Author Topic: [Resolved] AVG found Trojan Horse Crypt.ASHD  (Read 4765 times)

0 Members and 1 Guest are viewing this topic.

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #30 on: March 29, 2012, 05:54:57 PM »
.
---- Directory of c:\program files\Jasc Software Inc\Paint Shop Pro Studio ----
.
2004-09-14 06:00 . 2004-09-14 06:00   260531   ----a-r-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   85618   ----a-w-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   1012   ----a-w-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   1375   ----a-w-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   657   ----a-w-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   545   ----a-w-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   4876   ----a-w-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   12280   ----a-r-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   1354   ----a-r-   c:\program files\Jasc
2004-09-14 06:00 . 2004-09-14 06:00   1110   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\cp869.enc
2004-09-14 06:00 . 2004-09-14 06:00   1110   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\cp874.enc
2004-09-14 06:00 . 2004-09-14 06:00   49008   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\cp932.enc
2004-09-14 06:00 . 2004-09-14 06:00   134671   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\cp936.enc
2004-09-14 06:00 . 2004-09-14 06:00   132551   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\cp949.enc
2004-09-14 06:00 . 2004-09-14 06:00   93330   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\cp950.enc
2004-09-14 06:00 . 2004-09-14 06:00   1113   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\dingbats.enc
2004-09-14 06:00 . 2004-09-14 06:00   1073   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\ebcdic.enc
2004-09-14 06:00 . 2004-09-14 06:00   86971   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\euc-cn.enc
2004-09-14 06:00 . 2004-09-14 06:00   83890   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\euc-jp.enc
2004-09-14 06:00 . 2004-09-14 06:00   95451   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\euc-kr.enc
2004-09-14 06:00 . 2004-09-14 06:00   88033   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\gb12345.enc
2004-09-14 06:00 . 2004-09-14 06:00   1111   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\gb1988.enc
2004-09-14 06:00 . 2004-09-14 06:00   85912   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\gb2312-raw.enc
2004-09-14 06:00 . 2004-09-14 06:00   86971   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\gb2312.enc
2004-09-14 06:00 . 2004-09-14 06:00   204   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso2022-jp.enc
2004-09-14 06:00 . 2004-09-14 06:00   122   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso2022-kr.enc
2004-09-14 06:00 . 2004-09-14 06:00   240   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso2022.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-1.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-10.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-13.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-14.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-15.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-16.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-2.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-3.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-4.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-5.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-6.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-7.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-8.enc
2004-09-14 06:00 . 2004-09-14 06:00   1114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\iso8859-9.enc
2004-09-14 06:00 . 2004-09-14 06:00   1112   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\jis0201.enc
2004-09-14 06:00 . 2004-09-14 06:00   81778   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\jis0208.enc
2004-09-14 06:00 . 2004-09-14 06:00   72133   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\jis0212.enc
2004-09-14 06:00 . 2004-09-14 06:00   1111   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\koi8-r.enc
2004-09-14 06:00 . 2004-09-14 06:00   1111   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\koi8-u.enc
2004-09-14 06:00 . 2004-09-14 06:00   94393   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\ksc5601.enc
2004-09-14 06:00 . 2004-09-14 06:00   1116   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macCentEuro.enc
2004-09-14 06:00 . 2004-09-14 06:00   1116   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macCroatian.enc
2004-09-14 06:00 . 2004-09-14 06:00   1116   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macCyrillic.enc
2004-09-14 06:00 . 2004-09-14 06:00   1116   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macDingbats.enc
2004-09-14 06:00 . 2004-09-14 06:00   1113   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macGreek.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macIceland.enc
2004-09-14 06:00 . 2004-09-14 06:00   48813   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macJapan.enc
2004-09-14 06:00 . 2004-09-14 06:00   1113   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macRoman.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macRomania.enc
2004-09-14 06:00 . 2004-09-14 06:00   1112   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macThai.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macTurkish.enc
2004-09-14 06:00 . 2004-09-14 06:00   1115   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\macUkraine.enc
2004-09-14 06:00 . 2004-09-14 06:00   42552   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\shiftjis.enc
2004-09-14 06:00 . 2004-09-14 06:00   1111   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\symbol.enc
2004-09-14 06:00 . 2004-09-14 06:00   1110   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\encoding\tis-620.enc
2004-09-14 06:00 . 2004-09-14 06:00   10138   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\http1.0\http.tcl
2004-09-14 06:00 . 2004-09-14 06:00   746   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\http1.0\pkgIndex.tcl
2004-09-14 06:00 . 2004-09-14 06:00   24433   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\http2.4\http.tcl
2004-09-14 06:00 . 2004-09-14 06:00   738   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\http2.4\pkgIndex.tcl
2004-09-14 06:00 . 2004-09-14 06:00   13138   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\msgcat1.3\msgcat.tcl
2004-09-14 06:00 . 2004-09-14 06:00   134   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\msgcat1.3\pkgIndex.tcl
2004-09-14 06:00 . 2004-09-14 06:00   34090   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\opt0.4\optparse.tcl
2004-09-14 06:00 . 2004-09-14 06:00   617   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\opt0.4\pkgIndex.tcl
2004-09-14 06:00 . 2004-09-14 06:00   622   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\tcltest2.2\pkgIndex.tcl
2004-09-14 06:00 . 2004-09-14 06:00   101574   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tcl8.4\tcltest2.2\tcltest.tcl
2004-09-14 06:00 . 2004-09-14 06:00   9423   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\bgerror.tcl
2004-09-14 06:00 . 2004-09-14 06:00   17337   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\button.tcl
2004-09-14 06:00 . 2004-09-14 06:00   9268   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\choosedir.tcl
2004-09-14 06:00 . 2004-09-14 06:00   22063   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\clrpick.tcl
2004-09-14 06:00 . 2004-09-14 06:00   8009   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\comdlg.tcl
2004-09-14 06:00 . 2004-09-14 06:00   27882   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\console.tcl
2004-09-14 06:00 . 2004-09-14 06:00   6673   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\dialog.tcl
2004-09-14 06:00 . 2004-09-14 06:00   17672   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\entry.tcl
2004-09-14 06:00 . 2004-09-14 06:00   5253   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\focus.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2248   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\license.terms
2004-09-14 06:00 . 2004-09-14 06:00   14129   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\listbox.tcl
2004-09-14 06:00 . 2004-09-14 06:00   38345   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\menu.tcl
2004-09-14 06:00 . 2004-09-14 06:00   28627   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\mkpsenc.tcl
2004-09-14 06:00 . 2004-09-14 06:00   16349   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgbox.tcl
2004-09-14 06:00 . 2004-09-14 06:00   824   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\obsolete.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1704   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\optMenu.tcl
2004-09-14 06:00 . 2004-09-14 06:00   8246   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\palette.tcl
2004-09-14 06:00 . 2004-09-14 06:00   5155   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\panedwindow.tcl
2004-09-14 06:00 . 2004-09-14 06:00   145   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\pkgIndex.tcl
2004-09-14 06:00 . 2004-09-14 06:00   7817   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\safetk.tcl
2004-09-14 06:00 . 2004-09-14 06:00   7784   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\scale.tcl
2004-09-14 06:00 . 2004-09-14 06:00   12181   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\scrlbar.tcl
2004-09-14 06:00 . 2004-09-14 06:00   15722   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\spinbox.tcl
2004-09-14 06:00 . 2004-09-14 06:00   22487   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\tclIndex
2004-09-14 06:00 . 2004-09-14 06:00   4841   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\tearoff.tcl
2004-09-14 06:00 . 2004-09-14 06:00   32020   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\text.tcl
2004-09-14 06:00 . 2004-09-14 06:00   17470   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\tk.tcl
2004-09-14 06:00 . 2004-09-14 06:00   50716   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\tkfbox.tcl
2004-09-14 06:00 . 2004-09-14 06:00   11759   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\unsupported.tcl
2004-09-14 06:00 . 2004-09-14 06:00   26219   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\xmfbox.tcl
2004-09-14 06:00 . 2004-09-14 06:00   8377   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\arrow.tcl
2004-09-14 06:00 . 2004-09-14 06:00   3165   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\bind.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1682   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\bitmap.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1863   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\browse
2004-09-14 06:00 . 2004-09-14 06:00   1520   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\button.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1402   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\check.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1682   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\clrpick.tcl
2004-09-14 06:00 . 2004-09-14 06:00   5294   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\colors.tcl
2004-09-14 06:00 . 2004-09-14 06:00   3290   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\cscroll.tcl
2004-09-14 06:00 . 2004-09-14 06:00   5215   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\ctext.tcl
2004-09-14 06:00 . 2004-09-14 06:00   746   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\dialog1.tcl
2004-09-14 06:00 . 2004-09-14 06:00   699   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\dialog2.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1619   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\entry1.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2357   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\entry2.tcl
2004-09-14 06:00 . 2004-09-14 06:00   6321   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\entry3.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2203   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\filebox.tcl
2004-09-14 06:00 . 2004-09-14 06:00   80729   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\floor.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1282   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\form.tcl
2004-09-14 06:00 . 2004-09-14 06:00   569   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\hello
2004-09-14 06:00 . 2004-09-14 06:00   1738   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\hscale.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2258   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\icon.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1184   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\image1.tcl
2004-09-14 06:00 . 2004-09-14 06:00   3459   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\image2.tcl
2004-09-14 06:00 . 2004-09-14 06:00   10149   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\items.tcl
2004-09-14 06:00 . 2004-09-14 06:00   8541   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\ixset
2004-09-14 06:00 . 2004-09-14 06:00   1502   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\label.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2167   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\labelframe.tcl
2004-09-14 06:00 . 2004-09-14 06:00   6963   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\menu.tcl
2004-09-14 06:00 . 2004-09-14 06:00   4625   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\menubu.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2240   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\msgbox.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1338   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\paned1.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2489   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\paned2.tcl
2004-09-14 06:00 . 2004-09-14 06:00   3049   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\plot.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2885   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\puzzle.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2471   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\radio.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2181   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\README
2004-09-14 06:00 . 2004-09-14 06:00   5520   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\rmt
2004-09-14 06:00 . 2004-09-14 06:00   8305   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\rolodex
2004-09-14 06:00 . 2004-09-14 06:00   5542   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\ruler.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2443   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\sayings.tcl
2004-09-14 06:00 . 2004-09-14 06:00   4737   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\search.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2022   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\spin.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1279   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\square
2004-09-14 06:00 . 2004-09-14 06:00   1910   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\states.tcl
2004-09-14 06:00 . 2004-09-14 06:00   7114   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\style.tcl
2004-09-14 06:00 . 2004-09-14 06:00   4421   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\tclIndex
2004-09-14 06:00 . 2004-09-14 06:00   11905   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\tcolor
2004-09-14 06:00 . 2004-09-14 06:00   3726   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\text.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1175   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\timer
2004-09-14 06:00 . 2004-09-14 06:00   6950   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\twind.tcl
2004-09-14 06:00 . 2004-09-14 06:00   2847   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\unicodeout.tcl
2004-09-14 06:00 . 2004-09-14 06:00   1719   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\vscale.tcl
2004-09-14 06:00 . 2004-09-14 06:00   12929   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\widget
2004-09-14 06:00 . 2004-09-14 06:00   51712   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\earth.gif
2004-09-14 06:00 . 2004-09-14 06:00   6343   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\earthris.gif
2004-09-14 06:00 . 2004-09-14 06:00   12720   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\face.bmp
2004-09-14 06:00 . 2004-09-14 06:00   1886   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\flagdown.bmp
2004-09-14 06:00 . 2004-09-14 06:00   1880   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\flagup.bmp
2004-09-14 06:00 . 2004-09-14 06:00   275   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\gray25.bmp
2004-09-14 06:00 . 2004-09-14 06:00   1883   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\letters.bmp
2004-09-14 06:00 . 2004-09-14 06:00   1889   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\noletter.bmp
2004-09-14 06:00 . 2004-09-14 06:00   272   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\pattern.bmp
2004-09-14 06:00 . 2004-09-14 06:00   2341   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\tcllogo.gif
2004-09-14 06:00 . 2004-09-14 06:00   196623   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\demos\images\teapot.ppm
2004-09-14 06:00 . 2004-09-14 06:00   34991   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\logo.eps
2004-09-14 06:00 . 2004-09-14 06:00   2341   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\logo100.gif
2004-09-14 06:00 . 2004-09-14 06:00   1670   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\logo64.gif
2004-09-14 06:00 . 2004-09-14 06:00   11000   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\logoLarge.gif
2004-09-14 06:00 . 2004-09-14 06:00   3889   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\logoMed.gif
2004-09-14 06:00 . 2004-09-14 06:00   29706   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\pwrdLogo.eps
2004-09-14 06:00 . 2004-09-14 06:00   1615   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\pwrdLogo100.gif
2004-09-14 06:00 . 2004-09-14 06:00   2489   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\pwrdLogo150.gif
2004-09-14 06:00 . 2004-09-14 06:00   2981   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\pwrdLogo175.gif
2004-09-14 06:00 . 2004-09-14 06:00   3491   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\pwrdLogo200.gif
2004-09-14 06:00 . 2004-09-14 06:00   1171   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\pwrdLogo75.gif
2004-09-14 06:00 . 2004-09-14 06:00   400   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\README
2004-09-14 06:00 . 2004-09-14 06:00   5473   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\images\tai-ku.gif
2004-09-14 06:00 . 2004-09-14 06:00   3901   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\cs.msg
2004-09-14 06:00 . 2004-09-14 06:00   3798   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\de.msg
2004-09-14 06:00 . 2004-09-14 06:00   8696   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\el.msg
2004-09-14 06:00 . 2004-09-14 06:00   2610   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\en.msg
2004-09-14 06:00 . 2004-09-14 06:00   66   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\en_gb.msg
2004-09-14 06:00 . 2004-09-14 06:00   3774   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\es.msg
2004-09-14 06:00 . 2004-09-14 06:00   3797   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\fr.msg
2004-09-14 06:00 . 2004-09-14 06:00   3614   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\it.msg
2004-09-14 06:00 . 2004-09-14 06:00   7066   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\nl.msg
2004-09-14 06:00 . 2004-09-14 06:00   7178   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Python Libraries\tcl\tk8.4\msgs\ru.msg
2004-09-14 06:00 . 2004-09-14 06:00   4893   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Crop\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   865   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Crop\Images\Crop_tool.gif
2004-09-14 06:00 . 2004-09-14 06:00   775   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Crop\Scripts\SelectCrop.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4438   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Download from camera\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   927   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Download from camera\images\camera.gif
2004-09-14 06:00 . 2004-09-14 06:00   3123   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Import from scanner\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   919   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Import from scanner\images\scanner.gif
2004-09-14 06:00 . 2004-09-14 06:00   4181   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Open\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   932   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Open\Images\CreateFileBrowse.gif
2004-09-14 06:00 . 2004-09-14 06:00   892   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Open\Images\CreateFileOpen.gif
2004-09-14 06:00 . 2004-09-14 06:00   1966   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Open\Scripts\Open.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   5726   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Resize\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   890   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Resize\Images\Resize_icon.gif
2004-09-14 06:00 . 2004-09-14 06:00   1329   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Resize\Scripts\Resize.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   3641   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Rotate\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   971   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Rotate\Images\Rotate.gif
2004-09-14 06:00 . 2004-09-14 06:00   3239   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Save\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   920   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Save\Images\saveasicon.gif
2004-09-14 06:00 . 2004-09-14 06:00   923   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Save\Images\saveicon.gif
2004-09-14 06:00 . 2004-09-14 06:00   6173   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Zoom in\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   938   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Zoom in\Images\handicon.gif
2004-09-14 06:00 . 2004-09-14 06:00   879   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Zoom in\Images\quickguide.gif
2004-09-14 06:00 . 2004-09-14 06:00   934   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Zoom in\Images\ZoomTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   774   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Zoom in\Scripts\SelectPan.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   775   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Basics\Zoom in\Scripts\SelectZoom.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4629   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Embellishments\index.htm

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #31 on: March 29, 2012, 05:56:34 PM »
2004-09-14 06:00 . 2004-09-14 06:00   967   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Embellishments\Images\picturetubesicon.gif
2004-09-14 06:00 . 2004-09-14 06:00   4791   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Picture Frames\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1202   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Picture Frames\Scripts\PictureFrame.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   5709   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Talk Bubbles\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   900   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Talk Bubbles\Images\presetshapesicon.gif
2004-09-14 06:00 . 2004-09-14 06:00   777   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Talk Bubbles\Scripts\SelectTextEx.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   5400   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Enhance\Text\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   3215   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Add flash\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   941   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Add flash\Images\flashTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   896   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Add flash\Scripts\FillFlash.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   3951   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Fix a photo\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   964   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Fix a photo\Images\OneStepPhotoFixButton.gif
2004-09-14 06:00 . 2004-09-14 06:00   937   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Fix a photo\Images\undo-redoicons.gif
2004-09-14 06:00 . 2004-09-14 06:00   878   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Fix a photo\Scripts\OneStepPhotoFix.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4455   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Perspective Distortion\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   821   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Perspective Distortion\Images\bullet.gif
2004-09-14 06:00 . 2004-09-14 06:00   929   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Perspective Distortion\Images\PerspectiveDistortionTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   791   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Perspective Distortion\Scripts\SelectPerspectiveTransform.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   6779   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Red Eye\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   916   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Red Eye\Images\redeye.gif
2004-09-14 06:00 . 2004-09-14 06:00   905   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Red Eye\Scripts\RedEye.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   3284   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Remove backlight\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   936   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Remove backlight\Images\BacklightTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   902   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Remove backlight\Scripts\Backlighting.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4314   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Straighten\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   865   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Straighten\Images\applyicon.gif
2004-09-14 06:00 . 2004-09-14 06:00   941   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Straighten\Images\StraigtenTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   781   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Improve\Straighten\Scripts\SelectStraighten.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4204   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Antique Effect\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1033   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Antique Effect\Scripts\AddNoise.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   3305   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Black & White\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1343   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Black & White\Scripts\HueSaturationLightness.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   8383   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   994   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Images\BackgroundEraserTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   807   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Images\blank_pixel.gif
2004-09-14 06:00 . 2004-09-14 06:00   915   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Images\deformicon.gif
2004-09-14 06:00 . 2004-09-14 06:00   883   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Images\movericon.gif
2004-09-14 06:00 . 2004-09-14 06:00   856   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Scripts\Copy.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   1001   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Scripts\PasteAsNewLayer.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   787   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Scripts\SelectBackgroundEraser.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   776   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Scripts\SelectMover.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   783   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create a collage\Scripts\SelectRasterDeform.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4082   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create soft focus\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1072   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Create soft focus\Scripts\SoftFocus.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   6919   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1149   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\css\BPStyles.css
2004-09-14 06:00 . 2004-09-14 06:00   1016   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\Images\freehandselecticon.gif
2004-09-14 06:00 . 2004-09-14 06:00   900   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\Scripts\GaussianBlur.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   946   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\Scripts\HideMarquee.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   788   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\Scripts\SelectFreehandSelection.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   872   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\Scripts\SelectInvert.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   992   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Depth of field\Scripts\UnsharpMask.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   6982   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Erase a background\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1000   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Erase a background\Images\erasericon.gif
2004-09-14 06:00 . 2004-09-14 06:00   6054   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Greeting card\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1110   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Greeting card\Scripts\AddBorders_White.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   782   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Greeting card\Scripts\SelectPictureTube.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   7987   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Text on a path\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   892   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Text on a path\Images\TextTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   898   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Text on a path\Scripts\CenterInCanvas.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   2047   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Text on a path\Scripts\New_Vector.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   2651   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Text on a path\Scripts\PresetShapes_Circle.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   868   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Text on a path\Scripts\SelectNone.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   783   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Text on a path\Scripts\SelectPresetShapes.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4065   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Warp\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   940   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Warp\Images\WarpBrushIcon.gif
2004-09-14 06:00 . 2004-09-14 06:00   783   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Projects\Warp\Scripts\SelectWarpingBrush.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   3396   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Restore\Fix faded color\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   915   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Restore\Fix faded color\Scripts\FadeCorrection.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   3954   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Restore\Remove scratches\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   908   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Restore\Remove scratches\Images\removeScratchesTool.gif
2004-09-14 06:00 . 2004-09-14 06:00   785   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Restore\Remove scratches\Scripts\SelectScratchRemover.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   4061   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Share\Email\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   5578   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Share\Upload to the Web\index.htm
2004-09-14 06:00 . 2004-09-14 06:00   1246   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Quick Guides\Share\Upload to the Web\Scripts\Browse.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   393216   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\libs\kodak\DCSPro3SLR.dll
2004-09-14 06:00 . 2004-09-14 06:00   483328   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\libs\kodak\DCSPro4SLR.dll
2004-09-14 06:00 . 2004-09-14 06:00   393216   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\libs\kodak\DCSProBack.dll
2004-09-14 06:00 . 2004-09-14 06:00   36864   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\libs\kodak\ProDriver.dll
2004-09-14 06:00 . 2004-09-14 06:00   1692   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\libs\kodak\ProDriver.inf
2004-09-14 06:00 . 2004-09-14 06:00   16768   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\libs\kodak\ProDriver.sys
2004-09-14 06:00 . 2004-09-14 06:00   45056   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\libs\kodak\ProFamily.dll
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon1.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon2.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon3.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon4.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon5.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon6.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon7.icm
2004-09-14 06:00 . 2004-09-14 06:00   242516   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon8.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canon9.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\canona.icm
2004-09-14 06:00 . 2004-09-14 06:00   242916   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS720xDaylightSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   242912   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS720xFlashSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   242920   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS720xFluorescentSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   242916   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS720xTungstenSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   242900   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS760CDaylightSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   242896   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS760CFlashSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   242904   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS760CFluorescentSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   242900   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCS760CTungstenSource.icm
2004-09-14 06:00 . 2004-09-14 06:00   50288   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCSPortraitLook.icm
2004-09-14 06:00 . 2004-09-14 06:00   50284   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\DCSProductLook.icm
2004-09-14 06:00 . 2004-09-14 06:00   55092   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\ERIMM_PCS3.icm
2004-09-14 06:00 . 2004-09-14 06:00   242520   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\fuji1.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\kodak1.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\kodak2.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\kodak3.icm
2004-09-14 06:00 . 2004-09-14 06:00   102496   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\lab.icm
2004-09-14 06:00 . 2004-09-14 06:00   242528   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\minolta1.icm
2004-09-14 06:00 . 2004-09-14 06:00   224456   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nf2.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nikon1.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nikon2.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nikon3.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nikon4.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nikon5.icm
2004-09-14 06:00 . 2004-09-14 06:00   102496   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nklab.icm
2004-09-14 06:00 . 2004-09-14 06:00   27258   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\nnnormfinal.icm
2004-09-14 06:00 . 2004-09-14 06:00   27258   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\normfinal.icm
2004-09-14 06:00 . 2004-09-14 06:00   242516   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\oly1.icm
2004-09-14 06:00 . 2004-09-14 06:00   242516   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\oly2.icm
2004-09-14 06:00 . 2004-09-14 06:00   242516   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\oly3.icm
2004-09-14 06:00 . 2004-09-14 06:00   242516   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\oly4.icm
2004-09-14 06:00 . 2004-09-14 06:00   242524   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\pentax1.icm
2004-09-14 06:00 . 2004-09-14 06:00   1000   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\rimm.icm
2004-09-14 06:00 . 2004-09-14 06:00   3144   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\srgb.icm
2004-09-14 06:00 . 2004-09-14 06:00   2044   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\WideGamut.icm
2004-09-14 06:00 . 2004-09-14 06:00   27258   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Raw Resources\Profiles\znorm.icm
2004-09-14 06:00 . 2004-09-14 06:00   645994   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Beau.JPG
2004-09-14 06:00 . 2004-09-14 06:00   616766   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Berries.JPG
2004-09-14 06:00 . 2004-09-14 06:00   680401   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\City.JPG
2004-09-14 06:00 . 2004-09-14 06:00   187115   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Flatiron Building.jpg
2004-09-14 06:00 . 2004-09-14 06:00   4292127   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Marble head.PspImage
2004-09-14 06:00 . 2004-09-14 06:00   1659125   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Peppers.JPG
2004-09-14 06:00 . 2004-09-14 06:00   199504   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\photo3.jpg
2004-09-14 06:00 . 2004-09-14 06:00   690040   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Straighten.JPG
2004-09-14 06:00 . 2004-09-14 06:00   87876   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\sunset foreground.jpg
2004-09-14 06:00 . 2004-09-14 06:00   73652   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\sunset sky.jpg
2004-09-14 06:00 . 2004-09-14 06:00   69749   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Sunset.jpg
2004-09-14 06:00 . 2004-09-14 06:00   147581   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Sample Images\Vector balloon.PspImage
2004-09-14 06:00 . 2004-09-14 06:00   6139   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\1024 x 768.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   3927   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\120 x 240 Vertical.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   6640   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\1200 x 800.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   3884   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\125 x 125 Square button.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   3876   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\234 x 60 Half banner.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   3910   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\468 x 60 Full banner.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   4747   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\640 x 480.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   3914   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\72 x 392 Full vertical navbar.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   5248   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\800 x 600.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   3836   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Selections\88 x 31 Micro button.PspSelection
2004-09-14 06:00 . 2004-09-14 06:00   104   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\+Solid.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Arrowhead - Ball.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   104   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Arrowhead end.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   104   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Arrowhead start.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   104   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Arrowheads both.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Dash with Arrowhead End.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   112   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Opposing Arrowheads - Equal.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   112   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Opposing Arrowheads - Overlap.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   112   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Opposing Arrowheads 01.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Repeating Arrows.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Arrowheads\Repeating End Arrows - Short.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   120   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Artistic\Ball - Fleur de Lis Dashed.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Artistic\Barbed Wire.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   120   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Artistic\Round End - Gaps.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   120   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Artistic\Spikes.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   120   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Artistic\Whip.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   128   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Dash Dot Dot.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   120   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Dash dot.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   112   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Dashed.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Diamond.PspStyledLine

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #32 on: March 29, 2012, 05:57:34 PM »
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Dot dash.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Dot.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   124   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Long-Short Dash 2.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   124   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Long-Short Dash.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   116   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Styled Lines\Dashed Lines\Small Dash.PspStyledLine
2004-09-14 06:00 . 2004-09-14 06:00   836   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Animal_zebra.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   676   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Blue.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   838   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Bright_emerald.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   678   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Cyan.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   1151   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Duotone_dark_blue.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   834   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Geometric.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   676   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Green.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   674   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey000.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   677   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey032.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   677   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey064.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   677   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey096.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   680   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey128.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   680   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey160.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   680   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey192.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   680   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey224.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   680   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Grey255.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   1150   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Landscape_desert.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   678   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Magenta.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   1149   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Metallic_silver.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   676   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Red.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   678   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Swatches\Swatch_Yellow.PspScript
2004-09-14 06:00 . 2004-09-14 06:00   37909   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Canvas coarse.png
2004-09-14 06:00 . 2004-09-14 06:00   32373   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Canvas fine.png
2004-09-14 06:00 . 2004-09-14 06:00   120056   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Canvas simple .bmp
2004-09-14 06:00 . 2004-09-14 06:00   120056   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Grain fine cloudy .bmp
2004-09-14 06:00 . 2004-09-14 06:00   196664   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Grain long deep.bmp
2004-09-14 06:00 . 2004-09-14 06:00   90056   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Hatch fine lump .bmp
2004-09-14 06:00 . 2004-09-14 06:00   49208   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Hatch fine shallow.bmp
2004-09-14 06:00 . 2004-09-14 06:00   49208   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Hatch fine smooth.bmp
2004-09-14 06:00 . 2004-09-14 06:00   49208   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Hatch fine.bmp
2004-09-14 06:00 . 2004-09-14 06:00   31080   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Hatch lump.bmp
2004-09-14 06:00 . 2004-09-14 06:00   121080   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Hatch medium lump .bmp
2004-09-14 06:00 . 2004-09-14 06:00   36219   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Paper coarse .png
2004-09-14 06:00 . 2004-09-14 06:00   41080   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Paper contrast .bmp
2004-09-14 06:00 . 2004-09-14 06:00   30685   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Paper fine.png
2004-09-14 06:00 . 2004-09-14 06:00   120056   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Paper smooth heavy .bmp
2004-09-14 06:00 . 2004-09-14 06:00   188056   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Paper standard directional.bmp
2004-09-14 06:00 . 2004-09-14 06:00   120056   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Art Media\Striation.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Daze.bmp
2004-09-14 06:00 . 2004-09-14 06:00   11078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Dither 25 pct.bmp
2004-09-14 06:00 . 2004-09-14 06:00   11078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Dither 50 pct.bmp
2004-09-14 06:00 . 2004-09-14 06:00   11078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Dither 75 pct.bmp
2004-09-14 06:00 . 2004-09-14 06:00   11078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Fine canvas.bmp
2004-09-14 06:00 . 2004-09-14 06:00   11078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Grid.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Letters.bmp
2004-09-14 06:00 . 2004-09-14 06:00   364082   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Mosaic weave.bmp
2004-09-14 06:00 . 2004-09-14 06:00   189866   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Plaid.bmp
2004-09-14 06:00 . 2004-09-14 06:00   11078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Polka dot.bmp
2004-09-14 06:00 . 2004-09-14 06:00   41078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Small dimples.bmp
2004-09-14 06:00 . 2004-09-14 06:00   11078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Geometric\Squares.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Asphalt.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Blue spruce.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Brick wall.bmp
2004-09-14 06:00 . 2004-09-14 06:00   48870   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Bricks.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Carpet.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Cobblestone.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Concrete.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Cork.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Crumpled paper.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Fur.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Grass.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Old cement.bmp
2004-09-14 06:00 . 2004-09-14 06:00   19438   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Old paper.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Plant leaves.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Sidewalk.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Small stones.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Snake skin.bmp
2004-09-14 06:00 . 2004-09-14 06:00   91078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Tin foil.bmp
2004-09-14 06:00 . 2004-09-14 06:00   308278   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Wet fall leaves.bmp
2004-09-14 06:00 . 2004-09-14 06:00   17078   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Textures\Photo\Woodgrain.bmp
2004-09-01 01:52 . 2004-09-01 01:52   36864   ----a-w-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Unlock.exe
2004-08-19 18:06 . 2004-08-19 18:06   2091   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\4x1.jpg
2004-08-19 16:20 . 2004-08-19 16:20   1510   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\dell_logo.gif
2004-08-19 16:20 . 2004-08-19 16:20   2364   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\jasclogo.gif
2004-08-19 16:18 . 2004-08-19 16:18   32131   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\1x1.jpg
2004-08-19 16:18 . 2004-08-19 16:18   34516   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\2x1.jpg
2004-08-19 16:18 . 2004-08-19 16:18   26199   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\3x1.jpg
2004-08-19 16:18 . 2004-08-19 16:18   168   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\arrow_circle.gif
2004-08-19 16:18 . 2004-08-19 16:18   468   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\buynow.gif
2004-08-19 16:18 . 2004-08-19 16:18   1161   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\buy_full.gif
2004-08-19 16:18 . 2004-08-19 16:18   1432   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\buy_upgrade.gif
2004-08-19 16:18 . 2004-08-19 16:18   971   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\close_window.gif
2004-08-19 16:18 . 2004-08-19 16:18   1016   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\continue_trial.gif
2004-08-19 16:18 . 2004-08-19 16:18   43   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\grey_rule.gif
2004-08-19 16:18 . 2004-08-19 16:18   1022   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\lower.gif
2004-08-19 16:18 . 2004-08-19 16:18   807   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\space.gif
2004-08-19 16:18 . 2004-08-19 16:18   3836   ----a-r-   c:\program files\Jasc Software Inc\Paint Shop Pro Studio\Images\upper.gif
.
.

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #33 on: March 29, 2012, 05:58:40 PM »
(((((((((((((((((((((((((((((   SnapShot@2012-03-28_21.34.40   )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-03-29 21:21 . 2012-03-29 21:21   16384              c:\windows\temp\Perflib_Perfdata_74.dat
+ 2012-03-29 21:22 . 2012-03-29 21:22   16384              c:\windows\temp\Perflib_Perfdata_374.dat
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]
2012-03-12 13:03   1869152   ----a-w-   c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{95B7759C-8C7F-4BF1-B163-73684A933233}"= "c:\program files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll" [2012-03-12 1869152]
.
[HKEY_CLASSES_ROOT\clsid\{95b7759c-8c7f-4bf1-b163-73684a933233}]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj.1]
[HKEY_CLASSES_ROOT\AVG Secure Search.PugiObj]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"FaxCenterServer"="c:\program files\Dell PC Fax\fm3032.exe" [2006-11-03 312200]
"dlcxmon.exe"="c:\program files\Dell Photo AIO Printer 926\dlcxmon.exe" [2007-01-12 292336]
"MemoryCardManager"="c:\program files\Dell Photo AIO Printer 926\memcard.exe" [2006-11-03 304008]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"dlccmon.exe"="c:\program files\Dell Photo AIO Printer 924\dlccmon.exe" [2005-07-22 425984]
"DLCCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 69632]
"DLCXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-10-16 106496]
"SoundMAXPnP"="c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 1388544]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"AVG_TRAY"="c:\program files\AVG\AVG2012\avgtray.exe" [2012-01-24 2416480]
"vProt"="c:\program files\AVG Secure Search\vprot.exe" [2012-03-12 982880]
"TkBellExe"="c:\program files\real\realplayer\update\realsched.exe" [2012-01-15 296056]
"ROC_roc_dec12"="c:\program files\AVG Secure Search\ROC_roc_dec12.exe" [2012-01-30 928096]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute   REG_MULTI_SZ      autocheck autochk *\0c:\progra~1\AVG\AVG2012\avgrsx.exe /sync /restart
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLCCCATS]
2005-06-07 18:38   69632   ----a-w-   c:\windows\system32\spool\drivers\w32x86\3\dlcctime.dll
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\dlcxcoms.exe"=
"c:\\WINDOWS\\system32\\dlcccoms.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\dlccPSWX.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgmfapx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgnsx.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG2012\\avgemcx.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [7/11/2011 2:14 AM 23120]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [9/13/2011 7:30 AM 32592]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [10/7/2011 7:23 AM 230608]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [7/11/2011 2:14 AM 295248]
R2 avgwd;AVG WatchDog;c:\program files\AVG\AVG2012\avgwdsvc.exe [8/2/2011 7:09 AM 192776]
R2 dlcx_device;dlcx_device;c:\windows\system32\dlcxcoms.exe -service --> c:\windows\system32\dlcxcoms.exe -service [?]
R2 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [8/4/2004 7:00 AM 14336]
R2 vToolbarUpdater10.2.0;vToolbarUpdater10.2.0;c:\program files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe [3/12/2012 8:03 AM 918880]
S3 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\AVG2012\AVGIDSAgent.exe [10/12/2011 7:25 AM 4433248]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [7/11/2011 2:14 AM 134608]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [7/11/2011 2:14 AM 24272]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [10/4/2011 7:21 AM 16720]
S3 IPN2220;802.11g Wireless LAN Card Driver;c:\windows\system32\drivers\i2220ntx.sys [10/16/2006 7:52 PM 140288]
S3 SetupNTGLM7X;SetupNTGLM7X;\??\d:\ntglm7x.sys --> d:\NTGLM7X.sys [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc   REG_MULTI_SZ      p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2012-03-29 c:\windows\Tasks\AVG PC Tuneup Integrator Start On customer1 Logon.job
- c:\program files\AVG\AVG PC Tuneup\BoostSpeed.exe [2012-02-25 23:20]
.
2012-03-29 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-73586283-842925246-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 22:02]
.
2012-03-29 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-73586283-842925246-725345543-1004.job
- c:\program files\Real\RealUpgrade\realupgrade.exe [2011-11-29 22:02]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - c:\program files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll
FF - ProfilePath - c:\documents and settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://isearch.avg.com/search?cid=%7B9b5491a7-5335-4be7-ac85-02b376fd61ba%7D&mid=394e44f4630a47d18da8d15e776005a6-87d0ec190e4c69a23e608e916e5c08d08c9e9e6c&ds=AVG&v=9.0.0.23&lang=en&pr=pr&d=2011-12-22%2017%3A52%3A00&sap=ku&q=
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-29 16:22
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ... 
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
  DLCCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
  DLCXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ... 
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(928)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3396)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\progra~1\AVG\AVG2012\avgrsx.exe
c:\program files\AVG\AVG2012\avgcsrvx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlcxcoms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\tcpsvcs.exe
c:\windows\System32\snmp.exe
c:\program files\Analog Devices\SoundMAX\SMAgent.exe
c:\windows\system32\UTSCSI.EXE
c:\program files\AVG\AVG2012\avgnsx.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\dlcccoms.exe
.
**************************************************************************
.
Completion time: 2012-03-29  16:26:50 - machine was rebooted
ComboFix-quarantined-files.txt  2012-03-29 21:26
ComboFix2.txt  2012-03-28 21:36
.
Pre-Run: 140,707,692,544 bytes free
Post-Run: 140,701,667,328 bytes free
.
- - End Of File - - 58F20DD56F9B5A9C064E6977A6EFA2C7

Offline Bear

  • Malware Removal Mentors
  • Global Moderator
  • Gold Member
  • Posts: 2154
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #34 on: March 30, 2012, 12:57:45 AM »
Hi KC

We will get your PC running right, but it takes some time to get to the root causes of the problems.

Please read carefully and follow these steps:

1.  Download TDSSKiller and save it to your Desktop.   

2.  Doubleclick on TDSSKiller.exe to run the application. Now click Start Scan.

3.  Click on Change parameters and place a checkmark next to Verify Driver Digital Signature and Detect TDLFS file system, then click OK.

4.  If an infected file is detected, the default action will be Cure, click on Continue.  If a suspicious file is detected, the default action will be Skip, click on Continue.

Click on Reboot Now if you are asked to reboot the computer.

5.  If reboot is NOT required, click on Report.   Please copy that file.  If a reboot IS required, the report can also be found in your root directory (usually C:\ folder).   It's file name will take the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt]". Please copy that file.

6.  Download OTL from any of the following links and save to your Desktop.
OTL1
OTL2
OTL3

Rename the program google.exe.

7.  Disable all of your Anti-Virus, Anti-Spyware programs.  If you need help to disable them go to Disable Anti Malware, be sure to re-enable them before posting your reply.

8.   Double click on the google.exe icon to run it (Vista and Windows 7 users right click and select Run as  Administrator). Make sure all other windows are closed and to let it run uninterrupted. 

9.  In the lower right corner, checkmark "LOP Check" and checkmark "Purity Check".  On the upper right be sure Use Company-Name WhiteList and Skip Microsoft Files are checked.  Copy the code in the code box below and paste it into the Custom Scan box .

Code: [Select]
netsvcs
drivers32
CREATERESTOREPOINT
msconfig
%systemroot%\*. /rp /s


10.  Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.  When the scan completes, it will open two notepad windows.  OTL.Txt and Extras.Txt. These are saved in the same location as OTL.


Remember to be sure Word Wrap is NOT turned on in any Notepad files you post and to be sure and check that all the data you entered was posted. 

Now please post the following to me as a reply to this post:
TDSSKiller log
OTL.Txt
Extras.Txt
Let me know how your computer is operating
If you have any questions or problems, let me know that as well





Never interrupt your enemy when he is making a mistake.
- Napoleon Bonaparte

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #35 on: March 31, 2012, 12:19:29 PM »
11:12:58.0531 5520   TDSS rootkit removing tool 2.7.23.0 Mar 26 2012 13:40:18
11:12:59.0843 5520   ============================================================
11:12:59.0843 5520   Current date / time: 2012/03/31 11:12:59.0843
11:12:59.0843 5520   SystemInfo:
11:12:59.0843 5520   
11:12:59.0843 5520   OS Version: 5.1.2600 ServicePack: 3.0
11:12:59.0843 5520   Product type: Workstation
11:12:59.0843 5520   ComputerName: KEVINSPC
11:12:59.0843 5520   UserName: customer1
11:12:59.0843 5520   Windows directory: C:\WINDOWS
11:12:59.0843 5520   System windows directory: C:\WINDOWS
11:12:59.0843 5520   Processor architecture: Intel x86
11:12:59.0843 5520   Number of processors: 1
11:12:59.0843 5520   Page size: 0x1000
11:12:59.0843 5520   Boot type: Normal boot
11:12:59.0843 5520   ============================================================
11:13:01.0718 5520   Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054
11:13:01.0718 5520   \Device\Harddisk0\DR0:
11:13:01.0718 5520   MBR used
11:13:01.0718 5520   \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A18A82
11:13:01.0750 5520   Initialize success
11:13:01.0750 5520   ============================================================
11:13:11.0593 2064   ============================================================
11:13:11.0593 2064   Scan started
11:13:11.0593 2064   Mode: Manual;
11:13:11.0593 2064   ============================================================
11:13:12.0109 2064   6to4            (c07d5197410aab28d0d93f943f59656d) C:\WINDOWS\System32\6to4svc.dll
11:13:12.0109 2064   6to4 - ok
11:13:12.0187 2064   Abiosdsk - ok
11:13:12.0218 2064   abp480n5 - ok
11:13:12.0296 2064   ACPI            (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:13:12.0296 2064   ACPI - ok
11:13:12.0406 2064   ACPIEC          (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
11:13:12.0406 2064   ACPIEC - ok
11:13:12.0453 2064   adpu160m - ok
11:13:12.0546 2064   aeaudio         (9f59ae2de835641fbb0c6afd80d8fa9b) C:\WINDOWS\system32\drivers\aeaudio.sys
11:13:12.0546 2064   aeaudio - ok
11:13:12.0625 2064   aec             (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
11:13:12.0625 2064   aec - ok
11:13:12.0703 2064   AFD             (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
11:13:12.0703 2064   AFD - ok
11:13:12.0734 2064   Aha154x - ok
11:13:12.0765 2064   aic78u2 - ok
11:13:12.0812 2064   aic78xx - ok
11:13:12.0843 2064   ALCXWDM - ok
11:13:12.0890 2064   Alerter         (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
11:13:12.0890 2064   Alerter - ok
11:13:12.0984 2064   ALG             (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
11:13:12.0984 2064   ALG - ok
11:13:13.0062 2064   AliIde - ok
11:13:13.0156 2064   AmdK8           (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
11:13:13.0156 2064   AmdK8 - ok
11:13:13.0218 2064   amsint - ok
11:13:13.0250 2064   AppMgmt - ok
11:13:13.0281 2064   asc - ok
11:13:13.0312 2064   asc3350p - ok
11:13:13.0343 2064   asc3550 - ok
11:13:13.0437 2064   aspnet_state    (e1a1206a4fb19b675e947b29ccd25fba) C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
11:13:13.0437 2064   aspnet_state - ok
11:13:13.0515 2064   AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:13:13.0515 2064   AsyncMac - ok
11:13:13.0609 2064   atapi           (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
11:13:13.0609 2064   atapi - ok
11:13:13.0656 2064   Atdisk - ok
11:13:13.0734 2064   Ati HotKey Poller (c23082b890f21267037ca6111c385ff3) C:\WINDOWS\system32\Ati2evxx.exe
11:13:13.0750 2064   Ati HotKey Poller - ok
11:13:13.0859 2064   ATI Smart       (0d582dc5e3f74cea1bf56ba2a925d0f2) C:\WINDOWS\system32\ati2sgag.exe
11:13:13.0875 2064   ATI Smart - ok
11:13:14.0031 2064   ati2mtag        (f5fc6ac1e7bc776871361d463fc86be2) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
11:13:14.0046 2064   ati2mtag - ok
11:13:14.0125 2064   Atmarpc         (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:13:14.0125 2064   Atmarpc - ok
11:13:14.0203 2064   AudioSrv        (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
11:13:14.0203 2064   AudioSrv - ok
11:13:14.0312 2064   audstub         (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
11:13:14.0312 2064   audstub - ok
11:13:14.0562 2064   AVGIDSAgent     (6d440ff3f44ca72edfd6176c6d6a89c0) C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
11:13:14.0687 2064   AVGIDSAgent - ok
11:13:14.0796 2064   AVGIDSDriver    (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
11:13:14.0796 2064   AVGIDSDriver - ok
11:13:14.0890 2064   AVGIDSEH        (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
11:13:14.0890 2064   AVGIDSEH - ok
11:13:14.0968 2064   AVGIDSFilter    (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
11:13:14.0968 2064   AVGIDSFilter - ok
11:13:15.0078 2064   AVGIDSShim      (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
11:13:15.0078 2064   AVGIDSShim - ok
11:13:15.0187 2064   Avgldx86        (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
11:13:15.0187 2064   Avgldx86 - ok
11:13:15.0296 2064   Avgmfx86        (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
11:13:15.0296 2064   Avgmfx86 - ok
11:13:15.0406 2064   Avgrkx86        (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
11:13:15.0406 2064   Avgrkx86 - ok
11:13:15.0484 2064   Avgtdix         (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
11:13:15.0484 2064   Avgtdix - ok
11:13:15.0609 2064   avgwd           (6699ece24fe4b3f752a66c66a602ee86) C:\Program Files\AVG\AVG2012\avgwdsvc.exe
11:13:15.0625 2064   avgwd - ok
11:13:15.0718 2064   Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
11:13:15.0718 2064   Beep - ok
11:13:15.0796 2064   BITS            (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
11:13:15.0796 2064   BITS - ok
11:13:15.0875 2064   Bonjour Service (3f56903e124e820aeece6d471583c6c1) C:\Program Files\Bonjour\mDNSResponder.exe
11:13:15.0875 2064   Bonjour Service - ok
11:13:15.0984 2064   Browser         (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
11:13:15.0984 2064   Browser - ok
11:13:15.0984 2064   catchme - ok
11:13:16.0078 2064   cbidf2k         (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
11:13:16.0078 2064   cbidf2k - ok
11:13:16.0171 2064   CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
11:13:16.0171 2064   CCDECODE - ok
11:13:16.0218 2064   cd20xrnt - ok
11:13:16.0281 2064   Cdaudio         (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
11:13:16.0281 2064   Cdaudio - ok
11:13:16.0359 2064   Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
11:13:16.0359 2064   Cdfs - ok
11:13:16.0468 2064   Cdrom           (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:13:16.0468 2064   Cdrom - ok
11:13:16.0500 2064   Changer - ok
11:13:16.0562 2064   CiSvc           (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
11:13:16.0562 2064   CiSvc - ok
11:13:16.0656 2064   ClipSrv         (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
11:13:16.0656 2064   ClipSrv - ok
11:13:16.0718 2064   CmdIde - ok
11:13:16.0750 2064   COMSysApp - ok
11:13:16.0796 2064   Cpqarray - ok
11:13:16.0875 2064   CryptSvc        (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
11:13:16.0875 2064   CryptSvc - ok
11:13:16.0937 2064   dac2w2k - ok
11:13:16.0968 2064   dac960nt - ok
11:13:17.0062 2064   DcomLaunch      (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
11:13:17.0062 2064   DcomLaunch - ok
11:13:17.0156 2064   Dhcp            (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
11:13:17.0156 2064   Dhcp - ok
11:13:17.0265 2064   Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
11:13:17.0265 2064   Disk - ok
11:13:17.0328 2064   dlcc_device - ok
11:13:17.0359 2064   dlcx_device - ok
11:13:17.0390 2064   dmadmin - ok
11:13:17.0468 2064   dmboot          (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
11:13:17.0484 2064   dmboot - ok
11:13:17.0578 2064   dmio            (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
11:13:17.0578 2064   dmio - ok
11:13:17.0671 2064   dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
11:13:17.0671 2064   dmload - ok
11:13:17.0734 2064   dmserver        (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
11:13:17.0734 2064   dmserver - ok
11:13:17.0843 2064   DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
11:13:17.0843 2064   DMusic - ok
11:13:17.0937 2064   Dnscache        (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
11:13:17.0937 2064   Dnscache - ok
11:13:18.0000 2064   Dot3svc         (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
11:13:18.0000 2064   Dot3svc - ok
11:13:18.0125 2064   dot4            (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
11:13:18.0125 2064   dot4 - ok
11:13:18.0218 2064   Dot4Print       (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
11:13:18.0218 2064   Dot4Print - ok
11:13:18.0281 2064   dot4usb         (6ec3af6bb5b30e488a0c559921f012e1) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
11:13:18.0281 2064   dot4usb - ok
11:13:18.0328 2064   dpti2o - ok
11:13:18.0390 2064   drmkaud         (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
11:13:18.0390 2064   drmkaud - ok
11:13:18.0453 2064   EapHost         (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
11:13:18.0453 2064   EapHost - ok
11:13:18.0546 2064   ERSvc           (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
11:13:18.0546 2064   ERSvc - ok
11:13:18.0625 2064   Eventlog        (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
11:13:18.0625 2064   Eventlog - ok
11:13:18.0718 2064   EventSystem     (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
11:13:18.0718 2064   EventSystem - ok
11:13:18.0828 2064   Fastfat         (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
11:13:18.0828 2064   Fastfat - ok
11:13:18.0906 2064   FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:13:18.0906 2064   FastUserSwitchingCompatibility - ok
11:13:19.0031 2064   Fdc             (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
11:13:19.0031 2064   Fdc - ok
11:13:19.0140 2064   Fips            (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
11:13:19.0140 2064   Fips - ok
11:13:19.0218 2064   Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
11:13:19.0218 2064   Flpydisk - ok
11:13:19.0296 2064   FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
11:13:19.0296 2064   FltMgr - ok
11:13:19.0359 2064   Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:13:19.0359 2064   Fs_Rec - ok
11:13:19.0421 2064   Ftdisk          (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:13:19.0437 2064   Ftdisk - ok
11:13:19.0437 2064   GMSIPCI - ok
11:13:19.0515 2064   Gpc             (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:13:19.0515 2064   Gpc - ok
11:13:19.0625 2064   helpsvc         (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
11:13:19.0625 2064   helpsvc - ok
11:13:19.0734 2064   HidServ         (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll
11:13:19.0734 2064   HidServ - ok
11:13:19.0843 2064   HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:13:19.0843 2064   HidUsb - ok
11:13:19.0921 2064   hkmsvc          (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
11:13:19.0921 2064   hkmsvc - ok
11:13:19.0968 2064   hpn - ok
11:13:20.0062 2064   HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
11:13:20.0062 2064   HTTP - ok
11:13:20.0140 2064   HTTPFilter      (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
11:13:20.0140 2064   HTTPFilter - ok
11:13:20.0171 2064   i2omgmt - ok
11:13:20.0203 2064   i2omp - ok
11:13:20.0281 2064   i8042prt        (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:13:20.0296 2064   i8042prt - ok
11:13:20.0406 2064   Imapi           (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
11:13:20.0406 2064   Imapi - ok
11:13:20.0484 2064   ImapiService    (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
11:13:20.0500 2064   ImapiService - ok
11:13:20.0531 2064   InCDFs - ok
11:13:20.0562 2064   InCDPass - ok
11:13:20.0593 2064   InCDRm - ok
11:13:20.0625 2064   ini910u - ok
11:13:20.0656 2064   IntelIde - ok
11:13:20.0734 2064   Ip6Fw           (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
11:13:20.0734 2064   Ip6Fw - ok
11:13:20.0796 2064   IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:13:20.0796 2064   IpFilterDriver - ok
11:13:20.0875 2064   IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:13:20.0890 2064   IpInIp - ok
11:13:20.0953 2064   IPN2220         (eadcbd84f788d887e73d8c7691b2c508) C:\WINDOWS\system32\DRIVERS\i2220ntx.sys
11:13:20.0953 2064   IPN2220 - ok
11:13:21.0046 2064   IpNat           (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:13:21.0046 2064   IpNat - ok
11:13:21.0140 2064   Iprip           (f08d74ec300b8ba60ca953c58a24d19e) C:\WINDOWS\System32\iprip.dll
11:13:21.0140 2064   Iprip - ok
11:13:21.0265 2064   IPSec           (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:13:21.0265 2064   IPSec - ok
11:13:21.0328 2064   irda            (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
11:13:21.0328 2064   irda - ok
11:13:21.0406 2064   IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
11:13:21.0406 2064   IRENUM - ok
11:13:21.0500 2064   Irmon           (49cc4533ce897cb2e93c1e84a818fde5) C:\WINDOWS\System32\irmon.dll
11:13:21.0500 2064   Irmon - ok
11:13:21.0546 2064   irsir - ok
11:13:21.0609 2064   isapnp          (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:13:21.0609 2064   isapnp - ok
11:13:21.0781 2064   JavaQuickStarterService (9aa67569d5257462e230767510b0c815) C:\Program Files\Java\jre6\bin\jqs.exe
11:13:21.0781 2064   JavaQuickStarterService - ok
11:13:21.0875 2064   Kbdclass        (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:13:21.0890 2064   Kbdclass - ok
11:13:21.0968 2064   kbdhid          (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
11:13:21.0968 2064   kbdhid - ok
11:13:22.0046 2064   kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
11:13:22.0046 2064   kmixer - ok
11:13:22.0109 2064   KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
11:13:22.0125 2064   KSecDD - ok
11:13:22.0218 2064   lanmanserver    (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
11:13:22.0218 2064   lanmanserver - ok
11:13:22.0312 2064   lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
11:13:22.0312 2064   lanmanworkstation - ok
11:13:22.0359 2064   lbrtfdc - ok
11:13:22.0453 2064   LmHosts         (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
11:13:22.0453 2064   LmHosts - ok
11:13:22.0562 2064   LPDSVC          (32933b07fc16d9f778bee12545fa1b1a) C:\WINDOWS\system32\tcpsvcs.exe
11:13:22.0562 2064   LPDSVC - ok
11:13:22.0671 2064   MDM             (11f714f85530a2bd134074dc30e99fca) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
11:13:22.0687 2064   MDM - ok
11:13:22.0796 2064   Messenger       (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
11:13:22.0796 2064   Messenger - ok
11:13:22.0906 2064   MidiSyn         (8c7d037a53b495e7c250fd70b158b581) C:\WINDOWS\system32\drivers\MidiSyn.sys
11:13:22.0906 2064   MidiSyn - ok
11:13:22.0984 2064   mnmdd           (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
11:13:22.0984 2064   mnmdd - ok
11:13:23.0062 2064   mnmsrvc         (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
11:13:23.0062 2064   mnmsrvc - ok
11:13:23.0140 2064   Modem           (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
11:13:23.0140 2064   Modem - ok
11:13:23.0234 2064   Mouclass        (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:13:23.0234 2064   Mouclass - ok
11:13:23.0312 2064   mouhid          (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:13:23.0312 2064   mouhid - ok
11:13:23.0390 2064   MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
11:13:23.0390 2064   MountMgr - ok
11:13:23.0421 2064   mraid35x - ok
11:13:23.0515 2064   MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:13:23.0515 2064   MRxDAV - ok
11:13:23.0640 2064   MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:13:23.0687 2064   MRxSmb - ok
11:13:23.0796 2064   MSDTC           (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
11:13:23.0796 2064   MSDTC - ok
11:13:23.0906 2064   Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
11:13:23.0906 2064   Msfs - ok
11:13:23.0968 2064   MSIServer - ok
11:13:24.0046 2064   MSKSSRV         (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #36 on: March 31, 2012, 12:21:07 PM »
11:13:24.0046 2064   MSKSSRV - ok
11:13:24.0140 2064   MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:13:24.0140 2064   MSPCLOCK - ok
11:13:24.0234 2064   MSPQM           (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:13:24.0234 2064   MSPQM - ok
11:13:24.0328 2064   mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:13:24.0328 2064   mssmbios - ok
11:13:24.0390 2064   MSTEE           (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
11:13:24.0406 2064   MSTEE - ok
11:13:24.0500 2064   ms_mpu401       (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
11:13:24.0500 2064   ms_mpu401 - ok
11:13:24.0625 2064   Mup             (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:13:24.0625 2064   Mup - ok
11:13:24.0687 2064   NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
11:13:24.0687 2064   NABTSFEC - ok
11:13:24.0796 2064   napagent        (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
11:13:24.0796 2064   napagent - ok
11:13:24.0890 2064   NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:13:24.0890 2064   NDIS - ok
11:13:24.0968 2064   NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
11:13:24.0968 2064   NdisIP - ok
11:13:25.0046 2064   NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:13:25.0046 2064   NdisTapi - ok
11:13:25.0171 2064   Ndisuio         (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:13:25.0171 2064   Ndisuio - ok
11:13:25.0250 2064   NdisWan         (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:13:25.0296 2064   NdisWan - ok
11:13:25.0531 2064   NDProxy         (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:13:25.0531 2064   NDProxy - ok
11:13:25.0609 2064   NetBIOS         (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:13:25.0609 2064   NetBIOS - ok
11:13:25.0687 2064   NetBT           (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:13:25.0703 2064   NetBT - ok
11:13:25.0796 2064   NetDDE          (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:13:25.0796 2064   NetDDE - ok
11:13:25.0812 2064   NetDDEdsdm      (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:13:25.0812 2064   NetDDEdsdm - ok
11:13:25.0890 2064   Netlogon        (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:25.0906 2064   Netlogon - ok
11:13:25.0968 2064   Netman          (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
11:13:25.0984 2064   Netman - ok
11:13:26.0062 2064   Nla             (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
11:13:26.0062 2064   Nla - ok
11:13:26.0156 2064   Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:13:26.0156 2064   Npfs - ok
11:13:26.0171 2064   NTACCESS - ok
11:13:26.0265 2064   Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:13:26.0265 2064   Ntfs - ok
11:13:26.0343 2064   NtLmSsp         (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:26.0343 2064   NtLmSsp - ok
11:13:26.0453 2064   NtmsSvc         (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
11:13:26.0453 2064   NtmsSvc - ok
11:13:26.0546 2064   Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:13:26.0546 2064   Null - ok
11:13:26.0625 2064   nvata           (0344aa9113dc16eec379f4652020849d) C:\WINDOWS\system32\DRIVERS\nvata.sys
11:13:26.0625 2064   nvata - ok
11:13:26.0687 2064   nvax            (f3d3015e52f2732042197d4edcaac2cb) C:\WINDOWS\system32\drivers\nvax.sys
11:13:26.0687 2064   nvax - ok
11:13:26.0765 2064   NVENETFD        (720cc533eecb65553bd86b139ca04433) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
11:13:26.0765 2064   NVENETFD - ok
11:13:26.0828 2064   nvnetbus        (5f9f545cc5904dd8765f84ee1d056406) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
11:13:26.0828 2064   nvnetbus - ok
11:13:26.0921 2064   nvnforce        (6d6fd2b7035d415621acaf1e555c8b90) C:\WINDOWS\system32\drivers\nvapu.sys
11:13:26.0937 2064   nvnforce - ok
11:13:27.0078 2064   NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:13:27.0078 2064   NwlnkFlt - ok
11:13:27.0203 2064   NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:13:27.0203 2064   NwlnkFwd - ok
11:13:27.0296 2064   ose             (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:13:27.0296 2064   ose - ok
11:13:27.0406 2064   p2pgasvc        (937a02981f11b2ce96b1d493c95aed2b) C:\WINDOWS\system32\p2pgasvc.dll
11:13:27.0406 2064   p2pgasvc - ok
11:13:27.0515 2064   p2pimsvc        (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:13:27.0531 2064   p2pimsvc - ok
11:13:27.0546 2064   p2psvc          (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:13:27.0562 2064   p2psvc - ok
11:13:27.0656 2064   Parport         (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
11:13:27.0656 2064   Parport - ok
11:13:27.0765 2064   PartMgr         (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:13:27.0765 2064   PartMgr - ok
11:13:27.0859 2064   ParVdm          (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
11:13:27.0859 2064   ParVdm - ok
11:13:27.0890 2064   PCANDIS5 - ok
11:13:27.0968 2064   PCI             (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
11:13:27.0968 2064   PCI - ok
11:13:28.0015 2064   PCIDump - ok
11:13:28.0140 2064   PCIIde          (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
11:13:28.0140 2064   PCIIde - ok
11:13:28.0187 2064   Pcmcia          (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
11:13:28.0203 2064   Pcmcia - ok
11:13:28.0250 2064   PDCOMP - ok
11:13:28.0296 2064   PDFRAME - ok
11:13:28.0343 2064   PDRELI - ok
11:13:28.0406 2064   PDRFRAME - ok
11:13:28.0453 2064   perc2 - ok
11:13:28.0484 2064   perc2hib - ok
11:13:28.0578 2064   PlugPlay        (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
11:13:28.0578 2064   PlugPlay - ok
11:13:28.0656 2064   PNRPSvc         (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:13:28.0671 2064   PNRPSvc - ok
11:13:28.0765 2064   PolicyAgent     (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:28.0765 2064   PolicyAgent - ok
11:13:28.0875 2064   PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:13:28.0875 2064   PptpMiniport - ok
11:13:28.0984 2064   Processor       (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
11:13:28.0984 2064   Processor - ok
11:13:29.0093 2064   ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:29.0093 2064   ProtectedStorage - ok
11:13:29.0218 2064   PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:13:29.0218 2064   PSched - ok
11:13:29.0296 2064   Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:13:29.0296 2064   Ptilink - ok
11:13:29.0375 2064   PxHelp20        (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
11:13:29.0375 2064   PxHelp20 - ok
11:13:29.0421 2064   ql1080 - ok
11:13:29.0453 2064   Ql10wnt - ok
11:13:29.0484 2064   ql12160 - ok
11:13:29.0515 2064   ql1240 - ok
11:13:29.0546 2064   ql1280 - ok
11:13:29.0609 2064   RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:13:29.0625 2064   RasAcd - ok
11:13:29.0687 2064   RasAuto         (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
11:13:29.0687 2064   RasAuto - ok
11:13:29.0765 2064   Rasirda         (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
11:13:29.0765 2064   Rasirda - ok
11:13:29.0843 2064   Rasl2tp         (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:13:29.0859 2064   Rasl2tp - ok
11:13:29.0921 2064   RasMan          (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
11:13:29.0921 2064   RasMan - ok
11:13:30.0031 2064   RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:13:30.0046 2064   RasPppoe - ok
11:13:30.0156 2064   Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:13:30.0156 2064   Raspti - ok
11:13:30.0265 2064   Rdbss           (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:13:30.0265 2064   Rdbss - ok
11:13:30.0359 2064   RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:13:30.0375 2064   RDPCDD - ok
11:13:30.0453 2064   RDPWD           (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
11:13:30.0468 2064   RDPWD - ok
11:13:30.0546 2064   RDSessMgr       (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
11:13:30.0562 2064   RDSessMgr - ok
11:13:30.0671 2064   redbook         (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:13:30.0671 2064   redbook - ok
11:13:30.0750 2064   RemoteAccess    (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
11:13:30.0750 2064   RemoteAccess - ok
11:13:30.0843 2064   RpcLocator      (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
11:13:30.0843 2064   RpcLocator - ok
11:13:30.0937 2064   RpcSs           (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
11:13:30.0953 2064   RpcSs - ok
11:13:31.0062 2064   RSVP            (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
11:13:31.0062 2064   RSVP - ok
11:13:31.0125 2064   RT2500USB - ok
11:13:31.0203 2064   SamSs           (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:31.0203 2064   SamSs - ok
11:13:31.0500 2064   SCardSvr        (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
11:13:31.0515 2064   SCardSvr - ok
11:13:31.0609 2064   Schedule        (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
11:13:31.0609 2064   Schedule - ok
11:13:31.0703 2064   Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:13:31.0703 2064   Secdrv - ok
11:13:31.0796 2064   seclogon        (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
11:13:31.0796 2064   seclogon - ok
11:13:31.0890 2064   senfilt         (bb596a578330ad794c6769b588af6bb4) C:\WINDOWS\system32\drivers\senfilt.sys
11:13:31.0906 2064   senfilt - ok
11:13:32.0015 2064   SENS            (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
11:13:32.0031 2064   SENS - ok
11:13:32.0140 2064   serenum         (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:13:32.0140 2064   serenum - ok
11:13:32.0203 2064   Serial          (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
11:13:32.0218 2064   Serial - ok
11:13:32.0218 2064   SetupNTGLM7X - ok
11:13:32.0328 2064   sfdrv01         (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
11:13:32.0328 2064   sfdrv01 - ok
11:13:32.0437 2064   sfhlp02         (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
11:13:32.0437 2064   sfhlp02 - ok
11:13:32.0546 2064   Sfloppy         (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
11:13:32.0546 2064   Sfloppy - ok
11:13:32.0593 2064   sfsync02 - ok
11:13:32.0671 2064   SharedAccess    (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
11:13:32.0687 2064   SharedAccess - ok
11:13:32.0796 2064   ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:13:32.0796 2064   ShellHWDetection - ok
11:13:32.0859 2064   Simbad - ok
11:13:32.0921 2064   SimpTcp         (32933b07fc16d9f778bee12545fa1b1a) C:\WINDOWS\system32\tcpsvcs.exe
11:13:32.0937 2064   SimpTcp - ok
11:13:33.0046 2064   SiSGbeXP        (a86e52c55de3488b3fc0ff2b8ad711bf) C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys
11:13:33.0046 2064   SiSGbeXP - ok
11:13:33.0109 2064   SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
11:13:33.0109 2064   SLIP - ok
11:13:33.0218 2064   smwdm           (0d7efa9d5bac36ea49940a8ead9990b5) C:\WINDOWS\system32\drivers\smwdm.sys
11:13:33.0218 2064   smwdm - ok
11:13:33.0328 2064   SNMP            (60c377be6b3cc83f6a8584934b181d2e) C:\WINDOWS\System32\snmp.exe
11:13:33.0328 2064   SNMP - ok
11:13:33.0453 2064   SNMPTRAP        (80a050795a107a76c2b1cd4cfbe010e6) C:\WINDOWS\System32\snmptrap.exe
11:13:33.0453 2064   SNMPTRAP - ok
11:13:33.0578 2064   SoundMAX Agent Service (default) (3978f082274f723ad5a0a8058c2417dd) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
11:13:33.0578 2064   SoundMAX Agent Service (default) - ok
11:13:33.0656 2064   Sparrow - ok
11:13:33.0718 2064   splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:13:33.0718 2064   splitter - ok
11:13:33.0796 2064   Spooler         (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
11:13:33.0796 2064   Spooler - ok
11:13:33.0859 2064   sr              (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
11:13:33.0859 2064   sr - ok
11:13:33.0937 2064   srservice       (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
11:13:33.0953 2064   srservice - ok
11:13:34.0046 2064   Srv             (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
11:13:34.0062 2064   Srv - ok
11:13:34.0171 2064   SSDPSRV         (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
11:13:34.0171 2064   SSDPSRV - ok
11:13:34.0265 2064   stisvc          (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
11:13:34.0281 2064   stisvc - ok
11:13:34.0375 2064   streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
11:13:34.0375 2064   streamip - ok
11:13:34.0468 2064   swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:13:34.0468 2064   swenum - ok
11:13:34.0562 2064   swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:13:34.0562 2064   swmidi - ok
11:13:34.0625 2064   SwPrv - ok
11:13:34.0656 2064   symc810 - ok
11:13:34.0718 2064   symc8xx - ok
11:13:34.0765 2064   sym_hi - ok
11:13:34.0812 2064   sym_u3 - ok
11:13:34.0890 2064   sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:13:34.0890 2064   sysaudio - ok
11:13:35.0000 2064   SysmonLog       (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
11:13:35.0000 2064   SysmonLog - ok
11:13:35.0093 2064   TapiSrv         (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
11:13:35.0093 2064   TapiSrv - ok
11:13:35.0187 2064   Tcpip           (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:13:35.0187 2064   Tcpip - ok
11:13:35.0296 2064   Tcpip6          (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
11:13:35.0296 2064   Tcpip6 - ok
11:13:35.0375 2064   TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:13:35.0375 2064   TDPIPE - ok
11:13:35.0453 2064   TDTCP           (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:13:35.0453 2064   TDTCP - ok
11:13:35.0531 2064   TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:13:35.0531 2064   TermDD - ok
11:13:35.0625 2064   TermService     (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
11:13:35.0625 2064   TermService - ok
11:13:35.0750 2064   Themes          (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:13:35.0750 2064   Themes - ok
11:13:35.0828 2064   TosIde - ok
11:13:35.0921 2064   TrkWks          (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
11:13:35.0921 2064   TrkWks - ok
11:13:36.0031 2064   tunmp           (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
11:13:36.0031 2064   tunmp - ok
11:13:36.0125 2064   Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:13:36.0125 2064   Udfs - ok
11:13:36.0203 2064   ultra - ok
11:13:36.0281 2064   UMWdf           (ab0a7ca90d9e3d6a193905dc1715ded0) C:\WINDOWS\system32\wdfmgr.exe
11:13:36.0281 2064   UMWdf - ok
11:13:36.0406 2064   Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:13:36.0437 2064   Update - ok
11:13:36.0546 2064   upnphost        (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
11:13:36.0546 2064   upnphost - ok
11:13:36.0671 2064   UPS             (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
11:13:36.0671 2064   UPS - ok

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #37 on: March 31, 2012, 12:22:32 PM »
11:13:24.0046 2064   MSKSSRV - ok
11:13:24.0140 2064   MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:13:24.0140 2064   MSPCLOCK - ok
11:13:24.0234 2064   MSPQM           (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:13:24.0234 2064   MSPQM - ok
11:13:24.0328 2064   mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:13:24.0328 2064   mssmbios - ok
11:13:24.0390 2064   MSTEE           (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
11:13:24.0406 2064   MSTEE - ok
11:13:24.0500 2064   ms_mpu401       (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
11:13:24.0500 2064   ms_mpu401 - ok
11:13:24.0625 2064   Mup             (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:13:24.0625 2064   Mup - ok
11:13:24.0687 2064   NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
11:13:24.0687 2064   NABTSFEC - ok
11:13:24.0796 2064   napagent        (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
11:13:24.0796 2064   napagent - ok
11:13:24.0890 2064   NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:13:24.0890 2064   NDIS - ok
11:13:24.0968 2064   NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
11:13:24.0968 2064   NdisIP - ok
11:13:25.0046 2064   NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:13:25.0046 2064   NdisTapi - ok
11:13:25.0171 2064   Ndisuio         (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:13:25.0171 2064   Ndisuio - ok
11:13:25.0250 2064   NdisWan         (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:13:25.0296 2064   NdisWan - ok
11:13:25.0531 2064   NDProxy         (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:13:25.0531 2064   NDProxy - ok
11:13:25.0609 2064   NetBIOS         (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:13:25.0609 2064   NetBIOS - ok
11:13:25.0687 2064   NetBT           (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:13:25.0703 2064   NetBT - ok
11:13:25.0796 2064   NetDDE          (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:13:25.0796 2064   NetDDE - ok
11:13:25.0812 2064   NetDDEdsdm      (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:13:25.0812 2064   NetDDEdsdm - ok
11:13:25.0890 2064   Netlogon        (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:25.0906 2064   Netlogon - ok
11:13:25.0968 2064   Netman          (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
11:13:25.0984 2064   Netman - ok
11:13:26.0062 2064   Nla             (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
11:13:26.0062 2064   Nla - ok
11:13:26.0156 2064   Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:13:26.0156 2064   Npfs - ok
11:13:26.0171 2064   NTACCESS - ok
11:13:26.0265 2064   Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:13:26.0265 2064   Ntfs - ok
11:13:26.0343 2064   NtLmSsp         (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:26.0343 2064   NtLmSsp - ok
11:13:26.0453 2064   NtmsSvc         (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
11:13:26.0453 2064   NtmsSvc - ok
11:13:26.0546 2064   Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:13:26.0546 2064   Null - ok
11:13:26.0625 2064   nvata           (0344aa9113dc16eec379f4652020849d) C:\WINDOWS\system32\DRIVERS\nvata.sys
11:13:26.0625 2064   nvata - ok
11:13:26.0687 2064   nvax            (f3d3015e52f2732042197d4edcaac2cb) C:\WINDOWS\system32\drivers\nvax.sys
11:13:26.0687 2064   nvax - ok
11:13:26.0765 2064   NVENETFD        (720cc533eecb65553bd86b139ca04433) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
11:13:26.0765 2064   NVENETFD - ok
11:13:26.0828 2064   nvnetbus        (5f9f545cc5904dd8765f84ee1d056406) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
11:13:26.0828 2064   nvnetbus - ok
11:13:26.0921 2064   nvnforce        (6d6fd2b7035d415621acaf1e555c8b90) C:\WINDOWS\system32\drivers\nvapu.sys
11:13:26.0937 2064   nvnforce - ok
11:13:27.0078 2064   NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:13:27.0078 2064   NwlnkFlt - ok
11:13:27.0203 2064   NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:13:27.0203 2064   NwlnkFwd - ok
11:13:27.0296 2064   ose             (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:13:27.0296 2064   ose - ok
11:13:27.0406 2064   p2pgasvc        (937a02981f11b2ce96b1d493c95aed2b) C:\WINDOWS\system32\p2pgasvc.dll
11:13:27.0406 2064   p2pgasvc - ok
11:13:27.0515 2064   p2pimsvc        (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:13:27.0531 2064   p2pimsvc - ok
11:13:27.0546 2064   p2psvc          (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:13:27.0562 2064   p2psvc - ok
11:13:27.0656 2064   Parport         (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
11:13:27.0656 2064   Parport - ok
11:13:27.0765 2064   PartMgr         (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:13:27.0765 2064   PartMgr - ok
11:13:27.0859 2064   ParVdm          (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
11:13:27.0859 2064   ParVdm - ok
11:13:27.0890 2064   PCANDIS5 - ok
11:13:27.0968 2064   PCI             (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
11:13:27.0968 2064   PCI - ok
11:13:28.0015 2064   PCIDump - ok
11:13:28.0140 2064   PCIIde          (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
11:13:28.0140 2064   PCIIde - ok
11:13:28.0187 2064   Pcmcia          (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
11:13:28.0203 2064   Pcmcia - ok
11:13:28.0250 2064   PDCOMP - ok
11:13:28.0296 2064   PDFRAME - ok
11:13:28.0343 2064   PDRELI - ok
11:13:28.0406 2064   PDRFRAME - ok
11:13:28.0453 2064   perc2 - ok
11:13:28.0484 2064   perc2hib - ok
11:13:28.0578 2064   PlugPlay        (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
11:13:28.0578 2064   PlugPlay - ok
11:13:28.0656 2064   PNRPSvc         (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:13:28.0671 2064   PNRPSvc - ok
11:13:28.0765 2064   PolicyAgent     (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:28.0765 2064   PolicyAgent - ok
11:13:28.0875 2064   PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:13:28.0875 2064   PptpMiniport - ok
11:13:28.0984 2064   Processor       (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
11:13:28.0984 2064   Processor - ok
11:13:29.0093 2064   ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:29.0093 2064   ProtectedStorage - ok
11:13:29.0218 2064   PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:13:29.0218 2064   PSched - ok
11:13:29.0296 2064   Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:13:29.0296 2064   Ptilink - ok
11:13:29.0375 2064   PxHelp20        (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
11:13:29.0375 2064   PxHelp20 - ok
11:13:29.0421 2064   ql1080 - ok
11:13:29.0453 2064   Ql10wnt - ok
11:13:29.0484 2064   ql12160 - ok
11:13:29.0515 2064   ql1240 - ok
11:13:29.0546 2064   ql1280 - ok
11:13:29.0609 2064   RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:13:29.0625 2064   RasAcd - ok
11:13:29.0687 2064   RasAuto         (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
11:13:29.0687 2064   RasAuto - ok
11:13:29.0765 2064   Rasirda         (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
11:13:29.0765 2064   Rasirda - ok
11:13:29.0843 2064   Rasl2tp         (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:13:29.0859 2064   Rasl2tp - ok
11:13:29.0921 2064   RasMan          (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
11:13:29.0921 2064   RasMan - ok
11:13:30.0031 2064   RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:13:30.0046 2064   RasPppoe - ok
11:13:30.0156 2064   Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:13:30.0156 2064   Raspti - ok
11:13:30.0265 2064   Rdbss           (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:13:30.0265 2064   Rdbss - ok
11:13:30.0359 2064   RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:13:30.0375 2064   RDPCDD - ok
11:13:30.0453 2064   RDPWD           (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
11:13:30.0468 2064   RDPWD - ok
11:13:30.0546 2064   RDSessMgr       (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
11:13:30.0562 2064   RDSessMgr - ok
11:13:30.0671 2064   redbook         (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:13:30.0671 2064   redbook - ok
11:13:30.0750 2064   RemoteAccess    (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
11:13:30.0750 2064   RemoteAccess - ok
11:13:30.0843 2064   RpcLocator      (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
11:13:30.0843 2064   RpcLocator - ok
11:13:30.0937 2064   RpcSs           (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
11:13:30.0953 2064   RpcSs - ok
11:13:31.0062 2064   RSVP            (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
11:13:31.0062 2064   RSVP - ok
11:13:31.0125 2064   RT2500USB - ok
11:13:31.0203 2064   SamSs           (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:13:31.0203 2064   SamSs - ok
11:13:31.0500 2064   SCardSvr        (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
11:13:31.0515 2064   SCardSvr - ok
11:13:31.0609 2064   Schedule        (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
11:13:31.0609 2064   Schedule - ok
11:13:31.0703 2064   Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:13:31.0703 2064   Secdrv - ok
11:13:31.0796 2064   seclogon        (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
11:13:31.0796 2064   seclogon - ok
11:13:31.0890 2064   senfilt         (bb596a578330ad794c6769b588af6bb4) C:\WINDOWS\system32\drivers\senfilt.sys
11:13:31.0906 2064   senfilt - ok
11:13:32.0015 2064   SENS            (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
11:13:32.0031 2064   SENS - ok
11:13:32.0140 2064   serenum         (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:13:32.0140 2064   serenum - ok
11:13:32.0203 2064   Serial          (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
11:13:32.0218 2064   Serial - ok
11:13:32.0218 2064   SetupNTGLM7X - ok
11:13:32.0328 2064   sfdrv01         (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
11:13:32.0328 2064   sfdrv01 - ok
11:13:32.0437 2064   sfhlp02         (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
11:13:32.0437 2064   sfhlp02 - ok
11:13:32.0546 2064   Sfloppy         (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
11:13:32.0546 2064   Sfloppy - ok
11:13:32.0593 2064   sfsync02 - ok
11:13:32.0671 2064   SharedAccess    (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
11:13:32.0687 2064   SharedAccess - ok
11:13:32.0796 2064   ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:13:32.0796 2064   ShellHWDetection - ok
11:13:32.0859 2064   Simbad - ok
11:13:32.0921 2064   SimpTcp         (32933b07fc16d9f778bee12545fa1b1a) C:\WINDOWS\system32\tcpsvcs.exe
11:13:32.0937 2064   SimpTcp - ok
11:13:33.0046 2064   SiSGbeXP        (a86e52c55de3488b3fc0ff2b8ad711bf) C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys
11:13:33.0046 2064   SiSGbeXP - ok
11:13:33.0109 2064   SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
11:13:33.0109 2064   SLIP - ok
11:13:33.0218 2064   smwdm           (0d7efa9d5bac36ea49940a8ead9990b5) C:\WINDOWS\system32\drivers\smwdm.sys
11:13:33.0218 2064   smwdm - ok
11:13:33.0328 2064   SNMP            (60c377be6b3cc83f6a8584934b181d2e) C:\WINDOWS\System32\snmp.exe
11:13:33.0328 2064   SNMP - ok
11:13:33.0453 2064   SNMPTRAP        (80a050795a107a76c2b1cd4cfbe010e6) C:\WINDOWS\System32\snmptrap.exe
11:13:33.0453 2064   SNMPTRAP - ok
11:13:33.0578 2064   SoundMAX Agent Service (default) (3978f082274f723ad5a0a8058c2417dd) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
11:13:33.0578 2064   SoundMAX Agent Service (default) - ok
11:13:33.0656 2064   Sparrow - ok
11:13:33.0718 2064   splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:13:33.0718 2064   splitter - ok
11:13:33.0796 2064   Spooler         (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
11:13:33.0796 2064   Spooler - ok
11:13:33.0859 2064   sr              (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
11:13:33.0859 2064   sr - ok
11:13:33.0937 2064   srservice       (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
11:13:33.0953 2064   srservice - ok
11:13:34.0046 2064   Srv             (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
11:13:34.0062 2064   Srv - ok
11:13:34.0171 2064   SSDPSRV         (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
11:13:34.0171 2064   SSDPSRV - ok
11:13:34.0265 2064   stisvc          (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
11:13:34.0281 2064   stisvc - ok
11:13:34.0375 2064   streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
11:13:34.0375 2064   streamip - ok
11:13:34.0468 2064   swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:13:34.0468 2064   swenum - ok
11:13:34.0562 2064   swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:13:34.0562 2064   swmidi - ok
11:13:34.0625 2064   SwPrv - ok
11:13:34.0656 2064   symc810 - ok
11:13:34.0718 2064   symc8xx - ok
11:13:34.0765 2064   sym_hi - ok
11:13:34.0812 2064   sym_u3 - ok
11:13:34.0890 2064   sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:13:34.0890 2064   sysaudio - ok
11:13:35.0000 2064   SysmonLog       (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
11:13:35.0000 2064   SysmonLog - ok
11:13:35.0093 2064   TapiSrv         (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
11:13:35.0093 2064   TapiSrv - ok
11:13:35.0187 2064   Tcpip           (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:13:35.0187 2064   Tcpip - ok
11:13:35.0296 2064   Tcpip6          (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
11:13:35.0296 2064   Tcpip6 - ok
11:13:35.0375 2064   TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:13:35.0375 2064   TDPIPE - ok
11:13:35.0453 2064   TDTCP           (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:13:35.0453 2064   TDTCP - ok
11:13:35.0531 2064   TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:13:35.0531 2064   TermDD - ok
11:13:35.0625 2064   TermService     (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
11:13:35.0625 2064   TermService - ok
11:13:35.0750 2064   Themes          (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:13:35.0750 2064   Themes - ok
11:13:35.0828 2064   TosIde - ok
11:13:35.0921 2064   TrkWks          (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
11:13:35.0921 2064   TrkWks - ok
11:13:36.0031 2064   tunmp           (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
11:13:36.0031 2064   tunmp - ok
11:13:36.0125 2064   Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:13:36.0125 2064   Udfs - ok
11:13:36.0203 2064   ultra - ok
11:13:36.0281 2064   UMWdf           (ab0a7ca90d9e3d6a193905dc1715ded0) C:\WINDOWS\system32\wdfmgr.exe
11:13:36.0281 2064   UMWdf - ok
11:13:36.0406 2064   Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:13:36.0437 2064   Update - ok
11:13:36.0546 2064   upnphost        (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
11:13:36.0546 2064   upnphost - ok
11:13:36.0671 2064   UPS             (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
11:13:36.0671 2064   UPS - ok

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #38 on: March 31, 2012, 12:24:05 PM »
11:13:36.0734 2064   USBAAPL - ok
11:13:36.0796 2064   usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
11:13:36.0796 2064   usbaudio - ok
11:13:36.0906 2064   usbccgp         (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:13:36.0906 2064   usbccgp - ok
11:13:36.0968 2064   usbehci         (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:13:36.0984 2064   usbehci - ok
11:13:37.0062 2064   usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:13:37.0062 2064   usbhub - ok
11:13:37.0156 2064   usbohci         (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
11:13:37.0156 2064   usbohci - ok
11:13:37.0234 2064   usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
11:13:37.0234 2064   usbprint - ok
11:13:37.0296 2064   usbscan         (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
11:13:37.0296 2064   usbscan - ok
11:13:37.0359 2064   USBSTOR         (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:13:37.0375 2064   USBSTOR - ok
11:13:37.0453 2064   usbvideo        (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
11:13:37.0453 2064   usbvideo - ok
11:13:37.0562 2064   UTSCSI          (1413e1f3b48a0d36b9e6ad4ec40eb5da) C:\WINDOWS\system32\UTSCSI.EXE
11:13:37.0562 2064   UTSCSI - ok
11:13:37.0656 2064   VgaSave         (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
11:13:37.0656 2064   VgaSave - ok
11:13:37.0718 2064   ViaIde - ok
11:13:37.0812 2064   VolSnap         (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
11:13:37.0812 2064   VolSnap - ok
11:13:37.0906 2064   VSS             (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
11:13:37.0937 2064   VSS - ok
11:13:38.0125 2064   vToolbarUpdater10.2.0 (3080f1f093869a19fb3d1f0226c73809) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
11:13:38.0171 2064   vToolbarUpdater10.2.0 - ok
11:13:38.0281 2064   W32Time         (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
11:13:38.0281 2064   W32Time - ok
11:13:38.0390 2064   Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:13:38.0390 2064   Wanarp - ok
11:13:38.0531 2064   WDICA - ok
11:13:38.0609 2064   wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
11:13:38.0640 2064   wdmaud - ok
11:13:38.0765 2064   WebClient       (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
11:13:38.0765 2064   WebClient - ok
11:13:39.0218 2064   winmgmt         (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
11:13:39.0218 2064   winmgmt - ok
11:13:39.0437 2064   WmdmPmSN        (140ef97b64f560fd78643cae2cdad838) C:\WINDOWS\system32\mspmsnsv.dll
11:13:39.0468 2064   WmdmPmSN - ok
11:13:39.0781 2064   WmiApSrv        (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
11:13:39.0781 2064   WmiApSrv - ok
11:13:39.0953 2064   WMPNetworkSvc   (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
11:13:40.0156 2064   WMPNetworkSvc - ok
11:13:40.0375 2064   WpdUsb          (1385e5aa9c9821790d33a9563b8d2dd0) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
11:13:40.0375 2064   WpdUsb - ok
11:13:40.0750 2064   WS2IFSL         (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
11:13:40.0781 2064   WS2IFSL - ok
11:13:40.0875 2064   wscsvc          (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
11:13:40.0875 2064   wscsvc - ok
11:13:40.0984 2064   WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
11:13:40.0984 2064   WSTCODEC - ok
11:13:41.0078 2064   wuauserv        (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
11:13:41.0078 2064   wuauserv - ok
11:13:41.0171 2064   WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:13:41.0171 2064   WudfPf - ok
11:13:41.0281 2064   WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:13:41.0281 2064   WudfRd - ok
11:13:41.0375 2064   WudfSvc         (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
11:13:41.0375 2064   WudfSvc - ok
11:13:41.0515 2064   WZCSVC          (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
11:13:41.0531 2064   WZCSVC - ok
11:13:41.0625 2064   xmlprov         (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
11:13:41.0625 2064   xmlprov - ok
11:13:41.0671 2064   MBR (0x1B8)     (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
11:13:41.0828 2064   \Device\Harddisk0\DR0 - ok
11:13:41.0828 2064   Boot (0x1200)   (e492b30b1b00693dd34a17ab442d3836) \Device\Harddisk0\DR0\Partition0
11:13:41.0828 2064   \Device\Harddisk0\DR0\Partition0 - ok
11:13:41.0843 2064   ============================================================
11:13:41.0843 2064   Scan finished
11:13:41.0843 2064   ============================================================
11:13:41.0859 2100   Detected object count: 0
11:13:41.0859 2100   Actual detected object count: 0
11:14:38.0843 4696   ============================================================
11:14:38.0843 4696   Scan started
11:14:38.0843 4696   Mode: Manual; SigCheck; TDLFS;
11:14:38.0843 4696   ============================================================
11:14:39.0109 4696   6to4            (c07d5197410aab28d0d93f943f59656d) C:\WINDOWS\System32\6to4svc.dll
11:14:39.0296 4696   6to4 - ok
11:14:39.0375 4696   Abiosdsk - ok
11:14:39.0406 4696   abp480n5 - ok
11:14:39.0484 4696   ACPI            (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
11:14:40.0031 4696   ACPI - ok
11:14:40.0125 4696   ACPIEC          (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
11:14:40.0250 4696   ACPIEC - ok
11:14:40.0296 4696   adpu160m - ok
11:14:40.0406 4696   aeaudio         (9f59ae2de835641fbb0c6afd80d8fa9b) C:\WINDOWS\system32\drivers\aeaudio.sys
11:14:40.0453 4696   aeaudio - ok
11:14:40.0546 4696   aec             (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
11:14:40.0687 4696   aec - ok
11:14:40.0781 4696   AFD             (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys
11:14:40.0843 4696   AFD - ok
11:14:40.0906 4696   Aha154x - ok
11:14:40.0937 4696   aic78u2 - ok
11:14:40.0984 4696   aic78xx - ok
11:14:41.0015 4696   ALCXWDM - ok
11:14:41.0078 4696   Alerter         (a9a3daa780ca6c9671a19d52456705b4) C:\WINDOWS\system32\alrsvc.dll
11:14:41.0203 4696   Alerter - ok
11:14:41.0312 4696   ALG             (8c515081584a38aa007909cd02020b3d) C:\WINDOWS\System32\alg.exe
11:14:41.0437 4696   ALG - ok
11:14:41.0500 4696   AliIde - ok
11:14:41.0578 4696   AmdK8           (59301936898ae62245a6f09c0aba9475) C:\WINDOWS\system32\DRIVERS\AmdK8.sys
11:14:41.0609 4696   AmdK8 - ok
11:14:41.0671 4696   amsint - ok
11:14:41.0703 4696   AppMgmt - ok
11:14:41.0734 4696   asc - ok
11:14:41.0765 4696   asc3350p - ok
11:14:41.0812 4696   asc3550 - ok
11:14:41.0890 4696   aspnet_state    (e1a1206a4fb19b675e947b29ccd25fba) C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
11:14:41.0906 4696   aspnet_state ( UnsignedFile.Multi.Generic ) - warning
11:14:41.0906 4696   aspnet_state - detected UnsignedFile.Multi.Generic (1)
11:14:41.0984 4696   AsyncMac        (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
11:14:42.0109 4696   AsyncMac - ok
11:14:42.0203 4696   atapi           (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
11:14:42.0359 4696   atapi - ok
11:14:42.0406 4696   Atdisk - ok
11:14:42.0500 4696   Ati HotKey Poller (c23082b890f21267037ca6111c385ff3) C:\WINDOWS\system32\Ati2evxx.exe
11:14:42.0578 4696   Ati HotKey Poller - ok
11:14:42.0687 4696   ATI Smart       (0d582dc5e3f74cea1bf56ba2a925d0f2) C:\WINDOWS\system32\ati2sgag.exe
11:14:42.0750 4696   ATI Smart ( UnsignedFile.Multi.Generic ) - warning
11:14:42.0750 4696   ATI Smart - detected UnsignedFile.Multi.Generic (1)
11:14:42.0890 4696   ati2mtag        (f5fc6ac1e7bc776871361d463fc86be2) C:\WINDOWS\system32\DRIVERS\ati2mtag.sys
11:14:42.0984 4696   ati2mtag - ok
11:14:43.0078 4696   Atmarpc         (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
11:14:43.0203 4696   Atmarpc - ok
11:14:43.0296 4696   AudioSrv        (def7a7882bec100fe0b2ce2549188f9d) C:\WINDOWS\System32\audiosrv.dll
11:14:43.0421 4696   AudioSrv - ok
11:14:43.0515 4696   audstub         (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
11:14:43.0671 4696   audstub - ok
11:14:43.0921 4696   AVGIDSAgent     (6d440ff3f44ca72edfd6176c6d6a89c0) C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe
11:14:44.0125 4696   AVGIDSAgent - ok
11:14:44.0250 4696   AVGIDSDriver    (4fa401b33c1b50c816486f6951244a14) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
11:14:44.0281 4696   AVGIDSDriver - ok
11:14:44.0375 4696   AVGIDSEH        (69578bc9d43d614c6b3455db4af19762) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
11:14:44.0375 4696   AVGIDSEH - ok
11:14:44.0453 4696   AVGIDSFilter    (6df528406aa22201f392b9b19121cd6f) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
11:14:44.0453 4696   AVGIDSFilter - ok
11:14:44.0531 4696   AVGIDSShim      (1e01c2166b5599802bcd61b9691f7476) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
11:14:44.0531 4696   AVGIDSShim - ok
11:14:44.0578 4696   Avgldx86        (bf8118cd5e2255387b715b534d64acd1) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
11:14:44.0593 4696   Avgldx86 - ok
11:14:44.0656 4696   Avgmfx86        (1c77ef67f196466adc9924cb288afe87) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
11:14:44.0671 4696   Avgmfx86 - ok
11:14:44.0734 4696   Avgrkx86        (f2038ed7284b79dcef581468121192a9) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
11:14:44.0750 4696   Avgrkx86 - ok
11:14:44.0828 4696   Avgtdix         (a6d562b612216d8d02a35ebeb92366bd) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
11:14:44.0843 4696   Avgtdix - ok
11:14:44.0968 4696   avgwd           (6699ece24fe4b3f752a66c66a602ee86) C:\Program Files\AVG\AVG2012\avgwdsvc.exe
11:14:44.0984 4696   avgwd - ok
11:14:45.0093 4696   Beep            (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
11:14:45.0437 4696   Beep - ok
11:14:45.0515 4696   BITS            (574738f61fca2935f5265dc4e5691314) C:\WINDOWS\system32\qmgr.dll
11:14:45.0656 4696   BITS - ok
11:14:45.0734 4696   Bonjour Service (3f56903e124e820aeece6d471583c6c1) C:\Program Files\Bonjour\mDNSResponder.exe
11:14:45.0734 4696   Bonjour Service - ok
11:14:45.0843 4696   Browser         (a06ce3399d16db864f55faeb1f1927a9) C:\WINDOWS\System32\browser.dll
11:14:45.0984 4696   Browser - ok
11:14:46.0000 4696   catchme - ok
11:14:46.0078 4696   cbidf2k         (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
11:14:46.0218 4696   cbidf2k - ok
11:14:46.0312 4696   CCDECODE        (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
11:14:46.0421 4696   CCDECODE - ok
11:14:46.0484 4696   cd20xrnt - ok
11:14:46.0562 4696   Cdaudio         (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
11:14:46.0718 4696   Cdaudio - ok
11:14:46.0796 4696   Cdfs            (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
11:14:46.0921 4696   Cdfs - ok
11:14:47.0031 4696   Cdrom           (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
11:14:47.0156 4696   Cdrom - ok
11:14:47.0218 4696   Changer - ok
11:14:47.0296 4696   CiSvc           (1cfe720eb8d93a7158a4ebc3ab178bde) C:\WINDOWS\system32\cisvc.exe
11:14:47.0421 4696   CiSvc - ok
11:14:47.0500 4696   ClipSrv         (34cbe729f38138217f9c80212a2a0c82) C:\WINDOWS\system32\clipsrv.exe
11:14:47.0625 4696   ClipSrv - ok
11:14:47.0687 4696   CmdIde - ok
11:14:47.0718 4696   COMSysApp - ok
11:14:47.0765 4696   Cpqarray - ok
11:14:47.0828 4696   CryptSvc        (3d4e199942e29207970e04315d02ad3b) C:\WINDOWS\System32\cryptsvc.dll
11:14:47.0968 4696   CryptSvc - ok
11:14:48.0031 4696   dac2w2k - ok
11:14:48.0062 4696   dac960nt - ok
11:14:48.0156 4696   DcomLaunch      (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\system32\rpcss.dll
11:14:48.0218 4696   DcomLaunch - ok
11:14:48.0328 4696   Dhcp            (5e38d7684a49cacfb752b046357e0589) C:\WINDOWS\System32\dhcpcsvc.dll
11:14:48.0453 4696   Dhcp - ok
11:14:48.0546 4696   Disk            (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
11:14:48.0687 4696   Disk - ok
11:14:48.0734 4696   dlcc_device - ok
11:14:48.0765 4696   dlcx_device - ok
11:14:48.0796 4696   dmadmin - ok
11:14:48.0875 4696   dmboot          (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
11:14:49.0031 4696   dmboot - ok
11:14:49.0109 4696   dmio            (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
11:14:49.0234 4696   dmio - ok
11:14:49.0328 4696   dmload          (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
11:14:49.0468 4696   dmload - ok
11:14:49.0562 4696   dmserver        (57edec2e5f59f0335e92f35184bc8631) C:\WINDOWS\System32\dmserver.dll
11:14:49.0671 4696   dmserver - ok
11:14:49.0765 4696   DMusic          (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
11:14:49.0906 4696   DMusic - ok

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #39 on: March 31, 2012, 12:25:16 PM »
11:14:49.0984 4696   Dnscache        (5f7e24fa9eab896051ffb87f840730d2) C:\WINDOWS\System32\dnsrslvr.dll
11:14:50.0015 4696   Dnscache - ok
11:14:50.0109 4696   Dot3svc         (0f0f6e687e5e15579ef4da8dd6945814) C:\WINDOWS\System32\dot3svc.dll
11:14:50.0234 4696   Dot3svc - ok
11:14:50.0328 4696   dot4            (3e4b043f8bc6be1d4820cc6c9c500306) C:\WINDOWS\system32\DRIVERS\Dot4.sys
11:14:50.0593 4696   dot4 - ok
11:14:50.0687 4696   Dot4Print       (77ce63a8a34ae23d9fe4c7896d1debe7) C:\WINDOWS\system32\DRIVERS\Dot4Prt.sys
11:14:50.0828 4696   Dot4Print - ok
11:14:50.0921 4696   dot4usb         (6ec3af6bb5b30e488a0c559921f012e1) C:\WINDOWS\system32\DRIVERS\dot4usb.sys
11:14:51.0062 4696   dot4usb - ok
11:14:51.0125 4696   dpti2o - ok
11:14:51.0218 4696   drmkaud         (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
11:14:51.0343 4696   drmkaud - ok
11:14:51.0437 4696   EapHost         (2187855a7703adef0cef9ee4285182cc) C:\WINDOWS\System32\eapsvc.dll
11:14:51.0546 4696   EapHost - ok
11:14:51.0625 4696   ERSvc           (bc93b4a066477954555966d77fec9ecb) C:\WINDOWS\System32\ersvc.dll
11:14:51.0750 4696   ERSvc - ok
11:14:51.0859 4696   Eventlog        (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
11:14:51.0890 4696   Eventlog - ok
11:14:51.0984 4696   EventSystem     (d4991d98f2db73c60d042f1aef79efae) C:\WINDOWS\system32\es.dll
11:14:52.0031 4696   EventSystem - ok
11:14:52.0156 4696   Fastfat         (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
11:14:52.0296 4696   Fastfat - ok
11:14:52.0390 4696   FastUserSwitchingCompatibility (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:14:52.0437 4696   FastUserSwitchingCompatibility - ok
11:14:52.0546 4696   Fdc             (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
11:14:52.0671 4696   Fdc - ok
11:14:52.0765 4696   Fips            (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
11:14:52.0890 4696   Fips - ok
11:14:52.0968 4696   Flpydisk        (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
11:14:53.0109 4696   Flpydisk - ok
11:14:53.0203 4696   FltMgr          (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
11:14:53.0343 4696   FltMgr - ok
11:14:53.0437 4696   Fs_Rec          (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
11:14:53.0578 4696   Fs_Rec - ok
11:14:53.0671 4696   Ftdisk          (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
11:14:53.0843 4696   Ftdisk - ok
11:14:53.0859 4696   GMSIPCI - ok
11:14:53.0953 4696   Gpc             (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
11:14:54.0062 4696   Gpc - ok
11:14:54.0187 4696   helpsvc         (4fcca060dfe0c51a09dd5c3843888bcd) C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
11:14:54.0312 4696   helpsvc - ok
11:14:54.0421 4696   HidServ         (deb04da35cc871b6d309b77e1443c796) C:\WINDOWS\System32\hidserv.dll
11:14:54.0531 4696   HidServ - ok
11:14:54.0640 4696   HidUsb          (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
11:14:54.0765 4696   HidUsb - ok
11:14:54.0859 4696   hkmsvc          (8878bd685e490239777bfe51320b88e9) C:\WINDOWS\System32\kmsvc.dll
11:14:54.0968 4696   hkmsvc - ok
11:14:55.0046 4696   hpn - ok
11:14:55.0109 4696   HTTP            (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
11:14:55.0140 4696   HTTP - ok
11:14:55.0250 4696   HTTPFilter      (6100a808600f44d999cebdef8841c7a3) C:\WINDOWS\System32\w3ssl.dll
11:14:55.0359 4696   HTTPFilter - ok
11:14:55.0421 4696   i2omgmt - ok
11:14:55.0453 4696   i2omp - ok
11:14:55.0531 4696   i8042prt        (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
11:14:55.0671 4696   i8042prt - ok
11:14:55.0765 4696   Imapi           (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
11:14:55.0890 4696   Imapi - ok
11:14:55.0984 4696   ImapiService    (30deaf54a9755bb8546168cfe8a6b5e1) C:\WINDOWS\system32\imapi.exe
11:14:56.0109 4696   ImapiService - ok
11:14:56.0171 4696   InCDFs - ok
11:14:56.0234 4696   InCDPass - ok
11:14:56.0265 4696   InCDRm - ok
11:14:56.0296 4696   ini910u - ok
11:14:56.0328 4696   IntelIde - ok
11:14:56.0406 4696   Ip6Fw           (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
11:14:56.0531 4696   Ip6Fw - ok
11:14:56.0625 4696   IpFilterDriver  (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
11:14:56.0781 4696   IpFilterDriver - ok
11:14:56.0859 4696   IpInIp          (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
11:14:56.0984 4696   IpInIp - ok
11:14:57.0062 4696   IPN2220         (eadcbd84f788d887e73d8c7691b2c508) C:\WINDOWS\system32\DRIVERS\i2220ntx.sys
11:14:57.0078 4696   IPN2220 ( UnsignedFile.Multi.Generic ) - warning
11:14:57.0078 4696   IPN2220 - detected UnsignedFile.Multi.Generic (1)
11:14:57.0187 4696   IpNat           (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
11:14:57.0312 4696   IpNat - ok
11:14:57.0406 4696   Iprip           (f08d74ec300b8ba60ca953c58a24d19e) C:\WINDOWS\System32\iprip.dll
11:14:57.0531 4696   Iprip - ok
11:14:57.0640 4696   IPSec           (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
11:14:57.0765 4696   IPSec - ok
11:14:57.0875 4696   irda            (aca5e7b54409f9cb5eed97ed0c81120e) C:\WINDOWS\system32\DRIVERS\irda.sys
11:14:58.0000 4696   irda - ok
11:14:58.0078 4696   IRENUM          (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
11:14:58.0203 4696   IRENUM - ok
11:14:58.0328 4696   Irmon           (49cc4533ce897cb2e93c1e84a818fde5) C:\WINDOWS\System32\irmon.dll
11:14:58.0453 4696   Irmon - ok
11:14:58.0515 4696   irsir - ok
11:14:58.0578 4696   isapnp          (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
11:14:58.0703 4696   isapnp - ok
11:14:58.0843 4696   JavaQuickStarterService (9aa67569d5257462e230767510b0c815) C:\Program Files\Java\jre6\bin\jqs.exe
11:14:58.0859 4696   JavaQuickStarterService - ok
11:14:58.0968 4696   Kbdclass        (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
11:14:59.0093 4696   Kbdclass - ok
11:14:59.0187 4696   kbdhid          (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
11:14:59.0281 4696   kbdhid - ok
11:14:59.0359 4696   kmixer          (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
11:14:59.0500 4696   kmixer - ok
11:14:59.0578 4696   KSecDD          (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
11:14:59.0609 4696   KSecDD - ok
11:14:59.0703 4696   lanmanserver    (3a7c3cbe5d96b8ae96ce81f0b22fb527) C:\WINDOWS\System32\srvsvc.dll
11:14:59.0750 4696   lanmanserver - ok
11:14:59.0859 4696   lanmanworkstation (a8888a5327621856c0cec4e385f69309) C:\WINDOWS\System32\wkssvc.dll
11:14:59.0890 4696   lanmanworkstation - ok
11:14:59.0953 4696   lbrtfdc - ok
11:15:00.0046 4696   LmHosts         (a7db739ae99a796d91580147e919cc59) C:\WINDOWS\System32\lmhsvc.dll
11:15:00.0171 4696   LmHosts - ok
11:15:00.0281 4696   LPDSVC          (32933b07fc16d9f778bee12545fa1b1a) C:\WINDOWS\system32\tcpsvcs.exe
11:15:00.0437 4696   LPDSVC - ok
11:15:00.0562 4696   MDM             (11f714f85530a2bd134074dc30e99fca) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
11:15:00.0578 4696   MDM - ok
11:15:00.0671 4696   Messenger       (986b1ff5814366d71e0ac5755c88f2d3) C:\WINDOWS\System32\msgsvc.dll
11:15:00.0781 4696   Messenger - ok
11:15:00.0890 4696   MidiSyn         (8c7d037a53b495e7c250fd70b158b581) C:\WINDOWS\system32\drivers\MidiSyn.sys
11:15:00.0921 4696   MidiSyn - ok
11:15:01.0015 4696   mnmdd           (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
11:15:01.0187 4696   mnmdd - ok
11:15:01.0453 4696   mnmsrvc         (d18f1f0c101d06a1c1adf26eed16fcdd) C:\WINDOWS\system32\mnmsrvc.exe
11:15:01.0562 4696   mnmsrvc - ok
11:15:01.0656 4696   Modem           (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
11:15:01.0765 4696   Modem - ok
11:15:01.0843 4696   Mouclass        (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
11:15:01.0968 4696   Mouclass - ok
11:15:02.0062 4696   mouhid          (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
11:15:02.0218 4696   mouhid - ok
11:15:02.0312 4696   MountMgr        (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
11:15:02.0421 4696   MountMgr - ok
11:15:02.0468 4696   mraid35x - ok
11:15:02.0546 4696   MRxDAV          (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
11:15:02.0671 4696   MRxDAV - ok
11:15:02.0781 4696   MRxSmb          (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
11:15:02.0859 4696   MRxSmb - ok
11:15:02.0953 4696   MSDTC           (a137f1470499a205abbb9aafb3b6f2b1) C:\WINDOWS\system32\msdtc.exe
11:15:03.0062 4696   MSDTC - ok
11:15:03.0156 4696   Msfs            (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
11:15:03.0281 4696   Msfs - ok
11:15:03.0312 4696   MSIServer - ok
11:15:03.0375 4696   MSKSSRV         (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
11:15:03.0484 4696   MSKSSRV - ok
11:15:03.0562 4696   MSPCLOCK        (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
11:15:03.0687 4696   MSPCLOCK - ok
11:15:03.0765 4696   MSPQM           (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
11:15:03.0875 4696   MSPQM - ok
11:15:03.0968 4696   mssmbios        (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
11:15:04.0062 4696   mssmbios - ok
11:15:04.0125 4696   MSTEE           (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
11:15:04.0250 4696   MSTEE - ok
11:15:04.0343 4696   ms_mpu401       (ca3e22598f411199adc2dfee76cd0ae0) C:\WINDOWS\system32\drivers\msmpu401.sys
11:15:04.0484 4696   ms_mpu401 - ok
11:15:04.0593 4696   Mup             (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys
11:15:04.0625 4696   Mup - ok
11:15:04.0734 4696   NABTSFEC        (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
11:15:04.0843 4696   NABTSFEC - ok
11:15:04.0921 4696   napagent        (0102140028fad045756796e1c685d695) C:\WINDOWS\System32\qagentrt.dll
11:15:05.0031 4696   napagent - ok
11:15:05.0140 4696   NDIS            (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
11:15:05.0265 4696   NDIS - ok
11:15:05.0359 4696   NdisIP          (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
11:15:05.0453 4696   NdisIP - ok
11:15:05.0546 4696   NdisTapi        (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
11:15:05.0593 4696   NdisTapi - ok
11:15:05.0671 4696   Ndisuio         (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
11:15:05.0796 4696   Ndisuio - ok
11:15:05.0875 4696   NdisWan         (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
11:15:06.0000 4696   NdisWan - ok
11:15:06.0109 4696   NDProxy         (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
11:15:06.0156 4696   NDProxy - ok
11:15:06.0265 4696   NetBIOS         (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
11:15:06.0375 4696   NetBIOS - ok
11:15:06.0468 4696   NetBT           (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
11:15:06.0578 4696   NetBT - ok
11:15:06.0656 4696   NetDDE          (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:15:06.0781 4696   NetDDE - ok
11:15:06.0781 4696   NetDDEdsdm      (b857ba82860d7ff85ae29b095645563b) C:\WINDOWS\system32\netdde.exe
11:15:06.0906 4696   NetDDEdsdm - ok
11:15:07.0000 4696   Netlogon        (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:15:07.0093 4696   Netlogon - ok
11:15:07.0203 4696   Netman          (13e67b55b3abd7bf3fe7aae5a0f9a9de) C:\WINDOWS\System32\netman.dll
11:15:07.0343 4696   Netman - ok
11:15:07.0437 4696   Nla             (943337d786a56729263071623bbb9de5) C:\WINDOWS\System32\mswsock.dll
11:15:07.0468 4696   Nla - ok
11:15:07.0562 4696   Npfs            (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
11:15:07.0687 4696   Npfs - ok
11:15:07.0687 4696   NTACCESS - ok
11:15:07.0796 4696   Ntfs            (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
11:15:07.0953 4696   Ntfs - ok
11:15:08.0046 4696   NtLmSsp         (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:15:08.0156 4696   NtLmSsp - ok
11:15:08.0250 4696   NtmsSvc         (156f64a3345bd23c600655fb4d10bc08) C:\WINDOWS\system32\ntmssvc.dll
11:15:08.0390 4696   NtmsSvc - ok
11:15:08.0484 4696   Null            (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
11:15:08.0640 4696   Null - ok
11:15:08.0718 4696   nvata           (0344aa9113dc16eec379f4652020849d) C:\WINDOWS\system32\DRIVERS\nvata.sys
11:15:08.0781 4696   nvata - ok
11:15:08.0843 4696   nvax            (f3d3015e52f2732042197d4edcaac2cb) C:\WINDOWS\system32\drivers\nvax.sys
11:15:08.0875 4696   nvax - ok
11:15:08.0953 4696   NVENETFD        (720cc533eecb65553bd86b139ca04433) C:\WINDOWS\system32\DRIVERS\NVENETFD.sys
11:15:08.0984 4696   NVENETFD - ok
11:15:09.0078 4696   nvnetbus        (5f9f545cc5904dd8765f84ee1d056406) C:\WINDOWS\system32\DRIVERS\nvnetbus.sys
11:15:09.0109 4696   nvnetbus - ok
11:15:09.0234 4696   nvnforce        (6d6fd2b7035d415621acaf1e555c8b90) C:\WINDOWS\system32\drivers\nvapu.sys
11:15:09.0453 4696   nvnforce - ok
11:15:09.0546 4696   NwlnkFlt        (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
11:15:09.0718 4696   NwlnkFlt - ok
11:15:09.0796 4696   NwlnkFwd        (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
11:15:09.0953 4696   NwlnkFwd - ok
11:15:10.0031 4696   ose             (7a56cf3e3f12e8af599963b16f50fb6a) C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
11:15:10.0031 4696   ose - ok
11:15:10.0125 4696   p2pgasvc        (937a02981f11b2ce96b1d493c95aed2b) C:\WINDOWS\system32\p2pgasvc.dll
11:15:10.0250 4696   p2pgasvc - ok
11:15:10.0375 4696   p2pimsvc        (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:15:10.0515 4696   p2pimsvc - ok
11:15:10.0546 4696   p2psvc          (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:15:10.0656 4696   p2psvc - ok
11:15:10.0750 4696   Parport         (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
11:15:10.0875 4696   Parport - ok
11:15:10.0953 4696   PartMgr         (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
11:15:11.0125 4696   PartMgr - ok
11:15:11.0203 4696   ParVdm          (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
11:15:11.0375 4696   ParVdm - ok
11:15:11.0406 4696   PCANDIS5 - ok
11:15:11.0500 4696   PCI             (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
11:15:11.0609 4696   PCI - ok
11:15:11.0671 4696   PCIDump - ok
11:15:11.0750 4696   PCIIde          (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
11:15:11.0890 4696   PCIIde - ok
11:15:11.0984 4696   Pcmcia          (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
11:15:12.0093 4696   Pcmcia - ok
11:15:12.0140 4696   PDCOMP - ok
11:15:12.0187 4696   PDFRAME - ok
11:15:12.0234 4696   PDRELI - ok
11:15:12.0265 4696   PDRFRAME - ok
11:15:12.0296 4696   perc2 - ok
11:15:12.0343 4696   perc2hib - ok
11:15:12.0437 4696   PlugPlay        (65df52f5b8b6e9bbd183505225c37315) C:\WINDOWS\system32\services.exe
11:15:12.0468 4696   PlugPlay - ok
11:15:12.0562 4696   PNRPSvc         (4a1035cb8f0d57be41873b5183d96cf4) C:\WINDOWS\system32\p2psvc.dll
11:15:12.0687 4696   PNRPSvc - ok
11:15:12.0781 4696   PolicyAgent     (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:15:12.0875 4696   PolicyAgent - ok
11:15:12.0984 4696   PptpMiniport    (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
11:15:13.0109 4696   PptpMiniport - ok
11:15:13.0187 4696   Processor       (a32bebaf723557681bfc6bd93e98bd26) C:\WINDOWS\system32\DRIVERS\processr.sys
11:15:13.0312 4696   Processor - ok
11:15:13.0406 4696   ProtectedStorage (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:15:13.0515 4696   ProtectedStorage - ok
11:15:13.0609 4696   PSched          (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
11:15:13.0734 4696   PSched - ok
11:15:13.0828 4696   Ptilink         (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
11:15:13.0984 4696   Ptilink - ok
11:15:14.0078 4696   PxHelp20        (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
11:15:14.0078 4696   PxHelp20 - ok
11:15:14.0125 4696   ql1080 - ok
11:15:14.0187 4696   Ql10wnt - ok
11:15:14.0234 4696   ql12160 - ok
11:15:14.0265 4696   ql1240 - ok
11:15:14.0296 4696   ql1280 - ok
11:15:14.0375 4696   RasAcd          (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
11:15:14.0515 4696   RasAcd - ok
11:15:14.0578 4696   RasAuto         (ad188be7bdf94e8df4ca0a55c00a5073) C:\WINDOWS\System32\rasauto.dll
11:15:14.0703 4696   RasAuto - ok
11:15:14.0781 4696   Rasirda         (0207d26ddf796a193ccd9f83047bb5fc) C:\WINDOWS\system32\DRIVERS\rasirda.sys
11:15:14.0843 4696   Rasirda - ok
11:15:14.0937 4696   Rasl2tp         (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
11:15:15.0046 4696   Rasl2tp - ok
11:15:15.0109 4696   RasMan          (76a9a3cbeadd68cc57cda5e1d7448235) C:\WINDOWS\System32\rasmans.dll
11:15:15.0218 4696   RasMan - ok
11:15:15.0328 4696   RasPppoe        (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
11:15:15.0437 4696   RasPppoe - ok
11:15:15.0546 4696   Raspti          (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
11:15:15.0687 4696   Raspti - ok
11:15:15.0796 4696   Rdbss           (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
11:15:15.0906 4696   Rdbss - ok
11:15:16.0000 4696   RDPCDD          (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
11:15:16.0171 4696   RDPCDD - ok
11:15:16.0250 4696   RDPWD           (5b3055daa788bd688594d2f5981f2a83) C:\WINDOWS\system32\drivers\RDPWD.sys
11:15:16.0296 4696   RDPWD - ok
11:15:16.0390 4696   RDSessMgr       (3c37bf86641bda977c3bf8a840f3b7fa) C:\WINDOWS\system32\sessmgr.exe
11:15:16.0500 4696   RDSessMgr - ok
11:15:16.0593 4696   redbook         (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
11:15:16.0718 4696   redbook - ok
11:15:16.0812 4696   RemoteAccess    (7e699ff5f59b5d9de5390e3c34c67cf5) C:\WINDOWS\System32\mprdim.dll
11:15:16.0921 4696   RemoteAccess - ok
11:15:17.0015 4696   RpcLocator      (aaed593f84afa419bbae8572af87cf6a) C:\WINDOWS\system32\locator.exe
11:15:17.0109 4696   RpcLocator - ok
11:15:17.0218 4696   RpcSs           (6b27a5c03dfb94b4245739065431322c) C:\WINDOWS\System32\rpcss.dll
11:15:17.0453 4696   RpcSs - ok
11:15:17.0546 4696   RSVP            (471b3f9741d762abe75e9deea4787e47) C:\WINDOWS\system32\rsvp.exe
11:15:17.0703 4696   RSVP - ok
11:15:17.0750 4696   RT2500USB - ok

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #40 on: March 31, 2012, 12:26:37 PM »
11:15:17.0812 4696   SamSs           (bf2466b3e18e970d8a976fb95fc1ca85) C:\WINDOWS\system32\lsass.exe
11:15:17.0906 4696   SamSs - ok
11:15:17.0984 4696   SCardSvr        (86d007e7a654b9a71d1d7d856b104353) C:\WINDOWS\System32\SCardSvr.exe
11:15:18.0093 4696   SCardSvr - ok
11:15:18.0203 4696   Schedule        (0a9a7365a1ca4319aa7c1d6cd8e4eafa) C:\WINDOWS\system32\schedsvc.dll
11:15:18.0328 4696   Schedule - ok
11:15:18.0406 4696   Secdrv          (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
11:15:18.0531 4696   Secdrv - ok
11:15:18.0625 4696   seclogon        (cbe612e2bb6a10e3563336191eda1250) C:\WINDOWS\System32\seclogon.dll
11:15:18.0734 4696   seclogon - ok
11:15:18.0843 4696   senfilt         (bb596a578330ad794c6769b588af6bb4) C:\WINDOWS\system32\drivers\senfilt.sys
11:15:18.0890 4696   senfilt - ok
11:15:18.0984 4696   SENS            (7fdd5d0684eca8c1f68b4d99d124dcd0) C:\WINDOWS\system32\sens.dll
11:15:19.0109 4696   SENS - ok
11:15:19.0203 4696   serenum         (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
11:15:19.0328 4696   serenum - ok
11:15:19.0421 4696   Serial          (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
11:15:19.0531 4696   Serial - ok
11:15:19.0546 4696   SetupNTGLM7X - ok
11:15:19.0625 4696   sfdrv01         (4c0d673281178cb496011a2e28571fc8) C:\WINDOWS\system32\drivers\sfdrv01.sys
11:15:19.0656 4696   sfdrv01 ( UnsignedFile.Multi.Generic ) - warning
11:15:19.0656 4696   sfdrv01 - detected UnsignedFile.Multi.Generic (1)
11:15:19.0734 4696   sfhlp02         (15be2b5e4dc5b8623cf167720682abc9) C:\WINDOWS\system32\drivers\sfhlp02.sys
11:15:19.0765 4696   sfhlp02 ( UnsignedFile.Multi.Generic ) - warning
11:15:19.0765 4696   sfhlp02 - detected UnsignedFile.Multi.Generic (1)
11:15:19.0859 4696   Sfloppy         (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
11:15:19.0968 4696   Sfloppy - ok
11:15:20.0015 4696   sfsync02 - ok
11:15:20.0093 4696   SharedAccess    (83f41d0d89645d7235c051ab1d9523ac) C:\WINDOWS\System32\ipnathlp.dll
11:15:20.0218 4696   SharedAccess - ok
11:15:20.0343 4696   ShellHWDetection (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:15:20.0375 4696   ShellHWDetection - ok
11:15:20.0453 4696   Simbad - ok
11:15:20.0531 4696   SimpTcp         (32933b07fc16d9f778bee12545fa1b1a) C:\WINDOWS\system32\tcpsvcs.exe
11:15:20.0687 4696   SimpTcp - ok
11:15:20.0781 4696   SiSGbeXP        (a86e52c55de3488b3fc0ff2b8ad711bf) C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys
11:15:20.0812 4696   SiSGbeXP - ok
11:15:20.0906 4696   SLIP            (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
11:15:21.0015 4696   SLIP - ok
11:15:21.0093 4696   smwdm           (0d7efa9d5bac36ea49940a8ead9990b5) C:\WINDOWS\system32\drivers\smwdm.sys
11:15:21.0109 4696   smwdm - ok
11:15:21.0203 4696   SNMP            (60c377be6b3cc83f6a8584934b181d2e) C:\WINDOWS\System32\snmp.exe
11:15:21.0328 4696   SNMP - ok
11:15:21.0421 4696   SNMPTRAP        (80a050795a107a76c2b1cd4cfbe010e6) C:\WINDOWS\System32\snmptrap.exe
11:15:21.0546 4696   SNMPTRAP - ok
11:15:21.0640 4696   SoundMAX Agent Service (default) (3978f082274f723ad5a0a8058c2417dd) C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
11:15:21.0656 4696   SoundMAX Agent Service (default) ( UnsignedFile.Multi.Generic ) - warning
11:15:21.0656 4696   SoundMAX Agent Service (default) - detected UnsignedFile.Multi.Generic (1)
11:15:21.0718 4696   Sparrow - ok
11:15:21.0781 4696   splitter        (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
11:15:21.0906 4696   splitter - ok
11:15:21.0984 4696   Spooler         (60784f891563fb1b767f70117fc2428f) C:\WINDOWS\system32\spoolsv.exe
11:15:22.0015 4696   Spooler - ok
11:15:22.0125 4696   sr              (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
11:15:22.0250 4696   sr - ok
11:15:22.0328 4696   srservice       (3805df0ac4296a34ba4bf93b346cc378) C:\WINDOWS\system32\srsvc.dll
11:15:22.0421 4696   srservice - ok
11:15:22.0734 4696   Srv             (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys
11:15:22.0796 4696   Srv - ok
11:15:22.0906 4696   SSDPSRV         (0a5679b3714edab99e357057ee88fca6) C:\WINDOWS\System32\ssdpsrv.dll
11:15:23.0015 4696   SSDPSRV - ok
11:15:23.0109 4696   stisvc          (8bad69cbac032d4bbacfce0306174c30) C:\WINDOWS\system32\wiaservc.dll
11:15:23.0250 4696   stisvc - ok
11:15:23.0328 4696   streamip        (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
11:15:23.0437 4696   streamip - ok
11:15:23.0546 4696   swenum          (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
11:15:23.0656 4696   swenum - ok
11:15:23.0765 4696   swmidi          (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
11:15:23.0875 4696   swmidi - ok
11:15:23.0937 4696   SwPrv - ok
11:15:23.0968 4696   symc810 - ok
11:15:24.0000 4696   symc8xx - ok
11:15:24.0046 4696   sym_hi - ok
11:15:24.0078 4696   sym_u3 - ok
11:15:24.0140 4696   sysaudio        (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
11:15:24.0265 4696   sysaudio - ok
11:15:24.0359 4696   SysmonLog       (c7abbc59b43274b1109df6b24d617051) C:\WINDOWS\system32\smlogsvc.exe
11:15:24.0468 4696   SysmonLog - ok
11:15:24.0546 4696   TapiSrv         (3cb78c17bb664637787c9a1c98f79c38) C:\WINDOWS\System32\tapisrv.dll
11:15:24.0656 4696   TapiSrv - ok
11:15:24.0765 4696   Tcpip           (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
11:15:24.0812 4696   Tcpip - ok
11:15:24.0921 4696   Tcpip6          (4e53bbcc4be37d7a4bd6ef1098c89ff7) C:\WINDOWS\system32\DRIVERS\tcpip6.sys
11:15:24.0953 4696   Tcpip6 - ok
11:15:25.0031 4696   TDPIPE          (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
11:15:25.0140 4696   TDPIPE - ok
11:15:25.0218 4696   TDTCP           (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
11:15:25.0343 4696   TDTCP - ok
11:15:25.0421 4696   TermDD          (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
11:15:25.0531 4696   TermDD - ok
11:15:25.0625 4696   TermService     (ff3477c03be7201c294c35f684b3479f) C:\WINDOWS\System32\termsrv.dll
11:15:25.0734 4696   TermService - ok
11:15:25.0843 4696   Themes          (99bc0b50f511924348be19c7c7313bbf) C:\WINDOWS\System32\shsvcs.dll
11:15:25.0859 4696   Themes - ok
11:15:25.0937 4696   TosIde - ok
11:15:26.0015 4696   TrkWks          (55bca12f7f523d35ca3cb833c725f54e) C:\WINDOWS\system32\trkwks.dll
11:15:26.0140 4696   TrkWks - ok
11:15:26.0250 4696   tunmp           (8f861eda21c05857eb8197300a92501c) C:\WINDOWS\system32\DRIVERS\tunmp.sys
11:15:26.0359 4696   tunmp - ok
11:15:26.0453 4696   Udfs            (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
11:15:26.0562 4696   Udfs - ok
11:15:26.0609 4696   ultra - ok
11:15:26.0671 4696   UMWdf           (ab0a7ca90d9e3d6a193905dc1715ded0) C:\WINDOWS\system32\wdfmgr.exe
11:15:26.0703 4696   UMWdf - ok
11:15:26.0812 4696   Update          (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
11:15:26.0953 4696   Update - ok
11:15:27.0031 4696   upnphost        (1ebafeb9a3fbdc41b8d9c7f0f687ad91) C:\WINDOWS\System32\upnphost.dll
11:15:27.0156 4696   upnphost - ok
11:15:27.0250 4696   UPS             (05365fb38fca1e98f7a566aaaf5d1815) C:\WINDOWS\System32\ups.exe
11:15:27.0359 4696   UPS - ok
11:15:27.0421 4696   USBAAPL - ok
11:15:27.0500 4696   usbaudio        (e919708db44ed8543a7c017953148330) C:\WINDOWS\system32\drivers\usbaudio.sys
11:15:27.0609 4696   usbaudio - ok
11:15:27.0718 4696   usbccgp         (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
11:15:27.0828 4696   usbccgp - ok
11:15:27.0921 4696   usbehci         (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
11:15:28.0046 4696   usbehci - ok
11:15:28.0125 4696   usbhub          (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
11:15:28.0250 4696   usbhub - ok
11:15:28.0328 4696   usbohci         (0daecce65366ea32b162f85f07c6753b) C:\WINDOWS\system32\DRIVERS\usbohci.sys
11:15:28.0437 4696   usbohci - ok
11:15:28.0515 4696   usbprint        (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
11:15:28.0640 4696   usbprint - ok
11:15:28.0718 4696   usbscan         (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
11:15:28.0828 4696   usbscan - ok
11:15:28.0890 4696   USBSTOR         (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
11:15:28.0984 4696   USBSTOR - ok
11:15:29.0062 4696   usbvideo        (63bbfca7f390f4c49ed4b96bfb1633e0) C:\WINDOWS\system32\Drivers\usbvideo.sys
11:15:29.0187 4696   usbvideo - ok
11:15:29.0265 4696   UTSCSI          (1413e1f3b48a0d36b9e6ad4ec40eb5da) C:\WINDOWS\system32\UTSCSI.EXE
11:15:29.0281 4696   UTSCSI ( UnsignedFile.Multi.Generic ) - warning
11:15:29.0281 4696   UTSCSI - detected UnsignedFile.Multi.Generic (1)
11:15:29.0375 4696   VgaSave         (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
11:15:29.0484 4696   VgaSave - ok
11:15:29.0546 4696   ViaIde - ok
11:15:29.0609 4696   VolSnap         (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
11:15:29.0718 4696   VolSnap - ok
11:15:29.0812 4696   VSS             (7a9db3a67c333bf0bd42e42b8596854b) C:\WINDOWS\System32\vssvc.exe
11:15:29.0937 4696   VSS - ok
11:15:30.0078 4696   vToolbarUpdater10.2.0 (3080f1f093869a19fb3d1f0226c73809) C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
11:15:30.0125 4696   vToolbarUpdater10.2.0 - ok
11:15:30.0234 4696   W32Time         (54af4b1d5459500ef0937f6d33b1914f) C:\WINDOWS\system32\w32time.dll
11:15:30.0375 4696   W32Time - ok
11:15:30.0468 4696   Wanarp          (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
11:15:30.0578 4696   Wanarp - ok
11:15:30.0625 4696   WDICA - ok
11:15:30.0703 4696   wdmaud          (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
11:15:30.0828 4696   wdmaud - ok
11:15:30.0921 4696   WebClient       (77a354e28153ad2d5e120a5a8687bc06) C:\WINDOWS\System32\webclnt.dll
11:15:31.0046 4696   WebClient - ok
11:15:31.0156 4696   winmgmt         (2d0e4ed081963804ccc196a0929275b5) C:\WINDOWS\system32\wbem\WMIsvc.dll
11:15:31.0296 4696   winmgmt - ok
11:15:31.0390 4696   WmdmPmSN        (140ef97b64f560fd78643cae2cdad838) C:\WINDOWS\system32\mspmsnsv.dll
11:15:31.0421 4696   WmdmPmSN - ok
11:15:31.0562 4696   WmiApSrv        (e0673f1106e62a68d2257e376079f821) C:\WINDOWS\system32\wbem\wmiapsrv.exe
11:15:31.0687 4696   WmiApSrv - ok
11:15:31.0796 4696   WMPNetworkSvc   (f74e3d9a7fa9556c3bbb14d4e5e63d3b) C:\Program Files\Windows Media Player\WMPNetwk.exe
11:15:31.0875 4696   WMPNetworkSvc ( UnsignedFile.Multi.Generic ) - warning
11:15:31.0875 4696   WMPNetworkSvc - detected UnsignedFile.Multi.Generic (1)
11:15:31.0968 4696   WpdUsb          (1385e5aa9c9821790d33a9563b8d2dd0) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
11:15:31.0984 4696   WpdUsb - ok
11:15:32.0078 4696   WS2IFSL         (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
11:15:32.0234 4696   WS2IFSL - ok
11:15:32.0328 4696   wscsvc          (7c278e6408d1dce642230c0585a854d5) C:\WINDOWS\system32\wscsvc.dll
11:15:32.0437 4696   wscsvc - ok
11:15:32.0531 4696   WSTCODEC        (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
11:15:32.0640 4696   WSTCODEC - ok
11:15:32.0718 4696   wuauserv        (35321fb577cdc98ce3eb3a3eb9e4610a) C:\WINDOWS\system32\wuauserv.dll
11:15:32.0843 4696   wuauserv - ok
11:15:32.0937 4696   WudfPf          (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
11:15:32.0968 4696   WudfPf - ok
11:15:33.0062 4696   WudfRd          (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
11:15:33.0093 4696   WudfRd - ok
11:15:33.0171 4696   WudfSvc         (05231c04253c5bc30b26cbaae680ed89) C:\WINDOWS\System32\WUDFSvc.dll
11:15:33.0203 4696   WudfSvc - ok
11:15:33.0312 4696   WZCSVC          (81dc3f549f44b1c1fff022dec9ecf30b) C:\WINDOWS\System32\wzcsvc.dll
11:15:33.0453 4696   WZCSVC - ok
11:15:33.0531 4696   xmlprov         (295d21f14c335b53cb8154e5b1f892b9) C:\WINDOWS\System32\xmlprov.dll
11:15:33.0656 4696   xmlprov - ok
11:15:33.0687 4696   MBR (0x1B8)     (8f558eb6672622401da993e1e865c861) \Device\Harddisk0\DR0
11:15:33.0937 4696   \Device\Harddisk0\DR0 - ok
11:15:33.0968 4696   Boot (0x1200)   (e492b30b1b00693dd34a17ab442d3836) \Device\Harddisk0\DR0\Partition0
11:15:33.0968 4696   \Device\Harddisk0\DR0\Partition0 - ok
11:15:33.0968 4696   ============================================================
11:15:33.0968 4696   Scan finished
11:15:33.0968 4696   ============================================================
11:15:34.0078 3620   Detected object count: 8
11:15:34.0078 3620   Actual detected object count: 8
11:20:15.0468 3620   aspnet_state ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0468 3620   aspnet_state ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:15.0468 3620   ATI Smart ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0468 3620   ATI Smart ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:15.0468 3620   IPN2220 ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0468 3620   IPN2220 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:15.0468 3620   sfdrv01 ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0468 3620   sfdrv01 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:15.0468 3620   sfhlp02 ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0484 3620   sfhlp02 ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:15.0484 3620   SoundMAX Agent Service (default) ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0484 3620   SoundMAX Agent Service (default) ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:15.0484 3620   UTSCSI ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0484 3620   UTSCSI ( UnsignedFile.Multi.Generic ) - User select action: Skip
11:20:15.0484 3620   WMPNetworkSvc ( UnsignedFile.Multi.Generic ) - skipped by user
11:20:15.0484 3620   WMPNetworkSvc ( UnsignedFile.Multi.Generic ) - User select action: Skip

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #41 on: March 31, 2012, 12:29:14 PM »
OTL logfile created on: 3/31/2012 11:33:26 AM - Run 1
OTL by OldTimer - Version 3.2.39.2     Folder = C:\Documents and Settings\customer1\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.00 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 71.83% Memory free
5.85 Gb Paging File | 5.26 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): c:\pagefile.sys 4092 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.06 Gb Free Space | 87.93% Space Free | Partition Type: NTFS
 
Computer Name: KEVINSPC | User Name: customer1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - [2012/03/31 11:28:19 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\customer1\Desktop\google.exe.exe
PRC - [2012/03/12 08:03:43 | 000,918,880 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
PRC - [2012/03/12 08:03:40 | 000,982,880 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2012/01/24 18:24:26 | 002,416,480 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe
PRC - [2012/01/14 22:25:38 | 000,296,056 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\realplayer\Update\realsched.exe
PRC - [2011/11/28 02:19:04 | 001,229,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe
PRC - [2011/11/03 18:20:58 | 000,803,144 | ---- | M] (AVG) -- C:\Program Files\AVG\AVG PC Tuneup\BoostSpeed.exe
PRC - [2011/09/08 21:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe
PRC - [2011/08/15 07:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe
PRC - [2011/08/02 07:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe
PRC - [2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/12 11:57:28 | 000,292,336 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
PRC - [2006/11/03 17:04:46 | 000,304,008 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
PRC - [2006/10/11 16:48:50 | 000,532,480 | ---- | M] ( ) -- C:\WINDOWS\system32\dlcxcoms.exe
PRC - [2006/01/02 18:41:22 | 000,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
PRC - [2005/07/22 14:03:00 | 000,425,984 | ---- | M] (Dell) -- C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
PRC - [2005/06/21 15:19:38 | 000,491,520 | ---- | M] () -- C:\WINDOWS\system32\dlcccoms.exe
PRC - [2004/10/14 11:11:10 | 001,388,544 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
PRC - [2003/01/01 05:08:46 | 000,045,568 | ---- | M] (USBest) -- C:\WINDOWS\system32\UTSCSI.EXE
PRC - [2002/09/20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
 
 
========== Modules (No Company Name) ==========
 
MOD - [2012/03/12 08:03:43 | 000,918,880 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe
MOD - [2012/03/12 08:03:40 | 001,869,152 | ---- | M] () -- C:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll
MOD - [2012/03/12 08:03:40 | 000,982,880 | ---- | M] () -- C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2012/01/11 04:02:05 | 003,391,488 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c561934e089_cb6ca372\mscorlib.dll
MOD - [2012/01/11 04:01:58 | 000,835,584 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.drawing\1.0.5000.0__b03f5f7f11d50a3a_5af389e8\system.drawing.dll
MOD - [2012/01/11 04:01:50 | 002,088,960 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.xml\1.0.5000.0__b77a5c561934e089_68c1ca44\system.xml.dll
MOD - [2012/01/11 04:01:44 | 003,035,136 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system.windows.forms\1.0.5000.0__b77a5c561934e089_d6d5949d\system.windows.forms.dll
MOD - [2012/01/11 04:01:32 | 001,966,080 | ---- | M] () -- c:\windows\assembly\nativeimages1_v1.1.4322\system\1.0.5000.0__b77a5c561934e089_ab886053\system.dll
MOD - [2012/01/11 04:01:15 | 001,232,896 | ---- | M] () -- c:\windows\assembly\gac\system\1.0.5000.0__b77a5c561934e089\system.dll
MOD - [2012/01/11 04:01:14 | 001,269,760 | ---- | M] () -- c:\windows\assembly\gac\system.web\1.0.5000.0__b03f5f7f11d50a3a\system.web.dll
MOD - [2012/01/11 04:01:13 | 002,064,384 | ---- | M] () -- c:\windows\assembly\gac\system.windows.forms\1.0.5000.0__b77a5c561934e089\system.windows.forms.dll
MOD - [2011/11/03 18:21:06 | 000,350,024 | ---- | M] () -- C:\Program Files\AVG\AVG PC Tuneup\madExcept_.bpl
MOD - [2011/11/03 18:21:06 | 000,184,136 | ---- | M] () -- C:\Program Files\AVG\AVG PC Tuneup\madBasic_.bpl
MOD - [2011/11/03 18:21:06 | 000,050,504 | ---- | M] () -- C:\Program Files\AVG\AVG PC Tuneup\madDisAsm_.bpl
MOD - [2007/01/12 11:57:28 | 000,292,336 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
MOD - [2006/11/03 17:04:46 | 000,304,008 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
MOD - [2006/10/20 00:33:26 | 000,117,760 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\dlcxdrpp.dll
MOD - [2006/10/06 07:24:28 | 000,016,384 | ---- | M] () -- C:\Program Files\Dell PC Fax\dlctrstr.dll
MOD - [2006/10/06 07:06:16 | 000,045,056 | ---- | M] () -- C:\WINDOWS\system32\DLPRMON.DLL
MOD - [2006/10/06 07:04:20 | 000,032,768 | ---- | M] () -- C:\Program Files\Dell PC Fax\ipcmt.dll
MOD - [2006/09/06 05:13:14 | 000,073,728 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 926\DLCXcfg.dll
MOD - [2006/08/08 14:54:18 | 000,278,528 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 926\dlcxscw.dll
MOD - [2006/07/18 20:39:33 | 001,339,392 | ---- | M] () -- c:\windows\assembly\gac\system.xml\1.0.5000.0__b77a5c561934e089\system.xml.dll
MOD - [2006/07/18 20:39:33 | 000,372,736 | ---- | M] () -- c:\windows\assembly\gac\system.management\1.0.5000.0__b03f5f7f11d50a3a\system.management.dll
MOD - [2006/07/18 20:39:32 | 000,466,944 | ---- | M] () -- c:\windows\assembly\gac\system.drawing\1.0.5000.0__b03f5f7f11d50a3a\system.drawing.dll
MOD - [2006/07/18 20:39:32 | 000,323,584 | ---- | M] () -- c:\windows\assembly\gac\system.runtime.remoting\1.0.5000.0__b77a5c561934e089\system.runtime.remoting.dll
MOD - [2006/03/14 16:38:24 | 000,143,360 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 926\dlcxdrec.dll
MOD - [2005/06/21 15:22:06 | 000,483,328 | ---- | M] () -- C:\WINDOWS\system32\dlcclmpm.dll
MOD - [2005/06/21 15:19:38 | 000,491,520 | ---- | M] () -- C:\WINDOWS\system32\dlcccoms.exe
MOD - [2005/06/21 15:18:24 | 000,155,648 | ---- | M] () -- C:\WINDOWS\system32\dlccprox.dll
MOD - [2005/06/06 10:58:38 | 000,065,536 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 924\dlcccfg.dll
MOD - [2005/04/27 16:30:44 | 000,118,784 | ---- | M] () -- C:\Program Files\Dell Photo AIO Printer 924\dlccdrec.dll
 
 
========== Win32 Services (SafeList) ==========
 
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2012/03/12 08:03:43 | 000,918,880 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\10.2.0\ToolbarUpdater.exe -- (vToolbarUpdater10.2.0)
SRV - [2011/10/12 07:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [On_Demand | Stopped] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011/08/02 07:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2008/04/14 06:42:04 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2008/04/14 06:41:56 | 000,035,328 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\iprip.dll -- (Iprip)
SRV - [2006/10/11 16:48:50 | 000,532,480 | ---- | M] ( ) [Auto | Running] -- C:\WINDOWS\system32\dlcxcoms.exe -- (dlcx_device)
SRV - [2005/06/21 15:19:38 | 000,491,520 | ---- | M] () [On_Demand | Running] -- C:\WINDOWS\system32\dlcccoms.exe -- (dlcc_device)
SRV - [2003/01/01 05:08:46 | 000,045,568 | ---- | M] (USBest) [Auto | Running] -- C:\WINDOWS\system32\UTSCSI.EXE -- (UTSCSI)
SRV - [2002/09/20 16:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
 
 
========== Driver Services (SafeList) ==========
 
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | Boot | Stopped] -- System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTGLM7X.sys -- (SetupNTGLM7X)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (RT2500USB)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] --  -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] --  -- (PCANDIS5)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTACCESS.sys -- (NTACCESS)
DRV - File not found [Kernel | On_Demand | Unknown] -- C:\DOCUME~1\CUSTOM~1\LOCALS~1\Temp\mbr.sys -- (mbr)
DRV - File not found [Kernel | System | Stopped] --  -- (lbrtfdc)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\irsir.sys -- (irsir)
DRV - File not found [Kernel | System | Stopped] --  -- (InCDRm)
DRV - File not found [Kernel | System | Stopped] --  -- (InCDPass)
DRV - File not found [Kernel | System | Stopped] --  -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | System | Stopped] --  -- (Changer)
DRV - File not found [Kernel | On_Demand | Running] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\ALCXWDM.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2011/10/07 07:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011/10/04 07:21:42 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011/09/13 07:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011/08/08 07:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011/07/11 02:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011/07/11 02:14:28 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011/07/11 02:14:28 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV - [2011/07/11 02:14:26 | 000,134,608 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/02/11 07:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2008/03/03 11:00:00 | 000,043,392 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)
DRV - [2006/06/07 04:08:58 | 001,580,544 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2005/08/18 04:52:06 | 000,093,568 | R--- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvata.sys -- (nvata)
DRV - [2005/08/10 07:44:04 | 000,050,688 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2005/07/26 07:01:56 | 000,415,360 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvapu.sys -- (nvnforce) Service for NVIDIA(R) nForce(TM)
DRV - [2005/07/26 06:58:30 | 000,053,376 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvax.sys -- (nvax) Service for NVIDIA(R) nForce(TM)
DRV - [2005/05/16 08:20:39 | 000,006,656 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005/04/05 14:22:30 | 000,012,928 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/04/05 14:22:28 | 000,033,536 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2005/03/09 01:53:00 | 000,036,352 | R--- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdK8.sys -- (AmdK8)
DRV - [2005/03/01 12:01:40 | 000,392,704 | ---- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (senfilt)
DRV - [2004/09/14 12:55:44 | 000,088,960 | ---- | M] (Analog Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MidiSyn.sys -- (MidiSyn)
DRV - [2004/03/29 04:23:42 | 000,140,288 | R--- | M] (Inprocomm, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\i2220ntx.sys -- (IPN2220)
DRV - [2001/08/17 15:00:04 | 000,002,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\msmpu401.sys -- (ms_mpu401)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADBF_en
IE - HKCU\..\SearchScopes\{8260C2B8-E0D1-448a-B062-33D12D468BF0}: "URL" = http://search.alot.com/web?pr=prov&client_id=6B02A47001C8345C0009EC19&install_time=01-12-2007:14:54&src_id=11003&tb_version=1.0.1.0&q={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={4192E04B-5472-40CF-9B5A-D5A52A438979}&mid=394e44f4630a47d18da8d15e776005a6-87d0ec190e4c69a23e608e916e5c08d08c9e9e6c&lang=en&ds=AVG&pr=fr&d=2012-01-28 17:54:40&v=9.0.0.23&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #42 on: March 31, 2012, 12:30:42 PM »
========== FireFox ==========
 
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:12.0.0.1912
FF - prefs.js..extensions.enabledItems: avg@toolbar:9.0.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:15.0.1
FF - prefs.js..keyword.URL: "http://isearch.avg.com/search?cid=%7B9b5491a7-5335-4be7-ac85-02b376fd61ba%7D&mid=394e44f4630a47d18da8d15e776005a6-87d0ec190e4c69a23e608e916e5c08d08c9e9e6c&ds=AVG&v=9.0.0.23&lang=en&pr=pr&d=2011-12-22%2017%3A52%3A00&sap=ku&q="
FF - user.js - File not found
 
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=:  File not found
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.0: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine,version=1.1: C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\PROGRA~1\SONYON~1\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@real.com/RhapsodyPlayerEngine: C:\Documents and Settings\customer1\Application Data\nprhapengine.dll File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG2012\Firefox\ [2012/02/02 09:19:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012/02/02 09:20:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\avg@toolbar: C:\Documents and Settings\All Users\Application Data\AVG Secure Search\10.2.0.3\ [2012/03/12 08:03:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/01/14 22:25:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/24 13:21:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/03/24 13:21:30 | 000,000,000 | ---D | M]
 
[2009/07/05 17:25:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\customer1\Application Data\Mozilla\Extensions
[2009/07/05 17:25:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\customer1\Application Data\Mozilla\Firefox\Profiles\gygvqas6.default\extensions
[2012/03/24 13:21:38 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/03/12 08:03:53 | 000,000,000 | ---D | M] (AVG Security Toolbar) -- C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\AVG SECURE SEARCH\10.2.0.3
[2009/01/17 08:30:19 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2012/03/12 23:39:39 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/10 06:54:13 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/03/12 08:03:39 | 000,003,766 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/03/12 23:38:32 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/03/12 23:38:32 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
 
O1 HOSTS File: ([2012/03/29 16:21:49 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1       localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll ()
O2 - BHO: (AL2Spy Class) - {DC200356-0864-4F66-8964-5D43A19300F5} - C:\WINDOWS\AutoLogin\AL2DLL.dll (Fineart)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\10.2.0.3\AVG Secure Search_toolbar.dll ()
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DLCCCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.DLL ()
O4 - HKLM..\Run: [dlccmon.exe] C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe (Dell)
O4 - HKLM..\Run: [DLCXCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.DLL ()
O4 - HKLM..\Run: [dlcxmon.exe] C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe ()
O4 - HKLM..\Run: [FaxCenterServer] C:\Program Files\Dell PC Fax\fm3032.exe ()
O4 - HKLM..\Run: [MemoryCardManager] C:\Program Files\Dell Photo AIO Printer 926\memcard.exe ()
O4 - HKLM..\Run: [ROC_roc_dec12] C:\Program Files\AVG Secure Search\ROC_roc_dec12.exe ()
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\program files\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Mahjong%20Escape%20-%20Ancient%20Japan/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/3/9/8/398422c0-8d3e-40e1-a617-af65a72a0465/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {38AB6A6C-CC4C-4F9E-A3DD-3C5681EF18A1} http://www.freerealms.com/gamedata/FreeRealmsInstaller.cab (SonyOnlineInstallerX)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/scan8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1160522783484 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1155655455656 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/SCRABBLE/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DE22A7AB-A739-4C58-AD52-21F9CD6306B7} http://download.microsoft.com/download/7/E/6/7E6A8567-DFE4-4624-87C3-163549BE2704/clearadj.cab (CTAdjust Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A17128A-31C1-494A-B8F5-0761BE95C120}: DhcpNameServer = 66.38.1.91 66.38.0.240 66.38.0.241
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6151B8D1-1250-49F0-A78C-282061E09E38}: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8AD25AF2-6805-4F2F-B834-8F6890B2EDCB}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FAA11E2B-BF70-4753-AC88-0B28DAA776B1}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\10.2.0\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\customer1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\customer1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/07/18 17:45:42 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
 
NetSvcs: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
NetSvcs: Ias -  File not found
NetSvcs: Iprip - C:\WINDOWS\system32\iprip.dll (Microsoft Corporation)
NetSvcs: NWCWorkstation -  File not found
NetSvcs: Nwsapagent -  File not found
NetSvcs: WmdmPmSp -  File not found
 
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\WINDOWS\System32\xvidvfw.dll ()
 
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
 
MsConfig - StartUpReg: DLCCCATS - hkey= - key= -  File not found
 
========== Files/Folders - Created Within 30 Days ==========
 
[2012/03/31 11:28:19 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\customer1\Desktop\google.exe.exe
[2012/03/31 11:26:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\customer1\Desktop\Logs
[2012/03/31 11:11:59 | 002,068,016 | ---- | C] (Kaspersky Lab ZAO) -- C:\Documents and Settings\customer1\Desktop\tdsskiller.exe
[2012/03/29 16:13:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2012/03/28 16:29:16 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2012/03/28 16:27:08 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2012/03/28 16:27:08 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2012/03/28 16:27:08 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2012/03/28 16:27:08 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2012/03/28 16:26:58 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2012/03/28 16:26:54 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/03/28 16:20:48 | 004,448,457 | R--- | C] (Swearware) -- C:\Documents and Settings\customer1\Desktop\ComboFix.exe
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2012/03/31 11:36:15 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/03/31 11:28:19 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\customer1\Desktop\google.exe.exe
[2012/03/31 11:11:59 | 002,068,016 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\customer1\Desktop\tdsskiller.exe
[2012/03/31 08:55:03 | 093,178,787 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2012/03/30 07:29:01 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2012/03/29 18:56:46 | 000,245,021 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2012/03/29 16:22:13 | 000,001,596 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/03/29 16:21:49 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/03/29 16:21:27 | 000,000,286 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-73586283-842925246-725345543-1004.job
[2012/03/29 16:21:19 | 000,000,376 | ---- | M] () -- C:\WINDOWS\tasks\AVG PC Tuneup Integrator Start On customer1 Logon.job
[2012/03/29 16:21:10 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/29 15:55:52 | 000,000,417 | ---- | M] () -- C:\Documents and Settings\customer1\Desktop\fixhosts.bat
[2012/03/29 10:54:00 | 000,000,294 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-73586283-842925246-725345543-1004.job
[2012/03/28 16:29:22 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2012/03/28 16:20:48 | 004,448,457 | R--- | M] (Swearware) -- C:\Documents and Settings\customer1\Desktop\ComboFix.exe
[2012/03/24 13:21:45 | 000,000,742 | ---- | M] () -- C:\Documents and Settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/24 13:21:45 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/03/24 13:07:34 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/03/24 13:07:34 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2012/03/15 09:21:37 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2012/03/15 03:18:56 | 000,260,640 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/03/15 03:01:04 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2012/03/13 15:11:25 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/03/12 07:02:55 | 000,383,254 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/03/12 07:02:55 | 000,053,608 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/03/02 13:28:07 | 000,000,372 | ---- | M] () -- C:\Documents and Settings\customer1\My Documents\spider.sav
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2012/03/28 16:34:21 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/03/28 16:29:22 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2012/03/28 16:29:18 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2012/03/28 16:27:08 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/03/28 16:27:08 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/03/28 16:27:08 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/03/28 16:27:08 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/03/28 16:27:08 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/03/28 16:07:12 | 000,000,417 | ---- | C] () -- C:\Documents and Settings\customer1\Desktop\fixhosts.bat
[2012/03/24 13:21:45 | 000,000,742 | ---- | C] () -- C:\Documents and Settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/03/24 13:21:45 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/03/24 13:21:45 | 000,000,724 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk
[2012/03/24 13:07:34 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\customer1\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes Anti-Malware.lnk
[2012/03/13 16:10:00 | 000,001,374 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2012/02/15 01:19:34 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
 
========== LOP Check ==========
 
[2012/03/12 08:03:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Secure Search
[2012/02/24 23:23:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG2012
[2006/12/19 10:15:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CA
[2011/12/22 18:51:51 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/05/20 19:39:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\iWin Games
[2008/09/04 06:17:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\JollyBear
[2012/03/31 08:55:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2007/12/01 16:37:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YAHOO
[2009/07/16 10:20:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2012/02/24 23:33:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\AVG
[2011/12/22 18:52:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\AVG Secure Search
[2011/12/22 18:53:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\AVG2012
[2009/12/24 23:51:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\GameHouse
[2009/01/21 13:06:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\iWin
[2011/12/29 22:23:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\QuickScan
[2009/12/24 23:52:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\Scrabble Plus
[2009/02/02 14:31:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\Simply Super Software
[2008/08/19 12:22:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\customer1\Application Data\SpinTop
[2012/03/29 16:21:19 | 000,000,376 | ---- | M] () -- C:\WINDOWS\Tasks\AVG PC Tuneup Integrator Start On customer1 Logon.job
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %systemroot%\*. /rp /s >
 
<  >
 
<  >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 145 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4

< End of report >

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #43 on: March 31, 2012, 12:32:09 PM »
OTL Extras logfile created on: 3/31/2012 11:33:26 AM - Run 1
OTL by OldTimer - Version 3.2.39.2     Folder = C:\Documents and Settings\customer1\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
2.00 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 71.83% Memory free
5.85 Gb Paging File | 5.26 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): c:\pagefile.sys 4092 4092 [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 131.06 Gb Free Space | 87.93% Space Free | Partition Type: NTFS
 
Computer Name: KEVINSPC | User Name: customer1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] -- rundll32.exe ieframe.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] -- "%1" %*
InternetShortcut [open] -- rundll32.exe ieframe.dll,OpenURL %l
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"135:TCP" = 135:TCP:*:Enabled:TCP Port 135
"5000:TCP" = 5000:TCP:*:Enabled:TCP Port 5000
"5001:TCP" = 5001:TCP:*:Enabled:TCP Port 5001
"5002:TCP" = 5002:TCP:*:Enabled:TCP Port 5002
"5003:TCP" = 5003:TCP:*:Enabled:TCP Port 5003
"5004:TCP" = 5004:TCP:*:Enabled:TCP Port 5004
"5005:TCP" = 5005:TCP:*:Enabled:TCP Port 5005
"5006:TCP" = 5006:TCP:*:Enabled:TCP Port 5006
"5007:TCP" = 5007:TCP:*:Enabled:TCP Port 5007
"5008:TCP" = 5008:TCP:*:Enabled:TCP Port 5008
"5009:TCP" = 5009:TCP:*:Enabled:TCP Port 5009
"5010:TCP" = 5010:TCP:*:Enabled:TCP Port 5010
"5011:TCP" = 5011:TCP:*:Enabled:TCP Port 5011
"5012:TCP" = 5012:TCP:*:Enabled:TCP Port 5012
"5013:TCP" = 5013:TCP:*:Enabled:TCP Port 5013
"5014:TCP" = 5014:TCP:*:Enabled:TCP Port 5014
"5015:TCP" = 5015:TCP:*:Enabled:TCP Port 5015
"5016:TCP" = 5016:TCP:*:Enabled:TCP Port 5016
"5017:TCP" = 5017:TCP:*:Enabled:TCP Port 5017
"5018:TCP" = 5018:TCP:*:Enabled:TCP Port 5018
"5019:TCP" = 5019:TCP:*:Enabled:TCP Port 5019
"5020:TCP" = 5020:TCP:*:Enabled:TCP Port 5020
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\mmc.exe" = C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console -- (Microsoft Corporation)
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Enabled:RealPlayer -- (RealNetworks, Inc.)
"C:\WINDOWS\system32\dlcxcoms.exe" = C:\WINDOWS\system32\dlcxcoms.exe:*:Enabled:Lexmark Communications System -- ( )
"C:\WINDOWS\system32\dlcccoms.exe" = C:\WINDOWS\system32\dlcccoms.exe:*:Enabled:Dell 924 Server -- ()
"C:\WINDOWS\system32\spool\drivers\w32x86\3\dlccPSWX.EXE" = C:\WINDOWS\system32\spool\drivers\w32x86\3\dlccPSWX.EXE:*:Enabled:Dell 924 Printer Status -- ()
"C:\Program Files\AVG\AVG2012\avgmfapx.exe" = C:\Program Files\AVG\AVG2012\avgmfapx.exe:*:Enabled:AVG Installer -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgnsx.exe" = C:\Program Files\AVG\AVG2012\avgnsx.exe:*:Enabled:Online Shield -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgdiagex.exe" = C:\Program Files\AVG\AVG2012\avgdiagex.exe:*:Enabled:AVG Diagnostics 2012 -- (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG2012\avgemcx.exe" = C:\Program Files\AVG\AVG2012\avgemcx.exe:*:Enabled:Personal E-mail Scanner -- (AVG Technologies CZ, s.r.o.)
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{083F79E4-6FE9-46FB-A6C6-4F8862742947}" = ATI HYDRAVISION
"{0D2E80C8-0875-43EB-9623-47118E2DFBCA}" = Quicken 2007
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{22DE1881-9D24-4981-B5CC-EC7E9F2F4D52}" = Rhapsody Player Engine
"{26A24AE4-039D-4CA4-87B4-2F83216010FF}" = Java(TM) 6 Update 30
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}" = Rhapsody Player Engine
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java(TM) SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java(TM) 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java(TM) 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java(TM) 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{4192EAC0-6B36-4723-B216-D0E86E7757AC}" = Jasc Paint Shop Photo Album 5
"{4781569D-5404-1F26-4B2B-6DF444441031}" = Nero 7 Ultra Edition
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4EFC72DA-2314-4E5D-AC8E-1C954CDB8BBF}" = AVG 2012
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{78C496B9-5A6B-4692-8C2E-AFFFC34E4961}" = Jasc Paint Shop Pro Studio, Dell Editon
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D70145A-3BD3-4DBF-9CBF-223EF4A43257}" = ATI Parental Control & Encoder
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B4C88CF0-B617-4658-8F84-C4E847FBC9F7}" = Microsoft Managed DirectX (1126)
"{B6B834C0-0000-4F87-B767-D58D8035EC0E}" = RCA Video Converter
"{BE83EC7F-7519-4036-8B59-ECE494308124}" = ATI Catalyst Control Center
"{C151CE54-E7EA-4804-854B-F515368B0798}" = Athlon 64 Processor Driver
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{E78DAA24-38F8-4D35-B732-B18ABA0424DF}" = Microsoft Office Live Image Uploader
"{E7E84E23-C5C0-4B15-B13A-C63149E59C98}" = AVG 2012
"{F0A37341-D692-11D4-A984-009027EC0A9C}" = SoundMAX
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG" = AVG 2012
"Dell PC Fax" = Dell PC Fax
"Dell Photo AIO Printer 924" = Dell Photo AIO Printer 924
"Dell Photo AIO Printer 926" = Dell Photo AIO Printer 926
"Free Realms Installer" = Free Realms Installer
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InterActual Player" = InterActual Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 11.0 (x86 en-US)" = Mozilla Firefox 11.0 (x86 en-US)
"MSN Music Assistant" = MSN Music Assistant
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"RealPlayer 15.0" = RealPlayer
"SCRABBLE PLUS" = SCRABBLE PLUS
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format Runtime
"Windows Media Player" = Windows Media Player 10
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
 
========== Last 10 Event Log Errors ==========
 
[ Application Events ]
Error - 12/18/2009 3:04:49 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 489
Description = wuauclt (6600) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
 for read only access failed with system error 32 (0x00000020): "The process cannot
 access the file because it is being used by another process. ".  The open file
operation will fail with error -1032 (0xfffffbf8).
 
Error - 12/18/2009 3:04:49 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 455
Description = wuaueng.dll (6600) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
 
Error - 12/18/2009 5:16:38 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 489
Description = wuauclt (2660) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
 for read only access failed with system error 32 (0x00000020): "The process cannot
 access the file because it is being used by another process. ".  The open file
operation will fail with error -1032 (0xfffffbf8).
 
Error - 12/18/2009 5:16:38 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 455
Description = wuaueng.dll (2660) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
 
Error - 12/18/2009 5:16:48 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 489
Description = wuauclt (2660) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
 for read only access failed with system error 32 (0x00000020): "The process cannot
 access the file because it is being used by another process. ".  The open file
operation will fail with error -1032 (0xfffffbf8).
 
Error - 12/18/2009 5:16:48 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 455
Description = wuaueng.dll (2660) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
 
Error - 12/18/2009 7:39:10 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 489
Description = wuauclt (7536) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
 for read only access failed with system error 32 (0x00000020): "The process cannot
 access the file because it is being used by another process. ".  The open file
operation will fail with error -1032 (0xfffffbf8).
 
Error - 12/18/2009 7:39:10 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 455
Description = wuaueng.dll (7536) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
 
Error - 12/18/2009 7:39:20 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 489
Description = wuauclt (7536) An attempt to open the file "C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log"
 for read only access failed with system error 32 (0x00000020): "The process cannot
 access the file because it is being used by another process. ".  The open file
operation will fail with error -1032 (0xfffffbf8).
 
Error - 12/18/2009 7:39:20 AM | Computer Name = KEVINSPC | Source = ESENT | ID = 455
Description = wuaueng.dll (7536) SUS20ClientDataStore: Error -1032 (0xfffffbf8)
occurred while opening logfile C:\WINDOWS\SoftwareDistribution\DataStore\Logs\edb.log.
 
[ System Events ]
Error - 3/18/2012 6:25:35 AM | Computer Name = KEVINSPC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.2 for the Network Card with network
 address 00173184EC55 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server
 sent a DHCPNACK message).
 
Error - 3/18/2012 6:27:01 AM | Computer Name = KEVINSPC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   sfsync02
 
Error - 3/20/2012 5:30:24 AM | Computer Name = KEVINSPC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.2 for the Network Card with network
 address 00173184EC55 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server
 sent a DHCPNACK message).
 
Error - 3/24/2012 1:57:03 PM | Computer Name = KEVINSPC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   sfsync02
 
Error - 3/26/2012 3:47:35 PM | Computer Name = KEVINSPC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   sfsync02
 
Error - 3/27/2012 5:30:23 AM | Computer Name = KEVINSPC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.2 for the Network Card with network
 address 00173184EC55 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server
 sent a DHCPNACK message).
 
Error - 3/28/2012 5:02:45 PM | Computer Name = KEVINSPC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   sfsync02
 
Error - 3/28/2012 5:17:58 PM | Computer Name = KEVINSPC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   sfsync02
 
Error - 3/28/2012 5:46:36 PM | Computer Name = KEVINSPC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.2.2 for the Network Card with network
 address 00173184EC55 has been  denied by the DHCP server 0.0.0.0 (The DHCP Server
 sent a DHCPNACK message).
 
Error - 3/29/2012 5:22:08 PM | Computer Name = KEVINSPC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
   sfsync02
 
 
< End of report >

Offline kcrawhorn

  • Bronze Member
  • Posts: 126
Re: [In Progress B]AVG found Trojan Horse Crypt.ASHD
« Reply #44 on: March 31, 2012, 12:33:33 PM »
The computer is still slow and going slowly to websites.