TechSpot

Windows has encountered a critical problem and will restart

Solved
By ajptjd
Sep 30, 2012
  1. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzABBB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzABE4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzABE6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzABFE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAC55.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzACB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzACD3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAD8C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzADCB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzADD2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzADD3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzADFE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAE12.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAE50.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAE81.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAF20.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAF6E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzAF9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB03C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB06C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB06D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB08.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB08D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB097.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB09E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB0F2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB136.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB183.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB1BD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB1E5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB1F8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB200.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB205.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB266.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB296.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB2AD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB2BD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB2CD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB2ED.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB318.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB32.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB331.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB364.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB38F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB39D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB3B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB3BC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB3DA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB3FC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB404.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB423.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB46.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB487.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB494.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB4B7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB4C6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB52E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB549.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB589.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5B4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5BE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5D1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5D5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5D7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5D8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5D9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB5F1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB61F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB620.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB630.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB63F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB666.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB66A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB68C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB6A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB706.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB737.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB73A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB742.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB765.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB78E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB79B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB7B9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB7E5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB81B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB825.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB82B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB850.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB85B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB85E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB8B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB8B4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB8CC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB8D4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB90E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB915.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB937.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB988.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzB9F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBA5D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBA77.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBA7A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBA8A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBA8C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBAB3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBAE1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBB0A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBB84.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBB87.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBB88.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBB97.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBBA6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBC23.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBC7A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBC9C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBCB0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBCCD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBCFA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBD4B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBD4C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBD5B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBDC1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBDD9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBE06.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBE4D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBE6E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBEAB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBED6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBF0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBF4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBF65.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBF9A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBFD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBFDC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBFEB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzBFEC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC014.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC03B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC04D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC092.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC0A8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC0BC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC0CB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC188.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC191.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC1C6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC204.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC205.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC23E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC275.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC283.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC290.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC29A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC2A1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC2B6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC2BE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC2E4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC2F3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC350.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC39.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC39B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC3C9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC442.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC46.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC4BF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC4D8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC560.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC595.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC651.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC699.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC6A6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC6A7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC6B8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC6F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC768.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC784.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC7C6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC7C7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC7CB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC7D0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC7DA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC7EC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC83B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC87E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC8A7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC8C2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC8C5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC8C9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC8D8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC8EB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC98A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC9A7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzC9D8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCA06.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCA27.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCA71.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCA7C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCA96.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCAB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCAF3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCB0D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCB25.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCB5D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCB73.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCBC3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCBFD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCC13.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCC74.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCCB8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCCB9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCD29.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCD68.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCDA3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCDB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCDBB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCDD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCDDF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCDE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCDE4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCE26.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCE27.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCE63.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCF3C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCF7B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCF9A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzCFCA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD019.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD022.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD08F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD0B6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD101.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD102.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD10C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD180.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD1E9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD25A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD25D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD27C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD2AC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD2B2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD2BA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD2F7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD2F9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD2FB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD300.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD30A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD360.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD367.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD3A0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD3FA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD429.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD430.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD43D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD45E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD48D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD4A7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD4F2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD50D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD53E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD570.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD62E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD652.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD6AC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD6D2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD6EA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD715.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD72D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD753.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD75F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD7B6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD82B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD859.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD860.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD88C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD88E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD8B4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD8CF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD915.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD928.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD929.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD95B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD985.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzD9C4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDA4F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDA62.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDA78.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDA7D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDA9E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDAD0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDAEE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDB2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDB30.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDB56.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDB66.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDB82.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDB97.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDBA2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDBA8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDBA9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDBB5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDBDD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDCB5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDD09.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDD15.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDD6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDDC7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDDE5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDDE7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDDF1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDDF2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDDF9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE02.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE2E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE32.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE33.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE6D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE6F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDE76.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDEDB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDEE8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDEF9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDEFA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDF0A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDF1F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDF28.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDF35.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDF37.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDF7A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDFDD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzDFF1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE003.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE01.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE05F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE073.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE076.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE08A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE0C6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE0DA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE0FC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE11C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE121.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE148.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE169.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE177.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE17F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE190.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE1A0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE20C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE215.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE22E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE254.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE257.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE25F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE2C0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE2DB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE306.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE34E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE35C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE39B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE3D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE3DF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE3FF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE405.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE43A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE470.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE47A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE490.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE496.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE4E6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE502.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE534.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE550.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE570.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE599.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE5A4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE5BF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE5C2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE5D1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE5D3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE60D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE626.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE669.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE6A1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE6DA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE6DB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE6E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE6E2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE752.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE7A7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE7F2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE7F9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE820.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE855.tmp
  2. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE8EC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE8ED.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE928.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzE9EB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEA38.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEA70.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEABA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEACF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEB4D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEB50.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEB69.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEB8E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEBA9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEBC2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEBFC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEC1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEC16.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEC39.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEC4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEC4F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEC66.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEC89.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzECC8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzECFC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzED2B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzED6D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEDAE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEDE7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEDEB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEDF9.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEE23.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEE24.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEE92.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEECB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEEF7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEF2F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEF32.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEF48.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEF8C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEFA6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEFB7.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEFD8.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzEFF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF01A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF028.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF04B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF0F5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF107.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF11D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF14D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF158.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF170.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF181.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF1B0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF1C2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF202.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF214.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF22A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF243.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF259.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF25C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF260.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF28B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF2C3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF305.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF308.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF347.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF36C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF3CD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF421.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF44E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF475.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF4A6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF502.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF51.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF5AC.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF5D6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF5DD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF605.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF61D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF641.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF64A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF6A0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF6DD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF72.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF7E1.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF7FE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF86A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF88B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF8CB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF92F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF999.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF9BA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF9BB.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF9BD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF9BE.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF9CD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF9D5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzF9E6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFA0A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFA10.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFA4F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFA6F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFA79.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFA7A.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFA9C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFB10.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFB11.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFB2B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFB36.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFB5C.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFB90.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFBAA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFBB4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFBCF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFBE2.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFBF0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFBF4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFC22.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFC5F.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFC81.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFC84.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFC88.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFCD0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFD1D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFD2D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFD6E.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFD83.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFD84.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFDD4.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFE40.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFE76.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFE85.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFE89.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFE9D.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFEAD.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFEB6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFEBF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFEC3.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFEE0.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFEE5.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFEE6.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFF48.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFF49.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFF68.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFF7B.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFFEA.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFFF.tmp
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U\trzFFF6.tmp
    ZeroAccess:
    C:\Windows\assembly\GAC_32\Desktop.ini
    ZeroAccess:
    C:\Windows\assembly\GAC_64\Desktop.ini
    ZeroAccess:
    C:\Users\Family\AppData\Local\{1124a725-e7eb-82f4-e978-28044d39f9dc}
    C:\Users\Family\AppData\Local\{1124a725-e7eb-82f4-e978-28044d39f9dc}\@
    C:\Users\Family\AppData\Local\{1124a725-e7eb-82f4-e978-28044d39f9dc}\L
    C:\Users\Family\AppData\Local\{1124a725-e7eb-82f4-e978-28044d39f9dc}\U
    ATTENTION: ========> Check for possible partition/boot infection:
    C:\Windows\svchost.exe
    ==================== Known DLLs (Whitelisted) =================
  3. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    ==================== Bamital & volsnap Check =================
    C:\Windows\System32\winlogon.exe => MD5 is legit
    C:\Windows\System32\wininit.exe => MD5 is legit
    C:\Windows\SysWOW64\wininit.exe => MD5 is legit
    C:\Windows\explorer.exe => MD5 is legit
    C:\Windows\SysWOW64\explorer.exe => MD5 is legit
    C:\Windows\System32\svchost.exe => MD5 is legit
    C:\Windows\SysWOW64\svchost.exe => MD5 is legit
    C:\Windows\System32\services.exe 014A9CB92514E27C0107614DF764BC06 ZeroAccess <==== ATTENTION!.
    C:\Windows\System32\User32.dll => MD5 is legit
    C:\Windows\SysWOW64\User32.dll => MD5 is legit
    C:\Windows\System32\userinit.exe => MD5 is legit
    C:\Windows\SysWOW64\userinit.exe => MD5 is legit
    C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
    TDL4: custom:26000022 <===== ATTENTION!
    ==================== EXE ASSOCIATION =====================
    HKLM\...\.exe: exefile => OK
    HKLM\...\exefile\DefaultIcon: %1 => OK
    HKLM\...\exefile\open\command: "%1" %* => OK
    ==================== Restore Points =========================
    Restore point made on: 2012-08-27 12:26:59
    Restore point made on: 2012-08-27 12:33:34
    Restore point made on: 2012-09-03 10:27:46
    Restore point made on: 2012-09-03 10:52:00
    Restore point made on: 2012-09-16 21:26:28
    ==================== Memory info ===========================
    Percentage of memory in use: 18%
    Total physical RAM: 2662.87 MB
    Available physical RAM: 2161.62 MB
    Total Pagefile: 2661.07 MB
    Available Pagefile: 2149.33 MB
    Total Virtual: 8192 MB
    Available Virtual: 8191.91 MB
    ==================== Partitions =============================
    1 Drive c: (TI106302W0C) (Fixed) (Total:282.92 GB) (Free:182.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    2 Drive e: (System) (Fixed) (Total:1.46 GB) (Free:1.27 GB) NTFS ==>[System with boot components (obtained from reading drive)]
    ATTENTION: Malware custom entry on BCD on drive e: detected. Check for MBR/Partition infection.
    5 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
    6 Drive y: (TRAVELDRIVE) (Removable) (Total:7.2 GB) (Free:7.2 GB) FAT32
    Disk ### Status Size Free Dyn Gpt
    -------- ------------- ------- ------- --- ---
    Disk 0 Online 298 GB 0 B
    Disk 1 Online 7385 MB 0 B
    Disk 2 No Media 0 B 0 B
    Partitions of Disk 0:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Recovery 1500 MB 1024 KB
    Partition 2 Primary 282 GB 1501 MB
    Partition 3 Primary 13 GB 284 GB
    ==================================================================================
    Disk: 0
    Partition 1
    Type : 27
    Hidden: Yes
    Active: Yes
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 2 E System NTFS Partition 1500 MB Healthy Hidden
    =========================================================
    Disk: 0
    Partition 2
    Type : 07
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 1 C TI106302W0C NTFS Partition 282 GB Healthy
    =========================================================
    Disk: 0
    Partition 3
    Type : 17 (Suspicious Type)
    Hidden: Yes
    Active: No
    There is no volume associated with this partition.
    =========================================================
    Partitions of Disk 1:
    ===============
    Partition ### Type Size Offset
    ------------- ---------------- ------- -------
    Partition 1 Primary 7381 MB 4032 KB
    ==================================================================================
  4. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    Disk: 1
    Partition 1
    Type : 0C
    Hidden: No
    Active: No
    Volume ### Ltr Label Fs Type Size Status Info
    ---------- --- ----------- ----- ---------- ------- --------- --------
    * Volume 3 Y TRAVELDRIVE FAT32 Removable 7381 MB Healthy
    =========================================================
    Last Boot: 2012-09-16 21:17
    ==================== End Of Log =============================
  5. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    This is wrong.
    Re-read my instructions.

    [​IMG]
  6. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    yeah, I can tell. I am sorry. :oops: QUESTION: Do I download the TDSSKILLER to the flash, THEN plug it into the infected laptop?
  7. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    No.
    Re-read my instruction and run FRST fix correctly.

    I posted at the very beginning:
  8. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 07-10-2012
    Ran by SYSTEM at 2012-10-08 09:31:21 Run:1
    Running from Y:\
    ==============================================
    HKEY_LOCAL_MACHINE\System\ControlSet001\Control\Session Manager\SubSystems\\Windows No ZeroAccess entry found.
    C:\Windows\System32\consrv.dll not found.
    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ Default Value restored successfully.
    HKEY_USERS\Family\Software\Microsoft\Windows\CurrentVersion\Run\\SoftGrid Client Value deleted successfully.
    C:\windows\system32\config\systemprofile\AppData\Local\Temp\SoftGrid Client\khjdl.dll not found.
    C:\Windows\Installer\{1124a725-e7eb-82f4-e978-28044d39f9dc} moved successfully.
    C:\Windows\assembly\GAC_32\Desktop.ini moved successfully.
    C:\Windows\assembly\GAC_64\Desktop.ini moved successfully.
    C:\Users\Family\AppData\Local\{1124a725-e7eb-82f4-e978-28044d39f9dc} moved successfully.
    C:\Windows\svchost.exe moved successfully.
    C:\Windows\System32\services.exe moved successfully.
    C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe copied successfully to C:\Windows\System32\services.exe
    ==== End of Fixlog ====
  9. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    I had to restart, and there was two .txt logs, so I will paste the one that was in the report.

    10:27:02.0931 3376 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
    10:27:03.0368 3376 ============================================================
    10:27:03.0368 3376 Current date / time: 2012/10/08 10:27:03.0368
    10:27:03.0368 3376 SystemInfo:
    10:27:03.0368 3376
    10:27:03.0368 3376 OS Version: 6.1.7601 ServicePack: 1.0
    10:27:03.0368 3376 Product type: Workstation
    10:27:03.0368 3376 ComputerName: FAMILYLAPTOP
    10:27:03.0368 3376 UserName: Family
    10:27:03.0368 3376 Windows directory: C:\windows
    10:27:03.0368 3376 System windows directory: C:\windows
    10:27:03.0368 3376 Running under WOW64
    10:27:03.0368 3376 Processor architecture: Intel x64
    10:27:03.0368 3376 Number of processors: 2
    10:27:03.0368 3376 Page size: 0x1000
    10:27:03.0368 3376 Boot type: Normal boot
    10:27:03.0368 3376 ============================================================
    10:27:05.0942 3376 BG loaded
    10:27:07.0571 3376 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    10:27:07.0634 3376 ============================================================
    10:27:07.0634 3376 \Device\Harddisk0\DR0:
    10:27:07.0681 3376 MBR partitions:
    10:27:07.0681 3376 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x235D7000
    10:27:07.0681 3376 ============================================================
    10:27:07.0805 3376 C: <-> \Device\Harddisk0\DR0\Partition1
    10:27:07.0805 3376 ============================================================
    10:27:07.0805 3376 Initialize success
    10:27:07.0805 3376 ============================================================
  10. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    It's incomplete.
    Redo.
  11. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    10:27:02.0931 3376 TDSS rootkit removing tool 2.8.10.0 Sep 17 2012 19:23:24
    10:27:03.0368 3376 ============================================================
    10:27:03.0368 3376 Current date / time: 2012/10/08 10:27:03.0368
    10:27:03.0368 3376 SystemInfo:
    10:27:03.0368 3376
    10:27:03.0368 3376 OS Version: 6.1.7601 ServicePack: 1.0
    10:27:03.0368 3376 Product type: Workstation
    10:27:03.0368 3376 ComputerName: FAMILYLAPTOP
    10:27:03.0368 3376 UserName: Family
    10:27:03.0368 3376 Windows directory: C:\windows
    10:27:03.0368 3376 System windows directory: C:\windows
    10:27:03.0368 3376 Running under WOW64
    10:27:03.0368 3376 Processor architecture: Intel x64
    10:27:03.0368 3376 Number of processors: 2
    10:27:03.0368 3376 Page size: 0x1000
    10:27:03.0368 3376 Boot type: Normal boot
    10:27:03.0368 3376 ============================================================
    10:27:05.0942 3376 BG loaded
    10:27:07.0571 3376 Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 (298.09 Gb), SectorSize: 0x200, Cylinders: 0x9801, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040
    10:27:07.0634 3376 ============================================================
    10:27:07.0634 3376 \Device\Harddisk0\DR0:
    10:27:07.0681 3376 MBR partitions:
    10:27:07.0681 3376 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x2EE800, BlocksNum 0x235D7000
    10:27:07.0681 3376 ============================================================
    10:27:07.0805 3376 C: <-> \Device\Harddisk0\DR0\Partition1
    10:27:07.0805 3376 ============================================================
    10:27:07.0805 3376 Initialize success
    10:27:07.0805 3376 ============================================================
    10:51:29.0450 1112 ============================================================
    10:51:29.0450 1112 Scan started
    10:51:29.0450 1112 Mode: Manual;
    10:51:29.0451 1112 ============================================================
    10:51:32.0693 1112 ================ Scan system memory ========================
    10:51:32.0693 1112 System memory - ok
    10:51:32.0695 1112 ================ Scan services =============================
    10:51:32.0897 1112 [ A87D604AEA360176311474C87A63BB88 ] 1394ohci C:\windows\system32\drivers\1394ohci.sys
    10:51:32.0916 1112 1394ohci - ok
    10:51:32.0954 1112 [ D81D9E70B8A6DD14D42D7B4EFA65D5F2 ] ACPI C:\windows\system32\drivers\ACPI.sys
    10:51:32.0962 1112 ACPI - ok
    10:51:32.0989 1112 [ 99F8E788246D495CE3794D7E7821D2CA ] AcpiPmi C:\windows\system32\drivers\acpipmi.sys
    10:51:32.0992 1112 AcpiPmi - ok
    10:51:33.0038 1112 [ 2F6B34B83843F0C5118B63AC634F5BF4 ] adp94xx C:\windows\system32\drivers\adp94xx.sys
    10:51:33.0049 1112 adp94xx - ok
    10:51:33.0099 1112 [ 597F78224EE9224EA1A13D6350CED962 ] adpahci C:\windows\system32\drivers\adpahci.sys
    10:51:33.0109 1112 adpahci - ok
    10:51:33.0139 1112 [ E109549C90F62FB570B9540C4B148E54 ] adpu320 C:\windows\system32\drivers\adpu320.sys
    10:51:33.0144 1112 adpu320 - ok
    10:51:33.0213 1112 [ 4B78B431F225FD8624C5655CB1DE7B61 ] AeLookupSvc C:\windows\System32\aelupsvc.dll
    10:51:33.0217 1112 AeLookupSvc - ok
    10:51:33.0263 1112 [ 1C7857B62DE5994A75B054A9FD4C3825 ] AFD C:\windows\system32\drivers\afd.sys
    10:51:33.0274 1112 AFD - ok
    10:51:33.0311 1112 [ 608C14DBA7299D8CB6ED035A68A15799 ] agp440 C:\windows\system32\drivers\agp440.sys
    10:51:33.0315 1112 agp440 - ok
    10:51:33.0356 1112 [ 3290D6946B5E30E70414990574883DDB ] ALG C:\windows\System32\alg.exe
    10:51:33.0360 1112 ALG - ok
    10:51:33.0395 1112 [ 5812713A477A3AD7363C7438CA2EE038 ] aliide C:\windows\system32\drivers\aliide.sys
    10:51:33.0398 1112 aliide - ok
    10:51:33.0448 1112 [ 2F2E91FD092811353C3BC968BEC274D8 ] AMD External Events Utility C:\windows\system32\atiesrxx.exe
    10:51:33.0454 1112 AMD External Events Utility - ok
    10:51:33.0487 1112 [ 1FF8B4431C353CE385C875F194924C0C ] amdide C:\windows\system32\drivers\amdide.sys
    10:51:33.0490 1112 amdide - ok
    10:51:33.0514 1112 [ 7024F087CFF1833A806193EF9D22CDA9 ] AmdK8 C:\windows\system32\drivers\amdk8.sys
    10:51:33.0518 1112 AmdK8 - ok
    10:51:33.0780 1112 [ 194D76D2083318A2E7071A988E02ECF4 ] amdkmdag C:\windows\system32\DRIVERS\atikmdag.sys
    10:51:34.0023 1112 amdkmdag - ok
    10:51:34.0081 1112 [ 1EEFFCE9A3A65A56A28793EAA3F57026 ] amdkmdap C:\windows\system32\DRIVERS\atikmpag.sys
    10:51:34.0089 1112 amdkmdap - ok
    10:51:34.0128 1112 [ 1E56388B3FE0D031C44144EB8C4D6217 ] AmdPPM C:\windows\system32\DRIVERS\amdppm.sys
    10:51:34.0130 1112 AmdPPM - ok
    10:51:34.0161 1112 [ D4121AE6D0C0E7E13AA221AA57EF2D49 ] amdsata C:\windows\system32\drivers\amdsata.sys
    10:51:34.0166 1112 amdsata - ok
    10:51:34.0187 1112 [ F67F933E79241ED32FF46A4F29B5120B ] amdsbs C:\windows\system32\drivers\amdsbs.sys
    10:51:34.0193 1112 amdsbs - ok
    10:51:34.0213 1112 [ 540DAF1CEA6094886D72126FD7C33048 ] amdxata C:\windows\system32\drivers\amdxata.sys
    10:51:34.0218 1112 amdxata - ok
    10:51:34.0245 1112 [ CAEE7C1AFC9F1C9EE8DD11ACD18D22E7 ] amd_sata C:\windows\system32\DRIVERS\amd_sata.sys
    10:51:34.0249 1112 amd_sata - ok
    10:51:34.0278 1112 [ 23726116B4FBCC84FC45B95157C08F5F ] amd_xata C:\windows\system32\DRIVERS\amd_xata.sys
    10:51:34.0281 1112 amd_xata - ok
    10:51:34.0331 1112 [ 89A69C3F2F319B43379399547526D952 ] AppID C:\windows\system32\drivers\appid.sys
    10:51:34.0390 1112 AppID - ok
    10:51:34.0492 1112 [ 0BC381A15355A3982216F7172F545DE1 ] AppIDSvc C:\windows\System32\appidsvc.dll
    10:51:34.0495 1112 AppIDSvc - ok
    10:51:34.0543 1112 [ 3977D4A871CA0D4F2ED1E7DB46829731 ] Appinfo C:\windows\System32\appinfo.dll
    10:51:34.0547 1112 Appinfo - ok
    10:51:34.0639 1112 [ 3DEBBECF665DCDDE3A95D9B902010817 ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    10:51:34.0644 1112 Apple Mobile Device - ok
    10:51:34.0679 1112 [ C484F8CEB1717C540242531DB7845C4E ] arc C:\windows\system32\drivers\arc.sys
    10:51:34.0684 1112 arc - ok
    10:51:34.0730 1112 [ 019AF6924AEFE7839F61C830227FE79C ] arcsas C:\windows\system32\drivers\arcsas.sys
    10:51:34.0735 1112 arcsas - ok
    10:51:34.0783 1112 [ 55142B4F7A7E4C9C151C6000A6BF7809 ] aswFsBlk C:\windows\system32\drivers\aswFsBlk.sys
    10:51:34.0787 1112 aswFsBlk - ok
    10:51:34.0831 1112 [ AA9FDE3D630160B47DAB21BF8250111C ] aswMonFlt C:\windows\system32\drivers\aswMonFlt.sys
    10:51:34.0836 1112 aswMonFlt - ok
    10:51:34.0873 1112 [ 2A6675C24DF5159A9506CD13ECE5ABE9 ] aswRdr C:\windows\System32\Drivers\aswrdr2.sys
    10:51:34.0877 1112 aswRdr - ok
    10:51:34.0955 1112 [ 4E38475BDB51A867CCBA7D5DF7FDFC0C ] aswSnx C:\windows\system32\drivers\aswSnx.sys
    10:51:34.0978 1112 aswSnx - ok
    10:51:35.0027 1112 [ 9A49D80D65451AF22913AEF772CC3DA9 ] aswSP C:\windows\system32\drivers\aswSP.sys
    10:51:35.0037 1112 aswSP - ok
    10:51:35.0097 1112 [ C3EC420451AC5300A22190AE38418FBA ] aswTdi C:\windows\system32\drivers\aswTdi.sys
    10:51:35.0102 1112 aswTdi - ok
    10:51:35.0131 1112 [ 769765CE2CC62867468CEA93969B2242 ] AsyncMac C:\windows\system32\DRIVERS\asyncmac.sys
    10:51:35.0135 1112 AsyncMac - ok
    10:51:35.0180 1112 [ 02062C0B390B7729EDC9E69C680A6F3C ] atapi C:\windows\system32\drivers\atapi.sys
    10:51:35.0184 1112 atapi - ok
    10:51:35.0310 1112 [ B2931C83CFB12A3223A47B180473AE1A ] athr C:\windows\system32\DRIVERS\athrx.sys
    10:51:35.0370 1112 athr - ok
    10:51:35.0431 1112 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioEndpointBuilder C:\windows\System32\Audiosrv.dll
    10:51:35.0444 1112 AudioEndpointBuilder - ok
    10:51:35.0463 1112 [ F23FEF6D569FCE88671949894A8BECF1 ] AudioSrv C:\windows\System32\Audiosrv.dll
    10:51:35.0473 1112 AudioSrv - ok
    10:51:35.0575 1112 [ 04AC21E821F259845BD7367CEE057290 ] avast! Antivirus C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    10:51:35.0578 1112 avast! Antivirus - ok
    10:51:35.0626 1112 [ A6BF31A71B409DFA8CAC83159E1E2AFF ] AxInstSV C:\windows\System32\AxInstSV.dll
    10:51:35.0633 1112 AxInstSV - ok
    10:51:35.0696 1112 [ 3E5B191307609F7514148C6832BB0842 ] b06bdrv C:\windows\system32\drivers\bxvbda.sys
    10:51:35.0709 1112 b06bdrv - ok
    10:51:35.0760 1112 [ B5ACE6968304A3900EEB1EBFD9622DF2 ] b57nd60a C:\windows\system32\DRIVERS\b57nd60a.sys
    10:51:35.0768 1112 b57nd60a - ok
    10:51:35.0822 1112 [ FDE360167101B4E45A96F939F388AEB0 ] BDESVC C:\windows\System32\bdesvc.dll
    10:51:35.0828 1112 BDESVC - ok
    10:51:35.0848 1112 [ 16A47CE2DECC9B099349A5F840654746 ] Beep C:\windows\system32\drivers\Beep.sys
    10:51:35.0854 1112 Beep - ok
    10:51:36.0046 1112 [ 1D757A7E020C577C4259A755F21B7152 ] BHDrvx64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120215.001\BHDrvx64.sys
    10:51:36.0066 1112 BHDrvx64 - ok
    10:51:36.0100 1112 [ 61583EE3C3A17003C4ACD0475646B4D3 ] blbdrive C:\windows\system32\DRIVERS\blbdrive.sys
    10:51:36.0104 1112 blbdrive - ok
    10:51:36.0167 1112 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
    10:51:36.0179 1112 Bonjour Service - ok
    10:51:36.0223 1112 [ 6C02A83164F5CC0A262F4199F0871CF5 ] bowser C:\windows\system32\DRIVERS\bowser.sys
    10:51:36.0227 1112 bowser - ok
    10:51:36.0269 1112 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\windows\system32\drivers\BrFiltLo.sys
    10:51:36.0273 1112 BrFiltLo - ok
    10:51:36.0295 1112 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\windows\system32\drivers\BrFiltUp.sys
    10:51:36.0297 1112 BrFiltUp - ok
    10:51:36.0338 1112 [ 8EF0D5C41EC907751B8429162B1239ED ] Browser C:\windows\System32\browser.dll
    10:51:36.0343 1112 Browser - ok
    10:51:36.0377 1112 [ 43BEA8D483BF1870F018E2D02E06A5BD ] Brserid C:\windows\System32\Drivers\Brserid.sys
    10:51:36.0398 1112 Brserid - ok
    10:51:36.0421 1112 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\windows\System32\Drivers\BrSerWdm.sys
    10:51:36.0425 1112 BrSerWdm - ok
    10:51:36.0449 1112 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\windows\System32\Drivers\BrUsbMdm.sys
    10:51:36.0452 1112 BrUsbMdm - ok
    10:51:36.0471 1112 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\windows\System32\Drivers\BrUsbSer.sys
    10:51:36.0474 1112 BrUsbSer - ok
    10:51:36.0523 1112 [ 2347ABBD13BADA65826FDAB4CAAFE357 ] BtFilter C:\windows\system32\DRIVERS\btfilter.sys
    10:51:36.0526 1112 BtFilter - ok
    10:51:36.0564 1112 [ 9DA669F11D1F894AB4EB69BF546A42E8 ] BTHMODEM C:\windows\system32\drivers\bthmodem.sys
    10:51:36.0570 1112 BTHMODEM - ok
    10:51:36.0624 1112 [ 95F9C2976059462CBBF227F7AAB10DE9 ] bthserv C:\windows\system32\bthserv.dll
    10:51:36.0628 1112 bthserv - ok
    10:51:36.0703 1112 [ 2C6FFCCA37B002AAB3C7C31A6D780A76 ] ccSet_NIS C:\windows\system32\drivers\NISx64\1308000.00E\ccSetx64.sys
    10:51:36.0707 1112 ccSet_NIS - ok
    10:51:36.0740 1112 [ B8BD2BB284668C84865658C77574381A ] cdfs C:\windows\system32\DRIVERS\cdfs.sys
    10:51:36.0745 1112 cdfs - ok
     
  12. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    10:51:36.0792 1112 [ F036CE71586E93D94DAB220D7BDF4416 ] cdrom C:\windows\system32\DRIVERS\cdrom.sys
    10:51:36.0799 1112 cdrom - ok
    10:51:36.0857 1112 [ F17D1D393BBC69C5322FBFAFACA28C7F ] CertPropSvc C:\windows\System32\certprop.dll
    10:51:36.0862 1112 CertPropSvc - ok
    10:51:36.0897 1112 [ D7CD5C4E1B71FA62050515314CFB52CF ] circlass C:\windows\system32\drivers\circlass.sys
    10:51:36.0902 1112 circlass - ok
    10:51:36.0941 1112 [ FE1EC06F2253F691FE36217C592A0206 ] CLFS C:\windows\system32\CLFS.sys
    10:51:36.0953 1112 CLFS - ok
    10:51:37.0050 1112 [ D88040F816FDA31C3B466F0FA0918F29 ] clr_optimization_v2.0.50727_32 C:\windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    10:51:37.0056 1112 clr_optimization_v2.0.50727_32 - ok
    10:51:37.0115 1112 [ D1CEEA2B47CB998321C579651CE3E4F8 ] clr_optimization_v2.0.50727_64 C:\windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe
    10:51:37.0121 1112 clr_optimization_v2.0.50727_64 - ok
    10:51:37.0207 1112 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    10:51:37.0213 1112 clr_optimization_v4.0.30319_32 - ok
    10:51:37.0250 1112 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    10:51:37.0254 1112 clr_optimization_v4.0.30319_64 - ok
    10:51:37.0291 1112 [ 0840155D0BDDF1190F84A663C284BD33 ] CmBatt C:\windows\system32\DRIVERS\CmBatt.sys
    10:51:37.0294 1112 CmBatt - ok
    10:51:37.0316 1112 [ E19D3F095812725D88F9001985B94EDD ] cmdide C:\windows\system32\drivers\cmdide.sys
    10:51:37.0319 1112 cmdide - ok
    10:51:37.0366 1112 [ 9AC4F97C2D3E93367E2148EA940CD2CD ] CNG C:\windows\system32\Drivers\cng.sys
    10:51:37.0377 1112 CNG - ok
    10:51:37.0477 1112 [ 99B1B888B793DE320C5479B3C953781F ] CnxtHdAudService C:\windows\system32\drivers\CHDRT64.sys
    10:51:37.0505 1112 CnxtHdAudService - ok
    10:51:37.0556 1112 [ 102DE219C3F61415F964C88E9085AD14 ] Compbatt C:\windows\system32\drivers\compbatt.sys
    10:51:37.0560 1112 Compbatt - ok
    10:51:37.0605 1112 [ 03EDB043586CCEBA243D689BDDA370A8 ] CompositeBus C:\windows\system32\DRIVERS\CompositeBus.sys
    10:51:37.0609 1112 CompositeBus - ok
    10:51:37.0625 1112 COMSysApp - ok
    10:51:37.0664 1112 [ 1C827878A998C18847245FE1F34EE597 ] crcdisk C:\windows\system32\drivers\crcdisk.sys
    10:51:37.0683 1112 crcdisk - ok
    10:51:37.0735 1112 [ 4F5414602E2544A4554D95517948B705 ] CryptSvc C:\windows\system32\cryptsvc.dll
    10:51:37.0743 1112 CryptSvc - ok
    10:51:37.0856 1112 [ 72794D112CBAFF3BC0C29BF7350D4741 ] cvhsvc C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
    10:51:37.0873 1112 cvhsvc - ok
    10:51:37.0940 1112 [ 5C627D1B1138676C0A7AB2C2C190D123 ] DcomLaunch C:\windows\system32\rpcss.dll
    10:51:37.0980 1112 DcomLaunch - ok
    10:51:38.0025 1112 [ 3CEC7631A84943677AA8FA8EE5B6B43D ] defragsvc C:\windows\System32\defragsvc.dll
    10:51:38.0033 1112 defragsvc - ok
    10:51:38.0061 1112 [ 9BB2EF44EAA163B29C4A4587887A0FE4 ] DfsC C:\windows\system32\Drivers\dfsc.sys
    10:51:38.0065 1112 DfsC - ok
    10:51:38.0108 1112 [ 43D808F5D9E1A18E5EEB5EBC83969E4E ] Dhcp C:\windows\system32\dhcpcore.dll
    10:51:38.0118 1112 Dhcp - ok
    10:51:38.0159 1112 [ 13096B05847EC78F0977F2C0F79E9AB3 ] discache C:\windows\system32\drivers\discache.sys
    10:51:38.0162 1112 discache - ok
    10:51:38.0217 1112 [ 9819EEE8B5EA3784EC4AF3B137A5244C ] Disk C:\windows\system32\drivers\disk.sys
    10:51:38.0220 1112 Disk - ok
    10:51:38.0389 1112 [ 16835866AAA693C7D7FCEBA8FFF706E4 ] Dnscache C:\windows\System32\dnsrslvr.dll
    10:51:38.0397 1112 Dnscache - ok
    10:51:38.0437 1112 [ B1FB3DDCA0FDF408750D5843591AFBC6 ] dot3svc C:\windows\System32\dot3svc.dll
    10:51:38.0445 1112 dot3svc - ok
    10:51:38.0540 1112 [ B26F4F737E8F9DF4F31AF6CF31D05820 ] DPS C:\windows\system32\dps.dll
    10:51:38.0546 1112 DPS - ok
    10:51:38.0604 1112 [ 9B19F34400D24DF84C858A421C205754 ] drmkaud C:\windows\system32\drivers\drmkaud.sys
    10:51:38.0607 1112 drmkaud - ok
    10:51:38.0784 1112 [ F5BEE30450E18E6B83A5012C100616FD ] DXGKrnl C:\windows\System32\drivers\dxgkrnl.sys
    10:51:38.0841 1112 DXGKrnl - ok
    10:51:38.0890 1112 EagleX64 - ok
    10:51:38.0952 1112 [ E2DDA8726DA9CB5B2C4000C9018A9633 ] EapHost C:\windows\System32\eapsvc.dll
    10:51:38.0961 1112 EapHost - ok
    10:51:39.0097 1112 [ DC5D737F51BE844D8C82C695EB17372F ] ebdrv C:\windows\system32\drivers\evbda.sys
    10:51:39.0148 1112 ebdrv - ok
    10:51:39.0217 1112 [ 0C3F9EFF8DDD9F9EB56D754B4620155F ] eeCtrl C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys
    10:51:39.0230 1112 eeCtrl - ok
    10:51:39.0264 1112 [ C118A82CD78818C29AB228366EBF81C3 ] EFS C:\windows\System32\lsass.exe
    10:51:39.0270 1112 EFS - ok
    10:51:39.0343 1112 [ C4002B6B41975F057D98C439030CEA07 ] ehRecvr C:\windows\ehome\ehRecvr.exe
    10:51:39.0360 1112 ehRecvr - ok
    10:51:39.0399 1112 [ 4705E8EF9934482C5BB488CE28AFC681 ] ehSched C:\windows\ehome\ehsched.exe
    10:51:39.0404 1112 ehSched - ok
    10:51:39.0472 1112 [ 0E5DA5369A0FCAEA12456DD852545184 ] elxstor C:\windows\system32\drivers\elxstor.sys
    10:51:39.0482 1112 elxstor - ok
    10:51:39.0530 1112 [ 8C0F9B877BC0B7FFD327EF55F9EFB642 ] EraserUtilRebootDrv C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
    10:51:39.0533 1112 EraserUtilRebootDrv - ok
    10:51:39.0563 1112 [ 34A3C54752046E79A126E15C51DB409B ] ErrDev C:\windows\system32\drivers\errdev.sys
    10:51:39.0567 1112 ErrDev - ok
    10:51:39.0638 1112 [ 5D82D501D2FEE413B1F45F0302B5802C ] ETD C:\windows\system32\DRIVERS\ETD.sys
    10:51:39.0645 1112 ETD - ok
    10:51:39.0722 1112 [ 4166F82BE4D24938977DD1746BE9B8A0 ] EventSystem C:\windows\system32\es.dll
    10:51:39.0734 1112 EventSystem - ok
    10:51:39.0772 1112 [ A510C654EC00C1E9BDD91EEB3A59823B ] exfat C:\windows\system32\drivers\exfat.sys
    10:51:39.0778 1112 exfat - ok
    10:51:39.0809 1112 [ 0ADC83218B66A6DB380C330836F3E36D ] fastfat C:\windows\system32\drivers\fastfat.sys
    10:51:39.0815 1112 fastfat - ok
    10:51:39.0856 1112 [ DBEFD454F8318A0EF691FDD2EAAB44EB ] Fax C:\windows\system32\fxssvc.exe
    10:51:39.0869 1112 Fax - ok
    10:51:39.0905 1112 [ D765D19CD8EF61F650C384F62FAC00AB ] fdc C:\windows\system32\drivers\fdc.sys
    10:51:39.0908 1112 fdc - ok
    10:51:39.0949 1112 [ 0438CAB2E03F4FB61455A7956026FE86 ] fdPHost C:\windows\system32\fdPHost.dll
    10:51:39.0954 1112 fdPHost - ok
    10:51:39.0972 1112 [ 802496CB59A30349F9A6DD22D6947644 ] FDResPub C:\windows\system32\fdrespub.dll
    10:51:39.0977 1112 FDResPub - ok
    10:51:40.0002 1112 [ 655661BE46B5F5F3FD454E2C3095B930 ] FileInfo C:\windows\system32\drivers\fileinfo.sys
    10:51:40.0006 1112 FileInfo - ok
    10:51:40.0029 1112 [ 5F671AB5BC87EEA04EC38A6CD5962A47 ] Filetrace C:\windows\system32\drivers\filetrace.sys
    10:51:40.0032 1112 Filetrace - ok
    10:51:40.0078 1112 [ C172A0F53008EAEB8EA33FE10E177AF5 ] flpydisk C:\windows\system32\drivers\flpydisk.sys
    10:51:40.0081 1112 flpydisk - ok
    10:51:40.0115 1112 [ DA6B67270FD9DB3697B20FCE94950741 ] FltMgr C:\windows\system32\drivers\fltmgr.sys
    10:51:40.0122 1112 FltMgr - ok
    10:51:40.0172 1112 [ 5C4CB4086FB83115B153E47ADD961A0C ] FontCache C:\windows\system32\FntCache.dll
    10:51:40.0188 1112 FontCache - ok
    10:51:40.0247 1112 [ A8B7F3818AB65695E3A0BB3279F6DCE6 ] FontCache3.0.0.0 C:\windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    10:51:40.0250 1112 FontCache3.0.0.0 - ok
    10:51:40.0280 1112 [ D43703496149971890703B4B1B723EAC ] FsDepends C:\windows\system32\drivers\FsDepends.sys
    10:51:40.0284 1112 FsDepends - ok
    10:51:40.0327 1112 [ 6BD9295CC032DD3077C671FCCF579A7B ] Fs_Rec C:\windows\system32\drivers\Fs_Rec.sys
    10:51:40.0331 1112 Fs_Rec - ok
    10:51:40.0376 1112 [ 1F7B25B858FA27015169FE95E54108ED ] fvevol C:\windows\system32\DRIVERS\fvevol.sys
    10:51:40.0415 1112 fvevol - ok
    10:51:40.0600 1112 [ 60ACB128E64C35C2B4E4AAB1B0A5C293 ] FwLnk C:\windows\system32\DRIVERS\FwLnk.sys
    10:51:40.0623 1112 FwLnk - ok
    10:51:40.0778 1112 [ 8C778D335C9D272CFD3298AB02ABE3B6 ] gagp30kx C:\windows\system32\drivers\gagp30kx.sys
    10:51:40.0782 1112 gagp30kx - ok
    10:51:40.0857 1112 [ C403C5DB49A0F9AAF4F2128EDC0106D8 ] GamesAppService C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
    10:51:40.0865 1112 GamesAppService - ok
    10:51:40.0899 1112 [ E403AACF8C7BB11375122D2464560311 ] GEARAspiWDM C:\windows\system32\DRIVERS\GEARAspiWDM.sys
    10:51:40.0904 1112 GEARAspiWDM - ok
    10:51:40.0978 1112 [ 277BBC7E1AA1EE957F573A10ECA7EF3A ] gpsvc C:\windows\System32\gpsvc.dll
    10:51:41.0001 1112 gpsvc - ok
    10:51:41.0098 1112 [ F02A533F517EB38333CB12A9E8963773 ] gupdate C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    10:51:41.0102 1112 gupdate - ok
    10:51:41.0118 1112 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    10:51:41.0122 1112 gupdatem - ok
    10:51:41.0162 1112 [ F2523EF6460FC42405B12248338AB2F0 ] hcw85cir C:\windows\system32\drivers\hcw85cir.sys
    10:51:41.0165 1112 hcw85cir - ok
    10:51:41.0208 1112 [ 975761C778E33CD22498059B91E7373A ] HdAudAddService C:\windows\system32\drivers\HdAudio.sys
    10:51:41.0217 1112 HdAudAddService - ok
    10:51:41.0259 1112 [ 97BFED39B6B79EB12CDDBFEED51F56BB ] HDAudBus C:\windows\system32\DRIVERS\HDAudBus.sys
    10:51:41.0263 1112 HDAudBus - ok
    10:51:41.0294 1112 [ 78E86380454A7B10A5EB255DC44A355F ] HidBatt C:\windows\system32\drivers\HidBatt.sys
    10:51:41.0297 1112 HidBatt - ok
    10:51:41.0320 1112 [ 7FD2A313F7AFE5C4DAB14798C48DD104 ] HidBth C:\windows\system32\drivers\hidbth.sys
    10:51:41.0324 1112 HidBth - ok
    10:51:41.0350 1112 [ 0A77D29F311B88CFAE3B13F9C1A73825 ] HidIr C:\windows\system32\drivers\hidir.sys
    10:51:41.0354 1112 HidIr - ok
    10:51:41.0380 1112 [ BD9EB3958F213F96B97B1D897DEE006D ] hidserv C:\windows\system32\hidserv.dll
    10:51:41.0386 1112 hidserv - ok
    10:51:41.0436 1112 [ 9592090A7E2B61CD582B612B6DF70536 ] HidUsb C:\windows\system32\drivers\hidusb.sys
    10:51:41.0440 1112 HidUsb - ok
    10:51:41.0484 1112 [ 387E72E739E15E3D37907A86D9FF98E2 ] hkmsvc C:\windows\system32\kmsvc.dll
    10:51:41.0492 1112 hkmsvc - ok
    10:51:41.0518 1112 [ EFDFB3DD38A4376F93E7985173813ABD ] HomeGroupListener C:\windows\system32\ListSvc.dll
    10:51:41.0528 1112 HomeGroupListener - ok
    10:51:41.0568 1112 [ 908ACB1F594274965A53926B10C81E89 ] HomeGroupProvider C:\windows\system32\provsvc.dll
    10:51:41.0577 1112 HomeGroupProvider - ok
    10:51:41.0611 1112 [ 39D2ABCD392F3D8A6DCE7B60AE7B8EFC ] HpSAMD C:\windows\system32\drivers\HpSAMD.sys
    10:51:41.0615 1112 HpSAMD - ok
    10:51:41.0671 1112 [ 0EA7DE1ACB728DD5A369FD742D6EEE28 ] HTTP C:\windows\system32\drivers\HTTP.sys
    10:51:41.0684 1112 HTTP - ok
    10:51:41.0715 1112 [ A5462BD6884960C9DC85ED49D34FF392 ] hwpolicy C:\windows\system32\drivers\hwpolicy.sys
    10:51:41.0717 1112 hwpolicy - ok
    10:51:41.0760 1112 [ FA55C73D4AFFA7EE23AC4BE53B4592D3 ] i8042prt C:\windows\system32\DRIVERS\i8042prt.sys
    10:51:41.0764 1112 i8042prt - ok
    10:51:41.0798 1112 [ AAAF44DB3BD0B9D1FB6969B23ECC8366 ] iaStorV C:\windows\system32\drivers\iaStorV.sys
    10:51:41.0808 1112 iaStorV - ok
    10:51:41.0876 1112 [ 5988FC40F8DB5B0739CD1E3A5D0D78BD ] idsvc C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe
    10:51:41.0891 1112 idsvc - ok
    10:51:41.0960 1112 [ 18C40C3F368323B203ACE403CB430DB1 ] IDSVia64 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120229.002\IDSvia64.sys
    10:51:41.0971 1112 IDSVia64 - ok
    10:51:42.0012 1112 [ 5C18831C61933628F5BB0EA2675B9D21 ] iirsp C:\windows\system32\drivers\iirsp.sys
    10:51:42.0015 1112 iirsp - ok
    10:51:42.0083 1112 [ FCD84C381E0140AF901E58D48882D26B ] IKEEXT C:\windows\System32\ikeext.dll
    10:51:42.0103 1112 IKEEXT - ok
    10:51:42.0138 1112 [ F00F20E70C6EC3AA366910083A0518AA ] intelide C:\windows\system32\drivers\intelide.sys
    10:51:42.0142 1112 intelide - ok
    10:51:42.0187 1112 [ ADA036632C664CAA754079041CF1F8C1 ] intelppm C:\windows\system32\drivers\intelppm.sys
    10:51:42.0190 1112 intelppm - ok
    10:51:42.0231 1112 [ 098A91C54546A3B878DAD6A7E90A455B ] IPBusEnum C:\windows\system32\ipbusenum.dll
    10:51:42.0239 1112 IPBusEnum - ok
    10:51:42.0260 1112 [ C9F0E1BD74365A8771590E9008D22AB6 ] IpFilterDriver C:\windows\system32\DRIVERS\ipfltdrv.sys
    10:51:42.0264 1112 IpFilterDriver - ok
    10:51:42.0287 1112 [ 0FC1AEA580957AA8817B8F305D18CA3A ] IPMIDRV C:\windows\system32\drivers\IPMIDrv.sys
    10:51:42.0292 1112 IPMIDRV - ok
    10:51:42.0334 1112 [ AF9B39A7E7B6CAA203B3862582E9F2D0 ] IPNAT C:\windows\system32\drivers\ipnat.sys
    10:51:42.0339 1112 IPNAT - ok
  13. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    10:51:42.0413 1112 [ EE4C2A137C7088911A8919EFFC9812E7 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe
    10:51:42.0426 1112 iPod Service - ok
    10:51:42.0460 1112 [ 3ABF5E7213EB28966D55D58B515D5CE9 ] IRENUM C:\windows\system32\drivers\irenum.sys
    10:51:42.0464 1112 IRENUM - ok
    10:51:42.0495 1112 [ 2F7B28DC3E1183E5EB418DF55C204F38 ] isapnp C:\windows\system32\drivers\isapnp.sys
    10:51:42.0498 1112 isapnp - ok
    10:51:42.0529 1112 [ D931D7309DEB2317035B07C9F9E6B0BD ] iScsiPrt C:\windows\system32\drivers\msiscsi.sys
    10:51:42.0537 1112 iScsiPrt - ok
    10:51:42.0576 1112 [ BC02336F1CBA7DCC7D1213BB588A68A5 ] kbdclass C:\windows\system32\DRIVERS\kbdclass.sys
    10:51:42.0580 1112 kbdclass - ok
    10:51:42.0612 1112 [ 0705EFF5B42A9DB58548EEC3B26BB484 ] kbdhid C:\windows\system32\drivers\kbdhid.sys
    10:51:42.0615 1112 kbdhid - ok
    10:51:42.0643 1112 [ C118A82CD78818C29AB228366EBF81C3 ] KeyIso C:\windows\system32\lsass.exe
    10:51:42.0648 1112 KeyIso - ok
    10:51:42.0711 1112 [ 97A7070AEA4C058B6418519E869A63B4 ] KSecDD C:\windows\system32\Drivers\ksecdd.sys
    10:51:42.0716 1112 KSecDD - ok
    10:51:42.0748 1112 [ 26C43A7C2862447EC59DEDA188D1DA07 ] KSecPkg C:\windows\system32\Drivers\ksecpkg.sys
    10:51:42.0754 1112 KSecPkg - ok
    10:51:42.0809 1112 [ 6869281E78CB31A43E969F06B57347C4 ] ksthunk C:\windows\system32\drivers\ksthunk.sys
    10:51:42.0812 1112 ksthunk - ok
    10:51:42.0865 1112 [ 6AB66E16AA859232F64DEB66887A8C9C ] KtmRm C:\windows\system32\msdtckrm.dll
    10:51:42.0878 1112 KtmRm - ok
    10:51:42.0921 1112 [ 0E154DA6CA9105354A07D0C576804037 ] L1C C:\windows\system32\DRIVERS\L1C62x64.sys
    10:51:42.0924 1112 L1C - ok
    10:51:42.0965 1112 [ D9F42719019740BAA6D1C6D536CBDAA6 ] LanmanServer C:\windows\system32\srvsvc.dll
    10:51:42.0976 1112 LanmanServer - ok
    10:51:43.0010 1112 [ 851A1382EED3E3A7476DB004F4EE3E1A ] LanmanWorkstation C:\windows\System32\wkssvc.dll
    10:51:43.0022 1112 LanmanWorkstation - ok
    10:51:43.0075 1112 [ 1538831CF8AD2979A04C423779465827 ] lltdio C:\windows\system32\DRIVERS\lltdio.sys
    10:51:43.0078 1112 lltdio - ok
    10:51:43.0117 1112 [ C1185803384AB3FEED115F79F109427F ] lltdsvc C:\windows\System32\lltdsvc.dll
    10:51:43.0127 1112 lltdsvc - ok
    10:51:43.0151 1112 [ F993A32249B66C9D622EA5592A8B76B8 ] lmhosts C:\windows\System32\lmhsvc.dll
    10:51:43.0157 1112 lmhosts - ok
    10:51:43.0197 1112 [ 1A93E54EB0ECE102495A51266DCDB6A6 ] LSI_FC C:\windows\system32\drivers\lsi_fc.sys
    10:51:43.0201 1112 LSI_FC - ok
    10:51:43.0227 1112 [ 1047184A9FDC8BDBFF857175875EE810 ] LSI_SAS C:\windows\system32\drivers\lsi_sas.sys
    10:51:43.0231 1112 LSI_SAS - ok
    10:51:43.0251 1112 [ 30F5C0DE1EE8B5BC9306C1F0E4A75F93 ] LSI_SAS2 C:\windows\system32\drivers\lsi_sas2.sys
    10:51:43.0255 1112 LSI_SAS2 - ok
    10:51:43.0275 1112 [ 0504EACAFF0D3C8AED161C4B0D369D4A ] LSI_SCSI C:\windows\system32\drivers\lsi_scsi.sys
    10:51:43.0279 1112 LSI_SCSI - ok
    10:51:43.0309 1112 [ 43D0F98E1D56CCDDB0D5254CFF7B356E ] luafv C:\windows\system32\drivers\luafv.sys
    10:51:43.0312 1112 luafv - ok
    10:51:43.0427 1112 [ FD3AD5E1ECDAA94A89D6697F5C5465D6 ] McComponentHostService C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe
    10:51:43.0435 1112 McComponentHostService - ok
    10:51:43.0506 1112 [ 0BE09CD858ABF9DF6ED259D57A1A1663 ] Mcx2Svc C:\windows\system32\Mcx2Svc.dll
    10:51:43.0517 1112 Mcx2Svc - ok
    10:51:43.0549 1112 [ A55805F747C6EDB6A9080D7C633BD0F4 ] megasas C:\windows\system32\drivers\megasas.sys
    10:51:43.0553 1112 megasas - ok
    10:51:43.0612 1112 [ BAF74CE0072480C3B6B7C13B2A94D6B3 ] MegaSR C:\windows\system32\drivers\MegaSR.sys
    10:51:43.0620 1112 MegaSR - ok
    10:51:43.0640 1112 [ E40E80D0304A73E8D269F7141D77250B ] MMCSS C:\windows\system32\mmcss.dll
    10:51:43.0648 1112 MMCSS - ok
    10:51:43.0672 1112 [ 800BA92F7010378B09F9ED9270F07137 ] Modem C:\windows\system32\drivers\modem.sys
    10:51:43.0676 1112 Modem - ok
    10:51:43.0712 1112 [ B03D591DC7DA45ECE20B3B467E6AADAA ] monitor C:\windows\system32\DRIVERS\monitor.sys
    10:51:43.0714 1112 monitor - ok
    10:51:43.0751 1112 [ 7D27EA49F3C1F687D357E77A470AEA99 ] mouclass C:\windows\system32\DRIVERS\mouclass.sys
    10:51:43.0755 1112 mouclass - ok
    10:51:43.0786 1112 [ D3BF052C40B0C4166D9FD86A4288C1E6 ] mouhid C:\windows\system32\drivers\mouhid.sys
    10:51:43.0790 1112 mouhid - ok
    10:51:43.0823 1112 [ 32E7A3D591D671A6DF2DB515A5CBE0FA ] mountmgr C:\windows\system32\drivers\mountmgr.sys
    10:51:43.0827 1112 mountmgr - ok
    10:51:43.0895 1112 [ 46297FA8E30A6007F14118FC2B942FBC ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
    10:51:43.0901 1112 MozillaMaintenance - ok
    10:51:43.0952 1112 [ A44B420D30BD56E145D6A2BC8768EC58 ] mpio C:\windows\system32\drivers\mpio.sys
    10:51:43.0957 1112 mpio - ok
    10:51:44.0000 1112 [ 6C38C9E45AE0EA2FA5E551F2ED5E978F ] mpsdrv C:\windows\system32\drivers\mpsdrv.sys
    10:51:44.0004 1112 mpsdrv - ok
    10:51:44.0038 1112 [ DC722758B8261E1ABAFD31A3C0A66380 ] MRxDAV C:\windows\system32\drivers\mrxdav.sys
    10:51:44.0043 1112 MRxDAV - ok
    10:51:44.0073 1112 [ A5D9106A73DC88564C825D317CAC68AC ] mrxsmb C:\windows\system32\DRIVERS\mrxsmb.sys
    10:51:44.0079 1112 mrxsmb - ok
    10:51:44.0100 1112 [ D711B3C1D5F42C0C2415687BE09FC163 ] mrxsmb10 C:\windows\system32\DRIVERS\mrxsmb10.sys
    10:51:44.0107 1112 mrxsmb10 - ok
    10:51:44.0130 1112 [ 9423E9D355C8D303E76B8CFBD8A5C30C ] mrxsmb20 C:\windows\system32\DRIVERS\mrxsmb20.sys
    10:51:44.0135 1112 mrxsmb20 - ok
    10:51:44.0159 1112 [ C25F0BAFA182CBCA2DD3C851C2E75796 ] msahci C:\windows\system32\drivers\msahci.sys
    10:51:44.0162 1112 msahci - ok
    10:51:44.0187 1112 [ DB801A638D011B9633829EB6F663C900 ] msdsm C:\windows\system32\drivers\msdsm.sys
    10:51:44.0192 1112 msdsm - ok
    10:51:44.0216 1112 [ DE0ECE52236CFA3ED2DBFC03F28253A8 ] MSDTC C:\windows\System32\msdtc.exe
    10:51:44.0225 1112 MSDTC - ok
    10:51:44.0256 1112 [ AA3FB40E17CE1388FA1BEDAB50EA8F96 ] Msfs C:\windows\system32\drivers\Msfs.sys
    10:51:44.0259 1112 Msfs - ok
    10:51:44.0282 1112 [ F9D215A46A8B9753F61767FA72A20326 ] mshidkmdf C:\windows\System32\drivers\mshidkmdf.sys
    10:51:44.0285 1112 mshidkmdf - ok
    10:51:44.0304 1112 [ D916874BBD4F8B07BFB7FA9B3CCAE29D ] msisadrv C:\windows\system32\drivers\msisadrv.sys
    10:51:44.0306 1112 msisadrv - ok
    10:51:44.0344 1112 [ 808E98FF49B155C522E6400953177B08 ] MSiSCSI C:\windows\system32\iscsiexe.dll
    10:51:44.0351 1112 MSiSCSI - ok
    10:51:44.0363 1112 msiserver - ok
    10:51:44.0401 1112 [ 49CCF2C4FEA34FFAD8B1B59D49439366 ] MSKSSRV C:\windows\system32\drivers\MSKSSRV.sys
    10:51:44.0405 1112 MSKSSRV - ok
    10:51:44.0451 1112 [ BDD71ACE35A232104DDD349EE70E1AB3 ] MSPCLOCK C:\windows\system32\drivers\MSPCLOCK.sys
    10:51:44.0453 1112 MSPCLOCK - ok
    10:51:44.0464 1112 [ 4ED981241DB27C3383D72092B618A1D0 ] MSPQM C:\windows\system32\drivers\MSPQM.sys
    10:51:44.0467 1112 MSPQM - ok
    10:51:44.0516 1112 [ 759A9EEB0FA9ED79DA1FB7D4EF78866D ] MsRPC C:\windows\system32\drivers\MsRPC.sys
    10:51:44.0525 1112 MsRPC - ok
    10:51:44.0549 1112 [ 0EED230E37515A0EAEE3C2E1BC97B288 ] mssmbios C:\windows\system32\DRIVERS\mssmbios.sys
    10:51:44.0552 1112 mssmbios - ok
    10:51:44.0575 1112 [ 2E66F9ECB30B4221A318C92AC2250779 ] MSTEE C:\windows\system32\drivers\MSTEE.sys
    10:51:44.0578 1112 MSTEE - ok
    10:51:44.0603 1112 [ 7EA404308934E675BFFDE8EDF0757BCD ] MTConfig C:\windows\system32\drivers\MTConfig.sys
    10:51:44.0606 1112 MTConfig - ok
    10:51:44.0635 1112 [ F9A18612FD3526FE473C1BDA678D61C8 ] Mup C:\windows\system32\Drivers\mup.sys
    10:51:44.0639 1112 Mup - ok
    10:51:44.0715 1112 [ 582AC6D9873E31DFA28A4547270862DD ] napagent C:\windows\system32\qagentRT.dll
    10:51:44.0736 1112 napagent - ok
    10:51:44.0780 1112 [ 1EA3749C4114DB3E3161156FFFFA6B33 ] NativeWifiP C:\windows\system32\DRIVERS\nwifi.sys
    10:51:44.0788 1112 NativeWifiP - ok
    10:51:44.0850 1112 [ 2DBE90210DE76BE6E1653BB20EC70EC2 ] NAVENG C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120229.002\ENG64.SYS
    10:51:44.0855 1112 NAVENG - ok
    10:51:44.0929 1112 [ 346DA70E203B8E2C850277713DE8F71B ] NAVEX15 C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120229.002\EX64.SYS
    10:51:44.0965 1112 NAVEX15 - ok
    10:51:45.0011 1112 [ 79B47FD40D9A817E932F9D26FAC0A81C ] NDIS C:\windows\system32\drivers\ndis.sys
    10:51:45.0027 1112 NDIS - ok
    10:51:45.0060 1112 [ 9F9A1F53AAD7DA4D6FEF5BB73AB811AC ] NdisCap C:\windows\system32\DRIVERS\ndiscap.sys
    10:51:45.0063 1112 NdisCap - ok
    10:51:45.0104 1112 [ 30639C932D9FEF22B31268FE25A1B6E5 ] NdisTapi C:\windows\system32\DRIVERS\ndistapi.sys
    10:51:45.0107 1112 NdisTapi - ok
    10:51:45.0125 1112 [ 136185F9FB2CC61E573E676AA5402356 ] Ndisuio C:\windows\system32\DRIVERS\ndisuio.sys
    10:51:45.0129 1112 Ndisuio - ok
    10:51:45.0148 1112 [ 53F7305169863F0A2BDDC49E116C2E11 ] NdisWan C:\windows\system32\DRIVERS\ndiswan.sys
    10:51:45.0154 1112 NdisWan - ok
    10:51:45.0170 1112 [ 015C0D8E0E0421B4CFD48CFFE2825879 ] NDProxy C:\windows\system32\drivers\NDProxy.sys
    10:51:45.0174 1112 NDProxy - ok
    10:51:45.0208 1112 [ 6F4607E2333FE21E9E3FF8133A88B35B ] Netaapl C:\windows\system32\DRIVERS\netaapl64.sys
    10:51:45.0212 1112 Netaapl - ok
  14. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    10:51:45.0241 1112 [ 86743D9F5D2B1048062B14B1D84501C4 ] NetBIOS C:\windows\system32\DRIVERS\netbios.sys
    10:51:45.0244 1112 NetBIOS - ok
    10:51:45.0260 1112 [ 09594D1089C523423B32A4229263F068 ] NetBT C:\windows\system32\DRIVERS\netbt.sys
    10:51:45.0266 1112 NetBT - ok
    10:51:45.0287 1112 [ C118A82CD78818C29AB228366EBF81C3 ] Netlogon C:\windows\system32\lsass.exe
    10:51:45.0292 1112 Netlogon - ok
    10:51:45.0331 1112 [ 847D3AE376C0817161A14A82C8922A9E ] Netman C:\windows\System32\netman.dll
    10:51:45.0342 1112 Netman - ok
    10:51:45.0372 1112 [ 5F28111C648F1E24F7DBC87CDEB091B8 ] netprofm C:\windows\System32\netprofm.dll
    10:51:45.0386 1112 netprofm - ok
    10:51:45.0425 1112 [ 3E5A36127E201DDF663176B66828FAFE ] NetTcpPortSharing C:\windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe
    10:51:45.0430 1112 NetTcpPortSharing - ok
    10:51:45.0465 1112 [ 77889813BE4D166CDAB78DDBA990DA92 ] nfrd960 C:\windows\system32\drivers\nfrd960.sys
    10:51:45.0470 1112 nfrd960 - ok
    10:51:45.0562 1112 [ F2840DBFE9322F35557219AE82CC4597 ] NIS C:\Program Files (x86)\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe
    10:51:45.0566 1112 NIS - ok
    10:51:45.0628 1112 [ 1EE99A89CC788ADA662441D1E9830529 ] NlaSvc C:\windows\System32\nlasvc.dll
    10:51:45.0641 1112 NlaSvc - ok
    10:51:45.0678 1112 Norton PC Checkup Application Launcher - ok
    10:51:45.0718 1112 [ 1E4C4AB5C9B8DD13179BBDC75A2A01F7 ] Npfs C:\windows\system32\drivers\Npfs.sys
    10:51:45.0722 1112 Npfs - ok
    10:51:45.0755 1112 npggsvc - ok
    10:51:45.0801 1112 [ D54BFDF3E0C953F823B3D0BFE4732528 ] nsi C:\windows\system32\nsisvc.dll
    10:51:45.0809 1112 nsi - ok
    10:51:45.0829 1112 [ E7F5AE18AF4168178A642A9247C63001 ] nsiproxy C:\windows\system32\drivers\nsiproxy.sys
    10:51:45.0831 1112 nsiproxy - ok
    10:51:45.0913 1112 [ A2F74975097F52A00745F9637451FDD8 ] Ntfs C:\windows\system32\drivers\Ntfs.sys
    10:51:45.0944 1112 Ntfs - ok
    10:51:45.0968 1112 [ 9899284589F75FA8724FF3D16AED75C1 ] Null C:\windows\system32\drivers\Null.sys
    10:51:45.0971 1112 Null - ok
    10:51:45.0998 1112 [ 0A92CB65770442ED0DC44834632F66AD ] nvraid C:\windows\system32\drivers\nvraid.sys
    10:51:46.0004 1112 nvraid - ok
    10:51:46.0025 1112 [ DAB0E87525C10052BF65F06152F37E4A ] nvstor C:\windows\system32\drivers\nvstor.sys
    10:51:46.0031 1112 nvstor - ok
    10:51:46.0071 1112 [ 270D7CD42D6E3979F6DD0146650F0E05 ] nv_agp C:\windows\system32\drivers\nv_agp.sys
    10:51:46.0075 1112 nv_agp - ok
    10:51:46.0094 1112 [ 3589478E4B22CE21B41FA1BFC0B8B8A0 ] ohci1394 C:\windows\system32\drivers\ohci1394.sys
    10:51:46.0098 1112 ohci1394 - ok
    10:51:46.0146 1112 [ 9D10F99A6712E28F8ACD5641E3A7EA6B ] ose C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
    10:51:46.0152 1112 ose - ok
    10:51:46.0343 1112 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    10:51:46.0428 1112 osppsvc - ok
    10:51:46.0479 1112 [ 3EAC4455472CC2C97107B5291E0DCAFE ] p2pimsvc C:\windows\system32\pnrpsvc.dll
    10:51:46.0492 1112 p2pimsvc - ok
    10:51:46.0521 1112 [ 927463ECB02179F88E4B9A17568C63C3 ] p2psvc C:\windows\system32\p2psvc.dll
    10:51:46.0535 1112 p2psvc - ok
    10:51:46.0572 1112 [ 0086431C29C35BE1DBC43F52CC273887 ] Parport C:\windows\system32\drivers\parport.sys
    10:51:46.0576 1112 Parport - ok
    10:51:46.0614 1112 [ E9766131EEADE40A27DC27D2D68FBA9C ] partmgr C:\windows\system32\drivers\partmgr.sys
    10:51:46.0620 1112 partmgr - ok
    10:51:46.0651 1112 [ 3AEAA8B561E63452C655DC0584922257 ] PcaSvc C:\windows\System32\pcasvc.dll
    10:51:46.0661 1112 PcaSvc - ok
    10:51:46.0711 1112 [ 2F86BE1818C2D7AC90478E3323EE7FCB ] PCCUJobMgr C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.13.11\ccSvcHst.exe
    10:51:46.0716 1112 PCCUJobMgr - ok
    10:51:46.0776 1112 [ 94575C0571D1462A0F70BDE6BD6EE6B3 ] pci C:\windows\system32\drivers\pci.sys
    10:51:46.0783 1112 pci - ok
    10:51:46.0820 1112 [ B5B8B5EF2E5CB34DF8DCF8831E3534FA ] pciide C:\windows\system32\DRIVERS\pciide.sys
    10:51:46.0824 1112 pciide - ok
    10:51:46.0855 1112 [ B2E81D4E87CE48589F98CB8C05B01F2F ] pcmcia C:\windows\system32\drivers\pcmcia.sys
    10:51:46.0862 1112 pcmcia - ok
    10:51:46.0895 1112 [ D6B9C2E1A11A3A4B26A182FFEF18F603 ] pcw C:\windows\system32\drivers\pcw.sys
    10:51:46.0899 1112 pcw - ok
    10:51:46.0928 1112 [ 68769C3356B3BE5D1C732C97B9A80D6E ] PEAUTH C:\windows\system32\drivers\peauth.sys
    10:51:46.0940 1112 PEAUTH - ok
    10:51:47.0063 1112 [ E495E408C93141E8FC72DC0C6046DDFA ] PerfHost C:\windows\SysWow64\perfhost.exe
    10:51:47.0071 1112 PerfHost - ok
    10:51:47.0127 1112 [ 91111CEBBDE8015E822C46120ED9537C ] PGEffect C:\windows\system32\DRIVERS\pgeffect.sys
    10:51:47.0131 1112 PGEffect - ok
    10:51:47.0196 1112 [ C7CF6A6E137463219E1259E3F0F0DD6C ] pla C:\windows\system32\pla.dll
    10:51:47.0228 1112 pla - ok
    10:51:47.0283 1112 [ 25FBDEF06C4D92815B353F6E792C8129 ] PlugPlay C:\windows\system32\umpnpmgr.dll
    10:51:47.0306 1112 PlugPlay - ok
    10:51:47.0336 1112 [ 7195581CEC9BB7D12ABE54036ACC2E38 ] PNRPAutoReg C:\windows\system32\pnrpauto.dll
    10:51:47.0344 1112 PNRPAutoReg - ok
    10:51:47.0369 1112 [ 3EAC4455472CC2C97107B5291E0DCAFE ] PNRPsvc C:\windows\system32\pnrpsvc.dll
    10:51:47.0380 1112 PNRPsvc - ok
    10:51:47.0434 1112 [ 4F15D75ADF6156BF56ECED6D4A55C389 ] PolicyAgent C:\windows\System32\ipsecsvc.dll
    10:51:47.0452 1112 PolicyAgent - ok
    10:51:47.0493 1112 [ 6BA9D927DDED70BD1A9CADED45F8B184 ] Power C:\windows\system32\umpo.dll
    10:51:47.0506 1112 Power - ok
    10:51:47.0551 1112 [ F92A2C41117A11A00BE01CA01A7FCDE9 ] PptpMiniport C:\windows\system32\DRIVERS\raspptp.sys
    10:51:47.0556 1112 PptpMiniport - ok
    10:51:47.0579 1112 [ 0D922E23C041EFB1C3FAC2A6F943C9BF ] Processor C:\windows\system32\drivers\processr.sys
    10:51:47.0583 1112 Processor - ok
    10:51:47.0635 1112 [ 53E83F1F6CF9D62F32801CF66D8352A8 ] ProfSvc C:\windows\system32\profsvc.dll
    10:51:47.0648 1112 ProfSvc - ok
    10:51:47.0665 1112 [ C118A82CD78818C29AB228366EBF81C3 ] ProtectedStorage C:\windows\system32\lsass.exe
    10:51:47.0673 1112 ProtectedStorage - ok
    10:51:47.0702 1112 [ 0557CF5A2556BD58E26384169D72438D ] Psched C:\windows\system32\DRIVERS\pacer.sys
    10:51:47.0707 1112 Psched - ok
    10:51:47.0758 1112 [ A53A15A11EBFD21077463EE2C7AFEEF0 ] ql2300 C:\windows\system32\drivers\ql2300.sys
    10:51:47.0784 1112 ql2300 - ok
    10:51:47.0824 1112 [ 4F6D12B51DE1AAEFF7DC58C4D75423C8 ] ql40xx C:\windows\system32\drivers\ql40xx.sys
    10:51:47.0829 1112 ql40xx - ok
    10:51:47.0869 1112 [ 906191634E99AEA92C4816150BDA3732 ] QWAVE C:\windows\system32\qwave.dll
    10:51:47.0881 1112 QWAVE - ok
    10:51:47.0908 1112 [ 76707BB36430888D9CE9D705398ADB6C ] QWAVEdrv C:\windows\system32\drivers\qwavedrv.sys
    10:51:47.0911 1112 QWAVEdrv - ok
    10:51:47.0931 1112 [ 5A0DA8AD5762FA2D91678A8A01311704 ] RasAcd C:\windows\system32\DRIVERS\rasacd.sys
    10:51:47.0935 1112 RasAcd - ok
    10:51:47.0967 1112 [ 7ECFF9B22276B73F43A99A15A6094E90 ] RasAgileVpn C:\windows\system32\DRIVERS\AgileVpn.sys
    10:51:47.0970 1112 RasAgileVpn - ok
    10:51:47.0990 1112 [ 8F26510C5383B8DBE976DE1CD00FC8C7 ] RasAuto C:\windows\System32\rasauto.dll
    10:51:48.0000 1112 RasAuto - ok
    10:51:48.0034 1112 [ 471815800AE33E6F1C32FB1B97C490CA ] Rasl2tp C:\windows\system32\DRIVERS\rasl2tp.sys
    10:51:48.0039 1112 Rasl2tp - ok
    10:51:48.0081 1112 [ EE867A0870FC9E4972BA9EAAD35651E2 ] RasMan C:\windows\System32\rasmans.dll
    10:51:48.0095 1112 RasMan - ok
    10:51:48.0125 1112 [ 855C9B1CD4756C5E9A2AA58A15F58C25 ] RasPppoe C:\windows\system32\DRIVERS\raspppoe.sys
    10:51:48.0130 1112 RasPppoe - ok
    10:51:48.0149 1112 [ E8B1E447B008D07FF47D016C2B0EEECB ] RasSstp C:\windows\system32\DRIVERS\rassstp.sys
    10:51:48.0154 1112 RasSstp - ok
    10:51:48.0195 1112 [ 77F665941019A1594D887A74F301FA2F ] rdbss C:\windows\system32\DRIVERS\rdbss.sys
    10:51:48.0203 1112 rdbss - ok
    10:51:48.0227 1112 [ 302DA2A0539F2CF54D7C6CC30C1F2D8D ] rdpbus C:\windows\system32\drivers\rdpbus.sys
    10:51:48.0230 1112 rdpbus - ok
    10:51:48.0255 1112 [ CEA6CC257FC9B7715F1C2B4849286D24 ] RDPCDD C:\windows\system32\DRIVERS\RDPCDD.sys
    10:51:48.0257 1112 RDPCDD - ok
    10:51:48.0289 1112 [ BB5971A4F00659529A5C44831AF22365 ] RDPENCDD C:\windows\system32\drivers\rdpencdd.sys
    10:51:48.0291 1112 RDPENCDD - ok
    10:51:48.0311 1112 [ 216F3FA57533D98E1F74DED70113177A ] RDPREFMP C:\windows\system32\drivers\rdprefmp.sys
    10:51:48.0314 1112 RDPREFMP - ok
    10:51:48.0350 1112 [ E61608AA35E98999AF9AAEEEA6114B0A ] RDPWD C:\windows\system32\drivers\RDPWD.sys
    10:51:48.0356 1112 RDPWD - ok
    10:51:48.0387 1112 [ 34ED295FA0121C241BFEF24764FC4520 ] rdyboost C:\windows\system32\drivers\rdyboost.sys
    10:51:48.0394 1112 rdyboost - ok
    10:51:48.0442 1112 [ 254FB7A22D74E5511C73A3F6D802F192 ] RemoteAccess C:\windows\System32\mprdim.dll
    10:51:48.0449 1112 RemoteAccess - ok
    10:51:48.0502 1112 [ E4D94F24081440B5FC5AA556C7C62702 ] RemoteRegistry C:\windows\system32\regsvc.dll
    10:51:48.0512 1112 RemoteRegistry - ok
  15. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    10:51:48.0537 1112 [ E4DC58CF7B3EA515AE917FF0D402A7BB ] RpcEptMapper C:\windows\System32\RpcEpMap.dll
    10:51:48.0547 1112 RpcEptMapper - ok
    10:51:48.0584 1112 [ D5BA242D4CF8E384DB90E6A8ED850B8C ] RpcLocator C:\windows\system32\locator.exe
    10:51:48.0590 1112 RpcLocator - ok
    10:51:48.0618 1112 [ 5C627D1B1138676C0A7AB2C2C190D123 ] RpcSs C:\windows\system32\rpcss.dll
    10:51:48.0632 1112 RpcSs - ok
    10:51:48.0716 1112 [ DDC86E4F8E7456261E637E3552E804FF ] rspndr C:\windows\system32\DRIVERS\rspndr.sys
    10:51:48.0721 1112 rspndr - ok
    10:51:48.0771 1112 [ 0E3DCF76F11DC431B088A2DFD7265CDA ] RSUSBSTOR C:\windows\system32\Drivers\RtsUStor.sys
    10:51:48.0778 1112 RSUSBSTOR - ok
    10:51:48.0798 1112 [ C118A82CD78818C29AB228366EBF81C3 ] SamSs C:\windows\system32\lsass.exe
    10:51:48.0805 1112 SamSs - ok
    10:51:48.0828 1112 [ AC03AF3329579FFFB455AA2DAABBE22B ] sbp2port C:\windows\system32\drivers\sbp2port.sys
    10:51:48.0833 1112 sbp2port - ok
    10:51:48.0873 1112 [ 9B7395789E3791A3B6D000FE6F8B131E ] SCardSvr C:\windows\System32\SCardSvr.dll
    10:51:48.0885 1112 SCardSvr - ok
    10:51:48.0915 1112 [ 253F38D0D7074C02FF8DEB9836C97D2B ] scfilter C:\windows\system32\DRIVERS\scfilter.sys
    10:51:48.0919 1112 scfilter - ok
    10:51:48.0961 1112 [ 262F6592C3299C005FD6BEC90FC4463A ] Schedule C:\windows\system32\schedsvc.dll
    10:51:48.0986 1112 Schedule - ok
    10:51:49.0024 1112 [ F17D1D393BBC69C5322FBFAFACA28C7F ] SCPolicySvc C:\windows\System32\certprop.dll
    10:51:49.0028 1112 SCPolicySvc - ok
    10:51:49.0069 1112 [ 6EA4234DC55346E0709560FE7C2C1972 ] SDRSVC C:\windows\System32\SDRSVC.dll
    10:51:49.0079 1112 SDRSVC - ok
    10:51:49.0106 1112 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\windows\system32\drivers\secdrv.sys
    10:51:49.0109 1112 secdrv - ok
    10:51:49.0134 1112 [ BC617A4E1B4FA8DF523A061739A0BD87 ] seclogon C:\windows\system32\seclogon.dll
    10:51:49.0143 1112 seclogon - ok
    10:51:49.0175 1112 [ C32AB8FA018EF34C0F113BD501436D21 ] SENS C:\windows\System32\sens.dll
    10:51:49.0184 1112 SENS - ok
    10:51:49.0218 1112 [ 0336CFFAFAAB87A11541F1CF1594B2B2 ] SensrSvc C:\windows\system32\sensrsvc.dll
    10:51:49.0227 1112 SensrSvc - ok
    10:51:49.0251 1112 [ CB624C0035412AF0DEBEC78C41F5CA1B ] Serenum C:\windows\system32\drivers\serenum.sys
    10:51:49.0255 1112 Serenum - ok
    10:51:49.0282 1112 [ C1D8E28B2C2ADFAEC4BA89E9FDA69BD6 ] Serial C:\windows\system32\drivers\serial.sys
    10:51:49.0288 1112 Serial - ok
    10:51:49.0318 1112 [ 1C545A7D0691CC4A027396535691C3E3 ] sermouse C:\windows\system32\drivers\sermouse.sys
    10:51:49.0322 1112 sermouse - ok
    10:51:49.0382 1112 [ 0B6231BF38174A1628C4AC812CC75804 ] SessionEnv C:\windows\system32\sessenv.dll
    10:51:49.0392 1112 SessionEnv - ok
    10:51:49.0418 1112 [ A554811BCD09279536440C964AE35BBF ] sffdisk C:\windows\system32\drivers\sffdisk.sys
    10:51:49.0431 1112 sffdisk - ok
    10:51:49.0456 1112 [ FF414F0BAEFEBA59BC6C04B3DB0B87BF ] sffp_mmc C:\windows\system32\drivers\sffp_mmc.sys
    10:51:49.0459 1112 sffp_mmc - ok
    10:51:49.0481 1112 [ DD85B78243A19B59F0637DCF284DA63C ] sffp_sd C:\windows\system32\drivers\sffp_sd.sys
    10:51:49.0485 1112 sffp_sd - ok
    10:51:49.0522 1112 [ A9D601643A1647211A1EE2EC4E433FF4 ] sfloppy C:\windows\system32\drivers\sfloppy.sys
    10:51:49.0525 1112 sfloppy - ok
    10:51:49.0586 1112 [ C6CC9297BD53E5229653303E556AA539 ] Sftfs C:\windows\system32\DRIVERS\Sftfslh.sys
    10:51:49.0601 1112 Sftfs - ok
    10:51:49.0676 1112 [ 13693B6354DD6E72DC5131DA7D764B90 ] sftlist C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
    10:51:49.0690 1112 sftlist - ok
    10:51:49.0724 1112 [ 390AA7BC52CEE43F6790CDEA1E776703 ] Sftplay C:\windows\system32\DRIVERS\Sftplaylh.sys
    10:51:49.0731 1112 Sftplay - ok
    10:51:49.0759 1112 [ 617E29A0B0A2807466560D4C4E338D3E ] Sftredir C:\windows\system32\DRIVERS\Sftredirlh.sys
    10:51:49.0762 1112 Sftredir - ok
    10:51:49.0800 1112 [ 8F571F016FA1976F445147E9E6C8AE9B ] Sftvol C:\windows\system32\DRIVERS\Sftvollh.sys
    10:51:49.0803 1112 Sftvol - ok
    10:51:49.0848 1112 [ C3CDDD18F43D44AB713CF8C4916F7696 ] sftvsa C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
    10:51:49.0854 1112 sftvsa - ok
    10:51:49.0898 1112 [ AAF932B4011D14052955D4B212A4DA8D ] ShellHWDetection C:\windows\System32\shsvcs.dll
    10:51:49.0912 1112 ShellHWDetection - ok
    10:51:49.0958 1112 [ 843CAF1E5FDE1FFD5FF768F23A51E2E1 ] SiSRaid2 C:\windows\system32\drivers\SiSRaid2.sys
    10:51:49.0962 1112 SiSRaid2 - ok
    10:51:49.0986 1112 [ 6A6C106D42E9FFFF8B9FCB4F754F6DA4 ] SiSRaid4 C:\windows\system32\drivers\sisraid4.sys
    10:51:49.0991 1112 SiSRaid4 - ok
    10:51:50.0042 1112 [ DDAA5F4A6B958FC313EBD02DD925752F ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe
    10:51:50.0047 1112 SkypeUpdate - ok
    10:51:50.0095 1112 [ 548260A7B8654E024DC30BF8A7C5BAA4 ] Smb C:\windows\system32\DRIVERS\smb.sys
    10:51:50.0100 1112 Smb - ok
    10:51:50.0149 1112 [ 6313F223E817CC09AA41811DAA7F541D ] SNMPTRAP C:\windows\System32\snmptrap.exe
    10:51:50.0158 1112 SNMPTRAP - ok
    10:51:50.0184 1112 [ B9E31E5CACDFE584F34F730A677803F9 ] spldr C:\windows\system32\drivers\spldr.sys
    10:51:50.0188 1112 spldr - ok
    10:51:50.0221 1112 [ B96C17B5DC1424D56EEA3A99E97428CD ] Spooler C:\windows\System32\spoolsv.exe
    10:51:50.0238 1112 Spooler - ok
    10:51:50.0355 1112 [ E17E0188BB90FAE42D83E98707EFA59C ] sppsvc C:\windows\system32\sppsvc.exe
    10:51:50.0412 1112 sppsvc - ok
    10:51:50.0436 1112 [ 93D7D61317F3D4BC4F4E9F8A96A7DE45 ] sppuinotify C:\windows\system32\sppuinotify.dll
    10:51:50.0446 1112 sppuinotify - ok
    10:51:50.0547 1112 [ 891793E00432FA055CF040605C260E49 ] SRTSP C:\windows\System32\Drivers\NISx64\1308000.00E\SRTSP64.SYS
    10:51:50.0559 1112 SRTSP - ok
    10:51:50.0584 1112 [ 1CB7BB3B0561FB5ECFE37F7731E8BF3E ] SRTSPX C:\windows\system32\drivers\NISx64\1308000.00E\SRTSPX64.SYS
    10:51:50.0586 1112 SRTSPX - ok
    10:51:50.0617 1112 [ 441FBA48BFF01FDB9D5969EBC1838F0B ] srv C:\windows\system32\DRIVERS\srv.sys
    10:51:50.0627 1112 srv - ok
    10:51:50.0661 1112 [ B4ADEBBF5E3677CCE9651E0F01F7CC28 ] srv2 C:\windows\system32\DRIVERS\srv2.sys
    10:51:50.0671 1112 srv2 - ok
    10:51:50.0734 1112 [ 27E461F0BE5BFF5FC737328F749538C3 ] srvnet C:\windows\system32\DRIVERS\srvnet.sys
    10:51:50.0741 1112 srvnet - ok
    10:51:50.0786 1112 [ 51B52FBD583CDE8AA9BA62B8B4298F33 ] SSDPSRV C:\windows\System32\ssdpsrv.dll
    10:51:50.0802 1112 SSDPSRV - ok
    10:51:50.0831 1112 [ AB7AEBF58DAD8DAAB7A6C45E6A8885CB ] SstpSvc C:\windows\system32\sstpsvc.dll
    10:51:50.0841 1112 SstpSvc - ok
    10:51:50.0869 1112 [ F3817967ED533D08327DC73BC4D5542A ] stexstor C:\windows\system32\drivers\stexstor.sys
    10:51:50.0872 1112 stexstor - ok
    10:51:50.0925 1112 [ 8DD52E8E6128F4B2DA92CE27402871C1 ] stisvc C:\windows\System32\wiaservc.dll
    10:51:50.0943 1112 stisvc - ok
    10:51:50.0990 1112 [ D01EC09B6711A5F8E7E6564A4D0FBC90 ] swenum C:\windows\system32\DRIVERS\swenum.sys
    10:51:50.0994 1112 swenum - ok
    10:51:51.0041 1112 [ E08E46FDD841B7184194011CA1955A0B ] swprv C:\windows\System32\swprv.dll
    10:51:51.0058 1112 swprv - ok
    10:51:51.0108 1112 [ 8B2430762099598DA40686F754632EFD ] SymDS C:\windows\system32\drivers\NISx64\1308000.00E\SYMDS64.SYS
    10:51:51.0115 1112 SymDS - ok
    10:51:51.0174 1112 [ 5CB7F2FD7E30A0F52F93574BFC3A8041 ] SymEFA C:\windows\system32\drivers\NISx64\1308000.00E\SYMEFA64.SYS
    10:51:51.0188 1112 SymEFA - ok
    10:51:51.0229 1112 [ 894579207E39C465737E850A252CE4F2 ] SymEvent C:\windows\system32\Drivers\SYMEVENT64x86.SYS
    10:51:51.0235 1112 SymEvent - ok
    10:51:51.0275 1112 [ 5013A76CAAA1D7CF1C55214B490B4E35 ] SymIRON C:\windows\system32\drivers\NISx64\1308000.00E\Ironx64.SYS
    10:51:51.0279 1112 SymIRON - ok
    10:51:51.0321 1112 [ 3911BD0E68C010E5438A87706ABBE9AB ] SymNetS C:\windows\System32\Drivers\NISx64\1308000.00E\SYMNETS.SYS
    10:51:51.0327 1112 SymNetS - ok
    10:51:51.0402 1112 [ BF9CCC0BF39B418C8D0AE8B05CF95B7D ] SysMain C:\windows\system32\sysmain.dll
    10:51:51.0436 1112 SysMain - ok
    10:51:51.0463 1112 [ E3C61FD7B7C2557E1F1B0B4CEC713585 ] TabletInputService C:\windows\System32\TabSvc.dll
    10:51:51.0473 1112 TabletInputService - ok
    10:51:51.0495 1112 [ 40F0849F65D13EE87B9A9AE3C1DD6823 ] TapiSrv C:\windows\System32\tapisrv.dll
    10:51:51.0510 1112 TapiSrv - ok
    10:51:51.0549 1112 [ 1BE03AC720F4D302EA01D40F588162F6 ] TBS C:\windows\System32\tbssvc.dll
    10:51:51.0559 1112 TBS - ok
    10:51:51.0635 1112 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] Tcpip C:\windows\system32\drivers\tcpip.sys
    10:51:51.0667 1112 Tcpip - ok
    10:51:51.0723 1112 [ ACB82BDA8F46C84F465C1AFA517DC4B9 ] TCPIP6 C:\windows\system32\DRIVERS\tcpip.sys
    10:51:51.0746 1112 TCPIP6 - ok
    10:51:51.0789 1112 [ DF687E3D8836BFB04FCC0615BF15A519 ] tcpipreg C:\windows\system32\drivers\tcpipreg.sys
    10:51:51.0793 1112 tcpipreg - ok
    10:51:51.0832 1112 [ FD542B661BD22FA69CA789AD0AC58C29 ] tdcmdpst C:\windows\system32\DRIVERS\tdcmdpst.sys
    10:51:51.0836 1112 tdcmdpst - ok
    10:51:51.0858 1112 [ 3371D21011695B16333A3934340C4E7C ] TDPIPE C:\windows\system32\drivers\tdpipe.sys
    10:51:51.0861 1112 TDPIPE - ok
    10:51:51.0895 1112 [ 51C5ECEB1CDEE2468A1748BE550CFBC8 ] TDTCP C:\windows\system32\drivers\tdtcp.sys
    10:51:51.0898 1112 TDTCP - ok
    10:51:51.0924 1112 [ DDAD5A7AB24D8B65F8D724F5C20FD806 ] tdx C:\windows\system32\DRIVERS\tdx.sys
    10:51:51.0928 1112 tdx - ok
    10:51:51.0967 1112 [ 561E7E1F06895D78DE991E01DD0FB6E5 ] TermDD C:\windows\system32\DRIVERS\termdd.sys
    10:51:51.0971 1112 TermDD - ok
    10:51:52.0018 1112 [ 2E648163254233755035B46DD7B89123 ] TermService C:\windows\System32\termsrv.dll
    10:51:52.0036 1112 TermService - ok
    10:51:52.0059 1112 [ F0344071948D1A1FA732231785A0664C ] Themes C:\windows\system32\themeservice.dll
    10:51:52.0069 1112 Themes - ok
    10:51:52.0107 1112 [ E40E80D0304A73E8D269F7141D77250B ] THREADORDER C:\windows\system32\mmcss.dll
    10:51:52.0113 1112 THREADORDER - ok
  16. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    10:51:52.0198 1112 [ 71C321649B28638EE80A2EEB164C1DC8 ] TMachInfo C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
    10:51:52.0204 1112 TMachInfo - ok
    10:51:52.0240 1112 [ 8E2C799D3476EAC32C3BA0DF7CE6AF19 ] TODDSrv C:\windows\system32\TODDSrv.exe
    10:51:52.0252 1112 TODDSrv - ok
    10:51:52.0324 1112 [ 1C73689B900428C7D054A41C4687F55C ] TosCoSrv C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
    10:51:52.0336 1112 TosCoSrv - ok
    10:51:52.0406 1112 [ A22DEB5EC05FEBFDCA1D3FF70FA1FF46 ] TOSHIBA Bluetooth Service C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
    10:51:52.0413 1112 TOSHIBA Bluetooth Service - ok
    10:51:52.0497 1112 [ 29D0886CF250FCEF1BF9E65AB8D2C0C8 ] TOSHIBA HDD SSD Alert Service C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    10:51:52.0500 1112 TOSHIBA HDD SSD Alert Service - ok
    10:51:52.0512 1112 Tosrfcom - ok
    10:51:52.0562 1112 [ F5E3AC4CBCD154EE80849B21887FD0B0 ] tosrfec C:\windows\system32\DRIVERS\tosrfec.sys
    10:51:52.0566 1112 tosrfec - ok
    10:51:52.0602 1112 [ 7A0048693F98460FF537BE31C741B927 ] Tosrfusb C:\windows\system32\DRIVERS\tosrfusb.sys
    10:51:52.0610 1112 Tosrfusb - ok
    10:51:52.0648 1112 [ 7E7AFD841694F6AC397E99D75CEAD49D ] TrkWks C:\windows\System32\trkwks.dll
    10:51:52.0661 1112 TrkWks - ok
    10:51:52.0753 1112 [ 773212B2AAA24C1E31F10246B15B276C ] TrustedInstaller C:\windows\servicing\TrustedInstaller.exe
    10:51:52.0760 1112 TrustedInstaller - ok
    10:51:52.0803 1112 [ CE18B2CDFC837C99E5FAE9CA6CBA5D30 ] tssecsrv C:\windows\system32\DRIVERS\tssecsrv.sys
    10:51:52.0807 1112 tssecsrv - ok
    10:51:52.0842 1112 [ D11C783E3EF9A3C52C0EBE83CC5000E9 ] TsUsbFlt C:\windows\system32\drivers\tsusbflt.sys
    10:51:52.0846 1112 TsUsbFlt - ok
    10:51:52.0889 1112 [ 9CC2CCAE8A84820EAECB886D477CBCB8 ] TsUsbGD C:\windows\system32\drivers\TsUsbGD.sys
    10:51:52.0893 1112 TsUsbGD - ok
    10:51:52.0937 1112 [ 3566A8DAAFA27AF944F5D705EAA64894 ] tunnel C:\windows\system32\DRIVERS\tunnel.sys
    10:51:52.0944 1112 tunnel - ok
    10:51:52.0983 1112 [ 550B567F9364D8F7684C3FB3EA665A72 ] TVALZ C:\windows\system32\DRIVERS\TVALZ_O.SYS
    10:51:52.0988 1112 TVALZ - ok
    10:51:53.0019 1112 [ B4DD609BD7E282BFC683CEC7EAAAAD67 ] uagp35 C:\windows\system32\drivers\uagp35.sys
    10:51:53.0024 1112 uagp35 - ok
    10:51:53.0060 1112 [ FF4232A1A64012BAA1FD97C7B67DF593 ] udfs C:\windows\system32\DRIVERS\udfs.sys
    10:51:53.0068 1112 udfs - ok
    10:51:53.0115 1112 [ 3CBDEC8D06B9968ABA702EBA076364A1 ] UI0Detect C:\windows\system32\UI0Detect.exe
    10:51:53.0125 1112 UI0Detect - ok
    10:51:53.0154 1112 [ 4BFE1BC28391222894CBF1E7D0E42320 ] uliagpkx C:\windows\system32\drivers\uliagpkx.sys
    10:51:53.0158 1112 uliagpkx - ok
    10:51:53.0278 1112 [ DC54A574663A895C8763AF0FA1FF7561 ] umbus C:\windows\system32\DRIVERS\umbus.sys
    10:51:53.0300 1112 umbus - ok
    10:51:53.0363 1112 [ B2E8E8CB557B156DA5493BBDDCC1474D ] UmPass C:\windows\system32\drivers\umpass.sys
    10:51:53.0368 1112 UmPass - ok
    10:51:53.0412 1112 [ D47EC6A8E81633DD18D2436B19BAF6DE ] upnphost C:\windows\System32\upnphost.dll
    10:51:53.0435 1112 upnphost - ok
    10:51:53.0470 1112 [ AA33FC47ED58C34E6E9261E4F850B7EB ] USBAAPL64 C:\windows\system32\Drivers\usbaapl64.sys
    10:51:53.0476 1112 USBAAPL64 - ok
    10:51:53.0500 1112 [ 6F1A3157A1C89435352CEB543CDB359C ] usbccgp C:\windows\system32\DRIVERS\usbccgp.sys
    10:51:53.0505 1112 usbccgp - ok
    10:51:53.0525 1112 [ AF0892A803FDDA7492F595368E3B68E7 ] usbcir C:\windows\system32\drivers\usbcir.sys
    10:51:53.0530 1112 usbcir - ok
    10:51:53.0554 1112 [ C025055FE7B87701EB042095DF1A2D7B ] usbehci C:\windows\system32\DRIVERS\usbehci.sys
    10:51:53.0558 1112 usbehci - ok
    10:51:53.0589 1112 [ 287C6C9410B111B68B52CA298F7B8C24 ] usbhub C:\windows\system32\DRIVERS\usbhub.sys
    10:51:53.0598 1112 usbhub - ok
    10:51:53.0624 1112 [ 9840FC418B4CBD632D3D0A667A725C31 ] usbohci C:\windows\system32\DRIVERS\usbohci.sys
    10:51:53.0628 1112 usbohci - ok
    10:51:53.0648 1112 [ 73188F58FB384E75C4063D29413CEE3D ] usbprint C:\windows\system32\drivers\usbprint.sys
    10:51:53.0652 1112 usbprint - ok
    10:51:53.0685 1112 [ FED648B01349A3C8395A5169DB5FB7D6 ] USBSTOR C:\windows\system32\DRIVERS\USBSTOR.SYS
    10:51:53.0689 1112 USBSTOR - ok
    10:51:53.0716 1112 [ 62069A34518BCF9C1FD9E74B3F6DB7CD ] usbuhci C:\windows\system32\drivers\usbuhci.sys
    10:51:53.0723 1112 usbuhci - ok
    10:51:53.0760 1112 [ 454800C2BC7F3927CE030141EE4F4C50 ] usbvideo C:\windows\system32\Drivers\usbvideo.sys
    10:51:53.0766 1112 usbvideo - ok
    10:51:53.0806 1112 [ EDBB23CBCF2CDF727D64FF9B51A6070E ] UxSms C:\windows\System32\uxsms.dll
    10:51:53.0816 1112 UxSms - ok
    10:51:53.0832 1112 [ C118A82CD78818C29AB228366EBF81C3 ] VaultSvc C:\windows\system32\lsass.exe
    10:51:53.0838 1112 VaultSvc - ok
    10:51:53.0865 1112 [ C5C876CCFC083FF3B128F933823E87BD ] vdrvroot C:\windows\system32\drivers\vdrvroot.sys
    10:51:53.0869 1112 vdrvroot - ok
    10:51:53.0906 1112 [ 8D6B481601D01A456E75C3210F1830BE ] vds C:\windows\System32\vds.exe
    10:51:53.0924 1112 vds - ok
    10:51:53.0950 1112 [ DA4DA3F5E02943C2DC8C6ED875DE68DD ] vga C:\windows\system32\DRIVERS\vgapnp.sys
    10:51:53.0954 1112 vga - ok
    10:51:53.0971 1112 [ 53E92A310193CB3C03BEA963DE7D9CFC ] VgaSave C:\windows\System32\drivers\vga.sys
    10:51:53.0975 1112 VgaSave - ok
    10:51:54.0006 1112 [ 2CE2DF28C83AEAF30084E1B1EB253CBB ] vhdmp C:\windows\system32\drivers\vhdmp.sys
    10:51:54.0013 1112 vhdmp - ok
    10:51:54.0049 1112 [ E5689D93FFE4E5D66C0178761240DD54 ] viaide C:\windows\system32\drivers\viaide.sys
    10:51:54.0053 1112 viaide - ok
    10:51:54.0070 1112 [ D2AAFD421940F640B407AEFAAEBD91B0 ] volmgr C:\windows\system32\drivers\volmgr.sys
    10:51:54.0074 1112 volmgr - ok
    10:51:54.0101 1112 [ A255814907C89BE58B79EF2F189B843B ] volmgrx C:\windows\system32\drivers\volmgrx.sys
    10:51:54.0110 1112 volmgrx - ok
    10:51:54.0149 1112 [ DF8126BD41180351A093A3AD2FC8903B ] volsnap C:\windows\system32\drivers\volsnap.sys
    10:51:54.0157 1112 volsnap - ok
    10:51:54.0185 1112 [ 5E2016EA6EBACA03C04FEAC5F330D997 ] vsmraid C:\windows\system32\drivers\vsmraid.sys
    10:51:54.0191 1112 vsmraid - ok
    10:51:54.0266 1112 [ B60BA0BC31B0CB414593E169F6F21CC2 ] VSS C:\windows\system32\vssvc.exe
    10:51:54.0300 1112 VSS - ok
    10:51:54.0325 1112 [ 36D4720B72B5C5D9CB2B9C29E9DF67A1 ] vwifibus C:\windows\system32\DRIVERS\vwifibus.sys
    10:51:54.0329 1112 vwifibus - ok
    10:51:54.0385 1112 [ 6A3D66263414FF0D6FA754C646612F3F ] vwififlt C:\windows\system32\DRIVERS\vwififlt.sys
    10:51:54.0389 1112 vwififlt - ok
    10:51:54.0415 1112 [ 6A638FC4BFDDC4D9B186C28C91BD1A01 ] vwifimp C:\windows\system32\DRIVERS\vwifimp.sys
    10:51:54.0421 1112 vwifimp - ok
    10:51:54.0454 1112 [ 1C9D80CC3849B3788048078C26486E1A ] W32Time C:\windows\system32\w32time.dll
    10:51:54.0469 1112 W32Time - ok
    10:51:54.0502 1112 [ 4E9440F4F152A7B944CB1663D3935A3E ] WacomPen C:\windows\system32\drivers\wacompen.sys
    10:51:54.0506 1112 WacomPen - ok
    10:51:54.0553 1112 [ 356AFD78A6ED4457169241AC3965230C ] WANARP C:\windows\system32\DRIVERS\wanarp.sys
    10:51:54.0558 1112 WANARP - ok
    10:51:54.0568 1112 [ 356AFD78A6ED4457169241AC3965230C ] Wanarpv6 C:\windows\system32\DRIVERS\wanarp.sys
    10:51:54.0571 1112 Wanarpv6 - ok
    10:51:54.0650 1112 [ 3CEC96DE223E49EAAE3651FCF8FAEA6C ] WatAdminSvc C:\windows\system32\Wat\WatAdminSvc.exe
    10:51:54.0675 1112 WatAdminSvc - ok
    10:51:54.0754 1112 [ 78F4E7F5C56CB9716238EB57DA4B6A75 ] wbengine C:\windows\system32\wbengine.exe
    10:51:54.0792 1112 wbengine - ok
    10:51:54.0825 1112 [ 3AA101E8EDAB2DB4131333F4325C76A3 ] WbioSrvc C:\windows\System32\wbiosrvc.dll
    10:51:54.0838 1112 WbioSrvc - ok
    10:51:54.0871 1112 [ 7368A2AFD46E5A4481D1DE9D14848EDD ] wcncsvc C:\windows\System32\wcncsvc.dll
    10:51:54.0886 1112 wcncsvc - ok
    10:51:54.0913 1112 [ 20F7441334B18CEE52027661DF4A6129 ] WcsPlugInService C:\windows\System32\WcsPlugInService.dll
    10:51:54.0923 1112 WcsPlugInService - ok
    10:51:54.0962 1112 [ 72889E16FF12BA0F235467D6091B17DC ] Wd C:\windows\system32\drivers\wd.sys
    10:51:54.0966 1112 Wd - ok
    10:51:55.0001 1112 [ 441BD2D7B4F98134C3A4F9FA570FD250 ] Wdf01000 C:\windows\system32\drivers\Wdf01000.sys
    10:51:55.0014 1112 Wdf01000 - ok
    10:51:55.0037 1112 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiServiceHost C:\windows\system32\wdi.dll
    10:51:55.0047 1112 WdiServiceHost - ok
    10:51:55.0060 1112 [ BF1FC3F79B863C914687A737C2F3D681 ] WdiSystemHost C:\windows\system32\wdi.dll
    10:51:55.0070 1112 WdiSystemHost - ok
    10:51:55.0098 1112 [ 3DB6D04E1C64272F8B14EB8BC4616280 ] WebClient C:\windows\System32\webclnt.dll
    10:51:55.0112 1112 WebClient - ok
    10:51:55.0143 1112 [ C749025A679C5103E575E3B48E092C43 ] Wecsvc C:\windows\system32\wecsvc.dll
    10:51:55.0156 1112 Wecsvc - ok
    10:51:55.0180 1112 [ 7E591867422DC788B9E5BD337A669A08 ] wercplsupport C:\windows\System32\wercplsupport.dll
    10:51:55.0190 1112 wercplsupport - ok
    10:51:55.0215 1112 [ 6D137963730144698CBD10F202E9F251 ] WerSvc C:\windows\System32\WerSvc.dll
    10:51:55.0225 1112 WerSvc - ok
    10:51:55.0266 1112 [ 611B23304BF067451A9FDEE01FBDD725 ] WfpLwf C:\windows\system32\DRIVERS\wfplwf.sys
    10:51:55.0270 1112 WfpLwf - ok
    10:51:55.0302 1112 [ 05ECAEC3E4529A7153B3136CEB49F0EC ] WIMMount C:\windows\system32\drivers\wimmount.sys
    10:51:55.0306 1112 WIMMount - ok
    10:51:55.0323 1112 WinHttpAutoProxySvc - ok
    10:51:55.0422 1112 [ 19B07E7E8915D701225DA41CB3877306 ] Winmgmt C:\windows\system32\wbem\WMIsvc.dll
    10:51:55.0431 1112 Winmgmt - ok
    10:51:55.0515 1112 [ BCB1310604AA415C4508708975B3931E ] WinRM C:\windows\system32\WsmSvc.dll
    10:51:55.0562 1112 WinRM - ok
    10:51:55.0629 1112 [ FE88B288356E7B47B74B13372ADD906D ] WinUsb C:\windows\system32\DRIVERS\WinUsb.sys
    10:51:55.0633 1112 WinUsb - ok
    10:51:55.0702 1112 [ 4FADA86E62F18A1B2F42BA18AE24E6AA ] Wlansvc C:\windows\System32\wlansvc.dll
    10:51:55.0735 1112 Wlansvc - ok
    10:51:55.0802 1112 [ 06C8FA1CF39DE6A735B54D906BA791C6 ] wlcrasvc C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
    10:51:55.0807 1112 wlcrasvc - ok
  17. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    10:51:55.0951 1112 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    10:51:55.0990 1112 wlidsvc - ok
    10:51:56.0019 1112 [ F6FF8944478594D0E414D3F048F0D778 ] WmiAcpi C:\windows\system32\drivers\wmiacpi.sys
    10:51:56.0024 1112 WmiAcpi - ok
    10:51:56.0066 1112 [ 38B84C94C5A8AF291ADFEA478AE54F93 ] wmiApSrv C:\windows\system32\wbem\WmiApSrv.exe
    10:51:56.0072 1112 wmiApSrv - ok
    10:51:56.0093 1112 WMPNetworkSvc - ok
    10:51:56.0135 1112 [ 96C6E7100D724C69FCF9E7BF590D1DCA ] WPCSvc C:\windows\System32\wpcsvc.dll
    10:51:56.0146 1112 WPCSvc - ok
    10:51:56.0171 1112 [ 93221146D4EBBF314C29B23CD6CC391D ] WPDBusEnum C:\windows\system32\wpdbusenum.dll
    10:51:56.0181 1112 WPDBusEnum - ok
    10:51:56.0217 1112 [ 6BCC1D7D2FD2453957C5479A32364E52 ] ws2ifsl C:\windows\system32\drivers\ws2ifsl.sys
    10:51:56.0221 1112 ws2ifsl - ok
    10:51:56.0231 1112 WSearch - ok
    10:51:56.0257 1112 [ D3381DC54C34D79B22CEE0D65BA91B7C ] WudfPf C:\windows\system32\drivers\WudfPf.sys
    10:51:56.0261 1112 WudfPf - ok
    10:51:56.0290 1112 [ CF8D590BE3373029D57AF80914190682 ] WUDFRd C:\windows\system32\DRIVERS\WUDFRd.sys
    10:51:56.0295 1112 WUDFRd - ok
    10:51:56.0333 1112 [ 7A95C95B6C4CF292D689106BCAE49543 ] wudfsvc C:\windows\System32\WUDFSvc.dll
    10:51:56.0367 1112 wudfsvc - ok
    10:51:56.0398 1112 [ 9A3452B3C2A46C073166C5CF49FAD1AE ] WwanSvc C:\windows\System32\wwansvc.dll
    10:51:56.0412 1112 WwanSvc - ok
    10:51:56.0466 1112 ================ Scan global ===============================
    10:51:56.0500 1112 [ BA0CD8C393E8C9F83354106093832C7B ] C:\windows\system32\basesrv.dll
    10:51:56.0541 1112 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\windows\system32\winsrv.dll
    10:51:56.0563 1112 [ EB6A48CC998E1090E44E8E7F1009A640 ] C:\windows\system32\winsrv.dll
    10:51:56.0602 1112 [ D6160F9D869BA3AF0B787F971DB56368 ] C:\windows\system32\sxssrv.dll
    10:51:56.0653 1112 [ 24ACB7E5BE595468E3B9AA488B9B4FCB ] C:\windows\system32\services.exe
    10:51:56.0664 1112 [Global] - ok
    10:51:56.0665 1112 ================ Scan MBR ==================================
    10:51:56.0686 1112 [ 5B5E648D12FCADC244C1EC30318E1EB9 ] \Device\Harddisk0\DR0
    10:51:57.0062 1112 \Device\Harddisk0\DR0 - ok
    10:51:57.0064 1112 ================ Scan VBR ==================================
    10:51:57.0078 1112 [ 0E8181833307AF9717CE06CA6178D97C ] \Device\Harddisk0\DR0\Partition1
    10:51:57.0082 1112 \Device\Harddisk0\DR0\Partition1 - ok
    10:51:57.0084 1112 ============================================================
    10:51:57.0084 1112 Scan finished
    10:51:57.0084 1112 ============================================================
    10:51:57.0123 4000 Detected object count: 0
    10:51:57.0123 4000 Actual detected object count: 0
  18. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    Good :)

    • Download RogueKiller on the desktop
    • Close all the running programs
    • Windows Vista/7 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again

    ==============================

    Download Malwarebytes' Anti-Malware (MBAM): http://www.malwarebytes.org/products/malwarebytes_free to your desktop.
    Alternate download: http://www.filehippo.com/download_malwarebytes_anti_malware/
    NOTE. If you already have MBAM installed, update it before running the scan.

    * Double-click mbam-setup.exe and follow the prompts to install the program.
    * At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select Perform quick scan, then click Scan.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Be sure that everything is checked, and click Remove Selected.
    * When completed, a log will open in Notepad.
    * Post the log back here.

    Be sure to restart the computer IF MBAM asks you to do so.

    The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
    Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt

    ==============================

    Download aswMBR to your desktop.
    Double click the aswMBR.exe to run it.
    If you see this question: Would you like to download latest Avast! virus definitions?" say "Yes".
    Click the "Scan" button to start scan.
    On completion of the scan click "Save log", save it to your desktop and post in your next reply.

    NOTE. aswMBR will create MBR.dat file on your desktop. This is a copy of your MBR. Do NOT delete it.
  19. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    RogueKiller V8.1.1 [10/03/2012] by Tigzy
    mail: tigzyRK<at>gmail<dot>com
    Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
    Website: http://tigzy.geekstogo.com/roguekiller.php
    Blog: http://tigzyrk.blogspot.com

    Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : Family [Admin rights]
    Mode : Remove -- Date : 10/08/2012 15:29:55

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 8 ¤¤¤
    [RUN][SUSP PATH] HKUS\.DEFAULT[...]\Run : SoftGrid Client (rundll32.exe "C:\windows\system32\config\systemprofile\AppData\Local\Temp\SoftGrid Client\khjdl.dll",AllocInstanceDataW) -> DELETED
    [RUN][SUSP PATH] HKUS\S-1-5-19[...]\Run : SoftGrid Client (rundll32.exe "C:\windows\system32\config\systemprofile\AppData\Local\Temp\SoftGrid Client\khjdl.dll",AllocInstanceDataW) -> DELETED
    [RUN][SUSP PATH] HKUS\S-1-5-20[...]\Run : SoftGrid Client (rundll32.exe "C:\windows\system32\config\systemprofile\AppData\Local\Temp\SoftGrid Client\khjdl.dll",AllocInstanceDataW) -> DELETED
    [RUN][SUSP PATH] HKUS\S-1-5-21-836366110-978052858-2386034689-1000_Classes[...]\Run : SoftGrid Client (rundll32.exe "C:\windows\system32\config\systemprofile\AppData\Local\Temp\SoftGrid Client\khjdl.dll",AllocInstanceDataW) -> DELETED
    [TASK][SUSP PATH] RunAsStdUser Task : "C:\Users\Family\AppData\Local\shamrockspringSA\bin\1.0.18.0\ShamrockSpringSA.exe" -> DELETED
    [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
    [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\Users\Family\AppData\Local\{1124a725-e7eb-82f4-e978-28044d39f9dc}\n.) -> REPLACED (C:\windows\system32\shell32.dll)

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED] ¤¤¤

    ¤¤¤ Infection : ZeroAccess ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> C:\windows\system32\drivers\etc\hosts



    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: TOSHIBA MK3275GSX SATA Disk Device +++++
    --- User ---
    [MBR] f15bde6cfeb2a07fac1798f7125cda38
    [BSP] e4b67e3f6960bb73f78a032d786d7473 : Windows Vista MBR Code
    Partition table:
    0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 Mo
    1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 3074048 | Size: 289710 Mo
    2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 596400128 | Size: 14034 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[2].txt >>
    RKreport[1].txt ; RKreport[2].txt
  20. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    Malwarebytes Anti-Malware (Trial) 1.65.0.1400
    www.malwarebytes.org

    Database version: v2012.10.08.07

    Windows 7 Service Pack 1 x64 NTFS
    Internet Explorer 9.0.8112.16421
    Family :: FAMILYLAPTOP [administrator]

    Protection: Enabled

    10/8/2012 3:34:19 PM
    mbam-log-2012-10-08 (15-34-19).txt

    Scan type: Quick scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 264506
    Time elapsed: 16 minute(s), 12 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 38
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> No action taken.
    HKCR\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439} (PUP.Funmoods) -> No action taken.
    HKCR\escort.escortIEPane.1 (PUP.Funmoods) -> No action taken.
    HKCR\escort.escortIEPane (PUP.Funmoods) -> No action taken.
    HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> No action taken.
    HKCR\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> No action taken.
    HKCR\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} (PUP.Funmoods) -> No action taken.
    HKCR\funmoods.dskBnd.1 (PUP.Funmoods) -> No action taken.
    HKCR\funmoods.dskBnd (PUP.Funmoods) -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> No action taken.
    HKCR\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13} (PUP.Funmoods) -> No action taken.
    HKCR\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} (PUP.Funmoods) -> No action taken.
    HKCR\funmoodsApp.appCore.1 (PUP.Funmoods) -> No action taken.
    HKCR\funmoodsApp.appCore (PUP.Funmoods) -> No action taken.
    HKCR\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9} (PUP.Funmoods) -> No action taken.
    HKCR\f (PUP.Funmoods) -> No action taken.
    HKCR\Typelib\{1D085C0A-E4F4-4F66-BDBF-4BE51015BFC3} (PUP.Funmoods) -> No action taken.
    HKCR\Interface\{0D80F1C5-D17B-4177-AC68-955F3EF9F191} (PUP.Funmoods) -> No action taken.
    HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> No action taken.
    HKCU\Software\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> No action taken.
    HKLM\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\MyWebSearch (PUP.MyWebSearch) -> No action taken.
    HKLM\SOFTWARE\Google\Chrome\Extensions\bbjciahceamgodcoidkjpchnokgfpphh (PUP.Funmoods) -> No action taken.
    HKCR\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Quarantined and deleted successfully.
    HKCR\funmoods.funmoodsHlpr.1 (PUP.FunMoods) -> Quarantined and deleted successfully.
    HKCR\funmoods.funmoodsHlpr (PUP.FunMoods) -> Quarantined and deleted successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11111111-1111-1111-1111-110011221158} (Adware.GamePlayLab) -> Quarantined and deleted successfully.

    Registry Values Detected: 2
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar|{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: Funmoods Toolbar -> No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Data: -> No action taken.

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 16
    C:\Program Files (x86)\FunWebProducts (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\1.bin (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\1.bin\chrome (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\2.bin (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\2.bin\chrome (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\3.bin (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\3.bin\chrome (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\4.bin (PUP.MyWebSearch) -> No action taken.
    C:\Program Files (x86)\FunWebProducts\Installr\4.bin\chrome (PUP.MyWebSearch) -> No action taken.
    C:\Users\Family\Local Settings\Application Data\ShamrockSpringSA (Adware.HotBar.SS) -> Quarantined and deleted successfully.
    C:\Users\Family\Local Settings\Application Data\ShamrockSpringSA\bin (Adware.HotBar.SS) -> Quarantined and deleted successfully.
    C:\Users\Family\Local Settings\Application Data\ShamrockSpringSA\bin\1.0.18.0 (Adware.HotBar.SS) -> Quarantined and deleted successfully.
    C:\Users\Family\AppData\Local\ShamrockSpringSA (Adware.HotBar.SS) -> Quarantined and deleted successfully.
    C:\Users\Family\AppData\Local\ShamrockSpringSA\bin (Adware.HotBar.SS) -> Quarantined and deleted successfully.
    C:\Users\Family\AppData\Local\ShamrockSpringSA\bin\1.0.18.0 (Adware.HotBar.SS) -> Quarantined and deleted successfully.

    Files Detected: 12
    C:\Users\Guest.FamilyLaptop\AppData\Local\Temp\is135653842\trz4CB7.tmp (PUP.PlayBryte) -> No action taken.
    C:\Users\Family\Downloads\infoatoms_d84550.exe (PUP.BundleOffers.IIQ) -> No action taken.
    C:\Users\Family\AppData\Local\funmoods.crx (PUP.Funmoods) -> No action taken.
    C:\Users\Family\Local Settings\Application Data\funmoods.crx (PUP.Funmoods) -> No action taken.
    C:\Users\Family\AppData\Local\Temp\is135653842\IWantThis_US.exe (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
    C:\Windows\System32\config\systemprofile\AppData\Local\Temp\SoftGrid Client\khjdl.dll (Trojan.Labedo) -> Quarantined and deleted successfully.
    C:\Windows\Temp\0.4189997207277759 (Trojan.Happili) -> Quarantined and deleted successfully.
    C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Family\AppData\Local\Temp\0.8585892455291679 (Exploit.Drop.9) -> Quarantined and deleted successfully.
    C:\Users\Family\AppData\Local\Temp\.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\Users\Family\Local Settings\Application Data\ShamrockSpringSA\bin\1.0.18.0\shamrockspringSAHook.dll (Adware.HotBar.SS) -> Quarantined and deleted successfully.
    C:\Users\Family\AppData\Local\ShamrockSpringSA\bin\1.0.18.0\shamrockspringSAHook.dll (Adware.HotBar.SS) -> Quarantined and deleted successfully.

    (end)
  21. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

  22. Broni

    Broni Malware Annihilator Posts: 46,479   +252

    You posted MBAM log twice.
    On a top of it it says "No action taken".
    Re-run it, fix ALL issues and post new log.

    I still need aswMBR log.
  23. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software
    Run date: 2012-10-08 16:16:41
    -----------------------------
    16:16:41.950 OS Version: Windows x64 6.1.7601 Service Pack 1
    16:16:41.951 Number of processors: 2 586 0x200
    16:16:41.954 ComputerName: FAMILYLAPTOP UserName: Family
    16:16:45.622 Initialize success
    16:16:46.029 AVAST engine defs: 12100801
    16:17:05.910 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000074
    16:17:05.920 Disk 0 Vendor: TOSHIBA_ GT00 Size: 305245MB BusType: 11
    16:17:05.940 Disk 0 MBR read successfully
    16:17:05.945 Disk 0 MBR scan
    16:17:05.956 Disk 0 Windows VISTA default MBR code
    16:17:05.981 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048
    16:17:06.007 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 289710 MB offset 3074048
    16:17:06.055 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 14034 MB offset 596400128
    16:17:06.116 Disk 0 scanning C:\windows\system32\drivers
    16:17:20.268 Service scanning
    16:18:06.816 Modules scanning
    16:18:06.841 Disk 0 trace - called modules:
    16:18:06.920 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
    16:18:06.943 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8003016570]
    16:18:06.958 3 CLASSPNP.SYS[fffff8800160143f] -> nt!IofCallDriver -> [0xfffffa8002edf040]
    16:18:06.969 5 amd_xata.sys[fffff880010668b4] -> nt!IofCallDriver -> \Device\00000074[0xfffffa8002ed9060]
    16:18:08.185 AVAST engine scan C:\windows
    16:18:11.563 AVAST engine scan C:\windows\system32
    16:21:34.968 AVAST engine scan C:\windows\system32\drivers
    16:22:07.414 AVAST engine scan C:\Users\Family
    16:38:42.945 AVAST engine scan C:\ProgramData
    16:43:16.977 Scan finished successfully
    16:49:38.648 Disk 0 MBR has been saved successfully to "C:\Users\Family\Desktop\MBR.dat"
    16:49:38.668 The log file has been saved successfully to "C:\Users\Family\Desktop\aswMBR.txt"
  24. Broni

    Broni Malware Annihilator Posts: 46,479   +252

  25. ajptjd

    ajptjd Newcomer, in training Topic Starter Posts: 71

    Yeah, I did [MBAM] it twice because my son hit a key on the keyboard and it removed only the ones that was already selected. I re-did the scan, and the second MBAM was the corrected one.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.