TechSpot

Malwarebytes Anti-Malware successfully blocked access to a potentially malicious site

By Parkor
Jan 13, 2013
  1. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    2013-01-02 21:30 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\System32\Recovery
    2013-01-02 21:29 - 2013-01-02 21:29 - 00001108 ____A C:\Windows\System32\netcfg-17671.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000185 ____A C:\Windows\System32\netcfg-20843.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000169 ____A C:\Windows\System32\netcfg-19968.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000164 ____A C:\Windows\System32\netcfg-17531.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000161 ____A C:\Windows\System32\netcfg-20562.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000160 ____A C:\Windows\System32\netcfg-20453.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000160 ____A C:\Windows\System32\netcfg-20343.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000160 ____A C:\Windows\System32\netcfg-17421.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000159 ____A C:\Windows\System32\netcfg-20234.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000157 ____A C:\Windows\System32\netcfg-20734.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000157 ____A C:\Windows\System32\netcfg-17296.txt
    2013-01-02 21:29 - 2013-01-02 21:29 - 00000150 ____A C:\Windows\System32\netcfg-20125.txt
    2013-01-02 21:29 - 2012-07-26 00:13 - 00262144 ____A C:\Windows\System32\config\BCD-Template
    2013-01-02 19:38 - 2013-01-02 18:59 - 00000000 ____D C:\Users\DJ\AppData\Roaming\WinRAR
    2013-01-02 19:36 - 2013-01-02 19:17 - 00000000 ____D C:\Users\DJ\AppData\Roaming\.minecraft
    2013-01-02 19:28 - 2013-01-02 18:46 - 00859072 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
    2013-01-02 19:28 - 2013-01-02 18:46 - 00779704 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
    2013-01-02 19:17 - 2013-01-02 19:17 - 00263186 ____A C:\Users\DJ\Downloads\Minecraft.exe
    2013-01-02 19:17 - 2013-01-02 19:16 - 00001518 ____A C:\Users\DJ\Downloads\server.log
    2013-01-02 19:17 - 2013-01-02 19:16 - 00000510 ____A C:\Users\DJ\Downloads\server.properties
    2013-01-02 19:17 - 2013-01-02 19:16 - 00000000 ____D C:\Users\DJ\Downloads\world
    2013-01-02 19:16 - 2013-01-02 19:16 - 02242895 ____A C:\Users\DJ\Downloads\Minecraft_Server.exe
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000109 ____A C:\Users\DJ\Downloads\banned-players.txt
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000109 ____A C:\Users\DJ\Downloads\banned-ips.txt
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000000 ____A C:\Users\DJ\Downloads\white-list.txt
    2013-01-02 19:16 - 2013-01-02 19:16 - 00000000 ____A C:\Users\DJ\Downloads\ops.txt
    2013-01-02 18:59 - 2013-01-02 18:59 - 01656459 ____A C:\Users\DJ\Downloads\winrar-x64-420.exe
    2013-01-02 18:59 - 2013-01-02 18:59 - 00000000 ____D C:\Program Files\WinRAR
    2013-01-02 18:55 - 2013-01-02 18:55 - 00000117 ____A C:\Windows\System32\netcfg-1495234.txt
    2013-01-02 18:55 - 2013-01-02 18:55 - 00000117 ____A C:\Windows\System32\netcfg-1495203.txt
    2013-01-02 18:53 - 2013-01-02 18:53 - 00000000 ____D C:\Program Files (x86)\7-Zip
    2013-01-02 18:50 - 2013-01-02 18:50 - 01110476 ____A C:\Users\DJ\Downloads\7z920.exe
    2013-01-02 18:49 - 2013-01-02 18:49 - 15686819 ____A C:\Users\DJ\Downloads\jdk-7u10-windows-x64-demos.zip
    2013-01-02 18:46 - 2013-01-02 18:46 - 00000000 ____D C:\Users\All Users\Sun
    2013-01-02 18:46 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\System32\restore
    2013-01-02 18:44 - 2013-01-02 18:44 - 00896016 ____A (Oracle Corporation) C:\Users\DJ\Downloads\chromeinstall-7u10.exe
    2013-01-02 18:42 - 2013-01-02 18:42 - 00000000 ____D C:\Users\DJ\AppData\Roaming\Macromedia
    2013-01-02 18:40 - 2013-01-02 18:40 - 00002515 ____A C:\Users\Public\Desktop\Skype.lnk
    2013-01-02 18:40 - 2013-01-02 18:40 - 00000000 ___RD C:\Program Files (x86)\Skype
    2013-01-02 18:40 - 2013-01-02 18:40 - 00000000 ____D C:\Users\All Users\Skype
    2013-01-02 18:40 - 2013-01-02 18:40 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2013-01-02 18:40 - 2013-01-02 18:39 - 29304496 ____A (Skype Technologies S.A.) C:\Users\DJ\Downloads\SkypeSetupFull.exe
    2013-01-02 18:36 - 2013-01-02 18:36 - 00002293 ____A C:\Users\DJ\Desktop\Google Chrome.lnk
    2013-01-02 18:34 - 2013-01-02 18:34 - 00000278 ____A C:\Windows\System32\netcfg-231171.txt
    2013-01-02 18:34 - 2013-01-02 18:34 - 00000117 ____A C:\Windows\System32\netcfg-233750.txt
    2013-01-02 18:34 - 2013-01-02 18:34 - 00000117 ____A C:\Windows\System32\netcfg-230875.txt
    2013-01-02 18:32 - 2013-01-02 18:32 - 00000000 ____D C:\Users\DJ\AppData\Roaming\Adobe
    2013-01-02 18:32 - 2013-01-02 18:32 - 00000000 ____D C:\Users\DJ\AppData\Local\VirtualStore
    2013-01-02 18:32 - 2013-01-02 18:32 - 00000000 ____D C:\Users\All Users\PRICache
    2013-01-02 18:31 - 2013-01-02 21:31 - 00000117 ____A C:\Windows\System32\netcfg-58687.txt
    2013-01-02 18:31 - 2013-01-02 18:31 - 00000020 ___SH C:\Users\DJ\ntuser.ini
    2012-12-18 15:32 - 2012-07-26 00:14 - 00695640 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2012-12-18 15:32 - 2012-07-26 00:14 - 00080728 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2012-12-16 00:28 - 2013-01-03 18:34 - 00046080 ____A (Adobe Systems) C:\Windows\System32\atmlib.dll
    2012-12-16 00:20 - 2013-01-03 18:34 - 00035328 ____A (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2012-12-16 00:08 - 2013-01-03 18:34 - 00362496 ____A (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll
    2012-12-15 23:57 - 2013-01-03 18:34 - 00300032 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2012-12-14 13:49 - 2013-01-12 19:20 - 00024176 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys

    ==================== Known DLLs (Whitelisted) =================
     
  2. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    ==================== Bamital & volsnap Check =================

    C:\Windows\System32\winlogon.exe
    [2013-01-04 14:20] - [2012-10-10 21:46] - 0517120 ____A (Microsoft Corporation) BCF2036A0DD579E47C008C133550283E

    C:\Windows\System32\wininit.exe
    [2012-07-25 16:03] - [2012-07-25 19:08] - 0132608 ____A (Microsoft Corporation) FE9AB232B56A12224E8A3F3F9878C9A3

    C:\Windows\explorer.exe
    [2013-01-04 14:20] - [2012-10-10 23:35] - 2380944 ____A (Microsoft Corporation) E13A31D5254C25406A7946BDD9B06364

    C:\Windows\SysWOW64\explorer.exe
    [2013-01-04 14:20] - [2012-10-10 21:56] - 2115952 ____A (Microsoft Corporation) 953ADECFF08202A01EFC6110214FDE02

    C:\Windows\System32\svchost.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0029696 ____A (Microsoft Corporation) EDE27EACE742EE2888C5DD36400A2EC0

    C:\Windows\SysWOW64\svchost.exe
    [2013-01-09 13:41] - [2012-09-19 21:55] - 0023040 ____A (Microsoft Corporation) A46DC432F81473F526E3994AA483E366

    C:\Windows\System32\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 8F226143046435C75C033B0C52E90FFE

    C:\Windows\System32\User32.dll
    [2013-01-09 13:41] - [2012-09-19 22:33] - 1342464 ____A (Microsoft Corporation) A99AD14F26BDA7D7F27F76BC91B7EED7

    C:\Windows\SysWOW64\User32.dll
    [2013-01-09 13:41] - [2012-09-19 20:10] - 1126912 ____A (Microsoft Corporation) BA1C3ACD929A71E88B49C2B6E38F92B3

    C:\Windows\System32\userinit.exe
    [2012-07-25 16:06] - [2012-07-25 19:08] - 0025088 ____A (Microsoft Corporation) 0E925F7BA032920D58DD284B6181A247

    C:\Windows\SysWOW64\userinit.exe
    [2012-07-25 16:08] - [2012-07-25 19:21] - 0021504 ____A (Microsoft Corporation) 9F6289D194A04A09671FEED4B6CB6EF7

    C:\Windows\System32\Drivers\volsnap.sys
    [2012-07-25 18:30] - [2012-07-25 20:57] - 0332016 ____A (Microsoft Corporation) 2FB3CDFD5EAF4CD9D4AFAF96877D13AE


    ==================== EXE ASSOCIATION =====================

    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK

    ==================== Restore Points =========================


    ==================== Memory info ===========================

    Percentage of memory in use: 6%
    Total physical RAM: 16345.79 MB
    Available physical RAM: 15225.52 MB
    Total Pagefile: 16345.79 MB
    Available Pagefile: 15229.74 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.87 MB

    ==================== Partitions =============================

    1 Drive c: () (Fixed) (Total:55.9 GB) (Free:13.82 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
    2 Drive d: (System Reserved) (Fixed) (Total:0.34 GB) (Free:0.29 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    3 Drive e: () (Removable) (Total:1.91 GB) (Free:0.25 GB) FAT
    4 Drive f: () (Fixed) (Total:1396.92 GB) (Free:1142.41 GB) NTFS
    6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS


    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 55 GB 0 B
    Disk 1 Online 1397 GB 0 B
    Disk 2 Online 1960 MB 0 B

    Partitions of Disk 0:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 55 GB 1024 KB

    ==================================================================================

    Disk: 0
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C NTFS Partition 55 GB Healthy

    =========================================================

    Partitions of Disk 1:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 350 MB 1024 KB
    Partition 2 Primary 1396 GB 351 MB

    ==================================================================================

    Disk: 1
    Partition 1
    Type : 07
    Hidden: No
    Active: Yes

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 D System Rese NTFS Partition 350 MB Healthy

    =========================================================

    Disk: 1
    Partition 2
    Type : 07
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 F NTFS Partition 1396 GB Healthy

    =========================================================

    Partitions of Disk 2:
    ===============

    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 1959 MB 760 KB

    ==================================================================================

    Disk: 2
    Partition 1
    Type : 06
    Hidden: No
    Active: No

    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 4 E FAT Removable 1959 MB Healthy

    =========================================================

    Last Boot: 2013-01-13 06:29

    ==================== End Of Log =============================
     
  3. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    Farbar Recovery Scan Tool (x64) Version: 09-01-2013
    Ran by SYSTEM at 2013-01-13 22:52:12
    Running from E:\

    ================== Search: "services.exe" ===================

    C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.20521_none_98a9ea2e9f571eb2\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 581190907DA1CF8CB7B87B35FFE64A07

    C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16420_none_981f4d19863a6591\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 8F226143046435C75C033B0C52E90FFE

    C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
    [2012-07-25 21:26] - [2012-07-25 21:26] - 0410624 ____A (Microsoft Corporation) 754A2CC1F32107EA87CBD305ABE3E618

    C:\Windows\System32\services.exe
    [2013-01-09 13:41] - [2012-09-19 22:33] - 0410624 ____A (Microsoft Corporation) 8F226143046435C75C033B0C52E90FFE

    ====== End Of Search ======
     
  4. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    All looks clean.

    Download TDSSKiller and save it to your desktop.
    • Extract (unzip) its contents to your desktop.
    • Open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
    • If an infected file is detected, the default action will be Cure, click on Continue.
    • If a suspicious file is detected, the default action will be Skip, click on Continue.
    • It may ask you to reboot the computer to complete the process. Click on Reboot Now.
    • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
    • If a reboot is required, the report can also be found in your root directory (usually C:\ folder) in the form of TDSSKiller_xxxx_log.txt. Please copy and paste the contents of that file here.
     
  5. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    23:45:43.0362 3832 TDSS rootkit removing tool 2.8.15.0 Oct 31 2012 21:47:35
    23:45:43.0721 3832 ============================================================
    23:45:43.0737 3832 Current date / time: 2013/01/13 23:45:43.0721
    23:45:43.0737 3832 SystemInfo:
    23:45:43.0737 3832
    23:45:43.0737 3832 OS Version: 6.2.9200 ServicePack: 0.0
    23:45:43.0737 3832 Product type: Workstation
    23:45:43.0737 3832 ComputerName: PARKER
    23:45:43.0737 3832 UserName: DJ
    23:45:43.0737 3832 Windows directory: C:\Windows
    23:45:43.0737 3832 System windows directory: C:\Windows
    23:45:43.0737 3832 Running under WOW64
    23:45:43.0737 3832 Processor architecture: Intel x64
    23:45:43.0737 3832 Number of processors: 4
    23:45:43.0737 3832 Page size: 0x1000
    23:45:43.0737 3832 Boot type: Normal boot
    23:45:43.0737 3832 ============================================================
    23:45:43.0784 3832 BG loaded
    23:45:43.0955 3832 Drive \Device\Harddisk0\DR0 - Size: 0xDF99E6000 (55.90 Gb), SectorSize: 0x200, Cylinders: 0x1C81, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    23:45:43.0971 3832 Drive \Device\Harddisk1\DR1 - Size: 0x15D50F66000 (1397.27 Gb), SectorSize: 0x200, Cylinders: 0x2C881, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    23:45:43.0971 3832 Drive \Device\Harddisk2\DR2 - Size: 0x7A800000 (1.91 Gb), SectorSize: 0x200, Cylinders: 0xF9, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
    23:45:43.0971 3832 ============================================================
    23:45:43.0971 3832 \Device\Harddisk0\DR0:
    23:45:43.0971 3832 MBR partitions:
    23:45:43.0971 3832 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x6FCF202
    23:45:43.0971 3832 \Device\Harddisk1\DR1:
    23:45:43.0971 3832 MBR partitions:
    23:45:43.0971 3832 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xAF000
    23:45:43.0971 3832 \Device\Harddisk1\DR1\Partition2: MBR, Type 0x7, StartLBA 0xAF800, BlocksNum 0xAE9DAE02
    23:45:43.0971 3832 \Device\Harddisk2\DR2:
    23:45:43.0971 3832 MBR partitions:
    23:45:43.0971 3832 \Device\Harddisk2\DR2\Partition1: MBR, Type 0x6, StartLBA 0x5F0, BlocksNum 0x3D3A10
    23:45:43.0971 3832 ============================================================
    23:45:43.0971 3832 C: <-> \Device\Harddisk0\DR0\Partition1
    23:45:43.0971 3832 D: <-> \Device\Harddisk1\DR1\Partition1
    23:45:44.0002 3832 E: <-> \Device\Harddisk1\DR1\Partition2
    23:45:44.0002 3832 ============================================================
    23:45:44.0002 3832 Initialize success
    23:45:44.0002 3832 ============================================================
    23:45:52.0143 4888 ============================================================
    23:45:52.0143 4888 Scan started
    23:45:52.0143 4888 Mode: Manual; SigCheck; TDLFS;
    23:45:52.0143 4888 ============================================================
    23:45:52.0206 4888 ================ Scan system memory ========================
    23:45:52.0206 4888 System memory - ok
    23:45:52.0206 4888 ================ Scan services =============================
    23:45:52.0206 4888 [ 581D88B25C4D4121824FED2CA38E562F ] !SASCORE C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
    23:45:52.0253 4888 !SASCORE - ok
    23:45:52.0300 4888 [ E890C46E4754F0DF51BAFCC8D2E07498 ] 1394ohci C:\Windows\System32\drivers\1394ohci.sys
    23:45:52.0315 4888 1394ohci - ok
    23:45:52.0315 4888 [ 4F18D4C7EA14F11A7211F60D553C03DB ] 3ware C:\Windows\system32\drivers\3ware.sys
    23:45:52.0331 4888 3ware - ok
    23:45:52.0331 4888 [ 975AABEB243B800C23626D6B652C5A9C ] ACPI C:\Windows\system32\drivers\ACPI.sys
    23:45:52.0346 4888 ACPI - ok
    23:45:52.0346 4888 [ DC968C37822117E576B933F34A2D130C ] acpiex C:\Windows\system32\Drivers\acpiex.sys
    23:45:52.0362 4888 acpiex - ok
    23:45:52.0362 4888 [ 0CA9F7C3A78227C21A0A7854E245CFB2 ] acpipagr C:\Windows\System32\drivers\acpipagr.sys
    23:45:52.0362 4888 acpipagr - ok
    23:45:52.0362 4888 [ 8EB8DA03B142D3DD1EB9ED8107A76C43 ] AcpiPmi C:\Windows\System32\drivers\acpipmi.sys
    23:45:52.0378 4888 AcpiPmi - ok
    23:45:52.0378 4888 [ CBCE725C5D86ABA7D2604E22951AA9B8 ] acpitime C:\Windows\System32\drivers\acpitime.sys
    23:45:52.0393 4888 acpitime - ok
    23:45:52.0425 4888 [ 424877CB9D5517F980FF7BACA2EB379D ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    23:45:52.0425 4888 AdobeFlashPlayerUpdateSvc - ok
    23:45:52.0440 4888 [ 93C6388592B99925C1D1576E465BC80F ] adp94xx C:\Windows\system32\drivers\adp94xx.sys
    23:45:52.0440 4888 adp94xx - ok
    23:45:52.0456 4888 [ D27763E0247292654E7F7D16444C7C72 ] adpahci C:\Windows\system32\drivers\adpahci.sys
    23:45:52.0471 4888 adpahci - ok
    23:45:52.0471 4888 [ 67B90070FF48F794AF19F9FCF0080D75 ] adpu320 C:\Windows\system32\drivers\adpu320.sys
    23:45:52.0471 4888 adpu320 - ok
    23:45:52.0487 4888 [ 974AE60BF5B90E31412D93596C968E5B ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
    23:45:52.0487 4888 AeLookupSvc - ok
    23:45:52.0503 4888 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] AFD C:\Windows\system32\drivers\afd.sys
    23:45:52.0518 4888 AFD - ok
    23:45:52.0518 4888 [ 01590377A5AB19E792528C628A2A68F9 ] agp440 C:\Windows\system32\drivers\agp440.sys
    23:45:52.0518 4888 agp440 - ok
    23:45:52.0534 4888 [ D1BE8E6E5B3AF23A4393AF1BF867977A ] ALG C:\Windows\System32\alg.exe
    23:45:52.0534 4888 ALG - ok
    23:45:52.0534 4888 [ 025E8C755BE293E50854D26D1BBE5133 ] AllUserInstallAgent C:\Windows\system32\AUInstallAgent.dll
    23:45:52.0550 4888 AllUserInstallAgent - ok
    23:45:52.0550 4888 [ 4C1E3649C89C7D542CD18ECC5210099D ] AMD External Events Utility C:\Windows\system32\atiesrxx.exe
    23:45:52.0565 4888 AMD External Events Utility - ok
    23:45:52.0565 4888 [ 5A81054B824004B1ECC04F0034A1CDF9 ] AmdK8 C:\Windows\System32\drivers\amdk8.sys
    23:45:52.0581 4888 AmdK8 - ok
    23:45:52.0675 4888 [ A3C0A15B39F979E8F3EABA901D72ECD7 ] amdkmdag C:\Windows\system32\DRIVERS\atikmdag.sys
    23:45:52.0784 4888 amdkmdag - ok
    23:45:52.0800 4888 [ 20F3CD38B107C1BD747C0EA37D450165 ] amdkmdap C:\Windows\system32\DRIVERS\atikmpag.sys
    23:45:52.0831 4888 amdkmdap - ok
    23:45:52.0831 4888 [ B849D453E644FAB9BC8EF6DC8CA9C4C6 ] AmdPPM C:\Windows\System32\drivers\amdppm.sys
    23:45:52.0846 4888 AmdPPM - ok
    23:45:52.0846 4888 [ 35A0EB5AECB0FA3C41A2FB514A562304 ] amdsata C:\Windows\system32\drivers\amdsata.sys
    23:45:52.0846 4888 amdsata - ok
    23:45:52.0846 4888 [ 00452671904F5EE94B50BF0219C97164 ] amdsbs C:\Windows\system32\drivers\amdsbs.sys
    23:45:52.0862 4888 amdsbs - ok
    23:45:52.0862 4888 [ EA3FFE53E92E59C87E3ECA9BEB20D9B7 ] amdxata C:\Windows\system32\drivers\amdxata.sys
    23:45:52.0878 4888 amdxata - ok
    23:45:52.0878 4888 [ 83B3682CE922FB0F415734B26D9D6233 ] AppID C:\Windows\system32\drivers\appid.sys
    23:45:52.0878 4888 AppID - ok
    23:45:52.0893 4888 [ CE2BEAD7F31816FF0AC490D048C969F9 ] AppIDSvc C:\Windows\System32\appidsvc.dll
    23:45:52.0893 4888 AppIDSvc - ok
    23:45:52.0893 4888 [ D64C4AFEE8277F35EF729A2B924666B0 ] Appinfo C:\Windows\System32\appinfo.dll
    23:45:52.0909 4888 Appinfo - ok
    23:45:52.0909 4888 [ E933401B392387F4BE34DE8BAF1722A7 ] arc C:\Windows\system32\drivers\arc.sys
    23:45:52.0925 4888 arc - ok
    23:45:52.0925 4888 [ 07CA323EF2E8247A568AB0F3662AD644 ] arcsas C:\Windows\system32\drivers\arcsas.sys
    23:45:52.0925 4888 arcsas - ok
    23:45:52.0925 4888 [ 74DBAEC35366C4EE7670428808715A6A ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
    23:45:52.0940 4888 AsyncMac - ok
    23:45:52.0940 4888 [ A721FF570C2387E383BDDEA9632863C9 ] atapi C:\Windows\system32\drivers\atapi.sys
    23:45:52.0956 4888 atapi - ok
    23:45:52.0956 4888 [ 87DAD8D354E312DB16636DC71EB39E5E ] AtiHDAudioService C:\Windows\system32\drivers\AtihdW86.sys
    23:45:52.0956 4888 AtiHDAudioService - ok
    23:45:52.0971 4888 [ 810ED88782952228AF9C0985FB7D259E ] AudioEndpointBuilder C:\Windows\System32\AudioEndpointBuilder.dll
    23:45:52.0971 4888 AudioEndpointBuilder - ok
    23:45:52.0987 4888 [ 25CA8B87479A374919563B3EE7136F32 ] Audiosrv C:\Windows\System32\Audiosrv.dll
    23:45:52.0987 4888 Audiosrv - ok
    23:45:53.0003 4888 [ 58D7FAF5C81ECEFFD2EDEDA9C2619D82 ] Avgboota C:\Windows\system32\DRIVERS\avgboota.sys
    23:45:53.0003 4888 Avgboota - ok
    23:45:53.0050 4888 [ 4AFC14AFA58878FAA1D249E7E90EA54B ] AVGIDSAgent C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    23:45:53.0112 4888 AVGIDSAgent - ok
    23:45:53.0112 4888 [ 388056EBD5FE6718FE669078DBE37897 ] AVGIDSDriver C:\Windows\system32\DRIVERS\avgidsdrivera.sys
    23:45:53.0128 4888 AVGIDSDriver - ok
    23:45:53.0143 4888 [ 550E981747D6A6C55078C77346FFC2C6 ] AVGIDSHA C:\Windows\system32\DRIVERS\avgidsha.sys
    23:45:53.0143 4888 AVGIDSHA - ok
    23:45:53.0143 4888 [ 5989592A91A17587799792A81E1541D4 ] Avgldx64 C:\Windows\system32\DRIVERS\avgldx64.sys
    23:45:53.0159 4888 Avgldx64 - ok
    23:45:53.0159 4888 [ 3FC43AA02545FCDDC22817829114DEC8 ] Avgloga C:\Windows\system32\DRIVERS\avgloga.sys
    23:45:53.0159 4888 Avgloga - ok
    23:45:53.0175 4888 [ 841C40C193889730848849AC220D9242 ] Avgmfx64 C:\Windows\system32\DRIVERS\avgmfx64.sys
    23:45:53.0175 4888 Avgmfx64 - ok
    23:45:53.0175 4888 [ FE4F444DBE4BBBDFD8FECF49398DEFC7 ] Avgrkx64 C:\Windows\system32\DRIVERS\avgrkx64.sys
    23:45:53.0175 4888 Avgrkx64 - ok
    23:45:53.0190 4888 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] avgwd C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    23:45:53.0190 4888 avgwd - ok
    23:45:53.0190 4888 [ 64A0A811F096834E8B85AB5009609D10 ] Avgwfpa C:\Windows\system32\DRIVERS\avgwfpa.sys
    23:45:53.0206 4888 Avgwfpa - ok
    23:45:53.0206 4888 [ 89491EF71D5EA011127832C588002853 ] AxInstSV C:\Windows\System32\AxInstSV.dll
    23:45:53.0206 4888 AxInstSV - ok
    23:45:53.0222 4888 [ 87AB5BB072A3F128541D5B815F82FFDD ] b06bdrv C:\Windows\system32\drivers\bxvbda.sys
    23:45:53.0237 4888 b06bdrv - ok
    23:45:53.0237 4888 [ 81703BC5D68DEDBB086C2368FBE7B334 ] BasicDisplay C:\Windows\System32\drivers\BasicDisplay.sys
    23:45:53.0237 4888 BasicDisplay - ok
    23:45:53.0253 4888 [ 5EC68164E14D25675C98BBB5F09E8606 ] BasicRender C:\Windows\System32\drivers\BasicRender.sys
    23:45:53.0253 4888 BasicRender - ok
    23:45:53.0253 4888 [ 89143A7BA7850F5C7E61B43BB44B6418 ] BDESVC C:\Windows\System32\bdesvc.dll
    23:45:53.0268 4888 BDESVC - ok
    23:45:53.0268 4888 [ 9E7AEA59776D904607985AFFE7E5E183 ] Beep C:\Windows\system32\drivers\Beep.sys
    23:45:53.0284 4888 Beep - ok
    23:45:53.0284 4888 [ 9E6A544F465C582AB42444A217CF04DC ] BFE C:\Windows\System32\bfe.dll
    23:45:53.0300 4888 BFE - ok
    23:45:53.0315 4888 [ D598C44A7072D3108D8D8102EC5E07F7 ] BITS C:\Windows\System32\qmgr.dll
    23:45:53.0347 4888 BITS - ok
    23:45:53.0347 4888 [ B17AC10B47C7FCB44D22A1F06415840E ] bowser C:\Windows\system32\DRIVERS\bowser.sys
    23:45:53.0347 4888 bowser - ok
    23:45:53.0362 4888 [ 975398A3D2C1FEA73FC93931978DF354 ] BrokerInfrastructure C:\Windows\System32\bisrv.dll
    23:45:53.0362 4888 BrokerInfrastructure - ok
    23:45:53.0362 4888 [ 310068BDA80B1D55C36580FD8A873FAF ] Browser C:\Windows\System32\browser.dll
    23:45:53.0378 4888 Browser - ok
    23:45:53.0378 4888 [ 3AA4309EBD9491E516F13FE3DC752FEE ] BthAvrcpTg C:\Windows\System32\drivers\BthAvrcpTg.sys
    23:45:53.0393 4888 BthAvrcpTg - ok
    23:45:53.0393 4888 [ 616EB8748C988AEE98D93DA141C3D3B4 ] BthHFEnum C:\Windows\System32\drivers\bthhfenum.sys
    23:45:53.0409 4888 BthHFEnum - ok
    23:45:53.0425 4888 [ DCB4EBD928A6FB368BE6CAE522412DE1 ] bthhfhid C:\Windows\System32\drivers\BthHFHid.sys
    23:45:53.0425 4888 bthhfhid - ok
    23:45:53.0425 4888 [ 033916CE8784A848B9A3D686B7F66D97 ] BTHMODEM C:\Windows\System32\drivers\bthmodem.sys
    23:45:53.0440 4888 BTHMODEM - ok
    23:45:53.0440 4888 [ A4387C3D271959313E2577DB7BE8BA7A ] bthserv C:\Windows\system32\bthserv.dll
    23:45:53.0456 4888 bthserv - ok
    23:45:53.0456 4888 [ 990B1BABE6E81FB18E65A87EBEFB1772 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
    23:45:53.0456 4888 cdfs - ok
    23:45:53.0472 4888 [ 339BFF85D788268752DA8C9644B188EE ] cdrom C:\Windows\System32\drivers\cdrom.sys
    23:45:53.0472 4888 cdrom - ok
    23:45:53.0487 4888 [ BAF8F0F55BC300E5F882E521F054E345 ] CertPropSvc C:\Windows\System32\certprop.dll
    23:45:53.0487 4888 CertPropSvc - ok
    23:45:53.0487 4888 [ F64B7D1A37CC1D5F421D5359EEC81E2E ] circlass C:\Windows\System32\drivers\circlass.sys
    23:45:53.0503 4888 circlass - ok
    23:45:53.0518 4888 [ 9905168708DB68849B879B5548F68AB3 ] CLFS C:\Windows\system32\drivers\CLFS.sys
    23:45:53.0518 4888 CLFS - ok
    23:45:53.0534 4888 [ 2DC8538A2260647484A6C921CA837313 ] CmBatt C:\Windows\System32\drivers\CmBatt.sys
    23:45:53.0534 4888 CmBatt - ok
    23:45:53.0550 4888 [ E708BFF0473EC6B271EA46B65B16CA56 ] CNG C:\Windows\system32\Drivers\cng.sys
    23:45:53.0550 4888 CNG - ok
    23:45:53.0565 4888 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] CompositeBus C:\Windows\System32\drivers\CompositeBus.sys
    23:45:53.0565 4888 CompositeBus - ok
    23:45:53.0581 4888 COMSysApp - ok
    23:45:53.0581 4888 [ D9CB0782AF819548072AA45B70F8B22D ] condrv C:\Windows\system32\drivers\condrv.sys
    23:45:53.0581 4888 condrv - ok
    23:45:53.0597 4888 [ F0E78B119D12BA81F163D48C0FF30B9A ] CryptSvc C:\Windows\system32\cryptsvc.dll
    23:45:53.0597 4888 CryptSvc - ok
    23:45:53.0597 4888 [ C4D01BD86D6B207275FC143EEA951D75 ] dam C:\Windows\system32\drivers\dam.sys
    23:45:53.0612 4888 dam - ok
    23:45:53.0612 4888 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] DcomLaunch C:\Windows\system32\rpcss.dll
    23:45:53.0628 4888 DcomLaunch - ok
    23:45:53.0628 4888 [ C8650D1F61149AA546BDBC99172EBBC1 ] defragsvc C:\Windows\System32\defragsvc.dll
    23:45:53.0643 4888 defragsvc - ok
    23:45:53.0659 4888 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] DeviceAssociationService C:\Windows\system32\das.dll
    23:45:53.0659 4888 DeviceAssociationService - ok
    23:45:53.0675 4888 [ 799BE46D45D486704CE0F37CA5385262 ] DeviceInstall C:\Windows\system32\umpnpmgr.dll
    23:45:53.0675 4888 DeviceInstall - ok
    23:45:53.0675 4888 [ 09D9EB9E7898F8E6561473A20CC808B9 ] Dfsc C:\Windows\system32\Drivers\dfsc.sys
    23:45:53.0690 4888 Dfsc - ok
    23:45:53.0690 4888 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] Dhcp C:\Windows\system32\dhcpcore.dll
    23:45:53.0706 4888 Dhcp - ok
    23:45:53.0706 4888 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] discache C:\Windows\system32\drivers\discache.sys
    23:45:53.0706 4888 discache - ok
    23:45:53.0722 4888 [ 560495FF4CA22E1D9B1972FA18F43B6F ] disk C:\Windows\system32\drivers\disk.sys
    23:45:53.0722 4888 disk - ok
    23:45:53.0722 4888 [ 82A7C72593793FE1EADA7A305BD1567A ] dmvsc C:\Windows\System32\drivers\dmvsc.sys
    23:45:53.0737 4888 dmvsc - ok
    23:45:53.0737 4888 [ 066B9710B36AB550E01EEFCA52155968 ] Dnscache C:\Windows\System32\dnsrslvr.dll
    23:45:53.0753 4888 Dnscache - ok
    23:45:53.0753 4888 [ 9949AD2ABA168A618D46C799D6CC898C ] dot3svc C:\Windows\System32\dot3svc.dll
    23:45:53.0768 4888 dot3svc - ok
    23:45:53.0768 4888 [ 109FC3F80BF4F4DC5A071058074F13C1 ] DPS C:\Windows\system32\dps.dll
    23:45:53.0784 4888 DPS - ok
    23:45:53.0784 4888 [ 9C7C183F937951AE17C5B8B3259CF3FF ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
    23:45:53.0784 4888 drmkaud - ok
    23:45:53.0784 4888 [ BF48F32EE248C3D371DA5DC93BBEADA7 ] DsmSvc C:\Windows\System32\DeviceSetupManager.dll
    23:45:53.0800 4888 DsmSvc - ok
    23:45:53.0815 4888 [ 898BF1647BBF012B38EF45C7F9F7A67E ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
    23:45:53.0847 4888 DXGKrnl - ok
    23:45:53.0847 4888 [ 58BA473DD88F5FC1932282BA683AA03E ] Eaphost C:\Windows\System32\eapsvc.dll
    23:45:53.0862 4888 Eaphost - ok
    23:45:53.0893 4888 [ 5AB97B3282D7D6114949D1EB5C8598E4 ] ebdrv C:\Windows\system32\drivers\evbda.sys
    23:45:53.0940 4888 ebdrv - ok
    23:45:53.0940 4888 [ F702AB6181513303AB0FC8D59E52708B ] EFS C:\Windows\System32\lsass.exe
    23:45:53.0956 4888 EFS - ok
    23:45:53.0956 4888 [ 66D60BD9A4C05616ABECA2A901475098 ] EhStorClass C:\Windows\system32\drivers\EhStorClass.sys
    23:45:53.0956 4888 EhStorClass - ok
    23:45:53.0972 4888 [ A61D0F543024E458C0FE32352E1978E2 ] EhStorTcgDrv C:\Windows\system32\drivers\EhStorTcgDrv.sys
    23:45:53.0972 4888 EhStorTcgDrv - ok
    23:45:53.0972 4888 [ D790D058D67582DB9C84C2D33695FE6B ] ErrDev C:\Windows\System32\drivers\errdev.sys
    23:45:53.0987 4888 ErrDev - ok
    23:45:53.0987 4888 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] EventSystem C:\Windows\system32\es.dll
    23:45:54.0003 4888 EventSystem - ok
    23:45:54.0003 4888 [ 7A4D6FEB8C52B3FE855E4DCDF9107E03 ] exfat C:\Windows\system32\drivers\exfat.sys
    23:45:54.0018 4888 exfat - ok
    23:45:54.0018 4888 [ 60996602A7111FD2D086E803F33E4282 ] fastfat C:\Windows\system32\drivers\fastfat.sys
    23:45:54.0034 4888 fastfat - ok
    23:45:54.0034 4888 [ F0E7F8382ED5E138B0DFA4CB5058BCFE ] Fax C:\Windows\system32\fxssvc.exe
    23:45:54.0050 4888 Fax - ok
    23:45:54.0050 4888 [ 73B2D11DF0B6E03A0CB0323218ACB3E4 ] fdc C:\Windows\System32\drivers\fdc.sys
    23:45:54.0065 4888 fdc - ok
    23:45:54.0065 4888 [ 0828E3E7BD77C89149EAD3232BFD38DB ] fdPHost C:\Windows\system32\fdPHost.dll
    23:45:54.0081 4888 fdPHost - ok
    23:45:54.0081 4888 [ 872506AAB591E8908DF4461475AF92DF ] FDResPub C:\Windows\system32\fdrespub.dll
    23:45:54.0081 4888 FDResPub - ok
    23:45:54.0097 4888 [ 0588950D93A426F97C7AAADB1A9B0458 ] fhsvc C:\Windows\system32\fhsvc.dll
    23:45:54.0097 4888 fhsvc - ok
    23:45:54.0097 4888 [ 88A9EBACD1058ABB237A6B4E96E7F397 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
    23:45:54.0112 4888 FileInfo - ok
    23:45:54.0112 4888 [ 9E4EE3A0B00FF7D5F42A4AF9744CBA02 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
    23:45:54.0112 4888 Filetrace - ok
    23:45:54.0128 4888 [ B1D4C168FF7B8579E3745888658FFB1D ] flpydisk C:\Windows\System32\drivers\flpydisk.sys
    23:45:54.0128 4888 flpydisk - ok
    23:45:54.0128 4888 [ B33EC133AE4E6C1881D2302D93D2467D ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
    23:45:54.0143 4888 FltMgr - ok
    23:45:54.0159 4888 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] FontCache C:\Windows\system32\FntCache.dll
    23:45:54.0175 4888 FontCache - ok
    23:45:54.0175 4888 [ 0B56259F5611787222A04A8F254E51D4 ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    23:45:54.0190 4888 FontCache3.0.0.0 - ok
    23:45:54.0190 4888 [ A5F7873A39E4E9FAAAE59B7E9E36B705 ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
    23:45:54.0190 4888 FsDepends - ok
    23:45:54.0190 4888 [ A6DD7D491F587F4BC13FB972977DC8E8 ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
    23:45:54.0206 4888 Fs_Rec - ok
    23:45:54.0206 4888 [ FA228F4BB10DC7ED7E7D131C034E2331 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
    23:45:54.0222 4888 fvevol - ok
    23:45:54.0222 4888 [ A969D92973DFA895E7776B4BFE36DBB2 ] FxPPM C:\Windows\System32\drivers\fxppm.sys
    23:45:54.0237 4888 FxPPM - ok
    23:45:54.0237 4888 [ 52BC441E07A827EBAB70CDC7EAEDB28D ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys
    23:45:54.0237 4888 gagp30kx - ok
    23:45:54.0237 4888 [ 721F8EEF5E9747F32670DEFF7FB92541 ] gencounter C:\Windows\System32\drivers\vmgencounter.sys
    23:45:54.0253 4888 gencounter - ok
    23:45:54.0253 4888 [ CA18ECFCFFDD638ECE80799A9056B238 ] GPIOClx0101 C:\Windows\system32\Drivers\msgpioclx.sys
    23:45:54.0268 4888 GPIOClx0101 - ok
    23:45:54.0284 4888 [ 5358678C6370F2ADC5291849F6503262 ] gpsvc C:\Windows\System32\gpsvc.dll
    23:45:54.0300 4888 gpsvc - ok
    23:45:54.0300 4888 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    23:45:54.0300 4888 gupdate - ok
    23:45:54.0300 4888 [ 506708142BC63DABA64F2D3AD1DCD5BF ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    23:45:54.0315 4888 gupdatem - ok
    23:45:54.0315 4888 [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
    23:45:54.0331 4888 HdAudAddService - ok
    23:45:54.0331 4888 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] HDAudBus C:\Windows\System32\drivers\HDAudBus.sys
    23:45:54.0347 4888 HDAudBus - ok
    23:45:54.0347 4888 [ 3F76BBA53D65E85A7F53E7A71082082C ] HidBatt C:\Windows\System32\drivers\HidBatt.sys
    23:45:54.0362 4888 HidBatt - ok
    23:45:54.0362 4888 [ A25BAE8C1F2830C8E5625EC7E4E968BE ] HidBth C:\Windows\System32\drivers\hidbth.sys
    23:45:54.0378 4888 HidBth - ok
    23:45:54.0378 4888 [ CC4A07E51D89575CAB6F4EB590D87CD4 ] hidi2c C:\Windows\System32\drivers\hidi2c.sys
    23:45:54.0378 4888 hidi2c - ok
    23:45:54.0378 4888 [ DC96F7DACB777CDEAEF9958A50BFDA06 ] HidIr C:\Windows\System32\drivers\hidir.sys
    23:45:54.0393 4888 HidIr - ok
    23:45:54.0409 4888 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] hidserv C:\Windows\system32\hidserv.dll
    23:45:54.0409 4888 hidserv - ok
    23:45:54.0409 4888 [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] HidUsb C:\Windows\System32\drivers\hidusb.sys
    23:45:54.0425 4888 HidUsb - ok
    23:45:54.0425 4888 [ 43F884B61A24377567CD0FEB35236334 ] hkmsvc C:\Windows\system32\kmsvc.dll
    23:45:54.0440 4888 hkmsvc - ok
    23:45:54.0440 4888 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] HomeGroupListener C:\Windows\system32\ListSvc.dll
    23:45:54.0456 4888 HomeGroupListener - ok
    23:45:54.0456 4888 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] HomeGroupProvider C:\Windows\system32\provsvc.dll
    23:45:54.0472 4888 HomeGroupProvider - ok
    23:45:54.0472 4888 [ 64DB7A8D97CA53DCCF93D0A1E08342CF ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
    23:45:54.0487 4888 HpSAMD - ok
    23:45:54.0487 4888 [ 29CB98187BB5711F7759540976D295FC ] HTTP C:\Windows\system32\drivers\HTTP.sys
    23:45:54.0503 4888 HTTP - ok
    23:45:54.0503 4888 [ 2A98301068801700906C06649860FE94 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
    23:45:54.0518 4888 hwpolicy - ok
    23:45:54.0518 4888 [ DC76901D82097C9E297F20C287CB9A27 ] hyperkbd C:\Windows\System32\drivers\hyperkbd.sys
    23:45:54.0518 4888 hyperkbd - ok
    23:45:54.0534 4888 [ 716413AB3CA12DE0A7222D28C1C9352C ] HyperVideo C:\Windows\system32\DRIVERS\HyperVideo.sys
    23:45:54.0534 4888 HyperVideo - ok
    23:45:54.0534 4888 [ C9E9CBF73AFFBFE3E801EFB516787BA3 ] i8042prt C:\Windows\System32\drivers\i8042prt.sys
    23:45:54.0550 4888 i8042prt - ok
    23:45:54.0550 4888 [ 5E394EBD26FD68AA9300332C46BEDD62 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
    23:45:54.0565 4888 iaStorV - ok
    23:45:54.0565 4888 [ 24847A06B84339FEEDE5CABF3D27D320 ] iirsp C:\Windows\system32\drivers\iirsp.sys
    23:45:54.0565 4888 iirsp - ok
    23:45:54.0581 4888 [ 531B5A98145DA689741A0AC18F14EA94 ] IKEEXT C:\Windows\System32\ikeext.dll
    23:45:54.0597 4888 IKEEXT - ok
    23:45:54.0612 4888 [ 4F37726CF764CA18A8A84F85EF3A7F24 ] intelide C:\Windows\system32\drivers\intelide.sys
    23:45:54.0612 4888 intelide - ok
    23:45:54.0612 4888 [ E15CDF68DD73423F15D4AC404793AF0D ] intelppm C:\Windows\System32\drivers\intelppm.sys
    23:45:54.0628 4888 intelppm - ok
    23:45:54.0628 4888 [ 8FCA66234A0933D796BB780B7953BAB9 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
    23:45:54.0628 4888 IpFilterDriver - ok
    23:45:54.0643 4888 [ CAC5202757EF68C4849B0DFFA75F6D3C ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
    23:45:54.0659 4888 iphlpsvc - ok
    23:45:54.0659 4888 [ 6E98A046A12AA113F8898AA5D612BD6E ] IPMIDRV C:\Windows\System32\drivers\IPMIDrv.sys
    23:45:54.0675 4888 IPMIDRV - ok
    23:45:54.0675 4888 [ 3969B9C218DD3FAA9F4ED2FFC3651C02 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
    23:45:54.0675 4888 IPNAT - ok
    23:45:54.0690 4888 [ 25CD7C4BB2863FFC2B0B311F0AEBF77C ] IRENUM C:\Windows\system32\drivers\irenum.sys
    23:45:54.0690 4888 IRENUM - ok
    23:45:54.0690 4888 [ D940C5BB9DC92E588533C19ABCC3D2C2 ] isapnp C:\Windows\system32\drivers\isapnp.sys
    23:45:54.0706 4888 isapnp - ok
    23:45:54.0706 4888 [ 69C8BF0BC2B0EA10F130F4D3104DC2EF ] iScsiPrt C:\Windows\System32\drivers\msiscsi.sys
    23:45:54.0722 4888 iScsiPrt - ok
    23:45:54.0722 4888 [ 8FBD94B69D6423E20ABCD59D86368B21 ] kbdclass C:\Windows\System32\drivers\kbdclass.sys
    23:45:54.0722 4888 kbdclass - ok
    23:45:54.0722 4888 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] kbdhid C:\Windows\System32\drivers\kbdhid.sys
    23:45:54.0737 4888 kbdhid - ok
    23:45:54.0737 4888 [ FB6C185092E18011EF49989425C2AA87 ] kdnic C:\Windows\system32\DRIVERS\kdnic.sys
    23:45:54.0737 4888 kdnic - ok
    23:45:54.0753 4888 [ F702AB6181513303AB0FC8D59E52708B ] KeyIso C:\Windows\system32\lsass.exe
    23:45:54.0753 4888 KeyIso - ok
    23:45:54.0753 4888 [ DFA480F6DED551464F3A5B959F437800 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
    23:45:54.0768 4888 KSecDD - ok
    23:45:54.0768 4888 [ 127FB0AAD232BAAD2C9BBACD374F4FC5 ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
    23:45:54.0768 4888 KSecPkg - ok
    23:45:54.0784 4888 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] ksthunk C:\Windows\system32\drivers\ksthunk.sys
    23:45:54.0784 4888 ksthunk - ok
    23:45:54.0784 4888 [ 5825DBACEDC3812B5CF8D40B997BF210 ] KtmRm C:\Windows\system32\msdtckrm.dll
    23:45:54.0800 4888 KtmRm - ok
    23:45:54.0800 4888 [ 256EE31588257E8A555DBFAA13F1908E ] LanmanServer C:\Windows\system32\srvsvc.dll
    23:45:54.0815 4888 LanmanServer - ok
    23:45:54.0815 4888 [ 16650912BE5A94B40E0B3B4C39652B56 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
    23:45:54.0831 4888 LanmanWorkstation - ok
    23:45:54.0831 4888 [ CEEFD29FC551F289810B0B9381B321DC ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
    23:45:54.0847 4888 lltdio - ok
    23:45:54.0847 4888 [ BCF53485E0A94722CDE3C4A93CD8EB8C ] lltdsvc C:\Windows\System32\lltdsvc.dll
    23:45:54.0862 4888 lltdsvc - ok
    23:45:54.0862 4888 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] lmhosts C:\Windows\System32\lmhsvc.dll
    23:45:54.0862 4888 lmhosts - ok
    23:45:54.0878 4888 [ 022CDD12161B063D7852B1075BF3FFF2 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys
    23:45:54.0878 4888 LSI_SAS - ok
    23:45:54.0878 4888 [ 07AD59D669B996F29F91817F0ECFA34F ] LSI_SAS2 C:\Windows\system32\drivers\lsi_sas2.sys
    23:45:54.0893 4888 LSI_SAS2 - ok
    23:45:54.0893 4888 [ 216FB796AA4E252ACCE93B1BCB80B5EC ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys
    23:45:54.0893 4888 LSI_SCSI - ok
    23:45:54.0909 4888 [ 5E80530AF37102488EE980B4A92AF99F ] LSI_SSS C:\Windows\system32\drivers\lsi_sss.sys
    23:45:54.0909 4888 LSI_SSS - ok
    23:45:54.0909 4888 [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] LSM C:\Windows\System32\lsm.dll
    23:45:54.0925 4888 LSM - ok
    23:45:54.0925 4888 [ 2BDC5D711FA61307CE6190D47C956368 ] luafv C:\Windows\system32\drivers\luafv.sys
    23:45:54.0940 4888 luafv - ok
    23:45:54.0940 4888 [ 92EB844D90615CB266F84C3202B8786E ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
    23:45:54.0940 4888 MBAMProtector - ok
    23:45:54.0987 4888 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] MBAMScheduler e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    23:45:54.0987 4888 MBAMScheduler - ok
    23:45:55.0034 4888 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] MBAMService e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    23:45:55.0034 4888 MBAMService - ok
    23:45:55.0050 4888 [ 9B0D829C3BE4E7472DB9DD2B79908E3C ] megasas C:\Windows\system32\drivers\megasas.sys
    23:45:55.0050 4888 megasas - ok
    23:45:55.0050 4888 [ ECC3F54C7AFC318271C4F0B4606D8DB0 ] MegaSR C:\Windows\system32\drivers\MegaSR.sys
    23:45:55.0065 4888 MegaSR - ok
    23:45:55.0065 4888 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] MEIx64 C:\Windows\System32\drivers\HECIx64.sys
    23:45:55.0081 4888 MEIx64 - ok
    23:45:55.0081 4888 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] MMCSS C:\Windows\system32\mmcss.dll
    23:45:55.0081 4888 MMCSS - ok
    23:45:55.0081 4888 [ 780098AD5DA8A4822E2563984C85EF7B ] Modem C:\Windows\system32\drivers\modem.sys
    23:45:55.0097 4888 Modem - ok
    23:45:55.0097 4888 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
    23:45:55.0112 4888 monitor - ok
    23:45:55.0112 4888 [ 618446B98C79776654340CE27C73485E ] mouclass C:\Windows\System32\drivers\mouclass.sys
    23:45:55.0112 4888 mouclass - ok
    23:45:55.0112 4888 [ CB2527B8B87D83E56FBF3944BBB6F606 ] mouhid C:\Windows\System32\drivers\mouhid.sys
    23:45:55.0128 4888 mouhid - ok
    23:45:55.0128 4888 [ 89D263DBF08119CE16273991C120D6DD ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
    23:45:55.0143 4888 mountmgr - ok
    23:45:55.0143 4888 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
    23:45:55.0159 4888 mpsdrv - ok
    23:45:55.0159 4888 [ 3031573A739DBEE8923851929D0AF423 ] MpsSvc C:\Windows\system32\mpssvc.dll
    23:45:55.0175 4888 MpsSvc - ok
    23:45:55.0175 4888 [ 3D70147F55F1EC84EB9139ED7FFE48BC ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
    23:45:55.0190 4888 MRxDAV - ok
    23:45:55.0190 4888 [ 877D60D6E4156EC4A2E0B6871D41BED9 ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
    23:45:55.0206 4888 mrxsmb - ok
    23:45:55.0206 4888 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
    23:45:55.0222 4888 mrxsmb10 - ok
    23:45:55.0222 4888 [ E078446D4B8622AA6030C7B8A1A08962 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
    23:45:55.0237 4888 mrxsmb20 - ok
    23:45:55.0237 4888 [ 98487487D6B3797CA927E9D7B030AE13 ] MsBridge C:\Windows\system32\DRIVERS\bridge.sys
    23:45:55.0253 4888 MsBridge - ok
    23:45:55.0253 4888 [ 4A07458EB4F17573BD39F22029A991C1 ] MSDTC C:\Windows\System32\msdtc.exe
    23:45:55.0268 4888 MSDTC - ok
    23:45:55.0268 4888 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] Msfs C:\Windows\system32\drivers\Msfs.sys
    23:45:55.0284 4888 Msfs - ok
    23:45:55.0284 4888 [ C9BFB0353099B071E70299549C18C8AE ] msgpiowin32 C:\Windows\System32\drivers\msgpiowin32.sys
    23:45:55.0284 4888 msgpiowin32 - ok
    23:45:55.0284 4888 [ D3857A767B91A061B408CCAB02DA4F40 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
    23:45:55.0300 4888 mshidkmdf - ok
    23:45:55.0300 4888 [ 839B48910FB1E887635C48F3EC11A05E ] mshidumdf C:\Windows\System32\drivers\mshidumdf.sys
    23:45:55.0300 4888 mshidumdf - ok
    23:45:55.0300 4888 [ 55C0DB741E3AB7463242B185B1C2997C ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
    23:45:55.0315 4888 msisadrv - ok
    23:45:55.0315 4888 [ 216C6B035A4BA5560E1255BD8E5BB89F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
    23:45:55.0331 4888 MSiSCSI - ok
    23:45:55.0331 4888 msiserver - ok
    23:45:55.0331 4888 [ 509809566E49F4411055864EA8D437CD ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
    23:45:55.0331 4888 MSKSSRV - ok
    23:45:55.0347 4888 [ 63145201D6458E4958E572E7D6FC2604 ] MsLldp C:\Windows\system32\DRIVERS\mslldp.sys
    23:45:55.0347 4888 MsLldp - ok
    23:45:55.0347 4888 [ 99D526E803DB6D7FF290FD98B6204641 ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
    23:45:55.0362 4888 MSPCLOCK - ok
    23:45:55.0362 4888 [ 06FA77C3E2A491ADCD704C5E73006269 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
    23:45:55.0362 4888 MSPQM - ok
    23:45:55.0378 4888 [ E134EC4DE11CF78CB01432D180710D84 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
    23:45:55.0378 4888 MsRPC - ok
    23:45:55.0393 4888 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] mssmbios C:\Windows\System32\drivers\mssmbios.sys
    23:45:55.0393 4888 mssmbios - ok
    23:45:55.0393 4888 [ 72D66A05E0F99F2528F6C6204FD22AA1 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
    23:45:55.0393 4888 MSTEE - ok
    23:45:55.0409 4888 [ 8AAAE399FC255FA105D4158CBA289001 ] MTConfig C:\Windows\System32\drivers\MTConfig.sys
    23:45:55.0409 4888 MTConfig - ok
    23:45:55.0409 4888 [ 3BCB702F3E6CC622DCAFCAA45D7CDE0A ] Mup C:\Windows\system32\Drivers\mup.sys
    23:45:55.0425 4888 Mup - ok
    23:45:55.0425 4888 [ 3A1E095277BBD406CEA8EA6B76950664 ] mvumis C:\Windows\system32\drivers\mvumis.sys
    23:45:55.0440 4888 mvumis - ok
    23:45:55.0440 4888 [ 4B18840511D720BA118D3017E8165875 ] napagent C:\Windows\system32\qagentRT.dll
    23:45:55.0456 4888 napagent - ok
    23:45:55.0472 4888 [ 43D7388A90A4C6EA346A4D6FF0377479 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
    23:45:55.0472 4888 NativeWifiP - ok
    23:45:55.0487 4888 [ 6A0C3996DA7DAE6D6939676D786EEEC4 ] NcaSvc C:\Windows\System32\ncasvc.dll
    23:45:55.0503 4888 NcaSvc - ok
    23:45:55.0503 4888 [ C982FE4CC91DECE2259F494FCEB4030F ] NcdAutoSetup C:\Windows\System32\NcdAutoSetup.dll
    23:45:55.0503 4888 NcdAutoSetup - ok
    23:45:55.0519 4888 [ 0F89AE618DBA5D8AB7A2DFCC375F4159 ] NDIS C:\Windows\system32\drivers\ndis.sys
    23:45:55.0534 4888 NDIS - ok
    23:45:55.0550 4888 [ 39C8A1D9D46F5E83A016BCAB72455284 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
    23:45:55.0550 4888 NdisCap - ok
    23:45:55.0550 4888 [ 762941932B7E4C588E48A577BA9D6440 ] NdisImPlatform C:\Windows\system32\DRIVERS\NdisImPlatform.sys
    23:45:55.0565 4888 NdisImPlatform - ok
    23:45:55.0565 4888 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
    23:45:55.0581 4888 NdisTapi - ok
    23:45:55.0581 4888 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
    23:45:55.0597 4888 Ndisuio - ok
    23:45:55.0597 4888 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
    23:45:55.0597 4888 NdisWan - ok
    23:45:55.0612 4888 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] NDISWANLEGACY C:\Windows\system32\DRIVERS\ndiswan.sys
    23:45:55.0612 4888 NDISWANLEGACY - ok
    23:45:55.0612 4888 [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
    23:45:55.0628 4888 NDProxy - ok
    23:45:55.0628 4888 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] Ndu C:\Windows\system32\drivers\Ndu.sys
    23:45:55.0628 4888 Ndu - ok
    23:45:55.0644 4888 [ 7C203A76394F9AE68F69EEE5F9612C4A ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
    23:45:55.0644 4888 NetBIOS - ok
    23:45:55.0644 4888 [ 7CEC25C682D319D484630B3952C31A11 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
    23:45:55.0659 4888 NetBT - ok
    23:45:55.0659 4888 [ F702AB6181513303AB0FC8D59E52708B ] Netlogon C:\Windows\system32\lsass.exe
    23:45:55.0675 4888 Netlogon - ok
    23:45:55.0675 4888 [ 89519D29CBEC2121CA65CC29C4D345E0 ] Netman C:\Windows\System32\netman.dll
    23:45:55.0690 4888 Netman - ok
    23:45:55.0690 4888 [ 20F6FD63E6D456114BC8056D62792786 ] netprofm C:\Windows\System32\netprofmsvc.dll
    23:45:55.0706 4888 netprofm - ok
    23:45:55.0722 4888 [ 5243CFC2E7161C91C2B355240035B9E4 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    23:45:55.0722 4888 NetTcpPortSharing - ok
    23:45:55.0722 4888 [ 12DD2800E4EEA37DC9AE256AD62423B4 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys
    23:45:55.0737 4888 nfrd960 - ok
    23:45:55.0737 4888 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] NlaSvc C:\Windows\System32\nlasvc.dll
    23:45:55.0753 4888 NlaSvc - ok
    23:45:55.0753 4888 NPF - ok
    23:45:55.0753 4888 [ 17E19A742FB30C002F8B43575451DBE1 ] Npfs C:\Windows\system32\drivers\Npfs.sys
    23:45:55.0769 4888 Npfs - ok
    23:45:55.0769 4888 [ 8ED299C30792544264E558BEA79F0947 ] npsvctrig C:\Windows\System32\drivers\npsvctrig.sys
    23:45:55.0769 4888 npsvctrig - ok
    23:45:55.0784 4888 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] nsi C:\Windows\system32\nsisvc.dll
    23:45:55.0784 4888 nsi - ok
    23:45:55.0784 4888 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
    23:45:55.0800 4888 nsiproxy - ok
    23:45:55.0815 4888 [ 4A7EEA9C4AD5CBFDA3C0E5B821C99CAD ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
    23:45:55.0847 4888 Ntfs - ok
    23:45:55.0862 4888 [ 4163ADE07DB51843AE31F65B94F5398D ] Null C:\Windows\system32\drivers\Null.sys
    23:45:55.0862 4888 Null - ok
    23:45:55.0862 4888 [ D6D34118263412D3AAA8348A9572B7F2 ] nvraid C:\Windows\system32\drivers\nvraid.sys
    23:45:55.0878 4888 nvraid - ok
    23:45:55.0878 4888 [ 27AFC428D1D32ABD04A86763A4EDDEA9 ] nvstor C:\Windows\system32\drivers\nvstor.sys
    23:45:55.0894 4888 nvstor - ok
    23:45:55.0894 4888 [ 051CFB5107BAAE510419BDC41F8C4036 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
    23:45:55.0894 4888 nv_agp - ok
    23:45:55.0909 4888 [ B9C125314A025127FE562C116D614AA3 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    23:45:55.0909 4888 ose64 - ok
    23:45:55.0925 4888 [ AB76700D764A342D7475FB8F47CAB18C ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
    23:45:55.0925 4888 p2pimsvc - ok
    23:45:55.0940 4888 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] p2psvc C:\Windows\system32\p2psvc.dll
    23:45:55.0940 4888 p2psvc - ok
    23:45:55.0956 4888 [ 4563DAF8C6A740AD7F501E219BD10766 ] Parport C:\Windows\System32\drivers\parport.sys
    23:45:55.0956 4888 Parport - ok
    23:45:55.0956 4888 [ C1D7BA7F0DE487DFEEB51BF8D3EC5562 ] partmgr C:\Windows\system32\drivers\partmgr.sys
    23:45:55.0972 4888 partmgr - ok
    23:45:55.0972 4888 [ 4811D9EC53649105A5A8BEA661B0F936 ] PcaSvc C:\Windows\System32\pcasvc.dll
    23:45:55.0987 4888 PcaSvc - ok
    23:45:55.0987 4888 [ 4A003E8F718C1E6A2050CA98CD53E3E2 ] pci C:\Windows\system32\drivers\pci.sys
    23:45:56.0003 4888 pci - ok
    23:45:56.0003 4888 [ F9908D274D458220F91E89B54D78D837 ] pciide C:\Windows\system32\drivers\pciide.sys
    23:45:56.0019 4888 pciide - ok
    23:45:56.0019 4888 [ 84D19CB6102627932DCB5DFDF89FE269 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys
    23:45:56.0034 4888 pcmcia - ok
    23:45:56.0034 4888 [ CEBBAD5391C2644560C55628A40BFD27 ] pcw C:\Windows\system32\drivers\pcw.sys
    23:45:56.0050 4888 pcw - ok
    23:45:56.0050 4888 [ EF9B4F3136B4C45F421ADE6871659FB6 ] pdc C:\Windows\system32\drivers\pdc.sys
    23:45:56.0050 4888 pdc - ok
    23:45:56.0065 4888 [ 70DBB6A8B52B3830922F1C5789E1BEEB ] PEAUTH C:\Windows\system32\drivers\peauth.sys
    23:45:56.0081 4888 PEAUTH - ok
    23:45:56.0112 4888 [ EB88FA19F0EA05DD04BE9C5FFEEFFE1A ] PerfHost C:\Windows\SysWow64\perfhost.exe
    23:45:56.0128 4888 PerfHost - ok
    23:45:56.0144 4888 [ 6E84BFF58F7643499277F29DFA2F8C8D ] pla C:\Windows\system32\pla.dll
    23:45:56.0175 4888 pla - ok
    23:45:56.0175 4888 [ 799BE46D45D486704CE0F37CA5385262 ] PlugPlay C:\Windows\system32\umpnpmgr.dll
    23:45:56.0190 4888 PlugPlay - ok
    23:45:56.0190 4888 [ 8E2414E818C26C4A9C70CB2B8567F04F ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
    23:45:56.0206 4888 PNRPAutoReg - ok
    23:45:56.0206 4888 [ AB76700D764A342D7475FB8F47CAB18C ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
    23:45:56.0222 4888 PNRPsvc - ok
    23:45:56.0222 4888 [ 0108C8E5176D590F242701EF5A62CC26 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
    23:45:56.0237 4888 PolicyAgent - ok
    23:45:56.0237 4888 [ F1E067F56373F11EA4B785CAE823740A ] Power C:\Windows\system32\umpo.dll
    23:45:56.0253 4888 Power - ok
    23:45:56.0253 4888 [ 362D47E5B4D67270DE4B8606036F4ADD ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
    23:45:56.0269 4888 PptpMiniport - ok
    23:45:56.0284 4888 [ C2D3B3D0060619D5E03E696BD56FF59F ] PrintNotify C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll
    23:45:56.0315 4888 PrintNotify - ok
    23:45:56.0331 4888 [ DD979EB6A7212F60E4AFBE96EDC7AE6D ] Processor C:\Windows\System32\drivers\processr.sys
    23:45:56.0331 4888 Processor - ok
    23:45:56.0331 4888 [ 429E8502AD2227CF88F8840FC5BD590D ] ProfSvc C:\Windows\system32\profsvc.dll
    23:45:56.0347 4888 ProfSvc - ok
    23:45:56.0347 4888 [ EB8034147D4820CD31BFCB11A2A652DF ] Psched C:\Windows\system32\DRIVERS\pacer.sys
    23:45:56.0362 4888 Psched - ok
    23:45:56.0362 4888 [ 0AFBF333B6F87A2F598EAB379AF100B8 ] QWAVE C:\Windows\system32\qwave.dll
    23:45:56.0378 4888 QWAVE - ok
    23:45:56.0378 4888 [ 13D47BB0CCA2FC51BD15F8E85C6A078E ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
    23:45:56.0378 4888 QWAVEdrv - ok
    23:45:56.0394 4888 [ 873C60F8178100557740A832FCE10B5F ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
    23:45:56.0394 4888 RasAcd - ok
    23:45:56.0394 4888 [ 69B93F623B130976243ECA3D84CC99CA ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
    23:45:56.0409 4888 RasAgileVpn - ok
    23:45:56.0409 4888 [ 005F6E54C4A2DA4EBF68FB0392CE8BB0 ] RasAuto C:\Windows\System32\rasauto.dll
    23:45:56.0425 4888 RasAuto - ok
    23:45:56.0425 4888 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
    23:45:56.0440 4888 Rasl2tp - ok
    23:45:56.0440 4888 [ C923C785A2DE0B396AD6D13ACAFF2DE9 ] RasMan C:\Windows\System32\rasmans.dll
    23:45:56.0456 4888 RasMan - ok
    23:45:56.0456 4888 [ 00695B9C2DB6111064499C529E90C042 ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
    23:45:56.0456 4888 RasPppoe - ok
    23:45:56.0472 4888 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
    23:45:56.0472 4888 RasSstp - ok
    23:45:56.0487 4888 [ B72C33DBD5326B3864CF2091AF8B906B ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
    23:45:56.0487 4888 rdbss - ok
    23:45:56.0503 4888 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] rdpbus C:\Windows\System32\drivers\rdpbus.sys
    23:45:56.0503 4888 rdpbus - ok
    23:45:56.0503 4888 [ B2A3AD74FF2E2FFA73AF2567108231B3 ] RDPDR C:\Windows\system32\drivers\rdpdr.sys
    23:45:56.0519 4888 RDPDR - ok
    23:45:56.0519 4888 [ 57F4787E4602A3FCA719C0A33137C6DA ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
    23:45:56.0534 4888 RdpVideoMiniport - ok
    23:45:56.0534 4888 [ B3CB0721E81E30419CE7D837EF4EA151 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
    23:45:56.0534 4888 RDPWD - ok
    23:45:56.0550 4888 [ 62C1F8A0685FE07E998AA296C4F697C4 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
    23:45:56.0550 4888 rdyboost - ok
    23:45:56.0550 4888 [ 3663CCF243EE0C04E9F6F91ED1737273 ] RemoteAccess C:\Windows\System32\mprdim.dll
    23:45:56.0565 4888 RemoteAccess - ok
    23:45:56.0565 4888 [ E80DD61E52EDFFF9DA1ED7260A68855B ] RemoteRegistry C:\Windows\system32\regsvc.dll
    23:45:56.0581 4888 RemoteRegistry - ok
    23:45:56.0675 4888 [ 599091EDC1013A4A79CFE171638CF262 ] rpcapd C:\Program Files (x86)\WinPcap\rpcapd.exe
    23:45:56.0690 4888 rpcapd ( UnsignedFile.Multi.Generic ) - warning
    23:45:56.0690 4888 rpcapd - detected UnsignedFile.Multi.Generic (1)
    23:45:56.0690 4888 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
    23:45:56.0690 4888 RpcEptMapper - ok
    23:45:56.0706 4888 [ 10B21284B3D964AB3DC45490E57D422E ] RpcLocator C:\Windows\system32\locator.exe
    23:45:56.0706 4888 RpcLocator - ok
    23:45:56.0769 4888 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] RpcSs C:\Windows\system32\rpcss.dll
    23:45:56.0784 4888 RpcSs - ok
    23:45:56.0784 4888 [ E04E770DD198B9399640717145E79EBF ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
    23:45:56.0800 4888 rspndr - ok
    23:45:56.0800 4888 [ 15923AA360F7675D3D43C9669316A0BA ] RTL8168 C:\Windows\system32\DRIVERS\Rt630x64.sys
    23:45:56.0815 4888 RTL8168 - ok
    23:45:56.0831 4888 [ AE03548B97CC32199B69E20D29951BD6 ] RTL8192su C:\Windows\system32\DRIVERS\RTL8192su.sys
    23:45:56.0847 4888 RTL8192su - ok
    23:45:56.0847 4888 [ 752EC7DCD2F96871A3857EEE6AFE965A ] s3cap C:\Windows\System32\drivers\vms3cap.sys
    23:45:56.0862 4888 s3cap - ok
    23:45:56.0862 4888 [ F702AB6181513303AB0FC8D59E52708B ] SamSs C:\Windows\system32\lsass.exe
    23:45:56.0862 4888 SamSs - ok
    23:45:56.0878 4888 [ 3289766038DB2CB14D07DC84392138D5 ] SASDIFSV C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS
    23:45:56.0878 4888 SASDIFSV - ok
    23:45:56.0878 4888 [ 58A38E75F3316A83C23DF6173D41F2B5 ] SASKUTIL C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS
    23:45:56.0894 4888 SASKUTIL - ok
    23:45:56.0894 4888 [ 9C7B28CE0D136DB226E24DB3BC817F92 ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
    23:45:56.0894 4888 sbp2port - ok
    23:45:56.0909 4888 [ 14316954FCE79C9DE5A0AFF9D42C83AA ] SCardSvr C:\Windows\System32\SCardSvr.dll
    23:45:56.0925 4888 SCardSvr - ok
    23:45:56.0925 4888 [ 5D7733A12756B267FCA021672B26BC9E ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
    23:45:56.0925 4888 scfilter - ok
    23:45:56.0987 4888 [ EDCDF4DB82EF825B94B190D544C8C58B ] Schedule C:\Windows\system32\schedsvc.dll
    23:45:57.0003 4888 Schedule - ok
    23:45:57.0003 4888 [ BAF8F0F55BC300E5F882E521F054E345 ] SCPolicySvc C:\Windows\System32\certprop.dll
    23:45:57.0003 4888 SCPolicySvc - ok
    23:45:57.0019 4888 [ 66E29CADF9FF6C8325C356BDD617F7EA ] sdbus C:\Windows\System32\drivers\sdbus.sys
    23:45:57.0019 4888 sdbus - ok
    23:45:57.0034 4888 [ 92968277ED491E4B3DDA361E3952361E ] SDRSVC C:\Windows\System32\SDRSVC.dll
    23:45:57.0050 4888 SDRSVC - ok
    23:45:57.0065 4888 [ 206387AB881E93A1A6EB89966C8651F1 ] SDScannerService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    23:45:57.0081 4888 SDScannerService - ok
    23:45:57.0081 4888 [ BB107AA9980B0DA4E19A3A90C3BD4460 ] sdstor C:\Windows\System32\drivers\sdstor.sys
    23:45:57.0097 4888 sdstor - ok
    23:45:57.0112 4888 [ A529CFE32565C0B145578FFB2B32C9A5 ] SDUpdateService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    23:45:57.0128 4888 SDUpdateService - ok
    23:45:57.0128 4888 [ CB63BDB77BB86549FC3303C2F11EDC18 ] SDWSCService C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    23:45:57.0128 4888 SDWSCService - ok
    23:45:57.0144 4888 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys
    23:45:57.0144 4888 secdrv - ok
    23:45:57.0144 4888 [ CD282626738B6BC92B6E7CD0AAE95B63 ] seclogon C:\Windows\system32\seclogon.dll
    23:45:57.0159 4888 seclogon - ok
    23:45:57.0159 4888 [ 9C51620998F0763039DFA6BF68E475ED ] SENS C:\Windows\System32\sens.dll
    23:45:57.0175 4888 SENS - ok
    23:45:57.0175 4888 [ 0D50B4B860DAB65241628D04CD33ACAE ] SensrSvc C:\Windows\system32\sensrsvc.dll
    23:45:57.0175 4888 SensrSvc - ok
    23:45:57.0190 4888 [ 87C46B239A7EEF30FDFDD5E9BD46130C ] SerCx C:\Windows\system32\drivers\SerCx.sys
    23:45:57.0190 4888 SerCx - ok
    23:45:57.0190 4888 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] Serenum C:\Windows\System32\drivers\serenum.sys
    23:45:57.0206 4888 Serenum - ok
    23:45:57.0206 4888 [ F640A0A218BBF857F1D04A15D7D939F6 ] Serial C:\Windows\System32\drivers\serial.sys
    23:45:57.0206 4888 Serial - ok
    23:45:57.0222 4888 [ F1A5F56B2620B862CC28FF96A0A6DAAB ] sermouse C:\Windows\System32\drivers\sermouse.sys
    23:45:57.0222 4888 sermouse - ok
    23:45:57.0222 4888 [ CB60A60340788C8D6DE2A269D28086AB ] SessionEnv C:\Windows\system32\sessenv.dll
    23:45:57.0237 4888 SessionEnv - ok
    23:45:57.0237 4888 [ 7EE65419B29302C795714FF8073969A1 ] sfloppy C:\Windows\System32\drivers\sfloppy.sys
    23:45:57.0253 4888 sfloppy - ok
    23:45:57.0253 4888 [ 090AE16F79C8EAD04E6031F863DA85F3 ] SharedAccess C:\Windows\System32\ipnathlp.dll
    23:45:57.0269 4888 SharedAccess - ok
    23:45:57.0284 4888 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] ShellHWDetection C:\Windows\System32\shsvcs.dll
    23:45:57.0284 4888 ShellHWDetection - ok
    23:45:57.0300 4888 [ 2560721D6F16D5B611C36A3A9D28C1B2 ] SiSRaid2 C:\Windows\system32\drivers\SiSRaid2.sys
    23:45:57.0300 4888 SiSRaid2 - ok
    23:45:57.0300 4888 [ 3AA8FDE1DBF65BB8B88B053529554A0D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys
    23:45:57.0315 4888 SiSRaid4 - ok
    23:45:57.0315 4888 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    23:45:57.0315 4888 SkypeUpdate - ok
    23:45:57.0331 4888 [ E660156A4588A84305CB772FD2C0DB21 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
    23:45:57.0331 4888 SNMPTRAP - ok
    23:45:57.0347 4888 [ 465F3C355CE5ED2779B8F460F14C5A78 ] spaceport C:\Windows\system32\drivers\spaceport.sys
    23:45:57.0347 4888 spaceport - ok
    23:45:57.0347 4888 [ 3D8679C8DF52EB26EB7583A4E0A29202 ] SpbCx C:\Windows\system32\drivers\SpbCx.sys
    23:45:57.0362 4888 SpbCx - ok
    23:45:57.0362 4888 [ 3F215BF2D4D8D6756298B25B579772C2 ] Spooler C:\Windows\System32\spoolsv.exe
    23:45:57.0378 4888 Spooler - ok
    23:45:57.0425 4888 [ EC84D961501054F87A6878EC5D53388F ] sppsvc C:\Windows\system32\sppsvc.exe
    23:45:57.0487 4888 sppsvc - ok
    23:45:57.0487 4888 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] srv C:\Windows\system32\DRIVERS\srv.sys
    23:45:57.0503 4888 srv - ok
    23:45:57.0519 4888 [ C2106BB710AA34A046126AED7BCA6964 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
    23:45:57.0534 4888 srv2 - ok
    23:45:57.0534 4888 [ 9400C71F5A1A380B494B6922F007D485 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
    23:45:57.0550 4888 srvnet - ok
    23:45:57.0550 4888 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
    23:45:57.0565 4888 SSDPSRV - ok
    23:45:57.0565 4888 [ D233B16999A8E626F6004BD7814C57EC ] SstpSvc C:\Windows\system32\sstpsvc.dll
    23:45:57.0565 4888 SstpSvc - ok
    23:45:57.0565 4888 Steam Client Service - ok
    23:45:57.0581 4888 [ 4E85355B94CFCB67C135F6521A4895A7 ] stexstor C:\Windows\system32\drivers\stexstor.sys
     
  6. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    23:45:57.0581 4888 stexstor - ok
    23:45:57.0597 4888 [ BAC8A721736AECC55A4F71523AEAB65F ] stisvc C:\Windows\System32\wiaservc.dll
    23:45:57.0597 4888 stisvc - ok
    23:45:57.0597 4888 [ C588BBD37B432CE3204E5765B459E6B2 ] storahci C:\Windows\system32\drivers\storahci.sys
    23:45:57.0612 4888 storahci - ok
    23:45:57.0612 4888 [ F74DBC95A57B1EE866D3732EB5F79BE2 ] storflt C:\Windows\system32\DRIVERS\vmstorfl.sys
    23:45:57.0612 4888 storflt - ok
    23:45:57.0628 4888 [ 5337E138B49ED1F44CCBA4073BC35C20 ] StorSvc C:\Windows\system32\storsvc.dll
    23:45:57.0628 4888 StorSvc - ok
    23:45:57.0628 4888 [ 543CD3CC0E05B8D8815E0D4F040B6F59 ] storvsc C:\Windows\system32\drivers\storvsc.sys
    23:45:57.0644 4888 storvsc - ok
    23:45:57.0644 4888 [ 8BC1C1ED6EF9C985A3FAA6A72F41679A ] svsvc C:\Windows\system32\svsvc.dll
    23:45:57.0659 4888 svsvc - ok
    23:45:57.0659 4888 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] swenum C:\Windows\System32\drivers\swenum.sys
    23:45:57.0659 4888 swenum - ok
    23:45:57.0675 4888 [ 502F9488540051F3E6C39889ECFA76BB ] swprv C:\Windows\System32\swprv.dll
    23:45:57.0690 4888 swprv - ok
    23:45:57.0706 4888 [ DC21E1F06343773D7E24362DCEF7944B ] SysMain C:\Windows\system32\sysmain.dll
    23:45:57.0722 4888 SysMain - ok
    23:45:57.0722 4888 [ E219BF7BCCFE4881B0C053C7E0B47ECC ] SystemEventsBroker C:\Windows\System32\SystemEventsBrokerServer.dll
    23:45:57.0722 4888 SystemEventsBroker - ok
    23:45:57.0737 4888 [ A6C06C45C44AD06C70AF8899AEC15BDC ] TabletInputService C:\Windows\System32\TabSvc.dll
    23:45:57.0737 4888 TabletInputService - ok
    23:45:57.0737 4888 [ 88B7721AB551C4325036B25A34A2BF7B ] TapiSrv C:\Windows\System32\tapisrv.dll
    23:45:57.0753 4888 TapiSrv - ok
    23:45:57.0769 4888 [ 1D644E2D0FC395A055AB1C23C3B43631 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
    23:45:57.0815 4888 Tcpip - ok
    23:45:57.0894 4888 [ 1D644E2D0FC395A055AB1C23C3B43631 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
    23:45:57.0925 4888 TCPIP6 - ok
    23:45:57.0925 4888 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
    23:45:57.0940 4888 tcpipreg - ok
    23:45:57.0940 4888 [ 73DC722CE5DF26D7638CE2446F2655C7 ] tdx C:\Windows\system32\DRIVERS\tdx.sys
    23:45:57.0956 4888 tdx - ok
    23:45:57.0956 4888 [ F7C8AB5D8AFFAA318D6A21093D139BF4 ] terminpt C:\Windows\System32\drivers\terminpt.sys
    23:45:57.0956 4888 terminpt - ok
    23:45:57.0972 4888 [ 541EE228D0DEF392F7B2DFD885DD021B ] TermService C:\Windows\System32\termsrv.dll
    23:45:57.0987 4888 TermService - ok
    23:45:57.0987 4888 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] Themes C:\Windows\system32\themeservice.dll
    23:45:58.0003 4888 Themes - ok
    23:45:58.0003 4888 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] THREADORDER C:\Windows\system32\mmcss.dll
    23:45:58.0003 4888 THREADORDER - ok
    23:45:58.0019 4888 [ FF4135424A79DCC2998276D8E39C9B4D ] TimeBroker C:\Windows\System32\TimeBrokerServer.dll
    23:45:58.0019 4888 TimeBroker - ok
    23:45:58.0034 4888 [ B44EFE254C0B3719E4037088D24FE4B5 ] TPM C:\Windows\system32\drivers\tpm.sys
    23:45:58.0034 4888 TPM - ok
    23:45:58.0034 4888 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] TrkWks C:\Windows\System32\trkwks.dll
    23:45:58.0050 4888 TrkWks - ok
    23:45:58.0050 4888 [ 8D516AEF3C1DF980664CF17BB1FF6093 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
    23:45:58.0050 4888 TrustedInstaller - ok
    23:45:58.0066 4888 [ 4E7C5FB10A50435523DE0CAA37DE2BD3 ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
    23:45:58.0066 4888 TsUsbFlt - ok
    23:45:58.0066 4888 [ 16D684A820872EE54F6370703AC0B513 ] TsUsbGD C:\Windows\System32\drivers\TsUsbGD.sys
    23:45:58.0081 4888 TsUsbGD - ok
    23:45:58.0081 4888 [ 78C9EE193AC2B4CBDBC48B620314D740 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
    23:45:58.0097 4888 tunnel - ok
    23:45:58.0097 4888 [ 6D4F67CA56ACA2085DFA2CD89EAFBC1A ] uagp35 C:\Windows\system32\drivers\uagp35.sys
    23:45:58.0097 4888 uagp35 - ok
    23:45:58.0112 4888 [ 6FD6D03B7752C78712E5CFF29A305026 ] UASPStor C:\Windows\System32\drivers\uaspstor.sys
    23:45:58.0112 4888 UASPStor - ok
    23:45:58.0128 4888 [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] UCX01000 C:\Windows\System32\drivers\ucx01000.sys
    23:45:58.0128 4888 UCX01000 - ok
    23:45:58.0144 4888 [ DC5A461591C71AF7F19DC048A81E3F88 ] udfs C:\Windows
     
  7. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    \system32\DRIVERS\udfs.sys
    23:45:58.0144 4888 udfs - ok
    23:45:58.0175 4888 [ FB3475FEA1CCB0DAEA1EBE44D0E3BB7D ] UI0Detect C:\Windows\system32\UI0Detect.exe
    23:45:58.0191 4888 UI0Detect - ok
    23:45:58.0191 4888 [ 07FEBCDF24FABA0D47B635D85A0FFB7A ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
    23:45:58.0206 4888 uliagpkx - ok
    23:45:58.0206 4888 [ 02CEB3FE6152668A7BA420B93B664860 ] umbus C:\Windows\System32\drivers\umbus.sys
    23:45:58.0206 4888 umbus - ok
    23:45:58.0206 4888 [ 991EE6B5FC41EAEF99C8AF5B92F2CA09 ] UmPass C:\Windows\System32\drivers\umpass.sys
    23:45:58.0222 4888 UmPass - ok
    23:45:58.0222 4888 [ 43FEFB040A0CC30F795FBF544169594D ] UmRdpService C:\Windows\System32\umrdp.dll
    23:45:58.0237 4888 UmRdpService - ok
    23:45:58.0253 4888 [ 14D22C411854AA2560AFC94CD2D5E61F ] upnphost C:\Windows\System32\upnphost.dll
    23:45:58.0269 4888 upnphost - ok
    23:45:58.0269 4888 [ 3FBE0784E42E7BA93FCC5201D2BAFE23 ] usbaudio C:\Windows\system32\drivers\usbaudio.sys
    23:45:58.0284 4888 usbaudio - ok
    23:45:58.0284 4888 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] usbccgp C:\Windows\System32\drivers\usbccgp.sys
    23:45:58.0300 4888 usbccgp - ok
    23:45:58.0300 4888 [ B395B62B62F28106218FA6FB17F4C797 ] usbcir C:\Windows\System32\drivers\usbcir.sys
    23:45:58.0316 4888 usbcir - ok
    23:45:58.0316 4888 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] usbehci C:\Windows\System32\drivers\usbehci.sys
    23:45:58.0331 4888 usbehci - ok
    23:45:58.0331 4888 [ FBB6794E3BBAD92D66D59D206C1F849F ] usbhub C:\Windows\System32\drivers\usbhub.sys
    23:45:58.0347 4888 usbhub - ok
    23:45:58.0362 4888 [ B7A948501424805571BF562BB0BFE31D ] USBHUB3 C:\Windows\System32\drivers\UsbHub3.sys
    23:45:58.0362 4888 USBHUB3 - ok
    23:45:58.0378 4888 [ 325F6179009B5A7F6118951A5BA422AB ] usbohci C:\Windows\System32\drivers\usbohci.sys
    23:45:58.0378 4888 usbohci - ok
    23:45:58.0378 4888 [ BA3ABE0CD1C14B3295BAD0F076B84CAC ] usbprint C:\Windows\System32\drivers\usbprint.sys
    23:45:58.0394 4888 usbprint - ok
    23:45:58.0394 4888 [ F77177F6C95B2116EE7AD23B5EF57007 ] USBSTOR C:\Windows\System32\drivers\USBSTOR.SYS
    23:45:58.0394 4888 USBSTOR - ok
    23:45:58.0409 4888 [ D25EF4A6EC244C5DE85D88A05B7C149D ] usbuhci C:\Windows\System32\drivers\usbuhci.sys
    23:45:58.0409 4888 usbuhci - ok
    23:45:58.0409 4888 [ 9CD4259AD15F84DE27B94A956C978D6C ] USBXHCI C:\Windows\System32\drivers\USBXHCI.SYS
    23:45:58.0425 4888 USBXHCI - ok
    23:45:58.0425 4888 [ F702AB6181513303AB0FC8D59E52708B ] VaultSvc C:\Windows\system32\lsass.exe
    23:45:58.0441 4888 VaultSvc - ok
    23:45:58.0441 4888 [ BACECBFF9C97F7627A60B0E0F1FE7EE8 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
    23:45:58.0441 4888 vdrvroot - ok
    23:45:58.0456 4888 [ 8A8CDA9E3CF2E0B4C6CC19FBC6FB9A71 ] vds C:\Windows\System32\vds.exe
    23:45:58.0472 4888 vds - ok
    23:45:58.0472 4888 [ 74FA2D4368DE6F6CE14393EDF1F342BE ] VerifierExt C:\Windows\system32\drivers\VerifierExt.sys
    23:45:58.0472 4888 VerifierExt - ok
    23:45:58.0487 4888 [ 8628FA679F0EC4B709CCD1F6B6A3233B ] vhdmp C:\Windows\System32\drivers\vhdmp.sys
    23:45:58.0503 4888 vhdmp - ok
    23:45:58.0503 4888 [ F5B4A14B00E89250C50982AC762DDD1D ] viaide C:\Windows\system32\drivers\viaide.sys
    23:45:58.0503 4888 viaide - ok
    23:45:58.0519 4888 [ 78DB50F7329F6D1311658DABFFFC8BE0 ] vmbus C:\Windows\system32\drivers\vmbus.sys
    23:45:58.0519 4888 vmbus - ok
    23:45:58.0519 4888 [ ECFEE2F2BA3932C7880D1A8F67D68F91 ] VMBusHID C:\Windows\System32\drivers\VMBusHID.sys
    23:45:58.0534 4888 VMBusHID - ok
    23:45:58.0534 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicheartbeat C:\Windows\System32\ICSvc.dll
    23:45:58.0550 4888 vmicheartbeat - ok
    23:45:58.0550 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmickvpexchange C:\Windows\System32\ICSvc.dll
    23:45:58.0566 4888 vmickvpexchange - ok
    23:45:58.0566 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicrdv C:\Windows\System32\ICSvc.dll
    23:45:58.0581 4888 vmicrdv - ok
    23:45:58.0581 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicshutdown C:\Windows\System32\ICSvc.dll
    23:45:58.0581 4888 vmicshutdown - ok
    23:45:58.0597 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmictimesync C:\Windows\System32\ICSvc.dll
    23:45:58.0597 4888 vmictimesync - ok
    23:45:58.0612 4888 [ B8FF4248103E6EA47B9D85C55673ABA3 ] vmicvss C:\Windows\System32\ICSvc.dll
    23:45:58.0612 4888 vmicvss - ok
    23:45:58.0612 4888 [ CB60FAAED8B49B812EBBF77EB87D9B18 ] volmgr C:\Windows\system32\drivers\volmgr.sys
    23:45:58.0628 4888 volmgr - ok
    23:45:58.0628 4888 [ A74101DA9809251BCD0E5A26BAE0F824 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
    23:45:58.0644 4888 volmgrx - ok
    23:45:58.0644 4888 [ 2FB3CDFD5EAF4CD9D4AFAF96877D13AE ] volsnap C:\Windows\system32\drivers\volsnap.sys
    23:45:58.0659 4888 volsnap - ok
    23:45:58.0659 4888 [ A8DA1C1B52ECEA3726DEBED4FF1B700D ] vpci C:\Windows\System32\drivers\vpci.sys
    23:45:58.0675 4888 vpci - ok
    23:45:58.0675 4888 [ 38A60CD9C009C55C6D3B5586F8E6A353 ] vsmraid C:\Windows\system32\drivers\vsmraid.sys
    23:45:58.0675 4888 vsmraid - ok
    23:45:58.0691 4888 [ EA658570314042C914964FC72AB50E6B ] VSS C:\Windows\system32\vssvc.exe
    23:45:58.0722 4888 VSS - ok
    23:45:58.0722 4888 [ A0F6FE0FC2F647C22BBFD6BD4249DBCC ] VSTXRAID C:\Windows\system32\drivers\vstxraid.sys
    23:45:58.0737 4888 VSTXRAID - ok
    23:45:58.0753 4888 [ 62460A45435A26A334907E3F2EA45611 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
    23:45:58.0753 4888 vwifibus - ok
    23:45:58.0753 4888 [ 095E943D27025E4D588AF0A72CC2318F ] vwififlt C:\Windows\system32\DRIVERS\vwififlt.sys
    23:45:58.0769 4888 vwififlt - ok
    23:45:58.0769 4888 [ F690B6EEAA94576727B24376D7ED3601 ] W32Time C:\Windows\system32\w32time.dll
    23:45:58.0784 4888 W32Time - ok
    23:45:58.0784 4888 [ 6B806E893714019969E2B50D7EF6A4D9 ] WacomPen C:\Windows\System32\drivers\wacompen.sys
    23:45:58.0800 4888 WacomPen - ok
    23:45:58.0800 4888 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys
    23:45:58.0800 4888 Wanarp - ok
    23:45:58.0800 4888 [ 6081CEC9EF9EB145D8B46655C7708D51 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
    23:45:58.0816 4888 Wanarpv6 - ok
    23:45:58.0831 4888 [ 42DF22F8C448E7CD219F6D63743505E2 ] wbengine C:\Windows\system32\wbengine.exe
    23:45:58.0862 4888 wbengine - ok
    23:45:58.0862 4888 [ 31D37B2F6069C631EF0557D322924812 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
    23:45:58.0878 4888 WbioSrvc - ok
    23:45:58.0878 4888 [ D9C1E82651BF19C6FF69CEC6FD400124 ] Wcmsvc C:\Windows\System32\wcmsvc.dll
    23:45:58.0894 4888 Wcmsvc - ok
    23:45:58.0894 4888 [ 5B5FEAB51172F5513C2CF7B39CFA6A01 ] wcncsvc C:\Windows\System32\wcncsvc.dll
    23:45:58.0909 4888 wcncsvc - ok
    23:45:58.0909 4888 [ E19556D414332E2BEBA1F368229006B4 ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
    23:45:58.0925 4888 WcsPlugInService - ok
    23:45:58.0925 4888 [ B3A4D918DAB90505B6BC7B70632913CB ] Wd C:\Windows\system32\drivers\wd.sys
    23:45:58.0925 4888 Wd - ok
    23:45:58.0941 4888 [ 260F8DFC4D5748F4CCB9B19CFB0E58EA ] WdBoot C:\Windows\system32\drivers\WdBoot.sys
    23:45:58.0941 4888 WdBoot - ok
    23:45:58.0958 4888 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
    23:45:58.0981 4888 Wdf01000 - ok
    23:45:58.0986 4888 [ 880FFFC4D5BBBB4187B6B04AB2E8C32A ] WdFilter C:\Windows\system32\drivers\WdFilter.sys
    23:45:58.0996 4888 WdFilter - ok
    23:45:59.0000 4888 [ 240FC332484572227CD1DF82407F33E5 ] WdiServiceHost C:\Windows\system32\wdi.dll
    23:45:59.0011 4888 WdiServiceHost - ok
    23:45:59.0014 4888 [ 240FC332484572227CD1DF82407F33E5 ] WdiSystemHost C:\Windows\system32\wdi.dll
    23:45:59.0025 4888 WdiSystemHost - ok
    23:45:59.0030 4888 [ F2002DA5E6B78C15B2CD48CFF8F0FBB6 ] WebClient C:\Windows\System32\webclnt.dll
    23:45:59.0035 4888 WebClient - ok
    23:45:59.0035 4888 [ 35FD720943D4FCD75C3275BF062FF140 ] Wecsvc C:\Windows\system32\wecsvc.dll
    23:45:59.0057 4888 Wecsvc - ok
    23:45:59.0060 4888 [ 4D2612E3C462B68F499D840B1133263E ] wercplsupport C:\Windows\System32\wercplsupport.dll
    23:45:59.0074 4888 wercplsupport - ok
    23:45:59.0078 4888 [ 8E2426162ED6749A127B35D235F21E11 ] WerSvc C:\Windows\System32\WerSvc.dll
    23:45:59.0092 4888 WerSvc - ok
    23:45:59.0101 4888 [ FE762D3498719C3A23471BBA62F747B4 ] WFPLWFS C:\Windows\system32\DRIVERS\wfplwfs.sys
    23:45:59.0108 4888 WFPLWFS - ok
    23:45:59.0112 4888 [ 60E0C220593DA4F7C289CB909D2DBAE0 ] WiaRpc C:\Windows\System32\wiarpc.dll
    23:45:59.0120 4888 WiaRpc - ok
    23:45:59.0124 4888 [ A3C7624A42A3447EF5EDD1ED37FE4E60 ] WIMMount C:\Windows\system32\drivers\wimmount.sys
    23:45:59.0131 4888 WIMMount - ok
    23:45:59.0133 4888 WinDefend - ok
    23:45:59.0144 4888 [ 7911470B6018059A880469A63B65700A ] WinHttpAutoProxySvc C:\Windows\system32\winhttp.dll
    23:45:59.0156 4888 WinHttpAutoProxySvc - ok
    23:45:59.0163 4888 [ 3D6B518B71C75C8FA4115A33615C107A ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
    23:45:59.0172 4888 Winmgmt - ok
    23:45:59.0341 4888 [ 8E212A627F33F6FC3B5F3BB47212F66E ] WinRM C:\Windows\system32\WsmSvc.dll
    23:45:59.0379 4888 WinRM - ok
    23:45:59.0385 4888 [ BB20956C424531003F7FA6CD36F11D5D ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
    23:45:59.0399 4888 WinUsb - ok
    23:45:59.0412 4888 [ 6351724B8FA0255C2DBD970297F00B93 ] WlanSvc C:\Windows\System32\wlansvc.dll
    23:45:59.0429 4888 WlanSvc - ok
    23:45:59.0588 4888 [ 08EFA13A2234C8C3B8A99E4B88BE7E9B ] wlidsvc C:\Windows\system32\wlidsvc.dll
    23:45:59.0607 4888 wlidsvc - ok
    23:45:59.0610 4888 [ E2A596CACFC6504306CDB7B593B90084 ] WmiAcpi C:\Windows\System32\drivers\wmiacpi.sys
    23:45:59.0616 4888 WmiAcpi - ok
    23:45:59.0621 4888 [ D113499052C5E541906B727779F0F959 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
    23:45:59.0631 4888 wmiApSrv - ok
    23:45:59.0632 4888 WMPNetworkSvc - ok
    23:45:59.0636 4888 [ C6FF953D5D6F2EAE3B8883474D5076B3 ] wpcfltr C:\Windows\system32\DRIVERS\wpcfltr.sys
    23:45:59.0644 4888 wpcfltr - ok
    23:45:59.0647 4888 [ A6ED163169876BFD2437E872FE2F1509 ] WPCSvc C:\Windows\System32\wpcsvc.dll
    23:45:59.0687 4888 WPCSvc - ok
    23:45:59.0818 4888 [ 94AA5150E35B3ABB7191FE641E3C2473 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
    23:45:59.0829 4888 WPDBusEnum - ok
    23:45:59.0835 4888 [ 0346CAFC181C91C6E2330332EB332ED6 ] WpdUpFltr C:\Windows\system32\drivers\WpdUpFltr.sys
    23:45:59.0841 4888 WpdUpFltr - ok
    23:45:59.0845 4888 [ BC8B5CB336E63BB25EAD1CE8EDD34B81 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
    23:45:59.0852 4888 ws2ifsl - ok
    23:45:59.0857 4888 [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] wscsvc C:\Windows\System32\wscsvc.dll
    23:45:59.0868 4888 wscsvc - ok
    23:45:59.0873 4888 WSearch - ok
    23:45:59.0903 4888 [ C10BFFEE7E0D7A1366E84F251796C51D ] WSService C:\Windows\System32\WSService.dll
    23:46:00.0155 4888 WSService - ok
    23:46:00.0190 4888 [ A8484C0CB54DB48180FB7CA00F1C3F8F ] wuauserv C:\Windows\system32\wuaueng.dll
    23:46:00.0235 4888 wuauserv - ok
    23:46:00.0241 4888 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
    23:46:00.0249 4888 WudfPf - ok
    23:46:00.0255 4888 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\System32\drivers\WUDFRd.sys
    23:46:00.0267 4888 WUDFRd - ok
    23:46:00.0272 4888 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll
    23:46:00.0281 4888 wudfsvc - ok
    23:46:00.0287 4888 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdFs C:\Windows\system32\DRIVERS\WUDFRd.sys
    23:46:00.0295 4888 WUDFWpdFs - ok
    23:46:00.0298 4888 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFWpdMtp C:\Windows\system32\DRIVERS\WUDFRd.sys
    23:46:00.0305 4888 WUDFWpdMtp - ok
    23:46:00.0313 4888 [ F9D8D2E6ECE08B278621D5BF3A7240A6 ] WwanSvc C:\Windows\System32\wwansvc.dll
    23:46:00.0328 4888 WwanSvc - ok
    23:46:00.0334 4888 ================ Scan global ===============================
    23:46:00.0338 4888 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\system32\basesrv.dll
    23:46:00.0343 4888 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\system32\winsrv.dll
    23:46:00.0348 4888 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\system32\sxssrv.dll
    23:46:00.0354 4888 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\system32\services.exe
    23:46:00.0356 4888 [Global] - ok
    23:46:00.0357 4888 ================ Scan MBR ==================================
    23:46:00.0359 4888 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
    23:46:00.0452 4888 \Device\Harddisk0\DR0 - ok
    23:46:00.0467 4888 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk1\DR1
    23:46:00.0644 4888 \Device\Harddisk1\DR1 - ok
    23:46:00.0648 4888 [ DDAE9D649DB12F6AFF24483F2C298989 ] \Device\Harddisk2\DR2
    23:46:00.0796 4888 \Device\Harddisk2\DR2 - ok
    23:46:00.0796 4888 ================ Scan VBR ==================================
    23:46:00.0799 4888 [ 9B82BD1FBE697E6F0FE2F15F67AC54F4 ] \Device\Harddisk0\DR0\Partition1
    23:46:00.0800 4888 \Device\Harddisk0\DR0\Partition1 - ok
    23:46:00.0802 4888 [ 89CEC369F86E833A4B906697A32A20CD ] \Device\Harddisk1\DR1\Partition1
    23:46:00.0803 4888 \Device\Harddisk1\DR1\Partition1 - ok
    23:46:00.0835 4888 [ B06880233BB1F9143101554F63AEE209 ] \Device\Harddisk1\DR1\Partition2
    23:46:00.0836 4888 \Device\Harddisk1\DR1\Partition2 - ok
    23:46:00.0839 4888 [ EBB3321D986DA0D45E607B9DB38E3CB9 ] \Device\Harddisk2\DR2\Partition1
    23:46:00.0840 4888 \Device\Harddisk2\DR2\Partition1 - ok
    23:46:00.0840 4888 ================ Scan active images ========================
    23:46:00.0842 4888 [ A721FF570C2387E383BDDEA9632863C9 ] C:\Windows\System32\Drivers\atapi.sys
    23:46:00.0842 4888 C:\Windows\System32\Drivers\atapi.sys - ok
    23:46:00.0844 4888 [ 48753C871A12B9E2201E71D01B32F6EF ] C:\Windows\System32\Drivers\crashdmp.sys
    23:46:00.0844 4888 C:\Windows\System32\Drivers\crashdmp.sys - ok
    23:46:00.0845 4888 [ 15AFD3118600205B013550C8E81A0D92 ] C:\Windows\System32\Drivers\Dumpata.sys
    23:46:00.0845 4888 C:\Windows\System32\Drivers\Dumpata.sys - ok
    23:46:00.0847 4888 [ CB9EAD11F3312C77CE9B7F29B59C3A39 ] C:\Windows\System32\Drivers\dumpfve.sys
    23:46:00.0847 4888 C:\Windows\System32\Drivers\dumpfve.sys - ok
    23:46:00.0849 4888 [ 339BFF85D788268752DA8C9644B188EE ] C:\Windows\System32\Drivers\cdrom.sys
    23:46:00.0849 4888 C:\Windows\System32\Drivers\cdrom.sys - ok
    23:46:00.0851 4888 [ 5EC68164E14D25675C98BBB5F09E8606 ] C:\Windows\System32\Drivers\BasicRender.sys
    23:46:00.0851 4888 C:\Windows\System32\Drivers\BasicRender.sys - ok
    23:46:00.0853 4888 [ 9E7AEA59776D904607985AFFE7E5E183 ] C:\Windows\System32\Drivers\beep.sys
    23:46:00.0853 4888 C:\Windows\System32\Drivers\beep.sys - ok
    23:46:00.0855 4888 [ 4163ADE07DB51843AE31F65B94F5398D ] C:\Windows\System32\Drivers\null.sys
    23:46:00.0855 4888 C:\Windows\System32\Drivers\null.sys - ok
    23:46:00.0856 4888 [ 898BF1647BBF012B38EF45C7F9F7A67E ] C:\Windows\System32\Drivers\dxgkrnl.sys
    23:46:00.0856 4888 C:\Windows\System32\Drivers\dxgkrnl.sys - ok
    23:46:00.0859 4888 [ B9FF5E13079ADB858ED5C0B1E4CAB225 ] C:\Windows\System32\Drivers\watchdog.sys
    23:46:00.0859 4888 C:\Windows\System32\Drivers\watchdog.sys - ok
    23:46:00.0861 4888 [ 81703BC5D68DEDBB086C2368FBE7B334 ] C:\Windows\System32\Drivers\BasicDisplay.sys
    23:46:00.0861 4888 C:\Windows\System32\Drivers\BasicDisplay.sys - ok
    23:46:00.0863 4888 [ 728DFAEEF8E52E793DE8EB0423F4E948 ] C:\Windows\System32\Drivers\dxgmms1.sys
    23:46:00.0863 4888 C:\Windows\System32\Drivers\dxgmms1.sys - ok
    23:46:00.0865 4888 [ 17E19A742FB30C002F8B43575451DBE1 ] C:\Windows\System32\Drivers\npfs.sys
    23:46:00.0865 4888 C:\Windows\System32\Drivers\npfs.sys - ok
    23:46:00.0867 4888 [ 64A0A811F096834E8B85AB5009609D10 ] C:\Windows\System32\Drivers\avgwfpa.sys
    23:46:00.0868 4888 C:\Windows\System32\Drivers\avgwfpa.sys - ok
    23:46:00.0869 4888 [ 3886F1F2A4D2900ABAA7E4486BEEE6A2 ] C:\Windows\System32\Drivers\msfs.sys
    23:46:00.0869 4888 C:\Windows\System32\Drivers\msfs.sys - ok
    23:46:00.0871 4888 [ 749AFA28C01233E93F59BD31B2B088B1 ] C:\Windows\System32\Drivers\tdi.sys
    23:46:00.0871 4888 C:\Windows\System32\Drivers\tdi.sys - ok
    23:46:00.0873 4888 [ 73DC722CE5DF26D7638CE2446F2655C7 ] C:\Windows\System32\Drivers\tdx.sys
    23:46:00.0873 4888 C:\Windows\System32\Drivers\tdx.sys - ok
    23:46:00.0876 4888 [ 36D6A3201721558A8AFBCC09C2DA4C2C ] C:\Windows\System32\Drivers\afd.sys
    23:46:00.0876 4888 C:\Windows\System32\Drivers\afd.sys - ok
    23:46:00.0878 4888 [ 7CEC25C682D319D484630B3952C31A11 ] C:\Windows\System32\Drivers\netbt.sys
    23:46:00.0878 4888 C:\Windows\System32\Drivers\netbt.sys - ok
    23:46:00.0880 4888 [ 5989592A91A17587799792A81E1541D4 ] C:\Windows\System32\Drivers\avgldx64.sys
    23:46:00.0880 4888 C:\Windows\System32\Drivers\avgldx64.sys - ok
    23:46:00.0885 4888 [ 7C203A76394F9AE68F69EEE5F9612C4A ] C:\Windows\System32\Drivers\netbios.sys
    23:46:00.0885 4888 C:\Windows\System32\Drivers\netbios.sys - ok
    23:46:00.0888 4888 [ EB8034147D4820CD31BFCB11A2A652DF ] C:\Windows\System32\Drivers\pacer.sys
    23:46:00.0888 4888 C:\Windows\System32\Drivers\pacer.sys - ok
    23:46:00.0890 4888 [ 095E943D27025E4D588AF0A72CC2318F ] C:\Windows\System32\Drivers\vwififlt.sys
    23:46:00.0891 4888 C:\Windows\System32\Drivers\vwififlt.sys - ok
    23:46:00.0892 4888 [ B72C33DBD5326B3864CF2091AF8B906B ] C:\Windows\System32\Drivers\rdbss.sys
    23:46:00.0893 4888 C:\Windows\System32\Drivers\rdbss.sys - ok
    23:46:00.0894 4888 [ 3289766038DB2CB14D07DC84392138D5 ] C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys
    23:46:00.0894 4888 C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys - ok
    23:46:00.0896 4888 [ 58A38E75F3316A83C23DF6173D41F2B5 ] C:\Program Files\SUPERAntiSpyware\saskutil64.sys
    23:46:00.0896 4888 C:\Program Files\SUPERAntiSpyware\saskutil64.sys - ok
    23:46:00.0898 4888 [ B5AECF12F09DEE97C9FCAA5BA016CE1E ] C:\Windows\System32\Drivers\mssmbios.sys
    23:46:00.0898 4888 C:\Windows\System32\Drivers\mssmbios.sys - ok
    23:46:00.0900 4888 [ 8ED299C30792544264E558BEA79F0947 ] C:\Windows\System32\Drivers\npsvctrig.sys
    23:46:00.0900 4888 C:\Windows\System32\Drivers\npsvctrig.sys - ok
    23:46:00.0902 4888 [ 689B3B1E95C70ABF7AFF29F9406EF1E0 ] C:\Windows\System32\Drivers\nsiproxy.sys
    23:46:00.0902 4888 C:\Windows\System32\Drivers\nsiproxy.sys - ok
    23:46:00.0904 4888 [ 6081CEC9EF9EB145D8B46655C7708D51 ] C:\Windows\System32\Drivers\wanarp.sys
    23:46:00.0904 4888 C:\Windows\System32\Drivers\wanarp.sys - ok
    23:46:00.0906 4888 [ 388056EBD5FE6718FE669078DBE37897 ] C:\Windows\System32\Drivers\avgidsdrivera.sys
    23:46:00.0906 4888 C:\Windows\System32\Drivers\avgidsdrivera.sys - ok
    23:46:00.0908 4888 [ C4D01BD86D6B207275FC143EEA951D75 ] C:\Windows\System32\Drivers\dam.sys
    23:46:00.0908 4888 C:\Windows\System32\Drivers\dam.sys - ok
    23:46:00.0910 4888 [ 09D9EB9E7898F8E6561473A20CC808B9 ] C:\Windows\System32\Drivers\dfsc.sys
    23:46:00.0910 4888 C:\Windows\System32\Drivers\dfsc.sys - ok
    23:46:00.0912 4888 [ 3C736FAE17BA6F91BA37594AAB139CD0 ] C:\Windows\System32\Drivers\discache.sys
    23:46:00.0912 4888 C:\Windows\System32\Drivers\discache.sys - ok
    23:46:00.0914 4888 [ 7A6F8A6D0E01432EBA294EF29CDD0FA7 ] C:\Windows\System32\Drivers\ndistapi.sys
    23:46:00.0914 4888 C:\Windows\System32\Drivers\ndistapi.sys - ok
    23:46:00.0916 4888 [ 69B93F623B130976243ECA3D84CC99CA ] C:\Windows\System32\Drivers\agilevpn.sys
    23:46:00.0916 4888 C:\Windows\System32\Drivers\agilevpn.sys - ok
    23:46:00.0917 4888 [ 62C7DBF4F9301F76CF87D4B9D8F57BF8 ] C:\Windows\System32\Drivers\ndiswan.sys
    23:46:00.0917 4888 C:\Windows\System32\Drivers\ndiswan.sys - ok
    23:46:00.0919 4888 [ A7F24D8CD1956B0A1FDCB86CC5114DE4 ] C:\Windows\System32\Drivers\rassstp.sys
    23:46:00.0919 4888 C:\Windows\System32\Drivers\rassstp.sys - ok
    23:46:00.0921 4888 [ F1B8276F58969BD87683D33066DFE442 ] C:\Windows\System32\ntdll.dll
    23:46:00.0921 4888 C:\Windows\System32\ntdll.dll - ok
    23:46:00.0923 4888 [ 08F850FEBDBDE7C89017B6B0CA0D1CD2 ] C:\Windows\System32\smss.exe
    23:46:00.0923 4888 C:\Windows\System32\smss.exe - ok
    23:46:00.0925 4888 [ 0E5B1E9E7122EDAAF1F6CE047965CA92 ] C:\Windows\System32\Drivers\CompositeBus.sys
    23:46:00.0925 4888 C:\Windows\System32\Drivers\CompositeBus.sys - ok
    23:46:00.0926 4888 [ FB6C185092E18011EF49989425C2AA87 ] C:\Windows\System32\Drivers\kdnic.sys
    23:46:00.0926 4888 C:\Windows\System32\Drivers\kdnic.sys - ok
    23:46:00.0928 4888 [ 78C9EE193AC2B4CBDBC48B620314D740 ] C:\Windows\System32\Drivers\tunnel.sys
    23:46:00.0928 4888 C:\Windows\System32\Drivers\tunnel.sys - ok
    23:46:00.0931 4888 [ 02CEB3FE6152668A7BA420B93B664860 ] C:\Windows\System32\Drivers\umbus.sys
    23:46:00.0931 4888 C:\Windows\System32\Drivers\umbus.sys - ok
    23:46:00.0933 4888 [ 20F3CD38B107C1BD747C0EA37D450165 ] C:\Windows\System32\Drivers\atikmpag.sys
    23:46:00.0933 4888 C:\Windows\System32\Drivers\atikmpag.sys - ok
    23:46:00.0935 4888 [ A3C0A15B39F979E8F3EABA901D72ECD7 ] C:\Windows\System32\Drivers\atikmdag.sys
    23:46:00.0935 4888 C:\Windows\System32\Drivers\atikmdag.sys - ok
    23:46:00.0936 4888 [ 7D87B5B6C7188D553E11B59DC7F0B111 ] C:\Windows\System32\Drivers\hdaudbus.sys
    23:46:00.0936 4888 C:\Windows\System32\Drivers\hdaudbus.sys - ok
    23:46:00.0938 4888 [ A6518DCC42F7A6E999BB3BEA8FD87567 ] C:\Windows\System32\Drivers\HECIx64.sys
    23:46:00.0938 4888 C:\Windows\System32\Drivers\HECIx64.sys - ok
    23:46:00.0940 4888 [ 52F267AEE8CA5AA5CEB88C6A71EE1E86 ] C:\Windows\System32\Drivers\usbehci.sys
    23:46:00.0940 4888 C:\Windows\System32\Drivers\usbehci.sys - ok
    23:46:00.0942 4888 [ 169629C36CB835A36E23BBC37664401E ] C:\Windows\System32\Drivers\usbport.sys
    23:46:00.0942 4888 C:\Windows\System32\Drivers\usbport.sys - ok
    23:46:00.0944 4888 [ 9CD4259AD15F84DE27B94A956C978D6C ] C:\Windows\System32\Drivers\USBXHCI.SYS
    23:46:00.0944 4888 C:\Windows\System32\Drivers\USBXHCI.SYS - ok
    23:46:00.0945 4888 [ E890C46E4754F0DF51BAFCC8D2E07498 ] C:\Windows\System32\Drivers\1394ohci.sys
    23:46:00.0946 4888 C:\Windows\System32\Drivers\1394ohci.sys - ok
    23:46:00.0947 4888 [ 1ED222DFE6C13DA50FE081ABF90CAFE1 ] C:\Windows\System32\Drivers\UCX01000.SYS
    23:46:00.0947 4888 C:\Windows\System32\Drivers\UCX01000.SYS - ok
    23:46:00.0949 4888 [ 15923AA360F7675D3D43C9669316A0BA ] C:\Windows\System32\Drivers\Rt630x64.sys
    23:46:00.0949 4888 C:\Windows\System32\Drivers\Rt630x64.sys - ok
    23:46:00.0951 4888 [ 7A1F9347C85FD55E39B8A76B3A25C5AD ] C:\Windows\System32\Drivers\serenum.sys
    23:46:00.0951 4888 C:\Windows\System32\Drivers\serenum.sys - ok
    23:46:00.0952 4888 [ F640A0A218BBF857F1D04A15D7D939F6 ] C:\Windows\System32\Drivers\serial.sys
    23:46:00.0952 4888 C:\Windows\System32\Drivers\serial.sys - ok
    23:46:00.0955 4888 [ E15CDF68DD73423F15D4AC404793AF0D ] C:\Windows\System32\Drivers\intelppm.sys
    23:46:00.0955 4888 C:\Windows\System32\Drivers\intelppm.sys - ok
    23:46:00.0957 4888 [ A14D625C5AEE5FFE0F47D1A1D419FAAE ] C:\Windows\System32\Drivers\rasl2tp.sys
    23:46:00.0957 4888 C:\Windows\System32\Drivers\rasl2tp.sys - ok
    23:46:00.0959 4888 [ 00695B9C2DB6111064499C529E90C042 ] C:\Windows\System32\Drivers\raspppoe.sys
    23:46:00.0960 4888 C:\Windows\System32\Drivers\raspppoe.sys - ok
    23:46:00.0962 4888 [ 362D47E5B4D67270DE4B8606036F4ADD ] C:\Windows\System32\Drivers\raspptp.sys
    23:46:00.0962 4888 C:\Windows\System32\Drivers\raspptp.sys - ok
    23:46:00.0964 4888 [ E2A596CACFC6504306CDB7B593B90084 ] C:\Windows\System32\Drivers\wmiacpi.sys
    23:46:00.0964 4888 C:\Windows\System32\Drivers\wmiacpi.sys - ok
    23:46:00.0966 4888 [ 48258ED8A46D0F39ACBF891336250E89 ] C:\Windows\System32\Drivers\ks.sys
    23:46:00.0966 4888 C:\Windows\System32\Drivers\ks.sys - ok
    23:46:00.0968 4888 [ CA7DF5EC95D8DE0DD24BE7FF97369F68 ] C:\Windows\System32\Drivers\rdpbus.sys
    23:46:00.0968 4888 C:\Windows\System32\Drivers\rdpbus.sys - ok
    23:46:00.0970 4888 [ 4AFD66AAE74FFB5986BC240744DC5FC9 ] C:\Windows\System32\Drivers\swenum.sys
    23:46:00.0970 4888 C:\Windows\System32\Drivers\swenum.sys - ok
    23:46:00.0972 4888 [ CE6EBC0AD38CC6482D8FBB744FF15CE2 ] C:\Windows\System32\Drivers\ndproxy.sys
    23:46:00.0972 4888 C:\Windows\System32\Drivers\ndproxy.sys - ok
    23:46:00.0974 4888 [ 3FA129BFC7808A2BB7681BEAF339FACD ] C:\Windows\System32\Drivers\usbd.sys
    23:46:00.0974 4888 C:\Windows\System32\Drivers\usbd.sys - ok
    23:46:00.0975 4888 [ FBB6794E3BBAD92D66D59D206C1F849F ] C:\Windows\System32\Drivers\usbhub.sys
    23:46:00.0975 4888 C:\Windows\System32\Drivers\usbhub.sys - ok
    23:46:00.0977 4888 [ 87DAD8D354E312DB16636DC71EB39E5E ] C:\Windows\System32\Drivers\AtihdW86.sys
    23:46:00.0977 4888 C:\Windows\System32\Drivers\AtihdW86.sys - ok
    23:46:00.0979 4888 [ 946ECE07334A74373FAFBFAA063E62F2 ] C:\Windows\System32\Drivers\drmk.sys
    23:46:00.0979 4888 C:\Windows\System32\Drivers\drmk.sys - ok
    23:46:00.0981 4888 [ D10DAEA91AA8412A323DB8EADA23768A ] C:\Windows\System32\Drivers\portcls.sys
    23:46:00.0981 4888 C:\Windows\System32\Drivers\portcls.sys - ok
    23:46:00.0983 4888 [ 81492FEEBF2F26455B00EE8DBAE8A1B0 ] C:\Windows\System32\Drivers\ksthunk.sys
    23:46:00.0983 4888 C:\Windows\System32\Drivers\ksthunk.sys - ok
    23:46:00.0985 4888 [ 9FC1F11D4D19F61DFE5CC878B4557D3A ] C:\Windows\System32\Drivers\HdAudio.sys
    23:46:00.0985 4888 C:\Windows\System32\Drivers\HdAudio.sys - ok
    23:46:00.0987 4888 [ B7A948501424805571BF562BB0BFE31D ] C:\Windows\System32\Drivers\USBHUB3.SYS
    23:46:00.0987 4888 C:\Windows\System32\Drivers\USBHUB3.SYS - ok
    23:46:00.0989 4888 [ F77177F6C95B2116EE7AD23B5EF57007 ] C:\Windows\System32\Drivers\USBSTOR.SYS
    23:46:00.0989 4888 C:\Windows\System32\Drivers\USBSTOR.SYS - ok
    23:46:00.0990 4888 [ 490B7921C6DC58022FAA908E6310CF24 ] C:\Windows\System32\autochk.exe
    23:46:00.0990 4888 C:\Windows\System32\autochk.exe - ok
    23:46:00.0992 4888 [ DC83C9F4130F447EAD187879708C8035 ] C:\PROGRA~2\AVG\AVG2013\avgrsa.exe
    23:46:00.0992 4888 C:\PROGRA~2\AVG\AVG2013\avgrsa.exe - ok
    23:46:00.0994 4888 [ 23948829C6D049B8ADE0E0FB87305AC3 ] C:\Windows\System32\sdnclean64.exe
    23:46:00.0994 4888 C:\Windows\System32\sdnclean64.exe - ok
    23:46:00.0996 4888 [ E3F8DC5B5AF00A892ED3546C01C9B6E1 ] C:\Program Files (x86)\AVG\AVG2013\avgsysa.dll
    23:46:00.0996 4888 C:\Program Files (x86)\AVG\AVG2013\avgsysa.dll - ok
    23:46:00.0998 4888 [ 4848422594D3B6A6BFF438AF0B6D030D ] C:\Program Files (x86)\AVG\AVG2013\avgloga.dll
    23:46:00.0998 4888 C:\Program Files (x86)\AVG\AVG2013\avgloga.dll - ok
    23:46:01.0000 4888 [ 70D1A44B0D05FEC737CC2C9662D6FB70 ] C:\Program Files (x86)\AVG\AVG2013\avgntopenssla.dll
    23:46:01.0000 4888 C:\Program Files (x86)\AVG\AVG2013\avgntopenssla.dll - ok
    23:46:01.0001 4888 [ 784BD252A13B3DDDA29790FBCB64E536 ] C:\PROGRA~2\AVG\AVG2013\avgchjwa.dll
    23:46:01.0001 4888 C:\PROGRA~2\AVG\AVG2013\avgchjwa.dll - ok
    23:46:01.0003 4888 [ 2C19A4BC4D3C714F890A58B4C942077F ] C:\PROGRA~2\AVG\AVG2013\avgclita.dll
    23:46:01.0003 4888 C:\PROGRA~2\AVG\AVG2013\avgclita.dll - ok
    23:46:01.0005 4888 [ CF433BC29D4089D264F24A1ED371941D ] C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
    23:46:01.0005 4888 C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe - ok
    23:46:01.0007 4888 [ B4CF2DAC753DD785FD92076B3CD36CED ] C:\PROGRA~2\AVG\AVG2013\avgcclia.dll
    23:46:01.0007 4888 C:\PROGRA~2\AVG\AVG2013\avgcclia.dll - ok
    23:46:01.0009 4888 [ 6BCBEE7F87FBA202A834D856433079F2 ] C:\Program Files (x86)\AVG\AVG2013\avgcorea.dll
    23:46:01.0009 4888 C:\Program Files (x86)\AVG\AVG2013\avgcorea.dll - ok
    23:46:01.0011 4888 [ C297715529E28F7283EE621CCFDB1DDB ] C:\Program Files (x86)\AVG\AVG2013\avgcerta.dll
    23:46:01.0011 4888 C:\Program Files (x86)\AVG\AVG2013\avgcerta.dll - ok
    23:46:01.0013 4888 [ 06F3F7E9E9B29C32F8702B541E4C2156 ] C:\Program Files (x86)\AVG\AVG2013\avgchcla.dll
    23:46:01.0013 4888 C:\Program Files (x86)\AVG\AVG2013\avgchcla.dll - ok
    23:46:01.0015 4888 [ 275061F56FC648ED884C38A93EAB6FC6 ] C:\Program Files (x86)\AVG\AVG2013\avgcomma.dll
    23:46:01.0015 4888 C:\Program Files (x86)\AVG\AVG2013\avgcomma.dll - ok
    23:46:01.0016 4888 [ AAD184F33A9A4A2AECF3CB5247651D01 ] C:\Program Files (x86)\AVG\AVG2013\avgntsqlitea.dll
    23:46:01.0017 4888 C:\Program Files (x86)\AVG\AVG2013\avgntsqlitea.dll - ok
    23:46:01.0018 4888 [ 2AF9F0E16D75B8F783A1ACE74EF51C9B ] C:\Windows\System32\Drivers\usbccgp.sys
    23:46:01.0018 4888 C:\Windows\System32\Drivers\usbccgp.sys - ok
    23:46:01.0020 4888 [ 771BE60F1899D8E43CF563162A8A2FBB ] C:\Windows\System32\Drivers\hidclass.sys
    23:46:01.0020 4888 C:\Windows\System32\Drivers\hidclass.sys - ok
    23:46:01.0023 4888 [ 436188BB139D51E4A763D1D356C90EE3 ] C:\Windows\System32\Drivers\hidparse.sys
    23:46:01.0023 4888 C:\Windows\System32\Drivers\hidparse.sys - ok
    23:46:01.0024 4888 [ 590B6F71BCDA4368B4BF7D8DF22B60F7 ] C:\Windows\System32\Drivers\hidusb.sys
    23:46:01.0025 4888 C:\Windows\System32\Drivers\hidusb.sys - ok
    23:46:01.0027 4888 [ DF8663D43AAA1289DE7E32961722BBBA ] C:\Windows\System32\setupapi.dll
    23:46:01.0027 4888 C:\Windows\System32\setupapi.dll - ok
    23:46:01.0029 4888 [ AECED95ACFDCF96757EDD8D0CFFE34B8 ] C:\Windows\System32\msvcrt.dll
    23:46:01.0029 4888 C:\Windows\System32\msvcrt.dll - ok
    23:46:01.0031 4888 [ 8FBD94B69D6423E20ABCD59D86368B21 ] C:\Windows\System32\Drivers\kbdclass.sys
    23:46:01.0031 4888 C:\Windows\System32\Drivers\kbdclass.sys - ok
    23:46:01.0034 4888 [ E88C932ABDF8185A62C8F2FC7B051FB6 ] C:\Windows\System32\Drivers\kbdhid.sys
    23:46:01.0034 4888 C:\Windows\System32\Drivers\kbdhid.sys - ok
    23:46:01.0036 4888 [ B0CECE742DD090C8E2E0B47812F0A26F ] C:\Windows\System32\iertutil.dll
    23:46:01.0036 4888 C:\Windows\System32\iertutil.dll - ok
    23:46:01.0038 4888 [ 60996602A7111FD2D086E803F33E4282 ] C:\Windows\System32\Drivers\fastfat.sys
    23:46:01.0038 4888 C:\Windows\System32\Drivers\fastfat.sys - ok
    23:46:01.0040 4888 [ A74C6A6DA5A35686D7639ACDBD458BFB ] C:\Windows\System32\nsi.dll
    23:46:01.0040 4888 C:\Windows\System32\nsi.dll - ok
    23:46:01.0041 4888 [ 46501A8D9CF0383A104120810E1BABA6 ] C:\Windows\System32\shlwapi.dll
    23:46:01.0041 4888 C:\Windows\System32\shlwapi.dll - ok
    23:46:01.0043 4888 [ AE03548B97CC32199B69E20D29951BD6 ] C:\Windows\System32\Drivers\RTL8192su.sys
    23:46:01.0043 4888 C:\Windows\System32\Drivers\RTL8192su.sys - ok
    23:46:01.0045 4888 [ 62460A45435A26A334907E3F2EA45611 ] C:\Windows\System32\Drivers\vwifibus.sys
    23:46:01.0045 4888 C:\Windows\System32\Drivers\vwifibus.sys - ok
    23:46:01.0047 4888 [ 93FA1A230C11C8568DE3624263C35D39 ] C:\Windows\System32\GdiPlus.dll
    23:46:01.0047 4888 C:\Windows\System32\GdiPlus.dll - ok
    23:46:01.0048 4888 [ E1B2751640FA7840CC5EB6E78513A632 ] C:\Windows\System32\Wldap32.dll
    23:46:01.0048 4888 C:\Windows\System32\Wldap32.dll - ok
    23:46:01.0050 4888 [ 3FBE0784E42E7BA93FCC5201D2BAFE23 ] C:\Windows\System32\Drivers\USBAUDIO.sys
     
  8. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    23:46:01.0050 4888 C:\Windows\System32\Drivers\USBAUDIO.sys - ok
    23:46:01.0052 4888 [ 85B5B3797315F714A62AC986FFB2B17E ] C:\Windows\System32\sechost.dll
    23:46:01.0052 4888 C:\Windows\System32\sechost.dll - ok
    23:46:01.0054 4888 [ A99AD14F26BDA7D7F27F76BC91B7EED7 ] C:\Windows\System32\user32.dll
    23:46:01.0054 4888 C:\Windows\System32\user32.dll - ok
    23:46:01.0056 4888 [ CE1C66AD4D56FCD7301E1EFEA71340EC ] C:\Windows\System32\oleaut32.dll
    23:46:01.0056 4888 C:\Windows\System32\oleaut32.dll - ok
    23:46:01.0058 4888 [ 2AE813F005223E5B39E0C4D7B8314732 ] C:\Windows\System32\wow64win.dll
    23:46:01.0058 4888 C:\Windows\System32\wow64win.dll - ok
    23:46:01.0060 4888 [ 4522375A7B8693C2134D5613A134E4F6 ] C:\Windows\System32\msctf.dll
    23:46:01.0060 4888 C:\Windows\System32\msctf.dll - ok
    23:46:01.0062 4888 [ F02118B1D3B0D574C99D87380069B44E ] C:\Windows\System32\urlmon.dll
    23:46:01.0062 4888 C:\Windows\System32\urlmon.dll - ok
    23:46:01.0064 4888 [ 2E3EDE81672653E0C759F0A1135F704F ] C:\Windows\System32\clbcatq.dll
    23:46:01.0064 4888 C:\Windows\System32\clbcatq.dll - ok
    23:46:01.0066 4888 [ B3FB7D980FE7F6FB78D83B87C0D2F7F3 ] C:\Windows\System32\imagehlp.dll
    23:46:01.0066 4888 C:\Windows\System32\imagehlp.dll - ok
    23:46:01.0068 4888 [ 3A30E09AAA2BB060D39C8FA5E20D4FA3 ] C:\Windows\System32\advapi32.dll
    23:46:01.0068 4888 C:\Windows\System32\advapi32.dll - ok
    23:46:01.0070 4888 [ 3C6933B638BB812F4084CF44AE698704 ] C:\Windows\System32\kernel32.dll
    23:46:01.0070 4888 C:\Windows\System32\kernel32.dll - ok
    23:46:01.0072 4888 [ C3D51000E8FBEF76BC91E145B0D7FC67 ] C:\Windows\System32\comdlg32.dll
    23:46:01.0072 4888 C:\Windows\System32\comdlg32.dll - ok
    23:46:01.0073 4888 [ DA66D6D4A0B77D57F5CF449B1231010F ] C:\Windows\System32\imm32.dll
    23:46:01.0074 4888 C:\Windows\System32\imm32.dll - ok
    23:46:01.0075 4888 [ 1E2E99B4FA9A5F0D9934F8B99B528A62 ] C:\Windows\System32\wow64cpu.dll
    23:46:01.0075 4888 C:\Windows\System32\wow64cpu.dll - ok
    23:46:01.0077 4888 [ 2E5B349ACDA36C20612795754DB93312 ] C:\Windows\System32\ws2_32.dll
    23:46:01.0077 4888 C:\Windows\System32\ws2_32.dll - ok
    23:46:01.0079 4888 [ 6B3F1596000CB33F73E14B6F7D5CFF82 ] C:\Windows\System32\difxapi.dll
    23:46:01.0079 4888 C:\Windows\System32\difxapi.dll - ok
    23:46:01.0081 4888 [ 75CB0458521FFA420E4230A931E4517B ] C:\Windows\System32\normaliz.dll
    23:46:01.0081 4888 C:\Windows\System32\normaliz.dll - ok
    23:46:01.0082 4888 [ 652467DC0E67CF738972117C09D05571 ] C:\Windows\System32\rpcrt4.dll
    23:46:01.0082 4888 C:\Windows\System32\rpcrt4.dll - ok
    23:46:01.0084 4888 [ AAEF73606F58ADE710208F4B1B988FBF ] C:\Windows\System32\wininet.dll
    23:46:01.0084 4888 C:\Windows\System32\wininet.dll - ok
    23:46:01.0086 4888 [ CA7561AACEE1F578C5360E4C07B71708 ] C:\Windows\System32\gdi32.dll
    23:46:01.0086 4888 C:\Windows\System32\gdi32.dll - ok
    23:46:01.0088 4888 [ CC81790E0A18535853C33BABBFF15D56 ] C:\Windows\System32\lpk.dll
    23:46:01.0088 4888 C:\Windows\System32\lpk.dll - ok
    23:46:01.0090 4888 [ B74C50954E234506548CBBF3933AF391 ] C:\Windows\System32\wow64.dll
    23:46:01.0090 4888 C:\Windows\System32\wow64.dll - ok
    23:46:01.0092 4888 [ 1D2731630A5437C54217CDE1C4830F81 ] C:\Windows\System32\ole32.dll
    23:46:01.0092 4888 C:\Windows\System32\ole32.dll - ok
    23:46:01.0094 4888 [ 41AC2B1335317D2F8700E17328F71E0C ] C:\Windows\System32\psapi.dll
    23:46:01.0094 4888 C:\Windows\System32\psapi.dll - ok
    23:46:01.0095 4888 [ 154553459809F791C7335075211ED81B ] C:\Windows\System32\shell32.dll
    23:46:01.0095 4888 C:\Windows\System32\shell32.dll - ok
    23:46:01.0097 4888 [ CB2527B8B87D83E56FBF3944BBB6F606 ] C:\Windows\System32\Drivers\mouhid.sys
    23:46:01.0097 4888 C:\Windows\System32\Drivers\mouhid.sys - ok
    23:46:01.0099 4888 [ 618446B98C79776654340CE27C73485E ] C:\Windows\System32\Drivers\mouclass.sys
    23:46:01.0099 4888 C:\Windows\System32\Drivers\mouclass.sys - ok
    23:46:01.0100 4888 [ 0341C9184C252000D1AD396C71CFD860 ] C:\Windows\System32\combase.dll
    23:46:01.0100 4888 C:\Windows\System32\combase.dll - ok
    23:46:01.0102 4888 [ EFD55F2C466663F37412B843F6CC55F5 ] C:\Windows\System32\crypt32.dll
    23:46:01.0102 4888 C:\Windows\System32\crypt32.dll - ok
    23:46:01.0103 4888 [ 996604E515ACE3775D645A4FE0D66D4A ] C:\Windows\System32\wintrust.dll
    23:46:01.0103 4888 C:\Windows\System32\wintrust.dll - ok
    23:46:01.0106 4888 [ C26780F936820DBB3A1323FC1C09E05F ] C:\Windows\System32\cfgmgr32.dll
    23:46:01.0106 4888 C:\Windows\System32\cfgmgr32.dll - ok
    23:46:01.0108 4888 [ 03E223CC4AE2D2B55E400AD9C55449F6 ] C:\Windows\System32\comctl32.dll
    23:46:01.0108 4888 C:\Windows\System32\comctl32.dll - ok
    23:46:01.0111 4888 [ F37BD0CAA604B6FE5CEC9D0BC05ABAF8 ] C:\Windows\System32\KernelBase.dll
    23:46:01.0111 4888 C:\Windows\System32\KernelBase.dll - ok
    23:46:01.0113 4888 [ 51B6CB1852B49E150F7E8B8C2F4CB0F7 ] C:\Windows\System32\devobj.dll
    23:46:01.0113 4888 C:\Windows\System32\devobj.dll - ok
    23:46:01.0114 4888 [ C763F7DC50C70E657DCB164FA9D92085 ] C:\Windows\System32\msasn1.dll
    23:46:01.0114 4888 C:\Windows\System32\msasn1.dll - ok
    23:46:01.0116 4888 [ BD321B58C0CC6C8196F8CF4EE226E830 ] C:\Windows\SysWOW64\normaliz.dll
    23:46:01.0116 4888 C:\Windows\SysWOW64\normaliz.dll - ok
    23:46:01.0118 4888 [ 36D755FFED947A08B1650ACE9644FAB8 ] C:\Windows\SysWOW64\lpk.dll
    23:46:01.0118 4888 C:\Windows\SysWOW64\lpk.dll - ok
    23:46:01.0120 4888 [ F3427D3D28F02A4BE6DFC1E672E30BA3 ] C:\Windows\System32\win32k.sys
    23:46:01.0120 4888 C:\Windows\System32\win32k.sys - ok
    23:46:01.0122 4888 [ DDC1AFBF9DDF880CE9BD3896114D8DED ] C:\Windows\System32\basesrv.dll
    23:46:01.0122 4888 C:\Windows\System32\basesrv.dll - ok
    23:46:01.0123 4888 [ 1C510F9C2DB7393468EB789A96DAAFA8 ] C:\Windows\System32\csrsrv.dll
    23:46:01.0123 4888 C:\Windows\System32\csrsrv.dll - ok
    23:46:01.0125 4888 [ 0D9F14739D05F8B8B028B539FC6F1F29 ] C:\Windows\System32\csrss.exe
    23:46:01.0125 4888 C:\Windows\System32\csrss.exe - ok
    23:46:01.0127 4888 [ E9343076AE704D20BB0D01F3AF3EFFEF ] C:\Windows\System32\winsrv.dll
    23:46:01.0127 4888 C:\Windows\System32\winsrv.dll - ok
    23:46:01.0128 4888 [ 83EB0BF7E6EBD5B1AAC97F9DBD5EB935 ] C:\Windows\System32\Drivers\monitor.sys
    23:46:01.0128 4888 C:\Windows\System32\Drivers\monitor.sys - ok
    23:46:01.0130 4888 [ BD7C6949984D19AAA609896B675E7357 ] C:\Windows\System32\sxssrv.dll
    23:46:01.0130 4888 C:\Windows\System32\sxssrv.dll - ok
    23:46:01.0132 4888 [ F14D77B1B3347ED08272B65A3F80B4CE ] C:\Windows\System32\tsddd.dll
    23:46:01.0132 4888 C:\Windows\System32\tsddd.dll - ok
    23:46:01.0134 4888 [ 3491660B47A7CE7BC1B63C4E71E1E251 ] C:\Windows\System32\cdd.dll
    23:46:01.0134 4888 C:\Windows\System32\cdd.dll - ok
    23:46:01.0135 4888 [ FD777FE5B879BC921ED01A647143D709 ] C:\Windows\System32\KBDUS.DLL
    23:46:01.0135 4888 C:\Windows\System32\KBDUS.DLL - ok
    23:46:01.0137 4888 [ 4C7303709714F589A0809AC82F03CA84 ] C:\Windows\System32\profapi.dll
    23:46:01.0137 4888 C:\Windows\System32\profapi.dll - ok
    23:46:01.0138 4888 [ FE9AB232B56A12224E8A3F3F9878C9A3 ] C:\Windows\System32\wininit.exe
    23:46:01.0138 4888 C:\Windows\System32\wininit.exe - ok
    23:46:01.0140 4888 [ 8144BCD1736C3C76978B8378556CA746 ] C:\Windows\System32\wininitext.dll
    23:46:01.0140 4888 C:\Windows\System32\wininitext.dll - ok
    23:46:01.0142 4888 [ 10564D7D4FBAABDB826E9D607679C85F ] C:\Windows\System32\WlS0WndH.dll
    23:46:01.0142 4888 C:\Windows\System32\WlS0WndH.dll - ok
    23:46:01.0143 4888 [ 7679414791657155EDF45D388325BEFE ] C:\Windows\System32\sxs.dll
    23:46:01.0143 4888 C:\Windows\System32\sxs.dll - ok
    23:46:01.0145 4888 [ BCF2036A0DD579E47C008C133550283E ] C:\Windows\System32\winlogon.exe
    23:46:01.0145 4888 C:\Windows\System32\winlogon.exe - ok
    23:46:01.0147 4888 [ EF72CFB67C73A8751F3BC4F4C98EAD4C ] C:\Windows\System32\powrprof.dll
    23:46:01.0147 4888 C:\Windows\System32\powrprof.dll - ok
    23:46:01.0148 4888 [ C0FAB7DDA13CE5593A48B40056AA278D ] C:\Windows\System32\samcli.dll
    23:46:01.0148 4888 C:\Windows\System32\samcli.dll - ok
    23:46:01.0150 4888 [ 9D7EAFBAD213566D70BAE9A14B847666 ] C:\Windows\System32\winsta.dll
    23:46:01.0150 4888 C:\Windows\System32\winsta.dll - ok
    23:46:01.0152 4888 [ E8001E0F56F0B0F5D204EF865F47372B ] C:\Windows\System32\wtsapi32.dll
    23:46:01.0152 4888 C:\Windows\System32\wtsapi32.dll - ok
    23:46:01.0154 4888 [ 7F4E2FB897E35952C5B22BE48047FCA8 ] C:\Windows\System32\bcryptprimitives.dll
    23:46:01.0154 4888 C:\Windows\System32\bcryptprimitives.dll - ok
    23:46:01.0156 4888 [ 2577AEA213B0B70FF5B4E3D180E66B11 ] C:\Windows\System32\cryptbase.dll
    23:46:01.0156 4888 C:\Windows\System32\cryptbase.dll - ok
    23:46:01.0157 4888 [ F702AB6181513303AB0FC8D59E52708B ] C:\Windows\System32\lsass.exe
    23:46:01.0157 4888 C:\Windows\System32\lsass.exe - ok
    23:46:01.0159 4888 [ 8F226143046435C75C033B0C52E90FFE ] C:\Windows\System32\services.exe
    23:46:01.0159 4888 C:\Windows\System32\services.exe - ok
    23:46:01.0160 4888 [ D293F2E8CEE73B87B04790D5169C0F25 ] C:\Windows\System32\lsasrv.dll
    23:46:01.0160 4888 C:\Windows\System32\lsasrv.dll - ok
    23:46:01.0162 4888 [ ECFC9AF8D1A6E16223E1B17EA732FA08 ] C:\Windows\System32\scext.dll
    23:46:01.0162 4888 C:\Windows\System32\scext.dll - ok
    23:46:01.0165 4888 [ D71A882FE7A74F01B92F6A2C74305E45 ] C:\Windows\System32\srvcli.dll
    23:46:01.0165 4888 C:\Windows\System32\srvcli.dll - ok
    23:46:01.0167 4888 [ D1AEFA79EE1EE089D03249BE581D5DD6 ] C:\Windows\System32\sspicli.dll
    23:46:01.0167 4888 C:\Windows\System32\sspicli.dll - ok
    23:46:01.0168 4888 [ 90BEE4B9728DDCF9787100CB8A04815C ] C:\Windows\System32\sspisrv.dll
    23:46:01.0168 4888 C:\Windows\System32\sspisrv.dll - ok
    23:46:01.0170 4888 [ 8A6CAF25365FDF2432054C672885917E ] C:\Windows\System32\ubpm.dll
    23:46:01.0170 4888 C:\Windows\System32\ubpm.dll - ok
    23:46:01.0172 4888 [ E3D5F59826899393970533A8E6AB34EE ] C:\Windows\System32\bcrypt.dll
    23:46:01.0172 4888 C:\Windows\System32\bcrypt.dll - ok
    23:46:01.0174 4888 [ 1B5B5563C5008911D77398B8FDC6F757 ] C:\Windows\System32\samsrv.dll
    23:46:01.0174 4888 C:\Windows\System32\samsrv.dll - ok
    23:46:01.0176 4888 [ DF8111BDC2F35006F0CD471A2CC65665 ] C:\Windows\System32\SPInf.dll
    23:46:01.0176 4888 C:\Windows\System32\SPInf.dll - ok
    23:46:01.0178 4888 [ 39084062AB7B7CA19DBF0AA4581D833B ] C:\Windows\System32\msprivs.dll
    23:46:01.0178 4888 C:\Windows\System32\msprivs.dll - ok
    23:46:01.0179 4888 [ EA697BA99655FA048BB297EE9A3CCBC7 ] C:\Windows\System32\ncrypt.dll
    23:46:01.0179 4888 C:\Windows\System32\ncrypt.dll - ok
    23:46:01.0181 4888 [ 21AA2C2564DDB9F3B83CE322D9E97F9C ] C:\Windows\System32\netjoin.dll
    23:46:01.0181 4888 C:\Windows\System32\netjoin.dll - ok
    23:46:01.0182 4888 [ A6FE1FCAB4AC686D6BD7884B317935F7 ] C:\Windows\System32\ntasn1.dll
    23:46:01.0182 4888 C:\Windows\System32\ntasn1.dll - ok
    23:46:01.0184 4888 [ 058B0CDA8E19AF2A7E6CFA7604BB8D14 ] C:\Windows\System32\cryptdll.dll
    23:46:01.0184 4888 C:\Windows\System32\cryptdll.dll - ok
    23:46:01.0186 4888 [ 1654B23B029698077A59469E6AC93A99 ] C:\Windows\System32\kerberos.dll
    23:46:01.0186 4888 C:\Windows\System32\kerberos.dll - ok
    23:46:01.0188 4888 [ 016EDF8CF3BC0428F9A910637E918808 ] C:\Windows\System32\negoexts.dll
    23:46:01.0188 4888 C:\Windows\System32\negoexts.dll - ok
    23:46:01.0190 4888 [ 8F9F55C4B857E35552D78A2AAF1BADF9 ] C:\Windows\System32\cryptsp.dll
    23:46:01.0190 4888 C:\Windows\System32\cryptsp.dll - ok
    23:46:01.0191 4888 [ 4543E23FF678CA9D2C943A45B5B82A17 ] C:\Windows\System32\msv1_0.dll
    23:46:01.0191 4888 C:\Windows\System32\msv1_0.dll - ok
    23:46:01.0193 4888 [ 1AC307A2F7317007BC382046B3835202 ] C:\Windows\System32\mswsock.dll
    23:46:01.0193 4888 C:\Windows\System32\mswsock.dll - ok
    23:46:01.0195 4888 [ B16A14270DB26838B48A06835FDBBFB4 ] C:\Windows\System32\dnsapi.dll
    23:46:01.0195 4888 C:\Windows\System32\dnsapi.dll - ok
    23:46:01.0197 4888 [ FDC70965F0FC9DFEBC919627DED5DDFF ] C:\Windows\System32\netlogon.dll
    23:46:01.0197 4888 C:\Windows\System32\netlogon.dll - ok
    23:46:01.0198 4888 [ 113E9BB020461D5F9D0C0C6EA29C513F ] C:\Windows\System32\logoncli.dll
    23:46:01.0198 4888 C:\Windows\System32\logoncli.dll - ok
    23:46:01.0200 4888 [ 6847834F846A4CF1CD4FC86334B4879D ] C:\Windows\System32\schannel.dll
    23:46:01.0200 4888 C:\Windows\System32\schannel.dll - ok
    23:46:01.0202 4888 [ 72FCEDD4EEE5F1C38F84F0947A26950E ] C:\Windows\System32\userenv.dll
    23:46:01.0202 4888 C:\Windows\System32\userenv.dll - ok
    23:46:01.0205 4888 [ BB4FCE5019D973A8BA038A03C7ECECDD ] C:\Windows\System32\rsaenh.dll
    23:46:01.0205 4888 C:\Windows\System32\rsaenh.dll - ok
    23:46:01.0208 4888 [ CC6D17EDB5B1C73523E4B7D6EB7BBC09 ] C:\Windows\System32\TSpkg.dll
    23:46:01.0208 4888 C:\Windows\System32\TSpkg.dll - ok
    23:46:01.0209 4888 [ 0DFEBCD834EF05A112BF90F8A7993212 ] C:\Windows\System32\wdigest.dll
    23:46:01.0209 4888 C:\Windows\System32\wdigest.dll - ok
    23:46:01.0211 4888 [ 2F5E3751FAB4AE994262E2FB9CEDC885 ] C:\Windows\System32\dpapisrv.dll
    23:46:01.0211 4888 C:\Windows\System32\dpapisrv.dll - ok
    23:46:01.0213 4888 [ D8BEFDDADA7125E5A4DD37EA5AC620D9 ] C:\Windows\System32\efslsaext.dll
    23:46:01.0213 4888 C:\Windows\System32\efslsaext.dll - ok
    23:46:01.0214 4888 [ 5B92CE37EBE65A5424074E50C48AA52E ] C:\Windows\System32\livessp.dll
    23:46:01.0214 4888 C:\Windows\System32\livessp.dll - ok
    23:46:01.0216 4888 [ 0059D2032BCA18EBBC03D6D1308892F6 ] C:\Windows\System32\pku2u.dll
    23:46:01.0216 4888 C:\Windows\System32\pku2u.dll - ok
    23:46:01.0218 4888 [ 8EA33056071F6EB7A97C68E978F01573 ] C:\Windows\System32\credssp.dll
    23:46:01.0218 4888 C:\Windows\System32\credssp.dll - ok
    23:46:01.0219 4888 [ 4F6E1CA672370A9BCAC049CE3AB7F666 ] C:\Windows\System32\scecli.dll
    23:46:01.0219 4888 C:\Windows\System32\scecli.dll - ok
    23:46:01.0221 4888 [ C0D0F60B47079C2AAD30B836326313F4 ] C:\Windows\System32\scesrv.dll
    23:46:01.0221 4888 C:\Windows\System32\scesrv.dll - ok
    23:46:01.0223 4888 [ 0D7B278E91F0F07BBC4DFDF634BEFDB5 ] C:\Windows\System32\authz.dll
    23:46:01.0223 4888 C:\Windows\System32\authz.dll - ok
    23:46:01.0225 4888 [ 0CE9A21C24E62DFD77E273B56B11C2C7 ] C:\Windows\System32\devrtl.dll
    23:46:01.0225 4888 C:\Windows\System32\devrtl.dll - ok
    23:46:01.0227 4888 [ E17EA93682D88F1CE94CCE2A804FA691 ] C:\Windows\System32\netutils.dll
    23:46:01.0227 4888 C:\Windows\System32\netutils.dll - ok
    23:46:01.0229 4888 [ EDE27EACE742EE2888C5DD36400A2EC0 ] C:\Windows\System32\svchost.exe
    23:46:01.0229 4888 C:\Windows\System32\svchost.exe - ok
    23:46:01.0231 4888 [ 799BE46D45D486704CE0F37CA5385262 ] C:\Windows\System32\umpnpmgr.dll
    23:46:01.0231 4888 C:\Windows\System32\umpnpmgr.dll - ok
    23:46:01.0232 4888 [ 5C2758C697F6EC1C3771902D5FDF8079 ] C:\Windows\System32\gpapi.dll
    23:46:01.0232 4888 C:\Windows\System32\gpapi.dll - ok
    23:46:01.0234 4888 [ 2BA42F109B70D10E2F12072AD5BFFE27 ] C:\Windows\System32\hid.dll
    23:46:01.0234 4888 C:\Windows\System32\hid.dll - ok
    23:46:01.0236 4888 [ 61A8BF961A244C60697814D8CC2741FA ] C:\Windows\System32\pcwum.dll
    23:46:01.0236 4888 C:\Windows\System32\pcwum.dll - ok
    23:46:01.0238 4888 [ F1E067F56373F11EA4B785CAE823740A ] C:\Windows\System32\umpo.dll
    23:46:01.0238 4888 C:\Windows\System32\umpo.dll - ok
    23:46:01.0240 4888 [ 58CE8F135CC6F3271603A8BB094B1967 ] C:\Windows\System32\umpoext.dll
    23:46:01.0240 4888 C:\Windows\System32\umpoext.dll - ok
    23:46:01.0242 4888 [ 2BDC5D711FA61307CE6190D47C956368 ] C:\Windows\System32\Drivers\luafv.sys
    23:46:01.0242 4888 C:\Windows\System32\Drivers\luafv.sys - ok
    23:46:01.0243 4888 [ 92EB844D90615CB266F84C3202B8786E ] C:\Windows\System32\Drivers\mbam.sys
     
  9. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    23:46:01.0243 4888 C:\Windows\System32\Drivers\mbam.sys - ok
    23:46:01.0245 4888 [ 1EC6E533C954BDDF2A37E7851A7E58FD ] C:\Windows\System32\rpcss.dll
    23:46:01.0245 4888 C:\Windows\System32\rpcss.dll - ok
    23:46:01.0248 4888 [ 73F2E030B5C24E4E41401B5F0D59E6FD ] C:\Windows\System32\RpcEpMap.dll
    23:46:01.0248 4888 C:\Windows\System32\RpcEpMap.dll - ok
    23:46:01.0249 4888 [ 587089B7A93F3DE43832F3DBDD8F4653 ] C:\Windows\System32\RpcRtRemote.dll
    23:46:01.0249 4888 C:\Windows\System32\RpcRtRemote.dll - ok
    23:46:01.0251 4888 [ 975398A3D2C1FEA73FC93931978DF354 ] C:\Windows\System32\bisrv.dll
    23:46:01.0251 4888 C:\Windows\System32\bisrv.dll - ok
    23:46:01.0253 4888 [ 43197AE4DF1F8D5A95C5134C81B05FB9 ] C:\Windows\System32\FirewallAPI.dll
    23:46:01.0253 4888 C:\Windows\System32\FirewallAPI.dll - ok
    23:46:01.0255 4888 [ 8FEFDCEE40B75FD23B4BC60DA6576113 ] C:\Windows\System32\lsm.dll
    23:46:01.0255 4888 C:\Windows\System32\lsm.dll - ok
    23:46:01.0257 4888 [ 066FE80AE0AC570822EB37970E27EA1D ] C:\Windows\System32\psmsrv.dll
    23:46:01.0257 4888 C:\Windows\System32\psmsrv.dll - ok
    23:46:01.0259 4888 [ 2383FFF04B78586DB2F78E82583F630A ] C:\Windows\System32\sysntfy.dll
    23:46:01.0259 4888 C:\Windows\System32\sysntfy.dll - ok
    23:46:01.0261 4888 [ E5D1CB25AB7050FE4A4397089BE2AA09 ] C:\Windows\System32\wmsgapi.dll
    23:46:01.0261 4888 C:\Windows\System32\wmsgapi.dll - ok
    23:46:01.0264 4888 [ 4C1E3649C89C7D542CD18ECC5210099D ] C:\Windows\System32\atiesrxx.exe
    23:46:01.0264 4888 C:\Windows\System32\atiesrxx.exe - ok
    23:46:01.0266 4888 [ F718B60213F47D9702F5048DC703C13D ] C:\Windows\System32\UXInit.dll
    23:46:01.0266 4888 C:\Windows\System32\UXInit.dll - ok
    23:46:01.0268 4888 [ B5CCCD2C6A0CC5CAE2B5140A1985DD69 ] C:\Windows\System32\uxtheme.dll
    23:46:01.0268 4888 C:\Windows\System32\uxtheme.dll - ok
    23:46:01.0270 4888 [ 52576C623E5877D6CD73479610A532C2 ] C:\Windows\System32\dpapi.dll
    23:46:01.0270 4888 C:\Windows\System32\dpapi.dll - ok
    23:46:01.0272 4888 [ 11EA2B2C58E38BDBBEC4298BCEE40A59 ] C:\Windows\System32\wevtsvc.dll
    23:46:01.0272 4888 C:\Windows\System32\wevtsvc.dll - ok
    23:46:01.0274 4888 [ 0CBF0748B3F6C978233BBDD1D9D6A023 ] C:\Windows\System32\dwm.exe
    23:46:01.0274 4888 C:\Windows\System32\dwm.exe - ok
    23:46:01.0276 4888 [ 5358678C6370F2ADC5291849F6503262 ] C:\Windows\System32\gpsvc.dll
    23:46:01.0276 4888 C:\Windows\System32\gpsvc.dll - ok
    23:46:01.0278 4888 [ FAD009934DE5E8FA2511109B2349B9B1 ] C:\Windows\System32\LogonUI.exe
    23:46:01.0278 4888 C:\Windows\System32\LogonUI.exe - ok
    23:46:01.0279 4888 [ 3DB7FFC313BD190D0E64931302776BAF ] C:\Windows\System32\ntmarta.dll
    23:46:01.0279 4888 C:\Windows\System32\ntmarta.dll - ok
    23:46:01.0281 4888 [ 429E8502AD2227CF88F8840FC5BD590D ] C:\Windows\System32\profsvc.dll
    23:46:01.0281 4888 C:\Windows\System32\profsvc.dll - ok
    23:46:01.0283 4888 [ 519A6F672FFF56B7D8EE8C730CEC8ECD ] C:\Windows\System32\themeservice.dll
    23:46:01.0283 4888 C:\Windows\System32\themeservice.dll - ok
    23:46:01.0285 4888 [ 064FEE2A4EEE419868FE409C4C065A24 ] C:\Windows\System32\authui.dll
    23:46:01.0285 4888 C:\Windows\System32\authui.dll - ok
    23:46:01.0287 4888 [ 849958533A0CB20B5B738CA963A81EAF ] C:\Windows\System32\dwmredir.dll
    23:46:01.0287 4888 C:\Windows\System32\dwmredir.dll - ok
    23:46:01.0289 4888 [ 65F870703D4DC0FC382C23EB2A609252 ] C:\Windows\System32\dwmcore.dll
    23:46:01.0289 4888 C:\Windows\System32\dwmcore.dll - ok
    23:46:01.0291 4888 [ F0C56FAF38A244599CBC173D581E27FC ] C:\Windows\System32\nlaapi.dll
    23:46:01.0291 4888 C:\Windows\System32\nlaapi.dll - ok
    23:46:01.0292 4888 [ 91E1A704990CEE32FFFBDF8AB8C258E4 ] C:\Windows\System32\dsrole.dll
    23:46:01.0292 4888 C:\Windows\System32\dsrole.dll - ok
    23:46:01.0294 4888 [ F9E01C2D9F8BC049E04CF5DC24A5F638 ] C:\Windows\System32\es.dll
    23:46:01.0294 4888 C:\Windows\System32\es.dll - ok
    23:46:01.0296 4888 [ 91F2CB5172B120F7BE0645882D4427C8 ] C:\Windows\System32\profsvcext.dll
    23:46:01.0296 4888 C:\Windows\System32\profsvcext.dll - ok
    23:46:01.0298 4888 [ BF81D887348C8DD9E45B08F3718F7D96 ] C:\Windows\System32\SHCore.dll
    23:46:01.0298 4888 C:\Windows\System32\SHCore.dll - ok
    23:46:01.0300 4888 [ B1256D36D6D415FB924A26957A83C2CB ] C:\Windows\System32\dcomp.dll
    23:46:01.0300 4888 C:\Windows\System32\dcomp.dll - ok
    23:46:01.0302 4888 [ 80E5C64479952266CCFCF52CBBBE84DC ] C:\Windows\System32\dui70.dll
    23:46:01.0302 4888 C:\Windows\System32\dui70.dll - ok
    23:46:01.0304 4888 [ D70E930E67968D0F849333841DDBA02B ] C:\Windows\System32\netapi32.dll
    23:46:01.0304 4888 C:\Windows\System32\netapi32.dll - ok
    23:46:01.0306 4888 [ BB6591EA99CBCD17989CBF04214DD7E8 ] C:\Windows\System32\ntdsapi.dll
    23:46:01.0306 4888 C:\Windows\System32\ntdsapi.dll - ok
    23:46:01.0308 4888 [ F235600515AD6CBE06DB440FBB7C8E01 ] C:\Windows\System32\atl.dll
    23:46:01.0308 4888 C:\Windows\System32\atl.dll - ok
    23:46:01.0310 4888 [ 38082C25FC60B10977AC729127A4463D ] C:\Windows\System32\dwmapi.dll
    23:46:01.0310 4888 C:\Windows\System32\dwmapi.dll - ok
    23:46:01.0311 4888 [ C6D71F42C6CB7F3AECFEDC1C0DDE8232 ] C:\Windows\System32\WindowsCodecs.dll
    23:46:01.0311 4888 C:\Windows\System32\WindowsCodecs.dll - ok
    23:46:01.0313 4888 [ 6CB5B0F8F835B0E69857436405BA6E28 ] C:\Windows\System32\d3d10_1.dll
    23:46:01.0313 4888 C:\Windows\System32\d3d10_1.dll - ok
    23:46:01.0315 4888 [ 4A945F0177124D653B5EF975D11DA9F8 ] C:\Windows\System32\dfscli.dll
    23:46:01.0315 4888 C:\Windows\System32\dfscli.dll - ok
    23:46:01.0317 4888 [ FC414C8C91848FACFD6514AEF88A5ABA ] C:\Windows\System32\wkscli.dll
    23:46:01.0317 4888 C:\Windows\System32\wkscli.dll - ok
    23:46:01.0319 4888 [ E2B8F9FE6FA401AEB0BDFF8ED61A7568 ] C:\Windows\System32\wmiclnt.dll
    23:46:01.0319 4888 C:\Windows\System32\wmiclnt.dll - ok
    23:46:01.0321 4888 [ 16E116784B900D8A58DA4FB2FF1F0931 ] C:\Windows\System32\atieclxx.exe
    23:46:01.0321 4888 C:\Windows\System32\atieclxx.exe - ok
    23:46:01.0323 4888 [ 3951ECF063787EB40CD33D2961B39E23 ] C:\Windows\System32\d3d10_1core.dll
    23:46:01.0323 4888 C:\Windows\System32\d3d10_1core.dll - ok
    23:46:01.0325 4888 [ 9C51620998F0763039DFA6BF68E475ED ] C:\Windows\System32\Sens.dll
    23:46:01.0325 4888 C:\Windows\System32\Sens.dll - ok
    23:46:01.0327 4888 [ 4B249FD266D2FF17EE8809EB46A173A6 ] C:\Windows\System32\taskschd.dll
    23:46:01.0327 4888 C:\Windows\System32\taskschd.dll - ok
    23:46:01.0328 4888 [ ABA350274707D09D91826ED8EAF886B5 ] C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f\comctl32.dll
    23:46:01.0328 4888 C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_418c2a697189c07f\comctl32.dll - ok
    23:46:01.0330 4888 [ 810ED88782952228AF9C0985FB7D259E ] C:\Windows\System32\AudioEndpointBuilder.dll
    23:46:01.0330 4888 C:\Windows\System32\AudioEndpointBuilder.dll - ok
    23:46:01.0332 4888 [ 02DF949C584B02FAB05868502C578D42 ] C:\Windows\System32\dxgi.dll
    23:46:01.0332 4888 C:\Windows\System32\dxgi.dll - ok
    23:46:01.0334 4888 [ 0BCDC0FF11B984162B0CF0FF6E9E0146 ] C:\Windows\System32\FntCache.dll
    23:46:01.0334 4888 C:\Windows\System32\FntCache.dll - ok
    23:46:01.0335 4888 [ EEE908BE7143FCA48CF0CB87214E2AB8 ] C:\Windows\System32\mmcss.dll
    23:46:01.0335 4888 C:\Windows\System32\mmcss.dll - ok
    23:46:01.0337 4888 [ 37843E6888569097918544F0338BC19D ] C:\Windows\System32\avrt.dll
    23:46:01.0337 4888 C:\Windows\System32\avrt.dll - ok
    23:46:01.0339 4888 [ EAE1E802E8DBA1A8562652A29D520BEF ] C:\Windows\System32\d3d11.dll
    23:46:01.0339 4888 C:\Windows\System32\d3d11.dll - ok
    23:46:01.0341 4888 [ 5264BDA0ACE3D560336AC2EAD0728D41 ] C:\Windows\System32\duser.dll
    23:46:01.0341 4888 C:\Windows\System32\duser.dll - ok
    23:46:01.0343 4888 [ B5FEAE9A8C299EB6D1B6D810CDB4A9A7 ] C:\Windows\System32\MMDevAPI.dll
    23:46:01.0343 4888 C:\Windows\System32\MMDevAPI.dll - ok
    23:46:01.0345 4888 [ F76BE04CD180721363FBD7884C90C09E ] C:\Windows\System32\atiadlxx.dll
    23:46:01.0345 4888 C:\Windows\System32\atiadlxx.dll - ok
    23:46:01.0347 4888 [ D3F63550DCDA80A2AFB218A86A4EC5F0 ] C:\Windows\System32\BCP47Langs.dll
    23:46:01.0347 4888 C:\Windows\System32\BCP47Langs.dll - ok
    23:46:01.0348 4888 [ 46F09D226A9F0676932657A6761CEB82 ] C:\Windows\System32\d3d10warp.dll
    23:46:01.0349 4888 C:\Windows\System32\d3d10warp.dll - ok
    23:46:01.0350 4888 [ D39F1714D8944A0AC590B08F5A2DD0E7 ] C:\Windows\System32\SndVolSSO.dll
    23:46:01.0350 4888 C:\Windows\System32\SndVolSSO.dll - ok
    23:46:01.0352 4888 [ 721CAFC7474688EFB2961726DBBF1C78 ] C:\Windows\System32\wsock32.dll
    23:46:01.0352 4888 C:\Windows\System32\wsock32.dll - ok
    23:46:01.0354 4888 [ 8696D6FA6F96F34EB9151704ABAF133A ] C:\Windows\System32\aticfx64.dll
    23:46:01.0355 4888 C:\Windows\System32\aticfx64.dll - ok
    23:46:01.0357 4888 [ 156B8769D44187090781DFA9FED1AE18 ] C:\Windows\System32\SmartcardCredentialProvider.dll
    23:46:01.0357 4888 C:\Windows\System32\SmartcardCredentialProvider.dll - ok
    23:46:01.0359 4888 [ 25CA8B87479A374919563B3EE7136F32 ] C:\Windows\System32\audiosrv.dll
    23:46:01.0359 4888 C:\Windows\System32\audiosrv.dll - ok
    23:46:01.0362 4888 [ 20A19E2D29F86B2B3AA5B2A8B96B3041 ] C:\Windows\System32\DWrite.dll
    23:46:01.0362 4888 C:\Windows\System32\DWrite.dll - ok
    23:46:01.0365 4888 [ 439580916E49358F8BE33005E98E4B1F ] C:\Windows\System32\BioCredProv.dll
    23:46:01.0365 4888 C:\Windows\System32\BioCredProv.dll - ok
    23:46:01.0367 4888 [ C98F6286818474AB284144A73EC7BA6D ] C:\Windows\System32\cngcredui.dll
    23:46:01.0367 4888 C:\Windows\System32\cngcredui.dll - ok
    23:46:01.0368 4888 [ 7FA8C13A62CAEB2D84A731030DC1B866 ] C:\Windows\System32\oleacc.dll
    23:46:01.0368 4888 C:\Windows\System32\oleacc.dll - ok
    23:46:01.0372 4888 [ CE0884D5E82E48F0959BEE3006BEA0E1 ] C:\Windows\System32\certCredProvider.dll
    23:46:01.0372 4888 C:\Windows\System32\certCredProvider.dll - ok
    23:46:01.0374 4888 [ 855D7BA4DC79E4157651FF5B23B41FD0 ] C:\Windows\System32\UIAnimation.dll
    23:46:01.0374 4888 C:\Windows\System32\UIAnimation.dll - ok
    23:46:01.0376 4888 [ 77DA2B3F012A1F0D88F29C612F606F28 ] C:\Windows\System32\winbio.dll
    23:46:01.0376 4888 C:\Windows\System32\winbio.dll - ok
    23:46:01.0378 4888 [ 1D03DD2BA438D4B3E1A0289738619056 ] C:\Windows\System32\wlidcredprov.dll
    23:46:01.0378 4888 C:\Windows\System32\wlidcredprov.dll - ok
    23:46:01.0380 4888 [ CEEFD29FC551F289810B0B9381B321DC ] C:\Windows\System32\Drivers\lltdio.sys
    23:46:01.0380 4888 C:\Windows\System32\Drivers\lltdio.sys - ok
    23:46:01.0381 4888 [ 43D7388A90A4C6EA346A4D6FF0377479 ] C:\Windows\System32\Drivers\nwifi.sys
    23:46:01.0381 4888 C:\Windows\System32\Drivers\nwifi.sys - ok
    23:46:01.0383 4888 [ 6E578460E165F14D9BA473ED54E3299B ] C:\Windows\System32\rasapi32.dll
    23:46:01.0383 4888 C:\Windows\System32\rasapi32.dll - ok
    23:46:01.0384 4888 [ EC7C1F9882A5E2F4C5391DDC43582110 ] C:\Windows\System32\rasplap.dll
    23:46:01.0384 4888 C:\Windows\System32\rasplap.dll - ok
    23:46:01.0386 4888 [ 4E251FE2729D6A3FCCC87DC13F823DC2 ] C:\Windows\System32\rtutils.dll
    23:46:01.0386 4888 C:\Windows\System32\rtutils.dll - ok
    23:46:01.0388 4888 [ 79AB68BB3FFF974AD4F41FA559F4EC67 ] C:\Windows\System32\Drivers\ndisuio.sys
    23:46:01.0388 4888 C:\Windows\System32\Drivers\ndisuio.sys - ok
    23:46:01.0390 4888 [ E04E770DD198B9399640717145E79EBF ] C:\Windows\System32\Drivers\rspndr.sys
    23:46:01.0390 4888 C:\Windows\System32\Drivers\rspndr.sys - ok
    23:46:01.0392 4888 [ 04A9D55BDCD79EBB2F32D91FE5946C28 ] C:\Windows\System32\IPHLPAPI.DLL
    23:46:01.0392 4888 C:\Windows\System32\IPHLPAPI.DLL - ok
    23:46:01.0394 4888 [ 5A2F7F1CBC2E631A497DAD16164E06D2 ] C:\Windows\System32\lmhsvc.dll
    23:46:01.0394 4888 C:\Windows\System32\lmhsvc.dll - ok
    23:46:01.0396 4888 [ F28C7A1A04C73FD099CBA2441B07842D ] C:\Windows\System32\nrpsrv.dll
    23:46:01.0396 4888 C:\Windows\System32\nrpsrv.dll - ok
    23:46:01.0397 4888 [ 832B5FDF0B5577713FD7F2465FCD0ACE ] C:\Windows\System32\nsisvc.dll
    23:46:01.0398 4888 C:\Windows\System32\nsisvc.dll - ok
    23:46:01.0399 4888 [ 8C988C29CFB9B3673E882B4DA5EEC81D ] C:\Windows\System32\rasman.dll
    23:46:01.0399 4888 C:\Windows\System32\rasman.dll - ok
    23:46:01.0401 4888 [ D9C1E82651BF19C6FF69CEC6FD400124 ] C:\Windows\System32\wcmsvc.dll
    23:46:01.0401 4888 C:\Windows\System32\wcmsvc.dll - ok
    23:46:01.0403 4888 [ 0911A3B2DE545EA2498E560D745B7E71 ] C:\Windows\System32\winnsi.dll
    23:46:01.0403 4888 C:\Windows\System32\winnsi.dll - ok
    23:46:01.0405 4888 [ 9E0E72222264745ADEB0E5AC680B0ED6 ] C:\Windows\System32\dhcpcore.dll
    23:46:01.0405 4888 C:\Windows\System32\dhcpcore.dll - ok
    23:46:01.0407 4888 [ ACB80C69E775A1EA1D0500CE8C72FD69 ] C:\Windows\System32\dhcpcore6.dll
     
  10. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    23:46:01.0407 4888 C:\Windows\System32\dhcpcore6.dll - ok
    23:46:01.0409 4888 [ 066B9710B36AB550E01EEFCA52155968 ] C:\Windows\System32\dnsrslvr.dll
    23:46:01.0409 4888 C:\Windows\System32\dnsrslvr.dll - ok
    23:46:01.0411 4888 [ 536198D1FACCF6C6F5A4D71E7EA70039 ] C:\Windows\System32\FWPUCLNT.DLL
    23:46:01.0411 4888 C:\Windows\System32\FWPUCLNT.DLL - ok
    23:46:01.0412 4888 [ 028A5E6B0ABDD7B2D32745C5F1D8F711 ] C:\Windows\System32\wcmcsp.dll
    23:46:01.0412 4888 C:\Windows\System32\wcmcsp.dll - ok
    23:46:01.0414 4888 [ 6351724B8FA0255C2DBD970297F00B93 ] C:\Windows\System32\wlansvc.dll
    23:46:01.0414 4888 C:\Windows\System32\wlansvc.dll - ok
    23:46:01.0417 4888 [ FA705724D337C7555FE22C0D4E93F790 ] C:\Windows\System32\atidxx64.dll
    23:46:01.0417 4888 C:\Windows\System32\atidxx64.dll - ok
    23:46:01.0419 4888 [ 297A16EB62460FF10506539AAC515527 ] C:\Windows\System32\atiuxp64.dll
    23:46:01.0419 4888 C:\Windows\System32\atiuxp64.dll - ok
    23:46:01.0421 4888 [ EB87F1EFE1376CE0283635563026F9E0 ] C:\Windows\System32\dhcpcsvc6.dll
    23:46:01.0421 4888 C:\Windows\System32\dhcpcsvc6.dll - ok
    23:46:01.0423 4888 [ 137BBCFB2080C5F6F4E5C4EB6314D97A ] C:\Windows\System32\dnsext.dll
    23:46:01.0423 4888 C:\Windows\System32\dnsext.dll - ok
    23:46:01.0425 4888 [ 72EC1DEF102304EE8C2E47566328F035 ] C:\Windows\System32\onex.dll
    23:46:01.0425 4888 C:\Windows\System32\onex.dll - ok
    23:46:01.0427 4888 [ 5DCBA1A3AE7150D2B71347BDD08639ED ] C:\Windows\System32\version.dll
    23:46:01.0427 4888 C:\Windows\System32\version.dll - ok
    23:46:01.0430 4888 [ 21E796CF2D1B8A6FAA2347B0070316CE ] C:\Windows\System32\winbrand.dll
    23:46:01.0430 4888 C:\Windows\System32\winbrand.dll - ok
    23:46:01.0432 4888 [ 7D6BDD2A339080EFA03D9EB39398F4E6 ] C:\Windows\System32\wlanmsm.dll
    23:46:01.0432 4888 C:\Windows\System32\wlanmsm.dll - ok
    23:46:01.0434 4888 [ 8341C75945D37A0CA7642A47B7E79260 ] C:\Windows\System32\dhcpcsvc.dll
    23:46:01.0434 4888 C:\Windows\System32\dhcpcsvc.dll - ok
    23:46:01.0435 4888 [ F2CDA4A446FD4BA2D8BAF456219C6964 ] C:\Windows\System32\UIAutomationCore.dll
    23:46:01.0435 4888 C:\Windows\System32\UIAutomationCore.dll - ok
    23:46:01.0437 4888 [ 14D785DFBE808D9CF7B8C06884730B1D ] C:\Windows\System32\wlansec.dll
    23:46:01.0437 4888 C:\Windows\System32\wlansec.dll - ok
    23:46:01.0439 4888 [ 6684C72C745F0E5E385EEAFF3C15538F ] C:\Windows\System32\eappprxy.dll
    23:46:01.0439 4888 C:\Windows\System32\eappprxy.dll - ok
    23:46:01.0441 4888 [ 36E419B92BFBF76438B8C0C4DD28B9E6 ] C:\Windows\System32\msxml6.dll
    23:46:01.0441 4888 C:\Windows\System32\msxml6.dll - ok
    23:46:01.0443 4888 [ D142894EBEFD276A5CFE876884A6E3F9 ] C:\Windows\System32\uDWM.dll
    23:46:01.0443 4888 C:\Windows\System32\uDWM.dll - ok
    23:46:01.0444 4888 [ A22411CA36466FC676D6805B3196726E ] C:\Windows\System32\samlib.dll
    23:46:01.0444 4888 C:\Windows\System32\samlib.dll - ok
    23:46:01.0446 4888 [ 103E609A08474C43C04FB064440FCAE7 ] C:\Windows\System32\shacct.dll
    23:46:01.0446 4888 C:\Windows\System32\shacct.dll - ok
    23:46:01.0448 4888 [ 2C71C009DFAC4C6EE7795C6C042090B4 ] C:\Windows\System32\slc.dll
    23:46:01.0448 4888 C:\Windows\System32\slc.dll - ok
    23:46:01.0450 4888 [ BA47A3E78521EC9EA4341F6FA8A75EC9 ] C:\Windows\System32\propsys.dll
    23:46:01.0450 4888 C:\Windows\System32\propsys.dll - ok
    23:46:01.0452 4888 [ 9C09F1D54C7F391B1C3D7440AF30720A ] C:\Windows\System32\InputSwitch.dll
    23:46:01.0452 4888 C:\Windows\System32\InputSwitch.dll - ok
    23:46:01.0454 4888 [ 193F8B5C8E94D2F4512868135CDB3B1A ] C:\Windows\System32\l2gpstore.dll
    23:46:01.0454 4888 C:\Windows\System32\l2gpstore.dll - ok
    23:46:01.0458 4888 [ A77F3ABE13FCC698511E5DEC7ACEBD5F ] C:\Windows\System32\shsvcs.dll
    23:46:01.0458 4888 C:\Windows\System32\shsvcs.dll - ok
    23:46:01.0460 4888 [ 53B518707ECB8132E173ADAF42D68054 ] C:\Windows\System32\Windows.UI.Immersive.dll
    23:46:01.0460 4888 C:\Windows\System32\Windows.UI.Immersive.dll - ok
    23:46:01.0462 4888 [ 047DB56D72FDC16114606B1A6576904B ] C:\Windows\System32\wlanapi.dll
    23:46:01.0462 4888 C:\Windows\System32\wlanapi.dll - ok
    23:46:01.0464 4888 [ D9AEEA13463C68BC9506342A7D15CBDA ] C:\Windows\System32\wlgpclnt.dll
    23:46:01.0464 4888 C:\Windows\System32\wlgpclnt.dll - ok
    23:46:01.0466 4888 [ DC774C3671FBD6FD176864AF0EBA404E ] C:\Windows\System32\d2d1.dll
    23:46:01.0466 4888 C:\Windows\System32\d2d1.dll - ok
    23:46:01.0467 4888 [ 04E866855FC3282BFEC25E8B6703FFEE ] C:\Windows\System32\netcfgx.dll
    23:46:01.0467 4888 C:\Windows\System32\netcfgx.dll - ok
    23:46:01.0469 4888 [ EDCDF4DB82EF825B94B190D544C8C58B ] C:\Windows\System32\schedsvc.dll
    23:46:01.0469 4888 C:\Windows\System32\schedsvc.dll - ok
    23:46:01.0471 4888 [ 59FB8ADC92BF41345BD0034F02187C0E ] C:\Windows\System32\wlanhlp.dll
    23:46:01.0471 4888 C:\Windows\System32\wlanhlp.dll - ok
    23:46:01.0473 4888 [ F9D935D60C397809FC6E1E0676F4AC6E ] C:\Windows\System32\wuaext.dll
    23:46:01.0473 4888 C:\Windows\System32\wuaext.dll - ok
    23:46:01.0474 4888 [ 3E5177CAE5C4325C49345B4D48626856 ] C:\Windows\System32\SubscriptionMgr.dll
    23:46:01.0474 4888 C:\Windows\System32\SubscriptionMgr.dll - ok
    23:46:01.0476 4888 [ F0E5C2AACB8DFD8EF2F7A67A12CCDA5D ] C:\Windows\System32\IDStore.dll
    23:46:01.0476 4888 C:\Windows\System32\IDStore.dll - ok
    23:46:01.0478 4888 [ 81ECD8768D3E4AD61DB7EE27401A25E9 ] C:\Windows\System32\wevtapi.dll
    23:46:01.0478 4888 C:\Windows\System32\wevtapi.dll - ok
    23:46:01.0480 4888 [ D058F369A791DD5B4DF8E7C18C0EB282 ] C:\Windows\System32\ktmw32.dll
    23:46:01.0480 4888 C:\Windows\System32\ktmw32.dll - ok
    23:46:01.0481 4888 [ 467497DF10CF8D4014BD25CCE987EA84 ] C:\Windows\System32\wcmapi.dll
    23:46:01.0481 4888 C:\Windows\System32\wcmapi.dll - ok
    23:46:01.0483 4888 [ 554F73A015A84FA8B5F23635FE016314 ] C:\Windows\System32\wlidres.dll
    23:46:01.0483 4888 C:\Windows\System32\wlidres.dll - ok
    23:46:01.0485 4888 [ 15E300200794A8FC38589B44A0B314D6 ] C:\Windows\System32\xmllite.dll
    23:46:01.0485 4888 C:\Windows\System32\xmllite.dll - ok
    23:46:01.0487 4888 [ 2640C2240F9B6529AE779D83E8FF2127 ] C:\Windows\System32\apphelp.dll
    23:46:01.0487 4888 C:\Windows\System32\apphelp.dll - ok
    23:46:01.0489 4888 [ F38DD05686AC8597BCD38C2F324900B9 ] C:\Windows\System32\AuthExt.dll
    23:46:01.0489 4888 C:\Windows\System32\AuthExt.dll - ok
    23:46:01.0491 4888 [ BC484B89C153942BF5D8BFBE832274E1 ] C:\Windows\System32\batmeter.dll
    23:46:01.0491 4888 C:\Windows\System32\batmeter.dll - ok
    23:46:01.0492 4888 [ EB4EE894AF86408776C6FD03376DEA29 ] C:\Windows\System32\fveapi.dll
    23:46:01.0492 4888 C:\Windows\System32\fveapi.dll - ok
    23:46:01.0494 4888 [ 8FF250BD9B3AC4D9D3F325570F901F36 ] C:\Windows\System32\fvecerts.dll
    23:46:01.0494 4888 C:\Windows\System32\fvecerts.dll - ok
    23:46:01.0496 4888 [ AA221DD533C7B0897B90B92AFFA45A7E ] C:\Windows\System32\taskcomp.dll
    23:46:01.0496 4888 C:\Windows\System32\taskcomp.dll - ok
    23:46:01.0498 4888 [ 29CB98187BB5711F7759540976D295FC ] C:\Windows\System32\Drivers\http.sys
    23:46:01.0498 4888 C:\Windows\System32\Drivers\http.sys - ok
    23:46:01.0499 4888 [ 406388E840C631E3C338F4E3551F791C ] C:\Windows\System32\ProximityCommon.dll
    23:46:01.0499 4888 C:\Windows\System32\ProximityCommon.dll - ok
    23:46:01.0501 4888 [ 599FCE13B819BA7D2D4D4E9C5AD08002 ] C:\Windows\System32\ProximityService.dll
    23:46:01.0501 4888 C:\Windows\System32\ProximityService.dll - ok
    23:46:01.0503 4888 [ 3F215BF2D4D8D6756298B25B579772C2 ] C:\Windows\System32\spoolsv.exe
    23:46:01.0503 4888 C:\Windows\System32\spoolsv.exe - ok
    23:46:01.0505 4888 [ 4A627D948C498368B2F65A5312455520 ] C:\Windows\System32\taskhost.exe
    23:46:01.0505 4888 C:\Windows\System32\taskhost.exe - ok
    23:46:01.0507 4888 [ 9E6A544F465C582AB42444A217CF04DC ] C:\Windows\System32\BFE.DLL
    23:46:01.0507 4888 C:\Windows\System32\BFE.DLL - ok
    23:46:01.0509 4888 [ B17AC10B47C7FCB44D22A1F06415840E ] C:\Windows\System32\Drivers\bowser.sys
    23:46:01.0509 4888 C:\Windows\System32\Drivers\bowser.sys - ok
    23:46:01.0511 4888 [ 0D1609DD82C7440F5D5BF21A9D4D5C0C ] C:\Windows\System32\Drivers\mpsdrv.sys
    23:46:01.0511 4888 C:\Windows\System32\Drivers\mpsdrv.sys - ok
    23:46:01.0513 4888 [ 877D60D6E4156EC4A2E0B6871D41BED9 ] C:\Windows\System32\Drivers\mrxsmb.sys
    23:46:01.0513 4888 C:\Windows\System32\Drivers\mrxsmb.sys - ok
    23:46:01.0515 4888 [ 3031573A739DBEE8923851929D0AF423 ] C:\Windows\System32\MPSSVC.dll
    23:46:01.0515 4888 C:\Windows\System32\MPSSVC.dll - ok
    23:46:01.0516 4888 [ 06D5F2FA3C61E8EA91648EA8E9F99FD3 ] C:\Windows\System32\Drivers\mrxsmb10.sys
    23:46:01.0516 4888 C:\Windows\System32\Drivers\mrxsmb10.sys - ok
    23:46:01.0518 4888 [ E078446D4B8622AA6030C7B8A1A08962 ] C:\Windows\System32\Drivers\mrxsmb20.sys
    23:46:01.0518 4888 C:\Windows\System32\Drivers\mrxsmb20.sys - ok
    23:46:01.0520 4888 [ 581D88B25C4D4121824FED2CA38E562F ] C:\Program Files\SUPERAntiSpyware\SASCore64.exe
    23:46:01.0520 4888 C:\Program Files\SUPERAntiSpyware\SASCore64.exe - ok
    23:46:01.0522 4888 [ D8F969B29E087A860156E4FFDB04138D ] C:\Windows\System32\adhapi.dll
    23:46:01.0522 4888 C:\Windows\System32\adhapi.dll - ok
    23:46:01.0524 4888 [ FF468871BC365B52AE650D422FEA21F5 ] C:\Windows\System32\wfapigp.dll
    23:46:01.0524 4888 C:\Windows\System32\wfapigp.dll - ok
    23:46:01.0526 4888 [ 16650912BE5A94B40E0B3B4C39652B56 ] C:\Windows\System32\wkssvc.dll
    23:46:01.0526 4888 C:\Windows\System32\wkssvc.dll - ok
    23:46:01.0528 4888 [ 4AFC14AFA58878FAA1D249E7E90EA54B ] C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    23:46:01.0528 4888 C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe - ok
    23:46:01.0530 4888 [ AB74105622BBE9EE069AC56666DBC696 ] C:\Windows\System32\Windows.Globalization.dll
    23:46:01.0530 4888 C:\Windows\System32\Windows.Globalization.dll - ok
    23:46:01.0532 4888 [ 0F38E5BAB0E4CEBB57987967F5505CD7 ] C:\Windows\SysWOW64\ntdll.dll
    23:46:01.0532 4888 C:\Windows\SysWOW64\ntdll.dll - ok
    23:46:01.0533 4888 [ ABE4B349D12138772B0D3B1B55C5F2A8 ] C:\Windows\System32\MrmCoreR.dll
    23:46:01.0533 4888 C:\Windows\System32\MrmCoreR.dll - ok
    23:46:01.0535 4888 [ 185C71A41C02724A56BA625578651817 ] C:\Windows\System32\NetworkStatus.dll
    23:46:01.0535 4888 C:\Windows\System32\NetworkStatus.dll - ok
    23:46:01.0537 4888 [ 1C5F50F98291B7545391BB57C406E615 ] C:\Windows\SysWOW64\kernel32.dll
    23:46:01.0537 4888 C:\Windows\SysWOW64\kernel32.dll - ok
    23:46:01.0539 4888 [ 5A3BF11D81C7F7EE8EDE9A2430B70878 ] C:\Windows\SysWOW64\KernelBase.dll
    23:46:01.0539 4888 C:\Windows\SysWOW64\KernelBase.dll - ok
    23:46:01.0541 4888 [ 42836D10270B1940F9A2FF77AE679537 ] C:\Program Files (x86)\AVG\AVG2013\avgntopensslx.dll
    23:46:01.0541 4888 C:\Program Files (x86)\AVG\AVG2013\avgntopensslx.dll - ok
    23:46:01.0543 4888 [ 5C32C180AB29655EFDFF6B7F91271775 ] C:\Windows\System32\msftedit.dll
    23:46:01.0543 4888 C:\Windows\System32\msftedit.dll - ok
    23:46:01.0545 4888 [ 484987420BC8DED2CB26C6F4EC9BA7F2 ] C:\Program Files (x86)\AVG\AVG2013\avgsysx.dll
    23:46:01.0545 4888 C:\Program Files (x86)\AVG\AVG2013\avgsysx.dll - ok
    23:46:01.0546 4888 [ BC83108B18756547013ED443B8CDB31B ] C:\Windows\SysWOW64\msvcp100.dll
    23:46:01.0546 4888 C:\Windows\SysWOW64\msvcp100.dll - ok
    23:46:01.0548 4888 [ 0E37FBFA79D349D672456923EC5FBBE3 ] C:\Windows\SysWOW64\msvcr100.dll
    23:46:01.0548 4888 C:\Windows\SysWOW64\msvcr100.dll - ok
    23:46:01.0550 4888 [ 47AC075FC4DE7DCF690E861B9B2C22A9 ] C:\Windows\System32\ninput.dll
    23:46:01.0550 4888 C:\Windows\System32\ninput.dll - ok
    23:46:01.0552 4888 [ BFEF608CD713A4CD3165D72E2AEB23F2 ] C:\Windows\SysWOW64\advapi32.dll
    23:46:01.0552 4888 C:\Windows\SysWOW64\advapi32.dll - ok
    23:46:01.0554 4888 [ BD483C1AE32D5B21A22CABE74A9D4798 ] C:\Windows\SysWOW64\IPHLPAPI.DLL
    23:46:01.0554 4888 C:\Windows\SysWOW64\IPHLPAPI.DLL - ok
    23:46:01.0556 4888 [ 3588D5D12FF7BFEBF2A4955C36B38EB0 ] C:\Windows\SysWOW64\psapi.dll
    23:46:01.0556 4888 C:\Windows\SysWOW64\psapi.dll - ok
    23:46:01.0558 4888 [ BA1C3ACD929A71E88B49C2B6E38F92B3 ] C:\Windows\SysWOW64\user32.dll
    23:46:01.0558 4888 C:\Windows\SysWOW64\user32.dll - ok
    23:46:01.0559 4888 [ 682C3D4982B5375732A4273809365A0A ] C:\Windows\SysWOW64\version.dll
    23:46:01.0559 4888 C:\Windows\SysWOW64\version.dll - ok
    23:46:01.0561 4888 [ 314E662DD78AF3F7766BA25162BEEEDA ] C:\Windows\SysWOW64\wininet.dll
    23:46:01.0561 4888 C:\Windows\SysWOW64\wininet.dll - ok
    23:46:01.0563 4888 [ B3CC9EDFD97F7087013A9A47089DF571 ] C:\Windows\SysWOW64\ws2_32.dll
    23:46:01.0563 4888 C:\Windows\SysWOW64\ws2_32.dll - ok
    23:46:01.0565 4888 [ F036DB9CF05B3C21405403FF074A78D9 ] C:\Program Files (x86)\AVG\AVG2013\avgopensslx.dll
    23:46:01.0565 4888 C:\Program Files (x86)\AVG\AVG2013\avgopensslx.dll - ok
    23:46:01.0567 4888 [ B59E9810F8A416B9E5354834F26969D4 ] C:\Windows\SysWOW64\msvcrt.dll
    23:46:01.0567 4888 C:\Windows\SysWOW64\msvcrt.dll - ok
    23:46:01.0568 4888 [ 1AFB56F8A39455ACBAB16A29A45C30AC ] C:\Windows\SysWOW64\nsi.dll
    23:46:01.0568 4888 C:\Windows\SysWOW64\nsi.dll - ok
    23:46:01.0570 4888 [ 77ADCD16CCEB8A9AD1FD81FC464B1A6B ] C:\Windows\SysWOW64\winnsi.dll
    23:46:01.0570 4888 C:\Windows\SysWOW64\winnsi.dll - ok
    23:46:01.0572 4888 [ 05DE4C1D408A5A2E599E2DA0F6B909ED ] C:\Windows\SysWOW64\gdi32.dll
    23:46:01.0572 4888 C:\Windows\SysWOW64\gdi32.dll - ok
    23:46:01.0574 4888 [ E64021308A378207B317A97950B47413 ] C:\Windows\SysWOW64\rpcrt4.dll
    23:46:01.0574 4888 C:\Windows\SysWOW64\rpcrt4.dll - ok
    23:46:01.0575 4888 [ 496E036F16467D7B7D12E0794E9FB85D ] C:\Windows\SysWOW64\sechost.dll
    23:46:01.0575 4888 C:\Windows\SysWOW64\sechost.dll - ok
    23:46:01.0577 4888 [ A202E73D2906E7093BC00444DF4D7784 ] C:\Windows\SysWOW64\iertutil.dll
    23:46:01.0577 4888 C:\Windows\SysWOW64\iertutil.dll - ok
    23:46:01.0579 4888 [ 7DFC3FCD0D5B7FC2F60C344BB384607C ] C:\Windows\SysWOW64\bcryptprimitives.dll
    23:46:01.0579 4888 C:\Windows\SysWOW64\bcryptprimitives.dll - ok
    23:46:01.0580 4888 [ 0D3C6E1A7EBD401F46E00EDBD61D1A72 ] C:\Windows\SysWOW64\cryptbase.dll
    23:46:01.0580 4888 C:\Windows\SysWOW64\cryptbase.dll - ok
    23:46:01.0582 4888 [ 39B721A0FB5F3E9880EE247F04012D8C ] C:\Windows\SysWOW64\sspicli.dll
    23:46:01.0582 4888 C:\Windows\SysWOW64\sspicli.dll - ok
    23:46:01.0584 4888 [ 1C2E1FC9F8ED794CC191E92F27D1391C ] C:\Program Files (x86)\AVG\AVG2013\avglogx.dll
    23:46:01.0584 4888 C:\Program Files (x86)\AVG\AVG2013\avglogx.dll - ok
    23:46:01.0586 4888 [ B40F5DCD59ED2A46EED8AE340CC167FB ] C:\Program Files (x86)\AVG\AVG2013\avgcfgx.dll
    23:46:01.0586 4888 C:\Program Files (x86)\AVG\AVG2013\avgcfgx.dll - ok
    23:46:01.0588 4888 [ A6251155B7017D4B4A77A3531A8DA6D8 ] C:\Program Files (x86)\AVG\AVG2013\avgcommx.dll
    23:46:01.0588 4888 C:\Program Files (x86)\AVG\AVG2013\avgcommx.dll - ok
    23:46:01.0590 4888 [ 6B72E1E329C4E98C6B6FDD2D265E3BA3 ] C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    23:46:01.0590 4888 C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe - ok
    23:46:01.0592 4888 [ F0E78B119D12BA81F163D48C0FF30B9A ] C:\Windows\System32\cryptsvc.dll
    23:46:01.0592 4888 C:\Windows\System32\cryptsvc.dll - ok
    23:46:01.0594 4888 [ 5EAEF67AE2AF4D2DC664B649DB7B2E16 ] C:\Windows\System32\das.dll
    23:46:01.0594 4888 C:\Windows\System32\das.dll - ok
    23:46:01.0595 4888 [ 109FC3F80BF4F4DC5A071058074F13C1 ] C:\Windows\System32\dps.dll
    23:46:01.0595 4888 C:\Windows\System32\dps.dll - ok
    23:46:01.0597 4888 [ 7646E9DA362163D9C0F402F812EB1A0E ] C:\Windows\SysWOW64\shell32.dll
    23:46:01.0597 4888 C:\Windows\SysWOW64\shell32.dll - ok
    23:46:01.0599 4888 [ 3C5846581F329FD6768E5E7C1780151E ] C:\Windows\System32\cryptcatsvc.dll
    23:46:01.0599 4888 C:\Windows\System32\cryptcatsvc.dll - ok
    23:46:01.0600 4888 [ 57616A5583E6406F88BC71A5A5E0C165 ] C:\Program Files (x86)\AVG\AVG2013\avgwd.dll
    23:46:01.0600 4888 C:\Program Files (x86)\AVG\AVG2013\avgwd.dll - ok
    23:46:01.0602 4888 [ B278B76FF26BE911DD369724612F2D03 ] C:\Windows\System32\dasHost.exe
    23:46:01.0603 4888 C:\Windows\System32\dasHost.exe - ok
    23:46:01.0605 4888 [ 9C2CB23B77E539D87B4652FA68A6C275 ] C:\Windows\System32\vssapi.dll
    23:46:01.0605 4888 C:\Windows\System32\vssapi.dll - ok
    23:46:01.0608 4888 [ 1ACAA67676E9E7BDA5E0C41B6E0DECAF ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    23:46:01.0608 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe - ok
    23:46:01.0610 4888 [ 5579A2CE7756B59F4BB778AFDCAF2096 ] C:\Windows\System32\vsstrace.dll
    23:46:01.0610 4888 C:\Windows\System32\vsstrace.dll - ok
    23:46:01.0611 4888 [ 8624E0E2418413614EE1FECDB7B76B88 ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll
    23:46:01.0611 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.dll - ok
    23:46:01.0613 4888 [ 6ADA7F192919DD51930A73F364129433 ] C:\Windows\SysWOW64\ole32.dll
    23:46:01.0613 4888 C:\Windows\SysWOW64\ole32.dll - ok
    23:46:01.0615 4888 [ EA35B404D87B3A61E7A5FBF6CDA1CF94 ] C:\Windows\SysWOW64\oleaut32.dll
    23:46:01.0615 4888 C:\Windows\SysWOW64\oleaut32.dll - ok
    23:46:01.0618 4888 [ D4467A285C91752018F67CDBA8680BAB ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll
    23:46:01.0618 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamnet.dll - ok
    23:46:01.0620 4888 [ 828CFD406E60311A9E5414685FA7EEDF ] C:\Windows\SysWOW64\combase.dll
    23:46:01.0620 4888 C:\Windows\SysWOW64\combase.dll - ok
    23:46:01.0621 4888 [ B8ECF8A56EEF75468F9ABFECE70AF555 ] C:\Windows\SysWOW64\shlwapi.dll
    23:46:01.0622 4888 C:\Windows\SysWOW64\shlwapi.dll - ok
    23:46:01.0624 4888 [ 76FFA2433FEB42E78FB5421A50C8FBE3 ] C:\Program Files (x86)\AVG\AVG2013\avgclitx.dll
    23:46:01.0624 4888 C:\Program Files (x86)\AVG\AVG2013\avgclitx.dll - ok
    23:46:01.0626 4888 [ C7874A3B4C4FD56CB80FA4F2A02232FD ] C:\Program Files (x86)\AVG\AVG2013\avgcorex.dll
    23:46:01.0626 4888 C:\Program Files (x86)\AVG\AVG2013\avgcorex.dll - ok
    23:46:01.0628 4888 [ 7BB3FE507D7143CD54293DA3FB5DF3AB ] C:\Windows\SysWOW64\crypt32.dll
    23:46:01.0628 4888 C:\Windows\SysWOW64\crypt32.dll - ok
    23:46:01.0630 4888 [ 58EE457D0D49A95A1E981F6F67FB560F ] C:\Windows\SysWOW64\userenv.dll
    23:46:01.0630 4888 C:\Windows\SysWOW64\userenv.dll - ok
    23:46:01.0632 4888 [ 715A1F4D2A064DA1DDCAC2533FAF780F ] C:\Windows\SysWOW64\wtsapi32.dll
    23:46:01.0632 4888 C:\Windows\SysWOW64\wtsapi32.dll - ok
    23:46:01.0633 4888 [ 9E30B21B14FB24C383AC255BDFA47E0E ] C:\Program Files (x86)\AVG\AVG2013\avgsecapix.dll
    23:46:01.0634 4888 C:\Program Files (x86)\AVG\AVG2013\avgsecapix.dll - ok
    23:46:01.0635 4888 [ AFAACBE85092FBD8EE7F54CA7FF3F0F1 ] C:\Windows\SysWOW64\msasn1.dll
    23:46:01.0635 4888 C:\Windows\SysWOW64\msasn1.dll - ok
    23:46:01.0636 4888 [ 7D2306701584AE7B77B8622314B55F78 ] C:\Windows\SysWOW64\profapi.dll
    23:46:01.0636 4888 C:\Windows\SysWOW64\profapi.dll - ok
    23:46:01.0638 4888 [ 7D20883F79FF846AEE49678238BE8A7A ] C:\Windows\SysWOW64\cryptsp.dll
    23:46:01.0638 4888 C:\Windows\SysWOW64\cryptsp.dll - ok
    23:46:01.0640 4888 [ 85F7AFD9C7DFD6824BAFDC5E5D7D4E86 ] C:\Windows\SysWOW64\SHCore.dll
    23:46:01.0640 4888 C:\Windows\SysWOW64\SHCore.dll - ok
    23:46:01.0642 4888 [ 916B8954AC3E06DC9E898AFFB41F3FB6 ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    23:46:01.0642 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe - ok
    23:46:01.0644 4888 [ 95EFDCB44DD093EDAD447F1D21C8A3F7 ] C:\Program Files (x86)\AVG\AVG2013\avgcertx.dll
    23:46:01.0644 4888 C:\Program Files (x86)\AVG\AVG2013\avgcertx.dll - ok
    23:46:01.0646 4888 [ 6F19639188F792BBB234B2A3FCB0C8C9 ] C:\Program Files (x86)\AVG\AVG2013\avgchclx.dll
    23:46:01.0646 4888 C:\Program Files (x86)\AVG\AVG2013\avgchclx.dll - ok
    23:46:01.0648 4888 [ 46211947C1F1953B74C33FC80ECD3C6A ] C:\Windows\SysWOW64\rsaenh.dll
    23:46:01.0648 4888 C:\Windows\SysWOW64\rsaenh.dll - ok
    23:46:01.0649 4888 [ C28F010F8C6AB4341749E2DEDEAC5D06 ] C:\Windows\SysWOW64\wintrust.dll
    23:46:01.0649 4888 C:\Windows\SysWOW64\wintrust.dll - ok
    23:46:01.0651 4888 [ F820B93E4ABCCABD698A175FD5FC83FE ] C:\Program Files (x86)\AVG\AVG2013\avgntsqlitex.dll
    23:46:01.0651 4888 C:\Program Files (x86)\AVG\AVG2013\avgntsqlitex.dll - ok
    23:46:01.0653 4888 [ 491918E4C46ED4CEB6E7A90F7B73924D ] C:\Program Files (x86)\AVG\AVG2013\avgxpl.dll
    23:46:01.0653 4888 C:\Program Files (x86)\AVG\AVG2013\avgxpl.dll - ok
    23:46:01.0655 4888 [ DDF8C39C085D2E98BD030B3E8A1F40B8 ] C:\Windows\SysWOW64\secur32.dll
    23:46:01.0655 4888 C:\Windows\SysWOW64\secur32.dll - ok
    23:46:01.0657 4888 [ 5DDEA740B911D4E910AC031090183E6A ] C:\Windows\SysWOW64\sfc.dll
    23:46:01.0657 4888 C:\Windows\SysWOW64\sfc.dll - ok
    23:46:01.0658 4888 [ 0313A5DFA5966E31220C26A6167FD479 ] C:\Windows\SysWOW64\sfc_os.dll
    23:46:01.0658 4888 C:\Windows\SysWOW64\sfc_os.dll - ok
    23:46:01.0660 4888 [ ECC6D7B772AC59E2717B4A70A742EC5D ] C:\Windows\SysWOW64\wevtapi.dll
    23:46:01.0660 4888 C:\Windows\SysWOW64\wevtapi.dll - ok
    23:46:01.0662 4888 [ 4BE1DCAD76BE96D1EC887A41E570C404 ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.dll
    23:46:01.0662 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamcore.dll - ok
    23:46:01.0664 4888 [ 567612D556BBC4FC98169EA98F6EA480 ] C:\Windows\SysWOW64\cfgmgr32.dll
    23:46:01.0664 4888 C:\Windows\SysWOW64\cfgmgr32.dll - ok
    23:46:01.0666 4888 [ 785838B984563D12D4612256D2C78B48 ] C:\Windows\SysWOW64\mpr.dll
    23:46:01.0666 4888 C:\Windows\SysWOW64\mpr.dll - ok
    23:46:01.0668 4888 [ F67480EE1AC3CB32C63AF86B0AE57AC9 ] C:\Program Files (x86)\AVG\AVG2013\avgwdwsc.dll
    23:46:01.0668 4888 C:\Program Files (x86)\AVG\AVG2013\avgwdwsc.dll - ok
    23:46:01.0670 4888 [ D3F60A4345FCA9C1BE68AD7D0D6DE770 ] C:\Windows\System32\Drivers\Ndu.sys
    23:46:01.0670 4888 C:\Windows\System32\Drivers\Ndu.sys - ok
    23:46:01.0672 4888 [ 70DBB6A8B52B3830922F1C5789E1BEEB ] C:\Windows\System32\Drivers\PEAuth.sys
    23:46:01.0672 4888 C:\Windows\System32\Drivers\PEAuth.sys - ok
    23:46:01.0674 4888 [ 80ABCD4C2DE9FD832477303AE0CA3BE5 ] C:\Windows\System32\nlasvc.dll
    23:46:01.0674 4888 C:\Windows\System32\nlasvc.dll - ok
    23:46:01.0676 4888 [ 4811D9EC53649105A5A8BEA661B0F936 ] C:\Windows\System32\pcasvc.dll
    23:46:01.0676 4888 C:\Windows\System32\pcasvc.dll - ok
    23:46:01.0678 4888 [ 1580A33C6CD8E0117247A48C31825D6E ] C:\Windows\System32\aepic.dll
    23:46:01.0678 4888 C:\Windows\System32\aepic.dll - ok
    23:46:01.0679 4888 [ D47794FC9B672034F4932B47016A4998 ] C:\Windows\System32\ncsi.dll
    23:46:01.0679 4888 C:\Windows\System32\ncsi.dll - ok
    23:46:01.0681 4888 [ BA0231EEEED894158F22FBE5CDCD32CB ] C:\Windows\SysWOW64\wscapi.dll
    23:46:01.0681 4888 C:\Windows\SysWOW64\wscapi.dll - ok
    23:46:01.0683 4888 [ 206387AB881E93A1A6EB89966C8651F1 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    23:46:01.0683 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe - ok
    23:46:01.0685 4888 [ C954FE5796A0BFCDCDD8A9C210E9D2C3 ] C:\Windows\System32\sfc_os.dll
    23:46:01.0685 4888 C:\Windows\System32\sfc_os.dll - ok
    23:46:01.0687 4888 [ 7911470B6018059A880469A63B65700A ] C:\Windows\System32\winhttp.dll
    23:46:01.0687 4888 C:\Windows\System32\winhttp.dll - ok
    23:46:01.0689 4888 [ 26F0D5C6F38FFDE13E46F028CE12AFA5 ] C:\Windows\SysWOW64\urlmon.dll
    23:46:01.0689 4888 C:\Windows\SysWOW64\urlmon.dll - ok
    23:46:01.0691 4888 [ 4C867B62F6100C107A3A8F5E7A10461D ] C:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl
    23:46:01.0691 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\rtl150.bpl - ok
    23:46:01.0692 4888 [ 5858AA1B5AF20C37B186971A21460A4E ] C:\Windows\System32\ssdpapi.dll
    23:46:01.0692 4888 C:\Windows\System32\ssdpapi.dll - ok
    23:46:01.0694 4888 [ 2FC6C98A23864B2E50E53B4848939EAF ] C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
    23:46:01.0694 4888 C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe - ok
    23:46:01.0696 4888 [ 62F46FB1AED31B289F6A64718A3E5ECF ] C:\Windows\SysWOW64\clbcatq.dll
    23:46:01.0696 4888 C:\Windows\SysWOW64\clbcatq.dll - ok
    23:46:01.0698 4888 [ 5192F9A06BC32684ADF938EE16E118D9 ] C:\Windows\SysWOW64\ntmarta.dll
    23:46:01.0698 4888 C:\Windows\SysWOW64\ntmarta.dll - ok
    23:46:01.0699 4888 [ FF0602E28D69B977F889D435F902545E ] C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
    23:46:01.0699 4888 C:\Program Files (x86)\AVG\AVG2013\avgemca.exe - ok
    23:46:01.0702 4888 [ D9AF104F7E21FA859EFA3C67E5522E88 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\vcl150.bpl
    23:46:01.0702 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\vcl150.bpl - ok
    23:46:01.0704 4888 [ 2BD1447ECF8A9697AFCF4D7C71D45AA7 ] C:\Windows\SysWOW64\wbem\wbemprox.dll
    23:46:01.0704 4888 C:\Windows\SysWOW64\wbem\wbemprox.dll - ok
    23:46:01.0706 4888 [ 83C4E13852335E1EAC12AA62A2F01E52 ] C:\Windows\SysWOW64\winsta.dll
    23:46:01.0706 4888 C:\Windows\SysWOW64\winsta.dll - ok
    23:46:01.0708 4888 [ 366FD6F3A451351B5DF2D7C4ECF4C73A ] C:\Windows\System32\msvcr100.dll
    23:46:01.0709 4888 C:\Windows\System32\msvcr100.dll - ok
    23:46:01.0710 4888 [ FA0672B09ED377939BB9F3D39895B404 ] C:\Windows\SysWOW64\wbemcomn.dll
    23:46:01.0710 4888 C:\Windows\SysWOW64\wbemcomn.dll - ok
    23:46:01.0712 4888 [ 105ED75F4CEE9E58152061520DAA4ABD ] C:\Program Files (x86)\Spybot - Search & Destroy 2\Jcl150.bpl
     
  11. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    23:46:01.0713 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\Jcl150.bpl - ok
    23:46:01.0715 4888 [ 8622AE563E2AC2F8BF9FAFEE726FC7B8 ] C:\Program Files (x86)\AVG\AVG2013\avgsched.dll
    23:46:01.0715 4888 C:\Program Files (x86)\AVG\AVG2013\avgsched.dll - ok
    23:46:01.0716 4888 [ 76ACCC871C2A021BBC9A8B292244D0EC ] C:\Program Files (x86)\AVG\AVG2013\avgcfga.dll
    23:46:01.0716 4888 C:\Program Files (x86)\AVG\AVG2013\avgcfga.dll - ok
    23:46:01.0718 4888 [ FF9AFBD2864BBEA6A9E7F90F8C94F6B7 ] C:\Program Files (x86)\AVG\AVG2013\avgidpsdkx.dll
    23:46:01.0718 4888 C:\Program Files (x86)\AVG\AVG2013\avgidpsdkx.dll - ok
    23:46:01.0721 4888 [ A9BEAEE40D353F85D213BB46F54EBBED ] C:\Program Files (x86)\AVG\AVG2013\avgkrnlapia.dll
    23:46:01.0721 4888 C:\Program Files (x86)\AVG\AVG2013\avgkrnlapia.dll - ok
    23:46:01.0723 4888 [ 0FDABB1FD68CBC557084E16B0EA2F731 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\snlBase150.bpl
    23:46:01.0723 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\snlBase150.bpl - ok
    23:46:01.0726 4888 [ 7320560F4A6FA26EC432D0E4AFE6112F ] C:\Windows\SysWOW64\SensApi.dll
    23:46:01.0726 4888 C:\Windows\SysWOW64\SensApi.dll - ok
    23:46:01.0728 4888 [ FA27F4DF4015B22F04B5D18044A24322 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    23:46:01.0728 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl - ok
    23:46:01.0730 4888 [ 86E99E1222E671408ED5E8618521AEEB ] C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
    23:46:01.0730 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl - ok
    23:46:01.0732 4888 [ 9244E0240A1D150581C3BAA89D8AA154 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    23:46:01.0732 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl - ok
    23:46:01.0734 4888 [ 8964E7F65751FEC4185285E3329EADE6 ] C:\Program Files (x86)\AVG\AVG2013\avgsecapia.dll
    23:46:01.0734 4888 C:\Program Files (x86)\AVG\AVG2013\avgsecapia.dll - ok
    23:46:01.0736 4888 [ 14361FB2FD630988816A4F46AEAF0684 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
    23:46:01.0736 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll - ok
    23:46:01.0738 4888 [ FF3AA70595B26BD3DC0DDB00B90B1B57 ] C:\Windows\SysWOW64\imagehlp.dll
    23:46:01.0738 4888 C:\Windows\SysWOW64\imagehlp.dll - ok
    23:46:01.0740 4888 [ 5C96F30D1144AB5D8F03DFF045B8C791 ] C:\Windows\SysWOW64\netapi32.dll
    23:46:01.0740 4888 C:\Windows\SysWOW64\netapi32.dll - ok
    23:46:01.0742 4888 [ 7A3B96DE45ED3AB1B6BAA1D0B7B9869B ] C:\Windows\SysWOW64\comctl32.dll
    23:46:01.0742 4888 C:\Windows\SysWOW64\comctl32.dll - ok
    23:46:01.0744 4888 [ 6FA9D09428E56C11E01066CAF2FB5031 ] C:\Windows\SysWOW64\msimg32.dll
    23:46:01.0744 4888 C:\Windows\SysWOW64\msimg32.dll - ok
    23:46:01.0745 4888 [ 41E843174754F87D86EF0FBF7F60DB0D ] C:\Windows\SysWOW64\oleacc.dll
    23:46:01.0745 4888 C:\Windows\SysWOW64\oleacc.dll - ok
    23:46:01.0747 4888 [ 42FF7DC63C1CB122CE2C8061B5FE4390 ] C:\Windows\SysWOW64\shfolder.dll
    23:46:01.0747 4888 C:\Windows\SysWOW64\shfolder.dll - ok
    23:46:01.0749 4888 [ A2B03204078BBB32CDD3AF779717FCC4 ] C:\Windows\SysWOW64\wsock32.dll
    23:46:01.0749 4888 C:\Windows\SysWOW64\wsock32.dll - ok
    23:46:01.0750 4888 [ C2C86942ED94D1CD81F61BEFB3036AF6 ] C:\Windows\SysWOW64\comdlg32.dll
    23:46:01.0750 4888 C:\Windows\SysWOW64\comdlg32.dll - ok
    23:46:01.0752 4888 [ F6104D2DBF254FE23928F978F6CABE35 ] C:\Windows\SysWOW64\oledlg.dll
    23:46:01.0752 4888 C:\Windows\SysWOW64\oledlg.dll - ok
    23:46:01.0754 4888 [ 8E902EE869004D40F350C02C4E63B0CA ] C:\Windows\SysWOW64\winmm.dll
    23:46:01.0754 4888 C:\Windows\SysWOW64\winmm.dll - ok
    23:46:01.0757 4888 [ 4F583ABEF86D3B9DD2C0D24C9E41138E ] C:\Windows\SysWOW64\winspool.drv
    23:46:01.0757 4888 C:\Windows\SysWOW64\winspool.drv - ok
    23:46:01.0759 4888 [ 7FFC244DFE77909A13F52CF54B1FE475 ] C:\Windows\SysWOW64\netutils.dll
    23:46:01.0759 4888 C:\Windows\SysWOW64\netutils.dll - ok
    23:46:01.0761 4888 [ C3CD50F19851FB3DB7A9418B32E1FEC1 ] C:\Windows\SysWOW64\samcli.dll
    23:46:01.0761 4888 C:\Windows\SysWOW64\samcli.dll - ok
    23:46:01.0763 4888 [ D8533AF2AAE712047A3CCAC9AC98EDC4 ] C:\Windows\SysWOW64\srvcli.dll
    23:46:01.0763 4888 C:\Windows\SysWOW64\srvcli.dll - ok
    23:46:01.0765 4888 [ 5C539C92A7704C80EDB45BFD8D7F600F ] C:\Windows\SysWOW64\winmmbase.dll
    23:46:01.0765 4888 C:\Windows\SysWOW64\winmmbase.dll - ok
    23:46:01.0767 4888 [ 182DD861AD25CD72AE6F3B54AE7AA8AD ] C:\Windows\SysWOW64\wkscli.dll
    23:46:01.0767 4888 C:\Windows\SysWOW64\wkscli.dll - ok
    23:46:01.0768 4888 [ 51E886381803D55926A6D50643B9436C ] C:\Windows\SysWOW64\imm32.dll
    23:46:01.0768 4888 C:\Windows\SysWOW64\imm32.dll - ok
    23:46:01.0770 4888 [ 69229810EB42C6FA2BAA298E02A043E1 ] C:\Windows\SysWOW64\msctf.dll
    23:46:01.0770 4888 C:\Windows\SysWOW64\msctf.dll - ok
    23:46:01.0772 4888 [ 024B76FAD711EFECD6DD0FBD87265444 ] C:\Windows\SysWOW64\setupapi.dll
    23:46:01.0772 4888 C:\Windows\SysWOW64\setupapi.dll - ok
    23:46:01.0773 4888 [ B2A25F2C3DCCD9858701E0AF13E5EE4D ] C:\Windows\SysWOW64\devobj.dll
    23:46:01.0773 4888 C:\Windows\SysWOW64\devobj.dll - ok
    23:46:01.0776 4888 [ BFDD523AB06AB9932B6327E52C6E9AE6 ] C:\Windows\SysWOW64\propsys.dll
    23:46:01.0776 4888 C:\Windows\SysWOW64\propsys.dll - ok
    23:46:01.0778 4888 [ 27D5372C6D1657C586AE0A3E06D1B7E3 ] C:\Windows\SysWOW64\jsproxy.dll
    23:46:01.0778 4888 C:\Windows\SysWOW64\jsproxy.dll - ok
    23:46:01.0779 4888 [ 4E743FA4D61A2EF8CA1642F49DC4784D ] C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985\comctl32.dll
    23:46:01.0780 4888 C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16384_none_893961408605e985\comctl32.dll - ok
    23:46:01.0782 4888 [ C317E72447B437F99CC750BD876DF30E ] C:\Windows\SysWOW64\mswsock.dll
    23:46:01.0782 4888 C:\Windows\SysWOW64\mswsock.dll - ok
    23:46:01.0784 4888 [ 7A4797475ABAD6ECF1BCB08637922ECA ] C:\Windows\SysWOW64\winhttp.dll
    23:46:01.0784 4888 C:\Windows\SysWOW64\winhttp.dll - ok
    23:46:01.0786 4888 [ A4FAB5F7818A69DA6E740943CB8F7CA9 ] C:\Program Files (x86)\Skype\Updater\Updater.exe
    23:46:01.0786 4888 C:\Program Files (x86)\Skype\Updater\Updater.exe - ok
    23:46:01.0788 4888 [ 3EA8A16169C26AFBEB544E0E48421186 ] C:\Windows\System32\Drivers\secdrv.sys
    23:46:01.0788 4888 C:\Windows\System32\Drivers\secdrv.sys - ok
    23:46:01.0790 4888 [ CD282626738B6BC92B6E7CD0AAE95B63 ] C:\Windows\System32\seclogon.dll
    23:46:01.0790 4888 C:\Windows\System32\seclogon.dll - ok
    23:46:01.0792 4888 [ 84F0DC88E6AE4B49B032509868B4BD73 ] C:\Windows\SysWOW64\dhcpcsvc.dll
    23:46:01.0792 4888 C:\Windows\SysWOW64\dhcpcsvc.dll - ok
    23:46:01.0793 4888 [ 0F3B2F57676DEBB7F86B74A51BEC079C ] C:\Windows\SysWOW64\dhcpcsvc6.dll
    23:46:01.0793 4888 C:\Windows\SysWOW64\dhcpcsvc6.dll - ok
    23:46:01.0795 4888 [ 9400C71F5A1A380B494B6922F007D485 ] C:\Windows\System32\Drivers\srvnet.sys
    23:46:01.0795 4888 C:\Windows\System32\Drivers\srvnet.sys - ok
    23:46:01.0797 4888 [ 7090C3C7CE14F6EEBE5C0AFE1A7C32A5 ] C:\Program Files (x86)\AVG\AVG2013\winamapix.dll
    23:46:01.0797 4888 C:\Program Files (x86)\AVG\AVG2013\winamapix.dll - ok
    23:46:01.0799 4888 [ 8F2A13A5DF99D72FDDE87F502A66F989 ] C:\Windows\System32\Drivers\tcpipreg.sys
    23:46:01.0799 4888 C:\Windows\System32\Drivers\tcpipreg.sys - ok
    23:46:01.0800 4888 [ DC21E1F06343773D7E24362DCEF7944B ] C:\Windows\System32\sysmain.dll
    23:46:01.0800 4888 C:\Windows\System32\sysmain.dll - ok
    23:46:01.0802 4888 [ 3D6B518B71C75C8FA4115A33615C107A ] C:\Windows\System32\wbem\WMIsvc.dll
    23:46:01.0802 4888 C:\Windows\System32\wbem\WMIsvc.dll - ok
    23:46:01.0804 4888 [ BAC8A721736AECC55A4F71523AEAB65F ] C:\Windows\System32\wiaservc.dll
    23:46:01.0804 4888 C:\Windows\System32\wiaservc.dll - ok
    23:46:01.0806 4888 [ 21CA3869D0EA99C902B26ED697BD78E5 ] C:\Windows\System32\wbemcomn.dll
    23:46:01.0806 4888 C:\Windows\System32\wbemcomn.dll - ok
    23:46:01.0808 4888 [ 4B968083851285996B465FFDCB5AE9E8 ] C:\Windows\SysWOW64\FWPUCLNT.DLL
    23:46:01.0808 4888 C:\Windows\SysWOW64\FWPUCLNT.DLL - ok
    23:46:01.0810 4888 [ A529CFE32565C0B145578FFB2B32C9A5 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    23:46:01.0810 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe - ok
    23:46:01.0812 4888 [ 8C8CF3041B27E7657ADD0EE17F6DBFCA ] C:\Windows\System32\trkwks.dll
    23:46:01.0812 4888 C:\Windows\System32\trkwks.dll - ok
    23:46:01.0814 4888 [ 2935B83ADDED04242622580091251474 ] C:\Windows\System32\wiatrace.dll
    23:46:01.0814 4888 C:\Windows\System32\wiatrace.dll - ok
    23:46:01.0816 4888 [ 6A0C81508755C7F8EA5C5A4BC0E922CB ] C:\Windows\SysWOW64\apphelp.dll
    23:46:01.0816 4888 C:\Windows\SysWOW64\apphelp.dll - ok
    23:46:01.0818 4888 [ 735D4C58ADC1F4DE5A59850078910218 ] C:\Windows\System32\wbem\wbemcore.dll
    23:46:01.0818 4888 C:\Windows\System32\wbem\wbemcore.dll - ok
    23:46:01.0820 4888 [ CCBFC667F7D9FF80C560EA378C1B5F3E ] C:\Windows\apppatch\AcGenral.dll
    23:46:01.0820 4888 C:\Windows\apppatch\AcGenral.dll - ok
    23:46:01.0823 4888 [ E54F732758B5BB7405C2F4E05A64D6E1 ] C:\Windows\System32\wbem\esscli.dll
    23:46:01.0823 4888 C:\Windows\System32\wbem\esscli.dll - ok
    23:46:01.0825 4888 [ 508F0DE3A65183A3D7ADF4C1F20E9696 ] C:\Windows\System32\PortableDeviceWiaCompat.dll
    23:46:01.0825 4888 C:\Windows\System32\PortableDeviceWiaCompat.dll - ok
    23:46:01.0826 4888 [ 19304E66115DD1400182211B4FD7E73A ] C:\Windows\System32\wbem\fastprox.dll
    23:46:01.0827 4888 C:\Windows\System32\wbem\fastprox.dll - ok
    23:46:01.0828 4888 [ D07CDFA0320605FC429D5C54D89DC925 ] C:\Windows\SysWOW64\uxtheme.dll
    23:46:01.0828 4888 C:\Windows\SysWOW64\uxtheme.dll - ok
    23:46:01.0829 4888 [ 9B7280BAF510CE8AA3E712BC63EE50E3 ] C:\Windows\System32\wbem\wbemsvc.dll
    23:46:01.0829 4888 C:\Windows\System32\wbem\wbemsvc.dll - ok
    23:46:01.0831 4888 [ 8F625E3E627BC99823E7E168A9AB5625 ] C:\Windows\System32\wsdchngr.dll
    23:46:01.0831 4888 C:\Windows\System32\wsdchngr.dll - ok
    23:46:01.0833 4888 [ F082773EF130B7293E0F6D64B962A118 ] C:\Windows\System32\deviceassociation.dll
    23:46:01.0833 4888 C:\Windows\System32\deviceassociation.dll - ok
    23:46:01.0835 4888 [ E4A6D4B0E58231488F3BB32A24995D85 ] C:\Windows\SysWOW64\msacm32.dll
    23:46:01.0835 4888 C:\Windows\SysWOW64\msacm32.dll - ok
    23:46:01.0837 4888 [ 7139C54E7282804745F9991F588FE506 ] C:\Windows\SysWOW64\wbem\wbemsvc.dll
    23:46:01.0837 4888 C:\Windows\SysWOW64\wbem\wbemsvc.dll - ok
    23:46:01.0839 4888 [ 47E892006A6155BE617F526E02CA09DD ] C:\Windows\System32\fundisc.dll
    23:46:01.0839 4888 C:\Windows\System32\fundisc.dll - ok
    23:46:01.0842 4888 [ 992BD101F370B0D93A1131227BA342F6 ] C:\Windows\SysWOW64\wbem\fastprox.dll
    23:46:01.0842 4888 C:\Windows\SysWOW64\wbem\fastprox.dll - ok
    23:46:01.0843 4888 [ 64F6AFD2F4F8D0DB5B8770EC59103778 ] C:\Windows\System32\PortableDeviceApi.dll
    23:46:01.0843 4888 C:\Windows\System32\PortableDeviceApi.dll - ok
    23:46:01.0845 4888 [ 341ADCBB9A744F559C3CF3CA5D3D8934 ] C:\Windows\SysWOW64\dwmapi.dll
    23:46:01.0845 4888 C:\Windows\SysWOW64\dwmapi.dll - ok
    23:46:01.0847 4888 [ E24FCC199F4AD27289ACEC15D8A6740C ] C:\Windows\System32\fdPnp.dll
    23:46:01.0847 4888 C:\Windows\System32\fdPnp.dll - ok
    23:46:01.0849 4888 [ 616285E00B6B7F2DE84891F6D094528B ] C:\Windows\System32\wbem\repdrvfs.dll
    23:46:01.0849 4888 C:\Windows\System32\wbem\repdrvfs.dll - ok
    23:46:01.0850 4888 [ 4811A86C4CA6EDC58D316A29E56629F6 ] C:\Windows\System32\wbem\wmiutils.dll
    23:46:01.0850 4888 C:\Windows\System32\wbem\wmiutils.dll - ok
    23:46:01.0852 4888 [ E6C7752237B3A615A190D9EE23ECF152 ] C:\Windows\System32\wbem\WmiPrvSD.dll
    23:46:01.0852 4888 C:\Windows\System32\wbem\WmiPrvSD.dll - ok
    23:46:01.0854 4888 [ 54482D83FF8501A46BB0B349FED0DAEB ] C:\Windows\System32\ncobjapi.dll
    23:46:01.0854 4888 C:\Windows\System32\ncobjapi.dll - ok
    23:46:01.0856 4888 [ C6B60D86B37D1C10AF7E7764D74D9194 ] C:\Windows\apppatch\AcLayers.dll
    23:46:01.0856 4888 C:\Windows\apppatch\AcLayers.dll - ok
    23:46:01.0858 4888 [ E296B0D7842DD5478605B6C86573E52F ] C:\Windows\System32\wbem\wbemess.dll
    23:46:01.0858 4888 C:\Windows\System32\wbem\wbemess.dll - ok
    23:46:01.0860 4888 [ 0EFCE333980CA8C9CC7C13D067EB80AF ] C:\Windows\SysWOW64\cabinet.dll
    23:46:01.0861 4888 C:\Windows\SysWOW64\cabinet.dll - ok
    23:46:01.0864 4888 [ D21AB32F16E8DE67D45E5A383B5E52BA ] C:\Program Files (x86)\Spybot - Search & Destroy 2\ssleay32.dll
    23:46:01.0864 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\ssleay32.dll - ok
    23:46:01.0866 4888 [ B009D6171147BE129636A49C4178E487 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\libeay32.dll
    23:46:01.0866 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\libeay32.dll - ok
    23:46:01.0869 4888 [ F1F9EEEF647CFA62A7104C054CE0999B ] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_50944e7cbcb706e5\msvcr90.dll
    23:46:01.0869 4888 C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_50944e7cbcb706e5\msvcr90.dll - ok
    23:46:01.0871 4888 [ C2106BB710AA34A046126AED7BCA6964 ] C:\Windows\System32\Drivers\srv2.sys
    23:46:01.0871 4888 C:\Windows\System32\Drivers\srv2.sys - ok
    23:46:01.0873 4888 [ 0F1FCD575A03ABDE13FCA9D0ADE4DDA6 ] C:\Windows\System32\Drivers\srv.sys
    23:46:01.0873 4888 C:\Windows\System32\Drivers\srv.sys - ok
    23:46:01.0875 4888 [ CAC5202757EF68C4849B0DFFA75F6D3C ] C:\Windows\System32\iphlpsvc.dll
    23:46:01.0875 4888 C:\Windows\System32\iphlpsvc.dll - ok
    23:46:01.0877 4888 [ FB0C1B7F94FA08E72F19F6F2CE7210E1 ] C:\Windows\System32\wscsvc.dll
    23:46:01.0877 4888 C:\Windows\System32\wscsvc.dll - ok
    23:46:01.0879 4888 [ 648EDA660D32C7B80F62EF74B6B392D5 ] C:\Windows\System32\adhsvc.dll
    23:46:01.0879 4888 C:\Windows\System32\adhsvc.dll - ok
    23:46:01.0881 4888 [ 04ED9A5B39FFDDDD8314E8F34049022F ] C:\Windows\System32\dbghelp.dll
    23:46:01.0881 4888 C:\Windows\System32\dbghelp.dll - ok
    23:46:01.0882 4888 [ B1E1452C0DE1249BB22ADCA48B280AC7 ] C:\Windows\System32\httpprxm.dll
    23:46:01.0882 4888 C:\Windows\System32\httpprxm.dll - ok
    23:46:01.0884 4888 [ 47F7B9DF32E259FC7B8D9ED34EA4E0BF ] C:\Windows\System32\ncbservice.dll
    23:46:01.0884 4888 C:\Windows\System32\ncbservice.dll - ok
    23:46:01.0886 4888 [ B6191C2187460A0568A9F510188DE2ED ] C:\Windows\System32\wbem\wbemprox.dll
    23:46:01.0886 4888 C:\Windows\System32\wbem\wbemprox.dll - ok
    23:46:01.0888 4888 [ CB63BDB77BB86549FC3303C2F11EDC18 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    23:46:01.0888 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe - ok
    23:46:01.0890 4888 [ D86F25F0AD6CA6E77A9F67641EEB6722 ] C:\Windows\System32\sqmapi.dll
    23:46:01.0890 4888 C:\Windows\System32\sqmapi.dll - ok
    23:46:01.0892 4888 [ 310068BDA80B1D55C36580FD8A873FAF ] C:\Windows\System32\browser.dll
    23:46:01.0892 4888 C:\Windows\System32\browser.dll - ok
    23:46:01.0893 4888 [ 3A729A258006D813FCB2D3CEE8733878 ] C:\Windows\System32\netprofm.dll
    23:46:01.0893 4888 C:\Windows\System32\netprofm.dll - ok
    23:46:01.0895 4888 [ 256EE31588257E8A555DBFAA13F1908E ] C:\Windows\System32\srvsvc.dll
    23:46:01.0895 4888 C:\Windows\System32\srvsvc.dll - ok
    23:46:01.0897 4888 [ C9DA260FC97E22905A97FFC3D5F42B18 ] C:\Windows\System32\bi.dll
    23:46:01.0897 4888 C:\Windows\System32\bi.dll - ok
    23:46:01.0898 4888 [ 5C51484B4D2211FBE88DEB472588B5DF ] C:\Windows\System32\wdscore.dll
    23:46:01.0898 4888 C:\Windows\System32\wdscore.dll - ok
    23:46:01.0900 4888 [ 58D768B03F3C7FF919004634C29E7843 ] C:\Windows\System32\nci.dll
    23:46:01.0900 4888 C:\Windows\System32\nci.dll - ok
    23:46:01.0902 4888 [ 3C14BC7A5590DFDD754CA7A15CED0A9A ] C:\Windows\System32\sscore.dll
    23:46:01.0902 4888 C:\Windows\System32\sscore.dll - ok
    23:46:01.0904 4888 [ C5D0659CEA9A87C4C4E82B0464683F19 ] C:\Windows\System32\sscoreext.dll
    23:46:01.0904 4888 C:\Windows\System32\sscoreext.dll - ok
    23:46:01.0906 4888 [ 547D152592C3B4960DD80D9C61F7C8A9 ] C:\Windows\System32\mi.dll
    23:46:01.0906 4888 C:\Windows\System32\mi.dll - ok
    23:46:01.0907 4888 [ 8CABB7DB418AA58CEC8A00E43368EAA7 ] C:\Windows\System32\miutils.dll
    23:46:01.0907 4888 C:\Windows\System32\miutils.dll - ok
    23:46:01.0909 4888 [ 0AEF3F58E05D5BBCD8A3CF2B393FE465 ] C:\Windows\System32\wmidcom.dll
    23:46:01.0909 4888 C:\Windows\System32\wmidcom.dll - ok
    23:46:01.0911 4888 [ 95AB131067CD1695B62DEE20ADDD5071 ] C:\Windows\System32\resutils.dll
    23:46:01.0911 4888 C:\Windows\System32\resutils.dll - ok
    23:46:01.0912 4888 [ 59EA2E681CBB1F0D1DC966E27864B234 ] C:\Windows\System32\wuapi.dll
    23:46:01.0912 4888 C:\Windows\System32\wuapi.dll - ok
    23:46:01.0914 4888 [ A0CFAE5D60E2011E7531F1921028259C ] C:\Windows\System32\cabinet.dll
    23:46:01.0914 4888 C:\Windows\System32\cabinet.dll - ok
    23:46:01.0916 4888 [ 32550CE9B5AFB962A1BB8D995E76688D ] C:\Windows\System32\clusapi.dll
    23:46:01.0916 4888 C:\Windows\System32\clusapi.dll - ok
    23:46:01.0918 4888 [ 08AF5B64DA03D206508CBACAEB9E1FF3 ] C:\Windows\System32\ndiscapCfg.dll
    23:46:01.0918 4888 C:\Windows\System32\ndiscapCfg.dll - ok
    23:46:01.0920 4888 [ E1F5ACD2E86DFC938AD781EC162B745D ] C:\Windows\System32\wbem\NCProv.dll
    23:46:01.0920 4888 C:\Windows\System32\wbem\NCProv.dll - ok
    23:46:01.0921 4888 [ 52EF3A32EC17D3E9580A79A23B712917 ] C:\Windows\System32\brdgcfg.dll
    23:46:01.0921 4888 C:\Windows\System32\brdgcfg.dll - ok
    23:46:01.0923 4888 [ F7FE8684ADE6E144F6BCDA556B6907E7 ] C:\Windows\System32\dafupnp.dll
    23:46:01.0923 4888 C:\Windows\System32\dafupnp.dll - ok
    23:46:01.0926 4888 [ 20F6FD63E6D456114BC8056D62792786 ] C:\Windows\System32\netprofmsvc.dll
    23:46:01.0926 4888 C:\Windows\System32\netprofmsvc.dll - ok
    23:46:01.0928 4888 [ FAC37D7B3D6354A5A5E19A45B50B4008 ] C:\Windows\System32\hidserv.dll
    23:46:01.0928 4888 C:\Windows\System32\hidserv.dll - ok
    23:46:01.0929 4888 [ DD35092F11DCED777EF8621D4EE2505A ] C:\Windows\System32\rascfg.dll
    23:46:01.0929 4888 C:\Windows\System32\rascfg.dll - ok
    23:46:01.0931 4888 [ 240FC332484572227CD1DF82407F33E5 ] C:\Windows\System32\wdi.dll
    23:46:01.0931 4888 C:\Windows\System32\wdi.dll - ok
    23:46:01.0933 4888 [ 94AA5150E35B3ABB7191FE641E3C2473 ] C:\Windows\System32\wpdbusenum.dll
    23:46:01.0933 4888 C:\Windows\System32\wpdbusenum.dll - ok
    23:46:01.0935 4888 [ 54A59A152C795E4FD51FB247841F57D6 ] C:\Windows\System32\diagperf.dll
    23:46:01.0935 4888 C:\Windows\System32\diagperf.dll - ok
    23:46:01.0937 4888 [ 909EBA9AF43AF0E70EA7FFC352484424 ] C:\Windows\System32\mprapi.dll
    23:46:01.0937 4888 C:\Windows\System32\mprapi.dll - ok
    23:46:01.0938 4888 [ D1A04DC07552A12553D64404CDBAB3A1 ] C:\Windows\System32\perftrack.dll
    23:46:01.0939 4888 C:\Windows\System32\perftrack.dll - ok
    23:46:01.0941 4888 [ 04C84B41AD7BC0C663A613CA9E3D3FC5 ] C:\Windows\System32\rasadhlp.dll
    23:46:01.0941 4888 C:\Windows\System32\rasadhlp.dll - ok
    23:46:01.0942 4888 [ 829562D41F5359BCA0ABC9DBE51B8723 ] C:\Windows\System32\umb.dll
    23:46:01.0943 4888 C:\Windows\System32\umb.dll - ok
    23:46:01.0944 4888 [ 06DF6E95E59FF75FFB575A6FC63CC233 ] C:\Windows\System32\wups.dll
    23:46:01.0944 4888 C:\Windows\System32\wups.dll - ok
    23:46:01.0946 4888 [ 11F0834544D68B955E6C44DFFB272122 ] C:\Windows\System32\mprmsg.dll
    23:46:01.0946 4888 C:\Windows\System32\mprmsg.dll - ok
    23:46:01.0948 4888 [ 91E352ACB49DF3388C960A09243E5616 ] C:\Windows\System32\NdisImPlatform.dll
    23:46:01.0948 4888 C:\Windows\System32\NdisImPlatform.dll - ok
    23:46:01.0950 4888 [ EBA655700A35328F4E61266DD35FB71F ] C:\Windows\System32\pcadm.dll
    23:46:01.0950 4888 C:\Windows\System32\pcadm.dll - ok
    23:46:01.0952 4888 [ 7417B004B5BD4B9EC1140890131CD41D ] C:\Windows\System32\pnpts.dll
    23:46:01.0952 4888 C:\Windows\System32\pnpts.dll - ok
    23:46:01.0953 4888 [ F6BB843AFC93AEE9E928CFE4BB5B743C ] C:\Windows\System32\LldpNotify.dll
    23:46:01.0953 4888 C:\Windows\System32\LldpNotify.dll - ok
    23:46:01.0955 4888 [ CC5512FC3FCCEA164F01592B5979F1BE ] C:\Windows\System32\srumsvc.dll
    23:46:01.0955 4888 C:\Windows\System32\srumsvc.dll - ok
    23:46:01.0956 4888 [ 8B5D475B48506471669B9B46945138B0 ] C:\Windows\System32\wer.dll
    23:46:01.0956 4888 C:\Windows\System32\wer.dll - ok
    23:46:01.0958 4888 [ A2418204EBFA6F41DE3DF2FBB46B7F3F ] C:\Windows\System32\pcacli.dll
    23:46:01.0958 4888 C:\Windows\System32\pcacli.dll - ok
    23:46:01.0961 4888 [ AF56A8936DF2F7031D4311C81D065CE9 ] C:\Windows\System32\tcpipcfg.dll
    23:46:01.0961 4888 C:\Windows\System32\tcpipcfg.dll - ok
    23:46:01.0963 4888 [ A18100201E7477BB47C72711E092A8F0 ] C:\Windows\System32\esent.dll
    23:46:01.0963 4888 C:\Windows\System32\esent.dll - ok
    23:46:01.0965 4888 [ 98D9EC5E81ECFCCEEB94894D19AA9F7E ] C:\Windows\System32\mpr.dll
    23:46:01.0965 4888 C:\Windows\System32\mpr.dll - ok
    23:46:01.0967 4888 [ 26D38C1391CD81ADDD791DE136E2FEA7 ] C:\Windows\System32\npmproxy.dll
    23:46:01.0967 4888 C:\Windows\System32\npmproxy.dll - ok
    23:46:01.0969 4888 [ 0F57DEA30340B49B06DCB8B077BEF072 ] C:\Windows\System32\PortableDeviceConnectApi.dll
    23:46:01.0969 4888 C:\Windows\System32\PortableDeviceConnectApi.dll - ok
    23:46:01.0971 4888 [ 7A20882D76D4A78240A5AC9F2C2EBA21 ] C:\Windows\System32\ssdpsrv.dll
    23:46:01.0971 4888 C:\Windows\System32\ssdpsrv.dll - ok
    23:46:01.0973 4888 [ 0D97A065E85D59B8F0EE2BD31A679456 ] C:\Windows\System32\wdiasqmmodule.dll
    23:46:01.0973 4888 C:\Windows\System32\wdiasqmmodule.dll - ok
    23:46:01.0975 4888 [ CEB35EB551BE4F216691255D38867346 ] C:\Windows\System32\activeds.dll
    23:46:01.0975 4888 C:\Windows\System32\activeds.dll - ok
    23:46:01.0976 4888 [ 6AE7DC415EFF4840512E5354CE99F4A5 ] C:\Windows\System32\adsldpc.dll
    23:46:01.0976 4888 C:\Windows\System32\adsldpc.dll - ok
    23:46:01.0978 4888 [ D0398301E7E94D2B7DFE6D12DE77E809 ] C:\Windows\System32\cryptnet.dll
    23:46:01.0978 4888 C:\Windows\System32\cryptnet.dll - ok
    23:46:01.0980 4888 [ 335C4488A14AC4B52B3E1CDF6D6F7780 ] C:\Windows\System32\hnetcfg.dll
    23:46:01.0980 4888 C:\Windows\System32\hnetcfg.dll - ok
    23:46:01.0982 4888 [ 11A9C08F39F929B0D04FEE7C743CE8D9 ] C:\Windows\System32\adsldp.dll
    23:46:01.0982 4888 C:\Windows\System32\adsldp.dll - ok
    23:46:01.0984 4888 [ 2D7BB53EA2BB3F213CE558A79EC8448D ] C:\Windows\System32\nduprov.dll
    23:46:01.0984 4888 C:\Windows\System32\nduprov.dll - ok
    23:46:01.0986 4888 [ 9E2E7FE5237CFE3A0529B54C53021CA0 ] C:\Windows\System32\appsruprov.dll
    23:46:01.0986 4888 C:\Windows\System32\appsruprov.dll - ok
    23:46:01.0988 4888 [ D0A82052050909677C648B2496C0909E ] C:\Windows\System32\wpnsruprov.dll
    23:46:01.0988 4888 C:\Windows\System32\wpnsruprov.dll - ok
    23:46:01.0990 4888 [ 55955FB63C2E045AA9915184880B4F27 ] C:\Windows\System32\cscapi.dll
    23:46:01.0990 4888 C:\Windows\System32\cscapi.dll - ok
    23:46:01.0992 4888 [ 71697EDF104E5EACD75822E588FA8149 ] C:\Windows\System32\energyprov.dll
    23:46:01.0992 4888 C:\Windows\System32\energyprov.dll - ok
    23:46:01.0994 4888 [ FA6C8E59B74908550607EBEDCD7BA1E2 ] C:\Windows\System32\secur32.dll
    23:46:01.0994 4888 C:\Windows\System32\secur32.dll - ok
    23:46:01.0995 4888 [ AE03E9CBFFB8EDE81B3DA7603E546F56 ] C:\Windows\System32\srumapi.dll
    23:46:01.0995 4888 C:\Windows\System32\srumapi.dll - ok
    23:46:01.0997 4888 [ 855E7E347893BDB93245120E137577FB ] C:\Windows\System32\radardt.dll
    23:46:01.0997 4888 C:\Windows\System32\radardt.dll - ok
    23:46:01.0999 4888 [ 9AD609CFDA377BFCE0CB7ABF294BC74B ] C:\Windows\SysWOW64\wscisvif.dll
    23:46:01.0999 4888 C:\Windows\SysWOW64\wscisvif.dll - ok
    23:46:02.0001 4888 [ CA4FAFFA957C71C006B59E29DFE3EB8B ] C:\Windows\System32\pnrpnsp.dll
    23:46:02.0001 4888 C:\Windows\System32\pnrpnsp.dll - ok
    23:46:02.0003 4888 [ 768B5A538A11E9C6F8EDD9AFDFA16936 ] C:\Windows\System32\winrnr.dll
    23:46:02.0003 4888 C:\Windows\System32\winrnr.dll - ok
    23:46:02.0005 4888 [ 4E1278D5040A2D2D274EB98661CBF07E ] C:\Windows\SysWOW64\devrtl.dll
    23:46:02.0005 4888 C:\Windows\SysWOW64\devrtl.dll - ok
    23:46:02.0007 4888 [ 149FEE067A002D75B7714C300D019C9E ] C:\Windows\System32\NapiNSP.dll
    23:46:02.0007 4888 C:\Windows\System32\NapiNSP.dll - ok
    23:46:02.0009 4888 [ B460531B5F5ED9E8ABCA3BA342AE9563 ] C:\Program Files\Windows Defender\MpCmdRun.exe
    23:46:02.0009 4888 C:\Program Files\Windows Defender\MpCmdRun.exe - ok
    23:46:02.0011 4888 [ FC06C5B62750F4D2D0866FC525709842 ] C:\Windows\SysWOW64\AppXDeploymentClient.dll
    23:46:02.0011 4888 C:\Windows\SysWOW64\AppXDeploymentClient.dll - ok
    23:46:02.0013 4888 [ D9CB0782AF819548072AA45B70F8B22D ] C:\Windows\System32\Drivers\condrv.sys
    23:46:02.0013 4888 C:\Windows\System32\Drivers\condrv.sys - ok
    23:46:02.0015 4888 [ 3E30EF769BC47B9B16515EB66EFF1E2F ] C:\Windows\System32\conhost.exe
    23:46:02.0015 4888 C:\Windows\System32\conhost.exe - ok
    23:46:02.0017 4888 [ F6F1B55FC775E6F096AD400030E9D0B8 ] C:\Windows\System32\dimsjob.dll
    23:46:02.0017 4888 C:\Windows\System32\dimsjob.dll - ok
    23:46:02.0019 4888 [ E38D9838439D0BBC22EF3F1E9F058F8E ] C:\Windows\System32\msiexec.exe
    23:46:02.0019 4888 C:\Windows\System32\msiexec.exe - ok
    23:46:02.0020 4888 [ 93962D7FBE16AA0566A9C90E444C51A9 ] C:\Windows\System32\SettingSyncInfo.dll
    23:46:02.0021 4888 C:\Windows\System32\SettingSyncInfo.dll - ok
    23:46:02.0022 4888 [ 359F8D71B628966A72565BF7D9006826 ] C:\Windows\apppatch\apppatch64\AcLayers.dll
    23:46:02.0022 4888 C:\Windows\apppatch\apppatch64\AcLayers.dll - ok
    23:46:02.0024 4888 [ B617F2E83951A9A4F495BBA58CF492B2 ] C:\Windows\System32\dllhost.exe
    23:46:02.0024 4888 C:\Windows\System32\dllhost.exe - ok
    23:46:02.0026 4888 [ 173C770E388C31EDBB23F4283992F73E ] C:\Program Files\Windows Defender\MpClient.dll
    23:46:02.0026 4888 C:\Program Files\Windows Defender\MpClient.dll - ok
    23:46:02.0028 4888 [ B1E63281081B64BB570EA5B3EC5146C5 ] C:\Windows\System32\sfc.dll
    23:46:02.0028 4888 C:\Windows\System32\sfc.dll - ok
    23:46:02.0030 4888 [ AFE9464D80CFE0B0ECFE906C8A5996A0 ] C:\Windows\System32\winspool.drv
    23:46:02.0030 4888 C:\Windows\System32\winspool.drv - ok
    23:46:02.0032 4888 [ A6E506E122DF3244443BE6113404EB96 ] C:\Windows\System32\pautoenr.dll
    23:46:02.0032 4888 C:\Windows\System32\pautoenr.dll - ok
    23:46:02.0033 4888 [ 37814A36DBAF1AE9D42BE89889ECB4B7 ] C:\Windows\System32\certca.dll
    23:46:02.0033 4888 C:\Windows\System32\certca.dll - ok
    23:46:02.0035 4888 [ 7853D2AB445C10F97610B2B05FA4CF0A ] E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    23:46:02.0035 4888 E:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe - ok
    23:46:02.0037 4888 [ E60DEF401500F909C3DA7B13E21F02D8 ] C:\Program Files\Microsoft Office\Office15\msoia.exe
    23:46:02.0037 4888 C:\Program Files\Microsoft Office\Office15\msoia.exe - ok
    23:46:02.0039 4888 [ 15E174928C1ABD23B3647270F2632D6C ] C:\Windows\System32\CertEnroll.dll
    23:46:02.0039 4888 C:\Windows\System32\CertEnroll.dll - ok
    23:46:02.0041 4888 [ 14473D7F73F7C1DB535CD4C8D2CF35AA ] C:\Windows\System32\AppXDeploymentServer.dll
    23:46:02.0041 4888 C:\Windows\System32\AppXDeploymentServer.dll - ok
    23:46:02.0043 4888 [ 0E925F7BA032920D58DD284B6181A247 ] C:\Windows\System32\userinit.exe
    23:46:02.0043 4888 C:\Windows\System32\userinit.exe - ok
    23:46:02.0045 4888 [ CD09341CCD92DA45EA5A0C725270FA51 ] C:\Windows\System32\userinitext.dll
    23:46:02.0045 4888 C:\Windows\System32\userinitext.dll - ok
    23:46:02.0046 4888 [ 0828E3E7BD77C89149EAD3232BFD38DB ] C:\Windows\System32\fdPHost.dll
    23:46:02.0046 4888 C:\Windows\System32\fdPHost.dll - ok
    23:46:02.0048 4888 [ 872506AAB591E8908DF4461475AF92DF ] C:\Windows\System32\FDResPub.dll
    23:46:02.0048 4888 C:\Windows\System32\FDResPub.dll - ok
    23:46:02.0050 4888 [ 024632F2FC93286700FE82763C0A98FD ] C:\Windows\System32\tdh.dll
    23:46:02.0050 4888 C:\Windows\System32\tdh.dll - ok
    23:46:02.0052 4888 [ ACEBEB1F363C819576216CF9C4962FA2 ] C:\Windows\System32\fdWSD.dll
    23:46:02.0052 4888 C:\Windows\System32\fdWSD.dll - ok
    23:46:02.0053 4888 [ 8BC5E1F477761F75B26E66746828915D ] C:\Windows\System32\HotStartUserAgent.dll
    23:46:02.0054 4888 C:\Windows\System32\HotStartUserAgent.dll - ok
    23:46:02.0055 4888 [ 70B5BD19740464A41B835C082819B74D ] C:\Windows\System32\WSDApi.dll
    23:46:02.0055 4888 C:\Windows\System32\WSDApi.dll - ok
    23:46:02.0057 4888 [ D029339C0F59CF662094EDDF8C42B2B5 ] C:\Windows\System32\msvcp100.dll
    23:46:02.0057 4888 C:\Windows\System32\msvcp100.dll - ok
    23:46:02.0059 4888 [ 456913A14EAFD876ABDC1FC11DA856FA ] C:\Windows\System32\taskhostex.exe
    23:46:02.0059 4888 C:\Windows\System32\taskhostex.exe - ok
    23:46:02.0061 4888 [ E13A31D5254C25406A7946BDD9B06364 ] C:\Windows\explorer.exe
    23:46:02.0061 4888 C:\Windows\explorer.exe - ok
    23:46:02.0063 4888 [ B5EB8E2AF9B3E067A8525622AEEC212E ] C:\Windows\System32\wlroamextension.dll
    23:46:02.0063 4888 C:\Windows\System32\wlroamextension.dll - ok
    23:46:02.0066 4888 [ 509192E80BF34E985C4D277A8FFF2893 ] C:\Windows\System32\webservices.dll
    23:46:02.0066 4888 C:\Windows\System32\webservices.dll - ok
    23:46:02.0067 4888 [ 88449B888787E8BFA5145C9CF5E610E1 ] C:\Windows\SysWOW64\Windows.ApplicationModel.dll
    23:46:02.0067 4888 C:\Windows\SysWOW64\Windows.ApplicationModel.dll - ok
    23:46:02.0069 4888 [ D3B1196386488D4BEDA5DFDA3749E36C ] C:\Windows\System32\fdSSDP.dll
    23:46:02.0069 4888 C:\Windows\System32\fdSSDP.dll - ok
    23:46:02.0071 4888 [ A572A1F193C14D7C17AB2BF3029A52BB ] C:\Windows\System32\MsCtfMonitor.dll
    23:46:02.0071 4888 C:\Windows\System32\MsCtfMonitor.dll - ok
    23:46:02.0074 4888 [ 1A196FE539A6F81977805B6CE4F90BDC ] C:\Windows\System32\msutb.dll
    23:46:02.0074 4888 C:\Windows\System32\msutb.dll - ok
    23:46:02.0075 4888 [ 38E669E49C35B6A02A9AF0737C526C0F ] C:\Windows\System32\PlaySndSrv.dll
    23:46:02.0075 4888 C:\Windows\System32\PlaySndSrv.dll - ok
    23:46:02.0077 4888 [ 282191A781E23B9CB50BF7652A5F511C ] C:\Windows\System32\httpapi.dll
    23:46:02.0077 4888 C:\Windows\System32\httpapi.dll - ok
    23:46:02.0079 4888 [ D64C4AFEE8277F35EF729A2B924666B0 ] C:\Windows\System32\appinfo.dll
    23:46:02.0079 4888 C:\Windows\System32\appinfo.dll - ok
    23:46:02.0081 4888 [ C982FE4CC91DECE2259F494FCEB4030F ] C:\Windows\System32\NcdAutoSetup.dll
    23:46:02.0081 4888 C:\Windows\System32\NcdAutoSetup.dll - ok
    23:46:02.0083 4888 [ E0D9F6FE18FA7F53ADD29AF719CE2B7E ] C:\Windows\System32\provsvc.dll
    23:46:02.0083 4888 C:\Windows\System32\provsvc.dll - ok
    23:46:02.0084 4888 [ 06856DA4C306F557BF115C4EF2269095 ] C:\Windows\System32\dtsh.dll
    23:46:02.0084 4888 C:\Windows\System32\dtsh.dll - ok
    23:46:02.0086 4888 [ 33DFC14DFDCCFA7AA10E392F6A8EC1CF ] C:\Windows\System32\ListSvc.dll
    23:46:02.0086 4888 C:\Windows\System32\ListSvc.dll - ok
    23:46:02.0088 4888 [ 88D686DE8D296AAC4A634B0EFBED9028 ] C:\Windows\System32\P2P.dll
    23:46:02.0088 4888 C:\Windows\System32\P2P.dll - ok
    23:46:02.0090 4888 [ A075E18C6A60C5B2A0A95AB7F7BF94E8 ] C:\Windows\System32\fdProxy.dll
    23:46:02.0090 4888 C:\Windows\System32\fdProxy.dll - ok
    23:46:02.0092 4888 [ AB76700D764A342D7475FB8F47CAB18C ] C:\Windows\System32\pnrpsvc.dll
    23:46:02.0092 4888 C:\Windows\System32\pnrpsvc.dll - ok
    23:46:02.0093 4888 [ 1C8E051AA357E5B73B74B4C8FFDCE9C3 ] C:\Windows\System32\actxprxy.dll
    23:46:02.0093 4888 C:\Windows\System32\actxprxy.dll - ok
    23:46:02.0095 4888 [ 4319FD931DCD796435ECB5DB4A04FBA5 ] C:\Windows\System32\p2psvc.dll
    23:46:02.0095 4888 C:\Windows\System32\p2psvc.dll - ok
    23:46:02.0097 4888 [ 0AB4E16A91E3C937A4C61488120E323A ] C:\Windows\System32\hgprint.dll
    23:46:02.0097 4888 C:\Windows\System32\hgprint.dll - ok
    23:46:02.0099 4888 [ 733E0C2F074B17D660349768BB70393D ] C:\Windows\System32\P2PGraph.dll
    23:46:02.0099 4888 C:\Windows\System32\P2PGraph.dll - ok
    23:46:02.0101 4888 [ FAE5157339279E1251D2482E6365691A ] C:\Windows\System32\fhlisten.dll
    23:46:02.0101 4888 C:\Windows\System32\fhlisten.dll - ok
    23:46:02.0102 4888 [ 9DE5419BE2F4A47A79785E285BA005E2 ] C:\Windows\System32\IdListen.dll
    23:46:02.0102 4888 C:\Windows\System32\IdListen.dll - ok
    23:46:02.0104 4888 [ 5F46797ED1629F152EF4A8DD0DBBC31F ] C:\Windows\System32\DAFWSD.dll
    23:46:02.0104 4888 C:\Windows\System32\DAFWSD.dll - ok
    23:46:02.0106 4888 [ 0E658D67C4A79294BC7BBBF4656F0794 ] C:\Windows\System32\winmm.dll
    23:46:02.0106 4888 C:\Windows\System32\winmm.dll - ok
    23:46:02.0108 4888 [ 15343AA01C41F7AB4FE549499159DB6F ] C:\Windows\System32\winmmbase.dll
    23:46:02.0108 4888 C:\Windows\System32\winmmbase.dll - ok
    23:46:02.0110 4888 [ C84B51243DF6A6C5835FF6CAEC5C6B97 ] C:\Windows\System32\webio.dll
    23:46:02.0110 4888 C:\Windows\System32\webio.dll - ok
    23:46:02.0112 4888 [ 7EC788D53F6F43061A9BFB70D745CCBC ] C:\Program Files (x86)\AVG\AVG2013\avgxpla.dll
    23:46:02.0112 4888 C:\Program Files (x86)\AVG\AVG2013\avgxpla.dll - ok
    23:46:02.0114 4888 [ 7E87637EECBACBB11BBA1124B805A747 ] C:\Program Files (x86)\AVG\AVG2013\avgopenssla.dll
    23:46:02.0114 4888 C:\Program Files (x86)\AVG\AVG2013\avgopenssla.dll - ok
    23:46:02.0116 4888 [ 8411147754C00B3B096C5C0ED95B3CFC ] C:\Windows\System32\runonce.exe
    23:46:02.0116 4888 C:\Windows\System32\runonce.exe - ok
    23:46:02.0118 4888 [ F0408DB6F94E3F0D5ED94B16C097A622 ] C:\Windows\SysWOW64\runonce.exe
    23:46:02.0118 4888 C:\Windows\SysWOW64\runonce.exe - ok
    23:46:02.0120 4888 [ 5996C79FB52BDE3FA10F77396654AE42 ] C:\Windows\SysWOW64\cmd.exe
    23:46:02.0120 4888 C:\Windows\SysWOW64\cmd.exe - ok
    23:46:02.0121 4888 [ F2E12B5B7EEDE6854104E5AF8AC841A8 ] C:\Windows\SysWOW64\cmdext.dll
    23:46:02.0121 4888 C:\Windows\SysWOW64\cmdext.dll - ok
    23:46:02.0123 4888 [ 9DA86B80AE1339F19CD5D290787EB7B3 ] C:\Windows\SysWOW64\shdocvw.dll
    23:46:02.0123 4888 C:\Windows\SysWOW64\shdocvw.dll - ok
    23:46:02.0125 4888 [ EBC984F0CE40E0DAF0454D806EC2A7EC ] C:\Users\DJ\AppData\Local\Temp\A4B6AB33-B0D7-434D-B956-38E0CB8A9B49.exe
    23:46:02.0125 4888 C:\Users\DJ\AppData\Local\Temp\A4B6AB33-B0D7-434D-B956-38E0CB8A9B49.exe - ok
    23:46:02.0127 4888 [ F8DE2E949B135BA7E45AE18DC82BF262 ] C:\Windows\SysWOW64\pcacli.dll
    23:46:02.0127 4888 C:\Windows\SysWOW64\pcacli.dll - ok
    23:46:02.0129 4888 [ 974AE60BF5B90E31412D93596C968E5B ] C:\Windows\System32\aelupsvc.dll
    23:46:02.0129 4888 C:\Windows\System32\aelupsvc.dll - ok
    23:46:02.0131 4888 [ 9A777EDE50D61A30265C4448A67F80E9 ] C:\Windows\System32\themeui.dll
    23:46:02.0131 4888 C:\Windows\System32\themeui.dll - ok
    23:46:02.0133 4888 [ 18D61C0822414ACDBD88EB8AD6319D70 ] C:\Windows\System32\ExplorerFrame.dll
    23:46:02.0133 4888 C:\Windows\System32\ExplorerFrame.dll - ok
    23:46:02.0136 4888 [ 51187F2413CDB487542290E046B6378E ] C:\Windows\System32\twinapi.dll
    23:46:02.0136 4888 C:\Windows\System32\twinapi.dll - ok
    23:46:02.0137 4888 [ BD7849649C6E85118802010F442F67A8 ] C:\Windows\SysWOW64\webio.dll
    23:46:02.0138 4888 C:\Windows\SysWOW64\webio.dll - ok
    23:46:02.0139 4888 [ BB3717D6FC27A22D0403C825A93BC068 ] C:\Windows\SysWOW64\dnsapi.dll
    23:46:02.0139 4888 C:\Windows\SysWOW64\dnsapi.dll - ok
    23:46:02.0141 4888 [ 7CD424F005ED71204DCB14CF11F1EB0C ] C:\Windows\SysWOW64\rasadhlp.dll
    23:46:02.0141 4888 C:\Windows\SysWOW64\rasadhlp.dll - ok
    23:46:02.0143 4888 [ C4729C10C3D9E1517EFF2C7AAE72E819 ] C:\Windows\System32\gameux.dll
    23:46:02.0143 4888 C:\Windows\System32\gameux.dll - ok
    23:46:02.0145 4888 [ 8620189836543C2A0435BF37C864BCEE ] C:\Windows\System32\twinui.dll
    23:46:02.0145 4888 C:\Windows\System32\twinui.dll - ok
    23:46:02.0147 4888 [ 0671A791C292F46423CFE37B53D598D0 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFileScanLibrary.dll
    23:46:02.0147 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFileScanLibrary.dll - ok
    23:46:02.0149 4888 [ 9C2543A7AC524CAA63B26A16D4E3AD39 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl
    23:46:02.0149 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl - ok
    23:46:02.0151 4888 [ 70C3B722AE97E6C6A144EC20E5D7C080 ] C:\Windows\System32\windows.immersiveshell.serviceprovider.dll
    23:46:02.0151 4888 C:\Windows\System32\windows.immersiveshell.serviceprovider.dll - ok
    23:46:02.0153 4888 [ 5422CB64444C33F029483552A8FACE37 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\vclx150.bpl
    23:46:02.0153 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\vclx150.bpl - ok
    23:46:02.0155 4888 [ AEB9DD47B76075B05E27874384544F39 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\vclie150.bpl
    23:46:02.0155 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\vclie150.bpl - ok
    23:46:02.0158 4888 [ 1D2BF8A373546ADA00F09DC7496B86AB ] C:\Windows\System32\wpncore.dll
    23:46:02.0158 4888 C:\Windows\System32\wpncore.dll - ok
    23:46:02.0160 4888 [ F0814D492176F8A4FD49D852D2AD748E ] C:\Windows\System32\sppc.dll
    23:46:02.0160 4888 C:\Windows\System32\sppc.dll - ok
    23:46:02.0163 4888 [ FAD9807ACDE89A34D2EB4743D57016D7 ] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDAdvancedCheckLibrary.dll
    23:46:02.0163 4888 C:\Program Files (x86)\Spybot - Search & Destroy 2\SDAdvancedCheckLibrary.dll - ok
    23:46:02.0166 4888 [ F146E2BA475893DD77B2370DC1211FC6 ] C:\Windows\System32\Drivers\37585510.sys
    23:46:02.0166 4888 C:\Windows\System32\Drivers\37585510.sys - ok
    23:46:02.0167 4888 [ FCD59C405ADFADAC1B0729C580F7F70C ] C:\Windows\System32\wlidprov.dll
    23:46:02.0167 4888 C:\Windows\System32\wlidprov.dll - ok
    23:46:02.0169 4888 [ FF4135424A79DCC2998276D8E39C9B4D ] C:\Windows\System32\TimeBrokerServer.dll
    23:46:02.0169 4888 C:\Windows\System32\TimeBrokerServer.dll - ok
    23:46:02.0171 4888 [ 9C0502C5E747C8011D700DCA681A55A1 ] C:\Windows\System32\ELSCore.dll
    23:46:02.0171 4888 C:\Windows\System32\ELSCore.dll - ok
    23:46:02.0174 4888 [ E219BF7BCCFE4881B0C053C7E0B47ECC ] C:\Windows\System32\SystemEventsBrokerServer.dll
    23:46:02.0174 4888 C:\Windows\System32\SystemEventsBrokerServer.dll - ok
    23:46:02.0175 4888 [ 9314C83DE37182685C788FCA3CEC43A4 ] C:\Windows\System32\thumbcache.dll
    23:46:02.0175 4888 C:\Windows\System32\thumbcache.dll - ok
    23:46:02.0177 4888 [ A0F844B0E9ADACA064B832CAF0AEE338 ] C:\Windows\System32\elsTrans.dll
    23:46:02.0177 4888 C:\Windows\System32\elsTrans.dll - ok
    23:46:02.0179 4888 [ DCB7509F83B2A2089DBE07DDEDB52017 ] C:\Windows\System32\WinTypes.dll
    23:46:02.0179 4888 C:\Windows\System32\WinTypes.dll - ok
    23:46:02.0181 4888 [ F6F335A35D54FF8A55D15FA35E0F7671 ] C:\Windows\System32\elslad.dll
    23:46:02.0181 4888 C:\Windows\System32\elslad.dll - ok
    23:46:02.0183 4888 [ 09D886BA5A4BCC31079A2B12980CCF50 ] C:\Windows\SysWOW64\msi.dll
    23:46:02.0183 4888 C:\Windows\SysWOW64\msi.dll - ok
    23:46:02.0185 4888 [ 843D5C2D3032631E400E3ACD1F06312E ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe
    23:46:02.0185 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\LiveComm.exe - ok
    23:46:02.0187 4888 [ 15AC3A854C3DD59DFD11EEE2FF63C79A ] C:\Windows\SysWOW64\riched20.dll
    23:46:02.0187 4888 C:\Windows\SysWOW64\riched20.dll - ok
    23:46:02.0189 4888 [ C4A6771ABE5F9B2B9B5876175F14E61A ] C:\Windows\SysWOW64\msls31.dll
    23:46:02.0189 4888 C:\Windows\SysWOW64\msls31.dll - ok
    23:46:02.0191 4888 [ BC9503A901A545FAD807909F8C86B286 ] C:\Windows\SysWOW64\usp10.dll
    23:46:02.0191 4888 C:\Windows\SysWOW64\usp10.dll - ok
    23:46:02.0192 4888 [ 48067CB53E31B98A394CB12024F26D1B ] C:\Windows\System32\Windows.Globalization.Fontgroups.dll
    23:46:02.0193 4888 C:\Windows\System32\Windows.Globalization.Fontgroups.dll - ok
    23:46:02.0194 4888 [ 074223C4D8109C016B5864DEBF356BD8 ] C:\Windows\SysWOW64\ExplorerFrame.dll
     
  12. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    23:46:02.0194 4888 C:\Windows\SysWOW64\ExplorerFrame.dll - ok
    23:46:02.0197 4888 [ 5EFD801A12FB267405B24945012F5E1A ] C:\Windows\System32\linkinfo.dll
    23:46:02.0197 4888 C:\Windows\System32\linkinfo.dll - ok
    23:46:02.0198 4888 [ FE4D3F3C0F40B9CF957091847704D22E ] C:\Windows\SysWOW64\duser.dll
    23:46:02.0198 4888 C:\Windows\SysWOW64\duser.dll - ok
    23:46:02.0200 4888 [ FB11241B62F07C9FFE664610E262C528 ] C:\Windows\SysWOW64\dui70.dll
    23:46:02.0200 4888 C:\Windows\SysWOW64\dui70.dll - ok
    23:46:02.0202 4888 [ D86F25F0AD6CA6E77A9F67641EEB6722 ] C:\Program Files\Internet Explorer\sqmapi.dll
    23:46:02.0202 4888 C:\Program Files\Internet Explorer\sqmapi.dll - ok
    23:46:02.0204 4888 [ 638407A6996B1DD4CB7BB979B8C260DE ] C:\Windows\System32\Windows.Networking.Connectivity.dll
    23:46:02.0204 4888 C:\Windows\System32\Windows.Networking.Connectivity.dll - ok
    23:46:02.0206 4888 [ 4E6C0D003B381CC109A50794A2F1A222 ] C:\Windows\System32\stobject.dll
    23:46:02.0206 4888 C:\Windows\System32\stobject.dll - ok
    23:46:02.0207 4888 [ F7C576B31DD1D18E8C45A43AE807C5F5 ] C:\Windows\System32\ThumbnailExtractionHost.exe
    23:46:02.0207 4888 C:\Windows\System32\ThumbnailExtractionHost.exe - ok
    23:46:02.0209 4888 [ 44F388C294370B255F7EB751939BD6E3 ] C:\Windows\System32\wpnprv.dll
    23:46:02.0209 4888 C:\Windows\System32\wpnprv.dll - ok
    23:46:02.0211 4888 [ D12BEB5E114701442F1FAA92A739E60E ] C:\Windows\System32\prnfldr.dll
    23:46:02.0211 4888 C:\Windows\System32\prnfldr.dll - ok
    23:46:02.0214 4888 [ 5F59C3E414CC8A05FFB4D86FFCB13CD4 ] C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll
    23:46:02.0214 4888 C:\Windows\System32\Windows.Security.Authentication.OnlineId.dll - ok
    23:46:02.0216 4888 [ 907C4782AA98A587EAA50D830FFC246C ] C:\Windows\System32\DeviceSetupManagerAPI.dll
    23:46:02.0216 4888 C:\Windows\System32\DeviceSetupManagerAPI.dll - ok
    23:46:02.0218 4888 [ 7ECD8DF63A762BDE3F481BC4239FB9AB ] C:\Windows\System32\shdocvw.dll
    23:46:02.0218 4888 C:\Windows\System32\shdocvw.dll - ok
    23:46:02.0221 4888 [ 83A075C07425E84ACC6687FFF7126930 ] C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll
    23:46:02.0221 4888 C:\Windows\System32\Windows.Networking.Sockets.PushEnabledApplication.dll - ok
    23:46:02.0224 4888 [ CE0BD323EB9BDFD140271E550CBA4111 ] C:\Windows\System32\TimeBrokerClient.dll
    23:46:02.0224 4888 C:\Windows\System32\TimeBrokerClient.dll - ok
    23:46:02.0226 4888 [ DD236E26397C1C79D55684F5A72E1C3C ] C:\Windows\System32\PhotoMetadataHandler.dll
    23:46:02.0226 4888 C:\Windows\System32\PhotoMetadataHandler.dll - ok
    23:46:02.0228 4888 [ 7FD32D1A763D8BDF3A142C99FC21D232 ] C:\Windows\System32\AudioSes.dll
    23:46:02.0228 4888 C:\Windows\System32\AudioSes.dll - ok
    23:46:02.0230 4888 [ 4215C49E751ECA4BC42B3C10C8A55950 ] C:\Windows\System32\ncryptsslp.dll
    23:46:02.0230 4888 C:\Windows\System32\ncryptsslp.dll - ok
    23:46:02.0231 4888 [ F6E06380D717875F6AEFC2B0694B9E9D ] C:\Windows\System32\ncryptprov.dll
    23:46:02.0231 4888 C:\Windows\System32\ncryptprov.dll - ok
    23:46:02.0233 4888 [ 0515FF4F49057EDE5FAAB6537D26D5EB ] C:\Windows\System32\dssenh.dll
    23:46:02.0233 4888 C:\Windows\System32\dssenh.dll - ok
    23:46:02.0235 4888 [ 7C3B449F661D99A9B1033A14033D2987 ] C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\msvcr110.dll
    23:46:02.0235 4888 C:\Program Files\WindowsApps\Microsoft.VCLibs.110.00_11.0.51106.1_x64__8wekyb3d8bbwe\msvcr110.dll - ok
    23:46:02.0237 4888 [ 259C9486E06C16BF1BC36CAE784FDFDE ] C:\Windows\System32\WWanAPI.dll
    23:46:02.0237 4888 C:\Windows\System32\WWanAPI.dll - ok
    23:46:02.0238 4888 [ DC12FF4A1B00CAE279D5744F36B74873 ] C:\Windows\System32\wwapi.dll
    23:46:02.0238 4888 C:\Windows\System32\wwapi.dll - ok
    23:46:02.0240 4888 [ 043B150DA8B3559BD7AE701D3496D232 ] C:\Windows\System32\DXP.dll
    23:46:02.0240 4888 C:\Windows\System32\DXP.dll - ok
    23:46:02.0242 4888 [ 5A5E57A0E1D3674AE9ADBC9CAD80428D ] C:\Windows\System32\Syncreg.dll
    23:46:02.0242 4888 C:\Windows\System32\Syncreg.dll - ok
    23:46:02.0244 4888 [ EB003CF63697C3B6AFA9CF769759A5B2 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\wllog.dll
    23:46:02.0244 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\wllog.dll - ok
    23:46:02.0246 4888 [ F98FAED087C12A4D94D6ECDA0618C918 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Service.dll
    23:46:02.0246 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Service.dll - ok
    23:46:02.0248 4888 [ E9B9C28A237D8FEF1FCD2C0D08E7D3C4 ] C:\Windows\System32\upnp.dll
    23:46:02.0248 4888 C:\Windows\System32\upnp.dll - ok
    23:46:02.0250 4888 [ CB7242A05FFD365BBBBE102D24786DEE ] C:\Windows\System32\Windows.Storage.ApplicationData.dll
    23:46:02.0250 4888 C:\Windows\System32\Windows.Storage.ApplicationData.dll - ok
    23:46:02.0251 4888 [ 86F869D43E6E998466538A1DF0D1E6D7 ] C:\Windows\System32\drttransport.dll
    23:46:02.0251 4888 C:\Windows\System32\drttransport.dll - ok
    23:46:02.0253 4888 [ BFABA02A0EA273980BA69DA07483737E ] C:\Windows\System32\drt.dll
    23:46:02.0253 4888 C:\Windows\System32\drt.dll - ok
    23:46:02.0255 4888 [ 923260FAA0F64A90FA63F7EAC08881AF ] C:\Windows\System32\AltTab.dll
    23:46:02.0255 4888 C:\Windows\System32\AltTab.dll - ok
    23:46:02.0257 4888 [ D240CBB72679D6B4B5B07619F0A07F06 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\shared\bici.dll
    23:46:02.0257 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\shared\bici.dll - ok
    23:46:02.0261 4888 [ 3E4CC1E808A0FC8F487036349F4E6810 ] C:\Windows\System32\threadpoolwinrt.dll
    23:46:02.0261 4888 C:\Windows\System32\threadpoolwinrt.dll - ok
    23:46:02.0263 4888 [ 797769FC191B03A01661CB5F855CFD30 ] C:\Windows\System32\biwinrt.dll
    23:46:02.0263 4888 C:\Windows\System32\biwinrt.dll - ok
    23:46:02.0265 4888 [ 56C91F36ADE867F0EDFE0BC6179AC2BC ] C:\Windows\System32\WPDShServiceObj.dll
    23:46:02.0265 4888 C:\Windows\System32\WPDShServiceObj.dll - ok
    23:46:02.0267 4888 [ AC89ADD10CDAC8D5647928FBE5B94621 ] C:\Windows\System32\PortableDeviceTypes.dll
    23:46:02.0267 4888 C:\Windows\System32\PortableDeviceTypes.dll - ok
    23:46:02.0268 4888 [ 4681211F6D66604F34646FA6EB84D989 ] C:\Program Files\Windows Portable Devices\sqmapi.dll
    23:46:02.0268 4888 C:\Program Files\Windows Portable Devices\sqmapi.dll - ok
    23:46:02.0270 4888 [ B5198D9837E0EC371EF0D3F5BE423C61 ] C:\Windows\System32\SettingMonitor.dll
    23:46:02.0270 4888 C:\Windows\System32\SettingMonitor.dll - ok
    23:46:02.0272 4888 [ 797119E1F2752761610CDAA02CC472A3 ] C:\Windows\System32\IME\SHARED\IMEROAMING.DLL
    23:46:02.0272 4888 C:\Windows\System32\IME\SHARED\IMEROAMING.DLL - ok
    23:46:02.0274 4888 [ AAB25C7F73532849DE843C563BADA8CF ] C:\Windows\System32\PackageStateRoaming.dll
    23:46:02.0274 4888 C:\Windows\System32\PackageStateRoaming.dll - ok
    23:46:02.0276 4888 [ A084CB0B1898CE603EEF210DF7C13C2D ] C:\Windows\System32\pnidui.dll
    23:46:02.0276 4888 C:\Windows\System32\pnidui.dll - ok
    23:46:02.0277 4888 [ 4B5A42E0FDD2012B6940CC14F447E8D8 ] C:\Windows\System32\NcaApi.dll
    23:46:02.0277 4888 C:\Windows\System32\NcaApi.dll - ok
    23:46:02.0279 4888 [ 5BB92B4A3DDB7FB2D9085F7F7A771512 ] C:\Windows\System32\ieframe.dll
    23:46:02.0279 4888 C:\Windows\System32\ieframe.dll - ok
    23:46:02.0282 4888 [ 0208CAE5E09FA01DA2649702AE9616F6 ] C:\Windows\System32\srchadmin.dll
    23:46:02.0282 4888 C:\Windows\System32\srchadmin.dll - ok
    23:46:02.0284 4888 [ E7BE2296105069DA0C8F9206F070C6EF ] C:\Windows\System32\SearchIndexer.exe
    23:46:02.0284 4888 C:\Windows\System32\SearchIndexer.exe - ok
    23:46:02.0285 4888 [ AAA384C8F6412103973518D60FCEAAD0 ] C:\Windows\System32\bthprops.cpl
    23:46:02.0285 4888 C:\Windows\System32\bthprops.cpl - ok
    23:46:02.0287 4888 [ D8DCEE270674DDB6503730CC4C2F1691 ] C:\Windows\System32\BluetoothApis.dll
    23:46:02.0287 4888 C:\Windows\System32\BluetoothApis.dll - ok
    23:46:02.0289 4888 [ 7CEE52B25CA677E5B62DC00E3BD3BBCE ] C:\Windows\System32\ActionCenter.dll
    23:46:02.0289 4888 C:\Windows\System32\ActionCenter.dll - ok
    23:46:02.0291 4888 [ D9309C43C47D40315585871D9C6FED3C ] C:\Windows\System32\tquery.dll
    23:46:02.0291 4888 C:\Windows\System32\tquery.dll - ok
    23:46:02.0293 4888 [ 78E10345A0A592BDDACFB40EB8444B5B ] C:\Windows\System32\mssrch.dll
    23:46:02.0293 4888 C:\Windows\System32\mssrch.dll - ok
    23:46:02.0295 4888 [ 94F97611FFCFF810BF8CB0D467BADA60 ] C:\Windows\System32\msidle.dll
    23:46:02.0295 4888 C:\Windows\System32\msidle.dll - ok
    23:46:02.0296 4888 [ C3C9A444FA26DB4B993AE3DA6C3DD683 ] C:\Windows\System32\mssprxy.dll
    23:46:02.0296 4888 C:\Windows\System32\mssprxy.dll - ok
    23:46:02.0298 4888 [ CF4657A43B56ED26875C26DFE698DCCB ] C:\Windows\System32\SearchProtocolHost.exe
    23:46:02.0298 4888 C:\Windows\System32\SearchProtocolHost.exe - ok
    23:46:02.0300 4888 [ 924DAF97890A77590835B83E53CEC382 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.dll
    23:46:02.0300 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.dll - ok
    23:46:02.0302 4888 [ 16B0D0C1D0CFDB8F5F3DE9849487B509 ] C:\Windows\System32\SyncCenter.dll
    23:46:02.0302 4888 C:\Windows\System32\SyncCenter.dll - ok
    23:46:02.0303 4888 [ 255F0624A5A33EBB0FC545BDD2A9CB36 ] C:\Windows\System32\msshooks.dll
    23:46:02.0304 4888 C:\Windows\System32\msshooks.dll - ok
    23:46:02.0305 4888 [ 805AD714EF4126BE2D2390D446CA4280 ] C:\Windows\System32\imapi2.dll
    23:46:02.0305 4888 C:\Windows\System32\imapi2.dll - ok
    23:46:02.0307 4888 [ EC65798B20CF6B9D9581B0F896A72AB2 ] C:\Windows\System32\SearchFilterHost.exe
    23:46:02.0307 4888 C:\Windows\System32\SearchFilterHost.exe - ok
    23:46:02.0309 4888 [ 2EBA0464A93CA18F50269DC10CEB3CFE ] C:\Windows\System32\mssph.dll
    23:46:02.0309 4888 C:\Windows\System32\mssph.dll - ok
    23:46:02.0311 4888 [ B16BA8C18B51D0FDF120B1ED4E07C399 ] C:\Windows\System32\hgcpl.dll
    23:46:02.0311 4888 C:\Windows\System32\hgcpl.dll - ok
    23:46:02.0312 4888 [ D7507B2F96098C43D1BC835F8B8E5E8E ] C:\Windows\System32\mapi32.dll
    23:46:02.0312 4888 C:\Windows\System32\mapi32.dll - ok
    23:46:02.0314 4888 [ 30454C0337F045E79C2906E9DC039CC5 ] C:\Windows\System32\RuntimeBroker.exe
    23:46:02.0314 4888 C:\Windows\System32\RuntimeBroker.exe - ok
    23:46:02.0316 4888 [ 45005B77B9DACCE166D44ADA87240325 ] C:\Windows\System32\Windows.ApplicationModel.dll
    23:46:02.0316 4888 C:\Windows\System32\Windows.ApplicationModel.dll - ok
    23:46:02.0318 4888 [ AE216A0329FAC7804DC4DFEA49254F0D ] C:\Windows\System32\ntshrui.dll
    23:46:02.0318 4888 C:\Windows\System32\ntshrui.dll - ok
    23:46:02.0319 4888 [ 7308CF302FAD17A77A2EB87ACE9185E0 ] C:\Windows\System32\networkexplorer.dll
    23:46:02.0319 4888 C:\Windows\System32\networkexplorer.dll - ok
    23:46:02.0321 4888 [ 520C138EB08059060D30C92BE5F817FE ] C:\Windows\System32\msiltcfg.dll
    23:46:02.0321 4888 C:\Windows\System32\msiltcfg.dll - ok
    23:46:02.0323 4888 [ DA3021EFAC1D185AC725AFCCD3398521 ] C:\Windows\System32\msi.dll
    23:46:02.0323 4888 C:\Windows\System32\msi.dll - ok
    23:46:02.0325 4888 [ 2C63A256E18DA5CE4504A26C77691887 ] C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL
    23:46:02.0325 4888 C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL - ok
    23:46:02.0327 4888 [ 53A3DE22A97A40469FC6AEB54A151A61 ] C:\Windows\System32\atl100.dll
    23:46:02.0327 4888 C:\Windows\System32\atl100.dll - ok
    23:46:02.0329 4888 [ 7FA6470C89F68656D0D86A59177273CD ] C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    23:46:02.0329 4888 C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll - ok
    23:46:02.0331 4888 [ 8F6A65D15A0CB3653E2CA3A3B937F6B6 ] C:\Windows\System32\EhStorShell.dll
    23:46:02.0331 4888 C:\Windows\System32\EhStorShell.dll - ok
    23:46:02.0333 4888 [ DA5A90BB728583D7A5988D3C5D67EB64 ] C:\Windows\System32\mfsrcsnk.dll
    23:46:02.0333 4888 C:\Windows\System32\mfsrcsnk.dll - ok
    23:46:02.0335 4888 [ 0ABA7E925E54A222331B16BEF25A5958 ] C:\Program Files (x86)\Google\Drive\googledrivesync64.dll
    23:46:02.0335 4888 C:\Program Files (x86)\Google\Drive\googledrivesync64.dll - ok
    23:46:02.0337 4888 [ 1717CE7906AB980501948CEC53DFF636 ] C:\Windows\System32\mfplat.dll
    23:46:02.0337 4888 C:\Windows\System32\mfplat.dll - ok
    23:46:02.0339 4888 [ F8DA5BD9CDAA3B49A253F72843D9B869 ] C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcp90.dll
    23:46:02.0339 4888 C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcp90.dll - ok
    23:46:02.0341 4888 [ D876B344E40D4B4960C4B0FE1EE1A884 ] C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcr90.dll
    23:46:02.0341 4888 C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6871_none_08e717a5a83adddf\msvcr90.dll - ok
    23:46:02.0343 4888 [ B447650079883B58626DD6BBAE857877 ] C:\Windows\System32\NaturalLanguage6.dll
    23:46:02.0343 4888 C:\Windows\System32\NaturalLanguage6.dll - ok
    23:46:02.0345 4888 [ 49E2346A397A7512DD9D12E1D6D9A174 ] C:\Windows\System32\NlsData0009.dll
    23:46:02.0345 4888 C:\Windows\System32\NlsData0009.dll - ok
    23:46:02.0346 4888 [ 47DCA6F50C1D1E93F4DB5248557ED63C ] C:\Windows\System32\NlsLexicons0009.dll
    23:46:02.0346 4888 C:\Windows\System32\NlsLexicons0009.dll - ok
    23:46:02.0348 4888 [ 7BBA721129208393DD4E9F34C01B37AD ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Shared.Market.dll
    23:46:02.0348 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Shared.Market.dll - ok
    23:46:02.0350 4888 [ AEE89C0F144223B97EEDBAAE41CE181A ] C:\Windows\System32\wpnapps.dll
    23:46:02.0350 4888 C:\Windows\System32\wpnapps.dll - ok
    23:46:02.0352 4888 [ 38175536133BDC9324910582250CB8DD ] C:\Windows\System32\taskeng.exe
    23:46:02.0352 4888 C:\Windows\System32\taskeng.exe - ok
    23:46:02.0354 4888 [ BC61E429D78796F292D5E9A71C3A967F ] C:\Windows\System32\TSChannel.dll
    23:46:02.0354 4888 C:\Windows\System32\TSChannel.dll - ok
    23:46:02.0356 4888 [ 506708142BC63DABA64F2D3AD1DCD5BF ] C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    23:46:02.0356 4888 C:\Program Files (x86)\Google\Update\GoogleUpdate.exe - ok
    23:46:02.0358 4888 [ F3D0469E044672E6C57ABBEFDCE6CC85 ] C:\Windows\System32\netshell.dll
    23:46:02.0358 4888 C:\Windows\System32\netshell.dll - ok
    23:46:02.0360 4888 [ 07F7AE68602448F4B6D5A9A40BBA977C ] C:\Program Files (x86)\Google\Update\1.3.21.124\goopdate.dll
    23:46:02.0360 4888 C:\Program Files (x86)\Google\Update\1.3.21.124\goopdate.dll - ok
    23:46:02.0363 4888 [ E4B3CE98A6DBE4B609133C045D2C8525 ] C:\Windows\SysWOW64\cscapi.dll
    23:46:02.0363 4888 C:\Windows\SysWOW64\cscapi.dll - ok
    23:46:02.0365 4888 [ 5125C1F27F8537F33076D0C0151F6B7F ] C:\Windows\SysWOW64\dbghelp.dll
    23:46:02.0365 4888 C:\Windows\SysWOW64\dbghelp.dll - ok
    23:46:02.0367 4888 [ AE5A69F44C1F97EDC83237FC0B29B6FB ] C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe
    23:46:02.0367 4888 C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler.exe - ok
    23:46:02.0369 4888 [ 41938F2C1642459CBBA691B5DBD6395A ] C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler64.exe
    23:46:02.0369 4888 C:\Program Files (x86)\Google\Update\1.3.21.124\GoogleCrashHandler64.exe - ok
    23:46:02.0370 4888 [ D635063008E82F77E9E4563F4C987DDD ] C:\Windows\SysWOW64\mstask.dll
    23:46:02.0370 4888 C:\Windows\SysWOW64\mstask.dll - ok
    23:46:02.0372 4888 [ 649C7C38E573F1ACD68E23C0EDC941A4 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Calendar.dll
    23:46:02.0372 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Calendar.dll - ok
    23:46:02.0374 4888 [ 866A50DD5376C6DE69A09471CE44A173 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Eas.dll
    23:46:02.0374 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.Eas.dll - ok
    23:46:02.0376 4888 [ 68A793E65ABDB4FC74D5975AA7761968 ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\ModernChat\app\Components\ConversationSystem\Dll\Microsoft.WindowsLive.Chat.ChatSystem.dll
    23:46:02.0376 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\ModernChat\app\Components\ConversationSystem\Dll\Microsoft.WindowsLive.Chat.ChatSystem.dll - ok
    23:46:02.0378 4888 [ CC47BA87C1929948D737876AD7F79C5E ] C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.PresenceIM.dll
    23:46:02.0378 4888 C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16.4.4406.1205_x64__8wekyb3d8bbwe\Microsoft.WindowsLive.Platform.PresenceIM.dll - ok
    23:46:02.0380 4888 [ 37360B977F4711E694D99F9EC8BC4049 ] C:\Windows\System32\AuthBroker.dll
    23:46:02.0380 4888 C:\Windows\System32\AuthBroker.dll - ok
    23:46:02.0382 4888 [ 88A4A2C413BAA86B774D727B05F3FA15 ] C:\Windows\System32\profext.dll
    23:46:02.0382 4888 C:\Windows\System32\profext.dll - ok
    23:46:02.0383 4888 ============================================================
    23:46:02.0383 4888 Scan finished
    23:46:02.0383 4888 ============================================================
    23:46:02.0387 4880 Detected object count: 1
    23:46:02.0388 4880 Actual detected object count: 1
    23:47:06.0084 4880 C:\Program Files (x86)\WinPcap\rpcapd.exe - copied to quarantine
    23:47:06.0084 4880 HKLM\SYSTEM\ControlSet001\services\rpcapd - will be deleted on reboot
    23:47:06.0096 4880 C:\Program Files (x86)\WinPcap\rpcapd.exe - will be deleted on reboot
    23:47:06.0096 4880 rpcapd ( UnsignedFile.Multi.Generic ) - User select action: Delete
     
  13. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    Are there few more lines or that's it?
     
  14. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    That was it.
     
  15. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    =========================

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.

    =========================

    Download OTL to your Desktop.
    Alternate download: http://www.itxassociates.com/OT-Tools/OTL.exe

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Click the Scan All Users checkbox.
    • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
     
  16. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    # AdwCleaner v2.105 - Logfile created 01/14/2013 at 00:02:33
    # Updated 08/01/2013 by Xplode
    # Operating system : Windows 8 (64 bits)
    # User : DJ - PARKER
    # Boot Mode : Normal
    # Running from : C:\Users\DJ\Desktop\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****


    ***** [Files / Folders] *****

    Folder Deleted : C:\Program Files (x86)\Conduit
    Folder Deleted : C:\Program Files (x86)\uTorrentControl_v2
    Folder Deleted : C:\Users\DJ\AppData\Local\Conduit
    Folder Deleted : C:\Users\DJ\AppData\LocalLow\Conduit
    Folder Deleted : C:\Users\DJ\AppData\LocalLow\uTorrentControl_v2

    ***** [Registry] *****

    Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
    Key Deleted : HKCU\Software\AppDataLow\Software\Crossrider
    Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
    Key Deleted : HKCU\Software\AppDataLow\Software\uTorrentControl_v2
    Key Deleted : HKCU\Software\AppDataLow\Toolbar
    Key Deleted : HKCU\Software\Conduit
    Key Deleted : HKCU\Software\Cr_Installer
    Key Deleted : HKCU\Software\InstalledBrowserExtensions
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKCU\Software\Softonic
    Key Deleted : HKCU\Software\uTorrentControl_v2
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.BHO
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.BHO.1
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.Sandbox
    Key Deleted : HKLM\SOFTWARE\Classes\CrossriderApp0021804.Sandbox.1
    Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3220468
    Key Deleted : HKLM\Software\Conduit
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Deleted : HKLM\Software\uTorrentControl_v2
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{537F4F0B-3542-4C7D-A3E5-CF121482696C}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\mkndcbhcgphcfkkddanakjiepeknbgle
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{36CCDB35-EBCC-4FE4-B067-DB960FE780FD}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{683303AA-F768-430D-B852-3A125B4D1832}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7473B6BD-4691-4744-A82B-7854EB3D70B6}
    Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\uTorrentControl_v2 Toolbar
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]
    Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{7473B6BD-4691-4744-A82B-7854EB3D70B6}]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v10.0.9200.16453

    Replaced : [HKCU\Software\Microsoft\Internet Explorer\Main - Start Page] = hxxp://search.conduit.com?SearchSource=10&ctid=CT3220468 --> hxxp://www.google.com

    -\\ Google Chrome v24.0.1312.52

    File : C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Preferences

    Deleted [l.16] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT3220468&SearchSource=48"[...]
    Deleted [l.3355] : urls_to_restore_on_startup = [ "hxxp://search.conduit.com/?ctid=CT3220468&SearchSource=48" ]

    *************************

    AdwCleaner[S1].txt - [3949 octets] - [14/01/2013 00:02:33]

    ########## EOF - C:\AdwCleaner[S1].txt - [4009 octets] ##########
     
  17. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    JRT won't run. I open it, and a command prompt wiindow just opens and closes
     
  18. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    I already disabled AVG
     
  19. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    OTL logfile created on: 1/14/2013 12:13:44 AM - Run 1
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\DJ\Downloads
    64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
    Internet Explorer (Version = 9.10.9200.16453)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    15.96 Gb Total Physical Memory | 13.34 Gb Available Physical Memory | 83.60% Memory free
    18.21 Gb Paging File | 14.95 Gb Available in Paging File | 82.10% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 55.90 Gb Total Space | 13.72 Gb Free Space | 24.55% Space Free | Partition Type: NTFS
    Drive D: | 350.00 Mb Total Space | 297.25 Mb Free Space | 84.93% Space Free | Partition Type: NTFS
    Drive E: | 1396.92 Gb Total Space | 1142.41 Gb Free Space | 81.78% Space Free | Partition Type: NTFS
    Drive G: | 1.91 Gb Total Space | 0.25 Gb Free Space | 12.83% Space Free | Partition Type: FAT

    Computer Name: PARKER | User Name: DJ | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - [2013/01/14 00:13:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\DJ\Downloads\OTL.exe
    PRC - [2013/01/07 19:06:24 | 001,248,360 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    PRC - [2012/12/31 14:12:56 | 001,354,736 | ---- | M] (Valve Corporation) -- E:\Program Files (x86)\Steam\Steam.exe
    PRC - [2012/12/26 10:02:44 | 000,541,760 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    PRC - [2012/12/17 19:50:28 | 016,328,976 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Drive\googledrivesync.exe
    PRC - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
    PRC - [2012/12/14 16:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
    PRC - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
    PRC - [2012/12/11 03:52:44 | 003,147,384 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgui.exe
    PRC - [2012/11/15 23:34:30 | 005,814,904 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
    PRC - [2012/11/13 14:08:08 | 003,825,176 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
    PRC - [2012/11/13 14:07:24 | 000,168,384 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
    PRC - [2012/11/13 14:07:20 | 001,369,624 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
    PRC - [2012/11/13 14:07:16 | 001,103,392 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
    PRC - [2012/10/22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
    PRC - [2012/10/22 13:04:06 | 000,329,848 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2013\avgcfgex.exe


    ========== Modules (No Company Name) ==========

    MOD - [2013/01/14 00:03:58 | 001,169,408 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._core_.pyd
    MOD - [2013/01/14 00:03:58 | 001,056,256 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._controls_.pyd
    MOD - [2013/01/14 00:03:58 | 001,024,616 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\windows._cacheinvalidation.pyd
    MOD - [2013/01/14 00:03:58 | 000,807,424 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._windows_.pyd
    MOD - [2013/01/14 00:03:58 | 000,792,576 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._gdi_.pyd
    MOD - [2013/01/14 00:03:58 | 000,731,136 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._misc_.pyd
    MOD - [2013/01/14 00:03:58 | 000,645,120 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_ssl.pyd
    MOD - [2013/01/14 00:03:58 | 000,585,728 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\unicodedata.pyd
    MOD - [2013/01/14 00:03:58 | 000,571,392 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pysqlite2._sqlite.pyd
    MOD - [2013/01/14 00:03:58 | 000,354,304 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pythoncom26.dll
    MOD - [2013/01/14 00:03:58 | 000,311,808 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_hashlib.pyd
    MOD - [2013/01/14 00:03:58 | 000,263,168 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32com.shell.shell.pyd
    MOD - [2013/01/14 00:03:58 | 000,153,088 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pyexpat.pyd
    MOD - [2013/01/14 00:03:58 | 000,121,856 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._wizard.pyd
    MOD - [2013/01/14 00:03:58 | 000,111,104 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32file.pyd
    MOD - [2013/01/14 00:03:58 | 000,110,592 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32security.pyd
    MOD - [2013/01/14 00:03:58 | 000,110,592 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\pywintypes26.dll
    MOD - [2013/01/14 00:03:58 | 000,096,256 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32api.pyd
    MOD - [2013/01/14 00:03:58 | 000,086,016 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_elementtree.pyd
    MOD - [2013/01/14 00:03:58 | 000,073,728 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_ctypes.pyd
    MOD - [2013/01/14 00:03:58 | 000,070,656 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\wx._html2.pyd
    MOD - [2013/01/14 00:03:58 | 000,040,448 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\_socket.pyd
    MOD - [2013/01/14 00:03:58 | 000,039,424 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32inet.pyd
    MOD - [2013/01/14 00:03:58 | 000,036,352 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32process.pyd
    MOD - [2013/01/14 00:03:58 | 000,023,040 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32ts.pyd
    MOD - [2013/01/14 00:03:58 | 000,022,528 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32pdh.pyd
    MOD - [2013/01/14 00:03:58 | 000,017,920 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32profile.pyd
    MOD - [2013/01/14 00:03:58 | 000,017,920 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32event.pyd
    MOD - [2013/01/14 00:03:58 | 000,011,776 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\win32crypt.pyd
    MOD - [2013/01/14 00:03:58 | 000,011,776 | ---- | M] () -- C:\Users\DJ\AppData\Local\Temp\_MEI43122\select.pyd
    MOD - [2013/01/07 19:06:22 | 000,460,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppgooglenaclpluginchrome.dll
    MOD - [2013/01/07 19:06:21 | 012,459,624 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll
    MOD - [2013/01/07 19:06:19 | 004,012,648 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll
    MOD - [2013/01/07 19:05:29 | 000,598,120 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\libglesv2.dll
    MOD - [2013/01/07 19:05:28 | 000,124,520 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\libegl.dll
    MOD - [2013/01/07 19:05:25 | 001,553,000 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ffmpegsumo.dll
    MOD - [2012/12/31 14:15:47 | 000,647,168 | ---- | M] () -- E:\Program Files (x86)\Steam\sdl.dll
    MOD - [2012/12/26 10:02:43 | 020,320,240 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\libcef.dll
    MOD - [2012/12/26 10:02:43 | 001,100,800 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\avcodec-53.dll
    MOD - [2012/12/26 10:02:43 | 000,969,280 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\chromehtml.dll
    MOD - [2012/12/26 10:02:43 | 000,192,000 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\avformat-53.dll
    MOD - [2012/12/26 10:02:43 | 000,124,416 | ---- | M] () -- E:\Program Files (x86)\Steam\bin\avutil-51.dll
    MOD - [2012/11/13 14:06:32 | 000,158,624 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
    MOD - [2012/11/13 14:06:30 | 000,108,960 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
    MOD - [2012/11/13 14:06:28 | 000,554,400 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl
    MOD - [2012/11/13 14:06:28 | 000,528,288 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl
    MOD - [2012/11/13 14:06:28 | 000,416,160 | ---- | M] () -- C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl


    ========== Services (SafeList) ==========

    SRV:64bit: - [2012/12/05 23:23:00 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
    SRV:64bit: - [2012/12/05 23:22:59 | 000,178,176 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
    SRV:64bit: - [2012/11/05 23:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
    SRV:64bit: - [2012/11/05 23:17:41 | 000,169,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
    SRV:64bit: - [2012/10/18 04:52:28 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
    SRV:64bit: - [2012/09/20 04:10:47 | 002,367,528 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
    SRV:64bit: - [2012/09/20 01:31:18 | 000,116,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
    SRV:64bit: - [2012/09/20 01:30:41 | 000,179,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
    SRV:64bit: - [2012/07/25 22:17:59 | 000,015,440 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
    SRV:64bit: - [2012/07/25 22:08:04 | 001,968,128 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
    SRV:64bit: - [2012/07/25 22:07:47 | 000,065,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
    SRV:64bit: - [2012/07/25 22:07:42 | 000,263,680 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
    SRV:64bit: - [2012/07/25 22:07:40 | 000,283,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
    SRV:64bit: - [2012/07/25 22:07:25 | 000,012,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
    SRV:64bit: - [2012/07/25 22:06:36 | 000,463,872 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
    SRV:64bit: - [2012/07/25 22:06:34 | 000,743,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
    SRV:64bit: - [2012/07/25 22:06:33 | 000,161,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
    SRV:64bit: - [2012/07/25 22:06:33 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
    SRV:64bit: - [2012/07/25 22:06:00 | 000,438,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
    SRV:64bit: - [2012/07/25 22:05:55 | 000,059,904 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
    SRV:64bit: - [2012/07/25 22:05:34 | 000,037,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
    SRV:64bit: - [2012/07/25 22:05:28 | 000,207,872 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
    SRV:64bit: - [2012/07/25 22:05:24 | 000,342,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
    SRV:64bit: - [2012/07/25 22:05:08 | 000,122,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AUInstallAgent.dll -- (AllUserInstallAgent)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
    SRV:64bit: - [2012/07/25 19:24:02 | 000,336,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
    SRV:64bit: - [2012/07/11 13:54:58 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
    SRV - [2013/01/08 17:39:18 | 000,251,400 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
    SRV - [2012/12/26 10:02:44 | 000,541,760 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
    SRV - [2012/12/14 16:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
    SRV - [2012/12/14 16:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- e:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
    SRV - [2012/11/15 23:34:30 | 005,814,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe -- (AVGIDSAgent)
    SRV - [2012/11/09 14:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
    SRV - [2012/11/05 23:36:55 | 002,675,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll -- (PrintNotify)
    SRV - [2012/10/22 13:05:08 | 000,196,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe -- (avgwd)
    SRV - [2012/07/25 22:20:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - [2012/12/14 16:49:28 | 000,024,176 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\Drivers\mbam.sys -- (MBAMProtector)
    DRV:64bit: - [2012/11/27 02:00:32 | 000,194,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdbus.sys -- (sdbus)
    DRV:64bit: - [2012/11/26 23:36:16 | 000,208,736 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgwfpa.sys -- (Avgwfpa)
    DRV:64bit: - [2012/11/26 22:56:29 | 000,031,104 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
    DRV:64bit: - [2012/11/26 22:55:44 | 000,029,952 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\BthhfHid.sys -- (bthhfhid)
    DRV:64bit: - [2012/11/19 23:54:31 | 000,039,936 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hidi2c.sys -- (hidi2c)
    DRV:64bit: - [2012/11/15 23:33:24 | 000,111,968 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgmfx64.sys -- (Avgmfx64)
    DRV:64bit: - [2012/11/06 02:52:07 | 000,445,160 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\USBHUB3.SYS -- (USBHUB3)
    DRV:64bit: - [2012/11/06 02:36:23 | 000,069,864 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\pdc.sys -- (pdc)
    DRV:64bit: - [2012/11/05 22:55:44 | 000,022,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\fxppm.sys -- (FxPPM)
    DRV:64bit: - [2012/10/26 04:17:44 | 000,020,912 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\avgboota.sys -- (Avgboota)
    DRV:64bit: - [2012/10/22 13:02:44 | 000,154,464 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgidsdrivera.sys -- (AVGIDSDriver)
    DRV:64bit: - [2012/10/18 04:52:18 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmdag.sys -- (amdkmdag)
    DRV:64bit: - [2012/10/18 04:52:16 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\atikmpag.sys -- (amdkmdap)
    DRV:64bit: - [2012/10/15 03:48:50 | 000,063,328 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\avgidsha.sys -- (AVGIDSHA)
    DRV:64bit: - [2012/10/12 03:08:01 | 000,027,880 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
    DRV:64bit: - [2012/10/11 02:25:48 | 000,056,552 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\sdstor.sys -- (sdstor)
    DRV:64bit: - [2012/10/11 02:13:49 | 000,058,088 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\Drivers\dam.sys -- (dam)
    DRV:64bit: - [2012/10/02 03:30:38 | 000,185,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgldx64.sys -- (Avgldx64)
    DRV:64bit: - [2012/09/21 03:46:00 | 000,225,120 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\avgloga.sys -- (Avgloga)
    DRV:64bit: - [2012/09/20 02:55:33 | 000,337,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\USBXHCI.SYS -- (USBXHCI)
    DRV:64bit: - [2012/09/20 02:55:33 | 000,212,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\UCX01000.SYS -- (UCX01000)
    DRV:64bit: - [2012/09/20 02:55:30 | 000,120,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpioclx.sys -- (GPIOClx0101)
    DRV:64bit: - [2012/09/20 02:55:29 | 000,028,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\msgpiowin32.sys -- (msgpiowin32)
    DRV:64bit: - [2012/09/20 02:55:27 | 003,265,256 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\evbda.sys -- (ebdrv)
    DRV:64bit: - [2012/09/20 02:55:24 | 000,533,224 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\bxvbda.sys -- (b06bdrv)
    DRV:64bit: - [2012/09/20 02:03:08 | 000,148,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\tpm.sys -- (TPM)
    DRV:64bit: - [2012/09/14 03:05:18 | 000,040,800 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\avgrkx64.sys -- (Avgrkx64)
    DRV:64bit: - [2012/08/21 11:56:38 | 000,091,648 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\AtihdW86.sys -- (AtiHDAudioService)
    DRV:64bit: - [2012/07/26 00:26:46 | 000,025,328 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
    DRV:64bit: - [2012/07/26 00:26:45 | 000,033,792 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\condrv.sys -- (condrv)
    DRV:64bit: - [2012/07/26 00:00:58 | 000,322,800 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\VSTXRAID.SYS -- (VSTXRAID)
    DRV:64bit: - [2012/07/26 00:00:58 | 000,106,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\VerifierExt.sys -- (VerifierExt)
    DRV:64bit: - [2012/07/26 00:00:58 | 000,097,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\uaspstor.sys -- (UASPStor)
    DRV:64bit: - [2012/07/26 00:00:57 | 000,077,040 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\acpiex.sys -- (acpiex)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,283,888 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\spaceport.sys -- (spaceport)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,077,552 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\storahci.sys -- (storahci)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,064,240 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\mvumis.sys -- (mvumis)
    DRV:64bit: - [2012/07/26 00:00:55 | 000,030,960 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\stexstor.sys -- (stexstor)
    DRV:64bit: - [2012/07/26 00:00:52 | 000,092,400 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sas2.sys -- (LSI_SAS2)
    DRV:64bit: - [2012/07/26 00:00:52 | 000,081,136 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\lsi_sss.sys -- (LSI_SSS)
    DRV:64bit: - [2012/07/26 00:00:52 | 000,064,752 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\HpSAMD.sys -- (HpSAMD)
    DRV:64bit: - [2012/07/26 00:00:51 | 000,113,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
    DRV:64bit: - [2012/07/26 00:00:51 | 000,081,136 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\EhStorClass.sys -- (EhStorClass)
    DRV:64bit: - [2012/07/26 00:00:49 | 000,258,288 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsbs.sys -- (amdsbs)
    DRV:64bit: - [2012/07/26 00:00:49 | 000,106,736 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\3ware.sys -- (3ware)
    DRV:64bit: - [2012/07/26 00:00:49 | 000,076,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdsata.sys -- (amdsata)
    DRV:64bit: - [2012/07/26 00:00:48 | 000,026,352 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\Drivers\amdxata.sys -- (amdxata)
    DRV:64bit: - [2012/07/25 23:57:54 | 000,361,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\clfs.sys -- (CLFS)
    DRV:64bit: - [2012/07/25 23:54:34 | 000,096,496 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\wfplwfs.sys -- (WFPLWFS)
    DRV:64bit: - [2012/07/25 23:53:16 | 000,067,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vpci.sys -- (vpci)
    DRV:64bit: - [2012/07/25 23:44:30 | 000,258,288 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdFilter.sys -- (WdFilter)
    DRV:64bit: - [2012/07/25 23:36:15 | 000,034,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WdBoot.sys -- (WdBoot)
    DRV:64bit: - [2012/07/25 22:17:38 | 000,036,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\terminpt.sys -- (terminpt)
    DRV:64bit: - [2012/07/25 21:29:14 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mshidumdf.sys -- (mshidumdf)
    DRV:64bit: - [2012/07/25 21:29:08 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicDisplay.sys -- (BasicDisplay)
    DRV:64bit: - [2012/07/25 21:29:03 | 000,024,576 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\HyperVideo.sys -- (HyperVideo)
    DRV:64bit: - [2012/07/25 21:28:52 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\BasicRender.sys -- (BasicRender)
    DRV:64bit: - [2012/07/25 21:27:58 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\vmgencounter.sys -- (gencounter)
    DRV:64bit: - [2012/07/25 21:27:41 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\kdnic.sys -- (kdnic)
    DRV:64bit: - [2012/07/25 21:27:37 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpitime.sys -- (acpitime)
    DRV:64bit: - [2012/07/25 21:27:33 | 000,023,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\npsvctrig.sys -- (npsvctrig)
    DRV:64bit: - [2012/07/25 21:27:29 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
    DRV:64bit: - [2012/07/25 21:27:16 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\acpipagr.sys -- (acpipagr)
    DRV:64bit: - [2012/07/25 21:27:01 | 000,011,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\hyperkbd.sys -- (hyperkbd)
    DRV:64bit: - [2012/07/25 21:26:46 | 000,062,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SerCx.sys -- (SerCx)
    DRV:64bit: - [2012/07/25 21:26:43 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\SpbCx.sys -- (SpbCx)
    DRV:64bit: - [2012/07/25 21:26:34 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbGD.sys -- (TsUsbGD)
    DRV:64bit: - [2012/07/25 21:26:13 | 000,051,200 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\bthhfenum.sys -- (BthHFEnum)
    DRV:64bit: - [2012/07/25 21:25:57 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\dmvsc.sys -- (dmvsc)
    DRV:64bit: - [2012/07/25 21:25:56 | 000,057,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
    DRV:64bit: - [2012/07/25 21:25:13 | 000,045,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\wpcfltr.sys -- (wpcfltr)
    DRV:64bit: - [2012/07/25 21:25:01 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
    DRV:64bit: - [2012/07/25 21:23:53 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\mslldp.sys -- (MsLldp)
    DRV:64bit: - [2012/07/25 21:23:42 | 000,097,792 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\Drivers\Ndu.sys -- (Ndu)
    DRV:64bit: - [2012/06/02 09:31:56 | 000,589,824 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\Rt630x64.sys -- (RTL8168)
    DRV:64bit: - [2012/05/22 14:53:16 | 000,694,416 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RTL8192su.sys -- (RTL8192su)
    DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
    DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
    DRV:64bit: - [2010/10/20 02:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\HECIx64.sys -- (MEIx64)
    DRV - [2003/04/04 15:07:20 | 000,030,336 | ---- | M] (Politecnico di Torino) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\npf.sys -- (NPF)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========
     
  20. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    IE - HKLM\..\SearchScopes,DefaultScope =
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


    IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

    IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://t.msn.com/
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DC 2A 58 E8 5A E9 CD 01 [binary data]
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\..\SearchScopes,DefaultScope =
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE10SR
    IE - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


    ========== FireFox ==========

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_146.dll File not found
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
    FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
    FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
    FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\DJ\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\DJ\AppData\Local\Google\Update\1.3.21.124\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\pokki.com/PokkiDownloadHelper: C:\Users\DJ\AppData\Local\Pokki\Download Helper\npPokkiDownloadHelper.1.2.0.78.dll (Pokki)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}: C:\Program Files (x86)\RelevantKnowledge\firefox

    [2013/01/03 07:28:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\DJ\AppData\Roaming\mozilla\Firefox\extensions
    [2013/01/03 07:28:28 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\DJ\AppData\Roaming\mozilla\Firefox\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
    [2012/10/01 20:43:54 | 000,034,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll

    ========== Chrome ==========

    CHR - default_search_provider: Google (Enabled)
    CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:eek:riginalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
    CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter},
    CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll
    CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
    CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll
    CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.52\pdf.dll
    CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
    CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\DJ\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
    CHR - plugin: Microsoft Office 2013 (Enabled) = C:\PROGRA~2\MICROS~3\Office15\NPSPWRAP.DLL
    CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.124\npGoogleUpdate3.dll
    CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
    CHR - plugin: Microsoft Office 2013 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
    CHR - plugin: Pokki Download Helper (Enabled) = C:\Users\DJ\AppData\Local\Pokki\Download Helper\npPokkiDownloadHelper.1.2.0.78.dll
    CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_146.dll
    CHR - plugin: Java Deployment Toolkit 7.0.100.18 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
    CHR - Extension: No Hulu Ads = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdjcidbbokfiifpnpcglbehanlligmlh\1.3.5_0\
    CHR - Extension: Strict Pomodoro = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgmnfnmlficgeijcalkgnnkigkefkbhd\1.5.0.5_0\
    CHR - Extension: Facebook Courage Wolf = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmfejcfgfpcifgkniepcdakpiplpjgam\0.0.0.2_0\
    CHR - Extension: Facebook Friend Inviter = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\fojfflomljfbdfdcfmiihnijjfnnakdn\1.1_0\
    CHR - Extension: AdBlock = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.54_0\
    CHR - Extension: Netflix Enhancements = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\glefmeoggphbdgeddmnmhfejpiipcmlf\0.2.3_0\
    CHR - Extension: Memorize! = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfiakckbklmccchjegnnojbalafebakb\1.4.5_0\
    CHR - Extension: Reddit Enhancement Suite = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.1.5_0\
    CHR - Extension: Edit Any Page = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbjnggcjnmmicalchfiljffebcmfgcbh\1.2_0\
    CHR - Extension: Ti\u00EBsto = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnmeobddjkkgkglnogihcaejaleikhdh\2_0\
    CHR - Extension: Hover Zoom = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl\4.8.3_0\
    CHR - Extension: Instagram for Chrome = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\opnbmdkdflhjiclaoiiifmheknpccalb\3.5.8_0\
    CHR - Extension: Facebook Invite All Subrange = C:\Users\DJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlacnclhiinhhoaonnoflhaoaklmfek\0.1.1_0\

    O1 HOSTS File: ([2012/07/26 00:26:49 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
    O2:64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (Coupon Companion Plugin) - {11111111-1111-1111-1111-110211181104} - C:\Program Files (x86)\Coupon Companion Plugin\Coupon Companion Plugin.dll (215 Apps)
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
    O4 - HKLM..\Run: [AVG_UI] C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
    O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
    O4 - HKLM..\Run: [StartCCC] e:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [GoogleDriveSync] C:\Program Files (x86)\Google\Drive\googledrivesync.exe (Google)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [Spybot-S&D Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [Steam] E:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
    O4 - HKU\S-1-5-21-3044163233-2214013121-3301013928-1001..\Run: [uTorrent] e:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1517A28E-FBC3-4EDA-99E5-A32C81D05C19}: DhcpNameServer = 192.168.1.1
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18 - Protocol\Handler\ms-help - No CLSID value found
    O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - File not found
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) - File not found
    O20 - HKLM Winlogon: UserInit - (userinit.exe) - File not found
    O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - File not found
    O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O29:64bit: - HKLM SecurityProviders - (credssp.dll) - File not found
    O29 - HKLM SecurityProviders - (credssp.dll) - File not found
    O30 - LSA: Security Packages - (livessp) - File not found
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*
    O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
    O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

    ========== Files/Folders - Created Within 30 Days ==========

    [2013/01/14 01:50:10 | 000,000,000 | ---D | C] -- C:\FRST
    [2013/01/14 00:08:09 | 000,499,023 | ---- | C] (Oleg N. Scherbakov) -- C:\Users\DJ\Desktop\JRT (3).exe
    [2013/01/14 00:05:59 | 000,000,000 | ---D | C] -- C:\JRT
    [2013/01/13 22:16:38 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\rkill
    [2013/01/13 21:31:43 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\RK_Quarantine
    [2013/01/13 15:56:09 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\tdsskiller
    [2013/01/13 15:32:10 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\SUPERAntiSpyware.com
    [2013/01/13 15:32:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
    [2013/01/13 15:32:08 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
    [2013/01/13 15:32:08 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
    [2013/01/13 15:17:07 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
    [2013/01/12 22:51:14 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\Apex Rise Trap Sample Pack 1
    [2013/01/12 22:20:14 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Malwarebytes
    [2013/01/12 22:20:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
    [2013/01/12 22:20:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
    [2013/01/12 22:20:08 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
    [2013/01/12 18:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
    [2013/01/12 18:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
    [2013/01/12 18:12:23 | 000,017,272 | ---- | C] (Safer Networking Limited) -- C:\Windows\SysNative\sdnclean64.exe
    [2013/01/12 18:12:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
    [2013/01/12 18:12:05 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Programs
    [2013/01/12 17:33:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\AVG2013
    [2013/01/12 17:32:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\TuneUp Software
    [2013/01/12 17:32:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
    [2013/01/12 17:32:21 | 000,000,000 | -H-D | C] -- C:\$AVG
    [2013/01/12 17:32:21 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2013
    [2013/01/12 17:32:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
    [2013/01/12 17:30:25 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
    [2013/01/12 17:30:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\MFAData
    [2013/01/12 17:30:25 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
    [2013/01/12 17:30:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Avg2013
    [2013/01/12 08:43:25 | 000,285,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
    [2013/01/12 08:42:38 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
    [2013/01/12 08:42:38 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2013/01/12 01:43:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinPcap
    [2013/01/11 22:17:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Net Tools
    [2013/01/11 22:17:50 | 000,077,824 | ---- | C] (JVSoftware) -- C:\Windows\SysWow64\nmapwin.exe
    [2013/01/11 22:17:49 | 000,114,688 | ---- | C] (Open Source Telecom) -- C:\Windows\SysWow64\CCGNU32.dll
    [2013/01/11 22:17:45 | 000,010,752 | ---- | C] (Almeida & Andrade Ltda) -- C:\Windows\SysWow64\aamd532.dll
    [2013/01/11 22:17:44 | 000,939,224 | ---- | C] (Macromedia, Inc.) -- C:\Windows\SysWow64\Flash.ocx
    [2013/01/11 22:16:31 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Coupon Companion Plugin
    [2013/01/11 22:16:27 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Updater21804
    [2013/01/11 22:16:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Coupon Companion Plugin
    [2013/01/11 19:33:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MKV Player
    [2013/01/10 17:39:05 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Custom Office Templates
    [2013/01/10 17:19:22 | 000,000,000 | -HSD | C] -- C:\Config.Msi
    [2013/01/10 16:52:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
    [2013/01/10 16:52:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
    [2013/01/10 16:52:17 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
    [2013/01/10 16:52:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server
    [2013/01/10 16:52:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
    [2013/01/10 16:51:58 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
    [2013/01/10 16:51:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SQL Server
    [2013/01/10 16:49:30 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Analysis Services
    [2013/01/10 16:49:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
    [2013/01/10 16:49:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
    [2013/01/10 16:49:28 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Microsoft Help
    [2013/01/10 16:49:26 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
    [2013/01/10 16:49:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
    [2013/01/10 16:49:17 | 000,000,000 | RH-D | C] -- C:\MSOCache
    [2013/01/10 16:39:44 | 000,000,000 | --SD | C] -- C:\Users\DJ\Google Drive
    [2013/01/10 16:38:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
    [2013/01/09 19:47:24 | 000,000,000 | R--D | C] -- C:\Users\DJ\Desktop\GLIDE Project
    [2013/01/09 16:49:53 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\The Official Lex Luger Sound Kit (LEWIS CITY)
    [2013/01/09 16:46:58 | 000,000,000 | ---D | C] -- C:\Users\DJ\Desktop\Free.Lex.Luger.Drum.Kits.Samples-Download.FULL.KIT.from.HexLoops.com
    [2013/01/09 07:37:25 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Native Instruments
    [2013/01/09 07:37:24 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Native Instruments
    [2013/01/09 07:34:49 | 000,000,000 | -H-D | C] -- C:\ProgramData\{E26B3878-7CEC-469C-B449-5CAA336DF8CD}
    [2013/01/09 07:34:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments
    [2013/01/09 07:34:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Native Instruments
    [2013/01/09 07:34:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Digidesign
    [2013/01/09 07:34:39 | 000,000,000 | -H-D | C] -- C:\ProgramData\{C78336EC-F2EB-4640-99A4-DFE96581B90B}
    [2013/01/09 07:34:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments
    [2013/01/09 07:34:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
    [2013/01/09 07:34:38 | 000,000,000 | ---D | C] -- C:\Program Files\Native Instruments
    [2013/01/08 21:53:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Ableton
    [2013/01/08 21:53:02 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\CrashDumps
    [2013/01/08 21:53:01 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Ableton
    [2013/01/08 21:52:29 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Ableton
    [2013/01/08 21:51:54 | 000,368,640 | ---- | C] (Propellerhead Software AB) -- C:\Windows\SysWow64\ReWire.dll
    [2013/01/08 21:51:54 | 000,233,472 | ---- | C] (Propellerhead Software AB) -- C:\Windows\SysWow64\REX Shared Library.dll
    [2013/01/08 21:51:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ableton
    [2013/01/08 19:55:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\logs
    [2013/01/08 19:55:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\.techniclauncher
    [2013/01/08 19:50:43 | 000,000,000 | ---D | C] -- C:\Program Files\Java
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\ATI
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\ATI
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
    [2013/01/06 19:03:26 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
    [2013/01/06 19:03:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
    [2013/01/06 19:03:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
    [2013/01/06 19:03:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
    [2013/01/06 19:03:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
    [2013/01/06 19:02:56 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
    [2013/01/06 13:43:15 | 000,000,000 | ---D | C] -- C:\Users\DJ\jagexcache
    [2013/01/05 12:28:49 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\PAYDAY
    [2013/01/05 12:28:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NVIDIA Corporation
    [2013/01/05 12:01:43 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Awesomium
    [2013/01/05 12:00:14 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Uber_Entertainment
    [2013/01/05 12:00:13 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\UberLauncher
    [2013/01/05 12:00:05 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
    [2013/01/05 01:38:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft XNA
    [2013/01/05 00:50:18 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Shiner
    [2013/01/04 20:48:07 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\ArmA 2 OA
    [2013/01/04 20:47:16 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\ArmA 2
    [2013/01/04 20:47:16 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\ArmA 2
    [2013/01/04 20:47:13 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2013/01/04 20:47:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    [2013/01/04 20:46:24 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\DayZCommander
    [2013/01/04 20:23:15 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haunt 1.0
    [2013/01/04 16:59:26 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\My Games
    [2013/01/04 16:12:49 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\LolClient
    [2013/01/04 15:53:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    [2013/01/04 15:53:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
    [2013/01/04 15:38:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
    [2013/01/04 15:38:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\.swt
    [2013/01/04 15:36:28 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\InstallShield Installation Information
    [2013/01/04 15:36:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
    [2013/01/03 21:50:46 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Pokki
    [2013/01/03 18:34:29 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
    [2013/01/03 16:47:07 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\TechSmith
    [2013/01/03 16:47:01 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\TechSmith
    [2013/01/03 16:46:58 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\Camtasia Studio
    [2013/01/03 16:46:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
    [2013/01/03 16:46:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
    [2013/01/03 16:46:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\TechSmith Shared
    [2013/01/03 16:46:33 | 000,000,000 | ---D | C] -- C:\ProgramData\TechSmith
    [2013/01/03 16:45:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reference Assemblies
    [2013/01/03 16:45:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSBuild
    [2013/01/03 16:45:15 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies
    [2013/01/03 16:45:15 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild
    [2013/01/03 16:36:02 | 000,000,000 | ---D | C] -- C:\Users\DJ\Documents\telltale games
    [2013/01/03 07:28:30 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\CRE
    [2013/01/03 07:28:27 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Mozilla
    [2013/01/03 07:27:40 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\uTorrent
    [2013/01/03 00:29:54 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
    [2013/01/03 00:29:45 | 000,000,000 | ---D | C] -- C:\Windows\Panther
    [2013/01/03 00:29:24 | 000,000,000 | -HSD | C] -- C:\Boot
    [2013/01/02 22:17:11 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\.minecraft
    [2013/01/02 21:59:30 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\WinRAR
    [2013/01/02 21:59:30 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2013/01/02 21:59:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    [2013/01/02 21:59:25 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
    [2013/01/02 21:53:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\7-Zip
    [2013/01/02 21:50:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    [2013/01/02 21:46:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
    [2013/01/02 21:42:39 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Macromedia
    [2013/01/02 21:40:47 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Skype
    [2013/01/02 21:40:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    [2013/01/02 21:40:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
    [2013/01/02 21:40:43 | 000,000,000 | R--D | C] -- C:\Program Files (x86)\Skype
    [2013/01/02 21:40:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
    [2013/01/02 21:40:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
    [2013/01/02 21:36:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    [2013/01/02 21:35:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Steam
    [2013/01/02 21:35:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
    [2013/01/02 21:35:10 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Google
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\Searches
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\Contacts
    [2013/01/02 21:32:17 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
    [2013/01/02 21:32:17 | 000,000,000 | -H-D | C] -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
    [2013/01/02 21:32:17 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Adobe
    [2013/01/02 21:32:05 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\VirtualStore
    [2013/01/02 21:32:04 | 000,000,000 | ---D | C] -- C:\ProgramData\PRICache
    [2013/01/02 21:32:04 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Packages
    [2013/01/02 21:32:01 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
    [2013/01/02 21:31:56 | 000,000,000 | --SD | C] -- C:\Users\DJ\AppData\Roaming\Microsoft
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Videos
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Saved Games
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Pictures
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Music
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Links
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Favorites
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Downloads
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Documents
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\Desktop
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
    [2013/01/02 21:31:56 | 000,000,000 | R--D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\AppData\Local\Temporary Internet Files
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Templates
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Start Menu
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\SendTo
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Recent
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\PrintHood
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\NetHood
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Documents\My Videos
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Documents\My Pictures
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Documents\My Music
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\My Documents
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Local Settings
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\AppData\Local\History
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Cookies
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\Application Data
    [2013/01/02 21:31:56 | 000,000,000 | -HSD | C] -- C:\Users\DJ\AppData\Local\Application Data
    [2013/01/02 21:31:56 | 000,000,000 | -H-D | C] -- C:\Users\DJ\AppData
    [2013/01/02 21:31:56 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Temp
    [2013/01/02 21:31:56 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Local\Microsoft
    [2013/01/02 21:31:56 | 000,000,000 | ---D | C] -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
    [2012/12/26 08:50:21 | 000,000,000 | -HSD | C] -- C:\Recovery
    [2012/12/26 08:49:18 | 000,000,000 | -HSD | C] -- C:\System Volume Information
     
  21. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    ========== Files - Modified Within 30 Days ==========

    [2013/01/14 00:09:29 | 000,848,230 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2013/01/14 00:09:29 | 000,718,176 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2013/01/14 00:09:29 | 000,132,542 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2013/01/14 00:08:13 | 000,499,023 | ---- | M] (Oleg N. Scherbakov) -- C:\Users\DJ\Desktop\JRT (3).exe
    [2013/01/14 00:05:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2013/01/14 00:03:47 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013/01/14 00:03:24 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
    [2013/01/14 00:03:19 | 826,941,437 | -HS- | M] () -- C:\hiberfil.sys
    [2013/01/14 00:01:30 | 000,554,087 | ---- | M] () -- C:\Users\DJ\Desktop\adwcleaner.exe
    [2013/01/13 23:46:00 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001UA.job
    [2013/01/13 23:40:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013/01/13 23:39:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2013/01/13 23:32:00 | 000,000,518 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task f80611e4-a410-4fd3-b7c0-1c618bc4f252.job
    [2013/01/13 22:53:20 | 000,002,259 | ---- | M] () -- C:\Users\DJ\Desktop\Google Chrome.lnk
    [2013/01/13 22:42:36 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
    [2013/01/13 21:31:34 | 000,764,416 | ---- | M] () -- C:\Users\DJ\Desktop\RogueKiller.exe
    [2013/01/13 20:46:00 | 000,000,858 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001Core.job
    [2013/01/13 15:55:40 | 002,195,061 | ---- | M] () -- C:\Users\DJ\Desktop\tdsskiller.zip
    [2013/01/13 15:51:07 | 000,000,518 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 31b9111b-1432-484b-927c-d61581e72c2d.job
    [2013/01/13 15:32:09 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2013/01/12 22:47:02 | 000,422,160 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2013/01/12 22:45:20 | 000,001,938 | ---- | M] () -- C:\Windows\wininit.ini
    [2013/01/12 22:20:09 | 000,000,814 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013/01/12 18:12:36 | 000,002,177 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    [2013/01/12 17:34:14 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
    [2013/01/12 17:32:25 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2013.lnk
    [2013/01/11 22:17:53 | 000,000,730 | ---- | M] () -- C:\Users\DJ\Desktop\NetTools.lnk
    [2013/01/11 19:33:10 | 008,141,967 | ---- | M] ( ) -- C:\Users\DJ\Desktop\MKVPlayerSetupD.exe
    [2013/01/10 17:26:16 | 000,000,953 | ---- | M] () -- C:\Users\DJ\Desktop\Apex Rise Trap Sample Pack 1.lnk
    [2013/01/10 16:39:45 | 000,001,694 | ---- | M] () -- C:\Users\DJ\Desktop\Google Drive.lnk
    [2013/01/09 22:29:21 | 000,329,315 | ---- | M] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav.asd
    [2013/01/09 22:29:04 | 043,446,902 | ---- | M] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav
    [2013/01/09 22:25:51 | 157,686,659 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe.rar
    [2013/01/09 22:08:39 | 000,329,305 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe320.wav.asd
    [2013/01/09 22:07:41 | 231,716,620 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe320.wav
    [2013/01/09 22:00:02 | 000,305,581 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe160.wav.asd
    [2013/01/09 21:59:50 | 026,611,244 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe160.wav
    [2013/01/09 21:49:55 | 000,305,425 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe240.wav.asd
    [2013/01/09 21:34:53 | 000,329,419 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe.wav.asd
    [2013/01/09 21:33:52 | 231,716,620 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDEe.wav
    [2013/01/09 21:23:17 | 000,332,829 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDE.wav.asd
    [2013/01/09 21:23:02 | 029,030,444 | ---- | M] () -- C:\Users\DJ\Desktop\GLIDE.wav
    [2013/01/09 17:49:18 | 000,305,237 | ---- | M] () -- C:\Users\DJ\Desktop\trap1.wav.asd
    [2013/01/09 17:49:04 | 026,611,244 | ---- | M] () -- C:\Users\DJ\Desktop\trap1.wav
    [2013/01/09 07:34:48 | 000,000,624 | ---- | M] () -- C:\Users\Public\Desktop\Massive.lnk
    [2013/01/09 07:34:38 | 000,001,059 | ---- | M] () -- C:\Users\Public\Desktop\Service Center.lnk
    [2013/01/08 19:55:41 | 000,582,227 | ---- | M] () -- C:\Users\DJ\AppData\Roaming\technic-launcher.jar
    [2013/01/07 20:53:03 | 000,005,632 | ---- | M] () -- C:\Users\DJ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2013/01/06 15:49:01 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Mass Effect.url
    [2013/01/06 15:48:27 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Prototype.url
    [2013/01/06 15:48:13 | 000,000,220 | ---- | M] () -- C:\Users\DJ\Desktop\BioShock.url
    [2013/01/06 15:47:58 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Dead Space.url
    [2013/01/06 15:33:07 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    [2013/01/06 13:49:12 | 000,000,024 | ---- | M] () -- C:\Users\DJ\random.dat
    [2013/01/06 13:43:15 | 000,000,041 | ---- | M] () -- C:\Users\DJ\jagex_cl_runescape_LIVE.dat
    [2013/01/05 01:21:12 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead Beta.url
    [2013/01/04 20:55:17 | 000,001,089 | ---- | M] () -- C:\Users\DJ\Desktop\Steam - Shortcut (2).lnk
    [2013/01/04 20:46:09 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2013/01/04 20:23:15 | 000,001,029 | ---- | M] () -- C:\Users\DJ\Desktop\Haunt 64bit Shortcut.lnk
    [2013/01/04 15:45:11 | 000,000,641 | ---- | M] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
    [2013/01/04 15:31:37 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Amnesia The Dark Descent.url
    [2013/01/04 15:31:34 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\ARMA 2.url
    [2013/01/04 15:31:22 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead.url
    [2013/01/04 15:31:18 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Batman Arkham Asylum GOTY Edition.url
    [2013/01/04 15:31:14 | 000,000,219 | ---- | M] () -- C:\Users\DJ\Desktop\Counter-Strike Source.url
    [2013/01/04 15:31:11 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Dungeon Defenders.url
    [2013/01/04 15:31:07 | 000,000,220 | ---- | M] () -- C:\Users\DJ\Desktop\Garry's Mod.url
    [2013/01/04 15:31:04 | 000,000,218 | ---- | M] () -- C:\Users\DJ\Desktop\Half-Life.url
    [2013/01/04 15:30:55 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Hitman Absolution.url
    [2013/01/04 15:30:51 | 000,000,220 | ---- | M] () -- C:\Users\DJ\Desktop\Killing Floor.url
    [2013/01/04 15:30:45 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Orcs Must Die! 2.url
    [2013/01/04 15:30:42 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\PAYDAY The Heist.url
    [2013/01/04 15:30:21 | 000,000,219 | ---- | M] () -- C:\Users\DJ\Desktop\Portal 2.url
    [2013/01/04 15:30:06 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Super Monday Night Combat.url
    [2013/01/04 15:30:00 | 000,000,219 | ---- | M] () -- C:\Users\DJ\Desktop\Team Fortress 2.url
    [2013/01/04 15:29:47 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Terraria.url
    [2013/01/04 15:29:37 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\The Walking Dead.url
    [2013/01/03 18:34:45 | 000,000,221 | ---- | M] () -- C:\Users\DJ\Desktop\Mass Effect 2.url
    [2013/01/03 18:34:29 | 000,000,222 | ---- | M] () -- C:\Users\DJ\Desktop\Torchlight II.url
    [2013/01/03 16:46:42 | 000,000,919 | ---- | M] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
    [2013/01/03 15:11:42 | 015,512,472 | ---- | M] () -- C:\Users\DJ\Documents\****ingdopeasstrapshit.wav
    [2013/01/03 07:28:21 | 000,000,658 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
    [2013/01/03 07:28:21 | 000,000,658 | ---- | M] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
    [2013/01/03 00:30:00 | 000,000,000 | ---- | M] () -- C:\Windows\ativpsrm.bin
    [2013/01/02 21:40:45 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
    [2013/01/02 21:34:51 | 000,001,428 | ---- | M] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk

    ========== Files Created - No Company Name ==========

    [2013/01/14 00:01:43 | 000,554,087 | ---- | C] () -- C:\Users\DJ\Desktop\adwcleaner.exe
    [2013/01/13 22:42:36 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_11_00.Wdf
    [2013/01/13 21:31:37 | 000,764,416 | ---- | C] () -- C:\Users\DJ\Desktop\RogueKiller.exe
    [2013/01/13 15:55:51 | 002,195,061 | ---- | C] () -- C:\Users\DJ\Desktop\tdsskiller.zip
    [2013/01/13 15:32:16 | 000,000,518 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task f80611e4-a410-4fd3-b7c0-1c618bc4f252.job
    [2013/01/13 15:32:16 | 000,000,518 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 31b9111b-1432-484b-927c-d61581e72c2d.job
    [2013/01/13 15:32:09 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
    [2013/01/12 22:47:00 | 000,422,160 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
    [2013/01/12 22:30:00 | 000,001,938 | ---- | C] () -- C:\Windows\wininit.ini
    [2013/01/12 22:20:09 | 000,000,814 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    [2013/01/12 18:12:36 | 000,002,189 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
    [2013/01/12 18:12:36 | 000,002,177 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
    [2013/01/12 17:32:25 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2013.lnk
    [2013/01/12 08:43:25 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
    [2013/01/11 22:17:53 | 000,000,730 | ---- | C] () -- C:\Users\DJ\Desktop\NetTools.lnk
    [2013/01/11 22:17:50 | 000,809,345 | ---- | C] () -- C:\Windows\SysWow64\nmap-os-fingerprints
    [2013/01/11 22:17:50 | 000,557,444 | ---- | C] () -- C:\Windows\SysWow64\nmap-service-probes
    [2013/01/11 22:17:50 | 000,482,123 | ---- | C] () -- C:\Windows\SysWow64\nmapwin.chm
    [2013/01/11 22:17:50 | 000,452,096 | ---- | C] () -- C:\Windows\SysWow64\nmap.exe
    [2013/01/11 22:17:50 | 000,290,816 | ---- | C] () -- C:\Windows\SysWow64\nmapserv.exe
    [2013/01/11 22:17:50 | 000,225,546 | ---- | C] () -- C:\Windows\SysWow64\nmap-mac-prefixes
    [2013/01/11 22:17:50 | 000,192,007 | ---- | C] () -- C:\Windows\SysWow64\CHANGELOG
    [2013/01/11 22:17:50 | 000,108,536 | ---- | C] () -- C:\Windows\SysWow64\nmap-services
    [2013/01/11 22:17:50 | 000,025,611 | ---- | C] () -- C:\Windows\SysWow64\COPYING
    [2013/01/11 22:17:50 | 000,021,552 | ---- | C] () -- C:\Windows\SysWow64\nmap.xsl
    [2013/01/11 22:17:50 | 000,017,955 | ---- | C] () -- C:\Windows\SysWow64\nmap-rpc
    [2013/01/11 22:17:50 | 000,006,318 | ---- | C] () -- C:\Windows\SysWow64\nmap-protocols
    [2013/01/11 22:17:50 | 000,000,192 | ---- | C] () -- C:\Windows\SysWow64\nmap_performance.reg
    [2013/01/11 22:17:44 | 000,010,348 | ---- | C] () -- C:\Windows\SysWow64\SubclassingSink.tlb
    [2013/01/11 19:33:05 | 008,141,967 | ---- | C] ( ) -- C:\Users\DJ\Desktop\MKVPlayerSetupD.exe
    [2013/01/10 17:26:16 | 000,000,953 | ---- | C] () -- C:\Users\DJ\Desktop\Apex Rise Trap Sample Pack 1.lnk
    [2013/01/10 16:39:45 | 000,001,694 | ---- | C] () -- C:\Users\DJ\Desktop\Google Drive.lnk
    [2013/01/09 22:29:21 | 000,329,315 | ---- | C] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav.asd
    [2013/01/09 22:26:29 | 043,446,902 | ---- | C] () -- C:\Users\DJ\Desktop\Parkor - Glide.wav
    [2013/01/09 22:25:34 | 157,686,659 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe.rar
    [2013/01/09 22:08:39 | 000,329,305 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe320.wav.asd
    [2013/01/09 22:07:41 | 231,716,620 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe320.wav
    [2013/01/09 21:59:50 | 026,611,244 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe160.wav
    [2013/01/09 21:59:50 | 000,305,581 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe160.wav.asd
    [2013/01/09 21:49:55 | 000,305,425 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe240.wav.asd
    [2013/01/09 21:34:53 | 000,329,419 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe.wav.asd
    [2013/01/09 21:32:28 | 231,716,620 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDEe.wav
    [2013/01/09 21:23:02 | 029,030,444 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDE.wav
    [2013/01/09 21:23:02 | 000,332,829 | ---- | C] () -- C:\Users\DJ\Desktop\GLIDE.wav.asd
    [2013/01/09 17:48:36 | 000,305,237 | ---- | C] () -- C:\Users\DJ\Desktop\trap1.wav.asd
    [2013/01/09 16:41:09 | 000,110,592 | ---- | C] () -- C:\Windows\SysNative\OEMLicense.dll
    [2013/01/09 16:41:09 | 000,083,968 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
    [2013/01/09 16:28:00 | 026,611,244 | ---- | C] () -- C:\Users\DJ\Desktop\trap1.wav
    [2013/01/09 07:34:48 | 000,000,624 | ---- | C] () -- C:\Users\Public\Desktop\Massive.lnk
    [2013/01/09 07:34:38 | 000,001,059 | ---- | C] () -- C:\Users\Public\Desktop\Service Center.lnk
    [2013/01/08 20:41:10 | 000,000,910 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001UA.job
    [2013/01/08 20:41:10 | 000,000,858 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3044163233-2214013121-3301013928-1001Core.job
    [2013/01/08 19:55:40 | 000,582,227 | ---- | C] () -- C:\Users\DJ\AppData\Roaming\technic-launcher.jar
    [2013/01/06 15:49:01 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Mass Effect.url
    [2013/01/06 15:48:27 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Prototype.url
    [2013/01/06 15:48:13 | 000,000,220 | ---- | C] () -- C:\Users\DJ\Desktop\BioShock.url
    [2013/01/06 15:47:58 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Dead Space.url
    [2013/01/06 15:33:07 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
    [2013/01/06 13:43:15 | 000,000,041 | ---- | C] () -- C:\Users\DJ\jagex_cl_runescape_LIVE.dat
    [2013/01/06 13:43:15 | 000,000,024 | ---- | C] () -- C:\Users\DJ\random.dat
    [2013/01/05 01:21:12 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead Beta.url
    [2013/01/04 20:55:20 | 000,001,089 | ---- | C] () -- C:\Users\DJ\Desktop\Steam - Shortcut (2).lnk
    [2013/01/04 20:46:09 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\DayZ Commander.lnk
    [2013/01/04 20:23:15 | 000,001,029 | ---- | C] () -- C:\Users\DJ\Desktop\Haunt 64bit Shortcut.lnk
    [2013/01/04 17:20:00 | 000,385,604 | ---- | C] () -- C:\Windows\SysNative\ApnDatabase.xml
    [2013/01/04 15:56:24 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
    [2013/01/04 15:45:11 | 000,000,641 | ---- | C] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
    [2013/01/04 15:31:37 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Amnesia The Dark Descent.url
    [2013/01/04 15:31:34 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\ARMA 2.url
    [2013/01/04 15:31:22 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\ARMA 2 Operation Arrowhead.url
    [2013/01/04 15:31:14 | 000,000,219 | ---- | C] () -- C:\Users\DJ\Desktop\Counter-Strike Source.url
    [2013/01/04 15:31:11 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Dungeon Defenders.url
    [2013/01/04 15:31:07 | 000,000,220 | ---- | C] () -- C:\Users\DJ\Desktop\Garry's Mod.url
    [2013/01/04 15:31:04 | 000,000,218 | ---- | C] () -- C:\Users\DJ\Desktop\Half-Life.url
    [2013/01/04 15:30:55 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Hitman Absolution.url
    [2013/01/04 15:30:51 | 000,000,220 | ---- | C] () -- C:\Users\DJ\Desktop\Killing Floor.url
    [2013/01/04 15:30:45 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Orcs Must Die! 2.url
    [2013/01/04 15:30:42 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\PAYDAY The Heist.url
    [2013/01/04 15:30:12 | 000,000,219 | ---- | C] () -- C:\Users\DJ\Desktop\Portal 2.url
    [2013/01/04 15:30:06 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Super Monday Night Combat.url
    [2013/01/04 15:30:00 | 000,000,219 | ---- | C] () -- C:\Users\DJ\Desktop\Team Fortress 2.url
    [2013/01/04 15:29:47 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Terraria.url
    [2013/01/04 15:29:37 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\The Walking Dead.url
    [2013/01/03 18:34:58 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Batman Arkham Asylum GOTY Edition.url
    [2013/01/03 18:34:45 | 000,000,221 | ---- | C] () -- C:\Users\DJ\Desktop\Mass Effect 2.url
    [2013/01/03 18:34:29 | 000,000,222 | ---- | C] () -- C:\Users\DJ\Desktop\Torchlight II.url
    [2013/01/03 16:58:44 | 000,005,632 | ---- | C] () -- C:\Users\DJ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
    [2013/01/03 16:46:42 | 000,000,919 | ---- | C] () -- C:\Users\Public\Desktop\Camtasia Studio 8.lnk
    [2013/01/03 15:09:32 | 015,512,472 | ---- | C] () -- C:\Users\DJ\Documents\****ingdopeasstrapshit.wav
    [2013/01/03 07:28:21 | 000,000,658 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
    [2013/01/03 07:28:21 | 000,000,658 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
    [2013/01/03 00:30:31 | 826,941,437 | -HS- | C] () -- C:\hiberfil.sys
    [2013/01/03 00:30:00 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
    [2013/01/03 00:29:45 | 268,435,456 | -HS- | C] () -- C:\swapfile.sys
    [2013/01/02 21:40:45 | 000,002,515 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
    [2013/01/02 21:36:09 | 000,002,259 | ---- | C] () -- C:\Users\DJ\Desktop\Google Chrome.lnk
    [2013/01/02 21:35:13 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2013/01/02 21:35:13 | 000,000,900 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2013/01/02 21:34:51 | 000,001,428 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
    [2013/01/02 21:32:17 | 000,001,434 | ---- | C] () -- C:\Users\DJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    [2013/01/02 21:31:56 | 000,000,352 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
    [2013/01/02 21:31:56 | 000,000,334 | ---- | C] () -- C:\Users\DJ\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
    [2012/10/18 04:52:18 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
    [2012/10/18 04:52:10 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
    [2012/10/18 04:52:06 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
    [2012/07/26 03:13:10 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
    [2012/07/26 03:13:09 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
    [2012/07/26 02:21:26 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
    [2012/07/25 20:17:42 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
    [2012/07/25 15:37:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
    [2012/07/25 15:28:31 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
    [2012/06/02 09:31:19 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
    [2012/05/02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll

    ========== ZeroAccess Check ==========

    [2013/01/04 16:58:57 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

    [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

    [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

    [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
    "" = C:\Windows\SysNative\shell32.dll -- [2012/11/05 23:19:27 | 019,789,824 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
    "" = %SystemRoot%\system32\shell32.dll -- [2012/11/05 23:20:00 | 017,560,576 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Apartment

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\fastprox.dll -- [2012/07/25 22:05:38 | 001,004,544 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
    "" = %systemroot%\system32\wbem\fastprox.dll -- [2012/07/25 22:18:27 | 000,784,896 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Free

    [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
    "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2012/07/25 22:07:41 | 000,455,680 | ---- | M] (Microsoft Corporation)
    "ThreadingModel" = Both

    [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

    ========== LOP Check ==========

    [2013/01/02 22:36:38 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\.minecraft
    [2013/01/08 19:59:48 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\.techniclauncher
    [2013/01/08 21:53:01 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\Ableton
    [2013/01/12 17:33:25 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\AVG2013
    [2013/01/05 12:27:59 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\Awesomium
    [2013/01/08 19:59:43 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\logs
    [2013/01/04 16:12:49 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\LolClient
    [2013/01/03 16:47:01 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\TechSmith
    [2013/01/12 17:32:25 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\TuneUp Software
    [2013/01/13 22:47:06 | 000,000,000 | ---D | M] -- C:\Users\DJ\AppData\Roaming\uTorrent

    ========== Purity Check ==========


    < End of report >
     
  22. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    Re-run OTL.
    Use the following settings:

    • Click the NONE button
    • Under Custom Scans/Fixes paste:
    Code:
    /md5start
    userinit.exe
    winlogon.exe
    explorer.exe
    /md5stop
    
    • Finally hit Run Scan and wait for the log to open.
    • Please post the content of the log into your next reply.
     
  23. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    OTL logfile created on: 1/14/2013 3:11:16 PM - Run 2
    OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\DJ\Downloads
    64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
    Internet Explorer (Version = 9.10.9200.16453)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    15.96 Gb Total Physical Memory | 13.17 Gb Available Physical Memory | 82.51% Memory free
    18.21 Gb Paging File | 14.76 Gb Available in Paging File | 81.04% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 55.90 Gb Total Space | 13.17 Gb Free Space | 23.56% Space Free | Partition Type: NTFS
    Drive D: | 350.00 Mb Total Space | 297.25 Mb Free Space | 84.93% Space Free | Partition Type: NTFS
    Drive E: | 1396.92 Gb Total Space | 1141.91 Gb Free Space | 81.74% Space Free | Partition Type: NTFS
    Drive G: | 1.91 Gb Total Space | 0.25 Gb Free Space | 12.83% Space Free | Partition Type: FAT

    Computer Name: PARKER | User Name: DJ | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
    Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days

    ========== Custom Scans ==========

    < MD5 for: EXPLORER.EXE >
    [2012/10/11 00:53:24 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
    [2012/10/11 03:09:58 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
    [2012/07/25 22:50:01 | 002,114,936 | ---- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
    [2012/07/25 23:49:13 | 002,380,440 | ---- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
    [2012/10/11 00:56:41 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 -- C:\Windows\SysWOW64\explorer.exe
    [2012/10/11 00:56:41 | 002,115,952 | ---- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 -- C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
    [2012/10/11 02:35:16 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 -- C:\Windows\explorer.exe
    [2012/10/11 02:35:16 | 002,380,944 | ---- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 -- C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe
    [2012/11/13 14:07:52 | 003,906,584 | ---- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 -- C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe

    < MD5 for: USERINIT.EXE >
    [2012/07/25 22:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\SysNative\userinit.exe
    [2012/07/25 22:08:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 -- C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_34f2617a5b742e02\userinit.exe
    [2012/07/25 22:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\SysWOW64\userinit.exe
    [2012/07/25 22:21:00 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_d8d3c5f6a316bccc\userinit.exe

    < MD5 for: WINLOGON.EXE >
    [2012/09/20 01:33:55 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
    [2012/09/20 01:33:17 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
    [2012/07/25 22:08:50 | 000,516,608 | ---- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
    [2012/10/11 00:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\SysNative\winlogon.exe
    [2012/10/11 00:46:58 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe
    [2012/10/11 00:45:27 | 000,517,120 | ---- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F -- C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe

    < End of report >
     
  24. Broni

    Broni Malware Annihilator Posts: 52,747   +342

    Is MBAM still complaining?
     
  25. Parkor

    Parkor TS Rookie Topic Starter Posts: 43

    Not as often, and now it's just one ip it's blocking. 213.186.33.87
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...