Malwarebytes Anti-Malware successfully blocked access to a potentially malicious site

Solved
By Parkor
Jan 13, 2013
  1. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    2013-01-02 21:30 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\System32\Recovery
    2013-01-02 21:29 - 2013-01-02 21:29 - 00001108 ____A C:\Windows\System32\netcfg-17671.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000185 ____A C:\Windows\System32\netcfg-20843.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000169 ____A C:\Windows\System32\netcfg-19968.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000164 ____A C:\Windows\System32\netcfg-17531.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000161 ____A C:\Windows\System32\netcfg-20562.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000160 ____A C:\Windows\System32\netcfg-20453.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000160 ____A C:\Windows\System32\netcfg-20343.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000160 ____A C:\Windows\System32\netcfg-17421.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000159 ____A C:\Windows\System32\netcfg-20234.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000157 ____A C:\Windows\System32\netcfg-20734.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000157 ____A C:\Windows\System32\netcfg-17296.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000150 ____A C:\Windows\System32\netcfg-20125.txt
    2013-01-02 21:29 - 2012-07-26 00:13 - 00262144 ____A C:\Windows\System32\config\BCD-Template
    2013-01-02 19:38 - 2013-01-02 18:59 - 00000000 ____D C:\Users\DJ\AppData\Roaming\WinRAR
    2013-01-02 19:36 - 2013-01-02 19:17 - 00000000 ____D C:\Users\DJ\AppData\Roaming\.minecraft
    2013-01-02 19:28 - 2013-01-02 18:46 - 00859072 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2013-01-02 19:28 - 2013-01-02 18:46 - 00779704 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2013-01-02 19:17 - 2013-01-02 19:17 - 00263186 ____A C:\Users\DJ\Downloads\Minecraft.exe
    2013-01-02 19:17 - 2013-01-02 19:16 - 00001518 ____A C:\Users\DJ\Downloads\server.log
    2013-01-02 19:17 - 2013-01-02 19:16 - 00000510 ____A C:\Users\DJ\Downloads\server.properties
    2013-01-02 19:17 - 2013-01-02 19:16 - 00000000 ____D C:\Users\DJ\Downloads\world
    2013-01-02 19:16 - 2013-01-02 19:16 - 02242895 ____A C:\Users\DJ\Downloads\Minecraft_Server.exe
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000109 ____A C:\Users\DJ\Downloads\banned-players.txt
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000109 ____A C:\Users\DJ\Downloads\banned-ips.txt
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000000 ____A C:\Users\DJ\Downloads\white-list.txt
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000000 ____A C:\Users\DJ\Downloads\ops.txt
    2013-01-02 18:59 - 2013-01-02 18:59 - 01656459 ____A C:\Users\DJ\Downloads\winrar-x64-420.exe
    2013-01-02 18:59 - 2013-01-02 18:59 - 00000000 ____D C:\Program Files\WinRAR
    2013-01-02 18:55 - 2013-01-02 18:55 - 00000117 ____A C:\Windows\System32\netcfg-1495234.txt
    2013-01-02 18:55 - 2013-01-02 18:55 - 00000117 ____A C:\Windows\System32\netcfg-1495203.txt
    2013-01-02 18:53 - 2013-01-02 18:53 - 00000000 ____D C:\Program Files (x86)\7-Zip
    2013-01-02 18:50 - 2013-01-02 18:50 - 01110476 ____A C:\Users\DJ\Downloads\7z920.exe
    2013-01-02 18:49 - 2013-01-02 18:49 - 15686819 ____A C:\Users\DJ\Downloads\jdk-7u10-windows-x64-demos.zip
    2013-01-02 18:46 - 2013-01-02 18:46 - 00000000 ____D C:\Users\All Users\Sun
    2013-01-02 18:46 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\System32\restore
    2013-01-02 18:44 - 2013-01-02 18:44 - 00896016 ____A (Oracle Corporation) C:\Users\DJ\Downloads\chromeinstall-7u10.exe
    2013-01-02 18:42 - 2013-01-02 18:42 - 00000000 ____D C:\Users\DJ\AppData\Roaming\Macromedia
    2013-01-02 18:40 - 2013-01-02 18:40 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
    2013-01-02 18:40 - 2013-01-02 18:40 - 00000000 ___RD C:\Program Files (x86)\Skype
    2013-01-02 18:40 - 2013-01-02 18:40 - 00000000 ____D C:\Users\All Users\Skype
    2013-01-02 18:40 - 2013-01-02 18:40 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2013-01-02 18:40 - 2013-01-02 18:39 - 29304496 ____A (Skype Technologies S.A.) C:\Users\DJ\Downloads\SkypeSetupFull.exe
    2013-01-02 18:36 - 2013-01-02 18:36 - 00002293 ____A C:\Users\DJ\Desktop\Google Chrome.lnk
    2013-01-02 18:34 - 2013-01-02 18:34 - 00000278 ____A C:\Windows\System32\netcfg-231171.txt
    2013-01-02 18:34 - 2013-01-02 18:34 - 00000117 ____A C:\Windows\System32\netcfg-233750.txt
    2013-01-02 18:34 - 2013-01-02 18:34 - 00000117 ____A C:\Windows\System32\netcfg-230875.txt
    2013-01-02 18:32 - 2013-01-02 18:32 - 00000000 ____D C:\Users\DJ\AppData\Roaming\Adobe
    2013-01-02 18:32 - 2013-01-02 18:32 - 00000000 ____D C:\Users\DJ\AppData\Local\VirtualStore
    2013-01-02 18:32 - 2013-01-02 18:32 - 00000000 ____D C:\Users\All Users\PRICache
    2013-01-02 18:31 - 2013-01-02 21:31 - 00000117 ____A C:\Windows\System32\netcfg-58687.txt
    2013-01-02 18:31 - 2013-01-02 18:31 - 00000020 ___SH C:\Users\DJ\ntuser.ini
    2012-12-18 15:32 - 2012-07-26 00:14 - 00695640 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-12-18 15:32 - 2012-07-26 00:14 - 00080728 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-12-16 00:28 - 2013-01-03 18:34 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
    2012-12-16 00:20 - 2013-01-03 18:34 - 00035328 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2012-12-16 00:08 - 2013-01-03 18:34 - 00362496 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
    2012-12-15 23:57 - 2013-01-03 18:34 - 00300032 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2012-12-14 13:49 - 2013-01-12 19:20 - 00024176 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys

    ==================== Known DLLs (Whitelisted) =================
  2. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe
    [2013-01-04 14:20] - [2012-10-10 21:46] - 0517120 ____A (Microsoft Corporation) BCF2036A0DD579E47C008C133550283E

    C:\Windows\System32\wininit.exe
    [2012-07-25 16:03] - [2012-07-25 19:08] - 0132608 ____A (Microsoft Corporation) FE9AB232B56A12224E8A3F3F9878C9A3

    C:\Windows\explorer.exe
    [2013-01-04 14:20] - [2012-10-10 23:35] - 2380944 ____A (Microsoft Corporation) E13A31D5254C25406A7946BDD9B06364

    C:\Windows\SysWOW64\explorer.exe
    [2013-01-04 14:20] - [2012-10-10 21:56] - 2115952 ____A (Microsoft Corporation) 953ADECFF08202A01EFC6110214FDE02

    C:\Windows\System32\svchost.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0029696 ____A (Microsoft Corporation) EDE27EACE742EE2888C5DD36400A2EC0

    C:\Windows\SysWOW64\svchost.exe
    [2013-01-09 13:41] - [2012-09-19 21:55] - 0023040 ____A (Microsoft Corporation) A46DC432F81473F526E3994AA483E366

    C:\Windows\System32\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 8F226143046435C75C033B0C52E90FFE

    C:\Windows\System32\User32.dll
    [2013-01-09 13:41] - [2012-09-19 22:33] - 1342464 ____A (Microsoft Corporation) A99AD14F26BDA7D7F27F76BC91B7EED7

    C:\Windows\SysWOW64\User32.dll
    [2013-01-09 13:41] - [2012-09-19 20:10] - 1126912 ____A (Microsoft Corporation) BA1C3ACD929A71E88B49C2B6E38F92B3

    C:\Windows\System32\userinit.exe
    [2012-07-25 16:06] - [2012-07-25 19:08] - 0025088 ____A (Microsoft Corporation) 0E925F7BA032920D58DD284B6181A247

    C:\Windows\SysWOW64\userinit.exe
    [2012-07-25 16:08] - [2012-07-25 19:21] - 0021504 ____A (Microsoft Corporation) 9F6289D194A04A09671FEED4B6CB6EF7

    C:\Windows\System32\Drivers\volsnap.sys
    [2012-07-25 18:30] - [2012-07-25 20:57] - 0332016 ____A (Microsoft Corporation) 2FB3CDFD5EAF4CD9D4AFAF96877D13AE


    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================


    ==================== Memory info ===========================

    Percentage of memory in use: 6%
    Total physical RAM: 16345.79 MB
    Available physical RAM: 15225.52 MB
    Total Pagefile: 16345.79 MB
    Available Pagefile: 15229.74 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.87 MB

    ==================== Partitions =============================

    1 Drive c: () (Fixed) (Total:55.9 GB) (Free:13.82 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    2 Drive d: (System Reserved) (Fixed) (Total:0.34 GB) (Free:0.29 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    3 Drive e: () (Removable) (Total:1.91 GB) (Free:0.25 GB) FAT
    4 Drive f: () (Fixed) (Total:1396.92 GB) (Free:1142.41 GB) NTFS
    6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS


    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 55 GB 0 B
    Disk 1 Online 1397 GB 0 B
    Disk 2 Online 1960 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 55 GB 1024 KB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C NTFS Partition 55 GB Healthy

    =========================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 350 MB 1024 KB
    Partition 2 Primary 1396 GB 351 MB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 D System Rese NTFS Partition 350 MB Healthy

    =========================================================

    Disk: 1
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F NTFS Partition 1396 GB Healthy

    =========================================================

    Partitions of Disk 2:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1959 MB 760 KB

    ==================================================================================

    Disk: 2
    Partition 1
    Type : 06
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 E FAT Removable 1959 MB Healthy

    =========================================================

    Last Boot: 2013-01-13 06:29

    ==================== End Of Log =============================
  3. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    Farbar Recovery Scan Tool (x64) Version: 09-01-2013
    Ran by SYSTEM at 2013-01-13 22:52:12
    Running from E:\

    ================== Search: "services.exe" ===================

    C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.20521_none_98a9ea2e9f571eb2\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 581190907DA1CF8CB7B87B35FFE64A07

    C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16420_none_981f4d19863a6591\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 8F226143046435C75C033B0C52E90FFE

    C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
    [2012-07-25 21:26] - [2012-07-25 21:26] - 0410624 ____A (Microsoft Corporation) 754A2CC1F32107EA87CBD305ABE3E618

    C:\Windows\System32\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 8F226143046435C75C033B0C52E90FFE

    ====== End Of Search ======
  4. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    All looks clean.

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
  5. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    23:45:43.0362 3832 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
    23:45:43.0721 3832 ============================================================
    23:45:43.0737 3832 Current date / time: 2013/01/13 23:45:43.0721
    23:45:43.0737 3832 SystemInfo:
    23:45:43.0737 3832
    23:45:43.0737 3832 OS Version: 6.2.9200 ServicePack: 0.0
    23:45:43.0737 3832 Product type: Workstation
    23:45:43.0737 3832 ComputerName: PARKER
    23:45:43.0737 3832 UserName: DJ
    23:45:43.0737 3832 Windows directory: C:\Windows
    23:45:43.0737 3832 System windows directory: C:\Windows
    23:45:43.0737 3832 Running under WOW64
    23:45:43.0737 3832 Processor architecture: Intel x64
    23:45:43.0737 3832 Number of processors: 4
    23:45:43.0737 3832 Page size: 0x1000
    23:45:43.0737 3832 Boot type: Normal boot
    23:45:43.0737 3832 ============================================================
    23:45:43.0784 3832 BG loaded
    23:45:43.0955 3832 Drive \Device\Harddisk0\DR0 - Size: 0xDF99E6000 (55.90 Gb), SectorSize: 0x200, Cylinders: 0x1C81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    23:45:43.0971 3832 Drive \Device\Harddisk1\DR1 - Size: 0x15D50F66000 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    23:45:43.0971 3832 Drive \Device\Harddisk2\DR2 - Size: 0x7A800000 (1.91 Gb), SectorSize: 0x200, Cylinders: 0xF9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
    23:45:43.0971 3832 ============================================================
    23:45:43.0971 3832 \Device\Harddisk0\DR0:
    23:45:43.0971 3832 MBR partitions:
    23:45:43.0971 3832 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x6FCF202
    23:45:43.0971 3832 \Device\Harddisk1\DR1:
    23:45:43.0971 3832 MBR partitions:
    23:45:43.0971 3832 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAF000
    23:45:43.0971 3832 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0xAF800, BlocksNum 0xAE9DAE02
    23:45:43.0971 3832 \Device\Harddisk2\DR2:
    23:45:43.0971 3832 MBR partitions:
    23:45:43.0971 3832 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x6, StartLBA 0x5F0, BlocksNum 0x3D3A10
    23:45:43.0971 3832 ============================================================
    23:45:43.0971 3832 C: <-> \Device\Harddisk0\DR0\Partition1
    23:45:43.0971 3832 D: <-> \Device\Harddisk1\DR1\Partition1
    23:45:44.0002 3832 E: <-> \Device\Harddisk1\DR1\Partition2
    23:45:44.0002 3832 ============================================================
    23:45:44.0002 3832 Initialize success
    23:45:44.0002 3832 ============================================================
    23:45:52.0143 4888 ============================================================
    23:45:52.0143 4888 Scan started
    23:45:52.0143 4888 Mode: Manual; SigCheck; TDLFS;
    23:45:52.0143 4888 ============================================================
    23:45:52.0206 4888 ================ Scan system memory ========================
    23:45:52.0206 4888 System memory - ok
    23:45:52.0206 4888 ================ Scan services =============================
    23:45:52.0206 4888 [ 581D88B25C4D4121824FED2CA38E562F ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    23:45:52.0253 4888 !SASCORE - ok
    23:45:52.0300 4888 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
    23:45:52.0315 4888 1394ohci - ok
    23:45:52.0315 4888 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
    23:45:52.0331 4888 3ware - ok
    23:45:52.0331 4888 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
    23:45:52.0346 4888 ACPI - ok
    23:45:52.0346 4888 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
    23:45:52.0362 4888 acpiex - ok
    23:45:52.0362 4888 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
    23:45:52.0362 4888 acpipagr - ok
    23:45:52.0362 4888 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
    23:45:52.0378 4888 AcpiPmi - ok
    23:45:52.0378 4888 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
    23:45:52.0393 4888 acpitime - ok
    23:45:52.0425 4888 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    23:45:52.0425 4888 AdobeFlashPlayerUpdateSvc - ok
    23:45:52.0440 4888 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
    23:45:52.0440 4888 adp94xx - ok
    23:45:52.0456 4888 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
    23:45:52.0471 4888 adpahci - ok
    23:45:52.0471 4888 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
    23:45:52.0471 4888 adpu320 - ok
    23:45:52.0487 4888 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    23:45:52.0487 4888 AeLookupSvc - ok
    23:45:52.0503 4888 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\Windows\system32\drivers\afd.sys
    23:45:52.0518 4888 AFD - ok
    23:45:52.0518 4888 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
    23:45:52.0518 4888 agp440 - ok
    23:45:52.0534 4888 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
    23:45:52.0534 4888 ALG - ok
    23:45:52.0534 4888 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
    23:45:52.0550 4888 AllUserInstallAgent - ok
    23:45:52.0550 4888 [ 4C1E3649C89C7D542CD18ECC5210099D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
    23:45:52.0565 4888 AMD External Events Utility - ok
    23:45:52.0565 4888 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
    23:45:52.0581 4888 AmdK8 - ok
    23:45:52.0675 4888 [ A3C0A15B39F979E8F3EABA901D72ECD7 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
    23:45:52.0784 4888 amdkmdag - ok
    23:45:52.0800 4888 [ 20F3CD38B107C1BD747C0EA37D450165 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
    23:45:52.0831 4888 amdkmdap - ok
    23:45:52.0831 4888 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
    23:45:52.0846 4888 AmdPPM - ok
    23:45:52.0846 4888 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    23:45:52.0846 4888 amdsata - ok
    23:45:52.0846 4888 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
    23:45:52.0862 4888 amdsbs - ok
    23:45:52.0862 4888 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
    23:45:52.0878 4888 amdxata - ok
    23:45:52.0878 4888 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
    23:45:52.0878 4888 AppID - ok
    23:45:52.0893 4888 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
    23:45:52.0893 4888 AppIDSvc - ok
    23:45:52.0893 4888 [ D64C4AFEE8277F35EF729A2B924666B0 ] Appinfo C:\Windows\System32\appinfo.dll
    23:45:52.0909 4888 Appinfo - ok
    23:45:52.0909 4888 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
    23:45:52.0925 4888 arc - ok
    23:45:52.0925 4888 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
    23:45:52.0925 4888 arcsas - ok
    23:45:52.0925 4888 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    23:45:52.0940 4888 AsyncMac - ok
    23:45:52.0940 4888 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
    23:45:52.0956 4888 atapi - ok
    23:45:52.0956 4888 [ 87DAD8D354E312DB16636DC71EB39E5E ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW86.sys
    23:45:52.0956 4888 AtiHDAudioService - ok
    23:45:52.0971 4888 [ 810ED88782952228AF9C0985FB7D259E ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
    23:45:52.0971 4888 AudioEndpointBuilder - ok
    23:45:52.0987 4888 [ 25CA8B87479A374919563B3EE7136F32 ] Audiosrv C:\Windows\System32\Audiosrv.dll
    23:45:52.0987 4888 Audiosrv - ok
    23:45:53.0003 4888 [ 58D7FAF5C81ECEFFD2EDEDA9C2619D82 ] Avgboota C:\Windows\system32\DRIVERS\avgboota.sys
    23:45:53.0003 4888 Avgboota - ok
    23:45:53.0050 4888 [ 4AFC14AFA58878FAA1D249E7E90EA54B ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    23:45:53.0112 4888 AVGIDSAgent - ok
    23:45:53.0112 4888 [ 388056EBD5FE6718FE669078DBE37897 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdrivera.sys
    23:45:53.0128 4888 AVGIDSDriver - ok
    23:45:53.0143 4888 [ 550E981747D6A6C55078C77346FFC2C6 ] AVGIDSHA C:\Windows\system32\DRIVERS\avgidsha.sys
    23:45:53.0143 4888 AVGIDSHA - ok
    23:45:53.0143 4888 [ 5989592A91A17587799792A81E1541D4 ] Avgldx64 C:\Windows\system32\DRIVERS\avgldx64.sys
    23:45:53.0159 4888 Avgldx64 - ok
    23:45:53.0159 4888 [ 3FC43AA02545FCDDC22817829114DEC8 ] Avgloga C:\Windows\system32\DRIVERS\avgloga.sys
    23:45:53.0159 4888 Avgloga - ok
    23:45:53.0175 4888 [ 841C40C193889730848849AC220D9242 ] Avgmfx64 C:\Windows\system32\DRIVERS\avgmfx64.sys
    23:45:53.0175 4888 Avgmfx64 - ok
    23:45:53.0175 4888 [ FE4F444DBE4BBBDFD8FECF49398DEFC7 ] Avgrkx64 C:\Windows\system32\DRIVERS\avgrkx64.sys
    23:45:53.0175 4888 Avgrkx64 - ok
    23:45:53.0190 4888 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] avgwd C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    23:45:53.0190 4888 avgwd - ok
    23:45:53.0190 4888 [ 64A0A811F096834E8B85AB5009609D10 ] Avgwfpa C:\Windows\system32\DRIVERS\avgwfpa.sys
    23:45:53.0206 4888 Avgwfpa - ok
    23:45:53.0206 4888 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
    23:45:53.0206 4888 AxInstSV - ok
    23:45:53.0222 4888 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
    23:45:53.0237 4888 b06bdrv - ok
    23:45:53.0237 4888 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
    23:45:53.0237 4888 BasicDisplay - ok
    23:45:53.0253 4888 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
    23:45:53.0253 4888 BasicRender - ok
    23:45:53.0253 4888 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
    23:45:53.0268 4888 BDESVC - ok
    23:45:53.0268 4888 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
    23:45:53.0284 4888 Beep - ok
    23:45:53.0284 4888 [ 9E6A544F465C582AB42444A217CF04DC ] BFE C:\Windows\System32\bfe.dll
    23:45:53.0300 4888 BFE - ok
    23:45:53.0315 4888 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
    23:45:53.0347 4888 BITS - ok
    23:45:53.0347 4888 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    23:45:53.0347 4888 bowser - ok
    23:45:53.0362 4888 [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
    23:45:53.0362 4888 BrokerInfrastructure - ok
    23:45:53.0362 4888 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
    23:45:53.0378 4888 Browser - ok
    23:45:53.0378 4888 [ 3AA4309EBD9491E516F13FE3DC752FEE ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
    23:45:53.0393 4888 BthAvrcpTg - ok
    23:45:53.0393 4888 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
    23:45:53.0409 4888 BthHFEnum - ok
    23:45:53.0425 4888 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
    23:45:53.0425 4888 bthhfhid - ok
    23:45:53.0425 4888 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
    23:45:53.0440 4888 BTHMODEM - ok
    23:45:53.0440 4888 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
    23:45:53.0456 4888 bthserv - ok
    23:45:53.0456 4888 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    23:45:53.0456 4888 cdfs - ok
    23:45:53.0472 4888 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
    23:45:53.0472 4888 cdrom - ok
    23:45:53.0487 4888 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
    23:45:53.0487 4888 CertPropSvc - ok
    23:45:53.0487 4888 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
    23:45:53.0503 4888 circlass - ok
    23:45:53.0518 4888 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
    23:45:53.0518 4888 CLFS - ok
    23:45:53.0534 4888 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
    23:45:53.0534 4888 CmBatt - ok
    23:45:53.0550 4888 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
    23:45:53.0550 4888 CNG - ok
    23:45:53.0565 4888 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
    23:45:53.0565 4888 CompositeBus - ok
    23:45:53.0581 4888 COMSysApp - ok
    23:45:53.0581 4888 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
    23:45:53.0581 4888 condrv - ok
    23:45:53.0597 4888 [ F0E78B119D12BA81F163D48C0FF30B9A ] CryptSvc C:\Windows\system32\cryptsvc.dll
    23:45:53.0597 4888 CryptSvc - ok
    23:45:53.0597 4888 [ C4D01BD86D6B207275FC143EEA951D75 ] dam C:\Windows\system32\drivers\dam.sys
    23:45:53.0612 4888 dam - ok
    23:45:53.0612 4888 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
    23:45:53.0628 4888 DcomLaunch - ok
    23:45:53.0628 4888 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll
    23:45:53.0643 4888 defragsvc - ok
    23:45:53.0659 4888 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
    23:45:53.0659 4888 DeviceAssociationService - ok
    23:45:53.0675 4888 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
    23:45:53.0675 4888 DeviceInstall - ok
    23:45:53.0675 4888 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
    23:45:53.0690 4888 Dfsc - ok
    23:45:53.0690 4888 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
    23:45:53.0706 4888 Dhcp - ok
    23:45:53.0706 4888 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
    23:45:53.0706 4888 discache - ok
    23:45:53.0722 4888 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys
    23:45:53.0722 4888 disk - ok
    23:45:53.0722 4888 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
    23:45:53.0737 4888 dmvsc - ok
    23:45:53.0737 4888 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    23:45:53.0753 4888 Dnscache - ok
    23:45:53.0753 4888 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
    23:45:53.0768 4888 dot3svc - ok
    23:45:53.0768 4888 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
    23:45:53.0784 4888 DPS - ok
    23:45:53.0784 4888 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    23:45:53.0784 4888 drmkaud - ok
    23:45:53.0784 4888 [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
    23:45:53.0800 4888 DsmSvc - ok
    23:45:53.0815 4888 [ 898BF1647BBF012B38EF45C7F9F7A67E ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    23:45:53.0847 4888 DXGKrnl - ok
    23:45:53.0847 4888 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
    23:45:53.0862 4888 Eaphost - ok
    23:45:53.0893 4888 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
    23:45:53.0940 4888 ebdrv - ok
    23:45:53.0940 4888 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
    23:45:53.0956 4888 EFS - ok
    23:45:53.0956 4888 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
    23:45:53.0956 4888 EhStorClass - ok
    23:45:53.0972 4888 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
    23:45:53.0972 4888 EhStorTcgDrv - ok
    23:45:53.0972 4888 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
    23:45:53.0987 4888 ErrDev - ok
    23:45:53.0987 4888 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
    23:45:54.0003 4888 EventSystem - ok
    23:45:54.0003 4888 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
    23:45:54.0018 4888 exfat - ok
    23:45:54.0018 4888 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
    23:45:54.0034 4888 fastfat - ok
    23:45:54.0034 4888 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
    23:45:54.0050 4888 Fax - ok
    23:45:54.0050 4888 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
    23:45:54.0065 4888 fdc - ok
    23:45:54.0065 4888 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
    23:45:54.0081 4888 fdPHost - ok
    23:45:54.0081 4888 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
    23:45:54.0081 4888 FDResPub - ok
    23:45:54.0097 4888 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
    23:45:54.0097 4888 fhsvc - ok
    23:45:54.0097 4888 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    23:45:54.0112 4888 FileInfo - ok
    23:45:54.0112 4888 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    23:45:54.0112 4888 Filetrace - ok
    23:45:54.0128 4888 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
    23:45:54.0128 4888 flpydisk - ok
    23:45:54.0128 4888 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    23:45:54.0143 4888 FltMgr - ok
    23:45:54.0159 4888 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
    23:45:54.0175 4888 FontCache - ok
    23:45:54.0175 4888 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    23:45:54.0190 4888 FontCache3.0.0.0 - ok
    23:45:54.0190 4888 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    23:45:54.0190 4888 FsDepends - ok
    23:45:54.0190 4888 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    23:45:54.0206 4888 Fs_Rec - ok
    23:45:54.0206 4888 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    23:45:54.0222 4888 fvevol - ok
    23:45:54.0222 4888 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
    23:45:54.0237 4888 FxPPM - ok
    23:45:54.0237 4888 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
    23:45:54.0237 4888 gagp30kx - ok
    23:45:54.0237 4888 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
    23:45:54.0253 4888 gencounter - ok
    23:45:54.0253 4888 [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
    23:45:54.0268 4888 GPIOClx0101 - ok
    23:45:54.0284 4888 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
    23:45:54.0300 4888 gpsvc - ok
    23:45:54.0300 4888 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    23:45:54.0300 4888 gupdate - ok
    23:45:54.0300 4888 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    23:45:54.0315 4888 gupdatem - ok
    23:45:54.0315 4888 [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    23:45:54.0331 4888 HdAudAddService - ok
    23:45:54.0331 4888 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
    23:45:54.0347 4888 HDAudBus - ok
    23:45:54.0347 4888 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
    23:45:54.0362 4888 HidBatt - ok
    23:45:54.0362 4888 [ A25BAE8C1F2830C8E5625EC7E4E968BE ] HidBth C:\Windows\System32\drivers\hidbth.sys
    23:45:54.0378 4888 HidBth - ok
    23:45:54.0378 4888 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
    23:45:54.0378 4888 hidi2c - ok
    23:45:54.0378 4888 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
    23:45:54.0393 4888 HidIr - ok
    23:45:54.0409 4888 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll
    23:45:54.0409 4888 hidserv - ok
    23:45:54.0409 4888 [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
    23:45:54.0425 4888 HidUsb - ok
    23:45:54.0425 4888 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
    23:45:54.0440 4888 hkmsvc - ok
    23:45:54.0440 4888 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    23:45:54.0456 4888 HomeGroupListener - ok
    23:45:54.0456 4888 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    23:45:54.0472 4888 HomeGroupProvider - ok
    23:45:54.0472 4888 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
    23:45:54.0487 4888 HpSAMD - ok
    23:45:54.0487 4888 [ 29CB98187BB5711F7759540976D295FC ] HTTP C:\Windows\system32\drivers\HTTP.sys
    23:45:54.0503 4888 HTTP - ok
    23:45:54.0503 4888 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    23:45:54.0518 4888 hwpolicy - ok
    23:45:54.0518 4888 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
    23:45:54.0518 4888 hyperkbd - ok
    23:45:54.0534 4888 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
    23:45:54.0534 4888 HyperVideo - ok
    23:45:54.0534 4888 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
    23:45:54.0550 4888 i8042prt - ok
    23:45:54.0550 4888 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    23:45:54.0565 4888 iaStorV - ok
    23:45:54.0565 4888 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
    23:45:54.0565 4888 iirsp - ok
    23:45:54.0581 4888 [ 531B5A98145DA689741A0AC18F14EA94 ] IKEEXT C:\Windows\System32\ikeext.dll
    23:45:54.0597 4888 IKEEXT - ok
    23:45:54.0612 4888 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
    23:45:54.0612 4888 intelide - ok
    23:45:54.0612 4888 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
    23:45:54.0628 4888 intelppm - ok
    23:45:54.0628 4888 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    23:45:54.0628 4888 IpFilterDriver - ok
    23:45:54.0643 4888 [ CAC5202757EF68C4849B0DFFA75F6D3C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    23:45:54.0659 4888 iphlpsvc - ok
    23:45:54.0659 4888 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
    23:45:54.0675 4888 IPMIDRV - ok
    23:45:54.0675 4888 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    23:45:54.0675 4888 IPNAT - ok
    23:45:54.0690 4888 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
    23:45:54.0690 4888 IRENUM - ok
    23:45:54.0690 4888 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
    23:45:54.0706 4888 isapnp - ok
    23:45:54.0706 4888 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
    23:45:54.0722 4888 iScsiPrt - ok
    23:45:54.0722 4888 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
    23:45:54.0722 4888 kbdclass - ok
    23:45:54.0722 4888 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
    23:45:54.0737 4888 kbdhid - ok
    23:45:54.0737 4888 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
    23:45:54.0737 4888 kdnic - ok
    23:45:54.0753 4888 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
    23:45:54.0753 4888 KeyIso - ok
    23:45:54.0753 4888 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    23:45:54.0768 4888 KSecDD - ok
    23:45:54.0768 4888 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    23:45:54.0768 4888 KSecPkg - ok
    23:45:54.0784 4888 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    23:45:54.0784 4888 ksthunk - ok
    23:45:54.0784 4888 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
    23:45:54.0800 4888 KtmRm - ok
    23:45:54.0800 4888 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll
    23:45:54.0815 4888 LanmanServer - ok
    23:45:54.0815 4888 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    23:45:54.0831 4888 LanmanWorkstation - ok
    23:45:54.0831 4888 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    23:45:54.0847 4888 lltdio - ok
    23:45:54.0847 4888 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
    23:45:54.0862 4888 lltdsvc - ok
    23:45:54.0862 4888 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
    23:45:54.0862 4888 lmhosts - ok
    23:45:54.0878 4888 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
    23:45:54.0878 4888 LSI_SAS - ok
    23:45:54.0878 4888 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
    23:45:54.0893 4888 LSI_SAS2 - ok
    23:45:54.0893 4888 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
    23:45:54.0893 4888 LSI_SCSI - ok
    23:45:54.0909 4888 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
    23:45:54.0909 4888 LSI_SSS - ok
    23:45:54.0909 4888 [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] LSM C:\Windows\System32\lsm.dll
    23:45:54.0925 4888 LSM - ok
    23:45:54.0925 4888 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
    23:45:54.0940 4888 luafv - ok
    23:45:54.0940 4888 [ 92EB844D90615CB266F84C3202B8786E ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
    23:45:54.0940 4888 MBAMProtector - ok
    23:45:54.0987 4888 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    23:45:54.0987 4888 MBAMScheduler - ok
    23:45:55.0034 4888 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    23:45:55.0034 4888 MBAMService - ok
    23:45:55.0050 4888 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
    23:45:55.0050 4888 megasas - ok
    23:45:55.0050 4888 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
    23:45:55.0065 4888 MegaSR - ok
    23:45:55.0065 4888 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys
    23:45:55.0081 4888 MEIx64 - ok
    23:45:55.0081 4888 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
    23:45:55.0081 4888 MMCSS - ok
    23:45:55.0081 4888 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
    23:45:55.0097 4888 Modem - ok
    23:45:55.0097 4888 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    23:45:55.0112 4888 monitor - ok
    23:45:55.0112 4888 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
    23:45:55.0112 4888 mouclass - ok
    23:45:55.0112 4888 [ CB2527B8B87D83E56FBF3944BBB6F606 ] mouhid C:\Windows\System32\drivers\mouhid.sys
    23:45:55.0128 4888 mouhid - ok
    23:45:55.0128 4888 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
    23:45:55.0143 4888 mountmgr - ok
    23:45:55.0143 4888 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    23:45:55.0159 4888 mpsdrv - ok
    23:45:55.0159 4888 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
    23:45:55.0175 4888 MpsSvc - ok
    23:45:55.0175 4888 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    23:45:55.0190 4888 MRxDAV - ok
    23:45:55.0190 4888 [ 877D60D6E4156EC4A2E0B6871D41BED9 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    23:45:55.0206 4888 mrxsmb - ok
    23:45:55.0206 4888 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    23:45:55.0222 4888 mrxsmb10 - ok
    23:45:55.0222 4888 [ E078446D4B8622AA6030C7B8A1A08962 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    23:45:55.0237 4888 mrxsmb20 - ok
    23:45:55.0237 4888 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
    23:45:55.0253 4888 MsBridge - ok
    23:45:55.0253 4888 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
    23:45:55.0268 4888 MSDTC - ok
    23:45:55.0268 4888 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
    23:45:55.0284 4888 Msfs - ok
    23:45:55.0284 4888 [ C9BFB0353099B071E70299549C18C8AE ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
    23:45:55.0284 4888 msgpiowin32 - ok
    23:45:55.0284 4888 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
    23:45:55.0300 4888 mshidkmdf - ok
    23:45:55.0300 4888 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
    23:45:55.0300 4888 mshidumdf - ok
    23:45:55.0300 4888 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    23:45:55.0315 4888 msisadrv - ok
    23:45:55.0315 4888 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    23:45:55.0331 4888 MSiSCSI - ok
    23:45:55.0331 4888 msiserver - ok
    23:45:55.0331 4888 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    23:45:55.0331 4888 MSKSSRV - ok
    23:45:55.0347 4888 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
    23:45:55.0347 4888 MsLldp - ok
    23:45:55.0347 4888 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    23:45:55.0362 4888 MSPCLOCK - ok
    23:45:55.0362 4888 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    23:45:55.0362 4888 MSPQM - ok
    23:45:55.0378 4888 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    23:45:55.0378 4888 MsRPC - ok
    23:45:55.0393 4888 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
    23:45:55.0393 4888 mssmbios - ok
    23:45:55.0393 4888 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    23:45:55.0393 4888 MSTEE - ok
    23:45:55.0409 4888 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
    23:45:55.0409 4888 MTConfig - ok
    23:45:55.0409 4888 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
    23:45:55.0425 4888 Mup - ok
    23:45:55.0425 4888 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
    23:45:55.0440 4888 mvumis - ok
    23:45:55.0440 4888 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
    23:45:55.0456 4888 napagent - ok
    23:45:55.0472 4888 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    23:45:55.0472 4888 NativeWifiP - ok
    23:45:55.0487 4888 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
    23:45:55.0503 4888 NcaSvc - ok
    23:45:55.0503 4888 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
    23:45:55.0503 4888 NcdAutoSetup - ok
    23:45:55.0519 4888 [ 0F89AE618DBA5D8AB7A2DFCC375F4159 ] NDIS C:\Windows\system32\drivers\ndis.sys
    23:45:55.0534 4888 NDIS - ok
    23:45:55.0550 4888 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
    23:45:55.0550 4888 NdisCap - ok
    23:45:55.0550 4888 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
    23:45:55.0565 4888 NdisImPlatform - ok
    23:45:55.0565 4888 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    23:45:55.0581 4888 NdisTapi - ok
    23:45:55.0581 4888 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    23:45:55.0597 4888 Ndisuio - ok
    23:45:55.0597 4888 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    23:45:55.0597 4888 NdisWan - ok
    23:45:55.0612 4888 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
    23:45:55.0612 4888 NDISWANLEGACY - ok
    23:45:55.0612 4888 [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    23:45:55.0628 4888 NDProxy - ok
    23:45:55.0628 4888 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
    23:45:55.0628 4888 Ndu - ok
    23:45:55.0644 4888 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    23:45:55.0644 4888 NetBIOS - ok
    23:45:55.0644 4888 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
    23:45:55.0659 4888 NetBT - ok
    23:45:55.0659 4888 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
    23:45:55.0675 4888 Netlogon - ok
    23:45:55.0675 4888 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
    23:45:55.0690 4888 Netman - ok
    23:45:55.0690 4888 [ 20F6FD63E6D456114BC8056D62792786 ] netprofm C:\Windows\System32\netprofmsvc.dll
    23:45:55.0706 4888 netprofm - ok
    23:45:55.0722 4888 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    23:45:55.0722 4888 NetTcpPortSharing - ok
    23:45:55.0722 4888 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
    23:45:55.0737 4888 nfrd960 - ok
    23:45:55.0737 4888 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
    23:45:55.0753 4888 NlaSvc - ok
    23:45:55.0753 4888 NPF - ok
    23:45:55.0753 4888 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    23:45:55.0769 4888 Npfs - ok
    23:45:55.0769 4888 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
    23:45:55.0769 4888 npsvctrig - ok
    23:45:55.0784 4888 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
    23:45:55.0784 4888 nsi - ok
    23:45:55.0784 4888 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    23:45:55.0800 4888 nsiproxy - ok
    23:45:55.0815 4888 [ 4A7EEA9C4AD5CBFDA3C0E5B821C99CAD ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    23:45:55.0847 4888 Ntfs - ok
    23:45:55.0862 4888 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
    23:45:55.0862 4888 Null - ok
    23:45:55.0862 4888 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
    23:45:55.0878 4888 nvraid - ok
    23:45:55.0878 4888 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
    23:45:55.0894 4888 nvstor - ok
    23:45:55.0894 4888 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    23:45:55.0894 4888 nv_agp - ok
    23:45:55.0909 4888 [ B9C125314A025127FE562C116D614AA3 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    23:45:55.0909 4888 ose64 - ok
    23:45:55.0925 4888 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
    23:45:55.0925 4888 p2pimsvc - ok
    23:45:55.0940 4888 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
    23:45:55.0940 4888 p2psvc - ok
    23:45:55.0956 4888 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
    23:45:55.0956 4888 Parport - ok
    23:45:55.0956 4888 [ C1D7BA7F0DE487DFEEB51BF8D3EC5562 ] partmgr C:\Windows\system32\drivers\partmgr.sys
    23:45:55.0972 4888 partmgr - ok
    23:45:55.0972 4888 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
    23:45:55.0987 4888 PcaSvc - ok
    23:45:55.0987 4888 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
    23:45:56.0003 4888 pci - ok
    23:45:56.0003 4888 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
    23:45:56.0019 4888 pciide - ok
    23:45:56.0019 4888 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
    23:45:56.0034 4888 pcmcia - ok
    23:45:56.0034 4888 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
    23:45:56.0050 4888 pcw - ok
    23:45:56.0050 4888 [ EF9B4F3136B4C45F421ADE6871659FB6 ] pdc C:\Windows\system32\drivers\pdc.sys
    23:45:56.0050 4888 pdc - ok
    23:45:56.0065 4888 [ 70DBB6A8B52B3830922F1C5789E1BEEB ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    23:45:56.0081 4888 PEAUTH - ok
    23:45:56.0112 4888 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
    23:45:56.0128 4888 PerfHost - ok
    23:45:56.0144 4888 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
    23:45:56.0175 4888 pla - ok
    23:45:56.0175 4888 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    23:45:56.0190 4888 PlugPlay - ok
    23:45:56.0190 4888 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
    23:45:56.0206 4888 PNRPAutoReg - ok
    23:45:56.0206 4888 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
    23:45:56.0222 4888 PNRPsvc - ok
    23:45:56.0222 4888 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    23:45:56.0237 4888 PolicyAgent - ok
    23:45:56.0237 4888 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
    23:45:56.0253 4888 Power - ok
    23:45:56.0253 4888 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    23:45:56.0269 4888 PptpMiniport - ok
    23:45:56.0284 4888 [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
    23:45:56.0315 4888 PrintNotify - ok
    23:45:56.0331 4888 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
    23:45:56.0331 4888 Processor - ok
    23:45:56.0331 4888 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
    23:45:56.0347 4888 ProfSvc - ok
    23:45:56.0347 4888 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
    23:45:56.0362 4888 Psched - ok
    23:45:56.0362 4888 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
    23:45:56.0378 4888 QWAVE - ok
    23:45:56.0378 4888 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    23:45:56.0378 4888 QWAVEdrv - ok
    23:45:56.0394 4888 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    23:45:56.0394 4888 RasAcd - ok
    23:45:56.0394 4888 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
    23:45:56.0409 4888 RasAgileVpn - ok
    23:45:56.0409 4888 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
    23:45:56.0425 4888 RasAuto - ok
    23:45:56.0425 4888 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    23:45:56.0440 4888 Rasl2tp - ok
    23:45:56.0440 4888 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
    23:45:56.0456 4888 RasMan - ok
    23:45:56.0456 4888 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    23:45:56.0456 4888 RasPppoe - ok
    23:45:56.0472 4888 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    23:45:56.0472 4888 RasSstp - ok
    23:45:56.0487 4888 [ B72C33DBD5326B3864CF2091AF8B906B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    23:45:56.0487 4888 rdbss - ok
    23:45:56.0503 4888 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
    23:45:56.0503 4888 rdpbus - ok
    23:45:56.0503 4888 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
    23:45:56.0519 4888 RDPDR - ok
    23:45:56.0519 4888 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
    23:45:56.0534 4888 RdpVideoMiniport - ok
    23:45:56.0534 4888 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    23:45:56.0534 4888 RDPWD - ok
    23:45:56.0550 4888 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
    23:45:56.0550 4888 rdyboost - ok
    23:45:56.0550 4888 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
    23:45:56.0565 4888 RemoteAccess - ok
    23:45:56.0565 4888 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
    23:45:56.0581 4888 RemoteRegistry - ok
    23:45:56.0675 4888 [ 599091EDC1013A4A79CFE171638CF262 ] rpcapd C:\Program Files (x86)\WinPcap\rpcapd.exe
    23:45:56.0690 4888 rpcapd ( UnsignedFile.Multi.Generic ) - warning
    23:45:56.0690 4888 rpcapd - detected UnsignedFile.Multi.Generic (1)
    23:45:56.0690 4888 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
    23:45:56.0690 4888 RpcEptMapper - ok
    23:45:56.0706 4888 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
    23:45:56.0706 4888 RpcLocator - ok
    23:45:56.0769 4888 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
    23:45:56.0784 4888 RpcSs - ok
    23:45:56.0784 4888 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    23:45:56.0800 4888 rspndr - ok
    23:45:56.0800 4888 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
    23:45:56.0815 4888 RTL8168 - ok
    23:45:56.0831 4888 [ AE03548B97CC32199B69E20D29951BD6 ] RTL8192su C:\Windows\system32\DRIVERS\RTL8192su.sys
    23:45:56.0847 4888 RTL8192su - ok
    23:45:56.0847 4888 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
    23:45:56.0862 4888 s3cap - ok
    23:45:56.0862 4888 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
    23:45:56.0862 4888 SamSs - ok
    23:45:56.0878 4888 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
    23:45:56.0878 4888 SASDIFSV - ok
    23:45:56.0878 4888 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
    23:45:56.0894 4888 SASKUTIL - ok
    23:45:56.0894 4888 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    23:45:56.0894 4888 sbp2port - ok
    23:45:56.0909 4888 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
    23:45:56.0925 4888 SCardSvr - ok
    23:45:56.0925 4888 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
    23:45:56.0925 4888 scfilter - ok
    23:45:56.0987 4888 [ EDCDF4DB82EF825B94B190D544C8C58B ] Schedule C:\Windows\system32\schedsvc.dll
    23:45:57.0003 4888 Schedule - ok
    23:45:57.0003 4888 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
    23:45:57.0003 4888 SCPolicySvc - ok
    23:45:57.0019 4888 [ 66E29CADF9FF6C8325C356BDD617F7EA ] sdbus C:\Windows\System32\drivers\sdbus.sys
    23:45:57.0019 4888 sdbus - ok
    23:45:57.0034 4888 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
    23:45:57.0050 4888 SDRSVC - ok
    23:45:57.0065 4888 [ 206387AB881E93A1A6EB89966C8651F1 ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    23:45:57.0081 4888 SDScannerService - ok
    23:45:57.0081 4888 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
    23:45:57.0097 4888 sdstor - ok
    23:45:57.0112 4888 [ A529CFE32565C0B145578FFB2B32C9A5 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    23:45:57.0128 4888 SDUpdateService - ok
    23:45:57.0128 4888 [ CB63BDB77BB86549FC3303C2F11EDC18 ] SDWSCService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    23:45:57.0128 4888 SDWSCService - ok
    23:45:57.0144 4888 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    23:45:57.0144 4888 secdrv - ok
    23:45:57.0144 4888 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
    23:45:57.0159 4888 seclogon - ok
    23:45:57.0159 4888 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
    23:45:57.0175 4888 SENS - ok
    23:45:57.0175 4888 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
    23:45:57.0175 4888 SensrSvc - ok
    23:45:57.0190 4888 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
    23:45:57.0190 4888 SerCx - ok
    23:45:57.0190 4888 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
    23:45:57.0206 4888 Serenum - ok
    23:45:57.0206 4888 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
    23:45:57.0206 4888 Serial - ok
    23:45:57.0222 4888 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
    23:45:57.0222 4888 sermouse - ok
    23:45:57.0222 4888 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
    23:45:57.0237 4888 SessionEnv - ok
    23:45:57.0237 4888 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
    23:45:57.0253 4888 sfloppy - ok
    23:45:57.0253 4888 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
    23:45:57.0269 4888 SharedAccess - ok
    23:45:57.0284 4888 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    23:45:57.0284 4888 ShellHWDetection - ok
    23:45:57.0300 4888 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
    23:45:57.0300 4888 SiSRaid2 - ok
    23:45:57.0300 4888 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
    23:45:57.0315 4888 SiSRaid4 - ok
    23:45:57.0315 4888 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    23:45:57.0315 4888 SkypeUpdate - ok
    23:45:57.0331 4888 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    23:45:57.0331 4888 SNMPTRAP - ok
    23:45:57.0347 4888 [ 465F3C355CE5ED2779B8F460F14C5A78 ] spaceport C:\Windows\system32\drivers\spaceport.sys
    23:45:57.0347 4888 spaceport - ok
    23:45:57.0347 4888 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
    23:45:57.0362 4888 SpbCx - ok
    23:45:57.0362 4888 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
    23:45:57.0378 4888 Spooler - ok
    23:45:57.0425 4888 [ EC84D961501054F87A6878EC5D53388F ] sppsvc C:\Windows\system32\sppsvc.exe
    23:45:57.0487 4888 sppsvc - ok
    23:45:57.0487 4888 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys
    23:45:57.0503 4888 srv - ok
    23:45:57.0519 4888 [ C2106BB710AA34A046126AED7BCA6964 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    23:45:57.0534 4888 srv2 - ok
    23:45:57.0534 4888 [ 9400C71F5A1A380B494B6922F007D485 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    23:45:57.0550 4888 srvnet - ok
    23:45:57.0550 4888 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    23:45:57.0565 4888 SSDPSRV - ok
    23:45:57.0565 4888 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll
    23:45:57.0565 4888 SstpSvc - ok
    23:45:57.0565 4888 Steam Client Service - ok
    23:45:57.0581 4888 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys
  6. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    23:45:57.0581 4888 stexstor - ok
    23:45:57.0597 4888 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll
    23:45:57.0597 4888 stisvc - ok
    23:45:57.0597 4888 [ C588BBD37B432CE3204E5765B459E6B2 ] storahci C:\Windows\system32\drivers\storahci.sys
    23:45:57.0612 4888 storahci - ok
    23:45:57.0612 4888 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
    23:45:57.0612 4888 storflt - ok
    23:45:57.0628 4888 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll
    23:45:57.0628 4888 StorSvc - ok
    23:45:57.0628 4888 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys
    23:45:57.0644 4888 storvsc - ok
    23:45:57.0644 4888 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll
    23:45:57.0659 4888 svsvc - ok
    23:45:57.0659 4888 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys
    23:45:57.0659 4888 swenum - ok
    23:45:57.0675 4888 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll
    23:45:57.0690 4888 swprv - ok
    23:45:57.0706 4888 [ DC21E1F06343773D7E24362DCEF7944B ] SysMain C:\Windows\system32\sysmain.dll
    23:45:57.0722 4888 SysMain - ok
    23:45:57.0722 4888 [ E219BF7BCCFE4881B0C053C7E0B47ECC ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
    23:45:57.0722 4888 SystemEventsBroker - ok
    23:45:57.0737 4888 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
    23:45:57.0737 4888 TabletInputService - ok
    23:45:57.0737 4888 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll
    23:45:57.0753 4888 TapiSrv - ok
    23:45:57.0769 4888 [ 1D644E2D0FC395A055AB1C23C3B43631 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    23:45:57.0815 4888 Tcpip - ok
    23:45:57.0894 4888 [ 1D644E2D0FC395A055AB1C23C3B43631 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
    23:45:57.0925 4888 TCPIP6 - ok
    23:45:57.0925 4888 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    23:45:57.0940 4888 tcpipreg - ok
    23:45:57.0940 4888 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    23:45:57.0956 4888 tdx - ok
    23:45:57.0956 4888 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys
    23:45:57.0956 4888 terminpt - ok
    23:45:57.0972 4888 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll
    23:45:57.0987 4888 TermService - ok
    23:45:57.0987 4888 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll
    23:45:58.0003 4888 Themes - ok
    23:45:58.0003 4888 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll
    23:45:58.0003 4888 THREADORDER - ok
    23:45:58.0019 4888 [ FF4135424A79DCC2998276D8E39C9B4D ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
    23:45:58.0019 4888 TimeBroker - ok
    23:45:58.0034 4888 [ B44EFE254C0B3719E4037088D24FE4B5 ] TPM C:\Windows\system32\drivers\tpm.sys
    23:45:58.0034 4888 TPM - ok
    23:45:58.0034 4888 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll
    23:45:58.0050 4888 TrkWks - ok
    23:45:58.0050 4888 [ 8D516AEF3C1DF980664CF17BB1FF6093 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    23:45:58.0050 4888 TrustedInstaller - ok
    23:45:58.0066 4888 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
    23:45:58.0066 4888 TsUsbFlt - ok
    23:45:58.0066 4888 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
    23:45:58.0081 4888 TsUsbGD - ok
    23:45:58.0081 4888 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    23:45:58.0097 4888 tunnel - ok
    23:45:58.0097 4888 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys
    23:45:58.0097 4888 uagp35 - ok
    23:45:58.0112 4888 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
    23:45:58.0112 4888 UASPStor - ok
    23:45:58.0128 4888 [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
    23:45:58.0128 4888 UCX01000 - ok
    23:45:58.0144 4888 [ DC5A461591C71AF7F19DC048A81E3F88 ] udfs C:\Windows
  7. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    \system32\DRIVERS\udfs.sys
    23:45:58.0144 4888 udfs - ok
    23:45:58.0175 4888 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe
    23:45:58.0191 4888 UI0Detect - ok
    23:45:58.0191 4888 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    23:45:58.0206 4888 uliagpkx - ok
    23:45:58.0206 4888 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys
    23:45:58.0206 4888 umbus - ok
    23:45:58.0206 4888 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys
    23:45:58.0222 4888 UmPass - ok
    23:45:58.0222 4888 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll
    23:45:58.0237 4888 UmRdpService - ok
    23:45:58.0253 4888 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll
    23:45:58.0269 4888 upnphost - ok
    23:45:58.0269 4888 [ 3FBE0784E42E7BA93FCC5201D2BAFE23 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
    23:45:58.0284 4888 usbaudio - ok
    23:45:58.0284 4888 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
    23:45:58.0300 4888 usbccgp - ok
    23:45:58.0300 4888 [ B395B62B62F28106218FA6FB17F4C797 ] usbcir C:\Windows\System32\drivers\usbcir.sys
    23:45:58.0316 4888 usbcir - ok
    23:45:58.0316 4888 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci C:\Windows\System32\drivers\usbehci.sys
    23:45:58.0331 4888 usbehci - ok
    23:45:58.0331 4888 [ FBB6794E3BBAD92D66D59D206C1F849F ] usbhub C:\Windows\System32\drivers\usbhub.sys
    23:45:58.0347 4888 usbhub - ok
    23:45:58.0362 4888 [ B7A948501424805571BF562BB0BFE31D ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
    23:45:58.0362 4888 USBHUB3 - ok
    23:45:58.0378 4888 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys
    23:45:58.0378 4888 usbohci - ok
    23:45:58.0378 4888 [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint C:\Windows\System32\drivers\usbprint.sys
    23:45:58.0394 4888 usbprint - ok
    23:45:58.0394 4888 [ F77177F6C95B2116EE7AD23B5EF57007 ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
    23:45:58.0394 4888 USBSTOR - ok
    23:45:58.0409 4888 [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
    23:45:58.0409 4888 usbuhci - ok
    23:45:58.0409 4888 [ 9CD4259AD15F84DE27B94A956C978D6C ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
    23:45:58.0425 4888 USBXHCI - ok
    23:45:58.0425 4888 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe
    23:45:58.0441 4888 VaultSvc - ok
    23:45:58.0441 4888 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
    23:45:58.0441 4888 vdrvroot - ok
    23:45:58.0456 4888 [ 8A8CDA9E3CF2E0B4C6CC19FBC6FB9A71 ] vds C:\Windows\System32\vds.exe
    23:45:58.0472 4888 vds - ok
    23:45:58.0472 4888 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
    23:45:58.0472 4888 VerifierExt - ok
    23:45:58.0487 4888 [ 8628FA679F0EC4B709CCD1F6B6A3233B ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
    23:45:58.0503 4888 vhdmp - ok
    23:45:58.0503 4888 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys
    23:45:58.0503 4888 viaide - ok
    23:45:58.0519 4888 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys
    23:45:58.0519 4888 vmbus - ok
    23:45:58.0519 4888 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
    23:45:58.0534 4888 VMBusHID - ok
    23:45:58.0534 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
    23:45:58.0550 4888 vmicheartbeat - ok
    23:45:58.0550 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
    23:45:58.0566 4888 vmickvpexchange - ok
    23:45:58.0566 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll
    23:45:58.0581 4888 vmicrdv - ok
    23:45:58.0581 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll
    23:45:58.0581 4888 vmicshutdown - ok
    23:45:58.0597 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll
    23:45:58.0597 4888 vmictimesync - ok
    23:45:58.0612 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll
    23:45:58.0612 4888 vmicvss - ok
    23:45:58.0612 4888 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys
    23:45:58.0628 4888 volmgr - ok
    23:45:58.0628 4888 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    23:45:58.0644 4888 volmgrx - ok
    23:45:58.0644 4888 [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE ] volsnap C:\Windows\system32\drivers\volsnap.sys
    23:45:58.0659 4888 volsnap - ok
    23:45:58.0659 4888 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys
    23:45:58.0675 4888 vpci - ok
    23:45:58.0675 4888 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
    23:45:58.0675 4888 vsmraid - ok
    23:45:58.0691 4888 [ EA658570314042C914964FC72AB50E6B ] VSS C:\Windows\system32\vssvc.exe
    23:45:58.0722 4888 VSS - ok
    23:45:58.0722 4888 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
    23:45:58.0737 4888 VSTXRAID - ok
    23:45:58.0753 4888 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
    23:45:58.0753 4888 vwifibus - ok
    23:45:58.0753 4888 [ 095E943D27025E4D588AF0A72CC2318F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
    23:45:58.0769 4888 vwififlt - ok
    23:45:58.0769 4888 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll
    23:45:58.0784 4888 W32Time - ok
    23:45:58.0784 4888 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
    23:45:58.0800 4888 WacomPen - ok
    23:45:58.0800 4888 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
    23:45:58.0800 4888 Wanarp - ok
    23:45:58.0800 4888 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    23:45:58.0816 4888 Wanarpv6 - ok
    23:45:58.0831 4888 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe
    23:45:58.0862 4888 wbengine - ok
    23:45:58.0862 4888 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
    23:45:58.0878 4888 WbioSrvc - ok
    23:45:58.0878 4888 [ D9C1E82651BF19C6FF69CEC6FD400124 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
    23:45:58.0894 4888 Wcmsvc - ok
    23:45:58.0894 4888 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll
    23:45:58.0909 4888 wcncsvc - ok
    23:45:58.0909 4888 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    23:45:58.0925 4888 WcsPlugInService - ok
    23:45:58.0925 4888 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys
    23:45:58.0925 4888 Wd - ok
    23:45:58.0941 4888 [ 260F8DFC4D5748F4CCB9B19CFB0E58EA ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
    23:45:58.0941 4888 WdBoot - ok
    23:45:58.0958 4888 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    23:45:58.0981 4888 Wdf01000 - ok
    23:45:58.0986 4888 [ 880FFFC4D5BBBB4187B6B04AB2E8C32A ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
    23:45:58.0996 4888 WdFilter - ok
    23:45:59.0000 4888 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll
    23:45:59.0011 4888 WdiServiceHost - ok
    23:45:59.0014 4888 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll
    23:45:59.0025 4888 WdiSystemHost - ok
    23:45:59.0030 4888 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll
    23:45:59.0035 4888 WebClient - ok
    23:45:59.0035 4888 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll
    23:45:59.0057 4888 Wecsvc - ok
    23:45:59.0060 4888 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll
    23:45:59.0074 4888 wercplsupport - ok
    23:45:59.0078 4888 [ 8E2426162ED6749A127B35D235F21E11 ] WerSvc C:\Windows\System32\WerSvc.dll
    23:45:59.0092 4888 WerSvc - ok
    23:45:59.0101 4888 [ FE762D3498719C3A23471BBA62F747B4 ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
    23:45:59.0108 4888 WFPLWFS - ok
    23:45:59.0112 4888 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll
    23:45:59.0120 4888 WiaRpc - ok
    23:45:59.0124 4888 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
    23:45:59.0131 4888 WIMMount - ok
    23:45:59.0133 4888 WinDefend - ok
    23:45:59.0144 4888 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
    23:45:59.0156 4888 WinHttpAutoProxySvc - ok
    23:45:59.0163 4888 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    23:45:59.0172 4888 Winmgmt - ok
    23:45:59.0341 4888 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll
    23:45:59.0379 4888 WinRM - ok
    23:45:59.0385 4888 [ BB20956C424531003F7FA6CD36F11D5D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
    23:45:59.0399 4888 WinUsb - ok
    23:45:59.0412 4888 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll
    23:45:59.0429 4888 WlanSvc - ok
    23:45:59.0588 4888 [ 08EFA13A2234C8C3B8A99E4B88BE7E9B ] wlidsvc C:\Windows\system32\wlidsvc.dll
    23:45:59.0607 4888 wlidsvc - ok
    23:45:59.0610 4888 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
    23:45:59.0616 4888 WmiAcpi - ok
    23:45:59.0621 4888 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    23:45:59.0631 4888 wmiApSrv - ok
    23:45:59.0632 4888 WMPNetworkSvc - ok
    23:45:59.0636 4888 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
    23:45:59.0644 4888 wpcfltr - ok
    23:45:59.0647 4888 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll
    23:45:59.0687 4888 WPCSvc - ok
    23:45:59.0818 4888 [ 94AA5150E35B3ABB7191FE641E3C2473 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    23:45:59.0829 4888 WPDBusEnum - ok
    23:45:59.0835 4888 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
    23:45:59.0841 4888 WpdUpFltr - ok
    23:45:59.0845 4888 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    23:45:59.0852 4888 ws2ifsl - ok
    23:45:59.0857 4888 [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] wscsvc C:\Windows\System32\wscsvc.dll
    23:45:59.0868 4888 wscsvc - ok
    23:45:59.0873 4888 WSearch - ok
    23:45:59.0903 4888 [ C10BFFEE7E0D7A1366E84F251796C51D ] WSService C:\Windows\System32\WSService.dll
    23:46:00.0155 4888 WSService - ok
    23:46:00.0190 4888 [ A8484C0CB54DB48180FB7CA00F1C3F8F ] wuauserv C:\Windows\system32\wuaueng.dll
    23:46:00.0235 4888 wuauserv - ok
    23:46:00.0241 4888 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
    23:46:00.0249 4888 WudfPf - ok
    23:46:00.0255 4888 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
    23:46:00.0267 4888 WUDFRd - ok
    23:46:00.0272 4888 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    23:46:00.0281 4888 wudfsvc - ok
    23:46:00.0287 4888 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
    23:46:00.0295 4888 WUDFWpdFs - ok
    23:46:00.0298 4888 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdMtp C:\Windows\system32\DRIVERS\WUDFRd.sys
    23:46:00.0305 4888 WUDFWpdMtp - ok
    23:46:00.0313 4888 [ F9D8D2E6ECE08B278621D5BF3A7240A6 ] WwanSvc C:\Windows\System32\wwansvc.dll
    23:46:00.0328 4888 WwanSvc - ok
    23:46:00.0334 4888 ================ Scan global ===============================
    23:46:00.0338 4888 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
    23:46:00.0343 4888 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
    23:46:00.0348 4888 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
    23:46:00.0354 4888 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
    23:46:00.0356 4888 [Global] - ok
    23:46:00.0357 4888 ================ Scan MBR ==================================
    23:46:00.0359 4888 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
    23:46:00.0452 4888 \Device\Harddisk0\DR0 - ok
    23:46:00.0467 4888 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
    23:46:00.0644 4888 \Device\Harddisk1\DR1 - ok
    23:46:00.0648 4888 [ DDAE9D649DB12F6AFF24483F2C298989 ] \Device\Harddisk2\DR2
    23:46:00.0796 4888 \Device\Harddisk2\DR2 - ok
    23:46:00.0796 4888 ================ Scan VBR ==================================
    23:46:00.0799 4888 [ 9B82BD1FBE697E6F0FE2F15F67AC54F4 ] \Device\Harddisk0\DR0\Partition1
    23:46:00.0800 4888 \Device\Harddisk0\DR0\Partition1 - ok
    23:46:00.0802 4888 [ 89CEC369F86E833A4B906697A32A20CD ] \Device\Harddisk1\DR1\Partition1
    23:46:00.0803 4888 \Device\Harddisk1\DR1\Partition1 - ok
    23:46:00.0835 4888 [ B06880233BB1F9143101554F63AEE209 ] \Device\Harddisk1\DR1\Partition2
    23:46:00.0836 4888 \Device\Harddisk1\DR1\Partition2 - ok
    23:46:00.0839 4888 [ EBB3321D986DA0D45E607B9DB38E3CB9 ] \Device\Harddisk2\DR2\Partition1
    23:46:00.0840 4888 \Device\Harddisk2\DR2\Partition1 - ok
    23:46:00.0840 4888 ================ Scan active images ========================
    23:46:00.0842 4888 [ A721FF570C2387E383BDDEA9632863C9 ] C:\Windows\System32\Drivers\atapi.sys
    23:46:00.0842 4888 C:\Windows\System32\Drivers\atapi.sys - ok
    23:46:00.0844 4888 [ 48753C871A12B9E2201E71D01B32F6EF ] C:\Windows\System32\Drivers\crashdmp.sys
    23:46:00.0844 4888 C:\Windows\System32\Drivers\crashdmp.sys - ok
    23:46:00.0845 4888 [ 15AFD3118600205B013550C8E81A0D92 ] C:\Windows\System32\Drivers\Dumpata.sys
    23:46:00.0845 4888 C:\Windows\System32\Drivers\Dumpata.sys - ok
    23:46:00.0847 4888 [ CB9EAD11F3312C77CE9B7F29B59C3A39 ] C:\Windows\System32\Drivers\dumpfve.sys
    23:46:00.0847 4888 C:\Windows\System32\Drivers\dumpfve.sys - ok
    23:46:00.0849 4888 [ 339BFF85D788268752DA8C9644B188EE ] C:\Windows\System32\Drivers\cdrom.sys
    23:46:00.0849 4888 C:\Windows\System32\Drivers\cdrom.sys - ok
    23:46:00.0851 4888 [ 5EC68164E14D25675C98BBB5F09E8606 ] C:\Windows\System32\Drivers\BasicRender.sys
    23:46:00.0851 4888 C:\Windows\System32\Drivers\BasicRender.sys - ok
    23:46:00.0853 4888 [ 9E7AEA59776D904607985AFFE7E5E183 ] C:\Windows\System32\Drivers\beep.sys
    23:46:00.0853 4888 C:\Windows\System32\Drivers\beep.sys - ok
    23:46:00.0855 4888 [ 4163ADE07DB51843AE31F65B94F5398D ] C:\Windows\System32\Drivers\null.sys
    23:46:00.0855 4888 C:\Windows\System32\Drivers\null.sys - ok
    23:46:00.0856 4888 [ 898BF1647BBF012B38EF45C7F9F7A67E ] C:\Windows\System32\Drivers\dxgkrnl.sys
    23:46:00.0856 4888 C:\Windows\System32\Drivers\dxgkrnl.sys - ok
    23:46:00.0859 4888 [ B9FF5E13079ADB858ED5C0B1E4CAB225 ] C:\Windows\System32\Drivers\watchdog.sys
    23:46:00.0859 4888 C:\Windows\System32\Drivers\watchdog.sys - ok
    23:46:00.0861 4888 [ 81703BC5D68DEDBB086C2368FBE7B334 ] C:\Windows\System32\Drivers\BasicDisplay.sys
    23:46:00.0861 4888 C:\Windows\System32\Drivers\BasicDisplay.sys - ok
    23:46:00.0863 4888 [ 728DFAEEF8E52E793DE8EB0423F4E948 ] C:\Windows\System32\Drivers\dxgmms1.sys
    23:46:00.0863 4888 C:\Windows\System32\Drivers\dxgmms1.sys - ok
    23:46:00.0865 4888 [ 17E19A742FB30C002F8B43575451DBE1 ] C:\Windows\System32\Drivers\npfs.sys
    23:46:00.0865 4888 C:\Windows\System32\Drivers\npfs.sys - ok
    23:46:00.0867 4888 [ 64A0A811F096834E8B85AB5009609D10 ] C:\Windows\System32\Drivers\avgwfpa.sys
    23:46:00.0868 4888 C:\Windows\System32\Drivers\avgwfpa.sys - ok
    23:46:00.0869 4888 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] C:\Windows\System32\Drivers\msfs.sys
    23:46:00.0869 4888 C:\Windows\System32\Drivers\msfs.sys - ok
    23:46:00.0871 4888 [ 749AFA28C01233E93F59BD31B2B088B1 ] C:\Windows\System32\Drivers\tdi.sys
    23:46:00.0871 4888 C:\Windows\System32\Drivers\tdi.sys - ok
    23:46:00.0873 4888 [ 73DC722CE5DF26D7638CE2446F2655C7 ] C:\Windows\System32\Drivers\tdx.sys
    23:46:00.0873 4888 C:\Windows\System32\Drivers\tdx.sys - ok
    23:46:00.0876 4888 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] C:\Windows\System32\Drivers\afd.sys
    23:46:00.0876 4888 C:\Windows\System32\Drivers\afd.sys - ok
    23:46:00.0878 4888 [ 7CEC25C682D319D484630B3952C31A11 ] C:\Windows\System32\Drivers\netbt.sys
    23:46:00.0878 4888 C:\Windows\System32\Drivers\netbt.sys - ok
    23:46:00.0880 4888 [ 5989592A91A17587799792A81E1541D4 ] C:\Windows\System32\Drivers\avgldx64.sys
    23:46:00.0880 4888 C:\Windows\System32\Drivers\avgldx64.sys - ok
    23:46:00.0885 4888 [ 7C203A76394F9AE68F69EEE5F9612C4A ] C:\Windows\System32\Drivers\netbios.sys
    23:46:00.0885 4888 C:\Windows\System32\Drivers\netbios.sys - ok
    23:46:00.0888 4888 [ EB8034147D4820CD31BFCB11A2A652DF ] C:\Windows\System32\Drivers\pacer.sys
    23:46:00.0888 4888 C:\Windows\System32\Drivers\pacer.sys - ok
    23:46:00.0890 4888 [ 095E943D27025E4D588AF0A72CC2318F ] C:\Windows\System32\Drivers\vwififlt.sys
    23:46:00.0891 4888 C:\Windows\System32\Drivers\vwififlt.sys - ok
    23:46:00.0892 4888 [ B72C33DBD5326B3864CF2091AF8B906B ] C:\Windows\System32\Drivers\rdbss.sys
    23:46:00.0893 4888 C:\Windows\System32\Drivers\rdbss.sys - ok
    23:46:00.0894 4888 [ 3289766038DB2CB14D07DC84392138D5 ] C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys
    23:46:00.0894 4888 C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys - ok
    23:46:00.0896 4888 [ 58A38E75F3316A83C23DF6173D41F2B5 ] C:\Program Files\SUPERAntiSpyware\saskutil64.sys
    23:46:00.0896 4888 C:\Program Files\SUPERAntiSpyware\saskutil64.sys - ok
    23:46:00.0898 4888 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] C:\Windows\System32\Drivers\mssmbios.sys
    23:46:00.0898 4888 C:\Windows\System32\Drivers\mssmbios.sys - ok
    23:46:00.0900 4888 [ 8ED299C30792544264E558BEA79F0947 ] C:\Windows\System32\Drivers\npsvctrig.sys
    23:46:00.0900 4888 C:\Windows\System32\Drivers\npsvctrig.sys - ok
    23:46:00.0902 4888 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] C:\Windows\System32\Drivers\nsiproxy.sys
    23:46:00.0902 4888 C:\Windows\System32\Drivers\nsiproxy.sys - ok
    23:46:00.0904 4888 [ 6081CEC9EF9EB145D8B46655C7708D51 ] C:\Windows\System32\Drivers\wanarp.sys
    23:46:00.0904 4888 C:\Windows\System32\Drivers\wanarp.sys - ok
    23:46:00.0906 4888 [ 388056EBD5FE6718FE669078DBE37897 ] C:\Windows\System32\Drivers\avgidsdrivera.sys
    23:46:00.0906 4888 C:\Windows\System32\Drivers\avgidsdrivera.sys - ok
    23:46:00.0908 4888 [ C4D01BD86D6B207275FC143EEA951D75 ] C:\Windows\System32\Drivers\dam.sys
    23:46:00.0908 4888 C:\Windows\System32\Drivers\dam.sys - ok
    23:46:00.0910 4888 [ 09D9EB9E7898F8E6561473A20CC808B9 ] C:\Windows\System32\Drivers\dfsc.sys
    23:46:00.0910 4888 C:\Windows\System32\Drivers\dfsc.sys - ok
    23:46:00.0912 4888 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] C:\Windows\System32\Drivers\discache.sys
    23:46:00.0912 4888 C:\Windows\System32\Drivers\discache.sys - ok
    23:46:00.0914 4888 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] C:\Windows\System32\Drivers\ndistapi.sys
    23:46:00.0914 4888 C:\Windows\System32\Drivers\ndistapi.sys - ok
    23:46:00.0916 4888 [ 69B93F623B130976243ECA3D84CC99CA ] C:\Windows\System32\Drivers\agilevpn.sys
    23:46:00.0916 4888 C:\Windows\System32\Drivers\agilevpn.sys - ok
    23:46:00.0917 4888 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] C:\Windows\System32\Drivers\ndiswan.sys
    23:46:00.0917 4888 C:\Windows\System32\Drivers\ndiswan.sys - ok
    23:46:00.0919 4888 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] C:\Windows\System32\Drivers\rassstp.sys
    23:46:00.0919 4888 C:\Windows\System32\Drivers\rassstp.sys - ok
    23:46:00.0921 4888 [ F1B8276F58969BD87683D33066DFE442 ] C:\Windows\System32\ntdll.dll
    23:46:00.0921 4888 C:\Windows\System32\ntdll.dll - ok
    23:46:00.0923 4888 [ 08F850FEBDBDE7C89017B6B0CA0D1CD2 ] C:\Windows\System32\smss.exe
    23:46:00.0923 4888 C:\Windows\System32\smss.exe - ok
    23:46:00.0925 4888 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] C:\Windows\System32\Drivers\CompositeBus.sys
    23:46:00.0925 4888 C:\Windows\System32\Drivers\CompositeBus.sys - ok
    23:46:00.0926 4888 [ FB6C185092E18011EF49989425C2AA87 ] C:\Windows\System32\Drivers\kdnic.sys
    23:46:00.0926 4888 C:\Windows\System32\Drivers\kdnic.sys - ok
    23:46:00.0928 4888 [ 78C9EE193AC2B4CBDBC48B620314D740 ] C:\Windows\System32\Drivers\tunnel.sys
    23:46:00.0928 4888 C:\Windows\System32\Drivers\tunnel.sys - ok
    23:46:00.0931 4888 [ 02CEB3FE6152668A7BA420B93B664860 ] C:\Windows\System32\Drivers\umbus.sys
    23:46:00.0931 4888 C:\Windows\System32\Drivers\umbus.sys - ok
    23:46:00.0933 4888 [ 20F3CD38B107C1BD747C0EA37D450165 ] C:\Windows\System32\Drivers\atikmpag.sys
    23:46:00.0933 4888 C:\Windows\System32\Drivers\atikmpag.sys - ok
    23:46:00.0935 4888 [ A3C0A15B39F979E8F3EABA901D72ECD7 ] C:\Windows\System32\Drivers\atikmdag.sys
    23:46:00.0935 4888 C:\Windows\System32\Drivers\atikmdag.sys - ok
    23:46:00.0936 4888 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] C:\Windows\System32\Drivers\hdaudbus.sys
    23:46:00.0936 4888 C:\Windows\System32\Drivers\hdaudbus.sys - ok
    23:46:00.0938 4888 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] C:\Windows\System32\Drivers\HECIx64.sys
    23:46:00.0938 4888 C:\Windows\System32\Drivers\HECIx64.sys - ok
    23:46:00.0940 4888 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] C:\Windows\System32\Drivers\usbehci.sys
    23:46:00.0940 4888 C:\Windows\System32\Drivers\usbehci.sys - ok
    23:46:00.0942 4888 [ 169629C36CB835A36E23BBC37664401E ] C:\Windows\System32\Drivers\usbport.sys
    23:46:00.0942 4888 C:\Windows\System32\Drivers\usbport.sys - ok
    23:46:00.0944 4888 [ 9CD4259AD15F84DE27B94A956C978D6C ] C:\Windows\System32\Drivers\USBXHCI.SYS
    23:46:00.0944 4888 C:\Windows\System32\Drivers\USBXHCI.SYS - ok
    23:46:00.0945 4888 [ E890C46E4754F0DF51BAFCC8D2E07498 ] C:\Windows\System32\Drivers\1394ohci.sys
    23:46:00.0946 4888 C:\Windows\System32\Drivers\1394ohci.sys - ok
    23:46:00.0947 4888 [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] C:\Windows\System32\Drivers\UCX01000.SYS
    23:46:00.0947 4888 C:\Windows\System32\Drivers\UCX01000.SYS - ok
    23:46:00.0949 4888 [ 15923AA360F7675D3D43C9669316A0BA ] C:\Windows\System32\Drivers\Rt630x64.sys
    23:46:00.0949 4888 C:\Windows\System32\Drivers\Rt630x64.sys - ok
    23:46:00.0951 4888 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] C:\Windows\System32\Drivers\serenum.sys
    23:46:00.0951 4888 C:\Windows\System32\Drivers\serenum.sys - ok
    23:46:00.0952 4888 [ F640A0A218BBF857F1D04A15D7D939F6 ] C:\Windows\System32\Drivers\serial.sys
    23:46:00.0952 4888 C:\Windows\System32\Drivers\serial.sys - ok
    23:46:00.0955 4888 [ E15CDF68DD73423F15D4AC404793AF0D ] C:\Windows\System32\Drivers\intelppm.sys
    23:46:00.0955 4888 C:\Windows\System32\Drivers\intelppm.sys - ok
    23:46:00.0957 4888 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] C:\Windows\System32\Drivers\rasl2tp.sys
    23:46:00.0957 4888 C:\Windows\System32\Drivers\rasl2tp.sys - ok
    23:46:00.0959 4888 [ 00695B9C2DB6111064499C529E90C042 ] C:\Windows\System32\Drivers\raspppoe.sys
    23:46:00.0960 4888 C:\Windows\System32\Drivers\raspppoe.sys - ok
    23:46:00.0962 4888 [ 362D47E5B4D67270DE4B8606036F4ADD ] C:\Windows\System32\Drivers\raspptp.sys
    23:46:00.0962 4888 C:\Windows\System32\Drivers\raspptp.sys - ok
    23:46:00.0964 4888 [ E2A596CACFC6504306CDB7B593B90084 ] C:\Windows\System32\Drivers\wmiacpi.sys
    23:46:00.0964 4888 C:\Windows\System32\Drivers\wmiacpi.sys - ok
    23:46:00.0966 4888 [ 48258ED8A46D0F39ACBF891336250E89 ] C:\Windows\System32\Drivers\ks.sys
    23:46:00.0966 4888 C:\Windows\System32\Drivers\ks.sys - ok
    23:46:00.0968 4888 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] C:\Windows\System32\Drivers\rdpbus.sys
    23:46:00.0968 4888 C:\Windows\System32\Drivers\rdpbus.sys - ok
    23:46:00.0970 4888 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] C:\Windows\System32\Drivers\swenum.sys
    23:46:00.0970 4888 C:\Windows\System32\Drivers\swenum.sys - ok
    23:46:00.0972 4888 [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] C:\Windows\System32\Drivers\ndproxy.sys
    23:46:00.0972 4888 C:\Windows\System32\Drivers\ndproxy.sys - ok
    23:46:00.0974 4888 [ 3FA129BFC7808A2BB7681BEAF339FACD ] C:\Windows\System32\Drivers\usbd.sys
    23:46:00.0974 4888 C:\Windows\System32\Drivers\usbd.sys - ok
    23:46:00.0975 4888 [ FBB6794E3BBAD92D66D59D206C1F849F ] C:\Windows\System32\Drivers\usbhub.sys
    23:46:00.0975 4888 C:\Windows\System32\Drivers\usbhub.sys - ok
    23:46:00.0977 4888 [ 87DAD8D354E312DB16636DC71EB39E5E ] C:\Windows\System32\Drivers\AtihdW86.sys
    23:46:00.0977 4888 C:\Windows\System32\Drivers\AtihdW86.sys - ok
    23:46:00.0979 4888 [ 946ECE07334A74373FAFBFAA063E62F2 ] C:\Windows\System32\Drivers\drmk.sys
    23:46:00.0979 4888 C:\Windows\System32\Drivers\drmk.sys - ok
    23:46:00.0981 4888 [ D10DAEA91AA8412A323DB8EADA23768A ] C:\Windows\System32\Drivers\portcls.sys
    23:46:00.0981 4888 C:\Windows\System32\Drivers\portcls.sys - ok
    23:46:00.0983 4888 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] C:\Windows\System32\Drivers\ksthunk.sys
    23:46:00.0983 4888 C:\Windows\System32\Drivers\ksthunk.sys - ok
    23:46:00.0985 4888 [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] C:\Windows\System32\Drivers\HdAudio.sys
    23:46:00.0985 4888 C:\Windows\System32\Drivers\HdAudio.sys - ok
    23:46:00.0987 4888 [ B7A948501424805571BF562BB0BFE31D ] C:\Windows\System32\Drivers\USBHUB3.SYS
    23:46:00.0987 4888 C:\Windows\System32\Drivers\USBHUB3.SYS - ok
    23:46:00.0989 4888 [ F77177F6C95B2116EE7AD23B5EF57007 ] C:\Windows\System32\Drivers\USBSTOR.SYS
    23:46:00.0989 4888 C:\Windows\System32\Drivers\USBSTOR.SYS - ok
    23:46:00.0990 4888 [ 490B7921C6DC58022FAA908E6310CF24 ] C:\Windows\System32\autochk.exe
    23:46:00.0990 4888 C:\Windows\System32\autochk.exe - ok
    23:46:00.0992 4888 [ DC83C9F4130F447EAD187879708C8035 ] C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
    23:46:00.0992 4888 C:\PROGRA~2\AVG\AVG2013\avgrsa.exe - ok
    23:46:00.0994 4888 [ 23948829C6D049B8ADE0E0FB87305AC3 ] C:\Windows\System32\sdnclean64.exe
    23:46:00.0994 4888 C:\Windows\System32\sdnclean64.exe - ok
    23:46:00.0996 4888 [ E3F8DC5B5AF00A892ED3546C01C9B6E1 ] C:\Program Files (x86)\AVG\AVG2013\avgsysa.dll
    23:46:00.0996 4888 C:\Program Files (x86)\AVG\AVG2013\avgsysa.dll - ok
    23:46:00.0998 4888 [ 4848422594D3B6A6BFF438AF0B6D030D ] C:\Program Files (x86)\AVG\AVG2013\avgloga.dll
    23:46:00.0998 4888 C:\Program Files (x86)\AVG\AVG2013\avgloga.dll - ok
    23:46:01.0000 4888 [ 70D1A44B0D05FEC737CC2C9662D6FB70 ] C:\Program Files (x86)\AVG\AVG2013\avgntopenssla.dll
    23:46:01.0000 4888 C:\Program Files (x86)\AVG\AVG2013\avgntopenssla.dll - ok
    23:46:01.0001 4888 [ 784BD252A13B3DDDA29790FBCB64E536 ] C:\PROGRA~2\AVG\AVG2013\avgchjwa.dll
    23:46:01.0001 4888 C:\PROGRA~2\AVG\AVG2013\avgchjwa.dll - ok
    23:46:01.0003 4888 [ 2C19A4BC4D3C714F890A58B4C942077F ] C:\PROGRA~2\AVG\AVG2013\avgclita.dll
    23:46:01.0003 4888 C:\PROGRA~2\AVG\AVG2013\avgclita.dll - ok
    23:46:01.0005 4888 [ CF433BC29D4089D264F24A1ED371941D ] C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
    23:46:01.0005 4888 C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe - ok
    23:46:01.0007 4888 [ B4CF2DAC753DD785FD92076B3CD36CED ] C:\PROGRA~2\AVG\AVG2013\avgcclia.dll
    23:46:01.0007 4888 C:\PROGRA~2\AVG\AVG2013\avgcclia.dll - ok
    23:46:01.0009 4888 [ 6BCBEE7F87FBA202A834D856433079F2 ] C:\Program Files (x86)\AVG\AVG2013\avgcorea.dll
    23:46:01.0009 4888 C:\Program Files (x86)\AVG\AVG2013\avgcorea.dll - ok
    23:46:01.0011 4888 [ C297715529E28F7283EE621CCFDB1DDB ] C:\Program Files (x86)\AVG\AVG2013\avgcerta.dll
    23:46:01.0011 4888 C:\Program Files (x86)\AVG\AVG2013\avgcerta.dll - ok
    23:46:01.0013 4888 [ 06F3F7E9E9B29C32F8702B541E4C2156 ] C:\Program Files (x86)\AVG\AVG2013\avgchcla.dll
    23:46:01.0013 4888 C:\Program Files (x86)\AVG\AVG2013\avgchcla.dll - ok
    23:46:01.0015 4888 [ 275061F56FC648ED884C38A93EAB6FC6 ] C:\Program Files (x86)\AVG\AVG2013\avgcomma.dll
    23:46:01.0015 4888 C:\Program Files (x86)\AVG\AVG2013\avgcomma.dll - ok
    23:46:01.0016 4888 [ AAD184F33A9A4A2AECF3CB5247651D01 ] C:\Program Files (x86)\AVG\AVG2013\avgntsqlitea.dll
    23:46:01.0017 4888 C:\Program Files (x86)\AVG\AVG2013\avgntsqlitea.dll - ok
    23:46:01.0018 4888 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] C:\Windows\System32\Drivers\usbccgp.sys
    23:46:01.0018 4888 C:\Windows\System32\Drivers\usbccgp.sys - ok
    23:46:01.0020 4888 [ 771BE60F1899D8E43CF563162A8A2FBB ] C:\Windows\System32\Drivers\hidclass.sys
    23:46:01.0020 4888 C:\Windows\System32\Drivers\hidclass.sys - ok
    23:46:01.0023 4888 [ 436188BB139D51E4A763D1D356C90EE3 ] C:\Windows\System32\Drivers\hidparse.sys
    23:46:01.0023 4888 C:\Windows\System32\Drivers\hidparse.sys - ok
    23:46:01.0024 4888 [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] C:\Windows\System32\Drivers\hidusb.sys
    23:46:01.0025 4888 C:\Windows\System32\Drivers\hidusb.sys - ok
    23:46:01.0027 4888 [ DF8663D43AAA1289DE7E32961722BBBA ] C:\Windows\System32\setupapi.dll
    23:46:01.0027 4888 C:\Windows\System32\setupapi.dll - ok
    23:46:01.0029 4888 [ AECED95ACFDCF96757EDD8D0CFFE34B8 ] C:\Windows\System32\msvcrt.dll
    23:46:01.0029 4888 C:\Windows\System32\msvcrt.dll - ok
    23:46:01.0031 4888 [ 8FBD94B69D6423E20ABCD59D86368B21 ] C:\Windows\System32\Drivers\kbdclass.sys
    23:46:01.0031 4888 C:\Windows\System32\Drivers\kbdclass.sys - ok
    23:46:01.0034 4888 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] C:\Windows\System32\Drivers\kbdhid.sys
    23:46:01.0034 4888 C:\Windows\System32\Drivers\kbdhid.sys - ok
    23:46:01.0036 4888 [ B0CECE742DD090C8E2E0B47812F0A26F ] C:\Windows\System32\iertutil.dll
    23:46:01.0036 4888 C:\Windows\System32\iertutil.dll - ok
    23:46:01.0038 4888 [ 60996602A7111FD2D086E803F33E4282 ] C:\Windows\System32\Drivers\fastfat.sys
    23:46:01.0038 4888 C:\Windows\System32\Drivers\fastfat.sys - ok
    23:46:01.0040 4888 [ A74C6A6DA5A35686D7639ACDBD458BFB ] C:\Windows\System32\nsi.dll
    23:46:01.0040 4888 C:\Windows\System32\nsi.dll - ok
    23:46:01.0041 4888 [ 46501A8D9CF0383A104120810E1BABA6 ] C:\Windows\System32\shlwapi.dll
    23:46:01.0041 4888 C:\Windows\System32\shlwapi.dll - ok
    23:46:01.0043 4888 [ AE03548B97CC32199B69E20D29951BD6 ] C:\Windows\System32\Drivers\RTL8192su.sys
    23:46:01.0043 4888 C:\Windows\System32\Drivers\RTL8192su.sys - ok
    23:46:01.0045 4888 [ 62460A45435A26A334907E3F2EA45611 ] C:\Windows\System32\Drivers\vwifibus.sys
    23:46:01.0045 4888 C:\Windows\System32\Drivers\vwifibus.sys - ok
    23:46:01.0047 4888 [ 93FA1A230C11C8568DE3624263C35D39 ] C:\Windows\System32\GdiPlus.dll
    23:46:01.0047 4888 C:\Windows\System32\GdiPlus.dll - ok
    23:46:01.0048 4888 [ E1B2751640FA7840CC5EB6E78513A632 ] C:\Windows\System32\Wldap32.dll
    23:46:01.0048 4888 C:\Windows\System32\Wldap32.dll - ok
    23:46:01.0050 4888 [ 3FBE0784E42E7BA93FCC5201D2BAFE23 ] C:\Windows\System32\Drivers\USBAUDIO.sys
  8. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    23:46:01.0050 4888 C:\Windows\System32\Drivers\USBAUDIO.sys - ok
    23:46:01.0052 4888 [ 85B5B3797315F714A62AC986FFB2B17E ] C:\Windows\System32\sechost.dll
    23:46:01.0052 4888 C:\Windows\System32\sechost.dll - ok
    23:46:01.0054 4888 [ A99AD14F26BDA7D7F27F76BC91B7EED7 ] C:\Windows\System32\user32.dll
    23:46:01.0054 4888 C:\Windows\System32\user32.dll - ok
    23:46:01.0056 4888 [ CE1C66AD4D56FCD7301E1EFEA71340EC ] C:\Windows\System32\oleaut32.dll
    23:46:01.0056 4888 C:\Windows\System32\oleaut32.dll - ok
    23:46:01.0058 4888 [ 2AE813F005223E5B39E0C4D7B8314732 ] C:\Windows\System32\wow64win.dll
    23:46:01.0058 4888 C:\Windows\System32\wow64win.dll - ok
    23:46:01.0060 4888 [ 4522375A7B8693C2134D5613A134E4F6 ] C:\Windows\System32\msctf.dll
    23:46:01.0060 4888 C:\Windows\System32\msctf.dll - ok
    23:46:01.0062 4888 [ F02118B1D3B0D574C99D87380069B44E ] C:\Windows\System32\urlmon.dll
    23:46:01.0062 4888 C:\Windows\System32\urlmon.dll - ok
    23:46:01.0064 4888 [ 2E3EDE81672653E0C759F0A1135F704F ] C:\Windows\System32\clbcatq.dll
    23:46:01.0064 4888 C:\Windows\System32\clbcatq.dll - ok
    23:46:01.0066 4888 [ B3FB7D980FE7F6FB78D83B87C0D2F7F3 ] C:\Windows\System32\imagehlp.dll
    23:46:01.0066 4888 C:\Windows\System32\imagehlp.dll - ok
    23:46:01.0068 4888 [ 3A30E09AAA2BB060D39C8FA5E20D4FA3 ] C:\Windows\System32\advapi32.dll
    23:46:01.0068 4888 C:\Windows\System32\advapi32.dll - ok
    23:46:01.0070 4888 [ 3C6933B638BB812F4084CF44AE698704 ] C:\Windows\System32\kernel32.dll
    23:46:01.0070 4888 C:\Windows\System32\kernel32.dll - ok
    23:46:01.0072 4888 [ C3D51000E8FBEF76BC91E145B0D7FC67 ] C:\Windows\System32\comdlg32.dll
    23:46:01.0072 4888 C:\Windows\System32\comdlg32.dll - ok
    23:46:01.0073 4888 [ DA66D6D4A0B77D57F5CF449B1231010F ] C:\Windows\System32\imm32.dll
    23:46:01.0074 4888 C:\Windows\System32\imm32.dll - ok
    23:46:01.0075 4888 [ 1E2E99B4FA9A5F0D9934F8B99B528A62 ] C:\Windows\System32\wow64cpu.dll
    23:46:01.0075 4888 C:\Windows\System32\wow64cpu.dll - ok
    23:46:01.0077 4888 [ 2E5B349ACDA36C20612795754DB93312 ] C:\Windows\System32\ws2_32.dll
    23:46:01.0077 4888 C:\Windows\System32\ws2_32.dll - ok
    23:46:01.0079 4888 [ 6B3F1596000CB33F73E14B6F7D5CFF82 ] C:\Windows\System32\difxapi.dll
    23:46:01.0079 4888 C:\Windows\System32\difxapi.dll - ok
    23:46:01.0081 4888 [ 75CB0458521FFA420E4230A931E4517B ] C:\Windows\System32\normaliz.dll
    23:46:01.0081 4888 C:\Windows\System32\normaliz.dll - ok
    23:46:01.0082 4888 [ 652467DC0E67CF738972117C09D05571 ] C:\Windows\System32\rpcrt4.dll
    23:46:01.0082 4888 C:\Windows\System32\rpcrt4.dll - ok
    23:46:01.0084 4888 [ AAEF73606F58ADE710208F4B1B988FBF ] C:\Windows\System32\wininet.dll
    23:46:01.0084 4888 C:\Windows\System32\wininet.dll - ok
    23:46:01.0086 4888 [ CA7561AACEE1F578C5360E4C07B71708 ] C:\Windows\System32\gdi32.dll
    23:46:01.0086 4888 C:\Windows\System32\gdi32.dll - ok
    23:46:01.0088 4888 [ CC81790E0A18535853C33BABBFF15D56 ] C:\Windows\System32\lpk.dll
    23:46:01.0088 4888 C:\Windows\System32\lpk.dll - ok
    23:46:01.0090 4888 [ B74C50954E234506548CBBF3933AF391 ] C:\Windows\System32\wow64.dll
    23:46:01.0090 4888 C:\Windows\System32\wow64.dll - ok
    23:46:01.0092 4888 [ 1D2731630A5437C54217CDE1C4830F81 ] C:\Windows\System32\ole32.dll
    23:46:01.0092 4888 C:\Windows\System32\ole32.dll - ok
    23:46:01.0094 4888 [ 41AC2B1335317D2F8700E17328F71E0C ] C:\Windows\System32\psapi.dll
    23:46:01.0094 4888 C:\Windows\System32\psapi.dll - ok
    23:46:01.0095 4888 [ 154553459809F791C7335075211ED81B ] C:\Windows\System32\shell32.dll
    23:46:01.0095 4888 C:\Windows\System32\shell32.dll - ok
    23:46:01.0097 4888 [ CB2527B8B87D83E56FBF3944BBB6F606 ] C:\Windows\System32\Drivers\mouhid.sys
    23:46:01.0097 4888 C:\Windows\System32\Drivers\mouhid.sys - ok
    23:46:01.0099 4888 [ 618446B98C79776654340CE27C73485E ] C:\Windows\System32\Drivers\mouclass.sys
    23:46:01.0099 4888 C:\Windows\System32\Drivers\mouclass.sys - ok
    23:46:01.0100 4888 [ 0341C9184C252000D1AD396C71CFD860 ] C:\Windows\System32\combase.dll
    23:46:01.0100 4888 C:\Windows\System32\combase.dll - ok
    23:46:01.0102 4888 [ EFD55F2C466663F37412B843F6CC55F5 ] C:\Windows\System32\crypt32.dll
    23:46:01.0102 4888 C:\Windows\System32\crypt32.dll - ok
    23:46:01.0103 4888 [ 996604E515ACE3775D645A4FE0D66D4A ] C:\Windows\System32\wintrust.dll
    23:46:01.0103 4888 C:\Windows\System32\wintrust.dll - ok
    23:46:01.0106 4888 [ C26780F936820DBB3A1323FC1C09E05F ] C:\Windows\System32\cfgmgr32.dll
    23:46:01.0106 4888 C:\Windows\System32\cfgmgr32.dll - ok
    23:46:01.0108 4888 [ 03E223CC4AE2D2B55E400AD9C55449F6 ] C:\Windows\System32\comctl32.dll
    23:46:01.0108 4888 C:\Windows\System32\comctl32.dll - ok
    23:46:01.0111 4888 [ F37BD0CAA604B6FE5CEC9D0BC05ABAF8 ] C:\Windows\System32\KernelBase.dll
    23:46:01.0111 4888 C:\Windows\System32\KernelBase.dll - ok
    23:46:01.0113 4888 [ 51B6CB1852B49E150F7E8B8C2F4CB0F7 ] C:\Windows\System32\devobj.dll
    23:46:01.0113 4888 C:\Windows\System32\devobj.dll - ok
    23:46:01.0114 4888 [ C763F7DC50C70E657DCB164FA9D92085 ] C:\Windows\System32\msasn1.dll
    23:46:01.0114 4888 C:\Windows\System32\msasn1.dll - ok
    23:46:01.0116 4888 [ BD321B58C0CC6C8196F8CF4EE226E830 ] C:\Windows\SysWOW64\normaliz.dll
    23:46:01.0116 4888 C:\Windows\SysWOW64\normaliz.dll - ok
    23:46:01.0118 4888 [ 36D755FFED947A08B1650ACE9644FAB8 ] C:\Windows\SysWOW64\lpk.dll
    23:46:01.0118 4888 C:\Windows\SysWOW64\lpk.dll - ok
    23:46:01.0120 4888 [ F3427D3D28F02A4BE6DFC1E672E30BA3 ] C:\Windows\System32\win32k.sys
    23:46:01.0120 4888 C:\Windows\System32\win32k.sys - ok
    23:46:01.0122 4888 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\System32\basesrv.dll
    23:46:01.0122 4888 C:\Windows\System32\basesrv.dll - ok
    23:46:01.0123 4888 [ 1C510F9C2DB7393468EB789A96DAAFA8 ] C:\Windows\System32\csrsrv.dll
    23:46:01.0123 4888 C:\Windows\System32\csrsrv.dll - ok
    23:46:01.0125 4888 [ 0D9F14739D05F8B8B028B539FC6F1F29 ] C:\Windows\System32\csrss.exe
    23:46:01.0125 4888 C:\Windows\System32\csrss.exe - ok
    23:46:01.0127 4888 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\System32\winsrv.dll
    23:46:01.0127 4888 C:\Windows\System32\winsrv.dll - ok
    23:46:01.0128 4888 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] C:\Windows\System32\Drivers\monitor.sys
    23:46:01.0128 4888 C:\Windows\System32\Drivers\monitor.sys - ok
    23:46:01.0130 4888 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\System32\sxssrv.dll
    23:46:01.0130 4888 C:\Windows\System32\sxssrv.dll - ok
    23:46:01.0132 4888 [ F14D77B1B3347ED08272B65A3F80B4CE ] C:\Windows\System32\tsddd.dll
    23:46:01.0132 4888 C:\Windows\System32\tsddd.dll - ok
    23:46:01.0134 4888 [ 3491660B47A7CE7BC1B63C4E71E1E251 ] C:\Windows\System32\cdd.dll
    23:46:01.0134 4888 C:\Windows\System32\cdd.dll - ok
    23:46:01.0135 4888 [ FD777FE5B879BC921ED01A647143D709 ] C:\Windows\System32\KBDUS.DLL
    23:46:01.0135 4888 C:\Windows\System32\KBDUS.DLL - ok
    23:46:01.0137 4888 [ 4C7303709714F589A0809AC82F03CA84 ] C:\Windows\System32\profapi.dll
    23:46:01.0137 4888 C:\Windows\System32\profapi.dll - ok
    23:46:01.0138 4888 [ FE9AB232B56A12224E8A3F3F9878C9A3 ] C:\Windows\System32\wininit.exe
    23:46:01.0138 4888 C:\Windows\System32\wininit.exe - ok
    23:46:01.0140 4888 [ 8144BCD1736C3C76978B8378556CA746 ] C:\Windows\System32\wininitext.dll
    23:46:01.0140 4888 C:\Windows\System32\wininitext.dll - ok
    23:46:01.0142 4888 [ 10564D7D4FBAABDB826E9D607679C85F ] C:\Windows\System32\WlS0WndH.dll
    23:46:01.0142 4888 C:\Windows\System32\WlS0WndH.dll - ok
    23:46:01.0143 4888 [ 7679414791657155EDF45D388325BEFE ] C:\Windows\System32\sxs.dll
    23:46:01.0143 4888 C:\Windows\System32\sxs.dll - ok
    23:46:01.0145 4888 [ BCF2036A0DD579E47C008C133550283E ] C:\Windows\System32\winlogon.exe
    23:46:01.0145 4888 C:\Windows\System32\winlogon.exe - ok
    23:46:01.0147 4888 [ EF72CFB67C73A8751F3BC4F4C98EAD4C ] C:\Windows\System32\powrprof.dll
    23:46:01.0147 4888 C:\Windows\System32\powrprof.dll - ok
    23:46:01.0148 4888 [ C0FAB7DDA13CE5593A48B40056AA278D ] C:\Windows\System32\samcli.dll
    23:46:01.0148 4888 C:\Windows\System32\samcli.dll - ok
    23:46:01.0150 4888 [ 9D7EAFBAD213566D70BAE9A14B847666 ] C:\Windows\System32\winsta.dll
    23:46:01.0150 4888 C:\Windows\System32\winsta.dll - ok
    23:46:01.0152 4888 [ E8001E0F56F0B0F5D204EF865F47372B ] C:\Windows\System32\wtsapi32.dll
    23:46:01.0152 4888 C:\Windows\System32\wtsapi32.dll - ok
    23:46:01.0154 4888 [ 7F4E2FB897E35952C5B22BE48047FCA8 ] C:\Windows\System32\bcryptprimitives.dll
    23:46:01.0154 4888 C:\Windows\System32\bcryptprimitives.dll - ok
    23:46:01.0156 4888 [ 2577AEA213B0B70FF5B4E3D180E66B11 ] C:\Windows\System32\cryptbase.dll
    23:46:01.0156 4888 C:\Windows\System32\cryptbase.dll - ok
    23:46:01.0157 4888 [ F702AB6181513303AB0FC8D59E52708B ] C:\Windows\System32\lsass.exe
    23:46:01.0157 4888 C:\Windows\System32\lsass.exe - ok
    23:46:01.0159 4888 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\System32\services.exe
    23:46:01.0159 4888 C:\Windows\System32\services.exe - ok
    23:46:01.0160 4888 [ D293F2E8CEE73B87B04790D5169C0F25 ] C:\Windows\System32\lsasrv.dll
    23:46:01.0160 4888 C:\Windows\System32\lsasrv.dll - ok
    23:46:01.0162 4888 [ ECFC9AF8D1A6E16223E1B17EA732FA08 ] C:\Windows\System32\scext.dll
    23:46:01.0162 4888 C:\Windows\System32\scext.dll - ok
    23:46:01.0165 4888 [ D71A882FE7A74F01B92F6A2C74305E45 ] C:\Windows\System32\srvcli.dll
    23:46:01.0165 4888 C:\Windows\System32\srvcli.dll - ok
    23:46:01.0167 4888 [ D1AEFA79EE1EE089D03249BE581D5DD6 ] C:\Windows\System32\sspicli.dll
    23:46:01.0167 4888 C:\Windows\System32\sspicli.dll - ok
    23:46:01.0168 4888 [ 90BEE4B9728DDCF9787100CB8A04815C ] C:\Windows\System32\sspisrv.dll
    23:46:01.0168 4888 C:\Windows\System32\sspisrv.dll - ok
    23:46:01.0170 4888 [ 8A6CAF25365FDF2432054C672885917E ] C:\Windows\System32\ubpm.dll
    23:46:01.0170 4888 C:\Windows\System32\ubpm.dll - ok
    23:46:01.0172 4888 [ E3D5F59826899393970533A8E6AB34EE ] C:\Windows\System32\bcrypt.dll
    23:46:01.0172 4888 C:\Windows\System32\bcrypt.dll - ok
    23:46:01.0174 4888 [ 1B5B5563C5008911D77398B8FDC6F757 ] C:\Windows\System32\samsrv.dll
    23:46:01.0174 4888 C:\Windows\System32\samsrv.dll - ok
    23:46:01.0176 4888 [ DF8111BDC2F35006F0CD471A2CC65665 ] C:\Windows\System32\SPInf.dll
    23:46:01.0176 4888 C:\Windows\System32\SPInf.dll - ok
    23:46:01.0178 4888 [ 39084062AB7B7CA19DBF0AA4581D833B ] C:\Windows\System32\msprivs.dll
    23:46:01.0178 4888 C:\Windows\System32\msprivs.dll - ok
    23:46:01.0179 4888 [ EA697BA99655FA048BB297EE9A3CCBC7 ] C:\Windows\System32\ncrypt.dll
    23:46:01.0179 4888 C:\Windows\System32\ncrypt.dll - ok
    23:46:01.0181 4888 [ 21AA2C2564DDB9F3B83CE322D9E97F9C ] C:\Windows\System32\netjoin.dll
    23:46:01.0181 4888 C:\Windows\System32\netjoin.dll - ok
    23:46:01.0182 4888 [ A6FE1FCAB4AC686D6BD7884B317935F7 ] C:\Windows\System32\ntasn1.dll
    23:46:01.0182 4888 C:\Windows\System32\ntasn1.dll - ok
    23:46:01.0184 4888 [ 058B0CDA8E19AF2A7E6CFA7604BB8D14 ] C:\Windows\System32\cryptdll.dll
    23:46:01.0184 4888 C:\Windows\System32\cryptdll.dll - ok
    23:46:01.0186 4888 [ 1654B23B029698077A59469E6AC93A99 ] C:\Windows\System32\kerberos.dll
    23:46:01.0186 4888 C:\Windows\System32\kerberos.dll - ok
    23:46:01.0188 4888 [ 016EDF8CF3BC0428F9A910637E918808 ] C:\Windows\System32\negoexts.dll
    23:46:01.0188 4888 C:\Windows\System32\negoexts.dll - ok
    23:46:01.0190 4888 [ 8F9F55C4B857E35552D78A2AAF1BADF9 ] C:\Windows\System32\cryptsp.dll
    23:46:01.0190 4888 C:\Windows\System32\cryptsp.dll - ok
    23:46:01.0191 4888 [ 4543E23FF678CA9D2C943A45B5B82A17 ] C:\Windows\System32\msv1_0.dll
    23:46:01.0191 4888 C:\Windows\System32\msv1_0.dll - ok
    23:46:01.0193 4888 [ 1AC307A2F7317007BC382046B3835202 ] C:\Windows\System32\mswsock.dll
    23:46:01.0193 4888 C:\Windows\System32\mswsock.dll - ok
    23:46:01.0195 4888 [ B16A14270DB26838B48A06835FDBBFB4 ] C:\Windows\System32\dnsapi.dll
    23:46:01.0195 4888 C:\Windows\System32\dnsapi.dll - ok
    23:46:01.0197 4888 [ FDC70965F0FC9DFEBC919627DED5DDFF ] C:\Windows\System32\netlogon.dll
    23:46:01.0197 4888 C:\Windows\System32\netlogon.dll - ok
    23:46:01.0198 4888 [ 113E9BB020461D5F9D0C0C6EA29C513F ] C:\Windows\System32\logoncli.dll
    23:46:01.0198 4888 C:\Windows\System32\logoncli.dll - ok
    23:46:01.0200 4888 [ 6847834F846A4CF1CD4FC86334B4879D ] C:\Windows\System32\schannel.dll
    23:46:01.0200 4888 C:\Windows\System32\schannel.dll - ok
    23:46:01.0202 4888 [ 72FCEDD4EEE5F1C38F84F0947A26950E ] C:\Windows\System32\userenv.dll
    23:46:01.0202 4888 C:\Windows\System32\userenv.dll - ok
    23:46:01.0205 4888 [ BB4FCE5019D973A8BA038A03C7ECECDD ] C:\Windows\System32\rsaenh.dll
    23:46:01.0205 4888 C:\Windows\System32\rsaenh.dll - ok
    23:46:01.0208 4888 [ CC6D17EDB5B1C73523E4B7D6EB7BBC09 ] C:\Windows\System32\TSpkg.dll
    23:46:01.0208 4888 C:\Windows\System32\TSpkg.dll - ok
    23:46:01.0209 4888 [ 0DFEBCD834EF05A112BF90F8A7993212 ] C:\Windows\System32\wdigest.dll
    23:46:01.0209 4888 C:\Windows\System32\wdigest.dll - ok
    23:46:01.0211 4888 [ 2F5E3751FAB4AE994262E2FB9CEDC885 ] C:\Windows\System32\dpapisrv.dll
    23:46:01.0211 4888 C:\Windows\System32\dpapisrv.dll - ok
    23:46:01.0213 4888 [ D8BEFDDADA7125E5A4DD37EA5AC620D9 ] C:\Windows\System32\efslsaext.dll
    23:46:01.0213 4888 C:\Windows\System32\efslsaext.dll - ok
    23:46:01.0214 4888 [ 5B92CE37EBE65A5424074E50C48AA52E ] C:\Windows\System32\livessp.dll
    23:46:01.0214 4888 C:\Windows\System32\livessp.dll - ok
    23:46:01.0216 4888 [ 0059D2032BCA18EBBC03D6D1308892F6 ] C:\Windows\System32\pku2u.dll
    23:46:01.0216 4888 C:\Windows\System32\pku2u.dll - ok
    23:46:01.0218 4888 [ 8EA33056071F6EB7A97C68E978F01573 ] C:\Windows\System32\credssp.dll
    23:46:01.0218 4888 C:\Windows\System32\credssp.dll - ok
    23:46:01.0219 4888 [ 4F6E1CA672370A9BCAC049CE3AB7F666 ] C:\Windows\System32\scecli.dll
    23:46:01.0219 4888 C:\Windows\System32\scecli.dll - ok
    23:46:01.0221 4888 [ C0D0F60B47079C2AAD30B836326313F4 ] C:\Windows\System32\scesrv.dll
    23:46:01.0221 4888 C:\Windows\System32\scesrv.dll - ok
    23:46:01.0223 4888 [ 0D7B278E91F0F07BBC4DFDF634BEFDB5 ] C:\Windows\System32\authz.dll
    23:46:01.0223 4888 C:\Windows\System32\authz.dll - ok
    23:46:01.0225 4888 [ 0CE9A21C24E62DFD77E273B56B11C2C7 ] C:\Windows\System32\devrtl.dll
    23:46:01.0225 4888 C:\Windows\System32\devrtl.dll - ok
    23:46:01.0227 4888 [ E17EA93682D88F1CE94CCE2A804FA691 ] C:\Windows\System32\netutils.dll
    23:46:01.0227 4888 C:\Windows\System32\netutils.dll - ok
    23:46:01.0229 4888 [ EDE27EACE742EE2888C5DD36400A2EC0 ] C:\Windows\System32\svchost.exe
    23:46:01.0229 4888 C:\Windows\System32\svchost.exe - ok
    23:46:01.0231 4888 [ 799BE46D45D486704CE0F37CA5385262 ] C:\Windows\System32\umpnpmgr.dll
    23:46:01.0231 4888 C:\Windows\System32\umpnpmgr.dll - ok
    23:46:01.0232 4888 [ 5C2758C697F6EC1C3771902D5FDF8079 ] C:\Windows\System32\gpapi.dll
    23:46:01.0232 4888 C:\Windows\System32\gpapi.dll - ok
    23:46:01.0234 4888 [ 2BA42F109B70D10E2F12072AD5BFFE27 ] C:\Windows\System32\hid.dll
    23:46:01.0234 4888 C:\Windows\System32\hid.dll - ok
    23:46:01.0236 4888 [ 61A8BF961A244C60697814D8CC2741FA ] C:\Windows\System32\pcwum.dll
    23:46:01.0236 4888 C:\Windows\System32\pcwum.dll - ok
    23:46:01.0238 4888 [ F1E067F56373F11EA4B785CAE823740A ] C:\Windows\System32\umpo.dll
    23:46:01.0238 4888 C:\Windows\System32\umpo.dll - ok
    23:46:01.0240 4888 [ 58CE8F135CC6F3271603A8BB094B1967 ] C:\Windows\System32\umpoext.dll
    23:46:01.0240 4888 C:\Windows\System32\umpoext.dll - ok
    23:46:01.0242 4888 [ 2BDC5D711FA61307CE6190D47C956368 ] C:\Windows\System32\Drivers\luafv.sys
    23:46:01.0242 4888 C:\Windows\System32\Drivers\luafv.sys - ok
    23:46:01.0243 4888 [ 92EB844D90615CB266F84C3202B8786E ] C:\Windows\System32\Drivers\mbam.sys
  9. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    23:46:01.0243 4888 C:\Windows\System32\Drivers\mbam.sys - ok
    23:46:01.0245 4888 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] C:\Windows\System32\rpcss.dll
    23:46:01.0245 4888 C:\Windows\System32\rpcss.dll - ok
    23:46:01.0248 4888 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] C:\Windows\System32\RpcEpMap.dll
    23:46:01.0248 4888 C:\Windows\System32\RpcEpMap.dll - ok
    23:46:01.0249 4888 [ 587089B7A93F3DE43832F3DBDD8F4653 ] C:\Windows\System32\RpcRtRemote.dll
    23:46:01.0249 4888 C:\Windows\System32\RpcRtRemote.dll - ok
    23:46:01.0251 4888 [ 975398A3D2C1FEA73FC93931978DF354 ] C:\Windows\System32\bisrv.dll
    23:46:01.0251 4888 C:\Windows\System32\bisrv.dll - ok
    23:46:01.0253 4888 [ 43197AE4DF1F8D5A95C5134C81B05FB9 ] C:\Windows\System32\FirewallAPI.dll
    23:46:01.0253 4888 C:\Windows\System32\FirewallAPI.dll - ok
    23:46:01.0255 4888 [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] C:\Windows\System32\lsm.dll
    23:46:01.0255 4888 C:\Windows\System32\lsm.dll - ok
    23:46:01.0257 4888 [ 066FE80AE0AC570822EB37970E27EA1D ] C:\Windows\System32\psmsrv.dll
    23:46:01.0257 4888 C:\Windows\System32\psmsrv.dll - ok
    23:46:01.0259 4888 [ 2383FFF04B78586DB2F78E82583F630A ] C:\Windows\System32\sysntfy.dll
    23:46:01.0259 4888 C:\Windows\System32\sysntfy.dll - ok
    23:46:01.0261 4888 [ E5D1CB25AB7050FE4A4397089BE2AA09 ] C:\Windows\System32\wmsgapi.dll
    23:46:01.0261 4888 C:\Windows\System32\wmsgapi.dll - ok
    23:46:01.0264 4888 [ 4C1E3649C89C7D542CD18ECC5210099D ] C:\Windows\System32\atiesrxx.exe
    23:46:01.0264 4888 C:\Windows\System32\atiesrxx.exe - ok
    23:46:01.0266 4888 [ F718B60213F47D9702F5048DC703C13D ] C:\Windows\System32\UXInit.dll
    23:46:01.0266 4888 C:\Windows\System32\UXInit.dll - ok
    23:46:01.0268 4888 [ B5CCCD2C6A0CC5CAE2B5140A1985DD69 ] C:\Windows\System32\uxtheme.dll
    23:46:01.0268 4888 C:\Windows\System32\uxtheme.dll - ok
    23:46:01.0270 4888 [ 52576C623E5877D6CD73479610A532C2 ] C:\Windows\System32\dpapi.dll
    23:46:01.0270 4888 C:\Windows\System32\dpapi.dll - ok
    23:46:01.0272 4888 [ 11EA2B2C58E38BDBBEC4298BCEE40A59 ] C:\Windows\System32\wevtsvc.dll
    23:46:01.0272 4888 C:\Windows\System32\wevtsvc.dll - ok
    23:46:01.0274 4888 [ 0CBF0748B3F6C978233BBDD1D9D6A023 ] C:\Windows\System32\dwm.exe
    23:46:01.0274 4888 C:\Windows\System32\dwm.exe - ok
    23:46:01.0276 4888 [ 5358678C6370F2ADC5291849F6503262 ] C:\Windows\System32\gpsvc.dll
    23:46:01.0276 4888 C:\Windows\System32\gpsvc.dll - ok
    23:46:01.0278 4888 [ FAD009934DE5E8FA2511109B2349B9B1 ] C:\Windows\System32\LogonUI.exe
    23:46:01.0278 4888 C:\Windows\System32\LogonUI.exe - ok
    23:46:01.0279 4888 [ 3DB7FFC313BD190D0E64931302776BAF ] C:\Windows\System32\ntmarta.dll
    23:46:01.0279 4888 C:\Windows\System32\ntmarta.dll - ok
    23:46:01.0281 4888 [ 429E8502AD2227CF88F8840FC5BD590D ] C:\Windows\System32\profsvc.dll
    23:46:01.0281 4888 C:\Windows\System32\profsvc.dll - ok
    23:46:01.0283 4888 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] C:\Windows\System32\themeservice.dll
    23:46:01.0283 4888 C:\Windows\System32\themeservice.dll - ok
    23:46:01.0285 4888 [ 064FEE2A4EEE419868FE409C4C065A24 ] C:\Windows\System32\authui.dll
    23:46:01.0285 4888 C:\Windows\System32\authui.dll - ok
    23:46:01.0287 4888 [ 849958533A0CB20B5B738CA963A81EAF ] C:\Windows\System32\dwmredir.dll
    23:46:01.0287 4888 C:\Windows\System32\dwmredir.dll - ok
    23:46:01.0289 4888 [ 65F870703D4DC0FC382C23EB2A609252 ] C:\Windows\System32\dwmcore.dll
    23:46:01.0289 4888 C:\Windows\System32\dwmcore.dll - ok
    23:46:01.0291 4888 [ F0C56FAF38A244599CBC173D581E27FC ] C:\Windows\System32\nlaapi.dll
    23:46:01.0291 4888 C:\Windows\System32\nlaapi.dll - ok
    23:46:01.0292 4888 [ 91E1A704990CEE32FFFBDF8AB8C258E4 ] C:\Windows\System32\dsrole.dll
    23:46:01.0292 4888 C:\Windows\System32\dsrole.dll - ok
    23:46:01.0294 4888 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] C:\Windows\System32\es.dll
    23:46:01.0294 4888 C:\Windows\System32\es.dll - ok
    23:46:01.0296 4888 [ 91F2CB5172B120F7BE0645882D4427C8 ] C:\Windows\System32\profsvcext.dll
    23:46:01.0296 4888 C:\Windows\System32\profsvcext.dll - ok
    23:46:01.0298 4888 [ BF81D887348C8DD9E45B08F3718F7D96 ] C:\Windows\System32\SHCore.dll
    23:46:01.0298 4888 C:\Windows\System32\SHCore.dll - ok
    23:46:01.0300 4888 [ B1256D36D6D415FB924A26957A83C2CB ] C:\Windows\System32\dcomp.dll
    23:46:01.0300 4888 C:\Windows\System32\dcomp.dll - ok
    23:46:01.0302 4888 [ 80E5C64479952266CCFCF52CBBBE84DC ] C:\Windows\System32\dui70.dll
    23:46:01.0302 4888 C:\Windows\System32\dui70.dll - ok
    23:46:01.0304 4888 [ D70E930E67968D0F849333841DDBA02B ] C:\Windows\System32\netapi32.dll
    23:46:01.0304 4888 C:\Windows\System32\netapi32.dll - ok
    23:46:01.0306 4888 [ BB6591EA99CBCD17989CBF04214DD7E8 ] C:\Windows\System32\ntdsapi.dll
    23:46:01.0306 4888 C:\Windows\System32\ntdsapi.dll - ok
    23:46:01.0308 4888 [ F235600515AD6CBE06DB440FBB7C8E01 ] C:\Windows\System32\atl.dll
    23:46:01.0308 4888 C:\Windows\System32\atl.dll - ok
    23:46:01.0310 4888 [ 38082C25FC60B10977AC729127A4463D ] C:\Windows\System32\dwmapi.dll
    23:46:01.0310 4888 C:\Windows\System32\dwmapi.dll - ok
    23:46:01.0311 4888 [ C6D71F42C6CB7F3AECFEDC1C0DDE8232 ] C:\Windows\System32\WindowsCodecs.dll
    23:46:01.0311 4888 C:\Windows\System32\WindowsCodecs.dll - ok
    23:46:01.0313 4888 [ 6CB5B0F8F835B0E69857436405BA6E28 ] C:\Windows\System32\d3d10_1.dll
    23:46:01.0313 4888 C:\Windows\System32\d3d10_1.dll - ok
    23:46:01.0315 4888 [ 4A945F0177124D653B5EF975D11DA9F8 ] C:\Windows\System32\dfscli.dll
    23:46:01.0315 4888 C:\Windows\System32\dfscli.dll - ok
    23:46:01.0317 4888 [ FC414C8C91848FACFD6514AEF88A5ABA ] C:\Windows\System32\wkscli.dll
    23:46:01.0317 4888 C:\Windows\System32\wkscli.dll - ok
    23:46:01.0319 4888 [ E2B8F9FE6FA401AEB0BDFF8ED61A7568 ] C:\Windows\System32\wmiclnt.dll
    23:46:01.0319 4888 C:\Windows\System32\wmiclnt.dll - ok
    23:46:01.0321 4888 [ 16E116784B900D8A58DA4FB2FF1F0931 ] C:\Windows\System32\atieclxx.exe
    23:46:01.0321 4888 C:\Windows\System32\atieclxx.exe - ok
    23:46:01.0323 4888 [ 3951ECF063787EB40CD33D2961B39E23 ] C:\Windows\System32\d3d10_1core.dll
    23:46:01.0323 4888 C:\Windows\System32\d3d10_1core.dll - ok
    23:46:01.0325 4888 [ 9C51620998F0763039DFA6BF68E475ED ] C:\Windows\System32\Sens.dll
    23:46:01.0325 4888 C:\Windows\System32\Sens.dll - ok
    23:46:01.0327 4888 [ 4B249FD266D2FF17EE8809EB46A173A6 ] C:\Windows\System32\taskschd.dll
    23:46:01.0327 4888 C:\Windows\System32\taskschd.dll - ok
    23:46:01.0328 4888 [ ABA350274707D09D91826ED8EAF886B5 ] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f\comctl32.dll
    23:46:01.0328 4888 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f\comctl32.dll - ok
    23:46:01.0330 4888 [ 810ED88782952228AF9C0985FB7D259E ] C:\Windows\System32\AudioEndpointBuilder.dll
    23:46:01.0330 4888 C:\Windows\System32\AudioEndpointBuilder.dll - ok
    23:46:01.0332 4888 [ 02DF949C584B02FAB05868502C578D42 ] C:\Windows\System32\dxgi.dll
    23:46:01.0332 4888 C:\Windows\System32\dxgi.dll - ok
    23:46:01.0334 4888 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] C:\Windows\System32\FntCache.dll
    23:46:01.0334 4888 C:\Windows\System32\FntCache.dll - ok
    23:46:01.0335 4888 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] C:\Windows\System32\mmcss.dll
    23:46:01.0335 4888 C:\Windows\System32\mmcss.dll - ok
    23:46:01.0337 4888 [ 37843E6888569097918544F0338BC19D ] C:\Windows\System32\avrt.dll
    23:46:01.0337 4888 C:\Windows\System32\avrt.dll - ok
    23:46:01.0339 4888 [ EAE1E802E8DBA1A8562652A29D520BEF ] C:\Windows\System32\d3d11.dll
    23:46:01.0339 4888 C:\Windows\System32\d3d11.dll - ok
    23:46:01.0341 4888 [ 5264BDA0ACE3D560336AC2EAD0728D41 ] C:\Windows\System32\duser.dll
    23:46:01.0341 4888 C:\Windows\System32\duser.dll - ok
    23:46:01.0343 4888 [ B5FEAE9A8C299EB6D1B6D810CDB4A9A7 ] C:\Windows\System32\MMDevAPI.dll
    23:46:01.0343 4888 C:\Windows\System32\MMDevAPI.dll - ok
    23:46:01.0345 4888 [ F76BE04CD180721363FBD7884C90C09E ] C:\Windows\System32\atiadlxx.dll
    23:46:01.0345 4888 C:\Windows\System32\atiadlxx.dll - ok
    23:46:01.0347 4888 [ D3F63550DCDA80A2AFB218A86A4EC5F0 ] C:\Windows\System32\BCP47Langs.dll
    23:46:01.0347 4888 C:\Windows\System32\BCP47Langs.dll - ok
    23:46:01.0348 4888 [ 46F09D226A9F0676932657A6761CEB82 ] C:\Windows\System32\d3d10warp.dll
    23:46:01.0349 4888 C:\Windows\System32\d3d10warp.dll - ok
    23:46:01.0350 4888 [ D39F1714D8944A0AC590B08F5A2DD0E7 ] C:\Windows\System32\SndVolSSO.dll
    23:46:01.0350 4888 C:\Windows\System32\SndVolSSO.dll - ok
    23:46:01.0352 4888 [ 721CAFC7474688EFB2961726DBBF1C78 ] C:\Windows\System32\wsock32.dll
    23:46:01.0352 4888 C:\Windows\System32\wsock32.dll - ok
    23:46:01.0354 4888 [ 8696D6FA6F96F34EB9151704ABAF133A ] C:\Windows\System32\aticfx64.dll
    23:46:01.0355 4888 C:\Windows\System32\aticfx64.dll - ok
    23:46:01.0357 4888 [ 156B8769D44187090781DFA9FED1AE18 ] C:\Windows\System32\SmartcardCredentialProvider.dll
    23:46:01.0357 4888 C:\Windows\System32\SmartcardCredentialProvider.dll - ok
    23:46:01.0359 4888 [ 25CA8B87479A374919563B3EE7136F32 ] C:\Windows\System32\audiosrv.dll
    23:46:01.0359 4888 C:\Windows\System32\audiosrv.dll - ok
    23:46:01.0362 4888 [ 20A19E2D29F86B2B3AA5B2A8B96B3041 ] C:\Windows\System32\DWrite.dll
    23:46:01.0362 4888 C:\Windows\System32\DWrite.dll - ok
    23:46:01.0365 4888 [ 439580916E49358F8BE33005E98E4B1F ] C:\Windows\System32\BioCredProv.dll
    23:46:01.0365 4888 C:\Windows\System32\BioCredProv.dll - ok
    23:46:01.0367 4888 [ C98F6286818474AB284144A73EC7BA6D ] C:\Windows\System32\cngcredui.dll
    23:46:01.0367 4888 C:\Windows\System32\cngcredui.dll - ok
    23:46:01.0368 4888 [ 7FA8C13A62CAEB2D84A731030DC1B866 ] C:\Windows\System32\oleacc.dll
    23:46:01.0368 4888 C:\Windows\System32\oleacc.dll - ok
    23:46:01.0372 4888 [ CE0884D5E82E48F0959BEE3006BEA0E1 ] C:\Windows\System32\certCredProvider.dll
    23:46:01.0372 4888 C:\Windows\System32\certCredProvider.dll - ok
    23:46:01.0374 4888 [ 855D7BA4DC79E4157651FF5B23B41FD0 ] C:\Windows\System32\UIAnimation.dll
    23:46:01.0374 4888 C:\Windows\System32\UIAnimation.dll - ok
    23:46:01.0376 4888 [ 77DA2B3F012A1F0D88F29C612F606F28 ] C:\Windows\System32\winbio.dll
    23:46:01.0376 4888 C:\Windows\System32\winbio.dll - ok
    23:46:01.0378 4888 [ 1D03DD2BA438D4B3E1A0289738619056 ] C:\Windows\System32\wlidcredprov.dll
    23:46:01.0378 4888 C:\Windows\System32\wlidcredprov.dll - ok
    23:46:01.0380 4888 [ CEEFD29FC551F289810B0B9381B321DC ] C:\Windows\System32\Drivers\lltdio.sys
    23:46:01.0380 4888 C:\Windows\System32\Drivers\lltdio.sys - ok
    23:46:01.0381 4888 [ 43D7388A90A4C6EA346A4D6FF0377479 ] C:\Windows\System32\Drivers\nwifi.sys
    23:46:01.0381 4888 C:\Windows\System32\Drivers\nwifi.sys - ok
    23:46:01.0383 4888 [ 6E578460E165F14D9BA473ED54E3299B ] C:\Windows\System32\rasapi32.dll
    23:46:01.0383 4888 C:\Windows\System32\rasapi32.dll - ok
    23:46:01.0384 4888 [ EC7C1F9882A5E2F4C5391DDC43582110 ] C:\Windows\System32\rasplap.dll
    23:46:01.0384 4888 C:\Windows\System32\rasplap.dll - ok
    23:46:01.0386 4888 [ 4E251FE2729D6A3FCCC87DC13F823DC2 ] C:\Windows\System32\rtutils.dll
    23:46:01.0386 4888 C:\Windows\System32\rtutils.dll - ok
    23:46:01.0388 4888 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] C:\Windows\System32\Drivers\ndisuio.sys
    23:46:01.0388 4888 C:\Windows\System32\Drivers\ndisuio.sys - ok
    23:46:01.0390 4888 [ E04E770DD198B9399640717145E79EBF ] C:\Windows\System32\Drivers\rspndr.sys
    23:46:01.0390 4888 C:\Windows\System32\Drivers\rspndr.sys - ok
    23:46:01.0392 4888 [ 04A9D55BDCD79EBB2F32D91FE5946C28 ] C:\Windows\System32\IPHLPAPI.DLL
    23:46:01.0392 4888 C:\Windows\System32\IPHLPAPI.DLL - ok
    23:46:01.0394 4888 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] C:\Windows\System32\lmhsvc.dll
    23:46:01.0394 4888 C:\Windows\System32\lmhsvc.dll - ok
    23:46:01.0396 4888 [ F28C7A1A04C73FD099CBA2441B07842D ] C:\Windows\System32\nrpsrv.dll
    23:46:01.0396 4888 C:\Windows\System32\nrpsrv.dll - ok
    23:46:01.0397 4888 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] C:\Windows\System32\nsisvc.dll
    23:46:01.0398 4888 C:\Windows\System32\nsisvc.dll - ok
    23:46:01.0399 4888 [ 8C988C29CFB9B3673E882B4DA5EEC81D ] C:\Windows\System32\rasman.dll
    23:46:01.0399 4888 C:\Windows\System32\rasman.dll - ok
    23:46:01.0401 4888 [ D9C1E82651BF19C6FF69CEC6FD400124 ] C:\Windows\System32\wcmsvc.dll
    23:46:01.0401 4888 C:\Windows\System32\wcmsvc.dll - ok
    23:46:01.0403 4888 [ 0911A3B2DE545EA2498E560D745B7E71 ] C:\Windows\System32\winnsi.dll
    23:46:01.0403 4888 C:\Windows\System32\winnsi.dll - ok
    23:46:01.0405 4888 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] C:\Windows\System32\dhcpcore.dll
    23:46:01.0405 4888 C:\Windows\System32\dhcpcore.dll - ok
    23:46:01.0407 4888 [ ACB80C69E775A1EA1D0500CE8C72FD69 ] C:\Windows\System32\dhcpcore6.dll
  10. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    23:46:01.0407 4888 C:\Windows\System32\dhcpcore6.dll - ok
    23:46:01.0409 4888 [ 066B9710B36AB550E01EEFCA52155968 ] C:\Windows\System32\dnsrslvr.dll
    23:46:01.0409 4888 C:\Windows\System32\dnsrslvr.dll - ok
    23:46:01.0411 4888 [ 536198D1FACCF6C6F5A4D71E7EA70039 ] C:\Windows\System32\FWPUCLNT.DLL
    23:46:01.0411 4888 C:\Windows\System32\FWPUCLNT.DLL - ok
    23:46:01.0412 4888 [ 028A5E6B0ABDD7B2D32745C5F1D8F711 ] C:\Windows\System32\wcmcsp.dll
    23:46:01.0412 4888 C:\Windows\System32\wcmcsp.dll - ok
    23:46:01.0414 4888 [ 6351724B8FA0255C2DBD970297F00B93 ] C:\Windows\System32\wlansvc.dll
    23:46:01.0414 4888 C:\Windows\System32\wlansvc.dll - ok
    23:46:01.0417 4888 [ FA705724D337C7555FE22C0D4E93F790 ] C:\Windows\System32\atidxx64.dll
    23:46:01.0417 4888 C:\Windows\System32\atidxx64.dll - ok
    23:46:01.0419 4888 [ 297A16EB62460FF10506539AAC515527 ] C:\Windows\System32\atiuxp64.dll
    23:46:01.0419 4888 C:\Windows\System32\atiuxp64.dll - ok
    23:46:01.0421 4888 [ EB87F1EFE1376CE0283635563026F9E0 ] C:\Windows\System32\dhcpcsvc6.dll
    23:46:01.0421 4888 C:\Windows\System32\dhcpcsvc6.dll - ok
    23:46:01.0423 4888 [ 137BBCFB2080C5F6F4E5C4EB6314D97A ] C:\Windows\System32\dnsext.dll
    23:46:01.0423 4888 C:\Windows\System32\dnsext.dll - ok
    23:46:01.0425 4888 [ 72EC1DEF102304EE8C2E47566328F035 ] C:\Windows\System32\onex.dll
    23:46:01.0425 4888 C:\Windows\System32\onex.dll - ok
    23:46:01.0427 4888 [ 5DCBA1A3AE7150D2B71347BDD08639ED ] C:\Windows\System32\version.dll
    23:46:01.0427 4888 C:\Windows\System32\version.dll - ok
    23:46:01.0430 4888 [ 21E796CF2D1B8A6FAA2347B0070316CE ] C:\Windows\System32\winbrand.dll
    23:46:01.0430 4888 C:\Windows\System32\winbrand.dll - ok
    23:46:01.0432 4888 [ 7D6BDD2A339080EFA03D9EB39398F4E6 ] C:\Windows\System32\wlanmsm.dll
    23:46:01.0432 4888 C:\Windows\System32\wlanmsm.dll - ok
    23:46:01.0434 4888 [ 8341C75945D37A0CA7642A47B7E79260 ] C:\Windows\System32\dhcpcsvc.dll
    23:46:01.0434 4888 C:\Windows\System32\dhcpcsvc.dll - ok
    23:46:01.0435 4888 [ F2CDA4A446FD4BA2D8BAF456219C6964 ] C:\Windows\System32\UIAutomationCore.dll
    23:46:01.0435 4888 C:\Windows\System32\UIAutomationCore.dll - ok
    23:46:01.0437 4888 [ 14D785DFBE808D9CF7B8C06884730B1D ] C:\Windows\System32\wlansec.dll
    23:46:01.0437 4888 C:\Windows\System32\wlansec.dll - ok
    23:46:01.0439 4888 [ 6684C72C745F0E5E385EEAFF3C15538F ] C:\Windows\System32\eappprxy.dll
    23:46:01.0439 4888 C:\Windows\System32\eappprxy.dll - ok
    23:46:01.0441 4888 [ 36E419B92BFBF76438B8C0C4DD28B9E6 ] C:\Windows\System32\msxml6.dll
    23:46:01.0441 4888 C:\Windows\System32\msxml6.dll - ok
    23:46:01.0443 4888 [ D142894EBEFD276A5CFE876884A6E3F9 ] C:\Windows\System32\uDWM.dll
    23:46:01.0443 4888 C:\Windows\System32\uDWM.dll - ok
    23:46:01.0444 4888 [ A22411CA36466FC676D6805B3196726E ] C:\Windows\System32\samlib.dll
    23:46:01.0444 4888 C:\Windows\System32\samlib.dll - ok
    23:46:01.0446 4888 [ 103E609A08474C43C04FB064440FCAE7 ] C:\Windows\System32\shacct.dll
    23:46:01.0446 4888 C:\Windows\System32\shacct.dll - ok
    23:46:01.0448 4888 [ 2C71C009DFAC4C6EE7795C6C042090B4 ] C:\Windows\System32\slc.dll
    23:46:01.0448 4888 C:\Windows\System32\slc.dll - ok
    23:46:01.0450 4888 [ BA47A3E78521EC9EA4341F6FA8A75EC9 ] C:\Windows\System32\propsys.dll
    23:46:01.0450 4888 C:\Windows\System32\propsys.dll - ok
    23:46:01.0452 4888 [ 9C09F1D54C7F391B1C3D7440AF30720A ] C:\Windows\System32\InputSwitch.dll
    23:46:01.0452 4888 C:\Windows\System32\InputSwitch.dll - ok
    23:46:01.0454 4888 [ 193F8B5C8E94D2F4512868135CDB3B1A ] C:\Windows\System32\l2gpstore.dll
    23:46:01.0454 4888 C:\Windows\System32\l2gpstore.dll - ok
    23:46:01.0458 4888 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] C:\Windows\System32\shsvcs.dll
    23:46:01.0458 4888 C:\Windows\System32\shsvcs.dll - ok
    23:46:01.0460 4888 [ 53B518707ECB8132E173ADAF42D68054 ] C:\Windows\System32\Windows.UI.Immersive.dll
    23:46:01.0460 4888 C:\Windows\System32\Windows.UI.Immersive.dll - ok
    23:46:01.0462 4888 [ 047DB56D72FDC16114606B1A6576904B ] C:\Windows\System32\wlanapi.dll
    23:46:01.0462 4888 C:\Windows\System32\wlanapi.dll - ok
    23:46:01.0464 4888 [ D9AEEA13463C68BC9506342A7D15CBDA ] C:\Windows\System32\wlgpclnt.dll
    23:46:01.0464 4888 C:\Windows\System32\wlgpclnt.dll - ok
    23:46:01.0466 4888 [ DC774C3671FBD6FD176864AF0EBA404E ] C:\Windows\System32\d2d1.dll
    23:46:01.0466 4888 C:\Windows\System32\d2d1.dll - ok
    23:46:01.0467 4888 [ 04E866855FC3282BFEC25E8B6703FFEE ] C:\Windows\System32\netcfgx.dll
    23:46:01.0467 4888 C:\Windows\System32\netcfgx.dll - ok
    23:46:01.0469 4888 [ EDCDF4DB82EF825B94B190D544C8C58B ] C:\Windows\System32\schedsvc.dll
    23:46:01.0469 4888 C:\Windows\System32\schedsvc.dll - ok
    23:46:01.0471 4888 [ 59FB8ADC92BF41345BD0034F02187C0E ] C:\Windows\System32\wlanhlp.dll
    23:46:01.0471 4888 C:\Windows\System32\wlanhlp.dll - ok
    23:46:01.0473 4888 [ F9D935D60C397809FC6E1E0676F4AC6E ] C:\Windows\System32\wuaext.dll
    23:46:01.0473 4888 C:\Windows\System32\wuaext.dll - ok
    23:46:01.0474 4888 [ 3E5177CAE5C4325C49345B4D48626856 ] C:\Windows\System32\SubscriptionMgr.dll
    23:46:01.0474 4888 C:\Windows\System32\SubscriptionMgr.dll - ok
    23:46:01.0476 4888 [ F0E5C2AACB8DFD8EF2F7A67A12CCDA5D ] C:\Windows\System32\IDStore.dll
    23:46:01.0476 4888 C:\Windows\System32\IDStore.dll - ok
    23:46:01.0478 4888 [ 81ECD8768D3E4AD61DB7EE27401A25E9 ] C:\Windows\System32\wevtapi.dll
    23:46:01.0478 4888 C:\Windows\System32\wevtapi.dll - ok
    23:46:01.0480 4888 [ D058F369A791DD5B4DF8E7C18C0EB282 ] C:\Windows\System32\ktmw32.dll
    23:46:01.0480 4888 C:\Windows\System32\ktmw32.dll - ok
    23:46:01.0481 4888 [ 467497DF10CF8D4014BD25CCE987EA84 ] C:\Windows\System32\wcmapi.dll
    23:46:01.0481 4888 C:\Windows\System32\wcmapi.dll - ok
    23:46:01.0483 4888 [ 554F73A015A84FA8B5F23635FE016314 ] C:\Windows\System32\wlidres.dll
    23:46:01.0483 4888 C:\Windows\System32\wlidres.dll - ok
    23:46:01.0485 4888 [ 15E300200794A8FC38589B44A0B314D6 ] C:\Windows\System32\xmllite.dll
    23:46:01.0485 4888 C:\Windows\System32\xmllite.dll - ok
    23:46:01.0487 4888 [ 2640C2240F9B6529AE779D83E8FF2127 ] C:\Windows\System32\apphelp.dll
    23:46:01.0487 4888 C:\Windows\System32\apphelp.dll - ok
    23:46:01.0489 4888 [ F38DD05686AC8597BCD38C2F324900B9 ] C:\Windows\System32\AuthExt.dll
    23:46:01.0489 4888 C:\Windows\System32\AuthExt.dll - ok
    23:46:01.0491 4888 [ BC484B89C153942BF5D8BFBE832274E1 ] C:\Windows\System32\batmeter.dll
    23:46:01.0491 4888 C:\Windows\System32\batmeter.dll - ok
    23:46:01.0492 4888 [ EB4EE894AF86408776C6FD03376DEA29 ] C:\Windows\System32\fveapi.dll
    23:46:01.0492 4888 C:\Windows\System32\fveapi.dll - ok
    23:46:01.0494 4888 [ 8FF250BD9B3AC4D9D3F325570F901F36 ] C:\Windows\System32\fvecerts.dll
    23:46:01.0494 4888 C:\Windows\System32\fvecerts.dll - ok
    23:46:01.0496 4888 [ AA221DD533C7B0897B90B92AFFA45A7E ] C:\Windows\System32\taskcomp.dll
    23:46:01.0496 4888 C:\Windows\System32\taskcomp.dll - ok
    23:46:01.0498 4888 [ 29CB98187BB5711F7759540976D295FC ] C:\Windows\System32\Drivers\http.sys
    23:46:01.0498 4888 C:\Windows\System32\Drivers\http.sys - ok
    23:46:01.0499 4888 [ 406388E840C631E3C338F4E3551F791C ] C:\Windows\System32\ProximityCommon.dll
    23:46:01.0499 4888 C:\Windows\System32\ProximityCommon.dll - ok
    23:46:01.0501 4888 [ 599FCE13B819BA7D2D4D4E9C5AD08002 ] C:\Windows\System32\ProximityService.dll
    23:46:01.0501 4888 C:\Windows\System32\ProximityService.dll - ok
    23:46:01.0503 4888 [ 3F215BF2D4D8D6756298B25B579772C2 ] C:\Windows\System32\spoolsv.exe
    23:46:01.0503 4888 C:\Windows\System32\spoolsv.exe - ok
    23:46:01.0505 4888 [ 4A627D948C498368B2F65A5312455520 ] C:\Windows\System32\taskhost.exe
    23:46:01.0505 4888 C:\Windows\System32\taskhost.exe - ok
    23:46:01.0507 4888 [ 9E6A544F465C582AB42444A217CF04DC ] C:\Windows\System32\BFE.DLL
    23:46:01.0507 4888 C:\Windows\System32\BFE.DLL - ok
    23:46:01.0509 4888 [ B17AC10B47C7FCB44D22A1F06415840E ] C:\Windows\System32\Drivers\bowser.sys
    23:46:01.0509 4888 C:\Windows\System32\Drivers\bowser.sys - ok
    23:46:01.0511 4888 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] C:\Windows\System32\Drivers\mpsdrv.sys
    23:46:01.0511 4888 C:\Windows\System32\Drivers\mpsdrv.sys - ok
    23:46:01.0513 4888 [ 877D60D6E4156EC4A2E0B6871D41BED9 ] C:\Windows\System32\Drivers\mrxsmb.sys
    23:46:01.0513 4888 C:\Windows\System32\Drivers\mrxsmb.sys - ok
    23:46:01.0515 4888 [ 3031573A739DBEE8923851929D0AF423 ] C:\Windows\System32\MPSSVC.dll
    23:46:01.0515 4888 C:\Windows\System32\MPSSVC.dll - ok
    23:46:01.0516 4888 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] C:\Windows\System32\Drivers\mrxsmb10.sys
    23:46:01.0516 4888 C:\Windows\System32\Drivers\mrxsmb10.sys - ok
    23:46:01.0518 4888 [ E078446D4B8622AA6030C7B8A1A08962 ] C:\Windows\System32\Drivers\mrxsmb20.sys
    23:46:01.0518 4888 C:\Windows\System32\Drivers\mrxsmb20.sys - ok
    23:46:01.0520 4888 [ 581D88B25C4D4121824FED2CA38E562F ] C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    23:46:01.0520 4888 C:\Program Files\SUPERAntiSpyware\SASCore64.exe - ok
    23:46:01.0522 4888 [ D8F969B29E087A860156E4FFDB04138D ] C:\Windows\System32\adhapi.dll
    23:46:01.0522 4888 C:\Windows\System32\adhapi.dll - ok
    23:46:01.0524 4888 [ FF468871BC365B52AE650D422FEA21F5 ] C:\Windows\System32\wfapigp.dll
    23:46:01.0524 4888 C:\Windows\System32\wfapigp.dll - ok
    23:46:01.0526 4888 [ 16650912BE5A94B40E0B3B4C39652B56 ] C:\Windows\System32\wkssvc.dll
    23:46:01.0526 4888 C:\Windows\System32\wkssvc.dll - ok
    23:46:01.0528 4888 [ 4AFC14AFA58878FAA1D249E7E90EA54B ] C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    23:46:01.0528 4888 C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe - ok
    23:46:01.0530 4888 [ AB74105622BBE9EE069AC56666DBC696 ] C:\Windows\System32\Windows.Globalization.dll
    23:46:01.0530 4888 C:\Windows\System32\Windows.Globalization.dll - ok
    23:46:01.0532 4888 [ 0F38E5BAB0E4CEBB57987967F5505CD7 ] C:\Windows\SysWOW64\ntdll.dll
    23:46:01.0532 4888 C:\Windows\SysWOW64\ntdll.dll - ok
    23:46:01.0533 4888 [ ABE4B349D12138772B0D3B1B55C5F2A8 ] C:\Windows\System32\MrmCoreR.dll
    23:46:01.0533 4888 C:\Windows\System32\MrmCoreR.dll - ok
    23:46:01.0535 4888 [ 185C71A41C02724A56BA625578651817 ] C:\Windows\System32\NetworkStatus.dll
    23:46:01.0535 4888 C:\Windows\System32\NetworkStatus.dll - ok
    23:46:01.0537 4888 [ 1C5F50F98291B7545391BB57C406E615 ] C:\Windows\SysWOW64\kernel32.dll
    23:46:01.0537 4888 C:\Windows\SysWOW64\kernel32.dll - ok
    23:46:01.0539 4888 [ 5A3BF11D81C7F7EE8EDE9A2430B70878 ] C:\Windows\SysWOW64\KernelBase.dll
    23:46:01.0539 4888 C:\Windows\SysWOW64\KernelBase.dll - ok
    23:46:01.0541 4888 [ 42836D10270B1940F9A2FF77AE679537 ] C:\Program Files (x86)\AVG\AVG2013\avgntopensslx.dll
    23:46:01.0541 4888 C:\Program Files (x86)\AVG\AVG2013\avgntopensslx.dll - ok
    23:46:01.0543 4888 [ 5C32C180AB29655EFDFF6B7F91271775 ] C:\Windows\System32\msftedit.dll
    23:46:01.0543 4888 C:\Windows\System32\msftedit.dll - ok
    23:46:01.0545 4888 [ 484987420BC8DED2CB26C6F4EC9BA7F2 ] C:\Program Files (x86)\AVG\AVG2013\avgsysx.dll
    23:46:01.0545 4888 C:\Program Files (x86)\AVG\AVG2013\avgsysx.dll - ok
    23:46:01.0546 4888 [ BC83108B18756547013ED443B8CDB31B ] C:\Windows\SysWOW64\msvcp100.dll
    23:46:01.0546 4888 C:\Windows\SysWOW64\msvcp100.dll - ok
    23:46:01.0548 4888 [ 0E37FBFA79D349D672456923EC5FBBE3 ] C:\Windows\SysWOW64\msvcr100.dll
    23:46:01.0548 4888 C:\Windows\SysWOW64\msvcr100.dll - ok
    23:46:01.0550 4888 [ 47AC075FC4DE7DCF690E861B9B2C22A9 ] C:\Windows\System32\ninput.dll
    23:46:01.0550 4888 C:\Windows\System32\ninput.dll - ok
    23:46:01.0552 4888 [ BFEF608CD713A4CD3165D72E2AEB23F2 ] C:\Windows\SysWOW64\advapi32.dll
    23:46:01.0552 4888 C:\Windows\SysWOW64\advapi32.dll - ok
    23:46:01.0554 4888 [ BD483C1AE32D5B21A22CABE74A9D4798 ] C:\Windows\SysWOW64\IPHLPAPI.DLL
    23:46:01.0554 4888 C:\Windows\SysWOW64\IPHLPAPI.DLL - ok
    23:46:01.0556 4888 [ 3588D5D12FF7BFEBF2A4955C36B38EB0 ] C:\Windows\SysWOW64\psapi.dll
    23:46:01.0556 4888 C:\Windows\SysWOW64\psapi.dll - ok
    23:46:01.0558 4888 [ BA1C3ACD929A71E88B49C2B6E38F92B3 ] C:\Windows\SysWOW64\user32.dll
    23:46:01.0558 4888 C:\Windows\SysWOW64\user32.dll - ok
    23:46:01.0559 4888 [ 682C3D4982B5375732A4273809365A0A ] C:\Windows\SysWOW64\version.dll
    23:46:01.0559 4888 C:\Windows\SysWOW64\version.dll - ok
    23:46:01.0561 4888 [ 314E662DD78AF3F7766BA25162BEEEDA ] C:\Windows\SysWOW64\wininet.dll
    23:46:01.0561 4888 C:\Windows\SysWOW64\wininet.dll - ok
    23:46:01.0563 4888 [ B3CC9EDFD97F7087013A9A47089DF571 ] C:\Windows\SysWOW64\ws2_32.dll
    23:46:01.0563 4888 C:\Windows\SysWOW64\ws2_32.dll - ok
    23:46:01.0565 4888 [ F036DB9CF05B3C21405403FF074A78D9 ] C:\Program Files (x86)\AVG\AVG2013\avgopensslx.dll
    23:46:01.0565 4888 C:\Program Files (x86)\AVG\AVG2013\avgopensslx.dll - ok
    23:46:01.0567 4888 [ B59E9810F8A416B9E5354834F26969D4 ] C:\Windows\SysWOW64\msvcrt.dll
    23:46:01.0567 4888 C:\Windows\SysWOW64\msvcrt.dll - ok
    23:46:01.0568 4888 [ 1AFB56F8A39455ACBAB16A29A45C30AC ] C:\Windows\SysWOW64\nsi.dll
    23:46:01.0568 4888 C:\Windows\SysWOW64\nsi.dll - ok
    23:46:01.0570 4888 [ 77ADCD16CCEB8A9AD1FD81FC464B1A6B ] C:\Windows\SysWOW64\winnsi.dll
    23:46:01.0570 4888 C:\Windows\SysWOW64\winnsi.dll - ok
    23:46:01.0572 4888 [ 05DE4C1D408A5A2E599E2DA0F6B909ED ] C:\Windows\SysWOW64\gdi32.dll
    23:46:01.0572 4888 C:\Windows\SysWOW64\gdi32.dll - ok
    23:46:01.0574 4888 [ E64021308A378207B317A97950B47413 ] C:\Windows\SysWOW64\rpcrt4.dll
    23:46:01.0574 4888 C:\Windows\SysWOW64\rpcrt4.dll - ok
    23:46:01.0575 4888 [ 496E036F16467D7B7D12E0794E9FB85D ] C:\Windows\SysWOW64\sechost.dll
    23:46:01.0575 4888 C:\Windows\SysWOW64\sechost.dll - ok
    23:46:01.0577 4888 [ A202E73D2906E7093BC00444DF4D7784 ] C:\Windows\SysWOW64\iertutil.dll
    23:46:01.0577 4888 C:\Windows\SysWOW64\iertutil.dll - ok
    23:46:01.0579 4888 [ 7DFC3FCD0D5B7FC2F60C344BB384607C ] C:\Windows\SysWOW64\bcryptprimitives.dll
    23:46:01.0579 4888 C:\Windows\SysWOW64\bcryptprimitives.dll - ok
    23:46:01.0580 4888 [ 0D3C6E1A7EBD401F46E00EDBD61D1A72 ] C:\Windows\SysWOW64\cryptbase.dll
    23:46:01.0580 4888 C:\Windows\SysWOW64\cryptbase.dll - ok
    23:46:01.0582 4888 [ 39B721A0FB5F3E9880EE247F04012D8C ] C:\Windows\SysWOW64\sspicli.dll
    23:46:01.0582 4888 C:\Windows\SysWOW64\sspicli.dll - ok
    23:46:01.0584 4888 [ 1C2E1FC9F8ED794CC191E92F27D1391C ] C:\Program Files (x86)\AVG\AVG2013\avglogx.dll
    23:46:01.0584 4888 C:\Program Files (x86)\AVG\AVG2013\avglogx.dll - ok
    23:46:01.0586 4888 [ B40F5DCD59ED2A46EED8AE340CC167FB ] C:\Program Files (x86)\AVG\AVG2013\avgcfgx.dll
    23:46:01.0586 4888 C:\Program Files (x86)\AVG\AVG2013\avgcfgx.dll - ok
    23:46:01.0588 4888 [ A6251155B7017D4B4A77A3531A8DA6D8 ] C:\Program Files (x86)\AVG\AVG2013\avgcommx.dll
    23:46:01.0588 4888 C:\Program Files (x86)\AVG\AVG2013\avgcommx.dll - ok
    23:46:01.0590 4888 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    23:46:01.0590 4888 C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe - ok
    23:46:01.0592 4888 [ F0E78B119D12BA81F163D48C0FF30B9A ] C:\Windows\System32\cryptsvc.dll
    23:46:01.0592 4888 C:\Windows\System32\cryptsvc.dll - ok
    23:46:01.0594 4888 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] C:\Windows\System32\das.dll
    23:46:01.0594 4888 C:\Windows\System32\das.dll - ok
    23:46:01.0595 4888 [ 109FC3F80BF4F4DC5A071058074F13C1 ] C:\Windows\System32\dps.dll
    23:46:01.0595 4888 C:\Windows\System32\dps.dll - ok
    23:46:01.0597 4888 [ 7646E9DA362163D9C0F402F812EB1A0E ] C:\Windows\SysWOW64\shell32.dll
    23:46:01.0597 4888 C:\Windows\SysWOW64\shell32.dll - ok
    23:46:01.0599 4888 [ 3C5846581F329FD6768E5E7C1780151E ] C:\Windows\System32\cryptcatsvc.dll
    23:46:01.0599 4888 C:\Windows\System32\cryptcatsvc.dll - ok
    23:46:01.0600 4888 [ 57616A5583E6406F88BC71A5A5E0C165 ] C:\Program Files (x86)\AVG\AVG2013\avgwd.dll
    23:46:01.0600 4888 C:\Program Files (x86)\AVG\AVG2013\avgwd.dll - ok
    23:46:01.0602 4888 [ B278B76FF26BE911DD369724612F2D03 ] C:\Windows\System32\dasHost.exe
    23:46:01.0603 4888 C:\Windows\System32\dasHost.exe - ok
    23:46:01.0605 4888 [ 9C2CB23B77E539D87B4652FA68A6C275 ] C:\Windows\System32\vssapi.dll
    23:46:01.0605 4888 C:\Windows\System32\vssapi.dll - ok
    23:46:01.0608 4888 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    23:46:01.0608 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe - ok
    23:46:01.0610 4888 [ 5579A2CE7756B59F4BB778AFDCAF2096 ] C:\Windows\System32\vsstrace.dll
    23:46:01.0610 4888 C:\Windows\System32\vsstrace.dll - ok
    23:46:01.0611 4888 [ 8624E0E2418413614EE1FECDB7B76B88 ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll
    23:46:01.0611 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll - ok
    23:46:01.0613 4888 [ 6ADA7F192919DD51930A73F364129433 ] C:\Windows\SysWOW64\ole32.dll
    23:46:01.0613 4888 C:\Windows\SysWOW64\ole32.dll - ok
    23:46:01.0615 4888 [ EA35B404D87B3A61E7A5FBF6CDA1CF94 ] C:\Windows\SysWOW64\oleaut32.dll
    23:46:01.0615 4888 C:\Windows\SysWOW64\oleaut32.dll - ok
    23:46:01.0618 4888 [ D4467A285C91752018F67CDBA8680BAB ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll
    23:46:01.0618 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll - ok
    23:46:01.0620 4888 [ 828CFD406E60311A9E5414685FA7EEDF ] C:\Windows\SysWOW64\combase.dll
    23:46:01.0620 4888 C:\Windows\SysWOW64\combase.dll - ok
    23:46:01.0621 4888 [ B8ECF8A56EEF75468F9ABFECE70AF555 ] C:\Windows\SysWOW64\shlwapi.dll
    23:46:01.0622 4888 C:\Windows\SysWOW64\shlwapi.dll - ok
    23:46:01.0624 4888 [ 76FFA2433FEB42E78FB5421A50C8FBE3 ] C:\Program Files (x86)\AVG\AVG2013\avgclitx.dll
    23:46:01.0624 4888 C:\Program Files (x86)\AVG\AVG2013\avgclitx.dll - ok
    23:46:01.0626 4888 [ C7874A3B4C4FD56CB80FA4F2A02232FD ] C:\Program Files (x86)\AVG\AVG2013\avgcorex.dll
    23:46:01.0626 4888 C:\Program Files (x86)\AVG\AVG2013\avgcorex.dll - ok
    23:46:01.0628 4888 [ 7BB3FE507D7143CD54293DA3FB5DF3AB ] C:\Windows\SysWOW64\crypt32.dll
    23:46:01.0628 4888 C:\Windows\SysWOW64\crypt32.dll - ok
    23:46:01.0630 4888 [ 58EE457D0D49A95A1E981F6F67FB560F ] C:\Windows\SysWOW64\userenv.dll
    23:46:01.0630 4888 C:\Windows\SysWOW64\userenv.dll - ok
    23:46:01.0632 4888 [ 715A1F4D2A064DA1DDCAC2533FAF780F ] C:\Windows\SysWOW64\wtsapi32.dll
    23:46:01.0632 4888 C:\Windows\SysWOW64\wtsapi32.dll - ok
    23:46:01.0633 4888 [ 9E30B21B14FB24C383AC255BDFA47E0E ] C:\Program Files (x86)\AVG\AVG2013\avgsecapix.dll
    23:46:01.0634 4888 C:\Program Files (x86)\AVG\AVG2013\avgsecapix.dll - ok
    23:46:01.0635 4888 [ AFAACBE85092FBD8EE7F54CA7FF3F0F1 ] C:\Windows\SysWOW64\msasn1.dll
    23:46:01.0635 4888 C:\Windows\SysWOW64\msasn1.dll - ok
    23:46:01.0636 4888 [ 7D2306701584AE7B77B8622314B55F78 ] C:\Windows\SysWOW64\profapi.dll
    23:46:01.0636 4888 C:\Windows\SysWOW64\profapi.dll - ok
    23:46:01.0638 4888 [ 7D20883F79FF846AEE49678238BE8A7A ] C:\Windows\SysWOW64\cryptsp.dll
    23:46:01.0638 4888 C:\Windows\SysWOW64\cryptsp.dll - ok
    23:46:01.0640 4888 [ 85F7AFD9C7DFD6824BAFDC5E5D7D4E86 ] C:\Windows\SysWOW64\SHCore.dll
    23:46:01.0640 4888 C:\Windows\SysWOW64\SHCore.dll - ok
    23:46:01.0642 4888 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    23:46:01.0642 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe - ok
    23:46:01.0644 4888 [ 95EFDCB44DD093EDAD447F1D21C8A3F7 ] C:\Program Files (x86)\AVG\AVG2013\avgcertx.dll
    23:46:01.0644 4888 C:\Program Files (x86)\AVG\AVG2013\avgcertx.dll - ok
    23:46:01.0646 4888 [ 6F19639188F792BBB234B2A3FCB0C8C9 ] C:\Program Files (x86)\AVG\AVG2013\avgchclx.dll
    23:46:01.0646 4888 C:\Program Files (x86)\AVG\AVG2013\avgchclx.dll - ok
    23:46:01.0648 4888 [ 46211947C1F1953B74C33FC80ECD3C6A ] C:\Windows\SysWOW64\rsaenh.dll
    23:46:01.0648 4888 C:\Windows\SysWOW64\rsaenh.dll - ok
    23:46:01.0649 4888 [ C28F010F8C6AB4341749E2DEDEAC5D06 ] C:\Windows\SysWOW64\wintrust.dll
    23:46:01.0649 4888 C:\Windows\SysWOW64\wintrust.dll - ok
    23:46:01.0651 4888 [ F820B93E4ABCCABD698A175FD5FC83FE ] C:\Program Files (x86)\AVG\AVG2013\avgntsqlitex.dll
    23:46:01.0651 4888 C:\Program Files (x86)\AVG\AVG2013\avgntsqlitex.dll - ok
    23:46:01.0653 4888 [ 491918E4C46ED4CEB6E7A90F7B73924D ] C:\Program Files (x86)\AVG\AVG2013\avgxpl.dll
    23:46:01.0653 4888 C:\Program Files (x86)\AVG\AVG2013\avgxpl.dll - ok
    23:46:01.0655 4888 [ DDF8C39C085D2E98BD030B3E8A1F40B8 ] C:\Windows\SysWOW64\secur32.dll
    23:46:01.0655 4888 C:\Windows\SysWOW64\secur32.dll - ok
    23:46:01.0657 4888 [ 5DDEA740B911D4E910AC031090183E6A ] C:\Windows\SysWOW64\sfc.dll
    23:46:01.0657 4888 C:\Windows\SysWOW64\sfc.dll - ok
    23:46:01.0658 4888 [ 0313A5DFA5966E31220C26A6167FD479 ] C:\Windows\SysWOW64\sfc_os.dll
    23:46:01.0658 4888 C:\Windows\SysWOW64\sfc_os.dll - ok
    23:46:01.0660 4888 [ ECC6D7B772AC59E2717B4A70A742EC5D ] C:\Windows\SysWOW64\wevtapi.dll
    23:46:01.0660 4888 C:\Windows\SysWOW64\wevtapi.dll - ok
    23:46:01.0662 4888 [ 4BE1DCAD76BE96D1EC887A41E570C404 ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.dll
    23:46:01.0662 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.dll - ok
    23:46:01.0664 4888 [ 567612D556BBC4FC98169EA98F6EA480 ] C:\Windows\SysWOW64\cfgmgr32.dll
    23:46:01.0664 4888 C:\Windows\SysWOW64\cfgmgr32.dll - ok
    23:46:01.0666 4888 [ 785838B984563D12D4612256D2C78B48 ] C:\Windows\SysWOW64\mpr.dll
    23:46:01.0666 4888 C:\Windows\SysWOW64\mpr.dll - ok
    23:46:01.0668 4888 [ F67480EE1AC3CB32C63AF86B0AE57AC9 ] C:\Program Files (x86)\AVG\AVG2013\avgwdwsc.dll
    23:46:01.0668 4888 C:\Program Files (x86)\AVG\AVG2013\avgwdwsc.dll - ok
    23:46:01.0670 4888 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] C:\Windows\System32\Drivers\Ndu.sys
    23:46:01.0670 4888 C:\Windows\System32\Drivers\Ndu.sys - ok
    23:46:01.0672 4888 [ 70DBB6A8B52B3830922F1C5789E1BEEB ] C:\Windows\System32\Drivers\PEAuth.sys
    23:46:01.0672 4888 C:\Windows\System32\Drivers\PEAuth.sys - ok
    23:46:01.0674 4888 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] C:\Windows\System32\nlasvc.dll
    23:46:01.0674 4888 C:\Windows\System32\nlasvc.dll - ok
    23:46:01.0676 4888 [ 4811D9EC53649105A5A8BEA661B0F936 ] C:\Windows\System32\pcasvc.dll
    23:46:01.0676 4888 C:\Windows\System32\pcasvc.dll - ok
    23:46:01.0678 4888 [ 1580A33C6CD8E0117247A48C31825D6E ] C:\Windows\System32\aepic.dll
    23:46:01.0678 4888 C:\Windows\System32\aepic.dll - ok
    23:46:01.0679 4888 [ D47794FC9B672034F4932B47016A4998 ] C:\Windows\System32\ncsi.dll
    23:46:01.0679 4888 C:\Windows\System32\ncsi.dll - ok
    23:46:01.0681 4888 [ BA0231EEEED894158F22FBE5CDCD32CB ] C:\Windows\SysWOW64\wscapi.dll
    23:46:01.0681 4888 C:\Windows\SysWOW64\wscapi.dll - ok
    23:46:01.0683 4888 [ 206387AB881E93A1A6EB89966C8651F1 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    23:46:01.0683 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe - ok
    23:46:01.0685 4888 [ C954FE5796A0BFCDCDD8A9C210E9D2C3 ] C:\Windows\System32\sfc_os.dll
    23:46:01.0685 4888 C:\Windows\System32\sfc_os.dll - ok
    23:46:01.0687 4888 [ 7911470B6018059A880469A63B65700A ] C:\Windows\System32\winhttp.dll
    23:46:01.0687 4888 C:\Windows\System32\winhttp.dll - ok
    23:46:01.0689 4888 [ 26F0D5C6F38FFDE13E46F028CE12AFA5 ] C:\Windows\SysWOW64\urlmon.dll
    23:46:01.0689 4888 C:\Windows\SysWOW64\urlmon.dll - ok
    23:46:01.0691 4888 [ 4C867B62F6100C107A3A8F5E7A10461D ] C:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl
    23:46:01.0691 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl - ok
    23:46:01.0692 4888 [ 5858AA1B5AF20C37B186971A21460A4E ] C:\Windows\System32\ssdpapi.dll
    23:46:01.0692 4888 C:\Windows\System32\ssdpapi.dll - ok
    23:46:01.0694 4888 [ 2FC6C98A23864B2E50E53B4848939EAF ] C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
    23:46:01.0694 4888 C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe - ok
    23:46:01.0696 4888 [ 62F46FB1AED31B289F6A64718A3E5ECF ] C:\Windows\SysWOW64\clbcatq.dll
    23:46:01.0696 4888 C:\Windows\SysWOW64\clbcatq.dll - ok
    23:46:01.0698 4888 [ 5192F9A06BC32684ADF938EE16E118D9 ] C:\Windows\SysWOW64\ntmarta.dll
    23:46:01.0698 4888 C:\Windows\SysWOW64\ntmarta.dll - ok
    23:46:01.0699 4888 [ FF0602E28D69B977F889D435F902545E ] C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
    23:46:01.0699 4888 C:\Program Files (x86)\AVG\AVG2013\avgemca.exe - ok
    23:46:01.0702 4888 [ D9AF104F7E21FA859EFA3C67E5522E88 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\vcl150.bpl
    23:46:01.0702 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\vcl150.bpl - ok
    23:46:01.0704 4888 [ 2BD1447ECF8A9697AFCF4D7C71D45AA7 ] C:\Windows\SysWOW64\wbem\wbemprox.dll
    23:46:01.0704 4888 C:\Windows\SysWOW64\wbem\wbemprox.dll - ok
    23:46:01.0706 4888 [ 83C4E13852335E1EAC12AA62A2F01E52 ] C:\Windows\SysWOW64\winsta.dll
    23:46:01.0706 4888 C:\Windows\SysWOW64\winsta.dll - ok
    23:46:01.0708 4888 [ 366FD6F3A451351B5DF2D7C4ECF4C73A ] C:\Windows\System32\msvcr100.dll
    23:46:01.0709 4888 C:\Windows\System32\msvcr100.dll - ok
    23:46:01.0710 4888 [ FA0672B09ED377939BB9F3D39895B404 ] C:\Windows\SysWOW64\wbemcomn.dll
    23:46:01.0710 4888 C:\Windows\SysWOW64\wbemcomn.dll - ok
    23:46:01.0712 4888 [ 105ED75F4CEE9E58152061520DAA4ABD ] C:\Program Files (x86)\Spybot - Search & Destroy 2\Jcl150.bpl
  11. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    23:46:01.0713 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\Jcl150.bpl - ok
    23:46:01.0715 4888 [ 8622AE563E2AC2F8BF9FAFEE726FC7B8 ] C:\Program Files (x86)\AVG\AVG2013\avgsched.dll
    23:46:01.0715 4888 C:\Program Files (x86)\AVG\AVG2013\avgsched.dll - ok
    23:46:01.0716 4888 [ 76ACCC871C2A021BBC9A8B292244D0EC ] C:\Program Files (x86)\AVG\AVG2013\avgcfga.dll
    23:46:01.0716 4888 C:\Program Files (x86)\AVG\AVG2013\avgcfga.dll - ok
    23:46:01.0718 4888 [ FF9AFBD2864BBEA6A9E7F90F8C94F6B7 ] C:\Program Files (x86)\AVG\AVG2013\avgidpsdkx.dll
    23:46:01.0718 4888 C:\Program Files (x86)\AVG\AVG2013\avgidpsdkx.dll - ok
    23:46:01.0721 4888 [ A9BEAEE40D353F85D213BB46F54EBBED ] C:\Program Files (x86)\AVG\AVG2013\avgkrnlapia.dll
    23:46:01.0721 4888 C:\Program Files (x86)\AVG\AVG2013\avgkrnlapia.dll - ok
    23:46:01.0723 4888 [ 0FDABB1FD68CBC557084E16B0EA2F731 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\snlBase150.bpl
    23:46:01.0723 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\snlBase150.bpl - ok
    23:46:01.0726 4888 [ 7320560F4A6FA26EC432D0E4AFE6112F ] C:\Windows\SysWOW64\SensApi.dll
    23:46:01.0726 4888 C:\Windows\SysWOW64\SensApi.dll - ok
    23:46:01.0728 4888 [ FA27F4DF4015B22F04B5D18044A24322 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    23:46:01.0728 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl - ok
    23:46:01.0730 4888 [ 86E99E1222E671408ED5E8618521AEEB ] C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    23:46:01.0730 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl - ok
    23:46:01.0732 4888 [ 9244E0240A1D150581C3BAA89D8AA154 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    23:46:01.0732 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl - ok
    23:46:01.0734 4888 [ 8964E7F65751FEC4185285E3329EADE6 ] C:\Program Files (x86)\AVG\AVG2013\avgsecapia.dll
    23:46:01.0734 4888 C:\Program Files (x86)\AVG\AVG2013\avgsecapia.dll - ok
    23:46:01.0736 4888 [ 14361FB2FD630988816A4F46AEAF0684 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
    23:46:01.0736 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll - ok
    23:46:01.0738 4888 [ FF3AA70595B26BD3DC0DDB00B90B1B57 ] C:\Windows\SysWOW64\imagehlp.dll
    23:46:01.0738 4888 C:\Windows\SysWOW64\imagehlp.dll - ok
    23:46:01.0740 4888 [ 5C96F30D1144AB5D8F03DFF045B8C791 ] C:\Windows\SysWOW64\netapi32.dll
    23:46:01.0740 4888 C:\Windows\SysWOW64\netapi32.dll - ok
    23:46:01.0742 4888 [ 7A3B96DE45ED3AB1B6BAA1D0B7B9869B ] C:\Windows\SysWOW64\comctl32.dll
    23:46:01.0742 4888 C:\Windows\SysWOW64\comctl32.dll - ok
    23:46:01.0744 4888 [ 6FA9D09428E56C11E01066CAF2FB5031 ] C:\Windows\SysWOW64\msimg32.dll
    23:46:01.0744 4888 C:\Windows\SysWOW64\msimg32.dll - ok
    23:46:01.0745 4888 [ 41E843174754F87D86EF0FBF7F60DB0D ] C:\Windows\SysWOW64\oleacc.dll
    23:46:01.0745 4888 C:\Windows\SysWOW64\oleacc.dll - ok
    23:46:01.0747 4888 [ 42FF7DC63C1CB122CE2C8061B5FE4390 ] C:\Windows\SysWOW64\shfolder.dll
    23:46:01.0747 4888 C:\Windows\SysWOW64\shfolder.dll - ok
    23:46:01.0749 4888 [ A2B03204078BBB32CDD3AF779717FCC4 ] C:\Windows\SysWOW64\wsock32.dll
    23:46:01.0749 4888 C:\Windows\SysWOW64\wsock32.dll - ok
    23:46:01.0750 4888 [ C2C86942ED94D1CD81F61BEFB3036AF6 ] C:\Windows\SysWOW64\comdlg32.dll
    23:46:01.0750 4888 C:\Windows\SysWOW64\comdlg32.dll - ok
    23:46:01.0752 4888 [ F6104D2DBF254FE23928F978F6CABE35 ] C:\Windows\SysWOW64\oledlg.dll
    23:46:01.0752 4888 C:\Windows\SysWOW64\oledlg.dll - ok
    23:46:01.0754 4888 [ 8E902EE869004D40F350C02C4E63B0CA ] C:\Windows\SysWOW64\winmm.dll
    23:46:01.0754 4888 C:\Windows\SysWOW64\winmm.dll - ok
    23:46:01.0757 4888 [ 4F583ABEF86D3B9DD2C0D24C9E41138E ] C:\Windows\SysWOW64\winspool.drv
    23:46:01.0757 4888 C:\Windows\SysWOW64\winspool.drv - ok
    23:46:01.0759 4888 [ 7FFC244DFE77909A13F52CF54B1FE475 ] C:\Windows\SysWOW64\netutils.dll
    23:46:01.0759 4888 C:\Windows\SysWOW64\netutils.dll - ok
    23:46:01.0761 4888 [ C3CD50F19851FB3DB7A9418B32E1FEC1 ] C:\Windows\SysWOW64\samcli.dll
    23:46:01.0761 4888 C:\Windows\SysWOW64\samcli.dll - ok
    23:46:01.0763 4888 [ D8533AF2AAE712047A3CCAC9AC98EDC4 ] C:\Windows\SysWOW64\srvcli.dll
    23:46:01.0763 4888 C:\Windows\SysWOW64\srvcli.dll - ok
    23:46:01.0765 4888 [ 5C539C92A7704C80EDB45BFD8D7F600F ] C:\Windows\SysWOW64\winmmbase.dll
    23:46:01.0765 4888 C:\Windows\SysWOW64\winmmbase.dll - ok
    23:46:01.0767 4888 [ 182DD861AD25CD72AE6F3B54AE7AA8AD ] C:\Windows\SysWOW64\wkscli.dll
    23:46:01.0767 4888 C:\Windows\SysWOW64\wkscli.dll - ok
    23:46:01.0768 4888 [ 51E886381803D55926A6D50643B9436C ] C:\Windows\SysWOW64\imm32.dll
    23:46:01.0768 4888 C:\Windows\SysWOW64\imm32.dll - ok
    23:46:01.0770 4888 [ 69229810EB42C6FA2BAA298E02A043E1 ] C:\Windows\SysWOW64\msctf.dll
    23:46:01.0770 4888 C:\Windows\SysWOW64\msctf.dll - ok
    23:46:01.0772 4888 [ 024B76FAD711EFECD6DD0FBD87265444 ] C:\Windows\SysWOW64\setupapi.dll
    23:46:01.0772 4888 C:\Windows\SysWOW64\setupapi.dll - ok
    23:46:01.0773 4888 [ B2A25F2C3DCCD9858701E0AF13E5EE4D ] C:\Windows\SysWOW64\devobj.dll
    23:46:01.0773 4888 C:\Windows\SysWOW64\devobj.dll - ok
    23:46:01.0776 4888 [ BFDD523AB06AB9932B6327E52C6E9AE6 ] C:\Windows\SysWOW64\propsys.dll
    23:46:01.0776 4888 C:\Windows\SysWOW64\propsys.dll - ok
    23:46:01.0778 4888 [ 27D5372C6D1657C586AE0A3E06D1B7E3 ] C:\Windows\SysWOW64\jsproxy.dll
    23:46:01.0778 4888 C:\Windows\SysWOW64\jsproxy.dll - ok
    23:46:01.0779 4888 [ 4E743FA4D61A2EF8CA1642F49DC4784D ] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985\comctl32.dll
    23:46:01.0780 4888 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985\comctl32.dll - ok
    23:46:01.0782 4888 [ C317E72447B437F99CC750BD876DF30E ] C:\Windows\SysWOW64\mswsock.dll
    23:46:01.0782 4888 C:\Windows\SysWOW64\mswsock.dll - ok
    23:46:01.0784 4888 [ 7A4797475ABAD6ECF1BCB08637922ECA ] C:\Windows\SysWOW64\winhttp.dll
    23:46:01.0784 4888 C:\Windows\SysWOW64\winhttp.dll - ok
    23:46:01.0786 4888 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] C:\Program Files (x86)\Skype\Updater\Updater.exe
    23:46:01.0786 4888 C:\Program Files (x86)\Skype\Updater\Updater.exe - ok
    23:46:01.0788 4888 [ 3EA8A16169C26AFBEB544E0E48421186 ] C:\Windows\System32\Drivers\secdrv.sys
    23:46:01.0788 4888 C:\Windows\System32\Drivers\secdrv.sys - ok
    23:46:01.0790 4888 [ CD282626738B6BC92B6E7CD0AAE95B63 ] C:\Windows\System32\seclogon.dll
    23:46:01.0790 4888 C:\Windows\System32\seclogon.dll - ok
    23:46:01.0792 4888 [ 84F0DC88E6AE4B49B032509868B4BD73 ] C:\Windows\SysWOW64\dhcpcsvc.dll
    23:46:01.0792 4888 C:\Windows\SysWOW64\dhcpcsvc.dll - ok
    23:46:01.0793 4888 [ 0F3B2F57676DEBB7F86B74A51BEC079C ] C:\Windows\SysWOW64\dhcpcsvc6.dll
    23:46:01.0793 4888 C:\Windows\SysWOW64\dhcpcsvc6.dll - ok
    23:46:01.0795 4888 [ 9400C71F5A1A380B494B6922F007D485 ] C:\Windows\System32\Drivers\srvnet.sys
    23:46:01.0795 4888 C:\Windows\System32\Drivers\srvnet.sys - ok
    23:46:01.0797 4888 [ 7090C3C7CE14F6EEBE5C0AFE1A7C32A5 ] C:\Program Files (x86)\AVG\AVG2013\winamapix.dll
    23:46:01.0797 4888 C:\Program Files (x86)\AVG\AVG2013\winamapix.dll - ok
    23:46:01.0799 4888 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] C:\Windows\System32\Drivers\tcpipreg.sys
    23:46:01.0799 4888 C:\Windows\System32\Drivers\tcpipreg.sys - ok
    23:46:01.0800 4888 [ DC21E1F06343773D7E24362DCEF7944B ] C:\Windows\System32\sysmain.dll
    23:46:01.0800 4888 C:\Windows\System32\sysmain.dll - ok
    23:46:01.0802 4888 [ 3D6B518B71C75C8FA4115A33615C107A ] C:\Windows\System32\wbem\WMIsvc.dll
    23:46:01.0802 4888 C:\Windows\System32\wbem\WMIsvc.dll - ok
    23:46:01.0804 4888 [ BAC8A721736AECC55A4F71523AEAB65F ] C:\Windows\System32\wiaservc.dll
    23:46:01.0804 4888 C:\Windows\System32\wiaservc.dll - ok
    23:46:01.0806 4888 [ 21CA3869D0EA99C902B26ED697BD78E5 ] C:\Windows\System32\wbemcomn.dll
    23:46:01.0806 4888 C:\Windows\System32\wbemcomn.dll - ok
    23:46:01.0808 4888 [ 4B968083851285996B465FFDCB5AE9E8 ] C:\Windows\SysWOW64\FWPUCLNT.DLL
    23:46:01.0808 4888 C:\Windows\SysWOW64\FWPUCLNT.DLL - ok
    23:46:01.0810 4888 [ A529CFE32565C0B145578FFB2B32C9A5 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    23:46:01.0810 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe - ok
    23:46:01.0812 4888 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] C:\Windows\System32\trkwks.dll
    23:46:01.0812 4888 C:\Windows\System32\trkwks.dll - ok
    23:46:01.0814 4888 [ 2935B83ADDED04242622580091251474 ] C:\Windows\System32\wiatrace.dll
    23:46:01.0814 4888 C:\Windows\System32\wiatrace.dll - ok
    23:46:01.0816 4888 [ 6A0C81508755C7F8EA5C5A4BC0E922CB ] C:\Windows\SysWOW64\apphelp.dll
    23:46:01.0816 4888 C:\Windows\SysWOW64\apphelp.dll - ok
    23:46:01.0818 4888 [ 735D4C58ADC1F4DE5A59850078910218 ] C:\Windows\System32\wbem\wbemcore.dll
    23:46:01.0818 4888 C:\Windows\System32\wbem\wbemcore.dll - ok
    23:46:01.0820 4888 [ CCBFC667F7D9FF80C560EA378C1B5F3E ] C:\Windows\apppatch\AcGenral.dll
    23:46:01.0820 4888 C:\Windows\apppatch\AcGenral.dll - ok
    23:46:01.0823 4888 [ E54F732758B5BB7405C2F4E05A64D6E1 ] C:\Windows\System32\wbem\esscli.dll
    23:46:01.0823 4888 C:\Windows\System32\wbem\esscli.dll - ok
    23:46:01.0825 4888 [ 508F0DE3A65183A3D7ADF4C1F20E9696 ] C:\Windows\System32\PortableDeviceWiaCompat.dll
    23:46:01.0825 4888 C:\Windows\System32\PortableDeviceWiaCompat.dll - ok
    23:46:01.0826 4888 [ 19304E66115DD1400182211B4FD7E73A ] C:\Windows\System32\wbem\fastprox.dll
    23:46:01.0827 4888 C:\Windows\System32\wbem\fastprox.dll - ok
    23:46:01.0828 4888 [ D07CDFA0320605FC429D5C54D89DC925 ] C:\Windows\SysWOW64\uxtheme.dll
    23:46:01.0828 4888 C:\Windows\SysWOW64\uxtheme.dll - ok
    23:46:01.0829 4888 [ 9B7280BAF510CE8AA3E712BC63EE50E3 ] C:\Windows\System32\wbem\wbemsvc.dll
    23:46:01.0829 4888 C:\Windows\System32\wbem\wbemsvc.dll - ok
    23:46:01.0831 4888 [ 8F625E3E627BC99823E7E168A9AB5625 ] C:\Windows\System32\wsdchngr.dll
    23:46:01.0831 4888 C:\Windows\System32\wsdchngr.dll - ok
    23:46:01.0833 4888 [ F082773EF130B7293E0F6D64B962A118 ] C:\Windows\System32\deviceassociation.dll
    23:46:01.0833 4888 C:\Windows\System32\deviceassociation.dll - ok
    23:46:01.0835 4888 [ E4A6D4B0E58231488F3BB32A24995D85 ] C:\Windows\SysWOW64\msacm32.dll
    23:46:01.0835 4888 C:\Windows\SysWOW64\msacm32.dll - ok
    23:46:01.0837 4888 [ 7139C54E7282804745F9991F588FE506 ] C:\Windows\SysWOW64\wbem\wbemsvc.dll
    23:46:01.0837 4888 C:\Windows\SysWOW64\wbem\wbemsvc.dll - ok
    23:46:01.0839 4888 [ 47E892006A6155BE617F526E02CA09DD ] C:\Windows\System32\fundisc.dll
    23:46:01.0839 4888 C:\Windows\System32\fundisc.dll - ok
    23:46:01.0842 4888 [ 992BD101F370B0D93A1131227BA342F6 ] C:\Windows\SysWOW64\wbem\fastprox.dll
    23:46:01.0842 4888 C:\Windows\SysWOW64\wbem\fastprox.dll - ok
    23:46:01.0843 4888 [ 64F6AFD2F4F8D0DB5B8770EC59103778 ] C:\Windows\System32\PortableDeviceApi.dll
    23:46:01.0843 4888 C:\Windows\System32\PortableDeviceApi.dll - ok
    23:46:01.0845 4888 [ 341ADCBB9A744F559C3CF3CA5D3D8934 ] C:\Windows\SysWOW64\dwmapi.dll
    23:46:01.0845 4888 C:\Windows\SysWOW64\dwmapi.dll - ok
    23:46:01.0847 4888 [ E24FCC199F4AD27289ACEC15D8A6740C ] C:\Windows\System32\fdPnp.dll
    23:46:01.0847 4888 C:\Windows\System32\fdPnp.dll - ok
    23:46:01.0849 4888 [ 616285E00B6B7F2DE84891F6D094528B ] C:\Windows\System32\wbem\repdrvfs.dll
    23:46:01.0849 4888 C:\Windows\System32\wbem\repdrvfs.dll - ok
    23:46:01.0850 4888 [ 4811A86C4CA6EDC58D316A29E56629F6 ] C:\Windows\System32\wbem\wmiutils.dll
    23:46:01.0850 4888 C:\Windows\System32\wbem\wmiutils.dll - ok
    23:46:01.0852 4888 [ E6C7752237B3A615A190D9EE23ECF152 ] C:\Windows\System32\wbem\WmiPrvSD.dll
    23:46:01.0852 4888 C:\Windows\System32\wbem\WmiPrvSD.dll - ok
    23:46:01.0854 4888 [ 54482D83FF8501A46BB0B349FED0DAEB ] C:\Windows\System32\ncobjapi.dll
    23:46:01.0854 4888 C:\Windows\System32\ncobjapi.dll - ok
    23:46:01.0856 4888 [ C6B60D86B37D1C10AF7E7764D74D9194 ] C:\Windows\apppatch\AcLayers.dll
    23:46:01.0856 4888 C:\Windows\apppatch\AcLayers.dll - ok
    23:46:01.0858 4888 [ E296B0D7842DD5478605B6C86573E52F ] C:\Windows\System32\wbem\wbemess.dll
    23:46:01.0858 4888 C:\Windows\System32\wbem\wbemess.dll - ok
    23:46:01.0860 4888 [ 0EFCE333980CA8C9CC7C13D067EB80AF ] C:\Windows\SysWOW64\cabinet.dll
    23:46:01.0861 4888 C:\Windows\SysWOW64\cabinet.dll - ok
    23:46:01.0864 4888 [ D21AB32F16E8DE67D45E5A383B5E52BA ] C:\Program Files (x86)\Spybot - Search & Destroy 2\ssleay32.dll
    23:46:01.0864 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\ssleay32.dll - ok
    23:46:01.0866 4888 [ B009D6171147BE129636A49C4178E487 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\libeay32.dll
    23:46:01.0866 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\libeay32.dll - ok
    23:46:01.0869 4888 [ F1F9EEEF647CFA62A7104C054CE0999B ] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_50944e7cbcb706e5\msvcr90.dll
    23:46:01.0869 4888 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_50944e7cbcb706e5\msvcr90.dll - ok
    23:46:01.0871 4888 [ C2106BB710AA34A046126AED7BCA6964 ] C:\Windows\System32\Drivers\srv2.sys
    23:46:01.0871 4888 C:\Windows\System32\Drivers\srv2.sys - ok
    23:46:01.0873 4888 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] C:\Windows\System32\Drivers\srv.sys
    23:46:01.0873 4888 C:\Windows\System32\Drivers\srv.sys - ok
    23:46:01.0875 4888 [ CAC5202757EF68C4849B0DFFA75F6D3C ] C:\Windows\System32\iphlpsvc.dll
    23:46:01.0875 4888 C:\Windows\System32\iphlpsvc.dll - ok
    23:46:01.0877 4888 [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] C:\Windows\System32\wscsvc.dll
    23:46:01.0877 4888 C:\Windows\System32\wscsvc.dll - ok
    23:46:01.0879 4888 [ 648EDA660D32C7B80F62EF74B6B392D5 ] C:\Windows\System32\adhsvc.dll
    23:46:01.0879 4888 C:\Windows\System32\adhsvc.dll - ok
    23:46:01.0881 4888 [ 04ED9A5B39FFDDDD8314E8F34049022F ] C:\Windows\System32\dbghelp.dll
    23:46:01.0881 4888 C:\Windows\System32\dbghelp.dll - ok
    23:46:01.0882 4888 [ B1E1452C0DE1249BB22ADCA48B280AC7 ] C:\Windows\System32\httpprxm.dll
    23:46:01.0882 4888 C:\Windows\System32\httpprxm.dll - ok
    23:46:01.0884 4888 [ 47F7B9DF32E259FC7B8D9ED34EA4E0BF ] C:\Windows\System32\ncbservice.dll
    23:46:01.0884 4888 C:\Windows\System32\ncbservice.dll - ok
    23:46:01.0886 4888 [ B6191C2187460A0568A9F510188DE2ED ] C:\Windows\System32\wbem\wbemprox.dll
    23:46:01.0886 4888 C:\Windows\System32\wbem\wbemprox.dll - ok
    23:46:01.0888 4888 [ CB63BDB77BB86549FC3303C2F11EDC18 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    23:46:01.0888 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe - ok
    23:46:01.0890 4888 [ D86F25F0AD6CA6E77A9F67641EEB6722 ] C:\Windows\System32\sqmapi.dll
    23:46:01.0890 4888 C:\Windows\System32\sqmapi.dll - ok
    23:46:01.0892 4888 [ 310068BDA80B1D55C36580FD8A873FAF ] C:\Windows\System32\browser.dll
    23:46:01.0892 4888 C:\Windows\System32\browser.dll - ok
    23:46:01.0893 4888 [ 3A729A258006D813FCB2D3CEE8733878 ] C:\Windows\System32\netprofm.dll
    23:46:01.0893 4888 C:\Windows\System32\netprofm.dll - ok
    23:46:01.0895 4888 [ 256EE31588257E8A555DBFAA13F1908E ] C:\Windows\System32\srvsvc.dll
    23:46:01.0895 4888 C:\Windows\System32\srvsvc.dll - ok
    23:46:01.0897 4888 [ C9DA260FC97E22905A97FFC3D5F42B18 ] C:\Windows\System32\bi.dll
    23:46:01.0897 4888 C:\Windows\System32\bi.dll - ok
    23:46:01.0898 4888 [ 5C51484B4D2211FBE88DEB472588B5DF ] C:\Windows\System32\wdscore.dll
    23:46:01.0898 4888 C:\Windows\System32\wdscore.dll - ok
    23:46:01.0900 4888 [ 58D768B03F3C7FF919004634C29E7843 ] C:\Windows\System32\nci.dll
    23:46:01.0900 4888 C:\Windows\System32\nci.dll - ok
    23:46:01.0902 4888 [ 3C14BC7A5590DFDD754CA7A15CED0A9A ] C:\Windows\System32\sscore.dll
    23:46:01.0902 4888 C:\Windows\System32\sscore.dll - ok
    23:46:01.0904 4888 [ C5D0659CEA9A87C4C4E82B0464683F19 ] C:\Windows\System32\sscoreext.dll
    23:46:01.0904 4888 C:\Windows\System32\sscoreext.dll - ok
    23:46:01.0906 4888 [ 547D152592C3B4960DD80D9C61F7C8A9 ] C:\Windows\System32\mi.dll
    23:46:01.0906 4888 C:\Windows\System32\mi.dll - ok
    23:46:01.0907 4888 [ 8CABB7DB418AA58CEC8A00E43368EAA7 ] C:\Windows\System32\miutils.dll
    23:46:01.0907 4888 C:\Windows\System32\miutils.dll - ok
    23:46:01.0909 4888 [ 0AEF3F58E05D5BBCD8A3CF2B393FE465 ] C:\Windows\System32\wmidcom.dll
    23:46:01.0909 4888 C:\Windows\System32\wmidcom.dll - ok
    23:46:01.0911 4888 [ 95AB131067CD1695B62DEE20ADDD5071 ] C:\Windows\System32\resutils.dll
    23:46:01.0911 4888 C:\Windows\System32\resutils.dll - ok
    23:46:01.0912 4888 [ 59EA2E681CBB1F0D1DC966E27864B234 ] C:\Windows\System32\wuapi.dll
    23:46:01.0912 4888 C:\Windows\System32\wuapi.dll - ok
    23:46:01.0914 4888 [ A0CFAE5D60E2011E7531F1921028259C ] C:\Windows\System32\cabinet.dll
    23:46:01.0914 4888 C:\Windows\System32\cabinet.dll - ok
    23:46:01.0916 4888 [ 32550CE9B5AFB962A1BB8D995E76688D ] C:\Windows\System32\clusapi.dll
    23:46:01.0916 4888 C:\Windows\System32\clusapi.dll - ok
    23:46:01.0918 4888 [ 08AF5B64DA03D206508CBACAEB9E1FF3 ] C:\Windows\System32\ndiscapCfg.dll
    23:46:01.0918 4888 C:\Windows\System32\ndiscapCfg.dll - ok
    23:46:01.0920 4888 [ E1F5ACD2E86DFC938AD781EC162B745D ] C:\Windows\System32\wbem\NCProv.dll
    23:46:01.0920 4888 C:\Windows\System32\wbem\NCProv.dll - ok
    23:46:01.0921 4888 [ 52EF3A32EC17D3E9580A79A23B712917 ] C:\Windows\System32\brdgcfg.dll
    23:46:01.0921 4888 C:\Windows\System32\brdgcfg.dll - ok
    23:46:01.0923 4888 [ F7FE8684ADE6E144F6BCDA556B6907E7 ] C:\Windows\System32\dafupnp.dll
    23:46:01.0923 4888 C:\Windows\System32\dafupnp.dll - ok
    23:46:01.0926 4888 [ 20F6FD63E6D456114BC8056D62792786 ] C:\Windows\System32\netprofmsvc.dll
    23:46:01.0926 4888 C:\Windows\System32\netprofmsvc.dll - ok
    23:46:01.0928 4888 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] C:\Windows\System32\hidserv.dll
    23:46:01.0928 4888 C:\Windows\System32\hidserv.dll - ok
    23:46:01.0929 4888 [ DD35092F11DCED777EF8621D4EE2505A ] C:\Windows\System32\rascfg.dll
    23:46:01.0929 4888 C:\Windows\System32\rascfg.dll - ok
    23:46:01.0931 4888 [ 240FC332484572227CD1DF82407F33E5 ] C:\Windows\System32\wdi.dll
    23:46:01.0931 4888 C:\Windows\System32\wdi.dll - ok
    23:46:01.0933 4888 [ 94AA5150E35B3ABB7191FE641E3C2473 ] C:\Windows\System32\wpdbusenum.dll
    23:46:01.0933 4888 C:\Windows\System32\wpdbusenum.dll - ok
    23:46:01.0935 4888 [ 54A59A152C795E4FD51FB247841F57D6 ] C:\Windows\System32\diagperf.dll
    23:46:01.0935 4888 C:\Windows\System32\diagperf.dll - ok
    23:46:01.0937 4888 [ 909EBA9AF43AF0E70EA7FFC352484424 ] C:\Windows\System32\mprapi.dll
    23:46:01.0937 4888 C:\Windows\System32\mprapi.dll - ok
    23:46:01.0938 4888 [ D1A04DC07552A12553D64404CDBAB3A1 ] C:\Windows\System32\perftrack.dll
    23:46:01.0939 4888 C:\Windows\System32\perftrack.dll - ok
    23:46:01.0941 4888 [ 04C84B41AD7BC0C663A613CA9E3D3FC5 ] C:\Windows\System32\rasadhlp.dll
    23:46:01.0941 4888 C:\Windows\System32\rasadhlp.dll - ok
    23:46:01.0942 4888 [ 829562D41F5359BCA0ABC9DBE51B8723 ] C:\Windows\System32\umb.dll
    23:46:01.0943 4888 C:\Windows\System32\umb.dll - ok
    23:46:01.0944 4888 [ 06DF6E95E59FF75FFB575A6FC63CC233 ] C:\Windows\System32\wups.dll
    23:46:01.0944 4888 C:\Windows\System32\wups.dll - ok
    23:46:01.0946 4888 [ 11F0834544D68B955E6C44DFFB272122 ] C:\Windows\System32\mprmsg.dll
    23:46:01.0946 4888 C:\Windows\System32\mprmsg.dll - ok
    23:46:01.0948 4888 [ 91E352ACB49DF3388C960A09243E5616 ] C:\Windows\System32\NdisImPlatform.dll
    23:46:01.0948 4888 C:\Windows\System32\NdisImPlatform.dll - ok
    23:46:01.0950 4888 [ EBA655700A35328F4E61266DD35FB71F ] C:\Windows\System32\pcadm.dll
    23:46:01.0950 4888 C:\Windows\System32\pcadm.dll - ok
    23:46:01.0952 4888 [ 7417B004B5BD4B9EC1140890131CD41D ] C:\Windows\System32\pnpts.dll
    23:46:01.0952 4888 C:\Windows\System32\pnpts.dll - ok
    23:46:01.0953 4888 [ F6BB843AFC93AEE9E928CFE4BB5B743C ] C:\Windows\System32\LldpNotify.dll
    23:46:01.0953 4888 C:\Windows\System32\LldpNotify.dll - ok
    23:46:01.0955 4888 [ CC5512FC3FCCEA164F01592B5979F1BE ] C:\Windows\System32\srumsvc.dll
    23:46:01.0955 4888 C:\Windows\System32\srumsvc.dll - ok
    23:46:01.0956 4888 [ 8B5D475B48506471669B9B46945138B0 ] C:\Windows\System32\wer.dll
    23:46:01.0956 4888 C:\Windows\System32\wer.dll - ok
    23:46:01.0958 4888 [ A2418204EBFA6F41DE3DF2FBB46B7F3F ] C:\Windows\System32\pcacli.dll
    23:46:01.0958 4888 C:\Windows\System32\pcacli.dll - ok
    23:46:01.0961 4888 [ AF56A8936DF2F7031D4311C81D065CE9 ] C:\Windows\System32\tcpipcfg.dll
    23:46:01.0961 4888 C:\Windows\System32\tcpipcfg.dll - ok
    23:46:01.0963 4888 [ A18100201E7477BB47C72711E092A8F0 ] C:\Windows\System32\esent.dll
    23:46:01.0963 4888 C:\Windows\System32\esent.dll - ok
    23:46:01.0965 4888 [ 98D9EC5E81ECFCCEEB94894D19AA9F7E ] C:\Windows\System32\mpr.dll
    23:46:01.0965 4888 C:\Windows\System32\mpr.dll - ok
    23:46:01.0967 4888 [ 26D38C1391CD81ADDD791DE136E2FEA7 ] C:\Windows\System32\npmproxy.dll
    23:46:01.0967 4888 C:\Windows\System32\npmproxy.dll - ok
    23:46:01.0969 4888 [ 0F57DEA30340B49B06DCB8B077BEF072 ] C:\Windows\System32\PortableDeviceConnectApi.dll
    23:46:01.0969 4888 C:\Windows\System32\PortableDeviceConnectApi.dll - ok
    23:46:01.0971 4888 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] C:\Windows\System32\ssdpsrv.dll
    23:46:01.0971 4888 C:\Windows\System32\ssdpsrv.dll - ok
    23:46:01.0973 4888 [ 0D97A065E85D59B8F0EE2BD31A679456 ] C:\Windows\System32\wdiasqmmodule.dll
    23:46:01.0973 4888 C:\Windows\System32\wdiasqmmodule.dll - ok
    23:46:01.0975 4888 [ CEB35EB551BE4F216691255D38867346 ] C:\Windows\System32\activeds.dll
    23:46:01.0975 4888 C:\Windows\System32\activeds.dll - ok
    23:46:01.0976 4888 [ 6AE7DC415EFF4840512E5354CE99F4A5 ] C:\Windows\System32\adsldpc.dll
    23:46:01.0976 4888 C:\Windows\System32\adsldpc.dll - ok
    23:46:01.0978 4888 [ D0398301E7E94D2B7DFE6D12DE77E809 ] C:\Windows\System32\cryptnet.dll
    23:46:01.0978 4888 C:\Windows\System32\cryptnet.dll - ok
    23:46:01.0980 4888 [ 335C4488A14AC4B52B3E1CDF6D6F7780 ] C:\Windows\System32\hnetcfg.dll
    23:46:01.0980 4888 C:\Windows\System32\hnetcfg.dll - ok
    23:46:01.0982 4888 [ 11A9C08F39F929B0D04FEE7C743CE8D9 ] C:\Windows\System32\adsldp.dll
    23:46:01.0982 4888 C:\Windows\System32\adsldp.dll - ok
    23:46:01.0984 4888 [ 2D7BB53EA2BB3F213CE558A79EC8448D ] C:\Windows\System32\nduprov.dll
    23:46:01.0984 4888 C:\Windows\System32\nduprov.dll - ok
    23:46:01.0986 4888 [ 9E2E7FE5237CFE3A0529B54C53021CA0 ] C:\Windows\System32\appsruprov.dll
    23:46:01.0986 4888 C:\Windows\System32\appsruprov.dll - ok
    23:46:01.0988 4888 [ D0A82052050909677C648B2496C0909E ] C:\Windows\System32\wpnsruprov.dll
    23:46:01.0988 4888 C:\Windows\System32\wpnsruprov.dll - ok
    23:46:01.0990 4888 [ 55955FB63C2E045AA9915184880B4F27 ] C:\Windows\System32\cscapi.dll
    23:46:01.0990 4888 C:\Windows\System32\cscapi.dll - ok
    23:46:01.0992 4888 [ 71697EDF104E5EACD75822E588FA8149 ] C:\Windows\System32\energyprov.dll
    23:46:01.0992 4888 C:\Windows\System32\energyprov.dll - ok
    23:46:01.0994 4888 [ FA6C8E59B74908550607EBEDCD7BA1E2 ] C:\Windows\System32\secur32.dll
    23:46:01.0994 4888 C:\Windows\System32\secur32.dll - ok
    23:46:01.0995 4888 [ AE03E9CBFFB8EDE81B3DA7603E546F56 ] C:\Windows\System32\srumapi.dll
    23:46:01.0995 4888 C:\Windows\System32\srumapi.dll - ok
    23:46:01.0997 4888 [ 855E7E347893BDB93245120E137577FB ] C:\Windows\System32\radardt.dll
    23:46:01.0997 4888 C:\Windows\System32\radardt.dll - ok
    23:46:01.0999 4888 [ 9AD609CFDA377BFCE0CB7ABF294BC74B ] C:\Windows\SysWOW64\wscisvif.dll
    23:46:01.0999 4888 C:\Windows\SysWOW64\wscisvif.dll - ok
    23:46:02.0001 4888 [ CA4FAFFA957C71C006B59E29DFE3EB8B ] C:\Windows\System32\pnrpnsp.dll
    23:46:02.0001 4888 C:\Windows\System32\pnrpnsp.dll - ok
    23:46:02.0003 4888 [ 768B5A538A11E9C6F8EDD9AFDFA16936 ] C:\Windows\System32\winrnr.dll
    23:46:02.0003 4888 C:\Windows\System32\winrnr.dll - ok
    23:46:02.0005 4888 [ 4E1278D5040A2D2D274EB98661CBF07E ] C:\Windows\SysWOW64\devrtl.dll
    23:46:02.0005 4888 C:\Windows\SysWOW64\devrtl.dll - ok
    23:46:02.0007 4888 [ 149FEE067A002D75B7714C300D019C9E ] C:\Windows\System32\NapiNSP.dll
    23:46:02.0007 4888 C:\Windows\System32\NapiNSP.dll - ok
    23:46:02.0009 4888 [ B460531B5F5ED9E8ABCA3BA342AE9563 ] C:\Program Files\Windows Defender\MpCmdRun.exe
    23:46:02.0009 4888 C:\Program Files\Windows Defender\MpCmdRun.exe - ok
    23:46:02.0011 4888 [ FC06C5B62750F4D2D0866FC525709842 ] C:\Windows\SysWOW64\AppXDeploymentClient.dll
    23:46:02.0011 4888 C:\Windows\SysWOW64\AppXDeploymentClient.dll - ok
    23:46:02.0013 4888 [ D9CB0782AF819548072AA45B70F8B22D ] C:\Windows\System32\Drivers\condrv.sys
    23:46:02.0013 4888 C:\Windows\System32\Drivers\condrv.sys - ok
    23:46:02.0015 4888 [ 3E30EF769BC47B9B16515EB66EFF1E2F ] C:\Windows\System32\conhost.exe
    23:46:02.0015 4888 C:\Windows\System32\conhost.exe - ok
    23:46:02.0017 4888 [ F6F1B55FC775E6F096AD400030E9D0B8 ] C:\Windows\System32\dimsjob.dll
    23:46:02.0017 4888 C:\Windows\System32\dimsjob.dll - ok
    23:46:02.0019 4888 [ E38D9838439D0BBC22EF3F1E9F058F8E ] C:\Windows\System32\msiexec.exe
    23:46:02.0019 4888 C:\Windows\System32\msiexec.exe - ok
    23:46:02.0020 4888 [ 93962D7FBE16AA0566A9C90E444C51A9 ] C:\Windows\System32\SettingSyncInfo.dll
    23:46:02.0021 4888 C:\Windows\System32\SettingSyncInfo.dll - ok
    23:46:02.0022 4888 [ 359F8D71B628966A72565BF7D9006826 ] C:\Windows\apppatch\apppatch64\AcLayers.dll
    23:46:02.0022 4888 C:\Windows\apppatch\apppatch64\AcLayers.dll - ok
    23:46:02.0024 4888 [ B617F2E83951A9A4F495BBA58CF492B2 ] C:\Windows\System32\dllhost.exe
    23:46:02.0024 4888 C:\Windows\System32\dllhost.exe - ok
    23:46:02.0026 4888 [ 173C770E388C31EDBB23F4283992F73E ] C:\Program Files\Windows Defender\MpClient.dll
    23:46:02.0026 4888 C:\Program Files\Windows Defender\MpClient.dll - ok
    23:46:02.0028 4888 [ B1E63281081B64BB570EA5B3EC5146C5 ] C:\Windows\System32\sfc.dll
    23:46:02.0028 4888 C:\Windows\System32\sfc.dll - ok
    23:46:02.0030 4888 [ AFE9464D80CFE0B0ECFE906C8A5996A0 ] C:\Windows\System32\winspool.drv
    23:46:02.0030 4888 C:\Windows\System32\winspool.drv - ok
    23:46:02.0032 4888 [ A6E506E122DF3244443BE6113404EB96 ] C:\Windows\System32\pautoenr.dll
    23:46:02.0032 4888 C:\Windows\System32\pautoenr.dll - ok
    23:46:02.0033 4888 [ 37814A36DBAF1AE9D42BE89889ECB4B7 ] C:\Windows\System32\certca.dll
    23:46:02.0033 4888 C:\Windows\System32\certca.dll - ok
    23:46:02.0035 4888 [ 7853D2AB445C10F97610B2B05FA4CF0A ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    23:46:02.0035 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe - ok
    23:46:02.0037 4888 [ E60DEF401500F909C3DA7B13E21F02D8 ] C:\Program Files\Microsoft Office\Office15\msoia.exe
    23:46:02.0037 4888 C:\Program Files\Microsoft Office\Office15\msoia.exe - ok
    23:46:02.0039 4888 [ 15E174928C1ABD23B3647270F2632D6C ] C:\Windows\System32\CertEnroll.dll
    23:46:02.0039 4888 C:\Windows\System32\CertEnroll.dll - ok
    23:46:02.0041 4888 [ 14473D7F73F7C1DB535CD4C8D2CF35AA ] C:\Windows\System32\AppXDeploymentServer.dll
    23:46:02.0041 4888 C:\Windows\System32\AppXDeploymentServer.dll - ok
    23:46:02.0043 4888 [ 0E925F7BA032920D58DD284B6181A247 ] C:\Windows\System32\userinit.exe
    23:46:02.0043 4888 C:\Windows\System32\userinit.exe - ok
    23:46:02.0045 4888 [ CD09341CCD92DA45EA5A0C725270FA51 ] C:\Windows\System32\userinitext.dll
    23:46:02.0045 4888 C:\Windows\System32\userinitext.dll - ok
    23:46:02.0046 4888 [ 0828E3E7BD77C89149EAD3232BFD38DB ] C:\Windows\System32\fdPHost.dll
    23:46:02.0046 4888 C:\Windows\System32\fdPHost.dll - ok
    23:46:02.0048 4888 [ 872506AAB591E8908DF4461475AF92DF ] C:\Windows\System32\FDResPub.dll
    23:46:02.0048 4888 C:\Windows\System32\FDResPub.dll - ok
    23:46:02.0050 4888 [ 024632F2FC93286700FE82763C0A98FD ] C:\Windows\System32\tdh.dll
    23:46:02.0050 4888 C:\Windows\System32\tdh.dll - ok
    23:46:02.0052 4888 [ ACEBEB1F363C819576216CF9C4962FA2 ] C:\Windows\System32\fdWSD.dll
    23:46:02.0052 4888 C:\Windows\System32\fdWSD.dll - ok
    23:46:02.0053 4888 [ 8BC5E1F477761F75B26E66746828915D ] C:\Windows\System32\HotStartUserAgent.dll
    23:46:02.0054 4888 C:\Windows\System32\HotStartUserAgent.dll - ok
    23:46:02.0055 4888 [ 70B5BD19740464A41B835C082819B74D ] C:\Windows\System32\WSDApi.dll
    23:46:02.0055 4888 C:\Windows\System32\WSDApi.dll - ok
    23:46:02.0057 4888 [ D029339C0F59CF662094EDDF8C42B2B5 ] C:\Windows\System32\msvcp100.dll
    23:46:02.0057 4888 C:\Windows\System32\msvcp100.dll - ok
    23:46:02.0059 4888 [ 456913A14EAFD876ABDC1FC11DA856FA ] C:\Windows\System32\taskhostex.exe
    23:46:02.0059 4888 C:\Windows\System32\taskhostex.exe - ok
    23:46:02.0061 4888 [ E13A31D5254C25406A7946BDD9B06364 ] C:\Windows\explorer.exe
    23:46:02.0061 4888 C:\Windows\explorer.exe - ok
    23:46:02.0063 4888 [ B5EB8E2AF9B3E067A8525622AEEC212E ] C:\Windows\System32\wlroamextension.dll
    23:46:02.0063 4888 C:\Windows\System32\wlroamextension.dll - ok
    23:46:02.0066 4888 [ 509192E80BF34E985C4D277A8FFF2893 ] C:\Windows\System32\webservices.dll
    23:46:02.0066 4888 C:\Windows\System32\webservices.dll - ok
    23:46:02.0067 4888 [ 88449B888787E8BFA5145C9CF5E610E1 ] C:\Windows\SysWOW64\Windows.ApplicationModel.dll
    23:46:02.0067 4888 C:\Windows\SysWOW64\Windows.ApplicationModel.dll - ok
    23:46:02.0069 4888 [ D3B1196386488D4BEDA5DFDA3749E36C ] C:\Windows\System32\fdSSDP.dll
    23:46:02.0069 4888 C:\Windows\System32\fdSSDP.dll - ok
    23:46:02.0071 4888 [ A572A1F193C14D7C17AB2BF3029A52BB ] C:\Windows\System32\MsCtfMonitor.dll
    23:46:02.0071 4888 C:\Windows\System32\MsCtfMonitor.dll - ok
    23:46:02.0074 4888 [ 1A196FE539A6F81977805B6CE4F90BDC ] C:\Windows\System32\msutb.dll
    23:46:02.0074 4888 C:\Windows\System32\msutb.dll - ok
    23:46:02.0075 4888 [ 38E669E49C35B6A02A9AF0737C526C0F ] C:\Windows\System32\PlaySndSrv.dll
    23:46:02.0075 4888 C:\Windows\System32\PlaySndSrv.dll - ok
    23:46:02.0077 4888 [ 282191A781E23B9CB50BF7652A5F511C ] C:\Windows\System32\httpapi.dll
    23:46:02.0077 4888 C:\Windows\System32\httpapi.dll - ok
    23:46:02.0079 4888 [ D64C4AFEE8277F35EF729A2B924666B0 ] C:\Windows\System32\appinfo.dll
    23:46:02.0079 4888 C:\Windows\System32\appinfo.dll - ok
    23:46:02.0081 4888 [ C982FE4CC91DECE2259F494FCEB4030F ] C:\Windows\System32\NcdAutoSetup.dll
    23:46:02.0081 4888 C:\Windows\System32\NcdAutoSetup.dll - ok
    23:46:02.0083 4888 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] C:\Windows\System32\provsvc.dll
    23:46:02.0083 4888 C:\Windows\System32\provsvc.dll - ok
    23:46:02.0084 4888 [ 06856DA4C306F557BF115C4EF2269095 ] C:\Windows\System32\dtsh.dll
    23:46:02.0084 4888 C:\Windows\System32\dtsh.dll - ok
    23:46:02.0086 4888 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] C:\Windows\System32\ListSvc.dll
    23:46:02.0086 4888 C:\Windows\System32\ListSvc.dll - ok
    23:46:02.0088 4888 [ 88D686DE8D296AAC4A634B0EFBED9028 ] C:\Windows\System32\P2P.dll
    23:46:02.0088 4888 C:\Windows\System32\P2P.dll - ok
    23:46:02.0090 4888 [ A075E18C6A60C5B2A0A95AB7F7BF94E8 ] C:\Windows\System32\fdProxy.dll
    23:46:02.0090 4888 C:\Windows\System32\fdProxy.dll - ok
    23:46:02.0092 4888 [ AB76700D764A342D7475FB8F47CAB18C ] C:\Windows\System32\pnrpsvc.dll
    23:46:02.0092 4888 C:\Windows\System32\pnrpsvc.dll - ok
    23:46:02.0093 4888 [ 1C8E051AA357E5B73B74B4C8FFDCE9C3 ] C:\Windows\System32\actxprxy.dll
    23:46:02.0093 4888 C:\Windows\System32\actxprxy.dll - ok
    23:46:02.0095 4888 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] C:\Windows\System32\p2psvc.dll
    23:46:02.0095 4888 C:\Windows\System32\p2psvc.dll - ok
    23:46:02.0097 4888 [ 0AB4E16A91E3C937A4C61488120E323A ] C:\Windows\System32\hgprint.dll
    23:46:02.0097 4888 C:\Windows\System32\hgprint.dll - ok
    23:46:02.0099 4888 [ 733E0C2F074B17D660349768BB70393D ] C:\Windows\System32\P2PGraph.dll
    23:46:02.0099 4888 C:\Windows\System32\P2PGraph.dll - ok
    23:46:02.0101 4888 [ FAE5157339279E1251D2482E6365691A ] C:\Windows\System32\fhlisten.dll
    23:46:02.0101 4888 C:\Windows\System32\fhlisten.dll - ok
    23:46:02.0102 4888 [ 9DE5419BE2F4A47A79785E285BA005E2 ] C:\Windows\System32\IdListen.dll
    23:46:02.0102 4888 C:\Windows\System32\IdListen.dll - ok
    23:46:02.0104 4888 [ 5F46797ED1629F152EF4A8DD0DBBC31F ] C:\Windows\System32\DAFWSD.dll
    23:46:02.0104 4888 C:\Windows\System32\DAFWSD.dll - ok
    23:46:02.0106 4888 [ 0E658D67C4A79294BC7BBBF4656F0794 ] C:\Windows\System32\winmm.dll
    23:46:02.0106 4888 C:\Windows\System32\winmm.dll - ok
    23:46:02.0108 4888 [ 15343AA01C41F7AB4FE549499159DB6F ] C:\Windows\System32\winmmbase.dll
    23:46:02.0108 4888 C:\Windows\System32\winmmbase.dll - ok
    23:46:02.0110 4888 [ C84B51243DF6A6C5835FF6CAEC5C6B97 ] C:\Windows\System32\webio.dll
    23:46:02.0110 4888 C:\Windows\System32\webio.dll - ok
    23:46:02.0112 4888 [ 7EC788D53F6F43061A9BFB70D745CCBC ] C:\Program Files (x86)\AVG\AVG2013\avgxpla.dll
    23:46:02.0112 4888 C:\Program Files (x86)\AVG\AVG2013\avgxpla.dll - ok
    23:46:02.0114 4888 [ 7E87637EECBACBB11BBA1124B805A747 ] C:\Program Files (x86)\AVG\AVG2013\avgopenssla.dll
    23:46:02.0114 4888 C:\Program Files (x86)\AVG\AVG2013\avgopenssla.dll - ok
    23:46:02.0116 4888 [ 8411147754C00B3B096C5C0ED95B3CFC ] C:\Windows\System32\runonce.exe
    23:46:02.0116 4888 C:\Windows\System32\runonce.exe - ok
    23:46:02.0118 4888 [ F0408DB6F94E3F0D5ED94B16C097A622 ] C:\Windows\SysWOW64\runonce.exe
    23:46:02.0118 4888 C:\Windows\SysWOW64\runonce.exe - ok
    23:46:02.0120 4888 [ 5996C79FB52BDE3FA10F77396654AE42 ] C:\Windows\SysWOW64\cmd.exe
    23:46:02.0120 4888 C:\Windows\SysWOW64\cmd.exe - ok
    23:46:02.0121 4888 [ F2E12B5B7EEDE6854104E5AF8AC841A8 ] C:\Windows\SysWOW64\cmdext.dll
    23:46:02.0121 4888 C:\Windows\SysWOW64\cmdext.dll - ok
    23:46:02.0123 4888 [ 9DA86B80AE1339F19CD5D290787EB7B3 ] C:\Windows\SysWOW64\shdocvw.dll
    23:46:02.0123 4888 C:\Windows\SysWOW64\shdocvw.dll - ok
    23:46:02.0125 4888 [ EBC984F0CE40E0DAF0454D806EC2A7EC ] C:\Users\DJ\AppData\Local\Temp\A4B6AB33-B0D7-434D-B956-38E0CB8A9B49.exe
    23:46:02.0125 4888 C:\Users\DJ\AppData\Local\Temp\A4B6AB33-B0D7-434D-B956-38E0CB8A9B49.exe - ok
    23:46:02.0127 4888 [ F8DE2E949B135BA7E45AE18DC82BF262 ] C:\Windows\SysWOW64\pcacli.dll
    23:46:02.0127 4888 C:\Windows\SysWOW64\pcacli.dll - ok
    23:46:02.0129 4888 [ 974AE60BF5B90E31412D93596C968E5B ] C:\Windows\System32\aelupsvc.dll
    23:46:02.0129 4888 C:\Windows\System32\aelupsvc.dll - ok
    23:46:02.0131 4888 [ 9A777EDE50D61A30265C4448A67F80E9 ] C:\Windows\System32\themeui.dll
    23:46:02.0131 4888 C:\Windows\System32\themeui.dll - ok
    23:46:02.0133 4888 [ 18D61C0822414ACDBD88EB8AD6319D70 ] C:\Windows\System32\ExplorerFrame.dll
    23:46:02.0133 4888 C:\Windows\System32\ExplorerFrame.dll - ok
    23:46:02.0136 4888 [ 51187F2413CDB487542290E046B6378E ] C:\Windows\System32\twinapi.dll
    23:46:02.0136 4888 C:\Windows\System32\twinapi.dll - ok
    23:46:02.0137 4888 [ BD7849649C6E85118802010F442F67A8 ] C:\Windows\SysWOW64\webio.dll
    23:46:02.0138 4888 C:\Windows\SysWOW64\webio.dll - ok
    23:46:02.0139 4888 [ BB3717D6FC27A22D0403C825A93BC068 ] C:\Windows\SysWOW64\dnsapi.dll
    23:46:02.0139 4888 C:\Windows\SysWOW64\dnsapi.dll - ok
    23:46:02.0141 4888 [ 7CD424F005ED71204DCB14CF11F1EB0C ] C:\Windows\SysWOW64\rasadhlp.dll
    23:46:02.0141 4888 C:\Windows\SysWOW64\rasadhlp.dll - ok
    23:46:02.0143 4888 [ C4729C10C3D9E1517EFF2C7AAE72E819 ] C:\Windows\System32\gameux.dll
    23:46:02.0143 4888 C:\Windows\System32\gameux.dll - ok
    23:46:02.0145 4888 [ 8620189836543C2A0435BF37C864BCEE ] C:\Windows\System32\twinui.dll
    23:46:02.0145 4888 C:\Windows\System32\twinui.dll - ok
    23:46:02.0147 4888 [ 0671A791C292F46423CFE37B53D598D0 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFileScanLibrary.dll
    23:46:02.0147 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFileScanLibrary.dll - ok
    23:46:02.0149 4888 [ 9C2543A7AC524CAA63B26A16D4E3AD39 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl
    23:46:02.0149 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl - ok
    23:46:02.0151 4888 [ 70C3B722AE97E6C6A144EC20E5D7C080 ] C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
    23:46:02.0151 4888 C:\Windows\System32\windows.immersiveshell.serviceprovider.dll - ok
    23:46:02.0153 4888 [ 5422CB64444C33F029483552A8FACE37 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\vclx150.bpl
    23:46:02.0153 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\vclx150.bpl - ok
    23:46:02.0155 4888 [ AEB9DD47B76075B05E27874384544F39 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\vclie150.bpl
    23:46:02.0155 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\vclie150.bpl - ok
    23:46:02.0158 4888 [ 1D2BF8A373546ADA00F09DC7496B86AB ] C:\Windows\System32\wpncore.dll
    23:46:02.0158 4888 C:\Windows\System32\wpncore.dll - ok
    23:46:02.0160 4888 [ F0814D492176F8A4FD49D852D2AD748E ] C:\Windows\System32\sppc.dll
    23:46:02.0160 4888 C:\Windows\System32\sppc.dll - ok
    23:46:02.0163 4888 [ FAD9807ACDE89A34D2EB4743D57016D7 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDAdvancedCheckLibrary.dll
    23:46:02.0163 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDAdvancedCheckLibrary.dll - ok
    23:46:02.0166 4888 [ F146E2BA475893DD77B2370DC1211FC6 ] C:\Windows\System32\Drivers\37585510.sys
    23:46:02.0166 4888 C:\Windows\System32\Drivers\37585510.sys - ok
    23:46:02.0167 4888 [ FCD59C405ADFADAC1B0729C580F7F70C ] C:\Windows\System32\wlidprov.dll
    23:46:02.0167 4888 C:\Windows\System32\wlidprov.dll - ok
    23:46:02.0169 4888 [ FF4135424A79DCC2998276D8E39C9B4D ] C:\Windows\System32\TimeBrokerServer.dll
    23:46:02.0169 4888 C:\Windows\System32\TimeBrokerServer.dll - ok
    23:46:02.0171 4888 [ 9C0502C5E747C8011D700DCA681A55A1 ] C:\Windows\System32\ELSCore.dll
    23:46:02.0171 4888 C:\Windows\System32\ELSCore.dll - ok
    23:46:02.0174 4888 [ E219BF7BCCFE4881B0C053C7E0B47ECC ] C:\Windows\System32\SystemEventsBrokerServer.dll
    23:46:02.0174 4888 C:\Windows\System32\SystemEventsBrokerServer.dll - ok
    23:46:02.0175 4888 [ 9314C83DE37182685C788FCA3CEC43A4 ] C:\Windows\System32\thumbcache.dll
    23:46:02.0175 4888 C:\Windows\System32\thumbcache.dll - ok
    23:46:02.0177 4888 [ A0F844B0E9ADACA064B832CAF0AEE338 ] C:\Windows\System32\elsTrans.dll
    23:46:02.0177 4888 C:\Windows\System32\elsTrans.dll - ok
    23:46:02.0179 4888 [ DCB7509F83B2A2089DBE07DDEDB52017 ] C:\Windows\System32\WinTypes.dll
    23:46:02.0179 4888 C:\Windows\System32\WinTypes.dll - ok
    23:46:02.0181 4888 [ F6F335A35D54FF8A55D15FA35E0F7671 ] C:\Windows\System32\elslad.dll
    23:46:02.0181 4888 C:\Windows\System32\elslad.dll - ok
    23:46:02.0183 4888 [ 09D886BA5A4BCC31079A2B12980CCF50 ] C:\Windows\SysWOW64\msi.dll
    23:46:02.0183 4888 C:\Windows\SysWOW64\msi.dll - ok
    23:46:02.0185 4888 [ 843D5C2D3032631E400E3ACD1F06312E ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
    23:46:02.0185 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe - ok
    23:46:02.0187 4888 [ 15AC3A854C3DD59DFD11EEE2FF63C79A ] C:\Windows\SysWOW64\riched20.dll
    23:46:02.0187 4888 C:\Windows\SysWOW64\riched20.dll - ok
    23:46:02.0189 4888 [ C4A6771ABE5F9B2B9B5876175F14E61A ] C:\Windows\SysWOW64\msls31.dll
    23:46:02.0189 4888 C:\Windows\SysWOW64\msls31.dll - ok
    23:46:02.0191 4888 [ BC9503A901A545FAD807909F8C86B286 ] C:\Windows\SysWOW64\usp10.dll
    23:46:02.0191 4888 C:\Windows\SysWOW64\usp10.dll - ok
    23:46:02.0192 4888 [ 48067CB53E31B98A394CB12024F26D1B ] C:\Windows\System32\Windows.Globalization.Fontgroups.dll
    23:46:02.0193 4888 C:\Windows\System32\Windows.Globalization.Fontgroups.dll - ok
    23:46:02.0194 4888 [ 074223C4D8109C016B5864DEBF356BD8 ] C:\Windows\SysWOW64\ExplorerFrame.dll
     
  12. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    23:46:02.0194 4888 C:\Windows\SysWOW64\ExplorerFrame.dll - ok
    23:46:02.0197 4888 [ 5EFD801A12FB267405B24945012F5E1A ] C:\Windows\System32\linkinfo.dll
    23:46:02.0197 4888 C:\Windows\System32\linkinfo.dll - ok
    23:46:02.0198 4888 [ FE4D3F3C0F40B9CF957091847704D22E ] C:\Windows\SysWOW64\duser.dll
    23:46:02.0198 4888 C:\Windows\SysWOW64\duser.dll - ok
    23:46:02.0200 4888 [ FB11241B62F07C9FFE664610E262C528 ] C:\Windows\SysWOW64\dui70.dll
    23:46:02.0200 4888 C:\Windows\SysWOW64\dui70.dll - ok
    23:46:02.0202 4888 [ D86F25F0AD6CA6E77A9F67641EEB6722 ] C:\Program Files\Internet Explorer\sqmapi.dll
    23:46:02.0202 4888 C:\Program Files\Internet Explorer\sqmapi.dll - ok
    23:46:02.0204 4888 [ 638407A6996B1DD4CB7BB979B8C260DE ] C:\Windows\System32\Windows.Networking.Connectivity.dll
    23:46:02.0204 4888 C:\Windows\System32\Windows.Networking.Connectivity.dll - ok
    23:46:02.0206 4888 [ 4E6C0D003B381CC109A50794A2F1A222 ] C:\Windows\System32\stobject.dll
    23:46:02.0206 4888 C:\Windows\System32\stobject.dll - ok
    23:46:02.0207 4888 [ F7C576B31DD1D18E8C45A43AE807C5F5 ] C:\Windows\System32\ThumbnailExtractionHost.exe
    23:46:02.0207 4888 C:\Windows\System32\ThumbnailExtractionHost.exe - ok
    23:46:02.0209 4888 [ 44F388C294370B255F7EB751939BD6E3 ] C:\Windows\System32\wpnprv.dll
    23:46:02.0209 4888 C:\Windows\System32\wpnprv.dll - ok
    23:46:02.0211 4888 [ D12BEB5E114701442F1FAA92A739E60E ] C:\Windows\System32\prnfldr.dll
    23:46:02.0211 4888 C:\Windows\System32\prnfldr.dll - ok
    23:46:02.0214 4888 [ 5F59C3E414CC8A05FFB4D86FFCB13CD4 ] C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
    23:46:02.0214 4888 C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll - ok
    23:46:02.0216 4888 [ 907C4782AA98A587EAA50D830FFC246C ] C:\Windows\System32\DeviceSetupManagerAPI.dll
    23:46:02.0216 4888 C:\Windows\System32\DeviceSetupManagerAPI.dll - ok
    23:46:02.0218 4888 [ 7ECD8DF63A762BDE3F481BC4239FB9AB ] C:\Windows\System32\shdocvw.dll
    23:46:02.0218 4888 C:\Windows\System32\shdocvw.dll - ok
    23:46:02.0221 4888 [ 83A075C07425E84ACC6687FFF7126930 ] C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll
    23:46:02.0221 4888 C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll - ok
    23:46:02.0224 4888 [ CE0BD323EB9BDFD140271E550CBA4111 ] C:\Windows\System32\TimeBrokerClient.dll
    23:46:02.0224 4888 C:\Windows\System32\TimeBrokerClient.dll - ok
    23:46:02.0226 4888 [ DD236E26397C1C79D55684F5A72E1C3C ] C:\Windows\System32\PhotoMetadataHandler.dll
    23:46:02.0226 4888 C:\Windows\System32\PhotoMetadataHandler.dll - ok
    23:46:02.0228 4888 [ 7FD32D1A763D8BDF3A142C99FC21D232 ] C:\Windows\System32\AudioSes.dll
    23:46:02.0228 4888 C:\Windows\System32\AudioSes.dll - ok
    23:46:02.0230 4888 [ 4215C49E751ECA4BC42B3C10C8A55950 ] C:\Windows\System32\ncryptsslp.dll
    23:46:02.0230 4888 C:\Windows\System32\ncryptsslp.dll - ok
    23:46:02.0231 4888 [ F6E06380D717875F6AEFC2B0694B9E9D ] C:\Windows\System32\ncryptprov.dll
    23:46:02.0231 4888 C:\Windows\System32\ncryptprov.dll - ok
    23:46:02.0233 4888 [ 0515FF4F49057EDE5FAAB6537D26D5EB ] C:\Windows\System32\dssenh.dll
    23:46:02.0233 4888 C:\Windows\System32\dssenh.dll - ok
    23:46:02.0235 4888 [ 7C3B449F661D99A9B1033A14033D2987 ] C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\msvcr110.dll
    23:46:02.0235 4888 C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\msvcr110.dll - ok
    23:46:02.0237 4888 [ 259C9486E06C16BF1BC36CAE784FDFDE ] C:\Windows\System32\WWanAPI.dll
    23:46:02.0237 4888 C:\Windows\System32\WWanAPI.dll - ok
    23:46:02.0238 4888 [ DC12FF4A1B00CAE279D5744F36B74873 ] C:\Windows\System32\wwapi.dll
    23:46:02.0238 4888 C:\Windows\System32\wwapi.dll - ok
    23:46:02.0240 4888 [ 043B150DA8B3559BD7AE701D3496D232 ] C:\Windows\System32\DXP.dll
    23:46:02.0240 4888 C:\Windows\System32\DXP.dll - ok
    23:46:02.0242 4888 [ 5A5E57A0E1D3674AE9ADBC9CAD80428D ] C:\Windows\System32\Syncreg.dll
    23:46:02.0242 4888 C:\Windows\System32\Syncreg.dll - ok
    23:46:02.0244 4888 [ EB003CF63697C3B6AFA9CF769759A5B2 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\wllog.dll
    23:46:02.0244 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\wllog.dll - ok
    23:46:02.0246 4888 [ F98FAED087C12A4D94D6ECDA0618C918 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Service.dll
    23:46:02.0246 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Service.dll - ok
    23:46:02.0248 4888 [ E9B9C28A237D8FEF1FCD2C0D08E7D3C4 ] C:\Windows\System32\upnp.dll
    23:46:02.0248 4888 C:\Windows\System32\upnp.dll - ok
    23:46:02.0250 4888 [ CB7242A05FFD365BBBBE102D24786DEE ] C:\Windows\System32\Windows.Storage.ApplicationData.dll
    23:46:02.0250 4888 C:\Windows\System32\Windows.Storage.ApplicationData.dll - ok
    23:46:02.0251 4888 [ 86F869D43E6E998466538A1DF0D1E6D7 ] C:\Windows\System32\drttransport.dll
    23:46:02.0251 4888 C:\Windows\System32\drttransport.dll - ok
    23:46:02.0253 4888 [ BFABA02A0EA273980BA69DA07483737E ] C:\Windows\System32\drt.dll
    23:46:02.0253 4888 C:\Windows\System32\drt.dll - ok
    23:46:02.0255 4888 [ 923260FAA0F64A90FA63F7EAC08881AF ] C:\Windows\System32\AltTab.dll
    23:46:02.0255 4888 C:\Windows\System32\AltTab.dll - ok
    23:46:02.0257 4888 [ D240CBB72679D6B4B5B07619F0A07F06 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\shared\bici.dll
    23:46:02.0257 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\shared\bici.dll - ok
    23:46:02.0261 4888 [ 3E4CC1E808A0FC8F487036349F4E6810 ] C:\Windows\System32\threadpoolwinrt.dll
    23:46:02.0261 4888 C:\Windows\System32\threadpoolwinrt.dll - ok
    23:46:02.0263 4888 [ 797769FC191B03A01661CB5F855CFD30 ] C:\Windows\System32\biwinrt.dll
    23:46:02.0263 4888 C:\Windows\System32\biwinrt.dll - ok
    23:46:02.0265 4888 [ 56C91F36ADE867F0EDFE0BC6179AC2BC ] C:\Windows\System32\WPDShServiceObj.dll
    23:46:02.0265 4888 C:\Windows\System32\WPDShServiceObj.dll - ok
    23:46:02.0267 4888 [ AC89ADD10CDAC8D5647928FBE5B94621 ] C:\Windows\System32\PortableDeviceTypes.dll
    23:46:02.0267 4888 C:\Windows\System32\PortableDeviceTypes.dll - ok
    23:46:02.0268 4888 [ 4681211F6D66604F34646FA6EB84D989 ] C:\Program Files\Windows Portable Devices\sqmapi.dll
    23:46:02.0268 4888 C:\Program Files\Windows Portable Devices\sqmapi.dll - ok
    23:46:02.0270 4888 [ B5198D9837E0EC371EF0D3F5BE423C61 ] C:\Windows\System32\SettingMonitor.dll
    23:46:02.0270 4888 C:\Windows\System32\SettingMonitor.dll - ok
    23:46:02.0272 4888 [ 797119E1F2752761610CDAA02CC472A3 ] C:\Windows\System32\IME\SHARED\IMEROAMING.DLL
    23:46:02.0272 4888 C:\Windows\System32\IME\SHARED\IMEROAMING.DLL - ok
    23:46:02.0274 4888 [ AAB25C7F73532849DE843C563BADA8CF ] C:\Windows\System32\PackageStateRoaming.dll
    23:46:02.0274 4888 C:\Windows\System32\PackageStateRoaming.dll - ok
    23:46:02.0276 4888 [ A084CB0B1898CE603EEF210DF7C13C2D ] C:\Windows\System32\pnidui.dll
    23:46:02.0276 4888 C:\Windows\System32\pnidui.dll - ok
    23:46:02.0277 4888 [ 4B5A42E0FDD2012B6940CC14F447E8D8 ] C:\Windows\System32\NcaApi.dll
    23:46:02.0277 4888 C:\Windows\System32\NcaApi.dll - ok
    23:46:02.0279 4888 [ 5BB92B4A3DDB7FB2D9085F7F7A771512 ] C:\Windows\System32\ieframe.dll
    23:46:02.0279 4888 C:\Windows\System32\ieframe.dll - ok
    23:46:02.0282 4888 [ 0208CAE5E09FA01DA2649702AE9616F6 ] C:\Windows\System32\srchadmin.dll
    23:46:02.0282 4888 C:\Windows\System32\srchadmin.dll - ok
    23:46:02.0284 4888 [ E7BE2296105069DA0C8F9206F070C6EF ] C:\Windows\System32\SearchIndexer.exe
    23:46:02.0284 4888 C:\Windows\System32\SearchIndexer.exe - ok
    23:46:02.0285 4888 [ AAA384C8F6412103973518D60FCEAAD0 ] C:\Windows\System32\bthprops.cpl
    23:46:02.0285 4888 C:\Windows\System32\bthprops.cpl - ok
    23:46:02.0287 4888 [ D8DCEE270674DDB6503730CC4C2F1691 ] C:\Windows\System32\BluetoothApis.dll
    23:46:02.0287 4888 C:\Windows\System32\BluetoothApis.dll - ok
    23:46:02.0289 4888 [ 7CEE52B25CA677E5B62DC00E3BD3BBCE ] C:\Windows\System32\ActionCenter.dll
    23:46:02.0289 4888 C:\Windows\System32\ActionCenter.dll - ok
    23:46:02.0291 4888 [ D9309C43C47D40315585871D9C6FED3C ] C:\Windows\System32\tquery.dll
    23:46:02.0291 4888 C:\Windows\System32\tquery.dll - ok
    23:46:02.0293 4888 [ 78E10345A0A592BDDACFB40EB8444B5B ] C:\Windows\System32\mssrch.dll
    23:46:02.0293 4888 C:\Windows\System32\mssrch.dll - ok
    23:46:02.0295 4888 [ 94F97611FFCFF810BF8CB0D467BADA60 ] C:\Windows\System32\msidle.dll
    23:46:02.0295 4888 C:\Windows\System32\msidle.dll - ok
    23:46:02.0296 4888 [ C3C9A444FA26DB4B993AE3DA6C3DD683 ] C:\Windows\System32\mssprxy.dll
    23:46:02.0296 4888 C:\Windows\System32\mssprxy.dll - ok
    23:46:02.0298 4888 [ CF4657A43B56ED26875C26DFE698DCCB ] C:\Windows\System32\SearchProtocolHost.exe
    23:46:02.0298 4888 C:\Windows\System32\SearchProtocolHost.exe - ok
    23:46:02.0300 4888 [ 924DAF97890A77590835B83E53CEC382 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.dll
    23:46:02.0300 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.dll - ok
    23:46:02.0302 4888 [ 16B0D0C1D0CFDB8F5F3DE9849487B509 ] C:\Windows\System32\SyncCenter.dll
    23:46:02.0302 4888 C:\Windows\System32\SyncCenter.dll - ok
    23:46:02.0303 4888 [ 255F0624A5A33EBB0FC545BDD2A9CB36 ] C:\Windows\System32\msshooks.dll
    23:46:02.0304 4888 C:\Windows\System32\msshooks.dll - ok
    23:46:02.0305 4888 [ 805AD714EF4126BE2D2390D446CA4280 ] C:\Windows\System32\imapi2.dll
    23:46:02.0305 4888 C:\Windows\System32\imapi2.dll - ok
    23:46:02.0307 4888 [ EC65798B20CF6B9D9581B0F896A72AB2 ] C:\Windows\System32\SearchFilterHost.exe
    23:46:02.0307 4888 C:\Windows\System32\SearchFilterHost.exe - ok
    23:46:02.0309 4888 [ 2EBA0464A93CA18F50269DC10CEB3CFE ] C:\Windows\System32\mssph.dll
    23:46:02.0309 4888 C:\Windows\System32\mssph.dll - ok
    23:46:02.0311 4888 [ B16BA8C18B51D0FDF120B1ED4E07C399 ] C:\Windows\System32\hgcpl.dll
    23:46:02.0311 4888 C:\Windows\System32\hgcpl.dll - ok
    23:46:02.0312 4888 [ D7507B2F96098C43D1BC835F8B8E5E8E ] C:\Windows\System32\mapi32.dll
    23:46:02.0312 4888 C:\Windows\System32\mapi32.dll - ok
    23:46:02.0314 4888 [ 30454C0337F045E79C2906E9DC039CC5 ] C:\Windows\System32\RuntimeBroker.exe
    23:46:02.0314 4888 C:\Windows\System32\RuntimeBroker.exe - ok
    23:46:02.0316 4888 [ 45005B77B9DACCE166D44ADA87240325 ] C:\Windows\System32\Windows.ApplicationModel.dll
    23:46:02.0316 4888 C:\Windows\System32\Windows.ApplicationModel.dll - ok
    23:46:02.0318 4888 [ AE216A0329FAC7804DC4DFEA49254F0D ] C:\Windows\System32\ntshrui.dll
    23:46:02.0318 4888 C:\Windows\System32\ntshrui.dll - ok
    23:46:02.0319 4888 [ 7308CF302FAD17A77A2EB87ACE9185E0 ] C:\Windows\System32\networkexplorer.dll
    23:46:02.0319 4888 C:\Windows\System32\networkexplorer.dll - ok
    23:46:02.0321 4888 [ 520C138EB08059060D30C92BE5F817FE ] C:\Windows\System32\msiltcfg.dll
    23:46:02.0321 4888 C:\Windows\System32\msiltcfg.dll - ok
    23:46:02.0323 4888 [ DA3021EFAC1D185AC725AFCCD3398521 ] C:\Windows\System32\msi.dll
    23:46:02.0323 4888 C:\Windows\System32\msi.dll - ok
    23:46:02.0325 4888 [ 2C63A256E18DA5CE4504A26C77691887 ] C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL
    23:46:02.0325 4888 C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL - ok
    23:46:02.0327 4888 [ 53A3DE22A97A40469FC6AEB54A151A61 ] C:\Windows\System32\atl100.dll
    23:46:02.0327 4888 C:\Windows\System32\atl100.dll - ok
    23:46:02.0329 4888 [ 7FA6470C89F68656D0D86A59177273CD ] C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    23:46:02.0329 4888 C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll - ok
    23:46:02.0331 4888 [ 8F6A65D15A0CB3653E2CA3A3B937F6B6 ] C:\Windows\System32\EhStorShell.dll
    23:46:02.0331 4888 C:\Windows\System32\EhStorShell.dll - ok
    23:46:02.0333 4888 [ DA5A90BB728583D7A5988D3C5D67EB64 ] C:\Windows\System32\mfsrcsnk.dll
    23:46:02.0333 4888 C:\Windows\System32\mfsrcsnk.dll - ok
    23:46:02.0335 4888 [ 0ABA7E925E54A222331B16BEF25A5958 ] C:\Program Files (x86)\Google\Drive\googledrivesync64.dll
    23:46:02.0335 4888 C:\Program Files (x86)\Google\Drive\googledrivesync64.dll - ok
    23:46:02.0337 4888 [ 1717CE7906AB980501948CEC53DFF636 ] C:\Windows\System32\mfplat.dll
    23:46:02.0337 4888 C:\Windows\System32\mfplat.dll - ok
    23:46:02.0339 4888 [ F8DA5BD9CDAA3B49A253F72843D9B869 ] C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcp90.dll
    23:46:02.0339 4888 C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcp90.dll - ok
    23:46:02.0341 4888 [ D876B344E40D4B4960C4B0FE1EE1A884 ] C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcr90.dll
    23:46:02.0341 4888 C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcr90.dll - ok
    23:46:02.0343 4888 [ B447650079883B58626DD6BBAE857877 ] C:\Windows\System32\NaturalLanguage6.dll
    23:46:02.0343 4888 C:\Windows\System32\NaturalLanguage6.dll - ok
    23:46:02.0345 4888 [ 49E2346A397A7512DD9D12E1D6D9A174 ] C:\Windows\System32\NlsData0009.dll
    23:46:02.0345 4888 C:\Windows\System32\NlsData0009.dll - ok
    23:46:02.0346 4888 [ 47DCA6F50C1D1E93F4DB5248557ED63C ] C:\Windows\System32\NlsLexicons0009.dll
    23:46:02.0346 4888 C:\Windows\System32\NlsLexicons0009.dll - ok
    23:46:02.0348 4888 [ 7BBA721129208393DD4E9F34C01B37AD ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Shared.Market.dll
    23:46:02.0348 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Shared.Market.dll - ok
    23:46:02.0350 4888 [ AEE89C0F144223B97EEDBAAE41CE181A ] C:\Windows\System32\wpnapps.dll
    23:46:02.0350 4888 C:\Windows\System32\wpnapps.dll - ok
    23:46:02.0352 4888 [ 38175536133BDC9324910582250CB8DD ] C:\Windows\System32\taskeng.exe
    23:46:02.0352 4888 C:\Windows\System32\taskeng.exe - ok
    23:46:02.0354 4888 [ BC61E429D78796F292D5E9A71C3A967F ] C:\Windows\System32\TSChannel.dll
    23:46:02.0354 4888 C:\Windows\System32\TSChannel.dll - ok
    23:46:02.0356 4888 [ 506708142BC63DABA64F2D3AD1DCD5BF ] C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    23:46:02.0356 4888 C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - ok
    23:46:02.0358 4888 [ F3D0469E044672E6C57ABBEFDCE6CC85 ] C:\Windows\System32\netshell.dll
    23:46:02.0358 4888 C:\Windows\System32\netshell.dll - ok
    23:46:02.0360 4888 [ 07F7AE68602448F4B6D5A9A40BBA977C ] C:\Program Files (x86)\Google\Update\1.3.21.124\goopdate.dll
    23:46:02.0360 4888 C:\Program Files (x86)\Google\Update\1.3.21.124\goopdate.dll - ok
    23:46:02.0363 4888 [ E4B3CE98A6DBE4B609133C045D2C8525 ] C:\Windows\SysWOW64\cscapi.dll
    23:46:02.0363 4888 C:\Windows\SysWOW64\cscapi.dll - ok
    23:46:02.0365 4888 [ 5125C1F27F8537F33076D0C0151F6B7F ] C:\Windows\SysWOW64\dbghelp.dll
    23:46:02.0365 4888 C:\Windows\SysWOW64\dbghelp.dll - ok
    23:46:02.0367 4888 [ AE5A69F44C1F97EDC83237FC0B29B6FB ] C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe
    23:46:02.0367 4888 C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe - ok
    23:46:02.0369 4888 [ 41938F2C1642459CBBA691B5DBD6395A ] C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler64.exe
    23:46:02.0369 4888 C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler64.exe - ok
    23:46:02.0370 4888 [ D635063008E82F77E9E4563F4C987DDD ] C:\Windows\SysWOW64\mstask.dll
    23:46:02.0370 4888 C:\Windows\SysWOW64\mstask.dll - ok
    23:46:02.0372 4888 [ 649C7C38E573F1ACD68E23C0EDC941A4 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Calendar.dll
    23:46:02.0372 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Calendar.dll - ok
    23:46:02.0374 4888 [ 866A50DD5376C6DE69A09471CE44A173 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Eas.dll
    23:46:02.0374 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Eas.dll - ok
    23:46:02.0376 4888 [ 68A793E65ABDB4FC74D5975AA7761968 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\ModernChat\app\Components\ConversationSystem\Dll\Microsoft.WindowsLive.Chat.ChatSystem.dll
    23:46:02.0376 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\ModernChat\app\Components\ConversationSystem\Dll\Microsoft.WindowsLive.Chat.ChatSystem.dll - ok
    23:46:02.0378 4888 [ CC47BA87C1929948D737876AD7F79C5E ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.PresenceIM.dll
    23:46:02.0378 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.PresenceIM.dll - ok
    23:46:02.0380 4888 [ 37360B977F4711E694D99F9EC8BC4049 ] C:\Windows\System32\AuthBroker.dll
    23:46:02.0380 4888 C:\Windows\System32\AuthBroker.dll - ok
    23:46:02.0382 4888 [ 88A4A2C413BAA86B774D727B05F3FA15 ] C:\Windows\System32\profext.dll
    23:46:02.0382 4888 C:\Windows\System32\profext.dll - ok
    23:46:02.0383 4888 ============================================================
    23:46:02.0383 4888 Scan finished
    23:46:02.0383 4888 ============================================================
    23:46:02.0387 4880 Detected object count: 1
    23:46:02.0388 4880 Actual detected object count: 1
    23:47:06.0084 4880 C:\Program Files (x86)\WinPcap\rpcapd.exe - copied to quarantine
    23:47:06.0084 4880 HKLM\SYSTEM\ControlSet001\services\rpcapd - will be deleted on reboot
    23:47:06.0096 4880 C:\Program Files (x86)\WinPcap\rpcapd.exe - will be deleted on reboot
    23:47:06.0096 4880 rpcapd ( UnsignedFile.Multi.Generic ) - User select action: Delete
  13. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    Are there few more lines or that's it?
  14. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    That was it.
  15. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    =========================

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.

    =========================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
  16. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    # AdwCleaner v2.105 - Logfile created 01/14/2013 at 00:02:33
    # Updated 08/01/2013 by Xplode
    # Operating system : Windows 8 (64 bits)
    # User : DJ - PARKER
    # Boot Mode : Normal
    # Running from : C:\Users\DJ\Desktop\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****


    ***** [Files / Folders] *****

    Folder Deleted : C:\Program Files (x86)\Conduit
    Folder Deleted : C:\Program Files (x86)\uTorrentControl_v2
    Folder Deleted : C:\Users\DJ\AppData\Local\Conduit
    Folder Deleted : C:\Users\DJ\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\DJ\AppData\LocalLow\uTorrentControl_v2

    ***** [Registry] *****

    Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
    Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
    Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
    Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
    Key Deleted : HKCU\Software\AppDataLow\Toolbar
    Key Deleted : HKCU\Software\Conduit
    Key Deleted : HKCU\Software\Cr_Installer
    Key Deleted : HKCU\Software\InstalledBrowserExtensions
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\uTorrentControl_v2
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.BHO
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.BHO.1
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.Sandbox
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.Sandbox.1
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Deleted : HKLM\Software\uTorrentControl_v2
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36CCDB35-EBCC-4FE4-B067-DB960FE780FD}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{683303AA-F768-430D-B852-3A125B4D1832}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v10.0.9200.16453

    Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3220468 --> hxxp://www.google.com

    -\\ Google Chrome v24.0.1312.52

    File : C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Preferences

    Deleted [l.16] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT3220468&SearchSource=48"[...]
    Deleted [l.3355] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT3220468&SearchSource=48" ]

    *************************

    AdwCleaner[S1].txt - [3949 octets] - [14/01/2013 00:02:33]

    ########## EOF - C:\AdwCleaner[S1].txt - [4009 octets] ##########
  17. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    JRT won't run. I open it, and a command prompt wiindow just opens and closes
  18. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    I already disabled AVG
  19. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    OTL logfile created on: 1/14/2013 12:13:44 AM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\DJ\Downloads
    64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
    Internet Explorer (Version = 9.10.9200.16453)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    15.96 Gb Total Physical Memory | 13.34 Gb Available Physical Memory | 83.60% Memory free
    18.21 Gb Paging File | 14.95 Gb Available in Paging File | 82.10% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 55.90 Gb Total Space | 13.72 Gb Free Space | 24.55% Space Free | Partition Type: NTFS
    Drive D: | 350.00 Mb Total Space | 297.25 Mb Free Space | 84.93% Space Free | Partition Type: NTFS
    Drive E: | 1396.92 Gb Total Space | 1142.41 Gb Free Space | 81.78% Space Free | Partition Type: NTFS
    Drive G: | 1.91 Gb Total Space | 0.25 Gb Free Space | 12.83% Space Free | Partition Type: FAT

    Computer Name: PARKER | User Name: DJ | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2013/01/14 00:13:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\DJ\Downloads\OTL.exe
    PRC - [2013/01/07 19:06:24 | 001,248,360 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    PRC - [2012/12/31 14:12:56 | 001,354,736 | ---- | M] (Valve Corporation) -- E:\Program Files (x86)\Steam\Steam.exe
    PRC - [2012/12/26 10:02:44 | 000,541,760 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    PRC - [2012/12/17 19:50:28 | 016,328,976 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    PRC - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/12/14 16:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    PRC - [2012/12/11 03:52:44 | 003,147,384 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe
    PRC - [2012/11/15 23:34:30 | 005,814,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    PRC - [2012/11/13 14:08:08 | 003,825,176 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    PRC - [2012/11/13 14:07:24 | 000,168,384 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    PRC - [2012/11/13 14:07:20 | 001,369,624 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    PRC - [2012/11/13 14:07:16 | 001,103,392 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    PRC - [2012/10/22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    PRC - [2012/10/22 13:04:06 | 000,329,848 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe


    ========== Modules (No Company Name) ==========

    MOD - [2013/01/14 00:03:58 | 001,169,408 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._core_.pyd
    MOD - [2013/01/14 00:03:58 | 001,056,256 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._controls_.pyd
    MOD - [2013/01/14 00:03:58 | 001,024,616 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\windows._cacheinvalidation.pyd
    MOD - [2013/01/14 00:03:58 | 000,807,424 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._windows_.pyd
    MOD - [2013/01/14 00:03:58 | 000,792,576 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._gdi_.pyd
    MOD - [2013/01/14 00:03:58 | 000,731,136 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._misc_.pyd
    MOD - [2013/01/14 00:03:58 | 000,645,120 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_ssl.pyd
    MOD - [2013/01/14 00:03:58 | 000,585,728 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\unicodedata.pyd
    MOD - [2013/01/14 00:03:58 | 000,571,392 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pysqlite2._sqlite.pyd
    MOD - [2013/01/14 00:03:58 | 000,354,304 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pythoncom26.dll
    MOD - [2013/01/14 00:03:58 | 000,311,808 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_hashlib.pyd
    MOD - [2013/01/14 00:03:58 | 000,263,168 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32com.shell.shell.pyd
    MOD - [2013/01/14 00:03:58 | 000,153,088 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pyexpat.pyd
    MOD - [2013/01/14 00:03:58 | 000,121,856 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._wizard.pyd
    MOD - [2013/01/14 00:03:58 | 000,111,104 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32file.pyd
    MOD - [2013/01/14 00:03:58 | 000,110,592 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32security.pyd
    MOD - [2013/01/14 00:03:58 | 000,110,592 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pywintypes26.dll
    MOD - [2013/01/14 00:03:58 | 000,096,256 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32api.pyd
    MOD - [2013/01/14 00:03:58 | 000,086,016 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_elementtree.pyd
    MOD - [2013/01/14 00:03:58 | 000,073,728 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_ctypes.pyd
    MOD - [2013/01/14 00:03:58 | 000,070,656 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._html2.pyd
    MOD - [2013/01/14 00:03:58 | 000,040,448 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_socket.pyd
    MOD - [2013/01/14 00:03:58 | 000,039,424 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32inet.pyd
    MOD - [2013/01/14 00:03:58 | 000,036,352 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32process.pyd
    MOD - [2013/01/14 00:03:58 | 000,023,040 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32ts.pyd
    MOD - [2013/01/14 00:03:58 | 000,022,528 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32pdh.pyd
    MOD - [2013/01/14 00:03:58 | 000,017,920 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32profile.pyd
    MOD - [2013/01/14 00:03:58 | 000,017,920 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32event.pyd
    MOD - [2013/01/14 00:03:58 | 000,011,776 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32crypt.pyd
    MOD - [2013/01/14 00:03:58 | 000,011,776 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\select.pyd
    MOD - [2013/01/07 19:06:22 | 000,460,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppgooglenaclpluginchrome.dll
    MOD - [2013/01/07 19:06:21 | 012,459,624 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll
    MOD - [2013/01/07 19:06:19 | 004,012,648 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll
    MOD - [2013/01/07 19:05:29 | 000,598,120 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\libglesv2.dll
    MOD - [2013/01/07 19:05:28 | 000,124,520 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\libegl.dll
    MOD - [2013/01/07 19:05:25 | 001,553,000 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ffmpegsumo.dll
    MOD - [2012/12/31 14:15:47 | 000,647,168 | ---- | M] () -- E:\Program Files (x86)\Steam\sdl.dll
    MOD - [2012/12/26 10:02:43 | 020,320,240 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\libcef.dll
    MOD - [2012/12/26 10:02:43 | 001,100,800 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\avcodec-53.dll
    MOD - [2012/12/26 10:02:43 | 000,969,280 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\chromehtml.dll
    MOD - [2012/12/26 10:02:43 | 000,192,000 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\avformat-53.dll
    MOD - [2012/12/26 10:02:43 | 000,124,416 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\avutil-51.dll
    MOD - [2012/11/13 14:06:32 | 000,158,624 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    MOD - [2012/11/13 14:06:30 | 000,108,960 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    MOD - [2012/11/13 14:06:28 | 000,554,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl
    MOD - [2012/11/13 14:06:28 | 000,528,288 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl
    MOD - [2012/11/13 14:06:28 | 000,416,160 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl


    ========== Services (SafeList) ==========

    SRV:64bit: - [2012/12/05 23:23:00 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
    SRV:64bit: - [2012/12/05 23:22:59 | 000,178,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
    SRV:64bit: - [2012/11/05 23:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
    SRV:64bit: - [2012/11/05 23:17:41 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
    SRV:64bit: - [2012/10/18 04:52:28 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV:64bit: - [2012/09/20 04:10:47 | 002,367,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
    SRV:64bit: - [2012/09/20 01:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
    SRV:64bit: - [2012/09/20 01:30:41 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
    SRV:64bit: - [2012/07/25 22:17:59 | 000,015,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
    SRV:64bit: - [2012/07/25 22:08:04 | 001,968,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
    SRV:64bit: - [2012/07/25 22:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
    SRV:64bit: - [2012/07/25 22:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
    SRV:64bit: - [2012/07/25 22:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
    SRV:64bit: - [2012/07/25 22:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
    SRV:64bit: - [2012/07/25 22:06:36 | 000,463,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
    SRV:64bit: - [2012/07/25 22:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
    SRV:64bit: - [2012/07/25 22:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
    SRV:64bit: - [2012/07/25 22:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
    SRV:64bit: - [2012/07/25 22:06:00 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
    SRV:64bit: - [2012/07/25 22:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
    SRV:64bit: - [2012/07/25 22:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
    SRV:64bit: - [2012/07/25 22:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
    SRV:64bit: - [2012/07/25 22:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
    SRV:64bit: - [2012/07/25 22:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
    SRV:64bit: - [2012/07/11 13:54:58 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
    SRV - [2013/01/08 17:39:18 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/12/26 10:02:44 | 000,541,760 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2012/11/15 23:34:30 | 005,814,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)
    SRV - [2012/11/09 14:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/11/05 23:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
    SRV - [2012/10/22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd)
    SRV - [2012/07/25 22:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/11/27 02:00:32 | 000,194,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2012/11/26 23:36:16 | 000,208,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgwfpa.sys -- (Avgwfpa)
    DRV:64bit: - [2012/11/26 22:56:29 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
    DRV:64bit: - [2012/11/26 22:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
    DRV:64bit: - [2012/11/19 23:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
    DRV:64bit: - [2012/11/15 23:33:24 | 000,111,968 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgmfx64.sys -- (Avgmfx64)
    DRV:64bit: - [2012/11/06 02:52:07 | 000,445,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
    DRV:64bit: - [2012/11/06 02:36:23 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
    DRV:64bit: - [2012/11/05 22:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
    DRV:64bit: - [2012/10/26 04:17:44 | 000,020,912 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\avgboota.sys -- (Avgboota)
    DRV:64bit: - [2012/10/22 13:02:44 | 000,154,464 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgidsdrivera.sys -- (AVGIDSDriver)
    DRV:64bit: - [2012/10/18 04:52:18 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)
    DRV:64bit: - [2012/10/18 04:52:16 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2012/10/15 03:48:50 | 000,063,328 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\avgidsha.sys -- (AVGIDSHA)
    DRV:64bit: - [2012/10/12 03:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
    DRV:64bit: - [2012/10/11 02:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
    DRV:64bit: - [2012/10/11 02:13:49 | 000,058,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)
    DRV:64bit: - [2012/10/02 03:30:38 | 000,185,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgldx64.sys -- (Avgldx64)
    DRV:64bit: - [2012/09/21 03:46:00 | 000,225,120 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\avgloga.sys -- (Avgloga)
    DRV:64bit: - [2012/09/20 02:55:33 | 000,337,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
    DRV:64bit: - [2012/09/20 02:55:33 | 000,212,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
    DRV:64bit: - [2012/09/20 02:55:30 | 000,120,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
    DRV:64bit: - [2012/09/20 02:55:29 | 000,028,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
    DRV:64bit: - [2012/09/20 02:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2012/09/20 02:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2012/09/20 02:03:08 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
    DRV:64bit: - [2012/09/14 03:05:18 | 000,040,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgrkx64.sys -- (Avgrkx64)
    DRV:64bit: - [2012/08/21 11:56:38 | 000,091,648 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\AtihdW86.sys -- (AtiHDAudioService)
    DRV:64bit: - [2012/07/26 00:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/07/26 00:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
    DRV:64bit: - [2012/07/26 00:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
    DRV:64bit: - [2012/07/26 00:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
    DRV:64bit: - [2012/07/26 00:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
    DRV:64bit: - [2012/07/26 00:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,283,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,077,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2012/07/26 00:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2012/07/26 00:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
    DRV:64bit: - [2012/07/26 00:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2012/07/26 00:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
    DRV:64bit: - [2012/07/26 00:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
    DRV:64bit: - [2012/07/26 00:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2012/07/26 00:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
    DRV:64bit: - [2012/07/26 00:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2012/07/26 00:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2012/07/25 23:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
    DRV:64bit: - [2012/07/25 23:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
    DRV:64bit: - [2012/07/25 23:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
    DRV:64bit: - [2012/07/25 23:44:30 | 000,258,288 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
    DRV:64bit: - [2012/07/25 23:36:15 | 000,034,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
    DRV:64bit: - [2012/07/25 22:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
    DRV:64bit: - [2012/07/25 21:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
    DRV:64bit: - [2012/07/25 21:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
    DRV:64bit: - [2012/07/25 21:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
    DRV:64bit: - [2012/07/25 21:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
    DRV:64bit: - [2012/07/25 21:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
    DRV:64bit: - [2012/07/25 21:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
    DRV:64bit: - [2012/07/25 21:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
    DRV:64bit: - [2012/07/25 21:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
    DRV:64bit: - [2012/07/25 21:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
    DRV:64bit: - [2012/07/25 21:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
    DRV:64bit: - [2012/07/25 21:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
    DRV:64bit: - [2012/07/25 21:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
    DRV:64bit: - [2012/07/25 21:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
    DRV:64bit: - [2012/07/25 21:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
    DRV:64bit: - [2012/07/25 21:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
    DRV:64bit: - [2012/07/25 21:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
    DRV:64bit: - [2012/07/25 21:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2012/07/25 21:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
    DRV:64bit: - [2012/07/25 21:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
    DRV:64bit: - [2012/07/25 21:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
    DRV:64bit: - [2012/07/25 21:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
    DRV:64bit: - [2012/06/02 09:31:56 | 000,589,824 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168)
    DRV:64bit: - [2012/05/22 14:53:16 | 000,694,416 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RTL8192su.sys -- (RTL8192su)
    DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
    DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
    DRV:64bit: - [2010/10/20 02:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\HECIx64.sys -- (MEIx64)
    DRV - [2003/04/04 15:07:20 | 000,030,336 | ---- | M] (Politecnico di Torino) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\npf.sys -- (NPF)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========
  20. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DC 2A 58 E8 5A E9 CD 01 [binary data]
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


    ========== FireFox ==========

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\DJ\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\DJ\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\pokki.com/PokkiDownloadHelper: C:\Users\DJ\AppData\Local\Pokki\Download Helper\npPokkiDownloadHelper.1.2.0.78.dll (Pokki)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}: C:\Program Files (x86)\RelevantKnowledge\firefox

    [2013/01/03 07:28:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DJ\AppData\Roaming\mozilla\Firefox\extensions
    [2013/01/03 07:28:28 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\DJ\AppData\Roaming\mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
    [2012/10/01 20:43:54 | 000,034,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll
    CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll
    CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    CHR - plugin: Microsoft Office 2013 (Enabled) = C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
    CHR - plugin: Microsoft Office 2013 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
    CHR - plugin: Pokki Download Helper (Enabled) = C:\Users\DJ\AppData\Local\Pokki\Download Helper\npPokkiDownloadHelper.1.2.0.78.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
    CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
    CHR - Extension: No Hulu Ads = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdjcidbbokfiifpnpcglbehanlligmlh\1.3.5_0\
    CHR - Extension: Strict Pomodoro = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgmnfnmlficgeijcalkgnnkigkefkbhd\1.5.0.5_0\
    CHR - Extension: Facebook Courage Wolf = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfejcfgfpcifgkniepcdakpiplpjgam\0.0.0.2_0\
    CHR - Extension: Facebook Friend Inviter = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\fojfflomljfbdfdcfmiihnijjfnnakdn\1.1_0\
    CHR - Extension: AdBlock = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.54_0\
    CHR - Extension: Netflix Enhancements = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\glefmeoggphbdgeddmnmhfejpiipcmlf\0.2.3_0\
    CHR - Extension: Memorize! = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfiakckbklmccchjegnnojbalafebakb\1.4.5_0\
    CHR - Extension: Reddit Enhancement Suite = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.1.5_0\
    CHR - Extension: Edit Any Page = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbjnggcjnmmicalchfiljffebcmfgcbh\1.2_0\
    CHR - Extension: Ti\u00EBsto = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnmeobddjkkgkglnogihcaejaleikhdh\2_0\
    CHR - Extension: Hover Zoom = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl\4.8.3_0\
    CHR - Extension: Instagram for Chrome = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb\3.5.8_0\
    CHR - Extension: Facebook Invite All Subrange = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlacnclhiinhhoaonnoflhaoaklmfek\0.1.1_0\

    O1 HOSTS File: ([2012/07/26 00:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (Coupon Companion Plugin) - {11111111-1111-1111-1111-110211181104} - C:\Program Files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll (215 Apps)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
    O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
    O4 - HKLM..\Run: [StartCCC] e:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [Spybot-S&D Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [Steam] E:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [uTorrent] e:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1517A28E-FBC3-4EDA-99E5-A32C81D05C19}: DhcpNameServer = 192.168.1.1
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18 - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
    O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
    O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found
    O29 - HKLM SecurityProviders - (credssp.dll) - File not found
    O30 - LSA: Security Packages - (livessp) - File not found
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2013/01/14 01:50:10 | 000,000,000 | ---D | C] -- C:\FRST
    [2013/01/14 00:08:09 | 000,499,023 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\DJ\Desktop\JRT (3).exe
    [2013/01/14 00:05:59 | 000,000,000 | ---D | C] -- C:\JRT
    [2013/01/13 22:16:38 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\rkill
    [2013/01/13 21:31:43 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\RK_Quarantine
    [2013/01/13 15:56:09 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\tdsskiller
    [2013/01/13 15:32:10 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\SUPERAntiSpyware.com
    [2013/01/13 15:32:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    [2013/01/13 15:32:08 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2013/01/13 15:32:08 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2013/01/13 15:17:07 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
    [2013/01/12 22:51:14 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\Apex Rise Trap Sample Pack 1
    [2013/01/12 22:20:14 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Malwarebytes
    [2013/01/12 22:20:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2013/01/12 22:20:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2013/01/12 22:20:08 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2013/01/12 18:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    [2013/01/12 18:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
    [2013/01/12 18:12:23 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
    [2013/01/12 18:12:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
    [2013/01/12 18:12:05 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Programs
    [2013/01/12 17:33:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\AVG2013
    [2013/01/12 17:32:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\TuneUp Software
    [2013/01/12 17:32:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    [2013/01/12 17:32:21 | 000,000,000 | -H-D | C] -- C:\$AVG
    [2013/01/12 17:32:21 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
    [2013/01/12 17:32:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
    [2013/01/12 17:30:25 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
    [2013/01/12 17:30:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\MFAData
    [2013/01/12 17:30:25 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
    [2013/01/12 17:30:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Avg2013
    [2013/01/12 08:43:25 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
    [2013/01/12 08:42:38 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
    [2013/01/12 08:42:38 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2013/01/12 01:43:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinPcap
    [2013/01/11 22:17:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net Tools
    [2013/01/11 22:17:50 | 000,077,824 | ---- | C] (JVSoftware) -- C:\Windows\SysWow64\nmapwin.exe
    [2013/01/11 22:17:49 | 000,114,688 | ---- | C] (Open Source Telecom) -- C:\Windows\SysWow64\CCGNU32.dll
    [2013/01/11 22:17:45 | 000,010,752 | ---- | C] (Almeida & Andrade Ltda) -- C:\Windows\SysWow64\aamd532.dll
    [2013/01/11 22:17:44 | 000,939,224 | ---- | C] (Macromedia, Inc.) -- C:\Windows\SysWow64\Flash.ocx
    [2013/01/11 22:16:31 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Coupon Companion Plugin
    [2013/01/11 22:16:27 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Updater21804
    [2013/01/11 22:16:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Coupon Companion Plugin
    [2013/01/11 19:33:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKV Player
    [2013/01/10 17:39:05 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Custom Office Templates
    [2013/01/10 17:19:22 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2013/01/10 16:52:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
    [2013/01/10 16:52:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
    [2013/01/10 16:52:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
    [2013/01/10 16:52:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
    [2013/01/10 16:52:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
    [2013/01/10 16:51:58 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
    [2013/01/10 16:51:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
    [2013/01/10 16:49:30 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
    [2013/01/10 16:49:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
    [2013/01/10 16:49:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
    [2013/01/10 16:49:28 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Microsoft Help
    [2013/01/10 16:49:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
    [2013/01/10 16:49:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
    [2013/01/10 16:49:17 | 000,000,000 | RH-D | C] -- C:\MSOCache
    [2013/01/10 16:39:44 | 000,000,000 | --SD | C] -- C:\Users\DJ\Google Drive
    [2013/01/10 16:38:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
    [2013/01/09 19:47:24 | 000,000,000 | R--D | C] -- C:\Users\DJ\Desktop\GLIDE Project
    [2013/01/09 16:49:53 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\The Official Lex Luger Sound Kit (LEWIS CITY)
    [2013/01/09 16:46:58 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\Free.Lex.Luger.Drum.Kits.Samples-Download.FULL.KIT.from.HexLoops.com
    [2013/01/09 07:37:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Native Instruments
    [2013/01/09 07:37:24 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Native Instruments
    [2013/01/09 07:34:49 | 000,000,000 | -H-D | C] -- C:\ProgramData\{E26B3878-7CEC-469C-B449-5CAA336DF8CD}
    [2013/01/09 07:34:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments
    [2013/01/09 07:34:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Native Instruments
    [2013/01/09 07:34:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Digidesign
    [2013/01/09 07:34:39 | 000,000,000 | -H-D | C] -- C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
    [2013/01/09 07:34:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments
    [2013/01/09 07:34:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
    [2013/01/09 07:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Native Instruments
    [2013/01/08 21:53:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Ableton
    [2013/01/08 21:53:02 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\CrashDumps
    [2013/01/08 21:53:01 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Ableton
    [2013/01/08 21:52:29 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Ableton
    [2013/01/08 21:51:54 | 000,368,640 | ---- | C] (Propellerhead Software AB) -- C:\Windows\SysWow64\ReWire.dll
    [2013/01/08 21:51:54 | 000,233,472 | ---- | C] (Propellerhead Software AB) -- C:\Windows\SysWow64\REX Shared Library.dll
    [2013/01/08 21:51:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton
    [2013/01/08 19:55:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\logs
    [2013/01/08 19:55:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\.techniclauncher
    [2013/01/08 19:50:43 | 000,000,000 | ---D | C] -- C:\Program Files\Java
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\ATI
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\ATI
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
    [2013/01/06 19:03:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
    [2013/01/06 19:03:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
    [2013/01/06 19:03:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
    [2013/01/06 19:03:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
    [2013/01/06 19:02:56 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
    [2013/01/06 13:43:15 | 000,000,000 | ---D | C] -- C:\Users\DJ\jagexcache
    [2013/01/05 12:28:49 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\PAYDAY
    [2013/01/05 12:28:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
    [2013/01/05 12:01:43 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Awesomium
    [2013/01/05 12:00:14 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Uber_Entertainment
    [2013/01/05 12:00:13 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\UberLauncher
    [2013/01/05 12:00:05 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
    [2013/01/05 01:38:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft XNA
    [2013/01/05 00:50:18 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Shiner
    [2013/01/04 20:48:07 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\ArmA 2 OA
    [2013/01/04 20:47:16 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\ArmA 2
    [2013/01/04 20:47:16 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\ArmA 2
    [2013/01/04 20:47:13 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2013/01/04 20:47:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2013/01/04 20:46:24 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\DayZCommander
    [2013/01/04 20:23:15 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunt 1.0
    [2013/01/04 16:59:26 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\My Games
    [2013/01/04 16:12:49 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\LolClient
    [2013/01/04 15:53:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    [2013/01/04 15:53:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
    [2013/01/04 15:38:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
    [2013/01/04 15:38:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\.swt
    [2013/01/04 15:36:28 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
    [2013/01/04 15:36:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
    [2013/01/03 21:50:46 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Pokki
    [2013/01/03 18:34:29 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
    [2013/01/03 16:47:07 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\TechSmith
    [2013/01/03 16:47:01 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\TechSmith
    [2013/01/03 16:46:58 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Camtasia Studio
    [2013/01/03 16:46:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
    [2013/01/03 16:46:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
    [2013/01/03 16:46:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TechSmith Shared
    [2013/01/03 16:46:33 | 000,000,000 | ---D | C] -- C:\ProgramData\TechSmith
    [2013/01/03 16:45:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
    [2013/01/03 16:45:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
    [2013/01/03 16:45:15 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
    [2013/01/03 16:45:15 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
    [2013/01/03 16:36:02 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\telltale games
    [2013/01/03 07:28:30 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\CRE
    [2013/01/03 07:28:27 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Mozilla
    [2013/01/03 07:27:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\uTorrent
    [2013/01/03 00:29:54 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
    [2013/01/03 00:29:45 | 000,000,000 | ---D | C] -- C:\Windows\Panther
    [2013/01/03 00:29:24 | 000,000,000 | -HSD | C] -- C:\Boot
    [2013/01/02 22:17:11 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\.minecraft
    [2013/01/02 21:59:30 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\WinRAR
    [2013/01/02 21:59:30 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2013/01/02 21:59:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2013/01/02 21:59:25 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
    [2013/01/02 21:53:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
    [2013/01/02 21:50:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    [2013/01/02 21:46:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
    [2013/01/02 21:42:39 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Macromedia
    [2013/01/02 21:40:47 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Skype
    [2013/01/02 21:40:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    [2013/01/02 21:40:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
    [2013/01/02 21:40:43 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
    [2013/01/02 21:40:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
    [2013/01/02 21:40:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
    [2013/01/02 21:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2013/01/02 21:35:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
    [2013/01/02 21:35:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
    [2013/01/02 21:35:10 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Google
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\Searches
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\Contacts
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    [2013/01/02 21:32:17 | 000,000,000 | -H-D | C] -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
    [2013/01/02 21:32:17 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Adobe
    [2013/01/02 21:32:05 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\VirtualStore
    [2013/01/02 21:32:04 | 000,000,000 | ---D | C] -- C:\ProgramData\PRICache
    [2013/01/02 21:32:04 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Packages
    [2013/01/02 21:32:01 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
    [2013/01/02 21:31:56 | 000,000,000 | --SD | C] -- C:\Users\DJ\AppData\Roaming\Microsoft
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Videos
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Saved Games
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Pictures
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Music
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Links
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Favorites
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Downloads
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Documents
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Desktop
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\AppData\Local\Temporary Internet Files
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Templates
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Start Menu
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\SendTo
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Recent
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\PrintHood
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\NetHood
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Documents\My Videos
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Documents\My Pictures
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Documents\My Music
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\My Documents
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Local Settings
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\AppData\Local\History
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Cookies
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Application Data
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\AppData\Local\Application Data
    [2013/01/02 21:31:56 | 000,000,000 | -H-D | C] -- C:\Users\DJ\AppData
    [2013/01/02 21:31:56 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Temp
    [2013/01/02 21:31:56 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Microsoft
    [2013/01/02 21:31:56 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    [2012/12/26 08:50:21 | 000,000,000 | -HSD | C] -- C:\Recovery
    [2012/12/26 08:49:18 | 000,000,000 | -HSD | C] -- C:\System Volume Information
  21. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    ========== Files - Modified Within 30 Days ==========

    [2013/01/14 00:09:29 | 000,848,230 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2013/01/14 00:09:29 | 000,718,176 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2013/01/14 00:09:29 | 000,132,542 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2013/01/14 00:08:13 | 000,499,023 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\DJ\Desktop\JRT (3).exe
    [2013/01/14 00:05:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2013/01/14 00:03:47 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013/01/14 00:03:24 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
    [2013/01/14 00:03:19 | 826,941,437 | -HS- | M] () -- C:\hiberfil.sys
    [2013/01/14 00:01:30 | 000,554,087 | ---- | M] () -- C:\Users\DJ\Desktop\adwcleaner.exe
    [2013/01/13 23:46:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001UA.job
    [2013/01/13 23:40:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013/01/13 23:39:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2013/01/13 23:32:00 | 000,000,518 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task f80611e4-a410-4fd3-b7c0-1c618bc4f252.job
    [2013/01/13 22:53:20 | 000,002,259 | ---- | M] () -- C:\Users\DJ\Desktop\Google Chrome.lnk
    [2013/01/13 22:42:36 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
    [2013/01/13 21:31:34 | 000,764,416 | ---- | M] () -- C:\Users\DJ\Desktop\RogueKiller.exe
    [2013/01/13 20:46:00 | 000,000,858 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001Core.job
    [2013/01/13 15:55:40 | 002,195,061 | ---- | M] () -- C:\Users\DJ\Desktop\tdsskiller.zip
    [2013/01/13 15:51:07 | 000,000,518 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 31b9111b-1432-484b-927c-d61581e72c2d.job
    [2013/01/13 15:32:09 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2013/01/12 22:47:02 | 000,422,160 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2013/01/12 22:45:20 | 000,001,938 | ---- | M] () -- C:\Windows\wininit.ini
    [2013/01/12 22:20:09 | 000,000,814 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013/01/12 18:12:36 | 000,002,177 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    [2013/01/12 17:34:14 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
    [2013/01/12 17:32:25 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk
    [2013/01/11 22:17:53 | 000,000,730 | ---- | M] () -- C:\Users\DJ\Desktop\NetTools.lnk
    [2013/01/11 19:33:10 | 008,141,967 | ---- | M] ( ) -- C:\Users\DJ\Desktop\MKVPlayerSetupD.exe
    [2013/01/10 17:26:16 | 000,000,953 | ---- | M] () -- C:\Users\DJ\Desktop\Apex Rise Trap Sample Pack 1.lnk
    [2013/01/10 16:39:45 | 000,001,694 | ---- | M] () -- C:\Users\DJ\Desktop\Google Drive.lnk
    [2013/01/09 22:29:21 | 000,329,315 | ---- | M] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav.asd
    [2013/01/09 22:29:04 | 043,446,902 | ---- | M] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav
    [2013/01/09 22:25:51 | 157,686,659 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe.rar
    [2013/01/09 22:08:39 | 000,329,305 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe320.wav.asd
    [2013/01/09 22:07:41 | 231,716,620 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe320.wav
    [2013/01/09 22:00:02 | 000,305,581 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe160.wav.asd
    [2013/01/09 21:59:50 | 026,611,244 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe160.wav
    [2013/01/09 21:49:55 | 000,305,425 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe240.wav.asd
    [2013/01/09 21:34:53 | 000,329,419 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe.wav.asd
    [2013/01/09 21:33:52 | 231,716,620 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe.wav
    [2013/01/09 21:23:17 | 000,332,829 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDE.wav.asd
    [2013/01/09 21:23:02 | 029,030,444 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDE.wav
    [2013/01/09 17:49:18 | 000,305,237 | ---- | M] () -- C:\Users\DJ\Desktop\trap1.wav.asd
    [2013/01/09 17:49:04 | 026,611,244 | ---- | M] () -- C:\Users\DJ\Desktop\trap1.wav
    [2013/01/09 07:34:48 | 000,000,624 | ---- | M] () -- C:\Users\Public\Desktop\Massive.lnk
    [2013/01/09 07:34:38 | 000,001,059 | ---- | M] () -- C:\Users\Public\Desktop\Service Center.lnk
    [2013/01/08 19:55:41 | 000,582,227 | ---- | M] () -- C:\Users\DJ\AppData\Roaming\technic-launcher.jar
    [2013/01/07 20:53:03 | 000,005,632 | ---- | M] () -- C:\Users\DJ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2013/01/06 15:49:01 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Mass Effect.url
    [2013/01/06 15:48:27 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Prototype.url
    [2013/01/06 15:48:13 | 000,000,220 | ---- | M] () -- C:\Users\DJ\Desktop\BioShock.url
    [2013/01/06 15:47:58 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Dead Space.url
    [2013/01/06 15:33:07 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    [2013/01/06 13:49:12 | 000,000,024 | ---- | M] () -- C:\Users\DJ\random.dat
    [2013/01/06 13:43:15 | 000,000,041 | ---- | M] () -- C:\Users\DJ\jagex_cl_runescape_LIVE.dat
    [2013/01/05 01:21:12 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead Beta.url
    [2013/01/04 20:55:17 | 000,001,089 | ---- | M] () -- C:\Users\DJ\Desktop\Steam - Shortcut (2).lnk
    [2013/01/04 20:46:09 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2013/01/04 20:23:15 | 000,001,029 | ---- | M] () -- C:\Users\DJ\Desktop\Haunt 64bit Shortcut.lnk
    [2013/01/04 15:45:11 | 000,000,641 | ---- | M] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
    [2013/01/04 15:31:37 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Amnesia The Dark Descent.url
    [2013/01/04 15:31:34 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\ARMA 2.url
    [2013/01/04 15:31:22 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead.url
    [2013/01/04 15:31:18 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Batman Arkham Asylum GOTY Edition.url
    [2013/01/04 15:31:14 | 000,000,219 | ---- | M] () -- C:\Users\DJ\Desktop\Counter-Strike Source.url
    [2013/01/04 15:31:11 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Dungeon Defenders.url
    [2013/01/04 15:31:07 | 000,000,220 | ---- | M] () -- C:\Users\DJ\Desktop\Garry's Mod.url
    [2013/01/04 15:31:04 | 000,000,218 | ---- | M] () -- C:\Users\DJ\Desktop\Half-Life.url
    [2013/01/04 15:30:55 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Hitman Absolution.url
    [2013/01/04 15:30:51 | 000,000,220 | ---- | M] () -- C:\Users\DJ\Desktop\Killing Floor.url
    [2013/01/04 15:30:45 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Orcs Must Die! 2.url
    [2013/01/04 15:30:42 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\PAYDAY The Heist.url
    [2013/01/04 15:30:21 | 000,000,219 | ---- | M] () -- C:\Users\DJ\Desktop\Portal 2.url
    [2013/01/04 15:30:06 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Super Monday Night Combat.url
    [2013/01/04 15:30:00 | 000,000,219 | ---- | M] () -- C:\Users\DJ\Desktop\Team Fortress 2.url
    [2013/01/04 15:29:47 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Terraria.url
    [2013/01/04 15:29:37 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\The Walking Dead.url
    [2013/01/03 18:34:45 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Mass Effect 2.url
    [2013/01/03 18:34:29 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Torchlight II.url
    [2013/01/03 16:46:42 | 000,000,919 | ---- | M] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
    [2013/01/03 15:11:42 | 015,512,472 | ---- | M] () -- C:\Users\DJ\Documents\****ingdopeasstrapshit.wav
    [2013/01/03 07:28:21 | 000,000,658 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
    [2013/01/03 07:28:21 | 000,000,658 | ---- | M] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
    [2013/01/03 00:30:00 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
    [2013/01/02 21:40:45 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
    [2013/01/02 21:34:51 | 000,001,428 | ---- | M] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

    ========== Files Created - No Company Name ==========

    [2013/01/14 00:01:43 | 000,554,087 | ---- | C] () -- C:\Users\DJ\Desktop\adwcleaner.exe
    [2013/01/13 22:42:36 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
    [2013/01/13 21:31:37 | 000,764,416 | ---- | C] () -- C:\Users\DJ\Desktop\RogueKiller.exe
    [2013/01/13 15:55:51 | 002,195,061 | ---- | C] () -- C:\Users\DJ\Desktop\tdsskiller.zip
    [2013/01/13 15:32:16 | 000,000,518 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task f80611e4-a410-4fd3-b7c0-1c618bc4f252.job
    [2013/01/13 15:32:16 | 000,000,518 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 31b9111b-1432-484b-927c-d61581e72c2d.job
    [2013/01/13 15:32:09 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2013/01/12 22:47:00 | 000,422,160 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2013/01/12 22:30:00 | 000,001,938 | ---- | C] () -- C:\Windows\wininit.ini
    [2013/01/12 22:20:09 | 000,000,814 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013/01/12 18:12:36 | 000,002,189 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    [2013/01/12 18:12:36 | 000,002,177 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    [2013/01/12 17:32:25 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk
    [2013/01/12 08:43:25 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
    [2013/01/11 22:17:53 | 000,000,730 | ---- | C] () -- C:\Users\DJ\Desktop\NetTools.lnk
    [2013/01/11 22:17:50 | 000,809,345 | ---- | C] () -- C:\Windows\SysWow64\nmap-os-fingerprints
    [2013/01/11 22:17:50 | 000,557,444 | ---- | C] () -- C:\Windows\SysWow64\nmap-service-probes
    [2013/01/11 22:17:50 | 000,482,123 | ---- | C] () -- C:\Windows\SysWow64\nmapwin.chm
    [2013/01/11 22:17:50 | 000,452,096 | ---- | C] () -- C:\Windows\SysWow64\nmap.exe
    [2013/01/11 22:17:50 | 000,290,816 | ---- | C] () -- C:\Windows\SysWow64\nmapserv.exe
    [2013/01/11 22:17:50 | 000,225,546 | ---- | C] () -- C:\Windows\SysWow64\nmap-mac-prefixes
    [2013/01/11 22:17:50 | 000,192,007 | ---- | C] () -- C:\Windows\SysWow64\CHANGELOG
    [2013/01/11 22:17:50 | 000,108,536 | ---- | C] () -- C:\Windows\SysWow64\nmap-services
    [2013/01/11 22:17:50 | 000,025,611 | ---- | C] () -- C:\Windows\SysWow64\COPYING
    [2013/01/11 22:17:50 | 000,021,552 | ---- | C] () -- C:\Windows\SysWow64\nmap.xsl
    [2013/01/11 22:17:50 | 000,017,955 | ---- | C] () -- C:\Windows\SysWow64\nmap-rpc
    [2013/01/11 22:17:50 | 000,006,318 | ---- | C] () -- C:\Windows\SysWow64\nmap-protocols
    [2013/01/11 22:17:50 | 000,000,192 | ---- | C] () -- C:\Windows\SysWow64\nmap_performance.reg
    [2013/01/11 22:17:44 | 000,010,348 | ---- | C] () -- C:\Windows\SysWow64\SubclassingSink.tlb
    [2013/01/11 19:33:05 | 008,141,967 | ---- | C] ( ) -- C:\Users\DJ\Desktop\MKVPlayerSetupD.exe
    [2013/01/10 17:26:16 | 000,000,953 | ---- | C] () -- C:\Users\DJ\Desktop\Apex Rise Trap Sample Pack 1.lnk
    [2013/01/10 16:39:45 | 000,001,694 | ---- | C] () -- C:\Users\DJ\Desktop\Google Drive.lnk
    [2013/01/09 22:29:21 | 000,329,315 | ---- | C] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav.asd
    [2013/01/09 22:26:29 | 043,446,902 | ---- | C] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav
    [2013/01/09 22:25:34 | 157,686,659 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe.rar
    [2013/01/09 22:08:39 | 000,329,305 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe320.wav.asd
    [2013/01/09 22:07:41 | 231,716,620 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe320.wav
    [2013/01/09 21:59:50 | 026,611,244 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe160.wav
    [2013/01/09 21:59:50 | 000,305,581 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe160.wav.asd
    [2013/01/09 21:49:55 | 000,305,425 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe240.wav.asd
    [2013/01/09 21:34:53 | 000,329,419 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe.wav.asd
    [2013/01/09 21:32:28 | 231,716,620 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe.wav
    [2013/01/09 21:23:02 | 029,030,444 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDE.wav
    [2013/01/09 21:23:02 | 000,332,829 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDE.wav.asd
    [2013/01/09 17:48:36 | 000,305,237 | ---- | C] () -- C:\Users\DJ\Desktop\trap1.wav.asd
    [2013/01/09 16:41:09 | 000,110,592 | ---- | C] () -- C:\Windows\SysNative\OEMLicense.dll
    [2013/01/09 16:41:09 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
    [2013/01/09 16:28:00 | 026,611,244 | ---- | C] () -- C:\Users\DJ\Desktop\trap1.wav
    [2013/01/09 07:34:48 | 000,000,624 | ---- | C] () -- C:\Users\Public\Desktop\Massive.lnk
    [2013/01/09 07:34:38 | 000,001,059 | ---- | C] () -- C:\Users\Public\Desktop\Service Center.lnk
    [2013/01/08 20:41:10 | 000,000,910 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001UA.job
    [2013/01/08 20:41:10 | 000,000,858 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001Core.job
    [2013/01/08 19:55:40 | 000,582,227 | ---- | C] () -- C:\Users\DJ\AppData\Roaming\technic-launcher.jar
    [2013/01/06 15:49:01 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Mass Effect.url
    [2013/01/06 15:48:27 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Prototype.url
    [2013/01/06 15:48:13 | 000,000,220 | ---- | C] () -- C:\Users\DJ\Desktop\BioShock.url
    [2013/01/06 15:47:58 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Dead Space.url
    [2013/01/06 15:33:07 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    [2013/01/06 13:43:15 | 000,000,041 | ---- | C] () -- C:\Users\DJ\jagex_cl_runescape_LIVE.dat
    [2013/01/06 13:43:15 | 000,000,024 | ---- | C] () -- C:\Users\DJ\random.dat
    [2013/01/05 01:21:12 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead Beta.url
    [2013/01/04 20:55:20 | 000,001,089 | ---- | C] () -- C:\Users\DJ\Desktop\Steam - Shortcut (2).lnk
    [2013/01/04 20:46:09 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2013/01/04 20:23:15 | 000,001,029 | ---- | C] () -- C:\Users\DJ\Desktop\Haunt 64bit Shortcut.lnk
    [2013/01/04 17:20:00 | 000,385,604 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
    [2013/01/04 15:56:24 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2013/01/04 15:45:11 | 000,000,641 | ---- | C] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
    [2013/01/04 15:31:37 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Amnesia The Dark Descent.url
    [2013/01/04 15:31:34 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\ARMA 2.url
    [2013/01/04 15:31:22 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead.url
    [2013/01/04 15:31:14 | 000,000,219 | ---- | C] () -- C:\Users\DJ\Desktop\Counter-Strike Source.url
    [2013/01/04 15:31:11 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Dungeon Defenders.url
    [2013/01/04 15:31:07 | 000,000,220 | ---- | C] () -- C:\Users\DJ\Desktop\Garry's Mod.url
    [2013/01/04 15:31:04 | 000,000,218 | ---- | C] () -- C:\Users\DJ\Desktop\Half-Life.url
    [2013/01/04 15:30:55 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Hitman Absolution.url
    [2013/01/04 15:30:51 | 000,000,220 | ---- | C] () -- C:\Users\DJ\Desktop\Killing Floor.url
    [2013/01/04 15:30:45 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Orcs Must Die! 2.url
    [2013/01/04 15:30:42 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\PAYDAY The Heist.url
    [2013/01/04 15:30:12 | 000,000,219 | ---- | C] () -- C:\Users\DJ\Desktop\Portal 2.url
    [2013/01/04 15:30:06 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Super Monday Night Combat.url
    [2013/01/04 15:30:00 | 000,000,219 | ---- | C] () -- C:\Users\DJ\Desktop\Team Fortress 2.url
    [2013/01/04 15:29:47 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Terraria.url
    [2013/01/04 15:29:37 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\The Walking Dead.url
    [2013/01/03 18:34:58 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Batman Arkham Asylum GOTY Edition.url
    [2013/01/03 18:34:45 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Mass Effect 2.url
    [2013/01/03 18:34:29 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Torchlight II.url
    [2013/01/03 16:58:44 | 000,005,632 | ---- | C] () -- C:\Users\DJ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2013/01/03 16:46:42 | 000,000,919 | ---- | C] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
    [2013/01/03 15:09:32 | 015,512,472 | ---- | C] () -- C:\Users\DJ\Documents\****ingdopeasstrapshit.wav
    [2013/01/03 07:28:21 | 000,000,658 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
    [2013/01/03 07:28:21 | 000,000,658 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
    [2013/01/03 00:30:31 | 826,941,437 | -HS- | C] () -- C:\hiberfil.sys
    [2013/01/03 00:30:00 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2013/01/03 00:29:45 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
    [2013/01/02 21:40:45 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
    [2013/01/02 21:36:09 | 000,002,259 | ---- | C] () -- C:\Users\DJ\Desktop\Google Chrome.lnk
    [2013/01/02 21:35:13 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013/01/02 21:35:13 | 000,000,900 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013/01/02 21:34:51 | 000,001,428 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2013/01/02 21:32:17 | 000,001,434 | ---- | C] () -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    [2013/01/02 21:31:56 | 000,000,352 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
    [2013/01/02 21:31:56 | 000,000,334 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
    [2012/10/18 04:52:18 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
    [2012/10/18 04:52:10 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
    [2012/10/18 04:52:06 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2012/07/26 03:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2012/07/26 03:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2012/07/26 02:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2012/07/25 20:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2012/07/25 15:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2012/07/25 15:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2012/06/02 09:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2012/05/02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll

    ========== ZeroAccess Check ==========

    [2013/01/04 16:58:57 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/11/05 23:19:27 | 019,789,824 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/11/05 23:20:00 | 017,560,576 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/25 22:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/25 22:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/25 22:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    ========== LOP Check ==========

    [2013/01/02 22:36:38 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\.minecraft
    [2013/01/08 19:59:48 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\.techniclauncher
    [2013/01/08 21:53:01 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\Ableton
    [2013/01/12 17:33:25 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\AVG2013
    [2013/01/05 12:27:59 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\Awesomium
    [2013/01/08 19:59:43 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\logs
    [2013/01/04 16:12:49 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\LolClient
    [2013/01/03 16:47:01 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\TechSmith
    [2013/01/12 17:32:25 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\TuneUp Software
    [2013/01/13 22:47:06 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\uTorrent

    ========== Purity Check ==========


    < End of report >
  22. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    Re-run OTL.
    Use the following settings:

    • Click the NONE button
    • Under Custom Scans/Fixes paste:
    Code:
    /md5start
    userinit.exe
    winlogon.exe
    explorer.exe
    /md5stop
    
    • Finally hit Run Scan and wait for the log to open.
    • Please post the content of the log into your next reply.
  23. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    OTL logfile created on: 1/14/2013 3:11:16 PM - Run 2
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\DJ\Downloads
    64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
    Internet Explorer (Version = 9.10.9200.16453)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    15.96 Gb Total Physical Memory | 13.17 Gb Available Physical Memory | 82.51% Memory free
    18.21 Gb Paging File | 14.76 Gb Available in Paging File | 81.04% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 55.90 Gb Total Space | 13.17 Gb Free Space | 23.56% Space Free | Partition Type: NTFS
    Drive D: | 350.00 Mb Total Space | 297.25 Mb Free Space | 84.93% Space Free | Partition Type: NTFS
    Drive E: | 1396.92 Gb Total Space | 1141.91 Gb Free Space | 81.74% Space Free | Partition Type: NTFS
    Drive G: | 1.91 Gb Total Space | 0.25 Gb Free Space | 12.83% Space Free | Partition Type: FAT

    Computer Name: PARKER | User Name: DJ | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

    ========== Custom Scans ==========

    < MD5 for: EXPLORER.EXE >
    [2012/10/11 00:53:24 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
    [2012/10/11 03:09:58 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
    [2012/07/25 22:50:01 | 002,114,936 | ---- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
    [2012/07/25 23:49:13 | 002,380,440 | ---- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
    [2012/10/11 00:56:41 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 -- C:\Windows\SysWOW64\explorer.exe
    [2012/10/11 00:56:41 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
    [2012/10/11 02:35:16 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 -- C:\Windows\explorer.exe
    [2012/10/11 02:35:16 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe
    [2012/11/13 14:07:52 | 003,906,584 | ---- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 -- C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe

    < MD5 for: USERINIT.EXE >
    [2012/07/25 22:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\SysNative\userinit.exe
    [2012/07/25 22:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_34f2617a5b742e02\userinit.exe
    [2012/07/25 22:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\SysWOW64\userinit.exe
    [2012/07/25 22:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_d8d3c5f6a316bccc\userinit.exe

    < MD5 for: WINLOGON.EXE >
    [2012/09/20 01:33:55 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
    [2012/09/20 01:33:17 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
    [2012/07/25 22:08:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
    [2012/10/11 00:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\SysNative\winlogon.exe
    [2012/10/11 00:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe
    [2012/10/11 00:45:27 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe

    < End of report >
  24. Broni

    Broni Malware Annihilator Posts: 46,416   +252

    Is MBAM still complaining?
  25. Parkor

    Parkor Newcomer, in training Topic Starter Posts: 45

    Not as often, and now it's just one ip it's blocking. 213.186.33.87


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.