Ukash Australian Federal Police Virus

Paleoworld-101

New Member
Thread author
May 6, 2013
11
OTL LOG

OTL logfile created on: 5/6/2013 8:13:45 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Nathan\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy

2.90 Gb Total Physical Memory | 1.22 Gb Available Physical Memory | 42.11% Memory free
5.80 Gb Paging File | 3.54 Gb Available in Paging File | 61.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 448.47 Gb Total Space | 376.57 Gb Free Space | 83.97% Space Free | Partition Type: NTFS
Drive E: | 14.90 Gb Total Space | 0.92 Gb Free Space | 6.15% Space Free | Partition Type: FAT32
Drive F: | 1.99 Gb Total Space | 1.96 Gb Free Space | 98.84% Space Free | Partition Type: FAT32
Unable to calculate disk information.

Computer Name: NATHANS-LAPTOP | User Name: Nathan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Nathan\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccsvchst.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Hewlett-Packard\Shared\hpCaslNotification.exe (Hewlett-Packard Development Company L.P.)
PRC - C:\Program Files\Hewlett-Packard\HP Support Framework\HPSF.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe (Motorola, Inc.)
PRC - C:\Program Files\Motorola\Bluetooth\obexsrv.exe (Motorola, Inc.)
PRC - C:\Program Files\Motorola\Bluetooth\audiosrv.exe (Motorola, Inc.)
PRC - C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
PRC - C:\Program Files\Motorola\Bluetooth\btplayerctrl.exe (Motorola, Inc.)
PRC - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
PRC - C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe (Hewlett-Packard Company)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\stacsv.exe (IDT, Inc.)
PRC - C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - c:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation)
PRC - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Modules (No Company Name) ==========

MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\5cf7fcba96db2ec632eda5e52fc373da\System.Data.DataSetExtensions.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\56b5e47c9cfbdf44d230853cf87fab5a\IAStorUtil.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\77dfcfed5fd5f67d0d3edc545935bb21\System.Core.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\d7d20811a7ce7cc589153648cbb1ce5c\PresentationFramework.Aero.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\ff7c9a4f41f7cccc47e696c11b9f8469\PresentationFramework.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\23da92e38ffc0bbf6673adb1892aa0f4\UIAutomationProvider.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\19b3d17c3ce0e264c4fb62028161adf7\PresentationCore.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d908c91e24616e6b8d38c9da61038b25\Accessibility.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\Users\Nathan\AppData\Roaming\drent.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\windows\assembly\GAC_MSIL\hpcasl\3.5.1.1__9c6f83d5b7f3d097\hpcasl.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CaslShared\3.5.1.1__9c6f83d5b7f3d097\CaslShared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportFramework\1.0.0.0__2a4860322af7ba08\HP.SupportFramework.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.ActiveSupportLibrary\2.0.0.1__01a974bc1760f423\HP.ActiveSupportLibrary.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()


========== Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (NIS) -- C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe (Symantec Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (HPDrvMntSvc.exe) -- C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (Bluetooth Device Manager) -- C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe (Motorola, Inc.)
SRV - (Bluetooth OBEX Service) -- C:\Program Files\Motorola\Bluetooth\obexsrv.exe (Motorola, Inc.)
SRV - (Bluetooth Media Service) -- C:\Program Files\Motorola\Bluetooth\audiosrv.exe (Motorola, Inc.)
SRV - (NOBU) -- C:\Program Files\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation)
SRV - (IAStorDataMgrSvc) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (hpHotkeyMonitor) -- C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\stacsv.exe (IDT, Inc.)
SRV - (pdfcDispatcher) -- C:\Program Files\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (IJPLMSVC) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (PSI_SVC_2) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Driver Services (SafeList) ==========

DRV - (TotRec8) -- C:\Windows\System32\drivers\TotRec8.sys (High Criteria inc.)
DRV - (ctxusbm) -- C:\Windows\System32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (mcaudrv_simple) -- C:\Windows\System32\drivers\mcaudrv.sys (ManyCam LLC)
DRV - (ManyCam) -- C:\Windows\System32\drivers\mcvidrv.sys (ManyCam LLC)
DRV - (BHDrvx86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110929.001\BHDrvx86.sys (Symantec Corporation)
DRV - (IDSVix86) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111004.030\IDSvix86.sys (Symantec Corporation)
DRV - (SymEvent) -- C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111004.021\NAVEX15.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111004.021\NAVENG.SYS (Symantec Corporation)
DRV - (SymNetS) -- C:\Windows\System32\drivers\NIS\1207020.003\symnets.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\System32\drivers\NIS\1207020.003\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) -- C:\Windows\System32\drivers\NIS\1207020.003\srtspx.sys (Symantec Corporation)
DRV - (SymEFA) -- C:\Windows\System32\drivers\NIS\1207020.003\symefa.sys (Symantec Corporation)
DRV - (SymDS) -- C:\Windows\System32\drivers\NIS\1207020.003\symds.sys (Symantec Corporation)
DRV - (SymIRON) -- C:\Windows\System32\drivers\NIS\1207020.003\ironx86.sys (Symantec Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (BTMUSB) -- C:\Windows\System32\drivers\btmusb.sys (Motorola, Inc.)
DRV - (BTMNET) -- C:\Windows\System32\drivers\btmnet.sys (Motorola, Inc.)
DRV - (rtsuvc) -- C:\Windows\System32\drivers\rtsuvc.sys (Realtek Semiconductor Corp.)
DRV - (BTMCOM) -- C:\Windows\System32\drivers\btmcom.sys (Motorola, Inc.)
DRV - (IntcHdmiAddService) -- C:\Windows\System32\drivers\IntcHdmi.sys (Intel(R) Corporation)
DRV - (HpqKbFiltr) -- C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Company)
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (AgereSoftModem) -- C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.jp.msn.com/HPALL/14
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.jp.msn.com/HPALL/14
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\..\SearchScopes\{D2AFE21D-6DDC-492E-9987-7FE9DADD4385}: "URL" = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.jp.msn.com/HPALL/14
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws/?source=c3348dd4&tbp=rbox&toolbarid=blekkotb_031&u=9FF0416AE9AB371AE98BDB504086AB98&q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7SKPT_enAU447
IE - HKCU\..\SearchScopes\{C076212A-D3FD-4EF4-A144-BE97B75732A5}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=MYC-ST&o=102869&src=kw&q={searchTerms}&locale=en_US&apn_ptnrs=5J&apn_dtid=YYYYYYYYAU&apn_uid=385205e7-b57b-44ce-b38c-db9780c28260&apn_sauid=D90BA786-986F-4062-B1D4-ADBC1CB2162E
IE - HKCU\..\SearchScopes\{D2AFE21D-6DDC-492E-9987-7FE9DADD4385}: "URL" = http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.2.1.5:8080


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Citrix.com/npagee,version=9.2.48.6: C:\Program Files\Citrix\Secure Access Client\npagee.dll (Citrix Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2011/09/30 13:04:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_12_1 [2013/05/06 18:46:23 | 000,000,000 | ---D | M]


========== Chrome ==========

CHR - homepage: http://blekko.com/ws/?source=c3348dd4&toolbarid=blekkotb_031&u=9FF0416AE9AB371AE98BDB504086AB98&tbp=homepage
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://blekko.com/ws/?source=c3348dd4&toolbarid=blekkotb_031&u=9FF0416AE9AB371AE98BDB504086AB98&tbp=homepage
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Nathan\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Bing Bar (Enabled) = C:\Program Files\MSN Toolbar\Platform\6.0.2237.0\npwinext.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Nathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Nathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Nathan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2009/06/11 07:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\18.7.2.3\coieplg.dll (Symantec Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BTMTrayAgent] C:\Program Files\Motorola\Bluetooth\btmshell.dll (Motorola, Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [drent] C:\Users\Nathan\AppData\Roaming\drent.dll ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [IJNetworkScanUtility] C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
O4 - HKLM..\Run: [mosit] C:\Users\Nathan\AppData\Roaming\mosit.dll (SiliconMotion)
O4 - HKLM..\Run: [NortonOnlineBackup] C:\Program Files\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [QLBController] C:\Program Files\Hewlett-Packard\HP HotKey Support\QLBController.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [sedgf] C:\Users\Nathan\AppData\Roaming\sedgf.dll (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKCU..\Run: [Opupmewa] C:\Users\Nathan\AppData\Roaming\Moxu\niakf.exe ()
O4 - HKCU..\Run: [Ovmeipodek] C:\Users\Nathan\AppData\Roaming\Rykua\etiqy.exe ()
O4 - HKCU..\Run: [Wisdom-soft AutoScreenRecorder 3.1 Pro] 0 File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\Motorola\Bluetooth\btmshell.dll,-137 - {bd707fe6-39f6-4bda-9265-86a76719bdc5} - C:\Program Files\Motorola\Bluetooth\btmiesend.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C474A887-AC2D-4C69-A8B3-6D3BD482EBBC}: DhcpNameServer = 10.2.20.10 10.2.21.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CEA37B9C-85A2-4B25-8B3B-03082B66B217}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/04 19:45:44 | 000,000,000 | ---D | C] -- C:\Users\Nathan\Documents\ezvid
[2013/05/04 19:45:38 | 000,000,000 | ---D | C] -- C:\Program Files\ezvid
[2013/05/04 19:38:06 | 000,000,000 | ---D | C] -- C:\Users\Nathan\AppData\Local\Programs
[2013/05/04 14:45:06 | 000,000,000 | ---D | C] -- C:\Users\Nathan\AppData\Local\{095EFD83-13C7-464A-A216-60D821D2D01C}
[2013/05/03 19:56:30 | 000,000,000 | ---D | C] -- C:\Users\Nathan\AppData\Local\{CA5D3EBE-CB80-48B1-B725-D3B8DA1A2364}
[2013/04/17 19:39:35 | 000,000,000 | ---D | C] -- C:\Users\Nathan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2013/04/17 19:39:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Related Programs
[2013/04/11 06:31:03 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\mshtml.tlb
[2013/04/11 06:31:02 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jsproxy.dll
[2013/04/11 06:31:01 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\msfeeds.dll
[2013/04/11 06:31:01 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieui.dll
[2013/04/11 06:31:01 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ieUnatt.exe
[2013/04/11 06:31:00 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\jscript9.dll
[2013/04/11 06:31:00 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\url.dll
[2013/04/11 06:30:59 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\inetcpl.cpl
[2013/04/10 08:06:15 | 002,347,008 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\win32k.sys
[2013/04/10 08:06:10 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\aaclient.dll
[2013/04/10 08:06:10 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\tsgqec.dll
[2013/04/10 08:06:05 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntkrnlpa.exe
[2013/04/10 08:06:05 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\ntoskrnl.exe
[2013/04/10 08:06:03 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\windows\System32\csrsrv.dll
[2012/12/20 11:05:35 | 000,290,816 | ---- | C] (S3 Graphics Co., Ltd.) -- C:\Users\Nathan\AppData\Roaming\sedgf.dll
[2012/12/20 11:05:05 | 000,601,088 | ---- | C] (SiliconMotion) -- C:\Users\Nathan\AppData\Roaming\mosit.dll
[2012/12/20 11:04:16 | 000,165,376 | ---- | C] (Donkey) -- C:\Users\Nathan\AppData\Roaming\windw.dll

========== Files - Modified Within 30 Days ==========

[2013/05/06 20:16:11 | 000,006,525 | ---- | M] () -- C:\Users\Nathan\AppData\Local\3d9f906e-fc35-40e6-919c-4cd324017d36.crx
[2013/05/06 20:14:00 | 000,000,886 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/06 20:08:00 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2013/05/06 20:07:25 | 000,019,760 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/06 20:07:25 | 000,019,760 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/06 19:37:05 | 000,631,496 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2013/05/06 19:37:05 | 000,111,588 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2013/05/06 19:35:05 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2013/05/06 18:46:20 | 000,000,882 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/06 18:46:10 | 3116,646,400 | -HS- | M] () -- C:\hiberfil.sys
[2013/05/05 22:35:56 | 000,131,944 | ---- | M] () -- C:\Users\Nathan\Desktop\guide pic.jpg
[2013/05/04 19:59:27 | 000,002,792 | ---- | M] () -- C:\Users\Nathan\Desktop\EPISODE 4 FINAL PROJECT USE THIS.wlmp
[2013/05/04 19:18:38 | 1832,351,659 | ---- | M] () -- C:\Users\Nathan\Desktop\Episode 4 FINAL.wmv
[2013/05/03 23:19:11 | 000,002,768 | ---- | M] () -- C:\Users\Nathan\Desktop\EPISODE 4.wlmp
[2013/05/03 23:11:48 | 1830,862,942 | ---- | M] () -- C:\Users\Nathan\Desktop\Episode 4- Creeks.wmv
[2013/05/02 02:06:08 | 000,238,872 | ---- | M] (Microsoft Corporation) -- C:\windows\System32\MpSigStub.exe
[2013/05/01 19:44:05 | 000,081,587 | ---- | M] () -- C:\Users\Nathan\Desktop\lol.png
[2013/04/30 10:48:11 | 000,048,103 | ---- | M] () -- C:\Users\Nathan\Desktop\f1020[1].jpg
[2013/04/28 17:36:35 | 000,038,077 | ---- | M] () -- C:\Users\Nathan\Desktop\f850[1].jpg
[2013/04/28 17:07:24 | 000,023,790 | ---- | M] () -- C:\Users\Nathan\Desktop\$(KGrHqIOKosFFz43uMFiBRdL0GrzPw~~60_12[1].jpg
[2013/04/28 17:04:12 | 000,037,773 | ---- | M] () -- C:\Users\Nathan\Desktop\$T2eC16R,!)cE9s4PtHWdBRLFByvUkg~~60_12[1].jpg
[2013/04/27 23:31:09 | 000,000,324 | ---- | M] () -- C:\windows\tasks\HPCeeScheduleForNathan.job
[2013/04/27 21:02:54 | 000,000,282 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_UPDATES.job
[2013/04/25 17:05:09 | 000,155,600 | ---- | M] () -- C:\Users\Nathan\Desktop\guide pic 2.jpg
[2013/04/19 22:06:32 | 000,016,062 | ---- | M] () -- C:\Users\Nathan\Desktop\Best Carch Tooth!.jpg
[2013/04/19 17:21:00 | 000,338,789 | ---- | M] () -- C:\Users\Nathan\Desktop\Crinoids.jpg
[2013/04/17 20:48:10 | 000,000,266 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2013/04/17 19:39:33 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Express Burn.lnk
[2013/04/16 15:33:18 | 000,095,288 | ---- | M] () -- C:\Users\Nathan\Desktop\JurassicBanner[1].jpg
[2013/04/15 16:50:55 | 004,301,348 | ---- | M] () -- C:\Users\Nathan\Desktop\Promises- Skrillex Remix.mp3
[2013/04/15 16:50:46 | 004,512,973 | ---- | M] () -- C:\Users\Nathan\Desktop\Levels- Skrillex Remix.mp3
[2013/04/15 16:48:20 | 003,124,721 | ---- | M] () -- C:\Users\Nathan\Desktop\Let The Bass Kick.mp3
[2013/04/15 16:48:01 | 012,089,822 | ---- | M] () -- C:\Users\Nathan\Desktop\Summit.mp3
[2013/04/15 16:11:58 | 003,381,708 | ---- | M] () -- C:\Users\Nathan\Desktop\Father Said.mp3
[2013/04/12 07:26:43 | 000,002,129 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/04/11 12:53:38 | 000,409,760 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2013/04/07 07:13:51 | 000,011,207 | ---- | M] () -- C:\Users\Nathan\Desktop\244376_1282574945[1].jpg

========== Files Created - No Company Name ==========

[2013/05/04 19:58:09 | 000,002,792 | ---- | C] () -- C:\Users\Nathan\Desktop\EPISODE 4 FINAL PROJECT USE THIS.wlmp
[2013/05/04 18:00:32 | 1832,351,659 | ---- | C] () -- C:\Users\Nathan\Desktop\Episode 4 FINAL.wmv
[2013/05/03 23:19:11 | 000,002,768 | ---- | C] () -- C:\Users\Nathan\Desktop\EPISODE 4.wlmp
[2013/05/03 22:00:20 | 1830,862,942 | ---- | C] () -- C:\Users\Nathan\Desktop\Episode 4- Creeks.wmv
[2013/05/01 19:44:05 | 000,081,587 | ---- | C] () -- C:\Users\Nathan\Desktop\lol.png
[2013/04/28 17:35:35 | 000,038,077 | ---- | C] () -- C:\Users\Nathan\Desktop\f850[1].jpg
[2013/04/28 17:30:03 | 000,048,103 | ---- | C] () -- C:\Users\Nathan\Desktop\f1020[1].jpg
[2013/04/28 17:04:49 | 000,023,790 | ---- | C] () -- C:\Users\Nathan\Desktop\$(KGrHqIOKosFFz43uMFiBRdL0GrzPw~~60_12[1].jpg
[2013/04/28 17:01:59 | 000,037,773 | ---- | C] () -- C:\Users\Nathan\Desktop\$T2eC16R,!)cE9s4PtHWdBRLFByvUkg~~60_12[1].jpg
[2013/04/25 17:05:09 | 000,155,600 | ---- | C] () -- C:\Users\Nathan\Desktop\guide pic 2.jpg
[2013/04/25 16:55:15 | 000,131,944 | ---- | C] () -- C:\Users\Nathan\Desktop\guide pic.jpg
[2013/04/19 22:06:31 | 000,016,062 | ---- | C] () -- C:\Users\Nathan\Desktop\Best Carch Tooth!.jpg
[2013/04/19 17:20:14 | 000,338,789 | ---- | C] () -- C:\Users\Nathan\Desktop\Crinoids.jpg
[2013/04/17 19:39:33 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Express Burn.lnk
[2013/04/17 19:39:32 | 000,001,128 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Burn.lnk
[2013/04/16 15:32:10 | 000,095,288 | ---- | C] () -- C:\Users\Nathan\Desktop\JurassicBanner[1].jpg
[2013/04/15 16:08:22 | 003,381,708 | ---- | C] () -- C:\Users\Nathan\Desktop\Father Said.mp3
[2013/04/15 16:01:10 | 004,512,973 | ---- | C] () -- C:\Users\Nathan\Desktop\Levels- Skrillex Remix.mp3
[2013/04/15 15:58:01 | 004,301,348 | ---- | C] () -- C:\Users\Nathan\Desktop\Promises- Skrillex Remix.mp3
[2013/04/07 07:08:00 | 000,011,207 | ---- | C] () -- C:\Users\Nathan\Desktop\244376_1282574945[1].jpg
[2013/03/17 21:33:59 | 000,160,768 | ---- | C] () -- C:\Users\Nathan\AppData\Roaming\drent.dll
[2013/03/02 22:35:31 | 000,001,030 | ---- | C] () -- C:\Users\Nathan\3206055.exe
[2012/12/20 11:05:14 | 000,006,525 | ---- | C] () -- C:\Users\Nathan\AppData\Local\3d9f906e-fc35-40e6-919c-4cd324017d36.crx
[2012/09/28 08:08:06 | 000,006,523 | ---- | C] () -- C:\Users\Nathan\AppData\Local\chromeupdate.crx
[2012/09/13 20:46:45 | 000,380,928 | ---- | C] () -- C:\windows\System32\lame_enc.dll
[2012/01/11 22:34:11 | 000,098,304 | ---- | C] () -- C:\Users\Nathan\AppData\Roaming\skype.dat
[2011/09/01 18:13:48 | 000,040,448 | ---- | C] () -- C:\windows\System32\REGOBJ.DLL
[2011/08/05 17:40:48 | 000,000,088 | RHS- | C] () -- C:\ProgramData\7AF8E60013.sys
[2011/08/05 17:40:43 | 000,002,828 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys

========== ZeroAccess Check ==========

[2013/05/06 17:40:41 | 000,002,048 | -HS- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\@
[2013/05/06 17:40:41 | 000,115,200 | -HS- | M] (Корпорация Майкрософт) -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\n
[2012/09/28 08:07:04 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\L
[2013/05/06 18:24:24 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U
[2013/05/06 18:24:24 | 000,000,928 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\00000001.@
[2012/10/28 14:16:12 | 000,011,776 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\80000000.@
[2013/05/06 17:40:47 | 000,022,016 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\800000cb.@
[2009/07/14 14:42:31 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 14:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 11:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/01/25 12:05:21 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Afeb
[2013/04/03 15:35:33 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Audacity
[2012/09/06 21:23:09 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Canon
[2012/12/16 07:29:14 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\dll-files.com
[2013/04/02 16:48:49 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Free Sound Recorder
[2013/03/11 06:53:15 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\FunnyGames
[2012/05/22 09:19:37 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\ICAClient
[2013/01/25 12:05:21 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Moxu
[2013/04/04 05:59:33 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Moys
[2013/04/09 14:39:02 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Origs
[2013/04/02 16:12:42 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Recordpad
[2013/05/06 18:45:18 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Rykua
[2012/05/22 09:11:43 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\TeamViewer
[2012/09/28 08:29:41 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Tific
[2013/04/01 17:48:30 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\TotalRecorder
[2013/05/06 19:47:02 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Udtili

========== Purity Check ==========



< End of report >

Pretty much said all the info above, although i will say that when the lock screen first appeared i was so terrified!!!!!!!!!!!! Thought my life was officially over...

I know it's a virus now but the shock still hasn't worn off yet

Thanks for your help i appreciate it!!!!!!!!![/u]

EDIT*- SORRY I POSTED THE TOPIC TWICE, I THOUGHT IT DIDNT WORK THE FIRST TIME AS IT DIDNT SHOW UP IN THE THREADS LIST STRAIGHT AWAY
 

Fiery

Level 1
Jan 11, 2011
2,007
Hi and welcome to MalwareTips! :)

I'm Fiery and I would gladly assist you in removing the malware on your computer.

Before we start:
  • Note that the removal process is not immediate. Depending on the severity of your infection, it could take a long time.
  • Malware removal can be dangerous. I cannot guarantee the safety of your system as malware can be unpredictable. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system. Therefore, I would advise you to backup all your important files before we start.
  • Please be patient and stay with me until I give you the green lights and inform you that your PC is clean.
  • Some tools may be flagged by your antivirus as harmful. Rest assure that ALL the tools we use are safe, the detections are false positives.
  • The absence of symptoms does not mean your PC is fully disinfected.
  • If you are unclear about the instructions, please stop and ask. Following the steps in the order that I post them in is vital.
  • Lastly, if you have requested help on other sites, that will delay and hinder the removal process. Please only stick to one site.

<hr>
Don't be scared, that is exactly what the bad guys want you to feel and all they are trying to do is scare you to pay money.

You PC is badly infected, there's tons of malware to remove.

Open OTL. Under custom scan/fixes, copy and paste the following:

:OTL
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.2.1.5:8080
O4 - HKLM..\Run: [drent] C:\Users\Nathan\AppData\Roaming\drent.dll ()
O4 - HKCU..\Run: [Opupmewa] C:\Users\Nathan\AppData\Roaming\Moxu\niakf.exe ()
O4 - HKCU..\Run: [Ovmeipodek] C:\Users\Nathan\AppData\Roaming\Rykua\etiqy.exe ()
O4 - HKLM..\Run: [sedgf] C:\Users\Nathan\AppData\Roaming\sedgf.dll (S3 Graphics Co., Ltd.)
O4 - HKLM..\Run: [mosit] C:\Users\Nathan\AppData\Roaming\mosit.dll (SiliconMotion)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C474A887-AC2D-4C69-A8B3-6D3BD482EBBC}: DhcpNameServer = 10.2.20.10 10.2.21.10
[2012/12/20 11:04:16 | 000,165,376 | ---- | C] (Donkey) -- C:\Users\Nathan\AppData\Roaming\windw.dll
2013/03/02 22:35:31 | 000,001,030 | ---- | C] () -- C:\Users\Nathan\3206055.exe
[2012/12/20 11:05:14 | 000,006,525 | ---- | C] () -- C:\Users\Nathan\AppData\Local\3d9f906e-fc35-40e6-919c-4cd324017d36.crx
[2012/09/28 08:08:06 | 000,006,523 | ---- | C] () -- C:\Users\Nathan\AppData\Local\chromeupdate.crx
[2012/01/11 22:34:11 | 000,098,304 | ---- | C] () -- C:\Users\Nathan\AppData\Roaming\skype.dat
[2011/09/01 18:13:48 | 000,040,448 | ---- | C] () -- C:\windows\System32\REGOBJ.DLL
[2013/05/06 17:40:41 | 000,002,048 | -HS- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\@
[2013/05/06 17:40:41 | 000,115,200 | -HS- | M] (Корпорация Майкрософт) -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\n
[2012/09/28 08:07:04 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\L
[2013/05/06 18:24:24 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U
[2013/05/06 18:24:24 | 000,000,928 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\00000001.@
[2012/10/28 14:16:12 | 000,011,776 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\80000000.@
[2013/05/06 17:40:47 | 000,022,016 | ---- | M] () -- C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\800000cb.@
[2013/01/25 12:05:21 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Afeb
[2013/01/25 12:05:21 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Moxu
[2013/04/04 05:59:33 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Moys
[2013/04/09 14:39:02 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Origs
[2013/05/06 18:45:18 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Rykua
[2013/05/06 19:47:02 | 000,000,000 | ---D | M] -- C:\Users\Nathan\AppData\Roaming\Udtili

:Files
ipconfig /flushdns /c

:Commands
[EMPTYTEMP]
[RESETHOSTS]

Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.

Download & SAVE to your Desktop RogueKiller or from here
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select Run as Administrator to start
  • Wait until Prescan has finished, then click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • Click delete and wait until it saids deleting finished
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
    Exit/Close RogueKiller+

Download TDSSkiller from here
  • Double-Click on TDSSKiller.exe to run the application
  • When TDSSkiller opens, click change parameters , check the box next to Loaded modules . A reboot will be required.
  • After reboot, TDSSKiller will run again. Click Change parameters again and make sure everything is checked.
    clip.jpg
  • click Start scan .
  • If a suspicious object is detected, the default action will be Skip, click on Continue. (If it saids TDL4/TDSS file system, select delete)
  • If malicious objects are found, ensure Cure (default) is selected, then click Continue and Reboot now to finish the cleaning process.

Post the log after (usually C:\ folder in the form of TDSSKiller.[Version]_[Date]_[Time]_log.txt
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
Here is the new OTL log as per your first step in the removal process written above. I am currently working on the following steps right now.

All processes killed
========== OTL ==========
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\drent deleted successfully.
C:\Users\Nathan\AppData\Roaming\drent.dll moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Opupmewa deleted successfully.
C:\Users\Nathan\AppData\Roaming\Moxu\niakf.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Ovmeipodek deleted successfully.
C:\Users\Nathan\AppData\Roaming\Rykua\etiqy.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\sedgf deleted successfully.
C:\Users\Nathan\AppData\Roaming\sedgf.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\mosit deleted successfully.
C:\Users\Nathan\AppData\Roaming\mosit.dll moved successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C474A887-AC2D-4C69-A8B3-6D3BD482EBBC}\\DhcpNameServer| /E : value set successfully!
C:\Users\Nathan\AppData\Roaming\windw.dll moved successfully.
C:\Users\Nathan\AppData\Local\3d9f906e-fc35-40e6-919c-4cd324017d36.crx moved successfully.
C:\Users\Nathan\AppData\Local\chromeupdate.crx moved successfully.
C:\Users\Nathan\AppData\Roaming\skype.dat moved successfully.
C:\Windows\System32\REGOBJ.DLL moved successfully.
C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\@ moved successfully.
C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\n moved successfully.
C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\L folder moved successfully.
C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U folder moved successfully.
File C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\00000001.@ not found.
File C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\80000000.@ not found.
File C:\$Recycle.Bin\S-1-5-18\$0ed46d269463da8412b7eea80fcdf09e\U\800000cb.@ not found.
C:\Users\Nathan\AppData\Roaming\Afeb folder moved successfully.
C:\Users\Nathan\AppData\Roaming\Moxu folder moved successfully.
C:\Users\Nathan\AppData\Roaming\Moys folder moved successfully.
C:\Users\Nathan\AppData\Roaming\Origs folder moved successfully.
C:\Users\Nathan\AppData\Roaming\Rykua folder moved successfully.
C:\Users\Nathan\AppData\Roaming\Udtili folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Nathan\Downloads\cmd.bat deleted successfully.
C:\Users\Nathan\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Nathan
->Temp folder emptied: 3443896462 bytes
->Temporary Internet Files folder emptied: 1486778862 bytes
->Java cache emptied: 17960984 bytes
->Google Chrome cache emptied: 287844857 bytes
->Flash cache emptied: 8772553 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2005827042 bytes
RecycleBin emptied: 2529195864 bytes

Total Files Cleaned = 9,327.00 mb

C:\windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 05072013_141947

Files\Folders moved on Reboot...
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
File\Folder C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T30B2BH1\bind[1].htm not found!
File\Folder C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T30B2BH1\bind[2].htm not found!
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SX1V43MM\0[1].htm moved successfully.
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SS05V6D3\recentposts[1].htm moved successfully.
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JC8SA7ZC\d=1[2].htm moved successfully.
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JC8SA7ZC\tweet_button.1367516458[1].htm moved successfully.
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3WY37U4\ifr[1].htm moved successfully.
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3WY37U4\ifr[2].htm moved successfully.
C:\Users\Nathan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A4V6DZ4T\fastbutton[1].htm moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
Hello again. Here is the result of my Roguekiller scan, as per your second bit of instructions. I'd also like to add that DLL FILES FIXER has stopped showing up after the first scan i did with OTL. Yipee!

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : Nathan [Admin rights]
Mode : Remove -- Date : 05/07/2013 15:16:45
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 10 ¤¤¤
[RUN][SUSP PATH] HKCU\[...]\Run : Opupmewa (C:\Users\Nathan\AppData\Roaming\Moxu\niakf.exe) [x] -> DELETED
[RUN][SUSP PATH] HKCU\[...]\Run : Ovmeipodek (C:\Users\Nathan\AppData\Roaming\Rykua\etiqy.exe) [x] -> DELETED
[RUN][SUSP PATH] HKLM\[...]\Run : mosit ("C:\Windows\System32\rundll32.exe" "C:\Users\Nathan\AppData\Roaming\mosit.dll",ImportWarning) [7] -> DELETED
[TASK][ROGUE ST] 0 : c:\program files\internet explorer\iexplore.exe -> DELETED
[TASK][ROGUE ST] 4783 : wscript.exe C:\Users\Nathan\AppData\Local\Temp\launchie.vbs //B -> DELETED
[HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED (2)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
[SCREENSV][SUSP PATH] HKCU\[...]\Desktop (C:\Windows\WLXPGSS.SCR) [7] -> REPLACED (C:\windows\system32\logon.scr)

¤¤¤ Particular Files / Folders: ¤¤¤
[ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-21-1274404661-877237858-3025515097-1001\$0ed46d269463da8412b7eea80fcdf09e\n [-] --> REMOVED
[ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-1274404661-877237858-3025515097-1001\$0ed46d269463da8412b7eea80fcdf09e\@ [-] --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-21-1274404661-877237858-3025515097-1001\$0ed46d269463da8412b7eea80fcdf09e\U --> REMOVED
[ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-21-1274404661-877237858-3025515097-1001\$0ed46d269463da8412b7eea80fcdf09e\L --> REMOVED

¤¤¤ Driver : [LOADED] ¤¤¤
SSDT[13] : NtAlertResumeThread @ 0x82EDEDA5 -> HOOKED (Unknown @ 0x886F7818)
SSDT[14] : NtAlertThread @ 0x82E31CC7 -> HOOKED (Unknown @ 0x886F78F8)
SSDT[19] : NtAllocateVirtualMemory @ 0x82E2ACBC -> HOOKED (Unknown @ 0x886F95E0)
SSDT[22] : NtAlpcConnectPort @ 0x82E7656E -> HOOKED (Unknown @ 0x8865A360)
SSDT[43] : NtAssignProcessToJobObject @ 0x82E000BE -> HOOKED (Unknown @ 0x8867C2F0)
SSDT[74] : NtCreateMutant @ 0x82E1134C -> HOOKED (Unknown @ 0x886F74D0)
SSDT[86] : NtCreateSymbolicLinkObject @ 0x82E029C6 -> HOOKED (Unknown @ 0x881E00F0)
SSDT[87] : NtCreateThread @ 0x82EDCFE2 -> HOOKED (Unknown @ 0x886F9AE8)
SSDT[88] : NtCreateThreadEx @ 0x82E7149B -> HOOKED (Unknown @ 0x88686F38)
SSDT[96] : NtDebugActiveProcess @ 0x82EAEEAA -> HOOKED (Unknown @ 0x886EA140)
SSDT[111] : NtDuplicateObject @ 0x82E32761 -> HOOKED (Unknown @ 0x886F97B0)
SSDT[131] : NtFreeVirtualMemory @ 0x82CB981C -> HOOKED (Unknown @ 0x886F7008)
SSDT[145] : NtImpersonateAnonymousToken @ 0x82DF6962 -> HOOKED (Unknown @ 0x886F7658)
SSDT[147] : NtImpersonateThread @ 0x82E7A962 -> HOOKED (Unknown @ 0x886F7738)
SSDT[155] : NtLoadDriver @ 0x82DC6C32 -> HOOKED (Unknown @ 0x8855A168)
SSDT[168] : NtMapViewOfSection @ 0x82E475F1 -> HOOKED (Unknown @ 0x886F7F28)
SSDT[177] : NtOpenEvent @ 0x82E10D48 -> HOOKED (Unknown @ 0x886F73F0)
SSDT[190] : NtOpenProcess @ 0x82E12B93 -> HOOKED (Unknown @ 0x886F9990)
SSDT[191] : NtOpenProcessToken @ 0x82E6536F -> HOOKED (Unknown @ 0x886F96D0)
SSDT[194] : NtOpenSection @ 0x82E6A9EB -> HOOKED (Unknown @ 0x886F71B0)
SSDT[198] : NtOpenThread @ 0x82E5F0EE -> HOOKED (Unknown @ 0x886F98A0)
SSDT[215] : NtProtectVirtualMemory @ 0x82E43651 -> HOOKED (Unknown @ 0x8861F2E0)
SSDT[304] : NtResumeThread @ 0x82E716C2 -> HOOKED (Unknown @ 0x886F79D8)
SSDT[316] : NtSetContextThread @ 0x82EDE851 -> HOOKED (Unknown @ 0x886F7C78)
SSDT[333] : NtSetInformationProcess @ 0x82E39875 -> HOOKED (Unknown @ 0x886F7D58)
SSDT[350] : NtSetSystemInformation @ 0x82E4F37A -> HOOKED (Unknown @ 0x886F7068)
SSDT[366] : NtSuspendProcess @ 0x82EDECDF -> HOOKED (Unknown @ 0x886F7310)
SSDT[367] : NtSuspendThread @ 0x82E9619B -> HOOKED (Unknown @ 0x886F7AB8)
SSDT[370] : NtTerminateProcess @ 0x82E5BD86 -> HOOKED (Unknown @ 0x8868C428)
SSDT[371] : NtTerminateThread @ 0x82E7969B -> HOOKED (Unknown @ 0x886F7B98)
SSDT[385] : NtUnmapViewOfSection @ 0x82E659AA -> HOOKED (Unknown @ 0x886F7E48)
SSDT[399] : NtWriteVirtualMemory @ 0x82E60A83 -> HOOKED (Unknown @ 0x886F94F0)
S_SSDT[318] : NtUserAttachThreadInput -> HOOKED (Unknown @ 0x88AB49F0)
S_SSDT[402] : NtUserGetAsyncKeyState -> HOOKED (Unknown @ 0x881C9E00)
S_SSDT[434] : NtUserGetKeyboardState -> HOOKED (Unknown @ 0x88211E00)
S_SSDT[436] : NtUserGetKeyState -> HOOKED (Unknown @ 0x88A7B240)
S_SSDT[448] : NtUserGetRawInputData -> HOOKED (Unknown @ 0x882180A0)
S_SSDT[490] : NtUserMessageCall -> HOOKED (Unknown @ 0x88219968)
S_SSDT[508] : NtUserPostMessage -> HOOKED (Unknown @ 0x88219B08)
S_SSDT[509] : NtUserPostThreadMessage -> HOOKED (Unknown @ 0x88219A38)
S_SSDT[585] : NtUserSetWindowsHookEx -> HOOKED (Unknown @ 0x8992EC80)
S_SSDT[588] : NtUserSetWinEventHook -> HOOKED (Unknown @ 0x882156F0)

¤¤¤ Infection : ZeroAccess ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\windows\system32\drivers\etc\hosts

ÿþ1

¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: WDC WD5000BEVT-60A0RT0 +++++
--- User ---
[MBR] d3797c914e7d11e39b3a508ff2024a7a
[BSP] f74607e4580fd0fd260b34b18baedc06 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 300 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 616448 | Size: 459229 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 941117440 | Size: 15360 Mo
3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 972574720 | Size: 2043 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2]_D_05072013_02d1516.txt >>
RKreport[1]_S_05072013_02d1514.txt ; RKreport[2]_D_05072013_02d1516.txt
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
Ok i tried the last step you posted, the TDSSKILLER scan. It found 4 'threats' but i couldn't find the specific options you mentioned. I left all 4 threats (didn't use the word suspicious or malicious) with 'Skip' next to them and clicked continue, upon which nothing else happened. The window closed, it didn't ask me to reboot or anything to confirm that it had removed the threats.

I tried it again and it found the same 4 threats again. Should i just delete them?
 

Fiery

Level 1
Jan 11, 2011
2,007
Paleoworld-101 said:
I tried it again and it found the same 4 threats again. Should I just delete them?

No, do not delete any, the tool detects unsigned drivers but they can be legitimate files. If you delete them, your system may become unstable.

Can you attach the TDSSKiller logs? They should be in the C:\ directory.

To attach a file, click New Reply, scroll down to the Attachments section and click Choose File. Select the TDSSKiller logs and click Add Attachment. Once they are upload, click Post Reply
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
Is this it?

16:36:55.0427 9796 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42
16:36:56.0504 9796 ============================================================
16:36:56.0504 9796 Current date / time: 2013/05/08 16:36:56.0504
16:36:56.0504 9796 SystemInfo:
16:36:56.0504 9796
16:36:56.0504 9796 OS Version: 6.1.7601 ServicePack: 1.0
16:36:56.0504 9796 Product type: Workstation
16:36:56.0504 9796 ComputerName: NATHANS-LAPTOP
16:36:56.0504 9796 UserName: Nathan
16:36:56.0504 9796 Windows directory: C:\windows
16:36:56.0504 9796 System windows directory: C:\windows
16:36:56.0504 9796 Processor architecture: Intel x86
16:36:56.0504 9796 Number of processors: 2
16:36:56.0504 9796 Page size: 0x1000
16:36:56.0504 9796 Boot type: Normal boot
16:36:56.0504 9796 ============================================================
16:36:56.0613 9796 BG loaded
16:36:56.0940 9796 Drive \Device\Harddisk0\DR0 - Size: 0x7470C06000 (465.76 Gb), SectorSize: 0x200, Cylinders: 0xED81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
16:36:56.0940 9796 ============================================================
16:36:56.0940 9796 \Device\Harddisk0\DR0:
16:36:56.0940 9796 MBR partitions:
16:36:56.0940 9796 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x96000
16:36:56.0940 9796 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x96800, BlocksNum 0x380EE800
16:36:56.0940 9796 \Device\Harddisk0\DR0\Partition3: MBR, Type 0x7, StartLBA 0x38185000, BlocksNum 0x1E00000
16:36:56.0940 9796 \Device\Harddisk0\DR0\Partition4: MBR, Type 0xC, StartLBA 0x39F85000, BlocksNum 0x3FD800
16:36:56.0940 9796 ============================================================
16:36:56.0956 9796 C: <-> \Device\Harddisk0\DR0\Partition2
16:36:56.0987 9796 F: <-> \Device\Harddisk0\DR0\Partition4
16:36:56.0987 9796 ============================================================
16:36:56.0987 9796 Initialize success
16:36:56.0987 9796 ============================================================
16:37:25.0769 6164 ============================================================
16:37:25.0769 6164 Scan started
16:37:25.0769 6164 Mode: Manual; SigCheck; TDLFS;
16:37:25.0785 6164 ============================================================
16:37:26.0003 6164 ================ Scan system memory ========================
16:37:26.0003 6164 System memory - ok
16:37:26.0003 6164 ================ Scan services =============================
16:37:26.0159 6164 [ 1B133875B8AA8AC48969BD3458AFE9F5 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
16:37:26.0253 6164 1394ohci - ok
16:37:26.0315 6164 [ CEA80C80BED809AA0DA6FEBC04733349 ] ACPI C:\windows\system32\drivers\ACPI.sys
16:37:26.0346 6164 ACPI - ok
16:37:26.0393 6164 [ 1EFBC664ABFF416D1D07DB115DCB264F ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
16:37:26.0456 6164 AcpiPmi - ok
16:37:26.0565 6164 [ EA856F4A46320389D1899B2CAA7BF40F ] AdobeFlashPlayerUpdateSvc C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
16:37:26.0596 6164 AdobeFlashPlayerUpdateSvc - ok
16:37:26.0658 6164 [ 21E785EBD7DC90A06391141AAC7892FB ] adp94xx C:\windows\system32\DRIVERS\adp94xx.sys
16:37:26.0674 6164 adp94xx - ok
16:37:26.0705 6164 [ 0C676BC278D5B59FF5ABD57BBE9123F2 ] adpahci C:\windows\system32\DRIVERS\adpahci.sys
16:37:26.0721 6164 adpahci - ok
16:37:26.0752 6164 [ 7C7B5EE4B7B822EC85321FE23A27DB33 ] adpu320 C:\windows\system32\DRIVERS\adpu320.sys
16:37:26.0768 6164 adpu320 - ok
16:37:26.0814 6164 [ 8B5EEFEEC1E6D1A72A06C526628AD161 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
16:37:26.0861 6164 AeLookupSvc - ok
16:37:26.0970 6164 [ 827DBC22C96EECF6D36A13162FABAFD3 ] AESTFilters C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\aestsrv.exe
16:37:27.0033 6164 AESTFilters - ok
16:37:27.0095 6164 [ 9EBBBA55060F786F0FCAA3893BFA2806 ] AFD C:\windows\system32\drivers\afd.sys
16:37:27.0158 6164 AFD - ok
16:37:27.0204 6164 [ 7E10E3BB9B258AD8A9300F91214D67B9 ] AgereSoftModem C:\windows\system32\DRIVERS\AGRSM.sys
16:37:27.0251 6164 AgereSoftModem - ok
16:37:27.0298 6164 [ 507812C3054C21CEF746B6EE3D04DD6E ] agp440 C:\windows\system32\drivers\agp440.sys
16:37:27.0314 6164 agp440 - ok
16:37:27.0376 6164 [ 8B30250D573A8F6B4BD23195160D8707 ] aic78xx C:\windows\system32\DRIVERS\djsvs.sys
16:37:27.0392 6164 aic78xx - ok
16:37:27.0438 6164 [ 18A54E132947CD98FEA9ACCC57F98F13 ] ALG C:\windows\System32\alg.exe
16:37:27.0485 6164 ALG - ok
16:37:27.0548 6164 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44 ] aliide C:\windows\system32\drivers\aliide.sys
16:37:27.0563 6164 aliide - ok
16:37:27.0626 6164 [ 3C6600A0696E90A463771C7422E23AB5 ] amdagp C:\windows\system32\drivers\amdagp.sys
16:37:27.0641 6164 amdagp - ok
16:37:27.0672 6164 [ CD5914170297126B6266860198D1D4F0 ] amdide C:\windows\system32\drivers\amdide.sys
16:37:27.0688 6164 amdide - ok
16:37:27.0735 6164 [ 00DDA200D71BAC534BF56A9DB5DFD666 ] AmdK8 C:\windows\system32\DRIVERS\amdk8.sys
16:37:27.0782 6164 AmdK8 - ok
16:37:27.0797 6164 [ 3CBF30F5370FDA40DD3E87DF38EA53B6 ] AmdPPM C:\windows\system32\DRIVERS\amdppm.sys
16:37:27.0828 6164 AmdPPM - ok
16:37:27.0875 6164 [ D320BF87125326F996D4904FE24300FC ] amdsata C:\windows\system32\drivers\amdsata.sys
16:37:27.0891 6164 amdsata - ok
16:37:27.0922 6164 [ EA43AF0C423FF267355F74E7A53BDABA ] amdsbs C:\windows\system32\DRIVERS\amdsbs.sys
16:37:27.0938 6164 amdsbs - ok
16:37:27.0953 6164 [ 46387FB17B086D16DEA267D5BE23A2F2 ] amdxata C:\windows\system32\drivers\amdxata.sys
16:37:27.0969 6164 amdxata - ok
16:37:28.0016 6164 [ AEA177F783E20150ACE5383EE368DA19 ] AppID C:\windows\system32\drivers\appid.sys
16:37:28.0140 6164 AppID - ok
16:37:28.0203 6164 [ 62A9C86CB6085E20DB4823E4E97826F5 ] AppIDSvc C:\windows\System32\appidsvc.dll
16:37:28.0250 6164 AppIDSvc - ok
16:37:28.0281 6164 [ FB1959012294D6AD43E5304DF65E3C26 ] Appinfo C:\windows\System32\appinfo.dll
16:37:28.0312 6164 Appinfo - ok
16:37:28.0452 6164 [ A5299D04ED225D64CF07A568A3E1BF8C ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
16:37:28.0484 6164 Apple Mobile Device - ok
16:37:28.0530 6164 [ 2932004F49677BD84DBC72EDB754FFB3 ] arc C:\windows\system32\DRIVERS\arc.sys
16:37:28.0562 6164 arc - ok
16:37:28.0577 6164 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7 ] arcsas C:\windows\system32\DRIVERS\arcsas.sys
16:37:28.0593 6164 arcsas - ok
16:37:28.0655 6164 [ ADD2ADE1C2B285AB8378D2DAAF991481 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
16:37:28.0780 6164 AsyncMac - ok
16:37:28.0827 6164 [ 338C86357871C167A96AB976519BF59E ] atapi C:\windows\system32\drivers\atapi.sys
16:37:28.0858 6164 atapi - ok
16:37:28.0936 6164 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
16:37:28.0998 6164 AudioEndpointBuilder - ok
16:37:29.0014 6164 [ CE3B4E731638D2EF62FCB419BE0D39F0 ] Audiosrv C:\windows\System32\Audiosrv.dll
16:37:29.0045 6164 Audiosrv - ok
16:37:29.0108 6164 [ 6E30D02AAC9CAC84F421622E3A2F6178 ] AxInstSV C:\windows\System32\AxInstSV.dll
16:37:29.0170 6164 AxInstSV - ok
16:37:29.0232 6164 [ 1A231ABEC60FD316EC54C66715543CEC ] b06bdrv C:\windows\system32\DRIVERS\bxvbdx.sys
16:37:29.0279 6164 b06bdrv - ok
16:37:29.0326 6164 [ BD8869EB9CDE6BBE4508D869929869EE ] b57nd60x C:\windows\system32\DRIVERS\b57nd60x.sys
16:37:29.0342 6164 b57nd60x - ok
16:37:29.0388 6164 [ EE1E9C3BB8228AE423DD38DB69128E71 ] BDESVC C:\windows\System32\bdesvc.dll
16:37:29.0420 6164 BDESVC - ok
16:37:29.0435 6164 [ 505506526A9D467307B3C393DEDAF858 ] Beep C:\windows\system32\drivers\Beep.sys
16:37:29.0482 6164 Beep - ok
16:37:29.0529 6164 [ 1E2BAC209D184BB851E1A187D8A29136 ] BFE C:\windows\System32\bfe.dll
16:37:29.0591 6164 BFE - ok
16:37:29.0732 6164 [ 163340A63F197C91D65CA9CE4B5811F7 ] BHDrvx86 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20110929.001\BHDrvx86.sys
16:37:29.0778 6164 BHDrvx86 - ok
16:37:29.0825 6164 [ E585445D5021971FAE10393F0F1C3961 ] BITS C:\windows\System32\qmgr.dll
16:37:29.0919 6164 BITS - ok
16:37:29.0950 6164 [ 2287078ED48FCFC477B05B20CF38F36F ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
16:37:29.0997 6164 blbdrive - ok
16:37:30.0122 6164 [ FAF2AAAC84D952B3077D13220A0606A5 ] Bluetooth Device Manager C:\Program Files\Motorola\Bluetooth\devmgrsrv.exe
16:37:30.0246 6164 Bluetooth Device Manager - ok
16:37:30.0324 6164 [ 1733DD1E2B722AB476571DE53C6A6367 ] Bluetooth Media Service C:\Program Files\Motorola\Bluetooth\audiosrv.exe
16:37:30.0356 6164 Bluetooth Media Service - ok
16:37:30.0371 6164 [ 55FBB6E578BFB2327BA41B3E526CCE1A ] Bluetooth OBEX Service C:\Program Files\Motorola\Bluetooth\obexsrv.exe
16:37:30.0402 6164 Bluetooth OBEX Service - ok
16:37:30.0480 6164 [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
16:37:30.0512 6164 Bonjour Service - ok
16:37:30.0558 6164 [ 8F2DA3028D5FCBD1A060A3DE64CD6506 ] bowser C:\windows\system32\DRIVERS\bowser.sys
16:37:30.0621 6164 bowser - ok
16:37:30.0652 6164 [ 9F9ACC7F7CCDE8A15C282D3F88B43309 ] BrFiltLo C:\windows\system32\DRIVERS\BrFiltLo.sys
16:37:30.0714 6164 BrFiltLo - ok
16:37:30.0730 6164 [ 56801AD62213A41F6497F96DEE83755A ] BrFiltUp C:\windows\system32\DRIVERS\BrFiltUp.sys
16:37:30.0761 6164 BrFiltUp - ok
16:37:30.0808 6164 [ 3DAA727B5B0A45039B0E1C9A211B8400 ] Browser C:\windows\System32\browser.dll
16:37:30.0870 6164 Browser - ok
16:37:30.0902 6164 [ 845B8CE732E67F3B4133164868C666EA ] Brserid C:\windows\System32\Drivers\Brserid.sys
16:37:30.0933 6164 Brserid - ok
16:37:30.0948 6164 [ 203F0B1E73ADADBBB7B7B1FABD901F6B ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
16:37:30.0980 6164 BrSerWdm - ok
16:37:31.0011 6164 [ BD456606156BA17E60A04E18016AE54B ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
16:37:31.0042 6164 BrUsbMdm - ok
16:37:31.0073 6164 [ AF72ED54503F717A43268B3CC5FAEC2E ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
16:37:31.0089 6164 BrUsbSer - ok
16:37:31.0120 6164 [ 2865A5C8E98C70C605F417908CEBB3A4 ] BthEnum C:\windows\system32\drivers\BthEnum.sys
16:37:31.0198 6164 BthEnum - ok
16:37:31.0214 6164 [ ED3DF7C56CE0084EB2034432FC56565A ] BTHMODEM C:\windows\system32\DRIVERS\bthmodem.sys
16:37:31.0260 6164 BTHMODEM - ok
16:37:31.0292 6164 [ AD1872E5829E8A2C3B5B4B641C3EAB0E ] BthPan C:\windows\system32\DRIVERS\bthpan.sys
16:37:31.0338 6164 BthPan - ok
16:37:31.0401 6164 [ 1153DE2E4F5941E10C399CB5592F78A1 ] BTHPORT C:\windows\System32\Drivers\BTHport.sys
16:37:31.0448 6164 BTHPORT - ok
16:37:31.0510 6164 [ 1DF19C96EEF6C29D1C3E1A8678E07190 ] bthserv C:\windows\system32\bthserv.dll
16:37:31.0572 6164 bthserv - ok
16:37:31.0604 6164 [ C81E9413A25A439F436B1D4B6A0CF9E9 ] BTHUSB C:\windows\System32\Drivers\BTHUSB.sys
16:37:31.0619 6164 BTHUSB - ok
16:37:31.0682 6164 [ 44FFFF590169E88441FB2BC86277457A ] BTMCOM C:\windows\system32\Drivers\btmcom.sys
16:37:31.0728 6164 BTMCOM - ok
16:37:31.0775 6164 [ ED4E0FFB491FA281A339BD7311CBFCC6 ] BTMNET C:\windows\system32\DRIVERS\btmnet.sys
16:37:31.0822 6164 BTMNET - ok
16:37:31.0869 6164 [ 68FB465327CE3A980911B197F19E1614 ] BTMUSB C:\windows\system32\Drivers\btmusb.sys
16:37:31.0916 6164 BTMUSB - ok
16:37:31.0978 6164 [ 77EA11B065E0A8AB902D78145CA51E10 ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
16:37:32.0025 6164 cdfs - ok
16:37:32.0072 6164 [ BE167ED0FDB9C1FA1133953C18D5A6C9 ] cdrom C:\windows\system32\drivers\cdrom.sys
16:37:32.0087 6164 cdrom - ok
16:37:32.0134 6164 [ 319C6B309773D063541D01DF8AC6F55F ] CertPropSvc C:\windows\System32\certprop.dll
16:37:32.0181 6164 CertPropSvc - ok
16:37:32.0228 6164 [ 3FE3FE94A34DF6FB06E6418D0F6A0060 ] circlass C:\windows\system32\DRIVERS\circlass.sys
16:37:32.0274 6164 circlass - ok
16:37:32.0306 6164 [ 635181E0E9BBF16871BF5380D71DB02D ] CLFS C:\windows\system32\CLFS.sys
16:37:32.0337 6164 CLFS - ok
16:37:32.0446 6164 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
16:37:32.0462 6164 clr_optimization_v2.0.50727_32 - ok
16:37:32.0555 6164 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
16:37:32.0586 6164 clr_optimization_v4.0.30319_32 - ok
16:37:32.0618 6164 [ DEA805815E587DAD1DD2C502220B5616 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
16:37:32.0664 6164 CmBatt - ok
16:37:32.0696 6164 [ C537B1DB64D495B9B4717B4D6D9EDBF2 ] cmdide C:\windows\system32\drivers\cmdide.sys
16:37:32.0727 6164 cmdide - ok
16:37:32.0789 6164 [ 247B4CE2DAB1160CD422D532D5241E1F ] CNG C:\windows\system32\Drivers\cng.sys
16:37:32.0836 6164 CNG - ok
16:37:32.0867 6164 [ A6023D3823C37043986713F118A89BEE ] Compbatt C:\windows\system32\DRIVERS\compbatt.sys
16:37:32.0883 6164 Compbatt - ok
16:37:32.0945 6164 [ CBE8C58A8579CFE5FCCF809E6F114E89 ] CompositeBus C:\windows\system32\drivers\CompositeBus.sys
16:37:32.0961 6164 CompositeBus - ok
16:37:32.0976 6164 COMSysApp - ok
16:37:33.0008 6164 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1 ] crcdisk C:\windows\system32\DRIVERS\crcdisk.sys
16:37:33.0023 6164 crcdisk - ok
16:37:33.0086 6164 [ 96C0E38905CFD788313BE8E11DAE3F2F ] CryptSvc C:\windows\system32\cryptsvc.dll
16:37:33.0148 6164 CryptSvc - ok
16:37:33.0210 6164 [ A1998B05CDB931DEB5C653DE13D56E13 ] ctxusbm C:\windows\system32\DRIVERS\ctxusbm.sys
16:37:33.0226 6164 ctxusbm - ok
16:37:33.0273 6164 [ 7660F01D3B38ACA1747E397D21D790AF ] DcomLaunch C:\windows\system32\rpcss.dll
16:37:33.0335 6164 DcomLaunch - ok
16:37:33.0382 6164 [ 8D6E10A2D9A5EED59562D9B82CF804E1 ] defragsvc C:\windows\System32\defragsvc.dll
16:37:33.0429 6164 defragsvc - ok
16:37:33.0476 6164 [ F024449C97EC1E464AAFFDA18593DB88 ] DfsC C:\windows\system32\Drivers\dfsc.sys
16:37:33.0507 6164 DfsC - ok
16:37:33.0554 6164 [ E9E01EB683C132F7FA27CD607B8A2B63 ] Dhcp C:\windows\system32\dhcpcore.dll
16:37:33.0616 6164 Dhcp - ok
16:37:33.0632 6164 [ 1A050B0274BFB3890703D490F330C0DA ] discache C:\windows\system32\drivers\discache.sys
16:37:33.0678 6164 discache - ok
16:37:33.0710 6164 [ 565003F326F99802E68CA78F2A68E9FF ] Disk C:\windows\system32\DRIVERS\disk.sys
16:37:33.0725 6164 Disk - ok
16:37:33.0756 6164 [ 33EF4861F19A0736B11314AAD9AE28D0 ] Dnscache C:\windows\System32\dnsrslvr.dll
16:37:33.0788 6164 Dnscache - ok
16:37:33.0834 6164 [ 366BA8FB4B7BB7435E3B9EACB3843F67 ] dot3svc C:\windows\System32\dot3svc.dll
16:37:33.0881 6164 dot3svc - ok
16:37:33.0912 6164 [ 8EC04CA86F1D68DA9E11952EB85973D6 ] DPS C:\windows\system32\dps.dll
16:37:33.0959 6164 DPS - ok
16:37:34.0006 6164 [ B918E7C5F9BF77202F89E1A9539F2EB4 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
16:37:34.0022 6164 drmkaud - ok
16:37:34.0084 6164 [ 23F5D28378A160352BA8F817BD8C71CB ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
16:37:34.0100 6164 DXGKrnl - ok
16:37:34.0131 6164 [ 8600142FA91C1B96367D3300AD0F3F3A ] EapHost C:\windows\System32\eapsvc.dll
16:37:34.0178 6164 EapHost - ok
16:37:34.0271 6164 [ 024E1B5CAC09731E4D868E64DBFB4AB0 ] ebdrv C:\windows\system32\DRIVERS\evbdx.sys
16:37:34.0365 6164 ebdrv - ok
16:37:34.0427 6164 [ 8F7DBC4BE48F5388A6FE1F285E7948EF ] eeCtrl C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
16:37:34.0458 6164 eeCtrl - ok
16:37:34.0474 6164 [ 81951F51E318AECC2D68559E47485CC4 ] EFS C:\windows\System32\lsass.exe
16:37:34.0521 6164 EFS - ok
16:37:34.0568 6164 [ A8C362018EFC87BEB013EE28F29C0863 ] ehRecvr C:\windows\ehome\ehRecvr.exe
16:37:34.0630 6164 ehRecvr - ok
16:37:34.0677 6164 [ D389BFF34F80CAEDE417BF9D1507996A ] ehSched C:\windows\ehome\ehsched.exe
16:37:34.0708 6164 ehSched - ok
16:37:34.0755 6164 [ 0ED67910C8C326796FAA00B2BF6D9D3C ] elxstor C:\windows\system32\DRIVERS\elxstor.sys
16:37:34.0786 6164 elxstor - ok
16:37:34.0848 6164 [ 3EE14D400E0FDD0D214275A4A20B7022 ] EraserUtilRebootDrv C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
16:37:34.0864 6164 EraserUtilRebootDrv - ok
16:37:34.0895 6164 [ 8FC3208352DD3912C94367A206AB3F11 ] ErrDev C:\windows\system32\drivers\errdev.sys
16:37:34.0942 6164 ErrDev - ok
16:37:34.0989 6164 [ F6916EFC29D9953D5D0DF06882AE8E16 ] EventSystem C:\windows\system32\es.dll
16:37:35.0036 6164 EventSystem - ok
16:37:35.0067 6164 [ 2DC9108D74081149CC8B651D3A26207F ] exfat C:\windows\system32\drivers\exfat.sys
16:37:35.0129 6164 exfat - ok
16:37:35.0145 6164 [ 7E0AB74553476622FB6AE36F73D97D35 ] fastfat C:\windows\system32\drivers\fastfat.sys
16:37:35.0176 6164 fastfat - ok
16:37:35.0223 6164 [ 967EA5B213E9984CBE270205DF37755B ] Fax C:\windows\system32\fxssvc.exe
16:37:35.0270 6164 Fax - ok
16:37:35.0301 6164 [ E817A017F82DF2A1F8CFDBDA29388B29 ] fdc C:\windows\system32\DRIVERS\fdc.sys
16:37:35.0348 6164 fdc - ok
16:37:35.0379 6164 [ F3222C893BD2F5821A0179E5C71E88FB ] fdPHost C:\windows\system32\fdPHost.dll
16:37:35.0426 6164 fdPHost - ok
16:37:35.0441 6164 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B ] FDResPub C:\windows\system32\fdrespub.dll
16:37:35.0488 6164 FDResPub - ok
16:37:35.0519 6164 [ 6CF00369C97F3CF563BE99BE983D13D8 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
16:37:35.0519 6164 FileInfo - ok
16:37:35.0566 6164 [ 42C51DC94C91DA21CB9196EB64C45DB9 ] Filetrace C:\windows\system32\drivers\filetrace.sys
16:37:35.0628 6164 Filetrace - ok
16:37:35.0691 6164 [ 3D9B36631032FDE0FFEA0DC0260E4E35 ] FLEXnet Licensing Service C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
16:37:35.0722 6164 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - warning
16:37:35.0722 6164 FLEXnet Licensing Service - detected UnsignedFile.Multi.Generic (1)
16:37:35.0753 6164 [ 87907AA70CB3C56600F1C2FB8841579B ] flpydisk C:\windows\system32\DRIVERS\flpydisk.sys
16:37:35.0769 6164 flpydisk - ok
16:37:35.0816 6164 [ 7520EC808E0C35E0EE6F841294316653 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
16:37:35.0831 6164 FltMgr - ok
16:37:35.0878 6164 [ B3A5EC6B6B6673DB7E87C2BCDBDDC074 ] FontCache C:\windows\system32\FntCache.dll
16:37:35.0940 6164 FontCache - ok
16:37:35.0987 6164 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
16:37:36.0018 6164 FontCache3.0.0.0 - ok
16:37:36.0018 6164 [ 1A16B57943853E598CFF37FE2B8CBF1D ] FsDepends C:\windows\system32\drivers\FsDepends.sys
16:37:36.0050 6164 FsDepends - ok
16:37:36.0081 6164 [ 7DAE5EBCC80E45D3253F4923DC424D05 ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
16:37:36.0096 6164 Fs_Rec - ok
16:37:36.0143 6164 [ E306A24D9694C724FA2491278BF50FDB ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
16:37:36.0159 6164 fvevol - ok
16:37:36.0206 6164 [ 65EE0C7A58B65E74AE05637418153938 ] gagp30kx C:\windows\system32\DRIVERS\gagp30kx.sys
16:37:36.0221 6164 gagp30kx - ok
16:37:36.0268 6164 [ 185ADA973B5020655CEE342059A86CBB ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
16:37:36.0268 6164 GEARAspiWDM - ok
16:37:36.0315 6164 [ E897EAF5ED6BA41E081060C9B447A673 ] gpsvc C:\windows\System32\gpsvc.dll
16:37:36.0377 6164 gpsvc - ok
16:37:36.0455 6164 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
16:37:36.0486 6164 gupdate - ok
16:37:36.0502 6164 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
16:37:36.0502 6164 gupdatem - ok
16:37:36.0549 6164 [ 5D4BC124FAAE6730AC002CDB67BF1A1C ] gusvc C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
16:37:36.0564 6164 gusvc - ok
16:37:36.0580 6164 [ C44E3C2BAB6837DB337DDEE7544736DB ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
16:37:36.0611 6164 hcw85cir - ok
16:37:36.0658 6164 [ A5EF29D5315111C80A5C1ABAD14C8972 ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
16:37:36.0705 6164 HdAudAddService - ok
16:37:36.0736 6164 [ 9036377B8A6C15DC2EEC53E489D159B5 ] HDAudBus C:\windows\system32\drivers\HDAudBus.sys
16:37:36.0752 6164 HDAudBus - ok
16:37:36.0767 6164 [ 1D58A7F3E11A9731D0EAAAA8405ACC36 ] HidBatt C:\windows\system32\DRIVERS\HidBatt.sys
16:37:36.0798 6164 HidBatt - ok
16:37:36.0814 6164 [ 89448F40E6DF260C206A193A4683BA78 ] HidBth C:\windows\system32\DRIVERS\hidbth.sys
16:37:36.0845 6164 HidBth - ok
16:37:36.0876 6164 [ CF50B4CF4A4F229B9F3C08351F99CA5E ] HidIr C:\windows\system32\DRIVERS\hidir.sys
16:37:36.0923 6164 HidIr - ok
16:37:36.0954 6164 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B ] hidserv C:\windows\system32\hidserv.dll
16:37:36.0986 6164 hidserv - ok
16:37:37.0017 6164 [ 10C19F8290891AF023EAEC0832E1EB4D ] HidUsb C:\windows\system32\drivers\hidusb.sys
16:37:37.0048 6164 HidUsb - ok
16:37:37.0095 6164 [ 196B4E3F4CCCC24AF836CE58FACBB699 ] hkmsvc C:\windows\system32\kmsvc.dll
16:37:37.0157 6164 hkmsvc - ok
16:37:37.0188 6164 [ 6658F4404DE03D75FE3BA09F7ABA6A30 ] HomeGroupListener C:\windows\system32\ListSvc.dll
16:37:37.0235 6164 HomeGroupListener - ok
16:37:37.0266 6164 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8 ] HomeGroupProvider C:\windows\system32\provsvc.dll
16:37:37.0298 6164 HomeGroupProvider - ok
16:37:37.0376 6164 [ 3F4ADD4196E2B860019539837BE305F9 ] HP Health Check Service C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
16:37:37.0391 6164 HP Health Check Service ( UnsignedFile.Multi.Generic ) - warning
16:37:37.0391 6164 HP Health Check Service - detected UnsignedFile.Multi.Generic (1)
16:37:37.0454 6164 [ C7A62D20DC8E7790BA2E788F88377AE4 ] HPDrvMntSvc.exe C:\Program Files\Hewlett-Packard\Shared\HPDrvMntSvc.exe
16:37:37.0485 6164 HPDrvMntSvc.exe - ok
16:37:37.0578 6164 [ 4D94F4D7782657E79EB1352570B563DB ] hpHotkeyMonitor C:\Program Files\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe
16:37:37.0594 6164 hpHotkeyMonitor - ok
16:37:37.0625 6164 [ EE9F88368739554DCCA142AE0214BCB1 ] HpqKbFiltr C:\windows\system32\DRIVERS\HpqKbFiltr.sys
16:37:37.0641 6164 HpqKbFiltr - ok
16:37:37.0688 6164 [ E91BFC73B5874484886BC7D0E402ECD8 ] hpqwmiex C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
16:37:37.0719 6164 hpqwmiex - ok
16:37:37.0766 6164 [ 295FDC419039090EB8B49FFDBB374549 ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
16:37:37.0781 6164 HpSAMD - ok
16:37:37.0844 6164 [ 871917B07A141BFF43D76D8844D48106 ] HTTP C:\windows\system32\drivers\HTTP.sys
16:37:37.0890 6164 HTTP - ok
16:37:37.0922 6164 [ 0C4E035C7F105F1299258C90886C64C5 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
16:37:37.0937 6164 hwpolicy - ok
16:37:38.0000 6164 [ F151F0BDC47F4A28B1B20A0818EA36D6 ] i8042prt C:\windows\system32\drivers\i8042prt.sys
16:37:38.0031 6164 i8042prt - ok
16:37:38.0062 6164 [ 26541A068572F650A2FA490726FE81BE ] iaStor C:\windows\system32\DRIVERS\iaStor.sys
16:37:38.0093 6164 iaStor - ok
16:37:38.0187 6164 [ 31A0E93CDF29007D6C6FFFB632F375ED ] IAStorDataMgrSvc C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
16:37:38.0202 6164 IAStorDataMgrSvc - ok
16:37:38.0249 6164 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E ] iaStorV C:\windows\system32\drivers\iaStorV.sys
16:37:38.0296 6164 iaStorV - ok
16:37:38.0343 6164 [ C521D7EB6497BB1AF6AFA89E322FB43C ] idsvc C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
16:37:38.0390 6164 idsvc - ok
16:37:38.0483 6164 [ 9BC8840DE4140E8E2A6FC3192E054A8C ] IDSVix86 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20111004.030\IDSvix86.sys
16:37:38.0514 6164 IDSVix86 - ok
16:37:38.0670 6164 [ 4EE7874572A515D112D2F35112F5AD41 ] igfx C:\windows\system32\DRIVERS\igdkmd32.sys
16:37:38.0842 6164 igfx - ok
16:37:38.0889 6164 [ 4173FF5708F3236CF25195FECD742915 ] iirsp C:\windows\system32\DRIVERS\iirsp.sys
16:37:38.0904 6164 iirsp - ok
16:37:38.0982 6164 [ A06EFD4965F8A3F97A8C9A291D032678 ] IJPLMSVC C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
16:37:38.0998 6164 IJPLMSVC - ok
16:37:39.0060 6164 [ F95622F161474511B8D80D6B093AA610 ] IKEEXT C:\windows\System32\ikeext.dll
16:37:39.0123 6164 IKEEXT - ok
16:37:39.0170 6164 [ 81486F0EB4238B65C317F97DE246C4AC ] IntcHdmiAddService C:\windows\system32\drivers\IntcHdmi.sys
16:37:39.0216 6164 IntcHdmiAddService - ok
16:37:39.0248 6164 [ A0F12F2C9BA6C72F3987CE780E77C130 ] intelide C:\windows\system32\drivers\intelide.sys
16:37:39.0263 6164 intelide - ok
16:37:39.0310 6164 [ 3B514D27BFC4ACCB4037BC6685F766E0 ] intelppm C:\windows\system32\DRIVERS\intelppm.sys
16:37:39.0326 6164 intelppm - ok
16:37:39.0357 6164 [ ACB364B9075A45C0736E5C47BE5CAE19 ] IPBusEnum C:\windows\system32\ipbusenum.dll
16:37:39.0404 6164 IPBusEnum - ok
16:37:39.0450 6164 [ 709D1761D3B19A932FF0238EA6D50200 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
16:37:39.0482 6164 IpFilterDriver - ok
16:37:39.0544 6164 [ 58F67245D041FBE7AF88F4EAF79DF0FA ] iphlpsvc C:\windows\System32\iphlpsvc.dll
16:37:39.0575 6164 iphlpsvc - ok
16:37:39.0622 6164 [ 4BD7134618C1D2A27466A099062547BF ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
16:37:39.0653 6164 IPMIDRV - ok
16:37:39.0684 6164 [ A5FA468D67ABCDAA36264E463A7BB0CD ] IPNAT C:\windows\system32\drivers\ipnat.sys
16:37:39.0731 6164 IPNAT - ok
16:37:39.0778 6164 [ E8A39D41474BE42FD8830CED32932D6C ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
16:37:39.0825 6164 iPod Service - ok
16:37:39.0856 6164 [ 42996CFF20A3084A56017B7902307E9F ] IRENUM C:\windows\system32\drivers\irenum.sys
16:37:39.0934 6164 IRENUM - ok
16:37:39.0996 6164 [ 1F32BB6B38F62F7DF1A7AB7292638A35 ] isapnp C:\windows\system32\drivers\isapnp.sys
16:37:40.0012 6164 isapnp - ok
16:37:40.0059 6164 [ CB7A9ABB12B8415BCE5D74994C7BA3AE ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
16:37:40.0074 6164 iScsiPrt - ok
16:37:40.0106 6164 [ ADEF52CA1AEAE82B50DF86B56413107E ] kbdclass C:\windows\system32\drivers\kbdclass.sys
16:37:40.0121 6164 kbdclass - ok
16:37:40.0168 6164 [ 9E3CED91863E6EE98C24794D05E27A71 ] kbdhid C:\windows\system32\drivers\kbdhid.sys
16:37:40.0199 6164 kbdhid - ok
16:37:40.0230 6164 [ 81951F51E318AECC2D68559E47485CC4 ] KeyIso C:\windows\system32\lsass.exe
16:37:40.0246 6164 KeyIso - ok
16:37:40.0262 6164 [ B7895B4182C0D16F6EFADEB8081E8D36 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
16:37:40.0277 6164 KSecDD - ok
16:37:40.0324 6164 [ D30159AC9237519FBC62C6EC247D2D46 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
16:37:40.0340 6164 KSecPkg - ok
16:37:40.0386 6164 [ 89A7B9CC98D0D80C6F31B91C0A310FCD ] KtmRm C:\windows\system32\msdtckrm.dll
16:37:40.0418 6164 KtmRm - ok
16:37:40.0464 6164 [ D64AF876D53ECA3668BB97B51B4E70AB ] LanmanServer C:\windows\system32\srvsvc.dll
16:37:40.0511 6164 LanmanServer - ok
16:37:40.0558 6164 [ 58405E4F68BA8E4057C6E914F326ABA2 ] LanmanWorkstation C:\windows\System32\wkssvc.dll
16:37:40.0620 6164 LanmanWorkstation - ok
16:37:40.0667 6164 [ 3503F257B3203F824B1567238EBE17E2 ] LightScribeService C:\Program Files\Common Files\LightScribe\LSSrvc.exe
16:37:40.0683 6164 LightScribeService ( UnsignedFile.Multi.Generic ) - warning
16:37:40.0683 6164 LightScribeService - detected UnsignedFile.Multi.Generic (1)
16:37:40.0730 6164 [ F7611EC07349979DA9B0AE1F18CCC7A6 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
16:37:40.0792 6164 lltdio - ok
16:37:40.0823 6164 [ 5700673E13A2117FA3B9020C852C01E2 ] lltdsvc C:\windows\System32\lltdsvc.dll
16:37:40.0870 6164 lltdsvc - ok
16:37:40.0886 6164 [ 55CA01BA19D0006C8F2639B6C045E08B ] lmhosts C:\windows\System32\lmhsvc.dll
16:37:40.0932 6164 lmhosts - ok
16:37:40.0964 6164 [ EB119A53CCF2ACC000AC71B065B78FEF ] LSI_FC C:\windows\system32\DRIVERS\lsi_fc.sys
16:37:40.0979 6164 LSI_FC - ok
16:37:40.0995 6164 [ 8ADE1C877256A22E49B75D1CC9161F9C ] LSI_SAS C:\windows\system32\DRIVERS\lsi_sas.sys
16:37:41.0010 6164 LSI_SAS - ok
16:37:41.0026 6164 [ DC9DC3D3DAA0E276FD2EC262E38B11E9 ] LSI_SAS2 C:\windows\system32\DRIVERS\lsi_sas2.sys
16:37:41.0042 6164 LSI_SAS2 - ok
16:37:41.0057 6164 [ 0A036C7D7CAB643A7F07135AC47E0524 ] LSI_SCSI C:\windows\system32\DRIVERS\lsi_scsi.sys
16:37:41.0073 6164 LSI_SCSI - ok
16:37:41.0088 6164 [ 6703E366CC18D3B6E534F5CF7DF39CEE ] luafv C:\windows\system32\drivers\luafv.sys
16:37:41.0135 6164 luafv - ok
16:37:41.0166 6164 [ 8E17D513D8011B0EE03C355EAAB0E0CC ] ManyCam C:\windows\system32\DRIVERS\mcvidrv.sys
16:37:41.0198 6164 ManyCam - ok
16:37:41.0229 6164 [ 562D95E00E14A944DEBE655DECBD3F5B ] mcaudrv_simple C:\windows\system32\drivers\mcaudrv.sys
16:37:41.0276 6164 mcaudrv_simple - ok
16:37:41.0338 6164 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
16:37:41.0369 6164 Mcx2Svc - ok
16:37:41.0385 6164 [ 0FFF5B045293002AB38EB1FD1FC2FB74 ] megasas C:\windows\system32\DRIVERS\megasas.sys
16:37:41.0400 6164 megasas - ok
16:37:41.0447 6164 [ DCBAB2920C75F390CAF1D29F675D03D6 ] MegaSR C:\windows\system32\DRIVERS\MegaSR.sys
16:37:41.0463 6164 MegaSR - ok
16:37:41.0494 6164 [ 146B6F43A673379A3C670E86D89BE5EA ] MMCSS C:\windows\system32\mmcss.dll
16:37:41.0541 6164 MMCSS - ok
16:37:41.0572 6164 [ F001861E5700EE84E2D4E52C712F4964 ] Modem C:\windows\system32\drivers\modem.sys
16:37:41.0619 6164 Modem - ok
16:37:41.0666 6164 [ 79D10964DE86B292320E9DFE02282A23 ] monitor C:\windows\system32\DRIVERS\monitor.sys
16:37:41.0712 6164 monitor - ok
16:37:41.0790 6164 [ FB18CC1D4C2E716B6B903B0AC0CC0609 ] mouclass C:\windows\system32\drivers\mouclass.sys
16:37:41.0822 6164 mouclass - ok
16:37:41.0853 6164 [ 2C388D2CD01C9042596CF3C8F3C7B24D ] mouhid C:\windows\system32\DRIVERS\mouhid.sys
16:37:41.0884 6164 mouhid - ok
16:37:41.0931 6164 [ FC8771F45ECCCFD89684E38842539B9B ] mountmgr C:\windows\system32\drivers\mountmgr.sys
16:37:41.0962 6164 mountmgr - ok
16:37:41.0993 6164 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0 ] mpio C:\windows\system32\drivers\mpio.sys
16:37:42.0009 6164 mpio - ok
16:37:42.0040 6164 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0 ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
16:37:42.0071 6164 mpsdrv - ok
16:37:42.0118 6164 [ 9835584E999D25004E1EE8E5F3E3B881 ] MpsSvc C:\windows\system32\mpssvc.dll
16:37:42.0165 6164 MpsSvc - ok
16:37:42.0196 6164 [ CEB46AB7C01C9F825F8CC6BABC18166A ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
16:37:42.0227 6164 MRxDAV - ok
16:37:42.0274 6164 [ 5D16C921E3671636C0EBA3BBAAC5FD25 ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
16:37:42.0321 6164 mrxsmb - ok
16:37:42.0336 6164 [ 6D17A4791ACA19328C685D256349FEFC ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
16:37:42.0383 6164 mrxsmb10 - ok
16:37:42.0430 6164 [ B81F204D146000BE76651A50670A5E9E ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
16:37:42.0461 6164 mrxsmb20 - ok
16:37:42.0492 6164 [ 012C5F4E9349E711E11E0F19A8589F0A ] msahci C:\windows\system32\drivers\msahci.sys
16:37:42.0508 6164 msahci - ok
16:37:42.0539 6164 [ 55055F8AD8BE27A64C831322A780A228 ] msdsm C:\windows\system32\drivers\msdsm.sys
16:37:42.0555 6164 msdsm - ok
16:37:42.0570 6164 [ E1BCE74A3BD9902B72599C0192A07E27 ] MSDTC C:\windows\System32\msdtc.exe
16:37:42.0602 6164 MSDTC - ok
16:37:42.0648 6164 [ DAEFB28E3AF5A76ABCC2C3078C07327F ] Msfs C:\windows\system32\drivers\Msfs.sys
16:37:42.0680 6164 Msfs - ok
16:37:42.0680 6164 [ 3E1E5767043C5AF9367F0056295E9F84 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
16:37:42.0726 6164 mshidkmdf - ok
16:37:42.0742 6164 [ 0A4E5757AE09FA9622E3158CC1AEF114 ] msisadrv C:\windows\system32\drivers\msisadrv.sys
16:37:42.0758 6164 msisadrv - ok
16:37:42.0820 6164 [ 90F7D9E6B6F27E1A707D4A297F077828 ] MSiSCSI C:\windows\system32\iscsiexe.dll
16:37:42.0882 6164 MSiSCSI - ok
16:37:42.0882 6164 msiserver - ok
16:37:42.0929 6164 [ 8C0860D6366AAFFB6C5BB9DF9448E631 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
16:37:42.0976 6164 MSKSSRV - ok
16:37:42.0992 6164 [ 3EA8B949F963562CEDBB549EAC0C11CE ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
16:37:43.0038 6164 MSPCLOCK - ok
16:37:43.0054 6164 [ F456E973590D663B1073E9C463B40932 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
16:37:43.0101 6164 MSPQM - ok
16:37:43.0116 6164 [ 0E008FC4819D238C51D7C93E7B41E560 ] MsRPC C:\windows\system32\drivers\MsRPC.sys
16:37:43.0132 6164 MsRPC - ok
16:37:43.0163 6164 [ FC6B9FF600CC585EA38B12589BD4E246 ] mssmbios C:\windows\system32\drivers\mssmbios.sys
16:37:43.0179 6164 mssmbios - ok
16:37:43.0194 6164 [ B42C6B921F61A6E55159B8BE6CD54A36 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
16:37:43.0226 6164 MSTEE - ok
16:37:43.0241 6164 [ 33599130F44E1F34631CEA241DE8AC84 ] MTConfig C:\windows\system32\DRIVERS\MTConfig.sys
16:37:43.0288 6164 MTConfig - ok
16:37:43.0304 6164 [ 159FAD02F64E6381758C990F753BCC80 ] Mup C:\windows\system32\Drivers\mup.sys
16:37:43.0319 6164 Mup - ok
16:37:43.0366 6164 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E ] napagent C:\windows\system32\qagentRT.dll
16:37:43.0413 6164 napagent - ok
16:37:43.0460 6164 [ 26384429FCD85D83746F63E798AB1480 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
16:37:43.0506 6164 NativeWifiP - ok
16:37:43.0569 6164 [ 862F55824AC81295837B0AB63F91071F ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111004.021\NAVENG.SYS
16:37:43.0584 6164 NAVENG - ok
16:37:43.0647 6164 [ 529D571B551CB9DA44237389B936F1AE ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20111004.021\NAVEX15.SYS
16:37:43.0709 6164 NAVEX15 - ok
16:37:43.0772 6164 [ 8C9C922D71F1CD4DEF73F186416B7896 ] NDIS C:\windows\system32\drivers\ndis.sys
16:37:43.0818 6164 NDIS - ok
16:37:43.0850 6164 [ 0E1787AA6C9191D3D319E8BAFE86F80C ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
16:37:43.0912 6164 NdisCap - ok
16:37:43.0943 6164 [ E4A8AEC125A2E43A9E32AFEEA7C9C888 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
16:37:43.0974 6164 NdisTapi - ok
16:37:44.0021 6164 [ D8A65DAFB3EB41CBB622745676FCD072 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
16:37:44.0052 6164 Ndisuio - ok
16:37:44.0084 6164 [ 38FBE267E7E6983311179230FACB1017 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
16:37:44.0130 6164 NdisWan - ok
16:37:44.0162 6164 [ A4BDC541E69674FBFF1A8FF00BE913F2 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
16:37:44.0240 6164 NDProxy - ok
16:37:44.0255 6164 [ 80B275B1CE3B0E79909DB7B39AF74D51 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
16:37:44.0302 6164 NetBIOS - ok
16:37:44.0333 6164 [ 280122DDCF04B378EDD1AD54D71C1E54 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
16:37:44.0380 6164 NetBT - ok
16:37:44.0396 6164 [ 81951F51E318AECC2D68559E47485CC4 ] Netlogon C:\windows\system32\lsass.exe
16:37:44.0411 6164 Netlogon - ok
16:37:44.0458 6164 [ 7CCCFCA7510684768DA22092D1FA4DB2 ] Netman C:\windows\System32\netman.dll
16:37:44.0505 6164 Netman - ok
16:37:44.0536 6164 [ 8C338238C16777A802D6A9211EB2BA50 ] netprofm C:\windows\System32\netprofm.dll
16:37:44.0567 6164 netprofm - ok
16:37:44.0630 6164 [ 091D731C04E7A1543B391A5B883B4598 ] netr28 C:\windows\system32\DRIVERS\netr28.sys
16:37:44.0676 6164 netr28 - ok
16:37:44.0723 6164 [ F476EC40033CDB91EFBE73EB99B8362D ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
16:37:44.0723 6164 NetTcpPortSharing - ok
16:37:44.0739 6164 [ 1D85C4B390B0EE09C7A46B91EFB2C097 ] nfrd960 C:\windows\system32\DRIVERS\nfrd960.sys
16:37:44.0754 6164 nfrd960 - ok
16:37:44.0864 6164 [ E78A365CC3E0FBFC018A33DCE01909F8 ] NIS C:\Program Files\Norton Internet Security\Engine\18.7.2.3\ccSvcHst.exe
16:37:44.0879 6164 NIS - ok
16:37:44.0926 6164 [ 374071043F9E4231EE43BE2BB48DD36D ] NlaSvc C:\windows\System32\nlasvc.dll
16:37:44.0957 6164 NlaSvc - ok
16:37:45.0004 6164 NOBU - ok
16:37:45.0035 6164 [ 1DB262A9F8C087E8153D89BEF3D2235F ] Npfs C:\windows\system32\drivers\Npfs.sys
16:37:45.0066 6164 Npfs - ok
16:37:45.0082 6164 [ BA387E955E890C8A88306D9B8D06BF17 ] nsi C:\windows\system32\nsisvc.dll
16:37:45.0129 6164 nsi - ok
16:37:45.0144 6164 [ E9A0A4D07E53D8FEA2BB8387A3293C58 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
16:37:45.0191 6164 nsiproxy - ok
16:37:45.0269 6164 [ 5E43D2B0EE64123D4880DFA6626DEFDE ] Ntfs C:\windows\system32\drivers\Ntfs.sys
16:37:45.0316 6164 Ntfs - ok
16:37:45.0332 6164 [ F9756A98D69098DCA8945D62858A812C ] Null C:\windows\system32\drivers\Null.sys
16:37:45.0363 6164 Null - ok
16:37:45.0394 6164 [ B3E25EE28883877076E0E1FF877D02E0 ] nvraid C:\windows\system32\drivers\nvraid.sys
16:37:45.0410 6164 nvraid - ok
16:37:45.0456 6164 [ 4380E59A170D88C4F1022EFF6719A8A4 ] nvstor C:\windows\system32\drivers\nvstor.sys
16:37:45.0472 6164 nvstor - ok
16:37:45.0503 6164 [ 5A0983915F02BAE73267CC2A041F717D ] nv_agp C:\windows\system32\drivers\nv_agp.sys
16:37:45.0519 6164 nv_agp - ok
16:37:45.0566 6164 [ 08A70A1F2CDDE9BB49B885CB817A66EB ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
16:37:45.0597 6164 ohci1394 - ok
16:37:45.0628 6164 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
16:37:45.0644 6164 ose - ok
16:37:45.0784 6164 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
16:37:45.0940 6164 osppsvc - ok
16:37:45.0971 6164 [ 82A8521DDC60710C3D3D3E7325209BEC ] p2pimsvc C:\windows\system32\pnrpsvc.dll
16:37:46.0018 6164 p2pimsvc - ok
16:37:46.0049 6164 [ 59C3DDD501E39E006DAC31BF55150D91 ] p2psvc C:\windows\system32\p2psvc.dll
16:37:46.0096 6164 p2psvc - ok
16:37:46.0112 6164 [ 2EA877ED5DD9713C5AC74E8EA7348D14 ] Parport C:\windows\system32\DRIVERS\parport.sys
16:37:46.0143 6164 Parport - ok
16:37:46.0174 6164 [ 3F34A1B4C5F6475F320C275E63AFCE9B ] partmgr C:\windows\system32\drivers\partmgr.sys
16:37:46.0174 6164 partmgr - ok
16:37:46.0205 6164 [ EB0A59F29C19B86479D36B35983DAADC ] Parvdm C:\windows\system32\DRIVERS\parvdm.sys
16:37:46.0236 6164 Parvdm - ok
16:37:46.0268 6164 [ 358AB7956D3160000726574083DFC8A6 ] PcaSvc C:\windows\System32\pcasvc.dll
16:37:46.0299 6164 PcaSvc - ok
16:37:46.0330 6164 [ 673E55C3498EB970088E812EA820AA8F ] pci C:\windows\system32\drivers\pci.sys
16:37:46.0346 6164 pci - ok
16:37:46.0377 6164 [ AFE86F419014DB4E5593F69FFE26CE0A ] pciide C:\windows\system32\drivers\pciide.sys
16:37:46.0392 6164 pciide - ok
16:37:46.0424 6164 [ F396431B31693E71E8A80687EF523506 ] pcmcia C:\windows\system32\DRIVERS\pcmcia.sys
16:37:46.0439 6164 pcmcia - ok
16:37:46.0486 6164 [ 250F6B43D2B613172035C6747AEEB19F ] pcw C:\windows\system32\drivers\pcw.sys
16:37:46.0502 6164 pcw - ok
16:37:46.0548 6164 pdfcDispatcher - ok
16:37:46.0580 6164 [ 9E0104BA49F4E6973749A02BF41344ED ] PEAUTH C:\windows\system32\drivers\peauth.sys
16:37:46.0642 6164 PEAUTH - ok
16:37:46.0704 6164 [ 414BBA67A3DED1D28437EB66AEB8A720 ] pla C:\windows\system32\pla.dll
16:37:46.0798 6164 pla - ok
16:37:46.0860 6164 [ EC7BC28D207DA09E79B3E9FAF8B232CA ] PlugPlay C:\windows\system32\umpnpmgr.dll
16:37:46.0892 6164 PlugPlay - ok
16:37:46.0907 6164 [ 63FF8572611249931EB16BB8EED6AFC8 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
16:37:46.0938 6164 PNRPAutoReg - ok
16:37:46.0970 6164 [ 82A8521DDC60710C3D3D3E7325209BEC ] PNRPsvc C:\windows\system32\pnrpsvc.dll
16:37:46.0985 6164 PNRPsvc - ok
16:37:47.0032 6164 [ 53946B69BA0836BD95B03759530C81EC ] PolicyAgent C:\windows\System32\ipsecsvc.dll
16:37:47.0079 6164 PolicyAgent - ok
16:37:47.0126 6164 [ F87D30E72E03D579A5199CCB3831D6EA ] Power C:\windows\system32\umpo.dll
16:37:47.0157 6164 Power - ok
16:37:47.0204 6164 [ 631E3E205AD6D86F2AED6A4A8E69F2DB ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
16:37:47.0235 6164 PptpMiniport - ok
16:37:47.0250 6164 [ 85B1E3A0C7585BC4AAE6899EC6FCF011 ] Processor C:\windows\system32\DRIVERS\processr.sys
16:37:47.0282 6164 Processor - ok
16:37:47.0313 6164 [ CADEFAC453040E370A1BDFF3973BE00D ] ProfSvc C:\windows\system32\profsvc.dll
16:37:47.0344 6164 ProfSvc - ok
16:37:47.0360 6164 [ 81951F51E318AECC2D68559E47485CC4 ] ProtectedStorage C:\windows\system32\lsass.exe
16:37:47.0375 6164 ProtectedStorage - ok
16:37:47.0422 6164 [ 6270CCAE2A86DE6D146529FE55B3246A ] Psched C:\windows\system32\DRIVERS\pacer.sys
16:37:47.0453 6164 Psched - ok
16:37:47.0484 6164 [ A6A7AD767BF5141665F5C675F671B3E1 ] PSI_SVC_2 c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
16:37:47.0500 6164 PSI_SVC_2 - ok
16:37:47.0547 6164 [ E42E3433DBB4CFFE8FDD91EAB29AEA8E ] PxHelp20 C:\windows\system32\Drivers\PxHelp20.sys
16:37:47.0562 6164 PxHelp20 - ok
16:37:47.0640 6164 [ AB95ECF1F6659A60DDC166D8315B0751 ] ql2300 C:\windows\system32\DRIVERS\ql2300.sys
16:37:47.0718 6164 ql2300 - ok
16:37:47.0734 6164 [ B4DD51DD25182244B86737DC51AF2270 ] ql40xx C:\windows\system32\DRIVERS\ql40xx.sys
16:37:47.0750 6164 ql40xx - ok
16:37:47.0781 6164 [ 31AC809E7707EB580B2BDB760390765A ] QWAVE C:\windows\system32\qwave.dll
16:37:47.0812 6164 QWAVE - ok
16:37:47.0843 6164 [ 584078CA1B95CA72DF2A27C336F9719D ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
16:37:47.0874 6164 QWAVEdrv - ok
16:37:47.0906 6164 [ 30A81B53C766D0133BB86D234E5556AB ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
16:37:47.0921 6164 RasAcd - ok
16:37:47.0968 6164 [ 57EC4AEF73660166074D8F7F31C0D4FD ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
16:37:48.0015 6164 RasAgileVpn - ok
16:37:48.0046 6164 [ A60F1839849C0C00739787FD5EC03F13 ] RasAuto C:\windows\System32\rasauto.dll
16:37:48.0077 6164 RasAuto - ok
16:37:48.0108 6164 [ D9F91EAFEC2815365CBE6D167E4E332A ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
16:37:48.0171 6164 Rasl2tp - ok
16:37:48.0202 6164 [ CB9E04DC05EACF5B9A36CA276D475006 ] RasMan C:\windows\System32\rasmans.dll
16:37:48.0233 6164 RasMan - ok
16:37:48.0249 6164 [ 0FE8B15916307A6AC12BFB6A63E45507 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
16:37:48.0280 6164 RasPppoe - ok
16:37:48.0327 6164 [ 44101F495A83EA6401D886E7FD70096B ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
16:37:48.0358 6164 RasSstp - ok
16:37:48.0405 6164 [ D528BC58A489409BA40334EBF96A311B ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
16:37:48.0436 6164 rdbss - ok
16:37:48.0452 6164 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF ] rdpbus C:\windows\system32\DRIVERS\rdpbus.sys
16:37:48.0483 6164 rdpbus - ok
16:37:48.0514 6164 [ 23DAE03F29D253AE74C44F99E515F9A1 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
16:37:48.0545 6164 RDPCDD - ok
16:37:48.0577 6164 [ 5A53CA1598DD4156D44196D200C94B8A ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
16:37:48.0608 6164 RDPENCDD - ok
16:37:48.0623 6164 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
16:37:48.0670 6164 RDPREFMP - ok
16:37:48.0717 6164 [ F031683E6D1FEA157ABB2FF260B51E61 ] RDPWD C:\windows\system32\drivers\RDPWD.sys
16:37:48.0764 6164 RDPWD - ok
16:37:48.0826 6164 [ 518395321DC96FE2C9F0E96AC743B656 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
16:37:48.0857 6164 rdyboost - ok
16:37:48.0873 6164 [ 7B5E1419717FAC363A31CC302895217A ] RemoteAccess C:\windows\System32\mprdim.dll
16:37:48.0951 6164 RemoteAccess - ok
16:37:48.0982 6164 [ CB9A8683F4EF2BF99E123D79950D7935 ] RemoteRegistry C:\windows\system32\regsvc.dll
16:37:49.0013 6164 RemoteRegistry - ok
16:37:49.0060 6164 [ CB928D9E6DAF51879DD6BA8D02F01321 ] RFCOMM C:\windows\system32\DRIVERS\rfcomm.sys
16:37:49.0076 6164 RFCOMM - ok
16:37:49.0091 6164 [ 78D072F35BC45D9E4E1B61895C152234 ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
16:37:49.0123 6164 RpcEptMapper - ok
16:37:49.0154 6164 [ 94D36C0E44677DD26981D2BFEEF2A29D ] RpcLocator C:\windows\system32\locator.exe
16:37:49.0185 6164 RpcLocator - ok
16:37:49.0216 6164 [ 7660F01D3B38ACA1747E397D21D790AF ] RpcSs C:\windows\system32\rpcss.dll
16:37:49.0247 6164 RpcSs - ok
16:37:49.0294 6164 [ 032B0D36AD92B582D869879F5AF5B928 ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
16:37:49.0325 6164 rspndr - ok
16:37:49.0388 6164 [ 83F5445DC0BA1994C1F5FF02BA79CC3A ] RTL8167 C:\windows\system32\DRIVERS\Rt86win7.sys
16:37:49.0403 6164 RTL8167 - ok
16:37:49.0435 6164 [ A33E97AB22C481AFC2BDA6731C0E1B8B ] rtsuvc C:\windows\system32\DRIVERS\rtsuvc.sys
16:37:49.0466 6164 rtsuvc - ok
16:37:49.0466 6164 [ 81951F51E318AECC2D68559E47485CC4 ] SamSs C:\windows\system32\lsass.exe
16:37:49.0481 6164 SamSs - ok
16:37:49.0528 6164 [ 05D860DA1040F111503AC416CCEF2BCA ] sbp2port C:\windows\system32\drivers\sbp2port.sys
16:37:49.0544 6164 sbp2port - ok
16:37:49.0575 6164 [ 8FC518FFE9519C2631D37515A68009C4 ] SCardSvr C:\windows\System32\SCardSvr.dll
16:37:49.0622 6164 SCardSvr - ok
16:37:49.0637 6164 [ 0693B5EC673E34DC147E195779A4DCF6 ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
16:37:49.0684 6164 scfilter - ok
16:37:49.0731 6164 [ A04BB13F8A72F8B6E8B4071723E4E336 ] Schedule C:\windows\system32\schedsvc.dll
16:37:49.0793 6164 Schedule - ok
16:37:49.0825 6164 [ 319C6B309773D063541D01DF8AC6F55F ] SCPolicySvc C:\windows\System32\certprop.dll
16:37:49.0840 6164 SCPolicySvc - ok
16:37:49.0903 6164 [ 08236C4BCE5EDD0A0318A438AF28E0F7 ] SDRSVC C:\windows\System32\SDRSVC.dll
16:37:49.0934 6164 SDRSVC - ok
16:37:49.0965 6164 [ 90A3935D05B494A5A39D37E71F09A677 ] secdrv C:\windows\system32\drivers\secdrv.sys
16:37:50.0012 6164 secdrv - ok
16:37:50.0059 6164 [ A59B3A4442C52060CC7A85293AA3546F ] seclogon C:\windows\system32\seclogon.dll
16:37:50.0121 6164 seclogon - ok
16:37:50.0137 6164 [ DCB7FCDCC97F87360F75D77425B81737 ] SENS C:\windows\System32\sens.dll
16:37:50.0183 6164 SENS - ok
16:37:50.0215 6164 [ 50087FE1EE447009C9CC2997B90DE53F ] SensrSvc C:\windows\system32\sensrsvc.dll
16:37:50.0246 6164 SensrSvc - ok
16:37:50.0293 6164 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1 ] Serenum C:\windows\system32\DRIVERS\serenum.sys
16:37:50.0324 6164 Serenum - ok
16:37:50.0355 6164 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2 ] Serial C:\windows\system32\DRIVERS\serial.sys
16:37:50.0386 6164 Serial - ok
16:37:50.0417 6164 [ 79BFFB520327FF916A582DFEA17AA813 ] sermouse C:\windows\system32\DRIVERS\sermouse.sys
16:37:50.0449 6164 sermouse - ok
16:37:50.0495 6164 [ 4AE380F39A0032EAB7DD953030B26D28 ] SessionEnv C:\windows\system32\sessenv.dll
16:37:50.0511 6164 SessionEnv - ok
16:37:50.0558 6164 [ 9F976E1EB233DF46FCE808D9DEA3EB9C ] sffdisk C:\windows\system32\drivers\sffdisk.sys
16:37:50.0589 6164 sffdisk - ok
16:37:50.0605 6164 [ 932A68EE27833CFD57C1639D375F2731 ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
16:37:50.0636 6164 sffp_mmc - ok
16:37:50.0651 6164 [ 6D4CCAEDC018F1CF52866BBBAA235982 ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
16:37:50.0683 6164 sffp_sd - ok
16:37:50.0698 6164 [ DB96666CC8312EBC45032F30B007A547 ] sfloppy C:\windows\system32\DRIVERS\sfloppy.sys
16:37:50.0714 6164 sfloppy - ok
16:37:50.0761 6164 [ D1A079A0DE2EA524513B6930C24527A2 ] SharedAccess C:\windows\System32\ipnathlp.dll
16:37:50.0807 6164 SharedAccess - ok
16:37:50.0839 6164 [ 414DA952A35BF5D50192E28263B40577 ] ShellHWDetection C:\windows\System32\shsvcs.dll
16:37:50.0870 6164 ShellHWDetection - ok
16:37:50.0917 6164 [ 2565CAC0DC9FE0371BDCE60832582B2E ] sisagp C:\windows\system32\drivers\sisagp.sys
16:37:50.0932 6164 sisagp - ok
16:37:50.0963 6164 [ A9F0486851BECB6DDA1D89D381E71055 ] SiSRaid2 C:\windows\system32\DRIVERS\SiSRaid2.sys
16:37:50.0979 6164 SiSRaid2 - ok
16:37:50.0995 6164 [ 3727097B55738E2F554972C3BE5BC1AA ] SiSRaid4 C:\windows\system32\DRIVERS\sisraid4.sys
16:37:51.0010 6164 SiSRaid4 - ok
16:37:51.0073 6164 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
16:37:51.0104 6164 SkypeUpdate - ok
16:37:51.0135 6164 [ 3E21C083B8A01CB70BA1F09303010FCE ] Smb C:\windows\system32\DRIVERS\smb.sys
16:37:51.0197 6164 Smb - ok
16:37:51.0244 6164 [ 6A984831644ECA1A33FFEAE4126F4F37 ] SNMPTRAP C:\windows\System32\snmptrap.exe
16:37:51.0291 6164 SNMPTRAP - ok
16:37:51.0307 6164 [ 95CF1AE7527FB70F7816563CBC09D942 ] spldr C:\windows\system32\drivers\spldr.sys
16:37:51.0322 6164 spldr - ok
16:37:51.0369 6164 [ 9AEA093B8F9C37CF45538382CABA2475 ] Spooler C:\windows\System32\spoolsv.exe
16:37:51.0431 6164 Spooler - ok
16:37:51.0525 6164 [ CF87A1DE791347E75B98885214CED2B8 ] sppsvc C:\windows\system32\sppsvc.exe
16:37:51.0665 6164 sppsvc - ok
16:37:51.0697 6164 [ B0180B20B065D89232A78A40FE56EAA6 ] sppuinotify C:\windows\system32\sppuinotify.dll
16:37:51.0743 6164 sppuinotify - ok
16:37:51.0821 6164 [ 83726CF02ECED69138948083E06B6EAC ] SRTSP C:\windows\System32\Drivers\NIS\1207020.003\SRTSP.SYS
16:37:51.0868 6164 SRTSP - ok
16:37:51.0899 6164 [ 4E7EAB2E5615D39CF1F1DF9C71E5E225 ] SRTSPX C:\windows\system32\drivers\NIS\1207020.003\SRTSPX.SYS
16:37:51.0915 6164 SRTSPX - ok
16:37:51.0946 6164 [ E4C2764065D66EA1D2D3EBC28FE99C46 ] srv C:\windows\system32\DRIVERS\srv.sys
16:37:51.0993 6164 srv - ok
16:37:52.0009 6164 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB ] srv2 C:\windows\system32\DRIVERS\srv2.sys
16:37:52.0040 6164 srv2 - ok
16:37:52.0071 6164 [ BE6BD660CAA6F291AE06A718A4FA8ABC ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
16:37:52.0118 6164 srvnet - ok
16:37:52.0149 6164 [ D887C9FD02AC9FA880F6E5027A43E118 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
16:37:52.0196 6164 SSDPSRV - ok
16:37:52.0211 6164 [ D318F23BE45D5E3A107469EB64815B50 ] SstpSvc C:\windows\system32\sstpsvc.dll
16:37:52.0258 6164 SstpSvc - ok
16:37:52.0352 6164 [ 9C1EA4217DC30E085F8418474DCC3616 ] STacSV C:\windows\System32\DriverStore\FileRepository\stwrt.inf_x86_neutral_9b219d80a8843bf8\STacSV.exe
16:37:52.0383 6164 STacSV - ok
16:37:52.0414 6164 [ DB32D325C192B801DF274BFD12A7E72B ] stexstor C:\windows\system32\DRIVERS\stexstor.sys
16:37:52.0430 6164 stexstor - ok
16:37:52.0492 6164 [ C502802475B7A2CB843F9F815D7DDC36 ] STHDA C:\windows\system32\DRIVERS\stwrt.sys
16:37:52.0523 6164 STHDA - ok
16:37:52.0570 6164 [ E1FB3706030FB4578A0D72C2FC3689E4 ] StiSvc C:\windows\System32\wiaservc.dll
16:37:52.0601 6164 StiSvc - ok
16:37:52.0648 6164 [ AD989072596AB313D7FA13BCF69573F7 ] stllssvr c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
16:37:52.0664 6164 stllssvr - ok
16:37:52.0679 6164 [ E58C78A848ADD9610A4DB6D214AF5224 ] swenum C:\windows\system32\drivers\swenum.sys
16:37:52.0695 6164 swenum - ok
16:37:52.0742 6164 [ A28BD92DF340E57B024BA433165D34D7 ] swprv C:\windows\System32\swprv.dll
16:37:52.0789 6164 swprv - ok
16:37:52.0820 6164 [ 9BBEB8C6258E72D62E7560E6667AAD39 ] SymDS C:\windows\system32\drivers\NIS\1207020.003\SYMDS.SYS
16:37:52.0835 6164 SymDS - ok
16:37:52.0882 6164 [ D5C02629C02A820A7E71BCA3D44294A3 ] SymEFA C:\windows\system32\drivers\NIS\1207020.003\SYMEFA.SYS
16:37:52.0913 6164 SymEFA - ok
16:37:52.0945 6164 [ AB33C3B196197CA467CBDDA717860DBA ] SymEvent C:\windows\system32\Drivers\SYMEVENT.SYS
16:37:52.0960 6164 SymEvent - ok
16:37:52.0976 6164 [ A73399804D5D4A8B20BA60FCF70C9F1F ] SymIRON C:\windows\system32\drivers\NIS\1207020.003\Ironx86.SYS
16:37:52.0991 6164 SymIRON - ok
16:37:53.0038 6164 [ 2C688094650D23B62B0A809DECD0B12F ] SymNetS C:\windows\System32\Drivers\NIS\1207020.003\SYMNETS.SYS
16:37:53.0054 6164 SymNetS - ok
16:37:53.0101 6164 [ 916A6435B54BD87C65950425AED642B7 ] SynTP C:\windows\system32\DRIVERS\SynTP.sys
16:37:53.0132 6164 SynTP - ok
16:37:53.0179 6164 [ 36650D618CA34C9D357DFD3D89B2C56F ] SysMain C:\windows\system32\sysmain.dll
16:37:53.0272 6164 SysMain - ok
16:37:53.0303 6164 [ 763FECDC3D30C815FE72DD57936C6CD1 ] TabletInputService C:\windows\System32\TabSvc.dll
16:37:53.0319 6164 TabletInputService - ok
16:37:53.0381 6164 [ 613BF4820361543956909043A265C6AC ] TapiSrv C:\windows\System32\tapisrv.dll
16:37:53.0413 6164 TapiSrv - ok
16:37:53.0444 6164 [ B799D9FDB26111737F58288D8DC172D9 ] TBS C:\windows\System32\tbssvc.dll
16:37:53.0491 6164 TBS - ok
16:37:53.0537 6164 [ 7C0507D2391AF5933600CBCED799F277 ] Tcpip C:\windows\system32\drivers\tcpip.sys
16:37:53.0615 6164 Tcpip - ok
16:37:53.0647 6164 [ 7C0507D2391AF5933600CBCED799F277 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
16:37:53.0678 6164 TCPIP6 - ok
16:37:53.0725 6164 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
16:37:53.0756 6164 tcpipreg - ok
16:37:53.0803 6164 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2 ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
16:37:53.0834 6164 TDPIPE - ok
16:37:53.0849 6164 [ 2C2C5AFE7EE4F620D69C23C0617651A8 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
16:37:53.0881 6164 TDTCP - ok
16:37:53.0912 6164 [ B459575348C20E8121D6039DA063C704 ] tdx C:\windows\system32\DRIVERS\tdx.sys
16:37:53.0974 6164 tdx - ok
16:37:54.0005 6164 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20 ] TermDD C:\windows\system32\drivers\termdd.sys
16:37:54.0021 6164 TermDD - ok
16:37:54.0052 6164 [ 382C804C92811BE57829D8E550A900E2 ] TermService C:\windows\System32\termsrv.dll
16:37:54.0115 6164 TermService - ok
16:37:54.0130 6164 [ 42FB6AFD6B79D9FE07381609172E7CA4 ] Themes C:\windows\system32\themeservice.dll
16:37:54.0177 6164 Themes - ok
16:37:54.0193 6164 [ 146B6F43A673379A3C670E86D89BE5EA ] THREADORDER C:\windows\system32\mmcss.dll
16:37:54.0224 6164 THREADORDER - ok
16:37:54.0271 6164 [ A5D859ACB470B166B3C996AB23DECA09 ] TotRec8 C:\windows\system32\drivers\TotRec8.sys
16:37:54.0286 6164 TotRec8 - ok
16:37:54.0333 6164 [ 5AD05191DC8B444A7BA4D79B76C42A30 ] TPM C:\windows\system32\drivers\tpm.sys
16:37:54.0349 6164 TPM - ok
16:37:54.0380 6164 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A ] TrkWks C:\windows\System32\trkwks.dll
16:37:54.0427 6164 TrkWks - ok
16:37:54.0489 6164 [ 81532F3628F8ACC80FD1264095960C3A ] TrueSight C:\windows\system32\drivers\TrueSight.sys
16:37:54.0505 6164 TrueSight ( UnsignedFile.Multi.Generic ) - warning
16:37:54.0505 6164 TrueSight - detected UnsignedFile.Multi.Generic (1)
16:37:54.0567 6164 [ 2C49B175AEE1D4364B91B531417FE583 ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
16:37:54.0614 6164 TrustedInstaller - ok
16:37:54.0645 6164 [ 254BB140EEE3C59D6114C1A86B636877 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
16:37:54.0707 6164 tssecsrv - ok
16:37:54.0739 6164 [ FD1D6C73E6333BE727CBCC6054247654 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
16:37:54.0770 6164 TsUsbFlt - ok
16:37:54.0817 6164 [ B2FA25D9B17A68BB93D58B0556E8C90D ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
16:37:54.0863 6164 tunnel - ok
16:37:54.0879 6164 [ 750FBCB269F4D7DD2E420C56B795DB6D ] uagp35 C:\windows\system32\DRIVERS\uagp35.sys
16:37:54.0895 6164 uagp35 - ok
16:37:54.0926 6164 [ EE43346C7E4B5E63E54F927BABBB32FF ] udfs C:\windows\system32\DRIVERS\udfs.sys
16:37:54.0957 6164 udfs - ok
16:37:54.0973 6164 [ 8344FD4FCE927880AA1AA7681D4927E5 ] UI0Detect C:\windows\system32\UI0Detect.exe
16:37:55.0004 6164 UI0Detect - ok
16:37:55.0035 6164 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
16:37:55.0051 6164 uliagpkx - ok
16:37:55.0097 6164 [ D295BED4B898F0FD999FCFA9B32B071B ] umbus C:\windows\system32\drivers\umbus.sys
16:37:55.0129 6164 umbus - ok
16:37:55.0175 6164 [ 7550AD0C6998BA1CB4843E920EE0FEAC ] UmPass C:\windows\system32\DRIVERS\umpass.sys
16:37:55.0207 6164 UmPass - ok
16:37:55.0238 6164 [ 833FBB672460EFCE8011D262175FAD33 ] upnphost C:\windows\System32\upnphost.dll
16:37:55.0300 6164 upnphost - ok
16:37:55.0363 6164 [ BD9C55D7023C5DE374507ACC7A14E2AC ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
16:37:55.0409 6164 usbccgp - ok
16:37:55.0441 6164 [ 04EC7CEC62EC3B6D9354EEE93327FC82 ] usbcir C:\windows\system32\drivers\usbcir.sys
16:37:55.0472 6164 usbcir - ok
16:37:55.0503 6164 [ F92DE757E4B7CE9C07C5E65423F3AE3B ] usbehci C:\windows\system32\DRIVERS\usbehci.sys
16:37:55.0534 6164 usbehci - ok
16:37:55.0581 6164 [ 8DC94AEC6A7E644A06135AE7506DC2E9 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
16:37:55.0612 6164 usbhub - ok
16:37:55.0628 6164 [ E185D44FAC515A18D9DEDDC23C2CDF44 ] usbohci C:\windows\system32\drivers\usbohci.sys
16:37:55.0675 6164 usbohci - ok
16:37:55.0690 6164 [ 797D862FE0875E75C7CC4C1AD7B30252 ] usbprint C:\windows\system32\DRIVERS\usbprint.sys
16:37:55.0721 6164 usbprint - ok
16:37:55.0753 6164 [ F991AB9CC6B908DB552166768176896A ] USBSTOR C:\windows\system32\drivers\USBSTOR.SYS
16:37:55.0799 6164 USBSTOR - ok
16:37:55.0831 6164 [ 68DF884CF41CDADA664BEB01DAF67E3D ] usbuhci C:\windows\system32\DRIVERS\usbuhci.sys
16:37:55.0846 6164 usbuhci - ok
16:37:55.0877 6164 [ 45F4E7BF43DB40A6C6B4D92C76CBC3F2 ] usbvideo C:\windows\System32\Drivers\usbvideo.sys
16:37:55.0924 6164 usbvideo - ok
16:37:55.0955 6164 [ 081E6E1C91AEC36758902A9F727CD23C ] UxSms C:\windows\System32\uxsms.dll
16:37:56.0002 6164 UxSms - ok
16:37:56.0018 6164 [ 81951F51E318AECC2D68559E47485CC4 ] VaultSvc C:\windows\system32\lsass.exe
16:37:56.0033 6164 VaultSvc - ok
16:37:56.0080 6164 [ A059C4C3EDB09E07D21A8E5C0AABD3CB ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
16:37:56.0096 6164 vdrvroot - ok
16:37:56.0143 6164 [ C3CD30495687C2A2F66A65CA6FD89BE9 ] vds C:\windows\System32\vds.exe
16:37:56.0205 6164 vds - ok
16:37:56.0236 6164 [ 17C408214EA61696CEC9C66E388B14F3 ] vga C:\windows\system32\DRIVERS\vgapnp.sys
16:37:56.0267 6164 vga - ok
16:37:56.0299 6164 [ 8E38096AD5C8570A6F1570A61E251561 ] VgaSave C:\windows\System32\drivers\vga.sys
16:37:56.0314 6164 VgaSave - ok
16:37:56.0361 6164 [ 5461686CCA2FDA57B024547733AB42E3 ] vhdmp C:\windows\system32\drivers\vhdmp.sys
16:37:56.0392 6164 vhdmp - ok
16:37:56.0439 6164 [ C829317A37B4BEA8F39735D4B076E923 ] viaagp C:\windows\system32\drivers\viaagp.sys
16:37:56.0455 6164 viaagp - ok
16:37:56.0470 6164 [ E02F079A6AA107F06B16549C6E5C7B74 ] ViaC7 C:\windows\system32\DRIVERS\viac7.sys
16:37:56.0501 6164 ViaC7 - ok
16:37:56.0517 6164 [ E43574F6A56A0EE11809B48C09E4FD3C ] viaide C:\windows\system32\drivers\viaide.sys
16:37:56.0533 6164 viaide - ok
16:37:56.0579 6164 [ 4C63E00F2F4B5F86AB48A58CD990F212 ] volmgr C:\windows\system32\drivers\volmgr.sys
16:37:56.0579 6164 volmgr - ok
16:37:56.0611 6164 [ B5BB72067DDDDBBFB04B2F89FF8C3C87 ] volmgrx C:\windows\system32\drivers\volmgrx.sys
16:37:56.0642 6164 volmgrx - ok
16:37:56.0673 6164 [ F497F67932C6FA693D7DE2780631CFE7 ] volsnap C:\windows\system32\drivers\volsnap.sys
16:37:56.0689 6164 volsnap - ok
16:37:56.0720 6164 [ 9DFA0CC2F8855A04816729651175B631 ] vsmraid C:\windows\system32\DRIVERS\vsmraid.sys
16:37:56.0735 6164 vsmraid - ok
16:37:56.0782 6164 [ 209A3B1901B83AEB8527ED211CCE9E4C ] VSS C:\windows\system32\vssvc.exe
16:37:56.0829 6164 VSS - ok
16:37:56.0860 6164 [ 90567B1E658001E79D7C8BBD3DDE5AA6 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
16:37:56.0891 6164 vwifibus - ok
16:37:56.0923 6164 [ 7090D3436EEB4E7DA3373090A23448F7 ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
16:37:56.0938 6164 vwififlt - ok
16:37:56.0985 6164 [ 55187FD710E27D5095D10A472C8BAF1C ] W32Time C:\windows\system32\w32time.dll
16:37:57.0032 6164 W32Time - ok
16:37:57.0047 6164 [ DE3721E89C653AA281428C8A69745D90 ] WacomPen C:\windows\system32\DRIVERS\wacompen.sys
16:37:57.0079 6164 WacomPen - ok
16:37:57.0125 6164 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
16:37:57.0141 6164 WANARP - ok
16:37:57.0157 6164 [ 3C3C78515F5AB448B022BDF5B8FFDD2E ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
16:37:57.0172 6164 Wanarpv6 - ok
16:37:57.0250 6164 [ 353A04C273EC58475D8633E75CCD5604 ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
16:37:57.0313 6164 WatAdminSvc - ok
16:37:57.0359 6164 [ 691E3285E53DCA558E1A84667F13E15A ] wbengine C:\windows\system32\wbengine.exe
16:37:57.0437 6164 wbengine - ok
16:37:57.0453 6164 [ 9614B5D29DC76AC3C29F6D2D3AA70E67 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
16:37:57.0500 6164 WbioSrvc - ok
16:37:57.0531 6164 [ 34EEE0DFAADB4F691D6D5308A51315DC ] wcncsvc C:\windows\System32\wcncsvc.dll
16:37:57.0562 6164 wcncsvc - ok
16:37:57.0578 6164 [ 5D930B6357A6D2AF4D7653BDABBF352F ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
16:37:57.0593 6164 WcsPlugInService - ok
16:37:57.0625 6164 [ 1112A9BADACB47B7C0BB0392E3158DFF ] Wd C:\windows\system32\DRIVERS\wd.sys
16:37:57.0640 6164 Wd - ok
16:37:57.0656 6164 [ A840213F1ACDCC175B4D1D5AAEAC0D7A ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
16:37:57.0687 6164 Wdf01000 - ok
16:37:57.0703 6164 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiServiceHost C:\windows\system32\wdi.dll
16:37:57.0749 6164 WdiServiceHost - ok
16:37:57.0765 6164 [ 46EF9DC96265FD0B423DB72E7C38C2A5 ] WdiSystemHost C:\windows\system32\wdi.dll
16:37:57.0781 6164 WdiSystemHost - ok
16:37:57.0812 6164 [ A9D880F97530D5B8FEE278923349929D ] WebClient C:\windows\System32\webclnt.dll
16:37:57.0843 6164 WebClient - ok
16:37:57.0859 6164 [ 760F0AFE937A77CFF27153206534F275 ] Wecsvc C:\windows\system32\wecsvc.dll
16:37:57.0890 6164 Wecsvc - ok
16:37:57.0921 6164 [ AC804569BB2364FB6017370258A4091B ] wercplsupport C:\windows\System32\wercplsupport.dll
16:37:57.0968 6164 wercplsupport - ok
16:37:57.0999 6164 [ 08E420D873E4FD85241EE2421B02C4A4 ] WerSvc C:\windows\System32\WerSvc.dll
16:37:58.0030 6164 WerSvc - ok
16:37:58.0077 6164 [ 8B9A943F3B53861F2BFAF6C186168F79 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
16:37:58.0108 6164 WfpLwf - ok
16:37:58.0124 6164 [ 5CF95B35E59E2A38023836FFF31BE64C ] WIMMount C:\windows\system32\drivers\wimmount.sys
16:37:58.0139 6164 WIMMount - ok
16:37:58.0217 6164 [ 3FAE8F94296001C32EAB62CD7D82E0FD ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
16:37:58.0280 6164 WinDefend - ok
16:37:58.0280 6164 WinHttpAutoProxySvc - ok
16:37:58.0342 6164 [ F62E510B6AD4C21EB9FE8668ED251826 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
16:37:58.0420 6164 Winmgmt - ok
16:37:58.0467 6164 [ 1B91CD34EA3A90AB6A4EF0550174F4CC ] WinRM C:\windows\system32\WsmSvc.dll
16:37:58.0545 6164 WinRM - ok
16:37:58.0607 6164 [ 16935C98FF639D185086A3529B1F2067 ] Wlansvc C:\windows\System32\wlansvc.dll
16:37:58.0639 6164 Wlansvc - ok
16:37:58.0748 6164 [ FB01D4AE207B9EFDBABFC55DC95C7E31 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
16:37:58.0826 6164 wlidsvc - ok
16:37:58.0873 6164 [ 0217679B8FCA58714C3BF2726D2CA84E ] WmiAcp
 

Fiery

Level 1
Jan 11, 2011
2,007
Yes that's the one!

But the log is way too long to fit into one reply, hence you have to attach the file in your next reply.

To attach a file, click New Reply, scroll down to the Attachments section and click Choose File. Select the TDSSKiller logs and click Add Attachment. Once they are upload, click Post Reply
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
Ok i have attached the log this time.

EDIT*- it doesn't appear to have worked. I selected the file and clicked add attachment but when i clicked the button the file link simply disappeared from the new attachment box and didn't show up. Why won't it work?
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
No problem, theres a bit of overlap but at least now it's all there :D

08:53:30.0386 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\nl.lproj\SyncUICoreLocalized.dll - ok
08:53:30.0386 6140 [ E0ECB842159AA01F8B775A52E6C97950 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\hr\Microsoft.VisualBasic.resources.dll
08:53:30.0386 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\hr\Microsoft.VisualBasic.resources.dll - ok
08:53:30.0396 6140 [ 68FD9FD1AA0AD6F8345D3875244CC1BC ] C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\pt.lproj\SoftwareUpdateLocalized.dll
08:53:30.0396 6140 C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\pt.lproj\SoftwareUpdateLocalized.dll - ok
08:53:30.0406 6140 [ 1BD1CEE99A296E7CC8EDB579829E2FC9 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\sr-Cyrl-CS\Microsoft.VisualBasic.resources.dll
08:53:30.0406 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\sr-Cyrl-CS\Microsoft.VisualBasic.resources.dll - ok
08:53:30.0416 6140 [ EB1CA5FA3289AFD43A570D098856CA28 ] C:\Program Files\Symantec\Norton Online Backup\no\ARA.resources.dll
08:53:30.0416 6140 C:\Program Files\Symantec\Norton Online Backup\no\ARA.resources.dll - ok
08:53:30.0416 6140 [ 6CADC44080498A268FE020155BF1E066 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\sv\mscorrc.dll
08:53:30.0416 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\sv\mscorrc.dll - ok
08:53:30.0426 6140 [ 9D8EF8FBD8B764C1023010F47273F637 ] C:\Program Files\iTunes\iTunesHelper.Resources\es.lproj\iTunesHelperLocalized.dll
08:53:30.0426 6140 C:\Program Files\iTunes\iTunesHelper.Resources\es.lproj\iTunesHelperLocalized.dll - ok
08:53:30.0436 6140 [ EB5790528A08DFAB633AD60C50A9CD9F ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\fi.lproj\iTunesMiniPlayerLocalized.dll
08:53:30.0436 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\fi.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:30.0436 6140 [ F3DFE4AFF0D279B5328295FFF5862178 ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUIHandler.exe
08:53:30.0436 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUIHandler.exe - ok
08:53:30.0446 6140 [ DED293F6CC883884F4D3BD2FE68932B4 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\IniFile.dll
08:53:30.0446 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\IniFile.dll - ok
08:53:30.0456 6140 [ B0BF2104E751CF42759C0A9722018298 ] C:\Program Files\Hewlett-Packard\HP Support Framework\SplashLib.dll
08:53:30.0456 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\SplashLib.dll - ok
08:53:30.0456 6140 [ FEB25C8570F0703CE3AB2C043BB73DD9 ] C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll
08:53:30.0456 6140 C:\Program Files\Common Files\Apple\Apple Application Support\libxslt.dll - ok
08:53:30.0466 6140 [ B1AA39493D8FB7EDF9FD330B1EF03D39 ] C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\HPDOM32.DLL
08:53:30.0466 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\HPDOM32.DLL - ok
08:53:30.0476 6140 [ 2CA39675C48D2B99B732BDAA8025808F ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\ES\HPWAMain.resources.dll
08:53:30.0476 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\ES\HPWAMain.resources.dll - ok
08:53:30.0476 6140 [ BDF8AB6A06F9BBA6124BC161FF24E927 ] C:\Program Files\Symantec\Norton Online Backup\tr\ARA.resources.dll
08:53:30.0476 6140 C:\Program Files\Symantec\Norton Online Backup\tr\ARA.resources.dll - ok
08:53:30.0486 6140 [ 416E157837360AE2CA29EA6AFA2088A0 ] C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.WindowsMail.client_main.dll
08:53:30.0486 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.WindowsMail.client_main.dll - ok
08:53:30.0496 6140 [ CFE0CFB7E01C76908EE5A27E9F457B99 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\lt\mscorlib.resources.dll
08:53:30.0496 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\lt\mscorlib.resources.dll - ok
08:53:30.0496 6140 [ 790C40429E45D9465AD3043B1082C115 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\et\Microsoft.VisualBasic.resources.dll
08:53:30.0496 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\et\Microsoft.VisualBasic.resources.dll - ok
08:53:30.0506 6140 [ EB84D69D08EED611E7F4C5669BE0AEE9 ] C:\Program Files\iTunes\iTunesHelper.Resources\fr.lproj\iTunesHelperLocalized.dll
08:53:30.0506 6140 C:\Program Files\iTunes\iTunesHelper.Resources\fr.lproj\iTunesHelperLocalized.dll - ok
08:53:30.0516 6140 [ 5605E8356A45F0B556937846A0D8712E ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\zh-Hans\system.resources.dll
08:53:30.0516 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\zh-Hans\system.resources.dll - ok
08:53:30.0516 6140 [ A37D0B785C191EE411ED66B75A4D34A1 ] C:\Program Files\Common Files\Apple\Mobile Device Support\Mingler_main.dll
08:53:30.0516 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\Mingler_main.dll - ok
08:53:30.0526 6140 [ 4575FE3B2EBCE8CC5CCECC293A7DC306 ] C:\Program Files\iTunes\iTunes.Resources\uk.lproj\iTunesLocalized.dll
08:53:30.0526 6140 C:\Program Files\iTunes\iTunes.Resources\uk.lproj\iTunesLocalized.dll - ok
08:53:30.0536 6140 [ AB596C645811711655CE1E55B61EF66B ] C:\Program Files\Hewlett-Packard\HP HotKey Support\el\HandlersStrings.resources.dll
08:53:30.0536 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\el\HandlersStrings.resources.dll - ok
08:53:30.0536 6140 [ B48B0BD1DCE35F91D8CB96C547E92F27 ] C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\de.lproj\SoftwareUpdateFilesLocalized.dll
08:53:30.0536 6140 C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\de.lproj\SoftwareUpdateFilesLocalized.dll - ok
08:53:30.0546 6140 [ 83BFE70CB81CCB6A5487BFE324BCB57E ] C:\Program Files\Hewlett-Packard\Energy Star\PowerSav.exe
08:53:30.0546 6140 C:\Program Files\Hewlett-Packard\Energy Star\PowerSav.exe - ok
08:53:30.0556 6140 [ D1C1A6FF9A1F6CB0121D3CF4DB6EBC66 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\TriStateTreeView.dll
08:53:30.0556 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\TriStateTreeView.dll - ok
08:53:30.0556 6140 [ BAAF9D8A75712501F105179E54C401F0 ] C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\ru.lproj\SoftwareUpdateLocalized.dll
08:53:30.0556 6140 C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\ru.lproj\SoftwareUpdateLocalized.dll - ok
08:53:30.0566 6140 [ 6F111476351AE42EE54094C0D96F7E18 ] C:\Program Files\iTunes\iTunesHelper.Resources\ko.lproj\iTunesHelperLocalized.dll
08:53:30.0566 6140 C:\Program Files\iTunes\iTunesHelper.Resources\ko.lproj\iTunesHelperLocalized.dll - ok
08:53:30.0576 6140 [ 78B62E4C13378F737603136975A07E1A ] C:\Windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe76806\ATL90.dll
08:53:30.0576 6140 C:\Windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.4148_none_51ca66a2bbe76806\ATL90.dll - ok
08:53:30.0586 6140 [ 57E6F746B43D192A2E58E67DCC4A4622 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\bg\mscorlib.resources.dll
08:53:30.0586 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\bg\mscorlib.resources.dll - ok
08:53:30.0586 6140 [ D4815BB658A287BAB970DF1DB8A40F56 ] C:\Program Files\Symantec\Norton Online Backup\ko\ARA.resources.dll
08:53:30.0586 6140 C:\Program Files\Symantec\Norton Online Backup\ko\ARA.resources.dll - ok
08:53:30.0596 6140 [ 5994190BC5AC4C2D627248A29E0E8E50 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\pt\mscorlib.resources.dll
08:53:30.0596 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\pt\mscorlib.resources.dll - ok
08:53:30.0606 6140 [ 05A3B6C8FD31242D11137C9D48E0FBF3 ] C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\pt.lproj\SoftwareUpdateFilesLocalized.dll
08:53:30.0606 6140 C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\pt.lproj\SoftwareUpdateFilesLocalized.dll - ok
08:53:30.0606 6140 [ 41B4337AE062F411FD8C56B7BE7AEFB4 ] C:\Program Files\Hewlett-Packard\HP HotKey Support\pt-PT\HandlersStrings.resources.dll
08:53:30.0606 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\pt-PT\HandlersStrings.resources.dll - ok
08:53:30.0616 6140 [ 6250E00EE632BF0DC179B01F3E3AF930 ] C:\Program Files\Hewlett-Packard\HP HotKey Support\hphksVer.exe
08:53:30.0616 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\hphksVer.exe - ok
08:53:30.0626 6140 [ 13005D0EA3585BD08AA16ED8FFEAB205 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\it\SoftpaqDownloadManager.resources.dll
08:53:30.0626 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\it\SoftpaqDownloadManager.resources.dll - ok
08:53:30.0626 6140 [ 97845B1DC95E356636E1806A98EF95CF ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\vi\Microsoft.VisualBasic.resources.dll
08:53:30.0626 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\vi\Microsoft.VisualBasic.resources.dll - ok
08:53:30.0636 6140 [ CD98F5EF48C9AFCF9BC3918B78EB6457 ] C:\Program Files\Hewlett-Packard\HP HotKey Support\sk\HandlersStrings.resources.dll
08:53:30.0636 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\sk\HandlersStrings.resources.dll - ok
08:53:30.0636 6140 [ F7946F5141ADD0BCB7CDB6B24FB8E7D3 ] C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\launchWebChat\launchWebChat.exe
08:53:30.0636 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\launchWebChat\launchWebChat.exe - ok
08:53:30.0646 6140 [ A5C14075B571AF1C9592595BE724D9D2 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
08:53:30.0646 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll - ok
08:53:30.0656 6140 [ A6521AB93ABF8B9B0F102B55B37A9B49 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\pl\SoftpaqDownloadManager.resources.dll
08:53:30.0656 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\pl\SoftpaqDownloadManager.resources.dll - ok
08:53:30.0666 6140 [ 0DCFD2C7BCBF1DA06E9299FD2BB11AD3 ] C:\Program Files\Hewlett-Packard\HP HotKey Support\lt\HandlersStrings.resources.dll
08:53:30.0666 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\lt\HandlersStrings.resources.dll - ok
08:53:30.0666 6140 [ 0EA7F173CD6F2F34B58461BEBB46C169 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\vi\mscorlib.resources.dll
08:53:30.0666 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\vi\mscorlib.resources.dll - ok
08:53:30.0676 6140 [ BE6C7F27ABAEC7420FB505811FF580EF ] C:\Program Files\Hewlett-Packard\HP Support Framework\Configurator.dll
08:53:30.0676 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Configurator.dll - ok
08:53:30.0686 6140 [ DC15360DF9B2523FC5EC6B46E8955D2F ] C:\Program Files\Common Files\LightScribe\LSPrtEn.dll
08:53:30.0686 6140 C:\Program Files\Common Files\LightScribe\LSPrtEn.dll - ok
08:53:30.0686 6140 [ 7B37F8EC25C9AD853E8126C1D0992201 ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll
08:53:30.0686 6140 C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll - ok
08:53:30.0696 6140 [ 871F979D70414C900B35E56222932DAF ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll
08:53:30.0696 6140 C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll - ok
08:53:30.0706 6140 [ 4D03CA609E68F4C90CF66515218017F8 ] C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll
08:53:30.0706 6140 C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll - ok
08:53:30.0706 6140 [ 1352E1648213551923A0A822E441553C ] C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl.sys
08:53:30.0706 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl.sys - ok
08:53:30.0716 6140 [ 4E2D1E4FDC91C112695BDB87688291C3 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ru\Microsoft.VisualBasic.resources.dll
08:53:30.0716 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ru\Microsoft.VisualBasic.resources.dll - ok
08:53:30.0726 6140 [ 0E106FD26806FB13D5AF449D9A420196 ] C:\Program Files\Common Files\LightScribe\LSSMsg.dll
08:53:30.0726 6140 C:\Program Files\Common Files\LightScribe\LSSMsg.dll - ok
08:53:30.0726 6140 [ CD5A7C39E3D4FBA4711BE195D3726939 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\Silverlight.ConfigurationUI.dll
08:53:30.0726 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\Silverlight.ConfigurationUI.dll - ok
08:53:30.0736 6140 [ 87B069610271A1FF01409946AA1DD82D ] C:\Program Files\Symantec\Norton Online Backup\de\ARA.resources.dll
08:53:30.0736 6140 C:\Program Files\Symantec\Norton Online Backup\de\ARA.resources.dll - ok
08:53:30.0746 6140 [ 14D8B865D575351BEA300AF788398DBE ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\FR\HPWAMain.resources.dll
08:53:30.0746 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\FR\HPWAMain.resources.dll - ok
08:53:30.0746 6140 [ 8DF3C315855CA328314D8EF5E5C72D88 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\el\system.resources.dll
08:53:30.0746 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\el\system.resources.dll - ok
08:53:30.0756 6140 [ CF73C3A03582408D422D4F7A01190D00 ] C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\DIFxAPI.dll
08:53:30.0756 6140 C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\DIFxAPI.dll - ok
08:53:30.0766 6140 [ FB45A66ADB7900D80AA65E666A5A3288 ] C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\DifXInst32.exe
08:53:30.0766 6140 C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\DifXInst32.exe - ok
08:53:30.0766 6140 [ 84B38788149B32A50ED6859ACD3DCC1D ] C:\swsetup\AppInstl\hpqnt.dll
08:53:30.0766 6140 C:\swsetup\AppInstl\hpqnt.dll - ok
08:53:30.0776 6140 [ D372C89E541A774741DBAF9F9B7DD03F ] C:\Program Files\Citrix\Secure Access Client\nsepa.exe
08:53:30.0776 6140 C:\Program Files\Citrix\Secure Access Client\nsepa.exe - ok
08:53:30.0786 6140 [ 2AA3703D87E1327A2290C9D416D89A28 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrlui.dll
08:53:30.0786 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrlui.dll - ok
08:53:30.0786 6140 [ 8350F918DB947F35A548A7E9D7CD3001 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\de\Microsoft.VisualBasic.resources.dll
08:53:30.0786 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\de\Microsoft.VisualBasic.resources.dll - ok
08:53:30.0796 6140 [ 6976EAB35F14637803D5582308FA491E ] C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_CN.lproj\SoftwareUpdateFilesLocalized.dll
08:53:30.0796 6140 C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\zh_CN.lproj\SoftwareUpdateFilesLocalized.dll - ok
08:53:30.0806 6140 [ A993FECCFD81945121F9C18BEEE75FA3 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\de\system.resources.dll
08:53:30.0806 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\de\system.resources.dll - ok
08:53:30.0806 6140 [ 1CC9BE56494FE02E51F745E9A4394507 ] C:\Program Files\Common Files\Apple\Mobile Device Support\libeay32.dll
08:53:30.0806 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\libeay32.dll - ok
08:53:30.0816 6140 [ 76E273D1F288E427757F8BE294FDF242 ] C:\Program Files\iTunes\iTunesHelper.Resources\ru.lproj\iTunesHelperLocalized.dll
08:53:30.0816 6140 C:\Program Files\iTunes\iTunesHelper.Resources\ru.lproj\iTunesHelperLocalized.dll - ok
08:53:30.0826 6140 [ 187652D4237FDD19F33E663F5643393E ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\ko.lproj\SyncUICoreLocalized.dll
08:53:30.0826 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\ko.lproj\SyncUICoreLocalized.dll - ok
08:53:30.0836 6140 [ 49DDBE2A113B80DC68E67AF30710F542 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\sr-Latn-CS\mscorrc.dll
08:53:30.0836 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\sr-Latn-CS\mscorrc.dll - ok
08:53:30.0836 6140 [ 79B5641E2F83838EB35C66379B02DFAD ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\Microsoft.Xna.Framework.dll
08:53:30.0836 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\Microsoft.Xna.Framework.dll - ok
08:53:30.0846 6140 [ 964CC70F2AD35604EBA1E973E25BDF52 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\da\system.resources.dll
08:53:30.0846 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\da\system.resources.dll - ok
08:53:30.0856 6140 [ FF31D89DA3A70CA3EB43250A7672DC6E ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\EL\HPWAMain.resources.dll
08:53:30.0856 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\EL\HPWAMain.resources.dll - ok
08:53:30.0856 6140 [ 0B18C6E1E8195A65864C1AFE271726D6 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\es\SoftpaqDownloadManager.resources.dll
08:53:30.0856 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\es\SoftpaqDownloadManager.resources.dll - ok
08:53:30.0866 6140 [ 274FC0F093B4A6F6A046354177375A9F ] C:\Program Files\iTunes\iTunesHelper.Resources\ja.lproj\iTunesHelperLocalized.dll
08:53:30.0866 6140 C:\Program Files\iTunes\iTunesHelper.Resources\ja.lproj\iTunesHelperLocalized.dll - ok
08:53:30.0876 6140 [ 5BB78227F7210417FB1EFEF8C09CE7F7 ] C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ru.lproj\SoftwareUpdateFilesLocalized.dll
08:53:30.0876 6140 C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ru.lproj\SoftwareUpdateFilesLocalized.dll - ok
08:53:30.0876 6140 [ 5892995674E9D44995558AC26D61E90F ] C:\swsetup\AppInstl\BiosConfigUtility.exe
08:53:30.0876 6140 C:\swsetup\AppInstl\BiosConfigUtility.exe - ok
08:53:30.0886 6140 [ 65950F59BE430ABE5AF55248206AB772 ] C:\Program Files\iTunes\iTunes.Resources\zh_CN.lproj\iTunesLocalized.dll
08:53:30.0886 6140 C:\Program Files\iTunes\iTunes.Resources\zh_CN.lproj\iTunesLocalized.dll - ok
08:53:30.0896 6140 [ 8F01B522B67BD94DBC8FD1A5A1FAA35E ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\sk\mscorlib.resources.dll
08:53:30.0896 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\sk\mscorlib.resources.dll - ok
08:53:30.0896 6140 [ E847BBED52A61B2FB462F44D807E53BE ] C:\Program Files\Hewlett-Packard\HP HotKey Support\sr\HandlersStrings.resources.dll
08:53:30.0896 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\sr\HandlersStrings.resources.dll - ok
08:53:30.0906 6140 [ 55259F75E79D29E4A4507B215524556C ] C:\Program Files\iTunes\iTunes.Resources\cs.lproj\iTunesLocalized.dll
08:53:30.0906 6140 C:\Program Files\iTunes\iTunes.Resources\cs.lproj\iTunesLocalized.dll - ok
08:53:30.0916 6140 [ 29394DAB2141B6E70E861F86A01FD555 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\sl\system.resources.dll
08:53:30.0916 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\sl\system.resources.dll - ok
08:53:30.0926 6140 [ DE3546A9EE7C74B4A0A21C3684BB7F23 ] C:\Program Files\iTunes\iTunes.Resources\nl.lproj\iTunesLocalized.dll
08:53:30.0926 6140 C:\Program Files\iTunes\iTunes.Resources\nl.lproj\iTunesLocalized.dll - ok
08:53:30.0926 6140 [ 9E3409F62204742FFD4304E5F850AB61 ] C:\Program Files\iPod\bin\iPodService.Resources\sv.lproj\iPodServiceLocalized.dll
08:53:30.0926 6140 C:\Program Files\iPod\bin\iPodService.Resources\sv.lproj\iPodServiceLocalized.dll - ok
08:53:30.0936 6140 [ C7ADBC2E57815D6059305FFAD85B618E ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\zh-TW\HPWAMain.resources.dll
08:53:30.0936 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\zh-TW\HPWAMain.resources.dll - ok
08:53:30.0946 6140 [ 32C34A629BCCD40695D6D54915449DA5 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\th\system.resources.dll
08:53:30.0946 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\th\system.resources.dll - ok
08:53:30.0946 6140 [ 95AF8EE27B24068AE1C359876F4742F2 ] C:\Program Files\Common Files\Apple\Mobile Device Support\syncli_main.dll
08:53:30.0946 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\syncli_main.dll - ok
08:53:30.0956 6140 [ 246B08EBBBAE411DF73C7A1B160A69CD ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\tr\mscorlib.resources.dll
08:53:30.0956 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\tr\mscorlib.resources.dll - ok
08:53:30.0966 6140 [ 5DE42F0C598DCE31AA72662FD6BBB0CC ] C:\Program Files\iTunes\iTunesHelper.Resources\th.lproj\iTunesHelperLocalized.dll
08:53:30.0966 6140 C:\Program Files\iTunes\iTunesHelper.Resources\th.lproj\iTunesHelperLocalized.dll - ok
08:53:30.0966 6140 [ 1335FAE1F181BA539A114F278303ABAA ] C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPThermalAssistant\HPThermalAssistant.exe
08:53:30.0966 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPThermalAssistant\HPThermalAssistant.exe - ok
08:53:30.0976 6140 [ DF03CB823943C6E76018796E6E1EEB85 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ro\mscorlib.resources.dll
08:53:30.0976 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ro\mscorlib.resources.dll - ok
08:53:30.0986 6140 [ B0EC350A75353178A96E3CE162227D72 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\pl\Microsoft.VisualBasic.resources.dll
08:53:30.0986 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\pl\Microsoft.VisualBasic.resources.dll - ok
08:53:30.0986 6140 [ 8819504BB0BDCE8A68F155BDA0BFDDBB ] C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ja.lproj\SoftwareUpdateFilesLocalized.dll
08:53:30.0986 6140 C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\ja.lproj\SoftwareUpdateFilesLocalized.dll - ok
08:53:30.0996 6140 [ 36CF6674B40A42F8DDA78F60029B5CC7 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\SLMSPRBootstrap.dll
08:53:30.0996 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\SLMSPRBootstrap.dll - ok
08:53:31.0006 6140 [ 8A4769F85F16548FAEEAE071F3C2FCBF ] C:\Program Files\iTunes\iTunesHelper.Resources\fi.lproj\iTunesHelperLocalized.dll
08:53:31.0006 6140 C:\Program Files\iTunes\iTunesHelper.Resources\fi.lproj\iTunesHelperLocalized.dll - ok
08:53:31.0006 6140 [ 1298DB824CCBA7CA301008C68CE909AF ] C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\sv.lproj\SoftwareUpdateFilesLocalized.dll
08:53:31.0006 6140 C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\sv.lproj\SoftwareUpdateFilesLocalized.dll - ok
08:53:31.0016 6140 [ 588FD3089AD5DD3C33E8133997CE21E5 ] C:\Program Files\Common Files\LightScribe\plugins\accessible\qtaccessiblecompatwidgets4.dll
08:53:31.0016 6140 C:\Program Files\Common Files\LightScribe\plugins\accessible\qtaccessiblecompatwidgets4.dll - ok
08:53:31.0026 6140 [ E5D2AC3A3B17B00DB00B97FA14BF495D ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\he\mscorrc.dll
08:53:31.0026 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\he\mscorrc.dll - ok
08:53:31.0026 6140 [ E55D4198BCBFEC64CC3A7DB0020E7573 ] C:\Program Files\Common Files\Apple\Mobile Device Support\com.google.ContactSync.client_main.dll
08:53:31.0026 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\com.google.ContactSync.client_main.dll - ok
08:53:31.0036 6140 [ 643F34A4C5B95A6C3C8591C2E5727496 ] C:\Program Files\Symantec\Norton Online Backup\nl\ARA.resources.dll
08:53:31.0036 6140 C:\Program Files\Symantec\Norton Online Backup\nl\ARA.resources.dll - ok
08:53:31.0046 6140 [ C485BEEB1A2BF50D5C8EE91170C438EC ] C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.WindowsContacts.client_main.dll
08:53:31.0046 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.WindowsContacts.client_main.dll - ok
08:53:31.0056 6140 [ C8EA7C5384650314E0EDF2C0D73A5DD0 ] C:\Program Files\iPod\bin\iPodService.Resources\el.lproj\iPodServiceLocalized.dll
08:53:31.0056 6140 C:\Program Files\iPod\bin\iPodService.Resources\el.lproj\iPodServiceLocalized.dll - ok
08:53:31.0056 6140 [ 69692F675039891F4703B872025E83DB ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\zh-Hant\system.resources.dll
08:53:31.0056 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\zh-Hant\system.resources.dll - ok
08:53:31.0066 6140 [ 894BE35E899F0FBA1DF4BFC1D27C6557 ] C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.Safari.client.exe
08:53:31.0066 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\com.apple.Safari.client.exe - ok
08:53:31.0066 6140 [ E6E577E4704117DE6AEB4B55E0B6CBA9 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\sl\SoftpaqDownloadManager.resources.dll
08:53:31.0066 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\sl\SoftpaqDownloadManager.resources.dll - ok
08:53:31.0076 6140 [ 50FEA3D99009B215EF2594008A9E7AF5 ] C:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.dll
08:53:31.0076 6140 C:\Program Files\iPod\bin\iPodService.Resources\zh_CN.lproj\iPodServiceLocalized.dll - ok
08:53:31.0086 6140 [ CA3E0D40C0CA5FC2355674526116FB0A ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\pt\mscorrc.dll
08:53:31.0086 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\pt\mscorrc.dll - ok
08:53:31.0096 6140 [ 1053F5626DC50B85D26352A3FB24CC7F ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.Xml.dll
08:53:31.0096 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.Xml.dll - ok
08:53:31.0096 6140 [ 8DFCB9F1975298FDA34B5BD893001BE0 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\lv\Microsoft.VisualBasic.resources.dll
08:53:31.0096 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\lv\Microsoft.VisualBasic.resources.dll - ok
08:53:31.0106 6140 [ B9322AE756B4D07C5EE13748ABE4F9AF ] C:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.dll
08:53:31.0106 6140 C:\Program Files\iTunes\iTunesHelper.Resources\zh_CN.lproj\iTunesHelperLocalized.dll - ok
08:53:31.0116 6140 [ 8A62E57F39AB14C2CD29A84FD684A512 ] C:\Program Files\Apple Software Update\SoftwareUpdateAdmin.dll
08:53:31.0116 6140 C:\Program Files\Apple Software Update\SoftwareUpdateAdmin.dll - ok
08:53:31.0116 6140 [ 5C3E20288ACA831BD97A3207D6FCF2B1 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ro\mscorrc.dll
08:53:31.0116 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ro\mscorrc.dll - ok
08:53:31.0126 6140 [ 985A1E361C88A36E98258B71D5AA1F79 ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\el.lproj\iTunesMiniPlayerLocalized.dll
08:53:31.0126 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\el.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:31.0136 6140 [ 86F8B9760C09A38D910A6663F8E9ECAB ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\hr.lproj\iTunesMiniPlayerLocalized.dll
08:53:31.0136 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\hr.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:31.0136 6140 [ 3D52580A72B367D1BAB493E1A57009D7 ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\sk.lproj\iTunesMiniPlayerLocalized.dll
08:53:31.0136 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\sk.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:31.0146 6140 [ CEB4EFEFCA108B7D75B49E2EF89F074A ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\sr-Latn-CS\system.resources.dll
08:53:31.0146 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\sr-Latn-CS\system.resources.dll - ok
08:53:31.0146 6140 [ E7C98CBCA27EA5FCFA18C52522D7EB64 ] C:\Program Files\iPod\bin\iPodService.Resources\pl.lproj\iPodServiceLocalized.dll
08:53:31.0146 6140 C:\Program Files\iPod\bin\iPodService.Resources\pl.lproj\iPodServiceLocalized.dll - ok
08:53:31.0156 6140 [ C88F8D915B66DD676FC85049C9DC667E ] C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\zh_TW.lproj\SoftwareUpdateLocalized.dll
08:53:31.0156 6140 C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\zh_TW.lproj\SoftwareUpdateLocalized.dll - ok
08:53:31.0166 6140 [ CF6CF5D1C4A7251448951846466AEE3B ] C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPODDCheck\HPODDCheck.exe
08:53:31.0166 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPODDCheck\HPODDCheck.exe - ok
08:53:31.0166 6140 [ 0E3281EAB3D4E615D388F0E0646749E5 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\fi\mscorlib.resources.dll
08:53:31.0166 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\fi\mscorlib.resources.dll - ok
08:53:31.0176 6140 [ 55A8C326733768992726E6F894F24DA0 ] C:\Program Files\Hewlett-Packard\HP Support Framework\Warranty\log4net.dll
08:53:31.0176 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Warranty\log4net.dll - ok
08:53:31.0186 6140 [ F5A0AE4732CC0E09FF05E5C5D5F9738F ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\ru.lproj\SyncUICoreLocalized.dll
08:53:31.0186 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\ru.lproj\SyncUICoreLocalized.dll - ok
08:53:31.0196 6140 [ E641CFD1A413FC8150CCC4490A038F65 ] C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\MiniHwScan.exe
08:53:31.0196 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\MiniHwScan.exe - ok
08:53:31.0196 6140 [ 6E9B623A1D55B228C3D4679CEA489DB8 ] C:\Program Files\iTunes\iTunes.Resources\da.lproj\iTunesLocalized.dll
08:53:31.0196 6140 C:\Program Files\iTunes\iTunes.Resources\da.lproj\iTunesLocalized.dll - ok
08:53:31.0206 6140 [ 735F987CFEF56EB9DC7AF8AB888E5B8F ] C:\Program Files\Symantec\Norton Online Backup\es\ARA.resources.dll
08:53:31.0206 6140 C:\Program Files\Symantec\Norton Online Backup\es\ARA.resources.dll - ok
08:53:31.0216 6140 [ CB9BD353A7F9278EBEDA6B9C14F1D406 ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\pt-BR\HPWAMain.resources.dll
08:53:31.0216 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\pt-BR\HPWAMain.resources.dll - ok
08:53:31.0216 6140 [ D94B21E53D57501A02B8D00BB95C05EF ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.Windows.dll
08:53:31.0216 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.Windows.dll - ok
08:53:31.0226 6140 [ 3949399FCAD1CE729399FD04B2D542F0 ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlcese30.dll
08:53:31.0226 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlcese30.dll - ok
08:53:31.0236 6140 [ C72AE351BD502558587B88A435DAF256 ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceer30EN.dll
08:53:31.0236 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceer30EN.dll - ok
08:53:31.0236 6140 [ 8BC8BF60CC3C61B3C57DB203E9D0ADB7 ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceqp30.dll
08:53:31.0236 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceqp30.dll - ok
08:53:31.0246 6140 [ 720242673F04D57D7E0526526312891F ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceme30.dll
08:53:31.0246 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceme30.dll - ok
08:53:31.0256 6140 [ F1BD9AC32D480A74C440FC18887FC2F2 ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceoledb30.dll
08:53:31.0256 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceoledb30.dll - ok
08:53:31.0256 6140 [ 5B2394178B7E0F123536C7E8943F51B0 ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceca30.dll
08:53:31.0256 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlceca30.dll - ok
08:53:31.0266 6140 [ F2A4D5AB7F803BA06B051737E3D9251A ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlcecompact30.dll
08:53:31.0266 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\sqlcecompact30.dll - ok
08:53:31.0276 6140 [ 6C69EA6A0C308A0FB81992CAC9F39C59 ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll
08:53:31.0276 6140 C:\Windows\Microsoft.NET\Framework\v4.0.30319\fusion.dll - ok
08:53:31.0276 6140 [ 82A98D0EB83505529AD81E4C1FADC37D ] C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll
08:53:31.0276 6140 C:\Windows\Microsoft.NET\Framework\v4.0.30319\clr.dll - ok
08:53:31.0286 6140 [ A200E7209B42BAA18F438695CE45B0B9 ] C:\Windows\assembly\GAC_MSIL\System.Data.SqlServerCe\9.0.242.0__89845dcd8080cc91\System.Data.SqlServerCe.dll
08:53:31.0286 6140 C:\Windows\assembly\GAC_MSIL\System.Data.SqlServerCe\9.0.242.0__89845dcd8080cc91\System.Data.SqlServerCe.dll - ok
08:53:31.0296 6140 [ A200E7209B42BAA18F438695CE45B0B9 ] C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\System.Data.SqlServerCe.dll
08:53:31.0296 6140 C:\Program Files\Microsoft SQL Server Compact Edition\v3.1\System.Data.SqlServerCe.dll - ok
08:53:31.0296 6140 [ 5769F5DF379CDFFF87345DA4E4D6C619 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\fr\mscorrc.dll
08:53:31.0296 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\fr\mscorrc.dll - ok
08:53:31.0306 6140 [ 3759A64A7CDD08B05BA06601AC474B58 ] C:\Program Files\iPod\bin\iPodService.Resources\hu.lproj\iPodServiceLocalized.dll
08:53:31.0306 6140 C:\Program Files\iPod\bin\iPodService.Resources\hu.lproj\iPodServiceLocalized.dll - ok
08:53:31.0316 6140 [ 6800E2D842D12FBCF945D269B0D91F9E ] C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPSFVersion.dll
08:53:31.0316 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPSFVersion.dll - ok
08:53:31.0316 6140 [ 171F1BB73D0238A7A56126D3459ECDCD ] C:\Program Files\Hewlett-Packard\HP Support Framework\Extract.exe
08:53:31.0316 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Extract.exe - ok
08:53:31.0326 6140 [ CF235893E5AAA7BC1D04364811E5F09B ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\ja.lproj\iTunesMiniPlayerLocalized.dll
08:53:31.0326 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\ja.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:31.0336 6140 [ 9B9ABD30E7B8C05349DCA83390B49C23 ] C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\CheckBattery.exe
08:53:31.0336 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\CheckBattery.exe - ok
08:53:31.0336 6140 [ 0564607B688E020F1D87424CD52CFA8E ] C:\Program Files\iPod\bin\iPodService.Resources\fr.lproj\iPodServiceLocalized.dll
08:53:31.0336 6140 C:\Program Files\iPod\bin\iPodService.Resources\fr.lproj\iPodServiceLocalized.dll - ok
08:53:31.0346 6140 [ 86919B26AE34113C1374C752B015F3DE ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\en.lproj\SyncUICoreLocalized.dll
08:53:31.0346 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\en.lproj\SyncUICoreLocalized.dll - ok
08:53:31.0356 6140 [ 6EC5C9E675BA1F29586D06D14FA0A902 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ar\mscorrc.dll
08:53:31.0356 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ar\mscorrc.dll - ok
08:53:31.0356 6140 [ 4428E5A3F19F1BD7430CF8DC40F21C6E ] C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
08:53:31.0356 6140 C:\Program Files\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe - ok
08:53:31.0366 6140 [ 4194161C882418A678EC379D5EADB59B ] C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\pl.lproj\SoftwareUpdateLocalized.dll
08:53:31.0366 6140 C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\pl.lproj\SoftwareUpdateLocalized.dll - ok
08:53:31.0376 6140 [ E3C999A27C10D24FCF9BF2E02085CC37 ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DA\HPWAMain.resources.dll
08:53:31.0376 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DA\HPWAMain.resources.dll - ok
08:53:31.0386 6140 [ 73C39BA6DBE8CD48FF2EE214B908B50E ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\fr\Microsoft.VisualBasic.resources.dll
08:53:31.0386 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\fr\Microsoft.VisualBasic.resources.dll - ok
08:53:31.0386 6140 [ 4964A5D10A35640BD97919553B8FCCBB ] C:\Program Files\iPod\bin\iPodService.Resources\es.lproj\iPodServiceLocalized.dll
08:53:31.0386 6140 C:\Program Files\iPod\bin\iPodService.Resources\es.lproj\iPodServiceLocalized.dll - ok
08:53:31.0396 6140 [ 16ADD4619540B9CFFE9DD5E323AEFE8F ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\zh_CN.lproj\SyncUICoreLocalized.dll
08:53:31.0396 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\zh_CN.lproj\SyncUICoreLocalized.dll - ok
08:53:31.0396 6140 [ B2F421D5270184B0DA808D4177A7DE05 ] C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fr.lproj\SoftwareUpdateFilesLocalized.dll
08:53:31.0396 6140 C:\Program Files\Apple Software Update\SoftwareUpdateFiles.Resources\fr.lproj\SoftwareUpdateFilesLocalized.dll - ok
08:53:31.0406 6140 [ 6C6D36BCD73F8BE01CB8AA2693BBFF87 ] C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe
08:53:31.0406 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\HPSFReport.exe - ok
08:53:31.0416 6140 [ 22538D34A639FE53D28A9DBB2A261178 ] C:\Program Files\Apple Software Update\ScriptingObjectModel.dll
08:53:31.0416 6140 C:\Program Files\Apple Software Update\ScriptingObjectModel.dll - ok
08:53:31.0416 6140 [ AD224347A432CC3A6AC3BB40DAA5ABB4 ] C:\Program Files\Symantec\Norton Online Backup\it\ARA.resources.dll
08:53:31.0416 6140 C:\Program Files\Symantec\Norton Online Backup\it\ARA.resources.dll - ok
08:53:31.0426 6140 [ 9BB1F801A89A9FEEEB448E38841C2269 ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\da.lproj\SyncUICoreLocalized.dll
08:53:31.0426 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.resources\da.lproj\SyncUICoreLocalized.dll - ok
08:53:31.0436 6140 [ D566F88E63A0525D20BC8E1FBE24E3D8 ] C:\Program Files\iPod\bin\iPodService.Resources\ru.lproj\iPodServiceLocalized.dll
08:53:31.0436 6140 C:\Program Files\iPod\bin\iPodService.Resources\ru.lproj\iPodServiceLocalized.dll - ok
08:53:31.0436 6140 [ 73A53BCFFE98F9483A967F289845AF03 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\nl\SoftpaqDownloadManager.resources.dll
08:53:31.0436 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\nl\SoftpaqDownloadManager.resources.dll - ok
08:53:31.0446 6140 [ 6EC2B6E515C02839446352325F2D5297 ] C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\Interop.HelpPane.dll
08:53:31.0446 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\Interop.HelpPane.dll - ok
08:53:31.0456 6140 [ ABB237204571AC35FE5EF44B2D66B9ED ] C:\Program Files\Hewlett-Packard\HP Support Framework\Warranty\HPSFConfigReader.dll
08:53:31.0456 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Warranty\HPSFConfigReader.dll - ok
08:53:31.0456 6140 [ B40CA4D4DF3A021F26958F2D159D19DF ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\mscorrc.dll
08:53:31.0456 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\mscorrc.dll - ok
08:53:31.0466 6140 [ A7379D0DC7B1346E401013B2086E5568 ] C:\Program Files\iTunes\iPodUpdaterExt.dll
08:53:31.0466 6140 C:\Program Files\iTunes\iPodUpdaterExt.dll - ok
08:53:31.0476 6140 [ CA432C50E07DD1A4C48884ECB61BCD89 ] C:\Program Files\Hewlett-Packard\Shared\CaslVer.exe
08:53:31.0476 6140 C:\Program Files\Hewlett-Packard\Shared\CaslVer.exe - ok
08:53:31.0476 6140 [ 2626D88D1E6BCF9FAF4394D021781BC2 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\de\SoftpaqDownloadManager.resources.dll
08:53:31.0476 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\de\SoftpaqDownloadManager.resources.dll - ok
08:53:31.0486 6140 [ DED2131B90E8E7FD32B8C3FF997E3349 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\ko\SoftpaqDownloadManager.resources.dll
08:53:31.0486 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\ko\SoftpaqDownloadManager.resources.dll - ok
08:53:31.0496 6140 [ 8286F8578773834C93F30A35C821B957 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\tr\SoftpaqDownloadManager.resources.dll
08:53:31.0496 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\tr\SoftpaqDownloadManager.resources.dll - ok
08:53:31.0496 6140 [ 178F99594E8968FDD7E441C2D504D108 ] C:\Program Files\iTunes\iTunesMiniPlayer.dll
08:53:31.0496 6140 C:\Program Files\iTunes\iTunesMiniPlayer.dll - ok
08:53:31.0506 6140 [ F33230E021C53B1A2413BFFB7A54EBA9 ] C:\Windows\assembly\GAC_MSIL\Interop.HPQTOASTERLib\1.0.0.0__67b8d1b5179ba5f8\Interop.HPQTOASTERLib.dll
08:53:31.0506 6140 C:\Windows\assembly\GAC_MSIL\Interop.HPQTOASTERLib\1.0.0.0__67b8d1b5179ba5f8\Interop.HPQTOASTERLib.dll - ok
08:53:31.0516 6140 [ 572FB7A78F4080A894CE02DDBBA55EF2 ] C:\Program Files\Hewlett-Packard\HP HotKey Support\hpUIFramework.dll
08:53:31.0516 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\hpUIFramework.dll - ok
08:53:31.0526 6140 [ 88F3F6646AFAFF31D50EE7112C3F20C7 ] C:\swsetup\AppInstl\HPSoftwareSetup.exe
08:53:31.0526 6140 C:\swsetup\AppInstl\HPSoftwareSetup.exe - ok
08:53:31.0526 6140 [ B04E9BE37D07CFAD10A064F1E364F0F9 ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\HWDetect.dll
08:53:31.0526 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\HWDetect.dll - ok
08:53:31.0536 6140 [ 42A80C8248DA570AA0D28A8CDD8DCB1A ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ar\system.resources.dll
08:53:31.0536 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ar\system.resources.dll - ok
08:53:31.0546 6140 [ 5BA2C3D996853F4DE4E05D68D514831B ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\lv\mscorlib.resources.dll
08:53:31.0546 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\lv\mscorlib.resources.dll - ok
08:53:31.0546 6140 [ 77C25B246F06042DCF0832028157EE5C ] C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\hddide.dll
08:53:31.0546 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\HPDOM\hddide.dll - ok
08:53:31.0556 6140 [ 361A47591FD31EC99A9794B6541360A6 ] C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll
08:53:31.0556 6140 C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll - ok
08:53:31.0566 6140 [ A76104D8D9ABA3670FD3CEA603D70ADA ] C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll
08:53:31.0566 6140 C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll - ok
08:53:31.0566 6140 [ C38774421C7B64D2C23129A200C60F47 ] C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll
08:53:31.0566 6140 C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll - ok
08:53:31.0576 6140 [ DB59CCE916665D8C9A8A87198DAEDE34 ] C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll
08:53:31.0576 6140 C:\Windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll - ok
08:53:31.0586 6140 [ 097E968857C828064DF347C8E8D0248D ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
08:53:31.0586 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll - ok
08:53:31.0586 6140 [ 53431F06DEDF0D0C337DA2E6EF65B432 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\sl\mscorlib.resources.dll
08:53:31.0586 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\sl\mscorlib.resources.dll - ok
08:53:31.0596 6140 [ C0961F04A6962FD0745CD89E298644C3 ] C:\Windows\assembly\GAC_MSIL\Interop.HPQWMIEXLib\1.0.0.0__67b8d1b5179ba5f8\Interop.HPQWMIEXLib.dll
08:53:31.0596 6140 C:\Windows\assembly\GAC_MSIL\Interop.HPQWMIEXLib\1.0.0.0__67b8d1b5179ba5f8\Interop.HPQWMIEXLib.dll - ok
08:53:31.0606 6140 [ 4EED1B0B7018925935182A850C5249B6 ] C:\Program Files\Hewlett-Packard\HP HotKey Support\sv\HandlersStrings.resources.dll
08:53:31.0606 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\sv\HandlersStrings.resources.dll - ok
08:53:31.0606 6140 [ 89F63C41363743551A661B07091AE9A9 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ro\Microsoft.VisualBasic.resources.dll
08:53:31.0606 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ro\Microsoft.VisualBasic.resources.dll - ok
08:53:31.0616 6140 [ A29AFD62C08C0896CF0F293B021D7C63 ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\JA\HPWAMain.resources.dll
08:53:31.0616 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\JA\HPWAMain.resources.dll - ok
08:53:31.0626 6140 [ FB0E41E35FA5141D95E4ADF21CA2245C ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\LogClassLibrary.dll
08:53:31.0626 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\LogClassLibrary.dll - ok
08:53:31.0626 6140 [ E3180D60623BF8B38E668A3A049B5505 ] C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\en.lproj\SoftwareUpdateLocalized.dll
08:53:31.0626 6140 C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\en.lproj\SoftwareUpdateLocalized.dll - ok
08:53:31.0636 6140 [ 95B78DAC95199871A1932B636BCFD38B ] C:\Program Files\iPod\bin\iPodService.Resources\sk.lproj\iPodServiceLocalized.dll
08:53:31.0636 6140 C:\Program Files\iPod\bin\iPodService.Resources\sk.lproj\iPodServiceLocalized.dll - ok
08:53:31.0646 6140 [ 8D0D0EE7C71D831BF209534CD3F21FCE ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ja\mscorlib.resources.dll
08:53:31.0646 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ja\mscorlib.resources.dll - ok
08:53:31.0646 6140 [ D5041B8920A65CFF3BAE85C1AC7C8FE4 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\he\mscorlib.resources.dll
08:53:31.0646 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\he\mscorlib.resources.dll - ok
08:53:31.0656 6140 [ 6E04C50CA4A3FA2CC812CD7AB84EB6D7 ] C:\Program Files\Common Files\Skype\Skype4COM.dll
08:53:31.0656 6140 C:\Program Files\Common Files\Skype\Skype4COM.dll - ok
08:53:31.0666 6140 [ 185ADA973B5020655CEE342059A86CBB ] C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\x86\GEARAspiWDM.sys
08:53:31.0666 6140 C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1\x86\x86\GEARAspiWDM.sys - ok
08:53:31.0666 6140 [ 16B77529F7FEC6986E454F73620B9B07 ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncDiagnostics_main.dll
08:53:31.0666 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncDiagnostics_main.dll - ok
08:53:31.0676 6140 [ 0D8CEC780BB83E3F62C1B8A90B7FFC35 ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUIHandlerDLL.dll
08:53:31.0676 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUIHandlerDLL.dll - ok
08:53:31.0686 6140 [ EFC122C14082D3D73FCD53C68723E38F ] C:\Program Files\Hewlett-Packard\HP Support Framework\Interop.HpUpdateComponentLib.dll
08:53:31.0686 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Interop.HpUpdateComponentLib.dll - ok
08:53:31.0686 6140 [ 48A375F62462ACB1629C7A2232A0AADF ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\th\SoftpaqDownloadManager.resources.dll
08:53:31.0686 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\th\SoftpaqDownloadManager.resources.dll - ok
08:53:31.0696 6140 [ 79DA8CB95E82437F6A0180734BA6E753 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\nl\mscorrc.dll
08:53:31.0696 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\nl\mscorrc.dll - ok
08:53:31.0706 6140 [ EB445751B25230CB084D624766D90DF5 ] C:\Program Files\Hewlett-Packard\HP Health Check\HPSF_Utils.exe
08:53:31.0706 6140 C:\Program Files\Hewlett-Packard\HP Health Check\HPSF_Utils.exe - ok
08:53:31.0706 6140 [ 856EFA6D87929259E85D146D7DA19503 ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\ro.lproj\iTunesMiniPlayerLocalized.dll
08:53:31.0706 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\ro.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:31.0716 6140 [ E6C56A6FE964AF2A18A7FAAE3F30EE49 ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncDiagnostics.exe
08:53:31.0716 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncDiagnostics.exe - ok
08:53:31.0726 6140 [ 7402E14B93958AC9CB3BB7BB677CE011 ] C:\Program Files\Google\Google Earth\plugin\alchemy\optimizations\IGOptExtension.dll
08:53:31.0726 6140 C:\Program Files\Google\Google Earth\plugin\alchemy\optimizations\IGOptExtension.dll - ok
08:53:31.0726 6140 [ 26CA9F4D9290DCDC1D8C8C2C2BF2294F ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\it\Microsoft.VisualBasic.resources.dll
08:53:31.0726 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\it\Microsoft.VisualBasic.resources.dll - ok
08:53:31.0736 6140 [ 72CD487466E3677A7754A8C092221B7D ] C:\Program Files\iTunes\iTunesHelper.Resources\de.lproj\iTunesHelperLocalized.dll
08:53:31.0736 6140 C:\Program Files\iTunes\iTunesHelper.Resources\de.lproj\iTunesHelperLocalized.dll - ok
08:53:31.0746 6140 [ E9EAF9A3F0B6F1A663DEA7C33324ABF1 ] C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll
08:53:31.0746 6140 C:\Program Files\Common Files\microsoft shared\VC\msdia90.dll - ok
08:53:31.0746 6140 [ 9E21C67710E90756DEA2F9D858530F72 ] C:\Program Files\iTunes\iTunes.Resources\sv.lproj\iTunesLocalized.dll
08:53:31.0756 6140 C:\Program Files\iTunes\iTunes.Resources\sv.lproj\iTunesLocalized.dll - ok
08:53:31.0756 6140 [ 4A25C09E69E52EC0B9EB178DFEB04457 ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServices\Schemas\Notes.syncschema\Contents\Windows\Notes.dll
08:53:31.0756 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServices\Schemas\Notes.syncschema\Contents\Windows\Notes.dll - ok
08:53:31.0766 6140 [ 8DDDC6E0D50EB5A5E859F314F74B16A5 ] C:\Program Files\iTunes\iTunes.Resources\pl.lproj\iTunesLocalized.dll
08:53:31.0766 6140 C:\Program Files\iTunes\iTunes.Resources\pl.lproj\iTunesLocalized.dll - ok
08:53:31.0776 6140 [ C82BC6335F0DBAC118016AB9061A854C ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\uk\mscorlib.resources.dll
08:53:31.0776 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\uk\mscorlib.resources.dll - ok
08:53:31.0776 6140 [ F411617EB87719020442F3DE4B437CE9 ] C:\Program Files\iTunes\iTunesHelper.Resources\pl.lproj\iTunesHelperLocalized.dll
08:53:31.0776 6140 C:\Program Files\iTunes\iTunesHelper.Resources\pl.lproj\iTunesHelperLocalized.dll - ok
08:53:31.0786 6140 [ B9080BAC8807AECE84E3989B0544CFA6 ] C:\Windows\System32\jdns_sd.dll
08:53:31.0786 6140 C:\Windows\System32\jdns_sd.dll - ok
08:53:31.0796 6140 [ 254E3B06494EEAF1F735E2AC49EFF24C ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.dll
08:53:31.0796 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncUICore.dll - ok
08:53:31.0796 6140 [ 9D2E482AB4DBFFF755725AE04DF12CE3 ] C:\Program Files\iPod\bin\iPodService.Resources\hr.lproj\iPodServiceLocalized.dll
08:53:31.0796 6140 C:\Program Files\iPod\bin\iPodService.Resources\hr.lproj\iPodServiceLocalized.dll - ok
08:53:31.0806 6140 [ E2D0FAA0F0761B3C38372A257B1668BF ] C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServices\Clients\com.apple.Safari\com.apple.Safari.isRegistered.dll
08:53:31.0806 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServices\Clients\com.apple.Safari\com.apple.Safari.isRegistered.dll - ok
08:53:31.0816 6140 [ A459B7ADF43C228C59D2438DF69CC1C0 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ar\mscorlib.resources.dll
08:53:31.0816 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ar\mscorlib.resources.dll - ok
08:53:31.0816 6140 [ 311CDB3E8FB4D0B8C72D2981B6ACE4F3 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\bg\Microsoft.VisualBasic.resources.dll
08:53:31.0816 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\bg\Microsoft.VisualBasic.resources.dll - ok
08:53:31.0826 6140 [ A535E9AC2E26F98DF0E963B0FBDCAB9A ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\da\SoftpaqDownloadManager.resources.dll
08:53:31.0826 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\da\SoftpaqDownloadManager.resources.dll - ok
08:53:31.0836 6140 [ 0CCFFAE55A39074A19687211B9D9FDA4 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\th\mscorrc.dll
08:53:31.0836 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\th\mscorrc.dll - ok
08:53:31.0836 6140 [ C5FE20B87DCE62EEDC583033234C61A4 ] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncMapiInterface.dll
08:53:31.0836 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncMapiInterface.dll - ok
08:53:31.0846 6140 [ F4F18E9646E85D371A687F17170AD0DD ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\nl\mscorlib.resources.dll
08:53:31.0846 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\nl\mscorlib.resources.dll - ok
08:53:31.0856 6140 [ AC126FDF4FDE90A9CE6E9B23D449771C ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\zh_TW.lproj\iTunesMiniPlayerLocalized.dll
08:53:31.0856 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\zh_TW.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:31.0856 6140 [ BFFF991DE8DEE94D0A4BB6BE05FBDD23 ] C:\Program Files\Symantec\Norton Online Backup\ru\ARA.resources.dll
08:53:31.0856 6140 C:\Program Files\Symantec\Norton Online Backup\ru\ARA.resources.dll - ok
08:53:31.0866 6140 [ 7A9F21037C0F951280419C3D062F9327 ] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileBackup_main.dll
08:53:31.0866 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileBackup_main.dll - ok
08:53:31.0876 6140 [ 5E7342F9B419B91644847807670752E3 ] C:\Program Files\iTunes\iTunesMiniPlayer.Resources\zh_CN.lproj\iTunesMiniPlayerLocalized.dll
08:53:31.0876 6140 C:\Program Files\iTunes\iTunesMiniPlayer.Resources\zh_CN.lproj\iTunesMiniPlayerLocalized.dll - ok
08:53:31.0876 6140 [ 25D36BC6F3345E78F70B384B414D7597 ] C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\fi.lproj\SoftwareUpdateLocalized.dll
08:53:31.0876 6140 C:\Program Files\Apple Software Update\SoftwareUpdate.Resources\fi.lproj\SoftwareUpdateLocalized.dll - ok
08:53:31.0886 6140 [ 4B733DE782C80E773B75897ED7727493 ] C:\Program Files\iTunes\iTunes.Resources\zh_TW.lproj\iTunesLocalized.dll
08:53:31.0886 6140 C:\Program Files\iTunes\iTunes.Resources\zh_TW.lproj\iTunesLocalized.dll - ok
08:53:31.0896 6140 [ F87CD4CE3ABDC85FA70672F1730533A7 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\uk\system.resources.dll
08:53:31.0896 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\uk\system.resources.dll - ok
08:53:31.0896 6140 [ 1B2E7E2E66F379698F5CAC342A39D6C2 ] C:\Program Files\Google\Google Earth\client\Plugins\npgeinprocessplugin.dll
08:53:31.0896 6140 C:\Program Files\Google\Google Earth\client\Plugins\npgeinprocessplugin.dll - ok
08:53:31.0906 6140 [ 1E4A8130772D727BA84014F239486B49 ] C:\Program Files\Google\Google Earth\plugin\alchemy\ogl\IGAttrs.dll
08:53:31.0906 6140 C:\Program Files\Google\Google Earth\plugin\alchemy\ogl\IGAttrs.dll - ok
08:53:31.0916 6140 [ 8497531CE1452AC2A4BB26F71E4CAC5A ] C:\Program Files\Google\Google Earth\plugin\alchemy\ogl\IGGfx.dll
08:53:31.0916 6140 C:\Program Files\Google\Google Earth\plugin\alchemy\ogl\IGGfx.dll - ok
08:53:31.0916 6140 [ D1559D2508661AA8043C1B562DC4EED4 ] C:\Program Files\Google\Google Earth\plugin\alchemy\ogl\IGSg.dll
08:53:31.0916 6140 C:\Program Files\Google\Google Earth\plugin\alchemy\ogl\IGSg.dll - ok
08:53:31.0926 6140 [ BCF4E6AD24754097918612A9B7B6E6AD ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WAMobCtr.exe
08:53:31.0926 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WAMobCtr.exe - ok
08:53:31.0936 6140 [ 4EFAB1C6C4BFFF293D272240D88169D0 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\da\mscorrc.dll
08:53:31.0936 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\da\mscorrc.dll - ok
08:53:31.0936 6140 [ 58974C653D14865E57F2AA7EA3F05A27 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\da\mscorlib.resources.dll
08:53:31.0936 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\da\mscorlib.resources.dll - ok
08:53:31.0946 6140 [ 8A59FCA23EF89C0ACD6976A24602D708 ] C:\Program Files\Hewlett-Packard\HP HotKey Support\fr\HandlersStrings.resources.dll
08:53:31.0946 6140 C:\Program Files\Hewlett-Packard\HP HotKey Support\fr\HandlersStrings.resources.dll - ok
08:53:31.0956 6140 [ 1EFEE7E060C65B92BDD187DFA51604D7 ] C:\Program Files\Hewlett-Packard\HP Support Framework\SIDUtilities.dll
08:53:31.0956 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\SIDUtilities.dll - ok
08:53:31.0956 6140 [ 8663B723D8AF24750D7CA57040B75012 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\Microsoft.VisualBasic.dll
08:53:31.0956 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\Microsoft.VisualBasic.dll - ok
08:53:31.0966 6140 [ 1E4A8130772D727BA84014F239486B49 ] C:\Program Files\Google\Google Earth\client\IGAttrs.dll
08:53:31.0966 6140 C:\Program Files\Google\Google Earth\client\IGAttrs.dll - ok
08:53:31.0976 6140 [ 077B770CBBDD895AA30A93358D3D9757 ] C:\Program Files\Google\Google Earth\client\IGCore.dll
08:53:31.0976 6140 C:\Program Files\Google\Google Earth\client\IGCore.dll - ok
08:53:31.0976 6140 [ 9374052FCA34FBAD4B3B0B1BC28F4FEF ] C:\Program Files\Google\Google Earth\client\IGExportCommon.dll
08:53:31.0976 6140 C:\Program Files\Google\Google Earth\client\IGExportCommon.dll - ok
08:53:31.0986 6140 [ 8497531CE1452AC2A4BB26F71E4CAC5A ] C:\Program Files\Google\Google Earth\client\IGGfx.dll
08:53:31.0986 6140 C:\Program Files\Google\Google Earth\client\IGGfx.dll - ok
08:53:31.0996 6140 [ C809D48B2B5653230EFF0639E0C3F7DE ] C:\Program Files\Google\Google Earth\client\IGMath.dll
08:53:31.0996 6140 C:\Program Files\Google\Google Earth\client\IGMath.dll - ok
08:53:31.0996 6140 [ 3D0F415E9E4E44C1E738E15EC93C3D53 ] C:\Program Files\Google\Google Earth\client\IGOpt.dll
08:53:31.0996 6140 C:\Program Files\Google\Google Earth\client\IGOpt.dll - ok
08:53:32.0006 6140 [ D1559D2508661AA8043C1B562DC4EED4 ] C:\Program Files\Google\Google Earth\client\IGSg.dll
08:53:32.0006 6140 C:\Program Files\Google\Google Earth\client\IGSg.dll - ok
08:53:32.0016 6140 [ 81825EC090D51B14B3F41D6FE48C8E12 ] C:\Program Files\Google\Google Earth\client\IGUtils.dll
08:53:32.0016 6140 C:\Program Files\Google\Google Earth\client\IGUtils.dll - ok
08:53:32.0026 6140 [ A725A2C0DD788A02A32BDE1DD9C72880 ] C:\Program Files\Google\Google Earth\client\QtCore4.dll
08:53:32.0026 6140 C:\Program Files\Google\Google Earth\client\QtCore4.dll - ok
08:53:32.0026 6140 [ AB46B5ED48D5D6CFB8108F9A9668F72C ] C:\Program Files\Google\Google Earth\client\QtGui4.dll
08:53:32.0026 6140 C:\Program Files\Google\Google Earth\client\QtGui4.dll - ok
08:53:32.0036 6140 [ 20AB4A282C807E95374E36CC52E520BD ] C:\Program Files\Google\Google Earth\client\QtNetwork4.dll
08:53:32.0036 6140 C:\Program Files\Google\Google Earth\client\QtNetwork4.dll - ok
08:53:32.0046 6140 [ ECA0A1B9869AF0EE9D28BEC3A13F270B ] C:\Program Files\Google\Google Earth\client\QtWebKit4.dll
08:53:32.0046 6140 C:\Program Files\Google\Google Earth\client\QtWebKit4.dll - ok
08:53:32.0056 6140 [ F13BADB413C5680604D839CFB9F51587 ] C:\Program Files\Google\Google Earth\client\alchemyext.dll
08:53:32.0056 6140 C:\Program Files\Google\Google Earth\client\alchemyext.dll - ok
08:53:32.0066 6140 [ EFAB459FDD56AE93839FA817BA953A7F ] C:\Program Files\Google\Google Earth\client\earthflashsol.exe
08:53:32.0066 6140 C:\Program Files\Google\Google Earth\client\earthflashsol.exe - ok
08:53:32.0076 6140 [ 49E96960E11D0D9CD06DFF8279EC4E1D ] C:\Program Files\Google\Google Earth\client\ge_expat.dll
08:53:32.0076 6140 C:\Program Files\Google\Google Earth\client\ge_expat.dll - ok
08:53:32.0076 6140 [ CDAC6990D61774772FD1A09D90F4BD47 ] C:\Program Files\Google\Google Earth\client\googleearth_free.dll
08:53:32.0076 6140 C:\Program Files\Google\Google Earth\client\googleearth_free.dll - ok
08:53:32.0086 6140 [ 45F88C09E922FD22CE45CCD19B53AE7B ] C:\Program Files\Google\Google Earth\client\gpsbabel.exe
08:53:32.0086 6140 C:\Program Files\Google\Google Earth\client\gpsbabel.exe - ok
08:53:32.0096 6140 [ 360B5E2C91140CCA141B5CF51969F5B0 ] C:\Program Files\Google\Google Earth\client\icudt.dll
08:53:32.0096 6140 C:\Program Files\Google\Google Earth\client\icudt.dll - ok
08:53:32.0096 6140 [ 03E9314004F504A14A61C3D364B62F66 ] C:\Program Files\Google\Google Earth\client\msvcp100.dll
08:53:32.0096 6140 C:\Program Files\Google\Google Earth\client\msvcp100.dll - ok
08:53:32.0106 6140 [ 67EC459E42D3081DD8FD34356F7CAFC1 ] C:\Program Files\Google\Google Earth\client\msvcr100.dll
08:53:32.0106 6140 C:\Program Files\Google\Google Earth\client\msvcr100.dll - ok
08:53:32.0116 6140 [ E13950B3BEAB5DC6A34A14D6DF2BD044 ] C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\XMLViewerHPSF.exe
08:53:32.0116 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\Resources\XMLViewerHPSF.exe - ok
08:53:32.0116 6140 [ EB0E500928480AEB6C4F2D9306591173 ] C:\Program Files\Hewlett-Packard\Documentation\SettingsResource.dll
08:53:32.0116 6140 C:\Program Files\Hewlett-Packard\Documentation\SettingsResource.dll - ok
08:53:32.0126 6140 [ A9970042BE512C7981B36E689C5F3F9F ] C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\WdfCoInstaller01009.dll
08:53:32.0126 6140 C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\WdfCoInstaller01009.dll - ok
08:53:32.0136 6140 [ 90049A10BEBB3FDBB2FFA2F6407F4F4D ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\zh-TW\SoftpaqDownloadManager.resources.dll
08:53:32.0136 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\zh-TW\SoftpaqDownloadManager.resources.dll - ok
08:53:32.0136 6140 [ 11B8B75D05738EC5B219A30627A8EBE3 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ja\mscorrc.dll
08:53:32.0136 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ja\mscorrc.dll - ok
08:53:32.0146 6140 [ 2C4C804EA05F534AD69025E48A5CB32C ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.ServiceModel.Web.dll
08:53:32.0146 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.ServiceModel.Web.dll - ok
08:53:32.0146 6140 [ 23675ED600CA406D26DCA5EC6CF5DD74 ] C:\Program Files\iPod\bin\iPodService.Resources\en_GB.lproj\iPodServiceLocalized.dll
08:53:32.0146 6140 C:\Program Files\iPod\bin\iPodService.Resources\en_GB.lproj\iPodServiceLocalized.dll - ok
08:53:32.0156 6140 [ FA578B7AA7AE7C7D1C482D3FE7DEEBFE ] C:\Program Files\iTunes\iTunesHelper.Resources\da.lproj\iTunesHelperLocalized.dll
08:53:32.0156 6140 C:\Program Files\iTunes\iTunesHelper.Resources\da.lproj\iTunesHelperLocalized.dll - ok
08:53:32.0166 6140 [ 36C188863C98B230AD7440AA99F3FE46 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ms\mscorlib.resources.dll
08:53:32.0166 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ms\mscorlib.resources.dll - ok
08:53:32.0166 6140 [ 2C400CF3116AAA2F93548A0F897BF7A3 ] C:\Program Files\Symantec\Norton Online Backup\da\ARA.resources.dll
08:53:32.0166 6140 C:\Program Files\Symantec\Norton Online Backup\da\ARA.resources.dll - ok
08:53:32.0176 6140 [ E937E3AD4A64490D86851EA3145373DD ] C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\SoftpaqDownloadManager.exe
08:53:32.0176 6140 C:\Program Files\Hewlett-Packard\HP SoftPaq Download Manager\SoftpaqDownloadManager.exe - ok
08:53:32.0186 6140 [ B96CAE8F8224A5BA2A4931EEEA5EAE6D ] C:\x86\HpqKbFiltr.sys
08:53:32.0186 6140 C:\x86\HpqKbFiltr.sys - ok
08:53:32.0196 6140 [ 77BED3AC3939BE93EC4EB7C9A73C1324 ] C:\Program Files\iTunes\iTunes.Resources\fr.lproj\iTunesLocalized.dll
08:53:32.0196 6140 C:\Program Files\iTunes\iTunes.Resources\fr.lproj\iTunesLocalized.dll - ok
08:53:32.0196 6140 [ 6254F927A4BBA3AD58E937B5E847E8CC ] C:\Program Files\Hewlett-Packard\HP Support Framework\hpWireless.dll
08:53:32.0196 6140 C:\Program Files\Hewlett-Packard\HP Support Framework\hpWireless.dll - ok
08:53:32.0206 6140 [ CDF98CDF2F5324268FFADC57EF80D03C ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\ja\Microsoft.VisualBasic.resources.dll
08:53:32.0206 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\ja\Microsoft.VisualBasic.resources.dll - ok
08:53:32.0216 6140 [ CAE2E9F39544D7B7399F297AC07D6A99 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\agcp.exe
08:53:32.0216 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\agcp.exe - ok
08:53:32.0216 6140 [ 1205E11E8011B7B349DB14E761D97EC2 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\hu\mscorrc.dll
08:53:32.0216 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\hu\mscorrc.dll - ok
08:53:32.0226 6140 [ C84C7E595EC56A451E66440491A8244B ] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HE\HPWAMain.resources.dll
08:53:32.0226 6140 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HE\HPWAMain.resources.dll - ok
08:53:32.0236 6140 [ 24EC41F65A30F24EE7FDD4FF167CB635 ] C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.Windows.RuntimeHost.dll
08:53:32.0236 6140 C:\Program Files\Microsoft Silverlight\5.1.20125.0\System.Windows.RuntimeHost.dll - ok
08:53:32.0236 6140 [ 7CCB6AAFFDC51B58
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
Oh and incase your wondering why the times different, thats the end of a log i did just this morning. Should be the same though except for the time right?
 

Fiery

Level 1
Jan 11, 2011
2,007
One thing I don't like about this tool is the extremely long logs as I still can't see what it detected :p

If you scroll all the way to the bottom of the log, there should be a section like:

11:17:45.0640 3604 ============================================================
11:17:45.0640 3604 Scan finished
11:17:45.0640 3604 ============================================================
11:17:45.0828 3596 Detected object count: 14
11:17:45.0828 3596 Actual detected object count: 14

Copy and paste everthing after "scan finished" please.
 

Paleoworld-101

New Member
Thread author
May 6, 2013
11
Lol i thought i copied all of it, sorry mate. Here you go:

08:53:32.0916 6140 ============================================================
08:53:32.0916 6140 Scan finished
08:53:32.0916 6140 ============================================================
08:53:32.0926 5648 Detected object count: 4
08:53:32.0926 5648 Actual detected object count: 4
08:53:36.0096 5648 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - skipped by user
08:53:36.0096 5648 FLEXnet Licensing Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
08:53:36.0096 5648 HP Health Check Service ( UnsignedFile.Multi.Generic ) - skipped by user
08:53:36.0096 5648 HP Health Check Service ( UnsignedFile.Multi.Generic ) - User select action: Skip
08:53:36.0106 5648 LightScribeService ( UnsignedFile.Multi.Generic ) - skipped by user
08:53:36.0106 5648 LightScribeService ( UnsignedFile.Multi.Generic ) - User select action: Skip
08:53:36.0109 5648 TrueSight ( UnsignedFile.Multi.Generic ) - skipped by user
08:53:36.0109 5648 TrueSight ( UnsignedFile.Multi.Generic ) - User select action: Skip
 

Fiery

Level 1
Jan 11, 2011
2,007
All of those detections are ok, let's proceed :)

Download Malwarebytes Anti-Rootkit from here to your Desktop
  • Unzip the contents to a folder on your Desktop.
  • Open the folder where the contents were unzipped and run mbar.exe
  • Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
  • Make sure there is a check next to Create Restore Point and click the Cleanup button to remove any threats. Reboot if prompted to do so.
  • After the reboot, perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If there are threats, click Cleanup once more and reboot.
  • When done, please post the two logs in the MBAR folder(mbar-log.txt and system-log.txt)

Run Eset NOD32 Online AntiVirus here

Note: You will need to use Internet Explorer for this scan.
Vista / 7 users: You will need to to right-click on the Internet Explorer icon and select Run as Administrator
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your current antivirus software. You can usually do this with its Notfication Tray icon near the clock.
  • Make sure that the option "Remove found threats" is Un-checked, and the following Advance Settings are Checked
    • Scan unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Click Scan
  • Wait for the scan to finish
  • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
  • Save that text file on your desktop. Copy and paste the contents of that log in your next reply to this topic.
  • The log can also be found in logfile located at C:\Program Files\ESET\Eset Online Scanner\log.txt
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top