03 | 000,064,178 | ---- | C] () -- C:\Users\Ghost\Documents\cc_20130718_213659.reg
[2013.07.17 22:28:17 | 067,966,879 | ---- | C] () -- C:\Users\Ghost\Desktop\NTBD.rar
[2013.07.17 22:27:03 | 101,083,484 | ---- | C] () -- C:\Users\Ghost\Desktop\DHBTPO.rar
[2013.07.17 22:25:43 | 048,537,823 | ---- | C] () -- C:\Users\Ghost\Desktop\LJD.rar
[2013.07.17 21:58:58 | 002,297,856 | ---- | C] () -- C:\Users\Ghost\Desktop\Baby_shower.indd
[2013.07.17 20:40:27 | 000,001,165 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013.06.25 00:58:24 | 000,173,429 | ---- | C] () -- C:\Users\Ghost\Desktop\Threadless_130624.pdf
[2013.05.21 13:54:43 | 000,003,716 | ---- | C] () -- C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
[2013.02.15 17:20:04 | 001,325,198 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013.02.15 12:56:11 | 000,000,132 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012.07.21 09:40:05 | 000,001,456 | ---- | C] () -- C:\Users\Ghost\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.06.24 21:29:42 | 000,925,184 | ---- | C] () -- C:\Windows\expstart.exe
[2012.03.09 07:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012.03.09 07:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012.02.28 18:28:04 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2012.01.31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012.01.18 06:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2012.01.18 06:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2012.01.18 06:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011.11.23 22:03:49 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011.11.23 21:58:43 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2011.11.02 08:50:27 | 000,001,556 | ---- | C] () -- C:\Users\Ghost\.davmail.properties
[2011.10.25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011.09.13 01:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011.09.06 19:55:55 | 000,335,872 | ---- | C] () -- C:\Windows\SetupX32.EXE
[2011.05.30 20:17:54 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2011.05.17 20:03:05 | 000,114,688 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\fontdb.mdb
[2011.03.23 00:02:15 | 000,000,266 | ---- | C] () -- C:\Users\Ghost\AppData\Roaming\rftg
[2011.03.21 01:20:29 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2010.10.19 19:47:31 | 000,005,642 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010.09.09 23:55:23 | 000,007,603 | ---- | C] () -- C:\Users\Ghost\AppData\Local\Resmon.ResmonCfg
[2010.06.11 17:16:52 | 000,000,000 | ---- | C] () -- C:\Users\Ghost\AppData\Local\prvlcl.dat
[2010.06.01 05:02:35 | 000,008,192 | RHS- | C] () -- \BOOTSECT.BAK
[2010.06.01 05:02:34 | 000,383,786 | RHS- | C] () -- \bootmgr
[2010.05.31 18:11:07 | 000,203,836 | RHS- | C] () -- \grldr
[2010.05.31 18:11:07 | 000,000,000 | RHS- | C] () -- \winx.ld
[2010.05.31 18:03:42 | 3220,824,064 | -HS- | C] () -- \hiberfil.sys
[2007.11.07 08:12:28 | 000,232,960 | ---- | C] () -- \VC_RED.MSI
[2007.11.07 08:09:22 | 001,442,522 | ---- | C] () -- \VC_RED.cab
[2007.11.07 08:03:18 | 000,097,296 | ---- | C] () -- \install.res.1036.dll
[2007.11.07 08:03:18 | 000,096,272 | ---- | C] () -- \install.res.3082.dll
[2007.11.07 08:03:18 | 000,096,272 | ---- | C] () -- \install.res.1031.dll
[2007.11.07 08:03:18 | 000,095,248 | ---- | C] () -- \install.res.1040.dll
[2007.11.07 08:03:18 | 000,091,152 | ---- | C] () -- \install.res.1033.dll
[2007.11.07 08:03:18 | 000,081,424 | ---- | C] () -- \install.res.1041.dll
[2007.11.07 08:03:18 | 000,079,888 | ---- | C] () -- \install.res.1042.dll
[2007.11.07 08:03:18 | 000,076,304 | ---- | C] () -- \install.res.1028.dll
[2007.11.07 08:03:18 | 000,075,792 | ---- | C] () -- \install.res.2052.dll
[2007.11.07 08:00:40 | 000,005,686 | ---- | C] () -- \vcredist.bmp
[2007.11.07 08:00:40 | 000,001,110 | ---- | C] () -- \globdata.ini
[2007.11.07 08:00:40 | 000,000,843 | ---- | C] () -- \install.ini

========== ZeroAccess Check ==========

[2009.07.14 07:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013.02.27 08:52:56 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013.02.27 07:55:05 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009.07.14 04:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010.11.20 15:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 04:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

========== Drive Information ==========

Physical Drives
---------------

Error accessing drive info (0)
Error accessing drive info (0)

Partitions
---------------

Error accessing partition info (0)
Error accessing partition info (0)

< MD5 for: VBALSGRID6.OCX >
[2011.06.01 10:16:56 | 000,496,976 | ---- | M] (vbAccelerator) MD5=BAA4DE42156350754976DD563D02CDE4 -- C:\Program Files\Malwarebytes' Anti-Malware\vbalsgrid6.ocx

< MD5 for: WUAUENG.DLL >
[2010.11.20 16:27:32 | 002,420,736 | ---- | M] (Microsoft Corporation) MD5=9DF12EDBC698B0BC353B3EF84861E430 -- C:\Windows\winsxs\amd64_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.5.7601.17514_none_1f3413afc64d10c5\wuaueng.dll
[2012.06.03 01:19:43 | 002,428,952 | ---- | M] (Microsoft Corporation) MD5=D9EF901DCA379CFE914E9FA13B73B4C4 -- C:\Windows\winsxs\amd64_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.6.7600.256_none_d5f513f25190f276\wuaueng.dll

========== Files - Unicode (All) ==========
[2011.12.18 13:48:12 | 000,004,314 | ---- | M] ()(C:\Users\Ghost\Documents\H??kuvat.mds) -- C:\Users\Ghost\Documents\H¦¦kuvat.mds
[2011.12.18 13:48:12 | 000,004,314 | ---- | C] ()(C:\Users\Ghost\Documents\H??kuvat.mds) -- C:\Users\Ghost\Documents\H¦¦kuvat.mds
[2011.12.18 13:48:11 | 2439,053,312 | ---- | M] ()(C:\Users\Ghost\Documents\H??kuvat.iso) -- C:\Users\Ghost\Documents\H¦¦kuvat.iso
[2011.12.18 13:45:00 | 2439,053,312 | ---- | C] ()(C:\Users\Ghost\Documents\H??kuvat.iso) -- C:\Users\Ghost\Documents\H¦¦kuvat.iso

< End of report >


OTL Extras logfile created on: 23.7.2013 0:22:02 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ghost\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = )
Locale: 0000040b | Country: Suomi | Language: FIN | Date Format: d.M.yyyy

4,00 Gb Total Physical Memory | 2,55 Gb Available Physical Memory | 63,83% Memory free
8,00 Gb Paging File | 6,27 Gb Available in Paging File | 78,42% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 151,46 Gb Total Space | 13,30 Gb Free Space | 8,78% Space Free | Partition Type: NTFS
Drive D: | 322,26 Gb Total Space | 14,06 Gb Free Space | 4,36% Space Free | Partition Type: NTFS
Drive E: | 122,44 Gb Total Space | 4,31 Gb Free Space | 3,52% Space Free | Partition Type: NTFS
Drive F: | 465,76 Gb Total Space | 12,90 Gb Free Space | 2,77% Space Free | Partition Type: NTFS

Computer Name: PC-GHOST | User Name: Ghost | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = jsfile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = comfile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = jsfile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Waterfox\waterfox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Ohjelmat\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "D:\Ohjelmat\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Ohjelmat\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Ohjelmat\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" (VideoLAN)
Directory [Bridge] -- D:\Ohjelmat\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" (VideoLAN)
Directory [Winamp.Bookmark] -- "D:\Ohjelmat\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "D:\Ohjelmat\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "D:\Ohjelmat\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06CC555C-3C0C-436C-93DB-04F9F76D1C36}" = lport=7935 | protocol=6 | dir=in | name=adobe flash builder 4.5 |
"{0A70EC99-BEB9-4218-92A6-776F511DA93C}" = lport=57174 | protocol=17 | dir=in | name=pando media booster |
"{27563C54-340D-4262-A34A-1C1A079236A1}" = lport=67 | protocol=17 | dir=in | name=rtldhcp-port |
"{367FE8BF-00FF-4C90-BC50-5CD00B6EA122}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 |
"{4191DCCA-516F-4E05-BCD4-AC94E46AFE8A}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{65F2905A-72AD-49F1-A84F-D273CE56225A}" = lport=1542 | protocol=17 | dir=in | name=realtek wps udp prot |
"{758A484D-F095-4505-AA9D-27B67749AC57}" = lport=57174 | protocol=6 | dir=in | name=pando media booster |
"{7DD10E04-D5CB-49DC-82BB-109E9946EBF9}" = lport=53 | protocol=17 | dir=in | name=realtek ap udp prot |
"{83F1A3EE-82BC-449A-B808-A868A80F9559}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{87DF290E-1A24-43EC-803D-4C919BCB83CE}" = lport=53 | protocol=17 | dir=in | name=rtldns-port-2 |
"{8B3C5C6A-F112-4B4D-96A8-8CF4613744E2}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{9524594B-6142-4502-805A-DDAA7D025C77}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{9D85C712-EB00-4302-BF2E-720CC74AA321}" = lport=53 | protocol=6 | dir=in | name=rtldns-port |
"{AE22A9D7-E312-4B98-914D-96CFE9F0A944}" = lport=57174 | protocol=6 | dir=in | name=pando media booster |
"{AFF98C5D-7CE8-492A-BF10-BC94E0F50C90}" = lport=68 | protocol=17 | dir=in | name=rtldhcp-port-2 |
"{C684B152-1C7F-4B56-8E0B-EDC774D1C1CA}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{E0780ECD-304B-4CD8-8701-EA53A80435F5}" = lport=1542 | protocol=6 | dir=in | name=realtek wps tcp prot |
"{E0EE8052-241B-412E-B6C6-E1DD5B10FF33}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server |
"{E97ED8BA-0E2E-4CA5-B470-32C3C9A83740}" = lport=57174 | protocol=17 | dir=in | name=pando media booster |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00838FBB-4128-4A5E-B989-9F4E50A2EDF3}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\machinarium demo\machinarium.exe |
"{00DDBAFE-536B-48D7-95A6-050E291EAE2E}" = protocol=17 | dir=in | app=c:\users\ghost\appdata\roaming\dropbox\bin\dropbox.exe |
"{051B2617-8123-4BB2-8709-C8E35AE13D26}" = protocol=6 | dir=in | app=c:\users\ghost\appdata\roaming\dropbox\bin\dropbox.exe |
"{094AD716-F39E-4D6E-98FD-0123BABC27C5}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{09ABA972-4575-47F3-A858-F964E8766703}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{0C099537-408E-4212-9496-16B1049CBE12}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{0E0CA6C0-D70D-459D-A559-2D553BE190C0}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{0E0F4078-2021-47DB-8E0F-CC6C125BEF19}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\homefront - dev diary 2\smp.exe |
"{0E8DB0E8-5887-46B5-BE05-08B61F0DABD2}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{0F1FBB60-06FB-4E7C-A1F7-F613875C3CCB}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 teaser\smp.exe |
"{132DB705-FC2C-4E4B-8EBA-89D3EB816D2F}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{154AD296-8D34-4552-A6E2-DF6B131179B1}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 teaser\smp.exe |
"{1D0E0CD0-F670-4E19-8A44-0BE1F383FDA8}" = protocol=17 | dir=in | app=d:\ohjelmat\utorrent\utorrent.exe |
"{1E3A81A7-CA1A-4647-B332-8BDA11F582CC}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\brink - teaser trailer\smp.exe |
"{24C7CB00-087A-4648-A88E-8A860E85F965}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{2C3AF0F5-C2C8-4674-AD8D-72859357B269}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{2C77B1C7-3A84-4A37-AED6-FBD2539958E3}" = dir=in | app=c:\program files\soluto\solutoupdateservice.exe |
"{2CD547DB-16F7-43C0-B5B1-AE939AD7EC71}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 co-op trailer\smp.exe |
"{2DF622BD-C3FE-4A63-B760-83A1DF1FC562}" = protocol=6 | dir=in | app=d:\ohjelmat\adobe\adobe flash builder 4.5\flashbuilder.exe |
"{317028D7-D29F-4D2F-B751-F2772F2D28AD}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\ghoulone\source sdk base 2007\hl2.exe |
"{3BA204D8-0EE7-4319-AB8F-50D3E6AD928F}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{4525E3F7-1350-44F9-B545-AFF47ECC1986}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{453DD4BB-01EC-4C8E-8754-8671AEF234BB}" = dir=in | app=c:\program files\soluto\solutoservice.exe |
"{454D9169-8BC9-43EF-A520-8D26E7067F02}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\bastion demo\bastion.exe |
"{484F90B3-7594-4CFC-B2DD-06B5922D0F9E}" = dir=in | app=d:\ohjelmat\itunes\itunes.exe |
"{49A750B5-A094-494B-AE35-2C2EE25A0F30}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe |
"{49BA3119-C81A-4AB8-8C93-F63A7D5F284C}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{4AF77EDD-4E0E-437A-8757-BA0243D6D1C3}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\ghoulone\source sdk base 2007\hl2.exe |
"{4F08461C-48CD-4BB1-B65D-9FDA78298B89}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{4F1A7BD1-951A-47EF-9A28-FEFB80709E9D}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{5134357F-37BF-4805-A11F-171340B6774D}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{56B6313D-7309-4F51-9EAD-2C1BD510D61D}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\the undergarden\theundergarden.exe |
"{57ECF4DE-109E-4EEF-B4C6-9B6977B7DB93}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\swarm.exe |
"{6124EDB5-04E7-46AC-B354-DB8A928AC6A4}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\portal 2 co-op trailer\smp.exe |
"{6FC4426E-0ADC-4024-8AE9-E56FC37CE493}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\srcds.exe |
"{6FF52BB1-DA78-42E3-82D3-C913D3B9E0D0}" = protocol=17 | dir=in | app=d:\ohjelmat\adobe\adobe flash builder 4.5\flashbuilder.exe |
"{75A811D9-86B8-4CB3-BB59-2D2A4741B127}" = protocol=6 | dir=in | app=d:\ohjelmat\utorrent\utorrent.exe |
"{7668F4E6-0699-40AC-BFB8-AD6DA36CD472}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\nimbus\nimbus.exe |
"{78351D70-88F3-40C6-AAF3-D7E29A6AA8D4}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\the undergarden\theundergarden.exe |
"{7CD132D7-4D45-4164-A72B-3B66E95EDDA8}" = dir=in | app=c:\program files (x86)\realtek\11n usb wireless lan utility\rtldhcp.exe |
"{7E040714-C506-44AD-8618-585668A6F078}" = protocol=6 | dir=in | app=c:\program files (x86)\realtek\11n usb wireless lan utility\rtwlan.exe |
"{80D867EE-73AD-4E96-95AF-606D98DB5156}" = dir=in | app=c:\program files\soluto\soluto.exe |
"{8359F027-4CEC-4973-BD1E-17C364CFB3C5}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{85915FB6-9B66-456F-8936-9B2147DD00C2}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{85DF9D7B-8A32-479B-AB55-556845504162}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{8813CD25-99E7-4ACA-ABB8-5F2C18E5A464}" = dir=in | app=c:\program files (x86)\nokia\nokia suite\nokiasuite.exe |
"{898060F9-9DF4-4156-B131-B20AF02E06AF}" = dir=in | app=c:\program files\soluto\solutoconsole.exe |
"{8CB81D74-8BCC-43EB-AB7E-1C6F0F975EC9}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\machinarium demo\machinarium.exe |
"{8E2800D8-F88F-4A3A-8546-7E89EB074385}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{8F6A5ED9-4405-4F90-86CD-4335CFB40403}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |
"{92EF1CEE-1768-49AD-930D-BDA3EE7FF098}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{931168A0-101B-4CD9-A260-6FF14FAF75BC}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{93C2AEC8-2AC6-4C46-92D4-4528FF7B1A43}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |
"{9731D42A-AB7F-4570-BE22-FA40F7516CE3}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{9876CB94-5273-489F-9895-93B9F7C709EF}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{99EC7B45-2D2A-490F-A7FE-6FEEB177B81D}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steam.exe |
"{A8A4DBD4-8FBF-4A61-B7A5-8E9A278ED846}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\deus ex human revolution gameplay trailer\smp.exe |
"{ABA648A4-5FC3-402B-B99C-5FC3973DCB76}" = protocol=17 | dir=in | app=c:\program files (x86)\mass effect\binaries\masseffect.exe |
"{B1C99F76-7935-4AA5-A2DE-897CB5C9C760}" = protocol=6 | dir=in | app=c:\program files (x86)\mass effect\masseffectlauncher.exe |
"{B1F499DF-D4A2-4B39-A4D2-70A6A6E20752}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{B305EF28-9E7E-4D0E-BCB8-CE9A04F9EC1D}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\homefront - dev diary 2\smp.exe |
"{B744E4DE-8C82-4963-BB9F-D05C93852AFD}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\red faction armageddon trailer\smp.exe |
"{B9DB07BA-736B-4567-B5D6-42C98A8DC051}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2013\avgemca.exe |
"{C0E7516A-A643-4E6E-8FDC-CFBF918EFD5A}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{C30DB6FA-65AE-42E9-96CF-BEE104060F9F}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\braid\braid.exe |
"{C529B113-FC0F-405A-A97D-D1C297873760}" = protocol=17 | dir=in | app=d:\ohjelmat\streamtorrent 1.0\streamtorrent.exe |
"{CE8F9BC7-8337-49D3-B915-4984D58CF0AC}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\deus ex human revolution gameplay trailer\smp.exe |
"{CF7C7306-647A-4ACE-8096-49824C98346A}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{CFACB63D-3F2B-4353-A78F-8AC88206E3D3}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\space marine\smp.exe |
"{D3C3C849-F815-40A7-B382-9D94F55729E9}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\srcds.exe |
"{D632879A-39B9-40B6-99F1-84366C2A77D1}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\red faction armageddon trailer\smp.exe |
"{D6E4027F-8E51-4512-A337-244A7A274871}" = protocol=6 | dir=in | app=d:\ohjelmat\streamtorrent 1.0\streamtorrent.exe |
"{DBFC8786-F4BC-472B-9AC0-2A13E12A5BCA}" = protocol=17 | dir=in | app=c:\program files (x86)\realtek\11n usb wireless lan utility\rtwlan.exe |
"{DFA59D44-E8E0-420F-BD0C-3AF2F820C940}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\space marine\smp.exe |
"{E4441AA5-B30A-42EA-B941-42BA2B9A80A4}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\bastion demo\bastion.exe |
"{F1FAB12F-9E6D-4249-8BB0-F48F722B0974}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steam.exe |
"{F2958A22-DFCA-42EE-98E8-05363F1F4B11}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\brink - teaser trailer\smp.exe |
"{F4A7FC6F-D6CE-41EB-83A8-A174DAD8A06B}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe |
"{F5B34EB2-3E7C-4B0C-8284-9271FC0A0201}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{F798A0C9-05D5-4BAC-A3E4-91F0FB03C4DA}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{F89FBA8D-F606-4BB4-9FD2-4543F5329334}" = dir=in | app=c:\program files\soluto\solutocleanup.exe |
"{FC4155BE-423B-4A38-B668-3A0EF30B0730}" = protocol=17 | dir=in | app=d:\ohjelmat\steam\steamapps\common\alien swarm\swarm.exe |
"{FC715B17-F79F-4715-B898-A3BD058F97B4}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\nimbus\nimbus.exe |
"{FDCD7243-76A5-4E82-9206-3726581576AB}" = protocol=6 | dir=in | app=d:\ohjelmat\steam\steamapps\common\braid\braid.exe |
"TCP Query User{04B32F37-E0B9-4738-B936-CB2C052760E8}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=6 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"TCP Query User{1BB2142A-39DA-424F-ADAA-57913E6BF9DC}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"TCP Query User{227ADC52-2516-48D4-9CC6-DABFD3AF1842}C:\program files (x86)\sopcast\sopcast.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe |
"TCP Query User{23CD3322-EDB7-4E4B-928D-821EB22D4167}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{37921191-AEA0-43AD-B8C6-D39787A2114F}D:\ohjelmat\miranda im\miranda32.exe" = protocol=6 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"TCP Query User{3D16CBCA-2141-40B0-BD92-83F9CFC8746C}D:\ohjelmat\miranda im\miranda32.exe" = protocol=6 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"TCP Query User{57DA972D-E438-42BE-B353-D92A9D168024}D:\pelit\world_of_tanks\wotlauncher.exe" = protocol=6 | dir=in | app=d:\pelit\world_of_tanks\wotlauncher.exe |
"TCP Query User{5ADF9970-4E07-46E6-BDD0-BD80D89D2BAD}D:\ohjelmat\miranda im\miranda64.exe" = protocol=6 | dir=in | app=d:\ohjelmat\miranda im\miranda64.exe |
"TCP Query User{647E04C0-617B-44FD-BBB2-D604D13D89E8}D:\ohjelmat\winamp\winamp.exe" = protocol=6 | dir=in | app=d:\ohjelmat\winamp\winamp.exe |
"TCP Query User{67BA863E-FF18-4841-B77B-9D376E5E91AE}D:\ohjelmat\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=d:\ohjelmat\sopcast\adv\sopadver.exe |
"TCP Query User{6E5BBDA9-2739-4105-AF33-9D470F7A3EBD}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=6 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"TCP Query User{7824DFF4-C92E-4345-A5C4-274B3BDE5BB0}D:\ohjelmat\sopcast\sopcast.exe" = protocol=6 | dir=in | app=d:\ohjelmat\sopcast\sopcast.exe |
"TCP Query User{923BC80F-935B-4EEB-87B4-BDDC5CC0FED9}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=6 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |
"TCP Query User{9D07418D-3E9D-4035-9F4B-00D56E9AAEEA}D:\pelit\magic workstation\mwsplay.exe" = protocol=6 | dir=in | app=d:\pelit\magic workstation\mwsplay.exe |
"TCP Query User{9DE40345-20F9-4ACE-BC71-94A50D7567EF}D:\ohjelmat\spotify\spotify.exe" = protocol=6 | dir=in | app=d:\ohjelmat\spotify\spotify.exe |
"TCP Query User{C3E5F13C-9B38-46CC-A2CD-346BDA4D8A96}C:\program files (x86)\streamtorrent 1.0\streamtorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\streamtorrent 1.0\streamtorrent.exe |
"TCP Query User{C83B0CE5-3318-4DF5-93C6-44AD4A93000E}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{C8AFE3DB-13D3-40D7-A5D8-E1455B08502C}D:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=d:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{D515D45B-B5DE-4B8E-8C0E-CF649991ACBE}D:\pelit\wings 2\bin\wings.exe" = protocol=6 | dir=in | app=d:\pelit\wings 2\bin\wings.exe |
"TCP Query User{DC1CB7E6-8BC5-49B0-B676-9231A568CBE2}C:\program files (x86)\sopcast\adv\sopadver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe |
"TCP Query User{E18B7829-295C-4269-B4A6-2DBFE0558D03}D:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=d:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{F35E2854-381C-4D8D-A3CB-807034FFBC67}C:\program files (x86)\mektek.net\mtx\mtx.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mektek.net\mtx\mtx.exe |
"TCP Query User{F934AA10-88D6-466D-848B-EA2DA2A26280}D:\pelit\world_of_tanks\worldoftanks.exe" = protocol=6 | dir=in | app=d:\pelit\world_of_tanks\worldoftanks.exe |
"UDP Query User{04E25E59-E42B-4185-A473-08DC573FEF17}D:\pelit\world_of_tanks\worldoftanks.exe" = protocol=17 | dir=in | app=d:\pelit\world_of_tanks\worldoftanks.exe |
"UDP Query User{0BB4E2A0-3908-40F9-B410-CA560EDD4563}D:\pelit\world_of_tanks\wotlauncher.exe" = protocol=17 | dir=in | app=d:\pelit\world_of_tanks\wotlauncher.exe |
"UDP Query User{0EF1A7C6-8A0F-475F-BE3E-4113916FDF59}D:\pelit\magic workstation\mwsplay.exe" = protocol=17 | dir=in | app=d:\pelit\magic workstation\mwsplay.exe |
"UDP Query User{130DF8B3-CB7C-462D-9B0C-2A68D534FA49}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe |
"UDP Query User{1AB34845-40CE-4214-A2EE-F45A8F407DBF}C:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{209AB83A-089A-4C56-A85D-438A564131A9}D:\ohjelmat\miranda im\miranda64.exe" = protocol=17 | dir=in | app=d:\ohjelmat\miranda im\miranda64.exe |
"UDP Query User{2A04F2A5-1E57-43A7-B55E-B39CACF1A104}D:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=d:\pelit\activision\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{609C844D-497C-4D21-A035-C5500512E03E}D:\ohjelmat\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=d:\ohjelmat\sopcast\adv\sopadver.exe |
"UDP Query User{63F43DA4-49B6-4E59-A169-32A7ED6F82F8}C:\program files (x86)\mektek.net\mtx\mtx.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mektek.net\mtx\mtx.exe |
"UDP Query User{668D1C9C-7D6A-444C-B83B-A7967E30BD06}C:\program files (x86)\sopcast\adv\sopadver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\adv\sopadver.exe |
"UDP Query User{7B578158-51C4-4463-A2D5-A4DC4E1F163D}D:\ohjelmat\sopcast\sopcast.exe" = protocol=17 | dir=in | app=d:\ohjelmat\sopcast\sopcast.exe |
"UDP Query User{A213D92D-E3AA-4E6E-BFCF-D3D174E723B8}C:\program files (x86)\sopcast\sopcast.exe" = protocol=17 | dir=in | app=c:\program files (x86)\sopcast\sopcast.exe |
"UDP Query User{A5E9853B-41FA-4CDC-B18F-5ED07C88968F}C:\program files (x86)\streamtorrent 1.0\streamtorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\streamtorrent 1.0\streamtorrent.exe |
"UDP Query User{AD43633A-D31D-4076-9BAB-F8BF883F84AF}D:\pelit\wings 2\bin\wings.exe" = protocol=17 | dir=in | app=d:\pelit\wings 2\bin\wings.exe |
"UDP Query User{ADAB22D9-20BD-4F92-89B1-2B99ECC671A3}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=17 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"UDP Query User{B71645CA-0944-4B07-A211-DE7FA7523C0C}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{CCC2E477-4A44-4412-BC3D-84B0FFD4E097}D:\ohjelmat\winamp\winamp.exe" = protocol=17 | dir=in | app=d:\ohjelmat\winamp\winamp.exe |
"UDP Query User{CF24B148-EE8E-4444-A16A-D7D46CF20083}D:\ohjelmat\miranda im\miranda32.exe" = protocol=17 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"UDP Query User{D1610428-648E-48B9-8A04-6A9F7503B2F1}D:\ohjelmat\miranda im\miranda32.exe" = protocol=17 | dir=in | app=d:\ohjelmat\miranda im\miranda32.exe |
"UDP Query User{D4FE3F32-D846-4712-8313-8C6527CE5D71}D:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe" = protocol=17 | dir=in | app=d:\pelit\meteorentertainment\hawken\installedhawkenfiles\binaries\win32\hawkengame-win32-shipping.exe |
"UDP Query User{E07113BF-6472-4124-9ABE-4483B08BCB6B}D:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=d:\pelit\electronic arts\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{EAF84206-B1A1-4523-B032-27B7DFA5FD89}D:\ohjelmat\spotify\spotify.exe" = protocol=17 | dir=in | app=d:\ohjelmat\spotify\spotify.exe |
"UDP Query User{FDB2711D-6977-4AE0-A3F9-D3BCCED3B24C}C:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe" = protocol=17 | dir=in | app=c:\users\public\sony online entertainment\installed games\planetside 2 psg\planetside2.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08347912-0AA5-C85E-BC02-416568E741B4}" = AMD Drag and Drop Transcoding
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{129C5584-DB98-4A98-B28F-299C45E1E355}" = Microsoft Camera Codec Pack
"{1444D2EE-C7AD-44A8-844F-2634B49353D1}" = Logitech Gaming Software 5.10
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1" = Media Player Classic - Home Cinema v1.4.2499.0 x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{36E47D1C-2AD0-429C-8C1A-91A23C949B54}" = Soluto
"{3987279A-3504-2916-D063-741B910F0747}" = AMD Accelerated Video Transcoding
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{46DA7FD9-8BC1-7BA8-98D1-27F46647871B}" = AMD Catalyst Install Manager
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4D668D4F-FAA2-4726-834C-31F4614F312E}" = MSVC80_x64_v2
"{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}" = IconHandler 64 bit
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{63CE6C32-1EB3-4C51-89FC-9FD96A661A9C}" = AMD Media Foundation Decoders
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{66C10F29-31F0-4A9B-B2CF-465F488AE086}" = CorelDRAW Graphics Suite X5 - Windows Shell Extension 64 Bit
"{680EDA59-9266-44B4-949E-0C24F65DFF82}" = Microsoft_VC100_CRT_SP1_x64
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F05E704-30A6-421A-97A7-8EEB1C7FF011}" = Corel Shell Extension - 64Bit
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUS_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUS_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUS_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUS_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUS_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUS_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUS_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUS_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AA72DFB8-BA38-49C9-B5A4-A95FD62641F8}" = BOINC
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}" = MSVC90_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{BCF07271-A853-4D3A-B668-4B752174CAA8}" = iTunes
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{D759947B-8C5A-4480-B0DB-FC391F061C85}" = Adobe Photoshop Lightroom 4.3 64-bit
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FD7DEB7B-8CEA-44E5-AB2D-7C66786C0563}" = Waterfox
"62BBD193ADFDBB228C7E1ADB56463F5732FF7F6F" = Windows Driver Package - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"Autopano Giga" = Autopano Giga
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.58
"FCEC33AD40CEA5E0FC4CEE6E42041A0DA189652D" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"SP6" = Logitech SetPoint 6.15

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Chromium" = Chromium
"Dropbox" = Dropbox
"Hawken" = Hawken
"Limbo" = LIMBO
"SOE-C:/Users/Public/Sony Online Entertainment/Installed Games/PlanetSide 2 PSG" = gamelauncher-ps2-psg
"soe-PlanetSide 2 PSG" = PlanetSide 2
"Spotify" = Spotify
"UnityWebPlayer" = Unity Web Player
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 22.7.2013 17:19:25 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:19:27 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:19:27 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:19:27 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:20:16 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:20:16 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:20:16 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:24:23 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:24:24 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

Error - 22.7.2013 17:24:24 | Computer Name = PC-Ghost | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://ctldl.windows...uthrootstl.cab>
with error: The keyset is not defined. .

[ System Events ]
Error - 22.7.2013 17:19:13 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 17:19:20 | Computer Name = PC-Ghost | Source = WMPNetworkSvc | ID = 866293
Description =

Error - 22.7.2013 17:22:49 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 17:25:07 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 17:26:30 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 17:27:28 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 17:27:53 | Computer Name = PC-Ghost | Source = DCOM | ID = 10010
Description =

Error - 22.7.2013 17:29:24 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 17:30:28 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.

Error - 22.7.2013 17:31:10 | Computer Name = PC-Ghost | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort1.


< End of report >
  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Right click on Computer and select Manage, Yes, then select Device Manager. View, Show Hidden Drivers. Now look in the right pane - probably under Non-Plug and Play and see if you can find Tablet2. Right click on it and Disable. Restart

Download and save the AVG removal tool
http://download.avg....6_2011_1184.exe

Download and save the free Avast installer.
http://www.avast.com...ivirus-download
Uninstall AVG (if you can)

Run the Avg Remover by right clicking an Run As Admin

Reboot

Install Avast. (Register when it asks you - they will try to talk you in to buying the full product but the free version is what we want.)
Once you have it installed and it has updated then tonight let it run a boot-timt scan:


First mute the speakers so it won't wake you up when Windows loads. Click on the Orange ball. Click on Security. Click on AntiVirus. Scroll down to the bottom and find Boot-time scan. Click on Settings. Where it says Heuristic Sensitivity click on the last rectangle so that all of them are orange and it says High. Then change When a threat is found ... to: Move to Chest. OK. Now click on Schedule Now. Close the Avast window and then reboot. The scan will start. It will tell you where it will save the report. Usually it's
C:\ProgramData\AVAST Software\Avast\report\aswBoot.txt but it might change so verify the location. When Windows loads Click on the Orange Ball then Maintenance then Scan Logs. Click on the Boot-time scan log and then View Results. IF it found anything then open the saved Report and copy and paste the text into a reply so I can see it.
  • 0

#10
klmk

klmk

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Hi

Could not find Tablet2 and the Avast installer fails with an error. The AVG remover ran okay though. I've pasted the Avast installation log below.


23.07.201310:54:16Started: 23.07.2013, 10:54:16
23.07.201310:54:16Operation set to INST_OP_UNKNOWN
23.07.201310:54:16Old version: ffffffff (-1)
23.07.201310:54:16Cmdline: /sfx /sfxstorage "C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea" /GetEdition:free /edition "1" /brandcode "A" /srcpath "C:\Users\Ghost\Desktop" /sfxname "avast_free_antivirus_setup"
23.07.201310:54:16SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:16Running SETUP_AIS-5d1 (1489)
23.07.201310:54:16Operating system: Windows 7 ver 6.1, build 7601, sp 1.0 [Service Pack 1] x64
23.07.201310:54:16Memory: 33% load. Phys:2792964/4193784K free, Page:4194303/4194303K free, Virt:2008768/2097024K free
23.07.201310:54:16Computer WinName: PC-GHOST
23.07.201310:54:16Windows Net User: PC-Ghost\Ghost
23.07.201310:54:16DldSrc set to sfx
23.07.201310:54:16Old version: ffffffff (-1)
23.07.201310:54:16Install check: SetupVersion does NOT exist
23.07.201310:54:16SGW32AIS::CheckIfInstalled set m_bAlreadyInstalled and m_bIsOldVersionDetected to 0
23.07.201310:54:17SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:17SYNCER: Type: use IE settings
23.07.201310:54:17SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:20Used server:
23.07.201310:54:20Setup GUI has been successfuly loaded from DLL.
23.07.201310:54:20Ignoring cmdline switch: /GetEdition:free
23.07.201310:54:20Cannot get reg. key:Software\Microsoft\Internet Explorer
23.07.201310:54:20Error:Unknown error
23.07.201310:54:22Operation set to INST_OP_INSTALL
23.07.201310:54:22GUID: 7fd9fbe7-0699-4c26-be49-aeb426ef1c89
23.07.201310:54:22SelectCurrent: selected server 'tmp sfx storage' from 'sfx'
23.07.201310:54:22SYNCER: Type: use IE settings
23.07.201310:54:22SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:22Changed Edition=1
23.07.201310:54:22Debug: Windows Server registry key not retrieved.
23.07.201310:54:22Entered SetupProcessAIS::Do( INST_OP_INSTALL )
23.07.201310:54:22Entered SetupProcessWin32Avast::Do( INST_OP_INSTALL )
23.07.201310:54:22Entered SetupProcessWin32::Do( INST_OP_INSTALL )
23.07.201310:54:22Entered SetupProcess::Do( INST_OP_INSTALL )
23.07.201310:54:22SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:22SYNCER: Type: use IE settings
23.07.201310:54:22SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:22Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:25SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:25SYNCER: Type: use IE settings
23.07.201310:54:25SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:25Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:25SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:25SYNCER: Type: use IE settings
23.07.201310:54:25SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:25Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:27SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:27SYNCER: Type: use IE settings
23.07.201310:54:27SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:27Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:27Destination folder: C:\Program Files\AVAST Software\Avast
23.07.201310:54:27LoadPartInfo: jrog = jrog-a7 returned 00000000
23.07.201310:54:27LoadPartInfo: jrog2 = jrog2-7a5 returned 00000000
23.07.201310:54:27LoadPartInfo: program = prg_ais-5d1 returned 00000000
23.07.201310:54:27LoadPartInfo: setup = setup_ais-5d1 returned 00000000
23.07.201310:54:27LoadPartInfo: vps = vps_win32-13050900 returned 00000000
23.07.201310:54:27Part prg_ais-5d1 was set to be installed
23.07.201310:54:27Part vps_win32-13050900 was set to be installed
23.07.201310:54:27Part setup_ais-5d1 was set to be installed
23.07.201310:54:27Part jrog-a7 was set to be installed
23.07.201310:54:27Part jrog2-7a5 was set to be installed
23.07.201310:54:27SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:27SYNCER: Type: use IE settings
23.07.201310:54:27SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:27Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:27Operation set to INST_OP_INSTALL
23.07.201310:54:27FilterOutExistingFiles: 632 & 0 = 632
23.07.201310:54:27IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package setif_ais set to 1
23.07.201310:54:27IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package setup_ais set to 1
23.07.201310:54:27IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_core set to 1
23.07.201310:54:27IsFullOkay: ais_dll_fin-3c5.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_dll_fin-3c5.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_dll_fin set to 1
23.07.201310:54:27IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_res set to 1
23.07.201310:54:27IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_x64 set to 1
23.07.201310:54:27IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_32 set to 1
23.07.201310:54:27IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_win32 set to 1
23.07.201310:54:27IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_win64 set to 1
23.07.201310:54:27IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package jrog set to 1
23.07.201310:54:27IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package jrog2 set to 1
23.07.201310:54:27FilterOutExistingFiles: 632 & 0 = 632
23.07.201310:54:27FilterOutExistingFiles: 547 & 0 = 547
23.07.201310:54:27IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package setif_ais set to 1
23.07.201310:54:27IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package setup_ais set to 1
23.07.201310:54:27IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_core set to 1
23.07.201310:54:27IsFullOkay: ais_dll_fin-3c5.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_dll_fin-3c5.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_dll_fin set to 1
23.07.201310:54:27IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_res set to 1
23.07.201310:54:27IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_x64 set to 1
23.07.201310:54:27IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_32 set to 1
23.07.201310:54:27IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_win32 set to 1
23.07.201310:54:27IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_win64 set to 1
23.07.201310:54:27IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package jrog set to 1
23.07.201310:54:27IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package jrog2 set to 1
23.07.201310:54:27FilterOutExistingFiles: 547 & 0 = 547
23.07.201310:54:27FilterOutExistingFiles: 632 & 0 = 632
23.07.201310:54:27IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package setif_ais set to 1
23.07.201310:54:27IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package setup_ais set to 1
23.07.201310:54:27IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_core set to 1
23.07.201310:54:27IsFullOkay: ais_dll_fin-3c5.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_dll_fin-3c5.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_dll_fin set to 1
23.07.201310:54:27IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_res set to 1
23.07.201310:54:27IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package ais_x64 set to 1
23.07.201310:54:27IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_32 set to 1
23.07.201310:54:27IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_win32 set to 1
23.07.201310:54:27IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package vps_win64 set to 1
23.07.201310:54:27IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package jrog set to 1
23.07.201310:54:27IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:27IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:27SetFullAsMarked: Package jrog2 set to 1
23.07.201310:54:27FilterOutExistingFiles: 632 & 0 = 632
23.07.201310:54:28FilterOutExistingFiles: 632 & 0 = 632
23.07.201310:54:29FilterOutExistingFiles: 1058 & 0 = 1058
23.07.201310:54:30FilterOutExistingFiles: 624 & 0 = 624
23.07.201310:54:31FilterOutExistingFiles: 638 & 0 = 638
23.07.201310:54:38SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:38SYNCER: Type: use IE settings
23.07.201310:54:38SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:38Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:38SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:38SYNCER: Type: use IE settings
23.07.201310:54:38SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:38Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:38FilterOutExistingFiles: 640 & 0 = 640
23.07.201310:54:38IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: setif_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package setif_ais set to 1
23.07.201310:54:38IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: setup_ais-5d1.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package setup_ais set to 1
23.07.201310:54:38IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package ais_core set to 1
23.07.201310:54:38IsFullOkay: ais_dll_eng-52b.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: ais_dll_eng-52b.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package ais_dll_eng set to 1
23.07.201310:54:38IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package ais_res set to 1
23.07.201310:54:38IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package ais_x64 set to 1
23.07.201310:54:38IsFullOkay: winsys-8.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: winsys-8.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package winsys set to 1
23.07.201310:54:38IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package vps_32 set to 1
23.07.201310:54:38IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package vps_win32 set to 1
23.07.201310:54:38IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package vps_win64 set to 1
23.07.201310:54:38IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package jrog set to 1
23.07.201310:54:38IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:38IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:38SetFullAsMarked: Package jrog2 set to 1
23.07.201310:54:38FilterOutExistingFiles: 640 & 0 = 640
23.07.201310:54:39SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:39SYNCER: Type: use IE settings
23.07.201310:54:39SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:39Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:39SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:39SYNCER: Type: use IE settings
23.07.201310:54:39SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:39Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:39SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:39SYNCER: Type: use IE settings
23.07.201310:54:39SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:39Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:39SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:39SYNCER: Type: use IE settings
23.07.201310:54:39SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:39Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:40SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:40LoadPartInfo: jrog = jrog-a7 returned 00000000
23.07.201310:54:40LoadPartInfo: jrog2 = jrog2-7a5 returned 00000000
23.07.201310:54:40LoadPartInfo: program = prg_ais-5d1 returned 00000000
23.07.201310:54:40LoadPartInfo: setup = setup_ais-5d1 returned 00000000
23.07.201310:54:40LoadPartInfo: vps = vps_win32-13050900 returned 00000000
23.07.201310:54:40Part prg_ais-5d1 was set to be installed
23.07.201310:54:40Part vps_win32-13050900 was set to be installed
23.07.201310:54:40Part setup_ais-5d1 was set to be installed
23.07.201310:54:40Part jrog-a7 was set to be installed
23.07.201310:54:40Part jrog2-7a5 was set to be installed
23.07.201310:54:41FilterOutExistingFiles: 640 & 0 = 640
23.07.201310:54:41FilterOutExistingFiles: 640 & 0 = 640
23.07.201310:54:41IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_core set to 1
23.07.201310:54:41IsFullOkay: ais_dll_eng-52b.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_dll_eng-52b.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_dll_eng set to 1
23.07.201310:54:41IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_res set to 1
23.07.201310:54:41IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_x64 set to 1
23.07.201310:54:41IsFullOkay: winsys-8.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: winsys-8.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package winsys set to 1
23.07.201310:54:41IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package vps_32 set to 1
23.07.201310:54:41IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package vps_win32 set to 1
23.07.201310:54:41IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package vps_win64 set to 1
23.07.201310:54:41IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package jrog set to 1
23.07.201310:54:41IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package jrog2 set to 1
23.07.201310:54:41FilterOutExistingFiles: 640 & 0 = 640
23.07.201310:54:41IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_core-4d3.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_core set to 1
23.07.201310:54:41IsFullOkay: ais_dll_eng-52b.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_dll_eng-52b.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_dll_eng set to 1
23.07.201310:54:41IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_res-41a.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_res set to 1
23.07.201310:54:41IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: ais_x64-57a.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package ais_x64 set to 1
23.07.201310:54:41IsFullOkay: winsys-8.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: winsys-8.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package winsys set to 1
23.07.201310:54:41IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: vps_32-ac0.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package vps_32 set to 1
23.07.201310:54:41IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: vps_win32-ad3.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package vps_win32 set to 1
23.07.201310:54:41IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: vps_win64-763.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package vps_win64 set to 1
23.07.201310:54:41IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: jrog-a7.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package jrog set to 1
23.07.201310:54:41IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:41IsFullOkay: jrog2-7a5.vpx - not okay (doesn't exist)
23.07.201310:54:41SetFullAsMarked: Package jrog2 set to 1
23.07.201310:54:41Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:41GetFileWithRetry: ais_core-4d3.vpx downloaded and verified
23.07.201310:54:41DldPackage: C:\Program Files\AVAST Software\Avast\Setup\ais_core-4d3.vpx, returned 0x00000000
23.07.201310:54:42Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:42GetFileWithRetry: ais_dll_eng-52b.vpx downloaded and verified
23.07.201310:54:42DldPackage: C:\Program Files\AVAST Software\Avast\Setup\ais_dll_eng-52b.vpx, returned 0x00000000
23.07.201310:54:42Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:42GetFileWithRetry: ais_res-41a.vpx downloaded and verified
23.07.201310:54:42DldPackage: C:\Program Files\AVAST Software\Avast\Setup\ais_res-41a.vpx, returned 0x00000000
23.07.201310:54:42Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:42GetFileWithRetry: ais_x64-57a.vpx downloaded and verified
23.07.201310:54:42DldPackage: C:\Program Files\AVAST Software\Avast\Setup\ais_x64-57a.vpx, returned 0x00000000
23.07.201310:54:42Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:42GetFileWithRetry: winsys-8.vpx downloaded and verified
23.07.201310:54:42DldPackage: C:\Program Files\AVAST Software\Avast\Setup\winsys-8.vpx, returned 0x00000000
23.07.201310:54:43Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:43GetFileWithRetry: vps_32-ac0.vpx downloaded and verified
23.07.201310:54:43DldPackage: C:\Program Files\AVAST Software\Avast\Setup\vps_32-ac0.vpx, returned 0x00000000
23.07.201310:54:49Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:49GetFileWithRetry: vps_win32-ad3.vpx downloaded and verified
23.07.201310:54:49DldPackage: C:\Program Files\AVAST Software\Avast\Setup\vps_win32-ad3.vpx, returned 0x00000000
23.07.201310:54:49Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:49GetFileWithRetry: vps_win64-763.vpx downloaded and verified
23.07.201310:54:49DldPackage: C:\Program Files\AVAST Software\Avast\Setup\vps_win64-763.vpx, returned 0x00000000
23.07.201310:54:49Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:49GetFileWithRetry: jrog-a7.vpx downloaded and verified
23.07.201310:54:49DldPackage: C:\Program Files\AVAST Software\Avast\Setup\jrog-a7.vpx, returned 0x00000000
23.07.201310:54:49Used server: C:\Users\Ghost\AppData\Local\Temp\_av_sfx.tm~8664d548-fd38-4964-a3e9-5bad10c28eea
23.07.201310:54:49GetFileWithRetry: jrog2-7a5.vpx downloaded and verified
23.07.201310:54:49DldPackage: C:\Program Files\AVAST Software\Avast\Setup\jrog2-7a5.vpx, returned 0x00000000
23.07.201310:54:49setup: updated
23.07.201310:54:49setif: updated
23.07.201310:54:49FilterOutExistingFiles: 640 & 0 = 640
23.07.201310:54:49Extracting from ais_core-4d3.vpx
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\addtap.bat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\addtap.bat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\addtap.bat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\addtap.bat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\addtap.bat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\addtap.bat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\addtap.bat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\addtap.bat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\addtap.bat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\deltapall.bat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\deltapall.bat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\deltapall.bat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\deltapall.bat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\deltapall.bat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\deltapall.bat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\deltapall.bat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\deltapall.bat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\deltapall.bat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\Setup\INF\v5\aswnet.cat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\Setup\INF\v5\aswnet.cat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\Setup\INF\v5\aswnet.cat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\Setup\INF\v6\aswnet.cat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\Setup\INF\v6\aswnet.cat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\Setup\INF\v6\aswnet.cat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\tap0901.cat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\tap0901.cat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\tap0901.cat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\tap0901.cat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\tap0901.cat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\tap0901.cat
23.07.201310:54:49insInstallFile: strDestPath='C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\tapoas.cat', instOnly='0x00000000'.
23.07.201310:54:49Direct move of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\tapoas.cat
23.07.201310:54:49Installed file:C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\tapoas.cat
23.07.201310:54:49ERROR CPkgExtractor::ExtractToFile, creating file '%RWPATH%\SecureLine\\SecureLine\onefile', error 2 (0x00000002)
23.07.201310:54:49ERROR: ExtractToFile for file 'secureline.cfg' returned 2 (0x00000002)
23.07.201310:54:49Extract: tried to extract '%RWPATH%\SecureLine\\SecureLine\secureline.cfg' from pkg 'ais_core' but failed miserably. Error code 0x00000002
23.07.201310:54:50Uninstalling aswTdi.sys
23.07.201310:54:50Stopping service aswTdi
23.07.201310:54:50OpenSCManager
23.07.201310:54:50OpenService
23.07.201310:54:50OpenService, errcode: 0x00000424
23.07.201310:54:50Service aswTdi stopped, errcode: 0x00000424
23.07.201310:54:50Executing:"C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\tapinstall.exe" remove tap0901
23.07.201310:54:50ERROR:Not executed:"C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\tapinstall.exe" remove tap0901, code:0x00000002
23.07.201310:54:50Cannot open reg. key:Software\Microsoft\Windows\CurrentVersion\App Paths\AvastUI.exe
23.07.201310:54:50RegLoadKey(HKEY_USERS, Av_S-1-5-18, C:\Windows\system32\config\systemprofile\NtUser.dat)
23.07.201310:54:50RegUnloadKey
23.07.201310:54:50RegLoadKey(HKEY_USERS, Av_S-1-5-19, C:\Windows\ServiceProfiles\LocalService\NtUser.dat)
23.07.201310:54:50Load registry hive ERROR_SHARING_VIOLATION
23.07.201310:54:50RegLoadKey(HKEY_USERS, Av_S-1-5-20, C:\Windows\ServiceProfiles\NetworkService\NtUser.dat)
23.07.201310:54:50Load registry hive ERROR_SHARING_VIOLATION
23.07.201310:54:50RegLoadKey(HKEY_USERS, Av_S-1-5-21-3981131050-3490162696-685170398-1001, C:\Users\Ghost\NtUser.dat)
23.07.201310:54:50Load registry hive ERROR_SHARING_VIOLATION
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\addtap.bat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\addtap.bat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\addtap.bat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\addtap.bat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\addtap.bat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\addtap.bat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\deltapall.bat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\deltapall.bat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\deltapall.bat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\deltapall.bat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\deltapall.bat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\deltapall.bat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\Setup\INF\v5\aswnet.cat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\INF\v5\aswnet.cat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\Setup\INF\v6\aswnet.cat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\INF\v6\aswnet.cat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\tap0901.cat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win32\tap0901.cat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\tap0901.cat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win64\tap0901.cat
23.07.201310:54:50Removing file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\tapoas.cat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\OpenVPN\driver\win2k\tapoas.cat
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\ais_core-4d3.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\ais_dll_eng-52b.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\ais_res-41a.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\ais_x64-57a.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\avast.setup
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\jrog-a7.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\jrog2-7a5.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\part-jrog-a7.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\part-jrog2-7a5.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\part-prg_ais-5d1.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\part-setup_ais-5d1.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\part-vps_win32-13050900.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\prod-ais.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\servers.def
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\servers.def.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\setiface.dll
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\setiface.ovr
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\setif_ais-5d1.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\setup.ini
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\setup.ovr
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\setup_ais-5d1.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\vps_32-ac0.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\vps_win32-ad3.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\vps_win64-763.vpx
23.07.201310:54:50Direct delete of file: C:\Program Files\AVAST Software\Avast\Setup\winsys-8.vpx
23.07.201310:54:50No recommendation number found
23.07.201310:54:50Transferred: files 12, bytes 488, time 3631 ms
23.07.201310:54:50Retries: total 0, files 0, servers 1
23.07.201310:54:50GetLicNumber: LoadLibrary( C:\Program Files\AVAST Software\Avast\ashBase.dll ) return value: 0x00000000
23.07.201310:54:50DldSrc set to inet
23.07.201310:54:50Server definition(s) loaded for 'main': 112 (maintenance:0)
23.07.201310:54:50SelectCurrent: selected server 'Download412 AVAST5 Server' from 'main'
23.07.201310:54:50SYNCER: Type: use IE settings
23.07.201310:54:50SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:50Sending stats 'http://v7.stats.avast.com/cgi-bin/iavs4stats.cgi': 00000000 204
23.07.201310:54:50NeedReboot=false
23.07.201310:54:50Return code: 0x00000002 [The system cannot find the file specified.]
23.07.201310:54:50Stopped: 23.07.2013, 10:54:50
23.07.201310:54:50SYNCER: Agent=Syncer/5.00 (ais-1489;p)
23.07.201310:54:50SYNCER: Type: use IE settings
23.07.201310:54:50SYNCER: Auth: another authentication, use WinInet
23.07.201310:54:50Used server: http://50.7.97.18/iavs5x
  • 0

Advertisements


#11
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
This si starting to smell like zero access:

Do the following:
  • Click on the Start button and then choose Control Panel.
  • Click on the System and Security link.

    Note: If you're viewing the Large icons or Small icons view of Control Panel, you won't see this link so just click on the Administrative Tools icon and skip to Step 4.
  • In the System and Security window, click on the Administrative Tools heading located near the bottom of the window.
  • In the Administrative Tools window, double-click on the Computer Management icon.
  • When Computer Management opens, click on Disk Management on the left side of the window, located under Storage.

    After a brief loading period, Disk Management should now appear on the right side of the Computer Management window.

    Note: If you don't see Disk Management listed, you may need to click on the |> icon to the left of the Storage icon.
Take a screen Shot of the Disk Management Window and attach the screen shot to your reply.



Download MBRCheck

http://ad13.geekstogo.com/MBRCheck.exe

Save it and run it. It will produce a log MBRCheck(date).txt on your desktop. Copy and paste it into a reply. Close the program.



Try running

http://www.tweaking....all_in_one.html




  • Download RogueKiller and save it on your desktop.
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan
    Posted Image
  • Wait for the end of the scan.
  • Send me the RKreport.txt located on your desktop.

IF you have a USB drive:

For x32 (x86) bit systems download Farbar Recovery Scan Tool 32-Bit and save it to a flash drive.
For x64 bit systems download Farbar Recovery Scan Tool 64-Bit and save it to a flash drive.

Plug the flashdrive into the infected PC.

Enter System Recovery Options.

To enter System Recovery Options from the Advanced Boot Options:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
  • Use the arrow keys to select the Repair your computer menu item.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account an click Next.

To enter System Recovery Options by using Windows installation disc:
  • Insert the installation disc.
  • Restart your computer.
  • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
  • Click Repair your computer.
  • Select English as the keyboard language settings, and then click Next.
  • Select the operating system you want to repair, and then click Next.
  • Select your user account and click Next.

On the System Recovery Options menu you will get the following options:
Startup Repair
System Restore
Windows Complete PC Restore
Windows Memory Diagnostic Tool
Command Prompt
[*]Select Command Prompt
[*]In the command window type in notepad and press Enter.
[*]The notepad opens. Under File menu select Open.
[*]Select "Computer" and find your flash drive letter and close the notepad.
[*]In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
Note: Replace letter e with the drive letter of your flash drive.
[*]The tool will start to run.
[*]When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) on the flash drive. Please copy and paste it to your reply.[/list]
  • 0

#12
klmk

klmk

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Screenshot as attachment, MBRCheck(date), RKreport & FRST .txt's. Tweaking.com's utility doesn't start, Invalid picture error. This was the standalone, I assume the installed one would fare no better.

MBRCheck, version 1.2.3
© 2010, AD

Command-line:
Windows Version: Windows 7 Ultimate Edition
Windows Information: Service Pack 1 (build 7601), 64-bit
Base Board Manufacturer: Sapphire
BIOS Manufacturer: Phoenix Technologies, LTD
System Manufacturer: Unknow
System Product Name: Unknow
Logical Drives Mask: 0x000002fc

Kernel Drivers (total 210):
0x03459000 \SystemRoot\system32\ntoskrnl.exe
0x03410000 \SystemRoot\system32\hal.dll
0x00BD5000 \SystemRoot\system32\kdcom.dll
0x00CE7000 \SystemRoot\system32\mcupdate_AuthenticAMD.dll
0x00CF4000 \SystemRoot\system32\PSHED.dll
0x00D08000 \SystemRoot\system32\CLFS.SYS
0x00C00000 \SystemRoot\system32\CI.dll
0x00E3B000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00EFD000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x01190000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x01199000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x01000000 \SystemRoot\system32\drivers\ACPI.sys
0x01057000 \SystemRoot\system32\drivers\msisadrv.sys
0x01061000 \SystemRoot\system32\drivers\vdrvroot.sys
0x011C8000 \SystemRoot\system32\drivers\pci.sys
0x00F0D000 \SystemRoot\System32\drivers\partmgr.sys
0x00F22000 \SystemRoot\system32\drivers\volmgr.sys
0x00F37000 \SystemRoot\System32\drivers\volmgrx.sys
0x0106E000 \SystemRoot\system32\drivers\pciide.sys
0x00F93000 \SystemRoot\system32\drivers\PCIIDEX.SYS
0x00FA3000 \SystemRoot\System32\drivers\mountmgr.sys
0x00FBD000 \SystemRoot\system32\drivers\vmbus.sys
0x00E00000 \SystemRoot\system32\drivers\winhv.sys
0x01075000 \SystemRoot\system32\drivers\atapi.sys
0x00D66000 \SystemRoot\system32\drivers\ataport.SYS
0x00E14000 \SystemRoot\system32\drivers\amdxata.sys
0x00D90000 \SystemRoot\system32\drivers\fltmgr.sys
0x00E1F000 \SystemRoot\system32\drivers\fileinfo.sys
0x01220000 \SystemRoot\System32\Drivers\Ntfs.sys
0x014CE000 \SystemRoot\System32\Drivers\msrpc.sys
0x0152C000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01547000 \SystemRoot\System32\Drivers\cng.sys
0x015B9000 \SystemRoot\System32\drivers\pcw.sys
0x015CA000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016C4000 \SystemRoot\system32\drivers\ndis.sys
0x01600000 \SystemRoot\system32\drivers\NETIO.SYS
0x01660000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01800000 \SystemRoot\System32\drivers\tcpip.sys
0x017B6000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x0168B000 \SystemRoot\system32\drivers\vmstorfl.sys
0x01400000 \SystemRoot\system32\drivers\volsnap.sys
0x0169B000 \SystemRoot\System32\Drivers\spldr.sys
0x016A3000 \SystemRoot\SysWOW64\speedfan.sys
0x016AA000 \SystemRoot\system32\DRIVERS\Soluto.sys
0x0144C000 \SystemRoot\System32\drivers\rdyboost.sys
0x01486000 \SystemRoot\System32\Drivers\mup.sys
0x01498000 \SystemRoot\System32\drivers\hwpolicy.sys
0x013C2000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x014A1000 \SystemRoot\system32\DRIVERS\disk.sys
0x01ABD000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x01B23000 \SystemRoot\system32\drivers\cdrom.sys
0x01B4D000 \SystemRoot\System32\Drivers\Null.SYS
0x01B56000 \SystemRoot\System32\Drivers\Beep.SYS
0x01B5D000 \??\C:\Windows\system32\drivers\avgtpx64.sys
0x01B6C000 \SystemRoot\System32\drivers\vga.sys
0x01B7A000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x01B9F000 \SystemRoot\System32\drivers\watchdog.sys
0x01BAF000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0x01BB8000 \SystemRoot\system32\drivers\rdpencdd.sys
0x01BC1000 \SystemRoot\system32\drivers\rdprefmp.sys
0x01BCA000 \SystemRoot\System32\Drivers\Msfs.SYS
0x01BD5000 \SystemRoot\System32\Drivers\Npfs.SYS
0x01A00000 \SystemRoot\system32\DRIVERS\tdx.sys
0x01A22000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x01A2F000 \SystemRoot\System32\DRIVERS\netbt.sys
0x0107E000 \SystemRoot\system32\drivers\afd.sys
0x01A74000 \SystemRoot\system32\drivers\ws2ifsl.sys
0x01A7F000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x01A88000 \SystemRoot\system32\DRIVERS\pacer.sys
0x01BE6000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x01AAE000 \SystemRoot\system32\DRIVERS\netbios.sys
0x015D4000 \SystemRoot\system32\DRIVERS\serial.sys
0x01200000 \SystemRoot\system32\DRIVERS\wanarp.sys
0x014B7000 \SystemRoot\system32\drivers\termdd.sys
0x01107000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x015F1000 \SystemRoot\system32\drivers\nsiproxy.sys
0x01158000 \SystemRoot\system32\drivers\mssmbios.sys
0x01163000 \SystemRoot\System32\Drivers\ElbyCDIO.sys
0x0116E000 \SystemRoot\System32\drivers\discache.sys
0x0403A000 \SystemRoot\system32\drivers\csc.sys
0x040BD000 \SystemRoot\System32\Drivers\dfsc.sys
0x040DB000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x040EC000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x04112000 \SystemRoot\system32\DRIVERS\amdppm.sys
0x04127000 \SystemRoot\system32\drivers\wmiacpi.sys
0x04130000 \SystemRoot\system32\DRIVERS\atikmpag.sys
0x04A25000 \SystemRoot\system32\DRIVERS\atikmdag.sys
0x04461000 \SystemRoot\System32\drivers\dxgkrnl.sys
0x04555000 \SystemRoot\System32\drivers\dxgmms1.sys
0x0459B000 \SystemRoot\system32\drivers\HDAudBus.sys
0x0551F000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x045BF000 \SystemRoot\system32\DRIVERS\usbohci.sys
0x04400000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x045CA000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x045DB000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x045E8000 \SystemRoot\system32\DRIVERS\fdc.sys
0x055A4000 \SystemRoot\system32\DRIVERS\serenum.sys
0x055B0000 \SystemRoot\system32\DRIVERS\irsir.sys
0x045F5000 \SystemRoot\system32\drivers\irenum.sys
0x055BC000 \SystemRoot\system32\drivers\i8042prt.sys
0x055DA000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x055E9000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x04A00000 \SystemRoot\system32\drivers\CompositeBus.sys
0x0418A000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x041A0000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x04A10000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x041C4000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x04000000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x00DDC000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x0401B000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x04456000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x0117D000 \SystemRoot\system32\DRIVERS\VClone.sys
0x045FE000 \SystemRoot\system32\drivers\swenum.sys
0x04628000 \SystemRoot\system32\drivers\ks.sys
0x0466B000 \SystemRoot\system32\drivers\WmBEnum.sys
0x04670000 \SystemRoot\system32\drivers\WmXlCore.sys
0x04682000 \SystemRoot\system32\DRIVERS\PTSimBus.sys
0x0468E000 \SystemRoot\system32\DRIVERS\amdiox64.sys
0x046A2000 \SystemRoot\system32\drivers\umbus.sys
0x046B4000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x0470E000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x04723000 \SystemRoot\system32\drivers\AtihdW76.sys
0x0473E000 \SystemRoot\system32\drivers\portcls.sys
0x0477B000 \SystemRoot\system32\drivers\drmk.sys
0x0479D000 \SystemRoot\system32\drivers\ksthunk.sys
0x06C3A000 \SystemRoot\system32\drivers\RTKVHD64.sys
0x06C00000 \SystemRoot\System32\Drivers\crashdmp.sys
0x06C0E000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x06C1A000 \SystemRoot\System32\Drivers\dump_atapi.sys
0x06C23000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x000D0000 \SystemRoot\System32\win32k.sys
0x047A3000 \SystemRoot\System32\drivers\Dxapi.sys
0x0287B000 \SystemRoot\system32\DRIVERS\RTL8192su.sys
0x0293E000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x0294B000 \SystemRoot\system32\DRIVERS\monitor.sys
0x004C0000 \SystemRoot\System32\TSDDD.dll
0x00860000 \SystemRoot\System32\ATMFD.DLL
0x00710000 \SystemRoot\System32\cdd.dll
0x02959000 \SystemRoot\system32\drivers\luafv.sys
0x0297C000 \??\C:\Windows\system32\drivers\mbam.sys
0x02986000 \SystemRoot\system32\DRIVERS\irda.sys
0x029A9000 \SystemRoot\system32\DRIVERS\lltdio.sys
0x02800000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x02853000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x029BE000 \SystemRoot\system32\DRIVERS\rspndr.sys
0x029D6000 \SystemRoot\system32\DRIVERS\vwifimp.sys
0x03C68000 \SystemRoot\system32\drivers\HTTP.sys
0x03D31000 \SystemRoot\system32\DRIVERS\bowser.sys
0x03D4F000 \SystemRoot\System32\drivers\mpsdrv.sys
0x03D67000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x03D94000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x03C00000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x03C24000 \SystemRoot\System32\Drivers\adfs.SYS
0x03C3C000 \??\C:\Windows\system32\drivers\cpuz135_x64.sys
0x086BB000 \SystemRoot\system32\drivers\peauth.sys
0x08761000 \SystemRoot\System32\Drivers\secdrv.SYS
0x0876C000 \SystemRoot\System32\DRIVERS\srvnet.sys
0x0879D000 \SystemRoot\System32\drivers\tcpipreg.sys
0x08600000 \SystemRoot\System32\DRIVERS\srv2.sys
0x08CEA000 \SystemRoot\System32\DRIVERS\srv.sys
0x08D82000 \SystemRoot\system32\DRIVERS\LVPr2M64.sys
0x08D8C000 \SystemRoot\system32\DRIVERS\asyncmac.sys
0x08D97000 \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys
0x08C00000 \SystemRoot\system32\drivers\spsys.sys
0x770B0000 \Windows\System32\ntdll.dll
0x484B0000 \Windows\System32\smss.exe
0xFF3D0000 \Windows\System32\apisetschema.dll
0xFF770000 \Windows\System32\autochk.exe
0xFF320000 \Windows\System32\comdlg32.dll
0x77280000 \Windows\System32\normaliz.dll
0xFF210000 \Windows\System32\msctf.dll
0xFF190000 \Windows\System32\difxapi.dll
0xFF0B0000 \Windows\System32\advapi32.dll
0xFE320000 \Windows\System32\shell32.dll
0xFE280000 \Windows\System32\clbcatq.dll
0xFE230000 \Windows\System32\ws2_32.dll
0x76FB0000 \Windows\System32\user32.dll
0x76E90000 \Windows\System32\kernel32.dll
0xFE220000 \Windows\System32\nsi.dll
0xFE0F0000 \Windows\System32\rpcrt4.dll
0xFE090000 \Windows\System32\Wldap32.dll
0xFE070000 \Windows\System32\sechost.dll
0xFE040000 \Windows\System32\imm32.dll
0xFDFA0000 \Windows\System32\msvcrt.dll
0xFDD90000 \Windows\System32\ole32.dll
0xFDCB0000 \Windows\System32\oleaut32.dll
0xFDAD0000 \Windows\System32\setupapi.dll
0xFD8A0000 \Windows\System32\wininet.dll
0xFD880000 \Windows\System32\imagehlp.dll
0xFD720000 \Windows\System32\urlmon.dll
0xFD6A0000 \Windows\System32\shlwapi.dll
0xFD410000 \Windows\System32\iertutil.dll
0xFD400000 \Windows\System32\lpk.dll
0xFD330000 \Windows\System32\usp10.dll
0x77270000 \Windows\System32\psapi.dll
0xFD2C0000 \Windows\System32\gdi32.dll
0xFD2B0000 \Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
0xFD240000 \Windows\System32\KernelBase.dll
0xFD220000 \Windows\System32\devobj.dll
0xFD210000 \Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
0xFD200000 \Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
0xFD1F0000 \Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
0xFD1B0000 \Windows\System32\wintrust.dll
0xFD110000 \Windows\System32\comctl32.dll
0xFD0D0000 \Windows\System32\cfgmgr32.dll
0xFD0C0000 \Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
0xFD0B0000 \Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
0xFCF40000 \Windows\System32\crypt32.dll
0xFCF30000 \Windows\System32\msasn1.dll
0x758B0000 \Windows\SysWOW64\normaliz.dll

Processes (total 69):
0 System Idle Process
4 System
276 C:\Windows\System32\smss.exe
476 csrss.exe
548 C:\Windows\System32\wininit.exe
580 csrss.exe
604 C:\Windows\System32\services.exe
620 C:\Windows\System32\lsass.exe
628 C:\Windows\System32\lsm.exe
736 C:\Windows\System32\svchost.exe
812 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
856 C:\Windows\System32\winlogon.exe
896 C:\Windows\System32\svchost.exe
116 C:\Windows\System32\atiesrxx.exe
288 C:\Windows\System32\svchost.exe
492 C:\Windows\System32\svchost.exe
336 C:\Windows\System32\svchost.exe
560 C:\Windows\System32\svchost.exe
1068 C:\Windows\System32\audiodg.exe
1108 C:\Windows\System32\svchost.exe
1248 C:\Windows\System32\svchost.exe
1332 C:\Windows\System32\atieclxx.exe
1540 C:\Windows\System32\spoolsv.exe
1596 C:\Windows\System32\svchost.exe
1688 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
1788 C:\Windows\System32\taskhost.exe
1884 C:\Windows\System32\dwm.exe
1936 C:\Windows\explorer.exe
2008 C:\Program Files (x86)\Bonjour\mDNSResponder.exe
2044 C:\Windows\System32\svchost.exe
2052 C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
2192 C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
2212 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
2260 C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
2296 C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe
2304 C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
2344 C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe
2528 C:\Program Files\Soluto\SolutoLauncherService.exe
2596 C:\Program Files\Soluto\SolutoService.exe
2896 C:\Windows\System32\svchost.exe
2928 C:\Windows\System32\svchost.exe
2992 C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
2352 C:\Windows\System32\drivers\WTSrv.exe
2520 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
2712 C:\Program Files (x86)\Canon\CAL\CALMAIN.exe
1708 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
2664 C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
2984 C:\Program Files\Soluto\Soluto.exe
3000 D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe
2892 D:\Ohjelmat\Desktop Media\mediadetect.exe
3060 C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
3716 C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
3808 C:\Windows\System32\SearchIndexer.exe
4004 C:\Windows\System32\svchost.exe
3168 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
2544 C:\Users\Ghost\AppData\Roaming\Mozilla\Firefox\Profiles\nmnjp6bc.default\extensions\{E173B749-DB5B-4fd2-BA0E-94ECEA0CA55B}\components\afom.exe
4148 C:\Windows\System32\sppsvc.exe
4588 C:\Windows\System32\svchost.exe
3272 C:\Windows\System32\mmc.exe
2744 C:\Windows\System32\vds.exe
2700 WmiPrvSE.exe
3612 D:\Ohjelmat\Adobe\Adobe Photoshop CS5.1 (64 Bit)\Photoshop.exe
1992 WmiPrvSE.exe
3280 C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe
4704 C:\Windows\System32\svchost.exe
2068 C:\Program Files\Soluto\SolutoConsole.exe
4324 C:\Windows\System32\dllhost.exe
4876 D:\MBRCheck.exe
1048 C:\Windows\System32\conhost.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000050`91100000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000000`00100000 (NTFS)
\\.\E: --> \\.\PhysicalDrive0 at offset 0x00000076`6eb00000 (NTFS)
\\.\F: --> \\.\PhysicalDrive1 at offset 0x00000000`00100000 (NTFS)

PhysicalDrive0 Model Number: WDCWD6400AAKS-22A7B2, Rev: 01.03B01
PhysicalDrive1 Model Number: ST3500418AS, Rev: CC34

Size Device Name MBR Status
--------------------------------------------
596 GB \\.\PhysicalDrive0 Windows 7 MBR code detected
SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB79
465 GB \\.\PhysicalDrive1 Windows 2008 MBR code detected
SHA1: 8DF43F2BDE2D9451948FA14B5279969C777A7979


Done!


RogueKiller V8.6.3 _x64_ [Jul 17 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.co...es/roguekiller/
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Ghost [Admin rights]
Mode : Scan -- Date : 07/23/2013 21:17:49
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 5 ¤¤¤
[HJ POL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ POL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ POL] HKLM\[...]\Wow6432Node\[...]\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 2 ¤¤¤
[V1][SUSP PATH] AVG-Secure-Search-Update_JUNE2013_TB_rmv.job : C:\Windows\TEMP\{BFF050CB-C768-4C6C-AA66-368FF17EFFB1}.exe - --uninstall=1 [x] -> FOUND
[V2][SUSP PATH] AVG-Secure-Search-Update_JUNE2013_TB_rmv : C:\Windows\TEMP\{BFF050CB-C768-4C6C-AA66-368FF17EFFB1}.exe - --uninstall=1 [x] -> FOUND

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts


127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD6400AAKS-22A7B2 ATA Device +++++
--- User ---
[MBR] 3b82551e0277e70c8d9be63a301180e2
[BSP] 85f8278296a0fad3973466c0d106b7f5 : Windows 7/8 MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 329999 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 675842048 | Size: 155098 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 993482752 | Size: 125379 Mo
User = LL1 ... OK!
User = LL2 ... OK!

+++++ PhysicalDrive1: WDC WD6400AAKS-22A7B2 ATA Device +++++
--- User ---
[MBR] 39d5cec76d12b2b23857ab33d01a5866
[BSP] 61499852b250d39c589f88d28cbf3e2b : Windows Vista MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 476937 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_07232013_211749.txt >>


Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-07-2013
Ran by SYSTEM on 23-07-2013 21:28:09
Running from I:\
Windows 7 Ultimate (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981088 2009-07-20] (Realtek Semiconductor)
HKLM\...\Run: [Start WingMan Profiler] - C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2010-06-14] (Logitech Inc.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [Soluto] - c:\program files\soluto\soluto.exe [1230400 2013-06-04] (Soluto)
HKLM-x32\...\Winlogon: [Shell] [x ] () <=== ATTENTION
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\Ghost\...\Run: [AdobeBridge] - [x]
HKU\Ghost\...\Run: [Spotify Web Helper] - "D:\Ohjelmat\Spotify\Data\SpotifyWebHelper.exe" [x]
Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Ghost\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Ghost\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)

==================== Services (Whitelisted) =================

S3 Adobe Version Cue CS4; C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [284016 2008-08-14] (Adobe Systems Incorporated)
S2 CCALib8; C:\Program Files (x86)\Canon\CAL\CALMAIN.exe [96341 2005-09-30] (Canon Inc.)
S2 KMService; C:\Windows\SysWow64\srvany.exe [8192 2010-10-08] ()
S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75136 2010-11-29] ()
S2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2010-04-16] (Realtek)
S2 SolutoLauncherService; C:\Program Files\Soluto\SolutoLauncherService.exe [182848 2013-06-04] (Soluto)
S3 SolutoRemoteService; C:\Program Files\Soluto\SolutoRemoteService.exe [1671680 2013-06-04] (GlavSoft LLC.)
S2 vToolbarUpdater15.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [1598128 2013-07-01] (AVG Secure Search)
S2 wuauserv; %systemroot%\system32\wuaueng.dll [x]

==================== Drivers (Whitelisted) ====================

S1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-07-01] (AVG Technologies)
S2 cpuz135; C:\Windows\system32\drivers\cpuz135_x64.sys [21992 2010-11-09] (CPUID)
S3 irsir; C:\Windows\System32\DRIVERS\irsir.sys [27648 2008-01-18] (Microsoft Corporation)
S3 LVPr2M64; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-06] ()
S3 LVPr2Mon; C:\Windows\System32\DRIVERS\LVPr2M64.sys [30232 2009-10-06] ()
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
S0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows ® Server 2003 DDK provider)
S0 speedfan; C:\Windows\SysWow64\speedfan.sys [14104 2007-02-07] (Windows ® Server 2003 DDK provider)
S0 sptd; C:\Windows\System32\Drivers\sptd.sys [818424 2010-12-23] (Duplex Secure Ltd.)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2010-03-30] ()
S2 AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x]
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 cpuz130; \??\C:\Users\Ghost\AppData\Local\Temp\cpuz130\cpuz_x64.sys [x]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [x]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x]
S3 GPU-Z; \??\C:\Users\Ghost\AppData\Local\Temp\GPU-Z.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 Tablet2k; "%SystemRoot%\System32\Drivers\Tablet2k.sys" [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-23 21:27 - 2013-07-23 21:27 - 00000000 ____D C:\FRST
2013-07-23 10:17 - 2013-07-23 10:17 - 00002431 _____ C:\Users\Ghost\Desktop\RKreport[0]_S_07232013_211749.txt
2013-07-23 10:16 - 2013-07-23 10:17 - 00000000 ____D C:\Users\Ghost\Desktop\RK_Quarantine
2013-07-23 10:10 - 2013-07-23 10:10 - 00015787 _____ C:\Users\Ghost\Desktop\MBRCheck_07.23.13_21.10.26.txt
2013-07-22 23:50 - 2013-05-09 12:33 - 117478104 _____ C:\Users\Ghost\Desktop\avast_free_antivirus_setup.exe
2013-07-22 23:42 - 2013-07-22 23:54 - 00000000 ____D C:\Program Files\AVAST Software
2013-07-22 23:31 - 2013-07-22 23:32 - 00178352 _____ C:\Users\Ghost\Desktop\avgremover.log
2013-07-22 23:31 - 2013-05-13 14:54 - 03529160 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Ghost\Desktop\avg_remover_stf_x64_2013_3341.exe
2013-07-22 23:31 - 2011-01-03 05:59 - 01090912 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Ghost\Desktop\avg_remover_stf_x86_2011_1184.exe
2013-07-22 13:10 - 2013-07-22 13:10 - 00018917 _____ C:\AdwCleaner[S1].txt
2013-07-22 07:37 - 2010-09-28 23:51 - 00662016 _____ C:\Users\Ghost\Desktop\MicrosoftFixit50531.msi
2013-07-22 07:35 - 2013-07-22 07:35 - 00000914 _____ C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-22 07:35 - 2013-07-22 07:35 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-22 07:35 - 2013-04-04 03:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2013-07-22 07:34 - 2005-04-21 15:19 - 00935656 _____ (Microsoft Corporation) C:\Users\Ghost\Desktop\VisualBasic6-KB896559-v1-ENU.exe
2013-07-22 01:44 - 2013-07-22 01:44 - 00003804 _____ C:\Users\Ghost\Desktop\FSS.txt
2013-07-22 01:44 - 2013-07-13 04:55 - 00357077 _____ (Farbar) C:\Users\Ghost\Desktop\FSS.exe
2013-07-22 01:25 - 2012-10-05 12:57 - 00602112 _____ (OldTimer Tools) C:\Users\Ghost\Desktop\OTL.exe
2013-07-22 01:22 - 2013-01-10 22:29 - 00061440 _____ ( ) C:\Users\Ghost\Desktop\VEW.exe
2013-07-22 01:18 - 2013-07-22 01:18 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2013-07-22 01:18 - 2013-07-22 01:18 - 00000000 ____D C:\CC Support
2013-07-22 01:18 - 2012-07-11 09:46 - 04009167 _____ C:\Users\Ghost\Desktop\ServicesRepair.exe
2013-07-22 01:16 - 2013-07-22 01:18 - 00000083 _____ C:\Users\Ghost\Desktop\SFC.txt
2013-07-22 01:10 - 2013-07-22 01:10 - 00666633 _____ C:\Users\Ghost\Desktop\adwcleaner.exe
2013-07-22 01:08 - 2013-07-22 01:08 - 00171135 _____ C:\Users\Ghost\Desktop\3001-8022_4-10804572.html
2013-07-22 01:05 - 2013-07-18 13:08 - 00026896 _____ C:\Users\Ghost\Desktop\ComboFix.txt
2013-07-22 00:55 - 2013-07-22 00:55 - 00001631 _____ C:\Users\Ghost\Desktop\aswMBR.txt
2013-07-22 00:55 - 2013-07-22 00:55 - 00000512 _____ C:\Users\Ghost\Desktop\MBR.dat
2013-07-22 00:55 - 2013-02-11 12:29 - 02237968 _____ (Kaspersky Lab ZAO) C:\Users\Ghost\Desktop\tdsskiller.exe
2013-07-21 22:43 - 2013-03-18 11:00 - 04745728 _____ (AVAST Software) C:\Users\Ghost\Desktop\aswMBR.exe
2013-07-18 13:35 - 2013-07-18 13:35 - 00222290 _____ C:\Users\Ghost\Desktop\AVGInstLog.cab
2013-07-18 13:26 - 2013-07-22 13:31 - 00109962 _____ C:\Users\Ghost\Desktop\Extras.Txt
2013-07-18 13:25 - 2013-07-22 13:31 - 00113064 _____ C:\Users\Ghost\Desktop\OTL.Txt
2013-07-18 13:08 - 2013-07-18 13:08 - 00026896 _____ C:\ComboFix.txt
2013-07-18 12:51 - 2013-07-18 13:08 - 00000000 ____D C:\Qoobox
2013-07-18 12:51 - 2009-04-19 20:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-07-18 12:41 - 2013-07-21 17:55 - 00000000 ___SD C:\ComboFix
2013-07-18 12:27 - 2013-07-18 12:27 - 00001137 _____ C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
2013-07-18 12:18 - 2013-07-22 13:12 - 00005556 _____ C:\Windows\PFRO.log
2013-07-18 12:03 - 2013-07-18 12:03 - 00000000 ____D C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2013-07-18 12:03 - 2013-07-18 12:03 - 00000000 ____D C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2013-07-18 12:01 - 2013-07-18 12:17 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Spybot - Search & Destroy
2013-07-18 12:00 - 2013-06-19 08:19 - 36364784 _____ (Safer-Networking Ltd. ) C:\Users\Ghost\Desktop\spybotsd-2.1.20-SR1.exe
2013-07-18 11:29 - 2013-07-21 17:55 - 00000000 ____D C:\Windows\erdnt
2013-07-18 11:25 - 2013-07-18 11:25 - 00000000 _____ C:\Windows\WindowsUpdate.log
2013-07-18 10:52 - 2013-07-23 10:04 - 00000896 _____ C:\Windows\setupact.log
2013-07-18 10:52 - 2013-07-18 10:52 - 00000000 _____ C:\Windows\setuperr.log
2013-07-18 10:37 - 2013-07-18 10:37 - 00064178 _____ C:\Users\Ghost\Documents\cc_20130718_213659.reg
2013-07-18 09:45 - 2013-07-18 09:47 - 00000000 ____D C:\Windows\System32\MRT
2013-07-18 09:41 - 2013-07-18 12:01 - 00000000 ____D C:\Users\Ghost\Desktop\SUPERSetup
2013-07-18 09:41 - 2013-07-18 09:21 - 26611408 _____ (SUPERAntiSpyware.com) C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
2013-07-18 09:30 - 2013-07-18 09:30 - 00000000 ____D C:\Malwarebytes
2013-07-18 09:30 - 2013-04-09 14:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Ghost\Desktop\mbam-setup-1.75.0.1300.exe
2013-07-18 09:02 - 2013-07-18 09:03 - 17737608 _____ (Adobe Systems Incorporated) C:\Users\Ghost\Desktop\install_flash_player.exe
2013-07-17 11:28 - 2013-07-17 11:31 - 67966879 _____ C:\Users\Ghost\Desktop\NTBD.rar
2013-07-17 11:27 - 2013-07-17 12:00 - 101083484 _____ C:\Users\Ghost\Desktop\DHBTPO.rar
2013-07-17 11:25 - 2013-07-17 11:42 - 48537823 _____ C:\Users\Ghost\Desktop\LJD.rar
2013-07-17 10:58 - 2013-07-17 10:59 - 02297856 _____ C:\Users\Ghost\Desktop\Baby_shower.indd
2013-07-11 15:02 - 2013-06-11 15:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-11 15:02 - 2013-06-11 15:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-11 15:02 - 2013-06-11 15:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-11 15:02 - 2013-06-11 15:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-11 15:02 - 2013-06-11 15:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-11 15:02 - 2013-06-11 15:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-11 15:02 - 2013-06-11 15:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-11 15:02 - 2013-06-11 15:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-11 15:02 - 2013-06-11 15:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-11 15:02 - 2013-06-11 15:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-11 15:02 - 2013-06-11 15:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-11 15:02 - 2013-06-11 15:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-11 15:02 - 2013-06-11 15:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-11 15:02 - 2013-06-11 15:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-07-11 15:02 - 2013-06-11 15:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-07-11 15:02 - 2013-06-11 15:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-07-11 15:02 - 2013-06-11 15:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-07-11 15:02 - 2013-06-11 15:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-07-11 15:02 - 2013-06-11 14:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-11 15:02 - 2013-06-11 14:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-07-11 15:02 - 2013-06-06 19:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-07-11 15:02 - 2013-06-06 18:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 09:43 - 2013-06-03 22:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\System32\qedit.dll
2013-07-11 09:43 - 2013-06-03 20:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 09:43 - 2013-05-05 22:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL
2013-07-11 09:43 - 2013-05-05 20:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-11 09:39 - 2013-06-04 19:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2013-07-11 09:35 - 2013-04-09 15:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 09:35 - 2013-04-02 14:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll
2013-07-06 03:20 - 2013-07-06 03:20 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Opera Software
2013-07-06 03:20 - 2013-07-06 03:20 - 00000000 ____D C:\Users\Ghost\AppData\Local\Opera Software
2013-06-25 09:08 - 2013-06-30 08:39 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-24 14:25 - 2013-06-24 14:25 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\TuneUp Software

==================== One Month Modified Files and Folders =======

2013-07-23 21:27 - 2013-07-23 21:27 - 00000000 ____D C:\FRST
2013-07-23 10:17 - 2013-07-23 10:17 - 00002431 _____ C:\Users\Ghost\Desktop\RKreport[0]_S_07232013_211749.txt
2013-07-23 10:17 - 2013-07-23 10:16 - 00000000 ____D C:\Users\Ghost\Desktop\RK_Quarantine
2013-07-23 10:15 - 2012-07-20 22:40 - 00001456 _____ C:\Users\Ghost\AppData\Local\Adobe Save for Web 12.0 Prefs
2013-07-23 10:12 - 2013-01-15 12:50 - 00001006 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-23 10:12 - 2009-07-13 20:45 - 00020768 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-23 10:12 - 2009-07-13 20:45 - 00020768 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-23 10:10 - 2013-07-23 10:10 - 00015787 _____ C:\Users\Ghost\Desktop\MBRCheck_07.23.13_21.10.26.txt
2013-07-23 10:05 - 2010-12-30 02:40 - 00000224 _____ C:\Windows\Tasks\AutoRearm.job
2013-07-23 10:04 - 2013-07-18 10:52 - 00000896 _____ C:\Windows\setupact.log
2013-07-23 10:04 - 2013-06-03 05:51 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2013-07-23 10:04 - 2013-01-15 12:50 - 00001002 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-23 10:04 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-07-22 23:54 - 2013-07-22 23:42 - 00000000 ____D C:\Program Files\AVAST Software
2013-07-22 23:32 - 2013-07-22 23:31 - 00178352 _____ C:\Users\Ghost\Desktop\avgremover.log
2013-07-22 13:31 - 2013-07-18 13:26 - 00109962 _____ C:\Users\Ghost\Desktop\Extras.Txt
2013-07-22 13:31 - 2013-07-18 13:25 - 00113064 _____ C:\Users\Ghost\Desktop\OTL.Txt
2013-07-22 13:12 - 2013-07-18 12:18 - 00005556 _____ C:\Windows\PFRO.log
2013-07-22 13:11 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2013-07-22 13:10 - 2013-07-22 13:10 - 00018917 _____ C:\AdwCleaner[S1].txt
2013-07-22 07:35 - 2013-07-22 07:35 - 00000914 _____ C:\Users\Ghost\Desktop\Malwarebytes Anti-Malware.lnk
2013-07-22 07:35 - 2013-07-22 07:35 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-07-22 01:44 - 2013-07-22 01:44 - 00003804 _____ C:\Users\Ghost\Desktop\FSS.txt
2013-07-22 01:18 - 2013-07-22 01:18 - 00000000 ____D C:\Users\Public\Desktop\CC Support
2013-07-22 01:18 - 2013-07-22 01:18 - 00000000 ____D C:\CC Support
2013-07-22 01:18 - 2013-07-22 01:16 - 00000083 _____ C:\Users\Ghost\Desktop\SFC.txt
2013-07-22 01:10 - 2013-07-22 01:10 - 00666633 _____ C:\Users\Ghost\Desktop\adwcleaner.exe
2013-07-22 01:08 - 2013-07-22 01:08 - 00171135 _____ C:\Users\Ghost\Desktop\3001-8022_4-10804572.html
2013-07-22 00:55 - 2013-07-22 00:55 - 00001631 _____ C:\Users\Ghost\Desktop\aswMBR.txt
2013-07-22 00:55 - 2013-07-22 00:55 - 00000512 _____ C:\Users\Ghost\Desktop\MBR.dat
2013-07-21 17:55 - 2013-07-18 12:41 - 00000000 ___SD C:\ComboFix
2013-07-21 17:55 - 2013-07-18 11:29 - 00000000 ____D C:\Windows\erdnt
2013-07-21 17:55 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\registration
2013-07-21 17:54 - 2009-07-13 19:20 - 00000000 __RHD C:\users\Default
2013-07-21 06:56 - 2010-05-31 07:09 - 00000000 ____D C:\users\Ghost
2013-07-18 13:35 - 2013-07-18 13:35 - 00222290 _____ C:\Users\Ghost\Desktop\AVGInstLog.cab
2013-07-18 13:08 - 2013-07-22 01:05 - 00026896 _____ C:\Users\Ghost\Desktop\ComboFix.txt
2013-07-18 13:08 - 2013-07-18 13:08 - 00026896 _____ C:\ComboFix.txt
2013-07-18 13:08 - 2013-07-18 12:51 - 00000000 ____D C:\Qoobox
2013-07-18 12:27 - 2013-07-18 12:27 - 00001137 _____ C:\Users\Ghost\Desktop\asd.exe - Shortcut.lnk
2013-07-18 12:27 - 2013-03-08 17:58 - 00000000 ____D C:\Users\Ghost\Desktop\NOIR. - Side A- Dirty
2013-07-18 12:18 - 2010-05-31 08:57 - 00000000 ____D C:\Program Files (x86)\AVG
2013-07-18 12:17 - 2013-07-18 12:01 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Spybot - Search & Destroy
2013-07-18 12:17 - 2010-06-02 09:15 - 00000000 ____D C:\ProgramData\BOINC
2013-07-18 12:03 - 2013-07-18 12:03 - 00000000 ____D C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2013-07-18 12:03 - 2013-07-18 12:03 - 00000000 ____D C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2013-07-18 12:01 - 2013-07-18 09:41 - 00000000 ____D C:\Users\Ghost\Desktop\SUPERSetup
2013-07-18 11:44 - 2009-07-13 18:34 - 00000215 _____ C:\Windows\system.ini
2013-07-18 11:25 - 2013-07-18 11:25 - 00000000 _____ C:\Windows\WindowsUpdate.log
2013-07-18 10:52 - 2013-07-18 10:52 - 00000000 _____ C:\Windows\setuperr.log
2013-07-18 10:37 - 2013-07-18 10:37 - 00064178 _____ C:\Users\Ghost\Documents\cc_20130718_213659.reg
2013-07-18 10:35 - 2010-05-31 08:23 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Winamp
2013-07-18 10:34 - 2011-02-03 11:43 - 00000000 ____D C:\Users\Ghost\AppData\Local\LogMeIn Hamachi
2013-07-18 10:34 - 2010-08-04 09:23 - 00000000 ____D C:\Windows\Minidump
2013-07-18 10:34 - 2010-07-22 10:28 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Media Player Classic
2013-07-18 10:34 - 2010-06-03 10:15 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\uTorrent
2013-07-18 10:34 - 2010-05-31 18:02 - 00000000 ____D C:\Windows\Panther
2013-07-18 09:47 - 2013-07-18 09:45 - 00000000 ____D C:\Windows\System32\MRT
2013-07-18 09:30 - 2013-07-18 09:30 - 00000000 ____D C:\Malwarebytes
2013-07-18 09:21 - 2013-07-18 09:41 - 26611408 _____ (SUPERAntiSpyware.com) C:\Users\Ghost\Desktop\SUPERAntiSpyware.exe
2013-07-18 09:03 - 2013-07-18 09:02 - 17737608 _____ (Adobe Systems Incorporated) C:\Users\Ghost\Desktop\install_flash_player.exe
2013-07-17 14:36 - 2010-05-31 09:27 - 00000000 ____D C:\Users\Ghost\AppData\Local\Last.fm
2013-07-17 12:56 - 2010-10-31 04:55 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\vlc
2013-07-17 12:19 - 2010-06-03 09:16 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Mp3tag
2013-07-17 12:00 - 2013-07-17 11:27 - 101083484 _____ C:\Users\Ghost\Desktop\DHBTPO.rar
2013-07-17 11:42 - 2013-07-17 11:25 - 48537823 _____ C:\Users\Ghost\Desktop\LJD.rar
2013-07-17 11:31 - 2013-07-17 11:28 - 67966879 _____ C:\Users\Ghost\Desktop\NTBD.rar
2013-07-17 10:59 - 2013-07-17 10:58 - 02297856 _____ C:\Users\Ghost\Desktop\Baby_shower.indd
2013-07-17 09:25 - 2010-09-16 12:07 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Dropbox
2013-07-15 23:07 - 2013-01-15 12:50 - 00004002 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-15 23:07 - 2013-01-15 12:50 - 00003750 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-15 23:00 - 2009-07-13 20:45 - 05199576 _____ C:\Windows\System32\FNTCACHE.DAT
2013-07-15 22:58 - 2013-03-13 22:33 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-15 22:58 - 2013-03-13 22:33 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-15 22:58 - 2009-07-13 23:46 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-15 22:58 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-15 22:58 - 2009-07-13 21:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-13 04:55 - 2013-07-22 01:44 - 00357077 _____ (Farbar) C:\Users\Ghost\Desktop\FSS.exe
2013-07-11 15:11 - 2010-09-09 13:09 - 00479386 _____ C:\Windows\System32\perfh00B.dat
2013-07-11 15:11 - 2010-09-09 13:09 - 00100162 _____ C:\Windows\System32\perfc00B.dat
2013-07-11 15:11 - 2009-07-13 21:13 - 01367650 _____ C:\Windows\System32\PerfStringBackup.INI
2013-07-11 15:01 - 2010-09-03 23:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-11 12:00 - 2010-06-02 06:54 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Spotify
2013-07-11 11:03 - 2010-06-02 06:54 - 00000000 ____D C:\Users\Ghost\AppData\Local\Spotify
2013-07-06 03:20 - 2013-07-06 03:20 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Opera Software
2013-07-06 03:20 - 2013-07-06 03:20 - 00000000 ____D C:\Users\Ghost\AppData\Local\Opera Software
2013-07-06 03:20 - 2010-08-02 08:05 - 00000000 ____D C:\Program Files (x86)\Opera
2013-07-01 23:27 - 2010-11-18 10:32 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\Skype
2013-07-01 09:58 - 2013-05-21 02:54 - 00003716 _____ C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
2013-07-01 09:58 - 2012-07-24 01:44 - 00045856 _____ (AVG Technologies) C:\Windows\System32\Drivers\avgtpx64.sys
2013-07-01 09:58 - 2011-12-06 03:58 - 00000000 ____D C:\ProgramData\AVG Secure Search
2013-07-01 06:33 - 2012-08-05 02:53 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-06-30 08:39 - 2013-06-25 09:08 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-24 14:25 - 2013-06-24 14:25 - 00000000 ____D C:\Users\Ghost\AppData\Roaming\TuneUp Software
2013-06-23 13:57 - 2010-05-31 08:18 - 78277128 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe

==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points =========================

Restore point made on: 2013-07-18 12:41:45
Restore point made on: 2013-07-22 07:38:41

==================== Memory info ===========================

Percentage of memory in use: 15%
Total physical RAM: 4095.49 MB
Available physical RAM: 3468.52 MB
Total Pagefile: 4093.64 MB
Available Pagefile: 3464.54 MB
Total Virtual: 8192 MB
Available Virtual: 8191.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:151.46 GB) (Free:12.86 GB) NTFS (Disk=0 Partition=2) ==>[Drive with boot components (obtained from BCD)]
Drive d: (Barra Cuda) (Fixed) (Total:465.76 GB) (Free:12.9 GB) NTFS (Disk=1 Partition=1)
Drive e: (main) (Fixed) (Total:322.26 GB) (Free:13.94 GB) NTFS (Disk=0 Partition=1)
Drive f: (musiikki) (Fixed) (Total:122.44 GB) (Free:4.31 GB) NTFS (Disk=0 Partition=3)
Drive i: (PENDRIVE) (Removable) (Total:0.93 GB) (Free:0.93 GB) FAT32 (Disk=2 Partition=1)
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: C4F98237)
Partition 1: (Not Active) - (Size=322 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=151 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=122 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: E56CE56C)
Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (Size: 955 MB) (Disk ID: 0113CF16)
Partition 1: (Not Active) - (Size=955 MB) - (Type=0C)


LastRegBack: 2013-07-18 08:51

==================== End Of Log ============================

Attached Thumbnails

  • screen.jpg

  • 0

#13
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
This line looks interesting:

HKLM-x32\...\Winlogon: [Shell] [x ] () <=== ATTENTION
Shell should normally say: Explorer.exe

Copy the next 2 lines:

reg query "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon" /s > %userprofile%\desktop\junk.txt
notepad %userprofile%\desktop\junk.txt


Start, All Programs, Accessories, right click on Command Prompt and Run as Administrator, Continue. Right click and Paste or Edit then Paste and the copied lines should appear.
Notepad should open. (If not hit Enter.) Copy and paste the text from notepad. (Close the Command Window)
  • 0

#14
klmk

klmk

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
ReportBootOk REG_SZ 1
Shell REG_SZ Explorer.exe
PreCreateKnownFolders REG_SZ {A520A1A4-1780-4FF6-BD18-167343C5AF16}
VMApplet REG_SZ SystemPropertiesPerformance.exe /pagefile
AutoRestartShell REG_DWORD 0x1
Background REG_SZ 0 0 0
CachedLogonsCount REG_SZ 10
DebugServerCommand REG_SZ no
ForceUnlockLogon REG_DWORD 0x0
LegalNoticeCaption REG_SZ
LegalNoticeText REG_SZ
PasswordExpiryWarning REG_DWORD 0x5
PowerdownAfterShutdown REG_SZ 0
ShutdownWithoutLogon REG_SZ 0
WinStationsDisabled REG_SZ 0
DisableCAD REG_DWORD 0x1
scremoveoption REG_SZ 0
ShutdownFlags REG_DWORD 0x2b
allocatecdroms REG_SZ 0
Userinit REG_SZ C:\Windows\system32\userinit.exe,
LegalNotice Text REG_SZ
SFCDisable REG_DWORD 0x0
System REG_SZ

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}
(Default) REG_SZ Wireless Group Policy
DisplayName REG_EXPAND_SZ @wlgpclnt.dll,-100
ProcessGroupPolicyEx REG_SZ ProcessWLANPolicyEx
GenerateGroupPolicy REG_SZ GenerateWLANPolicy
DllName REG_EXPAND_SZ wlgpclnt.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{0E28E245-9368-4853-AD84-6DA3BA35BB75}
(Default) REG_SZ Group Policy Environment
ProcessGroupPolicy REG_SZ ProcessGroupPolicyEnviron
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyEnviron
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExEnviron
EventSources REG_SZ (Group Policy Environment,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-1
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{17D89FEC-5C44-4972-B12D-241CAEF74509}
(Default) REG_SZ Group Policy Local Users and Groups
ProcessGroupPolicy REG_SZ ProcessGroupPolicyLocUsAndGroups
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyLocUsAndGroups
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExLocUsAndGroups
EventSources REG_SZ (Group Policy Local Users and Groups,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-2
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{1A6364EB-776B-4120-ADE1-B63A406A76B5}
(Default) REG_SZ Group Policy Device Settings
ProcessGroupPolicy REG_SZ ProcessGroupPolicyDevices
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyDevices
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExDevices
EventSources REG_SZ (Group Policy Device Settings,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-3
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{25537BA6-77A8-11D2-9B6C-0000F8080861}
(Default) REG_SZ Folder Redirection
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
DllName REG_EXPAND_SZ fdeploy.dll
NoMachinePolicy REG_DWORD 0x1
NoSlowLink REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x0
NoBackgroundPolicy REG_DWORD 0x0
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
EventSources REG_MULTI_SZ (Folder Redirection,Application)
DisplayName REG_EXPAND_SZ @fdeploy.dll,-261

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{35378EAC-683F-11D2-A89A-00C04FBBCFA2}

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
(Default) REG_SZ Microsoft Disk Quota
DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\dskquota.dll,-100
NoMachinePolicy REG_DWORD 0x0
NoUserPolicy REG_DWORD 0x1
NoSlowLink REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
PerUserLocalSettings REG_DWORD 0x0
RequiresSuccessfulRegistry REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x0
DllName REG_EXPAND_SZ %SystemRoot%\System32\dskquota.dll
ProcessGroupPolicy REG_SZ ProcessGroupPolicy

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{3A0DBA37-F8B2-4356-83DE-3E90BD5C261F}
(Default) REG_SZ Group Policy Network Options
ProcessGroupPolicy REG_SZ ProcessGroupPolicyNetworkOptions
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyNetworkOptions
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExNetworkOptions
EventSources REG_SZ (Group Policy Network Options,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-4
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{426031c0-0b47-4852-b0ca-ac3d37bfcb39}
(Default) REG_SZ QoS Packet Scheduler
DisplayName REG_EXPAND_SZ @gptext.dll,-201
ProcessGroupPolicy REG_SZ ProcessPSCHEDPolicy
DllName REG_EXPAND_SZ gptext.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{42B5FAAE-6536-11d2-AE5A-0000F87571E3}
(Default) REG_SZ Scripts
ProcessGroupPolicy REG_SZ ProcessScriptsGroupPolicy
DllName REG_EXPAND_SZ gpscript.dll
GenerateGroupPolicy REG_SZ GenerateScriptsGroupPolicy
NoSlowLink REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ ProcessScriptsGroupPolicyEx
NoGPOListChanges REG_DWORD 0x1
NotifyLinkTransition REG_DWORD 0x1
DisplayName REG_EXPAND_SZ @gpscript.dll,-1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4bcd6cde-777b-48b6-9804-43568e23545d}
(Default) REG_SZ Remote Desktop USB Redirection
DllName REG_EXPAND_SZ %SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll
RequiresSuccessfulRegistry REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
NoGPOListChanges REG_DWORD 0x1
NoUserPolicy REG_DWORD 0x1
DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\TsUsbRedirectionGroupPolicyExtension.dll,-100
NoBackgroundPolicy REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
(Default) REG_SZ Internet Explorer Zonemapping
ProcessGroupPolicy REG_SZ ProcessGroupPolicyForZoneMap
DllName REG_SZ C:\Windows\System32\iedkcs32.dll
RequiresSuccessfulRegistry REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{5794DAFD-BE60-433f-88A2-1A31939AC01F}
(Default) REG_SZ Group Policy Drive Maps
ProcessGroupPolicy REG_SZ ProcessGroupPolicyDrives
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyDrives
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExDrives
EventSources REG_SZ (Group Policy Drive Maps,Application)
NoMachinePolicy REG_DWORD 0x1
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-5
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6232C319-91AC-4931-9385-E70C2B099F0E}
(Default) REG_SZ Group Policy Folders
ProcessGroupPolicy REG_SZ ProcessGroupPolicyFolders
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyFolders
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExFolders
EventSources REG_SZ (Group Policy Folders,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-6
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6A4C88C6-C502-4f74-8F60-2CB23EDC24E2}
(Default) REG_SZ Group Policy Network Shares
ProcessGroupPolicy REG_SZ ProcessGroupPolicyNetShares
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyNetShares
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExNetShares
EventSources REG_SZ (Group Policy Network Shares,Application)
NoUserPolicy REG_DWORD 0x1
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-7
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{6cfb9c5c-138e-4bb3-8a3d-d5383e910e57}
(Default) REG_SZ Remote Desktop Protocol Extension
DllName REG_EXPAND_SZ %SystemRoot%\System32\RdpGroupPolicyExtension.dll
RequiresSuccessfulRegistry REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
NoGPOListChanges REG_DWORD 0x1
NoUserPolicy REG_DWORD 0x1
DisplayName REG_EXPAND_SZ @%SystemRoot%\System32\RdpGroupPolicyExtension.dll,-100
NoBackgroundPolicy REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7150F9BF-48AD-4da4-A49C-29EF4A8369BA}
(Default) REG_SZ Group Policy Files
ProcessGroupPolicy REG_SZ ProcessGroupPolicyFiles
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyFiles
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExFiles
EventSources REG_SZ (Group Policy Files,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-8
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{728EE579-943C-4519-9EF7-AB56765798ED}
(Default) REG_SZ Group Policy Data Sources
ProcessGroupPolicy REG_SZ ProcessGroupPolicyDataSources
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyDataSources
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExDataSources
EventSources REG_SZ (Group Policy Data Sources,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-9
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{74EE6C03-5363-4554-B161-627540339CAB}
(Default) REG_SZ Group Policy Ini Files
ProcessGroupPolicy REG_SZ ProcessGroupPolicyIniFile
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyIniFile
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExIniFile
EventSources REG_SZ (Group Policy Ini Files,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-10
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7933F41E-56F8-41d6-A31C-4148A711EE93}
(Default) REG_SZ Windows Search Group Policy Extension
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
DllName REG_EXPAND_SZ %SystemRoot%\System32\srchadmin.dll
RequiresSuccessfulRegistry REG_DWORD 0x1
NoSlowLink REG_DWORD 0x0
NoGPOListChanges REG_DWORD 0x1
NoUserPolicy REG_DWORD 0x0
NoMachinePolicy REG_DWORD 0x0
PerUserLocalSettings REG_DWORD 0x0
EnableAsynchronousProcessing REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{7B849a69-220F-451E-B3FE-2CB811AF94AE}
(Default) REG_SZ Internet Explorer User Accelerators
ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities
DllName REG_SZ C:\Windows\System32\iedkcs32.dll
RequiresSuccessfulRegistry REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx
NoGPOListChanges REG_DWORD 0x1
DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
(Default) REG_SZ Security
DisplayName REG_EXPAND_SZ @(runtime.system32)\scecli.dll,-7650
ProcessGroupPolicy REG_SZ SceProcessSecurityPolicyGPO
GenerateGroupPolicy REG_SZ SceGenerateGroupPolicy
ExtensionRsopPlanningDebugLevel REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ SceProcessSecurityPolicyGPOEx
ExtensionDebugLevel REG_DWORD 0x1
DllName REG_EXPAND_SZ scecli.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1
MaxNoGPOListChangesInterval REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{8A28E2C5-8D06-49A4-A08C-632DAA493E17}
(Default) REG_SZ Deployed Printer Connections
DisplayName REG_EXPAND_SZ @%systemroot%\system32\gpprnext.dll,-1
DllName REG_EXPAND_SZ %systemroot%\system32\gpprnext.dll
EnableAsynchronousProcessing REG_DWORD 0x1
ExtensionEventSource REG_SZ
GenerateGroupPolicy REG_SZ PrinterGenerateGroupPolicy
MaxNoGPOListChangesInterval REG_DWORD 0x0
NoBackgroundPolicy REG_DWORD 0x0
NoGPOListChanges REG_DWORD 0x0
NoMachinePolicy REG_DWORD 0x0
NoSlowLink REG_DWORD 0x1
NotifyLinkTransition REG_DWORD 0x0
NoUserPolicy REG_DWORD 0x0
PerUserLocalSettings REG_DWORD 0x0
ProcessGroupPolicy REG_SZ PrinterProcessGroupPolicy
ProcessGroupPolicyEx REG_SZ PrinterProcessGroupPolicyEx
RequiresSuccessfulRegistry REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{91FBB303-0CD5-4055-BF42-E512A681B325}
(Default) REG_SZ Group Policy Services
ProcessGroupPolicy REG_SZ ProcessGroupPolicyServices
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyServices
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExServices
EventSources REG_SZ (Group Policy Services,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-11
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
(Default) REG_SZ Internet Explorer Branding
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
DllName REG_SZ C:\Windows\System32\iedkcs32.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
NoSlowLink REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
NoGPOListChanges REG_DWORD 0x1
NoMachinePolicy REG_DWORD 0x1
DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3014
NoBackgroundPolicy REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{A3F3E39B-5D83-4940-B954-28315B82F0A8}
(Default) REG_SZ Group Policy Folder Options
ProcessGroupPolicy REG_SZ ProcessGroupPolicyFolderOptions
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyFolderOptions
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExFolderOptions
EventSources REG_SZ (Group Policy Folder Options,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-12
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{AADCED64-746C-4633-A97C-D61349046527}
(Default) REG_SZ Group Policy Scheduled Tasks
ProcessGroupPolicy REG_SZ ProcessGroupPolicySchedTasks
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicySchedTasks
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExSchedTasks
EventSources REG_SZ (Group Policy Scheduled Tasks,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-13
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B087BE9D-ED37-454f-AF9C-04291E351182}
(Default) REG_SZ Group Policy Registry
ProcessGroupPolicy REG_SZ ProcessGroupPolicyRegistry
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyRegistry
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExRegistry
EventSources REG_SZ (Group Policy Registry,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-14
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
(Default) REG_SZ 802.3 Group Policy
DisplayName REG_EXPAND_SZ @dot3gpclnt.dll,-100
ProcessGroupPolicyEx REG_SZ ProcessLANPolicyEx
GenerateGroupPolicy REG_SZ GenerateLANPolicy
DllName REG_EXPAND_SZ dot3gpclnt.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{BC75B1ED-5833-4858-9BB8-CBF0B166DF9D}
(Default) REG_SZ Group Policy Printers
ProcessGroupPolicy REG_SZ ProcessGroupPolicyPrinters
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyPrinters
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExPrinters
EventSources REG_SZ (Group Policy Printers,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-16
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C418DD9D-0D14-4efb-8FBF-CFE535C8FAC7}
(Default) REG_SZ Group Policy Shortcuts
ProcessGroupPolicy REG_SZ ProcessGroupPolicyShortcuts
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyShortcuts
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExShortcuts
EventSources REG_SZ (Group Policy Shortcuts,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-17
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{C631DF4C-088F-4156-B058-4375F0853CD8}
(Default) REG_SZ Microsoft Offline Files
ProcessGroupPolicy REG_SZ ProcessGroupPolicy
DllName REG_EXPAND_SZ %SystemRoot%\System32\cscobj.dll
RequiresSuccessfulRegistry REG_DWORD 0x1
NoSlowLink REG_DWORD 0x0
NoGPOListChanges REG_DWORD 0x0
NoUserPolicy REG_DWORD 0x0
NoMachinePolicy REG_DWORD 0x0
PerUserLocalSettings REG_DWORD 0x0
EnableAsynchronousProcessing REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{c6dc5466-785a-11d2-84d0-00c04fb169f7}
(Default) REG_SZ Software Installation
RequiresSucessfulRegistry REG_DWORD 0x0
DllName REG_EXPAND_SZ appmgmts.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
NoSlowLink REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyObjectsEx
EventSources REG_MULTI_SZ (Application Management,Application)\0(MsiInstaller,Application)
NoUserPolicy REG_DWORD 0x0
DisplayName REG_EXPAND_SZ @appmgmts.dll,-3252
PerUserLocalSettings REG_DWORD 0x1
NoBackgroundPolicy REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{cdeafc3d-948d-49dd-ab12-e578ba4af7aa}
(Default) REG_SZ TCPIP
DisplayName REG_EXPAND_SZ @gptext.dll,-204
ProcessGroupPolicy REG_SZ ProcessTCPIPPolicy
DllName REG_EXPAND_SZ gptext.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
RequiresSuccessfulRegistry REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{CF7639F3-ABA2-41DB-97F2-81E2C5DBFC5D}
(Default) REG_SZ Internet Explorer Machine Accelerators
ProcessGroupPolicy REG_SZ ProcessGroupPolicyForActivities
DllName REG_SZ C:\Windows\System32\iedkcs32.dll
RequiresSuccessfulRegistry REG_DWORD 0x1
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyForActivitiesEx
NoGPOListChanges REG_DWORD 0x1
DisplayName REG_SZ @C:\Windows\System32\iedkcs32.dll,-3051

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{e437bc1c-aa7d-11d2-a382-00c04f991e27}
(Default) REG_SZ IP Security
ProcessGroupPolicyEx REG_SZ ProcessIPSECPolicyEx
GenerateGroupPolicy REG_SZ GenerateIPSECPolicy
DllName REG_EXPAND_SZ %SystemRoot%\System32\polstore.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x0
DisplayName REG_EXPAND_SZ @C:\Windows\system32\polstore.dll,-5012

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E47248BA-94CC-49c4-BBB5-9EB7F05183D0}
(Default) REG_SZ Group Policy Internet Settings
ProcessGroupPolicy REG_SZ ProcessGroupPolicyInternet
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyInternet
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExInternet
EventSources REG_SZ (Group Policy Internet Settings,Application)
NoMachinePolicy REG_DWORD 0x1
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-18
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E4F48E54-F38D-4884-BFB9-D4D2E5729C18}
(Default) REG_SZ Group Policy Start Menu Settings
ProcessGroupPolicy REG_SZ ProcessGroupPolicyStartMenu
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyStartMenu
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExStartMenu
EventSources REG_SZ (Group Policy Start Menu Settings,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-19
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E5094040-C46C-4115-B030-04FB2E545B00}
(Default) REG_SZ Group Policy Regional Options
ProcessGroupPolicy REG_SZ ProcessGroupPolicyRegionOptions
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyRegionOptions
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExRegionOptions
EventSources REG_SZ (Group Policy Regional Options,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-20
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{E62688F0-25FD-4c90-BFF5-F508B9D2E31F}
(Default) REG_SZ Group Policy Power Options
ProcessGroupPolicy REG_SZ ProcessGroupPolicyPowerOptions
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyPowerOptions
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExPowerOptions
EventSources REG_SZ (Group Policy Power Options,Application)
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-21
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{f3ccc681-b74c-4060-9f26-cd84525dca2a}
(Default) REG_SZ Audit Policy Configuration
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyEx
GenerateGroupPolicy REG_SZ GenerateGroupPolicy
DllName REG_EXPAND_SZ auditcse.dll
NoUserPolicy REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1
MaxNoGPOListChangesInterval REG_DWORD 0x3c0
ForceRefreshFG REG_DWORD 0x0

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{F9C77450-3A41-477E-9310-9ACD617BD9E3}
(Default) REG_SZ Group Policy Applications
ProcessGroupPolicy REG_SZ ProcessGroupPolicyApplications
DllName REG_EXPAND_SZ gpprefcl.dll
GenerateGroupPolicy REG_SZ GenerateGroupPolicyApplications
ProcessGroupPolicyEx REG_SZ ProcessGroupPolicyExApplications
EventSources REG_SZ (Group Policy Applications,Application)
NoMachinePolicy REG_DWORD 0x1
DisplayName REG_EXPAND_SZ @gpprefcl.dll,-15
PerUserLocalSettings REG_DWORD 0x1
EnableAsynchronousProcessing REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{FB2CA36D-0B40-4307-821B-A13B252DE56C}
(Default) REG_SZ Enterprise QoS
DisplayName REG_EXPAND_SZ @gptext.dll,-203
ProcessGroupPolicy REG_SZ ProcessEQoSPolicy
DllName REG_EXPAND_SZ gptext.dll
RequiresSuccessfulRegistry REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions\{fbf687e6-f063-4d9f-9f4f-fd9a26acdd5f}
(Default) REG_SZ CP
DisplayName REG_EXPAND_SZ @gptext.dll,-205
ProcessGroupPolicy REG_SZ ProcessConnectivityPlatformPolicy
DllName REG_EXPAND_SZ gptext.dll
NoUserPolicy REG_DWORD 0x1
NoGPOListChanges REG_DWORD 0x1
RequiresSuccessfulRegistry REG_DWORD 0x1

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn
DLLName REG_SZ c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
Asynchronous REG_DWORD 0x0
Startup REG_SZ OnStartup
Logon REG_SZ OnLogon
StartShell REG_SZ OnStartShell
Logoff REG_SZ OnLogoff
Shutdown REG_SZ OnShutdown

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn\Event
Logon REG_SZ LBTWLgn_LOGON
StartShell REG_SZ LBTWLgn_STARTSHELL

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\AutoLogonChecked
  • 0

#15
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Looks normal unfortunately. Let's try to remove the driver with the odd path:

Type in regedit in the search box and when it finds regedit.exe , right click on it and Run As Admin. Then navigate to

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services

Click on the + in front of Services.
Look for Tablet2k or Tablet2k.sys

Right click on Tablet2k and Delete.

Does it let you?

Close Regedit, reboot and then go back in and see if it is still there.

Please download MiniToolBox, save it to your desktop and run it.

Checkmark the following checkboxes:
  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer Errors
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files
Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP