Hi Ron,
Thanks, I followed all the steps. Below and attached are the logs as requested.
Good news is that the effectis already apparent; no ghost data flow as per my NetSpeedMonitor.
Cheers
FRST fix log:Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-10-2013
Ran by Stefan at 2013-10-24 17:26:32 Run:1
Running from C:\Users\Stefan\Downloads
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
HKLM\...\Run: [Microsoft Windows Hosting Service] - C:\Users\Stefan\AppData\Local\Temp\csrss.exe [239616 2013-09-19] (NoVirusThanks Company Srl) <===== ATTENTION
HKLM\...\Policies\Explorer\Run: [44992] - c:\progra~2\dxrrblix.exe [357888 2009-07-14] ( ())
HKLM\...\Policies\Explorer: [3212083974] 0x504B0304C239B7F8068374BFB511000000400000E269F63D73594F6202C9694280CC96A28BBD63516FE3C2D5F7A2FF87AC
HKCU\...\Run: [Google Update*] - [x] <===== ATTENTION (ZeroAccess rootkit hidden path)
HKCU\...\Run: [Microsoft Windows Hosting Service] - C:\Users\Stefan\AppData\Local\Temp\csrss.exe [239616 2013-09-19] (NoVirusThanks Company Srl) <===== ATTENTION
HKCU\...\CurrentVersion\Windows: [Load] c:\users\stefan\dxmwpq.exe <===== ATTENTION
S2 DefaultTabSearch; C:\Program Files\DefaultTab\DefaultTabSearch.exe [573952 2013-09-16] ()
R2 DefaultTabUpdate; C:\Users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe [107520 2013-08-23] ()
S3 rpcapd; "%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini" [x]
U2 *etadpug; "C:\Program Files\Google\Desktop\Install\{2e754a38-a09f-89b0-736a-408075ef620d}\ \...\???\{2e754a38-a09f-89b0-736a-408075ef620d}\GoogleUpdate.exe" < <==== ATTENTION (ZeroAccess)
S3 iBurstu; system32\DRIVERS\iBurstu.sys [x]
C:\Windows\assembly\GAC\Desktop.ini
C:\Users\Stefan\AppData\Local\Temp\csrss.exe
C:\Users\Stefan\AppData\Local\Google\Desktop\Install
C:\Program Files\Google\Desktop\Install
C:\ProgramData\dxrrblix.exe
C:\Users\Stefan\dxakokxu.exe
C:\Users\Stefan\dxavzr.exe
C:\Users\Stefan\dxbesgdoq.exe
C:\Users\Stefan\dxcadh.exe
C:\Users\Stefan\dxcbaathv.exe
C:\Users\Stefan\dxddoi.exe
C:\Users\Stefan\dxdjbu.exe
C:\Users\Stefan\dxehlohv.exe
C:\Users\Stefan\dxgcftur.exe
C:\Users\Stefan\dxhuamnw.exe
C:\Users\Stefan\dxhvrn.exe
C:\Users\Stefan\dxiewkke.exe
C:\Users\Stefan\dxifgxuu.exe
C:\Users\Stefan\dxiynj.exe
C:\Users\Stefan\dxizkvbep.exe
C:\Users\Stefan\dxkdufa.exe
C:\Users\Stefan\dxlabpuqo.exe
C:\Users\Stefan\dxlmhx.exe
C:\Users\Stefan\dxmwpq.exe
C:\Users\Stefan\dxojim.exe
C:\Users\Stefan\dxoyiv.exe
C:\Users\Stefan\dxqafz.exe
C:\Users\Stefan\dxriojni.exe
C:\Users\Stefan\dxrjiy.exe
C:\Users\Stefan\dxsezfjt.exe
C:\Users\Stefan\dxtjrk.exe
C:\Users\Stefan\dxtseu.exe
C:\Users\Stefan\dxudeh.exe
C:\Users\Stefan\dxvyvlii.exe
C:\Users\Stefan\dxxikia.exe
C:\Users\Stefan\dxxtwdeuo.exe
C:\Users\Stefan\dxyrsiu.exe
C:\Users\Stefan\dxzkhbwa.exe
C:\Users\Stefan\AppData\Local\Temp\1345545343.exe
C:\Users\Stefan\AppData\Local\Temp\1345550028.exe
C:\Users\Stefan\AppData\Local\Temp\1347056850.exe
C:\Users\Stefan\AppData\Local\Temp\1348369731.exe
C:\Users\Stefan\AppData\Local\Temp\1348385342.exe
C:\Users\Stefan\AppData\Local\Temp\1348385637.exe
C:\Users\Stefan\AppData\Local\Temp\1364500553.exe
C:\Users\Stefan\AppData\Local\Temp\1364503380.exe
C:\Users\Stefan\AppData\Local\Temp\1373093828.exe
C:\Users\Stefan\AppData\Local\Temp\1373099186.exe
C:\Users\Stefan\AppData\Local\Temp\1373307441.exe
C:\Users\Stefan\AppData\Local\Temp\1390877027.exe
C:\Users\Stefan\AppData\Local\Temp\1423717569.exe
C:\Users\Stefan\AppData\Local\Temp\77Zip973867.exe
C:\Users\Stefan\AppData\Local\Temp\AutoRun.exe
C:\Users\Stefan\AppData\Local\Temp\AutoRunGUI.dll
C:\Users\Stefan\AppData\Local\Temp\BackupSetup.exe
C:\Users\Stefan\AppData\Local\Temp\CmdLineExt03.dll
C:\Users\Stefan\AppData\Local\Temp\csrss.exe
C:\Users\Stefan\AppData\Local\Temp\drm_dyndata_7400009.dll
C:\Users\Stefan\AppData\Local\Temp\EBU1489.EXE
C:\Users\Stefan\AppData\Local\Temp\EBU14F6.DLL
C:\Users\Stefan\AppData\Local\Temp\EBU34D5.EXE
C:\Users\Stefan\AppData\Local\Temp\EBU35EE.DLL
C:\Users\Stefan\AppData\Local\Temp\EBU7B27.EXE
C:\Users\Stefan\AppData\Local\Temp\EBU7BA4.DLL
C:\Users\Stefan\AppData\Local\Temp\mgsqlite3.dll
C:\Users\Stefan\AppData\Local\Temp\msdt.exe
C:\Users\Stefan\AppData\Local\Temp\ootp13setup.exe
C:\Users\Stefan\AppData\Local\Temp\ose00000.exe
C:\Users\Stefan\AppData\Local\Temp\SIntf16.dll
C:\Users\Stefan\AppData\Local\Temp\SIntf32.dll
C:\Users\Stefan\AppData\Local\Temp\SIntfNT.dll
C:\Users\Stefan\AppData\Local\Temp\SweetIMSetup.exe
C:\Users\Stefan\AppData\Local\Temp\ubiC524.tmp.exe
C:\Users\Stefan\AppData\Local\Temp\uninstaller.exe
C:\Users\Stefan\AppData\Local\Temp\utt5FE5.tmp.exe
C:\Users\Stefan\AppData\Local\Temp\WAKUNX.exe
C:\Users\Stefan\AppData\Local\Temp\_isFD26.exe
DeleteJunctionsIndirectory: C:\Program Files\Windows Defender
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 02 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
CMD: netsh winsock reset
*****************
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Microsoft Windows Hosting Service => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\\44992 => Value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\3212083974 => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Google Update* => Value deleted successfully.
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\Microsoft Windows Hosting Service => Value not found.
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\\Load => Value was restored successfully.
DefaultTabSearch => Service deleted successfully.
DefaultTabUpdate => Service deleted successfully.
rpcapd => Service deleted successfully.
*etadpug => Service deleted successfully.
iBurstu => Service deleted successfully.
C:\Windows\assembly\GAC\Desktop.ini => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\csrss.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Google\Desktop\Install => Moved successfully.
"C:\Program Files\Google\Desktop\Install" directory move:
Could not move "C:\Program Files\Google\Desktop\Install" directory. => Scheduled to move on reboot.
C:\ProgramData\dxrrblix.exe => Moved successfully.
C:\Users\Stefan\dxakokxu.exe => Moved successfully.
C:\Users\Stefan\dxavzr.exe => Moved successfully.
C:\Users\Stefan\dxbesgdoq.exe => Moved successfully.
C:\Users\Stefan\dxcadh.exe => Moved successfully.
C:\Users\Stefan\dxcbaathv.exe => Moved successfully.
C:\Users\Stefan\dxddoi.exe => Moved successfully.
C:\Users\Stefan\dxdjbu.exe => Moved successfully.
C:\Users\Stefan\dxehlohv.exe => Moved successfully.
C:\Users\Stefan\dxgcftur.exe => Moved successfully.
C:\Users\Stefan\dxhuamnw.exe => Moved successfully.
C:\Users\Stefan\dxhvrn.exe => Moved successfully.
C:\Users\Stefan\dxiewkke.exe => Moved successfully.
C:\Users\Stefan\dxifgxuu.exe => Moved successfully.
C:\Users\Stefan\dxiynj.exe => Moved successfully.
C:\Users\Stefan\dxizkvbep.exe => Moved successfully.
C:\Users\Stefan\dxkdufa.exe => Moved successfully.
C:\Users\Stefan\dxlabpuqo.exe => Moved successfully.
C:\Users\Stefan\dxlmhx.exe => Moved successfully.
C:\Users\Stefan\dxmwpq.exe => Moved successfully.
C:\Users\Stefan\dxojim.exe => Moved successfully.
C:\Users\Stefan\dxoyiv.exe => Moved successfully.
C:\Users\Stefan\dxqafz.exe => Moved successfully.
C:\Users\Stefan\dxriojni.exe => Moved successfully.
C:\Users\Stefan\dxrjiy.exe => Moved successfully.
C:\Users\Stefan\dxsezfjt.exe => Moved successfully.
C:\Users\Stefan\dxtjrk.exe => Moved successfully.
C:\Users\Stefan\dxtseu.exe => Moved successfully.
C:\Users\Stefan\dxudeh.exe => Moved successfully.
C:\Users\Stefan\dxvyvlii.exe => Moved successfully.
C:\Users\Stefan\dxxikia.exe => Moved successfully.
C:\Users\Stefan\dxxtwdeuo.exe => Moved successfully.
C:\Users\Stefan\dxyrsiu.exe => Moved successfully.
C:\Users\Stefan\dxzkhbwa.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1345545343.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1345550028.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1347056850.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1348369731.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1348385342.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1348385637.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1364500553.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1364503380.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1373093828.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1373099186.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1373307441.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1390877027.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\1423717569.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\77Zip973867.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\AutoRun.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\AutoRunGUI.dll => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\BackupSetup.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\CmdLineExt03.dll => Moved successfully.
"C:\Users\Stefan\AppData\Local\Temp\csrss.exe" => File/Directory not found.
C:\Users\Stefan\AppData\Local\Temp\drm_dyndata_7400009.dll => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\EBU1489.EXE => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\EBU14F6.DLL => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\EBU34D5.EXE => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\EBU35EE.DLL => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\EBU7B27.EXE => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\EBU7BA4.DLL => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\mgsqlite3.dll => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\msdt.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\ootp13setup.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\ose00000.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\SIntf16.dll => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\SIntf32.dll => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\SIntfNT.dll => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\SweetIMSetup.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\ubiC524.tmp.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\uninstaller.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\utt5FE5.tmp.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\WAKUNX.exe => Moved successfully.
C:\Users\Stefan\AppData\Local\Temp\_isFD26.exe => Moved successfully.
"C:\Program Files\Windows Defender" => Deleting reparse point and unlocking started.
"C:\Program Files\Windows Defender\en-US" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpAsDesc.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpClient.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpCmdRun.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpCommu.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpEvMsg.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpOAV.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpRTP.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MpSvc.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MSASCui.exe" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpCom.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpLics.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender\MsMpRes.dll" => Deleting reparse point and unlocking done.
"C:\Program Files\Windows Defender" => Deleting reparse point and unlocking completed.
Winsock: Catalog5 entry 000000000001\\LibraryPath was set successfully to %SystemRoot%\system32\NLAapi.dll
Winsock: Catalog5 entry 000000000002\\LibraryPath was set successfully to %SystemRoot%\System32\mswsock.dll
========= netsh winsock reset =========
The following helper DLL cannot be loaded: WSHELPER.DLL.
The following command was not found: winsock reset.
========= End of CMD: =========
=========== Result of Scheduled Files to move ===========
C:\Program Files\Google\Desktop\Install => Moved successfully.
==== End of Fixlog ====
FRST.txtScan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-10-2013
Ran by Stefan (administrator) on STEFAN-PC on 24-10-2013 17:28:51
Running from C:\Users\Stefan\Downloads
Microsoft Windows 7 Ultimate (X86) OS Language: English(US)
Internet Explorer Version 8
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Windows\system32\AUDIODG.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
(Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Eastman Kodak Company) C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Eastman Kodak Company) C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
(Amonetizé Ltd) C:\Users\Stefan\AppData\Local\SwvUpdater\Updater.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(DT Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [33648 2007-08-24] (Microsoft Corporation)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [Conime] - %windir%\system32\conime.exe
HKLM\...\Run: [EKAiO2StatusMonitor] - C:\Windows\system32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe [2421760 2011-03-01] (Eastman Kodak Company)
HKLM\...\Run: [MobileBroadband] - C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [408576 2011-04-19] (Vodafone)
HKLM\...\Run: [Registry Helper] - "C:\Program Files\Registry Helper\RegistryHelper.Exe" /boot
HKCU\...\Run: [DAEMON Tools Lite] - C:\Program Files\DAEMON Tools Lite\DTLite.exe [3673728 2012-11-06] (DT Soft Ltd)
HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [354304 2009-07-14] (Microsoft Corporation)
MountPoints2: I - I:\autorun.exe
MountPoints2: {031d204d-7e61-11e2-85f8-02c0ee6543d1} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {031d210d-7e61-11e2-85f8-02c0ee6543d1} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {031d2165-7e61-11e2-85f8-02c0ee6543d1} - I:\autorun.exe
MountPoints2: {16f87916-03ea-11e3-abb3-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {16fba005-1aa2-11e3-a79d-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {3a9f90e5-86e5-11e2-b64c-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {65538eaf-8c71-11e2-a1e4-02c0ee6562cf} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {65538eb4-8c71-11e2-a1e4-02c0ee6562cf} - F:\setup_vmc_lite.exe /checkApplicationPresence
MountPoints2: {7127b1f2-1af4-11e3-ac9b-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {7127b204-1af4-11e3-ac9b-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {8f396b0a-ebb6-11e2-a859-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {ca4bcc16-1c3b-11e3-9400-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {f06774a7-b30b-11e2-8f64-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
MountPoints2: {f70ec47d-b898-11e2-a843-002618c91d6b} - F:\setup_vmb_lite.exe /checkApplicationPresence
AppInit_DLLs: [ ] ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://start.search....F6214E}&serpv=5HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://websearch.you...938&lg=EN&cc=ZASearchScopes: HKLM - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL =
http://websearch.you...938&lg=EN&cc=ZASearchScopes: HKCU - {5C49C060-6DEE-4BE9-8C91-B03DBFF55B81} URL =
http://search.us.com...k={searchTerms}SearchScopes: HKCU - {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL =
http://websearch.you...938&lg=EN&cc=ZASearchScopes: HKCU - {D735BCC8-CE8F-4074-A6F9-39F6424517E8} URL =
http://search.yahoo....petb&type=10547BHO: ElectroLyrics-1 - {11111111-1111-1111-1111-110411181144} - C:\Program Files\ElectroLyrics-1\ElectroLyrics-1-bho.dll (Lyrics)
BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: DefaultTab Browser Helper - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll (Search Results LLC.)
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
https://fpdownload.m...ash/swflash.cabHandler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Winsock: Catalog9 01 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 02 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 03 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 04 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 05 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 06 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 07 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 08 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 09 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 10 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 11 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 12 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 13 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 14 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 15 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 16 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 17 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 18 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 19 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 20 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 21 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 22 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 23 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 24 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 25 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 26 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 27 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 28 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 29 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 30 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 31 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 32 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 33 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 34 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 35 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 36 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 37 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 38 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 39 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 40 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 41 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 42 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 43 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 44 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 45 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 46 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 47 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 48 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 49 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 50 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 51 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 52 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 53 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 54 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 55 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 56 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 57 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 58 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 59 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 60 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 61 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 62 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 63 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 64 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 65 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 66 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 67 mswsock.dll File Not found (Microsoft Corporation)
Winsock: Catalog9 68 mswsock.dll File Not found (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{131B5047-1B2C-449F-9AAC-DC252D82C1E1}: [NameServer]196.207.36.251 196.207.36.254
Tcpip\..\Interfaces\{17F7B7DA-3406-4F8D-9541-EA905EED8D4A}: [NameServer]196.207.36.251 196.207.36.254
Tcpip\..\Interfaces\{C775872A-FCC3-42EA-AAFA-AD8B5396A367}: [NameServer]196.207.36.251 196.207.36.254
Tcpip\..\Interfaces\{CB318F49-15F3-407F-9EBE-BBA23BBCC213}: [NameServer]196.207.36.251 196.207.36.254
FireFox:
========
FF ProfilePath: C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default
FF Homepage: hxxp://start.search.us.com/v/2/?guid={5CD6CB79-8ADD-4852-82CF-00ED47F6214E}&serpv=5
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tightropeinteractive.com/Plugin - C:\Users\Stefan\AppData\Local\TNT2\2.0.0.1599\npTNT2.dll (Search.Us.com)
FF Plugin HKCU: @tnt2ghost.com/Plugin - C:\Users\Stefan\AppData\Local\TNT2\2.0.0.1599\npTNT2ghost.dll (Search.Us.com)
FF Extension: No Name - C:\Users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\Extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com
========================== Services (Whitelisted) =================
S3 CoordinatorServiceHost; C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [87336 2010-10-05] (Dassault Systèmes SolidWorks Corp.)
S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [1044816 2013-07-18] (Flexera Software, Inc.)
R2 Kodak AiO Network Discovery Service; C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe [366000 2011-03-09] (Eastman Kodak Company)
S4 msvsmon80; C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2799808 2006-10-26] (Microsoft Corporation)
S3 SolidWorks Licensing Service; C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe [79360 2013-07-18] (SolidWorks)
R2 VmbService; C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [9216 2011-04-19] (Vodafone)
S2 Registry Helper Service; C:\Program Files\Registry Helper\RegistryHelperService.exe [x]
==================== Drivers (Whitelisted) ====================
R0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-14] (Microsoft Corporation)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [242240 2013-02-24] (DT Soft Ltd)
S3 huawei_cdcacm; C:\Windows\System32\DRIVERS\ew_jucdcacm.sys [85760 2011-04-18] (Huawei Technologies Co., Ltd.)
S3 huawei_ext_ctrl; C:\Windows\System32\DRIVERS\ew_juextctrl.sys [26496 2011-04-18] (Huawei Technologies Co., Ltd.)
S3 huawei_wwanecm; C:\Windows\System32\DRIVERS\ew_juwwanecm.sys [168448 2011-04-18] (Huawei Technologies Co., Ltd.)
S3 NPF; C:\Windows\System32\drivers\npf.sys [34064 2011-01-04] (CACE Technologies)
R3 RTL85n86; C:\Windows\System32\DRIVERS\RTL85n86.sys [311808 2009-07-14] (Realtek)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-10-24 17:23 - 2013-10-24 17:23 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Stefan\Downloads\tdsskiller.exe
2013-10-24 17:20 - 2013-10-24 17:20 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Stefan\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-24 17:12 - 2013-10-24 17:13 - 05136677 _____ (Swearware) C:\Users\Stefan\Downloads\ComboFix.exe
2013-10-24 17:12 - 2013-10-24 17:13 - 01906472 _____ (Express Install ) C:\Users\Stefan\Downloads\setup.exe
2013-10-23 19:06 - 2013-10-23 21:06 - 00000000 ____D C:\Users\Stefan\Desktop\cd's musiek
2013-10-22 19:48 - 2013-10-22 21:19 - 00000000 ____D C:\Users\Stefan\Desktop\linds bday cd
2013-10-22 19:25 - 2013-10-22 19:25 - 00001336 _____ C:\Users\Stefan\Desktop\Free Video to MP3 Converter.lnk
2013-10-22 19:25 - 2013-10-22 19:25 - 00001201 _____ C:\Users\Stefan\Desktop\DVDVideoSoft Free Studio.lnk
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Users\Stefan\Documents\DVDVideoSoft
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\DVDVideoSoft
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Program Files\Common Files\Plasmoo
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-10-08 08:18 - 2013-10-24 17:28 - 00001348 _____ C:\Windows\Tasks\ElectroLyrics-1-updater.job
2013-10-08 08:18 - 2013-10-24 17:28 - 00001254 _____ C:\Windows\Tasks\ElectroLyrics-1-codedownloader.job
2013-10-08 08:18 - 2013-10-24 17:28 - 00001154 _____ C:\Windows\Tasks\ElectroLyrics-1-enabler.job
2013-10-08 08:18 - 2013-10-08 08:18 - 00000985 _____ C:\Users\Stefan\Desktop\SevenZip.lnk
2013-10-08 08:18 - 2013-10-08 08:18 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SevenZip 9.20
2013-10-08 08:18 - 2013-10-08 08:18 - 00000000 ____D C:\Program Files\SevenZip
2013-10-08 08:17 - 2013-10-24 17:28 - 00001882 _____ C:\Windows\Tasks\ElectroLyrics-1-firefoxinstaller.job
2013-10-08 08:17 - 2013-10-08 08:18 - 00000000 ____D C:\Program Files\ElectroLyrics-1
2013-10-08 08:15 - 2013-10-24 17:28 - 00000360 _____ C:\Windows\Tasks\AmiUpdXp.job
2013-10-08 08:15 - 2013-10-08 08:15 - 00000000 ____D C:\Users\Stefan\AppData\Local\SwvUpdater
2013-10-08 06:50 - 2013-10-24 17:28 - 00000000 ____D C:\FRST
2013-10-08 06:47 - 2013-10-08 06:47 - 01087213 _____ (Farbar) C:\Users\Stefan\Downloads\FRST.exe
2013-10-07 16:22 - 2013-10-07 16:23 - 00000000 ____D C:\ProgramData\MFAData
2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\MFAData
2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\Avg2014
2013-10-07 16:11 - 2013-10-07 16:12 - 04433128 _____ (AVG Technologies) C:\Users\Stefan\Downloads\avg_isct_stb_all_2014_4142_free.exe
2013-10-07 14:55 - 2013-10-07 14:54 - 00006396 _____ C:\Users\Stefan\Downloads\0677.mpssvc.reg
2013-10-07 14:54 - 2013-10-07 14:54 - 00229548 _____ C:\Users\Stefan\Downloads\1055.BFE.reg
2013-10-07 14:42 - 2013-10-23 05:26 - 00007632 _____ C:\Users\Stefan\AppData\Local\Resmon.ResmonCfg
2013-10-07 14:29 - 2013-10-24 17:28 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\NetSpeedMonitor
2013-10-07 14:29 - 2013-10-07 14:29 - 00000000 ____D C:\Program Files\NetSpeedMonitor
2013-10-04 04:26 - 2013-10-04 04:26 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-01 17:08 - 2013-10-01 17:08 - 00002153 _____ C:\Users\Public\Desktop\Sid Meier's Pirates!.lnk
2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\Documents\My Games
2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firaxis Games
2013-10-01 17:07 - 2013-10-01 17:07 - 00000000 ____D C:\Program Files\Firaxis Games
==================== One Month Modified Files and Folders =======
2013-10-24 17:28 - 2013-10-08 08:18 - 00001348 _____ C:\Windows\Tasks\ElectroLyrics-1-updater.job
2013-10-24 17:28 - 2013-10-08 08:18 - 00001254 _____ C:\Windows\Tasks\ElectroLyrics-1-codedownloader.job
2013-10-24 17:28 - 2013-10-08 08:18 - 00001154 _____ C:\Windows\Tasks\ElectroLyrics-1-enabler.job
2013-10-24 17:28 - 2013-10-08 08:17 - 00001882 _____ C:\Windows\Tasks\ElectroLyrics-1-firefoxinstaller.job
2013-10-24 17:28 - 2013-10-08 08:15 - 00000360 _____ C:\Windows\Tasks\AmiUpdXp.job
2013-10-24 17:28 - 2013-10-08 06:50 - 00000000 ____D C:\FRST
2013-10-24 17:28 - 2013-10-07 14:29 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\NetSpeedMonitor
2013-10-24 17:28 - 2013-05-18 14:17 - 00000000 ____D C:\ProgramData\Kodak
2013-10-24 17:28 - 2013-02-24 13:13 - 00000000 ____D C:\ProgramData\NVIDIA
2013-10-24 17:28 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-10-24 17:28 - 2009-07-14 06:39 - 00162568 _____ C:\Windows\setupact.log
2013-10-24 17:27 - 2013-02-25 18:47 - 00019674 _____ C:\Windows\PFRO.log
2013-10-24 17:26 - 2013-02-24 10:55 - 00000000 ____D C:\Users\Stefan
2013-10-24 17:23 - 2013-10-24 17:23 - 04121952 _____ (Kaspersky Lab ZAO) C:\Users\Stefan\Downloads\tdsskiller.exe
2013-10-24 17:20 - 2013-10-24 17:20 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Stefan\Downloads\mbam-setup-1.75.0.1300.exe
2013-10-24 17:13 - 2013-10-24 17:12 - 05136677 _____ (Swearware) C:\Users\Stefan\Downloads\ComboFix.exe
2013-10-24 17:13 - 2013-10-24 17:12 - 01906472 _____ (Express Install ) C:\Users\Stefan\Downloads\setup.exe
2013-10-24 17:00 - 2013-02-24 10:59 - 00795074 _____ C:\Windows\system32\PerfStringBackup.INI
2013-10-24 16:59 - 2013-03-01 08:23 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-10-24 06:32 - 2013-03-08 03:05 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\vlc
2013-10-23 21:06 - 2013-10-23 19:06 - 00000000 ____D C:\Users\Stefan\Desktop\cd's musiek
2013-10-23 18:44 - 2013-02-24 11:55 - 00000000 ____D C:\Users\Stefan\Desktop\Start-up CD
2013-10-23 05:26 - 2013-10-07 14:42 - 00007632 _____ C:\Users\Stefan\AppData\Local\Resmon.ResmonCfg
2013-10-22 21:19 - 2013-10-22 19:48 - 00000000 ____D C:\Users\Stefan\Desktop\linds bday cd
2013-10-22 19:25 - 2013-10-22 19:25 - 00001336 _____ C:\Users\Stefan\Desktop\Free Video to MP3 Converter.lnk
2013-10-22 19:25 - 2013-10-22 19:25 - 00001201 _____ C:\Users\Stefan\Desktop\DVDVideoSoft Free Studio.lnk
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Users\Stefan\Documents\DVDVideoSoft
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\DVDVideoSoft
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Program Files\DVDVideoSoft
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Program Files\Common Files\Plasmoo
2013-10-22 19:25 - 2013-10-22 19:25 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft
2013-10-17 03:41 - 2013-08-31 15:27 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\dvdcss
2013-10-17 03:03 - 2013-08-31 15:29 - 00000000 ____D C:\Users\Stefan\.dvdcss
2013-10-10 13:46 - 2013-07-19 00:59 - 00000000 ____D C:\Program Files\Industry Giant 2
2013-10-08 08:18 - 2013-10-08 08:18 - 00000985 _____ C:\Users\Stefan\Desktop\SevenZip.lnk
2013-10-08 08:18 - 2013-10-08 08:18 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SevenZip 9.20
2013-10-08 08:18 - 2013-10-08 08:18 - 00000000 ____D C:\Program Files\SevenZip
2013-10-08 08:18 - 2013-10-08 08:17 - 00000000 ____D C:\Program Files\ElectroLyrics-1
2013-10-08 08:15 - 2013-10-08 08:15 - 00000000 ____D C:\Users\Stefan\AppData\Local\SwvUpdater
2013-10-08 08:09 - 2013-07-03 17:21 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\BitTorrent
2013-10-08 06:47 - 2013-10-08 06:47 - 01087213 _____ (Farbar) C:\Users\Stefan\Downloads\FRST.exe
2013-10-07 16:23 - 2013-10-07 16:22 - 00000000 ____D C:\ProgramData\MFAData
2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\MFAData
2013-10-07 16:22 - 2013-10-07 16:22 - 00000000 ____D C:\Users\Stefan\AppData\Local\Avg2014
2013-10-07 16:12 - 2013-10-07 16:11 - 04433128 _____ (AVG Technologies) C:\Users\Stefan\Downloads\avg_isct_stb_all_2014_4142_free.exe
2013-10-07 16:09 - 2013-03-10 18:56 - 00000000 ____D C:\Users\Stefan\Desktop\Torrents
2013-10-07 14:54 - 2013-10-07 14:55 - 00006396 _____ C:\Users\Stefan\Downloads\0677.mpssvc.reg
2013-10-07 14:54 - 2013-10-07 14:54 - 00229548 _____ C:\Users\Stefan\Downloads\1055.BFE.reg
2013-10-07 14:29 - 2013-10-07 14:29 - 00000000 ____D C:\Program Files\NetSpeedMonitor
2013-10-07 13:31 - 2013-09-12 14:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-10-04 09:20 - 2013-02-24 12:10 - 00000000 ____D C:\Users\Stefan\AppData\Local\Mozilla
2013-10-04 04:26 - 2013-10-04 04:26 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-10-01 17:09 - 2013-03-11 06:33 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2013-10-01 17:09 - 2013-02-24 11:02 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2013-10-01 17:08 - 2013-10-01 17:08 - 00002153 _____ C:\Users\Public\Desktop\Sid Meier's Pirates!.lnk
2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\Documents\My Games
2013-10-01 17:08 - 2013-10-01 17:08 - 00000000 ____D C:\Users\Stefan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Firaxis Games
2013-10-01 17:07 - 2013-10-01 17:07 - 00000000 ____D C:\Program Files\Firaxis Games
2013-10-01 17:06 - 2013-03-11 06:30 - 00000000 ____D C:\Program Files\Common Files\InstallShield
2013-09-29 17:16 - 2013-08-23 11:17 - 00000000 ____D C:\Program Files\DefaultTab
2013-09-27 22:00 - 2013-02-24 12:07 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-27 22:00 - 2013-02-24 12:07 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
Files to move or delete:
====================
C:\Users\Stefan\dxagvi.exe
C:\Users\Stefan\dxaleyl.exe
C:\Users\Stefan\dxayxcs.exe
C:\Users\Stefan\dxeccpws.exe
C:\Users\Stefan\dxemys.exe
C:\Users\Stefan\dxeriuw.exe
C:\Users\Stefan\dxfjnn.exe
C:\Users\Stefan\dxhbewgfq.exe
C:\Users\Stefan\dxhgyx.exe
C:\Users\Stefan\dxijldymn.exe
C:\Users\Stefan\dxivie.exe
C:\Users\Stefan\dxmfdot.exe
C:\Users\Stefan\dxnaku.exe
C:\Users\Stefan\dxnsqb.exe
C:\Users\Stefan\dxoaua.exe
C:\Users\Stefan\dxokxybd.exe
C:\Users\Stefan\dxqeuiurj.exe
C:\Users\Stefan\dxqzso.exe
C:\Users\Stefan\dxrkosal.exe
C:\Users\Stefan\dxuhweann.exe
C:\Users\Stefan\dxujed.exe
C:\Users\Stefan\dxupon.exe
C:\Users\Stefan\dxveae.exe
C:\Users\Stefan\dxxdag.exe
Some content of TEMP:
====================
C:\Users\Stefan\AppData\Local\Temp\0_Offer_1.exe
C:\Users\Stefan\AppData\Local\Temp\1_Offer_2.exe
C:\Users\Stefan\AppData\Local\Temp\20131008081028.14.exe
C:\Users\Stefan\AppData\Local\Temp\DownloadManager.exe
C:\Users\Stefan\AppData\Local\Temp\UpdateCheckerSetup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-10-21 00:45
==================== End Of Log ============================
Combofix.txtComboFix 13-10-24.01 - Stefan 2013/10/24 17:33:17.1.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.27.1033.18.3583.2736 [GMT 2:00]
Running from: c:\users\Stefan\Downloads\ComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\DefaultTab
c:\program files\DefaultTab\DefaultTab.crx
c:\program files\DefaultTab\DefaultTabSearch.exe
c:\program files\DefaultTab\uid
c:\program files\ElectroLyrics-1
c:\program files\ElectroLyrics-1\41844.xpi
c:\program files\ElectroLyrics-1\background.html
c:\program files\ElectroLyrics-1\ElectroLyrics-1-bg.exe
c:\program files\ElectroLyrics-1\ElectroLyrics-1-bho.dll
c:\program files\ElectroLyrics-1\ElectroLyrics-1-buttonutil.dll
c:\program files\ElectroLyrics-1\ElectroLyrics-1-buttonutil.exe
c:\program files\ElectroLyrics-1\ElectroLyrics-1-codedownloader.exe
c:\program files\ElectroLyrics-1\ElectroLyrics-1-enabler.exe
c:\program files\ElectroLyrics-1\ElectroLyrics-1-firefoxinstaller.exe
c:\program files\ElectroLyrics-1\ElectroLyrics-1-helper.exe
c:\program files\ElectroLyrics-1\ElectroLyrics-1-updater.exe
c:\program files\ElectroLyrics-1\ElectroLyrics-1.ico
c:\program files\ElectroLyrics-1\Installer.log
c:\program files\ElectroLyrics-1\Uninstall.exe
c:\program files\ElectroLyrics-1\utils.exe
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\addon.ico
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.cfg
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart.exe
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabStart64.exe
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabUninstaller.exe
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap.dll
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabWrap64.dll
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DT.ico
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\DTUpdate.exe
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\search_here_ie.ico
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\searchhere.ico
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe
c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\update.exe
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome.manifest
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\asyncDB.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\background.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\browserAction.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\contextMenu.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\dbManager.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\dom_bg.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\fileManager.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\firefox.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\firefoxNotifications.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\firefoxOmnibox.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\message.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\pageAction.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\request.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\tabs.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\api\webRequest.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\background.html
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\baseObject.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\browser.xul
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\console.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\consts.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\delegate.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\extensionDataStore.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\folderIOWrapper.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\httpObserver.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\IDBWrapper.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\installer.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\logFile.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\prefs.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\progressListenerObserver.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\registry.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\reloadObserver.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\reports.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\requestObject.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\searchSettings.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\uninstallObserver.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\updateManager.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\utils.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\core\xhr.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\dialog.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\main.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\options.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\options.xul
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\chrome\content\search_dialog.xul
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\defaults\preferences\prefs.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\manifest.xml
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins.json
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\1_base.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\101_cortica_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\102_dealply_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\103_intext_5_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\104_jollywallet_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\105_corticas_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\107_coupish_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\108_icm_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\116_ads_only_5_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\117_coupons_intext_ads_5_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\119_similar_web_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\120_luck_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\123_intext_adv_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\124_superfish_no_search_no_coupons_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\125_arcadi2_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\126_revizer_ws_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\127_revizer_p_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\128_superfish_pricora_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\129_widdit_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\13_CrossriderAppUtils.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\135_arcadi3_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\138_getdeal_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\14_CrossriderUtils.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\141_corticas_ru_m.js.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\142_intext_fa_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\155_ibario_pops_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\158_50onred_ads_only_no_fb_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\159_cortica_rollover_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\16_FFAppAPIWrapper.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\17_jQuery.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\170_icm1_5_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\171_arcadi2_sourceID_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\174_arcadi_serp_dynamic_id_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\175_coolmirage_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\21_debug.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\22_resources.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\28_initializer.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\4_jquery_1_7_1.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\47_resources_background.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\64_appApiMessage.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\7_hooks.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\72_appApiValidation.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\78_CrossriderInfo.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\87_ginyas_wrapper.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\9_search_engine_hook.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\91_monetizationLoader.js.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\92_superfish_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\93_superfish_no_coupons_m.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\plugins\98_omniCommands.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\userCode\background.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\extensionData\userCode\extension.js
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\install.rdf
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\locale\en-US\translations.dtd
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\button1.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\button2.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\button3.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\button4.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\button5.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\crossrider_statusbar.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\icon128.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\icon16.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\icon24.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\icon48.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\panelarrow-up.png
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\popup.html
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\skin.css
c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\extensions\bbf8c9b4-8e92-4864-a738-39b4d9d297ba@c61f16d8-dec3-4ab4-a153-723bd1d0f742.com\skin\update.css
c:\users\Stefan\dxagvi.exe
c:\users\Stefan\dxaleyl.exe
c:\users\Stefan\dxayxcs.exe
c:\users\Stefan\dxeccpws.exe
c:\users\Stefan\dxemys.exe
c:\users\Stefan\dxeriuw.exe
c:\users\Stefan\dxfjnn.exe
c:\users\Stefan\dxhbewgfq.exe
c:\users\Stefan\dxhgyx.exe
c:\users\Stefan\dxijldymn.exe
c:\users\Stefan\dxivie.exe
c:\users\Stefan\dxmfdot.exe
c:\users\Stefan\dxnaku.exe
c:\users\Stefan\dxnsqb.exe
c:\users\Stefan\dxoaua.exe
c:\users\Stefan\dxokxybd.exe
c:\users\Stefan\dxqeuiurj.exe
c:\users\Stefan\dxrkosal.exe
c:\users\Stefan\dxuhweann.exe
c:\users\Stefan\dxujed.exe
c:\users\Stefan\dxupon.exe
c:\users\Stefan\dxveae.exe
c:\users\Stefan\dxxdag.exe
c:\windows\system32\drivers\etc\hosts.ics
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\roboot.exe
c:\windows\system32\wpcap.dll
.
----- File Replicators -----
.
c:\frst\Quarantine\dxakokxu.exe
c:\frst\Quarantine\dxavzr.exe
c:\frst\Quarantine\dxbesgdoq.exe
c:\frst\Quarantine\dxcadh.exe
c:\frst\Quarantine\dxcbaathv.exe
c:\frst\Quarantine\dxddoi.exe
c:\frst\Quarantine\dxdjbu.exe
c:\frst\Quarantine\dxgcftur.exe
c:\frst\Quarantine\dxhuamnw.exe
c:\frst\Quarantine\dxhvrn.exe
c:\frst\Quarantine\dxiewkke.exe
c:\frst\Quarantine\dxiynj.exe
c:\frst\Quarantine\dxizkvbep.exe
c:\frst\Quarantine\dxkdufa.exe
c:\frst\Quarantine\dxlmhx.exe
c:\frst\Quarantine\dxojim.exe
c:\frst\Quarantine\dxoyiv.exe
c:\frst\Quarantine\dxqafz.exe
c:\frst\Quarantine\dxriojni.exe
c:\frst\Quarantine\dxrjiy.exe
c:\frst\Quarantine\dxrrblix.exe
c:\frst\Quarantine\dxsezfjt.exe
c:\frst\Quarantine\dxtjrk.exe
c:\frst\Quarantine\dxtseu.exe
c:\frst\Quarantine\dxudeh.exe
c:\frst\Quarantine\dxxtwdeuo.exe
c:\frst\Quarantine\dxyrsiu.exe
c:\frst\Quarantine\dxzkhbwa.exe
c:\users\Stefan\dxagvi.exe
c:\users\Stefan\dxaleyl.exe
c:\users\Stefan\dxayxcs.exe
c:\users\Stefan\dxeccpws.exe
c:\users\Stefan\dxemys.exe
c:\users\Stefan\dxeriuw.exe
c:\users\Stefan\dxfjnn.exe
c:\users\Stefan\dxhbewgfq.exe
c:\users\Stefan\dxhgyx.exe
c:\users\Stefan\dxijldymn.exe
c:\users\Stefan\dxivie.exe
c:\users\Stefan\dxmfdot.exe
c:\users\Stefan\dxnaku.exe
c:\users\Stefan\dxnsqb.exe
c:\users\Stefan\dxoaua.exe
c:\users\Stefan\dxokxybd.exe
c:\users\Stefan\dxqeuiurj.exe
c:\users\Stefan\dxrkosal.exe
c:\users\Stefan\dxuhweann.exe
c:\users\Stefan\dxujed.exe
c:\users\Stefan\dxupon.exe
c:\users\Stefan\dxveae.exe
c:\users\Stefan\dxxdag.exe
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_NPF
-------\Service_NPF
-------\Service_Run
-------\Service_Registry Helper Service
.
.
((((((((((((((((((((((((( Files Created from 2013-09-24 to 2013-10-24 )))))))))))))))))))))))))))))))
.
.
2013-10-22 17:25 . 2013-10-22 17:25 -------- d-----w- c:\program files\Common Files\Plasmoo
2013-10-22 17:25 . 2013-10-22 17:25 -------- d-----w- c:\users\Stefan\AppData\Roaming\DVDVideoSoft
2013-10-22 17:25 . 2013-10-22 17:25 -------- d-----w- c:\program files\Common Files\DVDVideoSoft
2013-10-22 17:25 . 2013-10-22 17:25 -------- d-----w- c:\program files\DVDVideoSoft
2013-10-08 06:18 . 2013-10-08 06:18 -------- d-----w- c:\program files\SevenZip
2013-10-08 06:15 . 2013-10-08 06:15 -------- d-----w- c:\users\Stefan\AppData\Local\SwvUpdater
2013-10-08 04:50 . 2013-10-24 15:28 -------- d-----w- C:\FRST
2013-10-07 14:22 . 2013-10-07 14:23 -------- d-----w- c:\programdata\MFAData
2013-10-07 14:22 . 2013-10-07 14:22 -------- d--h--w- c:\programdata\Common Files
2013-10-07 14:22 . 2013-10-07 14:22 -------- d-----w- c:\users\Stefan\AppData\Local\MFAData
2013-10-07 14:22 . 2013-10-07 14:22 -------- d-----w- c:\users\Stefan\AppData\Local\Avg2014
2013-10-07 12:29 . 2013-10-24 15:41 -------- d-----w- c:\users\Stefan\AppData\Roaming\NetSpeedMonitor
2013-10-07 12:29 . 2013-10-07 12:29 -------- d-----w- c:\program files\NetSpeedMonitor
2013-10-01 15:07 . 2013-10-01 15:07 -------- d-----w- c:\program files\Firaxis Games
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-09-27 20:00 . 2013-02-24 10:07 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2013-09-27 20:00 . 2013-02-24 10:07 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2013-09-20 13:45 . 2013-09-20 13:45 389120 ----a-w- c:\windows\system32\RegistryHelperLM.ocx
2013-08-23 13:24 . 2013-08-23 13:24 87392 ----a-r- c:\users\Stefan\AppData\Roaming\Microsoft\Installer\{90481BEA-8F52-4FE7-A0D6-BBFAB003D997}\VideoConverter5_St_10EBE4A00F514DB49EA9B218A1E9D3F5.exe
2013-08-23 13:24 . 2013-08-23 13:24 87392 ----a-r- c:\users\Stefan\AppData\Roaming\Microsoft\Installer\{90481BEA-8F52-4FE7-A0D6-BBFAB003D997}\NewShortcut4_941FA141AAB14924B185046EE8E1BDD9.exe
2013-08-23 13:24 . 2013-08-23 13:24 71008 ----a-r- c:\users\Stefan\AppData\Roaming\Microsoft\Installer\{90481BEA-8F52-4FE7-A0D6-BBFAB003D997}\VideoConverter5_St_BF4E5749C8A942ACA48E229C02AC7D3D.exe
2013-08-23 13:24 . 2013-08-23 13:24 71008 ----a-r- c:\users\Stefan\AppData\Roaming\Microsoft\Installer\{90481BEA-8F52-4FE7-A0D6-BBFAB003D997}\ARPPRODUCTICON.exe
2013-08-23 13:24 . 2013-08-23 13:24 136544 ----a-r- c:\users\Stefan\AppData\Roaming\Microsoft\Installer\{90481BEA-8F52-4FE7-A0D6-BBFAB003D997}\VideoConverter5_St_4949825D36F8486CAED8D1FA37A2B641.exe
2013-07-30 15:36 . 2013-07-30 15:36 4608 ----a-w- c:\windows\system32\w95inf32.dll
2013-07-30 15:36 . 2013-07-30 15:36 2272 ----a-w- c:\windows\system32\w95inf16.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2013-03-26 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:\windows\System32\user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:\windows\winsxs\x86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2012-11-06 3673728]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2012-06-20 74752]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2012-01-03 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576]
"EKAiO2StatusMonitor"="c:\windows\system32\spool\DRIVERS\W32X86\3\EKAiO2MUI.exe" [2011-03-01 2421760]
"MobileBroadband"="c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe" [2011-04-19 408576]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
SolidWorks Background Downloader.lnk - c:\program files\Common Files\SolidWorks Installation Manager\BackgroundDownloading\sldBgDwld.exe /launch_from 0 [2013-7-18 1826600]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R3 CoordinatorServiceHost;SW Distributed TS Coordinator Service;c:\program files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe [2010-10-05 87336]
R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [2011-04-18 102784]
R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [2011-04-18 11136]
R3 huawei_cdcacm;huawei_cdcacm;c:\windows\system32\DRIVERS\ew_jucdcacm.sys [2011-04-18 85760]
R3 huawei_ext_ctrl;huawei_ext_ctrl;c:\windows\system32\DRIVERS\ew_juextctrl.sys [2011-04-18 26496]
R3 huawei_wwanecm;huawei_wwanecm;c:\windows\system32\DRIVERS\ew_juwwanecm.sys [2011-04-18 168448]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2013-03-26 1343400]
R4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2006-10-26 2799808]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2013-02-24 242240]
S2 Kodak AiO Network Discovery Service;Kodak AiO Network Discovery Service;c:\program files\Kodak\AiO\Center\EKAiOHostService.exe [2011-03-09 366000]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2012-05-15 382272]
S2 VmbService;Vodafone Mobile Broadband Service;c:\program files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe [2011-04-19 9216]
S3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [2011-04-18 72832]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
S3 RTL85n86;Realtek 8180/8185 Extensible 802.11 Wireless Device Driver;c:\windows\system32\DRIVERS\RTL85n86.sys [2009-07-13 311808]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS FontCache fdrespub AppIDSvc QWAVE wcncsvc SensrSvc
.
Contents of the 'Scheduled Tasks' folder
.
2013-10-24 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-02-24 20:00]
.
2013-10-24 c:\windows\Tasks\AmiUpdXp.job
- c:\users\Stefan\AppData\Local\SwvUpdater\Updater.exe [2013-10-08 06:15]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://start.search.us.com/v/2/?guid={5CD6CB79-8ADD-4852-82CF-00ED47F6214E}&serpv=5
mStart Page = hxxp://websearch.youwillfind.info/?pid=658&r=2013/05/02&hid=763785938&lg=EN&cc=ZA
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.42.129
TCP: Interfaces\{131B5047-1B2C-449F-9AAC-DC252D82C1E1}: NameServer = 196.207.36.251 196.207.36.254
TCP: Interfaces\{17F7B7DA-3406-4F8D-9541-EA905EED8D4A}: NameServer = 196.207.36.251 196.207.36.254
TCP: Interfaces\{C775872A-FCC3-42EA-AAFA-AD8B5396A367}: NameServer = 196.207.36.251 196.207.36.254
TCP: Interfaces\{CB318F49-15F3-407F-9EBE-BBA23BBCC213}: NameServer = 196.207.36.251 196.207.36.254
FF - ProfilePath - c:\users\Stefan\AppData\Roaming\Mozilla\Firefox\Profiles\ltu82yf4.default\
FF - prefs.js: browser.startup.homepage - hxxp://start.search.us.com/v/2/?guid={5CD6CB79-8ADD-4852-82CF-00ED47F6214E}&serpv=5
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-Conime - c:\windows\system32\conime.exe
HKLM-Run-Registry Helper - c:\program files\Registry Helper\RegistryHelper.Exe
AddRemove-DefaultTab - c:\users\Stefan\AppData\Roaming\DefaultTab\DefaultTab\uninstalldt.exe
AddRemove-ElectroLyrics-1 - c:\program files\ElectroLyrics-1\Uninstall.exe
AddRemove-Registry Helper - c:\program files\Registry Helper\uninst.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-2482761239-3750086217-1899643328-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**ˆL
( L
( ˜—5lÇW]
@Class="Shell"
@Allowed: (Read) (RestrictedCode)
.
[HKEY_USERS\S-1-5-21-2482761239-3750086217-1899643328-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.**ˆL
( L
( ˜—5lÇW\OpenWithList]
@Class="Shell"
"a"="vlc.exe"
"MRUList"="a"
.
[HKEY_USERS\S-1-5-21-2482761239-3750086217-1899643328-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs\.**ˆL
( L
( ˜—5lÇW]
@Allowed: (Read) (RestrictedCode)
"0"=hex:44,3a,5c,4d,75,73,69,63,20,76,69,64,65,6f,73,5c,42,65,65,20,47,65,65,
73,20,2d,20,49,6e,20,54,68,65,20,28,4f,72,69,67,69,6e,61,6c,20,31,39,36,35,\
"MRUListEx"=hex:00,00,00,00,ff,ff,ff,ff
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\windows\system32\AUDIODG.EXE
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\WUDFHost.exe
c:\windows\system32\conhost.exe
c:\windows\System32\rundll32.exe
c:\program files\NVIDIA Corporation\Display\nvtray.exe
c:\program files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
.
**************************************************************************
.
Completion time: 2013-10-24 17:43:47 - machine was rebooted
ComboFix-quarantined-files.txt 2013-10-24 15:43
.
Pre-Run: 3 218 190 336 bytes free
Post-Run: 3 553 181 696 bytes free
.
- - End Of File - - 6F44EDAF8F8BC53FD95CB9C13EFCC856
A36C5E4F47E84449FF07ED3517B43A31
TDSSKiller.txt17:46:01.0888 0x0f90 TDSS rootkit removing tool 3.0.0.14 Oct 15 2013 15:35:38
17:46:13.0962 0x0f90 ============================================================
17:46:13.0962 0x0f90 Current date / time: 2013/10/24 17:46:13.0962
17:46:13.0962 0x0f90 SystemInfo:
17:46:13.0962 0x0f90
17:46:13.0962 0x0f90 OS Version: 6.1.7600 ServicePack: 0.0
17:46:13.0962 0x0f90 Product type: Workstation
17:46:13.0962 0x0f90 ComputerName: STEFAN-PC
17:46:13.0962 0x0f90 UserName: Stefan
17:46:13.0962 0x0f90 Windows directory: C:\Windows
17:46:13.0962 0x0f90 System windows directory: C:\Windows
17:46:13.0962 0x0f90 Processor architecture: Intel x86
17:46:13.0962 0x0f90 Number of processors: 2
17:46:13.0962 0x0f90 Page size: 0x1000
17:46:13.0962 0x0f90 Boot type: Normal boot
17:46:13.0962 0x0f90 ============================================================
17:46:17.0878 0x0f90 System UUID: {4B2E4CFA-89B4-4330-DA2F-200EFCDF1139}
17:46:18.0206 0x0f90 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0x38080, SectorsPerTrack: 0x13, TracksPerCylinder: 0xE0, Type 'K0', Flags 0x00000050
17:46:18.0206 0x0f90 Drive \Device\Harddisk1\DR1 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
17:46:18.0830 0x0f90 Drive \Device\Harddisk2\DR2 - Size: 0x77800000 (1.87 Gb), SectorSize: 0x200, Cylinders: 0xF3, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
17:46:18.0830 0x0f90 ============================================================
17:46:18.0830 0x0f90 \Device\Harddisk0\DR0:
17:46:18.0830 0x0f90 MBR partitions:
17:46:18.0830 0x0f90 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
17:46:18.0830 0x0f90 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0xC350000
17:46:18.0830 0x0f90 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0xC382800, BlocksNum 0x2E002800
17:46:18.0830 0x0f90 \Device\Harddisk1\DR1:
17:46:18.0830 0x0f90 MBR partitions:
17:46:18.0830 0x0f90 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2542D682
17:46:18.0830 0x0f90 \Device\Harddisk2\DR2:
17:46:18.0830 0x0f90 MBR partitions:
17:46:18.0830 0x0f90 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x6, StartLBA 0x1F80, BlocksNum 0x3BA080
17:46:18.0830 0x0f90 ============================================================
17:46:18.0845 0x0f90 C: <-> \Device\Harddisk0\DR0\Partition2
17:46:18.0876 0x0f90 D: <-> \Device\Harddisk0\DR0\Partition3
17:46:18.0986 0x0f90 H: <-> \Device\Harddisk1\DR1\Partition1
17:46:18.0986 0x0f90 ============================================================
17:46:18.0986 0x0f90 Initialize success
17:46:18.0986 0x0f90 ============================================================
17:47:21.0105 0x0d30 ============================================================
17:47:21.0105 0x0d30 Scan started
17:47:21.0105 0x0d30 Mode: Manual; SigCheck; TDLFS;
17:47:21.0105 0x0d30 ============================================================
17:47:21.0105 0x0d30 KSN ping started
17:47:26.0893 0x0d30 KSN ping finished: true
17:47:27.0704 0x0d30 ================ Scan system memory ========================
17:47:27.0704 0x0d30 System memory - ok
17:47:27.0704 0x0d30 ================ Scan services =============================
17:47:27.0813 0x0d30 [ 6D2ACA41739BFE8CB86EE8E85F29697D, 74A4F53C8309A8E5E94CDE4D440DD5308566185E6D8D98FD08E70A25BD728C91 ] 1394ohci C:\Windows\system32\DRIVERS\1394ohci.sys
17:47:27.0891 0x0d30 1394ohci - ok
17:47:27.0938 0x0d30 [ F0E07D144C8685B8774BC32FC8DA4DF0, 39816ED2623CA9ABE2B2EDCDB2F8481634742F00FEEF7E324F34D2BAAD668A67 ] ACPI C:\Windows\system32\DRIVERS\ACPI.sys
17:47:27.0953 0x0d30 ACPI - ok
17:47:27.0969 0x0d30 [ 98D81CA942D19F7D9153B095162AC013, ACE5C073323176621F3312AA9B1EE1A3382F8CDD590D90DC57B34035FD6BC281 ] AcpiPmi C:\Windows\system32\DRIVERS\acpipmi.sys
17:47:28.0016 0x0d30 AcpiPmi - ok
17:47:28.0078 0x0d30 [ 24A0876D07EF356DCBC1D7A7929354AB, 765653E856EC5841DB851363E7C7CFC332D3605789ECD0998762F60ADD56A0D8 ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
17:47:28.0094 0x0d30 AdobeFlashPlayerUpdateSvc - ok
17:47:28.0156 0x0d30 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
17:47:28.0172 0x0d30 adp94xx - ok
17:47:28.0203 0x0d30 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
17:47:28.0219 0x0d30 adpahci - ok
17:47:28.0234 0x0d30 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
17:47:28.0250 0x0d30 adpu320 - ok
17:47:28.0265 0x0d30 [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
17:47:28.0297 0x0d30 AeLookupSvc - ok
17:47:28.0343 0x0d30 [ DDC040FDB01EF1712A6B13E52AFB104C, BF17E91BBB85A04F1EEF580CD006101332CDE5B876A0D04C6932F30707BB184F ] AFD C:\Windows\system32\drivers\afd.sys
17:47:28.0375 0x0d30 AFD - ok
17:47:28.0390 0x0d30 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\DRIVERS\agp440.sys
17:47:28.0406 0x0d30 agp440 - ok
17:47:28.0437 0x0d30 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
17:47:28.0453 0x0d30 aic78xx - ok
17:47:28.0468 0x0d30 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe
17:47:28.0484 0x0d30 ALG - ok
17:47:28.0499 0x0d30 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\DRIVERS\aliide.sys
17:47:28.0499 0x0d30 aliide - ok
17:47:28.0499 0x0d30 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\DRIVERS\amdagp.sys
17:47:28.0515 0x0d30 amdagp - ok
17:47:28.0531 0x0d30 [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
17:47:28.0531 0x0d30 amdide - ok
17:47:28.0546 0x0d30 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
17:47:28.0546 0x0d30 AmdK8 - ok
17:47:28.0562 0x0d30 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
17:47:28.0577 0x0d30 AmdPPM - ok
17:47:28.0609 0x0d30 [ 2101A86C25C154F8314B24EF49D7FBC2, E4C1326CF55850793B45B2BFDF361C4E98A07FB13E08BFD6DB50135489700998 ] amdsata C:\Windows\system32\DRIVERS\amdsata.sys
17:47:28.0609 0x0d30 amdsata - ok
17:47:28.0640 0x0d30 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
17:47:28.0640 0x0d30 amdsbs - ok
17:47:28.0655 0x0d30 [ B81C2B5616F6420A9941EA093A92B150, DA2000C9E06533232F8716A6674BC9DFD5C3AAE1FC46F7A91B8E917DB913F42F ] amdxata C:\Windows\system32\DRIVERS\amdxata.sys
17:47:28.0671 0x0d30 amdxata - ok
17:47:28.0687 0x0d30 [ FEB834C02CE1E84B6A38F953CA067706, E5A7F8B632ABFBD1283C3D44FB02449814EDB653B204E1720DAA780A6D64FD01 ] AppID C:\Windows\system32\drivers\appid.sys
17:47:28.0702 0x0d30 AppID - ok
17:47:28.0718 0x0d30 [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc C:\Windows\System32\appidsvc.dll
17:47:28.0749 0x0d30 AppIDSvc - ok
17:47:28.0765 0x0d30 [ 7DEAD9E3F65DCB2794F2711003BBF650, F541C30EEFD1BDB70F361B878B6E51DC728873695DD137148CE531FBACCDA21B ] Appinfo C:\Windows\System32\appinfo.dll
17:47:28.0796 0x0d30 Appinfo - ok
17:47:28.0843 0x0d30 [ A45D184DF6A8803DA13A0B329517A64A, C1D16B60A6D69689AE951DC3D6884ED2E233D144B3FC0B86BC1C50AAAAA01ED2 ] AppMgmt C:\Windows\System32\appmgmts.dll
17:47:28.0858 0x0d30 AppMgmt - ok
17:47:28.0874 0x0d30 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys
17:47:28.0889 0x0d30 arc - ok
17:47:28.0921 0x0d30 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
17:47:28.0921 0x0d30 arcsas - ok
17:47:29.0045 0x0d30 [ 776ACEFA0CA9DF0FAA51A5FB2F435705, 72DF7ED6B085BC468994F5B3189506FD726A9A17A9C42ACA1E420D787691361D ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
17:47:29.0045 0x0d30 aspnet_state - ok
17:47:29.0077 0x0d30 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
17:47:29.0108 0x0d30 AsyncMac - ok
17:47:29.0123 0x0d30 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\DRIVERS\atapi.sys
17:47:29.0123 0x0d30 atapi - ok
17:47:29.0186 0x0d30 [ 510C873BFA135AA829F4180352772734, BC528D840EB338B0C5D11801C63D8EADD40AF8043DC77ACB4B42E8D20767538F ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
17:47:29.0217 0x0d30 AudioEndpointBuilder - ok
17:47:29.0233 0x0d30 [ 510C873BFA135AA829F4180352772734, BC528D840EB338B0C5D11801C63D8EADD40AF8043DC77ACB4B42E8D20767538F ] Audiosrv C:\Windows\System32\Audiosrv.dll
17:47:29.0264 0x0d30 Audiosrv - ok
17:47:29.0311 0x0d30 [ DD6A431B43E34B91A767D1CE33728175, 8BFF6474C9DFBEC96FA7B2789EF9B17C7910B52DBCF70CDA1F0C698CFA5EFB6E ] AxInstSV C:\Windows\System32\AxInstSV.dll
17:47:29.0326 0x0d30 AxInstSV - ok
17:47:29.0357 0x0d30 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
17:47:29.0389 0x0d30 b06bdrv - ok
17:47:29.0420 0x0d30 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
17:47:29.0435 0x0d30 b57nd60x - ok
17:47:29.0467 0x0d30 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll
17:47:29.0482 0x0d30 BDESVC - ok
17:47:29.0513 0x0d30 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys
17:47:29.0529 0x0d30 Beep - ok
17:47:29.0607 0x0d30 [ 85AC71C045CEB054ED48A7841AAE0C11, BA0C0CC50E5C49838116AC9A12A7CF1A683601FD08D3CF6EC06620C51C0806FF ] BFE C:\Windows\System32\bfe.dll
17:47:29.0638 0x0d30 BFE - ok
17:47:29.0732 0x0d30 [ 53F476476F55A27F580661BDE09C4EC4, 90DFBF97F011CFF41D2CFA2E33978BC746A7E693AC75EED1436130C4F10B4E67 ] BITS C:\Windows\system32\qmgr.dll
17:47:29.0779 0x0d30 BITS - ok
17:47:29.0794 0x0d30 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
17:47:29.0810 0x0d30 blbdrive - ok
17:47:29.0857 0x0d30 [ FCAFAEF6798D7B51FF029F99A9898961, BFB37686B1386EB883B99DB6AC342C20514939F8B7A5CEC5D63865B3DC2B4D4F ] bowser C:\Windows\system32\DRIVERS\bowser.sys
17:47:29.0872 0x0d30 bowser - ok
17:47:29.0888 0x0d30 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:47:29.0903 0x0d30 BrFiltLo - ok
17:47:29.0903 0x0d30 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:47:29.0919 0x0d30 BrFiltUp - ok
17:47:29.0935 0x0d30 [ 77361D72A04F18809D0EFB6CCEB74D4B, 55E7DB65BB29FF421F138CDFF05E5ECFFC7C8862FAA68F6179A3BA9D6B69AE64 ] BridgeMP C:\Windows\system32\DRIVERS\bridge.sys
17:47:29.0950 0x0d30 BridgeMP - ok
17:47:29.0981 0x0d30 [ 598E1280E7FF3744F4B8329366CC5635, 9B6392AEBE7EF26253487AF8C7C114822ABB187BA32DA8DBF622DB1B8DA6F1C0 ] Browser C:\Windows\System32\browser.dll
17:47:29.0997 0x0d30 Browser - ok
17:47:30.0028 0x0d30 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys
17:47:30.0044 0x0d30 Brserid - ok
17:47:30.0044 0x0d30 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
17:47:30.0075 0x0d30 BrSerWdm - ok
17:47:30.0075 0x0d30 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
17:47:30.0091 0x0d30 BrUsbMdm - ok
17:47:30.0091 0x0d30 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
17:47:30.0106 0x0d30 BrUsbSer - ok
17:47:30.0106 0x0d30 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
17:47:30.0122 0x0d30 BTHMODEM - ok
17:47:30.0153 0x0d30 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll
17:47:30.0184 0x0d30 bthserv - ok
17:47:30.0278 0x0d30 catchme - ok
17:47:30.0309 0x0d30 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
17:47:30.0340 0x0d30 cdfs - ok
17:47:30.0387 0x0d30 [ BA6E70AA0E6091BC39DE29477D866A77, A17A68BDA46995F75FB1C2C593A81CD3B2BFE290CEAA45FA2380DDF5537A23C9 ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
17:47:30.0403 0x0d30 cdrom - ok
17:47:30.0449 0x0d30 [ 628A9E30EC5E18DD5DE6BE4DBDC12198, DDA43DCCB195440D6BD5752BD00D984F45BD6D23DBE2A656C33E3CD1E5D17AD7 ] CertPropSvc C:\Windows\System32\certprop.dll
17:47:30.0481 0x0d30 CertPropSvc - ok
17:47:30.0496 0x0d30 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
17:47:30.0496 0x0d30 circlass - ok
17:47:30.0512 0x0d30 [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS C:\Windows\system32\CLFS.sys
17:47:30.0527 0x0d30 CLFS - ok
17:47:30.0559 0x0d30 [ D88040F816FDA31C3B466F0FA0918F29, 39D3630E623DA25B8444B6D3AAAB16B98E7E289C5619E19A85D47B74C71449F3 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
17:47:30.0559 0x0d30 clr_optimization_v2.0.50727_32 - ok
17:47:30.0637 0x0d30 [ C5A75EB48E2344ABDC162BDA79E16841, 6070A8AAFD38FBC6A68A2B10C20117612354DF21B4492D90CA522BFB6870D726 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
17:47:30.0637 0x0d30 clr_optimization_v4.0.30319_32 - ok
17:47:30.0652 0x0d30 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
17:47:30.0668 0x0d30 CmBatt - ok
17:47:30.0683 0x0d30 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\DRIVERS\cmdide.sys
17:47:30.0699 0x0d30 cmdide - ok
17:47:30.0715 0x0d30 [ 1B675691ED940766149C93E8F4488D68, A55C41B2B343B1CF53D737ED1752D0510052094FFC60FDB833279A8A52398132 ] CNG C:\Windows\system32\Drivers\cng.sys
17:47:30.0746 0x0d30 CNG - ok
17:47:30.0761 0x0d30 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
17:47:30.0761 0x0d30 Compbatt - ok
17:47:30.0793 0x0d30 [ F1724BA27E97D627F808FB0BA77A28A6, F7D69082EEFEC0FB8B309F6AEE282D4A5DFC1A40851ED65904AA9582C5DEA5AB ] CompositeBus C:\Windows\system32\DRIVERS\CompositeBus.sys
17:47:30.0808 0x0d30 CompositeBus - ok
17:47:30.0808 0x0d30 COMSysApp - ok
17:47:30.0933 0x0d30 [ F46FF007508C32788D8D5F32F27C25C7, C93BA43D1AA760005DCE6B10D8209470C1BC442A7AF5208235A709185893DBAC ] CoordinatorServiceHost C:\Program Files\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe
17:47:30.0964 0x0d30 CoordinatorServiceHost - ok
17:47:30.0980 0x0d30 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
17:47:30.0995 0x0d30 crcdisk - ok
17:47:31.0027 0x0d30 [ 9C231178CE4FB385F4B54B0A9080B8A4, 08EFAEBFF68D5CCE432D75116ED4BDC63FEA651459C9AD363CBEEDB769806527 ] CryptSvc C:\Windows\system32\cryptsvc.dll
17:47:31.0058 0x0d30 CryptSvc - ok
17:47:31.0089 0x0d30 [ 27C9490BDD0AE48911AB8CF1932591ED, 751F576F797F8A7BA576C32598BD6FD2E60D4FACC7836CC5BA3F68C38D27CCCA ] CSC C:\Windows\system32\drivers\csc.sys
17:47:31.0120 0x0d30 CSC - ok
17:47:31.0151 0x0d30 [ 56FB5F222EA30D3D3FC459879772CB73, 2C4646774575858E26DBA9C73853E06D0BD18CC8A4C73C633071FF5FE04CA0F4 ] CscService C:\Windows\System32\cscsvc.dll
17:47:31.0167 0x0d30 CscService - ok
17:47:31.0214 0x0d30 [ B82CD39E336973359D7C9BF911E8E84F, 45DB8F1E88FC25A81D2F3C2F8A8CDB6B34C44950B038E24FB71DCDD9823DB22A ] DcomLaunch C:\Windows\system32\rpcss.dll
17:47:31.0245 0x0d30 DcomLaunch - ok
17:47:31.0276 0x0d30 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll
17:47:31.0323 0x0d30 defragsvc - ok
17:47:31.0354 0x0d30 [ 8E09E52EE2E3CEB199EF3DD99CF9E3FB, B03D0CF11C1D0DCBB76E74D796F3AFA2F9598C918017C29670BED4E3A9962EF5 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
17:47:31.0385 0x0d30 DfsC - ok
17:47:31.0432 0x0d30 [ C56495FBD770712367CAD35E5DE72DA6, 9D5456A2E208F542F0B6C951EFCABA2A10919777C4287D7298A28F543D5BAC32 ] Dhcp C:\Windows\system32\dhcpcore.dll
17:47:31.0463 0x0d30 Dhcp - ok
17:47:31.0479 0x0d30 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys
17:47:31.0510 0x0d30 discache - ok
17:47:31.0541 0x0d30 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys
17:47:31.0541 0x0d30 Disk - ok
17:47:31.0573 0x0d30 [ D0722E963D3C6145446874241401B209, 542B3E6EC7E0161AB4732380343139959775E749996A97684A5D423833DDB196 ] Dnscache C:\Windows\System32\dnsrslvr.dll
17:47:31.0604 0x0d30 Dnscache - ok
17:47:31.0619 0x0d30 [ 4408C85C21EEA48EB0CE486BAEEF0502, 67EA726F4053665D94D7790EC89616EA0698A7548073A9211E3F75937B4384BE ] dot3svc C:\Windows\System32\dot3svc.dll
17:47:31.0651 0x0d30 dot3svc - ok
17:47:31.0682 0x0d30 [ 7FA81C6E11CAA594ADB52084DA73A1E5, 9ED1C585D9CA091E75E4A2A1E5B923B104EBDC5FC9D12154DE909C583E4D0CAE ] DPS C:\Windows\system32\dps.dll
17:47:31.0713 0x0d30 DPS - ok
17:47:31.0744 0x0d30 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
17:47:31.0760 0x0d30 drmkaud - ok
17:47:31.0791 0x0d30 [ 687AF6BB383885FF6A64071B189A7F3E, 1C751B8DD27F63E88D0223A8434CED7589AC00EC6275938C59D1B954F0354F78 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
17:47:40.0090 0x0d30 dtsoftbus01 - ok
17:47:40.0137 0x0d30 [ 39806CFEDDCC55E686A49BCCD2972F23, EFD5816D3E8E7F0F8D8E52AB9C534737F32D2D6D3EACCA78940792C553881C64 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
17:47:40.0184 0x0d30 DXGKrnl - ok
17:47:40.0231 0x0d30 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll
17:47:40.0262 0x0d30 EapHost - ok
17:47:40.0371 0x0d30 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
17:47:40.0496 0x0d30 ebdrv - ok
17:47:40.0511 0x0d30 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] EFS C:\Windows\System32\lsass.exe
17:47:40.0527 0x0d30 EFS - ok
17:47:40.0543 0x0d30 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
17:47:40.0574 0x0d30 elxstor - ok
17:47:40.0589 0x0d30 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\DRIVERS\errdev.sys
17:47:40.0605 0x0d30 ErrDev - ok
17:47:40.0652 0x0d30 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll
17:47:40.0683 0x0d30 EventSystem - ok
17:47:40.0730 0x0d30 [ 57C171EA22F0A7F068FCB0CAEDD1E8E7, 9AAF39AA22372FB8582C1422581C08E61444BF843E1CE2E199EB00FBEA6F9C06 ] ew_hwusbdev C:\Windows\system32\DRIVERS\ew_hwusbdev.sys
17:47:40.0745 0x0d30 ew_hwusbdev - ok
17:47:40.0777 0x0d30 [ 61A973F60E94A551BA7B15F3460444FB, FC2FB69978D99D75673AFE9F08176F3139DCBAEDE4D339BD09DA29CD3EC01005 ] ew_usbenumfilter C:\Windows\system32\DRIVERS\ew_usbenumfilter.sys
17:47:40.0808 0x0d30 ew_usbenumfilter - ok
17:47:40.0823 0x0d30 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys
17:47:40.0855 0x0d30 exfat - ok
17:47:40.0870 0x0d30 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys
17:47:40.0901 0x0d30 fastfat - ok
17:47:40.0948 0x0d30 [ F7EA23CC5E6BF2181F3F399D54F6EFC1, 4659A2EDC5D5171668FB20BED7B56466A674876888519D6F524F7456EBD11263 ] Fax C:\Windows\system32\fxssvc.exe
17:47:40.0995 0x0d30 Fax - ok
17:47:41.0011 0x0d30 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
17:47:41.0011 0x0d30 fdc - ok
17:47:41.0026 0x0d30 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll
17:47:41.0057 0x0d30 fdPHost - ok
17:47:41.0073 0x0d30 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll
17:47:41.0104 0x0d30 FDResPub - ok
17:47:41.0120 0x0d30 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
17:47:41.0120 0x0d30 FileInfo - ok
17:47:41.0151 0x0d30 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
17:47:41.0198 0x0d30 Filetrace - ok
17:47:41.0323 0x0d30 [ 73081CF28F0AE20A52CA4F67CEE6E6B0, 806C769F3638D25FF1892C7223E7250AA3B9F627DF3AD83BC5AE1FEF7016F86A ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
17:47:41.0354 0x0d30 FLEXnet Licensing Service - ok
17:47:41.0369 0x0d30 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
17:47:41.0385 0x0d30 flpydisk - ok
17:47:41.0463 0x0d30 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
17:47:41.0494 0x0d30 FltMgr - ok
17:47:41.0525 0x0d30 [ B6512A85815FDC3D560C3705F5BDB93D, A04D60BF4649DD7582C0E26E9CED93841D8B2729FDF6E1551F48A94AFD5A6436 ] FontCache C:\Windows\system32\FntCache.dll
17:47:41.0572 0x0d30 FontCache - ok
17:47:41.0603 0x0d30 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
17:47:41.0603 0x0d30 FontCache3.0.0.0 - ok
17:47:41.0619 0x0d30 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
17:47:41.0635 0x0d30 FsDepends - ok
17:47:41.0635 0x0d30 [ A574B4360E438977038AAE4BF60D79A2, 7255CCDDDAC4853FA72E6487408C4B7390CBA37549CE952929B2A9CF3327C616 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
17:47:41.0650 0x0d30 Fs_Rec - ok
17:47:41.0681 0x0d30 [ 5592F5DBA26282D24D2B080EB438A4D7, 5376D6CFFE9A1406CFA0BF4325EB65206F57A5C50034DA7EB4238BEB08D4D6DB ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
17:47:41.0697 0x0d30 fvevol - ok
17:47:41.0713 0x0d30 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
17:47:41.0713 0x0d30 gagp30kx - ok
17:47:41.0744 0x0d30 [ 8BA3C04702BF8F927AB36AE8313CA4EE, 3B6460C8134AA9D6E4FB978201B35FE9B67DD5BBB6C8D9625F3097DDA30C2893 ] gpsvc C:\Windows\System32\gpsvc.dll
17:47:41.0775 0x0d30 gpsvc - ok
17:47:41.0791 0x0d30 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
17:47:41.0806 0x0d30 hcw85cir - ok
17:47:41.0853 0x0d30 [ 3530CAD25DEBA7DC7DE8BB51632CBC5F, 6706B8AD211A4B89B6571ACD227412026EAD87D71456B3EC6E7DD8FA15B997BE ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
17:47:41.0884 0x0d30 HdAudAddService - ok
17:47:41.0915 0x0d30 [ 717A2207FD6F13AD3E664C7D5A43C7BF, BF28A6F00B64FA0E801493E3289CFFD5E313E724DF7B5AB521C9E37A20890DCF ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys
17:47:41.0931 0x0d30 HDAudBus - ok
17:47:41.0947 0x0d30 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
17:47:41.0962 0x0d30 HidBatt - ok
17:47:41.0962 0x0d30 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
17:47:41.0978 0x0d30 HidBth - ok
17:47:41.0993 0x0d30 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
17:47:42.0009 0x0d30 HidIr - ok
17:47:42.0025 0x0d30 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\System32\hidserv.dll
17:47:42.0071 0x0d30 hidserv - ok
17:47:42.0087 0x0d30 [ 25072FB35AC90B25F9E4E3BACF774102, EBCE089947CC5A251A517CB91E81FCB948B18405FBACA04C874D4A48AF88676D ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
17:47:42.0103 0x0d30 HidUsb - ok
17:47:42.0118 0x0d30 [ 741C2A45CA8407E374AABA3E330B7872, FCF31C46297CFDF8240F0E783A61C8463FEDB1EF7A676AB89DFF0EAE9F3534B4 ] hkmsvc C:\Windows\system32\kmsvc.dll
17:47:42.0149 0x0d30 hkmsvc - ok
17:47:42.0181 0x0d30 [ A768CA158BB06782A2835B907F4873C3, EFF736C6BA38FB8FC8807286AB273E7274F505E8E59D952E8563DF77C412C5AE ] HomeGroupListener C:\Windows\system32\ListSvc.dll
17:47:42.0196 0x0d30 HomeGroupListener - ok
17:47:42.0227 0x0d30 [ FB08DEC5EF43D0C66D83B8E9694E7549, 9C9ECE9E90F524791FC5DCE797BAE39605F966592126FF058BA3FA0BEFD07BEB ] HomeGroupProvider C:\Windows\system32\provsvc.dll
17:47:42.0243 0x0d30 HomeGroupProvider - ok
17:47:42.0259 0x0d30 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\DRIVERS\HpSAMD.sys
17:47:42.0274 0x0d30 HpSAMD - ok
17:47:42.0305 0x0d30 [ C531C7FD9E8B62021112787C4E2C5A5A, 09205E2A5BFB6C623B312B8AC82F7F7CA8A922B1D9A0E3952BD3BA47BBE1F18C ] HTTP C:\Windows\system32\drivers\HTTP.sys
17:47:42.0337 0x0d30 HTTP - ok
17:47:42.0368 0x0d30 [ FB572C3FC151C308D1DC3A99954D97B7, 86AB7C90E0375A546C305548716DD40E76F619A2FDD5F178F0BA0C171D3F445B ] huawei_cdcacm C:\Windows\system32\DRIVERS\ew_jucdcacm.sys
17:47:42.0383 0x0d30 huawei_cdcacm - ok
17:47:42.0415 0x0d30 [ 00B363D211909FB85BC6300A3214AC03, C971B95187233131C42A10F4B86760810FF0B4D1938D96B918794C31707FE8D7 ] huawei_enumerator C:\Windows\system32\DRIVERS\ew_jubusenum.sys
17:47:42.0446 0x0d30 huawei_enumerator - ok
17:47:42.0446 0x0d30 [ 7B1DED0BE9A4203857AB0DED695983E6, 7B3611CEE17210E940D0E2F9E6CFFE7F907202B614DC27253D347A1237F67102 ] huawei_ext_ctrl C:\Windows\system32\DRIVERS\ew_juextctrl.sys
17:47:42.0461 0x0d30 huawei_ext_ctrl - ok
17:47:42.0477 0x0d30 [ 189AC9CB8630FAEB1DCAE2F97B8FF98C, 99120000693624B72A31D3281BEB93B0E8A074CD2FCCE08AE27D8A5E18AC351D ] huawei_wwanecm C:\Windows\system32\DRIVERS\ew_juwwanecm.sys
17:47:42.0508 0x0d30 huawei_wwanecm - ok
17:47:42.0555 0x0d30 [ 1C09309A3D793C57EF87AC60C6BBD739, DBC453F8B58CA7DB75E5771695EE0A011E536C2805341DFEEE91B02821B52972 ] hwdatacard C:\Windows\system32\DRIVERS\ewusbmdm.sys
17:47:42.0602 0x0d30 hwdatacard - ok
17:47:42.0617 0x0d30 [ 8305F33CDE89AD6C7A0763ED0B5A8D42, A7CA4978DC1FF6105EA39124DF854F0B1FD478476B871ED0E018AF3AE2165282 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
17:47:42.0633 0x0d30 hwpolicy - ok
17:47:42.0664 0x0d30 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys
17:47:42.0695 0x0d30 i8042prt - ok
17:47:42.0727 0x0d30 [ 934AF4D7C5F457B9F0743F4299B77B67, F232554352BB7CD716D6173FC1AB2661E49480994BB22E9A6FE7A33B51F0A51B ] iaStorV C:\Windows\system32\DRIVERS\iaStorV.sys
17:47:42.0742 0x0d30 iaStorV - ok
17:47:42.0836 0x0d30 [ 5AF815EB5BC9802E5A064E2BA62BFC0C, DC8CED05F623D30C57E8A7A382A219B4266C9C766ABF8A8D71783EACB8607B82 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
17:47:42.0867 0x0d30 idsvc - ok
17:47:42.0883 0x0d30 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
17:47:42.0883 0x0d30 iirsp - ok
17:47:42.0929 0x0d30 [ FAC0EE6562B121B1399D6E855583F7A5, 034C9EE9232EB2CE64297EC4BCBEB5DA443ED9176C436CC754EF84FFB4AD4B08 ] IKEEXT C:\Windows\System32\ikeext.dll
17:47:42.0976 0x0d30 IKEEXT - ok
17:47:43.0007 0x0d30 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\DRIVERS\intelide.sys
17:47:43.0007 0x0d30 intelide - ok
17:47:43.0039 0x0d30 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
17:47:43.0054 0x0d30 intelppm - ok
17:47:43.0070 0x0d30 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
17:47:43.0085 0x0d30 IPBusEnum - ok
17:47:43.0117 0x0d30 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:47:43.0132 0x0d30 IpFilterDriver - ok
17:47:43.0179 0x0d30 [ 477397B432A256A50EE7E4339EB9EA14, 3722938E69D16962F773F39669E9B90279DC9527BBC63564B33C89DAFD283497 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
17:47:43.0241 0x0d30 iphlpsvc - ok
17:47:43.0241 0x0d30 [ E4454B6C37D7FFD5649611F6496308A7, 5B2AA8C06076C9A1FF944E5EA07C29BA7FABEBB38E6BFB388ED46933EAC465FB ] IPMIDRV C:\Windows\system32\DRIVERS\IPMIDrv.sys
17:47:43.0257 0x0d30 IPMIDRV - ok
17:47:43.0273 0x0d30 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
17:47:43.0304 0x0d30 IPNAT - ok
17:47:43.0319 0x0d30 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys
17:47:43.0335 0x0d30 IRENUM - ok
17:47:43.0366 0x0d30 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\DRIVERS\isapnp.sys
17:47:43.0366 0x0d30 isapnp - ok
17:47:43.0382 0x0d30 [ ED46C223AE46C6866AB77CDC41C404B7, 1B2A4A3FF0E5F8F02717F20983D57612D62DFF809064A7E524700E7254BB7DB3 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys
17:47:43.0397 0x0d30 iScsiPrt - ok
17:47:43.0429 0x0d30 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
17:47:43.0429 0x0d30 kbdclass - ok
17:47:43.0444 0x0d30 [ 3D9F0EBF350EDCFD6498057301455964, B3CB5F0C045B06C86E683F3C67DC0D4E37AF16E20B189B05C926A5A7011438FB ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
17:47:43.0460 0x0d30 kbdhid - ok
17:47:43.0475 0x0d30 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] KeyIso C:\Windows\system32\lsass.exe
17:47:43.0475 0x0d30 KeyIso - ok
17:47:43.0631 0x0d30 [ 9249D2ACEC11F8958E0FCA436C5630BD, DB07B8A535179C1DF7C083BEE27822F9E7BB0E7E49E02CF9401106FE5C21F457 ] Kodak AiO Network Discovery Service C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
17:47:43.0647 0x0d30 Kodak AiO Network Discovery Service - ok
17:47:43.0663 0x0d30 [ E36A061EC11B373826905B21BE10948F, CB9F8B76E0A99307A841B66CBD96C7087CC0B068699CBEF01040E37C6EA60E6A ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
17:47:43.0694 0x0d30 KSecDD - ok
17:47:43.0725 0x0d30 [ 26C046977E85B95036453D7B88BA1820, 375B284AFB407CAE417D2090B112A0ED1CCD516ABFDDBFCD5D6AADE859F14ACD ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
17:47:43.0741 0x0d30 KSecPkg - ok
17:47:43.0772 0x0d30 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll
17:47:43.0819 0x0d30 KtmRm - ok
17:47:43.0865 0x0d30 [ BCA92CB047A4326925ECEF759DBAA233, C2A188F5526882A2E3AC4CC0190452DA37CBD93043DFE5571A20E8EFE9D56DA3 ] LanmanServer C:\Windows\System32\srvsvc.dll
17:47:43.0897 0x0d30 LanmanServer - ok
17:47:43.0912 0x0d30 [ B9891F885DCF1F0513A51CB58493CB1F, C883D243E1E7B7AEA031FB90FE4FCEED631F835DC95F9D9D60BC554E6EC358C2 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
17:47:43.0928 0x0d30 LanmanWorkstation - ok
17:47:43.0975 0x0d30 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
17:47:43.0990 0x0d30 lltdio - ok
17:47:44.0006 0x0d30 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll
17:47:44.0037 0x0d30 lltdsvc - ok
17:47:44.0053 0x0d30 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll
17:47:44.0099 0x0d30 lmhosts - ok
17:47:44.0131 0x0d30 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
17:47:44.0146 0x0d30 LSI_FC - ok
17:47:44.0162 0x0d30 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
17:47:44.0162 0x0d30 LSI_SAS - ok
17:47:44.0177 0x0d30 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:47:44.0177 0x0d30 LSI_SAS2 - ok
17:47:44.0193 0x0d30 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:47:44.0209 0x0d30 LSI_SCSI - ok
17:47:44.0240 0x0d30 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys
17:47:44.0271 0x0d30 luafv - ok
17:47:44.0271 0x0d30 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
17:47:44.0287 0x0d30 megasas - ok
17:47:44.0302 0x0d30 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
17:47:44.0318 0x0d30 MegaSR - ok
17:47:44.0411 0x0d30 [ 033B947AF4A997820E86FCB070B1F450, 2F54F9D1E8374187B2F206E7CF22A907C735C71F38445A94BDC84E83081D3A88 ] Microsoft Office Groove Audit Service C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe
17:47:44.0411 0x0d30 Microsoft Office Groove Audit Service - ok
17:47:44.0443 0x0d30 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll
17:47:44.0458 0x0d30 MMCSS - ok
17:47:44.0474 0x0d30 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys
17:47:44.0489 0x0d30 Modem - ok
17:47:44.0521 0x0d30 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
17:47:44.0536 0x0d30 monitor - ok
17:47:44.0552 0x0d30 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
17:47:44.0567 0x0d30 mouclass - ok
17:47:44.0583 0x0d30 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
17:47:44.0599 0x0d30 mouhid - ok
17:47:44.0614 0x0d30 [ 921C18727C5920D6C0300736646931C2, 19ACE502982E9C5B0134676102EAEE96675C9CA237E410DB36C389D6B4078301 ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
17:47:44.0614 0x0d30 mountmgr - ok
17:47:44.0692 0x0d30 [ 0329A45C849C9D77901094B8FFE8BBB9, 2151C15A4185FABBC3367B8213017B45E08C43E26E1D8942E707E217C6A5EDA7 ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
17:47:44.0692 0x0d30 MozillaMaintenance - ok
17:47:44.0723 0x0d30 [ 2AF5997438C55FB79D33D015C30E1974, E8F048A02FEB400C133D0BFC1659921E73B59549E3F7D2A13929901B87A1901F ] mpio C:\Windows\system32\DRIVERS\mpio.sys
17:47:44.0739 0x0d30 mpio - ok
17:47:44.0770 0x0d30 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
17:47:44.0786 0x0d30 mpsdrv - ok
17:47:44.0879 0x0d30 [ 5CD996CECF45CBC3E8D109C86B82D69E, ABE40DA4DA555D3D5054BE28BF82E775D90DCB9E31409DC95FABF2F016B17700 ] MpsSvc C:\Windows\system32\mpssvc.dll
17:47:44.0926 0x0d30 MpsSvc - ok
17:47:44.0957 0x0d30 [ B1BE47008D20E43DA3ADC37C24CDB89D, 6E8555E84B42E5098227B35EA5ABADF2CD3AC247B37CB9E9304FF67064EBE59B ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
17:47:44.0957 0x0d30 MRxDAV - ok
17:47:44.0989 0x0d30 [ F4A054BE78AF7F410129C4B64B07DC9B, 65E14D38CCAB4FBB0C0D4A12F11B2E150AEC00AC692EE92A5CE6C982CF1190F5 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
17:47:45.0020 0x0d30 mrxsmb - ok
17:47:45.0035 0x0d30 [ DEFFA295BD1895C6ED8E3078412AC60B, 3F13CD67659EC2C8ABADC2C5B48B939ECDC6DB7CAAAAC3C2823AC12842BC1630 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:47:45.0067 0x0d30 mrxsmb10 - ok
17:47:45.0082 0x0d30 [ 24D76ABE5DCAD22F19D105F76FDF0CE1, D0A7E033B4DF4AA5A9600A2A7A890FDE20AC7CE87C660817EB92FE10E2DAD343 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:47:45.0098 0x0d30 mrxsmb20 - ok
17:47:45.0113 0x0d30 [ 4326D168944123F38DD3B2D9C37A0B12, 322AE93418BE3BA6B3E11C86431EC3F4B23CADC3B968B92978A08A7C0D0D8902 ] msahci C:\Windows\system32\DRIVERS\msahci.sys
17:47:45.0129 0x0d30 msahci - ok
17:47:45.0145 0x0d30 [ 455029C7174A2DBB03DBA8A0D8BDDD9A, 614D71978B024109ADD9A7A74F74ABD5FAA1C36A2E859AF288398EAE7CD76DF2 ] msdsm C:\Windows\system32\DRIVERS\msdsm.sys
17:47:45.0145 0x0d30 msdsm - ok
17:47:45.0160 0x0d30 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe
17:47:45.0191 0x0d30 MSDTC - ok
17:47:45.0223 0x0d30 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys
17:47:45.0238 0x0d30 Msfs - ok
17:47:45.0238 0x0d30 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
17:47:45.0269 0x0d30 mshidkmdf - ok
17:47:45.0285 0x0d30 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\DRIVERS\msisadrv.sys
17:47:45.0285 0x0d30 msisadrv - ok
17:47:45.0332 0x0d30 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
17:47:45.0379 0x0d30 MSiSCSI - ok
17:47:45.0394 0x0d30 msiserver - ok
17:47:45.0425 0x0d30 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
17:47:45.0441 0x0d30 MSKSSRV - ok
17:47:45.0457 0x0d30 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
17:47:45.0472 0x0d30 MSPCLOCK - ok
17:47:45.0472 0x0d30 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
17:47:45.0503 0x0d30 MSPQM - ok
17:47:45.0519 0x0d30 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
17:47:45.0535 0x0d30 MsRPC - ok
17:47:45.0550 0x0d30 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys
17:47:45.0550 0x0d30 mssmbios - ok
17:47:45.0566 0x0d30 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
17:47:45.0581 0x0d30 MSTEE - ok
17:47:45.0753 0x0d30 [ 73FA09B84B23A1897809A84F976D5D99, 8ADBEE035DF08DB860D56597C88230F4ECE80B214A13AF22D5D5475C9B7FEFC1 ] msvsmon80 C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe
17:47:45.0847 0x0d30 msvsmon80 - ok
17:47:45.0862 0x0d30 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
17:47:45.0878 0x0d30 MTConfig - ok
17:47:45.0909 0x0d30 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys
17:47:45.0909 0x0d30 Mup - ok
17:47:45.0940 0x0d30 [ 80284F1985C70C86F0B5F86DA2DFE1DF, 424A5BBC28C72DA0DBABEB9E423B8C409754CD1BA3DFC9E174BF22D8BCE1BE63 ] napagent C:\Windows\system32\qagentRT.dll
17:47:45.0956 0x0d30 napagent - ok
17:47:46.0003 0x0d30 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
17:47:46.0034 0x0d30 NativeWifiP - ok
17:47:46.0065 0x0d30 [ 23759D175A0A9BAAF04D05047BC135A8, 2C8C553B4E1ED3A644F619F16BCEDD5A3C6D74A17E6E75A3E740E06B1D636348 ] NDIS C:\Windows\system32\drivers\ndis.sys
17:47:46.0096 0x0d30 NDIS - ok
17:47:46.0096 0x0d30 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
17:47:46.0127 0x0d30 NdisCap - ok
17:47:46.0159 0x0d30 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
17:47:46.0174 0x0d30 NdisTapi - ok
17:47:46.0205 0x0d30 [ B30AE7F2B6D7E343B0DF32E6C08FCE75, 39BBBF7AF886732CB9ED3E6C06DA4318554089F3BEA74C74328FE1C6EF68E70B ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
17:47:46.0221 0x0d30 Ndisuio - ok
17:47:46.0237 0x0d30 [ 267C415EADCBE53C9CA873DEE39CF3A4, BAA8626BDA7B68176B19A99FBBD40FB2A774C8F44B56F9FFB99A1F5C16A1C555 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
17:47:46.0268 0x0d30 NdisWan - ok
17:47:46.0283 0x0d30 [ AF7E7C63DCEF3F8772726F86039D6EB4, 1CFDED48E8844138864786DBF9D5519162A6DB28F885A781934E8AFBD52EAC50 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
17:47:46.0299 0x0d30 NDProxy - ok
17:47:46.0315 0x0d30 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
17:47:46.0330 0x0d30 NetBIOS - ok
17:47:46.0346 0x0d30 [ DD52A733BF4CA5AF84562A5E2F963B91, 5CEB9664CED3D120F5408A12035748728710D41090A289CF66023CED4C838A1F ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
17:47:46.0361 0x0d30 NetBT - ok
17:47:46.0377 0x0d30 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] Netlogon C:\Windows\system32\lsass.exe
17:47:46.0377 0x0d30 Netlogon - ok
17:47:46.0408 0x0d30 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll
17:47:46.0439 0x0d30 Netman - ok
17:47:46.0502 0x0d30 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:47:46.0517 0x0d30 NetMsmqActivator - ok
17:47:46.0533 0x0d30 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:47:46.0533 0x0d30 NetPipeActivator - ok
17:47:46.0549 0x0d30 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll
17:47:46.0580 0x0d30 netprofm - ok
17:47:46.0595 0x0d30 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:47:46.0595 0x0d30 NetTcpActivator - ok
17:47:46.0611 0x0d30 [ D22CD77D4F0D63D1169BB35911BFF12D, 85B1FDFA02E1B8EA4FCB9B7EEB687C5C448697FC7EC9D178C5A2F64D2C9CFEE8 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
17:47:46.0611 0x0d30 NetTcpPortSharing - ok
17:47:46.0642 0x0d30 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
17:47:46.0658 0x0d30 nfrd960 - ok
17:47:46.0689 0x0d30 [ 2226496E34BD40734946A054B1CD657F, 98392D98C9213822268971432BB55047ABD8B4EBD42483FA69BF50FB8FAD64A2 ] NlaSvc C:\Windows\System32\nlasvc.dll
17:47:46.0736 0x0d30 NlaSvc - ok
17:47:46.0751 0x0d30 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys
17:47:46.0798 0x0d30 Npfs - ok
17:47:46.0814 0x0d30 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll
17:47:46.0845 0x0d30 nsi - ok
17:47:46.0861 0x0d30 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
17:47:46.0892 0x0d30 nsiproxy - ok
17:47:46.0923 0x0d30 [ 3795DCD21F740EE799FB7223234215AF, B03DBFD33B201134473D23038E0BD86CFE64556754BF4EBA42C10B67AEECAEA6 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
17:47:46.0954 0x0d30 Ntfs - ok
17:47:46.0970 0x0d30 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys
17:47:46.0985 0x0d30 Null - ok
17:47:47.0875 0x0d30 [ AFB33A823AABC112FC7BD62AFBCDB0CD, B267AA94024363B1C4A26D853094F84895D7EA232B8A6690C315D99D3D4C79BD ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:47:48.0093 0x0d30 nvlddmkm - ok
17:47:48.0202 0x0d30 [ 3F3D04B1D08D43C16EA7963954EC768D, BA82C1D3D9F4AA5F1C9729D61D4E06DB961FDF2B1E9B483D29DB308204DF0754 ] nvraid C:\Windows\system32\DRIVERS\nvraid.sys
17:47:48.0249 0x0d30 nvraid - ok
17:47:48.0265 0x0d30 [ C99F251A5DE63C6F129CF71933ACED0F, 24D48A5F5D699AB0DD4D4435F8F7C6B73A924AEF8F9D1170FD644E26499546A2 ] nvstor C:\Windows\system32\DRIVERS\nvstor.sys
17:47:48.0280 0x0d30 nvstor - ok
17:47:48.0327 0x0d30 [ 782945716AD010AC3D41758E8E52C735, 5A2B869B697D5BCD31F59BF39E3B0C8C570DD01B1FC82063CD9530F2FC49C7D6 ] nvsvc C:\Windows\system32\nvvsvc.exe
17:47:48.0358 0x0d30 nvsvc - ok
17:47:48.0405 0x0d30 [ A974E5C310B9B00894070CEB055D467F, 37246487C0F38EE2F2F1892D7E4FF9742D2E4C5EC8185D8A0C3CACB23AF6D625 ] nvUpdatusService C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
17:47:48.0483 0x0d30 nvUpdatusService - ok
17:47:48.0514 0x0d30 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\DRIVERS\nv_agp.sys
17:47:48.0530 0x0d30 nv_agp - ok
17:47:48.0639 0x0d30 [ E54AA592A65F317390EEE386A8821692, 7997F8C07802F6C49F06620B35C4C382ADD5419EA8BE02CD7AF0F2EF42A93E53 ] odserv C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE
17:47:48.0670 0x0d30 odserv - ok
17:47:48.0701 0x0d30 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys
17:47:48.0733 0x0d30 ohci1394 - ok
17:47:48.0764 0x0d30 [ 5A432A042DAE460ABE7199B758E8606C, 6E5D1F477D290905BE27CEBF9572BAC6B05FFEF2FAD901D3C8E11F665F8B9A71 ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
17:47:48.0779 0x0d30 ose - ok
17:47:48.0811 0x0d30 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
17:47:48.0842 0x0d30 p2pimsvc - ok
17:47:48.0857 0x0d30 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll
17:47:48.0873 0x0d30 p2psvc - ok
17:47:48.0889 0x0d30 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys
17:47:48.0889 0x0d30 Parport - ok
17:47:48.0904 0x0d30 [ FF4218952B51DE44FE910953A3E686B9, 871E4F8300AFE2AE770B8F00C12911A08D8BBD8E07C37A11AFF67CA92607A602 ] partmgr C:\Windows\system32\drivers\partmgr.sys
17:47:48.0904 0x0d30 partmgr - ok
17:47:48.0951 0x0d30 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
17:47:48.0967 0x0d30 Parvdm - ok
17:47:49.0013 0x0d30 [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc C:\Windows\System32\pcasvc.dll
17:47:49.0029 0x0d30 PcaSvc - ok
17:47:49.0060 0x0d30 [ C858CB77C577780ECC456A892E7E7D0F, 21AE545B736739DE5A7B02CF227516BA6D02B1AAAECD8CC516CCF9F1FD710BCF ] pci C:\Windows\system32\DRIVERS\pci.sys
17:47:49.0060 0x0d30 pci - ok
17:47:49.0076 0x0d30 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\DRIVERS\pciide.sys
17:47:49.0076 0x0d30 pciide - ok
17:47:49.0091 0x0d30 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
17:47:49.0107 0x0d30 pcmcia - ok
17:47:49.0123 0x0d30 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
17:47:49.0123 0x0d30 pcw - ok
17:47:49.0169 0x0d30 [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
17:47:49.0232 0x0d30 PEAUTH - ok
17:47:49.0294 0x0d30 [ AF4D64D2A57B9772CF3801950B8058A6, C9C493A3775E6E1660CE5DF75DA574D0C04245FB88CF41B96217A725359C350D ] PeerDistSvc C:\Windows\system32\peerdistsvc.dll
17:47:49.0341 0x0d30 PeerDistSvc - ok
17:47:49.0497 0x0d30 [ 9C1BFF7910C89A1D12E57343475840CB, 62E00E1278BD263B2AC8CB803C31F2818C54DB143C49470FAD07731E04BD2DE3 ] pla C:\Windows\system32\pla.dll
17:47:49.0606 0x0d30 pla - ok
17:47:49.0684 0x0d30 [ 2CC2008F1296968FBA162ED9F9AFE328, 670E2BE4EB8210C9D6AEA635DFA20E390936762A22B2BB413BF9C7AF418150D6 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
17:47:49.0747 0x0d30 PlugPlay - ok
17:47:49.0747 0x0d30 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
17:47:49.0762 0x0d30 PNRPAutoReg - ok
17:47:49.0778 0x0d30 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
17:47:49.0793 0x0d30 PNRPsvc - ok
17:47:49.0840 0x0d30 [ 48E1B75C6DC0232FD92BAAE4BD344721, 5BA4EB5A60725836D8085EABF87F51160BA57E318A0C4378410217911A393CE7 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
17:47:49.0887 0x0d30 PolicyAgent - ok
17:47:49.0903 0x0d30 [ DBFF83F709A91049621C1D35DD45C92C, 0A722A44F431CAB5EA77FF5F25EB6975C2111B605564FF9FB59751067E7CD3A7 ] Power C:\Windows\system32\umpo.dll
17:47:49.0934 0x0d30 Power - ok
17:47:49.0965 0x0d30 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
17:47:49.0981 0x0d30 PptpMiniport - ok
17:47:49.0996 0x0d30 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys
17:47:50.0012 0x0d30 Processor - ok
17:47:50.0059 0x0d30 [ 630CF26F0227498B7D5A92B12548960F, 7B6E2A3C398DF2E8F63C03ED5B59BB8DA47D5C1ACA9F37438F71F35633ACD6CD ] ProfSvc C:\Windows\system32\profsvc.dll
17:47:50.0074 0x0d30 ProfSvc - ok
17:47:50.0090 0x0d30 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] ProtectedStorage C:\Windows\system32\lsass.exe
17:47:50.0090 0x0d30 ProtectedStorage - ok
17:47:50.0137 0x0d30 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
17:47:50.0152 0x0d30 Psched - ok
17:47:50.0199 0x0d30 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
17:47:50.0261 0x0d30 ql2300 - ok
17:47:50.0293 0x0d30 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
17:47:50.0293 0x0d30 ql40xx - ok
17:47:50.0324 0x0d30 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
17:47:50.0355 0x0d30 QWAVE - ok
17:47:50.0371 0x0d30 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
17:47:50.0386 0x0d30 QWAVEdrv - ok
17:47:50.0386 0x0d30 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
17:47:50.0417 0x0d30 RasAcd - ok
17:47:50.0449 0x0d30 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
17:47:50.0480 0x0d30 RasAgileVpn - ok
17:47:50.0480 0x0d30 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
17:47:50.0511 0x0d30 RasAuto - ok
17:47:50.0527 0x0d30 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
17:47:50.0542 0x0d30 Rasl2tp - ok
17:47:50.0589 0x0d30 [ 0CE66EC736B7FC526D78F7624C7D2A94, D70B45AA413691CF84B24E966EBA1689955E54BDDA206380CAB7CD50F56D5CEB ] RasMan C:\Windows\System32\rasmans.dll
17:47:50.0605 0x0d30 RasMan - ok
17:47:50.0620 0x0d30 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
17:47:50.0636 0x0d30 RasPppoe - ok
17:47:50.0651 0x0d30 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
17:47:50.0667 0x0d30 RasSstp - ok
17:47:50.0683 0x0d30 [ 835D7E81BF517A3B72384BDCC85E1CE6, DC855AF17150C1B27926293115C01B5E1FD00FABCE18AFAEAB3DC68BDE4C908B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
17:47:50.0714 0x0d30 rdbss - ok
17:47:50.0714 0x0d30 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
17:47:50.0729 0x0d30 rdpbus - ok
17:47:50.0745 0x0d30 [ 1E016846895B15A99F9A176A05029075, 78AE674B6E7D3A69099B24AC07E06563A4C867F9DCD8548E4DAAE6FC5ACA4E29 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
17:47:50.0761 0x0d30 RDPCDD - ok
17:47:50.0823 0x0d30 [ C5FF95883FFEF704D50C40D21CFB3AB5, 26CC53DDE126A6BD99F606695F063BB7FDC4BBABB9F75F7AD7A84B58C837EEAA ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
17:47:50.0839 0x0d30 RDPDR - ok
17:47:50.0870 0x0d30 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
17:47:50.0901 0x0d30 RDPENCDD - ok
17:47:50.0901 0x0d30 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
17:47:50.0932 0x0d30 RDPREFMP - ok
17:47:50.0948 0x0d30 [ 801371BA9782282892D00AADB08EE367, 884DDC24B8400E76F65F54C249053333AD29543224F9EC156C64A6BDF584DDCD ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
17:47:50.0979 0x0d30 RDPWD - ok
17:47:51.0010 0x0d30 [ 4EA225BF1CF05E158853F30A99CA29A7, F211480F13E2FE36C31110AE67ABE74E9D572D3A36BEEDE29E14ECBD8C246878 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
17:47:51.0010 0x0d30 rdyboost - ok
17:47:51.0073 0x0d30 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
17:47:51.0088 0x0d30 RemoteRegistry - ok
17:47:51.0119 0x0d30 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
17:47:51.0151 0x0d30 RpcEptMapper - ok
17:47:51.0166 0x0d30 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
17:47:51.0182 0x0d30 RpcLocator - ok
17:47:51.0197 0x0d30 [ B82CD39E336973359D7C9BF911E8E84F, 45DB8F1E88FC25A81D2F3C2F8A8CDB6B34C44950B038E24FB71DCDD9823DB22A ] RpcSs C:\Windows\System32\rpcss.dll
17:47:51.0229 0x0d30 RpcSs - ok
17:47:51.0275 0x0d30 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
17:47:51.0307 0x0d30 rspndr - ok
17:47:51.0322 0x0d30 [ 7DFD48E24479B68B258D8770121155A0, 3B5F7309403C46855DB888CF2058B07C9029690DBC7FB3224BAC7BE5547D2D57 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
17:47:51.0338 0x0d30 RTL8167 - ok
17:47:51.0369 0x0d30 [ C9B9B3219322786EF82745E09FE9CBE8, B704FEE5B7FC5B662ED80E51E53336DBBAC7402BC99A35E67036327DF6431D45 ] RTL85n86 C:\Windows\system32\DRIVERS\RTL85n86.sys
17:47:51.0385 0x0d30 RTL85n86 - ok
17:47:51.0416 0x0d30 [ 5423D8437051E89DD34749F242C98648, 28FD190E13676B0FD452A73C3069B72206E2938DB2240BAA9BDB56687C748A2B ] s3cap C:\Windows\system32\DRIVERS\vms3cap.sys
17:47:51.0431 0x0d30 s3cap - ok
17:47:51.0447 0x0d30 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] SamSs C:\Windows\system32\lsass.exe
17:47:51.0447 0x0d30 SamSs - ok
17:47:51.0494 0x0d30 [ 34EE0C44B724E3E4CE2EFF29126DE5B5, D27AAF77CB8830893558A600E19CDBF9A6AA7D69DE4B34F317ED4AFD38E8CAFB ] sbp2port C:\Windows\system32\DRIVERS\sbp2port.sys
17:47:51.0494 0x0d30 sbp2port - ok
17:47:51.0525 0x0d30 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll
17:47:51.0541 0x0d30 SCardSvr - ok
17:47:51.0572 0x0d30 [ A95C54B2AC3CC9C73FCDF9E51A1D6B51, 8C0189A6AF9AEC46CBA4DA422C52B2D3E4858B2F2658DB6CA7996B5F368D2503 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
17:47:51.0603 0x0d30 scfilter - ok
17:47:51.0650 0x0d30 [ 3E8B0C453E25613A1F59762A5C42AA75, 86801C49664441A08F7E95031E52AD2518D61CCB945A857A18F0714351A8158C ] Schedule C:\Windows\system32\schedsvc.dll
17:47:51.0681 0x0d30 Schedule - ok
17:47:51.0712 0x0d30 [ 628A9E30EC5E18DD5DE6BE4DBDC12198, DDA43DCCB195440D6BD5752BD00D984F45BD6D23DBE2A656C33E3CD1E5D17AD7 ] SCPolicySvc C:\Windows\System32\certprop.dll
17:47:51.0728 0x0d30 SCPolicySvc - ok
17:47:51.0743 0x0d30 [ 5FD90ABDBFAEE85986802622CBB03446, 0A8D9DC09C2ACA9EAABED04737E9EBF6EFB92BB2B9E5F37F10BFDF47CBF7DEDB ] SDRSVC C:\Windows\System32\SDRSVC.dll
17:47:51.0759 0x0d30 SDRSVC - ok
17:47:51.0806 0x0d30 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
17:47:51.0837 0x0d30 secdrv - ok
17:47:51.0853 0x0d30 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
17:47:51.0884 0x0d30 seclogon - ok
17:47:51.0884 0x0d30 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\system32\sens.dll
17:47:51.0915 0x0d30 SENS - ok
17:47:51.0931 0x0d30 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
17:47:51.0962 0x0d30 SensrSvc - ok
17:47:51.0962 0x0d30 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
17:47:51.0977 0x0d30 Serenum - ok
17:47:51.0993 0x0d30 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
17:47:52.0009 0x0d30 Serial - ok
17:47:52.0009 0x0d30 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
17:47:52.0024 0x0d30 sermouse - ok
17:47:52.0055 0x0d30 [ 8F55CE568C543D5ADF45C409D16718FC, 64D45854A91B656C1AF36EB272FDC54E9B5FB0200CB93E20F7D997DDA109EF7F ] SessionEnv C:\Windows\system32\sessenv.dll
17:47:52.0087 0x0d30 SessionEnv - ok
17:47:52.0087 0x0d30 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\DRIVERS\sffdisk.sys
17:47:52.0102 0x0d30 sffdisk - ok
17:47:52.0102 0x0d30 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\DRIVERS\sffp_mmc.sys
17:47:52.0118 0x0d30 sffp_mmc - ok
17:47:52.0133 0x0d30 [ 4F1E5B0FE7C8050668DBFADE8999AEFB, E36DAACC3D11F004808A3F44C471BBFDC2F33411D9F5C18B55B0DB2A6DA6E74C ] sffp_sd C:\Windows\system32\DRIVERS\sffp_sd.sys
17:47:52.0133 0x0d30 sffp_sd - ok
17:47:52.0149 0x0d30 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
17:47:52.0149 0x0d30 sfloppy - ok
17:47:52.0211 0x0d30 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
17:47:52.0227 0x0d30 SharedAccess - ok
17:47:52.0274 0x0d30 [ CD2E48FA5B29EE2B3B5858056D246EF2, B743F92D0121CF3D827753C85F1F5A14C2DAA1CAFD42C7810C3BECB853DB6175 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
17:47:52.0305 0x0d30 ShellHWDetection - ok
17:47:52.0321 0x0d30 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\DRIVERS\sisagp.sys
17:47:52.0321 0x0d30 sisagp - ok
17:47:52.0352 0x0d30 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:47:52.0352 0x0d30 SiSRaid2 - ok
17:47:52.0367 0x0d30 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
17:47:52.0383 0x0d30 SiSRaid4 - ok
17:47:52.0414 0x0d30 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
17:47:52.0430 0x0d30 Smb - ok
17:47:52.0477 0x0d30 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
17:47:52.0477 0x0d30 SNMPTRAP - ok
17:47:52.0555 0x0d30 [ 4945020BC094C322571184A6E8056B3A, 9E09257411F7C3631537D0198E0E64CDD1A697D80430F6379139B15A2BA8A6C9 ] SolidWorks Licensing Service C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
17:47:52.0570 0x0d30 SolidWorks Licensing Service - detected UnsignedFile.Multi.Generic ( 1 )
17:47:58.0061 0x0d30 Detect skipped due to KSN trusted
17:47:58.0061 0x0d30 SolidWorks Licensing Service - ok
17:47:58.0108 0x0d30 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
17:47:58.0108 0x0d30 spldr - ok
17:47:58.0171 0x0d30 [ 49B6DD6AB3715B7A67965F17194E98A9, 331D69F3630BA978AC13471A2E7465351D04416343A595C62B94BADFFCD02B3A ] Spooler C:\Windows\System32\spoolsv.exe
17:47:58.0202 0x0d30 Spooler - ok
17:47:58.0545 0x0d30 [ 4C287F9069FEDBD791178876EE9DE536, 6099E76FF6FBA002EBA2BA7BE4E3238D91332E077524D1DD402E0C9ADA22E852 ] sppsvc C:\Windows\system32\sppsvc.exe
17:47:58.0654 0x0d30 sppsvc - ok
17:47:58.0685 0x0d30 [ D8E3E19EEBDAB49DD4A8D3062EAD4EC7, E7A8A5774C62DC12B56DC3E0A385ACA9069F3A5E6AC664AD0C383EF44DCF81B3 ] sppuinotify C:\Windows\system32\sppuinotify.dll
17:47:58.0701 0x0d30 sppuinotify - ok
17:47:58.0732 0x0d30 [ 2BA4EBC7DFBA845A1EDBE1F75913BE33, 58D0B957469D55026A53C3963508C8B36BDB360A0A5B870332B79A39200DB3AC ] srv C:\Windows\system32\DRIVERS\srv.sys
17:47:58.0763 0x0d30 srv - ok
17:47:58.0763 0x0d30 [ DCE7E10FEAABD4CAE95948B3DE5340BB, B1E9CD14DC24BB161EFC83D83CE95D0A98008AD790041785C6C8B87564A491D7 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
17:47:58.0795 0x0d30 srv2 - ok
17:47:58.0810 0x0d30 [ B5665BAA2120B8A54E22E9CD07C05106, 86E50853D412ACDC752AD182ED52B49DD679D75843E1E9D6A6425E750594692C ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
17:47:58.0841 0x0d30 srvnet - ok
17:47:58.0857 0x0d30 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
17:47:58.0888 0x0d30 SSDPSRV - ok
17:47:58.0904 0x0d30 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
17:47:58.0919 0x0d30 SstpSvc - ok
17:47:58.0966 0x0d30 [ C354621B6B94E10AE7F5CDBE745FEB86, 790F739C71432AFFA69842C8C8BD62914A6F69FE0D242828AA317009B7176E0A ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
17:47:58.0982 0x0d30 Stereo Service - ok
17:47:58.0997 0x0d30 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
17:47:59.0013 0x0d30 stexstor - ok
17:47:59.0044 0x0d30 [ A22825E7BB7018E8AF3E229A5AF17221, 5C97557F8BC6ABBB5BE624AE41AAC22C3D845F76C3E930337A4C07B2381086D7 ] StiSvc C:\Windows\System32\wiaservc.dll
17:47:59.0060 0x0d30 StiSvc - ok
17:47:59.0091 0x0d30 [ 957E346CA948668F2496A6CCF6FF82CC, 5C0E0F0E0F2D36E3213885C60BC3B075AFD2257FEB4B8186FC1FE253E0C218AF ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
17:47:59.0091 0x0d30 storflt - ok
17:47:59.0122 0x0d30 [ D5751969DC3E4B88BF482AC8EC9FE019, DAEB50C0045364C75965B0E94744C6E2E1E85C8D00F1E8A5593F3EC780BDD7D9 ] storvsc C:\Windows\system32\DRIVERS\storvsc.sys
17:47:59.0122 0x0d30 storvsc - ok
17:47:59.0138 0x0d30 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\DRIVERS\swenum.sys
17:47:59.0138 0x0d30 swenum - ok
17:47:59.0153 0x0d30 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
17:47:59.0200 0x0d30 swprv - ok
17:47:59.0231 0x0d30 [ 04105C8DA62353589C29BDAEB8D88BD8, CC7A3A779A143E09FE5C0AA6795A7B13496C4E121347949CB23F7946EE5E2DED ] SysMain C:\Windows\system32\sysmain.dll
17:47:59.0278 0x0d30 SysMain - ok
17:47:59.0309 0x0d30 [ FCFB6C552FBC0DA299799CBD50AD9FD4, A2A90829087B1A7F9B57D6F184EB4AE38D10B2986B0DC8D2ACA5EE9412CA3976 ] TabletInputService C:\Windows\System32\TabSvc.dll
17:47:59.0325 0x0d30 TabletInputService - ok
17:47:59.0341 0x0d30 [ 2F46B0C70A4ADC8C90CF825DA3B4FEAF, FF66CBA014F3F8B721088F5AB3D004C1711E7F587CC8D4AC3DCFB45CDB746800 ] TapiSrv C:\Windows\System32\tapisrv.dll
17:47:59.0356 0x0d30 TapiSrv - ok
17:47:59.0403 0x0d30 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
17:47:59.0419 0x0d30 TBS - ok
17:47:59.0621 0x0d30 [ 2CC3D75488ABD3EC628BBB9A4FC84EFC, 62917CDBC6529D1CC3D7F6E211C717DC44033955749333DCBD052F9BF6639767 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
17:47:59.0668 0x0d30 Tcpip - ok
17:47:59.0731 0x0d30 [ 2CC3D75488ABD3EC628BBB9A4FC84EFC, 62917CDBC6529D1CC3D7F6E211C717DC44033955749333DCBD052F9BF6639767 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
17:47:59.0762 0x0d30 TCPIP6 - ok
17:47:59.0762 0x0d30 [ E64444523ADD154F86567C469BC0B17F, FBE8A1DC28C102068183754F6BF0D03F5D18FD24BEB7E4B57D1CFCEBB13B381F ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
17:47:59.0793 0x0d30 tcpipreg - ok
17:47:59.0824 0x0d30 [ 1875C1490D99E70E449E3AFAE9FCBADF, FFDF03826DAB748D51B53B648B632E79B3CD6238F684FDEA749B4D0F93BE5A77 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
17:47:59.0840 0x0d30 TDPIPE - ok
17:47:59.0855 0x0d30 [ 7551E91EA999EE9A8E9C331D5A9C31F3, C98C97DFD6C7276CD999545A7BC67B56E1BDDFB2886412E9198012322F95A10D ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
17:47:59.0871 0x0d30 TDTCP - ok
17:47:59.0902 0x0d30 [ CB39E896A2A83702D1737BFD402B3542, FA77D98EA3606CA2FCEF0E0949FDE2C32A080B47CAFDE46CE903CA3CBFC5DF35 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
17:47:59.0918 0x0d30 tdx - ok
17:47:59.0933 0x0d30 [ C36F41EE20E6999DBF4B0425963268A5, 9DB789A17DF2C283D6E803EEA15F2BDFC56EE3BE342A5606DD5C179C3550ECA6 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys
17:47:59.0949 0x0d30 TermDD - ok
17:47:59.0996 0x0d30 [ A01E50A04D7B1960B33E92B9080E6A94, 0512BF11F2FD62BDBD2B1AA34D509BE82AC374C37B925C8C0ED119C6331930FD ] TermService C:\Windows\System32\termsrv.dll
17:48:00.0027 0x0d30 TermService - ok
17:48:00.0043 0x0d30 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll
17:48:00.0089 0x0d30 Themes - ok
17:48:00.0105 0x0d30 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
17:48:00.0121 0x0d30 THREADORDER - ok
17:48:00.0152 0x0d30 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
17:48:00.0183 0x0d30 TrkWks - ok
17:48:00.0230 0x0d30 [ 41A4C781D2286208D397D72099304133, 447CAAD5589AA499EEE49FBA2CB53210359DB76AFF1DF2F0BD4D92A397037C1D ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
17:48:00.0245 0x0d30 TrustedInstaller - ok
17:48:00.0261 0x0d30 [ 98AE6FA07D12CB4EC5CF4A9BFA5F4242, 9606DACB8CBDAF520282BE8C8F064535767405F138D9E9A215D2C59183E93CC1 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
17:48:00.0277 0x0d30 tssecsrv - ok
17:48:00.0308 0x0d30 [ 3E461D890A97F9D4C168F5FDA36E1D00, 82A8778F404F7AC5102802CF46F279F1E58AC74244665D06FD0C68A8BD887536 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
17:48:00.0339 0x0d30 tunnel - ok
17:48:00.0355 0x0d30 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
17:48:00.0370 0x0d30 uagp35 - ok
17:48:00.0386 0x0d30 [ 09CC3E16F8E5EE7168E01CF8FCBE061A, 81EEAC72A7C4D72666C743DEFF8096FDB465AA1FA8076C60D19CC192846F01CA ] udfs C:\Windows\system32\DRIVERS\udfs.sys
17:48:00.0417 0x0d30 udfs - ok
17:48:00.0433 0x0d30 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
17:48:00.0448 0x0d30 UI0Detect - ok
17:48:00.0479 0x0d30 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\DRIVERS\uliagpkx.sys
17:48:00.0479 0x0d30 uliagpkx - ok
17:48:00.0511 0x0d30 [ 049B3A50B3D646BAEEEE9EEC9B0668DC, 5774438BBD0976424C20559E14BA2AC158D9FF5D4E1FDC1C9C9F4D7A5CE8C377 ] umbus C:\Windows\system32\DRIVERS\umbus.sys
17:48:00.0511 0x0d30 umbus - ok
17:48:00.0526 0x0d30 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
17:48:00.0557 0x0d30 UmPass - ok
17:48:00.0589 0x0d30 [ 8ECACA5454844F66386F7BE4AE0D7CD1, F3B02A9F598C6A9EFA019F5833959DD1A86FDFDB9FDDF99A8687BBB6211AAD00 ] UmRdpService C:\Windows\System32\umrdp.dll
17:48:00.0604 0x0d30 UmRdpService - ok
17:48:00.0620 0x0d30 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
17:48:00.0651 0x0d30 upnphost - ok
17:48:00.0667 0x0d30 [ 8455C4ED038EFD09E99327F9D2D48FFA, D166F98EA3D85F7DD6B5258949C186714A17EF89B6FDC9804165F7B4FA811C30 ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
17:48:00.0682 0x0d30 usbccgp - ok
17:48:00.0682 0x0d30 [ 04EC7CEC62EC3B6D9354EEE93327FC82, 6CB41D8644618A5F701F6CA91FB65BB94AA83EA48992133B5262DC539B334B2E ] usbcir C:\Windows\system32\DRIVERS\usbcir.sys
17:48:00.0698 0x0d30 usbcir - ok
17:48:00.0713 0x0d30 [ 1C333BFD60F2FED2C7AD5DAF533CB742, 97AE9CA39482B886FCD063E80B8AB153E1FC1459452657393D8B1745EF69E1C3 ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
17:48:00.0713 0x0d30 usbehci - ok
17:48:00.0745 0x0d30 [ EE6EF93CCFA94FAE8C6AB298273D8AE2, CBEE16CEAD02E994F0C2AD77DD8C01CB9964C6B42DE49FF7A787849CD25767B4 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
17:48:00.0760 0x0d30 usbhub - ok
17:48:00.0776 0x0d30 [ A6FB7957EA7AFB1165991E54CE934B74, 1CE83D9E3276AE380F720C7700A17D58A37A2A77FD72DA69EE0C756B88DB3689 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
17:48:00.0791 0x0d30 usbohci - ok
17:48:00.0823 0x0d30 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
17:48:00.0838 0x0d30 usbprint - ok
17:48:00.0869 0x0d30 [ 576096CCBC07E7C4EA4F5E6686D6888F, 8C643F43BD0017979548389C4DB36A1EE872CCF19C86FAE3752A4989173E28ED ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys
17:48:00.0885 0x0d30 usbscan - ok
17:48:00.0901 0x0d30 [ D8889D56E0D27E57ED4591837FE71D27, DB1B65EEBFB036086EC3347C1181D9D01FF65870EAEC4A1BA08AF43C35075647 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
17:48:00.0916 0x0d30 USBSTOR - ok
17:48:00.0932 0x0d30 [ 78780C3EBCE17405B1CCD07A3A8A7D72, FBFF3111E22EE0B4BCAFA81F89AAE985135BFF48EEFD130C09B49CCF8A9946B9 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys
17:48:00.0932 0x0d30 usbuhci - ok
17:48:00.0963 0x0d30 [ D82F43D15FDAA666856C0190CB73E7C9, A998F5F0535ADCFE0E6F37E4B222262F59D4E43CB596D62E785EF8E0D7E296F6 ] usb_rndisx C:\Windows\system32\DRIVERS\usb8023x.sys
17:48:00.0979 0x0d30 usb_rndisx - ok
17:48:01.0010 0x0d30 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
17:48:01.0041 0x0d30 UxSms - ok
17:48:01.0057 0x0d30 [ F42309C4191C506B71DB5D1126D26318, 29B0A8889857CEBFA6CBD795D5EECDDFFA04E794BD3C73FC488725B2A160F326 ] VaultSvc C:\Windows\system32\lsass.exe
17:48:01.0057 0x0d30 VaultSvc - ok
17:48:01.0088 0x0d30 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\DRIVERS\vdrvroot.sys
17:48:01.0103 0x0d30 vdrvroot - ok
17:48:01.0119 0x0d30 [ 8C4E7C49D3641BC9E299E466A7F8867D, 4F2E742EFE2DE47EE187B3BCDFDCB525FE484B74700A226D7894F9633F957AFA ] vds C:\Windows\System32\vds.exe
17:48:01.0150 0x0d30 vds - ok
17:48:01.0166 0x0d30 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
17:48:01.0166 0x0d30 vga - ok
17:48:01.0181 0x0d30 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
17:48:01.0197 0x0d30 VgaSave - ok
17:48:01.0213 0x0d30 [ 3BE6E1F3A4F1AFEC8CEE0D7883F93583, 33DF8F7C9A3176175113CA10D69FAF17A5412C055943F14DDC9923531FADB82D ] vhdmp C:\Windows\system32\DRIVERS\vhdmp.sys
17:48:01.0228 0x0d30 vhdmp - ok
17:48:01.0228 0x0d30 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\DRIVERS\viaagp.sys
17:48:01.0244 0x0d30 viaagp - ok
17:48:01.0244 0x0d30 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
17:48:01.0259 0x0d30 ViaC7 - ok
17:48:01.0275 0x0d30 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\DRIVERS\viaide.sys
17:48:01.0291 0x0d30 viaide - ok
17:48:01.0353 0x0d30 [ 59E6D1CC4EA1A19D07570AA0657ED966, 27E3366E7D2862148E6A8F6FAD02204FCAB50496ADCE49669096C54AA0A74022 ] VmbService C:\Program Files\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
17:48:01.0369 0x0d30 VmbService - detected UnsignedFile.Multi.Generic ( 1 )
17:48:05.0035 0x0d30 Detect skipped due to KSN trusted
17:48:05.0035 0x0d30 VmbService - ok
17:48:05.0066 0x0d30 [ 379B349F65F453D2A6E75EA6B7448E49, F52B1B3AE9F5D38B45C889A7B1EBE59533C17E73678D355D1466B5EF3338BF16 ] vmbus C:\Windows\system32\DRIVERS\vmbus.sys
17:48:05.0097 0x0d30 vmbus - ok
17:48:05.0097 0x0d30 [ EC2BBAB4B84D0738C6C83D2234DC36FE, 8BA2FA187DAC6994D5A29897AE5F46E6424FB53C827553E0BB148E31825D6676 ] VMBusHID C:\Windows\system32\DRIVERS\VMBusHID.sys
17:48:05.0113 0x0d30 VMBusHID - ok
17:48:05.0128 0x0d30 [ 384E5A2AA49934295171E499F86BA6F3, C79271F98506392422325C075144F45436F9979FE1E002B57F9426F3DA96CEF0 ] volmgr C:\Windows\system32\DRIVERS\volmgr.sys
17:48:05.0144 0x0d30 volmgr - ok
17:48:05.0144 0x0d30 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
17:48:05.0159 0x0d30 volmgrx - ok
17:48:05.0175 0x0d30 [ 58DF9D2481A56EDDE167E51B334D44FD, C77D7BE83CF1C0DEC80429C5A519E794FD2E8C1E6DAD6F5C92B5EB5694CEB8EA ] volsnap C:\Windows\system32\DRIVERS\volsnap.sys
17:48:05.0191 0x0d30 volsnap - ok
17:48:05.0222 0x0d30 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
17:48:05.0237 0x0d30 vsmraid - ok
17:48:05.0284 0x0d30 [ 7EA2BCD94D9CFAF4C556F5CC94532A6C, 7CD6637BE0A08E3B0F9991D79751DCA8AEC9224B83301821DAA29C9F42B7A9E3 ] VSS C:\Windows\system32\vssvc.exe
17:48:05.0315 0x0d30 VSS - ok
17:48:05.0331 0x0d30 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
17:48:05.0347 0x0d30 vwifibus - ok
17:48:05.0362 0x0d30 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
17:48:05.0393 0x0d30 W32Time - ok
17:48:05.0409 0x0d30 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
17:48:05.0440 0x0d30 WacomPen - ok
17:48:05.0456 0x0d30 [ 692A712062146E96D28BA0B7D75DE31B, B6D260272330E0C8EBFAD8F09212F48F1EFED42E6BD3F29A5780D0B691D55B34 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
17:48:05.0487 0x0d30 WANARP - ok
17:48:05.0487 0x0d30 [ 692A712062146E96D28BA0B7D75DE31B, B6D260272330E0C8EBFAD8F09212F48F1EFED42E6BD3F29A5780D0B691D55B34 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
17:48:05.0503 0x0d30 Wanarpv6 - ok
17:48:05.0596 0x0d30 [ 353A04C273EC58475D8633E75CCD5604, FFAE53B6B53AEFC9E8A10BF27480E072D74430276BEB532FE1D473E9616D8CE0 ] WatAdminSvc C:\Windows\system32\Wat\WatAdminSvc.exe
17:48:05.0643 0x0d30 WatAdminSvc - ok
17:48:05.0705 0x0d30 [ 7790B77FE1E5EE47DCC66247095BB4C9, FFB541F83CDE32E65007D41217C2F46CDDF68121E2846B638EAB620ACA940B05 ] wbengine C:\Windows\system32\wbengine.exe
17:48:05.0752 0x0d30 wbengine - ok
17:48:05.0768 0x0d30 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
17:48:05.0783 0x0d30 WbioSrvc - ok
17:48:05.0799 0x0d30 [ D0F88AA11EE1A62BCC6D6A8A7783CA11, 3DBC1806E6F8CD58A9E93EA2A0CDC83C1A90E37B5E385209E4D9A0C81922F447 ] wcncsvc C:\Windows\System32\wcncsvc.dll
17:48:05.0830 0x0d30 wcncsvc - ok
17:48:05.0846 0x0d30 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
17:48:05.0861 0x0d30 WcsPlugInService - ok
17:48:05.0861 0x0d30 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys
17:48:05.0877 0x0d30 Wd - ok
17:48:05.0893 0x0d30 [ 9950E3D0F08141C7E89E64456AE7DC73, DE4B96812B305A63F5874BBF2DC40354FB45B3D96C1D33436E677099760BA448 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
17:48:05.0908 0x0d30 Wdf01000 - ok
17:48:05.0924 0x0d30 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost C:\Windows\system32\wdi.dll
17:48:05.0939 0x0d30 WdiServiceHost - ok
17:48:05.0939 0x0d30 [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost C:\Windows\system32\wdi.dll
17:48:05.0955 0x0d30 WdiSystemHost - ok
17:48:05.0971 0x0d30 [ D87C7D2C517F82A5AB7A73E203063D9E, 8861AB4ECEDAE801008BE0406FCB19418AA2864E89D0776B94E25773E6DB5E88 ] WebClient C:\Windows\System32\webclnt.dll
17:48:05.0986 0x0d30 WebClient - ok
17:48:05.0986 0x0d30 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
17:48:06.0017 0x0d30 Wecsvc - ok
17:48:06.0033 0x0d30 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
17:48:06.0049 0x0d30 wercplsupport - ok
17:48:06.0095 0x0d30 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
17:48:06.0127 0x0d30 WerSvc - ok
17:48:06.0142 0x0d30 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
17:48:06.0173 0x0d30 WfpLwf - ok
17:48:06.0189 0x0d30 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
17:48:06.0189 0x0d30 WIMMount - ok
17:48:06.0267 0x0d30 [ 3FAE8F94296001C32EAB62CD7D82E0FD, 180FAECC426CF8F46700C855022E5865D528B1A20686F96D11080AB2FE2E0430 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
17:48:06.0298 0x0d30 WinDefend - ok
17:48:06.0298 0x0d30 WinHttpAutoProxySvc - ok
17:48:06.0345 0x0d30 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
17:48:06.0376 0x0d30 Winmgmt - ok
17:48:06.0423 0x0d30 [ C4F5D3901D1B41D602DDC196E0B95B51, 20FF2A9DEE3ECBFB163DFA62A407E30ED49F609EF46936F286C2A08A24EA3E7C ] WinRM C:\Windows\system32\WsmSvc.dll
17:48:06.0501 0x0d30 WinRM - ok
17:48:06.0548 0x0d30 [ 30FC6E5448D0CBAAA95280EEEF7FEDAE, 04374450882504D9031951F4E9317E5A128EBA5A22A3555ACD28BC742861AF9C ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
17:48:06.0563 0x0d30 WinUsb - ok
17:48:06.0595 0x0d30 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
17:48:06.0641 0x0d30 Wlansvc - ok
17:48:06.0657 0x0d30 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys
17:48:06.0673 0x0d30 WmiAcpi - ok
17:48:06.0704 0x0d30 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
17:48:06.0704 0x0d30 wmiApSrv - ok
17:48:06.0719 0x0d30 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
17:48:06.0735 0x0d30 WPCSvc - ok
17:48:06.0751 0x0d30 [ B7F658A2EBC07129538AD9AB35212637, 86774A760189E4B126C972A778F890C00C1C30EDD28044DD43B40644A8778B4D ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
17:48:06.0766 0x0d30 WPDBusEnum - ok
17:48:06.0782 0x0d30 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
17:48:06.0797 0x0d30 ws2ifsl - ok
17:48:06.0844 0x0d30 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\system32\wscsvc.dll
17:48:06.0875 0x0d30 wscsvc - ok
17:48:06.0875 0x0d30 WSearch - ok
17:48:06.0938 0x0d30 [ A33408CC036F9C08142B11BE5E93F0A1, A6CE3681EE4DE3C9A8B8B5DA4E8E46DB4443A32D1339F7D0893F1F2153635D86 ] wuauserv C:\Windows\system32\wuaueng.dll
17:48:07.0016 0x0d30 wuauserv - ok
17:48:07.0031 0x0d30 [ 6F9B6C0C93232CFF47D0F72D6DB1D21E, C685A458951820ED0F09E6197251CE6FC55AAB75D4FBEFF2992805309239A47A ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
17:48:07.0063 0x0d30 WudfPf - ok
17:48:07.0078 0x0d30 [ F91FF1E51FCA30B3C3981DB7D5924252, D7052B58F22638CA8B59C6FD7408D6D6DD1C33910912CACC05C133472CE0DDCE ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
17:48:07.0109 0x0d30 WUDFRd - ok
17:48:07.0141 0x0d30 [ DDEE3682FE97037C45F4D7AB467CB8B6, D5A8F07AF4EDD9D7E17FEC6222D187E2981C177A479511E407756E0E5CB8D387 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
17:48:07.0156 0x0d30 wudfsvc - ok
17:48:07.0172 0x0d30 [ FF2D745B560F7C71B31F30F4D49F73D2, B2FBF7E5F58E34AC64FE6CF65800F1F07939279203BDE89375FAC92B884A4F37 ] WwanSvc C:\Windows\System32\wwansvc.dll
17:48:07.0203 0x0d30 WwanSvc - ok
17:48:07.0250 0x0d30 ================ Scan global ===============================
17:48:07.0281 0x0d30 [ 9A595DF601070DA78C40481120DD2C06, 4C2D6216F212DE9346339ED29152962A39E4435E70F18DD655156727E70818F6 ] C:\Windows\system32\basesrv.dll
17:48:07.0297 0x0d30 [ 827E4F75901CA3F990B1487D3301841E, A0B17C83D52DB95EDBA81C6ABD78E5E4E3BB65CB57F977B07172A96D4C2B743B ] C:\Windows\system32\winsrv.dll
17:48:07.0312 0x0d30 [ 827E4F75901CA3F990B1487D3301841E, A0B17C83D52DB95EDBA81C6ABD78E5E4E3BB65CB57F977B07172A96D4C2B743B ] C:\Windows\system32\winsrv.dll
17:48:07.0328 0x0d30 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
17:48:07.0343 0x0d30 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
17:48:07.0359 0x0d30 [ Global ] - ok
17:48:07.0359 0x0d30 ================ Scan MBR ==================================
17:48:07.0359 0x0d30 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
17:48:07.0562 0x0d30 \Device\Harddisk0\DR0 - ok
17:48:07.0624 0x0d30 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR1
17:48:07.0749 0x0d30 \Device\Harddisk1\DR1 - ok
17:48:07.0765 0x0d30 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk2\DR2
17:48:07.0843 0x0d30 \Device\Harddisk2\DR2 - ok
17:48:07.0843 0x0d30 ================ Scan VBR ==================================
17:48:07.0874 0x0d30 [ 3A25597DBAB4E92DD5A7B6A35AC603D5 ] \Device\Harddisk0\DR0\Partition1
17:48:07.0874 0x0d30 \Device\Harddisk0\DR0\Partition1 - ok
17:48:07.0889 0x0d30 [ CC14C2FAA6D6137FEB8B012A65C7D01A ] \Device\Harddisk0\DR0\Partition2
17:48:07.0889 0x0d30 \Device\Harddisk0\DR0\Partition2 - ok
17:48:07.0905 0x0d30 [ 01730BADB69EE7A6D5B248CF09A2EE61 ] \Device\Harddisk0\DR0\Partition3
17:48:07.0905 0x0d30 \Device\Harddisk0\DR0\Partition3 - ok
17:48:07.0921 0x0d30 [ 2F7FCDA48F34901C96BDCCFDBAEF2BA4 ] \Device\Harddisk1\DR1\Partition1
17:48:07.0921 0x0d30 \Device\Harddisk1\DR1\Partition1 - ok
17:48:07.0921 0x0d30 [ 1D622D90A3B7B872396AA730B8C52E01 ] \Device\Harddisk2\DR2\Partition1
17:48:07.0921 0x0d30 \Device\Harddisk2\DR2\Partition1 - ok
17:48:07.0921 0x0d30 Waiting for KSN requests completion. In queue: 43
17:48:08.0935 0x0d30 Waiting for KSN requests completion. In queue: 43
17:48:09.0949 0x0d30 Waiting for KSN requests completion. In queue: 43
17:48:10.0963 0x0d30 Waiting for KSN requests completion. In queue: 43
17:48:11.0977 0x0d30 Win FW state via NFP2: enabled
17:48:16.0875 0x0d30 ============================================================
17:48:16.0875 0x0d30 Scan finished
17:48:16.0875 0x0d30 ============================================================
17:48:16.0891 0x0d44 Detected object count: 0
17:48:16.0891 0x0d44 Actual detected object count: 0
mbam-logMalwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.10.24.05
Windows 7 x86 NTFS
Internet Explorer 8.0.7600.16385
Stefan :: STEFAN-PC [administrator]
2013/10/24 17:54:56 PM
mbam-log-2013-10-24 (17-54-56).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 244779
Time elapsed: 4 minute(s), 1 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 29
HKCR\AppID\{38495740-0035-4471-851E-F5BBB86AB085} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\AppID\{72D89EBF-0C5D-4190-91FD-398E45F1D007} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3} (PUP.Optional.BrowseFox.A) -> Quarantined and deleted successfully.
HKCR\CLSID\{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\TypeLib\{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Interface\{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) -> Quarantined and deleted successfully.
HKCR\CLSID\{A1E28287-1A31-4b0f-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\DefaultTabBHO.DefaultTabBrowserActiveX.1 (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCR\DefaultTabBHO.DefaultTabBrowserActiveX (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7F6AFBF1-E065-4627-A2FD-810366367D01} (PUP.Optional.DefaultTab) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2D33ED6-EBBD-467C-BF6F-F175D9B51363} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{BAD84EE2-624D-4e7c-A8BB-41EFD720FD77} (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{96E277C1-EFCC-6C5F-F089-7BF080367B2E} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{29A2FD27-9630-A0E7-005B-845CC22AE62A} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0041844.BHO (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0041844.Sandbox (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCR\CrossriderApp0041844.Sandbox.1 (PUP.Optional.CrossRider.A) -> Quarantined and deleted successfully.
HKCR\AppID\DefaultTabBHO.DLL (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\DEFAULT TAB (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\SProtector (PUP.Optional.SProtector.A) -> Quarantined and deleted successfully.
HKCU\Software\AppDataLow\Software\DefaultTab (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\DEFAULT TAB (PUP.Optional.DefaultTab.A) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Speedchecker Limited\PC Speed Up (PUP.Optional.PCSpeedUp.A) -> Quarantined and deleted successfully.
HKLM\Software\ElectroLyrics-1 (PUP.Optional.ElectroLyrics.A) -> Quarantined and deleted successfully.
Registry Values Detected: 3
HKCU\SOFTWARE\Default Tab|Version (PUP.Optional.DefaultTab.A) -> Data: 2.2.8.0 -> Quarantined and deleted successfully.
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Data: 0A2T1U1Q0StGyEtH1I2Y0StGtBtH1N1QtI0EtGzv -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Default Tab|Version (PUP.Optional.DefaultTab.A) -> Data: 2.2.8.0 -> Quarantined and deleted successfully.
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 8
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504} (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Cache (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\OpenCandy (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\OpenCandy\0F379A89265945DEAD8E072F98CB17CC (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\OpenCandy\A7B1587E199847E3A81B5C9C2D01AFD5 (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\OpenCandy\OpenCandy_A7B1587E199847E3A81B5C9C2D01AFD5 (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\File Scout (PUP.Optional.FileScout.A) -> Quarantined and deleted successfully.
Files Detected: 25
C:\Users\Stefan\AppData\Local\SwvUpdater\Updater.exe (PUP.Software.Updater) -> Quarantined and deleted successfully.
C:\ProgramData\ccoonntoinuUEtossavea\5182b065d252e.dll (PUP.Optional.MultiPlug.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{AF0AF371-584C-4B47-A9AC-106E74E9D187}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{AF0AF371-584C-4B47-A9AC-106E74E9D187}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{CEFF2BF8-4E61-49C6-AB2D-0643151C090E}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\InstallMate\{CEFF2BF8-4E61-49C6-AB2D-0643151C090E}\TsuDll.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.exe (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\YTD Video Downloader\ytd_installer.exe (PUP.Optional.Spigot.A) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\File Scout\filescout.exe (PUP.Optional.FileScout.A) -> Quarantined and deleted successfully.
C:\Users\Stefan\dxqzso.exe (Trojan.Dropper.AI) -> Quarantined and deleted successfully.
C:\Users\Stefan\Downloads\77ZipSetup.exe (Adware.InstallBrain) -> Quarantined and deleted successfully.
C:\Users\Stefan\Downloads\setup.exe (PUP.Optional.ExpressInstall.A) -> Quarantined and deleted successfully.
C:\Users\Stefan\Downloads\SoftonicDownloader_for_vlc-media-player.exe (PUP.Optional.Softonic) -> Quarantined and deleted successfully.
C:\Users\Stefan\Downloads\SoftonicDownloader_for_winamp.exe (PUP.Optional.Softonic) -> Quarantined and deleted successfully.
C:\Users\Stefan\Downloads\sweetimsetup.exe (PUP.Optional.SweetIM) -> Quarantined and deleted successfully.
C:\Users\Stefan\Downloads\ELe.1.20.x264.rar.exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Users\Stefan\Downloads\Dexter.S08E02.Every.Silver.Lining..XviD-MGD[ettv].exe (PUP.Optional.Installex) -> Quarantined and deleted successfully.
C:\Windows\Tasks\AmiUpdXp.job (PUP.Software.Updater) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.dat (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\Setup.ico (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setup.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer\{361E80BE-388B-4270-BF54-A10C2B756504}\_Setupx.dll (PUP.Optional.Tarma.A) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\OpenCandy\0F379A89265945DEAD8E072F98CB17CC\IE9-Windows7-x86-enu.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\OpenCandy\A7B1587E199847E3A81B5C9C2D01AFD5\PCSU_SL_3.1.2.exe (PUP.Optional.OpenCandy) -> Quarantined and deleted successfully.
C:\Users\Stefan\AppData\Roaming\File Scout\uninst.exe (PUP.Optional.FileScout.A) -> Quarantined and deleted successfully.
(end)