Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93098 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Keylogger, KernelMode Rootkit SSDT hooks have plagued my PC since June

Windows redirect SSDT keylogger rootkits active ssdt hooks rootkit redirecting windows directori

  • This topic is locked This topic is locked
35 replies to this topic

#1 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 26 November 2014 - 06:21 PM

I've spent much time since June embroiled in a battle with this/these person/ who have taken away my administrative privileges. Multiple times I have reformated using winXP sp1, sp2, win Vista, win 7 and they have scripts changing all the directories to winsxs or similar. I was unsuccessful at doing a LLF of my WD sata drive. A particular link is my gmail account which they have also comandored; noted by my logging in at out public library and within minutes screen pops and I can tell they are online, no doubt using keylogging or similar. I have changed passwords mulstiple times using 2step authentication but they cleverly have created phising sites mimicking the login screens; they are online now as I'm working with you; but I've been trying KeyScrambler Personal and it shows it's encrypting my typing but I'm not certain. Even Cox my carrier was under subpoena, which I happened to discover when trying to identify geolocation of these malcontents (netstat) and so I emailed Cox abuse team relating what has been happening in case they were under subpoena by law enforcement. I filed complaint with Internet Criminal Complaint Center and local PD....the I3Cs works with FBI and other regional enforcement agencies but I haven't been directly contacted. So I'm hoping we can do something here. They've even gotten hold of my Roboform Password Manager, many which are 'dead file' to me in my circumstances but still. I've apppreciated the fact they don't appear to have done anything other than probably use my PC as a bot but I've changed all my bank accounts and credit cards. etc. I guess that is enough explanation. I'm just greatful to get it out to others that understand and don't think I'm Mel Gibson in Conspiracy Theory when they look at you with that 'BLANK STARE'.

I pray I've done this correctly but I'm sure it is out of order, my deepest apologies, it has become so overwhelming.

 

 

 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Webroot SecureAnywhere (Enabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
AS: Webroot SecureAnywhere (Enabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Apple Application Support (HKLM\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{235EBB33-3DA1-46DF-AADE-9955123409CB}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Belarc Advisor 8.4 (HKLM\...\Belarc Advisor) (Version: 8.4.0.0 - Belarc Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Canon IJ Scan Utility (HKLM\...\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon MG3500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3500_series) (Version: 1.00 - Canon Inc.)
Canon MG3500 series On-screen Manual (HKLM\...\Canon MG3500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon My Printer (HKLM\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.19 - Piriform)
Creative System Information (HKLM\...\SysInfo) (Version: 1.10 - Creative Technology Limited)
Creative WaveStudio 7 (HKLM\...\WaveStudio 7) (Version: 7.14 - Creative Technology Limited)
FileASSASSIN (HKLM\...\FileASSASSIN) (Version: 1.06 - Malwarebytes)
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.232 - SurfRight B.V.)
HitmanPro.Alert (HKLM\...\HitmanPro.Alert) (Version: 2.6.5.77 - SurfRight B.V.)
iTunes (HKLM\...\{5D928931-D1D2-4A93-A82D-BF60D0E7CFA5}) (Version: 12.0.1.26 - Apple Inc.)
KeyScrambler (HKLM\...\KeyScrambler) (Version: 3.5.0.0 - QFX Software Corporation)
Malwarebytes Anti-Exploit version 1.04.1.1012 (HKLM\...\Malwarebytes Anti-Exploit_is1) (Version: 1.04.1.1012 - Malwarebytes)
Malwarebytes Anti-Malware version 2.0.3.1025 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MozBackup 1.5.1 (HKLM\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 33.1.1 (x86 en-US) (HKLM\...\Mozilla Firefox 33.1.1 (x86 en-US)) (Version: 33.1.1 - Mozilla)
Mozilla Thunderbird 31.2.0 (x86 en-US) (HKLM\...\Mozilla Thunderbird 31.2.0 (x86 en-US)) (Version: 31.2.0 - Mozilla)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.62.40 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.311.0 - Tracker Software Products Ltd)
Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RoboForm 7-9-11-1 (HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\AI RoboForm) (Version: 7-9-11-1 - Siber Systems)
Skype™ 6.22 (HKLM\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 6.22.107 - Skype Technologies S.A.)
Sound Blaster X-Fi Go! Pro (HKLM\...\{587B7A6F-CA1F-4639-9083-16F9BB2363B4}) (Version: 1.0 - Creative Technology Limited)
Speccy (HKLM\...\Speccy) (Version: 1.26 - Piriform)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1164 - SUPERAntiSpyware.com)
Webroot SecureAnywhere (HKLM\...\WRUNINST) (Version: 8.0.5.111 - Webroot)
WinZip (HKLM\...\WinZip) (Version:  10.0  (6667) - WinZip Computing LP)
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{30A2652A-DDF7-45e7-ACA6-3EAB26FC8A4E}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{41662FC2-0D57-4aff-AB27-AD2E12E7C273}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{448BB771-CFE2-47C4-BCDF-1FBF378E202C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{7B342DC4-139A-4a46-8A93-DB0827CCEE9C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\ooofilt.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{7FA8AE11-B3E3-4D88-AABF-255526CD1CE8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{82154420-0FBF-11d4-8313-005004526AB4}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\propertyhdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{D0484DE6-AAEE-468a-991F-8D4B0737B57A}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{D2D59CD1-0A6A-4D36-AE20-47817077D57C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{E5A0B632-DFBA-4549-9346-E414DA06E6F8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{EE5D1EA4-D445-4289-B2FC-55FC93693917}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-674551400-1475256033-2490423522-1001_Classes\CLSID\{F616B81F-7BB8-4F22-B8A5-47428D59F8AD}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
 
==================== Restore Points  =========================
 
23-11-2014 13:27:49 Windows Update
23-11-2014 15:34:39 Revo Uninstaller's restore point - Mozilla Maintenance Service
23-11-2014 15:37:54 Revo Uninstaller's restore point - Adobe Reader 9.2
23-11-2014 15:38:11 Removed Adobe Reader 9.2.
23-11-2014 18:41:53 Windows Update
24-11-2014 20:32:53 Revo Uninstaller's restore point - KeyScrambler
25-11-2014 16:24:06 Revo Uninstaller's restore point - Sound Blaster X-Fi Go! Pro
25-11-2014 16:24:37 Removed Sound Blaster X-Fi Go! Pro
25-11-2014 16:25:22 Removed Host OpenAL
26-11-2014 14:06:26 Installed Sound Blaster X-Fi Go! Pro
26-11-2014 21:40:20 Windows Update
26-11-2014 23:32:09 Installed DirectX
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 20:04 - 2009-06-10 15:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {41698F6D-9A17-4953-A718-064B671D5BA7} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "http://www.roboform....GJKJMIBNKJHIKJ"
Task: {565B1EEB-82ED-42AD-A98E-738202B8C78B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-10-30] (Piriform Ltd)
Task: {8252635C-C411-4481-ACD9-D8EEF6157FDA} - System32\Tasks\SUPERAntiSpyware Scheduled Task 828c1455-990b-449d-a054-fa6632f3566c => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
Task: {863512DD-560C-4ACF-BF55-008E03A99CA9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-11-26] (Adobe Systems Incorporated)
Task: {B3BCE635-231D-4F7D-A340-B24C0D7A1863} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-19] (Google Inc.)
Task: {D2E455B4-6241-4E3F-AD15-B931FC35CE51} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-19] (Google Inc.)
Task: {D9131DBA-7C9B-4EF3-8E7D-FDCDEF38F626} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {E30E32B9-6307-400A-8939-19D831B1E34F} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2014-11-20] (Siber Systems)
Task: {FED4D7D6-815E-4D85-A847-2297DA02CAEF} - System32\Tasks\SUPERAntiSpyware Scheduled Task e0342571-d149-42b9-a590-c405e8897b8d => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 828c1455-990b-449d-a054-fa6632f3566c.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e0342571-d149-42b9-a590-c405e8897b8d.job => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-11-17 13:53 - 2014-07-02 13:42 - 00107992 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-11-26 08:09 - 2009-12-29 16:50 - 00073728 _____ () C:\Windows\SYSTEM32\CmdRtr.DLL
2014-11-26 08:09 - 2010-07-22 16:45 - 00181760 _____ () C:\Windows\SYSTEM32\APOMngr.DLL
2014-11-25 20:54 - 2014-11-25 00:39 - 09009480 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.71\pdf.dll
2014-11-25 20:54 - 2014-11-25 00:39 - 01677128 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll
2014-11-24 11:09 - 2014-02-10 12:44 - 04592128 _____ () C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll
2014-11-24 11:09 - 2014-02-10 12:44 - 00112128 _____ () C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
 
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION!
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: Creative ALchemy AL6 Licensing Service => 3
MSCONFIG\Services: Creative Audio Engine Licensing Service => 3
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-674551400-1475256033-2490423522-500 - Administrator - Disabled)
Guest (S-1-5-21-674551400-1475256033-2490423522-501 - Limited - Disabled)
Rickey (S-1-5-21-674551400-1475256033-2490423522-1001 - Administrator - Enabled) => C:\Users\Rickey
 
==================== Faulty Device Manager Devices =============
 
Name: NVIDIA nForce 10/100 Mbps Ethernet 
Description: NVIDIA nForce Networking Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: NVIDIA
Service: NVNET
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/26/2014 08:06:26 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {af35b232-a4b7-41b4-84e7-583895660a24}
 
Error: (11/25/2014 10:25:45 AM) (Source: SideBySide) (EventID: 75) (User: )
Description: Activation context generation failed for "1".Error in manifest or policy file "2" on line 3.
Multiple requestedPrivileges elements are not allowed in manifest.
 
Error: (11/25/2014 10:25:12 AM) (Source: Creative Labs SC) (EventID: 101) (User: )
Description: 98-164
 
Error: (11/25/2014 10:25:11 AM) (Source: Creative Labs SC) (EventID: 101) (User: )
Description: 98-164
 
Error: (11/25/2014 10:24:06 AM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {2e9792de-4463-4d9f-aca7-8b6863c10a4f}
 
Error: (11/24/2014 02:32:52 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {db56a493-905e-40cd-acfa-fedc9dc6b254}
 
Error: (11/24/2014 01:19:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 39.0.2171.65, time stamp: 0x546659db
Faulting module name: KeyScramblerIE.DLL_unloaded, version: 0.0.0.0, time stamp: 0x544d0aa6
Exception code: 0xc0000005
Fault offset: 0x723e5798
Faulting process id: 0x1138
Faulting application start time: 0xchrome.exe0
Faulting application path: chrome.exe1
Faulting module path: chrome.exe2
Report Id: chrome.exe3
 
Error: (11/24/2014 00:22:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 33.1.1.5430, time stamp: 0x54656826
Faulting module name: mozalloc.dll, version: 33.1.1.5430, time stamp: 0x54654321
Exception code: 0x80000003
Fault offset: 0x00001425
Faulting process id: 0x14d8
Faulting application start time: 0xplugin-container.exe0
Faulting application path: plugin-container.exe1
Faulting module path: plugin-container.exe2
Report Id: plugin-container.exe3
 
Error: (11/24/2014 00:21:39 PM) (Source: Creative Labs SC) (EventID: 101) (User: )
Description: 98-164
 
Error: (11/24/2014 11:28:47 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: rundll32.exe_sbavmon.dll, version: 6.1.7600.16385, time stamp: 0x4a5bc637
Faulting module name: KSVSPI32.dll, version: 1.0.312.0, time stamp: 0x4c4fa162
Exception code: 0xc0000005
Fault offset: 0x000163bb
Faulting process id: 0xf90
Faulting application start time: 0xrundll32.exe_sbavmon.dll0
Faulting application path: rundll32.exe_sbavmon.dll1
Faulting module path: rundll32.exe_sbavmon.dll2
Report Id: rundll32.exe_sbavmon.dll3
 
 
System errors:
=============
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 11
Processor ID: 2
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 2
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1
 
The details view of this entry contains further information.
 
Error: (11/26/2014 08:04:18 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1
 
The details view of this entry contains further information.
 
 
Microsoft Office Sessions:
=========================
Error: (11/26/2014 08:06:26 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {af35b232-a4b7-41b4-84e7-583895660a24}
 
Error: (11/25/2014 10:25:45 AM) (Source: SideBySide) (EventID: 75) (User: )
Description: C:\Program Files\Creative\Audio Device Selection Unicode\CTAudSeu.exeC:\Program Files\Creative\Audio Device Selection Unicode\CTAudSeu.exe2
 
Error: (11/25/2014 10:25:12 AM) (Source: Creative Labs SC) (EventID: 101) (User: )
Description: 98-164
 
Error: (11/25/2014 10:25:11 AM) (Source: Creative Labs SC) (EventID: 101) (User: )
Description: 98-164
 
Error: (11/25/2014 10:24:06 AM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {2e9792de-4463-4d9f-aca7-8b6863c10a4f}
 
Error: (11/24/2014 02:32:52 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {db56a493-905e-40cd-acfa-fedc9dc6b254}
 
Error: (11/24/2014 01:19:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: chrome.exe39.0.2171.65546659dbKeyScramblerIE.DLL_unloaded0.0.0.0544d0aa6c0000005723e5798113801d0080e9656f530C:\Program Files\Google\Chrome\Application\chrome.exeKeyScramblerIE.DLLda70b0a0-740e-11e4-9733-c43dc78040dd
 
Error: (11/24/2014 00:22:34 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: plugin-container.exe33.1.1.543054656826mozalloc.dll33.1.1.543054654321800000030000142514d801d0080c34a9fe10C:\Program Files\Mozilla Firefox\plugin-container.exeC:\Program Files\Mozilla Firefox\mozalloc.dlldbedad50-7406-11e4-9733-c43dc78040dd
 
Error: (11/24/2014 00:21:39 PM) (Source: Creative Labs SC) (EventID: 101) (User: )
Description: 98-164
 
Error: (11/24/2014 11:28:47 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: rundll32.exe_sbavmon.dll6.1.7600.163854a5bc637KSVSPI32.dll1.0.312.04c4fa162c0000005000163bbf9001d0080c177b3a70C:\Windows\System32\rundll32.exeC:\Windows\system32\KSVSPI32.dll585cffb0-73ff-11e4-9733-c43dc78040dd
 
 
CodeIntegrity Errors:
===================================
  Date: 2014-11-26 17:15:58.804
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-26 16:51:55.858
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-26 16:10:24.576
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-26 16:00:54.054
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-26 15:08:58.461
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-26 15:05:25.784
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2014-11-26 14:21:14.017
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\hmpalert.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: AMD Phenom™ 9550 Quad-Core Processor
Percentage of memory in use: 45%
Total physical RAM: 3071.3 MB
Available physical RAM: 1669.93 MB
Total Pagefile: 6140.9 MB
Available Pagefile: 4481.98 MB
Total Virtual: 2047.88 MB
Available Virtual: 1898.98 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:297.99 GB) (Free:262.19 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 7CC2FB56)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-11-2014 01
Ran by Rickey (administrator) on MAVERICK on 26-11-2014 17:37:45
Running from C:\Users\Rickey\Downloads
Loaded Profile: Rickey (Available profiles: Rickey)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Webroot) C:\Program Files\Webroot\WRSA.exe
(SurfRight B.V.) C:\Program Files\HitmanPro.Alert\hmpalert.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe
(QFX Software Corporation) C:\Program Files\KeyScrambler\KeyScrambler.exe
(Creative Technology Ltd) C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [768656 2014-11-23] (Webroot)
HKLM\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files\Malwarebytes Anti-Exploit\mbae.exe [440632 2014-08-29] (Malwarebytes Corporation)
HKLM\...\Run: [KeyScrambler] => C:\Program Files\KeyScrambler\keyscrambler.exe [508744 2014-10-26] (QFX Software Corporation)
HKLM\...\Run: [VolPanel] => C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe [241757 2010-12-08] (Creative Technology Ltd)
HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\...\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [4826904 2014-10-30] (Piriform Ltd)
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Run: [RoboForm] => C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110160 2014-11-20] (Siber Systems)
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Run: [Skype] => C:\Program Files\Skype\Phone\Skype.exe [30521952 2014-11-24] (Skype Technologies S.A.)
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [6697752 2014-11-13] (SUPERAntiSpyware)
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\MountPoints2: D - D:\setup.exe
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\MountPoints2: {d6b51267-6e66-11e4-826b-806e6f6e6963} - D:\SetupAssistant.exe
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-11-17] (Microsoft Corporation)
HKU\S-1-5-18\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoStartMenuSubFolders] 0
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-674551400-1475256033-2490423522-1001\Software\Microsoft\Internet Explorer\Main,Start Page = http://drudgereport.com/
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax86\wrflt.dll (Webroot)
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com...ols/pcmatic.cab
DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creat...13/CTPIDPDE.cab
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creat...015/CTSUEng.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...30321/CTPID.cab
Handler: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\BelarcAdvisor\System\BAVoilaX.dll (Belarc, Inc.)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.2
 
FireFox:
========
FF ProfilePath: C:\Users\Rickey\AppData\Roaming\Mozilla\Firefox\Profiles\yjbaetqq.default
FF Homepage: hxxp://drudgereport.com|hxxp://breitbart.com
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_239.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-674551400-1475256033-2490423522-1001: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Extension: Webroot Password Manager - C:\Users\Rickey\AppData\Roaming\Mozilla\Firefox\Profiles\yjbaetqq.default\Extensions\{8ac62a8b-8b3f-43ba-9b1a-90c299b9dfda} [2014-11-23]
FF HKLM\...\Firefox\Extensions: [webrootsecure@webroot.com] - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer
FF Extension: Webroot Filtering Extension - C:\ProgramData\WRData\PKG\FIREFOX\WebrootSecure_SocketServer [2014-11-17]
FF HKU\S-1-5-21-674551400-1475256033-2490423522-1001\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files\Siber Systems\AI RoboForm\Firefox
FF Extension: RoboForm Toolbar for Firefox - C:\Program Files\Siber Systems\AI RoboForm\Firefox [2014-11-20]
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.drudgereport.com/
CHR StartupUrls: Default -> "hxxp://help.comodo.com/topic-120-1-279-2590-Displaying-Hiding-Application-buttons-on-the-Toolbar.html", "hxxp://manhattan.lib.ks.us/", "https://www.yahoo.co...t&type=avastbcl", "hxxp://www.google.com/"
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\internal-nacl-plugin No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (PDF-XChange Viewer) - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
CHR Plugin: (iTunes Application Detector) - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_223.dll No File
CHR Profile: C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-19]
CHR Extension: (Bookmark Sentry (scanner)) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdglbbcbmgnimogcmcdenggkpdmihlga [2014-11-19]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-19]
CHR Extension: (Pop Block Pro - The Ultimate Popup Blocker) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib [2014-11-24]
CHR Extension: (Poper Blocker) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2014-11-19]
CHR Extension: (YouTube) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-19]
CHR Extension: (CancanIT SEO & Website Analysis) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdpkkcoifgekomfdnhgmhdbandakmped [2014-11-19]
CHR Extension: (Adblock Plus) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-19]
CHR Extension: (TrafficLight) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnpidifppmenkapgihekkeednfoenal [2014-11-23]
CHR Extension: (Link to Google Analytics | Shortcut) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbofdajbjpegicggccpealogclcdiap [2014-11-19]
CHR Extension: (Alexa Traffic Rank) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel [2014-11-19]
CHR Extension: (Google Search) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-19]
CHR Extension: (Netflix) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\deceagebecbceejblnlcjooeohmmeldh [2014-11-19]
CHR Extension: (Good News) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\deegloljmdbfbjhlimieancmcfombgjj [2014-11-19]
CHR Extension: (Lucidchart Diagrams - Desktop) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\djejicklhojeokkfmdelnempiecmdomj [2014-11-19]
CHR Extension: (Business Card Maker) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpchnngplfnmejdkfgpmfhifccngoiih [2014-11-19]
CHR Extension: (Reverse Phone Lookup) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\eccacjpoadkkkichonipjpkjoklpdacg [2014-11-19]
CHR Extension: (Typing Races Student) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejhoalfilhjkgjphcbnhnnjmhgbcmgeg [2014-11-19]
CHR Extension: (Google Calendar) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2014-11-19]
CHR Extension: (Antavo - Contest & Activation Suite) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ennfopamliahhindmboeiainjeanckib [2014-11-19]
CHR Extension: (Blur (Formerly DoNotTrackMe)) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2014-11-19]
CHR Extension: (AdBlock Premium) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj [2014-11-19]
CHR Extension: (Chrome Web Store Launcher (by Google)) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\gecgipfabdickgidpmbicneamekgbaej [2014-11-21]
CHR Extension: (Planetarium) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2014-11-19]
CHR Extension: (AdBlock) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-11-19]
CHR Extension: (DocuSign - Sign Documents for Free) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\goblijolcnempeilmnkmfbhohlpngemd [2014-11-19]
CHR Extension: (IE Tab) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2014-11-19]
CHR Extension: (Similar Sites Pro) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl [2014-11-23]
CHR Extension: (AWeber) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\iiecooifilpmabeidiegjiekkngdhhkc [2014-11-19]
CHR Extension: (How To Make Money) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\imojecgofbipiadfdmggpminpkpfdddg [2014-11-19]
CHR Extension: (Dropbox) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2014-11-19]
CHR Extension: (Typing Test - KeyHero) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm [2014-11-19]
CHR Extension: (RightSignature) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkhcpgjhhebecogfbaelmpmpcccdofep [2014-11-19]
CHR Extension: (Webroot Filtering Extension) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2014-11-19]
CHR Extension: (StayFocusd) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-11-19]
CHR Extension: (Presefy Presentation) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\laceanlcibahaedgdbmaehhdemabnppf [2014-11-19]
CHR Extension: (Currency Converter) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbhghjdcfghfhlogkgdklfgmpodeglno [2014-11-19]
CHR Extension: (Webcam Toy) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-11-19]
CHR Extension: (Simplebooklet) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhfhnhfkmicpmbafobnpegjhaihjinph [2014-11-19]
CHR Extension: (Classic Popup Blocker) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lijicndbkjoplmhnclmoahmcaffaeapp [2014-11-19]
CHR Extension: (Payable form: add Paypal to your Google Form) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkdpfjbplbappibihpepdcpikflmlnfb [2014-11-19]
CHR Extension: (Google Maps) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-11-19]
CHR Extension: (PayPal Transactions) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnoilgegkhenejdjcejnkkcklcdfibbd [2014-11-19]
CHR Extension: (Rain Alarm) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-11-19]
CHR Extension: (Ghostery Fixer) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaegpmdlhnpldpoadmnnbddbkcdmbhb [2014-11-19]
CHR Extension: (Ghostery) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2014-11-19]
CHR Extension: (ClearCheckbook Money Management) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncgheejpeplfmifkibfifpdhceopaifp [2014-11-19]
CHR Extension: (Similar Sites) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\necpbmbhhdiplmfhmjicabdeighkndkn [2014-11-19]
CHR Extension: (GData Centers 9 Hamina, Finland) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nellajllheicipgipifopnhjjhiljnpi [2014-11-26]
CHR Extension: (Google Wallet) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-19]
CHR Extension: (Adblock Pro) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2014-11-19]
CHR Extension: (Webroot Password Manager) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2014-11-19]
CHR Extension: (Click&Clean App) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-11-19]
CHR Extension: (HackerTarget.com IP Tools) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\phjkepckmcnjohilmbjlcoblenhgpjmo [2014-11-19]
CHR Extension: (Gmail) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-19]
CHR Extension: (Popout for YouTube™) - C:\Users\Rickey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pofekaindcmmojfnfgbpklepkjfilcep [2014-11-19]
CHR HKLM\...\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - C:\ProgramData\WRData\PKG\CHROME\CHROME_1.0.2.42.crx [2014-11-17]
CHR HKLM\...\Chrome\Extension: [okfhiodnpcnnnpgbjbhfebjnbagmfhab] - C:\ProgramData\WRData\pkg\lpchrome.crx [2014-11-17]
CHR HKLM\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-11-20]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [142648 2014-07-22] (SUPERAntiSpyware.com)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2014-11-26] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-11-26] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed]
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106248 2014-11-23] (SurfRight B.V.)
R2 hmpalertsvc; C:\Program Files\HitmanPro.Alert\hmpalert.exe [1876816 2014-11-26] (SurfRight B.V.)
R2 MbaeSvc; C:\Program Files\Malwarebytes Anti-Exploit\mbae-svc.exe [441144 2014-08-29] (Malwarebytes Corporation)
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [768656 2014-11-23] (Webroot)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ESProtectionDriver; C:\Program Files\Malwarebytes Anti-Exploit\mbae.sys [47896 2014-08-30] ()
S3 G311N6; C:\Windows\System32\DRIVERS\G311N6.sys [278560 2010-05-05] (Netgear) [File not signed]
R2 hmpalert; C:\Windows\System32\drivers\hmpalert.sys [75640 2014-11-26] ()
R3 KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [209016 2013-05-31] (QFX Software Corporation)
S3 ksaud; C:\Windows\System32\drivers\ksaud.sys [1254400 2010-08-11] (Creative Technology Ltd.) [File not signed]
R2 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [75480 2014-10-01] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2014-11-26] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [5810 2004-08-13] ()
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [116736 2014-11-23] (Webroot)
U0 SR; No ImagePath
U2 srservice; No ImagePath
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-13] (Microsoft Corporation)
U3 aswMBR; \??\C:\Users\Rickey\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Rickey\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-11-26 17:37 - 2014-11-26 17:38 - 00032158 _____ () C:\Users\Rickey\Downloads\FRST.txt
2014-11-26 17:37 - 2014-11-26 17:37 - 00000000 ____D () C:\FRST
2014-11-26 17:33 - 2014-11-26 17:33 - 00001999 _____ () C:\Users\Public\Desktop\Microsoft LifeCam.lnk
2014-11-26 17:33 - 2014-11-26 17:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft LifeCam
2014-11-26 17:32 - 2014-11-26 17:33 - 00000000 ____D () C:\Program Files\Microsoft LifeCam
2014-11-26 17:32 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-11-26 17:32 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-11-26 17:16 - 2014-11-26 17:34 - 00000000 ____D () C:\Users\Rickey\Downloads\WhatTheTech
2014-11-26 17:14 - 2014-11-26 17:14 - 01109504 _____ (Farbar) C:\Users\Rickey\Downloads\FRST.exe
2014-11-26 17:11 - 2014-11-26 17:11 - 05198336 _____ (AVAST Software) C:\Users\Rickey\Downloads\aswMBR.exe
2014-11-26 16:57 - 2014-11-26 16:57 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\EncryptStick
2014-11-26 16:31 - 2014-11-26 16:31 - 00000512 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e0342571-d149-42b9-a590-c405e8897b8d.job
2014-11-26 16:31 - 2014-11-26 16:31 - 00000512 _____ () C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 828c1455-990b-449d-a054-fa6632f3566c.job
2014-11-26 16:31 - 2014-11-26 16:31 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\SUPERAntiSpyware.com
2014-11-26 16:30 - 2014-11-26 16:31 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware
2014-11-26 16:30 - 2014-11-26 16:30 - 00001961 _____ () C:\Users\Rickey\Desktop\SUPERAntiSpyware Professional.lnk
2014-11-26 16:30 - 2014-11-26 16:30 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2014-11-26 16:30 - 2014-11-26 16:30 - 00000000 ____D () C:\ProgramData\SUPERAntiSpyware.com
2014-11-26 15:28 - 2014-11-26 17:33 - 00000430 _____ () C:\Windows\setupact.log
2014-11-26 15:28 - 2014-11-26 15:28 - 00000000 _____ () C:\Windows\setuperr.log
2014-11-26 15:12 - 2010-08-12 11:46 - 00758784 _____ (NVIDIA Corporation) C:\Windows\system32\cohelper.dll
2014-11-26 15:12 - 2010-08-09 22:33 - 00011164 _____ () C:\Windows\system32\Drivers\nvphy.bin
2014-11-26 15:10 - 2014-11-26 15:54 - 00000000 ____D () C:\Windows\LastGood
2014-11-26 14:41 - 2014-11-26 14:41 - 03984880 _____ () C:\Users\Rickey\Downloads\Tweaking.com-ResetRegistryPermissions.exe
2014-11-26 13:49 - 2014-11-26 17:31 - 00000000 ____D () C:\Windows\CryptoGuard
2014-11-26 13:49 - 2014-11-26 13:49 - 00477008 _____ (SurfRight) C:\Windows\system32\hmpalert.dll
2014-11-26 13:49 - 2014-11-26 13:49 - 00075640 _____ () C:\Windows\system32\Drivers\hmpalert.sys
2014-11-26 13:49 - 2014-11-26 13:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro.Alert
2014-11-26 13:49 - 2014-11-26 13:49 - 00000000 ____D () C:\Program Files\HitmanPro.Alert
2014-11-26 09:53 - 2014-11-26 17:21 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Skype
2014-11-26 09:53 - 2014-11-26 09:53 - 00002503 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-11-26 09:53 - 2014-11-26 09:53 - 00000000 ___RD () C:\Program Files\Skype
2014-11-26 09:53 - 2014-11-26 09:53 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Skype
2014-11-26 09:53 - 2014-11-26 09:53 - 00000000 ____D () C:\ProgramData\Skype
2014-11-26 09:53 - 2014-11-26 09:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-11-26 09:53 - 2014-11-26 09:53 - 00000000 ____D () C:\Program Files\Common Files\Skype
2014-11-26 08:36 - 2014-11-26 08:37 - 04745544 _____ (Google) C:\Users\Rickey\Downloads\software_removal_tool.exe
2014-11-26 08:12 - 2000-05-11 01:00 - 00090112 ____N (Creative Technology Ltd.) C:\Windows\Updreg.EXE
2014-11-26 08:09 - 2010-07-22 16:45 - 00181760 _____ () C:\Windows\system32\APOMngr.DLL
2014-11-26 08:09 - 2009-12-29 16:50 - 00073728 _____ () C:\Windows\system32\CmdRtr.DLL
2014-11-26 08:09 - 2009-05-26 15:59 - 00026768 _____ () C:\Windows\ksaudENG.reg
2014-11-26 08:09 - 2007-07-05 10:27 - 00002630 _____ () C:\Windows\MixerName.reg
2014-11-26 08:08 - 2014-11-26 08:08 - 00445016 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-11-26 08:08 - 2014-11-26 08:08 - 00109144 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-11-26 08:08 - 2014-11-26 08:08 - 00002267 _____ () C:\Users\Public\Desktop\Creative Product Registration.lnk
2014-11-26 08:08 - 2014-11-26 08:08 - 00000000 ____D () C:\Program Files\Common Files\Creative Labs Shared
2014-11-26 08:08 - 2012-01-13 11:21 - 02906586 ____N (Creative) C:\Windows\system32\Sens_oal.dll
2014-11-25 09:50 - 2014-11-25 09:50 - 00002078 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
2014-11-25 09:50 - 2014-11-25 09:50 - 00002066 _____ () C:\Users\Public\Desktop\Belarc Advisor.lnk
2014-11-25 09:50 - 2014-11-25 09:50 - 00000000 ____D () C:\Program Files\Belarc
2014-11-24 19:14 - 2014-11-24 19:14 - 00008489 _____ () C:\Users\Rickey\Documents\hijackthis_settings.txt
2014-11-24 18:52 - 2014-11-26 16:49 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-11-24 17:36 - 2014-11-24 17:36 - 00008385 _____ () C:\Users\Rickey\Downloads\hijackthis.log
2014-11-24 17:35 - 2014-11-24 17:35 - 00388608 _____ (Trend Micro Inc.) C:\Users\Rickey\Downloads\HijackThis.exe
2014-11-24 17:18 - 2014-11-24 17:34 - 00000000 ____D () C:\Users\Rickey\Downloads\mbar
2014-11-24 14:36 - 2014-11-24 14:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyScrambler
2014-11-24 14:36 - 2014-11-24 14:36 - 00000000 ____D () C:\Program Files\KeyScrambler
2014-11-24 14:36 - 2013-05-31 08:53 - 00209016 _____ (QFX Software Corporation) C:\Windows\system32\Drivers\keyscrambler.sys
2014-11-24 11:26 - 2014-11-24 11:26 - 00007599 _____ () C:\Users\Rickey\AppData\Local\Resmon.ResmonCfg
2014-11-24 03:42 - 2014-11-24 04:04 - 00000000 ____D () C:\Users\Rickey\EWTN Multimedia
2014-11-23 15:58 - 2014-11-23 15:58 - 00001893 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2014-11-23 15:58 - 2014-11-23 15:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2014-11-23 15:57 - 2014-11-23 15:58 - 00000000 ____D () C:\Program Files\HitmanPro
2014-11-23 15:56 - 2014-11-23 16:01 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-11-23 14:16 - 2014-11-23 14:16 - 00050529 _____ () C:\Users\Rickey\Downloads\user_accesslog.zip
2014-11-23 13:38 - 2014-11-23 13:38 - 43059656 _____ () C:\Users\Rickey\Downloads\BDPUARLauncher.exe
2014-11-23 12:59 - 2014-11-24 17:17 - 00000000 ____D () C:\Users\Rickey\Desktop\mbar
2014-11-23 12:59 - 2014-11-23 12:59 - 00001013 _____ () C:\Users\Public\Desktop\FileASSASSIN.lnk
2014-11-23 12:59 - 2014-11-23 12:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileASSASSIN
2014-11-23 12:59 - 2014-11-23 12:59 - 00000000 ____D () C:\Program Files\FileASSASSIN
2014-11-23 12:55 - 2014-11-23 12:55 - 04909382 _____ () C:\Users\Rickey\Downloads\mbam-chameleon-3.1.7.0.zip
2014-11-23 08:48 - 2014-11-23 08:48 - 04071672 _____ (Bitdefender LLC) C:\Users\Rickey\Downloads\BDUSBImmunizerLauncher.exe
2014-11-23 08:41 - 2014-11-23 08:41 - 07268536 _____ (Bitdefender LLC) C:\Users\Rickey\Downloads\BootkitRemoval_x86.exe
2014-11-23 05:47 - 2014-11-23 09:15 - 00000000 ____D () C:\Users\Rickey\AppData\Local\lptmp716602764
2014-11-23 05:34 - 2014-11-23 05:34 - 00000000 __SHD () C:\Users\Rickey\AppData\Local\EmieUserList
2014-11-23 05:34 - 2014-11-23 05:34 - 00000000 __SHD () C:\Users\Rickey\AppData\Local\EmieSiteList
2014-11-23 05:34 - 2014-11-23 05:34 - 00000000 __SHD () C:\Users\Rickey\AppData\Local\EmieBrowserModeList
2014-11-23 05:30 - 2014-11-23 05:30 - 00000000 ____D () C:\Support
2014-11-23 05:25 - 2012-07-30 11:14 - 00031616 ____N () C:\Windows\system32\FoolishEventLogMsgHelper.dll
2014-11-23 05:24 - 2014-11-23 09:15 - 00000000 ____D () C:\Users\Rickey\AppData\Local\lptmp893108261
2014-11-23 05:21 - 2014-11-23 09:15 - 00000000 ____D () C:\Users\Rickey\Downloads\D7
2014-11-23 04:51 - 2014-11-23 04:51 - 00000000 ____D () C:\Program Files\Tweaking.com
2014-11-22 23:29 - 2014-11-23 00:42 - 00000000 ____D () C:\Users\Rickey\.moneydance
2014-11-22 23:28 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Moneydance
2014-11-20 05:16 - 2014-11-23 09:15 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RoboForm
2014-11-20 05:16 - 2014-11-23 04:22 - 00000000 ____D () C:\Users\Rickey\Documents\My RoboForm Data
2014-11-20 05:16 - 2014-11-20 05:16 - 00000000 ____D () C:\ProgramData\RoboForm
2014-11-20 05:14 - 2014-11-23 09:06 - 00000000 ____D () C:\Program Files\Siber Systems
2014-11-19 18:25 - 2012-07-25 21:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-11-19 18:25 - 2012-07-25 21:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-11-19 18:25 - 2012-07-25 21:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-11-19 18:25 - 2012-07-25 21:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-11-19 18:25 - 2012-07-25 21:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-11-19 18:25 - 2012-07-25 20:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-11-19 18:25 - 2012-07-25 20:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-11-19 18:25 - 2012-06-02 08:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-11-19 18:14 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2014-11-19 18:14 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Speccy
2014-11-19 18:14 - 2014-11-19 18:14 - 00000937 _____ () C:\Users\Public\Desktop\Speccy.lnk
2014-11-19 17:55 - 2014-11-19 17:55 - 00965904 ____N () C:\Users\Rickey\Documents\Webroot Threat Removal 10_19_2014.log
2014-11-19 17:51 - 2014-11-19 17:51 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\OpenOffice
2014-11-19 17:50 - 2014-11-26 15:15 - 00000000 ____D () C:\Users\Rickey\AppData\Local\CrashDumps
2014-11-19 14:41 - 2014-11-19 14:41 - 00000000 __RSH () C:\MSDOS.SYS
2014-11-19 14:41 - 2014-11-19 14:41 - 00000000 __RSH () C:\IO.SYS
2014-11-19 14:29 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\RogueKiller
2014-11-19 14:29 - 2014-11-19 14:47 - 00029160 _____ () C:\Windows\system32\Drivers\TrueSight.sys
2014-11-19 14:28 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-11-19 14:28 - 2014-11-19 14:28 - 00001025 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-11-19 14:28 - 2014-11-19 14:28 - 00001019 _____ () C:\Users\Public\Desktop\WinZip.lnk
2014-11-19 13:45 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\WinZip
2014-11-19 13:36 - 2014-08-03 02:08 - 04806744 _____ () C:\Users\Rickey\Desktop\RogueKiller.exe
2014-11-19 13:35 - 2014-07-02 08:20 - 00237427 ____N () C:\Users\Rickey\Desktop\buy_sell_ecourse_udemy.htm
2014-11-19 11:02 - 2014-11-26 17:29 - 00000000 ____D () C:\ProgramData\Malwarebytes Anti-Exploit
2014-11-19 11:02 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Exploit
2014-11-19 11:02 - 2014-11-19 11:02 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Exploit.lnk
2014-11-19 11:01 - 2014-11-26 15:09 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-19 11:01 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-19 11:01 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-11-19 11:01 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Exploit
2014-11-19 11:01 - 2014-11-23 09:07 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-19 11:01 - 2014-11-19 11:01 - 00001060 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-19 11:01 - 2014-10-01 11:11 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-19 11:01 - 2014-10-01 11:11 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-19 11:01 - 2014-10-01 11:11 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-19 08:16 - 2014-11-19 08:16 - 00000218 _____ () C:\Users\Rickey\AppData\Local\recently-used.xbel
2014-11-19 07:54 - 2014-11-19 18:04 - 00000000 ____D () C:\Users\Rickey\AppData\Local\homebank
2014-11-19 07:53 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-11-19 07:53 - 2014-11-19 11:41 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Apple Computer
2014-11-19 07:53 - 2014-11-19 07:53 - 00001753 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-11-19 07:53 - 2014-11-19 07:53 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Apple Computer
2014-11-19 07:52 - 2012-10-03 16:14 - 00026840 _____ (GEAR Software Inc.) C:\Windows\system32\Drivers\GEARAspiWDM.sys
2014-11-19 07:51 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\B0FFCDD9-5261-4e59-B29A-17A4FABDEBAB
2014-11-19 07:51 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Apple Computer
2014-11-19 07:51 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\iTunes
2014-11-19 07:51 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\iPod
2014-11-19 07:50 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Apple
2014-11-19 07:50 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Bonjour
2014-11-19 07:50 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Apple Software Update
2014-11-19 07:50 - 2014-11-23 09:05 - 00000000 ____D () C:\Program Files\Common Files\Apple
2014-11-19 07:50 - 2014-11-19 07:50 - 00002519 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2014-11-19 07:50 - 2014-11-19 07:50 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Apple
2014-11-19 05:47 - 2014-11-26 16:52 - 00000886 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-19 05:47 - 2014-11-26 15:09 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-19 05:47 - 2014-11-25 20:54 - 00002129 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-11-19 05:47 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-11-19 05:47 - 2014-11-23 09:07 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Google
2014-11-19 05:47 - 2014-11-23 09:05 - 00000000 ____D () C:\Program Files\Google
2014-11-19 03:20 - 2014-11-10 20:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-11-19 03:20 - 2014-11-10 20:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-11-19 03:20 - 2012-02-10 23:37 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-11-19 03:20 - 2011-03-10 23:39 - 00143744 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2014-11-19 03:20 - 2011-03-10 23:39 - 00117120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2014-11-19 03:20 - 2011-03-10 23:38 - 00332160 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2014-11-19 03:20 - 2011-03-10 23:38 - 00080256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2014-11-19 03:20 - 2011-03-10 23:38 - 00022400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2014-11-19 03:20 - 2011-03-10 23:33 - 01699328 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2014-11-19 03:20 - 2011-03-10 23:31 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\fsutil.exe
2014-11-19 03:20 - 2011-03-10 22:01 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-11-19 03:19 - 2014-09-04 19:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-11-19 03:19 - 2014-08-28 19:44 - 02744320 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-11-19 03:19 - 2014-07-08 19:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDYAK.DLL
2014-11-19 03:19 - 2014-07-08 19:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAT.DLL
2014-11-19 03:19 - 2014-07-08 19:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU1.DLL
2014-11-19 03:19 - 2014-07-08 19:29 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-11-19 03:19 - 2014-07-08 19:29 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDRU.DLL
2014-11-19 03:19 - 2014-07-08 16:30 - 00419992 _____ () C:\Windows\system32\locale.nls
2014-11-19 03:19 - 2011-02-24 23:30 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-11-19 01:35 - 2014-05-08 03:06 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-11-18 17:00 - 2012-08-23 08:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-11-18 17:00 - 2012-08-23 08:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-11-18 17:00 - 2012-08-23 05:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-11-18 16:45 - 2013-10-01 18:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-11-18 16:45 - 2013-10-01 18:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-11-18 16:45 - 2013-10-01 18:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-11-18 16:45 - 2013-10-01 18:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-11-18 16:45 - 2013-10-01 18:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-11-18 16:45 - 2013-10-01 17:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-11-18 16:45 - 2013-10-01 17:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-11-18 16:45 - 2013-10-01 17:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-11-18 16:45 - 2013-10-01 17:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-11-18 16:45 - 2013-10-01 16:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-11-18 16:45 - 2013-10-01 16:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-11-18 15:34 - 2014-11-23 04:15 - 00000000 ____D () C:\aa5c4998d60b779146272f
2014-11-18 15:28 - 2014-06-26 19:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-11-18 15:18 - 2014-06-30 16:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-11-18 15:18 - 2014-06-06 00:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-11-18 15:18 - 2014-03-09 15:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-11-18 15:18 - 2014-03-09 15:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-11-18 15:18 - 2012-02-29 23:46 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-11-18 15:18 - 2012-02-29 23:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-11-18 15:11 - 2013-05-09 22:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-11-18 15:11 - 2013-05-09 22:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-11-18 08:13 - 2014-10-17 19:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-11-18 08:13 - 2014-07-13 19:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-11-18 08:13 - 2014-06-15 19:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-11-18 08:13 - 2014-06-15 19:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-11-18 08:13 - 2014-06-15 19:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-11-18 08:13 - 2014-03-04 03:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-11-18 08:13 - 2014-03-04 03:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-11-18 08:13 - 2013-10-29 20:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-11-18 08:13 - 2013-10-18 19:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-11-18 08:13 - 2013-10-03 19:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-11-18 08:13 - 2013-10-03 19:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-11-18 08:13 - 2013-07-08 22:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-11-18 08:13 - 2013-07-04 05:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-11-18 08:13 - 2013-07-02 22:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2014-11-18 08:13 - 2013-07-02 21:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-11-18 08:13 - 2013-07-02 21:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-11-18 08:13 - 2013-02-11 21:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-11-18 08:13 - 2013-01-23 22:47 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-11-18 08:13 - 2012-11-01 23:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-11-18 08:13 - 2012-08-22 11:16 - 00712048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-11-18 08:13 - 2012-07-04 13:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-11-18 08:13 - 2011-06-15 22:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-11-18 08:13 - 2011-04-28 20:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-11-18 08:13 - 2011-04-28 20:46 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-11-18 08:13 - 2011-04-28 20:46 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-11-18 08:13 - 2011-03-02 23:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-11-18 08:13 - 2011-03-02 23:38 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-11-18 08:13 - 2011-03-02 23:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-11-18 08:13 - 2011-02-17 23:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-11-18 08:12 - 2014-10-13 19:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-11-18 08:12 - 2014-10-09 18:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-11-18 08:12 - 2014-10-02 19:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-11-18 08:12 - 2014-10-02 19:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-11-18 08:12 - 2014-10-02 19:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-11-18 08:12 - 2014-10-02 19:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-11-18 08:12 - 2014-10-02 19:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-11-18 08:12 - 2014-09-03 23:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-11-18 08:12 - 2014-08-22 19:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-11-18 08:12 - 2014-08-21 00:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-11-18 08:12 - 2014-08-21 00:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-11-18 08:12 - 2014-08-11 19:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-11-18 08:12 - 2014-03-26 08:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-11-18 08:12 - 2014-03-26 08:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-11-18 08:12 - 2014-03-04 03:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-11-18 08:12 - 2014-01-27 20:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-11-18 08:12 - 2013-11-23 12:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-11-18 08:12 - 2013-10-11 20:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-11-18 08:12 - 2013-10-11 20:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-11-18 08:12 - 2013-10-11 19:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-11-18 08:12 - 2013-10-11 19:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-11-18 08:12 - 2013-08-27 18:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-11-18 08:12 - 2013-07-20 04:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-11-18 08:12 - 2013-06-05 22:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-11-18 08:12 - 2013-06-05 22:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-11-18 08:12 - 2013-06-05 22:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-11-18 08:12 - 2013-06-05 21:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-11-18 08:12 - 2013-06-05 21:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-11-18 08:12 - 2013-05-12 21:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-11-18 08:12 - 2013-05-12 21:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-11-18 08:12 - 2013-05-09 21:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-11-18 08:12 - 2013-04-25 22:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-11-18 08:12 - 2013-04-09 17:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-11-18 08:12 - 2013-03-18 21:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-11-18 08:12 - 2012-08-21 14:12 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-11-18 08:12 - 2011-12-29 23:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-11-18 08:12 - 2011-08-26 22:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-11-18 08:12 - 2011-08-16 22:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-11-18 08:12 - 2011-08-16 22:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-11-18 08:12 - 2011-07-08 20:30 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-11-18 08:12 - 2011-05-24 04:44 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-11-18 08:12 - 2011-05-02 22:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-11-18 08:12 - 2011-04-26 20:17 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-11-18 08:12 - 2011-04-26 20:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-11-18 08:11 - 2014-11-05 11:50 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-11-18 08:11 - 2014-11-05 11:50 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-11-18 08:11 - 2014-11-05 11:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-11-18 08:11 - 2014-09-24 19:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-11-18 08:11 - 2014-09-19 03:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-11-18 08:11 - 2014-09-19 03:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-11-18 08:11 - 2014-09-19 03:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-11-18 08:11 - 2014-09-19 03:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-11-18 08:11 - 2014-09-19 03:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-11-18 08:11 - 2014-09-19 03:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-11-18 08:11 - 2014-08-01 05:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-11-18 08:11 - 2014-06-23 20:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-11-18 08:11 - 2014-06-17 19:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-11-18 08:11 - 2014-06-06 03:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-11-18 08:11 - 2014-06-03 03:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-11-18 08:11 - 2014-06-03 03:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-11-18 08:11 - 2014-06-03 03:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-11-18 08:11 - 2014-05-30 00:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-11-18 08:11 - 2014-04-04 20:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-11-18 08:11 - 2014-04-04 20:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-11-18 08:11 - 2014-02-03 20:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-11-18 08:11 - 2014-02-03 20:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-11-18 08:11 - 2014-02-03 20:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-11-18 08:11 - 2014-02-03 20:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-11-18 08:11 - 2014-02-03 20:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-11-18 08:11 - 2014-01-23 20:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-11-18 08:11 - 2013-11-26 05:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-11-18 08:11 - 2013-10-03 19:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-11-18 08:11 - 2013-10-03 19:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-11-18 08:11 - 2013-07-25 02:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-11-18 08:11 - 2012-10-03 10:42 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-11-18 08:11 - 2012-10-03 10:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-11-18 08:11 - 2012-10-03 10:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-11-18 08:11 - 2012-10-03 10:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-11-18 08:11 - 2012-10-03 10:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-11-18 08:11 - 2012-10-03 10:40 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-11-18 08:11 - 2012-10-03 09:21 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-11-18 08:11 - 2012-07-04 15:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-11-18 08:11 - 2012-07-04 15:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-11-18 08:11 - 2012-07-04 15:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-11-18 08:11 - 2012-06-05 23:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-11-18 08:11 - 2012-05-05 01:46 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-11-18 08:11 - 2011-10-25 22:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-11-18 08:11 - 2011-10-14 23:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-11-18 08:11 - 2011-05-03 22:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-11-18 08:11 - 2011-05-03 22:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-11-18 08:11 - 2011-05-03 22:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-11-18 08:11 - 2011-05-03 22:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-11-18 08:11 - 2011-05-03 22:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-11-18 08:11 - 2011-05-03 22:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-11-18 08:11 - 2011-05-03 22:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-11-18 08:11 - 2011-05-03 22:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-11-18 08:11 - 2011-05-03 22:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-11-18 08:11 - 2011-02-11 23:35 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-11-18 08:11 - 2010-12-22 23:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-11-18 08:11 - 2010-12-22 23:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-11-18 08:11 - 2010-12-22 23:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-11-18 08:10 - 2014-10-24 19:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-11-18 08:10 - 2014-07-16 19:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-11-18 08:10 - 2014-07-16 19:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-11-18 08:10 - 2014-07-16 19:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-11-18 08:10 - 2014-07-16 19:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-11-18 08:10 - 2014-07-16 19:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-11-18 08:10 - 2014-06-18 16:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-11-18 08:10 - 2014-06-18 16:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-11-18 08:10 - 2014-06-18 16:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-11-18 08:10 - 2013-10-11 20:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-11-18 08:10 - 2013-10-11 20:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-11-18 08:10 - 2013-10-11 20:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-11-18 08:10 - 2013-08-04 19:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-11-18 08:10 - 2013-07-25 19:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-11-18 08:10 - 2013-07-04 05:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-11-18 08:10 - 2013-07-04 05:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-11-18 08:10 - 2013-07-04 03:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-11-18 08:10 - 2012-12-07 06:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-11-18 08:10 - 2012-12-07 06:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-11-18 08:10 - 2012-12-07 04:46 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-11-18 08:10 - 2012-12-07 04:46 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-11-18 08:10 - 2012-09-25 16:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-11-18 08:10 - 2012-05-13 22:33 - 00769024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-11-18 08:10 - 2012-04-30 22:44 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-11-18 08:10 - 2012-04-25 22:45 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-11-18 08:10 - 2012-04-25 22:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-11-18 08:10 - 2012-03-17 01:27 - 00056176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-11-18 08:10 - 2012-01-04 02:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-11-18 08:10 - 2011-12-16 01:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-11-18 08:10 - 2011-11-16 23:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-11-18 08:10 - 2011-06-15 02:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\odbcjt32.dll
2014-11-18 08:10 - 2011-06-15 02:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-11-18 08:10 - 2011-06-15 02:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-11-18 08:10 - 2011-06-15 02:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-11-18 08:10 - 2011-06-15 02:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-11-18 08:09 - 2014-11-05 20:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-11-18 08:09 - 2014-10-13 19:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-11-18 08:09 - 2014-10-13 19:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-11-18 08:09 - 2014-10-13 19:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-11-18 08:09 - 2014-10-13 19:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-11-18 08:09 - 2014-10-13 19:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-11-18 08:09 - 2014-09-09 15:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-11-18 08:09 - 2014-06-24 19:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-11-18 08:09 - 2014-04-24 20:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-11-18 08:09 - 2014-04-11 20:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-11-18 08:09 - 2014-04-11 20:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-11-18 08:09 - 2014-04-11 20:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-11-18 08:09 - 2014-04-11 20:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-11-18 08:09 - 2014-04-11 20:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-11-18 08:09 - 2014-03-04 03:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-11-18 08:09 - 2014-01-28 20:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-11-18 08:09 - 2013-12-03 20:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-11-18 08:09 - 2013-12-03 20:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-11-18 08:09 - 2013-12-03 20:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-11-18 08:09 - 2013-12-03 20:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-11-18 08:09 - 2013-12-03 20:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-11-18 08:09 - 2013-12-03 19:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-11-18 08:09 - 2013-12-03 19:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-11-18 08:09 - 2013-12-03 19:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-11-18 08:09 - 2013-12-03 19:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-11-18 08:09 - 2013-11-26 19:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-11-18 08:09 - 2013-11-26 19:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-11-18 08:09 - 2013-11-26 19:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-11-18 08:09 - 2013-11-26 19:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-11-18 08:09 - 2013-11-26 19:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-11-18 08:09 - 2013-11-26 19:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-11-18 08:09 - 2013-11-26 19:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-11-18 08:09 - 2013-11-26 02:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-11-18 08:09 - 2013-10-05 13:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-11-18 08:09 - 2013-08-01 19:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 18:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-11-18 08:09 - 2013-08-01 18:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 18:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 18:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-11-18 08:09 - 2013-08-01 18:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-11-18 08:09 - 2013-07-12 04:08 - 00146816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-11-18 08:09 - 2013-07-12 04:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-11-18 08:09 - 2013-07-12 04:07 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2014-11-18 08:09 - 2013-07-08 22:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-11-18 08:09 - 2013-07-08 22:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-11-18 08:09 - 2013-07-04 06:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-11-18 08:09 - 2013-06-25 16:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-11-18 08:09 - 2012-11-28 16:57 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-11-18 08:09 - 2012-11-28 16:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-11-18 08:09 - 2012-11-28 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-11-18 08:09 - 2012-10-09 11:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-11-18 08:09 - 2012-10-09 11:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-11-18 08:09 - 2011-03-10 23:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-11-18 08:09 - 2011-03-10 23:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-11-18 08:09 - 2011-02-22 22:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-11-18 07:56 - 2013-02-26 22:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-11-18 07:52 - 2012-02-16 23:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-11-18 07:52 - 2012-02-16 22:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-11-18 07:45 - 2014-05-14 10:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-11-18 07:45 - 2014-05-14 10:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-11-18 07:45 - 2014-05-14 10:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-11-18 07:45 - 2014-05-14 10:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-11-18 07:45 - 2014-05-14 10:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-11-18 07:45 - 2014-05-14 10:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-11-18 07:45 - 2014-05-14 10:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-11-18 07:45 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-11-18 07:45 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-11-18 07:23 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
2014-11-18 07:23 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Tracker Software
2014-11-18 07:23 - 2014-11-18 07:23 - 00001171 _____ () C:\Users\Public\Desktop\PDF-Viewer.lnk
2014-11-18 04:37 - 2014-11-23 09:15 - 00000000 ___SD () C:\Users\Rickey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-11-18 04:37 - 2014-11-18 04:37 - 00001142 _____ () C:\Users\Rickey\Desktop\OpenOffice 4.1.1.lnk
2014-11-18 04:36 - 2014-11-23 09:06 - 00000000 ____D () C:\Program Files\OpenOffice 4
2014-11-18 03:59 - 2014-11-18 03:59 - 19781632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 12819456 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-11-18 03:59 - 2014-11-18 03:59 - 02277376 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-11-18 03:59 - 2014-11-18 03:59 - 01892864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-11-18 03:59 - 2014-11-18 03:59 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00341168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-11-18 03:59 - 2014-11-18 03:59 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-11-18 03:59 - 2014-11-18 03:59 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-11-18 03:59 - 2014-11-18 03:59 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-11-18 03:59 - 2014-11-18 03:59 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-11-18 03:57 - 2014-11-18 03:57 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-11-18 03:56 - 2014-11-18 03:56 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-11-18 03:35 - 2014-08-11 07:26 - 00000773 ____N () C:\Users\Rickey\Documents\indexfile.txt
2014-11-18 03:32 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup
2014-11-18 03:32 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\MozBackup
2014-11-18 03:32 - 2014-11-18 03:32 - 00000985 _____ () C:\Users\Public\Desktop\MozBackup.lnk
2014-11-18 03:30 - 2014-11-23 09:15 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Thunderbird
2014-11-18 03:30 - 2014-11-18 03:30 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Thunderbird
2014-11-17 18:02 - 2014-11-17 18:02 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Macromedia
2014-11-17 18:02 - 2014-11-17 18:02 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Macromedia
2014-11-17 18:01 - 2014-11-23 09:16 - 00000000 ____D () C:\Windows\system32\SPReview
2014-11-17 18:01 - 2014-11-23 09:16 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-11-17 16:51 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2014-11-17 16:51 - 2014-11-17 16:51 - 00002044 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-11-17 16:51 - 2014-11-17 16:51 - 00002032 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-11-17 16:51 - 2014-11-17 16:51 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-17 16:37 - 2014-11-26 09:49 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-11-17 16:37 - 2014-11-26 09:49 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-11-17 16:37 - 2014-11-23 09:16 - 00000000 ____D () C:\Windows\system32\Macromed
2014-11-17 16:11 - 2014-11-23 09:06 - 00000000 ____D () C:\Program Files\VS Revo Group
2014-11-17 16:11 - 2014-11-17 16:11 - 00001222 _____ () C:\Users\Rickey\Desktop\Revo Uninstaller.lnk
2014-11-17 16:09 - 2014-11-24 18:52 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Adobe
2014-11-17 16:04 - 2014-11-23 09:07 - 00000000 ____D () C:\ProgramData\Creative
2014-11-17 16:01 - 2010-08-11 08:50 - 01254400 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\ksaud.sys
2014-11-17 16:01 - 2010-08-05 02:26 - 00192512 _____ (Creative Technology Ltd.) C:\Windows\system32\KSVSPI32.dll
2014-11-17 16:01 - 2010-08-02 22:28 - 00104448 _____ (Creative Technology Ltd.) C:\Windows\system32\SBAVMon.dll
2014-11-17 16:01 - 2010-07-23 13:13 - 00044795 _____ () C:\Windows\system32\kschimp.ini
2014-11-17 16:01 - 2010-07-22 04:13 - 00631431 _____ (Creative Technology Ltd) C:\Windows\KSAIM32.exe
2014-11-17 16:01 - 2010-07-22 02:37 - 00728576 _____ (Creative Technology Ltd.) C:\Windows\system32\KSAPO32.dll
2014-11-17 16:01 - 2010-07-22 02:37 - 00047104 _____ (Creative Technology Ltd.) C:\Windows\system32\KSPPLD32.dll
2014-11-17 16:01 - 2010-06-23 00:54 - 00003077 _____ () C:\ProgramData\cfSB1290.ini
2014-11-17 16:01 - 2010-06-02 02:26 - 00004534 _____ () C:\Windows\system32\SB.bmp
2014-11-17 16:01 - 2009-11-10 23:42 - 00196608 _____ (Creative Technology Limited) C:\Windows\system32\KsDvInst.dll
2014-11-17 16:00 - 2014-11-26 08:12 - 00000214 ___RH () C:\Windows\ctfile.rfc
2014-11-17 15:59 - 2006-10-06 14:17 - 00053248 ____N (Creative Technology Ltd ) C:\Windows\Ctregrun.exe
2014-11-17 15:59 - 2003-06-12 23:25 - 00007062 _____ () C:\Windows\system32\audiopid.vxd
2014-11-17 15:59 - 2000-05-22 16:58 - 00647872 ____N (Microsoft Corporation) C:\Windows\system32\Mscomct2.ocx
2014-11-17 15:58 - 2014-11-26 08:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2014-11-17 15:57 - 2014-11-26 08:12 - 00000000 ____D () C:\Program Files\Creative
2014-11-17 15:57 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2014-11-17 14:12 - 2014-11-26 15:18 - 00000000 ____D () C:\Windows\pss
2014-11-17 14:09 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2014-11-17 14:09 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\CCleaner
2014-11-17 14:09 - 2014-11-17 14:09 - 00000965 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2014-11-17 13:54 - 2014-11-26 17:30 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-11-17 13:53 - 2014-07-02 14:54 - 00061728 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-11-17 13:53 - 2014-07-02 13:42 - 04389848 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-11-17 13:53 - 2014-07-02 13:42 - 03063256 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll
2014-11-17 13:53 - 2014-07-02 13:42 - 00670552 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-11-17 13:53 - 2014-07-02 13:42 - 00377288 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-11-17 13:53 - 2014-07-02 13:42 - 00062936 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-11-17 13:53 - 2014-07-01 23:14 - 03826628 _____ () C:\Windows\system32\nvcoproc.bin
2014-11-17 13:51 - 2014-07-02 14:54 - 24198088 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv32.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 16122344 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2um.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 15296456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 14498552 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dum.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 11283344 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 11222048 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 10681176 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2014-11-17 13:51 - 2014-07-02 14:54 - 03988952 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 02814656 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 01054552 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco3234052.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 00907552 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco3234052.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 00907096 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 00869152 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC.dll
2014-11-17 13:51 - 2014-07-02 14:54 - 00021215 _____ () C:\Windows\system32\nvinfo.pb
2014-11-17 13:22 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-11-17 13:22 - 2014-11-23 09:08 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Mozilla
2014-11-17 13:22 - 2014-11-17 13:22 - 00001117 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-11-17 13:22 - 2014-11-17 13:22 - 00001105 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-11-17 13:22 - 2014-11-17 13:22 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Mozilla
2014-11-17 13:21 - 2010-11-20 06:32 - 05066752 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2014-11-17 13:21 - 2010-11-20 06:30 - 00245632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-11-17 13:21 - 2010-11-20 06:29 - 00520064 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-11-17 13:21 - 2010-11-20 06:29 - 00014208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys
2014-11-17 13:21 - 2010-11-20 06:24 - 00508904 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-11-17 13:21 - 2010-11-20 06:24 - 00442720 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-11-17 13:21 - 2010-11-20 06:23 - 00144768 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 02755072 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01712640 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01667584 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01363456 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01175040 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01159168 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01128448 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01115136 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01086976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 01063936 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00974336 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00750592 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00335872 _____ (Microsoft Corporation) C:\Windows\system32\WinSATAPI.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00269824 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\upnp.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2014-11-17 13:21 - 2010-11-20 06:21 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 01414144 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00563712 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2014-11-17 13:21 - 2010-11-20 06:20 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL
2014-11-17 13:21 - 2010-11-20 06:19 - 03207680 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 02291712 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 02151936 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 01493504 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00954752 _____ (Microsoft Corporation) C:\Windows\system32\mfc40.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00954288 _____ (Microsoft Corporation) C:\Windows\system32\mfc40u.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00732160 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-11-17 13:21 - 2010-11-20 06:19 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 02522624 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 01828352 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 01555456 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 01371136 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 01334272 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00863744 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00854016 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00762880 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-11-17 13:21 - 2010-11-20 06:18 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00252928 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
2014-11-17 13:21 - 2010-11-20 06:18 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\dot3api.dll
2014-11-17 13:21 - 2010-11-20 06:17 - 03367424 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 01025536 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 00280576 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\lsm.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
2014-11-17 13:21 - 2010-11-20 06:17 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-11-17 13:21 - 2010-11-20 06:16 - 00776192 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2014-11-17 13:21 - 2010-11-20 04:22 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2014-11-17 13:21 - 2010-11-20 04:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\1394ohci.sys
2014-11-17 13:21 - 2010-11-20 02:40 - 00513536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2014-11-17 13:21 - 2010-11-04 20:20 - 00146852 _____ () C:\Windows\system32\systemsf.ebd
2014-11-17 13:21 - 2010-11-04 19:58 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2014-11-17 13:21 - 2010-11-04 19:58 - 00049488 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2014-11-17 13:21 - 2010-11-04 19:53 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2014-11-17 13:21 - 2010-11-04 19:53 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2014-11-17 13:20 - 2010-11-20 06:36 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2014-11-17 13:20 - 2010-11-20 06:36 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\NAPHLPR.DLL
2014-11-17 13:20 - 2010-11-20 06:36 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\NAPCRYPT.DLL
2014-11-17 13:20 - 2010-11-20 06:30 - 00173440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00160128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00153984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00140160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scsiport.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00130432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpio.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00116096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00085376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sbp2port.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00078208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2014-11-17 13:20 - 2010-11-20 06:30 - 00028032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2014-11-17 13:20 - 2010-11-20 06:29 - 02217856 _____ (Microsoft Corporation) C:\Windows\system32\bootres.dll
2014-11-17 13:20 - 2010-11-20 06:29 - 00274304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2014-11-17 13:20 - 2010-11-20 06:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2014-11-17 13:20 - 2010-11-20 06:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-11-17 13:20 - 2010-11-20 06:29 - 00137088 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2014-11-17 13:20 - 2010-11-20 06:24 - 00690680 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-11-17 13:20 - 2010-11-20 06:24 - 00271664 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 02983424 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 02202624 _____ (Microsoft Corporation) C:\Windows\system32\SensorsCpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 02157568 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 01624064 _____ (Microsoft Corporation) C:\Windows\system32\WMPEncEn.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 01326592 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 01227776 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 01003008 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\Vault.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00907776 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2014-11-17 13:20 - 2010-11-20 06:21 - 00782336 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00766464 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00755200 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00750080 _____ (Microsoft Corporation) C:\Windows\system32\sdcpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00739328 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2014-11-17 13:20 - 2010-11-20 06:21 - 00738816 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00697344 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\VAN.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00577024 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00541184 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2014-11-17 13:20 - 2010-11-20 06:21 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmdev.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00463360 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00436736 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmnet.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00428544 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\wiadefui.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00410624 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00380416 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\wbemcomn.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\termmgr.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00352256 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00350720 _____ (Microsoft Corporation) C:\Windows\system32\WPDSp.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00318976 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\sqlcese30.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00307712 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00276992 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\srrstr.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\taskbarcpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\wavemsp.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\unattend.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\wpdwcn.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\wmpsrcwp.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\syncui.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\remotepg.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\twext.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\recovery.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\sdrsvc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\uxlib.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00111104 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\wiavideo.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WPDShServiceObj.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\wmpshell.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\sppinst.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\srvcli.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\QUTIL.DLL
2014-11-17 13:20 - 2010-11-20 06:21 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountControlSettings.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\unimdmat.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\vfwwdm32.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\sppuinotify.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rdpd3d.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00051200 _____ (Twain Working Group) C:\Windows\twain_32.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\samcli.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\umb.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\wkscli.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\WavDest.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\RpcRtRemote.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wtsapi32.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\shimgvw.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wiarpc.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\wdiasqmmodule.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\utildll.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\vpnikeapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\TRAPI.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\rdprefdrvapi.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\shgina.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\spopk.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\sisbkup.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\schedcli.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\syssetup.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\wshirda.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\shunimpl.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\riched32.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\rdpcfgex.dll
2014-11-17 13:20 - 2010-11-20 06:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-11-17 13:20 - 2010-11-20 06:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 02504192 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2014-11-17 13:20 - 2010-11-20 06:20 - 02494464 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 02130944 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 01750528 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 01661440 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 01644032 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\onexui.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00932352 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceStatus.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00395264 _____ (Microsoft Corporation) C:\Windows\system32\prnfldr.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\nshipsec.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00283136 _____ (Microsoft Corporation) C:\Windows\system32\qdv.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\netdiagfx.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\OnLineIDCpl.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\qcap.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceSyncProvider.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\ocsetapi.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\QAGENT.DLL
2014-11-17 13:20 - 2010-11-20 06:20 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\QSHVHOST.DLL
2014-11-17 13:20 - 2010-11-20 06:20 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\provsvc.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\netjoin.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\mydocs.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\prntvpt.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\netid.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\prncache.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\QSVRMGMT.DLL
2014-11-17 13:20 - 2010-11-20 06:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\nci.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\olethk32.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\QCLIPROV.DLL
2014-11-17 13:20 - 2010-11-20 06:20 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\ntlanman.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\napdsnap.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\PrintIsolationProxy.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\profprov.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\netutils.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\perfts.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\nrpsrv.dll
2014-11-17 13:20 - 2010-11-20 06:20 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 01066496 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\FirewallControlPanel.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2014-11-17 13:20 - 2010-11-20 06:19 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00592384 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00429056 _____ (Microsoft Corporation) C:\Windows\system32\localsec.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\msdri.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\mspbda.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2014-11-17 13:20 - 2010-11-20 06:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\hgcpl.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\MSAC3ENC.DLL
2014-11-17 13:20 - 2010-11-20 06:19 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\iTVData.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\mstask.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\ListSvc.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\hgprint.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\fde.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\msvfw32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL
2014-11-17 13:20 - 2010-11-20 06:19 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\fphc.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00093696 _____ (Windows ® Codename Longhorn DDK provider) C:\Windows\system32\fms.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\mciavi32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00082944 _____ (Radius Inc.) C:\Windows\system32\iccvid.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\KMSVC.DLL
2014-11-17 13:20 - 2010-11-20 06:19 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\Mcx2Svc.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\inetmib1.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\luainstall.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\FXSMON.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\mciqtz32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\msdmo.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\iscsium.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\HotStartUserAgent.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\lsmproxy.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll
2014-11-17 13:20 - 2010-11-20 06:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 03727872 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 01400320 _____ (Microsoft Corporation) C:\Windows\system32\DxpTaskSync.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 01188864 _____ (Microsoft Corporation) C:\Windows\system32\DiagCpl.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 01040384 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 01003520 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00740864 _____ (Microsoft Corporation) C:\Windows\system32\batmeter.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00685056 _____ (Microsoft Corporation) C:\Windows\system32\dsuiext.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00665600 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00537600 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenterCPL.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCenter.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\biocpl.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00402944 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\dot3ui.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\azroleui.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\dpx.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\audiodev.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\defaultlocationcpl.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingFolder.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\dxdiagn.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\activeds.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\dskquoui.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\adsldp.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\ActionQueue.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cfgmgr32.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\dps.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\bcdsrv.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\dnscmmc.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\avifil32.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\cabinet.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\amstream.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\cca.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\CertPolEng.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acppage.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dsauth.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\AzSqlExt.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\elsTrans.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\bitsperf.dll
2014-11-17 13:20 - 2010-11-20 06:18 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\C_ISCII.DLL
2014-11-17 13:20 - 2010-11-20 06:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll
2014-11-17 13:20 - 2010-11-20 06:17 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 01131008 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00941568 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\WFS.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\dfrgui.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\FXSSVC.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00477696 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00453632 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\slui.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00257536 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgrade.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\msconfig.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\taskmgr.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\recdisc.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00182784 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\iscsicli.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\net1.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\MdSched.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\setupugc.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\setupcl.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\mobsync.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00098816 _____ (Microsoft) C:\Windows\system32\Robocopy.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\isoburn.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\cmstp.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\tabcal.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\MuiUnattend.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\w32tm.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\manage-bde.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\djoin.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\repair-bde.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\MultiDigiMon.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\takeown.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\runonce.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\tzutil.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\unlodctr.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\proquota.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\userinit.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netiougc.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netcfg.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe
2014-11-17 13:20 - 2010-11-20 06:17 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\LogonUI.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00905216 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00878592 _____ (Microsoft Corporation) C:\Windows\system32\Bubbles.scr
2014-11-17 13:20 - 2010-11-20 06:16 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00668160 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00658944 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\TabletPC.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00516096 _____ (Microsoft Corporation) C:\Windows\system32\main.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2014-11-17 13:20 - 2010-11-20 06:16 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2014-11-17 13:20 - 2010-11-20 06:16 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00326656 _____ (Microsoft Corporation) C:\Windows\system32\sysdm.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2014-11-17 13:20 - 2010-11-20 06:16 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\ssText3d.scr
2014-11-17 13:20 - 2010-11-20 06:16 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2014-11-17 13:20 - 2010-11-20 06:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\Mystify.scr
2014-11-17 13:20 - 2010-11-20 06:16 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\Ribbons.scr
2014-11-17 13:20 - 2010-11-20 06:16 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\bitsadmin.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv
2014-11-17 13:20 - 2010-11-20 06:16 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\desk.cpl
2014-11-17 13:20 - 2010-11-20 06:16 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\aitagent.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\kstvtune.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\WSTPager.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00065024 _____ (Microsoft Corporation) C:\Windows\bfsvc.exe
2014-11-17 13:20 - 2010-11-20 06:16 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ksxbar.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\g711codc.ax
2014-11-17 13:20 - 2010-11-20 06:16 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\vbisurf.ax
2014-11-17 13:20 - 2010-11-20 06:07 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2014-11-17 13:20 - 2010-11-20 06:07 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwizres.dll
2014-11-17 13:20 - 2010-11-20 06:06 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2014-11-17 13:20 - 2010-11-20 06:05 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\RDPENCDD.dll
2014-11-17 13:20 - 2010-11-20 06:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\pifmgr.dll
2014-11-17 13:20 - 2010-11-20 06:00 - 01027584 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2014-11-17 13:20 - 2010-11-20 06:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2014-11-17 13:20 - 2010-11-20 06:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDSG.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdlk41a.dll
2014-11-17 13:20 - 2010-11-20 06:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDCZ1.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUQ.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUF.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDSF.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDPO.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDNEPR.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGR1.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGKL.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUS.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUGHR1.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTURME.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAJIK.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMON.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMAORI.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDLT1.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBULG.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBLR.DLL
2014-11-17 13:20 - 2010-11-20 06:00 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDGEO.DLL
2014-11-17 13:20 - 2010-11-20 05:57 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2014-11-17 13:20 - 2010-11-20 05:56 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\BlbEvents.dll
2014-11-17 13:20 - 2010-11-20 04:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbrpm.sys
2014-11-17 13:20 - 2010-11-20 04:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RDPCDD.sys
2014-11-17 13:20 - 2010-11-20 04:21 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\RDPREFDD.dll
2014-11-17 13:20 - 2010-11-20 04:21 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdpipe.sys
2014-11-17 13:20 - 2010-11-20 04:07 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys
2014-11-17 13:20 - 2010-11-20 04:07 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2014-11-17 13:20 - 2010-11-20 04:07 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2014-11-17 13:20 - 2010-11-20 04:06 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2014-11-17 13:20 - 2010-11-20 04:06 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2014-11-17 13:20 - 2010-11-20 04:06 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndisuio.sys
2014-11-17 13:20 - 2010-11-20 04:00 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2014-11-17 13:20 - 2010-11-20 04:00 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\umbus.sys
2014-11-17 13:20 - 2010-11-20 04:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys
2014-11-17 13:20 - 2010-11-20 04:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys
2014-11-17 13:20 - 2010-11-20 03:59 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-11-17 13:20 - 2010-11-20 03:59 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2014-11-17 13:20 - 2010-11-20 03:50 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-11-17 13:20 - 2010-11-20 03:50 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\CompositeBus.sys
2014-11-17 13:20 - 2010-11-20 03:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys
2014-11-17 13:20 - 2010-11-20 03:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffp_sd.sys
2014-11-17 13:20 - 2010-11-20 03:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-11-17 13:20 - 2010-11-20 03:24 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2014-11-17 13:20 - 2010-11-20 03:19 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-11-17 13:20 - 2010-11-20 02:47 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpipmi.sys
2014-11-17 13:20 - 2010-11-20 02:44 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-11-17 13:20 - 2010-11-20 02:42 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2014-11-17 13:20 - 2010-11-20 02:42 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-11-17 13:20 - 2010-11-20 02:39 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2014-11-17 13:20 - 2010-11-20 02:39 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-11-17 13:20 - 2010-11-20 02:39 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdi.sys
2014-11-17 13:20 - 2010-11-20 02:38 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2014-11-17 13:20 - 2010-11-19 23:23 - 00053600 _____ () C:\Windows\system32\dosx.exe
2014-11-17 13:20 - 2010-11-09 19:45 - 00010429 _____ () C:\Windows\system32\ScavengeSpace.xml
2014-11-17 13:20 - 2010-11-04 20:20 - 00105559 _____ () C:\Windows\system32\RacRules.xml
2014-11-17 13:20 - 2010-11-04 20:11 - 00312168 _____ (Microsoft Corporation) C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2014-11-17 12:15 - 2014-11-17 12:15 - 00000000 ____D () C:\Users\Rickey\AppData\Local\Apps\2.0
2014-11-17 12:14 - 2014-11-17 13:07 - 00000000 ____D () C:\ProgramData\CanonIJScan
2014-11-17 12:12 - 2014-11-17 12:14 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Canon
2014-11-17 11:10 - 2014-11-23 09:13 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-17 10:57 - 2014-11-23 09:08 - 00000000 ____D () C:\Users\Rickey\AppData\Local\NVIDIA
2014-11-17 10:21 - 2014-11-17 14:10 - 00000000 ____D () C:\Windows\Minidump
2014-11-17 10:05 - 2014-11-26 15:12 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-11-17 10:05 - 2014-11-17 13:52 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-11-17 10:03 - 2014-11-17 10:04 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-17 10:03 - 2014-10-31 23:25 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-17 10:02 - 2011-04-08 23:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-11-17 09:19 - 2014-11-20 18:38 - 00000000 ____D () C:\ProgramData\Adobe
2014-11-17 09:19 - 2014-11-04 14:30 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-11-17 09:18 - 2014-11-18 02:24 - 00000000 ____D () C:\Program Files\Belkin
2014-11-17 09:18 - 2014-11-17 12:47 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\Adobe
2014-11-17 09:14 - 2014-11-26 08:08 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-11-17 09:14 - 2014-11-18 01:13 - 00000000 ____D () C:\Program Files\Netgear
2014-11-17 09:14 - 2010-05-05 07:01 - 00278560 _____ (Netgear) C:\Windows\system32\Drivers\G311N6.sys
2014-11-17 09:14 - 2009-12-03 03:27 - 00080416 _____ () C:\Windows\system32\RtNicProp.dll
2014-11-17 09:03 - 2014-11-26 15:42 - 00064024 _____ () C:\Users\Rickey\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-17 09:03 - 2014-11-17 09:03 - 00000000 ____D () C:\ProgramData\CanonIJQuickMenu
2014-11-17 09:00 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-11-17 09:00 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG3500 series Manual
2014-11-17 09:00 - 2014-11-17 09:00 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-11-17 08:59 - 2014-11-23 09:15 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-11-17 08:59 - 2014-11-17 08:59 - 00002304 _____ () C:\Users\Public\Desktop\Canon MG3500 series On-screen Manual.lnk
2014-11-17 08:58 - 2014-11-17 08:58 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-11-17 08:56 - 2014-11-23 09:05 - 00000000 ____D () C:\Program Files\Canon
2014-11-17 08:51 - 2014-11-23 09:07 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-11-17 08:51 - 2013-04-04 05:00 - 00317952 _____ (CANON INC.) C:\Windows\system32\CNMLMBV.DLL
2014-11-17 08:51 - 2013-02-04 15:10 - 00321536 _____ (CANON INC.) C:\Windows\system32\CNC_BVL.dll
2014-11-17 08:51 - 2012-11-26 12:32 - 00088576 _____ () C:\Windows\system32\CNC176ED.TBL
2014-11-17 08:51 - 2012-11-08 13:03 - 00262656 _____ (CANON INC.) C:\Windows\system32\CNC_BVC.dll
2014-11-17 08:51 - 2012-11-08 13:02 - 00096768 _____ (CANON INC.) C:\Windows\system32\CNC_BVI.dll
2014-11-17 08:51 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\system32\CNHMCA.dll
2014-11-17 08:50 - 2014-11-23 09:15 - 00000000 ____D () C:\Users\Rickey\AppData\Local\lptmp369672632
2014-11-17 08:50 - 2014-11-17 08:50 - 10395072 _____ (Webroot Software, Inc.) C:\Program Files\Common Files\wruninstall.exe
2014-11-17 08:49 - 2014-11-26 17:38 - 00000000 ____D () C:\ProgramData\WRData
2014-11-17 08:49 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2014-11-17 08:49 - 2014-11-23 09:15 - 00000000 ____D () C:\Program Files\Webroot
2014-11-17 08:49 - 2014-11-23 07:29 - 00153256 _____ (Webroot) C:\Windows\system32\WRusr.dll
2014-11-17 08:49 - 2014-11-23 07:29 - 00116736 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2014-11-17 08:47 - 2014-11-23 09:15 - 00000000 ____D () C:\Users\Rickey\AppData\Roaming\QFX Software
2014-11-17 08:47 - 2014-11-23 09:15 - 00000000 ____D () C:\ProgramData\QFX Software
2014-11-17 08:44 - 2014-11-26 17:25 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-17 08:44 - 2014-11-17 08:44 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-11-17 08:43 - 2014-11-24 03:42 - 00000000 ____D () C:\Users\Rickey
2014-11-17 08:43 - 2014-11-23 09:15 - 00000000 ___RD () C:\Users\Rickey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-17 08:43 - 2014-11-23 09:15 - 00000000 ___RD () C:\Users\Rickey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-17 08:43 - 2014-11-17 08:43 - 00001413 _____ () C:\Users\Rickey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-17 08:43 - 2014-11-17 08:43 - 00000020 ___SH () C:\Users\Rickey\ntuser.ini
2014-11-17 08:43 - 2014-11-17 08:43 - 00000000 ____D () C:\Users\Rickey\AppData\Local\VirtualStore
2014-11-17 08:43 - 2014-11-17 08:43 - 00000000 ____D () C:\Recovery
2014-11-17 08:37 - 2014-11-26 17:34 - 01325065 _____ () C:\Windows\WindowsUpdate.log
2014-11-17 08:37 - 2014-11-17 08:37 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2014-11-17 08:37 - 2014-11-17 08:37 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-11-17 08:33 - 2014-11-20 18:36 - 00000000 ____D () C:\Windows\Panther
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-11-26 15:22 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-26 15:16 - 2009-07-13 22:34 - 00022352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-11-26 15:16 - 2009-07-13 22:34 - 00022352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-11-26 15:15 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-11-26 15:08 - 2009-07-13 22:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-11-26 15:08 - 2009-07-13 22:33 - 00286544 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-11-24 07:59 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\rescache
2014-11-23 13:01 - 2014-10-08 11:37 - 00000000 ____D () C:\Users\Rickey\Documents\Chameleon
2014-11-23 09:16 - 2009-07-14 01:48 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-11-23 09:16 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\twain_32
2014-11-23 09:16 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\Offline Web Pages
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 __RSD () C:\Windows\Media
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ___RD () C:\Users\Public
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\TAPI
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\wfp
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\Msdtc
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\security
2014-11-23 09:16 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-11-23 09:15 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Help
2014-11-23 09:15 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\AppCompat
2014-11-23 09:15 - 2009-07-13 20:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-11-23 09:14 - 2009-07-13 22:56 - 00000000 ____D () C:\Windows\system32\winrm
2014-11-23 09:14 - 2009-07-13 22:56 - 00000000 ____D () C:\Windows\system32\WCN
2014-11-23 09:14 - 2009-07-13 22:56 - 00000000 ____D () C:\Windows\system32\slmgr
2014-11-23 09:14 - 2009-07-13 22:56 - 00000000 ____D () C:\Windows\system32\Printing_Admin_Scripts
2014-11-23 09:14 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\system32\WindowsPowerShell
2014-11-23 09:14 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\system32\WinBioPlugIns
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Web
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Vss
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\spp
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\spool
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\Speech
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\SMI
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\NetworkList
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\MUI
2014-11-23 09:14 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\registration
2014-11-23 09:13 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\IME
2014-11-23 09:13 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\com
2014-11-23 09:12 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Speech
2014-11-23 09:11 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\Performance
2014-11-23 09:11 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\schemas
2014-11-23 09:11 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Resources
2014-11-23 09:11 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\PLA
2014-11-23 09:09 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\IME
2014-11-23 09:09 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Globalization
2014-11-23 09:09 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Branding
2014-11-23 09:07 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-11-23 09:07 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-11-23 09:07 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Defender
2014-11-23 09:07 - 2009-07-13 20:37 - 00000000 __RHD () C:\Users\Default
2014-11-23 09:07 - 2009-07-13 20:37 - 00000000 ____D () C:\Program Files\Windows NT
2014-11-23 09:06 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Reference Assemblies
2014-11-23 09:06 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\MSBuild
2014-11-23 09:05 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\DVD Maker
2014-11-23 09:05 - 2009-07-13 20:37 - 00000000 ____D () C:\Program Files\Common Files\System
2014-11-23 09:05 - 2009-07-13 20:37 - 00000000 ____D () C:\Program Files\Common Files\SpeechEngines
2014-11-18 07:17 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\sv-SE
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\pt-PT
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\pt-BR
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\pl-PL
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\nl-NL
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\ko-KR
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\it-IT
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\hu-HU
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\fr-FR
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\fi-FI
2014-11-18 04:28 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\el-GR
2014-11-18 04:27 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\zh-TW
2014-11-18 04:27 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\zh-CN
2014-11-18 04:27 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\ru-RU
2014-11-18 04:27 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\nb-NO
2014-11-18 04:27 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\ja-JP
2014-11-18 04:27 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-11-18 00:17 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-11-18 00:17 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2014-11-18 00:15 - 2009-07-13 20:05 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2014-11-17 08:43 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\system32\restore
2014-11-17 08:43 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\Recovery
2014-11-17 08:33 - 2009-07-13 22:57 - 00025600 ____N () C:\Windows\system32\config\BCD-Template.LOG
2014-11-17 08:33 - 2009-07-13 22:52 - 00028672 ____N () C:\Windows\system32\config\BCD-Template
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-11-25 06:05
 
==================== End Of Log ============================
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2014-11-26 17:17:22
-----------------------------
17:17:22.787    OS Version: Windows 6.1.7601 Service Pack 1
17:17:22.787    Number of processors: 4 586 0x203
17:17:22.787    ComputerName: MAVERICK  UserName: Rickey
17:17:27.331    Initialize success
17:17:27.801    VM: initialized successfully
17:17:27.801    VM: Amd CPU supported 
17:20:26.457    AVAST engine defs: 14112601
17:20:34.459    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005a
17:20:34.459    Disk 0 Vendor: WDC_WD32 01.0 Size: 305245MB BusType: 3
17:20:34.529    Disk 0 MBR read successfully
17:20:34.539    Disk 0 MBR scan
17:20:34.569    Disk 0 Windows 7 default MBR code
17:20:34.579    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          100 MB offset 2048
17:20:34.589    Disk 0 default boot code
17:20:34.599    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       305143 MB offset 206848
17:20:34.609    Disk 0 scanning sectors +625139712
17:20:34.679    Disk 0 scanning C:\Windows\system32\drivers
17:20:48.238    Service scanning
17:21:09.811    Service WRkrn C:\Windows\System32\drivers\WRkrn.sys **LOCKED** 32
17:21:11.381    Modules scanning
17:21:11.381    Disk 0 trace - called modules:
17:21:11.411    ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll storport.sys nvstor.sys 
17:21:11.411    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x862f82e0]
17:21:11.421    3 CLASSPNP.SYS[8afa259e] -> nt!IofCallDriver -> [0x853c05d0]
17:21:11.421    5 ACPI.sys[836163d4] -> nt!IofCallDriver -> \Device\0000005a[0x853c0c68]
17:21:12.129    AVAST engine scan C:\Windows
17:21:13.799    AVAST engine scan C:\Windows\system32
17:25:26.354    AVAST engine scan C:\Windows\system32\drivers
17:25:51.469    AVAST engine scan C:\Users\Rickey
17:29:05.711    AVAST engine scan C:\ProgramData
17:29:31.174    Disk 0 statistics 2510040/0/0 @ 4.11 MB/s
17:29:31.190    Scan finished successfully
17:30:00.155    Disk 0 MBR has been saved successfully to "F:\whatTheTech\MBR.dat"
17:30:00.171    The log file has been saved successfully to "F:\whatTheTech\aswMBR.txt"
17:34:16.554    Disk 0 MBR has been saved successfully to "C:\Users\Rickey\Downloads\WhatTheTech\MBR.dat"
17:34:16.554    The log file has been saved successfully to "C:\Users\Rickey\Downloads\WhatTheTech\aswMBR.txt"
 
Rick
 

 


    Advertisements

Register to Remove


#2 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 01 December 2014 - 11:34 PM

Hi BrotherPorter,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
  • Copy and Paste logs directly into the reply window. DO NOT attach the logs unless specifically instructed to do so.

IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Please stay with this topic until I let you know that your system appears to be "All Clear"

Important: All tools MUST be run from the Desktop.

=========================

I apologize for the delay in answering your post. It has been a few days since your original post, please run the following tools and post the new logs generated.

=========================

bullseye_zpse9eaf36e.gif Security Check

Download Security Check by screen317 from here or here.

  • Save it to your Desktop.
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

=========================

bullseye_zpse9eaf36e.gif Malwarebytes Anti-Rootkit

  • Download Malwarebytes Anti-Rootkit
  • Once the file has been downloaded, right click on the downloaded file and select the Extract all menu option.
  • Follow the instructions to extract the ZIP file to a folder called mbar-versionnumber on your desktop.
  • Once the ZIP file has been extracted, open the folder and when that folder opens, double-click on the mbar folder.
  • Double-click on the mbar.exe file to launch Malwarebytes Anti-Rootkit.
  • After you double-click on the mbar.exe file, you may receive a User Account Control (UAC) message if you are sure you wish to allow the program to run. Please allow to start Malwarebytes Anti-Rootkit correctly.
  • Malwarebytes Anti-Rootkit will now install necessary drivers that are required for the program to operate correctly.
  • If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.

MBAMAnti-Rootkit1_zps4613be8c.png

  • Please click by the introduction screen on the Next button to continue.

MBAMAnti-Rootkit2update_zpsf85fca28.png

  • Next you will see the Update Database screen.
  • Click on the Update button so Malwarebytes Anti-Rootkit can download the latest definition updates.

MBAMAnti-Rootkitupdatecomplete_zpscf9f4c

  • When the update has finished, click on the Next button.

MBAMAnti-Rootkitscan_zps9b346fe7.png

  • Next you can select some basic scanning options. Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
  • Malwarebytes Anti-Rootkit will now start scanning your computer for rootkits. This scan can take some time, so please be patient.

MBAMAnti-Rootkitscan-results_zps9f0fdf8e

  • When the scan with Malwarebytes Anti-Rootkit is finished, the program will display a screen with the results from the scan.
  • Make sure everything is selected and that the option to create a restore point is checked.
  • Next click on the Cleanup button. Malwarebytes Anti-Rootkit will then prompt you to reboot your computer.
  • Click on Yes button to restart your computer.
  • There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log.
  • The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run.
    • For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt.
  • The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program.

=========================

bullseye_zpse9eaf36e.gif Re-run Farbar Recovery Scan Tool it should be on your desktop.

    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • When the tool opens click Yes to disclaimer.
  • Select the Addition box
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.

=========================

In your next post please provide the following:

  • checkup.txt
  • system-log.txt
  • mbar-log
  • FRST.txt
  • Addition.txt

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#3 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 06 December 2014 - 12:43 AM

Hi BrotherPorter,

Just checking in to see if you still need help?
OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#4 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 06 December 2014 - 09:00 AM

Where did my post get delivered? I posted everything that you requested about 2 days ago., This could be the interloper...he has kept files that I print from actually printing, proof of that can be confirmed by help desk at our local library and I could see it happening when I attempted to print a document which would help me to accomplish another keypoint. I'll put it again. Thanks.

 

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01-12-2014
Ran by Monk at 2014-12-02 15:56:57
Running from C:\Users\Monk\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Webroot SecureAnywhere (Enabled - Up to date) {66A6FE14-08CB-F415-3742-517201416109}
AS: Webroot SecureAnywhere (Enabled - Up to date) {DDC71FF0-2EF1-FB9B-0DF2-6A007AC62BB4}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall Firewall (Enabled) {1B8D532F-88B1-B2AD-ED22-AED92687A1D2}
 
==================== Installed Programs ======================
 
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.239 - Adobe Systems Incorporated)
Canon IJ Scan Utility (HKLM\...\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon MG3500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG3500_series) (Version: 1.00 - Canon Inc.)
Canon MG3500 series On-screen Manual (HKLM\...\Canon MG3500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon MG3500 series User Registration (HKLM\...\Canon MG3500 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Printer (HKLM\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM\...\CanonQuickMenu) (Version: 2.2.1 - Canon Inc.)
Creative System Information (HKLM\...\SysInfo) (Version: 1.10 - Creative Technology Limited)
DoxBox version 6.0 Beta (HKLM\...\{650A6F8D-35DD-4162-A119-A78A2B7E7885}_is1) (Version: 6.0 Beta - DoxBox)
Google Chrome (HKLM\...\Google Chrome) (Version: 39.0.2171.71 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.9.232 - SurfRight B.V.)
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217071FF}) (Version: 7.0.710 - Oracle)
Java 8 Update 25 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
KeyScrambler (HKLM\...\KeyScrambler) (Version: 3.5.0.0 - QFX Software Corporation)
Malwarebytes Anti-Malware version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft LifeCam (HKLM\...\{BD71B413-9FEE-49BB-A6D1-2C0BFB99BDFE}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
MozBackup 1.5.1 (HKLM\...\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 31.2.0 - Mozilla)
Mozilla Thunderbird 31.2.0 (x86 en-US) (HKLM\...\Mozilla Thunderbird 31.2.0 (x86 en-US)) (Version: 31.2.0 - Mozilla)
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 340.52 - NVIDIA Corporation)
NVIDIA Graphics Driver 340.52 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 340.52 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
OpenOffice 4.1.1 (HKLM\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
PDF-Viewer (HKLM\...\{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1) (Version: 2.5.311.0 - Tracker Software Products Ltd)
Sound Blaster X-Fi Go! Pro (HKLM\...\{587B7A6F-CA1F-4639-9083-16F9BB2363B4}) (Version: 1.0 - Creative Technology Limited)
Webroot SecureAnywhere (HKLM\...\WRUNINST) (Version: 8.0.5.111 - Webroot)
WinZip (HKLM\...\WinZip) (Version:  10.0  (6667) - WinZip Computing LP)
ZoneAlarm Firewall (Version: 13.3.052.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM\...\ZoneAlarm Free Firewall) (Version: 13.3.052.000 - Check Point)
ZoneAlarm Security (Version: 13.3.052.000 - Check Point Software Technologies Ltd.) Hidden
 
==================== Custom CLSID (selected items): ==========================
 
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
 
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{30A2652A-DDF7-45e7-ACA6-3EAB26FC8A4E}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{41662FC2-0D57-4aff-AB27-AD2E12E7C273}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{448BB771-CFE2-47C4-BCDF-1FBF378E202C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{7B342DC4-139A-4a46-8A93-DB0827CCEE9C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\ooofilt.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{7FA8AE11-B3E3-4D88-AABF-255526CD1CE8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{82154420-0FBF-11d4-8313-005004526AB4}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\propertyhdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\InprocServer32 -> C:\Program Files\OpenOffice 4\program\shlxthdl\shlxthdl.dll (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{D0484DE6-AAEE-468a-991F-8D4B0737B57A}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{D2D59CD1-0A6A-4D36-AE20-47817077D57C}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{E5A0B632-DFBA-4549-9346-E414DA06E6F8}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{EE5D1EA4-D445-4289-B2FC-55FC93693917}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
CustomCLSID: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000_Classes\CLSID\{F616B81F-7BB8-4F22-B8A5-47428D59F8AD}\localserver32 -> C:\Program Files\OpenOffice 4\program\soffice.exe (Apache Software Foundation)
 
==================== Restore Points  =========================
 
01-12-2014 02:48:44 Windows Update
01-12-2014 09:08:16 Checkpoint by HitmanPro
01-12-2014 09:09:29 Checkpoint by HitmanPro
01-12-2014 13:24:10 Windows Update
01-12-2014 14:00:19 Windows Modules Installer
01-12-2014 17:36:46 Windows Update
01-12-2014 23:58:41 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
02-12-2014 00:00:43 Installed OpenOffice 4.1.1
02-12-2014 00:13:48 Removed Microsoft Silverlight
02-12-2014 16:41:13 Windows Update
02-12-2014 20:10:13 Installed DirectX
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 20:04 - 2009-06-10 15:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
 
Task: {D5095EC4-86D7-4235-A494-0025955F775A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-30] (Google Inc.)
Task: {FF4D21F7-7829-4F47-96CD-10F11C5001E3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-11-30] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (whitelisted) =============
 
2014-11-30 04:30 - 2014-07-02 13:42 - 00107992 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2014-11-30 03:53 - 2009-12-29 16:50 - 00073728 _____ () C:\Windows\SYSTEM32\CmdRtr.DLL
2014-11-30 03:53 - 2010-07-22 16:45 - 00181760 _____ () C:\Windows\SYSTEM32\APOMngr.DLL
2014-11-30 05:01 - 2014-11-25 00:39 - 01077064 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.71\libglesv2.dll
2014-11-30 05:01 - 2014-11-25 00:39 - 00211272 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.71\libegl.dll
2014-11-30 05:01 - 2014-11-25 00:39 - 09009480 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.71\pdf.dll
2014-11-30 05:01 - 2014-11-25 00:39 - 01677128 _____ () C:\Program Files\Google\Chrome\Application\39.0.2171.71\ffmpegsumo.dll
 
==================== Alternate Data Streams (whitelisted) =========
 
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
 
 
==================== Safe Mode (whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\97533190.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\97533190.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
 
==================== EXE Association (whitelisted) =============
 
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
 
 
 
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
 
==================== MSCONFIG/TASK MANAGER disabled items =========
 
(Currently there is no automatic fix for this section.)
 
 
========================= Accounts: ==========================
 
Administrator (S-1-5-21-3795844004-4128841395-3337064661-500 - Administrator - Disabled)
Guest (S-1-5-21-3795844004-4128841395-3337064661-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3795844004-4128841395-3337064661-1002 - Limited - Enabled)
Monk (S-1-5-21-3795844004-4128841395-3337064661-1000 - Administrator - Enabled) => C:\Users\Monk
 
==================== Faulty Device Manager Devices =============
 
Name: Standard PS/2 Keyboard
Description: Standard PS/2 Keyboard
Class Guid: {4d36e96b-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard keyboards)
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (12/02/2014 02:10:12 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {c58dc9ca-5783-4a96-ab8a-1acf3ada25c8}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000002ac,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0112F588.64).  hr = 0x80070005, Access is denied.
.
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001dc,(null),0,REG_BINARY,023AF168.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {216b905c-20be-483f-a242-b10cc5fbd383}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000096c,(null),0,REG_BINARY,0338F060.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {22b2ed44-2074-45b5-81d7-80179174410d}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000710,(null),0,REG_BINARY,02CFF1F0.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {e36f1c6d-c6de-4928-8083-d8f13560fef5}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001bc,(null),0,REG_BINARY,0120F5E8.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}
   Writer Name: Registry Writer
   Writer Instance ID: {1612e3b4-1c17-49f7-a5ec-684244c7a83e}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001dc,(null),0,REG_BINARY,023AF154.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {216b905c-20be-483f-a242-b10cc5fbd383}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x0000096c,(null),0,REG_BINARY,0338F04C.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {22b2ed44-2074-45b5-81d7-80179174410d}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x000001f8,(null),0,REG_BINARY,00E1F6E8.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Writer Name: Shadow Copy Optimization Writer
   Writer Instance ID: {7f3e4986-3aa3-4ef1-ac2b-d752687c6cf3}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine RegSetValueExW(0x00000710,(null),0,REG_BINARY,02CFF1DC.64).  hr = 0x80070005, Access is denied.
.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {e36f1c6d-c6de-4928-8083-d8f13560fef5}
 
 
System errors:
=============
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 3
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 11
Processor ID: 2
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 2
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 8
Processor ID: 2
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 2
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1
 
The details view of this entry contains further information.
 
Error: (12/02/2014 02:58:49 AM) (Source: Microsoft-Windows-WHEA-Logger) (EventID: 18) (User: NT AUTHORITY)
Description: A fatal hardware error has occurred.
 
Reported by component: Processor Core
Error Source: 3
Error Type: 256
Processor ID: 1
 
The details view of this entry contains further information.
 
 
Microsoft Office Sessions:
=========================
Error: (12/02/2014 02:10:12 PM) (Source: VSS) (EventID: 8194) (User: )
Description: 0x80070005, Access is denied.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {c58dc9ca-5783-4a96-ab8a-1acf3ada25c8}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000002ac,SYSTEM\CurrentControlSet\Services\VSS\Diag\VssvcPublisher,0,REG_BINARY,0112F588.64)0x80070005, Access is denied.
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001dc,(null),0,REG_BINARY,023AF168.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {216b905c-20be-483f-a242-b10cc5fbd383}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x0000096c,(null),0,REG_BINARY,0338F060.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {22b2ed44-2074-45b5-81d7-80179174410d}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x00000710,(null),0,REG_BINARY,02CFF1F0.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {e36f1c6d-c6de-4928-8083-d8f13560fef5}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001bc,(null),0,REG_BINARY,0120F5E8.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {afbab4a2-367d-4d15-a586-71dbb18f8485}
   Writer Name: Registry Writer
   Writer Instance ID: {1612e3b4-1c17-49f7-a5ec-684244c7a83e}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001dc,(null),0,REG_BINARY,023AF154.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {216b905c-20be-483f-a242-b10cc5fbd383}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x0000096c,(null),0,REG_BINARY,0338F04C.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {cd3f2362-8bef-46c7-9181-d62844cdc0b2}
   Writer Name: MSSearch Service Writer
   Writer Instance ID: {22b2ed44-2074-45b5-81d7-80179174410d}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x000001f8,(null),0,REG_BINARY,00E1F6E8.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
   Writer Name: Shadow Copy Optimization Writer
   Writer Instance ID: {7f3e4986-3aa3-4ef1-ac2b-d752687c6cf3}
 
Error: (12/01/2014 03:10:16 AM) (Source: VSS) (EventID: 8193) (User: )
Description: RegSetValueExW(0x00000710,(null),0,REG_BINARY,02CFF1DC.64)0x80070005, Access is denied.
 
 
Operation:
   BackupShutdown Event
 
Context:
   Execution Context: Writer
   Writer Class Id: {a6ad56c2-b509-4e6c-bb19-49d8f43532f0}
   Writer Name: WMI Writer
   Writer Instance ID: {e36f1c6d-c6de-4928-8083-d8f13560fef5}
 
 
==================== Memory info =========================== 
 
Processor: AMD Phenom™ 9550 Quad-Core Processor
Percentage of memory in use: 68%
Total physical RAM: 3071.3 MB
Available physical RAM: 964.65 MB
Total Pagefile: 6140.9 MB
Available Pagefile: 3650.4 MB
Total Virtual: 2047.88 MB
Available Virtual: 1899.77 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:297.99 GB) (Free:267.65 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 7CC2FB56)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
 
==================== End Of Log ============================


#5 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 06 December 2014 - 09:01 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2014
Ran by Monk (administrator) on MBPHBROTHERS on 02-12-2014 15:55:37
Running from C:\Users\Monk\Downloads
Loaded Profile: Monk (Available profiles: Monk)
Platform: Microsoft Windows 7 Home Premium  Service Pack 1 (X86) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Webroot) C:\Program Files\Webroot\WRSA.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Creative Technology Ltd) C:\Program Files\Creative\Shared Files\CTAudSvc.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(Check Point Software Technologies, Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\ZAPrivacyService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Webroot) C:\Program Files\Webroot\WRSA.exe
(Creative Technology Ltd) C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(QFX Software Corporation) C:\Program Files\KeyScrambler\KeyScrambler.exe
(Check Point Software Technologies Ltd.) C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(CANON INC.) C:\Program Files\Canon\Quick Menu\CNQMUPDT.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS32.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [WRSVC] => C:\Program Files\Webroot\WRSA.exe [768656 2014-11-30] (Webroot)
HKLM\...\Run: [VolPanel] => C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe [241789 2010-02-18] (Creative Technology Ltd)
HKLM\...\Run: [Creative SB Monitoring Utility] => RunDll32 sbavmon.dll,SBAVMonitor
HKLM\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM\...\Run: [KeyScrambler] => C:\Program Files\KeyScrambler\keyscrambler.exe [508744 2014-10-26] (QFX Software Corporation)
HKLM\...\Run: [ZoneAlarm] => C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe [134624 2014-07-23] (Check Point Software Technologies Ltd.)
HKLM\...\Run: [CanonQuickMenu] => C:\Program Files\Canon\Quick Menu\CNQMMAIN.EXE [1282120 2013-05-02] (CANON INC.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM\...\Run: [LifeCam] => C:\Program Files\Microsoft LifeCam\LifeExp.exe [135536 2010-12-13] (Microsoft Corporation)
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKLM\...\Policies\Explorer: [NoViewOnDrive] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKLM\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKLM\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKLM\...\Policies\Explorer: [NoViewContextMenu] 0
HKLM\...\Policies\Explorer: [NoShellSearchButton] 0
HKLM\...\Policies\Explorer: [NoFind] 0
HKLM\...\Policies\Explorer: [NoFile] 0
HKLM\...\Policies\Explorer: [HideClock] 0
HKLM\...\Policies\Explorer: [NoTrayContextMenu] 0
HKLM\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKLM\...\Policies\Explorer: [NoSetFolders] 0
HKLM\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKLM\...\Policies\Explorer: [NoSetTaskbar] 0
HKLM\...\Policies\Explorer: [NoDeletePrinter] 0
HKLM\...\Policies\Explorer: [NoDFSTab] 0
HKLM\...\Policies\Explorer: [NoChangeStartMenu] 0
HKLM\...\Policies\Explorer: [NoLogoff] 0
HKLM\...\Policies\Explorer: [NoWindowsUpdate] 0
HKLM\...\Policies\Explorer: [NoEncryptOnMove] 0
HKLM\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKLM\...\Policies\Explorer: [NoResolveSearch] 0
HKLM\...\Policies\Explorer: [NoSaveSettings] 0
HKLM\...\Policies\Explorer: [NoHardwareTab] 0
HKLM\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKLM\...\Policies\Explorer: [NoDesktop] 0
HKU\S-1-5-19\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-19\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-19\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-19\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-19\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-19\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-20\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-20\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-20\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-20\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-20\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-20\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\...\Policies\Explorer: [NoStartMenuSubFolders] 0
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-11-30] (Microsoft Corporation)
HKU\S-1-5-18\...\Policies\system: [DisableCMD] 0
HKU\S-1-5-18\...\Policies\system: [NoDispAppearancePage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispBackgroundPage] 0
HKU\S-1-5-18\...\Policies\system: [NoDispSettingsPage] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewOnDrive] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableLocalMachineRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRun] 0
HKU\S-1-5-18\...\Policies\Explorer: [DisableCurrentUserRunOnce] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoViewContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoShellSearchButton] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFind] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoFile] 0
HKU\S-1-5-18\...\Policies\Explorer: [HideClock] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayContextMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoTrayItemsDisplay] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetFolders] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDevMgrUpdate] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSetTaskbar] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDeletePrinter] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoDFSTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoChangeStartMenu] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoLogoff] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoWindowsUpdate] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoEncryptOnMove] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoRunasInstallPrompt] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoResolveSearch] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoSaveSettings] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoHardwareTab] 0
HKU\S-1-5-18\...\Policies\Explorer: [NoStartMenuSubFolders] 0
Startup: C:\Users\Monk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DoxBox.lnk
ShortcutTarget: DoxBox.lnk -> C:\Program Files\DoxBox\DoxBox.exe (DoxBox)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Microsoft\Internet Explorer\Main,Start Page = http://drudgereport.com/
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://breitbart.com/
SearchScopes: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000 -> DefaultScope {C3816696-7FE9-4002-BECB-F796533B514D} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000 -> {4FD7E10A-87A8-4C0D-B298-3E87DF422E0A} URL = http://www.officedep..._-2010-_-Search
SearchScopes: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000 -> {C3816696-7FE9-4002-BECB-F796533B514D} URL = https://www.google.c...q={searchTerms}
SearchScopes: HKU\S-1-5-21-3795844004-4128841395-3337064661-1000 -> {E3918987-26A6-46C5-A63E-989C15A997F4} URL = http://www.browsemyt...C={searchTerms}
BHO: No Name -> {724d43a9-0d85-11d4-9908-00400523e39a} ->  No File
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Webroot\WRData\PKG\Vistax86\wrflt.dll (Webroot)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll (Webroot)
DPF: {1842B0EE-B597-11D4-8997-00104BD12D94} http://pcpitstop.com...cpConnCheck.cab
DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://pcpitstop.com...ols/pcmatic.cab
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
 
FireFox:
========
FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKU\S-1-5-21-3795844004-4128841395-3337064661-1000: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf -> C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
 
Chrome: 
=======
CHR HomePage: Default -> hxxp://www.drudgereport.com/
CHR StartupUrls: Default -> "hxxp://help.comodo.com/topic-120-1-279-2590-Displaying-Hiding-Application-buttons-on-the-Toolbar.html", "hxxp://manhattan.lib.ks.us/", "https://www.yahoo.co...t&type=avastbcl", "hxxp://www.google.com/"
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.703\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\internal-nacl-plugin No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\39.0.2171.71\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java Deployment Toolkit 8.0.250.18) - C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java™ Platform SE 8 U25) - C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (NVIDIA 3D Vision) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
CHR Plugin: (NVIDIA 3D VISION) - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
CHR Plugin: (PDF-XChange Viewer) - C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
CHR Profile: C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-30]
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-11-30]
CHR Extension: (Pop Block Pro - The Ultimate Popup Blocker) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjmjkdknjeokcmgjmdpkccpmahfmiib [2014-11-30]
CHR Extension: (Poper Blocker) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2014-11-30]
CHR Extension: (YouTube) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-11-30]
CHR Extension: (CancanIT SEO & Website Analysis) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdpkkcoifgekomfdnhgmhdbandakmped [2014-11-30]
CHR Extension: (Adblock Plus) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-11-30]
CHR Extension: (TrafficLight) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfnpidifppmenkapgihekkeednfoenal [2014-11-30]
CHR Extension: (Link to Google Analytics | Shortcut) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbofdajbjpegicggccpealogclcdiap [2014-11-30]
CHR Extension: (Alexa Traffic Rank) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknebhggccemgcnbidipinkifmmegdel [2014-11-30]
CHR Extension: (Google Search) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-30]
CHR Extension: (Netflix) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\deceagebecbceejblnlcjooeohmmeldh [2014-11-30]
CHR Extension: (Good News) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\deegloljmdbfbjhlimieancmcfombgjj [2014-11-30]
CHR Extension: (Lucidchart Diagrams - Desktop) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\djejicklhojeokkfmdelnempiecmdomj [2014-11-30]
CHR Extension: (Business Card Maker) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpchnngplfnmejdkfgpmfhifccngoiih [2014-11-30]
CHR Extension: (Reverse Phone Lookup) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\eccacjpoadkkkichonipjpkjoklpdacg [2014-11-30]
CHR Extension: (Typing Races Student) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejhoalfilhjkgjphcbnhnnjmhgbcmgeg [2014-11-30]
CHR Extension: (Google Calendar) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2014-11-30]
CHR Extension: (Antavo - Contest & Activation Suite) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ennfopamliahhindmboeiainjeanckib [2014-11-30]
CHR Extension: (Blur (Formerly DoNotTrackMe)) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd [2014-11-30]
CHR Extension: (Google Sheets) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-30]
CHR Extension: (AdBlock Premium) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\fndlhnanhedoklpdaacidomdnplcjcpj [2014-11-30]
CHR Extension: (Chrome Web Store Launcher (by Google)) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gecgipfabdickgidpmbicneamekgbaej [2014-11-30]
CHR Extension: (Planetarium) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp [2014-11-30]
CHR Extension: (AdBlock) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2014-11-30]
CHR Extension: (DocuSign - Sign Documents for Free) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\goblijolcnempeilmnkmfbhohlpngemd [2014-11-30]
CHR Extension: (IE Tab) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\hehijbfgiekmjfkfjpbkbammjbdenadd [2014-11-30]
CHR Extension: (Similar Sites Pro) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\hidjnkeodmholilgafgdlgmgggbhnigl [2014-11-30]
CHR Extension: (AWeber) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\iiecooifilpmabeidiegjiekkngdhhkc [2014-11-30]
CHR Extension: (How To Make Money) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\imojecgofbipiadfdmggpminpkpfdddg [2014-11-30]
CHR Extension: (Dropbox) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2014-11-30]
CHR Extension: (Typing Test - KeyHero) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm [2014-11-30]
CHR Extension: (RightSignature) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkhcpgjhhebecogfbaelmpmpcccdofep [2014-11-30]
CHR Extension: (StayFocusd) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\laankejkbhbdhmipfmgcngdelahlfoji [2014-11-30]
CHR Extension: (Presefy Presentation) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\laceanlcibahaedgdbmaehhdemabnppf [2014-11-30]
CHR Extension: (Currency Converter) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbhghjdcfghfhlogkgdklfgmpodeglno [2014-11-30]
CHR Extension: (Webcam Toy) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2014-11-30]
CHR Extension: (Simplebooklet) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhfhnhfkmicpmbafobnpegjhaihjinph [2014-11-30]
CHR Extension: (Payable form: add Paypal to your Google Form) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkdpfjbplbappibihpepdcpikflmlnfb [2014-11-30]
CHR Extension: (Google Maps) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2014-11-30]
CHR Extension: (PayPal Transactions) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnoilgegkhenejdjcejnkkcklcdfibbd [2014-11-30]
CHR Extension: (Rain Alarm) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok [2014-11-30]
CHR Extension: (Feedbro) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\mefgmmbdailogpfhfblcnnjfmnpnmdfa [2014-11-30]
CHR Extension: (Ghostery Fixer) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaegpmdlhnpldpoadmnnbddbkcdmbhb [2014-11-30]
CHR Extension: (Christophe Lopez-Huici) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\mldcndgjaaommbfoppackndancebpjhn [2014-11-30]
CHR Extension: (Ghostery) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2014-11-30]
CHR Extension: (ClearCheckbook Money Management) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncgheejpeplfmifkibfifpdhceopaifp [2014-11-30]
CHR Extension: (Similar Sites) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\necpbmbhhdiplmfhmjicabdeighkndkn [2014-11-30]
CHR Extension: (Google Wallet) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-11-30]
CHR Extension: (Adblock Pro) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocifcklkibdehekfnmflempfgjhbedch [2014-11-30]
CHR Extension: (Webroot Password Manager) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\okfhiodnpcnnnpgbjbhfebjnbagmfhab [2014-11-30]
CHR Extension: (Click&Clean App) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2014-11-30]
CHR Extension: (HackerTarget.com IP Tools) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\phjkepckmcnjohilmbjlcoblenhgpjmo [2014-11-30]
CHR Extension: (Gmail) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-30]
CHR Extension: (Popout for YouTube™) - C:\Users\Monk\AppData\Local\Google\Chrome\User Data\Default\Extensions\pofekaindcmmojfnfgbpklepkjfilcep [2014-11-30]
CHR HKLM\...\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - C:\ProgramData\WRData\PKG\CHROME\CHROME_1.0.2.42.crx [2014-11-30]
CHR HKLM\...\Chrome\Extension: [okfhiodnpcnnnpgbjbhfebjnbagmfhab] - C:\ProgramData\WRData\pkg\lpchrome.crx [2014-11-30]
 
========================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 Creative Audio Engine Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2014-11-30] (Creative Labs) [File not signed]
R2 CTAudSvcService; C:\Program Files\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-11] (Creative Technology Ltd) [File not signed]
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [106248 2014-11-30] (SurfRight B.V.)
S2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 vsmon; C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe [3596240 2014-07-23] (Check Point Software Technologies Ltd.)
R2 WRSVC; C:\Program Files\Webroot\WRSA.exe [768656 2014-11-30] (Webroot)
R2 ZAPrivacyService; C:\Program Files\CheckPoint\ZoneAlarm\ZaPrivacyService.exe [93712 2014-07-03] (Check Point Software Technologies, Ltd.)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 FreeOTFE; C:\Windows\System32\FreeOTFE.sys [32480 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherAES_Gladman; C:\Windows\System32\FreeOTFECypherAES_Gladman.sys [44768 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherAES_ltc; C:\Windows\System32\FreeOTFECypherAES_ltc.sys [47968 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherBlowfish; C:\Windows\System32\FreeOTFECypherBlowfish.sys [25952 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherCAST5; C:\Windows\System32\FreeOTFECypherCAST5.sys [31840 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherCAST6_Gladman; C:\Windows\System32\FreeOTFECypherCAST6_Gladman.sys [30560 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherDES; C:\Windows\System32\FreeOTFECypherDES.sys [57568 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherMARS_Gladman; C:\Windows\System32\FreeOTFECypherMARS_Gladman.sys [27232 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherRC6_ltc; C:\Windows\System32\FreeOTFECypherRC6_ltc.sys [26720 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherSerpent_Gladman; C:\Windows\System32\FreeOTFECypherSerpent_Gladman.sys [29920 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFECypherTwofish_ltc; C:\Windows\System32\FreeOTFECypherTwofish_ltc.sys [32480 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFEHashMD; C:\Windows\System32\FreeOTFEHashMD.sys [17504 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFEHashRIPEMD; C:\Windows\System32\FreeOTFEHashRIPEMD.sys [33248 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFEHashSHA; C:\Windows\System32\FreeOTFEHashSHA.sys [26848 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFEHashTiger; C:\Windows\System32\FreeOTFEHashTiger.sys [22624 2014-08-19] (Sarah Dean) [File not signed]
R1 FreeOTFEHashWhirlpool; C:\Windows\System32\FreeOTFEHashWhirlpool.sys [31328 2014-08-19] (Sarah Dean) [File not signed]
S3 G311N6; C:\Windows\System32\DRIVERS\G311N6.sys [278560 2010-05-05] (Netgear) [File not signed]
R3 KeyScrambler; C:\Windows\System32\drivers\keyscrambler.sys [209016 2013-05-31] (QFX Software Corporation)
R3 ksaud; C:\Windows\System32\drivers\ksaud.sys [1254400 2010-08-11] (Creative Technology Ltd.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [6504 2009-05-13] ()
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2014-03-31] (NVIDIA Corporation)
R1 Vsdatant; C:\Windows\System32\DRIVERS\vsdatant.sys [456088 2014-07-23] (Check Point Software Technologies Ltd.)
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [116736 2014-11-30] (Webroot)
U0 SR; No ImagePath
U2 srservice; No ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== One Month Created Files and Folders ========
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-02 15:55 - 2014-12-02 15:56 - 00033985 _____ () C:\Users\Monk\Downloads\FRST.txt
2014-12-02 15:55 - 2014-12-02 15:55 - 01109504 _____ (Farbar) C:\Users\Monk\Downloads\FRST.exe
2014-12-02 15:55 - 2014-12-02 15:55 - 00000000 ____D () C:\FRST
2014-12-02 15:15 - 2014-12-02 15:46 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-12-02 15:13 - 2014-12-02 15:14 - 14349744 _____ (Malwarebytes Corp.) C:\Users\Monk\Downloads\malwarebytes-anti-rootkit-1-07-0-1012-en-win.exe
2014-12-02 15:06 - 2014-12-02 15:06 - 00000000 ____D () C:\Users\Monk\AppData\Roaming\OpenOffice
2014-12-02 14:52 - 2014-12-02 15:46 - 00000000 ____D () C:\Users\Monk\Desktop\mbar
2014-12-02 14:45 - 2014-12-02 14:45 - 00852487 _____ () C:\Users\Monk\Desktop\SecurityCheck.exe
2014-12-02 14:11 - 2014-12-02 14:11 - 00001999 _____ () C:\Users\Public\Desktop\Microsoft LifeCam.lnk
2014-12-02 14:11 - 2014-12-02 14:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft LifeCam
2014-12-02 14:10 - 2014-12-02 14:10 - 00000000 ____D () C:\Program Files\Microsoft LifeCam
2014-12-02 14:10 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2014-12-02 14:10 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2014-12-02 13:15 - 2012-08-23 08:48 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2014-12-02 13:15 - 2012-08-23 08:44 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2014-12-02 13:15 - 2012-08-23 07:52 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2014-12-02 13:15 - 2012-08-23 05:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll
2014-12-02 13:15 - 2012-08-23 04:08 - 02739712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2014-12-02 12:59 - 2013-10-01 18:42 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys
2014-12-02 12:59 - 2013-10-01 18:32 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2014-12-02 12:59 - 2013-10-01 18:30 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2014-12-02 12:59 - 2013-10-01 18:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll
2014-12-02 12:59 - 2013-10-01 18:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll
2014-12-02 12:59 - 2013-10-01 17:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
2014-12-02 12:59 - 2013-10-01 17:45 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll
2014-12-02 12:59 - 2013-10-01 17:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2014-12-02 12:59 - 2013-10-01 17:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2014-12-02 12:59 - 2013-10-01 16:53 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2014-12-02 12:59 - 2013-10-01 16:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-12-02 12:59 - 2013-10-01 14:55 - 05698048 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-12-02 12:43 - 2014-06-26 19:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2014-12-02 12:35 - 2012-07-25 21:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\WUDFHost.exe
2014-12-02 12:35 - 2012-07-25 21:20 - 00613888 _____ (Microsoft Corporation) C:\Windows\system32\WUDFx.dll
2014-12-02 12:35 - 2012-07-25 21:20 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2014-12-02 12:35 - 2012-07-25 21:20 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\WUDFSvc.dll
2014-12-02 12:35 - 2012-07-25 21:20 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\WUDFCoinstaller.dll
2014-12-02 12:35 - 2012-07-25 20:33 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFPf.sys
2014-12-02 12:35 - 2012-07-25 20:32 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WUDFRd.sys
2014-12-02 12:35 - 2012-06-02 08:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2014-12-02 12:34 - 2014-12-02 12:35 - 03272048 _____ (Microsoft Corporation) C:\Users\Monk\Downloads\CinemaFW1033.exe
2014-12-02 12:33 - 2014-06-30 16:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2014-12-02 12:33 - 2014-06-06 00:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2014-12-02 12:33 - 2014-03-09 15:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2014-12-02 12:33 - 2014-03-09 15:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2014-12-02 10:53 - 2012-02-29 23:46 - 00019824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fs_rec.sys
2014-12-02 10:53 - 2012-02-29 23:29 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\wmi.dll
2014-12-02 10:46 - 2013-05-09 22:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-12-02 10:46 - 2013-05-09 22:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-12-02 10:37 - 2014-08-19 13:03 - 00044768 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherAES_Gladman.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00057568 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherDES.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00047968 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherAES_ltc.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00033248 _____ (Sarah Dean) C:\Windows\system32\FreeOTFEHashRIPEMD.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00032480 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherTwofish_ltc.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00032480 _____ (Sarah Dean) C:\Windows\system32\FreeOTFE.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00031840 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherCAST5.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00031328 _____ (Sarah Dean) C:\Windows\system32\FreeOTFEHashWhirlpool.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00030560 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherCAST6_Gladman.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00029920 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherSerpent_Gladman.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00027232 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherMARS_Gladman.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00026848 _____ (Sarah Dean) C:\Windows\system32\FreeOTFEHashSHA.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00026720 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherRC6_ltc.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00025952 _____ (Sarah Dean) C:\Windows\system32\FreeOTFECypherBlowfish.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00022624 _____ (Sarah Dean) C:\Windows\system32\FreeOTFEHashTiger.sys
2014-12-02 10:22 - 2014-08-19 13:03 - 00017504 _____ (Sarah Dean) C:\Windows\system32\FreeOTFEHashMD.sys
2014-12-02 10:14 - 2014-12-02 10:25 - 00001026 _____ () C:\Users\Monk\AppData\Roaming\DoxBox.ini
2014-12-02 10:14 - 2014-12-02 10:14 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DoxBox
2014-12-02 10:14 - 2014-12-02 10:14 - 00000000 ____D () C:\Program Files\DoxBox
2014-12-02 10:08 - 2014-12-02 10:08 - 02604613 _____ (DoxBox ) C:\Users\Monk\Downloads\InstallDoxBox_v60Beta.exe
2014-12-02 09:46 - 2014-12-02 09:46 - 00167296 _____ (Gibson Research Corp.) C:\Users\Monk\Downloads\DNSBench.exe
2014-12-02 09:46 - 2014-12-02 09:46 - 00029696 _____ (Gibson Research Corp.) C:\Users\Monk\Downloads\DCOMbob.exe
2014-12-02 09:46 - 2014-12-02 09:46 - 00022528 _____ (Gibson Research Corp.) C:\Users\Monk\Downloads\unpnp.exe
2014-12-02 03:15 - 2014-11-05 20:51 - 00667648 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-12-02 03:15 - 2014-06-23 20:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-12-02 03:15 - 2014-02-03 20:04 - 01230336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2014-12-02 03:15 - 2013-11-26 02:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-12-02 03:15 - 2013-11-23 12:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2014-12-01 18:19 - 2014-12-01 18:19 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2014-12-01 18:19 - 2014-12-01 18:19 - 00000000 ____D () C:\Program Files\Microsoft Silverlight
2014-12-01 18:02 - 2014-12-01 18:02 - 00001146 _____ () C:\Users\Monk\Desktop\OpenOffice 4.1.1.lnk
2014-12-01 18:02 - 2014-12-01 18:02 - 00000000 ___SD () C:\Users\Monk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OpenOffice 4.1.1
2014-12-01 18:01 - 2014-12-01 18:01 - 00000000 ____D () C:\Program Files\OpenOffice 4
2014-12-01 17:39 - 2014-12-01 17:39 - 00000000 __SHD () C:\Users\Monk\AppData\Local\EmieUserList
2014-12-01 17:39 - 2014-12-01 17:39 - 00000000 __SHD () C:\Users\Monk\AppData\Local\EmieSiteList
2014-12-01 17:39 - 2014-12-01 17:39 - 00000000 __SHD () C:\Users\Monk\AppData\Local\EmieBrowserModeList
2014-12-01 15:19 - 2014-12-01 15:19 - 00000000 ____D () C:\Program Files\Common Files\Java
2014-12-01 15:18 - 2014-12-01 15:18 - 00000000 ____D () C:\ProgramData\Sun
2014-12-01 15:17 - 2014-12-01 15:19 - 00096680 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2014-12-01 15:17 - 2014-12-01 15:19 - 00000000 ____D () C:\ProgramData\Oracle
2014-12-01 15:17 - 2014-12-01 15:19 - 00000000 ____D () C:\Program Files\Java
2014-12-01 15:17 - 2014-12-01 15:17 - 00272808 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe
2014-12-01 15:17 - 2014-12-01 15:17 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe
2014-12-01 15:17 - 2014-12-01 15:17 - 00175528 _____ (Oracle Corporation) C:\Windows\system32\java.exe
2014-12-01 15:17 - 2014-12-01 15:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2014-12-01 11:44 - 2014-12-01 11:44 - 00131072 ____H () C:\Windows\DUMPce20.DMP
2014-12-01 10:59 - 2014-12-01 10:59 - 00000000 ____D () C:\Users\Monk\AppData\Local\IE Tab
2014-12-01 09:36 - 2014-12-01 09:36 - 00001971 _____ () C:\Users\Public\Desktop\Canon Quick Menu.lnk
2014-12-01 09:36 - 2014-12-01 09:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG3500 series User Registration
2014-12-01 09:36 - 2014-12-01 09:36 - 00000000 ____D () C:\ProgramData\CanonIJWSpt
2014-12-01 09:35 - 2014-12-01 10:16 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2014-12-01 09:35 - 2014-12-01 09:35 - 00002308 _____ () C:\Users\Public\Desktop\Canon MG3500 series On-screen Manual.lnk
2014-12-01 09:35 - 2014-12-01 09:35 - 00000000 ___HD () C:\ProgramData\CanonBJ
2014-12-01 09:35 - 2014-12-01 09:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG3500 series Manual
2014-12-01 09:34 - 2014-12-01 09:35 - 00000000 ___HD () C:\Program Files\CanonBJ
2014-12-01 09:34 - 2013-04-04 05:00 - 00317952 _____ (CANON INC.) C:\Windows\system32\CNMLMBV.DLL
2014-12-01 09:34 - 2013-02-04 15:10 - 00321536 _____ (CANON INC.) C:\Windows\system32\CNC_BVL.dll
2014-12-01 09:34 - 2012-11-26 12:32 - 00088576 _____ () C:\Windows\system32\CNC176ED.TBL
2014-12-01 09:34 - 2012-11-08 13:03 - 00262656 _____ (CANON INC.) C:\Windows\system32\CNC_BVC.dll
2014-12-01 09:34 - 2012-11-08 13:02 - 00096768 _____ (CANON INC.) C:\Windows\system32\CNC_BVI.dll
2014-12-01 09:34 - 2008-08-25 18:02 - 00015872 _____ (CANON INC.) C:\Windows\system32\CNHMCA.dll
2014-12-01 09:33 - 2014-12-01 09:33 - 00000000 ___HD () C:\ProgramData\CanonIJETV
2014-12-01 09:32 - 2014-12-01 10:16 - 00000000 ____D () C:\Program Files\Canon
2014-12-01 09:07 - 2014-10-13 19:50 - 02363904 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-12-01 09:07 - 2014-08-22 19:46 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2014-12-01 09:07 - 2014-08-21 00:26 - 01237504 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-12-01 09:07 - 2014-08-21 00:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-12-01 09:07 - 2013-05-09 21:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll
2014-12-01 09:07 - 2012-08-21 14:12 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\OxpsConverter.exe
2014-12-01 09:07 - 2011-12-29 23:27 - 00478720 _____ (Microsoft Corporation) C:\Windows\system32\timedate.cpl
2014-12-01 09:07 - 2011-08-26 22:26 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2014-12-01 09:07 - 2011-08-16 22:24 - 00465408 _____ (Microsoft Corporation) C:\Windows\system32\psisdecd.dll
2014-12-01 09:07 - 2011-08-16 22:19 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\psisrndr.ax
2014-12-01 09:07 - 2011-07-08 20:30 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2014-12-01 09:07 - 2011-05-24 04:44 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\umpnpmgr.dll
2014-12-01 09:07 - 2011-04-26 20:17 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2014-12-01 09:07 - 2011-04-26 20:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2014-12-01 09:06 - 2014-11-05 11:50 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-12-01 09:06 - 2014-11-05 11:50 - 00203776 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-12-01 09:06 - 2014-11-05 11:47 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-12-01 09:06 - 2014-10-09 18:45 - 02379264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-12-01 09:06 - 2014-10-02 19:44 - 00475136 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-12-01 09:06 - 2014-10-02 19:44 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-12-01 09:06 - 2014-10-02 19:44 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-12-01 09:06 - 2014-10-02 19:44 - 00275968 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-12-01 09:06 - 2014-10-02 19:44 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-12-01 09:06 - 2014-09-19 03:23 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2014-12-01 09:06 - 2014-09-19 03:23 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2014-12-01 09:06 - 2014-09-19 03:23 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2014-12-01 09:06 - 2014-09-19 03:23 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2014-12-01 09:06 - 2014-09-19 03:23 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-12-01 09:06 - 2014-09-19 03:23 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-12-01 09:06 - 2014-09-03 23:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-12-01 09:06 - 2014-02-03 20:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-12-01 09:06 - 2014-02-03 20:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-12-01 09:06 - 2014-02-03 20:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-12-01 09:06 - 2014-02-03 20:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-12-01 09:06 - 2014-01-27 20:07 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2014-12-01 09:06 - 2013-08-27 18:57 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2014-12-01 09:06 - 2013-07-20 04:33 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-12-01 09:06 - 2013-06-05 22:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2014-12-01 09:06 - 2013-06-05 22:51 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2014-12-01 09:06 - 2013-06-05 22:50 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2014-12-01 09:06 - 2013-06-05 21:01 - 00295424 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2014-12-01 09:06 - 2013-06-05 21:01 - 00034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2014-12-01 09:06 - 2013-05-12 21:08 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe
2014-12-01 09:06 - 2013-05-12 21:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll
2014-12-01 09:06 - 2013-04-25 22:55 - 00492544 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2014-12-01 09:06 - 2013-04-09 17:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2014-12-01 09:06 - 2013-03-18 21:33 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll
2014-12-01 09:06 - 2012-10-03 10:42 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2014-12-01 09:06 - 2012-10-03 10:42 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\netcorehc.dll
2014-12-01 09:06 - 2012-10-03 10:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2014-12-01 09:06 - 2012-10-03 10:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2014-12-01 09:06 - 2012-10-03 10:42 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\netevent.dll
2014-12-01 09:06 - 2012-10-03 10:40 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll
2014-12-01 09:06 - 2012-10-03 09:21 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2014-12-01 09:06 - 2011-05-02 22:30 - 00741376 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2014-12-01 09:05 - 2014-10-17 19:33 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2014-12-01 09:05 - 2013-10-03 19:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll
2014-12-01 09:05 - 2013-10-03 19:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll
2014-12-01 09:05 - 2013-07-08 22:52 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-12-01 09:05 - 2013-07-04 05:50 - 00530432 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll
2014-12-01 09:05 - 2013-07-02 22:02 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbscan.sys
2014-12-01 09:05 - 2013-07-02 21:36 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2014-12-01 09:05 - 2013-07-02 21:36 - 00025728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2014-12-01 09:05 - 2012-08-22 11:16 - 00712048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2014-12-01 09:05 - 2012-07-04 13:45 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RNDISMP.sys
2014-12-01 09:05 - 2012-06-05 23:03 - 00805376 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2014-12-01 09:05 - 2011-05-03 22:34 - 01549312 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2014-12-01 09:05 - 2011-05-03 22:32 - 01401344 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2014-12-01 09:05 - 2011-05-03 22:32 - 00666624 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2014-12-01 09:05 - 2011-05-03 22:32 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2014-12-01 09:05 - 2011-05-03 22:32 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2014-12-01 09:05 - 2011-05-03 22:32 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2014-12-01 09:05 - 2011-05-03 22:28 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2014-12-01 09:05 - 2011-05-03 22:28 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2014-12-01 09:05 - 2011-05-03 22:28 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2014-12-01 09:04 - 2014-11-10 20:44 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2014-12-01 09:04 - 2014-11-10 20:44 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\pku2u.dll
2014-12-01 09:04 - 2014-07-13 19:42 - 00654336 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2014-12-01 09:04 - 2013-10-29 20:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll
2014-12-01 09:04 - 2013-02-11 21:32 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usb8023.sys
2014-12-01 09:04 - 2013-01-23 22:47 - 00196328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys
2014-12-01 09:04 - 2012-11-01 23:11 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\dpnet.dll
2014-12-01 09:04 - 2011-06-15 22:33 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\xmllite.dll
2014-12-01 09:04 - 2011-04-28 20:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2014-12-01 09:04 - 2011-04-28 20:46 - 00310272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2014-12-01 09:04 - 2011-04-28 20:46 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2014-12-01 09:04 - 2011-02-17 23:39 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\prevhost.exe
2014-12-01 09:03 - 2014-08-11 19:36 - 00701440 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2014-12-01 09:03 - 2014-06-15 19:44 - 00730048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2014-12-01 09:03 - 2014-06-15 19:44 - 00219072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2014-12-01 09:03 - 2014-06-15 19:40 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2014-12-01 09:03 - 2014-03-26 08:27 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2014-12-01 09:03 - 2014-03-26 08:25 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2014-12-01 09:03 - 2014-03-04 03:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2014-12-01 09:03 - 2014-03-04 03:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-12-01 09:03 - 2014-03-04 03:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll
2014-12-01 09:03 - 2014-03-04 03:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2014-12-01 09:03 - 2014-03-04 03:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll
2014-12-01 09:03 - 2014-03-04 03:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll
2014-12-01 09:03 - 2014-03-04 03:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll
2014-12-01 09:03 - 2014-03-04 03:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll
2014-12-01 09:03 - 2014-03-04 03:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll
2014-12-01 09:03 - 2014-03-04 03:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll
2014-12-01 09:03 - 2013-12-31 17:05 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-12-01 09:03 - 2013-10-18 19:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2014-12-01 09:03 - 2013-10-11 20:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2014-12-01 09:03 - 2013-10-11 20:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2014-12-01 09:03 - 2013-10-11 19:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2014-12-01 09:03 - 2013-10-11 19:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2014-12-01 09:03 - 2011-03-02 23:38 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2014-12-01 09:03 - 2011-03-02 23:38 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\dnsrslvr.dll
2014-12-01 09:03 - 2011-03-02 23:36 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\dnscacheugc.exe
2014-12-01 08:50 - 2014-09-24 19:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-12-01 08:50 - 2014-08-01 05:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2014-12-01 08:50 - 2014-06-18 16:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-12-01 08:50 - 2014-06-18 16:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-12-01 08:50 - 2014-06-18 16:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-12-01 08:50 - 2014-06-17 19:51 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\osk.exe
2014-12-01 08:50 - 2014-06-06 03:44 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-12-01 08:50 - 2014-06-03 03:30 - 00101824 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2014-12-01 08:50 - 2014-06-03 03:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2014-12-01 08:50 - 2014-06-03 03:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2014-12-01 08:50 - 2014-05-30 00:36 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2014-12-01 08:50 - 2014-04-04 20:25 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2014-12-01 08:50 - 2014-04-04 20:24 - 00187840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2014-12-01 08:50 - 2014-01-23 20:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-12-01 08:50 - 2013-11-26 05:11 - 00240576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-12-01 08:50 - 2013-10-03 19:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2014-12-01 08:50 - 2013-10-03 19:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2014-12-01 08:50 - 2013-07-25 02:57 - 01620992 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2014-12-01 08:50 - 2012-12-07 06:26 - 00308736 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll
2014-12-01 08:50 - 2012-12-07 06:20 - 02576384 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll
2014-12-01 08:50 - 2012-12-07 04:46 - 00055296 _____ (Microsoft) C:\Windows\system32\cero.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00051712 _____ (Microsoft) C:\Windows\system32\esrb.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00046592 _____ (Microsoft) C:\Windows\system32\fpb.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00045568 _____ (Microsoft) C:\Windows\system32\oflc-nz.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00044544 _____ (Microsoft) C:\Windows\system32\pegibbfc.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00043520 _____ (Microsoft) C:\Windows\system32\csrr.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00040960 _____ (Microsoft) C:\Windows\system32\cob-au.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00030720 _____ (Microsoft) C:\Windows\system32\usk.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00023552 _____ (Microsoft) C:\Windows\system32\oflc.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00021504 _____ (Microsoft) C:\Windows\system32\grb.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-pt.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi-fi.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00020480 _____ (Microsoft) C:\Windows\system32\pegi.rs
2014-12-01 08:50 - 2012-12-07 04:46 - 00015360 _____ (Microsoft) C:\Windows\system32\djctq.rs
2014-12-01 08:50 - 2012-07-04 15:16 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\netapi32.dll
2014-12-01 08:50 - 2012-07-04 15:14 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\browser.dll
2014-12-01 08:50 - 2012-07-04 15:14 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\browcli.dll
2014-12-01 08:50 - 2012-05-05 01:46 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-12-01 08:50 - 2011-10-25 22:32 - 01328128 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-12-01 08:50 - 2011-10-14 23:38 - 00534528 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll
2014-12-01 08:50 - 2011-02-11 23:35 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\FXSCOVER.exe
2014-12-01 08:50 - 2010-12-22 23:54 - 00850944 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2014-12-01 08:50 - 2010-12-22 23:54 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2014-12-01 08:50 - 2010-12-22 23:50 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\mpg2splt.ax
2014-12-01 08:49 - 2014-10-24 19:32 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-12-01 08:49 - 2013-07-25 19:55 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2014-12-01 08:49 - 2013-07-04 05:57 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-12-01 08:49 - 2013-07-04 05:51 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-12-01 08:49 - 2013-07-04 03:48 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2014-12-01 08:49 - 2012-09-25 16:47 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\synceng.dll
2014-12-01 08:49 - 2012-05-13 22:33 - 00769024 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2014-12-01 08:49 - 2012-04-30 22:44 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2014-12-01 08:49 - 2012-03-17 01:27 - 00056176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys
2014-12-01 08:49 - 2012-01-04 02:58 - 00442880 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2014-12-01 08:49 - 2011-12-16 01:52 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\msvcrt.dll
2014-12-01 08:49 - 2011-11-16 23:35 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2014-12-01 08:49 - 2011-06-15 02:55 - 00319488 _____ (Microsoft Corporation) C:\Windows\system32\odbcjt32.dll
2014-12-01 08:49 - 2011-06-15 02:55 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\odbctrac.dll
2014-12-01 08:49 - 2011-06-15 02:55 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\odbccp32.dll
2014-12-01 08:49 - 2011-06-15 02:55 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\odbccu32.dll
2014-12-01 08:49 - 2011-06-15 02:55 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\odbccr32.dll
2014-12-01 08:48 - 2014-07-16 19:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-12-01 08:48 - 2014-07-16 19:39 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-12-01 08:48 - 2014-07-16 19:39 - 00130048 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-12-01 08:48 - 2014-07-16 19:03 - 00184320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-12-01 08:48 - 2014-07-16 19:02 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-12-01 08:48 - 2014-06-24 19:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2014-12-01 08:48 - 2014-04-24 20:06 - 00626688 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2014-12-01 08:48 - 2014-03-04 03:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-12-01 08:48 - 2014-01-28 20:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-12-01 08:48 - 2013-11-26 19:14 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-12-01 08:48 - 2013-11-26 19:13 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-12-01 08:48 - 2013-11-26 19:13 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-12-01 08:48 - 2013-11-26 19:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-12-01 08:48 - 2013-11-26 19:13 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-12-01 08:48 - 2013-11-26 19:13 - 00020480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-12-01 08:48 - 2013-11-26 19:13 - 00006016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-12-01 08:48 - 2013-10-05 13:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-12-01 08:48 - 2013-08-01 19:50 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 19:48 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 18:52 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2014-12-01 08:48 - 2013-08-01 18:43 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 18:43 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 18:43 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-12-01 08:48 - 2013-08-01 18:43 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-12-01 08:48 - 2013-07-12 04:08 - 00146816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbvideo.sys
2014-12-01 08:48 - 2013-07-12 04:07 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbcir.sys
2014-12-01 08:48 - 2013-07-12 04:07 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBAUDIO.sys
2014-12-01 08:48 - 2013-07-08 22:46 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-12-01 08:48 - 2013-07-08 22:46 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2014-12-01 08:48 - 2013-06-25 16:56 - 00527064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2014-12-01 08:48 - 2012-11-28 16:57 - 00047720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2014-12-01 08:48 - 2012-11-28 16:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2014-12-01 08:48 - 2012-11-28 16:57 - 00000003 _____ () C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2014-12-01 08:48 - 2012-10-09 11:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore6.dll
2014-12-01 08:48 - 2012-10-09 11:40 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcsvc6.dll
2014-12-01 08:48 - 2012-04-25 22:45 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\rdpwsx.dll
2014-12-01 08:48 - 2012-04-25 22:41 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\rdrmemptylst.exe
2014-12-01 08:48 - 2011-03-10 23:33 - 01164288 _____ (Microsoft Corporation) C:\Windows\system32\mfc42u.dll
2014-12-01 08:48 - 2011-03-10 23:33 - 01137664 _____ (Microsoft Corporation) C:\Windows\system32\mfc42.dll
2014-12-01 08:48 - 2011-02-22 22:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2014-12-01 08:47 - 2014-10-13 19:56 - 00136632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2014-12-01 08:47 - 2014-10-13 19:50 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2014-12-01 08:47 - 2014-10-13 19:50 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-12-01 08:47 - 2014-10-13 19:47 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2014-12-01 08:47 - 2014-10-13 19:46 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2014-12-01 08:47 - 2014-09-09 15:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-12-01 08:47 - 2014-04-11 20:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2014-12-01 08:47 - 2014-04-11 20:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2014-12-01 08:47 - 2014-04-11 20:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2014-12-01 08:47 - 2014-04-11 20:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2014-12-01 08:47 - 2014-04-11 20:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2014-12-01 08:47 - 2013-12-03 20:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-12-01 08:47 - 2013-12-03 20:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-12-01 08:47 - 2013-12-03 20:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-12-01 08:47 - 2013-12-03 20:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-12-01 08:47 - 2013-12-03 20:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-12-01 08:47 - 2013-12-03 19:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-12-01 08:47 - 2013-12-03 19:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-12-01 08:47 - 2013-12-03 19:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-12-01 08:47 - 2013-12-03 19:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-12-01 08:47 - 2013-08-04 19:56 - 00133056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2014-12-01 08:47 - 2013-07-04 06:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2014-12-01 08:10 - 2013-10-11 20:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2014-12-01 08:10 - 2013-10-11 20:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2014-12-01 08:10 - 2013-10-11 20:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2014-12-01 08:05 - 2014-12-01 08:05 - 19781632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 12819456 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 04298240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-12-01 08:05 - 2014-12-01 08:05 - 02277376 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 02051072 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-12-01 08:05 - 2014-12-01 08:05 - 01892864 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 01310208 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00708096 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00683008 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2014-12-01 08:05 - 2014-12-01 08:05 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00341168 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2014-12-01 08:05 - 2014-12-01 08:05 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2014-12-01 08:05 - 2014-12-01 08:05 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2014-12-01 08:05 - 2014-12-01 08:05 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2014-12-01 08:05 - 2014-12-01 08:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-12-01 08:04 - 2014-12-01 08:04 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2014-12-01 08:04 - 2014-12-01 08:04 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2014-12-01 08:04 - 2014-12-01 08:04 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2014-12-01 08:04 - 2014-12-01 08:04 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2014-12-01 08:04 - 2014-12-01 08:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2014-12-01 08:04 - 2014-12-01 08:04 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2014-12-01 08:04 - 2014-12-01 08:04 - 00038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 01158144 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 01080832 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00906240 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00604160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00364544 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2014-12-01 08:02 - 2014-12-01 08:02 - 00002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2014-12-01 08:00 - 2014-12-01 08:00 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2014-12-01 07:59 - 2014-12-01 08:10 - 00012067 _____ () C:\Windows\IE11_main.log
2014-12-01 07:38 - 2013-02-26 22:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2014-12-01 07:33 - 2012-02-16 23:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2014-12-01 07:33 - 2012-02-16 22:13 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2014-12-01 07:24 - 2014-05-14 10:23 - 01973728 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2014-12-01 07:24 - 2014-05-14 10:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2014-12-01 07:24 - 2014-05-14 10:23 - 00054240 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2014-12-01 07:24 - 2014-05-14 10:23 - 00045536 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2014-12-01 07:24 - 2014-05-14 10:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2014-12-01 07:24 - 2014-05-14 10:17 - 02425856 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2014-12-01 07:24 - 2014-05-14 10:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2014-12-01 07:24 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2014-12-01 07:24 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2014-12-01 06:17 - 2014-08-21 18:48 - 00000703 _____ () C:\Users\Monk\Desktop\cover letter.txt
2014-12-01 05:40 - 2014-12-01 05:40 - 00000000 ____D () C:\Users\Monk\AppData\Roaming\Macromedia
2014-12-01 03:44 - 2014-12-01 03:44 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-12-01 03:44 - 2014-12-01 03:44 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-12-01 03:44 - 2014-12-01 03:44 - 00000000 ____D () C:\Windows\system32\Macromed
2014-12-01 03:16 - 2014-08-11 07:26 - 00000773 _____ () C:\Users\Monk\Documents\indexfile.txt
2014-12-01 03:15 - 2014-12-01 03:15 - 00000989 _____ () C:\Users\Public\Desktop\MozBackup.lnk
2014-12-01 03:15 - 2014-12-01 03:15 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MozBackup
2014-12-01 03:15 - 2014-12-01 03:15 - 00000000 ____D () C:\Program Files\MozBackup
2014-12-01 03:09 - 2014-12-01 03:09 - 00000524 _____ () C:\Windows\system32\.crusader
2014-11-30 20:49 - 2014-11-30 20:49 - 00000000 ____D () C:\Windows\system32\SPReview
2014-11-30 20:49 - 2014-11-30 20:49 - 00000000 ____D () C:\Windows\system32\EventProviders
2014-11-30 20:41 - 2014-11-30 20:41 - 00000000 ____D () C:\Users\Monk\AppData\Roaming\Thunderbird
2014-11-30 20:41 - 2014-11-30 20:41 - 00000000 ____D () C:\Users\Monk\AppData\Roaming\Mozilla
2014-11-30 20:41 - 2014-11-30 20:41 - 00000000 ____D () C:\Users\Monk\AppData\Local\Thunderbird
2014-11-30 16:43 - 2014-11-30 16:43 - 00002048 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
2014-11-30 16:43 - 2014-11-30 16:43 - 00002036 _____ () C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
2014-11-30 16:43 - 2014-11-30 16:43 - 00000000 ____D () C:\ProgramData\Mozilla
2014-11-30 16:43 - 2014-11-30 16:43 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird
2014-11-30 16:43 - 2014-11-30 16:43 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-11-30 16:42 - 2014-11-30 16:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-11-30 13:02 - 2014-11-30 13:02 - 00000000 ____D () C:\Program Files\AGEIA Technologies
2014-11-30 13:01 - 2014-07-02 11:39 - 00609240 _____ (NVIDIA Corporation) C:\Windows\system32\nvStreaming.exe
2014-11-30 13:01 - 2010-11-20 06:29 - 00520064 _____ (Microsoft Corporation) C:\Windows\system32\mcupdate_GenuineIntel.dll
2014-11-30 13:01 - 2010-11-20 06:21 - 01159168 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2014-11-30 13:01 - 2010-11-20 06:21 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\spwizui.dll
2014-11-30 13:01 - 2010-11-20 06:19 - 03207680 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-11-30 13:01 - 2010-11-20 06:19 - 00954752 _____ (Microsoft Corporation) C:\Windows\system32\mfc40.dll
2014-11-30 13:01 - 2010-11-20 06:19 - 00954288 _____ (Microsoft Corporation) C:\Windows\system32\mfc40u.dll
2014-11-30 13:01 - 2010-11-20 06:18 - 01334272 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2014-11-30 13:01 - 2010-11-04 19:58 - 00297808 _____ (Microsoft Corporation) C:\Windows\system32\mscoree.dll
2014-11-30 13:01 - 2010-11-04 19:53 - 00295264 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHost.exe
2014-11-30 13:01 - 2010-11-04 19:53 - 00099176 _____ (Microsoft Corporation) C:\Windows\system32\PresentationHostProxy.dll
2014-11-30 13:00 - 2010-11-20 06:36 - 01077248 _____ (Microsoft Corporation) C:\Windows\system32\Narrator.exe
2014-11-30 13:00 - 2010-11-20 06:36 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\NAPHLPR.DLL
2014-11-30 13:00 - 2010-11-20 06:32 - 05066752 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2014-11-30 13:00 - 2010-11-20 06:30 - 00245632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00173440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00160128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00153984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00143744 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvstor.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00140160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scsiport.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00130432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpio.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00117120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvraid.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00116096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msdsm.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00085376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sbp2port.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00078208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00053120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2014-11-30 13:00 - 2010-11-20 06:30 - 00028032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msahci.sys
2014-11-30 13:00 - 2010-11-20 06:29 - 02217856 _____ (Microsoft Corporation) C:\Windows\system32\bootres.dll
2014-11-30 13:00 - 2010-11-20 06:29 - 00332160 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorV.sys
2014-11-30 13:00 - 2010-11-20 06:29 - 00274304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2014-11-30 13:00 - 2010-11-20 06:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2014-11-30 13:00 - 2010-11-20 06:29 - 00194432 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2014-11-30 13:00 - 2010-11-20 06:29 - 00137088 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2014-11-30 13:00 - 2010-11-20 06:29 - 00080256 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdsata.sys
2014-11-30 13:00 - 2010-11-20 06:29 - 00022400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdxata.sys
2014-11-30 13:00 - 2010-11-20 06:29 - 00014208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys
2014-11-30 13:00 - 2010-11-20 06:24 - 00690680 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-11-30 13:00 - 2010-11-20 06:24 - 00508904 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-11-30 13:00 - 2010-11-20 06:24 - 00442720 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-11-30 13:00 - 2010-11-20 06:24 - 00271664 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2014-11-30 13:00 - 2010-11-20 06:23 - 00144768 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 02983424 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 02755072 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 02311168 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 02202624 _____ (Microsoft Corporation) C:\Windows\system32\SensorsCpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 02157568 _____ (Microsoft Corporation) C:\Windows\system32\themecpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 02146304 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01712640 _____ (Microsoft Corporation) C:\Windows\system32\xpsservices.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01667584 _____ (Microsoft Corporation) C:\Windows\system32\setupapi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01624064 _____ (Microsoft Corporation) C:\Windows\system32\WMPEncEn.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01363456 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01326592 _____ (Microsoft Corporation) C:\Windows\system32\wlanpref.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01227776 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01175040 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01128448 _____ (Microsoft Corporation) C:\Windows\system32\vssapi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01115136 _____ (Microsoft Corporation) C:\Windows\system32\RacEngn.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01086976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01063936 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 01003008 _____ (Microsoft Corporation) C:\Windows\system32\WMNetMgr.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00974336 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\Vault.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00907776 _____ (Microsoft Corporation) C:\Windows\system32\sdengin2.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00811520 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00782336 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\sqlsrv32.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00766464 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00755200 _____ (Microsoft Corporation) C:\Windows\system32\sud.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00750592 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00750080 _____ (Microsoft Corporation) C:\Windows\system32\sdcpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00738816 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00697344 _____ (Microsoft Corporation) C:\Windows\system32\SmiEngine.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00638976 _____ (Microsoft Corporation) C:\Windows\system32\VAN.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00600064 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00577024 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00551424 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00473600 _____ (Microsoft Corporation) C:\Windows\system32\riched20.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00463360 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\WSDApi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00428544 _____ (Microsoft Corporation) C:\Windows\system32\shwebsvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00416768 _____ (Microsoft Corporation) C:\Windows\system32\wiadefui.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\wlangpui.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00410624 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\wlanui.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00380416 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\termmgr.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00352256 _____ (Microsoft Corporation) C:\Windows\system32\wmpeffects.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\wmicmiplugin.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00351232 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\shlwapi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00346624 _____ (Microsoft Corporation) C:\Windows\system32\untfs.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00335872 _____ (Microsoft Corporation) C:\Windows\system32\WinSATAPI.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00328192 _____ (Microsoft Corporation) C:\Windows\system32\shsvcs.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\sharemediacpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00307712 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00305152 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\srchadmin.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00286208 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00276992 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00270848 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00269824 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\srrstr.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\scansetting.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\tapisrv.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\taskbarcpl.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00228352 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\wavemsp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\SndVolSSO.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\upnp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\sysclass.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\vaultsvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\winmm.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\wmpsrcwp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\tcpipcfg.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\spp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\syncui.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\twext.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\recovery.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\XpsRasterService.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00134656 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\uxlib.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SessEnv.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00111104 _____ (Microsoft Corporation) C:\Windows\system32\shsetup.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\userenv.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\regapi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00051200 _____ (Twain Working Group) C:\Windows\twain_32.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\samcli.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\RpcRtRemote.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\wtsapi32.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\rtutils.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\sisbkup.dll
2014-11-30 13:00 - 2010-11-20 06:21 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\slwga.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 02504192 _____ (Microsoft Corporation) C:\Windows\system32\WMVCORE.DLL
2014-11-30 13:00 - 2010-11-20 06:20 - 02494464 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 02130944 _____ (Microsoft Corporation) C:\Windows\system32\networkmap.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 01750528 _____ (Microsoft Corporation) C:\Windows\system32\pnidui.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 01644032 _____ (Microsoft Corporation) C:\Windows\system32\netcenter.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 01508864 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 01414144 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00988160 _____ (Microsoft Corporation) C:\Windows\system32\propsys.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00932352 _____ (Microsoft Corporation) C:\Windows\system32\printui.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\OobeFldr.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\PerfCenterCPL.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00585728 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\odbc32.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00563712 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceApi.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\powercpl.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00395264 _____ (Microsoft Corporation) C:\Windows\system32\prnfldr.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\nshipsec.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00330240 _____ (Microsoft Corporation) C:\Windows\system32\QAGENTRT.DLL
2014-11-30 13:00 - 2010-11-20 06:20 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00297472 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\photowiz.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00225792 _____ (Microsoft Corporation) C:\Windows\system32\netdiagfx.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00218112 _____ (Microsoft Corporation) C:\Windows\system32\OnLineIDCpl.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\qasf.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00199168 _____ (Microsoft Corporation) C:\Windows\system32\onex.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\qcap.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\QAGENT.DLL
2014-11-30 13:00 - 2010-11-20 06:20 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\QSHVHOST.DLL
2014-11-30 13:00 - 2010-11-20 06:20 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\netiohlp.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\provsvc.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\netjoin.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\prntvpt.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\netid.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\prncache.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\nci.dll
2014-11-30 13:00 - 2010-11-20 06:20 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\ntlanman.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 02291712 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 02151936 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 01698816 _____ (Microsoft Corporation) C:\Windows\system32\esent.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 01493504 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 01066496 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00856576 _____ (Microsoft Corporation) C:\Windows\system32\FirewallControlPanel.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\MSMPEG2ENC.DLL
2014-11-30 13:00 - 2010-11-20 06:19 - 00828928 _____ (Microsoft Corporation) C:\Windows\system32\fontext.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00732160 _____ (Microsoft Corporation) C:\Windows\system32\imapi2fs.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00727040 _____ (Microsoft Corporation) C:\Windows\system32\mcmde.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00593408 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00592384 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00566272 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00481792 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00429056 _____ (Microsoft Corporation) C:\Windows\system32\localsec.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\msdri.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\mspbda.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00400896 _____ (Microsoft Corporation) C:\Windows\system32\ipsmsnap.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00350208 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2014-11-30 13:00 - 2010-11-20 06:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\mtxclu.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00312832 _____ (Microsoft Corporation) C:\Windows\system32\hgcpl.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00271360 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\MediaMetadataHandler.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00226304 _____ (Microsoft Corporation) C:\Windows\system32\MSAC3ENC.DLL
2014-11-30 13:00 - 2010-11-20 06:19 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\mstask.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\framedynos.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\framedyn.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00194560 _____ (Microsoft Corporation) C:\Windows\system32\ListSvc.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\msutb.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\hgprint.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\ifsutil.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\fde.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00118272 _____ (Microsoft Corporation) C:\Windows\system32\imm32.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\IPHLPAPI.DLL
2014-11-30 13:00 - 2010-11-20 06:19 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00093696 _____ (Windows ® Codename Longhorn DDK provider) C:\Windows\system32\fms.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\KMSVC.DLL
2014-11-30 13:00 - 2010-11-20 06:19 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\fdeploy.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\mimefilt.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\httpapi.dll
2014-11-30 13:00 - 2010-11-20 06:19 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\msasn1.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 03727872 _____ (Microsoft Corporation) C:\Windows\system32\accessibilitycpl.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 02522624 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 01828352 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 01555456 _____ (Microsoft Corporation) C:\Windows\system32\certmgr.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 01400320 _____ (Microsoft Corporation) C:\Windows\system32\DxpTaskSync.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 01371136 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 01188864 _____ (Microsoft Corporation) C:\Windows\system32\DiagCpl.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 01040384 _____ (Microsoft Corporation) C:\Windows\system32\Display.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 01003520 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00863744 _____ (Microsoft Corporation) C:\Windows\system32\diagperf.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00854016 _____ (Microsoft Corporation) C:\Windows\system32\dbghelp.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00762880 _____ (Microsoft Corporation) C:\Windows\system32\azroles.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00744448 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00740864 _____ (Microsoft Corporation) C:\Windows\system32\batmeter.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00685056 _____ (Microsoft Corporation) C:\Windows\system32\dsuiext.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00665600 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayCpl.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00630784 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00537600 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenterCPL.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2014-11-30 13:00 - 2010-11-20 06:18 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCenter.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00428032 _____ (Microsoft Corporation) C:\Windows\system32\biocpl.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00399872 _____ (Microsoft Corporation) C:\Windows\system32\DXP.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00333824 _____ (Microsoft Corporation) C:\Windows\system32\dot3ui.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00323072 _____ (Microsoft Corporation) C:\Windows\system32\drvstore.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\azroleui.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\apphelp.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\dpx.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00254464 _____ (Microsoft Corporation) C:\Windows\system32\dhcpcore.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00252928 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00222208 _____ (Microsoft Corporation) C:\Windows\system32\eapphost.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\defaultlocationcpl.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00214016 _____ (Microsoft Corporation) C:\Windows\system32\dot3svc.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\activeds.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\dskquoui.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\adsldp.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\autoplay.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cfgmgr32.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\dps.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\bcdsrv.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\cabview.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\AuxiliaryDisplayServices.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\dnscmmc.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00097280 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\dot3api.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\dot3cfg.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2014-11-30 13:00 - 2010-11-20 06:18 - 00067584 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2014-11-30 13:00 - 2010-11-20 06:17 - 03367424 _____ (Microsoft Corporation) C:\Windows\system32\WinSAT.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 02616320 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 01131008 _____ (Microsoft Corporation) C:\Windows\system32\sdclt.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 01025536 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00941568 _____ (Microsoft Corporation) C:\Windows\system32\mblctr.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00802304 _____ (Microsoft Corporation) C:\Windows\system32\WFS.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\dfrgui.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\FXSSVC.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00477696 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\spinstall.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00453632 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\slui.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\wusa.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\SndVol.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00303104 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\cmd.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\eudcedit.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00280576 _____ (Microsoft Corporation) C:\Windows\system32\spreview.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00270336 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00267776 _____ (Microsoft Corporation) C:\Windows\system32\lsm.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00254976 _____ (Microsoft Corporation) C:\Windows\system32\wsqmcons.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\msconfig.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\taskmgr.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\mcbuilder.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\recdisc.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00209920 _____ (Microsoft Corporation) C:\Windows\system32\PkgMgr.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00197632 _____ (Microsoft Corporation) C:\Windows\system32\ocsetup.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\net1.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\setupugc.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00103936 _____ (Microsoft Corporation) C:\Windows\system32\setupcl.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00098816 _____ (Microsoft) C:\Windows\system32\Robocopy.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\isoburn.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\w32tm.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\tzutil.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ftp.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\proquota.exe
2014-11-30 13:00 - 2010-11-20 06:17 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\userinit.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00905216 _____ (Microsoft Corporation) C:\Windows\system32\mmsys.cpl
2014-11-30 13:00 - 2010-11-20 06:16 - 00776192 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
2014-11-30 13:00 - 2010-11-20 06:16 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\autoconv.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00668160 _____ (Microsoft Corporation) C:\Windows\system32\autochk.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00658944 _____ (Microsoft Corporation) C:\Windows\system32\autofmt.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2014-11-30 13:00 - 2010-11-20 06:16 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\TabletPC.cpl
2014-11-30 13:00 - 2010-11-20 06:16 - 00516096 _____ (Microsoft Corporation) C:\Windows\system32\main.cpl
2014-11-30 13:00 - 2010-11-20 06:16 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2014-11-30 13:00 - 2010-11-20 06:16 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2014-11-30 13:00 - 2010-11-20 06:16 - 00345088 _____ (Microsoft Corporation) C:\Windows\system32\intl.cpl
2014-11-30 13:00 - 2010-11-20 06:16 - 00326656 _____ (Microsoft Corporation) C:\Windows\system32\sysdm.cpl
2014-11-30 13:00 - 2010-11-20 06:16 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2014-11-30 13:00 - 2010-11-20 06:16 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\ssText3d.scr
2014-11-30 13:00 - 2010-11-20 06:16 - 00281088 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2014-11-30 13:00 - 2010-11-20 06:16 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\MSNP.ax
2014-11-30 13:00 - 2010-11-20 06:16 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\ksproxy.ax
2014-11-30 13:00 - 2010-11-20 06:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdmaud.drv
2014-11-30 13:00 - 2010-11-20 06:16 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\aitagent.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-11-30 13:00 - 2010-11-20 06:16 - 00068608 _____ (Microsoft Corporation) C:\Windows\system32\WSTPager.ax
2014-11-30 13:00 - 2010-11-20 04:22 - 00213504 _____ (Microsoft Corporation) C:\Windows\system32\rdpdd.dll
2014-11-30 13:00 - 2010-11-20 04:07 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2014-11-30 13:00 - 2010-11-20 04:01 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\1394ohci.sys
2014-11-30 13:00 - 2010-11-20 04:00 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS
2014-11-30 13:00 - 2010-11-20 03:50 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ks.sys
2014-11-30 13:00 - 2010-11-20 02:44 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2014-11-30 13:00 - 2010-11-20 02:42 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\udfs.sys
2014-11-30 13:00 - 2010-11-20 02:40 - 00513536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2014-11-30 13:00 - 2010-11-20 02:39 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2014-11-30 13:00 - 2010-11-20 02:39 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2014-11-30 13:00 - 2010-11-04 20:20 - 00146852 _____ () C:\Windows\system32\systemsf.ebd
2014-11-30 13:00 - 2010-11-04 20:11 - 00312168 _____ (Microsoft Corporation) C:\Windows\system32\MCEWMDRMNDBootstrap.dll
2014-11-30 13:00 - 2010-11-04 19:58 - 00049488 _____ (Microsoft Corporation) C:\Windows\system32\netfxperf.dll
2014-11-30 12:59 - 2010-11-20 06:36 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\NAPCRYPT.DLL
2014-11-30 12:59 - 2010-11-20 06:21 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\WMADMOD.DLL
2014-11-30 12:59 - 2010-11-20 06:21 - 00739328 _____ (Microsoft Corporation) C:\Windows\system32\WMSPDMOD.DLL
2014-11-30 12:59 - 2010-11-20 06:21 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00541184 _____ (Microsoft Corporation) C:\Windows\system32\WMVSDECD.DLL
2014-11-30 12:59 - 2010-11-20 06:21 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmdev.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00436736 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmnet.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00350720 _____ (Microsoft Corporation) C:\Windows\system32\WPDSp.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00318976 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\sqlcese30.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\wmpdxm.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\unattend.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\wpdwcn.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00196608 _____ (Microsoft Corporation) C:\Windows\system32\wwanconn.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\wdscore.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\sqmapi.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00160256 _____ (Microsoft Corporation) C:\Windows\system32\vdsbas.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\remotepg.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\sdrsvc.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\setupcln.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00109568 _____ (Microsoft Corporation) C:\Windows\system32\wiavideo.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\WPDShServiceObj.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\wmpshell.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\sppinst.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\srvcli.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\QUTIL.DLL
2014-11-30 12:59 - 2010-11-20 06:21 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountControlSettings.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00071168 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\tlscsp.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\rastapi.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\unimdmat.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\vfwwdm32.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\sppuinotify.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\rdpd3d.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\umb.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\wkscli.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\WavDest.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\shimgvw.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\wiarpc.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\wdiasqmmodule.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\utildll.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\vpnikeapi.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\wsdchngr.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\TRAPI.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\rdprefdrvapi.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00020992 _____ (Microsoft Corporation) C:\Windows\system32\shgina.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00019968 _____ (Microsoft Corporation) C:\Windows\system32\spopk.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\schedcli.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\syssetup.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\tsbyuv.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\wshirda.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\shunimpl.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\riched32.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\rdpcfgex.dll
2014-11-30 12:59 - 2010-11-20 06:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-11-30 12:59 - 2010-11-20 06:21 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 01661440 _____ (Microsoft Corporation) C:\Windows\system32\networkexplorer.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 01160192 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\onexui.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00427520 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceStatus.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00283136 _____ (Microsoft Corporation) C:\Windows\system32\qdv.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00183296 _____ (Microsoft Corporation) C:\Windows\system32\PortableDeviceSyncProvider.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\ocsetapi.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\mydocs.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00121344 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\QSVRMGMT.DLL
2014-11-30 12:59 - 2010-11-20 06:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\olepro32.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\olethk32.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\QCLIPROV.DLL
2014-11-30 12:59 - 2010-11-20 06:20 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\napdsnap.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ncryptui.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\PrintIsolationProxy.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\profprov.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\netutils.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\perfts.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\nrpsrv.dll
2014-11-30 12:59 - 2010-11-20 06:20 - 00008192 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\FXSTIFF.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\iTVData.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00202240 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\msorcl32.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\mprapi.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\iasrecst.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00120320 _____ (Microsoft Corporation) C:\Windows\system32\msvfw32.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\fphc.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\mciavi32.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00082944 _____ (Radius Inc.) C:\Windows\system32\iccvid.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapistub.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\mapi32.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\Mcx2Svc.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\inetmib1.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\iyuv_32.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\luainstall.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\FXSMON.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\mciqtz32.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00031744 _____ (Microsoft Corporation) C:\Windows\system32\msvidc32.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\msdmo.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\iscsium.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\msyuv.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\HotStartUserAgent.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\lsmproxy.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\muifontsetup.dll
2014-11-30 12:59 - 2010-11-20 06:19 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msrle32.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00402944 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\audiodev.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\eapp3hst.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00230912 _____ (Microsoft Corporation) C:\Windows\system32\clusapi.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairingFolder.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\dxdiagn.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00179200 _____ (Microsoft Corporation) C:\Windows\system32\ActionQueue.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00128512 _____ (Microsoft Corporation) C:\Windows\system32\EhStorAPI.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\dot3msm.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00094208 _____ (Microsoft Corporation) C:\Windows\system32\eappgnui.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\avifil32.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\cabinet.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\amstream.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\cca.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\CertPolEng.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\acppage.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\cscapi.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\dsauth.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\AzSqlExt.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00023040 _____ (Microsoft Corporation) C:\Windows\system32\cscdll.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\elsTrans.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\bitsperf.dll
2014-11-30 12:59 - 2010-11-20 06:18 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\C_ISCII.DLL
2014-11-30 12:59 - 2010-11-20 06:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\browseui.dll
2014-11-30 12:59 - 2010-11-20 06:17 - 00327680 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00292864 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgradeResults.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\diskraid.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00257536 _____ (Microsoft Corporation) C:\Windows\system32\WindowsAnytimeUpgrade.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00182784 _____ (Microsoft Corporation) C:\Windows\system32\RelPost.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\iscsicli.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\diskpart.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\MdSched.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\mobsync.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\nslookup.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\logagent.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\cmstp.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\logman.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\tabcal.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00070656 _____ (Microsoft Corporation) C:\Windows\system32\MuiUnattend.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\findstr.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\manage-bde.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\PnPUnattend.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\djoin.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\repair-bde.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\MultiDigiMon.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\takeown.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00050688 _____ (Microsoft Corporation) C:\Windows\system32\runonce.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\relog.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\unlodctr.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netiougc.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\netcfg.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe
2014-11-30 12:59 - 2010-11-20 06:17 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\LogonUI.exe
2014-11-30 12:59 - 2010-11-20 06:16 - 00878592 _____ (Microsoft Corporation) C:\Windows\system32\Bubbles.scr
2014-11-30 12:59 - 2010-11-20 06:16 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\Mystify.scr
2014-11-30 12:59 - 2010-11-20 06:16 - 00220672 _____ (Microsoft Corporation) C:\Windows\system32\Ribbons.scr
2014-11-30 12:59 - 2010-11-20 06:16 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\bitsadmin.exe
2014-11-30 12:59 - 2010-11-20 06:16 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\VBICodec.ax
2014-11-30 12:59 - 2010-11-20 06:16 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\powercfg.cpl
2014-11-30 12:59 - 2010-11-20 06:16 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\desk.cpl
2014-11-30 12:59 - 2010-11-20 06:16 - 00107008 _____ (Microsoft Corporation) C:\Windows\system32\Kswdmcap.ax
2014-11-30 12:59 - 2010-11-20 06:16 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\kstvtune.ax
2014-11-30 12:59 - 2010-11-20 06:16 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\Mpeg2Data.ax
2014-11-30 12:59 - 2010-11-20 06:16 - 00065024 _____ (Microsoft Corporation) C:\Windows\bfsvc.exe
2014-11-30 12:59 - 2010-11-20 06:16 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\MSDvbNP.ax
2014-11-30 12:59 - 2010-11-20 06:16 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ksxbar.ax
2014-11-30 12:59 - 2010-11-20 06:16 - 00045568 _____ (Microsoft Corporation) C:\Windows\system32\g711codc.ax
2014-11-30 12:59 - 2010-11-20 06:16 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\vbisurf.ax
2014-11-30 12:59 - 2010-11-20 06:07 - 01164800 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2014-11-30 12:59 - 2010-11-20 06:07 - 00007680 _____ (Microsoft Corporation) C:\Windows\system32\spwizres.dll
2014-11-30 12:59 - 2010-11-20 06:06 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2014-11-30 12:59 - 2010-11-20 06:05 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\RDPENCDD.dll
2014-11-30 12:59 - 2010-11-20 06:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\pifmgr.dll
2014-11-30 12:59 - 2010-11-20 06:00 - 01027584 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2014-11-30 12:59 - 2010-11-20 06:00 - 00430080 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2014-11-30 12:59 - 2010-11-20 06:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDSG.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdlk41a.dll
2014-11-30 12:59 - 2010-11-20 06:00 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDCZ1.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUQ.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDTUF.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDSF.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDPO.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDNEPR.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDINBEN.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGR1.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\KBDGKL.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUS.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDUGHR1.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTURME.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDTAJIK.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMON.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDMAORI.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDLT1.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTEL.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINTAM.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINORI.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINMAR.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINKAN.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDINHIN.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBULG.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBLR.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDBASH.DLL
2014-11-30 12:59 - 2010-11-20 06:00 - 00005632 _____ (Microsoft Corporation) C:\Windows\system32\KBDGEO.DLL
2014-11-30 12:59 - 2010-11-20 05:57 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\dpnaddr.dll
2014-11-30 12:59 - 2010-11-20 05:56 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\BlbEvents.dll
2014-11-30 12:59 - 2010-11-20 04:52 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbrpm.sys
2014-11-30 12:59 - 2010-11-20 04:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RDPCDD.sys
2014-11-30 12:59 - 2010-11-20 04:21 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\RDPREFDD.dll
2014-11-30 12:59 - 2010-11-20 04:21 - 00018432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdpipe.sys
2014-11-30 12:59 - 2010-11-20 04:07 - 00118784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys
2014-11-30 12:59 - 2010-11-20 04:07 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2014-11-30 12:59 - 2010-11-20 04:06 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys
2014-11-30 12:59 - 2010-11-20 04:06 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2014-11-30 12:59 - 2010-11-20 04:06 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndisuio.sys
2014-11-30 12:59 - 2010-11-20 04:00 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2014-11-30 12:59 - 2010-11-20 04:00 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\umbus.sys
2014-11-30 12:59 - 2010-11-20 04:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD2.sys
2014-11-30 12:59 - 2010-11-20 04:00 - 00025856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBCAMD.sys
2014-11-30 12:59 - 2010-11-20 03:59 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hdaudbus.sys
2014-11-30 12:59 - 2010-11-20 03:59 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2014-11-30 12:59 - 2010-11-20 03:50 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\CompositeBus.sys
2014-11-30 12:59 - 2010-11-20 03:50 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\kbdhid.sys
2014-11-30 12:59 - 2010-11-20 03:50 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sffp_sd.sys
2014-11-30 12:59 - 2010-11-20 03:29 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-11-30 12:59 - 2010-11-20 03:24 - 00026624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scfilter.sys
2014-11-30 12:59 - 2010-11-20 03:19 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\IPMIDrv.sys
2014-11-30 12:59 - 2010-11-20 02:47 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpipmi.sys
2014-11-30 12:59 - 2010-11-20 02:42 - 00078336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2014-11-30 12:59 - 2010-11-20 02:39 - 00021504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdi.sys
2014-11-30 12:59 - 2010-11-20 02:38 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cdrom.sys
2014-11-30 12:59 - 2010-11-19 23:23 - 00053600 _____ () C:\Windows\system32\dosx.exe
2014-11-30 12:59 - 2010-11-09 19:45 - 00010429 _____ () C:\Windows\system32\ScavengeSpace.xml
2014-11-30 12:59 - 2010-11-04 20:20 - 00105559 _____ () C:\Windows\system32\RacRules.xml
2014-11-30 12:58 - 2010-11-20 06:21 - 00363008 _____ (Microsoft Corporation) C:\Windows\system32\wbemcomn.dll
2014-11-30 12:56 - 2014-11-30 12:56 - 00000000 ____D () C:\Program Files\Microsoft.NET
2014-11-30 12:45 - 2014-03-31 10:42 - 00034760 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2014-11-30 12:45 - 2014-03-31 10:42 - 00034080 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2014-11-30 12:43 - 2014-11-30 12:43 - 00000000 ____D () C:\NVIDIA
2014-11-30 06:58 - 2014-11-30 06:58 - 00001175 _____ () C:\Users\Public\Desktop\PDF-Viewer.lnk
2014-11-30 06:58 - 2014-11-30 06:58 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
2014-11-30 06:58 - 2014-11-30 06:58 - 00000000 ____D () C:\Program Files\Tracker Software
2014-11-30 06:12 - 2014-12-02 15:40 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-11-30 06:12 - 2014-12-02 15:40 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-11-30 06:12 - 2014-12-02 12:33 - 00001064 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-11-30 06:12 - 2014-12-02 12:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-11-30 06:12 - 2014-12-02 12:33 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2014-11-30 06:12 - 2014-11-30 06:12 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-11-30 06:12 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-11-30 06:12 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-11-30 06:09 - 2014-11-30 06:09 - 00001897 _____ () C:\Users\Public\Desktop\HitmanPro.lnk
2014-11-30 06:09 - 2014-11-30 06:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2014-11-30 06:09 - 2014-11-30 06:09 - 00000000 ____D () C:\Program Files\HitmanPro
2014-11-30 06:08 - 2014-12-01 03:09 - 00000000 ____D () C:\ProgramData\HitmanPro
2014-11-30 06:08 - 2014-11-30 06:08 - 00155400 _____ (SurfRight B.V.) C:\Windows\system32\LnkProtect.dll
2014-11-30 06:05 - 2014-11-30 06:05 - 00431395 _____ () C:\Windows\system32\Drivers\vsconfig.xml
2014-11-30 06:05 - 2014-11-30 06:05 - 00000732 _____ () C:\Users\Public\Desktop\ZoneAlarm Security.lnk
2014-11-30 06:05 - 2014-11-30 06:05 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
2014-11-30 06:04 - 2014-11-30 06:05 - 00000000 ____D () C:\Program Files\CheckPoint
2014-11-30 06:03 - 2014-11-30 06:03 - 00000000 ____D () C:\ProgramData\CheckPoint
2014-11-30 05:01 - 2014-11-30 05:01 - 00002205 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-11-30 05:01 - 2014-11-30 05:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-11-30 05:00 - 2014-12-02 15:05 - 00000882 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-11-30 05:00 - 2014-12-02 14:08 - 00000878 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-11-30 05:00 - 2014-11-30 05:01 - 00000000 ____D () C:\Users\Monk\AppData\Local\Google
2014-11-30 05:00 - 2014-11-30 05:00 - 00000000 ____D () C:\Users\Monk\AppData\Local\Deployment
2014-11-30 05:00 - 2014-11-30 05:00 - 00000000 ____D () C:\Program Files\Google
2014-11-30 04:52 - 2014-11-30 04:52 - 00000000 ____D () C:\Users\Monk\AppData\Roaming\QFX Software
2014-11-30 04:52 - 2014-11-30 04:52 - 00000000 ____D () C:\Users\Monk\AppData\Local\NVIDIA
2014-11-30 04:52 - 2014-11-30 04:52 - 00000000 ____D () C:\ProgramData\QFX Software
2014-11-30 04:32 - 2014-12-02 14:03 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-11-30 04:31 - 2014-12-02 14:06 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-11-30 04:31 - 2014-11-30 04:31 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyScrambler
2014-11-30 04:31 - 2014-11-30 04:31 - 00000000 ____D () C:\Program Files\KeyScrambler
2014-11-30 04:31 - 2013-05-31 08:53 - 00209016 _____ (QFX Software Corporation) C:\Windows\system32\Drivers\keyscrambler.sys
2014-11-30 04:30 - 2014-11-30 13:03 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-11-30 04:30 - 2014-11-30 13:02 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-11-30 04:30 - 2014-08-19 22:16 - 00061728 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2014-11-30 04:30 - 2014-07-02 13:42 - 04389848 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2014-11-30 04:30 - 2014-07-02 13:42 - 03063256 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc.dll
2014-11-30 04:30 - 2014-07-02 13:42 - 02556360 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2014-11-30 04:30 - 2014-07-02 13:42 - 00670552 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
2014-11-30 04:30 - 2014-07-02 13:42 - 00377288 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2014-11-30 04:30 - 2014-07-02 13:42 - 00062936 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2014-11-30 04:30 - 2014-07-01 23:14 - 03826628 _____ () C:\Windows\system32\nvcoproc.bin
2014-11-30 04:28 - 2014-11-30 04:29 - 00000000 ____D () C:\Windows\system32\MRT
2014-11-30 04:28 - 2014-10-31 23:25 - 100445232 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-11-30 04:19 - 2011-04-08 23:56 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2014-11-30 03:56 - 2014-12-01 12:39 - 00000000 ____D () C:\ProgramData\Creative
2014-11-30 03:55 - 2014-12-02 14:06 - 00085376 _____ () C:\Windows\PFRO.log
2014-11-30 03:54 - 2000-05-11 01:00 - 00090112 ____N (Creative Technology Ltd.) C:\Windows\Updreg.EXE
2014-11-30 03:53 - 2014-11-30 03:53 - 00000214 ___RH () C:\Windows\ctfile.rfc
2014-11-30 03:53 - 2010-08-11 08:50 - 01254400 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\ksaud.sys
2014-11-30 03:53 - 2010-08-05 02:26 - 00192512 _____ (Creative Technology Ltd.) C:\Windows\system32\KSVSPI32.dll
2014-11-30 03:53 - 2010-08-02 22:28 - 00104448 _____ (Creative Technology Ltd.) C:\Windows\system32\SBAVMon.dll
2014-11-30 03:53 - 2010-07-24 00:30 - 00012344 _____ () C:\Windows\system32\MixerDefault.reg
2014-11-30 03:53 - 2010-07-22 23:13 - 00044795 ____R () C:\Windows\system32\kschimp.ini
2014-11-30 03:53 - 2010-07-22 23:13 - 00034637 _____ () C:\Windows\system32\ksaud.ini
2014-11-30 03:53 - 2010-07-22 16:45 - 00181760 _____ () C:\Windows\system32\APOMngr.DLL
2014-11-30 03:53 - 2010-07-22 04:13 - 00631431 _____ (Creative Technology Ltd) C:\Windows\KSAIM32.exe
2014-11-30 03:53 - 2010-07-22 02:37 - 00728576 _____ (Creative Technology Ltd.) C:\Windows\system32\KSAPO32.dll
2014-11-30 03:53 - 2010-07-22 02:37 - 00047104 _____ (Creative Technology Ltd.) C:\Windows\system32\KSPPLD32.dll
2014-11-30 03:53 - 2010-06-23 00:54 - 00003077 _____ () C:\ProgramData\cfSB1290.ini
2014-11-30 03:53 - 2010-06-02 02:26 - 00004534 _____ () C:\Windows\system32\SB.bmp
2014-11-30 03:53 - 2009-12-29 16:50 - 00073728 _____ () C:\Windows\system32\CmdRtr.DLL
2014-11-30 03:53 - 2009-11-10 23:42 - 00196608 _____ (Creative Technology Limited) C:\Windows\system32\KsDvInst.dll
2014-11-30 03:53 - 2007-07-04 20:27 - 00002630 ____R () C:\Windows\MixerName.reg
2014-11-30 03:52 - 2014-11-30 03:52 - 00445016 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll
2014-11-30 03:52 - 2014-11-30 03:52 - 00109144 _____ (Portions © Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll
2014-11-30 03:52 - 2014-11-30 03:52 - 00000000 ____D () C:\Program Files\Common Files\Creative Labs Shared
2014-11-30 03:52 - 2010-06-07 17:12 - 02902493 ____N (Creative) C:\Windows\system32\Sens_oal.dll
2014-11-30 03:52 - 2009-12-23 20:49 - 00809560 ____R (Creative Labs Inc.) C:\Windows\system32\tmp1546.tmp
2014-11-30 03:52 - 2006-10-06 00:17 - 00053248 ____N (Creative Technology Ltd ) C:\Windows\Ctregrun.exe
2014-11-30 03:52 - 2003-06-12 23:25 - 00007062 _____ () C:\Windows\system32\audiopid.vxd
2014-11-30 03:52 - 2000-05-22 02:58 - 00647872 ____N (Microsoft Corporation) C:\Windows\system32\Mscomct2.ocx
2014-11-30 03:51 - 2014-11-30 03:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2014-11-30 03:51 - 2014-11-30 03:54 - 00000000 ____D () C:\Program Files\Creative
2014-11-30 03:50 - 2014-11-30 03:50 - 00000000 ____D () C:\Program Files\Common Files\InstallShield
2014-11-30 03:29 - 2014-11-24 14:04 - 00229000 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-11-30 03:21 - 2014-11-30 03:21 - 00001029 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\WinZip.lnk
2014-11-30 03:21 - 2014-11-30 03:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2014-11-30 03:20 - 2014-11-30 03:20 - 00000000 ____D () C:\Program Files\WinZip
2014-11-30 03:13 - 2014-11-30 03:13 - 00000000 ____D () C:\Users\Monk\AppData\Local\lptmp1129086521
2014-11-30 03:12 - 2014-12-02 15:55 - 00000000 ____D () C:\ProgramData\WRData
2014-11-30 03:12 - 2014-12-02 14:06 - 00000828 _____ () C:\Users\Public\Desktop\Webroot SecureAnywhere.lnk
2014-11-30 03:12 - 2014-11-30 03:12 - 00153256 _____ (Webroot) C:\Windows\system32\WRusr.dll
2014-11-30 03:12 - 2014-11-30 03:12 - 00116736 _____ (Webroot) C:\Windows\system32\Drivers\WRkrn.sys
2014-11-30 03:12 - 2014-11-30 03:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webroot SecureAnywhere
2014-11-30 03:12 - 2014-11-30 03:12 - 00000000 ____D () C:\Program Files\Webroot
2014-11-30 02:40 - 2007-02-05 08:44 - 00028160 ____R (Windows ® Codename Longhorn DDK provider) C:\Windows\system32\Drivers\RtNdPt60.sys
2014-11-30 01:37 - 2014-11-30 05:00 - 00000000 ____D () C:\Users\Monk\AppData\Local\Apps\2.0
2014-11-30 00:55 - 2014-12-01 03:44 - 00000000 ____D () C:\Users\Monk\AppData\Local\Adobe
2014-11-29 19:05 - 2014-11-29 19:05 - 00001345 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2014-11-29 19:05 - 2014-11-29 19:05 - 00001326 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2014-11-29 19:04 - 2014-12-02 14:14 - 01530932 _____ () C:\Windows\WindowsUpdate.log
2014-11-29 19:02 - 2014-11-29 19:04 - 00001313 _____ () C:\Windows\TSSysprep.log
2014-11-29 19:01 - 2014-11-29 17:18 - 00000000 ____D () C:\Windows\Panther
2014-11-29 18:00 - 2014-11-29 18:00 - 00001154 _____ () C:\Windows\system32\MultiLanguage.tmp
2014-11-29 17:56 - 2014-12-02 14:09 - 00064024 _____ () C:\Users\Monk\AppData\Local\GDIPFONTCACHEV1.DAT
2014-11-29 17:53 - 2014-11-29 17:54 - 00000000 ____D () C:\AdwCleaner
2014-11-29 17:43 - 2014-11-30 11:15 - 00000000 ____D () C:\ProgramData\Adobe
2014-11-29 17:43 - 2014-11-30 04:02 - 00000000 ____D () C:\Program Files\Belkin
2014-11-29 17:43 - 2014-11-30 00:55 - 00000000 ____D () C:\Users\Monk\AppData\Roaming\Adobe
2014-11-29 17:32 - 2014-11-30 04:03 - 00000000 ___HD () C:\Program Files\InstallShield Installation Information
2014-11-29 17:32 - 2014-11-29 17:32 - 00000000 ____D () C:\Program Files\Netgear
2014-11-29 17:32 - 2010-05-05 07:01 - 00278560 _____ (Netgear) C:\Windows\system32\Drivers\G311N6.sys
2014-11-29 17:32 - 2009-12-03 03:27 - 00080416 _____ () C:\Windows\system32\RtNicProp.dll
2014-11-29 17:24 - 2014-08-11 07:26 - 107337514 _____ () C:\Users\Monk\Desktop\Thunderbird 31.0 (en-US) - 2014-08-11.pcv
2014-11-29 17:24 - 2014-06-01 16:51 - 00140136 _____ () C:\Users\Monk\Desktop\X-Fi Go! manual English.chm
2014-11-29 17:22 - 2009-05-13 19:11 - 00006504 _____ () C:\Windows\system32\Drivers\ASACPI.sys
2014-11-29 17:21 - 2014-12-02 14:13 - 00781298 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-11-29 17:20 - 2014-11-29 17:20 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2014-11-29 17:20 - 2014-11-01 11:24 - 04184008 _____ (Kaspersky Lab ZAO) C:\Users\Monk\Desktop\tdsskiller.exe
2014-11-29 17:18 - 2014-11-29 17:18 - 00001417 _____ () C:\Users\Monk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2014-11-29 17:18 - 2014-11-29 17:18 - 00000020 ___SH () C:\Users\Monk\ntuser.ini
2014-11-29 17:18 - 2014-11-29 17:18 - 00000000 __SHD () C:\Recovery
2014-11-29 17:18 - 2014-11-29 17:18 - 00000000 ____D () C:\Users\Monk\AppData\Local\VirtualStore
2014-11-29 17:18 - 2014-11-29 17:18 - 00000000 ____D () C:\Users\Monk
2014-11-29 17:18 - 2009-07-13 22:42 - 00000000 ___RD () C:\Users\Monk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2014-11-29 17:18 - 2009-07-13 22:37 - 00000000 ___RD () C:\Users\Monk\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
 
==================== One Month Modified Files and Folders =======
 
(If an entry is included in the fixlist, the file\folder will be moved.)
 
2014-12-02 15:38 - 2009-07-13 22:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-02 15:38 - 2009-07-13 22:34 - 00009920 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-02 14:13 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Microsoft.NET
2014-12-02 14:11 - 2009-07-13 22:39 - 00022805 _____ () C:\Windows\setupact.log
2014-12-02 14:08 - 2009-07-13 22:46 - 00001515 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2014-12-02 14:08 - 2009-07-13 20:37 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2014-12-02 14:06 - 2009-07-13 22:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-02 14:06 - 2009-07-13 22:33 - 00286544 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-12-02 14:04 - 2009-07-13 20:37 - 00000000 ____D () C:\Program Files\Common Files\System
2014-12-02 14:03 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Defender
2014-12-01 17:59 - 2009-07-13 20:37 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\zh-TW
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\zh-HK
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\zh-CN
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\tr-TR
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\sv-SE
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\ru-RU
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\pt-PT
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\pt-BR
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\pl-PL
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\nl-NL
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\nb-NO
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\ko-KR
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\ja-JP
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\it-IT
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\hu-HU
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\fr-FR
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\fi-FI
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\el-GR
2014-12-01 11:45 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-12-01 10:58 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\system32\FxsTmp
2014-12-01 10:16 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\twain_32
2014-12-01 10:16 - 2009-07-13 20:37 - 00000000 __RSD () C:\Windows\Media
2014-12-01 02:59 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Sidebar
2014-12-01 02:59 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2014-12-01 02:59 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2014-12-01 02:59 - 2009-07-13 22:52 - 00000000 ____D () C:\Program Files\DVD Maker
2014-12-01 02:58 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers
2014-11-30 20:53 - 2009-07-13 20:05 - 00152576 _____ (Microsoft Corporation) C:\Windows\system32\msclmd.dll
2014-11-30 04:30 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\Help
2014-11-30 04:07 - 2009-07-13 22:52 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-11-30 04:07 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\spool
2014-11-30 03:07 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\LogFiles
2014-11-30 02:37 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\system32\NDF
2014-11-30 02:01 - 2009-07-13 20:37 - 00000000 __RHD () C:\Users\Public\Libraries
2014-11-29 19:17 - 2009-07-13 20:37 - 00000000 ____D () C:\Windows\rescache
2014-11-29 19:02 - 2009-07-13 22:34 - 00001774 _____ () C:\Windows\DtcInstall.log
2014-11-29 19:00 - 2009-07-13 22:57 - 00025600 ___SH () C:\Windows\system32\config\BCD-Template.LOG
2014-11-29 19:00 - 2009-07-13 22:52 - 00028672 _____ () C:\Windows\system32\config\BCD-Template
2014-11-29 17:32 - 2009-07-13 22:52 - 00000000 ____D () C:\Windows\system32\restore
 
Some content of TEMP:
====================
C:\Users\Monk\AppData\Local\Temp\MSETUP4.EXE
C:\Users\Monk\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\Monk\AppData\Local\Temp\nvStInst.exe
C:\Users\Monk\AppData\Local\Temp\Quarantine.exe
C:\Users\Monk\AppData\Local\Temp\uninstall.exe
 
 
==================== Bamital & volsnap Check =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2014-11-29 19:02
 
==================== End Of Log ============================


#6 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 06 December 2014 - 09:03 AM

Malwarebytes Anti-Rootkit BETA 1.07.0.1012
www.malwarebytes.org
 
Database version: v2014.12.02.09
 
Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 11.0.9600.17420
Monk :: MBPHBROTHERS [administrator]
 
12/2/2014 15:40:43
mbar-log-2014-12-02 (15-40-43).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 283063
Time elapsed: 6 minute(s), 7 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)


#7 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 06 December 2014 - 09:03 AM

---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.08.2.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x86
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.17420
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.210000 GHz
Memory total: 3220496384, free: 1299013632
 
=======================================
 
 
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.08.2.1001
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x86
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.17420
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.210000 GHz
Memory total: 3220496384, free: 1269010432
 
Downloaded database version: v2014.12.02.09
Downloaded database version: v2014.12.02.02
=======================================
Initializing...
This version of Malwarebytes Anti-Rootkit requires you to completely exit the Malwarebytes Anti-Malware application to continue.
=======================================
 
 
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1012
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x86
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.17420
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.210000 GHz
Memory total: 3220496384, free: 1139609600
 
Downloaded database version: v2014.12.02.09
Downloaded database version: v2014.12.02.02
Initializing...
=======================================
Done!
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 7CC2FB56
 
Partition information:
 
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition file system is NTFS
    Partition is bootable
 
    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 624932864
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
Disk Size: 320072933376 bytes
Sector size: 512 bytes
 
Scanning physical sectors of unpartitioned space on drive 0 (1-2047-625122448-625142448)...
Done!
Scan finished
=======================================
 
 
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished
---------------------------------------
Malwarebytes Anti-Rootkit BETA 1.07.0.1012
 
© Malwarebytes Corporation 2011-2012
 
OS version: 6.1.7601 Windows 7 Service Pack 1 x86
 
Account is Administrative
 
Internet Explorer version: 11.0.9600.17420
 
File system is: NTFS
Disk drives: C:\ DRIVE_FIXED
CPU speed: 2.210000 GHz
Memory total: 3220496384, free: 1407590400
 
=======================================
Initializing...
------------ Kernel report ------------
     12/02/2014 15:40:33
------------ Loaded modules -----------
\SystemRoot\system32\ntkrnlpa.exe
\SystemRoot\system32\halmacpi.dll
\SystemRoot\system32\kdcom.dll
\SystemRoot\system32\mcupdate_AuthenticAMD.dll
\SystemRoot\system32\PSHED.dll
\SystemRoot\system32\BOOTVID.dll
\SystemRoot\system32\CLFS.SYS
\SystemRoot\system32\CI.dll
\SystemRoot\system32\drivers\Wdf01000.sys
\SystemRoot\system32\drivers\WDFLDR.SYS
\SystemRoot\system32\drivers\ACPI.sys
\SystemRoot\system32\drivers\WMILIB.SYS
\SystemRoot\system32\drivers\msisadrv.sys
\SystemRoot\system32\drivers\pci.sys
\SystemRoot\system32\drivers\vdrvroot.sys
\SystemRoot\System32\drivers\partmgr.sys
\SystemRoot\system32\drivers\volmgr.sys
\SystemRoot\System32\drivers\volmgrx.sys
\SystemRoot\system32\drivers\pciide.sys
\SystemRoot\system32\drivers\PCIIDEX.SYS
\SystemRoot\System32\drivers\mountmgr.sys
\SystemRoot\system32\drivers\atapi.sys
\SystemRoot\system32\drivers\ataport.SYS
\SystemRoot\system32\drivers\nvstor.sys
\SystemRoot\system32\drivers\storport.sys
\SystemRoot\system32\drivers\amdxata.sys
\SystemRoot\system32\drivers\fltmgr.sys
\SystemRoot\system32\drivers\fileinfo.sys
\SystemRoot\System32\drivers\WRkrn.sys
\SystemRoot\System32\drivers\msrpc.sys
\SystemRoot\System32\drivers\NETIO.SYS
\SystemRoot\System32\drivers\NDIS.SYS
\SystemRoot\System32\drivers\TDI.SYS
\SystemRoot\System32\Drivers\Ntfs.sys
\SystemRoot\System32\Drivers\ksecdd.sys
\SystemRoot\System32\Drivers\cng.sys
\SystemRoot\System32\drivers\pcw.sys
\SystemRoot\System32\Drivers\Fs_Rec.sys
\SystemRoot\System32\Drivers\ksecpkg.sys
\SystemRoot\System32\drivers\tcpip.sys
\SystemRoot\System32\drivers\fwpkclnt.sys
\SystemRoot\system32\drivers\volsnap.sys
\SystemRoot\System32\Drivers\spldr.sys
\SystemRoot\System32\drivers\rdyboost.sys
\SystemRoot\System32\Drivers\mup.sys
\SystemRoot\System32\drivers\hwpolicy.sys
\SystemRoot\System32\DRIVERS\fvevol.sys
\SystemRoot\system32\DRIVERS\disk.sys
\SystemRoot\system32\DRIVERS\CLASSPNP.SYS
\SystemRoot\system32\drivers\cdrom.sys
\SystemRoot\System32\Drivers\Null.SYS
\SystemRoot\System32\Drivers\Beep.SYS
\SystemRoot\System32\drivers\vga.sys
\SystemRoot\System32\drivers\VIDEOPRT.SYS
\SystemRoot\System32\drivers\watchdog.sys
\SystemRoot\System32\DRIVERS\RDPCDD.sys
\SystemRoot\system32\drivers\rdpencdd.sys
\SystemRoot\system32\drivers\rdprefmp.sys
\SystemRoot\System32\Drivers\Msfs.SYS
\SystemRoot\System32\Drivers\Npfs.SYS
\SystemRoot\system32\DRIVERS\tdx.sys
\SystemRoot\system32\drivers\afd.sys
\SystemRoot\System32\DRIVERS\netbt.sys
\SystemRoot\system32\DRIVERS\vsdatant.sys
\SystemRoot\system32\DRIVERS\wfplwf.sys
\SystemRoot\system32\DRIVERS\pacer.sys
\SystemRoot\system32\DRIVERS\netbios.sys
\SystemRoot\system32\DRIVERS\wanarp.sys
\SystemRoot\system32\drivers\termdd.sys
\SystemRoot\system32\DRIVERS\rdbss.sys
\SystemRoot\system32\drivers\nsiproxy.sys
\SystemRoot\system32\drivers\mssmbios.sys
\??\C:\Windows\System32\FreeOTFEHashWhirlpool.sys
\??\C:\Windows\System32\FreeOTFEHashTiger.sys
\??\C:\Windows\System32\FreeOTFEHashSHA.sys
\??\C:\Windows\System32\FreeOTFEHashRIPEMD.sys
\??\C:\Windows\System32\FreeOTFEHashMD.sys
\??\C:\Windows\System32\FreeOTFECypherTwofish_ltc.sys
\??\C:\Windows\System32\FreeOTFECypherSerpent_Gladman.sys
\??\C:\Windows\System32\FreeOTFECypherRC6_ltc.sys
\??\C:\Windows\System32\FreeOTFECypherMARS_Gladman.sys
\??\C:\Windows\System32\FreeOTFECypherDES.sys
\??\C:\Windows\System32\FreeOTFECypherCAST6_Gladman.sys
\??\C:\Windows\System32\FreeOTFECypherCAST5.sys
\??\C:\Windows\System32\FreeOTFECypherBlowfish.sys
\??\C:\Windows\System32\FreeOTFECypherAES_ltc.sys
\??\C:\Windows\System32\FreeOTFECypherAES_Gladman.sys
\??\C:\Windows\System32\FreeOTFE.sys
\SystemRoot\System32\drivers\discache.sys
\SystemRoot\System32\Drivers\dfsc.sys
\SystemRoot\system32\DRIVERS\blbdrive.sys
\SystemRoot\system32\DRIVERS\tunnel.sys
\SystemRoot\system32\DRIVERS\amdppm.sys
\SystemRoot\system32\DRIVERS\parport.sys
\SystemRoot\system32\DRIVERS\ASACPI.sys
\SystemRoot\System32\drivers\keyscrambler.sys
\SystemRoot\system32\drivers\kbdclass.sys
\SystemRoot\system32\drivers\usbohci.sys
\SystemRoot\system32\drivers\USBPORT.SYS
\SystemRoot\system32\drivers\usbehci.sys
\SystemRoot\system32\DRIVERS\Rt86win7.sys
\SystemRoot\system32\drivers\HDAudBus.sys
\SystemRoot\system32\DRIVERS\nvlddmkm.sys
\SystemRoot\System32\drivers\dxgkrnl.sys
\SystemRoot\System32\drivers\dxgmms1.sys
\SystemRoot\system32\drivers\CompositeBus.sys
\SystemRoot\system32\DRIVERS\AgileVpn.sys
\SystemRoot\system32\DRIVERS\rasl2tp.sys
\SystemRoot\system32\DRIVERS\ndistapi.sys
\SystemRoot\system32\DRIVERS\ndiswan.sys
\SystemRoot\system32\DRIVERS\raspppoe.sys
\SystemRoot\system32\DRIVERS\raspptp.sys
\SystemRoot\system32\DRIVERS\rassstp.sys
\SystemRoot\system32\drivers\mouclass.sys
\SystemRoot\system32\drivers\swenum.sys
\SystemRoot\system32\drivers\ks.sys
\SystemRoot\system32\drivers\umbus.sys
\SystemRoot\system32\drivers\nvvad32v.sys
\SystemRoot\system32\drivers\portcls.sys
\SystemRoot\system32\drivers\drmk.sys
\SystemRoot\system32\drivers\usbhub.sys
\SystemRoot\System32\Drivers\NDProxy.SYS
\SystemRoot\system32\drivers\HdAudio.sys
\SystemRoot\system32\drivers\nvhda32v.sys
\SystemRoot\System32\win32k.sys
\SystemRoot\System32\drivers\Dxapi.sys
\SystemRoot\System32\Drivers\crashdmp.sys
\SystemRoot\System32\Drivers\dump_diskdump.sys
\SystemRoot\System32\Drivers\dump_nvstor.sys
\SystemRoot\System32\Drivers\dump_dumpfve.sys
\SystemRoot\system32\drivers\usbccgp.sys
\SystemRoot\system32\drivers\USBD.SYS
\SystemRoot\system32\drivers\HIDPARSE.SYS
\SystemRoot\system32\DRIVERS\monitor.sys
\SystemRoot\System32\TSDDD.dll
\SystemRoot\System32\cdd.dll
\SystemRoot\system32\drivers\luafv.sys
\SystemRoot\system32\drivers\WudfPf.sys
\SystemRoot\system32\DRIVERS\lltdio.sys
\SystemRoot\system32\DRIVERS\nwifi.sys
\SystemRoot\system32\DRIVERS\ndisuio.sys
\SystemRoot\system32\DRIVERS\rspndr.sys
\SystemRoot\system32\drivers\HTTP.sys
\SystemRoot\system32\DRIVERS\bowser.sys
\SystemRoot\System32\drivers\mpsdrv.sys
\SystemRoot\system32\DRIVERS\mrxsmb.sys
\SystemRoot\system32\DRIVERS\mrxsmb10.sys
\SystemRoot\system32\DRIVERS\mrxsmb20.sys
\SystemRoot\system32\DRIVERS\parvdm.sys
\SystemRoot\system32\drivers\peauth.sys
\SystemRoot\System32\Drivers\secdrv.SYS
\SystemRoot\System32\DRIVERS\srvnet.sys
\SystemRoot\System32\drivers\tcpipreg.sys
\SystemRoot\System32\DRIVERS\srv2.sys
\SystemRoot\System32\DRIVERS\srv.sys
\SystemRoot\system32\drivers\hidusb.sys
\SystemRoot\system32\drivers\HIDCLASS.SYS
\SystemRoot\system32\DRIVERS\mouhid.sys
\SystemRoot\System32\Drivers\nx6000.sys
\SystemRoot\System32\Drivers\usbvideo.sys
\SystemRoot\system32\drivers\kbdhid.sys
\SystemRoot\system32\DRIVERS\cdfs.sys
\SystemRoot\system32\drivers\usbscan.sys
\SystemRoot\system32\DRIVERS\usbprint.sys
\SystemRoot\system32\drivers\ksaud.sys
\SystemRoot\system32\drivers\spsys.sys
\SystemRoot\system32\drivers\usbaudio.sys
\??\C:\Windows\system32\drivers\mbamchameleon.sys
\??\C:\Windows\system32\drivers\MBAMSwissArmy.sys
\Windows\System32\ntdll.dll
\Windows\System32\smss.exe
\Windows\System32\apisetschema.dll
\Windows\System32\autochk.exe
\Windows\System32\urlmon.dll
\Windows\System32\msctf.dll
\Windows\System32\oleaut32.dll
\Windows\System32\gdi32.dll
\Windows\System32\shell32.dll
\Windows\System32\ws2_32.dll
\Windows\System32\nsi.dll
\Windows\System32\usp10.dll
\Windows\System32\clbcatq.dll
\Windows\System32\ole32.dll
\Windows\System32\imagehlp.dll
\Windows\System32\imm32.dll
\Windows\System32\user32.dll
\Windows\System32\wininet.dll
\Windows\System32\msvcrt.dll
\Windows\System32\kernel32.dll
\Windows\System32\iertutil.dll
\Windows\System32\sechost.dll
\Windows\System32\rpcrt4.dll
\Windows\System32\shlwapi.dll
\Windows\System32\normaliz.dll
\Windows\System32\difxapi.dll
\Windows\System32\Wldap32.dll
\Windows\System32\comdlg32.dll
\Windows\System32\psapi.dll
\Windows\System32\advapi32.dll
\Windows\System32\lpk.dll
\Windows\System32\setupapi.dll
\Windows\System32\wintrust.dll
\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
\Windows\System32\crypt32.dll
\Windows\System32\userenv.dll
\Windows\System32\cfgmgr32.dll
\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
\Windows\System32\devobj.dll
\Windows\System32\comctl32.dll
\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
\Windows\System32\KernelBase.dll
\Windows\System32\profapi.dll
\Windows\System32\msasn1.dll
----------- End -----------
Done!
<<<1>>>
Upper Device Name: \Device\Harddisk0\DR0
Upper Device Object: 0xffffffff8671cac8
Upper Device Driver Name: \Driver\Disk\
Lower Device Name: \Device\0000006a\
Lower Device Object: 0xffffffff864cd738
Lower Device Driver Name: \Driver\nvstor\
<<<2>>>
Physical Sector Size: 512
Drive: 0, DevicePointer: 0xffffffff8671cac8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
--------- Disk Stack ------
DevicePointer: 0xffffffff86baa298, DeviceName: Unknown, DriverName: \Driver\WRkrn\
DevicePointer: 0xffffffff8671c700, DeviceName: Unknown, DriverName: \Driver\partmgr\
DevicePointer: 0xffffffff8671cac8, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\
DevicePointer: 0xffffffff860ea428, DeviceName: Unknown, DriverName: \Driver\ACPI\
DevicePointer: 0xffffffff864cd738, DeviceName: \Device\0000006a\, DriverName: \Driver\nvstor\
------------ End ----------
Alternate DeviceName: Unknown, DriverName: \Driver\partmgr\
Upper DeviceData: 0x0, 0x0, 0x0
Lower DeviceData: 0x0, 0x0, 0x0
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
<<<2>>>
<<<3>>>
Volume: C:
File system type: NTFS
SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes
Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers...
Done!
Drive 0
This is a System drive
Scanning MBR on drive 0...
Inspecting partition table:
MBR Signature: 55AA
Disk Signature: 7CC2FB56
 
Partition information:
 
    Partition 0 type is Primary (0x7)
    Partition is ACTIVE.
    Partition starts at LBA: 2048  Numsec = 204800
    Partition file system is NTFS
    Partition is bootable
 
    Partition 1 type is Primary (0x7)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 206848  Numsec = 624932864
 
    Partition 2 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
    Partition 3 type is Empty (0x0)
    Partition is NOT ACTIVE.
    Partition starts at LBA: 0  Numsec = 0
 
Disk Size: 320072933376 bytes
Sector size: 512 bytes
 
Scanning physical sectors of unpartitioned space on drive 0 (1-2047-625122448-625142448)...
Done!
Scan finished
=======================================
 
 
Removal queue found; removal started
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\VBR-0-0-2048-i.mbam...
Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR-0-r.mbam...
Removal finished


#8 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 06 December 2014 - 09:04 AM

I guess when I posted, it was obviously more than 2mb and I didn't wait long enough for it to give me a warning.



#9 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 06 December 2014 - 09:33 AM

Hi BrotherPorter,
 

Where did my post get delivered?

I'm not sure where your post went.
  • Please try and post all requested logs in one reply.(if they will fit)
  • Have you installed any new browser extensions or add-ons just prior to this issue starting?
  • Can you tell me what this program is:FreeOTFE
=========================

bullseye_zpse9eaf36e.gif FRST Fix Script

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. Save it on the desktop as fixlist.txt
 


Start
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
EmptyTemp:
Hosts:
CMD: ipconfig /flushdns
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST and press the Fix button just once and wait.
The tool will make a log (Fixlog.txt) please post it to your reply.

=========================

bullseye_zpse9eaf36e.gif TDSSKiller

Please download TDSSKiller.zip - Extract it to your desktop
or from here >> http://www.bleepingc...oad/tdsskiller/
  • TDSSKiller.exe
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
=========================

In your next post please provide the following:
  • Fixlog.txt
  • TDSSKiller.[Version]_[Date]_[Time]_log.txt
  • Answers to questions above

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#10 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 09 December 2014 - 04:53 PM

thank you for ur patience; don't give up on me, I haven't forgotten I need ur help. I have started chemo and it has been kicking my butt; they have started me on antinausea meds and he says it should help me perk up in couple of days; I've tried multiple times to start posting and just have to lay down again. Let's see, l posted the answers and then ran frst and fix and it didn't warn me it needed to restart :( so this post is # 2, heehee)

  • Please try and post all requested logs in one reply.(if they will fit)
    yes, I will do that, except for this one again; I think I just didn't give the first one time to paste that whole gamut of screens at one time.
  • Have you installed any new browser extensions or add-ons just prior to this issue starting?
    no new add-ons/extensions, etc only ones I'd use previously long before this intrusion; I have a couple of days ago removed the netgear ga311 (internal wireless adapter card) and bought netgear fs650 fast ethernet switch (no wireless) and only thing wireless in my home now is ethernet, I just can't use my ipod touch and bluray dvd streaming netflix.
  • Can you tell me what this program is:FreeOTFE
    this is sourceforge similar program to sandboxie alternative you can create one or more "virtual disks" on your PC/PDA. These disks operate exactly like a normal disk, with the exception that anything written to one of them is transparently, and securely, encrypted before being stored on your computer's hard drive. I want to use it on my flash drive to protect my roboform password manager 

​I have run the fixlist, and I can log this but pls I have to lay down again.

---------------------------------------

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-12-2014
Ran by Monk at 2014-12-09 16:30:02 Run:1
Running from C:\Users\Monk\Desktop
Loaded Profile: Monk (Available profiles: Monk)
Boot Mode: Normal
 
==============================================
 
Content of fixlist:
*****************
Start
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION!
HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
EmptyTemp:
Hosts:
CMD: ipconfig /flushdns
End
*****************
 
"HKU\.DEFAULT\Software\Classes\exefile" => Key deleted successfully.
"HKU\.DEFAULT\Software\Classes\.exe" => Key deleted successfully.
"HKU\.DEFAULT\Software\Classes\exefile" => Key not found.
"HKU\S-1-5-19\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-19\Software\Classes\.exe" => Key deleted successfully.
"HKU\S-1-5-19\Software\Classes\exefile" => Key not found.
"HKU\S-1-5-20\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-20\Software\Classes\.exe" => Key deleted successfully.
"HKU\S-1-5-20\Software\Classes\exefile" => Key not found.
"HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\.exe" => Key deleted successfully.
"HKU\S-1-5-21-3795844004-4128841395-3337064661-1000\Software\Classes\exefile" => Key not found.
"C:\Windows\System32\Drivers\etc\hosts" => Could not move.
Could not reset Hosts.
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
EmptyTemp: => Removed 508.6 MB temporary data.
 
 
The system needed a reboot. 
 
==== End of Fixlog ====

    Advertisements

Register to Remove


#11 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 09 December 2014 - 06:57 PM

Hi BrotherPorter,

Thank you answering all my questions in a detailed manner. :thumbup: 

I am sorry to hear you are experiencing some medical issues. Take your time completing the tasks I outline, and post when you are able. I will keep the thread open.


OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#12 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 11 December 2014 - 01:17 PM

Thank you for your understanding; I have to tell you- this is the first time TDSS has ever found otfee as any kind of 'hit' -- but all that was found (12) different all had 'skip' instead of quarantee. The other thing I noticed is there is a folder labelled: winsxs under windows and I think a lot of windows stuff is redirected to that folder and appears to be used instead of regular windows.

 

 

12:43:17.0288 0x183c  TDSS rootkit removing tool 3.0.0.41 Oct 28 2014 17:58:34
12:43:22.0030 0x183c  ============================================================
12:43:22.0030 0x183c  Current date / time: 2014/12/11 12:43:22.0030
12:43:22.0030 0x183c  SystemInfo:
12:43:22.0030 0x183c  
12:43:22.0030 0x183c  OS Version: 6.1.7601 ServicePack: 1.0
12:43:22.0030 0x183c  Product type: Workstation
12:43:22.0030 0x183c  ComputerName: MBPHBROTHERS
12:43:22.0030 0x183c  UserName: Monk
12:43:22.0030 0x183c  Windows directory: C:\Windows
12:43:22.0030 0x183c  System windows directory: C:\Windows
12:43:22.0030 0x183c  Processor architecture: Intel x86
12:43:22.0030 0x183c  Number of processors: 4
12:43:22.0030 0x183c  Page size: 0x1000
12:43:22.0030 0x183c  Boot type: Normal boot
12:43:22.0030 0x183c  ============================================================
12:43:25.0729 0x183c  KLMD registered as C:\Windows\system32\drivers\27815539.sys
12:43:25.0851 0x183c  System UUID: {39C677B9-3EBA-4C61-E279-17D2EB4D966C}
12:43:26.0771 0x183c  Drive \Device\Harddisk0\DR0 - Size: 0x4A85D56000 ( 298.09 Gb ), SectorSize: 0x200, Cylinders: 0x847C26, SectorsPerTrack: 0x4, TracksPerCylinder: 0x12, Type 'K0', Flags 0x00000050
12:43:26.0779 0x183c  ============================================================
12:43:26.0779 0x183c  \Device\Harddisk0\DR0:
12:43:26.0779 0x183c  MBR partitions:
12:43:26.0779 0x183c  \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0x32000
12:43:26.0779 0x183c  \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x32800, BlocksNum 0x253FB800
12:43:26.0779 0x183c  ============================================================
12:43:26.0809 0x183c  C: <-> \Device\Harddisk0\DR0\Partition2
12:43:26.0809 0x183c  ============================================================
12:43:26.0809 0x183c  Initialize success
12:43:26.0809 0x183c  ============================================================
12:43:37.0481 0x08bc  ============================================================
12:43:37.0481 0x08bc  Scan started
12:43:37.0481 0x08bc  Mode: Manual; SigCheck; TDLFS; 
12:43:37.0481 0x08bc  ============================================================
12:43:37.0481 0x08bc  KSN ping started
12:43:51.0010 0x08bc  KSN ping finished: true
12:43:51.0747 0x08bc  ================ Scan system memory ========================
12:43:51.0747 0x08bc  System memory - ok
12:43:51.0747 0x08bc  ================ Scan services =============================
12:43:51.0872 0x08bc  [ 72D6D8E2D4F82C6E829125C7EC2A88F9, F357CFC3D04EB3F8E1A504D531D099698C6E2B29EB6CEDF75C08BF8917C46573 ] !SASCORE        C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
12:43:51.0938 0x08bc  !SASCORE - ok
12:43:52.0066 0x08bc  [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci        C:\Windows\system32\drivers\1394ohci.sys
12:43:52.0094 0x08bc  1394ohci - detected UnsignedFile.Multi.Generic ( 1 )
12:43:54.0772 0x08bc  Detect skipped due to KSN trusted
12:43:54.0772 0x08bc  1394ohci - ok
12:43:54.0827 0x08bc  [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI            C:\Windows\system32\drivers\ACPI.sys
12:43:54.0862 0x08bc  ACPI - ok
12:43:54.0902 0x08bc  [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi         C:\Windows\system32\drivers\acpipmi.sys
12:43:54.0911 0x08bc  AcpiPmi - detected UnsignedFile.Multi.Generic ( 1 )
12:43:57.0353 0x08bc  Detect skipped due to KSN trusted
12:43:57.0353 0x08bc  AcpiPmi - ok
12:43:57.0414 0x08bc  [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx         C:\Windows\system32\DRIVERS\adp94xx.sys
12:43:57.0449 0x08bc  adp94xx - ok
12:43:57.0468 0x08bc  [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci         C:\Windows\system32\DRIVERS\adpahci.sys
12:43:57.0502 0x08bc  adpahci - ok
12:43:57.0520 0x08bc  [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320         C:\Windows\system32\DRIVERS\adpu320.sys
12:43:57.0540 0x08bc  adpu320 - ok
12:43:57.0564 0x08bc  [ 8B5EEFEEC1E6D1A72A06C526628AD161, 026CDF4C96F4D493E7BABF79A14C4B0B5ADCCEF0B081FFFA2E3B243B2414167F ] AeLookupSvc     C:\Windows\System32\aelupsvc.dll
12:43:57.0575 0x08bc  AeLookupSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:44:00.0438 0x08bc  Detect skipped due to KSN trusted
12:44:00.0438 0x08bc  AeLookupSvc - ok
12:44:00.0502 0x08bc  [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD             C:\Windows\system32\drivers\afd.sys
12:44:00.0529 0x08bc  AFD - detected UnsignedFile.Multi.Generic ( 1 )
12:44:02.0954 0x08bc  Detect skipped due to KSN trusted
12:44:02.0954 0x08bc  AFD - ok
12:44:02.0994 0x08bc  [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440          C:\Windows\system32\drivers\agp440.sys
12:44:03.0011 0x08bc  agp440 - ok
12:44:03.0025 0x08bc  [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx         C:\Windows\system32\DRIVERS\djsvs.sys
12:44:03.0043 0x08bc  aic78xx - ok
12:44:03.0070 0x08bc  [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG             C:\Windows\System32\alg.exe
12:44:03.0081 0x08bc  ALG - detected UnsignedFile.Multi.Generic ( 1 )
12:44:05.0555 0x08bc  Detect skipped due to KSN trusted
12:44:05.0555 0x08bc  ALG - ok
12:44:05.0597 0x08bc  [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide          C:\Windows\system32\drivers\aliide.sys
12:44:05.0613 0x08bc  aliide - ok
12:44:05.0658 0x08bc  [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp          C:\Windows\system32\drivers\amdagp.sys
12:44:05.0675 0x08bc  amdagp - ok
12:44:05.0689 0x08bc  [ CD5914170297126B6266860198D1D4F0, 2239FCBD1A7EC27CE4F10DA36AE6BD6CCB87E5128C82CA71B84BFE5AF5602A60 ] amdide          C:\Windows\system32\drivers\amdide.sys
12:44:05.0704 0x08bc  amdide - ok
12:44:05.0719 0x08bc  [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8           C:\Windows\system32\DRIVERS\amdk8.sys
12:44:05.0730 0x08bc  AmdK8 - detected UnsignedFile.Multi.Generic ( 1 )
12:44:08.0156 0x08bc  Detect skipped due to KSN trusted
12:44:08.0156 0x08bc  AmdK8 - ok
12:44:08.0171 0x08bc  [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM          C:\Windows\system32\DRIVERS\amdppm.sys
12:44:08.0182 0x08bc  AmdPPM - detected UnsignedFile.Multi.Generic ( 1 )
12:44:11.0860 0x08bc  Detect skipped due to KSN trusted
12:44:11.0860 0x08bc  AmdPPM - ok
12:44:11.0915 0x08bc  [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata         C:\Windows\system32\drivers\amdsata.sys
12:44:11.0932 0x08bc  amdsata - ok
12:44:11.0952 0x08bc  [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs          C:\Windows\system32\DRIVERS\amdsbs.sys
12:44:11.0972 0x08bc  amdsbs - ok
12:44:11.0982 0x08bc  [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata         C:\Windows\system32\drivers\amdxata.sys
12:44:11.0998 0x08bc  amdxata - ok
12:44:12.0074 0x08bc  [ D1AF38FBAC0DC7E6D796B0ED01707EE0, FAFD2C36594A1628293E7623C8CAB2D47EDF8C6C0E18CC2FB37F9A6CA1F0E57C ] AppHostSvc      C:\Windows\system32\inetsrv\apphostsvc.dll
12:44:12.0085 0x08bc  AppHostSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:44:14.0693 0x08bc  Detect skipped due to KSN trusted
12:44:14.0693 0x08bc  AppHostSvc - ok
12:44:14.0748 0x08bc  [ AEA177F783E20150ACE5383EE368DA19, 8FA9EE27AA1F22E8B8FE33A21028CA1E0062BAA95CB132C20D55B98C03B4254F ] AppID           C:\Windows\system32\drivers\appid.sys
12:44:14.0758 0x08bc  AppID - detected UnsignedFile.Multi.Generic ( 1 )
12:44:17.0438 0x08bc  Detect skipped due to KSN trusted
12:44:17.0438 0x08bc  AppID - ok
12:44:17.0461 0x08bc  [ 62A9C86CB6085E20DB4823E4E97826F5, E0F840B49710022C4FB437002AD06F64B0F6B5D628B32D00F2B66765E6B97E4B ] AppIDSvc        C:\Windows\System32\appidsvc.dll
12:44:17.0470 0x08bc  AppIDSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:44:20.0086 0x08bc  Detect skipped due to KSN trusted
12:44:20.0086 0x08bc  AppIDSvc - ok
12:44:20.0134 0x08bc  [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo         C:\Windows\System32\appinfo.dll
12:44:20.0145 0x08bc  Appinfo - detected UnsignedFile.Multi.Generic ( 1 )
12:44:22.0573 0x08bc  Detect skipped due to KSN trusted
12:44:22.0573 0x08bc  Appinfo - ok
12:44:22.0695 0x08bc  [ 650D03E40F93FAE323CB841F80368E5C, F67B97CFDCE2EE9294977725268EFDB0DD724BD16E7ED5BFCA45375AA8EBA5BB ] Apple Mobile Device C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
12:44:22.0710 0x08bc  Apple Mobile Device - ok
12:44:22.0726 0x08bc  [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc             C:\Windows\system32\DRIVERS\arc.sys
12:44:22.0744 0x08bc  arc - ok
12:44:22.0752 0x08bc  [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas          C:\Windows\system32\DRIVERS\arcsas.sys
12:44:22.0769 0x08bc  arcsas - ok
12:44:22.0778 0x08bc  ASInsHelp - ok
12:44:22.0858 0x08bc  [ 4DFB39347CE1E8E51AD2D8B124C9D7FA, 172262CD6B5EEFB927EADB3BEF130351994EFD7D660E791A76E64FB6DEA5B561 ] aspnet_state    C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
12:44:22.0875 0x08bc  aspnet_state - ok
12:44:22.0898 0x08bc  [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac        C:\Windows\system32\DRIVERS\asyncmac.sys
12:44:22.0908 0x08bc  AsyncMac - detected UnsignedFile.Multi.Generic ( 1 )
12:44:25.0517 0x08bc  Detect skipped due to KSN trusted
12:44:25.0517 0x08bc  AsyncMac - ok
12:44:25.0555 0x08bc  [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi           C:\Windows\system32\drivers\atapi.sys
12:44:25.0571 0x08bc  atapi - ok
12:44:25.0623 0x08bc  [ F4157B3CECF19B1C266C83AFF051C97A, 26728B59B6003EB36BC322D189254574E94790CE23637228A669FAD6ED76ECE3 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
12:44:25.0653 0x08bc  AudioEndpointBuilder - detected UnsignedFile.Multi.Generic ( 1 )
12:44:28.0094 0x08bc  Detect skipped due to KSN trusted
12:44:28.0094 0x08bc  AudioEndpointBuilder - ok
12:44:28.0112 0x08bc  [ F4157B3CECF19B1C266C83AFF051C97A, 26728B59B6003EB36BC322D189254574E94790CE23637228A669FAD6ED76ECE3 ] Audiosrv        C:\Windows\System32\Audiosrv.dll
12:44:28.0137 0x08bc  Audiosrv - detected UnsignedFile.Multi.Generic ( 1 )
12:44:28.0137 0x08bc  Detect skipped due to KSN trusted
12:44:28.0137 0x08bc  Audiosrv - ok
12:44:28.0197 0x08bc  [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV        C:\Windows\System32\AxInstSV.dll
12:44:28.0209 0x08bc  AxInstSV - detected UnsignedFile.Multi.Generic ( 1 )
12:44:30.0884 0x08bc  Detect skipped due to KSN trusted
12:44:30.0884 0x08bc  AxInstSV - ok
12:44:30.0913 0x08bc  [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv         C:\Windows\system32\DRIVERS\bxvbdx.sys
12:44:30.0959 0x08bc  b06bdrv - detected UnsignedFile.Multi.Generic ( 1 )
12:44:33.0401 0x08bc  Detect skipped due to KSN trusted
12:44:33.0402 0x08bc  b06bdrv - ok
12:44:33.0420 0x08bc  [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x        C:\Windows\system32\DRIVERS\b57nd60x.sys
12:44:33.0447 0x08bc  b57nd60x - detected UnsignedFile.Multi.Generic ( 1 )
12:44:36.0214 0x08bc  Detect skipped due to KSN trusted
12:44:36.0214 0x08bc  b57nd60x - ok
12:44:36.0236 0x08bc  [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC          C:\Windows\System32\bdesvc.dll
12:44:36.0248 0x08bc  BDESVC - detected UnsignedFile.Multi.Generic ( 1 )
12:44:38.0994 0x08bc  Detect skipped due to KSN trusted
12:44:38.0994 0x08bc  BDESVC - ok
12:44:39.0033 0x08bc  [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep            C:\Windows\system32\drivers\Beep.sys
12:44:39.0042 0x08bc  Beep - detected UnsignedFile.Multi.Generic ( 1 )
12:44:41.0667 0x08bc  Detect skipped due to KSN trusted
12:44:41.0667 0x08bc  Beep - ok
12:44:41.0726 0x08bc  [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE             C:\Windows\System32\bfe.dll
12:44:41.0757 0x08bc  BFE - detected UnsignedFile.Multi.Generic ( 1 )
12:44:44.0369 0x08bc  Detect skipped due to KSN trusted
12:44:44.0369 0x08bc  BFE - ok
12:44:44.0434 0x08bc  [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS            C:\Windows\System32\qmgr.dll
12:44:44.0476 0x08bc  BITS - detected UnsignedFile.Multi.Generic ( 1 )
12:44:47.0154 0x08bc  Detect skipped due to KSN trusted
12:44:47.0154 0x08bc  BITS - ok
12:44:47.0174 0x08bc  [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive        C:\Windows\system32\DRIVERS\blbdrive.sys
12:44:47.0185 0x08bc  blbdrive - detected UnsignedFile.Multi.Generic ( 1 )
12:44:49.0625 0x08bc  Detect skipped due to KSN trusted
12:44:49.0625 0x08bc  blbdrive - ok
12:44:49.0735 0x08bc  [ DB5BEA73EDAF19AC68B2C0FAD0F92B1A, 10F21999FF6B1D410EBF280F7F27DEACA5289739CF12F4293B614B8FC6C88DCC ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe
12:44:49.0766 0x08bc  Bonjour Service - ok
12:44:49.0810 0x08bc  [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser          C:\Windows\system32\DRIVERS\bowser.sys
12:44:49.0821 0x08bc  bowser - detected UnsignedFile.Multi.Generic ( 1 )
12:44:59.0891 0x08bc  Object is SCO, delete is not allowed
12:44:59.0892 0x08bc  bowser ( UnsignedFile.Multi.Generic ) - warning
12:45:03.0383 0x08bc  [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo        C:\Windows\system32\DRIVERS\BrFiltLo.sys
12:45:03.0392 0x08bc  BrFiltLo - detected UnsignedFile.Multi.Generic ( 1 )
12:45:05.0832 0x08bc  Detect skipped due to KSN trusted
12:45:05.0832 0x08bc  BrFiltLo - ok
12:45:05.0860 0x08bc  [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp        C:\Windows\system32\DRIVERS\BrFiltUp.sys
12:45:05.0869 0x08bc  BrFiltUp - detected UnsignedFile.Multi.Generic ( 1 )
12:45:08.0308 0x08bc  Detect skipped due to KSN trusted
12:45:08.0308 0x08bc  BrFiltUp - ok
12:45:08.0347 0x08bc  [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser         C:\Windows\System32\browser.dll
12:45:08.0359 0x08bc  Browser - detected UnsignedFile.Multi.Generic ( 1 )
12:45:10.0798 0x08bc  Detect skipped due to KSN trusted
12:45:10.0798 0x08bc  Browser - ok
12:45:10.0820 0x08bc  [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid         C:\Windows\System32\Drivers\Brserid.sys
12:45:10.0848 0x08bc  Brserid - detected UnsignedFile.Multi.Generic ( 1 )
12:45:13.0591 0x08bc  Detect skipped due to KSN trusted
12:45:13.0591 0x08bc  Brserid - ok
12:45:13.0603 0x08bc  [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm        C:\Windows\System32\Drivers\BrSerWdm.sys
12:45:13.0615 0x08bc  BrSerWdm - detected UnsignedFile.Multi.Generic ( 1 )
12:45:16.0047 0x08bc  Detect skipped due to KSN trusted
12:45:16.0047 0x08bc  BrSerWdm - ok
12:45:16.0076 0x08bc  [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm        C:\Windows\System32\Drivers\BrUsbMdm.sys
12:45:16.0085 0x08bc  BrUsbMdm - detected UnsignedFile.Multi.Generic ( 1 )
12:45:18.0521 0x08bc  Detect skipped due to KSN trusted
12:45:18.0521 0x08bc  BrUsbMdm - ok
12:45:18.0538 0x08bc  [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer        C:\Windows\System32\Drivers\BrUsbSer.sys
12:45:18.0547 0x08bc  BrUsbSer - detected UnsignedFile.Multi.Generic ( 1 )
12:45:21.0093 0x08bc  Detect skipped due to KSN trusted
12:45:21.0093 0x08bc  BrUsbSer - ok
12:45:21.0108 0x08bc  [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM        C:\Windows\system32\DRIVERS\bthmodem.sys
12:45:21.0119 0x08bc  BTHMODEM - detected UnsignedFile.Multi.Generic ( 1 )
12:45:23.0558 0x08bc  Detect skipped due to KSN trusted
12:45:23.0558 0x08bc  BTHMODEM - ok
12:45:23.0593 0x08bc  [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv         C:\Windows\system32\bthserv.dll
12:45:23.0604 0x08bc  bthserv - detected UnsignedFile.Multi.Generic ( 1 )
12:45:26.0042 0x08bc  Detect skipped due to KSN trusted
12:45:26.0042 0x08bc  bthserv - ok
12:45:26.0060 0x08bc  [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs            C:\Windows\system32\DRIVERS\cdfs.sys
12:45:26.0071 0x08bc  cdfs - detected UnsignedFile.Multi.Generic ( 1 )
12:45:28.0706 0x08bc  Detect skipped due to KSN trusted
12:45:28.0707 0x08bc  cdfs - ok
12:45:28.0759 0x08bc  [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom           C:\Windows\system32\drivers\cdrom.sys
12:45:28.0772 0x08bc  cdrom - detected UnsignedFile.Multi.Generic ( 1 )
12:45:31.0815 0x08bc  Detect skipped due to KSN trusted
12:45:31.0815 0x08bc  cdrom - ok
12:45:31.0855 0x08bc  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc     C:\Windows\System32\certprop.dll
12:45:31.0866 0x08bc  CertPropSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:45:34.0546 0x08bc  Detect skipped due to KSN trusted
12:45:34.0546 0x08bc  CertPropSvc - ok
12:45:34.0564 0x08bc  [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass        C:\Windows\system32\DRIVERS\circlass.sys
12:45:34.0575 0x08bc  circlass - detected UnsignedFile.Multi.Generic ( 1 )
12:45:37.0254 0x08bc  Detect skipped due to KSN trusted
12:45:37.0254 0x08bc  circlass - ok
12:45:37.0288 0x08bc  [ 635181E0E9BBF16871BF5380D71DB02D, 58D5150C6F3B9F1730FFDF3A8A2ABF5FF207F9785BD66C0C1E03A0F1C223A26A ] CLFS            C:\Windows\system32\CLFS.sys
12:45:37.0320 0x08bc  CLFS - ok
12:45:37.0383 0x08bc  [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
12:45:37.0404 0x08bc  clr_optimization_v2.0.50727_32 - ok
12:45:37.0521 0x08bc  [ E87213F37A13E2B54391E40934F071D0, 7EB221127EFB5BF158FB03D18EFDA2C55FB6CE3D1A1FE69C01D70DBED02C87E5 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
12:45:37.0577 0x08bc  clr_optimization_v4.0.30319_32 - ok
12:45:37.0608 0x08bc  [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt          C:\Windows\system32\DRIVERS\CmBatt.sys
12:45:37.0617 0x08bc  CmBatt - detected UnsignedFile.Multi.Generic ( 1 )
12:45:40.0205 0x08bc  Detect skipped due to KSN trusted
12:45:40.0205 0x08bc  CmBatt - ok
12:45:40.0231 0x08bc  [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide          C:\Windows\system32\drivers\cmdide.sys
12:45:40.0248 0x08bc  cmdide - ok
12:45:40.0305 0x08bc  [ 85449EEBE8F8EBD6481EFBF0F352B4EB, E6FF04970C5A5BFDE7297A86C1C7B9BFE2E0F976A1A1AFB874CEB488DC6151CC ] CNG             C:\Windows\system32\Drivers\cng.sys
12:45:40.0345 0x08bc  CNG - ok
12:45:40.0363 0x08bc  [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt        C:\Windows\system32\DRIVERS\compbatt.sys
12:45:40.0378 0x08bc  Compbatt - ok
12:45:40.0424 0x08bc  [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus    C:\Windows\system32\drivers\CompositeBus.sys
12:45:40.0434 0x08bc  CompositeBus - detected UnsignedFile.Multi.Generic ( 1 )
12:45:43.0109 0x08bc  Detect skipped due to KSN trusted
12:45:43.0109 0x08bc  CompositeBus - ok
12:45:43.0134 0x08bc  COMSysApp - ok
12:45:43.0141 0x08bc  [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk         C:\Windows\system32\DRIVERS\crcdisk.sys
12:45:43.0157 0x08bc  crcdisk - ok
12:45:43.0204 0x08bc  [ 623E143F2DF17C0106A9988F5D7DC878, 9DA30262FF22FA9F1DB247CB3B4A2892D79730EF0ECC9589D399D24B4F58E565 ] CryptSvc        C:\Windows\system32\cryptsvc.dll
12:45:43.0218 0x08bc  CryptSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:45:45.0881 0x08bc  Detect skipped due to KSN trusted
12:45:45.0881 0x08bc  CryptSvc - ok
12:45:46.0012 0x08bc  [ 5CE3D0E1D1B3832EE052CFC442EEE0FA, 6B9DB2C350140ED547C7A96DB0EAD812E8987176B312C79AF52FC9B23EEEB8C4 ] CTAudSvcService C:\Program Files\Creative\Shared Files\CTAudSvc.exe
12:45:46.0057 0x08bc  CTAudSvcService - detected UnsignedFile.Multi.Generic ( 1 )
12:45:48.0659 0x08bc  Detect skipped due to KSN trusted
12:45:48.0659 0x08bc  CTAudSvcService - ok
12:45:48.0709 0x08bc  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch      C:\Windows\system32\rpcss.dll
12:45:48.0738 0x08bc  DcomLaunch - detected UnsignedFile.Multi.Generic ( 1 )
12:45:51.0407 0x08bc  Detect skipped due to KSN trusted
12:45:51.0407 0x08bc  DcomLaunch - ok
12:45:51.0432 0x08bc  [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc       C:\Windows\System32\defragsvc.dll
12:45:51.0459 0x08bc  defragsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:45:53.0899 0x08bc  Detect skipped due to KSN trusted
12:45:53.0899 0x08bc  defragsvc - ok
12:45:53.0929 0x08bc  [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC            C:\Windows\system32\Drivers\dfsc.sys
12:45:53.0940 0x08bc  DfsC - detected UnsignedFile.Multi.Generic ( 1 )
12:45:56.0382 0x08bc  Detect skipped due to KSN trusted
12:45:56.0382 0x08bc  DfsC - ok
12:45:56.0448 0x08bc  [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp            C:\Windows\system32\dhcpcore.dll
12:45:56.0475 0x08bc  Dhcp - detected UnsignedFile.Multi.Generic ( 1 )
12:45:59.0147 0x08bc  Detect skipped due to KSN trusted
12:45:59.0147 0x08bc  Dhcp - ok
12:45:59.0157 0x08bc  [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache        C:\Windows\system32\drivers\discache.sys
12:45:59.0167 0x08bc  discache - detected UnsignedFile.Multi.Generic ( 1 )
12:46:01.0607 0x08bc  Detect skipped due to KSN trusted
12:46:01.0607 0x08bc  discache - ok
12:46:01.0623 0x08bc  [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk            C:\Windows\system32\DRIVERS\disk.sys
12:46:01.0640 0x08bc  Disk - ok
12:46:01.0686 0x08bc  [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache        C:\Windows\System32\dnsrslvr.dll
12:46:01.0700 0x08bc  Dnscache - detected UnsignedFile.Multi.Generic ( 1 )
12:46:11.0700 0x08bc  Object is SCO, delete is not allowed
12:46:11.0700 0x08bc  Dnscache ( UnsignedFile.Multi.Generic ) - warning
12:46:16.0239 0x08bc  [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc         C:\Windows\System32\dot3svc.dll
12:46:16.0266 0x08bc  dot3svc - detected UnsignedFile.Multi.Generic ( 1 )
12:46:18.0934 0x08bc  Detect skipped due to KSN trusted
12:46:18.0934 0x08bc  dot3svc - ok
12:46:18.0981 0x08bc  [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS             C:\Windows\system32\dps.dll
12:46:18.0996 0x08bc  DPS - detected UnsignedFile.Multi.Generic ( 1 )
12:46:21.0747 0x08bc  Detect skipped due to KSN trusted
12:46:21.0747 0x08bc  DPS - ok
12:46:21.0813 0x08bc  [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud         C:\Windows\system32\drivers\drmkaud.sys
12:46:21.0822 0x08bc  drmkaud - detected UnsignedFile.Multi.Generic ( 1 )
12:46:24.0491 0x08bc  Detect skipped due to KSN trusted
12:46:24.0491 0x08bc  drmkaud - ok
12:46:24.0552 0x08bc  [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl         C:\Windows\System32\drivers\dxgkrnl.sys
12:46:24.0596 0x08bc  DXGKrnl - ok
12:46:24.0625 0x08bc  [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost         C:\Windows\System32\eapsvc.dll
12:46:24.0637 0x08bc  EapHost - detected UnsignedFile.Multi.Generic ( 1 )
12:46:27.0317 0x08bc  Detect skipped due to KSN trusted
12:46:27.0317 0x08bc  EapHost - ok
12:46:27.0464 0x08bc  [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv           C:\Windows\system32\DRIVERS\evbdx.sys
12:46:27.0618 0x08bc  ebdrv - detected UnsignedFile.Multi.Generic ( 1 )
12:46:30.0044 0x08bc  Detect skipped due to KSN trusted
12:46:30.0045 0x08bc  ebdrv - ok
12:46:30.0089 0x08bc  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] EFS             C:\Windows\System32\lsass.exe
12:46:30.0099 0x08bc  EFS - detected UnsignedFile.Multi.Generic ( 1 )
12:46:32.0523 0x08bc  Detect skipped due to KSN trusted
12:46:32.0523 0x08bc  EFS - ok
12:46:32.0566 0x08bc  [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr         C:\Windows\ehome\ehRecvr.exe
12:46:32.0606 0x08bc  ehRecvr - detected UnsignedFile.Multi.Generic ( 1 )
12:46:35.0045 0x08bc  Detect skipped due to KSN trusted
12:46:35.0046 0x08bc  ehRecvr - ok
12:46:35.0062 0x08bc  [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched         C:\Windows\ehome\ehsched.exe
12:46:35.0074 0x08bc  ehSched - detected UnsignedFile.Multi.Generic ( 1 )
12:46:37.0513 0x08bc  Detect skipped due to KSN trusted
12:46:37.0513 0x08bc  ehSched - ok
12:46:37.0541 0x08bc  [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor         C:\Windows\system32\DRIVERS\elxstor.sys
12:46:37.0574 0x08bc  elxstor - ok
12:46:37.0614 0x08bc  [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev          C:\Windows\system32\drivers\errdev.sys
12:46:37.0623 0x08bc  ErrDev - detected UnsignedFile.Multi.Generic ( 1 )
12:46:40.0378 0x08bc  Detect skipped due to KSN trusted
12:46:40.0378 0x08bc  ErrDev - ok
12:46:40.0427 0x08bc  [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem     C:\Windows\system32\es.dll
12:46:40.0455 0x08bc  EventSystem - detected UnsignedFile.Multi.Generic ( 1 )
12:46:43.0118 0x08bc  Detect skipped due to KSN trusted
12:46:43.0118 0x08bc  EventSystem - ok
12:46:43.0153 0x08bc  [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat           C:\Windows\system32\drivers\exfat.sys
12:46:43.0167 0x08bc  exfat - detected UnsignedFile.Multi.Generic ( 1 )
12:46:45.0785 0x08bc  Detect skipped due to KSN trusted
12:46:45.0785 0x08bc  exfat - ok
12:46:45.0804 0x08bc  [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat         C:\Windows\system32\drivers\fastfat.sys
12:46:45.0818 0x08bc  fastfat - detected UnsignedFile.Multi.Generic ( 1 )
12:46:48.0482 0x08bc  Detect skipped due to KSN trusted
12:46:48.0482 0x08bc  fastfat - ok
12:46:48.0581 0x08bc  [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax             C:\Windows\system32\fxssvc.exe
12:46:48.0641 0x08bc  Fax - detected UnsignedFile.Multi.Generic ( 1 )
12:46:51.0323 0x08bc  Detect skipped due to KSN trusted
12:46:51.0323 0x08bc  Fax - ok
12:46:51.0336 0x08bc  [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc             C:\Windows\system32\DRIVERS\fdc.sys
12:46:51.0345 0x08bc  fdc - detected UnsignedFile.Multi.Generic ( 1 )
12:46:54.0014 0x08bc  Detect skipped due to KSN trusted
12:46:54.0014 0x08bc  fdc - ok
12:46:54.0027 0x08bc  [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost         C:\Windows\system32\fdPHost.dll
12:46:54.0036 0x08bc  fdPHost - detected UnsignedFile.Multi.Generic ( 1 )
12:46:57.0847 0x08bc  Detect skipped due to KSN trusted
12:46:57.0847 0x08bc  fdPHost - ok
12:46:57.0877 0x08bc  [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub        C:\Windows\system32\fdrespub.dll
12:46:57.0887 0x08bc  FDResPub - detected UnsignedFile.Multi.Generic ( 1 )
12:47:00.0563 0x08bc  Detect skipped due to KSN trusted
12:47:00.0563 0x08bc  FDResPub - ok
12:47:00.0570 0x08bc  [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo        C:\Windows\system32\drivers\fileinfo.sys
12:47:00.0587 0x08bc  FileInfo - ok
12:47:00.0594 0x08bc  [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace       C:\Windows\system32\drivers\filetrace.sys
12:47:00.0604 0x08bc  Filetrace - detected UnsignedFile.Multi.Generic ( 1 )
12:47:03.0043 0x08bc  Detect skipped due to KSN trusted
12:47:03.0043 0x08bc  Filetrace - ok
12:47:03.0057 0x08bc  [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk        C:\Windows\system32\DRIVERS\flpydisk.sys
12:47:03.0066 0x08bc  flpydisk - detected UnsignedFile.Multi.Generic ( 1 )
12:47:05.0735 0x08bc  Detect skipped due to KSN trusted
12:47:05.0735 0x08bc  flpydisk - ok
12:47:05.0750 0x08bc  [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr          C:\Windows\system32\drivers\fltmgr.sys
12:47:05.0772 0x08bc  FltMgr - ok
12:47:05.0849 0x08bc  [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache       C:\Windows\system32\FntCache.dll
12:47:05.0900 0x08bc  FontCache - detected UnsignedFile.Multi.Generic ( 1 )
12:47:08.0570 0x08bc  Detect skipped due to KSN trusted
12:47:08.0570 0x08bc  FontCache - ok
12:47:08.0677 0x08bc  [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
12:47:08.0702 0x08bc  FontCache3.0.0.0 - ok
12:47:08.0851 0x08bc  [ C96C52D0D80666AF585516FFA97B7C00, 3DD41D59AF28433D419C91DB1DE54C9758C9318A9F1415C3DF8DAE45ADCC999E ] ForceWare Intelligent Application Manager (IAM) C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
12:47:08.0924 0x08bc  ForceWare Intelligent Application Manager (IAM) - ok
12:47:09.0102 0x08bc  [ F9F089ABDC10CED295BC05E7D1779D98, A2DBC93DCD2EE7D17A72B5D7068D8C00D780F377FD63D1DAD9653135BC64628A ] FreeOTFE        C:\Windows\System32\FreeOTFE.sys
12:47:09.0124 0x08bc  FreeOTFE - detected UnsignedFile.Multi.Generic ( 1 )
12:47:11.0610 0x08bc  FreeOTFE ( UnsignedFile.Multi.Generic ) - warning
12:47:14.0147 0x08bc  [ D74BA750BD14438F92C38605C6F7FDBD, 9A2A97DEB18B625583D40AD0D7E0001229747D1872774F561E8F9DAB46CF28C1 ] FreeOTFECypherAES_Gladman C:\Windows\System32\FreeOTFECypherAES_Gladman.sys
12:47:14.0178 0x08bc  FreeOTFECypherAES_Gladman - detected UnsignedFile.Multi.Generic ( 1 )
12:47:24.0178 0x08bc  FreeOTFECypherAES_Gladman ( UnsignedFile.Multi.Generic ) - warning
12:47:24.0178 0x08bc  Force sending object to P2P due to detect: FreeOTFECypherAES_Gladman
12:47:27.0895 0x08bc  Object send P2P result: true
12:47:30.0411 0x08bc  [ 83D8CEB38406565248AD4D974C77A051, 6B906E20DD237CAAA27EB793F837614D7BE9FB10515C2B164B86B2EBB2A1A636 ] FreeOTFECypherAES_ltc C:\Windows\System32\FreeOTFECypherAES_ltc.sys
12:47:30.0425 0x08bc  FreeOTFECypherAES_ltc - detected UnsignedFile.Multi.Generic ( 1 )
12:47:33.0052 0x08bc  FreeOTFECypherAES_ltc ( UnsignedFile.Multi.Generic ) - warning
12:47:33.0052 0x08bc  Force sending object to P2P due to detect: FreeOTFECypherAES_ltc
12:47:35.0738 0x08bc  Object send P2P result: true
12:47:38.0247 0x08bc  [ C2D17B3CD673DA94C3BB35EFADF6F201, CA476CF331E93DD28E5827ED00CD6F46F33F6A4A4E19BB9EB5F258465AFA4D23 ] FreeOTFECypherBlowfish C:\Windows\System32\FreeOTFECypherBlowfish.sys
12:47:38.0259 0x08bc  FreeOTFECypherBlowfish - detected UnsignedFile.Multi.Generic ( 1 )
12:47:40.0999 0x08bc  FreeOTFECypherBlowfish ( UnsignedFile.Multi.Generic ) - warning
12:47:43.0488 0x08bc  [ D2D61587BB4F02E728423111691A5139, 1956505509BDDF1D44B36DC9C5AE4F58C668149C9FEEF7115C36F9C75D7BDB5C ] FreeOTFECypherCAST5 C:\Windows\System32\FreeOTFECypherCAST5.sys
12:47:43.0502 0x08bc  FreeOTFECypherCAST5 - detected UnsignedFile.Multi.Generic ( 1 )
12:47:45.0942 0x08bc  FreeOTFECypherCAST5 ( UnsignedFile.Multi.Generic ) - warning
12:47:48.0461 0x08bc  [ C3ABBDAB78F94653D7C88E7594090E1C, F01117F45EAB27AE2408374D1BB22B93CEA093D42D88C703DDA45ED2E66D099D ] FreeOTFECypherCAST6_Gladman C:\Windows\System32\FreeOTFECypherCAST6_Gladman.sys
12:47:48.0475 0x08bc  FreeOTFECypherCAST6_Gladman - detected UnsignedFile.Multi.Generic ( 1 )
12:47:50.0917 0x08bc  FreeOTFECypherCAST6_Gladman ( UnsignedFile.Multi.Generic ) - warning
12:47:53.0441 0x08bc  [ 53753A3EF11E892F001E4DEA74BF556F, 58AC436EE4FD4BC2829946A5CE2EAD731847D9A8F0B7B406890B83983BA45B3D ] FreeOTFECypherDES C:\Windows\System32\FreeOTFECypherDES.sys
12:47:53.0455 0x08bc  FreeOTFECypherDES - detected UnsignedFile.Multi.Generic ( 1 )
12:47:55.0896 0x08bc  FreeOTFECypherDES ( UnsignedFile.Multi.Generic ) - warning
12:47:55.0896 0x08bc  Force sending object to P2P due to detect: FreeOTFECypherDES
12:47:58.0574 0x08bc  Object send P2P result: true
12:48:01.0082 0x08bc  [ 796E664402C3F6B95419804E9E292699, 836DCDC483FE1275431C38817872B6A304D98E207EACA4A5B085E92BB312607A ] FreeOTFECypherMARS_Gladman C:\Windows\System32\FreeOTFECypherMARS_Gladman.sys
12:48:01.0095 0x08bc  FreeOTFECypherMARS_Gladman - detected UnsignedFile.Multi.Generic ( 1 )
12:48:03.0525 0x08bc  FreeOTFECypherMARS_Gladman ( UnsignedFile.Multi.Generic ) - warning
12:48:03.0525 0x08bc  Force sending object to P2P due to detect: FreeOTFECypherMARS_Gladman
12:48:06.0191 0x08bc  Object send P2P result: true
12:48:08.0673 0x08bc  [ D91BD70DF21A2FC9AD86D94CCF7B97D0, F27FA21AA1A2FBD8154FE09889AB834E2DCDE14A3CF4774AA520D96196063A09 ] FreeOTFECypherRC6_ltc C:\Windows\System32\FreeOTFECypherRC6_ltc.sys
12:48:08.0685 0x08bc  FreeOTFECypherRC6_ltc - detected UnsignedFile.Multi.Generic ( 1 )
12:48:11.0121 0x08bc  FreeOTFECypherRC6_ltc ( UnsignedFile.Multi.Generic ) - warning
12:48:13.0620 0x08bc  [ F9FFB8F8E4BBE1CE7DF65884B9B80AA9, EAA98F8F61681082080422BA80A9FA524D1B21A30BA3277452A4B45A81DEEE19 ] FreeOTFECypherSerpent_Gladman C:\Windows\System32\FreeOTFECypherSerpent_Gladman.sys
12:48:13.0634 0x08bc  FreeOTFECypherSerpent_Gladman - detected UnsignedFile.Multi.Generic ( 1 )
12:48:16.0062 0x08bc  FreeOTFECypherSerpent_Gladman ( UnsignedFile.Multi.Generic ) - warning
12:48:18.0564 0x08bc  [ 7194E78D7B96BA3E3F08361DA7A0F3CE, D31B36F264749664B95FEE3D76717FAC549F12A422F9C4D322F5F5B5C0DC1E3D ] FreeOTFECypherTwofish_ltc C:\Windows\System32\FreeOTFECypherTwofish_ltc.sys
12:48:18.0578 0x08bc  FreeOTFECypherTwofish_ltc - detected UnsignedFile.Multi.Generic ( 1 )
12:48:21.0239 0x08bc  FreeOTFECypherTwofish_ltc ( UnsignedFile.Multi.Generic ) - warning
12:48:23.0760 0x08bc  [ 91B27E7E1DECDAA83DAE79BA49A99649, 0CB4983672C33739EA641F7016D87CCB5E1D2309C848ACADAD3A91A81E224BF7 ] FreeOTFEHashMD  C:\Windows\System32\FreeOTFEHashMD.sys
12:48:23.0773 0x08bc  FreeOTFEHashMD - detected UnsignedFile.Multi.Generic ( 1 )
12:48:26.0376 0x08bc  FreeOTFEHashMD ( UnsignedFile.Multi.Generic ) - warning
12:48:26.0376 0x08bc  Force sending object to P2P due to detect: FreeOTFEHashMD
12:48:40.0049 0x08bc  Object send P2P result: true
12:48:42.0566 0x08bc  [ 2F6B9FA4EB4E53720484E6FD4D8D6F8F, 89A57776040F22675F0B1A214A2EBC3988A972E329E68B7D3A4FA6337E9E239E ] FreeOTFEHashRIPEMD C:\Windows\System32\FreeOTFEHashRIPEMD.sys
12:48:42.0580 0x08bc  FreeOTFEHashRIPEMD - detected UnsignedFile.Multi.Generic ( 1 )
12:48:45.0240 0x08bc  FreeOTFEHashRIPEMD ( UnsignedFile.Multi.Generic ) - warning
12:48:47.0759 0x08bc  [ 0D872DAA85AAD172223B2EF8FAF09A7C, B466EB941EE1CF3E66297E252760568EE6B9942780B14B9CDE221EDDD378E28A ] FreeOTFEHashSHA C:\Windows\System32\FreeOTFEHashSHA.sys
12:48:47.0772 0x08bc  FreeOTFEHashSHA - detected UnsignedFile.Multi.Generic ( 1 )
12:48:50.0195 0x08bc  FreeOTFEHashSHA ( UnsignedFile.Multi.Generic ) - warning
12:48:52.0729 0x08bc  [ E13238B84D76FF9FB1835588C863B64D, F3FEA2FE218ADDA78E894C2DF7527345BA28CB9A342D18BFD89AFECA9EA15B93 ] FreeOTFEHashTiger C:\Windows\System32\FreeOTFEHashTiger.sys
12:48:52.0742 0x08bc  FreeOTFEHashTiger - detected UnsignedFile.Multi.Generic ( 1 )
12:48:55.0164 0x08bc  FreeOTFEHashTiger ( UnsignedFile.Multi.Generic ) - warning
12:48:57.0675 0x08bc  [ 1F601BF0B40BC10BAE69E676DC54B0EC, C9FF25457E89D2D74425A9481BE1656A5B46A7AA16F2999A8651072B7E742FF7 ] FreeOTFEHashWhirlpool C:\Windows\System32\FreeOTFEHashWhirlpool.sys
12:48:57.0688 0x08bc  FreeOTFEHashWhirlpool - detected UnsignedFile.Multi.Generic ( 1 )
12:49:00.0120 0x08bc  FreeOTFEHashWhirlpool ( UnsignedFile.Multi.Generic ) - warning
12:49:02.0625 0x08bc  [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends       C:\Windows\system32\drivers\FsDepends.sys
12:49:02.0642 0x08bc  FsDepends - ok
12:49:02.0680 0x08bc  [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec          C:\Windows\system32\drivers\Fs_Rec.sys
12:49:02.0696 0x08bc  Fs_Rec - ok
12:49:02.0748 0x08bc  [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol          C:\Windows\system32\DRIVERS\fvevol.sys
12:49:02.0775 0x08bc  fvevol - ok
12:49:02.0814 0x08bc  [ B69CC457199BEE996B8EDDB6830CD638, 8C4D07B7F6958420728F43959E775ACF8E0B0BD9ECF1DA723DD2A9A09AD4C783 ] G311N6          C:\Windows\system32\DRIVERS\G311N6.sys
12:49:02.0847 0x08bc  G311N6 - detected UnsignedFile.Multi.Generic ( 1 )
12:49:05.0285 0x08bc  Detect skipped due to KSN trusted
12:49:05.0285 0x08bc  G311N6 - ok
12:49:05.0312 0x08bc  [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx        C:\Windows\system32\DRIVERS\gagp30kx.sys
12:49:05.0329 0x08bc  gagp30kx - ok
12:49:05.0387 0x08bc  [ 185ADA973B5020655CEE342059A86CBB, D3E352DFAF30761505480A4C557D980083F65EC5BD46E2656B2114D47B272A89 ] GEARAspiWDM     C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
12:49:05.0401 0x08bc  GEARAspiWDM - ok
12:49:05.0460 0x08bc  [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc           C:\Windows\System32\gpsvc.dll
12:49:05.0501 0x08bc  gpsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:49:07.0944 0x08bc  Detect skipped due to KSN trusted
12:49:07.0944 0x08bc  gpsvc - ok
12:49:07.0976 0x08bc  [ F172AD4E906D97ED8F071896FC6789DC, FC10B3CE3DB0D3BF84DFD28E900EB6A11EDAAE32AC50F23CB03AACC6AA496911 ] gupdate         C:\Program Files\Google\Update\GoogleUpdate.exe
12:49:07.0992 0x08bc  gupdate - ok
12:49:08.0007 0x08bc  [ F172AD4E906D97ED8F071896FC6789DC, FC10B3CE3DB0D3BF84DFD28E900EB6A11EDAAE32AC50F23CB03AACC6AA496911 ] gupdatem        C:\Program Files\Google\Update\GoogleUpdate.exe
12:49:08.0023 0x08bc  gupdatem - ok
12:49:08.0038 0x08bc  [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir        C:\Windows\system32\drivers\hcw85cir.sys
12:49:08.0048 0x08bc  hcw85cir - detected UnsignedFile.Multi.Generic ( 1 )
12:49:10.0483 0x08bc  Detect skipped due to KSN trusted
12:49:10.0483 0x08bc  hcw85cir - ok
12:49:10.0577 0x08bc  [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
12:49:10.0613 0x08bc  HdAudAddService - detected UnsignedFile.Multi.Generic ( 1 )
12:49:13.0046 0x08bc  Detect skipped due to KSN trusted
12:49:13.0046 0x08bc  HdAudAddService - ok
12:49:13.0075 0x08bc  [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus        C:\Windows\system32\drivers\HDAudBus.sys
12:49:13.0091 0x08bc  HDAudBus - detected UnsignedFile.Multi.Generic ( 1 )
12:49:15.0575 0x08bc  Detect skipped due to KSN trusted
12:49:15.0575 0x08bc  HDAudBus - ok
12:49:15.0599 0x08bc  [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt         C:\Windows\system32\DRIVERS\HidBatt.sys
12:49:15.0609 0x08bc  HidBatt - detected UnsignedFile.Multi.Generic ( 1 )
12:49:18.0276 0x08bc  Detect skipped due to KSN trusted
12:49:18.0276 0x08bc  HidBatt - ok
12:49:18.0292 0x08bc  [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth          C:\Windows\system32\DRIVERS\hidbth.sys
12:49:18.0303 0x08bc  HidBth - detected UnsignedFile.Multi.Generic ( 1 )
12:49:21.0057 0x08bc  Detect skipped due to KSN trusted
12:49:21.0057 0x08bc  HidBth - ok
12:49:21.0081 0x08bc  [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr           C:\Windows\system32\DRIVERS\hidir.sys
12:49:21.0091 0x08bc  HidIr - detected UnsignedFile.Multi.Generic ( 1 )
12:49:23.0769 0x08bc  Detect skipped due to KSN trusted
12:49:23.0769 0x08bc  HidIr - ok
12:49:23.0795 0x08bc  [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv         C:\Windows\system32\hidserv.dll
12:49:23.0806 0x08bc  hidserv - detected UnsignedFile.Multi.Generic ( 1 )
12:49:26.0242 0x08bc  Detect skipped due to KSN trusted
12:49:26.0242 0x08bc  hidserv - ok
12:49:26.0314 0x08bc  [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb          C:\Windows\system32\DRIVERS\hidusb.sys
12:49:26.0324 0x08bc  HidUsb - detected UnsignedFile.Multi.Generic ( 1 )
12:49:28.0988 0x08bc  Detect skipped due to KSN trusted
12:49:28.0988 0x08bc  HidUsb - ok
12:49:29.0019 0x08bc  [ DCBF0A04840DD09C6EA7D63F358CE251, 4273AD6437BE14A2AC908F5BA9F793B720C7DF53A8EC6860EB65BC98C25E4FBE ] HitmanProScheduler C:\Program Files\HitmanPro\hmpsched.exe
12:49:29.0035 0x08bc  HitmanProScheduler - ok
12:49:29.0080 0x08bc  [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc          C:\Windows\system32\kmsvc.dll
12:49:29.0092 0x08bc  hkmsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:49:31.0532 0x08bc  Detect skipped due to KSN trusted
12:49:31.0532 0x08bc  hkmsvc - ok
12:49:31.0596 0x08bc  [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
12:49:31.0623 0x08bc  HomeGroupListener - detected UnsignedFile.Multi.Generic ( 1 )
12:49:34.0311 0x08bc  Detect skipped due to KSN trusted
12:49:34.0311 0x08bc  HomeGroupListener - ok
12:49:34.0358 0x08bc  [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
12:49:34.0385 0x08bc  HomeGroupProvider - detected UnsignedFile.Multi.Generic ( 1 )
12:49:36.0993 0x08bc  Detect skipped due to KSN trusted
12:49:36.0994 0x08bc  HomeGroupProvider - ok
12:49:37.0054 0x08bc  [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD          C:\Windows\system32\drivers\HpSAMD.sys
12:49:37.0071 0x08bc  HpSAMD - ok
12:49:37.0133 0x08bc  [ 871917B07A141BFF43D76D8844D48106, 30C702008D0EE57D63F74864967DD19A55A268E77E42B5B3CC73037AD51D2987 ] HTTP            C:\Windows\system32\drivers\HTTP.sys
12:49:37.0163 0x08bc  HTTP - detected UnsignedFile.Multi.Generic ( 1 )
12:49:39.0780 0x08bc  Detect skipped due to KSN trusted
12:49:39.0780 0x08bc  HTTP - ok
12:49:39.0808 0x08bc  [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy        C:\Windows\system32\drivers\hwpolicy.sys
12:49:39.0823 0x08bc  hwpolicy - ok
12:49:39.0871 0x08bc  [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt        C:\Windows\system32\drivers\i8042prt.sys
12:49:39.0882 0x08bc  i8042prt - detected UnsignedFile.Multi.Generic ( 1 )
12:49:49.0882 0x08bc  Object is SCO, delete is not allowed
12:49:49.0882 0x08bc  i8042prt ( UnsignedFile.Multi.Generic ) - warning
12:49:52.0810 0x08bc  [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV         C:\Windows\system32\drivers\iaStorV.sys
12:49:52.0843 0x08bc  iaStorV - ok
12:49:52.0933 0x08bc  [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc           C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
12:49:53.0003 0x08bc  idsvc - ok
12:49:53.0033 0x08bc  IEEtwCollectorService - ok
12:49:53.0055 0x08bc  [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp           C:\Windows\system32\DRIVERS\iirsp.sys
12:49:53.0071 0x08bc  iirsp - ok
12:49:53.0133 0x08bc  [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT          C:\Windows\System32\ikeext.dll
12:49:53.0174 0x08bc  IKEEXT - detected UnsignedFile.Multi.Generic ( 1 )
12:49:55.0843 0x08bc  Detect skipped due to KSN trusted
12:49:55.0843 0x08bc  IKEEXT - ok
12:49:55.0872 0x08bc  [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide        C:\Windows\system32\drivers\intelide.sys
12:49:55.0887 0x08bc  intelide - ok
12:49:55.0905 0x08bc  [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm        C:\Windows\system32\DRIVERS\intelppm.sys
12:49:55.0916 0x08bc  intelppm - detected UnsignedFile.Multi.Generic ( 1 )
12:49:58.0529 0x08bc  Detect skipped due to KSN trusted
12:49:58.0529 0x08bc  intelppm - ok
12:49:58.0553 0x08bc  [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum       C:\Windows\system32\ipbusenum.dll
12:49:58.0566 0x08bc  IPBusEnum - detected UnsignedFile.Multi.Generic ( 1 )
12:50:01.0181 0x08bc  Detect skipped due to KSN trusted
12:50:01.0181 0x08bc  IPBusEnum - ok
12:50:01.0203 0x08bc  [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver  C:\Windows\system32\DRIVERS\ipfltdrv.sys
12:50:01.0213 0x08bc  IpFilterDriver - detected UnsignedFile.Multi.Generic ( 1 )
12:50:03.0652 0x08bc  Detect skipped due to KSN trusted
12:50:03.0652 0x08bc  IpFilterDriver - ok
12:50:03.0708 0x08bc  [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc        C:\Windows\System32\iphlpsvc.dll
12:50:03.0747 0x08bc  iphlpsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:50:06.0361 0x08bc  Detect skipped due to KSN trusted
12:50:06.0362 0x08bc  iphlpsvc - ok
12:50:06.0409 0x08bc  [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV         C:\Windows\system32\drivers\IPMIDrv.sys
12:50:06.0420 0x08bc  IPMIDRV - detected UnsignedFile.Multi.Generic ( 1 )
12:50:08.0859 0x08bc  Detect skipped due to KSN trusted
12:50:08.0859 0x08bc  IPMIDRV - ok
12:50:08.0885 0x08bc  [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT           C:\Windows\system32\drivers\ipnat.sys
12:50:08.0897 0x08bc  IPNAT - detected UnsignedFile.Multi.Generic ( 1 )
12:50:11.0508 0x08bc  Detect skipped due to KSN trusted
12:50:11.0508 0x08bc  IPNAT - ok
12:50:11.0569 0x08bc  [ 4D800977F7EB0C310AF04BF5B517985A, DD4EC347D4759AC401BD08739DE012E5F1903DF2EDEBEA17CCD3C19FF1F6005E ] iPod Service    C:\Program Files\iPod\bin\iPodService.exe
12:50:11.0596 0x08bc  iPod Service - ok
12:50:11.0613 0x08bc  [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM          C:\Windows\system32\drivers\irenum.sys
12:50:11.0622 0x08bc  IRENUM - detected UnsignedFile.Multi.Generic ( 1 )
12:50:14.0230 0x08bc  Detect skipped due to KSN trusted
12:50:14.0230 0x08bc  IRENUM - ok
12:50:14.0241 0x08bc  [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp          C:\Windows\system32\drivers\isapnp.sys
12:50:14.0257 0x08bc  isapnp - ok
12:50:14.0276 0x08bc  [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt        C:\Windows\system32\drivers\msiscsi.sys
12:50:14.0308 0x08bc  iScsiPrt - ok
12:50:14.0320 0x08bc  [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass        C:\Windows\system32\DRIVERS\kbdclass.sys
12:50:14.0337 0x08bc  kbdclass - ok
12:50:14.0382 0x08bc  [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid          C:\Windows\system32\DRIVERS\kbdhid.sys
12:50:14.0392 0x08bc  kbdhid - detected UnsignedFile.Multi.Generic ( 1 )
12:50:16.0822 0x08bc  Detect skipped due to KSN trusted
12:50:16.0822 0x08bc  kbdhid - ok
12:50:16.0840 0x08bc  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] KeyIso          C:\Windows\system32\lsass.exe
12:50:16.0851 0x08bc  KeyIso - detected UnsignedFile.Multi.Generic ( 1 )
12:50:16.0851 0x08bc  Detect skipped due to KSN trusted
12:50:16.0851 0x08bc  KeyIso - ok
12:50:16.0872 0x08bc  [ D9CA77A69473A93E40B7551A7DE425A9, 15733F12EC5AE8675CAFA79653AFDE4F52D1886A516FCB9BB9B20179E676282F ] KeyScrambler    C:\Windows\system32\drivers\keyscrambler.sys
12:50:16.0896 0x08bc  KeyScrambler - ok
12:50:16.0997 0x08bc  [ 7BE497351A3D45BA9AB95DCCC5189341, 85890466B3D943531091AF58E83A28BDE422854BFA513C657053D245D3921A7E ] ksaud           C:\Windows\system32\drivers\ksaud.sys
12:50:17.0087 0x08bc  ksaud - detected UnsignedFile.Multi.Generic ( 1 )
12:50:24.0652 0x08bc  Detect skipped due to KSN trusted
12:50:24.0652 0x08bc  ksaud - ok
12:50:24.0666 0x08bc  [ 4120DA10AA42A9996F4575DB9E3E6E6E, 1C6E790772EA327ACB885D731A030408160534997DD56FEE4D6CEE6929873BB8 ] KSecDD          C:\Windows\system32\Drivers\ksecdd.sys
12:50:24.0683 0x08bc  KSecDD - ok
12:50:24.0713 0x08bc  [ 1E1845606C5A4579F7F3D95796CC1ED1, 26A478A0B5417CBC880A7F2D977AAC5FBF40EC4296426B757D6ACCBBC09486CC ] KSecPkg         C:\Windows\system32\Drivers\ksecpkg.sys
12:50:24.0733 0x08bc  KSecPkg - ok
12:50:24.0771 0x08bc  [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm           C:\Windows\system32\msdtckrm.dll
12:50:24.0799 0x08bc  KtmRm - detected UnsignedFile.Multi.Generic ( 1 )
12:50:27.0238 0x08bc  Detect skipped due to KSN trusted
12:50:27.0238 0x08bc  KtmRm - ok
12:50:27.0287 0x08bc  [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer    C:\Windows\system32\srvsvc.dll
12:50:27.0313 0x08bc  LanmanServer - detected UnsignedFile.Multi.Generic ( 1 )
12:50:29.0985 0x08bc  Detect skipped due to KSN trusted
12:50:29.0985 0x08bc  LanmanServer - ok
12:50:30.0024 0x08bc  [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
12:50:30.0038 0x08bc  LanmanWorkstation - detected UnsignedFile.Multi.Generic ( 1 )
12:50:32.0786 0x08bc  Detect skipped due to KSN trusted
12:50:32.0786 0x08bc  LanmanWorkstation - ok
12:50:32.0816 0x08bc  [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio          C:\Windows\system32\DRIVERS\lltdio.sys
12:50:32.0826 0x08bc  lltdio - detected UnsignedFile.Multi.Generic ( 1 )
12:50:35.0421 0x08bc  Detect skipped due to KSN trusted
12:50:35.0421 0x08bc  lltdio - ok
12:50:35.0447 0x08bc  [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc         C:\Windows\System32\lltdsvc.dll
12:50:35.0474 0x08bc  lltdsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:50:38.0070 0x08bc  Detect skipped due to KSN trusted
12:50:38.0070 0x08bc  lltdsvc - ok
12:50:38.0095 0x08bc  [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts         C:\Windows\System32\lmhsvc.dll
12:50:38.0106 0x08bc  lmhosts - detected UnsignedFile.Multi.Generic ( 1 )
12:50:40.0841 0x08bc  Detect skipped due to KSN trusted
12:50:40.0841 0x08bc  lmhosts - ok
12:50:40.0853 0x08bc  [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC          C:\Windows\system32\DRIVERS\lsi_fc.sys
12:50:40.0871 0x08bc  LSI_FC - ok
12:50:40.0879 0x08bc  [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS         C:\Windows\system32\DRIVERS\lsi_sas.sys
12:50:40.0897 0x08bc  LSI_SAS - ok
12:50:40.0903 0x08bc  [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2        C:\Windows\system32\DRIVERS\lsi_sas2.sys
12:50:40.0921 0x08bc  LSI_SAS2 - ok
12:50:40.0929 0x08bc  [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI        C:\Windows\system32\DRIVERS\lsi_scsi.sys
12:50:40.0947 0x08bc  LSI_SCSI - ok
12:50:40.0954 0x08bc  [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv           C:\Windows\system32\drivers\luafv.sys
12:50:40.0966 0x08bc  luafv - detected UnsignedFile.Multi.Generic ( 1 )
12:50:43.0654 0x08bc  Detect skipped due to KSN trusted
12:50:43.0654 0x08bc  luafv - ok
12:50:43.0717 0x08bc  [ A3F4391DFDF2F9E9FE4EAD193265A5AD, A60A1A345622F4758181FB0B6EE784B0B718105FEE7B0F6FEDE5AD59FE448EE1 ] MBAMProtector   C:\Windows\system32\drivers\mbam.sys
12:50:43.0732 0x08bc  MBAMProtector - ok
12:50:43.0819 0x08bc  [ 0BB29DE40C9D9529793DCDB59A43CF5B, 251001A407D32EF22F64915EEFFAAEC229073C4549BF7D9D1D4209B7D15B4681 ] MBAMScheduler   C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
12:50:43.0908 0x08bc  MBAMScheduler - ok
12:50:43.0981 0x08bc  [ 5F82D8188B370B0CF185D4AE2B9B4A0E, 549B53DD989A069E1C38347C4CEF5283DF9B428CE102799B06A20D3D8F23825F ] MBAMService     C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
12:50:44.0032 0x08bc  MBAMService - ok
12:50:44.0050 0x08bc  [ 312CD3307F600E7CD340B79B3DCB3A01, 861A6DFC53C69743129DAAFE73DECDE8D842475503E8D713E7CE5D22AC8D1370 ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
12:50:44.0065 0x08bc  MBAMWebAccessControl - ok
12:50:44.0104 0x08bc  [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc         C:\Windows\system32\Mcx2Svc.dll
12:50:44.0117 0x08bc  Mcx2Svc - detected UnsignedFile.Multi.Generic ( 1 )
12:50:46.0786 0x08bc  Detect skipped due to KSN trusted
12:50:46.0786 0x08bc  Mcx2Svc - ok
12:50:46.0792 0x08bc  [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas         C:\Windows\system32\DRIVERS\megasas.sys
12:50:46.0808 0x08bc  megasas - ok
12:50:46.0826 0x08bc  [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR          C:\Windows\system32\DRIVERS\MegaSR.sys
12:50:46.0858 0x08bc  MegaSR - ok
12:50:46.0876 0x08bc  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS           C:\Windows\system32\mmcss.dll
12:50:46.0888 0x08bc  MMCSS - detected UnsignedFile.Multi.Generic ( 1 )
12:50:49.0487 0x08bc  Detect skipped due to KSN trusted
12:50:49.0487 0x08bc  MMCSS - ok
12:50:49.0503 0x08bc  [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem           C:\Windows\system32\drivers\modem.sys
12:50:49.0513 0x08bc  Modem - detected UnsignedFile.Multi.Generic ( 1 )
12:50:52.0120 0x08bc  Detect skipped due to KSN trusted
12:50:52.0120 0x08bc  Modem - ok
12:50:52.0147 0x08bc  [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor         C:\Windows\system32\DRIVERS\monitor.sys
12:50:52.0156 0x08bc  monitor - detected UnsignedFile.Multi.Generic ( 1 )
12:51:02.0156 0x08bc  Object is SCO, delete is not allowed
12:51:02.0156 0x08bc  monitor ( UnsignedFile.Multi.Generic ) - warning
12:51:06.0692 0x08bc  [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass        C:\Windows\system32\DRIVERS\mouclass.sys
12:51:06.0709 0x08bc  mouclass - ok
12:51:06.0715 0x08bc  [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid          C:\Windows\system32\DRIVERS\mouhid.sys
12:51:06.0725 0x08bc  mouhid - detected UnsignedFile.Multi.Generic ( 1 )
12:51:09.0342 0x08bc  Detect skipped due to KSN trusted
12:51:09.0342 0x08bc  mouhid - ok
12:51:09.0389 0x08bc  [ FC8771F45ECCCFD89684E38842539B9B, 806DDF2B4830CA866582FE74A521BB7DF26CA0E19013DAF584D3677FB48CC77A ] mountmgr        C:\Windows\system32\drivers\mountmgr.sys
12:51:09.0406 0x08bc  mountmgr - ok
12:51:09.0467 0x08bc  [ A08662124B1510709C4514E7333E27D8, 4ECF5200484A0412F1B9EEBA10D3E01F6610FA33C99140EB8F329CFDF812FD3B ] MozillaMaintenance C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
12:51:09.0487 0x08bc  MozillaMaintenance - ok
12:51:09.0501 0x08bc  [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio            C:\Windows\system32\drivers\mpio.sys
12:51:09.0521 0x08bc  mpio - ok
12:51:09.0535 0x08bc  [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv          C:\Windows\system32\drivers\mpsdrv.sys
12:51:09.0546 0x08bc  mpsdrv - detected UnsignedFile.Multi.Generic ( 1 )
12:51:12.0229 0x08bc  Detect skipped due to KSN trusted
12:51:12.0229 0x08bc  mpsdrv - ok
12:51:12.0294 0x08bc  [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc          C:\Windows\system32\mpssvc.dll
12:51:12.0334 0x08bc  MpsSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:51:15.0003 0x08bc  Detect skipped due to KSN trusted
12:51:15.0003 0x08bc  MpsSvc - ok
12:51:15.0050 0x08bc  [ 21F4B24ACFC79A483515BD986DD9043F, 22681907E02E0B723ABE2CEF0602D36C8EF862E7E2B62A9B40A5EF582E58D7BA ] MRxDAV          C:\Windows\system32\drivers\mrxdav.sys
12:51:15.0063 0x08bc  MRxDAV - detected UnsignedFile.Multi.Generic ( 1 )
12:51:17.0503 0x08bc  Detect skipped due to KSN trusted
12:51:17.0503 0x08bc  MRxDAV - ok
12:51:17.0555 0x08bc  [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb          C:\Windows\system32\DRIVERS\mrxsmb.sys
12:51:17.0569 0x08bc  mrxsmb - detected UnsignedFile.Multi.Generic ( 1 )
12:51:20.0241 0x08bc  Detect skipped due to KSN trusted
12:51:20.0241 0x08bc  mrxsmb - ok
12:51:20.0266 0x08bc  [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10        C:\Windows\system32\DRIVERS\mrxsmb10.sys
12:51:20.0292 0x08bc  mrxsmb10 - detected UnsignedFile.Multi.Generic ( 1 )
12:51:22.0955 0x08bc  Detect skipped due to KSN trusted
12:51:22.0955 0x08bc  mrxsmb10 - ok
12:51:22.0982 0x08bc  [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20        C:\Windows\system32\DRIVERS\mrxsmb20.sys
12:51:22.0994 0x08bc  mrxsmb20 - detected UnsignedFile.Multi.Generic ( 1 )
12:51:25.0672 0x08bc  Detect skipped due to KSN trusted
12:51:25.0672 0x08bc  mrxsmb20 - ok
12:51:25.0710 0x08bc  [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci          C:\Windows\system32\drivers\msahci.sys
12:51:25.0726 0x08bc  msahci - ok
12:51:25.0820 0x08bc  [ B03E3F64B70F8031E65EB26DA23DE91A, 73184B4A75C1EA5D10B9D78A9E705432551DE15231F10C5A31021896D0938D80 ] MSCamSvc        C:\Program Files\Microsoft LifeCam\MSCamS32.exe
12:51:25.0837 0x08bc  MSCamSvc - ok
12:51:25.0886 0x08bc  [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm           C:\Windows\system32\drivers\msdsm.sys
12:51:25.0927 0x08bc  msdsm - ok
12:51:25.0999 0x08bc  [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC           C:\Windows\System32\msdtc.exe
12:51:26.0037 0x08bc  MSDTC - detected UnsignedFile.Multi.Generic ( 1 )
12:51:28.0718 0x08bc  Detect skipped due to KSN trusted
12:51:28.0718 0x08bc  MSDTC - ok
12:51:28.0730 0x08bc  [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs            C:\Windows\system32\drivers\Msfs.sys
12:51:28.0740 0x08bc  Msfs - detected UnsignedFile.Multi.Generic ( 1 )
12:51:31.0183 0x08bc  Detect skipped due to KSN trusted
12:51:31.0183 0x08bc  Msfs - ok
12:51:31.0198 0x08bc  [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf       C:\Windows\System32\drivers\mshidkmdf.sys
12:51:31.0207 0x08bc  mshidkmdf - detected UnsignedFile.Multi.Generic ( 1 )
12:51:33.0867 0x08bc  Detect skipped due to KSN trusted
12:51:33.0867 0x08bc  mshidkmdf - ok
12:51:33.0898 0x08bc  [ 7A0F9CBDBDB135113B9A3C138E20C85D, 2AEC135A2108ED1708368ADD496FD373862C00532CB495A9A68D6C54A82975EE ] MSHUSBVideo     C:\Windows\system32\Drivers\nx6000.sys
12:51:33.0913 0x08bc  MSHUSBVideo - ok
12:51:33.0964 0x08bc  [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv        C:\Windows\system32\drivers\msisadrv.sys
12:51:33.0980 0x08bc  msisadrv - ok
12:51:34.0036 0x08bc  [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI         C:\Windows\system32\iscsiexe.dll
12:51:34.0050 0x08bc  MSiSCSI - detected UnsignedFile.Multi.Generic ( 1 )
12:51:36.0648 0x08bc  Detect skipped due to KSN trusted
12:51:36.0648 0x08bc  MSiSCSI - ok
12:51:36.0653 0x08bc  msiserver - ok
12:51:36.0682 0x08bc  [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV         C:\Windows\system32\drivers\MSKSSRV.sys
12:51:36.0691 0x08bc  MSKSSRV - detected UnsignedFile.Multi.Generic ( 1 )
12:51:39.0369 0x08bc  Detect skipped due to KSN trusted
12:51:39.0369 0x08bc  MSKSSRV - ok
12:51:39.0386 0x08bc  [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK        C:\Windows\system32\drivers\MSPCLOCK.sys
12:51:39.0395 0x08bc  MSPCLOCK - detected UnsignedFile.Multi.Generic ( 1 )
12:51:42.0140 0x08bc  Detect skipped due to KSN trusted
12:51:42.0140 0x08bc  MSPCLOCK - ok
12:51:42.0147 0x08bc  [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM           C:\Windows\system32\drivers\MSPQM.sys
12:51:42.0156 0x08bc  MSPQM - detected UnsignedFile.Multi.Generic ( 1 )
12:51:44.0587 0x08bc  Detect skipped due to KSN trusted
12:51:44.0587 0x08bc  MSPQM - ok
12:51:44.0597 0x08bc  [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC           C:\Windows\system32\drivers\MsRPC.sys
12:51:44.0618 0x08bc  MsRPC - ok
12:51:44.0663 0x08bc  [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios        C:\Windows\system32\drivers\mssmbios.sys
12:51:44.0679 0x08bc  mssmbios - ok
12:51:44.0692 0x08bc  [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE           C:\Windows\system32\drivers\MSTEE.sys
12:51:44.0701 0x08bc  MSTEE - detected UnsignedFile.Multi.Generic ( 1 )
12:51:47.0682 0x08bc  Detect skipped due to KSN trusted
12:51:47.0682 0x08bc  MSTEE - ok
12:51:47.0710 0x08bc  [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig        C:\Windows\system32\DRIVERS\MTConfig.sys
12:51:47.0719 0x08bc  MTConfig - detected UnsignedFile.Multi.Generic ( 1 )
12:51:50.0449 0x08bc  Detect skipped due to KSN trusted
12:51:50.0449 0x08bc  MTConfig - ok
12:51:50.0480 0x08bc  [ 0F24624106D8042E7F27882D9D6FF5C0, 2CD6E0962FB20EB8E1033CE1663FD223807BAE1FBE27D3AC9582FB765F2C70F0 ] MTsensor        C:\Windows\system32\DRIVERS\ASACPI.sys
12:51:50.0489 0x08bc  MTsensor - detected UnsignedFile.Multi.Generic ( 1 )
12:51:52.0911 0x08bc  Detect skipped due to KSN trusted
12:51:52.0911 0x08bc  MTsensor - ok
12:51:52.0918 0x08bc  [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup             C:\Windows\system32\Drivers\mup.sys
12:51:52.0935 0x08bc  Mup - ok
12:51:52.0978 0x08bc  [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent        C:\Windows\system32\qagentRT.dll
12:51:53.0007 0x08bc  napagent - detected UnsignedFile.Multi.Generic ( 1 )
12:51:55.0600 0x08bc  Detect skipped due to KSN trusted
12:51:55.0600 0x08bc  napagent - ok
12:51:55.0632 0x08bc  [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP     C:\Windows\system32\DRIVERS\nwifi.sys
12:51:55.0659 0x08bc  NativeWifiP - detected UnsignedFile.Multi.Generic ( 1 )
12:51:58.0082 0x08bc  Detect skipped due to KSN trusted
12:51:58.0082 0x08bc  NativeWifiP - ok
12:51:58.0161 0x08bc  [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS            C:\Windows\system32\drivers\ndis.sys
12:51:58.0205 0x08bc  NDIS - ok
12:51:58.0217 0x08bc  [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap         C:\Windows\system32\DRIVERS\ndiscap.sys
12:51:58.0227 0x08bc  NdisCap - detected UnsignedFile.Multi.Generic ( 1 )
12:52:00.0890 0x08bc  Detect skipped due to KSN trusted
12:52:00.0890 0x08bc  NdisCap - ok
12:52:00.0904 0x08bc  [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi        C:\Windows\system32\DRIVERS\ndistapi.sys
12:52:00.0915 0x08bc  NdisTapi - detected UnsignedFile.Multi.Generic ( 1 )
12:52:03.0652 0x08bc  Detect skipped due to KSN trusted
12:52:03.0652 0x08bc  NdisTapi - ok
12:52:03.0691 0x08bc  [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio         C:\Windows\system32\DRIVERS\ndisuio.sys
12:52:03.0701 0x08bc  Ndisuio - detected UnsignedFile.Multi.Generic ( 1 )
12:52:06.0333 0x08bc  Detect skipped due to KSN trusted
12:52:06.0333 0x08bc  Ndisuio - ok
12:52:06.0373 0x08bc  [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan         C:\Windows\system32\DRIVERS\ndiswan.sys
12:52:06.0386 0x08bc  NdisWan - detected UnsignedFile.Multi.Generic ( 1 )
12:52:16.0386 0x08bc  Object is SCO, delete is not allowed
12:52:16.0386 0x08bc  NdisWan ( UnsignedFile.Multi.Generic ) - warning
12:52:19.0938 0x08bc  [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy         C:\Windows\system32\drivers\NDProxy.sys
12:52:19.0948 0x08bc  NDProxy - detected UnsignedFile.Multi.Generic ( 1 )
12:52:22.0617 0x08bc  Detect skipped due to KSN trusted
12:52:22.0617 0x08bc  NDProxy - ok
12:52:22.0642 0x08bc  [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS         C:\Windows\system32\DRIVERS\netbios.sys
12:52:22.0652 0x08bc  NetBIOS - detected UnsignedFile.Multi.Generic ( 1 )
12:52:25.0321 0x08bc  Detect skipped due to KSN trusted
12:52:25.0321 0x08bc  NetBIOS - ok
12:52:25.0367 0x08bc  [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT           C:\Windows\system32\DRIVERS\netbt.sys
12:52:25.0382 0x08bc  NetBT - detected UnsignedFile.Multi.Generic ( 1 )
12:52:27.0981 0x08bc  Detect skipped due to KSN trusted
12:52:27.0981 0x08bc  NetBT - ok
12:52:28.0008 0x08bc  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] Netlogon        C:\Windows\system32\lsass.exe
12:52:28.0018 0x08bc  Netlogon - detected UnsignedFile.Multi.Generic ( 1 )
12:52:28.0018 0x08bc  Detect skipped due to KSN trusted
12:52:28.0018 0x08bc  Netlogon - ok
12:52:28.0099 0x08bc  [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman          C:\Windows\System32\netman.dll
12:52:28.0121 0x08bc  Netman - detected UnsignedFile.Multi.Generic ( 1 )
12:52:30.0732 0x08bc  Detect skipped due to KSN trusted
12:52:30.0732 0x08bc  Netman - ok
12:52:30.0835 0x08bc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
12:52:30.0883 0x08bc  NetMsmqActivator - ok
12:52:30.0891 0x08bc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
12:52:30.0920 0x08bc  NetPipeActivator - ok
12:52:30.0996 0x08bc  [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm        C:\Windows\System32\netprofm.dll
12:52:31.0030 0x08bc  netprofm - detected UnsignedFile.Multi.Generic ( 1 )
12:52:33.0466 0x08bc  Detect skipped due to KSN trusted
12:52:33.0466 0x08bc  netprofm - ok
12:52:33.0496 0x08bc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
12:52:33.0517 0x08bc  NetTcpActivator - ok
12:52:33.0548 0x08bc  [ 21318671BCAD3ACF16638F98D4D00973, CEA6E3B6BCB4B74A9ACACBEEA12EEA967BBC2240398E2EBC04D7910109CACA11 ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
12:52:33.0570 0x08bc  NetTcpPortSharing - ok
12:52:33.0601 0x08bc  [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960         C:\Windows\system32\DRIVERS\nfrd960.sys
12:52:33.0618 0x08bc  nfrd960 - ok
12:52:33.0669 0x08bc  [ 374071043F9E4231EE43BE2BB48DD36D, C4FA3FC40CC49DBBB91901D14210A55D3831FAC9F9B3FF45FCA7F5CF242C9E92 ] NlaSvc          C:\Windows\System32\nlasvc.dll
12:52:33.0694 0x08bc  NlaSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:52:36.0135 0x08bc  Detect skipped due to KSN trusted
12:52:36.0136 0x08bc  NlaSvc - ok
12:52:36.0151 0x08bc  [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs            C:\Windows\system32\drivers\Npfs.sys
12:52:36.0162 0x08bc  Npfs - detected UnsignedFile.Multi.Generic ( 1 )
12:52:38.0764 0x08bc  Detect skipped due to KSN trusted
12:52:38.0764 0x08bc  Npfs - ok
12:52:38.0782 0x08bc  [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi             C:\Windows\system32\nsisvc.dll
12:52:38.0792 0x08bc  nsi - detected UnsignedFile.Multi.Generic ( 1 )
12:52:41.0231 0x08bc  Detect skipped due to KSN trusted
12:52:41.0231 0x08bc  nsi - ok
12:52:41.0268 0x08bc  [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy        C:\Windows\system32\drivers\nsiproxy.sys
12:52:41.0277 0x08bc  nsiproxy - detected UnsignedFile.Multi.Generic ( 1 )
12:52:43.0889 0x08bc  Detect skipped due to KSN trusted
12:52:43.0889 0x08bc  nsiproxy - ok
12:52:43.0954 0x08bc  [ B6C48D01147EC020DE7F1856734127F8, D63C1B4A25BDE31F352999F13269A6F61890E0AFFB11D66CF92CA778FA3E6A6B ] nSvcIp          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
12:52:43.0973 0x08bc  nSvcIp - ok
12:52:44.0047 0x08bc  [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs            C:\Windows\system32\drivers\Ntfs.sys
12:52:44.0110 0x08bc  Ntfs - ok
12:52:44.0127 0x08bc  [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null            C:\Windows\system32\drivers\Null.sys
12:52:44.0136 0x08bc  Null - detected UnsignedFile.Multi.Generic ( 1 )
12:52:46.0755 0x08bc  Detect skipped due to KSN trusted
12:52:46.0755 0x08bc  Null - ok
12:52:46.0785 0x08bc  [ B5E37E31C053BC9950455A257526514B, 16E2880621F3AA12BDADE71CD7682CA79E2A199D3C9E3E5927C49DCEF0F6183B ] NVENETFD        C:\Windows\system32\DRIVERS\nvm62x32.sys
12:52:46.0813 0x08bc  NVENETFD - detected UnsignedFile.Multi.Generic ( 1 )
12:52:49.0253 0x08bc  Detect skipped due to KSN trusted
12:52:49.0253 0x08bc  NVENETFD - ok
12:52:49.0304 0x08bc  [ 9F8EE4948B7ADD9D12F778F61A2758A4, 9848C7D97AC000BF7A00BAE12593E48E14D36D7FFFCF25A163FAAB446691032F ] NVHDA           C:\Windows\system32\drivers\nvhda32v.sys
12:52:49.0324 0x08bc  NVHDA - ok
12:52:49.0710 0x08bc  [ 1E3D32DDBE6BBDC0843432BAD599069F, 908893652F953C01E3FFEA19E76154B6246277720B088A61086A9B336B3EC6AD ] nvlddmkm        C:\Windows\system32\DRIVERS\nvlddmkm.sys
12:52:50.0129 0x08bc  nvlddmkm - ok
12:52:50.0198 0x08bc  [ 1DE923088878B495CD4219E47BA34EB8, 68B8FF593E2972DC239BB9A9E2436A513DBDD16FAC071117AFD45285AD004EC1 ] NVNET           C:\Windows\system32\DRIVERS\nvmf6232.sys
12:52:50.0229 0x08bc  NVNET - ok
12:52:50.0314 0x08bc  [ D6310F79E51D1F997E964E81DD368AEA, 27D0159F45C712C6165FDB9F40823438225555E71BB01E3B55F5B5D7BE15D389 ] NvNetworkService C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
12:52:50.0395 0x08bc  NvNetworkService - ok
12:52:50.0447 0x08bc  [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid          C:\Windows\system32\drivers\nvraid.sys
12:52:50.0466 0x08bc  nvraid - ok
12:52:50.0517 0x08bc  [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor          C:\Windows\system32\drivers\nvstor.sys
12:52:50.0536 0x08bc  nvstor - ok
12:52:50.0579 0x08bc  [ 5004DAF6A37C5C73FFCF4D3935A6FE87, 52F2149383EC41B18310801FD07C1363EE81C5D1F2B0206460FC7922C00D7A15 ] nvsvc           C:\Windows\system32\nvvsvc.exe
12:52:50.0622 0x08bc  nvsvc - ok
12:52:50.0638 0x08bc  nvvad_WaveExtensible - ok
12:52:50.0656 0x08bc  [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp          C:\Windows\system32\drivers\nv_agp.sys
12:52:50.0675 0x08bc  nv_agp - ok
12:52:50.0718 0x08bc  [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394        C:\Windows\system32\drivers\ohci1394.sys
12:52:50.0729 0x08bc  ohci1394 - detected UnsignedFile.Multi.Generic ( 1 )
12:52:53.0404 0x08bc  Detect skipped due to KSN trusted
12:52:53.0404 0x08bc  ohci1394 - ok
12:52:53.0453 0x08bc  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc        C:\Windows\system32\pnrpsvc.dll
12:52:53.0481 0x08bc  p2pimsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:52:55.0910 0x08bc  Detect skipped due to KSN trusted
12:52:55.0910 0x08bc  p2pimsvc - ok
12:52:55.0953 0x08bc  [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc          C:\Windows\system32\p2psvc.dll
12:52:55.0981 0x08bc  p2psvc - detected UnsignedFile.Multi.Generic ( 1 )
12:52:58.0405 0x08bc  Detect skipped due to KSN trusted
12:52:58.0405 0x08bc  p2psvc - ok
12:52:58.0439 0x08bc  [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport         C:\Windows\system32\DRIVERS\parport.sys
12:52:58.0450 0x08bc  Parport - detected UnsignedFile.Multi.Generic ( 1 )
12:53:01.0123 0x08bc  Detect skipped due to KSN trusted
12:53:01.0123 0x08bc  Parport - ok
12:53:01.0160 0x08bc  [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr         C:\Windows\system32\drivers\partmgr.sys
12:53:01.0177 0x08bc  partmgr - ok
12:53:01.0191 0x08bc  [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm          C:\Windows\system32\DRIVERS\parvdm.sys
12:53:01.0200 0x08bc  Parvdm - detected UnsignedFile.Multi.Generic ( 1 )
12:53:03.0624 0x08bc  Detect skipped due to KSN trusted
12:53:03.0624 0x08bc  Parvdm - ok
12:53:03.0654 0x08bc  [ 358AB7956D3160000726574083DFC8A6, 6CAFD4D1B8AB8C1D167ADC018985DDAB5AC2CBFFB3434FE6390F14AF50C19025 ] PcaSvc          C:\Windows\System32\pcasvc.dll
12:53:03.0672 0x08bc  PcaSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:53:06.0460 0x08bc  Detect skipped due to KSN trusted
12:53:06.0460 0x08bc  PcaSvc - ok
12:53:06.0475 0x08bc  [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci             C:\Windows\system32\drivers\pci.sys
12:53:06.0495 0x08bc  pci - ok
12:53:06.0536 0x08bc  [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide          C:\Windows\system32\drivers\pciide.sys
12:53:06.0552 0x08bc  pciide - ok
12:53:06.0569 0x08bc  [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia          C:\Windows\system32\DRIVERS\pcmcia.sys
12:53:06.0592 0x08bc  pcmcia - ok
12:53:06.0603 0x08bc  [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw             C:\Windows\system32\drivers\pcw.sys
12:53:06.0619 0x08bc  pcw - ok
12:53:06.0654 0x08bc  [ 9E0104BA49F4E6973749A02BF41344ED, B32F39F38DB48D77FBA884DEE34112BAB81CCEF5DD2EAAA12D9589D73D2BB116 ] PEAUTH          C:\Windows\system32\drivers\peauth.sys
12:53:06.0685 0x08bc  PEAUTH - detected UnsignedFile.Multi.Generic ( 1 )
12:53:09.0612 0x08bc  Detect skipped due to KSN trusted
12:53:09.0612 0x08bc  PEAUTH - ok
12:53:09.0719 0x08bc  [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla             C:\Windows\system32\pla.dll
12:53:09.0803 0x08bc  pla - detected UnsignedFile.Multi.Generic ( 1 )
12:53:12.0245 0x08bc  Detect skipped due to KSN trusted
12:53:12.0245 0x08bc  pla - ok
12:53:12.0285 0x08bc  [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay        C:\Windows\system32\umpnpmgr.dll
12:53:12.0307 0x08bc  PlugPlay - detected UnsignedFile.Multi.Generic ( 1 )
12:53:14.0995 0x08bc  Detect skipped due to KSN trusted
12:53:14.0995 0x08bc  PlugPlay - ok
12:53:15.0030 0x08bc  [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg     C:\Windows\system32\pnrpauto.dll
12:53:15.0042 0x08bc  PNRPAutoReg - detected UnsignedFile.Multi.Generic ( 1 )
12:53:17.0713 0x08bc  Detect skipped due to KSN trusted
12:53:17.0713 0x08bc  PNRPAutoReg - ok
12:53:17.0726 0x08bc  [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc         C:\Windows\system32\pnrpsvc.dll
12:53:17.0745 0x08bc  PNRPsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:53:17.0745 0x08bc  Detect skipped due to KSN trusted
12:53:17.0745 0x08bc  PNRPsvc - ok
12:53:17.0786 0x08bc  [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent     C:\Windows\System32\ipsecsvc.dll
12:53:17.0814 0x08bc  PolicyAgent - detected UnsignedFile.Multi.Generic ( 1 )
12:53:20.0424 0x08bc  Detect skipped due to KSN trusted
12:53:20.0425 0x08bc  PolicyAgent - ok
12:53:20.0477 0x08bc  [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power           C:\Windows\system32\umpo.dll
12:53:20.0492 0x08bc  Power - detected UnsignedFile.Multi.Generic ( 1 )
12:53:30.0492 0x08bc  Power ( UnsignedFile.Multi.Generic ) - warning
12:53:30.0492 0x08bc  Force sending object to P2P due to detect: Power
12:53:35.0198 0x08bc  Object send P2P result: true
12:53:37.0725 0x08bc  [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport    C:\Windows\system32\DRIVERS\raspptp.sys
12:53:37.0736 0x08bc  PptpMiniport - detected UnsignedFile.Multi.Generic ( 1 )
12:53:40.0171 0x08bc  Detect skipped due to KSN trusted
12:53:40.0171 0x08bc  PptpMiniport - ok
12:53:40.0190 0x08bc  [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor       C:\Windows\system32\DRIVERS\processr.sys
12:53:40.0201 0x08bc  Processor - detected UnsignedFile.Multi.Generic ( 1 )
12:53:42.0863 0x08bc  Detect skipped due to KSN trusted
12:53:42.0864 0x08bc  Processor - ok
12:53:42.0916 0x08bc  [ CADEFAC453040E370A1BDFF3973BE00D, 2E3DD8DA702468D8AB0F3CE27188B1991D4CB015FB36BAE4C6E7996B61CF49B8 ] ProfSvc         C:\Windows\system32\profsvc.dll
12:53:42.0942 0x08bc  ProfSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:53:45.0366 0x08bc  Detect skipped due to KSN trusted
12:53:45.0366 0x08bc  ProfSvc - ok
12:53:45.0383 0x08bc  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] ProtectedStorage C:\Windows\system32\lsass.exe
12:53:45.0394 0x08bc  ProtectedStorage - detected UnsignedFile.Multi.Generic ( 1 )
12:53:45.0394 0x08bc  Detect skipped due to KSN trusted
12:53:45.0394 0x08bc  ProtectedStorage - ok
12:53:45.0414 0x08bc  [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched          C:\Windows\system32\DRIVERS\pacer.sys
12:53:45.0426 0x08bc  Psched - detected UnsignedFile.Multi.Generic ( 1 )
12:53:48.0023 0x08bc  Detect skipped due to KSN trusted
12:53:48.0023 0x08bc  Psched - ok
12:53:48.0093 0x08bc  [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300          C:\Windows\system32\DRIVERS\ql2300.sys
12:53:48.0165 0x08bc  ql2300 - ok
12:53:48.0179 0x08bc  [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx          C:\Windows\system32\DRIVERS\ql40xx.sys
12:53:48.0197 0x08bc  ql40xx - ok
12:53:48.0226 0x08bc  [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE           C:\Windows\system32\qwave.dll
12:53:48.0253 0x08bc  QWAVE - detected UnsignedFile.Multi.Generic ( 1 )
12:53:50.0922 0x08bc  Detect skipped due to KSN trusted
12:53:50.0922 0x08bc  QWAVE - ok
12:53:50.0929 0x08bc  [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv        C:\Windows\system32\drivers\qwavedrv.sys
12:53:50.0985 0x08bc  QWAVEdrv - detected UnsignedFile.Multi.Generic ( 1 )
12:53:53.0582 0x08bc  Detect skipped due to KSN trusted
12:53:53.0582 0x08bc  QWAVEdrv - ok
12:53:53.0594 0x08bc  [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd          C:\Windows\system32\DRIVERS\rasacd.sys
12:53:53.0603 0x08bc  RasAcd - detected UnsignedFile.Multi.Generic ( 1 )
12:53:56.0218 0x08bc  Detect skipped due to KSN trusted
12:53:56.0218 0x08bc  RasAcd - ok
12:53:56.0239 0x08bc  [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn     C:\Windows\system32\DRIVERS\AgileVpn.sys
12:53:56.0250 0x08bc  RasAgileVpn - detected UnsignedFile.Multi.Generic ( 1 )
12:53:58.0968 0x08bc  Detect skipped due to KSN trusted
12:53:58.0968 0x08bc  RasAgileVpn - ok
12:53:58.0996 0x08bc  [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto         C:\Windows\System32\rasauto.dll
12:53:59.0010 0x08bc  RasAuto - detected UnsignedFile.Multi.Generic ( 1 )
12:54:01.0432 0x08bc  Detect skipped due to KSN trusted
12:54:01.0432 0x08bc  RasAuto - ok
12:54:01.0448 0x08bc  [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp         C:\Windows\system32\DRIVERS\rasl2tp.sys
12:54:01.0459 0x08bc  Rasl2tp - detected UnsignedFile.Multi.Generic ( 1 )
12:54:04.0123 0x08bc  Detect skipped due to KSN trusted
12:54:04.0123 0x08bc  Rasl2tp - ok
12:54:04.0174 0x08bc  [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan          C:\Windows\System32\rasmans.dll
12:54:04.0202 0x08bc  RasMan - detected UnsignedFile.Multi.Generic ( 1 )
12:54:06.0625 0x08bc  Detect skipped due to KSN trusted
12:54:06.0625 0x08bc  RasMan - ok
12:54:06.0633 0x08bc  [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe        C:\Windows\system32\DRIVERS\raspppoe.sys
12:54:06.0645 0x08bc  RasPppoe - detected UnsignedFile.Multi.Generic ( 1 )
12:54:09.0327 0x08bc  Detect skipped due to KSN trusted
12:54:09.0327 0x08bc  RasPppoe - ok
12:54:09.0335 0x08bc  [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp         C:\Windows\system32\DRIVERS\rassstp.sys
12:54:09.0346 0x08bc  RasSstp - detected UnsignedFile.Multi.Generic ( 1 )
12:54:12.0014 0x08bc  Detect skipped due to KSN trusted
12:54:12.0014 0x08bc  RasSstp - ok
12:54:12.0055 0x08bc  [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss           C:\Windows\system32\DRIVERS\rdbss.sys
12:54:12.0082 0x08bc  rdbss - detected UnsignedFile.Multi.Generic ( 1 )
12:54:14.0679 0x08bc  Detect skipped due to KSN trusted
12:54:14.0679 0x08bc  rdbss - ok
12:54:14.0695 0x08bc  [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus          C:\Windows\system32\DRIVERS\rdpbus.sys
12:54:14.0704 0x08bc  rdpbus - detected UnsignedFile.Multi.Generic ( 1 )
12:54:17.0303 0x08bc  Detect skipped due to KSN trusted
12:54:17.0303 0x08bc  rdpbus - ok
12:54:17.0343 0x08bc  [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD          C:\Windows\system32\DRIVERS\RDPCDD.sys
12:54:17.0351 0x08bc  RDPCDD - detected UnsignedFile.Multi.Generic ( 1 )
12:54:19.0781 0x08bc  Detect skipped due to KSN trusted
12:54:19.0781 0x08bc  RDPCDD - ok
12:54:19.0800 0x08bc  [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD        C:\Windows\system32\drivers\rdpencdd.sys
12:54:19.0809 0x08bc  RDPENCDD - detected UnsignedFile.Multi.Generic ( 1 )
12:54:22.0234 0x08bc  Detect skipped due to KSN trusted
12:54:22.0234 0x08bc  RDPENCDD - ok
12:54:22.0250 0x08bc  [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP        C:\Windows\system32\drivers\rdprefmp.sys
12:54:22.0260 0x08bc  RDPREFMP - detected UnsignedFile.Multi.Generic ( 1 )
12:54:24.0700 0x08bc  Detect skipped due to KSN trusted
12:54:24.0700 0x08bc  RDPREFMP - ok
12:54:24.0755 0x08bc  [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
12:54:24.0765 0x08bc  RdpVideoMiniport - detected UnsignedFile.Multi.Generic ( 1 )
12:54:27.0437 0x08bc  Detect skipped due to KSN trusted
12:54:27.0437 0x08bc  RdpVideoMiniport - ok
12:54:27.0486 0x08bc  [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD           C:\Windows\system32\drivers\RDPWD.sys
12:54:27.0502 0x08bc  RDPWD - detected UnsignedFile.Multi.Generic ( 1 )
12:54:29.0933 0x08bc  Detect skipped due to KSN trusted
12:54:29.0933 0x08bc  RDPWD - ok
12:54:29.0997 0x08bc  [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost        C:\Windows\system32\drivers\rdyboost.sys
12:54:30.0029 0x08bc  rdyboost - ok
12:54:30.0061 0x08bc  [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess    C:\Windows\System32\mprdim.dll
12:54:30.0074 0x08bc  RemoteAccess - detected UnsignedFile.Multi.Generic ( 1 )
12:54:32.0685 0x08bc  Detect skipped due to KSN trusted
12:54:32.0685 0x08bc  RemoteAccess - ok
12:54:32.0701 0x08bc  [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry  C:\Windows\system32\regsvc.dll
12:54:32.0716 0x08bc  RemoteRegistry - detected UnsignedFile.Multi.Generic ( 1 )
12:54:35.0149 0x08bc  Detect skipped due to KSN trusted
12:54:35.0149 0x08bc  RemoteRegistry - ok
12:54:35.0166 0x08bc  [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper    C:\Windows\System32\RpcEpMap.dll
12:54:35.0178 0x08bc  RpcEptMapper - detected UnsignedFile.Multi.Generic ( 1 )
12:54:45.0178 0x08bc  RpcEptMapper ( UnsignedFile.Multi.Generic ) - warning
12:54:48.0331 0x08bc  [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator      C:\Windows\system32\locator.exe
12:54:48.0341 0x08bc  RpcLocator - detected UnsignedFile.Multi.Generic ( 1 )
12:54:50.0775 0x08bc  Detect skipped due to KSN trusted
12:54:50.0775 0x08bc  RpcLocator - ok
12:54:50.0796 0x08bc  [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs           C:\Windows\system32\rpcss.dll
12:54:50.0819 0x08bc  RpcSs - detected UnsignedFile.Multi.Generic ( 1 )
12:54:50.0819 0x08bc  Detect skipped due to KSN trusted
12:54:50.0819 0x08bc  RpcSs - ok
12:54:50.0851 0x08bc  [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr          C:\Windows\system32\DRIVERS\rspndr.sys
12:54:50.0862 0x08bc  rspndr - detected UnsignedFile.Multi.Generic ( 1 )
12:54:53.0457 0x08bc  Detect skipped due to KSN trusted
12:54:53.0457 0x08bc  rspndr - ok
12:54:53.0501 0x08bc  [ 5283B9A27FF230F2FF70D92451FF409A, B8BAC70E1DE4485C79CA7B47D4DCFE0223CECEA8ED75CE4F128D47051F95FE5D ] RTL8167         C:\Windows\system32\DRIVERS\Rt86win7.sys
12:54:53.0535 0x08bc  RTL8167 - ok
12:54:53.0551 0x08bc  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] SamSs           C:\Windows\system32\lsass.exe
12:54:53.0561 0x08bc  SamSs - detected UnsignedFile.Multi.Generic ( 1 )
12:54:53.0561 0x08bc  Detect skipped due to KSN trusted
12:54:53.0561 0x08bc  SamSs - ok
12:54:53.0631 0x08bc  [ 39763504067962108505BFF25F024345, 73C9710B61EDC7FBEDE1D7A767AA3D3A169E7AD012494D05CB5EE7E5C5752BB9 ] SASDIFSV        C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS
12:54:53.0644 0x08bc  SASDIFSV - ok
12:54:53.0657 0x08bc  [ 77B9FC20084B48408AD3E87570EB4A85, B5BC5FEC1356DECB66A7A671DB67112BDAC8F942BF1C4B986B1805B41EF362B1 ] SASKUTIL        C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS
12:54:53.0671 0x08bc  SASKUTIL - ok
12:54:53.0691 0x08bc  [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port        C:\Windows\system32\drivers\sbp2port.sys
12:54:53.0709 0x08bc  sbp2port - ok
12:54:53.0728 0x08bc  [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr        C:\Windows\System32\SCardSvr.dll
12:54:53.0746 0x08bc  SCardSvr - detected UnsignedFile.Multi.Generic ( 1 )
12:54:56.0326 0x08bc  Detect skipped due to KSN trusted
12:54:56.0326 0x08bc  SCardSvr - ok
12:54:56.0368 0x08bc  [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter        C:\Windows\system32\DRIVERS\scfilter.sys
12:54:56.0378 0x08bc  scfilter - detected UnsignedFile.Multi.Generic ( 1 )
12:54:58.0815 0x08bc  Detect skipped due to KSN trusted
12:54:58.0815 0x08bc  scfilter - ok
12:54:58.0893 0x08bc  [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule        C:\Windows\system32\schedsvc.dll
12:54:58.0944 0x08bc  Schedule - detected UnsignedFile.Multi.Generic ( 1 )
12:55:01.0384 0x08bc  Detect skipped due to KSN trusted
12:55:01.0384 0x08bc  Schedule - ok
12:55:01.0400 0x08bc  [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc     C:\Windows\System32\certprop.dll
12:55:01.0411 0x08bc  SCPolicySvc - detected UnsignedFile.Multi.Generic ( 1 )
12:55:01.0411 0x08bc  Detect skipped due to KSN trusted
12:55:01.0411 0x08bc  SCPolicySvc - ok
12:55:01.0462 0x08bc  [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC          C:\Windows\System32\SDRSVC.dll
12:55:01.0477 0x08bc  SDRSVC - detected UnsignedFile.Multi.Generic ( 1 )
12:55:04.0160 0x08bc  Detect skipped due to KSN trusted
12:55:04.0160 0x08bc  SDRSVC - ok
12:55:04.0188 0x08bc  [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv          C:\Windows\system32\drivers\secdrv.sys
12:55:04.0198 0x08bc  secdrv - detected UnsignedFile.Multi.Generic ( 1 )
12:55:06.0882 0x08bc  Detect skipped due to KSN trusted
12:55:06.0882 0x08bc  secdrv - ok
12:55:06.0897 0x08bc  [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon        C:\Windows\system32\seclogon.dll
12:55:06.0909 0x08bc  seclogon - detected UnsignedFile.Multi.Generic ( 1 )
12:55:09.0351 0x08bc  Detect skipped due to KSN trusted
12:55:09.0351 0x08bc  seclogon - ok
12:55:09.0377 0x08bc  [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS            C:\Windows\System32\sens.dll
12:55:09.0389 0x08bc  SENS - detected UnsignedFile.Multi.Generic ( 1 )
12:55:12.0350 0x08bc  Detect skipped due to KSN trusted
12:55:12.0350 0x08bc  SENS - ok
12:55:12.0373 0x08bc  [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc        C:\Windows\system32\sensrsvc.dll
12:55:12.0384 0x08bc  SensrSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:55:14.0873 0x08bc  Detect skipped due to KSN trusted
12:55:14.0873 0x08bc  SensrSvc - ok
12:55:14.0896 0x08bc  [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum         C:\Windows\system32\DRIVERS\serenum.sys
12:55:14.0905 0x08bc  Serenum - detected UnsignedFile.Multi.Generic ( 1 )
12:55:17.0581 0x08bc  Detect skipped due to KSN trusted
12:55:17.0582 0x08bc  Serenum - ok
12:55:17.0604 0x08bc  [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial          C:\Windows\system32\DRIVERS\serial.sys
12:55:17.0616 0x08bc  Serial - detected UnsignedFile.Multi.Generic ( 1 )
12:55:23.0684 0x08bc  Detect skipped due to KSN trusted
12:55:23.0684 0x08bc  Serial - ok
12:55:23.0730 0x08bc  [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse        C:\Windows\system32\DRIVERS\sermouse.sys
12:55:23.0739 0x08bc  sermouse - detected UnsignedFile.Multi.Generic ( 1 )
12:55:26.0495 0x08bc  Detect skipped due to KSN trusted
12:55:26.0495 0x08bc  sermouse - ok
12:55:26.0551 0x08bc  [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv      C:\Windows\system32\sessenv.dll
12:55:26.0565 0x08bc  SessionEnv - detected UnsignedFile.Multi.Generic ( 1 )
12:55:29.0253 0x08bc  Detect skipped due to KSN trusted
12:55:29.0253 0x08bc  SessionEnv - ok
12:55:29.0284 0x08bc  [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk         C:\Windows\system32\drivers\sffdisk.sys
12:55:29.0293 0x08bc  sffdisk - detected UnsignedFile.Multi.Generic ( 1 )
12:55:33.0740 0x08bc  Detect skipped due to KSN trusted
12:55:33.0740 0x08bc  sffdisk - ok
12:55:33.0760 0x08bc  [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc        C:\Windows\system32\drivers\sffp_mmc.sys
12:55:33.0771 0x08bc  sffp_mmc - detected UnsignedFile.Multi.Generic ( 1 )
12:55:36.0442 0x08bc  Detect skipped due to KSN trusted
12:55:36.0442 0x08bc  sffp_mmc - ok
12:55:36.0448 0x08bc  [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd         C:\Windows\system32\drivers\sffp_sd.sys
12:55:36.0457 0x08bc  sffp_sd - detected UnsignedFile.Multi.Generic ( 1 )
12:55:39.0218 0x08bc  Detect skipped due to KSN trusted
12:55:39.0218 0x08bc  sffp_sd - ok
12:55:39.0232 0x08bc  [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy         C:\Windows\system32\DRIVERS\sfloppy.sys
12:55:39.0241 0x08bc  sfloppy - detected UnsignedFile.Multi.Generic ( 1 )
12:55:41.0988 0x08bc  Detect skipped due to KSN trusted
12:55:41.0988 0x08bc  sfloppy - ok
12:55:42.0017 0x08bc  [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess    C:\Windows\System32\ipnathlp.dll
12:55:42.0045 0x08bc  SharedAccess - detected UnsignedFile.Multi.Generic ( 1 )
12:55:44.0641 0x08bc  Detect skipped due to KSN trusted
12:55:44.0641 0x08bc  SharedAccess - ok
12:55:44.0688 0x08bc  [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
12:55:44.0716 0x08bc  ShellHWDetection - detected UnsignedFile.Multi.Generic ( 1 )
12:55:47.0158 0x08bc  Detect skipped due to KSN trusted
12:55:47.0158 0x08bc  ShellHWDetection - ok
12:55:47.0203 0x08bc  [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp          C:\Windows\system32\drivers\sisagp.sys
12:55:47.0220 0x08bc  sisagp - ok
12:55:47.0235 0x08bc  [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2        C:\Windows\system32\DRIVERS\SiSRaid2.sys
12:55:47.0251 0x08bc  SiSRaid2 - ok
12:55:47.0258 0x08bc  [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4        C:\Windows\system32\DRIVERS\sisraid4.sys
12:55:47.0276 0x08bc  SiSRaid4 - ok
12:55:47.0297 0x08bc  [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb             C:\Windows\system32\DRIVERS\smb.sys
12:55:47.0308 0x08bc  Smb - detected UnsignedFile.Multi.Generic ( 1 )
12:55:57.0309 0x08bc  Object is SCO, delete is not allowed
12:55:57.0309 0x08bc  Smb ( UnsignedFile.Multi.Generic ) - warning
12:56:02.0843 0x08bc  [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP        C:\Windows\System32\snmptrap.exe
12:56:02.0854 0x08bc  SNMPTRAP - detected UnsignedFile.Multi.Generic ( 1 )
12:56:05.0450 0x08bc  Detect skipped due to KSN trusted
12:56:05.0450 0x08bc  SNMPTRAP - ok
12:56:05.0468 0x08bc  [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr           C:\Windows\system32\drivers\spldr.sys
12:56:05.0484 0x08bc  spldr - ok
12:56:05.0534 0x08bc  [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler         C:\Windows\System32\spoolsv.exe
12:56:05.0562 0x08bc  Spooler - detected UnsignedFile.Multi.Generic ( 1 )
12:56:07.0983 0x08bc  Detect skipped due to KSN trusted
12:56:07.0983 0x08bc  Spooler - ok
12:56:08.0131 0x08bc  [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc          C:\Windows\system32\sppsvc.exe
12:56:08.0294 0x08bc  sppsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:56:10.0959 0x08bc  Detect skipped due to KSN trusted
12:56:10.0960 0x08bc  sppsvc - ok
12:56:11.0021 0x08bc  [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify     C:\Windows\system32\sppuinotify.dll
12:56:11.0034 0x08bc  sppuinotify - detected UnsignedFile.Multi.Generic ( 1 )
12:56:13.0473 0x08bc  Detect skipped due to KSN trusted
12:56:13.0473 0x08bc  sppuinotify - ok
12:56:13.0531 0x08bc  [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv             C:\Windows\system32\DRIVERS\srv.sys
12:56:13.0559 0x08bc  srv - detected UnsignedFile.Multi.Generic ( 1 )
12:56:16.0176 0x08bc  Detect skipped due to KSN trusted
12:56:16.0177 0x08bc  srv - ok
12:56:16.0217 0x08bc  [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2            C:\Windows\system32\DRIVERS\srv2.sys
12:56:16.0245 0x08bc  srv2 - detected UnsignedFile.Multi.Generic ( 1 )
12:56:18.0686 0x08bc  Detect skipped due to KSN trusted
12:56:18.0686 0x08bc  srv2 - ok
12:56:18.0737 0x08bc  [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet          C:\Windows\system32\DRIVERS\srvnet.sys
12:56:18.0750 0x08bc  srvnet - detected UnsignedFile.Multi.Generic ( 1 )
12:56:21.0192 0x08bc  Detect skipped due to KSN trusted
12:56:21.0192 0x08bc  srvnet - ok
12:56:21.0211 0x08bc  [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV         C:\Windows\System32\ssdpsrv.dll
12:56:21.0237 0x08bc  SSDPSRV - detected UnsignedFile.Multi.Generic ( 1 )
12:56:23.0914 0x08bc  Detect skipped due to KSN trusted
12:56:23.0914 0x08bc  SSDPSRV - ok
12:56:23.0923 0x08bc  [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc         C:\Windows\system32\sstpsvc.dll
12:56:23.0965 0x08bc  SstpSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:56:26.0404 0x08bc  Detect skipped due to KSN trusted
12:56:26.0404 0x08bc  SstpSvc - ok
12:56:26.0411 0x08bc  [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor        C:\Windows\system32\DRIVERS\stexstor.sys
12:56:26.0427 0x08bc  stexstor - ok
12:56:26.0459 0x08bc  [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc          C:\Windows\System32\wiaservc.dll
12:56:26.0497 0x08bc  StiSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:56:29.0187 0x08bc  Detect skipped due to KSN trusted
12:56:29.0187 0x08bc  StiSvc - ok
12:56:29.0220 0x08bc  [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum          C:\Windows\system32\drivers\swenum.sys
12:56:29.0236 0x08bc  swenum - ok
12:56:29.0265 0x08bc  [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv           C:\Windows\System32\swprv.dll
12:56:29.0293 0x08bc  swprv - detected UnsignedFile.Multi.Generic ( 1 )
12:56:31.0726 0x08bc  Detect skipped due to KSN trusted
12:56:31.0726 0x08bc  swprv - ok
12:56:31.0803 0x08bc  [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain         C:\Windows\system32\sysmain.dll
12:56:31.0875 0x08bc  SysMain - detected UnsignedFile.Multi.Generic ( 1 )
12:56:34.0599 0x08bc  Detect skipped due to KSN trusted
12:56:34.0600 0x08bc  SysMain - ok
12:56:34.0613 0x08bc  [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
12:56:34.0627 0x08bc  TabletInputService - detected UnsignedFile.Multi.Generic ( 1 )
12:56:37.0049 0x08bc  Detect skipped due to KSN trusted
12:56:37.0049 0x08bc  TabletInputService - ok
12:56:37.0091 0x08bc  [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv         C:\Windows\System32\tapisrv.dll
12:56:37.0118 0x08bc  TapiSrv - detected UnsignedFile.Multi.Generic ( 1 )
12:56:39.0542 0x08bc  Detect skipped due to KSN trusted
12:56:39.0542 0x08bc  TapiSrv - ok
12:56:39.0549 0x08bc  [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS             C:\Windows\System32\tbssvc.dll
12:56:39.0562 0x08bc  TBS - detected UnsignedFile.Multi.Generic ( 1 )
12:56:42.0307 0x08bc  Detect skipped due to KSN trusted
12:56:42.0307 0x08bc  TBS - ok
12:56:42.0400 0x08bc  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip           C:\Windows\system32\drivers\tcpip.sys
12:56:42.0472 0x08bc  Tcpip - ok
12:56:42.0530 0x08bc  [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6          C:\Windows\system32\DRIVERS\tcpip.sys
12:56:42.0582 0x08bc  TCPIP6 - ok
12:56:42.0636 0x08bc  [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg        C:\Windows\system32\drivers\tcpipreg.sys
12:56:42.0646 0x08bc  tcpipreg - detected UnsignedFile.Multi.Generic ( 1 )
12:56:45.0309 0x08bc  Detect skipped due to KSN trusted
12:56:45.0309 0x08bc  tcpipreg - ok
12:56:45.0358 0x08bc  [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE          C:\Windows\system32\drivers\tdpipe.sys
12:56:45.0367 0x08bc  TDPIPE - detected UnsignedFile.Multi.Generic ( 1 )
12:56:48.0107 0x08bc  Detect skipped due to KSN trusted
12:56:48.0107 0x08bc  TDPIPE - ok
12:56:48.0149 0x08bc  [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP           C:\Windows\system32\drivers\tdtcp.sys
12:56:48.0158 0x08bc  TDTCP - detected UnsignedFile.Multi.Generic ( 1 )
12:56:50.0587 0x08bc  Detect skipped due to KSN trusted
12:56:50.0587 0x08bc  TDTCP - ok
12:56:50.0628 0x08bc  [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx             C:\Windows\system32\DRIVERS\tdx.sys
12:56:50.0640 0x08bc  tdx - detected UnsignedFile.Multi.Generic ( 1 )
12:56:53.0072 0x08bc  Detect skipped due to KSN trusted
12:56:53.0072 0x08bc  tdx - ok
12:56:53.0116 0x08bc  [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD          C:\Windows\system32\drivers\termdd.sys
12:56:53.0132 0x08bc  TermDD - ok
12:56:53.0192 0x08bc  [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService     C:\Windows\System32\termsrv.dll
12:56:53.0231 0x08bc  TermService - detected UnsignedFile.Multi.Generic ( 1 )
12:56:55.0825 0x08bc  Detect skipped due to KSN trusted
12:56:55.0825 0x08bc  TermService - ok
12:56:55.0840 0x08bc  [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes          C:\Windows\system32\themeservice.dll
12:56:55.0852 0x08bc  Themes - detected UnsignedFile.Multi.Generic ( 1 )
12:56:58.0295 0x08bc  Detect skipped due to KSN trusted
12:56:58.0295 0x08bc  Themes - ok
12:56:58.0320 0x08bc  [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER     C:\Windows\system32\mmcss.dll
12:56:58.0331 0x08bc  THREADORDER - detected UnsignedFile.Multi.Generic ( 1 )
12:56:58.0331 0x08bc  Detect skipped due to KSN trusted
12:56:58.0331 0x08bc  THREADORDER - ok
12:56:58.0351 0x08bc  [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks          C:\Windows\System32\trkwks.dll
12:56:58.0365 0x08bc  TrkWks - detected UnsignedFile.Multi.Generic ( 1 )
12:57:00.0984 0x08bc  Detect skipped due to KSN trusted
12:57:00.0984 0x08bc  TrkWks - ok
12:57:01.0057 0x08bc  [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
12:57:01.0073 0x08bc  TrustedInstaller - detected UnsignedFile.Multi.Generic ( 1 )
12:57:11.0073 0x08bc  Object is SCO, delete is not allowed
12:57:11.0073 0x08bc  TrustedInstaller ( UnsignedFile.Multi.Generic ) - warning
12:57:16.0644 0x08bc  [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv        C:\Windows\system32\DRIVERS\tssecsrv.sys
12:57:16.0654 0x08bc  tssecsrv - detected UnsignedFile.Multi.Generic ( 1 )
12:57:19.0275 0x08bc  Detect skipped due to KSN trusted
12:57:19.0275 0x08bc  tssecsrv - ok
12:57:19.0321 0x08bc  [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt        C:\Windows\system32\drivers\tsusbflt.sys
12:57:19.0331 0x08bc  TsUsbFlt - detected UnsignedFile.Multi.Generic ( 1 )
12:57:22.0010 0x08bc  Detect skipped due to KSN trusted
12:57:22.0010 0x08bc  TsUsbFlt - ok
12:57:22.0057 0x08bc  [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel          C:\Windows\system32\DRIVERS\tunnel.sys
12:57:22.0070 0x08bc  tunnel - detected UnsignedFile.Multi.Generic ( 1 )
12:57:24.0742 0x08bc  Detect skipped due to KSN trusted
12:57:24.0742 0x08bc  tunnel - ok
12:57:24.0767 0x08bc  [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35          C:\Windows\system32\DRIVERS\uagp35.sys
12:57:24.0784 0x08bc  uagp35 - ok
12:57:24.0831 0x08bc  [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs            C:\Windows\system32\DRIVERS\udfs.sys
12:57:24.0858 0x08bc  udfs - detected UnsignedFile.Multi.Generic ( 1 )
12:57:27.0300 0x08bc  Detect skipped due to KSN trusted
12:57:27.0300 0x08bc  udfs - ok
12:57:27.0327 0x08bc  [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect       C:\Windows\system32\UI0Detect.exe
12:57:27.0340 0x08bc  UI0Detect - detected UnsignedFile.Multi.Generic ( 1 )
12:57:29.0995 0x08bc  Detect skipped due to KSN trusted
12:57:29.0996 0x08bc  UI0Detect - ok
12:57:30.0025 0x08bc  [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx        C:\Windows\system32\drivers\uliagpkx.sys
12:57:30.0042 0x08bc  uliagpkx - ok
12:57:30.0097 0x08bc  [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus           C:\Windows\system32\drivers\umbus.sys
12:57:30.0107 0x08bc  umbus - detected UnsignedFile.Multi.Generic ( 1 )
12:57:32.0725 0x08bc  Detect skipped due to KSN trusted
12:57:32.0725 0x08bc  umbus - ok
12:57:32.0749 0x08bc  [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass          C:\Windows\system32\DRIVERS\umpass.sys
12:57:32.0758 0x08bc  UmPass - detected UnsignedFile.Multi.Generic ( 1 )
12:57:35.0415 0x08bc  Detect skipped due to KSN trusted
12:57:35.0415 0x08bc  UmPass - ok
12:57:35.0438 0x08bc  [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost        C:\Windows\System32\upnphost.dll
12:57:35.0465 0x08bc  upnphost - detected UnsignedFile.Multi.Generic ( 1 )
12:57:37.0900 0x08bc  Detect skipped due to KSN trusted
12:57:37.0900 0x08bc  upnphost - ok
12:57:37.0966 0x08bc  [ A1977C315BF5691DA99235AA4A6907AF, 34B52FBA83F0E1C6B001D0AD1808B00152F731D18AAECC3C53B9918AA89BACEC ] usbaudio        C:\Windows\system32\drivers\usbaudio.sys
12:57:37.0977 0x08bc  usbaudio - detected UnsignedFile.Multi.Generic ( 1 )
12:57:40.0569 0x08bc  Detect skipped due to KSN trusted
12:57:40.0569 0x08bc  usbaudio - ok
12:57:40.0619 0x08bc  [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp         C:\Windows\system32\DRIVERS\usbccgp.sys
12:57:40.0630 0x08bc  usbccgp - detected UnsignedFile.Multi.Generic ( 1 )
12:57:43.0054 0x08bc  Detect skipped due to KSN trusted
12:57:43.0054 0x08bc  usbccgp - ok
12:57:43.0061 0x08bc  [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir          C:\Windows\system32\drivers\usbcir.sys
12:57:43.0073 0x08bc  usbcir - detected UnsignedFile.Multi.Generic ( 1 )
12:57:45.0830 0x08bc  Detect skipped due to KSN trusted
12:57:45.0830 0x08bc  usbcir - ok
12:57:45.0847 0x08bc  [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci         C:\Windows\system32\DRIVERS\usbehci.sys
12:57:45.0858 0x08bc  usbehci - detected UnsignedFile.Multi.Generic ( 1 )
12:57:48.0544 0x08bc  Detect skipped due to KSN trusted
12:57:48.0544 0x08bc  usbehci - ok
12:57:48.0578 0x08bc  [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub          C:\Windows\system32\DRIVERS\usbhub.sys
12:57:48.0605 0x08bc  usbhub - detected UnsignedFile.Multi.Generic ( 1 )
12:57:51.0045 0x08bc  Detect skipped due to KSN trusted
12:57:51.0045 0x08bc  usbhub - ok
12:57:51.0055 0x08bc  [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci         C:\Windows\system32\DRIVERS\usbohci.sys
12:57:51.0065 0x08bc  usbohci - detected UnsignedFile.Multi.Generic ( 1 )
12:57:53.0739 0x08bc  Detect skipped due to KSN trusted
12:57:53.0740 0x08bc  usbohci - ok
12:57:53.0756 0x08bc  [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint        C:\Windows\system32\DRIVERS\usbprint.sys
12:57:53.0766 0x08bc  usbprint - detected UnsignedFile.Multi.Generic ( 1 )
12:57:56.0433 0x08bc  Detect skipped due to KSN trusted
12:57:56.0433 0x08bc  usbprint - ok
12:57:56.0492 0x08bc  [ FC6B21DB4B5B398AB93DBE59CBF11036, A94094C208F376405C07822A6143001EF1B12AE93205CD8002E87F6EB45F6374 ] usbscan         C:\Windows\system32\drivers\usbscan.sys
12:57:56.0502 0x08bc  usbscan - detected UnsignedFile.Multi.Generic ( 1 )
12:57:58.0924 0x08bc  Detect skipped due to KSN trusted
12:57:58.0925 0x08bc  usbscan - ok
12:57:58.0965 0x08bc  [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR         C:\Windows\system32\drivers\USBSTOR.SYS
12:57:58.0976 0x08bc  USBSTOR - detected UnsignedFile.Multi.Generic ( 1 )
12:58:01.0652 0x08bc  Detect skipped due to KSN trusted
12:58:01.0652 0x08bc  USBSTOR - ok
12:58:01.0677 0x08bc  [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci         C:\Windows\system32\drivers\usbuhci.sys
12:58:01.0686 0x08bc  usbuhci - detected UnsignedFile.Multi.Generic ( 1 )
12:58:04.0341 0x08bc  Detect skipped due to KSN trusted
12:58:04.0342 0x08bc  usbuhci - ok
12:58:04.0363 0x08bc  [ DE014425522610BEDCA3821BB8C0F1D5, D6FEA0DF07F89834AEEE8C02CC7FD41068D758B6CCECE2EEE5CF4B9DB646FA1E ] usbvideo        C:\Windows\system32\Drivers\usbvideo.sys
12:58:04.0377 0x08bc  usbvideo - detected UnsignedFile.Multi.Generic ( 1 )
12:58:07.0104 0x08bc  Detect skipped due to KSN trusted
12:58:07.0104 0x08bc  usbvideo - ok
12:58:07.0128 0x08bc  [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms           C:\Windows\System32\uxsms.dll
12:58:07.0139 0x08bc  UxSms - detected UnsignedFile.Multi.Generic ( 1 )
12:58:09.0880 0x08bc  Detect skipped due to KSN trusted
12:58:09.0880 0x08bc  UxSms - ok
12:58:09.0894 0x08bc  [ DD17E1573651293D4ED31053795B3471, 94F7D1BB1C3B0C1FAAEED07375DB0F3BC995394FB5C26983548D946C8D229D54 ] VaultSvc        C:\Windows\system32\lsass.exe
12:58:09.0904 0x08bc  VaultSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:58:09.0904 0x08bc  Detect skipped due to KSN trusted
12:58:09.0904 0x08bc  VaultSvc - ok
12:58:09.0925 0x08bc  [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot        C:\Windows\system32\drivers\vdrvroot.sys
12:58:09.0942 0x08bc  vdrvroot - ok
12:58:09.0997 0x08bc  [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds             C:\Windows\System32\vds.exe
12:58:10.0044 0x08bc  vds - detected UnsignedFile.Multi.Generic ( 1 )
12:58:12.0476 0x08bc  Detect skipped due to KSN trusted
12:58:12.0476 0x08bc  vds - ok
12:58:12.0515 0x08bc  [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga             C:\Windows\system32\DRIVERS\vgapnp.sys
12:58:12.0525 0x08bc  vga - detected UnsignedFile.Multi.Generic ( 1 )
12:58:15.0270 0x08bc  Detect skipped due to KSN trusted
12:58:15.0270 0x08bc  vga - ok
12:58:15.0286 0x08bc  [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave         C:\Windows\System32\drivers\vga.sys
12:58:15.0296 0x08bc  VgaSave - detected UnsignedFile.Multi.Generic ( 1 )
12:58:25.0296 0x08bc  Object is SCO, delete is not allowed
12:58:25.0296 0x08bc  VgaSave ( UnsignedFile.Multi.Generic ) - warning
12:58:28.0876 0x08bc  [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp           C:\Windows\system32\drivers\vhdmp.sys
12:58:28.0897 0x08bc  vhdmp - ok
12:58:28.0919 0x08bc  [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp          C:\Windows\system32\drivers\viaagp.sys
12:58:28.0936 0x08bc  viaagp - ok
12:58:28.0976 0x08bc  [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7           C:\Windows\system32\DRIVERS\viac7.sys
12:58:28.0987 0x08bc  ViaC7 - detected UnsignedFile.Multi.Generic ( 1 )
12:58:31.0427 0x08bc  Detect skipped due to KSN trusted
12:58:31.0427 0x08bc  ViaC7 - ok
12:58:31.0469 0x08bc  [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide          C:\Windows\system32\drivers\viaide.sys
12:58:31.0486 0x08bc  viaide - ok
12:58:31.0501 0x08bc  [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr          C:\Windows\system32\drivers\volmgr.sys
12:58:31.0518 0x08bc  volmgr - ok
12:58:31.0533 0x08bc  [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx         C:\Windows\system32\drivers\volmgrx.sys
12:58:31.0557 0x08bc  volmgrx - ok
12:58:31.0574 0x08bc  [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap         C:\Windows\system32\drivers\volsnap.sys
12:58:31.0606 0x08bc  volsnap - ok
12:58:31.0646 0x08bc  [ 8AEDAF658E36A863DDAA06A79FADECB0, 918495589C2593885F14257CAC7900B959F719331D5DD218A8DCC38F380B1A53 ] Vsdatant        C:\Windows\system32\DRIVERS\vsdatant.sys
12:58:31.0680 0x08bc  Vsdatant - ok
12:58:31.0846 0x08bc  [ EA02B9C499A795AD537E25F7C9612194, 44AE3BDBFB9CB3904387001E4937C3687D1FFD66F830A42E5F8C4CE2542BC2EC ] vsmon           C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe
12:58:32.0010 0x08bc  vsmon - ok
12:58:32.0056 0x08bc  [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid         C:\Windows\system32\DRIVERS\vsmraid.sys
12:58:32.0076 0x08bc  vsmraid - ok
12:58:32.0145 0x08bc  [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS             C:\Windows\system32\vssvc.exe
12:58:32.0207 0x08bc  VSS - detected UnsignedFile.Multi.Generic ( 1 )
12:58:34.0810 0x08bc  Detect skipped due to KSN trusted
12:58:34.0810 0x08bc  VSS - ok
12:58:34.0816 0x08bc  [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus        C:\Windows\System32\drivers\vwifibus.sys
12:58:34.0826 0x08bc  vwifibus - detected UnsignedFile.Multi.Generic ( 1 )
12:58:37.0491 0x08bc  Detect skipped due to KSN trusted
12:58:37.0491 0x08bc  vwifibus - ok
12:58:37.0536 0x08bc  [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time         C:\Windows\system32\w32time.dll
12:58:37.0563 0x08bc  W32Time - detected UnsignedFile.Multi.Generic ( 1 )
12:58:40.0242 0x08bc  Detect skipped due to KSN trusted
12:58:40.0242 0x08bc  W32Time - ok
12:58:40.0324 0x08bc  [ 57C8C20BFA5BEF6BD851EBAC67A8CED0, D5968069D934400A46B9FF92ECA9D7660BDC30C6909BA588AD49F7656246EE98 ] W3SVC           C:\Windows\system32\inetsrv\iisw3adm.dll
12:58:40.0353 0x08bc  W3SVC - detected UnsignedFile.Multi.Generic ( 1 )
12:58:43.0035 0x08bc  Detect skipped due to KSN trusted
12:58:43.0035 0x08bc  W3SVC - ok
12:58:43.0054 0x08bc  [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen        C:\Windows\system32\DRIVERS\wacompen.sys
12:58:43.0063 0x08bc  WacomPen - detected UnsignedFile.Multi.Generic ( 1 )
12:58:45.0506 0x08bc  Detect skipped due to KSN trusted
12:58:45.0506 0x08bc  WacomPen - ok
12:58:45.0528 0x08bc  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP          C:\Windows\system32\DRIVERS\wanarp.sys
12:58:45.0539 0x08bc  WANARP - detected UnsignedFile.Multi.Generic ( 1 )
12:58:47.0982 0x08bc  Detect skipped due to KSN trusted
12:58:47.0982 0x08bc  WANARP - ok
12:58:47.0987 0x08bc  [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6        C:\Windows\system32\DRIVERS\wanarp.sys
12:58:47.0998 0x08bc  Wanarpv6 - detected UnsignedFile.Multi.Generic ( 1 )
12:58:47.0998 0x08bc  Detect skipped due to KSN trusted
12:58:47.0998 0x08bc  Wanarpv6 - ok
12:58:48.0014 0x08bc  [ 57C8C20BFA5BEF6BD851EBAC67A8CED0, D5968069D934400A46B9FF92ECA9D7660BDC30C6909BA588AD49F7656246EE98 ] WAS             C:\Windows\system32\inetsrv\iisw3adm.dll
12:58:48.0036 0x08bc  WAS - detected UnsignedFile.Multi.Generic ( 1 )
12:58:48.0036 0x08bc  Detect skipped due to KSN trusted
12:58:48.0036 0x08bc  WAS - ok
12:58:48.0118 0x08bc  [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine        C:\Windows\system32\wbengine.exe
12:58:48.0191 0x08bc  wbengine - detected UnsignedFile.Multi.Generic ( 1 )
12:58:50.0630 0x08bc  Detect skipped due to KSN trusted
12:58:50.0631 0x08bc  wbengine - ok
12:58:50.0651 0x08bc  [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc        C:\Windows\System32\wbiosrvc.dll
12:58:50.0677 0x08bc  WbioSrvc - detected UnsignedFile.Multi.Generic ( 1 )
12:58:53.0117 0x08bc  Detect skipped due to KSN trusted
12:58:53.0117 0x08bc  WbioSrvc - ok
12:58:53.0165 0x08bc  [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc         C:\Windows\System32\wcncsvc.dll
12:58:53.0193 0x08bc  wcncsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:58:55.0869 0x08bc  Detect skipped due to KSN trusted
12:58:55.0870 0x08bc  wcncsvc - ok
12:58:55.0882 0x08bc  [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
12:58:55.0895 0x08bc  WcsPlugInService - detected UnsignedFile.Multi.Generic ( 1 )
12:58:58.0580 0x08bc  Detect skipped due to KSN trusted
12:58:58.0580 0x08bc  WcsPlugInService - ok
12:58:58.0596 0x08bc  [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd              C:\Windows\system32\DRIVERS\wd.sys
12:58:58.0612 0x08bc  Wd - ok
12:58:58.0673 0x08bc  [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000        C:\Windows\system32\drivers\Wdf01000.sys
12:58:58.0719 0x08bc  Wdf01000 - ok
12:58:58.0728 0x08bc  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiServiceHost  C:\Windows\system32\wdi.dll
12:58:58.0742 0x08bc  WdiServiceHost - detected UnsignedFile.Multi.Generic ( 1 )
12:59:01.0184 0x08bc  Detect skipped due to KSN trusted
12:59:01.0184 0x08bc  WdiServiceHost - ok
12:59:01.0190 0x08bc  [ 46EF9DC96265FD0B423DB72E7C38C2A5, 43801A51FB0E45CFFC73DF6441B54A75FC2FEAF5E0424DFE7AB04FC26CF6CD16 ] WdiSystemHost   C:\Windows\system32\wdi.dll
12:59:01.0203 0x08bc  WdiSystemHost - detected UnsignedFile.Multi.Generic ( 1 )
12:59:01.0204 0x08bc  Detect skipped due to KSN trusted
12:59:01.0204 0x08bc  WdiSystemHost - ok
12:59:01.0250 0x08bc  [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient       C:\Windows\System32\webclnt.dll
12:59:01.0278 0x08bc  WebClient - detected UnsignedFile.Multi.Generic ( 1 )
12:59:03.0706 0x08bc  Detect skipped due to KSN trusted
12:59:03.0706 0x08bc  WebClient - ok
12:59:03.0729 0x08bc  [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc          C:\Windows\system32\wecsvc.dll
12:59:03.0755 0x08bc  Wecsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:59:06.0435 0x08bc  Detect skipped due to KSN trusted
12:59:06.0435 0x08bc  Wecsvc - ok
12:59:06.0443 0x08bc  [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport   C:\Windows\System32\wercplsupport.dll
12:59:06.0456 0x08bc  wercplsupport - detected UnsignedFile.Multi.Generic ( 1 )
12:59:09.0080 0x08bc  Detect skipped due to KSN trusted
12:59:09.0081 0x08bc  wercplsupport - ok
12:59:09.0088 0x08bc  [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc          C:\Windows\System32\WerSvc.dll
12:59:09.0101 0x08bc  WerSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:59:11.0790 0x08bc  Detect skipped due to KSN trusted
12:59:11.0790 0x08bc  WerSvc - ok
12:59:11.0811 0x08bc  [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf          C:\Windows\system32\DRIVERS\wfplwf.sys
12:59:11.0820 0x08bc  WfpLwf - detected UnsignedFile.Multi.Generic ( 1 )
12:59:14.0481 0x08bc  Detect skipped due to KSN trusted
12:59:14.0481 0x08bc  WfpLwf - ok
12:59:14.0497 0x08bc  [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount        C:\Windows\system32\drivers\wimmount.sys
12:59:14.0513 0x08bc  WIMMount - ok
12:59:14.0598 0x08bc  [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend       C:\Program Files\Windows Defender\mpsvc.dll
12:59:14.0639 0x08bc  WinDefend - detected UnsignedFile.Multi.Generic ( 1 )
12:59:17.0067 0x08bc  Detect skipped due to KSN trusted
12:59:17.0067 0x08bc  WinDefend - ok
12:59:17.0085 0x08bc  WinHttpAutoProxySvc - ok
12:59:17.0135 0x08bc  [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt         C:\Windows\system32\wbem\WMIsvc.dll
12:59:17.0150 0x08bc  Winmgmt - detected UnsignedFile.Multi.Generic ( 1 )
12:59:19.0821 0x08bc  Detect skipped due to KSN trusted
12:59:19.0821 0x08bc  Winmgmt - ok
12:59:19.0899 0x08bc  [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM           C:\Windows\system32\WsmSvc.dll
12:59:19.0964 0x08bc  WinRM - detected UnsignedFile.Multi.Generic ( 1 )
12:59:22.0621 0x08bc  Detect skipped due to KSN trusted
12:59:22.0622 0x08bc  WinRM - ok
12:59:22.0692 0x08bc  [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc         C:\Windows\System32\wlansvc.dll
12:59:22.0746 0x08bc  Wlansvc - detected UnsignedFile.Multi.Generic ( 1 )
12:59:25.0185 0x08bc  Detect skipped due to KSN trusted
12:59:25.0185 0x08bc  Wlansvc - ok
12:59:25.0232 0x08bc  [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi         C:\Windows\system32\drivers\wmiacpi.sys
12:59:25.0241 0x08bc  WmiAcpi - detected UnsignedFile.Multi.Generic ( 1 )
12:59:27.0678 0x08bc  Detect skipped due to KSN trusted
12:59:27.0678 0x08bc  WmiAcpi - ok
12:59:27.0707 0x08bc  [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv        C:\Windows\system32\wbem\WmiApSrv.exe
12:59:27.0733 0x08bc  wmiApSrv - detected UnsignedFile.Multi.Generic ( 1 )
12:59:37.0734 0x08bc  Object is SCO, delete is not allowed
12:59:37.0734 0x08bc  wmiApSrv ( UnsignedFile.Multi.Generic ) - warning
12:59:42.0343 0x08bc  [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc   C:\Program Files\Windows Media Player\wmpnetwk.exe
12:59:42.0407 0x08bc  WMPNetworkSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:59:44.0846 0x08bc  Detect skipped due to KSN trusted
12:59:44.0846 0x08bc  WMPNetworkSvc - ok
12:59:44.0864 0x08bc  [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc          C:\Windows\System32\wpcsvc.dll
12:59:44.0876 0x08bc  WPCSvc - detected UnsignedFile.Multi.Generic ( 1 )
12:59:47.0306 0x08bc  Detect skipped due to KSN trusted
12:59:47.0306 0x08bc  WPCSvc - ok
12:59:47.0342 0x08bc  [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum      C:\Windows\system32\wpdbusenum.dll
12:59:47.0357 0x08bc  WPDBusEnum - detected UnsignedFile.Multi.Generic ( 1 )
12:59:50.0022 0x08bc  Detect skipped due to KSN trusted
12:59:50.0022 0x08bc  WPDBusEnum - ok
12:59:50.0075 0x08bc  [ DD057FC1271F23EC8F7575EB37C72F7F, F8FF72F7E00410818B6227A0BB3077129B6C2F77904A3918C0FCBB6981EF4EA2 ] WRkrn           C:\Windows\system32\drivers\WRkrn.sys
12:59:50.0093 0x08bc  WRkrn - ok
12:59:50.0145 0x08bc  [ 1059BA958126DF693CA5D1DA697AB507, A3E44C7FB9FB5ED7E5E0C0B8BDC54DDC3C2E36BB43E829A74B2CA80FCAF60C08 ] WRSVC           C:\Program Files\Webroot\WRSA.exe
12:59:50.0197 0x08bc  WRSVC - ok
12:59:50.0225 0x08bc  [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl         C:\Windows\system32\drivers\ws2ifsl.sys
12:59:50.0256 0x08bc  ws2ifsl - detected UnsignedFile.Multi.Generic ( 1 )
12:59:52.0681 0x08bc  Detect skipped due to KSN trusted
12:59:52.0682 0x08bc  ws2ifsl - ok
12:59:52.0698 0x08bc  [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc          C:\Windows\System32\wscsvc.dll
12:59:52.0712 0x08bc  wscsvc - detected UnsignedFile.Multi.Generic ( 1 )
12:59:55.0378 0x08bc  Detect skipped due to KSN trusted
12:59:55.0379 0x08bc  wscsvc - ok
12:59:55.0384 0x08bc  WSearch - ok
12:59:55.0489 0x08bc  [ D9B0134913E5EF007AF82A418C503322, 7418DD28C8E968674382F8352AAFFC4DE77887E2B71B8844D615F19432B4C55A ] wuauserv        C:\Windows\system32\wuaueng.dll
12:59:55.0591 0x08bc  wuauserv - ok
12:59:55.0640 0x08bc  [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf          C:\Windows\system32\drivers\WudfPf.sys
12:59:55.0651 0x08bc  WudfPf - detected UnsignedFile.Multi.Generic ( 1 )
12:59:58.0092 0x08bc  Detect skipped due to KSN trusted
12:59:58.0092 0x08bc  WudfPf - ok
12:59:58.0122 0x08bc  [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd          C:\Windows\system32\DRIVERS\WUDFRd.sys
12:59:58.0137 0x08bc  WUDFRd - detected UnsignedFile.Multi.Generic ( 1 )
13:00:00.0630 0x08bc  Detect skipped due to KSN trusted
13:00:00.0630 0x08bc  WUDFRd - ok
13:00:00.0691 0x08bc  [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc         C:\Windows\System32\WUDFSvc.dll
13:00:00.0705 0x08bc  wudfsvc - detected UnsignedFile.Multi.Generic ( 1 )
13:00:03.0309 0x08bc  Detect skipped due to KSN trusted
13:00:03.0309 0x08bc  wudfsvc - ok
13:00:03.0351 0x08bc  [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc         C:\Windows\System32\wwansvc.dll
13:00:03.0378 0x08bc  WwanSvc - detected UnsignedFile.Multi.Generic ( 1 )
13:00:06.0049 0x08bc  Detect skipped due to KSN trusted
13:00:06.0049 0x08bc  WwanSvc - ok
13:00:06.0069 0x08bc  [ 06C2D86214E0D3590F288D18365EFE04, 2405E924B3C5648EF69103DB339F3F385797C8763C1C31B549505E62D8E903E8 ] ZAPrivacyService C:\Program Files\CheckPoint\ZoneAlarm\ZaPrivacyService.exe
13:00:06.0085 0x08bc  ZAPrivacyService - ok
13:00:06.0097 0x08bc  ================ Scan global ===============================
13:00:06.0143 0x08bc  [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
13:00:06.0191 0x08bc  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
13:00:06.0205 0x08bc  [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
13:00:06.0234 0x08bc  [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
13:00:06.0266 0x08bc  [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
13:00:06.0283 0x08bc  [ Global ] - ok
13:00:06.0283 0x08bc  ================ Scan MBR ==================================
13:00:06.0294 0x08bc  [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
13:00:06.0625 0x08bc  \Device\Harddisk0\DR0 - ok
13:00:06.0626 0x08bc  ================ Scan VBR ==================================
13:00:06.0629 0x08bc  [ 64C18DCA728E033754650F389239052A ] \Device\Harddisk0\DR0\Partition1
13:00:06.0632 0x08bc  \Device\Harddisk0\DR0\Partition1 - ok
13:00:06.0636 0x08bc  [ DFBFBDBADAD0A32F9857D1A1A0CC93D3 ] \Device\Harddisk0\DR0\Partition2
13:00:06.0638 0x08bc  \Device\Harddisk0\DR0\Partition2 - ok
13:00:06.0639 0x08bc  ================ Scan generic autorun ======================
13:00:06.0686 0x08bc  [ 1059BA958126DF693CA5D1DA697AB507, A3E44C7FB9FB5ED7E5E0C0B8BDC54DDC3C2E36BB43E829A74B2CA80FCAF60C08 ] C:\Program Files\Webroot\WRSA.exe
13:00:06.0722 0x08bc  WRSVC - ok
13:00:06.0751 0x08bc  [ A66520B6437484D9DA15F514D5F88390, AEB61ABC90854A4A736D5DF38D096E657C572E4729223C758FE18EBB5C055F3C ] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe
13:00:06.0767 0x08bc  ZoneAlarm - ok
13:00:06.0902 0x08bc  [ CA0C365133D27649D3EFAD5E611AF271, 5B1E2E7C2DCC0B45163B8BC8E8607D03328530A89EA929645437CBA154C74DE4 ] C:\Program Files\Creative\Sound Blaster X-Fi Go Pro\Volume Panel\VolPanlu.exe
13:00:06.0928 0x08bc  VolPanel - detected UnsignedFile.Multi.Generic ( 1 )
13:00:09.0599 0x08bc  Detect skipped due to KSN trusted
13:00:09.0599 0x08bc  VolPanel - ok
13:00:09.0602 0x08bc  Creative SB Monitoring Utility - ok
13:00:09.0618 0x08bc  [ C419DF63E0121D72411285780C2FC6CC, F47F854D327C589D174D3BB5B55D5C05F5ACA73DF52A6BEF47596B9010190291 ] C:\Windows\UpdReg.EXE
13:00:09.0630 0x08bc  UpdReg - detected UnsignedFile.Multi.Generic ( 1 )
13:00:12.0285 0x08bc  Detect skipped due to KSN trusted
13:00:12.0285 0x08bc  UpdReg - ok
13:00:12.0356 0x08bc  [ 77C980C97A17D31B21CCCD3F2ED823CB, 7F90CA4C0FEA00CEC2442A5A82E183838CFE17EABC8A2991D20A52170C6A6BAA ] C:\Program Files\KeyScrambler\keyscrambler.exe
13:00:12.0397 0x08bc  KeyScrambler - ok
13:00:12.0486 0x08bc  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
13:00:12.0552 0x08bc  Sidebar - detected UnsignedFile.Multi.Generic ( 1 )
13:00:15.0298 0x08bc  Detect skipped due to KSN trusted
13:00:15.0298 0x08bc  Sidebar - ok
13:00:15.0324 0x08bc  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
13:00:15.0337 0x08bc  mctadmin - detected UnsignedFile.Multi.Generic ( 1 )
13:00:18.0009 0x08bc  Detect skipped due to KSN trusted
13:00:18.0010 0x08bc  mctadmin - ok
13:00:18.0057 0x08bc  [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
13:00:18.0109 0x08bc  Sidebar - detected UnsignedFile.Multi.Generic ( 1 )
13:00:18.0109 0x08bc  Detect skipped due to KSN trusted
13:00:18.0109 0x08bc  Sidebar - ok
13:00:18.0116 0x08bc  [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
13:00:18.0128 0x08bc  mctadmin - detected UnsignedFile.Multi.Generic ( 1 )
13:00:18.0128 0x08bc  Detect skipped due to KSN trusted
13:00:18.0128 0x08bc  mctadmin - ok
13:00:18.0399 0x08bc  [ 9234F8EE0AD16136EA95C6521E6375B0, 7F550FF46D172483B8B44C58EDA091821A24D45138CD2E01F8BEAAB193CC34B9 ] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
13:00:18.0667 0x08bc  SUPERAntiSpyware - ok
13:00:18.0686 0x08bc  Waiting for KSN requests completion. In queue: 1
13:00:19.0686 0x08bc  Waiting for KSN requests completion. In queue: 1
13:00:20.0686 0x08bc  Waiting for KSN requests completion. In queue: 1
13:00:21.0705 0x08bc  AV detected via SS2: Webroot SecureAnywhere, C:\Program Files\Webroot\WRSA.exe ( 8.0.6.28 ), 0x41000 ( enabled : updated )
13:00:21.0716 0x08bc  FW detected via SS2: ZoneAlarm Free Firewall Firewall, C:\Program Files\CheckPoint\ZoneAlarm\\MultiFix.exe ( 13.3.52.0 ), 0x41010 ( enabled )
13:00:24.0207 0x08bc  ============================================================
13:00:24.0207 0x08bc  Scan finished
13:00:24.0207 0x08bc  ============================================================
13:00:24.0217 0x1ff4  Detected object count: 27
13:00:24.0217 0x1ff4  Actual detected object count: 27
13:05:48.0521 0x1ff4  bowser ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0521 0x1ff4  bowser ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0521 0x1ff4  Dnscache ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0521 0x1ff4  Dnscache ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0523 0x1ff4  FreeOTFE ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0523 0x1ff4  FreeOTFE ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0525 0x1ff4  FreeOTFECypherAES_Gladman ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0525 0x1ff4  FreeOTFECypherAES_Gladman ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0527 0x1ff4  FreeOTFECypherAES_ltc ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0527 0x1ff4  FreeOTFECypherAES_ltc ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0529 0x1ff4  FreeOTFECypherBlowfish ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0529 0x1ff4  FreeOTFECypherBlowfish ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0531 0x1ff4  FreeOTFECypherCAST5 ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0531 0x1ff4  FreeOTFECypherCAST5 ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0534 0x1ff4  FreeOTFECypherCAST6_Gladman ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0534 0x1ff4  FreeOTFECypherCAST6_Gladman ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0536 0x1ff4  FreeOTFECypherDES ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0536 0x1ff4  FreeOTFECypherDES ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0538 0x1ff4  FreeOTFECypherMARS_Gladman ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0538 0x1ff4  FreeOTFECypherMARS_Gladman ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0540 0x1ff4  FreeOTFECypherRC6_ltc ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0540 0x1ff4  FreeOTFECypherRC6_ltc ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0542 0x1ff4  FreeOTFECypherSerpent_Gladman ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0542 0x1ff4  FreeOTFECypherSerpent_Gladman ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0544 0x1ff4  FreeOTFECypherTwofish_ltc ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0544 0x1ff4  FreeOTFECypherTwofish_ltc ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0546 0x1ff4  FreeOTFEHashMD ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0546 0x1ff4  FreeOTFEHashMD ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0548 0x1ff4  FreeOTFEHashRIPEMD ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0548 0x1ff4  FreeOTFEHashRIPEMD ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0550 0x1ff4  FreeOTFEHashSHA ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0550 0x1ff4  FreeOTFEHashSHA ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0552 0x1ff4  FreeOTFEHashTiger ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0552 0x1ff4  FreeOTFEHashTiger ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0555 0x1ff4  FreeOTFEHashWhirlpool ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0555 0x1ff4  FreeOTFEHashWhirlpool ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0557 0x1ff4  i8042prt ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0557 0x1ff4  i8042prt ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0559 0x1ff4  monitor ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0559 0x1ff4  monitor ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0561 0x1ff4  NdisWan ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0561 0x1ff4  NdisWan ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0563 0x1ff4  Power ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0563 0x1ff4  Power ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0565 0x1ff4  RpcEptMapper ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0565 0x1ff4  RpcEptMapper ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0567 0x1ff4  Smb ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0567 0x1ff4  Smb ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0569 0x1ff4  TrustedInstaller ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0569 0x1ff4  TrustedInstaller ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0571 0x1ff4  VgaSave ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0571 0x1ff4  VgaSave ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:05:48.0573 0x1ff4  wmiApSrv ( UnsignedFile.Multi.Generic ) - skipped by user
13:05:48.0573 0x1ff4  wmiApSrv ( UnsignedFile.Multi.Generic ) - User select action: Skip 
13:06:01.0511 0x0810  Deinitialize success


#13 OCD

OCD

    SuperHelper

  • Malware Team
  • 5,574 posts

Posted 11 December 2014 - 09:55 PM

Hi BrotherPorter,

Here is some information about the winsxs folder.
https://support.micr...b/2795190/en-us

Here is some information about FreeOTFE:
FreeOTFE is a discontinued open source computer program for on-the-fly disk encryption (OTFE). On Microsoft Windows, and Windows Mobile (using FreeOTFE4PDA), it can create a virtual drive within a file or partition, to which anything written is automatically encrypted before being stored on a computer's hard or USB drive. It is similar in function to other disk encryption programs including TrueCrypt and Microsoft's BitLocker.[2]

=========================

bullseye_zpse9eaf36e.gif Re-run TDSSKiller

  • TDSSKiller.exe
    • Windows XP : Double click on the icon to run it.
    • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
    Select Change Parameters.

    TDSS-1_zpsf463732c.gif

    Under Additional Options, select all options. The select OK.

    TDSS-2_zpsb54cc24f.gif

    Next press the Start Scan button.

    TDSS-3_zpsb6ee4ebd.gif
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
  • =========================

    In your next post please provide the following:
    • TDSSKiller log

OCD

Proud Graduate of WTT Classroom
Member of UNITE

Threads will be closed if no response after 5 days








If you are satisfied with the help you have received, please consider making a donation.


#14 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 12 December 2014 - 10:34 AM

2014-07-27 20:35:58, Info                  DISM   PID=3244 Scratch directory set to 'C:\Users\BROPOR~1\AppData\Local\Temp\'. - CDISMManager::put_ScratchDir
2014-07-27 20:35:58, Info                  DISM   PID=3244 Successfully loaded the ImageSession at "C:\Windows\System32\Dism" - CDISMManager::LoadImageSession
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Failed to get and initialize the PE Provider.  Continuing by assuming that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Manager: PID=3244 Successfully created the local image session and provider store. - CDISMManager::CreateLocalImageSession
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM.EXE: 
2014-07-27 20:35:58, Info                  DISM   DISM.EXE: <----- Starting Dism.exe session ----->
2014-07-27 20:35:58, Info                  DISM   DISM.EXE: 
2014-07-27 20:35:58, Info                  DISM   DISM.EXE: Host machine information: OS Version=6.1.7600, Running architecture=x86, Number of processors=4
2014-07-27 20:35:58, Info                  DISM   DISM.EXE: Executing command line: C:\Windows\system32\dism.exe /online /add-package /packagepath:C:\Windows\TEMP\IE9A7D2.tmp\KB2454826_x86\Windows6.1-KB2454826-v2-x86.cab /quiet /norestart
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Getting Provider FolderManager - CDISMProviderStore::GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Loading Provider from location C:\Windows\System32\Dism\FolderProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Connecting to the provider located at C:\Windows\System32\Dism\FolderProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Getting Provider FolderManager - CDISMProviderStore::GetProvider
2014-07-27 20:35:58, Info                  DISM   DISM Provider Store: PID=3244 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Manager: PID=3244 Successfully loaded the ImageSession at "C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3" - CDISMManager::LoadImageSession
2014-07-27 20:35:59, Info                  DISM   DISM Image Session: PID=4428 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Initializing a provider store for the IMAGE session type. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\OSProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\OSProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM OS Provider: PID=4428 Defaulting SystemPath to C:\ - CDISMOSServiceManager::Final_OnConnect
2014-07-27 20:35:59, Info                  DISM   DISM OS Provider: PID=4428 Defaulting Windows folder to C:\Windows - CDISMOSServiceManager::Final_OnConnect
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\LogProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\LogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Getting Provider OSServices - CDISMProviderStore::GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\PEProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Warning               DISM   DISM Provider Store: PID=4428 Failed to Load the provider: C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\PEProvider.dll. - CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Failed to get and initialize the PE Provider.  Continuing by assuming that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Manager: PID=3244 Image session successfully loaded from the temporary location: C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3 - CDISMManager::CreateImageSession
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Getting Provider OSServices - CDISMProviderStore::GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:35:59, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Target image information: OS Version=6.1.7600.16385, Image architecture=x86
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Getting the collection of providers from an image provider store type. - CDISMProviderStore::GetProviderCollection
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\CbsProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\CbsProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:35:59, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Finished initializing the CbsConUI Handler. - CCbsConUIHandler::Initialize
2014-07-27 20:35:59, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:35:59, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 CBS is being initialized for online use. More information about CBS actions can be located at: %windir%\logs\cbs\cbs.log - CDISMPackageManager::Initialize
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Loaded servicing stack for online use only. - CDISMPackageManager::RefreshInstanceAndLock
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\MsiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\MsiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\IntlProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\IntlProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\DmiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\DmiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:35:59, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:35:59, Info                  DISM   DISM OS Provider: PID=4428 Successfully loaded the hive. - CDISMOSServiceManager::DetermineBootDrive
2014-07-27 20:35:59, Info                  DISM   DISM Driver Manager: PID=4428 Further logs for driver related operations can be found in the target operating system at %WINDIR%\inf\setupapi.offline.log - CDriverManager::Initialize
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\UnattendProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\UnattendProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\SmiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\SmiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\TransmogProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\2241C774-5F60-4253-B491-6253144CB3D3\TransmogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Getting Provider DISM Package Manager - CDISMProviderStore::GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Getting Provider DISM Unattend Manager - CDISMProviderStore::GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Got the collection of providers. Now enumerating them to build the command table.
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DISM Package Manager
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: DISM Package Manager.
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: OSServices
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: MsiManager
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: MsiManager.
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: IntlManager
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: IntlManager.
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DriverManager
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: DriverManager.
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DISM Unattend Manager
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: DISM Unattend Manager.
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DISM Log Provider
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: SmiManager
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: Edition Manager
2014-07-27 20:35:59, Info                  DISM   DISM Transmog Provider: PID=4428 Current image session is [ONLINE] - CTransmogManager::GetMode
2014-07-27 20:35:59, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: Edition Manager.
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Getting Provider DISM Package Manager - CDISMProviderStore::GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Provider Store: PID=4428 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Processing the top level command token(add-package). - CPackageManagerCLIHandler::Private_ValidateCmdLine
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Attempting to route to appropriate command handler. - CPackageManagerCLIHandler::ExecuteCmdLine
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Routing the command... - CPackageManagerCLIHandler::ExecuteCmdLine
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Encountered the option "packagepath" with value "C:\Windows\TEMP\IE9A7D2.tmp\KB2454826_x86\Windows6.1-KB2454826-v2-x86.cab" - CPackageManagerCLIHandler::Private_GetPackagesFromCommandLine
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Package Package_for_KB2454826~31bf3856ad364e35~x86~~6.1.2.0 with CBS state 0(CbsInstallStateAbsent) being mapped to dism state 1(DISM_INSTALL_STATE_NOTPRESENT) - CDISMPackage::LogInstallStateMapping
2014-07-27 20:35:59, Info                  DISM   DISM Package Manager: PID=4428 Initiating Changes on Package with values: 4, 7 - CDISMPackage::Internal_ChangePackageState
2014-07-27 20:36:20, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:36:20, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:36:20, Info                  DISM   DISM Package Manager: PID=4428 CBS has requested a shutdown. - CDISMPackageManager::Internal_Finalize
2014-07-27 20:36:20, Info                  DISM   DISM Package Manager: PID=4428 DISM has detected a DISM component change. Requesting a shutdown. - CDISMPackageManager::Internal_Finalize
2014-07-27 20:36:20, Info                  DISM   DISM Image Session: PID=4428 The image requries a reboot. - CDISMImageSession::put_ImageState
2014-07-27 20:36:20, Info                  DISM   DISM Image Session: PID=4428 Disconnecting the provider store - CDISMImageSession::Final_OnDisconnect
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Finalizing the servicing provider(DISM Package Manager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Package Manager: PID=4428 Finalizing CBS core. - CDISMPackageManager::Finalize
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: DISM Package Manager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Found the OSServices.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Finalizing the servicing provider(MsiManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: MsiManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Finalizing the servicing provider(IntlManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: IntlManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Found the PE Provider.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Finalizing the servicing provider(DriverManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: DriverManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Finalizing the servicing provider(DISM Unattend Manager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: DISM Unattend Manager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Found the OSServices.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Finalizing the servicing provider(SmiManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: SmiManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Finalizing the servicing provider(Edition Manager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: Edition Manager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Releasing the local reference to OSServices. - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Disconnecting Provider: OSServices - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=4428 Releasing the local reference to DISMLogger.  Stop logging. - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM.EXE: Image session has been closed. Reboot required=yes.
2014-07-27 20:36:20, Info                  DISM   DISM.EXE: Restart suppressed by /NoRestart command line switch.
2014-07-27 20:36:20, Info                  DISM   DISM.EXE: 
2014-07-27 20:36:20, Info                  DISM   DISM.EXE: <----- Ending Dism.exe session ----->
2014-07-27 20:36:20, Info                  DISM   DISM.EXE: 
2014-07-27 20:36:20, Info                  DISM   DISM Image Session: PID=3244 Disconnecting the provider store - CDISMImageSession::Final_OnDisconnect
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=3244 Disconnecting Provider: FolderManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=3244 Found the OSServices.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:20, Info                  DISM   DISM Provider Store: PID=3244 Releasing the local reference to DISMLogger.  Stop logging. - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:22, Info                  DISM   PID=716 Scratch directory set to 'C:\Users\BROPOR~1\AppData\Local\Temp\'. - CDISMManager::put_ScratchDir
2014-07-27 20:36:22, Info                  DISM   PID=716 Successfully loaded the ImageSession at "C:\Windows\System32\Dism" - CDISMManager::LoadImageSession
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Failed to get and initialize the PE Provider.  Continuing by assuming that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Manager: PID=716 Successfully created the local image session and provider store. - CDISMManager::CreateLocalImageSession
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: 
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: <----- Starting Dism.exe session ----->
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: 
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Host machine information: OS Version=6.1.7600, Running architecture=x86, Number of processors=4
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Executing command line: C:\Windows\system32\dism.exe /online /add-package /packagepath:C:\Windows\TEMP\IE9A7D2.tmp\IE9-neutral.Downloaded\IE9-Windows6.1-KB982861-x86.cab /quiet /norestart
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Getting Provider FolderManager - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Loading Provider from location C:\Windows\System32\Dism\FolderProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Connecting to the provider located at C:\Windows\System32\Dism\FolderProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Getting Provider FolderManager - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=716 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Manager: PID=716 Successfully loaded the ImageSession at "C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82" - CDISMManager::LoadImageSession
2014-07-27 20:36:22, Info                  DISM   DISM Image Session: PID=4156 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Initializing a provider store for the IMAGE session type. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\OSProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\OSProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM OS Provider: PID=4156 Defaulting SystemPath to C:\ - CDISMOSServiceManager::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM OS Provider: PID=4156 Defaulting Windows folder to C:\Windows - CDISMOSServiceManager::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\LogProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\LogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Getting Provider OSServices - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\PEProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Warning               DISM   DISM Provider Store: PID=4156 Failed to Load the provider: C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\PEProvider.dll. - CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Failed to get and initialize the PE Provider.  Continuing by assuming that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Manager: PID=716 Image session successfully loaded from the temporary location: C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82 - CDISMManager::CreateImageSession
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Getting Provider OSServices - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:36:22, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Target image information: OS Version=6.1.7600.16385, Image architecture=x86
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Getting the collection of providers from an image provider store type. - CDISMProviderStore::GetProviderCollection
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\CbsProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\CbsProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:36:22, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Finished initializing the CbsConUI Handler. - CCbsConUIHandler::Initialize
2014-07-27 20:36:22, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:36:22, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 CBS is being initialized for online use. More information about CBS actions can be located at: %windir%\logs\cbs\cbs.log - CDISMPackageManager::Initialize
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Loaded servicing stack for online use only. - CDISMPackageManager::RefreshInstanceAndLock
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\MsiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\MsiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\IntlProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\IntlProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\DmiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\DmiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:36:22, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:36:22, Info                  DISM   DISM OS Provider: PID=4156 Successfully loaded the hive. - CDISMOSServiceManager::DetermineBootDrive
2014-07-27 20:36:22, Info                  DISM   DISM Driver Manager: PID=4156 Further logs for driver related operations can be found in the target operating system at %WINDIR%\inf\setupapi.offline.log - CDriverManager::Initialize
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\UnattendProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\UnattendProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\SmiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\SmiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\TransmogProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\334BB893-9179-49DC-A2BC-A04D4A6A6B82\TransmogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Getting Provider DISM Package Manager - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Getting Provider DISM Unattend Manager - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Got the collection of providers. Now enumerating them to build the command table.
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DISM Package Manager
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: DISM Package Manager.
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: OSServices
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: MsiManager
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: MsiManager.
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: IntlManager
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: IntlManager.
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DriverManager
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: DriverManager.
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DISM Unattend Manager
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: DISM Unattend Manager.
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DISM Log Provider
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: SmiManager
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: Edition Manager
2014-07-27 20:36:22, Info                  DISM   DISM Transmog Provider: PID=4156 Current image session is [ONLINE] - CTransmogManager::GetMode
2014-07-27 20:36:22, Info                  DISM   DISM.EXE: Succesfully registered commands for the provider: Edition Manager.
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Getting Provider DISM Package Manager - CDISMProviderStore::GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Provider Store: PID=4156 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Processing the top level command token(add-package). - CPackageManagerCLIHandler::Private_ValidateCmdLine
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Attempting to route to appropriate command handler. - CPackageManagerCLIHandler::ExecuteCmdLine
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Routing the command... - CPackageManagerCLIHandler::ExecuteCmdLine
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Encountered the option "packagepath" with value "C:\Windows\TEMP\IE9A7D2.tmp\IE9-neutral.Downloaded\IE9-Windows6.1-KB982861-x86.cab" - CPackageManagerCLIHandler::Private_GetPackagesFromCommandLine
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Package Microsoft-Windows-InternetExplorer-Package-TopLevel~31bf3856ad364e35~x86~~9.4.8112.16421 with CBS state 0(CbsInstallStateAbsent) being mapped to dism state 1(DISM_INSTALL_STATE_NOTPRESENT) - CDISMPackage::LogInstallStateMapping
2014-07-27 20:36:22, Info                  DISM   DISM Package Manager: PID=4156 Initiating Changes on Package with values: 4, 7 - CDISMPackage::Internal_ChangePackageState
2014-07-27 20:36:54, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-27 20:36:54, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7600.16385_none_0935b76c289e0fd5\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-27 20:36:54, Info                  DISM   DISM Package Manager: PID=4156 CBS has requested a shutdown. - CDISMPackageManager::Internal_Finalize
2014-07-27 20:36:54, Info                  DISM   DISM Package Manager: PID=4156 DISM has detected a DISM component change. Requesting a shutdown. - CDISMPackageManager::Internal_Finalize
2014-07-27 20:36:54, Info                  DISM   DISM Image Session: PID=4156 The image requries a reboot. - CDISMImageSession::put_ImageState
2014-07-27 20:36:54, Info                  DISM   DISM Image Session: PID=4156 Disconnecting the provider store - CDISMImageSession::Final_OnDisconnect
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Finalizing the servicing provider(DISM Package Manager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Package Manager: PID=4156 Finalizing CBS core. - CDISMPackageManager::Finalize
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: DISM Package Manager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Found the OSServices.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Finalizing the servicing provider(MsiManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: MsiManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Finalizing the servicing provider(IntlManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: IntlManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Found the PE Provider.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Finalizing the servicing provider(DriverManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: DriverManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Finalizing the servicing provider(DISM Unattend Manager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: DISM Unattend Manager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Found the OSServices.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Finalizing the servicing provider(SmiManager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: SmiManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Finalizing the servicing provider(Edition Manager) - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: Edition Manager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Releasing the local reference to OSServices. - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Disconnecting Provider: OSServices - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=4156 Releasing the local reference to DISMLogger.  Stop logging. - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM.EXE: Image session has been closed. Reboot required=yes.
2014-07-27 20:36:54, Info                  DISM   DISM.EXE: Restart suppressed by /NoRestart command line switch.
2014-07-27 20:36:54, Info                  DISM   DISM.EXE: 
2014-07-27 20:36:54, Info                  DISM   DISM.EXE: <----- Ending Dism.exe session ----->
2014-07-27 20:36:54, Info                  DISM   DISM.EXE: 
2014-07-27 20:36:54, Info                  DISM   DISM Image Session: PID=716 Disconnecting the provider store - CDISMImageSession::Final_OnDisconnect
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=716 Disconnecting Provider: FolderManager - CDISMProviderStore::Internal_DisconnectProvider
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=716 Found the OSServices.  Waiting to finalize it until all other providers are unloaded. - CDISMProviderStore::Final_OnDisconnect
2014-07-27 20:36:54, Info                  DISM   DISM Provider Store: PID=716 Releasing the local reference to DISMLogger.  Stop logging. - CDISMProviderStore::Internal_DisconnectProvider
2014-07-28 12:18:57, Info                  DISM   PID=6396 Scratch directory set to 'C:\Users\BROPOR~1\AppData\Local\Temp\'. - CDISMManager::put_ScratchDir
2014-07-28 12:18:57, Info                  DISM   PID=6396 Successfully loaded the ImageSession at "C:\Windows\System32\Dism" - CDISMManager::LoadImageSession
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Failed to get and initialize the PE Provider.  Continuing by assuming that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Manager: PID=6396 Successfully created the local image session and provider store. - CDISMManager::CreateLocalImageSession
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM.EXE: 
2014-07-28 12:18:57, Info                  DISM   DISM.EXE: <----- Starting Dism.exe session ----->
2014-07-28 12:18:57, Info                  DISM   DISM.EXE: 
2014-07-28 12:18:57, Info                  DISM   DISM.EXE: Host machine information: OS Version=6.1.7601, Running architecture=x86, Number of processors=4
2014-07-28 12:18:57, Info                  DISM   DISM.EXE: Executing command line: C:\Windows\System32\dism.exe /online /add-package /packagepath:C:\Windows\TEMP\IE1218.tmp\KB2834140\Windows6.1-KB2834140-v2-x86.cab /quiet /norestart
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Getting Provider FolderManager - CDISMProviderStore::GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Loading Provider from location C:\Windows\System32\Dism\FolderProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Connecting to the provider located at C:\Windows\System32\Dism\FolderProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Getting Provider FolderManager - CDISMProviderStore::GetProvider
2014-07-28 12:18:57, Info                  DISM   DISM Provider Store: PID=6396 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Manager: PID=6396 Successfully loaded the ImageSession at "C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F" - CDISMManager::LoadImageSession
2014-07-28 12:18:59, Info                  DISM   DISM Image Session: PID=6516 Instantiating the Provider Store. - CDISMImageSession::get_ProviderStore
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Initializing a provider store for the IMAGE session type. - CDISMProviderStore::Final_OnConnect
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\OSProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\OSProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:18:59, Info                  DISM   DISM OS Provider: PID=6516 Defaulting SystemPath to C:\ - CDISMOSServiceManager::Final_OnConnect
2014-07-28 12:18:59, Info                  DISM   DISM OS Provider: PID=6516 Defaulting Windows folder to C:\Windows - CDISMOSServiceManager::Final_OnConnect
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Attempting to initialize the logger from the Image Session. - CDISMProviderStore::Final_OnConnect
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\LogProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\LogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Getting Provider OSServices - CDISMProviderStore::GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Found and Initialized the DISM Logger. - CDISMProviderStore::Internal_InitializeLogger
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\PEProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Warning               DISM   DISM Provider Store: PID=6516 Failed to Load the provider: C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\PEProvider.dll. - CDISMProviderStore::Internal_GetProvider(hr:0x8007007e)
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Failed to get and initialize the PE Provider.  Continuing by assuming that it is not a WinPE image. - CDISMProviderStore::Final_OnConnect
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Finished initializing the Provider Map. - CDISMProviderStore::Final_OnConnect
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Getting Provider DISMLogger - CDISMProviderStore::GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Manager: PID=6396 Image session successfully loaded from the temporary location: C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F - CDISMManager::CreateImageSession
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Getting Provider OSServices - CDISMProviderStore::GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-28 12:18:59, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-28 12:18:59, Info                  DISM   DISM.EXE: Target image information: OS Version=6.1.7601.17592, Image architecture=x86
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Getting the collection of providers from an image provider store type. - CDISMProviderStore::GetProviderCollection
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\CbsProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\CbsProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:18:59, Info                  DISM   DISM Provider Store: PID=6516 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:18:59, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-28 12:18:59, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-28 12:19:00, Info                  DISM   DISM Package Manager: PID=6516 Finished initializing the CbsConUI Handler. - CCbsConUIHandler::Initialize
2014-07-28 12:19:00, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-28 12:19:00, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-28 12:19:00, Info                  DISM   DISM Package Manager: PID=6516 CBS is being initialized for online use. More information about CBS actions can be located at: %windir%\logs\cbs\cbs.log - CDISMPackageManager::Initialize
2014-07-28 12:19:00, Info                  DISM   DISM Package Manager: PID=6516 Loaded servicing stack for online use only. - CDISMPackageManager::RefreshInstanceAndLock
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\MsiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\MsiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\IntlProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\IntlProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\DmiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\DmiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  CSI    00000001 Shim considered [l:252{126}]"\??\C:\Windows\Servicing\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_OBJECT_PATH_NOT_FOUND
2014-07-28 12:19:00, Info                  CSI    00000002 Shim considered [l:246{123}]"\??\C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_6.1.7601.17592_none_0b0e4b4025cf4049\pkgmgr.exe" : got STATUS_SUCCESS
2014-07-28 12:19:00, Info                  DISM   DISM OS Provider: PID=6516 Successfully loaded the hive. - CDISMOSServiceManager::DetermineBootDrive
2014-07-28 12:19:00, Info                  DISM   DISM Driver Manager: PID=6516 Further logs for driver related operations can be found in the target operating system at %WINDIR%\inf\setupapi.offline.log - CDriverManager::Initialize
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\UnattendProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\UnattendProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\SmiProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\SmiProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has not previously been encountered.  Attempting to initialize the provider. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Loading Provider from location C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\TransmogProvider.dll - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Connecting to the provider located at C:\Users\BROPOR~1\AppData\Local\Temp\52AAE85E-60D6-4161-8E50-3FD44785817F\TransmogProvider.dll. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Encountered a servicing provider, performing additional servicing initializations. - CDISMProviderStore::Internal_LoadProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Getting Provider DISM Package Manager - CDISMProviderStore::GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Getting Provider DISM Unattend Manager - CDISMProviderStore::GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM Provider Store: PID=6516 Provider has previously been initialized.  Returning the existing instance. - CDISMProviderStore::Internal_GetProvider
2014-07-28 12:19:00, Info                  DISM   DISM.EXE: Got the collection of providers. Now enumerating them to build the command table.
2014-07-28 12:19:00, Info                  DISM   DISM.EXE: Attempting to add the commands from provider: DISM Package Manager
20-----------------------------------------------------
said post was too long for the rest


#15 BrotherPorter

BrotherPorter

    Authentic Member

  • Authentic Member
  • PipPip
  • 24 posts

Posted 12 December 2014 - 10:48 AM

i will rerun the tdss, originally when I ran it above the text I just did above it said 38 threats but didn't offer to quarantine and mostly windows errors. it won't let me connect  i am at library. I will get on library again. The control panel troubleshooter won't work since last night now and I did sfc /scannow and copied cbs.log but they prevented me from copying it from hdd to flash so I can't print it here. I will try to come into library early tomorrow if we don't get our snow storm. Please leave some requests. I know they are trying to add network p2p stuff even though I've pulled the wireless adapter and just running the onboard LAN and using a 5 port fast ethernet switch.


Edited by BrotherPorter, 12 December 2014 - 10:51 AM.

Related Topics




Also tagged with one or more of these keywords: Windows redirect, SSDT, keylogger, rootkits, active, ssdt, hooks, rootkit, redirecting windows directori

1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users