Author Topic: [Resolved - K] Slow boot, slow application launch, slow browser  (Read 4832 times)

Offline Canoo

  • Bronze Member
  • Posts: 42
I have not had any luck finding viruses or any malware but my system seems to be very slow. This is a recent occurence. I can't remember any new software I installed except for windows updates. I run McAfee Security Center and I ran Malwarebytes Anti Malware earlier today. No malware was detected. My symptoms include: very slow to boot, slow to launch applications, slow browser (IE and Chrome), slow to switch application, seems like slow everything.

Thank you for any help you can provide.


DDS (Ver_2012-11-20.01) - NTFS_x86
Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.71.2
Run by Kelsie at 21:55:43 on 2015-08-11
.
============== Running Processes ================
.
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AOMEI Backupper\ABService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\system32\FsUsbExService.Exe
C:\Program Files\Java\jre7\bin\jqs.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe
C:\WINDOWS\system32\mfevtps.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\System32\StkASv2K.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\McAfee\MSC\McAPExe.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
c:\PROGRA~1\mcafee\msc\mcupdmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k rpcss
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k imgsvc
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uURLSearchHooks: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: DriveLetterAccess: {5CA3D70E-1895-11CF-8E15-001234567890} - c:\windows\system32\dla\tfswshx.dll
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\program files\java\jre7\bin\ssv.dll
BHO: McAfee SiteAdvisor BHO: {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - c:\program files\java\jre7\bin\jp2ssv.dll
TB: McAfee SiteAdvisor Toolbar: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [dla] c:\windows\system32\dla\tfswctrl.exe
mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\ISUSPM.exe" -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [RemoteControl] "c:\program files\cyberlink\powerdvd\PDVDServ.exe"
mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\stsystra.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [IntelZeroConfig] "c:\program files\intel\wireless\bin\ZCfgSvc.exe"
mRun: [IntelWireless] "c:\program files\intel\wireless\bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [mcpltui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
mRun: [UVS10 Preload] c:\program files\ulead systems\ulead videostudio se dvd\uvPL.exe
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
mRun: [ShowLOMControl] 
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [KernelFaultCheck] c:\windows\system32\dumprep 0 -k
mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
mRun: [ehTray] c:\windows\ehome\ehtray.exe
mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
uPolicies-Explorer: NoDriveTypeAutoRun = dword:323
uPolicies-Explorer: NoDriveAutoRun = dword:67108863
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDrives = dword:0
mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1
mPolicies-Explorer: NoDriveTypeAutoRun = dword:323
mPolicies-Explorer: NoDriveAutoRun = dword:67108863
IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - c:\program files\pokerstars\PokerStarsUpdate.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} - hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} - hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1354990920625
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} - hxxp://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} - hxxp://sympatico.zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} - hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} - hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab
TCP: NameServer = 192.168.1.254
TCP: Interfaces\{0948C638-1EE9-4A6F-A2BA-C3EA1D729236} : DHCPNameServer = 192.168.1.254
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\program files\mcafee\msc\McSnIePl.dll
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\program files\mcafee\siteadvisor\McIEPlg.dll
Notify: igfxcui - igfxdev.dll
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "c:\program files\google\chrome\application\44.0.2403.155\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
.
============= SERVICES / DRIVERS ===============
.
2 mcbootdelaystartsvc;McAfee Boot Delay Start Service
R? ampa;ampa
R? cfwids;McAfee Inc. cfwids
R? mfebopk;McAfee Inc. mfebopk
R? mfencrk;McAfee Inc. mfencrk
R? mfendisk;McAfee Core NDIS Intermediate Filter
S? ambakdrv;ambakdrv
S? ammntdrv;ammntdrv
S? amwrtdrv;amwrtdrv
S? Backupper Service;AOMEI Backupper Scheduler Service
S? FsUsbExDisk;FsUsbExDisk
S? FsUsbExService;FsUsbExService
S? HomeNetSvc;McAfee Home Network
S? MBAMProtector;MBAMProtector
S? MBAMScheduler;MBAMScheduler
S? MBAMService;MBAMService
S? MBAMSwissArmy;MBAMSwissArmy
S? McAfee SiteAdvisor Service;McAfee SiteAdvisor Service
S? McAPExe;McAfee AP Service
S? McNaiAnn;McAfee VirusScan Announcer
S? mcpltsvc;McAfee Platform Services
S? McProxy;McAfee Proxy Service
S? McrdSvc;Media Center Extender Service
S? mfeavfk;McAfee Inc. mfeavfk
S? mfecore;McAfee Anti-Malware Core
S? mfefire;McAfee Firewall Core Service
S? mfefirek;McAfee Inc. mfefirek
S? mfehidk;McAfee Inc. mfehidk
S? mfencbdc;McAfee Inc. mfencbdc
S? mfendiskmp;mfendiskmp
S? mfetdi2k;McAfee Inc. mfetdi2k
S? mfevtp;McAfee Validation Trust Protection Service
.
=============== Created Last 30 ================
.
2015-08-11 09:34:55   98520   ----a-w-   c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-11 09:28:07   121560   ----a-w-   c:\windows\system32\drivers\mbamchameleon.sys
2015-08-11 09:28:07   --------   d-----w-   c:\program files\Malwarebytes Anti-Malware
.
==================== Find3M  ====================
.
2015-06-18 12:41:36   23256   ----a-w-   c:\windows\system32\drivers\mbam.sys
.
============= FINISH: 22:35:41.17 ===============




.
==== Installed Programs ======================
.
6300
6300_Help
6300Trb
Adobe Flash Player 15 ActiveX
Adobe Reader 8.3.1
Adobe Shockwave Player 11.5
AiO_Scan_CDA
AiOSoftwareNPI
AOMEI Backupper
AOMEI Partition Assistant Standard Edition 5.5
Apple Application Support
Apple Mobile Device Support
Apple Software Update
Banctec Service Agreement
Bluetooth Stack for Windows by Toshiba
Bonjour
Broadcom Management Programs
BufferChm
Compatibility Pack for the 2007 Office system
Conexant HDA D110 MDC V.92 Modem
Corel Photo Album 6
Curious George Learning Games
Dell Digital Jukebox Driver
Dell Driver Download Manager
Dell System Restore
DellSupport
Destinations
DeviceManagementQFolder
Digital Content Portal
Digital Line Detect
Documentation & Support Launcher
DocumentViewer
DocumentViewerQFolder
EducateU
ESPNMotion
eSupportQFolder
Fax_CDA
Fender FUSE
Fender FUSE 2.7.1.44
Games, Music, & Photos Launcher
GemMaster Mystic
Google Chrome
Google Update Helper
High Definition Audio Driver Package - KB835221
HiJackThis
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB2158563)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB2570791)
Hotfix for Windows XP (KB2633952)
Hotfix for Windows XP (KB2756822)
Hotfix for Windows XP (KB2779562)
Hotfix for Windows XP (KB915800-v4)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB961118)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
HP Document Viewer 7.0
HP Imaging Device Functions 7.0
HP Photosmart, Officejet and Deskjet 7.0.A
HP Solution Center 7.0
HP Update
HPPhotoSmartExpress
HPProductAssistant
InstantShareDevicesMFC
Intel(R) Graphics Media Accelerator Driver
Intel(R) Processor ID Utility
Intel(R) PROSet/Wireless Software
Internal Network Card Power Management
iTunes
Java 7 Update 71
Java Auto Updater
Learn2 Player (Uninstall Only)
Malwarebytes Anti-Malware version 2.1.8.1057
McAfee SecurityCenter
McAfee SiteAdvisor
McAfee Virtual Technician
mCore
MCU
mDriver
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.0 Hotfix (KB2572066)
Microsoft .NET Framework 1.0 Hotfix (KB2604042)
Microsoft .NET Framework 1.0 Hotfix (KB2656378)
Microsoft .NET Framework 1.0 Hotfix (KB953295)
Microsoft .NET Framework 1.0 Hotfix (KB979904)
Microsoft .NET Framework 1.0 Security Update (KB2698035)
Microsoft .NET Framework 1.0 Security Update (KB2742607)
Microsoft .NET Framework 1.0 Security Update (KB2833951)
Microsoft .NET Framework 1.0 Security Update (KB2904878)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Security Update (KB2698023)
Microsoft .NET Framework 1.1 Security Update (KB2833941)
Microsoft .NET Framework 1.1 Security Update (KB979906)
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft Application Error Reporting
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office File Validation Add-In
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Silverlight
mIWA
mLogView
mMHouse
Modem Helper
Move Media Player
mPfMgr
mPfWiz
mProSafe
mSCfg
mSSO
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
mWlsSafe
mWMI
mZConfig
NetWaiting
NewCopy_CDA
Octoshape add-in for Adobe Flash Player
Otto
PanoStandAlone
PC Connectivity Solution
Picture Package Music Transfer
PokerStars
PowerDirector Express
PowerDVD
PowerProducer
ProductContextNPI
QuickSet
QuickTime
Readme
RealPlayer Basic
SAMSUNG Mobile Composite Device Software
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Samsung New PC Studio
SamsungConnectivityCableDriver
Scan
ScannerCopy
SCRABBLE
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697)
Security Update for Microsoft Windows (KB2564958)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 7 (KB956390)
Security Update for Windows Internet Explorer 7 (KB958215)
Security Update for Windows Internet Explorer 7 (KB960714)
Security Update for Windows Internet Explorer 7 (KB961260)
Security Update for Windows Internet Explorer 7 (KB963027)
Security Update for Windows Internet Explorer 7 (KB969897)
Security Update for Windows Internet Explorer 7 (KB972260)
Security Update for Windows Internet Explorer 7 (KB974455)
Security Update for Windows Internet Explorer 7 (KB976325)
Security Update for Windows Internet Explorer 7 (KB978207)
Security Update for Windows Internet Explorer 8 (KB2183461)
Security Update for Windows Internet Explorer 8 (KB2360131)
Security Update for Windows Internet Explorer 8 (KB2416400)
Security Update for Windows Internet Explorer 8 (KB2482017)
Security Update for Windows Internet Explorer 8 (KB2497640)
Security Update for Windows Internet Explorer 8 (KB2510531)
Security Update for Windows Internet Explorer 8 (KB2530548)
Security Update for Windows Internet Explorer 8 (KB2544521)
Security Update for Windows Internet Explorer 8 (KB2559049)
Security Update for Windows Internet Explorer 8 (KB2586448)
Security Update for Windows Internet Explorer 8 (KB2618444)
Security Update for Windows Internet Explorer 8 (KB2647516)
Security Update for Windows Internet Explorer 8 (KB2675157)
Security Update for Windows Internet Explorer 8 (KB2699988)
Security Update for Windows Internet Explorer 8 (KB2722913)
Security Update for Windows Internet Explorer 8 (KB2744842)
Security Update for Windows Internet Explorer 8 (KB2761465)
Security Update for Windows Internet Explorer 8 (KB2792100)
Security Update for Windows Internet Explorer 8 (KB2797052)
Security Update for Windows Internet Explorer 8 (KB2799329)
Security Update for Windows Internet Explorer 8 (KB2809289)
Security Update for Windows Internet Explorer 8 (KB2817183)
Security Update for Windows Internet Explorer 8 (KB2829530)
Security Update for Windows Internet Explorer 8 (KB2838727)
Security Update for Windows Internet Explorer 8 (KB2846071)
Security Update for Windows Internet Explorer 8 (KB2847204)
Security Update for Windows Internet Explorer 8 (KB2862772)
Security Update for Windows Internet Explorer 8 (KB2870699)
Security Update for Windows Internet Explorer 8 (KB2879017)
Security Update for Windows Internet Explorer 8 (KB2888505)
Security Update for Windows Internet Explorer 8 (KB2898785)
Security Update for Windows Internet Explorer 8 (KB2909210)
Security Update for Windows Internet Explorer 8 (KB2909921)
Security Update for Windows Internet Explorer 8 (KB2925418)
Security Update for Windows Internet Explorer 8 (KB2936068)
Security Update for Windows Internet Explorer 8 (KB2964358)
Security Update for Windows Internet Explorer 8 (KB971961)
Security Update for Windows Internet Explorer 8 (KB981332)
Security Update for Windows Internet Explorer 8 (KB982381)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB2834905-v2)
Security Update for Windows Media Player (KB2834905)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Search 4 - KB963093
Security Update for Windows XP (KB2079403)
Security Update for Windows XP (KB2115168)
Security Update for Windows XP (KB2121546)
Security Update for Windows XP (KB2160329)
Security Update for Windows XP (KB2229593)
Security Update for Windows XP (KB2259922)
Security Update for Windows XP (KB2279986)
Security Update for Windows XP (KB2286198)
Security Update for Windows XP (KB2296011)
Security Update for Windows XP (KB2296199)
Security Update for Windows XP (KB2347290)
Security Update for Windows XP (KB2360937)
Security Update for Windows XP (KB2387149)
Security Update for Windows XP (KB2393802)
Security Update for Windows XP (KB2412687)
Security Update for Windows XP (KB2419632)
Security Update for Windows XP (KB2423089)
Security Update for Windows XP (KB2436673)
Security Update for Windows XP (KB2440591)
Security Update for Windows XP (KB2443105)
Security Update for Windows XP (KB2476490)
Security Update for Windows XP (KB2476687)
Security Update for Windows XP (KB2478960)
Security Update for Windows XP (KB2478971)
Security Update for Windows XP (KB2479628)
Security Update for Windows XP (KB2481109)
Security Update for Windows XP (KB2483185)
Security Update for Windows XP (KB2485376)
Security Update for Windows XP (KB2485663)
Security Update for Windows XP (KB2503658)
Security Update for Windows XP (KB2503665)
Security Update for Windows XP (KB2506212)
Security Update for Windows XP (KB2506223)
Security Update for Windows XP (KB2507618)
Security Update for Windows XP (KB2507938)
Security Update for Windows XP (KB2508272)
Security Update for Windows XP (KB2508429)
Security Update for Windows XP (KB2509553)
Security Update for Windows XP (KB2511455)
Security Update for Windows XP (KB2524375)
Security Update for Windows XP (KB2535512)
Security Update for Windows XP (KB2536276-v2)
Security Update for Windows XP (KB2536276)
Security Update for Windows XP (KB2544893-v2)
Security Update for Windows XP (KB2544893)
Security Update for Windows XP (KB2555917)
Security Update for Windows XP (KB2562937)
Security Update for Windows XP (KB2566454)
Security Update for Windows XP (KB2567053)
Security Update for Windows XP (KB2567680)
Security Update for Windows XP (KB2570222)
Security Update for Windows XP (KB2570947)
Security Update for Windows XP (KB2584146)
Security Update for Windows XP (KB2585542)
Security Update for Windows XP (KB2592799)
Security Update for Windows XP (KB2598479)
Security Update for Windows XP (KB2603381)
Security Update for Windows XP (KB2618451)
Security Update for Windows XP (KB2620712)
Security Update for Windows XP (KB2621440)
Security Update for Windows XP (KB2624667)
Security Update for Windows XP (KB2631813)
Security Update for Windows XP (KB2633171)
Security Update for Windows XP (KB2639417)
Security Update for Windows XP (KB2641653)
Security Update for Windows XP (KB2646524)
Security Update for Windows XP (KB2647518)
Security Update for Windows XP (KB2653956)
Security Update for Windows XP (KB2655992)
Security Update for Windows XP (KB2659262)
Security Update for Windows XP (KB2660465)
Security Update for Windows XP (KB2661637)
Security Update for Windows XP (KB2676562)
Security Update for Windows XP (KB2685939)
Security Update for Windows XP (KB2686509)
Security Update for Windows XP (KB2691442)
Security Update for Windows XP (KB2695962)
Security Update for Windows XP (KB2698365)
Security Update for Windows XP (KB2705219)
Security Update for Windows XP (KB2707511)
Security Update for Windows XP (KB2709162)
Security Update for Windows XP (KB2712808)
Security Update for Windows XP (KB2718523)
Security Update for Windows XP (KB2719985)
Security Update for Windows XP (KB2723135)
Security Update for Windows XP (KB2724197)
Security Update for Windows XP (KB2727528)
Security Update for Windows XP (KB2731847)
Security Update for Windows XP (KB2753842-v2)
Security Update for Windows XP (KB2753842)
Security Update for Windows XP (KB2757638)
Security Update for Windows XP (KB2758857)
Security Update for Windows XP (KB2761226)
Security Update for Windows XP (KB2770660)
Security Update for Windows XP (KB2778344)
Security Update for Windows XP (KB2779030)
Security Update for Windows XP (KB2780091)
Security Update for Windows XP (KB2799494)
Security Update for Windows XP (KB2802968)
Security Update for Windows XP (KB2807986)
Security Update for Windows XP (KB2808735)
Security Update for Windows XP (KB2813170)
Security Update for Windows XP (KB2813345)
Security Update for Windows XP (KB2820197)
Security Update for Windows XP (KB2820917)
Security Update for Windows XP (KB2829361)
Security Update for Windows XP (KB2834886)
Security Update for Windows XP (KB2839229)
Security Update for Windows XP (KB2845187)
Security Update for Windows XP (KB2847311)
Security Update for Windows XP (KB2849470)
Security Update for Windows XP (KB2850851)
Security Update for Windows XP (KB2850869)
Security Update for Windows XP (KB2859537)
Security Update for Windows XP (KB2862152)
Security Update for Windows XP (KB2862330)
Security Update for Windows XP (KB2862335)
Security Update for Windows XP (KB2864063)
Security Update for Windows XP (KB2868038)
Security Update for Windows XP (KB2868626)
Security Update for Windows XP (KB2876217)
Security Update for Windows XP (KB2876315)
Security Update for Windows XP (KB2876331)
Security Update for Windows XP (KB2883150)
Security Update for Windows XP (KB2892075)
Security Update for Windows XP (KB2893294)
Security Update for Windows XP (KB2893984)
Security Update for Windows XP (KB2898715)
Security Update for Windows XP (KB2900986)
Security Update for Windows XP (KB2914368)
Security Update for Windows XP (KB2916036)
Security Update for Windows XP (KB2922229)
Security Update for Windows XP (KB2929961)
Security Update for Windows XP (KB2930275)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956744)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB969947)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB970430)
Security Update for Windows XP (KB971468)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB972270)
Security Update for Windows XP (KB973346)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB973904)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974318)
Security Update for Windows XP (KB974392)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Security Update for Windows XP (KB975560)
Security Update for Windows XP (KB975561)
Security Update for Windows XP (KB975562)
Security Update for Windows XP (KB975713)
Security Update for Windows XP (KB977165)
Security Update for Windows XP (KB977816)
Security Update for Windows XP (KB977914)
Security Update for Windows XP (KB978037)
Security Update for Windows XP (KB978251)
Security Update for Windows XP (KB978262)
Security Update for Windows XP (KB978338)
Security Update for Windows XP (KB978542)
Security Update for Windows XP (KB978601)
Security Update for Windows XP (KB978706)
Security Update for Windows XP (KB979309)
Security Update for Windows XP (KB979482)
Security Update for Windows XP (KB979559)
Security Update for Windows XP (KB979683)
Security Update for Windows XP (KB979687)
Security Update for Windows XP (KB980195)
Security Update for Windows XP (KB980218)
Security Update for Windows XP (KB980232)
Security Update for Windows XP (KB980436)
Security Update for Windows XP (KB981322)
Security Update for Windows XP (KB981852)
Security Update for Windows XP (KB981957)
Security Update for Windows XP (KB981997)
Security Update for Windows XP (KB982132)
Security Update for Windows XP (KB982214)
Security Update for Windows XP (KB982665)
Security Update for Windows XP (KB982802)
Shared C Run-time for x86
SigmaTel Audio
SolutionCenter
Sonic DLA
Sonic Encoders
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
Sony Picture Utility
Sony USB Driver
Status
Synaptics Pointing Device Driver
Toolbox
TrayApp
Ulead VideoStudio SE DVD
Unity Web Player
Unload
Unlocker 1.8.9
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 7 (KB976749)
Update for Windows Internet Explorer 7 (KB980182)
Update for Windows Internet Explorer 8 (KB2447568)
Update for Windows Internet Explorer 8 (KB2598845)
Update for Windows Internet Explorer 8 (KB2632503)
Update for Windows Internet Explorer 8 (KB976662)
Update for Windows Internet Explorer 8 (KB980182)
Update for Windows Internet Explorer 8 (KB980302)
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB2141007)
Update for Windows XP (KB2345886)
Update for Windows XP (KB2467659)
Update for Windows XP (KB2492386)
Update for Windows XP (KB2541763)
Update for Windows XP (KB2607712)
Update for Windows XP (KB2616676)
Update for Windows XP (KB2641690)
Update for Windows XP (KB2661254-v2)
Update for Windows XP (KB2718704)
Update for Windows XP (KB2736233)
Update for Windows XP (KB2749655)
Update for Windows XP (KB2808679)
Update for Windows XP (KB2863058)
Update for Windows XP (KB2904266)
Update for Windows XP (KB2934207)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955759)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB971029)
Update for Windows XP (KB971737)
Update for Windows XP (KB973687)
Update for Windows XP (KB973815)
Update Rollup 2 for Windows XP Media Center Edition 2005
USB2.0 Capture Device
WebFldrs XP
WebReg
WildGames
WildTangent Web Driver
Windows Driver Package - MobileTop (sshpmdm) Modem  (02/23/2007 2.5.0.0)
Windows Driver Package - MobileTop (sshpusb) USB  (02/23/2007 2.5.0.0)
Windows Driver Package - Nokia pccsmcfd  (10/12/2007 6.85.4.0)
Windows Genuine Advantage Notifications (KB905474)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB895316
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player Firefox Plugin
Windows XP Media Center Edition 2005 KB2502898
Windows XP Media Center Edition 2005 KB2619340
Windows XP Media Center Edition 2005 KB2628259
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB925766
Windows XP Media Center Edition 2005 KB973768
Windows XP Service Pack 3
Zuma Deluxe 1.0
.
==== End Of File ===========================
« Last Edit: August 27, 2015, 03:16:14 PM by kevinf80 »

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 7656
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #1 on: August 12, 2015, 01:13:16 AM »
Hello Canoo and welcome to SpywareHammer,

My screen name is kevinf80, either that or Kevin is good for replies. Ok lets continue:

P2P/illegal software Warning:

Quote
If you're using Peer 2 Peer software such as uTorrent, BitTorrent or similar you must either fully uninstall them or completely disable them from running while being assisted here. Failure to remove or disable such software will result in your topic being closed and no further assistance being provided.If you have illegal/cracked software, cracks, keygens etc. on the system, please remove or uninstall them now and read the Forum policy on P2P and Illegal Software.

Next,

Change the download folder setting in the default Browser so all tools we may use are saved to the Desktop:

Google Chrome - Click the "Customize and control Google Chrome" button in the upper right-corner of the browser.
Choose Settings. at the bottom of the screen click the
"Show advanced settings..." link. Scroll down to find the Downloads section and click the Change... button. Select your desktop and click OK.

Mozilla Firefox - Click the "Open Menu" button in the upper right-corner of the browser. Choose Options. In the downloads section, click the Browse button, click on the Desktop folder and the click the "Select Folder" button. Click OK to get out of the Options menu.

Internet Explorer - Click the Tools menu in the upper right-corner of the browser. Select View downloads. Select the Options link in the lower left of the window. Click Browse and select the Desktop and then choose the Select Folder button. Click OK to get out of the download options screen and then click Close to get out of the View Downloads screen.
NOTE: IE8 Does not support changing download locations in this manner. You will need to download the tool(s) to the default folder, usually Downloads, then copy them to the desktop.

Next,

Follow the instructions in the following link to show hidden files:

http://www.bleepingcomputer.com/tutorials/how-to-see-hidden-files-in-windows/

Next,

Please open Malwarebytes Anti-Malware.

  • On the Settings tab > Detection and Protection sub tab, Detection Options, tick the box "Scan for rootkits".
  • Under Non-Malware Protection sub tab Change PUP and PUM entries to Treat detections as Malware
  • Click on the Scan tab, then click on Scan Now >> . If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • With some infections, you may or may not see this message box.
'Could not load DDA driver'

  • Click 'Yes' to this message, to allow the driver to load after a restart.
  • Allow the computer to restart. Continue with the rest of these instructions.
  • When the scan is complete, click Apply Actions.
  • Wait for the prompt to restart the computer to appear, then click on Yes.
  • After the restart once you are back at your desktop, open MBAM once more.

To get the log from Malwarebytes do the following:

  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have three options:

      Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
      Text file (*.txt)        - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply
      XML file (*.xml)      - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply

  • Recommend you use "Copy to Clipboard, then Right click to your reply > select "Paste" that will copy the log to your reply…


If Malwarebytes is not installed follow these instructions first:

Download Malwarebytes Anti-Malware to your desktop.
  • Double-click mbam-setup and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
  • Launch Malwarebytes Anti-Malware
  • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish. Follow the instructions above....
Next,

Download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

If your security alerts to FRST either accept the alert or disable your security and allow FRST to run...

  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Next,

Please download RogueKiller and save it to your desktop from the following link: http://www.bleepingcomputer.com/download/roguekiller/

  • Quit all running programs.
  • For Windows XP, double-click to start.
  • For Vista,Windows 7/8, Right-click on the program and select Run as Administrator to start and when prompted allow it to run.
  • Read and accept the EULA (End User Licene Agreement)
  • Click Scan to scan the system.
  • When the scan completes select "Report", log will open. Close the program > Don't Fix anything!
  • Post back the report which should also be located here:

C:\Programdata\RogueKiller\Logs <-------- W7/8
C:\Documents and Settings\All Users\Application Data\RogueKiller\Logs <------XP


Let me see those logs in your reply....

Thank you,

Kevin...

Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #2 on: August 14, 2015, 05:06:27 AM »
The reply exceeds max allowed character length. I will reply in three message to accommodate the long post. This is post 1 of 3.

Roguekiller did not finish running, I tried twice and got he same pop-up message when it got partially through the scan, "Anti~mal~ware tool has encountered a problem and needs to close. We are sorry for the inconvenience. If you were in the middle of something, the information you were working on might be lost. Please tell Microsoft about this problem.... etc."

After running Malwarebytes i received the following Threat Scan Result. I saved the results and posted immediately below. Wasn't sure if you needed this too.  I did not click "Remove Selected". Please advise if anything needs to be done with this. ***FYI, Malwarebytes took over 10 hours to run***


Threat - PUP.Optional.ConduitTB.Gen
Category - Potentially Unwanted Program
Type - Registry Key
Location - HKLM\SOFTWARE\CLASSES|Toolbar.CT2438727


Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 8/12/2015
Scan Time: 8:40:43 PM
Logfile:
Administrator: Yes

Version: 2.1.8.1057
Malware Database: v2015.08.12.05
Rootkit Database: v2015.08.06.01
License: Premium
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows XP Service Pack 3
CPU: x86
File System: NTFS
User: Kelsie

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 377405
Time Elapsed: 16 hr, 47 min, 55 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 1
PUP.Optional.ConduitTB.Gen, HKLM\SOFTWARE\CLASSES\Toolbar.CT2438727, , [6293d235a2e9ad89d84dfea84abac13f],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)

The following is from the Malwarebytes History . Application Logs section


Malwarebytes Anti-Malware
www.malwarebytes.org


Protection, 8/12/2015 7:59:53 PM, SYSTEM, KMDELL, Protection, Malware Protection, Starting,
Protection, 8/12/2015 7:59:53 PM, SYSTEM, KMDELL, Protection, Malware Protection, Started,
Protection, 8/12/2015 7:59:53 PM, SYSTEM, KMDELL, Protection, Malicious Website Protection, Starting,
Protection, 8/12/2015 8:00:38 PM, SYSTEM, KMDELL, Protection, Malicious Website Protection, Started,
Update, 8/12/2015 8:39:49 PM, SYSTEM, KMDELL, Manual, AKA Domain Database, 2015.8.10.2, 2015.8.11.1,
Update, 8/12/2015 8:40:26 PM, SYSTEM, KMDELL, Manual, Malware Database, 2015.8.11.4, 2015.8.12.5,
Protection, 8/12/2015 8:40:26 PM, SYSTEM, KMDELL, Protection, Refresh, Starting,
Protection, 8/12/2015 8:40:26 PM, SYSTEM, KMDELL, Protection, Malicious Website Protection, Stopping,
Protection, 8/12/2015 8:40:27 PM, SYSTEM, KMDELL, Protection, Malicious Website Protection, Stopped,
Protection, 8/12/2015 8:40:50 PM, SYSTEM, KMDELL, Protection, Refresh, Success,
Protection, 8/12/2015 8:40:55 PM, SYSTEM, KMDELL, Protection, Malicious Website Protection, Starting,
Protection, 8/12/2015 8:41:05 PM, SYSTEM, KMDELL, Protection, Malicious Website Protection, Started,

(end)


Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #3 on: August 14, 2015, 05:09:44 AM »
The reply exceeds max allowed character length. I will reply in three message to accommodate the long post. This is post 2 of 3.


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:13-08-2015
Ran by Kelsie (administrator) on KMDELL (13-08-2015 19:04:03)
Running from C:\Documents and Settings\Kelsie\Desktop
Loaded Profiles: Kelsie (Available Profiles: Kelsie & Administrator)
Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation ) C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AOMEI Tech Co., Ltd.) C:\Program Files\AOMEI Backupper\ABService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehrecvr.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehSched.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
(Teruten) C:\WINDOWS\system32\FsUsbExService.Exe
(Oracle Corporation) C:\Program Files\Java\jre7\bin\jqs.exe
(McAfee, Inc.) C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
(Dell Inc.) C:\Program Files\Dell\NicConfigSvc\NicConfigSvc.exe
(HP) C:\WINDOWS\system32\HPZipm12.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
(Syntek America Inc.) C:\WINDOWS\system32\StkASv2K.exe
(Ulead Systems, Inc.) C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(Microsoft Corporation) C:\WINDOWS\ehome\mcrdsvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
(Microsoft Corporation) C:\WINDOWS\system32\dllhost.exe
(Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Sonic Solutions) C:\WINDOWS\system32\dla\tfswctrl.exe
(Cyberlink Corp.) C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
(SigmaTel, Inc.) C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe
(Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
(Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe
(Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Hewlett-Packard) C:\Program Files\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehtray.exe
(Microsoft Corporation) C:\WINDOWS\ehome\ehmsas.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbam.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe
(McAfee, Inc.) C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
(McAfee, Inc.) C:\Program Files\Common Files\Mcafee\Platform\McUICnt.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [761947 2006-03-08] (Synaptics, Inc.)
HKLM\...\Run: [dla] => C:\WINDOWS\system32\dla\tfswctrl.exe [127035 2004-12-06] (Sonic Solutions)
HKLM\...\Run: [ISUSPM Startup] => C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [249856 2005-06-10] (InstallShield Software Corporation)
HKLM\...\Run: [ISUSScheduler] => C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-06-09] (InstallShield Software Corporation)
HKLM\...\Run: [RemoteControl] => C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [32768 2004-06-28] (Cyberlink Corp.)
HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe [405504 2007-05-10] (SigmaTel, Inc.)
HKLM\...\Run: [IntelZeroConfig] => C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [995328 2007-10-08] (Intel Corporation)
HKLM\...\Run: [IntelWireless] => C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [1101824 2007-10-08] (Intel Corporation)
HKLM\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [517392 2014-04-25] (McAfee, Inc.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-03-29] (Adobe Systems Incorporated)
HKLM\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [517392 2014-04-25] (McAfee, Inc.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.)
HKLM\...\Run: [UVS10 Preload] => C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe [36864 2006-08-09] (Ulead Systems, Inc.)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation)
HKLM\...\Run: [ShowLOMControl] => 
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\qttask.exe [421888 2010-11-29] (Apple Inc.)
HKLM\...\Run: [KernelFaultCheck] => %systemroot%\system32\dumprep 0 -k
HKLM\...\Run: [HP Software Update] => C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [49208 2011-05-10] (Hewlett-Packard)
HKLM\...\Run: [ehTray] => C:\WINDOWS\ehome\ehtray.exe [67584 2005-09-29] (Microsoft Corporation)
HKLM\...\Run: [DellSupportCenter] => "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
HKLM\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [40368 2011-08-30] (Adobe Systems Incorporated)
HKLM\...\Policies\Explorer: [NoCDBurning] 0
HKLM\...\Policies\Explorer: [NoControlPanel] 0
BootExecute:

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/
HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
SearchScopes: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
BHO: Adobe PDF Reader Link Helper -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2011-08-30] (Adobe Systems Incorporated)
BHO: DriveLetterAccess -> {5CA3D70E-1895-11CF-8E15-001234567890} -> C:\WINDOWS\system32\dla\tfswshx.dll [2004-12-06] (Sonic Solutions)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-09-26] (Oracle Corporation)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-09-26] (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} hxxp://support.dell.com/systemprofiler/SysPro.CAB
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
DPF: {233C1507-6A77-46A4-9443-F871F945D258} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} hxxp://disney.go.com/pirates/online/testActiveX/built/signed/DisneyOnlineGames.cab
DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} hxxp://photos.walmart.com/WalmartActivia.cab
DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} hxxp://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} hxxp://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab
DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} hxxp://sympatico.zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab
DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} hxxp://cdn2.zone.msn.com/binFramework/v10/ZPAFramework.cab102118.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} hxxp://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
DPF: {FF3C5A9F-5A99-4930-80E8-4709194C2AD3} hxxp://zone.msn.com/bingame/zpagames/ZPA_Backgammon.cab64162.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll [2015-08-04] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll [2014-04-25] (McAfee, Inc.)
Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{0948C638-1EE9-4A6F-A2BA-C3EA1D729236}: [DhcpNameServer] 192.168.1.254

FireFox:
========
FF Plugin: @adobe.com/ShockwavePlayer -> C:\WINDOWS\system32\Adobe\Director\np32dsw.dll [2010-09-23] (Adobe Systems, Inc.)
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-02-20] ()
FF Plugin: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-11-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-09-26] (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2014-04-25] ()
FF Plugin: @mcafee.com/MVT -> C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll [2012-05-22] (McAfee, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @movenetworks.com/Quantum Media Player -> C:\Documents and Settings\Kelsie\Application Data\Move Networks\plugins\npqmp071504000001.dll [2009-09-05] (Move Networks)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin HKU\S-1-5-21-1564659014-3411320573-4261112345-1005: @movenetworks.com/Quantum Media Player -> C:\Documents and Settings\Kelsie\Application Data\Move Networks\plugins\npqmp071504000001.dll [2009-09-05] (Move Networks)
FF Plugin HKU\S-1-5-21-1564659014-3411320573-4261112345-1005: @unity3d.com/UnityPlayer,version=1.0 -> C:\Documents and Settings\Kelsie\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-08-24]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files\McAfee\SiteAdvisor [2011-06-25]
FF HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\...\Firefox\Extensions: [moveplayer@movenetworks.com] - C:\Documents and Settings\Kelsie\Application Data\Move Networks
FF Extension: Move Media Player - C:\Documents and Settings\Kelsie\Application Data\Move Networks [2007-04-26]

Chrome:
=======
CHR Profile: C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-19]
CHR Extension: (Google Drive) - C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-19]
CHR Extension: (No Name) - C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2012-10-07]
CHR Extension: (Google Search) - C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2012-10-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-17]
CHR Extension: (Chrome Web Store Payments) - C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-25]
CHR Extension: (Gmail) - C:\Documents and Settings\Kelsie\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2012-10-07]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 Alerter; C:\WINDOWS\system32\alrsvc.dll [17408 2008-04-13] (Microsoft Corporation) [File not signed]
R3 ALG; C:\WINDOWS\System32\alg.exe [44544 2008-04-13] (Microsoft Corporation) [File not signed]
S3 AppMgmt; C:\WINDOWS\System32\appmgmts.dll [167936 2008-04-13] (Microsoft Corporation) [File not signed]
R2 AudioSrv; C:\WINDOWS\System32\audiosrv.dll [42496 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Backupper Service; C:\Program Files\AOMEI Backupper\ABService.exe [29912 2013-08-26] (AOMEI Tech Co., Ltd.)
R2 BITS; C:\WINDOWS\system32\qmgr.dll [409088 2008-04-13] (Microsoft Corporation) [File not signed]
S4 Bluetooth Hid Switch Service; C:\Program Files\BlueTooth\HidSwitchService\HidSw.exe [188416 2005-08-30] (Cambridge Silicon Radio) [File not signed]
R2 Browser; C:\WINDOWS\System32\browser.dll [78336 2012-07-06] (Microsoft Corporation) [File not signed]
S3 CiSvc; C:\WINDOWS\system32\cisvc.exe [5632 2008-04-13] (Microsoft Corporation) [File not signed]
S3 ClipSrv; C:\WINDOWS\system32\clipsrv.exe [33280 2008-04-13] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\WINDOWS\System32\cryptsvc.dll [62464 2008-04-13] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\WINDOWS\system32\rpcss.dll [401408 2009-02-09] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\WINDOWS\System32\dhcpcsvc.dll [126976 2008-04-13] (Microsoft Corporation) [File not signed]
S3 dmadmin; C:\WINDOWS\System32\dmadmin.exe [224768 2008-04-13] (Microsoft Corp., Veritas Software) [File not signed]
S3 dmserver; C:\WINDOWS\System32\dmserver.dll [23552 2008-04-13] (Microsoft Corp.) [File not signed]
R2 Dnscache; C:\WINDOWS\System32\dnsrslvr.dll [45568 2009-04-20] (Microsoft Corporation) [File not signed]
S3 Dot3svc; C:\WINDOWS\System32\dot3svc.dll [132096 2008-04-13] (Microsoft Corporation) [File not signed]
S3 DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [76848 2007-03-07] ()
S3 EapHost; C:\WINDOWS\System32\eapsvc.dll [33792 2008-04-13] (Microsoft Corporation) [File not signed]
R2 ehRecvr; C:\WINDOWS\eHome\ehRecvr.exe [237568 2006-10-09] (Microsoft Corporation) [File not signed]
R2 ehSched; C:\WINDOWS\eHome\ehSched.exe [102912 2005-08-05] (Microsoft Corporation) [File not signed]
R2 ERSvc; C:\WINDOWS\System32\ersvc.dll [23040 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Eventlog; C:\WINDOWS\system32\services.exe [110592 2009-02-06] (Microsoft Corporation) [File not signed]
R3 EventSystem; C:\WINDOWS\system32\es.dll [253952 2008-07-07] (Microsoft Corporation) [File not signed]
R2 EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [794624 2007-10-08] (Intel Corporation) [File not signed]
S3 FastUserSwitchingCompatibility; C:\WINDOWS\System32\shsvcs.dll [135168 2009-07-27] (Microsoft Corporation) [File not signed]
R2 FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [233472 2009-02-19] (Teruten) [File not signed]
R2 helpsvc; C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll [38400 2008-04-13] (Microsoft Corporation) [File not signed]
R2 HidServ; C:\WINDOWS\System32\hidserv.dll [21504 2008-04-13] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\WINDOWS\System32\kmsvc.dll [61440 2008-04-13] (Microsoft Corporation) [File not signed]
R2 HomeNetSvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
S3 HTTPFilter; C:\WINDOWS\System32\w3ssl.dll [15872 2008-04-13] (Microsoft Corporation) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
S3 ImapiService; C:\WINDOWS\system32\imapi.exe [150528 2008-04-13] (Microsoft Corporation) [File not signed]
R2 JavaQuickStarterService; C:\Program Files\Java\jre7\bin\jqs.exe [182696 2014-09-26] (Oracle Corporation)
R2 lanmanserver; C:\WINDOWS\System32\srvsvc.dll [99840 2010-08-27] (Microsoft Corporation) [File not signed]
R2 lanmanworkstation; C:\WINDOWS\System32\wkssvc.dll [132096 2009-06-10] (Microsoft Corporation) [File not signed]
R2 LmHosts; C:\WINDOWS\System32\lmhsvc.dll [13824 2008-04-13] (Microsoft Corporation) [File not signed]
R2 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [132160 2015-08-04] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [145568 2014-04-25] (McAfee, Inc.)
U2 mcbootdelaystartsvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [472072 2014-09-04] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe [281560 2013-07-30] (McAfee, Inc.)
R2 McrdSvc; C:\WINDOWS\ehome\mcrdsvc.exe [99328 2005-08-05] (Microsoft Corporation) [File not signed]
S4 Messenger; C:\WINDOWS\System32\msgsvc.dll [33792 2008-04-13] (Microsoft Corporation) [File not signed]
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [655936 2014-08-20] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [169800 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [179600 2014-06-20] (McAfee, Inc.)
S3 MHN; C:\WINDOWS\System32\mhn.dll [85504 2004-08-10] (Microsoft Corporation) [File not signed]
S3 mnmsrvc; C:\WINDOWS\system32\mnmsrvc.exe [32768 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\WINDOWS\system32\msdtc.exe [6144 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSIServer; C:\WINDOWS\System32\msiexec.exe [78848 2008-04-13] (Microsoft Corporation) [File not signed]
S3 napagent; C:\WINDOWS\System32\qagentrt.dll [291328 2008-04-13] (Microsoft Corporation) [File not signed]
S4 NetDDE; C:\WINDOWS\system32\netdde.exe [111104 2008-04-13] (Microsoft Corporation) [File not signed]
S4 NetDDEdsdm; C:\WINDOWS\system32\netdde.exe [111104 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Netman; C:\WINDOWS\System32\netman.dll [198144 2008-04-13] (Microsoft Corporation) [File not signed]
R2 NICCONFIGSVC; C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe [380928 2005-12-06] (Dell Inc.) [File not signed]
R3 Nla; C:\WINDOWS\System32\mswsock.dll [245248 2008-06-20] (Microsoft Corporation) [File not signed]
S3 NtLmSsp; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
S3 NtmsSvc; C:\WINDOWS\system32\ntmssvc.dll [435200 2008-04-13] (Microsoft Corporation) [File not signed]
R2 PlugPlay; C:\WINDOWS\system32\services.exe [110592 2009-02-06] (Microsoft Corporation) [File not signed]
R2 Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [69632 2006-03-03] (HP) [File not signed]
R2 PolicyAgent; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
R2 ProtectedStorage; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\WINDOWS\System32\rasauto.dll [88576 2008-04-13] (Microsoft Corporation) [File not signed]
R3 RasMan; C:\WINDOWS\System32\rasmans.dll [186368 2008-04-13] (Microsoft Corporation) [File not signed]
S3 RDSessMgr; C:\WINDOWS\system32\sessmgr.exe [141312 2008-04-13] (Microsoft Corporation) [File not signed]
R2 RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [483328 2007-10-08] (Intel Corporation) [File not signed]
S4 RemoteAccess; C:\WINDOWS\System32\mprdim.dll [53248 2008-04-13] (Microsoft Corporation) [File not signed]
R2 RemoteRegistry; C:\WINDOWS\system32\regsvc.dll [59904 2008-04-13] (Microsoft Corporation) [File not signed]
S3 RpcLocator; C:\WINDOWS\system32\locator.exe [75264 2008-04-13] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\WINDOWS\System32\rpcss.dll [401408 2009-02-09] (Microsoft Corporation) [File not signed]
S3 RSVP; C:\WINDOWS\system32\rsvp.exe [132608 2004-08-10] (Microsoft Corporation) [File not signed]
R2 S24EventMonitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [1183744 2007-10-08] (Intel Corporation ) [File not signed]
R2 SamSs; C:\WINDOWS\system32\lsass.exe [13312 2008-04-13] (Microsoft Corporation) [File not signed]
S3 SCardSvr; C:\WINDOWS\System32\SCardSvr.exe [95744 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\WINDOWS\system32\schedsvc.dll [192512 2008-04-13] (Microsoft Corporation) [File not signed]
R2 seclogon; C:\WINDOWS\System32\seclogon.dll [18944 2008-04-13] (Microsoft Corporation) [File not signed]
R2 SENS; C:\WINDOWS\system32\sens.dll [39424 2008-04-13] (Microsoft Corporation) [File not signed]
S3 ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [430592 2008-04-07] (Nokia.) [File not signed]
R2 SharedAccess; C:\WINDOWS\System32\ipnathlp.dll [331264 2008-04-13] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\WINDOWS\System32\shsvcs.dll [135168 2009-07-27] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\WINDOWS\system32\spoolsv.exe [58880 2010-08-17] (Microsoft Corporation) [File not signed]
R2 srservice; C:\WINDOWS\system32\srsvc.dll [171008 2008-04-13] (Microsoft Corporation) [File not signed]
R2 SSDPSRV; C:\WINDOWS\System32\ssdpsrv.dll [71680 2008-04-13] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\WINDOWS\system32\wiaservc.dll [333824 2008-04-13] (Microsoft Corporation) [File not signed]
R2 StkASSrv; C:\WINDOWS\System32\StkASv2K.exe [24576 2006-05-24] (Syntek America Inc.) [File not signed]
S3 SysmonLog; C:\WINDOWS\system32\smlogsvc.exe [89600 2008-04-13] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\WINDOWS\System32\tapisrv.dll [249856 2008-04-13] (Microsoft Corporation) [File not signed]
R3 TermService; C:\WINDOWS\System32\termsrv.dll [295424 2008-04-13] (Microsoft Corporation) [File not signed]
R2 Themes; C:\WINDOWS\System32\shsvcs.dll [135168 2009-07-27] (Microsoft Corporation) [File not signed]
S3 TlntSvr; C:\WINDOWS\system32\tlntsvr.exe [73216 2008-04-13] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\WINDOWS\system32\trkwks.dll [90112 2008-04-13] (Microsoft Corporation) [File not signed]
R2 UleadBurningHelper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [49152 2006-09-28] (Ulead Systems, Inc.) [File not signed]
R2 UMWdf; C:\WINDOWS\system32\wdfmgr.exe [38912 2005-08-03] (Microsoft Corporation) [File not signed]
S3 upnphost; C:\WINDOWS\System32\upnphost.dll [185856 2008-04-13] (Microsoft Corporation) [File not signed]
S3 UPS; C:\WINDOWS\System32\ups.exe [18432 2008-04-13] (Microsoft Corporation) [File not signed]
S3 VSS; C:\WINDOWS\System32\vssvc.exe [289792 2008-04-13] (Microsoft Corporation) [File not signed]
R2 w32time; C:\WINDOWS\system32\w32time.dll [175104 2008-04-13] (Microsoft Corporation) [File not signed]
R2 WebClient; C:\WINDOWS\System32\webclnt.dll [68096 2008-04-13] (Microsoft Corporation) [File not signed]
R2 winmgmt; C:\WINDOWS\system32\wbem\WMIsvc.dll [144896 2008-04-13] (Microsoft Corporation) [File not signed]
R2 WLANKEEPER; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [356352 2007-10-08] (Intel Corporation) [File not signed]
S3 WmdmPmSN; C:\WINDOWS\system32\mspmsnsv.dll [25088 2005-08-03] (Microsoft Corporation) [File not signed]
S3 Wmi; C:\WINDOWS\System32\advapi32.dll [617472 2009-02-09] (Microsoft Corporation) [File not signed]
S3 WmiApSrv; C:\WINDOWS\system32\wbem\wmiapsrv.exe [126464 2008-04-13] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\WINDOWS\system32\wscsvc.dll [80896 2008-04-13] (Microsoft Corporation) [File not signed]
R2 wuauserv; C:\WINDOWS\system32\wuauserv.dll [6656 2008-04-13] (Microsoft Corporation) [File not signed]
S2 WZCSVC; C:\WINDOWS\System32\wzcsvc.dll [483840 2008-04-13] (Microsoft Corporation) [File not signed]
S3 xmlprov; C:\WINDOWS\System32\xmlprov.dll [129024 2008-04-13] (Microsoft Corporation) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 abp480n5; C:\WINDOWS\system32\DRIVERS\ABP480N5.SYS [23552 2001-08-17] (Microsoft Corporation) [File not signed]
R0 ACPI; C:\WINDOWS\System32\DRIVERS\ACPI.sys [187776 2008-04-13] (Microsoft Corporation) [File not signed]
S4 ACPIEC; C:\WINDOWS\system32\Drivers\ACPIEC.sys [11648 2004-08-10] (Microsoft Corporation) [File not signed]
S4 adpu160m; C:\WINDOWS\system32\DRIVERS\adpu160m.sys [101888 2001-08-17] (Microsoft Corporation) [File not signed]
S3 aec; C:\WINDOWS\System32\drivers\aec.sys [142592 2008-04-13] (Microsoft Corporation) [File not signed]
R2 AegisP; C:\WINDOWS\System32\DRIVERS\AegisP.sys [21361 2011-06-24] (Cisco Systems, Inc.) [File not signed]
R1 AFD; C:\WINDOWS\System32\drivers\afd.sys [138496 2011-08-17] (Microsoft Corporation) [File not signed]
S4 agp440; C:\WINDOWS\system32\DRIVERS\agp440.sys [42368 2008-04-13] (Microsoft Corporation) [File not signed]
S4 agpCPQ; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [44928 2008-04-13] (Microsoft Corporation) [File not signed]
S4 Aha154x; C:\WINDOWS\system32\DRIVERS\aha154x.sys [12800 2001-08-17] (Microsoft Corporation) [File not signed]
S4 aic78u2; C:\WINDOWS\system32\DRIVERS\aic78u2.sys [55168 2001-08-17] (Microsoft Corporation) [File not signed]
S4 aic78xx; C:\WINDOWS\system32\DRIVERS\aic78xx.sys [56960 2001-08-17] (Microsoft Corporation) [File not signed]
S4 AliIde; C:\WINDOWS\system32\DRIVERS\aliide.sys [5248 2001-08-17] (Acer Laboratories Inc.) [File not signed]
S4 alim1541; C:\WINDOWS\system32\DRIVERS\alim1541.sys [42752 2008-04-13] (Microsoft Corporation) [File not signed]
R0 ambakdrv; C:\WINDOWS\System32\ambakdrv.sys [26424 2013-05-07] () [File not signed]
S4 amdagp; C:\WINDOWS\system32\DRIVERS\amdagp.sys [43008 2008-04-13] (Advanced Micro Devices, Inc.) [File not signed]
R2 ammntdrv; C:\WINDOWS\system32\ammntdrv.sys [129720 2013-05-07] () [File not signed]
S3 ampa; C:\WINDOWS\system32\ampa.sys [12656 2013-11-29] ()
S4 amsint; C:\WINDOWS\system32\DRIVERS\amsint.sys [12032 2001-08-17] (Microsoft Corporation) [File not signed]
R2 amwrtdrv; C:\WINDOWS\system32\amwrtdrv.sys [14392 2013-02-06] () [File not signed]
R1 APPDRV; C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS [16128 2005-08-12] (Dell Inc) [File not signed]
R3 Arp1394; C:\WINDOWS\System32\DRIVERS\arp1394.sys [60800 2008-04-13] (Microsoft Corporation) [File not signed]
S4 asc; C:\WINDOWS\system32\DRIVERS\asc.sys [26496 2001-08-17] (Advanced System Products, Inc.) [File not signed]
S4 asc3350p; C:\WINDOWS\system32\DRIVERS\asc3350p.sys [22400 2001-08-17] (Microsoft Corporation) [File not signed]
S4 asc3550; C:\WINDOWS\system32\DRIVERS\asc3550.sys [14848 2001-08-17] (Advanced System Products, Inc.) [File not signed]
R2 ASCTRM; C:\WINDOWS\system32\Drivers\ASCTRM.sys [8552 2006-04-24] (Windows (R) 2000 DDK provider) [File not signed]
R3 AsyncMac; C:\WINDOWS\System32\DRIVERS\asyncmac.sys [14336 2008-04-13] (Microsoft Corporation) [File not signed]
R0 atapi; C:\WINDOWS\System32\DRIVERS\atapi.sys [96512 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Atmarpc; C:\WINDOWS\System32\DRIVERS\atmarpc.sys [59904 2008-04-13] (Microsoft Corporation) [File not signed]
R3 audstub; C:\WINDOWS\System32\DRIVERS\audstub.sys [3072 2001-08-17] (Microsoft Corporation) [File not signed]
S3 bcm4sbxp; C:\WINDOWS\System32\DRIVERS\bcm4sbxp.sys [45312 2005-08-05] (Broadcom Corporation) [File not signed]
R1 Beep; C:\WINDOWS\system32\Drivers\Beep.sys [4224 2004-08-10] (Microsoft Corporation) [File not signed]
S4 cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [13952 2001-08-17] (Microsoft Corporation) [File not signed]
S4 cbidf2k; C:\WINDOWS\system32\Drivers\cbidf2k.sys [13952 2001-08-17] (Microsoft Corporation) [File not signed]
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) [File not signed]
S4 cd20xrnt; C:\WINDOWS\system32\DRIVERS\cd20xrnt.sys [7680 2001-08-17] (Microsoft Corporation) [File not signed]
S1 Cdaudio; C:\WINDOWS\system32\Drivers\Cdaudio.sys [18688 2004-08-10] (Microsoft Corporation) [File not signed]
R4 Cdfs; C:\WINDOWS\system32\Drivers\Cdfs.sys [63744 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Cdrom; C:\WINDOWS\System32\DRIVERS\cdrom.sys [62976 2008-04-13] (Microsoft Corporation) [File not signed]
S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [62832 2014-06-20] (McAfee, Inc.)
R3 CmBatt; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [13952 2008-04-13] (Microsoft Corporation) [File not signed]
S4 CmdIde; C:\WINDOWS\system32\DRIVERS\cmdide.sys [6656 2001-08-17] (CMD Technology, Inc.) [File not signed]
R0 Compbatt; C:\WINDOWS\System32\DRIVERS\compbatt.sys [10240 2008-04-13] (Microsoft Corporation) [File not signed]
S4 Cpqarray; C:\WINDOWS\system32\DRIVERS\cpqarray.sys [14976 2001-08-17] (Microsoft Corporation) [File not signed]
S4 dac2w2k; C:\WINDOWS\system32\DRIVERS\dac2w2k.sys [179584 2001-08-17] (Mylex Corporation) [File not signed]
S4 dac960nt; C:\WINDOWS\system32\DRIVERS\dac960nt.sys [14720 2001-08-17] (Microsoft Corporation) [File not signed]
R0 Disk; C:\WINDOWS\System32\DRIVERS\disk.sys [36352 2008-04-13] (Microsoft Corporation) [File not signed]
S4 dmboot; C:\WINDOWS\System32\drivers\dmboot.sys [799744 2008-04-13] (Microsoft Corp., Veritas Software) [File not signed]
R0 dmio; C:\WINDOWS\System32\drivers\dmio.sys [153344 2008-04-13] (Microsoft Corp., Veritas Software) [File not signed]
S4 dmload; C:\WINDOWS\System32\drivers\dmload.sys [5888 2004-08-10] (Microsoft Corp., Veritas Software.) [File not signed]
S3 DMusic; C:\WINDOWS\System32\drivers\DMusic.sys [52864 2008-04-13] (Microsoft Corporation) [File not signed]
S4 dpti2o; C:\WINDOWS\system32\DRIVERS\dpti2o.sys [20192 2001-08-17] (Microsoft Corporation) [File not signed]
S3 drmkaud; C:\WINDOWS\System32\drivers\drmkaud.sys [2944 2008-04-13] (Microsoft Corporation) [File not signed]
R0 drvmcdb; C:\WINDOWS\System32\drivers\drvmcdb.sys [87488 2004-12-01] (Sonic Solutions) [File not signed]
R2 drvnddm; C:\WINDOWS\System32\drivers\drvnddm.sys [40480 2004-11-23] (Sonic Solutions) [File not signed]
S3 DSproct; C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys [4736 2006-10-05] (Gteko Ltd.) [File not signed]
R2 dsunidrv; C:\WINDOWS\System32\DRIVERS\dsunidrv.sys [5376 2007-02-25] (Gteko Ltd.) [File not signed]
S3 E100B; C:\WINDOWS\System32\DRIVERS\e100b325.sys [117760 2001-08-17] (Intel Corporation) [File not signed]
R4 Fastfat; C:\WINDOWS\system32\Drivers\Fastfat.sys [143744 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Fdc; C:\WINDOWS\System32\DRIVERS\fdc.sys [27392 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Fips; C:\WINDOWS\system32\Drivers\Fips.sys [44544 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Flpydisk; C:\WINDOWS\System32\DRIVERS\flpydisk.sys [20480 2008-04-13] (Microsoft Corporation) [File not signed]
R0 FltMgr; C:\WINDOWS\System32\drivers\fltmgr.sys [129792 2008-04-13] (Microsoft Corporation) [File not signed]
R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [36608 2009-02-19] () [File not signed]
U1 Fs_Rec; C:\WINDOWS\system32\Drivers\Fs_Rec.sys [7936 2004-08-10] (Microsoft Corporation) [File not signed]
R0 Ftdisk; C:\WINDOWS\System32\DRIVERS\ftdisk.sys [125056 2001-08-17] (Microsoft Corporation) [File not signed]
R3 Gpc; C:\WINDOWS\System32\DRIVERS\msgpc.sys [35072 2008-04-13] (Microsoft Corporation) [File not signed]
R3 HDAudBus; C:\WINDOWS\System32\DRIVERS\HDAudBus.sys [144384 2008-04-13] (Windows (R) Server 2003 DDK provider) [File not signed]
R3 HidUsb; C:\WINDOWS\System32\DRIVERS\hidusb.sys [10368 2008-04-13] (Microsoft Corporation) [File not signed]
S4 hpn; C:\WINDOWS\system32\DRIVERS\hpn.sys [25952 2001-08-17] (Microsoft Corporation) [File not signed]
R3 HSFHWAZL; C:\WINDOWS\System32\DRIVERS\HSFHWAZL.sys [201600 2005-07-22] (Conexant Systems, Inc.) [File not signed]
R3 HSF_DPV; C:\WINDOWS\System32\DRIVERS\HSF_DPV.sys [1035008 2005-07-22] (Conexant Systems, Inc.) [File not signed]
R3 HTTP; C:\WINDOWS\System32\Drivers\HTTP.sys [265728 2009-10-20] (Microsoft Corporation) [File not signed]
R1 i2omgmt; C:\WINDOWS\system32\Drivers\i2omgmt.sys [8576 2008-04-13] (Microsoft Corporation) [File not signed]
S4 i2omp; C:\WINDOWS\system32\DRIVERS\i2omp.sys [18560 2008-04-13] (Microsoft Corporation) [File not signed]
R1 i8042prt; C:\WINDOWS\System32\DRIVERS\i8042prt.sys [52480 2008-04-13] (Microsoft Corporation) [File not signed]
R3 ialm; C:\WINDOWS\System32\DRIVERS\igxpmp32.sys [5704672 2007-03-30] (Intel Corporation) [File not signed]
R1 Imapi; C:\WINDOWS\System32\DRIVERS\imapi.sys [42112 2008-04-13] (Microsoft Corporation) [File not signed]
S4 ini910u; C:\WINDOWS\system32\DRIVERS\ini910u.sys [16000 2001-08-17] (Microsoft Corporation) [File not signed]
S4 IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [5504 2008-04-13] (Microsoft Corporation) [File not signed]
R1 intelppm; C:\WINDOWS\System32\DRIVERS\intelppm.sys [36352 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Ip6Fw; C:\WINDOWS\System32\drivers\ip6fw.sys [36608 2008-04-13] (Microsoft Corporation) [File not signed]
R3 IpFilterDriver; C:\WINDOWS\System32\DRIVERS\ipfltdrv.sys [32896 2004-08-10] (Microsoft Corporation) [File not signed]
S3 IpInIp; C:\WINDOWS\System32\DRIVERS\ipinip.sys [20864 2008-04-13] (Microsoft Corporation) [File not signed]
R3 IpNat; C:\WINDOWS\System32\DRIVERS\ipnat.sys [152832 2008-04-13] (Microsoft Corporation) [File not signed]
R1 IPSec; C:\WINDOWS\System32\DRIVERS\ipsec.sys [75264 2008-04-13] (Microsoft Corporation) [File not signed]
S3 IRENUM; C:\WINDOWS\System32\DRIVERS\irenum.sys [11264 2008-04-13] (Microsoft Corporation) [File not signed]
R0 isapnp; C:\WINDOWS\System32\DRIVERS\isapnp.sys [37248 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Kbdclass; C:\WINDOWS\System32\DRIVERS\kbdclass.sys [24576 2008-04-13] (Microsoft Corporation) [File not signed]
S3 kmixer; C:\WINDOWS\System32\drivers\kmixer.sys [172416 2008-04-13] (Microsoft Corporation) [File not signed]
R0 KSecDD; C:\WINDOWS\system32\Drivers\KSecDD.sys [92928 2009-06-24] (Microsoft Corporation) [File not signed]
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [98520 2015-08-12] (Malwarebytes Corporation)
R2 mdmxsdk; C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys [13059 2004-03-17] (Conexant) [File not signed]
R3 mfeapfk; C:\WINDOWS\System32\drivers\mfeapfk.sys [135968 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [238176 2014-06-20] (McAfee, Inc.)
S3 mfebopk; C:\WINDOWS\System32\drivers\mfebopk.sys [67816 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [369248 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [576048 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [350240 2014-08-20] (McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [81296 2014-08-20] (McAfee, Inc.)
S3 mfendisk; C:\WINDOWS\System32\DRIVERS\mfendisk.sys [87520 2014-06-20] (McAfee, Inc.)
R3 mfendiskmp; C:\WINDOWS\System32\DRIVERS\mfendisk.sys [87520 2014-06-20] (McAfee, Inc.)
R1 mfetdi2k; C:\WINDOWS\System32\drivers\mfetdi2k.sys [93624 2014-06-20] (McAfee, Inc.)
S3 MHNDRV; C:\WINDOWS\System32\DRIVERS\mhndrv.sys [11008 2004-08-10] (Microsoft Corporation) [File not signed]
R1 mnmdd; C:\WINDOWS\system32\Drivers\mnmdd.sys [4224 2004-08-10] (Microsoft Corporation) [File not signed]
R3 Modem; C:\WINDOWS\system32\Drivers\Modem.sys [30080 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Mouclass; C:\WINDOWS\System32\DRIVERS\mouclass.sys [23040 2008-04-13] (Microsoft Corporation) [File not signed]
R3 mouhid; C:\WINDOWS\System32\DRIVERS\mouhid.sys [12160 2001-08-17] (Microsoft Corporation) [File not signed]
R0 MountMgr; C:\WINDOWS\system32\Drivers\MountMgr.sys [42368 2008-04-13] (Microsoft Corporation) [File not signed]
S4 mraid35x; C:\WINDOWS\system32\DRIVERS\mraid35x.sys [17280 2001-08-17] (American Megatrends Inc.) [File not signed]
R3 MRxDAV; C:\WINDOWS\System32\DRIVERS\mrxdav.sys [180608 2008-04-13] (Microsoft Corporation) [File not signed]
R1 MRxSmb; C:\WINDOWS\System32\DRIVERS\mrxsmb.sys [456320 2011-07-15] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\WINDOWS\System32\drivers\MSKSSRV.sys [7552 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\WINDOWS\System32\drivers\MSPCLOCK.sys [5376 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\WINDOWS\System32\drivers\MSPQM.sys [4992 2008-04-13] (Microsoft Corporation) [File not signed]
R3 mssmbios; C:\WINDOWS\System32\DRIVERS\mssmbios.sys [15488 2008-04-13] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\WINDOWS\System32\drivers\MSTEE.sys [5504 2008-04-13] (Microsoft Corporation) [File not signed]
R0 Mup; C:\WINDOWS\system32\Drivers\Mup.sys [105472 2011-04-21] (Microsoft Corporation) [File not signed]
S3 NABTSFEC; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [85248 2008-04-13] (Microsoft Corporation) [File not signed]
R0 NDIS; C:\WINDOWS\system32\Drivers\NDIS.sys [182656 2008-04-13] (Microsoft Corporation) [File not signed]
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\WINDOWS\System32\DRIVERS\ndistapi.sys [10496 2011-07-08] (Microsoft Corporation) [File not signed]
R3 Ndisuio; C:\WINDOWS\System32\DRIVERS\ndisuio.sys [14592 2008-04-13] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\WINDOWS\System32\DRIVERS\ndiswan.sys [91520 2008-04-13] (Microsoft Corporation) [File not signed]
R3 NDProxy; C:\WINDOWS\system32\Drivers\NDProxy.sys [40960 2013-11-27] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\WINDOWS\System32\DRIVERS\netbios.sys [34688 2008-04-13] (Microsoft Corporation) [File not signed]
R1 NetBT; C:\WINDOWS\System32\DRIVERS\netbt.sys [162816 2008-04-13] (Microsoft Corporation) [File not signed]
S3 NETw3x32; C:\WINDOWS\System32\DRIVERS\NETw3x32.sys [1711104 2006-10-17] (Intel® Corporation) [File not signed]
R3 NETw4x32; C:\WINDOWS\System32\DRIVERS\NETw4x32.sys [2236032 2007-09-26] (Intel Corporation) [File not signed]
R3 NIC1394; C:\WINDOWS\System32\DRIVERS\nic1394.sys [61824 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Npfs; C:\WINDOWS\system32\Drivers\Npfs.sys [30848 2008-04-13] (Microsoft Corporation) [File not signed]
R4 Ntfs; C:\WINDOWS\system32\Drivers\Ntfs.sys [574976 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Null; C:\WINDOWS\system32\Drivers\Null.sys [2944 2004-08-10] (Microsoft Corporation) [File not signed]
S3 nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [1897408 2004-08-03] (NVIDIA Corporation) [File not signed]
S3 NwlnkFlt; C:\WINDOWS\System32\DRIVERS\nwlnkflt.sys [12416 2004-08-10] (Microsoft Corporation) [File not signed]
S3 NwlnkFwd; C:\WINDOWS\System32\DRIVERS\nwlnkfwd.sys [32512 2004-08-10] (Microsoft Corporation) [File not signed]
R0 ohci1394; C:\WINDOWS\System32\DRIVERS\ohci1394.sys [61696 2008-04-13] (Microsoft Corporation) [File not signed]
R1 omci; C:\WINDOWS\System32\DRIVERS\omci.sys [17153 2004-02-13] (Dell Inc) [File not signed]
S3 Parport; C:\WINDOWS\System32\DRIVERS\parport.sys [80128 2008-04-13] (Microsoft Corporation) [File not signed]
R0 PartMgr; C:\WINDOWS\system32\Drivers\PartMgr.sys [19712 2008-04-13] (Microsoft Corporation) [File not signed]
S4 ParVdm; C:\WINDOWS\system32\Drivers\ParVdm.sys [6784 2004-08-10] (Microsoft Corporation) [File not signed]
S3 pccsmcfd; C:\WINDOWS\System32\DRIVERS\pccsmcfd.sys [21632 2007-09-17] (Nokia) [File not signed]
R0 PCI; C:\WINDOWS\System32\DRIVERS\pci.sys [68224 2008-04-13] (Microsoft Corporation) [File not signed]
R0 PCIIde; C:\WINDOWS\System32\DRIVERS\pciide.sys [3328 2001-08-17] (Microsoft Corporation) [File not signed]
S4 Pcmcia; C:\WINDOWS\system32\Drivers\Pcmcia.sys [120192 2008-04-13] (Microsoft Corporation) [File not signed]
S4 perc2; C:\WINDOWS\system32\DRIVERS\perc2.sys [27296 2001-08-17] (Microsoft Corporation) [File not signed]
S4 perc2hib; C:\WINDOWS\system32\DRIVERS\perc2hib.sys [5504 2001-08-17] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\WINDOWS\System32\DRIVERS\raspptp.sys [48384 2008-04-13] (Microsoft Corporation) [File not signed]
R3 PSched; C:\WINDOWS\System32\DRIVERS\psched.sys [69120 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Ptilink; C:\WINDOWS\System32\DRIVERS\ptilink.sys [17792 2004-08-10] (Parallel Technologies, Inc.) [File not signed]
R0 PxHelp20; C:\WINDOWS\System32\Drivers\PxHelp20.sys [36624 2006-11-02] (Sonic Solutions) [File not signed]
S4 ql1080; C:\WINDOWS\system32\DRIVERS\ql1080.sys [40320 2001-08-17] (QLogic Corporation) [File not signed]
S4 Ql10wnt; C:\WINDOWS\system32\DRIVERS\ql10wnt.sys [33152 2001-08-17] (Microsoft Corporation) [File not signed]
S4 ql12160; C:\WINDOWS\system32\DRIVERS\ql12160.sys [45312 2001-08-17] (QLogic Corporation) [File not signed]
S4 ql1240; C:\WINDOWS\system32\DRIVERS\ql1240.sys [40448 2001-08-17] (Microsoft Corporation) [File not signed]
S4 ql1280; C:\WINDOWS\system32\DRIVERS\ql1280.sys [49024 2001-08-17] (QLogic Corporation) [File not signed]
R1 RasAcd; C:\WINDOWS\System32\DRIVERS\rasacd.sys [8832 2004-08-10] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\WINDOWS\System32\DRIVERS\rasl2tp.sys [51328 2008-04-13] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\WINDOWS\System32\DRIVERS\raspppoe.sys [41472 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Raspti; C:\WINDOWS\System32\DRIVERS\raspti.sys [16512 2004-08-10] (Microsoft Corporation) [File not signed]
R1 Rdbss; C:\WINDOWS\System32\DRIVERS\rdbss.sys [175744 2008-04-13] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\WINDOWS\System32\DRIVERS\RDPCDD.sys [4224 2004-08-10] (Microsoft Corporation) [File not signed]
R3 rdpdr; C:\WINDOWS\System32\DRIVERS\rdpdr.sys [196224 2008-04-13] (Microsoft Corporation) [File not signed]
R1 redbook; C:\WINDOWS\System32\DRIVERS\redbook.sys [57600 2008-04-13] (Microsoft Corporation) [File not signed]
R3 rimmptsk; C:\WINDOWS\System32\DRIVERS\rimmptsk.sys [28544 2005-10-14] (REDC) [File not signed]
R3 rimsptsk; C:\WINDOWS\System32\DRIVERS\rimsptsk.sys [51328 2005-10-14] (REDC) [File not signed]
R3 rismxdp; C:\WINDOWS\System32\DRIVERS\rixdptsk.sys [307968 2005-10-14] (REDC) [File not signed]
R2 s24trans; C:\WINDOWS\System32\DRIVERS\s24trans.sys [12288 2007-08-27] (Intel Corporation) [File not signed]
R3 sdbus; C:\WINDOWS\System32\DRIVERS\sdbus.sys [79232 2008-04-13] (Microsoft Corporation) [File not signed]
S3 Secdrv; C:\WINDOWS\System32\DRIVERS\secdrv.sys [20480 2007-11-13] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
S3 serenum; C:\WINDOWS\System32\DRIVERS\serenum.sys [15744 2008-04-13] (Microsoft Corporation) [File not signed]
S1 Serial; C:\WINDOWS\System32\DRIVERS\serial.sys [64512 2008-04-13] (Microsoft Corporation) [File not signed]
S3 sffdisk; C:\WINDOWS\System32\DRIVERS\sffdisk.sys [11904 2008-04-13] (Microsoft Corporation) [File not signed]
S3 sffp_sd; C:\WINDOWS\System32\DRIVERS\sffp_sd.sys [11008 2008-04-13] (Microsoft Corporation) [File not signed]
S1 Sfloppy; C:\WINDOWS\system32\Drivers\Sfloppy.sys [11392 2008-04-13] (Microsoft Corporation) [File not signed]
S4 sisagp; C:\WINDOWS\system32\DRIVERS\sisagp.sys [40960 2008-04-13] (Silicon Integrated Systems Corporation) [File not signed]
S3 SLIP; C:\WINDOWS\System32\DRIVERS\SLIP.sys [11136 2008-04-13] (Microsoft Corporation) [File not signed]
S4 Sparrow; C:\WINDOWS\system32\DRIVERS\sparrow.sys [19072 2001-08-17] (Adaptec, Inc.) [File not signed]
S3 splitter; C:\WINDOWS\System32\drivers\splitter.sys [6272 2008-04-13] (Microsoft Corporation) [File not signed]
R0 sr; C:\WINDOWS\System32\DRIVERS\sr.sys [73472 2008-04-13] (Microsoft Corporation) [File not signed]
R3 Srv; C:\WINDOWS\System32\DRIVERS\srv.sys [357888 2011-02-17] (Microsoft Corporation) [File not signed]
R1 sscdbhk5; C:\WINDOWS\System32\drivers\sscdbhk5.sys [5627 2004-07-14] (Sonic Solutions) [File not signed]
R1 ssrtln; C:\WINDOWS\System32\drivers\ssrtln.sys [23545 2004-07-14] (Sonic Solutions) [File not signed]
R3 STHDA; C:\WINDOWS\System32\drivers\sthda.sys [1222840 2007-05-10] (SigmaTel, Inc.) [File not signed]
R3 StillCam; C:\WINDOWS\System32\DRIVERS\serscan.sys [6784 2001-08-17] (Microsoft Corporation) [File not signed]
S3 StkAMini; C:\WINDOWS\System32\Drivers\StkAMini.sys [242139 2006-11-15] (Syntek America Inc.) [File not signed]
S3 StkScan; C:\WINDOWS\System32\Drivers\StkScan.sys [4772 2006-06-27] (Syntek America Inc.) [File not signed]
S3 streamip; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [15232 2008-04-13] (Microsoft Corporation) [File not signed]
R3 swenum; C:\WINDOWS\System32\DRIVERS\swenum.sys [4352 2008-04-13] (Microsoft Corporation) [File not signed]
S3 swmidi; C:\WINDOWS\System32\drivers\swmidi.sys [56576 2008-04-13] (Microsoft Corporation) [File not signed]
S4 symc810; C:\WINDOWS\system32\DRIVERS\symc810.sys [16256 2001-08-17] (Symbios Logic Inc.) [File not signed]
S4 symc8xx; C:\WINDOWS\system32\DRIVERS\symc8xx.sys [32640 2001-08-17] (LSI Logic) [File not signed]
S4 sym_hi; C:\WINDOWS\system32\DRIVERS\sym_hi.sys [28384 2001-08-17] (LSI Logic) [File not signed]
S4 sym_u3; C:\WINDOWS\system32\DRIVERS\sym_u3.sys [30688 2001-08-17] (LSI Logic) [File not signed]
R3 SynTP; C:\WINDOWS\System32\DRIVERS\SynTP.sys [191872 2006-03-08] (Synaptics, Inc.) [File not signed]
R3 sysaudio; C:\WINDOWS\System32\drivers\sysaudio.sys [60800 2008-04-13] (Microsoft Corporation) [File not signed]
R1 Tcpip; C:\WINDOWS\System32\DRIVERS\tcpip.sys [361600 2008-06-20] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\WINDOWS\system32\Drivers\TDPIPE.sys [12040 2008-04-13] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\WINDOWS\system32\Drivers\TDTCP.sys [21896 2008-04-13] (Microsoft Corporation) [File not signed]
R1 TermDD; C:\WINDOWS\System32\DRIVERS\termdd.sys [40840 2008-04-13] (Microsoft Corporation) [File not signed]
R2 tfsnboio; C:\WINDOWS\System32\dla\tfsnboio.sys [25883 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsncofs; C:\WINDOWS\System32\dla\tfsncofs.sys [34843 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsndrct; C:\WINDOWS\System32\dla\tfsndrct.sys [4123 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsndres; C:\WINDOWS\System32\dla\tfsndres.sys [2239 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsnifs; C:\WINDOWS\System32\dla\tfsnifs.sys [86586 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsnopio; C:\WINDOWS\System32\dla\tfsnopio.sys [15227 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsnpool; C:\WINDOWS\System32\dla\tfsnpool.sys [6363 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsnudf; C:\WINDOWS\System32\dla\tfsnudf.sys [98714 2004-12-06] (Sonic Solutions) [File not signed]
R2 tfsnudfa; C:\WINDOWS\System32\dla\tfsnudfa.sys [100603 2004-12-06] (Sonic Solutions) [File not signed]
S3 toshidpt; C:\WINDOWS\System32\drivers\Toshidpt.sys [3712 2006-02-10] (TOSHIBA Corporation.) [File not signed]
S4 TosIde; C:\WINDOWS\system32\DRIVERS\toside.sys [4992 2001-08-17] (Microsoft Corporation) [File not signed]
R3 tosporte; C:\WINDOWS\System32\DRIVERS\tosporte.sys [47104 2006-02-10] (TOSHIBA Corporation) [File not signed]
R3 Tosrfbd; C:\WINDOWS\System32\Drivers\tosrfbd.sys [108800 2006-02-10] (TOSHIBA CORPORATION) [File not signed]
R3 Tosrfbnp; C:\WINDOWS\System32\Drivers\tosrfbnp.sys [36480 2006-02-10] (TOSHIBA Corporation) [File not signed]
R1 Tosrfcom; C:\WINDOWS\System32\Drivers\tosrfcom.sys [64896 2006-02-10] (TOSHIBA Corporation) [File not signed]
R3 Tosrfhid; C:\WINDOWS\System32\DRIVERS\Tosrfhid.sys [62848 2006-02-10] (TOSHIBA Corporation.) [File not signed]
S3 tosrfnds; C:\WINDOWS\System32\DRIVERS\tosrfnds.sys [18612 2006-02-10] (TOSHIBA Corporation.) [File not signed]
S3 TosRfSnd; C:\WINDOWS\System32\drivers\TosRfSnd.sys [50048 2006-02-10] (TOSHIBA Corporation) [File not signed]
R3 Tosrfusb; C:\WINDOWS\System32\Drivers\tosrfusb.sys [39808 2006-02-10] (TOSHIBA CORPORATION) [File not signed]
S4 ultra; C:\WINDOWS\system32\DRIVERS\ultra.sys [36736 2001-08-17] (Promise Technology, Inc.) [File not signed]
R3 Update; C:\WINDOWS\System32\DRIVERS\update.sys [384768 2008-04-13] (Microsoft Corporation) [File not signed]
S3 USBAAPL; C:\WINDOWS\System32\Drivers\usbaapl.sys [45056 2013-03-18] (Apple, Inc.) [File not signed]
S3 usbaudio; C:\WINDOWS\System32\drivers\usbaudio.sys [60160 2013-07-16] (Microsoft Corporation) [File not signed]
S3 usbccgp; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [32384 2013-08-08] (Microsoft Corporation) [File not signed]
R3 usbehci; C:\WINDOWS\System32\DRIVERS\usbehci.sys [30336 2009-03-18] (Microsoft Corporation) [File not signed]
R3 usbhub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [59520 2008-04-13] (Microsoft Corporation) [File not signed]
S3 usbprint; C:\WINDOWS\System32\DRIVERS\usbprint.sys [25856 2008-04-13] (Microsoft Corporation) [File not signed]
S3 usbscan; C:\WINDOWS\System32\DRIVERS\usbscan.sys [14976 2013-07-02] (Microsoft Corporation) [File not signed]
S3 USBSTOR; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [26368 2008-04-13] (Microsoft Corporation) [File not signed]
R3 usbuhci; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [20608 2008-04-13] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\WINDOWS\System32\drivers\vga.sys [20992 2008-04-13] (Microsoft Corporation) [File not signed]
S4 viaagp; C:\WINDOWS\system32\DRIVERS\viaagp.sys [42240 2008-04-13] (Microsoft Corporation) [File not signed]
S4 ViaIde; C:\WINDOWS\system32\DRIVERS\viaide.sys [5376 2008-04-13] (Microsoft Corporation) [File not signed]
R0 VolSnap; C:\WINDOWS\system32\Drivers\VolSnap.sys [52352 2008-04-13] (Microsoft Corporation) [File not signed]
S3 w39n51; C:\WINDOWS\System32\DRIVERS\w39n51.sys [1428096 2005-12-04] (Intel® Corporation) [File not signed]
R3 Wanarp; C:\WINDOWS\System32\DRIVERS\wanarp.sys [34560 2008-04-13] (Microsoft Corporation) [File not signed]
R3 wdmaud; C:\WINDOWS\System32\drivers\wdmaud.sys [83072 2008-04-13] (Microsoft Corporation) [File not signed]
R3 winachsf; C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys [717952 2005-07-22] (Conexant Systems, Inc.) [File not signed]
R1 WmiAcpi; C:\WINDOWS\System32\DRIVERS\wmiacpi.sys [8832 2008-04-13] (Microsoft Corporation) [File not signed]
S3 WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [18944 2006-03-03] (Microsoft Corporation) [File not signed]
S3 WSTCODEC; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [19200 2008-04-13] (Microsoft Corporation) [File not signed]
U5 BattC; C:\Windows\System32\Drivers\BattC.sys [14208 2008-04-13] (Microsoft Corporation) [File not signed]
S3 BVRPMPR5; \??\D:\INSTAL~E\Core\BVRPMPR5.SYS [X]
S3 catchme; \??\C:\DOCUME~1\Kelsie\LOCALS~1\Temp\catchme.sys [X]
U0 mfewfpk; no ImagePath
S3 pfc; system32\drivers\pfc.sys [X]
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-13] (Microsoft Corporation) [File not signed]
S3 wanatw; system32\DRIVERS\wanatw4.sys [X]
U1 WS2IFSL; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

NETSVC: MHN -> C:\Windows\System32\mhn.dll (Microsoft Corporation)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-13 19:04 - 2015-08-13 20:12 - 00056516 _____ C:\Documents and Settings\Kelsie\Desktop\FRST.txt
2015-08-13 19:02 - 2015-08-13 19:04 - 00000000 ____D C:\FRST
2015-08-13 19:01 - 2015-08-13 19:01 - 01678336 _____ (Farbar) C:\Documents and Settings\Kelsie\Desktop\FRST.exe
2015-08-12 20:55 - 2015-08-12 20:55 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\McAfee
2015-08-11 22:39 - 2015-08-11 22:39 - 00022429 _____ C:\Documents and Settings\Kelsie\Desktop\attach.txt
2015-08-11 22:39 - 2015-08-11 22:35 - 00011221 _____ C:\Documents and Settings\Kelsie\Desktop\dds.txt
2015-08-11 05:34 - 2015-08-12 20:40 - 00098520 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-08-11 05:28 - 2015-08-11 05:28 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-11 05:28 - 2015-08-11 05:28 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-11 05:28 - 2015-06-18 08:41 - 00121560 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-13 20:12 - 2012-10-07 19:39 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-13 20:12 - 2011-06-24 18:54 - 00000000 ____D C:\Documents and Settings\Kelsie\Local Settings\temp
2015-08-13 20:11 - 2005-08-16 05:40 - 01823025 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-12 22:12 - 2012-10-07 19:39 - 00000882 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-12 19:33 - 2005-08-16 05:33 - 00524848 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-12 19:29 - 2014-03-15 12:46 - 00000224 _____ C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-08-12 19:29 - 2005-08-16 05:38 - 00000000 ____D C:\WINDOWS\Registration
2015-08-12 19:29 - 2005-08-16 05:18 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl
2015-08-12 19:27 - 2006-05-13 03:21 - 00000000 __SHD C:\WINDOWS\CSC
2015-08-12 19:27 - 2005-08-16 05:49 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-12 19:27 - 2005-08-16 05:35 - 00000159 _____ C:\WINDOWS\wiadebug.log
2015-08-12 19:27 - 2005-08-16 05:35 - 00000049 _____ C:\WINDOWS\wiaservc.log
2015-08-12 15:12 - 2005-08-16 05:49 - 00032534 _____ C:\WINDOWS\SchedLgU.Txt
2015-08-11 22:44 - 2011-06-20 20:08 - 00000000 ____D C:\Documents and Settings\Kelsie\Desktop\Malware cleaner
2015-08-11 05:28 - 2011-06-25 14:46 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2015-08-11 05:28 - 2011-06-19 23:19 - 00000000 ____D C:\Documents and Settings\Kelsie\Application Data\Malwarebytes
2015-08-11 05:28 - 2011-06-19 23:19 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-08-11 04:03 - 2006-05-13 02:42 - 00000178 ___SH C:\Documents and Settings\Kelsie\ntuser.ini
2015-08-11 04:02 - 2006-04-24 10:23 - 00000325 _____ C:\boot.ini
2015-08-11 04:02 - 2005-08-16 05:18 - 00000533 _____ C:\WINDOWS\win.ini
2015-08-11 04:02 - 2005-08-16 05:18 - 00000227 _____ C:\WINDOWS\system.ini
2015-08-11 01:32 - 2007-11-05 18:49 - 00000000 ____D C:\Program Files\Dell Support Center
2015-08-11 01:32 - 2006-04-24 10:23 - 00000000 ____D C:\dell
2015-08-11 01:30 - 2007-11-05 18:52 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Dell
2015-08-07 13:24 - 2014-02-13 11:56 - 03617109 _____ C:\WINDOWS\setupapi.log
2015-08-02 12:03 - 2010-04-07 21:16 - 00000664 _____ C:\WINDOWS\system32\d3d9caps.dat
2015-07-31 21:21 - 2006-05-13 11:56 - 00000010 _____ C:\WINDOWS\popcinfo.dat

==================== Files in the root of some directories =======

2009-10-28 17:21 - 2009-10-28 17:21 - 0002528 _____ () C:\Documents and Settings\Kelsie\Application Data\$_hpcst$.hpc
2006-05-13 05:29 - 2009-12-01 17:25 - 0012996 _____ () C:\Documents and Settings\Kelsie\Application Data\wklnhst.dat
2007-02-15 10:22 - 2014-10-20 17:51 - 0060416 _____ () C:\Documents and Settings\Kelsie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2006-05-13 02:42 - 2006-05-14 15:25 - 0000129 _____ () C:\Documents and Settings\Kelsie\Local Settings\Application Data\fusioncache.dat
2007-02-15 10:34 - 2007-02-15 10:34 - 0252416 ___SH () C:\Documents and Settings\All Users\ehthumbs.db
2008-03-11 16:01 - 2008-01-11 16:01 - 0000032 ____R () C:\Documents and Settings\All Users\hash.dat

Some files in TEMP:
====================
C:\Documents and Settings\Kelsie\Local Settings\temp\hpzmsi01.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\hpzscr01.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-7u25-windows-i586-iftw.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-7u45-windows-i586-iftw.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-7u51-windows-i586-iftw.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-7u55-windows-i586-iftw.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-7u60-windows-i586-iftw.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-7u67-windows-i586-iftw.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-7u71-windows-i586-iftw.exe
C:\Documents and Settings\Kelsie\Local Settings\temp\jre-8u40-windows-au.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => MD5 is legit
C:\WINDOWS\system32\winlogon.exe => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit
C:\WINDOWS\system32\User32.dll => MD5 is legit
C:\WINDOWS\system32\userinit.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\dnsapi.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\volsnap.sys => MD5 is legit

==================== End of log =========================

Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #4 on: August 14, 2015, 05:11:00 AM »
The reply exceeds max allowed character length. I will reply in three message to accommodate the long post. This is post 3 of 3.

Additional scan result of Farbar Recovery Scan Tool (x86) Version:13-08-2015
Ran by Kelsie (2015-08-13 20:15:00)
Running from C:\Documents and Settings\Kelsie\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1564659014-3411320573-4261112345-500 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Administrator
Guest (S-1-5-21-1564659014-3411320573-4261112345-501 - Limited - Enabled)
HelpAssistant (S-1-5-21-1564659014-3411320573-4261112345-1004 - Limited - Disabled)
Kelsie (S-1-5-21-1564659014-3411320573-4261112345-1005 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\Kelsie
SUPPORT_388945a0 (S-1-5-21-1564659014-3411320573-4261112345-1002 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

6300 (Version: 71.0.215.000 - Hewlett-Packard) Hidden
6300_Help (Version: 71.0.215.000 - Hewlett-Packard) Hidden
6300Trb (Version: 71.0.215.000 - Hewlett-Packard) Hidden
Adobe Flash Player 15 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 15.0.0.246 - Adobe Systems Incorporated)
Adobe Reader 8.3.1 (HKLM\...\{AC76BA86-7AD7-1033-7B44-A83000000003}) (Version: 8.3.1 - Adobe Systems Incorporated)
Adobe Shockwave Player 11.5 (HKLM\...\Adobe Shockwave Player) (Version: 11.5.8.612 - Adobe Systems, Inc.)
AiO_Scan_CDA (Version: 71.0.215.000 - Hewlett-Packard) Hidden
AiOSoftwareNPI (Version: 71.0.215.000 - Hewlett-Packard) Hidden
AOMEI Backupper (HKLM\...\{A83692F5-3E9B-4E95-9E7E-B5DF5536C09D}_is1) (Version:  - AOMEI Technology Co., Ltd.)
AOMEI Partition Assistant Standard Edition 5.5 (HKLM\...\{02F850ED-FD0E-4ED1-BE0B-54981f5BD3D4}_is1) (Version:  - AOMEI Technology Co., Ltd.)
Apple Application Support (HKLM\...\{AAC5D43E-816D-4C2D-8E51-55FFF35BE301}) (Version: 3.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{18D47FA1-0440-48D3-A7E0-DA09537FF471}) (Version: 7.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Banctec Service Agreement (HKLM\...\{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}) (Version: 1.10.0000 - Dell)
Bluetooth Stack for Windows by Toshiba (HKLM\...\{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}) (Version: v4.00.20(D) - )
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Management Programs (HKLM\...\{26E1BFB0-E87E-4696-9F89-B467F01F81E5}) (Version: 8.65.05 - Broadcom Corporation)
BufferChm (Version: 70.0.170.000 - Hewlett-Packard) Hidden
Compatibility Pack for the 2007 Office system (HKLM\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Conexant HDA D110 MDC V.92 Modem (HKLM\...\CNXT_MODEM_HDAUDIO_VEN_14F1&DEV_2BFA&SUBSYS_14F100C3) (Version:  - )
Corel Photo Album 6 (HKLM\...\{8A9B8148-DDD7-448F-BD6C-358386D32354}) (Version: 6.33 - Corel, Inc.)
Curious George Learning Games (HKLM\...\CGELAV11) (Version:  - )
Dell Digital Jukebox Driver (HKLM\...\Dell Digital Jukebox Driver) (Version:  - )
Dell Driver Download Manager (HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\...\f031ef6ac137efc5) (Version: 2.1.0.0 - Dell Inc.)
Dell System Restore (HKLM\...\{74F7662C-B1DB-489E-A8AC-07A06B24978B}) (Version: 2.00.0000 - Dell Inc.)
DellSupport (HKLM\...\{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}) (Version: 6.0.3062 - Dell)
Destinations (Version: 70.0.170.000 - Hewlett-Packard) Hidden
DeviceManagementQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Digital Content Portal (HKLM\...\{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}) (Version: 1.00.0000 - Dell)
Digital Line Detect (HKLM\...\{E646DCF0-5A68-11D5-B229-002078017FBF}) (Version: 1.15 - BVRP Software, Inc)
Documentation & Support Launcher (HKLM\...\{B0DF58A2-40DF-4465-AA56-38623EC9938C}) (Version: 1.00.0000 - Dell Inc.)
DocumentViewer (Version: 70.0.170.000 - Hewlett-Packard) Hidden
DocumentViewerQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
EducateU (HKLM\...\{A683A2C0-821C-486F-858C-FA634DB5E864}) (Version: 1.00.0000 - Dell)
ESPNMotion (HKLM\...\ESPNMotion) (Version: 2.1.6.0011 - ESPN Internet Ventures)
eSupportQFolder (Version: 1.00.0000 - Hewlett-Packard) Hidden
Fax_CDA (Version: 71.0.215.000 - Hewlett-Packard) Hidden
Fender FUSE (HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\...\1908894683.fuse.fender.com) (Version:  - fuse.fender.com)
Fender FUSE 2.7.1.44 (HKLM\...\Fender FUSE) (Version:  - )
Games, Music, & Photos Launcher (HKLM\...\{B6884A07-0305-47AE-9969-8F26FADC17DE}) (Version: 1.00.0000 - Dell Inc.)
GemMaster Mystic (HKLM\...\12133444-BF36-4d4e-B7FB-A3424C645DE4) (Version:  - )
Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
High Definition Audio Driver Package - KB835221 (HKLM\...\KB835221WXP) (Version: 20040219.000000 - Microsoft Corporation)
HiJackThis (HKLM\...\{45A66726-69BC-466B-A7A4-12FCBA4883D7}) (Version: 1.0.0 - Trend Micro)
HP Document Viewer 7.0 (HKLM\...\HP Document Viewer) (Version: 7.0 - HP)
HP Imaging Device Functions 7.0 (HKLM\...\HP Imaging Device Functions) (Version: 7.0 - HP)
HP Photosmart, Officejet and Deskjet 7.0.A (HKLM\...\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}) (Version:  - HP)
HP Solution Center 7.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 7.0 - HP)
HP Update (HKLM\...\{97486FBE-A3FC-4783-8D55-EA37E9D171CC}) (Version: 5.005.000.002 - Hewlett-Packard)
HPPhotoSmartExpress (Version: 70.0.170.000 - Hewlett-Packard) Hidden
HPProductAssistant (Version: 70.0.170.000 - Hewlett-Packard) Hidden
InstantShareDevicesMFC (Version: 70.0.170.000 - Hewlett-Packard) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version:  - )
Intel(R) Processor ID Utility (HKLM\...\{A92A4DB0-CD37-42D1-BE1D-603D53C24328}) (Version: 4.40.0000 - Intel(R) Corporation)
Intel(R) PROSet/Wireless Software (HKLM\...\ProInst) (Version: 11.5.0000 - Intel Corporation)
Internal Network Card Power Management (HKLM\...\{1F528948-0E80-4C96-B455-DE4167CB1DF7}) (Version: 1.7.2 - )
iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: 11.1.5.5 - Apple Inc.)
Java 7 Update 71 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217025FF}) (Version: 7.0.710 - Oracle)
Learn2 Player (Uninstall Only) (HKLM\...\StreetPlugin) (Version:  - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
McAfee SecurityCenter (HKLM\...\MSC) (Version: 12.8.992 - McAfee, Inc.)
McAfee SiteAdvisor (HKLM\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 3.7.264 - McAfee, Inc.)
McAfee Virtual Technician (HKLM\...\McAfee Virtual Technician) (Version: 6.5.0.2101 - McAfee, Inc.)
mCore (Version: 11.02.0000 - Intel Corporation) Hidden
MCU (Version: 1.00.0000 - Dell) Hidden
mDriver (Version: 11.02.0000 - Intel) Hidden
mDrWiFi (Version: 11.02.0000 - Intel Corporation) Hidden
mHlpDell (Version: 11.02.0000 - Intel) Hidden
Microsoft .NET Framework 1.0 Hotfix (KB2572066) (HKLM\...\KB2572066) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB2604042) (HKLM\...\KB2604042) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB2656378) (HKLM\...\KB2656378) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB953295) (HKLM\...\KB953295) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Hotfix (KB979904) (HKLM\...\KB979904) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2698035) (HKLM\...\KB2698035) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2742607) (HKLM\...\KB2742607) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2833951) (HKLM\...\KB2833951) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.0 Security Update (KB2904878) (HKLM\...\KB2904878) (Version:  - Microsoft Corporation)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB2833941) (HKLM\...\M2833941) (Version:  - )
Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version:  - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.0 Service Pack 2 (HKLM\...\{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}) (Version: 3.2.30729 - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version:  - Microsoft Corporation)
Microsoft Base Smart Card Cryptographic Service Provider Package (HKLM\...\KB909520) (Version:  - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Edition 2003 (HKLM\...\{91E30409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Plus! Digital Media Edition Installer (HKLM\...\{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}) (Version: 1.1.0.3514 - Microsoft Corporation)
Microsoft Plus! Photo Story 2 LE (HKLM\...\{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}) (Version: 1.1.0.3463 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
mIWA (Version: 11.02.0000 - Intel Corporation) Hidden
mLogView (Version: 11.02.0000 - Intel Corporation) Hidden
mMHouse (Version: 11.02.0000 - Intel Corporation) Hidden
Modem Helper (HKLM\...\{7F142D56-3326-11D5-B229-002078017FBF}) (Version: 3.01 - BVRP Software)
Move Media Player (HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\...\Move Media Player) (Version:  - Move Networks)
mPfMgr (Version: 11.02.0000 - Intel Corporation) Hidden
mPfWiz (Version: 11.02.0000 - Intel Corporation) Hidden
mProSafe (Version: 9.00.0000 - Intel) Hidden
mSCfg (Version: 11.02.0000 - Intel Corporation) Hidden
mSSO (Version: 11.02.0000 - Intel Corporation) Hidden
MSXML 4.0 SP2 (KB927978) (HKLM\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB936181) (HKLM\...\{C04E32E0-0416-434D-AFB9-6969D703A9EF}) (Version: 4.20.9848.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 6.0 Parser (KB933579) (HKLM\...\{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}) (Version: 6.10.1200.0 - Microsoft Corporation)
mWlsSafe (Version: 9.00.0000 - Intel) Hidden
mWMI (Version: 11.02.0000 - Intel Corporation) Hidden
mZConfig (Version: 11.02.0000 - Intel Corporation) Hidden
NetWaiting (HKLM\...\{3F92ABBB-6BBF-11D5-B229-002078017FBF}) (Version: 2.5.23 - BVRP Software, Inc)
NewCopy_CDA (Version: 71.0.215.000 - Hewlett-Packard) Hidden
Octoshape add-in for Adobe Flash Player (HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\...\Octoshape add-in for Adobe Flash Player) (Version:  - )
Otto (HKLM\...\B3EE3001-DC24-4cd1-8743-5692C716659F) (Version:  - )
PanoStandAlone (Version: 70.0.170.000 - Hewlett-Packard) Hidden
PC Connectivity Solution (HKLM\...\{AC599724-5755-48C1-ABE7-ABB857652930}) (Version: 8.15.0.0 - Nokia)
Picture Package Music Transfer (HKLM\...\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}) (Version: 1.0.02.02130 - Sony Corporation)
PokerStars (HKLM\...\PokerStars) (Version:  - PokerStars)
PowerDirector Express (HKLM\...\{EDE721EC-870A-11D8-9D75-000129760D75}) (Version:  - )
PowerDVD (HKLM\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version:  - )
PowerProducer (HKLM\...\{B7A0CE06-068E-11D6-97FD-0050BACBF861}) (Version:  - )
ProductContextNPI (Version: 71.0.215.000 - Hewlett-Packard) Hidden
QuickSet (HKLM\...\{C5074CC4-0E26-4716-A307-960272A90040}) (Version: 7.0.9 - )
QuickTime (HKLM\...\{57752979-A1C9-4C02-856B-FBB27AC4E02C}) (Version: 7.69.80.9 - Apple Inc.)
Readme (Version: 71.0.215.000 - Hewlett-Packard) Hidden
RealPlayer Basic (HKLM\...\RealPlayer 6.0) (Version:  - )
SAMSUNG Mobile Composite Device Software (HKLM\...\SAMSUNG Mobile Composite Device) (Version:  - )
SAMSUNG Mobile Modem Driver Set (HKLM\...\SAMSUNG Mobile Modem) (Version:  - )
Samsung Mobile phone USB driver Software (HKLM\...\Samsung Mobile phone USB driver) (Version:  - )
SAMSUNG Mobile USB Modem 1.0 Software (HKLM\...\SAMSUNG Mobile USB Modem 1.0) (Version:  - )
SAMSUNG Mobile USB Modem Software (HKLM\...\SAMSUNG Mobile USB Modem) (Version:  - )
Samsung New PC Studio (HKLM\...\InstallShield_{F193FC0E-9E18-40FC-A974-509A1BDD240A}) (Version: 1.00.0000 - Samsung Electronics Co., Ltd.)
Samsung New PC Studio (Version: 1.00.0000 - Samsung Electronics Co., Ltd.) Hidden
SamsungConnectivityCableDriver (HKLM\...\{7E84FAC8-C518-40F9-9807-7455301D6D25}) (Version: 6.83.6.2.1 - Samsung)
Scan (Version: 7.0.0.0 - Hewlett-Packard) Hidden
ScannerCopy (Version: 7.0.0.0 - Hewlett-Packard) Hidden
SCRABBLE (HKLM\...\6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA) (Version: 09/20/2005  12:02 AM - WildTangent)
Shared C Run-time for x86 (Version: 10.0.0 - McAfee) Hidden
SigmaTel Audio (HKLM\...\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}) (Version: 5.10.5210.0 - SigmaTel)
SolutionCenter (Version: 70.0.170.000 - Hewlett-Packard) Hidden
Sonic DLA (HKLM\...\{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}) (Version: 4.95 - Sonic Solutions)
Sonic Encoders (HKLM\...\{9941F0AA-B903-4AF4-A055-83A9815CC011}) (Version: 1.00 - Sonic Solutions)
Sonic MyDVD LE (HKLM\...\{21657574-BD54-48A2-9450-EB03B2C7FC29}) (Version: 6.1.1 - Sonic Solutions)
Sonic RecordNow Audio (HKLM\...\{AB708C9B-97C8-4AC9-899B-DBF226AC9382}) (Version: 2.0.0 - Sonic Solutions)
Sonic RecordNow Copy (HKLM\...\{B12665F4-4E93-4AB4-B7FC-37053B524629}) (Version: 2.0.0 - Sonic Solutions)
Sonic RecordNow Data (HKLM\...\{075473F5-846A-448B-BCB3-104AA1760205}) (Version: 2.0.0 - Sonic Solutions)
Sonic Update Manager (HKLM\...\{30465B6C-B53F-49A1-9EBA-A3F187AD502E}) (Version: 3.0.0 - Sonic Solutions)
Sony Picture Utility (HKLM\...\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 2.0.05.16060 - Sony Corporation)
Sony USB Driver (HKLM\...\{5C29CB8B-AC1E-4114-8D68-9CD080140D4A}) (Version: 2.00 - Sony Corporation)
Status (Version: 70.0.170.000 - Hewlett-Packard) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 8.2.4.6 - Synaptics)
Toolbox (Version: 70.0.170.000 - Hewlett-Packard) Hidden
TrayApp (Version: 70.0.170.000 - Hewlett-Packard) Hidden
Ulead VideoStudio SE DVD (HKLM\...\{8F8D9297-FDD2-405A-97E7-E52C7B2F97B3}) (Version: 10.0 - Ulead Systems)
Unity Web Player (HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\...\UnityWebPlayer) (Version: 2.6.1f3_31223 - Unity Technologies ApS)
Unload (Version: 7.0.0 - Hewlett-Packard) Hidden
Unlocker 1.8.9 (HKLM\...\Unlocker) (Version: 1.8.9 - Cedrick Collomb)
Update Rollup 2 for Windows XP Media Center Edition 2005 (HKLM\...\KB900325) (Version:  - Microsoft Corporation)
USB2.0 Capture Device (HKLM\...\{E337B156-DF81-48D8-8977-B1574EE87BCF}) (Version: 1.0.3.0 - )
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
WebReg (Version: 70.0.170.000 - Hewlett-Packard) Hidden
WildGames (HKLM\...\WildTangent wildgames Master Uninstall) (Version: 1.0.0.43 - WildTangent)
WildTangent Web Driver (HKLM\...\WildTangent CDA) (Version:  - )
Windows Driver Package - MobileTop (sshpmdm) Modem  (02/23/2007 2.5.0.0) (HKLM\...\6194C28A8F62DD817EA1B918E6E46E806A21B452) (Version: 02/23/2007 2.5.0.0 - MobileTop)
Windows Driver Package - MobileTop (sshpusb) USB  (02/23/2007 2.5.0.0) (HKLM\...\65B6FE5418CE28F4D72543FB2D964C3CEC83F161) (Version: 02/23/2007 2.5.0.0 - MobileTop)
Windows Driver Package - Nokia pccsmcfd  (10/12/2007 6.85.4.0) (HKLM\...\3A5DEFA413DDE699DBA6EBE0A63534ACA524D30F) (Version: 10/12/2007 6.85.4.0 - Nokia)
Windows Genuine Advantage Notifications (KB905474) (HKLM\...\WgaNotify) (Version: 1.7.0017.0 - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\KB892130) (Version:  - Microsoft Corporation)
Windows Genuine Advantage Validation Tool (KB892130) (HKLM\...\WGA) (Version: 1.7.0069.2 - Microsoft Corporation)
Windows Installer 3.1 (KB893803) (HKLM\...\KB893803v2) (Version:  - Microsoft Corporation)
Windows Internet Explorer 8 (HKLM\...\ie8) (Version: 20090308.140743 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM\...\Windows Media Encoder 9) (Version:  - )
Windows Media Format Runtime (HKLM\...\Windows Media Format Runtime) (Version:  - )
Windows Media Player 10 Hotfix - KB895316 (HKLM\...\KB895316) (Version:  - Microsoft Corporation)
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] (HKLM\...\EmeraldQFE2) (Version:  - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
Windows XP Media Center Edition 2005 KB2502898 (HKLM\...\KB2502898) (Version:  - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB2619340 (HKLM\...\KB2619340) (Version:  - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB2628259 (HKLM\...\KB2628259) (Version:  - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB908246 (HKLM\...\KB908246) (Version:  - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB925766 (HKLM\...\KB925766) (Version:  - Microsoft Corporation)
Windows XP Media Center Edition 2005 KB973768 (HKLM\...\KB973768) (Version:  - Microsoft Corporation)
Windows XP Service Pack 3 (HKLM\...\Windows XP Service Pack) (Version: 20080414.031525 - Microsoft Corporation)
Zuma Deluxe 1.0 (HKLM\...\Zuma Deluxe 1.0) (Version:  - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Documents and Settings\Kelsie\Local Settings\Application Data\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005_Classes\CLSID\{e3e02f12-2adb-478c-8742-5f0819f9f0f4}\InprocServer32 -> C:\Documents and Settings\Kelsie\Application Data\Move Networks\plugins\npqmp071504000001.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005_Classes\CLSID\{e473a65c-8087-49a3-affd-c5bc4a10669b}\InprocServer32 -> C:\Documents and Settings\Kelsie\Application Data\Move Networks\plugins\npqmp071504000001.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005_Classes\CLSID\{fc345d4c-b8f4-4674-bff7-3c37d2e535ee}\InprocServer32 -> C:\Documents and Settings\Kelsie\Application Data\Move Networks\plugins\npqmp071504000001.dll (Move Networks)
CustomCLSID: HKU\S-1-5-21-1564659014-3411320573-4261112345-1005_Classes\CLSID\{fd6484ed-ebe3-4c3d-938a-8238003b41b7}\InprocServer32 -> C:\Documents and Settings\Kelsie\Application Data\Move Networks\plugins\npqmp071504000001.dll (Move Networks)

==================== Restore Points =========================

22-05-2015 18:55:48 System Checkpoint
23-05-2015 19:22:36 System Checkpoint
26-05-2015 07:46:33 System Checkpoint
27-05-2015 20:52:44 System Checkpoint
29-05-2015 23:10:43 System Checkpoint
30-05-2015 23:54:16 System Checkpoint
01-06-2015 01:54:23 System Checkpoint
02-06-2015 01:57:03 System Checkpoint
04-06-2015 09:52:37 System Checkpoint
05-06-2015 11:22:18 System Checkpoint
06-06-2015 13:08:23 System Checkpoint
07-06-2015 16:46:58 System Checkpoint
10-06-2015 17:52:32 System Checkpoint
10-06-2015 18:37:08 Software Distribution Service 3.0
12-06-2015 20:13:42 System Checkpoint
17-06-2015 15:40:41 System Checkpoint
18-06-2015 17:34:31 System Checkpoint
19-06-2015 19:37:17 System Checkpoint
21-06-2015 13:25:30 System Checkpoint
22-06-2015 15:10:04 System Checkpoint
23-06-2015 15:54:49 System Checkpoint
24-06-2015 17:20:33 System Checkpoint
25-06-2015 18:33:30 System Checkpoint
27-06-2015 00:12:54 System Checkpoint
28-06-2015 01:21:09 System Checkpoint
29-06-2015 01:58:03 System Checkpoint
30-06-2015 20:59:30 System Checkpoint
01-07-2015 22:17:10 System Checkpoint
06-07-2015 04:46:41 System Checkpoint
07-07-2015 14:48:06 System Checkpoint
08-07-2015 15:40:33 System Checkpoint
09-07-2015 15:59:46 System Checkpoint
11-07-2015 21:00:45 System Checkpoint
13-07-2015 10:27:56 System Checkpoint
14-07-2015 20:27:48 System Checkpoint
15-07-2015 20:06:41 Software Distribution Service 3.0
16-07-2015 20:27:28 System Checkpoint
20-07-2015 11:45:22 System Checkpoint
23-07-2015 18:35:04 System Checkpoint
31-07-2015 22:15:17 System Checkpoint
01-08-2015 22:46:08 System Checkpoint
02-08-2015 23:24:46 System Checkpoint
04-08-2015 02:22:13 System Checkpoint
05-08-2015 07:29:11 System Checkpoint
06-08-2015 17:11:54 System Checkpoint
07-08-2015 19:01:00 System Checkpoint
09-08-2015 20:01:39 System Checkpoint
11-08-2015 01:29:46 Removed Dell Support Center (Support Software).
12-08-2015 15:18:51 System Checkpoint
13-08-2015 15:30:52 System Checkpoint

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2005-08-16 05:18 - 2015-03-24 02:58 - 00000058 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1       localhost
HP002264464D41 HP002264464D41

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job => C:\WINDOWS\system32\xp_eos.exe
Task: C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job => C:\WINDOWS\system32\xp_eos.exe

==================== Loaded Modules (Whitelisted) ==============


==================== Memory info ===========================

Processor: Genuine Intel(R) CPU T2400 @ 1.83GHz
Percentage of memory in use: 65%
Total physical RAM: 2038.37 MB
Available physical RAM: 713.32 MB
Total Virtual: 3408.68 MB
Available Virtual: 2106.61 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:293.16 GB) (Free:240.08 GB) NTFS ==>[drive with boot components (Windows XP)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: 82337274)
Partition 1: (Not Active) - (Size=39 MB) - (Type=06)
Partition 2: (Active) - (Size=293.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=4.9 GB) - (Type=0B)

==================== End of log ============================

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 7656
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #5 on: August 14, 2015, 05:52:27 AM »
Thanks for the reply/logs, continue as follows please:

Download attached fixlist.txt file (end of reply) and save it to the Desktop, or the folder you saved FRST into.
NOTE. It's important that both FRST and fixlist.txt are in the same location or the fix will not work.

Run FRST and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt) or the folder it was ran from. Please post it to your reply.

Next,

Read the following link before we continue and run Combofix:

ComboFix usage, Questions, Help? - Look here

Next,

Download Combofix from either of the following links :-

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

http://www.infospyware.net/antimalware/combofix/

  • Ensure that Combofix is saved directly to the Desktop <--- Very important

  • Disable all security programs as they will have a negative effect on Combofix, instructions available here  http://www.bleepingcomputer.com/forums/topic114351.html if required. Be aware the list may not have all programs listed, if you need more help please ask.

  • Close any open browsers and any other programs you might have running
  • Double click the icon to run the tool (Vista or Windows 7 users right click and select "Run as Administrator)

  • Instructions for running Combofix available here http://www.bleepingcomputer.com/combofix/how-to-use-combofix if required.

  • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this. Once the recovery console is installed Combofix will then offer to scan for malware. Select continue or yes.
  • When finished, it will produce a report for you. Please post the "C:\ComboFix.txt" for further review

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****

Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell us when you reply. Read here  http://thespykiller.co.uk/index.php?page=20 why  disabling autoruns is recommended.

*EXTRA NOTES*
  • If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
  • If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
       
  • If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)

Post those logs in next reply please...

Kevin



Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #6 on: August 16, 2015, 06:14:03 PM »
Having issues with ComboFix. Takes a long time to run. Let it run overnight when i cam back in the morning the laptop looked like it went to sleep but did not wake up. Rebooted and ran again because there was not a ComboFix.txt file to be found. I sat with it and after a couple of hours and getting through more that 30 stages I got a blue screen. It said,

"A problem has been detected and windows has been shut down to prevent damage to your computer.

BAD_POOL_HEADER

If this is the first time you've seen this ... (left off the next section)

Technical information:
*** STOP: 0x00000019 (0x00000020, 0x883AD330, 0x883AD748, 0x1A830001)

Beginning of dump of physical memory...."


In my initial reply Roguekiller did not finish and Malwarebytes indicated a PUP.

Here is Fixlog.txt

Fix result of Farbar Recovery Scan Tool (x86) Version:13-08-2015
Ran by Kelsie (2015-08-14 19:02:37) Run:1
Running from C:\Documents and Settings\Kelsie\Desktop
Loaded Profiles: Kelsie (Available Profiles: Kelsie & Administrator)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
S3 BVRPMPR5; \??\D:\INSTAL~E\Core\BVRPMPR5.SYS [X]
S3 catchme; \??\C:\DOCUME~1\Kelsie\LOCALS~1\Temp\catchme.sys [X]
U0 mfewfpk; no ImagePath
S3 pfc; system32\drivers\pfc.sys [X]
S3 wanatw; system32\DRIVERS\wanatw4.sys [X]
U1 WS2IFSL; no ImagePath
Emptytemp:
End
*****************

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
"HKU\S-1-5-21-1564659014-3411320573-4261112345-1005\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully.
BVRPMPR5 => service removed successfully.
catchme => service removed successfully.
mfewfpk => service could not remove
pfc => service removed successfully.
wanatw => service removed successfully.
WS2IFSL => service removed successfully.
EmptyTemp: => 8.3 GB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 19:06:10 ====


Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #7 on: August 16, 2015, 08:15:09 PM »
Forgot to add one thing in the last reply regarding Combofix.

After the blue screen I rebooted and tried to run it again. I tried twice and both times i got an error window that says,

Error opening file for writing:
C:\32788R22FWJFW\swreg.3XE
Click Abort to stop the installation
Retry to try again, or Ignore to skip this file.

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 7656
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #8 on: August 17, 2015, 12:42:09 AM »
Thanks for the update... Did you turn off your security before running Combofix? It is essential that all security is off before starting a run...

If your security was definitely off try the following:

Download RKill from here: http://www.bleepingcomputer.com/download/rkill/

There are three buttons to choose from with different names on, select the first one and save it to your desktop.

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Vista or Windows 7/8, right-click on it and Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • A log pops up at the end of the run. This log file is located at C:\rkill.log. Please post this in your next reply.
  • If you do not see the black box flash on the screen delete the icon from the desktop and go back to the link for the download, select the next button and try to run the tool again, continue to repeat this process using the remaining buttons until the tool runs. You will find further links if you scroll down the page with other names, try them one at a time.
  • If the tool does not run from any of the links provided, please let me know.

Next,

Delete any version of ComboFix you have on your Desktop.  Download a fresh copy from either of the following links:

Link 1
Link 2

Before you save it to the Desktop Make sure to rename it to sega.com

Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).

Click Start --> Run, and type this command exactly as shown or use copy/paste:

"%userprofile%\desktop\sega.com" /killall Tap enter or select OK.

See if it will run successfully now.

Post the logs in next reply,

Kevin

Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #9 on: August 18, 2015, 05:22:48 AM »
Reply 1 of 5  -  (exceeded 65,000 characters) this portion only includes a portion of rkill.txt

I did have the antivirus and firewall disabled.

I did not find c:\rkill.log but I did find rkill.txt on my desktop so I included that.

Combofix ran in safe mode and it rebooted. It rebooted into regular mode and continued its process. It made it to where it said it was creating a log and after a while it gave me the same blue screen. It did create combo.txt log and it is below. It was in c:\sega8998s folder.

Rkill 2.7.0 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2015 BleepingComputer.com
More Information about Rkill can be found at this link:
 http://www.bleepingcomputer.com/forums/topic308364.html

Program started at: 08/17/2015 07:12:08 AM in x86 mode.
Windows Version: Microsoft Windows XP Service Pack 3

Checking for Windows services to stop:

 * No malware services found to stop.

Checking for processes to terminate:

 * C:\WINDOWS\eHome\ehRecvr.exe (PID: 932) [WD-HEUR]
 * C:\WINDOWS\eHome\ehSched.exe (PID: 1288) [WD-HEUR]
 * C:\WINDOWS\system32\FsUsbExService.Exe (PID: 1720) [WD-HEUR]
 * C:\WINDOWS\system32\HPZipm12.exe (PID: 2560) [WD-HEUR]
 * C:\WINDOWS\System32\StkASv2K.exe (PID: 3024) [WD-HEUR]
 * C:\WINDOWS\system32\wdfmgr.exe (PID: 3072) [WD-HEUR]
 * C:\WINDOWS\ehome\mcrdsvc.exe (PID: 3288) [WD-HEUR]
 * C:\WINDOWS\system32\rundll32.exe (PID: 2640) [WD-HEUR]
 * C:\WINDOWS\system32\dla\tfswctrl.exe (PID: 2196) [WD-HEUR]
 * C:\WINDOWS\ehome\ehtray.exe (PID: 2072) [WD-HEUR]
 * C:\WINDOWS\System32\alg.exe (PID: 3988) [WD-HEUR]
 * C:\WINDOWS\eHome\ehmsas.exe (PID: 1932) [WD-HEUR]

12 proccesses terminated!

Possibly Patched Files.

 * C:\WINDOWS\system32\services.exe
 * C:\WINDOWS\system32\lsass.exe
 * C:\WINDOWS\system32\svchost.exe
 * C:\WINDOWS\system32\svchost.exe
 * C:\WINDOWS\System32\svchost.exe
 * C:\WINDOWS\system32\svchost.exe
 * C:\WINDOWS\system32\svchost.exe
 * C:\WINDOWS\system32\spoolsv.exe
 * C:\WINDOWS\system32\svchost.exe
 * C:\WINDOWS\system32\svchost.exe
 * C:\WINDOWS\system32\svchost.exe
 * C:\WINDOWS\system32\wbem\wmiprvse.exe
 * C:\WINDOWS\system32\ctfmon.exe
 * C:\WINDOWS\system32\dllhost.exe
 * C:\WINDOWS\system32\wscntfy.exe

Checking Registry for malware related settings:

 * No issues found in the Registry.

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

 * Windows Defender Disabled

   [HKLM\SOFTWARE\Microsoft\Windows Defender]
   "DisableAntiSpyware" = dword:00000001

 * Windows Firewall Disabled

   [HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
   "EnableFirewall" = dword:00000000

Checking Windows Service Integrity:

 * No issues found.

Searching for Missing Digital Signatures:

 * C:\WINDOWS\System32\appmgmts.dll : 167,936 : 04/13/2008 08:11 PM : d8849f77c0b66226335a59d26cb4edc6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\appmgmts.dll : 167,936 : 08/10/2004 06:00 AM : 9c3c12975c97119412802b181fbeeffe [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\appmgmts.dll : 167,936 : 04/13/2008 08:11 PM : d8849f77c0b66226335a59d26cb4edc6 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\appmgmts.dll : 167,936 : 04/13/2008 08:11 PM : d8849f77c0b66226335a59d26cb4edc6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\appmgmts.dll : 167,936 : 04/13/2008 08:11 PM : d8849f77c0b66226335a59d26cb4edc6 [Pos Repl]

 * C:\WINDOWS\System32\browser.dll : 78,336 : 07/06/2012 09:58 AM : cfd4e51402da9838b5a04ae680af54a0 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2705219\SP3QFE\browser.dll : 78,336 : 07/06/2012 09:58 AM : fc6d1d80588d371f0321e15a75b2f8f2 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\browser.dll : 77,312 : 08/10/2004 06:00 AM : e3cfccdda4edd1d0dc9168b2e18f27b8 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2705219$\browser.dll : 77,824 : 04/13/2008 08:11 PM : a06ce3399d16db864f55faeb1f1927a9 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\browser.dll : 77,824 : 04/13/2008 08:11 PM : a06ce3399d16db864f55faeb1f1927a9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\browser.dll : 77,824 : 04/13/2008 08:11 PM : a06ce3399d16db864f55faeb1f1927a9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\browser.dll : 78,336 : 07/06/2012 09:58 AM : cfd4e51402da9838b5a04ae680af54a0 [Pos Repl]

 * C:\WINDOWS\System32\clipsrv.exe : 33,280 : 04/13/2008 08:12 PM : 34cbe729f38138217f9c80212a2a0c82 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\clipsrv.exe : 33,280 : 08/10/2004 06:00 AM : c8dec22c4137d7a90f8bdf41ca4b82ae [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\clipsrv.exe : 33,280 : 04/13/2008 08:12 PM : 34cbe729f38138217f9c80212a2a0c82 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\clipsrv.exe : 33,280 : 04/13/2008 08:12 PM : 34cbe729f38138217f9c80212a2a0c82 [Pos Repl]

 * C:\WINDOWS\System32\comctl32.dll : 617,472 : 08/23/2010 12:12 AM : 93afb83fbc1f9443cac722fca63d73bf [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\comctl32.dll : 617,472 : 08/25/2006 11:45 AM : b0124cb21d28b1c9f678b566b6b57d92 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2296011$\comctl32.dll : 617,472 : 04/13/2008 08:11 PM : 06f247492bc786ce5c24a23e178c711a [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB923191$\comctl32.dll : 611,328 : 08/10/2004 06:00 AM : a77dfb85faee49d66c74da6024ebc69b [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\comctl32.dll : 617,472 : 08/23/2010 12:12 AM : 93afb83fbc1f9443cac722fca63d73bf [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\comctl32.dll : 617,472 : 04/13/2008 08:11 PM : 06f247492bc786ce5c24a23e178c711a [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\comctl32.dll : 617,472 : 08/23/2010 12:12 AM : 93afb83fbc1f9443cac722fca63d73bf [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll : 921,088 : 08/10/2004 06:00 AM : aef3d788dbf40c7c4d204ea45eb0c505 [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll : 1,050,624 : 08/10/2004 06:00 AM : 5af68a5e44734a082442668e9c787743 [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll : 1,054,208 : 08/25/2006 11:45 AM : c4e80875c1cf1222fc5efd0314ae5c01 [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll : 1,054,208 : 04/13/2008 08:12 PM : bd38d1ebe24a46bd3eda059560afba12 [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll : 1,054,208 : 08/23/2010 12:12 AM : 736b12b725aeb2b07f0241a9f680cb10 [Pos Repl]

 * C:\WINDOWS\System32\comres.dll : 792,064 : 04/13/2008 08:11 PM : 1280a158c722fa95a80fb7aebe78fa7d [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\comres.dll : 792,064 : 08/10/2004 06:00 AM : 6728270cb7dbb776ed086f5ac4c82310 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\comres.dll : 792,064 : 04/13/2008 08:11 PM : 1280a158c722fa95a80fb7aebe78fa7d [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\comres.dll : 792,064 : 04/13/2008 08:11 PM : 1280a158c722fa95a80fb7aebe78fa7d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\comres.dll : 792,064 : 04/13/2008 08:11 PM : 1280a158c722fa95a80fb7aebe78fa7d [Pos Repl]

 * C:\WINDOWS\System32\cryptsvc.dll : 62,464 : 04/13/2008 08:11 PM : 3d4e199942e29207970e04315d02ad3b [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\cryptsvc.dll : 60,416 : 08/10/2004 06:00 AM : 10654f9ddcea9c46cfb77554231be73b [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\cryptsvc.dll : 62,464 : 04/13/2008 08:11 PM : 3d4e199942e29207970e04315d02ad3b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll : 62,464 : 04/13/2008 08:11 PM : 3d4e199942e29207970e04315d02ad3b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\cryptsvc.dll : 62,464 : 04/13/2008 08:11 PM : 3d4e199942e29207970e04315d02ad3b [Pos Repl]

 * C:\WINDOWS\System32\csrss.exe : 6,144 : 04/13/2008 08:12 PM : 44f275c64738ea2056e3d9580c23b60f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\csrss.exe : 6,144 : 08/10/2004 06:00 AM : f12b178b1678d778cfd3ff1fc38c71fb [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\csrss.exe : 6,144 : 04/13/2008 08:12 PM : 44f275c64738ea2056e3d9580c23b60f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\csrss.exe : 6,144 : 04/13/2008 08:12 PM : 44f275c64738ea2056e3d9580c23b60f [Pos Repl]

 * C:\WINDOWS\System32\ctfmon.exe : 15,360 : 04/13/2008 08:12 PM : 5f1d5f88303d4a4dbc8e5f97ba967cc3 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ctfmon.exe : 15,360 : 08/10/2004 06:00 AM : 24232996a38c0b0cf151c2140ae29fc8 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ctfmon.exe : 15,360 : 04/13/2008 08:12 PM : 5f1d5f88303d4a4dbc8e5f97ba967cc3 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ctfmon.exe : 15,360 : 04/13/2008 08:12 PM : 5f1d5f88303d4a4dbc8e5f97ba967cc3 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ctfmon.exe : 15,360 : 04/13/2008 08:12 PM : 5f1d5f88303d4a4dbc8e5f97ba967cc3 [Pos Repl]

 * C:\WINDOWS\System32\d3d8.dll : 1,179,648 : 04/13/2008 08:11 PM : f099b129022170f2df9e1c0185c9bcfb [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\d3d8.dll : 1,179,648 : 08/10/2004 06:00 AM : 42803ec60803c1a0754671e9183458f1 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\d3d8.dll : 1,179,648 : 04/13/2008 08:11 PM : f099b129022170f2df9e1c0185c9bcfb [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\d3d8.dll : 1,179,648 : 04/13/2008 08:11 PM : f099b129022170f2df9e1c0185c9bcfb [Pos Repl]

 * C:\WINDOWS\System32\d3d8thk.dll : 8,192 : 04/13/2008 08:11 PM : 31b067c412fa1a9bad3ca2a63d7da440 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\d3d8thk.dll : 8,192 : 08/10/2004 06:00 AM : 8d9210e9858d525646251dfa1fe37ebe [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\d3d8thk.dll : 8,192 : 04/13/2008 08:11 PM : 31b067c412fa1a9bad3ca2a63d7da440 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\d3d8thk.dll : 8,192 : 04/13/2008 08:11 PM : 31b067c412fa1a9bad3ca2a63d7da440 [Pos Repl]

 * C:\WINDOWS\System32\d3d9.dll : 1,689,088 : 04/13/2008 08:11 PM : 0607cbc6fa20114cb491efe4b2f9efad [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\d3d9.dll : 1,689,088 : 08/10/2004 06:00 AM : d67bdbbda86cc9aeebbaf3217c1717d8 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\d3d9.dll : 1,689,088 : 04/13/2008 08:11 PM : 0607cbc6fa20114cb491efe4b2f9efad [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\d3d9.dll : 1,689,088 : 04/13/2008 08:11 PM : 0607cbc6fa20114cb491efe4b2f9efad [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\d3d9.dll : 1,689,088 : 04/13/2008 08:11 PM : 0607cbc6fa20114cb491efe4b2f9efad [Pos Repl]

 * C:\WINDOWS\System32\ddraw.dll : 279,552 : 04/13/2008 08:11 PM : a340cd71eb535a3dd751b5f28723e50c [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ddraw.dll : 266,240 : 08/10/2004 06:00 AM : 7ed462f353b3d915a418a689fa881f96 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ddraw.dll : 279,552 : 04/13/2008 08:11 PM : a340cd71eb535a3dd751b5f28723e50c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ddraw.dll : 279,552 : 04/13/2008 08:11 PM : a340cd71eb535a3dd751b5f28723e50c [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ddraw.dll : 279,552 : 04/13/2008 08:11 PM : a340cd71eb535a3dd751b5f28723e50c [Pos Repl]

 * C:\WINDOWS\System32\dllhost.exe : 5,120 : 04/13/2008 08:12 PM : 0a9ba6af531afe7fa5e4fb973852d863 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\dllhost.exe : 5,120 : 08/10/2004 06:00 AM : dd87db7387b9eb441c5674888a0d840c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\dllhost.exe : 5,120 : 04/13/2008 08:12 PM : 0a9ba6af531afe7fa5e4fb973852d863 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\dllhost.exe : 5,120 : 04/13/2008 08:12 PM : 0a9ba6af531afe7fa5e4fb973852d863 [Pos Repl]

 * C:\WINDOWS\System32\dsound.dll : 367,616 : 04/13/2008 08:11 PM : 4d83ed8bddec431fc8ad907b47cfb6e3 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\dsound.dll : 367,616 : 08/10/2004 06:00 AM : 55e148c01296696588eafa425782c3e8 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\dsound.dll : 367,616 : 04/13/2008 08:11 PM : 4d83ed8bddec431fc8ad907b47cfb6e3 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\dsound.dll : 367,616 : 04/13/2008 08:11 PM : 4d83ed8bddec431fc8ad907b47cfb6e3 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\dsound.dll : 367,616 : 04/13/2008 08:11 PM : 4d83ed8bddec431fc8ad907b47cfb6e3 [Pos Repl]

 * C:\WINDOWS\System32\dssenh.dll : 138,752 : 04/13/2008 01:37 PM : fede68bf80052bad393afd5c2e60dcb0 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\dssenh.dll : 137,216 : 08/10/2004 06:00 AM : cacd2c63a79268d131ea37e85524cc44 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\dssenh.dll : 138,752 : 04/13/2008 01:37 PM : fede68bf80052bad393afd5c2e60dcb0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\dssenh.dll : 138,752 : 04/13/2008 01:37 PM : fede68bf80052bad393afd5c2e60dcb0 [Pos Repl]

 * C:\WINDOWS\System32\es.dll : 253,952 : 07/07/2008 04:26 PM : d4991d98f2db73c60d042f1aef79efae [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\es.dll : 243,200 : 07/26/2005 00:20 AM : 95f5fea4c6de2c3f28784d0dcc8f0dd3 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB950974\SP3QFE\es.dll : 253,952 : 07/07/2008 04:23 PM : f17f6226bdc0cd5f0bef0daf84d29bec [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\es.dll : 243,200 : 07/26/2005 00:39 AM : 34bbd9acc1538818f2c878898c64e793 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB902400$\es.dll : 243,200 : 08/10/2004 06:00 AM : acd36a2dd7d1e9d8a060aa651dc07e63 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB950974$\es.dll : 246,272 : 04/13/2008 08:11 PM : 19a799805b24990867b00c120d300c3a [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\es.dll : 253,952 : 07/07/2008 04:26 PM : d4991d98f2db73c60d042f1aef79efae [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\es.dll : 246,272 : 04/13/2008 08:11 PM : 19a799805b24990867b00c120d300c3a [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\es.dll : 253,952 : 07/07/2008 04:26 PM : d4991d98f2db73c60d042f1aef79efae [Pos Repl]

 * C:\WINDOWS\System32\eventlog.dll : 56,320 : 04/13/2008 08:11 PM : 6d4feb43ee538fc5428cc7f0565aa656 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll : 55,808 : 08/10/2004 06:00 AM : 82b24cb70e5944e6e34662205a2a5b78 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\eventlog.dll : 56,320 : 04/13/2008 08:11 PM : 6d4feb43ee538fc5428cc7f0565aa656 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\eventlog.dll : 56,320 : 04/13/2008 08:11 PM : 6d4feb43ee538fc5428cc7f0565aa656 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\eventlog.dll : 56,320 : 04/13/2008 08:11 PM : 6d4feb43ee538fc5428cc7f0565aa656 [Pos Repl]

 * C:\WINDOWS\System32\hid.dll : 20,992 : 04/13/2008 08:11 PM : 8973122796e3b5d6b5900fc186e55fea [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\hid.dll : 20,992 : 08/10/2004 06:00 AM : 18afee0ede045b6255408d634372dc29 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\hid.dll : 20,992 : 04/13/2008 08:11 PM : 8973122796e3b5d6b5900fc186e55fea [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\hid.dll : 20,992 : 04/13/2008 08:11 PM : 8973122796e3b5d6b5900fc186e55fea [Pos Repl]

 * C:\WINDOWS\System32\hnetcfg.dll : 344,064 : 04/13/2008 08:11 PM : 3cb32d3b8cbe79899d63280bb7a83cd9 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\hnetcfg.dll : 344,064 : 08/10/2004 06:00 AM : 765b30c776a1780b46b479fe614f707c [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\hnetcfg.dll : 344,064 : 04/13/2008 08:11 PM : 3cb32d3b8cbe79899d63280bb7a83cd9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\hnetcfg.dll : 344,064 : 04/13/2008 08:11 PM : 3cb32d3b8cbe79899d63280bb7a83cd9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\hnetcfg.dll : 344,064 : 04/13/2008 08:11 PM : 3cb32d3b8cbe79899d63280bb7a83cd9 [Pos Repl]

 * C:\WINDOWS\System32\imm32.dll : 110,080 : 04/13/2008 08:11 PM : 0da85218e92526972a821587e6a8bf8f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\imm32.dll : 110,080 : 08/10/2004 06:00 AM : 87ca7ce6469577f059297b9d6556d66d [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\imm32.dll : 110,080 : 04/13/2008 08:11 PM : 0da85218e92526972a821587e6a8bf8f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\imm32.dll : 110,080 : 04/13/2008 08:11 PM : 0da85218e92526972a821587e6a8bf8f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\imm32.dll : 110,080 : 04/13/2008 08:11 PM : 0da85218e92526972a821587e6a8bf8f [Pos Repl]

 * C:\WINDOWS\System32\ipsecsvc.dll : 183,808 : 04/13/2008 08:11 PM : 332760fba1655fcfd35bd6f4fd871300 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ipsecsvc.dll : 182,784 : 08/10/2004 06:00 AM : d1e299962b5956005113ec4ab1e0d9b7 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ipsecsvc.dll : 183,808 : 04/13/2008 08:11 PM : 332760fba1655fcfd35bd6f4fd871300 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ipsecsvc.dll : 183,808 : 04/13/2008 08:11 PM : 332760fba1655fcfd35bd6f4fd871300 [Pos Repl]

 * C:\WINDOWS\System32\kernel32.dll : 993,280 : 03/12/2014 06:48 AM : 4a45b692d2baa74124df57472d5ea2f1 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2758857\SP3QFE\kernel32.dll : 991,744 : 10/03/2012 00:57 AM : 6cbfeeb384f04681af75f495aa48dd32 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB917422\SP2QFE\kernel32.dll : 985,088 : 07/05/2006 06:57 AM : 0fdd84928a5dde2510761b7ec76ccec9 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB935839\SP2QFE\kernel32.dll : 986,112 : 04/16/2007 12:07 AM : 09f7cb3687f86edaa4ca081f7ab66c03 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB959426\SP3QFE\kernel32.dll : 991,744 : 03/21/2009 09:59 AM : da11d9d6ecbdf0f93436a4b7c13f7bec [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\kernel32.dll : 984,576 : 04/16/2007 11:52 AM : a01f9ca902a88f7ced06884174d6419d [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2758857$\kernel32.dll : 989,696 : 03/21/2009 10:06 AM : b921fb870c9ac0d509b2ccabbbbe95f3 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2922229$\kernel32.dll : 990,208 : 10/03/2012 00:58 AM : 6fe42512ab1b89f32a7407f261b1d2d0 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB917422$\kernel32.dll : 983,552 : 08/10/2004 06:00 AM : 888190e31455fad793312f8d087146eb [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB935839$\kernel32.dll : 984,064 : 07/05/2006 06:55 AM : d8db5397de07577c1cb50ba6d23b3ad4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB959426$\kernel32.dll : 989,696 : 04/13/2008 08:11 PM : c24b983d211c34da8fcc1ac38477971d [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\kernel32.dll : 989,696 : 03/21/2009 10:06 AM : b921fb870c9ac0d509b2ccabbbbe95f3 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\kernel32.dll : 989,696 : 04/13/2008 08:11 PM : c24b983d211c34da8fcc1ac38477971d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\kernel32.dll : 993,280 : 03/12/2014 06:48 AM : 4a45b692d2baa74124df57472d5ea2f1 [Pos Repl]

 * C:\WINDOWS\System32\ksuser.dll : 4,096 : 04/13/2008 08:11 PM : 9b9f1c38d559047b8ac0dba2d5febde9 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ksuser.dll : 4,096 : 08/04/2004 01:56 AM : cbcd254547689bff80c9f547b20911e9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ksuser.dll : 4,096 : 04/13/2008 08:11 PM : 9b9f1c38d559047b8ac0dba2d5febde9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ksuser.dll : 4,096 : 04/13/2008 08:11 PM : 9b9f1c38d559047b8ac0dba2d5febde9 [Pos Repl]

 * C:\WINDOWS\System32\linkinfo.dll : 19,968 : 04/13/2008 08:11 PM : 2dc5a8019e2387987905f77c664e4be2 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB900725\SP2QFE\linkinfo.dll : 19,968 : 08/31/2005 09:44 PM : 648bf0b4dde4f7a1156dae7174d36efa [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\linkinfo.dll : 19,968 : 08/31/2005 09:41 PM : a1a688ee56cf3bbd24edeb815d48e9ba [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB900725$\linkinfo.dll : 18,944 : 08/10/2004 06:00 AM : c2bbd044c741ea4292016c36f718d2e4 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\linkinfo.dll : 19,968 : 04/13/2008 08:11 PM : 2dc5a8019e2387987905f77c664e4be2 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\linkinfo.dll : 19,968 : 04/13/2008 08:11 PM : 2dc5a8019e2387987905f77c664e4be2 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\linkinfo.dll : 19,968 : 04/13/2008 08:11 PM : 2dc5a8019e2387987905f77c664e4be2 [Pos Repl]

 * C:\WINDOWS\System32\lpk.dll : 22,016 : 04/13/2008 08:11 PM : 012df358cebaa23acb26d82077820817 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\lpk.dll : 22,016 : 08/10/2004 06:00 AM : 74d66b3de265e8789153414e75175f26 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\lpk.dll : 22,016 : 04/13/2008 08:11 PM : 012df358cebaa23acb26d82077820817 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\lpk.dll : 22,016 : 04/13/2008 08:11 PM : 012df358cebaa23acb26d82077820817 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\lpk.dll : 22,016 : 04/13/2008 08:11 PM : 012df358cebaa23acb26d82077820817 [Pos Repl]

 * C:\WINDOWS\System32\lsass.exe : 13,312 : 04/13/2008 08:12 PM : bf2466b3e18e970d8a976fb95fc1ca85 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\lsass.exe : 13,312 : 08/10/2004 06:00 AM : 84885f9b82f4d55c6146ebf6065d75d2 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\lsass.exe : 13,312 : 04/13/2008 08:12 PM : bf2466b3e18e970d8a976fb95fc1ca85 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\lsass.exe : 13,312 : 04/13/2008 08:12 PM : bf2466b3e18e970d8a976fb95fc1ca85 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\lsass.exe : 13,312 : 04/13/2008 08:12 PM : bf2466b3e18e970d8a976fb95fc1ca85 [Pos Repl]

 * C:\WINDOWS\System32\mfc40u.dll : 953,856 : 09/18/2010 02:53 AM : e76a5c202e68af5a322d16b5a78f48b9 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll : 953,856 : 09/18/2010 03:18 AM : 842900dedbc8e3e8dbcccb298fd88f65 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mfc40u.dll : 927,504 : 11/01/2006 03:17 PM : 925f8b61ed301a317ba850ebeecbdaa0 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2387149$\mfc40u.dll : 927,504 : 04/13/2008 08:11 PM : cddd4416b2b4c7295fe3fdb6dde57e4e [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB924667$\mfc40u.dll : 924,432 : 08/10/2004 06:00 AM : ddf8d47acf8fc3fe5f7f2b95c4d4d136 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\mfc40u.dll : 953,856 : 09/18/2010 02:53 AM : e76a5c202e68af5a322d16b5a78f48b9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mfc40u.dll : 927,504 : 04/13/2008 08:11 PM : cddd4416b2b4c7295fe3fdb6dde57e4e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mfc40u.dll : 953,856 : 09/18/2010 02:53 AM : e76a5c202e68af5a322d16b5a78f48b9 [Pos Repl]

 * C:\WINDOWS\System32\midimap.dll : 18,944 : 04/13/2008 08:11 PM : 5c12660a97822f6e61576943b49aaad6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\midimap.dll : 18,944 : 08/10/2004 06:00 AM : 3b4702155bb2ae9dc00c06a68834bdfa [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\midimap.dll : 18,944 : 04/13/2008 08:11 PM : 5c12660a97822f6e61576943b49aaad6 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\midimap.dll : 18,944 : 04/13/2008 08:11 PM : 5c12660a97822f6e61576943b49aaad6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\midimap.dll : 18,944 : 04/13/2008 08:11 PM : 5c12660a97822f6e61576943b49aaad6 [Pos Repl]

 * C:\WINDOWS\System32\msgsvc.dll : 33,792 : 04/13/2008 08:11 PM : 986b1ff5814366d71e0ac5755c88f2d3 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\msgsvc.dll : 33,792 : 08/10/2004 06:00 AM : 95fd808e4ac22aba025a7b3eac0375d2 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\msgsvc.dll : 33,792 : 04/13/2008 08:11 PM : 986b1ff5814366d71e0ac5755c88f2d3 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\msgsvc.dll : 33,792 : 04/13/2008 08:11 PM : 986b1ff5814366d71e0ac5755c88f2d3 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\msgsvc.dll : 33,792 : 04/13/2008 08:11 PM : 986b1ff5814366d71e0ac5755c88f2d3 [Pos Repl]

 * C:\WINDOWS\System32\mshtml.dll : 6,022,144 : 04/30/2014 04:13 AM : 3db2624ccb1663bf6d62311b2b9e7b55 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2183461-IE8\SP3QFE\mshtml.dll : 5,954,560 : 06/24/2010 08:24 AM : 94dc7e938c57f3c3d1bc4a0f68fc5830 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2360131-IE8\SP3QFE\mshtml.dll : 5,958,656 : 09/10/2010 01:57 AM : 8a03cc037e6b7d1796192815231b0c3f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2416400-IE8\SP3QFE\mshtml.dll : 5,960,704 : 11/05/2010 08:27 PM : 864e69f32656a7121444ba0193d7b64b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2482017-IE8\SP3QFE\mshtml.dll : 5,962,240 : 12/20/2010 07:58 PM : 2a2c070ec691ce410533a1da7aa3cd86 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2497640-IE8\SP3QFE\mshtml.dll : 5,964,800 : 02/22/2011 07:27 PM : 3422847aa07e37076a87d0b7d5044dc6 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2530548-IE8\SP3QFE\mshtml.dll : 5,967,360 : 05/30/2011 06:17 PM : d0b1db576941cb0b6669b8752ffac79a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2559049-IE8\SP3QFE\mshtml.dll : 5,971,456 : 07/25/2011 11:15 AM : bce7ccebad6c8955d2b4c3b246bd0e57 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2586448-IE8\SP3QFE\mshtml.dll : 5,972,992 : 10/03/2011 04:34 AM : 1240a6b7b470bed0aa6c9fec7ab0ea26 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2618444-IE8\SP3QFE\mshtml.dll : 5,978,624 : 11/04/2011 03:19 PM : 699421e2e1313c18671a703953cae14b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2647516-IE8\SP3QFE\mshtml.dll : 5,980,160 : 12/17/2011 03:45 PM : 49b88a833eca99efbffc5aae5cc998ed [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2675157-IE8\SP3QFE\mshtml.dll : 5,980,672 : 03/01/2012 06:58 AM : 5dbb0c997ad276bce9d30cd609bdbf67 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2699988-IE8\SP3QFE\mshtml.dll : 6,009,344 : 05/11/2012 10:41 AM : 55f148b94246a77fb4ac33346671cac8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2722913-IE8\SP3QFE\mshtml.dll : 6,010,368 : 07/02/2012 01:48 PM : df599ac52b62de001e42d36f92b45e68 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2744842-IE8\SP3QFE\mshtml.dll : 6,010,368 : 08/28/2012 11:13 AM : cf6b381c3518ab328382429cae206d64 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2761465-IE8\SP3QFE\mshtml.dll : 6,010,880 : 11/13/2012 02:23 AM : 02d8509e2362d777debffc05c022cbf2 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2792100-IE8\SP3QFE\mshtml.dll : 6,011,904 : 01/09/2013 03:03 AM : 99e9e2606fb13adb711935fe8e8e29c1 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2799329-IE8\SP3QFE\mshtml.dll : 6,011,392 : 01/06/2013 01:33 AM : 14fd1caefb6d2749019ac2f54859568c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2809289-IE8\SP3QFE\mshtml.dll : 6,012,928 : 02/28/2013 10:31 PM : ae3a26c04c794e5451adf6872f7d48f4 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2817183-IE8\SP3QFE\mshtml.dll : 6,013,440 : 03/01/2013 10:05 PM : 990f4518e1607f445969c12f014e4e29 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB905915\SP2QFE\mshtml.dll : 3,018,240 : 11/23/2005 06:07 PM : d3f037f5da702ae9ddd7663ec9d78ba7 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\mshtml.dll : 3,582,976 : 03/07/2007 11:40 AM : da297a862e5f093a07d37c05f608c686 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\mshtml.dll : 3,584,000 : 05/08/2007 05:25 AM : 1d4e3b86c601a2497c99790cc4d7df26 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\mshtml.dll : 3,584,000 : 07/18/2007 05:09 PM : 7ce243cfd47ad0dc431586cb8c542a11 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\mshtml.dll : 3,592,192 : 08/20/2007 06:02 AM : aa8a4bd78d24fcdb96ddaee3756aa372 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\mshtml.dll : 3,593,216 : 10/30/2007 07:48 PM : 54d8b404f17aa74c666f7f3aef2ae459 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\mshtml.dll : 3,593,216 : 12/06/2007 10:01 PM : 976c46ed4a75fc66d9c596778898ce1e [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\mshtml.dll : 3,593,216 : 03/01/2008 09:03 AM : 4ee273e2b09317c1217ef0db91f93534 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\mshtml.dll : 3,593,728 : 04/22/2008 11:35 PM : 4d612ff5d3b7eef200595ae6f95d5e68 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\mshtml.dll : 3,594,240 : 06/23/2008 12:01 AM : 28b8231ca8d55fc85e027a57c90f5c88 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll : 3,594,752 : 08/26/2008 05:08 AM : 25cc085720ee3617fd1f8ab9e2f7cab2 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll : 3,595,264 : 10/16/2008 04:24 PM : b74f31a4bd83797d7a083f922169287d [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll : 3,594,752 : 12/13/2008 02:26 AM : c79fad61cd4a26ed5aa8c16d991c6fbd [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll : 3,596,288 : 01/16/2009 12:24 AM : cc9d001b7370b292c35b366ca05b12b4 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll : 3,596,800 : 02/21/2009 03:39 AM : 1bb754ab47b327de8dbf2fa18c36357c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\mshtml.dll : 3,598,336 : 04/29/2009 00:49 AM : c6fd770d518fb024245a0ee217d72bc1 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\mshtml.dll : 3,600,384 : 07/19/2009 09:31 AM : f6098cc1b1c3858d53f20f3cb5774f3b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\mshtml.dll : 3,600,384 : 08/29/2009 03:31 AM : edad55105ddd067ae3906011f297267c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\mshtml.dll : 3,602,432 : 10/29/2009 03:45 AM : 8b48737260c273c9b0daca84ea1ccdbd [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB976749-IE7\SP3QFE\mshtml.dll : 3,602,432 : 10/20/2009 11:59 PM : e6453ee08b283419171889786d057a75 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\mshtml.dll : 3,602,944 : 01/05/2010 05:57 AM : 1673677dbd70142db1294f1b6fc3323e [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\mshtml.dll : 3,602,944 : 03/11/2010 07:49 AM : 9289ebb759293a1381ab0c326a115aec [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll : 5,946,880 : 02/25/2010 02:19 AM : 974772c74da7c7a8e7c813a9908a845f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll : 5,953,024 : 05/06/2010 06:36 AM : 9be28f749a7fe7f8f177c6aa2e9da609 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB912812$\mshtml.dll : 3,015,680 : 11/23/2005 09:06 PM : 5e7a39950ea133bb54719a6e08c544a7 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB916281$\mshtml.dll : 3,055,616 : 03/23/2006 04:31 PM : abcd123f888e4e97c8751378cccc4f26 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB918899$\mshtml.dll : 3,055,104 : 05/19/2006 11:06 AM : 8687e029be63c77d4919485068c54d77 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB922760$\mshtml.dll : 3,058,176 : 07/28/2006 07:30 AM : d251679bd9ef0250201fb899ec40fd32 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\mshtml.dll : 5,964,800 : 05/30/2011 06:19 PM : 22ba5235ea846eda87f68a1dcc2bfcf9 [Pos Repl]
 +-> C:\WINDOWS\ie7\mshtml.dll : 3,058,688 : 09/14/2006 04:31 AM : cefea1c301139a817931be132f0359fe [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB928090-IE7\mshtml.dll : 3,577,856 : 11/07/2006 10:03 PM : cbf04597f9cf7739e572276a2698fdd3 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB931768-IE7\mshtml.dll : 3,580,416 : 01/12/2007 10:27 AM : 5d45318804a30ce9d6ea83066e84b4a7 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB933566-IE7\mshtml.dll : 3,581,952 : 03/07/2007 01:45 PM : 190e1ae9b973049b12a67bad478c770c [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB937143-IE7\mshtml.dll : 3,583,488 : 05/08/2007 05:24 AM : 5d90a7200f72dace663ee78de234fcc7 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB939653-IE7\mshtml.dll : 3,583,488 : 07/19/2007 02:59 AM : bd609a26b683332a0e0e1445c5724851 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB942615-IE7\mshtml.dll : 3,584,512 : 08/20/2007 06:04 AM : e267ee248cda7667c19001c069de867b [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB944533-IE7\mshtml.dll : 3,590,656 : 10/30/2007 07:42 PM : 8ab7ecf59d6ebbe986277b65ed4a40a1 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB947864-IE7\mshtml.dll : 3,592,192 : 12/08/2007 01:21 AM : a097c36412455f0c7e42377faf8809b7 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB950759-IE7\mshtml.dll : 3,591,680 : 03/01/2008 06:36 PM : ab2c88167d78d71d93558acecb24cc7a [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB953838-IE7\mshtml.dll : 3,591,680 : 04/23/2008 10:16 PM : 8976cab317105f7431b08ea32ab73c65 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB956390-IE7\mshtml.dll : 3,592,192 : 06/24/2008 10:57 AM : ec936148284f557f19c333178768109b [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB958215-IE7\mshtml.dll : 3,593,216 : 08/27/2008 04:24 AM : 1ad035e04a7068ec2820b055a3131ed8 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB960714-IE7\mshtml.dll : 3,593,216 : 10/17/2008 03:08 AM : eacaedef6fa2a969de5b36190d45396f [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB961260-IE7\mshtml.dll : 3,593,216 : 12/13/2008 02:40 AM : 121ec39a64d64205a88c2c45b034b455 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB963027-IE7\mshtml.dll : 3,594,752 : 01/16/2009 10:35 PM : 3b413267da8ae71c20e5ef3e54f74728 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB969897-IE7\mshtml.dll : 3,595,264 : 02/20/2009 02:09 PM : c7c3e41cc2f6eb4a629fe2184136c098 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB972260-IE7\mshtml.dll : 3,596,288 : 04/29/2009 00:56 AM : 2b4315ec9e3124408a2a5074c4b97700 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB974455-IE7\mshtml.dll : 3,597,824 : 07/19/2009 09:33 AM : 758c8bedab7ce5f9070c85e2e57cbd80 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB976325-IE7\mshtml.dll : 3,598,336 : 10/21/2009 00:08 AM : 36145d2d908fb8a24772f04842366918 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB976749-IE7\mshtml.dll : 3,598,336 : 08/29/2009 03:36 AM : e52a845dce011d56b12b8f3f4606f956 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB978207-IE7\mshtml.dll : 3,598,336 : 10/29/2009 03:46 AM : 89a9658515a18e673034369e043fab01 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB980182-IE7\mshtml.dll : 3,599,360 : 01/05/2010 06:00 AM : 3b8259ef10c0f1425395981e40ed0eaa [Pos Repl]
 +-> C:\WINDOWS\ie8\mshtml.dll : 3,599,872 : 03/11/2010 08:38 AM : 94359cd5bb6ac1cc08088f4a4091ff1e [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2183461-IE8\mshtml.dll : 5,950,976 : 05/06/2010 06:41 AM : c7b7a88cc7d7aba5c395145bf92f46f7 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2360131-IE8\mshtml.dll : 5,951,488 : 06/24/2010 08:22 AM : 4d7ef94795384cd2bbaab078b7929fea [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2416400-IE8\mshtml.dll : 5,957,120 : 09/10/2010 01:58 AM : de41132da8e5a3cd57201c6f2175ec05 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2482017-IE8\mshtml.dll : 5,959,168 : 11/05/2010 08:26 PM : d7cca87057901c87ed8cc40ddcc7fa1b [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2497640-IE8\mshtml.dll : 5,961,216 : 12/20/2010 07:59 PM : 1edcec5d649dbac37ed9ffb5a14ceb0c [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2530548-IE8\mshtml.dll : 5,962,240 : 02/22/2011 07:06 PM : c2ef2335f1b6c2be20a67d9098f6c9a1 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2559049-IE8\mshtml.dll : 5,964,800 : 05/30/2011 06:19 PM : 22ba5235ea846eda87f68a1dcc2bfcf9 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2586448-IE8\mshtml.dll : 5,969,920 : 07/25/2011 11:17 AM : 23b3c8e9f3f280180573569253ce98ab [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2618444-IE8\mshtml.dll : 5,971,456 : 10/03/2011 04:35 AM : 4963cb503600fc3bcbdbfba51fba1fac [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2647516-IE8\mshtml.dll : 5,978,112 : 11/04/2011 03:20 PM : dd8d655e1881b70a5259a23a6018a6c2 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2675157-IE8\mshtml.dll : 5,979,136 : 12/17/2011 03:46 PM : a9259cd226283cd4f798c00909754a94 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2699988-IE8\mshtml.dll : 5,978,624 : 03/01/2012 07:01 AM : dade53318d8e5335ee2e1745f1c3fc4d [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2722913-IE8\mshtml.dll : 6,007,808 : 05/11/2012 10:42 AM : 886b62a906b3967cbbf0fd2c833a30bf [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2744842-IE8\mshtml.dll : 6,008,320 : 07/02/2012 01:49 PM : 13d2e016b784730a98f24d6e5beed22f [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2761465-IE8\mshtml.dll : 6,008,832 : 08/28/2012 11:14 AM : df3c3ca94cbc9de07ac3eb49440a8d45 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2792100-IE8\mshtml.dll : 6,009,856 : 01/06/2013 01:34 AM : bdf6cc938c0644fe3643bc0d6a678e26 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2799329-IE8\mshtml.dll : 6,008,832 : 11/12/2012 03:57 PM : 9c46e5c82f94d9aedd2ce798f0df1158 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2809289-IE8\mshtml.dll : 6,010,368 : 01/08/2013 04:34 PM : 727c9e97cb26879c17a30484c2c76e98 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2817183-IE8\mshtml.dll : 6,011,392 : 02/28/2013 10:33 PM : 937091e40652c6b1b6c1a71eb90c08e1 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2838727-IE8\mshtml.dll : 6,015,488 : 05/07/2013 00:27 AM : 6dd9251c4d427de5eb828e0bffb95c5a [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2846071-IE8\mshtml.dll : 6,014,976 : 05/17/2013 06:07 PM : 05cf1926e4e7b6d91d66bd5cd54fc1f0 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2847204-IE8\mshtml.dll : 6,012,416 : 03/01/2013 10:06 PM : 85fe43a44239e406d7bb9513569d4d00 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2862772-IE8\mshtml.dll : 6,017,536 : 06/07/2013 05:56 PM : 76a0cf7f71b56cf9ccf46536affe3e26 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2870699-IE8\mshtml.dll : 6,017,536 : 07/25/2013 10:47 PM : 17965d48033d1a6e6320aa867351cc21 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2879017-IE8\mshtml.dll : 6,017,536 : 08/08/2013 02:05 AM : 4c9afe1ae4112d260a3e7846c60c774d [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2888505-IE8\mshtml.dll : 6,017,536 : 09/23/2013 02:33 PM : 579017cf9c919429188190dae79bb8fc [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2898785-IE8\mshtml.dll : 6,021,120 : 10/13/2013 03:25 AM : 0794cd09be3d1e7a966c95e76fc86f47 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2909921-IE8\mshtml.dll : 6,020,608 : 10/29/2013 03:57 AM : 680bd97ba5c817bce79162496d51528d [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2925418-IE8\mshtml.dll : 6,021,120 : 02/05/2014 07:26 PM : 516e371cc348141277a73eb9d3c25951 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2936068-IE8\mshtml.dll : 6,022,144 : 02/24/2014 07:46 AM : 427c63c2075abf62faa897bbd3de44f4 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2964358-IE8\mshtml.dll : 6,021,632 : 03/06/2014 01:59 PM : 0964efc80bd54fdf37397a09fdae8395 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB980182-IE8\mshtml.dll : 5,937,152 : 03/08/2009 04:41 AM : d469a0eba2ef5c6bee8065b7e3196e5e [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB982381-IE8\mshtml.dll : 5,944,832 : 02/25/2010 02:24 AM : 7054f6adc9b670887659f1561603b0d0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mshtml.dll : 3,066,880 : 04/13/2008 08:11 PM : a706e122b398fe1ab85cb9b75d044223 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mshtml.dll : 6,022,144 : 04/30/2014 04:13 AM : 3db2624ccb1663bf6d62311b2b9e7b55 [Pos Repl]

 * C:\WINDOWS\System32\msimg32.dll : 4,608 : 04/13/2008 08:11 PM : affc87e2501fce8f09d4c10ba6421ccf [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\msimg32.dll : 4,608 : 08/10/2004 06:00 AM : b5331f2b6f37c66c29c847f3b94ff900 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\msimg32.dll : 4,608 : 04/13/2008 08:11 PM : affc87e2501fce8f09d4c10ba6421ccf [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\msimg32.dll : 4,608 : 04/13/2008 08:11 PM : affc87e2501fce8f09d4c10ba6421ccf [Pos Repl]

 * C:\WINDOWS\System32\mspmsnsv.dll : 25,088 : 08/03/2005 07:29 PM : b9715b9c18bc6c8f4b66733d208cc9f7 [NoSig]
 +-> C:\WINDOWS\ERDNT\cache\MsPMSNSv.dll : 25,088 : 08/03/2005 07:29 PM : b9715b9c18bc6c8f4b66733d208cc9f7 [Pos Repl]
 +-> C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll : 25,088 : 08/03/2005 07:29 PM : b9715b9c18bc6c8f4b66733d208cc9f7 [Pos Repl]
 +-> C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}$BACKUP$\System\MsPMSNSv.dll : 25,088 : 08/10/2004 06:00 AM : 6eaa72fd9ef993ec1fa9a06de65105da [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mspmsnsv.dll : 25,088 : 08/03/2005 07:29 PM : b9715b9c18bc6c8f4b66733d208cc9f7 [Pos Repl]

 * C:\WINDOWS\System32\msprivs.dll : 48,128 : 04/13/2008 12:23 AM : c6bb1d1500db4a0e224cb65e6c7e8a80 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\msprivs.dll : 48,128 : 08/10/2004 06:00 AM : 6bec17053284e847cf1fbb8c9a181e1e [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\msprivs.dll : 48,128 : 04/13/2008 12:23 AM : c6bb1d1500db4a0e224cb65e6c7e8a80 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\msprivs.dll : 48,128 : 04/13/2008 12:23 AM : c6bb1d1500db4a0e224cb65e6c7e8a80 [Pos Repl]

 * C:\WINDOWS\System32\msvcrt.dll : 343,040 : 04/13/2008 08:12 PM : 355edbb4d412b01f1740c17e3f50fa00 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\msvcrt.dll : 343,040 : 08/10/2004 06:00 AM : b0fefa816d61ec66aa765ddf534eab5e [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\msvcrt.dll : 343,040 : 04/13/2008 08:12 PM : 355edbb4d412b01f1740c17e3f50fa00 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\msvcrt.dll : 343,040 : 04/13/2008 08:12 PM : 355edbb4d412b01f1740c17e3f50fa00 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\msvcrt.dll : 343,040 : 04/13/2008 08:12 PM : 355edbb4d412b01f1740c17e3f50fa00 [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\msvcrt.dll : 322,560 : 08/10/2004 06:00 AM : 4200be3808f6406dbe45a7b88dae5035 [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.2180_x-ww_b2505ed9\msvcrt.dll : 343,040 : 08/10/2004 06:00 AM : 98ec447e00229afd88d5161a25d065da [Pos Repl]
 +-> C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll : 343,040 : 04/13/2008 08:12 PM : d7075e95aa599ee77b7a89d39296bd3d [Pos Repl]

 * C:\WINDOWS\System32\mswsock.dll : 245,248 : 06/20/2008 12:02 AM : 943337d786a56729263071623bbb9de5 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\mswsock.dll : 245,248 : 06/20/2008 01:43 PM : fcee5fcb99f7c724593365c706d28388 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\mswsock.dll : 245,248 : 06/20/2008 01:36 PM : 1dfca7713ea5a70d5d93b436aea0317a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\mswsock.dll : 245,248 : 06/20/2008 01:46 PM : 832e4dd8964ab7acc880b2837cb1ed20 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\mswsock.dll : 245,248 : 06/20/2008 01:43 PM : fcee5fcb99f7c724593365c706d28388 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mswsock.dll : 245,248 : 06/20/2008 01:41 PM : 097722f235a1fb698bf9234e01b52637 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2509553$\mswsock.dll : 245,248 : 06/20/2008 01:46 PM : 832e4dd8964ab7acc880b2837cb1ed20 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748$\mswsock.dll : 245,248 : 04/13/2008 08:12 PM : b4138e99236f0f57d4cf49bae98a0746 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748_0$\mswsock.dll : 245,248 : 08/10/2004 06:00 AM : 4e74af063c3271fbea20dd940cfd1184 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\mswsock.dll : 245,248 : 06/20/2008 12:02 AM : 943337d786a56729263071623bbb9de5 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mswsock.dll : 245,248 : 04/13/2008 08:12 PM : b4138e99236f0f57d4cf49bae98a0746 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mswsock.dll : 245,248 : 06/20/2008 12:02 AM : 943337d786a56729263071623bbb9de5 [Pos Repl]

 * C:\WINDOWS\System32\netlogon.dll : 407,040 : 04/13/2008 08:12 PM : 1b7f071c51b77c272875c3a23e1e4550 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll : 407,040 : 08/10/2004 06:00 AM : 96353fcecba774bb8da74a1c6507015a [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\netlogon.dll : 407,040 : 04/13/2008 08:12 PM : 1b7f071c51b77c272875c3a23e1e4550 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\netlogon.dll : 407,040 : 04/13/2008 08:12 PM : 1b7f071c51b77c272875c3a23e1e4550 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\netlogon.dll : 407,040 : 04/13/2008 08:12 PM : 1b7f071c51b77c272875c3a23e1e4550 [Pos Repl]

 * C:\WINDOWS\System32\netman.dll : 198,144 : 04/13/2008 08:12 PM : 13e67b55b3abd7bf3fe7aae5a0f9a9de [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB905414\SP2QFE\netman.dll : 197,632 : 08/22/2005 02:24 PM : 3516d8a18b36784b1005b950b84232e1 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\netman.dll : 197,632 : 08/22/2005 02:29 PM : 36739b39267914ba69ad0610a0299732 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB905414$\netman.dll : 198,144 : 08/10/2004 06:00 AM : dab9e6c7105d2ef49876fe92c524f565 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\netman.dll : 198,144 : 04/13/2008 08:12 PM : 13e67b55b3abd7bf3fe7aae5a0f9a9de [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\netman.dll : 198,144 : 04/13/2008 08:12 PM : 13e67b55b3abd7bf3fe7aae5a0f9a9de [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\netman.dll : 198,144 : 04/13/2008 08:12 PM : 13e67b55b3abd7bf3fe7aae5a0f9a9de [Pos Repl]

 * C:\WINDOWS\System32\ntkrnlpa.exe : 2,028,544 : 07/03/2013 10:08 PM : 05f3db567eae368ae3bbd7e973490646 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2393802\SP3QFE\ntkrnlpa.exe : 2,069,376 : 12/09/2010 07:39 PM : f67cd97282e0abfaf91a9a1359b16f2d [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2633171\SP3QFE\ntkrnlpa.exe : 2,069,376 : 10/25/2011 08:52 AM : db19fff0c805664cb95062c027b11fe9 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2676562\SP3QFE\ntkrnlpa.exe : 2,069,120 : 04/11/2012 08:42 AM : 063a0f8a90d8e2b802e5243fe9aabcf3 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2707511\SP3QFE\ntkrnlpa.exe : 2,069,120 : 05/04/2012 08:41 AM : 8e99a0ce02c1beda6c0935a4dde9ceaa [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2724197\SP3QFE\ntkrnlpa.exe : 2,069,632 : 08/21/2012 09:05 AM : b326d5e256d2f32b23e64f49debce31b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2799494\SP3QFE\ntkrnlpa.exe : 2,069,760 : 01/06/2013 08:45 PM : 1251d608dfce4b6801ad27a59b74985c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2813170\SP3QFE\ntkrnlpa.exe : 2,070,016 : 03/06/2013 08:53 PM : 9ebeda306e5eabdabcff8b695fcd4cd6 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe : 2,056,832 : 03/01/2005 08:36 PM : d8aba3eab509627e707a3b14f00fbb6b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\ntkrnlpa.exe : 2,066,176 : 02/06/2009 06:30 AM : 607352b9cb3d708c67f6039097801b5a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntkrnlpa.exe : 2,066,048 : 08/14/2008 03:39 PM : a25e9b86effb2af33bf51e676b68bfb0 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB971486\SP3QFE\ntkrnlpa.exe : 2,066,176 : 08/04/2009 06:47 PM : 363b2bbee0aedc9e5433616d0ad0236a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB977165\SP3QFE\ntkrnlpa.exe : 2,066,176 : 12/09/2009 00:10 AM : ffdce1eea79c678c40237d4e031e5b51 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB979683\SP3QFE\ntkrnlpa.exe : 2,066,944 : 02/16/2010 08:12 AM : ded8b5a89b085284634502e9d75ac78c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB981852\SP3QFE\ntkrnlpa.exe : 2,066,944 : 04/28/2010 07:14 AM : 756362706de8bc92f11e197c98a73844 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe : 2,017,280 : 02/28/2007 05:15 AM : 2dfb215e291e3d9b1cf9a6739b3bf16c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2393802$\ntkrnlpa.exe : 2,024,448 : 04/27/2010 09:05 AM : 49e936e1398d1a536e84cd5d068f0f09 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2633171$\ntkrnlpa.exe : 2,027,008 : 12/09/2010 09:07 AM : 9ed77e2307f6ec6f174c063c15aa3b8c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2676562$\ntkrnlpa.exe : 2,027,008 : 10/25/2011 08:52 AM : 36cac3c8c4c10f4e21bfeabbfe7acffc [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2707511$\ntkrnlpa.exe : 2,026,496 : 04/11/2012 08:35 AM : 61cce48f7bd00e0e4d5cde206f2ddc1b [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2724197$\ntkrnlpa.exe : 2,026,496 : 05/04/2012 08:32 AM : 87763bb6c95901818050e52c378c9e15 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2799494$\ntkrnlpa.exe : 2,027,520 : 08/21/2012 08:58 AM : 61027ee2d9859a2b41d588d92f256cfb [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2813170$\ntkrnlpa.exe : 2,027,520 : 01/06/2013 08:37 PM : 2c9091c3350e369bbb2464aabe2fd7ca [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2839229$\ntkrnlpa.exe : 2,028,544 : 03/06/2013 08:50 PM : 9ed39805df38061bb031d0f2b20dfb77 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2859537$\ntkrnlpa.exe : 2,028,544 : 05/02/2013 08:38 PM : 70f7df7268c6ab388319a03375dac4e5 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB929338$\ntkrnlpa.exe : 2,015,744 : 06/22/2005 08:05 PM : 65f4b29a0793adb5d924fb3f47f1bca4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe : 2,017,280 : 12/19/2006 12:12 AM : fa64f313f5237c53a909906113acae7d [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956572$\ntkrnlpa.exe : 2,023,936 : 08/14/2008 05:33 AM : 8206b5f94a6a9450e934029420c1693f [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956841$\ntkrnlpa.exe : 2,023,936 : 04/13/2008 02:31 PM : 7f653a89f6e89e3ae0d49830eece35d4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB971486$\ntkrnlpa.exe : 2,023,936 : 02/06/2009 06:32 AM : 65d4220799e6fc2cb079070a6393cc0e [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB977165$\ntkrnlpa.exe : 2,023,936 : 08/04/2009 10:20 AM : 32b1a971183ec22dd91eeda61c499e7c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB979683$\ntkrnlpa.exe : 2,023,936 : 12/08/2009 02:43 PM : 089f1e207b067a4ddeb2eec37bbb1aa7 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB981852$\ntkrnlpa.exe : 2,024,448 : 02/16/2010 09:25 AM : e8b8801de921912ebdeefc76662f7ead [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe : 2,070,144 : 07/03/2013 10:08 PM : 4c47b37cf351ffeb1227ced0ff4751d5 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ntkrnlpa.exe : 2,027,008 : 12/09/2010 09:07 AM : 9ed77e2307f6ec6f174c063c15aa3b8c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe : 2,065,792 : 04/13/2008 02:31 PM : 109f8e3e3c82e337bb71b6bc9b895d61 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ntkrnlpa.exe : 2,070,144 : 07/03/2013 10:08 PM : 4c47b37cf351ffeb1227ced0ff4751d5 [Pos Repl]

 * C:\WINDOWS\System32\ntmssvc.dll : 435,200 : 04/13/2008 08:12 PM : 156f64a3345bd23c600655fb4d10bc08 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ntmssvc.dll : 435,200 : 08/10/2004 06:00 AM : b62f29c00ac55a761b2e45877d85ea0f [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ntmssvc.dll : 435,200 : 04/13/2008 08:12 PM : 156f64a3345bd23c600655fb4d10bc08 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ntmssvc.dll : 435,200 : 04/13/2008 08:12 PM : 156f64a3345bd23c600655fb4d10bc08 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ntmssvc.dll : 435,200 : 04/13/2008 08:12 PM : 156f64a3345bd23c600655fb4d10bc08 [Pos Repl]

 * C:\WINDOWS\System32\ntoskrnl.exe : 2,149,888 : 07/03/2013 11:03 PM : afee19399cf992a098309f7fdf87880a [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2393802\SP3QFE\ntoskrnl.exe : 2,192,768 : 12/09/2010 09:43 AM : a531bbd3de13121c1380ed7dc99082db [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2633171\SP3QFE\ntoskrnl.exe : 2,192,768 : 10/25/2011 09:34 AM : f512c662874d7545e5bd8005e6800a44 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2676562\SP3QFE\ntoskrnl.exe : 2,192,640 : 04/11/2012 09:22 AM : 8d061bb825bc606c2b1c6f7452d1baaa [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2707511\SP3QFE\ntoskrnl.exe : 2,192,640 : 05/04/2012 09:20 AM : 099a0f80a563ebe935f4a9750f96c219 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2724197\SP3QFE\ntoskrnl.exe : 2,193,024 : 08/21/2012 09:48 AM : eca5980e1a78dbf9cb7f49f76791c0d1 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2799494\SP3QFE\ntoskrnl.exe : 2,193,152 : 01/06/2013 09:28 PM : ae2fee63789f5df6b19dd9a39e26d03e [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2813170\SP3QFE\ntoskrnl.exe : 2,193,536 : 03/06/2013 09:31 PM : 9fc16e5ebfe88f3c844ffe2e6cb7f1e8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe : 2,179,456 : 03/01/2005 09:04 PM : 28187802b7c368c0d3aef7d4c382aabb [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\ntoskrnl.exe : 2,189,184 : 02/07/2009 07:35 PM : efe8eace83eaad5849a7a548fb75b584 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956841\SP3QFE\ntoskrnl.exe : 2,189,184 : 08/14/2008 04:11 PM : 31914172342bff330063f343ac6958fe [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB971486\SP3QFE\ntoskrnl.exe : 2,189,312 : 08/04/2009 09:56 AM : fde779ea1a564ebfe16f4e0f82b61bad [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB977165\SP3QFE\ntoskrnl.exe : 2,189,312 : 12/09/2009 00:52 AM : 05be3d9a71972223aff6a3c823ba51b1 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB979683\SP3QFE\ntoskrnl.exe : 2,190,080 : 02/16/2010 08:52 AM : e1f653a542449d54fa2d27463d99b6b6 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB981852\SP3QFE\ntoskrnl.exe : 2,190,080 : 04/27/2010 09:50 AM : a2abbec40cdb57454645d06b7ebd22f5 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe : 2,137,600 : 02/28/2007 05:53 AM : e6679c3023b17d8b78946bc5df53fa20 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2393802$\ntoskrnl.exe : 2,146,304 : 04/27/2010 09:59 AM : 466a3e1239f4a9428797730e81a7a865 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2633171$\ntoskrnl.exe : 2,148,864 : 12/09/2010 09:42 AM : 60e16152d847d7a7b7d3da4c4b8e2120 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2676562$\ntoskrnl.exe : 2,148,864 : 10/25/2011 09:37 AM : 3b663b9b193d7e1de39a466020f1fd91 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2707511$\ntoskrnl.exe : 2,148,352 : 04/11/2012 09:14 AM : a144d60b35e6dd14ccb9649b5e0d1092 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2724197$\ntoskrnl.exe : 2,148,352 : 05/04/2012 09:16 AM : ac4b3c4a6dc31867034c66663b9b8a38 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2799494$\ntoskrnl.exe : 2,148,864 : 08/21/2012 09:33 AM : b9a14d5875ce262774388bd43ba56ff3 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2813170$\ntoskrnl.exe : 2,148,864 : 01/06/2013 09:19 PM : dd5a89274b47499ccff7adca3a3c560e [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2839229$\ntoskrnl.exe : 2,149,888 : 03/06/2013 09:32 PM : 8c39722f8c291f1bbcce80ee23065897 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2859537$\ntoskrnl.exe : 2,149,888 : 05/02/2013 09:30 PM : 0f1ece75329996ebdcf2774f9e46623d [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe : 2,136,064 : 06/22/2005 08:30 PM : 5611f453c6d20ab0552956f39bcddb88 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe : 2,137,600 : 12/19/2006 12:49 AM : 57b9d140e1eb8b0ea06df927b63b0eee [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956572$\ntoskrnl.exe : 2,145,280 : 08/14/2008 06:09 AM : f6f8245b3a2e9ca834dd318e7ae0c6d0 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956841$\ntoskrnl.exe : 2,145,280 : 04/13/2008 03:24 PM : 40f8880122a030a7e9e1fedea833b33d [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB971486$\ntoskrnl.exe : 2,145,280 : 02/06/2009 07:06 AM : 0cba44d0938d57f334c0862424148b70 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB977165$\ntoskrnl.exe : 2,145,280 : 08/04/2009 11:13 AM : 78fcc97cd878d4cf5b5d2158a5a7cf92 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB979683$\ntoskrnl.exe : 2,145,280 : 12/08/2009 03:26 PM : 9696c553f994340cd6aa5c5a724c3a19 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB981852$\ntoskrnl.exe : 2,146,304 : 02/16/2010 10:08 AM : 048db3459fab4ca741dcc84e1f374d65 [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe : 2,193,536 : 07/03/2013 10:59 PM : a4a50a53ffbfec545cda85e98af2106b [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ntoskrnl.exe : 2,148,864 : 12/09/2010 09:42 AM : 60e16152d847d7a7b7d3da4c4b8e2120 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe : 2,188,928 : 04/13/2008 03:27 PM : 0c89243c7c3ee199b96fcc16990e0679 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ntoskrnl.exe : 2,193,536 : 07/03/2013 10:59 PM : a4a50a53ffbfec545cda85e98af2106b [Pos Repl]


 

 


                                                                                                                                                                                                                                                                                           

Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #10 on: August 18, 2015, 05:24:27 AM »
Reply 2 of 5  -  (exceeded 65,000 characters) this portion only includes a portion of rkill.txt


* C:\WINDOWS\System32\oakley.dll : 278,528 : 10/12/2013 11:56 AM : 584c4da856450cb22ebbe7a68cc6250f [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB974392\SP3QFE\oakley.dll : 270,336 : 10/13/2009 06:38 AM : 7eadba6d371c60cca9e4db57c28c8045 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\oakley.dll : 266,752 : 08/10/2004 06:00 AM : a76128be63eea6a3af521a0576d3ebf7 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2862152$\oakley.dll : 270,336 : 10/13/2009 06:30 AM : c5ff8682eada5b3b27a865f1c3ef9270 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB974392$\oakley.dll : 270,336 : 04/13/2008 08:12 PM : 33ceb89b62589e8b12aee9e2d523dade [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\oakley.dll : 270,336 : 04/13/2008 08:12 PM : 33ceb89b62589e8b12aee9e2d523dade [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\oakley.dll : 278,528 : 10/12/2013 11:56 AM : 584c4da856450cb22ebbe7a68cc6250f [Pos Repl]

 * C:\WINDOWS\System32\ole32.dll : 1,289,728 : 08/05/2013 09:30 AM : 59b408e5b8489b0b36a0d783d150edcc [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2624667\SP3QFE\ole32.dll : 1,289,216 : 11/01/2011 12:05 AM : 7d9dde1ab4b00ddb173f5a16e9206517 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\ole32.dll : 1,286,144 : 04/28/2005 03:35 PM : 7440d29f257b7e44329343f944f2142c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\ole32.dll : 1,285,632 : 07/26/2005 00:20 AM : a2f755e237fa2cdd748a80bfbe6657f3 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB979687\SP3QFE\ole32.dll : 1,289,216 : 07/16/2010 08:04 AM : 8d51fb47062f2a1a9efeccef338a4c46 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ole32.dll : 1,285,120 : 07/26/2005 00:39 AM : ab8231d13692ac5088eb9c226b0c0576 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2624667$\ole32.dll : 1,288,192 : 07/16/2010 08:05 AM : 7a6a7900b5e322763430ba6fd9a31224 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2876217$\ole32.dll : 1,288,704 : 11/01/2011 12:07 AM : 6bad1bed9872e62049e487fb91ae2f3a [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB894391$\ole32.dll : 1,281,536 : 08/10/2004 06:00 AM : 4fe9d9fa62d020e35e0ac6d1aeeb96f0 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB902400$\ole32.dll : 1,285,120 : 04/28/2005 03:31 PM : 5950e4f28fda9d147576bf6798937397 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB979687$\ole32.dll : 1,287,168 : 04/13/2008 08:12 PM : ecce74bc6168375016450a86a164d976 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ole32.dll : 1,288,192 : 07/16/2010 08:05 AM : 7a6a7900b5e322763430ba6fd9a31224 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ole32.dll : 1,287,168 : 04/13/2008 08:12 PM : ecce74bc6168375016450a86a164d976 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ole32.dll : 1,289,728 : 08/05/2013 09:30 AM : 59b408e5b8489b0b36a0d783d150edcc [Pos Repl]

 * C:\WINDOWS\System32\olepro32.dll : 84,992 : 04/13/2008 08:12 PM : 5652f6ce1d9e9d8068b9d29bc21b5409 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\olepro32.dll : 83,456 : 08/10/2004 06:00 AM : b48d3193dd1474dcbcc32bf4779ac698 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\olepro32.dll : 84,992 : 04/13/2008 08:12 PM : 5652f6ce1d9e9d8068b9d29bc21b5409 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\olepro32.dll : 84,992 : 04/13/2008 08:12 PM : 5652f6ce1d9e9d8068b9d29bc21b5409 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\olepro32.dll : 84,992 : 04/13/2008 08:12 PM : 5652f6ce1d9e9d8068b9d29bc21b5409 [Pos Repl]

 * C:\WINDOWS\System32\perfctrs.dll : 39,936 : 04/13/2008 08:12 PM : dbe2b62353660ecca0d75ea307a717e9 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\perfctrs.dll : 39,936 : 08/10/2004 06:00 AM : 96492c721c6ea517e2bfd5381fef55e3 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\perfctrs.dll : 39,936 : 04/13/2008 08:12 PM : dbe2b62353660ecca0d75ea307a717e9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\perfctrs.dll : 39,936 : 04/13/2008 08:12 PM : dbe2b62353660ecca0d75ea307a717e9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\perfctrs.dll : 39,936 : 04/13/2008 08:12 PM : dbe2b62353660ecca0d75ea307a717e9 [Pos Repl]

 * C:\WINDOWS\System32\powrprof.dll : 17,408 : 04/13/2008 08:12 PM : 50a166237a0fa771261275a405646cc0 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\powrprof.dll : 17,408 : 08/10/2004 06:00 AM : 1b5f6923abb450692e9fe0672c897aed [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\powrprof.dll : 17,408 : 04/13/2008 08:12 PM : 50a166237a0fa771261275a405646cc0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\powrprof.dll : 17,408 : 04/13/2008 08:12 PM : 50a166237a0fa771261275a405646cc0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\powrprof.dll : 17,408 : 04/13/2008 08:12 PM : 50a166237a0fa771261275a405646cc0 [Pos Repl]

 * C:\WINDOWS\System32\psbase.dll : 96,768 : 04/13/2008 08:12 PM : 22d89d84e8e081cda529dbf8c0255a38 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\psbase.dll : 96,768 : 08/10/2004 06:00 AM : 4d3ccdf22d2b4bae229ba73b81d13e26 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\psbase.dll : 96,768 : 04/13/2008 08:12 PM : 22d89d84e8e081cda529dbf8c0255a38 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\psbase.dll : 96,768 : 04/13/2008 08:12 PM : 22d89d84e8e081cda529dbf8c0255a38 [Pos Repl]

 * C:\WINDOWS\System32\pstorsvc.dll : 34,304 : 04/13/2008 08:12 PM : 853d0d0c6f02d7bfdf1cf99dd7553732 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\pstorsvc.dll : 34,304 : 08/10/2004 06:00 AM : 306b30a036db25fcb76b507fede07d58 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\pstorsvc.dll : 34,304 : 04/13/2008 08:12 PM : 853d0d0c6f02d7bfdf1cf99dd7553732 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\pstorsvc.dll : 34,304 : 04/13/2008 08:12 PM : 853d0d0c6f02d7bfdf1cf99dd7553732 [Pos Repl]

 * C:\WINDOWS\System32\qmgr.dll : 409,088 : 04/13/2008 08:12 PM : 574738f61fca2935f5265dc4e5691314 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\qmgr.dll : 382,464 : 08/10/2004 06:00 AM : 2c69ec7e5a311334d10dd95f338fccea [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\qmgr.dll : 409,088 : 04/13/2008 08:12 PM : 574738f61fca2935f5265dc4e5691314 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\qmgr.dll : 409,088 : 04/13/2008 08:12 PM : 574738f61fca2935f5265dc4e5691314 [Pos Repl]
 +-> C:\WINDOWS\system32\bits\qmgr.dll : 409,088 : 04/13/2008 08:12 PM : 574738f61fca2935f5265dc4e5691314 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\qmgr.dll : 409,088 : 04/13/2008 08:12 PM : 574738f61fca2935f5265dc4e5691314 [Pos Repl]

 * C:\WINDOWS\System32\rasadhlp.dll : 7,680 : 04/13/2008 08:12 PM : 6f9bef24c578d5d6740e080bedd6a448 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB920683\SP2QFE\rasadhlp.dll : 7,680 : 06/26/2006 01:45 PM : b5d08c96b2dadaf5171fb69e341b272b [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rasadhlp.dll : 8,192 : 06/26/2006 01:37 PM : 5f098bd2ae6b03044b085decffdf91ec [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB920683$\rasadhlp.dll : 8,192 : 08/10/2004 06:00 AM : 4caec028c1e21c75e17877d4522d3db4 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\rasadhlp.dll : 7,680 : 04/13/2008 08:12 PM : 6f9bef24c578d5d6740e080bedd6a448 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rasadhlp.dll : 7,680 : 04/13/2008 08:12 PM : 6f9bef24c578d5d6740e080bedd6a448 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rasadhlp.dll : 7,680 : 04/13/2008 08:12 PM : 6f9bef24c578d5d6740e080bedd6a448 [Pos Repl]

 * C:\WINDOWS\System32\regsvc.dll : 59,904 : 04/13/2008 08:12 PM : 5b19b557b0c188210a56a6b699d90b8f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\regsvc.dll : 59,904 : 08/10/2004 06:00 AM : 3151427db7d87107d1c5be58fac53960 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\regsvc.dll : 59,904 : 04/13/2008 08:12 PM : 5b19b557b0c188210a56a6b699d90b8f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\regsvc.dll : 59,904 : 04/13/2008 08:12 PM : 5b19b557b0c188210a56a6b699d90b8f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\regsvc.dll : 59,904 : 04/13/2008 08:12 PM : 5b19b557b0c188210a56a6b699d90b8f [Pos Repl]

 * C:\WINDOWS\System32\rpcss.dll : 401,408 : 02/09/2009 08:10 AM : 6b27a5c03dfb94b4245739065431322c [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB894391\SP2QFE\rpcss.dll : 396,288 : 04/28/2005 03:35 PM : da383fb39a6f1c445f3afc94b3eb1248 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB902400\SP2QFE\rpcss.dll : 398,336 : 07/26/2005 00:20 AM : c369df215d352b6f3a0b8c3469aa34f8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\rpcss.dll : 401,408 : 02/09/2009 06:56 AM : 9222562d44021b988b9f9f62207fb6f2 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rpcss.dll : 397,824 : 07/26/2005 00:39 AM : ce94a2bd25e3e9f4d46a7373ff455c6d [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB894391$\rpcss.dll : 395,776 : 08/10/2004 06:00 AM : 5c83a4408604f737717ab96371201680 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB902400$\rpcss.dll : 395,776 : 04/28/2005 03:31 PM : c8061f289e000703e7672916b7fe1571 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956572$\rpcss.dll : 399,360 : 04/13/2008 08:12 PM : 2589fe6015a316c0f5d5112b4da7b509 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\rpcss.dll : 401,408 : 02/09/2009 08:10 AM : 6b27a5c03dfb94b4245739065431322c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rpcss.dll : 399,360 : 04/13/2008 08:12 PM : 2589fe6015a316c0f5d5112b4da7b509 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rpcss.dll : 401,408 : 02/09/2009 08:10 AM : 6b27a5c03dfb94b4245739065431322c [Pos Repl]

 * C:\WINDOWS\System32\scecli.dll : 181,248 : 04/13/2008 08:12 PM : a86bb5e61bf3e39b62ab4c7e7085a084 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\scecli.dll : 180,224 : 08/10/2004 06:00 AM : 0f78e27f563f2aaf74b91a49e2abf19a [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\scecli.dll : 181,248 : 04/13/2008 08:12 PM : a86bb5e61bf3e39b62ab4c7e7085a084 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\scecli.dll : 181,248 : 04/13/2008 08:12 PM : a86bb5e61bf3e39b62ab4c7e7085a084 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\scecli.dll : 181,248 : 04/13/2008 08:12 PM : a86bb5e61bf3e39b62ab4c7e7085a084 [Pos Repl]

 * C:\WINDOWS\System32\schannel.dll : 152,576 : 06/04/2012 00:32 AM : 0f64207b49390c8063c36ae7cbf9c2db [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2541763\SP3QFE\schannel.dll : 151,552 : 04/29/2011 01:23 PM : 6fd5eec3703d7770c9029e774acc2294 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2585542\SP3QFE\schannel.dll : 152,064 : 11/16/2011 10:20 AM : d444009f7cd704c89f7f9e62396ed4f1 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2655992\SP3QFE\schannel.dll : 153,088 : 06/04/2012 00:31 AM : 26f1193092b9ac2586deb38dd1cbb25c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB935840\SP2QFE\schannel.dll : 144,896 : 04/25/2007 04:32 PM : d8b13f0b90de29903cbe044190417f98 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB960225\SP3QFE\schannel.dll : 144,896 : 12/05/2008 02:58 AM : 1cdfcf9d0fdc55d76ac3955bd04ac200 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB968389\SP3QFE\schannel.dll : 147,456 : 06/25/2009 04:41 AM : e513ba8bc33fd00f35d69659b478b1df [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB980436\SP3QFE\schannel.dll : 149,504 : 06/30/2010 08:23 AM : e04b6497b6407d2f444e86b30680dc5a [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\schannel.dll : 144,896 : 04/25/2007 10:21 AM : 532ea80e9f5452928f8426653215be29 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2541763$\schannel.dll : 149,504 : 06/30/2010 08:31 AM : 30ace70b3c0242f0d1ac3b4fa708710f [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2585542$\schannel.dll : 151,552 : 04/29/2011 01:25 PM : abeedd547e939ad827b2e29dec754206 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2655992$\schannel.dll : 152,064 : 11/16/2011 10:21 AM : a645a78fcdabad67067324d7e6cd9f79 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB935840$\schannel.dll : 144,896 : 08/10/2004 06:00 AM : 29632e787dcfc0085a555c681eb82693 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB960225$\schannel.dll : 144,384 : 04/13/2008 08:12 PM : c61e8ecffdbf05ff71d079bbd35396b3 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB968389$\schannel.dll : 144,896 : 12/05/2008 02:54 AM : 636c52fc618acb09ec356e9e82d072e2 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB980436$\schannel.dll : 147,456 : 06/25/2009 04:25 AM : bfdece69e293e6db4e25def862418428 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\schannel.dll : 144,384 : 04/13/2008 08:12 PM : c61e8ecffdbf05ff71d079bbd35396b3 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\schannel.dll : 152,576 : 06/04/2012 00:32 AM : 0f64207b49390c8063c36ae7cbf9c2db [Pos Repl]

 * C:\WINDOWS\System32\schedsvc.dll : 192,512 : 04/13/2008 08:12 PM : 0a9a7365a1ca4319aa7c1d6cd8e4eafa [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\schedsvc.dll : 190,976 : 08/10/2004 06:00 AM : 92360854316611f6cc471612213c3d92 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\schedsvc.dll : 192,512 : 04/13/2008 08:12 PM : 0a9a7365a1ca4319aa7c1d6cd8e4eafa [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\schedsvc.dll : 192,512 : 04/13/2008 08:12 PM : 0a9a7365a1ca4319aa7c1d6cd8e4eafa [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\schedsvc.dll : 192,512 : 04/13/2008 08:12 PM : 0a9a7365a1ca4319aa7c1d6cd8e4eafa [Pos Repl]

 * C:\WINDOWS\System32\services.exe : 110,592 : 02/06/2009 07:11 AM : 65df52f5b8b6e9bbd183505225c37315 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe : 110,592 : 02/06/2009 07:06 AM : 020ceaaedc8eb655b6506b8c70d53bb6 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\services.exe : 108,032 : 08/10/2004 06:00 AM : c6ce6eec82f187615d1002bb3bb50ed4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956572$\services.exe : 108,544 : 04/13/2008 08:12 PM : 0e776ed5f7cc9f94299e70461b7b8185 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\services.exe : 110,592 : 02/06/2009 07:11 AM : 65df52f5b8b6e9bbd183505225c37315 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\services.exe : 108,544 : 04/13/2008 08:12 PM : 0e776ed5f7cc9f94299e70461b7b8185 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\services.exe : 110,592 : 02/06/2009 07:11 AM : 65df52f5b8b6e9bbd183505225c37315 [Pos Repl]

 * C:\WINDOWS\System32\setupapi.dll : 985,088 : 04/14/2008 05:42 AM : 24192246760e0e64435522e246b1d6c2 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\setupapi.dll : 983,552 : 08/10/2004 06:00 AM : 7808313cbc634ee08346d5ddfef1cc5f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\setupapi.dll : 985,088 : 04/14/2008 05:42 AM : 24192246760e0e64435522e246b1d6c2 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\setupapi.dll : 985,088 : 04/14/2008 05:42 AM : 24192246760e0e64435522e246b1d6c2 [Pos Repl]

 * C:\WINDOWS\System32\sfc.dll : 5,120 : 04/13/2008 08:12 PM : 96e1c926f22ee1bfbae82901a35f6bf3 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sfc.dll : 5,120 : 08/10/2004 06:00 AM : e8a12a12ea9088b4327d49edca3add3e [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\sfc.dll : 5,120 : 04/13/2008 08:12 PM : 96e1c926f22ee1bfbae82901a35f6bf3 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sfc.dll : 5,120 : 04/13/2008 08:12 PM : 96e1c926f22ee1bfbae82901a35f6bf3 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sfc.dll : 5,120 : 04/13/2008 08:12 PM : 96e1c926f22ee1bfbae82901a35f6bf3 [Pos Repl]

 * C:\WINDOWS\System32\sfcfiles.dll : 1,614,848 : 04/13/2008 08:12 PM : 9dd07af82244867ca36681ea2d29ce79 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sfcfiles.dll : 1,580,544 : 08/10/2004 06:00 AM : 30a609e00bd1d4ffc49d6b5a432be7f2 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\sfcfiles.dll : 1,614,848 : 04/13/2008 08:12 PM : 9dd07af82244867ca36681ea2d29ce79 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sfcfiles.dll : 1,614,848 : 04/13/2008 08:12 PM : 9dd07af82244867ca36681ea2d29ce79 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sfcfiles.dll : 1,614,848 : 04/13/2008 08:12 PM : 9dd07af82244867ca36681ea2d29ce79 [Pos Repl]

 * C:\WINDOWS\System32\shsvcs.dll : 135,168 : 07/27/2009 07:17 PM : 99bc0b50f511924348be19c7c7313bbf [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB928255\SP2QFE\shsvcs.dll : 135,168 : 12/19/2006 05:50 PM : 53d9184a21c5cbf600d918e51ef3a7e5 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB971029\SP3QFE\shsvcs.dll : 135,168 : 07/27/2009 06:13 PM : 888cd7b39c37e13a2419becfaaf0a28c [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\shsvcs.dll : 134,656 : 12/19/2006 05:52 PM : 6815def9b810aefac107eeaf72da6f82 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB928255$\shsvcs.dll : 134,656 : 08/10/2004 06:00 AM : e7518dc542d3ebdcb80edd98462c7821 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB971029$\shsvcs.dll : 135,168 : 04/13/2008 08:12 PM : 1926899bf9ffe2602b63074971700412 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\shsvcs.dll : 135,168 : 07/27/2009 07:17 PM : 99bc0b50f511924348be19c7c7313bbf [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\shsvcs.dll : 135,168 : 04/13/2008 08:12 PM : 1926899bf9ffe2602b63074971700412 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\shsvcs.dll : 135,168 : 07/27/2009 07:17 PM : 99bc0b50f511924348be19c7c7313bbf [Pos Repl]

 * C:\WINDOWS\System32\smss.exe : 50,688 : 04/13/2008 08:12 PM : 5f816c1f539266d2d4c78694239da0b5 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\smss.exe : 50,688 : 08/10/2004 06:00 AM : bd7fb0957c716f1a60333aee04de2178 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\smss.exe : 50,688 : 04/13/2008 08:12 PM : 5f816c1f539266d2d4c78694239da0b5 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\smss.exe : 50,688 : 04/13/2008 08:12 PM : 5f816c1f539266d2d4c78694239da0b5 [Pos Repl]

 * C:\WINDOWS\System32\spoolsv.exe : 58,880 : 08/17/2010 09:17 AM : 60784f891563fb1b767f70117fc2428f [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe : 58,880 : 08/17/2010 09:19 AM : 258dd5d4283fd9f9a7166be9ae45ce73 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB896423\SP2QFE\spoolsv.exe : 57,856 : 06/10/2005 08:17 PM : ad3d9d191aea7b5445fe1d82ffbb4788 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\spoolsv.exe : 57,856 : 06/10/2005 07:53 PM : da81ec57acd4cdc3d4c51cf3d409af9f [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2347290$\spoolsv.exe : 57,856 : 04/13/2008 08:12 PM : d8e14a61acc1d4a6cd0d38aebac7fa3b [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\spoolsv.exe : 58,880 : 08/17/2010 09:17 AM : 60784f891563fb1b767f70117fc2428f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\spoolsv.exe : 57,856 : 04/13/2008 08:12 PM : d8e14a61acc1d4a6cd0d38aebac7fa3b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\spoolsv.exe : 58,880 : 08/17/2010 09:17 AM : 60784f891563fb1b767f70117fc2428f [Pos Repl]

 * C:\WINDOWS\System32\srsvc.dll : 171,008 : 04/13/2008 08:12 PM : 3805df0ac4296a34ba4bf93b346cc378 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\srsvc.dll : 170,496 : 08/10/2004 06:00 AM : 92bdf74f12d6cbec43c94d4b7f804838 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\srsvc.dll : 171,008 : 04/13/2008 08:12 PM : 3805df0ac4296a34ba4bf93b346cc378 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\srsvc.dll : 171,008 : 04/13/2008 08:12 PM : 3805df0ac4296a34ba4bf93b346cc378 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\srsvc.dll : 171,008 : 04/13/2008 08:12 PM : 3805df0ac4296a34ba4bf93b346cc378 [Pos Repl]

 * C:\WINDOWS\System32\ssdpsrv.dll : 71,680 : 04/13/2008 08:12 PM : 0a5679b3714edab99e357057ee88fca6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ssdpsrv.dll : 71,680 : 08/10/2004 06:00 AM : 4b8d61792f7175bed48859cc18ce4e38 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ssdpsrv.dll : 71,680 : 04/13/2008 08:12 PM : 0a5679b3714edab99e357057ee88fca6 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ssdpsrv.dll : 71,680 : 04/13/2008 08:12 PM : 0a5679b3714edab99e357057ee88fca6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ssdpsrv.dll : 71,680 : 04/13/2008 08:12 PM : 0a5679b3714edab99e357057ee88fca6 [Pos Repl]

 * C:\WINDOWS\System32\svchost.exe : 14,336 : 04/13/2008 08:12 PM : 27c6d03bcdb8cfeb96b716f3d8be3e18 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\svchost.exe : 14,336 : 08/10/2004 06:00 AM : 8f078ae4ed187aaabc0a305146de6716 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\svchost.exe : 14,336 : 04/13/2008 08:12 PM : 27c6d03bcdb8cfeb96b716f3d8be3e18 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\svchost.exe : 14,336 : 04/13/2008 08:12 PM : 27c6d03bcdb8cfeb96b716f3d8be3e18 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\svchost.exe : 14,336 : 04/13/2008 08:12 PM : 27c6d03bcdb8cfeb96b716f3d8be3e18 [Pos Repl]

 * C:\WINDOWS\System32\tapisrv.dll : 249,856 : 04/13/2008 08:12 PM : 3cb78c17bb664637787c9a1c98f79c38 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB893756\SP2QFE\tapisrv.dll : 249,344 : 07/08/2005 12:28 AM : 1418a3a6e76e5a2e3f5e43866e793a8b [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tapisrv.dll : 249,344 : 07/08/2005 12:27 AM : fb78839b36025aa286a51289ed28b73e [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB893756$\tapisrv.dll : 246,272 : 08/10/2004 06:00 AM : eb4a4187d74a8efdcbea3ea2cb1bdfbd [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\tapisrv.dll : 249,856 : 04/13/2008 08:12 PM : 3cb78c17bb664637787c9a1c98f79c38 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tapisrv.dll : 249,856 : 04/13/2008 08:12 PM : 3cb78c17bb664637787c9a1c98f79c38 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tapisrv.dll : 249,856 : 04/13/2008 08:12 PM : 3cb78c17bb664637787c9a1c98f79c38 [Pos Repl]

 * C:\WINDOWS\System32\termsrv.dll : 295,424 : 04/13/2008 08:12 PM : ff3477c03be7201c294c35f684b3479f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\termsrv.dll : 295,424 : 03/09/2005 08:49 PM : c29a5286e64d97385178452d5f307b98 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB895961$\termsrv.dll : 295,424 : 08/10/2004 06:00 AM : b60c877d16d9c880b952fda04adf16e6 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\termsrv.dll : 295,424 : 04/13/2008 08:12 PM : ff3477c03be7201c294c35f684b3479f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\termsrv.dll : 295,424 : 04/13/2008 08:12 PM : ff3477c03be7201c294c35f684b3479f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\termsrv.dll : 295,424 : 04/13/2008 08:12 PM : ff3477c03be7201c294c35f684b3479f [Pos Repl]

 * C:\WINDOWS\System32\upnphost.dll : 185,856 : 04/13/2008 08:12 PM : 1ebafeb9a3fbdc41b8d9c7f0f687ad91 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB931261\SP2QFE\upnphost.dll : 185,344 : 02/05/2007 04:19 PM : 36aca6cdc19c95ff468a1426eb7f32f0 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\upnphost.dll : 185,344 : 02/05/2007 04:17 PM : aca5d98663d879c6baafcea7e2f1b710 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB931261$\upnphost.dll : 185,344 : 08/10/2004 06:00 AM : 0546477bde979e33294fe97f6b3de84a [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\upnphost.dll : 185,856 : 04/13/2008 08:12 PM : 1ebafeb9a3fbdc41b8d9c7f0f687ad91 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\upnphost.dll : 185,856 : 04/13/2008 08:12 PM : 1ebafeb9a3fbdc41b8d9c7f0f687ad91 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\upnphost.dll : 185,856 : 04/13/2008 08:12 PM : 1ebafeb9a3fbdc41b8d9c7f0f687ad91 [Pos Repl]

 * C:\WINDOWS\System32\user32.dll : 578,560 : 04/13/2008 08:12 PM : b26b135ff1b9f60c9388b4a7d16f600b [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\user32.dll : 577,024 : 03/02/2005 02:19 PM : 1800f293bccc8ede8a70e12b88d80036 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB925902\SP2QFE\user32.dll : 578,048 : 03/08/2007 11:48 AM : 7aa4f6c00405dfc4b70ed4214e7d687b [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\user32.dll : 577,536 : 03/08/2007 11:36 AM : b409909f6e2e8a7067076ed748abf1e7 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB890859$\user32.dll : 577,024 : 08/10/2004 06:00 AM : c72661f8552ace7c5c85e16a3cf505c4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB925902$\user32.dll : 577,024 : 03/02/2005 02:09 PM : de2db164bbb35db061af0997e4499054 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\user32.dll : 578,560 : 04/13/2008 08:12 PM : b26b135ff1b9f60c9388b4a7d16f600b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\user32.dll : 578,560 : 04/13/2008 08:12 PM : b26b135ff1b9f60c9388b4a7d16f600b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\user32.dll : 578,560 : 04/13/2008 08:12 PM : b26b135ff1b9f60c9388b4a7d16f600b [Pos Repl]

 * C:\WINDOWS\System32\userinit.exe : 26,112 : 04/13/2008 08:12 PM : a93aee1928a9d7ce3e16d24ec7380f89 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\userinit.exe : 24,576 : 08/10/2004 06:00 AM : 39b1ffb03c2296323832acbae50d2aff [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\userinit.exe : 26,112 : 04/13/2008 08:12 PM : a93aee1928a9d7ce3e16d24ec7380f89 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\userinit.exe : 26,112 : 04/13/2008 08:12 PM : a93aee1928a9d7ce3e16d24ec7380f89 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\userinit.exe : 26,112 : 04/13/2008 08:12 PM : a93aee1928a9d7ce3e16d24ec7380f89 [Pos Repl]

 * C:\WINDOWS\System32\usp10.dll : 406,016 : 07/10/2013 06:37 AM : 1d845821f5adb076831de4c2818f858b [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB981322\SP3QFE\usp10.dll : 406,016 : 04/16/2010 11:29 AM : f8894bcc961d461674002b4bae7aecc1 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usp10.dll : 406,528 : 08/10/2004 06:00 AM : 2eb58f9dcd6ab320b46744a4ea48b2d2 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2850869$\usp10.dll : 406,016 : 04/16/2010 11:36 AM : 9e03dc5ab51cfd0190541ce2038d819d [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB981322$\usp10.dll : 406,016 : 04/13/2008 08:12 PM : 7d7d8501f3cb45d0408cdefa08cdaeff [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\usp10.dll : 406,016 : 04/16/2010 11:36 AM : 9e03dc5ab51cfd0190541ce2038d819d [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usp10.dll : 406,016 : 04/13/2008 08:12 PM : 7d7d8501f3cb45d0408cdefa08cdaeff [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usp10.dll : 406,016 : 07/10/2013 06:37 AM : 1d845821f5adb076831de4c2818f858b [Pos Repl]

 * C:\WINDOWS\System32\UxTheme.dll : 218,624 : 04/13/2008 08:12 PM : 7a2cc3719b255e6b5d74396183b7715b [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\uxtheme.dll : 218,624 : 08/10/2004 06:00 AM : 2cde496666a975a2ce8f969f3042c8db [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\uxtheme.dll : 218,624 : 04/13/2008 08:12 PM : 7a2cc3719b255e6b5d74396183b7715b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\uxtheme.dll : 218,624 : 04/13/2008 08:12 PM : 7a2cc3719b255e6b5d74396183b7715b [Pos Repl]

 * C:\WINDOWS\System32\version.dll : 18,944 : 04/13/2008 08:12 PM : c7ce131408739b0b3a318be2d0032719 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\version.dll : 18,944 : 08/10/2004 06:00 AM : d38408967be738d0c1b47005bce8ceeb [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\version.dll : 18,944 : 04/13/2008 08:12 PM : c7ce131408739b0b3a318be2d0032719 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\version.dll : 18,944 : 04/13/2008 08:12 PM : c7ce131408739b0b3a318be2d0032719 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\version.dll : 18,944 : 04/13/2008 08:12 PM : c7ce131408739b0b3a318be2d0032719 [Pos Repl]

 * C:\WINDOWS\System32\w32time.dll : 175,104 : 04/13/2008 08:12 PM : 54af4b1d5459500ef0937f6d33b1914f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\w32time.dll : 174,592 : 08/10/2004 06:00 AM : 2b281958f5d0cf99ed626e3ef39d5c8d [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\w32time.dll : 175,104 : 04/13/2008 08:12 PM : 54af4b1d5459500ef0937f6d33b1914f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\w32time.dll : 175,104 : 04/13/2008 08:12 PM : 54af4b1d5459500ef0937f6d33b1914f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\w32time.dll : 175,104 : 04/13/2008 08:12 PM : 54af4b1d5459500ef0937f6d33b1914f [Pos Repl]

 * C:\WINDOWS\System32\wbem\wmiprvse.exe : 227,840 : 02/06/2009 06:10 AM : 798a9e6828997eef4517ada8a2259831 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\wmiprvse.exe : 227,840 : 02/06/2009 06:15 AM : f520ab392d58c0a1070268032d809382 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\wmiprvse.exe : 218,112 : 08/10/2004 06:00 AM : 075ea6c849ab0fe416a3d6dd65c3cf41 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956572$\wmiprvse.exe : 218,112 : 04/13/2008 08:12 PM : 0ffae66e6d5b1c87cbd22d1f3b6079fd [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\wmiprvse.exe : 218,112 : 04/13/2008 08:12 PM : 0ffae66e6d5b1c87cbd22d1f3b6079fd [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\wmiprvse.exe : 227,840 : 02/06/2009 06:10 AM : 798a9e6828997eef4517ada8a2259831 [Pos Repl]

 * C:\WINDOWS\System32\wdigest.dll : 54,272 : 06/25/2009 04:25 AM : 3aaf9b35939ff9e58ccd18d41655c2fc [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB904942\SP2QFE\wdigest.dll : 49,152 : 03/24/2006 00:47 AM : 2f66af12e42a328a023f5492e495b84c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB968389\SP3QFE\wdigest.dll : 54,272 : 06/25/2009 04:41 AM : d9dcec3fa1b27689fc56e34c38d3f148 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\wdigest.dll : 49,152 : 03/24/2006 00:37 AM : c43d8f6ff8ac074ccd9b34b781e23e86 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB904942$\wdigest.dll : 49,152 : 08/10/2004 06:00 AM : a8b82c5d30b7ab937e164ab349478fba [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB968389$\wdigest.dll : 49,152 : 04/13/2008 08:12 PM : cefcc6a64983eb8119f3a07a0c1ede30 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\wdigest.dll : 49,152 : 04/13/2008 08:12 PM : cefcc6a64983eb8119f3a07a0c1ede30 [Pos Repl]
 +-> C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\sp2gdr\wdigest.dll : 49,152 : 03/24/2006 00:37 AM : c43d8f6ff8ac074ccd9b34b781e23e86 [Pos Repl]
 +-> C:\WINDOWS\SoftwareDistribution\Download\355f788b6de8a3ec79e9aa172e6317f1\sp2qfe\wdigest.dll : 49,152 : 03/24/2006 00:47 AM : 2f66af12e42a328a023f5492e495b84c [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\wdigest.dll : 54,272 : 06/25/2009 04:25 AM : 3aaf9b35939ff9e58ccd18d41655c2fc [Pos Repl]

 * C:\WINDOWS\System32\wiaservc.dll : 333,824 : 04/13/2008 08:12 PM : 8bad69cbac032d4bbacfce0306174c30 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB927802\SP2QFE\wiaservc.dll : 333,824 : 12/19/2006 02:47 PM : d9f097aa3b97034d3358a01b43e635b2 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\wiaservc.dll : 333,824 : 12/19/2006 02:16 PM : b6763f8534ac547cf1af98afdff2edc8 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB927802$\wiaservc.dll : 333,312 : 08/10/2004 06:00 AM : d9f6c4f6b1e188adafc42b561d9bc2e6 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\wiaservc.dll : 333,824 : 04/13/2008 08:12 PM : 8bad69cbac032d4bbacfce0306174c30 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\wiaservc.dll : 333,824 : 04/13/2008 08:12 PM : 8bad69cbac032d4bbacfce0306174c30 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\wiaservc.dll : 333,824 : 04/13/2008 08:12 PM : 8bad69cbac032d4bbacfce0306174c30 [Pos Repl]

 * C:\WINDOWS\System32\wininet.dll : 920,064 : 03/06/2014 01:59 PM : 8af91e4b4c1f5338ebe1548117304296 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2183461-IE8\SP3QFE\wininet.dll : 919,040 : 06/24/2010 08:24 AM : 60237e50d575fba9bec9bc043f157149 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2360131-IE8\SP3QFE\wininet.dll : 919,552 : 09/10/2010 01:57 AM : 0555e190dcd06b8998e6ddca42daeb82 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2416400-IE8\SP3QFE\wininet.dll : 919,552 : 11/05/2010 08:27 PM : 9357c4249f4810fb0e49c13387a8a77c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2482017-IE8\SP3QFE\wininet.dll : 919,552 : 12/20/2010 07:58 PM : 5504b4ecce892eb82cd2c5fa71940ac1 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2497640-IE8\SP3QFE\wininet.dll : 919,552 : 02/22/2011 07:27 PM : a9fa95f0d7f511959ac721e4843e5967 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2530548-IE8\SP3QFE\wininet.dll : 919,552 : 04/25/2011 12:09 AM : 7f4f1697001b9e9a7924d219dc215903 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2559049-IE8\SP3QFE\wininet.dll : 919,552 : 06/23/2011 02:33 PM : 509cf67ae762a38e23a5455a0053853c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2586448-IE8\SP3QFE\wininet.dll : 919,552 : 08/22/2011 07:47 PM : 19630aebbfaeb06984cab91848270aaf [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2618444-IE8\SP3QFE\wininet.dll : 919,552 : 11/04/2011 03:19 PM : 4e4716caf514717814d07113ad0425b6 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2647516-IE8\SP3QFE\wininet.dll : 919,552 : 12/17/2011 03:45 PM : 84a48e9818e8440ddbfd8eec37c8a937 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2675157-IE8\SP3QFE\wininet.dll : 919,552 : 03/01/2012 06:58 AM : 4ec67fab39f37626ad6d9895fc094abf [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2699988-IE8\SP3QFE\wininet.dll : 920,064 : 05/16/2012 11:06 AM : 553ad35768cd27959391dd5aa82cef6f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2722913-IE8\SP3QFE\wininet.dll : 920,064 : 07/02/2012 01:48 PM : efb2241de3aa6480521a16d0cb67b0ec [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2744842-IE8\SP3QFE\wininet.dll : 920,064 : 08/28/2012 11:13 AM : dcea3b3193b7181cf818ecc4eab30a66 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2761465-IE8\SP3QFE\wininet.dll : 920,064 : 11/01/2012 08:15 AM : acc92628cfff9bb6f8886329888014a8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2792100-IE8\SP3QFE\wininet.dll : 920,064 : 12/26/2012 04:15 PM : b8bef9519a1b124deaf94081f6c5a767 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2809289-IE8\SP3QFE\wininet.dll : 920,064 : 02/05/2013 04:04 PM : be30bef4c13065d09772f9895fcb9d22 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2817183-IE8\SP3QFE\wininet.dll : 920,064 : 03/01/2013 10:05 PM : 43eadba9f3cd2a5f01b189bd95fcde95 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB905915\SP2QFE\wininet.dll : 661,504 : 10/20/2005 11:38 PM : af785c4947676a7fc1673fdc5c8d0b5b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB931768-IE7\SP2QFE\wininet.dll : 823,296 : 03/07/2007 01:40 PM : b8f4db39ca7353752f245379d285c80e [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB933566-IE7\SP2QFE\wininet.dll : 823,808 : 04/25/2007 05:08 AM : 431defbb4a3d7b0dc062c1b064623a2f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB937143-IE7\SP2QFE\wininet.dll : 824,320 : 06/27/2007 10:40 AM : d6ed5e042c5207553e7f5e842918137f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB939653-IE7\SP2QFE\wininet.dll : 825,344 : 08/20/2007 06:02 AM : 357d54bf94fe9d6d8505a96b5c2a3bca [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll : 825,344 : 10/10/2007 07:47 PM : 0e5d918f87efa7d2424d66b499c7eb04 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll : 825,344 : 12/06/2007 10:01 PM : b5b411bb229ae6ead7652a32ed47bfb9 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll : 827,392 : 03/01/2008 09:03 AM : 6316c2f0c61271c8abdff7429174879e [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll : 827,392 : 04/22/2008 11:35 PM : 41546b396a526918da7995a02ea04e51 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\wininet.dll : 827,904 : 06/23/2008 12:01 AM : c66402a06b83b036c195242c0c8cf83c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll : 827,904 : 08/26/2008 05:08 AM : 77c192fe56a70d7fa0247ba0a6201c32 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll : 827,904 : 10/16/2008 04:24 PM : 0d5b75171ff51775b630a431b6c667e8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll : 827,904 : 12/20/2008 07:56 PM : 044e0a4e9fe97c0fb9afe9c89e2a82e6 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll : 828,416 : 03/02/2009 08:17 PM : c8667854873938ca13c986f16b0cd183 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\wininet.dll : 828,928 : 04/29/2009 00:49 AM : 62cca075f44015147b8971daffbcff76 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\wininet.dll : 828,928 : 06/29/2009 12:23 AM : 4c6b4138165a4c53fe8a5b1d809526c3 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\wininet.dll : 840,704 : 08/29/2009 03:31 AM : a5885af9bfbd942b828e6020ad326517 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\wininet.dll : 841,216 : 10/29/2009 03:45 AM : ca5cb4f174592090fbecfead9b51bb90 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\wininet.dll : 841,216 : 01/05/2010 05:57 AM : e7b99465de2edcf29784b7600bf6fae8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\wininet.dll : 841,216 : 03/11/2010 07:49 AM : 7f6a9d2f3caa7780aafd478bf3411462 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll : 919,040 : 02/25/2010 02:19 AM : 4458d59f2b0369f4d3b137541d284041 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll : 919,040 : 05/06/2010 06:36 AM : c1490f68b44af8b781f52f12f564625d [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB912812$\wininet.dll : 658,432 : 10/20/2005 11:39 PM : e7b27b6b6e06ce34ea019fd8b858c613 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB916281$\wininet.dll : 663,552 : 03/03/2006 11:58 PM : c0845ecbf4f9164e618ee381b79c9032 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB918899$\wininet.dll : 663,552 : 05/10/2006 01:25 AM : d94cffdb53e7ac867438e2dfd50e7cbc [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB922760$\wininet.dll : 664,576 : 06/23/2006 07:25 AM : 64ce26db72810b30f7855ea51e1df836 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\wininet.dll : 916,480 : 04/25/2011 12:11 AM : cc951c2212a200475a587a440e0aa804 [Pos Repl]
 +-> C:\WINDOWS\ie7\wininet.dll : 664,576 : 09/14/2006 04:31 AM : d207370287cf769aebebf03837784963 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB928090-IE7\wininet.dll : 818,688 : 11/07/2006 10:03 PM : 92995334f993e6e49c25c6d02ec04401 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB931768-IE7\wininet.dll : 822,784 : 01/12/2007 10:27 AM : be43d00d802c92f01c8cc952c6f483f8 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB933566-IE7\wininet.dll : 822,784 : 03/07/2007 01:45 PM : 5b35dae6e4886f64d1da58c4e3e01eb9 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB937143-IE7\wininet.dll : 822,784 : 04/25/2007 04:41 AM : 0586a7f0b2fdb94d624f399d4728e7c8 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB939653-IE7\wininet.dll : 823,808 : 06/27/2007 10:34 AM : 8068cbb58fe60cc95aeb2cff70178208 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll : 824,832 : 08/20/2007 06:04 AM : 774435e499d8e9643ec961a6103c361f [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll : 824,832 : 10/10/2007 07:56 PM : 30c1e0f34ad2972c72a01db5c74ab065 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll : 824,832 : 12/06/2007 10:21 PM : 806d274c9a6c3aaea5eae8e4af841e04 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll : 826,368 : 03/01/2008 09:06 AM : ad21461aef8244edec2ef18e55e1dcf3 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB953838-IE7\wininet.dll : 826,368 : 04/23/2008 00:16 AM : f6589be784647cfdbc22ea51ccb1a57a [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB956390-IE7\wininet.dll : 826,368 : 06/23/2008 12:57 AM : 8c13d4a7479fa0a026eda8abce82c0ed [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB958215-IE7\wininet.dll : 826,368 : 08/26/2008 03:24 AM : ef8eba98145bfa44e80d17a3b3453300 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB961260-IE7\wininet.dll : 826,368 : 10/16/2008 04:38 PM : 6741eaf7b7f110e803a6e38f6e5fa6b0 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB963027-IE7\wininet.dll : 826,368 : 12/20/2008 07:15 PM : a82935d32d0672e8ff4e91ae398e901c [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB969897-IE7\wininet.dll : 826,368 : 03/02/2009 08:18 PM : 28775945ccd53dee280ef58dea1a94c4 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB972260-IE7\wininet.dll : 827,392 : 04/29/2009 00:56 AM : 8e2d471157b0df329d8d0ea5d83b0ddb [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB974455-IE7\wininet.dll : 827,392 : 06/29/2009 12:12 AM : a39b7ba7ab9b1cc2a0009f59772db83c [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB976325-IE7\wininet.dll : 832,512 : 08/29/2009 03:36 AM : db111200015f08dddb8857e11c6a80e3 [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB978207-IE7\wininet.dll : 832,512 : 10/29/2009 03:46 AM : 7c599dec022bef6e3c9f4db4fc164e8b [Pos Repl]
 +-> C:\WINDOWS\ie7updates\KB980182-IE7\wininet.dll : 832,512 : 01/05/2010 06:00 AM : 21e7890f1ec89bef0af7c08d730ae317 [Pos Repl]
 +-> C:\WINDOWS\ie8\wininet.dll : 832,512 : 03/11/2010 08:38 AM : b6ab2eb1da4bb29079b84ac842520670 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2183461-IE8\wininet.dll : 916,480 : 05/06/2010 06:41 AM : 2d9c7b010409372c34f725da5cced083 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2360131-IE8\wininet.dll : 916,480 : 06/24/2010 08:22 AM : d3deb6b2b424ac93de3801eaeb21a9a5 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2416400-IE8\wininet.dll : 916,480 : 09/10/2010 01:58 AM : 36fe8abc59aafbe20cbe54bc372f9429 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2482017-IE8\wininet.dll : 916,480 : 11/05/2010 08:26 PM : 306a2b05ea9846278113964dc6e2c940 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2497640-IE8\wininet.dll : 916,480 : 12/20/2010 07:59 PM : 88014d62b5e3cdb0ac67948d86c926c8 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2530548-IE8\wininet.dll : 916,480 : 02/22/2011 07:06 PM : f192d49eefe297fa858b2c774ba2291d [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2559049-IE8\wininet.dll : 916,480 : 04/25/2011 12:11 AM : cc951c2212a200475a587a440e0aa804 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2586448-IE8\wininet.dll : 916,480 : 06/23/2011 02:36 PM : af4eddc6c0446fce5681b5ded52b8f0e [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2618444-IE8\wininet.dll : 916,480 : 08/22/2011 07:48 PM : 1a377838b4b468e37c3eeb5baa24f925 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2647516-IE8\wininet.dll : 916,992 : 11/04/2011 03:20 PM : 552263502ea8c24d301a0c43ff90b3ed [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2675157-IE8\wininet.dll : 916,992 : 12/17/2011 03:46 PM : f362d50fbdc6e34918df41bde1770e5c [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2699988-IE8\wininet.dll : 916,992 : 03/01/2012 07:01 AM : 009e7b4c284f080608d7286484015ee5 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2722913-IE8\wininet.dll : 916,992 : 05/16/2012 11:08 AM : 6b1774334e2975aa60596e54f5ea1430 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2744842-IE8\wininet.dll : 916,992 : 07/02/2012 01:49 PM : c4300cb4d20b1159dc77e01e8a2525ec [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2761465-IE8\wininet.dll : 916,992 : 08/28/2012 11:14 AM : ff1c14bca1a797ce45dd359fa2c9eda8 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2792100-IE8\wininet.dll : 916,992 : 11/01/2012 08:17 AM : 9ad88ea663124336e88eb031f917ce20 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2809289-IE8\wininet.dll : 916,480 : 12/26/2012 04:16 PM : d175f91a4c98b8848818c9b5089f88a2 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2817183-IE8\wininet.dll : 916,480 : 02/05/2013 04:05 PM : 5aacf4b4dee1972b7952e8a747122232 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2829530-IE8\wininet.dll : 916,480 : 03/01/2013 10:06 PM : da5b96a293b006572209e5eac9f3a045 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2838727-IE8\wininet.dll : 920,064 : 04/16/2013 06:17 PM : 5c4aac5a91422c95522ecc6c26fb93c8 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2846071-IE8\wininet.dll : 920,064 : 05/07/2013 06:30 PM : ce5ba470204a3176e60721c4b63b8df3 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2862772-IE8\wininet.dll : 920,064 : 06/07/2013 05:56 PM : c087cc88d7cd554409cbb5ebc29e8e38 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2870699-IE8\wininet.dll : 920,064 : 07/25/2013 10:47 PM : d46e195d0c76d430d73576cdac763f78 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2879017-IE8\wininet.dll : 920,064 : 08/08/2013 02:05 AM : f1bd516a4446b737baefb9fbaa92f01a [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2888505-IE8\wininet.dll : 920,064 : 09/23/2013 02:33 PM : d73f1be00684e675571015b3a5880f5b [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2898785-IE8\wininet.dll : 920,064 : 10/13/2013 03:25 AM : c5acab147f9697f40ecebb4bc0247ebf [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2909921-IE8\wininet.dll : 920,064 : 10/29/2013 03:57 AM : fbf173582874c30ec5faf8f8a67d873e [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2925418-IE8\wininet.dll : 920,064 : 02/05/2014 07:26 PM : e09551776d365bca891bbffb31ee4b4c [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB2936068-IE8\wininet.dll : 920,064 : 02/24/2014 07:46 AM : c29c1990c6ca8d7b098318f5887c3bdc [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB980182-IE8\wininet.dll : 914,944 : 03/08/2009 04:34 AM : 6ce32f7778061ccc5814d5e0f282d369 [Pos Repl]
 +-> C:\WINDOWS\ie8updates\KB982381-IE8\wininet.dll : 916,480 : 02/25/2010 02:24 AM : 7a42cfed96cda7f2fb1a26d1f9f65775 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\wininet.dll : 666,112 : 04/13/2008 08:12 PM : 7a4f775abb2f1c97def3e73afa2faedd [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\wininet.dll : 920,064 : 03/06/2014 01:59 PM : 8af91e4b4c1f5338ebe1548117304296 [Pos Repl]

 * C:\WINDOWS\System32\winlogon.exe : 507,904 : 04/13/2008 08:12 PM : ed0ef0a136dec83df69f04118870003e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe : 502,272 : 08/10/2004 06:00 AM : 01c3346c241652f43aed8e2149881bfe [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\winlogon.exe : 507,904 : 04/13/2008 08:12 PM : ed0ef0a136dec83df69f04118870003e [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\winlogon.exe : 507,904 : 04/13/2008 08:12 PM : ed0ef0a136dec83df69f04118870003e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\winlogon.exe : 507,904 : 04/13/2008 08:12 PM : ed0ef0a136dec83df69f04118870003e [Pos Repl]

 * C:\WINDOWS\System32\ws2_32.dll : 82,432 : 04/13/2008 08:12 PM : 2ccc474eb85ceaa3e1fa1726580a3e5a [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ws2_32.dll : 82,944 : 08/10/2004 06:00 AM : 2ed0b7f12a60f90092081c50fa0ec2b2 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ws2_32.dll : 82,432 : 04/13/2008 08:12 PM : 2ccc474eb85ceaa3e1fa1726580a3e5a [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll : 82,432 : 04/13/2008 08:12 PM : 2ccc474eb85ceaa3e1fa1726580a3e5a [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ws2_32.dll : 82,432 : 04/13/2008 08:12 PM : 2ccc474eb85ceaa3e1fa1726580a3e5a [Pos Repl]

 * C:\WINDOWS\System32\ws2help.dll : 19,968 : 04/13/2008 08:12 PM : 9789e95e1d88eeb4b922bf3ea7779c28 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ws2help.dll : 19,968 : 08/10/2004 06:00 AM : 9beacb911ca61e5881102188ab7fb431 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ws2help.dll : 19,968 : 04/13/2008 08:12 PM : 9789e95e1d88eeb4b922bf3ea7779c28 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ws2help.dll : 19,968 : 04/13/2008 08:12 PM : 9789e95e1d88eeb4b922bf3ea7779c28 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ws2help.dll : 19,968 : 04/13/2008 08:12 PM : 9789e95e1d88eeb4b922bf3ea7779c28 [Pos Repl]

 * C:\WINDOWS\System32\wscntfy.exe : 13,824 : 04/13/2008 08:12 PM : f92e1076c42fcd6db3d72d8cfe9816d5 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\wscntfy.exe : 13,824 : 08/10/2004 06:00 AM : 49911dd39e023bb6c45e4e436cfbd297 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\wscntfy.exe : 13,824 : 04/13/2008 08:12 PM : f92e1076c42fcd6db3d72d8cfe9816d5 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\wscntfy.exe : 13,824 : 04/13/2008 08:12 PM : f92e1076c42fcd6db3d72d8cfe9816d5 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\wscntfy.exe : 13,824 : 04/13/2008 08:12 PM : f92e1076c42fcd6db3d72d8cfe9816d5 [Pos Repl]

 * C:\WINDOWS\System32\xmlprov.dll : 129,024 : 04/13/2008 08:12 PM : 295d21f14c335b53cb8154e5b1f892b9 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\xmlprov.dll : 129,536 : 08/10/2004 06:00 AM : eef46dab68229a14da3d8e73c99e2959 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\xmlprov.dll : 129,024 : 04/13/2008 08:12 PM : 295d21f14c335b53cb8154e5b1f892b9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\xmlprov.dll : 129,024 : 04/13/2008 08:12 PM : 295d21f14c335b53cb8154e5b1f892b9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\xmlprov.dll : 129,024 : 04/13/2008 08:12 PM : 295d21f14c335b53cb8154e5b1f892b9 [Pos Repl]



* C:\WINDOWS\explorer.exe : 1,033,728 : 04/13/2008 08:12 PM : 12896823fb95bfb3dc9b46bcaedc9923 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe : 1,033,216 : 06/13/2007 07:26 AM : 7712df0cdde3a5ac89843e61cd5b3658 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\explorer.exe : 1,033,216 : 06/13/2007 06:23 AM : 97bd6515465659ff8f3b7be375b2ea87 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB938828$\explorer.exe : 1,032,192 : 08/10/2004 06:00 AM : a0732187050030ae399b241436565e64 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\explorer.exe : 1,033,728 : 04/13/2008 08:12 PM : 12896823fb95bfb3dc9b46bcaedc9923 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\explorer.exe : 1,033,728 : 04/13/2008 08:12 PM : 12896823fb95bfb3dc9b46bcaedc9923 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\explorer.exe : 1,033,728 : 04/13/2008 08:12 PM : 12896823fb95bfb3dc9b46bcaedc9923 [Pos Repl]

 * C:\WINDOWS\System32\drivers\acpiec.sys : 11,648 : 08/10/2004 06:00 AM : 9859c0f6936e723e4892d7141b1327d5 [NoSig]
 +-> C:\WINDOWS\ERDNT\cache\acpiec.sys : 11,648 : 08/10/2004 06:00 AM : 9859c0f6936e723e4892d7141b1327d5 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\acpiec.sys : 11,648 : 08/10/2004 06:00 AM : 9859c0f6936e723e4892d7141b1327d5 [Pos Repl]

 * C:\WINDOWS\System32\drivers\acpi.sys : 187,776 : 04/13/2008 02:36 PM : 8fd99680a539792a30e97944fdaecf17 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\acpi.sys : 187,776 : 08/10/2004 06:00 AM : a10c7534f7223f4a73a948967d00e69b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\acpi.sys : 187,776 : 04/13/2008 02:36 PM : 8fd99680a539792a30e97944fdaecf17 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\acpi.sys : 187,776 : 04/13/2008 02:36 PM : 8fd99680a539792a30e97944fdaecf17 [Pos Repl]

 * C:\WINDOWS\System32\drivers\aec.sys : 142,592 : 04/13/2008 12:39 AM : 8bed39e3c35d6a489438b8141717a557 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB900485\SP2QFE\aec.sys : 142,464 : 02/14/2006 08:30 PM : 1ee7b434ba961ef845de136224c30fec [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\aec.sys : 142,464 : 02/14/2006 08:22 PM : 1ee7b434ba961ef845de136224c30fec [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB900485$\aec.sys : 142,464 : 08/03/2004 11:39 PM : 841f385c6cfaf66b58fbd898722bb4f0 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\aec.sys : 142,592 : 04/13/2008 12:39 AM : 8bed39e3c35d6a489438b8141717a557 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\aec.sys : 142,592 : 04/13/2008 12:39 AM : 8bed39e3c35d6a489438b8141717a557 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\aec.sys : 142,592 : 04/13/2008 12:39 AM : 8bed39e3c35d6a489438b8141717a557 [Pos Repl]

 * C:\WINDOWS\System32\drivers\afd.sys : 138,496 : 08/17/2011 09:49 AM : 1e44bc1e83d8fd2305f8d452db109cf9 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2503665\SP3QFE\afd.sys : 138,496 : 02/16/2011 09:25 AM : 8d499b1276012eb907e7a9e0f4d8fda4 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\afd.sys : 138,496 : 10/16/2008 11:07 AM : 38d7b715504da4741df35e3594fe2099 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2592799\SP3QFE\afd.sys : 138,496 : 08/17/2011 09:41 AM : f6b7b1ecd7b41736bdb6ff4b092bcb79 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\afd.sys : 138,368 : 06/20/2008 06:44 AM : d99ddffb33deacdcf20717cb520379f6 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\afd.sys : 138,496 : 06/20/2008 07:40 AM : e3049b90fe06f3f740b7cfda44995e2c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\afd.sys : 138,496 : 06/20/2008 07:48 AM : d6ee6014241d034e63c49a50cb2b442a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB956803\SP3QFE\afd.sys : 138,496 : 08/14/2008 06:34 AM : 4d43e74f2a1239d53929b82600f1971c [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\afd.sys : 138,368 : 06/20/2008 06:44 AM : 944ca435bfcfc82cc1ed9e3a7d731aa9 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2503665$\afd.sys : 138,496 : 10/16/2008 10:43 AM : 7618d5218f2a614672ec61a80d854a37 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2509553$\afd.sys : 138,496 : 08/14/2008 06:04 AM : 7e775010ef291da96ad17ca4b17137d7 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2592799$\afd.sys : 138,496 : 02/16/2011 09:22 AM : 355556d9e580915118cd7ef736653a89 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748$\afd.sys : 138,112 : 04/13/2008 03:19 PM : 322d0e36693d6e24a2398bee62a268cd [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748_0$\afd.sys : 138,496 : 08/10/2004 06:00 AM : 5ac495f4cb807b2b98ad2ad591e6d92e [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB956803$\afd.sys : 138,496 : 06/20/2008 07:40 AM : e3049b90fe06f3f740b7cfda44995e2c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\afd.sys : 138,112 : 04/13/2008 03:19 PM : 322d0e36693d6e24a2398bee62a268cd [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\afd.sys : 138,496 : 08/17/2011 09:49 AM : 1e44bc1e83d8fd2305f8d452db109cf9 [Pos Repl]

 * C:\WINDOWS\System32\drivers\agp440.sys : 42,368 : 04/13/2008 02:36 PM : 08fd04aa961bdc77fb983f328334e3d7 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\agp440.sys : 42,368 : 08/04/2004 00:07 AM : 2c428fa0c3e3a01ed93c9b2a27d8d4bb [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\agp440.sys : 42,368 : 04/13/2008 02:36 PM : 08fd04aa961bdc77fb983f328334e3d7 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\agp440.sys : 42,368 : 04/13/2008 02:36 PM : 08fd04aa961bdc77fb983f328334e3d7 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\agp440.sys : 42,368 : 04/13/2008 02:36 PM : 08fd04aa961bdc77fb983f328334e3d7 [Pos Repl]

 * C:\WINDOWS\System32\drivers\amdk6.sys : 37,376 : 04/13/2008 02:31 PM : d7701d7e72243286cc88c9973d891057 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\amdk6.sys : 36,992 : 08/10/2004 06:00 AM : dad16a9d5c873e7219e6b43802ed316a [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\amdk6.sys : 37,376 : 04/13/2008 02:31 PM : d7701d7e72243286cc88c9973d891057 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\amdk6.sys : 37,376 : 04/13/2008 02:31 PM : d7701d7e72243286cc88c9973d891057 [Pos Repl]

 * C:\WINDOWS\System32\drivers\amdk7.sys : 37,760 : 04/13/2008 02:31 PM : 8fce268cdbdd83b23419d1f35f42c7b1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\amdk7.sys : 37,376 : 08/10/2004 06:00 AM : 680ad1c1bb16239e28d8f33a54a7a3c7 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\amdk7.sys : 37,760 : 04/13/2008 02:31 PM : 8fce268cdbdd83b23419d1f35f42c7b1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\amdk7.sys : 37,760 : 04/13/2008 02:31 PM : 8fce268cdbdd83b23419d1f35f42c7b1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\arp1394.sys : 60,800 : 04/13/2008 02:51 PM : b5b8a80875c1dededa8b02765642c32f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\arp1394.sys : 60,800 : 08/10/2004 06:00 AM : f0d692b0bffb46e30eb3cea168bbc49f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\arp1394.sys : 60,800 : 04/13/2008 02:51 PM : b5b8a80875c1dededa8b02765642c32f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\arp1394.sys : 60,800 : 04/13/2008 02:51 PM : b5b8a80875c1dededa8b02765642c32f [Pos Repl]

 * C:\WINDOWS\System32\drivers\asyncmac.sys : 14,336 : 04/13/2008 02:57 PM : b153affac761e7f5fcfa822b9c4e97bc [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\asyncmac.sys : 14,336 : 08/10/2004 06:00 AM : 02000abf34af4c218c35d257024807d6 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\asyncmac.sys : 14,336 : 04/13/2008 02:57 PM : b153affac761e7f5fcfa822b9c4e97bc [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\asyncmac.sys : 14,336 : 04/13/2008 02:57 PM : b153affac761e7f5fcfa822b9c4e97bc [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\asyncmac.sys : 14,336 : 04/13/2008 02:57 PM : b153affac761e7f5fcfa822b9c4e97bc [Pos Repl]

 * C:\WINDOWS\System32\drivers\atapi.sys : 96,512 : 04/13/2008 02:40 PM : 9f3a2f5aa6875c72bf062c712cfa2674 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\atapi.sys : 95,360 : 08/03/2004 11:59 PM : cdfe4411a69c224bd1d11b2da92dac51 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\atapi.sys : 96,512 : 04/13/2008 02:40 PM : 9f3a2f5aa6875c72bf062c712cfa2674 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\atapi.sys : 96,512 : 04/13/2008 02:40 PM : 9f3a2f5aa6875c72bf062c712cfa2674 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\atapi.sys : 96,512 : 04/13/2008 02:40 PM : 9f3a2f5aa6875c72bf062c712cfa2674 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys : 95,360 : 08/03/2004 11:59 PM : cdfe4411a69c224bd1d11b2da92dac51 [Pos Repl]

 * C:\WINDOWS\System32\drivers\audstub.sys : 3,072 : 08/17/2001 02:59 PM : d9f724aa26c010a217c97606b160ed68 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\audstub.sys : 3,072 : 08/17/2001 02:59 PM : d9f724aa26c010a217c97606b160ed68 [Pos Repl]

 * C:\WINDOWS\System32\drivers\battc.sys : 14,208 : 04/13/2008 02:36 PM : 0d93976f7801b7fcd8135cc77257bbd0 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\battc.sys : 14,080 : 08/17/2001 02:57 PM : ea22edadf90c0aba8319454b2a07b700 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\battc.sys : 14,208 : 04/13/2008 02:36 PM : 0d93976f7801b7fcd8135cc77257bbd0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\battc.sys : 14,208 : 04/13/2008 02:36 PM : 0d93976f7801b7fcd8135cc77257bbd0 [Pos Repl]

Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #11 on: August 18, 2015, 05:26:09 AM »
Reply 3 of 5  -  (exceeded 65,000 characters) this portion only includes a portion of rkill.txt

 * C:\WINDOWS\System32\drivers\beep.sys : 4,224 : 08/10/2004 06:00 AM : da1f27d85e0d1525f6621372e7b685e9 [NoSig]
 +-> C:\WINDOWS\ERDNT\cache\beep.sys : 4,224 : 08/10/2004 06:00 AM : da1f27d85e0d1525f6621372e7b685e9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\beep.sys : 4,224 : 08/10/2004 06:00 AM : da1f27d85e0d1525f6621372e7b685e9 [Pos Repl]

 * C:\WINDOWS\System32\drivers\bridge.sys : 71,552 : 04/13/2008 02:53 PM : f934d1b230f84e1d19dd00ac5a7a83ed [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\bridge.sys : 71,552 : 08/10/2004 06:00 AM : e4e6a0922e3d983728c9ad4e8d466954 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\bridge.sys : 71,552 : 04/13/2008 02:53 PM : f934d1b230f84e1d19dd00ac5a7a83ed [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\bridge.sys : 71,552 : 04/13/2008 02:53 PM : f934d1b230f84e1d19dd00ac5a7a83ed [Pos Repl]

 * C:\WINDOWS\System32\drivers\bthport.sys : 272,128 : 06/13/2008 07:05 AM : 662bfd909447dd9cc15b1a1c366583b4 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB951376\SP2QFE\bthport.sys : 272,128 : 04/14/2008 07:00 AM : fc50ce8c3ada692fbe82f1d4c8a4b70b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951376\SP3GDR\bthport.sys : 272,128 : 04/14/2008 08:30 AM : 8381fb906f05495f3d2045fbc9576cd5 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951376\SP3QFE\bthport.sys : 272,128 : 04/14/2008 08:36 AM : f6cbbcc40f94eb8a88b1e826911ac795 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951376-v2\SP2QFE\bthport.sys : 272,128 : 06/13/2008 05:52 AM : 956e7e86bb00e792c8ff3afb2f8e460d [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951376-v2\SP3GDR\bthport.sys : 272,128 : 06/13/2008 07:05 AM : 662bfd909447dd9cc15b1a1c366583b4 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951376-v2\SP3QFE\bthport.sys : 272,128 : 06/13/2008 07:27 AM : 51d05d5a8a7d93ab0b1a8d6a38db3ca4 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\bthport.sys : 272,128 : 06/13/2008 09:10 AM : 95ef6f3f386d93ee1e4d9ca45a50252a [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951376$\bthport.sys : 273,024 : 04/13/2008 02:46 PM : 10b85171b90c449f8da71c2640b797e9 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951376-v2$\bthport.sys : 272,128 : 04/14/2008 08:30 AM : 8381fb906f05495f3d2045fbc9576cd5 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951376-v2_0$\bthport.sys : 272,128 : 04/14/2008 07:01 AM : 0bedc4527aafdae75b1844d4db29b6db [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\bthport.sys : 272,128 : 06/13/2008 07:05 AM : 662bfd909447dd9cc15b1a1c366583b4 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\bthport.sys : 273,024 : 04/13/2008 02:46 PM : 10b85171b90c449f8da71c2640b797e9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\bthport.sys : 272,128 : 06/13/2008 07:05 AM : 662bfd909447dd9cc15b1a1c366583b4 [Pos Repl]

 * C:\WINDOWS\System32\drivers\cbidf2k.sys : 13,952 : 08/17/2001 02:52 PM : 90a673fc8e12a79afbed2576f6a7aaf9 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\cbidf2k.sys : 13,952 : 08/17/2001 02:52 PM : 90a673fc8e12a79afbed2576f6a7aaf9 [Pos Repl]

 * C:\WINDOWS\System32\drivers\cdaudio.sys : 18,688 : 08/10/2004 06:00 AM : c1b486a7658353d33a10cc15211a873b [NoSig]
 +-> C:\WINDOWS\system32\dllcache\cdaudio.sys : 18,688 : 08/10/2004 06:00 AM : c1b486a7658353d33a10cc15211a873b [Pos Repl]

 * C:\WINDOWS\System32\drivers\cdfs.sys : 63,744 : 04/13/2008 03:14 PM : c885b02847f5d2fd45a24e219ed93b32 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\cdfs.sys : 63,744 : 08/10/2004 06:00 AM : cd7d5152df32b47f4e36f710b35aae02 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\cdfs.sys : 63,744 : 04/13/2008 03:14 PM : c885b02847f5d2fd45a24e219ed93b32 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\cdfs.sys : 63,744 : 04/13/2008 03:14 PM : c885b02847f5d2fd45a24e219ed93b32 [Pos Repl]

 * C:\WINDOWS\System32\drivers\cdrom.sys : 62,976 : 04/13/2008 02:40 PM : 1f4260cc5b42272d71f79e570a27a4fe [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\cdrom.sys : 49,536 : 08/10/2004 06:00 AM : af9c19b3100fe010496b1a27181fbf72 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\cdrom.sys : 62,976 : 04/13/2008 02:40 PM : 1f4260cc5b42272d71f79e570a27a4fe [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\cdrom.sys : 62,976 : 04/13/2008 02:40 PM : 1f4260cc5b42272d71f79e570a27a4fe [Pos Repl]

 * C:\WINDOWS\System32\drivers\classpnp.sys : 49,536 : 04/13/2008 03:16 PM : fe47dd8fe6d7768ff94ebec6c74b2719 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\classpnp.sys : 49,664 : 08/10/2004 06:00 AM : d86173b401470f06d9810f7962969ddf [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\classpnp.sys : 49,536 : 04/13/2008 03:16 PM : fe47dd8fe6d7768ff94ebec6c74b2719 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\classpnp.sys : 49,536 : 04/13/2008 03:16 PM : fe47dd8fe6d7768ff94ebec6c74b2719 [Pos Repl]

 * C:\WINDOWS\System32\drivers\CmBatt.sys : 13,952 : 04/13/2008 02:36 PM : 0f6c187d38d98f8df904589a5f94d411 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\cmbatt.sys : 14,080 : 08/04/2004 00:07 AM : 4266be808f85826aedf3c64c1e240203 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\cmbatt.sys : 13,952 : 04/13/2008 02:36 PM : 0f6c187d38d98f8df904589a5f94d411 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\cmbatt.sys : 13,952 : 04/13/2008 02:36 PM : 0f6c187d38d98f8df904589a5f94d411 [Pos Repl]

 * C:\WINDOWS\System32\drivers\compbatt.sys : 10,240 : 04/13/2008 02:36 PM : 6e4c9f21f0fae8940661144f41b13203 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\compbatt.sys : 9,344 : 08/17/2001 02:58 PM : df1b1a24bf52d0ebc01ed4ece8979f50 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\compbatt.sys : 10,240 : 04/13/2008 02:36 PM : 6e4c9f21f0fae8940661144f41b13203 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\compbatt.sys : 10,240 : 04/13/2008 02:36 PM : 6e4c9f21f0fae8940661144f41b13203 [Pos Repl]

 * C:\WINDOWS\System32\drivers\cpqdap01.sys : 11,776 : 08/10/2004 06:00 AM : 9624293e55ad405415862b504ca95b73 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\cpqdap01.sys : 11,776 : 08/10/2004 06:00 AM : 9624293e55ad405415862b504ca95b73 [Pos Repl]

 * C:\WINDOWS\System32\drivers\crusoe.sys : 36,736 : 04/13/2008 02:31 PM : f50d9bdbb25cce075e514dc07472a22f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\crusoe.sys : 36,480 : 08/10/2004 06:00 AM : 6af1684ccaac3f7ef4ee9ba65eb0677a [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\crusoe.sys : 36,736 : 04/13/2008 02:31 PM : f50d9bdbb25cce075e514dc07472a22f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\crusoe.sys : 36,736 : 04/13/2008 02:31 PM : f50d9bdbb25cce075e514dc07472a22f [Pos Repl]

 * C:\WINDOWS\System32\drivers\diskdump.sys : 14,208 : 04/13/2008 02:40 PM : e65e2353a5d74ea89971cb918eeeb2f6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\diskdump.sys : 14,208 : 08/10/2004 06:00 AM : d16c81677a9be399c63cd2ea486472a5 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\diskdump.sys : 14,208 : 04/13/2008 02:40 PM : e65e2353a5d74ea89971cb918eeeb2f6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\diskdump.sys : 14,208 : 04/13/2008 02:40 PM : e65e2353a5d74ea89971cb918eeeb2f6 [Pos Repl]

 * C:\WINDOWS\System32\drivers\disk.sys : 36,352 : 04/13/2008 02:40 PM : 044452051f3e02e7963599fc8f4f3e25 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\disk.sys : 36,352 : 08/10/2004 06:00 AM : 00ca44e4534865f8a3b64f7c0984bff0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\disk.sys : 36,352 : 04/13/2008 02:40 PM : 044452051f3e02e7963599fc8f4f3e25 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\disk.sys : 36,352 : 04/13/2008 02:40 PM : 044452051f3e02e7963599fc8f4f3e25 [Pos Repl]

 * C:\WINDOWS\System32\drivers\dmboot.sys : 799,744 : 04/13/2008 02:44 PM : d992fe1274bde0f84ad826acae022a41 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\dmboot.sys : 799,744 : 08/10/2004 06:00 AM : c0fbb516e06e243f0cf31f597e7ebf7d [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\dmboot.sys : 799,744 : 04/13/2008 02:44 PM : d992fe1274bde0f84ad826acae022a41 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\dmboot.sys : 799,744 : 04/13/2008 02:44 PM : d992fe1274bde0f84ad826acae022a41 [Pos Repl]

 * C:\WINDOWS\System32\drivers\dmio.sys : 153,344 : 04/13/2008 02:44 PM : 7c824cf7bbde77d95c08005717a95f6f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\dmio.sys : 153,344 : 08/10/2004 06:00 AM : f5e7b358a732d09f4bcf2824b88b9e28 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\dmio.sys : 153,344 : 04/13/2008 02:44 PM : 7c824cf7bbde77d95c08005717a95f6f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\dmio.sys : 153,344 : 04/13/2008 02:44 PM : 7c824cf7bbde77d95c08005717a95f6f [Pos Repl]

 * C:\WINDOWS\System32\drivers\dmload.sys : 5,888 : 08/10/2004 06:00 AM : e9317282a63ca4d188c0df5e09c6ac5f [NoSig]
 +-> C:\WINDOWS\system32\dllcache\dmload.sys : 5,888 : 08/10/2004 06:00 AM : e9317282a63ca4d188c0df5e09c6ac5f [Pos Repl]

 * C:\WINDOWS\System32\drivers\DMusic.sys : 52,864 : 04/13/2008 02:45 PM : 8a208dfcf89792a484e76c40e5f50b45 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\dmusic.sys : 52,864 : 08/04/2004 00:07 AM : a6f881284ac1150e37d9ae47ff601267 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\dmusic.sys : 52,864 : 04/13/2008 02:45 PM : 8a208dfcf89792a484e76c40e5f50b45 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\dmusic.sys : 52,864 : 04/13/2008 02:45 PM : 8a208dfcf89792a484e76c40e5f50b45 [Pos Repl]

 * C:\WINDOWS\System32\drivers\drmkaud.sys : 2,944 : 04/13/2008 02:45 PM : 8f5fcff8e8848afac920905fbd9d33c8 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\drmkaud.sys : 2,944 : 08/04/2004 00:07 AM : 1ed4dbbae9f5d558dbba4cc450e3eb2e [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\drmkaud.sys : 2,944 : 04/13/2008 02:45 PM : 8f5fcff8e8848afac920905fbd9d33c8 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\drmkaud.sys : 2,944 : 04/13/2008 02:45 PM : 8f5fcff8e8848afac920905fbd9d33c8 [Pos Repl]

 * C:\WINDOWS\System32\drivers\drmk.sys : 60,160 : 04/13/2008 02:45 PM : 6cb08593487f5701d2d2254e693eafce [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\drmk.sys : 60,288 : 08/04/2004 00:08 AM : ff86422268de771d571e123eb7092c6a [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\drmk.sys : 60,160 : 04/13/2008 02:45 PM : 6cb08593487f5701d2d2254e693eafce [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\drmk.sys : 60,160 : 04/13/2008 02:45 PM : 6cb08593487f5701d2d2254e693eafce [Pos Repl]

 * C:\WINDOWS\System32\drivers\dxapi.sys : 10,496 : 08/10/2004 06:00 AM : fe97d0343acfdebdd578fc67cc91fa87 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\dxapi.sys : 10,496 : 08/10/2004 06:00 AM : fe97d0343acfdebdd578fc67cc91fa87 [Pos Repl]

 * C:\WINDOWS\System32\drivers\dxg.sys : 71,168 : 04/13/2008 02:38 PM : ac7280566a7bb85cb3291f04ddc1198e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\dxg.sys : 71,040 : 08/10/2004 06:00 AM : d3dac8432110aad0b02a58b4459ab835 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\dxg.sys : 71,168 : 04/13/2008 02:38 PM : ac7280566a7bb85cb3291f04ddc1198e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\dxg.sys : 71,168 : 04/13/2008 02:38 PM : ac7280566a7bb85cb3291f04ddc1198e [Pos Repl]

 * C:\WINDOWS\System32\drivers\dxgthk.sys : 3,328 : 08/10/2004 06:00 AM : a73f5d6705b1d820c19b18782e176efd [NoSig]
 +-> C:\WINDOWS\system32\dllcache\dxgthk.sys : 3,328 : 08/10/2004 06:00 AM : a73f5d6705b1d820c19b18782e176efd [Pos Repl]

 * C:\WINDOWS\System32\drivers\fastfat.sys : 143,744 : 04/13/2008 03:14 PM : 38d332a6d56af32635675f132548343e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\fastfat.sys : 143,360 : 08/10/2004 06:00 AM : 3117f595e9615e04f05a54fc15a03b20 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\fastfat.sys : 143,744 : 04/13/2008 03:14 PM : 38d332a6d56af32635675f132548343e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\fastfat.sys : 143,744 : 04/13/2008 03:14 PM : 38d332a6d56af32635675f132548343e [Pos Repl]

 * C:\WINDOWS\System32\drivers\fdc.sys : 27,392 : 04/13/2008 02:40 PM : 92cdd60b6730b9f50f6a1a0c1f8cdc81 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\fdc.sys : 27,392 : 08/10/2004 06:00 AM : ced2e8396a8838e59d8fd529c680e02c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\fdc.sys : 27,392 : 04/13/2008 02:40 PM : 92cdd60b6730b9f50f6a1a0c1f8cdc81 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\fdc.sys : 27,392 : 04/13/2008 02:40 PM : 92cdd60b6730b9f50f6a1a0c1f8cdc81 [Pos Repl]

 * C:\WINDOWS\System32\drivers\fips.sys : 44,544 : 04/13/2008 02:33 PM : d45926117eb9fa946a6af572fbe1caa3 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\fips.sys : 34,944 : 08/10/2004 06:00 AM : e153ab8a11de5452bcf5ac7652dbf3ed [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\fips.sys : 44,544 : 04/13/2008 02:33 PM : d45926117eb9fa946a6af572fbe1caa3 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\fips.sys : 44,544 : 04/13/2008 02:33 PM : d45926117eb9fa946a6af572fbe1caa3 [Pos Repl]

 * C:\WINDOWS\System32\drivers\flpydisk.sys : 20,480 : 04/13/2008 02:40 PM : 9d27e7b80bfcdf1cdd9b555862d5e7f0 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\flpydisk.sys : 20,480 : 08/10/2004 06:00 AM : 0dd1de43115b93f4d85e889d7a86f548 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\flpydisk.sys : 20,480 : 04/13/2008 02:40 PM : 9d27e7b80bfcdf1cdd9b555862d5e7f0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\flpydisk.sys : 20,480 : 04/13/2008 02:40 PM : 9d27e7b80bfcdf1cdd9b555862d5e7f0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\fltMgr.sys : 129,792 : 04/13/2008 02:32 PM : b2cf4b0786f8212cb92ed2b50c6db6b0 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB922582\SP2QFE\fltmgr.sys : 128,768 : 08/21/2006 05:43 AM : 5a85cd3d07273e3f6fe72ee9c6431632 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\fltmgr.sys : 128,896 : 08/21/2006 05:14 AM : 3d234fb6d6ee875eb009864a299bea29 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB922582$\fltmgr.sys : 124,800 : 08/10/2004 06:00 AM : 157754f0df355a9e0a6f54721914f9c6 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\fltmgr.sys : 129,792 : 04/13/2008 02:32 PM : b2cf4b0786f8212cb92ed2b50c6db6b0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\fltmgr.sys : 129,792 : 04/13/2008 02:32 PM : b2cf4b0786f8212cb92ed2b50c6db6b0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\fs_rec.sys : 7,936 : 08/10/2004 06:00 AM : 3e1e2bd4f39b0e2b7dc4f4d2bcc2779a [NoSig]
 +-> C:\WINDOWS\system32\dllcache\fs_rec.sys : 7,936 : 08/10/2004 06:00 AM : 3e1e2bd4f39b0e2b7dc4f4d2bcc2779a [Pos Repl]

 * C:\WINDOWS\System32\drivers\fsvga.sys : 12,160 : 08/10/2004 06:00 AM : 455f778ee14368468560bd7cb8c854d0 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\fsvga.sys : 12,160 : 08/10/2004 06:00 AM : 455f778ee14368468560bd7cb8c854d0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ftdisk.sys : 125,056 : 08/17/2001 02:52 PM : 6ac26732762483366c3969c9e4d2259d [NoSig]
 +-> C:\WINDOWS\system32\dllcache\ftdisk.sys : 125,056 : 08/17/2001 02:52 PM : 6ac26732762483366c3969c9e4d2259d [Pos Repl]

 * C:\WINDOWS\System32\drivers\hidclass.sys : 36,864 : 04/13/2008 02:45 PM : 1af592532532a402ed7c060f6954004f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\hidclass.sys : 36,224 : 08/10/2004 06:00 AM : 378055ab8dda86228683c697c4e11685 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\hidclass.sys : 36,864 : 04/13/2008 02:45 PM : 1af592532532a402ed7c060f6954004f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\hidclass.sys : 36,864 : 04/13/2008 02:45 PM : 1af592532532a402ed7c060f6954004f [Pos Repl]

 * C:\WINDOWS\System32\drivers\hidparse.sys : 25,088 : 07/02/2013 10:12 PM : c569ef030b11f896e123a30ac92678db [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\hidparse.sys : 24,960 : 08/10/2004 06:00 AM : 5fff41cd5108e9051d255c37825af697 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2862335$\hidparse.sys : 24,960 : 04/13/2008 02:45 PM : 96eccf28fdbf1b2cc12725818a63628d [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\hidparse.sys : 25,088 : 07/02/2013 10:12 PM : c569ef030b11f896e123a30ac92678db [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\hidparse.sys : 24,960 : 04/13/2008 02:45 PM : 96eccf28fdbf1b2cc12725818a63628d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\hidparse.sys : 25,088 : 07/02/2013 10:12 PM : c569ef030b11f896e123a30ac92678db [Pos Repl]

 * C:\WINDOWS\System32\drivers\hidusb.sys : 10,368 : 04/13/2008 02:45 PM : ccf82c5ec8a7326c3066de870c06daf1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\hidusb.sys : 9,600 : 08/17/2001 02:02 PM : 1de6783b918f540149aa69943bdfeba8 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\hidusb.sys : 10,368 : 04/13/2008 02:45 PM : ccf82c5ec8a7326c3066de870c06daf1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\hidusb.sys : 10,368 : 04/13/2008 02:45 PM : ccf82c5ec8a7326c3066de870c06daf1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\http.sys : 265,728 : 10/20/2009 12:20 AM : f80a415ef82cd06ffaf0d971528ead38 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB887742\SP2QFE\http.sys : 262,272 : 10/08/2004 07:18 PM : 3247a2db333d1521680e6864a8295a47 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB916595\SP2QFE\http.sys : 262,656 : 03/16/2006 09:08 PM : 909d110c9634b0f1487eaaea837317d9 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB970430\SP3QFE\http.sys : 265,728 : 10/20/2009 11:21 AM : 937031c085718c1c04a9c0864625ec6b [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\http.sys : 262,784 : 03/16/2006 08:33 PM : cb77bb47e67e84deb17ba29632501730 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB887742$\http.sys : 263,040 : 08/10/2004 06:00 AM : c19b522a9ae0bbc3293397f3055e80a1 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB916595$\http.sys : 262,400 : 10/08/2004 07:48 PM : bfb7b73c942e816c4fb4a5a7bae87136 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB970430$\http.sys : 264,832 : 04/13/2008 02:53 PM : f6aacf5bce2893e0c1754afeb672e5c9 [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\http.sys : 265,728 : 10/20/2009 12:20 AM : f80a415ef82cd06ffaf0d971528ead38 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\http.sys : 264,832 : 04/13/2008 02:53 PM : f6aacf5bce2893e0c1754afeb672e5c9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\http.sys : 265,728 : 10/20/2009 12:20 AM : f80a415ef82cd06ffaf0d971528ead38 [Pos Repl]

 * C:\WINDOWS\System32\drivers\i8042prt.sys : 52,480 : 04/13/2008 03:18 PM : 4a0b06aa8943c1e332520f7440c0aa30 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\i8042prt.sys : 52,736 : 08/10/2004 06:00 AM : 5502b58eef7486ee6f93f3f164dcb808 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\i8042prt.sys : 52,480 : 04/13/2008 03:18 PM : 4a0b06aa8943c1e332520f7440c0aa30 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\i8042prt.sys : 52,480 : 04/13/2008 03:18 PM : 4a0b06aa8943c1e332520f7440c0aa30 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0020\DriverFiles\i386\i8042prt.sys : 52,480 : 04/13/2008 03:18 PM : 4a0b06aa8943c1e332520f7440c0aa30 [Pos Repl]

 * C:\WINDOWS\System32\drivers\imapi.sys : 42,112 : 04/13/2008 02:40 PM : 083a052659f5310dd8b6a6cb05edcf8e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\imapi.sys : 41,856 : 08/10/2004 06:00 AM : f8aa320c6a0409c0380e5d8a99d76ec6 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\imapi.sys : 42,112 : 04/13/2008 02:40 PM : 083a052659f5310dd8b6a6cb05edcf8e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\imapi.sys : 42,112 : 04/13/2008 02:40 PM : 083a052659f5310dd8b6a6cb05edcf8e [Pos Repl]

 * C:\WINDOWS\System32\drivers\intelide.sys : 5,504 : 04/13/2008 02:40 PM : b5466a9250342a7aa0cd1fba13420678 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\intelide.sys : 5,504 : 08/03/2004 11:59 PM : 2d722b2b54ab55b2fa475eb58d7b2aad [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\intelide.sys : 5,504 : 04/13/2008 02:40 PM : b5466a9250342a7aa0cd1fba13420678 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\intelide.sys : 5,504 : 04/13/2008 02:40 PM : b5466a9250342a7aa0cd1fba13420678 [Pos Repl]

 * C:\WINDOWS\System32\drivers\intelppm.sys : 36,352 : 04/13/2008 02:31 PM : 8c953733d8f36eb2133f5bb58808b66b [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\intelppm.sys : 36,096 : 08/10/2004 06:00 AM : 279fb78702454dff2bb445f238c048d2 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\intelppm.sys : 36,352 : 04/13/2008 02:31 PM : 8c953733d8f36eb2133f5bb58808b66b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\intelppm.sys : 36,352 : 04/13/2008 02:31 PM : 8c953733d8f36eb2133f5bb58808b66b [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0013\DriverFiles\i386\intelppm.sys : 36,096 : 08/10/2004 06:00 AM : 279fb78702454dff2bb445f238c048d2 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0014\DriverFiles\i386\intelppm.sys : 36,096 : 08/10/2004 06:00 AM : 279fb78702454dff2bb445f238c048d2 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ip6fw.sys : 36,608 : 04/13/2008 02:53 PM : 3bb22519a194418d5fec05d800a19ad0 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ip6fw.sys : 29,056 : 08/10/2004 06:00 AM : 4448006b6bc60e6c027932cfc38d6855 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ip6fw.sys : 36,608 : 04/13/2008 02:53 PM : 3bb22519a194418d5fec05d800a19ad0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys : 36,608 : 04/13/2008 02:53 PM : 3bb22519a194418d5fec05d800a19ad0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ip6fw.sys : 36,608 : 04/13/2008 02:53 PM : 3bb22519a194418d5fec05d800a19ad0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ipfltdrv.sys : 32,896 : 08/10/2004 06:00 AM : 731f22ba402ee4b62748adaf6363c182 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\ipfltdrv.sys : 32,896 : 08/10/2004 06:00 AM : 731f22ba402ee4b62748adaf6363c182 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ipinip.sys : 20,864 : 04/13/2008 02:57 PM : b87ab476dcf76e72010632b5550955f5 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ipinip.sys : 20,992 : 08/10/2004 06:00 AM : e1ec7f5da720b640cd8fb8424f1b14bb [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ipinip.sys : 20,864 : 04/13/2008 02:57 PM : b87ab476dcf76e72010632b5550955f5 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ipinip.sys : 20,864 : 04/13/2008 02:57 PM : b87ab476dcf76e72010632b5550955f5 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ipnat.sys : 152,832 : 04/13/2008 02:57 PM : cc748ea12c6effde940ee98098bf96bb [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB886185\SP2QFE\ipnat.sys : 134,912 : 09/29/2004 06:31 PM : 5191673215c91ff13ceaa83ef8e9653f [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ipnat.sys : 134,912 : 09/29/2004 06:28 PM : e2168cbc7098ffe963c6f23f472a3593 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB886185$\ipnat.sys : 134,912 : 08/10/2004 06:00 AM : b5a8e215ac29d24d60b4d1250ef05ace [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ipnat.sys : 152,832 : 04/13/2008 02:57 PM : cc748ea12c6effde940ee98098bf96bb [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ipnat.sys : 152,832 : 04/13/2008 02:57 PM : cc748ea12c6effde940ee98098bf96bb [Pos Repl]

 * C:\WINDOWS\System32\drivers\ipsec.sys : 75,264 : 04/13/2008 03:19 PM : 23c74d75e36e7158768dd63d92789a91 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ipsec.sys : 74,752 : 08/10/2004 06:00 AM : 64537aa5c003a6afeee1df819062d0d1 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ipsec.sys : 75,264 : 04/13/2008 03:19 PM : 23c74d75e36e7158768dd63d92789a91 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ipsec.sys : 75,264 : 04/13/2008 03:19 PM : 23c74d75e36e7158768dd63d92789a91 [Pos Repl]

 * C:\WINDOWS\System32\drivers\irenum.sys : 11,264 : 04/13/2008 02:54 PM : c93c9ff7b04d772627a3646d89f7bf89 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\irenum.sys : 11,264 : 08/10/2004 06:00 AM : 50708daa1b1cbb7d6ac1cf8f56a24410 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\irenum.sys : 11,264 : 04/13/2008 02:54 PM : c93c9ff7b04d772627a3646d89f7bf89 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\irenum.sys : 11,264 : 04/13/2008 02:54 PM : c93c9ff7b04d772627a3646d89f7bf89 [Pos Repl]

 * C:\WINDOWS\System32\drivers\isapnp.sys : 37,248 : 04/13/2008 02:36 PM : 05a299ec56e52649b1cf2fc52d20f2d7 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\isapnp.sys : 35,840 : 08/17/2001 02:58 PM : e504f706ccb699c2596e9a3da1596e87 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\isapnp.sys : 37,248 : 04/13/2008 02:36 PM : 05a299ec56e52649b1cf2fc52d20f2d7 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\isapnp.sys : 37,248 : 04/13/2008 02:36 PM : 05a299ec56e52649b1cf2fc52d20f2d7 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\isapnp.sys : 35,840 : 08/17/2001 02:58 PM : e504f706ccb699c2596e9a3da1596e87 [Pos Repl]

* C:\WINDOWS\System32\drivers\kbdclass.sys : 24,576 : 04/13/2008 02:39 PM : 463c1ec80cd17420a542b7f36a36f128 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\kbdclass.sys : 24,576 : 08/03/2004 11:58 PM : ebdee8a2ee5393890a1acee971c4c246 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\kbdclass.sys : 24,576 : 04/13/2008 02:39 PM : 463c1ec80cd17420a542b7f36a36f128 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\kbdclass.sys : 24,576 : 04/13/2008 02:39 PM : 463c1ec80cd17420a542b7f36a36f128 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\kbdclass.sys : 24,576 : 04/13/2008 02:39 PM : 463c1ec80cd17420a542b7f36a36f128 [Pos Repl]

 * C:\WINDOWS\System32\drivers\kmixer.sys : 172,416 : 04/13/2008 02:45 PM : 692bcf44383d056aed41b045a323d378 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB920872\SP2QFE\kmixer.sys : 172,416 : 06/14/2006 04:50 AM : 8531438246ce9474e41ee1599904c0c7 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\kmixer.sys : 172,416 : 06/14/2006 04:47 AM : ba5deda4d934e6288c2f66caf58d2562 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB920872$\kmixer.sys : 171,776 : 08/04/2004 00:07 AM : d93cad07c5683db066b0b2d2d3790ead [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\kmixer.sys : 172,416 : 04/13/2008 02:45 PM : 692bcf44383d056aed41b045a323d378 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\kmixer.sys : 172,416 : 04/13/2008 02:45 PM : 692bcf44383d056aed41b045a323d378 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ksecdd.sys : 92,928 : 06/24/2009 07:18 AM : b467646c54cc746128904e1654c750c1 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB968389\SP3QFE\ksecdd.sys : 92,928 : 06/24/2009 06:28 AM : c6ebf1d6ad71df30db49b8d3287e1368 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ksecdd.sys : 92,032 : 08/10/2004 06:00 AM : eb7ffe87fd367ea8fca0506f74a87fbb [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB968389$\ksecdd.sys : 92,288 : 04/13/2008 02:31 PM : 1705745d900dabf2d89f90ebaddc7517 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ksecdd.sys : 92,288 : 04/13/2008 02:31 PM : 1705745d900dabf2d89f90ebaddc7517 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ksecdd.sys : 92,928 : 06/24/2009 07:18 AM : b467646c54cc746128904e1654c750c1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ks.sys : 141,056 : 04/13/2008 03:16 PM : 0753515f78df7f271a5e61c20bcd36a1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ks.sys : 140,928 : 08/10/2004 06:00 AM : b9540e258f952650de8dec68719a5c97 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ks.sys : 141,056 : 04/13/2008 03:16 PM : 0753515f78df7f271a5e61c20bcd36a1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ks.sys : 141,056 : 04/13/2008 03:16 PM : 0753515f78df7f271a5e61c20bcd36a1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\mcd.sys : 7,680 : 08/10/2004 06:00 AM : d1f8be91ed4ddb671d42e473e3fe71ab [NoSig]
 +-> C:\WINDOWS\system32\dllcache\mcd.sys : 7,680 : 08/10/2004 06:00 AM : d1f8be91ed4ddb671d42e473e3fe71ab [Pos Repl]

 * C:\WINDOWS\System32\drivers\mf.sys : 63,744 : 04/13/2008 02:36 PM : a7da20ab18a1bdae28b0f349e57da0d1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mf.sys : 63,744 : 08/10/2004 06:00 AM : 729d83e56c29c510258a6e9e79ffddc3 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mf.sys : 63,744 : 04/13/2008 02:36 PM : a7da20ab18a1bdae28b0f349e57da0d1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mf.sys : 63,744 : 04/13/2008 02:36 PM : a7da20ab18a1bdae28b0f349e57da0d1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\mnmdd.sys : 4,224 : 08/10/2004 06:00 AM : 4ae068242760a1fb6e1a44bf4e16afa6 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\mnmdd.sys : 4,224 : 08/10/2004 06:00 AM : 4ae068242760a1fb6e1a44bf4e16afa6 [Pos Repl]

 * C:\WINDOWS\System32\drivers\modem.sys : 30,080 : 04/13/2008 03:00 PM : dfcbad3cec1c5f964962ae10e0bcc8e1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\modem.sys : 30,080 : 08/10/2004 06:00 AM : 6fc6f9d7acc36dca9b914565a3aeda05 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\modem.sys : 30,080 : 04/13/2008 03:00 PM : dfcbad3cec1c5f964962ae10e0bcc8e1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\modem.sys : 30,080 : 04/13/2008 03:00 PM : dfcbad3cec1c5f964962ae10e0bcc8e1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\mouclass.sys : 23,040 : 04/13/2008 02:39 PM : 35c9e97194c8cfb8430125f8dbc34d04 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mouclass.sys : 23,040 : 08/03/2004 11:58 PM : 34e1f0031153e491910e12551400192c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mouclass.sys : 23,040 : 04/13/2008 02:39 PM : 35c9e97194c8cfb8430125f8dbc34d04 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mouclass.sys : 23,040 : 04/13/2008 02:39 PM : 35c9e97194c8cfb8430125f8dbc34d04 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0020\DriverFiles\i386\mouclass.sys : 23,040 : 04/13/2008 02:39 PM : 35c9e97194c8cfb8430125f8dbc34d04 [Pos Repl]

 * C:\WINDOWS\System32\drivers\mouhid.sys : 12,160 : 08/17/2001 01:48 PM : b1c303e17fb9d46e87a98e4ba6769685 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\mouhid.sys : 12,160 : 08/17/2001 01:48 PM : b1c303e17fb9d46e87a98e4ba6769685 [Pos Repl]

 * C:\WINDOWS\System32\drivers\mountmgr.sys : 42,368 : 04/13/2008 02:39 PM : a80b9a0bad1b73637dbcbba7df72d3fd [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mountmgr.sys : 42,240 : 08/10/2004 06:00 AM : 65653f3b4477f3c63e68a9659f85ee2e [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mountmgr.sys : 42,368 : 04/13/2008 02:39 PM : a80b9a0bad1b73637dbcbba7df72d3fd [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mountmgr.sys : 42,368 : 04/13/2008 02:39 PM : a80b9a0bad1b73637dbcbba7df72d3fd [Pos Repl]

 * C:\WINDOWS\System32\drivers\mqac.sys : 92,544 : 04/13/2008 02:39 PM : 70c14f5cca5cf73f8a645c73a01d8726 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB937894\SP2QFE\mqac.sys : 72,960 : 07/06/2007 05:52 AM : d92fce6729ee150a15a7cdbc433f390e [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mqac.sys : 72,960 : 07/06/2007 06:05 AM : 157a32ddc6a019a4e31b19d604d2f127 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB937894$\mqac.sys : 72,960 : 08/10/2004 06:00 AM : db07b0088cdfd20c2a22e675120ede34 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mqac.sys : 92,544 : 04/13/2008 02:39 PM : 70c14f5cca5cf73f8a645c73a01d8726 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mqac.sys : 92,544 : 04/13/2008 02:39 PM : 70c14f5cca5cf73f8a645c73a01d8726 [Pos Repl]

 * C:\WINDOWS\System32\drivers\mrxdav.sys : 180,608 : 04/13/2008 02:32 PM : 11d42bb6206f33fbb3ba0288d3ef81bd [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB946026\SP2QFE\mrxdav.sys : 179,712 : 12/18/2007 05:38 AM : 9921d9df98f266560ec28b3bdb580180 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mrxdav.sys : 179,584 : 12/18/2007 05:51 AM : 29414447eb5bde2f8397dc965dbb3156 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB946026$\mrxdav.sys : 181,248 : 08/10/2004 06:00 AM : 46edcc8f2db2f322c24f48785cb46366 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mrxdav.sys : 180,608 : 04/13/2008 02:32 PM : 11d42bb6206f33fbb3ba0288d3ef81bd [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mrxdav.sys : 180,608 : 04/13/2008 02:32 PM : 11d42bb6206f33fbb3ba0288d3ef81bd [Pos Repl]

 * C:\WINDOWS\System32\drivers\mrxsmb.sys : 456,320 : 07/15/2011 09:29 AM : 7d304a5eb4344ebeeab53a2fe3ffb9f0 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2511455\SP3QFE\mrxsmb.sys : 457,472 : 02/17/2011 09:19 AM : fb7dfd15d760ad339837a470f0e780d3 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2536276\SP3QFE\mrxsmb.sys : 457,856 : 04/29/2011 12:47 AM : 8dd801e28eb76fda2a38907882a0036f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2536276-v2\SP3QFE\mrxsmb.sys : 457,856 : 07/15/2011 09:29 AM : fb2fccc70f7174c7bf64f48e96d3adf4 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB885250\SP2QFE\mrxsmb.sys : 451,584 : 01/18/2005 11:51 PM : 7b195060ff456fa65954c72c5c1640ff [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB885835\SP2QFE\mrxsmb.sys : 448,128 : 10/27/2004 09:15 PM : a1be3cb080dcc0a8270d21e3ca3b7005 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB914389\SP2QFE\mrxsmb.sys : 454,400 : 05/05/2006 06:16 AM : 7412ce77c6fd823f8889b4df420c680b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB957097\SP3QFE\mrxsmb.sys : 455,936 : 10/24/2008 07:41 AM : 7170ab42b51954def2781a4d1cce65f4 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB978251\SP3QFE\mrxsmb.sys : 456,832 : 12/04/2009 01:25 PM : 602549d1e8a622e5746991f6c56b21ca [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB980232\SP3QFE\mrxsmb.sys : 457,216 : 02/24/2010 07:57 AM : d09b9f0b9960dd41e73127b7814c115f [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mrxsmb.sys : 453,120 : 05/05/2006 05:41 AM : 025af03ce51645c62f3b6907a7e2be5e [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2511455$\mrxsmb.sys : 455,680 : 02/24/2010 09:11 AM : f3aefb11abc521122b67095044169e98 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2536276$\mrxsmb.sys : 455,936 : 02/17/2011 09:18 AM : 0ea4d8ed179b75f8afa7998ba22285ca [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2536276-v2$\mrxsmb.sys : 456,320 : 04/29/2011 12:19 AM : 0dc719e9b15e902346e87e9dcd5751fa [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB914389$\mrxsmb.sys : 451,584 : 01/19/2005 00:26 AM : 5ddc9a1b2eb5a4bf010ce8c019a18c1f [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB957097$\mrxsmb.sys : 456,576 : 04/13/2008 03:17 PM : 68755f0ff16070178b54674fe5b847b0 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB978251$\mrxsmb.sys : 455,296 : 10/24/2008 07:21 AM : 60ae98742484e7ab80c3c1450e708148 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB980232$\mrxsmb.sys : 455,424 : 12/04/2009 02:22 PM : 421f7b922cec5a5f340e7574a98f7b7c [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\mrxsmb.sys : 456,320 : 07/15/2011 09:29 AM : 7d304a5eb4344ebeeab53a2fe3ffb9f0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mrxsmb.sys : 456,576 : 04/13/2008 03:17 PM : 68755f0ff16070178b54674fe5b847b0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mrxsmb.sys : 456,320 : 07/15/2011 09:29 AM : 7d304a5eb4344ebeeab53a2fe3ffb9f0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\msfs.sys : 19,072 : 04/13/2008 02:32 PM : c941ea2454ba8350021d774daf0f1027 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\msfs.sys : 19,072 : 08/10/2004 06:00 AM : 561b3a4333ca2dbdba28b5b956822519 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\msfs.sys : 19,072 : 04/13/2008 02:32 PM : c941ea2454ba8350021d774daf0f1027 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\msfs.sys : 19,072 : 04/13/2008 02:32 PM : c941ea2454ba8350021d774daf0f1027 [Pos Repl]

 * C:\WINDOWS\System32\drivers\msgpc.sys : 35,072 : 04/13/2008 02:56 PM : 0a02c63c8b144bd8c86b103dee7c86a2 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\msgpc.sys : 35,072 : 08/10/2004 06:00 AM : c0f1d4a21de5a415df8170616703debf [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\msgpc.sys : 35,072 : 04/13/2008 02:56 PM : 0a02c63c8b144bd8c86b103dee7c86a2 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\msgpc.sys : 35,072 : 04/13/2008 02:56 PM : 0a02c63c8b144bd8c86b103dee7c86a2 [Pos Repl]

 * C:\WINDOWS\System32\drivers\MSKSSRV.sys : 7,552 : 04/13/2008 02:39 PM : d1575e71568f4d9e14ca56b7b0453bf1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mskssrv.sys : 7,552 : 08/03/2004 11:58 PM : ae431a8dd3c1d0d0610cdbac16057ad0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mskssrv.sys : 7,552 : 04/13/2008 02:39 PM : d1575e71568f4d9e14ca56b7b0453bf1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mskssrv.sys : 7,552 : 04/13/2008 02:39 PM : d1575e71568f4d9e14ca56b7b0453bf1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\MSPCLOCK.sys : 5,376 : 04/13/2008 02:39 PM : 325bb26842fc7ccc1fcce2c457317f3e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mspclock.sys : 5,376 : 08/03/2004 11:58 PM : 13e75fef9dfeb08eeded9d0246e1f448 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mspclock.sys : 5,376 : 04/13/2008 02:39 PM : 325bb26842fc7ccc1fcce2c457317f3e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mspclock.sys : 5,376 : 04/13/2008 02:39 PM : 325bb26842fc7ccc1fcce2c457317f3e [Pos Repl]

 * C:\WINDOWS\System32\drivers\MSPQM.sys : 4,992 : 04/13/2008 02:39 PM : bad59648ba099da4a17680b39730cb3d [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mspqm.sys : 4,992 : 08/03/2004 11:58 PM : 1988a33ff19242576c3d0ef9ce785da7 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mspqm.sys : 4,992 : 04/13/2008 02:39 PM : bad59648ba099da4a17680b39730cb3d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mspqm.sys : 4,992 : 04/13/2008 02:39 PM : bad59648ba099da4a17680b39730cb3d [Pos Repl]

 * C:\WINDOWS\System32\drivers\mssmbios.sys : 15,488 : 04/13/2008 02:36 PM : af5f4f3f14a8ea2c26de30f7a1e17136 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mssmbios.sys : 15,488 : 08/04/2004 00:07 AM : 469541f8bfd2b32659d5d463a6714bce [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mssmbios.sys : 15,488 : 04/13/2008 02:36 PM : af5f4f3f14a8ea2c26de30f7a1e17136 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mssmbios.sys : 15,488 : 04/13/2008 02:36 PM : af5f4f3f14a8ea2c26de30f7a1e17136 [Pos Repl]

 * C:\WINDOWS\System32\drivers\mup.sys : 105,472 : 04/21/2011 09:37 AM : de6a75f5c270e756c5508d94b6cf68f5 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2535512\SP3QFE\mup.sys : 105,472 : 04/21/2011 09:52 AM : f7b1ad991491f02af6da70b00b8bf114 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\mup.sys : 107,904 : 08/10/2004 06:00 AM : 82035e0f41c2dd05ae41d27fe6cf7de1 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2535512$\mup.sys : 105,344 : 04/13/2008 03:17 PM : 2f625d11385b1a94360bfc70aaefdee1 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\mup.sys : 105,344 : 04/13/2008 03:17 PM : 2f625d11385b1a94360bfc70aaefdee1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\mup.sys : 105,472 : 04/21/2011 09:37 AM : de6a75f5c270e756c5508d94b6cf68f5 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ndis.sys : 182,656 : 04/13/2008 03:20 PM : 1df7f42665c94b825322fae71721130d [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ndis.sys : 182,912 : 08/10/2004 06:00 AM : 558635d3af1c7546d26067d5d9b6959e [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ndis.sys : 182,656 : 04/13/2008 03:20 PM : 1df7f42665c94b825322fae71721130d [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ndis.sys : 182,656 : 04/13/2008 03:20 PM : 1df7f42665c94b825322fae71721130d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ndis.sys : 182,656 : 04/13/2008 03:20 PM : 1df7f42665c94b825322fae71721130d [Pos Repl]

 * C:\WINDOWS\System32\drivers\ndistapi.sys : 10,496 : 07/08/2011 10:02 AM : 0109c4f3850dfbab279542515386ae22 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2566454\SP3QFE\ndistapi.sys : 10,496 : 07/08/2011 09:51 AM : 091735a5f20acb1dc147383a905ae002 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ndistapi.sys : 9,600 : 08/10/2004 06:00 AM : 08d43bbdacdf23f34d79e44ed35c1b4c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2566454$\ndistapi.sys : 10,112 : 04/13/2008 02:57 PM : 1ab3d00c991ab086e69db84b6c0ed78f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ndistapi.sys : 10,112 : 04/13/2008 02:57 PM : 1ab3d00c991ab086e69db84b6c0ed78f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ndistapi.sys : 10,496 : 07/08/2011 10:02 AM : 0109c4f3850dfbab279542515386ae22 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ndisuio.sys : 14,592 : 04/13/2008 02:55 PM : f927a4434c5028758a842943ef1a3849 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ndisuio.sys : 14,592 : 06/20/2005 02:52 PM : eefa1ce63805d2145978621be5c6d955 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB899337$\ndisuio.sys : 12,928 : 08/10/2004 06:00 AM : 34d6cd56409da9a7ed573e1c90a308bf [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ndisuio.sys : 14,592 : 04/13/2008 02:55 PM : f927a4434c5028758a842943ef1a3849 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ndisuio.sys : 14,592 : 04/13/2008 02:55 PM : f927a4434c5028758a842943ef1a3849 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ndiswan.sys : 91,520 : 04/13/2008 03:20 PM : edc1531a49c80614b2cfda43ca8659ab [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ndiswan.sys : 91,776 : 08/10/2004 06:00 AM : 0b90e255a9490166ab368cd55a529893 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ndiswan.sys : 91,520 : 04/13/2008 03:20 PM : edc1531a49c80614b2cfda43ca8659ab [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ndiswan.sys : 91,520 : 04/13/2008 03:20 PM : edc1531a49c80614b2cfda43ca8659ab [Pos Repl]

 * C:\WINDOWS\System32\drivers\ndproxy.sys : 40,960 : 11/27/2013 04:21 PM : 2f597bb467e05b1fe3830eabd821b8e0 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2440591\SP3QFE\ndproxy.sys : 40,960 : 11/03/2010 01:55 AM : 816460bd4b4acd27937d1d0813e2e9e9 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ndproxy.sys : 38,016 : 08/10/2004 06:00 AM : 59fc3fb44d2669bc144fd87826bb571f [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2440591$\ndproxy.sys : 40,576 : 04/13/2008 02:57 PM : 6215023940cfd3702b46abc304e1d45a [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2914368$\ndproxy.sys : 40,960 : 11/02/2010 11:17 AM : 9282bd12dfb069d3889eb3fcc1000a9b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ndproxy.sys : 40,576 : 04/13/2008 02:57 PM : 6215023940cfd3702b46abc304e1d45a [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ndproxy.sys : 40,960 : 11/27/2013 04:21 PM : 2f597bb467e05b1fe3830eabd821b8e0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\netbios.sys : 34,688 : 04/13/2008 02:56 PM : 5d81cf9a2f1a3a756b66cf684911cdf0 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\netbios.sys : 34,560 : 08/10/2004 06:00 AM : 3a2aca8fc1d7786902ca434998d7ceb4 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\netbios.sys : 34,688 : 04/13/2008 02:56 PM : 5d81cf9a2f1a3a756b66cf684911cdf0 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\netbios.sys : 34,688 : 04/13/2008 02:56 PM : 5d81cf9a2f1a3a756b66cf684911cdf0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\netbt.sys : 162,816 : 04/13/2008 03:21 PM : 74b2b2f5bea5e9a3dc021d685551bd3d [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\netbt.sys : 162,816 : 08/10/2004 06:00 AM : 0c80e410cd2f47134407ee7dd19cc86b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\netbt.sys : 162,816 : 04/13/2008 03:21 PM : 74b2b2f5bea5e9a3dc021d685551bd3d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\netbt.sys : 162,816 : 04/13/2008 03:21 PM : 74b2b2f5bea5e9a3dc021d685551bd3d [Pos Repl]

 * C:\WINDOWS\System32\drivers\nic1394.sys : 61,824 : 04/13/2008 02:51 PM : e9e47cfb2d461fa0fc75b7a74c6383ea [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\nic1394.sys : 61,824 : 08/10/2004 06:00 AM : 5c5c53db4fef16cf87b9911c7e8c6fbc [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\nic1394.sys : 61,824 : 04/13/2008 02:51 PM : e9e47cfb2d461fa0fc75b7a74c6383ea [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\nic1394.sys : 61,824 : 04/13/2008 02:51 PM : e9e47cfb2d461fa0fc75b7a74c6383ea [Pos Repl]

 * C:\WINDOWS\System32\drivers\nikedrv.sys : 12,032 : 08/10/2004 06:00 AM : be984d604d91c217355cdd3737aad25d [NoSig]
 +-> C:\WINDOWS\system32\dllcache\nikedrv.sys : 12,032 : 08/10/2004 06:00 AM : be984d604d91c217355cdd3737aad25d [Pos Repl]

 * C:\WINDOWS\System32\drivers\nmnt.sys : 40,320 : 04/13/2008 02:53 PM : 1e421a6bcf2203cc61b821ada9de878b [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\nmnt.sys : 40,320 : 08/10/2004 06:00 AM : 60cf8c7192b3614f240838ddbaa4a245 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\nmnt.sys : 40,320 : 04/13/2008 02:53 PM : 1e421a6bcf2203cc61b821ada9de878b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\nmnt.sys : 40,320 : 04/13/2008 02:53 PM : 1e421a6bcf2203cc61b821ada9de878b [Pos Repl]

 * C:\WINDOWS\System32\drivers\npfs.sys : 30,848 : 04/13/2008 02:32 PM : 3182d64ae053d6fb034f44b6def8034a [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\npfs.sys : 30,848 : 08/10/2004 06:00 AM : 4f601bcb8f64ea3ac0994f98fed03f8e [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\npfs.sys : 30,848 : 04/13/2008 02:32 PM : 3182d64ae053d6fb034f44b6def8034a [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\npfs.sys : 30,848 : 04/13/2008 02:32 PM : 3182d64ae053d6fb034f44b6def8034a [Pos Repl]

 * C:\WINDOWS\System32\drivers\ntfs.sys : 574,976 : 04/13/2008 03:15 PM : 78a08dd6a8d65e697c18e1db01c5cdca [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB930916\SP2QFE\ntfs.sys : 574,976 : 02/09/2007 07:23 AM : 05ab81909514bfd69cbb1f2c147cf6b9 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\ntfs.sys : 574,464 : 02/09/2007 07:10 AM : 19a811ef5f1ed5c926a028ce107ff1af [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB930916$\ntfs.sys : 574,592 : 08/10/2004 06:00 AM : b78be402c3f63dd55521f73876951cdd [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\ntfs.sys : 574,976 : 04/13/2008 03:15 PM : 78a08dd6a8d65e697c18e1db01c5cdca [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\ntfs.sys : 574,976 : 04/13/2008 03:15 PM : 78a08dd6a8d65e697c18e1db01c5cdca [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\ntfs.sys : 574,976 : 04/13/2008 03:15 PM : 78a08dd6a8d65e697c18e1db01c5cdca [Pos Repl]

 * C:\WINDOWS\System32\drivers\null.sys : 2,944 : 08/10/2004 06:00 AM : 73c1e1f395918bc2c6dd67af7591a3ad [NoSig]
 +-> C:\WINDOWS\ERDNT\cache\null.sys : 2,944 : 08/10/2004 06:00 AM : 73c1e1f395918bc2c6dd67af7591a3ad [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\null.sys : 2,944 : 08/10/2004 06:00 AM : 73c1e1f395918bc2c6dd67af7591a3ad [Pos Repl]

 * C:\WINDOWS\System32\drivers\nwlnkflt.sys : 12,416 : 08/10/2004 06:00 AM : b305f3fad35083837ef46a0bbce2fc57 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\nwlnkflt.sys : 12,416 : 08/10/2004 06:00 AM : b305f3fad35083837ef46a0bbce2fc57 [Pos Repl]

 * C:\WINDOWS\System32\drivers\nwlnkfwd.sys : 32,512 : 08/10/2004 06:00 AM : c99b3415198d1aab7227f2c88fd664b9 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\nwlnkfwd.sys : 32,512 : 08/10/2004 06:00 AM : c99b3415198d1aab7227f2c88fd664b9 [Pos Repl]

 * C:\WINDOWS\System32\drivers\nwlnkipx.sys : 88,320 : 04/13/2008 02:56 PM : 8b8b1be2dba4025da6786c645f77f123 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\nwlnkipx.sys : 88,448 : 08/10/2004 06:00 AM : 79ea3fcda7067977625b3363a2657c80 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\nwlnkipx.sys : 88,320 : 04/13/2008 02:56 PM : 8b8b1be2dba4025da6786c645f77f123 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\nwlnkipx.sys : 88,320 : 04/13/2008 02:56 PM : 8b8b1be2dba4025da6786c645f77f123 [Pos Repl]

 * C:\WINDOWS\System32\drivers\nwlnknb.sys : 63,232 : 08/10/2004 06:00 AM : 56d34a67c05e94e16377c60609741ff8 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\nwlnknb.sys : 63,232 : 08/10/2004 06:00 AM : 56d34a67c05e94e16377c60609741ff8 [Pos Repl]

 * C:\WINDOWS\System32\drivers\nwlnkspx.sys : 55,936 : 08/10/2004 06:00 AM : c0bb7d1615e1acbdc99757f6ceaf8cf0 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\nwlnkspx.sys : 55,936 : 08/10/2004 06:00 AM : c0bb7d1615e1acbdc99757f6ceaf8cf0 [Pos Repl]

 * C:\WINDOWS\System32\drivers\nwrdr.sys : 163,584 : 04/13/2008 02:34 PM : 36b9b950e3d2e100970a48d8bad86740 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB923980\SP2QFE\nwrdr.sys : 163,456 : 10/13/2006 06:39 AM : bbbc2e555bb5e4adbaeb1447f11c68c9 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\nwrdr.sys : 163,584 : 10/13/2006 06:23 AM : 3f18d9365be71c7b2e43b7cf4a0c1a10 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB923980$\nwrdr.sys : 163,584 : 08/10/2004 06:00 AM : 03373a79440473062c6f3aedec6a49c8 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\nwrdr.sys : 163,584 : 04/13/2008 02:34 PM : 36b9b950e3d2e100970a48d8bad86740 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\nwrdr.sys : 163,584 : 04/13/2008 02:34 PM : 36b9b950e3d2e100970a48d8bad86740 [Pos Repl]

 * C:\WINDOWS\System32\drivers\oprghdlr.sys : 3,456 : 08/10/2004 06:00 AM : 4bb30ddc53ebc76895e38694580cdfe9 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\oprghdlr.sys : 3,456 : 08/10/2004 06:00 AM : 4bb30ddc53ebc76895e38694580cdfe9 [Pos Repl]

 * C:\WINDOWS\System32\drivers\p3.sys : 42,752 : 04/13/2008 02:31 PM : c90018bafdc7098619a4a95b046b30f3 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\p3.sys : 42,496 : 08/10/2004 06:00 AM : 3e16eff2a6fed2d8d7f5a66dfe65d183 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\p3.sys : 42,752 : 04/13/2008 02:31 PM : c90018bafdc7098619a4a95b046b30f3 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\p3.sys : 42,752 : 04/13/2008 02:31 PM : c90018bafdc7098619a4a95b046b30f3 [Pos Repl]

 * C:\WINDOWS\System32\drivers\parport.sys : 80,128 : 04/13/2008 02:40 PM : 5575faf8f97ce5e713d108c2a58d7c7c [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\parport.sys : 80,128 : 08/10/2004 06:00 AM : 29744eb4ce659dfe3b4122deb45bc478 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\parport.sys : 80,128 : 04/13/2008 02:40 PM : 5575faf8f97ce5e713d108c2a58d7c7c [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\parport.sys : 80,128 : 04/13/2008 02:40 PM : 5575faf8f97ce5e713d108c2a58d7c7c [Pos Repl]

 * C:\WINDOWS\System32\drivers\partmgr.sys : 19,712 : 04/13/2008 02:40 PM : beb3ba25197665d82ec7065b724171c6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\partmgr.sys : 18,688 : 08/10/2004 06:00 AM : 3334430c29dc338092f79c38ef7b4cd0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\partmgr.sys : 19,712 : 04/13/2008 02:40 PM : beb3ba25197665d82ec7065b724171c6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\partmgr.sys : 19,712 : 04/13/2008 02:40 PM : beb3ba25197665d82ec7065b724171c6 [Pos Repl]

 * C:\WINDOWS\System32\drivers\parvdm.sys : 6,784 : 08/10/2004 06:00 AM : 70e98b3fd8e963a6a46a2e6247e0bea1 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\parvdm.sys : 6,784 : 08/10/2004 06:00 AM : 70e98b3fd8e963a6a46a2e6247e0bea1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\pciidex.sys : 24,960 : 04/13/2008 02:40 PM : 52e60f29221d0d1ac16737e8dbf7c3e9 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\pciidex.sys : 25,088 : 08/03/2004 11:59 PM : 520b91ab011456b940d9b05fc91108ff [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\pciidex.sys : 24,960 : 04/13/2008 02:40 PM : 52e60f29221d0d1ac16737e8dbf7c3e9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\pciidex.sys : 24,960 : 04/13/2008 02:40 PM : 52e60f29221d0d1ac16737e8dbf7c3e9 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\pciidex.sys : 25,088 : 08/03/2004 11:59 PM : 520b91ab011456b940d9b05fc91108ff [Pos Repl]

 * C:\WINDOWS\System32\drivers\pci.sys : 68,224 : 04/13/2008 02:36 PM : a219903ccf74233761d92bef471a07b1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\pci.sys : 68,224 : 08/04/2004 00:07 AM : 8086d9979234b603ad5bc2f5d890b234 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\pci.sys : 68,224 : 04/13/2008 02:36 PM : a219903ccf74233761d92bef471a07b1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\pci.sys : 68,224 : 04/13/2008 02:36 PM : a219903ccf74233761d92bef471a07b1 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0000\DriverFiles\i386\pci.sys : 68,224 : 08/04/2004 00:07 AM : 8086d9979234b603ad5bc2f5d890b234 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0009\DriverFiles\i386\pci.sys : 68,224 : 08/04/2004 00:07 AM : 8086d9979234b603ad5bc2f5d890b234 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\i386\pci.sys : 68,224 : 08/04/2004 00:07 AM : 8086d9979234b603ad5bc2f5d890b234 [Pos Repl]

 * C:\WINDOWS\System32\drivers\pcmcia.sys : 120,192 : 04/13/2008 02:36 PM : 9e89ef60e9ee05e3f2eef2da7397f1c1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\pcmcia.sys : 119,936 : 08/10/2004 06:00 AM : 82a087207decec8456fbe8537947d579 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\pcmcia.sys : 120,192 : 04/13/2008 02:36 PM : 9e89ef60e9ee05e3f2eef2da7397f1c1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\pcmcia.sys : 120,192 : 04/13/2008 02:36 PM : 9e89ef60e9ee05e3f2eef2da7397f1c1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\portcls.sys : 146,048 : 04/13/2008 03:19 PM : e82a496c3961efc6828b508c310ce98f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\portcls.sys : 136,960 : 03/16/2004 12:58 AM : bc6b2bc69c1e009443e8b1fe2db96101 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\portcls.sys : 146,048 : 04/13/2008 03:19 PM : e82a496c3961efc6828b508c310ce98f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\portcls.sys : 146,048 : 04/13/2008 03:19 PM : e82a496c3961efc6828b508c310ce98f [Pos Repl]

 * C:\WINDOWS\System32\drivers\processr.sys : 35,840 : 04/13/2008 02:31 PM : a32bebaf723557681bfc6bd93e98bd26 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\processr.sys : 35,328 : 08/10/2004 06:00 AM : 0d97d88720a4087ec93af7dbb303b30a [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\processr.sys : 35,840 : 04/13/2008 02:31 PM : a32bebaf723557681bfc6bd93e98bd26 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\processr.sys : 35,840 : 04/13/2008 02:31 PM : a32bebaf723557681bfc6bd93e98bd26 [Pos Repl]

 * C:\WINDOWS\System32\drivers\psched.sys : 69,120 : 04/13/2008 02:56 PM : 09298ec810b07e5d582cb3a3f9255424 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\psched.sys : 69,120 : 08/10/2004 06:00 AM : 48671f327553dcf1d27f6197f622a668 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\psched.sys : 69,120 : 04/13/2008 02:56 PM : 09298ec810b07e5d582cb3a3f9255424 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\psched.sys : 69,120 : 04/13/2008 02:56 PM : 09298ec810b07e5d582cb3a3f9255424 [Pos Repl]

 * C:\WINDOWS\System32\drivers\ptilink.sys : 17,792 : 08/10/2004 06:00 AM : 80d317bd1c3dbc5d4fe7b1678c60cadd [NoSig]
 +-> C:\WINDOWS\system32\dllcache\ptilink.sys : 17,792 : 08/10/2004 06:00 AM : 80d317bd1c3dbc5d4fe7b1678c60cadd [Pos Repl]

 * C:\WINDOWS\System32\drivers\rasacd.sys : 8,832 : 08/10/2004 06:00 AM : fe0d99d6f31e4fad8159f690d68ded9c [NoSig]
 +-> C:\WINDOWS\system32\dllcache\rasacd.sys : 8,832 : 08/10/2004 06:00 AM : fe0d99d6f31e4fad8159f690d68ded9c [Pos Repl]

 * C:\WINDOWS\System32\drivers\rasl2tp.sys : 51,328 : 04/13/2008 03:19 PM : 11b4a627bc9614b885c4969bfa5ff8a6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rasl2tp.sys : 51,328 : 08/10/2004 06:00 AM : 98faeb4a4dcf812ba1c6fca4aa3e115c [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rasl2tp.sys : 51,328 : 04/13/2008 03:19 PM : 11b4a627bc9614b885c4969bfa5ff8a6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rasl2tp.sys : 51,328 : 04/13/2008 03:19 PM : 11b4a627bc9614b885c4969bfa5ff8a6 [Pos Repl]

 * C:\WINDOWS\System32\drivers\raspppoe.sys : 41,472 : 04/13/2008 02:57 PM : 5bc962f2654137c9909c3d4603587dee [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\raspppoe.sys : 41,472 : 08/10/2004 06:00 AM : 7306eeed8895454cbed4669be9f79faa [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\raspppoe.sys : 41,472 : 04/13/2008 02:57 PM : 5bc962f2654137c9909c3d4603587dee [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\raspppoe.sys : 41,472 : 04/13/2008 02:57 PM : 5bc962f2654137c9909c3d4603587dee [Pos Repl]

 * C:\WINDOWS\System32\drivers\raspptp.sys : 48,384 : 04/13/2008 03:19 PM : efeec01b1d3cf84f16ddd24d9d9d8f99 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\raspptp.sys : 48,384 : 08/10/2004 06:00 AM : 1c5cc65aac0783c344f16353e60b72ac [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\raspptp.sys : 48,384 : 04/13/2008 03:19 PM : efeec01b1d3cf84f16ddd24d9d9d8f99 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\raspptp.sys : 48,384 : 04/13/2008 03:19 PM : efeec01b1d3cf84f16ddd24d9d9d8f99 [Pos Repl]

 * C:\WINDOWS\System32\drivers\raspti.sys : 16,512 : 08/10/2004 06:00 AM : fdbb1d60066fcfbb7452fd8f9829b242 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\raspti.sys : 16,512 : 08/10/2004 06:00 AM : fdbb1d60066fcfbb7452fd8f9829b242 [Pos Repl]

 * C:\WINDOWS\System32\drivers\rawwan.sys : 34,432 : 08/10/2004 06:00 AM : 01524cd237223b18adbb48f70083f101 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\rawwan.sys : 34,432 : 08/10/2004 06:00 AM : 01524cd237223b18adbb48f70083f101 [Pos Repl]

 * C:\WINDOWS\System32\drivers\rdbss.sys : 175,744 : 04/13/2008 03:28 PM : 7ad224ad1a1437fe28d89cf22b17780a [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB885835\SP2QFE\rdbss.sys : 174,592 : 10/27/2004 09:14 PM : d0fef8156d2d2fec557c100956d76887 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB914389\SP2QFE\rdbss.sys : 174,592 : 05/05/2006 06:22 AM : ed375ce745c42a14f10753f7022ecd6a [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rdbss.sys : 174,592 : 05/05/2006 05:47 AM : 03b965b1ca47f6ef60eb5e51cb50e0af [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB914389$\rdbss.sys : 174,592 : 10/27/2004 09:13 PM : 809ca45caa9072b3176ad44579d7f688 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rdbss.sys : 175,744 : 04/13/2008 03:28 PM : 7ad224ad1a1437fe28d89cf22b17780a [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rdbss.sys : 175,744 : 04/13/2008 03:28 PM : 7ad224ad1a1437fe28d89cf22b17780a [Pos Repl]

 * C:\WINDOWS\System32\drivers\rdpcdd.sys : 4,224 : 08/10/2004 06:00 AM : 4912d5b403614ce99c28420f75353332 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\rdpcdd.sys : 4,224 : 08/10/2004 06:00 AM : 4912d5b403614ce99c28420f75353332 [Pos Repl]

 * C:\WINDOWS\System32\drivers\rdpdr.sys : 196,224 : 04/13/2008 02:32 PM : 15cabd0f7c00c47c70124907916af3f1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rdpdr.sys : 196,864 : 08/04/2004 00:01 AM : a2cae2c60bc37e0751ef9dda7ceaf4ad [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rdpdr.sys : 196,224 : 04/13/2008 02:32 PM : 15cabd0f7c00c47c70124907916af3f1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rdpdr.sys : 196,224 : 04/13/2008 02:32 PM : 15cabd0f7c00c47c70124907916af3f1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\rdpwd.sys : 139,784 : 07/04/2012 10:05 AM : 43af5212bd8fb5ba6eed9754358bd8f7 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2570222\SP3QFE\rdpwd.sys : 139,656 : 06/24/2011 10:09 AM : 3348e61a78ba4f79c795aad6565d3b6f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2621440\SP3QFE\rdpwd.sys : 139,784 : 01/09/2012 12:19 AM : 2d293b720c206473a05950ce007db12a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2685939\SP3QFE\rdpwd.sys : 139,656 : 05/02/2012 09:45 AM : 997c59b9955f911ec460241dd9e01b04 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2723135\SP3QFE\rdpwd.sys : 139,784 : 07/04/2012 09:59 AM : c7d9bc54354b8c706abf172d48313f1b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB899591\SP2QFE\rdpwd.sys : 139,528 : 06/10/2005 00:06 AM : 047bea21274c8a4a233674a76c958c2c [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rdpwd.sys : 139,528 : 06/10/2005 00:09 AM : b54cd38a9ebfbf2b3561426e3fe26f62 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2570222$\rdpwd.sys : 139,656 : 04/13/2008 08:13 PM : 6728e45b66f93c08f11de2e316fc70dd [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2621440$\rdpwd.sys : 139,656 : 06/24/2011 10:10 AM : fc105dd312ed64eb66bff111e8ec6eac [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2685939$\rdpwd.sys : 139,784 : 01/09/2012 12:20 AM : 5b3055daa788bd688594d2f5981f2a83 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2723135$\rdpwd.sys : 139,656 : 05/02/2012 09:46 AM : 6589db6e5969f8eee594cf71171c5028 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rdpwd.sys : 139,656 : 04/13/2008 08:13 PM : 6728e45b66f93c08f11de2e316fc70dd [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rdpwd.sys : 139,784 : 07/04/2012 10:05 AM : 43af5212bd8fb5ba6eed9754358bd8f7 [Pos Repl]

 * C:\WINDOWS\System32\drivers\redbook.sys : 57,600 : 04/13/2008 02:40 PM : f828dd7e1419b6653894a8f97a0094c5 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\redbook.sys : 57,472 : 08/03/2004 11:59 PM : b31b4588e4086d8d84adbf9845c2402b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\redbook.sys : 57,600 : 04/13/2008 02:40 PM : f828dd7e1419b6653894a8f97a0094c5 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\redbook.sys : 57,600 : 04/13/2008 02:40 PM : f828dd7e1419b6653894a8f97a0094c5 [Pos Repl]

 * C:\WINDOWS\System32\drivers\rmcast.sys : 203,136 : 05/08/2008 10:02 AM : 96f7a9a7bf0c9c0440a967440065d33c [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB919007\SP2QFE\rmcast.sys : 202,496 : 07/13/2006 07:43 AM : bcea2b2bf1b6dddd11e65b7478f2d19a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB950762\SP2QFE\rmcast.sys : 203,008 : 05/08/2008 08:14 AM : b1f077190ba1cfa0a2a2afae9e7fde2b [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB950762\SP3GDR\rmcast.sys : 203,136 : 05/08/2008 10:02 AM : 96f7a9a7bf0c9c0440a967440065d33c [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB950762\SP3QFE\rmcast.sys : 203,136 : 05/08/2008 09:58 AM : c711645c76b8ed87c021bf6165e52795 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rmcast.sys : 202,752 : 05/08/2008 08:28 AM : d18208ed6c768663b08c972eaa7a8b60 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB919007$\rmcast.sys : 200,064 : 08/10/2004 06:00 AM : 35e81b908ae4e97fc7bdf4607c516ff4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB950762$\rmcast.sys : 202,624 : 04/13/2008 02:55 PM : ecff394d65671efde5a872eb9ef4f2d5 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB950762_0$\rmcast.sys : 202,240 : 07/13/2006 04:48 AM : 9d54c7c15847b933e03d6e7c9307bae5 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rmcast.sys : 202,624 : 04/13/2008 02:55 PM : ecff394d65671efde5a872eb9ef4f2d5 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rmcast.sys : 203,136 : 05/08/2008 10:02 AM : 96f7a9a7bf0c9c0440a967440065d33c [Pos Repl]

 * C:\WINDOWS\System32\drivers\rndismp.sys : 30,592 : 04/13/2008 02:56 PM : 601844cbcf617ff8c868130ca5b2039d [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\rndismp.sys : 30,464 : 11/30/2004 07:28 PM : b09d11d33c4a29857ac75f3148684890 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB890927$\rndismp.sys : 30,080 : 08/10/2004 06:00 AM : 7ce8b277f3207ea82d7d22ad348befc6 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\rndismp.sys : 30,592 : 04/13/2008 02:56 PM : 601844cbcf617ff8c868130ca5b2039d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\rndismp.sys : 30,592 : 04/13/2008 02:56 PM : 601844cbcf617ff8c868130ca5b2039d [Pos Repl]

 * C:\WINDOWS\System32\drivers\rootmdm.sys : 5,888 : 08/10/2004 06:00 AM : d8b0b4ade32574b2d9c5cc34dc0dbbe7 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\rootmdm.sys : 5,888 : 08/10/2004 06:00 AM : d8b0b4ade32574b2d9c5cc34dc0dbbe7 [Pos Repl]

 * C:\WINDOWS\System32\drivers\scsiport.sys : 96,384 : 04/13/2008 02:40 PM : 76c465f570e90c28942d52ccb2580a10 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\scsiport.sys : 96,256 : 08/10/2004 06:00 AM : d7fd0ff761e28ac0ea35ad71e0cd67e9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\scsiport.sys : 96,384 : 04/13/2008 02:40 PM : 76c465f570e90c28942d52ccb2580a10 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\scsiport.sys : 96,384 : 04/13/2008 02:40 PM : 76c465f570e90c28942d52ccb2580a10 [Pos Repl]

Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #12 on: August 18, 2015, 05:27:09 AM »
Reply 4 of 5  -  (exceeded 65,000 characters) this portion only includes a portion of rkill.txt


 * C:\WINDOWS\System32\drivers\sdbus.sys : 79,232 : 04/13/2008 02:36 PM : 8d04819a3ce51b9eb47e5689b44d43c4 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sdbus.sys : 67,584 : 08/10/2004 06:00 AM : 02fc71b020ec8700ee8a46c58bc6f276 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sdbus.sys : 79,232 : 04/13/2008 02:36 PM : 8d04819a3ce51b9eb47e5689b44d43c4 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sdbus.sys : 79,232 : 04/13/2008 02:36 PM : 8d04819a3ce51b9eb47e5689b44d43c4 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0015\DriverFiles\i386\sdbus.sys : 67,584 : 08/10/2004 06:00 AM : 02fc71b020ec8700ee8a46c58bc6f276 [Pos Repl]

 * C:\WINDOWS\System32\drivers\serenum.sys : 15,744 : 04/13/2008 02:40 PM : 0f29512ccd6bead730039fb4bd2c85ce [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\serenum.sys : 15,488 : 08/10/2004 06:00 AM : a2d868aeeff612e70e213c451a70cafb [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\serenum.sys : 15,744 : 04/13/2008 02:40 PM : 0f29512ccd6bead730039fb4bd2c85ce [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\serenum.sys : 15,744 : 04/13/2008 02:40 PM : 0f29512ccd6bead730039fb4bd2c85ce [Pos Repl]

 * C:\WINDOWS\System32\drivers\serial.sys : 64,512 : 04/13/2008 03:15 PM : cca207a8896d4c6a0c9ce29a4ae411a7 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\serial.sys : 64,896 : 08/10/2004 06:00 AM : cd9404d115a00d249f70a371b46d5a26 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\serial.sys : 64,512 : 04/13/2008 03:15 PM : cca207a8896d4c6a0c9ce29a4ae411a7 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\serial.sys : 64,512 : 04/13/2008 03:15 PM : cca207a8896d4c6a0c9ce29a4ae411a7 [Pos Repl]

 * C:\WINDOWS\System32\drivers\sffdisk.sys : 11,904 : 04/13/2008 02:40 PM : 0fa803c64df0914b41f807ea276bf2a6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sffdisk.sys : 11,136 : 08/10/2004 06:00 AM : 1d9f1bec651815741f088a8fb88e17ee [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sffdisk.sys : 11,904 : 04/13/2008 02:40 PM : 0fa803c64df0914b41f807ea276bf2a6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sffdisk.sys : 11,904 : 04/13/2008 02:40 PM : 0fa803c64df0914b41f807ea276bf2a6 [Pos Repl]

 * C:\WINDOWS\System32\drivers\sffp_sd.sys : 11,008 : 04/13/2008 02:40 PM : c17c331e435ed8737525c86a7557b3ac [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sffp_sd.sys : 10,240 : 08/10/2004 06:00 AM : 586499fd312ffd7f78553f408e71682e [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sffp_sd.sys : 11,008 : 04/13/2008 02:40 PM : c17c331e435ed8737525c86a7557b3ac [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sffp_sd.sys : 11,008 : 04/13/2008 02:40 PM : c17c331e435ed8737525c86a7557b3ac [Pos Repl]

 * C:\WINDOWS\System32\drivers\sfloppy.sys : 11,392 : 04/13/2008 02:40 PM : 8e6b8c671615d126fdc553d1e2de5562 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sfloppy.sys : 11,392 : 08/10/2004 06:00 AM : 0d13b6df6e9e101013a7afb0ce629fe0 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sfloppy.sys : 11,392 : 04/13/2008 02:40 PM : 8e6b8c671615d126fdc553d1e2de5562 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sfloppy.sys : 11,392 : 04/13/2008 02:40 PM : 8e6b8c671615d126fdc553d1e2de5562 [Pos Repl]

 * C:\WINDOWS\System32\drivers\smclib.sys : 14,592 : 08/10/2004 06:00 AM : 017daecf0ed3aa731313433601ec40fa [NoSig]
 +-> C:\WINDOWS\system32\dllcache\smclib.sys : 14,592 : 08/10/2004 06:00 AM : 017daecf0ed3aa731313433601ec40fa [Pos Repl]

 * C:\WINDOWS\System32\drivers\sonydcam.sys : 25,344 : 04/13/2008 02:46 PM : 489703624dac94ed943c2abda022a1cd [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sonydcam.sys : 25,472 : 08/10/2004 06:00 AM : addc9e4757a68ab60562ad3cb9c288d6 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sonydcam.sys : 25,344 : 04/13/2008 02:46 PM : 489703624dac94ed943c2abda022a1cd [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sonydcam.sys : 25,344 : 04/13/2008 02:46 PM : 489703624dac94ed943c2abda022a1cd [Pos Repl]

 * C:\WINDOWS\System32\drivers\splitter.sys : 6,272 : 04/13/2008 02:45 PM : ab8b92451ecb048a4d1de7c3ffcb4a9f [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB920872\SP2QFE\splitter.sys : 6,272 : 06/14/2006 04:50 AM : 9bb1dd670cb7505a90fc4e61d4aa8227 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\splitter.sys : 6,400 : 06/14/2006 04:47 AM : 0ce218578fff5f4f7e4201539c45c78f [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB920872$\splitter.sys : 6,400 : 08/04/2004 00:07 AM : 8e186b8f23295d1e42c573b82b80d548 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\splitter.sys : 6,272 : 04/13/2008 02:45 PM : ab8b92451ecb048a4d1de7c3ffcb4a9f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\splitter.sys : 6,272 : 04/13/2008 02:45 PM : ab8b92451ecb048a4d1de7c3ffcb4a9f [Pos Repl]

 * C:\WINDOWS\System32\drivers\sr.sys : 73,472 : 04/13/2008 02:36 PM : 76bb022c2fb6902fd5bdd4f78fc13a5d [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sr.sys : 73,472 : 08/10/2004 06:00 AM : e41b6d037d6cd08461470af04500dc24 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sr.sys : 73,472 : 04/13/2008 02:36 PM : 76bb022c2fb6902fd5bdd4f78fc13a5d [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sr.sys : 73,472 : 04/13/2008 02:36 PM : 76bb022c2fb6902fd5bdd4f78fc13a5d [Pos Repl]

 * C:\WINDOWS\System32\drivers\srv.sys : 357,888 : 02/17/2011 09:18 AM : 47ddfc2f003f7f9f0592c6874962a2e7 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2345886\SP3QFE\srv.sys : 357,248 : 08/26/2010 09:37 AM : 70cd8b8dd2a680b128617c19eb0ab94f [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB2508429\SP3QFE\srv.sys : 357,888 : 02/17/2011 09:19 AM : 9b390283569ea58d43d2586032b892f5 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB896422\SP2QFE\srv.sys : 332,544 : 05/09/2005 08:22 PM : 54e79b08d0abc9c551d0fe69cc2f87ec [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB917159\SP2QFE\srv.sys : 332,800 : 04/21/2006 02:46 AM : 58bb0cc6be72899190505741e3b83464 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB923414\SP2QFE\srv.sys : 332,928 : 08/14/2006 08:00 AM : 5230953c21c811b5fc1ff31ae2b48097 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB957095\SP3QFE\srv.sys : 333,824 : 09/08/2008 07:37 AM : ae4d13b572399b206b43d65da4d9983d [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB958687\SP3QFE\srv.sys : 333,952 : 12/11/2008 08:33 AM : e89b42b216bc86ada4345908284519cb [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB971468\SP3QFE\srv.sys : 353,792 : 01/01/2010 03:58 AM : 30efed0c77d59ae0cacb0b5c756767ed [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB982214\SP3QFE\srv.sys : 354,304 : 06/21/2010 10:18 AM : 422e4508508015c7d12f40bf9763f158 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\srv.sys : 332,928 : 08/14/2006 06:34 AM : ea554a3ffc3f536fe8320eb38f5e4843 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2345886$\srv.sys : 354,304 : 06/21/2010 11:27 AM : da852e3e0bf1cea75d756f9866241e57 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2508429$\srv.sys : 357,248 : 08/26/2010 09:39 AM : 0f6aefad3641a657e18081f52d0c15af [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB917159$\srv.sys : 332,544 : 05/09/2005 08:17 PM : 553007ecce7f6565bbe645beb66d3b69 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB923414$\srv.sys : 332,800 : 04/21/2006 02:12 AM : e03b4ea274c9e509cca7f9f0cec24232 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB957095$\srv.sys : 334,848 : 04/13/2008 03:15 PM : 5252605079810904e31c332e241cd59b [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB958687$\srv.sys : 333,824 : 09/08/2008 06:41 AM : 4f8a43adef66f135564085a9dca96a26 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB971468$\srv.sys : 333,952 : 12/11/2008 06:57 AM : 3bb03f2ba89d2be417206c373d2af17c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB982214$\srv.sys : 353,792 : 12/31/2009 12:50 AM : 89220b427890aa1dffd1a02648ae51c3 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\srv.sys : 334,848 : 04/13/2008 03:15 PM : 5252605079810904e31c332e241cd59b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\srv.sys : 357,888 : 02/17/2011 09:18 AM : 47ddfc2f003f7f9f0592c6874962a2e7 [Pos Repl]

 * C:\WINDOWS\System32\drivers\stream.sys : 49,408 : 04/13/2008 02:45 PM : 3e5d89099ded9e86e5639f411693218f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\stream.sys : 48,640 : 08/10/2004 06:00 AM : c43356072eb3e88cd62958db10cead47 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\stream.sys : 49,408 : 04/13/2008 02:45 PM : 3e5d89099ded9e86e5639f411693218f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\stream.sys : 49,408 : 04/13/2008 02:45 PM : 3e5d89099ded9e86e5639f411693218f [Pos Repl]

 * C:\WINDOWS\System32\drivers\swenum.sys : 4,352 : 04/13/2008 02:39 PM : 3941d127aef12e93addf6fe6ee027e0f [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\swenum.sys : 4,352 : 08/03/2004 11:58 PM : 03c1bae4766e2450219d20b993d6e046 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\swenum.sys : 4,352 : 04/13/2008 02:39 PM : 3941d127aef12e93addf6fe6ee027e0f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\swenum.sys : 4,352 : 04/13/2008 02:39 PM : 3941d127aef12e93addf6fe6ee027e0f [Pos Repl]

 * C:\WINDOWS\System32\drivers\swmidi.sys : 56,576 : 04/13/2008 02:45 PM : 8ce882bcc6cf8a62f2b2323d95cb3d01 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\swmidi.sys : 54,272 : 08/17/2001 03:00 PM : 94abc808fc4b6d7d2bbf42b85e25bb4d [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\swmidi.sys : 56,576 : 04/13/2008 02:45 PM : 8ce882bcc6cf8a62f2b2323d95cb3d01 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\swmidi.sys : 56,576 : 04/13/2008 02:45 PM : 8ce882bcc6cf8a62f2b2323d95cb3d01 [Pos Repl]

 * C:\WINDOWS\System32\drivers\sysaudio.sys : 60,800 : 04/13/2008 03:15 PM : 8b83f3ed0f1688b4958f77cd6d2bf290 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\sysaudio.sys : 60,800 : 08/04/2004 00:15 AM : 650ad082d46bac0e64c9c0e0928492fd [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\sysaudio.sys : 60,800 : 04/13/2008 03:15 PM : 8b83f3ed0f1688b4958f77cd6d2bf290 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\sysaudio.sys : 60,800 : 04/13/2008 03:15 PM : 8b83f3ed0f1688b4958f77cd6d2bf290 [Pos Repl]

 * C:\WINDOWS\System32\drivers\tape.sys : 14,976 : 04/13/2008 02:40 PM : fd6093e3decd925f1cffc8a0dd539d72 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tape.sys : 14,976 : 08/10/2004 06:00 AM : a2a9ca0d1a9ac1ff54220aa0789fe5cf [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tape.sys : 14,976 : 04/13/2008 02:40 PM : fd6093e3decd925f1cffc8a0dd539d72 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tape.sys : 14,976 : 04/13/2008 02:40 PM : fd6093e3decd925f1cffc8a0dd539d72 [Pos Repl]

 * C:\WINDOWS\System32\drivers\tcpip6.sys : 226,880 : 02/11/2010 08:02 AM : 4e53bbcc4be37d7a4bd6ef1098c89ff7 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip6.sys : 225,856 : 06/20/2008 07:16 AM : 026a94e4eb2960fdc96a447b5391d56a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB922819\SP2QFE\tcpip6.sys : 225,664 : 08/16/2006 06:13 AM : a026ea381b026d05a4a3d2388d80c3b8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip6.sys : 225,920 : 06/20/2008 05:32 AM : 7195e0ce397545e657a81ece9dfbc1c9 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip6.sys : 225,856 : 06/20/2008 07:08 AM : fb9f32acc1d3ad523f7ec900b66fc1bb [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip6.sys : 225,856 : 06/20/2008 07:16 AM : 026a94e4eb2960fdc96a447b5391d56a [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB978338\SP3QFE\tcpip6.sys : 226,880 : 02/11/2010 07:36 AM : f4a3c6abe7818b1b53f58fa1adb605cd [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tcpip6.sys : 225,920 : 06/20/2008 05:52 AM : 00586ed87ab564b03870a2a3dcc84b55 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB922819$\tcpip6.sys : 223,616 : 08/10/2004 06:00 AM : 4d58bb1ae8841aafd8790ad7e1e3b8ea [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748$\tcpip6.sys : 225,664 : 04/13/2008 03:00 PM : aa7a55536096d646dc7ab0ac5641e9e8 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748_0$\tcpip6.sys : 225,664 : 08/16/2006 05:37 AM : dccacdd2747ada221aece5c9ada5d551 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB978338$\tcpip6.sys : 225,856 : 06/20/2008 07:08 AM : fb9f32acc1d3ad523f7ec900b66fc1bb [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tcpip6.sys : 225,664 : 04/13/2008 03:00 PM : aa7a55536096d646dc7ab0ac5641e9e8 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tcpip6.sys : 226,880 : 02/11/2010 08:02 AM : 4e53bbcc4be37d7a4bd6ef1098c89ff7 [Pos Repl]

 * C:\WINDOWS\System32\Drivers\tcpip.sys : 361,600 : 06/20/2008 07:51 AM : 9aefa14bd6b182d61e3119fa5f436d3d [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2509553\SP3QFE\tcpip.sys : 361,600 : 06/20/2008 07:59 AM : ad978a1b783b5719720cff204b666c8e [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB913446\SP2QFE\tcpip.sys : 360,448 : 01/13/2006 01:07 PM : 5562cc0a47b2aef06d3417b733f3c195 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB917953\SP2QFE\tcpip.sys : 360,576 : 04/20/2006 08:18 AM : b2220c618b42a2212a59d91ebd6fc4b4 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys : 360,832 : 10/30/2007 12:53 AM : 64798ecfa43d78c7178375fcdd16d8c8 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP2QFE\tcpip.sys : 360,960 : 06/20/2008 06:44 AM : 744e57c99232201ae98c49168b918f48 [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\tcpip.sys : 361,600 : 06/20/2008 07:51 AM : 9aefa14bd6b182d61e3119fa5f436d3d [Pos Repl]
 +-> C:\WINDOWS\$hf_mig$\KB951748\SP3QFE\tcpip.sys : 361,600 : 06/20/2008 07:59 AM : ad978a1b783b5719720cff204b666c8e [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys : 360,320 : 06/20/2008 06:45 AM : 2a5554fc5b1e04e131230e3ce035c3f9 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB913446$\tcpip.sys : 359,040 : 08/10/2004 06:00 AM : 9f4b36614a0fc234525ba224957de55c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB917953$\tcpip.sys : 359,808 : 01/12/2006 10:28 PM : 583e063fdc888ca30d05c2724b0d7ef4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys : 359,808 : 04/20/2006 07:51 AM : 1dbf125862891817f374f407626967f4 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748$\tcpip.sys : 361,344 : 04/13/2008 03:20 PM : 93ea8d04ec73a85db02eb8805988f733 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB951748_0$\tcpip.sys : 360,064 : 10/30/2007 01:20 PM : 90caff4b094573449a0872a0f919b178 [Pos Repl]
 +-> C:\WINDOWS\ERDNT\cache\tcpip.sys : 361,600 : 06/20/2008 07:51 AM : 9aefa14bd6b182d61e3119fa5f436d3d [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tcpip.sys : 361,344 : 04/13/2008 03:20 PM : 93ea8d04ec73a85db02eb8805988f733 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tcpip.sys : 361,600 : 06/20/2008 07:51 AM : 9aefa14bd6b182d61e3119fa5f436d3d [Pos Repl]

 * C:\WINDOWS\System32\drivers\tdi.sys : 19,072 : 04/13/2008 03:00 PM : 0539d5e53587f82d1b4fd74c5be205cf [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tdi.sys : 18,560 : 08/10/2004 06:00 AM : 6891b74ab9a016064e82a419388d0601 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tdi.sys : 19,072 : 04/13/2008 03:00 PM : 0539d5e53587f82d1b4fd74c5be205cf [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tdi.sys : 19,072 : 04/13/2008 03:00 PM : 0539d5e53587f82d1b4fd74c5be205cf [Pos Repl]

 * C:\WINDOWS\System32\drivers\tdpipe.sys : 12,040 : 04/13/2008 08:13 PM : 6471a66807f5e104e4885f5b67349397 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tdpipe.sys : 12,040 : 08/10/2004 06:00 AM : 38d437cf2d98965f239b0abcd66dcb0f [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tdpipe.sys : 12,040 : 04/13/2008 08:13 PM : 6471a66807f5e104e4885f5b67349397 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tdpipe.sys : 12,040 : 04/13/2008 08:13 PM : 6471a66807f5e104e4885f5b67349397 [Pos Repl]

 * C:\WINDOWS\System32\drivers\tdtcp.sys : 21,896 : 04/13/2008 08:13 PM : c56b6d0402371cf3700eb322ef3aaf61 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tdtcp.sys : 21,896 : 08/10/2004 06:00 AM : ed0580af02502d00ad8c4c066b156be9 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tdtcp.sys : 21,896 : 04/13/2008 08:13 PM : c56b6d0402371cf3700eb322ef3aaf61 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tdtcp.sys : 21,896 : 04/13/2008 08:13 PM : c56b6d0402371cf3700eb322ef3aaf61 [Pos Repl]

 * C:\WINDOWS\System32\drivers\termdd.sys : 40,840 : 04/13/2008 08:13 PM : 88155247177638048422893737429d9e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\termdd.sys : 40,840 : 08/04/2004 02:01 AM : a540a99c281d933f3d69d55e48727f47 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\termdd.sys : 40,840 : 04/13/2008 08:13 PM : 88155247177638048422893737429d9e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\termdd.sys : 40,840 : 04/13/2008 08:13 PM : 88155247177638048422893737429d9e [Pos Repl]

 * C:\WINDOWS\System32\drivers\tosdvd.sys : 51,712 : 08/10/2004 06:00 AM : 699450901c5ccfd82357cbc531cedd23 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\tosdvd.sys : 51,712 : 08/10/2004 06:00 AM : 699450901c5ccfd82357cbc531cedd23 [Pos Repl]

 * C:\WINDOWS\System32\drivers\tunmp.sys : 12,288 : 04/13/2008 02:56 PM : 8f861eda21c05857eb8197300a92501c [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\tunmp.sys : 12,416 : 08/10/2004 06:00 AM : 87a0e9e18c10a9e454238e3330e2a26d [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\tunmp.sys : 12,288 : 04/13/2008 02:56 PM : 8f861eda21c05857eb8197300a92501c [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\tunmp.sys : 12,288 : 04/13/2008 02:56 PM : 8f861eda21c05857eb8197300a92501c [Pos Repl]

 * C:\WINDOWS\System32\drivers\udfs.sys : 66,048 : 04/13/2008 02:32 PM : 5787b80c2e3c5e2f56c2a233d91fa2c9 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\udfs.sys : 66,176 : 08/10/2004 06:00 AM : 12f70256f140cd7d52c58c7048fde657 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\udfs.sys : 66,048 : 04/13/2008 02:32 PM : 5787b80c2e3c5e2f56c2a233d91fa2c9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\udfs.sys : 66,048 : 04/13/2008 02:32 PM : 5787b80c2e3c5e2f56c2a233d91fa2c9 [Pos Repl]

 * C:\WINDOWS\System32\drivers\update.sys : 384,768 : 04/13/2008 02:39 PM : 402ddc88356b1bac0ee3dd1580c76a31 [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB936357\SP2QFE\update.sys : 364,160 : 04/23/2007 06:14 AM : 7b2170ee3d858ce8fbe503904cc9b663 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\update.sys : 364,160 : 04/23/2007 06:32 AM : ced744117e91bdc0beb810f7d8608183 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB936357$\update.sys : 209,408 : 08/10/2004 06:00 AM : aff2e5045961bbc0a602bb6f95eb1345 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\update.sys : 384,768 : 04/13/2008 02:39 PM : 402ddc88356b1bac0ee3dd1580c76a31 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\update.sys : 384,768 : 04/13/2008 02:39 PM : 402ddc88356b1bac0ee3dd1580c76a31 [Pos Repl]

 * C:\WINDOWS\System32\drivers\usb8023.sys : 12,928 : 02/11/2013 08:32 PM : 2a7a8ad9d39a2faf9d9293b5daff3a4b [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB2807986\SP3QFE\usb8023.sys : 12,928 : 02/11/2013 08:43 PM : c74f25c77d6c3edf58221e4060d8cd16 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usb8023.sys : 12,800 : 12/08/2004 10:34 AM : b379e9bb356b0f3b69e2c47857b63ffd [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2807986$\usb8023.sys : 12,800 : 04/13/2008 02:56 PM : bee793d4a059caea55d6ac20e19b3a8f [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB890927$\usb8023.sys : 12,672 : 08/10/2004 06:00 AM : af090265ec388bab320f1ff7e7a7d5ea [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usb8023.sys : 12,800 : 04/13/2008 02:56 PM : bee793d4a059caea55d6ac20e19b3a8f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usb8023.sys : 12,928 : 02/11/2013 08:32 PM : 2a7a8ad9d39a2faf9d9293b5daff3a4b [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbcamd2.sys : 25,728 : 04/13/2008 02:45 PM : ce97845d2e3f0d274b8bac1ed07c6149 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbcamd2.sys : 23,936 : 08/10/2004 06:00 AM : 61018ba9df6b63e51d9753c980e73ec2 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbcamd2.sys : 25,728 : 04/13/2008 02:45 PM : ce97845d2e3f0d274b8bac1ed07c6149 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbcamd2.sys : 25,728 : 04/13/2008 02:45 PM : ce97845d2e3f0d274b8bac1ed07c6149 [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbcamd.sys : 25,600 : 04/13/2008 02:45 PM : 1c1a47b40c23358245aa8d0443b6935e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbcamd.sys : 23,808 : 08/10/2004 06:00 AM : 2654eecc6fb13603ebddcd5c8ea943d1 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbcamd.sys : 25,600 : 04/13/2008 02:45 PM : 1c1a47b40c23358245aa8d0443b6935e [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbcamd.sys : 25,600 : 04/13/2008 02:45 PM : 1c1a47b40c23358245aa8d0443b6935e [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbccgp.sys : 32,384 : 08/08/2013 08:55 PM : 1b611611c28d2df25bc057d79c6f13fc [NoSig]
 +-> C:\WINDOWS\$NtUninstallKB2862330$\usbccgp.sys : 32,128 : 04/13/2008 02:45 PM : 173f317ce0db8e21322e71b7e60a27e8 [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\usbccgp.sys : 32,384 : 08/08/2013 08:55 PM : 1b611611c28d2df25bc057d79c6f13fc [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbccgp.sys : 32,128 : 04/13/2008 02:45 PM : 173f317ce0db8e21322e71b7e60a27e8 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbccgp.sys : 32,384 : 08/08/2013 08:55 PM : 1b611611c28d2df25bc057d79c6f13fc [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbd.sys : 5,376 : 08/08/2013 08:55 PM : 04fe5ef6ed4818ec4839ea5c611a6310 [NoSig]
 +-> C:\WINDOWS\$NtUninstallKB2862330$\usbd.sys : 4,736 : 08/10/2004 06:00 AM : 596eb39b50d6ebd9b734dc4ae0544693 [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\usbd.sys : 5,376 : 08/08/2013 08:55 PM : 04fe5ef6ed4818ec4839ea5c611a6310 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbd.sys : 5,376 : 08/08/2013 08:55 PM : 04fe5ef6ed4818ec4839ea5c611a6310 [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbehci.sys : 30,336 : 03/18/2009 07:02 AM : 4bac8df07f1d8434fc640e677a62204e [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbehci.sys : 27,264 : 10/25/2005 07:39 PM : 708579b01fed227aadb393cb0c3b4a2c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2862330$\usbehci.sys : 30,208 : 04/13/2008 02:45 PM : 65dcf09d0e37d4c6b11b5b0b76d470a7 [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\usbehci.sys : 30,336 : 03/18/2009 07:02 AM : 4bac8df07f1d8434fc640e677a62204e [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbehci.sys : 30,208 : 04/13/2008 02:45 PM : 65dcf09d0e37d4c6b11b5b0b76d470a7 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbehci.sys : 30,336 : 03/18/2009 07:02 AM : 4bac8df07f1d8434fc640e677a62204e [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\usbehci.sys : 26,624 : 08/10/2004 06:00 AM : 15e993ba2f6946b2bfbbfcd30398621e [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbhub.sys : 59,520 : 04/13/2008 02:45 PM : 1ab3cdde553b6e064d2e754efe20285c [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbhub.sys : 57,600 : 08/04/2004 00:08 AM : c72f40947f92cea56a8fb532edf025f1 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbhub.sys : 59,520 : 04/13/2008 02:45 PM : 1ab3cdde553b6e064d2e754efe20285c [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbhub.sys : 59,520 : 04/13/2008 02:45 PM : 1ab3cdde553b6e064d2e754efe20285c [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\usbhub.sys : 57,600 : 08/10/2004 06:00 AM : c72f40947f92cea56a8fb532edf025f1 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\usbhub.sys : 57,600 : 08/04/2004 00:08 AM : c72f40947f92cea56a8fb532edf025f1 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\usbhub.sys : 57,600 : 08/04/2004 00:08 AM : c72f40947f92cea56a8fb532edf025f1 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\usbhub.sys : 57,600 : 08/04/2004 00:08 AM : c72f40947f92cea56a8fb532edf025f1 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\usbhub.sys : 57,600 : 08/04/2004 00:08 AM : c72f40947f92cea56a8fb532edf025f1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbintel.sys : 15,872 : 04/13/2008 02:45 PM : 290913dc4f1125e5a82de52579a44c43 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbintel.sys : 16,000 : 08/10/2004 06:00 AM : 2853fd4c4489e0f8bfcf78efcdb7e998 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbintel.sys : 15,872 : 04/13/2008 02:45 PM : 290913dc4f1125e5a82de52579a44c43 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbintel.sys : 15,872 : 04/13/2008 02:45 PM : 290913dc4f1125e5a82de52579a44c43 [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbport.sys : 144,128 : 08/08/2013 08:55 PM : 6df35ca139c3bc15cc74390abb114efe [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbport.sys : 143,104 : 10/25/2005 07:39 PM : a6df50ba7534b13c5a34d0d22cfebe0c [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB2862330$\usbport.sys : 143,872 : 04/13/2008 02:45 PM : 791912e524cc2cc6f50b5f2b52d1eb71 [Pos Repl]
 +-> C:\WINDOWS\Driver Cache\i386\usbport.sys : 144,128 : 08/08/2013 08:55 PM : 6df35ca139c3bc15cc74390abb114efe [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbport.sys : 143,872 : 04/13/2008 02:45 PM : 791912e524cc2cc6f50b5f2b52d1eb71 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbport.sys : 144,128 : 08/08/2013 08:55 PM : 6df35ca139c3bc15cc74390abb114efe [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\usbport.sys : 142,976 : 08/10/2004 06:00 AM : 2034ca78f9c6e787b4b76d81ac888351 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\usbport.sys : 142,976 : 08/04/2004 00:08 AM : 2034ca78f9c6e787b4b76d81ac888351 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\usbport.sys : 142,976 : 08/04/2004 00:08 AM : 2034ca78f9c6e787b4b76d81ac888351 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\usbport.sys : 142,976 : 08/04/2004 00:08 AM : 2034ca78f9c6e787b4b76d81ac888351 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0008\DriverFiles\i386\usbport.sys : 142,976 : 08/04/2004 00:08 AM : 2034ca78f9c6e787b4b76d81ac888351 [Pos Repl]

 * C:\WINDOWS\System32\drivers\USBSTOR.sys : 26,368 : 04/13/2008 02:45 PM : a32426d9b14a089eaa1d922e0c5801a9 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbstor.sys : 26,496 : 08/03/2004 11:08 PM : 6cd7b22193718f1d17a47a1cd6d37e75 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbstor.sys : 26,368 : 04/13/2008 02:45 PM : a32426d9b14a089eaa1d922e0c5801a9 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbstor.sys : 26,368 : 04/13/2008 02:45 PM : a32426d9b14a089eaa1d922e0c5801a9 [Pos Repl]

 * C:\WINDOWS\System32\drivers\usbuhci.sys : 20,608 : 04/13/2008 02:45 PM : 26496f9dee2d787fc3e61ad54821ffe6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\usbuhci.sys : 20,480 : 08/04/2004 00:08 AM : f8fd1400092e23c8f2f31406ef06167b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\usbuhci.sys : 20,608 : 04/13/2008 02:45 PM : 26496f9dee2d787fc3e61ad54821ffe6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\usbuhci.sys : 20,608 : 04/13/2008 02:45 PM : 26496f9dee2d787fc3e61ad54821ffe6 [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\usbuhci.sys : 20,480 : 08/10/2004 06:00 AM : f8fd1400092e23c8f2f31406ef06167b [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\usbuhci.sys : 20,480 : 08/04/2004 00:08 AM : f8fd1400092e23c8f2f31406ef06167b [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\usbuhci.sys : 20,480 : 08/04/2004 00:08 AM : f8fd1400092e23c8f2f31406ef06167b [Pos Repl]
 +-> C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\usbuhci.sys : 20,480 : 08/04/2004 00:08 AM : f8fd1400092e23c8f2f31406ef06167b [Pos Repl]

 * C:\WINDOWS\System32\drivers\vga.sys : 20,992 : 04/13/2008 02:44 PM : 0d3a8fafceacd8b7625cd549757a7df1 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\vga.sys : 20,992 : 08/10/2004 06:00 AM : 8a60edd72b4ea5aea8202daf0e427925 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\vga.sys : 20,992 : 04/13/2008 02:44 PM : 0d3a8fafceacd8b7625cd549757a7df1 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\vga.sys : 20,992 : 04/13/2008 02:44 PM : 0d3a8fafceacd8b7625cd549757a7df1 [Pos Repl]

 * C:\WINDOWS\System32\drivers\videoprt.sys : 81,664 : 04/13/2008 02:44 PM : e28726b72c46821a28830e077d39a55b [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\videoprt.sys : 79,744 : 08/10/2004 06:00 AM : d5a9d123f5ed7c9965a481bd20cf66d8 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\videoprt.sys : 81,664 : 04/13/2008 02:44 PM : e28726b72c46821a28830e077d39a55b [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\videoprt.sys : 81,664 : 04/13/2008 02:44 PM : e28726b72c46821a28830e077d39a55b [Pos Repl]

 * C:\WINDOWS\System32\drivers\volsnap.sys : 52,352 : 04/13/2008 02:41 PM : 4c8fcb5cc53aab716d810740fe59d025 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\volsnap.sys : 52,352 : 08/10/2004 06:00 AM : ee4660083deba849ff6c485d944b379b [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\volsnap.sys : 52,352 : 04/13/2008 02:41 PM : 4c8fcb5cc53aab716d810740fe59d025 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\volsnap.sys : 52,352 : 04/13/2008 02:41 PM : 4c8fcb5cc53aab716d810740fe59d025 [Pos Repl]

 * C:\WINDOWS\System32\drivers\wanarp.sys : 34,560 : 04/13/2008 02:57 PM : e20b95baedb550f32dd489265c1da1f6 [NoSig]
 +-> C:\WINDOWS\$NtServicePackUninstall$\wanarp.sys : 34,560 : 08/10/2004 06:00 AM : 984ef0b9788abf89974cfed4bfbaacbc [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\wanarp.sys : 34,560 : 04/13/2008 02:57 PM : e20b95baedb550f32dd489265c1da1f6 [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\wanarp.sys : 34,560 : 04/13/2008 02:57 PM : e20b95baedb550f32dd489265c1da1f6 [Pos Repl]

 * C:\WINDOWS\System32\drivers\wdmaud.sys : 83,072 : 04/13/2008 03:17 PM : 6768acf64b18196494413695f0c3a00f [NoSig]
 +-> C:\WINDOWS\$hf_mig$\KB920872\SP2QFE\wdmaud.sys : 82,944 : 06/14/2006 05:17 AM : 0bfa8203b8148fb4e54bc212c41ce497 [Pos Repl]
 +-> C:\WINDOWS\$NtServicePackUninstall$\wdmaud.sys : 82,944 : 06/14/2006 05:00 AM : efd235ca22b57c81118c1aeb4798f1c1 [Pos Repl]
 +-> C:\WINDOWS\$NtUninstallKB920872$\wdmaud.sys : 82,944 : 08/04/2004 00:15 AM : 2797f33ebf50466020c430ee4f037933 [Pos Repl]
 +-> C:\WINDOWS\ServicePackFiles\i386\wdmaud.sys : 83,072 : 04/13/2008 03:17 PM : 6768acf64b18196494413695f0c3a00f [Pos Repl]
 +-> C:\WINDOWS\system32\dllcache\wdmaud.sys : 83,072 : 04/13/2008 03:17 PM : 6768acf64b18196494413695f0c3a00f [Pos Repl]

 * C:\WINDOWS\System32\drivers\wmilib.sys : 4,352 : 08/10/2004 06:00 AM : 2f31b7f954bed437f2c75026c65caf7b [NoSig]
 +-> C:\WINDOWS\system32\dllcache\wmilib.sys : 4,352 : 08/10/2004 06:00 AM : 2f31b7f954bed437f2c75026c65caf7b [Pos Repl]

 * C:\WINDOWS\System32\drivers\ws2ifsl.sys : 12,032 : 08/10/2004 06:00 AM : 6abe6e225adb5a751622a9cc3bc19ce8 [NoSig]
 +-> C:\WINDOWS\system32\dllcache\ws2ifsl.sys : 12,032 : 08/10/2004 06:00 AM : 6abe6e225adb5a751622a9cc3bc19ce8 [Pos Repl]

Checking HOSTS File:

 * HOSTS file entries found:

  127.0.0.1       localhost
  HP002264464D41 HP002264464D41

Program finished at: 08/17/2015 10:07:08 AM
Execution time: 2 hours(s), 54 minute(s), and 59 seconds(s

Offline Canoo

  • Bronze Member
  • Posts: 42
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #13 on: August 18, 2015, 05:28:35 AM »
Reply 5 of 5  -  (exceeded 65,000 characters) this portion includes combofix.txt

ComboFix 15-08-17.01 - Kelsie 08/17/2015  23:16:57.11.2 - x86 MINIMAL
Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.2038.1753 [GMT -4:00]
Running from: C:\Documents and Settings\Kelsie\desktop\sega.com
Command switches used :: /killall
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}


(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\All Users\Application Data\TEMP
C:\Documents and Settings\Kelsie\My Documents\~WRL0004.tmp
C:\Documents and Settings\Kelsie\My Documents\~WRL0005.tmp
C:\Documents and Settings\Kelsie\My Documents\~WRL1014.tmp
C:\Documents and Settings\Kelsie\My Documents\~WRL2805.tmp
C:\Documents and Settings\Kelsie\My Documents\~WRL3358.tmp
C:\Documents and Settings\Kelsie\My Documents\~WRL3425.tmp
C:\WINDOWS\msdownld.tmp
C:\WINDOWS\setupapi.log
C:\WINDOWS\system32\HPZipm12.1


(((((((((((((((((((((((((   Files Created from 2015-07-18 to 2015-08-18  )))))))))))))))))))))))))))))))


2015-08-17 23:23:47 . 2015-08-17 23:26:23   --------   d-----w-   C:\sega
2015-08-14 00:46:33 . 2015-08-14 01:33:58   35064   ----a-w-   C:\WINDOWS\system32\drivers\TrueSight.sys
2015-08-14 00:46:18 . 2015-08-14 00:46:18   --------   d-----w-   C:\Documents and Settings\All Users\Application Data\RogueKiller
2015-08-13 23:02:34 . 2015-08-14 23:11:08   --------   d-----w-   C:\FRST
2015-08-11 09:34:55 . 2015-08-13 00:40:32   98520   ----a-w-   C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2015-08-11 09:28:07 . 2015-08-11 09:28:11   --------   d-----w-   C:\Program Files\Malwarebytes Anti-Malware
2015-08-11 09:28:07 . 2015-06-18 12:41:46   121560   ----a-w-   C:\WINDOWS\system32\drivers\mbamchameleon.sys
.


((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))

2015-06-18 12:41:36 . 2011-06-25 18:46:27   23256   ----a-w-   C:\WINDOWS\system32\drivers\mbam.sys


------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.









[-] 2012-07-06 13:58:51 . CFD4E51402DA9838B5A04AE680AF54A0 . 78336 . . [5.1.2600.6260 (xpsp_sp3_gdr.120706-1619)] . . C:\WINDOWS\system32\browser.dll
[-] 2012-07-06 13:58:51 . CFD4E51402DA9838B5A04AE680AF54A0 . 78336 . . [5.1.2600.6260 (xpsp_sp3_gdr.120706-1619)] . . C:\WINDOWS\system32\dllcache\browser.dll

[-] 2008-04-14 00:12:24 . BF2466B3E18E970D8A976FB95FC1CA85 . 13312 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\lsass.exe

[-] 2008-04-14 00:12:01 . 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE . 198144 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\netman.dll

[-] 2008-04-14 00:11:51 . 1280A158C722FA95A80FB7AEBE78FA7D . 792064 . . [2001.12.4414.700] . . C:\WINDOWS\ERDNT\cache\comres.dll

[-] 2008-04-14 00:12:03 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ERDNT\cache\qmgr.dll
[-] 2008-04-14 00:12:03 . 574738F61FCA2935F5265DC4E5691314 . 409088 . . [6.7.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ServicePackFiles\i386\qmgr.dll


[-] 2009-02-06 11:11:05 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] . . C:\WINDOWS\ERDNT\cache\services.exe
[-] 2009-02-06 11:11:05 . 65DF52F5B8B6E9BBD183505225C37315 . 110592 . . [5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)] . . C:\WINDOWS\system32\services.exe

[-] 2010-08-17 13:19:36 . 258DD5D4283FD9F9A7166BE9AE45CE73 . 58880 . . [5.1.2600.6024 (xpsp_sp3_qfe.100817-1627)] . . C:\WINDOWS\$hf_mig$\KB2347290\SP3QFE\spoolsv.exe
[-] 2010-08-17 13:17:06 . 60784F891563FB1B767F70117FC2428F . 58880 . . [5.1.2600.6024 (xpsp_sp3_gdr.100817-1626)] . . C:\WINDOWS\ERDNT\cache\spoolsv.exe

[-] 2008-04-14 00:12:39 . ED0EF0A136DEC83DF69F04118870003E . 507904 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\winlogon.exe

[7] 2012-06-02 19:19:34 . 2E0B0A051FFAA86E358465BB0880D453 . 53784 . . [7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)] . . C:\WINDOWS\system32\wuauclt.exe
[7] 2012-06-02 19:19:34 . 2E0B0A051FFAA86E358465BB0880D453 . 53784 . . [7.6.7600.256 (winmain_wtr_wsus3sp2(oobla).120602-1459)] . . C:\WINDOWS\system32\dllcache\wuauclt.exe
[7] 2009-08-06 23:24:06 . 62BB79160F86CD962F312C68C6239BFD . 53472 . . [7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834)] . . C:\WINDOWS\ERDNT\cache\wuauclt.exe
[-] 2008-04-14 00:12:41 . ED7262E52C31CF1625B65039102BC16C . 111104 . . [5.4.3790.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\wuauclt.exe

[-] 2008-04-13 19:19:42 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\ipsec.sys
[-] 2008-04-13 19:19:42 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\ipsec.sys

[-] 2010-08-23 16:12:04 . 93AFB83FBC1F9443CAC722FCA63D73BF . 617472 . . [5.82 (xpsp_sp3_qfe.100823-1643)] . . C:\WINDOWS\ERDNT\cache\comctl32.dll

[-] 2008-04-14 00:11:51 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\cryptsvc.dll
[-] 2008-04-14 00:11:51 . 3D4E199942E29207970E04315D02AD3B . 62464 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ServicePackFiles\i386\cryptsvc.dll


[-] 2008-04-14 00:11:54 . 0DA85218E92526972A821587E6A8BF8F . 110080 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\imm32.dll

[-] 2014-03-12 10:48:50 . 4A45B692D2BAA74124DF57472D5EA2F1 . 993280 . . [5.1.2600.6532 (xpsp_sp3_qfe.140312-0419)] . . C:\WINDOWS\system32\kernel32.dll
[-] 2014-03-12 10:48:50 . 4A45B692D2BAA74124DF57472D5EA2F1 . 993280 . . [5.1.2600.6532 (xpsp_sp3_qfe.140312-0419)] . . C:\WINDOWS\system32\dllcache\kernel32.dll

[-] 2008-04-14 00:11:56 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\linkinfo.dll
[-] 2008-04-14 00:11:56 . 2DC5A8019E2387987905F77C664E4BE2 . 19968 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ServicePackFiles\i386\linkinfo.dll

[-] 2008-04-14 00:11:56 . 012DF358CEBAA23ACB26D82077820817 . 22016 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\lpk.dll


[-] 2008-04-14 00:12:51 . D7075E95AA599EE77B7A89D39296BD3D . 343040 . . [7.0.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.2600.5512_x-ww_3fd60d63\msvcrt.dll

[-] 2008-06-20 17:46:57 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\$hf_mig$\KB951748\SP3GDR\mswsock.dll
[-] 2008-06-20 17:46:57 . 832E4DD8964AB7ACC880B2837CB1ED20 . 245248 . . [5.1.2600.5625 (xpsp_sp3_gdr.080620-1249)] . . C:\WINDOWS\$NtUninstallKB2509553$\mswsock.dll

[-] 2008-04-14 00:12:01 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\netlogon.dll
[-] 2008-04-14 00:12:01 . 1B7F071C51B77C272875C3A23E1E4550 . 407040 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ServicePackFiles\i386\netlogon.dll

[-] 2008-04-14 00:12:03 . 50A166237A0FA771261275A405646CC0 . 17408 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\powrprof.dll

[-] 2008-04-14 00:12:05 . A86BB5E61BF3E39B62AB4C7E7085A084 . 181248 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\scecli.dll

[-] 2008-04-14 00:12:05 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\sfc.dll
[-] 2008-04-14 00:12:05 . 96E1C926F22EE1BFBAE82901A35F6BF3 . 5120 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ServicePackFiles\i386\sfc.dll

[-] 2008-04-14 00:12:36 . 27C6D03BCDB8CFEB96B716F3D8BE3E18 . 14336 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\svchost.exe

[-] 2008-04-14 00:12:07 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\tapisrv.dll
[-] 2008-04-14 00:12:07 . 3CB78C17BB664637787C9A1C98F79C38 . 249856 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\tapisrv.dll

[-] 2008-04-14 00:12:08 . B26B135FF1B9F60C9388B4A7D16F600B . 578560 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\user32.dll

[-] 2008-04-14 00:12:38 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\userinit.exe
[-] 2008-04-14 00:12:38 . A93AEE1928A9D7CE3E16D24EC7380F89 . 26112 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ServicePackFiles\i386\userinit.exe

[-] 2014-03-06 17:59:23 . 8AF91E4B4C1F5338EBE1548117304296 . 920064 . . [8.00.6001.23580 (longhorn_ie8_ldr.140222-1715)] . . C:\WINDOWS\system32\wininet.dll

[-] 2008-04-14 00:12:10 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\ws2_32.dll
[-] 2008-04-14 00:12:10 . 2CCC474EB85CEAA3E1FA1726580A3E5A . 82432 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\ws2_32.dll

[-] 2008-04-14 00:12:10 . 9789E95E1D88EEB4B922BF3EA7779C28 . 19968 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\ws2help.dll

[-] 2008-04-14 00:12:19 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\explorer.exe
[-] 2008-04-14 00:12:19 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\explorer.exe
[-] 2008-04-14 00:12:19 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ServicePackFiles\i386\explorer.exe

[-] 2008-04-14 00:12:32 . 058710B720282CA82B909912D3EF28DB . 146432 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\regedit.exe

[-] 2013-08-05 13:30:32 . 59B408E5B8489B0B36A0D783D150EDCC . 1289728 . . [5.1.2600.6435 (xpsp_sp3_qfe.130803-0418)] . . C:\WINDOWS\system32\ole32.dll

[-] 2013-07-10 10:37:53 . 1D845821F5ADB076831DE4C2818F858B . 406016 . . [1.0420.2600.6421 (xpsp_sp3_qfe.130709-0421)] . . C:\WINDOWS\system32\usp10.dll

[-] 2008-04-14 00:11:56 . 9B9F1C38D559047B8AC0DBA2D5FEBDE9 . 4096 . . [5.3.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ServicePackFiles\i386\ksuser.dll
[-] 2008-04-14 00:11:56 . 9B9F1C38D559047B8AC0DBA2D5FEBDE9 . 4096 . . [5.3.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\ksuser.dll

[-] 2008-04-14 00:12:16 . 5F1D5F88303D4A4DBC8E5F97BA967CC3 . 15360 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\ctfmon.exe

[-] 2009-07-27 23:17:41 . 99BC0B50F511924348BE19C7C7313BBF . 135168 . . [6.00.2900.5853 (xpsp_sp3_gdr.090727-1736)] . . C:\WINDOWS\ERDNT\cache\shsvcs.dll
[-] 2009-07-27 23:17:41 . 99BC0B50F511924348BE19C7C7313BBF . 135168 . . [6.00.2900.5853 (xpsp_sp3_gdr.090727-1736)] . . C:\WINDOWS\system32\shsvcs.dll

[-] 2008-04-14 00:11:59 . AFFC87E2501FCE8F09D4C10BA6421CCF . 4608 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ServicePackFiles\i386\msimg32.dll

[-] 2008-04-14 00:12:07 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ERDNT\cache\srsvc.dll
[-] 2008-04-14 00:12:07 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-14 00:12:07 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\system32\srsvc.dll

[-] 2008-04-14 00:12:41 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ERDNT\cache\wscntfy.exe
[-] 2008-04-14 00:12:41 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ServicePackFiles\i386\wscntfy.exe
[-] 2008-04-14 00:12:41 . F92E1076C42FCD6DB3D72D8CFE9816D5 . 13824 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\system32\wscntfy.exe


[-] 2010-12-09 15:15:41 . 15CE4DBC22FAB90B3CA5352AF1FFF81C . 718336 . . [5.1.2600.6055 (xpsp_sp3_qfe.101209-1646)] . . C:\WINDOWS\$hf_mig$\KB2393802\SP3QFE\ntdll.dll

[-] 2008-04-14 00:10:06 . 5733177BCF16EE78B99543C9B0AB81EA . 177152 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ServicePackFiles\i386\msctfime.ime
[-] 2008-04-14 00:10:06 . 5733177BCF16EE78B99543C9B0AB81EA . 177152 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\system32\msctfime.ime
[-] 2008-04-14 00:10:06 . 5733177BCF16EE78B99543C9B0AB81EA . 177152 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\system32\dllcache\msctfime.ime
[-] 2004-08-10 10:00:00 . D87041EAA67ECA4394F6D5D09C0C2885 . 177152 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\$NtServicePackUninstall$\msctfime.ime

[-] 2008-04-14 00:11:53 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\eventlog.dll
[-] 2008-04-14 00:11:53 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[-] 2008-04-14 00:11:53 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\eventlog.dll
[-] 2008-04-14 00:11:53 . 6D4FEB43EE538FC5428CC7F0565AA656 . 56320 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\dllcache\eventlog.dll

[-] 2008-04-14 00:12:05 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\sfcfiles.dll
[-] 2008-04-14 00:12:05 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ServicePackFiles\i386\sfcfiles.dll
[-] 2008-04-14 00:12:05 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\sfcfiles.dll
[-] 2008-04-14 00:12:05 . 9DD07AF82244867CA36681EA2D29CE79 . 1614848 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\dllcache\sfcfiles.dll

[-] 2008-04-13 19:19:42 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\ipsec.sys
[-] 2008-04-13 19:19:42 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\ipsec.sys
[-] 2008-04-13 19:19:42 . 23C74D75E36E7158768DD63D92789A91 . 75264 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\drivers\ipsec.sys
[-] 2004-08-10 10:00:00 . 64537AA5C003A6AFEEE1DF819062D0D1 . 74752 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\$NtServicePackUninstall$\ipsec.sys

[-] 2008-04-14 00:12:04 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\regsvc.dll
[-] 2008-04-14 00:12:04 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ServicePackFiles\i386\regsvc.dll
[-] 2008-04-14 00:12:04 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\regsvc.dll
[-] 2008-04-14 00:12:04 . 5B19B557B0C188210A56A6B699D90B8F . 59904 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\dllcache\regsvc.dll

[-] 2008-04-14 00:12:05 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ERDNT\cache\schedsvc.dll
[-] 2008-04-14 00:12:05 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ServicePackFiles\i386\schedsvc.dll
[-] 2008-04-14 00:12:05 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\system32\schedsvc.dll
[-] 2008-04-14 00:12:05 . 0A9A7365A1CA4319AA7C1D6CD8E4EAFA . 192512 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\system32\dllcache\schedsvc.dll

[-] 2008-04-14 00:12:07 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\ssdpsrv.dll
[-] 2008-04-14 00:12:07 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\ssdpsrv.dll
[-] 2008-04-14 00:12:07 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\ssdpsrv.dll
[-] 2008-04-14 00:12:07 . 0A5679B3714EDAB99E357057EE88FCA6 . 71680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\ssdpsrv.dll

[-] 2008-04-14 00:12:07 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\termsrv.dll
[-] 2008-04-14 00:12:07 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ServicePackFiles\i386\termsrv.dll
[-] 2008-04-14 00:12:07 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\termsrv.dll
[-] 2008-04-14 00:12:07 . FF3477C03BE7201C294C35F684B3479F . 295424 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\dllcache\termsrv.dll

[-] 2008-04-14 00:11:54 . 3CB32D3B8CBE79899D63280BB7A83CD9 . 344064 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\hnetcfg.dll
[-] 2008-04-14 00:11:54 . 3CB32D3B8CBE79899D63280BB7A83CD9 . 344064 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\hnetcfg.dll
[-] 2008-04-14 00:11:54 . 3CB32D3B8CBE79899D63280BB7A83CD9 . 344064 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\hnetcfg.dll
[-] 2008-04-14 00:11:54 . 3CB32D3B8CBE79899D63280BB7A83CD9 . 344064 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\hnetcfg.dll

[-] 2008-04-14 00:11:49 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\appmgmts.dll
[-] 2008-04-14 00:11:49 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ServicePackFiles\i386\appmgmts.dll
[-] 2008-04-14 00:11:49 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\system32\appmgmts.dll
[-] 2008-04-14 00:11:49 . D8849F77C0B66226335A59D26CB4EDC6 . 167936 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\system32\dllcache\appmgmts.dll

[-] 2004-08-10 10:00:00 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0 (xpclient.010817-1148)] . . C:\WINDOWS\ERDNT\cache\acpiec.sys
[-] 2004-08-10 10:00:00 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0 (xpclient.010817-1148)] . . C:\WINDOWS\system32\dllcache\acpiec.sys
[-] 2004-08-10 10:00:00 . 9859C0F6936E723E4892D7141B1327D5 . 11648 . . [5.1.2600.0 (xpclient.010817-1148)] . . C:\WINDOWS\system32\drivers\acpiec.sys

[-] 2008-04-13 16:39:23 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . C:\WINDOWS\ERDNT\cache\aec.sys
[-] 2008-04-13 16:39:23 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . C:\WINDOWS\ServicePackFiles\i386\aec.sys
[-] 2008-04-13 16:39:23 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . C:\WINDOWS\system32\dllcache\aec.sys
[-] 2008-04-13 16:39:23 . 8BED39E3C35D6A489438B8141717A557 . 142592 . . [5.1.2601.3142] . . C:\WINDOWS\system32\drivers\aec.sys

[-] 2008-04-13 18:36:38 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\agp440.sys
[-] 2008-04-13 18:36:38 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[-] 2008-04-13 18:36:38 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\dllcache\agp440.sys
[-] 2008-04-13 18:36:38 . 08FD04AA961BDC77FB983F328334E3D7 . 42368 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\drivers\agp440.sys

[-] 2008-04-13 18:53:34 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\ip6fw.sys
[-] 2008-04-13 18:53:34 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys
[-] 2008-04-13 18:53:34 . 3BB22519A194418D5FEC05D800A19AD0 . 36608 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\ip6fw.sys

[-] 2010-09-18 07:18:30 . 842900DEDBC8E3E8DBCCCB298FD88F65 . 953856 . . [4.1.6151] . . C:\WINDOWS\$hf_mig$\KB2387149\SP3QFE\mfc40u.dll
[-] 2010-09-18 06:53:25 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . C:\WINDOWS\ERDNT\cache\mfc40u.dll
[-] 2010-09-18 06:53:25 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . C:\WINDOWS\system32\mfc40u.dll
[-] 2010-09-18 06:53:25 . E76A5C202E68AF5A322D16B5A78F48B9 . 953856 . . [4.1.6151] . . C:\WINDOWS\system32\dllcache\mfc40u.dll

[-] 2008-04-14 00:11:59 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\msgsvc.dll
[-] 2008-04-14 00:11:59 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ServicePackFiles\i386\msgsvc.dll
[-] 2008-04-14 00:11:59 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\system32\msgsvc.dll
[-] 2008-04-14 00:11:59 . 986B1FF5814366D71E0AC5755C88F2D3 . 33792 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\system32\dllcache\msgsvc.dll

[-] 2005-08-03 23:29:52 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . C:\WINDOWS\ERDNT\cache\MsPMSNSv.dll
[-] 2005-08-03 23:29:52 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\MsPMSNSv.dll
[-] 2005-08-03 23:29:52 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . C:\WINDOWS\system32\MsPMSNSv.dll
[-] 2005-08-03 23:29:52 . B9715B9C18BC6C8F4B66733D208CC9F7 . 25088 . . [10.0.3790.4332] . . C:\WINDOWS\system32\dllcache\mspmsnsv.dll

[-] 2013-07-04 02:08:30 . 4C47B37CF351FFEB1227CED0FF4751D5 . 2070144 . . [5.1.2600.6419 (xpsp_sp3_qfe.130704-0421)] . . C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe
[-] 2013-07-04 02:08:30 . 05F3DB567EAE368AE3BBD7E973490646 . 2028544 . . [5.1.2600.6419 (xpsp_sp3_qfe.130704-0421)] . . C:\WINDOWS\system32\ntkrnlpa.exe
[-] 2013-07-04 02:08:30 . 4C47B37CF351FFEB1227CED0FF4751D5 . 2070144 . . [5.1.2600.6419 (xpsp_sp3_qfe.130704-0421)] . . C:\WINDOWS\system32\dllcache\ntkrnlpa.exe

[-] 2008-04-14 00:12:02 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . C:\WINDOWS\ERDNT\cache\ntmssvc.dll
[-] 2008-04-14 00:12:02 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . C:\WINDOWS\ServicePackFiles\i386\ntmssvc.dll
[-] 2008-04-14 00:12:02 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . C:\WINDOWS\system32\ntmssvc.dll
[-] 2008-04-14 00:12:02 . 156F64A3345BD23C600655FB4D10BC08 . 435200 . . [5.1.2400.5512] . . C:\WINDOWS\system32\dllcache\ntmssvc.dll

[-] 2008-04-14 00:12:08 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\upnphost.dll
[-] 2008-04-14 00:12:08 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\upnphost.dll
[-] 2008-04-14 00:12:08 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\upnphost.dll
[-] 2008-04-14 00:12:08 . 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 . 185856 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\upnphost.dll

[-] 2008-04-14 00:11:52 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ERDNT\cache\dsound.dll
[-] 2008-04-14 00:11:52 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ServicePackFiles\i386\dsound.dll
[-] 2008-04-14 00:11:52 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\dsound.dll
[-] 2008-04-14 00:11:52 . 4D83ED8BDDEC431FC8AD907B47CFB6E3 . 367616 . . [5.3.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\dllcache\dsound.dll

[-] 2008-04-14 00:11:51 . 0607CBC6FA20114CB491EFE4B2F9EFAD . 1689088 . . [5.03.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ERDNT\cache\d3d9.dll
[-] 2008-04-14 00:11:51 . 0607CBC6FA20114CB491EFE4B2F9EFAD . 1689088 . . [5.03.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ServicePackFiles\i386\d3d9.dll
[-] 2008-04-14 00:11:51 . 0607CBC6FA20114CB491EFE4B2F9EFAD . 1689088 . . [5.03.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\d3d9.dll

[-] 2008-04-14 00:11:51 . A340CD71EB535A3DD751B5F28723E50C . 279552 . . [5.03.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ERDNT\cache\ddraw.dll
[-] 2008-04-14 00:11:51 . A340CD71EB535A3DD751B5F28723E50C . 279552 . . [5.03.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ServicePackFiles\i386\ddraw.dll
[-] 2008-04-14 00:11:51 . A340CD71EB535A3DD751B5F28723E50C . 279552 . . [5.03.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\ddraw.dll
[-] 2008-04-14 00:11:51 . A340CD71EB535A3DD751B5F28723E50C . 279552 . . [5.03.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\dllcache\ddraw.dll

[-] 2008-04-14 00:12:02 . 5652F6CE1D9E9D8068B9D29BC21B5409 . 84992 . . [5.1.2600.5512] . . C:\WINDOWS\ERDNT\cache\olepro32.dll
[-] 2008-04-14 00:12:02 . 5652F6CE1D9E9D8068B9D29BC21B5409 . 84992 . . [5.1.2600.5512] . . C:\WINDOWS\ServicePackFiles\i386\olepro32.dll
[-] 2008-04-14 00:12:02 . 5652F6CE1D9E9D8068B9D29BC21B5409 . 84992 . . [5.1.2600.5512] . . C:\WINDOWS\system32\olepro32.dll
[-] 2008-04-14 00:12:02 . 5652F6CE1D9E9D8068B9D29BC21B5409 . 84992 . . [5.1.2600.5512] . . C:\WINDOWS\system32\dllcache\olepro32.dll

[-] 2008-04-14 00:12:02 . DBE2B62353660ECCA0D75EA307A717E9 . 39936 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ERDNT\cache\perfctrs.dll
[-] 2008-04-14 00:12:02 . DBE2B62353660ECCA0D75EA307A717E9 . 39936 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\ServicePackFiles\i386\perfctrs.dll
[-] 2008-04-14 00:12:02 . DBE2B62353660ECCA0D75EA307A717E9 . 39936 . . [5.1.2600.5512 (xpsp.080413-2111)] . . C:\WINDOWS\system32\perfctrs.dll

[-] 2008-04-14 00:12:08 . C7CE131408739B0B3A318BE2D0032719 . 18944 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\version.dll
[-] 2008-04-14 00:12:08 . C7CE131408739B0B3A318BE2D0032719 . 18944 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ServicePackFiles\i386\version.dll
[-] 2008-04-14 00:12:08 . C7CE131408739B0B3A318BE2D0032719 . 18944 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\system32\version.dll
[-] 2008-04-14 00:12:08 . C7CE131408739B0B3A318BE2D0032719 . 18944 . . [5.1.2600.5512 (xpsp.080413-2105)] . . C:\WINDOWS\system32\dllcache\version.dll

[7] 2010-02-23 05:20:02 . B5116340B84824DDD0A641E36B126194 . 634648 . . [7.00.6000.17023 (vista_gdr.100222-0012)] . . C:\WINDOWS\ie8\iexplore.exe
[7] 2010-02-23 05:19:59 . C8DDA4028065D5CE39CBE7A156B72AB9 . 634648 . . [7.00.6000.21228 (vista_ldr.100222-0012)] . . C:\WINDOWS\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[7] 2009-12-18 13:05:43 . 53C291F3B01EECECBD7FD358EA3ACC94 . 634648 . . [7.00.6000.16981 (vista_gdr.091215-2244)] . . C:\WINDOWS\ie7updates\KB980182-IE7\iexplore.exe
[7] 2009-12-18 07:00:27 . D19E56D5930C37CF211867DF450C372A . 634632 . . [7.00.6000.21183 (vista_ldr.091216-2236)] . . C:\WINDOWS\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[7] 2009-10-28 06:54:21 . 80675329E0FD54F016C4F8A83C616349 . 634632 . . [7.00.6000.21148 (vista_ldr.091027-0032)] . . C:\WINDOWS\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[7] 2009-10-28 06:54:16 . 4F9B04D546C23A295F3F0AE015BE51DB . 634632 . . [7.00.6000.16945 (vista_gdr.091027-0049)] . . C:\WINDOWS\ie7updates\KB978207-IE7\iexplore.exe
[7] 2009-08-27 05:18:44 . F232BA9F39BC0F722672C7E79E68EBEA . 634648 . . [7.00.6000.16915 (vista_gdr.090826-0339)] . . C:\WINDOWS\ie7updates\KB976325-IE7\iexplore.exe
[7] 2009-08-27 05:18:42 . 332EC7562F3AA7364F2D4231C56DA986 . 634648 . . [7.00.6000.21115 (vista_ldr.090826-0339)] . . C:\WINDOWS\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[7] 2009-06-29 08:35:10 . 3CFC56F73D494FC1AA2B6E981DF15ACD . 634632 . . [7.00.6000.16876 (vista_gdr.090625-2339)] . . C:\WINDOWS\ie7updates\KB974455-IE7\iexplore.exe
[7] 2009-06-29 07:25:31 . 02E2754D3E566C11A4934825920C47DD . 634632 . . [7.00.6000.21073 (vista_ldr.090625-2339)] . . C:\WINDOWS\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[7] 2009-04-25 05:27:50 . 092A7F2B49A19ECCE5369D3CB2276148 . 636088 . . [7.00.6000.16850 (vista_gdr.090423-0018)] . . C:\WINDOWS\ie7updates\KB972260-IE7\iexplore.exe
[7] 2009-04-25 05:27:39 . C0503FD8D163652735C1EE900672A75C . 636088 . . [7.00.6000.21045 (vista_ldr.090423-0018)] . . C:\WINDOWS\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[7] 2009-03-08 18:09:26 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)] . . C:\WINDOWS\ERDNT\cache\iexplore.exe
[7] 2009-03-08 18:09:26 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)] . . C:\WINDOWS\system32\dllcache\iexplore.exe
[7] 2009-02-28 04:54:44 . BCD8E48709BE4A79606F0B6E8E9A6162 . 636088 . . [7.00.6000.21020 (vista_ldr.090226-1506)] . . C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[7] 2009-02-28 04:54:41 . A251068640DDB69FD7805B57D89D7FF7 . 636072 . . [7.00.6000.16827 (vista_gdr.090226-1506)] . . C:\WINDOWS\ie7updates\KB969897-IE7\iexplore.exe
[7] 2008-12-19 05:25:30 . 15E8A89499741D5CF59A9CF6463A4339 . 634024 . . [7.00.6000.20978 (vista_ldr.081217-1620)] . . C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[7] 2008-12-19 05:25:25 . 030D78FE84A086ED376EFCBD2D72C522 . 634024 . . [7.00.6000.16791 (vista_gdr.081217-1620)] . . C:\WINDOWS\ie7updates\KB963027-IE7\iexplore.exe
[7] 2008-10-15 07:06:26 . 9D3DB9ADFABD2F0BC778EC03250A3ABB . 633632 . . [7.00.6000.16762 (vista_gdr.081013-1507)] . . C:\WINDOWS\ie7updates\KB961260-IE7\iexplore.exe
[7] 2008-10-15 06:34:58 . 056C927CF7207857E8B34F7A8FFD9B9E . 633632 . . [7.00.6000.20935 (vista_ldr.081013-1507)] . . C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[7] 2008-08-23 05:56:16 . E8305C30D35E85D6657ED3E9934CB302 . 635848 . . [7.00.6000.20900 (vista_ldr.080820-1506)] . . C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[7] 2008-08-23 05:56:15 . 1F03216084447F990AE797317D0A6E70 . 635848 . . [7.00.6000.16735 (vista_gdr.080820-1506)] . . C:\WINDOWS\ie7updates\KB958215-IE7\iexplore.exe
[-] 2008-06-23 09:20:52 . 64E376A47763DAEABCDA14BD5B6EA286 . 625664 . . [7.00.6000.16705 (vista_gdr.080618-1506)] . . C:\WINDOWS\ie7updates\KB956390-IE7\iexplore.exe
[-] 2008-06-23 08:23:52 . C52A9EF571E91535EB78DB4B8B95EA07 . 625664 . . [7.00.6000.20861 (vista_ldr.080618-1506)] . . C:\WINDOWS\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe

[-] 2013-07-04 03:03:25 . AFEE19399CF992A098309F7FDF87880A . 2149888 . . [5.1.2600.6419 (xpsp_sp3_qfe.130704-0421)] . . C:\WINDOWS\system32\ntoskrnl.exe
[-] 2013-07-04 02:59:11 . A4A50A53FFBFEC545CDA85E98AF2106B . 2193536 . . [5.1.2600.6419 (xpsp_sp3_qfe.130704-0421)] . . C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe
[-] 2013-07-04 02:59:11 . A4A50A53FFBFEC545CDA85E98AF2106B . 2193536 . . [5.1.2600.6419 (xpsp_sp3_qfe.130704-0421)] . . C:\WINDOWS\system32\dllcache\ntoskrnl.exe

[-] 2008-04-14 00:12:07 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ERDNT\cache\srsvc.dll
[-] 2008-04-14 00:12:07 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\ServicePackFiles\i386\srsvc.dll
[-] 2008-04-14 00:12:07 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\system32\srsvc.dll
[-] 2008-04-14 00:12:07 . 3805DF0AC4296A34BA4BF93B346CC378 . 171008 . . [5.1.2600.5512 (xpsp.080413-2108)] . . C:\WINDOWS\system32\dllcache\srsvc.dll

[-] 2008-04-14 00:12:08 . 54AF4B1D5459500EF0937F6D33B1914F . 175104 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ERDNT\cache\w32time.dll
[-] 2008-04-14 00:12:08 . 54AF4B1D5459500EF0937F6D33B1914F . 175104 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\ServicePackFiles\i386\w32time.dll
[-] 2008-04-14 00:12:08 . 54AF4B1D5459500EF0937F6D33B1914F . 175104 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\system32\w32time.dll
[-] 2008-04-14 00:12:08 . 54AF4B1D5459500EF0937F6D33B1914F . 175104 . . [5.1.2600.5512 (xpsp.080413-2113)] . . C:\WINDOWS\system32\dllcache\w32time.dll

[-] 2008-04-14 00:12:08 . 8BAD69CBAC032D4BBACFCE0306174C30 . 333824 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\wiaservc.dll
[-] 2008-04-14 00:12:08 . 8BAD69CBAC032D4BBACFCE0306174C30 . 333824 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\wiaservc.dll
[-] 2008-04-14 00:12:08 . 8BAD69CBAC032D4BBACFCE0306174C30 . 333824 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\wiaservc.dll

[-] 2008-04-14 00:11:57 . 5C12660A97822F6E61576943B49AAAD6 . 18944 . . [5.1.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ERDNT\cache\midimap.dll
[-] 2008-04-14 00:11:57 . 5C12660A97822F6E61576943B49AAAD6 . 18944 . . [5.1.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\ServicePackFiles\i386\midimap.dll
[-] 2008-04-14 00:11:57 . 5C12660A97822F6E61576943B49AAAD6 . 18944 . . [5.1.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\midimap.dll
[-] 2008-04-14 00:11:57 . 5C12660A97822F6E61576943B49AAAD6 . 18944 . . [5.1.2600.5512 (xpsp.080413-0845)] . . C:\WINDOWS\system32\dllcache\midimap.dll

[-] 2008-04-14 00:12:03 . 6F9BEF24C578D5D6740E080BEDD6A448 . 7680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ERDNT\cache\rasadhlp.dll
[-] 2008-04-14 00:12:03 . 6F9BEF24C578D5D6740E080BEDD6A448 . 7680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\rasadhlp.dll
[-] 2008-04-14 00:12:03 . 6F9BEF24C578D5D6740E080BEDD6A448 . 7680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\rasadhlp.dll
[-] 2008-04-14 00:12:03 . 6F9BEF24C578D5D6740E080BEDD6A448 . 7680 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\rasadhlp.dll

[-] 2008-04-14 00:12:10 . 4E3D06D6E68EEDB52565080F55B460D3 . 19456 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\ServicePackFiles\i386\wshtcpip.dll
[-] 2008-04-14 00:12:10 . 4E3D06D6E68EEDB52565080F55B460D3 . 19456 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\wshtcpip.dll
[-] 2008-04-14 00:12:10 . 4E3D06D6E68EEDB52565080F55B460D3 . 19456 . . [5.1.2600.5512 (xpsp.080413-0852)] . . C:\WINDOWS\system32\dllcache\wshtcpip.dll
[-] 2004-08-10 10:00:00 . A7F95A53EE055115DF03588997A47D4D . 19968 . . [5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)] . . C:\WINDOWS\$NtServicePackUninstall$\wshtcpip.dll

(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ShowLOMControl"="" [X]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 16:48:02 761947]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 06:05:00 127035]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 15:44:02 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 02:44:02 81920]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-06-29 02:29:42 32768]
"SigmatelSysTrayApp"="C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe" [2007-05-10 14:22:32 405504]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-03-31 00:00:02 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-03-31 00:00:16 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-03-30 23:59:36 138008]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-10-08 18:18:04 995328]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-10-08 18:13:36 1101824]
"mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2014-04-25 22:29:36 517392]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 01:59:06 937920]
"mcpltui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2014-04-25 22:29:36 517392]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2014-02-21 07:54:40 152392]
"UVS10 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe" [2006-08-09 13:27:48 36864]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2014-09-26 23:19:22 271744]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2010-11-29 21:38:18 421888]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 06:41:12 49208]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 19:01:14 67584]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2011-08-31 01:57:22 40368]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute   REG_MULTI_SZ      

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec AntiVirus"=2 (0x2)
"SPBBCSvc"=2 (0x2)
"SNDSrvc"=3 (0x3)
"gusvc"=2 (0x2)
"DefWatch"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"ccSetMgr"=2 (0x2)

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsasvr.exe"=
"C:\\Program Files\\Samsung\\Samsung New PC Studio\\npsvsvr.exe"=
"C:\\Documents and Settings\\Kelsie\\Application Data\\Macromedia\\Flash Player\\www.macromedia.com\\bin\\octoshape\\octoshape.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Common Files\\Mcafee\\McSvcHost\\McSvHost.exe"=
"C:\\Program Files\\Common Files\\Mcafee\\Platform\\McSvcHost\\McSvHost.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R?2 mcbootdelaystartsvc;McAfee Boot Delay Start Service;"C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [11/12/2013 8:42:19 AM 281560]
R0 ambakdrv;ambakdrv;C:\WINDOWS\system32\ambakdrv.sys [10/23/2013 6:34:05 PM 26424]
R1 mfetdi2k;McAfee Inc. mfetdi2k;C:\WINDOWS\system32\drivers\mfetdi2k.sys [6/25/2011 10:34:28 AM 93624]
R2 ammntdrv;ammntdrv;C:\WINDOWS\system32\ammntdrv.sys [10/23/2013 6:34:07 PM 129720]
R2 amwrtdrv;amwrtdrv;C:\WINDOWS\system32\amwrtdrv.sys [10/23/2013 6:34:07 PM 14392]
R2 Backupper Service;AOMEI Backupper Scheduler Service;C:\Program Files\AOMEI Backupper\ABService.exe [10/23/2013 6:34:01 PM 29912]
R2 FsUsbExService;FsUsbExService;C:\WINDOWS\system32\FsUsbExService.Exe [10/28/2009 5:21:49 PM 233472]
R2 HomeNetSvc;McAfee Home Network;"C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [11/12/2013 8:42:19 AM 281560]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [6/25/2011 10:36:11 AM 132160]
R2 McAPExe;McAfee AP Service;C:\Program Files\McAfee\MSC\McAPExe.exe [11/12/2013 8:43:10 AM 145568]
R2 McNaiAnn;McAfee VirusScan Announcer;"C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [11/12/2013 8:42:19 AM 281560]
R2 mcpltsvc;McAfee Platform Services;"C:\Program Files\Common Files\Mcafee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [11/12/2013 8:42:19 AM 281560]
R2 mfecore;McAfee Anti-Malware Core;C:\Program Files\Common Files\Mcafee\AMCore\mcshield.exe [11/12/2013 8:44:03 AM 655936]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe [6/25/2011 10:34:51 AM 169800]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\WINDOWS\system32\mfevtps.exe [6/25/2011 10:22:37 AM 179600]
R3 FsUsbExDisk;FsUsbExDisk;C:\WINDOWS\system32\FsUsbExDisk.Sys [10/28/2009 5:21:50 PM 36608]
R3 MBAMProtector;MBAMProtector;C:\WINDOWS\system32\drivers\mbam.sys [6/25/2011 2:46:27 PM 23256]
R3 mfefirek;McAfee Inc. mfefirek;C:\WINDOWS\system32\drivers\mfefirek.sys [6/25/2011 10:34:28 AM 369248]
R3 mfencbdc;McAfee Inc. mfencbdc;C:\WINDOWS\system32\drivers\mfencbdc.sys [9/20/2013 10:37:10 AM 350240]
R3 mfendiskmp;mfendiskmp;C:\WINDOWS\system32\drivers\mfendisk.sys [12/13/2012 8:38:13 PM 87520]
S2 MBAMService;MBAMService;C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [8/11/2015 5:28:08 AM 1133880]
S3 ampa;ampa;C:\WINDOWS\system32\ampa.sys [12/8/2013 9:46:55 PM 12656]
S3 cfwids;McAfee Inc. cfwids;C:\WINDOWS\system32\drivers\cfwids.sys [6/25/2011 10:34:28 AM 62832]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [8/11/2015 5:34:55 AM 98520]
S3 mfencrk;McAfee Inc. mfencrk;C:\WINDOWS\system32\drivers\mfencrk.sys [9/20/2013 10:37:24 AM 81296]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;C:\WINDOWS\system32\drivers\mfendisk.sys [12/13/2012 8:38:13 PM 87520]
S4 MBAMScheduler;MBAMScheduler;C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [8/11/2015 5:28:09 AM 1871160]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - FSUSBEXDISK
*NewlyCreated* - IPOD_SERVICE

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-08-12 01:16:54   995144   ----a-w-   C:\Program Files\Google\Chrome\Application\44.0.2403.155\Installer\chrmstp.exe

Contents of the 'Scheduled Tasks' folder

2015-08-18 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-07 23:39:07 . 2012-10-07 23:38:56]

2015-08-18 C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- C:\Program Files\Google\Update\GoogleUpdate.exe [2012-10-07 23:39:07 . 2012-10-07 23:38:56]

2015-08-18 C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
- C:\WINDOWS\system32\xp_eos.exe [2014-03-10 11:13:23 . 2014-02-26 01:59:05]

2015-07-08 C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
- C:\WINDOWS\system32\xp_eos.exe [2014-03-10 11:13:23 . 2014-02-26 01:59:05]


------- Supplementary Scan -------

uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
TCP: DhcpNameServer = 192.168.1.254

- - - - ORPHANS REMOVED - - - -

HKLM-Run-DellSupportCenter - C:\Program Files\Dell Support Center\bin\sprtcmd.exe
AddRemove-1908894683.fuse.fender.com - c:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exe


                                                                                                                                                                                                                                                                                           

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 7656
Re: [Resolved - K] Slow boot, slow application launch, slow browser
« Reply #14 on: August 18, 2015, 06:29:41 AM »
Combofix log is not complete.. Ok try the following from Normal mode, if it fails try from safe mode...

1.Download Malwarebytes Anti-Rootkit from this link:

 http://www.malwarebytes.org/products/mbar/

2. Unzip the File to a convenient location. (Recommend the Desktop)
3. Open the folder where the contents were unzipped to run mbar.exe



4. Double-click on the mbar.exe file, you may receive a User Account Control prompt asking if you are sure you wish to allow the program to run. Please allow the program to run and MBAR will now start to install any necessary drivers that are required for the program to operate correctly. If a rootkit is interfering with the installation of the drivers you will see a message that states that the DDA driver was not installed and that you should reboot your computer to install it. You will see this image:



5. If you receive this message, please click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer. Once the computer is rebooted and you login, MBAR will automatically start and you will now be at the start screen. (If no Rootkit warning you will go from step 4 to 6.)

6. The following image opens, select Next.



7. The following image opens, select Update



8. When the update completes select Next.



9. In the following window ensure "Targets" are ticked. Then select "Scan"



10. If an infection is found select the "Cleanup Button" to remove threats, Reboot if prompted. Wait while the system shuts down and the cleanup process is performed.



11. Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click "Cleanup Button" once more and repeat the process.
12. If no threats were found you will see the following image, Select Exit:



13. Verify that your system is now running normally, making sure that the following items are functional:

  • Internet access
  • Windows Update
  • Windows Firewall

14.  If there are additional problems with your system, such as any of those listed above or other system issues, then run the 'fixdamage' tool included within Malwarebytes Anti-Rootkit folder.

15. Select "Y" from your Keyboard, tap Enter.

16. The fix will be applied, select any key to Exit.

17. Let me know how your system now responds. Copy and paste the two following logs from the mbar folder:

System - log
Mbar - log   Date and time of scan will also be shown

Thanks,

Kevin...